From ff8a0c2107d52db93d9145229e8142220675a882 Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Fri, 28 Apr 2006 07:19:46 +0000 Subject: [PATCH] - moved RFCs from ikev2 into doc dir --- ...DoxygenManual] - Doxygen Manual v1.4.5.pdf | Bin 0 -> 808558 bytes ...g And Programming With Netlink Sockets.pdf | Bin 0 -> 172284 bytes ...ey Exchange in IPSec - Analysis of IKE.pdf | Bin 0 -> 104081 bytes ...ications and Implementation Guidelines.txt | 3248 ++++++++ ...ey Exchange (IKEv2) Protocol Draft v17.txt | 6535 +++++++++++++++ ...[IKEv2bis] - draft-hoffman-ikev2bis-00.txt | 6776 ++++++++++++++++ ...Architecture for the Internet Protocol.txt | 5657 +++++++++++++ ...v1 and IKEv2 - A Quantitative Analyses.pdf | Bin 0 -> 169659 bytes ...yed-Hashing for Message Authentication.txt | 619 ++ ...ty Domain of Interpretation for ISAKMP.txt | 1795 ++++ ...n and Key Management Protocol (ISAKMP).txt | 4819 +++++++++++ ...409] - The Internet Key Exchange (IKE).txt | 2299 ++++++ ... The OAKLEY Key Determination Protocol.txt | 3083 +++++++ ...ryptography Specifications Version 2.0.txt | 2187 +++++ doc/ikev2/[RFC3280] - x509 Certificates.txt | 7227 +++++++++++++++++ ...groups for Internet Key Exchange (IKE).txt | 563 ++ ...Architecture for the Internet Protocol.txt | 5659 +++++++++++++ ...Internet Key Exchange (IKEv2) Protocol.txt | 5547 +++++++++++++ ...nternet Key Exchange Version 2 (IKEv2).txt | 339 + ...rotokolle, Internet Key Exchange (IKE).pdf | Bin 0 -> 653279 bytes 20 files changed, 56353 insertions(+) create mode 100644 doc/ikev2/[DoxygenManual] - Doxygen Manual v1.4.5.pdf create mode 100644 doc/ikev2/[Horman04] - Understanding And Programming With Netlink Sockets.pdf create mode 100644 doc/ikev2/[IKEAnalysis] - Key Exchange in IPSec - Analysis of IKE.pdf create mode 100644 doc/ikev2/[IKEv2Clarifications] - IKEv2 Clarifications and Implementation Guidelines.txt create mode 100644 doc/ikev2/[IKEv2Draft] - Internet Key Exchange (IKEv2) Protocol Draft v17.txt create mode 100644 doc/ikev2/[IKEv2bis] - draft-hoffman-ikev2bis-00.txt create mode 100644 doc/ikev2/[IPsecArch] - Security Architecture for the Internet Protocol.txt create mode 100644 doc/ikev2/[QuantitativeAnalyses] - IKEv1 and IKEv2 - A Quantitative Analyses.pdf create mode 100644 doc/ikev2/[RFC2104] - HMAC - Keyed-Hashing for Message Authentication.txt create mode 100644 doc/ikev2/[RFC2407] - The Internet IP Security Domain of Interpretation for ISAKMP.txt create mode 100644 doc/ikev2/[RFC2408] - Internet Security Association and Key Management Protocol (ISAKMP).txt create mode 100644 doc/ikev2/[RFC2409] - The Internet Key Exchange (IKE).txt create mode 100644 doc/ikev2/[RFC2412] - The OAKLEY Key Determination Protocol.txt create mode 100644 doc/ikev2/[RFC2437] - PKCS #1 RSA Cryptography Specifications Version 2.0.txt create mode 100644 doc/ikev2/[RFC3280] - x509 Certificates.txt create mode 100644 doc/ikev2/[RFC3526] - More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE).txt create mode 100644 doc/ikev2/[RFC4301] - Security Architecture for the Internet Protocol.txt create mode 100644 doc/ikev2/[RFC4306] - Internet Key Exchange (IKEv2) Protocol.txt create mode 100644 doc/ikev2/[RFC4307] - Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2).txt create mode 100644 doc/ikev2/[Thomas03] - IPSec Architektur und Protokolle, Internet Key Exchange (IKE).pdf diff --git a/doc/ikev2/[DoxygenManual] - Doxygen Manual v1.4.5.pdf b/doc/ikev2/[DoxygenManual] - Doxygen Manual v1.4.5.pdf new file mode 100644 index 0000000000000000000000000000000000000000..496421eb5454a434d461c4e311693c2b20e7b5c4 GIT binary patch literal 808558 zcmd4(2UL^W@;?p-5KsiMfCwT)MWjOlA%GO=O+b1RkP>?DJros0rFW$FBE2J`B3(eF zSLwY;ui^g$toMA+@}7I%wccOWN+5amo@e%artO`~+`2C$!U$nv!-IiYz!o~jc--7z zW_d8PsD*+Bm{|x+W2tRz%LJhX^YY>$%=OSCIKGXf5eF;UAgsYs+U9oJrnKKLbN&q> z8-%W{k%js1v>?zQ#LR7MwM|X6(PMtlg0TL981z@hAnf0Xi6U%mjm!YYRI|V68t1{Rsf}UkS1P0)VcmogP|h`WDt^cBa}td1L((4DjDb{)E9= z+tSbmtZl9b)-%#Ju+}#Fh3222;P{m$+Yc!2TO%y3Ep!n!Hoq>K?N1nR{zmNw2K;um z7G{9X>4Hs-%uT=s2y=w>?<&alCtM&bzmfg{jEtSFrJXHU1Q4e7FF3RP2_DFA#s>R= z&pm)aG&;5xV1%PB!rENh6s-46FMnql_9wU?znKl}2VNr92rD~4%}t%a{5B>CJ+Q1D z!Uk=SKVgIY2{y=YCdB>&Hw8dXbxaX9h87lRGy0*f?0<*cvE%uTQT89OiHn2f5c&vf zgt;!_Km8B;9|8N#9@&2YCW6qmwX;V2Tr2w@q591x;Xj}fvT$?)R0%8wSh$6?(~q^n z{|L-)wh8|M%y)uzHrfV19S{7ESo~&}96zu?le5(}0RK*o1f;OhM}2U+F$;|3K!OCf>FIi<_S~p`UAqu>297-%JnkGy300 zSet^SEcEP55nziG$BB+Y+O~h=;vj#{41Tjs$j{v18{cTRrfmvn?e7T(<}LMcF1Q45C4M3Ev^GV8+@to&H3glR9s(*9k95q7 z>l_K>I=gOb^^~VX2>Dq?>vZ!mpDF5(3KvC?-s&#s-X~0aE+H#j&aK4e5?C~36ChT5BK6Vbn4DN8NKP+qZe{E>-xhC1~$ou z+9_(IZ`stR8E5{m95VA&U1y17gTgmld3LBuwRM938;EA zxH9;N*Uf*sSlw>_&7CWSlj}kcO0cJv%)fG7Q44r8{Vq?!{TYqn+;Y`MaECI6gm=&L zPu|zXhs2*j9$pit5_3^dpSTeo3vV!*3%-@$yWi_y1L7C9RR>beZ({nEe4fAnq@l;c zR&cUJfSKCJs&wJb)4qQfz_YXhoI-Kmz}`?Kjo_<+ds^I>tawi^nW)r(=7}2s+jS za09Q$j6nc`3c@N(0R9MRZ8HRzhKU()Y3R_PWolty!DOkYPy1~QdJWQcW;%eLe4i$6 zu5Te^qzkaaddxi-U|-wT+6Z7C?GsqQ$FBg_0zVeS&dLUcaKeGley$y@l=p#*NgiPf zRtJP7Bm!m@Hv?`b2nNOpJKBoM+X8xdyf8UnIxCtidhN{L7I<=n1Gs|rrsykx@_yHI z$Z>86NcIm({*qpS*J zz}R|y0N>;7hqrzBDe`=c0`G3c)1Sx3&=|hx{#SiCmd(k=<#?TXcDjHJX@uqPgGCK3 zfDBvL+Q`xt3}<42)1s~JJD|tQ{66nQkABDkkNFrbW;r%IW(7GwTzcr--_{9_S?0bJ z8XtKnFbfk4^f!9nLk(KqKQ!W4&}iK>wXl}A)CRH@X22~Q=_2Gr1@M@ajr0Il0f2_b zEQT;LFa)6HgaddQ+1daO5r{387UpPuSDP zTs+deP^g%WxU`arhNcFGu)Y~W%~W1pLlsQ~gYf+M%a<XRb*xgc>R5Z7!MjXyg_P_T z^=%qjIyM+PoP(1~P)JxrR7_k#UO`bwSw&S%R}Z0YU}$7)V{2#c;OOM+{pj%%AK#~b z!6Bhx;SrHh(MicEscGpMnOTKJ#U-U>4wSlG{X4S?{m zFaYqdE`azz8__gL9(cb#^^ZWt4ibJ93sUtxWY=Er%c~APCzq2Wn}{_Uv<{{cKeJy; zDG{9Q|3$4p!_m1g+Vw**k*u(-FHMpk=>MgspU&L}&Yeb`wv=l6CeJP}=_D~;Paq?( z5>N9xZ=VfQvCD?_dJYIR0z9u!{lCOGnioHdO5T!d;_zYOYfgPj;|c;^j!9A1-}jz% zRw;fgAF|V3nM}H0qgJi4Ly&T>+slt8@2*FZ9}VdLp(iFSYBpnD9C*oYYp}RD&M3+} zlu1Y1cHYgT9noM_ut}-*DW}dfpJKdtq2uk+bwz$*BIN`jZRQXYy8Tv9z z3=Q^s9r@X;|1wQZ6pZxBK_vff^z#RI+-7uldZ`NXweTt`Yg;l)gms_#qHgYXYC0^@ zXC8qZyK<}-&TkP`WLk=JD27YZLspoGJlZSV>SU%}dfBOqjR)$o&fST46s9>Z6X<4q zond_%NG2K6uX0IL@vra_oO(Cs@Pu8igl*sgh0$ypYC-`>sH&ix$M_Gb+3!wP~wZ* z9T%m1!D)9Ud4IkzuMDTypPkSRt4}iVm9S#j8?Vu^tAvL=qup5x&qKq;KO#s-^Z_L9 zd-*+4_Z=ULVVtEa8ZJ8g66#`?>m2DT-!b3vf)jd392j9?Va?s3|9EF|hWJ%a)(eE9 z#yQ&|_+>v@F1uIH>yk2u9(W9%--muC^;#)(hH| z*1~=?NtI%Fv;j9ns$#tYoIOUES7~o{eN}DCx&9Rzs@_*3EC)9gy+SErF`&igTrt8P zJuv0MNiv&7X<{`*`95~5cD9(o3_ipY`m9)y-zk2KGM0JZ2-JUQj4G2XuYUPVLBX<7 zPtMBor9#+is?KJ2aRT z>Ce(BS!HyY(!z*e>LXXmW(3+s4<~k_TNXMNDVn0$6tCOAUBk$}&=zcYjxaIT&(Y7O z1NwmMR#Mx-naD zQn8#oOPgmqCf?2;-M$cd(6lATMw27-rZRNw3ZbiQ=7+U_YI?{)hU0*VUW+YN8H^^U z$odHMg)f%JeAuc@v|6G;U@y^y6d>kk{#lOb;MKu=o!xt@=+~+tQikvSXtK}C3hOQO z9)S?07p{K@MtN7?n@l93*5EQv300P(KU8MW@yt*5s;&84^c=MrJ2O+w9J8Vc6PHMS z9bkP0fvu;temF~lTabnG5Jwy{3GPSO(rVDGTnKyoZZm~-I#X?T+hE%=xMpOQ&L}CI z@Xc#y|1ixqrRrkVV$KSSOn6M(Yd?pV#t|{1FL9k?NETbhwVeIOO~Fg83j22fQ`2ug z=hD%P7oJ*7V;wEg-g$?jgN(dE4OmDCg2NIO-2UFFTXr(#mXcSL2v&+k7sv$YXcSa^6T|dPQ9Sl8Itaf_nI6|HaY7C!s03;q@LdBXLDaS}`kP1~)ORRbGO)LgqB( zo{r2$TihX0cs|x{b-=sHP#AZHYKv++r7YjY5ia?$y~V{v{+3+hTe~IAN0v2}M$1lX z*_4LCeMaHYh%6jyLT))H)aHzJTtER=EIX2`57S+5S7swS?4uDp>1rLmWw2}dp0bQ) zJ(=sO@-T(wjfkT73ZFkjrzxFpoFBDMZ?Br`n<+?+W$Z&aAm3{BuGb;^Em zrb*)_dm>5mNa{*4S^&Wj+L3u8*AzC>pJs8YmgU2G%y&~+_j_dGSJd_x@?|PXbpEEuGZ_#UV4n?O zYO^jJ4xT3~3zraax0q7>iUnEM*XdtcQ0b5`h+%MRHGJlQtF~sM5GFe5!cyx(({FC{ zRN(nJYzicg3F{Iuw^j2jCAPxG?P>&>bx5I*^vj2NH@06wdOTUKE%4s$s~_j7lZ~D? zad;QV0!vw4_o{-XHp#Bl&6`J6&vCCfH+t>2PMo^1s}Sd=+ibDOV9vN}SjstR%Ucp* zWjz(C0NA8y&J|XJGT5y4LTLq+RZlI)e#g!AiV2wgXSwSKQrc&BvwMoh2|x5=J)LWd z?Z~~ooxB9f#H}HYG)TGhc?!CPlk}0;J`Z%?Ag9RcUBbm+BStkY=Dn~ zKG$nXDo!7&`B_$!(S=n*Qxd`rnV1_$7;rPPG_o`adRJ!eESr%OEF=dHfBZDVbZM%l z+V9kDTOZPmYpu5?$g@ze>d`8*&Y=hS`yMw?JjlT8bde=$1NBQympi)D)C3L8^WS^Q ziq0$>tz0ah^Olp<4DQr@XI5s97*d}A`xDqW^wgh0$*;k04pfN;a*@q!8ron{%-X2* zrlnJ|*=f^r*)euR^2=lSvS8d{0Jn7;?KK_z-KXO zwGip|+$5fLww<1lDUEztRG)Ha)oMSsp~RhIm(t}I!4j%l_t2RAG37^@a+#Z-dbJpI zgnxLd6MWfwgc>$E7OxFdhByUG_IN?fn70lUnT-D*2vZ%{?n5nKuO zr+yB7az|z6TIS%@p0w0Da?hm;7})%`%89GShS|QlS*BCDPswN>u4HC8EBb7`Xq&^> zXAqq}0-06w#+CH+D&n2t)py!?trXYB2MGb&-YA&T$Q3s0aa&a3B<^!E;B>?3-zKa) zK=I7iM69T7%kBnU7_z2^6VLRd8d3C+)xg-|W_?$B&bZHtNRUDb?D)8EW5kJ%@Y;~l>=3cQ$%ZKM7`L6978CyNQJ_=Zt zE(giGJqmNTsiLZ#hl&T)qc5rEwg-Yhqe}O_n)1*m2~0E|s<%|7b;dUru#KoTnBt9pkXNqcF(o!=YTmnCy5Ch=#8dLohIZ;I zpX`v_sI2GQgJyy|vAIUstZ7}huR3z;lph+qeWp^KTc>HV28@NIe6w)*{p{(z1Gn6g7!7+cmsgI2NuJ!`fcB{lXRc#yY<<2#&kbTygK?zV2F; z-@c6-J!d}df2CB&lgOU9{lQ^B?~}^8u?YgroOQa1TeAIz{tmE2gAiQJ=^`67d)&jT zW%3XFqvo@EsR!I<2bW|RXaZ(}l=na2#p}yw1u=(BCG7=8H@)E}Kd`)_Un#lsK8{P7 zC)?Kd5Si+rkXFIix5lzLwNw!=mnA0aeQsnk1N89pii*>XlBK8@ul4qH%41o36wRdy zi`j0-D?aP+#9f2Mm+yBElNMzS9?Go26vm9Gg^kjsC7WWyfDKsG`m~mBp{u~$tn|^p_C{-y>fpTq`oZT%n@jzCs4_N$Ka#CzaPyjY3u4foEtKC z={?(TU!yPT%@r<;Zujo?8oUZNCER~sUZr#dlJq&;MA?lPL!82`ndP4cyf60aNG5F=xi{s*wy2f~NZ>{*z#%=>AjCb7K+7(%+)d2Kg$LQo(YmcY0Ek+MB{Y)YxJ#{bm*$9K40y-D@Yh{VY(GcW@ZUR}RR zzM0;du=mRD3Vl_zYL?pLX8towme|HNkps`_0|SQ&_LB@Xy`Dqd&u> zZ{O(}ls{@CPNV>ESLHk9UYw0SQ}(tKpbNIM&W}! zx8Il7&rFo04m9=dc<;! zdQeu%)g$m`vC3_RlW**vK9b=B@5Fia)g#c2Kr3ZtCsO(1t9pa;Ju$cgD;J^X-mSww zDU$om6<@WW>ul5ZiHWZ*xu>0J^9qrety<|9XCjd`((s16m;b$u^K(tR&@3*`pdA~9 zF(j18bd$WND)$@#;>w#ANB~NevzbzGNJ;Ugo3tM>r!7HW_JHvC;0VFY=_3#=Z`_ki zVxl4ZE}H(K5&3B)0~-Yx&Q&Xw(t+yM*P5z>H#|M7GP0D*wzsJs8z#vQTT7XJ^ykxW zEO{0fv`go%zd!OmN}DhON5!?hDNWEYV{npMbbC%2OTRF9+CU24nB#3mmuR4f6>Le< zYBbk#ui2bjTXYDwrux>|!YQ@p$xD_y*Kjc_44Ow+ZYCdr)aG+>ZoyiOgLaj3UEm+- zRkM?$LvvaMx}s8^zHSVw7BQAeDwyJ`P83jQkDiNsd7DzLf=Ke>lJMK~38Jy^hgoMY zy~U~~Ph4UE6YKXho0NW#d^_Ke@apWfYcUr!R{6>aZ!f5e`S}tP(fNCv3zJP9YIA&M zDqq;CUA$ZHMr$P>r5WZNy`1rQ*emOKur!FMZ^|DrOyoP!twPpMRV+%CGP&Fw?K2E( zJ#k?gg3HmY z8M$)anJljyPh+U7uQSr`?)`n|t^xaGrWnTvmiQ<~I%k#*wwOW|5n+)}Hz}Ys5`Y^Q z{amttO;$k^>~GU^n}g5il~D_WrO0QAdEeLJx*qgR!5vUItCDvU{rjNTg zENL%4O47lfC|B4A)>~uW=aD%dB$5ifOZ`oTa z_-86-7ErLxItH713ew9$JfzaXPPKy{zPwkSlf-k2EfZNz?}AV^M-g0GPDB#C6l$EX znoZ8k<(;0(H88qb!w;O8Rf!EoJ%cPuOMxxaD3aAK^N+_+d9g9bfaC?O?(fPQ!;K6~ z;SfH^B2RmMX2FB{yho-l>J}pk3Bws4^X4GmA|V>FN}Y=n`9=N%%$43D!vQw(RgdJP z)I`jN^wt?5;Z*qe>krIRU3)`bBD3Y!0v42Ev3J|AKVjeH-}PNl#R(y|?J}}HNBdqX zA)Ev270YI(?E*=69(VrfQlBUlhYd9)=15yj6SZeg?uj%^Z8p5R`ZV{6i{08sgvfh{ z-%R?`SJRL(>4ZH$vWtP^II>MQIRC`@=V_n(j2#Hj#R?J$qkbk8r zU~wEms5lVqjk&VsT!YT4Xw>X6q;H#ldE2l@ww(36d0TcRfHy4Y#v1>taVU!k^)gSc zAy!O<7PY-h%be`;D+1~Bjkm5TdvD~Fz9nX7lcTzbhwr_hDBi%4#=0)-^U+x4t_AbW zN4B>a+;E+jy0GtOfj|#22J*S-4duF*U%Gxi$VSZqws4T0kQQ{&0Z#jyQeix(ISrmt0trrK?lov||y5$*7i5u8)-4XJqQ zLeUF*oKssljKGTAJ0!4+e#F_7BYqxQ$k7P)qAip!2uQm}c9WDlvvE&xsr$*;#^3>* z&Y4p26(Ypi>-5cmr25w%`g3E%{648aWkea=oYvj;+}O&McX-8nHPbBR3;yG)gVk&~ z)XVave+~DaXlQ3j-%($Q8Au~5yZskFQ zuk^)pF7b0xLDxPO+%7R4kVL(pirwrmU3SCmL0 z@nhpzsaUlkWHB-*U7OR;enVDRHd6i?RxSarA85R!=3HT8XMZj~r(weeki$;LK~uZ~ zMejS-IoE=%yj9iwpPD%nMp3pNZjOE;;htpC+#tO>r{4SKLZyIIPBs{|uxdiP!6VIH zt0smVeuq*xH+i8YJX?~co>0w|f}(4RTb+2@9<$_?E2Zry>2ffip4^vqBD`txq7>cf zg+AvlkLPxEwoRi8H17=7&8Zr2L?-z7{hDR)=B2jduqhU0Hj>`iuzo!I7Dg~J4V&Ta zy&HF~5?NyhiExI!myOS_;)Wl&N-I4Z`k89^4(<^;1-GIb2VO z5?cW!Q6Q0gs;j)gQ>U%r_;51D$qLmHuyFUmTPV5wS+Wi{92DQKcFnK~nXB{VWM<5v zyebw<&!JWV8Tq(_UVeiyc%w;+2ky2mB@mY$TlCL`+uwCMpJA~Qr@o#bN{>j=()5ss zF$_?pqJ)puOlU~Qq^TPP?%K~a?Y9jTxk+gxd0fng4T~pg(Lzb9_VB)Bm0dQXxf9C5 zusL7UrT;Dn&pBBa#va&C_u_7IQM%!1X0+c@=kG^#>WQIwx*ir_;JpiK_ocQ=y=`46Sc?_*1rTf;F_ zBDRtoS8>~3=j|vr#hj-fO*(RJL6B!U&rn@*pT`8q25G|@|Chr2Nr2)IMsX8hL zZWkd3IgUW}9u-aPXCLH+W__GINEDGasaYM@5>9#>?a#g0h*hrHzYQe)4%wyQNhslBnyN4%?Q+^C zt3&z>Z<*4v08`n=+sjBYyOPb4p(0TWsMu<0KM`f6aVyB+!N9|dxWo~3W*oVJ9^69lUc3uEFLJt7D$k5eH>B6Hp%)gROT8}}KL!YkFBXd# z^G?solUytA(#h3Y%e{d0J!MFZ(TZP32NSz-X+y5M#Wdv5@WPN~%6~tr5R;BE^q)rAyhuN_Up-QMf4~5q6uCK7Iu* zc$?_)f|3+1>C-a>0e0irEy?ZA>jhmXXwF70F_SAu?CQ2k!Cp)XEtf`6B#IN0vy*%- zYcjgyvdD(rfDs)Et~U|st=)SRxlXK2xm32JUzTHg$3=%i>x&qVXfq!kj?GrIZDD%! zXo_Zfwi~Vaj=$En%vx^J?%8u(N~g9gXo8&0Pu;)ib<4`0m}4%oKI8M%t|Z z)>d2R-dA~}J*JGnMH6vPg1Ls7yUQvUF?zyDSsl)CIXyd=SNsHX0QUH9$-`YpwGy+j zYT?`d;@n}14?kGUcyA;qvjGmX$d%p`6lh$;#b-Nz6n_8E60D2d@I7?#5K|m)n7%z46A0U+tM(;+`+f4#$UCzpoko!`&2VaZ*l~3>kav0M36qjMxumL z576`(q8QIUjHcY3rsp&E-;8L@&b-+hQ^y5tMk8Z^uUb7jkz+K#)Z6H(%0b5?Y4+KG z-K6YN;1Q_E*g-Up+0XVuuYAc7=uPIA)o??;4I&_6e3RXPY9%~aCvrm*FRm^mTpWn) zSU3Xx9FcJZdQ`-J1WHIPJKWS1+%iPYL?$nOIs&!Bk_W-4*34mwYGA)^?tKK}mqdQ- z`1ya^YoBl9z7M~C1k&$X4$uThmfb~@teH0A8)N#!H%n`=8^4-&1I=@*kvp0tH6DPO zW`LRa)d)k%4WhDx_8nP(xVqYY19w;K71=#Wqz8`Q-^EReHz;Mw6Y6?n#sT4lIw*?;yq$Z5HKk*0@XR<516!8%C zG4r5tGjHb}Hy@e>fE zdd_(V)N#kek=p>Hk11E9cU(|jzy|CKA&PiP3%wxbAF{yvF)jUo`pq?fr)cDtG9b0! z8-uN`9G>b#9oFn9hy5yz^huhnmV6{ye)I9GF^&!>F91;YF9$S$Fa~RDHZIESZykZg zG?mdR8H^GLC<6H44p~bcWO{cP#WyXQ+vgZB(v=%N(6*@`<#}CzWz^c)&u+0_w+-7G zh5LD;q%1}jlJ&Z#>iNWusQga+l+tTamnpSfy1rm!#B6o@#({}SRd$@4ntPi$N%eF3 zs+yAFCcf3UOZ}oUUk{8KCwh|FNU&1D`nc)N$v1{huMde5J!ra#ExT;eF`>fN%7JSc zsNN86(}xi(Gj9^K8k+#WsKqhP9L6`ogS>t)Ulw5JW1>>r7(-y~AnD%`@RhIevw8EB z2$P(whSbWAv@0i|X4io=1JI5e0;`^>jo-LPxjij|qJCYr_!Zes1z4~!g%IC*6W>aZ ziVLD|ldtI3K?7j2@9oCg_s$URuiplC0cz1oMd=HWChA!0q8tO0F^NDI%e$}%ULmdZ zR$!tUimV%%zj+;+u%>tQmf|(#-g(-r#wbLQc=59HP~qub>Iy<)$Ec<2CX%9cAH4Bv zcSr_@dcsrPs7hsEas3a{W_QP`>DyoF!Y^KZmLwSx=NvL`qWh6~$KIgRJa~2nDNr$A zUFU4~`s>i!B7t{7Px$kgE^0sFQV1Fu8f4#>i~@%ohP>PJf8xO-QfP;B>ZS4(6icu6 z^K4-gzI}BuzQmk6OExN9g@r{oC^E?wDFcu_9&87KnN;hH#SEl3IdurJYxcUrO{NBE zcx0%QcuLAe2x-ZYr(a#LOtCb?tZnftOKHb<`1(M4|GGD{@dE|s^COVNM-lv?=)}B{ z(+qD~NHJ#W7wzxb>;>}OyhkVkhGkYFik}3>MWhj77%o5m{G*goqc|-U1#LU zB!h30l8E0EiLU{~4wGY3gg+lOxa?aE7=&SMxp@SY)r@5hxz`60!zx(r?jhp{JD}fy$3v zAjy_(P2`5kYny~T^{2Rp1s1E>L5|zC9|d9>WNgk(>?%h%86DOgWUNh~#*c5qSCo3t zP}*-CPUg`XHc5g@`oS7gw9Agz`ZcMnqBos~r~t0SqASmYc+Qskyi0o7?5+8^%}vU@ zwY03X%^Qwq>NJ^VQe^KB4D&mg7Y#}jei#OhR3z12GOCL(-eM#=otSB)RQVEzKC(8? zLXkIND_1}U1dkliKwaWCe?~>vRy9xefT)Z;-8WNQ4S)Rzv~%|su)eQ=h-&uf_{KmH zC}hLo?h$A)`x8y(mer!kCh)tQ)}5OkfR{$zK0Jkcd@&O_rUm$Zehgq9a-VJ`Be}mJ z-_5yZ-Tm}v&6pP7_i=!DAG-sA=mO>T%n_(Ccgv6Gr3-Fv_7Mo!pERO}*0=$PgO5O4 z3N@>FF=#u%LJwT~eITI4TJXbDHEX!Q4`L(%&D^b-1^5o++oxNeMc*4$t+iW&jS>aS z27Qf+Z>0ekDSAK;e2bS5fdbNn#q6r200hOm&3W{CnAbRDc9a`XURuZZO9l9JMgAZO zEJyU)a>hh!SN5JFCkau_5h&vAL!lEMG+K#VXtoIRlu;J%$l(X{KuiV(Q63LE0v!qk zoXD{Jms{TSK?{R#mI}Gje!?3db^e^*xEIY2J$_qX5#|i_QDY;PotX1h2uMSG6!HlD*TrL71la* z1|XK%J6(1Ne6_sLYbH$5#^b%veFTbGfdWpZ`0VtWoDc(YM1WZ0=;{4=LV%Xf&L>x_)1;_R$o&nz z`YJVl(_I6iL$neclheC0QBvwZa=~}}e)4KAmO?eWGBgD9p5SBvF@!fgxC56(<6U3c6 zHzi2Of?fyNTq_%Hci`c>en{&%V6qiyI6(0c4hCy<01QG{U(y;USm$$BjUvqo>;tePoWKLFMrM2oI zII<_RKPpePN+fZHB$#pslsg_AU;yYG+J<(?WBp$an3eS(^n@t{r#^wib%(q%$`LOw zqg=^A*$oY;`H;%)DCw2vq^GJW^-YDojP0NC`{2f7q;yv-H$d*wy_6PH%!>KgfX>hP z)Fr|FTP;^_y7(72U1;Q?!_^q(U|a7zH60Bi!XOOo%D$wZBa%9JwuuMZVs7Nh>ngg> zdHoa1ZJYL-Jta*EyZ5Mw<1v>2kOdU$#?c-VL4Wfk8i!O&uOZ4=Pjv71N_K? zJB*#vd`^Sm#x-}zIaW`B9%@K>eli2HP;A13L#ZQ>tKTwB2B49)hvsGLO2i{X5M0dQrYT6FT#M`29UarVfvul(+(crJ^)*O8=E_QtY19~NXUCY!e`K= zcY)mQl=tyS2L;*1i9X&k^<94w)Oij*fNCRP6{o2v*Eivl^p#1+60ZF6(bDH_KC=De zmq6g=Dtt537LCZq4hj#Qe@wsh?eoq9TI3iukU+*q)yS;oE?|9<^_)F6tXDlK-A91a zzx)N|e*2Jy7w5;I6|B$C3He2-TyT4`k&t%)pM(}bY`KJr2NGp4kV>w9<(oqh4=-u) zi_~o-2LooMSQ9zMH-?KQ@$?8Jvzn@fH4x%$bv(>eOM;y_l~-(w@Rbru_eH>4C4v{d z%39HYivV;D?+7Ff%*w85MZT{*&c8^qQC#Z&n7+m@6T(DKjMR*J>;(_W2517ZGMWyIyU`orfAAD@ zB$B<0F;8<1o9I67QUCu@E%UwL5f1%P2?PCBxpG|RBLox|eXDe12FfGAoGf5C49>*K z3Im(lnVM<=N@*D_%{sP#3*?<+9&n?84il4=;v@2YnD6XP~TcR}VLpw2$af zRJVzwI;1}2WmGkOiXcL%=o^M-zr2!IxMaj%#N)c>`p(ssV9f6Pkz0|YZG)n|Z^w;6 zSEHI-QrVY?m|>r(5O^NEUDIMDkJn67zi{-!B=$id0c5{_yg%*8EME1D8FF`Uy!LkV z(%W|}*tgyj^*cC9onfWE!>EUGIrQsFz_aaVWrr(bOwfG-Z%i8M`E11kkbz3#sv z7jQGrvau0foX6A~B58KF@82J-l5N67#0O${uAQkWm)g-O(GUGR^`&>dP|Zd-0vSG| z?nHj|VFg&Aps&uiv@?Z(CR#91l!>Z7nmv18ijY!82hUTP^EOwz!CPDj{5NN-o=%NwUCZsP^R|lgIY3niUYQX3yVFM0B`$%zF^ z^7=U4Px{Df%1YXP;D|lpVlscpv|b%P&``UZ?NXB0){TuxU;5I#>*c#z21Qc~1z+h9 z+a8h|`M0fe&VQ<6fu-Y~4K=*(T0VSh*7#Mzc?pk!-!-mpsI)ckatF*{<2^xO=C$YYjg(Lml)`*+={# z+`iao!cVYW_Jd}F%{!A|_NuH$nqRYM42_;~x~V4!WsldIDVAq9$Eu%xGwiXw(-}7U zb#uXw-|QfGXG=-rD$N-pU8pF>;k1Dpfq#dvUa0P&v|T=gs(>W#RGp0+Pw5{OFVyaa^l63N}4R?4x1@uhDd{s*+f= z>kTI^YHX%jUmAP;N-mvM`W8f_!M%QB31&p^2Nlq+#y=GEPNbKz=1G4+5ZdSAFlPTY zH6CTZo83G;J)3Tl@JJq+sCy|ysof}ew<_qI)M)w8d3J*{-bYo3go#bVmj+^B#8Qa)JJtdDEA#jO?%pDuaK8(eNB^H<80!Wcx*<6v~ex!@#K6t zHB1wPqTI?6?Ed{)G)wc8w9^j)1+x3jSU=T=eH(c-RNHKO|4XCy`I}oETQrMR-M2S) zZ>G8;t41RXEkR9V_b!m#ZKF{NZXWi;!MQJu-AeXm#nb71@gB15HA*dP@+*1QhsnY_ zAMW7xj7>7ZxZhX7J8m@kQq9A+_x7hgv1yDJtsKNrNSAh)FyU^aCgk(yy$X;Z9_X{>wV_Dz9#t+?vBk};;wD z1^ynF%>sYX;S&A%@eP2#C!r1kgrSqq(WU3;>nBkUa@;8dcn>?N{)NE4(K~Jlg8uv) zJ=iyTuy6E^`+1KvR*EI{5E(lwj0p~b{u8!Nx=H-X)~`v~|Hc-K6V3!>14CI@ zm|$=KP!JDRrGO@6;17-^d4QToRgF%@%|BtlD9cZ)w*dZqe6DNQr8=z@$IQu_g>!hX4 zuWX^++xN}H|0XRq7$@K!V1P>mqy)GuHozVs#|e z4lopgwnr$K4Nx_9mVe|PPWtQo!q#yx`IpjSVPisfiGaXiOb{5D4FY3gf&3$l|JE|= zSGLfx?ccG*3TFrW1K_q`tV|q0Ok@RApAGt7#ho8M{-oQ_uYCP`C(p_T=sFN{pn%_E z1)M!Aplm?Hk$grDz?_x=rzfMfrj$a4Uj1$5#CB=i5sL;NNFd~f&n zFZkl%0GibR>;S(axww^%>D^i-+ILT;v`sq4c6!*(BrKma18nV2owTkV&mZa z>q+MEX7M}xKTk4&Q%nf!$+inP$z%n1J=vq7Pcr{}TFL%vqV?^xk{w9I|J&2bSj86W z7#5=8b>c-lR^g6rtVFYQ!TyUW(&l=%@y=W|9e3s$5#wrzu<_5O zTBSw3?d?*QyU?1-r{UZcKQZq@NKSU0d~?+y)4{$jCGV+!MLcf_GQd*|$DPaNbQ|AD zYJ|g_+fL-j&JAs$>{Dk+eWPG2(BU3?t#EGkFr+hKKv#UC*VTZFxtESe8$vyLP@gZI zkq8`UB^jySc2XB*S&l)@%3|TXCC<6f@8W=-bA~sL-sT*ERIOk2vg zbQ-!tj7hL2T++Ny@?w;o9$tRr;&tU=ixEVjgye1mCzDu$4OzA)9S9N*lBWu?l)$_* zJsWqYeAvc(`ygrW5Zc}Xzpm_Q!%G|UnmsYJUnd1C{|1SmEbg_3oT8hicM@*T6CZ_M zy!=f5U?nmcb!}*mq~|C-aIC&}IpK>^QR|Je3FFQj_7~Uq9^b=Jtj53IIP^Iu+C1E; zUr$Ol4A;!dz+;>M7Wn21wZDzRCVOg}t%n}ft;{P=yJ^d`131IwaLZ`LW90H~Js&oe zJs{mAh#u#mexkEgRcqxxKkK?(2TIm`0}HZd)ApNst66?@gxCK@!WVOxglyt0P37Ah z%$r{q$aLqmC=ZtlE;)=Yp7I5+y}HKNE8J=OcAKPu>0Udrlt!PEiwwfwHg;xVE?`TF zJ+WRO342>drgg2Kcr~`mH)yMS$oh?JV0e$iBh}N(6b>H+g`a=+)}<|2)m}qlEC}gbvrhS-%o0eJAM9}lbYiOpTJ27{M!i&{M!l3aVJmo=ig3P0NX>K z%>4G1!uRH&|H6^Mp+FNcAg@Pn(qJ5{U^pufprHRKAbsmk`HL$%Udwln^uKL~*g1g! zgbqaC`Cswl6bHz|;Qv)7{Y$gVUwQiX z***LBBOFcuJ0M5=UygA8l16{;6Z-!lF03mSh^*w1l9$Ue`)2tt7IGhkB zmjCGp2l|(c^?L)~V_~6V_pvkiC3gSa*O%WL1s_lR|5fb%-jny3=(pI-$_jj$dHnd< z$M5fYfySz-LoApH74hty^BV4CZs0qpyoQsqvM2J$R2jE4Ew+l-DH zhFeK2REnF#F0Z!^dpq-_QR&#)IP5SwZZ7*&<++#d=O0ciSG^D;Z3-shdQa_V2iF?j zbh|p~+t9b39`glt8jkyEv??ZWm0_5hpOcEMg+2XhkQbh;zIz0m(%gM<|H5;N)fcAr zpy%~MDfdUcQl8RVGe*}@C6VGsT3xJvhUH&$zVb5`YHO%RJsPJwaj;C-uAblh>yxzF zvk&i5pC*Y4MrydZyNAv&W(a!gNP3Hq*c@^w>@QQbn~mtGBPOF~(!y?QxMvtMJbIU1 zbGUR_0z#-cJfF6*#(377uZ#iDx^rV0#dmSzeHLFC8{T9aUJcSbpu6AKZGX>Ycy2|T z=uOtVOR}^(@9bV#-J9I#`9wv^%TI)8T?14I=C)ZTFLUB&ReDO#+BYQKuL*cu`nf%g zOI#y3qiyDLeHOCj2nXlDU6Pi-+^#jdW=PuENy>TW(T97p%n!NxW(+hqn%9yf+ZEH# zJ~lEAC}G=?QOD!qgCpY;5%|dyH#BTdr)zwzJse`w6B2s8A}AYwkKgb#Gw7A8m{L8V zD0b6(y;JE7?;jPMp1?RS-Qz@WSCUK2kB!5((mZZDe{ES&Wb#dJDZ{xqGSvmVNl|UG znhKZw>fJ6649dA@S#e-)@K=iSSo!$(7%BA_+g;YzL*uJncezE5iZBo! z%A}xID1u}K852Gy7EHs@+rOh!#WU&vM z`1shb6F*x|ez!CrY4B(@CgG#Z;FUf10<17g2DZTGvX?TP$`Zth-?De%JZ0%?6AK zHDos1jSGN(1?REC zNZL-(kt}PSU-tAlpQ5d#JZ9|2Bp3X)m`|YL$zF%p!Q{Ml%AxbUN;WO5>h%Jwh?mBJ z^^ejskq0960WoQh1V4|CQ(BQ?uyW0VVt$i#E3UBY2>)CtC;-MKXrK# z=f*9w$VXGx@d}=Me@VQpUF|l{km%lXfoe?XgAS2jl?box`8>{EX^(apje;XzrUs{+ z^DIM@8#0mJCX5LE2Zw^#436Oy67dwN;iXwRofzaPOv{kW*-tMNW>4L|s^V>tA%3n- zYUk1CcwsDgiLY9n0fm&8jaBK8ruyV-nx!&wQ-~oI@=l6a$!_6pSfz0IMMe|%VLp?B zkdN(Y5>hyrtp0BO*HUu18=rAgK5P@5h<2dR9^!ZBWT(Ua|9E@ru&CGX3lt><>F$&e zB!;0uIt2tNk?!tBK^l}+q@)$4JETLT8xf@&1d#>_@xFulJ=XahJ?Gy0hY!ynpP4=T z&AryzdmC+>?M9J&n0p5s5ks=TL{S~#(OYdsrmo}q92@tr?%YG6`zr|a-3Huh58>{| zWwO5BX*AaK7*S_fw!u8xr^Wt3d%h_^Fw>c1i+3$Fx~+4X@q^*~CiQM~8=4tSBpQ#s zc?^FiwK6x?r(Uizqz4*CTC1f*al_+zo>`d*37aETIafU_7TPq`9^ZdgJFsB4M#$N^ ze$)DamEk!~x_Qw%rRBXo4wAm&ey%ts1MVhG?l}xH?i5Mb4~8YZ3{&*OeC}8q+7n38 zDZG(ti9#B-6(gqN3?7(aE)4@_#fMj=s0Wk>}}M>9eS`(L|%O1Q_}fz zdV4$$r!;{bqaG?We|V-!StBP8bI9z8l8s1vIn^qm(dZpvdr2DRh;DH@I!m&wi^XqgmBq6S$X$}^yP#isE z-0u9|_fpUbMT1ogPm>#D*6)~lJ73Z`#aYJH+S;((uL?IJvQTp-6&t%z8L!5Np{(UX zQZ=&O?0i0&*#8}RujP@fQtqTNgB9h+Ws;+Eb^&$xR4ubDD6JoBA!o9yg7XZLGRhgT z9k1ngDfCwiUIq^b4=^_-u&i#+^;hn(sjrd6Km#l;9&hoTc-3F5hS+k+JQYUix%G$}!IYS*! zoirDMv(J)=UFpUxyp$I!a|YPr1`|hsdpBxfG;%k;H=qZ`qgTQok9}rq(%kKRG zh)+CwYu)ooh%VxFlu#D_3OBSNWzIKo4?TMs$+=3NVOkz=U^E7fcWr93-?x5K-XTWO zB`KA`t7$siU*CO^wzTsi=BvgWrfITVvPLfTs(3d22bf-inTq`7O*c(<#|SNpJs-?n zka%1?f~DS?i#n$yKO21!*~5>iR&o)Ft0UFL>$W}egv4W&QAihOyo;lJ-XK+MjZ$V z$9kx|youd%N8a***#{*8OWY?3Ch)fc13djYfw@S)TqIy_5HOb%n9KbPnClNSH!)`= zr$%3*YBV%7L?-KYyHqRY-KTfjS&(1iWNh}xXI*a)6c*mwQL+fXks-M~blyLVsUvpI zf2h74g}Jm9g;KpQgt?Je>X{F77?D8%XLIP~x7W-LpFMna6%tS5YT}L0LB&Qb*ilPR z1koiY3Y8%-qb1iB!)kZSthuNvw-QUezVBn-A!238VugK4SQTKnML;97EyZKywe39Y#;-iNduLC?{#iFQ93_Vg`S?E29iq_1GLbgil2X8J0-aHVzxl%iL zbDV*xk*#YQH{U=xx3SUq((l|JS8ojsd-&KvQ0f(_a}gD5uM@UeOMrj(+TcodV^8~| z3CFRK2l&cMkU&0}1Zq@FSs9^XU_brcXw3_Ek*%mY!ACG+Ow%aqGm(^VJo$uz{rKbZ zeb!+_gq!9i6Psa(EB)FJ-erF*H)XkdZeiRCoq29J_(ebcvJ9nJh1ey}_tTgz)^VF6 zQxxo@+_t2pO97Q*$@&&W!5(=W4LDBBDEzz~Lv?vQ4_72GZ}Q636qEbDpG#gFW{Nar zsx7-k*khshIQ@aY_ z9B}Dsp!hbVw5Q(P!9HZn^q7ST%ByXXXghj_YXf$og->E)7p!is7frW9{>rxi)c@6eb zZ`ne+mt5tM;Q}wMp)Uu=L(^o>qP4l>jnY3|UX50431G7`!|ds@eo2#St&K$TnpgCp z(VPzuRg*Om2Jm9;JQEM_R_VG*9$yZ9e_}GHt%&ANDez`TL$EcNo%)W)B4-f(rbR#- zYm7;ORAlek=;dg;6l0+`f}Zi_DRUYTb;zN{Jw!scV9|q=U7??ucV0<~j z6tei={M0*XK@(96MxJQPv0NJTi0`_`vK=wm>Ap!E4kt`H)0gZmxVy^V6)kR}Wo;=; z_F!I13caWMKw78CTrs=~M=U{V*iEeE!+dr0QD*_G7xKu8BkSa_(Ac8~L$hyPVxk!n zxl~Xp(hg6KKi$sPn<{H{dfZ(XGNlJc0d0&v8BcxI;PRe0>!@unezUyBI71?;eKIm9 zw4xlHJJMZedcbSoRbY>Tz4U7oFIof9+p4Zli6ziwe8mLF*Lu{9FK1Qz)18a#7Gv-T zDT^1NDGHq4Yq(It;)}iUtT{PyY_!5TAd3QTd#<6ajz7_eGTh zfc?+^|K`ew#an=@39YcPcI@(3AiP(WwFe^lIVa z0(9SRqW7?_S)fOc9?;P`8W=h2fxcWns$Wjs^xI$ntXBaHr@03DB~WQW0D;U4{0pPq z*@3ALPHtc_cnt^|cJ^<0H8z+~h)q;bkPQZ8v5B5G5MxteQ@bV$`^RYR>}=1^#^&bc z#tPauxwy01Ihrv6jQtyk=X4l<+fLY6vj5Lcpv(f24nU0p)dB>d1ss5jg!L@pgz010 ze+v(@_}s|mC+~fW@c$!7_k;JiAwV?rKcfJ{2FOXypN;wh=Y45P0dpT{P~m24ZD(N2 zYVK@f{i8GggVf@G&g2F(I80mwd2CF3ZDI#P3qWXbfMo#%=o=@Hr*M6{Y^hGC-me6HW?!4t{b<&I0AjyR zEC?`%8<1`gfXH%!;{XCyDPZe=XJ)}#4V^Z;`_ZibptAU%Szx~N016NS^c8$S0t$hV z^<3X^0O0^gKhWBq zDpY=tt@+&1>L;WA=n(jE-vZkvps8T$9d?+w2+$8OK{0Giva|mdB?1oj(XFCO)%Qw^xpax?ZC|ogeUl(pc#`qP7_m+G&l#osX`fG7N4(iZ3t#Q`+1unX^Z8C-uZ zf`EK&*!C@v0)c5pf0IZlPt>_TR)HV1zOS*&Iv9qC3)d96Q=mX55I#{h+3ifQ%N zmdB)gfvJ$Ep?+x^j!q_enwv8rS<|1wI?Wd=CIA=Hikc*jO11Jho+f7xx~bvYs%--tL@e`yjivCTU*BQ=hiE&J8#U-ynz1 z>VXpOO20d_?V{`<$bOXDI$Ekrq&@7WG{hE$QeIGkPmaUk<$7MKbU6(jrF%D)dctot zYf|Cfeh?n62aSePf?(D8=zH5f>`~9sPfmVYIci^i;`eFm@Jh5@zzyMqB>0b)g-kDH z?hTJDq3cmPZNKX!C@Fl6ch}drf3q~q`OS7nR0j?9wwMqVZ8_6r&vH#cnppa`BK_jX z#5Xg85i@q&`rBVN(_C-3lvt6I+UAW?5HBaL_agt!Rh^Ca7qYWCJdqEi(x|v=mrbUQk1v@HqeCOVFRntB|ry)-e&MN!6t8;<%8!m*&nHj7KU zKPw)KY>_A*0*hfn?U}97yWW(JS7!NA4LR=e;SR8bdhM}8YJ=Y94JoX3*>!FdL$WO^Ap2m}k zn8uMVSVR-q%8tBS##sJlAoNab^aqq5%t2-0F3T)gtZXk? zK)6Gp9%Y`1t$r#{KEEr_szkQ5j;EI|4i4_99;Xc7q*U@N<=q&W8g&=Kq6v_6gl)k|)Z>CCgr%_E6?u#kbH12#f%*jQNWY~$l!+znpbJklE)clVtk7$%X zPE=WxmIS0UDu$ZI&-w)x9qtXEzUB2#s^vuTczY; zhe(a(+H-6Oc{yrC9#*zCwWDG@laRp{2BJ1RBIwrp@(^{t*OH4(ysxoA%ekV2y)>pHiW_YpmdZm{c1b*lXJ{nHBwp=Jn zknZWQVo=}>Wa$?A0#-18SL{*L5Sv2? zQ&;+>p`_^-EMc)UGzH`?X0`^`vjZ+Ve|l|`j#~4k#<-j>DyS!_K(n~7=W-q|WzG#` zpI8ETd(8Lo&zokljdgjZ6w%?LmsJMdoatZc!-O*`<%JWx@ez&)4g6l(-oWZ|zxHI} z&0%RtezTw{Ybu-sMGrUI?Zc!8xY&HAvQ)J_`Zl!@D8!A25*TEB1YUMyaTGgFEV;;u zJ9=9u&o%3w^j2{-zY>++WlnutZLzwFp||ml0p2>Qh%Rwzg!f?k7V$&Ldchk)dPYr5 z^<+&K>a}|aHx^VV@$ak%FO|Qo-XA`>k+`9xGuBnU)_RnE(*!ZSF&t|2^g=zo?~8!K z^t|v9wGQ0txb42VpZ1BP74;FP9*y0sv{a$%pfku$O3g_=*1VV3gCl!6KjJZI)46-v zO^El961(U;z;_z-jijhp7F8!`xN3Jl&=7}UyM9HBv=E*QnH(>4~>o zMS|JC{CLK%=G{^?@8yb}gtO=4QG_q0ITUeT;Qe5O7;5mOl0YP-`awDZ`L#`GcqI)= zjK`GQks=i3Iu3ll5@|x>eZJ1)+LG*snqX4n1{aF{y2X^I;b_AOs!4Y%Sh>d-QC{iU zGX>nK^q71{Vb_c%;m=NS2#sJhcARUadUifkl zYhG!P8so*fzBG6!lfRqq?3KfQjR1K+#rsm|g?DK219yYNee8!9RY~&NNIGqD#ILlm zly`7qIttd#tOgDGBc^W3u(55A#+ru)p~jam^Q)alx*`n;;Qlo8oQ*ymGgz(~G~$Ds zzIMnUUR2+Y@qFD#cga2M&Re5oQ9K_HPg1|};Jfc%RUKRx6R@Iqv?4kiv!-zIW|sY9 zgA%8lDgv85r5H&oI@6W3y6Csh4yGe?3k}c4O<8`FCycZ5%1$H`RCB2H9vRfpx?74f zIh1@=EI`vJf8*}pGckt3nP!PJl0#~{uwpef#ki89Ok&L9awtt}cx2V)o4j3}JqJA; ziA}l3>_Mv4yj1xgUwKTMibSBjsE|0nqmKfw;y2V!P7>`eHJ`?@IVjTvyohX5n22Ob7rzjMLSJw*#>ehqn zhuStb#tN@AN!)+DzF4k_@LX8GN)PLP`upLWlku>g0pqLO!PWfA-1$mW%1IV}GZW_m z>Sf&;bF$tNRNWO{X8WLqyoSOxPzg^{itbp@J^p~aKMtM+d&`S(XHB=r!IUwK~C zq19%FXlQhbYDQ$Ws&Q5cZ}ytko%IvXjjZeE675_Un{@CmGkkk<=y14$;sV`#P-rhP zRihHK0xxG>?)oiM)&6;0yUy8|&DZr_Ue;q>m4$l3LP8vzQPAQF$O zR`xHZE^DLZt=Wv1hWa_*#gK8v5lYwoNLpA7?|yb+nEnw@8eLutGl@-K5GNnJy(lv0Fyo`RTJ2!@ji!TmANm7y0;bgPV z9=c4kVA$`I|&Gwhf+n3CB%JO@PW{3z{ zWJ+{#(MUQ!?q`0iCK8iw%)pXD<4olq^YVSC6X@l8Qv0m*ts9bUc-p1r&0Z=po?1UY zJFS!3Hw4lJe$saW!QMA9&u5742TcF-eg8X59|G_=5J~)dOdsS;orWTiF9j`Ncq1${ zfqd=;41Rvb?jffYFkrv`jQs-y>C4}J4rM@|#h2G#-tS9Y3drX+!2sI%@;;v%4gBJ)Q0hkICj`DK-7D8hBwaNYWxXou5{cE#6 z=jw0+DLxz$*~JMoOa9Tc(<$^{O#_)>APMCZ3+DkqDmMt=e>2e*W}CBtnclB$ zgH6Z(Y8wP(S%BOkur^qEKo5FuPCnM(LI+`%xq-Ioj>dmu+_zxFznK4=ApIRCX9c3l zQ#1z(=07)B4-lT;%6$4l$N($<#=QRs`GN+{R9qkv5nyo;Ae#o+!5~o?a0z_BWu1|o zt*M3CPjl_R;=O=lVl%`eRQPgpNNoM8#T0PE!eG!Qr`V7aYS zTwo}9*ni6`_rI~~KY_iUw=yUgI~bY@0c(>7@W)WVn{xeLqL_iBk@-*K_br0?FIFOq z8ij&1O~4*-!ghRcDnh|e?%zxGvo~?H20b=@GU{7&^j{jq$qS4El=o@IE!g@w`2g4P zdzrx22DWDAc5cpgKiYMA#Q*l5`aNUI0nSBUfER-_Tad>Myah{$1oda`aazvm79 zFkceJ>-_a?zvNtiTyV z@&GDmV>q?W=aqiujOS~|aKwqHM*_E&MyCtNJ}ebnGs6!qPClHuC@{&JD-`Da%whN) z(i5J#1IkLC%Jn+?2cs7Ag%wu~J?2N#mkKHlQeRCJHds%6Eb-F*RQ|CH6{k;e4uQLw ziL%Xh(x#>k-*H*`+4dCA?URK($NuS|aHAuO5>H>NHrF9%m)dhUO4RbhULM=-+v~Qe zjoTW}Xp(RF^zRl5`!0RyDs}JmEHWy;mZk1oG>!`)rbw@4p6NTr!j$XzF9lL8D_q4_ z1x}_iaJ}+`(j^UMWo{;pV2eiZjDR-|4=CDzsc=L9> zSwk~lyn)PjjQ~APV=AfNg7LxmqZEVJ3QeW`D`LLzOHW5CE7{oCDl$e)cTWi1Djc-D zS=hn@wA}9$R>09|7^3RV?6)L7c^%R=@nO19b{aj!Q{$pAm6|s*k^gGq$;4n#sC0nV z4RVQ3Rc+Oxu9lCxE!|{FhhDGl)fUxw zPglGPr32#+35%zZgesC675&r3#2pt~jfh5kFKqZ+xqf32r^t?i5H8srR27zsc+610 zOKCuq#;PC~;vgNpiJqdH*jamozZEky=5ki?Mdy;3uYQm>AKn|$Nkd;zzJ(AoKGcQ$G1UA^-kH-Q zEF8pFWWeddG(hO6)bcOIRYz0Xt@pH)M(gsc{JrNXR7H4oXsT0j?S zwKI8~H&EWq^@z>DMXCWViQSWOBgMSoQ-p(P%=4wuiFJ$3DQ&Z^2!?y&x8}*O?vDkh zs*PqY$X@8*b2j8krMnbiGvcr$%elS%m?)+JC+6c;9FnYHB2d#-a% zg<1;^vT$UY5F~5~^|$UKkM7W1VMh@9pn6L*vMxfbYv;|h?yS;FwJ};I`cNAsRC!bJ&0xdL;0Q2iGt+IJd;6Ymq-z?J>;gApn`GL0vniLE9!?2GOw%xhRKs z;dtS~Q*{?M5r+J8!MoI0f-ll2$0m;r#^w9A86*n^c`%J%lcp;~oAqDj$f-k!n0poZ zSm<6(vwBOU8uKhsrxKl!nyx-k)HRHG7OPDW3FBhv1D$gUUbL=v^7`zix|EkEhxM%u z+VvJq?&hgV3wSMZZrcrsh1jox|VI)rYvRw=8SWR z@sX@Ka#QW|{Y5j2SCA2R-R6~$dblM0YD`A{4Kblj_H^6+Ut`bG zrP48=uJtP{b#QEN&od_E&a>zfJAzT1-+^1l;CdM^w$HIY?{2Jic@{YoyNp+%xRBlw zd%`9WWQKU26_NAz@a#So6p~xKD1>%BD1~DhPe`aSwWwogEy>yldIs0QQ?~abLHtk; z#k%3~P3p+q(S|LHz1seW48$eK_Vzn4Z{C3c+XJ8YZWrza--8&*axA-?b#mG9Gd7)O1MAbRp|D%_Qix;ZB~6^);1p%?L9bQ zm56b7CBxO(s>^X(QV^v27!Gy#+?5Mw6=fL$LNom8vuH}f2*WQga``z7;@4*LUXc)W4>mB$W)l(SJzJ%T&YRO zzP-(wW?WF+csAC-mt#5xZ3nKhn(=y_Yx1|Xl@s72 z+lTGnEhxp`^Buc-h|BwAj`cAfSWs8Nf)WPfa~rmxR4|LW(v%tNId$pOHgA*=tG#+M zAs&H9FR8A+su*B~JnF1BcxZ;=bt{c1{(c9a{2F@_iyMZZFKOVXseL1ZaK_>}T`ja* zlCC7kEAYjGaGD2$%WiO(k1btvu@BT$HY$z|;du(s58ggFFdX0;QY`*Z(TEw0Scvv< zvd^V@-+Mo1*5T|GO8OC$2(pO$`f{_Chv{~z6Yg8(N(}IdxUQ+R0vyvc{izbZk?wPR zitO|h!by6NPr{%VIOJ!{_ZO9>e#Cq~S2Tplf}QMK9F0tzs34z<9{vZ+_e&K-7T= zAH*DA13ETuQww7=6K6IHTVoUVUj<92-|pX94q`h#SUE8s5Zi$|IG`vM(7u9L9w?ST zakjq%lYd~j2W9LoE^c$Wi>YWUg-RJviw{3g8E}TFsT_AuoH-(AOJaq={~`H;emVu zxcz~h_I8d&F7_6-Ccs=1R)EL-XzsTWKP+ndQZn>^dnSL8-KFBBx(H2m(|H zK!1M<_r5Fi^@|6AA{{UiKNrmTyuQDB_V41vzYh(+iy;3rPW-O+(APMT3lz-wO-Whi z4b8|oZXEA*Jp+A8LwF-@*=YVn8#e|{fhzVlF0^Ov31(e#)gmgNkDlLi_V&tgmw9R6 z;U7fFa_55jX6{2gE#(izYGNAEVKO-F!zXWp3MgjY29ugfSF+dcwtgzFsq*SuxJWHa zl;?`cOzdz^V)G&@adc9?>l-_(;sc}oiJr_j*x5z?GNCP)R1xzT%-RBFUx z!nQ(ta929!Mnfahxt-b9%pj}Qw!Oy2jH@R1OudKHO(g1lM**s4^52jEJc)_zp}f&@;083 zoC?!r*El^}ad(nt35bofn6?Y&)a;vN>7Glr#6zLeY@RO&l@a+x{Y_La^{A;HRq2MV zT+iWC70R|2d8fZ-y>Xdsh+iW-m^prVf-Fl^hREnj=xd09d4V5EBiR7HN;y(F|g%X!2*SjSZj#%M;w=!VCY?O!k_Xk z7?~A_wZzc7nlnLu#w{o|X&8f)&GxaXl9#v5dQ^i73DJcH2Zurj)8yD!WGRDvuZwf|>Vi4Wy;xwG3D-+u=RLqfbOZ#kV*D#BG0%V~vc1;>& zA0=Kj?e&^pi`iXbvSQCu+LAOU>!E=rwdo&k$`BH22fmQ-5m2Z|xzSRLxKox&#(|;s z#$t-QQg8Ii(N!@VlG3IVT*H%h_q@U{G`)JyB}siQop4*I?CoKVkNxV!ihP0jNaT=A z9JjEFGaob?Wam$=7^jywaJgq=aK!2-rj|@xj7#We>N`la5L%@bG*k-G+rtKvC6YJM z>T*d-?soLK=fsqo#3w^}TfvH6SZcKC*?b1Y*M0f#_1{xeJ&$xD>ZWw*&}cwAip@kU zu2QAAGikM*=+;Iw^yRiJ@YFPc!45Dr04ot1Pk@8*-Ft<>AI^)arw>f z&QL2Jy%nagiO=J732;vD6r!&n+?KyGPkTPY^eHqToK{p3tlHg!r>~1IBsX<8!G)->zZQUE}_BiL+*1C#suDa*#aL|pX)%O)0`&Z=;$Enz&YCW?uz(+n( z=V?B)mCccj7>TrFUt zvRka4pFLkI*KOtZzQ%Mxb#F|1PLSdX&cMLg*sW)osVt^ZZPNE=4cPG~IYUGBBN)U^DxA(|c~M>sm}?*Nx%%|!!@cR}!x@=l0u>bYFPDwhg(vh<1a_>4 z9rjvq!!Jd!E-BgFvgC;oXCQNSieKvuHLY&U<{7%++AA;Q>bAf!ahoEal2dZh?&GMw z{Y7ft>-Ku=fk{EZ{Z3}X@XKT3qrDU)b5g$XT7-x*nv8n;z9H)3ME653oCG;(6zt=4 zd-oZzoE@+?*%hdPFR&xRmbekn8+Gpn&-D2ao%r(l%ky7SSpc1O`up!<=F`vodV&Abm>Gmb zP+%;qXc{Mo^kF;~>_cEh(?Fr$e-(LtQR)0s?kcF+3%<*5+YMuszDWdzv7j74GXWw{ zSY{!}ZsGwl6j%j%(1++Rv;RJo?~Ck2@9R$|M0lKrE1e{Cfcu*|Tq z6G#~V`OU=*jQo}Z{e2@1Eo^^nn)`Vp}7oIp7P3*0$Db~+c(f^b5=nWVq(NZ4q*0W8PP?Po*(iwNVh zFF}4V(9Qt414y#t0g^^8u&SUOza>`rIvv0MgpK&$8Twy@8D9(q>xT=r>|t6mPJlN7 zJHK7^|Ljmh7Yl1+J!d;R>z^EXx~Kj2`u+i00)_T@LE#2iqCe1#f=(-}ynvsE=|(uY z{{Rp(JuOE7%a3I>uwVru4OSCl7dCqrLpC6SVEX~I`LiOA-y008oB*aKCpQ<&gTRxp zf|$U5nDFe|mKcA6F#$ae3|jih%s<*Uzc&*CY7+pN3z&~QFg+Yh>jlFbIlzMYYo-5z zjUW}%+S=K~$o$k$u=b5zjGUd=9Grgzk$#uF_>Wt_4~Bz16bj2F2jWpqu=9iF5TNEX zcn!p(04n`=#=DrE9#R&zAn(@1>9ftWrU23Vabo<@_WHfy9G_PjOyvi=9YDc>3v)RH z9I&9o_`k9n*lGfkkFgp!JD>X9$&KxF1+tkr8rYk=T6q36W&TL(_Wc)t01z4|?Z6s@ zbqaw3ff?+I01|eAUXhpcn@#NxrVUVZIXOESIa=6%{sKSv8^{m;x*5Q*%r6a+{s}$( zc9?$k*xz(NgyE_G=jUsOJYe|L!>enE&4&2n7{IxPXs;LU{qq{(o8u z1&tB-e)-_Hr`j)k16oXiulNfY(Rbza|9^&uPb>X=Jwd+0!?4yqzX=Z~YmOC+Rp5B- zYoPFY75RqX%jz7xN`YGV(Ocj?6&ctOtuTMcP%{7M%HHI`Ax1~K#Mr%6f-@CNjxrc# zukwf?FVUtccS{lsm*cxd6poRS@KUb@5R!~>Dm)wh~e zVO0eS5fiyeh$zs5`(k%Vd`p^nnwrp_jhh!^t4vfz3lib&gT1+flpe^ zcT_N>(y_Man~_FRBvcY(^QOnKgg4yqC9fE&dkiNGAZr#Z<4BS^asF!3=)0?r8>V1KW)|{N^c&^NZnXOS4#WbI7+>Q6de_f zWVReJNv~$<-BIz0F$)q~*Lrk+jziNAFQsm{J)5ayq2&ngr>rl0?De3MVt%BSso<(1wy)$gS-&umn&>$-FLVCk)95m4-C&$Ii_bKVgRqRkrdE@b-CqeXW;i*X z9HiorggGuLLCKay(XEk58-4EjSFZ;#iNv?PI-jtEG%=Bm%~&6;HYrmSDnhNMragoZ z$|uXBps#Z?-@ARLC6=s6pI0xql`dmk^J&*U?yAzgpj$FHIS3BD);UqULE3Rio71g} z`r_}fDyvwwsg2sZ_??YzqMkDliyJGjP3fiein>Ha&NbLyb=Mk#EhjjOh2hK{leGCp zsRXhjIAhH?F=`<)-?PRZGrl%y(b?IxE}y-3P4z6%8l>z{-8ZwCT6NchuaF)S?!z0e zGxI2Yh*9{&XHg0@$M$-a98p`Z>HC$LzoI<4BQ9QjV)1d&jJa+tGGk>+7VGu%q5y1> zWt&gDVj3g2(Bd`bgPKg~){ zZK@roYgg{|iU%BGOORNgiMFx~O6HwqWQFU-xee;_#ufxoQKMFOvd`^Gm3Re-T8Y`e zlSXHu6kA8C<9-g$FPS?dxA1{s|3XV0jy|>QT!{JHnZEv)2F4;3%`|BunD!@9*O7cF zdZ_j$M7UUqTSC$`4Qg|2GO?FSGP*8wp1(p?O^ce^)bGqRd!knea_F6MOokJD$CdZ0 z-N&Ks3dI~YY;yii#c~Z>ra1T5rLK15U`0x-x-AUGV-rOB5$4V%L$Nv3*Wn9G)M_Let6KP%_sZucad|&zqs#|*q?T9jm|x<&m5Jo z_GoZ`ia#zatkL7*S)-Ht85pmn1jtmftHtLRB+^8cg(VVIZdEZDi{vwDyI3ILJ-l%H zlVO)ktYX8+q3fk7&F&ip64>*zcm=Q3TZzQt;P0#Vv-p^a43?_qmpIh*2s{u&eX33h zIS<8?Qj-zXwMVQsTW7@?6sdU0G%_tBi;C}lE2wCs&dZ#);T?LU=+joE>}~p8$yw&W zK@WGMQL%Cxy+V>`!o7vn#Ey*f1r{@SbqM+#mIY0pPF|3w2Fi+YR#u0cX`()1IBS`9 ze#0T{ghz(yP)I7F8R?Z%rBntT9k%IQu#{^uc@bg$(iVzo^fX*qtOp4PrSQ3dM20Jo zrf0_Ie8f;XlWNyP^>w$i5e;Hbh^)E&J6d=je<585nGU~ zpJBpZ6r=kQCj4A(@H?3Bb3v6qg$e&E`UN>HUHJ841G|lVscraA7hG6^$M^TYA0K1~ zZE-;3sh=*6pmEp#`5-7v2qNoWJolp>;fD|81W^EpWq$GCw^8aZz9Ovp7AFv8{AB5m zMRk7k4F|Zz!}3CZe(+n}|KHqHzb}XLovHz#ARw-Up|Jm=HqL1c$*%+Y^`;8zAo80x z)qG8x$ngs76YmB?G`xI*BKHi&m4$wSA|nQe(PvAmRSH49Flu@r?=0I?$o;SL>R{wEus811#j!>hQ zh3QL%kxFr6HRufLuj44u<964)ABFDsV zrbpf3d|Ugh0a^EK6U#2Lm5Yqe0hJVvO&t|2R6dzEldX!y*h}NRB6`ZX@x*Axh|435 zmn9SI&*Ko0*4i7i%yxH)mh|DooLNHP=#1jc(9R%u8>PfER)Q_b&=l|tpPZNSrJ@0v z^P=A3Ky(ycNwI@16Mzk(ts3t=gSMrc$atPg?(A0W;u@lKrS;STw?UgAv9{l_lncy=Y3Y z=nxr?4wER*5&=0@so7ny6FJI*Kcu?r2%&xT(j;7~ZC`@JXPj!#GemG)=|Lx|O%Cgi8`dRhnb{Vj|Jc z)m9#ow&;v>pX& zr{T?V6+PYjIFOD!=7h5R+LkSn-ZY+xygL@7ye4l7Sv1Sx3TBz43WWgr+<1)(N^+~` zoU+Vb>kW2+3oj2AKM`5dj)*3*qfrY@AB2e`l{tARBOQOfdN)>8tRxam6aq@2RMVXSbB3GrQ(b0C|)*Yq;On+X+h|ZD2UQRqadZY{V}?{ zjpI3Ea%irHS3rg&%_x^e-I|P3`1F9wla81 z9y)Q61i*cqxqtMAs}#Mh9is!~-DH8Xz)9^B{R;|m>9eoI<_Z=RESGC|*6klNROUdh zXwI;gDC*>w2M*WZNK>dLbuLm!Paz933M36M<1S=9d9InPa;Jxhh|!qVXI$MjvlR_X z?17mt=||ky#QdAXJMT*@FD;M-bW-!YJ8)k~vA){r3HjJBvZ!Kb)=_zh}YE3;R{2)a0%FQrcKHjY?jLPt5d!c?g#*fh=(DHJbEec?$l5YCjTul*D z$A(N%9NE)n^>ncN3_6TY7=4>p_=CyhF>QN49PjO2_^`W+ewnEzTNACd*XDJ6`BH^b ztg7tW<1E_8tS!&3G$`w_oG(7P%o7wQt3Nd$#WCxs1!sf71aY@`rR}{;FG$|KyBvDa zX4D_QVB1M0!m&)g?xCDkzJ?dMISD7hy*##?qD7cWD~B>+ zTW<&=@0`I@kZ5ezM%#SLi2phl5v#D!?&Pp-^;50(%F*VAil9k!rldV5k_uM_&K0kB z7W--aLU>$BKB{AA6IU_x?Dn@*Z8lHJUK$SJ@oHIC=`r&w-zLk7sO&l%g4=Nw%9LY@ zewhE5ua)M)920ahR+`kPC!jPeAVCK~#6wB+&O9TcIeP0nf+vzj_zccA70xWe&{v-r^pVk zU*A8e%-VW&OXXnkkVNOc27}Z1HZhG1friG?cH3TGkdOg#qzw+-s;n9pS=J?rrP!wF zxc=^hBUR>O$&|p+2xgxPyNyPwEHlq1k={wY#tOpm73GhP^ye?rCflrsVmwKfVT>~* z3B=4)AbU5o6K~K^aO=`jq?CC|4~EMhQ(jJsN8ph1L!|MusNQQSQV7LpiH^P(BqZe& z6F<6;X04oMaH-g=pMWd|o)f;u{yHwQP$4#f?UM(%?rD8S$A|fg#X4FyETl3IZUz*$ zsFd}uZg>~guSc*`s>ewQi3hpF7&E2WLH(N4RU02$W5+$Q={Mdrx2xH95EFSxxL|SH z4qkk06j7F0;wqG$iQJTW#-RG_oLE<2i%2++Kq;uKgZ|F2K~Lz)=p7N4`c)SK&%Q#v z33(o~e$Al%#GToCqN{mXPgRXpNcFHV)M`E+91hDf%OI14DL`gqTs!X9I7sm_^1sgS za*K4fzk+d#jx9Y{qUrh0@yY1zecbwEhT2*dw@k~YhXlq+wOB%_(G7(P`OUWjg9M4t z!j2ev9Go-HwVznr%|GCok~hz}Uxho7Mzo8#YB}>s5+l<``ikPY>GRM`;DICp$MNG+yHKJqQ;t$FoiDRRYMrM&;Rj%*80j;1;FO-kK6et}{>t*7L8UT3Bq zmJ83DvM~EhzT>*v&qC#ZAQ&2d+YN0_=2h;BI3FrC^?2g`nFZFQaY&J*af5)r5RUM9 zKXXg>-MH29txxdHm-5no4p%_l?_an0&kV|s;mYYv^!utUp9`MY20cQN;I_nS}yO1v$7lC zskqaAkGZ3!()@5rfc9R=tCCVhZb@al(7+E6G7PhzzV3c&`I*RYBYq4?8AH9Wp|y~R z5%$B~kOWP_Cliy$s|V(X4;WfG?!ey`)GP0TmkMZW-F_z>jD33+BA2~gnUTc4B8Z1O zg8NdoYfW)M_K_TCQ7%1;qfe{mqNCPo({Kx}qUPJ)8Zj>)buy`!=NN>0rovA6*AX}k z(S${cPdE-Y8Tflej(KS1j(JIhMIPc1w9T!BNK-Y0C|&3Yar3hI@+1M%!^Bw9GCugk`{hUOPd6WP=_dP-OC zkSYn@M6b@#kTdm6^B!mIs;!q2Y7DZKcW>0fkWGoR$jF{l5gmfu-!PHk`*>FpS*uEZ zecdx@qey4m`f+iaQPoJer^@?n`O0X$drwRrWEb)e-MX18&{tF=}e z4bz+f8XqKn?CS_L2>N$j_f;t#4u=w-6S5RcbDMq?ruQ?!5soYgA)ku?gV$&ptnP2?ioAh%$)l?_fObi@1j@ruI^s- z)vEWKKDBcnC>4M0+msw1Q)wlL@is}Z=EaT`n_?DB2)5cu{FlO_xJE8q!mfHDlz;%( zBa)+?(Tp=fNk6n6^`SC#eU=#=blsV9}Gt6MHI5zas+c%7M8~yQ)`&@6SeAl_tiwm zu8W9$r=-SXf2|kPj%{og<_=eIU68E+u51jQ2lCY!rnr&+Zeh9 zDzkKO)mcNR5<2c> zhzTX73>|T&K(12UA%?F;ZG1ML_En&p3;%u{{hlCZDl-IQ2dTRC&MwHQ62v^FuV{?t z=xSiAEQH4DtEb_kqq5uD7MoVd5Y^%X;VM}hT-HO1ZW|;S!v)=`58(j^a>Wa}3y=ri zRnXPwE1#|HJ~yMzXV-ntQ37-}lE?T?!`TaBS-sywd;x8{6f8u7`?gnyDV&ynW9g8! z1iffciI&-y$qsU?e8rG^1=COwIH+!fwm_si@LfdNn9v{7%UL|$%ApF8a#3BrK0pA{a&N`xNdoVc&`)u%p?n>4$4j2dd$v@N1BWOluC#*qC{LLC&!FC`z%pK7zI8n*1GhQD1&)5Z@LTyJV$38}9}7u8ZIlzWPfvH=6t~#zDCTTa0`j zg}M7250>dCPWz6&O-;rxT$B)W62hx~WPgskNk0=I)7z52l{!;Ry zV@VCE5nLF9s~_fj4|+tYlnnv=x{xb`R{Q2JOc6CSWW3Wb-0zR=&Re|agLOsNQ8%>?vgD-=DE8BO%D#jbq)O~OaBC-Z zqIi-TrCUka3W>Kt;rSiWD3+T=FM_CJY2aA^0mXQ3ZQ9L$6HvDJuZR3!CZ0d@fZrvaOaQJ1&{O|u;`uL~9KiDY=CD9Q^fQkC zp1}P)@_$K){=F9bPyOKm$Cuy4`AZH26j?F;ZTa_^mi>JF$zrQO`p$ryJ+YwAa*DQz zKBw*bxi@%J&d5pbnc`yl(y?&jU!A-?oh#wPFy2XyIouKHR;p5C-Aae2zl!6 zyzhiJp55$BF9UJ2C2^SyGIFo*YG8MLP=~7O6c@0rRoy+vvH^Q(9De64$^Ni_RlcWg za$&3i>_JbRXS69ZV#2OevNoNX;^ZF27`X2&rt*6XYRm51`)pGd>}2I`wJ)m7^=NQ% zxjva~5}tz8gpzXOaC-avkQ#b(Iio%*sj~_ir!h(_4u~Pz_m*hI)z!}Z^kYU8T{G^X zSkw|X%F_8M389X*TNEDD&FQpRjb#5R>>)|uyG@QILU!+mx%gXYy;UKS0Cbyh&s1Ke zo%|jcYcVbug6Rt!IxVMS;)ca%f#i9UdFnw_lcNGvRG5)r=5Ewt{0)A+S_N0;Y6*S4 zd))=^it`I7V!`9s3RJ!)WWuBq#dgCu?U+l9TpF&s93$1D9235%49=$B+2Cy`_sG?& zqn*PJrXz%oqKZ?)>5d8!9cFQ56{&%)zuE9{b?FOvK2%DA=Y78ob-2258?FM66N+um z34u5@;#^>@lTKrW$`z#D$~n&W&3^N16aoo7RyXoJ_t%pCG;e&1CO6NEQ+>X{a_De( zq?TY`(3Adg;+;x!#Kg&Jr#kBi^XcyRuB=_$2#%HwwiF+X z6_dKmvzS`ZXL6J}naRb13+y}2<>IQ2CLoo5OR4peOu}S-F*w|F7>5G033o;AtMsgY zEzc@lnHeo}-F_bWLyc;Q2+f`dE{0Lhc^#yL1qg^vcE2QihT{cHTFks#hfpH z_t#R+4l47?oe^cj?^RXsUz0HM)Gs-;k-$f(h;#)%gTb$eYlC?)<_l)t;rr4p#3^Y- zuxCaB_r|KEczoX84o_Y(LdsZZx9z>0gk*MAA0t==cYBW)g;|VQ3CIgs-H2f3(PG4s zR|hxo@|KYFGlkNNTm%fA9@8kSGoWvqho@qlZVqe$_eto@MN~b^Kng5cHxbh<8Yee* zHRxPl=5d4HgKy-Jl}V;HB8?i-L!XwyxZXggmRz2+o@&2yM7|Pel6Zo`kOoVX_&R%6yM;&aS;K8c zn{XWOG(v9x&Z*{o1btwSY?+I={RXZp7+*;U7D&03eB^ePEFaE%A}mV;BB20_S;0uG z_;8hZ)Vn32IUlL6cl%oK*;)6e!krH!gaOB$$TQ-1mTu!cp?3jE-l$O!-Fgw+3@gxu zD%&QU&+s-(C=OiTBwv#%4esX4sRb96Q{3Mh7zxC-EFBBCCfUpJbM9o*QT zJWnNPO$!0*4mU7*za^C$tyd?Jk$g9b7_6yVES{4sKme{{2Q4hw zeZ?4#vg}IAO^PPZ5h}`ufUeDq7Txl`T$`(m?fMpqm8Sfosel|j6lO6M5>fALu?YOc zJ7s08Sx>iMWAj@*{bmu4YJ9a}$jZVo*I%CzRXlXQHoJ8<1ixw$pOr%IzJCxpvlDlB z!14hv_6=IHQcE%_bF8G}R~pAjJc0b2?Wb0?HsI^=%(a{jgNO&FBfPcfVJ3(0C9eyr z^>}-1n4QxgNz(HV4Gpv!&=_mN>x}!CuyJ$Upoeneh@aeIL~D?dq~CU)SKp68Hlx6) z7v8mO1c5J*sxX)I1iLLvNsC74G&g;|-gp~<3_dh^HM^H8CnF8^UMT_M(Vh-$@&>*+ zBnRO(YD)ppwH7={)zN=pw2qbm69Gx$S-`eO^td>|teqdSU9XQm50Y2fEv>EJ%>r7? z8FQ|!mZ9{bpA2~2Ir^NQ>|biEsa_K>@e>*$l^g83p%}n=4FO2_9dZ7YUt!* zYH^a`^TbhW9D4}%4M_SzjPC?U7a($<-`MF2;c`%CEtATov3yNTioT%FEq^Ih0p34F zeu{t4J)0<+ic{%?yUchDEHD>Z_=n(mT~FO!4FyH@*THRM|f9Ex*HOUB~s? zV**12AR`orAXJGE1{PxA4sKvEXFSy%oe-L|%JD7ifn3dury^tdP7^Iy19UG`*tu3J zyrM+Sea_~slCW9yuBO{GJ$DbsKM8lL+MMF0U7{nrZ}QAUHA-OCwrjzM?@QJX$;eFV z4kKRqN~G+1oGSWEkG3g$M{@&`oKTfCKpl!FpggT%FJ;_TIGP?V>T`}y6tL7_TOkg= zNG>~Ywus(=xoO5w_+q(rTdF>~y~CCCr6m!F6S<5r#iu>HflI0SQQjC;hi)e8`>-!f z*&)a}axd0YAP_7E*g+bFwfSuoXk0-?@!CN=HM-WC+OS~r=2RI@@*l*Cr*uI=`LfcI z>B-Nt2SQ;Tf)eF4lhgEVUC1Fyy*toHI}=_guw|c-tPp&RC!46#JEcjDy*`CcMfE|{ zq1{0-$A&52qrXuh0CnJj!0``%R(^gn`>_s!Sgv+^mO;=OM&djKheD-d$7kkKyDAe& ze<&`SvWXK02blbFmNI|Sm;`%I^$bm>$c2@j4uKwGQ0(d~znw#-q<_QP4=)G|Wh@J7 zJvU5b1>PJZIXG9Av%Q?3G;4S}`{`LA>hjFw5`B$ifQ~+02J;;Vqr78se21NtHcf;u zbh(38^d63##3bmflh%=h!K4)XSHbPxR8m4gT-{N^v%vbUMX`Y*Hs&q1P_3Naj`wg0 zs%+}Q+pqai9%Ro3M?OJ!k`J<>ii-+xnA*gg&?sVI_6_ue(-85lD+f={Jhs}rHNAgX zhqliJX7YNKm1<8JaVD~&VM#y@WLC)>Uj?7vgO)MTV`@wL8G%H~ZK5&}*47-O`jYU& zf)NX|GFaLrtEATw=~U3Ois2#6ao#Sw&^}s5WA1Nr5~&!Xs!42*cYxpMJiNmtrH7b; z=83_ovHGRYjN$^0P1ZI&yGy}zlFFHodbrBb2h@`FS6aQzpb-2I(%`QM^CmG4xcME3 z5nI*bYu`$U>D|-oVNU5(L?PCbLwg+Vj0X%#pGDmvc67EyBH&{SzdpEe$SIq}iQqgG z(=w1u8e1J&|L!^7CuBBm&3T6qSWfvUfLA78e`gv}ylEeMLGyY4Avw5-=2hfssM)J% zzT@QvmQ6VdNJ1YChB&;O4Dm)?*-_gH5&l?}8f^d3;9{3tR8zeU#ol>T>MepAE1{k1 zM|3wKdz8F=p$|lmUd9alFAWY@op(*q?K#YraCwmDLOeaPJHer6h*_37D`aN2dODD{ z6$2V_nKm>ZWpVWRWh^3c)>Me!EK_!fw+j(Y>Tuzii~d(rwMye_xO%%3MpK<&+cn4ft_nVFt>lyotd6^@V`#8{^GDqfWZIf zN*$)B?*7{B|Fc~EM4f3s32Pea3b9zc#psst_O{uRNjC%7o*yD*dUE+Y1E-fdO21GY#If<@j4PoxU|{am-hF znz4g-b@jnZN9FYdS{=s?Y!4TMlNWedSPbFdpX)y}eT07hvK^ak)>?AtZZg$9qwY?` z+F4jl@v5XocImWS`^2=U?tEgq+4YUR%jH^LdEq1WK6SCw$ND-h=8~Fo5?;-&l4WbJ z`kTvq^nSQ9Lmz>A*Nge1B@*xz@A}i^h@7vWbA)TQO*7ixQN=#$-)d@mHr&h%uEBq9 zV_TiAS=&~>p@ti_j*J{ zP!I{B*{1CnbHDU?K)>gON@e4cilw}QXo+KJnW-8Ua{VI5#p9<_Zg#&%EKboa@)@!n z@a9n~YFjouLQ`|js%*2pRVT8hjTRb*ugZJuDE(>DqbU5Tip;}ho@;N8N+MFlIcEv$ zUJc=HRdX_5R@jtzUpe)~eUv#j&dE)lr6g(hoU1-K+_<<{vC$0%y9bLUPJz6L$} zjNilf`lTr2Ca<$Be<=Aj7MG1$YU|1g zf}>Vl8W5Y^0;6RIMQe8Jd+7J;^&$${vO6b)QD!wrAZD`hX_Yu$+YCCw;0#@xmf~Hd zx10>AP-_0KZ?pJ1{1ABwM;zkTUdi@jQ-YU@z06M-6>1~+Bw#=fV^ib`YxFoRQDh|8 z{DE6$ll^o9(s2PRvfN@GzX@~@Q)ja_eZuKWt_5?=E=ylG*>U$!~H5H0GbdObVAl0d!@?&RgI-Y@u zkn%5&XfAe&x#Yw5!{$T+5ntj0Ib9cSyKEbmOFGkpW6j;H1#j%o9Og9xIcKAr)bsd; zSieQIY(y1|8;}uSGRQCoL27d#&opOmW)oBvZIO4#1j(y_Uw6x1%N)Aa9Kza3dH{nj$60g}c1 zauAAiwB-=rTaJY$0wf0_9rS>*9F#eNYJ`OJZn}Y%Q@CKAet7 zyD{!3kjob_a9jS8DnPQ>5F753|ylsa}ibBBnwQC%vl$Q6y#zf>bQD9p*uOtau{SSDs0$td5R?whO$H z%e#IE9u7c(ygj5^a2bpJ(kwB*%AkV|6N2+z0UwELuz=Of9=*|{(6Lr#esiwLpWNS_ z4be>h186lhm<;3BEledBp{h+6^LDiZIn)7EVeFdjQLa4h=FdZKhXYn3F3)jODf_QF zPaCgz4Fu=DwVxw4RUG+?U{t(a4>=kAhK|N+s zaIZUp!Z}h$G$=-6b{rxbkuxZAB-uZ(Qs7!~&5KP~5>v(3x7FRb zfpD&e=*5Ox9U$_$X`}hxAj&J8zLHQsVf?llNv3gjSs#KCi&Q|LC&2(;Un3Rvj6Z?^ z+F;W}#+`<=or?@QdAg%p%9~?p>z!>cF21{&jOS`bvrk~mG?mULSrHi(REY4L@6W!> z4b~h=vkvNkeELGajgwjmQWnBr&Y>g@sYt{xLq^O8Ra2j%6E6e7&-GIS^IO%S|{pwlta%)Bx+Q!^5mRBpj(eNe>~&1U*@J`mD&-+M<}5k)IBH7f^sd z6VGrCrMjhrq&3k=OH7ur@c-PO1-Trz7V|fGEJVGshF{rX3m7RK>v<5}v_ixmzF^HU$JQi?V z3>~o;80tmka}caq=yrV!QIT~mih)}L$RffnuO71KLV_6RGsY4^4dbp{D()nC_6SII zF7*eo$3sbA)YH|LhpobVh-RXpR=w~OfvhqA#zti1bZvG%gQ$`A)axwYSb99=ChSvyHnDeO`G>e%GM8nbR z&vib(t<-|Q3?$g;RficG9kG75rF#Ef|5H(EA3b>~a*l#=NIL6dK6Jw;=4PV4B!jdC z(gk}fYfe2wdFYNI#e5=RMqF*ke;l)1HqfSM7BEOsdK!}tX^J3*k-M*!4?Y> z<*{D#)A`(IT^vqo%4LICw?uQO)pl={u#Te6m&^}7zDK5`dE@NmLZh;FAJQ1Vqr-fG z@nGQIyDT_mCB%c_?JLnl2GAKL9xA8IgU?##|kn?#)3{#a>jdw z(lH}Ry1hJNwob97wq}&~874gG<2H>t=Dvq|av-jknKp|u47kd%q=b6HEJEu0L_tcY zwt&8cZsJ@H3o7)c3Q`+J$&MB)v-8xiq?s-tmah)@@=F4&ZuWx_!~nOfB|>NqFusBb zqyxKVDob~DhGWe7*HN>dyTKlD9la%651Z-B+9JtWCU@17Hl#D&9L``~C7-TlL6F+m zF{79JGme{*G%V*6kt$OkcOKgjJ40r+>>%_fVKgjheBq4XFXMlKv|SR+p@{u$u>)R3 zq4}h$@X$0v;6k$Lwc-c*_xu+;9d$S_BsIXhpuStZY;G528B6p!Nh-%98tZ(k%%tms zxEx3DbEBj|SY#R^xXFW!=aV4*)}*J7^Gq6=SsJ!@ z03?=vQO;$j7Lu=EawO2M+-;ihmZE@=3 zQPx%QzJxs$f<6eBHZLbTraG*=98lDVH7$um?Z5 zIT(<;xN(>mXBdK7tf(<@M#|JIb>N6N*^gj*n?&w|6~xDC>2F1pb{`g``x1!TkXSZE z4abx--B9l+&USjeLQZCjSc}(k1-X@S>bGNketTQqr(hW$oH8MP9$$}bADCU(s4BpA zxiNq-dX`^rEwytUig6e!{;6Ak`i_Ysl`HMDa7T8E%Myh1#=f!`mc5rN)a0yNPDyKP zm|9)pP;RQz^}Z13S>T$2^#_mV--k$(kBR%8Me8~~;?W+3)1)SUm!e0Am5j@G9mh}{ z-;I;rK@$pH))YX-8Y;Fx1Tor)80Q;F#DM;sbpCBa_q!e@e8?@k$lKy3dMVY10;yS;?45s!>~ojq!%-FWHhRSff8&JOjq7cE@OD{c7oSeP_|xGwfNlkE146>4ZzhZ=C#EGA9oE z>q>1HsI1}^r!MRJbuuvLJ3g92qi#T+$aK=8f*d16o})>g6nv*NckLN;4%lS%n&--A zqR7?HpV;5xB-}?Vkm-7Sq}$lpqpv=yfAj_c4LO*91g}8L?Br!TB>$csTCd4Sq-X;B z@s@KqWjNt}=|UFUat})L{H$Rnb)kZ`0e=oZ%JrIO7*8S&i|caW%8jtw~ero$=Nqv@OPi{$D6D|Fu?<>8BgrZ?|?a zJ^AAOVHD+5j_DUiJEmV8?S3G4e!l;-R{jJ1`}F_c z)mlFN&0jT(|5|JLdwjz${0V^I0N6MIprjvUVZaCu@GJVQ{rf*)HvlvmH#3{R0F(Ue z^8Xkn69-@v!$ic&0r=+uUkfupAz}uQwrs$DHV)R`RD}M`K!4J!o%QShIIk;!da-|s z7kCLo{|7k6&u{2|44V-!d}0LvI;=qD>XVTWE8t=eKpI#9AQj-d{y*V8EX}M;oS(oX zzsF+y976wNpv?4uoflBW!3qFi0B@-OYa_(U2<)c&jZfjb|yz}3k7!@UXE56i;J1k`E&^O%2(n%~jkEa-m5{1YHW3*1-!IOP9)6aNp6 zc7J*2V*v&X6F@crYKMSJ^2f*rZY}KpoEQY$MSz>zK_!c(c5yS}G4Vi&r^&hda098~#aTP7||8~BAM`-%P*?n?h{q=_OB;Wsh2>rKh z$V^XmtN)=P;He5cX8ydL81P&B<8s6AkI29b80rDrtN*;x@Y_-R@0JXH$0GmT=H4I9 ztUn*LbRtauFFSpie&^-(>-qt3Q~KNM2hV2X=2=fYTLi32id0cRmb~nNIxn=wPrWZ@ z%h-|e!=Bj&lVHZ3s(!yY5MiS{jv+6aP>i%;_7PcL%v2YKF$s5KhC(bZ*XVjVEh*yendpok4I@UE1HE0oFoz8g*#GOX6j zi(#}Rdz6E)p8gJz2{LYUSpAiLV=<>WeyW@OfQz^~@%}8vUPD? zjhoU6Y&7pn1KP0-H6cj=1F6SmrHXPMutIFws_N{n%E6-8L`!L!^|gR6l@yBKm=+JK zEF{!u0;9nD^Put`R_cdKqMSDt39{M`-U@*+ z!$?`+3vLPd5`((XaVRq`2{LbxWkj!gvdvg{apAKyQHgWgd%B0rJ3b?r7>dh{EGV`J%i3?J4SPIcdTryOj3@Aojl;p%Q3xTc~=w{|>W?|0i` zPrA}AIU_$fMctc?n1AC0krS*Q?*b7FN@rp`wx@P)R> zF&RSz5jX=*3eG#2JcDC$-L$;!2bSk!?`$785AUzI8D{4S_{M|U`(JZ{V^3oG6|2Iw zI(rDvYq#{<(Ys7>DUTEI5$X5GXw}h~u%p50480;}S8br2sx zf)^)zo_F6!#FgbrldRL+tWQek7lNMIxNzABN@ZY^rn^Ua9VIz)-3cx_@fu0nf;@Ai z6DdCK*sC*{bf7fVRO^ept)yf$@-f50MbVeO)PuD9xVmi()jKTIgZ@gwK4XhQSv%tH zwjC`;{@@lxP|o|Ue$K0^N_0OI+RJnNw_>Kq*bw9P9PPB)xR`tlh@qCi8( zuQoyq?`JHoONTPVQC>PmN}Zmtf9^%*xGRYfW)@*sEQ+2Rl7hxgu2r75N8-KYI)=HL zs&Kk{6oeomQU5mp(_kO6kRV4uUI-R%w=7XGIt(_{Enr zc{wPxHT#x%2>L)m(!W{vOk`q)(5+k#yV~LF90l<%_<_^G0G}`FC<-+V#Y!92H}w}B z$lYC{FIgIP#Gtw<}C^dbK%13xVH6+LBx{G=Jj?5T6#Js8o;;OVa>2# z4it>$V;ndJC+%H~kH^mt^2rM=a+P+^TxUQ<;^{Gsy?|$G*KO15$&C|3rWXrkUa=EI zLWWU&=h)}}%?S~YE2OYef8&$ydnJhcO)6Cf=QNjomFK1)O4MMaCirfhPH@m+<$1oI zdaqvfG^>)MOpS2CLJWBKWSL2z(F`VMvOL>tbCPaPi=$6HMSim|{DNXC@j3&hV+;4~ zipr25tU-6$vsIjyFW#X1T}6GIa_`>OGaKVLRz2(Ttamq+rHBR-nAd~8d7 zAs9f>M3D>|SEZ~dO0qh)cYBWdGH6NbRY(?|RcuE$6bG$Ez7wPHr8`-zCIuOR^|CX?(YZF=hJ8k9 z!=unJc|x*rAu>iR-Ci0%Gqan&U>Dw^(%IW+j0%!o0&7K~vcwrFpTR`tG{3i%0)@5b zJ>HPB^0dtg|QD1cSks&g-_g^KOS7l96m#E-6a3K%D`r zwCwCL(PUXje6M!0=Y8iB$Z19l_We^MsI+XO-g?D|#)6r;OMI^@a&s|*W&%tIULhc% z;AV~HlY{z4_BVLF*LyqxK|8A4bXPvhip>i?Zy_qzU*1j*4#h}AH2q);P7Cd8QqLvL zA&{o01y|1{Heh)SwLsQAJNB8}+<{@hN3mtyqi|=)R0cUQYg>VU-JP{@JmagC09c&0 zh1z%HPRg6>zPmbjrgRI?G`f)`q7mE~#_O-uR~Vl1#O*6F!(4yhGIYL#h^ z;g3i7${p%u^9Kh8o0V^@4_y;qEP5nfy}^d%pz0T{Z8WEolq%@|HHhea({?_7DQ z{99UfGYS0mX8CTz_&HAue=^0^F&rMpU;|NqoRY1VbWDY9x;hwXw(NtH^M@t+@n|^D zhbF7aV8btSUTd&<+}W~`gK`eOBlKK>EZ)k6y3vdY%9L>|%tn>WQrb?GS*`@n%Oz-f z7hjSSUt*Rpc8a6(`Z+<;E@{K0Zm^HNIFs5qOn)k_q^n7(l;b@ibL}wO*VsjSjl13) zD?}tM>;P3yG5;88q$>N#k8@2l{XMZ92=^M#n5WRaZt+GnNFo9;XxbNA3d20r<)M$; zQqzPXC5tj@r%-&y(aXrezM()`$4Yat@A2UvZDs3?+SZww-ozM3?{sL|jBEyDNP_0k zfVo#Jxn?+$jphgD&wa@bqU-IDZ^a9L%Znj@3y&En(A`_r>mR7Y0Z-oB;iAw4RgW-W zJAH6sQX> zJ%HHD-fxPQ4tYYrU}+Ow?TqWC2MiR{ReR{BFR_<{>)?orHR}?Z_2oqxvbC27Bpev* zT^cM>C6=y4I`>C!j-1}$ArH2y)w1$6Z0Ik+d9+?)mDWohj~&c3QII~GYpnj7+;-K7 z!LwoP2KskBUZi^L>RF>M6%qb1uf6pQsF6SI%B7f_e0Y2Ng-yd-CGF;;K_Rt=SE3>6 zPXDt(gT@l%Y0J5hgoeby^-ZQ4NX$-nNS^Veld8*sFCX7SqPw#$O-$h4a7HnN@Xz|0 zhO{R~BQS9|w)KpPH0wN1BSAbn!BlX_XtfB#*;G?-_)dM>^gXFx#-M4lPli@ou`tNx zY>%9Kzwmpnhn3P@Z{9JHxRmD>s&MDPd>cBaM5q1@K|1zY0glSY+E4Tf>O*R3xZ!O_ zEW_$wMj_GZU)nzMEU8E_R0=(kj+LY9T1{UEejA^|D4RldIg$DLVK2pl#IK`c{k@8T z4WSS09muX(Hu_g3a0^-b?Cgiiu;;PF?#MZMo*8F{1K(Q)G8tS|S#y$6P0Y-e-HGHV zUxzrJrUY)$(GD#)^XEG1unjRWl_kgD5TWwZ-}Z(<6ze`*M7M6R=eakO}~K1|VnC0|#LSw$^h12WR?G zd-zXK-@h?9H@0yAO!@$U=8xLUQ|JE2Kz|X^ffGRsR9i9wLeLMT20)kr`sqI=k^@|F zS|dGsS3o}kJo)G>&Ft)~?dSv*`QOmlyV^Sd{Cv76v5D@fD}U<7Z&j3kc)l3{g@qni zWMBZi1{r{wP9|mm{0p3K!1f-16Z`{N>?d0NM@N2~Y&`>7$G3FAE1Dl)nfk(H4h5W9}4gQbP3k%i44;1WMCh`$}^ z@1;p*Ccpv$0673w^MEr1%M&i11F-&M_yNM;_y=FYFN5CF-p~r5+y6M>*2X`@U<)&S zJ3TvBIzuC4Jx2=%T0MIkUPn6%Zn|IJFtVa?w5R*EcTX?qoa})!AST8Di28OL|E(Mg)Q~eg>B+#iAo7oQ-U2B7 ze|7d(`Uo4aWbrr4xyw`+Q+-!V`CsFqoq^dGBxKPaHI^paBWk)WN5d6 zTY>yOcRljoj0Ox|Q0f?WLuwQ1UK;c7?>Xg zq^2t*{K+GLK}0BI!?qpm+tKV0iVU980~@8Tdok^%cl7F#;J<*!Wv{tidGhCn2y6 zFUWD=-!uABR4}!(TI0_!okM)}faCJ*(Z#-7{y6Mk$E?z>6Eo@m9R5An5$t~3^KrTc zu|aY^KZ;{}epL9a^rN!jRcGeuW1YCk6<&09-(~FU#?o-y9(=NRj^QkQdIs~7?Dad zStW{r0pH5$`=Ys;e6T>jU9Bw3AZx>UCrg9z{2FsU3U|#(^RzRQ9Q`nT)R`s0Sq{#c zo!S^%n+_Eu%AA$Bb? zAF{TpVO-fCd_O6#bo|nyqrC5ps9J521ZwUPr)~iRS*(w5vxZNY^H{zTDU-0h=#Udo(8v1w2=GF)Oo5YZJN9uK9r=!4&$LU)lGmd&y>rgWkM4 z5k8`FXW>w;DWUr$eU{zWZ0cx1Hdg{~=!rj*V4CaTR?Q5!0q@G!#Ih$-$qcJuSD6l1xet#LcRPw|m_E!?oLP@cC%JKF z-RC-Nr$h0kk=tfY2Z2QqZU_6y2k zl2L_SxoL<* zNC~<82Vtv%UGTkC%u(F&fJAwgIik$WbuvUQH#8c{FfGX}{#a>YmJ5s{5|@&-C8MvaLZR;5TeS+D59Ek(TQ zUSKQfCXfzo^FgjTZA5BW4G*z9@kscUzMAf8PDmN-K{o9%Bgt)eb0Q*r0&oHrl+gTkP3nv%kq*=$2(#T&mb@AQ&q`Yz@A?1ZLL zMTNgkpFexZb}M067_57Zer0TG-ofQQS&mPD%}zAuJ19-_s(3fNncZ;mB!hP%pp(L+^*PI&1+m?KYne^}er6bL0n&hv(f1wSQ3=#r)?L>OamfpB}5fpJ6gTtM;;AR!c=y_I@mRpr=N^sPU0z!Uu-Fb^K2ytJMH0?Ni!?fB- z^)ZpSs*~0ugy4jYcWII%U!ajVa#px_ql7zGD6;)TQ+idiq^irYx#rq;N&=4;AZB_4 z9{U$pcO=cS{Vq36zNHY9qPX0NRlUpetX}21nu4`mAg{uQY)44?d0R4{CXu# zaPcf^L9Wpv>j(Cv#=MYdf{OW|p_60X6@zl6XYilzJg$sw-PxXPNwd8Y9&e%M@!A}P z(sZf%CWYyG4#I4bO_}YMWq;g`;pMH`q;toxJ1Q@HEo{pI)+3#33^`nWVh@msWku*S zv^tL~UljI`$r7P?`ob&F3a_{*%(^niC`TJ0R7(^AINV~ zi{2{r;eNdd{r<6D{dS6`mo(=ix>ampi*PL=#rvBj!T<{EIK-RGBLP?jEw40?%RxUVFQ&! z@DP-_4$`^hm5S!w4H}#H0--jL+LKqo z=I+^x6%-iZ)9DvRft(Q#<#{GNwA@_y9hpK{)&hYXC!bO%Yp{!<;HRU5m*u3Gs~J%X zE_=$^3Aj46XRaM*8r$^xbv+xFWKS3H$W4S3{Yey25I#7@1YOF_Nm@46BK29Cb~n(b zAzC6$pz?7mc4X*6lbJZf2ZpG-)bv_;eH@Y6n}Dyr!bvoVwxwc=0LKuA33%Z7M4`=` z((~E{EC=KxBk~(x&PcI1FdpAPD^H}9Ipsz}4TAmQ=@oK=_vi~;`Ke3Q0!1)5vy+z_o^bR<4F(-v03%ajiD;P&TvUgNqS)? z%GVpt>~+BF8+ZQN+^1BMCM&4JXoS4MMjB-Tv`ZS2^-SHjUo}-LffI})U-yuX>r@{0 z=twZIzO>rm*q_Rg#79v7big&U+KwA`pmN10|3)}06Ers!&7$n%I$v&TN~QASSp*!p z)QB=+Th?GGbq!3|GDw%ZP|k$Z2+RO4bWRoRQ3#1_c~G9ZrVw@&B~xJZ;(`jL_J#N7 z)XyiOGZsn@(#B=fnOS7dnyR#tQ5mDxdXi;ew_~8SJWxUD817y6;c#GaU^h1?9O2@P z=t)yFU{Oy7WEPIYATM%g=qd2sNp8)dopAZ561mCvL7y3aH3}V{-uaHpmwJQwQkP9A zQoIY1Y!=pmLZ-S}KkFL3a4pl5us~GBtp~dJImlN35LHpC`_%%cZO4|af2u#f%+1Jo zM}EU;LyzAEDVLtE&3iE>pP@cPiI>gU7?J+Y{24X0!O5N;vlnGam&UaAD~qU$J}1(*Jj@B)i3W%{s?YOH zJA&<|p~34_I9v}I8hreQH@_pDT!8lu0$Z(@7RO4yqtkdVHQn2Ae)I*)phPD}kmY?u zHiI+fTkX?9LNXUJ_u601yIqbGz#CsqJ+6bC;~Dp&KgP-oeD1afzppim-!JRP{w}Dm z@%lLwIwX_Ko#KR22MSI}d{VwXZbR6m4#RRD_RZiN;cL)%3b^Ey;}pGzk9Tw3^6Apj zFUDn8dMVFB;RW>-qKUB7zlR8NeG;-Oe-6Fmv+BD32)Zqa6ZGdL2S9=R*8}=z`tZku zkmZ-`Pu}R4!c!n&c%lOT(}eIhbT>e}`r~0$W%SLB3>@I-6dd&(0HQA-30d1&!ae=_ z6c_{WL{t=3r4=!=FnXhBX+%UxOJ`fsR^WLLnSe|p0Ic*y_XI>KL0DbPE> zk`n0r5A|Hg$iUjr2>26l_6~MNdX{i5@6**a0J{)Ouj!B9($X=QHnmpY#$&mvf=fGt z)`^|cFQzZ18&@-BXmz~t_H?Dq6%$A2^V7S{={Za9hz?#gI#=r{LqmHwe!TKL`~3Y_ zhAKlFuhDV!ZBA#F+>)4H>Z#hdzOXqiETTXXkr@^n-foL+qNgp#OB1dZJQI@ zcD|Fjzj^n*_q{*XI=x!ewX19Qsa0LOx=Z%=FB$PogO~k9lWj8#G(9tIy-J=~%h08} z`bTQipqRIo^FHl!JwoUV3ohIHML8b{Awk_X6lc%tx8RwP?M-oR{K)6?vo{=$zBTFV zw}F|4uNPA-d)Cfd`(ze^kYyMJaPV%3dGy(iQ?}-2Uy%0haz7^#47K_gc&)I*oO0@N z!f@v2{KRfv>{kY34kKhIby*3JQ@s(M^7p6ZrOuLv3>{Gb9p*HfM#%#@@BoV-gTzgl zljWH$kE4#Z@`SGRDHcpxjtVo8DUOdGh48IiC`S}?X1vYwnPQB9?%^l2n8y%KbW`L* zOB>aYG4ibxpFk8vQl!X&?lO$rNGK>|wO#HVs?3L73)z1?)Ae=@d|}4FwkL*vJu`jB zzD6NIb4Iv0xpZ*bc1o)2@1Il$;bB?lKtk=+(>Ip*wW=&J3$YRvrsG9&4IKMusjqRO zA1)Y4zrm+wNp)bDBNQx%1ev2XSxf$_QFGQMKvPd)Xg1d=wmBFRVhEe58#E>;cuF;` zbS8lB(&p*@N8Jc?JUe_XPHU5ZibY>{zn1}rB<}n0 zs8Et{pR#8+E0vm_Wf@LVDNb!@RCW3M5w32iz7FlNyiTnl52aLnX~Y~qnPn;9Gn0gc z2Gt}3%YN1ua9-ag|3|6t~Zg2L24X42%1 zFi|cDmta{gGk=X?n3xkt>2B}n*A(^505?@eE{*B0<&@MnRI#xOZA&E#=d5i095G+} zJI41i#zv2C2vU|*a%%LkG&dKLES82;l`J`-@>PMdH|V>Y^uwU48DY>jh&WLR+9~+h zBeGaq{WQ}Ma;7qp1M;1^?P;ZXBN`x+T#u1sY+U9o;4pV#c8vh+l7wlL<;0`~{%V@4 zeKizkb4&7!FAQm>x-~#Z{nLgB=}8r;@rPYFixQw7QwIqbF;!b<#X7oFUER?U&8!xS zN%vzGzeFfB5pPhgmTeEs#14OgN-A)Y`P>cbn{DXwJ;p;f|MWUmkTAEVPV6L`8!Kcs z7o^~sFZfGU%=9rNdOMMzhbTJ*+Ea)%LhnF;;CEG!jMSOwKvp6e$Pj zQPwjvXQWHh1wAGu$7yQhcM3kP`1zb{5{h=NXlV@CbnjpzJD3oKK~3T-0==Prpu(amBm z?K#)C^9g?sna;th@PkF3w{A+5_c~;U)RP*mOx>ZfF*d?D)-PwsP+H-@+`G#FS18ML zY9+z$QRM)w0&j)mG`J1ZtnDq&`5NCm!IBr>ED&iK=c&ZL_*jCS3d25BT3;*;7$6+M`ws{r(Ll=$r3 z%yOg25LJuu5mgrd_bWfa{x(N`J zCb^FusCB3&X^gCfy(OKrqDRiY#)YA4IzT}Ur#}*00t3G_Ch%T^tpbh=*L-_Zr9G4t zz`qCp|00mB@VZid+Nxq|Hf1#0sX5Fw+gr-R)>`iUz&g)@Ird6uu(RGz>>=%sTMF(t zq&)49vwrcg^-}XPF3uy0g2pg;!0nK@%``a>m`7wXFV)puo48UwJAHubSbcEy5Xs71 z*yJJAbQQwzU>t;FXJ7$ zGSL^Thc*EYT3_kn)TYJA2+yocGpV=q+*W72lV>RB(}o+x)s}K%7p(_zDTA;QCU2zc zTJI%oC+lYf?Qw+5uMg{n+ZGm(nOz!pEf5~a6L~mm$`hraK{#F)<(HP!)_Sq}B`tWK z5O>GV3)&rm&|unIm?c%%?NHBd55LbCjo>e5LS0sFZ5e8_ox_O`Y#MSlgH z%3LD0Afedgvasw(ap$lSjIxT&@Ye_uaJ&gekGQ*CIYDkqO$L{&03AZ}tK3(S6w441kla`$? z)kSQr_cmb2yZPBg0nB~Rx+?z8l`uQz!PJ{O{NU_G-IPFs4RVmQSPlTUOoYm7f%acMq9h@aQ6Y? zYC{fZEkcS_Id$ zYZUZ9x+)+jJ3yQKBCH@sDEjZn+k_uqtSLV9N&tor=zl4zf5-i6AMjrqEi~O9bsM16 zLenV%Yg|*7W{`Rr|Q~s#`h5H!$Q3jlP{I78w0Q`S(e6)Yy`Jmw=X9k=z{GjM%<&&S{-N)m@&|5aK>S94<^5020`TYh z%lkiLKgR$6OdsR^D}C_wKkNUa{6WJ9zy9A~{&TK>=kr15NBN_V4G_DX5n%WJ(+7BO zf7?ECK*;+)?-FpOH{dAVzu-UMm;o+3AJ6=N`O^;A*?qLL0owki51#yeKmRlTp!v_5 z0KB)4clS5_!S^40`k&+ev;MKh{2Ej%F&1HfN}h7k~zhk+j8u*31^oGoBeZEO$ldjohs+Uo;^*he!o zouICbn4zh$i31@k8!I&3$8$dVJ_bY6i96_8nCkOe8Cw_<0)&wQz(G%$kbwcvBW-GL z517{DMP!&CuS9{^qhcKrWMJpN<2|BosD)KxPp793%WC1UVNF#X}Bp{hN0yH$?2GYU8f z%$LkvO~K5CO@`{e)!Nlb)E3ub*EQEhnx)S*7dUDkQ<|G;Kj-}ZIE z<=$1omGU*~HMI+b%Ne(KMhHfaunSA8lNP}_CLll$<2l(m?>W`_eXF*M_cvUL zRJW)UDNiYyyaa{gBFlJ=xcDZf@w-DOpZBV@Q7vR z(M>KKy5A5#nLj~1vAGGQ=9cBYme*(0%ee>Ld7S1iQ`JS(HJF@Fua|hrt*EUiaPg^^ z(#%9I$jpsT(N337mM>V%oXznTc#1q%-_e{xEX&q)%y|`+O}{n3%Nn{;~brz9ig*3Cd{3+)$EU_->Zy#CMM1;g3s2M zEl6R9Xl!wlP4Du8a=N>@ytTW7*WhpjSy`ExS+gxJG5%Gd-l^zLPHs$oTgh{mF^;dm z*6iN={PYAWn_j1TH`@me9==yY5UwJ#hP1PLa?WI3+|m%<(%`Ohpy+O0Sj5$qrg>WE zw#3CzLQa2ahj4?C-aOm6_I!JQccul;52PU4usw^%E21z~aOUI$cU61;{){q1=uLoP zJi(_N<@3q7gV24#hmel$na`QPTE*M=na}urs-FSQ(e3UQ&Zm%`Q-XkOr3vVZVie#`17sSUE~|@I*@(?Z#nP! zI6lq^o)y6*-TM_pUOM!8p7YuH$APkJUMw|k%b(Wv?Zs0mOQ$t(}4 zOoJo`@M&C0ou;O%c*8MLBaWVn*E)6Hf6daU5AS3B;Q!?S)OQEH2q(6^#DTiSr zskKk}?QFeVKL=f{wMuS=O+&X*4;E^qKY$hwrP-kGjLn@^t9=`8Djc@o!m75Ha&m3P zREo5xF9H7Ut>E3hjtV`3#!6~qn!#5R*7<$SR78JLvsG`vo6mUkKt%rvE>ShoiT+i# zlNLXYjm%{!X@gYX4+H1y0iyOtlk-#*ZmN@~cNm zyc-cJ)*2a{561VI3t*{FOfvvUqMtgz=q(%*?ChEn+$=j)&~VjD5cha`ml<9EhHLCT zI-kKTRXyW1d+cOGz4hL1iRzyTeoq8)sKdb=HT{jv7``FvrmRW#T&6582Q zkcQOxc~08Wa;*noBwF-v{Y>;bz6k|&Y-2qJOeBOn^DZ4IYMjQ z`o>wm?TqPZ@|4a}aGicTbsfrp>)HIv#@tQ{6o_cxQx!PcCEpZo~%<95dZqw zNrpDJ8w35MhLi~12(vTb7lgx{sN!6ZGSWX4UbHtpC}!VaaHChPcT>%8&!F|yO|1f} z(yQpH+TgVWsKQ9C7|ZwxVD*8eDE+bJ2$pcIim7EWrX>;S z+{2Q76{jg~rl|wHQni*Uqtgmly}V@m+=8harERKflZ<2&#pMeLs0h+|b86jx_vo7f zdK{KMdidwfVXL*6_WM=7n+K(uWnh`QrIf_Mz%W0kUcoT&G{u2I<8A0Fof}gSUQ{q8lsf_*f!vSHf6TI{)*-~?0rkls zwG83bsdn9p`p$N_LEpdP`YoNzi?&7TRdb9Dyzz7$^}wo%q$?qfe84P%`sh)pbz!J| z)pWqrbty)Jcq-u%x^Nd^j4E;W{8%g?^i_ebbqG#;;B+8~HlXe*p~hIt{v~7YM>A}{4XvI1aG<0}8KAi(2dX!);DS&~gzUFLzu2X?;SWDZh{?Ty=mC1(!ye*? z8WN-!;>#Q@$k{6Z-pfzcD~L|Q$4Ub1MdKuryO`@ zmm#K~m5I+c7ii~APTXL86JLQw2$c=cFIh;G8$cR?3X>3HaxnLs*r;7d_01FhdW~cA z53iF@92V)`AmiPiYJHL0eNt`UBL%on`Ovrn)NP=^vq6TlLGimx*};uB>|I1i1bBTz zNIoZv5q%3~{+vEY$QVlfIdzc8E|mLorW_)e5Rtslmr%W&fG?!OA$B=_zetKh%yNQ$ zksgJ(<@lPAq=Xpd1e%a8hdAZG@!iL?ViY>h~hrrm^#|&E#5o#szBJ(2hBK0EnBB#&(92EK$G6<9C zjpR-EB^5N5P&`)9EJh<%^c#t^SsdpM`xT8HH;1oBszF26QO3ca--j0kNhN;XM z8I73abl9rk8EM&&=Z@EO5I5g)EQC1M6{4vuXLMv9%Ar(qba@`mp$tA5kC^Oq_zjt- znD%tk4LQglA7cnCnV=XFmPFVP{Wk%LAsa@&A0&nbs94hd(RPdpKZv)7KpA6%43Lwh z3Zjb)u#;tsqLU5Klco2fn+))iWhn=NtD~tu|1@Aw6G(_PG~iIj`jl{R2n5~z>0G~im|cZ$_CU|SNri}f`4%E1R8D>|6F!(bP}Et5eg8(TOyvx9X- z?Hb7~t3^l`n>aYKgLXyf8qq4VPG}w5Fer?x_wnLAAn+ZUr+?&1V*I3F)dd0SQHjY5>4Om29qhg- zX#GHs0UF0o4*_aL=m4zy3GzLlNFXT%TA^fPM`E3?D;OYNjAVq{IJ`D`N~#M<OB#RHY?W<>$QXM%ykBk7MnnvGJG|ibjo4&hIG78oF)R-e)|ZMsE$KOvQ@r-mDYFT zL*JoxuhUfCgQ}i?I;LFQ|MVPK`3}3-=pzk@^JT+_ZV}(dpPStU=|rHD76qQhS1{Ap z6ML}(G}zAOfsNhCKMs#w*hhhd{S|gxq4N>O#uhkH&!!2IcA~2edlk0RlcmwPYx5KP z3ncgVE_*nab>Iri4M&334BrMcmlfZ8*$ou1_L)v+)(2Mq-x?R@5bypQ@2J3c0-u8T zL?JyO`B#Vzph3+AZFoWTA*+I-M-c5`gvJRuA+o~>Yr%R6{2w4gCIlAAAh|$de-gUF zPYV+Az)t@rTE*^;;_DSf%nlgrL3~6s2qbiet+pl{M#{nGyI~07g_v3(Ecm2{@4E`O z^G5g;_=<_J1H6ihPzGmfi|7o!SCU8jy51UspcGTyma}W{q<8=w>uocTB&`gPx@2 zyrHpwWM@NQ^JE|LnAims7?~Ue?$JzofPBxJln^{_nM{GPtjVH5Ud|9)nV9V7bLXtx z7Yv4RkO>-xJz(@L$C-Qua*)i%5sbohQ{k_GxZ>oSW5NQ9=bOz$?|>F5xzX#uKJ|&5bF&wT-4 z2uvQbF}#@lGix^rxh}3KUQQstb_8fwZ!G9ML?Cpab)JV_Ji|P^s&sz!9mZ1>)m;RB zQ$_H8fgNSRMCu-t!hD2%a|r$lv7v3gp}oKHdk?f#l#dmt540*yrv{PrmJk7XXMx?& z51Kgtm-KC%-Bw&;oP(#*LM4Ot2{l}N$XXh;ARJO#vN3MPI*FpI{DGU-+bi?;A?DCu z>Q~$pjQOHY^361Zij)kI`NF7Nt)UB15ltvTn$gJT$8w&EQn2UpR|o}z)oWG^L&f24 zMBM$RBzibZ#GgmW__YJ>sVGvTTaQ-bUuwB^>E`$Jz$)~u%B_P4VvmTuZErG!z6UTB z#n_~c4WO3yGb@axXN4KJY8OAD1q_SU1y4xDTpYpVbZ;T=UNUrZNWlqiI=Fgi;15rU z3WxnDH~8MgE><+$2;c(49z&=b#T0bKktbNWSWXm)uaO>Ik#@9L*v=P9wFI(Z#KJHn zJWOO{o5uByYrA)-m&<5GI=Qitl8GT&*(u{);y|-2+pTUvi>qjbtdxFP*&&%>eh0?{ zgN|tNoXIn>B1c@BE-UC^PNmrJ6w_6)+xz%ERzkO|Rr~O0+k$AdMwiUyxH!M%O!Sy= za1&e!o(8U}^?8L>%eW0*w7Ax9i!?{vW96b)Mp?KqAw#k3UnYlr+ZWVr z*2zV1&*7_T;m7y_*}9DPLf;!m;DyOVera<5%Dc;xtVT%JqqhBt4-m&%ttx5mL`vS> z1luuos*>WZ2g+z|JFs*rn%hw)xzV~p50vPRjr`(Rh2qy!j^FFT`%JXf%N)>iSy8vy zVn+jtVw*<2kj}3cTOkdkqDHeP2foE*r{Q5_=gsGZjZDhcnvn%6h(0wwwnFv5sF~Mp zj60>ReEuf$az+~I`AAVfcF2lWU4SHypl?q+<;HS0^>ks=>D7gok3~c18R+yPA~U%2VYy&81napM+3f} zxl0BHXeT?E2S`VVZD3Q+`D(WUtJ!^i{LZf8A_)SMV?DEKseL8)i(?qoa(s2gLv;aW z92wmR(mzk*f&;^E^Y!k(mgzU6A#Q1~3&&ilmGX z2Y`2KW51_Sj|n@Qv<7$A*jy|X{>&Fu<%4e#N*J8|MqVAQG0h|1AetYxQ!@O;fviP1 zIWaRmb2(*r9FHjH`}XxVs(jxxwMuQeQG1@q10_f<>zzgEeuDas-}%8Kc}L(Mr_bYrLw`U(00zntb#7cwq!{|r51E7!~WaDcO; za#aIK?h7O}WZ`*CTh4m^k~Gle4Ucn$1+xdT zr{C}7)z%f=bP>PAR9JX2>G=S{jkfZ(@j7_*WAfxEY_I7AeCkNJEqe@K@cDR;*a&wS zt)0QZI=*A^EB)lysm=kuK{z~m)7i)lK!2ura~fJd2zgZd=Yd`W!KfI*(`3 zmabl`)h1oiMlKxErnzWtHM!NMF81rP%~@~X49&zO%uW6R&&YOaIinEMHBpWuOfnWBp$&O>vCBS$h`6kSl$JI z&^e$!l%+9(JDb=u5bm7sV+)@0hQ~j5nFC#&X>s{PR`L8scpXpNJ#0K zGDMCRQrqV;$&;5o^W9pK7>;^$i2~VfRv!>fZ9>ZKgnHBnhVhvB(d9_ip23vbpUmgl zI|j4CkZlZD+@!0?dUQ>XaX7wsKnCxvOFM1G@ZA@=Sv1--ld7x5Pn&$97Be6 zt->=<^2poj35yG@Q$W0&*g&vU*k{mNK(do1fKA-$^Mp&$eGPlaNDZ~q$KEUcIe$|x z^8kc81VhI=qr8!mr%l4A@In>%%TH9=94eP)%}W~~y4XjM>^*+4N`R@@;{PB6U2uHG{U7cMkEzfSF(lJIK#A~fVH$qFsBc61gvmlTs7 zG8Xqx@_4OaQwHqTM*ql?;`wdyoB8W}qf6Hl9JrCvcp^NEaCWwy>xu691tO}SpFJ_B zfQe?mLB+Xl;*k5d_u=qFGxYv{7I%pcsa@~3)w4&M6kO14pzTs#Q6Kz*w; z7y&PFz`x$Tpzy*tLSu1-Uz(i|hQ$~I+zmH1-=}MxMOw}86j*-i{>1Giq>AIIa_uQ< zE$Xa2M3F!$qU(A0b@H}^@>B4o+M*m1l^`jVTBk=hZ~><@Tq44Hz)1Kz6bAZAP)zP> zPXAqsBI|uKzrOVg)a@rU3A?X`eTO3wJrauHVLg)MIrfVO*dyW((CwoO=@`LZH$<+G zk#qErQMRMoaff1wXH=nwVWA~%Q>)DyZo$Ld21HrA6@pU*ph2Pw+tY)i>RODoio_5# zkd)B9V&S(BQy9Qq6-AuP>}buCUji68xO`iiDa%cU*I)|E;lPN-*zoIUaz_2BnUpbXnxRNzX z=;IuzJZH-~FF~BtqHV+}T7 zlr=hI*mUwRmG|woCPf~Ir&zZ&H>yZi#Z z1N-~ERd9{&?h8dTk5oj6GZ!Zpaq#BLZA8dNL zZleor>gjPyk-vEyP2Spd+*M*a=O?6j+4%8j^G+W;koMv?I8JjR)1Um9S`psIjTr@9 zH7}bko2J5k-S9bt7$qp+b9u1QQyJ;uuV1!4m7D?b-*+|@QyqX}Bi1#|KcPM-pJa`= zOfCMz>5U5)$nO#h>i#Cc1W#$fgisyA*-56&lq^_NGM~Ok+S+=_Wh|950NJrJyDp^9 z1)V-V#`RM~w$sr9_)(e1Hr7#`Omd$|m32Z!Dh5U`XGfla(Rf6VRo6C#;R+Kqd@Bz5 z8}fnvD5ACSY4!|A*{&!K=q5+ko1Pltv~!GNI>uIg<`*Z4`Kf(vk4-k{;5G6Nkcqo?(DgGN;}sBVHzHtm}~85B~sK zbDx><3#O!FqWc7^j98}VA#nO7bRT~!0%5Mmrjzh%f-%kz+3N$B#64||>L?dRCY9i` z37MY&Z`C)`JnLxV0F0b;Zfvf=W}XLLCP9hYfqltnnz20jlBY83`dTzaC8*}+#vnzr zZXH|u@fZ)!`J!TXI;hsr+oGSt2?VLtRFfPYDqqy)@<=IS(ZrX;I;bT_t$G?LYFXF6 zG78bgiActP4l(wUW*bhI($^Otph39SLcr@@-QaOcoA9*WWonEC>CfG#gCBnrk4@+1{rHyedgPM9A*72>2}h$Z)|^H@VBSb<>}qEO*N~+G}+%#7!BG8wi}Y1+6-JJq$C{N zOxzqeB}B1Y!_Z&w+w)cINqKTv1Lvc&<#}yWBd&UId0QA%VW#1hHd(u4bf8ZoqJC#Z zUTs2Ck_<5LS5`NsY8PBiJ! zB}z+r?pAW&&7AQTt>|&cf;XW^2VUIOGL*wsEG#ECZyK_`AT6tqF>fn2owzl3tmmdJ zN3`b9YOXT&;fnOFCN;OaScBIsS^dJ5)f_i8q?w!!Qh>=csH~o~k3HD+aoOTpBUozk z&F**m}jmV*jjX-=IOvw0|U`6oI7$JPb!Cq9@xAK4kPx_QA<~0G7l7sO-zi(5FHn=ruB~LrBt{Uv^ zDp!Lk{Q%s(XV5NL%#C+woK;)u=TvX<&R_A1iL@*UEjyc^1%guTz2Mp|)-GL{tnY zhLcLS`KKUC>&kw3s5Lq*>`&25WzW)bA+xU+1~pbKHEVdJq7%^5cj#cwSt3rC(q+sw z(KHa;`ni6@z$> zHv2|#HxC%>FI9rAMG}budB5!$myEon<#{+RRiMg)SS!Eudq2nY#dr8E$59XQTQXba$k`b=iHHcRspz8Qv`DTkN{xh0Qqv7p|5elm!u$d0znpFBG-xyG!Ii}JgYypw>Z6R><*^zG)9 zF`iFSe+Ha36_9OKQ6u8oA!cFDwN_vln*V$+CK=j18a-FipH5E8(@P}F;qrE2=4Dac z*30(9*Vx{`=_n~HA&eDbH4#>g5s5075e4rZbgQL@EIVLb;mK=$Qik*brxebcrlT)dddqPMTu!6&>46ny~Q! ze?z^$6_D>4etu5E&5yi12YwMo0dZ=G!jW7a4~2Oxm8em$Jg$qAJrW z)2GX!tJ;Gfzo7i8!dFDkR43R>%8C1n;Zn2Fhymhm}njBg7+fYiQjTD5&97j^+t zuRy1uO7$?ej2AFsxCZg|j`|fmcCH1l`PfR&MpPi?`J)q45!P4<@cw@R@e)25 zjTI_5@tdQo>#ZLh73RWMS$!4!lJeT``E!z4);33pxN~Qlju!mnOc+?|OqE6$J%XbK zwY6sA3+>7+**^9b<9FlR)@qbq6AwUwOJD=+sZb>s8VQv^bj5jC5CswME;b-ADAT6F zhsY)SE}Jot(d%I3@xwT$w-Wv5|8(9Ejx6UhHX{iv!DmZAB>x%DZ@MIHmev2ZpYZO^%G z?k>wL50=hZ-@ZnMF~ZI zH&@hUeMY<)=^;=eb)t17ydC+sPs(ATwCH#(YUo-lsJJ_0eqBg81w|Q`(Nuc|R>Qnc zGJZ6*#5IZxPl&I|=%^HWt{iIIm#8T8d=Zi={;A=<5#?X*vrUv)xkXY_3$&9F>^AxQ z%Pjc>xAC(L@$rdHxdNP|M1VUNIa$AvUD!CsE#|xq(%73Tab!ft2c;mF+!kNBgbf*V zKkl+rADFlb8L)Ga<2daSDFF9|O<(1-f;)Yk7ncnBN==rt_yiLEwmR6>tuGMFR_u)x zPAk9GDEzBb)d+j@(usiyCby*=br(a8ExFlX<5 z99X^sWf3>^!dNYB@cnu-g1rKtRad?Sva5=f0*Ibv6PM_sB6@BMS3G=V| z_R`vV)~s$x_Duw+ZrqcK$L$SS?;ZEYXID3shlN=s<=NRsB{!(c?fZA{I#V6i8hkEA zBo%@!O$3hH;@y{$QBr))FZYQeLwW{K>rfS2lFiH*x6=>it>LZ$*{`vcZAXLKUGon` z)fNu%%57PCak(hO+n;xya=w^apsJeG`Z)ovFTv|pUv4)DJybD3?_u`evUDZ0)#%mv|%P^h{@d)eN zqT>Ve_R)Ki*%!nXsCNwsSBV}Tuv`Ns?rgWu&H8RI&l+{DOyc)gXW!&4l-_%)3dX78 zzW%l`A`|pzUeYO*{^ zDyZhsi2af~HDFXQ3ZGX`{9B!G=9HEV`7vzq6df8G7 zk{9WNiK7M@x{8d@LY3=dD2|KslIHCIiDrvvF-(v9gHx-pWOvSJ3^DYmUD+*7gqU$$ zyDY2`;|&;H!rtLg|^u^y`*M1R)J6ISI?9?

=`(|vBs30SGzz-BA7Y`mvuD0{mY#%NWgZ}xR=gQ6vor>##HZ^uL& zye|pR3vCra4zP1P<_CxgifH=@MMd2BEAWWy!sZ>6UOLRF3R`HW+V$I3^;;qO(#<&5 zyVff2DHKbkw9wl>XX|$=KRZOUhb}ZQ9iPi#J!-s|axwYev#^>seOGrR36_Sv54$Q_ zj)jb&R>mboXZ-$yF4zAx2SyKOmQ=)6-YAoECIm&k?J`hzz}R!7bU~ljsh7$X>)YA) z{>7NNUeAYDy)AR@LF1Wp8SeB$MTJ3hw63)wEfGkTI32Y_iINmP?d>Ftv>ASn(x1*6 zu7(?lT*jANkh0lTQv#)97sO`?(x7nrIY0HRAxXC0uu z-@~K(O8cul>tq67>S#WyyWb-!ONTD1+GjZ>ENnT&XNox3Wv-MQbp88q7ucu;uUD#o zi^h7Q(n70wk8I9)>K58%x^5rC@FKTRB08#)V#rT^Bmg&w1R!ix)673(OHir68&S?c z%d=|Yt70P}VxkgCq8NvO_RX6Dg}SfC^%lVg5+!Gw##r2v!QWm}L@Vwa6&n16SwRad zil7j$>85GpreZ~7uqFaYaaD&??r+tY`yQ-s26@BLeixm~C_lE#gyL#(-<+3rb3F_* zyp@*rasw>1Z`9x4OWxZ*5?CdFDK91yj2?)l5|64<%ejDG`4#oxgxsbcaV0>yu<**D z^pK+!RD5Tzm%T~&1m6>?My7wVeGekWOGwd8M8eL@EQp?moD{@xDu4QgP&;ODqN=Oq z+(o@70-S%Xu6ttm@-DA+G!DxG{4#;FmFXNF`AGI{L+pjuaT90gY=UHz=mLVWrNci= zxAqObwkj!XMQv++w0~x*a#$wA^*B*vv}HoROu6rxA=s{hH%~Q2I@6ggcT~?K2mZO~ zIfy++@PN-(y+txYwrHoBc#K*8I_~ZU>_tK{>E6{?gOiw`e?}4~Q?9}8*e=x^yZ9&G zF9H@3Hc`}P=LdAA?TRV(7`HFSRdgCMOzP+taIyi4Sy~RQRhMSGYrU---uhZw;q|#R z<+LTFxu|$061z-Hm!*?AznGz>5#XZ`19!#3J_opT;ojbrdHboWNm){CZg|WA@nTER z(BY4|fW>5ed-uueAdJQKQ4I;GMnrmL5`zAg`Ykp=@p=)RSr{-Aj{FuNwk;MIfGe2K@ufDe8Uc%*mizw{#wy8 z{nh0(X+PSvBl;21UJyE;<(EK5P1T;5ejPJ2FE1~va@I3Ufbd{vo0AFzhRun6|~fvDNP6Y{c9M%pBjTvl^2sE@T^MJbulX zdg=8N%mbTfYm|0cK&x(a&*ju@#glZc%C7sM>>}+Hp+wcHB!21_&pmkae{%~PjmYdc=T z8=D*Sn$7;Xj_O<0+kG0*K&8_;VaL)1W!~xm?W=Sb<@w01(<2LF;;f{3JP*YqjEp^w zz)fkxeun0P0VnN~BMK`sM0_4)Z-O_~+GspX{dDwe} z!FgiQ@kWgzu(w6(e8Tp|mp_a7`N!nU_3PyJPdoBpQBM?CcUs|i*bGeNl{RPCm=e=j4thx)`^tqs= ztL5D9iTPuKv}a9eStsJ71yPV{@bmKX_Jx|mOrC|JVU7jx!*kJKLx{G0ufm3jz2~L% zNTl&W5dyqH$D*pjDvI*m-yMxZCXe%Dnb?+1SA9K_iT?*aK*7HsvT_3--QwV%nKk^4 zMM1UdU&>ce=nGNhI_2$RWhMGz^!|2f?bRYWhuV_pC-)BZ4wX2e-88e2LZ+dCn?o)K z7X_e=G-FC3ivox0(CW}C`6cy^J*#Sv@o!KghS);I{&Cr_X^fb=MRV*$ynM{T-RgHK zHXCrIRBl>MYHD&(Mqz3;Tj*s;JcR1kzz#D4VsO>6O`DcEXL?kv6F3Kbw8Pp2tI~GD7vlY_;>M2?sgvY4zrTm$iw4* z#uGkf`F$U=pmaE|RHRhz6P-(^E~#I?h#G#6f9lUByr7h~Ha%kW$D6O!FX)W@d{aO% zGq+nZ?|)jhyU#<|5KtX`K7nRVj{WKrgcnd-R95_DSsq6aW>fY2o|+O`_d!u!VS0NC z3*XH@{r3`J0zRM#py(3kvXp;mc%%B5;w*ma5}tgCP}Qm4=Z_?9Q6=%1$y%B(YB%3e zmE9un*~c7}5B`uJp60SUJc`W&m}nkeg-xD)({=~l)Bo|)yVEWA206O0HM7J+Y*G@d z*ZzHT{Z&LiJh^+tYTE@X77Lk;j5#+#HJOe6kAM4zv#@`vYY+RlzB=7HK0J{xb`FmS zL=q%Q7i9(H>ILTdrw5^Z$kkP{m9F9C)DUD%D*eG@!)zp^UVGZ*$ zHdeXt*X`Q5e(jl^w{M+2d*kk|Gi!u@9nax~f2Z&IK;?g9UPa;z^=q{fX|P*Y(6zhw zD?9pxeI1pj*oy8*Sf6)YNU12-PD$$?yV_ULGBo+Ywi65Y*@-<|1zx@qzo4CpIK7UW zJq_m(eX+;R%vIv*?=ST7@{w!`82y!vC5wL6#OrOm{9J5Jmb%Rx4NAH#v!8y_VN)4& z)FZb*Z{>NPCg0lumm}|>AJMOQpI4o$K3Cg((irPOo_(j89EO@~pBtMNvz4O>;#%%A?a_(_-bp zp}}H7oZQ#f+b=36CMKHAqV?2AZSpu8>+br$op6GxRb`1!@co>`5uPX*1*eI#7Wai_ z97MLrGuU?9kcVDnTVZY;DnTW&g;CEA6vgzgIcQx;?*;WibM)`3?pgvptNOj}YYvXb zhWwn%h3zeUy(bXLFR35MYepTYHM}{n%&loxnH8cJnr=6AEDWkEFDxw2m*+|fg%SC& zStygP@2wp;)4yl4ZMbECrNC#KXuoWKqMd&BR`r>Yhxgc-k$;8vtNL%o1=VVn4jb=s zRGv7D|B1@nj>lXcG3Rc>jm*lsc;!oq*?fV|#PDzo{*J5O(Q6)aS{YORt^V4|mfq`6 znnquX!SA`eSn|@L->-CUeMFevXJ%Dy)$7VP=d49D(e!Xb-yJ??UalL=NAZw)<}NF; zZg?KwXRUv*IogKYYo(WIZ(fphMu5_%!mVA@haRHdBe}o5aSVUsA7Jx;cnp93{~Ba! zQ~m3A0)LE~_y5u}kvZP2^k{+KInsmQ@Tg4UqN)5-axf7qdTKDJue4U&}EW>V2L=~CqUruYTcCWoiM+p-aLFLP8{xkciaK^k6~u;WSU=ONUd=C8C1E%^~FxnPG?)Ny0(`ilzNg z!j_m?nKC>lM$f@NOl})>Fj^de{OO?l@X~^;G-aWnrXejYGb1}IBdw`)6kneXlYIZc zKtG?7psMP!(yFS!G9RJ(#r{^@-EyxOFK_m0o`|p(?)-6*?(f6*RYiQZT)0mKqbitf`&sVaX5qq8J6m!&=T(9R?Abt|n|R($4qn2BEQ9Ul%U7P=_3+813lHz_Jic5Qb(r7ZV71P| z-_zD#lv^4h46BK1XIBQ)#TNNQ9(1R5Z#Ou5Hm=1>Tsl*E+Ss=BgHRF0HU8PZHinrC8Qf|=ejSFY~2Q|;^>c23^ffAGp+W8sM_ zg2uhA!6#84>L_TguPRqoSDmJrKaTQ|Yr0FGOHv}c!xHJxtsX8eUTytns>|{CZoz{g ze%jND=96d$mAND@Rbz|sXu?Zbnx1@{^ZhJ-Mr>wER#FbqZ&k?re1paA!C@&`K0>Ky zO+;B-J<`A1Uw^dAqtZ$yPfU;rD=u=~c&}fQ_}{-MriQlF|Ero~==c90mEJ44-{XJr zS6gxIsCz?PChVVH%fQ{#-DBKtYRw)lR{ZsbMp!!a<|`d)V;G%y#-`sVI5^ap@98I! zu?!RxR#;Y+S5j9YwBwfnu7WPZ~16qY)<>9%WrL@OR zevM_09oj}SwB5#a?t!_r{(|6ozVFG1Q|K!Fyzkugx>A{6mEd)eGrXMd&SNHg%#8n; z>(0aKLg$?Nl{Q%=&R3(ARgW{g5`V%!u+1&N2Du=&;?P>Z-l&$iCp6CB#h;C?39R#J zvnkt$tdLuXgT=lRj>X&A)cugy-P6|2dp%l9Gy0F_;qg~Gs;;yOYBx3eo0cI*uW_x52?e=u1ub zLo#--|A%DsU_YuRL@~^-nt1jhHhps7`6OM@&4+wl5!w?OG5T-3K2h~j7aKc|o^0H^ zbfuTW))+x>LUbI8LXlaqWr?(I$J6-kjm(tE%YzQui=s1269fsR31y*$K}g?E6zqGb z-RtC!_a9^8M9`pPqtK(;J7-5Ott?L+}F!i2I0D(HVQ0&9>sHha3>lA#1GTh>aGR-x3BL~Cbj0QeKbSsb7 z*#WC_`=P_j4qrO0$=-$xelF+b;}hV87|)=HJQ2|J5!1qHI_!lxE3DVJB)BCfO5)-- z31&zX98Qo?7!#Wjm!1(Xw$ZVqhpu<`wXtK^+wPv;j*bIX=UZ>d&rQfL(jh+6BL}6U zgvg8x2KU~@A)i13kz9N{0^Jeg;F6k|ohCVzCF(RRS=I;_xe?1X^yurmH1JsZ@j1wi zl%i2eh@#=kn;O+L{_-mg7_Vrq^0ASUrjMF7a(dL1LEo3IjGsyLaxs1v{}&t1mdwgt zE=o2{blhq(1dFt)sY}2dTD#r-IMK`{Fc97c!=vJ(HoHX5B`&F}${C~Yx#C&zi_ljL zUi1xq6>BY6m9oP~XJZLxcEn>3y1~GrEATpK?%C?JqDrSvQ;6GE&`5>9Qtxk7LwoLA z;6K=-&gTN+Ea#Zn&O^-brALV~?7i#o&BLXZ^P@#crzjNZAL$)xmaryjJ-KPEufD-= zVCwQjcysT?r1(%#(s>R1H9wid%kU8VnG~)K!9!pX`SU3ZfyJ;0e+FOTIig@=j{JXr zJP41%V{m`0gNNc_SQB($G>ijHco)7FwYOiATk1qY&T#wZWvr4+Ube#~UY~sa8()5a z2Vm`A2g6&n+mcJlM0<7@|B8M`r(Dli9Jb%)oVl#}=bc*X^M@>7mTww6GeXRHpFP`@Vu@}EeS?%N?oIR$-&pM{gn?f({7!(Nks#(;_ zo;${|XOyIlTZWR))W5i~WS#=sr%9W&XwM-5$VwH+Uiiw4s1Wbjtqwi#>`}WZ@A*_Z zG?QP>v48ba5oo{ICT2X0H&G(aPpqWLL`S=px96>+_${KONaqHa0-k|5levD z+7Io4DMz69aTvNslf7FD*8C=}+Mfg_h79(jkr6_A0_Z>&*)u-Fw)(O8@Hz2Y^FR-O0-xi>BIDlh6}*Gr!xQlctVP_|7p-pW8xZ~;CL5+~ znY2}tPTHzR3oYC28dM)GrlnK1{){vDC(}wtY!@5a>aG+)4ecMQ?_%xqos%|viuWlV zvVC@g;5W`Gv#9e)pvHs1UjT#7se^+TcR8|l+wKQ$(OO+n8CWH|q$BOD$Egg)BK-QX z;rHB4hH5P{hC5ove1Z+{vzk2LFR}0=#VO{8XYvobFb1JS#eZUVW z2CHHDcHRtJNo(cIYCv&W7*{QbqtM-KgXdG_J4BD3E0JD1O&XP~!Wk-@J0`*-Zx zD{A$sXB*Z26tXEV$+;eec`7Dxo}tz_o>S)0pX&&`ALuDXU@uftCJ7!)p;)yj$ytK1 z8-wnnMqwaZP!{$hql~-azZr#r$R%G*wFz-L{7gRJEGNJ}3sDhOCTn#0E!3hqpqS=x*!Ul)#2pdY; z5jNl@qYY_jsN(QP;7G9!1u;<-H;*XiZU8U%h;Aq22OHI3kzjbA4~*00e^50!UJDsV zq2RC@%>G3kssT8cNU^=QzYQYMIQ7%Dg9kFUpla>IODe~&HubQx({XU}a&ldf<))Rs zGbg=_K&2uxV@r!A%XLMc4AQWJh*qW>5)?fP(frOgcGICY?{3?sM!&6BlxO16yy8{UXke+}}WU zWa|yGUlhcWI~>@0hwMnlE#wvl%5Skvakfg!FyJMv!#o$|`K;+96>B?0cO*OEaD6}c z_Pj0$ps(E~f}Rl?w<*gv(Oa86nIlfvXfa@wjm;`2&#**$9j63Op>@+y?CM}%;Jh2u zukO3J+p2s)hKRjZS&)>GJ7Bwh*}S=HY^Iy)WI5+orY004?b38-i*+09zq4({Ktkf{ zmNPLPPPa7KKc7mwhQmURy{*Vnus0Q8uvT3<+^Duw3LBq;&zS|sRK$A+i^s>?w= zMNP&XqYm2zP0R0w7-lz}6ORK|!bw@qJSJp!0hsTgQD@P)tBs{<2cL z8sY%9=2jfqG$+G)Cn`r72}PAm6m93=;VVXry;sV1A?xY|>hSt8cwJ~(Uk>W(d;!>S z1lP@^Asnh7?+9%kuCRw4N!0#)l454*E~Vl7zj_ut27Hu9GA~O()?ZQ<-TkXrpYX({ z)yi^+1e#^4)m|2+Dt2%yLOml6(bXD`ArG_v#ZGYVvE zVbO~v3Bgl%b7jB96W98`-K9KE|2M10CqzAz22L+aJz(giu0qLwmu?gi-B5CZ-fn5W zX(#tW-%R*lYQNgc{5PjGS@)(@Fqm5mu?7@2#3>qjFk{%MTYG5y_FfK?&mRcWHLBoG zZUx2Gv7L>c2__hY8+E@gWP^cNB~>s}Dn{RQuNdLbQ*+BOSkP z)vYr<)Ga;@&*5AmHCT5+%xwlfaRTBX*a*`PaxmAXvtX1eSKI1NYJ0g`wXIfFZNC;A zqTD%WrR-DHiX{8&Z(uFs5-8V_vJQ}_XG zysWS^wO^c!nl(j6&H6Lyr6ua7Wfk|_2c zSFqJ^ru-~?-91ns@(cALhx9PRbX}a;K>RBD1T%JcEMq{~tkO6|1$!YM^2ZH%g}Co} z+`8dE5SHgnkl^W6#rW#*#U*P~SAC9jPycACGQqv0D7kW3X z-J%9loAfzIqfVj<&ooR2{6<*g&lxW9f=% zA|;n8SOE`OJ~H=ySJRC6+unRQ`B17))0o;Sr&5TjbSv$LviP$(nydv>LJns?%h^Qi zVrR3#-3r;DjdAu__F0~JXbW?pX8V!7Wj50bboMRavW_N}M8-30Qgv2AYURKplrPS) z%&|%^BgS~>f<+S-8KvJ@sk8D|j(e&y=Ozt5elJXNAoc{K|tX*zZheic5$9~)cvIxNtE+U8-L6V`UqU$fB8 z+|G-p$CSYr`z;SaUkxZZhBp!Y^hRlFVAB5p1`Sc=W^Z%#Ph+})+_8kW?&fgAe z;fgAU(bko6=l;h82Hopf16PgEjPiJ`ivSmFUh*UKU0Z6J#_P-B%YV)#5dc%_2}N#P zGzHX+AMbYyGVH-j<4M3yN2rtP`8d|e_RR3l4Oll^E7D(sJ>eM|MMA)V-L>EO1_yb! z@2k01_newW{rK9J5pG^vC_qhUM@4_{oF@T1$3f4F_&)a7xg+~eb`41+6dTV>~}Y;pE(x#4{Qnho$o4 zkhXq3+Y@o)GrRccQLx}R=)b(xG;pM;TJb#LzpVx9UtTv7dK%Ex!afgIk%Oz^e;3XS zoQ3~1S#eWJe_i9iq2!;! zE(*-n9sbFg_gDC)`2usz6i?3yzT{3`@|q>-XJ4&*8J~{7gvoN3*3v0`K%l00No~@v zgIFclIs#Skr>lsf!RT68MMP#B{Fi9Iy?%iG*TFt`jaC+wbgSS;B18;?2+6_1$7E@I z>)wgx;&gl89x5StDt;#&m zHtCX?!a6nRE#*mv2fPtC9~s-On8yGEbRD^(0kSnRzKdKQUn66Kd+S2)<^hV9$$%f- zvav=st@XFct1jR${j0&A$vS;_KO_;C@$XB7QROMpnxTV)TOQ_~B(%SV)97$~(k@~5 zz#1`K?H}iX^cdC&U&B-2xT1frpi2Mt&6oR2>&r9nMIa-xAZi z0^(hSfOr7S7R`44?>ZZw>|h(6jln*S$euAT@h+(Qu@dL5N0>^H%i=^Ud`B19xnFC7%`tx4rqpW zz4^#7wpc9~f6Txd_(=I4#`aTQYCT#s(xfMKjHfEVVXL68UU$J2)HT^k+47Spnyo}r zyu2p+2wGqTNz||CdTvEkPF})Jv=tp&cY0o-QKoLpc(ehz1aAmpU?lk%Ny4R2qPG)i z*+LZZ!_+c`l_&$@i{|Yd6ww)*5<*gilZ2io{X=16C1OMxx~tCMP5 z$SLkTUzv9V?M0PVc?*+GBG+%4%ix1l)T|h*Ec5(z+Z}e3;BQBAdGU@dIj7MT26U$U zgy|uZ=Hp(*I&cvW;XKEit(}YJBHLW|>*TjJL@E65RZ;{1^@3e$`o8H??$JaiO6h(a z_5vRP_09fWY{(%>AhT66oFR9YvJY6;KZTYVHTjm(a}hFMchNt_1C1gY*6fe#`3Ob- zMjnU!aJe5O8dgYESO(zF5n}2ogo0pLX|~kVp_7GjiYamO`AIuZSI@3bh*l1!~d3!$kke_&$Qq`adxxSFLbGd*U-CR{Cl@rhT)G+Rs-2qIM92jnAL1#(z0 z+v+d^B1t$#%k7n5l3Nb-V>)<5gZVbJ4ed|O$!A6>oao)6=$-gY+Qn|=hBYCkA**vk zDj8YG`I~$YXmLGg5F>t2MlND6kRv3f7bNFyEfHNjno@aJPC12|3W)vv6NE2910rykdy$iDoN5zQPk%wdUq+A?OXSx$l)-l0iu7+YwuGX3? z_}&CV%nA+7gANAls({9zOzw90S z>7#``9;NEj^t;?+Y?ANEyhF61rm1gF98dF1Jd$hYEQGS)dEY26nayi+Iqu!N9DKHS zCzsOdPlyewR=Cwu@40XFBrbp5NiZN^k)|Zjx^_>-UJK zaK6_W_@WHH%Tt3wu;9w@G&=afp0ig_DT?=uSsP)mCCdabDrN#&CwRxAc?aEZw{F%w z+o%R1jp|Qtl(#i~q<}q4F7^kcfG4Y|Nrj*UFMbr#6I?X69a8>C_>aWB{D3m93nYAv z+;W!~xmu2qn}$kg!t$u=!DsWG)OzU_}|sk~*(B z#CeT`2o4y9E=VCFfPpXvzpA<;`-J|N_W)o!h*kz^o)k7cpwA-7a#{4nYa{eSp>#5( zld&dp3@dpZ4u*GOe1*h|-294_m|x~Qe7-Z7Z)bU5+Vb*;GlULCKO?^B z0$d^}--*85f-e?$(36qn3A-B%dmFS&jS`m(G_-Qn-;imadPH1|az%+K&N*RD>adDg zMLs5eb{nk?hvN^mzQdG#Nd>|J za!#SbIb{gJs60m^YBjih9Wr zw)ke*3L}$6jjQmPv#BJoXJdG(b6&<``aFk`aO-@{zT)khp8Y~=_<9;T!8zDHtZ+Pzvj43BCe+c@Y@>1d{v%}mPif^+=s7F zEzuC;WZ=MbIO-HVsp8dYMmX!#l84 zYPp(Znc6P$v~4!XwHxS2e$+Jq4NBp3`?iW25LFUP*zm-dup=Ve{Wv0I*amSq0fhrq z#DwmT#65!5|EdX%p$}hE+`{=hNkRHNG?kvg_NvttkS@!(wz!5lw+ng=M z({Vja@4@!;4N#BQ(j9#cYq%+cc%6Y#r_<_iM13AEY`3iaL%6{A7b=QJ;RF{tJbzTp z;(fDEwp0?C_Lao%OFu(+7Q(%;rU#zOU^Q4m^(pp8&R>qBLEpVfPpDNeZ97tkM1vlTPX{_AX5eZWRcOh?)M7$V$ zO@lWatPj$_%V{*l-F#Gwe3dmr&iP_MVRH98Bbux+wOR~O;4YWWPbAsQ0wE~Zn1D}p3$$W$9^def`W`rU3j z$&acNi|ghNTxaWQvLW3gy}&OUWsCAr64u=5JX-8GSa-7Jx_}@YEs$W-jMI><3tOWG{LpAfRtx5yEnYuK=mlZUQ78jRBw1zK;dS^}>o+{8NH5t8iM3fHM}{ETc3%bqgv) z`QDjMDNZRHQWi$qZgSW}bXxzC%$Co_7TgsS7L??-!zINOtwWYB4jWt?+{6Jh5wkHQ zC0#nAf{qrpmY3_*K%=J(bub^2pNe^7p?3*PCQ`AK@_V;ANW77Vpx?0Q&OFB`+?J$ z*;h2#voJN2n}ybvxSX`}*NT~wK2_>-wJJ}Yx}=x2HcG@^*bv;Nm1^J->6oh=D81`DwCJj$=E$?bbDE7jQ`24)%1GiV0FP@<5u~M{l<7SH8d#Gyl z^hpctOvqul%W^Zj4yZMmcS_Cpx;w1GpDRzz za!sY}?%&I68*4;hB4lT>h3pLW2M3j4Uo^3w{e>7y5EQ6xPzRpKN*$$AtfVML_MuD4 zvr={;cpaU<9|q(8!Psb#f$hq!u6~zY6?}aTbm1!)JO-xYPeMd9kfrU?#WKL$+OJtk z?7I^m)U(-!(yj*>wzV5zSSYQK$$C%0u@>f%&oXG5KyIr!p|$x`2=GR`4{57)6+K?+ z+68(D3>k2Sxk9PSqKl4HgSL)TSOUhEK(9~J5^1yA451f87L-U$u{-Z7G#IRHHN&5f zAf>DJ4B{jdHfT&~*PtOZZ9P+~tRo#JY7juj@An}QXiYYWuNIE3%!z7ft;DcNXtKNe z=s?+Y(RK0!r_;)cOAAwfKs!;D&l%(LIeQjMMxkZsdmj%U1}4)|2mQJ6{j^|$6oXKc5(sh`=+Rog0l@EC;J-6sW0`j#p!1xED1@Q}cg9|xSp8Z9W z<@r(kRPL8z{4RcTr1_MoUz)+Y@aDC`Gp9vZm;Aorxc~Xjps&yxepy=do$woe2fsOG z6z=OOV)>cCbP*ydJbU_OZ>EuD+KjIWRcMeE(K=Noz`kCS-R{X(_umHNHJ&bt*rg~Z z^`oMk)KoV&Ssby;lQ*S=(p=YLj)lc#`Q%PBTf1zHrHxAOaUfQqQE6#}cRbnw#$d07 zSF6ydbTDX>5wd1FgK1bnkOslVkBcQ+*7^5Sh^r&`yUJRa7oZfdsN#D`)72%!XPfX7 zIA9e8^|&96>01*(bYM?TafJ?^s(L;Eo6#%RE!emiF{4%=|B)aMy46)D-&b!M$)Dnc zo=R{rckM|H7t3Orfga^|QMi6QO z)oK1_E&(_Lp_apXG@9<^zQ9km{75&(FG?7v(Wf66*L^eJ*mm9uoldhkK8swRbT(&K z*1Bm#k{(IJ=&cnHS0*!C{`bET3|C2c(TqIe3QF_w)>Zg8PBE%WWwRlnB3yTTxjkbaBdmveXUPn5!v z9Mt2b3X64j?$mv{U6E$3!1ap1|0xZ6x*Y8N9M@BQnwHC|9rF*(E#&(gw9f5^eu5PZ zu=FQQcBv;E=Vx&y$syruh(Ue(Yup=uAYwB;aliUuzwRr^*;%C{JXLEIguJ0s86-?r z2Du_DgUq}2=_1<=x`raCZL5R0(jDq5(|RM@0Cz7Rh8^tbWbf`_G0+0J#5ks!=Q$h| z$gW?j{NdW6*!44X8bUaBpl5z*>GmHsODiaACQUI|E3Kf&40FYS7iF5Gpj;(v`(?ZC zA#xs=i-hq%LoX1ay=b>X#p)iiS9jm}xNN({<$${k?5(2uJTy`;o6AqB;)JPMs=KM$ zhm+dolBOwwu&h|g=&lqwx7M*+a?O~7B|Rvccc}thIF=--|mS;TU5gLe=GI%r5zresL9z;ytC3MH!W_DPTHN4#^xoOc&a?@SkOh|58 zQ85s!EVWmp1dT9{qmig?&`2MCWcxw$k{hweGv1)*PDH>Y`xk4 zCkoLA3M|Ya2$qpA1T2)hn}4HFZ7*>!Q6!T3h)8`*aHyY-ueYDKub0VUBYoEZPhUS@ zTjY>xW^83QRZsK_?Z0V>{W|ygPTCh9^$cIhx|XlkJ&V3&{636tspUWc zOed$T%dg=4L+9I>xX*VcupvA|vPlvWgS0cEU5rG{eN`TCzt0nt->-uW=p!e(HTNYK zOhVJZi@xxtkpB!MF=}HQb@qsQ6C#3_WjvegrBC4r6yqBFIV{o2%Q=1Q(DuA2ZAnrH=*}{BKB)q-PK@j>qq- zU1|X4NtnTxfdgk_XJ>7lZkL;vk)D@pmtiG>Fud`Z2+gvliI4yE7qF*^S5sJcz2mi; zACOD1V=pxV*c}^6$=$;pFAfIp)<~qCgM&~Y0Wdy9I{70+pY>f#y}lQ)c2r0Nib70T zwAU&T9!i@O+QhCV*q;6ZYvA|sJLg8gEA{26JBmf$)1cNH`TBZzc{)38^s++C=*2%m zU(l%j;e2hi!4eS+zNgad%E!9{A2Z|MJX15i@#hH{#Ed8W5C-q2X2;nRGmg^YLefKu ztkc$^xya7T{u3{=r8DKGoCsT9-4l|~Mo|}(V9o_0J6GaHc1siTKqcbD!snlzKz6@$QO#F2@bfQw1?q;CB}5Ai;35FF51_BRQdr@0ThO4KO(~M z1;=*Sp>bLY?`?sijneZKI)oJ6L-U>`RGORY2xnqGzak? zax>PioQvi$%S+a5E6L0#F0@No=SP&9fa)NGf)V567ZFvITUu8p>Le8Wxc&lfk)q3V zp?fYZs_ zxX6mc^U()To_4xZvYoAyvz@EtlcZrf`>LL|61GHH{dBR0str7OI>Q{_y>N7wUDT$agx4WCKFGgPfW) zdr#?%U|CU7xu{4&v9|?idS<{f{-UB7CGes-yege+xZq2^(36jUU$6VOE=s~S@KYO+ zp)ACen)*Z#rM(ygu;|h39trcmrj|(X8mLQi1A$=imoy0qi+tgAX)@ylE&*GqYzdgs zj2{$u?S{2=(7RCWc!T;W*w4+-J&p%oe$@V|M?)zYZp*OU{M6UL489?KNwX7#Z}kN!jQ9? z?3im!^EDhdal(MvKGT5o2xV zWNndYwI?ehA}&po7AHxG&WX+m-zgMbPSEU%YjChRUn7b4pwRY^yzuz&_~?i@6p7;e z6Fn2XB>@SDDM(AtEws$jGqd(~b`Uu@yW9C&``ZNRqwg4OOhXB5HYw72Cy$+_zi)a^M1%I7mZ!75NxzMSj=lwalhj5OfIvSM2;5s~5O8WAx z!1kfr+Wy*7c{O=4Q$Bjiw*)`OQSTyHq3pAxTido4N_zvwa8ST=p3W5agwh=G6!%Ar2+Ov_g4Tkd$y&t1v8qLhoJ=**h#nyB|h}UVP zUCzP!+KIa9L|j5z$O+5qZb+w`q}`t6c&xhVxZDZTIQ{ZHb&IKOn<@{=hM*2^GFmBG zsJj=h5uT=X4oZbiPuX_#$0_($@;A6v?!5KB)^7GXBd@J7xi-?;#l%}5X*(jf5W7vx zMRH;)Q1QVmTE^#h2HVjMt9<-m29jaz7s^9SCk22Ue4g z1FOSuxZXCqyTWI+*g|K>Z);5MedO$F@4XRe3zNK}QLu??Hf?Q>0smyW^Mr5-DvHTV zmVW$*>s8xxPNGZNZPUU!7rN?_X&taXQ1>E7?3=})-F{`pkHD@=1G6lcAtXM);GEg9 zh37Td&Aq_fn+u`Xlb#PEijN!{fNG5E^urnUhhDkSmBsY~&djV)*vB5K;54~P}kjVzSVv{FJ`P&0B-r(ksKTbkxtjCc~tgMo#w% zjfxJ59jM|acbPpPC;1{R0uF}_@}q1uh7|{%k2$=j+Q22ARt}<0{Swh|f@{|5mZ6r< zSKRV|>wDHxLCeP6dR2i%yGQWkFiXojk%ZT`bRt1N8fdJ30gL7>wlQ0+15>+bu2=M4 zGkRO;zN|fnX*f7ztTf5GOu{!y)LqCh4O9)Ir(b_0EHnJp?T<|h6T^o z{vmPvxnYmF{mXK<|HKE{RgX%aCRcQs-&@)*4=DaKpfuTgS@1a*fj`%PEXoT8>m{!* zaIBqmKvm1y{{iU^6(nR!h%`F^>6Au5y1Tm(0cntKDM3KG5tI%I0qI6sKpN>1ehWS4 zea}5{-+Rve`OjuA_so3PGqvXPJTohQ$YpXxJKSRMeVkv4tJSP}S~>NW5YJY1(dP;#g>f^8!I&E1R1T&3tL0`-XOBP@RBLYSGqh+E(Y7A zW|-u*eBKKeVhO{8TrhfTogAT@7W_i;QbJnRB1u;9BlYJzN!4iR&g}UL4etf)_S6+8 zGY+1M)5N5Z?;rvj^VH2Lkujd+FmUV@_(}52552O014w}QaW3&C41&SX7x7cGOQ?cy1Sn-N_tM`V}3HzD*Ps~9n&4qnt^9_arC<0jW7^_{aq6W zKXdNr^xgH_vm@vazntZ@#+%VYoT|!=$m>80O1phcYuRBJo1a?fTW*cDh_m*L7H!Oz z-h@xc6~)9>LC-&OzC>TpsU5&+dSmyB(Y16tYvPDURw?^wEPt-&_$J{=tx%AF?T+rv#%XgV2@v#>(uLdtX%<|h1zgv;hf^?sW{=y48 zh<9ra6-T~Y@!Ac{|C(Y-fJzSW~l@2tLPXc-WYT zi@Yn684~;6d*$Qjra(5cd9OGWTqIP@5&h8ZeGWCm=85t~1XkXCnkk9-=4ncq*OP^N zeotZL6vx7|Bg=gurrao}Y83rwUS@pbmD?0zRakr$=O1a&*?X!2Y^zF(kR|Hyz_0@C zgdwzs)Z$0u^P0-q)kS>I>YNVGiT1i4=~zXcJ^El-U?!n?T=WE1FnVEsT=LK!smYOI z^COPZmZRhFN1QF=v5#X3p6oOHJe;wf{Ry4~q)UeV9?%z`zf&jFdZ%yCP2i1x@-`#o z>8ZB9<$9~ZFHL{Vf>2 z-(wtYOEw~&RuYvEea%d2ujFiSerjYzUmLi1MFByedK))<9#nbx&12^Qcc##8D7cKe z@2zW6Df_zMD@82^I!&q*9ZD8L^it*3g$ErsfOFrn-_dE97Hy?-EDM{q#^L+3vQ?^V ztWU-~P$7NsHL>+&u(#(T_?9}o@C3a>&&wpXTuqcJk7VBuc1dG5nn%*B)8=`&M#ww` zl8^?awPS0pj;@H@&vR7vTqrTyxR3H$9l5i+axrgQJPJU*Bt=U#dXscjk>0lB_nyg* zMMYCfDt!$fQsYlE!G{&bIen$P^B0+Q5Y6%4T)3qJoxdQ&p?LbZ2sQdN2J zLl2lg*`Cgso_urG+UH`rP&pdiD~6cSwLKYS-fzOXDz$>(Ax4CBPwl1xj2yg*@vTeJ zZQx$=nM-GT1~YES4S3I{cODqBV}d;}d?78qvKC<$!8EsvGJ{~ou1|%P#xmmGY;F$^ z$IxEi~kO^WOZC*HMjWevh5s*-rZHE^sc_4Kx{ei z{B{s)jIBbEWyI?#7ZmbcZw2eTA&d@}HZ>6ePA_3bP-Q7|ykpKx0&;~b`}i}FN>cyk znj801I%J0U#xHIk#@%$OiKnT!josk#g;W%3`}z1DQfCma!7$E3bKbld<+)&H+m+Hn zlsH>&f!~h9Xj~in*T^Mq(dO|g$$ORqQ!>Cg*fhtijmo(Gs3;kLPRtU^U2|VanJa57l;< z_jSPAaMqY&U#@!t)o-^K-_EaA=RBF9L&=U~uPbjJx1(f@+D=Y{HQWzUCv=yiy0lx8 zc_e=JC_p^u1C4dORGE3*6?W5G>mB#4yGX@%?ddkt9IdxXk&EXyCA8o0K0Oo+{IuOQ zvuGY!CRmmFviK=kosvAv=SVQ;=0voiGju6mMbBhBAvaxI)V&raU)(*_SHPe?J;_F7 zKrj%?;>?WCZ2iP<$DeLmy4moAtm%nznEn)4s9eILvqNhoT}%pj#Z}NbjhQ`kpArRG z?+zI@s?YWsJp8*s*S(1N3M8E)|9ox~JU#tHn2)N*+g+pxrQREExgu8|;&nI|_oX8U zKI@ndMPTjb<%VGo42r@+o3bbLs8sdJzStEjV2>xjX5aIs`-}?IiCHxrVwQhDb+TTf z#@P~x#3|Y3`930xzu;qaI=x)7kKuYL&`qsn^NBjiFUMkrI&Fh@t1@!SZt=ua^_#h$ z1WGqui9ZIiNh`yLa5s0yQ~l+T)5$cIpd(CInv1cQncg3#d_5MU&R{bM(t%z$+qcyo zE@$V+2MO91_zLErwmhPq3-?lqSm$9GqmRg1xIFFfc$_lomc+ZhE!l6{P|}&5J6(!n z3wLL(<|47U1wj-ag*=NXN<8J=RKhygZ#Zm+e9M}=`OqZ6XGJa4X5K-iw6zTTwm-Wy%pHe4qP?K2Dm$l_9 z!okMJVdr4zu=Cis-;3r87G>rWPC!pFexLK2RzflL#TRt@S0kWWS98KFR6n&~Rp*GW z5PuvsdM&}K3lxpWCIa0Jm3DcOF^BwbwsT5Bd7dTvjeImtO_!)Ul$>bm0yJcpJn-Zz zkx4^nI17`7u9laBj)%EQH)5}%<>vcbzg=)>8aYIU=Sv&d^`^kM_J>3Z~AMNJH zIEOCXEq#YKAoq@*NO+CHg4umr1(`?S!3QQcn81TiGX3 zvK7@BHGSyBE?dG!o9-Y2qkBUDIxC<^a< zo=&avO*Lly%$&pe`L-~QtC1y6jgz|KAZRozm?L<3f&haNwoFaN$g#Y2WMadR*+x2a zcJX5NRS4&P;S<(RkE-YH+G~+bSyd$3IWQ8EFrM6Ni3~>S78k{gqPfShT|N1{oMy_} zv$rs5Vpw2v%OKc=)-ovS@ZOR6-L*WV_8e0Zo~@v{?=9B8X>Mj1co-UwzggvnHqE8o z9HvUSkIEJfxtu|PWAc^a<2b$x=*rW&ic6_cNp49f-6oknQ8|r%0q;0J6wB2QN0+n3 zVuaY3&~1zL_K)D!3mR&s4+L7XbA)_%Lf8F<-SZC+N4Fxv>XNlg@XK@6rLFPJDm^*sjjCJ6P^W%CJ zylBc`5L>?+9f8XIwrootWKvTf?YG1*MbnG#o_ZT4l4NV*cxMp1w+aQjK4=$z94*Yd z_Gq!mOblH!!yUo?{En|aX;jsBZrP)|PY!es?U^5#+7_brR7O|`Ufm3BV0c{jiYjC1 zjZZ|nkM7sB8*^Ca#4el#*0BcF=|!>}$p|@BSI35sh!>B(#S{dzPWjhtR~5^WVZ6#q zPRwf`qp#nY)y=^XUl`#2Ccm_8UcpQ0vN|C^E&58p)fDMrBnh2C=2)33wm$UJS>I_4S>1T-ENqLb8r6o!a(Q1&dm&g_Jza?8(|i zj_T^XKUJ-cW0zCPl7n%(RSn95%7Z`K1H5FXm8DfzL%sGL<69ov6Rk_E79(^n8SPV< zpoW2A@oMV=Ro9RE=+Y+(`8L8*7Pe_onoYQdZg>$%p(TTgWTzx|TV+b>-Wr zFxI!m2L7@&u)u~QxIi4BAAdpN2*m$fhI9VB4C3X*W)}r%Lg8@Wf+C1rOm+s zbFy(m;UF7lD=Temetyue`N4n5?@tp#5L|3v1RMnA1ha8-ga0Ho_rEU|3PrGixgmc{ zh~W6Y5<=Nve^GkEP?%yXd)9)jTF@IVo{6Vgi1}#3$U)^qI*$-oD7sHuU*7trc!p60b##cz8Bl z)(+w|%5qm~o(Yx>ZrUJ)dm-*ND?Dt&dl;jAZS_UJJxl%9b-36WmFe8|WFKF$4;T?n18(sOR z&(qijR^i_1gh*AGPKV4&f*Kq;TdcaYASd50V>G|XTbBk3e&!B7RY=MR==$mIc6zHXi6wMZg}J^`TmYQ0ZnF0*uexr)rW;%M=C<$YF_Qg zy3L4H&O$R`Vh!tCkmWx9^X-)z^IzTGv%aX;$vy2@Q&3b2fORd-@cP3(fRthDXT=k zn=s!h)J8h5mECH_JW60(N#PWw67)W~fn2z#Hk*Toa=5M6t(1_J#-BqobuXdG8Eat9 z6@^3tv%`((0c#wtyfsRPj_Ux!VY&1Wd5pZSP06Er!z6Y1Jl|*JFlf)9TY9k3z!GNP z3z+u#$fPo^o!VinQq8Bw@(au0HaIqO?CdNcbyfeVus!7SQ-j( z@`cST=N6;j%IB3f17t~1p9~xHL5Ejy%mOGFTEy=Lxjfe_C>u$q`)c&FBqnUcXk_lI zCXT&DS74S}E@B}rDA?pT9ifV4dhyyT;;WnV!_;0m?d*@%^NxuT-`_DfWsu%apb1-+ zl$V>>z(4b6---29;r#vp-5+`9xy{2=_lN;fL6*s7%-WC+wuGW*92Z7y;WYB^6^3HJ z^Hz~}Vr>OwqeBy3rHkG=OW5hTKd9f2Z!R&U(Lq4EN;^hYeZbWpw50f9(21kbL~-As z{rP~-XOfK`?E9y2uSp$xzoB zmGnw<@GsRQw=@oxaP4d^U>4q5AthhwUZs=x%*PuRB8kb76|9iXKtmNh!?mQxNQt#1 zf@EVqahHefGm&D@}jaFXj1a7=AbELw+r<_ftpr!-dkUhKT&C5am}_cGTcL-f=QqzahSo zsz|%}cD0c4sVw$d>9gU}QU8aAwI!*IhAa7r3gjtCmAhV(n~h7Ms?-u zKB&jCP2SD{-l=|1JmZN*T{u#4*u8MJr^DhJ;;sIA0WzS)ScRlEpwV`Y*$EPNdR{I~ zzesU43=BII{B9!!}qK+PIRPpJTXE-M8m&8ZI5bo36!g@3?z7G?s~SW7#cXJMI+IAe^Des8Yu*E(`+prX21O@!*K z*nHnPwzbokz3{3SVgM6nEPJdHlPoLo`6)^jC61!f4Wr^YbY8uM%(Gw)oq##yZ^bX| z`uV1(+@$<^ujh1Md%-~wv~5?k_S$4<8HFiR=mpsI&H-{^Lsn85r6j)!5n78IlAn=Z zs`U}cLt^ZH#|Lo=2O&Nyt=q1!P)2e+5rc)6``bA_+8F)hAI?&h!($Yphne(8;}|yg z+v;9;5q*+N{`BQxw#z3|k{CapxQaWMO)$AXxH27_`3S9I|rDWT8ceC;mI3vIdSsZ3GqZS4sEi2@o$Pl3-7F&Yz?f9ta zw%(8W?{8M6aT}H!QmsE?c|!7qpEqq@Ak_e*ne((vM!BaA(a1Z>6Qo}w5mMJDev7DA zBYmE2VmgkRH3so4bH=Ep$|Fk5qt?_f1c&a-kHZP}kOXT+6h=@N6f*cc)(&xW_yn7< znh6v202NJ!u9Y;VYp+gHWCtG7@#TJCQ9Z5Lv!sc3Y$~Yq%fn!}c^ zG*1g2sabiig`O5CRK=@mzWw~Jdt`)d-w@_!gHAwFUV57__`qa`+w$A#ZD}dCfag!l zzE?XpgVwZl6&FS(f+b$+ydTkM>!P9-EsI~zF2Zv8;)$7Ty^QymOE$sC3^~ex{P1nQ zC2}^ahuDxw;NiB~AVnX3nzv}TN{o3qYi!-py-${^t`S;|p-FVeVd3s3GHgO9kw<0) zGP&5jn!Pu4V_#$`bd*Tl^*bAVB91!I@M&hzZSAZ=Hkt6l8^2voI{S>sY5|{uTHe{w z&KTWdwE_9t1W4g+9i*2`7J$ln11jR!vIMhe{9!N=74y0F2PK3O^YY2=bOT^Q_a$RRU(bUcEz~#wQY&Yrs zC~d4p?i+ShCd;u>I5!krR2wT_yolC9mvtU_^>U&7-cs+rpPB%s?_B}8%o}@$^)Q$6 zjz^GzX@Bfs?r5iTMQqan-8f6y%nj}2rn@%oK91#7M(z*pfj&(RF-gd^a&2>WRK1m= z=hCwz_WXQ@o8Nk}mQF(H)v^21eC5m?-}O@6BXi$DR+kmAPplB!38|Ad|1QG-zVFB2 z_Vu)YO6%rAZ2Z_hU83_OSC>UM2CAVpYYmmQ8yF8Yw!Y|kPDLCBJkOaW-6mts@0hxY zt!v;wP+rQbOz7}qveG$}OrJ3ARuWFmV{WM#_kKB6p*n!1)<>O_()C>+EW0`q< z?nqA%OM@ZZhWotwt?Alt4!4CLoor$*V7=TwdY6l!I@nm&R(~>DD^tTLj#kA$m`+Ik za7E>6P`*OcJ#Dg$Ge3FB+o&rQkzZVIyb(gRv>9u_ywdvZv2$o%0iKNA;ncyMy3~C0 zowD84M^EMOi~I8IByR0b55=aXIk3sejv2IYp=Y#VJ5U#oetd!E->{t_|C!}$?1#yB zXP%CyE?RTg*&NSS=5*!^H1=Pki6=c+4>?MdhGD%@?Pj?;UcYd7Ks%ehF55S<7>6Obc9SkwKHHXwO0IlhmAyj-Tzb_y}y|gpcJ% z;+I`|swNg5kOwqscDT4wilcc2@7{}cS>jioXV`Scc=oz^jzKagla!iY_CY+6*TnL7 zW~c6$WKtHSw$St}S~BzV(QGE?TqDJJ6SqvJ=b>cnkMP=!TtZhtP;$C^-to135B$PD zaQiB7J7Wx<56?qdw96%Dw8Xx~NkMn8_+eeZk1 zO3K=KOOjPj`lvyUA}!kwhfo`BwH`aeh`+8fhVxEXUGlzG!0iOV59|f~h$NCx^>s(i z$|BunjZJS6qnc0KDew5YNokbrfVqQQQN9*rQ}(g4(8wmdM9ZZaRf00UKVLkubJN90c*5Gx)Vf5_YMf4~7^vKN z{*-s#4pVt5H$OHgdxzu$GG zACF^84#BqS4JJW5AOC=J!gL?bpOROO<@e3l&p}qTq~+c7_BX?N6bDeQA%{U>Z@Mv- zmPl%LbkZW5z0HlYtmzYikI$a^I!ah9Y|~>41fPM~(vBZBXtv&-zbz{{VQdCTIe&y% zZdwX)I7WND{hiM9ZDR6*WFlQ>K~VBCJozxycx1lM)AWo=T648R^3C8IDkSarWWx6J zw_WdUp#kR`7;SbMS}QA<&Jz)k=*fyv>wev%hHV;SS0UzIwzsfgNbipVKZWcnFM|29 zp>C>7F}ba(K|mvqgmxlJQueNXKtiX`I>Pz(G7d@*49i=k7JkV zceB$|V(VskTE;A-dLi$?z&muAz5Cm-_T$8Q>Jr8@HQbnLeA%vd?sK{x%rX&~%k)xe z2DDs+h6TACbIzaUr&P>LXwBBBZ@+bYio9|2|dJrbpV~Z16YY3)>1zQ45_4HSAmUMnoJlSiYxXc3hP#LH_qig$kR~ zxtpwrD37ojpT%??``SjQUU4~BYIe_=+@maZ|0ei|F54wnwN+5uI1u}x)Mrf7gypD# zFH(XdJ8iw~myD``-ntulayg+T(;Ym9IA6{c{kxq`pY5meXjIaiHWJ-?7g3@$?1;~Z zX7otNn<@iI=2l8mQZgEa|UR4@EW1oN>jrSJ?Y8#x*{C%7@Ppc5Fx^Y;3l{ zl8MrqY8{EMt=ds}UX>x)XCuZ;Y`(?xly4hqF49?l9(69-tz#ht;vRBZ?w_;8r{Bgc zTsr7Z%)aXyPzO4U(nF&>-(BIDy^;5jVdv9#qF`7u$y7*;P+map%=6X-Q_MB4l+as7 z3>Bm#CDiHfsR&{DavJc_oagu8l;wdS9nVh)ac&8Jy)Te+ex?JcbO zBc9{@E!TSDZf6V-BYjh2Y<3ZVRT+E1?3|vB7V>IBBtg(@~ zzObzuNb@=yI5(UP!ifNJ!N6=>+}hYcP7Xj80GWdR{JD^gjV+L)CXnZkE5PSZo(1Ln z$*!P4>T8At<-Ep&*PlNb8IGC!nO`Z#tuL3l|!3df?bkbMDsc$4&YuD zuUVWX7y)I2b3j1|ZVomm6bgbsIM}#gTp&&k@U>}x-zhm8IQ=lQjJb^^HoMRd9;gIj ze`Nc_76g#c2ZpvbCg!G$*NpEs*z<>>{-G!sAOZ?l2Ehqo7=<&Vwqw|M{WS`xwuNCJc4a3~um zFg^ie5gP{_kcfb>asKUQXzXTaqDs25<-*&~80-G>sPPAx|HV)V0jd@bL4d%3`4F5yO#}TMc-{a5K0^c;_BUnPIy(XLjINP6 zFcvx4I=KHq=zlR-LasYH@I(W?9?OA_0|h2X1kjPdK$}It|E@vJoUE;Mf6D!X$p2=z z1STFZ_`Q-r@MWz1;0DD;u!GKb8mv=0e~(=zlZ< zQ#sJJuPgtbXtdV1`3p00{#N64RKSnr$^RV{0O7cPuK(5kf07UeJWE1>;r$Qc1V3Eu zf0Yml1}1~+p#lPDg9DEFKc@cebLF2D3+3Qq#Ho^c5v^B`jbrHKb@IVXsWibQnnx_X?Pm`lQB-GH-hRWx`?e!_hleizS&D3@Lv(D@MhIpdGfR z#<~eKvCw+QA*YAwt2>}OJDt5eO9IQvDxv9ZXz>1@9G=op8EQ% zmLddTUz?m+3+pFPhjnp<8xo}R~y+mrUov%5a zImXDoe$O!D7Ttxm){M^ghTJ9Tx6QXcZc5(BZ1j4Puf>kLsi55w^sMf5H@#2Uc`M)Y z8|t{NsHYCDL0n_u#fPF9N?6wiCH!E)ar45&){kcX68GYi>$dZH5Y~=KB~s)wIk;AM zSZkgi4;9h-8ca~8AD!_jyHAq4)2cjt!8aTVO+sJ@1@?ue?-%|A&Rz6UN7Mv)mqm? zxn*bjkh)-Q@3n+3X!65**<)#rlBz!4frDddv`%*KEhjwTUA~~s;g~hVs6x%D0_VZ0 z4HdBuww{-yA|_Q*etB~GA*K9kGVOD(7hQM@v)?#s%FvR;i64%pd*Lyn9zC?KBj=>X zi!}(Pvm<{uK>3y`NC928hG#%^N~;$A&QqJ4`C^zZ%m$Ky;UtGthM#d|J{y#xf9>df zbmlBX+`qqdwsf|#tcbZ_HI~TxfPO|zOyq9*vBHq-qC3IcimLSG$NA0S#$1bbj+HuB z`!i=jSdR8z#pegaQEGQRZ?B%pvSUW8XE`i=8aW%smx(S7@e)UfC59sc2&ZnI!C=gW zgb@APVPgJ)XB(BOTh7OIPK#MNXEW-$>}f`a^a$U1>V9ohI!r<{{CkhRBj|n)?=A^wQDc*ck|09-7>7cZz-x zQE$HC*`9o-!zK!K2`M~1S42O$&!<18*&6quj~uH@@`W4I-gjCrF+@dsUw(;8t+`oT zt9~zKN)*5F-LDuCk=tL}VcId0n}JDNiV&y1{7&JccnX}4YRAsA7A6d79}luA+`&s; z5?95?pvm_zc5E#odRii(){t#wzUa@$=C}c(wLVJxy=Dan zuojrfN*~dDX@$Z_JDFS2&w+cJ@@#PY&QUB@C!fL%BV7j+E~4}bJZCZaoUwC5joNo+ z7223$K@}`BB6lU6YU+u!1PVE3<;gk>SGx;x;y6@L3PNlSrPC)Bum>^kG(|Q)7hyZo zr38CXG6>ctxm)O{E29bVEUB4huLYFs`mOHVcQ7t}X2uezH#!<_Qiy|swhgo0WXvne zcqaW6Q=2$fGo5@?Vpn$Zz+Z$g(?OXdLV}?37)k2O)9T0hTx?s-(Pt_u&Xy$Zh!;LI zpup?`b6eRXVTBFGV#27e0fsqTa3vj-$6qIyBJF#~uF^RO^U5xCT33iw?)ksvuH{GN zFt+3$NgV5<%6DuWms!JTq-b{`3bu(TlljaQ(eM90&_@)8vbyBRMry|kB47^Kc`Sw8 z8h?>C`;rM=5L^GG(0#iMH?{LVhIKYPSVoEL)|(1^;_=9I;@$`Q(t_Ng6}u$CiVAzV zd(WgT;UE)8Re9p^4C;38Vp3c-Q+tt$M?-*qMAmSxXu-rA5PxFR6WP{P3DSi+_E90D zj@Nc}z>z!JCJ5L4X5o$mgNK-kWLKb0jfl2fa$ICzC&1+g%K12KALxmPq%J1i6FRQN zMJ=sGw)j}6cQ7|bHUC5=QR@a0YpuzRUAg-r&Cly@Jhnpr!qO3-aJ<}c`k9s}Vsj>L zDyY%H`$KZBp{f34&R%0L?2G2(RoIempo<%PF*DPjRW2`CQgEbnZosEp{zUdgV6L3< z@Rw;6moZq>4psp1Q!=uiiO1!W;2nqg9C2~MkD(u<+C)+<@UE`H&)BbCvk;T=r>_hl z^-A4-&glZU?PQzQJPbA3pTG-A$9o#2i*p@J6A!udLMuVw^ww&MY z-VykX(BKQDP|@Wik?=)r+lCd^3Z2LVKB?d;KB?!XtP_e)oM?!ny-6!?)H>!iGp~Qp z7k2+uoVBwk4cxwSnJvq5hQ&Jp$v80`MLu&qY2^?64pzPGtrN!fJsE?aLnyx;9(BrZ zq#W-3L;$4^O89&UqII6%9l5-5*5bENG^#y5ipp z_!cwRXYDb5pgm-6LLt&;$Q(*NUZa$C`=ls?%<#=z8L^_^#|_76p+jqocIzODgR2xy z@9eeR+@hM+^C=mz89QkK`6|OKEO=)IN!$`LT*B zL!gA(a&LKL?PlXpAkVa4|IzNLEB`w*zsr=Wo@_GsgL`e3dmSI7t+cnX{OaOmHC=f; z%e%}@Oc}oy@ucs%zRR%n3oTDy=%tFIVU&RqMTWv+cgRWLM6-@#`C9^pPxIEhx#?R{ zrf!)JYbCBJaOOJYmVT@+(H_s)=w#W9s%Y!hMBl_qiq!FX)+k_ANulG;UAhuBq&ErU z98QAq%V6E9vGZbC2hRi4?^*l2RO%UgwYt&6XN;zHMSMXuH zfzQ%}g!iUhF6|LYQz@2fb--;e(dYyuicePfOD&cbWr^0x5ejnE)ci;#@{L6!W8 zJ0QJVBQbOY6`ZyYO$(I32cZoynN?O(bmNiSM)RqBeRl}-myO76pBCN;55q?)aU{d> zymch|P4@O2Sa^RZY1}`#n)Pvp3)`SV(JhY2r_PktpHkSmzeEpO%=Wzt7)>R4r25Tw z=|v&fE^h!V$D>dk7n5a3x5w+Hn%ilpF&y-brA>XPUK9^TARgk1B$0(Y0pYiV2|hui zdnVHj-FRh3Jsa6A$(uUHJ3=uPCPh)0Qmi@`Pg)aeqOPoCs%GVb!<7T)t7_{lGsb@P zBtGzn<=)$q&E+zF+;P&=YPl_ohsMFTqMl__I|wb_$T+@~z;!DqESff-MNQp5D66h% zjL{L4HDm|Ln>D(=9poIg+F9fojD8&hlTS4$xsyw9vSmN# zww0$*P487GSl;fiKD*^EfAA%fE!cmK^c31p6(tqa>e3?T9DqP`AwxN&7IJfgO!ZWy z=+VYTzKpJ}C^~MiCbO>9c%=>zsRtuk%Y7bAGvp@F$m{YZLgq zK6kI5GHJ28T$XddJ+^?h{*nF!zZZ4jw;Ssa&iSUymYT{jxe2-RjSEcT-g|Ebj!6wK z!VXmYvVap7h(cBaC(@ixBbQw~E!TV3u_0Rdw+rvCn#!X#P#v3raOP%NyJ%5*j_-RT zg1iS1@fY4mVfEO?fA9)kJBR*vIsKCc{?04-bLsalUO^b(S^}JE|J*AG1J<9{UO5=B zLjC#q(~AcK0_3m1|JF5cAlS9|zsoD_j7)UR01v4H zz=17)?}Yl<6#k(te*tYUfaY)k{*7y2E#%rS0qptUg24YK0Csi+JY_~EKcL_rO!-?H z2+*CM{ptV4STF$l{cpefvxER6yl$|+2T?HKHvT#x6o6j0XJFc{)biv2%q3>`4>ksR;a}SraC!jbmJ>kYf0pvM&Xqs8Q!o%P z0hsHLMgAC3e{Jo50s8*U?xDYn^MEesF2RVsUNzAGTaK`4 ztUm4$xV@X24!B{#&E--O%9MZ+S=^iCys5{-)9Wo?Q)}E45u2H@M<{JkqcJr8N`o~h z1<7mSJ`N&8PV~*e8?Mi&DHwU*ftS%1^O()LZ(TLkonBbxbH3~{c>8{OdVJ}z*&Unh zZry6dylHJR)Rv;a<>sOH34f1 z4?{)}BQ;I4&s_IMXUy=X3zWmEFTD19N?YEbrZm-I`F9U}BH_iL>8<#*a9^s$EY1FX zqr2;VlY%_mDEeHNN>GuAGye)lTBJG?(TAxBcQbuVd-OK&!Q(HT7mdEKhu)Ls4)pE@=idzE9j42eYuCH#H7$N87Is-~9)^V@n3)XcdUxP|I9 zV#p)6^u+t`&!iZ8XR4`(+1h>5>zX{$JoAg^r+T;ko^LR2+1b?LYlG*TJwq>Mzpc*c z$F}Nm-%#bnH1|l@nsPDjrV~DKhejn-d|x_kfsGh_!@qj0U+Zbd^tCh}yTs12nSPj5 z+c^@)fxpVWMfdv&D?uAMDnZc2+{om!m^sT zaOAK=Sbd+^7?d&e-2|f`oCsLH#dhM!d8~%K`qrjMudzGY?<&wx8}7TcQ3u8G5im|V zy{(mtV61RTn{bgEcRpW~=mMop9#IDPefA(g;xs4@zzz(m8Yu+A*ySO`Qdr_Jvi27hbc z|4`3-p1`QH!TGroALu*sjR&`0^Lx2EVX+XhE-JlvSM-V%9r?LN7hSsk%zm<-1M#Ev z$7tC-S^b_8Xf(=Lk$nxu-TUSP&x0YH@)(ZqIMZfOTK$8hbK@B5MqBQi!fH~HQmwXDMOA-CO4aeI&F9IGrD zCyh2Q2oB5|aO(Bv-gfP%1yE32#^MNRn(I;V>^#%5x?sm!EX&uD#_aLyTe*0VjY%w# z^ws?#>Jt#;JbfMw_jX^4@n{e#@dx}x)Ln|4Nq@K%1A|}=#9<)@`;Kuol8$MH0$v*l zHqyRDMt66Es$oVTtItCR!nR~|8?Lb|Ch}LStXx>D6b9_ zuP<{YHdw=;_+O6Fzz4zv?3D)8zJg+cj~ueH9{cBe=@&W<@yK7`hDpbpUGRt}!Hu!# z@+t(^6Fc%*h_F1OZ9lgPr1mPuzDBBPHZzIQ#`;=|a39~@d`s1@;x(6!p8oD5H-an{ z3oQbnnS`cmdGtc3C>lG;<@In+Hsr1D{aXo{pfj3$tu=F+c*_}X#c#Ea*~HSg+fRx* z*2}2VazJ~J`vl+-Lm$C zYh^LE7lJ~x)@A*uZYskmfXS6f(!X_b?{))qtrB=%0af@a*|q=3PHl?`tpbmR9aqR4 zTYEu2ggUPx_I}hY&}9zO_(BC#Gp}$(L_YG=IS17cVOC94V^dn@9k3So*`c<#x=XUH zl6F6Jt)Xj%t@&az0CWV`Ql!1BN2w7RN=nzK$-}=SdGD3P*z{dY?00=d8)=y=$Os(} zB1i|5P%QZ)si9lUtotG!yhazYYVJ}?O%_{C1LQ+ zQErF9Thr6Xu0VIy<>R+XU|woj^CLOm8??|jnu^#JEi@Uz1!hIiI4c{GV)T%;NJH&g zqh*kZ$$~7Bp#pEooH;qZtR**;nYOsVk9S}Z2aH5zjaTpexW7AUnNejquD$N;ZvWO5 z$f4U4rZ`zbHM7IwWLIsLlu%b**vRyrKDWu-b!hT*+dq&-&&+S}MAq;KZ>%cYGze{) z|8ZLE)Aa&#(!8jtus(&S3IT^i9f1xTk`AMeN_o#J-oxmx(7hHR&@RAQfGd62Ru&T_m=^RuNM zuCyukr8r}q4{Py__fy$;wA%8=@0kc1-&9CeF(fq4driG(^ELk{pZxCogxC*c&8mLk z!zU%^1^4@Fc!+}M1eByVsx+p8u<=F83_(F9>jHMF@5CS*?n?AZMxewM6c5GKUQ9#j zHig#hxD58rjO=VvsUdZ!RdCB1$P}My8-nTJ>x7{-ltoHtjz0wm5~F}jvdh@DG^mu)wew4S1jjL16NVKp@-Woq&4W5%g)kcY?PTx zTKTDcX+F~<0baaamog(&|K*U!5M9&b%?k=lpX2?c+$||r6uX5J{c4N|irgNgL{br^ zq&VWG4>(42OQQaYI_NzkUUyhn_G#2g4&cv?Cl|=o>hb6Hh!7@p^CAmTAVcfPnK8w) zYG(CXGoI#gq6os9j)J#l8apa)U=}0|O%DWHIa+{579hH&Ton==Fln>*4UYXdlP!_15w(n;33g&a@EBBh=gWnNu_j z;Hwzq$=Iu0<~Qxf_ug|#t+Mi`L?lnFjzKFR!2x0HrbZ1%J#5Vo_S$BkEt0Cayjwxh z33BSHnv4EI&~X0xgGr`A&|*^NhPRc$B$27(l?AzJ4yD(P0 z<+;Rh>GbZmL9OHS#i=Etxjjhgm;#XrP#L`6OOx4}DChL!iOQ6al!;I8IaOkWBXPE2 zd>@|r3cLD>$MGF;l*yv=Xxht;!D0cbNNdipkn&~14x z+iK|hmQUe`y?K_%zTob`oXVyv+^yc?E$3aj z7OANC_~JlmjEi?TN7~F!>%6#6m?RCexQvfTquAJ--S%60+>S54J4OHjhd!e2)uO6+ z!GEMI3BI4m41km07ZP_2NcEw&tapiOrE z68!9&8R^4b6rxAufz7(Uw{b1uFR?Fzb#=DI?@aI?ewE82>lMpB@gdlc_9+E+VlRH9 z{j~q`iX?d}SMZO#4*J`r^q=#(A8WgR<#oU!_rK$HK(OBrP6z#k(*eOGKfc4R+*0jdS)|A!hOK!EA>rU*Ec3&0@2F&#j3J0}40-~b!r{?B#<7}**cSlJp{I_f&w z85^4GTmAUgB&=eE_SQT-7Zp(jI<$s~-xA5a{ zHbfX4*s6d4wtE144h{oivajt4MCxA0$-%h(qirAh&Q7-1#Pj#n3gq^W+ukqL3IT`~ z9M}AD;RzvGQwk)83{jagELEDdk@jn2sK#Th8gkVm(f6QvXO8wi+^k3s4 ze;XVl{TG@Fv~kY=l%^J|YXZTM_+H1QyZlt#;qS8_d{msBdSjmaQchm} zh}UU~-_Ck+Of*4Dvd`q|88XVqrv#H>b4aDHL@>yPT2OVvgWK>wDt8NeJBqL z(z2}ylW=NS$iOslb?ipM^wyXrYTayqc2)WI`J&r^C`ObH|N8nuGAm>L2FH>inReNetV@fHD@UG?esU?b4uxoIf9p4oVr5SrHx&qM72aSz0@^Gh9F51* z2@9VFjD5(4)4BB<-YuI~>Q9wX{N!inP)3vrG1M}l1Oatjek&Kf{k;`OoZb})w?a1Z z)3SS}ii%tcvvd5ySxY;f87Vo6!v4$k-||F-v}`3y;vj00175csS3eEGw{ef4!;YE_ zPX}vTh3lb;o?Jj1VSov=1wgIbq(^+c9>B*yyB%1+-pZS=YV--%w=*r{V$@rG;2$nj z>`VqCF9x-JtoZo4zwNk68}maeiCUiR+hQ)Ox6LkPEOezPx54devX#+#bzbD^j=6r& z#L;H!TM+F^`}x?o!_6B_TZ0snL_x%FUT~9JOO;HI`n60Z=0&6Bqlc0&1yNei#WsSr zjq`Gq&xbEK%7UqHZY5ha)hv~VN~)QXvmh$=2^_TQR^kFt(DNJIRqeZiFy_xjO>hM< z6m?P_969&y1R(f(LoRl!hNid~uI#nnmbbsM3T@?O_FTmbDlWMqreWo&XqUi_-P$`= z^MVt6O-a@dqt6_O&}3ly0h3kEi{hwt5Zt7s^~P{Z0PjPucfL%XzF9=TjWQaSpxTs* z(71!?SHhxIyMcdSK2?xmF=DL$umN|s2WV>zqhKx|tbM}Z2w4GZMkVQ(`?ekClzoK3vn z{#CQHlF}gk>$%imHthB!xt13mZa`P45K?;iE3=$72Vp1MoCQB91>hob7(L5pX!W>D zA%uMgSoNtM)F`oAp#9xcl71#SX>j@m%%BJJJcKCP!jck9J`EGoGgu*r2)9g0frpfa zt$2uoZ4Q~T3iYV!VIVsLdjYzw^z;CuW`-a4u3{(Qi(UkETnMSiA|Bs-W;s~$xS~v`^QpDy2y-%Os zDKl?mM|^D-eULcqH(Vt&eAjtXp(VFN%vuG{Kng;eQK57InM_UyhA4HPw->;k6_s|r zH~Un!d-W-*^6zC=fCMvO)r3{^xMdeAp$5dc5D*j9HM>(x-hk zRBRcI#35h@CoFm`nbxqB&DC1*^b|+^3o)+wG4cf`w@0BI?8l}DCwj>+h8~Cc8~V9W zn$T1Fg&ymB94Rs6xBhf!GCx7$;w1iK2k1oX+ww z7Aus?=vK^bx&EpJyKKQ|+{@Pe~L z;@>x(*c+AciP*^U-Hfx|A*mBiL+w{O3VlFRkTlCzd`lz+N2mxSY_|j@rP56jl8oe3 zP@ODW5N*c|8HI-FHOqXNE@0dD!PTfE;pFpOKv20A5u2Ukbu9s^y#ur4E0lh|IGR$H z$@)^Qjqo)=5XljWFpdygd0Ruo^P%`p6A(5gUhz}eq}ThI9S;W{W4b6nD1ivTALumS zZfWw!@F!gp18hY3RU@6LKH-E)t@kSW?x zG17Nzm}zls(sN`(T2ii>=)5$Lv-Dt`#Dy1!B13kUe*ZC+!+MN@+ZtbjEA$R)jN90G zEXhJ$=)sUlT|X6GIMP@N@oQdDzFQzp6*@*UH=Z$9=a;WJu{x$r4jh>x%6f@X?;X(* zdy>v#b|ma+4=#n@+eVUTMs7|NW|%!p;VNh8Cyg+nz9I@?rGx3gyHFtDL>r5$cyN3> z*k0UrE5azU6eLr8$<%ZqyV7$+>W8zEtCA1hr5_ffsoLiJ4DR_cQWZ|r9Tb~z6a}Z) zfIZE>?QW3Tj_ZPahC@t~ZzR|jaT56^ltzO=%SG!PHyWjhFH^NYMU2GExiMj|MZ&Os zS>ZE24sDPtm4&0<^DSrDXF5ojwO1xzL?b?a5#<@{^?f23m=Gg_TT;cOXub;pEiN{r zl}Hq69_DQ63qa@z>9d(tZ8FbR#-cKR+(ixj0Gxee!07QIOJZ1t>oNp z#gQ_ELuJe3uw+AL?DOGX*zmP_IimeerIxP^C)>E79^K3myFU?h5u^jG_~Hbbvis1{ zTLMJ52RJs$PVmx{D~-jwxqzOLu=)s9{B zyREyZYKsZ5peWcE1p}!KGQ6)EmP}j%hEkuJmbL8Toilux3Ilt%f(hhuSMif42NLOXCfI`C5J=nUvtxt<|y&F?+~pTMZ2{Z-EcI>vuPhrieJ zKj`9*dLEG52gvN7t-oOg^z;09`@g&LnOT0(>j32Zq1S(SZT_k5=Er+}#jAfv{@?o< znEu+SpeNYfHD?9M<`&k-y4+}e@a6A zD$cb5I!e#R*ud~FpW*LgO5ZickDKx*v=qyqHO8M70@`c=_5*)yiu!(_-|qUqxgx-x z6d(})Ml1aAj{WuP{+os0n|xXRPDio)S%Cd%tKaqf_dv*B)XAUiYybS=FaYjomcJ2T z%s>7|f8FX&sgpl6X#HN0{ISF9pVoT(aFYFXBmY(>fWP^ZwH|G%+L4Q_NS-$Zvdf#y zQ!z+Iyv~buv8Euk?^4XYv-ft3NG)cyQuBO#zZ-MFMLsbn0>eh2N|t5y>At;18fnusjsMmc@{>8(GLiK zH{74H0h%QG)3uwaP&$(b(1mzp@I<;>;Quy@_bnA}=5}Yf{ruhaY0GYuzfJ*4*>B?Q;{DI$HgDIZG z3){uZ_3_5d$7T{^itL`*t$WzuF0K|gUXbB~=6p&R@C0Nj%enXWpO-6~w>{l1h94SE zw$+5AUmL`0+DGLzQE`V%(Tf$p6%&vV!<`jDU{rp?SEE_c=(pA%=|)*b)c5dwfTAQT zRUIIbkYgFJou}M{Qr>6MpWLXbA%G}x$ychllqeQ6zMoefC5GcgIS9Jb{t|r|+EOp5 z^>kXN)TmYO3LCaf=KTatP~-*t3ZWZYh#gZ9^CF{I4b-IXX`Q|HfrTrun0o*I%~&!_ zNG>=J!x^Il}CcxS9Eu3Qj7oN)4^-S9l# z_DI~Ciy?g0)&ez4C8*gaOjeAnRlTyES7Zjwe{JnoC^6kvDPy~tfSkzFt+l3e!kiDP z2cjI>o0xs#_+j-+A4r%ZxTt{e?fGFIhN8h&#>_AX2{nuqpj4kICDNkg@blW)dSa}SGuIuC4NoA znv5Q*ME|WeM1}20#~GExe#K#^*kETNAfI}I@5$I}8z%u8hPQhfYqc;%z#%BXXFi6DIEXH@Ge|L12v_KwbY8~~g8~QmaXp$C&c27K^9!LC7i08lv^F*F zS8j%JFIS$WDvkd1l)>XBm2X=0(CfQ0M> z10%XE3;%ZH1zveai)YM4GL__tN_stqB`%6TwkUF>Mcdr#%uUp7By zAFE#;_;z7ZXVvx7#Z6!m@QxSpJ@0MYfv>6Iko(Zgy1z>$C9J(gPV9{{G4ahV&?5^% z02?9QU|0w#Y_AuQkVciLh?J7q*a#!I^5)A=&ghQN#S6Q;+CE|{+ zoi@v&=vl-^NS4+`+ZD$h|Me;oSTP62tvhL-B+U=%os_0iVKASst|x;?^lju(7I`=f z{gHIaLopm38r7yLsTGnT6#tDc6-=q{_SrORe!`S_AT0E`6U^F&5{=O6{I_4{)8bd4 zh_<#!Mzj3$)-RW;rVD0;LidQ6K2L>l%te`sBVy=z4vT@ku62_Qq$uF4NSLj!bA`!f zn03`mO;(mJmbs0<1`IIYgQzT$UR*fxv;AtZn{6!hs?O6stC*+;WFjmH%pYravJ8BP z6htun+ucxM7Au*~*F@i4Q|0+o9^W?VO)=q_8Ky{#gab}HfxZ1FhkR6fZY-#hHKXvn zS(;(}xebgKd<>Ko(U65apU6GdRS?OT(Zi zHE?MQ#pN~89Ky%*=TZv58I23F^eu!W{qRVJFu%ZSDE$lT(k z$|&M`+W&4-m)GW76Q)lfQCtPZV~YvKVHYTAM2q+O1(AQ1 zD1dCoZ?N|F66FVC{86F+QZ@fKi2~@x{~=9&w7~yKn*8|PuSoL`r3nKgAk_uPMX~~N zB=mqvUq*l*49j=VEP(e02kSpIp)%2R&;_Uf?eFQ6zlG~RbnySftug{~Ui1JL3noC) zi52jHG6V7^8~~DK0@Sm!(*Kl-`ki0af8Xk#1Mxq;`Jd1M0B-*64*5>ye_F^2pz`k? zX@7xhfZ5jnxR3?V1Hle3ZuslM-=}~616==+nt$($@W;^qKjrBkj&{G^e82EC1Hf12 zXL-68W6)-i^|HJ|$1+C5ugWT|Hn34{;X|MKdSO!!2Or7@YyM~|vB4|5^Aq>^#$csc zgN3sJAUwR4b|3<{0N(YUd8j9Z-Vw)`C9t>fKu@~-BjqrQ79U>>Ihs7A+{uNlJ5slV z-SH4M<=3g_GV)(XCrQxvO~boJ=W?Yq&Gb*(N8>mURXC@iad@>lH4lYsO0Yb%x*a$X zPDFz0P>4l|f{=$A5c?rce)L9Jn;R?`pI7xQv?Rx?EpMWxuFyF-*#05SUs){aI4>(IKtt0J$|Xc6^s@%@^a`pLA0kv2?ah`* zdUR7Cuvq(S&2Z3l7MMQaE2qy z70#l(HoB=+G*V8*%Cng_TN(RdAj(rvC;K)${9AEb(Fv5=2J0GjsT*JKpNQ$SF*Gql zp!{fqWhFP>3GNe8o)^=?i)qGnB$@N;QUrRfNRMt&@neWX|taEr)!>aO5_8 z&5ov%U3^j%xhA4Df5dd}P4E)xBG5i=vg1M#W|VNpZE&j~Ik8+hYg6(E;8M_BWz*r}!c>RPLyNtYjKmJK2^ zo=_WMgRblWYj4A1lA+f{PR5xn3~p^TK;@AM(jnT}4#d_gJnk?L~L7VYH?0lRQRa-77|@;q3Rsp)~##G{NeX``GG9l`9f zRJDQ9_EaZ$EHpMjAp3RqjK=K5o;Z%YMVDj=r~(#w&M~-OVp!$DwIkJt=j(ALKteIk z3PkQ?;`$Xv3VGd`-v+?X4U=prf(PjNN!zv~&!&?L7iP~S-e63RbSQWqK>>n%$|^UK zS#8dR3dp%t1!fQe;7csi)3w`F7n^SK6gl0J5K3)QZ`$_L5J?Eu46Bh`zU3d(RaTOB z3(nMi;A&i_Z*&Ap*1{6aQDD*w#VYt2b&|TQCfk{sj|AE!yG_mQ z_F0g=@dAQp@4?h6tCoES69Vr%2k&$9#3#t(bXcrTilCq-!k5bn<02xw5TbE{T(aE{ z=X*>P5V1}kbikQr1K*-KIugZ*RSBad2`ybNa@oE_-GebgL&rcQV)ZUm_dyuEGv{wv z3hqRY3Etnbk$cC0?5tNGG76;piK@`6SuOlL>aH81EmrxIYh%N5JYT!!D=eUVJ^(xt_X%fhZU}2graN#6|aHrhhrR>zP=R zAx^xF@39DRS-e*h@qsc*ES8@7dMS0_=QU%!k>Ui#ha3a6nSazACmclaP`}h5n|Li{ zmcyB7sZJufJm*rnPj2gi)#`I+MStGLaG)of2=>hDiZ37O{?3md$#LZ#1SK%t`G5&Y z)ZC-UPi{4SCs6p!*O4;Aijb9bJcU<&;O}Jjwq2f8^6kyp>_9*qnn6wTSuhmKB8!hP za`C|vT}#X)^e6&kN9Y+NBZAL3O@-_!V=CM&d~G9xD<+$Q2+Fu+Wt`Z_2YNHJ~00w z0s%%zeMcQYyc19|0tg#2vjR{E5L)~0p+(Q}Pdg5O5Sq5Rfw`W6jrIovTm3(WLVs-k zf4NmgdO(E|06G9=U*8Qdzqg+L@NxsZ3@EnvnHrqm!J3VMm4U7uz{Brv;sidX9JHa=9Y`B2+zmbYmqjHHMu1Fc}rd_ z67{TnlXdnmucdegkj!B|k;>3nhwHw$J93G~oArxv>OdmM_irrO_PfURBz9+D1iBqc zWcWwm^dBJN(|O-Nh$b#kn#s66B-Bh^teA1YsqS)YeC5Z#0gJ827>}Wg@9z0P#lG{U zKRjfbB1O`Cuq-zyrEch;P&yPx)WT@AhUi&Is(s9&uN?kd03Ib95|PN-j{ATQBWUUj zp-Vf5PWz4>xR8x_ER`O^Qg<{7virYBF`#93bk`W zVNv&6EY{8z9Bi~wHX3qgS>d1wiIbAxWr~rW?SX}!#G7U+JtCzmTKS$Y7lVQ-n`n{W z_*-r37>WF96@(tHpcBLWsMOx*Et!D5&G}4}-Fdd$v9B<^aS)Z8uy^2vjSiA3YB;7u zIbh4j_mG0lLX*u-EAADWdly4-B|f=6;6$Q?fz*(?SS1(Mqv$QE?*B44WwUN`0OHU# zu~4p11ot7wubL5qie6x=>MIo*=(2!BWSQyG5sZ2I(V|tfeHFwr26bq)naE7Df?OGr z-Yj09_CiVmWsg@rNpZ-qo$mq$!KtPxD^#N*Le7xfwuUz7kVc-ctmCZlWSrmvDy+3) zN%mmay7+A1;F=373;|Rt{RjSJlD=>oV|JcPpVqDP>-k8KCs`8CeZzI@gIPiLsr%BG z&&@732ZU&Y+}r*Z_``Q*b*dPtW3$F@4yfM`3T%U41MMkjU(BG^&VD{pMy4#2sR@QG zbxgot)_8F+^0FdDZfCmA44Ee{5gcYXQios-sFVZ7Fl8~1+F9?4gI6nuxRkPAA6zbCQG!s zWJ-R%kl)>FS#o7S+^1XLk3JjI7xmVzb zl*?y2*eBKC4d|SanIAvM)iKU+VeWquEbB6oD~X9W4yOfM)ILzl7DF|TwDE<68NV@V z8=ML4PJ|@c0I`twDeC@Wje-+kzpyboxi+tF^rqc{h%h#NQB0tp+wpgC# zK}7_@TD(O0e9RJbKdHF9G5LD+K$YYgRd$B|!jztRoEZ2=@SL4DiXz5Jn6!|mD*{ZgXDxvYh=?{0A-vC^%Qx}RP_ zQ;rF7kI8rQw><5hQ{n{PWgQaVuAP4!;)Hq6j&}j-=ykb!#`QE|Pz#0WYw1zWLU#edMoV6;IQRE6c%Srrb`i5vvkLbn zM;`_3S|vCdVNmWwG}GU;QNAxs*{UQ?Jp)O9#Q8)wo=qo@BQ!S1WnDqOZh;_2mZig9 zyk8xBkj;h48Y$796QP!bX5;yMEGTU;7VyJ@I?J07^1`eyAmHn|+;$)P5g|kYfxH}rFvUT$rMq16|ojO}yty7}Ca&8qJ{?c9`WN3yj zT8wf_#X&s8Z4FN1q4S~{O-Alxbn>L4afxSU-lFv)$@`cU%8@ut8b`U8j>XFn#@-eC za->fvbqjnUH2-qC*ZFPN!8b?P3xQYhXmNXy!g66e9meg7Vx&*;%)LQj+h3kOLF{6? zg=V_hf^GY4cUt+GeF3e!OM6a&ql;5n=0rtpi{L=gjyQd%n|Ju=o79>>&N@tw`&0+6 z1`ScY19h-=tF&Wcvt602#TJnaC%)6Fofq)T6F1Ml(%av-M*rE4?a<^Bzw z0C(A+hE9ptZ_Eho;}!I5<4T8hABOc`(aI9?6+5BApm%lZn^x04Vo<-;g@1Hxo~2p5 zP^tD48SSL8mw1|(EBgXT=aX@IKCoD%nb<${W>IRh&HF1It4|Yfr7!ABP0Q$!L{Tf( z$n<>6+xe{`$WJKCnpZXWfi~Dd6d{i%`PQW^Y>Rxw0~Pl+CiZM-`b&=VpEfMB8AfDyxj)M2`!ZFdPFwZ zq4MdX@#|ydoyRhHbXDM+^OABZMD2Sl33xJx-Qp-6N*k zizKpF&;&FOv2nARG6@E{Nu<7nYVB4PV%rjRv@C1U7PnZJZ5HU=&O?KXH4f*Z2T_k0 zSO{5KT2O~_l(@^3a!YE8?VM#SJaE3B9Ce>m49D|AV^2@&tx5Vu9P1uJIrRqBQ)TQ( zBAR9%)ZH41j6v*ip5>}S9q|rJj`XRXO?@qrdAHw{KSe_y@fIzD-V|@7Q2k5!{$gj}?`_5tHdIL%L`-)?+p$tDSYbpY-7ry&~nVkozYOT%qccvT$_W z2uEG4kJMNepr0ULj@wylpWeQ9KC9fV?nzoS(o?Mrca7&@6)Jj@o%Uo_iY^-MCkrRt zrFU;k!BB3!p3@1NiVuGP7g14Yqyvi6?*>V44NvX*NNA9F+4>=vKB21r0~D2@%UiUQ=}p-#_`LAaD+VqZ-+-JTE7$m=Xa<*$L#b+XH>2HN2kE{w$1 z@MW=)D!V|WLQv~4sj*5wj6X2%qT$};B07iC#O7I8^4xz|nkKNZvU{&*=E{%3H>C#z6$qSLbk-Dq zX9P{L149;R_`!f<$RmnlPe%XWe`E_ggi^1)D;{z;(>zG;+fp;vRl7hm@2M?{JwcW>*7;WX{q&mx?!w$?1DEX})!2lR^%1}Cr->1V*1nkE-?;4-ReXJgq2`0Ml4wkLlkKRGC zVYwIJPI4h^Sr~M?%g9t1dpOCqbr2n4HNJ75E_SDsP9_sSz(BG33KIXIR6_$kj#Ifl z(srz``o;#4EZA*|u>3;>PWDDS`d~)%3BHvNeoQe49MgEl?kbV%=)3K9^t_jPU%w8^ zduxmQP-}}4^BfS!8f7T_C-%}wVdCSG@dpmdsT8w@)<2sSf9N`F zF4?cfsB1!M2VA3ZhY{M%n`O3$?a`xv)2crBfS|PTfLqz8q?JdV*lmB#Ck>jZ@wVL2 ze5^9N#po+um66S=iglRB9$ zzv&2?N>4&e^p1*93mXJ3f_xXlR+VSW5H||ZESEli=feIbs}oE$x_vYs?Z{KF`i%yK zHsjO0fX%jsSHw2ElgLK({LlDxA9{L2i@aZ-y$tKbJL5vJd^Y*W5G1s21#>nJ&KMGN z(XpYOmJt1d46m2F@;B`H*WSm!u;&kZwm(D;0Zp0zi#+dd^NyH*3~c)Kf&Bw4{+0Os zuVC?qc>#Z3_2vMc~ID~`YEj{-FL0S^4@!vDZCKbv~| zABMjFcT0AT-xpE-LOP6qQ87PDI%$}yk&AtI?w5y7uFFgRmWjxydrL>&m-RBZj;(^X zGIz$+EA7tQ`AWOhfZ$Zg2OnmOFSohZd=<`&#=o6j$lsc5A4m=ev|P#Bl^ zlGFJ|!oLhbKjGfuHNPp`l9{`|O-4;SEvOh}j!If(@}hOYO-ssL9CLaczp>@iE_v+e zAG>a?xk9JAT-El3&lii@Y+>VP#P&VAo&V%o8<&iLbGMLJuGV6CwDycz7LCHkL{DNU zBcBSidYF^L88aVTET1RE7$0hY`>L%+#fbkC*s$@S{~DxWd~%F}vsNYalM1Qe-bxCE z#>Xq+zyn4){F913lkq|fkUKQpS4=sjvEJ3!dZ?zKMf`dQZLlW%D_CAZlW|K$cZDjd zat+se*@tt}%c`G+z;J%Rc`wbGo#;fxz;GH=+jDMJtvkVB%Y(tq2$J+E5d1?GG?F#} zZE5A9*&@0eMAj6XmbYnc01`M3aWG2mW&-S3Z42j{%o)-(7wxohzT8gLS~A^BEGHqFRdFpwoGn2O z3Nhc$4Xxki+Z5g>>KvlqRT#m&*@lF$#qhO0O3gw6O^I$RTyV}IVqz*1Q;Z=2@ih*B z`dCMwz#E_G1zNFf5Q}d%?mq_>^Z{~ z21DGE0U37W1IX5^)LWjMi@WFhpdm2rK(R`X>Q<*AR){H#uNjVfs(kkyi$_p{>x`JN z3FZ4lv{!2p{ifca6+kXBf|shSz_h-vx!^@tLQ%jzsSu;L_PZeaMX@dTW85f07DcX= zPCYGA8#-4!2ykWwnhR{fYv5R9IN~D7IV8^4xdOugU>Y~Wxgm0R& zHLw3p=RrjokxQUdyj+Zuvnpu z39tyal6}gNC?qn8k<7UrMtaRhoSuVxADqMt2Hn+r>1)#zmMCis2zgA}_cg>pPCG*k zR`7@xl8qi%L0_|hF*9LudTtSMD~bysGi_)-q=dPr({$>`~dnwdPPC)nb2 zmkxS6HJywzsS|@4ka{gW&maSPu!Di`hBCaPz3r_4lSM(@3pO#V_9*9EUhRsmuD1qy%MvN7UN}UEqHAB+YE?K!kaG-tR})29q{l6n zD4W_vWT*ybk!Z!gyg2N|fNqw{G3L|rRZnbQF>pu7pz&IgmDKyn*dB;_vipE(7A5hS zV%sPqZBlbA4=Olx(6xBIoe-F!&?bR%WjKo2l;~93#zln#iHSb*UTRfyv3j(L|9o|! zO;_v~H0T(Jr`{5#v#G{QaV*ON7Yf>?h(#g#E~Vjm#ApDvUqM2m99wR6^lDUYH!zp` zR#LorCE-K*<-&DUcFw_RW5VlrL3S0=HG0)ss2)q{H6T&w6gmGu!aNX?5IN}_0Y`7w zq-g}|D0GB9Vk~>3i2^;HV8-ZeIN6yZ-SiL0s|Io zX?%ART$u3?3Pklw-zDBijiyq4E9#!G_t%7aT6muV%*U;&+yY#&Njl@&{U$Rjsi%x$ zTehhlk;K2;U@AaSV(i74B=CfTqod1+TO-j^KD!M zIfvBE$Q7;cBPjSev#jdwN{k?>F5}S(+0%8Qr$DocvwcUe{IQ;3%@XTGfo3e0qmNu} z>j387xUG1W_=eLII8piIfVOmxQ$xkkWHTI*kAzIBbl9obJ%#8xCbQ-3at?!A z(5Ku^se^N z%xx%Q60BAINu3OJ=6#tkEor8wy4N3W@=*Oc3v2L7xF)H@H7vK6?YHG7Z%)3EhM(G? z4vi)7qg8AAOK8j&!Pw@%qotsnI4w@;jTMqV3zFDP9MM4>^HIOygR2 zpY*7_q-FD%)1e{QEFU{M`*M(>=5&oL>Y(FdT4NrMeogPn!ZmNGy^}E6J@)AAkFT}O zMqtIzr2N#Af3`G>T>fgb_xR#~iep&*b|f0?{+fIGTl>d*Va$QS_5Jspcg8@N)7#u;3lq|HoGo4tb@sV~V_Ng$6Oz%Py7z@0AgdHLVlSr2E4rF(cv+lkQbwQ4r zn{n`!t*BF<5i}+?sn`umKiFBrF6x+WP$V;eMVxoJWb_}WJr4Zzh9!WqcAzuHE>kb> zZYS^MMTD+eD6UYYVB^&}q__qFi!?i5)$`Xzv&)9kLk%)cy(y{7%1 zT6EzdnjtmVVD5t&`YwD-djoG7d8Z#eftAkHRsTxwf0#4$_j&&x!1%|=@sCkafR}!5 zyz8%xWWS?#z(C61X!tvX|JcV*;kn`GeTzgFqUZVVC+Lq;w@zPSW z)}+IHG6?7b4|{#8)0N0}q}Iu2d}Fctn0e_1J@!@V&^Xa&(dak<7SQKHG>qgOCz47W znj!RndjGF0=nAs-1P9Phb64xz{(DBiP#O~InLQo{cRYZ6e1U2w!T$}UrPj(3Z`ee)Zy1BY zney6S`^f5#pab$Z$AbM={DyCdjYA=yMEf4~Rlwp>z{<&GHu_Y@x>#w9_{@cq!OWu^ zAZqAz?V*#6qi7Sye6I}*IEO36yQTUBSCt>XaviIVDA^_9jMZe1&eo|8_aQjChbG$H zw^Ch-jgXFWOzeEPDjbJKsVo5*U&X806tQ}tG{lGPrtYhQvJIH%o!)yaDtDEJ=KR2QQb6PNdk#oS%LJp+&AU0gUe|=x6tlb5}meaBbch7 z$+jS*sUaPEtgakxec4QdoA-Sre@^Mh9peuERIi6STx6&^LrqY7kPz@ub3T?=>W6$_m`KHCtG5#V zB31{`Zv#b+_9N;KXXa}tV42E?%#(I>5$F1w6TM123kRcJ+51cFVqIh_;PS|;KL@KK z^DBjuhVTu{K6K`r0ZVyvY9N`A;S$7qEx*~P#)m&aq!06x>O!8`RNKuAH?^Vp@&-S? zL$Uh;(&A)6FHon=$q!h^MI+NhW>G`ce_e9kGX-k=-LJp^t%Dh6*H zf7TQ}&%Rml7OhVc?5eu_4E!#;vJ9L_6iu$EaE20Ox{Wqfo}wh+x~Q%Tg$tz4=#ioL z^YL(TbfADC5ozB+b(t)Q{6i?#VSX+;qu+z+m&aC{RMI~9tN2xhfcMs6=aX&mqp-bR zhN*GT@e0&$Vgpe1f;c@oJxhm%&YALg(Rh7*br#c_2XcFGTCX|-hS^^DpivgHYd*}+ z@}nX;I<@w^)(R{a$>xF2Def`IhaF-@NGfI;GZUHbvVj z4n7;Hp@$O`IdV(pgM0EEP8szN4v^a*BXo(E?jJip@*s5+))6!x_pU#`g*@~%idWQt zc^lOwO~asxES_%LM43fTq_4YV<c)8p{8W!lIz`cW8g*t_4e_XTDYN!2jlc=V@qoAhP z*1ncCxaS?3W=*Y5b^Ra_S!AOP?yd|~!c~moAwBLufNz06{mKnKLX0ooNjxt>_`9%P zMj0KsAeje3Xtu$QC~rA7MQj#1yx658#c~+}{tq&CF=d-~QBB2V(|T`g6y$Z=f|BcF zjsmDh$MbO@m8n+FX>C_K-fr`~OABrwu3^DKfJQ8S)e}D_ySk!4sgc_PK7O|$&49UL z-QStO!(8@gXg6oi?v9;(IOaa8ziTw>}oA!OE>uY@zVIo zot&(c(_Ex~t}Lb+8a8V@dI$%lGt_iIcNKe+&4?E+ z_wAgpG~{@KXk)QD`ay95F*p{9>~Qc#JqblbINnuBhfCmw%s$)!DWt@G{*c~M^X5?u z&EjB~_yvBxo#%AfYFA%LM6ua&$mH@E8=)Vw?F1tVk@5xX<>@n55M6aoj`uxi2#oPC znzMwFmr`4W0h%W=TA5@P)bhFkVe6aEJQhiX2(kykwxj*t zUa|5BJ@cYnYn1#AY5l%w;XjbpFAewa4Stz!`+ZIV;GzH1q{RYAmj8JBzgzZM=>OHS z|NF|yf4%l=Eb<@bQ(c*VQEdkS0e<@Y~47L3K*5knfXj=a(qJ5tp{ga4RhG80+ z%6j_n9AbX&A8rv03lT49GRrKLB5FLnovkz^^a;JSrBH_=QKSBIJ5#;$VHbCHsI=?+ z#+lRd27@NjZO(8abq;}zKCcQ{uMhPN(3A7KqkXLSxtyz=givz2HXY0s>s>lJM;BMo zrH-88;Y;6*7PGp1KZG4k(wMNFk~(w*a+=tBg!k5;J|Xc@JJdTTJx(WXNhY5x=5X#_ zNns!YG!{OcHl0WFVN+Erghx>8W6SMnG`0Nd-IY(HN2{t+{e|0^ z#hI&2pz|}5V^0mytC@_ULstnPK?+9FDv7pH#_V=%B;p&?E7e|8tELPPKnrINVGmac9Y=*b$q#wv`h#SAQ=Ld*L`56;M zX4v`d^@X>ofM#$#_Z{{UJ4}T!6^#%K4hw5UdtF9pLdzFJh09>ffBTYDS^X5$lETE{ zsLB)VwCd$pkV@e_N=3*mf6T$H7~z*VDSqm&W?cQ!v!Vn$XP-ZYY8xF_y@%qs8Xwxf z=-|je8WmTjP*eQDw)hcw+?32^N@2vx^$^j)UR6@oJ6yglRb^Ab@e)lP48Gd`i~6hP z#Xjz7P~CC}ZwI}I$ECxF8CE|-b+flNnpP2ZoVHzaP*rNDcI%=A%eK6qlVCe}z3yqA zJ1rvyD=@t5$HCIw8l3Z$GHR~)P!$~EwOza>&kE@z2v+j-62x4GQt+SoVJzAE1kv1W~^2(4L?(V7~yY65O~bN zO5seB)vym%D`%fo&b-W09;=9=QIgIIjgxD991hD`u-R2ZN;7jM)&3 zQ4*lkGP1*Z9Lt#+F&yIVEVjVMq)EhA+?W$yNqnHoEo=fgE&u@}ZuHGM%wnOYLJzLzEun?Wgyn_-c{5zxggF|mwi<}0;!}JZ2i@|h=pZbY>{dlX%nvJ zybVJ^mtn$>UDWH=d)U3`aZtAB4@PJkZEtlUa_QZQ04enf$Fuvgz<8q!B+8nE(vf#(_XS zGW6?7ZM!P(_Er+~M!S)WkI;)39WNot^u^OjX zNB;BQx}5ak8~eQGEPR>5sxU`o=MIEEzhkm1#pKGGlN@kSGKsEd+)5+Cfn%lU5XqOv z86tmcXiNPfEJ1C@&3?#5Uzz163kFXqDW8iy2Pa1En9(#tcH_!g4%}2`okl}2a+TDC z+A6rxO}%5jTR1nn2V)E7Q^yI^Gm65bJ9IEJQm%~hZNrGZwhVZ_sxUSy&rm6bu`Z{6 zPnlt7R|rxe8f%__)QJ0_(I?SQ6SfciL$o8!?G7`zD#^%4?@>G1Sgb}cB5SZ@FRX?$ zW<6Ts&M6rExtrakw$@kD%qxQrvS|Vs++ID&!V_Qn=`qfxuO8b-_X2?Y(+$*R$YOe{ zuqP@=RWA8DGi{nlBJzF0HD`z$(K1ByeUXoXt{@p3@GQ&B?ZtsgLJ8~C%rt?3Rl23# zzM*G$<+0gH!Ha*xpG=B86l8`}RqU+i$WlgI{LUwqk+OsGl{K~2kq*< zY6)yi;m9~lH8qxum4)+P{CV24VB37GujLwqNqVwZy>}7c#JW)4nN6%UJAfw%Ral^V+GsM`_e-FYT)bv!qRbf z#j???<-VX|Ay0Fc7?XU)z`{zG7$lixmd4EdvTXpmlq`yJ>z($rEAs^S#gPH%CE_~>l0%KN+t#Q)W!0{5c3}c*l(e(@8jfuyDT8o^{;*W1l6$q$zSIW3mKR= zXxRZFB&Huf|LOqBLjQXv`kTu#F#^>>g-=c>;xgPWG%)XBb~h!eT`9#{rBdHs ze?GbWG-}ulO`&GYUEdENC_LU*Z+RXoWACLU_2VFB2KW6>%ycdjz*%eXBwcgv3QBsr z(fv3n#dA7T%W$zeHLy6W{SZm#RkuzwkZ5^J$I!=>eKBgFV2LOk~i39>1o zu;+5J%w0qcd1~eJKBjoGRfVo?;AW|$q?)pKcGflHUQ@0tt2c56gxVlahX6%53$?D9 z^0GOMEzRgb@)Rw+K5E28oAR~htk6?@oy(w1^O>i@Nctzv07ydGjZB=db zaGmVU@c7DYL*@JwwZRl+`{8Ek2p%`@*r#6CcRrBeS+G%)C#dLFZv5`b-{`Z7s;h_% z3W~z)14`Dyvu=@EOr^FTr!C}}d8sMwTZ-@z#S!wQ{RB4UH^6LKmoNf&MUHh6+YlSh zgU%?)KxRkHLQ6k9vp28pg z4rw?vBHbN=ba!`yfOMCDG>A0Pjev9s(%mH~N|$^$%=kUyIP*Q@yx;Hr>)?@_v(LWc zT6Qb;A&h|@uEgc?{t)t;cN%WGBUYIY2Iw-3F*qr zt7~y-CYkc5b#%uN6?6F8UQaqnf~KcnS+9I4g;sT*@m@`vYox-4q-aXH<5jE7B%_!5 z=XORutlUaUzhbL}Fw!ojI#ubfrctQZ$W^8JzmooSmENU9BMvco9z4yaXa=~&x1r0vKE zI;Nx{XyFK&rG$%<9HJGk@kb0yMb+!v*^u7^kP+vj1o8@znnsdsKgvNW=3GtRbSq$U zQ6;+Cli8|Mrcqe(?f2*XTnrJZoQ3X~_CS!Cs(e$3J6kIq$N%L-@8#9t4W&i0O!Gmi z%#aTg!|6cqSJJweH-<_aaSge)2#Q}zd-`b6j&Fu@I%f^eWn55DL9h3$tobHaQ>AX7 zsT?g^TAPI(rJ>h!5!tE_SbU&Yc}1A4d#h|DG^VM;k;CPFSSE;r$th{daBH-VkkV{y z-S?I{TkMSU3XgRNc4AF)z}j}XDhMA*LlhX=E*D?mi*<8Ec2kx+O@(@RPN zU8W6%t_E6?5rtGTB=+ss>ukkCuVixSK(3%C5D%OvR(vmBC1w>x?=8083Mh>)e9@72 z=4>u=c(U+d6)vySH_>}FhFOHgsBg@-&%u-Y)UXYNPE-2zYGY@0sx?#I6_qkCH15km zem1|LISBRo3Egh44Jj5cG4r;cjjd{ut*Us@2;3X}YwxG5m2$;megRvhwt77_g<{2*!- z(yU7SLb%3u@rsWnSs;#TdIDI6L2%?WAD(>z_JF7 zM>8X8Zlra8^7K>t{3iD3#mGTt*1ICwfQ?T`&d*d|>hD9B>ErAr;`ypNChi)*+_bAa zU{JQjv&-)FeuI)96|?+)89ptBJ%!ngOA$ilaW8Yn;{}c5S7r->Y1JX}AII4ceK;qL-`yXn~yA5?b;AJ zM)<;gl92RVoRwIg1YQw;=nXnCA(r^@t#^i^Zg>t<7uUn*^!~@V!Pse*$WA5GZOwYJ zw!|!!=F&D)C6HvQ_$_<~M$RsfnM}7uo;2 z`{{2h*`JWa?_F^JY}4#7sGNKAN2NPa#Cuxg2TJD$W5{2mbU^HYY&kF_%KD6~7oDD+e$l3j_uNY!KOj z!2mX{yD45k_YM#^VF&%H$EmHIlex9Ihq11$vy+{(lkVLN!%xxPv1Z?+y+=>?)ZBli zqCh`@%)dAg1nB+&k}Q8lU7$a1GXB+Jch;Oh2L5~;`#&*&{C}XeUlcK6|3T*c`yS-o z=IuWOXz6Ow@xUHr%hj`jvGDZJ`dkqu1KU)|Q3_V>YI{^`4%nH*sgxSZXK`mEy1EKp zA(I1(gF_`W=xwlGP=Z389f#t)e(yp=B?1ODiA|=Pg6mp`Lo!bEXI(d!7)&{dAvfVE z+&(eX5v?&(*W=jxs|hr3Y+mu|g%b}jRiR2-ioGb0ktV+#YPoG&glTITWJVC(d-5Ka zoGidKc?6dpl%082Wn0Bx@(@2DV;t>8%P1I|A#MOxS1jEqW+Yy_h=7@32(zs)A|$Gn z2na-qwl>a+0V+@BZ0+sk4a?yIvq6If=l)`{5)Za^vERORST$Uv5gAr`DN8)o{MN^^ zx?c7DrfU$kFH(BeHBqisGICy%@9>C7dqc3AW#NQRlb@^Kl_K|o#DjwTMk7Ik zWuPt)pR#y0ckQh!xyeXz+ALQ7giq&amMvov>h?g9ME?ie^o~zi#^sq`rR_RW^49`I zaY3R(>ZN0*vKx#HW2BQd>rJWA6gHf%hYOr=6J5Ibmik;(|c@mvdyqwZpUW{W-oJ-R16lyzy3OGxt;K2Jiy z!dl|l0dr_0Gt>)&r`a_02Mi?K*Fx_Zj?mKgY1~>A~#q#+(=?ry`=n5}P_U-)qnPz3Bn5HQpzzR9J1?vOi>NjTYrNHv1{iVb18!+i!}8hr~8K70D~NLf-~Q!9vG5 z)E6{LK+EEO@wSYb4eGI7Om*TR{>Qt%+RJvZGMicoS`I!Nz^+N&VlWI zBA+OUG_vi9fZs6(eur1)JsuHZJrU|x8)hv%ucC2%d=|mS#(6doyt|hUF4Sg2*3K^8 zi9KvRM@g#`&|O;AB5umm#Zr;AqJ^84UXat0=?@xG-1~R56N@F?kDu9YTth3F$z4+)T)8^GVY`#sA7W)bYi%=us5Q%x< zgU2UI4V;UI-S2M-om4eiW-R?=wnSg<@FG=!5L1!-RYO&97G9J-8gR0XYBG8QqjIWC z&7?wf`;H`rO;$M-|Qn7qQNUC&vuZe_t(7H?#%&Dh=!e_DpS5ICFU%YPoW{#R0{9L7wu|+rjI^oj`L%L`T z<(Er1!%Sy|Z+D;+I~R9ezaHF~l_@zsIr4Uip;p&6*||{6pxl%>Psp3_m^u`J5+ghS z;cnYDTHe&qSZSX?QndD5s=_qV=XK79_#)PG8%_kmpXzmEI}kASZG|JhC#;P!L3Tl51gx_|HcI{vGugYC{b2%uOvnHf2OJsj4% zSx!JRgOv*~L1Ot;)ZwIWpz8>rj-QamAG><)R{s0!{danZ{m<^$e?E}?&cp{$O8W^i z{MjA*rvq64?UcW;)n@+*r2HvVV8#J(uKJ4){G$@!UwlP2zyyg4NbJv%{*kf!s{=uR zBW+(iD{xn9LTzwS?|Em#l&T?3Zoe8TPH1|YN*sT z{nKJ?XPlC#^2?6&V$8JQ0N|X=wO${shvxOO>}(Yl<(eM zBKB##0vZW}LJOG1D4x&XoO+heLRMrRK=2QaPGCkr>Ke@yHHIs-6@W65Tw51!9NRGa z>;kDPQ=4hg8Ck=vdOxBX7@uFeJ{#{j5i4rDIz0Shioc&y)W7Q;{H*>t)99{wOn}6- zn%L%HG_3D1#^;7@a|P_oDYC<3Bln~!E{S)|d-xhVk6{do;EW4X)D>O3GV~d#iS|;p zb+<3$bi?xU-dNA<@wtBUz@%ZB4;oU#IB*_BhJs6a`@H{gBPiBau;say^u~t3dcnSq zPqw0dt5=Z*VwpK!$q` z1j%aArKyv@upv}4jLFvW3#95MV%6;$@kRdZcsr3f$Ux37Nm-vs++}2|TgoW}<9C*H zLWNRdW*^|+QRV}+MiQkc=B5-W=QEbH)YxR$yp+&Y7f@gk;iqH2D1ry$R^Sd!xep-) zt3JWoXogcBHN4+%a5lqzE*YTc9bXg%w)vVxDu8iESeTqSFr&+Oa1C4I_5;#>s*h%i zudyKh8K!CYYmPSyoZ*|!OH2#jimJoE zwWsj-Szd86FSafx#7dDq=u0hp&+{6RbpXYD6IQS~EUs;s>}$7fN_a*W7`g;MIFn9} zslEx+LI9b6r#y+NI&QqG1woe;@7zXuhDdGB;^WY^?v_VKJKf!LJM+~^X{8=s@<^Ey z*kII!F-kg4&@U@8#bUycWuAyXxKO8cdu+>cW6xKEx7<{jOg$?5=$ehtckKbw1Z8%q}j^iv$x=V6V!H<(z z;`5=5WWYR=dVbq7RqL0SDV9`X^w~Q3$2lM6SC32E^*$Nv z%P6!6;;!S8w>*V17HFi04N^~h;s1_;z@By7XhNY%-=jGQ7X3mWi{LC`o9iPO=Z8Ui zXnXwE*QjEFvd>$B!tDd;3opA_mo)QZ1$(=wkQnn-E%8;C-@0o%y_PXk{-|mg<#{t!Tyu<+ zg=6o@*JL&;xhLSh2?~WNaq27dHyfdl8_E_^BrZ*15uswNeaq3;z^ z$n=r35%!f}a!Zae;ye4cEsV@83Wmq7RFBhWc>Ndo0P?W2Ut|s2B-W3H%m}PW6%RS| zxfIU}4&4GysrN!mtSo||GFf9T%CqMYQ{1ScjEPApY<6e)xY7A|P zL3cPpsj=6-;YfTR#**Xm2)kaX*K}||=A0}H21W-S1L^Lw1r7W$K98Sh#yq6Dvgh~9xtr;2ZU&BYI6>vc)#oL zwcR?#pTOp>o-5}VZfiWCgN)$&;x*~%U9ODK!8~ng^m@|8uqm;9w}E6!oO@4A&3O`s z`VD&x4eBl%vx)}=Ofy%!7=F1~6j}D8b!vg>T{&6Z1NddDN8$-Pc`b;2bYUA(zANJP z*D0St$KBwW5Au`~5CaR>+p&x!c+y`ILr5K34K8%nF$|{VD~_OF(m)v`QQIU-h*3S( zHJ(jBdCMFGZwUu?Dv|;2cm!oJ$hHCjE|+C68%0{bOJWNW_3sSmB#dtF3ID>6 zJWX%D+g2_Uw6rtYZm1qgUToaUq7yA@{zbfOz*Ni^+0)*Q2wicH7a~5}pX}&8M%{y` z?Cr1ot0v127Q)05B&l1T(=gTsR+p7@DEm9>N>RNIUM!vwYH;A&ZLaa|fa=LrOLfha zi%=frc;8<9b)}0iai10eVa}(j+qYKLkFwD(i$Sv6?{abEs~s_Oq^Sl((i+dAUK$ns zrvigO?d*Ud(PmX!mb+ANFJNsDGzu<%P8<$YsOkg}v2uRMM`ATKe+m)Q;!Ckz>2$(P z`IevCHzG`0JiKHYxj_~eEh^TWJ6d5c3{i3HDIch<9t9B^)~q;F{c*(bQyPlvkH?S7 zs<-biTkA`xjoY`lNTe)mOyrw+?|3=})g3&Y3&=^)qSWwPi5QyZ)^TubxMktZy{VRE z)?4_skBGETAO9^|p`Y4Ri$GYLKYHt-7;> zA23$EIz0Wtks9m$jYq5GW4D&UWj{rJ8M<)#NpmMoDDF$Xs{GEXQu9P47-GELDP`~} zj;@LJ6v@Lalx`YJTg^@EC6JX?@-;;XNVo7);%6ulLGtzj5K0(iW4D>V~1ZRROAZlD&`OMx!Aw1Nzm%JFqP6}Vhs)qb1YP<+D>%SSDm#UYA zs^Pj^SfK6q<*||-^tTJI9uq7b^#uvy=a-8}%$X3`L5XHykm^Ws;9n&;KyW#l`}0+5+I^~ zxAz5XSMDn>_Irm};Qin2ec6Hbz@I9z`@i`en*U-&#=;D^R&oIa7%O0Ab0_Wy=tBdo zhpd2oCLm+;t30*7gXy1(vHLIjZ-WDjDmm}V!{4L3GoS@F*#Bj8R^~qi_s25o7c&O} zY&!u>OcGY+yRJ=u;pYY_HQ=9j&71$s2-(!Z*4fV7##GnZ*2vk)_|Klbzg-jmGIgwg zz7r=pze0k8VnK`ldh806#dr{$h9_Za}mE5S;>X0sA+1Eg^TiBfxG6V4usy`H#Gw z{%`gioehBKfYba_`u<2${Azqaj|v+g_Rew_AFzD`0$ii-{GINlr&#|{fPYM%k+I2N zp5gzAYcwl6AdL^WMBTO30CWU!)3N{@2+$=AY>oYLfI#~0Zk9i%@cwD|FYgc*K+l#F zAZ}OyRah>LyVS7(#@pP$BM>;pzx?F;n*e_>iNB*;?w6haPDO!!XnX#P16cu8G{7nA zC!PkdJpRwJ_E*ON&w)Fa?4S6ZAN|_;;PQTVmEC#2|NNnM&eH$SPXz&v4uD$T zPak@}oPIxle?uz$*h~IHm-!$2&wsfw>IYN3@1zn3=RdXzuF|?xa!iL)0HS&U=8=OS>0C8K8vO;u#VNMvt)~f>u)6IoyMr}K$OVWHg&4(@ zNQn-I?>atwT(^@4yKpr8!tK0$SuT~zd)QU_D5 z-oTk_i-LKjTR!ghg+`-jTf+#XC7l&OY;L*L z)X0;WvO)W?Wr}F9f~70}&3ML2t*ojNDP2mK)b5*OqzBSt)h5y#j`2xXa*7=op5sf- zgjJUvN|zah1p0!I%f|FMB-P#5mNeN_JWS7M;}#8d+GLI2~7R=&J6i;Sa z;at(R2MuPKF@asA`izToLV0SyS?%R@H8r9z8f?u|wvD$%oI$i(pj)?EV^LN1vg|mR zdN87XWx83C$8f6L4%{2!WT9)K3AE@`=-fyyxZJ4T-)iQX@R6a621A5%Az>@$3c0+J2%& zWe!ZfkA_$Z)d(YnfbQbxITe%4jP>xyIPR;{JW`qn?jf+*fo5|Sfw_nB?p-b&HsFL7z?PhqE)Hm%=_az%7h5Wc8LcAPDg=nMIAx!}N61yH_Op*^Fo7`431nKy4MIH`j-Hwbo#Er2HNNn~)QS&|%4u z9Bg7jX4Etnlf9M~{+&FWoa)w0BXa@h<>G;sja}IuR`N-v9Ly?ian=ci1fCwt)@x0K z>W@kSd9+{74db=3qH>65U3MzBJ|a{_%sG7$etc0bD2~ilHpEE?mPKl7qAKZw=9W)3 zhf5nrAT%u$!?$u<N?zTkyM{N3!jI}4rbcX3CdB#F<5C&GkL^IB2(T%t89|>wg zypiYj&~I`1!n|ha+`r?3OL`TI?&^MU?lpxjMUp4*3XxWwS~a_o(8-E2x*LO%^br>X zQciSm(TXbHDz`Ovt%65m#M4FaXBDtT!>sR6{STjRsifD*t9>(RKv1?*t_U{Dil6oz zD1!T{9Bcd4Wiv6?nARw*MF973Xfi&{E-)j9zzm{(kzU$2CItc zDOf6g@>5bIrEQh{iCu^33Ma5uECMTIPOMldNcbdNx- z##kO)*t^rc>XyP3f=RxN_@%eOr-XiIGvJeicV zg2^EY)Gt^i>v&$#4mXfawi)hvwe~#n)5g2`_@IDYcjRW#<{6Y*zl z8Kqzk6SldypCFUbeUW8;w@-xRApS(E$IN38>bPlQqX7SygYh^;*2TpZ?csB3fU-$_fVppm9#5l6+^vggt;)o=P--N zl7xJ=(_DiMWok~+KGxI6LGz|V+CC#9TqiQegWY5tRY_{l_*SoJ#z;AEl(cVF9 z-NL`;9(3q7S#}-HaerZX!x2-q5K4qH#)-g>4(~Le7CJq}^iHuHcuMnmzs4qU0}T|s$yZ#Oq|r68h+0*G{a!SIUKz6E2ZoN2PSp_uDF$VJ zC7Oq1lQOtZ!8n~Fs-Lv$eYo`~tT7FRnHRFcXMtvf*C0*|wIw#o4kwCL5s(fp?rktH zCP#fSfLOCy14eAJyd%I={c!+JdUL&B(d<#eF$%Ibl;jj;sa!2B)3&Q-`o4R|L9}T- zhvV~FOY`SOJ<&l)53V*3J>2HNBItvc2d*y76X-nYA*&v4t?`W{%X?th$+geL>BzfK zZ8zxfG;#NEo>?M0qmMKS;`n^~z;rQv_+a(?0czpALVm!_Sx{SrlKm$$V;jHdZJ1Jn zg(vIi!GS?6!O$}$CX{Y9ixZR1SuUS!6cj4*5rbF{PrF`sg)ar@7fj=TAgaA-ut-kZ z2l%9cg=j44Cboac#}eU2LITOpd#$@{ik_9dkbg=7{atC4X}n*EfipRl+$AlR;Y;1G zab+)&A3v+md$p?;f%U-<{XJ1oU#VL8u`|6GZJ8c=^Z9#mXM9c$EUeZQKgI(L+`xb2<_V0Fz~6- zliwIWf2^ndL`sBy>>DwUNQ{&4nVA?i3DT_<62IlQn3r1zhDfsqi;tV8#7iX55k9c3 zp&y!m2+{INBHn*3k$xoo$eTL9UpLa619m{iXeS&lZ64Mt0o=88hzj-5 zVp2-yB^?C4P!A<|wA+JoA1-8R3z!RCaJ5Ojz@J$x_CF3Z{8mH$Nhy&19_Rkp7x3N3 z`d_zA-rEfWtkk`G@ZIZgeFE(F-oAJLzNg86*Wad1*?+UW1_oO1!Ug`H<2M$I{Woj6 zANvdL|MvHq;1|nc*5BAHpo{~G9H6~`9WVd^m^DsjK=hjZmy1q)BO@oYOd|^`*L~>@n5F>I+d!2Cv}dpbLN33D z{Hv_s--h_dTJ;x0{9PQJ{jP}{(B|6+hFfR{Pf zooqSK>H_+$h6Si2fL;KY8Wzrf*y{414q%6$%))=Wx&Gxvc-Q{R0x+xGfYTxi;AY4P zuwCDokpExF`ybF-Y=B+)T`B&1c)(md2MfT^{KnM$YJ7ip`TZ~q_KRm1&|d=jyT9j; z9SHYsDD7Vc`1jA5`{(4pJjK7?AzbXhqYua(8*mu{blH7Ie>H=y#`>0j`5e4|e*eq( zK)^$V8=x?M5Acp+x+8@DRe*n=LEs$y$V}a@nE#!CW4~V`zkjuVLQVZJrUyLV|DcBO zt1aO_m~nn@3BQwC_=o*YrD_Y&sa$A)EY*ARr{Pl^9LuMau2U}ZFFi)J$MS86)eJD6 zLU5BbrK;X64R;3}zLR{bQOeuhF=)&81qx5$n)HQW$7>=z6!!K72z-Js$2NY)g$z;q zlNXFjuSTu<-bkua85hJa_gAYEyphP|0 z=;&%vc`a&~6-DO^s2Y5IfN$xy(E$Mwe9;}BMJf=1*983~kiP$zPu)x7dZCwenq{59 zY8)#pEt{eD^Q`|vFl~*M=ALAV_h+xQ80JW$8v3d__~bY(>Nd~NR@oTW=oxf0IrKB! z2T^vIk(5LU5g6eOf@W+?Nm(VP0zD3~k~F(83ycYDYk8j?^F>$jGDe57PqqiRd85?s zhzOx6y~!{3e&yU|Uqe^dj1T|^nDl!0w^Mw2O^QQTpmrB5UAm%M60OwzC-fWnj)hO_QnVn>^tdG z#T0IJL{vQDh8tKnYZ!;}7WPIUF$mgi0E@R5W)ELj#ltEd1`Fu4^VY?R*2KF!;GW*c z{N}N&5#qPC%<}T)WZm*+2<(L$Rnbtf7xI(kP@xiailDh?W%P3oo)|W4#v(Y?luG1& zdg+uwvDo9TNc;8e5PU2{22)rnc#h>WIFWh}21YE$cZoGwpC}3>8P!RY;I`q^znNv4 zL)T5PYFdi%=_Q|(xc3?o(eTLl3qhU>Yf>ohSht?=4GIa zuT_nU2eT!lf5A5-u5$B^b3moRx{aKu61%m^RoyMsaW8^4QKYWx7X6Snt`@hd6X&z4 zuWH$xD*yHs5`%^k42_2me$=wFhZ}T=*AwNZroxQ!{yq!_qqdN%(vSEvO@(yAzVRNu zM@!vod0Y|qHrp?1a3!1aZM<@rlNbb_<+)cs^2pjN7k0(-AtRbqoDR0dkhCNG5v)sd zPilISEp>rBdfZcxLn-tS;su93_`XKD%{?&WMar}gVuf-Mt0)iQaR+Nh;C zvf`#X)z-mXndygT?}K#XiZSIpX?zva4s~bH=C-vs7FtI^DzP}OZGDsSu$*mXwMV*k zkXBII-jI8d6$#){ebdkn!z{TRwr>gSitXo5x{y<9n9dEdzJ_Gzu|tF&I+Er~a_f2_ zjS9y+;;Ce2XZ1eh@Z__pCvrg}@m>6cCytb9?0uNklTcTYrnd%)p7=H*-GZ9v7Kqw)>2O3vSFy4V4`2#;y(O@MI*h$S;@vaQ=kw{} z7OWZe;ndI7$X}R2|G65uf3*Erjof<{18@DqY6L)eKn;Pw^dCJQz*6L=J@NbZzCXTy zadBs11J=yDssX@~z@Rh>uq3f?a*=Sda05X79~vG02f6+I;`v8_bhqR3yU+H2)8=8n zPuTbG_P@L|{or``eQDwb-u;J5Qw{Dw)Evj*LD^xcOZjG4!XxQAHraTNw!CO7c}bK? znK>b&zL)D(5qh`pSktnJ5?$k~X^@0FR_t`rk|^?tuGiU4^Q7NlRg~p#`>e{=`FeB5 zHaGe1i`w4K?5|%2j*h8yX7j&Wm|n}q(&*dXzucEWWY?7#J~H7nX$4JqWmj{0s(&zM zql*sq`1b8|f=vygl?w{oO{6O%?b>S&!T4o0aZYb5we6DU7<<8~#VS01RGurCr%?A7 zCw_Rc4=fvIyur4wJOi>IOX>AfHYmT#vjXj9&SNqekOK2=wn-weYNZl`d0Vo$Xd{l zylqmHCL7?lNTtuu(2A}pC$YS8H@+zlDUxet zyNg+Md98TrOUF?=%aR1W{7Rm6^wg#oJ!FYerd&R(VY~{ntR(2&>jM0kAXaFM@dO57}rzdwJ@Bwj;zl-PSLgXzS4bNwRqb+ zQ$gzQ?V!ODuk22tXDD;vB$1*@FiBa=gbOngc>qQu>OOw}mp1^vvZpmfPu?Vv>}1X1 z2>;4{5Kq4p_O-caU5=@%in`TI71KvF14Jm%1qxA%x1Xd`sbr&SNNJ1^(JC0goc*~G z)cTMugSDN;I z1p(g6svRJ>SJ<>t7sTezm!z3+!cur}`KDmvv&sd-XZ0kYS=I+h`@8( z_c~O;*|8tlPl3K-WHOn^FXdg(I<*pt3rPhsj-vKBqG#3SagEz2ih$2uj7ebeWmGz3&uU3b3KJx5{M$d~`^H&b3=d9;Lt7bUPv|wv6 z23HP`c8>5ejzk9>9}AFSbM=ln#%jRp`jpm)@M1qa7D2_E6=RdD73hrVJl1g;!5okf z(Y1q$yVqv+nyS?BV3IV+#!YC>AYz~3u!Qt83e^XWe8wjF@)sBHCm;#F zwAm(i)?&L=EyX~hKyYZ24wTCV@nLq*B!SgBh+665ynPoYP2)$&S=Lb2z?|+?m zrsp{2UkTyhHf#%idR!Lp zC0#MZ2+C=KW%U(Fj(gPt`SgS&*xU{*b@Hfe9@qf}VU^ieGNe~XV5krwJP+&Ja@Yv4 z!H|Nu)KG)Cg!KJqTxpezqO`$Hvxkc8!KL;X-WMpZrK(H47+tCFhqu`xifgdE2 zH8Wqn<0^)iFaKn3|6U|aN#gLal~b~ZqR0^{3HL78Sone)mg~rjku;KgZOb%HHkZp3 zp(vx+8siXoqrAXFs{;r!do36G_s~wfC=($E@8q9&ea6#7E|Y_~I!ILO{A|vFjrFaoQ?Z&my>HmO|`_u(N?Ql4UfoOj{Yd&o`uD-{%OIUbyy*@OT1{Er; z)vS=@Q$nZ3;t*WeLv!dTevED@0nIBR$4=Dbhbsk4E>=Y5p`$gOqi@Jm=M)Em?1h+M zHPX+-sPJgUKSz4dJViUH*>M&rqkD5Rq{mOb!ceOlcbT3=Sv5t;=%&=c_4b7{&kN50 zq?6}YXqHT*0ndo>&iKiK55J)uQkKJ*9q86rYH~{2%Q*O38#LnJpUt!}=E4QEke$En zPwBQUsmI|T{>Z7WY+U_KB2*w;H==MX{R0D@Cm9l3a+_|IG74;~vU4_+kE%{J+h^Xw zxnX_=ymPWcZi_bJfxxfL%ky8(p*{94o`bP`_;UI)(7X4o{*FL?Lsx$WdiOx#N1zAr zP4~#{-vhnhX=MP6-P6eThIW4%PXkz^{}lYc3j6?SmJ>i%EI{`o2isli51bOiH*MXPc3Qpf&ZAddl-wrBxLJgWbB}Mhh&+xnIxDbnS?d(fG#ueu}a205bmn3+|72^cOStoooVloB06Rcq|L3~+ivt0t&3mHkryivrjL84;K;XOpMDNcB{*ik6 z8<_qhPxMFC%pd5aUv6&t!FTgJOuy>~{iiTp4R9plK=U~(Qy9VF4r$`4ELZ!(SE={a11Jbaxt8=c(L#}IhrVSm!ZhDpMy2TIm zuBc6QtorgecFmvCm*`EO4I6)YLm!z?H;;QNQLcbs`|5TjSmpzczvIEu!)I4}Ed>W# z&l#T|`{Rn_qW6l>cG)|gTFq=%s0PpqF+Bh9?L6L-TkU8qg7qcUBCMJt)#&)#2Y)D| zz(Q{(Q`f2`9&W#F^YGRP_q<5$ozH6h>OP%hhnnVH4{4@d@@sZWR&9aiR9x zGfOizx;xZ{Jy1#Xs-u8vEp5;65L6Fq1^7len;0fkv^xD$Y8>l&k7Kiz5R%iWW3?pp zF=h?^32W5^k6R6m zm*2*os+ewR*N#>9@1EG_7jsyKH|CVedS`VN+0<3fZZAj?6D?zyKi9=+cfBzQZZq*u6Kce^@;4Ds)huW%I%`{pT`^LiaqFhe%V^zjOr^HFyYEXG8*KXS zbx&LdLNqY#PH2_@!;r@ljg#*dR-CQS$CsKAW8_~`w{vrS=v5=kKtYLrn!foN>W`&@r2@We)$}R;` zHff$_Ltr)newJiKGwfsOvd zhFKeqOm8qp>FxsH?85mlL!h>t3p#+6VMo|Kv(&$$ zbu8^vG0`le$8QpnVbKn7zMOX1pY%;cQu4>|Ku-22eZLjjVc=&yiOI6{bs12kX;gl? z7|82C)ddeVA19&-Rjbhn1K-*2lD>MN%M&j|>Y_Lr<|% zu=)C6W_wPI%^7!)xJ==3Ak#x;so)~R9g3}aT~6M^l=qXgshh9K--JGtTfKY$v&@fL zf7|j=C3pwsynN?tvnEzZ>Lc_ef)H+sQIm?{QI!x#Sv8)I)jg(JWWFuf=1`x$f#nLU zc7jq(!T6tbmeBK(C=D%a!nII1qR8Nmr4dnaEJS&X_fQazO{}nj4wp& zI~4B`6+a3JFHbdp3HK<2)V@C0U^UsgHg?;`>dFE$e`xn;Qe+IVqOY4uo zmg|2CY`K01w)d9FK!3!&6C?0?Z>;zyfP4SD{}Mxj0677mR~zVwU<3iZ*Q_kSUNj)b z0J^hg{Pmu9yT2H^xc>(KGCEd3$cY&kq4~ezao)j5wtpMmZ-W;cm)AdHh-aZ@q^LlUmXaPLV#%5 zPY@gg?8*NK`u`Lvu!Yaa23)c~VfXtx`ukbMXCSOy)-9cqyg>tO z0`|wc!w`_(6|Vxt$_2t^E_U{{LdVXw_|u!YY-hMg{Xo6zV|{aHUbPVV{ONXit7b09 z#zP{6!?n~r5K)4AJE`$Y^515@jwpSw6X7kiBpJ`G6k>gYY!U7u(Nzy$lC$YV%C&XG zdEro{YkaY>Ed=A$!uRrh^P{>eS)~=3jAkrFPDADp3iRI9p4H7$&_R)Lk|(ieM-_Hm5Xh|iW<#+id9M;-jt!Kg z=dRn?#T7nl+{$W{q&BFlfbzY(Un*r!PnBkTc5B-$F3HK*Ret}TnOM7~m$Oa;h7eXp zC-e3z>j~vWSPIo9eT}~2qg#LOvD_j0J|R(XWe`+G8ykuECbWz?JSPtQbc5bXopOg@ zL2_%Z$D%@nWSyj3ptgf~Dt@1y#Ctg$@T4{x2s(_JK!PMKE3HCCGc^-KkTo=Sv_5kB zXhIbOTv1F@@fKV2L@y77>4ycUzMx`*hNV3B^l|mrOvU*oyN#n=tEz0J%0j(GXqB&Q z+KPoP4A1%s*N=wt$&&NmZuLKy6s^LYbymUY%F8iGe8ygaz0A2t6M>Q(8(c?Tw)EC6 zyGadQt4eJ*5mxTxA&W2p8`jH7aDyZG_#4`ZPMQLnH_nZ?OK z39q!U$&4@zZie56*?Fjhye|Tq88B!X;4pVDx*&Yf7O-q&=hj%6!GRSe(IDO5Pcv_^ zC_>p;GipyT<)Rj5udKX*9E<7?t#SGw^o!f%_Jw)xR-v*2vs|Ex>V$D^)`_KoT1#b} z7gNj`(Ti8Ife8xq0p(n{O4_$8F%E2~LF4G^+7if6azP2yb|>6(Dr2O^2@a$$eGAE~ zlhl=SmW*Rx2lpKt%SQ4WjI}N*Y&_g@h*!PQZ^c%*xvCs=If05L;IgBw=E@i9>nm=f z8AoedXDX;?3}<-hBdt0Evd3?&mtDY?#XQp1dayg2As{((!188JeY7aZ+NA$PkV4G} zrD<`O|I=mACg~J${6wSABfI{SmbL+!R>%6N)B$UK%uvEBwGpLCHmI6@#^h9 zO%zJxUSp;m%O34u1*x(iHKKumqt8o@?2&E>ZF@ht_j=eOJkYV^&A5&ag6MrlqbR4SHA3cO-5 zOoei5vs>hpsj0Iwwc}nsi4a~|0G%EhS{Nt5AKdW!2&E!U$TvokF)!!xE*W8B?mPRoKn# zNHA@|2Q37#Fcyv;n^;LID?zxw!~zMQb-~J;4epz2X8+|-q|Q7SH^%B2tQC|?xMtax z44BG_8b5ciL3`vLEp<|3jeSn%rpt_4A83pP^>)UtNenehdi_8*P)>;GJXcbVhaB>X zVIiC^j^ez6>vT2?mWn!7-4i+FZ=sIz&^U#+#TTAqcq|*~EM}&Kwk*01J}rKmyW* z9unyG$S-dsKZksIE&aYd)PJoYN8Ne14keo-wRTtnAIA48_Hf;sIAfU?e3{QRx(lTmiTc)8Q`qV&FTOMpxK5RxzW(&G; z+5|!Y5#!2cO?`L;+w}P*?@oQ|^v(rh^dz-|eXx|%N_~eH$~af3&Qk*P6<)PD*!>~h ztlf*CrshhM2G{e7(}Ip{vBXPhN7;TO=2ckzGgJF{J!zCz%(!}XT9z7mw-0Um;sWz# zE|+Ai`e-AFr!VI)rLRD|`=owPKdgFl_+!PeK(#NYr>X7-=Ga`rW4dS_m$P3Z%nH(F z`Ouie3CCb2-Ex)IM+4&`!Q?^&6AQN|5mjvi0ut4Jv2c&}3?R1C7z8ZnYFP$HB*FadNX+Amobc*>6slh{G3Y+)wN1jPMz2Jy0wQZu3 zWkt?XY$YUgXgh=mu1%?prZ|@r_%p!(C``*XxF;EmXW+qTMW0iM2v>NChDTA+k);KO zNT9=^@Vrl=q`BKCvkIdoWGtpxL=Ks2gU00Ak@8n+3~LYT(d!Ryrlrx8K0~HHU{15lW`dErya3}X z9o5@&sBnn@ap4Zr3SxQ8Bm-2C`~ed0p718DYKe+-_6J4c6}n}Xt{d6s6S6I~2Au{s z43aXG$W%MFlEogK^aiAx#LpKj!n@A40B@dw! zaW897ShRiYa~wN&t(UC53~lsNr~V5{m&4cyf*Rxf5BrbxMLIRuOj~I~QtMiA(_*cZ zEodiSybTo}MdQcJmWOQ@=Zy;*%R~w3lZO?#l0c9`LZ<1(Zyd8xPXKdu6>V{l%Ur2p zgWGOZ%)2N`s^GTLk`-EGMj?6yBPT9-%+=GF`^EXnE>1<(gGY)SmI=hrMa|r|*b>ZU z%Vg}}Y37Lr;}EFE&$w|M(nDj4G!trZQM28reMwV?e;paeSg42dWh_m)|3%C5(|4{o zQIhk;`>^iMpN*zFPX*uRk4>{6@-`y{)bGshT7`c$RSTp?bz2gYnWp=~dR_JIk11Xx!Wp>e1wsQF^(!EKe)ylI9W7~pyMUs^fElnXN4H0nA+_Xim5YYCY$ACy{{85*8MKgPbY{ix%=qp?4ArvGu=v*p2GSr+~=_4SVz{9%#^jQIE? zrh4{T{`Ukuqqsj@krn7Y!U$~0|I@%e|8nT^ z%h?PEkc@dg9|KOTFcTBd^y3HR1N?@a81S$E1O2^!^zHxnB}U*k{~GZR6~KTWe&oMZ z{y!Ly<=LO|Z(_h4)ejE9=5*ls&6pfbda0J0n9k^q_f^z_RH|v?9_z5!DW61jcU9DO zlsx{`lmiqt8adVM3_cGG1Qd&R`;b3Qgem_@FIE!$`&cx(Z#vCyvVys`T^)Mnx8eMh z+OLcDs)8-*RgE&yE9zU+^C5a{D@DzOUw`1{OGeAR&~c|^S5fAP+^OBWNOlkr)Fnj5dr-okI?JDLos@A~2b) zpp-WCO3NS=JAW9`^fMF%+rF&WOdatZDU2!V5$fcOsld?Oc;yrKVI^=h$+%j0dj{#^wv%jr0P1 zEDvk+hL~WRA?&@p4x9lMc-iC%v?$~{09gLKBe9nG)UQftB-1PxJQR6b<6SxsrVUPE zDorQ4gA%0Z1oY5q9vOJ~fs9_MSf<~Rn}}0`$n7DH-%y?t+4Muw(DU|xxqp|@1RrtMmke)^?GyFsXNP&?aB`5 z3N@uWo7(v;e<@wALhs}W)1ozV-MPDa_>mK`-q{-SA}9CxjZjxrC4T?|^5sgMO=;Xs z>HKwt>q{R7o^ge`LbqOW!GaM;Z7*=@IbK$j z*bAi+&CBgff9r1OP%(d1JRwy|;)gJCdD3Fy7wzH`aTcrRbklw^zxD1E@Mh~<#d*iU zla#hvB$CUqOmT2-f9T??s%mj>lRG{(b^{)vQR0S>0-mLI}5O4VxVCwRma=%OVhP5osH4@#TrA|q-&c|8*I%s!@+nZaCSj9Ab4T;cHpn7jZrU1!B z0cqC~>gr&WwKVWF^OB>Ly8!P{(Np@a(7wb)R~zwrRRzz3*U+^#`Z03cxWz@|yUOLS z*SL>s*2hFOrH8?tg#}@3FztpQpd>3p1x2|k3rD9|3ms8-OtoJMY!Kq1(fg)72Or

TZ{9ePz!zmAu4?9=ttoa=>$yd;G!aTo*-JcUh8J zmi2>Z-;1w;s>{{hnpiCt;UIzp53drm_-s+G$#V0TYR!%`HPpDdxk12Kg*3|Q$Sqb7 zv>j2@S&^}gQa3vq+q;$Js4*jrnZMaWoTO2Hr4ON(%7}}nd=l>Fo%b@!*5FkXG1b%U ziXqfq?~5D`u+mG}pv<6&YrHquGDuk7SJ4}E7KPA2Aa59J7nT#mgAikm^kCG`uQJ8Y zKf>?MYXeDh!i*4sdQl}v(**qz!{p|uF4Bb}KvbUUDNr?i+w>Mnf8*2e$Gqif|9jeR zhr=R6Jf&m{@0DRj{c3T(_~a$VCmL*8Q^vryp{E-~K-*~6KAd0LAS|Sy_1}YHnek@p zIw~&`fcBfVP&Tej+(b(tC;B0<;t5`tT28mXB13rBLQT)91lU&(Qw`!dv4$y!r*R21 z^w&+AD`gCR2w;hU(${>a))5F{nv&A81K)G-=yOFW6JSKmMOcfkYn%erfx!{GrS~aG zdAZ9>ovOSkv`hO0M`pM;H!lsFTgP}LPdfg|CH3R{B-#E+Q+f!TcXZY zG$QM2dxV#bpl)=TN@12X-5oYKkN6^}y+z|e{Z(k>x)yMxF-@~*;Ka~&EtuWraYMd- zBM3?g3)dbV>M_DqR6MSJOM*ij<9f~ovThE|r`rlUb^|g~M&`SU&B+6Wj>z573H4sD zt45ak!u%=WqNF$tV;Vqr`qPSqqTGRt6J3j7yb{;iTFs_7zE6XBc~%* z*O|-ZGniRs9~%PMYan-W^YNH{hdcskC-Ne{5WNW<3fmOZON*Q&J5yf9V1@?Ei{wPi zPZQq!MtqjCj4ENnVrh4CV?+J{RLzqGVyJ~MmZ0p@usjszmJExHfnbvHJ0s>+=r}!% zv>tXkoqEU@oCUqQMk#G;KBsSddJDSOsMuEZjR`fvb3Hd z_yb-Z3sY~s*4WDMlu)eSIaNAUY~!O_Q+M}^@h}##AQSwWbo)(fjr$k=@0=VsK^;P%uwGhzZR_}90Zu>1Th~A zCk8t_m?#f}W7k(bNTRY*dQI2+^}`EZmwVo@h8Rn#Bk&Q;Q0TO&;v{?v`mQnF2}k0M zee>n(Ch|m-!Wqk#V^%nJ9Bpc=;%t6*@N>~~Z-`1l?4ujJ`rcI>h91G0<&z3IR#&w^ zeLlRL3NYVWYdDa$i$feN<8^TbplIsYz7xigz4fVkout5r(Y&m~O`_7lB}~c9Ax-M} z*@&{ciBAL_7T>V|#8ZafAFNTF+=*-~=aqLQy2nTPuNYRR%kiVkLTDF0fnb@@l&7rH ziAIW_*~gWaV*&*{dj!1#H!7HN61BKlk;1sOR{Sp8q5Zd}1>HM~4!)1iNVsm6!7OK6 zfnV#tWNFA9svK3xM3>dmkt`5AKob5^>0F(uUNEV&6OfNas>_ghA3v>j&?uue{ zQ{S}UxEd$mmWOW7y~mlhF3#kEjg7?Z$tT=#VI`IZBj!3I9DVZLu_@?~p9)Ff`5GB6_M+<0$Apz@0Rp@7h@C?IWd& zF5(LJb{y_Ol@`b<*b)+dH7yPFs{D|JXI3J1{+Iq7s1F`Sh3LsmTHw*x_jUcjV+Ek9 z+c4%KC#blMT5SNHI^v>sk?2XSP6M{wJxAra-6c`vBdQRr$1qZv>1!f=fI-;^>1my#*)w{3NCVx4x*@W0UM`k&!Zs2N zH`nFBJDRPX27O!h`!22m*GOqMRtT8Std1*slM?MT(>99*L#{05e3bp71GWhp=bBdb zxSt{2ja=BS)!nvB&n&E%+@zt(&R%#PTW-l5>m#Ty))P3(t=2i{e~5nsXZ%jYaul4Y zVsX$rn$%Gco^IMuwmo%%T}yMXgWHjp1xhQwAmOoGrA^m3s#x=mgf7S0)bU=KxAy)C z)HYCT<4@!Q;4iYM{-8_v2^oJO7XUz@`pg#muRE)ro35WBFW_g81n}!modN&|nt%TM zC%^^#2u=Y0-j5uFU-b$RH(S!3FW>r}Dq7 zkBJ%RzxhmP0DwNQz`Kl@l?B+!4wQzl1KknX{-)^pUlsnCL1SHQQ%xgdee360{`99} ze{U7|UvGzBC-b>jAOi->Eu&|AHml_XQdG|ltiW^)&cCT{_*bdArrI_(nm-EuQ;Giv zA@p;J&*Ts@P$|O9$OKf101b74k`{Irpu@uNZdl?UcPy}rk(isCm_d%1LBvAdf|x;& zm`c~;Uo{$=>zdl>>Hl?=zl4?iFD8-^sC#&hP6N_h%)qn|PN3`Wa~K>m;Gb5hYhh}t ztz%)W{rorgA8LL69RJsMC=0L~^I2356q5s05KKU=IWv%pV*&t87XbhCZwPpAn*Mc- zK<@9~H3C`2pKI=aCsKj>`~Uwypm+2067WZM@`vN|Z*%e&*8|%B{_rRLr=Qh#6!Ag^3yD^&M@0aqt2B zLM{I$U||PJt&?W};jG)~5tLUyZ?K5rR!l z7Z;U5xsq$IPKQIHT8%Le2}u~Z1F1UEvjkBG0T-F-ii=FdmBjacfdFNybu6rmClCUT z!3gCfbhpNaRI4KUZT0rEk9sPJh!|h>am%A^Gdz0BaFMQ?Xk)Q&I`?$$?oNj29F{t` zIsX2DNFj6p{#S7x&b%q@@(0JzEHl8i`ntN3-foLza{5LaE=APd$b!n1=ZW9=C4X(_ z8ReT)F0*{|S7-G_Qdhcep>@FXG{0r}1O>2sod5)1Ifr+?U|1%22t_;jhW-t^Uz@(R zUK;NO>6Ppl$!CX}zuD^5RRksX>7KLbO4$>xF`~)%xRH>TM@csqDVXRsFep(F%9{B7 zA%du}D&-wxf*Ad+KVz-Lgr0&DcVT*9J&cke1vjQSDd=KLqg=QgMRrYR>NuDpd6MPa z_Z;)$-K-Q=TbI6I0iOB29=8$x&lk!4Fw{6GVV+m~C|E-FteaZz4g!iNr4x17cflBYP+(G%DZUBIP3JAy|r4DPy%u7l7m||Kb z60XVEL85UYQK;Q2-$Q_Ny|&GF1j(is;Acztt;Lm4o~{aR*QLc0)lKM2w!_0nH5uQf>vtUv7psy1P7FzPWQ|&{=!6OL z=r3<41YETOQouWXs%2V)y{U+xYgLKL6B+%WT`p2~OK;D$oFoHdU-NkEritkeXD^7& zWT*@mY!&yCj41f#;^58f2?kl0i3R? z0RhYOVo=L;tPTO+TbdMSLLWt7H85R>idY8wI2#rrbQm2j&lO9WtjcdIiY|Do>oc_U z)ba#Ow{?sgy@f}BAIlbZE|ZWI>nL8zfV_{{X-h~Hgc^xi^Cj2GAK#j;hFns6oH;+mai8>RF1%vu}UgP7&7tm z4p{>OzK}z{XG5q~LLB4?qD=>TLa7~Y`hdN*!a-C0T{y>dn>kOe{szwy)5uY&V9U+{ z;O&kwgh)Bj0)Z-(tXB#1Hi&P=gQlOB7%m`?3R5bVpESU#3YD)(!T($Ge7>Wv)(Gza zi-3M~%~fK6?8)1hfDHv^0;`u}7()9#g~d4y*(Fq_fp`9AcGa%(R|O3Sz3@s%gdKAY zLk&$s)r)SQ!#?ACba}R`_(y98q94cND6LnDBPE!hG4oKz+B#2t%W0ScE^IL>Qukh_ z`Q}0Lelue40wP-==yJa8=Swx5wv5)V=JAIX$`_gQ@_5C3A73|MOszD zN5zK%>0n|*(c_wh)Vt4Hw0!J{GPouS+ozA@T7f1Dmv3|ZIf)9~eYPMQ1E@Jf(v11S zpp@dtVWn5;CcV}5Ar0m(lT4EI_}ImkTkm_OZhu^8SRlW&Z9SCID6@3_xNI00 z)|(?OmV%K`&@f$ygdy4|AeML}>@=0)Rz&7|a)3u(5AuJ~7C%>m@oIF&naqd2h z9(W&PtaaeZrw3g5PJt`mI&kId3*&!M0^my3?M}BN`yAv)`{RP zOfP6?g1&Vy*7nC{-;M0IV*sM()>G_Ko*k}!T*t5Mp;9%ws@ZoP(-U3u2RTji>#wJn zIBKFSBlZN{BiB?@+18Y!dK*m6nti|s^Y5YA#mg{c(NTOGsb*RLcKpN@84_nWK^3sN z(rjG(Rz~)r!LQK0PQ5kpWEQ#z=`^Hb`8z7pU7BQ)P8)?n`6|)(24hzW;K;YdCv%1d zTywRVsNiYy6ze&RU!V-=)6@`JUO8Iut_AR0o|E+MVJGQ#WKP0gPewFvcYbu9k&pr> zy;V(B^POO^{hBj1l`G>yElJYBf|=50@MYh#%SmgOF9C+|BKL98GKDfts!O&!^GWfl z$L--Mrn+z$8id<`5KsDW=pu3cg1&qUB&g@;dNmKQeE5I2yis<5GWf{5^&7 zONoOksMn|1lD=0Fb{pcNi}{0PyP4C+gZvZm8~y;A!s_U-tXdZxK@yOAq>-Vk?5yXC9?x^!!x8}n6 z5Ki1nRMMC7Vx2C?#T#^FlhFI{8jl4dL1Zx!n?Yc#4RIw=Z=^H^l)(57&To4j3|TFz zih1(O_85_6BuT2s9yoXTw-~-6+r3=8h!`Fj0Pzl{&8yUrB*c?X0_UElM*w>b#S7Lg zx9$#YgY+Tx&%Dhq$%Q{b+8=qFAG_sWd7Gah0soY@`L`$p@Jk}hGq(5{W%FOVWS=uC z{|$ov6SnvTDg3@?6&O|nOvnJf!m|M4cd+3Pl8JxX%?kJhD*e{Y3S=t&HlRq*v;cOq zwkN$E!Il8XS}UPF!SnrNU)tukF!LgpCc2zJ4aZ|EzE>cM+NYuMaan5 zu^m=LHd?`GBk_>(=6J;k=6_I-GvtQ?mAbpx%5jTWCjLj{3*xRUjnbcEW zDg~Opi~GWe6s5QC15R5+<7wy=40dt!!=)Xp3SVn~#;a59X72k)Q76ryc+aX;To$^7 z1e1U+W(;4VrN?kKz_y_hCt<9oL@;>0?$l{9ifysp#vm8mW+YX(9RUWdkXb&5{PPTls&=h*9mmrH;zeRwDZ37 zOVP@uD9%wY0^XKHQ;A2TWf2dbk1>yIskG!z;-;Q}R6VXSi^9vy#zh2TK|~d8$<@9O zz2i&L7`&*^e#gG45~cSw5jwD3fI7Ghoh2RGfmw%u%~!^c8<|L64!4qyt$WBEGw97| z*~@sMGI{7%PiYOzw~lOyBa{<+gGKOcU}_jS=8Mo@c;mmFoT0v)kEz6pZhg4@$|{0T zD4gXeS|}MgQ`-`DmI)?fUtLJ%MMxAbPf&?>J0wCyy{g3G>yYeJ>O2=a=yH^Ml{@gw zH~VJ5Vloptl01nJHmX3NF@c3mDn=;FWuup1T6;Bv0NsET*t zlW%X2e!QoX@Em;sl5)>($IVh%`((-d**MDCX3o5~rK}B_0#`)X11RkK{#%snNlvL8 ze6-}9Kr3{3jw0gRk1KEK2dtwDE0jSPGKYM3%V>J4#~L~4J9dq9wGWBInJxLB7*R~T z7Pd-eA^Ihn)d%M}5+;eRRS|UfS9UeU__+O!Q>|*<^tC=aa-BYbd_BQ|`tt+lN1oVk zj35->VP-KVr*%yX^A==SLlXhdlfJ1LrRWvatV5 zi2frB_Q%ATKVI_|=o%?g>g^Io9+<@_YS)gP*jqXMS^&v$8fj0eTBf=__hIM4GX>V$2bu<)=TjHt)p~VzW8hZM@k7{|Qlbwc3 z1x(barh;?~`pOD=p+0TlA*rnTOXiaKBaUjcrsKmcM~qpkXu(;k-PK}3Jv0z~)DY>m z$v69A{-FuEs^5R6kD_z$tl!0r({(PAIU8&GorDCmVUcLq5kW)wX6*=r+Q;qrW;A;ZVaq1#4`%JtuU1TtF zwEEwNNs#LaT6yy0E0|!=1*7VBGF-o5i^aG?{#dHgfQxG9Y53@Rbq z@E$^v&a=H87b_Ocq2rFBw9KPg3*+pF$B0ZbL2uKtB>zB_ql*=k$f8rL=zr|eFh$GtNiT* z_#mWd+>c`jk!jtmBid2lc-(re=f`}|YB)tE2ILUZVpDDK)@vbsx=0E>PCk1riGNHXnBAr&WIssv9C z!8E}&$FWn4f-j-|dm&8TIc6OW9U4yU9+(t{(|!KZZ*`D8IEG~)8atTWSZYSoVgTZH zfW%sL9CwO#&4yKj(~D0C3;i$Kj}g(Zatt8EWekj6(pCrj>c;yhrIJ>(#O3-hL07{D ztdO{aZ^Jea6ZmS5VPWE{b-nAs<;?8qfCest;*2B=j8~7heAFrgn8Ud*B)#J-rzWl< z5KyQvU(3#e+Mcz9TLw*8?X;~3@1#oBa?J z;RTq$MhCIG479V5EHBu&tMx z^0u6S4!*pPu8%vYg}8Pil4%MHGDKghOpUWOJPVUAA80xvi_x=Fqoe}hbaBe%i|lt^ ze&*0xk-ZyZ?Y%k&8|0cs$CvBn&@Am}J2l0D7-^IGoL@jxYm6X^ppMv)7s4`b5FAKY zx};4N(+PJ<%h|9oqxiLKKqu?PLSeVr1UjlVi~%Fs8Uw^fOVxm>gB`9&&{e7xSxPi6 zrc@oA;AFL&KTl=+KE0v6(F#?ipxPq*CkKo5Jp_22NseCwFGD-xK=8yu?(nHWX@l z^f_6|B((83!b;nKs+l~jd>}BB+x;{9>Lo+f{}Q#fVac%b6Wn^Oyy>nZJUe2A2OgC78HBGki3xKE3+92_L?@k1;PbJ3vB_eF*c!cV-X0m!rn=;ex=Yg; z2RT>U`fqr4_4)HnUWSSmhWLzA-h$&9?Iska_LR1)l7hHoKek!nK#VVcc<8A;dVVrNc9%36_%^F-`Q>{CAt9Y2)P({-TU9Zg$20=z<8n|eiOuRqUf zhPGf2)$gliFu#NyP|6dsJ}PYLn^lkE`4%Htrvv6C9084G{enGBu#(bLKA)3}R733m ztd`|+B8LL4Qsb*I6WGjJlntKGm+n_W`F^Hs7gCOe z-TuyZd~gtc63S`v;*RL6LWk0<*_v5x(eV61?1~qq8f+s{Y{(Tc*TjPOkLNawha0 zL|o}-L{&m{TdbODYEoE7r3?|BjWc?WCl9OV@dOM+^ffQ;FrbXFj_9}8)pN3qt(_9k znq9suxQ$y(toVmliH#zPN_d4ImE~DTk4EYBC@r{Nu@GqNGik7-SsiC?G2!9eMt*&` zDj-LQzSU70q^Xqh8CIKtJikn>Ed278r6H<#N8G8ire52FIx>(S*N+{I1dkro-QMIN zY)|T&FRh-diN1Sc)@zND19Y(*`m3hRdD8_CjstH(LXk%C=EzsyE5QTPQI7x#x$9sD zT@==7)rTlNlE&gZnAA{?c}g|g33^Z|Aw@l#mqL}s@FYbvOyI;}@0aIx8ya?w2wcK! zUuEPeL!y5TA}u3Qo%zPku`AZ~eqkLNHcXx2etN1JlxvS63^oDBb%f%w;tdJP0U-=D zFXHeUqhpY2^@W2-wB>mB;&az7g_tAK*p=erk9I+yw0l1GfzsucY90+#mtJ(dFE}O@ zniI`vh#b|-{xsn4kfL-_!T};F#GOwbkn@;Ns@Sr*FGMhh^~m23D+q%TsnuVAkKb?R{{#5=p%{Ahw6n3Wv)0wOAqM2~If0TH z7NFb4vj~74D5l`}$C4R+b8Q_{eN9VieM{iMy1tFgpH1(6zOmoX)z5kT+qQwv)dBmE z06^swBO@y@(Cq>!JOU5{fa#~4e>W)QUxE}fZCz^%O?^j8ZF3u-*yE4FnI9AXzpN9O zMnVq&7RUz7QDz2;dVo34^o+pSeO6EWO$)()mHDGUJxvR9(@)P63k(4HQ>DKbd;G&0 z{a5r1F#j2-@Ok!Sf7s1D!SBF%SZO;M>hxi=!INiM)a9nxL=sQ)(xqIVeFp9+yLj3w zmeAJJ)Uov4d$NlFZBn8zgBiaa{4j$LQp+oq(M*XOv|RFxyRI$B2I0}mR?LUc6FZi+ zbB7$cGYwe7Q(6OIi1%DAo&-ZmJmj?1N)%l=CC!Xe|J~Z~J=g6mm;qmt+>3FP3_5Q9cy}1>PNT!%{@( z4OSlni*p+Ng1<3`BTPr*i3ihwafNy;(bav+%THfI6}>_exJR3qHB-e7*EAdO^pS{$m1mlQ0WL;77BZk&EwjebCoYxHrtdF=ei zOh7ft0DS{;_zi(`A_Ut>pl6%uQG2VfGuV?!96_V=1$M?z8uO9YCTnQHwcgjtIBMUT z&J{k}(gwS=2fKIJVy~3mfz^L2b%X^9^j`3l(dOV0W&8OKZ_LQGzQox=`74mKfPqM#nEv~$ZP(GLFBlgl zRW~Etxp3F%yO|35jtxXrpF1hGhqurhIQH+MxbC4EVb#a;KUUeb1Ya*TiuQJ!LpF^v-!=X2q5_LkH4G7V;FeIobJ zf9)6ATnHkPmSse5{*iyZnyJwAgD`^tv@HIFlnM+RZLP5yrOK;Z#XvX;Q*(lD6gpzP z<1)@JJJR6}iIaO9s$4E})O!crh&)MJ~SevYtc6lOxJYKNDTjv{OWsD+MK?0-fIt zlY+TZbV3g2F&z0b-Z#I#!!ID(Q>lpTP$$!3TFTJEiqVxP<=jsq7_nU{f zt<$9kx}fA8lU5Nt;qaDqP_b~-%89>|h3nU4DntgRh47EfFb`1eLvov-&WYZ^nOUO4dO`JB8+pT0MIDVS<}zG0>ix8`h~z z>`P3xNDT%;psM(J;^Ck^si8dA==(zZkSw!|F6H-=sosce*uJQK=t$zw-v;1B>E7!H zN98&bF<^USo2Qhp_lr;ZcKb2QlZWWL@YSn$UPhc8A1FqaB);JF3#wke>s+Rv3mSPn z8`!Vpmrq64%{WE!p|~SU54Avn)I%UX_E0B`BqkL9J=UF5+&w(hIveCg4ug(QX}z0= z9}e-{KnXR=22pacmd~y-^uhi|{bmlunq!^hP8W^v)ABm3ZA427j)N(HSF0MjQ#0?V zyh5qTp&?X7$^6F;0qA`V%~-Q^_Wm*}TN8E!{V;ehil)=~D~MtfF*wD7qlB5;41-_W zV524HH7(zM^X)o8fJY64$f(rFc<*oI>z8$5P}3T1%C~g-c0n@?A0BN@<09C!W?&Wz zw3AxF6b*Nxd0rr6CMB)Wd)jhNq|0fFKroBP3RxT)8Z*=FTh?;$uzg z&DO3;eMGhhdn2vBcG_M%*K8@=Jhtj?9jC{~LKIL37*U7~CQ7nNasA*dqe(te*N8cq zGFh>U{j#{B7L}S54nyuR%O_W4D%=CuwSt*hyzUiM5`?oI)xJBw)g!9W)?Ap8;?Vc9 z1WJsfl#T`zmTQS;F{VLXZL{ut%6u}&F|-loHOOKObOoy~3tpzIg$=k8vbas^FLV+Z zh$-Q5GOz?^_X*N`W>ng1+a2VdYoWy?aw2`?F{DK<@8Ux?&n+jN^@ji>3a<-(?~b*7 z;_Z92x@Qq}oy+jLXq_|s)CbFOIP5cm^HNp2=XuO{_xjV0I^0wEVoqPWYkY@Ai$rAA z(R)lRarWqCdk(~xni(tvZ=`P9EiD%gG;~T7dEfPDk0Bd=zFB-IenSYFoag3fU-K

`u210LC3nViZq%#M!ApPLS2>p9s8z1?}B zoU09wTfasU>vA+gHKei#ip2qx^*!j;+V}1vS{wI#}7r^s>%7X;z z!-4W$)*m)|&+do7T_q4)v2p^1&FuelbN-)qyuYMsK5rv`OyA$wM*f(v|FVtzW#{;- zJo=xSGyF(3{q1tU?Hrkb=<{!$>Ez(dSkDQcs%v__Cj`rtgt>}*#lwe2K0f%Cgv43h zDhS^5a{x0eBM0qAxx1q|o(T?^uNdg@gKVLRExAXinEZb3LCbw!`pQvRI0E&Y(Y}V$ z&0KQZ)yTaM-)~~w?X8M%y~sFoDX%5k8CQmwAP42i-zq@3pETyHG{3pOGECE~A|dfJ zAdP-A>h|;&3yXOFA(7TNjIIfURw8H(CYfacD$MWg(q7ffj0GE!`XofQCDN`5)oe>; z(yKN<-v+QZ{S{{I@7crvh`D>Q4(u<0y=T$>H+`=4P1iY7?D{JA#YV3+z+PMth_T!G z?T1?6e$%9(A?zty!moaH@G0yS zQ@a10UE=M(dBHV#e^S(5y9k!Er@!Hy=@iv5n?1=3Yw;`cJYUnhKy^HOh3 z`K%e8ZYQ5F@+|~g9I=2cdotp&G%iabuB28W1Y0=N@Oy;9TYE&#P}VP?m<>pbt@R4~ z2HOWTa4=OqErk-5L%v@k;F1c1%8dIx8AUlFL{OozcIu|KsBXR(z97}Ms4|+9>!L-> z;+AG=#ceVKx zUc}<+*s{Vf#B3^-FGPwRZ^SWt2x&jg>tNa~VHA={j^1wE+V%XAuxV1qIAzvzh3NE4ObKQh8@ex@%KMBj4KR@P zqvA2|E8&8ADi8wVUSvtYyk*L+igC0%g{ot;aQxcU&vFtn^%03jh=8Eu6;>7VjJDV- zQn>}x_#LO=Guo$`kMHLq^tw^yCn8zrOh4F;R{G3Ztk`R29;2{*CRTi5RIf@#%liPS zNwoV>z-*e~ZHh!A+)Yt}N?-nP##^vWAw}yf+=Jvjoye~SUuLZHLGEngUr23w%}g+Z zv)LD%l8R#S*Dg02t9;wG+r(X`J~vsTeX9nUy(uTZQz;s~%@^CgXo*ZVQYI7h`RlrD zJ0j@!V#JKWsM0yU0Eku|ByK0<_gN3?!Bv2^^>HvtoYm@U;0dEtIRtOKibqME0tT$-2dobCeax-)iH3q4nbZRA+_vxm(mKvs z>cEd+DljEt6H-`2g{Go$ft=goGRIPG8F6c->pu4-=Yws?$kT* zTZRujb$RUz8;9{uRW$l;P>Kibnv}=3ZVFZR-}C~P$?jwn0^M=s@AqqOils;~iqFms zI|3|)+j-j)jHbAUVZ!>uaX z++seP*+{QweABe*Z%4lZT{ujFHE$ZspxrPdKaA80-{F1V4+l1AS@X8j;$1Nlw1H_* z#N=(Z+-F<4Xnb{ajJNTob52i2^>L_g;ID4nEkCG?cUS|#J_Z^_8Ei$dv(Yz%1 zcv8i{l>A;RS_rjRVZNP2e-j=ur{JV`3!h`)-H;eZ)66Q}`;{jDgwEMq%5&&cY0`#l zyatdYuKU8nmKAOCv34iKFln3e(xixNnWgI`U7p!mI|U>Ar(s|AS?yslu^SHtm1-Yn z3T;8G*!Ila+GwUB>$ta5kXm@$EPYtf)@NN&sP-x!yfC4=ykcGEeMT@K;UC*W;N?M| z1o5&e@Fkk)ScXjSRoZ6?%>W&3Y%Z1*vzb|vG5eMlsq$BwJ}v?t2YGLK@`uR2uVcI# zgA3bSiNE+L*B%Y$Ipw5ZhTnmeZir$3RvCcG5?&hMNb?r6=p_o_Dmv8?6iMvO)q#BRGsVX6Onh9R7gKv(gn1k0wo+;YT*UW$ zI5sHv$ek&Ubp7sp=t$gQ9d#dem~wweo4{fR#PBzZ`yU>kjLS1@{$ii|`xdzWu+RNL z3I0O-|4fVjyE50mApZX+P9E?-aq_?HcmFTx&dflH7XS7IOx|F`O1vmv06KIZ2GgVT&`ez=-J(SpvTt43+`Xh9$v9)BA1uI}B@gfU^G1 z<4v1)v-wDgE339XjxQv^MEU0;XZcjKjRsK1v}#aD5rS)txm;Xih7ne<2eLtcX8ztO zWGA)$m@_Fdl^rXn)@x|wkU;qtDQ561CTb+yuEI-y3)gX%l7! zN%LXnjy>O7ftB{l>cqejFik8kALrfuC^RcQWuE;=A*DXIbSFHO?JBsAm_zaUAZjWRY^|5 zRJzkC3kGg9({@k6`TpZ>c@ZLR1l{fckwVsKsZnv^S@{$`j4r-K5N}E?H?|Z%m^aRS z8XUGP3MtKYg(5Z>S^(6TepL7iLyj~(SFDNySsJdmO=iP>NUs6#Gho`Cnkn!;UZY);1*O1U7KycMi$Z9S*YVfie z+6LOC=;fS{?3U%OooKwZoZ9uMK}2P42oVc zEsJSy*^vEGdkak)AszVGMKuqR+-qX`84avyV!d5>;grzeS##F=B5~W5T3TVm z!zev`X#J4)Of!h`RS>-lia^E_Oy}3@n0(&;vPi_tZTEaK`9YI^XxEE(NP$N%s>`NkIFPSp7;>CX z?~DVVg$mw1K3;9p&*&JDr|6)yL?8x-u z8}^*9{f14Y^!vwUB%+9>qbqbA-}Zkw)|GqPGbxFLD0S8IaU>*^j8Vo`9{7uh5>{7^ zQpP0{P1lzGKHq3d&wg+>Gm`CVs}Q%@SX22e;RRQwyY%tb3Uf6iZ{;cCH{V5iicZt+ zOGs&{+3RQqHq9g|rp-a28Qj9|=31)FznntRfbOJ)k`t7za$+WfB@yh>rO$O*iZg`Z zVEzOVIP&CQEG?YCm-SVsT@yJ)&0?p8OCqS0mPBS|noM#L+Wg)&?>%^Vz6iLeSJ|wT zKcZWlI-}oyr9xiyQC%L5SCxVB?vaO}y+i`r+g?ep>+AepaVmj&lOafOh|qnq3C}qd z*|!MH*Yp(;jybbb)?Chn(H*u>ZjvqASokkou@#bsCl=8)N#=zsWMtGz#XN{gH?jon zd@sfIH7O4)+W0#YNgQhHJt@>3Xkl>U9*?X{M4~s^^whSOh$hXH64VMZYzS8sE1zuF z`jlv+rHmRs))?fsN?0al4rEykx!P-V49Np|Bbu6EKk(QgSIq$b{TMtn~CtMTL z&1)V@%XRCDEo#*0Ut?hMb|aQOPIx4_IX8HX>cu#rZ;JEgSNzXlDfAsFcBApBcB2NX zM@F3zS18v=_wtvx9f2Z3xH0k3qasdd7A<3R%HIj9#WJj0EziCMZSAt80A) zB@u`-Up{k-bei{^H(m&gK0eh09I=Vn@n{Ld^%UKKd%FVEXF>P!S1S0yr~LO+@I43m z@##09ZQ=iR7U8?a{GWN%w|wyXJpRUGWI$5-V;jTIf&WGlndJww`JYFmX8^d`0CGqc zfcFwBAm9Hb2mP+;{2%7a!urkl^H%{8mhXP5|1J<9lLW9P0yO>r80K4d(yzn*Rj>Nz zNdsJn047x5;pf-DzxK}j9Qe(hlpgRPA7IBr^X>WluhD;PYxz0)+pu)sY)yX?_mg_` z&+jS|fYAUwM866AE1Ujiz;D`8Y`>l9U%T0U7x+!;hv`@Ipl{^(ANLUx;4PsC^sD@` zHf%rl(fqUl839{}j^Q_p!}eEwo!?BA5zw*5{5y8~!RP2Vf%Jg3v2O=0f1T=o**)~% zQ295iH!MFmlm2EzK-(7+pd;{?0l$AO{JGix4XOQ5*7*_J{wjgQA}?AFg7yRD1hC{dr!2^djY8zG4mPS=rGNnYkdvkETW-`ZTnX zX|<9bJy6sdP5`x@P#MhtMi!njMV8!GWnuY==)xlE(n`{oS>%c z7T6n^2fv23TY`xB*5B}Gy#LdU0FuAW%k{tvOgBEHdiVT={a~mJp$-aFSp#(s1M-QE z47_ejLOVI&kBftw4cSHIS>TZ+AF2vLmk%N)F^7YD#Tv>C!*fc-8LrD4v)%O!p%m0q zgxI5*0osE1CLhWM#1Etbr#49lWmFanqEw6mz*^?b%8U(ELv>rSeK!LOyHwIAJ7<^3 zoZroG6jR7CFjDSP^XY$J(A()t9FgPWZS^+7ecn24KbJDFz zT-y!`(?LQV^d!cLrX&Pban+znT(7k`e5Q*etix?1B`7qfSJ)y(nYcI7@L;+ZNhg=n zfP1Jq!h4tmb5dAHQhc;$D5MB0XR2c1s|xUg%mW#XqQWAKs$mtq{4xL>=hVb>(Uqug zKL@XZ3o+(QWO8j!1l2-f&_1C)rH@now#X;|!}7Gkhnp9UyingyqJ_$;vz1Mzp(>;_ z&`RSxM1M-hTy+`SkyD~Dyc{KHvcWxU1tPY`mv+44^K168N$)W^NEvF4#kb97> zM0@cJX8WB}&HRTdIu0f5vY(QQ)_2}5`r-4Eqy)yXt6z#lsi(xX!M;5pDBUU8K+6Hw zN~vgO4pcLHEUns&vx{2n)ogX#b08D63ciW zoiV!G7d4qXb$#WaDH9r z^dqoM-rXC8r&`)mwboP4RCAS^rn%!du9o+U?>v`} zd9uvAhF0V1Z!Mg6T8-{2`*>b<$UR<}D4=mm#WRO~)=D?-G>5RUIsZ1a`pUO>49%{=m3J-4d&yR05P)@!g1B;un;Wl{k?Li5Bok_*m zH;OYRJrS|FxkK+Ols8UAlmMfMd=sFG>R`|$J|}FG78SQoGdR>H^3)XP1#<}rLfEz) zrv19K_R~w{_|RjKhNv4u)lXIT?%FXtC@%0`3|C-$sJaQh^{ocmXoSWBSMHzj#G8b7 zfQgEx8n8sEI(WBBn27P@N8)ZKcuw~yUtC4U$A?{diRQ~uxI-~Q>t#~-XQ{=B8p1H3){<}EE-Nev*W zfcniKyc~lw2s4U^gdU59$t*Fw4F>h>Zv2uja#t{q$|Wip_Wje%OHKPq{hlLjOb%4U zR=X{BkuUA1ufp4;+CYi9j=vmWIUcVaU459iM5UjZk+h#}HgV~5B z8=M=^d~CIb?snE}HP3>mpYWkeZDS$)=lr7^+7)CThk*MVOGyEB-zraKd%2`Yx(U(Vm-^=CY; zI>oD4S7-9VJ9IlZFWYjUIByptBP&mhIvyG5!`Ov78ZkX`7=9Q}fk7keweq(po%OK? zoGKJqOr_NEx$RO?RI>{_x#>y^TqP4kB8In8)3S*Qjt;gt0lKd~;=gd7hrSAAu)Cnb zGe|&_C5qPjG&|+v|5hgb6VO+}hQV4hf&9TTHZQbn^Cq_7+4^!$uWB$Lfv3V-u=Tdd zi?$uISGkg(RXI8Rd&m}4!78+fKFa`|X+frgA~|J^+=R9Zk4Pp}nlUyq) z&+1~fsfjH@hsT0YZins@S#FQ+-_p^aE6Jlbw@}F7K^<*bqs9qE;}tSVOIBlb<&Ek1 z--PlQqItTxWJYb*4`3$=)OkE6N#(CBT-7f`-A%Gx)?{LFeTsYEz!gtg`$ey?iPBvj zNQ6DlGISaFX^cA&$v9g5iW%b$+wb_m6)w^ne}B^GM0D1{$vX$mWe~Gk-QU?VfsmRV z*CWVOAp6#rZpaX?S^s_%N!WR+a5srh&oj6rrZLdMe;I^aBla3)Hi| zgE&pOkS1N?&PmgV6^lAG@g^F5<_5-`19{1cqML{vE4V(N7kK-*Xlh)j#S=bz=ycM_ zBYW9WnRQN`eb^q9A^4CW0PP2qsB*E-u4={L(n1-j9RdP%<=@+kHIa<9H=2fE;|&r| zfD?PhEuGY&*0IHc6|g>Jc=CuhDAJA18B(l@TPJDa`G$;O>cGK9i+n%#8ed43loS@h z%owj+SK2OR%CtFn{9FX)l5h;v-!gCG@uK+U0AykNMU}36m=(BR@ux?3dUW<~&s*}t zxX@rk9E2QemQS~sMZ`SMUTIu+C_{*Z%tFuGyp#y>#rBGz*@r8i>YwS{L~dF7;hI%t zcxVs18`p2QmQmp`Ns$B=6}NL4iVqAoj=OAg%`}wyCyVeE&cdlC(&QA+{2Z~6F>gQk zL0`+$*N{veymLsGY==xhssw;nX9W-} zJ3vU`7xekT5cW5L0AnB;HUP=}8u&A7|1=_iUTGKr(DZBIUqSTWz}Am^_18lh|Cq17 zJ1hOUGJjUWz5)KE^Wue^t%0w6>bO`SJR=IpqBIud%CFs|NF?e_l=Ti}k$XY0&w?tZ0QA-K6b??WF zj3x(5bX<=HpO4ND*W^jjk%K|JZ0c2lfVMNVks)HBgfZgwM#QC*TGgMd9c|{y>G}Qf z38J+|JfFJMvIq_X86&<%sxR^{ykZJLZ)BwL$qbTcWpi`7jtECIdIC`rjBbG0kN9*o z2Li!A`N@?K+J{u1=L{s>{_(LikFrQhUX%zuzdaD~sY(?xwf4a+rORS^SE}gEkxkm3 zBG!q7nf#O?pTg8$V+{{+F`o13=y?PbVx4XT?zp*K4-B()oFZGlD4EBQ^uj4GZPVhm z@WfEM#C#KlL+S9mfJS1zquIOg38oVhip(LAeLFoPet4aP@SWLu%S~c8CYDjM%P|y9 z{=VE+;t%c|fz!xpBA7YH*n0lUdDVI;hB?=n6Id=Bub{b|+{_biyt*l#!UbUZV^Go{ zgCdxxzAE3B?Y*PTUN)8FUVWTMU&3Dvia(8&R+6A9bj7HZ9C;673SI%sPPH!;1`^)t z5B{lHo)B_U%&zXst4`*m0x}A9r=++U*F0NgOE^wt9O?~@3HQgm9azY>{s8HSbIA+W zt-t{)lh6%i$TVcaEJ6!}dk=+Ll>!otmshOCJTFTt&&To`#re3fsr^NQH*Lq2;QQv& zvAWQMupO~KIeXsjZ{-vBV>-LhQTC62(68T?gOK%o59%{g!BDs{yzj2(7{k66fjoj@ z7?-Ni)Z%>q^?d!EXg4u#PT__-7?{JB{ev2g;wyRelz8djk&M1(9PA;G4sO$`o>d=1 zmV|bBwXmbBE5&^@e41s+)61Zc@kApNWfiE`3b$hyvsb{^3gGy-Um}TKIeiWi7w+&L z%IHl`;EzlZ{-o)MhtpQw_DS{&XjZ48(EJX*6LIsBptZl8h@A<)4e=Tirj9lEdKt%k z0D=2hL^HlmECexBhspreP;V8XF*)?Azs7wFYSlyKXYhiL4Pwin)rm8`@xbO-xQ29G zl%ofa`o`x1w=cB^T1m`7)4+7t5EoJnU(^_4E4ZTJt#=mX%O?|&VVb8qz4r|`#8Er!{hl_A9N)WfPzUy#DSO#cp<58FVwjH zk&fr32r1j!I`Ew=mBh$8;BW$WAz7x6w?jlIStiN!N`0k0k!#EhhL{PfOncVPm&-#h z@9@_+x?)&}B>2w-gp|^nOH|eIh1$q0Ee7D4HNau83MR7SMwe%%6xeQeR)4sRwSE@Z}7JMR)k#4Yr*G~YnG zh;1#-Q^sB%A{4F2*`pwicJ|Y$t$z{hLO&~?IqhGYNhe_hSmO0hW^fH5 zRnJR?n6?h|Pm=+;VXRe;Je1@;YN8ov4$s8keq38B&AH^$MiRbgnVFE_NK2TGfNk_> z&aj0B?lR3VC9(V15!weIOvrXS=@&2bim5`CZ)ZALg!sxS3C->Pf$kJdM!W-k$i&h_ zxB&4Zrq3I3`q32|<23r}V4lp4pwQ@fnq*Ieg8g!}s;mO5M2qSfyQGHsxkAtwUoJHf zWsL!QvLjX#pow5_A{}Ofv>|wK9ZZ?ea!_;JuR_+U9pfc8-$&8Gk-zUo?;D}jY{3Fm z@&>uY!RSX_A-B-3zsNZwaJkw^lfg|CtxGaNy?{6wFECjlacHsXQ4r)6Brpt6O^lq> zLE}r;M1aUxDtsMZ#sD4e~OgT*GE(YC@uVk3Zfsg86!%@pr!?8p4Zi?MV z%3(MdY~S;;Id*A>Lk{xQSAJt}0ySN0+zspkcN4Qz4R^g|g&UL;myc}ycs$wV3)oAr z2xpQAx<(544tK!h$XYyIpTiLc{S=f`CK7>Ywd2-Cmn8Cr69shA&>`#MkV=bLTU;1Q zfIzf62&ZN8Ku>l8-%ri2G204Yw;g@ae=S|V7RZWWrPbp6xZytmW^K-AZ1vH?f$Z=q z(!)pIw@hYss?;m-RJ7Uef~Suk!lBLG;AB+dHY=s&0Erioe6xsHobiQ&>U+^Q*u8e8 zaCq1vm-RmAEICawNN<8#=3)IzX!QkX1?Q%*WSAY2+Lb+WVfoL{d&^;Sl7f+>(h+Pa zZF@FHkts!ZFrA;yg-mu$KiTA0f5K}RF2cWy>h*?yux@-Yu)$Lp+SEip(@hpA2*l>H zaXTyZuqNi%FAenG#{E3t2#)K;sTE!g5?$-@7iW@6eD=6fxW1QO-g)nmCE(mYDL#W;+ zS$zsBU(f3ozWJ2StF9=V+awVpVCsS<8~_3Lwg}{F=5C!ZBpS9IjYs`)f%ZO-wQIDN zB}4#lo`aGFuMm(CTN)KRlf2KIRA!F!`F8hbJN(yknfW402u?G}%HoVsZg;!=&Bg=| z8rAaY!D$4d@JH*Jmg-p87s4P(m^(u53h_EYrjn`i!@^#YgBw!ce(a39UQniFFFQ^} z!1BUtbmxbJ?T{Yt#dL6QhDj;W%`#i4?<*0`iYSLV>a?4Dgvx{&i@Z`YUNltt$`!na z7#fSOh-wz&mnxq_NmQi1Ucqce`PjvF@S!)aQ%yf@n6tTpjTy%L@&?;Vn5lFM!P4HA zzUc94^X+1ur8=foYyp@@9;TA$YmC8{+BrODT@NFg2t&m2LsiuFz}U?lLp%fH^f`pG zP`6F?fUWeV$ddoX9Vi;joiX@KZm{*XO*;4S1z1O~taK{Z-P(a)>f7`VuuF3wuKit| zZJ?wk>5XY5%l*R{0Y%cfX=}!6h={{I?bLK$<$ayZP!~F%0Wp4|UA(WbG2mOas^ma? z;*k8tyz@S92PIBEnmZKs^>@QjkaZ}vGE=a0=ayAQ9E4i~6cBL(!W~JuEy$%a-c;;a z!tK6evsll^lYQ=@Ps9$~`RW?Lm&Jt-zFk3iHif~Wy|CoBFiXtZhfc4hX+)mz6`ueZ zneZ!W9v3eH{Flck&bN=1as;ApA+6qMyjU>vj(w^uw=ybSKi57v3VUjWTXGpsL9r)W z6O6a0FTSX$M!DYF7i|GuxTqO+cxHW>KIkSI%M1j+XpOBi4yFJ>KjIVIhxnkW@HXyj z%4TWI{W1^p*%scd{Rjo*P^8WEaoDw*iLwHz@Jf8qvQ&iEq`QpHSj^ zE8X92eEbC^Sn2+npMNKU@7TN0?yoX!zq!JH6UXq~^5##J_)Q!GfR*S0K=t!Png7d* ze)C27ZFv!3oAIv;{Ku&De>%d>`rT~y&x`$&o7e%JuYZ%9si$;HOb2$~x6nvYmbDY~6Uf}N7t#$G>LZtJEAN2C@y4j+9GfQImqJQbJlLktM2HHuMY_Sca z@qR)&{QRbM@!9(3+>@X)35-FIsCDV_GPIVn-SEw#ONqq#5=vVtWt6^Cy*#}P+>2uj zr<3C+#!=ap#kCOqXr-;reoUbJMYegtV9*(WpI2X835F#;bi$Si*AR|Je&PFSlNoFf`yNsB;a)I&^Os27tRC^Ph!(~o^t7r%&N=0>ab)=ZB|G=++KsJ&?}GMw#zgm@aIy~oHjY}X;!Eu`0lV+Z_I^eSH}8r`@u$QP2U z2D^C`GAkoY3ALF9t}_XPo3}WrH0Mz?A5{9qO_@V>1agyJIBVCJB05OBL8MOPxUJ}= zpUa3z$~u5y=JRnj_Xo6>?FFpT5v{bEq@W~IA5=~BZYf#wcH*4IVC>P;o?CV*e>!m$ zTUuOPFLF#vC=5|YoK2{pOQh^CXfXEO&$&}DdI|gC78wN$Ia*1aU=P-mN)VqiP&&3 zxfADtne59rAkLx~8|;l$1BFq-LobOwDliw|C8Jmm%G#iQYWs?KxSKI$9VX`k<-Dwp z3t}zaEeY{L3Yo@TY$jdpqvk4ZUVa_tnGH!;40cS0B)yo#=@_{ft-ZGjz)wv$E+Geb zvu2|&W-&s=S}H+X(@@B3d{Q*O+{nNX53@2e_8kV{#v}X}Qf&`z1RpL$oZ*~SWncj) zDE;+^8}s4q!0Y3-(yOJpARq|*g6;S;)kNbqz6P$O+psi@JJPeD2_H$-&<)q1--=A|~dgVzP>d`#*L?eTGK@sz1Y)8fQ86Rc7MDdVb6a5%UnvDV^w z73KgQq#r9C-b#{W4YMuo#t_7gRSr$z~G zY5ZrMJouUk;k(!tm{Pz58j?it8kI<>)RAxUVXUE#U#m+XW z#>m$WIemw)+eTG_ISOSwqM((GS>h1;hKp92Ik7n$fl{QLNs@)VaA!F-HB=cZJ^zc{ z2HV%547I~fFpm^anzxp__3ZCjJ|EcD+`isNcU4DFP>v;- z$`A1fpo!W52Jy3!jn~H70~M_H?jQitTs|zJs{}Q2D#z&n@~=uoP9s3kXZVr@6FYC@ z7!PSm+^>eN0P%F~kFXMI0dB%ZzzurZYhO!r1#MeYR5+*?7^M$0nkWN&6k(;+2t~g0 zvNxCLw2wH1P0|#;?PF77*JN4Irl6v!x=rf4x(`~ioQdG}5Vx~Epg^(bk+8Q#(k27@ z!DR#-%Zx`R0kaAI#q0B<#8xAERL2x*6spbrGh1jg7BCE{bV#h?jnKo2CPukoAdaj| zbpy0_T{-3A4$;V=mFxPJ>%ll7*4+p*tuRDp3)>MS?e0QU#?uOXEoRB+nVjA2ru2QT zj1J~>rd1#!5^E*hK_xY>TrulCskQ@K@y4<4b1-9xpF?sx>zu`(NG+FRnm;$GK(D|@ zf2=$RfO-3Nx%bG&FmM$@!tmv61DGK>eohSBeHe}Qk@DoYaY`Z##cBnXuz4N-*Iwe9 z8QUuZ;|&c5e{%}FPu3iWZM)XfhIdTZo2%umjb0atDBOii(N$O$(HA|0!V9$#E+K9W z*I=*o*6s)n)f_q6=PKkmEe`GB+LWO;Syq-<#-LE@zmg)N8+Cn=kj#K;)9)4yX8f#udq-5|z#O@;e{!4rfVJ{v-tduuy;Dl``y*mhKl zW~516v&9NJOU`@6ND>U;%wRcfue)Qfr+n%ITZSBFnrhiGu$gVk2~@x>5SftXLI?*+ zjxGllQ?(^#?NDOVaS+qA)2a>n4e16ZS4L~}M>B!h#~`Qj*+A&KeTX>XA^2De$a_Cy zrDOQk#vtwCw&_}|w)*;FUna_sEnT%J(79EKadW@zs4S>OHki^Zl*>UBe(RiM!S~Aq z%2**|l|bfPuvL;;FSMH=5Oy2hGNzJXfaoiST7Rg9;&bFR{N!SiER91V&}IxWf;g=6 zY7Ot@NY(X{EkW7apszKcST>3XU>Suw`6*vUWRU?v8;InntvF8|7fVp4jcRJD$y2F} zUTb_FFy%e#t2rlk4J;#)L~DZxJ}#;6Uy(CUFMxzrmt8o(G;$h74154WMpMLT$qN)#Zq1af#H#Oi-+#iye_gV5j=?^K~E zegfj_qBAQWUIMpdKjXrAuo;E$@_)??>lkKW6^Y2wS1SoI39sLJxR}LYbRN+syI52* zb3f-%)bN;w&`6ALUJX zWvyn*1aDY-+TtmrX&<{s3d{Az@jg3MXV&%ph7@PR^z&RLzq_KCdjnhdl~Q&)8H?un zRLksF0coIA=Gh0$17JzMXQ$iC*1LEwya0OZ7zvb5NKGvj5p`dH8SeDV4w6|-<`zy6 z5y`~w4Lq-J`Re-Nzi!;gM?0mYu${kpW@Y!h8fqlX<$3J%j%=A|7#i*-5?rrO_kHNt zdh^BrH*%|YA6P3Ry$a9T^IDMCcmlm?z{ZmKc&lm$w#n$H?)%@V5R$m4OzdR=mPxy9Ugyl_x$63|3r{K zrues|>6idLf~VfKFg$dVtd(0CvAizR`bk0hM>qwFmfl{w*anBLho-<)poV zmc5P<;IN&+PY2rmxSIdvOzGJG-K+p_3??>K8dgBz>)RPNMgY4pv9kdV3jR}<%>S97 z-7hozYv1TUT}uE*10?eRMx*pJfLZs$QOQ;I)6K>xjK=Z}xf zpL^rqK>UAbF8zniH>}@nb^jdhPi|)dv>5$OZckBBvsWaB^@WaFC1Fem zH>C{bXz5ZMo}94fLIu~5`lbob@pQA)1=180m8_qbSV!gPvt)(Qh;*WIihmNIID)|g z`*JLl)kx6_Iun1SF7;){Wf}eR!R6tDAGIqXEO#!e#-%@`UHZ%g_ptwv+r%xt#|+j3 z`{R*0SMjVdVaM6Wz7->{2a~I9g2P(IPbnud^Pwic|F zh@6er#goU0V!0aB%7MdHX*{i4<-G1Ew`S{^J2S*94xWvn*-9f?nd?9>Y!5DeQH0`G8}O3u$a;UiTPumq#@9Y^vf&G^b6*RdShbsC3|)v-ZK7K=h@9 z7jJJ2@x-7i)3*!Z(=6~b=jM8o#et@9 zpV`}Mh^tJdq$dt2%UpLc?|t{wU++c$!BZwopb|x^j?m>K`OB);^*i<@&vObGqe8uG zjF|3eztXkZyYN``2|g-*(G%*qW?@X*z7?7e*IMf`kL&jqv?YgZQ1W|Ufd zf?B=!LLYc*PdjQ}(O0Df*6iAQtS0ZEj36&>Q!(elw~ivBO1)Veb5_`;KHNz(M!uEo zLPPyHM%RZ%ZFdRtE{F0}t46&74{VhzhZPJm>7}+=XexSXrvF_M*)!}E^@Z>1D(Iyk z4*V7cf0l~ln~o*6*a_6|4NMVh=Tu-PG%+MP%~3Dq+;U>cH}$fd6Zj*0Ku*j z=MrNjhSwRk4Dn&4Z`FSB=s*2D(v5zp(JzO?s_~h+!d=f&nu&M5Ne698-7|BWMOD%7 zvWwtupdB?Bc6*^Jv*##%ci*5w*Z z;61nf4kytr@kGz9l)`6OxGSaff~e0b75Hl|+NDBRB%*e;rUZ9mOBBP6Dxog2{nWYJ zpiKE)D`Pk40FB3nMb0^@`|DS723U-aZ$Wn;J0hupWIp!b!it35X0G*)enz@CX5%2q z_q}SV6Ijb5KaQ5Dv2sB54)Q`!9OpAC$Jk-D1+86xvpPg?7Y;mS3x?r#kV>QAE(jbq zeidqgdN3AL0>T~lX}ci<7y5Yn>0wI7u{?@YaneaHmKY0S+z3d3RTGnYmga(gr;ML@ zsElv28Xq-&M5x=HB~}kQC!5%tvAf+?GlCm5X+QA6D{VP~Cg*;>CLQ;NtI^1gYRzv( ztHQjl9-&na9==q^FQJ}sU(yHC)mI6`#wxS0kj535ao<2fHomBo4jM=wY$+N4dOKeH z#^%A=Kez9O6H7HY+xXsKf^v>NcQt*)JTT2M1Y(RYx9lh}(k5h%JeQ4pimgjDf1W&1 zPNcy6)S-OiD?&FNjP~r@HiyCcH!|`-o6X)Rn>u0qq~6OUrQ-)q6qP+DDvt170>Ecn zY+(}0@a2ULn`y#1Yg4k4usl3G2y@g^i%Zf^tcl@>#MZvhBcCsjFx%f~tgu51BZQA? zr(b3-hf9#=T2!QuBX+=`w5-^AEx_XTIbka3j2EK1Cy#5fsU6OsD4! zmj=0wnS|-h&B7*N&C<0Gyla2wQ-T!FywR&0w?7HxmP9tpXj*cGqybgOuLbo5lG4n4 zh%vwC9h?Y9uqa13SLpy+byXR^<+M%gN2YXp!nqeAL!&kKGZFU`$e1hwwfRwL5DjY% zat0?H4@+N$p`Zob~2Blf z7$Wtl@A9J@#;SP2lM|5X1hQ9>IN9aeI%P$Z2Hdu7G+__vf`dvc8oPC?^`oNxam2Yn zV|eD5n2AdB6jb4=e!uY=xJPB28piB>8j5sz+_M&e+P=ojV<4yMmo0Kp3YM}cPGSrj zXo-SdGf88mN*lS2_h(CwM_pgnbZjqd=r+T&EbX05jm~B=L+=-I&rX~&lLGsW;I(hR z!lZ+;k81KPEvs{9R1KU#N@!{#3;0JTof+KEWF7Rpt_B6IyMZ)?=^g1>bAp5&9p1wz zOMBLlnj+BzisPRxLg5;%4(%^-@`k*Xdka5$K(-{*z%@F8I$2NbEDw1MNop^8_JP)T zDk%zLXA2uP*a3Q`bpKi4q~z|3zn@5x+~IswHMplmd4*Z3c`Cg)DqlzFVro6Z zHKd@I7o(&;k{6#R%RY7?SgEb95YXBlG=@|5E8YEIIQ~a6{gXG~ABp0RbO&gz`zOaE z|EG5N7rFy@4}H^S{;OCD>-WF?nUMa|yq=DZ2H?p~z|71HpgDkO3c$CV0Z`KWR-t2M z_*?$$fP~%!fE>S1>H)~`F9-%y^jN>I+ka2$835wp|1pq>{TsynS_%9sbpK{NCRSz| zHh>t+&lN;g03iJ5@c;)6835XWzXtx5`+hSb!#5AC-_$Hw8Gb5S{=75{i~uMEfb}mU zGW=AP{Uwl&jfM?SUHmohzpN=e8(>X;b6$}3`?mdahy5GE`VSqY{}-VZR))W}!TyO` zEDTJ47q^cOsxCe9$&%4anWal|hYK)u}2IV(pIRj3~3T%EQDS<3G2J{&BOn9~+N;wu`B zXw^Sa8QKsS7B(i}w`t-Ic6c+cY*i}U4J=-ux0ZNvH7ZvdGa+k%1#Q+=YI!;sk|W)p z4eAhu8{W`4Vn%Gt9S?>AW#S*Wcskl$N1#XSgkYrxy>_{($7CGH3|FB6L9bt?vIn;V z(W1X6j1#5C5T9|{{v;uX&8)`W1Zv%xT*h69*>+``30y+0$aFgHi)S|>5;S;7Szp>; zU35@13x{Rx5#bWPu%k@?0%{jkcHoDpJC>!gil$@gbP*y;~W4W8wvkGBI;Z?zT;qy{a*rPNvm){WdD ztskis_eXh_E>Bp=qF0n2F8NKLqyx$GE}=6Q6Hoby*uiUB4S+js-vo@^x4j#;^_cC; z*po;vm6QQlqyv)%w-ksV>L$?*28)-c7;7L>O2R6#I6qgM!=s^C_AWP~i@1F_=(zG} zrm7#xR*CKcrk;>U3T&3xN=YCU5;K;E=1s%xq1KnA6capkqYRF(51xFD*AHsp4Tazm zq6E4{#U5ylmS+}^0<`^Jm6(o~q8=NPm{z%Q#qhuaR>`c_p&nF8+$@pgljiV%1HU=Y zd%qBPu+bFL{AG|+j7kL4UKrTqsx^msB)&HHAdK+!R?I?JcS44RCGJzH7Eo+{EGnVi z1Pm8dR8;9F;WnV|KAOuZWy%_dJX|_gY2Mh+Y$6=1<67)oFXQ+=a@kChcPp!C2~Djv4>b{duU5*f!>IC z7koXqRe5w;?jsrv#1Nm+Bl26c{c5!4ar7{?v>X%m=0$UqOxtr9I^V2uaSDHjJDRAJ zqMJU|&g$*V2Xw)#&C&-P(&A43&0by#1tZ|BMy~vW)Y52A33T&d$!zX7A-s-bV^u~+ z_>yiA!U~Ea6U*dc7V|h!Nn&m+^{lA-)gjTIFpDHw*0u2W&#tra#0eI>WkPe}I9pQK z@}gI}C1NaOkFDX<#rOn@Vp!#zfyv;6AXp&*j>O6VAT-eq0?}^z6aagrq8uT#`88Hi z`T5U>kdzvS{=sJ$Ky{F6qekzEl;{~jA_IN-$R31Aj6cVrv+cQJzNe0ffTCL+-3zLm z^_ibJuw$Wv0A<|nAtKgoC!#$(n*gUr6%)`k{b0ENz6tpTM!Xjlk-se8)6;m1#u+Eq z`mJrx*xTb0lyYxS`O`^j!iMD7MjuVp)mQb1vON696>oC|Ph1I6cup8usfL*cU4iJqdXzlOxBg{#R1=LP|K!(U z1-cH*OA)Fe=Cq{^fI`VNIq2Z@%ES=u350*yG#k1-A6~~vGqV)f3W74ZMw@temk#Z< zDN@r}^kIoNZlf{;g8J^`2)>qx6l5AdBm>s9ky0HU*7R6-1LsF8&Zyz#kR*Jg z`c2Hg1S1tccYameFtgyN<{7mzLxD-+Nr?-{Nu2z`*_$a&jHJyy6B9!af;e-crMbAM zuG!2o{`s~4`^r~?J)zJ#)`!RO*!BgRF9^AcGB-%#s=cZ<8R*`2zEQPJ$(Y0*__+A4 z&mfvp#kROsw45Hf#sLH^u-Q3vk+}l<-AxTm9Y!S?T-9N!eiz4^EbNk*aZt;;g%&-C z@V8f|r}?Gx;3y8bSvt-~olC-{9z_HL4fGhr1|C#xwK|Uwc||3(Z$8*reF3BR5(t@y z@njW-9%g1jnAAIll$#z-2QYoGYd%fBy?1)G-GNDi_rx=3qMn-&s*WD=xo2@}YCyIa zD&)+2^rStm-64v04Js&1Hlh>}HV;FKiVd=>WskLBKd1k?d4_t{hvnp*+(x&cV-aOR zj+XeYz4tq-Qi8Uag-x?KCDHQ7Rd?+r5X86vhM2q7Z^yQA?XA~;1 zSGl}5x%8<>*71|fv2yrI#JtF)HBSZwM|-z}Xpc3yFeT+CEMNS#$&bk0jz)}W4$!!i(=6~SC@i1tr45nKOUlcHIGPbZiY{7 z#Eyzu5`>3gNVTe`)9w8rqGNbdCP|5+-y;8%8P{_E20Ve!pf}xdbKTj%_z1rk4j%3W zbhzUCTrvk+{EtZma2B?&DLZR~O{2mdTS|&cnc}Pamn;;CQ(o<}U^rOcOqLazMJulq zEjK?J+97Djenn2mKNT22v%zXcRHAeVv;m7dF0d7OHTAwzLr6ou8$L^d^NyMkW|)RF zbkyG9Ma}YYcQOnaySselO9w#cVU1%ntmqE5`;4>FY zrq#*1Uq!p8!V?*$qG_oPg^juqnn~j|)(r?6Ywz}z;&u0RI9$Gt1@0?xHEBi8qirC_ zJ!`~LTR5e-Y9>c<@`jg6OMSklee8eb7ZlKRQ_SeyySWC=iE#S1y# z@KJ>iW5liM?v27Uli`M<7Z~@*DUL1#GucpUl%!eh#|lmP>@RwdAu9MKpPz4ZiX8|! z6yuOMMy*xjr4eoxjFey@Do*{UF?(Nq$(`86CqLD~?T&h8)$OF+{uTTHndiSi;rHP8 zJ!Sn7`~Y$j|2Obs_yha^HdWtV2w+$Bhg16xAo%@%{!G*VAqdg~ieYrDO#j~(iva+H zjDS+qKk&u+PcB%0%=>>iH%1m_8i1e;07}_u08?ZHpda8k9y5SeSlIuuSSCQ*^JllF zKNj{Lg^^iz#}*-ux96f2P`>Mq~lB3^V^mcjsGu^*@ft2#|>R9S#3ref^tD z1Sqxuv}}IUYyAC__2+x{Z`kyQ>L1_<1pW7Q0j!_!kJS2q(V1cW!PNRsP-O$C=={yP zU^cdi-9q0_O%so+dUqcU#BYcJL0Fv;K%m9B^V7&9K&6$;>z84>xdCG$^M4}-v z7rq2<^lg8MSQW%Bbn&!xJ8$9cacYKcK}H@(mM7er%X@HJ!Q)F9lGn0&VE}}BFD5*bzJf0MaiZayV$@` zjjqE`tgUCYv)wC^*14J_#w%SpdI$dWv-|*#xx6ukLS>j0%Dc6r6 zTM#fA_jdLyT7}~Qh21P58?uyx67ywBQ&X&bkxV3-5gK{wRTdffurpZ1FsW6y!W?@7`WP zvt@X*`Ajb^*`P`;y-dsViJ3`XBqs@%ys8IVLj=c2bQcmU`KwvrUPeE8uyM`QKpYj2l-5o zI!8aAYy_O%B*TC1m8_pT2-%h2>+`)QCwJkV55x$26Sqw`X97%+#l#FLw?29r7;h6Z z>%l(>7-l}Dc289BQZ`u;gcum;K&Y`R(!XU4LU!n#8`X{ANWwRb%%6q9O7CZLTb3^3 zhyZuwHDB;j9cJ|Iu}y{Gdx5@Fs;Rj$Xl1bNMu^`rrkMx!wKyv`dz>MfRLohDTU!k{ z%elv_THP+FcHsOBNqp6}+L*6@7eOWLOfz+$lHX`7YdWO=!ggQoARU4vEaa2#Erjd? zQ#p2tjBwG>KSRYF1Ib%|+O!*4$NI^(#}0$(p{tfn zkFX@8h~Gt@KY)KOeg|#kYB_gm@#;kZ+)IOey*maqK0XcyqENIZhhvF_fh#_%PpD1R z-W3A^x@B`%lU0Ua%25XqE&7W@(_T;$VNm*U2EE{9@AL(RYNf4DhDG!;A;(fj@#_SpT{ODN`Sdy{~v8{85U={Wewx* zPH+eo+%32Tx8UyX?(PnOkl^l4aCi6M4#C}>uaZ7Jr<3lP(>?QkKe(#u;ofyyJ+ju` zdu>OS5R*0QvejozvZZ3gi;r~D@C>PgSBMwMnE9zGU-vgYI$vPsr*NM$fjt>zdyiXY zLmt489u4-{8Ft>;(y79`HexmK{<1d z>~Gh7Y2=pi7;8%iGTc3VYpxLH4vA%$Y^iE%W5ZFZA`i>IsYH|B`Hg!OM6KjW1RDbt zx_Sf^0pPNz-YVNx%yNW)tr}hxe5~x3&!g{`1ocnPZ>7+6$fd*xL|tp5rrf_y%N=s> zB=kWuMWT0kLD9qRWug19d7!5l=4#N=HvC2?tB$Ti`^tskiULZ=o-EXFv+TuoASR=n zuTn$&BBv}c-JSKzXgG?EvR!d}M)~Vq^J{pN*gI||knBJQ&)qG)(UF#vk~h6u1?#G5 zXQ?R^#6E6gHxZLaH!G_KEXrK%j3%^}`E|G_#FvN7MJTq$#26YM1VZ|BfO~;IkmA7K z^OvlQ5!Ai9j+cDq4x~>*SPK5)dhk^=L03sp^%Q%`5JK%r@cINSq%^VAa(1Da#&_xne2n|zK89rRJX-OFY86zKN>DB1d=f<>|{sn;q{BT{Ta=9;SE_7>K=NM7|^la7woAQJe(WyHpNm z#$KhSgfgvBW@RtMV$;s-kxZg=vOHQ4p3CYiJG7GcRNr%0-Of0RN5GVQ#rESiAXaiY zdZH~+v`~0+te6$ee5?{*IH_+SmSVw0xHY5tbru`%D{Q8Rhb71RGLB49T((z^(E8rP zq|6~U(9YAOQMzWDS>)i?@!f9vrLdm*j%tp)s$VeNs}Wj`Z9w?;x}4-_Z?rV zwozlp!nI1uUGqRa)Sn7JpN32fwBFJv35@%w3m2BXIt@dlBibj^d~xNxSROYq*J<;) z*7n_fh{*GaD%-BoU^ubLI5wAGdA~0W36Gh6zW+|+m?B43nR)^rwBT)-^1g_WHqv?| zCX85z)v5f!c;i0J2ZWg@B( z32a(tM{wK=qRxo!(4SHGkFwLhKlT4L3jgsu{xb>(lurI%pl}`@Lcjn3ox!jHqDFs4 zH@}s?{*S4fY|Otp`+hNGVFoB?0+dw#1jGQ4=YQ;xnFHXcW&SI}UxC;!Jp$xq0TG>l z0sVfe1N|L|{c6YnfZu?64}Tu&ADNNAFl1zAqhUl=lcFMADuY=7$U z$A129_}^f^pAp_4m2Q4c-~1yg{HGc?YyctIfA7-o*pGwlZ)3kyHOu%#R)pu)woXgl zZY%v#p%ztBTDE0_lPc5XZIqqQ$$3+mqzg*Q*5m_cZgx*6kVqNS>ep5$M!Zn3`F&pd zKoYi$_6PAAqs?cJBbN4GiQ0PUMk|d!+`tBl=F`7DiqsyVqkSQJlrs?a<@!t~>II}P zM-KzqcOJ;}nY=BcMd$qB@oUdjGisN(2OA&JODmutvHJ&~DrL;tZz9zb7$%E$StcK} zU6^8aMVCftS2Q29<2Rw51DLYn&B4VI@f!GCW~ko|Y_O-H&l4Sr)hFT|-fX!%aB~n> z82Msh<1bB#E<#5;f2)sTxmc2unUN*BfI}a3gVB_wXa)^r8yaxfp5JsT4N>{ZIA$mn z87Ioy-WSy)>2rHp}T-P{`b+#X*gsXC4(z5j^aJ z$s%#`21EPy8g++s&79JDBM7Epo#fXlld4dr#8R^YSWFx!q`Aat-yzFc)5;B_&-tGW z#EK}`idjbJAIIp@y)WQnhvM$y&aLX?h5Ohwmh#@cU#_Wo=R@hBi`fdVhGRBRR3w3& zoi~n?yrQ%sjq6_WEl30>;^ktW;p(yGR zol>mk24fURdnolPW=62a>X*=bI<6W4I=v_`xY?OK(nS!!BR`d)p6}hPWt!&~B~@@% z_LT~@3mW9RCwPLu=ymo516~(|z;Qp%zE`-kqFzXxi3cOcqQUr6st)vT5i`45VBk67 z(9-yVTLpw5GdHD>Co(}<$HUKXKDs6pDj9N_k?TYYzHMKrk`3~VClz8uAf((=7-*EE z)(-a12$`YonKy;CVGMgcLJUO|#1F%tWT7Vn!*FqBaO>bhXtYv4k6zlG?OUr9#^EY5 zxEkODI<40yuzy<>iX0LK!n*dLPnC@f2BO9ZGx*t#y)vO#Z6IK$M^V^(zHCY|bq@U8 zj2)F{t;9f}E6+^2k<_46OnQ@I6{}bHVD&T4HpJS@ z3-BE_*5%royy=@L*d*@c(e@tZ5V?q>pAI~To1tb@4|aj@h1JP4d)3J+j0CgY7IPZH478=<=IY9g+(FG0-TMf>W)YHVN zB|DLILlQ^MT;2vsR`B(7jtXPVSm=Q5b&xF)PyiGM3pb8hS$f0mJ6TIL*$^JG7a;ww zXd7$BwdjEzx;@#Ni&ygllO?GeL=9FzvJghfKqf%O@b@52y%ok|xbI8r{Hv!D+ZxFP zL{w#?2aBCVbLN>QT3e(RuWVL3oq=KfUJO?$kTij>{0xQZSDgBQuCM%c9yR4Ul}5-6 zxG?PKgR{V{PqloR9u(_ERQH`tVvUKZ)Cup=UVFyL=WO28`M1!)^afI>v-ege4ov ze%f2JEK25G2jIftzR{8cT+j*kiD>&;qye_81?pf_HeEy=^_;6h71%L(8N{?YErSi!E2| z<{YO=?cbR0$K6*pDu}g|pX_`IeSdnDwP-Uso7H6#&~D#o0$$Kc!YFoEV!fL^1fq$^ zF94|7#-K#NPG(5DiMB4CyiKe0Mh?2l7qc=%)w@-jpswm3pfj?3QiY!$gbBx z5FytD0-Dfa`S{m3s&|C!K1?i-1L4z@dd=vQrov5?A9-> zo+P7E|B*kke=FP4Cc3-PMJuuZi_;p~upiYuj34t<2>#sl z?H)OLo#9i7`aN8Lh{m@AQW9k%q8(t6vz$DsR&EC0F$j*b-HW?u$lF$?uGnv9)hou! z=&D|8a%^{YUsMfDAGcg$w#UiRw75wM@2p{WiM}e3SK%@ogl7rEr^w$btpz!#uBXth zJ-^RtsDBgb7>2?5=>P=2mm^t0A2K8dmZjO{Odt5ngwk|UN|`y1B7oQ@W@(}7pJe9$aySufB`>`cD~xQv=T6-?oqd;ryhPNdt*N>t&EN3eHfrtqk8pk zBL{3JJ4@uM4r;iCyF}$$6mPcV7rvyPajDRTlc4!gn!9Q2N|~7O`GexAnAb)n%v+(X zEjuRxU&cdoTPYb%<%C-VH}19QWvV?1h2uUz%2-S^K@<5{C7(`|Feh4^dx&z2LImPl z%IfGnL2d_F(UY@F+2;gC!Erih1}clScYSp5%n*i`G84b!X_po2bA}o~8Yu>ki<%F= z?(N$j{osRFKu|KD6GXl;(Keq`&FMOSStwphFyqQS5_2FA3?B$B?y7vauPvv_83Cg1)CdV} zOET*SV;SYpdF>Eg>fL2v=Q=sGCPrf3X9F3IZc=J(NavnbUN%vfoQY@#@ICpLDuG<} z2|J6_0t#tGwJ17jHcoBRtKKn1wIE?-wT^l510JbVW&C0;MboP*ZZ>i^eXC_Khh+b( zVnI{Sz)s|5Lj2Vn!hx;J-9hIENb`c(#%()d+6}&AEr`o3xU50(WMpf%&bPxg%=&HY z!PcPf*6e8_52#kx*bvrXB>0?i*-%4zYp`gQgk~&^TvY13#GP*8`HQDd#)OnjdthhU zJXwOu_8{prq!-ixLZ&KF_P3V-?DH+S3zvd;UWmTPoHKbC-9bTGi#+dcS%gJoAn=GL zD7{HNuSGt(ry-~u9WPkm=r0;rv|I!%SWqSF!E_qN>+7Tgxwo2QQfiZ-bEoGzsuGUs z+@=ceVy{KskORAoxg(^1^7mG$!X~T~-~)kuBz?xpP>1t=BSI~(Kg4G3-O0AKs@3*# zwts)5jXU%lCj!M6bC2lBiP_V8IUO(HaExH+&&GMVc>eOT$oVuwUoAks4=M=Mw{D8N zujC_o*2+*$#XG1+f=zh^KeM(I&O^waXngkw;opYx#Ym^4;a)f_&5xJFNo@Yu?pY%D zvr3z5R7!s>$XGDVsW(nHZrrg~p@QzZH;g1#T6FCus=BwR4My6KFYFF-mcCmbs|?QeTODwiKLr2&kh%FK`1dF2 zoB!zZr6*({{GOUAZ>aA;sLsFy2!;jVDnMBWK-mUBQXil~1tUN_m6hXr$m$$e7bgHR;T&zX*TGh_v2~<~S zrdu1aoSf>FY8HE1bFshIc>qQs3T2^#;dd?dUd0~vVUw$Jck`h3YuACm@~{V;)pk7{ z(>7dr6N+5BT zQ|0J8chT231O(m<4?Fr}L4iWL5t7gK?k^MS-v|#sa*e@PJ6wTTj$Kt-C@zPhv5R20 zeFP{Mtz3HuA(h#P)Yi}RBhq0Wq^IXzxy7EzX9OpLL>jLyx)vp9POXT>ZqlaMq}-LIYXwi3JZ>0Nb)$=o zSGPyr4g?~t`a}D)s>e}}1lBW{(IEAnYq8z5?!2AQx**;W@zy!5QpRHmlUB%1ylGV^ zY+D!4=jv1lU6RCFDJRqTEJ2HY;5N&Op4wIUVduFY%Xd@3weu^hW!VvDUB39&RNPUe znFdWK&&@5jT#?q~pbnKnwhvrLINt zwVCS*z({D!xd(cG5@@u&Dz{iU_PI+$&i23;UnD_(N@AWl{oTo_{B&Y*1PI) z_MxL|4%Wa62U(ixghW&cD<>!L_N1O&>Dsr$!LX%>{Dh;%kA``TpGucy*AVR~VNXFN ztTK}PGvZvW=bGV62p03Kq^~e!OSbY1!VtB#uJ}Mv=pQK?I=c*znDUivqRew=Y>3AS zMcM36#r>S-RWvrG(Vl&Tya)1y3T?7+cnq1nM)FlqHWem|PuoZfgP$~(;$*Og9&Y%n zKBwiRVcWQ$H;O>oJX zSv;-om>Sfrwg{|Aww{KV34r2)!Daf^5GKbbgu!>s_5wj*Yh^ue-|AG9*~=!JGVYwo zp5Cs#tP4+O(_ROcWqqK{&0U{LgKMlGCdd33L>6-yVU|6NTs~0cgPNo?5WW_Q6PpmR}fvvEDow%wv%jX7`OeP9sD_D!U$6+V7rE$xNXMgS0#6`6 zYtU?vNNezpmVp{zwM8N2-MtaA>VHMgh*=L77u)VEEae{Yt{ORqxhdVo zU>(MP;bJCJF!uNUSh{V8PuCD-r|>~onIf_m0^-4iKqQJIAW4w-!`FnI2w!)^B|`4x zJeob#^h)^mmB!9kh{`aH#LbtQD_b%8(sY>*8H1aht%palH0si}7GmsT?<@=p6D;b2 zh0Ve9ki5#&59qy?)jn+(&$tQB=#<*~O3ZMgu-{%{nWN{5d4p}J%&Aw(T+U?AHKTJW z)wUEOdl0fOG5oVpoO3}SJ(W` zi|mr=x^|8ju_@}Y+jX}9Hm*zIlft6K#P}C^f&$l!3+3CP;{bg*tX_ooj*vaW;owm* zy=?W~7C1h7puUkZ)u<#<4*YaAQv>x{E2}oSV!+nLQ7Mzj4~G&aetFAK`_ty*xRKg{ zdAWD5n5_r)GhK;nfIsW|p7e9WI#elwkD^Tw=`jOtJXnEI$Re3d1&*;7LVk!b@8VZZ zMp6s&7&dKn3Ni)ph8SE0_upQo=rx*#r_4rMKMUg-%2o3z>@%U^xpQx(9T_I}^f62PAJa-!TO56U>MSi4LOmQHTc>53R%9fKL`4Rwie zn^qepe^`Gjr3#KaDO1p%hi9&!grudVwVbolz>nd%*!L0ntfvo?o-6j2n|JA82Le_2 zQLQQ)GP6oB=jj{DZOL{O(!4Pn@+N{gYx`y|B`rmXkhrw>!_gP{rLQ%?XJ>icLTxcySDx5u2mAIkyQ4PBFBpImi)5`=hg8 zP7v{TyIf&lhk6N8fzU(gSL^T5*BZTNuLYNJRMTH;#~;&k*NmE+lP)+1;&2m`adB}~ z=%RWn>L9B-Sn{8w@A)NbX;I~7?hD%7e%k3J_MaVxSCDl z#@-cBVfW`jxpdMib9t1AmKb@#EFKGD{xh6q`Ok3n$20%WaP~*__5TZ;{ZaZI5X#K@ z-Ea5{to^Ah{6B@Y-<5~}DXc6^v@8G*Ars^Gf{g%C9aaF!W&d|X?%xEpwg!3*4!U}d z7P@w{_STMe`i4fMRockI&t7Z(2^qyzA(GBbR~76_>v{)^!j1@>YhWD((h5Q9miF@o*G_Mm!&hogPBuvGqPK ze#{?RZFqiDyUACkbxp~F!MZGnvUS=qs!I^a~(R|vo8&9>@LYp?Ls?vg8y@!7>WQGXOSnrvs6`L%{?Z{b> zBPmTLlW5uySXP*|#zGWs=@$-+L>g-`@3f7-AzW$X)?b zc8Wj*ZzpUS`jOjc&L$? zx*^Tt;a(q)9ArSxFUzFeg<>3BHAfOz=L>xn=O^Nh0!6}`-7E|5syDeF8u=kQ8rTGU zmSSbM6cp3d%Y%xdnx=xF8b%*#XZw5MYt zm~hGUPrbN4yF~J3Og6v)d!TpI$wOPOaYi|^c*5tJg>lYjW*nLn4G&t*(0hE+fa)t8 zEw%~+{RU)hO`^xq&~C5LB}}PEVqm^nXVL7`=f<(ErXOCLH-qe?kIscJnwhkJFjjWp z*?+AXuPB~nW8vN*XNKvzxJL?I$BbS{p8%6FvaK51E?`u9yElR3&5kem)6CNY!iFow~uTJr8KB4LD=YYmzw0aC`i zxSw|U!ebLy-r${1+3Ou}>i{93!A)r-*^Rs&RA6GsFjKEkS2zKg;Yx}E1?Vbzu3kw6 z1+>q#9{Fn5C$NLPE$i(!A9Z!cRjO&3(vAa7WDOg4vW}bGnzfbF z9QnrAYV7nY*w?Z`Xe!|Qv&bd_f{L1!bJB&awGc~F2V~}x#HQ+IUH~m2X_z4R%@3-R zXO_qi7P-aXY(PAs?!IJH?M4j1c5w<8X`m4?FQ|-$)(I_%UOHT9Nl=PvA4%CG*r-|E zF{n7nSlgzRng(RMopH7CP%THvA=10*qrRaDAk(B(+gQe|IRS~iVh#)T`k-gH7Wn0L zo7e6laLQxij~S)IzH+LF~n1O$}3^3IOf8o;!=~`gf$Nj z!~@GNrb~Z0$D|juf`0}2fV}Y`mt#dS_N5FS5sth$h#e6Wi`48RhqagmAqx=nW;7(6UfoT5*e1(360cJMpfmgSL(=*WLFwaY@e?^nTER_ zS_RFUPdGYqA6TJ^*i)GclTJl(>~e!GY8BZ_CzB>#h(MEb%)%Lp_Sj?YD-Z}f-Rh!J z3^jd+sr;Ca$WD6i7Mt~xf}5KJ&9|0Q)=*C1{9e>xfobbZ#gg=Op}DF+EgH8hbWKDn z1B)5qs+h(p<&bI7r0bEMScJ*&C4s*WSXnAxPPA)?TnX#bMgh7k42rm#BTNfwI5^C!;yPWC1p= ze~p3vnlg!Z2?bXFIZwqTNmS1^dWH}~84R<#^Yv}lEN?plsJ3beozHrjz9-8m4OBbm z^MZcG3`H%t?=~GZ5luj^4_MroRfu9{wBCnBEC~PA_r4fIBJCJBt;Y3D@slFBC0HyI zSvDY+7GJ%zjFu}`eBW!R54{@Mz?#Icp`42vDjgdBjC^R=2bKdd zC>6>Nkd~-e_%=I(z8wxQ>xKe_AIy)c!4wLv=_nYJ z-uV`Lu%eKE^q`~`l$>R(1Rcu&eV|f2x%#?;7i^hNEODvhtCTgxkL{`5r=K0pUFLaE zh2UY%Zd}=P`r;YD2iK}17}IuUo*aRAYS)ug=T~0!PKceYn?}7+qU?8>aNA-#+HwNTT7QW zZ5$-!KTP>~*w(-Q8c$b#iBz*H@Ik2IjO4%)LQYF$$>f11zz+}hZG}xM6?PNM1;JJ* zL|b1xws?Yz0U-+T(q!WC;*u{pHUPMyo5sPSZv#(5xoh%T4vvW@_s zoiPbQQw2dlKA16y8GKDQ-B6J|2x%|p=eWB}mi(EDs!PMtpr}+OJd6y7K@zp-4RBIX z7y}rEW-{wtD3g7*QEBH_vPHRZ8xklOz1Djq#(v3M4*G5m_jfB;5HXY11x5pz1R%3m zAh7XH{ru`k#fF*sE1tUynS49hM7{XjLZg_kNL>NNxyzs^KQG;Ym%rzN!-L7z@mami zNSG<|Ah1gTAu&wH$7IZjdrXHbrB%*|BOoy-Q1RNmdYho6`&p0+OOG4c_nrK_fzOI^ z#Bu*z{rH4a@`pg~X}LmNNi<(p&U5|`Z-hQ72igKHGGg=}@cTEG==49zc9=TBGOS)_ z`LjmtUowfw%OXL%#Dz@Is2sc(qH_H z$^yEmu%k znNHZzlsFJ13#q_1{B#4pUe9o+G+&7I%i%F4;pS?b|hD` zgxI;Hj2Gj~lo(V$3o{WD>k4AEn253qEL>hbLEkovA+GwmJyzMk(PQhdV#ThgEbB-G> zcvT5K$hF{&vq@wTBYAz!8wmb$F68=yoDrr7{|ct}Wt9piT;H6CJKCB%7@#gFlDhDN z!KR7EKqKRHzYgUK?ANCk3~06FYL&IQ-^XqG1i1zFi4?zCX`);S*m;Nh6?@u|3~QHq zrfTrja2AHk-uVehMMsasp-CTjwh=<8^pw3Kb%4SNG}>y^G+8G6gqXs~{Rg?M#o#lMlqtzj;t^`yaPy92pD3bKoa)B%uCwxXnlMPzuAxyJP*nR+H*WdbsKz2|5GaN zn$w`EMmntB_g#3-9O`1=s%hr}kcXMi3^E1YdBQXztTtmy5U=k^YPSLm-}M3kZ+9-r zT0A^&AWq`O=pf&|tXf0v)q%z0h0Q&Z>g)9BF!HhW;t^VVTU?=@*NJ^S$gkvPRC1pa zvsInbac5WKVN)3>xGWFA;_MS0#T}kmyA!3lbc7f{`i4X7bl47BZFx~nslXa)x3mu- zz^+`z3JQk>?@f_`pwkX3!#fVj+ZlPlzLIiwn>}DY`hrQ)rQrW(LI+UG=ifl~HzML! zak3xa@Ml7Y^&i#U{)_kow(rh#0HMS7BiSAB`Wvys28e_H?f8%Id%*F(5Hb5<`#V_u zkKD=6aSV*#rKkb5ioT1NF#t#cMt}>Q1%RrV073QtJc>cj(b&z@!a|qU*vi_{kQPAp z{6h2mnBM<#s6TSo0c-#JPyt~V0Ie>j|7Sy`GqiFrw9^L6fmYwxlo!AP893@YaQ`a? z;b_QBW^V#8*ETS; z*Z<>t?eBy8Lsu5oR>uEo^j~j(ZS#Fezss&`TUZ0W>yMv)ZTZ{6Ydf2mIvDC%>)IIr zy8f{je>n83jk%$#v$dUpJvZ6!?|y5cYxUc4GHV-cdslnFARPc}3~2WA=U>0h2@p2~ zh(G#w^Is19+Fsw%;Kz~}SerVKS?O9D8UT)P|2Vs8EKK$6scdxZ9jF-TsSI>o?a8bR zooyWr?OeY%1dPPaz|f9c-q6wBkjfr#gvuVUIAclyE5uklQ573zSm&8636QG)6@UIxJLi8nf%$|@waEf1PGD? zs9z8Q0_6a@9{{2rkbuPia5pf~1KbUNBru^zt_#x1Fp00zd`}yXJsrs(tuQp(7@D`=w zgk8}~bbIMzy=<@6_m}Bq*6v_&V~5LF9G<3n8V_tM%W&pGQR(!?>QX6kdYrggH14bn z_HuF5v=tlZLXgzjxH9dBn%x%n!jf+qxniwd`RWuphs>T!&4?VNyu8bCNXXwPE?gC@ zT^sFjD0#oIjqfiEDeiX993`qEI*vs)`xzQAW*3;~>XwmqS6MNqai{bRI<8}l;G>tU z*y|UUF|*E8aP;}x20G}X7Ja3@pji#K=^B=1k<19x2Nj*F4OQ#e=*S zzm*-U&u>x92z;a=@w&B8VR-|I9h6S2B$|sx!uqn+igRt)0!cA23OxBj-~iTni?0Dx z^!91eu_SAaM->@|kueZe+*X%gfLx-aOkwYs&q9T_CQ^l#>6>9;wT5G(OFKGG%UL|K zE1^ykpN&fcP<~Kg-s$BU3_RnNmU6x7%$F(1hp5P# z;AshQ>!9iFB}iQF6eEp_$|f7Fr&};Ylt~_w@)=1+o?7;InSDC*1hJ11i`DK%KkI}~ zLuv)c)B!_V(lB9H0GC=DQd)luHRks3X_{HSl9*V+FSrZ9$T7b;1y6R2XW%V2xN8!; z6m=kmNtVIYmz8oF61mh{UKNzj^f)Q5L&y|zHr)*< zKwlrI-y_5VahmK34SR)*lOir180fcLraV5kJrANZ(KLN7 z1{~g11g%7z2NCOm+-!xiCc)r&c{tQMrK+)~lwwyI@@WWGfjVun(r?Z_XiiA-!I+xn9H-F33D zlj$bYOIF8LAqtzI4{kkak08f2Jp5cKSQ4gYXe7WLnZXLlTY+d`;Dtn#hYR)=jBlk& zy{6U-jI*w;3&=;an=k;lRX>;k(M2Z2zgfVZFj&s|ec;~Lk~h4yspHwPv{*Ba?WD_V zMPK&a((+RW^d_$EkW9yN2T^&nKkICK!0qSp*GckEjl)TI;fD-rcca^5WXy*#o?I^M zyg599%9sEGKh(Y5cCxDnQn|t?mBgS!bR=OD zi!@_nA&l8xxq=av#TsVkaj5bvAU z=cw8V*BPflo!RdTcFO*V8I-kula4%>dIOl8{S@9kMF46Y&Y(-f^i8 zRc%(L-1`<-3L3+eR2r1_GqF6M?Omf4D;AI>V?ZPu$K1HtJ_f#aTms0Ifgh4)AoyrW zSq^})y+Q?KtV=sQHs2u%ZF^jL6`N}dJKzAm945p$bKjc_w?F2TWR$$=bL0Z z_4~wB+$Me4&ucvc{ZgVDIjnEgl4DMP5ZZ}dEsY*!0{$$H^qQ($DOY^? zSn&;*i-iDvFkA3?exTW+@4(0D(|Z^)wi4+seH?t1paBXKyDvnBOsyH^lcSP8H}|^b zOf4*$npcKH%64#?uQ0V!D|N6I8H6IMF>vp8Xebz?)lU7&Cj9zfcBt9q*ju>A4yFUP z#%(PzPm*wlo2$VIWd0YQoPBh?8fkelrXCn9ae7c5tr=N>U8-*BL>`gWiuoR4~T z#%#CJc|~JgFLCL1UyYrqtS@m$qwyRxH3mH87G(&T;;A4(I{2?`(fWQ)_V9UE94=tF zFJc83SEaGcR)i)N7IHA|HV|tvGAakJux(?_ik2x?AHdZ;B7dZA8=G}9t>1#b4HLD6wtnOMQDi& zo20B!)mBZ2x358M-~-Vd5Hui@JEBnip0Y3Iu; zoxll*w|Ij}mZUxl9zULd-~TvQ@N{hdEYG_qxy;D89nQPtUS(8bVEb>~iAb4`+q zBuBcvS0(OQHoc7sfoy^A-EY%GXi0tF6SpIDm%rD)IkCBKHRh&*@uK=NymO#x&tT(|mV!ZG6u9e9W#Pd33VUXWbGsA2eQ@=5Tf7KZp6v8}g0PWRWo7$Z#N%Rc+N#Jcd zWqtK0KdMh4vk|C$(gGTnyJ|+r6 zDMax7NzIn~=PnV2-h^$|d)Fk`_$!b5td5bo(|hP%g|L(~UK;Y2mkLeAH`xy_^>E{+ z#`-av`@}r+q9;5&+3Bm2=AahKGs7|koOpgzYn3E$ zM*&3vbi4|fGpT{?NK9RZuZ57=}iUcjbb zg?46RmPM!AvUJ;WKD7HcJAjVKIY=OTe(Br6u^Cui!(0@9^&nDYrDB&M3XP=B{lV~& zBI~5!-E$W7dv*J9z1zZZr=wDc8DYQI##>C|l zd6;hoitZGd-kSDK!`RDj&Rj<;Y;`O26zX#{B0lfcB_3_+M_qH zWdtU{pBY>LM*cU(`;9jEmBIaiQ+{S}*}fyg|4T?7`@a}m_J1+B?0*rO_oL14*zBJ& z8UVn@_&wu{nf^!S+3$=7D+>dFKKw(WyZ_(7^N*SRFGv3`5(7|6kd_@l0yD5O0%~Ni z5wZecGdly@KaMQ?=g9xZcKj~~|Gi!#6CkYe_tF2?(*M)Ze z1t4ec-#_5*B*l+k^nWHPehU2j3p*A-UL7-le)*L$094EPpF3m$#3!=;g>20aO5*o5 z{i_cD8#}fiC)@9ae}|*^DYWnBe7ygY_ze3W*{t8iXV?J=sDG2NNLAC0->ilAUX@vI zWxjqr6MAo4Xg#Yz+wl6PA~e~Qd_dAP)SQY+BI@<(%Jmc`Azy4FY133g13I(-81y3$ z$cLWJU~j$HyKt%IvnqP6tv*QaO33{>L_g74`evuzmsU@g3!V_nPajFw^&VFSL?ZS=f4n z$R{z3)@yS=KAy4x(*Vc{!6mSkm=WW zGsVuiJu#|26V|(FWf~PmkMhyln&UD zhn%HaMOfOmX9Rp)O)3dXj&&=gBI$C6wnNh%islDk7U$3RG(2=x9h|44Uo2J8GR#IgD%Nh)gdWSUv%x2pmZY2F!pkDbbgfMZ&TyKEvRIh?S(t=I_%A`8ARAez3#a#OGjxOo~C?gvg z=n_^1c_6Z8{A(pJ4tz#nGP$hj;$!A{TK>yOv}YH&`9}q_OK8sev%)S2R!-Ld(|Y@? zJso^oUtSQ20a5=P(XU%ZE%!o{(_$S2pmHI~dXzhs$pKn%!|5%fx6PKHcFHWR`>Sg4 zU{k6}Nlqtgi70@iL!*u`E3>ii>nm z9{EGA)#JAYR)jnmBP{GHV%(X~*GL?(0T^2{AD9IU!aew!D_L-dx+j>(yAK{!cTVW# zz;`&p^YpRv_ZRI~($$5ju}I3LGSG`YlD;cwr0f>Lp6fz1Lf(uRBknz25*(&c z1=TA9lP2s%cUkY@H}i~Y{P--=2+KHW&j&m!5MB!6u$$;v=pyYT<1&_V$+sn+Zy*IK z9IUKI+=;|#L!>hy2FfQKW4S$~W9+d4G;BW$#Acuh8UZei-Hv>l7)QE#d=1hjQ@WJx z#6`<4Ni^94BF?MuAbX66{+Qo|qCFW*$c(nN@iA@Ujj9hex#FkWG=kOkD!g=M(u*a< zZ}6&03HrVYMGjzEI;!sV+_AXmvZ)BP%hT2cd@fyIK<}D*zR{0SNH3M*XZ7C*#S9lu zMvWE6xgHmt2T>OfR<=_ra)Lmq;ptDemux$*pFF|s zn(Qm|LFGk#Bk2m)|6Fv@4qA*!7YKERRfVNNMkU(1>@ufj8cd!SWfxcYO!YE-3Cn{u z5xW@OoEr9U5O^Yg6rpGI7ExyEHl^jX*pbRx$XIs4+}A%^T7yPfi4JzJaxZE^bL?WJ zZiz-Ca29Y^)W=Zo>nq?4-zDouy)>)w007oMMp9%6jCiX&%x3R@> zyi3|)QV@L}kNsd_4;dP=tf<&QVxs->ZF|z^5f%Zd`R~nVu)=mam!W~0C2GkxbxrhU z2NGJ8T$x`F^9Me>-U<%s(g(46G+m>A260T*SMkIxc1nR}>Vc^o$Rdh5o0Vzf&2&ws z&Fi-ELub};GY1LR+gx1PLRqRx-}PKciYJOj%nGDks4*W$T0KM{k($D5dB2L;{66L* zsQC1JIhaOX`;nBP*#V<1^i2lqf*fHfA2IapW5hUj83a=T4;lUwVM~cVIw~pRR-1WR z0y?y{R-&yu&>crI61u9xTgn^*dJ zZNeHS2z5sllBmA9TxNr0_(o9qVEN3XOsVMaos5aLP5q+5x2ZE z-@YdxxJ2h?3<{h>?I+Qx)aGz(?KSRYU7{Yv)uv$7y%0FXn=_jPFY?dulP ztd^Dzf{`;HYCDU&m`-0OCoS~LnuzGUE?8R0&ya5=^xige+o}nM?cRRULY|Jhx2BQ{ z)suJJ^)(AY7Oi~JI7@zU%jCeMh*A`Vrkg{#C@~7;xV<^EAR|$4XMI~$bOjvllvcfD44ewtV8V?PNyHWixvW$r zJ=#2p122^?IU>gIkd9XuN6shcvTGs0NB8pewJeBNN6>+s@s5qQhmE-f1SHPz<9G7o zx*cqPGVQj@!pIzw*1^c{S_?234Q!yK$!=q`88WcDfgP!uiznS-_ibx z%>k{xe}gvvfX#m@oPPMM`~vbE@qhG&_+Mi4AC$nK%H#kFoIi*1Zy#g>x*5^}&f|Y- zc31(&n@o)KwDbVj#>4_pPqA|R$8h$C`-_uFk|;n!fxQ zBL4Xt`{%;`Ylz7B(~$I6XYcdadcf4uwW!5s8}1|AHw zEC9vYp8+Nt;CH{R_1_Ex6m$VvXa3#5KSSZ)hYR?t|2XjHmicv_|Aa9A03H9i#_T^m z1qbx#_-(eof=UK}65!tim4%vGiOb9=J`zs<6DguxWi>&v;Bw))`4t9JN+yyXhWdS^*o{6IVAQFT6lI`(^*iFs%q@Qy^}gl zXs$^&QYiLqh%x`Fy$&2vVI^6YDZN)aScogGz#+iIP&)aptaZdb-j@W<6kaVO>20yh z*muH?rm8O@*he~Q-E{;?F`J~HzUEDU)p2BpoH6FUn~srwFY38|8Rwm9?n0H>Z5lqo zK`n6rm*cO1d-0J*5NdGfvIbvCvE?Jx(4cuQK9pncM*X?X;0U(M&=V!W+{~~c7^vh4 zF(4A5y;|{HTyX|=0Vbr9Ngqnang>eC7RPn{`Z@E+g5*jEYlFLa$H2n-2i8yH$j_%9 zvO6j_5+8kO#OaPSc_5zi?XJ70Xd5{}nU^py5xfRsPZap;mO1u$BMT<x462|}j zxGPOb0EU%OU{y;Xy_x5R*+(n{rU`wDM4Z`~tsy>aldW=A$6n5)ZlPN2SEMluwEo_K zV`cV`ZQU+@-`6I-Wi#sY^Nl8(_A8lw?cP)o@oxOZv7^$RntWJ1i8%SDG{nq_%ZJ7Z zLMbNoh(d~-a1yu+S@dag487{G*^`MDIfRVjqL5)AYZu|(TNE&|#-byy@s2H0WCJRv z*hW+ng4Wp8aYsZ9nRl@6~NS8k2AfDQA+`MZU;R*1^)tD>oPt3~B09lN1s)(tPi(cqB!| zC}>6VGlNw!2+LT=jE|^YF6{P3D`X5TEMNp@mJk7bigC)sH^Ye$rcS__u8=j2UcF=& zt^3B*R*^m`9*3arxh@-5yZmO0Hxg`2pCX{hk2HX}6E7SsiT^xB1kJ`i6+O!61OyDgjvh-%PSL^oj5SZ#9+WNkOQ0Gqo!aye%A zxn^}Ko^yjUx79)11C{rS@hSz!f?&3oZ`T+cS`Gq#HV|jp5H=&uf9!?b*?!d4nE|ci zBlDRQ7}M?61eK+zpD(V#tK-u<`XIC)#}cM`_LVgaQj0+w>g^XmSI$|`utAT0MC?uo zVE1@$=;T%2;1yGQXw&K$6j@*yr4ry;2V=a_(&d4;DW+~sIXK>HWKs{VlhwmuN}0|! zZ{VU=lMpGNc9e@)6$($?LO z7kilKMJQ-6;v&eIu<}kpnzb>$4=IhMbaMj3{Ag_9dfq1w≶n7kbwjBdUTxwaDUf4GgNcCoN z%>9?=TA5oh2%{}O#W1&IN}kn;@4|k_bAUF>Qv_uWjd-h8*6%|i*II?hOkgq`2&xjP zCvKlfc~Ki|jTooCgSw1X=$4$#>37-dqp90Kab zdHD>>fzXLyBx*qR@!&APXQSBrVya<*dOnt=H1!(Vtv0AmyYdxiORphFokAP1|@1>D?)O8_vF9KcK_0W*mMJSm%PMPh1t2d`l0 zMBqdGPS#ND#njm90rDyA24>utt_JvF-g>X+d{i6RdbkUD2Ye1;8N~1hRAorj6B2}} zd|PD$!S~HTo+LG@qQz%}{)K(WOH3$;ne;f{#WGr23&hHFdgPkhCt=Cn-+&TWdtgRz zCpF5V1YJNsg`!cs_U@GDo^hMrV+MWmZ$jAR6>kPc_n+tx2FAM_cU;w%^n$`&XM9EI zMgkT2Yq|~)(EgUm{C&FqGuip$Q5wJo@xMsde`jUL@q6L#k96^89RE7I{gJ!=7VqB- zWcqOo^*4SAYybu3e>w2ST>tAl^FKAqXQ%&tBK`lRmVmRZe>1hL)Rc(bW<_g%RAWzx zjQ+exSg+xD%n~h&HHgm=2qXbd8SX+sBlV7^bfzO)?9#qQ8em4H0GYUj%y;EURhqX9 z^m4!o(_o&FKppj^&luTi;^JEI z9O8sPTtJ`LzL6SQ0ewfq5A7%50eY|WQZ477skiI1Y~L6YXqD~W)8Yj*7iPK7Ae}(+ zl9_J*I<8>iybq&pvhT=0KTgvbYos$0?K6Hyz3^ObdP(cMj&^0hr~Ap8js45Jkf6eu z4rivbb7;J&D_Ik)yy*=))60P7WpH$AEtez;dfi@q-)ybj>Lf~4L z2QFhy5G43r5#$2I36kfXsZQ=NAL&lrxGop2xkjI&zFP2HsFG=sQ0LI}!`OyUfV3)J zCMbq2F;?;NsjyfyBvA_OA|zi?V+!h5`RDg{jaT8ojbM6eTg1jD35WAJYHaJ)Q>C)h z(;1l8uLE<=*ns*BVdwH0Y=}WG8Y?EBpq%a|uodR)V{{I0>AP*=ehh4~V6MCwE>wx_ z%Ewxi3^?D=Y336aV5iXG{`{HU7x|q(_Vr8hfyqO()C+3uZp_GRr=%TW%I*d|ur;1y zp!2d%ADAX;j&b#}S}g)sF9yC}9;|d#i5MzIBmVyRlS5^4Y6-hjrCV-x=2>Cp+*@N} zURw1?%sVZZ;R?+WkPkHK5LN@DvhRqwL42Dq;>EXzU6o$Eo zc6c!O@I==X@p>0SlOQmF3ovAhD{|4Ah$PhU!xMy<)!Lys>akUx5rZA4hbgRNIh&12 z(3l>5`(bVrH%AC?uxqimFUOb9ve(8qnzgTUSwJ}4WYHKk(BFEhDEO^dQ84su5v50I zKE`x)Q`R)aGid}n51(X6P{um?kwYw1WgNX47O>0F_tA1TxTA%eNC{8ePn30oLX}2? zR~;8C(|qEB>6}PErRruJ`3cde5Q0G101O7SbjfMrg^}2vi_r7qeH*4|6J`K^dx~p`$rjc}ICF z_2tXNBN;0BK>vH63gn~K^VL~ZjDej-`E;#qpK*DU&LJxe%~BI)4wr*17S$xs=! z+}QMJy7#+CUy~A>=|fH*Q>S};wh9I*ZGG^CmSM;G(gYs;_7%t-yQ!CTL^Syv7pKg1 zobb8fIKa54xCC$25Tw?mIV89%bJ$R!EozxU^QfSa6C;bTAqYG%MUIdR8R2iYgt?=c zuh5D)&$n?y1PO|mlH!msk9ZG~ZzbkS$#b~E(7OXL@5-S8Mkn=t#z`!YPUa&ZPq{XD zv%%54Z^TDF$D-&Y^U1m&VdEeyFc3QBw$}HzWl*HDjDM(RHg)xbAGhjcd+6Sh^M0J& zL2nlx!vyuafZI^W#Ldd4RH5fNZb1^sr}R>>Rh3%B-dD6g>9{mmFJU(U&TI#ByRqnh z_7F)`X`|K0Y#RsG@u&w{pR>MnX0!_tLn}Hb7rFqhn9i{-{UCFf(ft*HK*kksph%tq zWG#d~7&*_8VL7)ED{=oF#D2DACc5G_!8_DNcxb+Q>Qu)R`hc=T8D`LVk|=LbrA^F} zrCV?CN!p15bAIw0Q!C4rasiUMqAn8Z$}TScPzdWzy{gudBD)Vbr$j|wcH8tZ_-PDL;c=$G-~{O?cG`9`u5!@QR@QE#z&tI2Ab=Rb8M65i5c zkO1eCU!Fal??)o<8!f~uDPdYY9ni6iR;wwI*A|t6<5!k)qzNgZEp?>F%!`xC%$N(f z6!Z!8kOOljzQu=>L3+=(x+8}aEl~3)8W9GKRUEhbWd`w^<98dKn?Nsm4$!B7>~AYI zA<(`zh5px+Ohoo41>jCXCEQWZudnd{<9ty3O3Y&3oGweq^L`I|)ZuVn0> zG+V!|bfLeiRgP{!itpp0lF?z%=cL_4glHV0J*=?r+KG&vf?} zo|{fxLlYmsjsjf20NtMdN~^L1L_q)dfdIi11HhT<&qVHza@+rM;O{xnzX|n+=Qk^$ zG524u_!lhj$2tDdLY+B9b^u*ICoL9AFT z4F?hqERbQ9Ctoth)V}cCW`a@2^$ESLs5}&)&h~ViD#E`-#6e-d)qJ z?Lh%bU9MBY^2cB*c>1^99NQC-^pzRf&|US;UgkFA+ZQ&_FR4GdHKQkpY}S&u>+4QN zb{o?{-w{U^uBc<6?3NGo)X=X4%JD(OS9fa0hxGR~FLqbG&440U>o=gX!`oT`U68OhdP_f&@VR=Sa4!L&cCxwcx-f?k!? ze|U4#kEM`ary_Tn-2xS*{L$T=@P?Qr+A%Xu>Y9cAV1j?|JRiqn6NG`LpI$f_9?Dv|ZUQ8G+b3L(ZLjH+dBv7=&4hkWGBlgCZSGWn%UAyUTAdhU@0hirzxa5WNhUvqW&lOG8oaG{?`5L|M6bMD(8o*^jf zG6FkBk^2NO59A){p7hh%_EI;9oE&IRP~B5gXN?S%K}Iao(cL|l!7WByJU72D+jfDO z#YhbA+k-ucCXL4myU-qb;?79Hf0zuSCnhD&4T)eUUU+`tprTa@A~akfOBv?G9$vsA z;L@6ahCSe)K4`#+VBMF$Lai~;IZZO^#rAX_0=ULWDrK7P7!6cN96x;p85?J*cy%_g zg=O<~DJ@sZ%&3>kp>Q7r$+oE76SsSdY)#<>8&7Jh$?49R9_~(q4Bf9?lcDAPuDxwkpHQp>9}Y(O2!iTvCTDb6$P%;hwV$zLQZR%nxLnhc*{LGi zEU@^qeu=NCIoDO#t;>)S6p|#fF{`Xw+Zv}Vb{-7H@mDXV#FxSZYA`A4UEh7Lv;-bJ zX(~<}&dlnHz_;bat)xUKaO!VzMG2(_X?+mkMEV0Cgc13gd3XdqLGy`*cl)LqVG9y2F0UXn zAzk=$-JvE1VQEQ;#C_riJFFXw+^ZC!_k=XFs6-;1en-wbA1IEepNC3zGVw7pPCqWD z<0ObG$%9Or$TV}3V4ppA$ELFf8=`e)tY2;7T5f)+88u^5Hh!_*naWMWj*1UnKMZTQ z`alJ&m2wn{VEF1ZYzhem1eQFPwCZrGyCUHoQSF%lO3pP8x6%>Rx5(1Rg}zkR2tD;N zRk!gjV1uZlVaK!&@2tX;ux9RTKj1(@IFJgRLARdp!&jr>ECf_hI6V&pG{TMX`mw@d z%uetHjBxK3`||9H+!m*%Am!>)hM^htbLd53!URf(^`&U!&qTJ0jt`&29UDP#b)2Mp zX=E&#(Mk;KQo?3{np8HK@H!Ndv7R=y`f5MD_x16eo;0Gb;okN!k@Z2<1p z&&lyt1b6nLcTJT~CISy!+oRHQ`W$XR*8%b<>DY2H_Inyk1~yb!S=cem<8eWkt2G|Q z-lf|%RbNntE)tZ}d1nj_f`Wxyas9>v>2`Xlwt{r3f^1n+7Li>K5Wf?KxN$yZXX+cW zf|Z?Y5@PS|yc2qua ziv8-^CeQ}3xZlUBB21Qibt0;5Kf5tS;PRSdQn@c`z>ozhumICGe;)wi8<~@P? z)$L6rdL<;T^o0p5y2X=mgY74evVPEGN{AQM1vr9_Uy8nUHJ6m>VM~uOIw*4D5O*fw zs-z=f+dSgHj|F1Ocv2lyxR2M~u2qbo9>Q~;K4OkVpGliSJNhbkr?0FSj+8zk>ojHq z`6IRQj?2zyi&Cq%cbvtd(<#5%sfU?G71SBRR7x)$fUie5D0tum*@`*KHZZn|NZSKG zgmj7a(ce^uU5g^?G&JK}z{fsx-f!@*7R|maK_cIS;Xrh>U#jV}1c^n=>(uOLSXF0~ z1BYL|!MpZC6T9ZyJ*6pAsoIKjSA=WyaJzfi95^f#94tVwH2H#W`AyX9WX1V4?S|ZG zv=0Q<`d+9wyrz>dwT=)Sgc-SuNne0kk0C#JjcY?`05?~gkr=^C#~WAswT^_Q%DKO@ zi`#Z^A#@^}feN?i_8SlIb}^2H$$NR2I!TwPK^6*K)nzGjBQ14UYZz?S(yh0Nl(e&k z+FP^kz3XNQFm04w7`ujMTef_Yt1o=i7WS1)XkZtWeEKINo5kmN?OtAP?9zlYu^0&3 zDv_EgDz!$!M3K7K(__u7r{_M0=qNaB{N0myH;4~v5q<6T%|l zkA_(jr%gG@v`$vz;Hj=1kJz z)d9M>*KfL?)ByQ97%(dpFf)c_&GJOO+z0kXxM*_{kIX?kNN%P70nFr|6l|dCNTr5W&rNWzgBWE1L{#& zSeSnk?%@AKXaKB;&&`cbr-V-@W~*$APbZ8|{@&Ke5McFU>8R&uXKZ9{VDH|1w5~Ure}}0fj#F02^xtfEwqA(*rXLJuM5z@5Dv_>llBm`F|NBBL@II0gx^; z1HilpV6y@!PGSb&Yi1?@jAQ$^*3rn;#>Cw8&+GQ{{{NRT0gyK>BcOFPz~2SX5SkSb z3_GAV7r-$Epvq$Y4`R|YGBMTr0k`$cj12%DHh+on_aOLRG6a9ze+&R0Y(@ZX2ehf8 zWdSs(W(1VTFag|L0Dk4P%-t{=>FDHcW$b8XZ0z*sK>uu2{>vNbH@N+eBnH5@@ccIOqWm`hUZ@0KWU@s{+Ux zW>$8Dn|NlOaiH(*X(DCli^JHiI{bAwXgvtc)NMih(25syBgZKaI6`5E7 z4;b6ukTpO5E&RGT|Bo3Err*!@e;5!ZWQ3Y~8q=Hpph#Sc~ zQ~tb5tIpGXaOav}`h~vjX0Ky;wause8zpM#8?}~gN$eDz9>h zC)bYS1_MG)=Efo4^Ot)jbzHv%IahzE>GwCVcKGkps%TvmK)8;QvL{^e&U{X9!<8Gm zQ4gsmM}`8V^hjjOpenW5$s|(bY>t z?yrxC0M))K-d1%qrYd6bOuKBorJwm466>I&vs`TX2#uF_GXen#Wt*K0#=U2(Yiccf ze@aoj87q);R8$yRTw&whLGyaXFADugyhAQ*jo($8q0li!|1 zU8LXcMm6UJIy(+uf9T9x$^I1j#4m?H_ia6kQJzPXV|S6@(;HC|^74m-%n3TBzJzcT zdqZ^t_}P!>@~Xf=rpi*0>Y;5GLu$esODMbBY+pvF3KYp%E?~cmeHCf|0his}GF+#` zjTksHu?)~}^DcUI3<)t1cpG?-g&qrOBTj+TKWy{7ZC?l1qyHSxAH|=V-%F#Mye#Ci zGN_-aGeHBVDrc>b49Al*7<)i-kxQP=N_EG}G$fKpslgfr*K8n+Mykl?S_0GccnBMd*K3`g&TuajUsUGYj%G=+X6d%i|lP@VAsKkq<|9AKt{UUK!5K zKezTGmv$WNd+wzBWGUD@d~fD)@l$cD;p0uvx??g3t99XXI7@o-s#yP>jcHtD0N>8q zh7;ZPrO45qUC)tL>N6*Y4AeL~dUj5x0akjgN=tRPo*=}#;bXf zAUcqH10Ry|=kLL}wG{9iU2~uW8(z=#w+)9Nhz3_BQgNrXQIHf^S25G zFbwDUy*dyZhM%`DJOX>%ItluLP?z;%nd?BA40<4**sOK9Z-i<5)S3#F75j35$IHkFPL0*(=p*5Lf8{t4!YOZ`R2Y`B$ze& zu8;o_RqWvlXEcAJ5q!X8u!PAqY$E+XROz!Cf09pqpnrfYxv9WaE$^S+k1!_mx=9M*iGU*4oP^O&(QHK221t$ z=0!#lRV7IFaB?JaLNvT{{PTjW_E@yB$SL@3s?7~RH7&s5UQ41rX_015;pre@1rV>M zrSYPu)|P8GC`C)=oGEf!>!caqB|U;c(bh@PHctZAz9BL)5-WkjAcH~%F^p>IR<)zS ze{Y9x%TH~6dk|oBn=*lpx=={acC1EhV%;WZn2e5xO+5((hUb{ejs0$1Bo+BvTs&I< z%X|Ynx_mE28-!BS`{tLL-TJwYz>_yP;&!E`k(xcbErL~J7e%RLZ-=9tLlh4t-5E%m zxOU;{`a>PgfU7bP=4-AyQ|8ZLt4J{y<7s9SgPhX)`6_X~eae+_Z={VrV83m+QVOdP z>FP=#$5F)9LfMucgj+>7i&h0qQ!Tv7dCn(svAyC94XDo52o-^E9J7RVLYo#bMYsN3 z>+VS~`5NNK6Q~c$LknTLV3NZHiACp@6$v4-Cqc_dIQML~iDIBUZR~tD9ZwvpZ`g&Ai~#A7P_>l1naq9MY^op$tK}!wnc|}y z_$EH1Q;n`;|481Ga)&9$R>hKjq43i`64ZVR7fLkp!z*^0*WmKp?UW(B(}nN&aw@B4 zi3s^@bu{bl8|pFgA@wY+3rs>iEKek8eM@8dH>^@`(!K<3p^vEzOre~Ky2nY21UOGt zavy||;kJl@=Ymj9$}1&0H{oqme|h&XqY%>|%-i1ay8F_0j3(z6Mi5s%v%hKkan69`I=r^R!d=vWNF~nfM3Rs35`y^4Cw^=0Dc&Ct-y=o_bzapwXuO9&QeS0zjI#@Cp$ zIHKn9Ox6;Dp}*!qy~pH#C~m*~5LE+M>ru;+%@3-n9t`SL&4PxVQfd63nS^xvae4bS zcK9I`gNEWjE20ksl`gPqaDu|5j8&NEeFOu;B{CAkx+uQB;y1_wL#~j3J(F~vfGMI|jUH{+iiS~-tib83@b8N*S87TqlrB(_dZNm^E9F8^JKoQ2W@FF?X|$-8Awzqh zp(J*=Uj#!H{egnDU~%7#S5D@3KIPFjuY$NB8HDSiv-E@Q=Y{kLM6B;VM!|{u-56!qi3#Cp{=jDbBZ@3YL^C?9k>PS4GIdsf!ug6zqm zHw&-F3i&y2KO3xLM8L6-Z7;A08|=*AW@A@cQvqdJm5P!hI0vhYI0`j6&sUV($2UVT zxWXAO199dEkd)2~38b|d!slf-(4fC)8iKy?Ou#egz@fgW)c!h7QHT5{!I?0A4l!YJ z%dc8b8z^XbcBoU&1(gwfYXf(DLo`F9SsUKdc&SZ^M6GWXXLw!Q`(iaXJWt_#aE;Y6 zcN6ErzakZA|R>oY36o`YO-<%9Y8Q z`Km~CQ3yHNzBC3xiJtHpXAY04s7HD)(kf)qVo9atnH>{zu174wBgBiupcv)jHeZO3 zldwnrF+`tUQZ6?XLmCD??{x8GXuZRU6cdM`j=j^X9Z4+L-IdX67jC-VHTvqIKr#RrF{i+PI^TqSaLh2ddySN#CL9Q>6 z?xe#2-e^!T(`GPk)G%J~C!~*X=&$e4M`E#!Go{Bzmbh~k@uU$@nwa}+H7K=$b<(qW z%rwr3OT=n_>Uwr>4KY4!SGMizJFBwmO|a4;1KXv-ah3<)tUuj4W?KxOFDe$W#s zDx|>r3dav5N$@&6?;@4$@l}lVje0NsETg=n=!%Oeyu9+O`HGqupXqM$!;;-|iP9Nz z3fqf7pR@})?uR!4mO?iLiD;fVvTK!om@)HUE zk*@^!=KSyYN`U9cPd*aRUHq4yzwnam0CmMLpZ`Wl@^j3uX!t**V3_Fvu08<69X0^J z#sN6o2LM@GCV*^%4M4E5v;0m;@^A4(Rt8SSZvVh${hZN%86^`N6M$i30oeEe*gycQ z#mo+1R{`>GRsaLX@gGxe4o)TjbMjw#qMxSPeZ=B zG$v$a`kg7&KS%mMtrr1er(c9le+lo;WYo_$z`y1P83Fh9w|V`bzy36kg`SO;8L+y4 z=FR?KPV_h9e$0`Hk@+v<*nhrceqG4_9s31{oe^M+{o~aFXma=;7ND{Nc;(+_{y$V0 z1INGbYE+5wlL}ky5Cng~hh+FT^Re)B`sV9riZrSO_5-1}IG^9Pp%F^Oh#POCJ)g7n z5Ex4|d}&%UsF}25&%hjKqv3}4?H+0T5;IQ?WAtf(uF(}?0S~?VtV-XLW$D$YuF?Hn zuWo-W@i$g2I$3=>sa9t~bsQ*LrS|J>x9pdV)BCl6 z6KoG1+W3K9TDGQbST>;L?u%bou*qdntG(HO;X9~{mqb>cX;OrxI}@?W4AJLABZ=n# zHx&kArdyVM>rCOSI~#%aU1wQ~)9gq418GB8~TN?+3a@lP-Jq#n zO_xhsI2;Xo_R&CN`XnSS^)Bygsdr{y0Gc6$IS(3dPm)ZIU80&{Q~R{1kF>SJ+Hf=J z`-D6yFzEHbrtvgruNEH#P6Dq4MxTwAk>xjx;US(DAN4TN=5RR=0C4&TRMVN0VdJg{h+gKT$CeZCM)k$LA;v z-;PXaBg?dYRZ>F0MzgP*etcM&^D;E4M!+CLd85OLVyQ8F%c35Isx7`A((Ul(*Cdm10_JJ4z(F7c@72g4i_omnkHX}1V$>- zz&hx2p%=71#zPt1$)z@&Ia!Vh@!b39)~!`*t$AXoCkgWAmZp0ZNFi1FcYS*M8%UQd zkX&ym->yqP43@YY>r@qo>#=Yxs%S0+2v=nkG(6=QL&|a*g>d+`gByi+@|?iGJ0t0rPY~>#VG*?Kz&t|9DK9E{ zRQ#G(l@=SpPu(sqoeK#S!L*Oln;{7|siF!?0wyRVxRGZS=|hK|X@ndk3@#NUvExe@ zxk8+Y)Ku3>zu#{zfQDu9J^`3Z2?*Fi6RJjk%-b0V?m2Jio%u6Ryh$m|wpCHEfXWBC zRW$j`kzzOY+F9($af{TBk&nQ4eEF!v68Ol*g3?|lw6`!6!58uQg)jAQm=RbUHEAGaY2YTds)5!#&01(iPS`aAZpY}AZ->mz{cLgJNi(9b`d5N?Gt#3GyjlmB z-llTva8uC(4M7EyAVAN?pTX4YJtb7|&}vl^NSV05*fQ*ppCwKADabl9%1jV)v!r^x zv*)yp z7nV<|7HcYl2YWio{+)Z=3U#y~(Iq6?oZ$kvTFaGDLZ}TlIuE?pd<-t!@EWz!0dIro z0?6e&6B#^3qQG`?Ifwq5hPV!n&B$$y#BTE&!A9w)WP}x@%lfX~cChXGc`E|oYZvutxKq53aJE3R?VASw2?mTb|s{k#H>GUE86MF)&yf}RxF;r!{pgj zzDC4=ZI2kOQ%hjyo}=)7DPcQ7G& zqyA>{yOW5Gu)PW>6EA&(Zc7UNT4rEoxhEiHgm=lN65~5ElzM(TTGBx;$o-B{h4e0C zoKa6)I7=RtGW?seQulH^i0Nx^gQfMO?v_4&ca`?I{F8f2vis4bXp$CiO+{vjdBBtP z8SoJync$qICkERymuT(Z5!4NmGw-^fG??AdkCdV-IX^OMZNIk9Md;j@GKPGV#L;17 zf;57DsJ}RW4Kw#ql2I&)Uu385WIG-V37!SI@hvYPqUKl4U^A!r{hb}uCMk}ZyDac!>G;$6mi=#DB&^KhuFf z;-R0p(f>xj!Tbvj(t-Z1Y?J-xcfaO8|1vrMk)!;k%V1&vII8?;1@gn)6d-y496$dQ z6#Ptq*?-r1{J&2m0S1=8Wko;ox}Qt;ZzPg`SmM7K$Oyn>i~udfpA*SHxV`?}I7YxR zJN;jKV*fxTzeV~FiR2$mFn@1e@}H-RzXt%no}4lP6es`Y$!R8*CBOvp^zjASH zCBj1kZ+dO_>o;0+Pfu^@gw)Bm*5y=ERm7&Y*T*o3_&1-~PEST72nm3C({rAa{rG&7 zBUIj!=wb<%pFH8KilunpZCoFrefSc1!^h40^kRuwsYn+cIJ<3t+E@Ldznu8CP5hyJ z;3?D@#n#8;>2~upU#Leo4_}n{)%|{xtY+AM;R`}H%-7W;%>M4{X(wkNC|5rQ$?t7m z_xBfSp=3#2&>iCF?rgL{kMc7j1 zB5#=Wg>%}P%b(})kd+vUIGXgaGk9+h(HHw0B99c2^etoJ z>vq-eD|rR`p+h=~XeOeT@0EPEzB{lH-t#Rghp)sFTt=+jPdzYE7Mw;Lxry1bE7b-d z$aohi=zf+H{j4w4yQ2D_`?f!%>HG-31B&FLh!Y3=_~V15QtBo!L?x~B+|<1nP0N9P_IBObIqa!+Yh-{ zSnUr_4l}52dRlLz7Qt=z@zUihBK1^^lHe%8zyoaKN=qqSZ8#8h`?`;-Y@D_P%DITV zeaE1m3gwXzp;fbpKDyNq!`vTDny=WW0UduhXV%3w@*C=ca7-gW1rjejO+td>)(R$k z1+Nsmj@Sh9+gAlHj|e9Zuoq?ImmsZ$GeC|d8&NI?#+|m|^3I)5(MaH22CunIUk(n! z$(mQa?hS`@WHm@o1_?|waD)1E)ymJWvUH~x2d?6LbYO?Q?VSv*!3=u~J8QN<=ZZ6N zH>17C|1j1y;y9IAgqAnnR+*y`*i>DKv34=UTQ!KI?^YTafo=_Q7*Y2Q8;Rkn2A^&b z*#BWPKUgO1UMG&Jdqksc((eYyoF5bvTyhc6V}oAbKi^|Pa zsuulF9+|eR<=7|)7w`)963gq@#*hg_Snwvz{SwFH?4n&8ju-?EX^fB92A*s8`V?b{ z;Th}<@(WO@XPuNFP(`Gqn4&1iY-Nn=n(Lh(+bn1_Mo857kO|^uF*y4CqpN8SxPaK) z0{0LDl>$^HZZ2wl2^OS4!O{A>+=$vbuVNKL@VI83*mLT6Cm40#Qq$hR!_ifv7765{ z7m=$@;!l%QqTy~E%Q8xz4GskeU@JUQh=uUqYT(@p=K+swA0aJ7dNDh`l(f5`50;yF znIAo+#mfg1MAx-VJ}1qB0|U#KONpiSZm^|^(aNGUo2KoQ+cbLYm1$l|}d7pt?+omDpzOabO&kL)1vr2)91XMH_!nNWIwA zEYuOuM)naGEEOtko)g@wuv4-%O^NHh}{Vui{Y9=lz* z+p+@59%f{O1449qdEdA`wdnhVbew;>SZ|G`Ph^UxT z%d!%I(mg@GyiAm2FQJrN9t8t*ToQFtLHb>LF>fOe-%hK%8W9D^O zFdnQFLmmHz2t*dk0ZnS4y6ZZiQ0R@ZuCPK-qCP!f$vMhGnXkrQ>ynQ__mIF79Mdo^ z5cyN6^okY~ZlyMB=~5aq0;kNiPYq8dmsH*_-oVo7Q*r7gtaY&Rl5$9EwaaMnLRVFq z4@*LsW(L_AAZmd|WvE4Aa~Zs}&!V`6Dz!0h5ZpFyKJs%y z7##r0ADTQe9-Ukn?W)imb1?GG^#0PFsBq?Xrj3(x{;EnHYkcK1#Nfu~gaBdM6DV3eH)4lkH3_LbgN&uVg=(#Nk!lQMdzZW{Cz z6j!u%L-;wr&RRq~R%=lNS1OszDrLAKRZ~N_OGUg$QL9@A6M+|dm+{$;am4TJ5pxd_ zJk89Ks;dwGAJ)D*p347!--?WcvSsgmj(M!I_sk|`WEQeQ6d{}Jl|8aTMr39sv#e}V z_R7f0=y&7ruDn0r-@Bu~JZ{c?pUZ1K@8|WpUe`045(hyECyJK%3&>qh+Zs0;m)b<% ztXtqyY-03eW~T04Co0i_8v6lK$3ZZE-le{*6r!ly0^(05R*KuNhP3e_a)K;|3~VB# zZmJB=wUob{$1M}^jmyYbTm&P$`IH$N?8L~ZQ6+%Ct-QwDhaaZ3_OXzkA?njN!C9J$ zbpC}0=%tr##U{X&R@$EfYtmU=K-p8rb~Yp6BPkmo^Ga+ZszeZi->H^tt!qOKBC5Qm zL{0UWwV;Lfm9}RmDTz`yA$X|-zlm1c?)l(1!(kO!wp?Wb<*qv6ULlJ)j5=bH3;jJ` zkT|x!FG@;ue;B^cz9}eA$l=bgcFr)4iSCuWFvhvfOJ*SMwS}~z=Zn?*m6_^f)R$>W zdk6E!)S2olvp@0|JC`V+vS!&|E6`wCs_Zr)*6aVo6!Bdsm8_m8MgQC(+sN5n{3$W zQA?5eSfzMk-t1vQCj5Bpag#Q;OhXq$1shcu&6PL0to#5 zd*$>OYR&zAwt}e28T2|7&y~A3XZoym5b7)E(C?eBSF_WUO`sz_u4%*%msRL_35orN zV(-ndKHD2kG%WiNBE)jjZ;nT{Z|vNgnMM9@wcq7uwWIse9t1~*Ed_jfZ0C(6*(IoS zJ+=asIVcYvWQ79RG_WL?Yl(0zH7NF1(sZ#-4#D>@CQ=8Zg9E8wSx zGn(AnYA0hYoq_n+Bh}ETC?8@zUcse9Vu+~vggoKZ7d5_a35mI7dHXx^C<4VvE|fu< zX}pvnpHrAH@5PoEZY39E*U~f=xa%`)-+BVm zG1#u(eMEv>CRy&@Xy~1VWTsKJwYK5k8Ns^Fj$%sWnx~wZN7$W;Nl^nY(bv(0YJ_x= z$7NDh;p*gDyCJ#0q0vP=7hgGfA`XN7t#=^yV)D1tcxy3;)MRbJG|AgqXu@qgrfB>i{tl&4WT})bIyIa4kk}bEXQRmTWK!=JM)m=EUZ8S7etyG*X7UdN! zLvt&-qqB{~86?y4W=+&-D0OFjh_szO-}&1W?J7w{R92^NZlCC7Fdxl-vRu1pA2Y;( zFO|#iz2f|J`1jw17sXAy?jo-ngXTqEIc9M(Ew_Y}k4V#%@?dOe;1}b5?-lP!Y(l`! zYjMvef^TvLFJlPd1B`^gU1>7}$?e(zgLh5|jVS=?Q?!KiqZXI=BxwJ;8OfJNaui{%sB-7pDBW0_wT@*K)MXb`VS}qPVR#Z5@56Oz;hME$_e85 z@B4SAc6Qc$Y-|Uft0p%3)}{_-&ZjF?A2sQJM*2IM0b&IKry;-~U>g)D-O339PHq6F zR=|Kg059iH)lU95nemgz-^$+3+TQNw9iYguJzxazdy@i^@qfsILzdxaOZxb@`v26= zbN7E$iX7CT_W0K=w&-y=-950A0tcKpLR6O#kRzps?5Y;-FO7EB98@Bay!usV! z@q3V@@Zv%rrL;Q9D?fHR7TQ+tPP#Gey0^v;42)Nr7`zq)%=*9o2sU& zk21xj46)Lv*;{(CVLhOzk)R}9>FilTXB3*NpdpNL*}m@UcJD|p+m-k?8cYHq%&Xby z#Ad4K5 z^3vxg2XtGxF3F+3V)AE8n7&%9=7(2*rxtStX95KW-rdc~G7X7}mIILr5~8xHwWlWV zyhjN&e)n3IU`L7yVL;Sq`j+&Ms>spU7tAlB>~h6F&-zF4KO0!2y27N`aF5r(-7dG% zNdA3v@nhmN!(kc1bi`!K5T}bVeHNnS5Px2b66SKb|7pR9mYV)1Bj$#qMVR`98Tq_(PAXXEU+jg@?d@pSmC%^XG%-)Nl`VcA z&>$Y!Fy#N7pQ{k=NE}tvJwlWE0sFj$9=9KSN2oFo!-&gvZ6UY@v+46B9ShZF3Ku9w z6*043>KwiHJRm_KIItJxc3*N0;N>ldBc+mbUZfte3U8THyF-$4vHyM=HPXe&1_< ze!n!)aw z*)AMdhmE(^+o@{&_{aYK7Zh##(YqXBq7y^BH0IyIsJP*Zlochld>DPxulS<4cb>#L zUVyOFUwU20B|QUXXJ$5&`EK37{Y;dd&U)I|t&r_LOL4yZeMVif+$_Ylw2##xa8HIoLmmB`K$a}pTC*Elnq6(!(1Y~m@Vi4Zh3a2vLVQa2UqU*h z>%3c8Nr%`}So1RBkR13zbR%#HtZXB_s=RX*>5v{2W)WOt5PYR(jEOWzTzH=qX@C~) z&8C?`9FoUHzOu+B{Fg+}y%qSUvt2T~x-~yJ3-Ck2^Y$gTgNGk2T+scrGl<8g6-2R? z|32J`5wlk7TjT0ow<6VQNP(I{M@xvH46_}+{txcbI4LoAL=O#;!r?YEB$WpDINCke z7^%8XkJ^F_OScj6hG#p*rUl$^zl-9%g4gdzTpz!eEJ_!T z=fc9_(U!K8p?@x;a|6MMXz5Km3JYDo{3nd(SzhD{J=a;Jnts@5MO}ugNUCcqUsPVzN z40n>LRy`GOb0`wy@YP_o?R@qM;Ha<`*!)J(Xm3}}&J$Mg)&C88(;zYKGUB2;g^)?# z2S4g7F}K&ZTRI^n_8bW@#o`+;?6-UO%$3Pnxu@;5%HW40sd@^&GnSk8?HP5t`;6lU zXgEyvvs!K5NcoC>t{{3^0)*B3iMY2>SLlsa%OvI<+wIbUVC5vHD>o{=m5nz8#9t)g z_(?|X&6}3f)~;hsz9vJesQP}#fzYq*)fyXe$^0$L&fv;nsaokM)YA6Xw}qoF+(vp} z+fv#I_gp&0FN-mNMXmk96Y70sB*WA)uZW_F7>O%O^;vQ9^9CpGDDK{>A#}JzG$F}zJcFl*kRH<9s6*}mFg7lPc4Lu&RP8BVL zvuQaHUuYeAa%)1cY_1AL`7W?l5Ho5UqafV70=5{Y_Kc^$C$bRh;U0czT#|K;?@?*E zMT$#H!Ka+NY9n4eMN_y(@jb+qS_WPt6v!1+n(o=Q5*dGST$byKJn%m~Y z&zIMg2#abn+#PO?R8?2eNOkXtfoOykAml1MY84jR7TT}63)Y7}74q>5^Js&{ZTyUL z1`~#x!i`5+g*&`SNbo58<|S*5wlJ~coJ^F-6_Brt6Vo%ItXu5LwR~X{_0bUF zjV7{b>H0J?I`Ytxw|kZt^KRl>5~;ViT(aK}S&9=Z3&J^fr#$cd61S2@7q^#7e+uC? zRR=$TXEn!LSzH8Lf81ePBG&Nc*5Ta=X z5`HTG$B;R#k!upmz2@EHE-PtE!)2m~T6VEWPGZDkYmc)&tz5O73jIMwPr4>{I%Nk= z%KnoG{CmoNm@E9cVa|2dl%4A!+X7N`ZfMF5m=7FW|B|vFe&#qo`ookR1PFz}Jb+68 zgy*mZ2N=u+ac}<% zQZ7J{eBc6c`U`*8TKxPkf`Do{oB%%n1_ZbV#vi}m{d={T-`fWS^b+LXj-UTt0QJ<3 zz`1q6xZ>0o@&Z8;~6Ilge`Tkv;7W*9IpOG*cP=@*K0&6v&q zIwhM%nr2T|ck7m5W=T{THxEzxm1OseKR%GJpkN19QYU%z4tZU5bWcrWdn&;Hq}%Yz z?&Rv{_lfLRsP%A=JtjG71jI-iO$%JUPh;(n5(S2Q-KkfklJl;p*Kr`(v)C?$_l2WI zg^wsn1@SwEu*%AYqFfL$o-Xx&wBJf50H0WMV@vO8gU8o`3!kLHjuqsfTb*J{R;+mV zKQumLkzn-WO3yDUUFQ6X(%8FG>ptxrzUDH;W36j-Q{s!;R{h>=!5FU7c;H*kxAl`2 z9YLx3Adz}QhqkfR#g|y#A9e0EE0=5!Y_8DaqZD}vl(qP|=uQk7xat;R?zno+uum_W zI+i@(fEz2ke{UtV(xIkVeLD?l?d!QRU89izo-2f z4?D>Bt6DZC?*-gM;-SsoSuEzCI>#w?jqO^saB%#?iKrTSriIV3Raboydo3K^sWgG7pfH6Z%v?y65!^xM_qSt~gD-3#0fL%NplIIJo>1XlTp{RXBQ zQ21&)tv7N9mIEmtgy}Rbh>vPhT(Bln-mDdl@d(0hBt=yn^U)KiHfENi1{G*cejubK z2OGS3DgSnl%{TjDlXlTdT7yRSbt^reFJKHG|J8*8t)ihR6B(qkbRT4_MC{4Zj@YG* zCNADgQ?#_S7{iVE^T^Ju(o*UMs@8J%5YFdcWKpK$4^R?tfq-)4X0S?IQCE1c$+Ta6 z_0HEv($~CTXxe+>op@?nNVKFEC1c^(b$EBvEoz64L!YBfY*6^_ZVi8yS`u zdiC2qx}-wETZ`hlk8dnfTStF2kmSAi%w(SmGpp5TSjLg8ke-OTKA+0-sWtb#p!XMY z?L&SzwA8YojbH5#77(kGxwu9yGHYEi6hy`|u%R(kKoO7{BS7KetFqW-Q0h1m&#h=c zEYc17(v5qeG4qz>Yl}De1h{u(39yFdQ%(1gH=P(KI#Lm?Ucs#B-e8DA?$L7JX!zM_l>YHH3U^~qmtAUH_f*;FT8y8Vz(i33WpWQ`kYJ0gH64>rxz5%P>eyv= z1d}(|s~*u!1D3S;t?D&+>@9lYhHs_k6pQzxfz_-9@s&IZ1=fw10_{t}vGfi3A4onl znoe;B`XE)fs8c0V(o7ZK`$Si7$N%{C-sZYK-P`JAM1=iV)xB$(4>V1J<8(WkQfxCx z2=3rbcJByXDledVj-V=8A2pa(?j1mP^^T5&j93)`Wpr8Z5B-sd(T6YIEAXNUM#G^{ zNa%^pdK=SuadE#PD!L>`j&)Va>}kjjU(9>js6MlJ-D{Kt3uX8=Xsyz$N!9qm4tGKg zZRzfZKVceg@HgbT=cMwrVN*otdEu@E`7V+$BEq2WIkYqba(~K3g*z`wbJ}Ma@P+Ru zUJ3flexK{3l3v+RA=2z55YcR`#9MecUADV(r!%M zWNW#_(MsVf>5AL?{M??NB5Cp#qSwtkq;2ngx^!!y+(I6|K>v{J*(B5ubA(e z4pVsYV-VgXnH|RUZs>VRkgXJA_U0vm@m4PrS$pMc-Uq6E`Q#XD0q%<~CYQFCmUC1+ zF%my|yPWHu**Tx5zk+Oo(EY;4hDo~|S95qeXML@rzqw%`P%61G$eKN{x`Rd|L6y_6 zBG#K7O)Ngvx@VZcGZXlN_{BWyHoN$?}>X%@1e=21#X!echu8u@Lp9Of= zYcmSsIX3zzBy~%gx_r9H$}OieLQ?KtrQ9ngDxr4>)RknI0>0C579iPr_w~rD`U|0mFy7`ABGSYzbly$r*(FZ-NRC zHmtv-n-W$VWWB*(Y$3kov#9rK{zoRYD2ic7SaW)OjJ3dI<6HsjgY>(}?-$oz;7hS= zqUj0~#*?Gm-&?_1Wq*r^@cJRiTZN_&`6daS^?q3h=Blsvt@fnYg1l&5y^ikuqGtN! z`rA|(Ixg8Vu7;(ho@BmC_G zF>zdnq9L>I?NhzT>iGE%(Roxdos>Do8IwYlv30SW4GQf>my!qQYwI5cVA-0#ySO*5 zc;USS{DTi7D9GP}{pnsl6Y%h?*<^Q8=$@p9_bZyW8~lX7Q!p{>o7iBp>W?V(A$u2Z zHlnwbQ-yASzj@lXfIJQy1jIxRhR^tjYNk*sLk5b~ZFa7y!QX6Vm8#cM*<+y) z@@;^hNfUuciOibHeRASl9p;WCD&r+mRysb)pSO7zyrUaza8i>cZ^>KW zT$1h%bVarNWKXz_xn|#BOI2g=IygiTCprY-Ia4$3a76Vmryy$VtU8%3HRdGsxn%bU zhnO^>_E@XlmWRDc@!^F!Ko7~1GezzYd}FtIQq8fhAz!A_7bf1yhx6@xsJr{Rd$IB@ zpgH<;R$@D7sbsV=t6vJe0b%ibne)5zeco2O8@pualKjR$Ua`!`e=RmbN>Iw!ga)@e zZ8*#vwMUvhXMkwbDF&lLFn|TA;NfSNg1lJk_@%sjx~TiMD@LvkeYy$a1w@$N#K~~v z4It7Yo7>T6Y+Fx_ahyGRu<^5EJt3-Vqu^HS5+8;CN<$UWXR8c%?h zZB`O9_0kw3A`=Vz{7_SxnU3l618Oj*-Bf|)CTdlEr%3D{M2j0wq zXZeA)e=jJTr@2JM?o};$X?iy~_WX49Ycg@8chCEC-Xda&ozKllad-dzr4D$aI6|{I zi3Yu1YhQ@N3a1|3%EHvVk4j|&V}jZ1i!0}m#~h|UW;g$k6bKyjaK!YJ5%5TH%-d+@ z%P}ohDDoR|yrSIBSgpq2ZAVswmTR`xu#F?hH9pvWeaOOLqrCAsBI2@Pz9n31Gpp2A zw{F`a#XiWPiqMSTeP{mq$^DQ17)62@d%W%+ zzPKn;>G(`82vp&W7&tW}Ux|m~5ByHiP7v--kzUC+aBD^v#Wal-e#o-)$$baxTZ1oJ z-pKUT((1}R6IV|5cHJoCSUn%~tQ`3hDR!~F+WD9G92DshXvwp8I<@oVMK9|2$c}{9 z*{Gy`C^@f@Sz=t{iL0nG{L)gU#33e+YLL|FWsUwqjoRxp4xzocX%(|G4v9yeBO!ba_G#1_C8Ii2;9b;n+8zPO$w zJHJa{QE3CGxGOmTr`Q&=SM)}L13e1Yq!MyT9Ez4nmtE$&df}_$9tZCNBUjd-qB#F0r=t~Q@Vt(arX#>b?_;n&fT^-&a*px!PlpJj~qrJb%6onl0wssv?O zLEK53m*1B!MW-x*akbcbqb^T{H?=?(t#9L1%;ZY4GU;X~7ks@zfty|?w2TxRY~W<8fKojfalJ@h_?Nx$m+F@_i>b3IG(@i=&n~D)e7QQSD)IVhAdJwZz)VpM3D^M_`vGqpsOY77H2 z9UG3*Jx`{}>L8_S-eL3J#;!_OG?mUt_|Cxk%qF21syaKugU(RPII+4{fTP5!(qNK< zph{scSRsFRzSYvpY4Us5?blCcob@_2GAfDstj?wj zJp`YFExTvx#>=`VUTVb(xYpX773+K{msw14Up$}VVTr98&AHs3xhYd4Z@Hvn9QI-Q z(O|#i1>jy4bVN2EDX&=mFOfHfvj`OYjZKs!!&6E+s9bUD%sLm=_0mlxs`?`MyW-VT)fTt+l!M*=S;? zxD@kAr~C&rc3eKD(<)fpF1b-}%h;<3(Paov9hGIc{qaHi*x*%83accYms$fd~q?_$kvG&0e0e3s5I(ybcU5mWHR3>N(}*PvR}@Re^5z=S#U>mSCO< zbURKm(CuO~&#VP6E1Hc1gUTAYq*0OQsq~K#R?X*w3@p(j&R04aG!^ZyYqLMlS7L}( zCJ29c3DcFogk^0fGlns0o7KT4#;P!mQ^QyP9llgmL8zvJx;{eGXS5u%@2HVR*N3RQ zEhBU%sZhLu;Jg+hdQ(kzFl?bjCY_G3MCOV>mN%GnQ5w^sB@Dyie(5e(yJGuuOwf;= z9KAAN?v)a()J%e3kG$_TTeFgtUEx=YHoIRqlt)!QlJ$HQyr}RoG`%a%t~qr3MX2$4 zxcTBJ8P;=?lqjuJPgNOT1BG4ZIld?~>S}{?R)`YTFEQ#CJY;+=Q?+nTR)#J07V5WH z#n_7^`lJo_$R>5rS{nT*gJ)LhsWc2}Y9B@A@4e`L^xQnpW}~z_b9`VfBgSAuBoDMB zMhP76TO_mDL}6#LXHc0u`)B6z-?{TcBI;M}oExfu`)_hL$g#KZVKr`BavgGBpmg#fcMfoVM?a6` zZoGi;?9nyUj03PJJ-R;pLf}5Ax$xnMet>%i%pec{&I^4W;C*>?4SgQqw{dh0ecn;s zadKX0(P>_Q3O@QfRDK5-9vogD5|+U8p(plvj|w0H*U;x3)kp-cq4*BV6drsY`no z|IXbX_V8KJ0XrV-2kN_HbbuU;y%@OKa<#hiVoVd96W#z_5n2yZ95KLpnwrO=+AqW=M=hwF?+_Iv1&1Rb#b!113vlYecy)5Grcp5Wo?gT^LeWdk@sAL?`2Z?H+RNwbOS9L&mpPOctL z3XTICUSNivfCC(zxgh`PQ%7#v{B!piaAtc`wcIMC@Saj-m} zvE{(rfW#PxBPZ|xM{6Li2n8ZQhh@u?|s7`b5u z2kltk)HWv&p-->@Zt?7gy8G+)26j%?xBvGh@2@R)x?_Ji_zmN*0|8b~z=`z}bU?HO zR+v9ui2nuMS>nV|+W}@mz^MBN96Jy-cwvbD{{rqWgb5G;^1%J+xa~j(x&savhTW+d zd-y^K>#&1{*n@HooWPsp2|8f!ot+nkHvq`*apITVdf0{?2snGf15}MY0e7H);D90i zgV;}@`wMXb1e`;G0M)Kf-~skyTt9oa{nt5rdbK-Cq&V(bpkx5}(ERM^wfLZp2Ve^J z=X3Tny0b)zqbUn`{c{4V=5fmbiWYXBzcOQgQEU9+sN)1|;@APT)p0^`tO$ZRp*R&N z4pTB1XY2_&XhLy>0(WMbEK?iGE!SP$$ z9dTPQPuin!0fwd(C+J{ID}L|TBf{;h;GlWM2{>5uiqq)MKtG*yEHtk;K?iGIaT?tj z(u!kr(7fUV9ISc8X>eyqD^9>c(~4tsFsBu#(VZz&9LWV7IDrRiUU4c`9C7h5FDXZ_0U&5%aRLw4#Nrfb3;}p@m^rB9i2+S5 zj?uxITAa#ffiwR9U^`HsA8tSW2c7)khSPDI|G6srEa%K2hlMMTzx!B-%>|?(|5b>6 z<3`xfD_qyHo5@YRa`@vYaG}8#z80WPnQZm>e)+XevtM`h(U zf^Jqa%?yh^L&T!4E!t+}__3-M_JUE(H$ydtOlZU?C$Zh?=GeqWH~-qom95?0$*CM~ zkrzarGdA|yv)}FG(bXn$T7$<%@M7Ne-FJ$-U3zg|WMqG1yL*Ri{wv$fe52dfi0&%w zIAqU0a_ZJ|p=lM3D9>NZkNaBvUi~VO(9JQUlsj|1U#ET`SDL9OS{mIgP&ItCKRGo! zl}{>(H<|rIg5v>i;X84)-kb^*zw*cO8IlS9DfDff`04My&CJNJXJ6eC2&2qziLmG* z)7sgvslLf%U-7!ZJG!-t(@GsKM5v=~mo`zbh2LAeD@-QSykY5KO|TZOy}tJ3)86IU z>BPJK95c9mvDw5_+J@m_ErEE9R&OJyaQ))wn`z9kM+xZdU>Irl`hjayocnH)?n z@uA2M-eKp<)WZ}lJ!$2Sa+S<@%{g6l0YvXCifSG?nPB%=92fiVy!Z(Gd47HGIq@k|$weM%HGSpS)J8TtS@a!+a$=^Gz}tLF$k17>Tpj%O2XXPqk!YVZ3=wKJ+3THWh0N z3X`oIayC{ur6Nn7bhZn8h_KM(gouj;56W}n+RXdzDy<+GhdT0l5!_Q2(2Ox$h>$U| zm-aJ>`_@BRzSq$CS}Xf9WATF!b3FeEHTvXqk`=xeOlE2o#nXsFX2|{2c-Y#=0wVU6C_KqA8v$2r8C6l0|sgM9R?u_Z3X6Y1`VwC zV7LN?RcvO12AXY&2twm~x99LLK>RCceOJ$2L*72`pdj>SX?DwHRE~~mB>EEBB@Taa za1NR+yk5iJlba*(xj+}BA9Vpqn0pL{y=a2AZkR>BfTC5>x9hH9y-aZHkFU47iLWx6 z+eWwh;721nbVnF-*nv>4`irk#e{Jf_1OL$5USB;n*fSMDFEn*|6_jGH>duFzJ{6s4 zL}SyX*oQ3mqHi%-kg8ANb*>k;Bk9t)*b7of9I2X-qQ+AxG!?GZxoh7yOf?nWt)nn; zp+Nk_o?6Hxx1v2AdUf#6>%$`XP{GUO zgt}tOwn7NIdM|9hr1kAA%{~s=bBpHOxQ77x+=V-p32y3t-`*3YmgewEy3heWRG9y9 zVmIdU&;p-okz05gp&qY9acpm0Ymi%y>Cw=%8W5?u-Mdlu(kqeNF%Aex7|@%j>UqGl??>ziT1@1RhI zCV=mT8Nnk`d$=K8r6d1z-z<@}hl|HeR!a@1*RUbIbxHX)=J=|1_|XT)5vV<^fe(^= z;u)SAC6!)5Fal<=2Xq!Ehu%&J(q-7vfVk{GiV!ULL!n9m5NSCe&`>HbGQqO+HH`-a;2hB8&;{dZ~*r ztS-X$O)w5_?-$QcZOp{lT4jAh`?TlO$c!hgz+gCPE@s(BC>qaGaX-@%o=uvk(j}nG z@q!RzJE-62hac)e8+usIgDV7u5~sLhCgfitII;~Ibs2_Cv}Nh_f*^+3bgIR0k<>(b zz?z45A##e~PWr5({Ah}ueBQ(Ao6{;I)iDFinfX?n@Rj%rGXw=vHsUO?l>{L}r1|(Z znda~;(p;5}0cE*F%N z@Mk^e7Z_=Qzm}0JejXW^MA}BGF~UWaAi<>O*-kFP4w4}U%OO>DPY1RU?q0)?N;CNr>qK5HMDA_1(-Zl`nQ9!RJfj?Iyu|Q<1JoEB3O`Lw%I_gOyF+n4v!8M zF>e-aGYDx2$1BmA6gBYIk%iX_jR4lF&nXeNZU@Dv#O|k#2?4jh0HEXoP}C7B+sqbu zZ`5bWOh7K?!~3PBe-C`L?enpYxE+qAS;BFJ;9jQ$Fl7T&qhFV0D3-lyP6=Afg zuS3EO-wZg--ywm-VnTIo{-vu+Z^Av|bH&ueVTyBQQ< z*R~FvU#7g<0Q~exn!JN#8b4H3lOXnW1gr%dY0=NfarO8lsM8Jn-mR!$yE7>;5|oKZH)4x?Nl$USpdzf@ zG~GJ8{a898Qus?crA(7gxT@|phcKgnZlmnEIyI>*f>4vksz_{1xJm1FPNi0f4tM=q zBf=q4hx;_3YGTDY^|5ktG6F(I(quyql;zQ1=l;&Wa)J=za@@*N{BA5a(%$Q-OH$L zL8&to_?RiMnqZ^Dm-)R7XSpO+A0|_2N}iR*e`n+UPz=S#_sRm>U`!yI@Aw)&W3zSb zxT@CrEh-OZO-I)v+b+OIk5O;Z0L^N}2D_PBfi+sLkQ`sq&OgdO#duOAMMtT(%Rr~n z9La;AGmD%5T^U&CvAH9HkH!URH#_ee50+T3_lCz5;L5W4)l+7zYYb}#XSNF#+pKA5 zGy5fC`?i26@eJ6IuDLYU2@)3eyscKU0{BZs88vJV&=6S5q;wo zNQ$Y}f(Tvo#{6kDvmY*VNve2zq-e&-7Jxl(en_^QM7Mu9zFY?rPiqJH0eV#UbnTZ-V;L(06(x_${5hEejgUf_t=j& zkRXJw$~N5&3Ad9IjmxF!e z&FQ_*Uu>OIqLA^l`ZTV8S&xIj^CdlzsEnjiAo;Wr;skeacS)tCn3@c!Ht-^-hD*uz z)^*AOHHB5i?;j3aq86Zk*AXY|Cemfl94UCPqZTZ8QTQ}=~1{FOpY>iq1=CCVq2 z<@K+q@-BB5%2kE|F`aUfI*%ai6SY8gJwK|LJu|;AMFTajFZuK{q<5W)pS!_wk8e3H z5`4dZE%mQb2E4f@Ih6nl~-vlvnZuKWU>yls0S zh?`p!EY%HHKakTm_)H*P$eRfzCr#)WZ$z9W3EmtlHYSQCy!%#-FGusSED4@;M_X{9 zyXVAIeBQtPl;VT^iq!bY3q#0`^9hH1GvCpH$G^;S( zP8>+p#8CwvAd4r$AehoyT~++8K+#VTwVsrXj4DOg3N5X2nWb;p5sMAq2PJvJ;GG<* z4R-M}UAK?b{4Q&rG7*=fankB!n|z8@<;)oL7%6cZq|aR!KA**_qEe}PnS}{A&Fh8d zlLUEmnH6p9gZ5_1dm5gEn}GDW1VNfSc+*Px1;MKFV|65!=eS8;V%*_-I&SujqU{DD zJ>UE8CqPe*Wj4kOa9t1$MS$p9;vA0-S($tmv-ep*zD^m46p1@B~9(gE7|TN_n1Di#ai2^ z^?^J>G#GQxG5D^~LXWob_Mio-Vpe@0SFMncT3J1<7afSBNTTnLOPXA`U~2EZ)HU+8 zqDKB})~3cxAgj}i7IUaxs(97}@6{~+Po<{akHdBwg_QXu(nt$zy=a}NuqgyOq}V;D zSDgB3y4o#kyR>_zDo7~AG5x7CiIscSdDCV%n=62)bUtLt6J`@q&nB&~w>M(~Q)tB3oq* zKbqKg`XR%`oI>4(mPJ7IQ6>g-j#8G0TT|Q_BE}b+W~n+W$<7@_M(Gx*nC5#4UC8zh zDgoE6xs|y^sN>r&k6(TkXoBEm;sMm=FyUyRIcIWd_*oGJ&)@(_TV>HbhC_@WAznX`DE$m|>qi1!`7Ksi51f8xF#-_GcBd2U~h18o~durQ?2J--U@WjNl?gjy~BvCPJ-7oQo5{>)sv{4l+(?MJ4~Z z4NW7$x!21;L|DHQ&V>E0)$4gXZ^^a6HZy)Ly{L4&@=V^s`y`hevp8==^rc3p+}}%7 zj(yb6{mnvUHwYh%jdWZYJl@H_m-n`MM_j!lVX{!owrZ`QKcsL;1FqdggIkL%h$7p? zj(m{BXCb)3W%#*%)_C*MTFq4#y)j(I3RjmO^N&Vh_oAwMRQw6?aFu2VJ+8zmn|_+>d?D z3&so^BoP4#VC*FSSl76?$J8D)cZ0%+Vkeh!XzJ@g!H$uOSO%MsSx}Xg{`XX{2SwPL z)rej&@weR{@N}*2BBvDA5b$Y^|F?1;M-0<13Tp^pg9!+J|ErbM92A1S9H z-~&<>P!b>2O$2@(P;tQZQE5fsCsdhySmN;D_eV-+$YFiHgKMZV8IY13-3NUh2UMAS zSm6Tr9JB-n)iNK$Yx2E6$I`)-fachr6Z6;#wXs2r#7mM}^4)hOlzMBAY(7 zA9*<9&x($nla=EqJvjT1kpuFxs@>*_S zhmC{hue9A6w!x2AJ1#&_2m+SuR6y|G7xM3 zTp@ZI-Cqb4T!2kE&rh=M0|Rgl2n;>@yCey6_}X{Iwga^Kz>%?^x|aO_Eex~bbld%f zNWsZ-aLDW*;q+l8Y*-FXooc&Zs?Wg~$2hqFk;u4l@Md1W$Z}T2__aC1oJdk&RV3@L}G>%6}&Kc3M z1CDlph29A|K;Fd*f}vwUpx=dhznJy^>9{*;JHR^;uu=S{V}Yd)Knp|1f;dm1J4m?B z)^;2`?0{S1KRpY?e*i5EN2gAmb$}eEsb@sT1!e`Z;Ny!H7TY zSZE;Q;5ax^^AkKy04?}Gxs3jLcMdnz3MBz|ixjVFw1RHn}-q=vUCGx4U1e zhWzQUgQDZ+WaR{g@A0Gn17{1^IbrD6(`)e|Q3UI-gQDXEs=NI2ZU+WV7I1RHkZ1o3 zxU=LGP;dZY0wDUQ={OEb(ZJHNzn>C;{NjQ7ryUEOv0#8P;r{7ZJP^|WxG>NFrzgc( z0tFP^fh?K*Cw>PE94z4eEBwwO{|M`_J4OdkCY(PlCI<8r&J;#0fYk znSBBdRx3~}Q4pyM%{eF6_wHv9DPm9yAI9e3?9oqY@sRyzAsN^!W03S*!+ z0SBeCPr$)SXP*kPhkLtcMF-`xPtd{2XP<7nzYr>p>Fg79u+rJ5IEur4@UylZl+Hdu z2P>U@Y8&Nncm9m%j_K?Zbg=Sgb(%GkH z#Tjyn6Le5I`vl!zqq7fHA7>qRP(J$v9jtuzDYE@6hEXSN2j#O*(80=QpGJ3vjf!J* z$9(oNI+*$F)9B8yr+tDB%4eUT0}?fu`0Uf@&J-(-UZFUS`0NvKF!R}`*1JQE(-~*Q zF`s<`4^}?=blaUNuYk54l+Qjv2P>a_dY9)co>9lIpHM>k1Rbn|_P?MzQ?NK{ykkoH z7#{4D_NgthL-icYBM%A>%4wg#`+J=Bp{Vby@Qz6B6Lf!%)IOVU6twZ6to8}KzsG9- z4dbX|R{I1VtgQB_x2UrjM*-XG0P%dxYM-EkmDN7=7Iik?C@4B8t9^_PW>)(&y1zg} z9kbde=wM~FPoq0iynwbHl+`{#2P><68r@&WEsk036Lc`L+NZ&tDOy0A4oYjEfP~l1It-7I%YK9={#0>5xTS@PDbgEy+~#T)<>D2yF16>oAQRs^K{fAjqdc5KOy6O z_eGeon;ze0`I`gIMWOo9i*#+If?oB{XSTK%Cdf2&F<0p|4A>tq)Z}SWLx|fFeh5z7 zYmj`-9Q0+psom#x{rV$3#fnabsFi}>dAm?r~Bx)Qb&LhhVMZrH3byaC zWYDvB#2S1ME6%D{ZMDy%Y+fy&e}W?rY0by*>;VxC(-M_SwWW?1+K`r~`JS$e3(Z{r4BV28`=JVzX zV6nxGg{aSc*q3Y^x$myDuKM^hV;tB$cq}s}^ojDYnbb$jES9zF&<#ac$c58k;n zloCgP=6XwPf0?d`5p82S4>#_u{Qj*y9_$-;(s;Q0?R{)6fm>`8-oA~E?hg%T4~nfEmXv=R`WK zz!4{l8MNJ0>Wd961|hjBrgd5$ePZG<0>9FZdS;V9pb1YDzSKz@ejiO|jU=Tflvzeg zfi|2gi>AkwKN(D5O^b-+C?-P492)JgcAH*SjcZLxc<~k2zRpnnUR_TL)D-PFv2FtGe7$^4mdqa(VJQW?1HUekqaJ zHW4_=6+~l~t5LPj^_V=IxeEumD^)%^9fuOn}K!93P%__Yr9azxEAm7>pgobQd0=AcG^VghA2+O}6xENpSJ!gXmJXd{dpC+ZzPzn?)X z)Ueydi1lIRi{aq|zy$=^(i_{v_s2xfMDNsJe^B&teqRn*R0!!o&mLi*xQ!<&q4x^a zl%tLvi%_AQh>|LSG0-!S!naq8-?okFMA>X5r+!*H-K0}L+4i=Xjt zgI*)g$h8cYS9A1@In+;Jds|agQW0g;Qa1ZitB_xzon8`gye;bJYD6^*bZfKv8c7n( z`RG@^;krEzwCb-y0=#QVP~@F1*DE2^UICecHK}=`r|H<4Ylm5zuDjm%yj@>08~q_q zWHCKHQS4HuIbG$T{(FkzF!n?|yJoF0y+Ji=_+qLu$RZXGznGcwbwXXZ+XM&RG?9h$ z>e&+V!47-Ps`~3Pv^DdzpKFck5=6gQg-C*FzpC{db z($Zauw4fj@NOw0#cQ;bfA>G~GN_R<0cSuTp8;|;)qulS_SI>XjE$g?RJu`dO%rk2} zi`*mrIeGier^c;oe>ZoGdu=_MVfE<{oc6((iK6H)i^M+HnLZ%sCEex}RPul|$^W2) z)}P*+uGUF7{fbl_LuLv;S_mp|xkD#CJiT*kQ^RuTwN~mji9<7zM|{VFnvJCPQk<%3 zOJ#eFYw~99B7qcVT{;L~0F1p#-)p}Fk9H}K-52BOy;SoHDCDw?)q>_vm!n!9)Ev-w zh$;swttFz)N>^)Y_yHNKSmhLC_Q8`Yv))bIa*_?T5%X542kN%1N#M$B9AaZ1u!|Yj zBZM5Ym#jVvbn8lXbTco>DGriCPy`B^dlaHmpjf0z>)juru&C$R()SIA`jVf;Cr!uE z#!i-2DkSs>16==wn{ZZ?-v}k7(&pZrcViEY&d%Q4-X1|FX2C(>8wLTlElEE;Fg%Pd zc&M6hzi{{ydPFQzJi1Z7cFlNpeA(*W*npD3jn%4G0v7Px! zX8)Em39nDOB_gIdZUyO`CXZ_Lhq`&Kur?sR=4CVZiKJ%_r4qce z8-1mEh?6RxYgw84fu@Swx2(Pu?#&7WWAuvOWDCvx7L()^2zKBfN=4SdjF=Gt%!pxP z6x*yKT%y(K+S+W`flRRk{ZFu_2zWv$2atG8C5jPbBrlZRLTNm36mTFEWXa27*av$DKq0z ze=uW+!9by2=?p|K2bVJKo6kjf3H(zhP^V6=uX}0%jwdFXmx#39-I=9AnW)t*{p29us`)ww#g+ zoVcJNcIGOph)GMdpx6tlgf8Nahv^^zKnA_0-}w6;>b^XOjNt@|H-v`AAl z^e|Hwa@(gcZ!A}%LV~rP$ z`Pet>TloH3*&11qumNUGT<}>D&~{PuMc#qH9hM6I3g4uwg~odFFcKD z;9trb6eJb!1O{HImk{SHTClh7ah)q@c`K*ORm6gJ^b_Q)o~aD8gR<6*vXhO|kIh!p z$%!%s+suAE%7U->>72MC1mNUEKuI6ya|R<7>`oADFDbeoqjc}p`HMXFo`o`CKG&(^ zv_E|xi#MFh50`?@*JI$VKUIb6;zr%pcjhu)qo9+f40<};H<0EpvgI@Dlg)UA*)1Jj z<(|+5I*T-XP%BlQZyGax)$!WGadiaF{dg!~e^!vRBDcn*U5#+hvOUF<|3hEiPK~xy zfEwE|cv0p1bS9#r8_LA270+dr`ur}cQmPzSRmY7+ZezpD3zHNE+!yN2es2&ngpyXS z*RohKL<3>3oScF`rY|8Bo_l-5s%xVqi1!ettE@=mP-@k$nxE*ryJGcQkrX~ryJzRo zVUMv=0)s;13;4KuFB^p_sTGe$AXpL)e6CHe?I9v&tgB}>=cmj~c}%1828!;LU5PiD zSvT0TC13mL)X$9uW4bobzmynvy3$0fEix$>y3j3iQF}~J)4z23nUFPdPmdBhs!-Z( z?C|{R;I+m1#DzoEq=x{M9MSNn-5zC3zYjjs^joJBdSwkxs`)lO(R=;68aA%8)gB)A z>ElXxE_Zr9Zv;+NRXM3XX=noN#4|K*_o2R5$J+FS{$*frVY@zr_)9+F7?KThR#)l> zaDM-;Xy13b^Hqfo(bR|2cB8mGvw5?lL&Ht;<4XG`TdsQ}PM2Ia^~EWNa^O~`E)6uo z%KRS?$T>bv7B%)KV@!V-;ZPv2x2;rJ;$>3_Zo}Ul;s81>*fUiJ7dmtN>Y>J!?jVbd zHXhKZS_QA0N$I^)Tj}bQpwW^gp&fh&=?6tT+Iuv@4i^1g;=SqBkD1Y9RatoZJfCwq z#YInL`-I*rYg=i=+Z|tp8IA4|HIROp3g+EbyU(U;C6oDizK2%%AZTUtY6rOyUa1zU zrhsqcab%G6)q{{y5b-9M?b1V<@cRNt#w*~(+2zo)b}MPpmn0e22I zFlK(KdD0&|l-Z$1c&RvEajZ5@81r_=;NUW1?%u?8BAMZ(`|MIH_*CO{e28!1NzoRC zE#m$Lu5$d2``YnMqwBbajqj14foajv^sJNCQ~Y9EV_(>!Kum67JEz2=>*@U?2rU|X z7SF~RUPl$PMkRAAy5Xef;UkZsGb3WxR5C6yWu~lc@Exn26wMS9Ue~YoR3ySt^3D@0 z?BL!{wYf1zJhtA$$3b$>_JKl3P80xNmdT@%R)w1|_ECJLK3;_gt$g${2WmJvSDIHnR*kH0?Du?)9?e_I^excf%~JiP`F$EcYeunVvC?Mg?im zkSOw^&O(e|Npq>2yfBrjF}<0n`;2gv*yF`07<+8bl5p;7xANpnrhq*o@3RHV2qul^ zXP=$%J{i-sywjQ;33{$vBgchd(cCAznZlnbrU%53lgB;ZiELbjjaIF;s*Kg`W~6NHD;J+~SWxIKOS`Zr&nd;2%Hz`x$PrDMNd+)|%kFTVdWkQDaU9j3pE9WpZf zB@zOdf7KYd{o}7%wO=p3|ME8-5a7SQ|ME8_5a7=DU;d^A!pQJV3Dv8w9xX9rHJJ z5a7;t%-{4u7#Y3^ga8-cF@KW?0q%Uq{7obTxbq$JH<=LN&Ueh;ghKu*n#7pdoOgY6ID0l~qnf6M4&2jVjr|CNkBU{v1@)IWpA1|%FZ z{4F>AHaeK?cXHEzNjL=H{Xqc9x6Zv4yI}iU5)K;>p~3W9NjN{}Ljv&rAcEvOJRn5l z@5!WWK!EV?C6oRfqXEFX{kVR&bH63JumMSj?0>8N#0CUuF#kq2>CXp80J__`*#|i{#u(A9`68O)7uE5Z{by0sf z^jKMdNH1W1`T-B9hr-108wZ1T!25&n^dGGUgct%f`TheBsA|N{{u^nVzkV8D7dOA# zdVeJ{v3{$F@}u#-Rz&%YY2}wRaA3{!=RSi4$e9OHg#XicKur{&5cGdPuiORi&wU09 z(1^EnxWBg^3kNHZ-uExH-k)|Wrvu>r^Yzf%hGuGae#r|}IQ3p1c} z@t*`g7FGrzx9&GmH-Aao0LI>*c#UuHfI8o-fOOrD)&p{MfTR517<)e_G=1A({O*_g zZ9%{S6y{?Db{IeK0fqT~Ck642dF5Yl8n=b{{`1{31Bz2j|3*>cZ#%I+Y&vG3pchc& z>qpbw7W(F3`wfrwb7&d>?_Y2k%(oT2fNkaXo@EBIbXb`Fg}hu~lldpxjBf*v8K~*S z3}_$zfcG^`=U-{PKhj?N>$7DBJlL&bJ;nm2*cemt9;$z|LNFc07SU}Uf~Bm zAj6dLcZ64d9eZDShd+eJ1n4C){7plQ2@swFHkSYWtak^zKX4h}!~DN91m7dnew!iq zb+PxAqxsF&`vDK=Tn=C@`U4)&xh((ATJ$S(^oQ`+fb|I*Fze_$M0jgq*jKAS%XV9}4M=PJ(Ri$Ez(n&KU&bBq{=jMc zfOi{63M_kmzyoG!4yNCjm4AizCn9X$(R*zaztOk9jqk6}T-MucdLUorJ3dxG=Y*N#H@f%N z#pqX3`A^{iLMK3&>ko85MEJiV>-3H3{%v&MI`=jy5s1tG0q-^`k>huE8b4?M1Ni=6 zr}6#UWd+g_nE~GZ2R~-Tz1p9MvHgGt@ZSIVG63QXke>Vvukmx>HPCi{ zu+jJqj^%d20?^9e+wL~C7?`U6`?kAd-uoB41`FWSH~|LZ2Ry*3vHlK&aYxtw3toc- zaBA$pYWW8|)>|I;H#+xMX7o=4*?x2`;MCXve) z9*v#--|5_cVW+_iod4YJ=6}EgTpDn!@!!uYceLIgxs1PD8Z+S1H~k9eS_A59n7%eP{(E=;=RXdR?=}SXFF?$}&z6AH+TS^=J57P3P&Ob!;||lm&+>Pg z0%@Pj0LlBaDGQ*r{r_(xM&LM`1sFg-TLO6hS5tslW&;8)el`6XT=RXg`#)rq0h^Rt zdHk>aB@Aqr8NY?C&QMs**~kPiq?P!=F zpePCPCS8>dSBlT)Li{&4CFN-Rr)i|cOBHv%9LM{M?MrD7;qSmbt>z_)6(Mz_Cj=p* zhq#Qu^sn|4$0L1LGr6ti7YLp0e8F$Ig%da7c_MF1f4vpVgem$)@KeWZe*-~RGo`&n z)z!o^e_oZs3?$9tn#M>Qxhu6w1Nw<>zbME4fbzadS*gbr_Ht~|H;oq?{O<>!qVQ#X zAP-mgvUpyI>ea!b;iY+bvZ!{0fvJRanuYlQ2G#KZUI+ODY0YHQAckG6S8^a`75#PA zQktBdyBTR&8Y@!*qWnjfYUxcP_f^pI;auKr_0M1pQyCu-5HKa6RXjT#duN=Zyt7`FgLv#SZExqA zMX_GA>XRifU5khxoto0h%jsFQK}^4aDcgFL?nq}prrbTozPlmqL4XL!oV$>5&Iv8| z0=i6;j|`!pBrAVT?wE&G)FnGR@8SV?qhqF$Xgn0B%jlhT_0zbf= zRg@X|i;jciR3-4Uetg`B4S92Pyn8rNx73&(0ETb`F5I)F2I-%uc4ahRB=s;SoEMiB zW#_6V)U2t|$?-8V-3t#pni)aVB;DZ+eZ5!s?H_}<8XT=h97z))xjJ|mix|rv?*zQng_~Df;+a@V>lpQmJ_3g)o|Fl;%5; z9$$g;W(j-Irh(8et6>4A_ZKgw4Xr>-jjH5kj78oFbL%EYnLI;ELzyyBv@>|ldOE*e z1&-px`|jYhrhl4^8nn$i`=z`<_}UC8-=bsy+|H8DjiGAo?3C^7%cl>jv(Quzg4pD0 zlBSNt<57&UdHpe({kpvvJIzczFK(#va<=8LQj&s{ObcD&caThm1%?n|>7{6Nrw8|5 zf0117OA}~|;q}LfYa2mzyUEpE-{M|kAK|)qua6am+nL98C84@(;7=n^~@Y ze9lPU;&hf(3)aU+;e6p*+D8&yG#pL_&L;0$X=E1>t#a=Xai^}%#5tQl`O*E?Z?C#( z=J0ioug(3nh}{LE@=bZ?t~audsC4`f4w~o%Vv@MhP9*c^)^?UaAt2+)<&{rMa+8@^ zV(&jr9zf5FCD=UKH(#G}$vFw}b$!GV>=^gVF@EecUm4_d+GB@V%;kK`f(&Pe>99hA z<4V;`;Q;=m!tvSj6NAQU#VpQl%VBL8*y#b9_@E@+acy&E#PzKmv~X|8CkB&4YV4Tp zhEhbZo2;Jh?_{6MJJp{b9qtG+p|&cmg#{_lKG#hp8q(@2eA0Mr{rd1=r(N5RLvmCq}T@GUNJ2Kk10R5H;Z6|NTwQ@ePKp_?J zQ%60x@{Gm>+vJ*p-iqaGzE5k1$t8M@V7BuJ%bL{P&{fzuc z<;bI=W49^oJnTta{+vRA$iS;$1}XQ*r3xDqLiJahXRU%zHbeIp!AlfR>od=gK%c`< z#x7$KbaE?ExI@xlpP9h1p>L0OZS(5KDD0(NAD-KEKi3pxf~08#=cR7F9Dh0R~A2>}@}`JxFPOo7oxC&hcbZp&yC+0?&~-V&|lSngTKOvFXK*p}H~ z79Nya&Y{7w`oW1*qPC7kUr?zw7IfIr$MZ7-;a4~hFeDbhxmQk*8EzC;UGw8llv)xI zntQzCv++#1K5s^bUTPB-@Sqz6B2tC=UUEwNNG()u4LyXyqVC!x>_gvNi@fq>ARNzA zEWZJdNR>nxuZP-!C%Z7e`ZRVNy@BBy&F@Gs z6f;q(k8Cb^AX1*UH9djaVvOR|P1hfq6>H5gH^T)Z#I(7u>sx5D96XAwinX7736`8F zp`h8!#1lCDs7NS-YQInx<;wqyY)bef=^ApdJ#8S=D(Se54Ns^OqxHlx(%bb=~df`GcRp7aoBHEErFH*-Wkqqjh$^Ay|4?`F7ue~qi{1$hnZ zpa&BsR}h$A*cvA3NItY+gcSuXuNoLm<;}P%!eGg+YZE%|UcuuY0%d?BlR_Nz98r!Ew4W&R@q3WRMIE3% zNS|M2=n8Wn_X#e%O3;(DQ|(E0$1Ko%jI!e;fX<1h(Kmrz-~uL~vD$*PyqRLkRvQ7H zS{M3&G(T zh2c30AS5hjW;t+B`0|BkrFdjt^~8eW7Fj0XTR*5F&e)tsG>9lVL|HBP&;n68y6LQu zf;G+Tba+jGL0%o%v}UkHgC$wgW5jt6x`}Rn^R2XTa|yOy7A54Cw5Q|4g8(lN?wGT- zg0mQz!ne+oTt$coaw!6d(f4DpMqd^c%Gi=aBZw>2iS>X#c7Spk9x$ubg0JYdRSg1< zwZ~GiB9#cs;K6@{(a+Tr!f#XFV8p;fhqfnonBj4k8cDPD%hdCUTGmW?rQWXKx7ce_`MOlfPx`oQ4{0;3 z;EM}C*wB_y4}YFm;<1sFlI-+Dc}YZ2kiPh)FW7&PbxGo0vDe%Zz4~Kpg<}wVVvoK4 z*dA}D#v`-B`8LvW7uhXt-%^VTgo^dZ!uuGk=holq!9=GoXcrGfcX_h0pxX`KZm zHgEAH;J=a9-V)V%8ppmQukpHeq#4hqD`psQet}Cq;*c%ossv*mtLorH?ZMn4@3jp$ zU7&V84N#$?d)Q`Z#6=sAy6N_de9_g*n7g_BoLrT)I1QRc7-|-s{`p`>5|}RQqS^O~ ziZU@J7eQuP%039^zZEKbP)v^PZ{zs*I0bUmx3%NT0ZYWSFi$iHCf#t_werlnu`XlH zbf+`UC&>>>`Sh1xS+CmDJ{0d@f;mo(dtn`^r8V#%eyxHMS3%KSbFl_CQE*2i#))Fr zFT$L04RqL(eAM3OeLaS67GwbJ(>Cs?!{&sdT`K~F0w&9&cMGk`@(-fb29np`d~`oR zN?AK3LL$zi>smCWt3Begb=P0+zHbU~`~^-g-nYh=9C!KQ2juiXJlTl7+Fox7&1F0m z*^K*$F;%vpo!G%LBKau2l{9)d&@5IW+wrpmH)q$YOUG2C1PtdEq^jZFBnJxRwi9Zm zySgcpKJH^DkA@kGbT(*w<_<)-f^sR`C^QUwZ7f0_^`*BlLQV1_kWZ(T1T01vNKVln zeBqQULC9y&8;V=2$Y#|cTZp{2vcmC^Vo;rR#V_(3OEq>Yb`Oe}!cHV55o4)+>L0Pd zX4NhV%T8@23LDe@fremk31Po@;2BXC!CSW{Z78zrq06mSnqYHi#SfmE){)5B@xo_E z$WW%XFUSg85WGY_Ss*jxQL```qW>~vXX0eNz~m4QuA=RRjCc5k&eXb|t2VbwH{Fh0 zRxspv9RGNrJ&*=hEK~xsC#tTQu6Ogb9DjmcbKZ3Dy~+K_22e0H(LD=u7)Y2)g6@WU zI|4cKcI?bM8_Mw1!J)8yn*>F>ESC!qT`{8+od_zh{JN)B>>ig+iBO*hn}?NNT)^w= zx+lb!G_kAAHzk8)jJhM+Opd8RKU=M!jA)P4M+t?vxct03E67j)=B{9k*aG-yb(}@X z_EdLuLN%A_#zd>bHU--LkgV7vjz+!0W)1w)bv#2Y39ivIRzD8T_=gbpEmLL)>r7wN zV?_Cwl(5bxilf7>4J8UOtX9w{K(LMGewj+(i2oSWKLM|^#=kVMYQeucuv#GAXw{gB zI#B=QG4pH*xB0HbK#&9{-_Gt}MV57@CnmXAN;}8=Aijr?&A#ZpN9LBqi&jS;)ZBxh z*4B|%%Cg_S7+qT@EVJGUSv=?2w|g|aZJ}VcOoJcTR>VzC_!*=)Z@Tw%rBe_h21&HW zA^AGMH^c?z5R=MxzWq!rSOLHLvP!__;f4$ELe`@#`2KD|PUd>AGQblj9QV=b)?HX0 zei;?Y22Cbxf~g>lY=U8p-0q8(Ak5^wM*!7+t%n?BPkT>S@J+iV>0~~nI=o6;BBEX> zcS75ghHts~im3c6m=i>V*HXm2 z@J{pN(5T&0qlP}Do98#3GKy8QmhMltJtGtfXY`nMNE9F1)xOpfwys6C$|c*Cre*A8 zBI}9Rb5dgKQOrO0x~RmgcGB17k97WMN|4A`c0EFmTeB2%O!7)OdrgYhbE{i8X_({r zM!%)zH4WI*poWehp_%%pB&ADYNx@vNI66w}3Rah+gwvYr#!w%agdM_XA73eD3#z&6 z)J*j$=<;au*9H2Dy=S*N6Ht6%va`>jRiPIsJ`eZ8(v*kfC1J?J%bJK3H_OTU7Z{%0 z4yK%maHabns{-D7=7aX-AFQqJ;oc+-U`ls#{10v%)ARa_VfO zicHwz%E9*`=`#lzCFv9k-+Wi|K&E*t^QkRv`eq7YthUe)67pe$dI`q~8o2bBZ#wUA zEaf|x&yX&C;_TyD!rh|zsAAN*ZAJ@{LWDj7?x8A_4V3cNX5lOwCF&KVqC&6bMefln(&Xf0D`~CF|51%v>{n*VI)<+8gRSTaz zWZl^H&D*mI`!d*LGsh(@m?iLLQV%X?0)kEO9 zGmcyXFEn|SX#~MKN=mz?>_x{R|`X%M=uiD9Q^wK(3X0I)^bgY0(wZG~s z|F;FMd3cBb48Y^yfM57KBmI>J{Z^})Ug4D@5gd6%8U8{t|Ah8yz~mjIIPlD0sN$bZZ{0(u2(ynm?-+vVwpo{;0Fq{821*c?l*sy zZBBmF*KVL0K{;|_eQo~W#a_y>FKSnV%z6^k6}>LSK$H9lOJJ!&a{t@iwUVIx@T{_q zB2=;mui2vb{ko?6V#O$qT?6bL+2me|DK{vrn3SaWILy9%J(h6AcCj%^${>udq6Q-D{-GM4d_#hTm1#Kd(G5m8T7ou@yoIU=YhqeWv<-7A3#Cos|;@h(4k zjb7jxM6)<*7uxjk$Iwe_h5Q)N#!ur;W224BI;zF`Wf$RH&y!{=soqYb4@5$`=2xX- z$9@pWO;3xxz{@yW68i{?7?U3H<)Il)7H#$@?xk+Ny6L5z8oSswdSH4v8*jZ^7+=3m z$vc89%VjYc$bfo9^NH|AA`;X?X|B@M5`#c!Lo;5T<4lv<{FH|5xKdgR-XzF=IcxHo zCD_bfQTX!_X|e0qx)35&L=|j;AP=nr)tOWw^m{N}BZJv}OvKebB2Du46qiM)l;&-% zZ@kj$L3=Nnj>2tN4;Dwfv{Hwke`$ARIxe6&X+s{|R&re%tgf2IFY1OG5fh@_#?}fP zhd9XIOUh)|gyz%acvZ{&fI!jY2$WhQ4NEMPBcGK_tI9s)9V^h2M$h<%@CHAkGC)lt zzEi+m33>8j!bH>Iv6p)xrtouAe1y`y zhXJ)_vAtSEHYj1bPWIhz_Ps?h7`kfpbBl()n8dpA`aaC7ttBA{awsghyn=s|o`T46 z;e2HO+W9ajWkH;0Exb+ctkH?p*_X)rYL!T2!G3s(LuA_kiqE4?Dki!A#{PQqTxXBL z!=GK)C++HW4A3;1q9*T(NIrhKm^u!$jmDfm_3F`%bmB(`T1a2dQ_mvOy3@K-r3;+n z9m)FAp*gR`!{W$*1~+5 zkwhC6wuM^TDL3Xi<3Z(@AW&Nf2%-TtXm*I7+D+od>r4zF)+abQ^Gf**`8Y}oK3WQm zVYt{gZK1%`RClME!g3c&({IF&tWns!ZXRDN0`{y~;uqDLY=`Hc-et##&+T)#yqOk< zZK90%l&ZfPKRk8rcUkm&mw0TE-ss$;r!F4EN@o9p%tN?Qh0`Dz!3}B%jNeO|9xUu# zU=)1D^dbTNWC%5M-^~=;b}FDrgoiV8iS2;@dh-|Jh5-6nqc$A{#(?T6g26gJ)L#Brd3Z!6~nKlPIRpND2dE5+6 z!Z?QS9&?$szO z1x=Q3%JO0On)XODz6eE+!xDaIWWQhK)H2kIxA6~I*cOC)yNomD zAS1(y=$(~aIMgYcPu1v~x|P~L=p`b+1rN(0fYipeH>+HJx77!x%#ekT07X(#TSVYJ zhXt2*L{MLHOl+3O487B1!U`QDa8snw4K|K@$rF9wdYLXJjc!y|t`-ZX7rw%>e4SE7 z^T2dV(#K)#_1G%eeK93CIG5)L-j*-XhVZxP^MX+CD|tBkP@mb#^21AFO^c2Ojg)eU zuS4mj9C)$T)^AZKz_s2ZwTCznZRwU849W0yS|dztc^%*Vs^daarqZ5u4eI5CgiMEu zZZo4{hW9&EFzH-|3XxxC$zAmyC9MS=rid=(LsrM+4We<3alP@4ni4vbbj@aWJX34) z*(WyZ_+-kHY&JCTL?4|ue>5aZ9XyUNuX(m#sj)t`q0Z^RWn98mk@uA!4Y;lvNK3ns zEK|F|(R=;_7dzXl>mA8jX4VZ0QZ3b`@C-(;dQo``@O~;Ug@*(x#DLEj@4!T-8X5B} zy9ah+dtkoh@tAVn1c|b8Yq&#na3RFgoK35R7TtM+2*&H=%L)7x2)yJjgwh6!mvueu zJ`I8~!o9cD{UK$nkBX$C6hO(Dc5=15?c!r8-H~`66+V%C!(MD9hLd4oW5^_inny48 z3AMh6&lAZ!n$q0Y{pxeI!W^|e#6N`aoU=)eaMT$Af*onzTsu~>-biQv(l6% zaBH*-HCajAmjjf{(sZkVB?*mfs^k#*Kx#H#kq{#_q* zd^@M#iDgbC4G3XyBtDtQvsA6jd#bmG*j(Ns$w1({;ie0d>C6uIdG+zxZV`PE6kP_q z@kb84y?Zt+2RP{PW`)*<+yE0j{ls7aN@tkhDcve7oqR$oEHi!$9kgk;wl)ZF$ODW+ z9879fB$N*P5~wn|m@2U->{*W6iT=Hln`>Oat{*d(Al&H?wv*2(ir{!y6j=zjN#YtppbK#3wL8 z$qCnZLd{5PI;78_b!{M5javf#Oeq(sI`WjwsvMJD#lqAzqzNv7d!-p@8h>Pb#_8&EbhU4ov07-TE;`mS~VbAA?b&K1D*Xo!Aj;9ok(J zrRC5@I>!@Y1ICpSJcD{|X&(bP)IAZLj0>f!qwBYY_xHCz0;2}li;HY>Y8SX(N^F|c z%~eXgH1v&)eCmNuVLf3D#SvhO3Ul?v=b4j=J4aJziUj#5R(g$03_KiykVs1=WawgeF!+d&re+v@sFI+% zS<#yFgT>jEZKAh3ocN$U!tI|GF#MnxT?n-_Tr(9z3|mHyI=32|-57Xt3+c{|hu+yb zl(+_%^BO!e;&^mU`RuS>IBGTN(110&B5Mt&ey-oBx_4JqJ(vfT`IR=$7h#$YG>1{d z=8l#+)g!b`x;CCnzS?f0Y6G^>m?uEH-B7t0O{*rKWODkD@O-Z_ax`psV;#;uZq9GE+!BXs z3O{VP`<%#7T~|4%kWw&WH|!(h(dzB`1N9zxNpeXl7Mg> zGiz*`hI80#jVR-rd7T>)aAs{HGBZ0p_Kdd9W6<-EnJ#uZ9&Sou4nsQFuS2e#blEkP zPOgJC+Hz{_fwvP|-J0kmIU?qGX@Ns_a7JAYOoSoMRfiq}YDWt%(!<6+@w(#g`i*7t zA`uI+#l(0<_PE~1f|;x{w7wP_#x1<)R;k%~YhKM46hZ#XX77XVXry|51i@1YU@s#D zdj>Dcl%1WVq|G#T5NO<4^CW(VrxIHYO4A>OfJeG`E-$nr{Uc8^Y|0^soUQB|q$+cP zmGG(6%aKcrqDh9Zj0oqTc5t>N*Df+R#g|Ig$?js!GqQXB5cbqt==gZic{M9(mOX_7 zs-zq|j!z9#>EZU6R&3Lf5YH10&i&IWvala1&g^*1PXL=R@S=hW|8lmpG@w(>6BF~x zM4nG$N1%icXE|j^e0kq(G{KdiI#ENQksBG5;_`SWCDk!~D6S=*!D7A##>y~|o zZ>KGUH~VE-!CNolbq{>t;J*!5q?IgfIqu2+W;BU20uT z#U{Kt9pp$fXNj+K<5a-4}0*NKsZ}T}h>U+oL(>atdlQhckj$f)o*t z5{meiPTA~`)<#~IAalw$NrZ!aBz*&M$UqwG*!tA^K4a zUk2{tR*MgrcPAlwrq)5_FWyvF-|#F_C|P?iIKex~mp4+BhU)ZWTs%;d+{MY}q14fj zD&Ep$M^>O(x3GonT8?IhJ;;4tgzF0KMPfYN=uyGYZ|eNkBd=)4*{Jq#u?`U(q%N;? zM39|j`DLri*envq9-(dM^#Tq$?n%_-kaZP~en~`s%)ew`de$V5+;bKi6CJ7h2$JWSSr14g)qD0Nu<_PtIQ0vJiTe3u5$B zTG-<%+6_JhQ>PN!JHF4bYjk~M7%e_=2jK}+$o)?c<^Mo7|NYk*V}B<+ z|51+XE8FxH%l{?BmE#vW?G0Oi0STT`h^$%>8W3%%mG1;pWl`BtD@U?4)Lys-o{(A0$Hp-TLQ28_d$H8 zDZqK&mT$kq^cM#FC%k}Oz}Ld`zncDo0{ zR93PDNKcp3qQU9zH9_UYXXf(>?FNY>?NjXrRnsT#Z}sB~#A+Wz8DC%ZtAnTt!ac)H zNT-Z`SwJd37AMSE_hG>Q(0)ri^T^b-I)hmsKNSCT$+eUn5&Y{eBvU)z-Hx{3F zqe^h%4~r_Qi}6_MQ;3D6X{{19J#{u_1WmXFlkDzNUtK6W$(TBq7*nV&>BIaOe-d!! zary1BUkn1#srqeXS_`;&(f`xRwo}U<+ug2_QY^XePVq6I+7r0>IemuUr_q+Q!4Jsk&;HDUFx`}x* zw_5k{IS-oBV+@2K3??Z!5SN@}esc{RgD#1$_FtE?1xsU!@X z`}l*{d=*0m`4u^NwhWHX7vBdWv%ME>f32^m9NbpvQ{O@|S$S1SW8xPx(v4n{GUXw} zB#LCw9+jk}U7wv&%ln{sRs3-x1lNc(44#1iD=IJwL-^v=@&w3TRDBFp_ucHNE^| zKI*O*f~0*s*>FjoU4wCY#K$`h@u3^ER6r{VshdYf@WHc+m@NENDy-3ZC?v9KZ{*w@ zthq1XaoLFpPfn*Q&salhisXy(vPuR`+k`qjr^45(@vCu7( zmrK&CP}t}g9B&>zp4$WB>BKAEI6KZheZmJm3{RWLRkjMYU9s8|A#RX|Nhx5YXloR= zsdJ>Ilxq3>@Xc{~(=3M3v-zE#ietYV=1TW~-1*f;hb7W+*#**xi|LoumaP@+(hdO+ z^YjU3mw3E7n&{aX;Gc>SK;+oIcp}#H`5gJfSdBBk4qx1;=zDJOwPb%-J-8W+-L=D= zW4l&toW6nrC3~Vi3$`ck$e^c3azIFS9aJMvUjzo4MC^6vQ`Me(1q~o2najfYHgDyp zw-;>fWInvAr(haxrf>#v?6%d`tf>$bCS=(bZ*|%(?i`e_lqC0;U8E$qXLDNEd2wC% zx%p6fLRddA-UIQkWaH%x6jt^(3NjgldSF%HZx_u0rdVD@}y>s0NI-3>(SzHHsuCtpTx%Hl^t=15M7QdR;sAgC`t@Hxu+Q5!gr;()s7 zEv6wqg$lMp?O;mO8LZD=NU=!CSBS}x!u`@tB?Eqg!}W|88GMwra1GUsd_=^+s`b;0 zSi(5*EeOv?dNF*c>tW-^*NnEIKg_Z7lr8i5s1s3;fDK#dv8W5P z1Q{1FV@E&c7Qe3AQ_!TZu63*)wfXT4$mQFy{iuA@)2YvNEztT3H^x5+k;z#Ds4=ERBo}#SK^%D!)JoRTKq`C$vR+TdG(3YL=B`(k%l-t7=_b zgi*98eyj~*D2*!e^Wu>){tmcD-eyYms^hs7#&}r#YxHkTJhP|kPUWAd&M3bCX$%ky zJmUyodI2_9IX)f6^UR!F#w!&2d|e0ff-*KhdSCUz`O@6V!ip6c43(<-yy5Yt?kJs! z*rZB;)su?n?z)R2hzOijub|Jc+i-bhQG&GIg(^%G_UFnQSd+HKxQREtf$hCl9W_3l z6L+bW24#<8P~7N=P|KAD1?`4FnrcrCjazT=HpIZ96Qp<)J%ddsI6jIXp+(PJukFQ5 zl={PJ+p_6y2cI_(Rwdr|yEkm!p@-K5uu#0A%$p@qpTcx-07IITi@)NU7vu0t9%4^i zjG8R^m`pd<1nH^;rio4?-svPZf~^NJtsf^&1A|p4yH0E@p@15mC*r>RhIJ^9Sx5YA zv8b5bA-r)m4kl+M-@noDu|76bf3xbu0}iCd{_L(6FjjS9x4a3n5k<6csSg_6*+^j_ z9k6L&t2~SwG+JvqkncmNK{G=*+3cXJ;d$>X*&U>-ZJ*vC7q>SB$9xhz454(T%(UvV<>Q`xijiA8E=#nQ<w3}YhXSrdzft8I57)f!7aNk+{bHMv!S_tv^7`7xGL@gCv&CbzB$l8Q9JQJE+5N?5 zK{Z%pR!|`EA>7S4A!OXh`T^eSd*sxk*l97llZXVy`7k&=>qFSNY&%N@LA_G4B}ckk zARf(Rqh$h(mK5mdNs9QhqH#k0aC_;M-ODdhhl{2}fw6BhY>{~RV)N+y(|Je7 z7K{Bs*?mHk z{VJ+&!vTIO@mkAverZu4$;1h-a-_)>ac{Jf#KN}sy7Y5YcX!{I=RHOB$+iZy#WqY^ zzugxeit~U)-bkcZ!Kt6*1-h#{|K3)%ayc0oX!m4My-`o&ggOk)5qe)20lT z0wxjV`Nek@dmviJ9&qDhB4SBJ2P{lEk3jkIgYy&yi7Z0x4;S(= zKV#W8%G2+L9V#(hk15yAZ<{KJZfcP> z)$GYuZkDwYDc+c-)m&lpabpmgp_eW}-L;avJ(};$$S0qyDWcY_u8k!cs^d>zGFW#I z2k3V`LD3>O9%k9Q@!4ei@H(pF5F9zfL9)L$_ou*;XXI1f9E)uwQwzE}zusKoumpK5 zuRd|wetFffrw#d9v-n0k4j%2|>}2J5@-*CTK)yFEHUfPdzCM&i1H5lexzXO`iwmB+ zm>j7(w-5OTU_r_`Gj7q|;<#O9AYab#6yYgZ0~HhNJ7t`Gl{1>QRUJrQ1RBEP`pFI0 z6(1oVvP1ni6GlC;MxV-FH4lmCEMtVe z3HJvVN;b|6reqz@+Bt6VVZR(}w;+@HXxzCc#h>iD+}p7mx1oIwYM8edT0X}iYZq(S z8aWC^4mx1|Je$>;RPCH;^elCWGhaV+28|HEhRU=nOw-_n zZ=B23V>%|ADE3DwULjpnS8v8l?xAAF|3Bj1IxNd=YagY%M7l+~U%I8cLAo31Zlt6e z1f->v?k*)nQo6gl8$6HhZ=K)T%GqnJ{hjNazvS{_Fvc8nzVmtBdyH}4DE;#*Hl(@? zU|RBNhb!w)konK)Xw{DwaV#AxRrw5zv}HS{F|9q{uj=%!cN`1ou3Y!n2ZklZy$)5>)HF^=XF%*GNdLos{I`lREzYy8$z1KCJeQ}iQ2G1BYqSy8zk576fB_^FYo zvZwjP$CF#Iwj@$r0cWE{ETS)3uQ2Y{wXr3%JUSYk7K}bePd$(&zt8mT zoZrK6F)N}H6srn>bNceBFD^}N&*qu0zko3}r)H-G)!aPmW)=bb2|kn1wIs?4A1bnl zi{9sV7sG^jEZSo|_LzdYr zK@~`Y283JXNJH(nBRcSu^c-AUqIze`kvezmqO_G20=A?s@AE^SL>s*vURT!FhzN;I zIq!s%y^>~uHjMYKC*XoAefH{g38ZT_kRJeva2 z-etuo(1^hjM*aWQ#Z_5j+cWQ(P8CT252#6A5V_ z!#B%nh)XboIf?O@s?zU5aNQju?ICvxyokEeipveb$Y;uX*<8TZmmoEGXZzC5Hu4?-e2KL>pifj0(TFOeLHDh9g5Cg?;iQuRp{o>RRR(p`NO@nABRT6 z(A?zd#QK@p%{*QpEEafIgZ%c3!=qV`MIBd~%gXjL*l<&|;ZsT;tQB+>e+;WK{-oP>1SCsAOh6~%k4CybPxk-MfBu23{X^n^ z5GTMt^MkbvApc+jS|phPQZ?2eq#!_>CLnw8ci1+JY^|*gY>XZCjI51qY#p5q%^Yl< z?JR7}s7V0D)jxy6|EA3R6UqCT$-f4L*?wwH{ISHxEZG5k76|)y9FOZajP)0v>;MZc zkbp-le`}ch#ggp@Ki=<Q`F{x*#06lniL z4d(yV=?@weKwsoHQ>K4Yxc~nczy?73Kjrxk0Gs{qckK>nTidSICO%~7#YUqjRIL<| z>D&9g3!TkRrm&9dn75fl4J#p=;dUvdcTKt7y(DOr$Q2n~z-26lL+f4nw)|Q6WSPtB z3E$9CbVky&JA<@6UF3qHsh>IVGPG>EmJT2DL zc&~OpbJN@0Qq!orRO<2Z7@LtSlgj?M=RVr3>K3JjK7I`W^nG`)?nUJ(bi#g5Rm4#x z=Xaz_-1jE#4-OOvRB3ekhwIbx(~Rjv9amhfiej?Qahf&Sk+E~X-=kBFB! z$6BMS&XN^F)YVxWvMF2iCP)lD@rTn)^ZYmhZ3M=kTl``4ZKo(SIcXoHT@nZJfmpkW zTo@e~du2d8t_d8;4U(hS3GypLmPUIzBP|r0KMM^NS z;;BEe1h4(-}x=5^W*DR*pUH9nW!}6VhVgXq0Qlu64Fl zo`{_&BvZt#d(+g4i%q1zuB7R=$nwsai+-mE5y7iYtM(|(g;Nz$+}kEXyzL=Q8y{ zR@ZZQlRMs}^U7MAH%SaASx)4npY!!Cl-J3@VdS1zGNP}(Obxs8sc%e+Oh$Yq20?o+ z)taVQ@)3gsp_BaUoVfGl^2R2J&Tkdr1w3654ZO5zZvO|=-J5y&D$o!%fu_<&rQ%Me zsw_qf=w;q7GM6tpDCnz0aOQ=h)%s(_i}7&PM5sIvJh@&{doJ6NtaWG_BP@Wyu3;1w zedq>Qyg8z=yE6?&r8N&V=|(z2I^ zbxAHR_LAvKKk;kL0n1ZI9=*05MI2o#)pQ2Or%WIe676Id?M4HLg|JbJ4?M3^RgL)hnWn!0MLg!3u^3m-0M+wi zh4*Y(p$1qZLpeu|yT}w98h~y?|#gpbd>Q zTT)1*QF5ILO5yqTaf@;V_?jW7kqXA-Af`#Xt9R1t zc@5Z7<|LD<8q|qsNYuScIwR?)+6fH)?bsa7OLf!jx6AaymbxzfkORV-tY7BW1Mu_% zH6}dWsaHitAe+bfMBIBRQYp@kcRc29aZwKEhW7eA+s5CDh~nNLSb^;~rGn@sl_WB% z{ejOWPDCpL?2{*^AvLj^josY~m`Ic9u9$UrMhS)GVXbLTi%WCIaeS3HeMO4d!}8uL z`7uI5kK1dN?)gTLM{_YlH+xXEDx!Tu<-;AGywo=z9efAE(tX$Tm1K+Lexf)LZSK1P z5xy^&Q%wnnsT5LXslNw=kxASdYs5Th%f5Y!z0T9q@_1t$J&QJTz36x@6=?ZjwG5f! zo(AK6__?`-!&4|;HoZgmTqZ90cG!#2y@JcCS^MbKqY;Z3+?N*mO0h}_;N@G!De&)= zoL94p4O}Xi`i2HOHKvL1d`V~>bv=t|oQ=uk3>k}PEEoxmD^^0njJbvld*uT9ccg^- z5S1{#r9=Q%#oF4y^fVRiEWQcI!#9l+KmO@fc%a67E;_}ff$B!E#;)wHP;nXtoiSmN z_D&j>vld&Q$8vRFRD!Q#qq~$vGuVC9InmMrl#bmh1gL(0l>P zHVpe!9??{2k|c-9q!Arq(mvbA8t64P`!wpL7_pK9+c^}oMUJ)GsYzNIfE*{rF!yP@9OGh#l z1Q%$oK~O3i6u$|%R8F;qhqzQbUPoO8;c=e_TN}-rsiwu(n|~1*s-bH zB2#4rxR;C!xV}yC*ta6SJ24&l3cCGN70jVGJg2pT$y`^ZmzR1UrWHjSa`G}ZgPo3x zIKs?y0`Ug;XJ zn(?tr?^t%(fwq;uzHfS{t_s!n;AC}tKG_e4;d^MVXj(tjZq_Q;y##qcvHh_t4RjSu zW7cr~;qxk?IDtTKgy$MBC9{^S+Y8mYt&G9(gu(5a;zG!i)o2}0^~0-Y4aX=4$eMhV z%0330?3;QI6PgLe_wa+K8JR^uW$KRwPl{HJ+wKrkIeU*H;u;EmxN%k<8hAjwYq5%f z)ZFT<>~9}S0UJ1-m}{Usm7Q-3GWMOE)R|rJiCjitp@*Z*!gFM4anXM>EhW!)e2j1^ zu>OR$Usoge3L}sxi?5wyZoS;gI%XHULing$gq-lIo&Q@1_f^**&QT&^GZ^z046Yd zl?`9bIdCPH?mf<{Pm=fAUC(n}TGTIDzTu=Q_Rue%IT=xA^Vl3yreE42#`s?BK-0Dd znC+l-IivBhK9)SKNH1_RKW5gPD2uzU-()M5xL_Upu&+* z&wnPW$qD}c^g=&Sh-X>BxtO<~NX%m=RD9~WiaV00{uA-NSihVsA>-#4Ow2~SewJU~ zw*|UInV_CQKV^U$!d&*eSm(MpGB(^>j*B)xl^>t15=TffLM5KNm0uL^h5Y&sF@^O_ zJnlMfoVb`nw?8kkcljNfx3LI<5Be#mj%1;XJ*hj~IUmfzga}@x0a`r>$v+;amMKwC z-3AA$lrW(DS%5&cDO&vn62yx;-=K3A6V6^($es2!pL+di<4Y&r&~{8oD6Q`myx9n! zpwHmQv)l=@pV0E|=k?H`)9{iu+vgF0v;`}*VZH>tugAn)KHeorDNy;^<5-R8pL+F_ zj8wqL-d6-TKA}^_B5X}Qmk+CZ4*ky};Pwhy^2?Uca%kbh9VE+@J%$fVi4V$bN)Im_ zBtD_@1tXnAID{l^x3-+*+0C9`s3TpDZQJibVL3L&VSSDi)S$jhp`$D6hwF2%kI2_9 z&#@}cY19{=))#m0KnW>R3x^TsY=Olk3f$dtDRQ!4f9(-bS+ePoa*oearEdKo@^Jda zaLvfyGFi~52cF)?mpJXHI*I7`v%vBbIk8jDkIQtyS@fs^$R9ewBC-@-yWoF>`1BO@ z>+6X3zC_DW9O|dCN#nvT)!D3tGt7=vpT394APD=+ZIcE@P?rVTkVLc8K9$4u%sPTI znj9__yV$^(n`@Sto(+u{hFaD~0p*~=Y#s%>+k->8`=lYK*?on9d?P*u#xn_*NGGBA zH5a~E;$yG9C_LlX_e_f5Q4sXVJ!r$_6SX5M2GQi2Ar`i~q;X?BPpnGLQ?zko1IpLx zrJJu0=EXayONR(>COqG5mD|LhGeo<7=UP!obKLY1)8o&^e<>-jLJ7^B^<`m`!1f8Cav36s<=UhbJ7GlP)v#PgCX=Gm3(9X;b7*w-g47xp&8W5tNkB7Ay^d!q3(_97-vADrhQJfN7q+X!%J=-Wg-Q` zdeLj_`Z@1a!7PZQA5?3^Q24w`&~nHEMlMu;KCwZ<*}qDdVCpieQDA4%jT%oSQ+3T;hV?R`^~~E3mq}zH(XYK1eHC!k{v*Ih}w$MR|BWh4S&O z@x5eG39a5byNhrYm>DOhlxowdp36=DEps@_QB11+yXz1gTDlxE9y^c4_)v!`S^h5r zEh$g!93hl@28hc0ie{&SZ&PQBrWdvs5~v%u7Yte}wsl`D9!xb)w|=6SJ-1;g+s8fV z&dBiz2;Mkwu6j81SV$qh`j#H*jq0J-WYM4PuL12BY;Lu2FEY9HLtS57Y&0$;xXPZ}JN@S8D?iI8SGq!v zkTyTdd!$QQtMdLxO~Tx7W|%imRb15GAlf?GxV|j6QG>2(qFHL3ReyKBqlIIiwa+_~ zV0IgK*;SO*Fh!utRN%TC%Yk$Av5sEFv_?byylH{}CkUg;&aWpEKHh{$VrF3H#uz#M zu6e-*zX^}_Cdw#63^@r!wDIAmOKynfiY+M@Y8!(N$KxZc3}w(c4o0i z5c@|qmQC9a1+QuxGr>o&9L>}in~W@uAe-Gt_v2EH8)js|FMx_n`{^E;4`=AJ& zDv{R1Yp`7y4C3FRcwmD6Pe9Y-9nSv(qy8O=2Zq`KyT1*^gFye13r6@877zMEG#Lc? z5d$D(4EjU$81#qOG3XDC<3BiJL7+dRjX{4%8~-sJ5BT^2iT?OI|D$O9Zz%u2-2H(n z|3j3Y6%emr1JHdA5J1}iw7~vBYRm!9yR-d0LApPq{1!G&CJr_RR=)!L|H{OF8zaE( zzzj4j1BC8?@CWb@2LmfWTFeSag8>DJe_DtzHnDRsF*0y6G5$TsKV#PaFpsPVPyfx$yxrE=)s>8>11nc`&)efE7?W>ZU@dG2@8Nla{^?> zEC9VS7XV7L0x&TL+dq%b#L?;Z`2Gxp|I_>dyUGGkny>)Mh+IFEoPqMw4-yWbwH{!t z{>SkdI{#K=`qwAzzdVB=fU%zgU~y&vTK0cT7%&48e;mN}{vdk?I9C4YA+#|4J$ZjF zD*e;saRSi*#h*W-V*#=MB=G+)qXTZ!#{&HQLjBuvzbt@4Bfud3f5-Pj!5OGm{Fm_= z+1mX6;r+=Z@?Y*QD?nPq3Fxu>5#Nuih3&uJT_AsthWPUu|1U#i;Q-3809nuv7I)?! zw;*uvfN~eW%kp<6b^m<5IGWqKTG&`PSr}MZc$hf+b{PLRYJaS3fHDX$s`E#re>_tD z%TUcNj7|Pis7!ypw0{(U|Mlem>(ViB8~$1@{MD2l5Xa;Kcz=GYp#e|pKfPT%=9L{# ziUg={9BXnFJB_48FkGcG-Gx%friHYTrVk`)#eEw&r%)rbQ`y)CCz{}uYog`*}#ft;DW`EBS zAWr+Ay@G)ELN3-vvIMB;{H5s+$*f1c{#vvCb!R}pA>;ra{*MIwSBDUIZwC~WAKRRt zFZ6%hy8p{^H}J^%*(mT|F;;g?E;?tGaToAKoX!qTcokZdK`;9$gS(W)%#6$yUe9Bj%hWv4f zjkAdy#U>)mxbkGra9uiO?IE)WF_DgN!D#x-3?vD>5w#?R`tAF_Y9PW5Fc(mA9{Kpx;^ZWv{blgS(`)rsTU6_(_Y5 zL@~=f%|fOsoT;}YBnYqjDb<|g7~{}uXjS8@>B7-d9UR;(8?m}3wX($WS)P6Boz4DO z+4u5Qw@u8nagC_h5pL39AERk!?|Sqoc(31vxLj*{KiHcXyTSd4Dh_Xi3(x+*o}eVg zKBo};L5VM&I(vZ?>9HjoMg86xu`CGUhY`AY^SF)_6-h@i9zqkd+478EV?Wa}mdW(c zv{X{wJG@=XyuAwo9r0Xj`-h0_SAHE9B7bgbgKckGL83yfFY8~57b))5%PtSoDIl41 zj;;KRQd2gz@p9mzYVQlP)->b2lBsi|{Px-mFMg+Oot9qwFQc=>7C-1Q@)Cmb4u2c?z zy#ODPE0@RXi@gEHL%qxloizU0^+@Pv2CuBN_9Eulydw<*;Ws3gUoBO`2ENG-sN*vg zk$~X*3>%a1oQ;A;L35asztvp^MEaH+PCjvrN?r<`dVT8Rx)POqndYD!O3gtj&zwD> za>D?Y3cQ~zvC?SkFD>S8o4Vg6zjsaOeaUY`4*uIo`f1{aQ47D08eR4VFn zGNS76sEK0X;<`uzZAt`~=>froj8+de^LPw1orK`BiP_-Dj{VgvkuwyY$r0Au{7`zr z`)I-TZ_ypK(|lN;YOQt+k(c-!XJIo18q5whdS5wPmZS*Z7fZEUtM5U3;XQrU#ko@F z2=iTU4S*X0KsWt1x(8F0I^dWgsb8h#|L#0gG4bTXRf z(Pg8jryQGngQU>qIbv+x1KTBA9coB;()XCbSYA zwltJ7ck|&ar*LEXP6N?g||FKgr-wb;fcB(L3@K>O|$ zy25)J4NG~$?-A8OM`{<-bntSRrZC-Bs%C>R0}h{Er;AbE1B`x%y{9=XIxJzS5GjH&y!b|>uQ$+$IHA!@9vkOhzivniGYD$g$hPz zFMvu)FK(%#9U+b060h^#6h&umT9y{5KvBgvz@x^kuV_FnMI2@-1Yr~hnp>JrA!0Aj2vz!TukrhHYN&#aQ3~Sws3B!4 zrt3`nY7?U_rz~9O; zO|IRz1T@4*aHj}Cw!f;hBZkBslg7_F4tauk1z#fSktf=uGtQKhjnou`OjK;J`Yrd1 zGgG@(j%h|*pO9IDJ=oF3%pilTS|TKwt?CE%kfXVf?viyaMhbryMmv9Y?R{qN)KRkB zxIUVJO$I^Nn$$c99;Ud$xFt1_Jrw-mLELI^mn%8^;W#c|WSr#>72t&38Essz@6WP{ z$-zb>_-UXy3hHtTylF_DK()`42ge_0^(<4(z#Ltx5Qu0-O%ztElYqxv6ItxnCoiEO zOqV<BSnWG5HB8Z`5OVO`o>vN}2k%7S8)QA5 z-f*q>utVfdE)A{nKLIDxe%Sd&(|1S#j&!{20g>Z-G&uTNr9f}D!`zpxQ@@Bt`lydt zm>Bm376}Se1v6@rs**{g2Knh2!sf|Dyk)tF8PAZ|`9_TbJ~8>*MnGt>53yTn(J_w?EZyT}_UJ&@~%GTWVNt0xJ{V zSoY=Uj)!b!Fe+PUc6&G(w}|Et1uxtx#Ffuvl=x^&V=rCs-YmMC=x+%G+{dlJRyoISux$CTTRErLNDc(-shoG;li#nFohj&kYjeKQ53Bu8lif2WbLGVuljQ{CMksbnY(J!v|P0$g_iA{ zokvT9QC8L>6|{r zoO#je20}%9H!!kKsw(LFbPlZ_VMOZ5ZEr1&{6`0$%2w#MRmLn3S`yUKFFTjwnS?MQVl1WjV5n9D4m?g$KNG}XZ&dSpw++jUky zkz+bQ|CGM@o)9bSiC$8xX8`?&Z}*sZ4=XLVyNDLu>~$g{A^{qm_;xB%+|y0zxkKbS^%6%>|W$0?E?I`aEoNmKYnP6 zao6+Loz8o^B*!~F9Sx2bA-pGlD7d;i2~Ij6bEXx-%6|DEqAt9)nRzQ>$}7?nd&rID zYJaBY5RX(y<#sNsaDq%{GED@&7|^ME9dt=@0(Q+#+8eayX-j&&v&_>nmvgg6M3%VN z#6thTD{!jCkA{vZ!feb%ri&~5#hv(#R&mfEm^yaX%58?9VFh>lw^E`gQ0hAP7Bikp5Rqi2_DCwW<3tCq|4c7r*?;~5tN(vF1WY*XLs{` z9QR~+Y01gNAsoPihU4hK5bFQ|nYYd-ECU@T(cCH+xDVnUkl96((HG(ZK7bd03v%l0 z>*C3XU4o5G%weOUr{D_BTE%xkXH3Y6_C#BtE3sc#QD3~kUFang$5@4(Kvst0Oys^n zTaqPuY;OkJMa?{(>U=@)zeGhf)y@?3^(JWjQ#?ChV%NM-FITKg}cYP&jcF)p~6~$pH+3!Atlj<_)EV!Aw9E?5J(e6(Z&dphTmC_YHPFcBwGeYg#NJF{}9wy z*|I6F?MZ_IDxW7J$03{d|38RK5*+-K>Ob>SaC$?$=XEGpYM+%DVuu4PmD67t61w1XFy} z-^zWFr@WGoXMb^VNpj_L-1b=-CFw?_E_kK4UEZpLEAjK?aDWk=WN+~OmFo8>b7guc1{MR?oP5>q74Z?sJqb4I-O-Q4<8Fj@`0o+%3Y9hnSl;QpZgu zNJO$?(TE@3=8w-&!AC-7AK4&Qw3)dqKeN?H2l>As&tP-phf!fSNi@aNjk7ODI)QtJ z1J_x)bj+@$ck&(9ip)#*k*XvBsr(-Z;9n^JuLDB=f(d@9O8(U2{^wQ6Kh4+xqXd6) z{S#9A8O+}SO4)t`N`Em0kT^i<`w_SZ1VGjQXTgtoWoH4Zdyh^>{6=sO`o$|70OYYe z#@-Hao&SZ`A2jvsERP2K8%Xtw*B>(G9FJkb|0d4+*iwHWl6$GO@k52bqcva`L^t2swvF*5N^1mbdOHzkQ_ z?2#8|$9?g|?86}{@0A}X%q z2gc72?4B92FA|+N=@y^p*vny#kCzs+pDzy;EDota%&{QPKZ7i(I9a-?e$s(}BOM8G zce_-OIlV^!b^qWi$}DZhpI8cnV5VH31EzmQU>8xkY&*4 zhK+PmZpS*n8L_cRMFlo2VUW7OP=PEb0;& z<$D{)`r)i3r<&>X6P*qZ%u5et&lGBzk*3HY+ANlb7#dJ$O}( zQeKz$`+Dzb52Ja4-pFb^`PaIlkC-i)*ykg!t_)i&&(AlB*)yH;?M@b#H9FeoPce%fVWx=S zVd7mOUIb)h-p3K)8=L;w6Wr$ z$}Z|E|5*CgwJVkByL|PMc2Y94)1;R=NoF=JZ9Evqym~quFQ!lm6`0h)vW!LsqI)R4 z_rXo^te7#bH@x(TSoPylgEtv(==P{WNl5K8w1*vEYELbvmz)fgc^_1S8Dh!X!|Kq$ z4(Acl%bBv8qREJWb>$(_6EM4H6nIXR!N+2ZaGc? zU)y5mXg|7~;xiX?)+< zOsY4-ftf%rM>0hpT4Yq4+$>EEx2~bsmFUogMvXAy;MB#m*ihYw-(=Lwybz~_-WsHj zYHVC!_{N*y04XqPK)qE3)l~9fdjl!d|iB^k&f~Xv70Can- zlR@YJoHtEDk(OceELLLQfXPd(La_FJJ3)`HQ>t&-aO-9U#+E_|yyg;`q-l^Xqx=+m zR&2(}Et(X%`>A2P#>=zw`+IY6nJFiEEr5=_wA&V09xc+ZBL-@g%Wkq^T_yz7xFIel zt5pT^8Q=GFDe;k5;7xW@8}qi$ag#l|vqeI(Mh%qZvsKRN=dq>Q8NMdZg?}O_lYA4Z z?q5JB#x^mX@cw!F4HH>ztr!J-P`ST8oaK%obhl8=fNlh`X+hvuSre^U?-9$I+S+n_ zyA)9pTXWUCSsM7txqL}1mnQxq)%6h@&2^ZF+sT>zK2YC>D-Y#XRQBCj54Ga`MBTNf zU2E{M=FhxP!ot!D2K#mPP{Y$WY{KBPOsk`&QzJ+z@2y*-ack2q^n;!na&BUxlvD@j*8aLpmDg_%0kufw zrDFtFA9Hmqtu*Ra=i1KmI6&v2(s&|o=W|+D>?l&~a7VaT)L5@|_aov-2&CSx+F2B( zEwPOQ+%Euc&h#*Zt^jShoq??LYgr-XJZF-ayW&#S$x>y7?sdrBRh5fNOg3k)XInnd zZZ(x6(9V>f{HmTn<%{lp&P<2qS^rv90wqLU7u$|z{Q8^la5{I}6&yL&P8E2vWX(Z2 zuCE5>XGd-qbIBlqiQ2epKCg?DZL02CFMc9JO5;kn-CpR6a~*lAfgF{S563)lHfG?} zugdKh?iR$1-m%)~zfzDF$_1m}=096gm)(|>u=5vT&MlPdOcTitm8SX>*Dt0XryNNB zF1$ReTSPt1{Rx%|p4TVMry7FL%TFh&JFrKrKQJRT$Iz}oy7NehDFrS>&8vICc1kDG z7oC1`C%v9!o3gK%j`S2??{?K4CjJNe1ObUKOQ1flA1CR652gPz9<&cV$i-@o?k`L?!REk) z5kp->)?Kug_$z5a{O-Z+2i&b$vD3#(`AMSa`4f|w#N(Z3so&`0{BgJyFTb=Y4=zfR zd7C$KLsCY5e@$Lw0uhfCmSJcwzQZ4t7XPmVZxM%hqf>O!=Mwm5S{;#ZYJ zf?#bIM~o`CDAshIMYK0PA6#Z}J{!)k4U2DOzI9nmP%MX52|GNB=1UPQuNi>R&fvSN zZELrWma18t3}&?Jvs9u&vB~iFo=LJ|`V@T6E4v~|&Y7YcynNjfHo^(dO@Md;?TFHu zRY?*RW%zbaR3mCKw-Rb}gJCG9l6woDiB=>8>QkPF8eARG2_Kw!DX7ZLTq z7+G%l z$@~W5y4Q>Mvz(A$aV9@zhIEj7>~;}1(E!QA)W%Y-0orR#e$Vzy`1g2s$7G&&Yt&Zd zMqJ(0Y^;*qHc7%7Vr_lj9LG4fiTa`7I#=PqtQmJ4nkmM~+pV}7y90K17^)-!2Sa4$ za9_O|Qi$I`VtaNQgcV5Qw1wy@Yr&#to1V6TrmEPxx0 z3(+;9)1l)pE*0E^OEI$H#O&V#(XH2x5cci8!kTmhz&e@je1M{)zZs$g4*s~wS6_loJg zWRaYp7H+>k6xiy?YVpj8rd$7wYPt|>;>Y~YJjL9nWn#STh)SWGt*1*w+%;L*ty63@ht*rlU6d*N6L*DBu zfXP#OLWQh5z$D{GRD{k*t>5db{>r2S!i{=&r~}c$kxkD-_l*JH+v+E7YUw7f3ra`v z?0TiPx5uF&oL7OoiWFCOg~r+IHAl(k@u6Tw+GMi9-Bk^ZJL%QgWq60;3_X@g4A2IR zs@yT*X&HX|tj*JY-zG^7JbaXp+7UC3rTNym>k(yd0oo?6SFef>91>nkg!U=s=t6r$ z*t{+nLezI{tzVc)O(-`>N(~SDC`*URmW1h{!*RCKaKJW>h62Wyu1_bDXy{{eG@&s< zV27Mj8)4FEn5-0uz07~W9lZJ@vPpKgexy1AX_m+t1fAot7xjL}*p^OcE_K1&882|u zWh8S)d$-V643AVUS` zk3aJK*t$A4g2XLXdrcIj+-Hs&H5#ZAxw;nWaBz{j&9u$MP=faq+p*xywVV9b` z^J@PpH`7k^P(*GpCTIH`C!=#mVyj#{zH!rGEjy5Pf^&PSLm}Sy1_=JO8FcSV z+_!Wv%F{y;+`94El8Ive(f#I!rXWj{JZf2}_$8+Pxh1A5X1f4kL6QMV`8lqI4!bW8 zS?PLB?-lI2^A7v%PZFh?@QT5%z=<|=8uJZL@skI-n-`sGrxY1^Pkf5M8E|FLyhMOY zSiB5Q{jknP|4u4f<%8tzo5CCFOL8UtWqXG(| zAThkvTbXkRIQ_ZFyYFDF-mt-sK!t37?iTugfC_(N8oxk=01WrP9bjPp0iXStH~6Ve z`QrzU9|+(t^g^JYzxD^5^AB5=e{}KxAXopp70<7D~A4b?VA zR?fyIzcsS{o4n>f43PzB;bdh8TF?OujR|1=2Et?D_|e+W!VEO?{bL3s3u^yJqsHh(z^46Yr))rb z<0CSfEPz_-Ul;;3OOFxCgMM#|{3Tk}AA<~!wt)T=k^SQc{KSoaH3fRT*&kz~0s*`I zpW_9x2ryAShT{H|v;9wAe;j|HA^x}Yvj62$S%3~^rbj!1e-oYs{jyYMU~&N%P5I3! za0C5TzWBuyfWCnlgGczfK)@Kuf6fvx+yS(nKH~J}UHV6o{(tQq{WsNt|3R+-_@C|X zqSqz(vo5ps$Mbs2bzjY%L#gSWY;?|a&UQ*#=j~_AduN%_P9({*0X-UO0Yz4T$;3>z#xe?1PLQ`M7Cb=Y4>)IX__ znpr*_iCaW8lTDKv-=HsbqJfclS97;-Ua?nS$xHj>nf!OYn^i^+FUaQaE+U~4@vGu) z1%Y|n#~Tt9?afmA-*N)2|uhjw*IaTVJPUgE!rBb9a6+Z1a z+p~#8g%NXY``$?f(6M}(6g8?)Q|&}n53WUW`yQ{a47;3k-CbsFwK|v-8$Bq7t3bosSk9&OWJ=?hOul zd|3M}?g3q_SYu4{G1RLOq;Vl;5st7duhLvJEmymGPQxu$=bmu`-9Gg@5mh}Yir_p)J+jVvA}6KWk$XGuzon!Y1k+ukq4n#V_9ZWe0X~7F9A$XtU(9TWAQq`Y6~p z(-EPWm_C7D-pu=*nUzk8jOGw!2ob4o34ytb#5ShljMMY-+RFSG{Uln1AP5vr+mEy7 zj910i&F`(LO$SRcME!iu%%)rz#Z+JnmE;L{_{nAOyJmf>PixQ7K^y)jQ?(EVq@*rr z+g#d$+s9DF>U>Q_XdflA;{uM>?VzvGWnx6Si1)cLJ5fsV}gX< zII6x@60JFY-kN%cb-HZTWMh!_PH?ptYITVrrFOypR=s8dF%R@!+e3FN|K`}K;51T# z1x}v3iE+4RSwb~~DeoTjZj^Veh*S$d`DKk@kCAEVxJ~%@D*aqRm5}>#lr~p!n`QA_h@#I(2&UC-0xu zfH}AJhK)48W=vV}NSEi5d&@kPp0zmV7ttWg6TYX*;G?6>z_36+2t$NWE$T}-`~Joq z)xG_v}5@IcG@HgX1T5qyl@`R z=k-$yUte=U@gm3eF@R20Xs2M^7#~xu2N~78l!1CVG^Q$)fBW$C*y4My$Aj|IjveVH zY48u8{ZEIs=TvJ3Mk~i#GW{E7de(f}eO_|Es74Xo5sS2!$q(6S#20Nk9MK+sgZcj8 zQpSS;nu27cd>1%DHw--c7PsTMr!&uZd@m8~CK?!{Tj2EsJB+-U8A$qTpSJpc^;QGPd{>e)PaqI+1CG8M@0%92JDFP(b!U;RW<}BQ&zEMPPo4sTE3{6@Z}Y)U{!;v4yPaB(V6n>jw|x zyTMUb7n$1X<6xpb5%qq7Mg1LKKzgkzimnWwQ3+47qGio!{lRMnhQ&{bK6q0fB|-v` zw}2hes;T$)0?k{7@on(a$qiv83BQ2YjUY!1`_zGC?lBOZ;6J%RB+L3TBriU_SA~l{ z6P?h7)*O#m#0gk{)6{jA0;GJ1&2XyBJF~)iO;!~_<)<$wlgh}J)P^ugbVBAaNqp_p zeZjbl@;zq8u{evZKPA8F5A8(CHv3qrA}|Gao8jMGb*S#ScFtycXk7scDB1zH;K%*4 zGr>zQ4I;Cdmeoxa9K~fjoG~Hsg`eZh#b@%YioSf4Iw*Cz=fTgZH-+j%9eCxus?trZ zI-B_RE3K-`=*~*jInLYNeb(u7ZdaRJ92ZgCH^@r}=meq|*sCxG1{-|;7inh!RY#X* zZQR{Lkl^kv!QFyuaCdhP?gV#-;O_1g2$0|&B)Gc;_$%q@fBH)@^L4LbEfy@O_trV5 zPF3Ce)INLX^njuVjIbFGxkZ9|EshHud+8~4yliwZKohisQEX%cAIYMElOgM2=CB{^jvNLUH==qrLo-rh$=A@Vqh|HO)qDXdDczK^c;U9HJW z1_UL66nn@Mw7WnC*6li^w7XH!0LR2*IL6-(c~p*IOuniq@Yz5tX`a34RWmddD>e{h zBLjtR;$eA#>@q~Cifx8K!Z|NW8-*@6);Q3b`C?1r`C~(!LDG2T!G2)bf+2XWI2Gdo zSA+($=IWCBSd=>?`MUsY`4=wVh{`lCg00pr9tY;Sh_VJjRx4=m!H-;_cYnM; zJBwXT)Kr{ttxDf-^bRyOa(;TtU~WzDt#hRunhxGBS+d+q_6E-{;HBNpQt6Q)nE z+~`*nMrJdWT5BIno~ySS-&T$B1q^?c2~#at%OuB3j^9Qy*=-^uz+`eXi_v74L4p8> zM-zODMJfUBrPFJiJEW(XH63NvDCB&~AsOUNYL3`Y8^xztB&wrau_%sNuo z)uYd+4P{Y_>{Si!vSG~8l5qtS!w%4_bTaVy45>2GEFzWYrlA?}rtg>YmdQNOZ(emz zP{1C<`wHqYHTzpRgk!DS-(8=JOfKx8=bGH#2l!HQVIk(O7AiPl7t&QSPMJ$lHm~x{ z5hPKRq+}8wpkN-o+{@apEJeGxd|i~#N}4j+1hd@cCHvJyVCvpPKSq+N!j{M(vomOz z%ljbqA;G)vet4y2e)cX)V4R`TOFK;s-y&Vdn0N|bOIxMFc5Ox3H7+3F$|(VL9z1X2 zqa)CCIrsqhgsF3c*n@8`iFdv&khr$cX>;097@Og!T72NDU^Yjz0*g4B>QAjZ#{H}~k!)O_~0$_Y})4aTr{$FZ9IM~(D-p(j@C{W|N`jiRnCEEHo^>;wuU0FMjDoSd40lJv8?HSLA3vE=*!MQ!hS4BPDFKtWl@3%2b6@%n0@M|&G8 zd)lNtS(EtoD*k07+$r1w77}isv$rJz=^_f!5lnNuEM5ae9Y%xL6dr2k8=r>?f7!H| zM(_FK)Ph-T0|%EAldTNbZOA+CjY_q_YmcqH`*pqm5Up~pX8Muz??cayVR4Sb`Nasc zg}f;>i_>pNl!^$tyg0qv)U&!?KXO{Z+YvX5pFt6(iaDvHih zhGH^1jTC%(>d;$pV~~o&rt4QPTgl)=Ij*G+j!K=umnO3q!6=PZg_FUND5~BNaM-<$ zC#!BzxDCyNW-+<4S=7qBb7MJRNa*n>cMKaQHA-7b!r&()-_ zQ0+8PXkThN)qAah!Z?>WANBI^O8i=l>PjVH2fsWavKrhxxDRs~gz9WfBHFgwrvaj} z*|mOzJ2z1bJHN)59s@(8#+Q}FqLi2{u4j_uHmQS=QB&*URc&m%2+YfB8YGimJatk&3{%V2}T3A5{Q$8%0%#9v=KjC2@cIf>g*SQf4MZsKY(i zJQ;(ud6w!Wiq~$o>mx_oILK?K+98zhv{Vj`#GrFUQoRVWu8R?OtOaCRv$;u2U3Ef> zwB+mEcFd27WiF~+j=1a1`kYVlWK2d`hY}7@+=6UWR~P2^v57LC*kBb< zEnz@den}*7!4mykhLGf1s1W_I&I>ep_T-x40^e+WUwExk^i0V8hr}B6VXP zjh{=9LLP3GprzK-S3OJp-OBQ8^Jo!mBE2Dx`cNh;RuMafbz!ix1>J&Py(tdKia`+5 z>&2&PtwP1Q_P(6NZgSV;z@bDbm}Sh8#E8L;XduSh3Gb@RyjCh?z%~({~NdAy5x1Q5_-Q zR_=R@9y%8*ZM}+=mJ?N09x?Vi?T&Ocv7BxmxRJkM5=~nSGh)uY2oF=t-y(<97rMKz z{pz@{TPAjE*b!Glf8mrchO`zMp5k z64)l^teWGDWv%Tbj_9QFt?FbZ~XzURAS>OKw` zKK7uk8m&Li23L{tF}%*+LHk48GeM$O&$mBtTtF-M-}K>s;J80O-T%UI0n_sTE63&h zu~zp7zWo^r`76Ht`QLxSjsK910_>Nb5m*ZQgK9Cd0L+n#5m@xgLdXiB6qf(o?!?dv z_(<~`b^J?|<=-}tkq|(k05?`NHgx)71MriLvNAE#vjHke7NC8c00&}a28<|J{>86@ zLB`z1l0lG%hvCN#7z7QS%x!HLlo(VLC4YQVnmIYyaWgQuy1LSv+BnnOI+!vz+L}1I z>N^-Sm|EEy=v)2Q4|+2vYb&b1`r0!ARQA7*{ZF*_b2j`vHw9eKe_Ln$YboHV!3dD^ zUj>@1zZs|li@AT!0|s@Cw}gQEH(+E!&jlE9|6chU=KZCT9YEj!TK=sPz;pllwBk=a zWoKgs)^`8No8Y%Z*k9Yr4w$WQ0%4!OwilS!f7f6(4&X7vAG!*Z{sskq>FWf&EYS=oQM#Qd?r|9Ua_(=f3z0x%yi`uW3Nf8*i5?3D$u%mJQv{GsyiW+4k; zDgxM@{Gsyijw%Zq#~-~E{^BwJr+zX67mgopSikO*3ozOF-%lB4;K>miV1@B(C1A4k zce8;R0O_26%C7|+`u}dPfXT%l2luz=ieG0h6Ts0qflK8d+WU9&=tl_cj|;)?r9W>D z|GakpAHnp0tfc+x zp!8<&cywPHD-*uO?-t(OaMUq;Q!Lo!WVibWP3Ia?*SFyAEm4OW^lX*zB~~HWNGNK% zjD)*2cp*DFMfZ&!SJx*5xPSeaZYiJQhT>6hmU)t z>*3K&=tGR8~qho-^!Tb6`0!J^)d>-*+j!O2`8`A~|9X>MFFow++;nUl0y~E2ltl7;KOfK=ax6cqnQsYn3xDg?3L^*;vu{k zFdH_HtR1`hvSHsoDSa2i6vccy7_ni|yUW={Lz7}^6F;zB#V|LpsNkiO^Z~a=xdu|) zPHmk@0DT!H)t*!RM5FrSc4ccv84_2REUcQryd+MV4#n9h^ihmt-e)9S_OHi;S#vou zk-2Cx($#hE>vZ|Xx$~$*6?3pBg>v?+793C!L8XUhlj``sf_!npkAA2hpb`;0V_k%6 zhiVuoAx|KfRDEC~;!((K~@Tf@0_b=CZotfsp>u#;{O0X2Fzzrge9 zZVf4az~p$rjV9#Fha#{GvUm{z=4yLr6Ne#F_ys+%B{~YNsOJpe`kFz&n1z~DxQd)n z_jP*)@jl|bl6GjI6)YCZX7YjP9Mr_!U5ztuOl5+K`LnCth0oLmpS9%&SZG79X)X^P z$^LTBXdG>lG7gb1(Q@NOwkD=K*{$NR%0hvJ_+SwZ)FDNKq3cc!E?sI%W38oZ8%c*H zc6)VxILQNvT?e(F=6pH#eZMM~ouAk&9&dtSs>mZ4RR}om^`$nEU~jdNj~xz4aOfi^ zMt#gZ9Zb9$?Kz$Od>PEqoU8m1~ft6O% z|IIU7x=%AF*Td&1$H-G`-y~9P>V!e~r4olzNpvCaf+|M*bW&(CTa6ynd0dSk) z!U>8uS)?2|wZU#UJv>$VJu+fWBS_gs6iL`$M&MHMCN3Iq)tknZ?JQGj_CS5oFW<$_ z4(XrberUhE!N8t+E)Bmzf_s$T5MV5*#aygn*9;YbBKF|xvd@<%qB~W*6$yZEx^rF^ zQ}wz8@`<>|;c+8wp{b?z+R-Bp-1;VlNAHd$ivth%Mq;*PQ zC!ItDqNWdt_Y$QFky^pBdpq;+@+~R)>6#tQ6y`j8=RB(?IqU7%(()H&Iq@kXz}~nY9k1tJf`_LQ z>w-k#&y6Ev%yQUIdN^y(!A9!v9@p9tZLT1+f2s|JcXByZrrL62m)vvPEUdCdPM&F4 zorET5P{Jw|#C~VjJ@FAb+1_q(#p+nfcL%RDe|c7_I>z(ZIQE3PDa(_tPGa=)5Ip|I zHnKK47<}9V*0c#|rpsWj;Nv{61f`NQ&i=Glhn*CL9$0XiD#TGNvX^wV{+>|$_xr=! zDbPKrAeIqURVYwZ0m3#B!=8O5`Qu*dr{0%`%cmZ78n+)IGotWw9~V-u+S@fTe9i}v zU1nZ1cOa;7h$=va^PD1o$}a~^PS!n5X4B@B-OjppR7mPK$B6T$eltq_m0@mF<#_2z z)nNho4F+rPjKo<&=yZQ>32q*bH5w|k90x>%k33DXi2n@~nx~f;-!+WDBV70gQW8b! zE+~bZy6smRAqyW5o$fb1y_!6? zwC4eEVWZIOzuRpua)Yw}(05_u3~Mr#C?`;jd_OdfhqJYb!xu=`Zr^LBxtw&jY)A%1 z4W4f-ovnvXQ|=mt=y%%&$-?kC$DsPdWyE-(o!*;1Bvi5(We&@fh?>x(FU#L;+UQW! zy5T*8uU{z#?=->PSj}dxXG@Rw|gV+L;l7-F1)^3`x6lV(o&|vZ0 zYj{@5r4Y4~BHn294>pG`z;w6Hgu1_+oZS%|Bjx!(D6+`h1P*5~f&%KUVw47x$Xl6v z+8!6G(UkjcUk66p)(rFV?D1fgm54kWm&BHWEAM(cyG%(_)>RtKVAjM6oKGRlUL8&DC%I;0F^iLQ3;x~-V~{mVufblO0nmM}V*qU2zY1ldw8%bbQu{NbIKk4ml;i zh#LrAD~QOkH1j5h!&GW6wLK~6Yl8Nv*s$qS^qxeOjV_CBIR_^a%nMUK^)4Y{ALh=r z?|G@1iP5I|TFsro!99B5QtIZjk`)RgC!ZkY^7*f)gY$*ni?DhZ%c*xFUxm%{yt;ZB zN0q}@qh~uYZW5x9O++_cJn@tSY|w7ZzYm@n#2!%m-c$Ml;~%$mDhnFkoQjSFs4sH$ zI$rRZEp`#$2u<>)w{{UM>|i~%Q4edPI!exV1X|aiXkuz864tcf79oATMuAr_vMFYX zc1+XYXY>LRurMb`f@%+qgBmCQ<T(E* zU8x_+X(=Mnn#{3}1q>*|k8iNRcblaPFk5>8DD~vd4LqTQ#kojrcP<;KFkrO`Oz9!u z(9i;*Re~t}`jztj((bMgmPKbhu{>7?53mWj2Taus zRcGaD9QAgp4C5AsJd0@}%iq+-Q#L$ruA zjE$`UjcOoJ2`GVG^`M!^p-9!Mbu^3!VZuLU+$JQ>FxUCSvMKd?<=NmB*LItGXE#Ts zWmgFJ`;2u%ct1UYm%CJC|=ujC}`BW5Z`*KmrlpW)~RS z)ecnf9N$sDY-yV_YU53SL)~59mql)39k_I6%ps(~JRG;6ufN@E5M{ zDR4LvGY<iJ6(o=wjf4AR}m*Dovt~wF2^a=7< zx((XAMMlN;i#%P%y>rn}(O;kBzdCb(gws)7`q1_?h0{vmp@#7q`Mf$(NIlpj^0vz^ z?V*_hM*&^-v??MlZJT2xfg~au#)(My0^*(#7Qn1Dubxp#%I=;)aa1a;{(xEkA{YE0 zFze3`uD@W`p901Id}aN=_+iM%R9+1iZ`X*@5Z% z8**a)EnM^0p0cw7NDnyvzm{?W($!y(-Y+|4;{s;!AIxVte|qBob5{Puh`&^_FauNW z4^mUkpC)l4M){xq z27pDzzf0vRw3b|#*e88&0EuYg#Gv{{?^5T7u*K#B&PO!k^sL4mTDmV-9Lyzg$}5Mu z&trN}?V&G<8lnjxz}EB_Q||OlK;C9~o>EL0p72}>qgp=`|)CCdnf2z#LJ$FcS2K(qAWt4Zc^?=^2iO=R!}6? z9(~Caq6)?XH_iF}#@x)!4tXHz21u|7v0!AP>8MH{6wBTLNb2p;;f`*{1tR0aV=9Fc zUM9cL0y=Z_1i`orME&=aY*$l)@u#X>!vww|j*TxZIFPnt@}I>-*3FWKUt~oJl1jld z0BPJRx}?jIb?$W@p58nJR8glLyY0dzK8kSIxY?5*^4Uh?6LJ~t=M4|Hu4Y_0z{e3r z1hRu!3fU%7k*U!~UYXh^+jePmJ~OV-T?bu%r?(A&bnu2U94W?Ea?g@i_>6n8k2F1b z8{v_@(dk%-mhw8QmW z54JkgfI&sP=Ucz>UfsIl$+YAG>`Iv8q-e6P`zeROW|7Yh{kruLmgf8g$W7)N3f4W+ zU8`g&iK@#tFD8`Q5>EFNgKA(R8`x>U3p5fSjNH#-R3D5oRWHA%9JwgBzS-kgFn-}+ zpZ$7w)ZxA%%}6=~aK9^2r)Xj_F7tF*m zuOyp8f|EAC0ejwUPmfZ)!$un>5Fda04M9?oQQAKSXlPN`WL|%frfZ6okIySMwCZLBoRS(F<

MNw0Z7pq6CaClc0B7B34S@ z&$hB&jiG~eSqL{xcYH| zXh%^Jw0k^q-O@Mo$c3L6AB?TZ5dr3oP|sV$O`qSlYOX)ou zxeo;JdX3+;tRo(o@}UAtyL0!LxM2v3C*HMWO@V9b!@ONFuGGtYbkqO*dLHA&h%S$+ zzZ!%pF|)mE@_=#IwBNeMd|YM_l2;B|58uF4HQzCHaI8F3rm9rq1ZyWL_$jgTap2F|z*9bE!*&8HK%$7wXUTN;a9w}OgVClao z$7|uBQ77OiR}wh9jew46T;=Pof*6JIYH?$8OV*i=G8NBHk|CzZRXXz1or);HN%dQ) zZJ>Dn0)eJO6i;C@NfkoMRrD@qn&ETN)Hf_WI(JHS|1qEBawU%rBAr9_`26~5-a^?1 zRg|TbSCBo*4)-5|E}*1l(_i_~F)EQL(ByTuO593E3i@f0((J%&Aw*1~I)4u3-VNsl zK`Ql^Du1t)*`|*@tRPz>caIXoFGC#?-RgH14c|(zHQ%DRqSNeKaH7j4;I0lWS{DA=T?wkrxkKP`AITM3`SQ-~YWt`g@`89?tQGvx zc_&6f@+yDxl!PxzjIi{zu@tCy@oAVDV8ugqeya}SJq0Is9p8)v1Yp;> zDGvQ%b0W)ko+)C`BxiS9BLhCn8Ig!h%MInikT|0;alfr|V9lcFwNrc+>&M26h|Qt= z#>lMKU0@~wEd*^(fRBpiUk$3@7K%-fvR34s#8;_0i-W1>AbRpJ^0L zP-Zz?%oUKnF38G`&)6I#BWwHA;o-;@R?K2xhI(bzt{`$0X^N^c6d$7O!=*$$gbU(vJ0 zAXBHyDUa@)P~Mxb5rUVc2NJ(aaq;iRuBUaO9gl3FvhOYpiZ)_Em;dn4zinRe81Nz$ zpQtBvbZAKLhTY(}7n*o2v>=MXfBSNOFUSx@teN_K-TRl%F1*q^!f1^oO5#O!h>N_W zDn~h|^ZHroe!ZIw+so#cdf|*6ncbvrZ<{DnpeGt9DBT=bkgmpN#zt@W5eeZ8Fu)&Q z2R?B-F;{3*7Jym$lO5MKdT?CEpIH%Ing*@iBMcsdEpZT^_pQ2Narc>tP zaYfDJRcO>u9fb+p46wszdUH@atx|>@xm<6qQf}uzCvb4%H#HTt1Cd=kBw!5OVHo%o z8dSYmbl*AglsZ8zf)(-eP3DE)xOprWGTuyn*k zJr=0AN_V(0%1_5A?k@d&LopHaZCZ5vkEiF`R~RDWVL5)on?yr|wG^QW;*|b`M9l|LddIH&!wIA4=WEsbm{ctObY{cb* zTRuK%OU6JI9b$@eom0wTNppRQH%EEQ{dC8y^@J=B9kYVp^qGw_sMR>&Lq;@SZeg3u zY0C6*;c6B&9CoPNtg_vyuo3pJZ%ro+_+KYdU8e$h|bE#Sk6#FMVm!G6R87;9orZ+ZI^nn;)uP;$WNB(J zbQyVX+@6f0x`v#8Ey}F49v5QzgS;eLREP4kfACxKJ8!8merckF8ya2iSf&p~v2EOa{U#e ztM7qVc)IlZE5&5pmkLgsFlSi+B!1?~8l;k-<0O@YoJNJ|Q_ zP!yAq&ql*#bz#6o)grhtfVWi+o($z&lKk$``t}hP!~Jd@l9%*S$v8cs^(3BWMS)CH zY)vu6UVLIN>D`#saK5L|brLGR{!5&0iGwBGd6bM*WvRD?~q){ ze5QMJK%SHKY(qZjm~P2Zl4N17;*{+N@?pIzY8rUfyF$yO4!XH{q3jz!JHx$DM8X1> zqsA}p2uY-y+IGTXR&(8!=fq`^y$Vu$9ObKRW_NP&70Fy9!O`8Moh@+xb%eWhw!){) zZ4Gt%l({%=(Cx9)89kkl7J@3Bs#SzcNV;Ci6wJT_7VH{=E>U8HdlH?iK1XJLaJXvi#7^XtkdOZyydo129ZmXuK&YeiSmWU}^lqb!%T2ym0-JO~xi`*83f5KfvAn7&(GlI%vPE~aT77Q-4pO6pB)$oO?5D_jb!JIi}-ymcuNNyp_ zCCdpMW5p;^O)l`8z*t>)cpDwQk4{_5|aVASj9zzdZsZA%_%WsV&$BNgWkY8Y4UB`{Cx z>TZK?*}=DZ%9{%a$VNn6+XTd)9$%wAd{yutHWB51#sd}uCV^*M42?kA*v5Zf`!1jE z<$AVsU}J)SrF_dEM&JGQyuyF(Wfq-@b81ULBQN;|sd}2~TJ#2-#Qb}(@24uKzUKA> zW&24gjH=&vD3jl0>+8R%>Nac`IlhJfBf;E4DWBb?_c%5KL9xwkV3=`1+PW1YYcKpr` zR=ofJAI5+|h$F)fS+JS0mEF%@7+f5IWH<>4CM73*ho2?CD2ADTi!=MjQTcnG%mUEu zzf#s;EB{B6UgqC|(0(mt1Cp=UfW!PdEd4DA?YB}Oy^|eqx%flruPpl4QdU5g%E|Hv z(8~N9JO8be6|maZ%Jssl`{RX`}h+9XZlyX`-4XRTFL@E@n8bf=6~qxuj1X` zN`c%^*55^Kb-am)vKWF{_spyvZFX?pu#QQ(8e}8_#F^K(iZXsk4vjVbhMT`w?jf~-d z)d-GG4#xV{aBhnYn%0g>>_0@e>*;$kTdCL~9G%YFe9bkUlDHHtBAJp!ds^mUjnfi& z(FGf~U%%2<=Lnz{OfKU4qR6~!i-7J1%!?^yxxR-@MP`#L^fF^+j?YqjzeLJHu!YBR7trY!p%s>uW5Gfu(mew0hmf>NE0ki&RS)a$K?D3v? z0y$144G#}w<8hIs%t|>YxZ1qPC*90;{yRAuacSppTce&%3s~DidHJ*tlGTzpK$7A+ z5$eHBUQ#I+qFjr^v9gH0nUFptSP-eAvl0r^b~Q9w_?x}uk2q{n0-3T-L$y0|$-Hg# zMj7IAhA%$iG)Y@x-&JZ?F;rH01e1X|xgs1OMq5rPQ7X#mqp>9R;|EQN`rRYZN~gYi zzB?t9T4;D=(&N&|*OO!s+^P{w;5Lbs|F0J^rQKlW4As6QlZb$sBJTnx56%Bb`*pte zjlQpI0}(7G+lR-BrU5JWhj-7rl65&Q5=^j77y%9=SKMDer>A>qI~gyh2nL&jd6BWo zpcB2LEN>VcOWls2Fhz6Qn@R;qb#!s5%sD-uot!Ccwzk?cNwno#*f<$BH6>2-y2E<4 zYvs_TRZ*;>?_0tkKVtb{ITq5}-YlweXCoSSga6LA8vM}CEX;QUp*2P1Ah|Q%el0_uoe)Z@|io6s3yG z&K7G|JLsQqVOOzWzOnm+5FG4Xtv3%1&k;ypKF`9Gs#G`m)Cghps@2a9e)b$Ll4c?f zsY)G7krc-FBpgwKftnQQLa!xN6RzfYH7Sv<{@dW;vxEqvb!g}*EGjCNukKD#<6HBu zi*V8sx2uSIb%B9oq@-J|0YOMa>#u#D-Kq=&4g(|9O*aqgZPAS=O4%>=#;%qkcBWPp zmEz3lysUjQ!6jykHH1WE%A(EnztYR9k4!0GYo%xPR+bTK#5rT6NeXyMOc=(ZN-H+C zA?1)aRMVWn$~)GIDZ~prn2-hQy;iS>i@fZLbT zNg&47#`Rk=woi{x$9QH{ZN&(GxP~y=TjT=F21-@Ub8RUPE^)Oz7J$!{jIt%Bl?pI^ z!GCLWND^^o5yJ>kUVaOsf4Bqz8&Hax(e%Q$Y86pbD=TA2T+2|bC3LjO>V9;oa};FU z5pK!{0piCj5PpFwlTEotjUdJj8z%|4t1dfBsU8=Ao>VAU?STq$5*LU8 z8-yaySf^7keiTe$GSXYMj(njfXx(_%SiHN?*J#(k)xbhiO0vJ5OG4xqRJY7ZND@w7 zjbfbiW;MyVqg|s#9y|w2VOgUU#YiOHtAS?Op)CBw!%;|pbvS+sX1NST4|W{Z!tt1` z)=}sop3%gdR#VWdTbw@b$%Oiy$8@uh#gx+g3aMc3G=5OaF)|5uRfF`c*EbYiIGeLu z17D*g6!?nVx7C87dK6JtOrh6N!9;oN;zT$~^FmHJj4-i9jB_`m?x^#8iiL|G!Wm~; z@-<$_Zr{H|z6-};keIPK9+o!p%^6B5HT*>~*r2eH0W#q|8s zXez69UU}@mIi+T59Ie8k^*0*RsX;>ZcJ$#McvN=C@weEDz_tG={-R93Ov^4KCH zz_!QdDj<}wl^X0&2~Qq55LPDV*z&-30>E|xz;=GXb`T><>RwbPZ6xlf4Tb}@RHJ(*YhKV)7|x55mA>kMGo1^2`5i$A)n+j zcD}=qy|xIVuF?1lw=T<1lsm3>NrI%8Qv+Sr>YvA`X<$+}6bOMcW74KLsTWO(TdJ>9 zZ7{EYfJhK9E6|S2ol9mwI%$50v86dsr4$Y*Ce!liOg1f_m)vqFQh$1d>HmSnzeox?1c=nt@KmD zgn0`4MPW84QnM#46>S@bv|6I@aL%0jk$CIXzg$P!)6&_|- z?4^A~E3Bh4J-Hj=fMB@9OEK67!V{`n!;Eag%vw2~;KNxXQh*aKgX5OS%$YE{-o z#0Px9`8Wndl3M?*6H6D_SeR&7{6=Sbk~U^kx_zZ|Go*?%3#-qo9M|i^2~mn@&RqIN zt|nASNq6 z@ReU>)Q8n+1qmJz*~fn>91bc=Of+{BDC)(ZnrZCGi%%cAUslEL6t@^MJs|!X1L7oU zfi7wwx{0yiLAE-?Xq6mBkv$p%f@CzO6~iX|momB6yWvZ-vVJ z9y4PgEZx@jYscMLsV`xffx1jJ$uOtke(ZW@yz?>aK}!;KkJ3`H3a5j{sJwmpAld}X zhY@0w-VYHwgv{Fxu+Z91pAkSviFr6>Wy!uphgSPP)AOPAQ^lGXEvVS^{XUhtLzZjOui;Aeb2aIkyRMg6^tL zhbQnBNiHC)kqLWIWGQ!1K5tCTl4o8SSt}ewjd#`t@mfE=dWd`tj0e&NxaHZoO|gWD z*&VoW4oX9nqOS<5Ma3g^ZCiEa9z!3C?qV!|cRJL8fayoRk=%4uq935v8xI#2#ROFxgm@!|~o zwExc1TbrGx#*vSU<2}gA$56%EkJYha7;A!~P04y{G$@ZI4}}pKr@@I47i(u0EqBT% zGtV_F_8BGBO>M)okYVmj9X^=zn^rax8B}YsdWueKqYJ)v@8e;~OUD@l8=sX2tU=Rv z%NcJZH~Lp7Bu~*oRkWAp_KvN^q^w$2>C(TOh_YcFK*YDxe6CrJiAx`8t$?tIl-y`c zSt59w6Ow*CDbjtTLyDWD9=qZ9l@ste6T&zsRoI(2se+=MML#zS$7dN~Xed_l*l(Abn-aJ{K3NcQq zl|3$;$iv$EdzFzIe+by~@+KUUQH)eLXYOZXEU>QnE{T9sG{|oc3W8Q>Cg^GHdNK=Y3*N@QTpCw zh?ndAL^SX;r*^Z`_^Yl=c2~2H31 zL%~C?uU@bG+&h1bWo;;NAtSEYNuLoSc+MxpnydTaTn|AmxE8XiVw{4 zRk)-haz(|CK?%j@m5zktwK=dasqFf1*bq7$WN1KzE@pVRd=F*EZ4-QQyhNh=#t)r^i4yTi;pt+qb z56$D{Ik=DpQ5HjXC^2d$s~P5^Hjt_3Nj%#3dJOR82uN;WRd+cqhqz7`lDsnEB1TWJ z>TLl>bc_mS(x-EGCOhL>woG^~fxdg$S3Qiiy9-atRrZ)1-;Q+Y=dc}EXC|MX7x2Kj z=^4UtfNnXTSZ{NUFe;&^SG4 zh2t>;?Dc;iBf!y_3jo%?@AT(s_s`SgKc|nZz-jm6$O1D~3@}{yhm*G=A;1e65ba`o}mPu2o=oHw|rJN+GU);>OzGzzu5t&S_8$t&2+d4J~dko$(2JtsOy5Ex7ELXfd5!Vqpou``&`p`d!5LftU52DTj_dyB>|WJZOh}~LI_d_ zYBUkSU+>KPB~-*!*_KqQo&ue5?QnSg$3|9#RStLe;^eMM-)00uLOqh4P)>ue_!nvi zN$}fWc46FaPX;EspprG$u0kRN%+j@d{FqQ0uN{0*$={8t`_R)@GCa*}z$SL~a~$rf zMos5?CZeI>bZLALMMNXRFQE%H3;%n zO$$G}K?~R(?W`*WVeusmnPF@{s+X23BcVuD>|}FP_4(n&v%B_UA|~Qfhm4**)eFq3 z`4pciaJj=NXdFDLL5+m16IP3nIH((ySyqG_GTY-6N<8dBCF4EzvVGe+>s1izmg0c~ z;!V)$_mmFMETzNkJRfKT!Az>r((#;B3%dPCa0ze!g08~sx{EM=&j9_&r#m&#W_a%R1`if;4I8{ zmaBzl={hgW^MO_At7*E|jX=Eanwd%aF)KU>_g27yb&I}Cc^RW?-@EceL6JgK6GgD% z&-z=^##p|zA2i%fffdgsWe|SiZvLM8``D@$vG_Q8=F-Uh=m<{&M&|b4h8$d6n#Grhz&pb2y^uG`4_xJ_|5?*q67* zeQoaQA*BcwhCDSfg}lJ+;@Jm`-Gt) zD^xWhbg_zy2=7B=_5NP(nHzafzA|w+59avC43&Zu}*u6RF9r*&A_$Y2VwUDYD7 zKJ*aHtYC`J31~7IQ{B9Z{-8H4U2+_VZYrkWBf5Eu9Pp+8PtlxE<$0-oj&0owD zNAr~`P|Z!ntZPLQuQlMvhS3gVOz4q!WX6%dxDhH^Eqx%yhLLhUjkI;&Y!9kThxgvy zijCsP)mtv+>!ecOp0O&CMuwLEjr4nClZo6y8l8}+<~(iwPMZN0xv8|&RS)74xq z$a3!UZDFJe{H&HD+32m->6`T=i+3xrRm}1o%QpAC3$$Ef5z`i*9xvi;0n0j!+Y#_l*dL515LzVAAdq;1Ay>D}72T)kjPlbtn*;O9+e6yA zLv19I?y5vf#fAoDn>^CU+0K9&V0iF29wO zoENeskyVa$6KpRLq{9wEolV6V+>dT^XnZl<;wKhIbHaNoK(t5-a=| z+P=v=OUPqO2rp4-S4ayc^V36?EfmRFlP#4=BU=1G=x(SO#mxp$ja$c}YCb|EcoAs8 zZ9UepTXZ-W8KcfIq`I9LE_Q=Yi6pdkfW>QXfmt1JJ7_c9PirSOYr*z1u5{)#joKp< zobY@dlY@1u;%8m{;E^-2!VDAjBIH#i{GJ1lP8(H(SEjxoaQn$6o@aS@Qm}kLXTxU6 zmV~YE?a(%1$w;{Q#VHB3lYs(-$?J~{IuIzWVJ^9B?A@G!mrc3Kh;h{8LVO!Jy`mD$UqpfG%7z zIvQ$gpbK>W9;D0nfMT6;kIP^=uKv?NsQGLn?@H-;E+>&69F^`gI#E>}_jS$sv}n*a z@?m?B`;59~F+_gk#s>w4d7$=h_I$|}cRuqhy=Kri+L=&rHc9b$b8re@P3snX;Uq}~f)uk`F ze4~ZS1V%}0#p>3;5<`j(x##sRaSHFX*E^Lv3IeGwoD?99O-lj2g><#YoS~x7U1;vQ zrArtn=oSStJXLh@kDBC^G`p8YLAWzi23fpSTkPJ_S%+_San2s=$7X!$?O#H?u0KxL z(yA|4bZS|Gmg2p-TxC(#evvDaC8ZH*nby53g1M+shoi=lQYF}TcN zaN=EFf4bM)u0d;cOJT?rduSvCKk)pnxo1z}(M(cr{0uSRxlspo3JMfigM+PSx?Js` zH-&Lbb-iL-?@U0koX1tV%2rR3ib_MPc*l>C&bxa)SiKM}xmG7j9M=qp=ybg!pqx8$ z?s{tHdQ7i3s8HZLl&%1+Sso7xj}Q|~aU9|M=3P0zfwL72A~({kUTBI?Lm+J+Vxpyi zd;!zV@s^)-BzW3H)ttc9ND3M(o56W}0-wy8YH?=oIxju!yqZPcr!PS-h-$`xb3+

GB1RCWjIxcH#q1M#XNp|N_^npI#F5I`TG0(u} z>w2jh3f|uN-733>>{jcj`FXw0ftu_~FXrcL|DyP?43_+1IcS`5IDH%s6Ap9KMgg9+ zn4{)4e71%<>odpHa*fVZCHrbaa05T+Ae;9Ol7cNLJakHw5XAmQJ&DBuJ&9f~#!)c$ zh~jgEP7}52$tpbl27<)dh#U2s^PsF3-zPF9_nE|G`4aQ@W}OtbX{x>;$lQQ_J(xtb zx|>5fiMx<6DMuU?s#~fcDAn5^FY|X|l{+->=GH>o)bd{=UX5`P;3*RMRNu%1vd$I~ z#Jm?tnr4&9+&?)&7=xtnuAb2Gkd99ce*&Xg+HHdyglX(S9hdP+YtaIR9jx$ygO&j* zMFb=X2fV{8P-rwy@-|uRwN$fOa-VgVMOm$VyO;?1;>Qo+*!X?0;&NKq1t~*KOX+!U zKp^hW)ffU58rPc3_f~b9Cf{_#a3T2cJ80H$q$J%EE+Ku>BChUiC}2y};)n-b^Cv7> z+4cC~LjN*}4C&s}@5wkfUz{w1j>h;czs9Q^lzrP*+5KRdu<7{FHFH>;Q3n%02W#1sh;cBQ)IbhgO{-|ei-eA!a z`eTNw+s#6PoTKFe&$+$*h-vZm+Sm0pG22Ak8DwDcitlC4mvW*Dc!{`e>w3)~Zc7EK z0U>iY&i#kt<_aWetNAQGjRo!QDYZUC#tPP>m$O{+{%aPGU~~E0c10rLJydT@hw)!& z=3|pTp_Yfpqme1HL9$n(Kw07qP$Gy|dI zDWGQk(+55cO$R|tadU=YrU3S`4%-f4tk)LEXW^Q(FrBI$n?kUea*t13AI-v_;ZuMN z?4R$P|AJ5bdN2KrPqF>V#D`;2FgLR@7Pa>v(f#?R&jHw!vI6#r+<;7sn+M1OR|5Pz z?OcGj;%E32pd$Q}PyPDvA1~nlC7)sea;({b*Lrpic19i`?U@xw;^zR0X|Z#10KS|* zyQAuA;sV%_{=f36KiSK#>HB*=^|LztKd1Q@@A*CQUnZrq{eg;p5B--(>3=8}e~bLr zN$EgArGMXFPQdb!3n)AECqiNW1Nr>k>c6lZ<^J1|asU;%xPWgx)94?>=eI`L0rLcA zfK@&d`d32x+@WCuGo@_I*sQ`=RKO)(GsjmNV1$u6zKkLGA z0lfM5BLiII{(4aVdwTd^14E9#BGP|o7ukUI_MZYny%p!B2GpO{1gU~*Sv>17{vaK# zjg^eMoRzA&`^yUD$Ti~H2QnY!R1}umTAQy)MB;)cwc-b0AliFO0v?W_g{OvK9w&y_ zo8-ksRTvquo1^y5aIM!2m6muzc8ca6cW-)PgjgI?->aPs-N?2v(x65gj3z&&RD>(} zaRB9!6+V}Xv)}NyeYAFZ@^f>)9J?`Ov^WoCSHOvrIp;)q`q3lwh^x;S5YeV59$av6 z2A>dMl4kIo5l2SdI=c=#2K$XoYE5oFQ5n%Ec2se=ne{7+tErg;(Bv1asrJ>phG~%- zd8-(A2iAk1#9zb*6FS@XP&V+7c$NzLnWX$kIhFGvCrt1g{;B{8Nraw=;HDfX&K}ap z_L6LY5$)BAMAZoQk)fd99)o1A5o0n@+_52o7;QgFUIk2h?byu2?hVyELtk_c&9L5e z#-;ez+l$cLL3|Z|7>P+-r`A!&7V=e$h$$TEmZ6^r~ z%RuAS(JV*ssR2oQGfp10hPKLl#$o%*_e`86np5}YnL%XoPUmXn&Qs9lIq*yi&UQ4u z3%2$7X9HJWJkwj&ctaje&8)txQ%WBVUVlzWx!;Y9j7Z`hCg?8Zj`R<-OOg3vc8NF5 z^p?F#J}=(Ka5ryOrf?d;cwI=Eeu>Cwsz?iwp3FSBXBp1K!-i!bBDZ2c0P>a-#3?tQ zp=_0vl_nxO1^?yd*iqNv%KhW|+@mPmUgnuvx25Ym)u ziMl>fYbAJEdNR?slH!F{sHjAG?%)CQOesK4G^5< zLEK}O&{&{hjdRL@3_es(KnUb2M^u67aYm}9tU>Pe^BUg!<-VNx);ij%gKXhCJ&$tF z5IN6TF6m0ILGji~t8Y;-h}R-raZgKb>xdW2sBnTMrX>AFA%+eK9_{?=y?*wp2O;F< z`&|0((OmgPk(K^|FIbEt_+xVD%PMl;2Qw?(fXWbRgTg&%Ni}=eCW64}z&4~17^UM0 z_(PW&jnC8K@HcQp2a14(-gP8oxYY)SyddB^>ij@JdhVPnqqB)IZ!udbZ@hx1MxQdk z;}S*b|Ap#MbLo{*z3n;digiSbemxihN7J_B<^KBPL)T>=a(&GCQu7brk~oyq!5nJ6 z?A397MTnr*T(+7kmy}8PDOE0q?8cnUgWio4m~fOaQa&jW8(c~&|J66y*=K9HcDeiJqJS0x{p&2hefzqY=$o(YxgV#J7U6_s-=bp0AwDn*!o z9LejhlcjykzV=FSsaJIF+uO@mZC^8L{88vQ$L z{Wn?2<;3*fK9sBUWz6=nqQk4(h;zp{Qsft8fplig7n0v@ad0}TM=kNzBzPl_tu~y9 zP2mUCgxB^=8Ffs5{jfVIgA+Qph!)>-aJ)CO-TO2{&N%wz%Ji>(%;j?<72Z{KG zwMs)Ow@ZU6Ks`cHD>KQ%#??QomX{eqV?xFNjDJ2D{E!4rxfFSU5-L9ao0xtJaN;Yx z(~9PNwW-nsDDesg&sV>L1W>TRKwQ25xO}KTb$ypd_b{^rTK6>V{hMeJ@gYWP9*A+k?opvSp6}N7&Uv)8W{qDqi8rt0K6I*h zY*0#R28&rsTgNz$>sLM^y4VStq#Z+GO5=ti$cK3s`YGLX_4J#ZfgQW6zFZlVF*mIn z)6z0xZkd3K1Ny-&WHVUAz0eMK-OlyY;d)o!-OoHimXr_(lfl@=^IL>ezPWpbol){j zH)rgPp;W$X9;$+@M)26c9Cix0xdJW=DnUhZOVdo2TH_Bc(-q=xH~Fo#D9F{Ss>4So z;3AR0T!n>sDVx4$m{z=Xq#_Khp5YZwg>;bZ>kKW7xa4q z(2q+c%06?lk!?2F7lk=N7D45+cAq~O=CU7$8=7U)Od$m+Z0hU^9aO^+!n^gb42fAB zn=N02i;_QyBn}e}3V1<%VH6>Wl*CWe&_zLAn*xEHZVe(qz-z2DAw?yhc$}=T1#)f; z3b%CdNvoqP7xd8oZNV6t==}O6ZYRl6(o=8+$=0cofITIDo4G2b5(;DjwES++4eG zS@TO``5B{7hZNF2<{(E;I5v!LrlGdXVmVWDAfcB+6%}LHp6Vailv>l$Vit})q7(S; zLBukQK2NDO^bSPC%fK3`7$>nfUI*3Ad|YmsPV^i<2n#`8xTgi3Z2S7D#xekrHxsr^ z@ruWLk*K!jaC534J^P*XnqJSu)^Yt#hxm;}th)9geNnA9{sMuMWD*okvu7YF3QA!A zH3UqJFO*0-=NovKnuJjhFwi;znCnu3;hl5CyG9p>&P0U4j?4YG^Aeztl`50CD%l<} z`Gk<`EPSBgIm{KgyC~@|Fca{iRLMMe$?8@`@V0B>59(p1zN5X%co9TR(mrNA8PP>8 ze2GEt_+=rWa7KpOxOl?O(Z@C+cR<=?f1vI=7rYB=T{$BH>h1mH9Ckc@>Bt1ZwLr+t z%JdFkKFZ=9**ARSe`Gs)I$R5NtxfFq***2uP)iG%N#LpoEtT^TtmWX<52fvruG!hL z;bR*|<`AY^1Rwj$zJV#Nb^ zFyK(E?ZRd-C8gj&OqMmtoR!fs+HbF%JTh6zlA9Qu+}8{(@Zzs(`cF-qvzf!M27EZn zRACel+Xt}7Di2w~EiNl9+_g%NI;A26>rYn72tAy?=M*@W9WwI$ z_3%xJ@J>&?Zb+(wGg7#Gl6k()7ph|xnEClSVCL(9nV|3L7(z>Y4 z&6e94T@+3o=N59se79e>i@=(O=D-k0w*@?79g<*Q+v?L=cwhWOigdv`y9B4C%xfVBFbEtLYu|}24f0LfZA>soF3Kf0czF>DOR75g zd7@WuCYGB#Ne%mI^D{Ugr$q&9Cp&G5F7tO)zgYoQm?fTQ(1F5B1f|Sc*1qG)-w2lL zNxfK#dZb~_pdLIP9AYUBk6j;P1)idE-ADR255M1z5#MU_P|6@Y2#BsB|GWXw4XU8Q z&l)4TZ5M>yxmWk~1&H}V8IeOGMs@+Kf7uo0R64|6a#p0yjC|Gg5VELi!!!Z}`-*=9 zxWR0gqL3-MiTX(O-L^x1(<|)2#XpYXJB~u^TZ|Mh;&yFEYqlg%6fFJJbAOloy@udi z-w212mxN1-Apteqi&yEiN6v6R{mYJ|-E3~5-gz?(PI@xhw9iJ#f|KeF{F6q7`ge6l zOLW7&1{H$AkZ*gteRW~xj|y}4g|gBa!R2cnzM(ZU9QfpC-`88qOHm_8!!Pz)M6?mh zNK`R~bu+pNM=jcXnp(YEz7SvUk%jCfLcdtQy^uU=xS*w!q38XSW}AYe_>pVw0QyD2 zxu$%Egws0>B`02NN$~f4P45|`*+A2g(EIk8S<;ZACRO(@zC)25yk1aBE5{w zH9if7JpK(FSq;nESszM!f$7q*OeQQUVkE%6ju+PcfB*{CdrD8<;0%rY-p8uoR2jav zp$kFiX+H~_3#^QOq~8prMsuo(&J#O^b*Xw>6Kn_!Ob%Xx^4*)GCJ7Qzcg$1EAIdE; zJ7-;9YnQ&}usXd7S0y0{_7_r!Wkpi9?ZgVwqVX2O50~95VFtW!#rnsTG{-tp@-Qvv zF;NnF2z%S}kybT?SL~1b5s#L`{lAA@#BE^Px182W4a*?hrDro!z0MYKHc9WR_jjJ> z7qxeP6xHL|9eefK68>u+SrI?7VW?UP11YHA6q4={)ZQvHX0Q}l13z%z=x3zv5>&2Y zqaZUSctOsIq-87k4%gu2Ltd;rAgTav9b69!s32=a+h#N$8@Z89ffK2cJ=C9`NPFA> ztqGGJuf3!E3NMk!g{grz28}fHYd81mgnDuL61g3u!Q-Xg)1WPLW@$&KYCr@oy?P_! zDvv5&mXB%vRPTFh?w~-}BQbXM z`y<2pT3abGA+{+s>n%K}6LNmuT=)&OAb06p1`}VaHmzeR4i+y_Nie@2y;u~&wtvtW zh)wgVfjXguqD$c1-1mMH^U!4#jNnG}8F-M>MT;cNm&}WqYiQU#c^9UR8cvS*ChPDL zwuX+jZcAmfkN{UAH9c2Dvj0AmOv;_O;eFSyfha~ zEB~-`O}^hv45G;iA){v$jF3_jX#Q!${~*8J%YO_xCr^C$>QkmKaU5Fb=9Ws{qT3h5 zID{fAIUC_iRQEjmmqEvu_q(7)0dC^c==iG%waOE9?HME3*flp&uNcjW&r0=5^_7Bm zjAkM-9>--CZ10DWaj)6n$wClWJ&cG!hc0wm+mRnYp&qaqa{~*hE`@YrZ)d9>l-eEq zC$E=%7_V5Ch?mV7GWFey7>=Qw**{QFZa~u&IjPQl?g$Cv!sp*y{VEeRV)w1u=={Vv zOY=$%orysf1nNY3WRl^q=`?AEhWvV$B3~hUjf^(!&|`{WBAYpF2GWy4^~8D8v;&@G zIr;txLINE&Bc~Egwk4 z1!~uDumTnBf%@%ioXh}+XCdJLP#`DsU#w#P!?b*3R~LK0)0WZMg3-?0<@a2Apd!t0 zXzkZj{yhd~VFl!c|2~wHhm(;9@Du(Mu5tVouKnV2zqQKw6Y~QZ?9YV$!99Nu1v0j| z0cq?rp?`4C-$FUKe>w*LNdtNQaIj_lJrby)1=P`cuF*e;>F=Q&fS46H&d>Ds4{-lm zC_4|ZHS?VIk@*iJ+TT0O&dmXI_|KuTuyX$ORC?~%umi5JKXcgs>@eqF8RoO00B+^v zcy5{i+lha_nAm_~Se(Gt%QLP1-8y9ZX|M1sLq&sy89E2|4nC^fju+eiuU^yasJ8Ae{1unYXJK*!vt2t-<@ti zl{mmQ;Lk>Z(7!v~er~8d<4X)|Q2ce_|Np?=f$slvX8$49)RFq^xQ`VhqKSKv#t!UU%V!Kx=UY=ecv!i+t>|*;y5rd z?7(e5xRKB$I)eU ze&?G-?*jDjKz+M$=rZ^l8}>b%2=FmUrQT%S-|`9RgYODuIpj}nU7+^1OQvNBX6!*Y zq)tDqX0`C$XomeV4#-fH_Bm`+mMOvW@c20jZur1`r?y-u)Ue&$W>n6+U)am zw&5TrDwAK!O=y(1mJG3)?_PV+V6lKU$Xo_CyPCCj&%6Quj#C-bketRN1yvvpVNU{8 zE*Jr3b$M6%*uOGZqC!)UiXlSEG)qc{Xs)y-cY}T=eiE)8wm! zhLKYmtUF4>DS6$A>V@qRlXG#Q;>iwm4h4QS*O#AMm3K?(ilbT_VcMO(SI?pr4+7PE zZ6xGAV4~wqtHR8aI_f8s9Qhp$f9D$A#yb5PGfUQ?tkHZ~<-`U#PVIi@wo$vpHh}Gy z*I0hFRIBSC?dDoLh~I3;_pmkK`mGT>U<9w)C@kzKnqC$XJtDQX3v@Vv@YdYhXAYZ* z$>2+ClLwEACwXf0N9{l&3vm`D&l6=8D$oT}S|+sh1WGgdZkzyPsQ|Zulz6xG_DF)P zTzziQqs~_a`q!U2r(ALhjjkymt3TPQH`fmyb`Uu)TS*<(fqzkT&~085+OmN1_TvOK2}U z6)e?D;L*L6FxwBW8m1-)2~$FFU%g#{2L)w8D+nU08>KJGwUuVDQ`S6~u_xZCoqDs1 z3@Tk8>eWWDg?yFAQQgezj!d5QS~l%QH|D)Cf_ZzD1MF+!qR<2yHhwp>D0=-8N!g$j zqDU-7J^I#w2C1kahhRM zgUQd&+mFL7n-z>IFSJ`wDBiKbq7f}ef3e@c_S~Jk4sgRr-!&duPkSY2BW>c^K3f?c zpDRCLcICrA9BzT)s4{|~2%cuvRivI0w-y_kI)4Xvb+k46vB}mVgj339OV|NReK}WI zKGm$$>e!&I5$}#Qyt4C-^+LjQ4yPK&@(edoJJ%Q@~5&@(`iLK0`#l zHb`l8a#uNT2it8C2rC29FrgIPW`Fj0SxG*g;VRQFrJ{u1BLWv$`g-q1?a1oHgOWtO zW*?K;;=Ha~iXX=;0f!nXlCrbg2(f|0!|p7tifyVOHx!zT4{OI?2uoyD0DA|DS=D%y ziCpaX@#glZ-xMAZSAmt{@@ArYJ#AaYAAib@o zu32WRFh)!)gwr%z*C0!HEk`D%`on%pCLNQRzWXG_$RKAm7k*Ik@?jHOj7)94X1F}t zl(u5?xVs9*YP-moP42RLj*L2HevZ{lntN}PmNt;Ls0*wNVK?SIU2&98Z4K)Mh%%~M ziRbnz83qYxNnvxpv)O*WPy_Al@;bO9+0pSpXztXQSP=*40Sa1Sqn5-@nTBC#AmLq#>hbz zbE%~lkxk?SxMBG5B8lvN&52K%k&@(4UZ%nNgb+@ zq5}BFu;5|BA@w}cdimDEvLo+BbYs~*xC||J{QRGXaFA(fbn@m$xq+d9Jci&`;^34Q zyT+0ifg7S?ZYjmFduDv_cRP~{N3mr=!0|w^a+mpA^NI_ zN4(m-l%b#12l^3nVYvwo!|-f(7L{W8<|z$t3}kR*Uj(mgsfne2Xh0`ooOVar;I#}! zzi+0V(vKWwy_`CwK#nn1BKJ=NoQa7=2 z7z6R7u1en^^QulVBlIRmh);AJj(h#yW%8SmrvQqPotvVe~ z%3zx*P#8xL^aR%+p7%6xE)FFR;AZcF>ZS97$r8a*Y!w7>J}l1~Gmecnud5Yse*IyV z)-X!i5h%_p)N}OZ{qdtVuEJpZUD;LZneW*ZQ0M!cfzwnIoaZiNSb%E=%ZP;3&$gA& zib|RTaxTvkj74A%KU!hAgAuxYHBa~oOCrJi{q8w)04Ni=U9-aVy#Fy4P?AuI9>>&_ zZMQHbR&4S^cKKZ0kfb-UU5jex%P-RJavVBBg0RP%s_&nq)Zj{)BD)JBtU-L#)QBt$ z)R>IQUm6&SVC;v?27vnCM}|uE6beTtjc*F5Nug^qnvE9yC`{Vm&WqGSD~h?0%dtI< z>nE4?;Z&GSlr+<~LO{jpyvYHTExB@8PhH`haa-e^*SA>eMSM78J}zg%m)GNV%{j7x zU{S(NsVN3g>|ep7#R4_ktkjCS@-s~3K73*3o}yhiUzDy=Hv+c`!zOjtTvp8R_D~@B zEe0n;S~SL_C6-t~zA(4rZKd@3hh*@R$`V0gtC9?GN~)j`G@7VkP$p>E@5UB9N}M12 z{lVWet-2~zC^aEtIV7p?PdcXC>U@IKl5I0`h@CXa*P0kC;|ujNbc1*C27x3E3+J#! zD=o$=7eOX~${l^feweZ^CtVyII|UodbptxSCkIVh3L5xcWE)FY@N+RI@f}`87mU1R zQce&qDuN0mWUGXmhb?$~XM${od$0($xzT-vy$&8B9B(BhM2xTYeWSbTRowt7OGXPE zX&bS~d>4g%9MYX63HtXHNTTz8UE#VH=*LdCce|vR4&XlwUT2K_Kv1-+vCMEv!LSy` zofXhnFq?$b#6MiGf1T4YWvISBzg8gB*f|rxzlyCft|lwEvTc_Iw}ewWeT%%WV^9?@ zKyR^>|FKa}J#lqPdeKf33tg(U>gat;gcD56uGW|wt^DY2xf^h<_5>SBs;n6T4jkEQ z@;>=s5ugO$L1wUh@kjF zu{*9$2E$ER(Fhi@*fm|g=a|Eo(;21=acXhC+hov*J=vaQ=_nCrvD>PKS=~&-Y>_4F zg`VU`@u6nn&K37Ye+m_!NJV_iDJGOE;r-Dg*iG`46$zXzQu8{$73E7t$nm>P`oX#n z>#rrhKz6*Qf-Kl;(lNp`71HT2P8M67TcJ3qva1lvf}@3WJeBtEODBXOo0ka&vk+`S zKXd}&M=Aqt%7GCdrQB=^T^wmIf|8GJ)ge#O-nh2Xg>dwh&cb8s#17Dq4PSVgV(JzxiLJeXgww?iCP5Bcsu-5oa;1fgb)fwqgap|O6ZeTwGfJJ((4bSvY5|Q7 z4`}11$ncW#lFG~-O3kHGE6cq@-2SCIrj!m{_9`*BkA9nOfvYZSf&S1*8^DGd2dY_a zKsi?{&6Hbab`hU=rdPe^r3KmXxV%kUb@4KhpNB>Qic-|9doq#^?0n?n#!h;#W|r@_ z(>ghB$0?~x94GX6AMqIP6d3`xAs2TAJSTceWF=ou`K-;MzAaMcHN!T~CpTLI$3YVh ztCwiNGcGIl5QHr0Yq0lb1{*1!u3V2(D)E%YWM)V3tu`cj)hh9EMqnSm*Gx+$(^^r8 zM!93Jb{dw!I}UF&-lud7QLuZkO#3N$ad~QL-etn4u5L6|d$3e^L}LgN#^5BBh0R^H zHaD#Pc%3m;=^2o$sXyj1xffxV9HA8DVRl#IyJE<6d~nc)a^Ac|k`kC1gmbtfG;~JV z+N(FJ>xax{bz`@%+GnU|NYoralyh^2zsHkxkLc1qKaIT^J4R{6N(YY2Muu~H9Q?u& z4~5@tZTyV@-wWFNN4NGH?1;hjG;H-qY$+f^Nivh2#`kjBS760e%xoF|p|mWcE$1)ra#%*Qzvi{X?C#V=(8n86J%;&lUG3xX?`dp4uO!^F%B!MM8;r zIqzQMQ+ht(5+gNKY26rnC@HQSu=2!PgB76<_Z@yrYZWJaI)(O9VoQB=5`H1LjSRN) zNZ&;!pgwBgHXmzp~ff zaOh;{IvLV0O|QmPr0waWqSam>vgc|;9c5AxYPY!bX(3&U)0vt;iQK?Rj9wDqu)SW& z_rYp#aBY`u{C;u++0n}nUlB=&9{cNS{}2NHEsy<)vHnt5?3b}8%P%Q13jk(VSy=%! z=PxBPGtYmVDeq$Z>R*%<`_=RR$G!m&7ATw!6h#8^r-9m1z|Wu1m<_0b2Gkeh{*P*& zS=l+e7~9$c+5G>ie}9E!|K;4Vak2p^;Xq9>pkF_0&;PWT<@j0u41n1zZ0!H3jQihA z-XFB`*JAv8e$DwmAk!~c`FkXwZRU9n#QlP2|2SaJMREd?`Jcv|zk@hnmHt6Ue`}Nj zfMV>=&|vOAQRVNEEIiLTfAaikKl?`{pq_n3Da`e^k?eqr1p6~0ZmvJwa(`>{r$GVm zrDta758(KFBv6*_rz^lSp??6!-$GdcO3wyt13eS^2V4C;6i^tmKWjO`_1BBvbE|;` zz_QHG^YXv8`d@QSK-bR-oKin8cKOCbzW|Y^P4MI zn$dXii55Az0fmCdT(>e&I*I&kyg*_+v~}qFhAh%rXP$Rw-|F$P(MUx4UD=UolI3tf zY}xUI->kf)9I%3W>MxR4Jf~Nr7V3$=XkdE=Ho(=Bu?{OXvaN86XxF0+Ei-|7}JADmBjRkOeuX#Ba|#&|Tc z^yr&F5&3Y@xtE_Z?>Dpe_u=Mm&t=k>wKE?5S))m}_jiJ^h3VpVe%x+--zq00e7Qg) zNE%c<2m}8z3WX$P!BaUYm+Y>{vr(10isHqYT0hx91k5}8rr}J%NJvS6fklh0uU#`Y zD=QAvU_Pg!4W>O3lIYsOkeu~3ALUVFVaFQ#7W#(H73+8BOn01;wgjEYMdk%RiO8%Y zq=}{Xe-U9K9^HwKUwAC)bo6DkN`f(|(^9faIL-BM?Tby%!%W0C_f#=+QL%drW_zz> zeZ7_(X__ zDT7yrOfl-8r0$i==bG?}i(fZ#DJC6Qj?rMtAVIs^#h^x4=q2-+Wq=hm`79^lKY&Yp z9_ufi5E23mU0sT7HJTh|P8rc)bzdF{BK1{pL!Pl}ZjJS!o5}P#zH;@&(mAEb0JCBL zkWqX9ud3gE+LSsYAV_jQ)fK^v3EL}> z43^$khKs)D&B@-n#jg$Xc3l=`i)6kRt3%o}bkg!Pzo|qP)zAATD0X@uU157wAGJ=p zMFZZeD1l@X+j@k6r{WwoD;;%$u@&sKaG@-9vJ+iUAtE`|Qa;N7x7U~2Zy_li^^)Xr z)Yb#G@2!&J#p`Oni4&y*pX}aGY2LrJ5;&yQ*Q&j9Z>lLt&nqfLd`NE6DIdm3ceBySz8rSgu0w_v!>#K*N4K4Z zrQam+N$aUBJx1?lor-3?^$}b}3_hWdgLf}nLpBf9NT3ou3l55Oz`gUR#yN#d)154Y zkWZelBnmawmHje-(&fPSr3TtpC&9Wt%&l~ZZN6>R2`(a51uj&}4+B+4M;TQGWHH)| z6ctIBD&(?XUtG1?HfTI^haS#IdMFYU!u+KzwA!^8IA$cq#j&v}qWXuruM|!oUP~^u z1 z7I#lbyX;Fz5*G91Li_>;MLMp|Tjj5bk~({~mI63Bgdd1Jyrh|nNf3$9k~&q+!j(a8 zW1Lyo&oB%SqFX9j$8v)cql)iZ<)oL=XEh0vvj&$Ql3=7}Upvl&P2GLlMb*tQjf(Es zv2R8QJMU(i%r#ndke$Q632p;(fP7~;Y)r~+?S|l~t-|7|tm3avkTlo6m@i|;)91{c zhMz-^Q^_*@p5EAKgUHl6RL#X&h2n8io>YUenyAvv>qgdG9MkCO<4w)nb`H5ld;V7W z*A%wEUKX4WeJt0;4hX$_gp56*l|t|z9cI*RBnzshn;4Y}2lI+_NRb#oQPTzR(zMJ4 z*r~r~)mRl~CQS3vTnBR9)#!YdXeLs`k0tuy>=Bn{B+!z{32*?i5_=Fo{bKk0{w4HA8qCOokDfq!v zzZ*4_&P4u#E;6`-jQ7H??ToAD<8U0oGCQ|5W0=ULV#iwy7<5!C;L3^mprA!Tb}prc zO2@6Qib|(s;5OHj3q4dKO(f=(q@m`8a1!W*m9z?i&_4L_43izDCOii;zQ}3i9jkyC zouEKFf(!V{eh6v+1;s8A*;gl8aU->q1_DM0Vf%=S#FPv%ybr=f?i&7XIO1+z9!7-x z%*aGqpNDNq*>^amsj1s}5h1l|t-T4_v4X(ox7I=GtP&%TaYJGf%}q^&l)ire@t#TF zb%m_i6}hyF)=vsxxs67RvC!7!)Bn^NC=lDiR$4pKT8h7Ql}YHGN4(cC3Sv)G%z#o| zQv+XLHW9M4?@y#rk9=F68ZRXpcB#g+4I91iBNvLcHtHngk`|f`yn?A%GgFZCi*@>C zWAn|G>tK@GUdu|#I~MaYt8BJ$7*jSw6y{(VHH5k`OX;!{sE2qNY* z>{ygu8fgsz3DG2t1bx}4;1hld(w?eQtrvyu5nrjnvENN>R@hoeXj|l@t+(|#5fe$U z*pTC-a7tFVs=%8X3By}+HB-K2yo7^aEE7oo*qMe;&Y2ehH~%ASxVTC%+*&=gZp&8R z+hcWMuRvM*m1Vdf62h04T&{}RuNvlr;;FQ@WHefw0`CMn&~4Kkt=B%6ONK#2Lpo3s zlC?cuTdOFC!ocu4Q|6nHa&f&$h4Ja#u?NrYS{DsabmumQgRK_Uf{~FxW5%r74DT6_ zWTW*YgCQQ0s4lj%3Pu`dHZETeUcI~4Jo2T#(6k_{)wJkrW))-2s;7vSZSSnoFCV&d zD{)jIjMJmMX&-U6cfP$&;9+Qf7;37j2TS)t4Ewlz`&rnX)9$m-!zulcMd)OG{v(G% zQAqtaH}$e+a94HCn6R_TG=4gIa7jZRI^XQC+AJdn8{ao>zs=m3_^7wHH-_dpOFul8 z8Cy!+kY!L1V6~fnzuJ&p*fkxFH`+H$#63adG?|t{_OjLo#RD7}%PWrTKn%v=<}3vn)K-}^hE+n2j#mOoHCKCGfn`q& zrN|`gGjc#l5lEtRabl#-nv!%xkl9%Z@p`-_N_4jpDQ<;1_3E;L{+^tYv(0?8|lz+OT7Dy1Sg{3Kue%VBcLutn@-Id;@8_*-MTb zZye9^CrHn)(tB}$Ds&U(hfB#ZT*Q(Yj_s=cS)Uv%EPHr{PAoz_G8AYz({>y%KGK;r zMfYB0>Sw-Qe^(^$nS~$p9vd$|2dwUfPc=xBDUs3pYsAWh#^xT)hCq5ycCm(`-M7yc z@nZW$29SG2reFuDEKg1Sjb6|Y7h_#^9@VOsa}ppe5D(`aiBBJJz2483)(YUITWIiR z?Mzo1^EeD{_VweIo-a0n89%{Mq*8tLQMk>1s-I)WMpT0_uNuc zc|8{~T6L1ysfipfC+B!ND+N>h+^h}~l zoc_@{2=KSg=jroz1SuaS91~!Hzrs4DkU*X@HQYecVmh?#B`dz3%h`tj-x*YKJQYfL z+eMMmld7Z9;^VO-Ggq^NROugqctEnf;$IoXBl^HhpH~ziql6!yv;K{|rP+7;te^C= zDbDm;Y}7VDDh)JMMN&KCiu>r!X{q&E_--~8)=d(v@nl&zJoh{Jh-xgJq!Bi0#-EM%I)25 zA5FnH>7`o%b8oUMoc_-06YD6o(Mh{w!({G;yg67x$VCbqxdo}ZJaZi{FvH!(^TBzK z;V`Kgih3231Q&JDVip<{^q-{SeoieuCPX~gGS5AN$so>0j1`762oo%J;~q!O(mc#e zilC|9Gk%w}e3bZZs+5~p9^UvCe`kuA>UT*RE|Gejsr3DHuUO?g-}4SVVAau=QS0J1 zNYLaF>CTcSvy*nuoeD*qCCKOS8&J8Wz7TOqrs+qkBSNKZzJFb*u3+;W1;6A)iy6b2 zT{}*bX>U&0_wM`^6z73R4)i_7GtI9nA3m>VHqdY}2L`wox_!;uOOPmKKY4kWNs9rp zI>A%h&FjxT@R2|dM@ajkh*lFzNx%E@SpN$?LQXMyw^Y9kZ<6;MV+GG%rs~4=r4inR zn@DyyBSy+pV30Ci&snP+%%DPvtTT68Q(EN6h4?B_S_HEhIUACuam|)WQFH&r z>*RF@A`J_E8diJmOz@XfIcVe*SZ1Odon{yyUrob@-bY46ZO~yr!bjR9V8OiXr&C@Q zm8@QHzJPeg#wA9}%jK_>>g}99sg!X?s;4JZ_JP$J-Mt9zF*pH3SmdSQkkKYM1LQ>p zg!^KM_5LAhj7>pdEc(MM?ZvHEv=BMS=jAb_bpEhIIp|umMVv{n@jNiDmK~! zO#AJo!>elaRWh_m6S;ZL@Q8zGz9Q)J6&A|+hT&aM-Wq58 z4n-W<)Tc#$#UpU}}PW8#GCJwqrJoBgTn4 zwS91Qdq2f(20fIWzu<_&RTvE8RF2Fx(6tOz{(?Je1cKE&>gBlpjL1N+`V$#Y$TAlP>N<4B8U z9|X8&#RTMq!|Ac{E1?_Gl$TQhZM=J=DX?0iA6ED1aj64snw2MHL~6^p4_*lth)kni ziRE#^*w~H$=@-@5J1a-!M|PUuk}n$Bk9|s!^^wvZ_IgYoj97b~e%zd{d|kX~^sF)5 zVXixD@?t)nzH?phIc`E!*uN{jBkIe26YV8DshOa$MpalNe@-V`LUrbrhiP1>s)M9y zIEI}~#oBLrUXQy4Ja*x3eRsH>f}`K2WWk5CE-(@4GilI4r#I)7z_)fAo2l~iU_lm4 z^}FtY(!T{g(L>aksV7rYSo+Mt6EgUgajAo75nNJwhreL)FqHR8gj#v6m-YeQjzw%| zcZ|mqA?`ipBFT!pZ@mde6VzTS+_+9#scl9XjFhmWi9mVB`Ryjgrs8MgPK9gVK8)Fb z@Wa={rmBW<=-1nH`+l#>?mnxI1<1Z#UTBW{R<++EeTfO_oq0OpYAe$7B9&)SsP59w z9>28eT5Ge<_28jyw(X6oTm1e-W3k)U>kZzo>PaBjvhe?uhRarAU>gCvD&4O+D z6jLk9xB>J{BrN^p*;DLBg#H)%AHQ(hZ~Gry|9ka0 z_j9`)zdrm2p#EE8|C{=p6~L>2Fqo5-3(yvGk+5>{Ffs#GtT@@Y0h17xe-iuuP=4<2 z?#}3B?rd)CWNOK1?DBu>!a2J$x!Bv=Iy1d;GIp?Zv+`p4U6;=NhaULXB>z3v|LFz$ zPp+g|(ukGK>5eKlD!1`=~H|{?m`){rORF*#v*}4CUyPq2>JFuJe zJY?to1G4|#Dl1TZ51`?{kCpRJAL`#C*|>Qap9TBCqW|~DlnvMu;C^P3fK%u1BAEe$ z6@cIW+1tNcfviBA&nHIk{PiOA-0T7s0Rg4YYhAd%zQeUo3;&42Xwzuq?i(n|g}&d$JC{<$pvv2Vf(WVHN; z`zA-ahVe_>@7^3MuGd$Wm`LPGKgi4&s2}H34H)E8rF&Tauzp26UDs5GuX`qY=5ls~ zOd_0GWp*{){lje=TA2bOkRqHIWYPqyQ*pS;A!(1IpG-ja*uHZCeY&+7b-5{cCvWO; zcV^@pac-8m2$od!%%>ZEtbinwy2X2E#xCL9s63c1hsV7B^bqOYZ$~CHuG~z;1y!_# zdc;jtpBH=DG~Q$uLCn8mxdM_$Jujb*0go(g)QO4U?x>+aa!qknfGeYANq|1%`k#btpv$< zGLY?hCt4n?F1x~F+<|KHaR>=$Y+>XnqGb$X-x#@MYLohrl7CDar8keIc9Ay z@ALm*?Yjf1?BD-OBBRX6rbNj)&Tx#B?3GshDq=krr)Iwk#-Dyv9tIQ(bjS*jC-r}5$>MfQw+ zLcFmu+(mNrU`}AHe(pYMF?#tgvx}dyzmDCf@#)hTpa^wcIeMKZM+z44acwxjWllz& zLxSI@Sl^Vp^Pa+aW7GJ(IW*UK&!78BSi)AXg&(iNlk<)huWKNlyS-gRTg_CQx|#3z ztx&3>8*R?xMtYuAQT(!|KT6!B(!5oJ^JL9jU5|#GX5&3RpmHLey7IFQ1ABx#6=i+z zA@+LWGkDx=lm-eHoOFv#Z+rYKf6elBDQfP@mow8VP}hSBMBXWWJ@roZAq$q)l_t%H zFN}E{tK;=cp{=1&I#xb#v%oMQIGf{?&4pZduH5uC5lTqnDfiNfI+9%yjW$1h>beqY z#Z`ogIG0qs8>C-1*t?7$J$W$f)6Fcr(Y*0l&&NI!HO8NVbr4?$>{)&3ERcsr9jk_R z@8|zWPc2U#rPfrebG_q-ng7vCTC8-Tq}mdE_cIZf0`W~{;QNpl6(*)A{qo}1tkAY02{&A%pYjOH>`+`yUTaDN9|WINoqRSYSftDOD%Cn!_TAtgF$&n(POPdouDe zTx4o`5?moMVmaJu!fGp#3-rEUWIsfA9L^Ncce!)UxUB>x3;ob{NC7&1d0z|#KGS37 zY#&M+^LKln^2_$-DIP3c=!(%$jd;Rm6&GsCTKZAg2*OvVTYSLec5VIzf#>2;x-t*A z`RYtk56E$6JI|1E9xaOAliE@LCat{So=uTJC-=ECVZ~omB(xH=mwaziojda>3wh{5 z0)70EN@{XX5PQrqId&}E?R|(5+zW5_+4lkPKu=kz_q5l;9!(HW6IkwRc&ok(k}K{m zl^)2vdbqHXF#JhsNx_wlnq0xXf_pC2Q|CWec^s~N67eOa)h#HIewPvHO=%5^ZWikq zo|uEp>4(KLn&TwwB>jU&9PPwyS2>X+0|wMhw8QIV(&iRFm7ar=q_lLkL0{jRwb znO#bvr&-@joJ%#{QzEF*J_d=|tC{dQo+~LRq@LwNAilTxBR&zWBf6B{b*t55ZnI4C zsYjW@Ml=%V8Bf95=n9(nb=#}nX8ET?F<(1UE4}ylf?W%rQn66MYFFhh=I+rzw#&2p zd|#XJAD)*oY@CsmEK)H$8x!(QtFBp_KQrK=6t}+BJfEG*`&w34smBM`E~Uk&N2{9U zvaRgxrYjR_C;xJQDnw0;a(^MwT=2S<#iiTvcx%By<%9LeyngnFvVDrZc+%>9`GlW7 zQ^f8~&UV(;(6#0mansW^J($iS^=gWyOJY}GZcMPbaL;awU1?MZn6l#M!G_}skDOX% zkj`BTc*Iij-YZN?KU%Jnff|PjIj1??SO0N`Cn(nSG0AxNn3~rqMmQsTK9C&tLb2(B)Y?GuE?}Ui&~waMUY% zQpd`x+nk%vqCmdqcSCY5Y z-j0-H`LD|s3rbEme^9(W#&f!hMK(8U9OVs+A`z}faN1@K6z1)HIW0xz#9=T+F zc5!XqSCgTUPlUAPVjce$ZR~dCRjLWUUA%zhAi#gk;J-okvoEy}mHr*cN|FUqB_0yZ`wscyJ(eejzCki8mw@ z5a`=z*zstAEq&jh&w=BNh=b!|0oj)hoqDg{($q}wnCN5Ed+z#IhY}e>)Ta+Uz54?4 zBH;x@w2f3EO_|AfP>$(wo*Yw4FQa_0(4<`K;a2bF*DFbFt1loAN!41i>K>LHHJDW|?p!|mA|ZE29Yv#=OT(kUN`&`-s^F->7*LV7jL9ol+t za-zw}Gu2kJ?2wa45+`APJ7m9`s76B4zV+4F_V{RO@pK+8dWL;T`NL^~(YY2mimz^F zCW+WC<$oF~=Yv|Pe{F0M%v(G=QKiD=r{=!h{@u45P9X(AxvNMQ`y4|;l zOL>r4#fdMuzxC+kvnRUwnVlaFD%QJSpugb9*q!-p^{^C)YHZ(ghI>KdKWr}_%iTX& z)r{yiN%!`@#D?cs+b%NS@>OHMEZ!qqJ=FvG_Z9+}CfYkVIrIremR1DrWrk8xU*S-w zGJJJAg>0pnz3p(v=#>e9kys(0gPuMgdI)z>x-kWrm4>}sZdK&)AFupDknMXIX~=Tu zf&DBUd+Y<($Ak&ZZzYt}$KMRG6IUcYD;{~4Y{9XgNwCh~{aMA@k!P;>)BBT;^xZt= zrR#BsuuNcI!>zhtgN}B-1T}GjwCWRs)60uBHGQ`}1R}l^gahFV@z;^Rxo!-5|2$s* z_(a)CY^$bg2Op{ClL2jIu>9JpSz1K%@!fm!Q94FXMgR;uZn;jm_8WUocE^jqMLy(V zn}BiEN9DAVkg%4P5XwL5R$%N*Mjqd*z3U#bVQ>Fz1LG}1$6?Y})5ZZ+?!E+F4=OqC z)t%?mJTu9VGC9jkQ-3SN*Epq~$fer5!c>SU1eJd%Qnm}~4J(owo1 z&86sNyvV2@>GG4)du{#a&-4 zq?eGSAU-Muy(F+ASs&rcdUK5_D*DT$6t&&$(>}{Dlb7#|X`ZdWT=K?eU+-x@#`sb_FwIw!bovLSqNF9UnfO)1#k1_v0=jYQ_M>FHJZQTh-^`&?p~JN@v%Em5Np#U+zD%<^oF2 zLzN~Zu|@q0F{({9nvX-L=Nn^PM^Dog`lUq=49Ue7OAt7+`5x=N-s))nkk6oT=zYXc zQ7_DWZ+B^asEbhR+w>r=1@*`CIy!e)?Vf&bt@)Cc6^dUsS@HN`aoXpm#P;FwPl%^_ zy06EIW}kXpn3fc%dYscYN0_4J{(#|qWV4%3xUAR8RhMh)i`kJ{^k?dQbjNHv*{7He z%(VrOYaM?e@%qJKDq2K2{@7fIgM>;YthU)n`&{ixdkt1V0R}isRM8-&L%|F&0UxwQ;HBLPjh{!ltxog!( z{hgU$4Ws&C!l9o+_2Tw3dwP<)y6hU?{rJ|>tSe#sZunhSILxc17*90akzO1QETs8bGMo@*j=%Jp%Ww~ zhxQAnh{^22uLzoOZ0mY`;%y8^0sV;t9;ICyeiv8!G_lPwj+DIbj#IFrE?srN_c6J%pSVZXVZ|Yq29o3vS1k@$ z8ZaHaRFj&-`s76J2N!7VGrQ*Aw47TAkG*1!)MRht3y$Tq>h?4TBnxrh>hnKMH^6#i zpR??#N9#{U@)H-HsnSi*&qKUUTTPEqK{KUXsveW8zjQhEHl!!AwfY^eMD$`oqCStp zWJ%6Id(gM*>(@*u)#&kP@)U%hcI+nVUpq&$TzP%Ok!yae>Z%s+GY&z<92K~qbLGaV>e80SQ>vQr^wpMq;1r1p-pik+WS1jp=A2j%$ zx!8c8OO|lk3(skIv~y;lySux=@Y=rI^lOj0^X^uqeXG8wcT00fJkW-N^0@RsVDB;6 z-HL?1DGA3EppE*ns3f=58w&?>6w*|WH7ROQBW6|dK+XTtU7 z_hs9x__9573=L@tce?%l(D9K}&zTf!51alQ3jDE-QR1%{VtoB+^9QJMoIg|&nh72m zN%9+{shnnToZ(aCTPE;~I6x^>R#)--Q>F6$pJ(GzLg}&$c3;bFSU~ zDx$MZcWBxVF?SJ@zIpJRJ|O$hcTh!fYyye0l1= z*UbB>HxstjImdoBM88TOteT=KdOq{z18YTo)>)m?t)3M6EJKrDB!s>Ubg;`_dyu3I z`}Q&JXIgM(R;x=T%jv;>Zce_+M;b@r_?d&xk_5XZU7UTcL_j{pba_EP*I5Qul&6HA zJwvYdBgKn(^{1-sPbTJU@xuaNyGM(Ih`vpd$$3kxRF$t3vh?(p^d?>_?0@s<(_@>f z6uT`LIPaw}JZ#t9Po-k7KpNg&aD25)N7iL*bizZm%=)hDTM$!}Uw;-q>2eXxVd0?a znB6~5xeq@7K}kH!(4RtjbHS#6*W?kOW5+e_hPYilZw6ajCwcOrF=!iZTj+PH@PBaI zXiDTC+&17kfoJMYeEXs3l+3`lABxUqfj-#u_J@Mx#8^)L8`ooKq5qTiM!CQKa`J}) zmKBvd0S?kkfE?qjFsKlqB9W}9lpr88!Y|tUf9D%Fwzo60G}kvaGuO8@ysB?v@1&2W zxAk2tO`I%_qbi4qiLn9^1Bk?%AB7`Y7)U4$0aC}Hg`;?B)c^khS_@N4a|$D9D?F^-_N9@Q;7q3hZ^;RZxUsn~DB;C#d+iU8*H0_=Nv|%Rq!c zF->6D#DXh;p8YYC+YT9e5Z#2%9gkC(1N4s=mQA`I0s{pd|0P{tu5}^$wk);h*Yop5 zWKlX1lN=dbWYU-YwWaoU*l|Ud95P|#3RO%UZu_x%Qb~|l_F0BiJE5|R*HmwI_WYoP5-0^<_^0Ps=ze=0UCGq(W{Ld5K?Ci3`Cd!cuIJ=m&a#*$o;pP{EldfgyZm!m zK|fB?WF9YyJ!eizy!pso7O~I1`EqL(bs=9VVxQA8X0Il#Pmf%lChtfT{&s}MUpV2T z_D=`_OWoh%zX1Y!uJr&t2 zV)MQSy!vmxT{#*QEO|OtNwu%pO%joHmlhMu+-alr?Rq=jS44UUr4Gklc0? zm>*o|Vp_SIm~*m}{@I+?lZM&X^Sut{i4(1L6MOrR4TJ%r45Cj~8x&%WPKk+HkB8gy zOf_GjUv;6uKN){`OhY}DI3O)@chF72RK3#*(rXvXZkFtlaq_zpU!?T-v13`w?r_%^ z%3qz9A)RL{rIp%p*|_|hKg^RAggno(9;sCOKI8Q6s4jA}o$8eIFu&XxeOs0y7Ewk@ z)-y+T?aeu?7OJx=OyC5YQg)xlaf@SIr$d9E-(vki^HIyp=KELb`H~mww`6qg@Gve| z47I*9CT>%Rin&$()B52^&mjNsh(gpuk<)K{N}2|VOB9ER_w62DYUC3?+Os+-O{eX2 z`mj=M@cDx_B!y4=?DXJj`h4%2UJ*Lja#WB!CHV@~G`y|+tt!*E@Nmo(pQ@EqYRO~T z)iLIyRf1<^8wExjm@XYZuUjk9yMB@3v#q)41!ZpO9xG}2f%U2V5gCRNKl)GB3k-Tv z+$#_97CluG_+sIMFsq{!8rr>#5LtDO1Gy5`NPO?kxco0lB2pX~o}cjC+k)-gODF8Q&+*2R3gqtk5;(kw&=bx9D23Q;noma%nS z-ipOXUPS+?_Q^pCjM%o_?Xpr|Cw;BCT z>U@*ByeNo0HN#M2Oed^_`|9F|SLzvwG@2(?G*j`cZC)Y~gGo;eceAf2)0_`@PflUN z=Je_Z^$ld_zBu{hE4Pp*j17#kZLi%_KvId^zjlbZ6JK{9E!5E1p{nO)-dIRg0oS>f zWabv}ZyFh8@iO9Ww_KWI3;ITIWZH5fVbF?XL)&r%dw7=NhFQrZ6JF4F6 z8PRKrU@i%?`h?H)(sY0_D}&a@Iqni=_4USoc!DP>y5I%Hu>LC>LD4hQHCLCZuQO*v=_ZCefzbkJqgyr+%AEV|YiN z(5K8S%r0w6XG9UflfM`k+aUUq#n&&HS*WT+jN`*iK?}_fyM)zMjg=;?X^eGwMIS<( z6y@2QwG~_D`#HYsA*c>Z7tOFeC2&;ryz@)E)n&?(bj`DAXM}P~o)XD)Jo1AP=gsbO zNaOmrN-}PIY!}@Nvv+WQ_mq|OT^!;;`PjP>=pXTg+wV#?X8u2SB~S>;NdE74B~Y|8 z3Ap}ODQ+lODzUd7=#!ZB?k^QiP*jB%l;dVapo*A))f&7M6&uTn03njU#~1&F!U-aJ zjX^0+8$M4HOIu4P2TQ)oCPq$9hDOddh7LgaG%>x(YvE*T^AEKX3YNt`SNsh@{|mKq zL$VkN{QZjmxAjt>eYf zl}K?cLh8byVD6zawr#QFiIXF9D(pvf3ioLpVd-eOWOmieUo^`18s(4Cl%rorJ5R@@ ze|fleGuo}au_>jqmckv{Zr#ryy(X_6&y9TdhkP4# zuP#c~-49JaF08sR^KOVN=K-Ga9bWbfEwj0UuP7Vi`iAuHaag?I?jO0x&CBd~GB?7Zx;3>RxhQmH7M~d)>0N8uuH0KkZsEB8Giif{nINP zV?DzT0*@;0h`bd`8Rj{CHGyX`uc+uqCc*cc&j%SRpbzXhy0gi}`agOKS68=ZuuPT~ zKhjdnVrlUEan^lKW^BdA^3#5Cs2clO&_pWv1 zx+7Iftv+6G!iyqe1)83j2^+Vs&T^maI@OePVLIH4-;PBcx-;0vdF>;&z4Usya)5za06E zz;qH?w$r)ygnej5Rk_(Oz^DZ{%*FhyFV8=!H~rq+<2mP_m!Z|=-W}IY&NXP#PH~=} z==oLePR}x7x8pAh2;#Vp+G#CaJ=%4mgedlLsOcltj5_?v{M`dh6nOYU9DOv!md73; zGnIVFZL5~1n!b2)hzJ_q&8SR(T8)P0Tea>w!)n^~;%eUE_9r&C8TV_@$rW}`FFsZZ zkSii;kCU8E%d1C{W_>uNDM3zpk(QLrVeh@Qw%c4DA>n1a2TPX6dQ+$TmrPW4>2xC7 z1X>G{XI5Ytyxp;QcD;9zM&2Ik;|v!XN{UZIXTH~1uv)L3@AtS{M_#}>Nf2&0-7>DH z^erQCa#A)k>)-{p)yzxj56wt3+CzJu3Ecl^Fcaml5|VK;@#dK~2F#Ia;YJ4}<1!gq zbNH2ZS?^Ww82VDtr(JMLsNpd%wd{|tD`v3!;nn|4R;niwKSl7erlHtfFC!}>A_rwn zMa;*|bL&`5-2Igm(gNCQrd8ZX3lh{mgBWh&z2{E`EMySM(FDwCYsD zmtK1;yM51f2oi?1J!B}OxghoIDZz{{$02re|9tvEacT*=g7*za^UQX0D5~=tM)(j( zPms_nngW-~3{|02erDuJV&9NJAD9l(_+(nemI#Ab4^J;ErVk1Tr z1~P8s1$f;`;`E0&9tG~RW&7;wnxSo_YQ_4KXT=#`#*2U0dsI2{&Rml|@G-ZV(L zpCr#6n+*<8k*Lp>;^mf|dN4Ix(Cv_CIH#MjM=S53hWC065wt;z_Sw_gzEqCy1Vta*sBAd1E?kDz zjAkXa@|T}`9WTrIy4OPDj(2##QyN9OK(bjPj-hA9y$8vpmgMQ_+#HTvO`mY|&Td?M zXjSIhA}Q=m>vjQoDN(I}zwh{jd`e$t(px$?p}Q3Do+Tj_b#{E}w1aSt-reQ#uVIPO zFNrTC8=R;*N0|7QUg+)Z6PhrOaH<0-B%~5{H^PFPym|I!HIAsfz&o!sgRk3GCHxkD zY8UdmQ9cc_XNhiMzo({@?c*>xC+|=36)!9d?~#}sePBgS_4=?kTrV?ySe^8k2s55c zSqviIiCux+Ly_GOeDvM|+dU>1DueL+E)br5m5}%_MlefwR4_8tL`+ zLbNjS$BmcpwG4TYB6vnIS!Chm)0GP!tV?IS-Om#BB2(AuN^X@azVH7^Wv_5*RfpWv zfQr&+-EORS;HLcOw2E|Y{<42nhYOLlE7!P@_l>6`YIw{9>=_z~Pi#i;7S{LJx=V0x zr^)}$ru{EX9?kX>^QoCS+B-WKn>qrU03ZZ+s>!2WuTf?Nw2v_Q0R2$Z85An?nGHh& zID_`p2R}j4TL{#_M(z!8fU!z!6h=k;w6RA32Po?a>Ny*AS5XHWPrmqvE#MC)@c(oB z@TcWM0F`Y}|;X{oZ zJP62Z!;gZs2@e9Cdw-86_}^xgKhYr&*yw(D$o*S%NZ>XOlI=qfs9e+_+5rO(6wd@H zrT$)e0@(1dJ2-kbNz8Y~-oeDw0bOjD|016(pB$gWg>Bmw0s}d=(dk|`+7^P^8A9QI zj}9S-4exhz!QV=6qw4{i11J|N@Jo151n80fDl^ufjf>o-aewEaafAmF1|a}{zSXuM z9lQYiH%rdH?R!udmh{k*0cO{W8$7f%3=}xt?0MjikbuD7H!T!<*rF#W9KpfB_~Zv+ z5twNOV`0R7TEXsm=y`L8_%QPd1|P2T3KYBRp=a}*!rPozw&3A9uRymE-|vRAzwCRM z=Eck`TljFDS&&HVv4QP5@UJI6m=F@3k_!ttmR31_Ia8v=fP@=@mDEdeJ9SnIY1Y$1#rBU>Ll7iz{C589g z&x4}l2Ir+nPgA<2uOm=lzzV0Dj;ri#5Q8KR_4M>c{1=?=D zTc_+zbGWoc?ZrgTmBc8YIPQ1#$B?_&$+n-Li(K{ZWIz6~^kJnX{lk)qL|zM`=c2vm z%KVi1o$hmYr~6G-zdjC7PJj76*VCQc^yE@g;dgV@r-sLt$&?CP)UL0s&yG$7czwHk zJD0aZpR^~$$|>RE0Bv6N@zn$Vul4G<^KyGhbE~Os4W5zS=z2qkuLjHfINf+7{zQ%L zryDULR!?*7J~|hYCGylRt_}Q->ZwXP?lklB++L9xF|!@x(HM zgsTDa_ey%l3Nk!h=$nkQ)}=M&Oa}HHD0Y>gT(s1xkCSS;dLtcHP|bPS=OLX%c~)|b zNkA3(fx@u|orX$md#aEfmnzb0 z@}CZd>~T&wdxUfHuygo1bK^>4f%&^U%wbWpE+%^dm$rY@O@$l@M}qz>W_M2 zFvNXpdv5q~JKd{2B&>4B^=IUJa0!)0%N2=aNplJ0`*2!^ zq4JcRajM-JCQ6zbhBmpr#PEmywT~KJ2+=DCmRNmfKgrOTDwy2rN#d%t=KnPK3&XK? zZV_1{en$c$`KdX{k`di~*IycnDKENxJKJu->G~-*VG(m^Lb9$gX9E7 z!wj9=>_!j?=cag{>W=5pDariK{tP-$Sal4dspH0cyb>QZJR(?P|9P4;f)mgetvOY) z$!X6!*p$@U+2P#F0z_^X>4;AK^?IF_ssNw;+k}CGxe!SKrQkYPr@BM!1>QS40H-};CXN*Xyv|g%MLTplD zj{I`Q*K-^@o>xB~3LW1aNn&U?bknh9^o%f#kjBMO#(P~bMpxom+2p&Ue3fgzln$x7<-*43G>Eprml@rz}gUk8V;TBQK9b^!3b(I$=);)TiqEN!|8D z&B7QO8!Fx~C%04Vr7bD0PkU$d_Vi`5<1({Kv^kE7Jv!4$vJMJ!XJ)ToTVZlOzsC~k z0@u|XFCfUPE~9s~D{D=@JCIRp7Aq>~z(#7qB5T67pM)-#%b!%kSzLN{3IJw}c6)u6 zy{6*^e}qSRgb$3-q%s$@Mc-b!surE`E`ErqV2ps$NBYYwTHhbXMFcwXNtjC6nWl0} zgzDPVKNQl*?;D~>5dC?HEtKYn{Tl0j653p@W)clk@5rykphG;lokiUi>mOFxJ=0z` zcy`e#rFnR1CN9cmt_tENPGIpW3PmHZS6;S4$$eFw20tsC{jQ54FIoR~M z-j=f;&_Al+df>Ii1i)ZsNi`AI<^uj39dtA%>3;6sZ>^uhJat*d*O;h#HzSYe7zI=1 z`(d72pBU?Vs!Iu5`jfL)awu-zBBN=34(l3^jxiS{bSwKDD&wTw`^~A-Lkx-=E#jTr^!j zQ1VW0mCclQSby?KM8)jGL|HxVA))zn;2e@Z1($R+RZHH(_sV(s;md+jZBLcOsBEEC z*Mw(44tAd@2;<}~AE>uz8Qfzm(gnHGpwFz}2>$N`AL;IoEK&@1+$Am2#e8V!@|&B_ z-9u-yJ{~O*o!S+)jJjQ~+1@yT(VUEjO-RJTy)EI{sn^K?=0dC2v>P3ok9@zT?UWX& zaQVP9@OTOEcxX^aCX!IM>|LnL(w)PB#|jiZ9qXk?x|nG%TuNy#q8jk- zz^2s`(SwZMkyfQsO`3`O3mzC7(X~e;A^*M zUV+Oe(1hcR&w8Rj6E^0(dk&3$%lJOhzcio)o;3A1!44MwiqRs{3QFH?3mFTGld)dD zN2yn8-1PM}nVGrWqq-{YKESeH*;}77PdlZTQ781=ZE$l_?y*uuVMhb$)s7UpA@j35 z>#iI?n28-%B?vLe-tzfYej@s=$wD)Dkz7FVgEPk9{VQ3p3>*v??nHT}Fnk=SZ_|V@Y-#e;gCMw%F$0r{hMVrh`-p$J(z- z4w&~OdhzNDk>9;xsvOG0%|d2BK6tA89B9@HK(yXcb3dvSCw7INi#^F-k!w@O;cwDR z8M_CnqtSds*bH^A92glqrrn{o$61u4^}BELHR@=}i+WPa|5$pgJg^>rmu-zi?*8km zh*JHkqc&!u>9=-`=|U4ad`{dKxK>~jOLy60NUx6Uv&ei&$CURi#GTK9F7sw3DJS26 z+(GjTmz-)~w)S#33j=pD|%U7Q-XM7wEapJ(cjnhuc13?|@Ddxs+KorG41d$_MZOza6Ws4) zz>y>THsik4&1hRq{mVc7T{}w(_GrGUZa(rR?RHz`vWDfvD{<2k0|T1hN#L274UT>U1SDr+X<>)$+=mQM14xElR zufZ_uXkS|NHJB%FR1-kmj(PG%%>i&m5X0G{^RJ`s!qg3bV(JC}r`^q006KW%T_6k2 z<^cvXI@dS)b`0jtWFipgMt&dgWOU{l)HUdAGUx-$lhJ8c&}T4DMyEtUpTS^8XB|PE zLFe;8A7JbZ=v*7<8 zgNtEkuWa^Y#w0Op!aIm0ma9GJkSoMD^x zoImX_=w6E1um2^bwrPhE1SS+Akgf;A=L!OH91h39l7JM#qO8zkXNT}mH9|q7Y{7$o zOf>vBn2Dg+gx}v4J>J&Rfk1*}M_?dh;DMA$ARGq=I$Ve!TY9Lzv@_`;5JDhy<(Kpj zf~ZosI9NKM*p2%~-QB5yjsgh+OEBo*AgdMx2OFE_ug z&H4=-h&%({wtsJA6M|sPDt}Zt#!+@KU@t`#$=Ngk!r?Gp9J-wlw(S|M675iQ0;noD zs8S;vwr4oX0`u>p_Wm5RLf9r4w4$~{cn}ao_}i#JC9dQDck!Bk!h>zov^!rgU_zii z6Zp(6>48`)7~)^WJpKb7cH^Rz+MP)c2G%c>9RULm2I5DBa2d8j*aj@Ls=Y&aAk0+| z=-gZIfOQ8b>^O{DY!lW_DuQjQdN5R(Ct$?hf(P6*kODa9QZVeHv7@438L6w4SGc-`!k{!YWOBg>0rpEL=s2~XHh2bJSY;^$mLG2hGh!lo{9pe@}5dI6{ z$6--JYy%Iqh1;R@KybGZ&}g^d!2n!14!V>OwjTdSa>~C}2*8j9iVBEs0jt_Cg#`+d zX!1jF5FdmeTNg!B7C6gq6Cgi7NPYTCejubAWKH<{i5c_>ER71yq~MBgQ&$G_99Y}Km01^kC3c`=ARQ-_|`LCOI z6Cha0Ai&XO3n1`n5rpC(KnOp!V(>@)WgG!Qgg_Nezzc2x1Ai4h+J0kX01<08Io`rpp?96+f8i`y^7 z3IYdk;W(%U5bWOfN0RBk?tSRl4+2WSqL|(->7mlGLvT>6kl1|>B$?U4?6)y`A^afm zJ<9WSbHfV(;kYmaF5=_Ip8x(xmyMhJw(}RpK{J41EA@XQ7~}{f+TC#F_qv zVQck&c>n!1K7NqS1;Hw~$$xL*!M1GjSCmt2Hk%UE&<;p!?)1kN`@o0 z!S^359`H>zdl>u1h=YfFMR2&5UmW#FZHrz#hCaAn2?vGvnGQeNRGJ`6FA!G|j` z4&P?@{s+s4z$P`m1rJwh9F9FY{)pqlReYP=_!d4~xp6r5=sRUsGef=|!2e(s*)HxK2Z~$}OGALde;**|FmiNE#lK0Ai4LN` zOz;0A7JP?s-Eg!+Kjs~nxNboZD)DdQx)U$l9IH6kGBTxJ`M&dj5wBcOHMMxr@d`_d zR5Du*Rc=4rgBg=&tr^t|` zm>?~i11?U**FnKZNU6*IngNUTJ9Bey+`F67*-hiPXIc72>5ll8HmxnMML`?Sv&?y2 zT|B7}z?u@B(UEqBu6KH^GAbr!uV78yr;52NEeB7;4X+HoX!6%;AW~4H`qAlpQK;>C zue@f!_iBO^@)Vsa`$B62>gB}Yxl=0Qt63uhMGayF{Y1)=#T^Q+FNgJK`BF)xBTXou zce~7;>TROA^z)L;=u9c6z`V|QSH_v@^gK%KK3cJ zAfT$-NKJ-h7Y6@^#@~}5-1v;7MESWt}c#zQDY_~H|n1LtO26k z$kCG!p?{;`)tzeAT5%}x9pjz=GVPde3#?+?CxetFN85w(C`A(+%_WRJGv$tD8%(l2 zI^{$@Z&yM{hVRaJa`*WP&Ia*F@bU#U$rZWX)rF$G1zrSY-h)UVl`?wcc zHl)bTKDxqwl8RDkZZWvWw4AJ$f&K1#p#vUE5fXBIFK5Csrdl6KMx>8NFDbU#x@B|8 z+C&5$o~&G;kSJg;HjojFN;xv3C9bBbNC{=5crvXt;xuX|Y$0Xnn7>lQX6@kCaQ$V` z5@V1wT^j#zLZjIkqoO`>lj~=x1zO_B=t_=4@9#SdfUr_Y;aNo|m`NOtIO$xXe$Db# zmVK_rqJjr0n`AX)-^D~`zn57_vG^3>8Ri!Ghuim2ePBOBMd?#yDcJB(LSFS5qp_Gp zYkWtIz`p$o-H|Sq;tuD|o&kuSiNU+Y&919ZLtAd$q+8hAK}>JrpE)I4CYkkRys_Q? z31mpn7CAsre9SIfkVSA@$-!9MPRlJ^*O;ivM@dFfW#;CT5{t#L;~vo=v}=n8Ws1Dx~&m)&e ziEhO>q$8_3O4ukm^zO{qt{rOhFEc8t>KA=k1hU2B4}Fkz3q7oPr1^G~(+~E>u=ah~ zyY^&xSG95sa=YZd`fW3u{!-{lo8ho_Yvxh8A4fjkNFoa294Jd%bG<-VYWFPksc=g=-%Nzmpb8bA z2)77HjbBvnDW=*YC|l3Rvs4mzy&>-=UoKvjSRQ9@>fYbp)fjd;iYEG{(-T`OzF1HG zmt{4q@0!Lvy*%6>em^pv3TnZ1qNv{^#FiF33=`q1X z>)X!q$dBCP4!dV!+e}K?9<+G~eXO~%PESuAajqlvtnaQ ziFTNYys6G;(+y|y_!;8UQS+8M9OH=l55#q@%Tx2T#N4D2$h26ACYkAq(xsk6OpH%I z_dlj<8_}wwN=+d%AcOyb>+qY)mor2NBgU>H z9p0O~mzGCPY*_q5;LzH0`|Cx#^s4#I;qLbcWOA9}^weaX4yY{n+nwPYKqAHwxg!B8 zY_W&V6&xqywvnHR{o33qJ0Q;bRsVQ{JF{1IgvrA39Lg%M-1F9YChaYDb#v!*TOXue zDLE$7?Vv0?x$?4Y@4}SXg_%J4TXTu(g(TH77u7y}tu}bhbU?G_V)29=?UJ&lJ(*ei z-JJJY_SF}MeyG`h`Ak+=?LOq;I^4&jeP8_?ua}i7<0T)c9#mRBEt^ln%8^|=_x+`D%nrT8i zC(7%Nri1us?Mj)EjjQvCh_-COO9i6svZ}AG!Vzv^jm}5JM?O?)rYrb%%bsHF&91x8 zQf~c~F8W~sjHSkL6-njzDW_h4CiFy9x_)75_gH(t!R&U&LLd13=JF4(erhEvT8<>F zSFh!)Ra@r1Ta**Lc2IT3JNoNgwsUdpCz^w9*h;%!Vb_=AZLz#zZBTOkY{yTD>{rEC z3V3&yHQ~`8yjmYt7d^*PAXFA`OWIkisPD?7H^~0%#Wyx5MCa=SdcLRmKm0(*FXZIC zN72<}FEZS%#yZTm^X$?7Q(@C0FLG69H3If94B0t~y|C5K84z|dv0k?9En-Wo|7^mp zN!6QpbGYiu7pG}P6Z`(Bb~BpmDjtO&+fx)<%vU8Ga@aWOlmk3ZjdtW7P2x+8=ABN- z9I)bxK9Sk3ZhrWV)2^qC+7EYA<(9p=ldAA(=_aB2ly+R-g|)kaBBtGS!>??=6rOCK z{U)9scWR=l_33Wi=Yn5|Si0lRsk*%4|90@{AVc|66!JX^Otu@46HCyo-0HZI?| zSsQb9vHiU3CxjN+(r1mA^}|jlbD?(?M5K2QovJ!1v)h{L9IuvYy@8kq)f2x0)%@vG zl%5Gjr%MkO{V1jAeVkb6S*l|m!+WZT9eyPEsg3rPtHVt2r!nIW-_`VJ67=u)7oARR zpQ{*>&JGrP(&ntav~Mi`)oJ*;g65jcwFHw#MjCTN>u)`z7sKpUn@JT36!i4E8bKA^ zSrOxj*LrX6J2>c2j-!mm~jCx6q&5j%Ey*~?QPr&hJI zKo7r*b&neK3-mxn!=1Ca#@9ctUh7NwWHPDRwOgcgEIGyV150Rzr2G8``r%3=Lri2@ zd)x*XQz-=3ihJt5EE-WQJ*XD5O`+yEcZTrJnQKR0i}JpTuZSYmn|K(+xzI$yu;eo> zVm#)EN1wxV!dv#h%--p`i%v~Hy$mD!%&^0s;pn(mjCQ=SIs0e$^M(ffXZSNr2(=~I zQTQ_)6IY80^FfEN!hx6X<^gI;3*uN&9%Y*cs686`4En|3Crn%|u+Xhl09+xTFX`Vp#xDX~%au zaN%GH6Z|bI5RS?Sip#truubFce9eG?$O-6guK#d;;A@YI>%ZVO(%XUcd9!h0U6CbX#hgGvdT9Y69CRt@HZA)f7@hyKs0rvcP5U4Cy$S*& zIBKtlvG@rBKT`-US?ZD7H0}--4UAVB0?c##sQTByy8u-O8zBT#0wEk!0_ZmQcCcz- zjP?lNrHKG$xGj9B3c)xiR1nBE_;#>tY{~B*ZY`+NgE)nJBC*#EG&6wXy0L{1B+)_w z4rNPzKxu*EG&665ZwI@LEqq`+pi;_h;REs8Lb$BE2<(MzCnY8@_~2kX2mvBx3m9eAVB>1GU@#88xxNI_FdPto1KW}xs3a-?!$GeCzM0t9gg0)Twn0tlQo zkq}%WX0gL|Hn>Ba8+a2S7!ZQLxoyIMG6OO>;?e`R8NvU-3IYQ|0t(U-Vk8Iy`L%@L zI03{aT+m$W4kZW!V?qcJ#9IJ?BQ_wFagiW4Uxns?cM1>;3NRo30tg(jaY+;f!S?)z zqp9hg;u8RDDaaGIB|t#1A#f>E1i^N#hyPJ_<1cqd7$pY8uka$kbhQN#L<$PvlI{qC z9ow-%>t_q%y?-1UXQ71#ziE1yozCX%KB07IfGP=PUmisBOhJ2#X% zBLJ!aLE-;udv0uRYinp{;;3(IYhq$*X6|6`du_z=%I?wt82vYJM7ASkFUQy^2uqM!;^gsX6bI*TfFAOsY+>_ax6NAPcZq% z*N;ZKiQNO^jBmCaF(`g{k$agaCI0d^PBWrAQo=?-y`_D_2k+SK{{B(^W#3V5zDHlY z-soOD73&sP#I8}A7&gdEoRt|roUh-RX<+qvaaeBqnWkI3uk5MWR%XTBP~ws5lUKw;p3N6ecx`RN)@a2%M4e(&m=v zn!5Sbw6vY;woUk|X7sIVw@+3h%<=bga_=i2{94;Fz^S`(+xo!zjhlxKJy|FF`g8X5 zVY48`YKI?VE_ZSYA8SE*qqL8WiaGJ;?g}YcxE?jN>I<$M0--rcyzaif2C7bWZTK0nj3B~!<-I@y#QjwMO&kkHWc73kvWK_!e z)%5i9Br{brHl)22 z#^iCPHMU$x_HMFRG5aPvc?&JexaMZ(i4D`I4qOHERx6LE{7fJz`;&)hE4HcyZz!d!J{TAU zi;G4_lB=96^SlMGaj?A{kVSQAZx>Cs6T8-~y60JAMYov0zm5COu1eL-!spk!xGqLF ze?I93*TRZ&wkHvdV9K{!;r(S!!~!*>BE24qj}O0HO!Tp#KY%B7T1N0>jWhDOsB^24 ztcRGg%NJ*}!rJ2>-u?VKo*8t-K$Xq*g0Qil?fwLfV^cE=4+3~}s}e`1q{Q#qR&?i< zwO!%}_1Q(PbZeJMJwYYp9Nu-aTZl5ZTx;@hsrEE3TGoM8_vHITgnp?LKW0@-4APWd zjk5+1nc6&8>2#C4sCk``xYI`#&!a^B(B1rdDdZhVT)ch-?R^xkrZnvo_lt9lR46|f zcuFujU(@vvF0j+2F5@c6$R$;-y!hT#=YB|j0nz_s?W?1@TDPt#X(^GGZt3^|0@4!F zNOyO4cO%{1EnR|iBPAgXB7%g3w3OdQFZWvKyn4>}hXV#2dKF=9Lq)Ix$l63&P&29ody~4JTuz0(KLp zQ$e%Tkca!~<0oD^E4YTsGUBtCf*9v6yvIP5K;;KAvnZDA**Qi=Twd@;*u(g@7$lQ+?6;bW}7EOtr#otjWv|`mo*l zEpgM)uwq1D^4&S;QPJ!QJOt8u64iV< z*QH<`9?3*@GAw9NzZOyVr-e7LFRyTEw7MG}dq7~}*&P5UaNz1^__EwMYaSC>la^3u z>r?%?eK>~9c!-3fY|;lchS< zJq#8>$mb&|3qiiAu@rtwaE$om3nhE@km+|wAvw3DQN)Es70=&OGL-T(+~%L&P((l- zsb6cTg`BDVu)s)b6l5QYh<1k)dPImHE~tb%W19_S+ZB}xDR`FplUj{pC0I%jMNV^| zE!}Jhlu5gwdlzIc`U>d72}gv#d!TQrc`MHwxO+l`D|90VmUtMhea*J_)T1%&?Cq$0 zPmtM7&?QScfrmavc->4GlS3zwOecZtkirnovC+dR5Iu^N0M_TsHW&6Nn2O(X2OZTd zA3ckQPH0_91a)*%Acyn;RY$~Wlocw^TXHesj?hyEYv5PV+uiLtj|Lbh_>(9jxEU+t zPS-*7p>XmQaAi>j9?C%qU6%_ET^B6A5U$J%X}E{%ugramGG}i;Nb1v=lI@UrM%1n} zShP=ix$G8bpD9pVz`9jpCzYv+P>4K3Ei5~ejCyX#=JyJVI36E0=0&Y$^~^+EMVKJi z%vgKi7$vF9>5IM-OWO7-5|TK`Nplm8M?0_$)W`@Tw#a^>v}*LYa@eV)6#8w6$-;OG zvy*PE)ZzJ5`Pi3rDH%&{pM4(PyRV}ZB}hJmRF1*Lf;g%FdfC`)UOMxBJneB%mKUz@ z*t7GQ^xXW=!(rFb1!cYwJ>GRI>6-I_oL-2r3-`DbL)hg-M89fuvJcGOt%8`MgezrU zg1e+0OueYhQMGfK13p`|l9ajSW+$ZJ(k|-YoYWt)z%veqCb;QQUS0;Z@^fUZM6{xo z5KuD2qTRbZeKqr*w9uuY;fWm4bfh)%_KsMuo#O2Lm=Ewz11#5+p7hzw^XFGJ=v{Ti

Ogj7l75u3* zzIA3F1d7kmeQ)tMw+N=WM%@&3BJ4aLBzf1>2aMv(lXJ?HJFZqL-O-SVw}jiIJ9uoD zYUOdxJKHq|Y7=%GnI1oyJx$)gwy^=>wQ|Ojv#vDMRJbH4z~C(UOvpD9g9_GixROcz zBmzxkrHksUoj0}#X3W^8386`B5FUO$QerE>$j>v0`f&AZN^@tVmJCfZVnR>RhM!|9 zR-_a~hpC66HSZL~uI?T-(}&MUO)=?Ei}jXMDN2ZEYi2y|<0EHIjwieVs>gOb9x9JM13O{wO!BLNvMj;tz(Qqt zg)Y3qmY0#=YfO2Xv;492twy|&=p#q$i8%ipH&uLE30*r97@TDr?&JAX2JS0~r@9Mx zn^Nbd@CVZOdbBWuEo+Dp#osIzi9*Eg@zmPx?T)*j^H=aqS!-NLoL9l#X(zOpD_>N) z&tkEB+^!=q360%aWRu*=hTTidJyPW&R8B>_OoNyytaV(jr~ryCjwyWHzh@~BPdjW% zXE$eFW0V=%mPaxwTmvNscNWsiLxOE`g$zDyocs&9+AqAeev+$wNh!aVs{xK9*BL52 zy@bA=u{OV@6XBN$!+<$AFwq!9$bRiNb6wMt*0upgegKmqzUsx`>A#4hYzb9?jQ5KZ z)V0FuX28U?wf9%?)y;s3YyY_a{N=0o3h4X#s?_>kh4pVtrGV@mum)oz1OaprV8I1U zX$DG6*YrLM2T-&A9ctkVPBOMI{0S=k8!ss)hHL*u*8hfeZJ5XgfQ{b|>$lL{mo2}6 zIDd%QnXU%`00{GD=a>Mx2-v`X79p^Izl57#ZiRmsAW%dHL>&LyLjVQ?CXP)1FhWOt zZPUMq@n0yN0H{vK2Gkx|f!hvfOeSOjyl6mxM-?j@z-Ip5%nV&i3jNTN22=G00%q+jfuYMDuuC|$(rlF0tmC=te zetoq6;iU$K?EqDOCcUck%;Am4v6diU$6?B=Te4$JdBL-W^6&Ub7OAfX0y6kon(4<7;_MjK0A zIek0eLr5-GA%yh;gY}A>x$d&0 zYz)#9d_stsauGo10CxE?U`ClB|8n@^q$H)Fyg`jJyF;t8ar~vgBT~cA$z$JMY`BCB z1s-nqZo$wl60|~CSYk2lwI)F*8OHkYxx-;JEn0{eQk$)er&GeDXaiAF`*z}9Fn*zJ z*=}t4D20h#vMPRwL_I?<<#S+4$guqi{g*5rx@Cvb8f_Ke!mEa2o-pM5QPuWY3LMzH zLpzv`bxy~?sC!70q-fz`FDI0y=db>pmd&tBe6y4WalMR-Lq#Rt%Mnjdgt%e6Uz3kY zIVxNTgV30eMj_oyk_@|1j0R5M1T_F0&WPREF!ZgX)gzeu3VyPcuq2{ReXOks$f6!x zxl2eKOar1&DM?x!ZXn_YRuXJ5=qpTPf=sK5HnMy01AB)ltu&XBvb!V*UFr@ZLn*H? zXL5`Xpj+CtT|-YR5Ny;XxgZkxus&(Fs|Ktq|pp+`qiT7 zXg!u;n+24k~qr3kd0O<*e7 zj(%6enUcefzDU*BX-lbdKakVJW#eFX$<*FNAE$9|^NRJ96R)b3b$97($jS(U(SV^s zF~XlHBIl)-5M&C-CZltE2gRkQ5anZ1x>FS1z) z1rfGc6lTaYx`EqAjME_|BLg^eZ0NHla3nekj3L(}JF< z?AtUwO_KAD(;hJDy_Y+$14yk6n_^hyA{_ffVKrt~xcgX;4AXTfgP|VVb7aGqrrnD! z7Av86Oc0HN6};~|UM>fp-0Gw9Cee&x81lY$RUnce7gLwJp(A07D10ua>(&INW$14m}i0wSY-UA#NbdUVvqGukJ<%D4K-g{YAPrM zA-x0q1o&CKZw z?(DumSCQPZsgy7@{Dx101a=7>(u*dV>By>03pMrq@DA=Gm*-?S5cYbns%T4xN5Of0 zWnHF1+6n#cOZFLrwj&MK>M#WHXD3p1Efz=$?)jFGE#s}^L*d!%YzEr7{T69CVnLa3mA&okUSeIM(5jZC5di!a?B+NO0o49Wn-u?$`>^Bw&iK2jjZ|6= zxWv>+zs{t|u1FLcGPzZfc}?0{4RCBvYw)C*nj`Jv!xcZaPj6K|ty8z^%I=y+yovo_ zCx#^#_67rQWFmUO<#7B-Gwd1s-Bty9X#QCjMie4)d^eUO;^A4BS8eLeL3eyzP*Lrg zgKXnb*5Q4WoEvEb#N}F^L`inyyeE0zQOHYQOU+xD_i89^MXZx-*o!aei5b#+faN$G zf`XxSbjl-l--44vYbT@~IIytnQQ|#}SDit5lKg&lI5qS`ef7Pit!GJGYP#FGKJk9E zHZ=@NL)gwt&zxu-UfR59Un#mkesf1|c4jj#!2^l}Z$JUxme~JH?YJ7a<=s=mph@kA zJue-wMRqetj#0^E@Em4F>M1#(LN=iDc8!J*U<|=I9o3gL=387pb;93U-ENvo*cArH zqN@SNyGjoU0H1z4xWDETop^Fr4u4xhl-D}#^#;`xEt!+z;^o8ITV)KZ91sYlwx-Ol zA7(4oX@u;RdI`i*(5{v;N$s7GB`msYpW}_eP8?xvPvIfSaWB)Locp0$apYOiqGr&> zA=WMNWl+YQk=9n1E-qX#IXnrHwN5z7a6}g{(V&BMrg_5sT%%bPezVz~8I3ldH1}ew z&%k&H0Tbp-W%}+;Lf+d&+XgE}%Oe-H9U;MW$& zL(#uZgM#fz@_%wf#fd-u%zH6y;KdO;cLOH@lEGL$o7XeBy^RU9;@dRf)WI$2#1-qG zXwNdDCY|b^yT-mhb1Eya;jR@;Zz3&kVd*dE=ExA~0iQp5M^b&RW*ao(mfqGB(U4qL zWV3N|^$hmsxAjCi z*v~vQGNXJ-yzFd=k1g8ecf}Pf)ySnI?`a9K5t=Zci6>Epj6e}YnTukfkY5>4gVHb% z+MPnyXPZ!&q=|h>J5IlvG$H}Rpf1jF?E}hc|nP8BclW)XOz;r^FymqA?PEE-4C&O(}%Z}SCrTXKMWXT zoa*dPFYCy_ANav8!^Va;q%rlpdMp>Y@O+^Gr8uSM>AC_nDWd*ocFm?ZCCN@?XJ?y@ z6ZHYElFGYl=H<0du!J2It7+qa_eVUuZ!`(Ifg?}C(NTn{?M1TWK;-fhitgoxM~TKY z>fy$%uJPzQa63b}j{T3PLboVUo5F--Ub}BUua2_FuxoOxHQiLMS*i?ar{|i?FmNAw zkf~0zcCJo4AU`La@5#28XqllKkn#DDBU0<_%YyFF+q$;-A4&S*TOWpd5)$6c&FwGt z(s=;Cns8~y`x%`ijIS(RAds-Cg6DPxT4uxNLN%!q3E9*b-{ytv?ghm?%+*f)1Qk_* zOOf28`13pX4>>FAC=P_;SDN8Mklu5Z9>q=>tC-LCY8E4-lO0nK;o_qDC_Kryb3x>{ z^u{e$93=XJ4^o|_bq35`5anqR7B#*nGvn(EPjKf&NwS~$9MG56znf(CE1v(6&-t2I ze$VHCzV;6O8$Jie-v={{#fTp5Z@? z?}l#z2GG*603(iW_$Fp{px5c&5l&w>{2#`3Lpa^U#RS0n>n4dmi0fMf{TF=B*IVJA zh6wofvH?=S|Aq*(I57a2?jMGzt*2*a`AbIU>wWqUqXZNHKqnLPf1|uMV`RR@g1>)( zzum~cq@BJ#L;o;HV4f}@mIE4y0GbJ~*96oez)yf_xVGwJ{=G3G-;g@CMwX76dd48bOIQI_$p0|@uU4{fT#p`P`e`LF z`sG`C;Fn8*F}J|9uAi5JzVvnfUA)XdTj(zqvV5oE`_(a-fxa{jU^{+1QAW^rZCk%u z$^^(?0RiIAOId#M!}{^cFahNT4xm}@=c9i4tlgaH?{GWcaW>xzbH3B;e9r;>F}DN! zU;n%A|KWBRIe_c(o7_$wmT~zC%bu&J(5Yb4tkZVaa3x`Gppp{Gee2j;!9tW0mx~Cw zqWzT-6kVQ%A1d#>H&Vusmv;+$pZ+l{NqD*UMXXC@kSGp3J&$>zBTR{=S>nu*_MGD} z&w^#TJ3cHunK8P{xvD#tjv&Je;$tPU?fYj~`?;{NA!7?NXt zN#>sn9Udf%5o#l$z47UR-drJzPVAZ=a}qF?7Hb`lG!2qP%k}oY&A0lZO=-%pgnsN%!D@euC3yvt?EqEkF1KOjk@P*`?sNl$U8#vh(v#9tYcAfiPJG zlDQ?xm^5m|4-t6>SrpWm;2|Kz@%;QA@gJNe=-h=uWjK-RASp{2xy+*3f8R;oE5Sul za#eFcB36Hn*||r5@nTr)*bWPt{p_6NDJ-5Z8R>1=r>iqD$W|x$#Z9g=Zv>Y??+HS7 z@P&osG2*&DRt~G;aXTAShPy?SVwWcK!I;spI!d+Hl|ot)tgM?W90xF|l7yaW_-4{H z*fAvH9b)P|b#aSFgC4Nn(@>np#n^u_sFD-WY{q$eSTxm-&YJ@I%_74)yaxjy%Me?| ziMz@J`pO_Idd6jTsJ*?5PadOZWC|7-6V_QR-Ij*R_hcL+3_o4bv7tzS3l$SU`4vRH4@|8f)ewy(F-wdT+!M;j1BdeStcs@= zdc$kY=M+t6vkD6~EZUu?$02n04taimG?{MIA$CMi5MQHLOk_@FOKG@Jx;@%Flep|C zQ1hnjl+wtMtYR_^tQz(V)P^rpQ&g|hjU-l4^ST%{6{#BWVm({;jLFZR_(kJ;&FSD!&7B@5{k+bGKHdT@7> z!biWvaYUtRcQS&4?0JCR*qMYucb8D@6`j8moE9^L7j@2Af&TA1{^JgX!)L1I`W&R|Rtmdd#vo1?6h~hQ9 zUhAkUbGWonG!ND+tjSDCbvP1~A9fGcY_%yUdkLBwMrPq_J2Si>cV{7CIiDBaFCB9e zknm2&&Rr(VUSRJZ=L6A7R&54JKd^rpPbt(hM{jA(S`tec0j&V%U3k6;OO0$CWFnI} z;5!RPNNB!UcZBPV5Z(Vs;W^919=t-u*5X6P(6?|6r;C)tB7WBC7!<5pmR3$QI7yE7 za?{+Sut-R2dam)#S>dJ%T3ME%n@E8HnDuS&IevQ#hwKt|IOD5Pvqn3JU5=7jdRgu; zYM75LMh9i6oi#7)4mMNDH3y4qF;H=A6V8rs=)E@Wn>!9@%Sv8YQ{FXVS=~;#m$+fj zi#4~SNyq+9dOtYH!(cVX|G6agPB4_1c7ja;c4y&-tRdCUpPVR4kR2fqgZZ9O>)8(< z;Rk8yFE_O?YTtu3Q8Q?uOcFD9LiMetXCf#h3NAAoeV4{;{19~eDECCs+d7s}TkjLK8H+?yg2`k; z>3l{5$CxI_O2|(qezEo$;*105LGIGhiSALaS!vyy=(@YF@&Y|B?&-n2h zvJxSre|~~Zy7=&Qv-Kf**8ChobxP)OV^=?i=>t4tLzH}U*|P)G=VEn=-iT9 zIZ>*a*^r(;O7f>_M3BjGl(HwGjT;<$HW=Ofq6dtHa#B99Q%uZ#q=fOT_GQINk5un7 zAw>eeL8?b3`l-*&F9nr1LA{TqB}yM68`N8_Mhy<7!}2R{`fI@wWy@FNqAYnUzfdHN z)TKP(H%h*RzB8?Z{~w zTedks7Z;A%`OakRaLx^(Z$m6`I%t?mY~)I4zIYI1T8`vKUa`?+MxR5WM4NO~QodiA zCI8{pot7m57`fOx%4)3Q>o1;#uK10!J&``Gj&sP+v^WuFnJyZROqxn)RV08j#8$RBYq9yjJsAkLKWMO6Rp!ZN%wuXkK>yMOGiY1Dm2sOfIT~tgLTpww zpA+U(wy~OUoRXbyoQ?f+Ttaid>)N{Yg7E!_Y6v9Q76&2eqaD=X&nIRjOI=xMLCTvN zjHrDthhiF*c|V>B+#fnRqb@lsWr3C+s6W{;RMJ}ULzVPPx&^`tig#B>p#t(in3R2!U%HnpF9a%%}s*w7kK;2$NmSr{na+-xA8XUt543i`U%jD znGWbbW;)+P=zr5}%Y2=11Gydxpg~{;%yL**08?849011FS4#nTI?yWdGpGP^?QfUPN!8R!ezD*6zn4nBL3U1l^5NGBoTLcS8N>iSJbkZgd}8bz+`ao$ccC)tfeGob0qV zH#r}xYzlQmOVjQ+93M$D(00G2b8U_FfvY@oIys&(MNQ3$)uR>zBk73UX^9}y5~W!` zgM44bP*OYL_96IO+oikw(TjQ279y#NBG%9)V;hnWZ~jQtq2j+)U*J&D?ASv#KT^5;X4zjY!n9jPGHpBK{Q@D=y9?MZ-C zeTiQhi<0<}v}Obh?v9$2j%yH!jx{lPJ9os&$^@Y)5xU6j2XWwXk)kL&5=pCbHLOD> z&jeqXofvN^6uFv}bhgLZ)ln61?_Rwy8-I~IRb}GJUop{`$vrE71STVww)xE3)G?0c z#DFZ`*uZEjE{G7>xyiBQlX#%>eQA@zS1mP~Q8Yxgj=|?C&WMY8gRAkpHu=sz#dczW zB~9G3>OzJDUbT5fih+l(Xx$J|O4oX8EEdXUwXbZpUgvP;7lNO!S=g;oJ{u7n%ceF? zV(a1)>XXvH>g{KcCPz-NT$6d4bSzRVuvkZ4-ErVOLCHIe@(jam#^>J2YnxY9eUF>q z6E@0jjZ4BCNzVwj3^3$D;tY&{ z#^2V+u%Z*_*1^AQEe!;Pj4|2z;qPZ#?LhJM31ZzwZ(`JX>6#!q8?o&}lA@yE^^>F=a-7>XsgKfb&Dyh+EL3*F_D$hOdSS|;8D zK4{q(I>b+WVv5N5lyuI5k$#9YE<;4agqWA$G_j51nvX__`AgDi6oc(NfG zEr)D#I0UT8GkZt0%7!#(pMcl%r&ojRe->FRs0 z?Xm&aP+hD+WOSye3C(3{`v{B7w%e>aJM;CL4Y+shxT+w90!8?&F<&w_S$RQdeTIzj zEn0|@xNr5O!8|YvyTXnk@M%_w$@}vBZk(D|EQN4$N6@1l?#iJXLC3I--pj`zez& zB*=d(&y2He-RcwU3Tat(x`6T0jFerZmuK-#Z;(N;cUL~yXI=kJAz6~AA%(KD59_0L zX2l?ptS~5vy*s>l@q@Qs<885nCtz>OLGaOz8;d-L3V0FsZo1s3%7!ia*{gyY9Cl;# zD!HV*)w(G<(D~+*$Sk!E;=FMuig*Ee(}6NmDxzV@>CMKtyEtu+9T{qf@fu#U)gK_3 zjpN82G(XitR~FOhR#yeRnZX+Z3DaUXTKVSqXQXwa2i^Pl<_wSg{L}472WBh_yiW8r z0nK1`QmI{p+kLW$Nxc3+QHxntZ{5Wfkfy`~m)nTFbWMBoTMMv@&-5Ryk{+?@At!?t zXp_viNC`iBsu?9!)FIe6>uD}^5b%_s=tF7Pd42>K#zuZoh@2^WNGzIsxbX><5Yi0N zQl8@cx}m(KZ1y;s?#zag){!kZILxBj>6{SU-4Brt&elq*vX*ZgJWT?){ff4VE$E(F z5QA}dFWcj0Xw%Iot@{aipB68h2fWjived;l=wU-1n^a-LolnY78^-jU%~_1Nl#J*d zho-TbQ-{8E%cL?`?TN@fjKVw*qvjCK1gux?Vg-{dJdIm?d^DqNIN6+%o#RqeJUfv zpYR@Q6@Fe6#y=OL4Qo&Ibwl$>gFMT8gqQiy!vgW{iCw|{6jhMjf4{fC<}qX^^Dg)0FoOJ z!vZbTztx2PZP~=wLf6b*Pya^^C+OceT`&UPl7M+5fH(kWn(Lwo;PAr;NYt4*{ z!oNd0-_iTu!ye}Ay4cssHPE{I$7KI^<)Itc!vY}I--JESRLmphdQh)CTKO-Zq-j4p ziF=15WC)nb{TX zKGNr|fqi*19fLS!bAqx{6XcvFb-3h(wnOs7&ueR&ld8rF@iQXNEOzF%qO=}`Ob+c_ zs=$*^9QCH`YBt|(OpuK(n)Z1VOLgg1D8!rso7^(usI0Ljk&f}{a}~V5qKYj>Q4lHG zQ(wiUMLP>w6llS=e$BE)&vzyFpbjqY8V-<`P&loLD>b<^jKK-&(zw%?EvjFZjOXO3 zEaN(0AdpO;Ba$gHpy;Ce^wL0MpNvR0YnJp0(ZHEvTbEh<^7t5tTv)#Rk4}>Z)_=XvDGC zX6{{}4Mwy^zphFi@;h*%SDa}UDWy8qV8c|IeR5}hPF0udmqm~>@6C^c!p{;m4NlHj zX}U)On=(pj<_$fjmHU%H4XFyxRI4Gumo+$6tm9aFi&K%~OYe=IY`!Ch9Z}N3!gSCl z?kMj$k298x#A#!=I!>t6G0J%E7hPWgp3{lJH z-09B{lgpUv9mzrR9W~+sAnWYem@cU-`{;BPWJ;@2CasRq{zy2_=6HiNg*)#Nc@t8> z{q*9&8R16vQ6g*RB|fyvw!>=#`D1DX=oIcjkS4$HHG{!p*cXQ} z@C7yB=|ekPqJH;f(8Xa<`Yy^eblrF?L3wXQlfYi zRBNRmhobRTx(ZBdOIqbkGWT-d*k0H*2g{fa)tqoFz{TnFk0}Eap%aM~tM~ebV+HeST<(2XFfT)zb8HA&LMpPhIU^&~Y4^xa;ew7WmJc zHqn*gy5wo`P)~GN)lNUsCA2q=C#&{)rQcf)C80Wnf><)xR@&eh*H~mGcQeLj_JO!- zbUe&c7d>48xD)6+J=|cr6~=kyCnZ?!0VN>$NJmYNn&L>xStgRmh3!`M{3nnQIg(@s z&c#P#B#&F%2%Q3$6ci;aPtFbdn)PFHEF)uIbMiQyi?0WJiLux@k&M?*D}>(o}nBR1dQ&`f}Fca+8Kl& zKgOYjV6#Zbhke?o&hIbg6d|#VdkjH4n^)TrY(|%5R=2O#p50QRW&E<>oMwUVRngm{ z0Gl;&_pEyb>PnhU@W}@V$(p7ffw~l4A;f)AYhkMSwx;>-P*D;wI4OFW%$J^eQcom1~NG+-Fagt2I+DC`D?_w7+jZu zEMt4A11fc@AhD3uF~Xz|71Fm-A;#6CJ!{p}c$Z3^DJ{*%xE9?PI_Z5{9{dE4FAWFz zOdm0M^WKt0r@-+`M%qFJc$0ildAL=dZTNWRcYF!+g`p+`a%5ppgA@A_I`lTheo>DY zu!UQ*{FE8y;uuJpY{?LV)ka?iK#$Z{>5em}nQ5J6cPBn!M^aquZpTYl_cFFjDtuA-Q;^WOem7Nw3Z^wi{l9 z=cg`@-NQR|C>33o#u)J=r-k8}Fy_Qd5q{Cp`+nF$B{HOE!Qb7&4SgV>28|JknNEp5;@v7Suv|3)Z?EnL^cQUK8fDBp z^cUtT?Bi@v40E6;hMlM#D4`PmaQUE}56@*@G&nVm)H6_h)IgH9Kd~T$$-lsPJmsfg zzk*}I_Qvs+2C_m%0N4V2D(@^SiPCRhHFR-B=*?KLyqXqMUb=dBgO^aRwA$ERt$+g zBuB}3olO#lIWL<^sCc(`(1sECmWH|{6+PCLc_`}#GByR{x(b8PI{N6~mCq9@*|XcN z<-V?w&5Hja3-s|VfrNHtu^HQ7OFaugX;a<8YuAAgpHF_DNg{8rKKLxtNc)+^h($CL zdm&&#$)f?V+Msv>Q{zb6Oy9a@Rk$_3w3pLz$!evjfyCDGxq8{N%)hNwK{l4^xfdRX zB>yRe`x_67EOqt-+~yDYnCav>-VYq1JsUn97Z8-iDSKW<1Y0AFNe`aDCwMXwYV!<# z*3lX-R1SbZ0a6A~Td8Mr6P~nI)~#lYnUNa?zrt7ghy3Ca8MT(!6VK zxq6m1t>KMqIkdywX*5>?Uq|ic3*SUvJ~Oz>66TMgG;*uAk}+s7;nJt`Qj1J1lfPPf z5{qvkv*>^n870AU3j5aaNX-YaWlqEwPfv%I4-OuZTtJNvj_M;R+?L?9ejNBwBHYtp zAceZ1dLa13-_J9RPZ)zge;QpFxp>w#`qV={tSWpN4mBmkH=ZZ^8rAaezM{;5GKo!n1R> z(g!@0eh%^f143p2VGO%ptQ&e`YqSR8x`(PTlk%$(;vq5UzO{B;<{<8zAkzGW?bL0 z41eX4_4Nt+hY!k4U-ix2F#|P12A~}H4`cirnd`r?lw)QBl!@13-2dz(U`-0#ga8@x z&vx>!Wv*XdP5*E!Z#X3;VBk1A@aDZ~3uXf5Tre{K)@}Ih<^E+`@Yh%7KMW9Ppaztd zj6is7z*BPFz03{}N{oPvlI{0qtb7}ut-h|Ev8Bb&56rjq;6Hp|7y)7M_16KgN(J0g z0r4$x*_p1*%z%DnfG+w&F@Uj!oxY8Qwi(c)uKTlC_-9G$mk;W1NN^dye64P-!58-F zho!85{GSDw6Y~>?1b9jUAG*I?3dqjcfl(DdF8%7+_IE3<&EA=R)tSu#nB4vSK>-W< zU-v76zOz~U)u}QAcN1Wc{!_fbUG=Ta>aUjq27G|G$B(B9c;0^d-TKv1rfa)Z!2aQ< zr7S=j{@b#rZghZ+1%_V71k;CBk)f5{Af znd^HKRrsc1vAgf+Z?%zTL;A55RXIfh7sR$v#83Q>TV^L31CN0Cu|+oWN$&1UNz`AI3mo= zwO?uODmwC5Jr5VfJKZ{O=D=ql=1^TSB;X!~MPSR=^=v%%4#ppN--WE(R;VpDPoRTJ z8lJfDkj&Xx63L``HQI%MM@Dq+1ueSxw4u8lEfkqIfzqkSX7}XD$-VJoF*IJURZT?# zo^g9<#dBk!U;^PS;Y7KPw@&UV!LU2zy65Vp4@*5Z_F#9)kAj_Kn4&+0W@{s&h*99~ z+`;L)HFK!tAxKPR(6Iqd8r-?AumQGTi1|SQ7VVQ;^QzA&F^F<;XSw2yhU*hs3Gi0% z3nNu_qW5}-#!Q-mA81_#kdhsSk+ytE|d4U+kR-qZbx`9R zro+@jCsKuXtx_fLBhD*!wH$=OR}Nl6UJN>3#jxC&OB%o$H03#IXCS0;$wF4qw*{}m zIEboRDx8fTNs+`e5Ihl)e9zyU4*g05ZQ!kaTiYH4D9o!`#E7pRQt1vNpBu_O0bKZn zGJ}ns6dtoW@LQbvE$f{@8qOzvE3WcvMs{agw5R)+O<8=e4m)8ja3B@z<}Fk2t&?dd zJYae%R*SvDuTf`zWT|AczRcW2*ap_WyWGrU5{2XEz*4+JsTBK;j2+X-T*c}sQN00? zGgUqGfj%4mV$J5D)fsp`yKcGl#hh}SvvcCSnWDQhocv_IAC2f63o7+2Ne;bT*qo(S z5F!`$C5xR04&UC4?(}U&U3?Duj;jB9{TY>I8RN080)YLB97>{RC z{^r4Fx3<<`G=3Pdc41{Hgl8{t5WIO$BNGU(Xyf?lz!0?z{B_Xph~4TEhTEWJBITjP z#0bq#zD4+m1CGc~jpT!tL2Mwg77Hm6x+&757>9=pd2r8V_l(5lEGJ+PKAsTSBXAcy ztf_z-!2R%nV~rnLzuZ%u5M!;8mpq7NND*{N8?#2ppV7-U(9NeA_Y!@T)@DO@DwYS% znC*qdeWbNwqXt9~^gUF?x;M@W><{mf2h5Y>!MMw_%f+&>pUmWUqZ&#t*btS4bhoSB zeTg1LE`sqOj`oBWq{(~xj)S|@VXeDVQtA^;eFFLDqFM9}wpy;l0(bH=Iw8-RgvOdJ z(N=R4=1c7+WNv>mji+Eykg0}ZCs6v~%JSvB@@!BKi^hk+2{t!v0+JPE!}U*@^#aLg zAFV&c=0&ROm{t^$NxI0M4}WG8;|zxz2HL8I!Nfx8%Ybu#;zXV5FlaDk_m}Ls zr$TDPr1vU2)g*{ev*sMk)9JcOs{FhZZBV-|A$Kst#X?)e=p6Vd*MOw7320GSU^MljP}yQF>NU(-cVd(=X*Gjlzb&;W zSUfXntK-lIe#naT;V`1;BF^5=$c`4nquj))?*tlx{IWtnd8+WD-+`t*C!`y+<^{*@ zM(V9c;PZilpAGIsCee>C$lt2ziEB81HM3S^Iq%?ap+aF`DrF#VqQX@=`Yh))iCQz* z;CtOg{PWu{>2aa7G&}q|Dy4gN&_j&KV~F5KQ$8%dX;JSPeSRFx$h!}9`%F&v&0)#Y zET2IShG&cof|>#VS=1-eJCv*;xAv%IrGeRx}J zrR3>)hU^DGPFIqo@a5cMXD$)u{#kJG0JsS#u zY4dMnPV(v<6PhAB$a-y&J!~;OH7k*~1BIoVTjB z-k3iRYa$c>oLVj~{osi%~t1+|jnd9QTcW%*G`D@x!H<4zZa6ig(7&{&Z#N&^P?0KsL8|A*f{Z($g z@aT3<9PE0Bw{kq*v&>1;c$@1xO!0e9i#2I(Q|R@cLJwCEG8@`H;8ad?6`7x?zMRX#8s0TuFxWXDeDsQY4%eB z%UF}KoL2;)RB%ue0$o?o3A1}^C#4n~uXqg1ITNK~`{^1Tv`3j>HG_t45+UDFCqMjM}DHozNAJ!&}3iyf&Lv$_NABXn%?>%ul@4NP1`ci zY4|hY^2p zL?&P+3o`)X|7nQ!I)8;hfpYhc*ZlWex&fZ+x?X;>k<7rP7C_4K4}-MQHvCx@^5x>+ zWa59gi2#uRjPL^5kgumx0&y_`d<`JNCcJL^W%|7VEjL`3rn$cPuRD@~8KVE&zc2Xf z%Tx3l*ci~o|6fc0sy&tcM;9>A4+mud*Z=^o{EYd4M$W$v_qvzhdTh#1OM!6&|Hsm6 z&IDkeeqPGL{u7k{Azo&HmIO={e>^BFfbRc3T)?pG%OuhtS2D5yPGHzb{Q(#@wwwbU0$><0at}=;qLM|c&f;y#-wMfJkVT#zMNiauRmq^d zPrAzg>T^r)zFii^%6~2VO8DPHrtTBYPLnlAcMZ23hf7u}jCr`&zm$qwu+(T< zwU)8|NQF38h?FLd^o zQ( z3_2Sqx!!Ci+xk@vk_SUP(Ay71}-nDHBf;YzSr$Od8efyvmX25b*)dkX{ z_WgkM8Qg1ywbxIW4q|1Z$OraJbh%)kR1GX|uU^f1mn1jjB$kLY%6aNVt;u|_pu$YS zeLO~J*rUoVT$VsYSs?Ax4KA1;u9KhSA0VQ~M%RbvL3BVIFJ$cSz+xgBGkA0TRU*Aw zY|{nk>5w*6NefByr~t&6&#qiogCSlKSohQJ2D9fA+T|+ikO{}4)Oky-O=@RYcDt2^ zN`(3IOQR{0xaerhPGd?ODlr|55DelEI@D7&xp-Rff_mHqecsFk85m21_S_9U*NnPh+!5ad%~9uW6*uzuHW-KUrFZPrro8&YQDtl1>#-cX4r z_#@(eIiu(N1}0YF2ITO;{D;hUxYLu!r$I?Yy^bu*%6OMMJMStS?i31UO+8z<$6RmX z$m6YauzKzuJ0p?$*mRPneDJMD(Y`i#oIg|6mWX5VZu;Or)=w)gTcUEFX*K z7!hr%F48gtiFQ-+L7)sg(oZDiVNuA_<-C~xckiq-&h9<2pdD8=l0^`%?wfy5rIp8*Q{H^3g-^i^Cc|CdEGXH7r{f=- z#zLEX5??-UOc9f!&dNKNg<3B8pu}(_oHE49<2}>Kh~PPJ5rb|+1WsUuO9Z9XRbct5Jc4G{@dbMhbI=|+odxdCj-Ja&R=0KU zh1|n^?HXSbf3A|La^+Mrtr{xzEfo1Qcmvb;8MT5@@Ga2+ugq%y?Dqq@eisA~xqXd#DnLB3{{Rpnz93EkksfxdD{^?V=!{`6J=CK^N5 zW&?Id>{QmWySq_X&n+h!^tW@pLV?gVi%JcTM4S2KW%I_G>3s=1D078%gIwqWD91Gd ze8~f}bcL;NS=>SaBer!CdG{ze#?3VSaukB5x06}!9+!k1bSAruGOIgFufI46vmkZ9 zjc>GJynu6L$~$=7Mr>?YdsM%7{Xt@JiN!SAx0d;ZYF%cd(86$4L-9O`9NRLf&?UWIYzC!mTdHYYqozVMZdsMV!H*!>}~r`Gg`XPJzDu8VZp= zGn~PFx;l%QyDMq)gGp+wL}wWPeohdR$*hPgUPlYZ<#@jBWZ+7sZe#rHraN6pVc~!z zUEiUXyXEp5h9jz8vT%b)>$C&92T#Ui&(GN=3#N>7bW;h!S*J*~`U>o-o?9&AnU;yJ z3qZqNDcW*(?7tkc*9?eSo6SO;#k(VFQlOAK9)7e)6gXkoEFt4YlA|QNEVz}2Wzx!F zQ&EYx?agvrl!aq2?UkZYgxV^KsN$8DW9@3*ANzF7e~S~Ba^r|ncyv8Tf!=mbX?yE6 zbAR3QalT`+?MQ{*!^9$!I^kS(PTG3W<=KSSd07kO^ER=V+aG;a=9P^@W|T-;aKz2> z6E@wQ*1VwQt==_v7CU{q*m@|swR_$X^ZOTY1^vn}nD?;m54B8g1hI=T1$`wys6&=wp;NN!z zm%o62U#(KVSFeNqy-EUT7yTLIefi@};_-*MKQO=TdPEu_khRhQh4|~%Qy@bEU8j71 zY>jMdX=8T{0CeCf)LWS ze$e)$d_11$;!t+OXOB)c<=rio+dict)-23!?5T#7Ni+->B%xUJxsj9xI+Yx1%iZ`p z9*#ou>+k`J&pvuCXmEdy4-pD`8%b;7xb`uUkgxx(!#OAuN~Xol^StxG5{~CFV@P5c zUrv1gwv#G?u(ja)UZq+zC1rSVDM7-0YO6gYgp1`^y$#N=qS@IL+DbCGRK0XObdfvj z-Ld_I(X+27kIb2g*wowkxzmspEtgihG4d}v?>?dl$3PzK3F`Xz)~cH%u|7zhr>XJz znPX0%T-~TtS56^ZM?eK*qZh91NP<={Xp^LHSjcnm<#zH;BNY4vmsZNGm1XQc8D+q=0lIjdV#XA>Gp5t%S6|yTR*ougY^D_51sL z-oM-)U1!a`cAPcFoO2APYEiR2QH>9FxqLGt5zrW-bXutxet{3IT?(JwvZ9m7qVBeX zWu4E9;sft$@_+KeLG->~iy-QqPWFn;nj$Z%i;Oc3U%Lx0wfWwB->9R)hxJb`Rxk=w zkcr$*8U|V~L=3%19x}hWJv~j27n)8@hZ*XF{KoCgP85Y~6D4T@hJr9E#%kL0RW~$_ z=J$}i2{E!$$!H9PPEm~vrN?6$#ib+7=p@4!1I9@ojKl0iS(Qd|t$V4DhdFl# zweuH*Dl69n@^7WvK_F{XwUPuznDM0#C7KQS)Fm-25sHsWa*Bu`M0g?4z|7CU4bk*J z3#w4>Bd+7PF;0mL@w%5lD2QSc)BbEjhPl3mMmUD+E~eoFiBFS;DbX!=^4vWlf&_}v zB7=7PXoSHxr3OQfpLVdDD#JwP`t@1DO|-NgcjAFZyb|eQ(^=YJf}nX8*IwQy4-2L3 ziX167q2F^TE(cNK3}%C}iEFA{***v9C@a+sUBL9#7O3>nrTXiR?`(Dlj*NhtM7@gq zbF7OR1#bFMQHeCHHiQ_H#c?~cP}F$N;7Kxg!e?Ae#}msjaidw2y}+Mm%YU8FKr?Y# zCNUgaGDXo#lK8eqgWOhPVxV??DYrHEp55cL7>h{IexuY~*1W+|&2eo^ctMjA zPw!WIlK64NCTzIYwvJwdvT#o_)@mLWI5BqcsAQ?A3i6P^Ysc56%t5PGnoWC(hclMi zvBJw5*Ko?kc+ePozLCVyvZi`egaPG!a%OAKrxAAxg^LK9P8*Mizn}cf5=L>~XAe%_ zRego!F|kT|id=3YgHpX*O`vAIYvZ3AsvmKn8v zN+1=IE&}roull9p-M5{ivs3s{TN8Si^Dq2(IQQ>V*z?nQ28N(tCDI~Ul{B&oa^v!1_4bM(v{-xwu%Ym5C8_aCT z(wcI}gz?RpARR84fn_|M#SBBxdR{FA<>&%*Yc|bY0pyVASlFz>wvv~EL&uwy(Alwr zaOw9cxSxseAvYcP!;mIm_Cm=Dw5_6(Vx7`9L)za$Yc5bg@QL*MoY!63QMpEwBb^k) z-cD0)Mtx91?=Fs3P~dmYbBnX#IJNe{z$AawZO%;7J!<~R5*&O{jgey0FWyP1IUh(4 zt=*DuY*3YMHBL$9hOohJi&lBLM~xrLNk4d_)@^uS$rztq2^+;P{ev7NkpP;s`)T}o z(|yu=j7?3+RHbYcA3$7N*zep$og}$$WIfb&m{x6yhHu7E$1|Q-QYeGXdW`dK%_*cp zl~tjvMIS+1LeQgP83kN6RLLi%rm+k)zCP+4R{=LHZj@(s)-H;F1RF;4ls(iZA{H?B zDJhtpn0}M8#zqx2FHe;4nGcOWl8viR!{{(Ekb-KI5BH%SNkBndI}wqZ5)HJtG#sv* zJX}GbbeM|V=nX?Tw4ubsDXhv@w|uc;&`l;o&=|B0%G4HZt>1>BwAQ1!@uqo{r#Ce*Wj9HGk39`yDHRL`CBk2vdPd4?tLNoW9iT)8-!3#COcdqt?-=Tu^1U zJA13nFith;CY zj7XW3ytQIK5I5tKDuP1f93RmG1Co%WwEGWVXsA@OpbJLhO2y=LEe3}Z- z=`QSM*AdUPxkTF~M_0dk=x6K8CR&f8F*H22kW=6o@uVhK7m5KS#`7En%dvWBV4#7< z^Szry>44hAp2WF9jVoSUh)3>OcCU2b=Qg4DY_leI)H_dTq<05e8EZ@jh$Ux{^2&Mj zd)|;oMpdxS*r5r0>_d4{c1uBDQEu!=eXM|%8}W$*R77%WV&zO#BMPe$_i-*$pmU+- z>-FhOE@HMN_IN3CoH39+Yw;va_u^eQ{pn5C8Wzh_<@%p*VpgiuWMuCbaU7l=`Dv1l9(Y-p-NZ!pV`MiQ&w@(|_cq2`0C*b%7!6f4`#tluKx6!Qhb~PH>=BSs<1hREA89 zrYMb}a{uy{i=mAx>G7C51d2PHI0fO8X{45wvy``A2B6ky@6R8EAdnMPou>Ni-Qhiw z%$R)WoVX~x|7LKl=~KT&KxnAblExW!bC~7CS*p~=IQr`;gA1A=ZcbQB(+drY^JYYs zLdEhbHkL5_S1+J#$PWWUgBM6_ZEZxu&K;U_!yNpc8;#auLNmsN(z*Mo%Z={3%a^`~7u7fE5ixM7i3~{g9yoQYQeu_&*hLUsX$8CZ>SG-b<_k99%NYR|j9w z3-HOeoYfVz|D$^DclB1kiD$kQOmYAw9b7k;{{A;Z z{Fbx&7UH*@)t`p=-*Z;qmCOBRlx%=@5;tJ#`YlQ}R=~O%`0Jmovcbyzk zoWCD>+26ngJbynSXLbOK{*R$R$Ht{c)lWk?0okp8A9~rc093>NJe2(>XC%%a&XpY~ zhUNkqPkx^D=k(+cLoaL7S*}aHas1?O^y9362r`hQzi!s6cl@_o`&S5t?^0&p5e(mD z%zj9w{WihyUGnok`7_{G>K6%yZk36U2~G@`!$)sq%Dw#Olqdoz?s$Dh`kdN*K#wS! zFZ~HAETcKxE*|IX5Y2+srg-=roM^GKG9j9wZ&Pd&<#R^Rm#~b+PAR>6pyJ6*JbMS| z0aCo?P#Ts5kp<=g++NodotzgEW4k7XSy?cM5>byPMs7)9bPrn;x;h*{&(Yo%!|cRS zX6K2#8JcgIPPNnI#}Rhx@p8WTZb?oZ2#em(pJlncf%s;p?0fy~$WQyDQ2PG6T64#v zP?Gdm-j1;J!SCl!^O$Z47}B`E+=NZdX|W+HbGIzD~2 zW3r=W=%;`HWsu$e0lD#gl_Ab>7ArROyCV6%b}eqM8=S*#QrRs0~NP| z7@vcIetX;YdUYAFi( zqijMMBq&zKl@7T+WnNLCY&rfU92^SeAfysQFN1pw1BLe}WNyS_AjG|^#_GVdimj@? ztwoxXk|$j^vobV1Su{jbnDAM(W=8kbne3eSxSC*DKDf26V0_Xv4SR?;E52qTw;;T3 zT64pz2Ax;HoWYk{!e@1bT%!rr1@X?nyXHM(WNrL>Y_XD|-hAZ4vtl#2z(8RRo4c~_ zQ}Trd-o3Y(n)WmgAZL><=Gc>;M|Izp8DUhTMO&`7^$MOoN`DtDt;%Pkuq?fx*F@B0 z^wIC5jmiOaM$gF0*B?zw3GQk~!xAdFjILy0*T0L2n#PWism>IrJ zib^(dq*yt$>RkltQr@Ts6?y0n@NwsLyf77R)(EFgZI*S)F8EGN)Y?EF-#sO8lx|r! zmu{9IB~!`pWeoO$*UHX|-+eVE-lp&3tXYlqKCi;Ip^6lmt?KrZ0`&p2$6A_rMQlne zRt<1ZUF=8Rs8upPZ7hP5E@L8r3~**lVXrKIzF40fP|?;ok6kwWW`35UTkW(gQ=gUKFvXMnY6r8bMt{*W4%*`dD3mjLai`lJ(R-$itWkp zlz5#2b18De9O(eeyB9T$?BM)-bE_ex$|{hJj_cka{>##uDqlDULneiq<$GH%IjszH z-+y@@Yi}aaW8t-DHLgOt-5-IdK@hLd371{j664|q1XR)hFj^@-^u`-;y}cwc@z z_RgGFJaCEgXbK)V;y?IU-a1W*%fn7!^MpuGO3Y$T5ue?J`5v_#O`Ee$ZI81KobMze zSk$VhlGB}f-$>a6y;Yj`uC#ki=Sw#S$HCIObd3yL4*WMn%jj1;5%w%>>V4{T#u#>J zmtc$+`e;pQ((IKi9$QGYh_a|Zj!B>^U~`aAcscOdBikNt=x8)0GlX@T7wihBJjOL3 zb7Lz+-{kJ&er&Y3o1tD0G-6AKWNr@NV>lS}5$say6@EgN%%3%hTZhyVO6`ph-8U+s zlhF$+#ZeADfK+?vri=H%-W7qJ#M&`t6ODe<;cU*R>XFDDl=09cD+OP9u@hoDG*u|k zGL+UN`IYS?P_`>)=wVn7cdem1*&6u*Yi+XCI|=dk<{v4Swltq7GQsfE-a z1GAb1tIr2hXAS##U&|y+l>X8U7HM=AF%}4X$`S}&re}sFfx~T5M})FsPKog)^_`h9?HFy$g0vVD7t;FK^~r;S1;7ff`f^dT!mLjiOI5KX1ii(DT#}B;2cjk8REL zHYTap4`i_D0;Q|-3EjMrjw!ngrSn+bKJi!`A|F&puwdle|M`nP%$$^Z9DE^vvY$tL zEMMPUV|1?wEJV&^xjd0X4cKv9qF>X$2Qk}ugFjG}$ zrua-vf9VKj$*h(ZZRtT{s9C}~o8YmsmmboROB!Kq{?cBIMaH*2jk2SljIq;kak{WB zGPFtX#lp=wu%2nw+b^+O8Y8TsMB|QKgiB(FLq6zEwhHU1vI>zs%1E~A>E`~}Q$?+&Eq*pJY#mFvFZ5Iwh5{0DcSV^fO9;~3! zq(OH-Kz-Kl!t3L#hv?&rPc!XYLu7caS#VDj_8QpwUDegseeF+$l~>z@A7JZM`O|N} z)+@hV;Q#;a=F53ikaP)BfgY=`X!WZ_F!0G=PK?08RRZq^ub1yCnf`Due%UO=b?K#Y zS@Z-n4Y31KL!e*tQu$|vrIE3o{=YTEUY**vo!=jZ$_5mJ0(!cC;|8Ee5D59#`sn@_ zZul;3_J;vpHe;~>ZVlfsAuBsj5(@h50I$J>SNFl6F5h36@ITT01q%N#y6ZsUckZr# zxOhOH91{oNNb?O9UY3S(as8rX^8dWLKUErDJ@3DQ3W1P*z-K=U1)5lyxPd3=Cy)j7 zP5#fJAfRUWnk+8pN=x9|1;4_gKg@cGMFINex>y;pc&X<@NuV^Qv1KK*`t4`9FsOm9p0*$vLki$^LD5S%JHe z1>m55p7gt9^mQkC>9up|x%1OdPT>3geR)AZ`7$7@2YHn1v!6*kH3S_KY-`0C$G6lxJK)~_i^w@&bqZ+1#B`f!XmsH@#b8T2BG0*v^m$w|4*H`zr_-u% zIK0a8cy(L2O!!C*-ARL;FHy&d>L)lg809@(E;b@GH#SONW~if9y!%D|ip^N5xMOoP z%9~oB&rq|*IHU@l_5>%VYhCbiMH{hh<5t?)RxL~UI6tj9D?{PNo?GwSlChY1>X3>> zjx7g86qaed=fV_D4a!CpzMmKcn8{{nm*{}RNU)(8)e;jSO{FZYWE0O zZnJ})V-wXL?^H}6ZYe+_ZY~_g%V>JG;2xX~O1~AsV(#ff!q+r6b2XV8~8dk2Qu-wOM6+9p?wVs(B%)f<}A>KL}+6peJT8B|fKFxD6-F^f!m z(S>9uY^TJpW!-?JB%_JH1Cz-|e8S$+{swU}vwfm2XXF5Bt)O-*`rXhZ8F;pF;yU@owL^}7pnnYJ{e+1l zUL!;Z+53q#Pw*tV?Nsm{Lf4XSq3H#Gy5i`{9F^WTneC+{0m zs2m#6uwc+KA}k7RVDPD_X_KN>X{fRfk+wc_z$ihO+=|nZVGEm_Aw{RaeV4z-PFD?z z-7hbedZWl1sBSW3x8K@JFxKV_8yNu4iaKh85U_$7Apt6fun=#xj zMUUsbx({d~E>mcfQ8TmSluMiY7`wS3zHTMmAc9mWPUv(9q-JSu=mE?-Y(dWCLkd)*Q4;C#ZEJbuk^WV zf69st`v!|~*%1ToJPOJ*kWSS+=#-zs-P2%$$Dn0sm%Mv?z8@9m_z{Yr!MrUZzBuA2 zr{Pl!{uNu1x{qNpQ|8UPu;$U`m1gC6Ya(z-v>e!PT~cO7_W*rerI|gkAlc3MAyv5c zXQfD9OF5##YfB^x*s6@wO-lFzJ@}DDPOq&H^qgZW^+xxm`|d90pZeJA5w@ZT1rz5= zE8IAAsM^E9_yipWP1cCvdzVXRT$q_q)oWCgNyVK*JC@R)Q^p5{8dgtX-K1@`pYI0i zOL-}pFE@qWbG&=phA)|fOppX8N;)|8L0ee1So|=k32Wb`pE8Q>q^|Nzxi(~!t)?7j z1a{rqn8iYKR{fqohXRk|+C$*lRJno088z*|J_d-*V^4;+*&l6z4A_H^_=&u&m61l% z+$Gb5pY;aGD@&cJo2w6Xt4kr~%Lwlxk`dZsiq>#)5CfS~ z#j!kd$aOF>RMwG=t~Z_N77e_|!jFPWI#Fg0x*dWQFVobEi4^)ck>s$z2~NtZYzoB) zqLr}LvqIPhu1rF=B1uI?UmZeyKzwAnk0%DcUQKEu0%5?GjaiVn=z;&dIdK9t(^N?; z&%39P>gJDAo;>c2Lg8A^Iu%NJQcQePf5|oeRr@owlsmM{cb)pmKSN8aC6^p1-u%Fi z5bbu`XkNhLK~mex)3Pp#uBt-hP+2!SSioAAg8QJXJLloa!6w35$R;PY38@cdi~k?(_*%5QQh zas>C;ZqXS`HxEoR6HQ=D!9KN4f4i}*x7?yS^O4yF*V-G_0G-D($UyweS`)$gu@EAv zcXS5_?<6Ltkwagx0)Josi(<9DcZldbjn(St)|OfjJY2IuP{F~mV*#RMTxqLNJbkt) zl)5$0TC1N5+=;6Ec<*REHPpY&56v$Jg?Hl9CoCQ?@AL+mzma$ii3n$WE<|Z!KE(PB zv>@@vHY4|w?AM*IS%f`5-$f0}1l^k&uf89!1eZ^fF$h~?N=LtqunAfInFFzB`i@G* zjbU^l@nL<#*ANhs)N;K`%G0G8Z?sU>=Rz>W&`Gw724ezg%J&h;G9)E=dUed&I2LBo z!^&?qn`Nex*!Kmp;7t{VR?UJg>_)d(>@o?Fbm{mOhjdnjb`@{q&|rnzRBn)x4nV7W z(&nY)yxsX!Mn`B2A&hy)xq*rTNpW`T&<#Qv!E?!wDgBIUz4`)fHn*pnx$$JD(+Po{=LiOz!x*5(O~wpwsq-aTd&%c&@}B0{Je)(+vT9ABOn?#(3J zt3toMmG&UM4otG9qPS(G%i)Sq$Ug>ni17-}@)O3MYmt2vSbHKW zVHvg}={>Bq>AREVZlj9qjzn_wc4K7j;w=UDt$7M{U)KcB?kxPhTzbL8THI%w79xq}PP;dK zu=UM}a;+_J;NVZ*ca@LiqC@xJm>5FJ_S}3IBA1(UA2c$wT%SHiS1$glV^OXKe!~KP z2wnlnH=sWipeFvx1_LQECT`aMC&>Sw80UAR`wRJhi|#W0&kg8K{b6+0*Xy!6`B` z2av#K1SVw#c#)rwHuyW= z)9d2B^qm4^;IA9{6U+2N!2fk9(3kr^0{*Wznm*O@D2b2)kv503(Ixt^FX5i z-^K&XBRfE7fUcoYu93X|;e0_HK>PkR92MKonqxnX1j-LCJ9U4$KAcxS72j^fUt&W3 z$#8s6etgG^{5JUkzH)2-7RopBg9ET`|5frsWy)&u4XWFrX0b~In~LhZpTIM-tg7a< zrA)g-PIJw0zBbi@M|k;Vk!1%CJckXWcV4KjQ{Dux9cha~z}&?+f=qvS^eTtGvj-nBgi_`ePJg|B`YgCJlO)1CVfhL$a_L_LkH6-V9$(Ds6>fHxj3~q&Dw(>VP#0s(UvFPx*sETB+?$2$1=KFVALtB z$+@roB!QLQC(#x>!k~vzq2`L4_O@ledzNfNfLh18*Nth~4du~I%Y{%pa%`1qNB2)J zL{%!rHQR8$WV7-XFik)HqT5HwJqp2A(xM<67DFohG9=Uk8TWn1s6+OykcHME1?nz| zTWQLS@yY0FCmmgGZFjIZO8!{*Hd)!osoIn(>b|eP-$PRCx~Flc2I<_e-7Xpr9T$cP zCVQAhD1yAAsca{r9C;(irv=B~C z9`YcqiR4b+7+l|5$>9{g#EP=Xp4Yo4gYD)NoLh|rd)1I5^W@E-QMHul4ni-Uhj;ro z53O0=vO5Jn9ZTaLt~1|el))q&xoL%J(xtA(Z=tmqJ`#r{v!OXG*32djzihHS9sC>! zv#5c47q^Lq&gRABw92_)9o4gvjk_@eZGJIf)okaMEH6pPKa9sJK`@ZZIOowIZc$}c z*msKDZ&Q3}Utt;_m7pCC=^AY1)_rJMFziR)ts;&XSYFbZxBp%Lop^^h&$ zl1RdZBQ~uzgjTMGo@jJswbZImMQ%@HSII`CRS7GxCbXl}5757V5}RuoK2OBQ&5TUz zfn)oEubjz#kSkDxoe8C0a2RtQgpEt9`R~W?!tU9 zrE3tYII?x+CN=K&z4wtSVR;_pLFz}xuS$4UlMC7Pi5jyI`cpT`OH*p?ZxyeG=8Iv& zpldvgda7wF4i+7$sb%_{Gz$|$vIr4ho3`2GZb>Ee=uK zzXnu+AT28XtQ9(xh+fW-CO<-8vIGgr=2{bcg2I|9NhLhzk;li~_EC~}f6Y~9-ONS{ zP}dukW>7>&H8*GD2UIQYO!GT;{Fg(zs~XC*8LQkq%hwWx@kab7zOCrxMpg zk#kvbeL8NK^6c0|&Im>IM0&7cAw0x7-@|+9qR!}R$s5uB4AjNN(J*P6BO;k?vm#6v zcejBp`Uc(o0=H!dxij;$G#}hO_ki^p;~0db5*R)vwzoX1g*|>n5gJbOr5H)M&QM(L z`^%e|?^`TIVP}GZ;+u;iV&fO{sZ%&`p0cyH>%6skjR<9#$@qFgVx#SRM;6yXiGRQn zc~%QEFe|+$^Z+ZAO1hT!o&=Y03zz7kNq~$!{XEe&PCw$>=<7FCe!5OZJkrosO;W`~ zH@#jYMsLNeM7F(j@9HvI#VfSc_@WqUe~S`#$v}=6Jicar>XU1M+XxruD&S3CxCyH} z!Rd6uQzo5S6Jo9^CgD>@Pm`5lc2nBPgV}w&W7$N3_aI*hb-(KKdUzyn(nEU=)lr*c z*lF5!a_bB0Q||qPOe<^({tQesbDN8l{YEwTNvcNX@}qtPXYac6Ud8qo?VH9K1NvTa zwmdp)9qFhkyvl7B^p}A9QH<~=(dyRD$ycSQfhEnmyfKlAE#+b=;@n_RO9-Dq1e-x|PmEQG z8S${8N8pAfL2bFzqhs0n(sIpyGn*KpbOi&brYZ1}EcH+kns<4X(Xa?pr3fc_adw=e z_I+3gL9!ahRSr`;E*Fr%?VIDR_m3=>^y#hK`n(hm#|$gTp@Vav1!DMyv%c7b;%Ku_ zRf1Mp*sI`3)4=G6E_X^a+hhu(n!ePNO zQQODvY`Zl10z?pj7r^j|N2ekGG@toS$XOw|zSKJyi|ILgwaAu0dIf2e)Z{wfThq&X zVw2Hk78)M1v-R}(tGHVD@u2n77rV44hz&P;*z^gqCR&GvZalpZnu2$oR&S_L!Q$5? zu(0rgzjA*)Hue4;+mBCR zfg9>^MQOjh&KF(%k|iSJQJMHeR3TySZrqX()!v7@!sgn+c%OwK4=zHwmS#`lEO*oF zcHTCqS)L6b%A6>{(g@#B&c-00Zr9y6yRcQXz1`C9bX({h?&^8<2S#>Yie+MN7_#4ss4aC^ui+1 z>D;cO<=y$uTnL!upBUtNF68SD@_Q}>3{=kkAGr`P=o|9^WC6c2AE2+y2M7%8a{v0| zigE$i5nzLU`N?-~WM9AG+t&7XX@|c=oj5P$->-Jn+)ONho(?DXrPlgyXY>K1FC&Ye zB-X)Kr}l>tUddlw0%f4}{Icns9RSi?mjd>HI~kA!|83ggzeM=YcIw|;LpIhc8EYW2 zE4?m2SPaN10|B#K+Nb?CF9O`1fMc`XPvpbZ&G3h72n5D*+4lfkY!*Ps33Nr^fB?g5 zz;o{RovzKbbxig3H2;!7`$^v#3{;~34RU{XEjhjlPysdRKxq@uvJS|sa{-IV4gzp3 z>u)QW8~@}?@bwY;!*#qAF6X{n$iJey{1YIR{xmw^QeP7wfJy&ezDrW$>)YuU_#2>e z>3<9b1QLKd;98Xb&o|(8vjUoEfHL~eL&4wqzFjwxgB?(z2i~wh@dKB-`u~2a9Bk}> zeA+eC!q+$Nx6AndFSP*lI{bYW|DhIu-jiRY7F4IK7Ai0SY9UqpgvNVEx@61RvC3-P zAWly{&!v6IBZ@8%QM8)ECWI6ys_=lN3s1qHdfd7|j=+c;IO7UMp(b~vn-^4o75PFc zduZ8G_>oNC>B!AxF}p4D2;&G_{nV-2<(GXc9UgfTaZx{?57EPWcF$kx=!J0Cjo=E=8t$mx$73JJ zJH5jdk-#hTdh}GAl1@2n26W~hNBB9>xT(wTE(?MM&!iry-PxYFiA0v3hi9bFSYm4P zCXD`0HtV6r6yM~R(Y-JtZ+C*R*HAdvscycfb~w&UMUcro;i}Gp5B`r*W+nIY?d^4xLZHwPpdsyDzEkbMHn* zF!RzJn&hm;3f{J?hFpUN4F8rJAnru=wjNjrQCzAD0gJ& zmN51-^q!oBldO*KDC(Q@%H%Hj@SV+FQr^Vc6#@Z)W)^6u{OWb`dzVU((+Td=rwig9!}n7ny%0(uFM&ZV zuJ#!07zQP8A-gVouDW{p2Ls|{ywb5d_=pfTX=Eopm zhLP))_6vS&cgfEak3&klxFO&c7Fc+j$qZCqG>dR6YuvL=@naIS9mWl(1EUl3ue5$y zixK=(jK?>xtW}!hvf!WY_a2>qoH$h{L0(kMPg+-<8CBsK> z!c#kCYY$qXL@+$XEpCCgi%n%*CFDNsIVupbRKK0g+D2e#DO|PK2Rdd65cY?j~tIQIC=$2N_+N{d09*4eVH(VjnJEW0;oc; z7@pp^qR!&`UY73#B$zGL5=6OGg`to(#L)7~-rW zr$j?D{-KFG2XUy9#zlZM^sSIsE-lCLXpE#z_`-&cBftLib4Qo3bi z+lisa!D!1s3*Ycz;Z*oR9~l3F(>% zO93kjx1puY-;P(XO)83UVUH}=v@m9+s-}&}M@hnbh%*)FG)BSM#?K@{eTwoLx8v?8 zM3i^m(AFNBF|S%({BXAa`-0Zou`la!qC+2KLO#3~%|CO5qx1`P0jEOTVvbOL88W?; zr0pRSP4z-41`i`s{1M@zw)2yQM)ETFHp|4FuG_W`mwLKQllR6IY~!f|G3#22n9F0* zOacj}?r$U0of;^K%h@Q3Eo;dV!j5L&S0bg^M1FY^g|sJV4e=58WeGR805;sSuGyt1 z$fS@DNku64^!> zQY6ZRS~zn?IW96G5zBi9R&dc>B#r#^DupZNqGl6SUVADrj9nUjpMSGy$GRo-| zQ_w+2i@3S6TjJ`~nG@6xbL;52B_$nkFr~^pJ!d^aN{2Zqb8|>stz9Y)I?7YR;#NcQM_3aI#qaikin%ki_8Gi`nWM5k7zxbz+ibeB{a`1 zDen!{=B@siilIf-yQfclo(}kg7~h6{yfSIrbIxlw{K*3OL><|ut9^hK~&0*{%c2 zLeRn|z`){8#ytctOR(1Q7&s+qB+VJ?J-%Y5@Uicsl!aFWdScYA+c4s6=_(o@+#45- z`kCCGF%+CFQDOPm$>-eG7L@Hse$YC7BC6-u6^m;6Qv6dNSGQSUsmycn;Nho5t+0bC zvzygMQ=$Z2uDqMV)gBi2?apqw+wBMN_XtmJqa|}sw<21J6%tyNvn|{VdAhNl{OXo> z4@#ufJ%w&h^3v>T#i-bn?hN(Uop9{YNNffnT`C8NK4SxoNi@n1FBjB@mW;*T!eqeG zdIs#IMMosQLW?Ffs6p&}GWeJ*j&nJgX<^PNYA1#zPUhtKUCtU@1o1kQX744#Xg4h( z2}ZT_EEPDNMk8E=2RqSI8}8d50`EwvXsE!zh2KpL*MEiyFH`E@^s;~U&T0Xbc&7xU z4Mqbl2JjVaz*jtK;RAUj-WHxWiXx9?sXki3ktD8cZ%I6whuR$|d~F2=9ezASF}cNK zAGASh^|U_=U*FZ<_nw7CpVZ{1yppvuxDT?B_2EVA9$pE)<;S1arsZ0pcV!Q;qaLkJ zFR+F)N^U(uplr{Kvtv)?d-Ws?^h#rojT;2rjaVOp)k}rPMghAZ6Cu;)A02(xoEPxi z((2KTki~#>j;tFrvqu@xR3ZHL$+}o%L&v&uVbGp3K;tFYIGQ|AQgs;vGaT@eB|dc+32<2ssGoiva^|4*!XcoeOY``}5$;Ev$c{GOli( zKV3b*;0gegf5*plsX7l31%I}B`leR;*R9|`H3EL~4g>*I8i3)yE#Osm0$_9hrvYBe z5nMfNf4G8d02{;(Jb;%KC;)#6xP@J6g|heyo5P zCl}Bc^`G#7^#lr7{x9)e^DJNe*8FLNU_cKDXh6DrD{=v^K~|vi@>0$p1n^Q^pkJyc z`)AeGwZ!gs{Mm0_;BUVrz%zVFIfE|CvjBBd5Mb&GX8&#W{@U<>7N@^|Os?p?s~yQN z(2-!)e`vWe2$Z%U_$HW(BkUM7{p7Oza?_S@)VIHTIuL+aE@6z`=-&A%@&V90Rgi237C@K5%YU$>}#-w+_cr)0 z)|+|`pm1EtH~=$5zouAHW6;7jc4-^kWl;@>%d({j7QARQe4^Zl4o=A7i|48)od zemlZjU!o_9Rhyxmc*CsD9PbXs9@I^4O%9f-Tk+M|{?p?(TnCIQZ}CtF-iArWb2Xp1 z;n!2}d}Yp|){jC#3c0_MRBFvE?Q@et1v1N+_i?wj5VRrv$jA-<2+!)Z_dH~MdL+(Y zY{}Ufo=KJ~mHVb|BUG;Q0 zO;g+IaO9oyOjuK_?P^5!7~`Eg)eR)iJa!&bR4RQzsMEd5eKToRij8SE_Wm;(1#X8g ze4VWG1k|aFh6%K6(9iF6e2BF)ysaXuXtuW{TR0n@QPg-Vpeb$&0}D+}a5uD#=bb{7 zjwgQH2s(rg5?@%fE?!8lOs`&8F?)^4F6(ws{__PJGK8VC=~E;qlWbfo%YhNcv761# zQv@y^kDNg~*!(q8P$~!2VE?6Rwi6v$;`p|%&X*!N-tP>ON@~y788004NgtcoI;*~S zPI>D+f7pt6mwPnL&oipKNxba6=dznNcYqIdJi;Lt>Xaym$AeeMAYl`n#JV20debjb_J zVyRaxvYEy?!i+`#w zd7DIML}hDp9a{*!h9r06-b1^)gSt=YD*WdAm7ZG4*7gxY5oE}sS2#`!j4M4yKzOb{ zH6~14KmO5D-KNzG_G~=+cq2EByCG@|#4_gi=xy3z#Yg`llY`Sn?b~`&c)cR7MIT7i zDsQtW4x3dSC>rwGKBy=~T$mxwD{y{o8Qa(uxZkSdVyZC@56EVT^JzA>_W)-JpIQE$F@D+Z4B2eJGufduYTE1m8Y>YT~YL zqU=jOm_Ng%){YZN=$Sg|V_EoIQ5L%G{Tu@Lp+~Acd&vjbUVN+j-9b{W5m~YX#5Y;^ z(^STtR{6I~rETpeNOIH8MIM)RO}K4KnjAzqqKY(m!0}TZTB0PRrZDcFkL^#05)2bl z8qJY$iU%3kIpPpedh*x5WYEK@`xy(i{@lxe^%2ycVh*2x20Coaus2%~V}aJ&-+h+umrNZD@kbp(=H z3mzv-TMY#~d$AM8q87@Iw_b$wl8ufvI#BbS3H19nLxd+n>pkNRs(iViD^^_I9#5}L z^%M)SdlE#*NW?0`>}PizI&Pkfdtu(;=GK5qW1n%0!C-ZaaYx7F>MQ81u+Pp$tI9%1 z8xM9WaF@=Qdu5O1jV5b_GHtYJ~%W$Q0<)5G)&bKsHRkD!?`zhK725t*GK4;XHI-LkSXij@x#Vl{c=@YOwK+x$~bKA znjjn5Z)Meo7=I9KWmjFuIKm@b1=^|VPL0Tm4?CpoE3+TKHke>IAAgXX7Zwn>Ls;wq zBD%Siyr1GyqGXe^PEV=QI5d=tx1*lxh{V(?VTe!S0y0x>nwXF;rq$9swjmC;s+QM8|3!-e_NwvG%SRfz2c5h7=Y zXZeEgFlG5lXgri?Sia~ITSpezv~rj~KV6rmmEQ<1Ar6EMu}Ri!@#CTGj))l0Fiom8 z*Kn&7o-&cIWW9(thj;F!cy3$7%we=xSdTr;aaYk$Q1gY&*x}jMn$MU`Y9URs0KRzJ z3)a+Cj590plmYF1dHct<=mhFj(NYxelp^l&w}e!U2@4^NDAv08)nsGK;^v!?+fe6l zManE9(Z1VrP*Liy5TSoUVe^sM%h%s>WsD>+e?Km%U5kBPIo~N-eGq-B8hM$vC%F`(~9iguX%WpdK&RTujrivk*~YkVDp9G>g_wo zZYKGH@Sg(4>o}{BaRki0p?5QnztonWpCH*$W}ZQx4W@2Zv&_B#J&U$q?))e_a9D^& z>y+7`JmJ_7NTfMESJLz)x%^gg@Q1Mv)Gy@_Pc7$<-}(qVj(=b}8%Q;o`<9fR>}FDs zB?AJ9(|H4|nBF4*s9RY-)7Lgb0*-)<8xlYh{&S=I6(jxFs|LQ>T>U_TUTx@s&!qMB zjJ1U@>SBqwn4|A~&1 z17MWESG{U~6y0^a$9DkbHa{z&Ju>3YI{#oSb z>!tt0nY z6#)@~fF>>upudbApsYdv&$+^%f&0~C|2MD%NI;+`@){t_{*y4x*EhyLhW?kvHQ*us z3Aq0-D<{B{vR)_rbLrLj_sU+u@1KUU0>*~d&;SsYr`#&Xuy5k#*78u?=5W8U15Si*Ge}^6tPY&WHBUsE4n)AD zH&5u&%w(9Sd-#0AeAh+o!%#(+tpm4GhJJGf_SuGFg!h^Rb;2D6x%u^z%)RG(F;Q^* zyQf2bGNv{Vy=V3<6tOgU;&i3{S!?U(64bLiiPeq{`{(PLi6qo-5$q`wZEE4LX_Hpk z`}Tyyx{RKzxP97Hs2@Y>9^Oj4H94%WV&SbJh&vP(S5ndzSL+cVF%s*x@WM?`O7Yku zSCm7(tnd~NSCR|?PZVKsM%M+OtxOu_`@zWjgZ}i`J!Y)pwAHA3TkIL`mYK!z8J}8I z>d)4uCJskFfz_Ds)!b^v2<@FC9<`PjeXKug%V03i=`VK?=GeR|{76;A*TZn|9(U`z z2|rm##lVT3CqdJ)pWn|-e)M}a7GFOkw$&?ByBcq%%JrJ6zk-)YV|U2VwgF( zomIx$U3^(Ov(6<%nRSicVyn!yHE&70*?>P0m*fz+B{33@_lEuWgnfa4=`F|jnvF+d z2pWw1 zTQ$VTJC;ClW6Pl^s1S~JN{OLmwGy~9ynPXkm{K0g#2Hjagcd-Y^(x}Xj;l5z35}F0 zxVVGN4ut|S@1gaauNeoZ`z^b5$tF5&>1Jpc1<{U7M8D2wQ^y?2gwG|EVhnghp!;di zgYpnJs%k0fx`2-Y42a3``#n2}<}&bzK@S}~D0fTRX`>(|?<%jajW!66+&)v zw}iqjwj40w`xJg+yQg^%($JsVi)AhKNfSF)U_n!r5QNJ7@#p&b2ETHP;2T<|+H9~Q zDzuohb%!aDD49%eR%yK>(^6^m&!ClTWj^yQR^CK&+ElM#d2w%HzneyTV|*VsSQjZf zD`Q2$CA0CY>Zvrk;UluR3ANcY^Z1epPQiVhS7xuQP1fq7+6D*lD$1g#;pQVy*&p7A zv7p>{j9N4{pn#sBl|3G!>fKN+lPP6qEus=St-#T3$+;EutnC7>3PA&mvWZt@hs}{3 zn9#+E5w}dyLIGFX);XJEX8Yv=owaud3=1P=T-r7R6}xg2?>p&ZZ^!MXM)+pIVj&Fp zAiB!C0Ts?Awn5rAdCp>PyKv4T@O=A=SwAVIXyBJEA#wZjidFxxj=-ad<^mXb{=n$E zS-q$_7J2qhK2*i6$;frH>CwPnkINTPx5e@6|GM;Pcx~~Em@B|Vmt^MAd%YWe29lX( zpVg}kQq(XQqox$?jQ}r{sqE75?nc$d)hgX=8BR8{6}+J`)I+CeoX+c0$%cd-6S`vH zS38y*;778#F~P)9%Y}tU!8%#^egUN$JI3b!W9_TMvf8$<>6Gs7lapIsVR3IQQzg-yc4{&-*anJ@?vc?Y-w%V~!C*9-kdR z$M}%$%BNG*u_r8hYdI`0++HQ%K|-uyqT?D2!WxKgIp#DW+tg;>C)m}Jr^z|>$DzF0 z;aPRPkzR4iyzjUSL>|Soa>Ca`n(sewa=;+B9r1BtTeNw9IilFFu~vQ`vqdXn0$q)M%X4w?fS zP<4YzIVHU&Ss!*@7j!0k@N(hW{|16vhvS9NlsF*>-cCmdEPsOM{a;;5l)-FTN&0MF z3&QW{70?Xjcr40+o1>GkS*?p-RWjr)IJ?n9y~kl^6WZhn?^{|`TdCbfv zx6Pg@p^xNsgUI&cd^r~TU0|$3gjX?4+=uiU7zKFmc z^V35{J4qxV#@b8{=r4)PGoq~PE~%lRUSXmTZ4(k#k0>cYMeRxuc6xZ9>^2=2(H~zz zEHe9OyPKx4e;ooL;5|-)wg$SFI1!2QbW*mk&cPq$xCXuUTU7KOJ{bdb7Bv7_P=IgN z#M@}XTLAv~`7a?L@UNy)TRwdHjvF=!Vq)rJGp;7hypW!so#+bqDu)?pO=LpnSsB5m zkBLZY=^7Z==t9jUVt(j>TIl1U^j5QUe^?2-fZnN5B#u?4X6GK^()l!7i{gwf=(c$} z9#+%gxImD%sr{+tEZrp=3K4MkzPVLO<(xd4dW1LXOL2)rw1Ds_dn#aGj9$E zmn{c11aGFBVF_@&G~J19UXd(0X}QNCv=vFo)ktHBIe1?xBLq96)Jbv$LmRVo1+-gy za3!@JSN?%k(g`2fW9%x4`&16=yyyIgud^!8W{kPIZ2US~7S!&qor9jrE5lvJdtErW zIC{PHRj1s4v+QvwOK7t(SW5Y=?4E*BSP`UM&t0Smr)AFb4yUic1%)#zGf1~EbJ1-js>C$QiO$nQgP^3@krFD9(2tso@QLwYY<`f8 z+Pr+_wRve5XG=pc%VK6jL!e2WX<)GZMM1iX-rm0~w3RiQpqQx7-h_I9WQB=e_vwo0 zSl=;peXx@I{-G%2!Q3SDfHS$$8NQp`^#1fN;wWhH1-R-lj=rJr9yG%hN{dtqsP*MZ zz-6-HIg2@N-omOJ@1Y5=+_48MqV7rm#HYy%gu%=9VRBtVT-PD5i=GSces!;RSK0e) zJL?5$Z@o{#B{$-_j*s4Cr&9&l?1Wa-J$}xIVfmSNt4cPSVb5NtBHL%vo@~SKG7|hK zI~_+}-4GpluIpm_+3rNcmfU<0%$0KWwxIw^5iiehpf_Xm)f4#3msMafU8}96)Jd+F zo>6n`ukHYA0A=F8%A$V&Yi{27e*$Z6geLwsu;#|^;u?{;k#oKI@SSo7zyN>1Hvog= z&kui~HozZWZ%f|%@pa}mAHI{>*uM)D{o%^`Q|H|e_8PxgT7PG^Z~$x;fPZtXQ*%vj z;keeXVgGG!n!Cv@H>2<`Q3{~@>W19%J-E&npVySXhu5&82>`DLQocW%p{`Ta?4 z`IqV4No~2AG5>P(zEfMiXZI(w<$p-;4h-*RCjZL>zk^WM9afxxc*}PX3b3;Uz=L1o zR{c5#1(1CH^@aWugJQp?-~eQ(?-&$2faq{?{(lFdZteyDa!kK3>1)m@H{j9peN6*0 zGXUQF|7%U(zPtYNn)$w_|1Uwn2#X64QTmq&-Zdrvj^zCA9r2pd1IUwq&yI!pS~eRn z6Z@CLcNbml=6?P!FE0zAY0nHWfB!E(0LSG3wh{h^{O%aRAH=zTa|GF#0g*A_G0Fn? zom~rrv#|mj9RR?|0?^nve$}Y^FUF*e-tAWI+equppy|CcMyku3T5X8B*5>W zbg|vC^}cpLxPDSIs;O%b1F~1_fWk&{@4BPu25FsfxrUHrCXuEo z5gb4R_^nX3A507G3k23Oh)3u4Rp(O}nzoppM6*vv zD%(iB7}RHwS_`+sU=D6=Q%U6+FYuk3RaQv;9L#-q;YIn))QaUe4#w2EszM7pc={P0 ziAS-5TU{OH?Q8-E;8Nl~=-ko%^%%o${A?UIynI z1JLc=n_v#f`)t|-yDbm{a#>>na~{>_62(;LB~G!C3`w=C&EKZLLF*nGY~wSi#fs;v zLFg8ay=&00CS5#!UX)XNDXC1xKYmYU{?#nan;z$xOm5|N%(h^Duh@Ijr2Lkh^s1Eh zh_TA|Jwauz-}D((9I~zAT^kuqcQs@u4{FVN9oM2{_?c^sI423lX37?aiY#V!xOW@A ztXf-c)a8}PEU=}ilyrYEA2{)tr~X`R(h@sXKkShZ(GIJHl~kgf;Yu!ONRQ)GT%dD# z-e`UPd4O9>HjvY_6|{Qq9VE$$R6R(VuSG0_vcRJ+dUu z@yA_|4M_vixV=`KSBPLBn9p(hO2&pkK4CTD%M$c^#Yly>LS*ydEZL*&fe2YtqL9Fg z*zpk67Bssdca8PRF4G0cIX#*$%}nWFt&QX(1-Q~@I0@T7aH~?Sdqgnn4IzpKswXWFaB8sI zrsxYBQ)041qeK)EqgWg(*@T3vT>ZsFh)m^UYqW5`Y=G4Vk4~1w`-w-Nn~x%_3dcb2fM?OE%YMqQ!J*&6U*6UkTb z5|W$nu5JEgTv78f?4bGhfy#$5!ex+1Qa#=M=f#*TWH4E}AtF{edJLRBAxosbz5898 zE02iK-yN%)(=IVmixy9yyok+rt1F_Z!rnJAWI}%`Ps`|}>XAX6#u*O&V48Y{|Le+r zNQXo%F($Z{e1d;ur5 zB_3p7L0Us}{MIOrmMpe6#6bIPHhA~b#O9z<0=F~Y_K8OXhiLv^j}lDvVW_tb?J>?k z6Q67uJCtvQiE)N)u{Ha$jfQ>jU#vg#b%auUYs0;Fex^*DR=ZtUKCZ1qBu7tXRx~L0 za11UXC*eKk z+9^ClRUE>Vrm1$(>93Rez5VKTl(aD~pbkbcP@a8qdy(YMPoA}^A_2lDykdDubYzX1 zgDlbb)&OyeeCd(c>FA=P{irN+H}w`j+j6Q~-e^s^lGo%0OKXkjmH8-Fl|4!G>tZ>v zr>EVSNkaWBX+DKygiUKNl}kkvU@5FfAI?cYevO9!H&?Ng4h_TQw`HmKjPH3jQ^dVK zUo$-Q25z?w9D(ok_B33sS+YtEk6BoASiOK1CN(%pB1hrwE62>ux5{d7-WjE8(ZP?t zNSw3nJ3mal&yEa*Ph59G(K{TCbKV9TY;ekV5h6(O^hM2b(nJLVMJDrhN#Q%XqrVzbcEnI%sDPuVV4UL(pUWludUZH;f+A6O)xO{=psJwL}l$burj6^~r;I!-exq!GP+cq(4NGnO1D zRwf-nFQ^W2`Ep z-NGdpISrg3YvK65YzR|?9+jxPIz|c+)j%?{IJ|K?C3$VTmU!a0~>ML7H_k}G6A!TPq;sO0~E3L;-%vmL0eC)C&8v7$OzclD}Baj%OGoggy zv?1_KOGvC9`+>c6WlC$Kc7TCAqf3Q=O^g>99dMx~D*7zx8VmmbY>W;$YzZXn;KiWG z3O^IcZnEE_Wcdt2e{s`L%W+-tbOV^is%orc0d+77Ffd4c%wrkGDK^-KPZ^oJQ+cr6 z#=>I3q760tO(=NA(G5o8VvH@u`r=z8#`tP|Oe^-KIPj>9xz<3E}n2@P^6|oZS4euSR8x;vQJe}l_@#;W2TK}AWL}Wq|6>Y5( zU-o&cDdwP$NLsc?TC!B`T*~t!Nh%SB?)no6FnJG5l76N$b=quJL?|UrpJi*}gePmw z>t$3KPwu&+%t(TIw#Cx)J&$fqmRU=>5)|w~-n#>x`$4JqAJDm*SErxQIY31hc;o(M zDi!A+2H$@-PviX4w)V$n&zmp5zqI~ly>o4ZcFmk&0qUG<)ms*z{$T-r@LHPsU)Xrx z!SlIYdEAWOUzNu{a#A>dFwnhurT!_D{hEFTe0S@W8t7g9+bi{*q1T)gfPQi-l=GJ5 z5$8`wWdTH>fELBup=>wgx9?ZtuA{QB0A(f6^>D{gZ`C_L9hLdIJrn2^z8!iquf8Ak zx66nBR5AR$viSX8jUODQzn2f!(&WEbK2&PRgwJ+eb5f8af+5r_zeZV*!9?h8lXo!q z6i{W)^DCg5h-s3VNcDVOoy^Y5Pp}YJt8`2OKYz59SCn^|S4$1(1$L@(sAuvRJ>DF@ zbbno7rT1l5b#Bl~&lRs9(0$xI;!RbJQ72QK+`09BVL1e54Q|WoTSfEm0c1kIM`bku>8mmo7)b>g2meO2xhy-`8v;K z9zzcuoag&VB@{LY@#@XZjGsyyr5Ia!T-hHjZ!TW&NOxg0=wXFs)M!XVlhqt8Du${> z^%KwSoPd_@l!q2#vL$YPnr6zxPv!c*7EQf54dkIvx z?){4TGH5ea_58!VvXLgjNrB|U&84`vhi+zDK`#omW%5zxRPkw!OH!0cS;61Kx}s*X_gRTF~#^)Xds$$;J4*Qt;ai{Oe6!{@sRKFW`Yw!7Aw zeVU$FX97#Yg$m~1fzZCE12SeYupgf24tigFJo~c6DzDhUp30~Kw$wZk?m0emf@ioSh>mp&$Ld@l0eyhr%ypKK6A|zaTGpu}`w!o-|8eKlWk+TPIcK z1P%gGM^Cp&^^@31kdo*GZ-AhP#sGB2$0&4cDzY3OLIS?0TTC=*SrQrp0R>ny#Z`~)h*9I_vBL^MT6>(Pt~m`z&E5xSrRySLE$&@OFl zU5KeDisaO#gc_|0mbbF2@ygU-{aW!a5wsLzA?<@RYham@+?>vx3 z&Cijr>(@_67^oKP%-(G8wI;|&XN)61#xleRy8F};e8Ur!{InO91^#8dCpi-x`KOc% z(|&VBX{n_(64=!vm=&W}wP=t?T!9Qkg*kY7e2$$aXi$l%M*1zEL058*Gq=LV@(%2p zUUsY;=6;?z{)y)O5*^CcAJ@+1@=q$){o_rMgnlG6-Iz`?zp zf=fj+$z7!wr>>kt9tfxoEDvv&>-xfaRPQ6=yR>A%5;+4c-xV6FUdz^`?aQFKaYi=L z?M@F{d)e?R(|$uP;9S~RJVDV%iN3r4i`A>p0RqR)i9T6!(dufU@*>hA%G&Ct*v4w& z&UPF6LgTYsQoQ8PeWp?rAoObMFDuw&43cee6uw?5r?`BfWD-mGqM0t2!026X=r34R z^pIpND}^dCI};3vD|5TGL!Vh3CX4uhPVc?Fik*8Kh0(NXf9VDsbJ6fn6dd!^45!1a z6&`wIn_W7CUfZi0IBzE2GK@?^-qn7_h<>efATtr#W1jVQ3_=-0zoG9 zE1c({agpt}p7DUUu6nRj-cn%A$!qXJCtYB^_4~ZF$^mJnb+uogtvzwfzUbf>7SHx)wtR{(95y{Q#DZ%hU6i)3|8{iA*n5y7(k02zqIF$fYUWfNByS(t z&+Xg?5m0EqsA)KtZC4xK$nrfA?t%%Y1!f46Y? ze4j$|O*8sMYOx8FDsCF}373|Vm|5}xr#x_zFi}0;cr_^bjyfB=JCoJ8EKo~H;tQLd zslG%a-74b)wTTmxarUF-GNi8Qb1Fj(r=_=bBN$q9$IoOp=H!qxcMn4)>z^SVCDDJY z64A_ReuLTeaIe<#OV!2amW%UtLoZs64jypCyl;)P^$-lnPr)0mqE(fl+qSLT6I%w5 zjwa7%Bg&p-#XkS&G#{;vMd|niLogb9x2K3^1 z8L|VsX`N`hujLPt#f?wuHQVA3ukN3?6*qtOy)O98x{w9ffMo%y4Yq5m zCw4%J1u&xqtfQ{?yg8VDvBBc6ZLmAa!kg6pWpd0w?Z$Rpw{SB73Pr&GoPZnw@PpSv zF&wPFq$vT&EL&TcTAANc-XlwZ`G#kKk!rT zO8DBEi0jT)3t-^>bHeO^_zCM>u141lOaCPlXlnx0NA4)50V#q19C|JJ3|Nfa4rTv= zOmf$`0-7AaM(OR)Yk#Hxd{9;Z=-{|(vy=S?UdUYsz1G%d0tV#Pwc)%m%Kkpp?+RrG zI%qfmaOhSj`|ZA+pJoIzCva4*J7g$0fz8wZe6Gx_fPU7Up+9UV{}RygcL3u*^xOP^ zf&4zu0pMnTozi!pg9~U-`bD7Q+7@~Ra7IdQBn`(|+8V7YOrsvs-<=_}se0;kX77d+ z25g$WnNpgap5D;WQH=ifK2CR?35o0xo76C>Cpkfb-d-nXj3w&Zw#S=t&l?O9z!k2Z zcV3u5^bSA0utsuPyrTZn(J|50-H1qTjoacpt)%4Ny+xQ zTWXcMOOInVX+wAghHlN|^=5HucT(7s17^DcP(iU~&QGIf_IZzb?CPFbI$O{sH?)+l z@6EjI#tVU9o%PVJV9VPKgOadjuu7mV;f$>xYIC9I9nL7IP0MX5*p8Q3(2fU7M9@T^ zumCU*^J~oG1i(DJAx-u$P!4dDxRT4wc0;*Mp3Dv;*qAPFr^=9;>PK}28uaARA9v*} ze)3pY2k-mc7+hscRsTm7z&LRvsdj#?ZU?u;SshQWXKVQw>WpG++07F#NzN zNVqg`TD6SIqeo@%(EVllgU{{n`~=9e4zA}Aujeq zN);=>&OQ+)JRdTW3&0wOQTDs)m_*6ilTOfY5sF#rQvV=me78hN2f{UmU3v- z4+$0qW3rCY*J1lcN3DG?xMo~p>T_o~%z`BL@Fi#5JOm9-ZLJV3{l5&Lzes1F#kTSq z@K(J?mW_QW$PSrv|7+423%5`wsV{G3wp#~vU+p9H?OuGXaeqk0LaQF%a=6a$^7ake z`t5i7oQv-a>;{#bmG)|r0#$=cnKsH`^e+#CnDFefE?oC180XAGHs`5ecpV_`x&KNpC(69r%aG-<;=?j;Bt{iE8;2ssWsiy8E^Few!&Q!Y zI)#NX`@VZKEy)l>CF@ct3dEtap&j>R@uZh+Qn{VOJi}krG!cYOX^U`nTbPhqdllyH z+o91rGmR^unW!5tspE2taAEnyGjj*6<0=ubPI*a_v_AZpCo+f{>Wo<_W@gYaCe8{a z<+wR^q3G0}ytc`OW=q0{|>XQdxEpEYa3c+gR3;4mC9`F6X;T9EEGn3Z)d>a&fNw{-B zzO?(0c0!!9s;V)qsjT(B>~qJKT1y#*Lfrs z1`8+zkyy(Z*=`BceG(!eifE)1#2#py)dNr_>ijjcT33DB@NVytEOgBnZaH;0IcW$5sqibES7hfzrt z2o29rppFnorB1EJ^j@MaOK;PXrqsNI^0Om|afj@wYF11UegRwB3=cG>oT`ENk)jLO zbcj5IUoCYUrwV1kSA281oc={uhh`v5RYE9;rdoN2T9U@Yks+IcZzx<{=1U%>hzaU#1WZz9F`I!8jMbt-(2RXazg-cw>7| z^XJ>Tb`;Md-i`M17kEI=@l1#5nM>lZkz?_5G`wP?dpE=hYx6-K{9XwehT4oiQ+79X zka$ZIyK47pgzSq1@;SZ&qve-H97@Ov6jzul!k4;yvN>;k$QFZH{iS!wE0k;`x6$!y zV(@V{W@y4hw$UZNY@_$lV8)9uw!=|Fw@qr&AW{g{zuL3wB}t>g^PZ-WtV`O1-g(;A zAbGM*YHefbxDn=1-u0!l63&aQ)G}$qEh+QCiY$?c$E%*e2Oa|PE@G)_ac`3!=D)CQ zqkxTT&2YUhD`0|<=VUYNU~7Ck#w^K^ErB*sz$)2_XEnVd@oyCEz}yvEs> zlGta|D~gFck!{SQFZF@TKaIA z)djQ zPM4ydk+Cj>?{2Mr}$?N?e?=>4FjDz1gz(Ge@E4G-j_Y%3AObU5&X;L;^d8!fu}a#NJk zv3C!Sf`gk*p7IKoMsy36dOdu@OniF3ipEBQ>}$Jad~kiH!$yJ^TJIk6awfheN1cqf ziRqwZq;f9rrGeW}uAPU%l2noPk>7g5PGDRY9$#te;M$wk7Oo~5sP1JI6X&GQ1F^6o zZ;KX`XFbmjq8o&zw>3d#s93q4$%*jk$SpU(o{d9=hJh^|J^mv6d{^X!3=R3p%9pSs zy@t%nb%PDW`}bHkBUwT!k8mEkB)xseSi!LigSt}mDG6S6GZoV;>|lG8ruRL$lc1OK z`e~-EysOIVHxa}2G--%^%z|s+s2>D5p`>36%p(bO@}`DJa_ zp`MExO-8dhz3uf%y`mr0-C)ni=IlBL8^Zkb5d5yN* zY%bq?_@fL4zWLt&a$_C*v%S<0)X?7rVt~?`8>sx)0l^6N>y3H9LK=`?1cW#M6)Fv052Et8@^5!0BU|)EaV?7 zuzmnA{$+wU>WBab_j`iCl>@Yzf4i^XpEA5XH-EXYfE8c{umh|SW`L@HO=$p3g8_a5 zK-mSp=lbmg?X3;1Z(rfRm#M!wfUJN(&9x%s|D^|X8ZZG`9se#peFu|U*#Q;*Ukm#N zjksCrzW{9kzGnX|^q-(Dpx@-bgaY^?(9Lrf2J!uKHk;sF4GT&vl%?U`i z{O7C61~l)n1HjJhqy9i2xhr2*;I4D6rE@Ek^EMCXr-WI!0Ofcz?@`)!2v=TP8W zffldZp`16S-ap`Je-FJrBrwOX8;F2=`0a4^AK?1C&X*Z*cH;sBYi}iet#9?$DF3g( z*zdLpa54QIGW`yJaR9pozX*S2;!cOncI|sKi0q+3m%2_v7wd9*MIBM9bAgs6fq*(5 zdy{?bV~UZC%iv3Dlvhz@x9)xx;-Ww_t}^bRYPU-1Cs@TwkTm#cZKs(aJo9Dr+#E(DlyneR!^OqU`tI{r#$F@RpUA;O z09&O?>|hjiS{Gi%pfcL6_1VIpmZd5tINtLbU!A~pjt)Q431)B;ScZlA_n*1f&c#5$ zz5&MKN5?iwP4AyKz`ht5>1PcQB`LSCt7fLrqU&*PXms&BEG7(pGcQxBh8U^i)N8}nt8hsbyZf!x8`Gw-s_-JAY)wqT92*;IfH@X6WwNwifzzb z9v8eo(&hkW#h7F03T&qm1IkFLkET2aqbrx8eOYhF$SQ>RG;-6SQjJ^M_yFvModjN| zCeEs*jBFEqte|)-B$C7Eesed%Jlq_VHSWVAXFdmFDgxYBQ6sn|ujPbWaZuHSJ*VH$ z57w5=YOeEGZLUH#Qhh*10ckCiFqa5;3iEA%1Fvq7*Yhk^@POrMQEzXMSfKN<8|CzL ztI$e~{Ui~Y#i6fu&GA&q3bhbU6IeG$OUu)`k3y-@8=Gkzi<5w1wqtqbxh4h_mF}i( zMP&L%mzQ7&#sSA|IN)ruxbNVC0rIiPmqaSk$6K3Krr2XoXH#%yhlz_nVd2weN3!PA z!6t2LVn7a7Ozm?kAT#n!8?n9SL6y!Pwc&C6WXp9i$7TEo0db{B0RK~2SfNj~^Yfm# z(K2&WU80CmXdBRlr#exnLX(zK4NLFiof*wU{J(aVtkSGDAy>cdqtp;Lr@#YmZYU&N zUPY7JRD#YL%z{6B8%2C?M;(Ef1ZS$pJlylxXyEHm`gVQ)Nx~qiIBp>Flush5A#Qm3 z1?eX1Cr60SV2zKFL(2VD8WtU}qG!CI2ov!vR+tQ#mp_dY+|vo|U~`8aajP7o!NysQ zl0{iKHmYnjmr};QDobeIL*wzceDV~^SZji6fi$$Wi36Dz3>lTH_3P9aM!Fp(wf0a2 zcRD3Xk73u7iWxNl`#!+fet<)^{ehy_y01aLFKjN9OP4k_q)=Ezu_~!|YpN*5R)mhY zuU&{SPjqwh8uo<^Y+Prin}CQnqH0f2mz6aET$(wn#a%m)2QF+bzBlE(~I1i-afjJn>!$!Wu;Cm0YdT zh$n5z*KzKbdpx0;C>)4cUyGdfGTBpvnIpI2&znn!`st=+beJ9r!k> zhOgrhGQ&}3PsL2wL-W`$6e+JHa0y-os(odN0815xMcb3xm_g>d!~$E-=Oz;&57UDw zcNb;_nWYYl8dH4V~?m;#?h?p+_hDzatGPb6H7~BN(R|HwZ zx$)?2wyIZzaGsAuq%aO5db{7^Uh(WcnG|fE< zroNXUg&fZ^_PXKYM|3~Vg3ExH=@9q<`f>*&ZKQIf3Y5r7ri|yS2}U~GNlh&T3K;`> zr_Ui}D9PJwW;{E1s;z=B_;l$yVh^>6{5J2USyW^VD~Gei=PgwaI>m5m6+$*fuo165 zr=2}`zDsIB=?fR^f`d*tq8*v~c0x(#6nrFYfm`*+7VQ|jgHsLUNHIB}8G)~H}m z?Mrox4+>+VyM~NA^BX?8_ihwkpJ75oiW={oH1YeW^TlW2RFpv-xY44rIfcapyOW4Q z7S_~C4z|+4gfY^zijgZGzf2V5-quCP#DJYdcqj+X(+owF?eI~eD8om`!d9LjR4SLN z=aj9hA5zCjUuRcfsKjpj1#b%kl8Y$6Rx`{DEa@hltslwiSXvSZ&fuy6Y7W}SQ`+S6 zk8uG{q|FQ&?V_;?#7oDyo~$Pt<-$arq^R*|3opFPe%696C4{Xao7#shm7#PdJOOe{xBPbStnCu3C1U1G+FBl;pjd!oH$g(JR_Zg6(H?8}vB~Iu6OzNsoGQo-u^d(>tOY+dC3V!m}$7 zVzDMLT~#}{#5-E{SU4a~Tb+3CoCp`<@GPts16l;p=Oh9n)m0=oTVGvf4`Kye4V#+@ zcPv)~lMOE>gOgUf`9)am-70v`lppUU#6FvNE}St70X2|fkGl_PGbRI0by*76Il*|4 zPZ4rp_R)w8BAI=YhvI~dJ*%(aeRDBaHJ|&(mg)D~N%R^8vl^T}$OS?kp%_Ejj~Br7 zpwE;GqKd6o&v-*oV+JGMk*FTHj5l@fOn9=Ri;+?pYyoko_Z$0zPf1$Dl*MbZC66I_a7L4|Wua;$nVU(;@RYVJ zKPj9K1{gsGLtm|VTSs5cV%U$LcpD_LwU~~;1Z1$ff?oJpkDoT+dzZ*n>VIq`OOq8t zj(Kc_qrVf9ZhhVedrU-jQo`(U{)y--6rzIAl@-0rCn6Vzp5rZ7XEMfGqJVGMP>R?n z`&6^*SzA1fwu1*}rEP=#0NV6~>)8q438%T{B|go51s)0ah=6y;%QIGXJca`^W3= zPiPbH^7}uwdT=rQDZ9e;heP_c#mgTZ+rWpLUkASV?tISmr{VbzeIbAR!uNXQck6wC zHNXl`YJmC*P*`OlX60mJ031a)02xyz?q4*K{y%XGJquGkJEL1R*MFSZzf2J5Ex&=7 zSlL;D!~n?yppk_M=$K&zq&t6~YGb2ka?6e*=Kpzc&;s9OsKuHNmzXEy| zfJ50I+5Vb1$X}?PrJkwP-6{SZH2KX-{GCMw^rSNYq9E*m0x`ftVFe@_*qDABaC&BR z%P0Jg+4*nB?@x*s3o{!7H^8>Jrc!ZV19yOaE(_alJ6GLB_4;Gc{OkMx00AiYfuf$} zdsPqUIRmSOh4q&P@1F>0TtI)!U$>ka7~tk6^b0uHwGPRD4rRXvTkgUxxByG`e;LYp zTXguRg#W`)|BhSSb*|TZLqN9XHsk>;tpAcQ8$iYbAn99R3D<3R_@DB+{y zn+MqUwej1C5^%Dte?Gq$#eX1I{Y1k0ZLEp;?=$BAuqHsu;}@}}c3f@iIgW$*Mtw&4 zXSOoI=u%S6sX{w5S{iJSJ0HNH$z39xDxZ*Obib}}{I<(0ib%0(Fc}OVG=ub^^Qkcx zYa%1P&WpW4RnzJqmA(vRZ$6Uh)yBRgDBDt~ z{Ug>OiQv3td}P{eJg#Rs<33hUCDeL>uUJ3c0}0BsEz2OF;G-t=4LgtW%c+iBl7oxedrT4}7I#14sNDm~ zVvZW^Z8PgPcu7^5CHJPD6mPqQT&>cjn^ZE%pq#^HND&o|?Ukh?< zU7FuM*P)wxw}6l2GH&!Tw0de?X=eyZlrIJYKG9f-2vPmTT&C%sa&#ua{JP3Q6Z1A* zd3ae)!xD8Vv>%2H7?l0JrAK*FE4I#Y#2UPI3BC|BupLF8q;V&BtDO3MnVV@Aon%b- z-id!xgv3#djL&HTOGH+?n3*;bg;Cvp$3f-K`ati)TiAWI!VueWq^?JgN6G@!L3QSp zl2jcJ&P(4xLFl&Cf|lL~uM*N*3nUF(kPfj9wl1%Jo8)A?E`Vm0!hRW*fiwu{*;C`Z@IIV-$j@wCj0Khs7i&+~RG}6Wf{P=0WoV8ok{)R#vz`~Y+rtkn&lwmTs81rViVNm~yV;&1 zPHc{39P^Bv2A(A1X{vgf<;*?_m7bB2W@FOG$5dTg@&QywCe|JU5-(zsEgo!{nVFvG zta~Jia!)^q+sPwe9p$2ZNv!>Hn9MBAsC6!T23UHh(U|b)OC9*I!K~G@RrtRYjOiGd ze$NVRel)$DN{)cDE{kOlL*+xH7!ED}9Nrs-^86K6;KzztD@~A`@@&j!LtNVx(* zqFiw-c~2PY`4rZYd_w=F2IL?nh8ez-!V~&729YHPPSSvB1Ipi;Udcux)n4XUo%rfMNuoV`W0$dXM0Y!3UE&_5_2+1Nu$I}Q>9zp3SE!Tr@3KnH$?nxO2 za@tNSUKNZ?c=+ybvhG3If$Kv_YtcvVaJU|s&-&uAzFv(hY!%x34MOFr*f&M56;b}%v?0 zo(OSIw#ULM+9TdJ)@&_b!Bh+E4{adKPKxcAT=+C&D!v_#Sbd0KWt$16p3=?h2E>BY zul#cT!b7r)>oG@|!q}QPC0|?~w&T7`nFRD&qQ2)Nz!(DC(~BB|c7RN*&efyt!WCP7&{Y4Rx0FxIc%q7_ z@32N-q_TxKNo77Gy(F_2S3&c66Mie}^Nf)YLw zWO=n(tgGvRvc+czvi5{o9eL~33OiYq5#GB{x6et)>c#NjqskSA%(fqzv*SSPCxCF>=Alqs=b2$I+xX3s)F*(l6q+i zhw@1z$w86RmjNk8d$uRZOa+n@bkY(*0;alz1;dpPbLrQ*UFtNjf`()kTYt}bbz5ww6Vp0hJ&#IL z8{r5!0e*S%tQ!nFI|O{xiy0!pHHw#H0QrN9tYa1N)qeEYRZzeDv1*=f-|Cd%b8~(y zHW>3qIECe>#;}Ze8QNT@=Ueb3Pvz|Ka&?pWYZH{&K7FV-y%%eVCAOly)hg2!cf%PSt(oZL-YO`>AYgRLha?Sf^8UoLUd`Z9r zRpM9OQ|)l=C|{xJMC{iA%adOuaf$~?qL+p%pt_a4vEVW>d0rxul)8XXZf%k!a?BfY z;S)SPqFgqItd^Vr_d|FZ)tbr`Ug#y&G;u_7BnwnGHM0cd6%S=PsJgxTbd5sqm&m*y zBcpyit+k8)HYk8DJKIj9q}vZ4r~VQ%XT0j-RV!P(1DLw_rpc=ds!?xn!?UUhk1aQO zl1X=#Hur9iC#R{GXYR?PHC$1$HE@+QwF8#bv_dC&7r*^ZvT3#}ukLTGUHFGRvZgv^&d!Ve+C1@+=&E|EAo zmr-s5M_kN*fAjta;OORE_DA4|3ur$0UxA}Py-xvj=>K4%Kl{bFZtP?M;u6=5Km5&y z?C9`Kj+!z;D9~03ZWYQ5=AiF5q?pNO=Og*T5b($F*E4%P%!){oVNY zPWa>I4F6?*-$hXYgofps*aGmWxB>P9&^yEcxMlq=LStxTZ1T+7!RBXL3)c_kzrQ<# z>`V+y*ExO95iluc0&1&&nWL%I-6{THGW^>q0>j4+*hB&Ptblmp4bF8fIQmD%zdMTm zh;!Y{*ME7TSpYrgYp9VOn1~#J#Tg)A2y~nQIRYd#cJAN4(sv(Q2Y}uKh@t+O;G{|S5d6h=R$g?v&2iiM}PX3IjN3|?pOVrdzC0Ns!_u>K!$}wIDzGJa}o#Tg{ z`nc{8T$@1ei#1Z;pHe|b`^%qqYcz25E7bT2w^rg&+NU>duX^KIU%l)v4i|iW!5>u^ zy(C5s#g^9B-ruP~&P;PSIypPazBvA1<0E$PDw`DQ2ILjrSX6{qym!(z1@F435iCV6 z`jaz8QKJx42A_9G%EMjd^s4sSSVuGguuxSZnZ}m)%v_w0r`iT3RAEDh&lg)68%M?o z)4r{MQ?z8{%iGAovKl))kD&2W$MN)Zb-vmQ7Y|=uqUO^R$C5f|gR;2~DOFAQS_&hz zuSuUpii>>-mz~P4*EuQ^uzF zmTG*IxDTFw+pnpvRoLx0w{97RZV==`Y3b^8eg5*Q9k+IR-xeLb& z(J1qf=Aiq^?> z9%gMa{;Tq=zX|U-bk2?dGeI>mh=5ZNCPH3LzgT~sumpa2@pgy=K0ZkUbV$4bMj$y0 zdNJco)?AAqnRz~t)Lak67RfDvxPm(?n2`^H3){auoayI~@=?W%7Q&x@X2hA}5~7?P zO)kb@gcZmfs+=C2syu(!>K?bBJ?1uc0L(*vnD@jP;R*|bTHICKhEVLguV;$)^`q5v zB{f^=aIyoK&{wad%O+2C(hW7c9EzR^$Z6)tQ6_EmT5^J66Bg^dT zBejD_7Igb&#hB)y#i14VOb5DUa&M$+Z0q6LJ53R;;@#=H!BFn4=U`Fa&j>pvjw@#I z4H?OR4c|wvSF8o}d?JmZnK8EQCGh7=8-=w5W5?uBcJxmZxo~QMmE^f$OpY>o*U2K* z(1vo35^ueT{NvriGJ}{pp0L-{7{qLDBuyr_WSyvqwG(G&Nv#HtE7KKjl=M;tz>L3A z$jDhjac9Rc_t%^&+hHa<6}lIU7JS&I#>jOWQ4%ASc3Z7+swNcX4GtIfduLi3cqxha ztvZ$Aa_<7lb2S+4hO&Y{V>mu z`eBg7+dQ76V6fvS;v61Ql}q47^g+t8GUPv?E4OiIe#7@T**UnT+MtX0hJgcD8d6cO z60=QulW#D0ep~Va8m@ks>PH7`7Cu>r+WOE2)}x zq$9Rz3vTr>5$vNjL%u% z8f=Of0WaU)H`m#~^2RY|-5eE>r&&OHix6{fHm15CRc2cDIouOW)&JM+i( z+36YE>DicEiK<;F)&HT9;F=Of075eXG``@#+kVNCT1WE1k`abfeWF4ej*^40MuvwVo&9-SqZch{f)gZ!U;c6 z{daAc|H{zJ1{B!*kD-iUYOZSpUar=raQrkY+eP!})v6ZY;Q!Btqw5R?OK^efe6GYl zSb@&Ce>V6catZAHD?>Se^2dK33Ic8!2S7)5Whl$l2-8p33Ifxu0sK){hH_jI9KY^b znHhlx;<^$kjteREADiU2hO%7RU%xe!CjH%epxCvXIq%9W2|4|_V7sonvs4lNc>#|m zwDn=zYhB)P9W~?~BPTx7E4?3!v+9{oox1hv)r&i|hzmrsfi^gMxHr3_pm<%_um08HxNW`bE;!G!d!JDA(%r-efY%TAN=D2~ zCbKxP#g%Fu-AMAeC5)FBk-gY5dY|9FhD`q8n{q(Dgj1Le5h-o!mO~rHd?@0c*2B8G z;|^kf^tVyg0iw&Cx%TU}%sHv@x5TvYj+ecU>a9?2$adD#zR;SR@!Zu6bxmSztEO3h zF-rF}rM}W}&JZ>S&mxTol49w7T#>Kh%wm@AeYpeOV>{DfhP5@V#Amcc&(+7`GkN3I z@=o)KPAc=a?#?v|dNaxA@ykgi_fhv^%|xj$VJ!Ajn=b8D!((LnEjXe(QB-UP??uA< zx^z~llZcu~Lw0xa6@}WnG9C$~T7U|Q-)2Iq`)!pUJ3zY9aX}}4_*N*zj-wpMuKYs4 z!t2#&`I?!d!5sB|#*$nJJ}YDVu-VZw^U*B|EhS$2-21k{p4V3?hqYc!jBZCs_NILJ3G+D;gGqBR)Y| z1{y)QGFU$pI&0lP$2^3=BZPyTD%Vgl$LqFC$#$=WH=7N1sRkYihwu&&HmT(s&;1%< zw5JPaG4&4B+0wI*9=-4W9CPsQmH%iQv7n!u@(qXc5RV>WXnk}=Zyn_*0YZ-mvoXc_ z>A6_Zef?F#E$;F0aSg*440)#xH2$iyb6=GyzC{&E2A`_oh=+8s=4}hzY4$pOpa(_U z=!mHLZY2&;hb8T&$;hK z4i%k$+jy4`j}?7KqlZaR_Yq7eRHzT>e~eS7Eb zJ4+J9G|KVUjxKwyOnc34*v~hL+&R4pgnL3AD3U7G<68E%ccAnBrr2nbL2EB%s6ip*G8a2J$%%P z`Gyl`_meNNR_18y(Z?Ns6dbmSbUnuKm8s?s4{3EMJxEW9Qb!JEeAWu5Teyu@;` z>!isXR21w|Tr|(0Lj(j0I~6c9V_}i?ey(6)4!pzIBEf}0YC2H*rB676O=>gOMlJ6c z=w;=!*WZ8KteIn^v$_jtg^6AZ`RuLNjuyrI1h4vTP@bHeMXRQ;1cZMB zbWIL{C3dFRWZmNaF*gnusinBW^ zkr<6zeEov^@vv%}Ki~MlixKG3+M;cdvc)WGv%NDG7@udhbrOe$SOQOI9lAG$FyQY= zkwVH5MiT8WVlb{Y`n-di!mO@@<`5(Nz#~3A&Txawe1@$b4O4MyEKVS~v3d9KbDVe6 zOLI9P@>L}e?F~Hk5|{IWtxu!_jLzt|>^NJLqD}Vi9dM{!*DN*TcwI)U8l6yw*XK)3 zhKDU}=kl->9fp^(6qCI0;JSD0GVs_Ya8LVlBR5U>?Ah;#^}2b_YzpgiTI^<>M#Yx! zu6jOVjjGX4VxMUx9p$%RL&zF*I`_>rNGYgm=R#VoiAl&8Mn z{G4pT((WLZ;qhZyZ%uxLSU6@LUx^4I=&&?|C&*kj^LrcHsb#@%ZE?SwEdpwCH++~UM^ics8sgga%Zg`%!JDUD}>)m2DLU;_qf_S`+eM9J^ zPZ+NZg6-+^o0#M4hpP&nAz|w|vp+klXDvdkVL%UGCJzrIM@ML(j1qo=LU_o-{YAuc z!8OX5c&X&}Q+>1aDj`}UE0qs-2zx%Nu`!uXLwct)GbTwkAaN_kgj&$xxCaWua#P%& z5JRDJixJjYRE2_h8zR7of}Wc0+SRoOiF?=M z<52_WwjE01l=MnNyxB^b%77DN9K!qfo;hr)C9lGo9^(e{^=HhL#nuJSEtwvC)XBYf zw@rysX5AlRC;fJKrXV|^`D5j-#9G&A(a5*1#c9M8bR%a0U2i%BYu>}>)M_Ye$D^HW zb0O0pk-zq*Tvvr17*JPU*Aklj#%WS>KL;JP1(S9}+t6g{J(3_n)`2J}w^A=3p-U-a zYkNVMh(4sEks4W@U=`iYHu(`ne5;O)O=+eRuFd`JAs2!Gdo!l6fk)F3GPhnquj2D4 z@&>-6gk*oo%`TKE+Q(!gqq@czuFRFIA6sV(nc{0n-t4U!7>_Vr;{2+W$geCfH|yz3 z^o79BwRuPCeIIy8N|x;4&)EkJn#{krK(hBnh1sPp_R&F$ms|&!`^P7S(tp37-~6p5A^oz^G5i*L3<4 z1bQMat_YQ>n0RB4zSV=n9ap#X7&-drUJjbAK%;TLfyCR!)AJiGC2OqL#0M|6Ui_E% z;DxvSQ+)7(fCTtX_K~5fo{+T*u_hSD0bMkJv@aVmz;{B=0dDM(*Ry+Mie|Pmb z!9>CTXC5<9!36?ZBmaeY*RSAzhDUzWL}s83kO`nh{(ggj=lmk%^oJ%oS~-|nT#1FT zfS<}gyu&O&O%%}o0}dMlB17kobdKSN=cRF8ji6@h+4V0!=}WdL^$ zE5K8BK~w~EMKN;#R6L;H?MD5_h~1^CoZmDPOk52-&&)tA96PX!nSeMWGf>FI3~X{X z_TO$(n$#c;ie;G^{qA4f1>90$0a z5`1HU#}L>(oM1kEFy|fnZ>tU%S_AvV%D}?$x`q7DVBT*oBnxm3vi@x)xUP`(&#k=n z%(+A*|C{Fh2pj|N6mYnc3E0c5z#ji=O@D1m|NTz6_Rzk>Iscp1F#%57#mnV_4HEDdzFP?vA^?Z8|IkXOM|S#p4yKk@77{pO z|2}XoV$~N8>Mzuc0(GtbV<-s7_p)A>4Pdz>x_RBKAXavIc3`Jm4e4K@D+E*hf!)y` zavH$t#|XHCS4Uo=@cWmsb!M<*{MWSqI<|gEGV^gv{0VrZV@#RFN; zeo1v*bU}Q#Oy5JB_^@p$Cc|lD(l*~J2vABsJ?X!*NY5bdbGt$y1Y+<`OTr{)J>GWY z-Dh5g1v|{xOb=ve+5KT2&NiLY^z3Tm76$ z97(Hi?bW_(U1)w|p{yfE_R^T#);M(Wi{X?h^ZkU|BWrrHD(V8!o~2P0ci?EyG0@wO zV-b`S1IBP-XZjL9j8@zF?q=FNsFV}5yw6Sj&OZq$n(Osj6{wWk1_v3eB>2yCNzq{0 zB?1+Y>XU+q#4%u4vdHC#hnRGvN*s{j##h|pIC+OMUwPto-&Io_f`h4IA?wPxck`LY zQ+R9BidC*D7FXp^Lm>$J#4nH5Lxzj84r!vd@;iov@1v?c+}e(?Yj;3(&&+Y1Achjt zph)a2rn2qD6(;K$;;QRluFL0_%*wK zXxJ#NnvO;>%&HzqHSt>k*WA`rpk`kMbJ}oA>1yXtd#HtHRr2tAx)YC~a{H9HDojUe zZ29gF)>4mqO1MI*MQH&+GBm%Uf`)zv%^2B^_*zx!%`Lua0P{VXjqIdBfE7;h58mnkvJ1heee6z4uyf9k2p7sX7Wa zzjUS`9OMyJN_VtIBL=|OQ@PujhK>npI$DLUw2QDN|K}&G*Uo^Ike2X>Sr7LA@oOXBh*{ zN*0&rGSr^rS`8_J$i@TAkms`uRIx-~=RyX-wHh~&Lep=JN5ZZLuu7@UYAH`Duh?yr zS9A5msvv}W_-?Ep1IK^^)LQ%(h)hj z(CEjGU#dnF1o(W;9>>nbrwGGj1W1_}x*?#@cxT}iVyQrgW;jRkzIG~F8M0f9?OIO{ zE;iEd5gv;5hvu*38F4=PT+MUJ-u;B_H4Q2Sh+vK;aaR{Iw?}sF2K#L_m(%To9+ES6 z)VO@qPw(E`9;viuyLZ^4@%3chUfdQb$AX6z%3D}*=QeR7<};4Pqo-)M!`}%xNbj+r z%_!QSWQv=~3OMACk&(RJn8)0`h4yW_?YvlzOJBE+T~>UX@D;(=mmNM_p>*DBxI`B3xnlfdMoJv1M9Rh-lg%y+3B5q>LpDWZkN zXmMu~IE3mSgJU7;MVpn|qzOrzq6Eax z_$oic2Tfx--B!X#D)vr*MY#L=KZW5*LeKr~EBScKK%9Lk! zU=Fr1-Z|nc`4B<7z8Ow$k!vyG7&Ns(kbAQ;lQE~a3bn?K<7K8;me8m>@V| zuh;hFFx180{~_%9!2|?!n*iLjKv@yc@52t%0kHvYCM)M}mlgdt%yr4z`dyC~DAob< z?XUt)B$y@TLi!D0y!>Vqz})Zeb|e=RLyx#Uw`IM_cA z{V)Aoz-9ceS;5TQAfU|Tiigc|Me2^@r&-y+T7Ez;+?Ao=%AcQb$WKFAfks3&peX0c zP}Yk`_m4;Jx@%%1Ls@~}`{!k1Vq?0XmcKHT;}Q?~Z^NIT3WzQh8vQ32`u*m$O9V|nN{g6* zN9h+!i$>M|uX%0G42p@YUJ5A)a@?@kfBuyOCLDbD;*+sh%LT)(h{dTXuQU?>=zN@$ zX)A?vHC znUTnyJM1aW$=l?r?d)DWr^oIU6F#U7UIFmqT_5n;(K9p{&$dJ>spiMwI*Sv8-Dnwbu5$p zGle?`Su+8fn?@TBC+Pm8voyAdmJE(5F>-nlaWltc)fS>lyY_BeIFqVIVh)Au>fBnj z?zyJJZ|lllX(Q}IpH}4Fnhr*pP!&}uir3;>S-L@fS0Yz7IBSK=dg`Uauu0(n8Wr;k zv*g!o5)CLwWp@5h=1uc*=VBZYVR!pY&7E#ARF3A@yy))6`?3gqF#1R|ZV81pBip?& zo{C~q^IJ4$6U9^|0DGQ9*ae8l;z-$(Vm!?-v>Jh<{A_@x^w8~gfPpTIDYpuqp*60T z-u~8$GGu0FUER#UOgoc#sk(au>FYq!V@Z(<}B*n!>rI2Wwoe)p9NTE}!+Y9Co zfmTNm_n>VAWabNT!bLi|=uRVP!&Q=Ps3{=E5KT&Cw1i81sL?U0*U*}UREr8QL`3G* zDd2J5-|&;=&LO^YKW_wG}O-9SvL#5GOpk z=?7sHh<2z}Jo%g_@$?^4TF_9s2W1U#<0mJVpNwTRS4&ihee@Gl&z6umVuUTeyU;0a z@Vq|K1-4Lz&!iARBII5Oo+xU^en(uVy%(nKechD0-Jhc28ZDq!Z%%ep8 zPmVJcvJe%eKqeWLrZ3i7C34A19HTy-5YM3k>LimH`j6;tPzp{-N= ztbh)xFxP-|RKd@2F@Eto3u=iWd|KB!T|{)Y#(W0%^+7_%?(4%eJ74w3U(rFL{|XW6vERTpE1fQBz~U-ja%`P zthfT>9ozs#lgL4r7+4pP=(ka@GAt^OJ`d5PJ@6*C_0S~Pz|+lV6!6Nbclufg^|%P) zu@-T9|Kj{8cQr9uLpRLBWfXe&k-AhwtI6eR;)+l7^tgvB_&C#AleU6y zcE4#6pBvDx4hO*xBifqW)PFu|4VTk5>+QSE$hXwj#x`0B;?W?UF`|e`supWmGYUub zbyOnLk!D>(q9NbmTSq+oF!*J%;+}F{k^)pN0*Q4vB8w^E4nKL^_AaczMw_qCE-@|? z^-Gg79<}tOX8td>r6X0Ya%r4R zzi~E+VEnld-*YsMksR zEH9|^#2rQ3X|bw@JI0!Vor{m&<5QHD zy;gj(qOD^8w85yr^rbne>;W7n&1!lmv$3S>f=zmVqV(XywIkm>s+RC9MsX)9@YY&4lq8PK`LP_g7iBSZIfjIbP5FriTOlU5$~q~OBB8KuDa z!{gd#>hl#;juw)Xu*KWND?o({R5NJpgUpZ~xWO%2I%x=httr|o=T{?GlfI>-{cujN zavC;#&?9#?SL4eY!Pi=M6xlTs%Edvr-q|sxBytvA2K1Ht5}zWgJLqkc=Lf{%(V1FR z*y;NDuuPB8{axx!$&p+`QssIOZjFHQzWNF)=Wo*>rhLxF&{2b=vnmYcw0s7iA?=I; z5v_;1)gmzGl8GxogKcG7=CQkE_aUoDcyfZ#6Lxbe0k#d_h4cWfH_)czrA=0E;+Q#= zojX1fnWolrmlvhbjj>^C`y4I$68QDIEC%jEyu8mm`=_#`6B2~(;BzESt9Cfkqx5UN z8ia63Yt@*}_7PadM=pVPf8%a4KNfj=Gi;m?!@=TRW$kn1=gN@8p0LL?^;SrZ-LxmY zv~yh#$!=5XX{rd5ea%>jrbC&#b(G(5NB+$bM+Jn#4jbq5wF%Txh?}36HrIw0JLFr!MU#4tv_`|#*z+-^ z2(iuMFwW`qLMJfFYEo{(KPL*%CRvT)5Q%VP0DXHe$eLceZ??1J+a5Iv@nPY$72Pw8 zkFSYWVa2I}hHZ-Y-cqDSBjAI=I&ht^RbUmEj~VYZo!GJ6BO8XJI(mCQcE6>v4Fj_8!aXi~0?G_cz}9!JWlMd=tEN9Bb2rx=WTRHL1Ny zkY~g1YLGflO$<`j1E_|3&<=duHfnp^6=nU~iCMVtCLAY6ky6wMm6YehT>2oWIzrj! z%<_O9vvTQdm21HDC0F~uf$NKk3j~G-kL;}-?F=5-gK_XhUBHew=wlUfvih9&cA6U2*7;cE)F&z#SWyA z07?&_1O-6AY=D$HAddBGSn$`{OfCsO|Dl;Iz$yZKF8^mHkedM)F8u#A^NI`)$HjyC z3y_uLlBWFyjQeRQ8(=;s5XHCxZNM4PpHR`yL&2pZK&tD?P>xHA_1Db`5S#$_^cpM% z?koD|Sphku|3V~kkvqBsS${H^1+30~9q!}+Qd|E#>wg^zy4siWi?ae+@&98|5F?15 z6F6J0EHLPQ4h6TlF$1^Z%Fw^gsvoQL+lcj2Gt6c9dWml3QlHH4!`Dl4WIy053$V+6 z5x&*|oiS5v7+~%dqB@h_rJC#y^67DG<20|}w93DYe1a>Yb9aoms~TB8>E#7llpjmF zT{VRW`O?IW14M|N<|-jd%W;Ys?8iWgSt^py=H}Ic!@c^gBP4wg3#r)cqgO*iwL4`W zsa~LR@JUgU6%6PB?G}3jeU7fJ!^zaQFz0PQKFNDsO3~h8(f7W&=mZ-{(wZDb=fCryUYJ*ejavc`+;FC~;GY6ywC`h3H-MVC4a_H$o9f+uJqr^6AgZa0BM7 zJ->x8u%VR@S#u~#*19}nGbWY9J|Va*+$tl~5S(C{mGI#81R> zcWa7tF2=gNtk2Bt_GeSykc5%M%({Ic8q-7OHg)$^T})Ne8FU`3sn-hn0!6S_HYA zv|7!W*elqfP+vpIJ-7V5vsHONo4yKD+J|^URKN#;bJWUU0I>6ThUma|$<+EFp+OD| z$X7E4>Po#&u(QQbWC{*R9SM$tm!>Wx;{C z$M6OA>>r_<*J9-41GcOUcG~=xY_bnG!$gya5Zq3hX4hA;~cVfwp zAv-ZTdVR@^!`l#quzUFZX&Wi@_u`0y>jP+|rqIj0qY9kS)!{#M*r&K>!U_8^N%br- z$YPI0v$JIF@;X)`V|w5maJ6-*AM`{JxV$PvR@&&jr?NNy=!n*($nQgVKq6aC9fj^E znMPzn^vDM2))7bRPgecGxcNq>aQh=jGs7iCN~H8db*a6aZ}S#h0;(7C2l5&}B)#R(60Ha?9^2iXak(pS?nO1gSu6Lj$tSwB7nf;4 zpsSEm{&km;uBbUS8SegS*9lvZrb|PRxLVfd&uU5=sP%y`_-Xm5uJ*KXbE$3=A2{!s zZO}T3JDiqwRlPy?L2s0!edw`L`D))Vb9V8Oh9bX@vUK~|BnsAw%aQ|x2tv0azKi?8 zeqpiE03F9GvPSmafL8h*hixm>^fh>R9$rrhqiXu0+?!c*bQLcOxx$p`O2AW3-3O#N_QU*_35 zy$HD$>0!_VexYYul=Ta*Q|pt{1()^J+JpMjSm;a%GA){Q!pi({CZ2=fMByqvfZ*hY zwP#|8R7O8~Eok@W`*JZX=791T)ig#SM(0%gr!&+nzVRx+$-`^ki{M_pyVIWQZ)h?2 z6{j)Fx%)Liyldy!5!A|%pz3D2xf}dYBdd(Z%srE`FHJ@M`psfEVa2)JqwX(Z(@;!@ zpXIDr!u!B&p1s#ysN)bI*>UC}WMFSY+R^w_9Mglm`-luur;_?hl)T3Avl`=P3iHBK z1`8*rrfLj<&P_zlS~h!)9V2mf4!@p8kE(||qROz8^4#FZ%Q)~?Bpm!aKCL_USk9%N z7mpw&^4_+2;lk44vI|wZq2s~k!WJ)O5bI2_I^Tq$i%GUqg|p7sldpb)v(L%?x*^^hUFXB&aVYj_ zSLko|Oa&f#rxz|^IC~q!nLN$iTwizbcJ(!sF!#cDA z>HG31bviI*Wg`#i0i<1%C@Pn|1`k@?*a5^!x7inL#RSa*!H%$G!(GeOF0mU=<#0OE z=R`4#S?%F+#;7U@u(OsAGU!MsS+ z7Q?X?%tY)I6ol~m_DqvP8sXo@fn+uJYhGt@lymS*fjdPI09Y>IJSjZX@S%va#Go|e# zwm+@;*nN66(uLj++8{DBVHPO<=dh}(L)w8axf0;$WyIOIm;#=n;83E4ncVf641=;3 z_{_3<4pk=0e_hHNs7w9Zx&AMx`oiJ+DP{dbGy7jOXMAtfX5zR|Y6hcf0P6ge#Qv_2 zeHmU~>WcqOK*$6z9I^mKw`}0VDmc-~3JB}~{xTbo6#PZh`gbzD( zj5hzR3jE@R|DlP@K%p%N5Ts%LZXzIqeZi3WhbI2l!qH2z>=(fKV)Oh8(!V5@e%(+u zfZFETtSjhJL(a8B0gWwyY4sX3c}3P3Tr2;dg`=zh9niJn&!9_9BG=8z3J5EKm8z~{ z*sGKoKg|lRbOo2`Um41Bm8j$Ap+GjB&Jkzz-90kjjeg(Z@+FCM>Qw&X6?GA{a!pGKER;HxCA< zS-VZD?Q+P-mlfj>@t>5lCeM!}>iD^`)%e#l7^c2+!cl+~53oO@XW-L19oq}^wRuLf zTaFOmI|5$?PZp6w-*wXz8&PLDy_ooxC-W)|l2IcW>w33nvIt1phthq2(f^3_^W$yn zLN_n1ahhW{=URH@DL$`yZYz}07c}eZQA8&@I+1Q7i7>iE=r{Nm_YCX9Z_vLakfrq= z*UKxEThP~2IjZn=^4xt+7lRzD)+ynqz^v)*S9;%}%?KrJXrnTbi@Q#9{n@dov?Xs` zsk6VAgW{N3(fEB^(%sOnK2+~5A5)D_&uu7|a>^aPFro)-kHPmTcGN8+v+SN#G6X9R z#?)f4+UYnnzA5(@m8#-Tk99dIJ7kWl@8G^QT5@+o*te(MVL(bY>63cYklZU#FYf%Z!^IOHG56Mb)q<2k zkOS6RRHyasd^}@TsyR(f{g0>vku&M#FA76@hnYl0KYgoIv!rY#E6&b%q+VRVBNeL; z^^mMC$l2n{xbUFbO`p+M&c-*75m#ZS=dtx7pYXU>a27DiC^XKdGN-?~N$A2+`h4DnIY3ZCEL#hUyCykDC;{0sbPSXlOux38V~ zw^QIKo()707%R3n#Urygn=sj!QmAh@joxy1VvH|lXK7lbDqWjqLqK{nhag{-774ZR zh79|qU2D()+eR#mU#C6Ay*3*|_&y50d3pOD`)x{BM`D(yCfRr>f)2=6o-@yHVw56l zNgATT6GbM{^pne|M`B7QhfrA9@DHd&=g#&VPkkP9c|oM9vyW+wS{l^8dZ%$9U5=1# zD=drkF@gC!#Ekr^w_{EfHL7{dEVCIS%4`3!Cx^Y++>V8TsIYB5ZH)Db?g-(n@2$)g z8%YiCa|LBp~RS z(l4SEOkNB=NphaImD-QT*wI&h>=vIS9fbaxdY)pk^#L|k$K#41g4Q6pZMg%TsGbGK zr&LE8Q%cG*!t+`bv+S>@;*K*|?&MT=?j9gaREN$_KNb*58%fF*#J;V4>+s1%l5RS@ zP?{&CT7m_%+(ExXdHRZI(fRSw?IUdd(w65FG~TcWnnh!(abF**#(6AOa>pL8+ZDYp zdbsD=>u&pEoL`PzwE7t>3*Y?QMrhxFrLwX6`_INR8sZ7PFCIP4yX{r#zlt;E;zo_O z=!@x8Y&~0-bEnO@7r~DVM~;>CRft%AML*RTi|>8!*8Cu zJwu=9s3PF)6m2J6Mchg2w~2^{{=`Pa4fkH@MdlRCTUAge)LUlwk zGm{gE!-kk6_8WQxwb%@$wZfaXVlSH3q zfC#Pn1dN6gD51otqp}GP>jR!RV0%YI(w<=MSQOx(9Nn}@DH9RYIfL@)>?>rq_Tq~m zMrb^J1u^HPfB-?0;&oqxv2a@&rzr&5f+=#V?*x@n|E@O+aoO`*AfJ1&%O?c6^*714 zo~68f#B*c>x{>Zck^wr@mtsWJpz5b#GjB2+TY{aIR({RI%TV5lYtz1fEiGwk#h+(tA_f_Y;iR}7kmy&nXnNr|!M9NZ6a(H)@Fd{*wM?rgz? zj)%Bn&Ci6aKN}4V__mOaI_^Txdp3_z$!j08dZQ3-*sEzA0%PU?5T}Rm9W)r}g*=`e zhceR4k60b9#TA0cJNAF*JmCau5T>Iry#qs%1M@~Cdy>Vi30`okw@@}#{_gN3j1sJ% z{})RlbsImw{$zFm!ipNZ_oYCk`pjFCgB&i6hu*QPO;*iMg+CT}T30?TkZb9RurVxj z36g3JPkoer8wQlPy2Tn(PqLP*y1uX$VEnnXx56k2zP4pZg>`$X!34LIdauNgUCg?X zJ8|)}mUR-XX#kJGH`BIZd++7!NMD7o{g>XaiqWX=zs(L0LU=TvV;v?xp-%AD-I1uZ z4;zPK{D#LSNSaCI$uY%HCPPjf(8Q4aI?mzPDYGCVD>*%g&`IV_piKLRw_1=AjJ)0M z5J@7uET!YBHz2I4anI^L(ODGgdBA(CrEfm28Wh^zpI?{%utP>CJsM;mrY?Wem-Air zZ6Z3s2D{UPhPrs?5^~If-kG#GjGc(i`X>?4E_NIS!psedqk^_-)AK2Xu9;rZ&8YWC z(fOAY*+j=D1Mjx<$H7qNH&SAI_Ju>)JT7vqd2eUC77Se{xwEZB!=}Iy@D?8WEV5$N zl<$an>su8il(xv&Kzi7%rrxgmnoNv*qo)lwTwi<+xSHwaWc*LQy6Z9dUoPHHnEWqY z%72sT=Dg7L1fV$QcNO7F2>h@A{o(KaCXoEzX37cxa1cO^#{{Tp0Ls8XK{i;I_ZRsI z|Ayeesu@~4{0zhYvic7VWCF5s0KEfPSCbXUY%>Gs8;CeC19BTc|M+iai~-w>OaYch zLsPpeGRB-2N|!&31Vfd-Zul?YNX{#Ytv?S1+T8(mzw1!We^N_cHz}9`mKDgkUjay9 zsP;FSxNayjCjhvCR`V-ESuQmoUON;ZG6d@JuMP!^_x|&&OaN))wQY|q7wwV%w7_8T z9)N1$>Z}|WTj1nnwX%)CDg;joO^3O?gkt8bO>!!kTYz$dGPaXC1-=8HUE zZ_nGvvvAf~=HI_f7Ejt{f)PlNj}-4CmzgD^Cjnzft^0B)DW<(=fA0ItdC7hx5FxvV^rpM#lBb*wuRIX`VX!cR1 z8Zqfaf2n#X=u{3lTZ;T1S%B&KdI?pJveZ*7HxDZFD*FAc^7@{c50%tCW}-0j2bv9W z#Q|!3MV)03KC`=fHX4%K@dez%yMl_IYF@w%Z^v%|^2;T_6=tsJz@67}` zRJxphLY?)>7Yy|KAc?RrzHZy~peGGUhq=;tjKKS9-LLaMx~h*j*E5YjzaP zutQLPop>Jl^yoto=Eo7}>Ow)|4lDeUR3WrdaaYHLnv zHgR{Wo^aiJF9AnUo-|EM6nX>?Vh)6NaQ4SH;MO-I%uxvn_@MnD+0C=N)<^yZO%nrX z-E4$ebYv;W&sdHs*c(~aPa8sAOSr!@zJ346`?%~|?o#L*#j`b4 zqV=khv=Co2zv}qgY3N2~9tfcf_$l`5?*~W6+1a?DmYWCfF-AjoR+~78%@+*f5i{VX z)SS0$-kO`+T$CZy}6TwAU*o!2))y-8X4|;ge7k-_yQlEiMeZQzU-9nr!w4uHg$OwGgeDtJ7 z@yiJhn!D>uib-8L+aAcreFn6*7*)P9>5PlMCR+77wC8YhaFC135J!F8@n{0mRS@r4 z_CBiZ7a4p=BU;oHDZ`zRkHcS8>V@uFy*SoHC{6jQejB-^_uS)UxiB(xygRlV?Rt%; zAJudxrxNZ{O=|2fGFy;bA@fhBzl!!Rh8{~CGCCk(+UUW0bd)??hcq&g^N+0YrMMp? z;%3?>sZiyrQXIZg;OZriBQP5g#e9VAQAVx{}#C=>{S881)qX$Eu$UdCidCyvalI!z!PQ|_f)##^}9RV35m^JPs+$GnTVLs>C!3~17J|CX^8Jo=L{fyYeaO1Ard*$;je#P zaE(jI^b0QG#XI7%O9)OU00G~BjC(~#RKzi0nFq8D-&=>fuz9&_Z1MMW(Ek}Sbux%u0sR=N=xzk>H+n` z08RmNlZ^D>vN@nR4)psPfF=%>7S>i4u2=5wztJiD(S>_aC=Ae~aDago@C*W#xIkv} z*8t1kx7R|?;gQR=HUjOaf4iO+KK#XD^eb=$xSRhx6r7G_1*9UbK@R_OC?k+9y#_dd ziNF4NQWk*zh8ftU*Gzf^>HKu5EC3n=QpQ(@asm(XKhFvRW@Q4X^RJop3ex#$RuIq# z3N$ib9SY81|MRTO8~`B=kW0R1*8e$_4P1$S%}~xu0-)DD5nu`=K#1U)SugRWT|X2! z4X(@Zab6P5ylyD40oVZAxGR_X*GurnDfKI$4tSG-E>Jq~kc(Z)%w2+em+ELQ*W3O+ z!n>rZ@B`to0l)f-2yawf7O1L4t2rN5_ylT-aT!r|3}`2UxF| zNFTWQW1;Gi3niXde6{`RzTvO9TtK-KXTB=kFtDc6rG$Qf@}W{mDn5h)F3im!BF}09$JiU5Tx!1jJc)Qn{S^n2-6`j z+TT;HQcsSXMuahv5OE;CV^S7(HKsjV%_7)fa`WPXrN12|1RKSSL=TUSEW}RI-Y(nO z7||?(S>1pf0&15hhSHRP{un65e6;;4JH0R)E@ocR6?1e=FEbfhj3ky{gOiua;s25L z)p1#ETi0}VgLH$^jdUp`CEX25cXx+?ARt`=(j_U~-Q6K6(k<|9Jjd@I#dGiRy#Dq4 zfa#ihJ!|hh$BZ!^=TfjyxKYF5alXtmW>HokZIj06&F_JnQyNEc&dV$4_sQdK{ivZx zb{w3yovEEm+g0O^O0}AI7!~24h@!trX|VKEw}BCsqaU841ckvsbe5Zo%kgZ?jG%*( z8f`8)ZK6ZGcWAg^3T4shK_21-(u*UfE~ANEA_bGrPO&Bk$Pgve$#|pXZ%1)HsF%;a zH^f^7vtTm{;(5n3VdUMBq^mU%k9z6XaXidmBE`@zh9_L}=dvaqpV$WiK8U2MOIGpI z<)%M*`|3T-Fl7k{@3SM1B4(V2-Xw=PBOTS9gnbUAsBbMcy3R`I;r62eN zt9q05W(;!9=mN!=wzsg~=MjJF$D~isj=g)0UbBslb4K98>9%g-mz7%k3K6nU2Bg&^ z$i5%$^RVMI>ehJmkSG)1cyQn#fA96Gx!4ZBY(O1-w5}mYKw$op7jx~V_I(+a4)aq~ z&dD*SMO}kmmAaW|GiR2JO;h^bz`T(X_bL~0VK1lfX;y-ep+?2FQYRH&dyiJi4ll8W zaAXr4HbjNx!*}WLzjW$?flZFGKG*MGYHgd&{yg&R+C+^jdDc`9!G4{Ayj|^aD^9K5 z7L*}ar9&T=!^>4D0?vd*DVtSuYNW5zD^}Nw?YbYQq{UldE0#UuprlX&G8+`|xD&Zd z)BH&KrWCT8LFdF9L1jr)??O;6SD8 zc}r?XZ3Gf+*SY(d-EE^czclYqWjG99ea7H89GWwArF%ML6}J|Q1~Yo=aJF3E5E6R5 z1u}xhMl;IFMs@@lS!;+>>^KpKq~?y_Bv3>mmRg&CP&&D-)BA?Exy5Nl*ld-?f1t9@yk16yxhB#>=7nHiirVUu^A?%Ivdj^ z#jXj6dE3FEot8~W7T11|&ro4@l>7_`2$tX0x`4X#so$cTd+i1yV(yqc7L@zIFsiTL z&je}HRg0@GU|!(u;%TM)_94MTjW^wK3Tl)yta&@k{!c71Cf+}z4GI$A^k|y&w1n~2 z;5L<%RvAJu)TCU+MrBP4y0DuL4SK|kn@6RIKOhho3&PU5-_gt-_CGfDXDBF1A<*Mg~_@v;|AO#Z! zIgLTyH_) zZVqiaU9fSXj=;A3;t>7yTgYDbuD8E{sXxf_{!QiL+l%fenEHo=%Rh#xcf#x6VC{dX zp1Hm&z;S(7fa3z*)qen205<;l;oB%608_us1>NCQ;1&MIufFAs?|$+J6ZMb6_J926 z-y?{BiNo00fDSr9>l_%9`(tDdpzY)MZT1v%U5j5v>HjyqH4dP+40h2i79djQ0wxIW2z~CjBv}Eya^RNwCy>#|(#G80 zO!t0K>xW6Zf9V%9P$Oi&<0S=ne1Ssb9jo-eK(a=9Hu`3kw)e=8|G3xx?Y9dQ2Z5OW zyNAqo^isgH<2PLV+nxKNTJDijx37nUXLo*Ppbl$jh-EN z&fmkKtlz`~z8}DE2=-@FAa8g#O?}Ul>zW?|5sTqE@12a`z`?)b>O@C)uQ)O zRX_O)h+hEd)n6rzz6D#~kKsQ`hy0cM>i07nKlGCSnb`nZK>o3k-Z-8nkl8qN_w-lC zw{k#bA*BeBx1x!x1IU-w=_k#sdC5gdW@kRom#sYH{ zO(?K|yoMx&|8dLs;N&9jwHg#byrmxzn3x}pNp%DTiZ!`2=VS6J8vRIuATUC(en!u? z8H_CuOvsA`F(lnH7~fP^cXw6mcY^eP@VmhC*7@c ztnN$#a&~RXz|gxtHTblSMr}7##iz9L!drK%Ex#B1ZdJ4&dk(rhNExy!}Mdmg7)k7XzKig=bghgXnh zQX;KCa%w=Lnx(wDc--jXdNPP5llB#IAjtTGrsS=zy>i38kU7_l>vYzj)3BUOr_geh zkW8rJ5*@#hqALDKM!M#05MIJ_)w1rb^c$L6Gh+L*i222czRb#k zV97wW2$!#za?|#k>AR>!;)W3!tM%7|O2#T>QgF;sM23Pf<&TeFKq7|Pz6@)9paOQb)Z&jV*H1G+r#9L6gQ1aXc3XxNk;gsmpF;q}%+6LSJ9cT5@X~2|T6PA`vdBpAo zJ{YR_HSAnpFfAIlhZp4hWka{M%2fw8oZU0X7U*u`sVdQAB}69#{-7nCQU3QRtcX+B z*;xZdsq*^D7BZVo1zBw`2wa*ET~fzcb=3)xCh%26!p;MpcUSJ{*Y?XksFX=-%{Aa!Uj8HQTyUoj zKTVpUTNe2N+sg&2hyF-d^(3p*$%#DK7E1aQUWH0v;7B6|b$eYD;U-)hq|d!SeVqxJ zI@;BJ|3V`xr|Ds_LB&VjsPfKbCBMyW)GTZCUIkkorkKofq!yElDh0)6H%9k#t&AnZ zO(Pnwz9Tf5ubN78BL*Q2I#X;LjxO!Sri(UX%;7PkXaenZ$$f1Hk8Nzgq zr&6o3{3+6$`oa*ucXOm7ueT4gm6S(aqcl8Tb#DPXsF_wQQLbnnsITA0?1ciHC_c*m z1_uojOV(~E%WD<^cqqCmm+l<#t?H_3f^c#UX*D_Y;P6#{9QNiTY_(1y(PiOg1mR-W zrO_^3zmb{LNe0G*>-A4<6j$;BE)%VeTw=;gI~!!jY?-xPiC{Tc0x!llcKd0Sda)nU zd^)@w_v4q2nik+&jr7)~R|qhhd?5Z#+(ItYt^Vt2fJ4NX;FDx~vYilpj!*BGc>A3u zRTp)vTAOAM<7<+suEvFH>6*FCoatv#Tw}9H)-P*6^rBQ26wnB=lSNFi^6C2p=%XjN zX{A9L7mGJ}tSXljG_MmzoA;!Gm%}%am4|joURGftJ!niJ)?C?g0$yoLW*uqWdNst4 z5m_!Rr=D?EQyFz#g8B8o6tjrv?!WGPTUH`iEyW&*pPUfW;PG|Y^+i){0_*fJv}(Xm zw#5Eq0YSoL6^TFVV4@JBZAYD}Aa^Bzmf z0SB@;N#oM;W~1;HU1>7;L(#6oZLqk9yNvQPDv!MT`*6oxJiSUr+EWl$ACJ>ymJi^& zBvrgew?Z);dJ1=dPsHxD&zUB$nlRqUQzP?sgwpV~J!lSWicm%$B1Adn^T&rnMo&PJ zul$}A_B3Bq<-jxqieW%SiiQSsHoNtHG9OrSRSYIfzU z{!8$%%=wrjiBFOhN{Zz6A*7t_nQ_eUE!{=9@hy7)(^J59?Dr zbaV8V>1Vl+_S2Sb`T8x+`oIYnKzVXeztFlk6uQf&yw@nSkSNc34O8irnyB!sIrijq z>cag&y8yWXn0oohQY!Hfwzbsug&y9Pz$sQ*rnznr9sJS(u2mRR%_mA7{guEV^}Zj#H{ zjSZ-La5IYFkel#&NbNkTH`=5)XXV&`vP@3NRxa1?>u|I$oe|wzy-`v)`v(Ct0&id8 zCYdJo2|m=AxH^p4%XMsZhjq94n7oVgdSf%C{k=(7iUUskFqx^4dgFyYChS{*Pc<~l zvWyCA3a?w4Ql}4PgVV-Iw#<>sRlUd7TO6JuPdRKk#`kZA_)HZSo~qmiq8VB*5V0Gk zn7=PqgzX9ff9hZFwDe#mVQXy!v=6t1fKp ziw22gO$V_`22%-rODILvK0Z*REx6XoM^~SvRN40h3XD)brqB(Z>X;+I!*irLO^7wU zMe@aZz2&>mZev>2ctXl*R<}id)=Idi^!W0EbI!Z8{aigwnaiwe@z49M z95&W_!K4R)tRA=HB2>AGvUv4ngy}99-4Q0v8ZbWG>r!G|(I;qidfwlwz3|cN7{QFb z>$+w%L;Ew|4OmSNZZ-yIC1VV>CAkaZh6TCXAa;7zxu$?Ov zQ#P+7)v``)F8ynBJe2Or&mHDw)UM{Ok!;r+(6>$;+G!8K4Ih0 zK-3jw`qHB}q3flFna*ZbmFo{vL(+Q`Pt%rPlufNUt1|hRjykms6`^G^8OB;lI;b4% z*ODp?6zaVW6^B%kCW_Xf58e}n_v~RY$HqiV zJ?A-Y)}c@=Gam_&Uf@Q^&GtZ7n<^!UJZ z2x1S^F3(-I^no4^C2kLc!BGJ3(uKfBqTL5Dk`=rB*_a;+^(jtH$#k0}5c2}Lg5G=S zkGyeiJ3i?tF*>|G#xodzgM?b4z6ew&vAmcvrbc0CU&5ttcO&SkiIfrQ!WLaeCrsBM zp6zfYtF>Jw^yOKBlt^7_MV9TzGG0hMetMhYh;_c*j7;C-OH3a^Ccm_3n3@B)K552O-o9vU=9zNz%;@*i82oJ;BPxVKSm70&2MjPzmj~1e9*`_qNl-kU_ z(bjY);H27A_Rrz0XfJL-ODRIbf01ziregRV%l(m>`I&K^>l^<1DdGN2NAI8ah5ahw z{#_-J>$^%K*SD<7T@L+QqT}0#KQiw>wuAl91Ms`)q(9qo*a374O!I!vrE>r?(9F!g z-8A%f$@Kq=Y#KAbI1k7G0c7~!JiODOV+JU;|D}h2-S)Ee}2{9Wwri)f78E` z)%q_R`PWXP-}LcL8;=!8ynGkd;sCNWzzoH|l&t#OHnAVX5WnT&{!}mht^oD7na(>g z$)7SzKbf)vy*hVe55LH3-Am!!GX>Njf5id71@!*>_f?qzMtyeRF1f$zH?@lIPqbfM z>o@(uUu8PEevnrEl_^khWBpZI64wv1qW>r*_O~5EzIX`g|FlEso$5}+Y9;DzgQq{gi+2#}q5%p<_30Ni2uIKaGjA+$J`?j9 zEKu^i1-(DW??>=c!#xoUEmU&#Iq0yxjY*YA8zoRl-4Wr-TQ01 z9)FTTt9U*vdj;jSAGV%lvW<+`>dPT6&p?X6<4dvaf^rJSPloR!mo0b@)?E( zP$yjM-E`n8o9#E1k@@+*+Ag)iXij6gphCRbB89^N7best#`xsJ(9Af(6o5g&LM#UM zsv^dg+$$V!xyR|%^CD$j-5}=OAkQzMm3xFNEl2jto+z%#E*lZRMs8Etwg5Q*x#*3Eo2LO7J#w#=`wG` z$-N~LT7z7$EGZ1p5hwc``msg;f__{xuZ4?pMr)Ot_4V`lerv&D1-Z)R*tzAY^vY5Z z&scR9gruebshzr8r^~OVW8G|gh#8O?sz##vbf~Bt8s;&g^`{_bnTOTh9hURgYBXaa4q&2=LNVpVhmwR<0;icV@*8Ex@o?KOkptq9z-pjCH7rTB(g&IyOE0MMArKc>>Nkaa%!Q|BoPxVC|t!fI0-u7g{fjp06 z-W91s#^8T90)C?5qGzHId)sT6_=1Y94a?y{lz{C6RR1XX&q6uPq{RZlL1I#ekJE$4 zIMUyieFQ~RwZl=sq!4@lKJi>6A@N)aSGC)Oq{j&BX=k`R23T(B^yN!^2Ss|Tp{EGb zgBIT2VArc|(}1D?+k7^i%mF9W=NJJY5&u*8El{YcmwPV~i2SObh@zcQYZHYq&Wv?% zgq))0pDeVS$)JxwR8@TGy)()9z?xU0=a**tJ$O-9#dkU;Koh0dXe&W->IPZ}K2tmQ-3P0rsnRYW%ZL zml8=HdZ}V_FL7k^HYhulAt}XlDi}6+H|V{bN=(g_o_vC&xW(ub+dJ@i8^R@y)THc2 z)(q)Lm4AdF!4|XHp8Zz+Y0`+DX#ic+mxMV?DS`@;`jDD&q3Y$Oinkwe&Bb27Y!1-3 zVr;WqYL(QD`iN&_0fV2>C$b_R2}{mLn(ub)Lc4RVm@Wn0axS!OzXe;0j;t>$@sx^y zS)nAA8fw@S(r4|%$!@TcafUrnX?F|>tavA2${AJAUvSi11t zN=h5TV&`$aK19?&%gC=5N#L-mptJtZF^})#ZCfS6W;&S zjv!Is2#dXHP1KBX1*=rNje^4y32}^$lv1pjLW6jftV|E)Axb!;)jMB(D`dz8rfSJe zg4X?b>*h{J_0?2LdV*G=unY_`v6Ft{H$xhs@-cExr=5qY8woQkx*ue;JztWK3}IDT zd9o9e;587bEHJx{InOcLGVX7F^#yHFE?|ws`M7jTx+~hMgug3`0*PXaXhYVjr7;7~ zEAY8Vt#t=#ukNanCFvqXKt z(rt2yt!_SGinuSjYIEL%*SH<|BFuIanZSO4MK%jHHYS2dBu2`4WBIB&Y~kjrh7SZb zbaZex$yL2T z=r+=7F>hjY>c*Oc_1Sfc3!)(f@{u;-uB~>Rrj9U#UYIsCov&9GTVsj$nW1A|$m9S~ zsc#SaGf{Q?ew@PB(ZgW6w0n=IB@Gqm$)DIcz0u~=VSCEuNFP-ef+;9x^=Uw2c0^S2 zaiy(g3(7+h^?_(dxyKuDOtV&d86NqDQ^&HUHOn2hl}6YXr%mi(g#8E8`g+=4P5nE) zR5C9WS09{!=s8lznGGtfx+GAXPWm7jfmz!;-Xv!QKCZ(twSS=v#}aAKER?cW$yFi^ zcGVK3HuwU~G66}o=mtwu$D7tY_L7#SkSAxRiuP}LkfCSiVk{BCt6 zzoVX}k$0rq*`rGKd7X6U^n`L`eA=;JU+SLKfHwo)O%UbIG8*jrV6ff)89F$23aKx- z();$@RCR5-^GSDcJ8h|S>d5mIJY*tRodn-*8&BWc@%FE$wsNVVI)z_)<)wBPI2eju z(ao^J@DCzqRnMk7gK-!Z<4$Llr>j2g;|?w~Mk3;knj;NBlng|b96PAr5$szv_YS*$Q-%8W;g12RpFr$iE6u-&8osv*u`>bvEl z;r?$r`F%DFAb$gt)4vTk-AxIwFafBR>$f|ubZw09;nyG3vi_xaz=S(M;Q#+;!vN^b z#q_)1vHm^J?)O)GyLtY>R1WJ8G6mmY($A)U)BM7APdb_FCrfrfckHe&>KCx?uebKE z7G($Kc{qT5x@XFDPblr@RaqE;fgYeS?w%>@J%;_CO#%5rAY1c`RuWD?F8e>vqF*`8 z%nArL|EjBl^#@wGUz!3N%=xPpAx`#tvp_%XFrdG1mvFmxsa!vZtp6hj``50HA8_gq z<1atr+22R4Ka692N3C~rh~NIfF^HL(*%{gZQ2Fi|A!2yfIts_f2WM+%W2kEm=QQ&{ zRW)Lk6U}2!d)Zla%9kxM>#1B)PB&?%+0a|w6&>)bqqNwmN>tVD4{KX%iS&?3w%eEYijjv>9Yvy$&39l>rlu9DQf>>8{f|x3k;pr*v^F(sua$ zN)ZlDeL-txl|7ApTx4Mf?UUnIvsF@ddQqfu2rL;=TeVl^Fd69Ub+;;v+#FYd71Lj2 zZ74}4^eEgoGV#9 ztd9=XwRd@Zp0MDjQ_+#AvYNtm=m_DOHIoVHa~Xy{dj|7bq!~b1KFBEoR`{TKf8%=lvan^-M+kv)ir7J5s%FV~&$wC|SSoS`v8gulFw>Gef zAAQkj=)>@_Yy&)8^~3Btcy@-PnU@O>l)I|zFJ*BWSzY-YbWd$_R7KV zIV$8Ndso^a@)n0{rp^xS+sVLshU;7;m7#%}=7JjQli(wR7*vX>3-C`=$QTvV<>d|F zZ#rM>!BO_Jqt9?+&@?`qg;W%buJbRc%dyjLHR@kbyxxTl{$M(1?v*I4mj_ivlHb!Q zY<`&fj0+KmI^)1OXUpIjH)1GE#C-d;$w%89QO#tBw=5x#<8Vz=>~I-;^Ik@iNa1gV zp*1BLJKis1SQUc$JVlbet&x%U>HJ?Ag%Z;j_ z^)0bP`NKl=tU)zno==z)u#?SC3Nl4In1T)6CS(QI3(`B#(=C`$r{kn9rbz`=GPpBP z>SL(g7BLl7zg9P)u6dD)Bt4x@Rz z1;2x>K-%=w6#bIl69l35Xa>1|wE1P(10NmGbQv29vWn3MSTD(}%)LX9Q1XZ(gtL&a zwlj?1Mms!eGoi;%pEBF=jx5gNi{x`67lN>Rm+ezLq&ul~Bg^pyxipmyS*Y7iGZpTG zkT_}dQSNj!mw&=j>v!iYxz5k5LlgA-6>@P6iUj(-2YPdzv)sYhu4WjPTC%q+dUfn2 zgu#dh)Z2QKs-CtyeI3-CKrciI;S$+6!YX)KVA`Re)l3{Rws=KzWd(U2OK!Z2ZZI%o z%rk7-B=yw{i!mCBv0bz&X=-ys^7x3tah|N_pcWjd=0U{C#&soA1G4UGu*0nBs@kVJ z;Y6k4XQmTQQ2umh&qrX9;;f!}6-$BYz^zjXYX}x1ailj>Jf9k)w;_!HbRlT2J)dRD zR<*tmFh+%s7#QL%K~1zAscn4l>U=AnqCjCq_tt|?z zDJtIaGa?ivHIq}l*=*=xY9qXAcW|fT9Q+8vK$D9Rl&sIQqkGEGMD$YoZaR9uaQv9CSIy*b?$>@qFxW z7IfU<*(85h^^|We%ATMOx-kyA5z|*(avvkt@)~4^W}qemW@Umgn8UeuTG1w|o91Z#m^x3xKj`=uYR{31B zdQY@5Ys}R#eiLuf@D!ijNd$FLVEx96oA>OU!*VZr7hmys2;@cvRARKJ9>mvg`B5W1 z618bD_)3}?SQA^{{Yn*q55oS^%3R%!WEoY`%JZFu`cw0gdEQF_{q61RUcY``{s1jY zm*uppE-xz_a;3OO)UfD+9dyWE6@IgfA6j6PU^I23A`d=TW}Xl6*|!n0Ga;~q>c;FfShCO+WQ)+N0#S zBK;s!ea-Z;e33+FMlh7ZV5lR2f&-A4WRk|o7PE5Ji>qE=9~zquK-jSPU{$74*$@cH zqoi&UF*NPo&G@{{!ov7#s%6ep4KW;AAX#>nR!_{$VNU#O`BvqD4PK{MD#>~M93R#B z&`mILnnMTl6yb+dLvm>SSJBAt2p)Q$GJbAuByn6DXNL*^#q1Tj5>_}Xt>UAj6q+5# zI_KmgZ|PdNkfB~7GW1__Ieb{aHZdO1CIkv$UN`qWJ04~1*X9z@O6RiOjwOj z{?^hTaqP{W(>#?%7!2ukKB>(dr5(?CPQv7DGVkDZ5mi>VS z`48xD56gawjef$iKvCq|XwyF=R{vFH_76GnI|%z7)czql4*cYsny&m$(@j6<_;Y_@DkU10~M8sp@~} z-`(iY-{_Td{h&boFSn5uz}bvIHSW)p04uQ{0ddExnKTMf`$ImZI(f8}gKds6HJQ02g zsoCx+<#F9JWdStnevv)66NdZm4l@Bci#s~Ud)LbK?FI1tY4?8w@&M1~AMX=l08%r^ z+F0r<7}^o56Enz)h!Hb9H*~W5=~V!v{Ql$jcNPi`U>NToqV-)>@nV35qTxyz=BZCl z7fY+?17FfWN@?FTP_!{#3a%k$b9g}7O;T&2anEY>@X>U!^sunpIq_?jq-8fEE)6Lj z1pXE4&+WQlobdI>)lCb8YM!bn4>i4=*dlK$w0K;lg(JuanJnu^=gEA8BtD*;X3D^l zlB;@XHM*ZBK-A-fqJ}nQjL?KRnNSGukSKjs39k3j#c207CxghJXdm3MFmRY7iTAg@ zEr>!8H#jHJjXppJgA#@Y zF@$-ti~&-wg_7ns%mU-$k8;3Cs0RY|nlM8#NY1CGDg#sxbn?ZHuo8oEj1@m!#1lC) zMT!H<{DLT@A^a>F9`>?hV%jM7va%JMtk`qI*`ygLI%R~_boWtnakt4M;_cGl@DId0 z&y&_BSdIKICO!>^D9H6*LiMov(Z4r&`5rdVdA-D|s|<=&==00leaON>8dJypHKop%r5=!GmsG%iLjHD;SyLjo<{)(2FH@(^Z6+*J`!v`<3GDlhQTI@uv zvl=v&(}N-K&~fOA4pdVO5`yOWLGJ}yhkwwQ(I@oZmou}O48@L%*Fv} zB?UQZQb{2U?M0mQsK%I5RYgseMIO63VYL-5u@`9AndO4|Ls1W7=?90~wgU%2UnXfa zc9WQ2Lc^spX4hmtpzRm5R2Uf(QD#id;I+uw)&5doQs=Lk@#uIg&_&G$l7+Bd!5TXD zwf9qu?2o0{bX>AMA>6YwO5sWzxg%~7F9bd1L{thhpRc~B%5Hi;zozQ4IyHbWyUjY% zmB<92lV@fyv*#lDl)^!ev#i&_)5_2ku7>)waB5aXkL=C8aROmSY1k^@y7NnkU~jmk~nrN&M;v;iV*7rCmnnTp zny}hW+`DvMD{blGUOFla2f|8h`tQ45xP4XHpasEpJAu)#*(Ao{{0K0Y!S6W?f^z*F{3IT;D$*#j74YHHEG6ww`1#$c)+@vvc5)mF7PyRFr`@j2w%vR%SA zT%I#<*})*-Yc($sw<{^3d)vOUVjOg0NI{&<(+Iuv$)w+uTrlecw?u}Up3^lN(db&{ zVG)M_@qLQnu}D@a#^}>0a=!nDn>lM2icEI(y551oa!+Kq_RMGa{j%c4uEicb5d+Lvy@7XQn%2qnK(8YUPLh$~0I7v6>ddk>8t zv*q{}$hfW}>Gl{%s8@|AG-t#(1#dO-N0)m3CpR+e)+8dofNMX*aDM~WzP%iOf@^>1 z$^JHT1s@+V-~{lNhhyTpUyu3b%s+{D|F`Mi#=G|ext~_OYhYyu-u(9>6t?^Ijh{_9 z80i@SGKG7lT=#?4pH1(IcR(%Uo+;Zs1!1nAO#yM|yT7_;%5^`G`^gljYyqSVzbLD) z-4h@Fc~v%`1(flZ6`A`%>t9#Bn~3KE2=Z7tfZ`RfqxZZ9@Wx+av2OwXU+n=ks&4^4 z+b^nZT>o>g?gD)FUrk>FXzqWkdKcg`0x5%g4s-p_y}F}#($gPXW214&Waf?4ZztXLo(=_*wf6DK8QwJ6h785xk{Uo zcr+HvBdMC`*(e;1h8v8{F%ZI|vd*>MdF0L$7#9@A^fk&lq?0LBPGZ`rhG6*svEqi0 zbc7rHNUFS1B`hTw+AJx9HDk5?BwiFlx23~c1O>j!sq~VS#80a6(L&gIXc19xi%Fa7 zh4JwgJYg}&Za)lJ0_CdZei*9w=z#+UB}k|Ig*(e7<7N2{6~boxEh!sPthzC)h`3n< zh1Y=?Ef!jy3Jj7QUcl-^VCNxjbTtt|^FBJU;Lc00@ylvZSdf)-LY?m6COSEbrI`I! zH8s?e7Y!y-U-d%LY+o)VPZL&I9R!#|%ga3;nn}YEKIJl@YesC1!q4hmr>)Ee}7zz2gu9L$ziR8Rt$AI66U0cy27zrB5S z>yeJrVcCpDxs4)nlvkS9hMnE{R=!(mD}xXZ&5QG_Epl{i4$=9bfNix3gT!!?Na~>q zGdZN)e(skdSL}7@(#mB=v)tOju^9!SZ_NCuMOX9G7A%g+x)U;Jhwa3yd1?w0J}z2T znof-G_Sc#Z?j%8X>61dh1*R##V$hAItb5A2^VOAte{w{(s@S24 zhv!N3rx>Z{K|@yk53)*Y&HacHHI%Q+C!XfQ)y`BU8@+Q{(RZN@v{{PcXYFsOPJj}S ziLT;rh-G)xU|P36fF^DAiPcns4_U6E^*=ySn;Stu%mc@{`ci2+&*9i|gUj+LS(m;( zH8qq9Mth1OCq_C&yU)`$BTHBEODQaIpcCa86y%uMbms6;bI)RYQXcN3YJV7inoJbe zl?RO|>xW)P*kds%eCc#zr9;De=|#!Q+O&FH?MLop$18E5YBVcMN|X@0BP{fR`H?_i zrU5aEoX{>ab)6>E*6N#P?{@~9;0XppAiT^xu6%3PvLd7$d#rCxYjQVf5y#vtVToQZ zG9lA)b|H^~wD+ZeC(KKD?5vV4`j1EPgRn*xgS&KjGOeYgvp##3wIJ*3AllGJQ8l?z zj{2z)bx}#Qe%8Qoh&}4PT+EqEbsqbOmFAmpxi_2wuzm)LqSL#1Pl<|YksiI1AR5XF zf!dS|#*TNTcK+fUu z_(-SZ2XINbd1zL-LQt3J_P!6CY6NU@L_%ya3}mx@q<#44>eIVsl0*!%NRQebh=$rK zp*9nz_GBJOZzOfUXzYW2S-E!kBGp)1dTb9L^FymS(G)S(%<@}eAJ z6IitKyy;vysp}nm%3&rDH(gZkOzL!48f*ATeYgO=VY+c+&OkX)Be^*nl|{*3f+nNS zL-PIft{SlQSishc0$cA7wJ8mfkHaJZb~qFrFB#f^lGbmn)})6y6VcjZrYuzL(FFEhuQVnw_v>2)D6F}HhY+C;f{>R(M^kKYfbvWHV?9AZ?pJ$iW# zVWVpghX{g*w&k@T#T0rBUf1tjQya@3xOks##(jrg8!MFw zNhh@=M!H|KPIpH$ulIqyFEd2!40$D0yipY`aJ@0sy7oN?Ac#GiUJDQ`;zvsmSHUe! za0$#;4Ql1H{!x5dy7(#*@xZ~w0S+#+C6Vns(WBE{Iwf-rB^Y>Aq|aA0{T5WpmrmXG zIy5%G_iMu@uvg&es>h2bb-7yej)ZiI$r?B=g~tarJ5BO)r=ZevFT5Ip>&~?~3Z#e4 zY{-fkpQFuMma)|(D{rlS8uxzZvu}&?d+MY%iUQepvxs9@`I=VKEs5KU zTjI(DN{o#aIsGWKv$*7m#kKBM-2)9Ry99$oy{(1Qatx*;aaagpk&mYr`&F8s62qt| z-`^aX`;Bm}J<3J3!sDCRrTIkq(6T%npPRp>VvjLNadFSW2A5cnL{H|^7mxu?>6g{7 zZ%eozRtm@te}+G}UZjyb{@9ZaU_VRCD2z;M0~8-OP$wG5%on-kAOs5oyTAZK*_ZK- z0mSOfA}j9*CoCQO(_rJFgUE|pkXRC^kY6B+AHul5K^DJI*yZ{bW&eIt<6n`*J;hS4 zpQJ7SZf=PA{wU2)mh3>G;#cij_uHm^HUvoK7=K0H^T!4M>lpBdrllX-nSMJ9`h#%l z_bezt;`UFYzW&5nKy3vjVDALuV}+MXYb!mnfE=-DQk#Er^{X%~@|sAB8A@WgBB@F1 z)COVOcFjT~2ZLT~U-HP@xBFC$p4D~u5^^Xlsnpah#0qbz(J-afeHp9$WEPQ03FZU$ z8!$at@IJa==cl2FCO`npkMDwE$S@5|$)DpxW^TpRQ-=gDig_X+iCueCgh-4yFnA(2 zxWW6<-ne4jm>Mc{|9x!`pAW@|g^B~&ItH*}#5hJTeHtrY6faPe ziua08+D@52@UXXbERy5i5jjM9K1hol8% z&}q8WQGWE?4>KQ2a0m zv=X8Q?wMAu&oVOI||F=a(YI?`6J-oPk6 zvt_qVC?C+}0xr*38D-TBmN^NTgXW=}!G%IkjcZL&Pq5Yl2KriMm4~f(7j;_vGWm%+ z)8~YIv!i0qPio~b3(oSy&u+k!Jad`S(MmJ+P6|2A!v=K24@_|NH3a)`BqLeYSG%V- zb7~x;YS83|qq8xoOp9$eXZQ+JP6LRAX0g@+5?cv6Pc~i@piJsl+Nz6Y!%=cY_)l(ekp%grB+bcY=sa$LSP_zY8zN7v2>JD+>ur3joF~0Yc92X-vBb)GIna+^fvZfuP}O=AYg?VD z9u9@=<)k(7{0X@QHp%NR{HoRoWdpi2z)3VzM#(gTEfWpZ^%xU!EH@)Ul=pa_47#!&~u@ z{JzkrTF($Bx6Z5%GoM!b#Ph}yJ0haokV~v>NjgF~=DxX6;kj<69@OQ_oMcx@I<|S! z>by0&T|b8+^05N4Msj!Uq?4eN<@21fBinRFy~VX0;X++#dzo{a#zd zs#@dK4CqDy+hn7RB5VO$HVNCTA-1G;xcSh~amgy9G;7vGDG92`R%MBh4tx%?%}d=! zBRsYK0@RUYmhW+@19GZTXyxfkglI$iaPBB<#wR209O#tpLo`WA%7{$O^7^5K zEX&|RJ?!$~()W#@kbHi)-H>o|oT|84>=OEj_OrHgRz{bBYs@;#%qmZv z>O3ZX#Ln#anGM5?)}Rpdf`jyu1sR%ru6E>;-2B*s*%wHo=Hrj@Ev`~^4UD#t4V_tP zUc7~nLv6_rY^K@NPLN_9YQx|5ctq#{HL@X4lSkjrN2W839Na|adlevCyM+1KDf+9Y z9IlS+F9NY2MA-i(5c~G#|0%@_@M`{6N6xnlnmo|N{GSvr*S-4nH)sAqiuX=|;Xf7G ze^d_sA^r8&`Qsmy41T|p`-jl(dnY#|Add16b7B1nnh`T%7y)}1m>MLJIxD5THzxUF z!49MB(qrr-Z}P~owe*|daP$%_HjDR|QV#kOxL6Fz%`@sjYzHn+c=q1PqzOacY%)3o zkid(7F4e6i;B3WoyBzg8+(c+$p}4W*b2{!bY>jX8=15`)e6$}VJk5wetxHcZfNj|s z;}U&#wBfts>_}A9@-eNZx3hWnY`_Zi#UM1&!HS6!{2qbOs#7(=IcisFytXA&F|?=M z*@33z)Ym5k?o*W9M{a2TPU;#?3j&q?mt}Ng2jZWvgri0)J|zpcdg$kZ--4mUxF(wh zC)o<-!N{Z7wLJFWXMGWo;#?#JFTVN2YL@crW&fUeOY#-#jT6u66T*nG0MyCQc7pA! zg8c42!vRiH?NjGiquts0GWWuASi@Brd)E(L`PYq@1(+z<%LL@5mGPg~RNc2_zlW3)l)wgLKPZWn%R=;+SVo$1lmBV;@aN)Dy zoRb%wD4pGod)^jqouG*mIGwGcx*~*TC?owuK5v>ELTE&v9L@(Go=KtB4>D^n8iW!# zCM#@}+WFO+cY=~FpW(MnXniVcKaL=rV61m6-3Yr!No%k-D0Us9^1XK!tL&~shhsPC zJZ>`d;|3kj=&)Yr>Fk+Hqj-A;Y2Sw__!3szefg_PVWBpGAwp>@Oy;?bRPbt$^DE3! zKs)yf{5Hx%pUN_iliN4;H81&*r&IzHL=h4;({tZ&hN!Jg$tG5Cj~V;mjpe0%NYK6x z95?fQ08!$R&Z&XhxqOKKP{TLYZx(y3SrNkAp2zc?yTOVAY1Ot4Cs3wMPvhKnuF5^V zZ>PYFU;WE58R8K*n#;MoNboAs0e-$P6y27rw(LeEsR`Zf1$gXjT*2V5nl5$`!@)S0 zt+0^08)jCUHM;YwaS`8G)>4LC7CF?4`1767d`sg_*VJe0ett}D?ZBUSI=vbv@{K*t zVaPptf?8qETqvk*h#eLea@9Wn*^U--DG*lz|AXAxlo_k3J$nl53$y2tbnFez2a)Bt zd-Q=BoMx6~Wr_JOrqq)b%yr;;ADRaq_y#$Vc+91>S^O3b8Dhy$CMg(;{WIGoY2 zQD6WaE_X_Xwo)E|uo^at@la3WDcYC!TOg8b@QeJZA1?za!-Q~Nn;nkvD4a8n4Z~=^ zqOqRCNYS@%Pops3g5P$NgE03mwqM^#id%`Wi8zuMSQl*rJ$MTrsxX06eZvNjsrJ-AzN8h3YhcXtc!?hpv>9^9Qkut0Ek3GNV_ z06}k)m9_V>bIv~ZyU+c8OuBn?RSlu%m~V};^4`gORL-V+CQBF5Sxgl=RMA4%n5mVg z+sBW%0$-2b6l>LlZo|0r^)u;La<(6~v@hB^TWAR2eQFzIKrE82b?goyOK!8$qE@n1 zv1gUYz4Z>ej+-&9TeokP{Lu~hB`5<6Q8kGpCS*_JBUS@hYIbgNGzkZFeNvTiQ3h*B{4jNyvytctVB6$YV%1IMv7? z=^{Q*l!)d-$HX76&J_@m)0BVE*nd?MuFxZxi`oxzhDY-%C>eYLZ3a{UTzt@1eX%H) z8lbjma6akx3ZzWQHrM({=Gy z1w{vJDp4yNyLk$e&^XcZ>QZ=NUz{o$;I&ZIdA?Xht_%KU+2)y4)0}C!tMGhlRFR?=yVGxSBrSQyqohqW?wc-_l zq9lN#FmhDIn&?XeUvmWG#F!>>#Dwo@pa2&wAGm07z(vN)Q5U;0*yauvy_G5MeJcjM z;|FrdvA=^iM!)V>td%Hhe5c50UAN89{`DNe=Iw%6A;&Idf>DyHaz`U?W&I%dT+!G< z2;*bc5hMyziSj&g?FJF>w!{MN3I&4FM&Dqp7^wpbj>)l_vHEyzZs8URW<0245U#^W zAgsO%QV9uQMGAKyjaI4K+|GG~#JNzO8+n)K_r9$I-Ys*vblUqHmK@|X< zw`@*rV{#O4d>MS<(f4|{K3M@k@bNDv>;~-%8W_Qmglot2tscOlL~jSLJnx3Dnh!D# z^wAFcwk(-Oi+(t>^UB2Txy9h4y7bG_TxMnPZG{~-OFwicT#II6CmrwDuFmw{$qkXn z=YCJJcpG1&AbosaG|;NVnWg=49n2WzRse)`%~24cQ4tF>b^gV2^yQNW)z7vWe6>^W3Z%G-4T$mNyIf#_oGA3nZZ|YPETPI ztuL$;(t{3kH$nsGquD{XpjZ?Df!Ch}uV1K}PF3dyN1Xc55LM)fl;DP#( zF5(r@Tu~_+ugl9}gShm1_LRx?H;QX(U){AxXuSn}>eTM(s znEp>l>yHj>KaHlGFN67ykk%i4_Wmy-EhYw_U*Nwn-|y#7tia&N{}gGZ>L+BdA$P4k zQVk5FGv)3Ba+{_znk3VQSuD9-xTXhp0(!ot!9dZk>r~}*(2#*Nb$1LmFyr$})RgO5 zexI&lc+2n*PFjl=0WJ9^^U5_K3)lUAIuOh9)usX2v*Abg>v&jk5^N@OkK^$7#4^EX zA>c4lnLCH=($F`2wE6%&S}*RtD1*GZi}}q*sBaZr%SRAmGJRwCSHLPyT+MIT3_18xpkUmK4RtAXY?n2ghN*zkwx`#X>ToH> zuU6=xuZxRYKrRL@O2))ih2+!aZDiEDb`N-fd&YdudM*|(aenL_fB0JcQ0eDqp=tEm z$ue|RM!QJtTMxMKx7AsXj5JM(vN*d|IiAfq$tAN!U#FDjqc~U=YM!PHGt=_>6peL~ z=Y5oKWKer-Q>Lu6saHhJFN%6mI~N;&l~p$)d{bA|{T7IHZ(hw8?O1kcbxH zm9UDBuzN)&9p^do`rS4%TCCAcf_SiXvbm+wBTTwP@TSJeX0Yb1MrN?cx&cA4AYW|4 zBxl4liawZ}7b3-598Ml?`Ae>>+z7bW5kBcH3M??#R_X2*7J)YjETWY0-#BEi^ot{+ zEns&9&}5h<69}fk?Ga>2J*w)|THD)uQ%xgF$F&SnnZRMrhFAqZqc-$olZS%}^Gc*7 zuJ@COk@g;-^g{mNF%sJ&GZObk2tVe`6tUSp`}S!xYE}lu#HZ;%n&?D|C|Dsyz($%V znx9w zvSee&g@VEE8W?7`@|a9PKKYnQPRTLg3^{=_9K`12v3{bz$SB?JMKN}rZqr>@42EPg zG;S64c1k2hm?JligH2CvOtPHEsHekwcCEK94y0b^q9I|!or&{iD^c51QHcF<7}R>| zKwV-S_WrzHRqp{Q#`y5r-NK)tOPi0QXB@vLSKA~`77tLlUaRprFOp%Vejj6C$Yj znWTw5^kAOkz=fe-<>KJjM2W^I**1d+qsl!op|KD_S}a7^Ju+`R7jRu=fa@v)TvrC* zx&~WrpH+OaVnd^?#bQLcW;_MeP%Avqnbo{t{8%SmyGUjk>bxx!N~r<8UiS*S4EK=< zkdWVUBV@?_wa9#+zcnF+AgtVXb-R7Cp|w3E6Je*JmP@t+2j*VLOI78dzc1Cd(fhJK zP1Q^PTNyi>JaR}Hfi+8$Y}1`5|5>d-szjKyg&VyB)CPNccdk_sAu;wrti82($oAqi z1wo?RH{W|QXlMJ6YJ1AxZ8G+Y^vgXb+{Y!`B=+r)y^Fd17IMqN*zRpqay&ua<{bDy z+4;k_z?VmWHe?cYv)p!;O~=o?nZm@xe1wivEKv+Vfk%{i?Mj;MmU1M&LPb+1tCmsH zDLG`TB*Sfjg2(bW{@Rp*5gyH3&!?kvaHyIGV=>ZCu}m6E11dXxRVkMCq$FWvWXr+3 zgITZ5Lwhkw3{ImWVNMUvrpczRVU+InQM%<4Jv7tN)IQWwmCd&O_$mjFfGU;HJ1=w> zw!J|;;i!y~I=0LnBcqhfW693;+HOwEN~hW|{VoJWeVOannxsfHN3t?NR<}?S%pZ6A z)TM0-Bz?pR^;E;G=G#s*BP_qXBxw#@$>^z!ZFPtQrlB;8Y;8>k(F-%( z{T|00BsBSy>L6O7QI&f(9PBcG41|aG5TfkxNVyC-78YDQbQO>)bb2BCx`It-3_g?} z_Y5~HiE|F4q1z(G$-UkZ61OBtO(t17@zaILoA0#k^mG3ja8KHA&!l z{}jNSWIl-&&57ngkVUu&-!%R4xr%U=|G_#DO&Wb8(pyn8b7dfPhetPk9BVv|SXLwc ztEBrF3<(nqsX@e(KY|Ob(avs>vALwiCJbOLOZBPx_PH2Z#n#G1rgT795#gtZ) zAP4~%olYxe4tBq9GmfS)F>hbKHIepR%&H@Pt%6sccek}D#*~x{jpW&AwO5IWd?%lZq1th9N`s5JiNd}ouhM#| z#VSUmuIO8NQ|*u*R5Bb}p0MOo2+RGRaeS)&BuU^!~fqU67 zuIUj0Ai+Vqw(1?USwybsQBn}nNoN)CW8f)#1dh=J*fZM7gbxc-r^@Qz+s`o&EH(l~ zrI_P_6$q^^J*t9bQYQrUBVVz)Y>;MVbPgpK0-b*EI#Cap~ zXwDNCNRe4e&j2#{*Y*0mcv5qc@-s#q-?FK|84b>WG3Jb$l6~^XY z&KS{sOwpKy2$`-tTH0{O37J^eXl~0dIybbCg615|?8oyAAL^~RSZUPGs-=w~O%s;g zIP~iw^?$X<#IXdfnGwM-?@=s8C18c!OL3NKB|hzUd$vJ3kM|VmL6o~~;)tVI>&b;} zg**NME;$@o_5DX=6$Z)R&l-#7W5?Ag$fd&2v_!))tEy6K0~{e}0k4Y0l=FK%eewQRVayp#8cK}_H>re~ySK8>NmrLMcxv^a z7eHHl>b5#?5aQcBdh6lQGwO`}cJZ6cByyn2*G5yWHl1MOkFR_TRELDEoQoEeeecn( zcJ3h9l^jH_Rh`ogsai#lomfUehvvJmRSb4^gt!Wrl0$uJ3T(#Bg?!Hx)!$L9X(4+@ zU)Br>3v*D?`e5wVl~~_HoUV4kA>$VXNzGI?Lh%n{;-cQ;NWnRGuT?K?-Hhlg{#CCUVnU%WTXG`@?SN%=?u0Pv~yFDWPX=rQl zbV#r8`xx_mxjPFitXZQl0^84f@aFwKd9$B5t`Oma(A>;EdFz!$N!#z;`a`m~K;L51 z4xN0qMIE&O?X0&<#2%Z2x60+bp;VQ(e?LXYA+lBqTPgmzay(7Ub>(*H#7#QWYXQYI zK+D*2waL8o{2q=%ho$veW+cQspr}rK{iH*0`m6kwoICsX2nbtF?ee zdsb&h49j10Depl7eG03~sE!Qnp-YJKY;JsmC}=x-w^IW3!r{Y0ZCs}?XrHu^Vb7&> zh&{^g(0mJX`P86rl+zRYNX1OV#J5gWL~!h$IY3q`t_e)QOgdO?yCxQRAMblUshG=@ zOpIa~JHdeJ6N1X{)5Af_+Nn41oF)&=h&dtEDe_x*&bctnc$v$oDtvOYj4EiS;mj$+ z?fvpC;Hl{3lSGmPgiR&hEn*{dCnY;&7J9CQ1T@70?w1J3)&Pq>&iN?-_i9lc4^zI}!Z*$SpM&HeMP~0cNHK_-f1V`^;4HwX> zv)j0YwbUKh^H1fguDy!o20n%^iUPIo< z%GB5y7NG26FGbu~8DGNNl}w%NT^x-~orrjN{>wmBfT+8(xUw@aPt;E; zC6<@IUX+O!V=HhXcFw?dB7hPj!^;;h;9Kb>?)4?~^>-A@04y#4LjOOdoyx4#T(QSx zhxhC36tcI5x}}b|^VV%PM53E(gj6$F2-@JX3+=VUH}846KNoII0O)yzK?>q3k@$U} zBoL*_NjiBqb*1cUZ{Ie)64fkse9ArV^HIuVhF_DMcV=)FII7JJ-0cR$gG-{ z12EH6zf}9G{>_1+DAwmCS0N~a=(0^ES`8UuHAWINn~pMgU)#3Wl{Q41IgWkSJF148 z(3J`LT2L&!Xv(hFM%*axVXVc_4WZ!*!y%O!B4GvSHDqkttb#S!^i{<=d&k!U+-1*S zFInq(b)nZH;C{MDYY1O*<=fswm*wCugBI4H6lJLj4pLV27aIH%r#xEz0iB0jrybO) z*RuInDRZY&jxrV-__GR!WqJ^)5Ctf2I~O>Lfql+;EC6IhI@Ta$i$f~g7rQKs>avTE z({;!xZ^7DQe7aN_j0JBn3Uwtq*ad&ATG}#X;7Jt*thkQlesJo6wyQer$<^2B?!!Z7 zdoyny`%x$H-5ju7_ChXK>sPYo06c}d56z5A*AY`0N~l{Hcpou%HBmy9 zcwWIINm>tfmuYGS6v|-onaKL9&YNV=&`&2G8zpF-7g09GL>}>_N#O3V`lKZZYx{I{ z-Pw3SQ=2357(|EkR!ksEinymlli!P0*MUdo(dtCUb(Iy(w#dP1!55ECEdj)-0)fdEgH}ZcBlx|{XC)~2)wiMu5wQ}o^~4~f zEi%q?Due!Vqg_rgoEGEChWgYLiA@i38 zlYoOj`l=D3%3w4LZdWjos_}&$$_a0!1f=k30n{nB9x1E)aSm;U&Hs|F07VBNkf?%l zHTL=DwS#mJ1uhy#RN1TolMEYq=8kr%i7}Q$sBovF_I@PmX7+q%wRRO#f>g7}+l|sxQnS#(E?x0< zFXH?;$vzs}f~~&r?T`+4YR>|iL~~<0D<{6O8t$Qny)B_HAz7&4R*bqIFicuvjF&;! zhTIF4p=A<2O-wt~@bwAE*QCo?CO1+~yGp^Kr$BTQy<2H1Mvetwvb%gm&X??ywLlU^ ze(Ew&@gw;f*5rhji;Qs^4n{lqfZte~w$n>A-D_65`5An}ni`z@6RhASfodPKPXOB& zhPZc(|`jK21ekvO;T!E-H}$wwVK-#9Q+d^PE*w0fZ|-qh%SQ8L^>C~%61 zAX$f5WdSM0uf*37$Sf3-ci%clJrQghF;(|Ea6fE${MO1rxnHo0Sbje$rJ+7-60%(L z0na)}2G>6%5-#XHJ{!;2z-XUkt2LM0n*nI^Ns?whIqlX_4I4h#>W{3B-MTgjwG^{M zB1aS@vI1sWq2CTz8N`dkv)Dw|;2UWzZVx6&jiVcJdxBCb43nCf^!78s5-91nzjVYj z!c7${_ws0~7QqZDeFBzgz*6j_-5N7)d*DWV^aHFX6FtcqoE#EWG4`J{|pX zUmB&rc8XVjuxqA07qH_H^~JG#-qk}MyoDhQ75G~fP+~KZP9o8k;o96G6*eHH_iWWD z+~2N`iqJDWICxZ2kEWk0U?tQ?FiVhSu6!eHf4?|XST$*d_HDTqV^^nln6|wpgR=Uo zu<(g7sMTi=?f6meti7tw6r<`~w23L3JIafPPM_W^?=F5IUDm>PkEoQ(Fkgcg-MEWh zqj@H;eOOv8Bb)<17DB}wR*uT$o~9%`q~B5Go`1K!`L?sNap+miXB%_VwsrYkA0I1I z6Wc~+p0L%tnl0?H$E?#DTn$pV#N)cq)9I@Z*Q%}C&5avR1iP6^KOm&YPqWka%X`5} zePFKqo2MUcMgfqkReoa0JSO%ETkVt;pBk-_bg|p{ygfN4TLSVu{J8W8uS;Y)Qp?)8 zGh?3Pzt&H`ZSGk_U;oI`(!+3gcxUD|US*c9y}|qLjlMmiP1+iF5FlJT0`Z{6$3|W~ zmD%*V=lssT`vQ@_L%e{dYdrqRZeZ(vMRMg-j>0+9oDSn_(%X}|qc@v!U#N12KXK*~ zF4x7Rqz{i+lG?H3h8-6U@%-3YQESI$XE7Ijw%A=+>3Q2`O<{?47D(ZlF)g-&f0NPU zl2*hMr*r##Lu6y+6tQh<*V*lLwKqxF0l;8l zYAUE`D3dY?NtoKWnmSt=8v^_I1=s9==laQ-$oMxgiM?=-*vAby|MzvlbxB73l{%|o*p@W2}rMU%gH)H{B6ffPqeD}f(3y^d+w6Qc6v@^FcB?4|e%Fd>?YCw^| z4N%t7$;r~r{O7*%vJ9{QjbCDbiJ*Z}f!oka&LK*GlY^nLDL@z?0uTd80Av8N0C|7{ zKnb7>PyuKF3<1Uf6M!ke3}6nh1lR!V0QLX}fFr;O;0$m9xB@(Ys^`nRUbIu-Cd2^r zW&KU>`@_2ZGF$w^4lDe!DgHgr@E_E|7q^iYHS%AHhci`^ymZjiG5RS&M@Fbag}Czb zB~{9Dp`lwMd7K%Ma|J~RA^{@M$daJL(lz;N6>9W}$+O9Y7|0NlcU@3c=;)#=R)Ssm zSOS~kb#jV@kq+BfRG66RLMpO|laPeyoezOMav8iS^6Q%n>fa)6iB!D%LORcq1G z&K;ZnK&Fjpent=KJ4NYRha9$^(5d=}L7pyCdd-Wg&3_=TD|ePfs>0n>)J&NtprE1G z&Oy^gDV~rWN8uKw-}KdIjyCqWa^(ExCZ!tSc_~(QFY9YJA7C{?MzqlfI3vdGOnB?JZ)rB_}xFvPFwFMDM>H+?AiaJ%;SDHA)|CWj!g1WuDQ zDU*?r?A<56)dG2c$Pn*0pSE3fS6!Wrl|9SLsK9I8BQcvu--Gie^{6;_I}om}(qxEZ zj%%k>2vn$l^>K&Gtj5Xyo~cb(r~Zb`E03!_@asSb;iw>$KQx@>r`I{3Cmp1MMOnV} z`tvtNV}PVphaT0y>SKZkM~&Y2u0_ar7fKG8M+cb@h+r_JxuhC9^o4`XrQ?gF;!dWy z=MsMbC2{=DUMjqti;Q?d!NJpGPOWATVoBZ76J1xPxZ54iH5}&R zLT3&N)uGi6D_JuLYxB@O2_!HgILILcx+M)jT$mnXN0$%z#qS|y1x(n)|1Wy+z8q4aX(GPMsAq-0uViSmtlSp zJ{^>k0&-96_PXRY-GAHv2Y^fG&!E6tK|$LJG?AlBVp>^*UImS_rDNA+UGyr{Tk zpakNnI|y7HvMnfN(brFEi7py*smhg)EZL2^fjO4$VBI@{=7W>v8si88U_SI6tj%z> z>rCLFMC$txUv#iSOe0Ox6ib5xpt_?!fU%XfoIcmS;@)JG#&Eyy;{k_qXgQxSnJz~9 z+}2esuW&6ga2i5~=Xu-xWwe+@9<-_@p`mE}O*rl6sBGB)Y=gBm2xojjGJuVXCx?`P zHIhlzvb%f##uSZ>2d4Uu&D~>=UL1Rxy%VuEX*VxBjBH-Q< zzekypLBav7B=WX6frvo&)zqL58?dbseQyTKQC}b^uQ8&==Bb@$sR?s{ehz`pCUeGN zx@fk^qd+5F3Q6U1QvIz#Yfl|UF@9E#)K*5aZgowg&c(i+?7pMxiQd=$qFCJc< zsJlKzvwwj3xwu!!SM1LH7?XmAU#O6E%C4x!NPF>3FJ!f(7TG0?>a~X2&1E?hb_U#f zG|II`Y-k>)kmDg8V&wkO{zHdy|9Do_NB@%=1`k0(*QCvI(pJNCx7r}y_g(Ofm9Wqf z8au)#~Egg8s+-80oj11715H>2470iL9W0Ejj&) z6Or|<`1Lq42KwmD>?XS2u?0roylS`1QOn~{Vj)yy-3~^f+EIivdY;|&LX^&6BR#u@ z*V-<(_UvUi!N(tnMK6r1uFQ83c#{3!AgYXB*-M5rJ2MGyyxY73{g7SbxD)!m@v!U> zVv25-Q03Id%;x}>r-=sg4ccZulJh4PvaBpu1q_9P2c1qrR{0k9Yl-` zeeAr?`yxZZIrQ!uv>pi3>xfX?`%k-xoJ=tKI1zJCbfr@4AR^zL`vUM0+Vm3xeKsPx zj4QSq&#xwjAJMw0YH;NfHi@JBVJpp3}MNIZN)&a?CVg1HUc z4MryE1GH1O3!keh<*C-T^Jf@caa-FT{b3(?N1BkD6Fb5du5NDFhF|d;_P!UESkQn| zYz$Se9N$Y49!imPXP1BGjCYG8qcLCTIG$S(4&H&rya3ALrir>EPyfo z@?t@uGkklxxsZo>ZL{yzrMKhI+V-1Wk`$~k7OuG25~V+WaK8R1JzgRf-O5vqaqkzg z_p#SaG&&1EA>Ev8A5%~6)Tp^;# z7sLe1CZ4!HnGxk`YNr`rp!+Vd;=@D%^PPT{?RRy1DSkKd}DM`RQ+61Ec1d7+>XW4{8Oc5?J5yE?9j>=3D>5)*x-HaWOM+s{bq1^hXXtXRFo zxUEXn#lJ1;cdAz8$0RSYA!D7LDb;FJY?T|8zYF%WN*I#G`$951`G$XGV3aia$+5uQ z6>7R|@F5n7-OWDGA|Y~Sf3)W<8aCaBNVZx<64;sDjk9|-DyRGYp5=@jLP)Mp(jO3% zew>b;`VEYNxO#b!hR7w1QdmgmO*uQY!k{hCOMTQ|eek@j4v@pzNAQiSV#1|r-&P|h zZ5|MN1)nj%=sA`?$JVUafZp6Tk$U`i?pj>9WM&%i&R}`YCqdiFFOiATRys?*S<3FH zgGZscc(oZk{b&nH3nha_6Z10_gC^YeD|#_kg;TjBYGMI%EG6q>D$ z#zIKFr2WR<*&6b?L`FU>(fS!p$*MIL7KnlIo{>R@8W{#oFkY>XCB2b2`#ST{R+}P# zWfg;N)Y~eusvh0tuBn6|Zfpe?Kl-NRvj7$v=vy*R+GBGq=Jq2Z49RaP@4xvQWUDr; zWMgyAwdVvm(YZ>YqCiq9TV^~UV(FitQ^y6Tt4E+VP{mwbkJ5c5!$)GPDi;<6{e03< zak-bQ(XD-_{nq)$pCqU}iA1qJqoG-_;Sue5cxV-Fsmm5$ah)n&9OBSoW^*j(d`hbr z+YSa6i-N`)>G~CqRaOkorp%4X*^&)a1QE1ICb;)N3hlVMiJb`aoQ(9frZtjCDuQjF z7*c(84NTva3WscE8ynTXtP~KY9ZYQjK zH{ozy%H&so&zr{_ZN#Q$+mr*lm%@tG{ln&w@`n@_p1g?%EPO72JN?)SXLw)!DUnrk zm9rSW-Ye17PXvq`k(ii?(Tn!>Rj}VsDu&jIiFGcdoDs~@AVggZRzD`@4SPL07O57%uP9%P8Y5|5vR`D$qK0LA(+yJUG zBYX$m`$h>UOc-}KaK|+i!;3o@QPb@%FCQ#w_sC#Sr*9X@JY5m-D)J95aL(n8a4d1* z1r9jXakwpmq4I|&FkZ7y`@-NsO-?-=Q4DclO(-b-Q>6-zE5zhM4PKr-Ez(7{p zM-}iXGuKu+eZ#WVC%BX-EN-PId<~UNyl%0G_bV{N z%-&=FYFPn#x$88(Qm$Oz8rz(lCPeoO$ar@ z_DV{~#k9RR84aA4@~E}Z*-9a)>fo}(+Hq%P!CJ^n@^Inp!tK~-$I z-Rhx<>L2OwoelFuJzqj;m@@5dee;zusUw%x8gvLb+TtM^afT!niu4@nH^HLb*Bgr0 z?Q4N8*DHdV15V|fPq9nT<5F+Ax4$mQx_N*vPb}n z3C~1W;RDXDcY}bb-3o~W`h(DKAJz?{>5Lv%-Vr-N>d2!jv6z>X#}RB0{PJCt_r>vj z%@a1t8$U;arA%g0!dTgr9PQ|A!Mevul1%I3u#klK5Iwx)1H8LX8V9hBT#~42bV&*+ zE7oKy|4KL5I2$iQ^7`bj0*V2i7*z`%=jc|GH2QAe_%z#~gJ};0N9frwbT_~NMx=yO z7kA(s2ynW?OxxosA7^UK3AE&61pTqFzxPW)T^IRF_LuuhhA4?Rru*R?jss$w?zEob za>mENcV1B&gy9&Ww6rICjX*|#rkaRED2v|>hsRU>7(PyYJjZbZA)|3u8mWdDTDtx6ASS=B$@uh=4gkXn&@%nqZ3SJ}; zR-J6DB_f6a5OzyV?Rz`7(sn@PigYl%rW6KsW_2r`oG>c%=j4x{%qinP&VowwcC}>b zPEG8gHEpW#9_PLvQ4Jn9xrQ6NrPKKU5tw~>Ur zYKOI5c~|Bhwy_ZH-WA(qrQyao=}-9KMJfXYLzya7?|EmRt+^qEkTk!0MWrAu`;tRB z%5&uTEy3){b8lRi(jz^IhGnPC%vjK`hTPH}Y+n=Tl?kP+%0^6Esi*Xs)9kqv+bcd{ zOP<3)M;~hv)S_6OAS~!izpvt$m3y9cC}G<|)}nZ)hoYAsEcGd&2j{YEpQtqQUFtcEQLojPCjbsHfkm!9tJjppNpT}UCht4-bBv3 znze&h&R$A=j9N8j*%@dWgP|nmi$?vSf7WBYH&31Fw87)V+_N%`n&h^LXzNYNF7<{4 zC-MW~{<3PQ3=t?Z`Y?4o_=c#)w`_sIu;te_&|5JP;9_EExJ5xw}cs49KD5-x{cRzmoMd=vI(Tv)q-M!&jT8a6H2*KZNDCYyZSwD zuoH}jl6SWI^+QVcr+WJGF$Q>qd-H)CK9~g+Q?Nc9>s@D_YcSM?9z*5 zflSGic@KYA9DD?{hMs|wQi1g{h5-cB!m(>|CL7vdzQqEzuXMtVA4pAR5Gi?Zo=wtUl$nc2s9mZZ|U+p*$Hul+sfM`Fp(wzEI^n zFE!tXcS9QAzSITEn{rlm*?h3*N=XD<~-yJ)ykGPYV8A?aoH1mwF+|xW#Lsl$x9i%t)i-0&x_;R&a zsf(}Cc%X-FX3Z*SB(q9Bd8hBdF+VNkw}dvLBq>872k<~Y(_KH`d~r3mfG)!D<4{(@ z!bnJS7FsY(cz&i=9=*u)Chk=34|I!47tc_2iWCF?pj-pZt^d~DezW-erB=`{{q8TG zf=oX(#Q%eMS)kZIhMN9Vg?|p_e-6e0vi>cO=P#_RtPJ!VK#lqD3OG<-{`Z9csaIxJ zPI^{gtkFNP{w*HoFTFA`Z~*gG|C930^hbxxf9jQyg@K+OXfXSSUjKMl@&Bpb{~xIK z%zy0scTYx6;GxKW7>`qkvlzeCbneq3M6f4F9m@eOc&0&7%CXwBwN%N`mY`Dh$v0O* z!iY|Eh-X)V`Z?RqIVenIl<$L%F{?l1oj}fdWC+}Igy=VVA#|=lrP@3BRWwyAy^JechTW3ASJz0}{o3oh& zr$v;F$ACj2bn?Dkuab97mmr~alC|4IxHHyewW)Pm^6Bxs?G##KDB7Q8qYxpdv68Dz ztgW}Mbb2{S!%TH3I8lr1;C#PgZVCa4ZRv1Wszq9t3GSHBGEHZclIy@@iATGl^mVSM zLcbRD1j%5U8q~WFGmhHoP{E)*Xbdw6BhRDW=v_&Kki&%KGH8cQa{l)#f+@B=%w(k5 z;Y^!}8=w^aSVmLdib|#c2y|H3$Q*BE3z&sUq|&X+6O7Z#%9VLZMNn2r;OD*&A$I^%4c=KCXob?j{NgTo4h@95gFlab)Q%*YMquKHX^fV}R z%Chusl2n40y8rVk1}gbL`s$q+JUVUX%|;Ui~73_|9J z{*Hn7hLw6E`+eYPLu*s<0#>&kZIPL~v5fbqPV9>R*|{g}rPb^H#ARy~XaO5{4Udy} zAKnbEF-i<6{aP&O#pw@7zM6aKR|aC}TXU+@71r$#9z%)Ei=x8|w-W|w%>_NUfrE3% zb)PfNUKzi-WSd98s*ViW!MB%-EULqGW=11RH&<9kqcX@jy@q&bbS_{}wq4v7=K|mG zUk+{GUaeBm_4>9{Dpvn#&QhDFzTnCORK7w^j^K3dKxrO%a?&|HsvC}x%AL5kdsv4a z0s!7T7vRN3m7PAC(H))R83SM0hHVplowC9ljyHZYo{yd}zxc!Vm7xG5ml&1Pqj~XN z9-4>I>s&J(U7-auf;KM81N#akY^idkiM=1^wQ$p&Ag zRdMnhKAX6K%fa)s1$^DVGjNd~=lOXh~!r?5Mp$uAJIYWSe+E=+gw>~8RdX4_o%*6z`$;omB%5__0^~Pg* zj3ac9(vX<|-O|A<{dFR_P(^II8U=P=l0-n*o=mg)cTj7A0duqs##aqz=28^)X%q4R zJXp}Asm|Sef*o4T>E@LyAUy7U2%#*{brx$4MG4OGzyu`*!>rlEoJid=m_r`#b}kfeml zkBX;67^8}C4l)f(Z{m?~rBPa?oq+1VV1eU9gPhrFXlhd0FuH&hplUBKa7>0JTS+*x zb^Dg^I3jlVBghh+p)yS0=;hL^8z}|ylL&;0q%PlVY*tMyM>{Ye8y-)8Z@fwJRhczm75EriaL`rFs&rU zm_W}&z{5d;;TQKO>Hd|{UwlYyS_Cma@4!!dWYod+Rhu4?nEJ-DKZ_WM#;M!BXly-j}P-ITRc0IV(cq&z3IX`i?wq zB&pz5%-_^BCh1ww{NtcChcektm9#6*XYEd}*c-koVU&H+Scl>~wU%Uj!y&<<;8_s) zooLsaY+p12iYu@i1!c==6jvV85k%h`lYEux9+=$-h+Rd{2UgD4yXUU^5oFnYET5^FeP+%&QJW3Szq5^N3p_GDDJ$*Ecak9f_#KMrt0b#Et*r&& z0+w%p)@vpx_JlWS#B0T`+3#jYE;Cd*3i8)CN!Kj0vPT~j2j1qvhTW}g=GyVK?Nxh! z4xv-%>=YT^%tXWM=Kuj;aS&oSI0f;BZb(B?_gIC#(dD5o&sK(F!^rc~#P7K?bzvA& zpFIby6vQtE-nI%-DoK z0^HSwCD`RB{5$qg?=sQ7-`uoU*BdS8ihFaH9Rg$sm1mPj;NWmE%V?g-*pbU8k`u)s z2T;9Ylo&LHl||}be>XTZ(Bb)PKA*+*B{t1Wv!$%tggb6>E1r;1LXv<6CdYYD0zN+5 zqqJ*|MoE7@u(;1Y!2ypi{cMpa#Y3MxSQ@QLl4`w@8lD0I<>ty(T}UXT;x%OgQ|@=R z2M{vB`YIMi0yHSuNp_e))6hMyYmd3+!=O?ZF|^q@r>Jq*b6fL);+hVF))Uy#g!ge% z?PGWHs2=?Cv7rdZxnMgNH}ve4oc>&v*_Lt39yi;H#`{~JIs|b$i;v4TOsjZ2);Af# z(WKIq0RgjLr0Y1E%q0$dV{&doI)L;!Ida1VRw`mdLUo=#jLwoKV%7D9b9JNw5` zU^Y(0(jpYkr0(xO)SBneomk8p>n=9OJmncF;8Q^t#kA5}2q(<_sNHFP*YAUfe$&CoYXmsVk_tZ!+V?Xoa?PJ(w8YK{ZOTP;Oo z=&h)YCv{;jhh!!>oS1H`gKX6+`%nRli+SF*$U49KQQP^MW>JXGYjzhGbNge5lz}s7 zxS#lKoIXW$xup2z=a}W#YlA*t^z^$uKdhca;`0;LbIo0m!zfgpE^0Wu>ihho7ar-2 zFR92{#w&(xKDdLF`L)=Od6`#q#NFg525uYpyl0A6Uxo_dn9Pm88c`Y!?H8Ca~~r52_M0z z`I<=)6+Zc0t>N&InVNT^+A-QKLSME5(hP|32BO%R3FX=F^7QtgylecG#$0t4Dw(F_ zwb=0vMZR$bAf+vC__@D#yhsKsw;u2IW3D-Qo2#Mf{gZ7N=w|!hvodjV z09pT0HT~s9_%p=p|94IAj~eRlnjQ;qb^b$5uTs-Cc3BMZsiX6A$}kkRx;%@g`YFVK zA^QQkBp{{5!c)@WePJz~NU~15^A^VAsW>8Myp5$>!V$5+NZQ7GybI#6f+RTHr$JF0 zfDr%d+9SYJPg46r_qR)$!Ezc6y?1lZ9UYz*Bj=d4;b3mHtMm_D=uKCchD0H!17Enj z%q6k^AJ*P7s;+Iz8pYk+-Q6v?hT!h*?(PnO-~@t0a0~A4?(XjH8s0vs@4hb+mPwFRTivF2R6?bZ7jy$^bUvW~W9K#f#A@&bZtudvjO@Kg+9xxKAA1Xm(bE8B*6 z$K9dvnneC!fR~|SUHh#xd58NP#I3ic|9Lt?^MnUB1!_v&VnCQ@ip06|uydiG;H1?$ zxwNysob%))ZQ)0Rud~vE${Ra;$#Po~9|B(^7b z#!|2x9my4H{LidB5K%gP-LSki{?CauzLKSt`#q_q#JGNG=Q!Wq4pnsWODsHL%}!B- zN3jH_?H=AD)>qo!lFj^r2qjTFEbrrl^7u9oUPamE&Lt}e*Aj;c4t>5B%M2Ln+LlIg zS-$imXv=6{ugq4Jn75BAEM2%Rrhg}M5;)DHuC2J)f8WiY05EU!&yNCnBt-Njp;s@~ z5bHY7_kPAhPQ?o7OPJy+J{9ldG{cCJZ{JkFWDLX9N{CC!)G1~o#W9lvybDTA$P6jx zo&3m|`0Cwm)WMvlMEzYo7Y35{`MA7F!5?v+wo?4F#6cy`}`&ay1Nt8?DWbE(qi=5H(-=5fZHR#_lu`FeOZeN|qu}8=0aMlw1O#?h5%ze;xf)^K4qSLa8#!=<#oB0(sBk<{j@PPeSv}EoaBfw z$}=@Oj*C>#x_Wj)zkIeGy5u6IyR4!dt%V{Q4XNe;M8re%P8*3`XVF7{cBiOjcb_CM zu}z}_otiD0=KEv`sQeOAm4Y(`VRiG68@UBMT}|dCjlaemWYV7Zw7zpZkTuybDQxHYXI_6IsFFPJ(Lx&o`^qRJu8z6grW z!U5qqHX?JNoOlY(gk5u7Aqvm494Nf$_I1`l>E&R6-=`}q8=m3~-sCccy4`XsmH8(F zUtgXQo`t>;voJXQh%lJsiA_9pi#c@cay!8fH3ctutKUusrEbzx!$@Z<#^fU;5ZZJ; zUG_om1Rv5KxvkV?M5p+v_Txn1%vR)ek}aJ@hE?36~5Xm z8O0fu9~`u!(cyHy(^pE)v@vK8owRJIjT=_z+=HTs&sCLl&6TW>VJZ&*>-fGbda_cH zjV=rmxiE)})fuo1W3(TUf2Psdrct#_mPZKmN}|Ci!nL7=Q;od|bXelOkqY`y3c?~( zsA@fTtUgDdM8n1Gz9R}cyr3guts+x{H7bnney{Ap_O@P+KU|%%iM6;-RWC`be(Z#^ zhZw-E)|Jo5@dD!Ic- zD9yG(3BDde+ciFwe7%HZ&V8;%MnEGx$H?HN$mlBj15}d{a=h2qi!@y;yOZR5X2W)? zF4qX2M#B5&`9M)o{Ql<5r5bQ&<9bsc-wX1Rh5zE- z2#(8cWQX`lP`FY;Rg@i2)1LX{xzkBYa=HDX1NqCm%V|F6=eDzm#T!p-_wI*!ILho= z1K7rMew|RW+)Fs?%l7cIOKIZ%pUt0e9e76t5i&p8_Kr&&EXA^U1>!Y;RZySXZYTq} zFkzqFmov#rF1t<+WSJ+bPO|Nq7&WH6omO?5lk-kkZZGEq4DFBC#p1x1NS=6$;NN=8 zd)Y?_5}gWy`AeSZYZtkVUU{Bc?(2S8q^_Uh`Y|DvOOM;9-aLD;7zf38rw6upxmtRs zh!kS;S(8r20BJ2^dFnZ%h@BTP=bm4O&yo>+Jjb;RNdY!at&h$cRPQnFL+5;?c4)bk zL=^r4f>+{p889TPMIN!-%)HKUTb|8x?Fi0!#K-=!iyKrJF9pawi`SJ~Ci#X4UpK8y^vHuUafmZ4*u^69n3k#&nOLy-QJ?%!GW{psp zXmGp1wr@tV?%*7)JkB6Yn{FjD0$u(Ms^D((mwLjCni75&eYBydh^L#d)tE!xW71MF z8?i)JH8;_|-=$v?F?2ebx1tY%B`(r3epc>O$Q_fRo6uYIr2Pcr>_N(Jq#dLqwA`rmoWpLNNerS|;> zM=hLR)gOPJp4kPVVLx_U*ah=+1G7P0mwf<>2_abKRQHGQ-AIx9#F$XsVg4v49yB!| zyb|Ay`cv&ywCtvy9TuWt;mIH(i}*ObU*P0|WAye*;ECH0R?+@T)tl@c%vZCSM4cmq zf{IPx?Z!xz2~fe?7oc4Cc{%J{wg$Xdd{14#^qmZqwo%1hUAQRgkZ~KaX21K?$ z-rW`dZ9+KU;-9g=e7JsbAfYN<@qjcFJ}{jG{zT_9l+j zHg?8(#&+%=#&$+ddZqyT3Ik{A|L}SEm*M{ZNgW{H{Ph<9Kg<%Keq`VRj7?|e1Z4Y% zvW)GI0r3C<8=xf>Fc9^BnkFD!6YKvf&tFZW|H|_hvif!K|DgN^u#Ni*#Q94kI}A%2a|K4c(Zw7e(P1o%|sJ^lN84&&pll?JL_Mc)h&6Rk7 z8=g7IGRg6R+#Ll`pojn_@U0mK>9y zL1fsP9iE**ahk5Tva~Jyl0+jWX*ACeIDZ}^dv6P9MD3qJJ;7Qb|^ zXWg4X3K`t-F82KxJO^qX_voel!AXmNa3PK8y6wC;yMM)H(@RWgY9)3LK4#gdqbEpHJr{eM51){*(D&MV?i3kb$j_`Zq)18}N zQjn0q+N1E1^BwYXd#vUU1Wp4O46)RW(zKT}zlWRP0L?8-&ndzp|$cLUspVaqkGSkUgM3Tzk6lqYW^e3_pL=p?3%33qFf~u|1KS zXt=9DF9emj)XuUnPR1|fi6%9v`d+rUlUwaHH$`VR_Hz^IYytuwzTYknEGtf>Rqs=Y zL6D}W0Q((|>684vs^N>YoHpafnGrkRT{Ceb^M%}2kuRo7EnYMp{nw49;~rDXz8Li< z%B~sXxk#cBc7nZD+SP#p=+Em5{-tQG+GtA3lKGDW`E$}pz?|8ynV_4sS>c}MfpD9ynSr+PKDTK=_p;74MY9VczCSqik&}YHe94O0A zKQgwk>R-tV&;GO!#%K=3`a%MykdJ!NWlb1eFL&2uIApY@U^Mcnxw)WUX}(gr>EiAN z>2Nrfi=U|Su?HjDu-+N9=4!mZU0^!Cl*CW;Ngii)CqX`_{4_=B`)PZ3NW-nTHh2n` zF_!tF3lC>ubB45N5!q*4ekXLMwr}?wD+;F%pFGaB!Z9X#!Fk5zT3@&!df3pHlS{GG zY2ASXR9$CaCt{g0&uN}x&+y8nwB0ojnGDiJNuVs0?jei>k36PKOy;IxQSkV)+<_Ar zEx(r8{G`$fuwrc*u)QVd(FhSPIMN&A(~EVFa$Vq+N5D}jia3C$FV5u8nJe|jr!Wna zP5!p&GHIv_zt?p$i>4D+TPzI3oBea9*!)uhs=H&5?#+;c8lkMpRF$tt$*?KvW9CP6 zELpLt1~JNX4KPyc@y{O+)QI*syal)%TTTz5sZIPUir^)|IlgpP3x!OVey;DMD_6RZ z_}OhtYF$|c-X>Fx=ZY*^>A-(p*&=3$K-8Qm2ToSehu?+5B3iuyv-_fuWSam&7-MW6XozE!1+YbKOfG0 z`Bjjh^lJQbeD2dM^c6%Kd)>gHL8b=vWoL;RtzcRrE={YEcx7t}#Gr^5?0tGmqsDHb&`T^P#*?^6p#5MhX^zzwynCCeom4N$O8D zeIS0(_d<#;w!CDorrKLFhEnxjngcS>v_E#)Bp$A}$g)BGvBthvY~(S179rKZCTCj; zvAAKb&5jp|AFCExs+Pk-954}3r;O!kXQ!vYIR(aM%PjnUL)xYeTGeKE4C*7Qjd#y( zRrI{A{|FVtE96MARpNJAwesnXkuJ`n)tlg zFrIA;xVy5yov=!$2Vn~h{=rnm%52OjO$&2}B1Hcy^LNTHE^~X6Tmka2O$;k!T3pH6 zzSjArU6|;+9OEfYUebXj#j=xG7}Px*;cuTi6O#tLw_#t}mhdVCQ+`LKLbs6@>2pQ$*iW?>B>wM@!J za_>|Lf6)k#;*U^be{d%gLlJ8m;LO>`!cxQ~7s9cZS9-B#VT+DIXy+1D{}>@dT>bfT zSR!#`YN`(rqaZRBjy9Jd^T3h89jp|h7}?o$74MWg4|9rwygH=CU>DZS)5f%1E^qQ7 ze7-?EpCijzlkQlxYc7`qRT)d{T8<)*amL$debIDa|5wUk*N+y?var%(fo%-bsY$!w zjv~1)N?J^smP-tkaQJ(b#!S4re26Nw-*BB$)P?ImgX$K9Ys>SEZT?^Gg7*X(S6oSWe`by>96X0k3T#4G`+spBwWP&pjGf6_n-SFeR~8K0nhM7 zC{MsJBrX%DlV||(Q)W&t%BnW^{;YwlV-YUthIrc-gz~25ZRo;=-{dO2>F7pn zH2T6`OIDLa^S2hAQFV;vcOM|eNQL?W!f*Qou|gU9fg@YdAk@(A6qu&!(ZHhXa}3qT zTdHEK2r6Uj%|3zaEt!cU@_(oyT|r^|NC(=rA5AstNIt~UBwSijlWt}*A###f>3S^%vh_7s&Fq*X@)B5PyyHRnGUk+#;&MXR37I<2XWcFH078n{Z&q?)U z2b)t-LjINXr$2+s>;^o{P(#oI0)gw8W`XY3dW`+Y_BQaawp8Qdt`Afeay1luZ*8~( z@_tueNZ+fCl{qGQWT@*7pS?vnI12f{*v-iJ+EvMqmkjHqbxkkKZoL zNq*WIHt_0SkT~gs|7KDpP}l}kdVR@q!M$@sDE=xa=rcbNz?0Y5>$Sjk*XyQ&&zef6O+`B8==+ftH?bN0b9R?`ZHYCXF0ab+ zmO}76iGoqmOJBc-i555S6D}R&O$m~@?_xjqXcayzjHWo4B!6bZe;IG8$mk`ytaU!u z-Iqo%F+|bpxKkO%bijGnldg5rVORLJq4_;7V!_sj)JbM}<5~86=+ZO!>DsZ9;VPlY zFU0Z$r90y)5~_ivk;O3+XzF~@zXETazJ!iQKIXfc}Z)n zMEwesg$srb<+&FR04k;@cjRmyj)BvO?gJt(BFWrFRPs@Qj&oZvOD=oI|&zhT{)Y-XPj>zxPd9)M* zK`SVJ##Ai@r&buN$evF*RLdEXS^I^}STOE-mwHKOSRj__#}L9y@})A2pkZ@G63UDa z?T3ugorKV2umal8v|&vL?~vJ;X^?+|!2b8i3|CRawGD$Wr0N@6=#B*@5F)#s+ft{I^ft#BHkTe_M^AEeo z|NnS`-vI5eWB&*En~D9m%I2R#0p|+HotcP(6W}Y)_IDyw_TS2ze~t%WVGa%^26h1S z{T&YjCc*p#`~M}Bm4$-=z*ziEh>F7w}&Y4*w?e z1=x`Or?U6osfd4<`ThgKf#c5))_)QXO#hT{sMD0R+wDhhKT*3S7F_IP>mkw5rYNl1 zi?HeK?EMY~#mg^$s+fSqv9!ff{d#g!zdfBN&JrjXR%$#`%M8`x8sFsg$EIbqmX;mHXu{^MpV_<< zPW-1n6U;Vs0*}j1zLwDPsrTu33~+fuDBQyj_Z{nR z?l)^|?nK-b2qe7Yezv|(b1V2;ivsKJwy_i~66RhNpJvvcD5N)6d6IlxZm#wTNwX#q zT^mW(TI*E1o|kF9Rg^0q7U;G{zIEP_$hdXT4oCl(Mh6H7n|xU6ENXNsGPisx$PQa_ zt_}2d9jtx5O8lQW9~`~)m!Im9@wlOa@2gH>_m?rHhQ|9ehcCib9wwob4up(biPahH zRUUca`j6_kcpHNe=pcDBbkDMRv%}K-OmL;H=i15+3)_4NjvFSN2Ze;CBQ`*jZNhw`}i2t4gP0;#W_i%dK% zAm&D*iXSq43Lvpq-OAn`oHJ@*BnD?Ce{$8jdWr#L4gt_&FGzP$zJ!H%#c@C&I>|vpUD|@8(@m7#b7h zt-#oc>|3L5sm&nBybgtatF#jqDHWiS*l6kx7~_TBl%*adC(YNvsNGF*eIeF&;8}E5 zBd3`$O=yaOJQnb?SxDuVENhyg2D|-|bj}(+wGXj6*T9)O=>f{BT0rO7ZHb?sPdp*h zWfM=CbTJul-N%g-_Oo#UvUo%|jaBY?cMAAjSD*C-?WrtJD~mq3OX3$qiQ=_)<2llr zG=ZbmD|B5ZGlYpUhBLwF2+aOKBAz5yowdVa$+>7+mcs0g8_8|o)8NAavslyWNjNAt ziNYeEMr*X9Xg5+mWUw2NnmEg$J(+n1p^;hr2>C-b(OEh1PV43HSc$Ma8u#g$z38*Z z7N;8c#Co3H7jES}GiC55kA()2b;R;5+JmvD>8L<+g0fEi9JVZm0)OPV z-P^Xdi~GpOIbR1K^aNx#o3_HOYCl6CDN11QLWE?CgLQ+2$zNpyA&QHY&G4|L$w~KB zLgadFiCuvBU}Y82C}nxZdO6g6v?nP{QSFqDtJ7FdbN#`-;xN%9f>2=HCwh~ye?0%q zN%g^mA;y;tvz{h6S@P{uEh9)6Mb?w(?Xro_UITJH!;aNw5~Oe|yy(Unk=$o74SX%< z@H>pt?p~*aO^?N~{j89Td=F?>y%nqAwYyNQ$~3!2KHBAxA|*>v{N@iR&<$EQ`kG1y zs(LT|$2L7hT$~~Uc?m+s;F$dv?)8h`3F&*2G}5$;v2dzdFfkFFMdp$*PX+`$GVMyf zvlCF%gr*5M9Uw^rh;HLa!4w`M@F7NgBNdeZ*_sShjNr<(jAgKrv3^4L1~(t7Y9#ec z2(KppnvRYpmwCt@S)hXy1b#|yK_4~Jjw%ZQ&Ps!(0g34)Z+>6(>XW2;B+kM&eq(k>cX z{FmLP(NQicGo=?|sjKcokF%`(tOeg34~3VG>V>>FHC$WEck7-G&`gd*!rUCDE6TkE zA}@uXooaO5oe!9)F{njPT)z2FTz#oA2?>~#?HB!1nbbpIte6B?$KSgk%c)s{BRsh_ zf}Cvj&@PBh%-KcL(s&zg~nmSWlJ#mZ#dxK1%iZ-XnT&keKQfo zP1ur;XpDKPX80f_wTe*7@3DL`nXftaAaS}qPXC@O>aRHDAvs1d4(+6Cb$=+aF^W$u zo~~9gi*sou(X0sMn~Ld87nzO>Q9m#T{gUic{5sej`^X2l6hjo%; zxU(>SA%-JCI;o)IK;j3~&n;tLCJgYX^a@)~TWw825Bdz|qMRLFX=d46C zec%NLv!1%ku_4+*Qxn8A85-tCW~3kO9vg{6coAUV~X zPF9S3`oFxnUll=lDpYD@K2p&z=YE6{TcF^(TO*ooA@YBrR5a{~xFJ4I88C*v~e#Jn9s7^6@5KbUseWi_L~I;x=adq`}6C z4$Ru)yn{0J2revZZ7oi$)DsjZjfDwC-ucpDkhlv9U9M6?jvzeTI*HE+M85bfG_BpN zG)WMAgVvu3%?a(OcQi6NK{YpWlqBQ@aKd|okod*vDLxn4WMsPrR#ZX4uM#>f|tg9&W7;Gz9k$}k0dZe9G_|}*z zDPZx8z{MSDK3`fY9W@^IWTYlNU>nNXoWt#2w)nMFkRRzteduJg$ zlFXiMEMlK^5c{o0gSawYqa19EJL(j7L%`D-m4UZ4Wsa_ z1L;X@_8ms(UD!tV6%>i=&!(s}Re5?jOiebsraG4f6@MSta_~X>{pg* z@p%KhgHIysv1J$Z&N^wnxADWDjZSL7+9r8EFLQp#H2#_1GA1=?Gzm?7XAX0SdDYdL z?3M;|xq(3cHH9iSX>5;Fb$|hhA$N6hZqQ#l-4&#-m$eI0IccC8w*lN9O+;OU{lsi8 zfAAc>IhSQXj$`nRes|q|&JEG#i5s+c$abT4>4Mz%nTA@j=Mn}84obk9S4AKlLZlsw zmSIEq79uQ9_s|>GV%s{}YZ00#61p?Ncp!dmDZUoIHLfh|{DOipc!A!SNrxD#nZ8L?JR?Ah-H6Po5ta1yE1SvNdll?`D}Phb~} zs^8C5{CG*gHFWr z|50#fVfxkF@LSgZR`&h{_y4?A?0}XHF2F&s0H_&G0FU(7aOPigIsWzh{1y&an3wGn5`Q^ zO6c+3>@8Vw`PiiUT|F)Ny%F?ArteBNK6=-LC&aq@wths->J8|4Y<)YJMtm*x12i6< zHcXV@J<&R(Tq^#2JI#8(#?X4KGag(d4IIzSL&Ec zq*im@LDl@_i0wlW)e5*2rXYn>N=Yj<}q9&t&x4ZG<#nTO)(L$+Y#;?4g zj6ripP=faD2%b-YOQ*AtN!|C#@Pe^p?lOjPqN5FFhujKA^TzIxb;DiF^(Aw@d9b5u zzoPMaXU~=k0wbiQ6`+2L?tBkYF=+|2gRFuiOs&|s^Cv>|HkQy`PUZ@835WPJBEHy^SKMH0)5CkuzT zo_G;X$@zZr>F1E`W5;@RnH?7I*9zllWf_I3ip62rlvlOHP5PCe&VgEl6Kb{Vcg||H z+dJ^3n*^Jg=bDZ#_=qtw>C}6inmgNfZ#%-hjFZQ;g(tbRKg=?_LRIJ9R8Sam9+{xS zJ_OnEVMwCI^1^O@^6e{(cJ-lcH-0vaO#s>jSUnl2_yxZp#yfks?SYDp2pEsx^M;A1 z1ZA~YEGnd%YiwA5R>i}J2_Re>X-OWCD-89a?P>;>N8G@I8=3(4mh}=}wWhhcgMfCm z7u_{9Ay>@!g9$Q9$H9&2h@4;$pj!nqn%h23X4R*sj)H}f0gDY>VFz?YN^Vou1PBSB zYccnT5ulO&jNkCp9!5Hkry`xQt{g!{DHtM&*jkoey=|FNp?KIc>%^f~*6<^c{JPtD zeFJ28X;kr$-Hz~+HkDcf%lPup5U#e03Q`M8oNW9}!n%V+aK)L$(7ItPDT_X`J|kXS z=u;q7FA;vEW30FV)OwNt$(*K7Z_+@}jgh@aZjqHr@mnldFF2L(C!}CB#|fDOD?{r1 zSP4D_YTgcuVbBmP!$rK}v~YNn?joL3eWaAg~gHN-fyHBLXye^JrE zs?^kohRjaPH<&=efFZDb3!$LfAeB2D4m-fjBO%P0Oa#@?FwPqmmXFJjiWmg)k|S0l zBx7{BmC(@25AZKex=L|U#ez6+aH2U;aX8KPS#=f3aLOyMnHS2Qo37MSq3+4%6T!i9 z{?3Br%|qBa&~w$rHLM~vdEimUfb*@a!wkNTJ6nMv5K@-fOlLAXPeM>D ziI4p4C=`yt+(u46mV$a{=20SRC?s@(OX?%abHyX}!MY%SuUrw@nMJq)R^ScKp!fm% z)Ou34gPvkN!%4=R8#7kjg)Gs5_d;;laCxWJS#)h#<3+O}B}^GiCPQTO)J*W5q^P&n zX0K4o;@~%NGD*~ioBU0%SEQ6}J$>J##uYJWwLYxhZQH1=7E^wMg_1q%RFSp0 zY|nGiPzHG*?1*l+k&#kRud|cWH}hHXUqh%YJwLC_-<%aOv~;nCQ^Z%rH&rp1Bl6*) z?%QfvT*T>diD(gEh!&v|cE)SV9cy!L&#mOiVnFM8q6n`UHzPU+s-pRUC42RZs4}`Cv}Q!Ut@zawYYqR zt9g~1?5tFx8DNEY5Sa4ugHAawIk*WAq*6RXuH2MnZ44$Rn2YMfDHdx;m@8pBZ8ffv z>0ewscATVN_bjDGj3mwF>LE*YnX>Ej@#y91fBK2->DjG6(b#^t2-;ac2+c`2_yC~Fdu+o<63tE*+7n#)=%G-h8m7E>! z3qq7Ds|M)DS_W{PmVz0^W-8=oU+S1%{$b(LycReN>lZ2S?N>Nap zkKP@jf)k=dV97@XJrhxpj2qNg_flP9Wk6FdkA^-eHn3+$@6+pescjvQ*Y)llJ@4HS0!#;2!%A`Ehj7yl(bQM5SS4_u>z{fT8* z7%37|I--y0Mb8sm&_)rXy8J!o;y&N!D+^4i>Ij&tDm}z0C&i)agY(4VB($s1*-v4i zxo!JJm53fezV9qTTP>pnl4vinzNWGsz06m8&!|V@{lg zZ4Azqg#%`rQ{=~wyR%!thg~T7NiA zAM4C>AR?|HsK}jcsSa(18pZ%4gonUDjsSYfZqu*O(NJsHQf)9ViB6TRNrXDB5rCEF zwTx$8w{5jKe`;IA#X)~`a;+Sn(FW0_Kab;}u4d7ze-F(jQ>Nr)zZh#3v>&nP_ix^2yvBA=nJT4(Q#0-lU|a(ma>R0y7RnM;x*_DuH- z)Xzg#3>%wrfCbpro5VA1J4yB5XO*%@5oN*8m7zZx>IG}I(fXH@OzsgwjRF^fnNGGb z9G8zK|6G=DCzC20s(+9%n6&(nxjF7x7tlgY)cr7KDe+=C5}LV^!MbcTd2D{cRPp&9 z;tYF=AmoC@1;vy*B16hcWKjB5ovta)%S4?mcjVb2f~!$HBt?IsG}p$W&1M&bw#v3D zw=lsa0~Vq@eh|z}mY9M;rLhz@dlv>+FT6E(OLo)4v&xXq;>0%BK= zuZCS3h}Pl$B1}@e`s3|=$yq2JvPyF3<^TfQ-T=hPz)QQSjX*8iK*YydqxmgEH1)Gi z)MX7w4)c}v=o|AoGkiTSa!<*e*~Y?)uSF@FUMW$l-n2xASfYW`lTCiMqpL6Hgq<091GPt z7;v}UN^vcTC4k(KYko+B8?VyjfR68#N*J9#r{lbYbZ?ka;7%N0qW($k@l#?j0RCgIviEx~cPEUemL7{l3q@_9Kw z)~|%lE1CL0+<(Gp8+-}TE3$+cpF*C!z#!1Ub)&SFep$<9r%3kSc|ycSR- z-vsK&bCxtcvwWRAo~erPRFRqSS1NbRG*WkDNtTD%#Ys@kkA0V&1CBL?W3G7OA2i?O zk|VeLP=__%S*g-qdMsBm&xauwKKsJ;XL(8!0YO5E97xXrwK5|HO1{<>fQv^6oVPHv zPPxgnU(A3wIc+CGp~OW=MrER^iWMcUb5itMNBp`BaTRL;LLD{v`o`G zxkh?j1}=PE&c<~`F&=Oj*pl0eo2xzjbbXh>FS!S&~eb3D9c@YSwk)1b7~%=Z{A8+b;F0; zpTKYu>6_y`xdC2ijkPuq!v-t|CEp>JKn(*KD z#HMb;=Fyu0=S{#$oNXmAA2{&cfh^e~5Q}I1SBW1X zm2*AKAHf7%FR2AMfHtPYo2zt_eulEITtF5laT;w}+GSpjd)9Pmp*Mi8d5k%usp_DA zur4hz44P}Y$Adg$X{iiEvgLDdH2}Y~cDfm(;&Axmw{L4xahs|06NfE8I4<0`LQp0G zOO>LDhB~gHAk8%t-iX6Cg+FBLg}5ZZt${h4D`@4y6;(Q$lQS`>q;N?6>LlA~mN5hL-rm9~E&0{-SV~Tu zK1tw>!|h(gu~T;v=<=SBjuVrDDV>mx@x7mLM}luuZ#n#QP`8gba2GJ5AU z(Uce+{B?|UFlEuN2qz_jcAeL)RJGzhXtg8OypJBDiW5sg2M3$L*L6tO`S$g$K?=(; zw7nr5G`+@Ny6|;VoctYi$u;vDD_Pdpf&nVmDbwRaJ$d=$W(lx8S&Nz&A<7m#CJPF< z6va*hws^H8>7!d_z|dytl9Wt{wu7mE#y)ydYi&;x}^(6^a>D24+b#U9|W3ziu=0pOj+ zjjua}#Bn};*L67@Nr%-)%G*FnG*iZmkt+^BH$ECws@80ZYZ$G3H+8G(DuG>PDl7q+ zDiNXU1l-3ZSk0N4CE`qibszEORY<0?&o#k9PK8;^xX90=DFv=1iS!t5ANiU&l8Q)> zMGXg(aG0NX+QTf!YneHofg3jv&Su5ZQ3VhtG_^k9L2Sq-e3S9)cxl%0h3cO?_Okw> zafLl^j%dH(4Ep7s{Y5+!x^|wN4l7;L`@XQC*32G3i`7{5&LCFD90n6ub$>N`A%-PB zf6M4D0#kKmw-8orGAl?PdQ#9^t_4tsA|kW!{pxCb0T^az74>2j4CE8fk5Z=aDRy6+ z+D3<os0gSOQgBsjPl?H}(!aG(!S&7dI{!cIK=B7F7;Cy(|n`;p(8{RA#`X7O|onz_IN zxE2!y;TjREjVfA`T>1lCaf>*6IkZ%(^ogvhq*KiL44G<5fOMxNXLF`{R4JFOHLL4r zA%Zk$`wh(Uv4WP?Uix;oq>iD{^TfgZcBA8BlV$&25TaEuCCxff&N9d2W$Q?H^QpRkRk=`nH#!|bB zzAJj#uzVFfpb8sf55f8{)H6mk@9Hi`y zVpcYtwmt-eb`}s>gsbbQoL4HTEsy{E+=N*i9C`P|iEfcM!g zX@D@GTF##Miwd#T9`7>vWfDgI_~r&y59H$^%;u4)3z>;215fy}6}9({=)ASq_BSj# z=RaW4f6;V*VbKAjzy3EY`k%YIzn?9P zW}l1YM^#t8!GYg2ri&4qO&`?E?JsaYy!Bm_s;P07LLe%{k%-d0H$UIG+0_GE{;1%k zQ08q3svBrjtm#of0_83~(-@DOl{y#<&`i+M^H_qe2g`{FjM{3M0LET-@=c2v z)d3tjh%|#oudu-6te!3Ws*eXpWDEGizN7*wWv@0sA5e00rJi|sKCdVZ_rXK)bbN@R zPLT{OIgU3B#Wet6*kPMaeBJ@qTtoJLkc!%k&lM~JrZ0!M7(v`s%taA(#{!V1k(;v zc>KLd^V0q2yft=zj7K~=SVy7AkvuymLo#H zRh}DSFv3j}^2L!qcPo$D*wVg7Pd+!K7ni;9!10m4TL`bILY}zKV$;SA%=r^tY;ISM zPl^u876C7i1fSSYw{*e|u#)a9af7DlI`5cMtfJ&4$t%3%OJ(EA_pb7X{oyJ+Add4O z!Sa{R`uWCc30Q#rqW`{fO&<#s$&R1>cd9W|6CvZ7R+81_K_tm&T?ac3_KfS>DRquj zdRV6(o+7@Lc@!Kw8~hoVt6df-V@=q~W^mJ^#e|Y!*O0sUyynXZ&=fa#zoR1(E;gjE zIJivs&{tmvu8NMh9wcN2y0a^P79B||SW274<9&;kI>*M7fj5L+~64lWIz#s=liHnS3kmv70dXIlH_evu6aMA`-z9!)FnO*7S)f&$p8Ty zgCpEZ91rypC{2!mO%z%EOKU7prOmV%6qFtPS#?n*J+-Cv_iR~I2e>-lWy%7u#!@on zAPOKGeYirpHY^cfMR=ILH5MtYb>T)?5#cKIr+-@djpt)cu(u9$Ff zOe=H;%S`DgJL2xnN+F~QfX=x$lPM6ia6M2G9!E%PoXI8msB}qEfm)@WarQ}V=#3_o z#>aU1HMIZ(v%oJ*MJ07#NMXrLB+60KnEyxiF~+JLb45Zoo$OJLDEMnmo&No#qL3d_ zQG~WfMe&$~Y5JyWT^>6t)~w_5YHHw_aDi@!u7b!Wm|zVPoneu*VBib!yAquuM~IIX z0}%||qV8yCIy6-CcC*F9hz%iSKR;t76?NIIz3?TfFjC@*H(qG9CXo*W_<*{im0ip} z8;Fo)m-(kOz+CD%YE3jXd`-@@(_9aulbtK-)c6I87UM)>!Z^q*%q#rOs&G4@+bLr$ z-m?+^nErxn-gq$OvYQ)Hz8;}P3!725$+uw&yR==%_mWbM~zz#)-00J z_3$5(Yz=Qec?D~bX0>t9ArQxe>gUH(-zC{#ZE5lhKHI35rGUMuV|~&QCz>gf;85=( zS+aJ{6FM4hZvjHd=1EFQ1bI-3A<62SOZc(VxyeEj{^9zIF*#EqSG@-G_qsrkl>Af4 z55OnTbd$yegOA<)F_wCnH}Fa0$m5Y>lo-d_eV~OP0g?3}0kAyC>L$41{Y&@j+6qbG zn`7CafwsJUk<6$h+#GMqI0ia_WMFM!{J4ELPnGVzP*c@gexibmsy1BU?Ra0Guh2Ak zaj6DyJ)oL4jewnlFLA?vRHH;%9TA;qMBI|>KlzFvEqzx6T~$Im_nVkQ9E-(S-(%nB-kZv!mgQrSE4{;YLk)g z6_qPGJs-_QhzGsc%_+8T25t@MPN%OGTkH?do&HjV`+1BFWs4C6MXk zc0KuUY4*_IU$GZ}A0YYW2hc+~iFaR9D6OPP8V^2862mNb`sb)Mr%r2eHOuCd^cUBt zMCz`hweXhSLwIl&W%~%L1xijj=tboS!*mmY?!s+vGtk0xM!y0aZc#t_H_HS-g5dGO zFbJYfTMDP0)G`dnitxGPOg&ok%I0`V%YF$LSN}-kDXp#Zv0^U72-4`j(S+?BBehKUSku2pTeVWmf*p@Bvfuw3meZ3y)3zGlU-ITh*=_+CQXL`75Qi+jm z>Q6FEX=D;pqvQw5{Y&(9iKp%~-!eiitXS+=g;vslLH*%6)21y9`_CN0$#Q7>lQHFk zODSzBCk21P<(-DVU_VXB7KV<%%w{Lu^^M)#q`6&4G}Bm3bF=A+g!b&DJY@=4a*e+! z^i(l@q{L%Sr~dS1OFEvk$6?5#=Lk2*F!M8EEqDdUTV@~eb6>r_!yVb-HTsboM+F#Z zJyA+^!6YHDrkJ2hMB6~NIJD^z5cU@cox%u_4k6=yOWtE-wDdmtc^MS46n>!xD6yiA zibk-F{Ac_*`OxUJb^W{Z=dqWCh0=x#PyDRd=3VDOUylKaMo$*!bh%zn>7!x$n}UI_ zx3{wo3X3G#GuDzhl!FXfj1bT8~t$E~lqCL@7NIuy|oeOpC z4L{sWycN^W-lPj4Xa!rP(qmU&zAHWJ)Q7S$`sfutMH&1U;=ZLxIo(yK#fCK{#hLxt zQ_}?0T-g~4Fa3>=P72xaFqUU;^;W&2I6{`1Y}Z9o#g#vdRE9|SNA9T`w5d62k*xyP z^?bjyD`aFU#UOY=Z5o0j{iJ&=X$oY}Dq0uCpbiQij3a^&jHBiuy06JBS-$Kyvl@Q? z|A)1=438^GwnfFv%*Sb0b36aZ^-mQ+5z2vapm^8Fj8 z77EVM!4a~j!P?MK+XJq`cVJw4T(`ncvCW)hKh5HIRV@fwSiA{O=S)RftL0I841Bsi zgr8#T_;cgYQZ3kCJs2p0jm&cZ(Uk4Ksj9_6S*-YF znGnO{Qp^ddPexVLKwrK4IH_`Ut+u!5s4C)g!{S-XpFer|TYtZFLaChGooF2MhNa>2 zi+%ZPLWCqXT#G;C{Gb3OvaEN*=gzK3&A#MkWa}X`GOrs=8hb%oBWmGyQtF9tZ_=3i zPa;2W_ABsp1W|j*qKD4qG<8>Sn|^|2Zv8O5qh?v~O+(xp>yKounD_j`=T6s`S{lW_ ztD6WLkupbK569VPZ9vpMw9hgH0q2Cg7zF(kmeYS7u%3o0(0yd_<~ueNvHEuhzCZJ0 z{zH%!AkE+J!<~|;qph=pv8f{Hqq`_ZMmn$FITsR|meoFkJqvDLW@811F${ z`CrK~9DfOF`S+%P2rpKqzYC?|{7dqUe{aeN$k+e3c{@1&e6Ie@=J~g#Y#dAs%zvAT z5fE(lKdhL)Ys$*b&cMX_w*&s`k@{aP{3}xnD=$z`}pW*81%l z|C`e|fb+!ypg{dzda?gM2}PWL_OL(B=^Oyo)qhDSs=!%_+5MIGKkp1u+*-zwTxu4X z6cKl0pc4PnpdHW(6f6BiltIJnd`;U<*LxO?nxZWJT3a||pwJDK8hWI20t`F<3;5Tu z4Kf;J&0_ZF-sJBsp+7!Ufn=?9-%g~zKabDVeJEHqA&KlAA72ye&%Fd~klYre!nU%B z$Zi)5S<$!YY+4lf!6HrBsPuX2-#`;Q`%0@Hq}l2YYON2Z*~q0MN*$++{j&^k zrr(HlBf++@6Kx!!GeGgd5GF;jsD(iRiywLcV<-2&dZ;fU;kow?3FvbTj}x~ z@;u(953Fw`T-L&zZS&4B}x&Y30|5$T+Q~C^q{NTrS*AY_W z6#XosR{ zAeVcTm|j=zLYv>f`IlD6J817C@A-D`)e7^G4l#I15(S=F?{q4Kw)XSV_61f$G;CZ{ za>3@1fmmxtR%X8%Oo<)|dJIhz>=N?Ls%a-s*1EnaFMg2dJow;rNHMO}8NnLJ&rRHFtMS)G6H+Jo5}P@aRShk1tl|X3C=Bxi1*6J${gWjaYt; zW*A=@8TsK-S%dP}2ypNUY`U>ASiC-@vzWAVJM#L_7$s*4WX-%h?igYvse8P+F(`23 zPm(*_yWu%(uxppJb5yU<Q54J!0qtA7xKYWwB`ARTzyu+8y9%tn?1X;hnp6r< zmsd(X7}YFA(`?PkKc}ngU)RYZE7n1i|9QXt*rfk<`7%1$R6YIkO-z77aIzU5bV@y) z54s6sLDWX%D3VNqa#anF6l1JE9mw~Mb&RQUbc|dHET)s#(b;Ee)Gx-}yGR3hYDmFV z=B->ac5z=aeJBE}G*^Gob~FB}rYT4Q4{WPXJBAoH-;}Q?`&1ZEUZ7l=T!FlQSo6eb ze^TpPu#jAB-MoAFw0S1xaE){8uAaqZJnVBK5q5g@qBY3^T|M^@3Ne0=ub4ex@CX!M zkIn2^r<-TmSJio(aoWAuHwaVc&%m<^w=4GVmQTd`V5JF|;L&MLa6V@}Ak%u6n;;Ez zBu~2p##N4xTHE6!o<)*F@0T$cfi)#jn$(PldgB zYFCT~L_|m%H*-wqwTrwkp~Sn)TElNI$*2i`u0CuSOfSuFSot7MK*^Yq3*T>!A*E)U zs(3?)tK@`FY!3fHo@_@dGM>8X$8QDQ4vhd`~ z&JmvSB_T+y*A<{W{GTJeHPes=sg~AwBG8)`&HYp6cJEVY?IQ)#^_@*&)iLe8Q6w9d zH~}7IA<8WrMqxx9FEPj$Li#*(6l3Jwpq}E@<#e?rCS(0ae1`*|$xrzTCEAv)H3q)8 zU}6@s8(h&d?Y6e8L`?x|(y}K8@R6FEd>8II2fDF%0bp_tP#Or;w4@P0Rm!VUx<3;u+gAUqCR89Ghbh`7ei5KH<(&KM`hG#Nb zAo{qkHPVw-VA`E5MMN!|6+%1UoL+`C|Mad7hXN;1YgILM2h-1ql<{;5xqt= zp6sF;U-PGS-vFS#j;4j%=jQ0-!Fh}U18aLmc)X;d0V1mh$p#~_YiT)8EC?xZi=JAX zZi`zrO|euE*_&u=L1?O`c$#@kwRFm}GC`8p>w3swg|$$#3K3|`n*ydsQI-cp+FIOb z`84q20VjIMFh2wf<$KY0TE~*3J|dB$R;K77#|n;o+lsK)-KT*QMFB&tR9iKonC8q# z#!2_3VQ7|zcH95Dh!bdovr!#cP^&5_bfaVChfNWe;_cm3n}KqToT91{EG*=_JC9Vs zug0YcZ_uFYIJHWHXqwzKyJe|*%-R%ZceLJBxDLF577xbF=|kFQfBM-Tu}*`#V462E zcpjY?tht)L=nK6wZq}qMhKqnkcNY>lBlzS(e_c`Lrqo#Pi59%SsD1|Xl?jy4jGxmBK%g%49}9A3ux8~a#l zmFh~$#nOZAJL8~w7BZFIR*M=b_HosH-=q&dj7Y^!E=tq5QCiHnl{JN}`}_oPc3FigRel?ignDl+6jnfCBUJz|NM^19~79O~8-KFEzCFkO70d5Bp zd}jf)7y>k??Me$oFTHRF5KyO_O`ESqizhv=X2MIw+`TquP+z`P^LqMs z8z2{lSGU1V$K(byh{J%`gk*V3Q{)1v%^3AWmoL0>B}+x->f zEsC2lvxn7^elItBS7aO{Q(fJOK3?y*oLYts+kJ)?Z62*9V_VvYe=IZ@h+y}_3D=#O zKt^ur%%t}UocQPU&r>pdy?(LaJHq!uL;en2#UoGZZC7SeOSLZQU(_#jiPZP{*B|4r z*gRQfbfHqoY@e_#3P|C%_nepRL6@2Qi?qkyGb{S1bGdnM{$y<^}WvbIg_>Nkn0Z5({8Q=a;AmN{3&VQ#T2v7vvPE*Kq(PeX`~+P*IA7 z_TG`0rkuH5otSqEU~$BUDi1v*q^@tSWmFS^TxpxI*e$g5BA*|Cj*I#ik`OkIz2zoD z1WQf$GmdG&(g|f;keby$GTI!Rb;EdC;zyE6QL3J+qb*Z#TxIle5k6)X)0`B_jkP0mS@^)@#=UBsRot!_E791BZ8PQb3-`Ii&xN zcm^fH!zgde+=m;FYC`CZC010P>`c8$uMbG^3Us3!*3i&ud^X8B(!AX$t4MeHxJQgr z>RPTZ$&PW43dlnDqz|BgsBk4WBWFr*pSDh1L!S^Y3z>LvMlbpXR|cY3F#XZ|mQ8db zJ*l_v9UQwK{|4aU{PTa+{{i6neNO(jfAl$jBL)BKxVS(6qtE#ll;-zf{u_V?P_g0P z;D>)}%FfEdzzoQQ`&Z-w5a0BFXv)kC$Sm`>P5*+@{9CVVT>l~1i;?RuD9yh&W%~v2 z{58-EP;K$g5Zr%?x%!vLsy`=Z{a3u?e@$ihU998}u;velgp2vVFPMR&o4C?=_39H$ z;Ld^!k3>k8%`J(#Fj1fAJ@p!D!={UikLA}^H^9pzDej$I>ql^n zEL=aowq>8cac%twU*3#(p{U{ZPsV0Vim77-)ATok7@F9!f}XNHs4Fo6R=9YE$ak6ILUjuD@nmf%GHS90D)V?O46al)df~E%YD;6^kIscJYcQ(UjPZ zaxgq<^4j32aeuyu>-kUKE4i?Ol8^@<%WKxBnhTfy%9d4a)b0ry^dB|m7lq*rVC!gS zJ1uVISl;^eBFa&^0#i=jylitdp9f3ZNpe=;b(N#rFEyg&b;EfU@rJrZfF~Q3dMc1G zkC7<~W8_qQi|>scbI)tsd_Rb)Z21VzDKveb*7y%!eip0gC|CQOm7r z4SlQBR2AaLGL14Q-1j{DNPpiin1Mp$;TPCa=C_hjDeV73&K;b;iA+FoZnXy7kalDb5Q7s8=oBEJbvP0iaoJMGZ5 zT{-q<%5{*IuHVLQbS?ITg(4>y8_Cyu;11dfSv6o zBZEdrPK*3+d7_$ryX5Frz?Q%kmJlWB+fKQrEmsMb~)=Ai`}1L!EYcnN--$kWcv8FmYG$ z+zs#ehpz5(T0;7D~9>4zo0T!HNoG^?<_+MwTos}kxXvOlvs!qT<@@{YNcsJzC^}JW2E-W_lCwdDJTa>6CY=&9Y<{W>wbZ7G$#$`iNA-}c0ft1SWqb%Q0D#}L2DM`?< zY^fRPD^c)`KqgpV7i=^N3gW6LdbJsenw6vrdSw0x&=U@V85al(RiZT<#fpTs^fIc@ z->g?Oa=7SM9;C7smkt*dgkUYOh!$D&!jEj8K-X%9C-gn~d+vBch;?PAHG?P_bRVqu z-Ac=OcU}dULXq9N#fp5oA*qq|j3o=45l+X^YSx?;|Fb9k%Nwf2PS2wdPzvod7vxGcpt+Wwr(m4*8^_t`r^7OSnWj&Wln1W!2<&a&$<$ag$kW%E$7)~k3Bs^ z`IZG}UPN~y>-B^qS*RWlOV0IOm*b0ccV-tZbx37lcW)njnDq^vrkFE<ae<`dKjuQf7ab8#%UmAhi*9( z7{rM)xA+;tH2xpm(XsIc#fKNB7<^grTfHbAx1LWAiDDx2J!BzoirAGOeWDIJ$sd;U z3%jrzAVI2{&KT9eKUxt7T6N{5^R|4z-Q*)uWR2t*F%> z*p=Qp|Cl<=>LE05NgD+Aaw}b?&C7y+FJP~cIU70m(gUF^goi_>N>wI=&mT!EL#npO z;KxaJ^OkYi^_3*dwLgUzNkd6ROrFhCHi8BBt}!T&UG15g-m)6(q@DEqCIG833BEjx zi(-y?QO%~}ldqe@BlB}oz6(D#QNB$jKOgmxEb>dGr+h`tNpa1Eg!r*Ha1pesx_h|% zw0Zfxy!Go!3yFaNrslPO4e!-Q?6mu$K)gg?9fN2$-p$UF7E#GM@!b;t+1;A!A?l63 zd!={V!X^Wa=RoBPzKE~{E*iJKcH{wE^+3$SX-jkN0fWGCRt16V{LG@`S2lzqWuu28 zWz<)@O?%E+#cjEGeRtbZvjVfEIEB2L?rV#;|@e~2c)V*+#QPQ?J)AYoPHgc7<)Xgs5d@j!n_N!4dS z!IOFV!SYHH1&ZsN*3e3?QPTla1y!-Ogj?oh4?$s1bDw%MmDSdG5AD|u^pF0}5TH;8 zRt?|j#+x)7MB6^G02#A^HmIs{w^amz|C9*qb&nO!clea{BjLzI40DzW$jJVRpk~`{ z9C@xm1Rh&p@6p|f-+ItSJ0LpBHjD_vAc?~f=8Pa2#4ak5Ug{f~cZdNnAd~AZ>#ceN zxsH->!NeX9kYQGS!$;#m^KV9pfw{14hW1^9Ft6Col!=2!yHSr+$|aJp_@9;naDmHg z57UgPB>N{KM@TFplX1F*4Sol5wKkFol22A)(h~idNX?d1RVPUv` z%w7-va$wPfEv;=${E^3csa?H^cXr!_cmNS4-Af8ng1IZQW}tUU<#3eQC|sJhD0;rR z_$`DU>fojSz_43!u;k7^Lpwrf_;^_r19vME4t(_0Q{L={9`aa5ACrN&;0JfI+-(!h z;(l;*$r>ZR8QYuTE$OWQR!zf6!kMk~WQB}F8TZsD z_I+V3UEKv$Dq`3^>gGK6JdMJYd)3Ti1PTi5L^+l9V+}GpjeO98kNr$3?oJO$qN7A~ zutv7~6;GJV&?g%IVPWa$?%)z2oeVkepEdjehUPuw{5fBg!g%X*wnyf7>!`YCGXh&x z<*vcBh*<^5oxN%k+Wb5-t&`D%FyU9Kbo*-5q!D4lf&1Ae(UZOljn+=2qtG#ynEHpa(+#X7*&{2>7;6$i)E$J5u z@}#{U45gBU&+XdqUlEYZ%{f9r^qgBmGzlFjAgw?*vuqC5d~`?-ERtt2k5f(tXEE=ksj&xcpM~B9!%3p=^U2OL4mnJYk*-!(WMmn zFB)urY>euti|k$#9)KEl5GPfIoxSj8-GU`!3Ab#Z;MqdQ05cp>G`tiPJ~i^_Qg!s9 z_2z_zhuhM;)JzE&7L_ z=PdDZ&(k+2g@~=Nl(017hXR5uKzi{IaG1mqvL%iQ&WW?nsy`a!16vDuH!Dmk7S1>& z?{8wEpaBIVmUDWm*7Xw;f>$YbjP<48&EE=McHj46$7RatUKHSozvxjRgv|6L$FF;| zH<7MBIJH~_5F5uK7wrzhE+U~p!$MzlR>_k#9BgwrRhCJS!{_&KtYy76_VeC`;MQ1V z>@VG}Uwph&T{^RUi04&P=9QT!JNZ!1qFq+uNYyMKoaE)?6G@$+ziNsBYFrg9aM@r- zC_=@$-Sw8=WCb%*e?I2ey@1ELHP$o|I879lu!LW{lW6^6gXZgZVSjetU}23Rv0kdO zD5H2pO!+1s+79na2z&b=#&ldi<8>Ks*y3J}6ff*g#k`rvIzvB9eHJ(JjYTKc+Nt>p z$@JfE7n*E8jjpP6MmujSBw|h;lthSrW)FWJqI`6mJczQyC32kfjHIJ!sHyf?Mxwr0 zyV}0m;cSDPq5^^I=-X&J=i_V6QHj!N%XuLG%FjG>5DVA5jUyZ!92*?H1IbDMNuw$} zZ1YOT-YD9$?ZMC=Gx{ujltM$KbKMnNaF4%vAekfZq(tmE(6PLT{eU!8A+ryLCosBy zBGqMSG4j!oh9O)pb@a#WnvaD%pt?84XexYq*taTKud8G|6t{(&#oUBVtc6tF{hoA2 zJzJ0bfb_*BWu;HP2*Toc4#yB%t7vI`DrK)fJDhAa!S+yStS&2r$^@Dsh1)Z$aFz%2 z_%IoGLl6>L-HM&_F@+H(I(uqecWTh1@(2z(79e&@KFi(0!Mm+~t#&4N^t#QI+J8Wk zSpmXRb)ZwYdF&Kgrpe8Uio`gMV}=9dm~>FO7};<; zU@_hUQ#skXlT)4U#8FHjpSwqsk<&FH+pr!N!#_tR`VQ(p_!Z&x5K;+Sf6k>}=|z(3 ztT1;c*r!)z*(cABPNh6KmPT)(!;@g=BOkI;bTgvWS;Q8(v+JC2c&eu`T~P35Nr?Qt zBsp_l0yZ?UK=8~Ppk(hdpIUWUJV9;N@eb|Js9EKA?@_KcP-Do9hiwkwsnH1}uaupA z#7y5OBTqPKPP`mvN5Ib#{@XiFZa%f}NsKv_ynYw+ z3Z}^`I-z4C(=S2~!?KVVf?UOFk_fWi~%2r(R&Q=G?aG-g1il;0f;Q^ZF9XyT{EASz4X zM}B)3&~YJDTA`COCGZiq-r=1)fAq=&a(}JrF1r!P;3{mS?R%WsUm0!}5g*`Y*H`pR z!JKvJT(q^E4fQy+JbphXi}GJrnX7iyZ?Q39Fe>XN?th_gLbRWgIc5*PVmUnnyOEP% z!H$Q9bIbJ>1%HSS$P1ry-GV@>;(8b0jFDOV8z2V|UhqG-#(w~E{#knT!=ITtT)#*l z|BD1ifV?ojFo&e8RIjs4-H{~DS7rY5S@c|>-je@&CXhPUg@ z-5O`igi&vr*yG;*x9nG0|E12hs}4qK4tc6)y*SgaJF-be++Qs^I^7*_F6=Xgf^d)H zbxr3Xw!W+oWj2$u!(qkHvplV4*}77UG`<>pR>IPJTWRlve>p>aO%?cg{d&20U+6_Z zAf1c9;uEKoia7_o_Tagaw0_3$@q&Dw*HOeP-ct%7xn?K0Bl~u}Flruc_1aOR4WHL+tWTKXl$pqaPT?Nj6bM zQ<9;jm4$BY;JPm2P#V&%rs1$Yw5C{j2gYn0G9-xpM`Y%VcwHLN5V#>J0%RUrYs7Sfv-N6GIZp8id3GSysB)Yl-MBg zQlAxC6N)il<~m3PjgrMip{CD7c+8vBR$5C6OS#2BJU`q7_>;@c;aIX0VoDG8{1k#wp6A z$TLF}i+qI-zhCoPxO=aSm*A zMET%@z8lbUvER!a!v(w5Wi%JfXJuGIS;+X&^x2Irf45e#?m|B?-#qpCQ6>!a{lSj^ zEW{;LR-p-YdQ30TAqHf9^gy_w!Txw9$%uwOhk=4!&ulxn)2oEi$v=?9vV#bQqXy9* z-j@*8@bZ=$Ww|BSWkw^)b$?Zqz5iR6tTFYhh9z6 z$1KT!$({s+JH?a)0HtMu^U0dNqU3<`$LdIO$B4O^Aya>kAtZ z*cXv~BQRV|ZXtizXAvn~cZ5T^{jF7tqlHr33AjRx5b%fO@%H7UWOkvfj>S$eW2}s{ z8Sc9+ZYt~eS*dl$p5VF5<}A3Lrvnk-w$L(!Q74-7ukDrba0Utwg!!WeX!f zke9Hj(_Xs$wyGj zqoPIZ{QZs;v5#3)J#wsCM^0%iW*=7Cu!+7Q6!q%X1bfo7VRkF^r%T}kDl^Sjj9M4Z zC{Wfz9l0mPg59{(cG^SrBCfmjDi}gW>LVX7R&N)^QnzYO^dfW#rmK3e9rAW<=@kQ>?B{TDp7z8C; zCikkfAu^MqQ3D^_9?4LIPQ(+Tl=k{)wAWDwRleQD8#}mnX+ka-H5!x(IJpB8sp{8= z4sMvogDW*+ksFFP-_g~q779a(_Hztk0b|{UVzSUjkAku) zZvjqYX1Wf8?<++UPWA$W@e8t2*Hj5tQ2zp=6ZoC=F7Jmp+ujWQHn#7II=m1t4Mf&e z9@`4G3)QF?ZBH{S%iSLJg#<{y1^K|u3^{wt?9NmOndI$EMy%&VLXM2b$M4ET6EW%B zNm*dHOLpmFhQd2Imau7kSNR}^1RB6Rc#uo?&YnyYq8Fi+eA!}I^DqL^He?f8K*$Px zGt_3BbB{t@u!P zXEQ)JbMN(;)(?~ildBw5e+3SmYfhx{ip-4YW-wK|?1ys3HIy1ZoB&V^rz7(6kOu79BvU?YV}#qGYn=;=Z0VMlDe+tR0E-$N@+3b3DW@UI8m z*Fl|A$8(u?YZ9fAZZ{dV&gm|XW*hp`b;;(=v2lskFN!qDQN_u*&KC`dwhOF7GCKHa ztVu}{Wn{LL1%=KPV^ka^>l+^lWQOBEk`DE`jGq;2ELD{f!8&wwmAg>um({|H<)2e7NthIh1Oo&$f2^(93*%H>PLLP zWCJg9fsW|g!)J5+cq+?bTmQB+zOuYL2t*Wr1L@H5%_7N7`e)&22i{us4a82PVOHbZ zO&|ZloKOX1XK^XA2ZD8o>_&?#DDxwT*@-(=M;GG@S?GsNiCd{XkZ+H*$qme|P8=4Ejgx2k#Fc)sS0c6KFf9aRZ6Q%`dc8AYFSp>9Z zAvP&&B~9uU)KbIgNAta46%K-6)&uR2s-wLF>;*q1Ds+OsnT=}BP=%4filbej-wGBV zKi90Gd2UBO;l}-3#<-UQu!lKO`%Uu$;@on`WN4 ztHX9J=Co~IC(U!-vpdJ3F4G<}d$Esv(?LW#FFd-3ABE(|8ikBqx3Fzh!>VFZ5IAW> z{@`KJiIE+tlHMkuAt{^WRswBCgbg||9Wbx&w<0&2LT0Y<6}4+@w)G{#WSsM)!RuRf zC&)E&5FOWpo<0|EhIFcLr`ZkBY9Q+Pkz&>^Q$?$TkNl6~zH<;5m^>5zI^Sl(k&tYk zpr>UK+xVQ(Zz**B*1ue(vQ|$XM&G> z1zn~-D>e`#@y)Kv)B&yvm=?{@1QHb4T}$CN{(Po`0q$a!C8Zr$G8!iu+EphCT0$>| zLm3T7>%%qcppj_)z5L-IPN50=PG{2~?M{(T!%!r&vM2)LMqZH3_ zp2#U9su`b#Z?80OD+TtE(F3Zsm=SxY8hz{X`Gjf$MMVmhl+}shg4wp!cZ|T);txu& z(tZcZvm8}}eQ(qUwHOPAvMXMeg8*9P`u1*z*j?~<_{EZ$uQXUo4XU zEBu0q@h`j%K&hPHpn`^`77>6j!odb8nDn=mf`0e@f50#PrI5|PfEj>tzyDYG#h)Rc zf8rOcEP$%g|0RBrsVf_c+k)KjtPU3^y9vB1b5qymPZSCy8HWeD!R{IN$wa$a425ib z;H!SNk!xaatdTRViS zaz5(|?qkkPw$n&h3E|YFe-my!MhDL8f$!tPd91JUy%0`rwCBTvJHjerPxMUh;6e7r z`_66q``g3lpl|2%$>7j7lLJz%`WcpO_9Rn*ds^S_Ely8#pu+S7v0N4b(he?2mhY|8 z+s=kJRqrSPKLs*|y7C|`Sv889UKTh?>ZW{y@MZJmr_@+nkYTIZrM?=bZtn=rQ!wy;UOY~%_!Ez}CwRY(%>J%?<8 zajNw%;>rQeKdQ)9xvwE?7vgtYszuR`C2(3a#YfzN!KPtYYLAC5kfFtLGor|}QRogC z{7F%Elg8<$gzwm6bxgYhN_NmuZnZQHkKmwP%rOpsh$fuTT>`}NHRF^RG;^xyrnnKK z$o%Ie>UDs4Bn=_QQ8phRfsDuV>o2}9XqiK9>Flmd8Hu_=x6kM0+)gsWs~YSCeJSF# zE9s9Y=|wk!OSE$^iLe*&ZOPLA(111|Y^oM-EfRsgMt-Rk5il*#t*`(AOC|9{XGh&1 zk=u*@(GA|ILm{qotg0pNs2RL4mS+t23*r0ZzgA zSxBr19$U>RwaXG4W<+e;Qm`9l5+s$m93V^#`qCAemHMzC&ei#@bV8I|-4UsR%Uuqb z-U2sTQiaiBTgEu3`k6t<><<|1D2zZ=I_&eGuSY(d*>O_leZ{6^E2TldR#bv~j2ic( z2aBnzD-pbsW-9wRyZdG-9UWjwl>zDHX{;ZR2~^+T&}n0#2BF5l%l2tcuqPuK)y+{&F1xG-F9+PrAGgi{y#mQV zAx}MlyzAWU#bHgi)5pBwOt5i|U>+i?EB+p!4mNKPV$Z_C-M~cQ9?*F%7~JO$M_%&t zo0P55$0yunTHo}kw;;kt)E3jf(&!@ zg$Q<3jiz}ooCIq)D9J_+Op_ACAZfx#&AnQ%RN>KeVF${6u(ilT?2{PzsyXTSz1nm> z!00yQ$|EggQny}9aP9`DUf7Jz&BB4*k9-jF0RuuPR>~A?5TzBW)qZUpthG?gJt0s7 z5%wbiYP1GoD)BJD8OUNxiJJ~<&qBZ@;nniNov1^N6VqmPsX6ia^-1M0WH)Tw_}DENYAPJ>;u`1UgX>1w4uOD< zk_eeG9s{+0?Z)QAmXh#N0*FtaN1Xd^DL+FRw;nOLl|iQAUhi9ta^oNaNhX$IEJ|@> z^2+}f>$ptBNcO#pC<+iLnk9kt+oc4dqd9}Mgz8Fv}{Dg}_` zk)gJ)>)BaX-fX8H1^A?M_hKWz*SkPzBn9cMD@Wbk#DsE>3Gjx1GR`5fXhd3^_gL$J zEVU-yhxY{$50;?Dl?EM<<&bgTlnVVd0;ee{nS`%MhfrI#7{F+0SgFbR^0OSAKAPzY z>^I$nRLi^$g}uMFWA29^Gxj%IC$D>M{P^*`;;`0QClXD>0}+7T#lb#Hxv|eqjmo@6 zb5|+q*Ndg^kP^$dMbh6TS`X`tN zel>}+^3(JNt~)U}TE1XQG6qYt^pu2}NzizKoiKIcU`2va_v{u7ml&v$$DBe70YZ?^jxyj&HDj55v^tTOyv+21|^3soyp}n+p zH8z0jPU(V(H|B8dC16)hz>yXxyYJGlU;qp})gwtPZe#XxtUmnqWZ^2%o)hpuIw#md zKjbC#wM$V*NlF+=8%*rB8t_;nyrWL7&OWRklbQJ$P}Evy%eest@na@DskS7@SJZ5b zR9)$pPo)%?{zj-=cYXGK87^z&UjL?zDfug#mJ%SM(~ zPk4;pSJ_uBp&Hj3eN9WJr0+tao?pY8*^-=?tuiEMy}`wL(Iw6mFE}b8`Gn%9xqL9e-8Z= zIYKyEq?5=g&E5IYY1MX}Kzo!B*Wu^KPqzglJ!DM@R)m0Gu|Gq^CQDFy_J96_#G--y z>g&w~RJd_>pErrK?6_m}=yh_}`T*3LDTdV4Mwd`(XfEu=?lZ zB={CqD}%Ak>!Csz+M<|H=ezV#gESXFhi6*k0?v*i;mQZqzzIcnKp2c~@LR zHu0{g2_`mHBsipiSWxwPO-L^_f`r^!gH!u-wL7~lc?*>W&)x9I@GbzvDgk1e1R@=b z;^uq>mX^VBMHR(h8!dC?85j_s*%)7CfMuW3rA9;}I~mZmBrbju!^r}R;C#u$@lu~D zg}6<8J&LMV57Y993cGL3k#tm+Y%wP}v0POiWRz83>kBHBg74o4o z`9}a=bMfi(+Fdoz+7+37j72a&6h>8v9j8(rXz@T%uGo(_Q$Z1<6F;KUczR-jW1Ux9 z1z@-0gxWc`*AvV_;<8zj{)KVo_%MVL+oVEB_`(1a68ZCw7G&Ow!&{u^rU}eIiq%=NBUZ`}% zt(Q69gDR{<7wFA0DUFev7J&UN&*-Emvz%O{^*j6bRb ztc$LyQsWbJ4w^-!7I8rn&F3C=4c#x`NqglHcZqgt=s~!1iI-~q+mdNzc_3b)=t<+Y z4|c@Cvc-)FhC+!DWeE;)5W8+VFrZ%*MhpQ@U@uKXccbQ(a*9Cr8D!QZjURQks?efB zclLd2__ZcD)LvZ#&gHmT>KgiYi)7Rp6M%t+0R~c)mPl8OrzrCymQ_=P>YRZITHN|x z(w!}UxK2NOtqsn4)I>vVKbf9QihtG!80Zq98&@57CcP-U-`2>F@`Due|40X)oM&GgSZYg+_y#nDB~?B@fXi`> zh1b#ZC-`9mNVI%ooEm_?8YL%1o1u`AdTH1$qw<$iL2N`huWjg84gJWv`(A8f(h3lA zG6wAF^z$hqX*EU%B<&hP;e?DP{wSko#4fos2P^Vfn6x>PENYTVN+J`fg-O`71`;f4 zvw;^wt!G~@e6FoDuGZv7LIA^d(%3jD_~%D-=S|NVn`g>d*-h6zCCMUWfDTfCj>GZ^ zZC&`IUcl5s0aN=5khw>iU@_s!>-;&lH;n*L-N9%KRa2%jC`N61xK9v zK|d1nYc0TkLKAMq@mVsI$;dQ62Ywn31Kx6rGBWS`vCq{+l?1z zIRsdSIKYFli?xX>7g28lFz+zn!7k$n*wgpR6KWOdU*e9n8Mnp( z6Z(o?zlmFKQu;c5mcGu+jibzWN zRrs&S6BFZ~)1dq(O{P!VH|76a55VEncb#f%q1{8N<{7t6$b@3a; z`gQRSUYXiz#TyPlV4aA;Nl-SPyiRdDLcRJ{2tY>i+|*80bKmf#q;aVADRK^ z(?6U4p_%y)&CGvjX8uDnpfcA#gqi=)%>0LD=07w864?Ax<`2z)aG-zOVfjNd%O9En zaMwS-`a?6zADRJp+CRVgLo>@CnpytP3;@XfA;bEIW`+3LA`&ZM?%$e_8=bY-WG<20kD9pBN+4u8K#0VvJ0?P#!&DjLf(T z9#6juo`A5z|f`J+17s8$}Fk{?5*b~Oc^j4MEf}eI$IDtp<{;I;u(LUV}@(c z7*FV!q0^4>gofGre;2vYwkjjiOVbkAM&?%5^w_`CX}={}p*U;hP0E{p&jAXc@4W7aKjC>rt{r5RZE9<%Lb>mk4M|#Z~ zX=Nj6WgQP=4{2p>>6QEJcR4A6Qux2O_0cp3ySRW|iULdMUtBbt?BPN}WEmG(i2@po ztfHz!g@5q`q7oVIvLn-QGLH+VI!RubUS$iHiZmH6wx_~orr{zma59f;ih0D;JiEBy zoa)kZCxX$2HYFB2B|GE}{|~d1T;;!@)s^#6^U2mkyJ8SUAGuWsme8tFU0Y;Mi6H z(mWifdN@s$2%w?qFqwv>N|}rbDPdMokw}1wEUiKTemgKY@G4{_A{+s9m`uZ>Orayt zk-#b}&{<#*{fi0__rWcr(?vy{0u?%+SVcu3E8)NrP$83)@L&kwi7=N$21=%7HPsZd zqvv7&ser|+qC$XfeYD`IN+dL;G?Yxk0#kg_(!#7l+t2H!Q)kw;6Rops*;tc;78*L z6eSfPK&Inl8kZ`5l7fdN%eqAawgVY>fQVGMDII)k%;$j+5FIAdu&7hOVn@Zp8drr? zK%@}h4t3z$A%WB&EJBCL7A$s5coG2=7f6Q;3`G!L!>f>#aIhumFqwum)g-c`^%^^El9_9=j2_liAghSC9RQ(6uA{`{ts8lDL@K|7z zRrP=tJQ5BV4d~24#xfbnjs}xySa=+1@ze&hqxasEr`{CPYp{8>>3pahtoka4GWJ` znY84wYyqot2*N>Yil73fGe{jB)i?-D({ZwgiybWwxFC#6Ksyi%)POk%PCp$c)3Bym zTI?u!6ng*`I|4XiNKxQ{n-2$mEFC7(u%?_vw$!{TSj`m3DNx{+1Mu?Uq67jcRyt1h zaIt00BRN57I4Cd`6cr)DbV9t1j+1Fzs*{5vSk{ZxMX!RK3b6lFiLeQgxIk0DVxysC z8r4*@h~?l|g@vSpd}%5ikKkLQ)dhzm4J6a3rU-0d`9M}dfjxr-w8*NExBzgV!0@2- z=^&Ygg~yR6DK0EM$p$WT7J@|s+7v*kKq3=Q1IZpJcCjJC5^~<4BH&*P zB=evqYX&T#%`zzP2w}TG@dC2AFvk_MY%q{aqnbirVcB(7QQ>Gw9#yd3QA~uMXHo31r;)NC?o=8vnt>f&_J?>iVYi{2wtlS5i(8m1T_)ZXi0DsPCG$8 zg}%bdAXuD3A_U;c5G9}|ex-?!D1b}~11Hn+qD~GjV?`OP!h+!Bzgb_*FT}&9o^Ez} zDo|`#@I;t90vMx=~B8Fqwum zRgMR%o?#UioHA4}lIb~L2+*L*x&FmD4P29tXsnorRa~ITRnZcs=cd87f!Yz+0@KV* zPoYh*(jr!2!66N<1tT?0RDs|FxE9k*O{-3^5!o=|kv<@RQOih86Ty_hqe-P@(5Eqp zlXKHp*%hnO0@H;6t_~v$Or${C6-=DzW`UvOb&~xDrv}SjK9LHJE4Vz2G%!&W99Piu zbez+W*W{?_e{NZyW`Pu1PE>Gl7>Qsa1vcZq*=nX?Q75Y|tU`{}StLV1{(rK-XcEb| ze?hW^iXA-c&q=7INq)}8DX<#B$u~6Vv%IT+pr%(*+D0uMZN#KPs(!fw*096K%*~GHdOiODD z_a3W#WpxH2QiMY9j5IKj0!eD9Yn^r)cyd@0tHfm)7KHyGVMxyc6Dcrpyp!PIniA&q{?dVn!O62+>k1N+8m3GChe?;$kBbPlVDeGWe;CG%zxtRZs#J@Itzp zX^(@q0VF^OzM;)(P%&qxC^*8FtSz*DYycGNuN ze^I=Fkq1WjNKke^-8?XLveSdr{ho@xiRfT@MNdwKNlEHd&xsw6eV2giD0DX$*9C&nu*{k^3(sh9BI0+z!#%Hl8%uF zCW7%rffkzS=7Ciw8>U#x2+Ky>p>&Ic%2{aXYUcIU6tLK_;!$J^))pfT z{O{VLrK_2THCb={hf{gFlSqa$5jrgxX<#A+GO$pgJKaPub+XAk1wl2_4Kzf61(8@r zf)&&iMB_p0Pd5=f6)d*2Jd~|KsTLy-j7)h|=*63E9$0m=HI=m3vE?B+gStQ%d0^y^slv{jZXTFAg|yhw^5E(~Sq&o#jI2Uc zR0u)KRx>Ru)hRY2JCPcQz>~qPXC#4%5UzxfDFY@OuxR~qtZGx_tU~aCkpxC=KZ-s~ zHw!#jTD0yxR$*ZQc}5BtozEyBKkX#&q$#9z60!;kP8z82X5?4FnnC?D)6M};Rt~hb zMpjYL4<1?$m~re(HwQe`{IQX2g=!UOs6#ccSaubxcZdg~q}{Yqz>^gNEK4?mrLc^^ zonT~ukugey&YtOJfK?|MrL^8tmgkRV&oENJ=xD@x38t3<2GYa-8$UwTXskz;L5q@5 z-54zg3;``DK|=Y>>E(c@gvFL}M+K&g{3>igR9^~7eGDbjN_47)#g1-AP8gId({sSc z_d@j!)64-+)(cQt^S>q#UBrP37*L0|^8Xi+B{Hu5XYQx^C>h|P&hbe%s?vB67_0gJ zpXm6BOHg-DTE&ZQPYy!rE z!1z8o?IoECr2!6jMuO1zF=i(Bj_OkIfL1$>)1DB}7Atiwm zn)yfWbSBGx8`{OE{HH&bq@%SqyRWw^?(27xR~t`U4NLy(dB`W=o`1l%=V2w1pSCuh z!aX{6M0sb}k>3vAafa&U8*?^|A5s4E^?6V4F8(jgBKmhi|MdF(@G^?Dr~Vq&9J~Bz z{@~wr4_`m{F%+Sr>l17{-+W?YTJ{XhusNrtb5yR@KVK=xKXI~tq@Kq#%A;grc;M5- z7@w_1$;oQj?AziuSL7P<{wZ&^m2lAY_V?bkcm*Z4W2)pl}c#FL9!z0o)UtcySzX|;NW!0Veb0ne@dxiVTj>#X}n!Z#n zTjor{^3u=uUZ!;HOx%gTS&+6`Y=?MCvXPLKM#5D5CF8xxI zjlY&HwDe`m*)*9xj`C;juEE!u%KC5|w`bINE$y~^SRK4M!bGs++v%X*6OZm6pL<mS723kG?Mj|E2;d2j0K9|z?`-{*VDUQFVsB%`oO2GTZnc2Z1 zCyvgUr_io>-*W?1Z@1#DaN*@*g>O@r{`oQdwfbZ9k%tN+?=J1WDQtCQYiGi4&Q-b> zLk8V?MYO6nZ!pu_t$d5qtT4OWM&Rqy=2WSqjfao?I(IiRH~IBwTBLBlL+Ho;V+Q9P zW*Mx`PI~p2bMvVULNhbB7KHz}XQ*!>ic9;)rKM_9`sGi%&2shE@a*WU7Ya(IIZLj8W{#T(|k@wv_1xBYcS@9<~$B7ZNRgG+;{hhJaQ63%XUqnE5O81ty_#`B@G z#+TBU?rhnS8}v1L_nJ1FJvP@L_Wmy9una!+Jw)q!h3pp6n;XQUnFg=V7?$6YUlOVk zmcg&DXes_<=*{2fyNb?D{22azcU$r$jU#{0pDz^jA;y0y5818`yUX>a?3PzowioT` zc=Syo+((!249+#`o3Ea`>i1GLVy>|Z z`I8%eX=0h?=$<<#_lFd}DGq$??y>D$(BEh0a${8VQd6VP7w<-!p;&DDl_(`2H|0_% zHPVu}W_vR)vv*sgJAxFyPJH;(($m#9KCD)x)0D_{#31=y{%XzhCL7wCA2b9#@=T(B zJ?`$^q2;#B{iM{IL={P+D8o4S4Z0~Q9|cmnD)}VK6SdZ5S6hA2WV*B0wl8DpKUN zc)aP&^__dYE^&$U&bnMKYvrDAMsicTQN#C-K|s#-Ko=^PNThwOeSYr^$!j^@zD`AH z1DkoyoNa6G|8@A+JLz@Qj1#AwW?jEol))pXaUuNAkHIxXZ#~5HpD4QjkWHjW8Ad&< z-21aXmxp)P=(qrYwyl)>^W1mgy1*ajEmKYi_vi@ja~0n;+jREDmM2`C4Ov?yqItFo zSm-ZL7A_YnUwR^AZ*bxY-vY%Vn`c}H49=;d?=$JWGUz1z+1bl0x20#zo={&2r>IEN zxf~*O@i((0Yn24Y%MHra;`ezP+Lso8IGtI~^N+2{{4*{2BKsFNiG^-(?5oJH^jo3! z_7dTDeAb*@&$vpmwH(omjZ1BhlF!WMO%qmAkPzGI>!J{e_2)U5XkzhbSiXYWn+Foe%*kRuiK~nR>ewJD}44}?*IDd z&w`3uJwIfKWUX`)V<~k~w4KR%?ReX@n}XV6&$R5c%LPmuxo%hMc_@~WeyLFwWjh>` zXxbKKEYwvse-X#9nU-|_$msAN0&!7!4af2&!KWlnC?--Q4WrT%vQOpa%eiTlKQnO0 z-&VaHNPKnYv-Q9bxuDgq#~qhj=F7_IjCtkCR+W)jW>kT~djF-`0havlsz+v> ztvw^3_QoY;=AMc_8g?oX4UwQ499oCx_x1ESct!m4QV+tZ8Rt{D3lEn)+iPP%QkJ=* z;C-gvcxPK^XiTjxAW0E#x4z^=p?0e6jemAxuXGu=mT|hBr+XS9Ge>;l>g3d|BTcs1O1z){6y~jF!A{fidj86q z04;8#F|$=faf-Q@OVa_pgt5?b`GJdDPwC9&u|E~0ET<5EQ1*ec@AXf|p57r?OYeO0 zX_nA=bDNc!GZdYL%%dXXLRK6u4_`Pp8lZTb?*1}6dZ6;95>V%iG3?a9;sh^ z>!h^>>@M{i3VRkhuJldm+UaQzvv#uip?F)^spg~rtHV*_uKM$?wrVs|IFKD5OZT)kQ9aw~f6ntLub|7fd@O6seHb8Nw6{TO838@*uZ`s!Uj z%LB8b);VWotqb2+)OR>m!c4qZnd@!YqZ2M~4r!~ZX}zD@G*?}CH2H|4UuI9Z9W`x zpNX|D5xJ{hE_IzNyG1MJcU-|n;NXekT^QL@t8*^IXjIam7L12u=+`Wk!wumy3pX_T zdhOM55pAe$R;p>Aty5s=+ZGk{}vQZS!~@ zO6`w-?5Hi0_W)d>_HYjVqSv#*;m-$S9>~4fT3Md>dD9MojL#pUP56Sc#)lW&Ezj08 za^j)5^Vf<;ujEmedyuBz3~P^!CdqsK%d*`qc@Z7uqg9uPJLlp%x|{C)?aUm-ZQl_r zf8TUvh4s$WUq*yisQE>Yxt@w|y}hi?^K0M1+l`r{gk7}<1j{=e_TF%4P8Y7Vh+4&C z8J}MwqwhjB&$O8Dwm?&RzL-U@+f~~)e?KU<%#(Z2yZrq(j)mH$vo8g%*If18ulCE{ z83)LjN&ecwpe)X3g*~+YlJS_TtK-t}YR`%lz4p3Zm=>}u%oPgC{oY^uX~5ArcyDRa z+Qy2lsX921HF8Uy&WdT1Cs>3y$2`k^lG#+xVQu7htF4-2L1EN9SSjS@h zi|W0+dliAVtGaA|b5rAk!nQa0qR!4$m-{7!HwDLBB$#2FQ(tt(oa4Lgs0jo!_zmTc zhr0)I1Ir%&)65lbJI)&ra8)4d-n-c9Hv4%d!`vBRw+e_s;$EL9s^u z!}fvT;GdUfZ>zOmDwU|O3DfSjcd#zO>5F3X z_st4(vC-BxryhLtd+azD@2;(#{BW|EKAM$3H0pK-evmx;Ao=jzuz^nlb-x^o3TjCw z4yT2DzPV|1N!=BHQ2{6W;3qsL$2oadeB37tAKlei?Jbbav*vg0z*+B8iJf7CXQk2E zStLira}GO=-Lf#3H|rE6_?~xcC>{vUB0ZmZZXxX7OOCKKhGz{sR1FAud>#pF&oW(r zb2}^etNyoDC8(G2bakP$qPKeo2hR2%y5DBq@vu%|U#mqKA%_1x&yq-IpU3B}Y7uyr ztiP#2x}dNR9X1PseA9Bm$34$HXim-6k!o70utUYmsU837qOo!NUazQ+IX{yK2X?sL zu*_dceB<`+WLR*wn9;|KXPaD9U+wOl*?a!l*)KZZJR;&2QJ-e+KG*y70+p0k(=&=M z(7WpGA$YeY!tsxzh`$o~(<#E0!Bd>U4^#!Z+b%xU&-#6P?z#GmtIs{Z{+hcZUE_BC z@8QBM;R8tuO}=#b>pYkORZ-dPxYg?mN=|&wL2~^J%y}u?@Im2(xGyNQYx9%ab`L9liv5m8z-TUL^ z0acwo=Z|ghKmM#Cy!fTJ25+s+s+=f=r%$T;epzf5tt@<9d@P}V!}5)KYdLdvY2u@u zYoDI`8TZRVH2!?9y9PeGOSj)K_}W0L?8crNEBVKqF+1E(2rL~M9Q~zD(m$A_Rr+na zuY-gSSW{u9-L?E^?J5y|Zq6)y_psrxX!DxH97&^|F@x-;?tuA9-HA`Xgp8cge396& zM%cAn$R|vc@bQ(?Jd#!QlN;7X7cGqa$Au{D`lSZfKG5osJ#7J(n@lF z($g>3M+T)gH$IYRdzoEZg`ePimf*WSDaXpakm97*@eJ1?UQqgr;+L8DozrI5r%}DN z9~*9;k0%`QG3|Eqsdc{O#s9FgZW*Z{$!GIuPsVQjj`bp13-cv#6Zfp#zo|Bksyti$ zaeu?k(HU|z9bs!7mNOQYW}%X9tHdFGX`q*J$XO@RP&1WZk(1uY7j?zR%z93{T90+c(#G zEk8)|(72)y!gV>@-e@`f^NL;Y`4v)D@cHZr_IP;cdAS=3pY^*Xb;MisDe`-ru6IIC@oeYMk{7&GG~ey~kgiMhuT7J!;+i zX8bj&kIQTH@0lovdU0x4=wo} z-}7_3MYBPG;9w@cX8(?01!8#DrF~MIJW6M-iI?mjzn-&Wk(!c?{k)f+H8q*&PksKxYO%E<>7Hv&4iv3-9DTpBn;0C$ z?RYoUoaCW)Md3nw=kIxft@?XYPw~GI(XjYZb*Jcev2AufUsJ?+IN}wxQvxsl`t@t~ z*lE$0quw=K>YiD$NgM7jbf_A4GP{%bbkXy%|HcJ%dGX0zHThGHdePWZHZG%a|8lS3xDQ{mE&i-}0sg zL)90Ic#iF(@Vn{~X8Oy!h0BB+ z17^i-pYRe3`E4g*TeH(?7k@~zc>RGh4;H@US-q!gi=OgRZilyC_R*R_K+NtLu4hxU>9t za7d=pu+q^Rj)fmd^TtZmw#GlJvXSN)a4Ph^+wz{HFGLbuReKb{0;M%jYpW*c4>Ry&xIDSxF;@_S)zu)Bv-!|jRq ztZeyX{x^MGsGsh_lFIPgw4%RmO==3PM$byvz?_CIekA2V?yaBf3SSt8+%{53Y~(jO ze__^2Si*-0nm=X*#AWMu@IH5y9X#%1MTm*D)?B3FPD!GeCY5}A{qDn zqmET&yE&vjpK>*b=xV>Jku*1URfZp@hV_xU7tfDmMri>?t?;tE7G44TpQ9>W4l4?U zYZIeZ=^9zjl>aP4x=`bz7^-}8ETpVRDZ{gUmy)qtvC6t`;Ty^eAkf%jpma_9B_Str z-SYMj-cJiaJITt>F>%P1*w6#*nz|Vh#p zpIYR$8O|mbxJ1tKo-7a({Vrgy(RNny$beahGx6qJ{&JC~qFKU@TFu`@iC?ogoJGev zwUoD>EV;kFGD~Cy&d@4t!K`I|A#-YGzj)oW?wC2Ouu{HR>$ikD$K-n84{g3ERpDOf zD>eSjyLkWa8G30)Ol&y*+Rm zH#EDEBTXo%@qJ@nNM>#^&*h28ih)s^OL2qa{;yZZ{oyqK+9cH&GB%p}*5R3R$D^^9 zU>})*iXZQigai!FFKGDn^&dYwYK*_*q2b!Z?+;zRN|*YSCWyQ>P}#DYPrXLy{H??S z!X+2CWpX=4b_e7WUfYy^OiAZSU*D1C<>W4==4>xl2`A z{z1~w6MLNO@cv|b8F$e@?MJ7jL)U7Sbu~pqfc9FXZT8EETGe?c)yLR;wT*GxNxt`K zY4?kGiU~3PJ?+hVO17VZILVUXQu50_g~4}&hvGVpola2}$(4S8HqW6-v*z6pr~NUD z-PHSYWGeLXtPBHRY04F>Xmqc)c&&z4_l(u@HOWygDSCc;q!91-NGxlKkbHXB2Rp$^ zhm4Lcdkd``#rBp4UXQg)72du!+#_yQYxVjcPRs35!aril;06t4DJsh9JhGG zV4aujg<~6DtgZs@d42_TS=nlNjb%IR^mC2d%k0-&G5?NtN_ktq-)eYnC~@Ama4_^Z zwC5YBlxmIVbUQf8woh10mu4qoW}Yl1M(cs)S7vmhPfS9&->H#F1W0f zj9h5p>-Y4Exe(sT^@vXMK^F)}{fT<=CB)a0&?)}dzOeLMM=SA8n1t{$Y$|`N)y7+d zq^Ui4creiN#2J;HKl!_M7I4aBoj-UwVNddc;Cm7R=amk%WCU59@>4t6zZPd{^oMIF zhshI-yE;C6F=V5(`jpZ`K|VTFvbBah6*;k{VPRn3nSftl&@?5s2D#;ylxWTHZyS`_~$)=iZYjoFRmrW zvSerVT`hl`zC|o!ri1C;?ce|M#ol^1e=?IfuzvrqBp$73$N+eQxs|m%_If+*1=4Y7 zN=HR&|79|VG$HMozSB-udrgl6(ioYs3N#QBfER%ZbP`ll4sBq+9|nP14;mRW&=mj6 zWDbPdXb3bu%0Xf;P(~4Zfzry@3t9pY-h+~-=m~?093C;AVDQkNXqiiR!5A4Mxx+ri z7@0vuPN1h2;mwSZ8C2w`3ybz$3@UO0#yW+@VNj71pp>8f9>&NFDslqkj_H45jLe`S zhq5L5pD^APG$4bDoWP(WN6eqJk29#q2@EQ70wjRxe`1Wxpdu$QsK^l!3++7&DslqU z=Fy)pMrKfv6R>7!1OrOF=W#JKc7F{A;FJ@hAx zk+CK;^j!=pasq>joWP(WM^qZLPcf*-30T(*_9@25kWi+-hcPnN0D<1apdu$g8w%|` z3@UO0Fh$XyFr)#^V)Q4Bkr`CvhzF1UCx$c_ROF1i7h%;fq`{yfCorhU5z#H};|wZt zL_|Y>!WfxBMNVW;ks}^j>^+RsHi1ab#KQ|ZW+IlYhhIu$P>~a{0u1a4ePklzIshW$ zIshWJ$I*Le8yUTzOM^(?ga0R6j=qkOEuUr~A)<0Z3|JIAP|-o*Gf?AWG+j`A3{~XJ zH!Dr9G^VKuR$&2o85PRIDbV4MYG@I03l%g79VXLd9aF(V%ZF81c<6J1*~OaXp?efD z4j>{wI!xwaO)eM$-YV8%Ax<@VYd+XT+bPxC%R5SVaXesGz*Do_W}@cqo>m!0x8QWLj8L6b!M&M+{R)2Gx!A%)x ziM7mwK?S^K(D@0l5dQ#`Fb!CfNM*nhVPkQ@Rz&xEf2YwQP2fjD>&Q867R)6$x9 zaj~Q35iT$dvBrL|a}Z$>5XdrcGL360aUpY#)mg-$elvP&KVmKd4M7HDn+}s{SW}6M zEoNfq{iJ{m3jDgzA`8bN^nOynQBVQmLmZCzmQ?cO;$F-TVpUwgF@S?(Pz4MwM6m`O zkr-^>*y1Gy ziw51tMS^Z(?9LPT7Y924x-3DTF)u926w+eDl!u-Hu#usW9<{fC2LlE;^opZKdZaj} zA+1S`T{Q2R#Yu#kbEvV0UT`Rh#(^IVp#kVG0qG%D3nKG&;8Y8q9aA1W4Ae9TL`A@_ z28R!L7$oqNNzf7ijN#0$t;t6<7Fl3XTClFb4@1P|bjCcy9tP@x1nn>2X)q0IQY#}Z z%)u%uXx6}iT|)w9TQYd15FY}|0p=9^AMl5mMm5zOvZLdnJ(da<2nmN+T#(TWx)o7c zAUBP~ys+?-rNs^{F|=O+Ckf&y2iF4Z83@P$EJUXc&sC?f;wP&uEFi_|BtoYR5zH+b zgA!Wtun_?sYA%K*7^WwYGKI8IaD`P^s$gzG1P8GVK(Gnc7H~9xg9ZfC(B{wlBu=5^ zv0xpmuplsk;y{R;3kAI3sz8i28PStKb1~D>B2U&2Sm=;dSkO_4f=F-|1l$k<4g!z{(*aTUv$rB|jA`Hk3TXtif1X3e_R;40_3l!~ArLrY0HcWZAs}Nv8Ln<`fkia&Dn;;?D1xp@9yGYDSi#++H z#zM}lt}Wp4Qw23jfUYGHm|1YwBgBzFe}VZ$rcOgzlNikqfg9@z0@fA|)F(unK`|iP z6fQP^Jp?ggAW2|eT9nBaGh3|0h(;ZJdv$}Q!y+sK@KzxDZKNhp&ol&C zFqUwn&4}#T4{Q+=qef3q?ZECyfLs@f=Tabt0u9uN?UQL?O?G;)^cIVcL0oTOnv#&k3<(tq1OUN;W**k$%qBaW#BdoV=uyZ&!Odh8I8#aB z_E6!-2hu}`3{FE@Q@~=wfG5G(r;0KaU|pf)AqlK4)Sga;2%xGed(vVf6puW65?EPe zbTb)pp^>vl%L~I5Tx`uD8~Pp1A`99q z{SIy_BL9Wh45$f^7K&!Uzi?j+I6G`fi!DxKa34@`4JBG3jtuc+Nbo>@8X$qxm_MUQ zlMOAbT#-cuf$r=;mr|faDDYgh4S1LX)^$8s>~Lc|mTE=!wZk%p z6e}nU@LZX<-^o*eLZyo=$_mMb0s#<|XjMVhA510M03`6Pr*lKo6t)99gv7}Dqr$#J ziB^arW7Z!9v=|A@Ey^_3`(%p-t8ryfScn@IU3E+X69$6FkP!g)8S*Mnx`Hl}Vp?fU zc6VU4vOa|4=`gJsrbuOC#q_Mgf)E1=VG-e=#zE)-`H5J18r4uvLs(NREOz2Ea1K+!QbxCB zVCx*r1$3ndb`KGSd0|ZvP{#TUSQZwfqY>#ngo*Ird?6))s_qbhIV4?~p2I1UU=Xik zeZiyD1o%rtw9--83LHXUU_l-j0^elj51lD|L#zjbMQI_O1wJz*RN)pkbPok6Eix)~ z0Mm3D`*12@v1Py0)B$v!fQO2L4yfK0p+uJIG=w$T3B%e`SQHj=QK=|52iY$oRuKh3 zEr{Vlo`-o%lNBkgQ-)xnoUT`fs8;_=wt>PivV6M1W1^c)#TMq>u6#T z6%pJ)3aE9chX?PJcBKLZ6f1Pj!R05+o5_=mELwXNi>OfeoeU{3=p%%9H`wqf*#wCT z$OypYcheBoBr}=T?8PE1bOQ{eav&28>l@t+1Fk+|Q-$_Pbowwqhf}~}L%k#3S`_C- zxiAQg(ym}Zg?5O%S!Eih&J?iNh|drqSpkthJlHQ3=*B|13KUTWTLuhf=8x#9wjn#} z9a`tmMOJupD+Uz2fOn5wWQFQgAbP~~98L~q(Ru_~Tv|xIqq;iO*@yD=B-Fx#^7vpu zLy(IdSXjp*tFTa51`a>e^g%_|9~h}v*S-llcmGk(wX`Li*d0$;venmPV#R2cd{P#OH$WXNwZ&7W-^(@s8nxcP4H z(?L$5xO~oUhJ6_(aUIRZroZD`{Ob>rY@Ymj9jl_Q{`WA^bCIAn!Cc_UzToon4}X2* zAb4_Y_Gu_v*XQ7(T>QP(uKmfjl83I!heOv*eA#%tq~npTN9Eg+b;UpPEC-ZAoqKDZ zbPaWVytw;WvHSkZ6_=~@Pzx8~mO^#Y)lEgFqEmR(C56Nunn8;n|tnXNx z8I}2X8P9!dM;}|xwmL1AGmJI+ zBp~0S*xPe!39iW~W=DulupMW*cx!O(irE2WcZ@#Bwj8=HXs;Y5HI%39*QRJR68QGO zI)lLNA68`Fw$oJYK04FDBrY^nY186{C2FM!6)sY{@KTb=qa!Zqzc=;|hOepSjd0Vd z?AwC7)qo4R^5W81TU!TT4$q-B>JP<~7^~CuStDFd`-1KUz9suQ`1J*G3Y<#exV`&i z^qxIqUl!=(@}1=Ke(4ya+xh(ve*ro8q$_vEC;PrljcaXre|_tS-QM?YpJ`E9%MA~n zh_mtwErjtY^D}z;Be5eqi0P-r&k?kAgq-vCiqsgE$)&sm)w| zE7xd+s?0ylo@JZJL$j~!Nm=`7)2%=mPkWb**$NJtqV0D1UFPL|S-6_{_2B}wDe@N0 z`MFm!@^6|tW-h2ONzD9sr($Vy=xKa9zU_6X(7QK(&Bk=rDjaT9%UT$xkZx3anP@9jL(RYKpTzXhS z^q`H=DOjf!q#b4rPm zye)REyVRTJK)Ktka~lnQH_lwW^}^PT+3trmRr4PAi8cRxu}>xCB&@q%j|wZ2 z-p}$C-_R{*;MA!pBY1##C1JG^rh%jMwdHJKzRC7Z>GXUK+gL`6p+8AfHiP**=xUIdGXiJymb!`kAH}Zwq5u4kEOL4kyLnJw8Wrk_M4L~&UHroSB@UcKkj-z*V^9O zqHgvXJ$rmx%BP|w?wz$y<-3*MHi{p}-D8m&{o}jI+%vE{;$wqcEiRY|1dYGqb2i<( z@?6A43+?LM73YXvQIZC@4a)OPFIqef?|H=A{^`5D6De@#3eEYt? zW7e%5*SkKYCF5Wk7wo;(FJo5t_dx!)fe$O3|1MP9%oBU5LAQIWwg=~h0l!sF)XZrYu@^6gDn)aot8 z4+9Pqwh$Up?OyfX+=~CT)WU?2GQa;@Zj{FQ(vvATs|~g=TKzKN)th)z3*~?-?-^{Y zg-eHi1+^IV+0VJ#)DWA$(|W5)t^~KWr(S^FtZRPuJPG_Ko@xjvwj~>Un|WpKdQnTU zjHtk+8%bd^9WLh<#-W8OFC3KYE-|K1Zfvqn`joV%{Y->|COE##>pZVP9kZYX! zudi8n?^(Au_yp{i*YEYYfIC~O9#mP>hEMw9>vG{+Kc}u$7B01PT?T({Kyk~xYLmrZ zzskjaQPf*n)^*zjmSOWLzpl<4Tn+YM=K_w|`&tu>IN&#Moj&8Pu|B-GrJsvq_;%uM z!8jiQMayJ^(1LaYKRzu-yFshP8Rvaq6LL`EXP)0+5SCgXbJf(7Lng_GBX;bNm-^~M z)jO&#tHiDxO%PCwj5nwoNyt3=$=Wr)k0c8}^G&ahqxVv3hTEi)U;F#aTf479 z>3O=q1DSokHu|d?4n4SkH}GYOZd!+{svw*LA3odhH+ag34$ZL|`ucWTPJ`0PpFih) zoMVG+fz_8gE)VikUD zVD!Mr#n93gdG_oFR@^Y@a{D!CO5yG zaeG)7ajV7E_SUg8TQ7`$Xgz&<+sa*iZ_;lJ6oQf&hy*3mbhxc7eBHIyzxElUg1ci| zr3!l7lG6$!M7sKG*YfqtJ&4MFyv*%BZr}MA?;1s%+aCDsmavb|6`m`h`qeP){s7U- zl1KgJKO$AazjkRy=BA#Lv6E5dz{3SH7adbx*r-`{N9mfyMXE<}SLYow($l8>jll+j0sU6a+>m z215rNif-(1w&y-bG{xcpQsn&zMGs}(3~z-bYI1LnUc9_ z*i*ji867;$UfvfibWGlzbsF(Z)OGr5y5Y+uwKu0_+#T9CX1g5PqUyCnn`6swkXas* zS^g9Go350uPd_sQj@BJd^2mOm>hS!chcq14_r9NM>fdf<_W6Do_eC2Wi+5+Qk38x$ zmKhjzwUv52Q_nBGx60~@Qb(DbW`Sn&h~?nThxboZEz}}kaVi(A;?KIV!2E)9D|}HF z`l8c&WP&YxEGn0OR+CXbTN|bzv?A=Y*o!C``OVcby4M;_N8`q{d5Cz zks27C5wtzjXp!^Vrr`T`%l74Xio=1e;O&v z-Rg7Bdu#L5GX8gZo%Nr}_RE?2ZfV+IXKk1rxq3?(zkkgL*Njq!c#AuGw`qs(tH(|5F#Gdk(Lf+Uo7zTH4iW%g+(F+1XVRGn9Ev zFNMQzC@foGPf&Z980dUnr#{*Hf%>uMUOGq{^ek>8N$6Fl6_!Uox6IYqfALC{@Ig7+ zQP{lva-L`F`OpMOF8Ce8K@p#h)W0}#Wc=IHk8clO3Y-&jZ-vHjnJ+DVxL3uAft*H* zF9mSPCX^rB-5lTau^$(EGdJw##J=E*Le9t_jkliFIQ;r_c!oOX{fU~O>reHTNi^nt zIV6RwoDc017ax9|Fc5Q={PO#7%A;NmGi}khV*@YaY~uqK9?*KRBuH0e+0uhroqB8I z&W-Qj`XJWt?&@bz87y$eUdD1x>DgJl?dEM+_6sh0e%zz8A%j=Oarca5x%}<%7p^_> z?K&fDAKMO=Z#dTny|c5LpWHhwcIlUly|!0p*kKp638?;%X&4xnqB~(R z+hZf?~j=kmkZ-0|HO=2@8FwzVn|zMuBjVt{Dqw7;xl~P8dXG( zZ_YVszRb_2XCbjll&@r&`Rr=lbFrykRy*(Ni1_rKfSHvZC(J{lw+G-uY$__})YUCE zs!;s-Zru3bRr#Lp)e>v*+~w*vu3ro8%I|b3{?ud;cT>*Cq`#s+tM$jVZMiS?(xFfX=jnN-?9_}Z3Ffyx?Qpy&+mbU%W&4E0Rjn;YbOHIJx0-I$dMDc4B zJ<2M3w)=N*&nk1}sX_1-T$`xsg4ouL#LZXch$WFC33MxXRF zP(`cTT5&=vZ{^Qyig3^F*RsN)sSm8nDlb(A&D!e~ zXgjw`S7Ie@-r$5lpv`4%v|?vHQBkb1+v0yk_wv~HI>U&wx(h89;jdrtjF@xo+x4!S zx(hcddHHhPUZm!@Js~;oX1&kH_K+RUp~)X&5G=jswWK@uLp1)p3lSxGALNK#UiWmV z1z98Iee^Q-$haVH*ZjoO8&0|_{hn3T{&Ufh19Aa&TOwUo;qA@Am>{Q6X4@ozdFQHj zl4Fr`eM)HR)r}yF{jQ3`OIqt+G=1lnay}_~(B#!Jg!R@H-j~~M>A#lF!%o+?iP_ZV4yS(PtVtiJ?XU^iA*SER}!G~nwLpuC>90>!n7+O7=mzid-NzL0cPugkA z{YGvLhxZFt>@qW3b$#CI29dU>d__9T$6Iq744!h8kc_pzIBOGwZ27 z-6~r_SNEHl4apenckK>(qmg`hUt2}s-KceHer=19!_YwvEzl5(D6q<_@ju4<6z8_G z+Ug2nNu+vBoc6Wr-SzvLLlZ1I=XiOySFTn9`yE{D_jd)mxwP-PyXIRAZ#en+)DoiH z@3!g=qb09iw|uzlx-g%pcDr)f@z4zHjG;sx9}%djteJ>@PlfevaPCUBy8n zHMa$0x}9JF1RR$;%;8}dQF6C=@x8y6vg<%=y?i_;+Fnv(Y1A9;c28dI?w77U=(EC3 zdaHg8Xf7GH-1Fr90a4jFwW8o_7M9-6xcz%K#&JfpL@CLDL$}^O?5vQqx zi{-T2`+4q<^arfGY@=iL?rg}&>O#+1mMfCRz=PN)d3K?zrGehzz|A0FFlx;<2NF6ZWH$JG*uQX`Q+`7D^X4&#QViVY6m_Vb5K2g?tUb!pz_4%5kYT)_>m5AN3hu@2KKG+HXV# zs+W;Tvv>T7O_l!f`2B`n;iqeke|3}aQa6yh-}zJBV0&U&F~^4M54M?edu9!ny^*=s zb+OE~K$K{44wQsyMLB8LVg4AR^GU0|&-`ygdj#^F$J%?}sw|$#dL3FXm{pFb)kx-YA#epLt97uyIiT+!}jLGm)l}hqepxDHl}5^L~_y+lo0im1w*# zj6HOQV{u8q(6-*rg?nRXNEY;P#P?dv?^MZ_;4oVl#}OZH$+_rI~9j3Yu}jB1iGm?k5#-&0|tmw%H{6MN7TjV|`q7&r6T zda76C`!^@YSL3d35P)@QnV-+q?uw7KKUTS{PD94O_uZ;3YmbyF=lnbzJAMcbV9Q+! zHtF(S?es{5@hYN_(pw2>Xyf*0@nT8Y8vAjAV#!oXx^HWULDdsebtK#(pvcV0|P~j z7Cz8u_iF2wXw}X1%6nRL*-g$d@2OVadhd>PYXg6ux0cO|S}iEWt)1;2p!v*i^IR!! zpFr3AgDd%wBA+E_^f}dQ>E6&|(e1>~?V{W$UZJiP)OEJ1P_~;)bPi~@R$g=>BizNj zJoxNeez-8>s+y@-hLr&NH22xdy8EASi&k$mP%{SoYUsl zwsyj~YcNRs@uD8xEufb9jb!e<*i^B=Vc;@%>{r1(?Qe?qSZv6NupFAHAePKu_qkj2 z<@|Wg;KV!RH?kX*cKe1utR2*M_GkQs^j;``d-XmyT3MUV5NR|s}M=zxJmsv zN8eY&-1pD)o32^u@Qq-m*T3m;ME6?FW!-aH^sGADzGY;a@eT_t6(;J;QF_~PbHaSq zT|p6u?%47BjBS&8-7In7=#@LE?}W1m(iY@(DHp`e--RTV;bP9uM3ctDD}QVFKtPKK zS8EGmV#_Ph$dGgCGE4UPN@^`q2D7}7ft8m9c794?^S4G#}SDzH$dtmYQ z#Th1d1Z0zRokDlSH{zqq`S`{>3W$%I66RYT6c;Z|5~#hsg{Q0_?%t12e5Pg>omUJj z-6@#mk@+-5(QK`2t78CPe{RA?Vs?C3>eu(=d%hwP3OM&Ih95&K3cPoWMQ^ix*L^!I zx@4leTX~h}w^-k}lGKv?pA&!ojC@ah`|fXA1$l7K_|TEVKgUPh{zU%$VXArL&&U?* z!+(B#@EZU7_sLEvDZ$>sm#OOx|JrtYjoE^nu3EjMdHKm-qEq^6SNdE{A(yJ_)Rg4m z&3BnE)g!uG{#>e3-bpFkBhMEy&-PyXwVuCH9lR$GP9~s+3abB=TAG@GnwEb0F99_X z3jH8~#jVUb0X2|zU^y@-)xgNCQOyQ}gBRnH+>V|wm~t7M(nO4*5c?BCj=ezHG3*7( z_G2#?BQrRqfwzSICkCf95Uwzupz1>ODX7(@zhI0E*--iu#>kM_rafVBN<&!;;|ZOS z7^qtqPZ%RJIHieD@+R?24*PqpnZzLDGhfjGoCOoGdQJ*3{GjN_G7$HbX(ECXL6V?`i#$j+u6S3ld>zBQrRqiCBd&`V)gw8b}%F-v#v*G(1?XC-xo&W~`nOd&0ns745+j zC|ag{3QDXQFX(bc^(5GUBnGE6>hGjKp^uEJDCke1_1v zQ*lbu_8KE&Jxxw&xcnTkdi>ksOn~B0#8^J<7UxN2(6pV;A}myw1Ks=owm75mA;fb( z?H1=LU?J(U3=7qaLw_v2#Tju#0JrD#Tb!qWh31-NSkUYVn}E^cj4?ujrkZw(^Axbq znr0OiqR)hl%xH1O=ra*PG2&pHMwiRv5_=+B47<=|qXMT98EAG?fqWK-TA`L5+CG7< z0Z3Yzu7#P*=tMieSd|tc7XVaHKcotp7OHZfnh;PS>ey*Cx=ik$BCfW(OtQ2qi!LvAP^6l7(Cq%;)hnRgc~B!9^%+z+)b4?vUvO@SZq z8KM%80UQrNxgp3i$Tr-0Pi4NQQqsc0+43NRNx1>g}h*Xazh*g5R@3C8tx{0ZyOGk7vu}?`5grB-zG;hnB71v z1;87ScnrX?AekHxb?v;fwjn+@Y>2&f7FgB+^57T3nH%C|01D2o5zhZ6n};Z?_TE_# zO&?gzw*b!EfK3oU!FLaE-o9X=%&Wb27Q`V9I)@Ju2SSoSxND&OLEO@UyPz-o+lsZ1 z<((UV-uO3}4+OwI0o8o~;8=iX1UvW6*U{|^w!A3IbI+XxU-06Q4Yd;D+G_irE%m>sNA+XXz6CO--6zExa7v$-G6Kg*T zJhUkT^$KDj5du>TBJP9y3lOz5VD;SjTDmPk8vx$-F|~lz1u5>pxJNAu5PzT$P@N%a zX+S=@W3m3$TadxN*B22i4+3EEggBa^)eBWb2Y9p~YH3i5WyfM|2T`FsOM8_Hz=0sl z1}}iYaX~r_0H8t862K?}fmC-a)ppb;#818V&H^(XqSOFhGoZi&oc zKyV261hJDsvDh4+sfxphCOo ztL@72en@p8Do8Hi3gH2;H;57(BGVOy@Wc=k@h+%-|031C*7pspAmB;|)ThuU4G@h$ zC@{YOtJA*b)jpPYfFJ_q4FuH%Y_%x3Cot;4NP@ROU^mqF+gGgpaOy(!3Lr{Kh@Bbe zpj~AHN60N%g%+`?w;8X zr7lzn16s`?u4XWuz;?|AE(bYj0Kv?@gxc5I4kkI6RuKOws%jgAL>q{a*J?!2$~ zwlD7cV$_8odBBAXseA%}k_JVC4^Z@*y4KEnYx_>PFG^jA8xQ3y5(G{Hh$R+^l0j~G zpb+j{sK4~pezbRh)&;&80FMQjX2?ehh7i)00dEr5E?6`FqK@v1PMsD&nL(>UzM(&!YdHW)Y3ij@G z03q@@VOmI!0b12o0l8iBG=nh9Ha`~F#P-}%AkYdpWI!Bli>MhQ=mRS0ZljogF>+90 z@ICewYxystW{9Ezgs*oS#r%s{`{L6DnheCDwiU&MxG5p(zTFZv|4poYDDFVj z1I`Z+YT6`fhKPX#fo`}#9#ry{kxB1ZeOy1zP9%% z50)xaE!-`tX0W0Pg1r!`jk}9YXM05x$Z5W3sUV9KBHe+am;w-867c>(MSOM}#oWG- zf|YOYQh^Ox0AeNw<_%O=5+uTa-ymGL%OK`of=#G2m%Yv`pteBesszC51vWpFqX=UE zfP$JlyYOTECFF}ry4j;xe82^R;)De%AgHH`V$>A``w$e>1dfp%Z-#$~kE2q6_9_+_ zET}d$U~Go!6rdc*5JwRd)dViLeTlUX{T*^bf@((~7zdRU0-j~iOTgMe1vUXi_|C=J zu9NPIQ5R6P@B>E!KUAp=%m#=O52{TFMK%G;=#ItuOR!=;jJhb&MWB8F+YrPIL2p4^ zbP$O&2yKEozB?A{FZ@@i)UiFzEokfE18*Wf#GVesgSH+JB0z;U`FBx?>2G4~XN?D5 zB1k(1;Z#6{2YL(e9D>!E9}wSwmvLX6wU0HP4=7hChF`#g1Sqe+%xSv$oqisD#5k&MYV@Cj_=-KB(3a z#8L!uF@!*Z9~9aY+=VmiFaDYRu5FGPmocsC44JiUpjtP^f+@kO`F#0rjeO9mxFKAnt2{hg6tfaZG6JK>qEno3d0esp-Ks2*72c{d}O(3FB0ZFd{V+`b)dzyiE|j^QXLJMBvDeN5GYaaf%}6H1?}@4wy30`J-=x~d0uPbNLp-HW;aRA{ z1H^gH1HAfBXcN?C-|^zGJ*j&G@v_Ixf|&RL9%Um~2;M%Z{t?u9z?TF{v+r1{?fVXt z!?b6+0@Cw@pg`|tC=+t(f||j*4`yyN@HfCfd+aPo;o}0iE3i#$sya<9A zqBlzNX?_BYeGBz*X9_F7zqEfDr&W@5HU9*UvV@sGZw_C=#U~wX{nlqv*3f#aWm+Qz ze+nNIze;wKf=l6Te!8c-Z!%{7_)Ix(@#OsEtAOz+h2sa#%5u0+-*}R82G*q}Vob&y zx2SFZ^JND;Me!k_Y9{#9_qXVw##xeSgOU^r>(n9F?Q~DDnwV=Rl&zE1HXb&*)Z?drd@WzMHsco zAfxJou2icStxLiFk59&AkA8G?jnLwz5<7AzoXId*nPfF?%zjctT`+pwC5k^<`{`@T z=8L-11l?@Qn=oqQ`O4@%*H9S;lm|u!7}-6F1r%`L#sI;;&7eF~ z!yKer?LH{K&Djq^Kfj3u?Is&9#twFqjW=QIiT;o5CQwc~s?+dwL9zU3 zy&9XLivRo`#cr`BXd)+|ZwLZ~QH2TY>||j*fP&)^KwtCp#dawfR2> zOzfQgIpBz}u>A8B)R8~Vv9zT=_Uj8I+y!p?s|AOo|JAZZ{B|RI zAeNmO%+wAVT5C8G2}4>NBQ0STj&NfqxFZbdWb6pDH+FPF7+afx2?09;lY&XZWMHx| zIoMg4JWK(m2s;N;f}Mvc!!E#7V5%@Rm^w@YrU}!6X~QnUbYPcY=GMkeFk53MXGdde z7}C<%(H`8z+0g`UZRd*mWNc#R0*6^6O&t;Tp#NYdFjJTr3=T7gS->n|2-szq70eoD z1G9zM!R%oUFd!Gq3FZuQfw{umVD7LhFf%(RNP5K9hs!WmI0Ej7baFHX&*TC(b+U7W zIU(TC^Z**1FpSgI&dCgJ4w+jpq`k2zd{5IGf^PnEDM8-ipd*tT- z0|B$4a)OOTm=_43*^hczB1)T}hrwJEV`94H2bPpY_6 zKl{cKTS_bAOL_n|RaB-*nvKV=JKCQAIk}xJmk*kvtStFWj9HZ`DQq^&b7wGTd?c|{ zpR%#>9SPRVrltMJA|AnmJ~qm>COl{Lv3qXBbEV7T+R7v{PGc3jj57$M=H64j?k*e+z;qqMyN~; zRTx{nD88q65|3D(c_=+<`J5rGEaRI#iekPq%2F7ZUvL>7fBPW6*sI4Sqw?J8il8^C zyb2v5$vIkk^B3=rZD zDf3HXvB>$elF%BhR^EMd>)MCq2wV;HkGz(Lu+=Yo$RjK{-0Gk6%1_AG#N?$(2|D^2 z+!#`SgPS$x*UgwDxiQ($G`=2hMI2Ke4M)4m!z$@V5>xNtY>M^*^Nm^bR}XKjuLJc( z=@;ydtc>NkdwjWRWq>{}-ZeTN>p%D@WQaO`$W}c=MVW|* zKK(?jcp>34+&1RJ_c8EUZ*%H>eR9>*t0(N{2hCJLHj7iS9b{f*YnM&sZ0_UOOfwTU zbjhs!;QBh+3{W*jg}t%+;crKE)(Uo#b`RKUuoge zGabpI$6ERlduCi-)4*!@;S(QQWMMzo6Ke~H3`Ur86z;Fw9q7NMUw1cWA@2>9j#>-b z*OsGt8fAJ^mo4o?`u*ENb=@5sN3?2n#7k2gn&VR8PafvhXI{Fu7VmM@!t9Qhg>&`O zegS90tO4&r{`11E+F~9*N9CTm-OvnfyICQ8XCPFOC?11ymtP28S}&pFD`MRsA>~8a{hDJgh}};6{tEn4zrW$@h;6?Itbp zH7)HHZmETryJ-xy4_py@Q=e;?ZlI#39@h}o|2=X}y#lYPVy>mY^u{xBk!vTKKj#;J z8M1h-lM5eyhSx&M&VW!_2u$?yfj=OgyAiNV&>G8#RpLj#RIfX7LRj-)x30KI=&Ybe zy^@8v4qv2RYqo*|MW5Q$^+)Q~Kk~J8Q~KaV0&lI}t5)B&`o@^SUgKZ-c79Dczw;z_|TaQdItwc5S);h=Q z*qImw0{hAW?Wd61>UuY+m9bN?JVW5b2SjkzG~X}3e)Z_M#GSFQ&~?%J{?2?VVPs*d z6}^=bsq_L>9x~K$O01Q0^hq1m-Q!1}Yw?RUI8q`{6FsNuo4ZlS{^lO9&*Aj!k#p=P z#Eah-Uf6@e|dj zpO=!)buV%aTdml**Ky(mk88PfIlaZBf@POqR3fU0Eg3JfSuHqNi<%_biu^Ti#~TedJUx zyna=v)KG8u=WVV<3n!T_mA924D|Z#Xy-TU!yyyC)z2+O@{1DrhnitF?rnc3!ikv?# z*5M)giu5`9++4q>c%FZG0j`zk>$I-o`Kn=6*Q)D5V~l>&`clnVx7dbJWTe>DhqE27 zX#(US1a3Fh-j#Aae)L^MUn$_TqkGzmcaOc|=T@6=;-hV!^b9muP+5<))-skoNj+NL z%_>u{kaW$erLXPG3LA;YolHu~qI4+_)y#8beKVS`F{01lG-Hjamr~jm8V2e|zqOuv zx?=Wh>iNl};kTVRf><5_gaRT?xmu*!UIS5Gg}DogA74(8K5Oi~;pAK}FDp6K(<+Xr zYa`S2@4M7IcCG5o#ptF*LWws&vDTR}{f@BE%ImSw3aG9h&S}l4*=7oZ4fJ;#U_(iU z)OmcEy0eLsyFHv11|0-D=$7gXVip^;ari(T2P%j((0D**BG^@pw;EuJ)kc^(St6lx zQ640Gn3ORRj3>i%Fi`5jb)fG~0iXQFm6eTcz$5(YmI_YB)(F!xklG4P1!t-| z!ELkv9T7h4;^yT*jBVorQc`wqw7RDN&&nwfoB=*O;LsD~=K@YVIcsAJBrPNa=mB-O z6D`Yzin*y=vTppn90J^AQ&0K*p*DL4JQTjJAjml2qJ{qbW!-Q?2~_{sjQ?mhP)EaU zEu1X>7n%*PFl)4)+{oyty9`1d~lONa$;|Gs$GAz70?^{pg zsd7DoD}(HfX@r(N3$4+8wrE`5lNi3D8j{lP8fUU4Yi{tcsoP_OWLbS}zGYZ2d{<(m zt51BT%k|zDOPV*#Ph>9gjfdZNJQAujhfRF~_KxIOp$1!JOXT&c2<_8xNerSCVwW1}Xnd*j1vF^5rq;PFGQFkCv)XVJY6Op0fBNdZ7) z6EK>B1q2UVS0MIR)R4riBVwUTFs8Jgp6z@5Ot0IJF49l(J=W5VWUp5Lhk-IbU>Hp2 zRbCrYPjeB6q%>qkPDcrz;E*DHKhz^B%y7n!LxaNyJ!n`t?FH;};9DBiR}WNVI76_w zBV@2)16*vECaa119uO)fcvsMO_rbrJkbB%G@_mE#2=kcAHAdLSr-oM2GC~h9OES&a zV$EqOKPKvb$k*vorDKv(;ZEjFKzrpNFPlvH@arLL`80G)vPwlX_QU?HW~9+nVQA7I zwH><(?_klJhZr|8{vduhyU0y_ zz3yRAQ^|`(zGg#MNbRT5-bWI6mki8g4XZG$sA$5jE`|sCFrQr&f5v8N*u!m(wCZij z&(6y5JaAmGH+JUTVBil@{&AnVgZS1@a(MD$_#17+El}k;*Iu> z08*J-wk4E;N(o;CuHG7|RN*U1qK-`?6b?xx;Kz~;qw%0P(n0dsPLZ%|gp#x~SGVzP zinL+2=SNeLvgTI-h90KlI4*`0ienYb9&hK(*Y{(RZTS-sECduiJp zQ6dZx=;A&)3Vnct{z+p`9(Z_7J1Lcwp`V}X?H6U^B+IR;?qg;O4;$= z5mx+U)k=MPlZ$Hh@Ykj5pOj9?*XtX8%b9fQu&DaRu1Fu3FvyIZPq>!D!<#Wc|3rEG z#tNnOty0R4iGk(#IQq&snzLRhh|p=qUXGQoMq$jb8S4{*$;GM9axX>9tvEF+rnhpe zJ;$r}$BF8`lG1#PFJS$XUD6|QPj`p>tq+n#iVIWm8 zK%M>Wii=Jp!H3ehy7{Slj3=@(n6(x|mbs{lb%R^O?p>_nUI-28cWKHAy!eGELs-a= z1j$6tKJT~2@OgdhS>7aK>Bc~qg30@5EeCCemtMIRizU8pC0!WS=wTUD={j~4+c501 zYx7&@dNKQ>^;1`JqRM(5)1?g*u0$N94!GT5Sa52(c;>A%Q*38?cL!(EDF^tn_527y zSt-@6lB5F>!NQU*Q%?t@HG?!)*aepfDf>dd++}92S4nK;t=D5)*QvWaQqcaiZSekb z;-mB&{w{fe%uH1*E&8X_B*+UsW$gMa{8?%@u!JM&uXPBuGZ`u22Yw6hxPwtJ(R5q- zUhC++i;lHorBjnuRIdYxGQZJWXv=B1=47^5%C<5=7TO~^;m4VQ|NbO%&xeU|g4a!X zv;lk$6;5XD%H)-nGC$aF+YttLCJB4|NIf6zyG-Nd_w(TD1zcQ4F24qDR=+xubv))D zcbopE*KB9b`QNM8Y=#2<(Q8yS)D_j_PI$aVFm}kjBV^}%}|Hz zt(}n@S3vy>HDRU*M^kI~Zyz^K*f{*_${WqiOKvvooHqa1)Xv`B(FtZ}54SaOwzh^l z!8U)v9h?y^#z=P?dnY?5geh#JZ4LRDVUBQfYq%TI*#rsB-)evdgPM?Q51b3UhnuS7 zM#J6_ZVESpZ+>NNXAS&`n++tw24M|cm%xYYXy>+dI*`b5^A6xJs`1+$Y@AJhIX+RJ zx2_M{y!1cL;f+rl9$l0R+1Y;MkeQvU?Zzj_H@xx5*3J>QwZT|yG?8}Bo6SujH>5*d z#>@nC*Om(zG=94SX#Kj0iS})|N+B+g_;4p-(Il>m< z%XKMkqtl+>o4UOur=H}mk32I{O2uARq zDdV#7adT8%!1tzB8@=udx#TUuK$|Q(Jv-9j zj}8INjp>hc*qC%k=Z*RQtG(HAX2up4U@mO@g5(1s0Ap}jFf^vt&L&%n2nBKmk-@ zd*^`y6%y@ZWT#&rdrF37QjLHa#RMq0NWY>_KBl5*azGg?{Kt*<%1SZMa@6JGEf zx$9AL;>neu+eYt=7^IO$G;ThUlzHlw1>?jo=OT>%1fv7(%KiFPjECi;~v33o8~QO_a0~ZD4u^B zhqw1P44p$&&Az44*Q!3q&&ZR=))@JpS*naMxXyh*L1&$T%b%JAM~A49C?fT&8u=?@ zyOs#r^Zt<;{#7hTv|A}iF^_1_$*#s$p&>#T8Y2Q3g+)mon#K?l{GdA@^7K`@pqb3k z-0<*Q_XY($v!pL_$i3GqWyHZ4gw3jiu4~RwJb6gLK(B^*#{Fc4!CGoq0)Kohh3`XN zZ#@b$uDBWw48Qm&_E=gPEQa%vyx!)$kCha8sVlIi>q)(x{K*a(JkmoqlZ(1QV2a~& z|HRFcl5zf@JLK?r%?X|vN*KBcnKs2Q(n}tB8!pvC%ZPjE5a*%@w+|EYyb3Q43o$01 zQ~>?U^Be~ewqNyUI?5ikDu~n(nIAb+i+D)c#(3qu0>ZquS2M22kpeW zgQsK*Z#uwM(-tl(4{?5a{B3P)@)7oYZ5@qU<5$md%};!Vw~I;cKAn*1Yja7*D}TXb z*j(?ER6<=c-t8Bcd#@9_TdbB;lX>h#_%bK*f__*Gpu$+Dx`ej1VwXoFm>iahLO61gf-fH?)?1E|1i4Ux&W|7S+2L@BdtT3)n>&J<= z7&WyYX|k;CY8N-Nd*2xOIbSe4XQ)?Ic-|z>Lfg-_aW0j&+{VL*TIh^x8*-(Z)uxDY zrB%kswC8r`2>o0uw{eV4~}ua;79 zEy<&mG3fSL)7m5h3YUxO1L9p>A3aveo{96umx<<$>PSB{P|CjRlEjup4b-_vP-vA3E~xs+VOG@Ee* zt}N%9pC@|sNVHv~kTVmnzTv}hvd+QDR63le3vXuA!pMdSm03!cHS$LT3MB4b@n_`o z)BA9U^ybOx^PJ=(y)x^cnHLTFCFs1>iA;rSy`OaWN}$P!RMTuX)i$b-YVk&s z2#|^Oj|-Xycw&FKpn*N}yAK-5O9UtXW2;H2Ybam11Z*{Roxj*>o0U?2x79WdZ3($) zs{udoj$P1y-tj+dH6h{uw$&gHv@n#{4Jd+X1yOLTzj&axEQ4Q))gNx?jZN@h2HR%R zCcf^5!3NpQ|6lkIV6gu&EFp64?Yp}W@9*AnAwDqF8@}^Dw|5>s;Mm{!_AVNOpkWdo zm%nW+jS$lnRx&Z?s%8DiYHZGkp z1MT}aLN?5@IaLH@E0ZgQG<^%LD<1b&mh6A#{d6{5_))T6G#_t!0=rPdoVNI0eLtnq zA?~BzVm|#L2N-nuDARImnz8Hk0_*K*k!KE~ncCXo7f)MyM{;}D>KKJGN+?l1w#Z+! zW)bo`__c$+U0&#A96>%E{w;K(*WE-BoGr-_2ydKd3?IF6I-_$b=#y5=Lf#^;(L0D~ z+lc%t(KG^IVPRAn1)@vm=s22Va-(;jO?YFv)^QW9gF1*+(yoW;NJPRz9tu8jNv!Ke zEGN|+saR%!tNcgiqSuK~IfmBu!FJze-9)7T%hhW{2~J1D59Xs|MC0dE+*2d;p(!Jl zWUEfO*6BPPg&?YlBUUu5*x{z+qlmmA38hfSQyyEl=oy+%L4(morHeJjcXU zWFE8|GrO*ZU)P^{9!ZDY9^H(A{@rl!2j!ghsi45avgl{u`CIbINyTJKxUS#p9(tY3 zl}SW@jO*2H3^Remw*mJV)#NU65QU=CVv~hnykrS7j-k6=A4`qSPqi5-MA;i$kw^!EH*fDW@c9rAI8ej{uw z=gpgBxd!2xK_g9m@6Iou%%9*k^E2|cXs0Fo2Sw_k|y6) z9-M!8WtdFXu~F{Z(eWQyEo7=#Knu9nrB+cd!DG}h;9Xv#!fa{gyI$+bDio$KqB4hCOoJZ16d zSQi`r;o__s_Gat@H5BJcBm+0N0Q4&l?NL3MpLEY39gQlrw0& zehRqJk9}{yZF|sS{A^xFUlO%=`oOe(je($5$K|mZvh>V(13X2=!OBrhS zav5K_X!e;pYBx33Wc41^<}NOi>eTHDyfo-Q>`5qd(>Yo|+^d22G82hJKJvQSQvaIz zw1~iuiNZ)b8YWwFye`r!QKvrP!;VJy-c!g#})GB*eJ4)K%4a!H%6kPyt)jfz!{BnNvX+KErz-&FQjpdLizlnMze? zYsVKKy@Yz^L5U=dw&II%_N;fmywFv+aaDH2>3!Rs#PCjAD#L5eePQ_@^z+6$>NtZ! z7Y@pG_RNd7B}d&NDXN-ytJ_ukr`Au?75vtT1aW;)h0AoW&P9 z$DR*z%Grt>aLsLV&c(&m{dCEwV6;Rm=FU~>+NH95<6;xv9|h^M)T%3w68PbF&V@+d zbM2$FB&ouZ5E)%~e-=GgQsZ#?GuP_I0O#T$WY~*U4S0RJB(|>-C4A)oy`?A@hgUdO z+Vv_PJt?=#WCgD($QMr%i52=pUk*AbjzOp3N2r;n`XF%r?Z`!@R>xlQhkEb4iJOm^ z1;FK8rVdVvd7N)s=e)e^k(J`&Y8`uv1|$%fx^A)If1dm zdTUMYIfdtXlW=+liQ`JuN5XF-%=BwvE{*dFu43V=i%koNo*<5IvoWmVvqnkZYug_) z9D*=Et8UF0j>x>72psD17SA=CK>4KqtmX~+*TkqUa;tU7*A z=hM-Vq#8oNjq@N_3H2NO@9UVVB>8JS=8-M>7fJE*)- zFZuT6IRC5jspHB@q6;c3@_D1deIy6t1_<~<6R;LT;ufEInvF;c8lQP9d>M48hgdEH8@xLY-wAo`5Ze;?Cuo2D>kE4Sp?2yIh@SCz)A2; zh}GtYF2k9JX?b%75;`-hZl*Bl;8VTp6ula&gYrWSk3F4#4nFay7l?e8t&nln`Fo5z z{_u0G)9R|X_!20Qv(?A?iaeY?KI`l-G#@&DATRyv0mHhRGEB)E*_yxnTih<9^5bjh;<;u^NPsUxkk5M`MGHpp-qC+}+MY_tDQ>b(9 zVLP|l%3DDW$B8w%`OgI3uPs)t!=@$ZB=7r}3B)Tf7gQNtL(_D{7~W=12!IU!e>B0J zS`!ck?GI~$8*&A0CA0vtx!28qY_vvLf-j}s)P2}MRrk91N<(Is@%9lkX3hh&$1pHU zDSV9N_$n0KPp8yh<1@`;`zxVMr0TTL~MZ=xwOng1jLRiXRsefD##is7mFL! z7@@^HClHYI>EH^+kzPI~dcvEC4d)X11l7jr#vDmVK31-|OTYj`t8M|D~7Up8fa z!1kl0V|s&&L!00aaOgMUE2UU}9@eag>OxW+;yK21Rzf2ETE7wQE8L%|m51<#9F30l zzwt9Vx@?t6xT=4L{SaMugrVwLg4dE6S}aNE2a2ay{cOUgjb9)Cta1RI^0iUbocpmG zUSxE4x=S$+;7pzWI5}_SHSTo635Pi53&n|L<_WzYo*_Tkk2VF|m`1;L$G+Un`2O_j z>cPb!9+8+genc?@L?I#Q5j7Z9+^^c{Lqfc9MZJ@W-r^XQt32@$e=~@yi}qQ?1)Y!S zAa9YXC^}JYbTjb_BlMUEg0ZBK=la4trB%rk?KQal_E(Hp6~JZIK1R|leKbKjDhXh-#i+!zpM+W za~L@Fj}0&I=QJ{p!CW5A`J0s|wYfi{?Wyp4j$birWMQ^+I5g8HsD(-piQqpD45Z}1%xWfC@ z|1@4~HD8zC%Zm%zWRrJh4pV8dOTa23Z>tsc4Tx%Ky+ihnTAw&in&nng&1zvdiOoAY z!qnGf;ap{C5-+EqF+VhUC{3#?(UVg{B=X2tmE>aW9+B^#i7Qo}4~8wI;^;~<7IAv4 zu)gS+ZAg|2Y4KARx0j|XQnZMuEqQYFxrvU0)(Ta~m;TvUf3NAmY|UKLru$(cr{L(f zNdu?e-+0m;9h)HFag|$cdRnnHZDwZPPUN_9DqR^TmiVRF&>{IJb6TvK@m~ggq|(=K z;Q1WMy5jNZ6!UAc78l{jbhb}D7$sgwYL|GoSbZWaS}8}Rg}?m)p57FH zFP=xie7Nsx-!w}}(Hrki58oesriv# z3B7h#GKwUu-Kp`CVCKxjo}(XhMyd_on_z48c3sS}ZhBOj;E~{D%q_N_`1)OsrrBCA z;U!q@U|BkTScO7g;?VuFF;-WYomo2gN5M8R9+diBN5Ah1ZQg0a;n9+MES;<2f%GS5 z!|x6&N*HFftzNv(!Y|wQ{ODK5i*6bItYr55>MA5^m%HzI=6PLsXwXAISzPwT+G05> zAn(K6?YJM`C-pn;_Y8h^qIFwPRSH|5E?`p~LG}mn2-g&A2zCuDWVXsa9GPiXO{_XP zd@GUuX_sf6wt2dQ+R5@0bT-lbiEXo|9#ZPZoEA-4#SqB5z>XafZj=>VK7IWiSuy?Rfo(YmfAMxyUo$b^^n8t$E|KNHqVGc5CIZ+N|J#r-%o$Jky;IB0()>{DZH z=&f0n11FNG`F(EdCRQdKs`!>qQX|YeL858r>cAviR3zVUvo_>7Td}SZg{7UgEj~xN z<>UT1DTTGksz$|WCAU;1&nuOhm!GoP=yZ+0=wn1K5LcIGcV1%Ar1(U5v~ifXiu=Wx z`}$+0mtX7sIHx&#zk(lwMmdx~Pk^Qb*_T)5@-8tUX6U)lDVq!ik@d;e>XaAm6!Gr! zly5rdwU)aZe2tcCL&M3$*~dj391M>h31s@{Hk`|O$K0VfC-z}Xw3>))M#1S+Vg0n2 z;;g)6!2peOCc(5ku5(3<>k6|y6z|nw+;Z0k7qjWx)0*#`FYg&FynfTlrtuK5sFy+D;FM6jBYa>erLr)!l0-HC}9Ao-31{=pufZ*T;OgXUB(QF$|QmPN*$3xSXgYdQ28OK zCX~+t<#U)JkoMNb?pt{uCJ2i^t&I&3!9OMx58qbdQ+(Zx5}Lnj>O1``1ZY*DpPin+ z*Yo&M^<{SY*W6sdeEL0QZo5JIKcvk4LVof9TsteVW!58Adkw#5#WhoHpZqh94_3=6yUjG4$gK?aPT)9Sx~mlHYOlt3t?dkWC7O%cw@LD zl*KXGLhi6sB|jSr;USKiH@+1yhRk6+0xzK5^f7!3_>_>NCE+_ zA)qx30IUHn90039ZXd`?gMick7w!f_0jFUozzhrmN`w3=2+fX!+aNYRZ9D=h{ca=)S;~g3;>?@f|UL}TWqVBP|v#g#m3V@X-&>HP`V^Edd8-x&O)8Ok!H3B z{4`jNAlNtD2KCF*+1A3?(b>k@*x3o7rmazFqad{ui2(TU&B6Rvme>CQ6!rhrscHt$ z`<_l6+YCN>(ty&=r=U-483!nNags=H{66;+dhga7#PAh(*B zp0~%ka63Z9I@)XBHXJJ8>NWPq?KnL^dphi>Reh9Ha12q$!fO{6tKcxCQV?m<{Q^(J zk>;tDv6ZV+bIl%x?Q417Ny7tJMyKyf%C3Feb;+kL&OIohu?4TlyqA1|A{0ml0YJzIxy6 z_0;87v=EP?*W-zEkXs7VbMSRGxKU1Da`VZ zhvhRi*MFtq2$MQlu-=b|F~Y`tkFHCJ{!qQb))}kfVgVK&1NM;B(Sx5~Gn5kZdmq9G zgb}fRxKoXZN5Fu40dv)1P{p1KC(|$QyuC?RVY2Ozna%LP!_u-wn>XlZA4n-@_gBai zT`95}?Bi#qIvs@PcJc!eE<<`Ga(#7f{c;Qi*#-KDj5{OAnOOZ_ov07ix|82gBngzk zU|>Tx!=R1+qOBjQcwI;vO_@Q}TOyR8>k<UQ@Nxo9$-G z4Vecj-i1sjNBgLfG9MCQ2l5YvNYg%bt{4oocqi<2e?t3>&g*;6B!UXWiOhW6K7CTB zG=Pau*NFtBwwTMV!AoL_Lk>))b+z${XO4)7-L8}^??fDbz^6G;XmFRE?eSx)Gfb<| zW?vTwl~0Uu|Kt~75VLSY(v4S3*;b1w2)g8+vJzkHAN?jcnfdtyZapb6&m7j&rkFilkI!ZYI2!k0$DC&UCa0 zSkgPq-)SF+@P7HDzjhFp7g4`9aWqz4j-rQzRp_bRwQ1}JL#IqXusFYeEA?dhV&lqz zSmx+2P9a|e?&7nS>2=;Yd9fHfcPd&~k9t8LF@pO_HiWM(TiL9E^)dUGYdz@_%$_q} zKSxMe>$JXzX2MJ3vOlOudb*|DH2kyE^;=&f`GcjbR@`2-(dRwyt&Tt5{ps_8nzKj> z9OBl3g|mmVUwW$IwbFFQ!8^T367HW$s{R?H<*oQFFy7JT=SR=!mh_8HY3A8JH=gZ% zWpDx~r}s!>sq(k)wF^Ow3xu$o#KXF|ALl-C;4Wfy-m`7=xFO65yJ>tmlm5M0i7C_4 zlh#hL<7B1I1-Be{eTWM!77SjS)8xW9LdsN6moIA7Rx+gB)_$l`46{?cIH8(re7@|A zwUR;B$3%;&DX<{b*xOdHfRwGp}iG9>bnmRaYC|%L| zh0eK~{P>d0O-`D!Bwxzt56^~AT)JJ=7^VCpY5s~lw;eLBK>i^8gJWt_bs3GPf3)id z{Gir;=S$|^+=zh_q32Nh^>PLN`mBjqMU8`goCTx%+*$Gv>5lJ?E{;*0BK??t3?4Ze(%fDWA~5yHp-CuiMviEi$ z0gtaLSIW|l-L2`veRh!gxYkX^UPPvT*=ptI=blm@cn`9bJTm# z6J1Z}Z2p`#V(`of>q&9irwN|HljL0w-+U`Pr%n(*&I4a`@4q)jMY=+p&7?P-sy+U& zPK-^tb37>YbIYTk6SBl#Qvy^m8dj%sDckPJo~N>~{pM_$(13k>Rj8xsN9V;*Lpv{p z649d>J<&6bIFnWl4aRd(va0&zbrWA)<&#<_J>4JSx4_@HRxVV&<4p4jP+)IG5)v-E z$R(-G<}f&X^jSZ}|nzGu#r7s)Mqv3d@tChzj&AvplaaopCmQt95&<#=>q=v8HD{@WL~%=({t7 z>4{#K-BtK#4%76y3rjt2jfmppRKFB)r7eZ|hqKkEi$l_qa$N3BQ^QKvVl|Gxjb&E+ zcFSJ2JUqasZDBF(N|Aa`lP5jz`zD+II9{qFWJP=lS4dU!-Spb9(9+X zzAP>x`w)Rt;w0k?KL^r~@-)m*TWYX_-r!{?kqDnE8)G+uhJy&<*v{yJGaSeBK6h(L9Df`hK|MqCrVU=zFKC zE|C_dn;)x(A|}ZL-^7fjEy=AM7wK4v#kRpNun(%q3SMr!tMCQSe@RRw^oOkPb9qJg zJ9*6|DHQ3a2M;U+(X7s!!Y&`qdT?pj(WbfhT)$sYI;Lm9;E(U_b&V&BLcQsqIKz7V z!^b(ECte2(1fNh01k+|jX9Fxrsl{;TMcBzj%1@eLXir4c0 z;dFtn56=B3`BPEjoUE1xaJs1dEm{ki>AwdyH-ed4s_-6AdVk#RuRa&S{~_%Y)WF$< z=m7x3e-aP;)olC^bMQ~k3W|L2x8O7|);9+PUzZQ)@zBrjo(oWA397X8$ImZk1wW{v zwcTtG76Rk3Wj64FN>N*_Kck|6BYNj33w2;N*mM<={Li^XfC~n<|-Fas8P)C)7M9 z6uu&qr>pV0T2GB6%=ye$BW_HE%yVjQyyNcQB0U!I0ux*Mn5^uxY20JzH)<@aaB<<1 ziV6yp@6HrQkPn{KQP$E?zO737?$yBR49i0ibfG-w&u1eslD`GLOwltw_L4}>{;XS+ zu%5ByOX{(kQbemT^xKwvM)Rftf=2$+a{X6{rq6|_si9F1DWd5S$&>mMf0vFDuRVN_ zW!3kyOg9ZH4Q6j52folx^svm?!3%)vT&vHvYImH@_}5XN#lz%RRqr5@Csn zwvKhb)LF#~w;1nc|0qFm<-6X%dqNloex~E*BPAHUm9ptvCkkzfl3Jb(Xdyv=m=qVH2=D)Rf_ub0P1>l zA2l@m17{b}aV7GN-Z37ElkCNa5W~ane(Y9Db08M$04?>Q@R!NNwth63h8Z6!S`5Fe zki^kdSw2`W^gfA(FWLX(8oDAHZt$5^iiXH7Wgs zUtg3k6?P1nK4Y{lHHc0$AmLZfibi{A)b8p~{Z%3Znc0qIpVb8?TB2;j z2M=js#0|h9A9phg<>u)T)3kgY-|V?v9?<@Q-zbb%ol4ETLyDuEEX~ zo$`z;XesdQ8!RoXIkNVYNH)E!`Fhhhi#rz8@gto)!*XlF{||L<0#0@FK8&Ym(W0az zib|;{92~pImI`IxaymG6j(sV#tE6Z__J}B3)?_WRWXn?7DU?u1WGQ*)vz#sG`Muxo z^LwxBfBmoLDVdqiJ#)|8b8j>E+#EYZ@&q!n4BGE=;PNJQBEsXU*9UF!|9pdp%}jfx z-OIdXqWM<(H@EU}E8~$&``+AvmNj^p8`_$O z*74c~bBSKMQOt3YyRF1q{venCmO`OSkLlzHpPEk%4s7|hjSiJJSFGZ-voE>C`wRCZ zywK8W0@D=OJ?`|j@#6ku#mTp8q(dv+^~zHdYJSIA`W>0^@hZT*T`ei@=c_UG>v>>b zQ{4rjT5G}aPZhQWTAO$6T`e9R^ro+WMIZ0&8ok_(KQESqJk;vfO}wy7bM>#e_oF7N z>Bl8}l{E@>pRvEBV9_nr8Qu3W$3>m(?itNj-bFrH%$J1}TLp2hExJi}aVhMFc$R8y zxFh7H96kVy)BXE=Lw2TpS%NQ?RkdhI^JcP0V>^M>FU-!i+-D(hnb_?7C9))!uldN} zrBZfL)^BW_VVDYjsVhShGoxIi-v_+JO4~~uCcgaWt`B{1tLMU+`GE^LjB<{7S0$9j z`97L;iVMHzy1*59#;s>COz!KUwV$u21s!dQzl?d4>yqyK=)NYG+s%2GHg-+{vsvsN=+wu)WiJ96XpzZ?{I%(OXvLqa{33YN5oV|*aEk3J@mtlV(kILT&ZqHlpMLpbzAZbpVU3ifKzq3swn&;` zWxZt7#>a%C$3DrmIIsBQbtOXURLAMm(Pe4F9TGy-ho`a*%y}pdwzZ$_FZ^z>JQs)*R+@!UtO+m1=jcG(_% zoz!Qywb$#?mK%v%bC^SmzIJ*fY|}fxy)%q4Z^sq;jlT-T%tUt7r{lOflj|nZiO0V= znM`EH7Z$v~``$bHFpI2FO^ERHAC=AQmDu-AR7yeNXTItRgUZdRA_xtz%8}E`j0oj)xX*%kneE_{c8o*Xi_Wi(Y&A z6NiP|Xnt#$>rh17Qr&A2U+bJAyK6qBUz{E4baPleIC)QOR9DUUMQO?4*t)C(N8K2l z$4)8{JtdR0w}=`#Fx%LC4z=Vw{(O)-02`Q=F>u^dHf62q!EjIWXI(o)S3jHY<^2%z z)hYe!jbRZ&&OV<8KKtFzZQ5dw=vjniyKYsxbD-|>C%4Y5)GZA~ZE@C}eTPO_kIE+| z{fc!Ow+nU|Rq*@TtD8L(YHCW{%*hrw;HskVDR$J4yKD6=r-S`#r+RytirWPl1}{H+ zL<}>KKard{f4F+x#ORpL#?MUG^Ub(ZPAY%xbh`EJv#Q+u&(PSziGrVVF7FuBH?G>& zHGh?FGD=rT@j087PC@>@TDf72z%%uToyE$^m$Q!Tj45&M;UC3kGO)#K-Y!dec+5`o z;HD=LVH#mO*eZTjxbx%33Txx;;tGR4uT`2JeQPmb6!!Y$)Q4C8k{fp%-*u^}<42)s zAt6o#H}ZC*GL3!edJMKhv%~7U(c4#zt%cJXIv2lAVun&AtE?jui*Y}ATl%t+dUjv4 zn3empx$&1WK|rg$i8yD?-QxX}>xXcyNv&4)~hhO0bztubc z*nfS@m4mzRwh& z>v^Haakj48^W*Kh+@2V7QwfnT^D>;rYxWoA9I_~>UR}Gb_ESZKdPqag<-UVYwIc!t zMHL!KT5n{?<_Qo^l|=R?>SS}7yG!gg-z23~{hF&O#=3rCRx9(Rx;&5j4iK1_?`5jjEEtS_e-Ov! z943{sr>u0dZT7gv2cglgUVg^rHy&<%_1ndGP4VfqpJb*w`hPq#BF>0c?b{G~&{iPg zw_eZq67OBp--x$8jJP!mMVN8US`m)nKlfhgI_;^au-!5tucB^uyV5r{&DAm8+z%yc zs!O+LU$0LXFIn&!-FPm@*50fRZyI+c+UwW4ySWB!M-;Md-{iKMv%lb=%i60ER3Mex zb^D4r^UTKd>&v|)^47Dq@(T$+UUjSF(WZsD>1k(iLdNni;RMgKb^(*dAEn#2*FW8V z$^Jt3fm+wVioUofYu~Y5n!Lk(|2>CR{I%So6`ZX-z9)Oq)XvJia+G5)oYKioC@uP- za594LY@uPJd`kG~&?enIbDwkMH4=H>Rk7KpxK3Z)q%y}dH+pccVz4mj=Jz}|qn&$J zDFs?AwP>|@mB(YzrG9&+>0+GbCohvTqE^56ov7*LHAq@F-=%ZK@3_syEV30RgKK@M5o=*>)y-79UAa?%qf4Ddtxdh*VgZSfwty{ zbxrrYDLK_!l9lST+|mpqrdcOC-|kx#cq!>eR>twp%`;UW9|~4+B};VZ&!#m97)p#| zUWeJ~yno(U=z8pyaNA>njFmATemxN%*APh-jFM}Un5o=YaQ8~>Pn935%QvXYn&sZ+ z)p&GMQnP+=*U{$Hp5dj2PcE%BJt=&ZO|E}vKD6-wZ)=yf<;?7!^Qi{MgzH{c-cVeT zFTu!u*`WX77OxiEy5)%)A17@6>z${yjB*S_@l};W(ylGf?Hh`}UfG_aFsZOrX3t}m zhmSC8ykfuGcrZqJ$7}DEmhumkBNVziznfUXs_M4)m)0r6q;$ct&^NnRZ`RFU{%(bs zsh;swn^L}2gn=6-55fdmo781q`mGD~QzWJ+HSDfob#qs{$-7kcz+S_3+e7VICmItq z6yFWon>Tb0N*Jg2$9{d!vTbEpGn;s%!)`H7#!s!xkMEE8V+rr{FZw8E?lR83FfV$q z-aBn~BGbus-KI~b1P^aR-NOT2&3&F5&A*u1q$Ga69UgQDm z0*mnxKATGgPt5KdRq}1)yQ(N5pan}#W zkBzpU|9RHLTk+vE>rRa)9_lv*?r<5d*uLQ&lfl&wo=P0yeKi+a9x8nti7vbGEi5)E zN;P(5&11_q8=tb?S%wkx6y33_<$~3Pw?1!|kM;N^PP*pyhCH?1Ynj%VU$QDOaRCIH zi*F6$$UV+-=kbr;9KV*knJm}2jt8IgDQflH>TkH`{qZhtE|XE zSH|>U)DQ38!KmlyAN#S`jaObYYB;HjGV?QUUdF$~cKLFt)6VC|1rBOdR3-UekT%<3 zeXn5G=JX}!KYb!BImN{q9L)HNuqk2prUb&{nI&R5N!-gn_60C8zPs$l^m^%f7K!By z?n(^HZyD(4uZUazcEhUsad9gp-fONo&vX0yP{tbK3%1d|O<%?{pUay|NR%3jk z6hAUnA?AD}A?{&S#zd*~6!+k*?JE;{5AAB)9wQ;ZwQS1+ywjTDu{gc)bN5Bgm#>!y zDvcdJz3ukOy^NnOUS1Y|dY`cK<8xnD64fsYa#;qxIDCr1N;N_J_p^1XFaL~QZY=GU zli&PEMQ_-@Y=P_Bn4-BVBeUJ;;Hnj`7L*n&$GP{2uDUeNWM5J7s^aBk`Lb!8=CeN@ z;mer={CAuZ$Enh)1rO3atcD^y3=LN^j zxH&QXr(8>Ru3;RRIrb;*$Poq}+^f=)T1%IBpIN}$9KOhh54CRNR@=Trp=tZ}bGFsj zmhtd*b^Z#HPwtzrd$>wuHf+!8#-CQEg*|0`3_NYP;NYPN zcHV@71*TQcx1U>o+)KI+cfx;s?wrEmgQF}**B_jiU(LGa*L>wd)bveG>)s_N4`(aw zPFOY19(HG$MPkLJKW85>F@L;rX(V}BbDvAr9hc@(-M#BBU3mDk^qkG*Q*-RnyH<{@ zxcaLsPN!v~b+XxIV-<59@24tFN0=T5i>q21zB+x@!uL^pTV>JCe(B>aoURgs;{HdL zi!1H+ontTNNb4hR^p&>AKJZ7Qa|MOMG1V2F^Y`TitloX85X5PtcIgvkB8LNiPqyZoXs6 z?Pwc!qp@Z8eAw44KcQ%iZ1*=epTB9gtf?C02oAK`zfC(}^{kZOx|0{OyPrQwbN%FA z&$d^>qQ~&F)zZPXkbIG}5aWocHF@a*e=$ik59jOBr2zU_0q-?qW)NHZ?U_Z=)w#j*pksOxxN!D4d$Lr7erN#Gp3l zDn?W0*2n132S)l5KEL+Qf33F@tR@+w2+ zm-s`NF_Pw00o=U_#vdX}?!7iywP${dU%RY=eamm7^IeU^zU+6g*E06n>(6rmOapW!m`wd*XX9>G5(I{QMdMmg>MdH&zFQVCVQRSHbhxga0(T_Z6_#yG?wXqD4OY$$mgy+ z6#C#p$i8=HI2=>|_{A*+LG4K!yuWdM@0y(-8%pIrB;@JZV_Sz2?3mSZ`%&o^9IAvC@(_gDD_v zRtnnr)5xXHY3rr&n*mi-e8=7R?$zuLZ#a=BesG)oj)`?(**>OD^^f&D|d< zJ$8>dz+KgN+rwW+XIg91{fhgvPT!954bpsfP0`a^n&V; zkuzL!JAdyrnPDg|Okd@h@O?m~H{Hzt(VN}Jn>KEER+c=YbQ{0FX`e`pXib9J>uJK& z#-n4e`8RI={UI7#a5eT>^OmcPZ*?1q?=6EgorJkh;n-ab_X_3y)(FBKZDU*Cwd8hy z>#{3BZ>M=;cd^}E{#@AkrPry+vojl`gX(g6?1`2aZ}PBTGzrcP8#^Mv-8Q-0^$?4( z0h@;*znNT%ziLVK(3JDFHK)$#y>L&lDBctG(L8%&>(+2#kGDsM`u4KhN}RbqF}~-! z*{vNX6)x%;Db>lhZ2LUfc<*k}hX-3S!ip{lbTi0VSw`Cr=*4|s_TI*>*TM8;#Mo-4 z3L)X-nl!T^>zw6}r+i_xUMC?f5n_rWrQk4@+nfhHa z7M9*vtCq3VSk^kYyqE9(-8mji+jEwV^{3mU)8C&C{dDI;gRnhcX8!))j^|dtb}MtK zmN}=Jpw^m+f3iDwdg{E1mh`!9Ms(!42MtF# zDvJrB*7Em6WI?>pDov-Un9BuP#iJ@L36gGRP2Y!G?XGr+99nC2=+yC}k4N@3Zt;4o zU?%j=%&b61U8_GkM=2)#p4gYDEaL->!wc6k_I|^syjbzMQzAs7KVMpzTm9?T7hAKs`OF>`StnWj#0wgpOO`EG*;)6h zNabNFkECVizWRs8S8tp<>+9{F^ti9*Z28>-9w%{+f(M>Gdy^H!#dfx@D{{v6hQ!;9 z;FTQrROal2P3o&;@%7Kj+Z&3%8~4{-(cGS~{gvveM_*OfZZ?>$&a`^W!IHl^{pyt3 zopF~t0$it8uqJ%p-X0NTp)!{jJL?_EzUny7^p^~g&-IQ4dw4(HtZDs~Y;F6|h1xHY-TCy*X94{PdJz z?8Gd~vg3WHt{>ybHr+dMj(@ppwWZt_j|r2tTTBPtmX5J01xlso4?gx&`_AciZ#Q=T ztXe?)w;$8ivzO+#9=g#ctyEYe_+Hk?dc^g*R<)X9D~D+5$>FiL6B+GGO^aFl52>|0 z|MqpmJG-@~L)w3Rk`Dd$fMczr37dSy?6)8uWNz0Axo;klh_V}ueC5wC zvf#z+9Vp&zEZ1^Y-keAnJg@9X3{LmjSNCUGx$8&A-|?3c%8%LPiCisdDcr>E7*m^M zz59K$Ws%pTQ#oZ5x1JxcgwCSmUVR&vfPjlC`?iWhq z`F^t}yH(_K?wa4a^vNu5uT^=i^C^y$`;*_?aM9=GR|N*D|0>@*{jVxkJ}wd}Al44lz4>7&UDPS# z7`S}qlpc>`-@DJwKC-EiCeg!uJJ;_v6p%>oZ;ks|mas=b``(qq9`gJrK4@9Q+-+=J zCRJEHkeZvZ;sJ}lm26Jep--if3^;uqCE3)SI`4HfB|HX?`eK_jKOft4NMqQl_f4tv zgF7qjw9>8*E;|!3_*&{vtwe&IkG@S^*^3P?1qr(fB6{^@1vP*9F`3;oe67MLCT=9) z?b$W3mhZFL&mj1oV3-CkGeLT z4;mXVonO;~#Mwur19uOZtg&vxiE^BM7=BPcxV&ue4z@6ED z74uKL&m_x#HRgS7W7qvCBzVU=HB2ZU*UA3!N>SAf;owBC@|jpc`^GYXhNr*pnrqeR zSKAI2we^{L2N<}un<~Z&-4T16yxVhy?+E`!8PP9|)1ntNL{GiQP>>p3@A)RSqY6-dWimSs%G1NoW6tPt0OVOrGp@ z-peGiZ=<@jzeoQJZzvnT`;&KP`Ta@$9eHx>zO~NV z56w>ZYNrf+-zN3CMUz-p6UH_gZ9k}Ws?E7(dqdnz9?R`0>zv!REHA1~b=6HjCDuIJ z6sS4=LhyEY(esa`J|Rk#hfeSeD+UfllvV~Xj{o?X67?4*E-tu4%k!$MrY)P* zX=3);F?&Wm_W=QCe5h%@ztt;_q5WmXGp@3eZ#wJmwkNgZFup0d)Ei~gy0`QF^M~FW z1xIC`^xZNmdUg0=!{g0m_U|5;pQ~SexB6%5W3`%V_iu}`GNyMGoH4Ze)?j&Jb)R;P z#~qFIXY;>KBznq)qG$FFPj9nIEv&D27k%0@*En?`bM4(50tbh-awsxKV~$OJoNs($ zaUe@$V4B&=O;21&$6S9yo~8HeMAg~Gvw;`dU)l~kURfAhh5@B_%sO zmu`%6)2X8^XOaW}&|z z>h-ch%xjZu_KKaR#RsF*MN=GfPN|w0B`(!GFR)qAouepM;efb{t^S$mRyX{6$@~4e4O;1Z$!A8?pH91o-xZkJ%Q>p(t&`^=aealsgMgyh4yLVXe&e)7?ANhP%*`4Fe zv-S~o*$m%p=PD+b4C{1VaDu&o_B^6S)g5Fd4Ika=yVR`8JDrIyH-YI^hg-I6;W zIHUvf1MA)KV!35@B{2f38q#yG&g<7-;M!pL>i4_6f#Kqhb2->U$F}mj_}^nlln6{Sp)}w+JH#dcM zC3Sr!)VR8{XH`}x_H}%k`?8sTd!{7kPhmNOrBD5tC3j*k?uw}H z`jef|dPIM_tbTaq-Iw27us<&d$e23ooKXo)P%LfvS!5z~X|o^3S*E!zi`!KFkB91L z^0Qqn4qt69PN^N0w|TcRGDp$T1^43PCdPJ_&+U$8A>osnJ|M+P&6f@35@T_{X3yx| z$Jfuf5@S1}ELe5NIZAyVa7YhE*-LyXYIyAKf<3gh?N*lPb-5>=6;t;!)$cXj&s|D9 zvvMJ;Ogr-MsPNYw@w+A;PAL~$v47tqs6QO#R`_P4t8DNA$r#bJttW(6za#i|hr0|r z4(a5NJ=k&b!(`JrwYzV=DayCz^5D5oJPexp>cGr!pf`{wi`TJS{}@NSi_z+!`dW{i zWr@FD`fPi=C*-AY&F9&PGAt>)H$Zd*-GEyaLMbjaGOss0)0U{`Asuf6; z>Hrd?Lg`UKYE94eG-U(%0e=(DhkSQPS`K=}$2XbX)?Rp@^Z+6N!qG#w-SB440rfN)d%eFM<{3 z5fg{V6C9<0pWqCHa%ci3V{v%<{}6;rjw7ZD!bC%Bp=<|G{sEde%Hv1~sy*_9Xa&Mh z?ciWqkTQ)bUYHbY3nliT4oMak6*NMkanB$>kiQp)??PddNNg_;h7zVMA_Q`0Kykfr zoG2Q3jwHVQD=HTxTK@l2KrWoL7zxEC?S}uCQMlx1g5iL0kja4*aBOa4gTObZqu zOxc|1f==$g4#Fir1OR1)KmyRIdV}L|LDVfd&oB75grG7=2TdD_3s#!4#%3U?Ac*!R zf}m}3*fm^6u(!7XJjE5w@j#X8fhxKfFdR2)qB|Udt&Px|mAj2SOg%7`n#$m%1FC3u zQE_rFa6Ku889{@T1%@Wp7zr;1d73Q<4tN(kLD#?fK|UoyDFUf57n2k;q=e{#9M0t3 zh!sY|%;A7+I5Zl{f&*pk5HxppffAZ~3wndVa5ER89Y|0EW}1{Pgai;us^N|H>tbOE zV!z=~a0qpfDh0|k4U&0KXrU`uDXPeI1%x{&AmdP=A_4_ug%rrMqX54E03!SqNkdXbK2}CPR;Kz` znf#R+(nbwwqej(6jod~Vq|DJky3<6OYa-1xshVq|4ai@SlMLQ=&QhlmR z{>Big)UhVIIMO^~fP9Nbs_|6cg8Vm796U(7f(F9l;b{P`9)S3JrjSbQUWg&1VzYVz!0Zao(rUP|HM4A(k=0qxxAb}FxfczDjj0t^!!5#U~ z9r@6m>O*((7v4xE*y3Okyh+704^v1|N4fu}*GeEUN)u0{1M&^I9zc{Nsz@5>o%a9! z(#j&}ir@tYFul}(vDA;iAb~Yd(sS~K2M{QPAxG-d-hKed;f4R>*nAy3D3wWw*~ogO z6*;WdA^f5f8XgaYw=B227B95N|NMCak@Q0G*P#~T_E=%zl^Q46p2Ryaa3`;{y>gVp z+E-`W`b?%I-Qc|adS6xsTol}&_kLf8;{%PPne6#@L!+_tC9b2-t=@PJGCxYWyYmxc zF>_@T8|QWAlN=}Z-VIe_*stWZ^uompTaGoq^$EO!Io}X|Y3XxamJ_Sw6EMR2?_Tp> z`rtwRI{&wv2J7Qjy5CNacf7dfx;fhkvs8u%iM3oJ7kRhx?HF0V^m)@t(ezE5A6(d6 z-Nv(HAP(fjjbci95R>4wGc3;QsOqwzBau%daPrt{0|{-O%OV`i5;qvtIkufYFBNk{ z+4ZbK!|PJKZH`yeJ8K>Mp0FbRgs{_fN?W&`W3|59UUPW)UYn(ux7N1%xxPQT%xEKa zQ>EXq?ns}@QQ~DD*67_zmPb{VG_$I9?1%jJ;wXu`qDc)A8eDCwld&Nunsj|ns4!b>9+cD6Gi3o)k<1=H&Ud#su|~=4H%dbeqId7d!nzrUDNoM zk-YEssQuid(VD$tZrYQ(yJH~I`FiYmRd#hVx#`aMj#OV0xuNQ&i&=^`o$uAQUe>?s zv+X%kh3T8}OTYRfG1?yY9KZM}zJD?KwT30&ix=0u7L1>uGat4%{*PKKK{HmUeg*!* zpXOWT{ZieJW~8Ku&-f}e?aqfpPP@0}IpUk^cldq3vZ{1iC0a^{^IogW7Sp&A0fE7D zxTN7J$+I5ueTOGSGA=m%altfmnDlZlj6yI<9E;?j@dN#_oVam zbMv>ug@!aj!6pff6kuk>L@GWuanN|d!I5oc5LRRO!?5Mxvd-T{LT|j!JGb2 zNyC2CFboMTQZW587oXf1c~U9YV<_TcmkVD(?{;mUKh1WwAwdFP&#?DCC8z`rp002p zX4adE%Q=-j@-N?(W}Yn&`J1)wM^WXvyjUMs>nncej?Ra44;|y~5=~emGqLbRssG32 ztxaWj3AcK)3YN>n*d-G;&KgP@6Xi^0FTZVU=4`0ZbF$nQXg#vQ~7`w#$CngeQ*N243edKc`BRFK$aovTqx*G=3itmXN&JI>%5&u@!xOk25-ooX!tGmzr z8OG~c6S|c$O55Rwuu7tL~e{cXuf-(P-13*{|N>?Hbly@;8jwJr! zsW9s7i%4EYYLi|V7If5j0V@`o8h{u`S0V|CLHhrJm#8Euwy!WvqRs!MoIgyox1bir zAV8Nw3M64H3FQ(;egQA#Nc@vD#)yJ|+5hyV96cKy?ZM4V8+JPHy;gTge=nhdamV>< zOyD_Oi}f!VczMM?9zMde?D9T|!%7UtcEl%FpBR+dY;j^|{CbB6AJ+RbH-q*D2k#5tJqMYhN{nlP{!EF(*OqBWNX@7Uw1?IN@Cv|RR}`PacMJ*=F4%Q}Vju35f%ttJb>ZTnnD{sOy8;)Ax0~)?bHYq=4QB9R z>Nz0kUiKw*e2ij{wo>&HF-YAd&-0;WA$m*MWmc~TZ={w4y*wS|#GMv5-ew>CI(mWW zbl9N^(Uo!>Jk=}qRUhQIk#&Yx_wh+x_EIzNPD$OIxxj%c_EXo4@$W90U5nTrcxXd@ zKttM=gCY8#vBQ;lBePn1?6#Tbn%{gsv_<&jBlkGWuYt!;6{WwM=~z8=oQSb+YG%Q1 zE|prPDi$TsNW|X35|LnH{E7rdgvX$aZ#7l-rkP4=NsLZH$6;! z7}+H<>Ga9Vz4GH{v3pISqif|D3b-=tZ+Jv>_9d^Hh-9#kIFMP~y~nAs_+yi+_nqzT zdglEK-?1fS2G$XTKfj_sX#aj~e*te>HScwKblJxv8bcNxD((qwZT*g##{E5(l2XLM zxikH1Rqpux`r^5qmGfK^v(%$jznAY`+Rn$CFF%}aQf4{-oeMvH>GT|%j_mY1ddza;xF8PzF%!sU$cn>}xKX?Dj$2r48zJ!jfQCr3k zFP=JE##*Wv3I|J>^F}2?eVDM#zEIN7am5vW)5`b zD1I_|_(R2`J4P$Ty)E^Q*s7*K_8W;Wo$&g$pX2rP`^!m#4$m4yw;xF8HaBVWux#tS z8I!BhGIFMAB*QiF07sgj_Eq)hoXhx&4|`Af+WF1OC}{uom6!HaxD=c|;QO=K&+}bg z_s&eW$fu=giT2@^p7^Uf{J_s2YsyLNr{dF^z_olM)_%$G^tzcgoBzfa!271Yu&Hk?{}&MSsnsYF&P zrP|#)^U!Rb-JSX3(DGOLw|4F6xE6CU=ViuZsUB~*chTXvJ-02pl5wHmqgj79d&c@? z$}Ep-4i9tTz0!h9v^*osi09lf`5sp+dvLS%@lEmk6=%!(>O<9~Z{90rua;swdoOnQ zkh*MAU)sgUe3K_7XI?7?`)c?$4yj$a{`<_M!WTv7iCftG`b`9XtkQHX>KPw4?r-VQ z?%15Sd$+pkCABZS;bxPmoTGVuw|RvPHhS&9cIVl-)E z8{4oB@6Im%?b!B>EqVbCeG=#M99xecsg!srR(rE?|H-U?+j`61xE2b$-QG*!#ipJ( z_9M^7Idva)M5X#J=ls#KTSq#A`b;xgJKEl}l~yVE-sj!7?t_w1p2PNS0s-TzN0yA4 ztbS`IF<+qDT^HF^{?5|XnAHb*GY0XskKZRlG2 zTQzUwQB{nLZqY(qSgw_Ei_Qd#RO(if%Sy&;qeG;x{?2<$RAdPFc}r=g z#?3Nt=33B@#_>mkg%566Z@Vax$4HE3m^_dXFm9>O{iJ$GO?BO=dVK@Q4YK*vBwXR@& z;R~t2v*-HzZVi@(M8#xI#D3dyF5T*r_?p?qzWUwc)}HM*TW5#5)}0*olvJEp6SVtSk^`aOxmMk|8J>mS59i_;e584^ zpQlP-q&Ls5fxaGWMbJ4&6hwOIBe1Ujmpy{2|IEgeLqI5YY4LyXyS_+})8Cc!P7eQW z^Z(uN)S+0=X(uugsFWO%1*|+OE9ie|VQCS;qq{UF*5c^D6L>3vD@eXcba!;)0oi#@ zK=0Ax+Kz@2$BkjM?@HYbqV~0%c*-65vBI+A`|%^;wpl?ip3)$3X!B1 zj|fN>3jY*GMk5MmM$!U@%8PIn75mq?ih}cfs25ShR_76g51_&C5@@dy$Y?}iYn^6> z#pqn6_z!V~>}IG}F(LS}1o#Od0Dc!ndJ}_rEBJl!x{86MM-+qoznWn&EDBv5S|k8n z0{w~L#)B1x-x}k=!iV=XxI#gP|9P)4GR%Sq4P)UzN-Z8NLfSl7;81~j$BH4N!J;&c zMW~IMny@h8k@)xj4OiM;;jDDlPABta+f*FRGe4X)yFc(E3b1iCLJkoDt{fUj+Ua#3U_Ngz9l z8dphSh|K>Lt`aCUNy3@w0gnSI5Is%jSa|gR zu5&D@Pb@4ip&ro9Elk?gKtiFz!NOOTXt;!+%b2e@(kMmei*>!Z(DGn^9m2NV`v10%a}0U%GhBC19EQ?=Y7TMdYop z1Tv+-BMV=q0-Z}ppadt0+@b@|n!`JqcG@NX8>x(RMy7U2M5_jXQQjsj38#YqodYj1 zLT8eseJ+U%hi2L(;pO^IF^4gwbS{amxg@%oF+#A=1v-fky7(9&_&OO>vRG_kg#JC| z7$I2ZL4Z-rF+$*m8nm$hMq*xwNn(HXY#zG0tADKEkvsWN)gIr5zPlE5Xdx8FE{8H8t=dB z7tt~xp^Ye-C!jLs;S%!5P;e;S0&ob8{1Z5YTQCc1fTS`2IJ|4A z#|qc~1zZT`t?*b8)n+kp6x^b*!n5)>ICw`R;E)d}W*ItWPWd@lb^l~+rZ-kJ@D3CgVdql{NYCdRrHVg{clhE)H<@FyRp_suFgRm}Y zuuv`Sv>+TF0t>&eLZJtm0U}lyx_pa93)j+uMFbHH7Flc3T+@O@Ne~(B->V3lM}L7O zub~9(64HQ0*d{t!bm$a9rZvprxka=^Xtao6r$4uF5?C-n@Msa+jcRV;TH4VfUIG{_ z?OvlDE%lP2L#G<;;w3})AOsfCN9d0hF%QtuqC=;Eg==X?i|EcUSo%u_y4iFxQ6-e$K z?GD~?h$%)52*Q~b4Mfj^0nsiW4It{(L*z3x)WxfZnBNdoQPhe=oln$I5se33yhUS$ zYiY-d*kLeK+Qp-RO1<6SJO9+qNLtAQPbHju8LSod5Q=qVx;J>;KP3)MkTr2!c@Wd`W!BV=`i?$$yW4YEHdaG)JR zi!xd7pxsIo?gaxPF>!=pk;V!$ER+wB7#6skMd=Pef!HIdM<}%-@HFpLBAOr2b^|xk z_d$*g&_Ii4ubLad;h-=mK+Qf+G%<&_I@eN@yTULM1TgLB9gS5k_4y2w)6ALKO8= zp(OwbQPh8fmVmF2@Ffyj7=Q#4zCcgc!{XVgM3isJ{_y1CS6yjU2QD zAc2K*Ig%j*B(R7vk0Jp&2fhWWr4a#0V9}!h1dIqk0*g8a&=PAn%93X+E?HwS2MP0}!WPpS?dSro?03^hbEsw$hT_J}sBs@g{65zf! z6iaC9sL98v!gp5%mVd0yIDo^=`+40e~WyQ<8=R5Wxu1>}4##1QgN0 z0;qr@YFN;B=qUz*i#Wgqw4nwr4v+yZ9BO7F4zK~v9GX@D9pKHO##tPqSs|L;AP!N0 z5Y2WFhvrj=Wa#^g4>dv^KxhGs4tl166oIcqNE-m}Vr~sS zfpeXJeFYLj5`o2T2Mq|tjZ}n#%0Zq_S68rk(UUcDd$`il#-0Gxp^S#+LrZr@bEpo* zh^CGRqG4SijzF){-NhbMA@_VK^R1gbyl*NJThv2MZj? zx$8m%>=X62?xm@8vUb7|9qqjVWl6&ED_}OL8{k2O1c_E@Dl9B)K%}4-RF57N(SB%Q z;ReEei0)3HYee$?1=#`AfHMbFGSR?xGzUREFl2hQE&zKm5__Tf&JBi0XAkh>Y!L@X{G=s)M+WOQzlH)1ij!_DrX#iq*EFn1wD|oasVCD`G0Vgta zJ_AGpI;4Y$Io{qL#6md%>IKIZ=q9J`&>RmkEE8Rz1w}F${k5PdDTC7i?6`3YFb3p)gHqcCoBNhNHArTxPnDq8HxP(MrQ&iwk zBMMg|%Sva(K`n^KhKGxaj=#ROc5?vfgc0UJ5`%v=fd?&266=3e+Jn{eA^{*t&A;2g zY#HzvlrR5P4Q`H*0nnQ_M+*;viy4S^gr^9(3GvtDIa+v8&>-nLwB5KvUt>wi08O12 zNb3yof8hT{MIddpIl+m}G?vw*ik!gJ!}c z@k-MS&JEs2mDm&Uki5Z?j0fs^NS~2Fug}mdy%V@xh|UFi2js76h%UuQmJSU_Jgk$@ z)1SzZ^-!<$*cQ|P;#=Y*8=VF)NJDNc{%hEBB+kM<>{~kS2q`TbBF}6B$Je8bna%z&K4t? zSAW$~Ax@8>fK3SfPkxdNodhi`l&P{dhE#y>{%P& z^Mt{ZDb&%@26Tv_s5?*r4sY*djW;8>*#Hv;*rbT*2sB~R`XY^hA#O!*#1Y-yoZKM- zz>s_!=0v!Gxg~&PW(H1uZ2(KanIYyClna6e4&2P%20Rx7?Rg=R8-*GOc>Kf*5x7tj z425G+`k_B!@*+?*^u&9+;w%Vmc;E}LzyaEZdZjQ)a!at9co%OR;Db<~6pfwI073}o zK!DyX0svh>JLDlK*o>nz1CO@=69wn$W{(5Ur#KN|H#FJ5LWL(}Fyc^)5lb;1$dJsz z9DxBlg1;fz3QrfsCZaU6cEF+9B>!SL7_B& ztTHpA3sBdIj+8-@4HxQ$u7HLRnxY~mvLZs&(g8?cHyo@RL32)T3W!J>7dObl!l2ha zXwY*ZK-31Hh|fXgZl%)z11)SI z{TOFSbOBKm&^%Ds38hca3=X=$frAe#f*UjyA`~N+rkxYs4YC!;9@D?Z1D;571lk&O ziysEEm>PiX2~ixNDtOAt?n){^1V?z9fFl4X7v=<4=qV>4jVX2qc|=G{cxyt$1r1!7 zbizOb(A@zCggtmm2nUoI$iD{(6AXG^l6uMrh~#l<+?HOvCE?M5j-6a= zJOD2Mt@EVXzROvj{L%Q?JwFrG}fJq8;M9VE&+Sk-Yj;6M|GyEju6` zvTaIU0koAXcw5LE>~XNIU_9waO-pwmFCdzx5(i`zkqi&WXaZo<1RUhih6FaEIbrAw zklYlwJMF=XVh|prlPM}Z$j!{Hft3n&-2c!i#q~!5NQXa?0YY9X2qK+DrD zgkp{^#+D*Q783{=mOTOd6EYG-NXL`(&;$lBG^qcnH^6}G9f%MlQh*UPp_BU~i7m3r zVDY%!@K(^81NSY(il@^G=-i|Ur8u+bv;$f+sU5}bN2eWl5zfPg0918R^!hv9@dF(b zo(VeRhaBCozGw|z#DdOjfN@E>XG#ML^1C1s6=ocC1g|xC%M6G}Kz>*{)MssNj)OP` z>Z-$_fj!iHSOfnS&Jw6+fH4At!wE#9q0C}2rNV82equ(n@P_0v!c-QEIJg~nYtf0K ze4+O^X}Aj940J~{r($Tr6rVYH>ZuwcDkReJVvUump$h>}H7XJ@bQEQ1`v7)pW95jd zrSJ^X5&CdLh|F-1V(o}pB^Wq)8?E+=v?Kyo3*c%J=zV#bxrX|*CV)p2;RcKOBMgCL zB#2VH@RXT=Ah^1D14d^}Ab?eupriN!oWL`ekm$0sfex~Ok9CpIMYJNakS8B+kb6Sy zGm<_>iu9mHhtvdxf}x`WpiL}rW>lIX#lEHL4ICQUxRHnoy+uz$EjEsj)&g`#OW4+> z!$`?3U|7Ilfrtg*FGM=Sq+(cTTSRhzr5B~Mp1{=y8EYbx6G^J^f-15EBgMMVP7bOZ zkoU>r<+jCp;34XVqz!8FiPDi>Fnh)UZ@;-U;G3}GM)56>hlI3(PDT-DB9KOlHwe;* zOo9~O`(I$-jRdS&8=!qcT#VvR|EnQ|SQn$`0KKmXb`8*`kX=LNG9`m?z}o@;Ixw5z zLtXOF7aK=Fve528iseoP%n?4jhQ~}tU4~##M!cBl9q?WdGew9V2!AJ3*I%r8(6+QD z*jQOZDgcI#UPRl})5Zb@Dne&>LoKNsWU!hJp#s1z+Q6{A0`CZOCnubZE5&C(ahs9n zg$NF79Ki7fiacZu;b1k6&Q|=pEkvZifk`IdHZ>LnB{LrN#noY3V|AfTo7T9)#$)MG=^AOH`o|qWIb=lT3Zo z25jZUROW^^!?^-p3wS0Sl0Z!sFkEpuD+7GaPLPNuZ!LJn=}-&sv?78PHlyh9W;fJG z!I9(*hK@<&4wOlIA`v{Ul7f zN=c_3Y=F2!Gz9sB0O2m)c`!)ulsIB+f+mYuEZoGA2ng)|v~^~^vRucNe&?^aF9zsF z_vO8(PMuTLAPl%I8!*}pH{=0+BPfe%3y?)M2gvfT_qTS|&dR;MlmziGYR^LqD`H22 z6w~!+$!d3su?AyyGYI-HCTzxUe*M$f)03Iy*C&6ohLqm{41-n2j@{P!!M-=}Zm zksjg0mz>^T0UAWj;_dUMctj{ALba*Y0qE(@F&2=-_Po=Q<-@d`0)>9T>tiW zqXax-;zWl6!%6$|58wW7x<6CwaT0$0{eS!kfan`Oc97VDmnpkLhfzK0kIf1FkH7uT zZ-4mp{?pVOV$5%0DZAt6H{bq$+MI0pHz+SZ6PTKA9^K>bgOZmJml<{ZAiZR*W{`f) z_s@8aLVMJFhG!6rye--!Wksj2axTa7x9@-b^8huk(^T7k!fS&*F)sOauFt=5?MIO0 z%PgKljZK)b%*KEFdtlt)%sYnhpnNm#JYJsff0y!;oefQ^cm6d0nIeaV9_N1kno)$~;Zurt?qx>4Jbq{QpWFW6 z>M=vmqke*cyiC`1nB~~4$Bm!2kf-+BR&9ix_r6c8Ao|>R7c-%^jqr){G4-3z^Hq0OuIpuIx7Ph;yrOJx0hp56y7q4oDEm>)EP(P3_D z9|W2cIr|Xck8=0WW?;`o%gJABe$LG9(@uDl%FOQTh(Bj$_sLTq%N> zGPBo}#!xO(6l|p!$m;~mHwwdeokC@!Fo@R~-m_5{!t0cn8-)S9P8E5h(EaO-{27$& z`i#@s2(0SsL>)E?Yx+8)wl@m3W)hn(Hwu%uPF}iEn8bCN#0!(SPN}?=VG`Gglx-9y zah+F=s6g>zi#>o$>ytqha6O}%NOFp1m3 zHLgrzX6M-!^~xmf()Z6s!anRH|zd2t1D@DNE`DdvHKeq={) zOaw>ok+*G6u9nNZJ-M3r*VYzu!Gd0TWHRW%OIyqam*bH{y~|3-bY7-wY&4!HSE#MW z8Rp5=NUA?H$gNbS^D1I=`1HoJ+I&VvVw@hb`P1;IjI_r(UWjgBxzhyda3$MLp zI&X`zaLaV|S5{l|naaji1MTn7cXM%)6~K zt*lrD7#skOkDwrwfvIq8l>iU^<4^Im{O(w0isVO`+1vyFK(SwY{^k$=9(d#%3>I$u zr=5pCst2J7eHT6t`p=2>Nt8~Uotv&9LFgEphWZFQ{cl4XorRx7_WXV7 zV^1oJ`97neo>bQKeQGIBDl7Xw57v{){@>>9c~ZkUr{Vadatihrbx$e>;Wl-hCzZ2s zoBZ%eNp2Xbk`$Y1dWaf=d{W!i)G84xH zd>9~4a+>}$?T9CtsgqjmaZjFPrVd$cGj+(1yZS86)FD53_mj-jIpdG(^CUBM$h}Y* z$iz?fve9NJ+rx`W!xiiEk$2?i@gk3@PgehIJ3S(e>#Aku6Fb|>X5RCr??h((J`IVT z$eiEj-QS7K_B&d^0O0~RKGC@ew$}&ZIW^9KulH3_4zc- zr}~Y>yYE+KZIR{M!KkXm-MH^(ajnH2;R2s72*bbc!fL6N!SAPZ`DKj#d=)eF84b9O zkC8Lsc~qD7#>h{9Vc`2q<+VBP_|0~&{9+EvwM#4{Dow>ol~AJ6yX zWvt%BYP#8R_9kpoKaStdZZXGT9Lp0K@xpK8RPO4^I>&J+CoEe1ZD;cQ9&AVQgo)DM zIFZxYv9_7HUnZ_sKaJabzQbcdU(XkGtmo_bdL};=H|KN;LmztGExct}hFbKx+j;A6 z<0PI)M3#D(G}qmTTI-E-c+PWP#xXoUYMH|BY*?2p_$%Jw)9EGi75DJ;*aws4x6|Fb zq`&Kg@vFa_vYGt2?pZQq@!N^WLL14FU3Nu%S(Zyq+5E;uw>eJPgd=M#u+Ppc1?W!Z7kVt%dEd; z$#(C=I=!IL{C2tx$pgl3rzbEO!T9Zb>f6OUl>tGmsdswA#t!Yq%`$~#4&!2;o`~cS z zPT9EvFb?i?^sGZkf-+9hv^$rf4A^|nGF9~kFPkAU_1jpoGd242$0RXh8%~#VK+9(Fyh2#{N&|K7KmC>jU-QUA$|P z1OA^`;Y$(?Kfp{B-@grBHZvJin;ZK-UC!Ymcs-x`eVnrCWUDsEDLY@5;XT+L)>Us? zmlN^!IuM3WXL{LdY<58V6OQ{DlmSrjEnz|Uem{!!hTOvk1w|@K*Bvu?T)C!Lf_NW+lc_aXSi=CCf@xc zLhbEDNxcV9n_qVshweE?u#~ZqJ3h@%>#tePqrJWUnl(L|-0QE5^mWJk)H1_;-2w3R zSB^`D#esR83UU+vOjr`6>6Uy@2(lua{kx<#_z@gwDykr1GfZo=!1n?Fjwc&GRZ8A3 zXSwc`j)7%@Bd%YE)&X_ zYU4(I@zviyJ_`}jxGp5i9?69H_n`@FRsIj|v=3kX(~sZn<-hu;U;gdaUw`$#NY(J= zpOcvQ!&m>zv&!#&_`lCL248;-oi4}~_Ln0NJwEDyh_v~SfBi2X|AuG1zxwv~yxRTn z3xQSSGTKFGry^ZH18zr4LhnK{z(cl4sB z1@l;FKvOZ1k2KojzblR32?a1McI2@xZ~MlRnInz%#`~Wmjlc2oR$XY}mdA4O?(OUH zSOeN4ux>4v_F}Ui>+<&{K>Cq}TX0099BFAU-nb);zb`Rpn-(+TNF&BzIQWk=+WQpz z^GM_GA<~-`-TX+4uRhL^BaJk3_ZXN*8h>BIbDI_m??@x<(RllDq|x4pn>o_>d&El> zZG1=UNFz(@r>Gc58tsilW=9%-k6hM88xO;eG!iJi_a4#SkWa^Q{5?M2SF{ncaHPeH z7|rlVqrGdy+L6ZJx2P^n3l4dt;nDxpb<+;g@Y%z>*^kr}KzmJJM)x03b&i?GZY()(tHR)v+A!xJFdKkw$ytwaSr}y1}f9 zHXOl68to0=$dN{SBUR^-MtdV%xM-Ke7aVCY;Mbs?M;h&oMASzb?Tyf)ruAOp9Da?G zbSy{m*?aVWBaQY3TGO=H$Vb`>x2Sn1?cJKk(%yK&d8`{+RP7^;7(uNw?Tv_#W4Y7~ zj8U|alJiI-oNM6TM_SsGocTm}llNEmm-gNhqFC*X#Lzo|7Yuy2EGHw8Rh{X`q!O#_LF;!HKj6JdUV6Copb&_3v1h_J}ZB`#@Zh4pTNj6-* zM;h&o4~HIUv^Ty=SF{oFS2V<<`W>G@UCJe!p~o!UhhsWCxm9;)z6*^F+1LJ|uf4-N zgAX0cK^q^PUT81OxYn638r*}EFXc#i)w)?!kd{Z#hMVzN7utAOxzLzf>j!MxEf&#Q zj^Nqm?F1~w(pk#og3Ni$HF$X+vD8aBjz+BMg+|R-4@EQ2;R?onsd6{n1)fW|J+5Hg z53bPw<=6IjE>ZhNxwqDRpy_VqT1qd@Q=wkd1X0bknz}a{Yod;pvBbpeF{6Y?x6Soc zU2F~2MJD%NVzV|+P86SH_=K!0eI%_cCBQ1KT_%0e!+ebv=qt&c+Ik~c{p)MD_`?!y2 z#N(JLcRguuJWpN9ahx0D`9!(~@obV{>HJ{|C2n$UkBi=S2Io@qCJ-p=FCd5R=SMc5OQMGl<9Npq!y!ybf=zdu&&5by--gAIi>63VdPsZ}rmTdI*^pS8D_n`APg zHvYRB9}u8ul7mRCH`#fti}sCsDVr1Y+2do+n_uB9)qQ)r12pvbFpv6-!y|OA_(G)g zT~PD{o~>(uy|4DriflZD62PuXP3G;emxdG2q}GydnEgalP3AbHz{>C zc=sqi{?5nCdT#Fo2licf=ZR#EFG+x9H@;uSOX78IFOrwkl`jk0@OU2UhSoM+`jySe zbL!UbKk?>BHXY`m&KhQbcqg>Pq8`VBxiFr~Hm&(f=GONY(g@-_)@8D1YaqLux+r$* zSg1R`HCyc=^;8ZArf9+*Xz$)SFgfugYoR@D=V@DU+nOIxZhTE^9Up3}#&;X}Io5JK zeyFw2k|zFlDTmeF_Y%*^$icFd~GtWK-W04 z)-gkSYd$$#7{&iWYh4-F3E)Vz2maDB3e!ry+0fb!}Gs=a`mq!A5E<2-T4bpvs|Su45tF!3dJ9a^q{j3+)9= zy5$kJM$au-YWvPW8{dpv+6%_mW8rRzw_mU(OE*g#McWlwKgj@YLgNR-K4MJP8jw+` zaRJ(s|A@qx!k?kNHZA}S1flyN<#y?gjAdlNTi1nnqP|C9OIqjn)wC`b`BP9LI5IUB zJ|^B+DTv@TnSj@^0842sZ{wBHS`K%L&IYWccq~dbEWi8UE5LomDcAbY=L-sI^}$A> z$aZ`8@r|u@e0){3>N1v*lc~xPY@qh=yojcF8k~b8^XjoZXasauU19)r_t|olaB;>r4g$)mpvE zKf|*;;r!6dPhY{l`uq{`s&xi_(K)5A$AYd>XM?*nvN0a_9O#;pReOF7^4&D}U*82_ z@3!C4o@5?jZaUAn1KP(--SOUP9Un{8>w;*M&c%sry(#eweRlC=8T$u?6CVdu)tVxH zwf4N!Xj=myXnfdtod-d@efL2lS|`kNt;SWLq3ZO0yp2zeANzp6C?*R($*t{QoSZ1U z-Cn%!MdNe0t?L1f^O&y7eL|v(_NuiaO_1jC7AK49-X(j`#wBN%TjR0JSJ)i1k?!lb zR?tRt^O1&!4{5uO<$9&#K7SDlRStnN5-A_s!yh$1LwKaYu5hZaec&47?ej__guwBC zsLHxW;6u_0$(JN~gooby0Z`aF&D-^*ae<^{l6~~X!qgg2PB9qJ?v0n^)2b~Sp-IL= zV*%H735?#fgblZC3fo1ISnHA@%DNO7Pva%@t9VE1T7P*%oviWEEgq!m7q6-AIsP8W zOQM@}w>WF!FR%mg64*w^LLg~V6!9|`yAeM?Yp^N4q>Nte4f&Xs6KuN6Q|>!R;WuJ)2KE4CX!F`gc-^RVw2 zd>k&jt^wONlH?rgQtq|K686%(j&0LjrQCb#41@%ZH_}TVSblx}C?}sQbCX|}U>e18 z;#5}|;*7>GA@pd4xK7UDd*1lAdq!Bn$?cvMUow-rF&j#TZeJ_Efd>9vQZ z*f(g#BW}P*B?oc1jtp(bwdaF5vguN;;|VD@assY(q1GCN(q{uG%~&5F`fmR|u@D5m z^_ucNpyrV{bLn+JbFE+HTev-s#8$NZ3r{3yw)(~EtbPesksfhlGkbj0?R$>tVjJv^ z#j1XZ{q4ICO4I%$+9Mce9W%T8*5eDU^|hRW9^VBIc;gJAHLeU4sd!*$@-J}NMsB3z zc?o(iInDW#JjXPUeuY#J-zCyO`WnbcV@oh`>kNFHx&23!d+&3=2BDF!>&yj|p9x4+ zca>W%oS#1AmrRsVk0l(U^@Gsb=L!wLZXI7}jWt6XpU*t*2Q=8M>W)ljRSvGBa-4k8 zq!-hNVx1FG**qeUbo0s3+SY}JGp76X`vBl}@dys2-ha@ZuolV*Lr!}gGXVmCRPM2G zo<+m;Sv-QeZyhrcTI-4Fqxk{+ieRDc7gb7oggZ}X17P0egbl;}6n7I^>+M9DBYtWu zsDyn7SpdZgq^`~tncmu-i5Ic&J~X{Wfp%|P9v*h@y9Mp0^}{IE9$`tgjAF#&E5OVB z$a9U}bMgc<&V{2xevQyt2Z1J?E3~$wpb1+C@eq#04(WXgby2W--|q4wQdjsNeXw(? zI}#GF>q5v~pVOqr*IE$_)@Kp{(l!{k4bSe{FQGV!<$Q@-x9=NVL;MASq`QC$+&B{L z$*O z_QAvX(rrOs%$xAp=w1>>>v;fDs6E?YC=4JMJ!ZDD?;E#V`-T?QHVGF?I6r;JHwF!l zRP~EHrLk86A#fm7IeZCir%=v!A815;m)+HVfO<>L0DCtdM+qBWi&*vzYex4RGr8pg zb%m)y1L>-{K@%SjcvCtd?p3q~)s;R;IpLGg@V<9lUT5?=Ur+7=u$j&u_Pq*f?ntzC+&5PAq%L@3%a4S(HZS3cXWMjub&B1J z%UW_e&|&Wzk-EA^c(Qa(sjGW_b!-{^T2>H++?Y|^>}_j6v%SD6ZTZHP#yDNqKD6e4 z&;T0NatMWy4ga_wNIb=#GLKuwU{IIn+HMcyzV8uHo9)A(5BVHu&+;un;5|3EbK4Lg zZsRMM%RE4W+U7)r%J)RS@8Y|71EkxsQaT%9*?lGvp>3aYp_Mx!Vzse)#4irkT2m}> zw}-i}elhd<&VXIF&BS$6+$P$Kd@(5Pwg*9*WM2kg>ph3o{w>;5&W31Bx?8YQ%@=D` zdlU@0cn$(ZaZrdYyn(f*Shce0;5gDFh{)HP-f(7Bzb~9W%@-4_eHfIpjToq<`91MS zeW$5=7f(bjZoQbm4_>C$e6d!=>%fb>_7v>%ha_uk6JSn$4QQAQ-7o5a+T+v08Xuoy z={@3O6yh%oMf<_m5v1=D9;-damCzUu4g#Wod&~i9M3XJa3vI03DhD(y8y0I-wm7fk zbdNy7JI0khY%_r>OLi0PD7}Q+A->B~fc7O|kw}+^CXA7nD9SsN*C{&pVAm~^qcyc2 zi#tkoS?u%1{}PGVSOKwqikXF(>irDLpZOohzRx|lC=zbn%L`uTzHc~T6{D1pEa{0i z$GEaq!c=LKqYXkI&j|r0-f}Ok6$nEH}L0!cLK=V2iW+a^poWJ)RFapSAJsZ#z zn*vR5R-jp4Cd9w_3y7OAK|F@K=V&0h=SWrAOnFM%`T^dLw%I{TtcUTkKzJBiE;|ai zsdWngvXLTt-8Yu1^+fzkNh7_M!}x1{n&$y67w|cV=Oj#8Yl;e@H9-8Ty%%B-R0j1ysHEmWuD{}I^r5^97);hD z@tw#I0V>cjJJcmGqt_1wruj?4zO?74Ihq>+N#}t02<;oGnlxV=jv5OuMGoM=KvY1905RNdaIStvesFt zD?B?;TJIY)+3e7;ylWmj6X|nGIkW+lQ|vF$oZ^w7jSui0?*cSJLb^Rd8+%Pj;nI31 zbrs(PJUKqhxAx)OCxJ1W4?)wLJ!qtW>G7e+_Blv8EzN@iqctUjug)Z}qwE=I7!2Jn zTduJn@-!9%m&Sq+(3&FSH9ll~-J^KlTFyW_(f`n&d(329X+I~@NVW?!-LgVM>NGuBs^9;f~cF8mz1+j zOmuA9gWP?b*4;1NYQ9{3ttrJc4}kAJ2Yg|uX|cuI21B92vC(6RqpoQ@1M2e!mZ5u@ zPcCcBC|H^=N|MeW=U)9{Shzj;)u=c=kh|~_%$}Ar1o|o812jHx+4GICEgEl)+P^$Km&=ijpT4NN@gn>d+ymx4AyFf#+t386&IxFP>^}8G??V1mv zSv00aUBx^RtYSHh+TMCBek^>PO=Bds5=dd zkUTocTbs-_ZHMNmk#v;+1AQ+66}$#)o5~>;v`0i$svNE9yZ9QK#mSj855ue0{tw!-&I(QEo@a9EBP_f5Gc@S};7vNuacTDc zvdog_uK@+ub)hw3s_||~KOizsx)g7C+b)YMT5(#8#6ok2WNI9GdiT ze2bbdenice@FDRg%85_rF7(<1Tj*Rt6Ms2*AI0469pe?6&Lk$H&IVCS(ivF%#$UjE zam%gy!O>;)S6W0xV=Z9A)~V6LBtyZFbzX>!7mvsja;+aJqKelgLrP;>&=kKBKdfXe z5?Q(mH5<#NuI*o8j~d)BufA)ofD|NG ziHwp=h9;SuM;Fx|@>lO>5fsXMgrm)N8M#zstKt8UeZ)#NHb);t!QgN0uVpX=u{DQDepbz|CZ@GTX-gQ2*?E!oPY_&N?v9k8~#Smx)K9Vv4Up z)0qVJk=)19)g1&UY<~*ssow2C0|uxw2~B&1AG>3PsH>QKXo_Wm<~JtzsH8K*t*fzM zg!Mf_g_FICS|UAyC=*E#a^vctVaj9ILltZ$rJ&cHz zh6SNq2eB&JUxv~yyODB=p9BL?{4;fBH)03q9dpdu=4-JRTDQev&5qPOcz5DGCnUA( z^VDq{k!Van{cbN&)}l#Ar>?#;kmyeJo1{OrAH2#(LFhh^J$>#$!&*nDE{9xo&0olp z+BzWzQt!&4DQ`D4`KO^NHUJv0uX`-0Alf6`jeXxxsT)H{#-G-upebJlG{sIs!@%sZ zB&mdGdVdZWAv+WrsE6uGXQkY&?Q>{&-@7h>uNoh$-Q|?i4ylj9rS=rxNjc?2AO((M zG@*h1cY8pf+9Ptin#Q9{)s>HwSKH1DMhLF^K$+55fE`U!OagrUO5nqE9>kgte36stnnC^q9_14>wM_kPs z3mR+d*>FGQtxbLv-BqA}@p~}j-ZzAY_zTYiu&wp4NdqOw2RiB@wG0B)uV4HFh0F4 zpgrNm&;YAyKTv8ULwQ%;xI8GZ@Wl8qeEvvZSNDj1Nm#n}%a|2AL$@fcYq`Lztq(zx zE{fqN+bS=n+Qx<^-xK``KcJj^UW`TjnH)#5?HP+~u;kg19>zsc}qbxG~ms zN#2>p7^A)D?kBvd*B)-#I2U!5CxL!>^j-ZTrKQtk$bH|C(v6$JBdimGHuV_-saKAp zyjX7BmSrJ~rN_rDY`zQDY<`8Sqw5mx-F*}q zODL@68=#>2$VXagELc|U2ZP;{`CR3cV}^3dlK_i_vvplU9O|A2rP2Arec3oa<>cFe zro3<5Kpw_azsbql^N5J*J!e(4rioqXwc?hG{~_MArkpg{@d;2=dwH1OV@A<7P2VAk zYu0@@4?)C2+s@E<4ch$@KGf$05h@)npQx(+MY~7nt?dE&i2qRz5xkZ|gzDR)(1@~8 zIbqzC(|0|f>1_*Rk-sd_lYPc1$L&(T!XtRWYh9VN=epCRn(TQbI=j~tns6y-oZfXT zcpDXCLpfCKwHz@7dY4a}f^yGt=!NS+Q#>Z^5i!5^!B`X*M6|7RNBFpO!o*CpT?YW!d_yblyTCkftgT~4ZBk4=Uu~iCS`JS+45n!L6mgx6Jl7SEP2zys4>EE9 zs;WK3{i7b>F{^U%uev?Z0+mxd9Q`U+JAF8Y1q8)?fZg<%$->e;b#N)=7a*iVF>+CX z&5NiGg@G(P|qmA;FJ*F5ssk>X*IW#a9~GM!!W1_-A~9%1bVE`q*q*lO}U zWy5O!xs$@H+=sr4|T!|a0ueinvIgs^NTAT99-vQ|hJ0J)a^Mzo6fLDCQPzTxfG z*~J^x{&;FyZgD2XuktOXK10Mo>1<$;NIymIbUD;3wZ}8zK3DnfQt3I|5AzoyguR#W zzrL4vo!j1r@7l*lo>|!+q>k}kCLv>;KcJxY?*ow;yCIB1dLnK~=^#-pdLAJ9t?QvX zD*t_G+Bd9KtqWo1tv>^=>Af@UDW6ATi90rry1*H|E_^RRYlR`ub~mP)&Mu)T!hDfr z{RSFLRXQe*7D>j{VAnlFmyY2JhAf_q7AqWttOh!#?5^|!@IT2$-o1-I%Am1z1NT2 zi+!%J_N8;>NwDT|qNCHRWGEP|_#e-sIt~hU%7@(7`v$&Y{)fr#Jt7>qc@Fs~q%(jG zH|9$pis8$rK6>9Mr+6RADGrKqXJa8iM{`pS7cPv5h$zj25N7r393=FicrIwljRB2F#-0Zkv-`*=!|GmwRB`gF?#WwZ zv{*WV=0{ zRBOyhV%6nvd5K0UF3kfyM>GVD=0R1>H_r0zmn11}PwzQdcs9N3BB=WuBoSY)0Tyxl z-@s^vGvGDV_b^DXs{9Pl zF7beernfDH876Pwa^2A`(*DZAG80;_C)Emm3U z7L-$7;_OiC_s|qG22Hj&9w7N4D5n^D%9*dBUTN)7(Y4N81<7u7B-izO7lH&We~IL5 zJvK3^{VsvJ$|Vm?F~ZQ4pOE$lhOPb0Q|`XMh=9HyK$a(C0s88?q!JZxhvu_^0^Mg9 z#8X0AQ-n~G6+TELxhqL2vBPPR3$!yIwaWxrZ2rNPW4^`JQI!4qB%nB zeqo-Xafn)XB=eZg0g^&;kcb%ZahyAnd3ZWB7T~bPRfzZTw}b+GH?PBK(-;MH(aw6l zgzNSB3qaK8AVDlzgFKk*_P}VH*Ks@A7Gf-lQ{@)v%`N2|qlB0dA0nE@{Q~RtIpvA0 z_k(cYDu?XR8|b{S>vHjj>dqh-yqAFHT9+FSSZnlr7qsPF2~d6K7WwJBk<11u3(`XGs0i1TqP;iI0&&; z06#qzzrCTZzFh+i4MBC4JDPIJqZvPT`+uP+#wLE}exn0TIb5JAUrWN*To+}k*B+lk z(YH9EDGxI=>k)Y;tUkE1yqhN>6~~K|XWnaoi%&Ka9y#$&R$2N1G}+=jQ_`M8b02Xy)_jSI?0i}PGQ!Mp zRFXMLbrs_^(z3gpe43P#&p$8!CF8+aW$)uomTUy0Z7ech=ah~~ACdu})Y5ms{+pL@ zfAx+&?78nu(&-By!djJ1nACTD)>wMkmpm=i-Qp>p^f1(M$rjAlm7emt- z=e9|o%rk;M<9Lpx=dcEi@3K~kmtsxH{848O)Tem_<&=vi`_VRW_M@?N%IWX_| z_RgSgv>-8rMlVBG`I-0q~nfI9#7Ag34RJN5-3Hb28j7z-ado7SU@Jb*O1P zS<%_0ZtF;FxOr@xJ1qn9eYL*(AXV+lqCLehLzB-7n)2Hce5&tvLpvEWuMm2jfzdl= zg1X9m3{5d2&;S%`F9B{FZz4=p*ef)Ba}ApHuwbQqo(bodz83JX_Z%x;yaX_#jT-v z7_S3jR6Yf0*2CBi*|7PnTi-3z1Mwz6kCSrp?*o;}cL&Y(7BG@{Netya_h8cI5eZVN z^BnxS&mXw*NqdTM0A{tV2D~QT892822F9OwC+Q-^>-fIkNjbjO)AMjVAxu)SB+y9I zrn-1zL_-l1P47QwPrj3&2OYBr4Z+pzp)70d{hpJ$$_)<9dNE3a+lwQ%`z7{6W5G3H zn%+ReHTXiE+9PtaX(yNhmY?kI2mzf97^?ONhmUE1`s!ElNT6`~HhGXaw-=40+Y84M z4HRB99zHbj}xUYISp!YQcm$3IE0n&8pT#`oLFRi)0Vnu zvNbo@U*nhz4>YLCB}Ztl0pVtn6(IGE1JfR(QG5D!Axoe)t^SBg{zH1DZg`C{dTd zCH1TCb>vHzl0BeYl0BG>;_a-mcsuVaBvW#nd;R#fqIf$V;V>-Y!)Ipv#$ zrf;G{)3*yzsg(xCd5vdn%{zHxBALSJlT1l?cJl*58(j{}sP$NK4N0c(H4$M! zQI(rN=lQSJ^aL{^G`an{N!ieGJkXTy6`FE}Km!u%GtM`MOv6#!; z=KU5bU*nT44oV|CFQ4w}KKM>%zimNI8|Nnlgv${|+xx*Y5uJm4JG0jS4Nf)~oJ6ua z?|b^ZknuvY8~2Q4cVM{YL%fxdECaRB-G|ow;voeDSoetFQ}GBwI#~QJM@US`vV4BJ z@shmqYCMqy70Q#(Q%mVSd4Ab;1(C$^StkUeWfVRtJU%sMZbI`v%IT~@6EB9wf$sKD z>uNvnii3_+Ic(jwE66e-Oe>iuT2F+wys!A_hi`xTyYGJZ;_I)!`05{i`=8%^ASJ>5 zi?4q9{r5lRPj179Uw-k`-~RqL-{)Uh0RHta{^E-tfBN=^pZ?>A?|$AFLVxyG?*Bmwe4Z2=_>7jCl{rYk z+|AC~!4@QJX69n<>I#xDwzszP{y~`y@>itYP0knvUu2by>g*v;6|#n|5U$4$U&zjG7FdC7pG zXE!-7neV^iOhBq`E`apiUCe*p>3?bR;!S?2^88KY0ofZ{nu8=9UF?nBevlf2q&!{sKL(O6WyZimS;Ww4E{<-FrjB+$Z}69D{3&bbMOj0C=<>|QPt8)@^`~(_e?x=Ni;`ylp}{k&Q1f;& z|0!Vhzf<0MUjN{j>_0Rpt)wh}A`E#&G4UV2pZ)Ljc9HA_!{GR#yfd;&!lJU`YCi~b z{H5jqsuu}gunLYJIy@t+A+91OEqadfZ>j7e(H|-k_cFG3vNH#{yPAU>EkJH3!SKAD z$f=2|{Awi}f2q&!X2^ct3^{+O^3>UXl2=hwR}%**{m}+F|4y}MH@IknoIkYsmo~`x zcbfe{^@38lekk=1a{0!%{r7NXf6?{1{!Y_BZgfE(TtAd7?BEF8%jGWv0M~CQo1OVW z6yW-y>_7J;uD?{~1LB;`3vG^WBsAb6Y>h;(vniYGS9~PcZ$47 z{(>{HvHno!DfjAf;(tc{_jSr~-c{Ky;v!`+X;slbA^*34=pyr+7s+4HtEil?s_LJS z|9#DJT_FDxAf3oYLi#j%{bH1Ce~pU1yXQrj{6s_m{5io{XSx3@a=C)69Zo~1thtMW z`Ojp^2L1~r>#~7Q1fc=~u}E0Ef%MN|TsH7`{et-TP+8>69W33fKwwTb(6@i6zy)@0 zK!9M8urqcu7c)0?G&4s9AhN3)05I)Qy~f0EDJr&su-n&;E|XnJNFY9bM8<9ti)3mt z9I{d2uq@*-PHWc`NLJK=*8AMI$=hj?Gu3kx1&nB%<;B$65tamRI15bDIqPR}?RIRAsn__{$cd(64lO2bCYelLTd;ed z#;IvE(yoD(R6%pKfZLEki>g36*|?&|37VrqW!(TPO@AIY1WSsRNudVzFL zVhB4oJ2MzaJzP*WW-e}hRDhBTKmr7Siqo$P2!MXv_Pax#-c}6s!vI*cv~@sitYBs? zAO~@ynH}K}0O#;Tm0$8@GDp0lP0@4wa0I{fo6XPP4|i&qzRscCXHszq{rb@ z(G5RSuUUSwZ83TS~o`+zU+V%XsDC!Zdjlero?dJ$mFL;#imNm z=}LSr3c@cH?Lk>r_56kR_jWw zmuZC2wAy5es#A5vUN1fBRP~Xto@e^ z2Qx#P&rz!y#e?bSx(JdM=UjvMbmUr^#X0&5YTkcdMfMtv6)+8!bY*OAlIz3-fst@| zkWsziR`7g~z|-2Z93JXZ8;zASxv*6F!pl<+*ZJl@h_fw{L|qjh@JV;NsVcynWQrZZ zqO2h!mS~O&4vc`!0doIk&hlJ zYqM<|Rt+LDIoc}Ld&Kuk#I+;ulSh9JsB09q9%va+$sL_X(Fm%a2n&R9V2seZN=w!GmlgZSLodQmk;>=J&t!BXN`a=Cv|!UWOXmgpw3@;|Djpc&SKE?#Mqx!&9WdNQVttUxSPTZ_EKFR*e0 z^tvZ*VPTGZjQJKOUI@vxB`re1<~l^3WMA4hYd2Pm_?v+5#TY+&^itBDbvSPd`%>k- zhdrHIslc~F6>0B9?bI9bY7MZo_)YII*F}(L>(sfiJizQHOI5b1ecI_h%k48Qv9+vC z5c|51$Iv+SUQ3j`HLLGqQ7y1Mv1$S??!NRrwJ0hL6_niy+(d0;<8Iz?wuzgiL6tD% zuj-N04a=ivV@Tt!`p`R#Dr)D;XU5^&dIZaQMwaD#2Ad1;`xdOuC(p#`O?UMR8Q zOvsH_vRx1-BEH_YHc`AQElt_p2`V?dD{tOO#n$+`*B4XD#!?4mdFq#a$>X&lvW+=O zvqK!XEbB?y`^rR_in?}mM2^__x!gfmR(=JRh-XTPPp2P$crmc{MDxuUVF7OBt45X@ zVx}4?wCNMafcE`VE1@n5=n#L z16pUJM~H&xO8z_FC`a2PDbjWKgO%oN7!7hVBeT=c8Rr+>dg}%SOlgHi@=0LZuhMnD37?w2V7R%WiP9e@}=&{38 zqN)9%u3{hSYEa@sc3yp~qH(vr)5P4%v?!=QFj(_z{(_uOB!8a2PDAs>`~^7y75_MY zu?RZ=<%lbg1=ye`NJa&C{gxxxpr;uQcz;S5cs*eY_&fVaraE~&LC+_zCq=@^>$gP1 z#(n~hPu_p0cUq30y#G#*{X0GO@AOXVYT)mu<@3qwcX}M(>7ACxC!c?($MKy%j_>q1 zzSBFcSb^_xe&-JWRHuBL)}|+)f2YU!jlYYj?mLP*O?BTyekvGL77<4mprLe%1=#di zq*$a`M0HOHvjSKEXv+cl6DT8q)XoLs;Dj)90Zg$0kO2w^frAUEra0Ju@2R?*xShff zIiLfH$|8K4od3ENdJYww>f$V~|69JG?96~kfw{PtIRW-K*iRA2KVj=z-FBX>6Vd-$ zw%E9tp@401K!C;@pffO-o0$W!6%HtbnVkdrTYUYjKh9b|=b1aPhyThP8wWF#n+pU1 zLzy9f@HhY_+1R-LF>}94?pNRbeM38w94o*S(CdHz660nAaj-#|IXJ=pn73~g^Ettt zI`+R6+;=Bn=VWK*2I^`sH=tbr=duG<$Nqb~eJ{*@W$SyD{;z!VyU5r%Ak3UxATT>C zGk{=0?3_?$R?dHFYiAAU^CJ7+Ao)+cK{-!L0x$;h5Vy{`>m~Wo~{3q2)@e<$_=!-fWQXfWaa{rDm&n=>|E^sP-JJFxbwW7B)V^27&@k3V0>pr9h_Q20?*P z!v3526G#X@a{?g!?`_QU!uu~-;fz5j*NJDI^lF%)0PKKrumM@&w>5i_!(T=CUsA&v zhk(1XaRK@T)C>i>)KK7a4vv$)#s9`2zsT^HNPIQ{`BzFla}MB@6KI}5xPipL%?^S> zz|0W#e{O-lGWTE7#P@�iYW+j`>v$p?fxAL6fox<7w=(P~8 z6N3Xh<9kSfaI-OUvj5W*0YvU!nEO9S5fC76aR9Ld!hVWFKmashhOqr!&j0BWKs@?| zx&M+PzMC6_9n8!QQ~+R3t`jg0f^YzRI1bL=b%-;iejnqWSL^>lqJTiynYm8D()VZ# z0pbe))BiDZzhtq~66xRC-1krd0kfSr=4su)4KxxV0AA9%z)dGk%MSh*vF_(+>O6!02l)cb4L)^S2+;gxJ@F7$c4pS!2T$jn13>)0 zxX1rNzBq9URzSI6AR0qYG8=#gI3U069v3!)103cad2@nL;iGHbUr%$ocDksK%4Gco9kc9d(PG;PFeafmi#{M0sZfJkNeGf zhgQ(#@IAgu)acm#l}}4=FXa^Tc$e^K#p7u^%ZslM)~q!vsP1rVxN-|ldycH`VrZae zh_F872M-oCl&8PS&fa~<&$rd74AW$Gg~8G*-*3VMl4Vt$KTBmW7U2&c3|nOMgsLzW zMJ`wUW8WCO$c^f*d*OU>Tj?@`o0@l0)TWh(t?4Y|6*GkfrZ2T`PA1kAPWp|ud@0Rd zR-KsRN==ZX7G0FPTqkhTnP6z?`R!X0%YlTHx3GhkO~feh?@cjuUHH;F;~R%&?W7E~GTe^o&^N`{Wo>TN z^^TsD_scz+e(ma>?XR2z&wrdso+{vCR~N`@Koj$yP9@KEbx#*ufbQq%%8JUx0pHp3 z%Q=?*c{2*Ah1j8B5EKk%<^c90{z2E%!rBs8FZ>mho^99sC$`vuSO=__Ku?+}KvV{b zAZE_rE7iWU^$Q#Y`bR&@?-P$b)#x8Q_AlqVKtcPzujb$a>JI>={xTgtHG{J}^?&8> zT<7}m;se`@u9+FpcQw1f4t=HW+QefB;dNoq@~bhs-dCVsp{;H>kWW*%#0&ze4K z!!n#<7l-Du%A>7qN2+1?3W9O3eWF_uy0m_QNN^5J)5crm72RS`yur!$m4*IgVj;PG z4Yd`VS%~~Lb!*N8A=?$4dtZ)x!PA`5Gl(S2>JQa~!v#M|>o)KNtv>2%#~}n!_u;8< z-csxnC~ZTlQfFG7RYk$@v0nV3e3+L`;iR2lV#aAq8n$hq8`$=o5lgZvWzQ$3A%XC? zD4h#uFSwUP(tZ-7UeW2YNM9wqb-K!@s_yormjfHe**5e6i#%ZTnw18x71p*H5(%Q$ z!fLFXX0P~T9x)=g4o_g+(Y(^}rUHi5g}+7zyX}gP56$2{$Am*dumBqo0pDvf2d_(? zTUCvG6CyufUZ3-_->GRIRmXWQ`kqLC%=NP5Q7mt=@PJ>gV&?}*Q(~1ayM=@=?60DU zQ^Gc=#jPk>z47A{tP^%3g$5~do$Q~XEPR1+7zwjN5e%7Ehq%je^=CTBL((XDoD}0H zba=Mk1-%PpR}Z_Bd!yL3Eqnn^Tz+c?^zstT-m5kfCp_m+Hxh=%Z5@*~OUh5?aJBK* z;@q=o+GGT0$@zPm^<)EzVDP{MIj`h;9k`r}6hu?1-?|Vu4Ges-FD;0)6&RVhhBt4= zzQ&6soJ+EnhV%Tsy`qyy=B$+T!@Lq0>rAi7;SmzS_?`kt&dKH45{w)3yg z)jbr(vmO<_(ue0J_r+w${JMfD#Jcg$2W6Db4HM-yX=ZAC%eP~0<+{buvV$I8{Gs9* z1#_!bWTbDi2wyUI<)Gb*D8^t`mf=C|yAnpMMDW%eD@S0SlhOEtDm_JEx>JODLVm7u z4P1g*WpOb!a^$2@fn|anIL?Mbr|N-LGvv4vbZ+ z?J*l037va9#gS*hM`?DuJ*;jU`WjoW8GPebUHksvq|vZyOKbdYmM$%0Z4msk;Zo1u zoB%Y#7Hr%R{JUAilsa^Y!ZgO0k}}Na?&TS~R^1al2w)S9cp7H#cwY#CapZ-@p_C(i zGi0^hoBy~ItwV*WfLjWrG)p5cS|brZkL?q-ky_JrH#pHOg78Ba30%TxkTNf(Sg87y zI#T&?Th6EWKtcrRc_6KA89$75+~GEPw85yD7j>WpZ*&{bjM0X zA)&Mm)^4X43hGmp_HHx-*IMR$o#GMa=l! zY}7u4#_{|X*_c5M(%?1i3 z<-V00rb`TOJn`}9{%w)BLH?_r`d+**rz%l8Nd;W0UN5z*?$+MePU|3nLtZ!BU%!fZ zYs)U}dV6`zR05%+{QB|a-Q+Fz8>p77&+pfTqIES(+lnIJ&!$-ms2`UeOcQfCTn>gn znap0t*E`m;7$y~sUwyftk8A0U&kv7*ms^(SjO0qCv0f84(z;qcdGBsT>-7~U+Ew`D zNqTCsm(k(LjC1J6@46mF+iGVGOkOXZC+WB%udgnoU~JXJmyK&^j?gV2+yC2+eR4fp`tzA&jMi-Z+pC-s3CwW|rH`U$MX!p`M z2(HO?25V%;EA?^ct%dcep#6e;ux{|Wpl(t<`LDR=Y@PL7Hvc2;IZZ?tanI?x?0>;M zKx5!!`g>u@d-~Z~7X63QR0uF-J86Tk15@3TDep;p1Q=NY3t~V|nEki94pJ75j&8uT z{m&rJ`F6+&wm6mAZ(@t{Y5Xs*{j1F}V90q9mt43rP?>SD0V8doVgv&%{$Fs(*;ezZ za{o6jVUYl~(b%}Z4d_`UfZa);v^v!ji^R#`{M$sIMFMC>soBAI8}ldj_&xPc>v&5|~>EweE+UYvU~G#=MVm-p?=T_E<9R?#WkIZ~1x4JX_u8N8ZZ!2dx^+t^jLG`EA);C zx<88`6NmNGn=~p(UpBbx&rWEp9hkF+=cQdbmb?7%$S!M%bsU5;#6R#=>sZbYs>&lF zz^B!fd^L&&6TK_c)O8XD6>IA$?kwRKdY{nY*?NNg7}jN++TeS4g2YLXn}_H&pC?9f zRX*1+OJA=*Oek#tE423Z#5j@nO0mlB40sF?^6h`E3)E| zywk_e%AUjSD-7pp*BI%x^aYO9wdwKt++MxwfkXtNni`zg^N6WTtbX@6^}+F%FJ9xB zN3}!~scpqNBuLiNYdordxM)3qfz&?2=y{iyWwfJId&_)(OYXAv!nJNebZx%gh%)z^3Jc!L(K%!d9s+JMNrD!iwa3k^#QG?(lw6d7y8qaoawe#Cva zf<^Jrf^XluBV9&*9l^9;><;4HbPGN4)zUlq1IIOCI$jUkVLp{&N$Cn-B0_w(1*Kb9 zS!$XTi^ZN@2Ji>mB0~uoF}!CZ9t$SK`$!~O+1)$^FE%POXUPj?{s=L`7u!G zL237$&9=2z&>lQL7AZ-%rD-I9+f#(Q^E5wOIV!IdO?1DQqHoovuz*6ID14f-i;3*p)~%2DL(27fsG(%s7Od*4ENpfw0l=c0AJxxiUQwHWKZnF zGH<<~p3u@SN+rYm4nILwiRfi_Zy`>-5|8A^XQuD%*$S-aLK4*(QSPU5Bcky>yJzeJ zew2Wo;bms&%RILAisQj9^DE9_4^(A}9`#DN(noBwxGQTlYUU%ax<2riE_w+|Zr-fw zb|@xqsCT6^R^{F`K<}Pm^}5c`$?r&a#q^4COT>f3W`kLpt8r^pKJqVAi7Va7T5&#l zGH)Nix-LI2s7QA2*LLl0ALrM&;+5!a6W+b4yl4P>(qfFwXvA2g*F5CuvL69`?I+k?2Eg7I#d^`D(3RubwCj|jB61l6Qc%E zsq^%T3$a~ieBh}Nj54h(0%&3yyq=-hvccS~ouaq2t}>6@%+%9wyr<-m;6xy4qUJ&- zJs#PrN+~@~K5A@Fj?wM8JG-=99cOuMVPRVRuqcAjv}0C-OmYSI^JC!8d$ZuFk}590 zmniO+pYpxwagokROMWR;Q9YmFrTtJvN}>QiR1(Wbg~+4f|L`?Bq*fkncf(OMVaM0eyOu$#CSEQMY8rB zv*eT2C&E^;;>4t$nrkD47g-K zCLx#n3Og!%#1An0wYtPmAH{))b3>|0^*a7q(PLu<1)KcQ00rT4RdQpyUSY_>VLt|^h|w$^FeV0|bPuz0m1e_xvnYwT`gjE{a0sMb-w zPo;Rl*h&2z0U;q}#N{=}xR>5I^VA+s7U8%=p)@APkeXQ!8S&v#zGg0fA~<^ES(76JD)R%JUf41ag)Qd2}U&Z(!cIH!8tK zEe2Dd-bl{>(tF)(CWw*kK#3Z2SV6wl=2NN&*|7~NF3sDziju{CI@VRa@}ynug&UT- z@80__j%PzhUT^nKywWYE&DMt}d4tKp<-CDI8kRCX5g@e6xz<4mgeg>nyC1Py=%go( zI`JkX;W}SB!G0z{=0j&>gC(FhN|R$J<@O7*P#@M#y5pZjB^wkiwZvgQR zSoIs!xPVo`tfvc$|Gr0evM2RNtorS zuHT!G{luz&?1O>N9&0+qd;s43Cbi$hs%$6N@9by&<;8ymR?ow{zqu6E@@+9~WE= zI9gOq9uS&W5`U^4hOX*$3u32JLL*Hs3Xm+CZYZ1FmqCmWZn*|5H>9j)jTJ~zlXP_ek!N1IIXZd#wm@v&f99Mqo1!Xq&Z?BlIAuRS5`4$#+xMw!nC zdn|@#PQtJ-;m71m_p@K)%_Af3=e)!7soR5(vsQ_0Gy2G?4?T+a9Fo*@Fn?h4&Qlk? zAywNOX8t31_AR>rOliMUmz1DC#$jT7j`4dKl3aeYkOKnI)dpa_|#A@wBttJyB{DiJr;`X>vAd1U>8mlQpI?%4YTQ8o0GXm3U z3jd^AJ&Im_n9?WRq5#%yR53g0*o@>*i^P9p26oQK(5HPOB~#9SS~KsunSlY3T~DKr zm6n*BOuf*0<3s0ht{0JRB>Byiwu`l8Tx9z&a`@w=q{w#q0i?4Y|;T8 zq?tm-U-{H~DgD$!?leRwvl+j|=_aC^HATL!Aw)30E~U!_GnPI!!zmRtJg?l?H1t@+ zN{vi7Zym`d;u4&P2^-^S1osAr5_eOwPcmFUOL#V^g6ehK?fm3vZWrJKl|K4bOHIu|8QXY5eT7 zRgN<}Hm@^q>&OpZP7baq-e@lPBb@xR=Z;-`^8R$eBgUPimN_!43_j-K< zNUp!(M0HX4I!ftqDaa~sne5YFPja2S)AtQqNXXb$EU zNLKN7M0+a_#*=4C!xr2-G9xQ9!u$O-Fuin-uf@tyzj2W^WT7x0dE?H|OMUn2c%t!p znQH_oSw&VapUlvVKFNLg#Drs2wsnX{gZ33ek~!*K19L5k5ufl+V-=4SZpRI6v^_P3 z-9o7CFTIf`VEWP_m=H(dv1Lkl@BG}IgudkPKGM4(ZTspY+qG{XW+Nl9xceCUSXgbZ zMca*#-fiD2qw968xav)cN?w*q|JwNB!?=DrG8)_{zW$xIIUYxmOwk>}HsRL!E`grL zJ?7>(bs56U2VD;q8C=K`t7gFb5y$=JmS)6gBarke?pjAiC!)4?*&DV&sk#wCC!Z0cXK(b{o1Q z0#7|(y+C23tfI?$_wc+P8q5SBNTRK62DTnWWf9h{1qCD@mN(7E9E&l4M&G4b#kB1rP@cN#L8P3h{6_clI(LL_QZZ0qA?Yzs*NX=(CHc7s zha>n;xEhT2WRxV(H<=dN;oXi^czeKsKJq+q<`Fb2x=F#J6OJGT?JYx%;=?BD<_bf> z4JP;N`UDD`X!Q8^1#jf!4Xj)z$H}-czt>t=VnW@E?Fx#cQAs!o&OmmC4h>u;#RL=_ z`#z9a&TbE;t!!Fg>S%t;vF&bC$yN3d@BGAA(>PSfA!0E_;dQwwnc-_@EJbzjF3ye* zD#N!~AP|g*ZQ4aek}`ddxEHFTGVY1s=~DbSQXxZy08us@83I2266rafON7On(^a;F z?~P6K=R2ZW8-ls0N;i8O6S!#2SRz|tp9KddxT$P7Hi|BAOv1cXCu6W<=t?40vVm!P7o9 z_E%pb9k01t&{Htpa49fVzOrHQ;eBoUf5_oJu!$Xp;>u~yaJPl==e3`BpQ5t!q!r({peDZZ zf-&U-1qN!uY;ar?MX~%#tSXnchcv7#^h1OZ)&ub~cbENN^%fD`tY*c3>fy=6y6}lh zRWbC%hTPKQrd!1g2|a^F)OIFQ9p=5a_}9REgN(kqQmRUmqjsAlw0qX5aT4XilmVM< z`e2gEAbAQN#|b;_uhw%yxwy)QPgZ9%m?}dK+%qa^ewHT~o-kYVb_X@e8^c1IP3#%cZ-jW8{j8rVaw>iSP^^%?W1^jtB*rTgBTZ^s`m6&BHUaMm8$Y|tw%JPaFIb9C$e zbQDL6yT@o2lEiAa98b7wCIEt29~+uuROXS_;CU^x{7&6Er}J^vm3jrVc}7k8ZVD`# z6bUj*{43zXTC_O^&bP936;r`wkLA^GDEVx3BY>7EMB*QMca~j8%#z?y!-&Ye<|^b7 z{c-N$&6JeVn;L$G$sLV5%L0p;GV${RjXcjaq8+ZttwaZ`jn#9z=S{XMh8GDma$w4# z_eonPGI_Y;+F%Li3=yS=`rmHjE89VT`?$?5QAEXqZ$rdHj8--_uj`F|_HDye)B0IG zisRw_y0J^kdMUGnu==~sa@Uk=w=WrR@;k=(PrqutkJ9>7zBX~CWeHa+nVixdF}8Fvz_}bnmvpUYf}?suk};G zHxyS;%YVMQ`p}mZ50%4?A@V9S@4d)iZpE5(K4)eB%DXnb&6?Od^)YbpP_?oY{y3Jn z>Ls(Kqpj_t(Ji5&+94uL51RW_j()_ulV5qnDuby%2ZuAVhska0&3KN!fw(=KSiCMg zweH(PUoAL-G5eP#}PcBsKAwEgqS?G*i9tlZd6hXntjasvhezf^9g zpPhmIe>i0Ta{&8yz?K`Z^aJc|1Di%1z^WFo69oZ7fM?2nYpLvK<@U#oK``4N>!(wx z{buC`KEH`}Qhfc{#T;zF^8~;HHosIrz{BSk>%I$DpVd#mJ}mGg`>z+DU+w;_@(EaS z1I897ssTn0|6gjU3*z`*OF@8P#_!fr_9{Ipp{&>q3k)vkNF8z%xAaPfLO5j|Qjidy zhAkVckMFN)&uTR`OGU@zGkv?$#&^OH+jex?o*5hIj<<_X=%-LWGsYTVZqtNW!x@J zI7%o$tH}LwtqH6iHB+%{VaanCdKZm&V+)yPl!ou(_VJ zEINYQ16HnG=k|C}yMRhsvwOI;E&F&+s=?OLQhhpZC0^9Hd5kIDXF^sHS?N6oB_R_# zrLP(ybcA75iSjTWpUlJ3$IIPFa>FdjzW@q3l~?WB;G0=@U^QyxAnzbW`9|xZ*zIlkN|KprXd}zqos(}t_S-b!tac$BjetEvg+kE zUe?h5^2z!h3}K;a`-Brif^CFfjj8!_F`d##c!UFTX#8*vqZf)p$XCjEb^Z0k0JNBX zVP4lToq`_8T-KV!JGgbU8QiRb?bqeZ5GWC0ZxQ$M!uY*+U>hjtp`NyCenugt zukPZgxy$YRV89z@9Lr64rE<^9s8^UrFzgyJYk#i1^N7Q{a&u9Wd7Q$1Rrgp4EnUei zBt6lR$-3g;JkO)q+QplzRmx@l@2nlGELZ!DGD!4l*YFy!{A`gk8g2}==)4G!d=B^7 zv44RyG{M)$a2Hy6i{nbBZQvtf4o7#M-1>;zFZ_vh^poNnNPKryI*6P2;A`x@M zL2z{8c|+uLV?9=VEby>hL#7yB_7q5b9p$%2L()r+if6>{$Pc2_6wG}-H|%r87=%ir zcjwYD2W#bJ)Gy-}HC{FQD>v!r2$a`XsBSbvy|7lKx){+s(3q%{2A=tB^vo3s-zIp_ zv5Te_IwXa&OoM#Qt8ufu$BD)oegBIWOx!izVy^(w!fRov(q;z~NEn&L;~>-Y<`82G zknLA}PD2BBF*D(iFK*~;b5D(tuZe}<+HFPO*bIpeuf62L+J<1(q_VN;jU|*RTs9_Z zS;?C4+3XWrv+E>RN>*MJM36iA>wzH!)huOF?MIMR9r3+G1MW1U745&KVZ&UfPJsY6ZUU(h0>SCT%W_XzoV(_UZI zEe@6>EdP=spV314?IZsDI3~q9C(66^DS5ixLv}Q{?21ELifcE+$4UB(E1IEEH(b+- zmg;gJuBTf@la0K)#Yu!bH$o@!6u#g3cmX6*6pI8!>?@a*({&=iWx1i@#`l64BBzA- za^bOP(4w^OJG;T)kep8KvgZ^N!kZgM-nguaQi6Lo+!_zG)cWu+z3Hr;T0e_EXE#Y9QHy{q6sd3%zz0q+iyaB45}B|g8rx9k&z3`9Z<9f2<Rl3wR9tc#5FcML)A3|- zBF*T*?c~Nh-%4UiqF}cP$_HW$F;y&B^{9Iv-llYRQlVn56{w4T)KnlQKo!Zx*G#L6 z_v4H;?VD?Ot;|-pSwR^s=oZ(0|B>GHD|isU)v-0mcQz6KGSK# zcD+dkg-7ZO4bc*&kXeBLj4mmTh*mwB)l)97Sw-;B^g5n*)KSit5|aVx&HiTvGBhr$ z2GiuSW@_kdlhwTMNVs{J@}2UZN)WfEg9>?5`Z{)Q8E8Fe-)+3E)j2b?Onsx{DaJ8b zkSqK%=WVHg%erN&vAEc>6y0~ceVc1A2aaHa-M*N=40W0t8;?J9qS=jr*f5~^!~yAp@NX;S`dLGUAl5D;uuUK_d zStZzfGtZ2~jH)^so#D|XmfY~5Eeyfr_c_F-6kce zB$$yQTs@{e##%|9f&2*&JHOcU=QZ8gpg~R#H zv2UOK+nNq|oEdn09ylN5+ot@p(?VV+%F{Rmewg=Xp!d#|#>E_Y05#q$n#Rt>q8WyN$@XV{U zPmVsJbHmP?Qwa=D7HAeuL9^TH z=>r{yBW88IUUj#DNt>E7jnOq3$w7M=2fLmpOsmG-JNyw5xxzlHpK`oA`{2yenKtEU zh(Aed8{3PB*e&qHVY+Mb&!m!Qp@N*g$ikLj*j*B|bt7BpZXy@<)hboGj{kVr&^1#$ zp6W9C;c)ySuZ3|Qet@IuzVq00e16h3m&txYp~#rn+{_7&iXy%Fpx8!@$?!s+v@tI5 z^Tk5Wg~!=v66KO1X>&;?%gh9xW$^P0Yn> zdbxP1A5wa4Gho^oWzWISDK}_Ltk$(zPuM6A`yryGL;z1g|HL94ZyvbgfO^ zTT2zSDHl&9du-79Ho#$n!aYU&>lH@R<#KO3YL!--Kr3%MeYZHjRWV6OQH-d3^N$p@<@9a?g*9_i(q(ZmGI1Iw|RqhMl-*iZ!m$ojUc`C5N{lt z*NwV!B9tHzsZPFm7mL?Ur$~Dhczmi`S~8!@U$=hh7&Gv(po7)pyGJ<&uJxP}QmA`Q zR$aKWYN}pnp{V}Womx~X&15vW_nwSRj$EzDH0zt^dxbNmYn!Y1tj<&Dg_|Gas7oi@ z3M0>>h}<$t?_7Fa)_3v6JV!LWY_u~SJ+N#q9p)up9A#U1JDOEbXgd;-R3P*8H5<`Z zb0rytZ?099XN^!9c~~2|TZAIWzK;rL5-AInE=-8l=BK`#_JC3KnusyYE&5o5kL&Am zgQ3$~IYZv5R>+8&(e(E71}@r`-Nos7141c|kyImjff{i=fC_TV5zgL{#8%9AC#p<+1L zm8A$+Y=V0B`s;*DG@@wERB>IQZW93_jCun+NfIk4Sew~{r5>FF`aBXCmUr8x?ADf; zoE+B%oGsj$!I$IJhu*T=m;1W(?hy;gXpH zN@m2uwAHBQy?P8R;Gqkp()Iv z3GvWC67v!`2uLbNYD z7)hMp%_`>fVE(?TzZJ+)=mk;dYBf(+R*pQcv(N%1Ric@~`iQqVacKW&{j%#@Cal`a zfe`{@?d9O5>M4A3yJdt?la-)utQ{q-gAXLBjM{{m&#bPgiC_Q+OWu<}yV)!8dJrdW zX%<0cCz^{^tvo7NNzgxF&zLSmKD1BtYA8eFTh}skDR1nmvTA0W!x?r15ZvI6IVOjj zA5CKdoWpPv7u#xi<(hUd?-N)jD!4^RT2Om_jFeb&f_relONLk6)GAbTGoPJuCOgnO zDtNYJIT$!E@=6YVnmW1vcEHyhT7M?*QOk-!zA0nTT@`0+d9l}5RePSmA~qfL3S@uG z3(xabe-LT!k^A{mQ}s5=R}8#+UD+1tHE3y4!Q@}WQi{y(=u@^kC5D(9y=4(eN#R!3 zzdtok&;({1=hJI{yVYv)T!wsUPRqJ=KL)LQl#gX`CXMr6SgZ*Jp_m%i8; zp3R!?Ee?jz%++d>7C$|zRIz$c@Ny&Q?JJ(us17$j)CUdmH&Nfa^Icv#&}8In6d|Wn za!87KeWzlM&cB`Q{TOz9Mdw!*gMH(gr7N*CdMSB>A=du+K`WY+<%TBjDjPlsR9SmX z_F&ZxF1jOn+9}*470{dh(zfrhubxm&(egmNWNt9gz>FspTZ zpNPkz0x8yO1eOJR7&6$r4NO=4_O*x0?l^g>G)N8DUzIzO7ET+`St@ATS(cPM-pgP( z_BSfZT~w1=(CK=Bx(i!fsNRJa_h9g{iZ?z9es_ry-Q{K?yqm&%MWMseX?eE&JgBJ= z45ef*v>=fWLxs4k zfqvp4QTX$5`OgJ>9oFWJK--gxTTxyv36Xnc7DCp>$$XRf*-s?iy->>*0F%N#rY5*bRF)vb37PM@((J^nyVU3J{d@v^}cu0nksyT zTl#4Jh4Q%67cpTB%94a@;;P7o5E1O!g^3ZZSFmZK43MSt#3~sT*jc_DKG{adlJiN7 zgmo)4T9F$IOrU(*h>oAgbaby3M?^Y4Jn9}zk>%$Ff}G9Bo5Z88S1nhaa#Rm0a3i8W zJjuJt!QG|h=!}RzG%?FwY@Ti}d8q zt1Z@TA0n!-LOv(Ghoe_)u2(A8ls*}c#+?mET1BNywJ(0=s~2uuyBj=0Z7cq8e!<|T z3X@%yoO5H=@W;<%mnmV@yc%15%D`P+nd>)h_t5CP)47+u%f$b9;dt7sh@3BF;n-;_ zc7-o||62FUrpX1#Ba!0L!-d@Wuc$C#md*!h@~W$pDRkZ`8GLzz*PETNOhpsS$<)n` zF^`cNIkBRDt>4c6hmOB#q<=e{`20D{V8}n3$^A+F2EhAYW^$*WofSI&a3*)MMad03 zI>f=w0Xz%?%;ea>%-q2L(!s$2oB{y-z2nAy9#Zh@Ic>o441ehSp9=1GJO8KhI{RtA zQwyD&hyC6d;PhnCvpbxP0XTt^&3?18d91DNI^Km7Fj784{Z6OX1XJ&(hY9agRi+t} zrv0!5B?y;B84;El(|g76ULzs`eOGaEGNB9e_V)IMyW&8}-I9CLAN}q>?wB1WlQvA1M94#0gR}%#^NDaI#Midz4RkXD zR>S%V@N=%*OUjv%V_yf6ktz}|OES_WYZ41T_fwuO|pq zOP@^F1}4J0Yi*z~WW`ZqelapUaA*1&$g=1qD6A-HmC@jr7D#}^So379WW3HyM(+8> z#<2)_>m5cR6Mt`y3@?uivP+N1m6#1Th{Uhui7_L^ICeLQ$u0-SV$zl%V&dI2ucqZ( z^LCTXpsalbcN8xTwa0^FoEjds;Phn6@8^2S6j?7wVEgWphd^%36W*3vqU8!4tI6%d z zb0VA>5dul6jIAQRUwp30l0e?MYhEerY^3`sd%+-hCL*pm&=9&@T-LBWi>&(v6h85W z@46NpDK>8PRn+t;-GKJ4C)%txoQsNmu(4~bLnARecOxfv`D8k71%;!T*=NVerjMnn zcUCX&I+1x-*^stH(^yo_wAky8Fuf)IOdkMK56_Ne#Og%%W|C$F&6kdbCtDZ>-LY0Y zBRIgZvpD4nrE-OQr*-kX7GWE!*c%kG3P?K&SWdYr?!(9Q>z2(Ga=9*@cMvZX$a0ma zTU_G1(yc3sZInARe~5K&Y7R-W+_4P$5axgZkJ#L#+J)FIyL$M*X=h=0El{kaPyNxs z`|Bz*6eZ<@@yY$b+GICuWam&xxq$wWFBQIz&TQ-`L$6N%K13M~IYWV0Wzg^IDpMVz z#1X~hjIa02mr(U|kAc>rL7&i<=rkyc!x_pr=K64(Z9dJ!%^O=#f{p1<+~ivX;__8? zh!5vMuM&mcOL=jAdKyPiyEE;y-VLJ>bTC1o=y91hn)=dJlEEvf9f(f{N3%;zQ-#Qm zJE^}Wt#l~dA|jFhf3&@2SRF~%Hj29jC%C&i1h?Ss?hxGF9fAjUcMt9oG`I$Lx8Qzu zGEdITJTvos^PcxQ{9#|ayQ)@qSJz&5t+no3U5ZkUJ_6(8K#I~L=8Ga|5nJ?8U#VJ} zafa&;Bg;G}tLkEh-*BIBV2#5wJ<8gJxPI!Psf;$Xg{ZbRrln@knZUx6>qm(9mny*O zWh;uMVDsx51q&tp25}}%Cd!nZ$xZZ*`+ZtAFquW1VL;});~^YjHa-Tgc}lA8YmM#(T;EcYTou*u~Lw zIZo+1x{F@k{8SjlX6JM!n^A0)FE_iYLlV|T(NqzYl(1gt+hom9fEn?pUcz0n`W)fh zm}t$HtV%B+BG=Ev)LSK06dU0*Nku!;SdOB2T#OqZQL^ZIHO7Rw7L9kmqpZ1e#i5US z6O1^;yvM&U)o2uV4)BJ)U#cn?GZ9iMA5g5_bhl#V(ex67kyBnI^^LlR@m?W}c()$#O zF33f`@_+@CF&5XBb$y^M5`UDb{yxPw5c}sR>#x53c5yrjUSA|kZCOBpu=ixa^b66( zLTUXNmM8T3=mmNCo{zX(x+RTnY^tDx81refZP6(Qzhs7J=3GNH#+<8*EA1_Z^L#k# zNA#NXOSt`K-MR2%)Ke= zd$4N2J7;1gHg0v{sj(ipFQ50%ki5~$1~!w$fH;+3 z=8-OnZn>&+yTVl=pCF);b4=gqhJ9ai>d_EJ@rlhmKUazGt7_nnIkir0n*fKpjX~Jy zBj&A}>$0X5@Z52wj&9Pq(u8-1)gQo=Fb=Phmg`nP1uHMm9G0Mu6 z{e+IUUa@+U_4I4Y<6yf%7I$TRqVpB>fe0eASK}CT?%N4e+WA=Zqq~Vp8{Smy& zOE~8Rnd#*wT*_g`Wo~rG$3B#E(EbwVrY8=4{%S;=d)5N9WJSJhS8T|WOMzxk z)`48SVs0Js3)zLT&I)uC2Z?;AH;$Ksva)6*Lb`H#R-t(TI6*V>Fl(39tgSC<&Xb0$ z%1t#*U3g16sMKu>Mh-Ms@04<7_eu=iOG&qcXU~0x%o}}0Te5wycZ$W!i?owdn)Za7Jmo$6VljtOI z#9Ybi=^Z_bD#5>617=g!tx4jUvVYkK?|%LMj&%W~p>`d`9XE1_@UbM?1;%lVL+BeO z$acKMT(*x+)ctpKxXOFrkHNBYsduF)4G`+XviwjQx<>wn3p*7oOo6S~B)|wyO{3k! zpQaJ{JBrZ924iQYm2!BhS&oK+d#W_V zZOZ3hk@ys6!_)aWeZ2={K%27Xf_UKj5~2unHL<7bFq1dNV0-!tY+G>m{oeqZKUV4g zeL(6L3;!PiQom`g{4WAhzmfg_iOPWKPueX1LqPMZJd6dviNpqA@&8pG#=-$eGGzHz z%y7R4r2d;ykLge91wUd+zbWPXnb_=~0#bj4LjTF)`y(qFD}W6Z!1Mgqu+T5*#Giok zFGK%|Dg8r|;V<3C|B5O7QwG)lUwMT;RT%yYY%%^29Q(ImO9fD)1t4WQQeB5K7R09S zaE~B&8YnSr{P-H0hFMPr4XlP8)BQ z$8`oBFgOxZufBS_3=|&s3_?pa`rU3ouY@4@kgKHa+O#r6VRi?+kO|{Y9?6$nZ`D7w zxsxY|*Gp!MP<{wE{$30@w#Ayr2#<{r98D^|(IzGDsH}N5 zeUJUANWyr)H~F}CJWHvNV90LM-rTL&@KhUCtQC2wP8-qlCLE!$s)k#ItvY1MqQi=A zX~K{DD>zp`raTp`Bf6v`Y(Kkt{|U4Dy=?mWWc~HBn{Sq6onRKQUPx+)v&9YV&Fm*I z@=ng4L_}cZi4V?W;$pK!!7yu_zoZyyu`{UQd_J2L z?)(iMek+=RGTYwsr`0SAWJE2Wn>|JLgdI)CLZjxN*>hDHjKbCO&}w>>7*1-O7C>Ww z-Z{N#*8YY{HiV^rSe-Rd>KMqR*22KpBY+zw1DCZ1ucSBAxhvP9S+~o;r&QciSD3%d z9>|S;(a-%T!vH=3dIOjcJTbdPlHY_Vd#{ zkz=UX-tNbRhIcXprYvG)-8CZXtzYfn1kB(T8+h9GKl*w^9UE{j<*mDMHoyc;r$jP+ z6g*#?5^CS=ePOUO^KPEBn0MHb9m@9uHa-Y+>gvuFgb1zTPxS8?r?#V^zVHLZt)+oM zqGI>yXjw78Xn?d2L-GE)8jo^2kMY6}3@1fePNy(%-DWORsx1Bt`XV;G{Va*~T`ia+ zVf{4w7M>czCX?B~ZaO1nax~ZKl8FmaS5{h<$w1MRbNi@zfPptXFTXyu?3O(P$>I91 zzkz?^t^E7nz~6*q{bS{ozu3e0n-NkMHye!`JmvIWjJLoz)ON(htFZnE{IqxrQlfD<+Z6Xz{t`_45#S7v&H%s>YG&fUJ(c38FZhSEH_>uHIQ)_TLL!b>|8 z>y)NHr0RI2b`~Y9G3wZ-Yfh({CAwf!kC7a~R_4Vyw3_Z$FZzTn!xxoaJBYLj7*iuJ zoh?lYp@!8rGv-b$8t>%MU2^JjmM!E~*f#Mj+33?ScXXF=zQ<`MORF zd@aTq69^`RB!FtjbkdV5K{Eu2I19K{AMFT$$p+bqnLN>@&6jC!V&&+dR~^U`1Sopf zvr|un(jjcFV936gs@VVs31td=x~VhUtXi!c^9-=LkWr8j#0q4J*}fy+JJE56rND{Y ztKf|gr3jFNu-~m+1rfwT8vgM$!AY2VJ2)x=lyN(FAk(=e-4QK80&q@wqi+u|lWNT> z2n^(eCjSP|lk+Dp-cG=Y**}hOEa_On%W?SrILvPd90a-#FcnByOPi4!3KhW;b6{~w z9bgq`n(W6*;kqw?vs6B=*EJe<+|mH88-Ve>YywrQq1)7I0S%@P&H)1fb`1w0fC#{L zn1B+>Z9I{Nf6c+;^^n;UHa0l#E%kUMj>}VU_9{A`iR(d!qB}467cYp*e&Gfyv@t7> z?p@^%f>>c~_fYa2f>;3i31ZO@1l8G5hTS8C+1OB{G9mQyKS<0FdDa?lXpR>h{f&%1JJ_xGY#101g{niLPtlSo9*g_i6ncyOj z+#kmJ(T%uKtIh_LabWGLznluk&ksbgCoVz63CMuEeJ_@pQE3~<1n97vMSX+d$CnXu z4FhPu83$zy819FaC@1te{~6`&Q{fN=PEMrUoF>vR3}jCE9H4KagkRT~0Jz2<<3bs? zYHmR7%)LQm*Nj^BxPSD$i>-L|(%!$z4XRy@bHHy$@6RdUuBAX87IfoDg6zGT0fNF) z(cUN9lAs`e1*b>ouQMhB*dxfPv+t3km2vOw988xG^xZ1w>4xW4iDGX#M^JquhA;u~ z>-Ju>P?1GOHn(Hl`g}>p*qVPT$P=~vZT`%9Z z4c84`*e(;#& ztWD^Li0*N-nY#Gco=p#JoD(^Af8!tcT}At@Ayq4$lF7(|NvScz36! zD)KN^)RhU`P6VhBz{oH`H(O;9=U}Z&FM6mQ9uEPEs&`)kzhmdL?d@lLAmhG{LK+sl zABGN$rEhra+4Y?qI_SGW4i22tUJHH}J*@F)LaVMM%Uw#>w^+GMv%;s7Mi1)16?=6+ z*MKK`UiMkgEuN7qVLpvA>2j?zGJXLCZLHz;suE+kLY5f+)eNIuoPr$xq$0(>;SBE6 z2+UqxfG)+J)&@IoQ30H;<6P)fqGg`fHuD5qGq)h1)1wc`p7R`w1;_`qqM;f{!=yV0 zNAPC{Xv5gCs|JA-kj*^(Qf?tXZaE!E!bc=PaD^OZhoB$5sYsRLNKkMQN*+Pbtwm1f zI#Va792VM`SeO%PhiOPNH?i{%XQ==7ZudMJ3Qi{HJ?=Vf0}bF~FDC=p?_I<+MGi zDg0rvQFnPW>^{;1x*GQ3Ki#xS$Eae9{N7H0;z$Xw&@hgX{_5lB%JuLG@QOy-{%3_t zCZ@*uX{x%bp5z}4dK>t2Svl9ksd}e@DpM+FVukT`vZu4Ere@Z)18E4I%gyN%z#4a)GX-zDINQA}+K&n){A& zn0?gI%atjx%OOgDFhkZgh822A{j4mn@_qrsm#lY;(<}i5yUM!R&Fotb5Uf~$)%Bv~ z=L4WS(TC&o1_%hC`^%A72%zoJ*7S`J?7#$hHc@&@_&}#aX2@_rYlCK#a6sndlQLqU z{F#w}%lO+rliLSyfUIfQK5xfE`P@j9=Z;Sgm=^ET_U(B0!0XF4 zlGO!~Mit*n@7##9Pf4%t7ga={4(#DshL1wctW}m@9mE80KFT2=fNrXCT+0GAaVBgH z8S?Bzjz2eyQDwpG%#%0Fc^ZYy4t3BwLIB)|B%dnS=s^4Pbq-+qv4k?@WiD>3Lb$HT z9IcmktScEq4RoZ4FK0_R%i0b(a9tpPHQmX1uc*M8tl4v4v`Wu-^YLqCezhFLdWoF1 zh|ZCO^%0l7t@_QeW^Rj(F_kHu4&;&I3KShR=mR&AfK3)=W<~%P=HDds{&e$yZC?Byi~iFd z${)hdehuQnTCWfv#eXadC?xq`k8hme@=sYW7^fJI<0-_F6$@&5!NX zLpT(3s#(2u8ka?MsaiX*EqbF{W_D}4T*CioZsGhs+tYYzMd%{U^z>HZV9GqK! ztS#CG-)!jd{AH{C`-|J_WAC_&4gTp2T{hq6X}kThl*XLJ=n&c>yTPAMocNebrk4WS)&0z zK~_`&AxXM)%)L}ZKN2x|NNy=D>!&i#x`gz8#kaYOoh3Y ztY*}LjSF&j>mg+7b5I8B(_XbrEwHUj{E9vJ#esn?EtjU6D3dr`Y(v?=4qFXREG{6I zqVv1{n;70nfwW)|ysC6Fd_vpa$7KA{7HswU8q@;+w@#u6V1_IuQ*efSxL-P{HU(O9Tb-P0zsob+E%L^<-$J(d!w&?OL{jr zb+8~Y02;cL9IvEhPuaQJggMKo>>a)($!HNY4JD%s{ z$dn-sCWATY$y+CL`!@Pq-Igo`)^137lmFPYjD5Mw<9M)2+1iaIVCw_8Sk7k7lJB;| z=Z$64wF8PRD$&X^+Pzgbo8-gEi-9x7DvJy61DoQTLKDMaeLX`;t-=%rEzpS3afR?z zhI45>9VnWv51o1qvGnTuX*8*wgZ7HZEZ2kY!i+nmQ;-;HGXt- z#g?bmWI=7EO?;+nTkH3>8O^ZbrJNv9-&ksm&_lcE^D_740MCyr}d4ClHI0T7vZ z(mr7xKrl;`Qg(Dp7Cm_If-1m5rMG-2ZGGluC@E@LYuL_n zrb8UWkT>`ok@FP}+zW>D>nX4?pGZm1rVY6L_S>(p-;u)xNBv~XE7BM}_$oO_ zkv|qpQ$@fzRf{{N(kOTdFsZ^}(`!khGTEJK_p;}IgZ}c&eH!b@nxUv-+7U&W$C3ff z1RHYa;0T)h2+8&O^6oWwwUd|c>3hlz9>dD3-yZ}zsn%aW=z@OkktaQT-{yHVYwoy5oIA7Le~iJ zXTjtGN*3zBmehl)(D{%egVnV|Ec(fqGkvLqu9^)p&r&?U**BrL!qDJ7ua`GUqs2kker{F5MGZ+h*M$^(U4A}6cVdcGo{Y3HN8^sXZ8hCD^@1Y!C^r>J@F zZp)P;M@vtU$=%RI-*+v|tjtrPQ=e9E+?i#(0?;I$d$0`Ks8&|@5hHOGvu1a{ls83& zTmfsI^t&{*$)o8t67=ws#KhlL7Labhl4)ai=xwR<$>igYgZE8jkeP7DI0$VG)bvoN z%N{3qg+D@eQHSYE=C{v~##ZFBRJT8;*oBqMb%djk)UCfYsrQ}?SFq1nJV?;ODNX{G z9r^L50rL#qKh~%U+B2v zaqRHrN*3zP6xrA=>61(o+ps9Xa9Lo z_mr;rluW)RXi}lB+b$Y{&x_t8lE+*7UwApR?bRG@=NE)iho(H?@pB4;*#tqoaW-^a zBOx3>E`)We_78(hO%@YBhxUDj!)m4ITYM9M5@JBj#q{<->@<*v ziZ%?g%MMr%iJQq^F(TIoFDy79kT{@+!efKD;pajykehQPCF~+4Mp7e3PqMeaC8nZ9 ztX6|Ak4kki@bG02ID{BDSl1_J3RK!&Bk%Cc#H2Wyfdh{py#zv}0LRC7HGM_tosM~r z8|_12j1puh@a**4ZKQ0Q5!|vgj7AT)c4)|9 z9!G)pm<@RHzNqk>I4HFx65J^@II`ynaFK>ePsaz{8ov7`IEgLsmm*M>+x1=wC$v?o zJ1AMWIOJ)KQjB}Fve|U{#DrM;{Hv)3|t%Wsk4t&b4+jBSjn5DeDjmWxR)l^<$( z4b)Gn+Sne%W8}xkPCXnBYukt+yB%#ef{&H`y!3|J*3n*&3CF(@tDkPahyjDf?7lNW z_nd@+wjdU=xFw*Uu6G);GTsa8T{L48*o1uA{>;F>LR*G%ns{2UEO#l`gIPr$xuzTu zSRJ-az&s7Nv%fjpr2BklFO_s()aY97gEAY9y^zz>TfIo6o{=+8w&nm?~Z?gZ4mHsa_+5aQ} z{nPpX4+Z5Pqp$xIy8Y7*{XaJThg!lv>74&lV`fG`Eg?X3=f6PLcExfK zt5Dd{D5TimjN7nd6Oy^;NPj~|icP5z{>cahxPflADVxFfh(wCt+7Ro<_} zX%&^Vi{q+T@y%)Px;PAZ#!b_xhgdN5Rdk;(4<*N`KDJFE*Qpj?`*|*#n|wNT5vE*g zd)|4N=N$jOz4LfWQ6+KeB0WE@V#??vnYlSlm@8rHiKqJw@s z>m&_vcOu>zkV6{Sk!xb6h*Jp34h%f2qyVw09BV%+9`>Nd{jKy=tg%&X1^dZLtoBFa zH)C^{{q-|@i>&7oVxwfo7R$doLTboRv|mtTvKedpKgw@rMkJ+2VL+v8Lzz z*RXf_$rEsl>V?AznJI=+;`Pu-+#c^?tDkL++^U5j3R$L@M!w$CR;fYkrZ#x4e~L4mMx`9K`Smb=oyqO875WK&=H^YTZC2yMTWU`%Pia8(F)(b z=8pM}ondgHy)ql*I8SG~ypuHP)pu;ZLJT;m>PXky{n4EtqEPo`KDhf)Z5JZ3=-8l1;b_Ee9?2gI%7RtwiI@p+{|9xkH9p^4Oj`?f%jbO&! zTR&AU1GbH~ax*yj)#8rHAPBgi7802was`x{ZEYtK45<@bIhGLvn#(iFt(E8J7Xp4h z7RA9!R?U(5%5|hfx=a`N=!|Kw@Z=7!3%pFzQpP5Q_WhC0rf5Zj)VPe?bTUi<2IJbD z#8l5tx~GzFT&7*c)J~47yvTSXGa z4iF`w5D0?G_~tIxY7M8@W1(c2nG2Kn(>Yo~C#_G)iac6K+Rkj=X zpReus{b|(@a6fLwaF0vu#VUTQAjYP$>XYKJQ3;e|%b!PY`6$60aRR%r^p&J0c$9^?ul2%G**@hC$k}EtWX9 zE#?S+YDQ8#GdR{->-M+AB;GNO2i1qcIe_X9#&Z9MqCn7>k4O;?>@DHdQAbFYtu*lS z=pcL0Xn@V88Qhhggmr^>3Cq%g0b282@*m8bYtfp%B_UO@+bb@%VSUCzT5c z+Zw?B8%Tu7kh(1WniMdo$yXGx6H-K-6s?+k&%<&d3KK7j*H8x#-3o4 zEG)>O7!$3kc5psK%lGbGc-S0t8|l}C)mW$IR&%-#y)j(C@%T=nFZx}*Wcd5pswHK{ z$Aj5WW_fYZ(yF3d^mNk2d56KZQ_LW{w+l6F2Ph{|Hb^CR&?rnX&}_qDJx!F2Xc`Ql zW>Q9pSS~upqB;kmi^7Uk@O^m)E+mZ^=Zoo}8SRlqe)BFQy&o_)5J=JnsaEp?Oq*?S zK_j?3-Bp8k^sXac@Jd?>CxJnr>CCdJ8AApRo9%7shsXEPTB{wwFwHpGHW-fep=8=V z@F$m>9ahDH+`F%1@`lfRtP-#HT+*W+_fzzFA2G5nKA_A`O-8!yt5v(VOqWRo;-}1Y zo>~n2jj70S`OFA<&>@l9Ef=i1L{vmjY-juRLD^v5N50h~S9R!Xv8sSW@HRx=F0Ymr z1WCjP+I+B`z1c58bIOoSe%4z=hP2Rj?SxM za+?WJYSK8xj4`)vook9=0$UXX{8y5LXl@yaQl_?M>xPCyQC=To>)ul*e}3p%-1lJa zYRwt?lH$_kdzAF)OcD7WbXRjglZ<2uRr3`&(8O_I3Ax}X0;P?`vxR^4Lo}h+8nqZ8 zL*9@#6rU=;Ki&6zA>m;RR@4V+3e%?OPVFL@he@ZUsLJ(`!wy)~-uW4SmBKfns7Qk` zV9gVwgHLUbw_Si=inJylj2P#FBNtDqjlA`(Glhk(ljs4e4}jZ5>2&B)AN3_YW6Vqmx-drh#G{@Gk=;h{;QVmuX%&iT&1EAJ! z3&Zv9;qmzKX@02RvnLPi#kG&tRAuONtKY(&`TpizSor%l&s^`5M=c#8w*oI{B2-ZN z-;_KnzPmU4{y88VRAm{|!)3H`cC_%ocZI%AN_uT9Ke^)-exVI0v&g~ddJmE3$m^|U zcP*R>lD}Piiwz%pggv@sij>2HdWC6?cu`Q6cH@Y>WUq4ysCxh+4(j*o9Hu}ODH0~8 z662H|S!yAsul-F-Ab@ckhB2W?9ETMuThZjRZ?if9d=_<5KpAehV?1*x>Bhm(`jF{f z4^IdFEb1rXVXd{-8rJ^d?cZFCg8JcJw6{8IpTjyhMf~jph>hdk7wBatD}1T&Qk`Xu ziLh+>Fd4pto^|Y~NjH4hU{Semr+n(X|4!Uq`E);`)p&8@DBYXQO>IU-lH^uzHp&}U zSUoACfyQhXa%ydQ0ou1|b~h&jwNcLr4=XP@*vmdD$-d0 zeXXvNoT>m*qOSF`re?{ET?ME;P?$u#{qoV`TeP4U<%ojTH#4&OkEro+4K-Mcwc!N{ zz6`j?Y5f`p2WuJ9wlx4V%xeAUo6Psj@0QjrVOel>VNDA@)=m08zjbYPG4kM>E&*Ph zIfdskq$<2Tm+n}cQI_Ij!V*sL3r2U-tnfM(S3HYkVqN!k6Ua;VRzdI*dl8#S(tL6h zL8R!O>cm_ELfEdfNE+CdUYt{Qz@1yfrL7k>;R4U07~&64Oiz|&udZaSt`Bp$NyPic z`Yh$M$1m1gB6`b7Ou% z#TreQpmIk$xp_Fwbu#{{4V%oRjH2`gPBFRX+iZr^ZB?0qF~-^i(v%CX+4d$9V7NF~ zTPJQ}Ey~CNzi!gX02#UY51u}Io1Z)a>XwvOUp5<)aQgJfB7;NWM@UoH2}y=L)^*&u zF?L9?bpx;nBdu;D67i^+nB~@RNKv2(achf$EvX1~v*Is*OkVD>dw@SnlBLpMqF_Pj~3KquB1s9g-sTyq^n+=kt9mr zwat&?Q`v!|p%~&#J`-LZk8MFt2$jDulu1$iVn3M|FY}@A()J>Z=tshr8%6FuXbsO*9qG;g4u-fLt zGIqX+kg+^mr^Ui;H$1)Z^5vx+ULuAkSy$<57-nJKZ9{qA74D%&%+*E6fEgMyNv0bl z^#Bin&*$m>_=u1H3f+6A!~TUoSzK1UaW$`bfMh#ZpudoS2AXgTB_?|lZ!Xjmq$7yu zO=u>$Za9Lz%#wGbmlF=opPMB!mBbI2o z(GlPXr%*p>`eMnKH~9XB)I6)LELj+slJRGR)jSl~h6uZ}pyy?=QZue++~B10+Ba2!MZ|IpwNpYFm5pwx{HG|ffeilZrp=K9fO~C7mzNBD11hho6UBne z;f&pe!^jrR#BnN*IIOTV?w?Wm)@3=Q<_PUrm3h9&PHcs?z3C86#{iPBXcf54mKMoe z$YJ>5@~(mML#M82RFLr3LkTV1PQ;sg4Aal4loo zYrHQQNPk<=MMw)WEX){*(nN?j*s$9Xn>%=+LS^Ijl7Q6?wWX(;F7JYo*vgn4e*NfS z(!)BlGWEuG_8s-X4Un^7b0$SP7T3a#QR`*qI+dd0oq{7IJG09&&!$(pPR)kXVz zOqS=BC=@7&$f_#JBF8Z5jEB3O11*T0jg?yaINF1nBc$Ft+p3LtX#Uj=p$=kyI#M)c zcE=`w=0=q<(7CxQ&T9Xh_4C-Am;*&IC50~pDF?g$g}@b_!yX4-c+P_KRTXI$UBGWq=qGg0Iq^=^ z&Xt&aH-?!$WvajB%D)3*RlzEZ6l&iy&s5?Zch%k5pyEHb`y>?Z*v|es0kPR#peN}N z@^x#%*-B&pXyXxz2)O+)za^iuMdynodh*V(_{W#R%w9s3@1~C4O>-;c5>Ls3ttBk^VO`{i3;1xz5?JXtjQ#!JBni~L zg2QY3+Wd_x|9{^{XZ`CwIzZ_3f9J{r6x@Hf@=R<$ki?%gXqkQ<`{jTB4_$gj02@3b zAiJK81;9MP#zDZy&P>O_{+oyYKjemIqx>PQ`iBJjpSJ#gw2Ot29gq*i1YoIW0ALFy z0zeTNfZ>o0kS7Gd4UGSqA>((F3>G>jy1%g3v;C3c`bUfapj7|k_WmoT!=LB=y1ajE z{11SGiS56+x&Jiu|65qbLB|Xb?fOf2;^%z&HTJ)O9DmZq{R8CqFEH}IVJieYo!`;h zujmFV$G?wmXnb{9YC`UOtXhwCuj+fVrgxhlosMz##eB2nMBfE5Qhd?#6GceerqkoN z3k0ZK{`;jBa$PATOaut#&U^o->FY(rGviF#F_?<@Bjp~EF%tSWX%1gLNmiEWPOsTp zV|41iKJ|JKhUBMnrfg?!I}^IOM+=+o&70zw_?h=8cbD6}tJ~Q%;A{q{0PKM{$aREYGUT& z;MSY>Yczq9YY@tZeYHLAIk02(bzueyaf8mHqy7h4B#W{84RmEKh7qG?DKCaD6!S-r zPjtX;EY&v>h7wq^?Pa$F(BdtS_wu+s`Fj*I*CAnx;ptfVC|huK)q4>p@lp;Kfr}tj zmR+N1R*q~s6km)d&q6_bylD~#!58M*!qsBuFAc($eVLnL)iAO!qKYEnSnM-K{pR$` zq5x;MNGNZkL(hgu6<*)oyX*Dhc+WX~bP@2_b0k3EuUq9@3~h=A=z% zZkDdkd8Nl^SCB9*Xp;muInM$L>p&xz^ed-qSECy^R8Zt$6&2;i$|Wo$D#!~>IDRM- z5~Loz_H%|!bB_SVr$nivZj5qVO8PYd+tn#p18BB#7jE|=L@6KwxF{g7>XW@*;E-&6 zoq32B3jXFQLx19`B3dM~Tws%WdWYR|FTqD{sl*U#EFGKn2$kF7`dZl3E6;#fcc!Y79Qc-3tnCJI6&_3dLYp?RvFWFk)cOesZXr}mNbOLp9cvd48Jzw-Kvl?TJ zAgFTq%n26|c!C;)n#=Ad^kBS{!YIH>z}}=MVbm%-eWQn1->{W+G)Vt|RN#T{%uK4} zuKqGnk@DQS8QA_{0E z4q=87t44AJOz89XI`V7CsRHL9EtQ0+1D~)BkcUlUs89nks=Bl?t+~xi4iD)U=t_WW zvn|>DY}-pH(eEi{Ej2ZwQ+h78*rOjlvwppKzx#GKAHv?_363N8>R#M>Tw1`?>D*e; z<*Fgz@(z5*$-$-3I??!ygQLA{Dco!%F%x5O{St#9#nu0c5wRTVUPXwG1Dq{Zl}(SW zAO4Pwy6Mmb$K5{(-%#95XgGX8tG{{=4O2;8v0$aYP|=JAO+19_N`kqAo|U;-CcDzG znOepnp^N%0L)rzZ+V=7dw}QjLgENlI)d(k!4%M-G+h-Rqpde01bWdkiR?-FiKq)zW zY+Ix~6=6Z7KmmXNALbh+v}^K5ulD98$Y9K?)L4Q0y(f)}c)QKIj+#)5KCP`J^PB)RQBd@y76}%fq>?=&qxRKAF z=&zqZ?lHV4Zo~3R*(RFQm0c5rgx%qlg>}Zu1kFe6nWy>)CVk~U`v;nfs^At`LHP*= zml5;KSL#?V$*l~^D~y2GuU+hxYMKScj!o~l7&UxHS^BD_9#}#=C%z3;dW2%nGk~Sg;fHjy)9pe zgyczON_zcdF`orj^s2{JPSS3YZR}1Pwf5AI%lAK98e)LJ@{GD2PSkd_M(>M0*19Fk z^RGxt#%54Fh(dlrT_$cd?sDGp_{I-HtMopPOdR8wt%6?gdwDA9Dv$atlt?xaZW@{v z?NY%SoN?b*OW-tpLCW3-?c(@v!>YH5Kp~P|(U1=D5Wu^hsvWRvea|XOPHb_hOk7P2 z3jt4D4I9)fqKy|$i@K&7K?{`p8-CSktJJwIA6T+x2_Vx;xMLLfKf?NSBh0LkVc1R8 zfP_1QIYF|Mvm*bTvQ|WaJ;f9cxI>WyZ*vCHzSqR~T3SWSBQu@53y4GFlFqmY5waK0 zA~pIw`Yte0yM`{6HM2!8rK_8Z5^&UW*N;d`ieKtM(t^c%>0%Z;&4oM+V9m(#UavHY zDO5YN-ln|n^IhjpFeaJ@XzY$IpxBW8oP34R^*9e=(`Vv(H$7r5=}#8=DFFzttVWS- znMv~Na#6xOtNwA$%!bJcPj1sR7v4MQL{UDl^R$EJnsKpse$c~qJ{j-U-Izfsi{F*Q z#5~&FeE-InR)$1>{OW-_(`$VirNFd0&+Q7Ie{Kph3PLnhBu9Ir|~=3cI6V$90_zl`)hQkF10! z5y=JRxWTcxZBKn&FKw(Sn(w$!L4Grtm(QGK4CLvG$l50SM9*d_@^J7>Vy!k384#j( zA0{8bVJxQN;3Au@Ub*E=vDixOSlH>6NnbE${^3;-r|s_X){2IJD%Fxr9SY61XH&jilXa&~w4Z@gFw8e-1!&frWvEjv0`B z#Lmb_$HvI1{fAm)DRb)&F!TaHOBoai=*4W5Yyc(31QfqBXR!YTg8ea8@IQoxER1Xb zfiM;VR%U?IGr%Gi7A87Y02pCq0Z2fz{VQgu{Krzn0juTa=0cut_;5znH!93I<)yn2Z8lt8JV6K{{ z*+dYn5M_>~+MJGOoViX;vvd^_-f+Kf)gI0663(Sa&E-|Ve{^MZyAmFx+#5A}rw!o# zF((U3B||pVDwq~|A-pq1FP#Ca${gjT&6M7afX)&1 zI8KHfPnNOT&0(;deBhj`M)EmLIleJ|9#S%g84bbm9j^=B4$X%9_VTP$`1*tUmwd&@@2S&FX-#RQ`u&h_Op5X;MDb>`~V@E^=e|f zPD-=t5f$cGu&fK&jhid@XF5|t3G=uLmAS4;NJHlYW=9+B!teq+5OP(il7)xQ{FlSR zpqG?ZhX*hdx>{#)Dl^4fDygX|=geshi)))zC~jq}t}xuE=dz$jC#I$q1Mw~N8bjKP zHmU8*8H;D0jXGk)KJ$<0k&U(r$dEf@sp={rzJAs8EvpD9_=&Y01qIrg8b&Bv;gsD)C$8@V+{CCDuH2b zK$2oxgPj%9eX~|PO*fMszEOb1j?SKpw`@K$7mAwKcs=c_2+>kr|B7UWb4Spo5JiVF zalyD*dUzoiG%29z__aeD4L6_*HjA#OOF5nur$zGwN8C#lsZdYhy@{Vt(>2B4|-SNmh24<3!#3 znJ1?QdnXwALiRLqrm%tkyjq!M!g-arf`o_GH~8A6Pt>iekyi@h>(l&$Bqs9Mul6J) zW?>_-=Y=vtj9kf5aMNVC!J8u;3#|^8lN%g^x1Uh>?+M0p#8KD;2{|I9dHls8DFe7U zNJiNs`y0xcL(qI1SbY5;0(x?2Dm^I5oSTX~hs+!DvCS$L#??!dbM9K`+fwP}Za{=( ztvFr1v6Tu?5(_O#rTcQ#R;Wu?RX7-&@l?R0vjVeSN#Ta$i)?n!OnI2PXCp9Bxv}0C zMq>9@7Bf@qb1ENOHkJ*4`Z`cs(i&2_q%mOI5c0m>uL9pRRaJ0r6-O-qSLEJF%3{^_1xX zx?Rl^d973*Zg;;Gfhb8za-D;$ph!7Suun;c)`hxusnfNMGGVV)OC`%}93Y+VgmPfE zy&VE)=z>C}G&1%kEY@Ov=Z?|5XTmSK4;$@?(wF2UX1U4py2y9Rf6 zcXxM!1q;C;xCaRy+}$Dg`y^*2*|U57&hG!^(=apLT|NDD^bp@8vb5uH7OfeOj(rqIn80GZ9(ou=vt#fT)e;HL#E+XKXsNg*?`t!Lm; z+7nRiR7<_yEOyWf=|>e_#Ga(M~VJ< zCTpHSUYG<3g{irmWLxej4 zETv75dWIc^EHACbVC-0MGCqn3hHFmpUAWP{rlr<$i&&3Y1=51x*uv&_OC)DKDo46% zrt~fKO$_Q@ZC{m8V%reM)_1L8cWF=Gb?mnb3fwn!2fe{SO`E>(+qJPB^>I~eO_-Jf zmxtYa@;z9$2>~_6h;*aXK*{RGm}-Hk*!B>D`fOqyYbpwT%1wj3k-F?FY)m_7rFHh) z`u0PP!UHSWtWgwF{N~B}*>oxaMbUFATz;d_a>la#kktIW;Ie^|)AYTjZBDpBmPcs< zTqJf462XCG$U+v>3;j|k=}so;LP87Ps@aK(tI6Yfw(2K^rrwnTY5T|2-p)yC9^qJ) zNMIo3Yqo-yu5NR=ZVq~L(DR%APrfbu@b49RI=iJH&Nx!5sR**UKb?@lFh5}Jyn#tw z+z=SSlYn+3B>UzSlL0tLxnp4YAaeQSLKXrzzZ`K0G}L}h*pfPIgrI4T_x0;*H0_>#VSs%x zD|QOl-KcO|&%U63pN?!q9S~6plpcnBn3isi{(>I7h`)Om* zZ%l;S>=lEujajDeLS>*^D!OGJxV_rm;P?p$x55+zFGRiY#T_B0&gUHajxe{4+60U) zzynFWqdKpRdR?qmL0w5j@4$V%|O2lrdq9wCB+Ngzpu@G6%B#&!Cj!|0ekS zT#kPSr5yhg!RHqbJ0Jk{pG*7?{PRVST1oNLb?!UQ;{~A?=<5zI^cL>7D z$n{sLDkbVRcAH{IFB2bXPldm1*KUE!)G870INFbg#7p-asFWn^7(miS%UVlh-hOe* zThv`fLY-2R810;RK4DuGUr*L%?RnHg5Z=8c%b~aV`aPvY+n%@xN!HC{7qDKnM@A>0GgutqvWM8yZ z)F88BS;!m5U-TCZkJ0Gd0kz;S;t^;jA+9{Wioe$sji~oWE)k|=lcZA0mnXzWeWy^> zbJ7FL$R+C_a@J#aF_-5`A(;6l`% z;Mt#ZK{0^GkHqxYZ;3;!VV>~`s*NoWZqiCrCW?WT(e0W}X;^BYG(oW@k*Fn8Xd;iC zQr82?cEs6mn5@6#A)@p?bV>OZF7k?lnJ*8{|*CG7Y)O24EVU zq$1>fr}{-ucL7_*A;QVlXfg$GP&W)DTp{`LM*@~#DJO{npa{@!dpt?RL<#T(i>X!)Kj4g)P+u*`5*ZfQ>Em2s(7zg%I7)aAhYrZZ>vxrpg5JEhBddR z9(<49lBhl>q>@1rjNL9VS+jJyf}Qez_cW|Ri>Oe23MQf1PMheV$g4}L3!TR=3g+u!I>Iuo zAlRLy)OdK~I^=nDM_A&O)NmSA)KF)^cX#T!LMu`vc>ZMMd;9L}X?40I&e9pn1Oq&B zPt7^SwX;_ssprd;f3wd0y2tnLoi9Ii{=ckq|6TsPzY$q~UFUvvu>4%-esW#^+CJ@X z`;z~$@PFE;<@nXz^iMPYw?z_g&L=bA@;R&3 zHJz3ukN{cU@-O2Jhy{X>KktyK#s=kBFV^6WbdqW(M+a9ElF&kjyIH+@Jsjl<8q>A| zl(t1|XD5HD$Ie+}+?^*|iPmGT`V|G+tYUSC?MX
d;l*vmc7Ya8|1t-v9Sc_&@s z$WBDp*W1@BHr1}#8_(-y8<#e|&R2rG=8tA&YlmlU?jKgx$MvK=a(L2kXcE!+ND@Wc zWaV8hDh~zSX=uu2cbrftnxk?kld3%gqAt*IMQy(>O)ndjRL^fENy4PqLv`ZTD$`!- z@0Q!s0TYzl*M>Ep`o%YtU=v$24> z=HfaGzjXzFO7U20idHE1&%S6_S8vE1)y1-sF-hooKEq)VQiB?sW!p0w=Nve~)lmkD zr)Fl45t{b#gBPHEs6ZU)Bd*6xy9gwM&K_g693JUcHJ z`Pm%=M-P?j8qvjFGocBV*Lpr@Y#pLhMkU1-+o&{#q8G1w*F!1vlm>THdXPMOSwv0H zY?6E%+GJRVXL_3tt%;_+Dpc9vpsL{pnRh(x%~wta+YR7)qw`z5sXGDN>-qS7NP)ZC zp;xl|?81ie{A{5YF8*hZ)^n#u_LZQqH;lt0yal%$UBEo^vJfQ~?pCjl9$6F-RE^&G zvI(nv+yfVo#JzX>%EGKpYx`Ty8{Dxjl9_AWo;$X05*%dJ9nytfSx$`nk24PE8Q4l- zkgBEnbI@_tEYur|23xowH#huoNXHV`a9>QpoNmzyub_~8aSaTk4##mGO6PekblE9Ivt3qfYBD)m27x`x}%X4dV~)p z_6#LqFb=l|y0F$zC%Ih`3O%M{HrQL&zGI$GxJWg0IA^Z4ofGm7^Yg((K$WXJ? zVUg}0J$``h+3h)&D|&sGzOAQQiqk$<1PNeB1CD6SxG>{ub|7TW%YVg5J2f3fjFHw` z>1fboiucr}DD4+UO#&^b>&N+i0B-s12{syoy{%J7$d;R@W9sRDqf1cn2xFu_9VreL3=T4~o!&%7&NMgeb zh@ItRWuoW&;iy(Hbo_A!Ci9>5H|MWP^oI)mDaT*6Q+_)@=$|V1|55Ayx}^MF>v91i zj{mCG#av9>Vm;^6-xw^8gpyA6?w-L1hA4fr0Nvl)6T~qkGqxmGo2?uAp$u`@HP*E3 z-6th<>1wsgGuwlE&)XX}>If6^WY(z%{=_;IkD4OdRG~v&ExWa`aU-e{=Bt|t`cz4? z-4AM3K;w3HdUV@QW&L?a1m=}DGGa_mCdJbtLjm2T8P9xPSLV1j<__0ev~MI6#0d;= zVKvbdSy+hEe3ibOnsp&Kr^;Ax6Zj}$##0=3>XACWT-kMFJG2<(`W*n(o?RdU zId(424{;{V5KmDhYLBp@*GX-h3z=jX-Gd(|>OnIYd?V7;Ca!yj=toDO*rbjBv`aga zDoR>H30H>=sz_#%iL9trI--z~KLkrRq62MOPdOW+;BaBdN8TghqMHyf=O`4d;?a{g z7Be($#F^mo-f?orv%ejm8|@P$d=D5K)TDDK4IbhHp|WmaDt^_G$LE3`_U1bv?W-13 zMjAMXlr5iJ0dBinLn~!^MYbts@j+I?=r`Cg;NNZrCx|<|V~fu`H0Ib4CwY0gR<*W) zh+JknjTd|tRc=UPB^l4KY12`oO4Np*O80KyZOxTQvMBXtxl5IA=ox{n2()sWx3tY4 zVNbD*`dTi54YtYlF;Fuy>#GsOl?({7rAIN>ag;iHsiNvZ5w}0W8l7T@_vnpaUyJ^# zmTO3jr*uV=cBs0$r`}kOsI3+Rxezc>tw;gdKvY9Ct17t6DE9cshH zwsW=muBp6g5v&f;`r5PzGV|o(jl?dHPQ?ycF5ah`GdK*b1(hupnc*XPM-$2wz+ft8 zGmdDg9fU(L3|xf73H4HZkJi}2}q;J%r~|A_%4cESuzqhLTc>_PKivbqK0#> z3#5Ds)rlB^9O21VAQ?{s-MyG>`+dLW8j)SN^5vk1QzE2_U!PJh70#+MLez7zFMFvA z=9-$w_wR`EYa4y8)zvF0&fpQzPGC=p)ZT-ub0=}zVJE%C8hnnv8zRz592zJnEN@QD z#(em*P}4`GOnu6ebDl%J0!VWQe98Uauz}UtX$w4AA4`bIP+fwN3Zh+#b9J=|*$=zt zLnH{D^Czq~q%r6xRj#d6^GmAor5t*I-tJI#X{~s__Fe&4N?hocA@sh144ca{%_pgzuZ*7*POhp6ex$&HIxuta+^nf&N;?V+MD5~Jx5Sm> z0Y-pCooT;r;T+mV4H4H#P$`sBq_QT19|0a@OfXe~zMibBeaN4{Pi&pkkd}q;gMYiBn2{a-m zMn*7UYf9adwhQCtHXKE68YSE9SThTT8XH|gETh<)t!r(50dFV!USkGELBS;&fq2M2 zMwYZE(}x2@u!KJSiYOkhjW-+NAoKG3ZYJfB6JpL<-6stp6g$whM`0`X={Lkxmn$J8 zZ?SMxby&)UZl>f6HuK^e%f@=pU=k~FKe8~A?1k8M;Vfy6BAt)n-RWy5zG{PE?1M=L z>h_$KSrCGaq?iD2?Hu0143yYm+gYJ4Q!c^holz0b^IC@D$Pj|P7#HWhb&56!3V>*l zWo~97mZ_-a;R+M!ZG(}Mz&a`mp(6IowI1sIu;As~!x@zS);S)# zxsvc|py`(5&6f^O-R$=%b6v%S@)q$2mY zo5=T*3=H6lOG~!}@S?dMMVm3-5}eV?%05ikHszd5y>E8#?1FOBKNVPFMDRJ|FBXrp z_j9Ggm-)QG2q6!Zya9p#9Zemd%jlRlgxSn{Md8JTWd8~J1MlS9fx1W&gn97$;5%qK z$L9oo&Pl-hhnMFAU6$%Coa>Ds@H_hK%vMaDeFcB5WjG^-cCgbMt+xA056mo|?+2LoqTlO&U`<;WrV=}3lCj|B9?_?$+^uv*CCJ1U*z>vxFt2|E_Zw|^Zqjn1kbR!X{ zTO6Ei+27z@B)lHPsFroUl_UazFE94Oeem(0ZSu))C$8yxX^bZAM36mT$)=G&NhFUJ zs;4{1fFklWG#{-#ap%=b2}KPYz{QBKaNA3kr|(g*oi0fEd}9!&%%w3DpYyb1attTo zux3veaz4H8^&KR04;Pgg5&4`T=UngP-{75J9gzP4@B9D)|AKe^7D@RR@eY8V{IiCC z244PcGnW~V;_ru1_*>rhpU?j8b^R~5 zj`LS8!%qi2T!DKY--^=feNN3GgR3`@bv9&dCMfYIFUGX29_)(ELwgGXq#3 ztbl?16GwsbSBJ|#vF~s0hhIDn|AUX7>(>_k285Ye0BrQX2!uNThth1ZBXmBh?^DWu z#JngOoFHNwzBNg5Zgrzrtu9W){mOo#CYI`Tov!!#2o9x`Y7^sD!J8tTRV)Dn#_tdG zkkx-&`AG;OyFus3pbnuKExM9d!Wf}TvsUBzP18zt*f{T|Vb}3)f(-h&ears-7C{t2 zrzg!#xKd^ChJ&SyKLyBim6kPcZJwIPYHlbH#Yx5hE7=AWXl zm?J>(p{g|sgGi+{u%irGa(vRCZ^dz|%pA^pY0a3w1Y%$gM(=sl=1{!}>SL`md;8^u zO(7EZy@kk87K<))P8}%^V;`&vVY(pn(L5!-POS7B^Wn5EQ|k1|;k1^WfVmLuR$2D| zTYAxEKM2JY8+~~o!cAgBEqr|+VH^+N#)P03gFJs9Cc{(s$%({TJ6Yi(Q^lF}77GD7 zI!Cs~X}%UgD{k!LIokq1>uPU;bqRUbj3`>?Wi?Si-W525E*pdSx$aojV=V>&O*^@T zDmT@S!psZ_4GtrX6LF`KWr>{M-i$)TEU&KfBI?IaDYuA_%Qu=rMh0hC!Ys@aB?X7= zj6f^VJG4~XHpZqeOmU$=&AppZHGO^wCi0=t($d4KtT$EWNBM+ao%XRq*qhYHDiz;v z2jPZ3QGxk_!+ggbmr<#-``CE-8UM<;XU#BK5(CknhH%J8H~4I~1qS0vCvaB2d!iw| zX%9VzF9x*B<#En#8%B41!I$?{U zWDY+mJ+`l>2qKo4ls{)lz~KcEV<3r!xh9PYFR9}!WHFUqTOXkeRt1*Hlc{5d&+3*E zK_aZ$&WlQka~iI$B@=q1a0%o0m23gZy~8M6Rm*`~#Zx!lxv>zrE`k!v>P@fH9!J5t zpZMoBPAb*!5Q1N|s*pSlY@+egJGt9I{FCL0f{)O0laU3I;np&0>?V~{pkTEM%ZA8Z^R-kQBa-)>lY1S~t7}hpcI0&jq4N*S1bZ>r?}aORIO9YUfu55Cl(FMW_b@PaTEDXUF1dqwEK|NUq6g+ffuw@}iVuV_&m`N6IdoSxA^SG@4 zhC-oEolCZ5U(8;(Z`j*CNIt(%V?ta5I5ZzPoD2-30Idhy4_8OZlTdamKfy!>IDmp(a9Q)(Fo!jRgR(dN84g*j;8R1AqQB6NCB-}kUk2jlDV)BjjX?l%aGMdEh`GhR9 z%v}>Nv1+Wu?52JK&|nx{(01qYiSRE^FokP;3TPWhazH?N?&0ftB;IhyWRG3nhgd1y zo)*fTqY>XHDy9!1%UnXiro87^owAu@8wiOb3Ih^~L-(;>&I$Qe--xmdXT5`;r+99! z;KARA+wdU0nqy2V=@Ly!#lSDX9Dq~}3Qn6OqZ>h5h#nIzO9YJ&6+oo7etP@T22OoU z-~=);98)Z-7^GvGOsq708ogD#gwXkSRinMmfI=ClN9Rv3?%A9~@6QG6HHzp4?tRn^X(`oA_`xGpF>hocJk8KKHJ= z_zF(myjSo-{WNhd9^CtM5qzudQ80E$Qn2LUL&EX(@Zc<`f|Debvmq{cse}^G%^@yq`2yHFlc$_UpfEbNYNnQbJN^ zd@MwlF9e(lA4kMV{x016lm80Fn8r%Rv|=!EGY*s_`36{UVshoVm*=}LM`n{=Ypyl1 zgSClL(dJ*@`(MmiySc~kp@*mn?qKS;&bJ9oshif~5R7~c;UR7Dse!X0{_Zm8-*g)G zv0B$^*=XxNqQMN5_NE%cT8BF~`IY_T7-#G9mMu}R#cer>)6uW3`SImtkOfjM|Lfd2 z>?tXsS3CI|Ppzr&1rJ)Z2$1HH01~||JnGwxwJ7a0!G$J?y+j0Db>-$g=wN?Vw{8r` zbsEU0JUB|Mt;~Ym6%a*!+t7~~-EuI#ppoEIVP?uLS8+raNkx^Y$qozooSfUx(^ z$$aE_pL5EZ26J5M*iM}4oM%2BF>Wq+fyRCgbiYMNrLFoB^S&F1SS>(+Y)5@@Iw=yN zaY8nt#eM|!%h^IAJE;_5((sn&O^EUWox@CATR9ddrdr&M8j_NiV`|3s6Xe{o>hwj> zug8@jbQuaj)^(1fNR*AcA)n0(J~CI$4!HX2?beV?wtxDJ{?;(gdCk>KS{asqO{eek zW6O!`TxpL;M zLeKN$^Gb7RKye`haEJpbdg_1-;;(l9uc79=q zh;}F^Zs|dC(`|GsE(EQ9ZxGj!GIrIA)6VA?=qORp6)quiP%rY{gc{vAg3^qSR>ErG z>SJ7J-l4ncQb`>24pO?cT7-7HteocsDwSIW;qyFw*3-k$`(RXMi99`tJ>upFr(*LxtSO9L*=LO1HkBiu$oyI|6rm1Zm|3c zVE;>lg^87so(sTyVP|BaX9I9>nb-hfodEF44nW$h|9>Pp|0($YXt4mu&GcN1KP(jh zK^S0NuyOz#*#PG?0L9a@GIIVE>h&+|W|lvNm;UiJ|3~4NnOOk5aDZ?C9ylX_bPh<* zNY4iFw*S1(`QHi$Fc1ILoZ|Y`H2z_i{QL?2MRV#mm;8S!%)$bov;$oK|7z6yX4Cwq z!ps2EmI*+}{@23HKY#Oo|ET}LBKnO({r_Yhu`vF+WAgWX0!~1P_g^%Rsx|Zh$rIuH z?#d>Myw&T7sUlS#zp_m%)r>BE?cj3;B;#3}Qf*R}v`w{p3q)#4rIvWQIjTGM775C~ z8xhC@sh0rJoi?3GGC$hDG8HUpob)?#pUh0>Ysf4Cs;N>bfKbd}NL(-TaI$B|LCm=< z%P$ughkBYWp6m71_;uO)@+sRKc#l?@I{kw|ar&@IezIXt_w=Q-yI#%RO>$U2Yobut zW+<8Ja zY}d40xvcHdV(}?pIsIKn=unzOWh-r3mgTx8*7)9H)R&3&kwtM)(veAnQ59fLQhbjK z;?*g)_YDEDK=1VPx(LIwsZ!y!HkgEtQ06u^c+VLgY`{C)mzxe9KgQfU1=A%$#bN4V zmF7zGxXc0USSCtZU4d8OwxzyK0e=Utg#K|0*d$i=2(crbs6TrGLXx7v!|hBGw}F){ zAo5}^#wCwIf6IU?BFHT%T~ebxBj4|W7M2}#7!AW#O_pEQlYZMnl+SFCKDiHiD-3js zJI%e<&nNdwRrCB!jVNS51_DMKjA>|FBv-QoOj=qkspNsMGm)jq0$MembF5)v?Jb0e znTzI=$P9XF&9@p?HV=driMtaH&Y9pj&6C478cD-BHb-Z)%GW zEjRXu$`-MzZD`Y=9HJp6YaTbrE;h!vSh>X|p4KUs)arFo?N8wFdY;Tlj4fL+YfZJ+ z(o=2up1*?#fcB-zh|ivQqS*B$6)-RXgedKpNOBHty|f?k@}|Hkk}EPPYw?}(LPrVu zEACyi7vi%x<`x*d4;YedMOEyMT3lOgIBU*?h?|O-A*mnm*2VDf5=i@oZKwThflK$3 z!@RB^fq!II@RD9k%&I7pk);4qZ#`Ngaz68XS>s0uto*YGYafGK|7tuyOr@B_CH^sd zMO+52s!X?q!DU0CC2$^eKb|*FQCzSZL9hC~&m20V>wv7hr4A4oIMxR103V}QcXKQh z_>&LRj2m4PRSqJZmj^*#0=hbX1IRQ{fGBt4D~C{o9{2O?<9_~x5px=0?mDPM#ttlL zS0J?jY4Y?rMr|#XeK}>@{k|qi{D!YO_(FsIhi~k+LEom5t8uoMMKx7T_12c|6a9JJ zvSKljd}pdoz@F^7EbhvcnF8B6)JxK^sojJx*&Wg;H#!Vsrp8F zxVN&siG};FW+n=(g1`o35+0@AH*v;GPcd$>ZYD}Z_=d0zRk9bivZ6lF?-N6gx?t%S zLiVb_cRHVU-|dYrbDY*ChEkPdlM00T8kzho7M=(LgA)!eFXA$y0y8o`-EUR)K6I;Z zomv_OI&Me z>7&-wHs?{bp8poqUw28YhUDpwM2OONnv{G8m{kqNJEGQv*UoOlFfaF;GhvHIb>Zys z-~|D%d9!yx$m1>}!AND$2lx$-#!IMp=6hS^Z}Mx$JQc@dqTXRzN18?;GU*`l*tZ?& z8yi^Y8~a;Nt_qBe(89jucx)%;UEe3EsURxld3-#)?9Cc&DB8opYvA1Kvh5DbwZr{D z0*U}CDxErDWYE3%1pkpf&G?iUJ-Kfkg5n0FyiO!LcSs*$4F4QM{Oc^Q@jhbRo4Z_` zV9D&fZi6m5zx9U1tk_!>jp79ei>}YF2&YzU2^=wAC^SxiYC4TjBIPDnZD`Ei1wwBd z!oOsw3mkPpp*s58^2qA_2C$+ooA*q&(F`YG&nZ0XQP(IZZ+a3hiR z#I`sv*yr90nCE>?HKxm!RSPq7&3|V3WV#lOXra>@>VDLnuCA0f>S06-Fc+XCS?JvE|)-*Z|uLN#)3V+O6!GueJ)$0$mVghk0-K&0qRb|?Re$+ zzNKEOD^8Dfe-5p_iU#Cw&cmJC3ZcC9{iD}j)7Xc$ANRtzT1~pw6KG;%5gm7Afq~o; zi`q&Xap8fw$2_jpngP2r5>+>1vk;Iim!&{JykDlYdvEq@Lgr@44BgrRiA&`jo%0WR z*G%wUln;g;%T)iU1t6e?Df4L}(?2COprsc81?rvx0`e~c23ofO`gv{73Iw<|kRVTM zN@G|lqI37IJkeUKXVbs2EIB!q{=lqd=ufZ;v3VW;el8}C1oG8urZh*451&2q?m$=S za$45#R+yw2(fWA5A^|Z^A@Z|D$bkv3k{nz{l*`uEaLKZWBWo>zCY>=|XM?s&dn3<7 zt$*X#hsrOIs|Wi;!lj>V`@UfD3&DE;dPbmc3MziqbvLlqD^1big@@<2XzM|AzBILR zv(vIN^{9jteNn@(fD3OeZeEOohsVp+DgAih!72{gQPg(yRry2FmeSyNblz2EIcx(+qu+OEp zY1+_J+ZW(;9pA9CoY@zH+GeIzf11^B0j|w`Jz2=%xyz@zHW9N`AB65txGRNUZ`YpK z`7!;pDe*odB5`^i4~{iSn=GyD8L%3f>9$&)RVisk`B`H!7}#p+k&@Mc#EMg~KnHo+|GMw(XFlE0>=~i$*^sQ>@Zk{fw#ufE@5B{vZ z=V$G{x~;^0sq^go3!MX@fM+vyP+V`{$koz1Aoz!+|{wUuR73^ zYMeGy<1V#j)bO@=3JmaL!<3ca0oP;{0Uq~bg-+fAMPKQc8eZwTjtdMb{|@7=8r4V8FQz1v7xS^dIR2U`d?^DcP%W; z_f4Z!uNI=~L9&Yqa&DOI74zLFrmg%M`==%+JhApwx7}Fw%Ax_S&Ej}s#i^ecZa!Le zL!mbu!gs*E*>(6?ofs|QIP>HdK(fM|f;5K-a%_|OwipFfQ66E2B2rk{i}l!bKvNxX zO5NqYOhTrm01?PR+6#g>v6nO%g#C!h-gEu9>b=I|8pIG6<~cImC*MBi0aQLWIw?N1 z7zF6R)6&aLkybB~<)cGCaz(`t$wTn$_GN#(H07C*Ul&}eiVkQbT1B@APp`)EXW`cL z{DcOlv`&ul&bf)n(NZmU`&UQS#)jCrQGY-sL-6~iK!CcVZ}sM&e%!Dy|L45_E zyJm1U(}#t`xYzbk@RpHy9X>O7nqBn%Pkm=Sx8pR_d3Q{LuFsX}WI^frN;O=WMO<1D z%BgHsChHclyB31fqltpd5)iR-2h_PJ6lTMOW`Mh~Z;I<_u}Fh{ymRZ3V#*{9!Q|Aq zyJHcnwwY`SPlLtzqnh}UdXsp##DF3fZgCoik@`?{7I7z5aabkIR5(DT_KoGEOo+v)RaWUPm7UI3mHt!W ze>BClw5OWdPm9$zHkFz7dsluo#Y{PmJ3fV5-A6Twt;TH6D!%p*+vRums&J9a`Lh?S z;(kmOmhXOPwe<)}Hx_@|=pTiyy>Oqe-V(fOdlo%p(1x{b{jxB^12%%1@+oP$@sh+jGg|IxHke-;ZY0XxDAGL8Wwk*! zCwE(F|5G9NO0);=bAm4}-7XITJr-$izsV3Gf9%BZ{^~5A6<2HPhs?hXzpckcqk{IP zWWAQ9kc#ejeQ;6G2^#x+(Hff51bA@b#`ti&vUiCe^@$LcwHj*GE0yZ{07{P2$LVTC zw$+r&+ALe_d6q6JA0`P?4=v3me+A}ZsnG1rs4h9y)l#B2R--;SrQ=1AHEP&6vvW;B zcXPGMZo7bmg=X{)UJ}s1(6J)r2s@SX5RLSYUiY)N^>Et)6xV5zfS|VOZB`b zpsSvqGay34@kCgTk#_6z5fuztb5P?B*YUGbpST~cc|E1QYrK4KFkP&=>KL*WQp4^h zR!q4z07cH5OopgBYZP$KN-mM#ZRw&ResO_o+&G_=>cv~ROtH4=q#+a6ryaeMHB8>I z3Hi}un;$(!o#4|`7n`6dxMlPZh@aJd^vQOrtU1k6-rQtkFX@_*%K=PHca3{&%1-D# z(XcWwai{BrdY$p*!`a{r<+4>Tl$T4@Y-PvLfaT*V1auRi!JPhRmkBWQoEiyJ{?_@ZkzX}fjL1LA{_^nvYWHu7){)y2 znx7aW<;!C_;T@>*4`n)Xv$f~*+d9Aq23rFJWB^zkx+j2uXv@r8A%OgId}M%tIIUhk zlL3%n=0`w=TU7$Z!~tNSVkN}Kb2cEthy<#EG+dzWdEGHWEqtJJI#|Y@!;aENAcOwG z>d?`cBMS|nk)pr|4vHoRU`p%?uzYe#*!WvVe1GZ+{6n`6L?Gw<_PvWL2r!^;6!~eR z>WM%=YR(z!z(5*9{_l0F;(&lCTO3#10H9QL?qyRD2uPsFMw|~72NN}`LYWA6Kf^TDgU0cvQxaJicXuT~qwk-7` zn3Z2qhZ}rlXa5;iI^k3M*2a6FyIKe!Qs?X2yG+NZq9BSvp?1zVepbf=l_n2XpmpHb z)tB7Cnh7WAv;v&ho5rHb1Si04k68ZfBsKF7%TtznHj|lkgz4@FOXyU9M}!eY(h#(| z;Pkpd2=oWHFSivBS?{a&dfbq{7?L!T!t=(x0!<~YMf@9c?$`JifIIjP`|d9~qM3eU zwEwB}kJBv~ISAP}nCUrK{+yfkH!jwn3Ij-1oB%dFfXoCqndMK8=syg~KRcp-b2tCS z)A{XakY8NXKf;85PgBbb*pv8SZT^>OYFPkX{U^Qu?_3^MW~RStL5^#WIxdU7SvjI< zCar|X@dbf5XRjyw!Woer**~Ttn+Prn3B);|==zkV_IQV0x+m0_Y~ zW$zlaI_;|AOb?dZFnU``cJ~wN02MNAo=Gw?`He~Elg$H<>EdzRJ>pu&E-~#$_#4!B zktzyeMi~vG_gFzuNKQS)q_iorRs9dgUFKcSf)t}H-1i%B_{m4ZdG>P9qgTTZGAPu^ zk4@Zd{EsEjDc?0Dk&ej<&x8_}p1wnSs(u?^Xl%mu*LeiZP111`C(a-XG@rTmv6QF& zK4k_$@#yHLP5Vt174h_2i+j#B88u1fm1GaNA#Y4#C+keG&=}Z!G!j)I5-cL=h0hp8H|0;sO(}B8w?ikSks0sW<5lUYnkL-$X z3n{qKM$rn9Msr)H<(GNZrPvw+lBE(^xF%QMlXLGRCGQ6FwD}(!;`oE%4oxY#gvciq z#iW3Je%MY2xorovdyDG*09_%+$rXy!G7Sb_wDYus>5HVf9GU=yi27qtQ>EETSY&|sY1m$ z?9LA75?31S8UY_bzz)_=smK}whQ*p?lxODmMsy1|IPGe0)3GFswT2lSXj#Ygf#QQh z3Mdz~Ed5&h%fXYtDu{P#iEK*|D>&L7=%s62BB2H%^KgFJES||82F8Mio}NCU1<(4! zPR7*|zHIiqE7VyY_${pTvgw&jLr}Qkyt7N}o!-Zs0ml}aBTtD}#eLQXf}O1!g3J4P z87D%ejMFqFz7D~mk2p2B^~XTFJ)}y)K4y&NDi6hPwvEXIYw@KtS9!->5p2;y zbldnF!Oi&<6HjBTS@%|lda{@6WH-bp%yjCUjH`e#qJlV_>v&_MJ};<;AGb8?90+2d zG7?Qbgh!P`GLpx(rPE*x_AeQb(7z${x<@$rZeI2EDoTBC{)&jjiptLe1cwD@RNvSP zc!Y^XS(jy0l)YooCMJ)Jud|l&u*2$$_!B+E*4)_uC5JDDf^X;A`!DA_qLP^dmu>6| z{%b8Dd0TEwiL2jNG$wGmU>#q;eKEk#INrW1T8NCh$1@i(S#;=f+S&ZBi(}n)#yzx} zt6vaG9~ND+gKhYgJ+*mYU&uX2v`RRoi*9Zw->_d`6?+czdY~3$9}Po#;ri^>z|7(< zN7_!0!Y6v-L(Q5&$dmaHiqYgdTEl2nV`$(?hT33C_pTnKA>Ihlda#Uulqr%_LMOR$ zep~2H9W-gEKzMDT@Z)zcNB$UKr1E!xQ_&s_`|H&Ff%HmdYRwCc3txR6G}T>n?mU^CAp(?lI@L}p0R*5?eUg19cR-`=d2easg6_2EIpOfb=LT6P@>R>e zOg7VCh;P}{BF8`u)$Fm1m+m#gu@iXqqfGMYZWpy!iQp4fEe&(Cc8jj@q%L(9)?~uN z&K7=3yB3NODp!1_EE2l`E^2)kz20n|S-*9wC|^mK6t-5zmt$2DWhNp|li2=xN%> zXQANz=_fO}PYX4)NgrjyrR8j*-tY{*)Uj*NuES}6oy)DMYmodF%EBlR@VF;5tcDm@ z*&{pTo{9zE%Q8O7(pT#hH=lKN# zjpZS94{cMEx1!BA-3Ci@^;?$|K%T`kMwaw8nj;K8ZFWtu;_j8eeA1g^_z!1hEx}l9 z!JXWg2gM*u%;B_O!W9lIar$+BbfSpZLOywTH^L11>2i(bYpmrlAC9Www=5$!TlR{I z^hTCiy3fQ@wm~tIt|3V4{bYeb8x&c3I_n3o8SO^FQyMO-5I96z95!m158pkp{0U^o^?J3bb<-Qw^+SPlZ;=JdcN?L<;i z$-l$qS3?0iT1<)fFk}d{4U6RqPF|?>d9ds(=Zmsv`ROSwe?V^NqFN2flog=QP9b9z zVegMnK2dp##O~}K#mig_ktA3L#l$;@w7w3Xy9`mueUDh3O$59g?-UXpi?Qtb_6X|j zqdZoR76eL<<_<80HBK`Xh&oI?>d8Wg)RG3DEgXp#@RgqWfZTT4&fu9>G{xr(NDMqR zH$J^_6}j}pg}ba1LXB9KFV}t<5(uLI1`q#A$o{ufpg(Zlzie;(cQN*V+TQqa%=kaC z<4-L7Lyo@)!+#@X{HMY!oB+}f03QDSMt+8DILGz<=>F>Zy5VukhFrMow2g1 zGa&yJgMx?{A%lvkyYp`m7%WUbc7py6-2aY}*#Hp&e{r8>JX6wbSq#Ph>;auO@Ty1d zgT`tWtc^6o1gGP`rYZR_FgYQtF+Dy~WcAa-`$KqHWPeVzM>5C=4VaLM!-@};!0j5k z-hO2J(M(E|Y}zXmm}MfhMyZNo>0{=VhiTjDBlY)ol>}W~o5X0Qq!=s}qM6HF(o$%x z%{sb_oG?=6GG-zYAFMh$zMu6obWLfx2%5ju>yC-^zQt;yG8AQ6){_tlsrSl?%8K&y zl!dK)hrI6@FhHPPjES7V&HU2zEzoit;)M^BqPy({MN%^1&0JK!H<40G)#GI)&B6Lb6 ze3|AY!`hKY3?z)a*buaDeG|aU2P00jW5AMrYBG5}Kc7Z}`c!11jh0vpf*zFC7@lZt zIRecfl57I&97B{$CmC$VBhQhSMrLGVpmfz||J0r*447lk zS#I&FWK{gyVk*5Af2jJlWSLxR`Sq(7|ku!d%?j&XHGB@ojPC6Vu^8kiG&QAjUGfuryj_s+Cfh8BZxR>Br%@{ zmfUyO?irvtW&xd-;ou6lSl#QpNpngcaB$(BCcwoGw|J>*dR7i!?HRmQ@J_cFIjuP!|5|$X3K>Tz zSm27Aa-oZYnR}RYTcYzkRImyrfTgm?tB;l(TvGdUTHh==9lO3f+z_$f&?v74~{#(P3q>7r@Toy2kpXK3e` znSSU3Q^=ffg<+5+A0Wm^N;1$@jMzKTSPX55bW|^8%I1SQ#AU;kjHgg&zmVnDT*aiv z=Y?bHh7xno?{wo|1_(#pu;)N{P+4`0V266d5^4Ru`iwDIIYaNVzRwg66FaF*zwkd5 zvafG#fRvL_3z1393L*+ktqueUp>am|Y?vp!T@zp_jmAsmruxC<3TshmvkMaPMx2oA zYbq{gUx(zl8z+2?95bc4$c1%jGVuXR<;Z~+*oa(Za;n8(CW7+g9>$i;zZBry0;QYCb$aEG@UsV}&BMr-@@V zZKN*a!Yiw-uE6r3^M?##0(o6)6NY4_^UBp+h8Gc=2zk3oXtOXmO}+)>nnTnL51XXp zktBtzu7xvr`9YXyy;`5VJ7KTKunq+cGOOOLVX|4xBiXPcZYUu<;J5FyMt!D+5FS;M z2;9ujw05QgF%{O#7P?A&;5p=62zWN4?XbC9E-D?9C0Wu9(e)>V^OG^*g5yn7;OCvW z&6I<5uV3qa0t+(Hvas;PVBRrfPne`KCW$QQF_SL^ArE$GSY+KOsQAi)GKM)V0Qe1qK3Rtzzs znChkOY^1MDFjqOrZ8^vF+`SG@q|)n89$qH1*ib33M=}---TvJ$D$BWe9F<6$CMGh8 zJ19sPSF^IpOtEN#WP7otEEZC#c_;P5Gcz)pR;elWHzUn@`Uw=GUk*uThn5ZWkWw$O z3MMTM%|Vo~ro}~vM??6;^avKldNB!Jb8US`pnVTj5wIC2g{$7|d2@spIlMbDAtn#? z>g{!{B`*Ut^$BRYHg&p2H+`YLguhooGZhbP#Psd5nF@ww4ae!yBY&}l#Cg1Y(kd%t z&Vs7Q%T22Y(W;?-(Jp$zDgM>Rcu<>}o!HJx)1O2zXr}s*z}r4baHY<8AgiSbwmjsQ zhvZsPBZ{>xh&$|yNV(7MvkjDY_iZWFj}_za0A~qDm8idxGX!qu7OS%QrT4V4+31Vu zZo##CGC^gmZGWgqgUtz%*3;u&7_cn}nMfqSXZ0iSL9sMoKh zQHLshoEz~qY;;qW-Qj5DY3}sWm{$Wx>9YhHDUzR8pYPdbUh?Ku1(lsUpAYv~?BCWu zAB1it3l0~m;^X` zD=acNa9ij@rN<@0@B=Nv$*-SdyA$S-2%XDQ=U>PS4-RaNfbH{B=`RKAf^2f~}e;DK_$I5=M_`v4O-Zyum&w zVk)c%vF<=re%K04oi__u!OnW*^u)3eH@KjtL$Y0c?ORKlLdyRJA zR8B8atsJ&aEt1baQRBoin)*&Z@+K-p>iw}-Eisi-dzK-o4lF+W%J7ICpS+ZT<4k9y z9|_N=%?l3RR!NS5`hDCA_ucji#{*yB3gW=OLwAP1MwI@~(EWGt`9Glh@5c9kJG{!j zS@AQ0ylj6%>VLJ`|D)`mAoqW1wa?7V0gC7Xiu4V#(q~~{2N}k*&~bnWYFQXr=@^*) zwx98zk-u5!nE%ZHoe9M5^d}7e?ac7I^#107<2O&+KWqOl&kTPnE*BHSU(aFxJSH&w z{kU9>zd6P>A$J|C9*8NY(O;5mWNwXCj8zRpyX@|4-1iifVyPT5kd@(0b<470BT=PHO7dKSn`6no7 z&P8;t_g&R4cg!=wtlrOT`LCigj`e(C>Z*B|BkZbDl-pS6NIjpg0%;X0e;I{shhV$L ziI5)q-zSTZk=AWKoT8V0lC9C5^|_l?`UD>%K;)qO1YiCsR_XoK;gqM9km7nmi z)QklQM$_W4E8wVsI|6TGt}=-wYeQ*CJ!tWsTI|Bu&ln1mXUR+m)nKlZQATtw4xgEs zlBdQ_Po@^neT=St(qz0bkEJ>~zrNp&wA~A`zw|i|>MNC-Nc`fO@kF8Gk`#CZyQV zMe&m8KVG4?_`#fy*i#jO9~Rq7&~Y$kx1Cei^uu&$H|+F09A*31uWu;iS>5Q%Ry{*V z-!_9)s9{_GVf{FNLafTgc2%hht=Ek3kDE1eI2=@{4vY3ZIs7&JCOm{=_^GdwGIn1MJ zFvMN9+DF^<_(WKUR5*e;AEpavk`;1P9SqXgj#aW`;uj}<_s8okD2b~B z$plC!aI3ljw;$=($i#ze`0f~Th{hz12WW|UoT;tU^+QVf%)o6ZFb^@R=HSZ&jEeeVNoSl9OI*F%bXg%P`s8n%7o77%;3sQ+LeWFTl5W3I&3s;Lm zVar8N_r6OMpW>Wi)_i}r5E?4yVpkGP9UQLx#KZ#3sVDwO5;UQZwYT(C+Ygp>AG^-8 zT+RJatCjx}sbXVS!4TUSE$@4{3q@bCzj zdPAC(>2kx{THZ5TV08;yzWNw^R(jSx2UJj9+gf$2im30DclAeK=B7@GN7nf=k7cpw z0~M<030&V}Y(GY*VLWnGKI>OEEoB~@59gdG|DeaZ#4KYfW(e&%d%lOwd6$y}#vL_v zt;gm`hNNAl!=aSP(UBck>w5!kDA&1HbBBNx0B$}I0*U!9Ja#Q43WgUB;{LrN1Z(yM z!(%xNw5+~kU3s)umAk5Ae5cKt9T z#{-Td$YuS}df=0$;{t|z@vEy--d2-&*AHN7waeEw8c*cqz)2fiIO)xdodSvZ=-r_X zK|QKL_I*^dPSF0l=LacQT1ypX?V%!1Hl~sS{Z7N?@X@j? z%2}y{FxbF%3-BheLXHY6PwclPu-v3NoS*be`lZ!-yY4AlgwBV)FVXji9{3*&UF_8LM-NjT;6X?9Y4Z)}V=Cxgo4gaZe8-GzOLZpY%0nK*xCE z4yuDonBE$m8ucXMdf1Pjw8vBK4^mz}nm*H7-z?0STa162V8F#Q=P`yIcTS0doWz^0 zfwqMd9}aIeW7PxwP<)(#efOz=t4b8Udy0Z~C{PJg)E2F$78i*5gq)Thyy@$dpl^|C z|0{4)w43_L(~LpaTX5xjw((0gRE%a0G}N$N=Cfx-1^im=EApDL?B?cQ04F2`7 z<_}-v#;2GTRQTcGaWrabV&!$;pl3|7|J{|8iQ%u>)c*oPe^>3o0u+D_Hcs}2KnFr5 zkaH#oL;l}@&_7&B{}qJ(Rj2&F1fdKd(8&fe+Gk;6rekFXF_W@`XlOt*mMkDb7UsX@ z|M({_4*UObeq>_!tD(g2*z!RV1#!##cNWn93!)h&5PQ*|Gx`%Kv;A#-y2hCE zaua&iF*P&Ee7W3~aIE04yv7ZuvpIEE1KtPi$y@H(e3nMAYZ$-FM1Vf3WfwP_!C=#V3Lsvg@W^`ecFW0Zuy}kQebQ9wv zV^Fn?aAZvzV$2$b{0j~}g*M?a@f9h>l7UgZyYAQPGdVuw+dnC=-dO#scNg!O3Q+~F zJUj4V;%&`x%4b#&?uLF0ET+2->FA>(*nNxKiQQ(?Z?1T^qR73;OeLk68)t=A^g&{bhRf16W%l~WI=<+ z`<*Q9{6ezI>L=4~B-y1>!Y)Cc!%C88(@JZ@SYZGpk$miZJ=Kq8KYu~r4NgU1-&h@}G3(1!hz}{yrb7D`2rI}nrN(xuMYL+j zU^0_}zeGx6*ec4EuC_$Fq3^heA*gwvoT15=`bLYgWD7%;hX^;Z(OZCp=Gf{(%GgVl zVO2|iZK)7SQW4^jiF!91cye0$nI z7g`=#mYHF~BhnVAW3xmrq^3w-NmpC}9Mt#xN943_Bb^);Kh;UcMj(oXZVRb|nTL%# zV0Y5GNTMb++=V~7ndmIYo%o~MTkE&m%j?GtyrovvP5apcb&lAB-r7otYK5C1mKF9O z<#NA{9K?aadbR0d-hTOIdL5VvJ#WRkIW@0gM;_jg9eJ$yd6U1jMD(1{xne|+E4C2b3QR)^z=|}QsShjF@!z^ zL7{h-lx%tTtdnZYZ{dM(6nR35_AN<5{sA!w(@UTo9<8^H2Cn4pYlUyZ+~(@U@&cP} zK;p;y0eor++qZ-yj{Uvs#hUJVXNHcmMBZr_lET69ya+6QOGG)N-zQOsAAw@EB? z>rN6R?~j;LJ`|7u9r=l+(kt}C7UK0uzGEN9g@#zE5fg2&pd1G6lWg^R@OYsrraI|v zEWExRm43$QZFoTup!e!r`7m_1Q;^kE5gsz=(CBhBa~!V1Z(X%kl!Fw-J}rwc!N-{B z9iK>11a%$oc8&Is>aYJ}cHszF_M@d5*Si{)?}z<+iL(YC9t`bgXcEishyuUQXGO_z zS94@lOen2#F9_cra>C36`-qU|4PnIv;BXwzhxuCTnYsJRX?-J(CwONxyWB3r3XSjB=I6vxRh!}t*n9ecT1ffM#LSpH zEaLivIh8U0{jqLJgi@SP5qZ^^_95Z1{gm2W+sg1=LnX3yCC1)Z8>2^X4YP^0O?AR+ zCAGkG_f#$X3(rP#&-ua`=?I7rvNbRgv1pC&gxLMVv&-9Aom`b<$x7E>|Dj|A?Ifyu{?iOj&K&usDt!PEGj~>c*hTq7ioJk3;?>$RpOm{ zA-QHbOgQO}6cNg;w8_r2k7W&9=k;UFAD*(@G%`?U@rK?IR~3ViXgM6JzDL%O5NuEx z3N4*(&9<6T2W^^zn*54C{w8HpU9vj6)bx{xVrjoWIKK-qBVgWGx@AUG`Oy`&?rfs9 zlIMNhuoMA9{epFPc|tW&y3^igzLta%1K;W}VzX?o&$?Dc^qy8xHy1wx9**{kxpJGV z5PIi$5m_y7cwBo_yz08`g|vB&pQx=FZL6!XQd_~sTiZ>s^Lh61R5+NG5iAWaGUKGe zZ4Ar4q6HRZ*IFk((w~nf2SafkXO=WYA@a}j%5pa0yViwN-np{B4SLkmajD7^VP7Ji zpqDx0EI=Aay$lewe(wZ`kYzc~JG3 z88|^W7z=FC_iaTaYjxs+(Y8bcd+Q)a(CT@z+=$JIh%~xR6!cbQ9GR>$sqipa9Cmhb zyE;3lVw~tBWGaU8rG#;K?+$kIa&v;%$vxn-wc4OaYh@A`E2%rr>V7Hrs_^sfRi+My zv26eu-0I>1HsE%L98s>xv4pcU&_M90C%0UNW8HCA1<-JJ<_Sl6p1$>yC2m(}R^0|zs@dh2n+MXgS2Yt7_GV^^|*)s)pPwG8`P zZ`+5!LB1kUy79RT*y_*QKi6a$gKUMw8V@ZJMM(ThJC3_7z#XQg!0<6sux2Zh-Y-#I zBi=_bnjtpm@polUdVkSaw%)Zq8rUa)_J(HI1pIfEEyy_bPw?`e(em&3=3iB|AQrv<1zKie z`~zJ7=}Zc8>-mp%J45b?*Cewg#i>o<=;&`82$yn{@2=!9CVD#O#h+p|B1Z+lhi<-wsiFWVdPA| zFWSFj=f7oU^7mB6pa_nCO7x0SqWOSJJ44!*R9TbuhH6}VZ zqO)Slb?gcPotMA1b5@hzkv3pnV^gI~H+EiqabU=)8LDy|?%34+)Cx-tGttux7p%fU zUxhb}g^V$LsFM@68j1?2q47Ksm`LkhE!Uh{>LEuZ$XypXeO(Wz|6)M!u)M4up^?W} zlT)D%5Q8Q!y|Y#1rN|FO@zf3TH}-wqZaj6GT7&mjfIu;sgjh z2J8OVJUi)CjHw_j&3);4p3(&%c-}T{&#iQ3#;>0j3S%z_7bvR;>{iwIM*NjpJO~)n zx;m?Whp|5fXZs(XNq@aT|I0J!x1IJso=N{J3$Xw6O!~LG>vuK5-#ZjD{L3lu_dEMP z)&6g%V$jL-&pYS;{apJuZ^yqLwf~T#u(hF$k(sp#EI`Q2*cb>REci|Pp$Y07AgXU= zr4JASS~}_jluUu3zf$^E21fb-H8X&m89>p@1oXACt%I4RjWs~d6jbP729UJ^n&<=c z?d@$`oNWL2Z)D?Q4X|^vaRfSmIkOMQR|(B4Yl+Q`7t0iX{A z*nmC`mii8+fG@%TSVvuk4ek$V0`wgLUjPCCL4XiI7$5== z1&9H}0TKX7fD}L)AOnyE$N}U53IIib5*)gw0EPe~0BAk{6M!ke3}6nh09XR7 z0M-B-fGxldU=MHrI0Bpi&HxvHE5Hrl{(HZ`fAnhqNA54ZIht7-0Rcv4pv~!E<^cHX z5)v{nascS8Z5)k&#)J&4^ngDW_W#SyC1hY@__HZCrvG2<-_eqtLXV(zLX5^{%dJ`?sUY02U)oobb=R+SaXf9to7|hxp8YRJ`UA zE6SUoFg3D4i7hX4Fx4{DUnWRUn3>kpCe$(16U)hqgS``(OuluF7nua}R$%4jWmRCn za8PhoQDC+9mZ9^Ov3^gb0OJ9Tm|N5u#6(&7ewB~xGB$h>+&7s_#JNyHWD*@ra~hjW zgthSKmMj^}1kqT50S8B+(T96es2s``98CLN@%RTz%fjMhvdO|BFb7Gl_sKq(-xkvr z6Mj8YTOMs)@CjCd<)Vs(C!&*xi^3`}H#XN_60$(164iJ%K<|S4O1-YfKAsO2X3vW_`d1 ztsF^nn#sbA`&xg*XZ)71xQ5lh!!PNgpsix8qQW{YG`;@j`SeToTj7b+i8SpgKe>NI z#*Ysln1Atu;lU%>#ktqUX)L9IuZX`pBh*JX=JGI^{#=;Lb4kQf4^8}Bkb|39NE1zW zI|-&}nBf!oOg$nwYG8B>c2tX8+VUp!@XB+eEB%r~Pfkr45rB-OX97Y0L_K;EpAPUO6O1it*|Gl31@;QcE(RJq_u7JnDY`Fr~$PjWepvNt3|imYocKl^VT zs1z|LTz;&IXIcCYXlpP^nOj_bb<~}x6i>r0;6T+^#7qCWub`{ik3i*LLFMg_Tz-$G zmokJYvY_^6Jjr7t=0IN^KZo$M;YTn`j|^aMJaYhNUTOXp4(M`a6b&l5{Lh23O4|VpBpyJ8jig!W9t-lpF zyS#rvscm@!C1bjgjCLO|UfWH4-+qd-I#>CGtm8cR=$375-Ja=4Sr$s2o8_F);Aw-|$LG$cCnco>Z0E?MVh|qS+rRG1Vjk4J60p|4Up)cyBXO5m}N|XtAW|Z(C4OE zC!-~5zq#ZYd_`wG^kKr*nW~&l`Xd%(48cGw+YLyi7SQa5KpVI9gS$JY;We(XgC^mnK?RnqnZ@ERWaaYu?4;=ex44$b7$@g1(_ zooAKt+@|PgZ(|uOwsbfPS#r*g{iLHE`*i)n&At9m1n?{{0q+XRPKg$ysvg^5ob!GX z+H*p}e_>xeaNbiK9-4-&a*mCp_E{Icp%}W>q-Db0i3E7`*gr-`K|ybzIxRBs9Yar) zlt+H72FPtPqRZ4BPuvn89&M*vFkwyzc)A+eB^^z{i1bPvNN;r1#)V=cc-6^tZbTm6 z<~98c+*XH0>Z?S_NKl`HR+<#DouEc1vV;tX!T4D%TiB_R6&SJtP^aU+M8JCE?yGVw zz4;OvH|lKUXc3>N8_4$FuxIzfL8W#yqR3z?2L*UYCo=M3rY?QfN-$5=0gvGk_p zZi<37w?p!2wmd(S7S_A2wI%l-MzRlL<66!{!S~g`?)~ghs>7DLgnL#Uc{ZU3*dW_vNq!CB>0s&(<-Uv^&BTw?|!-2ZV7f*nb31% z?~&^g04X?2cuNsD0jMNsLh6~1_(Dx|Qu;IY!;p+RuF zb>9Rj!4C9jGYNH6`m9!1Qoil6=B2*%sd|>=Pi>7~6ARfTVm*~7z+naNnh6iv|J?IW zbb7AO`?Yz4B!{zbRE6#0iktc_Q2{S-H}PXC!*T|HF6e!mm(4W z-Hs8tn7v>YlW@)V+kWDzocO-5Pz{KznlTRcPvy7ik(Cz{ZlKraC?`e3Wb*}-3AC>I zEUK;UZl>LbK;185vh@P?5_|_(FG<%WupZ_UiUdo%0O0BUfx)Q7DBz&CSi*Lnoj~3n=6xdO)@jmmR08N&dpqbUO0giROQ6XcX zWXJ`%jmnpYp+2jND-b-kXGB=AKNX>jks+#=4Wr>lLg=4}x?*Xv@#Vz|NuA{72(hCp zcqy;my|bl$->5$7H|#Q-&=MyzwdNs(#S6<>Y2t7mca0pVzN%p~ z2}!S7YWTievZ6Mv#!{;mNuZ@K6x%4Sb-10-go_e_e?)I`aQhlwvxw>Y#J}zB``nqC zuE`nGp0pz3Ue|!s1S?@w^cE^AdMwA+A7FbjT09Ws#J6>2l|p*VW=FSnPQ#D{b_}U1 zJ+sa?GHaAirQ*cqz^cLS3*vUa-UU!h)Q=;)^a-pRWXc*!=* zUcZ)kT3}6l?&b9*kPN;(UklKSfKee;wtHas6?fit@0ys}z{dB8^m?$aUuRu)^uwCE zv{F4K?8uT*a#$)PYn1ceT)nJq;Z|9wNJza_jUQf=+RyDVs?@KA+6*5USDn?+2E^_S z`Ri>u?5i7ai;=j{1ktIX3){ z>zPZ^+gmK7?5z1Xjr2Y#kSrqw;G;OE;q`@~t26ctT=mcfmznrrXS1gd8$vK;w4Toi z3xKd?i#LFPPl-msG8g?wk2FzRO+?$gBR8+152IsSJg-?_!_M@SuWXa_x%{9`S~2KS zic|~G{L}kA30ySoNPFelw!xm~iW(jGSJHNghOHC+>rrz&Tl+ly(Ofx`-gi|v2hCRW z<8%3oY3yiULD@w^8?U9Iw5Id^i>U_s&CKI0XkfJK0 zI!$ZT$G?J?wE(=M&<8P+b``b36&LO;5ldQG=>UMJ!cyAW`^fn(GjsaW)kBkKl*=DUl-zJ-*0a>K7e{zc6|tvzD`Zk z*lI%L%!_$CK!ZQ4x1sg6WQfJRI$0~xo|2W2xrX!Aq#;EK<@D`^pV(=t8owu{2^tBfeGmLmD~XfQGRbO8XMO`_ywh9DkukwqeJgK|#@dBpr7~q- z2uue$X^} z4Bdl0%woZn>Bhr}*9-|Toe<{vjJe2v1Ly5xBg<$nnMRf(GCWZ;#Txxm6)lzfMOd#r zJlf`Q$GK~la2vxwa^odEBe(`}(#|eS#eK@O`gY~h(4MMiejf{z5|?M~z1_Z51c~Ef zf>fBG31?nPWhGu$>kY4mx;#P;K#+Yl3F@P39^R0$S&^%OE!Mq6d9R)e@ zf)F!F_MIqYrep_RLL2ZVYE$zfGR%uUJ-D?H2F}AD7a(|fZBC5avL1k+ZEP=i>YqOK zwr%Hm{~_f5XI#31&n!Zh?;;l`+YRHBX92H?Rm zg=1AWZFigzhi`j_c#z_2p^lcxN_RWUWLELyLcYdEYMZ3XyOLJ9UE{BlEe6R8L{I|t zrXM^?_JvfOyy_zRc|6WUN+ikw|4EykUVR)`o3VE zUl21le9c!Q5%*f5Tg87WGwyFoSBlH94oa}}kHZg^t@FFEwzU^rqOfbSCMTG@-Xn2i z-HGYRk|rHL+p}-HhoBK!VR;NB)+5>Ttw5$vCPha{(0^s8uday-UD_#L0dEaBT6?7z z@%h@EBOVu}s*JO`KKArL7**Y--rl&In!NnR^tO`)Cnx~1NVOU@9fF4`5UjJ9S?^I^ z$drn~S2QR)Ta|717~lZ=WChFmb5;|f`dMT(Sty|d%hIK#$_-m}_xko;6LY`hKC4|f zjLCZW;>2Hrm4}Y0F*5{%6?@AY8TJdjQ?zY!)7W`Wym2nC54ANc0_tI?V_K;9GE#k* zU}1h0B@KA@n;*hK$2aeX2KgJRmp}(b0O>h8fx>O+=tr<=HLI0*N9KOgb_eY#`iGd$ z*C}pp6XiJYM0?H0p*WbytZj|w=;QQl#7Rz9Yw0EJ)s!Ac2;7T+MKlpTE0ODK8w;zZ z7<4Mqw0iyIpYvX90hbjMSAHp-O54_pM-7N?dOx4T^{`U(NhX=Cf+L%-JsS-njITKH zh;EVTX{pcPu$EknC#gbsEeIRcBK`;RHo0e3xIf%)a^0i7+P@7HXFW~ z;orm%Y}I_nN6c!BWy6-cab?+nb*^M2PP}wONGaPjMxFN1lX1FA6T2nW;jn^4E2c&e z<-vLrQFW#+D<`j(#iJRD3)#QgJQ{_9J9LAb2+^2V;vvs`i`=i#g#|^zV)F{7&KTBZ zrdE$#l~du3I6QkvLhPMDkBe*eGn+{Y;kmV87?Si33n;3-IRiY_88MII8WMxbOpYWt zwvZbuszjdm+_NNZq%XT^Gg|X)ib%E)(;rvB?vkFI)0a$n$#ZrK_ps5A7E))Fa=+F{)*1`=F-ed=k%3|?1SdbBfg~no19vXL(8TYi!Es`$0V| zeOS_Ap7EQ~57Q1jt+{jF>J$FaooIm-x*-NNg<@EARxaO*Tg5=7^YIy>d7pmjV0d%by+rD)p#!_c%s*yr ze;fklDQjG=(0*+V@}=AyUI*CU_A|#7xRyi)w%Xsdn6eW2g;KQ8w*@M0AskvY;h25v zFQT+nm}6j-?j9F~F;9Ho(fifM7L`5{-a0E#dYW0I&P3+3^!KUn#GBp<{+K#bUJGxG zcmsXTgi*}`%lyUPqh}o?EU45{*IAmhzov9Gh^8?QdV$BBA(b_>RB!EZhazQh`OOOF zTse#|HEbH<8d`PJyJBRFxjS>N)jg%L4N;=fyw!{Pnrw%kV!axJFQ*L;RK^y4$=)XC zS6OBl<9`dIQqWupbEt65@pIuTA+0yXL7~(0nv$>{;G7XO7C6W&d*BsII;UKnb>;0) zS~2iAS+o)ZGB9@Hb76glxXCNn^%qELWYl*l(iKDznPPhkSG|5nj^1(6Yx%fy zv{h_3vXk;9v=dpA+fFHm8#-o@KpAYHOA* z^-R`H-tqW8or!+qqAFA^l8ah{n5R#e_cNGS6p`ho{^qw@jjE^qmT1oxilK%;phfoc zDN1|t@dTktz){-Fv*ba!K969o%Oz9A*-rYGgz7sKkwShj6$%G+d(9nB1~gnPmPp%a z#8#$(Y?3pwMS}}zw>_<9XSzDL{`zDy@7E~;A6YtqQTxRAA+3BWj4R!p3zm0>EB8L$ z-{Gwp(*v?kKhrc+`_SSIT>18HWVr`SO~nYXP38-y)c@Eu1{l+52`7zd^3_IJpnk@y zlvVfz+?g&#=0&rN*u4|%;|I$WKvNP*)iv-*d<>sHxH9H(_fSTjNPTJ*Q?-ly988ml zGrgVJ&>ze#Rmh?=nyQm?t|zzab=(;H60!F~o4CTa|C6j*89raAn0Oe2%IQ}gNEfEU zEnIS|Nh)jOOU5-E6JIH`N-vuXi#&=e?&6QX$_16QNPg@~?z#4BxURmBh}kgM^Ha-? z4*#l6JW7s*$GksLT?_c(q>pQHI`43M?EiBI+k;L3`+9cm{zFB|srx6o{;ywRc_Xv# z$gF$#PVhx*n?&gH*~tPhpe|7&qJ*%&EnDp&7_=6wRX~%_9^{k@xjL?2bIB^i)%brW zsYB&@U;2xLKAE`A*^C%dqAQf;gI#go4(OFbzfH&54qMAIQB^y}?auXhhq%90js2B3 z_ftjag@SNhhBA4p8O%5v#;R`NPo~fA)6RO$mF&?3x(3Jz$+t_n=IzaqAL+-ZMbH)> zl*G)FmPzV0cDfuFe3oz{)D*+W_4!!x!CS(>H``7F@@;$qLvr&LY?br; z+yNPdTwyJG$SY``*T69=7Rs}NF?`FIXBSOJYL{X}lx^c60$nJqbh*;ESD^LITI(!J z3QuDi4;L?lFcD&S{u|AfhDm|Zq=o$}t(M^qf=#s0<~6l(uK@ipmSSr2alQhJya3Y4 zab!sOc^MgPt-k_0HOZ+03@vc(>vz?oI(``UPBy|ITT6o#zqcY3=F|Og$rjV9Et+>y z-&hQ546nT&P`eD?MHyS-!9S;!j=knKpq{P-kwX@?_3Ux1q-&^QS3EbuZ;!|&lICcf znx2pzoE;{aGX?kbEQIe`$c)A`i-qW6GC5zY?CbMGLJ%(* zy)J^SYjx=W>N0vL0zi*zZ!_N^@&3yq51cw>!^0Ii|G21$dPWO*j|oHX67=3TJnsi& z5$~*^4F~P=)goN@2_tpHr(Hqmq;_h0 zw@Q1?AO4d0_60xOnyvG|h0Mc97`#hY3#O&Mc8fdCi6C4dzs*a{@W~&hNl_Cq3lc3r zeF-{HxEWA+H}PgEy^qTYETM&&&Pw{BzPvh_IFl|@o%0-<9M^qIrzjS`B=5QdSMBO4 z;#K2M9>iJwtBrfTdkna;p-Hl9wt^}n*fJP6Z(5iV^ zz{5-rDL(D&m|jcw4g$|c%uLE!zFKaN^9s?9HjP=I_D2^us`F8!jbD-+>?w3)nqKI} zfIIG!vs?lS5)qOt`r;l zJ9z>B*Qs=Dqxhs^Q`E#e)5cY{soCzb8;Y#BNoA(To*MOvnnpMH9z6nOhO;ao3rt?- zrL}%0rXe&bUat`nniy?3l3|Gk71dphQJz+P#t-K2*jPe-v6agR^Rj&9*! zbT9;&LRK~ADIdai_WOSM3ui)@5!+(t$Z7Rw;#(;qzBALM37SMDnVzhPZC+2ni}QA^ za`Y&5rqvg$Rz}8-`UO#B1E%Yx260TkZxwplZJMy%<7{8T#OOHSuLfXTo^CF-BUx8n zNrVA{ItTCYyv6P|E?vCv^_5bV0R?s=nK*c}GIvKf^{fJC7lQ6ywdeG*XDS> zPNJ;Vhz@1i#cDv!M&uMSLAY`NB!}m&opQhb)B%-X>>>#uy(KWoS zZZMJ#al>0bTe?JeGEs!LHCX+XSXH_%Xs^FA| zW;7If9f3o?5E(XKq>I0xZE{z-IobjUn%Iq#F}7=z5bhFc-oEgcRyJ66<;&th*V&0_ zT0p>b-)S_+aNAIR3~r(p4t?S{I;4QRRHzEM$}0BAcFl-cL>rp);rC^^`B>-B3ByX! z=;Vc+-=prOWuIa5v*7cn!BlQ`Sc}M4X(oTKU(doFAf6=8AS2>5UIHRic!5o*ldfr^uc@CH4~@o+-sTp zOI@^)_}G;YNv4FC{`ItF0gXg=`zcjlMoxvo2k#W&MG#&5{?`aJ4YJN)6NNYr{@g5F zv6@z`(D5JD?RO*zcTf>{R#SSB%U1q3qZ>k0Ro>Pq(LV*i*J+qaXJ1$E_uI_nz1fqS zU9C-5KF&+lzKdrG^D15~+^q_2nE%i&BCqmY4sE+a|FM6+lW~Y+SeDMwgi-G>4nwt; z_vZ2|esP(a2ocO_afJ+LfFW-lfhy3dYfnb?Fp@F>(nE?STBoFZ-L=9p%DPKY}|g%?@sl1FZJ)_MO2di@tKk z1+>~L8b_l*4sT0r54%EQOB`O=1r0$b8-A=V54xpQZJ5j>8-bOA{_!O~cOVaTV}BXo zW}}=M{Lyq}uOK2p+C1eQiXKV}>t@1$ywGF_?2n&K!0Co`5oK8os{~rvAM@QmrJ{eL z-Y9GNJD{i}#~K-a?MB4BO<|KQ=XlMYFTILp#@r-DSIA7RRqQezZdyTyc5)+^IV5%fB;*T2G>gU^LXXhOUW4YzJ=4=pg%WuK|5*20UEm!RhrBqM zZZG!%97GUA0A+@rATF`v&F89Pb;vC9g}2bV6eN8O;#CFB;xpf7slgYFEI-nKUueFD zW=hA*wuIYEcQNu~!JBKHG`(}hVl;1^^z2z*vcUW240oizg=f(xBJ`^XPt_Y)SY;QF zd;?RkeFc}AcxHkO%;_?Z+PaX_P1=%-6P4a-rNt$dyBCcsGrTqtH_%ZWew6!3NzROI zuc^1#jWYJURNq~XOZ1EDAmFZszt{eh?LewHx|%k5u32kCH{<#|T7VGx>+YEOw`)(T z#V-v`K$ejzqbN8&w?-~Kp}YFeHPTZ7=tgfucd1UyM|D&hH?I9+nT%hd01yolwgkMQT7 z23N@z-$xoGC0CBO{XKp*IMj9TX6=%sV9arlYuef&B1v-RLOkZu_IJE0DZ50H^y z>{-N3;(lBl;ysn?7`9PKqwe*$ylm#r(%bec&w#+4%yrq17dia6 zP?72-jwV>OYngcUX=o@cog&AN-^8;uJyjStm*QldQ*NCxB;4=K(?v9nk6QwFa0F9E zZkqI;{jFNrkQMlgNnB?qHjX|7Dax+lw?zt4W;y5D*hRpX{Xguz1$5oamhWkf?Kp`k zwqs^yW=_n^%*@Qp5HmxZn3@UdlBy(~ zy=(veVi+qd6@tJl>w;I@V8e{}_e!j>!ybhmo~fHP;ql~%OKw{159DU=Qn$^%kcadQW934+ z?rf~FmIN`aPPfV)=byyDQJg<+jWio*i>XkFbg`1a_vA8cy!Ntd0B=Lb0PeB!CR!_{ zsFl`Kvmxkzf5u_BH{qwITRlMDaNe(~5*VMENi5e0EQ!chJA)$9i{;iU)cUQ6iwe^+ z=NunAf3@`P%f;ZBq2;YsZEYD+e+@JRVg8*Tt{`*2Exyve>0<1rR&H;mfkXnFab*jX zsMc1lM%uyVmtD_R; zZ`f|BR3J+Hjb=Y|xFBZ|F-j30Vm&d#c^6t7k)K{qw(7L|{wnKG413ooaM z#qDjO1Iw$l%0v=VQy zF1F%Xn<_-y5fA%M^8#V19T?8GR=^8J|W5#Pg8@H-Y=3Pq_nm)~LA zoCzllBNim)cSqfMm4^s_d$vm|&p$~aeVU3>vGCq;g~&}yP;SBuT+Rp<@$E;B-h?Rm zVyed^re4Ibd4{we_w2E4C%s0f>2TEyg<#w5ssg2xO&J3#W!S{AS&vo?HG21*hlt9N z9q<uFrkFZ)17Fl0SqNV*sAkSkeuMaKSXi$njV569VZI6(-YN{WbQm z+!qhs3AJEfwBK)ne)_8H*U60=dgi5Jgj`%kY?)>oJk-iBW3^6OQ**$ixbtuvs}U-g zvYBKnIX-??Z(KjA?ZKYr164OVodaKeK;~f@B$P3qYu1P=9f+&JSYPWqU^pOpp(2Ek zO>D96zO5%{Q7IFAkAcZ@q(uCoO>1cj zGDeJcOb2T1=E-VLTidg}HsfSaKwtt(hIK9$))3ukx)Te9^0Wz`yJQ&t2UHQ^I0ae! zk698PUT`(rf>7fDu1*kTOBHtw&4f){TCWvt_rDSTKeZZ%=zN9wIWWOw@! zeaFvd3lwR`XTa+&$)tAdC3<_;oj{`L+no0f)=8<+bc)9DkZe!vkkzBNJpW>zQ}a$f z=p#Kg`jbRpDvCMhsZV-cP- z$8Br&qvQUS_GEcZNjnlfu@({Rp4@ow3($F-cWDTL&b^wUggdgr0l?m3tTT zgpli3$MV*pJUzAsGR!vFnW>K}aF}JFnGM%-b@rM_^m``j;3uu2I1rC*g&CFd`jv;K zJkI>fQb(S|vgv_gLiu&gkO}r3>-QK@*x?+8F{Im`Oj)&25Ln4LtGtbbp{RY0Nvi3( z0r7JZtwJW5)k!n=`HgcXASA3lE@g`@3>`XE#XPMprVkyd3^ER}T(jfmN2v?8BG_|C z+Et#d@q0STSHLKwQbo@5=?W55LiP=-GrEai@0i4HH-}!|Zc|!>I*e3R^%yN4xKAog>H{nN_%$BKe z5WIT6&+rE`#cDSpanv40zUT3$P5L9H)w))YdiWmD)n?}$RKX zA6=F%W!i5LlTD!+$I2JswL^uztktf(Vr268uoGt@N{PZAx{Taxq=0SX8ECSaE0#s% z6J|3ot4N5vKA)`TvyC~)Z&-XA;f0bpFjKT{l?CuYDSz>6Kfyee=a$6kqQ0{$$GAladpw&{&OV^e51!HdJs?MNy}d-t9O_4^Mv>+oFOe(=vUmhjA25~@&D)q#PF zq< zHYJGb%)Q`bG^o$C)s_-+C6@x2SijuTJF+J#sHir>919x`X)j6ZT#6+la3> zYJ*$$J}kj`;k*@nBf|r;SH=g(LkM0L=Orbrghq(&V%-E}i&_alI}9_9VMZ9v{%_0M zRnOM>Lu^7U3fi{rA$-~pM2X{q(C@2_(7*8WuNOrKbr!6Zj_p*L0lAR++21#gk5kN# zwj`g1!bf7P^z(0XgrZitAakIlAO6T}EbdjM-i11nBE~tC`yS0$lJKfP74uAv1?{4Q ztOASIU5Nr05gf@BOMO%+*L&&kBs>Q%XYN8g5W-K{Kg=0s1yev1M8MwDOOReGHel_; zG!6`~WC~Zm41O)!*N>&m+x@UmuuRh;u5zunPbWSnPgEyQLExgMK%ck`TvYJBGPFMd z7b*$^upM0+TL6(`1`U`4;FZv{%>T^PJ|kVwR5EtjwoaCM08wthFAX%+ZyF1mj`kVV z0`P2~jI3>J`3$wJvFYdmJO%(S`k4R_8PHS;M!L3!0I3=Pu=z7Dua=G8PgIPGPez>g zlPnpZn5--f0ONRG$ggLkV{K$i@SL3fXFz8tL#n(_YxrfWx%aGn2<=1XNk^S7G#YfU=*f z#mj5qh^<0F11OOW@M<9d7|h7RpaxiHs%2n<4LIcI!+n-7Cw^g!o;j`m%{0~vbM+sB zRy==0tNuM$rSw;*>IJZRft&t>PyH`KQ-D$dY#D$_BY8QgpNs(K{e}6FhW?|KUpmTj zk5pm!DT?&mZ=UD=?|z@Rd-?n>=kF!_F8Mz$|36;)_cDK{U$**pzrS<+@1DNwU+wob zP6v3K)*ry;f67*x8JPp{z!xI$`GNwlZMsxucBZyQmZnZrzac_1En7nX_-1ePlYi4P z18|Z*7d^9uFD3l^eL)QYOrELUpJrb&JfnK1djBZ-CHbq!UkM9as+Tz(3riMyqNpBUAj)T*`x;GF-QGqjiitjz(~u;~jk`j6DhS=TqUu(1Bw8b9Y=7V793nf`>20c7j1`Ii;X zaO*Gh^dEOoD!_^SGYb1h^4B(i4yvtX{qs@u+=-ss(f+070Lxxdf8etY&v33Gpdoeb zbO2X~7T}BlPB-9M`?bVeOB+BhKOaAUb~b%Eb{ng|oDe|rrTg1hy>vPoyO;j|kMyq- zr>kWEz@VvKCeQT)Fv?nhVgXH~V``@jxR?CAiBJK$HQ+)Az_NfF%g^5Ue7^n-O#6T8 zR`pK+?*H7n8~`Z$a|ip`n}4>}zXg2%g*Y<}HZwKdZ-y7Z_X6}!ey9G1_ddVX@xO}q zO1rSj?xPZxGe9L9ij-AGiVSw?sSXqwH7r}`Xon{H_wCT1K3kEE!vo()s6 z|0oDapcZx!0{?B?kFxt)wTTN;D$m2^@kHA8y`8&(+kW`5+tRkn^0v#8gh)rnd}~~g zzc(Uc8%&@-|LfMJ$ziq#L7+f?Fc5K(fiIwAG>{+BcTfz0VTXo_Dyv_q6j==R)|r1zjQr1)*ui(R|(EIo%IM zxdLv@BM#F`-w784grKd-O^gD8!+al1DBufF^k7K%fN{g}9@M%PSIToZSXhlaGcpL5 z8cWlg9DV7{dj`;t(vN8Q&E(=i{#s0|E?M_UQW|hOrjT16>0b|e4PiEbiir_6ur;I~ z+8FHYiSOmG1VZ2P!KmQFKmdcLm*KSa>QVq(k-)ywb>>FFL)RSDqO1+}fjk$%!M&5$ zTUkWszyMLb;F7Rs*yjm=9Sp#N0`YCxDWEwmQQUxkwFb-s7CFEVCsoOLeCaW2M%B)p z2n!DpAu0;Y8o;-`&Tk=zmct4@ld)Dvg4hNlTsykzIhNgqkiS42SxO-N@!jgg>1HU`Ur|9)R7XK8 zn1sbs8t5+j!BuKrutS8CEB`joYEH4x^+>3%>~X^f&S;F{HhekVY!v!Ltg32&{PoW^i^zxy6j(e?4sfzydq{aWOvwr7n0DPE4a(`jWt=a0-A zsjP0WBi=71pg$fRhP>bugvTwn-KH$R6$i5NU4XS%X% zch;a_QF$E`gJx`EDZQTYF3yi(V*f`^9#0E2Bdyb0&U2wKiO(JWQwF4QyWw1lOC0tM zbr*uZ2GSfpwn zE4i)mbJ(qs2B34L7W9Zirw}JqIrolZSsqOkTz^&mlw}ujAB>P=r;p0EjcidqVwbw; z&@(QUg@dbiQdXBjO{|w(hbU58p|Co8gyE4b>nCK?V!T9Rf0JgAxkN%t-EfQZO_M3& zODV~K25$g1`H&?gn}7@H9WS$E7JrE#=}4LfGfp$ZwyxsvatzZQ`*B`KX|BcF=CWyv zint4AUh}wjiuLF%Rp0fDN1GNsQ)#)R?U#%+@giYoxy47I#N8VuiZ46gNKhYy5~j^k zf}YsQ!F3%)W#rj^%vYK|WA1v@t#-@6)`?&4e(JH#qNnlwuS%7RAPQWNh=i-L zt7{UzwE@SrO#;*1j^%u2eaFwiwyQXl?e1aB&Mv;ygLFnfU7Rc`I&n;8ULs;G5#zg; zxOOIuc5-3dGTp<0W{>vvU7EF;z|G;Ye;cWhFw5S^mz0Rk5B4)9Iy+i<<%@4pU~eYo z7YxDEKFL)1MUk_-FFC^+ykzEW8mEw*I8#@qWS2}qwHyyDxgl=q%TVO-u(3z}I>8hZ zDTY=*HMiuFUdUzVQC84RX}8GHrE+wsF&V**<=@xH-rit&TO-ydq!@IbE#vB^l9&bY zdRTsdW6Zet&S;OThJ?>ix!Hqnh~9~lew2IDNn>G{wSb^kMcvs{KXQK!O9g?c6bJA} zL&&?!k0^Ptxrt6tBi*jRKsN6(^$gn8(SiT;6l*#l&j7`6aCNVLBTIpE&&$wHucn~8 z+iaep0sX#mKL}n;%*zKZqh`zejNqV}EFMaITR~$v{`Aq0|4j}%6)q{`<;Ud8k(6YWw|p>qII4|E`17Bxqn$RF;qVMzHyr(^vmL@}#CiA46njRRS0ydTcf)Fd> zRd$C%CRX<96XJqGsmvq5wxSdbXJ*+{0C;4SNOzQzfZs6E)5}mZF%^B3LrIEPQcT+0 zP1iKm)YQ}hJ5{nal9Do3hhhc?28HUD7yyGXH8%ceOglYfa?>|Op)_7oRa9uB=Bo9+ zfOC5U!9-(8mkYKm!`xn9*sOH7k-O_6il79Eb8gN-k^L^+SE2le>}oniRFgZ0l?D=2 z$?RN}rc$Rb#Q1|VlXn+cazpm%{Q*&$GS(bk;WKg zajB3iw-$%bDuQH&QE^c*H$(3a96oe)k{xrlkUtp-JY1|-_Z<%}ot?tKQrYiIwwR5 z@VhhlOut(fpm5rN&hU8g^)mFhqfUP^Ee2~IQ@-)5bXWY9*^eL%p7ec1^z257V`Bw2 zl@8*O%BP;aM!RG3Ec1ldR>a2*r9ZmEKl2oCz4sfqCmU?2L7{V2PsY`lyu5pgoQ;-X z^>=@eyAvuA#Fz9pk&e^7VBA_tjm<*DP?n3&#Z*R|{2EA3!qM)ZO`gBJ zbo;+(^89?+AHb&g$4EI1z*zWWq#Tg=hr#pfoi2YEJQ6&-60&>%gXdq{J3p17|7;V` z{zWVL-`P6=8|&ZMJAd2Zf5qJS+fX?mGJt}G5n%4n04x?JrhjMd{2aOai-Gg=$?@ld zp#zM#|2A-_ssC);{8@bVKQ(UtJ8GN1)HU@1%&8HTzA2Ud^8_&cKOg}M7&`$B5I$?C z{*<+lRtU&M9)pOAz7sox7QZhj6${6!J=d6>q|?0FFQ zx%ISkehTLP%>Fa)e|H_)=SGc(n)v!(i*80_!H{5NA)|DCS+ zPvcN8lE(k9cGdq>-xYBA{tIs&^| z!CU|V3y4^0Kd}ULtgWrnD@FOBr==<406C#FJcdCIy#fcf3Qp`IlhQJ#E8NPb9!43(L^lY6uJ;D4Z@mIL2G%E6H(&kDQk%pL8Dz&X)(z zlUFCbcp8DIYF9Tmy&QZ!p4_g^xVEAkAb5&!hO2?pfq6U$VDxuCgKKbD!UJ8O0bvhM zX;J~ryrzWNu=cO-2mo4PIDIw4t)=L}A&IFD^c~_%;lN^J`xOw6BoWcTG8{0__u=`j zw+HuZ_%J}Xo?72MKtMbIM0D#T6lD7=p(jEfAjvHzC}7X>7N{>GM@&ILo@Y-HuuMR? zC&`XL++E9^uYgFO2pz?LEQ5`t-@JqBs4#pWtj!;`@P1NjS_Z3`dJ0%6cz@jhgKH^K zund+4eDUtovLmPT5p*?sh3lkb@7~MOW}XYSSo7*tI|jA~wrcz8J6{#%M=#4aIm?h5 z+T7cKmB0_6tEiM7*skg`SdeMchwps3Xs-avS5IHHGq68#*LD{y_r9J!xdmif@>us+ z#;2u~q|y*q2gU@tZ+}q0`3QvTjr;iIAmL^ZSnx_w=`D8a&=3WF`;`OY2C$D;>f)0- zU7N#7%Pa)Qa*1XsGKy~%{X6g=zgdIIPqGlb$P#kj%5nNI4n*71xB&CXlI}mZ#Z-9!zR@|F@e?I6Eg!iOr!Li9Vu@j0p}2X4d*p!{ZO& z8pUyDiRWd>^Rc<)an@Sqlbj#Y;><6G@7W~2WvN9karo6@PPh=KeufGvh5|cEt zVmsLF6Z0>($rf~VJfXDyktX~~bF@w{oAcILP_HHClFFvT+Z6u3GG43c_4ms5ZY*@9 z>A3--5sPo~G8hv$0l;|(neK%H_>MM{MTtpI-MZ>v0?#*QOhdCHgy9`XS3NlQmKKfn zoeCT8z38`#<2J7Ef-zMsO()!|6l={?=BLzf=Cgg81xFbIF6Z?7NB+1YRSyFnlcpLT z7O*hfIq-CL`=NA5$|U-rl+{`vT`u&xHE`buxeArWd|yzsXS8^APm+$>5v2>aX*E?Z z7=8s;z1Gbmwe6ry6e8jS8A#Q7&8-EU1->&>Pb*y($0{&;akp}E;l9zC8$&D~OCDwpsc+$=i#nN?txQA}lbPVbhm8}T zcWip9MHveF4g<~?p;rfZSWd}yS?t9zX@?&qG@ytDYv;E1!HoO)Gyo%4>?u@lLx6QE zFi#ej`WVEb;^4@nk;4(gTsYzlv!xQR-=6fADMVMyDt0zt23h8QoG0dQD_K`ub@ls)>45_K2h}BO^KilXDw_ zIet+&o-D8)IJX@OS?9wd`eMoj72f*u3Gx$$Dx)=RP&o#^P;5IUrcFVno2?0TRMR10 zQqivh-*q}^YPC`YJru&uYs^K{_Ea^CWvpz!Ax0zA&kI`w;i*fPVUoaTPH8yue$C|~ zyNBNGQ`1+nWh8YI85~9Og=Fv?dVsU|95a3cVc3CfT^#*KybG0WfP<`NZ;j`Uq#5Si zNLB$SMB~+0Ol$KS&l)LpyUR$!TWalYRUm zXK`(sCpTpvo&hA7Hf?QNb|F!oBm#(p@@@^sGd<07x9UbpnXUJqd-qx8qze|8*eATY zLcM|m4f2v-rzM%=9i%u2=4X)A%Z>CQN@MpOHBYn&_K|{Y7fe-PAVqPH=V{`Yg^e2T zoX}6PutqBUyhssJOz$D}#n*dy3=@BXtR>?LZIp`M z=WZda0?|K~Z8|x?TO=$w<_e#0gSOheFFc3e(n8%N1!C3~Pe~>xc5Y}P?xH@kv0-a9+jxkgwWH}0>2LO17Li@t6qx1R@{CxE*^EJiS{Sk|^_ zyzaTrXqsJJHag%*@_C%z3)dSy!j8_u4e>QQ`|6STUAemwEKSm z;PYcMURh0o?D}M^vR1ad3ysjza@h6dB>tUs{1%Ih6kB!YiQ?(6a`13GM09C-lo`Am z+rv+j{!6K?gB-f}Kf-dkA1`OBi%n(j&bMnIyKbaaA2IhIYana#M>hA3wQtFZ#Ighy zM#z^w%1#`eLhNL9?dXmgf@_uFtIg}HXX>#faGblBMm}_?<3~ zq>jU!8c%%S{;L5ThjC3M+95L{L$;|@brvK=1WDaW7SYyt>^sHC8T)>*Ni{v{$y4p1 zp}EmB>-Tl$*M8!?5UFzydQBzdi;s&%Kf0U|5|6lzEVR~6dW;6)-_CKz8PE*yeJe9K zx*ODJ(N7XK^BT%@E(=thz%y%*4d@cGP;Urub2RZa)GszRJJr2Mc*`jD%^{SA0m{mj zcvpl>y*;mBHLY>-Jfb2O5EG2i!K*@bd9}Tq#HOTjw2d z<_UMk>a`r@-9T<14wc{>21f9rsmKUKt)w36!+Xm*xvdg$_>__WO5TGD?aR7+?{IK- z>(sFFvpp_xO7+!`^CI&fhU#+pOdM7;I=R!b1d~i0R_mLR-?SyU7F9Xy3eOmw>giKZ>SCMd zhk!SYG_NSnqdOci&)o%&Nqh5{Crp~Vvoo!CM39Q{!5Xb0&-K3h`^lVr|C%gm@)IKs z!}LWk_ZeHF^FlPC3bc5GltP_Mz3$%C#L867(O`G|66eQ+*;Y#J>AYM!ka6i~xX#$G z$M<{^tXh6$qyp=xTBEdDX~W~9NtOC$loc7nWhErx{=LH1)l>51umo7&RG|gkK|C80 zhOpQL9fD|^xSxQxSCV`#mZsR_HH2~;4W$Y*^JLme=&DqHRCx#ZRbChmzM~v(s5t2p z;1HN{&0Nzm%u7ilX!ohU`#O&Dz)$xh7 z*$NS7mW5Ie&DcRn5^UKCD%XSj92Vf!@f}u(t@&ZD2A;|N9u}$-vD$KJV?KJjdoVMd z6lT7Z*Gc+rrk`A9npf_xF>E|yZz8@Vc z6zrkVSG!kJtkNw@3V#?{_ph8c0(vFb&xJlBP5*S zSfk9;;8Vs0Y*-`V_Qv_H!p&UNf8v3)j{N~yj?#YXeg5l0GTD+F+I^>1%OS>eWDd=; z`uleI)v76pR@J&f=pkh@aj`f#jIP@Lsr`5n1FwU)6)+H*E7Rp>z2=u%unN zCA1#<=*C`P$H5QI*5oK%n7E=7NyINKnCl~!hmFoB&b?^{0m-Kt*gB>{*UtvY4dK~! zHv@Hb0gsv;7owoSm8OC)Aq?|h7(CiC?soR>qa+<>)jdt;qqUgSs7sFog_|u~7EEK- zi+u+|Go~Xg(DVrzmF|rINE} zvfxTd54N(=))R*Z-JDmJryQtJ`I#tg?Fz6{mc32u7AR1kRpGul2%@2j4L#NB7=~uP zlFNdsQF+sYXMf($;jU_fb_mlpC7fbw-f>0dztd@>`m&@xn_aqn~{yShG0 zB*V2C!h1YMuR`RK7fA&%XCi-fn+g*|V=JJbA!`y#S4mzf(xrouJ)^&MJcP9BI#ljjR2K*NL@)!}Wv9p1gRP3>cgxMxz@lR5 z*L#54;~?hJW>7p8p@L-GlDX$D1kKs2UzYuCn?3OvIM<#Cc`vdY1RjM>+c562R?S@#4rXC$D&c_p^cO(A$E9D(X`-g72 zY9q{^NKr;GWY^~q#mrimy@Qc2-2LLFIT`Mb#9OE0!A(|AxlP3#Yfh#;W~d7jI{qXN z$4;7QaK_5Fp{?iic-jYMd?5SfQ*leeKr};dnFArMQ#5uFG?^`pMIiy0Qg@q<#kIk3 zHofx4NA$e8U`$Bd6IX_VhQMedd5`%3$+4Vaj4sz)g43Mh_)FD8w=;g(oP%*2%DqS!muoc?;gd|Od!6SBga9W-w<27%m4mG&dh zPb_n2yh&tBzrX9k+JMq`QM@r0>WV}k{7NWfxVl%tf%283U z!)LsJHR-;bUHU9_g(tTgp8(3Np|X5zYt&VZuGcbi%B2Xn7x>7$=5;D zfD*{z-M0&59)W6+L>_FsA~;lV%yYlcBNabzxvA~*YdcU^fw$XX-h~IUgQpECY(kTW zw*HbA@!nK}m3ea=UYJt4m?t$#(Mpu@$7I9W~IKfHo20B;4eCV-yDOs6vqX88Gim6t_i3BsW_wE)K>?HC5pC54-7_0%_d<@wI?V;|Xe2+PteBlRV-^f{+dk3`@YViY8szaCA? zqCoc;XC`aQnLx&`S`?KQe)&N-ZY(`sVTFZ7t&^Pl{=#(R3SUYZ9L9{aHsJM!)&iru zH1QMbXK(m@b~NetjJQJfYB8_a(gsG&oyv%+-=ss{OnzEs(ts>1_?6}uQdYm{rTcM?mb}3@)dsv zT66a;J(Y~;E>?`-U>unrUxV#vmkpZDA1c&^<8|cS&|1>@w9~&&BEQ-4GWiZUp_wA4 zKSO*iU`X4I0LuIIbMt*)3FjD+n382u{!6(lG?Ts#N{pnzSV@ zsHrG7d(ez+tN4-Ts1X1BWFL9`y}<^;I?oou=uo;bB9mil)T(f$pD4L+Bsysfd!kh+ zYwcV4qu4T`KUNAeDxIN{ONw;dQ#_{Jsd|15FbC_FSDPcF2^t;Fsj7Xuc^Pb-Jj*tZ zw^K3#J-aZm!9&I`C6SWf_QTOw+i*(M9E!{Q6BR|QUhO3NMT}RpSI`tW_h;E{O@Jok zV%nThxKk5K)kmu%Es9>H$YJ&`U-3xRIYke~uht*$GMtG43Av&8 z)3@d*t5cGrHJkXMx(|%I#IyOxXIStr?-icsH^baV-1)SwKQ!fwO^Lfh@k}nhwkz?X zFSQjWxy0{yT+O_nX%5^*Il~Uldy__4Pa&M`9b}!Lis~&e9H)>RfC?@!r83+*g&M@P zM+lt;JdYbW&CR)d)&2t}i)f5w3xiOd{XLPSDw$`S&alDsN@f3T&k;q1{immm@66Ex zd4t2IYEKFcR}wacU6G(&Y!0T@d75#rzA%TvZ&xl1?ROT!BnArxVu8ZFD#6GrTHmxi zqQ09vF&OPJ?%;O?cNUt=D-UytK6;2CZ7qRiYoPZtCdHvodYhO>2DaBhrK^+bz2n zrh!MlH^oxGPTfqZ#a&`O+T~0(zOmG!t9~UzK5$wC z54<1(^xKK$S9K3mWC~0U(}w#Hf3I09GJnX}!TnG&((_bnK2cV}R)4n;CrVlBS$h>2 z9oKbWf`LRsU?Z6I?F* zKb(#;H%W#$MxPWrE1nsR)wObVls0>1ecKRz7?JF3jy6u~(7(`m1{GPuldSWMV0Rr! zI@$ST5U8r-T4u5V*r#JsKX$)!6hYqt)ci_O=O z`S^-ImFDTcLJAvRuEXtXK_>aG;CX zvJH2w7DGd2Pt;HIx`vAOEKdUqQ!N!!9j7nTyE>k48FZU3;%Ej{4zZ*?kuzlCw< z4@uZsE{QVQ_pR>B_cu8SY zD%UeZsj8up3-7bwI-ag~Q?KW8t!|i_JG9OG(!zusfmwZu5(4fjfpy7p=0Y;sKKU8B zt`#U;ydPy)yM*67Wv>}$T~f$9Rntv}2}1T}FDw)d>?7WYTAOvhtY$)Br8&Cwu9k*i zxZ}#I=x{a%?K}J&0OQoOZCag)$FSdg)5O&9nr3Jd&z6fzrGh#;VkicTr1&vqQ(PwM z$&1O$J*l52HN)d|I}t7aJE_b^Rc2SSPs#a4Is#8$*R#6XWa1(f<^ry)=4jR06AGa1 zSbd3RfE9e4WZoowPb1gV&AU@#r|?$L9upDY$;vf1*2v}AtuSn@5T{lV%EjIzb?G2F zv7(fBY5_Oe-VBCWUCfbE7T3&1rh9;zA7u)eFPOyE_;?1)$*U9v7dDJRUXpigiVEd< z>?61-PlC4?96=3^l^k*oL6gBJD4pX4v-s72o{me|`)HOvN|T|8ywp%g2gq*lly3Z6 zmB?!ALB-CulA|ap8e61;Y0dY1Aj0klsaTPhRcj>1H}#A%wv@<;X?gYkP-G10HWh|b9D z)-eq0giJ}2cIL&Yq}8gv5NCICij4IPb9`g^M2@-28x%a*e(C(kW4Lv6=45pTrtvO> zoGty8d}e;#SOiJ92REcJ=-Ud8JSQz6_er)lHhIB{x z``HyPR7zCoOE4nGz9SeM7BT+Z-yrcRA*s`3E_{I#;oD-cC4FHYBlTxpinmj{B~ujtKTtGzZWE&rO2AiPnX>c5fi0-Qq@8Y$@DL0 zsnJK%@YAe$yZ%WsC}Qq-6C^@{EXXB*Z70Bhg@f1aSRP5#)mi^NmufMRc}(Rzk;RpP zOv+7_h#w)mPeb0<&k^l@s95DST!eT@?dgbpj`=s#ph=<$y1tvXQ?|@+?WEUeuP{P~ z%+rn`SU78!cp$J$3jN;*vq1LhW(qpD#5Oz`-&H!v-pKk=G}7|bqB*j4%^+L3c^n!kQ>y?QKI0{VN8C+1i!4 z5U8|)mpIdK$YG`=3amx7YIYVOQDzv`5JfjA2hc-rORTe{GH_eG28BYMxB7r`3Qx zilC&b)Pto5Tk6zp% zV!z<_QCwe(mcYY;j^l^`y(x2xJ++T1N6ub({l08m0a~%9v7(PqU@R;{qaR|H38wi; zM$jw}gh?LU5WG{3O-!6e7h^Khn#wu^)PZxFp-)gf6D)8gB6(Kysh@KuauV1yz+RZ?WjLvTcb|-(~63@lxcD(DMLNB5ua!?Ej6vHY)7Rt zm9ISPI@5H~R2)|2g=m~M%QkZf&@c$dy*`&j-MU%;{|2*F&&abnQacuBw^9I|y6U3< zV{975wIr}(D_l3xLK}1!?3)k7;@k#1NoP}U#xs3Y z;-ZBN$FC~%0WC?cg(mhrTQ5;$4x)M8 zCn%LYjd2t-I9q4%8+fKflmMn47s4roK2RlW)At6zDWo6vH9Swv+aD5XEFw_iy&`eb zCK{k{ji^uxPYL8TO!4bb-Nq{7AY)b5idEQ=t*rPSfd-l%tL8+Q>SX;7$}}5KvY$++ zlkI@}Y;MdDJ*)WQWv7d4arrlF;N$Vy%2&2ro({azJ~hmpZwa|KrP$LRHNx1`ON*$y zRXS5rkiq-P6bXH2bu&uo)nlEDH>XmCZt??Se~2+KQScIPmHj*I?p;!j*ug@9|0r*DwU90x;TU z^37q*Z+)_0=l3yGUuhHeg|j7L`TJPRxfA0&IMdHUNf)!Ie&1lsL5IhMOTc;hc-Ow2 zT?@=rv~l;Qx9=ecaa{VUgC$A-jym>}U~1=RpfOabdvNV`vp|iCbavZyus)SBExEU* zu*Zma4WmI&g_Uc@R}!iE$saVXp>fO(;H8Zr^u+M>+>8h@xnsu!a#^M&y4&aW(pm+9 z8}(>KrdaPv@ciVOEZoodo}}&GDeRF3=a4ykd(+kM{VW!ws)-0g>Wv1$;?|)lAlb&TkTzx z{zZx&Fi^63DiWOPr&^GlQ|+MG5%WgoO%;B#2zL<4x3d`DfI5WPCmom3@<#{h!Itz8N z8te4!d(;E;g;X(f9kHQGcy_2xBuR$b4ohRBi? z!D1Dq4-X_`N=3?HU?2oP``{{x|65iW(>9@pr4cM)CX~fmcglj&?1KbFj1kN*y02cN zps*jzUokx7+8Zt?e`#*x(xsakFTzdLr!E(Z=Kyuq&68$N*CG9!6~2A}<}8f{UrtI) z8FjoR$z~8_83pfB@s?fcw)M&QOf73I(ob+7&g}TwG)CBi`b>356lXdi^ZW)r&K&Mt z5t)D4+6sy6iPk+3Q(p?c#4y>FfrfT4bP{=mAyfMs&2QAK2h`Qr5d8Yr{rx%i^$(FKK#bbI6N#c_c$SG`0EE6$Q?p>R zFtYq>ohU#ksg8x2nHH6ylck}aIhC`XwFN*51|VbdS9ua4DlsYvDoHA7Dp@Kys(+4C z{PSDu|Mt%MzsA)*$KL%luJ-v%zvwJ6JkS2Gd}x`N0SaHwG0p(Rp`T%Xf1Ug1vH|!d zHWMI_nu(Scn~4!1s0EN8V`QMiW@3KsEOd;|z3lnJ@{=!R0+j!p1F#Ll=S}-yFPS9f0(lY)V(1n&6Q2c)pbUBnZP?RwO zxVw-cBZ!AU_OeJm;z0Qd!odg{j`0d83sMSU<45owt4VQ#$EIVGHu(hqU+leObgb*X z?HhZ9BereZ9`VdjfI@~wG3ofYA_R)D`|J3q0rE=10O%|ceFK3ZzELwvQ4;|X zz@bgO`=ftHOamoDBdd&<0vJFwl!b7`(2X{UY{bgxVA{K!VBoi+&Lt%_rPF=iYH-IqNJg29wm z61)3yVT_+3=={}TJ}{_Q9s&&`3<~J#@_SHNA&8$4B~%0-So@VCNpnvC)6OJGbB&d% zEVujIM$dqnn?X7zF(p^fK<&4O*Sh0YXJA5aU27H?33ywqN}v$JW`T?6-O2mnVi+?J zjyQqcN?-}#Zbq~xT?iN2W(d$g0syEe2rxih_{FMHsHlk@ZNTQZKwxc0Fhj4@lXPE- zEU?N1Of*n%MK!-WT(q8kL$D`QP(<1L{5o`A2xc07$fpPaY*{1w^Up9jO&BoWdfZ5` z+!yXQr-RGoYQ)+dcV7O$Xg{n$u*l^jz=FhEa&My=E$yB36(S+=+ltxHD>H+M!B9Ea>fpq z&{cQGJA+)vv`07MDt8=+aMBA|YlM|6Zw|9G9MsA$EyvykzKZ{}{4y1C zu2rFP=!SpMyavz845LaMzm88JV&Y@4yH=eowSB5b3fUc2*?Q1Jk^Uml zlUCNNB)Hg(?#;Af7kzj=%t&0*s1cUKgPJ^1h1B3)aSOa3xWEWMp~BqHP#ZvicHFq> zjG&Br9@!lTkJy@j#4k2FgYs#FuoE4KdB0$5dz>acVtW@v!)M%wVrU_h9?8=JSoQdn ztZywA2fSXV@bPBNNfL3vr)YAJQ6H869Wd~Ys|@oR#mjn&oe}8nt})QKFKw|r6lM-; z_UpHTG;cHp3In z4_mShErMMv)^ga&$(-g#?=U@>KdZEN)kqZGrB)q`Wf`AbL7mS1JCc=#mn=o(^AE6w z3G>+8Vj02L>XfhNoVx9!ETHgu zlS^^D5(H)LhlM>EZ{W^I%4XSPpQrH{+4*Tce%}f{7r6(FnTR2{rvJd0?n?>@LuS!Q_vYwh&eL} zVP)!%bOLgO{)X-+P3)>$k*rRc3u$mzJzg+bKUhO5b(?C`@ck29D1Vzn zBB!Xx6@~|sEUmdI&O25M^bI3M$hR({YVQ*-g8+1&0c8r%cT0iun+bz=S z>)Y%nwy9Hdf_T%G^1>C zPwBr+t4@qT8ZHW4QYJ3Rn>Jcn;7Y}@tJka#qnq-ii8c_2Yut?S;6G??-y3rj6NACVmam=`Ik#rW z;R$L!fo9qok5DfY)B9FL7~gKy-wLQi2s&*Zkx$CBK|zn;0d5GL*@P#We~IP}cNX7g z#*wMRwwl8FKBi2cSlp4OV*>J_;V~{;cffZVTDaYJ0~sl-=vhkoQ+4LpJh|sos;d>o zxFMQEDYPkw$vzS?Bl7ppv(sNN!FE&j`?SpjOl)luh-hr+9V9N)J+;ylKs0UN6{gf? zV;d5aMICju*rv-wGm>R+jUZxtWbK;eJ|u_29JQ$K5J+dH84qr-{TQt(z`Xg&Mpd|E ztf$MdTd=kVb=cU>54#t0~;W>~_a ze!{j_YU`1w-H3Bp5sB4v$HaW2dKsJgre|kjvdu1$c6!<6`IC;cb@sbvYu1ENpJ*I zG@K-ja>N3h;BM`M9?+Lnz9-hQAuOz4aWs?_@K(hD40>-Y}{s%Blxbf@uu2*{X>|iDxZIPUIL7EInC3m z&n{Z(@dC<1iwE_#a~f>RgN#$hO8Yxt&VIbBINjOteY&3)>XLV4Qui#=FlNQ@?tr?W ze+l(eXo;O(i8O1ctl9P+i4}~|m&AWgxs-vtvL*?+@V(iCjQ*{pZTSK-C9Sz+=C{HH za@gxFrsNL>GDI1eGg$cS7(>hxeok9LgNXR!lp*x8mRrgwcZ#>Spw!h@H@dK}Ve1)` z{OaGcA;iluBQkLOeR1Be;%*87PRtZbv z;@25iI)MiE+PjT~+AZUU@k+edu8}t)T2tQG7HQ`(tK35lCksvwXU8X8hsM%jOFQiS za@+-*Gb4@$enRpllHcEW-|#+du6UP}Wf=ul(MSMt)-wVfZ0D@{R@2m0kc9v$|?%#f57Y)BmBY5e^@a8mUv9h{?{x2 zBMbMhmH!tk`!ARKw;I1H!}JQVU54C zJ82!vTxlJQzJjJ{|I8}>XBz#BoBowX|Mr9Uim_q&qOSkq_D}Tn&+#^Y_mlmP^z{Yp z|1M_Wi@q5D`}F0;mH3J?fg(aAoHiu+Baq%e2WceTi_~bW9W5%&Y%J2NB#wVbDk2aC zHZSh1w$L){S9#v9A-md0c3}^;)8z5mM9$-f6Yt~u`z_DpHgUgBlh&fpyQ(Gw| zL(mbx2Z*cU>M-D05H(TH0KmNQBceq822Licr9GNF@e|nw@BqSqjt|)O1%w4(vf6|I zIO_(86#}KVg+PSVtu|%Y0)5fFhA*_@HFmWD%Dv7SkPY=o{DnvEYXlW*l$Hprib4;< zMT6Guy8%y333N&wyZ;w_4SdI%fZFd`&rX`&EG6@yqIuGB^5=~c02B8m1_X}3;+4$m zxm=*)he_V~beNBf{H-?)=8B62f!C?91YlqZA6nBBKi%oe3WW;bz01#aV1iV>)Tt(0 z+rY%gP@D3}GHyeR`5i^Z8G__v*-_*58=;S`G7FI<{8qFtA-q^}tkcKS?bC5df-4hX zK!4o=zZ5oKoY*g22#YUC<{N}CkSZ4#3{W>-vJNp@HlMK;pz0TWZGa#edZd=B`yv9u zSto2(V*tq#fFpYA5<$PlcXyE`0utK*1>FV6>LI9}=zK5z%H|vW$We_7;-?7x?D+*O zvDv$6{E?lNhmTLDC?||9t7wcaK)?j=8;n8lgkB3}uu#r(_v&fI%l=ov5hLa{uTlRv2JvDog`z8y{-?xpZDgn$017(h1A97`BQ?JMz`$p=b)_I zU7Xw=XCg5&?lT@~Z!24jS&hb+Wj5>LxVNu3A7l5T!CcJEde2RrzM<|iWfH#2)Bg~j zk*2%%)Gnv+Vw1gEQJUD6Ru9C@Dwg-Q&6X8JP@mjs$*6U6H@g|PbBVjdae{j*%jVhC z_Q|9@vG*@&FBK9{o;fci9did(87 zq`d^Ch!j_fNHB%Lb(vyvF$aGDv=ZU^Ocgqyl=xvoDnyny*kaU9`>Cqkm(av2q_gOf z{%Y{cF+fHE-o>x#zEn@p$u^p&7!#jh-viu*HM=7xDDaZu!zf_3&6jn|=+t3Xx>2Hn z(b*3N-gr~jbJ!cXAoo3Qmb6w!z1fLPFfW_+DR9uTvOgzng|)oa1F9JcmV}>J{h5=A zJL!IN>*2^&z(8Y{m_G$iX9)7rsb|-HW}Y=DCS3`GMJTGn&TZODxOS9XjD8uKTwr&! zwO@OtzM5{#xS&_2{hq1)A;4yFfmFj%DkaQ zrHabkf)a9>_n~~ag12tXH*qHq+OUwu`{PY>=^+?b%|ZFIF3-OUIRy&&$ZbiU*Iw5%5*#C& zo-1>IJLH`8m;pC-nSdcW@!|70dPP{DN-;-1Df@!-sbeFlZ3=lqKk!*GjUmRMKfa$lO(~D9m|K z(vQMx`HP?K23ef!Yrm}5DS!L1vbv592qp z@eKN!-NejAGELMm=bUB+Qv1EK4ANvtcN+=747IbJj zj)1i5M#xol8kc1XK}mP-QysoIHP5oz~sQHN6U7 z3wzwZpzgV@`Vq%nbvi=h4xDq3k(?y0r#81xY|oxxYqHl*9nN!nXj{j13|~oUO`9fB zc2aNCr;F6)TRyb+!>n!}u|~m_S2_!KZrei1>CNh3n_d{iaCE0e)o!&@bsqLqqBXR2 z;2vaqa>It~KYj}__b&Q8S*{jMic-8bCwD@qabs;snjx(IjCJx)FZN_UtO>x6)`{dj^6bU5~t16f9b zveCP|+NgwMoV37FFXQj-Kc?>w)toG`%>BS^ZqQpfsJ}I@8#J+F&1oqOQpYwI-Zpp@ zm=VdgjLW7O@uE9q@8%d*U`BzD4PYS^nv?Kw1D;!VVhWc*Yl3w-Gty zEa$GrX1NM7ouyJP2-MC@r^tt$p@71>i(S{N`T$2n84D7ZokX@?a3UIS#3iS)Q|~HW zT0RGrsmj8k+$P)O$=P$aMM!@EN6tfZ ze)1E=Ic7uKd*)rWQn#G~1^4XRO27URrKfXNS8iI)!7thIZY5})29%l&)q`ohHj*$DA##Pzoc zBJ0whbE{S`y>kMER`@sE${uPNYHEGzSWar+PMVr2Yd=K6Ok{XaH&=c|;${*Stb zKRPDxZ*8b(=$ z&KnpDn@&YHAQ`}cVqUH-I13c2H5!fQmQ1c4%_gI0gMXZJ(wW?Exk#D3J$dFjd_H)? z8NBB8?wYjA^g+N^fHsr*K7laTuNO9Bi{8wTYh`H$kOI2JKo=Ss$^s|^Kh0JS>kmNz zY)eecmMd-#wiWJ6rHM{bMdgA*0A#v*WeBvg90U<+A^Aoj55Tm}2ZRyU4Kx6e4}BzZ z?kA)R0F8zC4RM&kmjnzr^^;>8Ff{-NZ<{1E-miQ6YotpA6rIb60qyr;Z|Ljv8xYDT zSdQpTrz8WfC%_yEzBoM*;1`M<8&xn&E*~kx9b$ATsC?F&P3nt@gBBu~1LXEY+508= zyC}|f@IdURmY+j!LMR>}-9R26&_hn4N;mH~dH@;I@Oh3JFac12h`D|iJs#dSUQ%Gr zM-!~`yod)Nxgt}78BkjRU9Rp;JNSr~Vx*Hh?^j>-)MHGYxrDbzbsthG1XHT%_(*WT zrOo*+^bb~r5FtJfKova(IdLSmqkU?8{ICa)o6r^2rY?x4xxhm`x^%*7g`09j zVSE5JeVZ-;t)E>>kW%kPd{fXu0>R+6VoC6efhjK8FFHeK!#`85wq(X2kIOr>(ti=$ z8foq?c?h^Q5tCK_w#(>6em^sPo9PE48xgmTe=IDrDT@KUdw>_Eq)ZWdA%q^V8KQND zt+y(n{&r?PyqyyaYI40FzbO*9NNT+>gNi}jjm+Shaxue=jrG)W;zO8gVgEEFn0Phl z8tP@5{BtLGhp>-n&n`V+O#dW8AZP!ROnGM5CU%Br87?%`AYIp zk513=P(AFjzIJzYax};>u;b=be1q$a>q**`yy`yR7dk&oj2rKW-LZP+<$U?hs?PIv zo_{=2x4W2kmZ3Qj@y;aF`!%o$W11d!p?PMDn+VU9!-YE^4Nb*B^^p!xVBzPdt8t;t zf-9>|J{$uz23G=u>XL+V^*$B%335$>`FH(3qdHZ}(bmBPX2gc7FEc`S>&MAgaYab^$p!u2bMP;0Oq6LxA_U zOHECew|sPW+x;E}wV4;+5VCh62XfzEI&%&X$FtjX#@4GXn$IqlJ72neLw&*bkP@yX zJJOUU{NnwC!9Piw?R#V7Jk+c+v;MbVrVMEf|ny>_7`e!Cy;^Em#1yi8puQc3m^G)Q}nA0LbU z@$w5e*dLRl}J-(S<^g);vr@kv(wyw^sXkF`S8v|L@306@~J^W z;>OMl<`i?}c?%StTyfDc4|;K!`2D=EezV(I1~R6_R&K)Aq*R`A7Z?YL9NAxY(xC|g zEa_3(QTt)i0j5cvI$)HYKNzW~Xk7dV+z3QM`_f--wF$RmbxgXsn{}8)nwg&T1{LTT zwOpLHPqTj8;<-GvLo_7SEg6}Nq{=2Lo$B?cysb{9%@|?T%Z1Lmj~A<#Xw>x3=^^PT zE~VPq!8An*bruq|TOM5Y9hexS%E}kk=>oGO<>-7jP9ke^aiC0tAlXmF({!boXJ_U0 z(Qq9SioS@M)IZ>_Q?{-n4^biVdTsKwDOC=QHe+8Z*g|CdMnwmEhVt_B01-AwtNP?% zU~c=-Y7-gPraDX*Mi?6@K&+5WVELp}cu}M7w(>-zWubk1L)LBNhmE$^vTkIbhX3RQ&b7;yUa({_h_Yl*-Lu+gytRR z73PPN%oE&R?u?Nf!t)E((WoDN(a@=F42niFjvHPGWn^uxus7MAYIQ#|j&Bw$=dh=p z)v{n=Ka$P?u0_(&AkgIXjg#;|3 zZJ+sQt@LGJ_of*$htjMPDhGzBu-~GfH=w_qaYngmS@oRuKEot2I}^4`*>&(j&Pv|5 zKz~628607;kYVU%Fd?yGnxX^dBCU@t8}rek$zMM!g>?}pl%*EVNBW)MfETy+NNi)( zhm5Q0Du{88V$bAOBI~A=&?BM^w}$t_t^sVf(p9zyfrMH;@8KQ^=u?jJGqpXm;HfmK zXmOY%OLh`;Qi~K4Bfs?$1Kb+AS%R-P;CX!r&ei zqL9}f?hU~v)1!o_y_xXciwJ|m!NBaIP{tCkoiOcTH~D*oy1D08&J+RZ*OD34=pwI> zYNj$;p(+uJW@f<$q38h*=~#oey8W1?!rSu>Z(-T=v(`*}%#sb+!OO||w8j)$HaRm~%D+Oe##8QI(Ir-H*Qp^%aFk4NVe$=^R*at}<=o|2aFvY{G7DuM5Tt%WFfEhk?cfELmp z;PoCq+38*Wj=bLlGFM#JX_h&@=6f(To6QuTd)~#xqN4nP&3gSj)|VMBn58zmEIGa7 z5{uQ8nI+&~Jdn2BD)IA3OUq5_dV+%~WmQK+vg?r4da?Gf>7fu2rLSnHGAEkZo~YrK z+Y9N+Nt`g7)c$oJJ){H5)N+8MK*glOvESr;$&;@kNah9`(!ysW{}*a8??W-kQQ_kE z%_5lwnlygie4QX0@2bozcKUtgG3?qNy$)LWke}S@d5?LwBVH*RCub3;ofA@G^zDnz zw_g=Tn6hodh3N&QSY|PmQCDh=QO3yAx&ri06HjwAgXtgY5V?wXq z^an{78Cm8cE3R7Su;Quj!KeGj!Fc18!CLAnmsnkcV5o1D4;ouER6TM{x6X!trJX1Ho6M86AZ;?O0kMyaB_f&r+S8^B8P)8nV$m({|X4?~%y2D& z9e4QtL&;H=lHIyHhlbC^P@Ao2h)N={B54TY6`gfaaGO(a)j6FdoJo-JRZMJKNOP@8 zC9YkLaDg?yVoSmww<^(UXkx`!Frxry(@=MF-OaM?U06_jC-_seH=*Yk%Aq2QV)2JF zr$@U(mGvfQSy)y<8+l8Xcu9@64A=Jt&Vtm^c`(oye}M^}!%(it9Qn<;{gOu87(FS5 ziy8phChu42DpGq(MX&ogPShso$I}Yr=(2qq4KdZDmckjiqxIk%02^j zX{5Z_q(y>6u{Nj*QnnQRR5bw^2KiFzK|}3II~DzG-Eje+GgP-NXOAttu#M3W?1Fh?*$yO2J)`Xq7 z(*Xf)3pU!{5%Kc)X;xz(t~ttSU7>Gz9?fnfY$sY7#P{W&u34W*nmWJjc%wA)s&zx7 zcLH}(tMWJql7rIwHLX&tNcDajV8Kzc8{0^9*lDb|gvTO(;ge*M^z$+HayHbgnbRX7 zVA8)X*!eEyszqT!Z&doO;UlVLunm=_utD6^GIUk#jL+$auu9xoNwqrUs{-9HG!czT zo8)U=W4U074((>aB{^bOsaLl))EOo9MzH6By7rl8VP|Y(F%3ZC5*{+vkS}J}y!O6E zX)iu~*KE+kQ^=bdfipoDj?n4Uaihq_m@K1ZGt1TrB6WaPWJP^}KRT%sSEB90y0?&S zDz1afq`&Uw;YFxfOia@0>2Mt?F@$QedQz-HdZGp?;D(BDXo89h79s9>NX5Kd(u?fB zM~|3*u2)MRLr_l`FrQ7g=Cz#o_%iNnd=&W$Z@5p-VE-4!xF$U)Xx4-)Ztl@}6}5md zqx|ITgFrc0uMQDX*Ub!J6*B0Cxk`Bt>f%glqP0(k4Y_BvJ{!a$vB5%ffNmX_8q1V10nPS#Fa0}sAs z=7^PVhHtocV#7JpZA&TDHag?zJR3rVOlkufjVGE3w#&LmTrq(;LO|0c(|ZLSC=@9e z;eir|IFDV6a2o6-1n72Tt9iQOava&0;O{p=9kg=S)5U3g&eu@8yjSp^#Hhf``FM4r z4dJ0P*qRl73P?9e*~JKej-@HgT4spTMW)^-2}?!1zjafwK_aoW_#FjU-`oC{rs#*Ohb`*EoRYV}Dru|83`j6G_>F485t zCCtvc;N>n^E$v1dp>`iUdA1@2M~tJe;k-BN)umTl9Ix-_tS!o!v@@2iS1QkmpTz3vvQ8b4rs!(sa_Yi*-L;}ZZb@m) zc7!mxjh3GLG!>@lkxJPTD9c>oa7hGyEW$hWMVUElll@U2dhIsZ{=sW7OBL+Vq{KmR zwnZV}rqvxP`0diIuep#hQ7(lMHMl;g$%dy^Ba{1i&?+DZJPSp>sg>2iJyN^5hO9X{ zP!1|9Gu>o{r=w&?!jcInXvOb_JHe^~nj`$D`5=^9DCh~7JMW3sTve6p+S*bDm8+MO z{HY#`7nWI}4&|%k++7`#k@|Kj-`Q76EUKCd0#3-AYoA%pTAMDTjLhkYN*uMsp z_tFR^IqW~eC%;82{SeT8oK3b9lj&uXF*4aNuctY7`!#G6@8c0Vb}l>fi1%;4)?Xo?n$pOcuaw?;PrTCrVSorA1QXx*n*pCuk3G>k{*BQ7hehIFwc7us zUFR=L%|F?7*#9sz{C$HHJ^h!2{`VbDUyWA(gVL@bCnhB+`lYlhivOEdcY3zJr1^g+ z(0{G`{T=>4(Axip3;wg({!iUpEMJbF|5|VVilU~c`!b;X&-8XZ+OJM&T4P!hS~J@J z?7DIOm;FtDs%`(Wzv<5p>Mx!BPk#*4pYD}EzJ9fB;Qe*)kE6ei|JZfK_NR;GFF(y+ zo*E{4Mm(mkRYrzCHj4f6od3||>6!j{V)1uDIwy!T; z3mXw=C?19)jf~GML z0{a0dNFtf|(hsf8z^3iviZVDG>jFG>^%l`Qe0mKd?;U|KgXRXM7Xb57r~98(l_VSvvTPkF#T`tzklFU~B>eRQ<%Rb&Rid1W%*T;K)z~7>l&b+@5pq+7c32y$Ofp*=UbRXK7(v8%t`Qh%a+%uI!5&w_KvxnXL^gfrwdxWgvsuIX31wfK`XcABmDVp`-v1xW3&fi z)l`^pFBuEmtq;`L!0aAo3#3ZLbw1$uh!qt{PV~<5T%uOxI2EOlwI(O zTKiw;asOC)5tuSA>wupdEk^Zsm-~7&YSh=kwCC4B#V0)NT*L!3e+L>TMw)6s=I3Dh zP3Tk#pKWsPxaEsS)ZA0n=lj zb2jC#-7P-&a|!o45X?rmr~+Ecop|skBNw!Rtw5havMLWg+q_86U+e52L7!tEIuK6# zZ(sLX-oDONemya16e7hset`R}@skWW z%<3Y2Oe&M#m;9*_;rp)6W`-_+`Qmi=yR~MkSJ02{2fD6YFzr^TB}sh4o&nZezlDj(pGYp zzf(ES1_K>sqPv17)uqLz7AXftJ0rRjQ+pJf)Fap0bhAH7(?I$86j|7^*^rX2UVj8P z(g{VJ(U*heQ0_Q^2{m$}HTLrS;dYa>?xx-*X=BSFQ7mNC{-?SKQ`3H&mw!okS?&X- zjp~S51Kpf*I|2G|7D;Vvf_EkK?H;ds#d{RW>>8k$mn2}p04HBru2k_)&t#(%=J%V;E;)*9BhZg!Bzmb<^ zP3h2dSgO19DA~sZoWddzp(j|RDXJzLk%FT7aAVCg>Zu21LPa`_4@bY!*jaX)G_^2s z8G0~bEPkuCm;hf}{?L_*(}*(t7Gs^Oobo!>9hvGQ9hC#!{BhYP*%=f2a4h_aZmPO8 zUzb3s6HJJm%^4){1TRPy?9SSJF0=G3>B-Z_<6T7A4{JWIFYvxgIAB?q#4UG6#m@E6 zR`xa_G^!oNC^w<0MxBPYfPb2&4QW-}os%3Ao%R4ecj*PBpfuThJ<4z4jE2Ly#EoD< zsk1Do3yhwntDS!f-ay++ga2W8W>;a}51;_x9YpP%Gf*sz)#XB8NZcli=*9t1k+vyX z<>R2gmG734M9MrCyinVTghuC%5j}9Gdg*$WjD5{oU1uUrDp2|TexG}E>*Xn1@v))e}hDD8dU5nQ9P@; z_{ovgA7iOKo*WZ>+V(X}wWG(=2~BciHse-SP&QA~URJzQqdGXPuMD?Q!$MG?7EbBZ zLM~_bhX7vW$}x=#FrOtW1LKRtJl_5Wi~B71O)Z1;wVRgv=s0((TPP`$wUmdD%=bel zhykzNy3CdS#Zlidx7Crv{SWw`H||swtmr+ku}psTrZg@;pYs-cHwn5Lc7j)xJP>nl zYB=a}daepk;5njrCj6E{y_>cgBdwKkX568uW;)7`P+lr>AawG*{OQ5^9FUt zF?a?mQ%(xTGfGX@i6uGL>~>}{hFwT~IYYRHtbtIPzX;wmmXVj|6#*Ub_wTBn3)AD! zIr?sO>p4=aNs03yri$-3I~I`lZI{a1>Zd2>I(k_>VR;cWRXy8OW>)SFw3Hy1BF$dRANwrSu9=V<$NkGOzsw(d3 zhPdVuWXRJ+Kfb@LpUNJ6bhxezq=uei9J59ol(jKbks>;LKo?YDQ{i2<4-ZvzLosgD zY{o3~9FUfdDQ*L|W`NIPKX&j;3cN`gDP z@!|rWeTp7yM{}KsgDId9u8Wku<^wDn3SP9f#AJ=GzbRR-zq%4_Ao9rE&)V94+1C*^ z79X^)QIjIBUG%`fP@dht*jp6_x@JR>Q+TSGMIgkhXaAsxsLbA97nnd#b=UpWtxFkXJy*iI3*5#23NWW+YHl%K3Y|o5COrIkk}lyXuL-3V?~f zz{u_@E_`Afdb+Fcx|@&ZU=MgCjc13j_*9yh#h>ojVeA(&u?#iT=4}2!-~cLyy~s3f zIUyIO3M>tItH#Y)k1Mm2#B{G%W+r%-0tG}->xvhPW2wugbY0(c&4ssNM-|<8rqZ`I zy$Yux=7@Mj8(lO=5*b#dEFvQHh1S6d_9DWN&;86Q{M)>Qah5c`GpksK$Rt2YM#x_u zKLS&a%E%zjHu&8U??pDVESaLoBsYFXm%|J4zP(5vp->|IuD7 zuNWFyRzzF4ry>7kUr+;PyhM7Fr5(J#I;q}OqVSSi$yzQ<|C~BC%jl2^x(T-2Hp;16 zDVG|ZQSK?_j@(nbHA^y#E6vAjxZ)(W>NZ8JW5b2xe<5lLP=4-dh=k}gKfsIG5!D&0 zqAVmlX`|R`T>2=S0RJBGSag+#d1RJisk6e+Sii`wa*xfpq&Ms;fO6fS0ixW~HX2!R*vGcx2dyMMRLMcwVvW$>?^Q%rMYr#;7P&g{|YUEK#$# z0kI6={jIzu6bpim(L1pZP6p^^uY&JO){fZZBN^t+BDx zX|*#8k7J~%aEhgJ|Hwz%!=^^#5QWQ`yS zF%6=95>X;9%o@hjq)gGC!o~^sWxhDt3LH!$hxp9b}ro*m>W4%0dhZKqGMrt>aLVoyz&>9w1^ zMjcZ2m`o^dB{4(mq7 z`Z<}Scpl7FD#t;NsKv=se7DiWJ6e$oT&=i%DuyO#0S=qDlOX1dTft|G*M}JS63%{k zxYwuA;K6dWAo{;J6Ui_K2-taXIGtZ^FEBd#wF3+dF?R#0X$WFZ>2T!LMhoAPrN#XT%b5A!qkj(GB*9+#VG324+T1a`!U zzR9vq_!bc!1?UEBGpi--!MQKPoaBflox`y?$3&_B_$Aq~NvP<1wWurpRs; z5d5A|c_UxPxzuofG7AeQtW`Mb^OQ)`}~)LVvE^!&vnUds!~FpT`R4Fi00Z-HzZ z2@EHCv=3bvs$MyFp>gx0(yHBX}&Chk-%LC7w#%poGPn3NGUqhgYGWs|QQEU_q z*22keIq#h=Y@%5+80!nOFFV`z0D_yrjI=^9xH`=0jB%-tUUlAtq|Um+I(e!Ka35sp}n=KCx9^MajBt;nN$N9^|lZ$MbqxpK^WdFHn=j zg?5{wZBH2>jNXPkbbj=FwzJ`Z>|C%S=gc8!Ml%Rs>t-vy)COJ*8F-STDjLU8;k(=k zA7S>;t=~TGhz($k%hmf}m&stac_qONgZV5uy$ahY^lqzLXM%Z-vw&yrM4GwZq9@(G z&&I]NOvsCl1XLgsfNT5A^>vqi1}e;Hc~zf*Zz%|>^@O4Zh#yeRBi87nm%8w&p0SQodj%DI5j*Uq~S$D;~Df;ei7Y(-F};tKY@SZ1uiTA@G9j)3h*X02j53G%tAT! zdt!bKG2-|v=Lp2xjrv;B$b4a2jhy-Z#k&wUME+0$`dO`B8yxmq@e;kkQ|KZrB+(6m z!NRhpZdrTXffF}8IixNnPC-R8uEkPZ(5yxXJO>TkM@63J9%^)*4Bqh~v@-W}Oxi%& z%Gx^%8mx^Qy-XtfMsmbCqFl{X8}3iJ+Maw!4uXl1d?^V(WtXld-3i(%)OJ=B*HrnN zr0gQ(yq}{HR{0j6x9Mj>f@@N59kkL7nv8TvoEfxW2{;Od&vi^r(^A!ILc`&4fE3h9 zQ;h{1$E3gM(&C+6_bBhV9ISLYg>m0!i(UHs#Id$3_qrH*Ep|PrPWobUq_e=cy|-w0 zA5rl3_w^XdkSPzvaN#TW0k#bLv!)dE-SrB9hcqMt5~zDJ{U#7YmXmMVQHHOM398`0 zNs-9p=7>=*(K;GIHa{VEjmt0XsEj<4}K5hdb3CBl)B z3EeoirbXE-vAoKe(OT=mH~9uEa2Ne40PPN~)fPA7$L(j~wI0FU8A3aNSNfvk3`+Vv zzn$=#sr-IND@n3Bf3gNqb~dM8b)WMp+Z1S`zEmLU#WY)KPLEkEeG*geo2lz^4QE%d$Del9yCia5Od`2f+9Ma$yNZ zo$ZNt2WVd~^~n`eM6RnPsY8P`VjT-z%4Yc{)Kz|}6#ry&0T=HZEK@bDR2Z4Y)Uo}j zUQz#W^!v+XQGv2x1$IN47*#;E-2yAM8DJ-aSL)?T}UqM)W`YBZS2a$+3AvGEtk}K=5 zpIqonjaecYRNgO>(Vl`tlrzPq;^ZQy23mP?dAmk|rEotC_@E%>AD3*Q4aVw6 zsAUwY0y$*ne=U5~qA|yp5?!fzvm)7OLFWL!XLX-C#PqiuG53_Yn-I;2F}iz9!ub!qPIj;iy4r} zu_fhUbduJo7Z<(Tyb!q%U*1(auf*DFWrD^ICII{#%E(jskzeR|kkFq4JSL&IPLP4V zf;72HEo67y7sr`s`~|0Lkiuet%9Dv|77#)R>==E%Fm>|4=A zMlI`Z(nb`LhLl&c)GBgqM+R92u7tg!<7JET#=xhEGZ#>t2;e=~53+7fhL5B%cjogL z&4?{#@=%NXt}67jah_u~(Co-@X@H>7cecPMjzJ;3_^iDRNm0WeuBriD$GJ`OgG_O^ zCjzT1n8a<)YD5##O2i{$b|COf9jqP>?nom?`rZrv9@0WSDELsr$i!lu__(=T4E8^< zr}m?(Fp!t0ozN4)sYY=L9k%Cpe)&8 z3COniHUGR8-Nk5RE;neMiss6rHmWZrF9NK}qX z<`dHlQ&2{1dS;I-7FVNG`U%X+g7td5{fhQeY$|??)9xa4W^0z+MTzve*Qh%2H`p#H z_227RL83n*7{kX37|CF+cPL{6A(Ne@mzuJzwPhlbbSwd_-kk)Tj1i-2j>HXQ+B4pL zB4YsBuXzoKp309#8-_iHY<-kIg@*7^T$>TZUCi3KLaH7yi-cK)1XyfxO3Wio-t~sD zI2{WxZ`^VhcGS{v_$6msdVx@!vlk}x-8=~=EuXOkD?I3b1_xJ9(#Ts8cS%u8eNYch zzpwrt=exreg1hufi>!*-aO9lGD#mrb9|-9|yX@#fcD3pNd`bhd`jL(({MIZr@DPVd z^KGS&@y_a*Ps{UPt&dUaTdl%D4J@xPVq#E?hO76nXCj^bzrE9UM3oJ ze5b4xW7eGjQ!haSVnYwa?j8v#7@fmqWNp2pvc3VTa&!Y@3MS)^l3&@bxI{-F-O@N= zI+uWp^;X)wq{z_K($?;h2q$43g->usWZ9XG1`tZYhWup+Px8-vY$XKYci(u1 zwJPG3PXb3OQneP#XQ%GR72&S>g~!`vy{%NJyUmV4`Hl@obQ(fqvBj$8>PWku+NF)o zWQ3}Nr;_oUb1iG^36H&V_4$YE7m!k^!82wU6MSyG*1N1nlBlMPmuv_vGvzHY-)k2h z$IHo{6_2WAiu_{5kq7EWPGO%=GwYvjc?zr`j`zl}^K7~#li}&$s7;$*tf*i>5-dM=Z+#;^5Flv!x|P82BbH*-B(@BHOSAb;}W zXiP$^Vcg6Q`7G{#&Fu8z$96>_t@Re!$gbbI0d#^ERrb-U9y0BTplCC>hd=#&>+*DEk6gAmC!zcJWVJSlamZ@KXez1eL z9muI%_q!gwEkn@%RH(Gm<+=xkG)aZb(ff1kZp^M2lhB5%QFu8N0ao;a>TCQb;nf1= zp@!75S0rG&vPF}P$*4}}?2NFMs5hrwI!ATjuw@b^dnm*1IN>tPtH1P)6%rpdT={3K|fva8GuG$1S=Ly_KiO z%oQ5mvJE@0nYzkfuLBod8q|YxuVjO!BVIxUV{kNzQ;gZgZ*)JL$xnz$?4ud3P_esM zu99{NmpE>U3=p!xhh!mgttAwaD@l9|0%ktIW%O?vmmaEZtpLpXP(FfRZD=rTIE5C3 zogfGsV944=x7kAVDaIcCnmIHrtvgFsDPvTLV{JUDvq>wLv^n5Q#J9E?G2-ETRcZyk zo*0}rO5RQs)goqT#W}Y4U`gd@Y&Cto3LnqfxECtlOxQyr=7`}i>9Ziy1=xQL^bR%L z0EntDtxi#C83)co#!gQ;eI8h5R7* zX!sdI&fC>#E9{PT_NUd>uKr{+KdyFLO*6?ezXW+z_y?n47~8h<1c#4%?SvO&Qg2M; zQFhS0?;4&UTJGn|E2QPG9v&xD9nEsXD`{wxU@q)S6$+WiHz7UNH5;BYN|B~JjZbDHlR;ai`c;HZ0LoVSs- zj~WlrJk=-9($Pa@pbEIt#lFW52(;Ftz2gMey6HWP^X{Z{=s~r>C1XOrC-*Itn4yeeG>6q;G zSuW81CF5ovfZt>tC(ItBxv!k5<$1@o^r8^;j)!^_odm6cZL*Rzl$5U4J;Gi^qasXb zPNb1%XfsUdlGUw(ByD&1!dY0WxgX~@RQ0-`-wZ^Ty4jVG*EzzQE%O~G*N5!Ydp1~- zbvJ!qsQ8^b4fAbu1FWw+GmblFuuD*49xDxd0CA86%54DVO zp5lP?W?OJ5x@kPlf?hj;9ezo@$mp=td`&M%tl_*}A?_Kh_Khn$wOmbo7pR z%TCAdcQB?sZCaDQTvJ6XM3bk%c9()xj_!r#V@-)>o_gSaW^ znoBr^YlN&AMfndx`B{M&&$3E)jWKH?c2)3X>lD3H_+!!(bckPMDL(4Rl~wci_~neH6gK&BOfDh!Z8Nwv?g z?IK`e*`>QPl{nxu!xnmyJr)c21ybm?UQd1a0JNP`x&l7Wld6)B<4$*s7%ss|q0X%y z*^3KD(d#>07uz-$0QuPD4oikumxFvcVYdPsM4L?^o!(n!#t23~$NWw=`tGNIWo~uY zJ4KSPj@*Nmm|Y-DMWl;bsXq$l6?xn&KlQApcDC(6-JF@M*s`A-#+Sa0ezi|heW^P^ zCjIA+OG|aGg_B66g>CSYVEl*CnHQEKM!0g&deXdi-3pVo4$UhGS=h(&sd zu47)Nz8)j~QSzkRI&4YZR3|SwY};QH3a9r_ylHBi1Uk#$ro`*=uVwc#uzH{(mNXHy zGUSd^#uk{1JNG!FbTZyHf_;e&i3BJ1OM-V(MFR6{=}z89$_Yq{psk8r`I$J^?520Z zx~{0DWaO0OxbH#i@OZM8Ez^N>s2mMVEnWAcDuA*ebZt50l+*E?2n63?y?Sks3S8m0 zCC9YM#8cmigE1)3#&++H#wR&+D^YShC&N$ZO%bZB3yv4qlv4LOe`MW)`wW{5e1?sP9I#F3({3ET1O!o*k5Vm2C&3Cdobm1Kp#tH6|TY! zp4=2id15vN9}rYAicg#JrK?jQ&qC)o*3@o2AbAFT1kf zy&&lqrH3!GRc*$*_kmomA4O_TDvBUWclx#cp7Kslh9LZJBeSRQ%-2r)BB?r8kkE~> zok=Ghzc_M>ODpn|nowFUu<-7q-W$*QZ>PDAs{H1=HAk`J@_$Ki&lu5QmCO;k@-mWRK!{+?T8vj@j$rZ!26xtJ9Y}p_HJWf8hKwoW zkcN*t5L#r)zPWps+i&*7z5Fx;EpI65P^ zuwR)Vnj9V{+q(oD)Z6fNd+lWet& zcznz8IhkdAGiNq7n9!&jXue9o4(En&71E8w6$EwJ)Uwj%pYal+GnhE zrF(-@mhrN{sAcB9lTlX+gJE;8Fdyi7d7E({GL-Ha}fG?}4k_lH5&O zuH58=X7s^Y%_gc@kXgQy@T?;1$^Fbo_%z5FIhw8l7mSp8R zE69nF8Kk-pLFvDHhB+RF*XS;O|8_7#W*S;8+Kzt~+I4D{2HEPDj4^KukBP=GlarkF zvG$q>wmb$Zjq)jgMQ1dC82k8y-L)oc+g5SUD7teKsH^2q%~C!A%!Ulg?X0`C8Z3){ zlhhjtj>yfHrOvqx_*x(4^mfnTp|0yixfV<^M>Jl|(2E)FguOhF|dLDu@7!HYh_ z-E5`|1bnRfkqh5V-A{ma$cU`XO|iZ!BN6d5rSACsUnO7zA$k+Ohtj!{6GAUsGy!#j zbnyy^#D$c2*B(Kh_2;warubOQpKTc4bO@uYj!*Q3hevP49JV$I??kT%xLU`0ptU^XNDJ%lP)@y~GIpG{r?C=>WvpsGm& z^jn?Tk3ZDzYrQ;9kv0(qAeUfujT4`%ft3exny$hvr)5m?;yclP5h+VEU*-Ka1jc{w zHomJz6pYqZ9+bt9ul$e(lesFU47asVayd4HiP9(T40x@z!`KojXuBh1$vA;z2K2>H zU{Y1{h&c}j(xE+FxYcjAxUj7O{pD9eX;;Wx zg{Zz}0zMhPMtD2EP`vU43nDU!NCCnWQRd!xXVNLbEDONFJD>Bx{-ne2gQQZzXnf;q zVEfkPF@Aes?t@CS#n4vMAdSRxqqc@lV$!Lu=ir9Wr+wOrgkib2|A_*Mk0TBk4$4Uu z>@)72IS%%$qYz_RO+JAyD5C5mD_0r9?^+%_`lnMAylj!HK+zH60L828NGnV~I6AjM z82j6}vh4BOE~oWMb5|`fMg%x3SlS&d-?15rpBdJ=by7h1eML%phnkC}pXgbo3mcn6 zIteTXZNcdSIeva*P)YLUOKD1T*f}t>ck!mU3|X*)UO6 z@p1H9Y$6sV$TTD3DC~y^JZtp>@ti&Z(3U@jw&f2_`UhxjryjZ^=KSrx1>E<%u8?HB zIr5?tYW1OlIPH205f16`^zJH9N~C7np5P)F#8&0jdwbGzzHU9o}Qa`DDp`TNI#_^VcN>5o`aN95jknNfyay1YKgzBD7 zrNkb*_sKp9KX>gB0zk-o6rK4Zb?o$x8oI3B{3;!A;M3~DbFA}A!XwI7257tR&Ov^w zrqUmzYKXEonD3YX8x}FUsE$2vp4a~bAzs|I$TY)VVmhfZopGxTg43f>-{{HfN;9F) z`L*%r-4^vYeTQ>)2?-4*z2|1>Drp-E?6%Sg(w+z3Tx$eE;f(@`2sdiQ#Jt#R*TaD6 z#O+U5@iXt0?HYSiq*m%1P!56E(CS$=lRb6mI=XwDNLg^9PO>>H*f?v}<^eCsRc^<= zp{~$9X9#gbJU>|qccoCdPF7@XFp?V%Qs5%$JRmaFQn21*5HS)B zpNJwFly0{zfoxjRUQvq2S~5u5;yGj7i7hD-e?-SDvdg(Qg1O25XVy;jpyH9la}oK}UM# z@Hz|li;LK`O z=AGFnB?}3L={!$UjDXcnC}9yIQ>ui9hHy)Hsc!CJ4OpdA*ZYT^O_)BO@J zaw6OAJ@aSkSMa)gaTDBptwwg4*Lz?vVuo84R*-YOwT0j!dT*sq1d(hB(Rog$&=1lA zArs0=V74)YqV+6zdml`hIjPQ@HuOzRaGlSWY#8nFzv}0(E>$v)!i&y{j>;HQP1%+D zYhq>z^OrNSjc`MDY+@DtrLgTD&RUPk5Q1SPExJz z;qK0;XWFi?6$WGJgA_=jd&Avu8{}IkMv%`kAP*i|@V4UYdl@|>B&yX*ad1)1Y<`jl zc#~DjIRM=KF@xka?Tt{t5!;aQ)V=fS)bT&?71Eejw<}@t;|fDZ&O0og<+st4a7$o8 z+-DWN%vzh)uG5t1UE-Msj2h-n$t0PzIIms77^h%9X-s4xtd;m&ipSEh4sAfQ*?6o{ z!?eT{bq0;CE;e6U)Zk+Nz9(!#+y^N+GgfK}Yb#ESIVhsws|Den@TX?#N9iZ&N=As|uRgXHrrC%k6RkbU zScDPHnLMJsiYW`R>NzER)mhK%w=80q*29_l&AZvHqLpBw;z6^I^L~rC=j7jddqU{D zIJ5ZA{sDGnl1sP`fFuN{M;WN^=E)0X^@LP-=KQuJm7*=fQk=?@+9j*qkoivvNyly?}FrAN`t7l~m3EMO@>flxotx{FZ z8nR`P-<*QztAuwjssZ>rDNYuVZ8R z2w^5Zv=E={LM7GTtaK9MU~urLST{+_=a};t*!12g7-ZbBn?uQNH{cdh9uCNB{X{h( z?9^IRz&F)>gstx1lF3EgxmCor;W}B^4xa7I;h7*dk>9KXd0Z#Np)p7%$uqwX58KyD z+<^kEj{b(%p#kAJ54AbYzWU&Azq-1=exT9S0AjLp1X@SqRK$P5v-j7~{9lPErvI)Q z{Qp;a>@V8%zlbP?Z@B2ch^W6VHUFVKCZ#4LC@=I)L}P?Py~gCjx5vztUuXu`U^XYhwc1|LuVPorwA`3nO~E|1SK@^zZfp0=8}hn$+Ju zJl_Ije}SlPsjvS>AnMz~$i#})PT#@U#>&{l>0gn9xv7~G?KdlC>|pL_`JWy~-$GgD zwnqQ5I{JU98vWm;tn8ijt!V9?jUAoLzcsG@(8W{B*lL$ zlT>I`Y1L@eX*FmK9P|w>jh+4(>%ZfFkCxWpo9#0CH{E6S&39S+2jOK;`@cCW(R$E+ zuPc2=v;Tm;{z0(*6Z-mlYX5=0SiX_1zv(aF_5bzF^sUkMH!-vPUAc_k5EvsX^FP~f zIP5#`|CIh7?{BMbr0l!hcbjjKx9|Ahh#A{=2^-6|zW4VLSm{^^*w~o9(>Gp5{}%&f z`)kYejfTz}^A`)B#4{r+|2 ze|`QP2{RMxKaKt(ZGRgx|DDfYqo(hf{N4X&et-A>8ZdpAv44;2pL+i;|C`Um@;$!q zI)A^Ff6Bh|{?6lX*+1zoI`>`wf8lZeSdjhCOX`2(aSU_}-|PNgd*65*BOBv?(Q^MA z9>>J~t;zTI^?jL{TYax>0$LF(eJ5ifV?$dbV<;XTC`Ts;V|{BVx7CX#L$~~m#_9|w ztF^}H80$6hfyTKSYuED_j+17?3|ws7wdYf9%d3Tsr>DD2-6IZV-%~tC9>;Y@DK1s{ zIPww(hz#~r01}*YZA>)`b+>Tg17$U}aCM9{{h#DQS%8C;DsYbmgOva}255MAXa@SM z&;}|d258^6G;MTD;MAZD?NYGQS!tE&aKfq;`S zFf=taq*dFV1V93>frqY1?!fF$#Mp*JF)^rjwFBi5fGH2huW1QnJm(#Q)UqeL^Bwq% zF6XO%4YcB`{|G$)a{8Pb2Q&J?3a;vx7Jku%{>n?u^|f%z+jlnq~3YLXA#FvT~-uI2?9q>#zEx{mP^d56HH_THf$Wcdry9tix~w^i@)N5Am+zJcYr z!OM?c>G6G7JC|o<01nP&;LkoBK6TYt-U}Q)X;n$nZe8xrl3#%tcRAg>548?oW#Dp4 zpv?(i`nl!M-5<27+okk?pF{2Jex;8pzL9ocjHa5QU3j}MrWl-MUzi6VP{1jxi_4Sa zJ$qGjbVb+rK!?aLg56qwd?8ZB&fx(Q!@feB{Q@Q53H7K+z7VS66nr7nKu&l;%KgUi zfm(+@33DUY{{~;*LGO1!{u$crPb1+Aas1~!)Q^VZZ}9pZSo{q>zXPnl!OM4`@i+Lu z-vw+vekWYy{juwNZjU$lW$}IH^wN1b)4)>)_u&EOQa{-}#=E&pduYC)o;-h@)LNGhHMhB|E`4Y%Y zp3{Y>cld<1@ongxu9bDD z=T`s#F2KU-u}HW=FT%x>34PShUE#T8g!)_}G+rbWthOVLod93bfYo0yqZ~6fOlI7w z#=i;i_;3*1+jm=poS!LV#k4>;NR6o4@td)6joh1d&9zNOJTEvCctCOp8d#^cvK{;= zCT*gW^UcuV_jTa1QOM;ZOK=4$;{EQATYaxa;CA+B6NYP*;o+@wjfmy>C+$kZ^x$=$ z_+-R^baS8{o8Uriert9(9NP(c(*%5`zgN1xd8&w^Gn)D zkr$HFv^88jw2+00+oe~eF%b6od^*b1(igcwtIzfxvs7L^Y55N3HoQ#NR5{?4N5O&{ zx6oL!L9KH42UA|Gz(?ILVVylnLls$T_~$B*SxI+_3hSC$6(^_UqiXA&Up_C6ui?+7 z_p;6jslUTS@1*?RW6YPw9bRlo#mC}WWF)-*Bk$08U}PZlU`r|8KAVw4n&pKb`nw`1 zVudB1N^dUBP`gAf9aNHf@0a159S=?KLbOv8D>KT~Rb%-LZ|!zCICS})b#l>*-_6|T zFjKa8McnGg!5ETIYLbS5C{iV5CgN4JdhS8-JZn%9LFwkCb4BNJH*=axg~^SdQd}s? zskvK*URna<<@dv3(vCZXZO(e5+fuxOb<7jAoYn@T#`-hY{6{St>%tIi)M%3 zg9DMX+GHr-9Ego%jN^0c z;@$06aFaJBWbu(es7+=dw!KM>k(Bz*9f{yz%GK6-$JqK}&iE3E@ek-3^j;YuI?|>T zFtFuL5qvhCVGy@2o1bco>zMGHmfRzVH2UftU+A&Xdl4H$iW)Fpa$M93!thfvo(BB0 zUVcKA$Lz|@ZlWWr&&z!58{r{(ix4Jd42L<;dmn%3%asji{h;;_;~P3ewJ(^Dm`II3 z`px90`uQ@*tt3Hbb-1{|C?Gej!P3p$n9p!~JbJIV*eZoIE|NslQ0U&|-O_08GW*pPTttQ|(0d)B>yE zR${H+PDDi=Me?P~E1vo4Q%oTTtl;wJE}i(r+&!Wz-um&k_q>D^h!M%i$lUG&Xd_B5 zv0}4Q7QT~6?*0cJuwv$*rqbL=Vp-6{E##`+X38MEU%SI?%h5H8FFW`VTbX_OM(p}t zJe^}z^@kwL6@9wz8PeNI1CBwYH;FBl5uIgjZaWOA;=FYYR~AyJy2<;M0_^QAUdK}| zVicvcPAa`enQHz4=4za}L$a1=4|_t0ggBibpgqFRh&$)ke8v@&3Xx<#b7<^f*!NXH z)*$Wt(69Vy!-vk8>wBuFT&C{qXtI~|MNK}T@))(mO_$DeaK|)Pl0)$MqNj^iXKry; zDtIcrJ+a|Yk)*x&aJk7d!_l~3IVuvoHJ&gFG}TlSCtq(9t>bjca!@BB_@~m@K9{M6FsZ8?S}di7s?e6$4rCjyGlk?4{Ik zL+ja-@DTNwzBuxtc5>dOx-^4IKyL0_mj$5Og&z8Rrez0Hh1aJ zj6~}Xs`+!ZfxOl`D~0W=C{hs zvdffvR9ji~`f;G)z3ow4JYZDT5W$H05upa$fDNM;jRK&@Fpc$ZgrIvhE>e+?Xul(v1mAU;NjA=*`tITe@X@3dh{Xcj z?U5D56Ip+&q!o{$G;j!?FyqO%94_D~p`Hsw0ET_cS7ciUCMH02TjtCFT7XkmH;ab&8&j z+0YUkV=`$vNHbOH2ECyU(Ou6Ir&cA+cuq5aKD1GUeT+Q(*x$mb?;^(fGqq%)XR-Re zAoQDoJIi}@^gQtA?X99@M!`K!wGEoGVLn=V_qqXePF$GSf_WZq zY}@K`4f03)gyl$eM*1JjLeKCdOWk@0EP)v{Ten8~uSFuR)#?1It*S>KDzp)Zhz9_6#7hjE#vSvkwLAe_zY z@?MEYVIxZ~g6t4|?dSb>&DGyWozrFGxRd3KQq)zrC*rk19q2>W(kMnQ4&xffLOngh zs_3WCp`{?&b$W0#0Er|eNNR$tcN@0eSOq~#ML6ReMzp+Srt&anK(pwUMAu>GjZYju2B}MxpnzH@|uND5}w_Wft*O;&R74 zlxr3Df@Ky9IkYBQ3Z?;vwdYidCUe;)z?1n?wkm~xzK(e$Xk3^bN90_2pA8Pqk788H z=r(s6llk4Y_l`OJWl?pkEvLC ztH?Moq*&amTTitji6B33DuS&x-(S8epIOJ3=_N{LVkni*ROD@;MLxKJujjwaMG07$ zCFo;#E~7f%KUim;K6TvibXpahqj%gfBDB7PReEZDC33jfRVS=IYv%9&Gh}9MkL|wk z0CowXaxA`tQxQX;4i^#vV1!3&1VPjl#gA5PiF<=fnkko}DAXZR{`*8~H-mX_K*^qJ ztgk!xeUBA(+lgejT@j;`Lcr_QKze{~E|SeA>dpwvCJL)IXrtwxlt!X9v^6(y2FqG4Dv=pN4F0S;Xo_4;WH5Zk_v|f^oyf^N?vUn76@}cqweZf2W zgz4;}g*erpZZ1bq#}YsLQNI4!$eDa~Nzu1n;kJXie2`)2A*H$#5Ze01`MTE3IaGL( zChg4P_DSGzECtDX*!nnNg&+&u&6?@-t-zB^Fj~gTH?>BJ?o2 zyP73WK;Xl9x#zAzIRF0FLlWlJ!lba54p0#n6Z#A2yaDyOhk`v?)HWW{BXFe}h(r;t ze9`%@D+Ee-9-Z^$<>eK4Dw##ML~6371l629&9bxy)Rm+$jIacYnhX`GP9b|jxGfDU=OQi;ruazO3MZPO1jDQ z@juRh{;d(DX1=6|Mm+F$}ADBbHnAKFJg$lYGO;MO#1p zdzSo_EYc&PNEPtnB1`x?-xgJ5Oain>Oi;Jj@h~)B9rfvc7F=rRQl61p5^NIA4!Vd@ z!g63m()a-?qR|KGwxEG*W5hIBLJu<6H(oE>9fWy0b9o@+&L+$saub)m{joWN@)nLx z5(oG?qZ2dusSGf0AU1U@Nnou{y_J>Ty7q$L8CK8e(Ex( zh7>i`2{whjG=+<`cwZn&!B3d&p<*bKk{V^l%RYR*scN40t$c8eFGlR(IusneGeDDY zi@*BH&G_^g9wZwioHG~sTADwYq3P02y&h6kcPzzK3@5Mk5lVyDXmu-_c-68~xnfQ^ zv(mashM6VcgY_UNp0|Tx)X6~9b))QvXe|d0NCZ{NaHM{K;t_V@rML26)+mcI zbkefBvm;r~V&%H!+beQhrfrknJU*2@yqu7{eDxW&)qZTXHOQajq^hd!uX>802dP); za`UMMynq|yT0kfw?$Dd52f0y~Pq_DN4)@j2<3Luh{B!L9I9LaP0F{)|sF|^jz%4^@ z)g6L%Yb$+z+{efgRadc#b=grqfelR^0PHaXiq1Y%7cPU*U~BMaki(cC{cz~cCc&jr4lD-0SxKBb1UB@nD!@UVydXRkZ(GKI)SB34*q z7`TM+{Eo23+e=J^9ifw39vEltmh~lxX7<^_kP-Dw`v2ftl-UN{{?H!eA*_nwWM~CB zymyRpal*6y9F|J{n9)^Y%P{_Vng{5XFMg}G1?jBZcg98i6m2A8Nx{r+9167agZ)DB zTEv8GN(l2fOcQpX7XS)%*gjuMdj8DgF)gEF_o7-7o>~Wywfj`z8ZoK>@1@L(PjZlv zfiHv46BPA9JX-u0*%_!m=-uw%F89 zU=Wy~E#?BVM0ioSUH!-qRwLwY2FGH)K4E35lKkv)n+i29*D~&5&l7FEVNp$di9woPwTb!k8r}wGD$BKUSVY6C;)-&ip z=eZG?%YI0yRE6pLh1NPnJxvtXSi@t%ewNJio$7&fIe*P*S+pl_<7v6w)o4*UYft6@ z{h$EDgV7rngtXC%o1RlUMw)puR=U>jFc&7)Q_4?snVt#&#(5t_*XD7&q)Jc^9)-%j2Ev;trlK0d4B?Z2s@xC2i6kZnod~(UTUN2t8bL!^`iGKe1yXU$=!ey10 zArwO)%gLOtUv&kN6th5Cr}TMWc7;-7j%EacKyr&)p(klXFRmq%&3x1sJ)NC!ZdF#g zum@tW2T-di%H8orRD_r4Al|}@%dB%c4W-V6^@vB3?oF1DTAi2=Vc|ztpCc$W44LQ+ z6FXdIC7g=y{(-eP)TGYiUtyle+KNj@wjeya$AzUYi`tIpU{{cx{MIqq;-w^#4kr+aR1G4I4s=TKMoyhR0>MH!E! z;P@^{-Tlh6aL6NEb0inRkQt+?`Z4QoxLa;6+!hepw=K7fBmE=fWPpvWg%r@PdZYS) zdNWi{6nI#%oVXC9lv~w#H&PU;KSHC&=7VN4Y*~E3t_+b4Ttg9 zG9+Wv_Q}jbr=(Lsv4W}BCgK3z3wSJ;Wl0-+=zdJ zQOD>=jVWIqjBs=;bfVwV*?UZJW*QqHZ_T!6CnC`Ghd&oTmJ4oE(H694?*VGs{20!TxJ|j6N>|HmoV@btV!6aP0)0GZPJJTWX z?Uh=CR6Tg{>PEka8|Q>fh%XOsOM8_L7)hPQ9G?*FwyU%zw+96cmx!C5_v58l1v!BO zozyEMYGF7S)0?80SYe)nX1cCA|1i-2Flpgfo76ddW0E0!rVU$}4U`UKj^d_2WbeQe z69D_#8M*-=R9^o`LT(E!)25fW;XVTIW^-ByytKrD3G*bsU~Pepr|EP}u@rsB!tTLL<)~Y> zoixW@wubRCn{P1(lNmur@@LVcDAdKIoH2PgpLqNMy8@_a0-2i_mlakfMqW2i@6V6W zrjj1mQyoSVh-($gTW_}DqnAPG_W>K7-)hMAfj-u07BN1(b#XSF@xr5-%Hg;C{!Z}l z*tSs3dyf>;;%P|I(b8A}Zb}W4@uUp4eJ#w%I6v?wNWxjs0}gtTWJeV(!m?5lVhK*f zrdzNcHaf$1!*g5_(BLvk;9tXE|8OZ!@+in5?_NsPk)wd7N$tbPqA^?L=qB|@w8-u% zN%JWBD8IF=kX^3Bn3S>@Rvd%0ew_(H5!+Ac`~stC-1h-o%Q#9SALSB9ir)Q}S+^OT z6EjX(Eb256eTO-8rF*SIvh>(sOhnA%l9!-;5Rdn;?|sY*u|D6;b`yXA!|=F}P4Hfi z!w5DZDn7}ikyTtBt48CRaNi|$&>PcQgn9!VUulL9hHtmNel?p<(LfjV%(~K(6;+WjB(t5orB5(t)LakEf;OP7$d&k zDN4%XSXW$8B!n@v)YB&P<)Ja-G`ea0XW_`$6cg>e;QH_N0N2yQkGr;BQ9^h;L`VOw zT7&tcd3gF0l~2T2Wk1tx`_tCalWt>59Cjtl-<4Y`;~9i$7q&Vp*9TCEHuW6wFH><| zw#n2@1ZX1%G`Iw&YRa=0GR)@7qb5ckWU>*pK$*72i_F26i0dL-$;dv2j;{UDp;pm@ z`2cVchGrAX3~eS$S?~`ySENX+FS+~+^zaI+)R_(DF}U}rZVVQ6RqBmZD&mZBU70@& zi`NZ#hVV{<%U=8j_A=%F9BwG&O`WeFXb5n6e=am^fwt=YPOiiAbHe!`o|a|y-opUY za1__n)Y^WGpM8i+k}dCI#>rNtXsXSi{K(wMc()SWuk$n#sR^-xfuN!m{SB-Dc<)0e zn>_tMCY}p@hRi)>T8{&`-n~G$4s@bb{GoG1`$T;D9N?Qa$;hm?q_w#Zq}BPom{^L zWM#x#Zk*EiYR7lqzCq@2iPwJK=Zi;hepqL+GzGiMr7o&$aF@Iw97fp&#NYQDYgVVH zI$4_#b#$`s2PiJFFHn#OcZnz7xWC44t2rLm>|;Bo z)V|1k9ml=fFM=!8>FR{p`(-plywF&ZKQN;5QyD%Lxi~0HJ*48vDzRNANAVD@%ZVRG%6Wz?d z&37`?h#(y`VzBR@6H=HqGjrtKSECeRke=wau*MK?Np33w<}K<%C5?#tlGO0k^=P6bHOaP|$3I+~6A^lAEJo8rjV|>iXFFe%dvFZ}$Q+LKMV9`D}A?K8aCjlj!f>uUi3 zVm!D!)Vv?v@l$UBH8|N!kni}-Jf2xs!g%b}_Xa!TPZJ}#-F$1UoMX0pSw@=O+U&Rz zoyZ8`GXFdMRF~GppF{(~mWQ`%2GSF4Rvr(TP8kaelJhx`j6Y|W7w>n)bvv)5G@k4; z^mQ(XkD>2r9S!Y*b<(`(EkM>wxb8?Ns)uW(*}Z7ZwYm8?6AF3ZeIcfj`Igdc!;C1Y zk~U$K2tc$+~?)9+4el&!r@a@Z)TS77Sot8+uzlY!_w~=O^ z6_%Kx_qhgTLP3`)j5JK}E=G9~y>1s^!cHCwz#{Nh#quu9x}eqQPi~PF^&N?XWL9MJ zXBuCtxaSDt6KjYhZc9wJt*V!6;K$r`W(9M)Clz>GC1YSng6N=rA#;Zzh%2mc7dmF| zYepRML^GwxMZ$$yKbN?;AlWy|^4-zqBkQTTPj-8tSu=%RitT&=AXh(A2z=2dj}Ogu zFC`yZ`+2RxVG_jno#8Oc^g z2xYwYD3MKOGD;ybQufYHgQBw15|WvnLTDh_BU`ePtPm+=^uN#hO}$6I@%_F2eLh~# z^FGgg&OPg%d+xc1tjMaM{T-g>tA>x#BOEYZs=d zr}VMVG*j@y!U^LT0WPhRK1KA7FGdr^%$8f5)!tW}&n?_TQxNk;F+N7-?CeJ6!Ip zN6}-0(^~dEi&EX7hk?r|kwXVvI?W|YaLq%<$EZv^+ zKO*~};}xS(lHd68`BWVSr}>kvBh0y?nlp@^KI%E|<@DLUR;ns5p36P{f;Y(fw0qdg zvX&pQ`bS?TZF7kpkN4S6XUbp2+o7#F|H0?R7U{6kh6H705l*j%2?mEb{WvO~*2l1i z(qwBj%)}Xl_2bW4qX!jaBg8fKM!42KpM$Mh_!XhVBI^_{RmF)7@7B+XP5a81kbO6H zgudJ4XG}*{^Mx&CV(xcRrz(CwkG0YpJ9RVNu*UJ)iNii4nw1{S>5V0&*UfCVl<(?v z{8DuA%iA5#C5)bB>)&Sm-Tm?HC|$8%AU3{jSFhr6c|Yqr3gztl<+Gl?MU#hB#pMSg zN|Z6u$X3=^ohoUC2hG?vZ&?|c!y=D`x*lqM=b0H2Z5_iC_^GTa|)I%JHYwEch^_jT%cdkt;EEk?}dz$rIX}xv>=q zPljCkbe{JcYgDhEtdFwfdG$(VIwEQU9$)mr??U&MA7^D{7glQ)l}a*7fRi!Fki5jd z>8on}GmW;4h*B8)SMzX1DQV50UH9qA-`cz51CVw3qZg|V?s%1}wQ;yyZcN{0;Tz>mC3FFulS z|G0v(NXNy4o2>N{V(gFa&SNbZU{qb$Bzn+vw#Q~QIVOI3uF)dLd(W8Bu+it}TTc$i z`W)@<@0}IhC!R+e9aP_+Y!=Y@5O?YMr{rLhSO?nI+`EO~5e84WMR)8HQrIcA>(l7g zm+x{#3a!IJ74JAVd5*l3k7_pcI~H!P%&ifZkk823sz_JQ&YQ^ebwJ)VzT(W3X70{Y z^q+egFYJzGsXrB+%)z#dH_m_l4SmC~IN8d}=2A9?>Zo9K20?ZrghoI>&4=~FN3y!XSezL68%Zthne;DKV{`!rti7f^89p5&9%rJq1ZZOA2>6t zsF(eC(`8?aj77|YP(CHz97FA^;x$H>YMq^{hqZ$O#w~hn>SYtKzKQDBIG)mu+1)T~ zNtcVBiW=G9R{QPRZN&qD`!aKed@?K%uS;h)djF(TGvCzVrWP-;diuU^|3!7?eV6=Z zyK>!&7B0JAF%3JXlr|b8PKmTvO>})lO}@q6#5c5`jhJ$-IX((alXX56XwEgt z$>j3k`cRGY3sL!?j$gFSMH`gupXPP#>2-5!bg|yraY;;x>*%i0b>wZhfQ$VhpQ{Mh0X>z-)WwD+h4Si-f~l0 zmFek&Jc0``XVq1j9An?3O3&ykSsTz@!z_O|;tykaF|YpA!S4O9xe9^sGhq!<<(TBs z^AcVM=2aA)$2h9h$7}lPbR%l#1;2e~42Ij|xLt~`c!smm*JCfed%5qbSM+ALC0L3* z?**ar4tw2iH#T|SygmErSRcNf4`;jlVK4zd^&4$rcqQnaM^&utPb<@3u>~*n5^qg> zZyy+97CJy{_%y7b!dKd!PB5Cm#sZ~d^X^}rBI zcBf#Gpn;X4npUjDc+s|&cyES^>;rdiH@t5MaiRVm-^M=Ni%emU55bQN${xP5QWBXHmV6c=KfPJUn=MLiF8uJVfLm9P zN9&{6wIh!_H?tZ_uF>fja@kYL%VTH}7^NxA-u=fkwWJfO?P<5(2)W+;dnnGn1%7kyg&r0cZt3u=OegNedJD1m6*1~* z7uhk**zA3|f*7bSJ2yL}k@ZeEitUDe`Xvz)=69LTXX~A7LcXPYetmFe=E#@e$6=qg zyk)q!>-WydJMBzgbmlFELV0bCDq5pNlyB1WF$VL8!Wb0=zV(U(?J|;O7w7ou?v?H6 zK!;-9c7!u?;{eLVBBVNedoo+@fw(al%Y`CTMv(OTB(9z;x2AcQ>~zm#ekNYZVN>U{ z?ww7WYfsi>6KTFRDgU~~-fhF;flYOp!#TLOa##KPl@{DBngl0yXS?<97$|R9oO6Vu zUtPkT(@XdXW4;hS`SHna;q=<6&o6$D#?d`F!|O6BHyQJ2p{pzS);q5a3Gt;TnUDGJ zbp+EKD^9o#>S@*G*EgGJ)6#8$vqwr!xL=RHcrHkCi|ALw_-fjDmh|zcV@j8gF1ZYs zc%;|{*2g@Nef9Q(%N?_$3NT+bpM|9IFU>(S%OWQkKGKCoRj!_T`OCTBFgkScP>xQ6 zLdcJ{&56%-1oEVH^L%+^eu+5_-@P0-Il7x}3X4V-0`XfpgL%QR3 zjLp~!Z*lkD(PZ$cv+nX4`Y;3V5oEsWyoKY9pP3$$@S(@p`3)%;)7l8lloE?n!%Stb zSjSEWmzHSbMtgN}4gFTO?9~x78Tqe#pWc##9>r@v#hk4l8>7MEglbfMD zN*z0XhVQzN=HN@4tNB7rDAGqc&Sa;mem}D~oBm~w&Y=4?!|2O{79+N-Zx&f>+~HSK zU3(ox1Qe6cz?%|yzU#k}`f>Lm7QM_CzcYB)y>ze6b2awbE={Y~Qs+KY$ET{Gg`fMY zj{OL%hs~{AzohxY?^R>yiRi*-_~{hw-#e}gWYyI^H=t*{JQTTYziHE3RFJrze>R=R zY-3G4`b^d0GK-Z~XzHU@)Hu8U(-@Y*8%=uq4~tfw|7H36#g4w%F9jnfO!aay%V7T6 z^$7OG53Lz@5;8EyuG=LqMKlTto~ko)epYxQd~0Rzv}lX)To|WAqU+YoVZRB3Ebp@^ zRa=f9QaZRg`*AF_Bh{-VYf$?Hdtv`cG@JJq$(Kheh71y9r7CgzC#5{X>TY0nuegix zKJKkPzjr(Tt1EABhs7^lZvFU1?CO{uSHqOOq4s!bKS`L?O*U$wU+49!~=2AOT_MP`?_h1M$7CCbGwbf-o$pcM{y^&Xg zr}YE7r8hm!gQ@S0I4vrg;Ox|h!=vJ(!D{VNcF9i{_NchnxZGk`{<3(b=jH=meaB6u zM(UE+@2l)=?!CBhr9IPKXNy6e%6+ph5JEniT{ z@40;GbqY6&fdACXJ3UjhC+UTx98k8ZSEEYmWS%p}huswU=I-}i4DYU^5Up)Jp47E3RK|lx)RwK> zhVRg5THCDOPysUvrBOX-+$T)K)B3PVq(4B|f-ydKTlReLDbL0GtwEj**lwM3IlL`m z6Ut@`$GL~q+aK|DZVc!dQ%%3u^wjG>mcz@_9O=bAIg5O6m<&fzXO@++?YeF>ZK?CL zweVjFPd7p7AX>90s(!*#S-uPH!`J6)r+;DV@DnvU{C)JS1iPc%R);n!mj!hvx>>g0Uayr)TaPeOAT3?^T%L zMo4wp=3M65(-`+_%Zs1kWqk!4zi!PQOO0nlml^fVUyXErpM0u%B(Iw@x_)*~%b4)u zXlvBRS9`xQpR#RHzIZ9_6Ekay-$aG%Ub%xtAs3h$OeX}c$rkL2=Gm`s?S5n;OeLgX zx2p72PI~F2Dala8r(0fj;$B5HH|(sX)n6M+vpOAkl7O?$=1f-G9UZp6_JMHBGoARI zOIP>O?%rpko^qg2DTptO`#~|b+@mhvuyVe@m$ z#$BooR*|WC&6j?L%{p3VNXx$nX^yQ8iMnmi{UMD`O?P?d^T#-zV%1Dr%jZF7($%${ zbH6kVI7#`WhMP%t{cL+|f2l01cf?lna-YYht`fVwo(9RaTK$<}*En;3W;tH{`S|;5 zp6$n$9?|N(=zmVjsy*}SVC<^yvpwnJAvNDIH@I#;_T~8bHffHpl=oG5y5xx;<#S9I zl^0(rT0DC3J~b-Bk=BLpwM?Stu_gE=7$bC2d%(lClA3g&Ib*^E4Lwhndu^o_&Z zn;v{+nCw+-cJ{OLSCjdu3h|pMKl0d+}jt(p;;{!DPd&MM{lLN5wZ46r}a- z?~7Vu`|R&pu++UA#B|||+zTFloPV?WU3u$e1k28^Zc9$`Lvg&#SD!u<3wjP8mtor~ ze%k42W!Q%h$p(hx-hQ`tS;AaP!WQ1VIri@h4?Bk_c;|`ioxH)QcXG<+8Pl(X^bX-& zpR@R_SsPhTwDz@#9_&;M-07jT!3p`Ay)j`l_ZjV5#ygjsj%wprb>rw555amil-6r-jtrI_n9ntTtgC`_goSRyVnBJ1-8qJfgHMO=zdD!kaT~WEQ$tq19(HSU zOGe_B+~k2>);Y%PBiXdtC|7mE%rarWnuN2j70a1eyzKayh0?Ck1v2<{p58`_4|{dg zL*)7WQ%?sUSe`t!0;`NG&Q7CA-txUQ^41&s)^H6?}*$-YbHn5>QoJVxOcCTpN~>vey64~X z#K-)6-w8BL2nj9f)H*zU!j_=K(YT#^<^K56)*tS*n?5tRiiSpwzupqi6Fzwq86)|~ z|I#B)96oA-?@L=+bTBx%<^(NUXh@)zc{|guvADr`C7xTmS5nr`W(X%NrmDQ zPKDR+{TMMVa-gY8JTvG2IfO~@MpJ&8@TrHwNic!bL+HL9AKO!A8784>yHkVNHiz)I ze~XOsD3dR*xp&R7t2@-kL}l`mUrtxD?3o`d5|$lX3v&Xl2N}5XE+1)(Vtrbob!8#{ zwcy4RH>(2kd$ObE+sE_O)$I_E)Gk&2G!bZXV_{^Kdim^&|FIn{8uU2lYvQ%CekMEn zn~F+5+!4q*n(|09`lf5QUXgrbr)wft>ia3jZQUlxH|sY~RvDc~+4yZuOPLAZtWf8X za?>?smpI&LL$KxreM{ut!Q*qG!pcu%balFovAPpp2Io#l#0qYuNsbia&DCRwZw$G4 zxi5aI#{S_r?Ujwq%?~hM3}yig$#13R6a9^rG4ZK}f!^a?d6??X;BcG>n-F~IBO`tp z={R@qL=f8)i|oi91DEYNeoteW76YxZuJm6`m-2(n z%WaN^q-o1nUm9od&ur??k%3)Ldunp~W8q*+GoNE?vt{VL-rKwG{^s{T{rfk~svJBp zUGhy=cY9f5S2yj?-y4=CKJ-#AV+RXT|Ko!_q1C@&X}XH7i>sUBS#uY#z?*CtJAz~x zJ9M5TD63%ZY6Yz<7mz-tqOPV6Eo0aF*D7`-icp?p6*~d4zU21*a;_&?eg9mB zq5InDqx2`ySU6bX4VGbpKO7vg(f`eVDE!}22rNPX36`Bhe?&L|g1`tsR|xXI{e#M{ z|E=T40<*;6!7;C3sXG=0mXBjF0vKqQ0}L<|@C*s|K0rgqz+%9{cQ{zejtAuc91E7U zLuH{W7D42ZfCG94{@^eec)0chjfYOT{maxk;gC>JKzi#}1RhT)1^p%v3Vx&ESi(Id zJVH6ZFm#3BM6qB9*L4^~1oRC0gK(3qdH?5;urM^(17dy6I|@bE$im9O#_cTml6N%N z`+>0H{eQFMJ<3)l+OMZdWY1HZe(k5h_wpQTB5PP9>~7eHMZCXj9_H7t*P<5vP{RD| z*Ah!^7x84lXi2LkJ=Q(WIwnniCWks#W-pi?iXV{y2RRSnR;#Ax7x}Bi#jS0#5~gpu zD=Or1m2Onpk+_BHzFAP(CKhE_R8o>46J6Eg+`Fz$GI|VwXU{2Y@cW$+$jTL%W-EUF ztav(1edE>R@uzo}lp#yH`g(iehqN`?ifa zTq_rnp<%{-U|!sR^KH@Z*3Ccq{7-B+!Odg*5P4{2L?&QZVo+@Rs!MK@nMnZ0Z;R@F z&6m4(?b{Z3k-hBnw&&r$R+s9=_>EP#Hh1j4@<{6P6P^uKg9BxnZ4C*L`&j5{bh$h& zSpv5w^3aM~m4BX05HRl?8?#TwV-!`M1>E|~HguYhWv^`Mb_gKLL|A zN%vKMU)496e!WAXy>c1ceRWi0FJHN;FZjA&mvO^jz+gaQ_nQs8Y)=w0w~L9T2hnJ; z8yq%KMlQeZ>^`mgYE>=DHEB5SuHj6aX`wpj^pPb+KwCFhJD5uh< z`7JA~{J|$)2KrzB`7#RblFKqs9M0ad=j?BhIvKA%RbNq$D_L1HKRONCg*by#;&-<0 zy6)pDCubs_8;$q85MiztmcqcH+kbm^YKjAMgF=t++s-56p(Ykh-$eR!)$h_<>Xc|; z(OkTPx8HR6dRuH->WX*G37L@}zsPXu`=yP0r^eC0A|Ah}3_60o>!U2)DiUfnaXRTV z+sG?cc@1mMCA(c-cV`AmU%M)OE)<$<&+P6F>)gxHK|8eBEhEmM=G3WH`O(TkKW@R9)o-L zFYgfHV~pj7m$QBrYHKMy&C79p9x*jJXNDRq@0PuIKdzV$yT@-n8a_U>6p2mBnMU7l zaZ*&;i-J$G-tx$f*H@K<0(9puS3X9X6w=uaYtS=x;UKv5xPm z$|g%(pH}Z3<%r&RC5E5<$-=Ma!i%P#AMhE)1adz%E#mr;A4MzO819P@+-%UCmG+XJ zQ#V%na}85eajw?2276wOwoCan`Ij$R&(0&>GTYxY<&L_szML#-5$jlP7q6uaJ(a-o-d#2OSes7hB}2urD!Yqc{QOXiM=G!L{>4`Z5puI%DwxWTO<_bc`WfiNzBs~VJ-Jf+4k>I~7tls}^vrJAN_WY}dLiFWs)=iy8dt zvt2{?_;97_4L^x{MQQvD_oKhPHoV{yF?l5H!FccVnZ(7(j>Y4G!e7R6YHd*VL42Oxx)gk>XyP-6%-$a_w;EyD zKh#u8-EM99678Y#>fpQUsQWL(#o1LcwRISbZfrKk#dJHHd_jyTqqT&~_ubOX+wmS% z<63FaiSMEo0^0O5J@;RbH|Fyzm%aj%*!{rMxx|X;M4x5$8 zvdd>8aHbBG<5_N#40RKZh98%bj+|nMvgo7rFdxx7e4ax#qG-c|Xh%*v2LI35x%GIi zxNS1pOHXPnXMRQawJaS`2x~7gMt`Xv>3Ak|NrKzf?nl*b&d?)suAgz^(Iv%8`Ny*7 zBx&#YM;qzQr#;G_*%yRp*ski$jE@r|ZR@S}RAwDG5 zNOkGZ>fL#9X}+GpvObBWucI6smLCvNaJ}$FkC2lr_@WC(<~n*k`4xmzoQHYsC(cKh zE((rt?3$F@?o&{UD(kpdf9{!5$BwqFq6irWcz-QzsU*5@yk9bzOc+b99g1Ohr_l-{sj9L6y+tIw2yUqelb7(U{haF2JU-gcf*054{wEz9DMR(!+|Z+R{RNj z-enpUgviER%@(SDR`>HPt455^gkEaF_OO@;cQrdiQCiBxDVwY#UPujLv)rw7L2P)X z+PoTC&0}wpzUwYUh#BPvFl3b7d$EGgT;WW-&a4?RE2S4x$>09fT-xqSFSgL6c2+&B zY)_`?Dh!&F~ zAGwB>A6=SMdhX?Vf7b5ukL@=;*nNGNQ+9H&!Ogf*tryP|X0O1sTiElvh9Ba0i~s4n zyg`SfHLv!nk@ zB{(13PS<9Q6-_l!sa_|a`2taq&x;y4-!y$A)9qznKiIGjX1DLSWrfW|-dKi>!0n9j zzU23e_Mxj`H4l0}9P>wan3Z_Ijv0&vJJ7I~G&$lKZcA#4WHg7&9G2_lHU5si8`3Cv z{gQ*V96!$Jf~1D$!5eI~v6p}R^nGQwIGc2P$=h$fQ~koxg)5?wM`W(bdvD|sU=IvN z9F(}58G80EzwPza#PK)YQQEETsqGPTR-(Z*=RRrLdf(#npNMz7&9WmdF3)L5v+hyx zw$K5A)+{acYvxbe%!8}zw3$~uaQIgmMn4ry1CYV}pSKLsDh@aU%@ohXRXnd>+V6)+ zpWa+xnmXU_Npnd?Z2@b0eV#t}neCBL{)O#4qov9v=guA$2~D!qkHg73iz`m|HVT|H zyqwKp=PR3@5xel@;`Gk+x5+3Y+DrUqD(PH(=X25G%X^S_d?Y;ePa@kMCu3O>y-&Dk zbvO6S-(x%0Y&g4wmGO5!ojhl%uzKz5^46!jo$*^0!uU3?@Wty?8dq_4M~SC$#%Xze zE4g|M_cS(J-qv()|NR|Tt65;uo56I4V9olYM;wl7FZ{wV)6LVBiK*_-Q(^vUv0 zj|q%ryqa3px6Kc$wNHXQEZdg+?*}oVGm6BwGpmO;W(;Y`w)mu#eBUnkYwI=cJ64{> z#*X+FX2#D>vAm0iO|S5lWTqCn_E>U$yXLor?HAXXo1Y%fsHNO!dn)nmrRR5@%tW#6 zA13VR#yf6J$mp4_8z>pZ{0cmLRz zaImXYPH0tDzSld4)(bssTUxF}8^AU! z%)K|z8$^bdifCQ&bjU2Z)6MUUmDzvjaS}$x%rvvMkH1NiF2Yf&*Ii~ZTr{sntezdQ zlztf}Rvyz_?a{(Brztj&cJz_TCY$ub3s$$%-rWDrKK9stYm{c1;ey6=(beX?qW62H zrFJkRp`NRzoU?v6BN;g%m8b)3edJlcKp(lyyZqpZ!*39#LXmW~tMse*UD4v9Fp*o#;0tJ~ke zRKJ=__kD8Xp^Ps|+~fQ0e5G&4($n9B+vz92<_^zt{IU@vE_l~(Zlqv)(VoJ_@9cxA zETT8!_B$1q^6`vo&wq5b2}eF28uy){7hx?JiCUOqjH|h5f}k z%vv|>XFSK#%{+WkD7w8ZCHIQ)?MSKpr%Ft%w?EorLtB-rW96B1?eyeQsK*Betv9vW zie)q5zK!SGM|7w>?0ygmNj zo5E^cU4|PP!lKU~raYKDHNDMib4t{qm>1b@Bkl#tyfXt=Usk04`1XGJ@+MktK{JbX z&C*kEzM5a&_WG%$RljlC+-}8B799i1kGpFf-$m@4IkRJ1@Xc@--GKg;?ZvrVUVW%;F z3g2d|mm_jcEdZ6$>t}lCJWYP^n^&0ux%@{~PRCXJR^GHxT;plAbSQ%<$nZaY|0@vp~i@i~aANrY=?Bc41 zQ%&;)T@7{-W#o4 ziU1pCcO2?#suwnHDI8FIZ`%}IRI7aL^iy%atG)8t($+PYCLzq4fleD`h%FkW*yijabQ95{$ZzV?Q&afwgk+bse zgZB;~H475tl1i_!xyE$u=xOVF=al1gi*33NBXdP@9?QKeuKfs8xOK>(&di;D8t^?F z`xTZp>2%JmJe2D&^nm5ghUpQ_OYeVo*$f$G_7A*#@Fe`m9AMW zZ1Od!=;!AsJ*^4HTXI-`JEw_DLY<=dCUuUIQmjJTjDxdPK25xMyL~>nmHC1e7v@MaGk=ef-QrmjLp4#q zsK)~Z7I;sdd26S$L7lu`zTBB&9QZw0G54EsRR?uAA;M`F-vnco$(diA?OPP0{xK)< z|6^-iD5?K?sKj$RSU@zd~YF5xTxF8=3a;?zYYy0XV3H$281n|%%swlh( zcxY#C<0=4lA%&)6j#;@0h=Gl5wWW2z=CuZ3<685zeQ9l^p4iu>|#N*jl;@oP>i30q_%O86pT=!7jCgE2tj2B0v(Ka0N+xa5Vv& zvkW7S=V~4mP$FAe< zW(VfvfF%;Ai5?2IAYBetsCiI<03x#gUS}{Hw}stXGf*w!7agpNF+dzANcKJ zF?>i@?SjZlXv?WJ-8Wfg46>4Mg1Q zG9-Ema=M9rfL?kHHL)fa4y?SIJxOxKZ+y~e~}vI&nVG5^sWm{|NTRYz=e z>ol)%K!TWBjd+3&fTTfi_Wy-R;7N73Mm-5yY7G*b41^Z9_Oau*(a}K8A z3G4z)wT?j&M`C=0*C^`yqe3u`Oe$!y`mm%LT(g_M zY!IGOp#7siEV=&3(XO#bkj@%UBxtGCN9?>HIb+G&;5u3YrZs9wFi~ra*eO7mz%K2i zd?P{7LHrGQ8bWjctc2Jq*4^2fr&}vX5c_&#B6>PW6p7TqmhhA<9?YVzX_?qb{qaoe z^%2}0I9dQI^_LH@S34D^Kl%eR@uYmLy-c(hLTo{bi2xv18Q3g-jV3g?%E&R1s*FGn z8Cq(U5qlL#(BPASe-TI!Ej5AEDkJvq5GEA4%E*KU_RS~MLO@FpJy0J}VT4Ex{30l9 zjrR3sf+P_$0R_2mz$XxE!uew!L?^mlH<1fUg%O@oVEUu5wG%DYT|K$sAxPO+w{9XE z>l_l z9byDZB4@(DgPcHOpa`Kwkn4CIEfEvZ2>&(=!c%fggixJ8AmKa-aQ7#eS~Fn+uY^b* zJS5;fhLfTw&zqOlr;Rsw7HzE&3u#dELSO!4*}YB*GEnegch&@U(0w9 zWJvxhFdA?m(tm{*vY$W32wo(A7qkuddh4OC7c>+&(Uw4RP}A1l){Vl6|AQKwIC(0A zv_m0gM2KAjSvm?y2>jOj9gsBz6(QFGFw#B+YI*CWi0L^+b2oE4M;j>Y0C~ELE(M2Kh?B-@gr>62qP)A?Sw|N!acO-hIRdW7+%3)l{{-$7 z!2wSott_T#4iF1?+Pa+;IC}vcX$I&NZ~`Zb0cnVXL5ZWK`xz@2F=G8|)k$kuUGQ{t zv2+y!Ia>lAK#~$TKT1FhoRSBFfv<337#J3gg~3Qk^8%>pp~NYi9=84ue3gtwgE-b& z;4cg`4(J~l3^;iz7-$MqFyJ()U_j>tn8R8fAZ-pcKvEbS0}_Di_}0sT0#FktEeG9$ z1I5T;a5Pv>Ne%-Q;GuCk^iSX~J~-5uQ^Fu$MFsJ`5C*lfu9~8VU#~VbCa;3x=?ID0mD%(6h-+il${}mfrSH<{GwneD7i#h z4&Z}9p))BA27|+(UXv0A^@n6I6buc;52P?S2E_doIs*9M)HVrH%oMc1P)H25KY-(* z{*tr~fDZwUp($Zh_Kd<3vf`xW0DU+pf+U3jd`KvsqJ%+-7%~{JdP+Y8@L?%o03V7< z_5cPYCCKpshf87O03Tt_jI10C4lTkUe;2@@Oc+@?G#VH*ISk+fP;wZc57a^pgVI)% z_$YM*-b6v86|!|KBl2~K|`g8}+*|BxS!vh4#S#X-XZQd$5$ z1ZA5B`0&7skd=dAQ0j#AUC84=Np4aYzz4i6IShK2+8;oNK2ns!fQ3L5bwK#2c|*Xc zWq<%DUQ*!0B0-l;4g>grw8&wgJAzaD12Dx%DFZA9hN6IhE(#B&8%SjUb#K%<2hN?+ z{=nKMN;?4fa8P!P0w0pn4nQ49Xx@OV9KeU6kSV~2g_2HW<$&a=Yz@Gu^aiXCngAqy z7vRHC$`sIo{uhkOuK|3Nb^!39p-ekz9RMGO+W!GFrIZVp*{1AQ0X`Ho3qpYpOJ%z- z1eVG_gD`^9oq znFq3RNGy)34@D#Jlr|3VVX5Q{b$Jx^g3yP$UxgvjRQ)Ov#K@GiAV3F92}5FVRPhU_ z7aDny@&Q65!n8023_4tvvK$C9sbE+rbx-jwo{~N&Y@+G|U?4!Ck^u%u?GG@3K*~BW z80y#u15U4{Du<`GD=eH+R#3=A<#RyurKSaof$|gN{9>`tEFA?5Pu=!$K>C#Ba0sec z6pR+Ab%cXfl~UA!174O2Mm4Sg#sZ`EIl$DYd@(p@n2J6;=%^{{z+<5qVRC-)&;iQi zFwlKak9$BoPWdkA7O3J*a5gt(+XA5(@a~j#0JEax15`_8e@GM@D-5dBfvB=`i3%10o8q^aMfmH`M8 zDSZy;%WzbEHv*hdPT7t?mVwIeBEZ<5QqCYpPNg>lf;wgZAsp2>6oe|2^nvh&@C6T< zTtM5RvIFogm5%`F11h&irBq~{fqv@&I4Ctky%rO~nV2u3_7|82UltY5y z7NuOkcpsW9q`(J^h#UrD%zxwxKp;l-E)XEayI=r;rIIO#Fe!aD7~3PLY!U@xQ7V3c z5GZvCA_l6s357vZ<#fS4TgwRG60T^GDZTuK9#@11Jj`77Yjl-O5X4w%}NPFgS{ds zc|(Jg2Q_^t=!-rwyFw!{lw&m*8uUGs`bDE~R60Tj1e2FkqmR0ggHz0^KT=y`XVuD*FQ?L@N5g zSez;@1}Sc;@d5@#-A7?ST8dIf7%Y-1#>Aj-RD6KuLFHdS4@%`*dO5|1#)~?>i7i<1W4J(V}UX$@PVKSPE8*c`sSUSW;_U=DcdR@ z1PGLN07d~+eJvg&&M0{Uqdcm<5s#AHgwb zkk$H2i<^tNt(}z%y^IXK^f6m+E5Zbvv>y0o225=NT|(bmt2qeB1x0QlQMI{*Lx literal 0 HcmV?d00001 diff --git a/doc/ikev2/[IKEAnalysis] - Key Exchange in IPSec - Analysis of IKE.pdf b/doc/ikev2/[IKEAnalysis] - Key Exchange in IPSec - Analysis of IKE.pdf new file mode 100644 index 0000000000000000000000000000000000000000..d5d3b43cc8dd2c4af1415099ed0714321094f976 GIT binary patch literal 104081 zcmeEvc|28J-*+KRj!HzPj--qo&MajfGh|kV$~@0gh|Dt~5+Q^_WQfWb8b~No37N~B zBr=qDts`Ah*LB~|{oL>8{pZbRxAtCpO?$21`u@hf4~Md(G@rm>41%M7prsA54JU}? zN7@=#AdVhIB2WtEHpco6=I+KuNC9wp0*Ob1L>8%o6u@H8NF16UsRxT81^BW2L|8-$ zWMTy|;7kcg0RO9lTWA6iWC#l*5ymz~ux;dj`0t#9u?Yf<5DQx7|M5=%k0hNTZ4ld5 zvINjX;%|8vJm$ANK^%I09$Ek`@LL`RkNYhTkNd4(4EFc-uxK21eO)Y`@LPLWK`=$@ zo&!g~|Mnbs0Sy28a(F?)`mqS`^Ao^A!hb*KMS!13Ags?50L!*M4~@qE)*c#%TR$&g zn)%m{Spb6*{H-oV5c}I$umtRHb#XY%Z{x#bes2#?5cqA(ctOG6`XFHVe`}8j2zA}_ zqWJ~!>*o}W<`-B$J~Rd=u%2GPO#QazXguM!`9l)~1b^#;KqRbh55vzdu%0$B{9u9C zjTr+r+xqq}Xi$57ISlSMdd6V+1=g=6hJZz{UpFj<|2G=Pp}_`O*9Sid3Vx+EegVO? zbn4`wZ*FDm05AoCQUhoLFaeK1$=R6LB5`0Tk*WYFRBdgYkZ>VLSIQ2?E+ph2Kq!%u z)H#Yl>*I{khG=~}cu;+Q6G20L10!P-W3(|5Cy3)W5dPOC^Z*7S9G&zXoJc^zkKo{t zIw4I$BLu1EpSY*)W@n5QiGJ7H&RBWCDiZfk?YgQ4d~1O}^MY-8$V2IdUV59k3l<>=&KtZ$9jCL3aS_Uu`c zvuBfQ9z1@4vcwK&3b1K1MT^kfJ5(t6a;rEGuSx1ni;=So-AT;u&Uo#5Y2I5@Lui9 zeJ3tt~mdneaE0WgOe9?=CV^?{J<`kDQ;b&_nOzzGu^! zQ@l~;L}+5!wK+awE6u}8F2%!=Rs!5RIaC;e4VB z!KgRrD0Q(f-o__&Q!7jichhg#5|Gg0&B!U*-cJ>tpCzijJvgt%#0@ew=8>> zyx;x7=<}_Y_xPpWR@CaiQEgJ#i+2>-g153Ss~@Nlsqyc_xjuNiPHs>Y7C&JKovP$91)5vqi(jT0#2h=fQ( z%279Swl+XwSNEBsv5~pHxa~PWnlK9wb~ix~O=9X24z_lGzN2dE1PBilUrVs0K7S5W z*}>LO&DaSvivj`$pj_i~PNY_)!HAGRwm?Z^kc5@JgObJ~i2!}zzL3Tti9fc8G#&|v zeI=KGB&^^BN?H&JtD@L{D0z%WD<+(P%6b zv|wA}D{H_f00ap>G?*s=0l@Bw;5ne=1xqODTZ8>CCnhc?m#S;OGSVMFQCpNR|3Ot^`PurIxvolbIu+C?JabLJ-}TA0V5`WGH`q0fPjjCCs2ySf!&S=L{Gqi6bA}|N5O-~ zzyXN?4<2#laRf;zX(WKlV?aZQ)#t;43>+YHEI%m3F93K1=n;(uWJCnd45Vc+0yN;W z1VPX!7$Fvp0Eo>99H4d#kj*eyJZN2jB+g^OB*GzMF`y!xOfZU{lecC<;oKlrC+I&- z|2qw=F3+DvK?HO2r~K7C5*@5wz!Xj#+*ndJfUTO_m?BYH<~CwBj^;lz5GZkdM`IF> zt!z5QKWsWk&A$Qxl;zj&4G1v*7xo4qA|Sl|BwHe&2Lhlth$)bK;juz9zwQkPL2xer z^SuFNNCE-yE<8XG$Vwo26M)nN=^Y1%3`oJC0Nfh{BnF5{Kzc^v0A&&Zasz1{YynUX z5FY}b;Q7&jRN-C#H$cmH3?6JE&?u0QVS{kSE8WRC~hCD$2Q09AXf?Bo1niQr^Qfb}s%sghR47|gEGPnqb) zjDm$U1v9x`Dgwrs-=QB$wttv2(D{EX77?M003Z!;ZXB36cn}~E19p!F(}spAI7o&& za1Ra3gPj0VXx)M35vvvdDTNhCm40*r%VKe0HNbNs2tcO50er--!aE!h;0aLlfp#x6 z=n(^y8aybBAp&V1^h|&$8Z-j-9Ri-{$2R!$mkRGn#U#b*Tm)3)b z00a>%Fk%A|fu`#}z`eBc54h(O2TBxZ;cwsr$O(VJ2Nc8C!Ux1{S=1@i34r_J0Bl!4 zLcgaT-Q z05t^wkO8AI2DS{w4O2K2_}o|^u7YO($Ogqs(t|=-6`~x#VA8MvqJTp1z=J%P3W7#g zkaDFSsR4+kkdPpl;eq~!2iPPCj1dHqL=9#ce=io4=pS@K+-c zD^~vCdciZ8uJ*c;2geD|;DJ~@S-G`Re6@+ytJN~UHoS7R<{_X6zFOt4CjQkKsR7u- zuZX3nZ>VZ(t#9*FeqFE1{kG@V;T8#`ezk9q#`j}4t=eG0$`b!xpsw**V^wC091>tqPHh88S$rDuQ7y4oaUsV?CP~3S$*nIJ0+-07$&Z1LsL2=4E(jVDOR?{yh@p&Z(-X(<1^^39i zUvB@TOt7@lw)tRPdFc)h>->9li@QR2XN}Sli#y5)Tl>yC)4k1@+jfi{?%yJ5t=y~# zqp1N)RXvxT+3}+XMm57^+)B%jOna1YT`i#%lC!m_+&$Mk5p>n#u19|c^~L%kv6&}d zv`1fk=O=40JvYiSeLhC$Y}zsRVH1JR0rMV78@qWqC6g!&P9IQ@LdqQz;gMv$m_s9( z#j7&;r~=(Q;)5NiO?|#8CnD%P3e9nY-}k_zW!wSUXM_)aS2xhO?IE1IB-GQ5d|-N& zw?LGwNvmjKvtMAbp`(kLQsjBzy&t9;9+F?Q&{Io2ir3?fs{&>g~+R(z=^NcU3hkGd6UVwA@m&#g+PZ9a%W{^< z<-{#`G?y|D+}E-Z?K!r${Rq;q{+kz1^_h@kG)W(nbmDc+SH^0%y^M*ayhbM$Ep*80 z1y^-Qxv8>+fK41td68h4nwv>7H;-`IE2bl7ED)(pyZnm|yVBTBT{eSiXQvP0syO8JwMlZS{HQ&`UzY*Y`}MS#dpIJCGfkkgQ3V5qv##xPwX$RR7EVhvufnROarL1Z-Z-Rg%c5r9jv>}Vb*B?e zXNxwo;M}%K?DA02q)0V)*cv#qmueH1Kk!;;QO(e4*}fBm#(VBne97(i-qa~D-#tcA zVY}%hx@|7&X_DA1uV3?*NOd7cO@GbqM3m1}?Ko4y#a-TM<7K5*6XS=n>rU=S7Y?j1 zx)|&CjPsRPiR?+oCpO~mU&aWL-$#gO&~H<}uEDv>617#WUzRg0KmIw=zW>{mmuc*p zq4zfWwC!}}^>K*2{&cZ)Mo5?IOOUorG{@4R6jOc|<##l0dLbN?%)HchRE85{=lc{M z+&U6r%SqI()z(wIY8T}bh2TF-?qGZ<{0QrYO#7Sf9v(%+UpuXRemP->fUdj8x3Qp} zs->~9eIHM=EVyi*<#jnvts<57Wyt0H2W*w4ryNZ<4R(x?Yf7U&B7}N7VQPED?jxBFbDh&qkp1Sh~II)vG86c`tZbH5O~g?ke0N)-hqNpkSk4`JCyo zyU3#MO}D2XEEfyU>P{FLEH-R#>DUtHV5Sm?k-Pcn#W|(!2a-{ADVqBaeAs){RN5dM z-#T7bhl0B8Q zwqh0Y)?BXnkS)itnr%qNZ7L^=Dm3KVs!q%JBBURgy^|l^dP@8j9icfU;Pbe{8CUcu zW%g%DNq4K*1k{Z@-MkJ7bK_A1YgrFmpL8N(Pd-1}Cx%C#hHFc8V?4=hT*!M{LuDjo z^!u?dh;ohC1 zbPwx|c?XObMs_*9QChMy)KHN7lnmv0elRV=)}WUIt=0|vTRLt-hcy!Ar9 zK8;jq(#KLq6_ny{qmb1RU9~Ke&?=LrvAl1?cC$h zcjCWp9k_Tkg001km~*W1(9OcBSq!KCOUeybY!XE-Zl=E?JZAGyN?9T!_ z2CaQYa}W2VcfH!MAv}-C&iTnUD~iMHK4Y~b1L!Y>UKwMr8^#&7Ts^rDA2%nr>x+NV z%jowT{C0E;_bt2C8a%SwJl45)OVv)fBdR=VfxA2>lgrC5(o>zM?Z3cS7vLRDpJX{Z z&bTLl)rvMyVff6{9#0C->bS<}37&9DrIQhz2jvxY=H^;nRq?nE%4cyO(8|KucLrY? z;XsD-_P;9I*cnLF6KT(7Pi$y?aOKpD-~t zPRDUI@clcF$;B@IZ3VO&HkOE{x2xL^FT^DIZMP+Ov^-I2iuVafVl#|{b%)^Au?k~8#+qS&LtS@=tL->=w7_S!W2 zLC>c>-6z~=oVgfmX*NrRQi+6`cShKB+!sJ)+#zl<`PT1_EA2kYrJ}MmFj&0J{b1Mu zE}IZag7}ir47+g4DcrsT9Tm$}H#4?980j_1H5PgoomTA|SH)EE(PqY>w$XeF+jxpW zE#PLuESvnSMaY1}_UV{oDJF!D_zmP6M6M#bes}7V+|&O{WqY0b6AQFcXu5(f9U`!% z!9zd*n5P6mCiHD!fmTX7fQAiqH&O*)VuL9GXeNl&TK_5~RRon_BdZ6DMM97+fL2NX z-V*5JA(DKdz;OsvS|aeQ5P_cu3k`v2;H`&_MW8E#@H3!p19eFdMmNB52m*Z^dWWDV z9EOb%fn$dVG;9F@SP}#5f?)Otz+8a^dKat!Q`j|Bw@KblXibI(4(jC~#Y3kI^dmtx z5%l^%8v{5%bQ5sqV89q)lmHkQROAr^I3I8_fh~aK7X`ji_;^sWg&}JMV1dK~TLB(e zh}RDRP7Pvpe*V++zt_O(O8#jiaK`?W5A#SPSYH6n!LN$*zjA@fO03$-KuCoHh$kT# z%+@Q zgvEFB}&eOB%Mp^O0$f0aNOf4`8x~w{Vq<}SV#Se5GxPO#?I)HQ$jv#_#<&FZ$ z>0t4fL&%-v5|RZ@p%XuxL94bxU@2Vh7t%$ndWKa0vKIcyNwhjtk{?O`r_)FSWo&H( zy;9=9XY|v5MDiRN{O}z)8oL1JmKHE-8lN+?(zgb-%@s$II&>wGJWxu|%K3|N5}5RX zac7-9<-ZUwvd%gQEs!9fljQq_&;bu32(};sb3O>_B!xGSf-FEJ2fRnJSc38^Dew(| zJP<3fQt_WsQb*7=8^ntMbOA_$hn75GWQ2Zh9Pq#rKtu|WA3BhMNf4ko zbdrEbSP*dpAs#>#L??hoAYKIA1O=c8lVsuq4s{S}3Sb`qAFy>n-v}Pqvq_HvLqQ-g z{ul|#F9LnvFoWd#hXue$pnDq&8o~kWMFT8GgPx)58x2MU;!^>F!w#W^6Tm(e00Z}ymAE|0yy+ms0q#}r~_zdwdP+f{r%aR zX@DL53bp^zM)@~5wH|DL_oV|;`S(36|GqCB5YalY1s3xaUpn;l{n?i;Beu#gP8e93 z0}sYJq~!zj{_i-|oq-qJ0C-aj0X{-63Jg(Ob;ddZhlm*PkNoZw0c89e?7*x)$Z3Cc zKLH`)pWIJC_yIGr8p-#&`w6@s0VfF15gtfvfS3gT#E$;RQvd9Og27#Xu_GLioYwlF z#D2kC7$(0Sa{tDE4_f*EzUcq&i(cym{!h+H&g}okzUV*U&3eRKiS}I^-V0x$`FBC# ze-PLLl$3Rd2^cO2?ZpAj2k?VGil=hN<=2R(D=+|BS&Ik1hV=d-p{|eUbp~>yIFLZC ze+Ztdj%il_rAnk27wDK?5#a1V91@InS>v8I`Qf0}MM(Wb+n+H^rXVud97uvr>pamw z_xcTafEe`03I5+84`lC9oPr|O59x;p6ifop9nl~fh9n)4gh6m0U@+vsBzXna0|%`0 zQ_LVW09?4M4XsUAWdzvB>H%NCfgOQ&)PTqY-O(`U5ysPID0gc1Lq{#z4ua01KUVag@Rx|%6>3^qz)g}8=&qN^H{waSo z53x!hs~K<(eihgLg=YLW+jc$l{LYgB?flnw22eiGfVSYnV1Wn&52$Ehf!afQKp-HZ z!2yGF;jE!yd0;q!DHcfkuspCAtW^A`lvEK^TAg|lO#(`Sb_UP@ASIx9VL(_Hi9Ug% zfdRc>0SRG&i3SE_VZbiI0^<+{NHRD;vshp?fXPr1*NUeZbq4;072n zu=8MHNHEFf0~M4Xn;WF7BY|%XARscp1MUFQIp_h3WN>G|9t6NWcwm6O1ydM@5A!i# z*TC|m24DyxoGkD@9LNNfVN3}a1*`-uO&FjPK(TCva#n)VR_6t=dh(y9|D6U_m+()c zfJ^nK{M9@XLatuG6i(3pY-cDat*QXvB_$(c8%OYt@d{g9BXa}&cfGU$zo4Pc3*ip(3_zPCVg_~#sMnJsc>wjm@*w7YrQ$!OD;=#g zvPzRUpwbgzKpV+80GSPhdT2leqB<7x5EAr5panYz6ol7U0QnHT;M=EoV9p{1&BGJe z`^t8K0rH?Hpt}=cAyUvhCDc@PN=xItM%i1C{^>v_TxCe)!zr052w! zQW#hT^C8E=fo%xz67mKx0?259B^n3g`@wLDuoAEfLsmzM#$PuA*eDbQ)@a6muRj0N zou8`!7i+a3oZXeb)qY410mcB+mAuu*L#$@4rm*5lkzX5Gdw*?-KRm*()mNMOyYxo` zu+py^>R(v~e zU^o%bh#(+1_@KX7W99yg4r|3-*!_>N`?bbc8~~%W+Aoa2Bw1Wx$h?uQ6|m~Ain4O6 z7Fa`DJGT|<>`II!c*%`q&Rhw_Ck5f_B1lHeUsdVf-{=8y(tm9Re~n^Yfh;&le}%&T zjA8{s;-8~fX;9q&xzfzC> z4xZL2NF-SO)lURu?Vm{dj~_$;QaTp7Zo^2d`#ge?=63bnT8t?>-&01hw3slD(=<`M zzO40do3FR_Rxxfd70xaF*C}Y&$Q}pE+`P%`$|p=5p3M1DcsXcRKe}D}BC;wtU&HOD zjMk?|DsxVAR=If-rLQiuij2Nvn_zYEuyMdRe(w3`wLEv>^Pz2zUk9mh(wOaH2(5Ry;;wkSabCfZoROUPf%S*HZHNF%T5KipYbdwQH7RYI5Gy!Ta3W_xK7+Fducc?uJi zlr`sY?p?Sq_2Y~B#6T5Hc%=U0c>(v!A^HiDfpW9PCiDD`3?}(IJ_p7$m|oecF7`NH zMZo=W{gnhUsRDz%{<4d`m->slOhx5l)6r_?T3+erdzl7wMmn3Mi}sG=XK6pN7a9q< zr6=ZCXx{(!YB71vqi^5fwU5;VZ^SviRKeb2Z+iBb;H0IpLy7^52&Izky5~3ckc~{b zvqjY)D_VT_`E=M_8!Dj3i}}}Xy2h;+qx4|QSK9sRy4La~GaG2=o^NwIZWhP7C1rEe zhx{jwS8nz@DV=m=KvxGI3HM>ZJ*;Eoov)`JagM6HP;*Fva!Jg4#?t@p_r(XvmJcY; za8I7GQ}@7LaQSS72<(;rbhGC`t$6JRr*X@VN8Xz7C}0jZwoW(XY7uNs^G!3c_H#dN zkG*Pn{9{T_PtU~YSjz-Hq$~Nd1p{K2>V37sca>+jCIVj6$}uSeJ(@NBLNT3T8=&{l+1}H_ zz4@cVBktOSXC2F>iV8F z9P+;ZQ+Lz1{V%hpx3@L6;_5k;Sfss|d#jOC4$IR??E77FHqvBDYVS(;a(G)OJ%u&J ztthIk%48g7-W0mr`}G>@B-6sY7xrP4{nFA#hEY{=#FuImTheVy=%u*wGK~WyFZP|P zH1d|zRjl?5^QzipK^Jr>`}v_Dnd*Uvl=)jJXyVpPY>|2-MKZa8xneqUcUI%xI|ejy_o#{=n~7EW5JeeeWH=ccN-_Mff=%g|-4>5Pg~Xs_ z?&i7@_42VGUvp$h6(QX20!wL?P9l$$f7P{}lX#l1?C*^GPEdS2&elst2ph|Gkt$l) z@qLFpT6OE_mdzJFk>S4))jDV??q_Hn&om+TI}}%`h_oJ_i5L=U*cyH#|!UInrv*e z-=*}Jv1^00g0K6L@F)tVR7(09BVKxeM*5|FBNxKNqTOd?mg|Fd&V0Kb)QfTmQ15Em ziTI3k50)-^t?%ZfB6s%j_0Fhmlrt<3h`aQP9;FAkI22#F0Uk>MkN(-Wx zM@YqmbOr8x?*2CvuYLQxcs5vSmNC$>&{FmTbz&#;_*s4OPYfe%ZITP$HRGes-jb)c z+(JK=VW5LNZSUi5?oT!7fTE#p34KeD@Qc2gTHD9tm&sowc~sjq_n^=@FR!8gQwf`e zrc2cL6PxaTks6U`Y7*kR(HusvRPAbsWVk2!`W}A5xBJ#a_q@juzl$kmf==m;r@Ukv z`(~~&bz?gQ!pA=mN2iZn*<$a|$lj%R=z!eC1k1$RxvW@3bHbH1(Hj79-g@lo>J<#Tb1-Zaz3At?r$zRLonM^FD2bqmvy*6n#2$$Zuz= zO(yqi(Oq5ix*uJ<23wPkY9>}I`i~TnF+B0xk=3t0v+u;RXcL7n&FM=z!>7Ksd+{-D zt?qe$=XRl446lq$FwKbz@9dZ=!ch|MxE40Nsy)fPU1fAGC{uYt^LS@as0+X8^-(8# zm(RKgrEN7T3_kijY(Bv}hh|wt4r|`*w`{G`dS%t2ojZiFxSQW`YB}Ya6}IWxa-B(g z0Cul*pV8#v@%V=K1Oq>WK6~4ezVcuI(rOpqjgeaqukcD6=pFdRUvmwe5go-bxHBPm zNPRf{!4}4oAv&Y7535BhLSo9M#P|DtV3H~R%!i8YFLxI?*W#AqnDV(|bE!kd-j1=k zyuPx8{U_s`<~`glFAp`O?3XWa*z4w!MBH@4;z%KY*3wtEZ za;sw+R0doHxY_ESOe<$ZPt&&F^Ru86Ze*tkYmAX_DXMdibxkukiGL$HVbqaofay?O z*09{&{pC9QUY@H%CY=~W&x;g_l1%RfLI`rDV)$%VDnNH2WseGj}+vO}>+O*?QXlwduD|wMUtf~jjcV`ANmt}7!3^i6?!%ntJhX zXpU2eV>=FwdCU!T4>Zl^lNV&xBv5zmj-YH7ZmJ1Nq*5^9$jJ~PquRhx;&=1+092AL zzWRRJKYch1MvwjrG1*GRTH&e&ZI$gvkaKtWn{jJ}unDPnLE-qq`w^4@tpVX|N_KU} zAB<0IzLlnYZe(+qfFuWEJB` z$Y*F$Yem-hs=&19jpju8K}7LYUQT_qj;SX$tN4chlW()M(eK7QD_G~QQt_8>+H-AT z;e{OL#kSh|8}z1KeUZD57Yv>ApPU+M)#F&4qnj!=dcAP}YT1&$t#_46IuDK6Sh~hU zRYB`6%|Y1*XC$+EXw#i7Z0Ym1J8g<(xX{gTnX>$*LY%046oGrANCan*$n%3ddDt!m zp6e6eQ&9{yH)MQS`u0fKP%juQ97n!o-X18vRK9<7VY95U;&N8yrx_84oj$0dh^Ptw z!Ck7d^-4bD&HI(a@s3;}fkx5pt@6z=JVtWoREBr6n(-zcRIKJ~ewY?XCy_iQz}#ps z*Sc%uy!FIXV=41n_4f|<^uDun-nyAwU#VszVmFrZ(Ptu;hy8=ik<=&8d-JF@I+c0n z_u_p%&E7t{@ZMzcMHuy`FJ5-O0k#-ofZ&u-q3fG;iso=jT#at;!@F*!mwJ-V;)97P zp_#iseGw-nE6EO@QuLNVsZ!VNS-y1E=H2V-^nI5ul%I{Ge|G9YT?M)OgK(|QDNba^ z_ReRpMmHQ8Jj4m0?dk2$gC8$(6m*?AO?F+PA}+KhnL$D9-2$zU#xu%$hmSEQ&kt46ofhqOy<+*K zk(=qt;Pv+24C;lMy@W+I#`YG^9yQhe$!r&=u}6Kx8>2zrYI&Il3>;ENoUUW-3x>}p zAU>;{W8H4QIHCE*q02toG;J}sq>8Q8sbIFafpSrp_Z5rY*F5Kj*?|+;xo3`;+)mcJ za@Th_$;+kd`{UrlU-dnw9mg`WUj}41ek$GWQi!HA4C`Xx)JSH_!Fb#!$T`)%dzQ|9 zlsQ;JP$%TG`BDBH%?O7t7{S1<)1fBVIpL+cW`}zZG6O4Wmgcv4G)2S>>veX=UCi&X zd$!DfZ>c;kj#2Wt%}EN093P2-gMEyfbukZ!jj!x?3v4!iw((Silre8IL*0u53fEfe z+7BG{wD{7ru};UdH3akZ5q~k&v5l`OF+J1_XFEIbScyQO{yG3*( zsEw2xZg|ca{sA1;1UUSo5)D2RO8A%Ppk}F{X38LZV?wa~)DFM5IjIwSpT6IeM75F5 zQ2K=pcRIOqT$t)xU+3q?x1X!od0T@sb@!w4D63{E%p*n2K$g{6N6R9RMif|6~Be6!BT zZ3m67Lwi|+Uf+E-R;+bDX~0OZxI(u%LSd@${^9CIt?Q|t;l_8*lr{=$CFq#X+)pYJ z?;Ob~SQNfgnORiwcECxf>-5E=EtSu7-WSK0vA766(a_T#IE>PYWQw0RX|8@c^tyE@ zc(&@qvflDFIp*6(b+J!I1a15inI7325^a(a<@@fb(`jY)hIS@}syRB|V?R$-9o5r( zO$DJ+dHZd~sOpoO)}s=mha)l?T4Uu}eU6-bgFX56I%n-p+Uys5Ed-R!56^S?p%2IG z%jB%wB7%;J-YycC*pPm|D1h=trgeHvv8iosug6^J*(thWC*+pxhx;fLYhthH)L#fC z`^NRHtMi%d196oLqfxU{uNr&yb&pJk&+`j>l-N!8+{hb?o6$0+ifTX0R$1R&BLaGyUg3}KY~WaUcbL73M&L79#*-F$UANnh zx-!~}7n5I4vLz2XW?r@3T4A74 zsIhAbw&65FH= zP5dYMn6(BDF1``v60xKwVk8k5r|0h@3(Cbgl z2U7)OT`vg-?68bX+avfsklk0Zywg(LXXtjz6JbM6(MKq9?X64;y~n2d_gb{46-&!= zBA@ROxaM-3hlwOpKR z#=72Ri*BZs9ksb#gTg)ABlw(hZ)va|UOklXN^eIOKMuzxuoS)FYHgkL=Z9N8RCNws z86D$F9@>6KG&a9-YaY3hf^yg7S#m_IXZ-PA?}5X|qawx|I8|OAIjFYP_-ZdU#YVa{ zS*R&i{p7ubm@K94@Qk*D*+F}n3XUPSrh_N%crXTFHivDG4SRmNj&)Y?T&R@A>_gd*;XRYAf-dEU_H4oqGb<8a z)W&Zd`p8KmG%Cb+WIy+&(LJ(tj~Sw_S3X}#c9piOx?xu(7ZYdSUH^U;eZzq3^`ha6 z<5Nyg0}poP#U0tdV2k=7q_U)C^dwjL!OmF=Ev%-^EdjnAFWcSwE1W$#35kSK9II8B zF)KIq?e<99>!(io;jFKGseky&BJ**Tliw|wru2vcne;r`&%>jMNllKghB#m3S2GW5 zyWZcR74%$nSHkgH8pT@OJ&*1dbK;m9(y5M2w!HNC^l5jS^y9gV+1Yp1J(e+}E&*ia zW}ZCSI#NkJdxT%-=#{h6z7Z4Bv8&A7*X+sq?seZ6BfDsmUmeBQE>s5T8(pJ9C`=)OGVLCHF~(J)Qfon5OXLhmGj%k>zpQ}T_UX{XOir{u+cSp2Gw#Yc$jy{+%8ICFuKG3B-}H<8FvW?I@j zK<>#En6)E$;XsF~iY1O7m_^TY?7T(b1@F3YjH%YWER(%<(u|9Lq}b9rF3aJnuwxr# zSV^rx(`_tW;MkWCW8;OAONIDv+LxM)@(z}_=#MnvJ*(bXaN{qD=4LCOF>gX)<38xf zf4RKhQ@cG&{4-^-@g?CWy82wD@97f=gJW7(b3${PjEx7&>^%GDLQWIt5_6xPiOMva zPG<<6&d4@D9eX+5iMAvv)7P9kHocbXsi;brId@`u%+Z?~N9iPJuhSkt2ELU{PCcyV zdh@~yVJBAW>&vNEZk)^{X4wh6P&izC$(}pn_|<9eBE9(?Lqw)$dy4kib07AW@1u6? z$)U=b)9_?WJ`#D{ZoToM8Z!)puyVnFA3H2MtO>$Bdjk3J{_I*z1qKDoWoYQLw%J6)VtsxA` zk#6@S{T{bnc^%|aRz>YX_bl6=xTRI}xqWaswWAX%{lPL@o7CZZk&cmu%#`N*H)#em z`1BhW^(#biuy`KCmZwrR(+YkE=oaYv1m}z}A2Xzv2^rC4H9&+iG`Lg=^V>m+_HQb~f6#Wi}#F)9^ z<|p*zy!DuWp~=Yba6~08D`3l&jaXhX0SXg?s4I(& zF2PrFwsf%uMlvqUQQwnsP;&J|_IfP^ej8zIdrE<54ltMX+4pQS2dC)fwp!5u4EHUe zQq2*U$-ujP6k&lO8)~kco2z*)x*XM=!n!9pijhz0Ek&eH5UTL0m2=y&K-dCHht@oL zcZs)l%z=gQii?8m+kI8u9m?)nw0rdV5G$2r8E?qDNp7RT9c*F4QIEVD(>k4Lx_2LH zxK443*GZlXZ=dRu%UfNd&p&JGaQ-_snjJl#OIF;RyApdkzFl@W?F6JHF zs>${t!V^ZicP#y$m*EHOvi9U%iIg*|Q;Z7Ss{FRob^KE9e*PRnu^MlPc58C+*^Rsb z#>l9aA=d@`@?dDaAE9un=RnyLF3V(vi~IcT3lOiOXeNWs7*bE2JY;a-19qD!vEJtm z?Jd#mj}IC~-isc{L(n8$NEzwyitFw!S!tWE5fY$!GK>f8HP(o5Ulk#UM!8vf)!go5sFCJ#JRp z7@Gr*AMk>^72h`xZjG#-K7Z+~_envq4U6i%eC_w~#IO^mlpViHo~GE*#}?KW;-$ru z+oHMn{gt!Yw@CL~<`Y>GB}*F%E8QOjm#26>(aqMa8Y?0WuU7t5W} zaJ))FOZ6L;jOIkxj`f$1Z~wN*UT=5#ce7Vd&X~D-w79yKbiBIO`YDk9Gxw#N_MtZs zBQc8z_KXvfG?_`4j!f9iW6tdUL`GytGTT(18;9sEXzi|j&^9S=^5F*c zmtDkGcK`R(5l4p^m_537?b};u<5qB!+WSoX?Jbl_o<{RZ8m1~PI*EHe@QIy3f5Q3= zBfb-aI)!a_hh%WcQMb>TPZXVruzjNbuBCUWaoVKUgJ;v`8{fy@*=X44XxZQ1LpI*4 zxM1;$W=hi9!o}Vt`kq=TBhia3fpadXA>4FOYv^cN_ScDT^V(FRnXKe0JI2YLmt5vP+s&V5O+=kg6i)7NRskyj7u=O( zz45tm8)D*(Q(#VqZmVjE6W5*Nc41+XzV|lmVHCGx;fYG+6%ZqL6g4n%e6cO^0i$+a zcuHWwO?m9cdc%;9$Kwl(4!bsR#LvB3{`RpF{M{&h(RWSpl0;lfNdwvG0}Bi^JFj&m z*GF<0sCSXYn|Fk~(7Z5_z_>f#Vb6yK2BJ2$z(`r0+=zpJJM)sV+EP$UnNsp(tiK~e zs1IMMZhOIW1=+DsB00;BvXRFg&dFTngHJTyISt{4On7*v;?hskFomA^evnOvA>T3u z zcT2cGnz7wb;ept+^MXFTk@51DQzlYNtX4T~W~UrfEorN&PM#otH}r|9SK0pUTjjBD z@kc8UpW;03mff=8Ja8v6&nZPp$Zp@*m>-Rk{S-r;#jwwD; zhxKoeotauLqn`?ir`BX~(_-}e5K%>*rNz@NQ|Z92qZF~{Xxv_V>^xE`6T3z9v0 zO!E7U4!e}&zPFWMJ-bwHTKt6W_!VaE0K16Xvb>))JkwQN6yK{3`egURxj}vpBX) zi+}IX#`V7TOfCE3I2hg1JE*!rDSPALYtj5HgA@gPS6}j_ylRP&W1X->MJ*dg|$ zvTnPldvN@Q!Qln0Xr8;>!|<>Bzc+R3A9#13F};ZxuF3Eok50=sEKDP>w$^%0xi>uN zRHE7Y-4}UscPAtqf6w^!X{wj?(h2X48{RA+ng5_e{2>VauW#mqC?qkYiN2L1e0fhz z5y^iTge)RZCzO9?ipzj^{8vK3P#O}dNDxv>iVH)jgRkn#ftX(>b0@c7KB!MB{!?pl zwjuq-2I-^m{794}_;#DQ4e6H(;0xR+Rec-qI|%TH3rLsZ=1z{v#tv%w)^^|n_fV&S zzcd0r7rzp;|KkTTz)!LKJKtv8uwmo!_YE7#$SF2aZr-wW+jc4h^^TppXm-=m?V)Gb z%gDsc!nzO1wx9g~$H7CKT--doe1}o|;G?wQo2B4Wfk%Xn9upQ36%&_`l#-T_1@8eU zC@P&$R#8<`*U;1gzy6`4t9Sa$S$zXT@EazkX66=_R@OGQcJ|-{_|7h_=iJ;q&U<=Y z@b>Zb^A89N3JwVk3y+Ar7!@6JDK_qM{FQ{nt4YZz*HY8cuV-Xt-ME>ZlY1*K|8_xP zQSqIU(!2NWmz7skR#iW!sjYkX=<$>KhNq3snwndlzi4fH+5YPFn~t}gUES|`di(kZ z28Z5%7#}^rSDHqzs`RBdd7i_j7*Nq%&dc1SvL;dxN(#7=FM!b?Cc!woSa;q z+}vBdw{GR}<>loc&dq7oS5i`nFD<=GxO?{= z@!q}rg7@#29Vsg-7b-8WI9gFrd91RsO1P@3TBN%Af#`z=HDWb2AmpUBPNJ^vq2$Ad zkE9+wdMy3;@e`RRPwHjs>l@@68lE11`m|BLvGJM0vu90;O-;>8&CM+*T3VhfKY#v0 z<;9Cu)z;QFwYIjG>MvimYqYn&(tP#mwbtv`Z%)2>({ZY!FO9Z*QM|UthmLfB%5tz`&r<;NXz)(9nC6_wPTLe)uqKHat9HJ~A?D zF*-VCIW{(KH9kIJJuxw9GdcOu_T$GXyQ!&9Kv0}^n4bRZ`1$jU)6C2l=PzGoU1n$J zT<7M#p8NWB-fezHN~tH_vb1zI%QDzIsd*usrc33f#px+~qcjyg1**opbUkT@7ado7q;TT~ykXipY#8 zVu*bb;ZPyV6Z^xFj>2b}XNS%U3q=n2KOB7Y#_givX~viSo3x)^J*$i~R^7yB?5i;` zeCNq<)DhFYt=Mdj@8`as^FsCX%zgGiiakYdq!0^b(J6NHTAm!!ag23-%5CjDa(ga2 z2m9#l(^eLD`y@5h`@xW>Z^s#$4AH0(*TF8lbwsw(^}}sEnsH0V3rz+BBSP~s-x|aj zT$8(@r7=P)lp}w~8Ta-`=4p+EK=HzoBGp1yfipMW%PUrjlqpav(3wg(d$HHE zM$CuUpjM!Oq&>g!(dA0st^>NVTqo{dE93f-Vism*Fi%~`u+v&4^;n!NLEL@EbB71t z=5kr}`&oKpsmik5Hy@wc`*O3()z-@@68-*lgLh3ON6cT#U<722@?COl>-LvV!B%|U)mTRMPEF`&(Bv)>7Ompt)xW}k`(h&bwW>= zRo(CBZ^*$SCf5<&JA)VhCSjsw-u2ae0weH(=F4ZY!3+wzvYn5z2iLHw{5{y+m_H*-UnpNzr|+LnX{qX@x!fd6$?Nj$SW*Y@U7R z^+9@D*TfjU;jde@m<9LVxG9HisN8Hib~5{E#3rWx$Gbmz-+HW8kQZ;zjcy(r+g4wF zf4QSQ*R?CnIlnn%K3urGs$sORsjaDK6+0sq7-@)24({+NU=ye%#>69r95`&N z%a}9Ym(+?(j!`!}p{-lhDWDh5?*6JX!>Ll=PeL$BeKF=dQn}CA<;if0Q9lF?%hg5d z^TPSS2oDUE2uJ+gtIF#BW7|sN$6c_9ctWXc#HsATj3Jx04OZF5DeBXythh-^Bui8k#erCjepV2M({T<>7a*&zr{SiyORzb~`R` z&m27v8W_A6;2YqCqzZo!+6uGR^;*^Ip%8g#^q{?v?{xOi2O_@u3k73h`2 zi7SFM+^-)uP;yhruTfUQUV<+)1ZDkwk|BCRw-iBC(0*?xuxH>8(oNczHmPbnXf zM3BuQh|wtGQ5~_|n6>jZO)?}Y8mDIZjIO`s?eSuzeqCg@5|Cu}_=JHtfr9Z=U{DXz z0X8!u$nykY#DhkL4W}N@tbEU{*$z%9fYx`h9NR=wAmZ3`gjdcRKmIrh+8^)N9g;IJ z1!}fbd!%i^Txp3x*?85j${M0( zq&C0MX!COLRlXr(hbF0=L!|cZN_nhhL5wLwKqqc@apBP@PbGS3c`M4lp zzmtck5Jd8EB7az?cHbX_J{!~56N5)GwX}3ayR*3XHdjdQuM&ED5=*eA{28T-OMLus zI-RdfEzt9$>=db_s}g}bWjnnQal56ODQGabN4uhK-yOSOKJgw zz=M{1`CIZ4Cx5Ez%Ms03d3SXZc=FvLm<`98{?tMWGU&5CZC;9cIwc;xlP6HAJ^E}U zex*G-kUM|rHp9!_4d4gaK)7c{ke+*_slj1oV@M6LBCV`YHfX-Rt!TJbv|aQ8EFHmF z)4Xf19h@uQk?9e(hU48qITj1b@3NPo1Y(_ImYqF$?8CwP721>wK+8jr^dRlga*U^ou%~O zRNmGKUh>FdI6G2~sg&-N=Rs{b+}_w&5pp)6bnp@7`09L_sQO}`JLDW%L$%uYcZ z388mm;SyIz3W}|IbgA0OvfW7x2dfI%65!>g8nhf`(r{J^;7vVlWa02S{M8yG!-9fE z>-@{hHjxSC@yCwAIGwm)IPbI?Eqf=fveEeQM4ERcrIgJiZOX&DfnqnyWZoo$(fJE2 zh-T4tVmy8V^l^hBe;KTMJZ18C@y+Ru&j4Q#%N$Fv5g|h;?;T=zOrBb>mZ(WIB;kl0 zm7qC^G=YFaGfb5L*bxcpfaU<=UL1|2ak6Go)_RSKC2iHW000ZCFpD~IQvF1!NS*s#Wd=SX_< zJ#;o0xISpC-UxTxPhXDthSK6tfT9KcIn=6EpsF^ev&)uiE{Ca<-O-sHjt+e*@W?jq z@)#&nqZ;IvW86MJHy09-MCA1_M9HgLZktzB^hba+qY0J~3$&uGtIyQ+g+8qsb8bgL z`-{=W160gNX143RI*4Z4(IQx)yTCKFaHJ@y^BOq|O2fF)fICs*x;69iDI4<=o;AC5 z4VweAc9J=hD3Bc@zJqZ^X<1f9C&C*%dQ0?B{by{yS1w4c!95(Lyzb}MY(G~g(P~4R zrvGhHY$N#n5L-fv^_Wqn(=Kn5=%cBot0$nE=)8^50Xir>bj4wXECkl#bcyn)AB`Uf z-Ir>7L)x$`V2=ur$;BWY3F)yNeIru$=6)a-tzj>~DkujI!ZplEy|m;A-lr4;!Co-| zFv!ndZ1JDREg+Fy6`Qp#lX(M!N!yOknw_&lb6v-NJ*|s}a|B{wgI`PPBh_O1qbgdO za>LAy@$QyD9?*)9C+6vGX4m zh5eUa%0KY-Urh0T?WGti_(&_Mq4=eWZ2}xqG=Q<Wrs*`PbRbgb!H{t51fuooi=h z#tY)9lQ*RlB&1Ibn7=6!popcIRIeMS6OLF@Nt-mJLk5`wC6*25S**~zMC}{SP@y~5 zHeBZ(pZv%=^7@{B%?K!)Lj)s4Os*K4oF12&S6Zv6erL#>KmqG1jAIAZy9_W&$`cxh zgxyio423{tafg(JThLnC#{P9GB$JVeBv0*6Cb6fga1%MJH&G@Rq@5+XC2cI;u%uo$ z8=OV29=V8mt}Tj4%lD0-;~h?|8_}mdx{tY##MaXdZ={NtQjJ`%XuS_%j$$E2-oZ64 z8`^xA-0|dpqMZqkPF9bt_6}E|Zh8Q-ZoGi?Zr{-inI2ZxQZb-M!< zj(lRzt)=AEXHFk-waD=E_*sl>eE>63c`x|%o6L)QBZm}WK%%7mD_K-#9Kk80AT{(y zu?d5`G)CU`g3xe|(pYf%%wa4h?jp{}8OfA>(OE35E2ziazWDV57|Rg|*gA%~|3}ue zA&~l-E^U3{Tm5Z$-zCB(bZ5fH?YBJV^&fMSYvK{r>s_b4`k4qr$TcI&qsZUZV>PWp z`+1pNN{YJM?gi%6ISIYdmbr_Awe3M$Y0|DXVjc3$HitR4V3rr_gWAMq3{wNj@!+53 zt3EkVUNbY(Xhxk~T#P1_Ucb0dYIhrxyS$u8umMOo*BiBvK|_jMt* zy%@(XBV@40F6AtHK!`|O5YomE-hpK=03yuZFXCKr`N%-6z{V9OS-Hf?4|-vG&(`8^ zDa^4Ts4To)X1E0obj}NMVd2TRr@tCQS0o3H!&ov-CjBuVtPz$`Ob1bYRVC%Q0heHv z%D17@HeAqng|M~-iO3!x#21aCxm`eVQc@B85$_b0-n z$eln3C<&zkI3^GOEDJ0W&%-nzy;#66b6c11{Ji|v%Dj!hz)s-%V^u|izQ3m0Qhb42 z{OlAY0O?>GAAH?>TDc^Wi_$77+Q-vypweI5H%&PHt^pR3gN)Iy#o-Y5<+>yM#)*b# z_odlf>SfvF2JRx5?%RGm*3(pg)|EQ^{9a0wVEz$;aVQ8EFs3MB2`f+{ts|%oVddDh zL(WkQTb!|-)Pr2OVKc+blRMfU3@js;ikv;hNm<%05k8Bz?sIMrhKHO|$G%SjZyiEb z{5~F~ZcsEgN+EL79tWnRZ_-e9A<#&40wVNU2>x^5_xDz)%m^aIV;`AL7=C_$k_);x zFJQF~q*%DAC@BdM7E%*A3~fUBCjZY8&(xF1;8)$Tt-n9Gy7{XeCj=r&R(w(!jHyP0S#PBTz9E?-J!u{mH{5 za!U48(^BKoGgGrl5aZNia&(f?lhU%vcTzMmRFhNVfSRSHdk{?8mjHbY9O_ zxi*b{cp2|P)|{iSKHq+{PmaEF2OqrApI%7tv#%E1T|C_00RN`j>7#1||Mx%r|K=|K zf89h2YiAS3e+?z;f7#{2CjZiX|Al7%ub$w)rMCYq{Nk+)EsyMmwM!CLMTTCxtSz*% z8U3fJxtK;*u9~M?QUzsJELqh%4}$<70ul*?;7Fh$)0iz&rU4rQzt+Dikedj89{6;o z(ertJevxxIUDK<2$GJvr^MY@O(+M4AME3T?)Xdea_t*E+%NrgeA|_BDL$!#wyVG@g zL@jZpB0?EdQ)b1g{33A6XXC4Ce34{dLmne|(5Y~s7bzHZ-hlcgbpVUtj_&Tv0A>Z| zck|raGd9`(M`Q2AsoTjcnh#!N(B4F5bBxl)KtsWH=Ev}OG95ZOGNrp&Iz6d)yHvF# zr=R{UV@@`(yfSCT*G_``~qmjJSLZ=;$PhhRM^9m6gfv zq+9)TwtIoNd6WkSkL`KPg;MqM&H(5mCZHZ_)g=;^KCTf2Hnpe#eEOuI7o-xAniOLryh{T0Pm-2 z*k^VzW_lbwk7!P*W_-mvXtT2(_$mxgZwN3ZKp@uF2*O$Sb?!)_?GTeq$Uut2YloV7 zrzr@iAw&8@rwpuqt4-is_t3El#}&aVzt1?)v}?hXl*eY$u7aEkY&HM&gucNuzn~i=^hIfGI92f(cAddB z5(h7Ik*2-vm5u@;E%%1;Gy=75SNE~snA$Y~8t z8!=Js!m08_f)2KX8OG_qVxtq#Tf;pGg_XQg08FWVb~R2O-#`8RbNBoEv2@L?JC)@R z^3$ehJeu2V=%dgtggeofwCN1lURl-E~2kn zg;7fY$E;>Z-_uf(Lq0^d1dEx`VSAVZaq4wSsTb+;UnSxon9tB!Qq|sWYC4j7n8x_1 zcp}7%(`?=+C3-&yV(lreY_y@x7vfdYyzoqm%M9`O>|>mHt5o=SX%WMrZ)Y(CW;p+N z3fywO69x@_=ziG;c81}@UTBCD@eIt8OZDdNJV2}I3-?}~;4WWV!b_{B)_9X|_DcuV z%`H;V!{wF|_?xzGE&q*flv|T{B^fo@Efwu)+|8YsX49%_%>Y`h1AMkU)l8*XM4Nb| zO^n4#D1UEauKqe?w~@qDva9uG`_#qdXbCw{QeK?E+ArX)SALKuPs}vGQ#1s>&Wo=P zT<^pBv?Sf>v$%t&`tZzFuhrsZgPyT5Pwz4HV-Y8S$KuLwi?TX=i}T4yTHB7AflwEQ zRh8?`R!Y|E?eCcZc-)v&1J#-=QmXT4mT_2;uyTunJzC0XhA%{Iyx>ke-Zna*-2mQo z^qcJO$@%L_N0xVYU0w}CMfEOWnY_W%%HawQyW~p5b7!_ym%LI-rWPf3ANrC70}7Hl z>!6Lg-M_?_FdiHce|XMQKRYbHqtj|*9^K_*H%0B;C5*rwP+)U77v}$dsuygW(5Fq# zXGPTTHNHt%rpK^eI?B6fxNX{N*@&UeurRy3FAXM`YG+usfz1T(?X?olp~}WVMy8Sn zV`^zGcskv8<%B0Jp6S^-Z(R&p^rkn?g_Sg^x8ll3cRF0&n*BPP)?NCO`fIVn59fRP z=(s^U44sWuHet1bCFd}BL)3)!g%;Z*4EZnN(K;5~h1_YZ(>v{;4v@p2lb%caXiB7{ z+tYj2cCQe^V_+KU7#~YcC2h+Z*&Z6a;8SvwiK9W^)9H8shsnLPf^^u!UpH`6JB#3` z>=W|1!v9%yJCgivE8UQ4*6fDR$ahPdcO-m6{W;)F4`^7kP8-%VU&^oKYx~+Z8%(7I z2SyFGx~BxTB3BV#gw6F=$@c=bzr$63Z-&qYOm2{m+&mrL=01F;xao3Yl#u_D^$*4n z@HS%LpV7JOSPz=#by6t?9;cmQGA-!caetQTjkFj_kDC&%zd6|pmKvnVz=_hS~>^SGvdDQNra>awqcbSL?FoU_7zeq%dz zaXil1^lYv)I+vsWV0Fn#!xxrn*Lu5ENuHPnkx*yk1&>%X$=*IO^c+=)fbJ@paCM@+ z+34cAwLFM}ja?*GTFNjr2ZF3n=o*e)l7*XDr2&%GA z&!j8zm5suk3w^&;-kQ;?Lh>#n=<{7#*J&dpwPB!)*SK6*8a1h2Fy56Abn5e~u%-vGs=NJm=`T=U_|GrBZgahiioqI3 zJrnJBK6Cr!vJ;C&V2JSdK6r+?Awnot0R|fwHDkzii{WN+i_!JQ^QG_Y&P&Vdj&E(I z4wvXE>f_(*M;F)?ul0KS{0N}{ckI(F9*X-xkDYqGuIU7A% z(_khxt|S=~;Rtb}G>}RTx7+b5T^c)$k>z!@OGhLbe3R|&_Vb0-G?N}`g3vlKDT(NS z(wWypYzLm?aXIo~XGV*<44BaA72%vObo-BofrL*aTT&{)_HAvvu9)9t_d@6Mi{{G- zz8A6>StXjD$?PD}_B^GR=UMr=I}kDQyEJAueS;la39nW)nZMa`Vrj}+=(E#vG-DO~ z2#!IKR@n+)?YqtGx|(YXmyHg9*6e zKD+Od%2uzffOhTcdw_&uVX&gZ;VEKIUvoX^65eLPhd#>jW6F_-?+Z3_xO+$rz=d!_ zPn_?M7*C|9+84eC#>4xM5piLEsScjPhk}!a{Vgk-ZCWYpJ|7U7d=$iF2+2?rILy z>C-}u5gmXc@_9y1)*LQX?zGzr*7WRLBM_1yVp`~H#t8%iAeK(etm~a-Yaig-*xrBN ztD-?=y~Z1S9V>LP9tbt$oTd(RcVgi0K}0+zQu>S7IQ-LvXmmUz7*O7>4K(MR+m{)g z{seS}(iVBHdbv{wFWi8=5PV00afBdLK17d5ZBNlUbI;?)`Mb9PobaG?*kBvLp@BCJ zX2|N~{r>P#R~$-ue4M`E(9FF*6za5&Glt-qE|Tn_^X7mP7dBNX(>EI zFp1*3wYak|0$*$>Xm_93Fv?i6;=6bGnhL!*uuB1*be!jc*e9kwnUFmV<1&3e-eJt_ zRGmp0ASkWK7?&{jmcx(Cu>mm(S#cOIp|~SXRu?^MGMd>?2!lXG{ks3$o<4Qeu=UB* zb2K1ECW&{NpfTr29~`r+68;(Q+_ISqPRoqqT|{!4xiH;W*ATExnIe-yVOGrYPtik% zBLh?R@QH74MHkoecRFAE!tj>6wrmOMUl4C-m=k;+9%*D`!Vt#InxpA; z)~byqfkiWp=J=jtDGoj)GjH_%$twNuV7vcJR{e*u(Eri~{I^~Bzomw~m3`!q&Hl+M zpi066v8#mU^|GZ}%RjZc$y}Sb8y2AP$Y*~Ho$(QlnD&Cn@d)_GUK=uHSRoO52G#Hp zKmg0-L7QJJsZtPms(C!kyjpg$56hk0?9!T@T2bnm++@wncKC8$eO}(beP?ey^vwhC zKnCftFzd+}Eq^N!ZzYb9G<0j6t%?K_64N=oUQ6sKjt2F2E%|mQx$!#q-BZP(9v&fs zRO=P2e=k6bnRefyGxvX$RcEpV0`mMQ-V8NvFH(JbaWnx2FDh07x;;iCkJ8UEq2@=H zWD2hLI|oD%7rK&|6}%OC2xU^}BBo@f6Y*vfrBEyuR)q_~vTzi(u0FjLv^9M*zKGGY zrP9R6C#KLPgrVAnGe{H18bv%teJ^5v6S+ojLifC{e#?aDUj?MT@L>X1`sX|`Heduc z@y)qFx@Ur11?F%;B3?odfb(UtLgMg-f(G)1@Iv@rt&Sx;R?%TTdXIm7_-*lV z)?)mFp9)MOW9ZOmN&;DFHJXjt-L>u(i|+}vgi2DbwO^JU?;o(KT52(L-Zv&XzbaI; z0)tlly)ht2-TmRw9#BCikdLK>omj0Pki@;)z(!{)>fWH+~3TBK*qV>-&jQCgQ74vqC z4-Wka!-eMEK4YPFs{RVI{oJ2Y&0gaR#KJ4_W8Z%>wQ$Ebq`;gtq{TNSxCPTSGoOR_FgA?} zrs%Fr`Wq@aB74GEg_Q(V(&XDGdwWhGU}<2;O5ztT!yIKt!U3+(FSdOW$lFtUiTJa- zMr6~rR|j$kW2m!8VUTgg@yaVqK(Js>157}p(SLaLz`225d_W2HqWt^^`P@gOyxC*< zLI>^gGdgdAf_Xunxr-`kH#yChY#Ej$rZl0y(RuY&)jF7r_LMK zGAU>s!J^fwO4T|4&_fU5jd~PDB64XX`Xmi1*~>XJqGAdp6tr%lO~S3|g&)c89_h&B z_J~=Os2Xq-N}s%&N+fo85J_WVlEGzBqi`9nJb}w-*KSF9e+L^w* zw#SCs;inMXjSyfT;rSjQ@21QF`BKG5XAL6It&pm z%ZbW=WYcMuH8~?FZWXnuu;{YLyY|N{3KVZvNjVV%X1b!H%?OM~TOY1ueCG4;qR%V-CvR&5lB^~Ra;C&ygg(PZ%<|uIU zlD+-?K4I0leT=zHLFC*vOtVno>sISTL_xT3^xntS)WdO zjrY5adT|r?4in;&Ao@e@lD@GONqbhHo})SxOX-p=kfzVW*0?+jBedkAwNG)q_RnN<%nIMUhWAsh6%*KKyWGP10&~SXXs~VRnR;}Lj&sn^HZju0NXRN@#Anyb- z5h}WEAfS$^=TZRx%oM$&$h-11FaH@syC}IvD^QgR#XS+_9ENSMCcn{FIGlQ+ohc> z&DIux-5LkUO|!bWN7k_NG;RtlIr1Rx>jW-vDIsHmhYV^a2?{m(bdUFt{qUy#w8%Vl z5Q~1pNt4>ps<>@ra-m9FoK4ZQx$ACqpg~YjOg?EFhxi2E z^iA-vtdq$U&l6f`Bc5sN*2)sg+H4og1#^&eAHzVUGlt+x?9Ij9irvZF(&+FbVv;x7bG=De^M$nmnNbFODw_-4XtW+ zlzLseZ51+5CuHQi*KGHb7%wSVZF0Fxah}1E;okTMx9xL1*_m#lc9d*CQh8-j%zl;- z-Z%L@c~7{#ssqUSrz~RnN4?3Y&cN8$*U%EA(JRWf8x>J4*S10=Q|mkNy6-1-$ngTo zks%&JY%Zzz2M4x^b>vKdhp1*=*h!CK&o2^waP_;=-|a-7b71nw#Fr4_GJ}V*$-328 z4)D!Q>FDY42nga z=MS^~2VMWJFRalw)zAK3MWv(G_-|)IGXB-<8kB&Xm`^ZT89d9?b`R|Ob0`rMi{%_s zPfUxxAt3R|tq%+5->leYS22a2q{aJJ;T1i+fdvlSuaw1kc@bq?Fzb~S$&_9#XJ&0i zHeZ^%JJOLR>}{~7k0TBZ*o`$Tnb?km8d?ChC|{m;aTF^FHNyr@fw}y7?68jxFndjH zGP;EKgZW6J!?7{_sB_`>%e67}lW_zb88eeKt1cL@U5Kw8SHAP(iC`k z$l-Z)#rjn^acmp?Iet4r22IRLa#~wjTF~KlnaxaA0<8uXu*5ARe$|G_wd&@p8KNuJ zqP%8}YJL-$Yy}*IKSkK9gv7-x;vy3_Oz3vfQE%SrZJmB4x05K^$e~@tM-1OLMUBw= zZVmCuA<YD?LQVfLk*B|~tO>v+k> z5m333H-puakBt&0hI&|);mRVKK;la1m`~wfJF>ONk?f&dU9`py2Ootd3S_8tZSA;D zYk$h9tXY}*2Anh6A>OwX_|E$!+S3z&C21S6UDDo~Pb;{S~9$uU*+-L5v}p!%sRf>@GFi~h6yviHl&=|pM$ zoeMUXgCFz`+4j5dmy=9ic=xtnAvIyTP3b1s&DmfLl@jUbret;{iboQ|dbzGHg}HP% z-vf}TSKb&9DxWP`BrmjOf#y(_Z3S7{G$rP$%VTuSC_xSDZ^X%?VW_3O8_BWcN#s~_ zmYJ9JS!6<~9@#WEf>-c*0&_!ZNOD6>oup;!iy_qFIg-k!mt=z-4EV+N7YP6MLjJ<| zk_Bb2>9@gJ4_3_JAUQFOpFGY1^Z zQ~5GUiNaQHSvx)e>JVi8>hbmCX|ur{8xVg$f57k@Wz=nCUS+ z*#WjlH~h2X$5^nGYhOj1_|a9r;={DE&_+b)+-r;IWblP7I#$V`4$pm#OHmmiRWc z7+W!MO7IDe982wH%-HIX+-|0EZ1R+3$u;QH=5 zO&;INtCl2L?L*bbIP$5_{;HU)Z@+cD=l1X$hAn4c}RBXBb{E&ZJ9pP=DHUK{&Z{dvXSxCUU`&w!Rvf*w0q zo>X#JvRkw?X-iWESdX93Yrz%Kl$tIQD0;R^OD~>;9!%Rj7@ZeF=JHaQeK9Y*xxYQ^a-ine>nXBZ(}WM7Mq1qi;PPi^7%Q>jT=tKPCVU3t3*VGntPy| zsC+IRr;4g=IJn&EFsX-pF}@xDqIXDT=etU1Pp6qDrvw`$MZv^x#V-!lwUOFgXtkqj zlK1rS3RbkB02Kr@W65+1j5-rmkAiZCOc&i=YA5-0>{x31lj5^k`VIQeI+%Ii{u{0J zgRXw-?}l2%s`_hTU@LReo{d41$|eC@Xf~MD34KQHTG#moXj$nzz}V(xcbK_ic);US z;s{4vs^i4hcPUjq%5xfSHB(Za-A8;!1i{MS7*R2^##xm52K_)-uE?vdRjzGUu*()A)`?Tcw_ z2bL=Y?a-_&NK(~Qiv*0`3^Fp9Z~rT|aNO!{xeYo^n@QL1jnpkaH`uYI3vK}GVZ*zp z?I^1gDCNY|>W9X?f%cuCjBO30KlEiA+qwxa8$J1VIYcLvFUZSMl7h#46;y+%spGn8 zF*dVQEI3DJFK^@aF%Asxzx3ovJb=F?~`JH z;U1#{1KHrL4$C~ike{1_0}%&&cL<3?*7pK(5Z7t$B)T|wlVW2- zg5xZj?O}JkxUFeT@*MP!fDZZN-N6J5rhVErv$;7fU^m60#;ljrPX6V1J3;oYe83) zY!NURH1?~&4s{GEbR*7EOPKD6_Er?@z00$6q9XncI{b*)nv~R0c4egbB8$KPGl633 zr84V6q5ar#;KYg?99sObN;4FwJj47BKH3#RSJ2T`cpYIe0Et&bg>c#wE)MO8sBE;D zKwYG2W_^=MnbSIp`}@jpy9e>8lAe$@@3v(^1?U6d{akSJal73Z|Inh11sO)U!V;;u zgp`rqw)AedB<(Mwr`-vk`rioP=VD`t>wHm$xJ#kIMIWidRfDf8J}l(7DTQ{?a?24D z#hMKTJwY7H4Fz@3rWAhsqln;0CDql0b{6`Ef`T)dg6=b*S~MGS&l92Za% zS_jdFX^%1gmwOS|1~dui{1y2>X`-ervryZvk)u%5rd&4uSlNKL1(4h0^}1bpO|87Cr~ccwnJtRP7X=sJjHnLMH3oHH z7(q3%V;SaOe#uzT(kr!Ce|WIp&pErE@p=4Qk8wS%Anvar2X@aHxg^jF-7@?o%o5k~ zbSk`rT;x6Y6}Pkn)E|YYVys>`4kDu8yK(L|i2Tq*9nTRG{-Sk0#E(BRuQjJcU7M!& z>S~92vKr@}{?haTME{NF`_J6p|B%1+U%I~>^#5WP|C<4-q$CezB{Qs%TM}pm29#0u zBe2_OLUF4<+9!Es#evXe${?6lCfe$Rgu>zjgaibCsoDNk@xvrcs0s^%3L{W*0>wZd zsw+ggU{}USRkoOE&c21bU!_A<&)_lTaG3qP&%Ez=<=%Sj?!M=MkEZEj#2kL9#4F4* zOqz*^l1U{FuXiq(l7%fiHY5}q;SFx}q-ptg0(WgGVcPnYWIm+_uH=RIdGmby6akz1rP<@TCyoj~v@}zCZMe!3v=IG>(KZmj=p1O@haL=$w^*kj-2V{N zs1c_|uGvV=pqU;|Aw7*)@FhYKH8p`m9{EXyL>6X@XWmu%7P%{7GYFARqn=78Ee#(U zUywFgeW z`LZK}AmzR<&r#>TCwL{=McD~&$L*+^5X%BBTl{~F2{^|cAdslkn5k_#( z%!5})n&VBDa~zkJBrN)Cu{a{f#qRU+l)-=7cY;|NxDcph1~zpCK_KW%u$;doPkTTa z5DgEI2&gNW1Mgate?OPsbrL0=&P-Iu(Hs2GFDjJAt6q|oLOJ!`0;>%DF;P-U(YpCg zbB8*)Vpmg3ka4skoj`??O&=BHhj%zS?~+rvAW0Ijy`0f4TCuW5iH=BNvA%g+q-&+3 zwvffQ4EF?!T)OC`C~k|ZN&kV=>k|&xKQ|VXCV=1LC%|c5xgkurD*~;+9zi6(rGo<3 z6Db}#Zs~$RK!+6Ik8#k9QNVpc9*Z?hOh`x^r>tcW8V|C|7Iu|M_-SI)Z7 zl<~%EkAOH<2q%IZFcN^H4*=cPCGDYGGf`2qqNwuGlVE&s7`;HvQog7aQ2~=h^?d4O zhnU)eyRmP9dGUBJBtOg!=E2=PBVR$fv~s{xOiYfg&e~Z#A)vfClK_=~%{k)c9#y-m z_3nt;;{Aoc#IUzyjzX6cEzCz!H`CBQ5p**Oet!s`e?$OGU6|-W?oOi_W18QNF8>!? z`3^M9zn$KShFa|3#!g7xWb@0bb*v^-4+1(^>+hFM$u%fll-0Q_Ulo6$83(!(3PDSr@)<< zZ0v-FA&+3?i^$MQm;iSrtT4G zfRWVxDre?wex>-|Px7WD>g5cmmpPm?yCCAb0CAulu>pajQ{u;INhX_S&iBumO)Hxg zQE0q_%-5AAW)o80U^M_uxpPx-`Cu} zHatVSDM{o?D7W~gnWAQFcC^q*RkAiWW^QU}lx}9?XA*l~YrtBs*fJ}&n^tY>IuCpc z8Y`BtOiYZSbhNbS9Y~_K8)zZ-NH1Vu(QS11P;1TlK*8(U5Sn2YtkiV)WLvS(=ae7d zQJ!rL3uFuV;UqGsIq<8YKcr5GDwK-WN~h{le@sx(Wc8$ij-&RPw`X*Lqen?;W48m* zMnKcam4@^e)}?1ErjjoQA((I0Q|$a*UJoKq>r2&K6G}B{-M)j}(Htys%YVYhBe$5D z7k1t69kHK}XD-8~!pdkQCM6<28Ey^T1~!^8wODTp47Cb7L&F=dzXyrYFF5zM1iprB zu^XYkp-UgE^a((Is1 z<=MYPKYou2kx#l=E+2TN+gf)=Y5^L1Bkv89_9T*mK@(;pDr8$Po#5nY+j-b>8aiVzM$roEgbI(=i;HOJ>y&#|?Kcu#jk$vi4ERg~7(xW&JCo;rt(2jvLt zx);0K%3x1$z{Ien`2t_zI&1OF+Socoy1-Hu4GNVt?jKog4y~mUk}g0ryPGZdj&^6f zWtXqrI4(d_D?GfOJEgOlR=?DMC1|LLk&#*(|Jo{&v9$g z0gp^EL5>{RxsCdQwrm@2G?j}~9o5pe7rtSaf8uumjHdA3d;M%XJVLW0=Ei1ITQ+oi)pSM+5f@zV1g#&fV*iQ2MtVj&rA2SDl zLw_yoQQ4zW)r-?9Pr|fUWT8pXk)P}7@nxf4?gtSWWHp{PvOSP8E}GmO&6;n)dSX*P zWsK1H3LIVI2dJn`Mu0kv3nZu0E1OiAWxU?6Y>gr~8p{g&CruS1&}5*3oT0uCKu6hc zot%ZMDpLN;nYa8!3u{sgU9QN^Q7E__r<$%HY(CV_uF*1$R8|}eSe4(@StR8^R47%i zeAEVIYqBxdWf?s>*s$to?3%kEBnn7<4mh{n3nqNN#*}|dwHJ4&HUKq~X+jh&%cloo zy(pNY`VgaS#1k9xe>LL+9$V#WcPtC3LaZlXHZ5(C#Eu)|K;oN}dVlxkB%fKUr70H=KJH0*e#8w7Z zC0`zK&Mz+ATRmeHrbN18g;R0Y$uRA0xY9u3?-7fGPyT|k`l}Rj8SxZJdVrK#cFOD? zYgM{;nkUD79JyJ-?^Chm@Z2dqWVaPwHrtcCb=vgwErPNK{E5vS3~xmYCSX5s@1&&4X-FwipQT{Xg~MrrKB+dq9NWi%eGS|*Ow9B-&_CW+Wzc_NvpoiyV@pt*cFCwS zsysm>0W|=7hirsl6%MbtT`3i+y7*(|vOt@$U*J=s*ROGKE$kb%(6&bP7V7z49)=-; zgiXOAC3u*XbqWbKCW6ts4BG^5z^t%rx~`rWFc9M~26bSrV z12Mop{b$rDh@Lb5r<&p2zn`88mjwxPoDkAL@KzN8=|&W-T*vbStpQT z8)7(#Djytm^c0P;aCU~U{NXrPMWh6N+*n16&^3*pX z!2hRwjsBQ;Ln!`FaC~v838a`%eDh$H`Txb+I|fmvJn%7W@SDK9qlv?)y<8w?_2+U0F=>u>U;Zi?JwL{d)Zb9*%8^- z_?+jj8%0AH3FK7oY`9W6-GwW}WPd?WMa*CdP$*}PLTM=h>aLb=U!n>O;Wbwdv?9P?jDp(-sjHSA{bk zDkd0_yJjnANk@f5MIx6)S9wV&?k^@(0_#;uC_23?EFaxn>@FH&9)4rQ8);PdiBchS z*Nb7Y}bd^5q5sTBm{2i}Bzg*EizoG| zj>#wJ;2rRRTL|;m9ZoJKQi9gUN$53CFBdF+`n~>IGj1xG6^0V!YZV~sv|I831AEyT z+(vJA5D;J@9(xnL$a@!SlNL*uEA#^Y^O~G^)IUk#xJJ;xVs0QUNZ1!HqcdQv9xGI5 zZ*_lFpvwisD>w}Y%Oz*I`!rYIth2gLPcnNQ?AI-2k`#Q&NO}JqwPK5|jLMbhpdpZu zB>?U@2xj2+JH~VDYirR>)f!d4yMu^$-lS&ZtA;j9Pk<|DS8mAPrv|ZalSV4E_hZPNkpsemfGGN02rNQo) zTLQyu9BSYNxvKxw`U-3N8?RQ1w;b{l#;{@NODMK~fTPCiqYKoyL*)6cV$ zl_iE7QPV6LU+^`TpN?Of7fjQ4Z5FI^;(XeE0EI``otF z1O@70NY<*B3v?8aaVv1~u7+!rHoHIRe8|(m>1k&f0_lFYb~<@X-G!xTxTg&}Fu;+up@(8iqa!mzwRcy2^?i5;crYNb zOcwn5;Koha^JoY8Cu+z2iT*KJS`@pMBAV0}!5xPqrwv1!7E55e(4-~3`D!qnYE{mw zRY$B_ETS*bc)cs{>#!iFFBL%uZWil~OD|uX3TuUZeKR%#D5*r(U{9T`N$>bIVNGv@ z*9Hz7CP0y6&k{k#*X%pDFdWR`zDD0F9d%nl;52c$RuL5Dk&Dnk4Hg*1)Icn{&|!B}_e6KHg7$i&8}FI{buYs^fdU$hiW0Ft1XWYd zfR%%OBA zd8b=A$OGfkvwVNfdtZiBWJ9e()DTid!~j`}ir|jQQ@PZpWfmb+)aZm7)dn>Nd;^mX zD1J}+p85f0R)SQ^Wulx6^D(Xf=_KA|)@cqK{`uS}3d;@dscMF8i6=%=WLn+L*X=YDA zqJ)rDGCPDBU}@x#(VxgD=1C*cpyHY<5~W!&UsPB=L6i~EWY&cIN#WbHLn`1w!4~46 z#jP9jmM`e)|6v_KQy^GPABbBC*)2U@irpsX95_3q6w4Uqj3D72xhH+*IzC@0<_z4M1Zd3PAQ2(roZ}aYQu!rHQfCiU@+Q(V;i?Wy{olvCnxx>slthag4LeNrq zJ=}F)Q~^qnrQM;X)TYb?zOKut4%azCOQ{DdkBmJ-AG|0reJiER1hzjR)LHM6FbQE! z^w9@eC(dciF1^BptWC7bi(r9;?ib5VCfhueEfX|UYTRjN)eA*ByEQi86WHFbw{YkV zpe2f?6y>DD{K2icU$AV?>ooe66;-oPyhNIvxClrf5m7{AAD2fi7fMdQ&~W@W`TOv8 zf2ZL%t5v((MUsI0X7E``;%)e`PCjV6Wql+bQ=@qQ3enu-mS$3zacOjjq zMiyYOt#Q38a{DReTIjlZ^d5b(JtH*1txYqQBb$abf8W}g@%b>o>ot!U5S_1^ro>8y zqBS{zmCKauFQpd<&M^`D=(>6r>KexS;t8prnIc>Awu&O<80)Z3B9IhdE5RNJPt1)G z2p6_UqqddGBsDyh4`9xLv}UK#`C*DfjyvsJEnVk~Gu+)01f5Tu;7F{ z5^R3blP;6@hz;Np#6if3I27W8$tBxgcW^1wIye_}vrP!!f4*=XRlzkpS52bEU0XQ5 zFj6BBW6Ao5Y}SSqIQFm;W%&B~$T0Lp3*ytdR8@~LCTe`vSe~XhK*0<~F(uuBrryuz zRK+EC^W4G4W?fiEN5X3XS-LJ^%4KC9-~eqc(qCdBa&h6*)j^og#F18}{^=IB8c{eg z519O>W`H(oSRH1syIy6sIJ@F2$nO#j{G8GXBlYB))#@Vf+al3^zXZhBt9;d}c=hgO%=yK$7;sD15RUvoG=fE=P9JF$a)BJ^CumanM zEw7d(H|CK#ubVww4D>R{0^1%yXqD{n21aeq7P(Rr!gqDk0?x!p57wp1Y-f;Ch8u^7 z=p<8|05Lw?ibZ4SmP3bpGUU-VHVzypjC=v3hCj2hma^GpDZG|EEfF?7UrAABmbGY7 zyAMuz!8$~}l92zSN=8Cb%;JT#O-6Xn7?uj8@kA{AH$pKTrp`bFgI{gZZHyd<$zkR`%NynODM#~j@8K5VP^!U%_A-2uN0;vj+f`BObx+Dc9 z{=5L%24o0pF$i}gvgqwF9Nw!W&bO%;cAj-{F#|IDiw=lsIdb}PK+3?}%C)6(Vd|_l zNQMUU?%ayvk166Hm)``NIZtmqJlo61cRwI<5~Po%s1iNcu*&)b+HPlfj0W4JyH~h0 z;u#Ft|MYQ}4qDZzT|l-+;M+O77aI)tfpOE8%$LoZpHZ6xtqZSUE^xwi!)61>1`K~f zJJ@_OHo(wOlTyWQwlz&{eK!5ZE9gg{jQ&+3QZi&X$v_#bokjQCYG{gL;6e9G$o)ZX zGx?p(wc5>odUn2FyNnhPN(8pEHniP4wlC3M2_pZ7>g88T1XL-!Y#`If;6nCf zY72V)DfI*2AP$DPkL?yS;LfyT}o*Gp13T*@Ev(&fZFVo7j+3pvWK?#=9WNZP&o zs!XheI;>T@qCE_g%?B?kt&=}CEm(&I7pcr&%)NV|)ePM-WUEbYp}C?-%xwE4XZQDp zW1x-}4MSsVF5Z-@I5;N^&VPm-R6`?oA73;%*vO38z!MFs-M!TjEUf8S7FHp^ZQ&I6 zLwM28+si|Z-me5@pZne7HYY4*pwVo?h8Y8h%7jFz7yg_dD|3ks@AN)cc_vT_Io)L$)l-PM#Fe8D z#$ETcU8aAS+3#{mSB+MSQZuiI`_XC^XNE`+CI@{nb4ixxBMWhKwmW56I~26+;6}d^9Xk z3XT{nISMk-<3){`f72vhP;FZeNN>vq=03KwO)-@N`$5*iF5hi}kC;(B`s%Xlm z)O%Npodry6K+tk=kHGanL{69^!!>uU&Wpq4Z4y<4trs9Jhy89rxA6c+#f;W<{K_0~ z`TWj!ZRRwA-?PwTYs)jgdCX+6cAvODIN8EiqN|-&tZZC+XV>XGo~=*8 ziedi-@|CSIC@bt8z8ai@>6*5#>6Z*{f{O7P6^Q1Hog}3PdfLx6Qd|4pwG`+@pWaZ6 zf@nKlDd*Oec#tf4L;FEG;wY+M<-FeQ}7;$O-SKXX;j%1GVP zxZDB?;MJR6Vs_%_rXzj5T9$L8^!!AsZ*iQfftw~rEnQPCn=P_a8GPQeC0nniir(|M z_Ag<_{vzu+2+jcTtjg&PcZ((`Q~>OUIU}sv7$75|~AX%zd|x5hj~@ zsJRciECcJ}Iv}4-qM-$0UY{Tn>BK<+e%tmI;E29Ld8OA8EBY&?YPc8;z34Ge@rR1P zt|4kf!!Hp#aZ3nbq%th1U4GCkM*GNjE$X%iTQ(QT9??=g+AbRCtX+ibgaT8=p zuQiF-oFqurWt$?4s?&ZnPq3uDeklvbPsmFpIgz%e{LEPa783nk3o_*Zx8D-vL3LJp zGLbvC!WbhNa$wN223xUFvt(szHE2*yB4GO=vVKA3Exhpt@FJzmZ?z2axa(NHA#8Mn zon2|Z-fH*=f1;q9vao@n;!QcD`A~Wq-wNx=TD%~+m1Q#;G{j8>oY&xc+J8{sZ4|gD zvZlaVQ?I>cRt;_b;v^3bOnQQNJXqhM@N6^xb&Ct_Bo<6;5011ZtGcYbDIRKZ@0lNX z20+{5?=dB^Zl&BlFsv-iLJK8Mp=P?V8ukfBonb1wXWfwwca1=<C@yzf+iy%I)P*Q8*x47T{~pm&XAOq<{W8lwXwoYW@<)vJ+VpQ z!*Yt`VpF0s^EeAi3fa-1J#zzdlai$B?=Tc)GQH5Oyp;e*$$4^Ri)cRn$?wVpS@pj5=3 zq)v~GPYzBCN=|5EUn&Mr7AI-*1aQ={ZJa+XBPzIlLcOJ%Is;Yg1}UOVru8y-FYR?D z&7rLv$(&8pB&)t(#$n-}E9gMqn|k_|XkFb)bAuPX$b61;_PCinxo&MvY{PwyfU;_{ zNvr>~)Y&{(!+iPk0#wVFvB-ghmdXjAF=H#cez?&*a6|W54@aoUygHEm z0~NVVg0DjJf&tJ#SycAB*g)iNg7(E-yP{m7C|==q{uhb2q%RTuV0OBz-4kfp$LV^4 zo(e)m=2gj>>oj-dX17J^cW{o-NBL_1lq&aI$`UrRR7dFOx~#IE`J- z+IvpOooL9&lWP9oU>t#vERz4u!}D+W1{k{k;A_zRPqIM&p?&Ewh&@adF{-JJfTsL1y`_*`7yQ9_LPO#d2!PJ{{nn=A774(LQ! z@Y(-4%8JkWH*V_hQ4W0ee-;IsXMLJ|3%mYx1T*8Cmh-yXx?4x);T_#A(OTfZxa zDl*}7{Hw&@mH#&Ozdg-=5{;M{Ss1^Y{x_LNf3I_Naxm7nhJh3db5d20Ul&2-2E3BX z$t}Q&>WhA{l%#2=vHZbeij5S{%au0WyobU8O9|>A>*SNtS`aeG}mZFN2S$U~_v}pcpxkc75njnmk2_6Y!7iawv_A%q6 z^;x%U$98Fr+V*Z5Lv4nQ?tMM`{cN?_-Tmd9X2;p^`F8(2z|)~0V~dyEUE`z9RXJ3$ zy|+o{_LRio(gO>v-)WfR>#Ekpmmi0=o*mKxw9SAwHkc63pu_;yge7K(00lJdf;g3i zwi0&!hD;iCz)mZCET^T?lTuOR#+6orPBH;ytRpr9chd3je0`k@3w}o5954`O@AHs8 zKa(3Iiy_XA|*U4%d2H4s?zKuGP2+FYY>pCaIm6ylM z;LETEPp7Pz7Pef{#{7GoYQ_nIcxmB1^QwHk>*Z)w$>-*u@Y%@ z2K6J(*nDuw|1h88oaC5Yw8T*I;6m=c-Q&cVR*$e*yDv%LP+TwHB?*gay=YOT#{&l3 ze=*8zzN@sUlGCMgrJhd3*D9QvW}K+s_ZFV8y{J-!m%IWN&-@x=*Tu?gL`UPWvb4@& zWOR!<3z-GL50vUrn&J^iIk%qC$Z#=6G;mXGmGpQzze?!E*u36zsbS8jGZ-fAk@(XI zM(bqR7BYo|+CGBD8!tyia#?Ux*Bj(FQ%PowjJ)k7a!U@c3;Eb>a8=Ri{#>nGsI)wa zx4bG_Ww~d$bb^G*po*@Ma6$gh@mY*b4g}uA)Lnj=OfFXMPV0FS*F>{;)h0=2k?Vfg z)3`;fM=fzg;w3*JzqN*VRDBggy%Wz4{iQWm= z_}wSbykPRid?qV3v&(=FFHr~7tzyN_Yy*;ICQNjBY)3=fmqjTep^bWWq*9Dklt21# zpya~6s1D4N2BRvq5?nSV%ZS?;g=?^mPft}dKED;ASzuCg2HCg7BAi%GKN!?A9bT$d z%6P^OkPO1}9OJ~DvgqgXy{IZ+>?N})osHks_!pr##hje|wbGkop|2iiV_2Grp6Q^% zK?QFS;bWwjiY;pj?abh@X=e0L)kpj8ZNjibAhUtC2se`khF@CnZez&G8Ro)TwuKFr z@#5=CN^OdFB;3aphq&Wj$o^QnUDHw%!v%Rs#ATt0X1gw90(YR~a7M83-sqRvE)kDyRq?)Id35L-W zci$MBh;&wk^G?p+QF3_rAu4&GW-hk2<=T)9k10nlptSJdDZ8;bqR0H~`O!cB9GwJy zCZE_%j8VIpc3}WRwx(*-F7c$qrnisk%xUO`oO9G5Q(7_3Z!Id`llV%3Mo&+f`dp~@ zDA;63Xgw|fa|0o$WjjA`CV#PxvFKl`vXMeG?Z4S5M=Tg~FcKyPpbC`hXC)y-PvdhC znhk-u3?rIdb`n)ffxLoCgPCOA0I@ngJOA*TMWq^xM1r&}+WBFz&XE_LMVGFcWh+t7 zGt#i~B{Mll0kb}9`a>w@17YFBD&~b!w#w_)8ut?QBKvL7L~bmpyaHCWFmh&U z579WhmTC^I`ok^tYm|hnwy=`UGBZ|?gYDc}2{?@4Oed%$*l!~f)W~Sl1wPxt2;MwS z(@(k{!JOC3#2Lxl1!zcIWUw$g?~QXroziew@r??NI|KbT-dDP~JiXuZp7VsiZC*OF6%Fb^#|n5J8_WF6MSz zJF0`_Qh-wr_VWZKg@V&bJ10-}l5fer+m0C3;bWjds)cBJKPW&m4~;(MPwm^_sRL(J zfXDgi<-Vwxv%pN39i(p)(%`J5OhT(7S~~R&#ZcI?(VxXvm`jj*9 zbI(~2-aTHkG>K>#Q8Q&qALcvc%ym?f&TAj@okDXt2XO*mLdo>;?Q5lwnE4HaIfEx7 zJuA+SjbP5$1@wOiR`YU8Efqd4a+`Hh@(<0KV`qj>Fb|KrShb}eXc;9-J6$Q*+}j>u4|^5Y<9-bxeU7Fo&yHEynz6DoOoR z!0z@06dEQ!f|H0I&rUTh5CJ$`AM+)R% zMoSe|2cbwzpdj~f^)`8N5x}fmz(yAD;@Xw=f?MXB(LU@Gx@|#+@tPEvmhrT~lvoNj zu%nLkGA%uica#aBdLb(Ebg;#ZRAKS_OV%?2VI};$qc0jz3cU$;HVlU#^LK3_GM>;6 ze68#j(rV<@4Z%DY+KJW)zad~wOLq}r_FM{gg>|q8p|lE7=uoZ_<>hjD&M4WbXXYw0 z9iul{I@5fD#r}hhoh=^Wo~#nQcJQDHZ* zr;X?!-fyb<81CcZP-=Y3mOHgvYf4g7@o%&l=uf2d407v7o*Fw`Tu9_$(@YYg#;Q3D zgRCHdbKpXxDq)a-!Ui+N^m|&UkkR%nDTb_j2>MoU$hvYemr4bo+~fgpT3 zh+CV2&*BBs@f_4fJPKV25(o;WX=&guH3e(J?I zh05A*K%*6K)HgbLLE8+g`sq3d0NW7Q$#IGvrH-d`R(^PnO#GyV{R*k%EtTfNAH|!X ze=;VmJY(}Gya`ddeU2f17{DsPt#BpQX&Lq?khe`Z$(}YZ#wZlH!Uim{%$iCJb((An~oT|Za?qnY1acneUsTWvR7UJ#;!FU+2#nNMJ7b5EXX`3iB#?fy*UuO zj|2Q9T0UDFx(UO%HI&;u4cbz+XP1*MWYi}2_by;94YtC%2@1c=c8b>sn=%<0E71pJ z=k)V!WR!wJz?)(nwq&;G2OSZme%pkNj0C?B@9jD)x^}@l%MG@q>?bdm-b3Ee{2>on zCY|{S>r=uB(Z@^hv&{pOn&g1(lSvtC6sY-mx4i8k%WB=loCVzAsaQj(N2tQJ4e*;} zd4>>6zB)kshQrwIJnnn|XL45%-eey-Brj-4lJ=D-R_-Qa})A_P)B&;f9!T1~ddt?AHMdFmcii1xIpQ91GkiHt8$}k_#AB zRDIfMB+w4|G%Q>wWX>QB9jEl;G2WLDoc?TvyWvuqX=o=1c7B1_kEk-V2|bYsrO<)Q zv(XZ=Dzm0>C3?J6T>hfch#Jm|rkXfwvdJi861itMDg=UN_;B#FST?TpB0c@gXwh=Y zO`%Vavpl&0zqcf$X8t)UcW(n&xeu3CAXo2k8vMUiZ2r`KI_BVROtwvkB6`WtZKR zo-yc;ev#P;_yq2{awKAX7=0*CRW_k`slGEa3O{BDawlRq>I*tdNkL0dM|-dg+fU6d z58`5=tcry)YCD$W42JIh@@uOFY<_)tFoV9@o|El4D@sT5##6Bor9(^kyx-RH`}x71 zQ?P!@6q|G}g(h%q*E^Ff6Iv7YIdTDZttXwJ3S2@AJ{>^b?zP2c*`iksR2u zZ@DKPjd`a92=cFPXNlBrg<2u%xM{`l`WE-_C&@NDp~FlHf~F{qdZE?8%fFrFm65*l zC>CbyA~@y)HuR5j(IO75Xn=3+KXz;2z98uVt{LW;{&&^t-$0K4V+rXWmF2%AqHo88^!Kay&q@DLjhNW~l6d~ls!^iqdi?qjLe&`O zmp*P7a@gPwYqlH_>^0X?xO6c95Q{os3y??~CZY}>K_czk4hyadoF zzphLU&!*t0jmy)AA)kxGQ5^BzXz#o3R8#%7Ng@Pe!4EH_SaR`E#!-Q}>(2{Og;UdI zC^0E-uAP0r_uU5%mnUsLa&=o%hMOH(Da0IN{XGvJuZZevIFf1fz!-ixHZe1yr5CGH zze#%h^LeY!7LU8TkhcfAgPV_SU!Co4-=~vG-f5NdtsdFydm=7x(rm0aq&!@ANuH0h zID=r^fCU&J2sTK8x4ca5GXO&zy@S^{#^hLXr%v`_;?NCZWqSka>|;ZzM70&BKS?mBtSHx(VrHo6U!Qn6Z3mK|-J@4;6 zjT+Jp1vZK96djG9sMDYT(3x+{-M-B_-fqnroZ|rS568A!-QK^}I^MS23Ku$TEkJw& zCZx#|nE^f5s9>0q5}{U$elodmB@>!fl~OsBx7Xo&KDHzAdt^4SP&~(}g8JdTpb==w zUncU#P?wz>Mz*OeD1;gWn?3d1aaRO#jev42)R7dq9UZ38E7Ss$K}X`IC6=_=n*nTv zgMO3hmwgvS_8X3iO#Nxte|f{Bkd=5#3rPkN(@^CQP#LOXB)$fuB$ zHG|Ac993RC4@|>%m>Qs=m_I$6Oi?X`dhi#PI`kM$+X~Cd>=;?0mKIrAv+pXyLg$Ia z-PIo2xlH#8_EWmU(|GNcqm@Z|Dj|q>UrC--^c>Yt&MAkq!D|Al&{7Rcs3(-$j0O{x zBpXIh@-`Uav+UMNo1bmmb_|Z-kBS(lfAi9}Dek1=4GVTEZZ_sje%eV4nnw!QVL3lv zxH)P@Lyya|p>GQSLe!r91|(dy<|*(E4U`TSWU{`MC7b908E8Ohubx$}Z!&(V58%rA zf-(#l3Kac}2ekfnB`bDrZjpE3WsDhWrM{tSUjOL0Y8g0@s&G{cV<21(FU7~;5QpZn z424N3L&!?zcC7nOM6aX=snTfL7h93XjIbAT&|4Rd3edAd#|%k`9%|b7PBYMl(5)g^ zRfTKgd7623U>C@RVeV!!>j3lRn~EV&iZUl)=B9*%b!!B=E{91`11;n80bL@?cBE)s zz;^R%>`=~G58IgsWVk5olVYhZZE|*$Bh@a5F`@69P`W*VyG4I7=M|g)==d@h#`SS~ zXz^HBd)FOc$-j}be_*Uo4W(V%(`D`>HPTB2VMwCfLh6BRapa&JE$!?WxjLkPY*2T` zC7d%+v_uV`#{qDey6p`1x4fJ9jT*to&whpgOFfW32ftk8*M=_v+j@JXsXKy9UP1Ag z#x*IAo`Y@nj=tuD>^lt)7sA=behCT^O3K1dtVS@cT$R8f{(hSK0!XpgsyCy+nE-obG2zd-JwK$M7{@IN5}U)+9xIQsTryTUcj$PQXC zsP#)3btkQYjWVFLBv>zqvXHTfpry7|YL8&R&>ku%x#5%!(G#h#>Kk>9@y%{OW;>M} zPJ#iEsGRs=vSO;MqRU2U2U!x!TtZ$z1hHlJb=YkVl?SxZ)+C|*flEWks(mb{w#QP= zZ1lH8LLXO+hrT2422F}t56~4ucr4kx8vF;aT;9qXth66~T*`KEI;@62=L4VP=om#cI z?CF}n^v7tW&3vb#O0%~n_G^4nnj4bzN@}aMmSi=Fdnxwsr)-J)QAOnoKm^imS zpH{Ca@o-hVmbi(zn_WE@YwF>6Gm0cwBd&J{Fl@kt?JY9>Jv3~S^wnTN}gj9(ZO^D`j-+2m;ruSRE?*OiQxC66wanZI8(F99&fIq6KbX*2@ zs6oPq@MeqBLnhXF?MB28-8r5V;#vvt}${Wrl!u>G0>TEew5q zDaBXX?OoW~w+6WAZ-cxI_3nH7r8DcpSCONw+u9R1){?pGJTyh zv^0YrywZKvK-ph;>#i`{#*kID08hH?ty!Lh&<*Tk^D|KMTijIsfqoJnFTlBn(mA}8 z>X*_Zod;r{TGx+dqL~Sk-ePrL#1Vt{0NNv^LeiLpL>TmWX@o(n9IL<;(8EML&cbHT z+X8$BXCv23Zvr@`dA@5`ZWYByPWcR_gJ75r z?uOvkibTp)aoZ)Wl-<8d7m~*=UJIHEWUQS!_f|fA9ke{R0ffAshY1}h9`LdTE)c$U zJ1o*SnEg-aW_)+ZON>(Z@N0*$y~GaVm0nWEsUwZXddPt!8ebmVH@Wek1-7hcb0x-L$msAP+Hf+yP{9g+1Qs-B(2N2sdRP@I(|9pfX?4)_b@Qi)*dqJZw~=_FtTWpdLjj)L?ULV;H*AGk#$-It&a(Ca5`~Rkd&M^(E3Qt>WgE2C&#{e)7QOxr;!$D5t!rplkm)@_GBP z3~Zl>de4fQ{0cFzzZxkAF`tsKT{j0Emd!C2?331X%yVJC+(!Tn0cys?tg0x{Ddn0p zYFKUq%g%fug%x~8p3A>?90F*0N%i+d#iQY>FXHW>;Q#rsFqFfui-LQ;gGK;bY=M7Q zzX+9)GIfg*LfIb(Qqn`kJipieF4WaI+9}!9>U?><(=`3Z^TQVt`;!+7 zd(y}r4A&WWT86esQl}(t-KfBNvAj6K!`?j*b`_sArH zZXgFU#&bPi88pIx7|UDqAOj#|Gju~w_oQcKL7WKu5VCL!?`Ri|WE772U>^Kz>gBSj}x+^E3ZlHIrOb>@mP@{&*i)D3}?< zJtCw;RdK0(sjmlT-vYOAvq+}V_KUUY*Ud37h(|HEcwdiN{OciMgM^Ke}9$1r!rL=rG+bAb|Ty3Y_9LpovI zpHqTJnr1`b_g=e1v!7J7=$J52p>2b`ql2VJ)nZ+BJLg)&^fQIR*-(9*5hu=%A8L)^ z;2?_b3iCkSxlshDhQ<43Abmm3+%}}Dhg3O!?8^B(-VfjZ6rXu&11gP)0z16WAr_ekXt6cMNb7c6 zgRs3F3>Wt-NCJ>g%1OFN*kH!!HHI@%+!d~8`mVmWzNmiVqt~EPtN(XR0X7OK|#=jgU|D|dCBXRuS(=`4K`}jYy#rz+=Fzoo>!SMh0Z86^#8D@N@f8GCo z$Rghs9y?v>*dM!~f&8`8Nm6zcbhpldkfp;f@h2_2JTYtQva#S?eqGrd zo_;;f_RkmEKx?Kuf=Qs2jIZ%klgFn>zd#Jh8)*ppwqNe)!gk0XtFm&Zrqgf)`hYkP zCjcM2hZZg$iV)B$8R|ehpTzLR&@rzJh4OnZfS*y=b8rEkkR-WssUgRNYKQf$F~bD_ zDsc7FQzr<1NE==1ZNAk$Sv0DhNo>#eR6HM`U1o&VBl{!G-HG*_IF|W_QJwfILkgk$Gj~iw_>rB|p@fhr0=FN(^6w~U$zV4Z zb)Vf?rCBENrIdV9&5-Bak6l`|&iZS4COX*f(A@qSW`cecIOb%nyH*?yyN)Mu!ZD2W zxIcVehHR@gU-_tg;7+%Gw$!2hic}+dUaVx9_AK?D7L&{gb=-!%S!k$M_B60fALJskyG&jYC!Z znch@~50oUqueKD{7J{C4gZWOO#IHY^4G3tu&?Ytf% zuX$V+EQt5dPCp%+tEAr0+G=IO0NbzYejamFOt%`B1$?1q02{o@Mm|lb&Pe?n7A>XA zpp8Fk=6Uw$z}wh!uu=!QwaIDyG4ZO_f{QaKdd2j(E%JebI+sSkb@J86&%&v}^YLJ1 zQQV=7)*dttTX|KFQm~iN*$SdN`}_Rl(@%S~esoj4ndUB!PWGT7HdUOhuPM>K0AjIe zN)l-Sr4AtUL?FDl5P)N6D0{{DSWbm;>*38ft2%nb_fK@yKN(!$K_Uq9f?Rqc1T2)2 zVpuDj;ui&Bl;phJt*&!vOZ_Z0kDXV0FvmG>4osKgVm1|`>8+41ioDJwVlP9oCS3Wd zdPl3mUzh{(glhRa$aAZD13k&ztJ{DZB}j{#Re%4{cyJ(!k%oGM{W8~3PyUT6xA4*c zb2{@l(a^aL1zr3LW@Cc`*k;k9Qx)(gtuP31z-I`e_=R0yV~oPTC0fd7k7wpe3(8E{8WQ&&pbf zmb(G>8L%8?C;cvTPe|Z^hPb4=5os2O?iSn)rM4x1BIHt#)Ykzsc64w5wT0X!JOR$n zy^L{mu-GfNMie@$uqQ1Qn|w;HQ>hhIau)RBmPt{s_C}^nF($mNr>+~I5z32m0RWF- z=I&nHnA<8d+Iv6H)t#b{Zjt6JwiJYV?<6y4^o>~)Irzvds&j!niAh2p8i9bC;{I|2 zIZpKvi-=1qSQZapX3a(iBKw&dJ7{HPB2hcgJ#q87!WwD#v{GmOxh{MmA@5J;qLU&r zF-<6L%Cz#-PYCljLaL!AKCyF7n=Izd8@oi9Vt*dU)>SojJ&BbwqG@?RvCOBASm$CC#9Z0s^<0~;Rn4jAV#_9>pL3e!8!i=f1?j~mHS5ORhgUa(}@z3o@FgF{i zfM=I+c(Dn7DeIVnBR1PytJKt(!GmlCFLgQr!UK85Ac>WEMHNW&mO&|5atv~3NW+TQ z14JbHh;En|xl!PRE?t*zbLF+Q4VAUQhh<@bzlRbiY4&(x24?n3^U&QE@#B?JI69Ud zLKW7)KWM5xMkpNm4aQ!7X8I>aQ4xaRZRpbA%-CM1-rw& zWS6c(wI@;^=Wf$>hP`VAqjFDvM~q067|~lup<{)yQC=}S37^2+q-+Lt8LlK0#Kx*= zObUn@8FtAA_+g=76mw%x){>oQw$xlekdM{zNa!;P2%yuA(nYT^Y(Ia>g;z)h8H$7x z45Kquttl3cUSekR)`ytqz%;xPLesP^-ti66VOF20E-K>X>AGd4k6rO5q~ z<(e0Zsz|z5CGpia5XIeX*})p1KrJ-)z(L6PsPQubm!IbK<8hE-wsdlU!4l@pJq042 z>EDMy`CUDo_XU)G*(RT)mWc%`tr2QJ?{Fdgw!uOrmY=Ym+qKc*@%1@*dHW~L(+D2? zQH152`@QjJ17AR|F?0ga((oDO$Fg38oM}%!La0@1lE&To7>>ol^+FQd*%J;fbS4Gp z+v{hpp~xhueU8CM7+Qtc>6g_mi985DvPW&WlkD(aT77PUpu~jeLuRql+?6DwmaHAi zqpR>nr!}uT2$2?kDftjojXPk2wV0We5s4wIG zLvQ@qB?3q6LBbHW)o~*TSA5Ek0MdZ+CKz`@^9g4V@dSBK-b7ro3w)W0m|uJR;){xI}9*#hDFR>;o9 zGbC#VJ^QkgRYLG!IDx3dXfo(Iuv9qen*|J4O0A)h68fZN+$oEc7aNWS{BDDS*&%ds zqydX9^U-+p4X!1Zc{}V68q$Yh{!j`VNg!H~2gGqw_CiUYuz|=6$vnD|#4RqBqgzO@ zD{cBj4JtObRLnY*hAO|xFCu$9d{A2zfYw`NH6zKdEO^dt51)V<(?iF#(MC&w$vds7 z(fkn!!x~$^6R^eR*}Yb_{C7dIPa#ghSJjrFI^QMm-L$g5JL!TvxGEvTAYPgh6jt)Ge-N$!=wtq zBBj!k4oiWL%JTEuK~Jo-{;IXCR^t;Xen0`zM_=rv?RtqcvbrM6{BD;KzUQN?TsSFg zY-4Q(>JDPhk3cE2-0SE$Ph)HkI6^Ibfr$~XG+#_A{ez6f90Veh*(1-4$^HzRfHjFZ zV%NhmL-@rYoVXCId`RXFRyyx}YP3a0(4I~isN{dq_Rc}JHCx(m*|u%lwry*dZQHhO z?6Pg!Hg{nccA2-{^Y-c6-M1sY)6w7kFK1;&&XFT$t-0d2o@bu9?>GlphIQ4TI~2hC7v#g35o_ZQ~~pl zpjOP&)IK~>W!{ga$o9$*)PD}Dhb9xEw2?gAuZL$@}+ z^s4$CdhXjf)|K``?cQabaRW~X?ia$3dTBo|b6hW^M%gSA6ui-JwLPx2&%K{|T$Mef z6qoPTs_T^<>i`X+yN1eOUwR31e-MsBoPGPw;z>4DHh{C512Z>Upm`kiWj(_sB6$euFjzQ|EcZ`2`th4&Z*iyG{N_xe$jJ6WAb378O6sL*Y%YGS1 zyL%2XKzi0XbI<+>N4P>Q%@@IM<;iP1$h{vaUfaf}q9fT)oc=WnE!=&|HMe8yr;%4x zbH5zYw7Q2}T(PsI8vO^!$Ckp|49hE5@?F&vD5bS;c*ueLe&$?rhcO}#J>Lw+OknY% zz5gvWstvE{K42`r7q+F2iD~P zM}T&;cUe0vxTn*-(Da^g;4>kWbm0<2n6HS?qU#JisARb;%4~;5Cg9+NwA7EJpf2L! zJ`l>5axX>Hx6G8@UDR^a&f8OZRWaCLg|H#xK1NW97iIzNR!_s)5j)MvlR_|6BdJiia7X$%jUfxoB|NQ*#YZ zw_K7Fn>}EAI-TAg^d&4cp6_n{yDE3+tSKmr@)W`hm};tNQ7&XS;@bdWVbdTY>v5>(Ly^zx+(VddcixiN7LD$~T;AD9 zhIMod`pdX8*3xuHz81=~@of{nPx2@mkv##KB~=yBtzh4TliMvZ{_tIZ4Wr=$=9>cY zwq{p}2xpzP9bMCiq;VG1OV<;Nr?Wj==PEiC7#w^jtrD;V>yBD9+{yN}`eUX2;=>1+ zftL{zo$H(OlVnCzPJ=jPOmK^^xkh%H;g3leSD(I>iw?_)?=nBPZNKLe=z|{`K%PH{ zN-tjL_rbA%`5=OgNP!ePUyRhzvvQ@D-Ai)?sWOxM;{=AXW~SbNqCrJLDeyOIb`Y+R zN)caJl?AqKgUs$@u0SaGN%S%r;wBauQWdH0yz}wB4okQS^Cdzop!^cC{L%l+#o@zWDunF7R_G>M2dB%hRX*xyk(jvvj7eZ1U10 zW3C=X7OLup(mV2Ej23#V2nYR+-spkv?C`#)?+$PMrY@}QK*?`)2g&8dg6KXUt|bqX zq!t`9`che~;QKNvc@YD9cE>6WS5EzwgDY##or7!kq5IZwfIRWQ5wF|hT8U)yXOShN zf)Y5?ZDMKRAd!743QRvMv{m;nyjkaTA{R300gf4SRNI_k##-ejN1dcFO%}faJJzTN z_smc!;M_rv-`qJIU1doO77=?&oIC}GO^Jl8 z!HkSGiEFBK5?ZK>sw1q5f4I-?<$yonZSKpw*Cu( zWBf1Hw0|uR*x=ZwQC>7lfO|W*`+Z|2fpPj+jFcOPV$;V>vM+jBK75UdLcQ z$8zd-l62yCva%&=}!ON4GB(MHcdsq|0E@WmB1>=#qYD5 zNBt~1LJfjofH)7Kj2WlOoA#;03^8%Z=A@s*_x-qUdqwx~_&i=+KK!#7)%j}NqN53X zy}vkn^9%mKi;)xQJPH2j&ov*V=^3MryCKB>$oCJ+Dvju<28BS;-2|y4N=V|lc_hif z^=Wh_*%(pR;25d&z>&l-d!M@A3A*X&=tAE69B-FAykAZ)`&W0!FYq23pZR=X25|@n zpFOWHmM|=#6c+IoUOnO#IGSI1Il8;oUk-kGtq-4be`cnc?DpMlTD$47-}&Ubr!3t4 zYI#i-1&Tnp&_wE4>3jV>P955HeVlZqoAg)T-I?fIx-K z#?R&V4&LGUDCbqG++F1j{2G{&rfgz?0=`NStN6tlgGR-w)*4nyeid4NsiEHzBkt>H zaZW0CvCzla!B{-0yZZu_r}TcLSmtDGzqi%y^e%?COAmu%E-pb#N9ozKtD z8l)+cRfEEJjSOEK0&u7+PAJDMhq@KXr0RE)iNGXduW~2`skM#+gfK>mq8KD>n{t}M z)2aQB0xO81%H~?qr?DdJV1*LAN)`+hpV5h{no;{x=Y1T_Qzh@8ea@PS(MC@}eeQR_ zSC#xNWL5!o1_`&rm5Gu8fo?U}B?9?Z>BXiG-_%5R# zKBkRF&&Yo^>T5j-!003LC^xNUu$5NcB3E(LiU@uL?H_m>E-z>Oq}E)7ekV0yp>)e$ zcLYX|N@4}Zc8Q9ideikftG6eOrK}1)|Jm<&kj>!D>+Lo3`ZDy);1Q4wS7zOUkcrtt)-5=!YwwF%?7DdPZe>pGD-ROW?WgJ z&CsDKBWc$*TJucy;U3U4;+v>adUn$5VDT*qSG61UdviB~4P9(j)+%_@rw&6b-98#C z2(#BJ3Ko>hr@A^|I+bh}ShkxsE5@RFVy;W2Gw}(;K5ZZK2^=hFdLIY-C!29)wrvr57QN!-4h#^P_u$s zhcC-{KnST1=z-VVb=D-v$H0%8P|O`@Ib@IVcP9@TlSh4(0b>Zt+qxAgvfE z28y3iELohOd;=X2zS2q~;btBkUw3T!MDFA|rVrF*CJRFUsMXX%YWZSBYrzhmmtG`!X>E4`1G$7$&9 zq0MixQxUh&j;v7(OGnp3QitC|f>mz-$qXVL!|^X2$fOv002vkf#8Q^q6ciu@;*f!s zhN&?2u5}ckf2O_-cFe@iGw{m9Qm+yY^yP$2Y4&sqhF5?U1m@Vg?N9?9c(F#OLkeiG zqePB07zPXU0KA0@>jM9J*X|Z`6+_z6;^H0AdiDqWuK#mfQ#g#*Ct?Vpeyf00hL=NR zg^@dMBY+sKWIGT}x$bHuCbecHb)P!~Xaw;H1+1{h(`$bQADw9~hC8}JT+duo`rPV6 z&5@iCAvoMe?*XUtJLU&y^K^mA>Fog+;?zsQrdx@Bg9^DDqF~0g7^wPmzY7D=0642v zGf5~Zqnn(3Z z2_c3?zA+U0QjHSTt>{k@69f#wMgGE&0PySaxu@L4`A}+tbwX7IrQ)DYZj>8KJ-N5F zzn+HsDpa+{RGHr)Lr{>@r3VemSQukpRG$QGZ%w{xfigjbCy5SS>`FJR&SErAtgQdA zD4GnOy-pWCl8)z+6+m!wMw%1~g{h@-Y@rB8f< zK7U0}MFtYOZ@)K;R|y+NZwr#ObE(RCsa!kSJ0RexbSv21wDZ8#GpqWn93y57Zv?Gj zI#W)4s`edgzvvwdE1ew7G6b0n(vU{rd)8a)RaZ}}D+azyYZn&?;)?qo1ZaCt;_G3A z6okR1CS0mskxao%=n0hc>_MK3xsEgjT(Q=W0k9Li)jUu`7#De&T=cdzd=hH-C;fm4ntaMW(11rYu&UdFmSw9T znF+^1VE$C~p%eG>6vql+xj~bY80>uz0Z{BSjl5-rR7k`3-=T#Z8@OI+#IrkX9c)q6n!52fiTXK9T MMJ43ZQF$mzy_qkHHP@0}X@@L+4V)MA0M& zOF72>2+~RH$7qL)=PxfQGaU}NlPUx}&UuG*-wRd^wz(SSYcE*6)m-F>nRr{V3@A01 z5I4Lw3gU|%bjPrz0X!bwqA0%B1g2#uPeSOP=-^@26fa}Gk9L+NyT&|-C8i4-&G;ku zl8iW*9fGjCi)D9$G<6Va*Fy8Zx1N9RtX8yx^2($-W1Yv0O!N zTw4Y#xJ^M*q>M%B*z-07yF1mc{Klw8P=tC(h%8z#A{~hHCrFpk(s5n=-0EvqKUmh1;e5Ui z`_RzzC%UdwQe^;yEhKf0J2U2~HKaKvy5gqsjWsq{!<;L+`jpyzq)4PEI{_;Ua<#3w ziHEuTBAK5J6-^`l2uIR&tYC7HEWPW(tZZ&8q|WDfl~NMV>hc9CCfHIC^LdDFzM;Eb zfovIG$-!I=5L!>&5A@CxD0ooqwSwQ=HZiw#C1V=0DKF(a>QvN6t@G(@tUU9}R^N2Q zW{3F*`~Y8(cNH&9b8E1BAkFv{jn6b8gMZF5Hm~JSElow~^6|vECpy_o!)?KXIf)?Q z4*+K`K%W^;bj9{iy^uzOZ2D@pizDwE42^5s;1N`>&f=|nDEs(RbD{z7-Yo?ET8f6* zBvo>$mBg?!mxev+%_b$ltlnZXF;In-r7-UbSAtzZ9CDZbXsVH6Opd3(Z-|YW>z)Nd ziw!Z0e?##^)}_cx3Lo%sl%D#&%C?cGKBb-((@P^YB|!#;=IG~pbXDzuv_(qzuMTcp zV=o~dfFj}OrqT!{i6^p9F-VaRu3oTW!$0>vt>ezIOF||u?Wb}l+s-O3dqXIll4#bY znCbfc!M+|NzjXGUb2)G?BsaD1fBQLc>AKbmSH&V{?8PCh+e~b*~#e9mn07SjI->15-6gB=2sCNdd+4X4XG~2VxF~Y7ZO4#{) zxbBImh8C5Jvhx8ZFQ_-2o@{SP1CNGvbPa3gWSk#)vyuLJYM9z)fKQ>M^5ervFpIpR zT;OAr@}z3M>P-Wup0z0vn1WbtB%Q-svKb$);uhkpiVnzzy2Bm>WbmmM9aPYh7iqfa z;KI(E`B#^#BF1z|kl9Lx9%(y=(M|AGr_fa4(F5=2S3uUMDJ}bD0%7y&Wvx7ImQp+` zsODaj*NOp@10b3mu&-CKR!1r~X_UcEGHCon~#*>NM2CZH**>xx)j?WakIGbU6C5d8TgBt znFDPo7@g){08^RpvDTk_b`%E0lNv$G^>0Ci`pGJ{|5>ooOkLg@T z%Bknu6x?G&q0h~G{ksmuEKM0U6@+bjhd}QNtNq0`t%~m?A7G2H-ieo6BTa3g)&!`^ znboEYc7el!!1~$FZp9S(lb{E&9wVi%ahRJ#P;*wT+QO3hy1_DPZkkR(_lSWX34?Oi z!R($61?UiBm`Coh>;}w(N09p8fD_^Y3!2ikg~`FbTT9IO*?RWG!meQxI_{wciigC| zmhKoA?WzTV;FKPUL9-m=!Wa^F6Q2R42UKVD(r`iUMT;X>|3 zGv;no6KgRBGo6QRk*xZ4@rK>)!e0Xta_tsPO7H`?bCJ37o(H)L&2f{mV*&!lQ$GQm zMxtf8_jqkA8(B4mK6-IgZJw~BuFdj#t5-3eN#S(%^>bs5Q=W6kH2Q?A|N z7Q;?D0e}I#A+JmR8$k1)jamN*&@lb)0nL9hRQ+A5=>J$bi1D8qsDIZ;G5)i>(BH-{ z*1uIi|2K_a|G4M>1kn6XiU<97f+<*fvH!P_(EneshM9ozZa;^Eqx2lTu(W$pAl1rA#FL<@-GM|@@+EV6}g zK;WziyFL?oHM|k2aX*4`y3qlsvTm`zb>Hhh=Xf*H-PQdvDVvJ;sgGxizxRo|_1V_s zr~AR6UE@j3f3OJue2?8G2O(}i=j~75+Yvv@;J+r1vnxJ3*vIOZ+z5VbRqPFmOP@Sq z1R=cZpghtCpR)uFGhO8eGi{+r(e0+wtV?z+unfA$Ms8-{RyAXS8sc#J8eJLX*urTlW$}|V13WWIIF!`fvCRfBU%iFZ7;^J=9nq;+>v-*ZDM+{-O4*5-?f;L_V9rWSEfQH-C zm!7YC<2%S#Nb4l_!`Z$dDy6A>NF}w1djLj|T7`qA-RzGZs{164{`#{P`z^F}G^+U) zZ(=QofK|?pVMYXz002cZ3}ES>i#5ocDAh27A)rn?QWZ^D#odE?Kk4@B_?9%)Sy)-D z&RT$6H;xLor7r429>?Ou=W(y%Khaoq(nQI|AU$T!^Uec@)}9t5*8LWFHfV}f27{(C zPTJ~qp>KBMZ#QDgp}raqQS_bJRwe^=#w5ydFrpwa2ij)})G)vV}`d_?KaYtH0ckqoSzIF?BDAis}EThJxkn3ca#VL$RS!rkQL zxkF1@SX$K9#P^|?pHq*b1-k1YEE0vrrO%7>1lIi%>EDmTMu{Bt%JOPhxTU|JwstW0 zTLi3wO0%&d>Z=?kf1XxrWMe*WdIq3_J7$7PpSE~5>NKrG(2vrI^!aDac%~y=fY>V9 zg^=DLH-)8(?(&fk7P?E1Rb3nfP7Yk^GrhTV3D(smW3LW6{G$I{qNy!E(5w@#-e%-V zfHr7mra;kop5gD)!y#$5g$Vh3S##OJbW1$!@MZ<}eEl0V#yB^07d1Q;98}TAu2C{| zQU|{jLA5BbV32$DD84;b2xRT7tUv?No((L;TM$J`A}PI3sh#^m270gaplP0{q^e{; zN%+|;wguTJjcv!SE?d=1eY8BO5_iD7gEo2m!cHE{@(*8%`y}hmF7c$HaNwszbW6iN z)50N?R&>vyIF=^)i9{CfI$+i6nW z#d8ZrkF-}V-KKNhfb45`|D*Vk}>r)`oO(H{tOVgR`JOM{hv7E^;U)Z4b z)^Mb(jRO!)iwIsP8abAaDY9e}Zjl;ngkgGZ9~BH{L`18li$!DX8fq$hjOuF{m~Fo3 zvDdSuqU(4oi;cN2k|#TivC4lto!{mDG=inyqlF7;SzB_f1B|&*axUbFncR=#&`$$a zB(BIdN^gU$G{Zk8CFccqtfxB{k{fUuG;&s5+FepFC9eq&hptjg6|oH4NG73gh~-Zm z`?4}`H9j1ZLSeh+%C%t}+|8z3%Y@Qario@qLBD98`v{v>X2UE?*E;3t3?BSx7!iFGzvRzAY`WRQY#t!;-SBUtzgi(|1j z)g~C7Rk@ju1X57)T=iXnn*C^e?0Yb~p3y{~Ict}&TTI|2aw5t&l#~=%XOgn#r_#0v zp+)M?NN>h^zC?@~IxoF*&6n1f^Xh@Mc9jVJwS!BM_z}tloMgYGKT! z$!C?bj73=_8@GpQ@ju(nC^6#uTgGm8ohUk>Nqd|QvnoPhD2a*Z3jwl`mH+Mc@#))cq%>Dig%X)f?+ zD)4aVy?Y68y|sP$^mXy7#)@fCbl2GN{&enqE!piXZc{4b-*7O{_3QYo8`6Cg)OT^k zz88|W3-aOQ_2?xr)d7Gph_(blLF1TlBm~u?Ws_BpKfq|3Ys9r5qMqU&?Uyhn!P>ma zPL5u?bYRE2&mCI=JQ#&ciA@*_&CQkqn8xGo5g&3{V#XMdjFA?JC|Z>okmp9F(ql+p zQe`1BTx}{>uXEsl%9i6x&H~%sQLDaJrpwwaCB%@&GS%>y;wUWgAU2mjGaxR0R>>>G zLn~s8O1f4kP)gS)y3&viYRv1-$YXaaLW;T`A;EewUW{SY?0vqYT@Vu9Ij9`T3q@RX zZL>OSGU8vpGJ&fToOJgbQxRQ-%V5#6TBD&{9|DVB+dH*UJeNzGwoMJTyXem;;3)zv z0TQ9YYXqsG5sG_=ZPR^oWVtBYC?e$k1JJY9aiQ0^C5tp7mIl1njR6hYs;a z!V6XGLt{ybJ;vDKEhV+xb4_MWEE*oW@qJE3u&h46Iu}zj2{{h+Q1Gxc$W>DO0{vB? zAU~f#P(0yYF&^rKyMlZ^K$tr*#)SOrZ59?hs;H(9!@~z_^j9DEW?H;ZcU<{CMLhW$ z9&0nYCBNb%oF*&ea75((xsv1;2$c4j95>^y=@&O=AXcGTYV!zQ3q}qXZ`&j1h1!^f zy09rsLfyC1M;)|_F6)@`x#}d;3uF?QusHf^5jl$W4Bt1!GY0yI{!uHT^$S!+?^5#} zDDz5K>saU-yi5A%!5Q2dxXc5SyZL=~I*$?5jE;S6- zQ)P1&zQnKuvr@zywD)9O0GW3`px97DtPN@@7^*E_4^U|;qCIIZNrb&>whHX6ohKY} z`d1O6^<=Kk6pye`<~>IYqj*Agl$U`UGZIuG@wf`hRG4xUcQfwa{r8I;C!Rye=_r+G==o!Mi_^=3p%u38h>QCJ~XGEkBi z2$oDAf8J7f@vf1TB4?c5kI( zwFfY~gZzQ3>~2tg+?%&xNtqaS95WRzuLD(WhiGS5!w7;O0w3$~`LvZZhD@!qUOou~ zVzI0!vGw_AeKsO@=G`LL3%|JzWTmV~0H&b$h;w43(vwPZhn*9&40M3CQ zlSlP}IOx;9UA&4FQfo(-&QK2Ac$2AU`%899ocHqDL6j1yWvEx(W3y8kLRA6cCcFtR zTc|phwhX(i0hE!4V>j>Bh0k&P2fLX4VTr*oPdc5zPmdECH&^}NI6mkJ1u|lk0(}#y z7K1S>kw3?Af8$sr2N?tg)AgH}&II=TU7Y+a8&|U*9W0Ewoup3{P&S-+>4%q$LDAv?!2Pq8*?{K!Zg|yk9QXk zlk@X8Os7-5p6b_Jg3tQ2h&5hA7VjI1Ilg}+gCOe-$~tY_t({|A-h^o_z7INr$c)5_ zt2(}eW3<7}x7BS8fMFddTb}pWcf$|wER0(jRV5(>D~yw~Vx@DYl}1XkH`mkoQjiFn zC=Xu|Nvt%Xzw4T6uV)`fZ2UrpNrAzMP&(YJL``1VfKbtbDZ1V;Fk__D+Kzp%m) zb;C+8%5My*pj6k9HZiECS_BPP2CT4`W2YjSqt_E9>+t}GG zgLA4$cB{m#zS1x*)}?sPKHWgEz};&>xZO4+-BOilJ*54Tg7TmuWYwgC;C;k#rQA%s zf{QC>M6cV2coKC}_8GNE z-J8US50!XE5~dt@oYM9a%u3vwz5!37}IqV=l)orW(3Gpq{F^d z)4Up_nfNGvoRk7QzWDtm$T-p7LgtG!&~%u}V=>yxoY(Ccoc}Jx zx9DwBS8=s^!+D?yIJ+sWqce~|p8Qz$uJV_5h;fW3u|H--bpS43Q|9dp`A6#SK z+M)jhzL@{lvormLsQ#TN{fpp>>F@f`|G^x{^iQqQzk#oRUjE-xCjH}{{~qYSpiKIo zfUo~^)$DHy#!SHWx8Ufz%}T)ZH>CP*vk@@;4FbR0>;z1IYqb7#Qubdk*FQ4(Z|nRg z=3-}KV)<7vmv@@<%#{RUu=>q)|6yv4gW8G{s00C6IXDagaXzAag<;?0cyuLKO*C~u z>I^S#Z!gEOHz)0?evj|%B>uzeq+d^NRgCk8)5lv}ZC;P>XW~WeY8s33Jyo^-?#9?^ z@7H_#quXll$mDC+{qP{=>)@%~}+vO+aW7z5Io4RzX-oml1dX3}h#panC!^bah z;V_KF&cm6Hjn7x=wjY=-LL)j&wD=@zxUUx9`Mfc10r146ff_|hn3LA zPlK?JZ!@zQ$(!oi^`?{6LiDv?Q}`C^i(qtf&`XBYqJ8malY4owo8! z!;!XhJ;2x52-;ShQ&k0%fitb5M$Sc*LbBE2yH`VG`hQs%2} zCzvng)N0x+aM$7C%OK;!s0&66@UksLCm74^jI81*K6CyDHundD9(JuS`7 z_mhXmYaP#yH+e@beAV{`w9AaX3bsPQQ`@iyr_28dTx`be=Q}9_uhs0~iWM+z((fWf zxR7TSxSb0EHMK;H6Ed7yAcYq&8;! zN#}dl-Y;?EbVki=KbOX~$t-{N{3G^fRuj9m^vLB_loNQICbQafHKDs!q5DNWoew$3 ztE8s~rtetux)=M&Z*sed+_E#J4Yc&QT;_5+6Ro8}Ha4Y>{+xlwbv}(yMv^`ar46`q z+LzUzt`E~f?<-)))5lVc4Ku4ZkP@nVFY&tZ4($2mZA`bG5|zr1`g{9F7t);a-YFv7 zDW)#^i9Izmq?-Tk!soyue-kcZ!B(ojPZfIB!QcV4$+tu3vSp^i^QDwIO%q!+&vK9B zepJIqgO6n~8LoxLR=mBGCiJ$2Mjo9~oXzeYG>87ti#oD9=q3W!8QD!CS>8#?z!Ud7 z50-IiP36)kj~_8i=w0U?EpCoO z@OPIx$`){1X!rOh-#4MURY~-lzE4ZdCVwcu zM|?*EPk+VbvAa$TAL7CL47B6W42XJeOC62h(y(l%N9R* z{aDiQ_+GGH53#GufsOM(0m9B(K#^TtSyRCB*HPL(LjUYKo6XTG@2qCX)$1y-i!`f= z`a2mt(>)e@+tPp1yX5P}gbjOo-g)?2x^nCKv)`4{SA)c#>&l$FmAgJD8GQN-$hoA5 z(V+TW7JSbl0jNA%%&LmM6KcqZ&m&YOq1(^E_fo<@Pao$Zi&{~|mM?T{6Y|_lC4(1} zG;%bm{Qbm#Cy_-?=sfeoF8V_$J+I^xR3!m&xN?EJ^86@G=zRl~EUqBwJz+j9rd-2Q z`a2k&9VgY-BQNjnb*Mk1FSqwfx9_lC50In!K=YA{Mb}7yGGUR@TU8}?ALji`mnUJmzDhn(2!p~`0&)eNz@ zg2$_)hk2o=*2!-Xn-6N~Y4G|tz8PW}-ciyEYT;?VH<&yNYBn4px!*w?@8OQ7GG)S+ z%`s^k;*f?7x9x#48cNq!fiG_46MN&XU$EsHEz^d)yxzg?Ur6lM0isUYQvUT1 zO?(+&$8FBck3-K9O<4}CFGJ77?4+2I!4Tv@93<7#CXFDR zMao4JfqUeVPO5;7vlOZl2PaJw*3L*11{BtX<4Ji55P@roYRUnD0|K{R$s`&^S}*L0 z%jBqNN(7xt)Nd$xH21piFOixtZD|<;Cv6mVNXHRA{?NQp0#fo~AxK_{ummWYR!%cnfNBUXacPgi5l1RE z^mvCi=^#Cnwyt8Ue1n!;HxeEmQ>PKDZ4~CsF~xl5h{0M9OyU~9y5Fyp2?kk<(r+MX z68~oC&p=kJv~;5JbA+~D*aNqZIKefhNh3oEbhCaWh(@$wKFC=m=3H zBZ7u)%!tu80{8sFA2X?VpkRX_YPgNmb#4$)F+L;ARk|?iJ86CSg8;asQP(BR@Db0= zdVTo?1-Ticw#Lzs4w9Gg@ZeJ=W~Pn?y>Q=Y0QbOUAVPA*kyPfzZ4rTU+ydoN9?^i~ ztvSJuz&+80`OatjBnjKtfv)vm$rp&46rfXXkVNycls>w-9~9gN0B#mU)3%hhR?q{c zd0W_YGgo1m)uHanjf82? z4pP?$y1^vEk~?soL6ix7Yp|lk$)K4k#zQq|hQIUw!9j73MPF5D$xM^_Jyrl77^Wl| zJlb@KjpO^lGw@%PweC-xWIB^K1C}sRfCE=4J<1p}BBn__OkER%2Om;2BcpcR*sCLP zb%(_oC}&QX7W->s69jW`EHGAA_+lU?5J|j%kL<5z_jAE-?2Ajq85H zEu9%CqJonHYxTH|H2@^;BDIyK z!F@ch0fJ+RbAL^c4-OI$`91%ECb>aSv(^YqW9FiiSPsRoN9p)lmNkgvNHXFx4QCvr z;s_^SjJKUEB9+zw!r6j zMj&RQMY*56yI4D3Ng?sa#2^tCwg^gA-rwCqjv^3uOYR~NfX>!hirwR45aJL8h?qhU zgeHrT=dx@A5Pegy4Se#BUc6a9A1o|+$TN?nhU=q=A=X*)yuQ~TgK(rpQ6K$p!vpaU zOkNWr$mJO1WdVnbs^uHzJ=>+ykK5(09;_PxNdnw?d54ikP_Rr%ix}50f(|_~b&Mj6 zMv4YO`qF9qIq(56s8bnEwl2s3MofT7#QoFP<1N7L%p|RW>&C$#zyV4XN^^#uko+>k zyT`%y9x?$rauMCqM1+S*GuE}L*w!ID z1t2&{3bG0B4=AHXjH=TlgQ5uHGYF43$PlHBGb6rNA1)5zjg{e&h#|kIbNQV-JOq-g zpdo_dh!(^(6G9MT`r>17qzMo#w&{`Yy^ijR=f+)iN@Su%1~6^_EY24KGhk>R-+$nN zwFY6+glMS#hCH+dQv^n8d{{{_@h}iXjZ9Z0oFY?F62=XP1BgK6WwW?sC0++Cgx|UB z187RtMbI7W^f0KM$y3@Z8(r4Is+o0=VHL6d>tPfN7lYsctcA-rSd_VxJzVx1KD{Q_ zQibZRLYby5&0rb!db=A6Bkfyovm~D#(@r6fV{SMEecgXKIJzV)%wIlu1ZlWF4C3dc zOMx89O{P(cqJ^7yYNSaL`Lp~n9t{Woh$ihD3`c_}x5G_enew_mJwKiEny+_#9>(9^ zOXFK?qtpm%Z&GBi1~EwUI4lV4imJitN-4Se(4_YhJg=&{oG3Xg_kFmi%2Igh2s7z0AShd}BZ_0haitK@UG z)a5U)QFHSG`xM$3T9Dd5kE*RM`7nP%P-4B2-ECZ7By9p; zqAjXgGl71br=0A5{qq!vuMd`2zt4=sMqJ{g<3e$Vc+N8&tcWSn273~WQ%2}-;nxIw zc@5n;>A8v1;VAzrg;TG)mm7PSQ5a`d21j_EZC@7|bY9M3xM2Q0y$y>yySoE&N!Kfo zl5kk@4M|LV)OTk3{k`lWYIyei7+Pkt15ndlE zT%EnaP##@Q)W8e#@tTV)s`y*fhMm$U>#HOo?>3>IE|c!MfC{KDY~HtL6Z73r~i-F6~L z>~_van2lEwoX)$N-&BU3w4G|pt$WrX5PQA4;7c7^sn&W#x6UU#Y>jx%jy)hn4Z-<6 zo9NRWT9u`1=$lBGo4I%Op8*0ze)%pby{r##&#Lt=Fi%3rJL^ldfzPyoj7(1;e(jJNg%bR$QuKO zbdk}-C@Sas1d@+a^=16q45zT1iq>frbnAv2_ZJU@qT(r0pSwggRd?8LLQ~PP-jt;d zneVHj#w*c(!fW#96<9ClQn@t4gb2~EC&ia}*^VnLqk$V;b<;=f%zCLU8jy~gu9L~;C$%*IY`>9ABd0Xf^q z(kg8A(d>?z(oB!j(j_?QG-$B#jxBY3#2pvek}2ZcrmXSX#TyOA`t{H|L#kX$ukVx3 zQBJ%G7Hr|MxyzOH4#=1L1;wumUa)FfaYYd;oYsnPP@e5xQ)g_fT4{J6UhW`*)}WbX z@Dx8oa*e>4Fy9*satnuSCuSbrkKa9gJ@|Sv)KcZ0pgOF1oY(tHww{Z(HNiS~v$;#d zq~*Jvg=1eof6o=(7EUZV$#2uFb|QhaF;?tUyryN%4>CuraFRnkpmyN%unAwJcLF-d zVWx8rpY&~KYZfFujAFAB@Q+VRgzC9CxDYeaq?P5pjwq{S1r}p7DO^cGg=041;o)s1 zAKPoi+VPyf1v`Aj?yQ1^QLpd3B<~n}mzqhQ@ViF9lLx#5D>t>d$=f?(6%L zIQkt1r;U>t+k&KZh3B0YI3+lbbGZeu*8u6o)79b6J?N*s=uRTd}%jf3_^4Ko>dW;_PB zaUE;7k_r<%PiF>}`CP^eyRWUve=CQ3(=R_vI-!dA+E>z*Q02=*N)gA5zNCEIV!vyt z-n8G>PW(bTnF+-({=t`tc zx$6-iASn!njsn)2eE*S+fA=dFZ>vp(%C)4$k~DlsW;TN_t*71hy&nK829Pv|Gt`+5 zSJREE=23a`E8Nr>NEWQ|N#iqx4Kl3;KImj7_R_%NN0DI0WvHb|Nnc9ANLkvt98WjV zLkWny;+a@f#II>>UwFf_Ouv`PgjM3y&}4Bl(8aZu_DpYeXurCczep{kLPDg9nRP`RdFryM*5Eh zCH)FNN~hTet9l)Uq%zv!;oVa0xCaxat8*Qn6Ohvp1x#wsQ0`j@L@s=YL(6Wy_3#Q^ zwej=ZP!&NH3{FAw3$`Z0S%u2;UD?#CFQ;tB@|M9UEtoGp+j{Z>yIV>F2wvu<0;wF? z0_`Y$>lo=xecO#tHXCp!1<}B`eOerjD<<@!vc5~wYQd^7(JK@HIeU5hH}nXfIgwJe z6gJH%LSl%&BB4b*NpONRZ!)HYjFG>fA5=Tmha6AwKcZDGgy!|`*o&jvq1~Qo1CnXLx`OJ&WDL{T>#;#CcPG7)XHw!*=p2g zr&Wir-L3o?+G#NLYk*bdq?rB~uTO%?WM0%)SEAs@wgMF{Y38AWRgorDVEkBo-g&79N*uX9&B7A>50 zes6$R00 zS08_d>93dIqMJ2q)YA>Ps^sRIQxED?bwmA`elnRPd2~E>(LQ* zxNW<$YtAsQ?1+<^+nf9J@%Lz!F1TYanUVQ1J#=@*ltYiLYWbX=oKV%3R^t%|c zHJDVx8xq?q%4eFNN^qsYa!lb5=RFp3mdj6&Gq}schCc7ydu!`0Gd?RaF%!3Ed^m}d zFCKTkF>Y+es$(Y~^12KtP=1=ReKd94O6!Ay^L58p>^;3mZKc;8f77n){j5>fOk-iE zPOO@?Wc<`5+Ei6y#@;P=&Mp7E>3$}%#&o-ubLYT%_(h{y$KCtUf3QMP_(3J(v{%#0 zul0hcuX4LxTC(L?d7ah)Z_{$-$f@i7ph=8GHhvnY#eiu`gojnx+E&?}1$WN}RzmlI z=-}{`Av?>q-EUg4X$Ye6Wd9-14~!{YW|zeGXfeLmg5C{1-)8g;jh()LYiqdO-*xHP z%SoLUnfjmayRW+@rNi4TYGJbQK%d&Oy2_R3v7)Vw{h@c>4m(urH(+kv?!bXQ{f{@b z>P)ycuJmkE%?1W#P9dYBru!PlqPn2le6!&2NE@Mz|Dla_RabI@SNl~8_O{e?IDGtM zDWc$Z$(kFlLwfJ29Jo9Pn7Y|^VTJNB{K}S#-G{#zX&s)X$hvR^)9qMA+i5fQxQ|ay zYZ!`Zr}R%L>9Md8Gk?wCLkmE&w;t=fa6yeYQIl3jl;uw8rTj=>)Z^EB| z>(gd8^G$i5OFa!QYY#jO>JmDBkXn?-8Ny60IJVBVr9%6xZp^q=&$ScHwTLxj+lE~$ z7lKT&qwvwi6$i^FIBp!yjo*^ySH5wmdRr3&4PX6k7xBZzVg_Gyc0+EPK0S9|8gOkH zy6@Rz3vN}9T8!yk0C7yMD&DIvJNT@+KzkANdE>#_?MoV-4i4(EVnoMYQ|@hlWlaBk z>}=jJj)y&)hlKhu@EP*UeN5psi9o!z=e!;Vm=i^uf#Ky_x=ac$QT%2~dq0bgj>=?+n>^IYU^a%Q_TR8Sv zi*EY_{zps&FMY_BW7-ZI{K7T5uYT(>d3WeQw8W!#53n17ZKHwz z*f3zRhQ;Y}vvPG#@1D_t=rrB8Pgr1E=s>jGlH<;G0eem3F{Cg8fdK4cjcwk^+Pj-I z7K6crk;%X!5FjKiut!gGYR&-2y#<=(z!3-J3G|lu&!pypKp_%P$@fGglEMNh-&!M) z$YI{(ZQ0wJ_oDZl40yuvctW$9-gB?~hl<_|fC|74*WOaz8orkVa(Z)r&H3$v_oDZP zyo!5|UOk9F3iRHQ_acczX%={o-p|cl<2?sz_UhnG&6NPh=9<4M?bV?<7p1v`x5}?2 zzv@H%(ZRr70oR&U095*}g12h|zxU67_xL|o!S|>6Cr!K$>rZm8tXTtZm;Ri=+d=I_EUrGT(JE`xXTcQUXZ3*fBi>?uZzIoAzr znhrcbw6}imRU{6G0R%LeuQLOi!jo`VGH`3n8Zf`^?T*Bf2tY2NlI9^mB@%w@)1Iy? z0KS9&>Mpo$UB1PTXfp#bg}hBj+{S_oV8xU7JoB3_M1bD{=mvaoy_>plE?e15I zEzLt#OI4sAyp(aGo>v(Csu6Ya9=3`TS=8VFQmDa=8e(Jr(FEl0c2 z1C7o?v`rNVFoeAQ0YsQK;=^!X2`oRy!)X?M=bQW~4)u2u3J!xIhyC)xVTE}g#ZUXZ zOWO&hk3v4L-`%+Gz^+5tU839dlSc-NTC)x<<@gqDScw>48h%kaJw)DnLc3RE(=qXS z*sB-5kb-qDKfE6?7&uw;_wT-p)JLl3I=^17W?!u*r&zHe`TI`d`W z>!FY4)fe@Yv^VsudLLN{&Aiv?$Qk!K)F$)wd5isbmYr};pO$iU!m*_Ew|yXfD|19h zp0dxxBTpV#7iJA8pV}laKA0d|T^tcn<61BHbaTtV3&DD82weBi>{K@s` z9_9s|JN2R$Uz%;d{9!pY{=~)$rUjae%$yT&0`vjeMQPXb^vUq7OYF_mc=F|WtKM~) zBPkd~GGi5*yZGzvPL(|jH=AZ6(dWwyeG%j{8z0fe9|z?x?$U#L1Ud)*dh?;4?r9&} z$C!4EA|~#wTDPIk4$i!3P5GI3Hb7>~&6~PPRJS5szJGoE zsis#G-hCRr8^g;DUXXk1!kWvqQ$~DJg-l<)Y6_k)>_zLhuS4OFW5A_PM`X$tPM(>F zV8?8`=Bz#ePdu}Ags-WX<4b?gCet;&FL%n80K|?qml3RX5ZyV^mIK{8J-#UFaj=tg z(X}=U+V{?938ahjA_gXvxwp=^18Q})GBr>E46DW;rTwtBJlMVrAR4$OM`SLWV$ zT-ggqH(KrXX+Z-I^vj*UXhivgu*9}E-@tZ)#LvNl{Sdq+CD@7A_LU+R?-P_E8D+-r7Rmwxy9gh4y6k@uE; z^1s24jjPU#%SF~a?=X`VukE#EiLCk!sS6AL4x$lnc;XL@93gvF|5v-}8{mezGpxFf z=S3G@zt}dVZTX(i-FIsqzK-5KMsDd%Ua+G9olsq}ci4j9_|6B$?;DLjw08A_&1rY% zT`3QV7LQ&u&1a>DvMbXz>ge&{Pj4UX)W@>lAAlsPUX8kOT<))FzxCCI#9=QI;gh+; zGkc_u2I+eCx*H3=u(fPizSvjIr{+#=ndNEGpa~q7F?8(FDFGYr(wvjej5dT+mApTA zz57@Ozw2lHc;n4gSH;99@0M@A>A87i^&{SjLhQxP52TNJR2hn*lV%^Dbad#{&yynC z+@fADdNaE`wL>S+s&?BbksE{XVMpw5(SuOE$F?K^$_2sjJUSAt`;YxWsi6nSd-@uf0goW`wL9L&6*f^jgd)589Q;fM68CL?@ z9w1C)Z`V$&po9{;++C-+zH@z6E77!tq@n83SbgI8x<-D;nSi~-F{f3;TejmVi$5n5 zyPP1jShTpfWqYGCuIK<0QdqsT-vs-*#SbnVRQDOOfw#&>ux~l6(AuR&kWzt>1UXlJ z$zHm9Z2F7AY25n!V_+yfW!;T-<)8aKsK4LFC&^#0%^j7rXGrDD8`R3NQ~fDDE9`d@ z$}I+4BS{@+TjgxK{?wV!PTTu89`rpoFyQ{>zPDnU#&n!H^tvCM&q~VF@3?r&^=ZiU zH3Rmi3g*s#J6F;eHEPAC6nv@tkb2SZk8|#5!Wx8O!#*6{Ni$!|D4DilWCWB* zU#6&Mv`EaXV(lANTb+J)Q*qU(R-+ea$XUhY+v5O~bM8l?!e_R++KVi^g9lpj^v4ga+kcC8c5t03`FL8bZ`POX z3kK_V%!{liOJ}WJha#m9f#Rd(z+=ktM$lkNm%*J*L%{+d!eX>)xOap9Fqj!mogJRaLH=*8W}Q*$>X zuTt9F#0#y#35RxWxF;T|>HBv1gUzKqy5mCZoqLtUxDIzp?t2_kLEgb+oGGb&ap~B$ zwZwvR5c|CZ1pKDTl%~G!yviQ9uAdB^J_6t6#beT(Im#gL^aYU{^j{DI}nH=>D4n8#jc5XTD?%9#u61(`E1Y2OT@GKkT~qzQ?ll z(*_?%`tV_E-0+4sXRF&T*wz6|eleTzp*#M5Vrh5qpck{@Y0iQr(@&`q<=F|jYpVvl znIcCYI9SKZdO}2}O?a|+%Mc2o@Y9f{>ith|GU|i6OhzhuHS|AmyZdK=@7!N44*dfj z@zP!Yhw%s*Fr5J!t=GtJMhSRK7?p%?PI!P}iwCZI6A{?aquJE__W8SpFSC_wrKO}wAI zg$V$VYQ6@@u^4YjBCc6Lrg}jQkgK@{pd^_Dz$rlJO<3SBthst306&0>UJTHz%TI9R zE3N|CZdTq4gMgbL0X;zgdZPK-2Ds~HMZHY|1p=E(dv6PI6P+6XCyHiRVnDOe0{}>pgH8hA$lqYZjOGC-#Njcz+?GNc07h*8L?Pee zmj2vhKP{p7V?2lNCrV6-<#eJuHReV*fe;5{n_bBoU;Vvp8VAGEc2ZG z=R^|qzOzsI#}9ICU5Xjt(!E?>UbhfdGd;ZeIAR7aYwg(XoO4Nw{2R}ld-eq~x1&$P z_TFcf%1#{IYFRY0@yy-$^O6Ame$Tq4jY+9S+5DwN2F2E%S#g5w4LL9GQZ}K+wO@-q zzP$8!`09DGM{BlSoA>I(+qElkbojWC{ z>Hg<}SFf$!$X$n+ae3x-`0A&t)|{EUc3Jh7RMeJPA9s}IlnylWr*7V}Y)`ew<{5I? za4ej9I3wun;NZ{c!|KnETyiY=7=buzi5?bHvLt)S%AE13GLb1{M!H1Nc?MrX?K~q{ z)RC=E<&>Adafj|5zwK;YLxF70lU^6MKapP;TAg+oadrn$KD#!p_xU45r%;z`G1q*$ z>}Y>%V26VXT4#So+uH~Ac;~UT9kGYCAuRaeo$=F-%sSUEcGkEZ6RmXe{r#{8b^p!M zyFTM6pY9F(SaxNKzFM5yl9oxi`N$@GGrYH6XBt@5c4b4sB0B3@LW_{0g0hw?0(PF> z{0KdN=>DhEI?Y%=ORBic+YnL_2uw?7O=@+zV#98X-$aIwk3Xg{5fa}+Cf%SLWH_O_ z{rS>ER`B}zR(_qTE_KCz+suNn(yuV8ExPx+d=8u4+Y{y?XC?+ zE&4LJm+48C4&W0O6dk0r4ulR&DhUF~llzr5a!*~XyoGC7fgRXsAMEAssrxq9tUG#U zC)N4n_<$whnklVmHEsOLW;=tIJ_;dRfB>7v_vr!JwrAVE!*5Re&1$oEe~4g1Y?^%< z&DzRv3j0ZP$S$S&ClD{poN=jZTkg)TU);MNEq%GJ{Y~2Gl%lvj2VO2+`*d><#D7Oe zVmqwwsYPY&dQ|x-Kl+r~#>~y_+WzHC@D-=E+u;$X{%X&F$MHXw^`6(MV?G02HOA1d zQ`Hy!qR2-(6bF1)JGv*;eAG=G_E&J9Hv{TxuY=oI@9rSq84E6yC%uIS&T2yU+I4|k zT{<82q)YG&2*cB7OT+Fv#oe^>X(#sOJ>+_WX9cky9bEkRgdg&~@9xc)jP<>NXyCGuMKc+ZOVPs`;V)L9*~7YixYAdU zEMKwWC`8}q{m`SI@bztymMf2g=IcAD*yz=BrBjvrt@F}G^nP*rG1xPHVg8hMubDS5 zv}@GkrW~&BHllX&ReJ2`gvOz#YZm&?k9=j7$gfQ+5O+FJ^*N*mMO|sAs6LEZ1i2Is zstTN3IZCYk;%iDte9J=&M(k-@JhsMX@6DTju5&Z%Pai*V9seR(G^X#X&yYK^qLA@7 z)myw$C8dTB#v^?JHirWU5= zSP{AAUAG%YUfn|MVL{k!Zs_d8P6d5>oOAa~{|9GK1I@zKx47L8Zk|TCcjn#2SEWZ| z2JvlWPiOh5!jCw2?;7-Ez5kR!9f!1@FetJ^2!6z%tAw5r1sN5gOI=OFyYw-=JMhp@ z(@=bDaQt%-?6zOlV8PVt5i^gC+1F8n9dLU61Nk~vF5o5j)hNe*ThsfKQQj>2&$tG# zL;zj=@@DzfC@-4UUf8K$m#Ti9`f}zj-|@7S$_b(FPzZ9Qpw_x*Lo zvb%U7nd~}$wT!&EetUggW7GS+$-&^5;gQFv+?W2NM+Oc}+fwJA%}d)>=|A((l3v^r z=7gQF{=Fm4MCL4*{%Ga>oq1(}jy&n6MgCRpHD7Aa3Fg8U&-nP)I$KQM@`FcNcH_f4 zJ$EexGgCJ0ym$XSbnSzSB-gRNW43H~jI}6Eu9AsTCn{pQ$x~h?J#|4WysbBNFu8*eS^e59}xbYdcJ&GA{Odj~&q_1%0{m5ZPI>`UE7oN`VBoZoHV!Y}(VZA<%) zjSOz9A2GhV)5t`AzNnK9#AfneunE|d(WN2x2gp`E*)?$OuB1<_6mg2Rt+2KSAW&qqM}B0&F@4j%qL#2lgbxe1G45nTywhfD(vuAlN*R%W+e1mvgL~G zk#jeD^4ewlMpiwbzm;qyV-4_-Q`pB@#5_Ikf9@_QqOHno1$>TW_yZHgADCzbW`bX-|sY3(3eydR9+oGJ=)(?cy-qK(m@pIkPiDEU7613h8Wh^Y( zeO#q54Bo1`F+T7@eV@PsiK}W4_b3kPb%K$b);Qezu#TgV1nRixG22jIHeFi0Gn?99<&`btr}hTmcQ;5%|~eE)uw|N82N| z+^5KQb)WACaGsBHBOZp8nI26#)NMRJ?fDb3rbhSLlNsc|&}%gZ|I(Gd$r!wAB`htz z|BOSS*VMJ^>)xE1wnUx<8;l0}GE0 zeYkwy+I>}=&+V6%yq)u;ABWW7lbOCzcdD;-?|k#+sujz-A0M7DqbNaqka*$12HeGk z%xBTntF5>0j_x}Y*qsgCxqo|@!neiqHQg@ts;5=ss~gX)8&>U$UwP^N^oMcTWpx9t z3*mPMUO5}G9^QY`HUw?=)y6eTF8Vh_-lwIW8KStqZz=L!+Xrdu%U4!|sS6rUyYgIL6Mtvb~!opdEXz4_LWzZ+TWjMJrJFW0DpYuyk@oYTAiSy0*lH8S89Q_1ROd z#w^cTtcu?#bW9!?+fFTgc5BZvO8j;8gT|*p6K6I z;WZJ&Om1zwNUk5ZTpPIei(7KLSOSE%g$87&y4JUel z>d7B>*WNmFtMR@OP6IptJm^C!K$A3;?>u*DZAZ zrWz=9b`u*QBVk#%8M!eIF znAbA%)5S-;HXo=Xd!(oMM{YreZkchVmz1)~Ke4EN=9LdSZ}ga$XvyJ3Fe9G6ojTW?IY{!TlYDBJow^%fR}V=LBX*< zJd!_fFMf1AK&-HsOh%{CW&rlZ&I-eZedQ{Ip>@EFB`_8Hv!U^a=)0W$?qrEu=Qesx zp2RS>)6;y$55u4^UNcA_{4QfAhXE$m*XJx_iNmPh9wb^S1~?fx0Jp>99`Mih{@}p) zPqb&!<-5E}{5Kl>7ZbwXd;4$VF`U*4aL@yHy@I?TH zsbl~r0mL^V&=L`73Fo~{K;C@xY674!yq7^k1cI`769FL5G@k>S;4wf!63_x*jN<_9 zyvf@D4yb?vXyKI;0ndUre{%(R0F@B{`VS6JnFwqv<-HAH-vA&J&{1C10jH1mHi-DI z1Tt?QeD9aQ?^c`Di^_h<4{X zjmBnhHUQlpZ7TFQ0SAht*@a^I8L7Ecf#0ZIUpZZN9q=m6H=5i4a%(i8Q+H%s8R&&{{nQX2|w6EQCay8Iz(vym@g%PSKlRfysU{*uFl%3A28_c z-RJv`toq)tfY7b2frAHDBttcPk(Fxqg@Dj5#4FC}7m;id`cHSNRD8_?Ndo zyLP)wDpo$&fK({g%|Y<097I znA2x1Ofr7_bn2XfGF+9?It9 z=92WezK~Og!)o6m9)f0XXQ2*v(=F+BZdw@gu6hb{;poo2MpjVHPCmZrzS+1H`TTKi z)0(9f&M@A?raAL^cL^X|IFQooLjTN{-P%RatuN>Vd(rJ!%*r?SGl{uXeh0&b2eBW1 zB&*4Z=GNQ+!-Gr4apM;y$2izcq6-(0?qUih(Z_!A6_E;}+{$7m6GSn-1t}07^RJc7EqlAW((>w6hi!kAbVPXybLW!I zQ>?Xx;uVV6GnZ0wO=la%?88h+>+rULhFOT-IpbVRJKp4a+lN=Kh}K7L9A*$Ik7(~) zFHP!@G;IB@N=}7(iaQUxrt3vy?)?|pL&?)X+wHAWFn4>rcu?JYY^Ti7_R!g}8RvtR zC#JSIi%!Y?5am0HQ@#ER)i_kp>UQ|Zd*h0r;|Aun>ew~l)4ns84x~8sK0epN7Tl|u z*Y428M)15_ps7y+#$FgeTDhm~gWS=r*MwC}^v^5_YFn9;nUn;J9Kkwtv^~3F!KB3$ zf9NU5+*=144+*CvKCfJSl=qR_O4t5{(0@;xmin5gUeQzNccZ#2saK5&o!#@TyeHI9 zGJ4#bceUF$?_F_wphcQ)oTxha%GR~@s-^=A`?4ajlP{D93C8!2BM-bR?F2g8krFT% zWuk96YCb+FCYyK~H9G;1y!mM-Z~R1){)XKAwk+(!K}jgG!tZgq-@z-6ocgmRdySWR z1%Ih?zDNeauC(kt;Dg@4%p|fnaG)X-_1t1Nxb6d z_qsS^XGutD*I|eK12Y4s&)%|O#qOpTl?xU`94jwxS6X`iV9Sp+#qdR)I&WZ&-LM4T zp>xLL-1YYmv~;O^PS~EVtq!)m%Wli2Ml8Ldgstwl(!SxL;=$yS_MNKQ5vyuX9PE1S zz%0mE&#FXZ$lUx1b8D`ZeoFYZ{F(G z6+2FyeiirtLNJbAv~Z%1`gqWm+kTx(_D^_octkO#*Sx1pX5-=yi)UI(OL|bZ-uPU4 zvOocuIQIOtu46P6E!w(vZ{IpKr|Tw3p5bJz@9vxRK@CHzllp@@eoULvH+VE_BCsJ( zCnPEuIdE(jE_*`G5)Qc~y3>aCsx31=g%00;-X$pNI~j4wX}-08=8J`r)r9qN~A|EVLUh8+&W$ z8hptb^0YVIo?FiP^dyXcLJPNHXUk3K(GLYz9%I%58M>$o=~+lPH7@W?C3AkX=_G5kpv;XNV`-e^%g5mRKCVI6T|`c(P0 zm23lkFtv77J76~{?Xz=)kCW#_Jm0u%$aGzI{NN|E<+0CtrSGh``to$RVR40GOMfoU zT27$PJVt5YIJVcmyooN}H)H3ZA)Du2jT?GC``*I%s~?V))WKtV9Q#6kGyq<$vDlEy z0&OGeTZ_AZj+mF$W7l3%eD1lk=Y@`_504w)^p*Myol;SK!oNeyj7CpM9o9Cuw-oK!R+FZ*eGmZIuzm@qOY1fo!~4E#`VL%0ye|3Tlhb1E z7oSGSrI034(*xf|RGY^4???GIVcIkWH?3~+Z(Qx$gl`knZ{hpV3!B!@ZLFQurg7io zM%;`~&PjfQ=Dr_2x9L#XyDqcZ0@9Dwll&VygBruyHFlUB5YQM_8W1=!AgFO`=XbUc zzzuf(Xv?_Y0V-go{V*`U+df%g=tK#N%cT(6#%A2_wHn>VZy(g&bqc^58GyVMhWIJ01e-;Cez|}35`xxVSybm_<$7zfccbWw3&g@05{8Phy6SyK%pts zU=}-?%!~@R%Mnfk%1!5>#U5~EYylTVA?2uLxkL%qZFkFD#%K;KBRYqZkjr856Qs_x zL@omfB2%zXJ3NV*>(oh5DUsk9p$tQ3<;1wHOnWj)snMG45Sq|q(MDwI;?fI6XgF2p zq2tVq2uidjpXt_vTv4RtRHxQL6y~#x2`LIzL}scuTb&`!lL-hJDcM?yS?Nm7;X@pv zES`&ynvpQPJ3_{JdB@SE=IUlj2CZr2L#*CNnN8 zo|lttPLDtck_z={qzqGLmRsV8h81`eSY@s`%LKweqax|?QPD;|jt8~yq+o@u~43%g=o;p`V1BnkxilEQ5tA?LKY|;gG@E>H3U8~hHuxg z83`6LoUUgVYA`aUt1!wVL~^K^;_z&Fv>C3oWfW2cR*}`5oSdGJMR$swJTQn68;wbp z;vtDz8z&`;tcuJPxYe;jjWVACNh&bQI5|V&|1g@o57j#xMDQ-H`nLXr@YA%^|Lzd` zJI?6$^%uYpQ;{QVNft*G62-vi)h36QCC{PB8G>{NCYMQWaMffR36e?9Qp%x}0zS!LW?Jb=VEgeDOz1#9)gi7i^RcX z;*3mWqzli1#}Kk2=;2v$dRQXF8lDbLN(@iuT0t2xPdp&+_lqGXtX4im$m31D58mLWjOFo_PL0vn4)f}-slX)>Zfp-Ilf^pBG*Af$&&2}F<=TtL`_Re&A=ulWkEAznGr0Bo)1pbI`lMdib@}+WO+DJ zI+c-5$iqUd6i{}82^VQg<;SOGCqN?pI3T}IPZ9t~`(r@k zAqa_6>YXuIkCu!v>C>SYHJ>EWpbDr$Fe)5_pb1kVz(S1^2&})zQDV|c8kqpW-B*ucpSp*nQ4>e_{X6Iu_$=T9;yV=1`RiYV=#8^=r zlq#dq5jbI#G2LAt#TlcM@|+AuES@7H87v@yoUh8(WAL7QJ2HxA)N!*dHY*23NkNm7 zby3l51)LY3XGU_Q*@g&eG9D#CTJg!`ct(LEHbWB4Qh7l5aEjfSsKU!BkzhOB7?A_c z^CaoB3bjsf0#9YanQVG)d`f;)ngLEBK*fRty;vcaB1J?7DwFD#n}i@io{~Y1md24x z&?uQ*fWy!vNd-2zTdt<*xyj}XdL98xGDz|YqyIS6zR%DSyi*_F-+ez#qyFy>wXc-h zUxu1GJW`knOOD9QXTrmC87!XBg9VnQ@N5xk3SKYPMi9}8C{z;LAy;HMNeU(@A8lo0 z$xca-Dfr<@gj6L?$e}5q1P#^2=9?1)%y6jIW~LLtIo!CI^fa=D29>KFmI6fv zA8Dbo@s8{`lr|y3Q4p63B6!eIOkRf3sbcUW%!Nt$*|AZXu&k&UtzI3I0RtOF7`!eK zV-1fI8S{z8LNSgi#gihf@h}O7!3PV}AQ6M_NQR0tp;BXJG{@thhv(`A1s;{nC?iKj zhR0=-7C>4rRAx`;)J z=0}Ia^-3}!I#n!@bE)Rb67xFL_9L4s$erz4z3b-q!Q>khY3WM+k4 zq*JPm2oTrm5R(5m4!=*N6G+s*$Kg-&i2u9e@auHjFXK=}j;Dm1oe>tdJ2EfcqZEsc zGD-|YFXktSvlGOaWT-5{?X;7Thy;{6CRr~b3W=ihcq+%4XIFSYiDFky50n&_E6WlqYzCJmpQMy=1uhxX>WP+;Wo|Y~ZeT~prpnoJ zz7rJBw?lv*wgQ1!na7b5MeGb@yhWwcYY8HG20tl=tB=yFL`1&U;zorhq({I+IoXlA z_~>Lo6i1tuz)uEg*hXtUM2Aut&~#3`B3Z#iA;eL(47xSK6;8_1CS~PC^F=VV)t#2k zhNxn>LL4NUq&6`fk#a`9hNA=txY4xu6l5YpW(d!*gX7^lEY(K75&30ev)BF&MI zZIT;_Jdqn>VWvgGgi+3PX+m@g(>PrMSni!#2wGJ(az|7Q>h;9B_uA_0D#bz()q zx1s957cz3ik#rI+OMswxa5gzC++c*K%fj<`bkj*JNl06n3Y2@)05;Dt?EMl23Y_U><#&PK|R!p=bP9e1*P2%X> zC>AX%0gSL`WJRFjA{FXnv<@V&W`i@>98sDHhzA5fC5|T@X%z{LVr5LcCK3Yi7$Vhh zXCWmgnHAwkA!o<)^KdcZe1=jVM^i>2p>zs0b z`H3Q(l*l5{@o<=otXG4LsZwrKCc>Qxm1RSTAdwXhyk}BTi3%E794Ah4B~#O)Q>l7! zJdeZ6H#(I`HbGWofm&_IN{`Lv#)jwQI5bJpY_pP<2ZvzzG*F_EWkq5bN$_Y)9$KeP zicWT@gb@yEtihV0LmFI>$xx1okF;4$N%Z`fbcilqDTOM`BqB?v&0+AYNg!la92*EK zXd-E{WNvyiKADt4qNH;qNjOIq9m+2MiV;GttMp1Cp4+AVzBvHC(8hKuV*eIWgg?@N^a=4lR?Z1&|aO4jhAs zf_YFe8Ur{d#tE_{8DNoAmJSck4;LqC3HfkhCL~;}N!2kU*s!$1a4WvhoMIHfc{wR@ zXEXhR{HAJU&Jhox~ue0i9%$M=B6% zsL;aBvgZ-aun1hFi9s_-ayUkZ1ghpMqA8RlVmQ;Iwc!zJrY18bp8|5I!_&ajbRJG^ zkr-VzEQz8q2*R1kbf-2UHkx5cHl<-RlelRTWm=5OM9Iib&6U^{xw%MICJzRf{TxuF zG7S}JuweC04uvj-$0cM&IFp4AzDw-lWW};1aEF$ju5j_`W=xu}Alfd~%50`Y6T^(l zCxfw3P&U2rkKg9+NRdnhJl@}bi@qa8uXp>0@VlWO7x!bwk>97x(vxaD zU%#WN2(#J@2f|Zmz#22lEudpe(UHO^1J^=P=9mmb2tH3ki6om*j5Mu+CreFFW(rmI zLNQ%KW9LJKFewN|W)>D^XG>zqSQtNDtrTSfj4!_D%4|F$x`ZzEOhXIYj7ML|LMyV}5h86?Oz{AZ2NDjy7 z&Wxfl3nM*FoXZuHu0 zqo(Vp3ajQb=;K(vgzvP%8`KJSa1jR3Zx(dY%O5R3JIAs3Qe66FNCSNSe@7a<6*Ns#(0o9 z2@QiM>v)Bc4x2Ge&UT6-Xhh)mNCixK5JU(HQH!L|Brv)%TrOb>GGdbW(F8;SQ;iVE znf1bSdIU&Nz~#m1VpW9{xTR2l1k3+8(!OKDEWlgNwdEN58*{>d7%P1(2BSEc2~aTr zy2jU;fhXDV+cXWNVV!n>FuOJXu$J%`1Yn=dB z!~4n0U0@Y@yfI(?LHq%TCO^zCU{~(K9JZHW1Y^en!A-CjED$7#h{qDV+lhbMXNhMV z5N7Oe$ko}*#xRR5j4PBF4Y6T~HeLPzm&FxUXbR)zuFY+9+JMk4-sxZT z2;*`%9H1(I;ge@H06|@V^F)t37YJkn`*w-tH0r#8ZJIv=MePHcz4}1L<}1MB$$zQf z*P2|-wE|l9D|7<=1T^6VBj3K@{hdZrAi#71kP;Bu>DwQ$iIJDxVG0DM>VQAs=N$)h zr1vk(_CrSSa;Schd8t0X$jDwA#ji5pt@oP@@1=VDqdpQA5Abb%l@WexgM{@GntsVg z!eId8`k(ay>!g3xnM5K0gs5Nhd87XPQ%1&kBS!ryqjh5;$|!j9Z)GV2B7lm2$w#07s}6pV z0bTH0K44w#Z}}(~fJpXBSt=FaO8rwt#gKoOVKKl`jMhbOCbGc z8^G)2H=QYDVA1}s`F?+vR4M`Jkzevry(G7P$h>R%0iN2gGAsZ&f0dDc9g{#=3b69# zmwZ?+J?}Rez_j~SMgfR+zsPXFp!`in@GiFT{(XPGK*R#?8|a4&SXvJRr*a0y#R2b1 z%Rs=xMg@L4*jaISoQ`P38E`rh9*5UqOjLtTpJOx`aYhP}O2p{n|Kl8L;C%?hr_wpy R%`ZbN86OxG#StV0{(pRYqKN. + + +2. Creating the IKE_SA + +2.1. SPI values in IKE_SA_INIT exchange + + Normal IKE messages include the initiator's and responder's SPIs, + both of which are non-zero, in the IKE header. However, there are + some corner cases where the IKEv2 specification is not fully + consistent about what values should be used. + + First, Section 3.1 says that the Responder's SPI "...MUST NOT be zero + in any other message" (than the first message of the IKE_SA_INIT + exchange). However, the figure in Section 2.6 shows the second + IKE_SA_INIT message as "HDR(A,0), N(COOKIE)", contradicting the text + in 3.1. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 4] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Since the responder's SPI identifies security-related state held by + the responder, and in this case no state is created, sending a zero + value seems reasonable. + + Second, in addition to cookies, there are several other cases when + the IKE_SA_INIT exchange does not result in the creation of an IKE_SA + (for instance, INVALID_KE_PAYLOAD or NO_PROPOSAL_CHOSEN). What + responder SPI value should be used in the IKE_SA_INIT response in + this case? + + Since the IKE_SA_INIT request always has a zero responder SPI, the + value will not be actually used by the initiator. Thus, we think + sending a zero value is correct also in this case. + + If the responder sends a non-zero responder SPI, the initiator should + not reject the response only for that reason. However, when retrying + the IKE_SA_INIT request, the initiator will use a zero responder SPI, + as described in Section 3.1: "Responder's SPI [...] This value MUST + be zero in the first message of an IKE Initial Exchange (including + repeats of that message including a cookie) [...]". We believe the + intent was to cover repeats of that message due to other reasons, + such as INVALID_KE_PAYLOAD, as well. + + (References: "INVALID_KE_PAYLOAD and clarifications document" thread, + Sep-Oct 2005.) + +2.2. Message IDs for IKE_SA_INIT messages + + The Message ID for IKE_SA_INIT messages is always zero. This + includes retries of the message due to responses such as COOKIE and + INVALID_KE_PAYLOAD. + + This is because Message IDs are part of the IKE_SA state, and when + the responder replies to IKE_SA_INIT request with N(COOKIE) or + N(INVALID_KE_PAYLOAD), the responder does not allocate any state. + + (References: "Question about N(COOKIE) and N(INVALID_KE_PAYLOAD) + combination" thread, Oct 2004. Tero Kivinen's mail "Comments of + draft-eronen-ipsec-ikev2-clarifications-02.txt", 2005-04-05.) + +2.3. Retransmissions of IKE_SA_INIT requests + + When a responder receives an IKE_SA_INIT request, it has to determine + whether the packet is a retransmission belonging to an existing + "half-open" IKE_SA (in which case the responder retransmits the same + response), or a new request (in which case the responder creates a + new IKE_SA and sends a fresh response). + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 5] + +Internet-Draft IKEv2 Clarifications February 2006 + + + The specification does not describe in detail how this determination + is done. In particular, it is not sufficient to use the initiator's + SPI and/or IP address for this purpose: two different peers behind a + single NAT could choose the same initiator SPI (and the probability + of this happening is not necessarily small, since IKEv2 does not + require SPIs to be chosen randomly). Instead, the responder should + do the IKE_SA lookup using the whole packet or its hash (or at the + minimum, the Ni payload which is always chosen randomly). + + For all other packets than IKE_SA_INIT requests, looking up right + IKE_SA is of course done based on the the recipient's SPI (either the + initiator or responder SPI depending on the value of the Initiator + bit in the IKE header). + +2.4. Interaction of COOKIE and INVALID_KE_PAYLOAD + + There are two common reasons why the initiator may have to retry the + IKE_SA_INIT exchange: the responder requests a cookie or wants a + different Diffie-Hellman group than was included in the KEi payload. + Both of these cases are quite simple alone, but it is not totally + obvious what happens when they occur at the same time, that is, the + IKE_SA_INIT exchange is retried several times. + + The main question seems to be the following: if the initiator + receives a cookie from the responder, should it include the cookie in + only the next retry of the IKE_SA_INIT request, or in all subsequent + retries as well? Section 3.10.1 says that: + + "This notification MUST be included in an IKE_SA_INIT request + retry if a COOKIE notification was included in the initial + response." + + This could be interpreted as saying that when a cookie is received in + the initial response, it is included in all retries. On the other + hand, Section 2.6 says that: + + "Initiators who receive such responses MUST retry the + IKE_SA_INIT with a Notify payload of type COOKIE containing + the responder supplied cookie data as the first payload and + all other payloads unchanged." + + Including the same cookie in later retries makes sense only if the + "all other payloads unchanged" restriction applies only to the first + retry, but not to subsequent retries. + + It seems that both interpretations can peacefully co-exist. If the + initiator includes the cookie only in the next retry, one additional + roundtrip may be needed in some cases: + + + +Eronen & Hoffman Expires August 6, 2006 [Page 6] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + <-- HDR(A,0), N(COOKIE) + HDR(A,0), N(COOKIE), SAi1, KEi, Ni --> + <-- HDR(A,0), N(INVALID_KE_PAYLOAD) + HDR(A,0), SAi1, KEi', Ni --> + <-- HDR(A,0), N(COOKIE') + HDR(A,0), N(COOKIE'), SAi1, KEi',Ni --> + <-- HDR(A,B), SAr1, KEr, Nr + + An additional roundtrip is needed also if the initiator includes the + cookie in all retries, but the responder does not support this. For + instance, if the responder includes the SAi1 and KEi payloads in + cookie calculation, it will reject the request by sending a new + cookie (see also Section 2.5 of this document for more text about + invalid cookies): + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + <-- HDR(A,0), N(COOKIE) + HDR(A,0), N(COOKIE), SAi1, KEi, Ni --> + <-- HDR(A,0), N(INVALID_KE_PAYLOAD) + HDR(A,0), N(COOKIE), SAi1, KEi', Ni --> + <-- HDR(A,0), N(COOKIE') + HDR(A,0), N(COOKIE'), SAi1, KEi',Ni --> + <-- HDR(A,B), SAr1, KEr, Nr + + If both peers support including the cookie in all retries, a slightly + shorter exchange can happen: + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + <-- HDR(A,0), N(COOKIE) + HDR(A,0), N(COOKIE), SAi1, KEi, Ni --> + <-- HDR(A,0), N(INVALID_KE_PAYLOAD) + HDR(A,0), N(COOKIE), SAi1, KEi', Ni --> + <-- HDR(A,B), SAr1, KEr, Nr + + This document recommends that implementations should support this + shorter exchange, but it must not be assumed the other peer also + supports this. + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 7] + +Internet-Draft IKEv2 Clarifications February 2006 + + + In theory, even this exchange has one unnecessary roundtrip, as both + the cookie and Diffie-Hellman group could be checked at the same + time: + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + <-- HDR(A,0), N(COOKIE), + N(INVALID_KE_PAYLOAD) + HDR(A,0), N(COOKIE), SAi1, KEi',Ni --> + <-- HDR(A,B), SAr1, KEr, Nr + + However, it is clear that this case is not allowed by the text in + Section 2.6, since "all other payloads" clearly includes the KEi + payload as well. + + (References: "INVALID_KE_PAYLOAD and clarifications document" thread, + Sep-Oct 2005.) + +2.5. Invalid cookies + + There has been some confusion what should be done when an IKE_SA_INIT + request containing an invalid cookie is received ("invalid" in the + sense that its contents do not match the value expected by the + responder). + + The correct action is to ignore the cookie, and process the message + as if no cookie had been included (usually this means sending a + response containing a new cookie). This is shown in Section 2.6 when + it says "The responder in that case MAY reject the message by sending + another response with a new cookie [...]". + + Other possible actions, such as ignoring the whole request (or even + all requests from this IP address for some time), create strange + failure modes even in the absence of any malicious attackers, and do + not provide any additional protection against DoS attacks. + + (References: "Invalid Cookie" thread, Sep-Oct 2005.) + + +3. Authentication + +3.1. Data included in AUTH payload calculation + + Section 2.15 describes how the AUTH payloads are calculated; this + calculation involves values prf(SK_pi,IDi') and prf(SK_pr,IDr'). The + text describes the method in words, but does not give clear + definitions of what is signed or MACed. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 8] + +Internet-Draft IKEv2 Clarifications February 2006 + + + The initiator's signed octets can be described as: + + InitiatorSignedOctets = RealMessage1 | NonceRData | MACedIDForI + GenIKEHDR = [ four octets 0 if using port 4500 ] | RealIKEHDR + RealIKEHDR = SPIi | SPIr | . . . | Length + RealMessage1 = RealIKEHDR | RestOfMessage1 + NonceRPayload = PayloadHeader | NonceRData + InitiatorIDPayload = PayloadHeader | RestOfIDPayload + RestOfInitIDPayload = IDType | RESERVED | InitIDData + MACedIDForI = prf(SK_pi, RestOfInitIDPayload) + + The responder's signed octets can be described as: + + ResponderSignedOctets = RealMessage2 | NonceIData | MACedIDForR + GenIKEHDR = [ four octets 0 if using port 4500 ] | RealIKEHDR + RealIKEHDR = SPIi | SPIr | . . . | Length + RealMessage2 = RealIKEHDR | RestOfMessage2 + NonceIPayload = PayloadHeader | NonceIData + ResponderIDPayload = PayloadHeader | RestOfIDPayload + RestOfRespIDPayload = IDType | RESERVED | InitIDData + MACedIDForR = prf(SK_pr, RestOfRespIDPayload) + +3.2. Hash function for RSA signatures + + Section 3.8 says that RSA digital signature is "Computed as specified + in section 2.15 using an RSA private key over a PKCS#1 padded hash." + + Unlike IKEv1, IKEv2 does not negotiate a hash function for the + IKE_SA. The algorithm for signatures is selected by the signing + party who, in general, may not know beforehand what algorithms the + verifying party supports. Furthermore, [IKEv2ALG] does not say what + algorithms implementations are required or recommended to support. + This clearly has a potential for causing interoperability problems, + since authentication will fail if the signing party selects an + algorithm that is not supported by the verifying party, or not + acceptable according to the verifying party's policy. + + This document recommends that all implementations support SHA-1, and + use SHA-1 as the default hash function when generating the + signatures, unless there are good reasons (such as explicit manual + configuration) to believe that the other end supports something else. + + Note that hash function collision attacks are not important for the + AUTH payloads, since they are not intended for third-party + verification, and the data includes fresh nonces. See [HashUse] for + more discussion about hash function attacks and IPsec. + + Another semi-reasonable choice would be to use the hash function that + + + +Eronen & Hoffman Expires August 6, 2006 [Page 9] + +Internet-Draft IKEv2 Clarifications February 2006 + + + was used by the CA when signing the peer certificate. However, this + does not guarantee that the IKEv2 peer would be able to validate the + AUTH payload, since it does not necessarily check the certificate + signature. The peer could be configured with a fingerprint of the + certificate, or certificate validation could be performed by an + external entity using [SCVP]. Furthermore, not all CERT payloads + types include a signature, and the certificate could be signed with + some other algorithm than RSA. + + Note that unlike IKEv1, IKEv2 uses the PKCS#1 v1.5 [PKCS1v20] + signature encoding method (see next section for details), which + includes the algorithm identifier for the hash algorithm. Thus, when + the verifying party receives the AUTH payload it can at least + determine which hash function was used. + + (References: Magnus Alstrom's mail "RE:", 2005-01-03. Pasi Eronen's + reply, 2005-01-04. Tero Kivinen's reply, 2005-01-04. "First draft + of IKEv2.1" thread, Dec 2005/Jan 2006.) + +3.3. Encoding method for RSA signatures + + Section 3.8 says that the RSA digital signature is "Computed as + specified in section 2.15 using an RSA private key over a PKCS#1 + padded hash." + + The PKCS#1 specification [PKCS1v21] defines two different encoding + methods (ways of "padding the hash") for signatures. However, the + Internet-Draft approved by the IESG had a reference to the older + PKCS#1 v2.0 [PKCS1v20]. That version has only one encoding method + for signatures (EMSA-PKCS1-v1_5), and thus there is no ambiguity. + + Note that this encoding method is different from the encoding method + used in IKEv1. If future revisions of IKEv2 provide support for + other encoding methods (such as EMSA-PSS), they will be given new + Auth Method numbers. + + (References: Pasi Eronen's mail "RE:", 2005-01-04.) + +3.4. Identification type for EAP + + Section 3.5 defines several different types for identification + payloads, including, e.g., ID_FQDN, ID_RFC822_ADDR, and ID_KEY_ID. + EAP [EAP] does not mandate the use of any particular type of + identifier, but often EAP is used with Network Access Identifiers + (NAIs) defined in [NAI]. Although NAIs look a bit like email + addresses (e.g., "joe@example.com"), the syntax is not exactly the + same as the syntax of email address in [RFC822]. This raises the + question of which identification type should be used. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 10] + +Internet-Draft IKEv2 Clarifications February 2006 + + + This document recommends that ID_RFC822_ADDR identification type is + used for those NAIs that include the realm component. Therefore, + responder implementations should not attempt to verify that the + contents actually conform to the exact syntax given in [RFC822] or + [RFC2822], but instead should accept any reasonable looking NAI. + + For NAIs that do not include the realm component, this document + recommends using the ID_KEY_ID identification type. + + (References: "need your help on this IKEv2/i18n/EAP issue" and "IKEv2 + identifier issue with EAP" threads, Aug 2004.) + +3.5. Identity for policy lookups when using EAP + + When the initiator authentication uses EAP, it is possible that the + contents of the IDi payload is used only for AAA routing purposes and + selecting which EAP method to use. This value may be different from + the identity authenticated by the EAP method (see [EAP], Sections 5.1 + and 7.3). + + It is important that policy lookups and access control decisions use + the actual authenticated identity. Often the EAP server is + implemented in a separate AAA server that communicates with the IKEv2 + responder using, e.g., RADIUS [RADEAP]. In this case, the + authenticated identity has to be sent from the AAA server to the + IKEv2 responder. + + (References: Pasi Eronen's mail "RE: Reauthentication in IKEv2", + 2004-10-28. "Policy lookups" thread, Oct/Nov 2004. RFC 3748, + Section 7.3.) + +3.6. (Section removed) + + (This issue was corrected in RFC 4306.) + +3.7. Certificate encoding types + + Section 3.6 defines a total of twelve different certificate encoding + types, and continues that "Specific syntax is for some of the + certificate type codes above is not defined in this document." + However, the text does not provide references to other documents that + would contain information about the exact contents and use of those + values. + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 11] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Without this information, it is not possible to develop interoperable + implementations. Therefore, this document recommends that the + following certificate encoding values should not be used before new + specifications that specify their use are available. + + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + Kerberos Token 6 + SPKI Certificate 9 + + (Future versions of this document may also contain clarifications + about how these values are to be used.) + + This document recommends that most implementations should use only + those values that are "MUST"/"SHOULD" requirements in [IKEv2]; i.e., + "X.509 Certificate - Signature" (4), "Raw RSA Key" (11), "Hash and + URL of X.509 certificate" (12), and "Hash and URL of X.509 bundle" + (13). + + Furthermore, Section 3.7 says that the "Certificate Encoding" field + for the Certificate Request payload uses the same values as for + Certificate payload. However, the contents of the "Certification + Authority" field are defined only for X.509 certificates (presumably + covering at least types 4, 10, 12, and 13). This document recommends + that other values should not be used before new specifications that + specify their use are available. + + The "Raw RSA Key" type needs one additional clarification. Section + 3.6 says it contains "a PKCS #1 encoded RSA key". What this means is + a DER-encoded RSAPublicKey structure from PKCS#1 [PKCS1v21]. + +3.8. Shared key authentication and fixed PRF key size + + Section 2.15 says that "If the negotiated prf takes a fixed-size key, + the shared secret MUST be of that fixed size". This statement is + correct: the shared secret must be of the correct size. If it is + not, it cannot be used; there is no padding, truncation, or other + processing involved to force it to that correct size. + + This requirement means that it is difficult to use these PRFs with + shared key authentication. The authors think this part of the + specification was very poorly thought out, and using PRFs with a + fixed key size is likely to result in interoperability problems. + Thus, we recommend that such PRFs should not be used with shared key + authentication. PRF_AES128_XCBC [RFC3664] originally used fixed key + sizes; that RFC has been updated to handle variable key sizes in + [RFC3664bis]. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 12] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Note that Section 2.13 also contains text that is related to PRFs + with fixed key size: "When the key for the prf function has fixed + length, the data provided as a key is truncated or padded with zeros + as necessary unless exceptional processing is explained following the + formula". However, this text applies only to the prf+ construction, + so it does not contradict the text in Section 2.15. + + (References: Paul Hoffman's mail "Re: ikev2-07: last nits", + 2003-05-02. Hugo Krawczyk's reply, 2003-05-12. Thread "Question + about PRFs with fixed size key", Jan 2005.) + +3.9. EAP authentication and fixed PRF key size + + As described in the previous section, PRFs with a fixed key size + require a shared secret of exactly that size. This restriction + applies also to EAP authentication. For instance, a PRF that + requires a 128-bit key cannot be used with EAP since [EAP] specifies + that the MSK is at least 512 bits long. + + (References: Thread "Question about PRFs with fixed size key", Jan + 2005.) + +3.10. Matching ID payloads to certificate contents + + In IKEv1, there was some confusion about whether or not the + identities in certificates used to authenticate IKE were required to + match the contents of the ID payloads. There has been some work done + on this in the PKI4IPSEC Working Group, but that work is not finished + at this time. However, Section 3.5 explicitly says that the ID + payload "does not necessarily have to match anything in the CERT + payload". + +3.11. Message IDs for IKE_AUTH messages + + According to Section 2.2, "The IKE_SA initial setup messages will + always be numbered 0 and 1." That is true when the IKE_AUTH exchange + does not use EAP. When EAP is used, each pair of messages have their + message numbers incremented. The first pair of AUTH messages will + have an ID of 1, the second will be 2, and so on. + + (References: "Question about MsgID in AUTH exchange" thread, April + 2005.) + + +4. Creating CHILD_SAs + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 13] + +Internet-Draft IKEv2 Clarifications February 2006 + + +4.1. Creating SAs with the CREATE_CHILD_SA exchange + + Section 1.3's organization does not lead to clear understanding of + what is needed in which environment. The section can be reorganized + with subsections for each use of the CREATE_CHILD_SA exchange + (creating child SAs, rekeying IKE SAs, and rekeying child SAs.) + + The new Section 1.3 with subsections and the above changes might look + like this. + + NEW-1.3 The CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA Exchange is used to create new CHILD_SAs and + to rekey both IKE_SAs and CHILD_SAs. This exchange consists of + a single request/response pair, and some of its function was + referred to as a phase 2 exchange in IKEv1. It MAY be initiated + by either end of the IKE_SA after the initial exchanges are + completed. + + All messages following the initial exchange are + cryptographically protected using the cryptographic algorithms + and keys negotiated in the first two messages of the IKE + exchange. These subsequent messages use the syntax of the + Encrypted Payload described in section 3.14. All subsequent + messages include an Encrypted Payload, even if they are referred + to in the text as "empty". + + The CREATE_CHILD_SA is used for rekeying IKE_SAs and CHILD_SAs. + This section describes the first part of rekeying, the creation + of new SAs; Section 2.8 covers the mechanics of rekeying, + including moving traffic from old to new SAs and the deletion of + the old SAs. The two sections must be read together to + understand the entire process of rekeying. + + Either endpoint may initiate a CREATE_CHILD_SA exchange, so in + this section the term initiator refers to the endpoint + initiating this exchange. An implementation MAY refuse all + CREATE_CHILD_SA requests within an IKE_SA. + + The CREATE_CHILD_SA request MAY optionally contain a KE payload + for an additional Diffie-Hellman exchange to enable stronger + guarantees of forward secrecy for the CHILD_SA or IKE_SA. The + keying material for the SA is a function of SK_d established + during the establishment of the IKE_SA, the nonces exchanged + during the CREATE_CHILD_SA exchange, and the Diffie-Hellman + value (if KE payloads are included in the CREATE_CHILD_SA + exchange). The details are described in sections 2.17 and 2.18. + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 14] + +Internet-Draft IKEv2 Clarifications February 2006 + + + If a CREATE_CHILD_SA exchange includes a KEi payload, at least + one of the SA offers MUST include the Diffie-Hellman group of + the KEi. The Diffie-Hellman group of the KEi MUST be an element + of the group the initiator expects the responder to accept + (additional Diffie-Hellman groups can be proposed). If the + responder rejects the Diffie-Hellman group of the KEi payload, + the responder MUST reject the request and indicate its preferred + Diffie-Hellman group in the INVALID_KE_PAYLOAD Notification + payload. In the case of such a rejection, the CREATE_CHILD_SA + exchange fails, and the initiator SHOULD retry the exchange with + a Diffie-Hellman proposal and KEi in the group that the + responder gave in the INVALID_KE_PAYLOAD. + + NEW-1.3.1 Creating New CHILD_SAs with the CREATE_CHILD_SA Exchange + + A CHILD_SA may be created by sending a CREATE_CHILD_SA request. + The CREATE_CHILD_SA request for creating a new CHILD_SA is: + + Initiator Responder + ----------- ----------- + HDR, SK {[N+], SA, Ni, [KEi], + TSi, TSr} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in + the Ni payload, optionally a Diffie-Hellman value in the KEi + payload, and the proposed traffic selectors for the proposed + CHILD_SA in the TSi and TSr payloads. The request can also + contain Notify payloads that specify additional details for the + CHILD_SA: these include IPCOMP_SUPPORTED, USE_TRANSPORT_MODE, + ESP_TFC_PADDING_NOT_SUPPORTED, and NON_FIRST_FRAGMENTS_ALSO. + + The CREATE_CHILD_SA response for creating a new CHILD_SA is: + + <-- HDR, SK {[N+], SA, Nr, + [KEr], TSi, TSr} + + The responder replies with the accepted offer in an SA payload, + and a Diffie-Hellman value in the KEr payload if KEi was + included in the request and the selected cryptographic suite + includes that group. As with the request, optional Notification + payloads can specify additional details for the CHILD_SA. + + The traffic selectors for traffic to be sent on that SA are + specified in the TS payloads in the response, which may be a + subset of what the initiator of the CHILD_SA proposed. + + The text about rekeying SAs can be found in Section 5.1 of this + document. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 15] + +Internet-Draft IKEv2 Clarifications February 2006 + + +4.2. Creating an IKE_SA without a CHILD_SA + + CHILD_SAs can be created either by being piggybacked on the IKE_AUTH + exchange, or using a separate CREATE_CHILD_SA exchange. The + specification is not clear about what happens if creating the + CHILD_SA during the IKE_AUTH exchange fails for some reason. + + Our recommendation in this sitation is that the IKE_SA is created as + usual. This is also in line with how the CREATE_CHILD_SA exchange + works: a failure to create a CHILD_SA does not close the IKE_SA. + + The list of responses in the IKE_AUTH exchange that do not prevent an + IKE_SA from being set up include at least the following: + NO_PROPOSAL_CHOSEN, TS_UNACCEPTABLE, SINGLE_PAIR_REQUIRED, + INTERNAL_ADDRESS_FAILURE, and FAILED_CP_REQUIRED. + + (References: "Questions about internal address" thread, April, 2005.) + +4.3. Diffie-Hellman for first CHILD_SA + + Section 1.2 shows that IKE_AUTH messages do not contain KEi/KEr or + Ni/Nr payloads. This implies that the SA payload in IKE_AUTH + exchange cannot contain Transform Type 4 (Diffie-Hellman Group) with + any other value than NONE. Implementations should probably leave the + transform out entirely in this case. + +4.4. Extended Sequence Numbers (ESN) transform + + The description of the ESN transform in Section 3.3 has be proved + difficult to understand. The ESN transform has the following + meaning:: + + o A proposal containing one ESN transform with value 0 means "do not + use extended sequence numbers". + + o A proposal containing one ESN transform with value 1 means "use + extended sequence numbers". + + o A proposal containing two ESN transforms with values 0 and 1 means + "I support both normal and extended sequence numbers, you choose". + (Obviously this case is only allowed in requests; the response + will contain only one ESN transform.) + + In most cases, the exchange initiator will include either the first + or third alternative in its SA payload. The second alternative is + rarely useful for the initiator: it means that using normal sequence + numbers is not acceptable (so if the responder does not support ESNs, + the exchange will fail with NO_PROPOSAL_CHOSEN). + + + +Eronen & Hoffman Expires August 6, 2006 [Page 16] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Note that including the ESN transform is mandatory when creating + ESP/AH SAs (it was optional in earlier drafts of the IKEv2 + specification). + + (References: "Technical change needed to IKEv2 before publication", + "STRAW POLL: Dealing with the ESN negotiation interop issue in IKEv2" + and "Results of straw poll regarding: IKEv2 interoperability issue" + threads, March-April 2005.) + +4.5. Negotiation of ESP_TFC_PADDING_NOT_SUPPORTED + + The description of ESP_TFC_PADDING_NOT_SUPPORTED notification in + Section 3.10.1 says that "This notification asserts that the sending + endpoint will NOT accept packets that contain Flow Confidentiality + (TFC) padding". + + However, the text does not say in which messages this notification + should be included, or whether the scope of this notification is a + single CHILD_SA or all CHILD_SAs of the peer. + + Our interpretation is that the scope is a single CHILD_SA, and thus + this notification is included in messages containing an SA payload + negotiating a CHILD_SA. If neither endpoint accepts TFC padding, + this notification will be included in both the request proposing an + SA and the response accepting it. If this notification is included + in only one of the messages, TFC padding can still be sent in one + direction. + +4.6. Negotiation of NON_FIRST_FRAGMENTS_ALSO + + NON_FIRST_FRAGMENTS_ALSO notification is described in Section 3.10.1 + simply as "Used for fragmentation control. See [RFC4301] for + explanation." + + [RFC4301] says "Implementations that will transmit non-initial + fragments on a tunnel mode SA that makes use of non-trivial port (or + ICMP type/code or MH type) selectors MUST notify a peer via the IKE + NOTIFY NON_FIRST_FRAGMENTS_ALSO payload. The peer MUST reject this + proposal if it will not accept non-initial fragments in this context. + If an implementation does not successfully negotiate transmission of + non-initial fragments for such an SA, it MUST NOT send such fragments + over the SA." + + However, it is not clear exactly how the negotiation works. Our + interpretation is that the negotiation works the same way as for + IPCOMP_SUPPORTED and USE_TRANSPORT_MODE: sending non-first fragments + is enabled only if NON_FIRST_FRAGMENTS_ALSO notification is included + in both the request proposing an SA and the response accepting it. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 17] + +Internet-Draft IKEv2 Clarifications February 2006 + + + In other words, if the peer "rejects this proposal", it only omits + NON_FIRST_FRAGMENTS_ALSO notification from the response, but does not + reject the whole CHILD_SA creation. + +4.7. Semantics of complex traffic selector payloads + + As described in Section 3.13, the TSi/TSr payloads can include one or + more individual traffic selectors. + + There is no requirement that TSi and TSr contain the same number of + individual traffic selectors. Thus, they are interpreted as follows: + a packet matches a given TSi/TSr if it matches at least one of the + individual selectors in TSi, and at least one of the individual + selectors in TSr. + + For instance, the following traffic selectors: + + TSi = ((17, 100, 192.0.1.66-192.0.1.66), + (17, 200, 192.0.1.66-192.0.1.66)) + TSr = ((17, 300, 0.0.0.0-255.255.255.255), + (17, 400, 0.0.0.0-255.255.255.255)) + + would match UDP packets from 192.0.1.66 to anywhere, with any of the + four combinations of source/destination ports (100,300), (100,400), + (200,300), and (200, 400). + + This implies that some types of policies may require several CHILD_SA + pairs. For instance, a policy matching only source/destination ports + (100,300) and (200,400), but not the other two combinations, cannot + be negotiated as a single CHILD_SA pair using IKEv2. + + (References: "IKEv2 Traffic Selectors?" thread, Feb 2005.) + +4.8. ICMP type/code in traffic selector payloads + + The traffic selector types 7 and 8 can also refer to ICMP type and + code fields. As described in Section 3.13.1, "For the ICMP protocol, + the two one-octet fields Type and Code are treated as a single 16-bit + integer (with Type in the most significant eight bits and Code in the + least significant eight bits) port number for the purposes of + filtering based on this field." + + Since ICMP packets do not have separate source and destination port + fields, there is some room for confusion what exactly the four TS + payloads (two in the request, two in the response, each containing + both start and end port fields) should contain. + + The answer to this question can be found from [RFC4301] Section + + + +Eronen & Hoffman Expires August 6, 2006 [Page 18] + +Internet-Draft IKEv2 Clarifications February 2006 + + + 4.4.1.3. + + To give a concrete example, if a host at 192.0.1.234 wants to create + a transport mode SA for sending "Destination Unreachable" packets + (ICMPv4 type 3) to 192.0.2.155, but is not willing to receive them + over this SA pair, the CREATE_CHILD_SA exchange would look like this: + + Initiator Responder + ----------- ----------- + HDR, SK { N(USE_TRANSPORT_MODE), SA, Ni, + TSi(1, 0x0300-0x03FF, 192.0.1.234-192.0.1.234), + TSr(1, 65535-0, 192.0.2.155-192.0.2.155) } --> + + <-- HDR, SK { N(USE_TRANSPORT_MODE), SA, Nr, + TSi(1, 0x0300-0x03FF, 192.0.1.234-192.0.1.234), + TSr(1, 65535-0, 192.0.2.155-192.0.2.155) } + + Since IKEv2 always creates IPsec SAs in pairs, two SAs are also + created in this case, even though the second SA is never used for + data traffic. + + An exchange creating an SA pair that can be used both for sending and + receiving "Destination Unreachable" places the same value in all the + port: + + Initiator Responder + ----------- ----------- + HDR, SK { N(USE_TRANSPORT_MODE), SA, Ni, + TSi(1, 0x0300-0x03FF, 192.0.1.234-192.0.1.234), + TSr(1, 0x0300-0x03FF, 192.0.2.155-192.0.2.155) } --> + + <-- HDR, SK { N(USE_TRANSPORT_MODE), SA, Nr, + TSi(1, 0x0300-0x03FF, 192.0.1.234-192.0.1.234), + TSr(1, 0x0300-0x03FF, 192.0.2.155-192.0.2.155) } + + (References: "ICMP and MH TSs for IKEv2" thread, Sep 2005.) + +4.9. Mobility header in traffic selector payloads + + Traffic selectors can use IP Protocol ID 135 to match the IPv6 + mobility header [MIPv6]. However, the IKEv2 specification does not + define how to represent the "MH Type" field in traffic selectors. + + At some point, it was expected that this will be defined in a + separate document later. However, [RFC4301] says that "For IKE, the + IPv6 mobility header message type (MH type) is placed in the most + significant eight bits of the 16 bit local "port" selector". The + direction semantics of TSi/TSr port fields are the same as for ICMP, + + + +Eronen & Hoffman Expires August 6, 2006 [Page 19] + +Internet-Draft IKEv2 Clarifications February 2006 + + + and are described in the previous section. + + (References: Tero Kivinen's mail "Issue #86: Add IPv6 mobility header + message type as selector", 2003-10-14. "ICMP and MH TSs for IKEv2" + thread, Sep 2005.) + +4.10. Narrowing the traffic selectors + + Section 2.9 describes how traffic selectors are negotiated when + creating a CHILD_SA. A more concise summary of the narrowing process + is presented below. + + o If the responder's policy does not allow any part of the traffic + covered by TSi/TSr, it responds with TS_UNACCEPTABLE. + + o If the responder's policy allows the entire set of traffic covered + by TSi/TSr, no narrowing is necessary, and the responder can + return the same TSi/TSr values. + + o Otherwise, narrowing is needed. If the responder's policy allows + all traffic covered by TSi[1]/TSr[1] (the first traffic selectors + in TSi/TSr) but not entire TSi/TSr, the responder narrows to an + acceptable subset of TSi/TSr that includes TSi[1]/TSr[1]. + + o If the responder's policy does not allow all traffic covered by + TSi[1]/TSr[1], but does allow some parts of TSi/TSr, it narrows to + an acceptable subset of TSi/TSr. + + In the last two cases, there may be several subsets that are + acceptable (but their union is not); in this case, the responder + arbitrarily chooses one of them, and includes ADDITIONAL_TS_POSSIBLE + notification in the response. + +4.11. SINGLE_PAIR_REQUIRED + + The description of the SINGLE_PAIR_REQUIRED notify payload in + Sections 2.9 and 3.10.1 is not fully consistent. + + We do not attempt to describe this payload in this document either, + since it is expected that most implementations will not have policies + that require separate SAs for each address pair. + + Thus, if only some part (or parts) of the TSi/TSr proposed by the + initiator is (are) acceptable to the responder, most responders + should simply narrow TSi/TSr to an acceptable subset (as described in + the last two paragraphs of Section 2.9), rather than use + SINGLE_PAIR_REQUIRED. + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 20] + +Internet-Draft IKEv2 Clarifications February 2006 + + +4.12. Traffic selectors violating own policy + + Section 2.9 describes traffic selector negotiation in great detail. + One aspect of this negotiation that may need some clarification is + that when creating a new SA, the initiator should not propose traffic + selectors that violate its own policy. If this rule is not followed, + valid traffic may be dropped. + + This is best illustrated by an example. Suppose that host A has a + policy whose effect is that traffic to 192.0.1.66 is sent via host B + encrypted using AES, and traffic to all other hosts in 192.0.1.0/24 + is also sent via B, but must use 3DES. Suppose also that host B + accepts any combination of AES and 3DES. + + If host A now proposes an SA that uses 3DES, and includes TSr + containing (192.0.1.0-192.0.1.0.255), this will be accepted by host + B. Now, host B can also use this SA to send traffic from 192.0.1.66, + but those packets will be dropped by A since it requires the use of + AES for those traffic. Even if host A creates a new SA only for + 192.0.1.66 that uses AES, host B may freely continue to use the first + SA for the traffic. In this situation, when proposing the SA, host A + should have followed its own policy, and included a TSr containing + ((192.0.1.0-192.0.1.65),(192.0.1.67-192.0.1.255)) instead. + + In general, if (1) the initiator makes a proposal "for traffic X + (TSi/TSr), do SA", and (2) for some subset X' of X, the initiator + does not actually accept traffic X' with SA, and (3) the initiator + would be willing to accept traffic X' with some SA' (!=SA), valid + traffic can be unnecessarily dropped since the responder can apply + either SA or SA' to traffic X'. + + (References: "Question about "narrowing" ..." thread, Feb 2005. + "IKEv2 needs a "policy usage mode"..." thread, Feb 2005. "IKEv2 + Traffic Selectors?" thread, Feb 2005. "IKEv2 traffic selector + negotiation examples", 2004-08-08.) + + +5. Rekeying and deleting SAs + +5.1. Rekeying SAs with the CREATE_CHILD_SA exchange + + Continued from Section 4.1 of this document. + + NEW-1.3.2 Rekeying IKE_SAs with the CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA request for rekeying an IKE_SA is: + + Initiator Responder + + + +Eronen & Hoffman Expires August 6, 2006 [Page 21] + +Internet-Draft IKEv2 Clarifications February 2006 + + + ----------- ----------- + HDR, SK {SA, Ni, [KEi]} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in + the Ni payload, and optionally a Diffie-Hellman value in the KEi + payload. + + The CREATE_CHILD_SA response for rekeying an IKE_SA is: + + <-- HDR, SK {SA, Nr, [KEr]} + + The responder replies (using the same Message ID to respond) + with the accepted offer in an SA payload, a nonce in the Nr + payload, and, optionally, a Diffie-Hellman value in the KEr + payload. + + The new IKE_SA has its message counters set to 0, regardless of + what they were in the earlier IKE_SA. The window size starts at + 1 for any new IKE_SA. The new initiator and responder SPIs are + supplied in the SPI fields of the SA payloads. + + NEW-1.3.3 Rekeying CHILD_SAs with the CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA request for rekeying a CHILD_SA is: + + Initiator Responder + ----------- ----------- + HDR, SK {N(REKEY_SA), [N+], SA, + Ni, [KEi], TSi, TSr} --> + + The leading Notify payload of type REKEY_SA identifies the + CHILD_SA being rekeyed, and contains the SPI that the initiator + expects in the headers of inbound packets. In addition, the + initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, optionally a Diffie-Hellman value in the KEi payload, + and the proposed traffic selectors in the TSi and TSr payloads. + The request can also contain Notify payloads that specify + additional details for the CHILD_SA. + + The CREATE_CHILD_SA response for rekeying a CHILD_SA is: + + <-- HDR, SK {[N+], SA, Nr, + [KEr], TSi, TSr} + + The responder replies with the accepted offer in an SA payload, + and a Diffie-Hellman value in the KEr payload if KEi was + included in the request and the selected cryptographic suite + includes that group. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 22] + +Internet-Draft IKEv2 Clarifications February 2006 + + + The traffic selectors for traffic to be sent on that SA are + specified in the TS payloads in the response, which may be a + subset of what the initiator of the CHILD_SA proposed. + +5.2. Rekeying the IKE_SA vs. reauthentication + + Rekeying the IKE_SA and reauthentication are different concepts in + IKEv2. Rekeying the IKE_SA establishes new keys for the IKE_SA and + resets the Message ID counters, but it does not authenticate the + parties again (no AUTH or EAP payloads are involved). + + While rekeying the IKE_SA may be important in some environments, + reauthentication (the verification that the parties still have access + to the long-term credentials) is often more important. + + IKEv2 does not have any special support for reauthentication. + Reauthentication is done by creating a new IKE_SA from scratch (using + IKE_SA_INIT/IKE_AUTH exchanges, without any REKEY_SA notify + payloads), creating new CHILD_SAs within the new IKE_SA (without + REKEY_SA notify payloads), and finally deleting the old IKE_SA (which + deletes the old CHILD_SAs as well). + + This means that reauthentication also establishes new keys for the + IKE_SA and CHILD_SAs. Therefore, while rekeying can be performed + more often than reauthentication, the situation where "authentication + lifetime" is shorter than "key lifetime" does not make sense. + + While creation of a new IKE_SA can be initiated by either party + (initiator or responder in the original IKE_SA), the use of EAP + authentication and/or configuration payloads means in practice that + reauthentication has to be initiated by the same party as the + original IKE_SA. IKEv2 does not currently allow the responder to + request reauthentication in this case; however, there is ongoing work + to add this functionality [ReAuth]. + + (References: "Reauthentication in IKEv2" thread, Oct/Nov 2004.) + +5.3. SPIs when rekeying the IKE_SA + + Section 2.18 says that "New initiator and responder SPIs are supplied + in the SPI fields". This refers to the SPI fields in the Proposal + structures inside the Security Association (SA) payloads, not the SPI + fields in the IKE header. + + (References: Tom Stiemerling's mail "Rekey IKE SA", 2005-01-24. + Geoffrey Huang's reply, 2005-01-24.) + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 23] + +Internet-Draft IKEv2 Clarifications February 2006 + + +5.4. SPI when rekeying a CHILD_SA + + Section 3.10.1 says that in REKEY_SA notifications, "The SPI field + identifies the SA being rekeyed." + + Since CHILD_SAs always exist in pairs, there are two different SPIs. + The SPI placed in the REKEY_SA notification is the SPI the exchange + initiator would expect in inbound ESP or AH packets (just as in + Delete payloads). + +5.5. Changing PRFs when rekeying the IKE_SA + + When rekeying the IKE_SA, Section 2.18 says that "SKEYSEED for the + new IKE_SA is computed using SK_d from the existing IKE_SA as + follows: + + SKEYSEED = prf(SK_d (old), [g^ir (new)] | Ni | Nr)" + + If the old and new IKE_SA selected a different PRF, it is not totally + clear which PRF should be used. + + Since the rekeying exchange belongs to the old IKE_SA, it is the old + IKE_SA's PRF that is used. This also follows the principle that the + same key (the old SK_d) should not be used with multiple + cryptographic algorithms. + + Note that this may work poorly if the new IKE_SA's PRF has a fixed + key size, since the output of the PRF may not be of the correct size. + This supports our opinion earlier in the document that the use of + PRFs with a fixed key size is a bad idea. + + (References: "Changing PRFs when rekeying the IKE_SA" thread, June + 2005.) + +5.6. Deleting vs. closing SAs + + The IKEv2 specification talks about "closing" and "deleting" SAs, but + it is not always clear what exactly is meant. However, other parts + of the specification make it clear that when local state related to a + CHILD_SA is removed, the SA must also be actively deleted with a + Delete payload. + + In particular, Section 2.4 says that "If an IKE endpoint chooses to + delete CHILD_SAs, it MUST send Delete payloads to the other end + notifying it of the deletion". Section 1.4 also explains that "ESP + and AH SAs always exist in pairs, with one SA in each direction. + When an SA is closed, both members of the pair MUST be closed." + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 24] + +Internet-Draft IKEv2 Clarifications February 2006 + + +5.7. Deleting a CHILD_SA pair + + Section 1.4 describes how to delete SA pairs using the Informational + exchange: "To delete an SA, an INFORMATIONAL exchange with one or + more delete payloads is sent listing the SPIs (as they would be + expected in the headers of inbound packets) of the SAs to be deleted. + The recipient MUST close the designated SAs." + + The "one or more delete payloads" phrase has caused some confusion. + You never send delete payloads for the two sides of an SA in a single + message. If you have many SAs to delete at the same time (such as + the nested example given in that paragraph), you include delete + payloads for in inbound half of each SA in your Informational + exchange. + +5.8. Deleting an IKE_SA + + Since IKE_SAs do not exist in pairs, it is not totally clear what the + response message should contain when the request deleted the IKE_SA. + + Since there is no information that needs to be sent to the other side + (except that the request was received), an empty Informational + response seems like the most logical choice. + + (References: "Question about delete IKE SA" thread, May 2005.) + +5.9. Who is the original initiator of IKE_SA + + In the IKEv2 document, "initiator" refers to the party who initiated + the exchange being described, and "original initiator" refers to the + party who initiated the whole IKE_SA. However, there is some + potential for confusion because the IKE_SA can be rekeyed by either + party. + + To clear up this confusion, we propose that "original initiator" + always refers to the party who initiated the exchange which resulted + in the current IKE_SA. In other words, if the the "original + responder" starts rekeying the IKE_SA, that party becomes the + "original initiator" of the new IKE_SA. + + (References: Paul Hoffman's mail "Original initiator in IKEv2", 2005- + 04-21.) + +5.10. (Section removed) + + (This issue was corrected in RFC 4306.) + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 25] + +Internet-Draft IKEv2 Clarifications February 2006 + + +5.11. Comparing nonces + + Section 2.8 about rekeying says that "If redundant SAs are created + though such a collision, the SA created with the lowest of the four + nonces used in the two exchanges SHOULD be closed by the endpoint + that created it." + + Here "lowest" uses an octet-by-octet (lexicographical) comparison + (instead of, for instance, comparing the nonces as large integers). + In other words, start by comparing the first octet; if they're equal, + move to the next octet, and so on. If you reach the end of one + nonce, that nonce is the lower one. + + (References: "IKEv2 rekeying question" thread, July 2005.) + +5.12. Exchange collisions + + Since IKEv2 exchanges can be initiated by both peers, it is possible + that two exchanges affecting the same SA partly overlap. This can + lead to a situation where the SA state information is temporarily out + of sync, and a peer can receive a request it cannot process in a + normal fashion. Some of these corner cases are discussed in the + specification, some are not. + + Obviously, using a window size greater than one leads to infinitely + more complex situations, especially if requests are processed out of + order. In this section, we concentrate on problems that can arise + even with window size 1. + + (References: "IKEv2: invalid SPI in DELETE payload" thread, Dec 2005/ + Jan 2006. "Problem with exchanges collisions" thread, Dec 2005.) + +5.12.1. Simultaneous CHILD_SA close + + Probably the simplest case happens if both peers decide to close the + same CHILD_SA pair at the same time: + + Host A Host B + -------- -------- + send req1: D(SPIa) --> + <-- send req2: D(SPIb) + --> recv req1 + <-- send resp1: () + recv resp1 + recv req2 + send resp2: () --> + --> recv resp2 + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 26] + +Internet-Draft IKEv2 Clarifications February 2006 + + + This case is described in Section 1.4, and is handled by omitting the + Delete payloads from the response messages. + +5.12.2. Simultaneous IKE_SA close + + Both peers can also decide to close the IKE_SA at the same time. The + desired end result is obvious; however, in certain cases the final + exchanges may not be fully completed. + + Host A Host B + -------- -------- + send req1: D() --> + <-- send req2: D() + --> recv req1 + + At this point, host B should reply as usual (with empty Informational + response), close the IKE_SA, and stop retransmitting req2. This is + because once host A receives resp1, it may not be able to reply any + longer. The situation is symmetric, so host A should behave the same + way. + + Host A Host B + -------- -------- + <-- send resp1: () + send resp2: () + + Even if neither resp1 nor resp2 ever arrives, the end result is still + correct: the IKE_SA is gone. The same happens if host A never + receives req2. + +5.12.3. Simultaneous CHILD_SA rekeying + + Another case that is described in the specification is simultaneous + rekeying. Section 2.8 says + + "If the two ends have the same lifetime policies, it is possible + that both will initiate a rekeying at the same time (which will + result in redundant SAs). To reduce the probability of this + happening, the timing of rekeying requests SHOULD be jittered + (delayed by a random amount of time after the need for rekeying is + noticed). + + This form of rekeying may temporarily result in multiple similar + SAs between the same pairs of nodes. When there are two SAs + eligible to receive packets, a node MUST accept incoming packets + through either SA. If redundant SAs are created though such a + collision, the SA created with the lowest of the four nonces used + in the two exchanges SHOULD be closed by the endpoint that created + + + +Eronen & Hoffman Expires August 6, 2006 [Page 27] + +Internet-Draft IKEv2 Clarifications February 2006 + + + it." + + However, a better explanation on what impact this has on + implementations is needed. Assume that hosts A and B have an + existing IPsec SA pair with SPIs (SPIa1,SPIb1), and both start + rekeying it at the same time: + + Host A Host B + -------- -------- + send req1: N(REKEY_SA,SPIa1), + SA(..,SPIa2,..),Ni1,.. --> + <-- send req2: N(REKEY_SA,SPIb1), + SA(..,SPIb2,..),Ni2,.. + recv req2 <-- + + At this point, A knows there is a simultaneous rekeying going on. + However, it cannot yet know which of the exchanges will have the + lowest nonce, so it will just note the situation and respond as + usual. + + send resp2: SA(..,SPIa3,..),Nr1,.. --> + --> recv req1 + + Now B also knows that simultaneous rekeying is going on. Similarly + as host A, it has to respond as usual. + + <-- send resp1: SA(..,SPIb3,..),Nr2,.. + recv resp1 <-- + --> recv resp2 + + At this point, there are three CHILD_SA pairs between A and B (the + old one and two new ones). A and B can now compare the nonces. + Suppose that the lowest nonce was Nr1 in message resp2; in this case, + B (the sender of req2) deletes the redundant new SA, and A (the node + that initiated the surviving rekeyed SA), deletes the old one. + + send req3: D(SPIa1) --> + <-- send req4: D(SPIb2) + --> recv req3 + <-- send resp4: D(SPIb1) + recv req4 <-- + send resp4: D(SPIa3) --> + + The rekeying is now finished. + + However, there is a second possible sequence of events that can + happen if some packets are lost in the network, resulting in + retransmissions. The rekeying begins as usual, but A's first packet + + + +Eronen & Hoffman Expires August 6, 2006 [Page 28] + +Internet-Draft IKEv2 Clarifications February 2006 + + + (req1) is lost. + + Host A Host B + -------- -------- + send req1: N(REKEY_SA,SPIa1), + SA(..,SPIa2,..),Ni1,.. --> (lost) + <-- send req2: N(REKEY_SA,SPIb1), + SA(..,SPIb2,..),Ni2,.. + recv req2 <-- + send resp2: SA(..,SPIa3,..),Nr1,.. --> + --> recv resp2 + <-- send req3: D(SPIb1) + recv req3 <-- + send resp3: D(SPIa1) --> + --> recv resp3 + + From B's point of view, the rekeying is now completed, and since it + has not yet received A's req1, it does not even know that these was + simultaneous rekeying. However, A will continue retransmitting the + message, and eventually it will reach B. + + resend req1 --> + --> recv req1 + + What should B do in this point? To B, it looks like A is trying to + rekey an SA that no longer exists; thus failing the request with + something non-fatal such as NO_PROPOSAL_CHOSEN seems like a + reasonable approach. + + <-- send resp1: N(NO_PROPOSAL_CHOSEN) + recv resp1 <-- + + When A receives this error, it already knows there was simultaneous + rekeying, so it can ignore the error message. + +5.12.4. Simultaneous IKE_SA rekeying + + Probably the most complex case occurs when both peers try to rekey + the IKE_SA at the same time. Basically, the text in Section 2.8 + applies to this case as well; however, it is important to ensure that + the CHILD_SAs are inherited by the right IKE_SA. + + The case where both endpoints notice the simultaneous rekeying works + the same way as with CHILD_SAs. After the CREATE_CHILD_SA exchanges, + three IKE_SAs exist between A and B; the one containing the lowest + nonce inherits the CHILD_SAs. + + However, there is a twist to the other case where one rekeying + + + +Eronen & Hoffman Expires August 6, 2006 [Page 29] + +Internet-Draft IKEv2 Clarifications February 2006 + + + finishes first: + + Host A Host B + -------- -------- + send req1: + SA(..,SPIa1,..),Ni1,.. --> + <-- send req2: SA(..,SPIb1,..),Ni2,.. + --> recv req1 + <-- send resp1: SA(..,SPIb2,..),Nr2,.. + recv resp1 <-- + send req3: D() --> + --> recv req3 + + At this point, host B sees a request to close the IKE_SA. There's + not much more to do than to reply as usual. However, at this point + host B should stop retransmitting req2, since once host A receives + resp3, it will delete all the state associated with the old IKE_SA, + and will not be able to reply to it. + + <-- send resp3: () + +5.12.5. Closing and rekeying a CHILD_SA + + A case similar to simultaneous rekeying can occur if one peers + decides to close an SA and the other peer tries to rekey it: + + Host A Host B + -------- -------- + send req1: D(SPIa) --> + <-- send req2: N(REKEY_SA,SPIb),SA,.. + --> recv req1 + + At this point, host B notices that host A is trying to close an SA + that host B is currently rekeying. Replying as usual is probably the + best choice: + + <-- send resp1: D(SPIb) + + Depending on in which order req2 and resp1 arrive, host A sees either + a request to rekey an SA that it is currently closing, or a request + to rekey an SA that does not exist. In both cases, + NO_PROPOSAL_CHOSEN is probably fine. + + recv req2 + recv resp1 + send resp2: N(NO_PROPOSAL_CHOSEN) --> + --> recv resp2 + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 30] + +Internet-Draft IKEv2 Clarifications February 2006 + + +5.12.6. Closing a new CHILD_SA + + Yet another case occurs when host A creates a CHILD_SA pair, but soon + thereafter host B decides to delete it (possible because its policy + changed): + + Host A Host B + -------- -------- + send req1: [N(REKEY_SA,SPIa1)], + SA(..,SPIa2,..),.. --> + --> recv req1 + (lost) <-- send resp1: SA(..,SPIb2,..),.. + + <-- send req2: D(SPIb2) + recv req2 + + At this point, host A has not yet received message resp1 (and is + retransmitting message req1), so it does not recognize SPIb in + message req2. What should host A do? + + One option would be to reply with an empty Informational response. + However, this same reply would also be sent if host A has received + resp1, but has already sent a new request to delete the SA that was + just created. This would lead to a situation where the peers are no + longer in sync about which SAs exist between them. However, host B + would eventually notice that the other half of the CHILD_SA pair has + not been deleted. Section 1.4 describes this case and notes that "a + node SHOULD regard half-closed connections as anomalous and audit + their existence should they persist", and continues that "if + connection state becomes sufficiently messed up, a node MAY close the + IKE_SA". + + Another solution that has been proposed is to reply with an + INVALID_SPI notification which contains SPIb. This would explicitly + tell host B that the SA was not deleted, so host B could try deleting + it again later. However, this usage is not part of the IKEv2 + specification, and would not be in line with normal use of the + INVALID_SPI notification where the data field contains the SPI the + recipient of the notification would put in outbound packets. + + Yet another solution would be to ignore req2 at this time, and wait + until we have received resp1. However, this alternative has not been + fully analyzed at this time; in general, ignoring valid requests is + always a bit dangerous, because both endpoints could do it, leading + to a deadlock. + + Currently, this document recommends the first alternative. + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 31] + +Internet-Draft IKEv2 Clarifications February 2006 + + +5.12.7. Rekeying a new CHILD_SA + + Yet another case occurs when a CHILD_SA is rekeyed soon after it has + been created: + + Host A Host B + -------- -------- + send req1: [N(REKEY_SA,SPIa1)], + SA(..,SPIa2,..),.. --> + (lost) <-- send resp1: SA(..,SPIb2,..),.. + + <-- send req2: N(REKEY_SA,SPIb2), + SA(..,SPIb3,..),.. + recv req2 <-- + + To host A, this looks like a request to rekey an SA that does not + exist. Like in the simultaneous rekeying case, replying with + NO_PROPOSAL_CHOSEN is probably reasonable: + + send resp2: N(NO_PROPOSAL_CHOSEN) --> + recv resp1 + +5.12.8. Collisions with IKE_SA rekeying + + Another set of cases occur when one peer starts rekeying the IKE_SA + at the same time the other peer starts creating, rekeying, or closing + a CHILD_SA. Suppose that host B starts creating a CHILD_SA, and soon + after, host A starts rekeying the IKE_SA: + + Host A Host B + -------- -------- + <-- send req1: SA,Ni1,TSi,TSr + send req2: SA,Ni2,.. --> + --> recv req2 + + What should host B do at this point? Replying as usual would seem + like a reasonable choice: + + <-- send resp2: SA,Ni2,.. + recv resp2 <-- + send req3: D() --> + --> recv req3 + + Now, a problem arises: If host B now replies normally with an empty + Informational response, this will cause host A to delete state + associated with the IKE_SA. This means host B should stop + retransmitting req1. However, host B cannot know whether or not host + A has received req1. If host A did receive it, it will move the + + + +Eronen & Hoffman Expires August 6, 2006 [Page 32] + +Internet-Draft IKEv2 Clarifications February 2006 + + + CHILD_SA to the new IKE_SA as usual, and the state information will + then be out of sync. + + It seems this situation is tricky to handle correctly. Our proposal + is as follows: if a host receives a request to rekey the IKE_SA when + it has CHILD_SAs in "half-open" state (currently being created or + rekeyed), it should reply with NO_PROPOSAL_CHOSEN. If a host + receives a request to create or rekey a CHILD_SA after it has started + rekeying the IKE_SA, it should reply with NO_ADDITIONAL_SAS. + + The case where CHILD_SAs are being closed is even worse. Our + recommendation is that if a host receives a request to rekey the + IKE_SA when it has CHILD_SAs in "half-closed" state (currently being + closed), it should reply with NO_PROPOSAL_CHOSEN. And if a host + receives a request to close a CHILD_SA after it has started rekeying + the IKE_SA, it should reply with an empty Informational response. + This ensures that at least the other peer will eventually notice that + the CHILD_SA is still in "half-closed" state, and will start a new + IKE_SA from scratch. + +5.12.9. Closing and rekeying the IKE_SA + + The final case considered in this section occurs if one peer decides + to close the IKE_SA while the other peer tries to rekey it. + + Host A Host B + -------- -------- + send req1: SA(..,SPIa1,..),Ni1 --> + <-- send req2: D() + --> recv req1 + recv req2 <-- + + At this point, host B should probably reply with NO_PROPOSAL_CHOSEN, + and host A should reply as usual, close the IKE_SA, and stop + retransmitting req1. + + <-- send resp1: N(NO_PROPOSAL_CHOSEN) + send resp2: () + + If host A wants to continue communication with B, it can now start a + new IKE_SA. + +5.12.10. Summary + + If a host receives a request to rekey: + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 33] + +Internet-Draft IKEv2 Clarifications February 2006 + + + o a CHILD_SA pair that the host is currently trying to close: reply + with NO_PROPOSAL_CHOSEN. + + o a CHILD_SA pair that the host is currently rekeying: reply as + usual, but prepare to close redundant SAs later based on the + nonces. + + o a CHILD_SA pair that does not exist: reply with + NO_PROPOSAL_CHOSEN. + + o the IKE_SA, and the host is currently rekeying the IKE_SA: reply + as usual, but prepare to close redundant SAs and move inherited + CHILD_SAs later based on the nonces. + + o the IKE_SA, and the host is currently creating, rekeying, or + closing a CHILD_SA: reply with NO_PROPOSAL_CHOSEN. + + o the IKE_SA, and the host is currently trying to close the IKE_SA: + reply with NO_PROPOSAL_CHOSEN. + + If a host receives a request to close: + + o a CHILD_SA pair that the host is currently trying to close: reply + without Delete payloads. + + o a CHILD_SA pair that the host is currently rekeying: reply as + usual, with Delete payload. + + o a CHILD_SA pair that does not exist: reply without Delete + payloads. + + o the IKE_SA, and the host is currently rekeying the IKE_SA: reply + as usual, and forget about our own rekeying request. + + o the IKE_SA, and the host is currently trying to close the IKE_SA: + reply as usual, and forget about our own close request. + + If a host receives a request to create or rekey a CHILD_SA when it is + currently rekeying the IKE_SA: reply with NO_ADDITIONAL_SAS. + + If a host receives a request to delete a CHILD_SA when it is + currently rekeying the IKE_SA: reply without Delete payloads. + +5.13. Diffie-Hellman and rekeying the IKE_SA + + There has been some confusion whether doing a new Diffie-Hellman + exchange is mandatory when the IKE_SA is rekeyed. + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 34] + +Internet-Draft IKEv2 Clarifications February 2006 + + + It seems that this case is allowed by the IKEv2 specification. + Section 2.18 shows the Diffie-Hellman term (g^ir) in brackets, and + the change history appendix in the draft mentioned this as one change + between draft versions -00 and -01. Section 3.3.3 does not + contradict this when it says that including the D-H transform is + mandatory: although including the transform is mandatory, it can + contain the value "NONE". + + However, having the option to skip the Diffie-Hellman exchange when + rekeying the IKE_SA does not add useful functionality to the + protocol. The main purpose of rekeying the IKE_SA is to ensure that + the compromise of old keying material does not provide information + about the current keys, or vice versa. This requires performing the + Diffie-Hellman exchange when rekeying. Furthermore, it is likely + that this option would have been removed from the protocol as + unnecessary complexity had it been discussed earlier. + + Given this, we recommend that implementations should have a hard- + coded policy that requires performing a new Diffie-Hellman exchange + when rekeying the IKE_SA. In other words, the initiator should not + propose the value "NONE" for the D-H transform, and the responder + should not accept such a proposal. This policy also implies that a + succesful exchange rekeying the IKE_SA always includes the KEi/KEr + payloads. + + (References: "Rekeying IKE_SAs with the CREATE_CHILD_SA exhange" + thread, Oct 2005. "Comments of + draft-eronen-ipsec-ikev2-clarifications-02.txt" thread, Apr 2005.) + + +6. Configuration payloads + +6.1. Assigning IP addresses + + Section 2.9 talks about traffic selector negotiation and mentions + that "In support of the scenario described in section 1.1.3, an + initiator may request that the responder assign an IP address and + tell the initiator what it is." + + This sentence is correct, but its placement is slightly confusing. + IKEv2 does allow the initiator to request assignment of an IP address + from the responder, but this is done using configuration payloads, + not traffic selector payloads. An address in a TSi payload in a + response does not mean that the responder has assigned that address + to the initiator; it only means that if packets matching these + traffic selectors are sent by the initiator, IPsec processing can be + performed as agreed for this SA. The TSi payload itself does not + give the initiator permission to configure the initiator's TCP/IP + + + +Eronen & Hoffman Expires August 6, 2006 [Page 35] + +Internet-Draft IKEv2 Clarifications February 2006 + + + stack with the address and use it as its source address. + + In other words, IKEv2 does not have two different mechanisms for + assigning addresses, but only one: configuration payloads. In the + scenario described in Section 1.1.3, both configuration and traffic + selector payloads are usually included in the same message, and often + contain the same information in the response message (see Section 6.4 + of this document for some examples). However, their semantics are + still different. + +6.2. (Section removed) + + (This issue was corrected in RFC 4306.) + +6.3. Requesting any INTERNAL_IP4/IP6_ADDRESS + + When describing the INTERNAL_IP4/IP6_ADDRESS attributes, Section + 3.15.1 says that "In a request message, the address specified is a + requested address (or zero if no specific address is requested)". + The question here is that does "zero" mean an address "0.0.0.0" or a + zero length string? + + Earlier, the same section also says that "If an attribute in the + CFG_REQUEST Configuration Payload is not zero-length, it is taken as + a suggestion for that attribute". Also, the table of configuration + attributes shows that the length of INTERNAL_IP4_ADDRESS is either "0 + or 4 octets", and likewise, INTERNAL_IP6_ADDRESS is either "0 or 17 + octets". + + Thus, if the client does not request a specific address, it includes + a zero-length INTERNAL_IP4/IP6_ADDRESS attribute, not an attribute + containing an all-zeroes address. The example in 2.19 is thus + incorrect, since it shows the attribute as + "INTERNAL_ADDRESS(0.0.0.0)". + + However, since the value is only a suggestion, implementations are + recommended to ignore suggestions they do not accept; or in other + words, treat the same way a zero-length INTERNAL_IP4_ADDRESS, + "0.0.0.0", and any other addresses the implementation does not + recognize as a reasonable suggestion. + +6.4. INTERNAL_IP4_SUBNET/INTERNAL_IP6_SUBNET + + Section 3.15.1 describes the INTERNAL_IP4_SUBNET as "The protected + sub-networks that this edge-device protects. This attribute is made + up of two fields: the first is an IP address and the second is a + netmask. Multiple sub-networks MAY be requested. The responder MAY + respond with zero or more sub-network attributes." + + + +Eronen & Hoffman Expires August 6, 2006 [Page 36] + +Internet-Draft IKEv2 Clarifications February 2006 + + + INTERNAL_IP6_SUBNET is defined in a similar manner. + + This raises two questions: first, since this information is usually + included in the TSr payload, what functionality does this attribute + add? And second, what does this attribute mean in CFG_REQUESTs? + + For the first question, there seem to be two sensible + interpretations. Clearly TSr (in IKE_AUTH or CREATE_CHILD_SA + response) indicates which subnets are accessible through the SA that + was just created. + + The first interpretation of the INTERNAL_IP4/6_SUBNET attributes is + that they indicate additional subnets that can be reached through + this gateway, but need a separate SA. According to this + interpretation, the INTERNAL_IP4/6_SUBNET attributes are useful + mainly when they contain addresses not included in TSr. + + The second interpretation is that the INTERNAL_IP4/6_SUBNET + attributes express the gateway's policy about what traffic should be + sent through the gateway. The client can choose whether other + traffic (covered by TSr, but not in INTERNAL_IP4/6_SUBNET) is sent + through the gateway or directly the destination. According to this + interpretation, the attributes are useful mainly when TSr contains + addresses not included in the INTERNAL_IP4/6_SUBNET attributes. + + It turns out that these two interpretations are not incompatible, but + rather two sides of the same principle: traffic to the addresses + listed in the INTERNAL_IP4/6_SUBNET attributes should be sent via + this gateway. If there are no existing IPsec SAs whose traffic + selectors cover the address in question, new SAs have to be created. + + A couple of examples are given below. For instance, if there are two + subnets, 192.0.1.0/26 and 192.0.2.0/24, and the client's request + contains the following: + + CP(CFG_REQUEST) = + INTERNAL_IP4_ADDRESS() + TSi = (0, 0-65535, 0.0.0.0-255.255.255.255) + TSr = (0, 0-65535, 0.0.0.0-255.255.255.255) + + Then a valid response could be the following (in which TSr and + INTERNAL_IP4_SUBNET contain the same information): + + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 37] + +Internet-Draft IKEv2 Clarifications February 2006 + + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = ((0, 0-65535, 192.0.1.0-192.0.1.63), + (0, 0-65535, 192.0.2.0-192.0.2.255)) + + In these cases, the INTERNAL_IP4_SUBNET does not really carry any + useful information. Another possible reply would have been this: + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 0.0.0.0-255.255.255.255) + + This would mean that the client can send all its traffic through the + gateway, but the gateway does not mind if the client sends traffic + not included by INTERNAL_IP4_SUBNET directly to the destination + (without going through the gateway). + + A different situation arises if the gateway has a policy that + requires the traffic for the two subnets to be carried in separate + SAs. Then a response like this would indicate to the client that if + it wants access to the second subnet, it needs to create a separate + SA: + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 192.0.1.0-192.0.1.63) + + INTERNAL_IP4_SUBNET can also be useful if the client's TSr included + only part of the address space. For instance, if the client requests + the following: + + CP(CFG_REQUEST) = + INTERNAL_IP4_ADDRESS() + TSi = (0, 0-65535, 0.0.0.0-255.255.255.255) + TSr = (0, 0-65535, 192.0.2.155-192.0.2.155) + + Then the gateway's reply could be this: + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 38] + +Internet-Draft IKEv2 Clarifications February 2006 + + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 192.0.2.155-192.0.2.155) + + It is less clear what the attributes mean in CFG_REQUESTs, and + whether other lengths than zero make sense in this situation (but for + INTERNAL_IP6_SUBNET, zero length is not allowed at all!). Currently + this document recommends that implementations should not include + INTERNAL_IP4_SUBNET or INTERNAL_IP6_SUBNET attributes in + CFG_REQUESTs. + + For the IPv4 case, this document recommends using only netmasks + consisting of some amount of "1" bits followed by "0" bits; for + instance, "255.0.255.0" would not be a valid netmask for + INTERNAL_IP4_SUBNET. + + It is also worthwhile to note that the contents of the INTERNAL_IP4/ + 6_SUBNET attributes do not imply link boundaries. For instance, a + gateway providing access to a large company intranet using addresses + from the 10.0.0.0/8 block can send a single INTERNAL_IP4_SUBNET + attribute (10.0.0.0/255.0.0.0) even if the intranet has hundreds of + routers and separate links. + + (References: Tero Kivinen's mail "Intent of couple of attributes in + Configuration Payload in IKEv2?", 2004-11-19. Srinivasa Rao + Addepalli's mail "INTERNAL_IP4_SUBNET and INTERNAL_IP6_SUBNET in + IKEv2", 2004-09-10. Yoav Nir's mail "Re: New I-D: IKEv2 + Clarifications and Implementation Guidelines", 2005-02-07. + "Clarifications open issue: INTERNAL_IP4_SUBNET/NETMASK" thread, + April 2005.) + +6.5. INTERNAL_IP4_NETMASK + + Section 3.15.1 defines the INTERNAL_IP4_NETMASK attribute, and says + that "The internal network's netmask. Only one netmask is allowed in + the request and reply messages (e.g., 255.255.255.0) and it MUST be + used only with an INTERNAL_IP4_ADDRESS attribute". + + However, it is not clear what exactly this attribute means, as the + concept of "netmask" is not very well defined for point-to-point + links (unlike multi-access links, where it means "you can reach hosts + inside this netmask directly using layer 2, instead of sending + packets via a router"). Even if the operating system's TCP/IP stack + requires a netmask to be configured, for point-to-point links it + could be just set to 255.255.255.255. So, why is this information + + + +Eronen & Hoffman Expires August 6, 2006 [Page 39] + +Internet-Draft IKEv2 Clarifications February 2006 + + + sent in IKEv2? + + One possible interpretation would be that the host is given a whole + block of IP addresses instead of a single address. This is also what + Framed-IP-Netmask does in [RADIUS], the IPCP "subnet mask" extension + does in PPP [IPCPSubnet], and the prefix length in the IPv6 Framed- + IPv6-Prefix attribute does in [RADIUS6]. However, nothing in the + specification supports this interpretation, and discussions on the + IPsec WG mailing list have confirmed it was not intended. Section + 3.15.1 also says that multiple addresses are assigned using multiple + INTERNAL_IP4/6_ADDRESS attributes. + + Currently, this document's interpretation is the following: + INTERNAL_IP4_NETMASK in a CFG_REPLY means roughly the same thing as + INTERNAL_IP4_SUBNET containing the same information ("send traffic to + these addresses through me"), but also implies a link boundary. For + instance, the client could use its own address and the netmask to + calculate the broadcast address of the link. (Whether the gateway + will actually deliver broadcast packets to other VPN clients and/or + other nodes connected to this link is another matter.) + + An empty INTERNAL_IP4_NETMASK attribute can be included in a + CFG_REQUEST to request this information (although the gateway can + send the information even when not requested). However, it seems + that non-empty values for this attribute do not make sense in + CFG_REQUESTs. + + Fortunately, Section 4 clearly says that a minimal implementation + does not need to include or understand the INTERNAL_IP4_NETMASK + attribute, and thus this document recommends that implementations + should not use the INTERNAL_IP4_NETMASK attribute or assume that the + other peer supports it. + + (References: Charlie Kaufman's mail "RE: Proposed Last Call based + revisions to IKEv2", 2004-05-27. Email discussion with Tero Kivinen, + Jan 2005. Yoav Nir's mail "Re: New I-D: IKEv2 Clarifications and + Implementation Guidelines", 2005-02-07. "Clarifications open issue: + INTERNAL_IP4_SUBNET/NETMASK" thread, April 2005.) + +6.6. Configuration payloads for IPv6 + + IKEv2 also defines configuration payloads for IPv6. However, they + are based on the corresponding IPv4 payloads, and do not fully follow + the "normal IPv6 way of doing things". + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 40] + +Internet-Draft IKEv2 Clarifications February 2006 + + + A client can be assigned an IPv6 address using the + INTERNAL_IP6_ADDRESS configuration payload. A minimal exchange could + look like this: + + CP(CFG_REQUEST) = + INTERNAL_IP6_ADDRESS() + INTERNAL_IP6_DNS() + TSi = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + TSr = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + + CP(CFG_REPLY) = + INTERNAL_IP6_ADDRESS(2001:DB8:0:1:2:3:4:5/64) + INTERNAL_IP6_DNS(2001:DB8:99:88:77:66:55:44) + TSi = (0, 0-65535, 2001:DB8:0:1:2:3:4:5 - 2001:DB8:0:1:2:3:4:5) + TSr = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + + In particular, IPv6 stateless autoconfiguration or router + advertisement messages are not used; neither is neighbor discovery. + + The client can also send a non-empty INTERNAL_IP6_ADDRESS attribute + in the CFG_REQUEST to request a specific address or interface + identifier. The gateway first checks if the specified address is + acceptable, and if it is, returns that one. If the address was not + acceptable, the gateway will attempt to use the interface identifier + with some other prefix; if even that fails, the gateway will select + another interface identifier. + + The INTERNAL_IP6_ADDRESS attribute also contains a prefix length + field. When used in a CFG_REPLY, this corresponds to the + INTERNAL_IP4_NETMASK attribute in the IPv4 case (and indeed, was + called INTERNAL_IP6_NETMASK in earlier versions of the IKEv2 draft). + See the previous section for more details. + + While this approach to configuring IPv6 addresses is reasonably + simple, it has some limitations: IPsec tunnels configured using IKEv2 + are not fully-featured "interfaces" in the IPv6 addressing + architecture [IPv6Addr] sense. In particular, they do not + necessarily have link-local addresses, and this may complicate the + use of protocols that assume them, such as [MLDv2]. (Whether they + are called "interfaces" in some particular operating system is a + different issue.) + + (References: "VPN remote host configuration IPv6 ?" thread, May 2004. + "Clarifications open issue: INTERNAL_IP4_SUBNET/NETMASK" thread, + April 2005.) + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 41] + +Internet-Draft IKEv2 Clarifications February 2006 + + +6.7. INTERNAL_IP6_NBNS + + Section 3.15.1 defines the INTERNAL_IP6_NBNS attribute for sending + the IPv6 address of NetBIOS name servers. + + However, NetBIOS is not defined for IPv6, and probably never will be. + Thus, this attribute most likely does not make much sense. + + (Pointed out by Bernard Aboba in the IP Configuration Security (ICOS) + BoF at IETF62.) + +6.8. INTERNAL_ADDRESS_EXPIRY + + Section 3.15.1 defines the INTERNAL_ADDRESS_EXPIRY attribute as + "Specifies the number of seconds that the host can use the internal + IP address. The host MUST renew the IP address before this expiry + time. Only one of these attributes MAY be present in the reply." + + Expiry times and explicit renewals are primarily useful in + environments like DHCP, where the server cannot reliably know when + the client has gone away. However, in IKEv2 this is known, and the + gateway can simply free the address when the IKE_SA is deleted. + + Also, Section 4 says that supporting renewals is not mandatory. + Given that this functionality is usually not needed, we recommend + that gateways should not send the INTERNAL_ADDRESS_EXPIRY attribute. + (And since this attribute does not seem to make much sense for + CFG_REQUESTs, clients should not send it either.) + + Note that according to Section 4, clients are required to understand + INTERNAL_ADDRESS_EXPIRY if the receive it. A minimum implementation + would use the value to limit the lifetime of the IKE_SA. + + (References: Tero Kivinen's mail "Comments of + draft-eronen-ipsec-ikev2-clarifications-02.txt", 2005-04-05. + "Questions about internal address" thread, April 2005.) + +6.9. Address assignment failures + + If the responder encounters an error while attempting to assign an IP + address to the initiator, it responds with an + INTERNAL_ADDRESS_FAILURE notification as described in Section 3.10.1. + However, there are some more complex error cases. + + First, if the responder does not support configuration payloads at + all, it can simply ignore all configuration payloads. This type of + implementation never sends INTERNAL_ADDRESS_FAILURE notifications. + If the initiator requires the assignment of an IP address, it will + + + +Eronen & Hoffman Expires August 6, 2006 [Page 42] + +Internet-Draft IKEv2 Clarifications February 2006 + + + treat a response without CFG_REPLY as an error. + + A second case is where the responder does support configuration + payloads, but only for particular type of addresses (IPv4 or IPv6). + Section 4 says that "A minimal IPv4 responder implementation will + ignore the contents of the CP payload except to determine that it + includes an INTERNAL_IP4_ADDRESS attribute". If, for instance, the + initiator includes both INTERNAL_IP4_ADDRESS and INTERNAL_IP6_ADDRESS + in the CFG_REQUEST, an IPv4-only responder can thus simply ignore the + IPv6 part and process the IPv4 request as usual. + + A third case is where the initiator requests multiple addresses of a + type that the responder supports: what should happen if some (but not + all) of the requests fail? It seems that an optimistic approach + would be the best one here: if the responder is able to assign at + least one address, it replies with those; it sends + INTERNAL_ADDRESS_FAILURE only if no addresses can be assigned. + + (References: "ikev2 and internal_ivpn_address" thread, June 2005.) + + +7. Miscellaneous issues + +7.1. Matching ID_IPV4_ADDR and ID_IPV6_ADDR + + When using the ID_IPV4_ADDR/ID_IPV6_ADDR identity types in IDi/IDr + payloads, IKEv2 does not require this address to match the address in + the IP header (of IKEv2 packets), or anything in the TSi/TSr + payloads. The contents of IDi/IDr is used purely to fetch the policy + and authentication data related to the other party. + + (References: "Identities types IP address,FQDN/user FQDN and DN and + its usage in preshared key authentication" thread, Jan 2005.) + +7.2. Relationship of IKEv2 to RFC4301 + + The IKEv2 specification refers to [RFC4301], but it never makes clear + what the exact relationship is. + + However, there are some requirements in the specification that make + it clear that IKEv2 requires [RFC4301]. In other words, an + implementation that does IPsec processing strictly according to + [RFC2401] cannot be compliant with the IKEv2 specification. + + One such example can be found in Section 2.24: "Specifically, tunnel + encapsulators and decapsulators for all tunnel-mode SAs created by + IKEv2 [...] MUST implement the tunnel encapsulation and + decapsulation processing specified in [RFC4301] to prevent discarding + + + +Eronen & Hoffman Expires August 6, 2006 [Page 43] + +Internet-Draft IKEv2 Clarifications February 2006 + + + of ECN congestion indications." + + Nevertheless, the changes required to existing [RFC2401] + implementations are not very large, especially since supporting many + of the new features (such as Extended Sequence Numbers) is optional. + +7.3. Reducing the window size + + In IKEv2, the window size is assumed to be a (possibly configurable) + property of a particular implementation, and is not related to + congestion control (unlike the window size in TCP, for instance). + + In particular, it is not defined what the responder should do when it + receives a SET_WINDOW_SIZE notification containing a smaller value + than is currently in effect. Thus, there is currently no way to + reduce the window size of an existing IKE_SA. However, when rekeying + an IKE_SA, the new IKE_SA starts with window size 1 until it is + explicitly increased by sending a new SET_WINDOW_SIZE notification. + + (References: Tero Kivinen's mail "Comments of + draft-eronen-ipsec-ikev2-clarifications-02.txt", 2005-04-05.) + +7.4. Minimum size of nonces + + Section 2.10 says that "Nonces used in IKEv2 MUST be randomly chosen, + MUST be at least 128 bits in size, and MUST be at least half the key + size of the negotiated prf." + + However, the initiator chooses the nonce before the outcome of the + negotiation is known. In this case, the nonce has to be long enough + for all the PRFs being proposed. + +7.5. Initial zero octets on port 4500 + + It is not clear whether a peer sending an IKE_SA_INIT request on port + 4500 should include the initial four zero octets. Section 2.23 talks + about how to upgrade to tunneling over port 4500 after message 2, but + it does not say what to do if message 1 is sent on port 4500. + + + + + + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 44] + +Internet-Draft IKEv2 Clarifications February 2006 + + + IKE MUST listen on port 4500 as well as port 500. + + [...] + + The IKE initiator MUST check these payloads if present and if + they do not match the addresses in the outer packet MUST tunnel + all future IKE and ESP packets associated with this IKE_SA over + UDP port 4500. + + To tunnel IKE packets over UDP port 4500, the IKE header has four + octets of zero prepended and the result immediately follows the + UDP header. [...] + + The very beginning of Section 2 says "... though IKE messages may + also be received on UDP port 4500 with a slightly different format + (see section 2.23)." + + That "slightly different format" is only described in discussing what + to do after changing to port 4500. However, [RFC3948] shows clearly + the format has the initial zeros even for initiators on port 4500. + Furthermore, without the initial zeros, the processing engine cannot + determine whether the packet is an IKE packet or an ESP packet. + + Thus, all packets sent on port 4500 need the four zero prefix; + otherwise, the receiver won't know how to handle them. + +7.6. Destination port for NAT traversal + + Section 2.23 says that "an IPsec endpoint that discovers a NAT + between it and its correspondent MUST send all subsequent traffic to + and from port 4500". + + This sentence is misleading. The peer "outside" the NAT uses source + port 4500 for the traffic it sends, but the destination port is, of + course, taken from packets sent by the peer behind the NAT. This + port number is usually dynamically allocated by the NAT. + +7.7. SPI values for messages outside of an IKE_SA + + The IKEv2 specification is not quite clear what SPI values should be + used in the IKE header for the small number of notifications that are + allowed to be sent outside of an IKE_SA. Note that such + notifications are explicitly *not* Informational exchanges; Section + 1.5 makes it clear that these are one-way messages that must not be + responded to. + + There are two cases when such a one-way notification can be sent: + INVALID_IKE_SPI and INVALID_SPI. + + + +Eronen & Hoffman Expires August 6, 2006 [Page 45] + +Internet-Draft IKEv2 Clarifications February 2006 + + + In case of INVALID_IKE_SPI, the message sent is a response message, + and Section 2.21 says that "If a response is sent, the response MUST + be sent to the IP address and port from whence it came with the same + IKE SPIs and the Message ID copied." + + In case of INVALID_SPI, however, there are no IKE SPI values that + would be meaningful to the recipient of such a notification. Also, + the message sent is now an INFORMATIONAL request. A strict + interpretation of the specification would require the sender to + invent garbage values for the SPI fields. However, we think this was + not the intention, and using zero values is acceptable. + + (References: "INVALID_IKE_SPI" thread, June 2005.) + +7.8. Protocol ID/SPI fields in Notify payloads + + Section 3.10 says that the Protocol ID field in Notify payloads "For + notifications that do not relate to an existing SA, this field MUST + be sent as zero and MUST be ignored on receipt". However, the + specification does not clearly say which notifications are related to + existing SAs and which are not. + + Since the main purpose of the Protocol ID field is to specify the + type of the SPI, our interpretation is that the Protocol ID field + should be non-zero only when the SPI field is non-empty. + + There are currently only two notifications where this is the case: + INVALID_SELECTORS and REKEY_SA. + +7.9. Which message should contain INITIAL_CONTACT + + The description of the INITIAL_CONTACT notification in Section 3.10.1 + says that "This notification asserts that this IKE_SA is the only + IKE_SA currently active between the authenticated identities". + However, neither Section 2.4 nor 3.10.1 says in which message this + payload should be placed. + + The general agreement is that INITIAL_CONTACT is best communicated in + the first IKE_AUTH request, not as a separate exchange afterwards. + + (References: "Clarifying the use of INITIAL_CONTACT in IKEv2" thread, + April 2005. "Initial Contact messages" thread, December 2004. + "IKEv2 and Initial Contact" thread, September 2004 and April 2005.) + +7.10. Alignment of payloads + + Many IKEv2 payloads contain fields marked as "RESERVED", mostly + because IKEv1 had them, and partly because they make the pictures + + + +Eronen & Hoffman Expires August 6, 2006 [Page 46] + +Internet-Draft IKEv2 Clarifications February 2006 + + + easier to draw. In particular, payloads in IKEv2 are not, in + general, aligned to 4-byte boundaries. (Note that payloads were not + aligned to 4-byte boundaries in IKEv1 either.) + + (References: "IKEv2: potential 4-byte alignment problem" thread, June + 2004.) + +7.11. Key length transform attribute + + Section 3.3.5 says that "The only algorithms defined in this document + that accept attributes are the AES based encryption, integrity, and + pseudo-random functions, which require a single attribute specifying + key width." + + This is incorrect. The AES-based integrity and pseudo-random + functions defined in [IKEv2] always use a 128-bit key. In fact, + there are currently no integrity or PRF algorithms that use the key + length attribute (and we recommend that they should not be defined in + the future either). + + For encryption algorithms, the situation is slightly more complex + since there are three different types of algorithms: + + o The key length attribute is never used with algorithms that use a + fixed length key, such as DES and IDEA. + + o The key length attribute is always included for the currently + defined AES-based algorithms (CBC, CTR, CCM and GCM). Omitting + the key length attribute is not allowed; if the proposal does not + contain it, the proposal has to be rejected. + + o For other algorithms, the key length attribute can be included but + is not mandatory. These algorithms include, e.g., RC5, CAST and + BLOWFISH. If the key length attribute is not included, the + default value specified in [RFC2451] is used. + +7.12. IPsec IANA considerations + + There are currently three different IANA registry files that contain + important numbers for IPsec: ikev2-registry, isakmp-registry, and + ipsec-registry. Implementors should note that IKEv2 may use numbers + different from IKEv1 for a particular algorithm. + + For instance, an encryption algorithm can have up to three different + numbers: the IKEv2 "Transform Type 1" identifier in ikev2-registry, + the IKEv1 phase 1 "Encryption Algorithm" identifier in ipsec- + registry, and the IKEv1 phase 2 "IPSEC ESP Transform Identifier" + isakmp-registry. Although some algorithms have the same number in + + + +Eronen & Hoffman Expires August 6, 2006 [Page 47] + +Internet-Draft IKEv2 Clarifications February 2006 + + + all three registries, the registries are not identical. + + Similarly, an integrity algorithm can have at least the IKEv2 + "Transform Type 3" identifier in ikev2-registry, the IKEv1 phase 2 + "IPSEC AH Transform Identifier" in isakmp-registry, and the IKEv1 + phase 2 ESP "Authentication Algorithm Security Association Attribute" + identifier in isakmp-registry. And there is also the IKEv1 phase 1 + "Hash Algorithm" list in ipsec-registry. + + This issue needs special care also when writing a specification for + how a new algorithm is used together with IPsec. + +7.13. Combining ESP and AH + + The IKEv2 specification contains some misleading text about how ESP + and AH can be combined. + + IKEv2 is based on [RFC4301] which does not include "SA bundles" that + were part of [RFC2401]. While a single packet can go through IPsec + processing multiple times, each of these passes uses a separate SA, + and the passes are coordinated by the forwarding tables. In IKEv2, + each of these SAs has to be created using a separate CREATE_CHILD_SA + exchange. Thus, the text in Section 2.7 about a single proposal + containing both ESP and AH is incorrect. + + Morever, the combination of ESP and AH (between the same endpoints) + become largely obsolete already in 1998 when RFC 2406 was published. + Our recommendation is that IKEv2 implementations should not support + this combination, and implementors should not assume the combination + can be made to work in interoperable manner. + + (References: "Rekeying SA bundles" thread, Oct 2005.) + + +8. Status of the clarifications + + This document is work-in-progress, and it contains both relatively + stable and finished parts, and other parts that are incomplete or + even incorrect. To help the reader in deciding how much weight + should be given to each clarification, this section contains our + opinions about which parts we believe to are stable, and which are + likely to change in future versions. + + Those clarifications believed to be correct and without controversy + are marked with three asterisks (***); those where the clarification + is known to be incomplete and/or there is disagreement about what the + correct interpretation is are marked with one asterisk (*). The + clarifications marked with two asterisks (**) are somewhere between + + + +Eronen & Hoffman Expires August 6, 2006 [Page 48] + +Internet-Draft IKEv2 Clarifications February 2006 + + + the extremes. + + 2. Creating the IKE_SA + 2.1 SPI values in IKE_SA_INIT exchange *** + 2.2 Message IDs for IKE_SA_INIT messages *** + 2.3 Retransmissions of IKE_SA_INIT requests *** + 2.4 Interaction of COOKIE and INVALID_KE_PAYLOAD *** + 2.5 Invalid cookies *** + 3. Authentication + 3.1 Data included in AUTH payload calculation *** + 3.2 Hash function for RSA signatures *** + 3.3 Encoding method for RSA signatures *** + 3.4 Identification type for EAP *** + 3.5 Identity for policy lookups when using EAP *** + 3.6 (Section removed) + 3.7 Certificate encoding types *** + 3.8 Shared key authentication and fixed PRF key size *** + 3.9 EAP authentication and fixed PRF key size *** + 3.10 Matching ID payloads to certificate contents *** + 3.11 Message IDs for IKE_AUTH messages *** + 4. Creating CHILD_SAs + 4.1 Creating SAs with the CREATE_CHILD_SA exchange ** + 4.2 Creating an IKE_SA without a CHILD_SA *** + 4.3 Diffie-Hellman for first CHILD_SA *** + 4.4 Extended Sequence Numbers (ESN) transform *** + 4.5 Negotiation of ESP_TFC_PADDING_NOT_SUPPORTED *** + 4.6 Negotiation of NON_FIRST_FRAGMENTS_ALSO *** + 4.7 Semantics of complex traffic selector payloads *** + 4.8 ICMP type/code in traffic selector payloads *** + 4.9 Mobility header in traffic selector payloads *** + 4.10 Narrowing the traffic selectors *** + 4.11 SINGLE_PAIR_REQUIRED *** + 4.12 Traffic selectors violating own policy *** + 5. Rekeying and deleting SAs + 5.1 Rekeying SAs with the CREATE_CHILD_SA exchange ** + 5.2 Rekeying the IKE_SA vs. reauthentication *** + 5.3 SPIs when rekeying the IKE_SA *** + 5.4 SPI when rekeying a CHILD_SA *** + 5.5 Changing PRFs when rekeying the IKE_SA *** + 5.6 Deleting vs. closing SAs *** + 5.7 Deleting an SA pair *** + 5.8 Deleting an IKE_SA *** + 5.9 Who is the original initiator of IKE_SA *** + 5.10 (Section removed) + 5.11 Comparing nonces *** + 5.12 Exchange collisions * + 5.13 Diffie-Hellman and rekeying the IKE_SA ** + 6. Configuration payloads + + + +Eronen & Hoffman Expires August 6, 2006 [Page 49] + +Internet-Draft IKEv2 Clarifications February 2006 + + + 6.1 Assigning IP addresses *** + 6.2 (Section removed) + 6.3 Requesting any INTERNAL_IP4/IP6_ADDRESS *** + 6.4 INTERNAL_IP4_SUBNET/INTERNAL_IP6_SUBNET *** + 6.5 INTERNAL_IP4_NETMASK ** + 6.6 Configuration payloads for IPv6 ** + 6.7 INTERNAL_IP6_NBNS *** + 6.8 INTERNAL_ADDRESS_EXPIRY *** + 6.9 Address assignment failures ** + 7. Miscellaneous issues + 7.1 Matching ID_IPV4_ADDR and ID_IPV6_ADDR *** + 7.2 Relationship of IKEv2 to RFC4301 *** + 7.3 Reducing the window size *** + 7.4 Minimum size of nonces *** + 7.5 Initial zero octets on port 4500 *** + 7.6 Destination port for NAT traversal *** + 7.7 SPI values for messages outside of an IKE_SA *** + 7.8 Protocol ID/SPI fields in Notify payloads *** + 7.9 Which message should contain INITIAL_CONTACT *** + 7.10 Alignment of payloads *** + 7.11 Key length transform attribute *** + 7.12 IPsec IANA considerations ** + 7.13 Combining ESP and AH * + + Future versions of this document will, of course, change these + estimates (and changes in both directions are possible, though + hopefully it's more towards higher confidence). + + +9. Implementation mistakes + + Some implementers at the early IKEv2 bakeoffs didn't do everything + correctly. This may seem like an obvious statement, but it is + probably useful to list a few things that were clear in the document + and not needing clarification, that some implementors didn't do. All + of these things caused interoperability problems. + + o Some implementations continued to send traffic on a CHILD_SA after + it was rekeyed, even after receiving an DELETE payload. + + o After rekeying an IKE_SA, some implementations did not reset their + message counters to zero. One set the counter to 2, another did + not reset the counter at all. + + o Some implementations could only handle a single pair of traffic + selectors, or would only process the first pair in the proposal. + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 50] + +Internet-Draft IKEv2 Clarifications February 2006 + + + o Some implementations responded to a delete request by sending an + empty INFORMATIONAL response, and then initiated their own + INFORMATIONAL exchange with the pair of SAs to delete. + + o Although this did not happen at the bakeoff, from the discussion + there, it is clear that some people had not implemented message + window sizes correctly. Some implementations might have sent + messages that did not fit into the responder's message windows, + and some implementations may not have torn down an SA if they did + not ever receive a message that they know they should have. + + +10. Security considerations + + This document does not introduce any new security considerations to + IKEv2. If anything, clarifying complex areas of the specification + can reduce the likelihood of implementation problems that may have + security implications. + + +11. IANA considerations + + This document does not change or create any IANA-registered values. + + +12. Acknowledgments + + This document is mainly based on conversations on the IPsec WG + mailing list. The authors would especially like to thank Bernard + Aboba, Jari Arkko, Vijay Devarapalli, William Dixon, Francis Dupont, + Mika Joutsenvirta, Charlie Kaufman, Stephen Kent, Tero Kivinen, Yoav + Nir, Michael Richardson, and Joel Snyder for their contributions. + + In addition, the authors would like to thank all the participants of + the first public IKEv2 bakeoff, held in Santa Clara in February 2005, + for their questions and proposed clarifications. + + +13. References + +13.1. Normative References + + [IKEv2] Kaufman, C., Ed., "Internet Key Exchange (IKEv2) + Protocol", RFC 4306, December 2005. + + [IKEv2ALG] + Schiller, J., "Cryptographic Algorithms for Use in the + Internet Key Exchange Version 2 (IKEv2)", RFC 4307, + + + +Eronen & Hoffman Expires August 6, 2006 [Page 51] + +Internet-Draft IKEv2 Clarifications February 2006 + + + December 2005. + + [PKCS1v20] + Kaliski, B. and J. Staddon, "PKCS #1: RSA Cryptography + Specifications Version 2.0", RFC 2437, October 1998. + + [PKCS1v21] + Jonsson, J. and B. Kaliski, "Public-Key Cryptography + Standards (PKCS) #1: RSA Cryptography Specifications + Version 2.1", RFC 3447, February 2003. + + [RFC2401] Kent, S. and R. Atkinson, "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + [RFC4301] Kent, S. and K. Seo, "Security Architecture for the + Internet Protocol", RFC 4301, December 2005. + +13.2. Informative References + + [EAP] Aboba, B., Blunk, L., Vollbrecht, J., Carlson, J., and H. + Levkowetz, "Extensible Authentication Protocol (EAP)", + RFC 3748, June 2004. + + [HashUse] Hoffman, P., "Use of Hash Algorithms in IKE and IPsec", + draft-hoffman-ike-ipsec-hash-use-01 (work in progress), + December 2005. + + [IPCPSubnet] + Cisco Systems, Inc., "IPCP Subnet Mask Support + Enhancements", http://www.cisco.com/univercd/cc/td/doc/ + product/software/ios121/121newft/121limit/121dc/121dc3/ + ipcp_msk.htm, January 2003. + + [IPv6Addr] + Hinden, R. and S. Deering, "Internet Protocol Version 6 + (IPv6) Addressing Architecture", RFC 3513, April 2004. + + [MIPv6] Johnson, D., Perkins, C., and J. Arkko, "Mobility Support + in IPv6", RFC 3775, June 2004. + + [MLDv2] Vida, R. and L. Costa, "Multicast Listener Discovery + Version 2 (MLDv2) for IPv6", RFC 3810, June 2004. + + [NAI] Aboba, B., Beadles, M., Arkko, J., and P. Eronen, "The + Network Access Identifier", RFC 4282, December 2005. + + [RADEAP] Aboba, B. and P. Calhoun, "RADIUS (Remote Authentication + Dial In User Service) Support For Extensible + + + +Eronen & Hoffman Expires August 6, 2006 [Page 52] + +Internet-Draft IKEv2 Clarifications February 2006 + + + Authentication Protocol (EAP)", RFC 3579, September 2003. + + [RADIUS] Rigney, C., Willens, S., Rubens, A., and W. Simpson, + "Remote Authentication Dial In User Service (RADIUS)", + RFC 2865, June 2000. + + [RADIUS6] Aboba, B., Zorn, G., and D. Mitton, "RADIUS and IPv6", + RFC 3162, August 2001. + + [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate + Requirement Levels", RFC 2119, March 1997. + + [RFC2451] Pereira, R. and R. Adams, "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + [RFC2822] Resnick, P., "Internet Message Format", RFC 2822, + April 2001. + + [RFC3664] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the + Internet Key Exchange Protocol (IKE)", RFC 3664, + January 2004. + + [RFC3664bis] + Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the + Internet Key Exchange Protocol (IKE)", + draft-hoffman-rfc3664bis (work in progress), October 2005. + + [RFC3948] Huttunen, A., Swander, B., Volpe, V., DiBurro, L., and M. + Stenberg, "UDP Encapsulation of IPsec ESP Packets", + RFC 3948, January 2005. + + [RFC822] Crocker, D., "Standard for the format of ARPA Internet + text messages", RFC 822, August 1982. + + [ReAuth] Nir, Y., "Repeated Authentication in IKEv2", + draft-nir-ikev2-auth-lt-03 (work in progress), + November 2005. + + [SCVP] Freeman, T., Housley, R., Malpani, A., Cooper, D., and T. + Polk, "Simple Certificate Validation Protocol (SCVP)", + draft-ietf-pkix-scvp-21 (work in progress), October 2005. + + +Appendix A. Exchanges and payloads + + This appendix contains a short summary of the IKEv2 exchanges, and + what payloads can appear in which message. This appendix is purely + informative; if it disagrees with the body of this document or the + + + +Eronen & Hoffman Expires August 6, 2006 [Page 53] + +Internet-Draft IKEv2 Clarifications February 2006 + + + IKEv2 specification, the other text is considered correct. + + Vendor-ID (V) payloads may be included in any place in any message. + This sequence shows what are, in our opinion, the most logical places + for them. + + The specification does not say which messages can contain + N(SET_WINDOW_SIZE). It can possibly be included in any message, but + it is not yet shown below. + +A.1. IKE_SA_INIT exchange + + request --> [N(COOKIE)], + SA, KE, Ni, + [N(NAT_DETECTION_SOURCE_IP)+, + N(NAT_DETECTION_DESTINATION_IP)], + [V+] + + normal response <-- SA, KE, Nr, + (no cookie) [N(NAT_DETECTION_SOURCE_IP), + N(NAT_DETECTION_DESTINATION_IP)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [V+] + +A.2. IKE_AUTH exchange without EAP + + request --> IDi, [CERT+], + [N(INITIAL_CONTACT)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [IDr], + AUTH, + [CP(CFG_REQUEST)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [V+] + + response <-- IDr, [CERT+], + AUTH, + [CP(CFG_REPLY)], + [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)], + + + +Eronen & Hoffman Expires August 6, 2006 [Page 54] + +Internet-Draft IKEv2 Clarifications February 2006 + + + [V+] + +A.3. IKE_AUTH exchange with EAP + + first request --> IDi, + [N(INITIAL_CONTACT)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [IDr], + [CP(CFG_REQUEST)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [V+] + + first response <-- IDr, [CERT+], AUTH, + EAP, + [V+] + + / --> EAP + repeat 1..N times | + \ <-- EAP + + last request --> AUTH + + last response <-- AUTH, + [CP(CFG_REPLY)], + [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)], + [V+] + + + + + + + + + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 55] + +Internet-Draft IKEv2 Clarifications February 2006 + + +A.4. CREATE_CHILD_SA exchange for creating/rekeying CHILD_SAs + + request --> [N(REKEY_SA)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, Ni, [KEi], TSi, TSr + + response <-- [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, Nr, [KEr], TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)] + +A.5. CREATE_CHILD_SA exchange for rekeying the IKE_SA + + request --> SA, Ni, [KEi] + + response <-- SA, Nr, [KEr] + +A.6. INFORMATIONAL exchange + + request --> [N+], + [D+], + [CP(CFG_REQUEST)] + + response <-- [N+], + [D+], + [CP(CFG_REPLY)] + + + + + + + + + + + + + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 56] + +Internet-Draft IKEv2 Clarifications February 2006 + + +Authors' Addresses + + Pasi Eronen + Nokia Research Center + P.O. Box 407 + FIN-00045 Nokia Group + Finland + + Email: pasi.eronen@nokia.com + + + Paul Hoffman + VPN Consortium + 127 Segre Place + Santa Cruz, CA 95060 + USA + + Email: paul.hoffman@vpnc.org + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 57] + +Internet-Draft IKEv2 Clarifications February 2006 + + +Intellectual Property Statement + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at + ietf-ipr@ietf.org. + + +Disclaimer of Validity + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + +Copyright Statement + + Copyright (C) The Internet Society (2006). This document is subject + to the rights, licenses and restrictions contained in BCP 78, and + except as set forth therein, the authors retain all their rights. + + +Acknowledgment + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + +Eronen & Hoffman Expires August 6, 2006 [Page 58] + diff --git a/doc/ikev2/[IKEv2Draft] - Internet Key Exchange (IKEv2) Protocol Draft v17.txt b/doc/ikev2/[IKEv2Draft] - Internet Key Exchange (IKEv2) Protocol Draft v17.txt new file mode 100644 index 000000000..c1493c197 --- /dev/null +++ b/doc/ikev2/[IKEv2Draft] - Internet Key Exchange (IKEv2) Protocol Draft v17.txt @@ -0,0 +1,6535 @@ + + +INTERNET-DRAFT Charlie Kaufman, Editor +draft-ietf-ipsec-ikev2-17.txt +Obsoletes: 2407, 2408, 2409 September 23, 2004 +Expires: March 2005 + + + Internet Key Exchange (IKEv2) Protocol + + +Status of this Memo + + This document is an Internet-Draft and is subject to all provisions + of Section 10 of RFC2026. Internet-Drafts are working documents of + the Internet Engineering Task Force (IETF), its areas, and its + working groups. Note that other groups may also distribute working + documents as Internet-Drafts. + + Internet-Drafts are draft documents valid for a maximum of six months + and may be updated, replaced, or obsoleted by other documents at any + time. It is inappropriate to use Internet-Drafts as reference + material or to cite them other than as "work in progress." + + The list of current Internet-Drafts can be accessed at + http://www.ietf.org/1id-abstracts.html + + The list of Internet-Draft Shadow Directories can be accessed at + http://www.ietf.org/shadow.html + + This document is a submission by the IPSEC Working Group of the + Internet Engineering Task Force (IETF). Comments should be submitted + to the ipsec@lists.tislabs.com mailing list. + + Distribution of this memo is unlimited. + + This Internet-Draft expires in March 2005. + +Copyright Notice + + Copyright (C) The Internet Society (2004). All Rights Reserved. + +Abstract + + This document describes version 2 of the Internet Key Exchange (IKE) + protocol. IKE is a component of IPsec used for performing mutual + authentication and establishing and maintaining security associations + (SAs). + + This version of the IKE specification combines the contents of what + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 1] + + + + + +Internet-Draft September 23, 2004 + + + were previously separate documents, including ISAKMP (RFC 2408), IKE + (RFC 2409), the Internet DOI (RFC 2407), NAT Traversal, Legacy + authentication, and remote address acquisition. + + Version 2 of IKE does not interoperate with version 1, but it has + enough of the header format in common that both versions can + unambiguously run over the same UDP port. + +Table of Contents + + + 1 Introduction...............................................3 + 1.1 Usage Scenarios..........................................5 + 1.2 The Initial Exchanges....................................7 + 1.3 The CREATE_CHILD_SA Exchange.............................9 + 1.4 The INFORMATIONAL Exchange..............................10 + 1.5 Informational Messages outside of an IKE_SA.............12 + 2 IKE Protocol Details and Variations.......................12 + 2.1 Use of Retransmission Timers............................13 + 2.2 Use of Sequence Numbers for Message ID..................13 + 2.3 Window Size for overlapping requests....................14 + 2.4 State Synchronization and Connection Timeouts...........15 + 2.5 Version Numbers and Forward Compatibility...............16 + 2.6 Cookies.................................................18 + 2.7 Cryptographic Algorithm Negotiation.....................20 + 2.8 Rekeying................................................21 + 2.9 Traffic Selector Negotiation............................23 + 2.10 Nonces.................................................25 + 2.11 Address and Port Agility...............................26 + 2.12 Reuse of Diffie-Hellman Exponentials...................26 + 2.13 Generating Keying Material.............................27 + 2.14 Generating Keying Material for the IKE_SA..............28 + 2.15 Authentication of the IKE_SA...........................29 + 2.16 Extensible Authentication Protocol Methods.............30 + 2.17 Generating Keying Material for CHILD_SAs...............32 + 2.18 Rekeying IKE_SAs using a CREATE_CHILD_SA exchange......33 + 2.19 Requesting an internal address on a remote network.....33 + 2.20 Requesting a Peer's Version............................35 + 2.21 Error Handling.........................................35 + 2.22 IPComp.................................................36 + 2.23 NAT Traversal..........................................37 + 2.24 ECN (Explicit Congestion Notification).................40 + 3 Header and Payload Formats................................40 + 3.1 The IKE Header..........................................40 + 3.2 Generic Payload Header..................................43 + 3.3 Security Association Payload............................44 + 3.4 Key Exchange Payload....................................54 + 3.5 Identification Payloads.................................55 + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 2] + + + + + +Internet-Draft September 23, 2004 + + + 3.6 Certificate Payload.....................................57 + 3.7 Certificate Request Payload.............................60 + 3.8 Authentication Payload..................................62 + 3.9 Nonce Payload...........................................62 + 3.10 Notify Payload.........................................63 + 3.11 Delete Payload.........................................71 + 3.12 Vendor ID Payload......................................72 + 3.13 Traffic Selector Payload...............................73 + 3.14 Encrypted Payload......................................76 + 3.15 Configuration Payload..................................77 + 3.16 Extensible Authentication Protocol (EAP) Payload.......82 + 4 Conformance Requirements..................................84 + 5 Security Considerations...................................86 + 6 IANA Considerations.......................................89 + 7 Acknowledgements..........................................89 + 8 References................................................90 + 8.1 Normative References....................................90 + 8.2 Informative References..................................91 + Appendix A: Summary of Changes from IKEv1...................94 + Appendix B: Diffie-Hellman Groups...........................96 + Change History (To be removed from RFC).....................97 + Editor's Address...........................................108 + Full Copyright Statement...................................108 + Intellectual Property Statement............................108 + +Requirements Terminology + + Keywords "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT" and + "MAY" that appear in this document are to be interpreted as described + in [Bra97]. + + The term "Expert Review" is to be interpreted as defined in + [RFC2434]. + +1 Introduction + + IP Security (IPsec) provides confidentiality, data integrity, access + control, and data source authentication to IP datagrams. These + services are provided by maintaining shared state between the source + and the sink of an IP datagram. This state defines, among other + things, the specific services provided to the datagram, which + cryptographic algorithms will be used to provide the services, and + the keys used as input to the cryptographic algorithms. + + Establishing this shared state in a manual fashion does not scale + well. Therefore a protocol to establish this state dynamically is + needed. This memo describes such a protocol-- the Internet Key + Exchange (IKE). This is version 2 of IKE. Version 1 of IKE was + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 3] + + + + + +Internet-Draft September 23, 2004 + + + defined in RFCs 2407, 2408, and 2409. This single document is + intended to replace all three of those RFCs. + + Definitions of the primitive terms in this document (such as Security + Association or SA) can be found in [RFC2401bis]. + + IKE performs mutual authentication between two parties and + establishes an IKE security association (SA) that includes shared + secret information that can be used to efficiently establish SAs for + ESP [RFC2406] and/or AH [RFC2402] and a set of cryptographic + algorithms to be used by the SAs to protect the traffic that they + carry. In this document, the term "suite" or "cryptographic suite" + refers to a complete set of algorithms used to protect an SA. An + initiator proposes one or more suites by listing supported algorithms + that can be combined into suites in a mix and match fashion. IKE can + also negotiate use of IPComp [IPCOMP] in connection with an ESP + and/or AH SA. We call the IKE SA an "IKE_SA". The SAs for ESP and/or + AH that get set up through that IKE_SA we call "CHILD_SA"s. + + All IKE communications consist of pairs of messages: a request and a + response. The pair is called an "exchange". We call the first + messages establishing an IKE_SA IKE_SA_INIT and IKE_AUTH exchanges + and subsequent IKE exchanges CREATE_CHILD_SA or INFORMATIONAL + exchanges. In the common case, there is a single IKE_SA_INIT exchange + and a single IKE_AUTH exchange (a total of four messages) to + establish the IKE_SA and the first CHILD_SA. In exceptional cases, + there may be more than one of each of these exchanges. In all cases, + all IKE_SA_INIT exchanges MUST complete before any other exchange + type, then all IKE_AUTH exchanges MUST complete, and following that + any number of CREATE_CHILD_SA and INFORMATIONAL exchanges may occur + in any order. In some scenarios, only a single CHILD_SA is needed + between the IPsec endpoints and therefore there would be no + additional exchanges. Subsequent exchanges MAY be used to establish + additional CHILD_SAs between the same authenticated pair of endpoints + and to perform housekeeping functions. + + IKE message flow always consists of a request followed by a response. + It is the responsibility of the requester to ensure reliability. If + the response is not received within a timeout interval, the requester + needs to retransmit the request (or abandon the connection). + + The first request/response of an IKE session (IKE_SA_INIT) negotiates + security parameters for the IKE_SA, sends nonces, and sends Diffie- + Hellman values. + + The second request/response (IKE_AUTH) transmits identities, proves + knowledge of the secrets corresponding to the two identities, and + sets up an SA for the first (and often only) AH and/or ESP CHILD_SA. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 4] + + + + + +Internet-Draft September 23, 2004 + + + The types of subsequent exchanges are CREATE_CHILD_SA (which creates + a CHILD_SA), and INFORMATIONAL (which deletes an SA, reports error + conditions, or does other housekeeping). Every request requires a + response. An INFORMATIONAL request with no payloads (other than the + empty Encrypted payload required by the syntax) is commonly used as a + check for liveness. These subsequent exchanges cannot be used until + the initial exchanges have completed. + + In the description that follows, we assume that no errors occur. + Modifications to the flow should errors occur are described in + section 2.21. + +1.1 Usage Scenarios + + IKE is expected to be used to negotiate ESP and/or AH SAs in a number + of different scenarios, each with its own special requirements. + +1.1.1 Security Gateway to Security Gateway Tunnel + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! + Protected !Tunnel ! Tunnel !Tunnel ! Protected + Subnet <-->!Endpoint !<---------->!Endpoint !<--> Subnet + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 1: Security Gateway to Security Gateway Tunnel + + In this scenario, neither endpoint of the IP connection implements + IPsec, but network nodes between them protect traffic for part of the + way. Protection is transparent to the endpoints, and depends on + ordinary routing to send packets through the tunnel endpoints for + processing. Each endpoint would announce the set of addresses + "behind" it, and packets would be sent in Tunnel Mode where the inner + IP header would contain the IP addresses of the actual endpoints. + +1.1.2 Endpoint to Endpoint Transport + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec Transport ! ! + !Protected! or Tunnel Mode SA !Protected! + !Endpoint !<---------------------------------------->!Endpoint ! + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 2: Endpoint to Endpoint + + In this scenario, both endpoints of the IP connection implement + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 5] + + + + + +Internet-Draft September 23, 2004 + + + IPsec, as required of hosts in [RFC2401bis]. Transport mode will + commonly be used with no inner IP header. If there is an inner IP + header, the inner addresses will be the same as the outer addresses. + A single pair of addresses will be negotiated for packets to be + protected by this SA. These endpoints MAY implement application layer + access controls based on the IPsec authenticated identities of the + participants. This scenario enables the end-to-end security that has + been a guiding principle for the Internet since [RFC1958], [RFC2775], + and a method of limiting the inherent problems with complexity in + networks noted by [RFC3439]. While this scenario may not be fully + applicable to the IPv4 Internet, it has been deployed successfully in + specific scenarios within intranets using IKEv1. It should be more + broadly enabled during the transition to IPv6 and with the adoption + of IKEv2. + + It is possible in this scenario that one or both of the protected + endpoints will be behind a network address translation (NAT) node, in + which case the tunneled packets will have to be UDP encapsulated so + that port numbers in the UDP headers can be used to identify + individual endpoints "behind" the NAT (see section 2.23). + +1.1.3 Endpoint to Security Gateway Transport + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! Protected + !Protected! Tunnel !Tunnel ! Subnet + !Endpoint !<------------------------>!Endpoint !<--- and/or + ! ! ! ! Internet + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 3: Endpoint to Security Gateway Tunnel + + In this scenario, a protected endpoint (typically a portable roaming + computer) connects back to its corporate network through an IPsec + protected tunnel. It might use this tunnel only to access information + on the corporate network or it might tunnel all of its traffic back + through the corporate network in order to take advantage of + protection provided by a corporate firewall against Internet based + attacks. In either case, the protected endpoint will want an IP + address associated with the security gateway so that packets returned + to it will go to the security gateway and be tunneled back. This IP + address may be static or may be dynamically allocated by the security + gateway. In support of the latter case, IKEv2 includes a mechanism + for the initiator to request an IP address owned by the security + gateway for use for the duration of its SA. + + In this scenario, packets will use tunnel mode. On each packet from + the protected endpoint, the outer IP header will contain the source + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 6] + + + + + +Internet-Draft September 23, 2004 + + + IP address associated with its current location (i.e., the address + that will get traffic routed to the endpoint directly) while the + inner IP header will contain the source IP address assigned by the + security gateway (i.e., the address that will get traffic routed to + the security gateway for forwarding to the endpoint). The outer + destination address will always be that of the security gateway, + while the inner destination address will be the ultimate destination + for the packet. + + In this scenario, it is possible that the protected endpoint will be + behind a NAT. In that case, the IP address as seen by the security + gateway will not be the same as the IP address sent by the protected + endpoint, and packets will have to be UDP encapsulated in order to be + routed properly. + +1.1.4 Other Scenarios + + Other scenarios are possible, as are nested combinations of the + above. One notable example combines aspects of 1.1.1 and 1.1.3. A + subnet may make all external accesses through a remote security + gateway using an IPsec tunnel, where the addresses on the subnet are + routed to the security gateway by the rest of the Internet. An + example would be someone's home network being virtually on the + Internet with static IP addresses even though connectivity is + provided by an ISP that assigns a single dynamically assigned IP + address to the user's security gateway (where the static IP addresses + and an IPsec relay is provided by a third party located elsewhere). + +1.2 The Initial Exchanges + + Communication using IKE always begins with IKE_SA_INIT and IKE_AUTH + exchanges (known in IKEv1 as Phase 1). These initial exchanges + normally consist of four messages, though in some scenarios that + number can grow. All communications using IKE consist of + request/response pairs. We'll describe the base exchange first, + followed by variations. The first pair of messages (IKE_SA_INIT) + negotiate cryptographic algorithms, exchange nonces, and do a Diffie- + Hellman exchange. + + The second pair of messages (IKE_AUTH) authenticate the previous + messages, exchange identities and certificates, and establish the + first CHILD_SA. Parts of these messages are encrypted and integrity + protected with keys established through the IKE_SA_INIT exchange, so + the identities are hidden from eavesdroppers and all fields in all + the messages are authenticated. + + In the following description, the payloads contained in the message + are indicated by names such as SA. The details of the contents of + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 7] + + + + + +Internet-Draft September 23, 2004 + + + each payload are described later. Payloads which may optionally + appear will be shown in brackets, such as [CERTREQ], would indicate + that optionally a certificate request payload can be included. + + The initial exchanges are as follows: + + Initiator Responder + ----------- ----------- + HDR, SAi1, KEi, Ni --> + + HDR contains the SPIs, version numbers, and flags of various sorts. + The SAi1 payload states the cryptographic algorithms the initiator + supports for the IKE_SA. The KE payload sends the initiator's + Diffie-Hellman value. Ni is the initiator's nonce. + + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + + The responder chooses a cryptographic suite from the initiator's + offered choices and expresses that choice in the SAr1 payload, + completes the Diffie-Hellman exchange with the KEr payload, and sends + its nonce in the Nr payload. + + At this point in the negotiation each party can generate SKEYSEED, + from which all keys are derived for that IKE_SA. All but the headers + of all the messages that follow are encrypted and integrity + protected. The keys used for the encryption and integrity protection + are derived from SKEYSEED and are known as SK_e (encryption) and SK_a + (authentication, a.k.a. integrity protection). A separate SK_e and + SK_a is computed for each direction. In addition to the keys SK_e + and SK_a derived from the DH value for protection of the IKE_SA, + another quantity SK_d is derived and used for derivation of further + keying material for CHILD_SAs. The notation SK { ... } indicates + that these payloads are encrypted and integrity protected using that + direction's SK_e and SK_a. + + HDR, SK {IDi, [CERT,] [CERTREQ,] [IDr,] + AUTH, SAi2, TSi, TSr} --> + + The initiator asserts its identity with the IDi payload, proves + knowledge of the secret corresponding to IDi and integrity protects + the contents of the first message using the AUTH payload (see section + 2.15). It might also send its certificate(s) in CERT payload(s) and + a list of its trust anchors in CERTREQ payload(s). If any CERT + payloads are included, the first certificate provided MUST contain + the public key used to verify the AUTH field. The optional payload + IDr enables the initiator to specify which of the responder's + identities it wants to talk to. This is useful when the machine on + which the responder is running is hosting multiple identities at the + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 8] + + + + + +Internet-Draft September 23, 2004 + + + same IP address. The initiator begins negotiation of a CHILD_SA + using the SAi2 payload. The final fields (starting with SAi2) are + described in the description of the CREATE_CHILD_SA exchange. + + <-- HDR, SK {IDr, [CERT,] AUTH, + SAr2, TSi, TSr} + + The responder asserts its identity with the IDr payload, optionally + sends one or more certificates (again with the certificate containing + the public key used to verify AUTH listed first), authenticates its + identity and protects the integrity of the second message with the + AUTH payload, and completes negotiation of a CHILD_SA with the + additional fields described below in the CREATE_CHILD_SA exchange. + + The recipients of messages 3 and 4 MUST verify that all signatures + and MACs are computed correctly and that the names in the ID payloads + correspond to the keys used to generate the AUTH payload. + +1.3 The CREATE_CHILD_SA Exchange + + This exchange consists of a single request/response pair, and was + referred to as a phase 2 exchange in IKEv1. It MAY be initiated by + either end of the IKE_SA after the initial exchanges are completed. + + All messages following the initial exchange are cryptographically + protected using the cryptographic algorithms and keys negotiated in + the first two messages of the IKE exchange. These subsequent + messages use the syntax of the Encrypted Payload described in section + 3.14. All subsequent messages included an Encrypted Payload, even if + they are referred to in the text as "empty". + + Either endpoint may initiate a CREATE_CHILD_SA exchange, so in this + section the term initiator refers to the endpoint initiating this + exchange. + + A CHILD_SA is created by sending a CREATE_CHILD_SA request. The + CREATE_CHILD_SA request MAY optionally contain a KE payload for an + additional Diffie-Hellman exchange to enable stronger guarantees of + forward secrecy for the CHILD_SA. The keying material for the + CHILD_SA is a function of SK_d established during the establishment + of the IKE_SA, the nonces exchanged during the CREATE_CHILD_SA + exchange, and the Diffie-Hellman value (if KE payloads are included + in the CREATE_CHILD_SA exchange). + + In the CHILD_SA created as part of the initial exchange, a second KE + payload and nonce MUST NOT be sent. The nonces from the initial + exchange are used in computing the keys for the CHILD_SA. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 9] + + + + + +Internet-Draft September 23, 2004 + + + The CREATE_CHILD_SA request contains: + + Initiator Responder + ----------- ----------- + HDR, SK {[N], SA, Ni, [KEi], + [TSi, TSr]} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, optionally a Diffie-Hellman value in the KEi payload, and + the proposed traffic selectors in the TSi and TSr payloads. If this + CREATE_CHILD_SA exchange is rekeying an existing SA other than the + IKE_SA, the leading N payload of type REKEY_SA MUST identify the SA + being rekeyed. If this CREATE_CHILD_SA exchange is not rekeying an + existing SA, the N payload MUST be omitted. If the SA offers include + different Diffie-Hellman groups, KEi MUST be an element of the group + the initiator expects the responder to accept. If it guesses wrong, + the CREATE_CHILD_SA exchange will fail and it will have to retry with + a different KEi. + + The message following the header is encrypted and the message + including the header is integrity protected using the cryptographic + algorithms negotiated for the IKE_SA. + + The CREATE_CHILD_SA response contains: + + <-- HDR, SK {SA, Nr, [KEr], + [TSi, TSr]} + + The responder replies (using the same Message ID to respond) with the + accepted offer in an SA payload, and a Diffie-Hellman value in the + KEr payload if KEi was included in the request and the selected + cryptographic suite includes that group. If the responder chooses a + cryptographic suite with a different group, it MUST reject the + request. The initiator SHOULD repeat the request, but now with a KEi + payload from the group the responder selected. + + The traffic selectors for traffic to be sent on that SA are specified + in the TS payloads, which may be a subset of what the initiator of + the CHILD_SA proposed. Traffic selectors are omitted if this + CREATE_CHILD_SA request is being used to change the key of the + IKE_SA. + +1.4 The INFORMATIONAL Exchange + + At various points during the operation of an IKE_SA, peers may desire + to convey control messages to each other regarding errors or + notifications of certain events. To accomplish this IKE defines an + INFORMATIONAL exchange. INFORMATIONAL exchanges MUST ONLY occur + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 10] + + + + + +Internet-Draft September 23, 2004 + + + after the initial exchanges and are cryptographically protected with + the negotiated keys. + + Control messages that pertain to an IKE_SA MUST be sent under that + IKE_SA. Control messages that pertain to CHILD_SAs MUST be sent under + the protection of the IKE_SA which generated them (or its successor + if the IKE_SA was replaced for the purpose of rekeying). + + Messages in an INFORMATIONAL Exchange contain zero or more + Notification, Delete, and Configuration payloads. The Recipient of an + INFORMATIONAL Exchange request MUST send some response (else the + Sender will assume the message was lost in the network and will + retransmit it). That response MAY be a message with no payloads. The + request message in an INFORMATIONAL Exchange MAY also contain no + payloads. This is the expected way an endpoint can ask the other + endpoint to verify that it is alive. + + ESP and AH SAs always exist in pairs, with one SA in each direction. + When an SA is closed, both members of the pair MUST be closed. When + SAs are nested, as when data (and IP headers if in tunnel mode) are + encapsulated first with IPComp, then with ESP, and finally with AH + between the same pair of endpoints, all of the SAs MUST be deleted + together. Each endpoint MUST close its incoming SAs and allow the + other endpoint to close the other SA in each pair. To delete an SA, + an INFORMATIONAL Exchange with one or more delete payloads is sent + listing the SPIs (as they would be expected in the headers of inbound + packets) of the SAs to be deleted. The recipient MUST close the + designated SAs. Normally, the reply in the INFORMATIONAL Exchange + will contain delete payloads for the paired SAs going in the other + direction. There is one exception. If by chance both ends of a set + of SAs independently decide to close them, each may send a delete + payload and the two requests may cross in the network. If a node + receives a delete request for SAs for which it has already issued a + delete request, it MUST delete the outgoing SAs while processing the + request and the incoming SAs while processing the response. In that + case, the responses MUST NOT include delete payloads for the deleted + SAs, since that would result in duplicate deletion and could in + theory delete the wrong SA. + + A node SHOULD regard half closed connections as anomalous and audit + their existence should they persist. Note that this specification + nowhere specifies time periods, so it is up to individual endpoints + to decide how long to wait. A node MAY refuse to accept incoming data + on half closed connections but MUST NOT unilaterally close them and + reuse the SPIs. If connection state becomes sufficiently messed up, a + node MAY close the IKE_SA which will implicitly close all SAs + negotiated under it. It can then rebuild the SAs it needs on a clean + base under a new IKE_SA. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 11] + + + + + +Internet-Draft September 23, 2004 + + + The INFORMATIONAL Exchange is defined as: + + Initiator Responder + ----------- ----------- + HDR, SK {[N,] [D,] [CP,] ...} --> + <-- HDR, SK {[N,] [D,] [CP], ...} + + The processing of an INFORMATIONAL Exchange is determined by its + component payloads. + +1.5 Informational Messages outside of an IKE_SA + + If an encrypted IKE packet arrives on port 500 or 4500 with an + unrecognized SPI, it could be because the receiving node has recently + crashed and lost state or because of some other system malfunction or + attack. If the receiving node has an active IKE_SA to the IP address + from whence the packet came, it MAY send a notification of the + wayward packet over that IKE_SA in an informational exchange. If it + does not have such an IKE_SA, it MAY send an Informational message + without cryptographic protection to the source IP address. Such a + message is not part of an informational exchange, and the receiving + node MUST NOT respond to it. Doing so could cause a message loop. + +2 IKE Protocol Details and Variations + + IKE normally listens and sends on UDP port 500, though IKE messages + may also be received on UDP port 4500 with a slightly different + format (see section 2.23). Since UDP is a datagram (unreliable) + protocol, IKE includes in its definition recovery from transmission + errors, including packet loss, packet replay, and packet forgery. IKE + is designed to function so long as (1) at least one of a series of + retransmitted packets reaches its destination before timing out; and + (2) the channel is not so full of forged and replayed packets so as + to exhaust the network or CPU capacities of either endpoint. Even in + the absence of those minimum performance requirements, IKE is + designed to fail cleanly (as though the network were broken). + + While IKEv2 messages are intended to be short, they contain + structures with no hard upper bound on size (in particular, X.509 + certificates), and IKEv2 itself does not have a mechanism for + fragmenting large messages. IP defines a mechanism for fragmentation + of oversize UDP messages, but implementations vary in the maximum + message size supported. Further, use of IP fragmentation opens an + implementation to denial of service attacks [KPS03]. Finally, some + NAT and/or firewall implementations may block IP fragments. + + All IKEv2 implementations MUST be able to send, receive, and process + IKE messages that are up to 1280 bytes long, and they SHOULD be able + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 12] + + + + + +Internet-Draft September 23, 2004 + + + to send, receive, and process messages that are up to 3000 bytes + long. IKEv2 implementations SHOULD be aware of the maximum UDP + message size supported and MAY shorten messages by leaving out some + certificates or cryptographic suite proposals if that will keep + messages below the maximum. Use of the "Hash and URL" formats rather + then including certificates in exchanges where possible can avoid + most problems. Implementations and configuration should keep in mind, + however, that if the URL lookups are only possible after the IPsec SA + is established, recursion issues could prevent this technique from + working. + +2.1 Use of Retransmission Timers + + All messages in IKE exist in pairs: a request and a response. The + setup of an IKE_SA normally consists of two request/response pairs. + Once the IKE_SA is set up, either end of the security association may + initiate requests at any time, and there can be many requests and + responses "in flight" at any given moment. But each message is + labeled as either a request or a response and for each + request/response pair one end of the security association is the + initiator and the other is the responder. + + For every pair of IKE messages, the initiator is responsible for + retransmission in the event of a timeout. The responder MUST never + retransmit a response unless it receives a retransmission of the + request. In that event, the responder MUST ignore the retransmitted + request except insofar as it triggers a retransmission of the + response. The initiator MUST remember each request until it receives + the corresponding response. The responder MUST remember each response + until it receives a request whose sequence number is larger than the + sequence number in the response plus its window size (see section + 2.3). + + IKE is a reliable protocol, in the sense that the initiator MUST + retransmit a request until either it receives a corresponding reply + OR it deems the IKE security association to have failed and it + discards all state associated with the IKE_SA and any CHILD_SAs + negotiated using that IKE_SA. + +2.2 Use of Sequence Numbers for Message ID + + Every IKE message contains a Message ID as part of its fixed header. + This Message ID is used to match up requests and responses, and to + identify retransmissions of messages. + + The Message ID is a 32 bit quantity, which is zero for the first IKE + request in each direction. The IKE_SA initial setup messages will + always be numbered 0 and 1. Each endpoint in the IKE Security + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 13] + + + + + +Internet-Draft September 23, 2004 + + + Association maintains two "current" Message IDs: the next one to be + used for a request it initiates and the next one it expects to see in + a request from the other end. These counters increment as requests + are generated and received. Responses always contain the same message + ID as the corresponding request. That means that after the initial + exchange, each integer n may appear as the message ID in four + distinct messages: The nth request from the original IKE initiator, + the corresponding response, the nth request from the original IKE + responder, and the corresponding response. If the two ends make very + different numbers of requests, the Message IDs in the two directions + can be very different. There is no ambiguity in the messages, + however, because the (I)nitiator and (R)esponse bits in the message + header specify which of the four messages a particular one is. + + Note that Message IDs are cryptographically protected and provide + protection against message replays. In the unlikely event that + Message IDs grow too large to fit in 32 bits, the IKE_SA MUST be + closed. Rekeying an IKE_SA resets the sequence numbers. + +2.3 Window Size for overlapping requests + + In order to maximize IKE throughput, an IKE endpoint MAY issue + multiple requests before getting a response to any of them if the + other endpoint has indicated its ability to handle such requests. For + simplicity, an IKE implementation MAY choose to process requests + strictly in order and/or wait for a response to one request before + issuing another. Certain rules must be followed to assure + interoperability between implementations using different strategies. + + After an IKE_SA is set up, either end can initiate one or more + requests. These requests may pass one another over the network. An + IKE endpoint MUST be prepared to accept and process a request while + it has a request outstanding in order to avoid a deadlock in this + situation. An IKE endpoint SHOULD be prepared to accept and process + multiple requests while it has a request outstanding. + + An IKE endpoint MUST wait for a response to each of its messages + before sending a subsequent message unless it has received a + SET_WINDOW_SIZE Notify message from its peer informing it that the + peer is prepared to maintain state for multiple outstanding messages + in order to allow greater throughput. + + An IKE endpoint MUST NOT exceed the peer's stated window size for + transmitted IKE requests. In other words, if the responder stated its + window size is N, then when the initiator needs to make a request X, + it MUST wait until it has received responses to all requests up + through request X-N. An IKE endpoint MUST keep a copy of (or be able + to regenerate exactly) each request it has sent until it receives the + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 14] + + + + + +Internet-Draft September 23, 2004 + + + corresponding response. An IKE endpoint MUST keep a copy of (or be + able to regenerate exactly) the number of previous responses equal to + its declared window size in case its response was lost and the + initiator requests its retransmission by retransmitting the request. + + An IKE endpoint supporting a window size greater than one SHOULD be + capable of processing incoming requests out of order to maximize + performance in the event of network failures or packet reordering. + +2.4 State Synchronization and Connection Timeouts + + An IKE endpoint is allowed to forget all of its state associated with + an IKE_SA and the collection of corresponding CHILD_SAs at any time. + This is the anticipated behavior in the event of an endpoint crash + and restart. It is important when an endpoint either fails or + reinitializes its state that the other endpoint detect those + conditions and not continue to waste network bandwidth by sending + packets over discarded SAs and having them fall into a black hole. + + Since IKE is designed to operate in spite of Denial of Service (DoS) + attacks from the network, an endpoint MUST NOT conclude that the + other endpoint has failed based on any routing information (e.g., + ICMP messages) or IKE messages that arrive without cryptographic + protection (e.g., Notify messages complaining about unknown SPIs). An + endpoint MUST conclude that the other endpoint has failed only when + repeated attempts to contact it have gone unanswered for a timeout + period or when a cryptographically protected INITIAL_CONTACT + notification is received on a different IKE_SA to the same + authenticated identity. An endpoint SHOULD suspect that the other + endpoint has failed based on routing information and initiate a + request to see whether the other endpoint is alive. To check whether + the other side is alive, IKE specifies an empty INFORMATIONAL message + that (like all IKE requests) requires an acknowledgment (note that + within the context of an IKE_SA, an "empty" message consists of an + IKE header followed by an Encrypted payload that contains no + payloads). If a cryptographically protected message has been received + from the other side recently, unprotected notifications MAY be + ignored. Implementations MUST limit the rate at which they take + actions based on unprotected messages. + + Numbers of retries and lengths of timeouts are not covered in this + specification because they do not affect interoperability. It is + suggested that messages be retransmitted at least a dozen times over + a period of at least several minutes before giving up on an SA, but + different environments may require different rules. To be a good + network citizen, retranmission times MUST increase exponentially to + avoid flooding the network and making an existing congestion + situation worse. If there has only been outgoing traffic on all of + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 15] + + + + + +Internet-Draft September 23, 2004 + + + the SAs associated with an IKE_SA, it is essential to confirm + liveness of the other endpoint to avoid black holes. If no + cryptographically protected messages have been received on an IKE_SA + or any of its CHILD_SAs recently, the system needs to perform a + liveness check in order to prevent sending messages to a dead peer. + Receipt of a fresh cryptographically protected message on an IKE_SA + or any of its CHILD_SAs assures liveness of the IKE_SA and all of its + CHILD_SAs. Note that this places requirements on the failure modes of + an IKE endpoint. An implementation MUST NOT continue sending on any + SA if some failure prevents it from receiving on all of the + associated SAs. If CHILD_SAs can fail independently from one another + without the associated IKE_SA being able to send a delete message, + then they MUST be negotiated by separate IKE_SAs. + + There is a Denial of Service attack on the initiator of an IKE_SA + that can be avoided if the initiator takes the proper care. Since the + first two messages of an SA setup are not cryptographically + protected, an attacker could respond to the initiator's message + before the genuine responder and poison the connection setup attempt. + To prevent this, the initiator MAY be willing to accept multiple + responses to its first message, treat each as potentially legitimate, + respond to it, and then discard all the invalid half open connections + when it receives a valid cryptographically protected response to any + one of its requests. Once a cryptographically valid response is + received, all subsequent responses should be ignored whether or not + they are cryptographically valid. + + Note that with these rules, there is no reason to negotiate and agree + upon an SA lifetime. If IKE presumes the partner is dead, based on + repeated lack of acknowledgment to an IKE message, then the IKE SA + and all CHILD_SAs set up through that IKE_SA are deleted. + + An IKE endpoint may at any time delete inactive CHILD_SAs to recover + resources used to hold their state. If an IKE endpoint chooses to + delete CHILD_SAs, it MUST send Delete payloads to the other end + notifying it of the deletion. It MAY similarly time out the IKE_SA. + Closing the IKE_SA implicitly closes all associated CHILD_SAs. In + this case, an IKE endpoint SHOULD send a Delete payload indicating + that it has closed the IKE_SA. + +2.5 Version Numbers and Forward Compatibility + + This document describes version 2.0 of IKE, meaning the major version + number is 2 and the minor version number is zero. It is likely that + some implementations will want to support both version 1.0 and + version 2.0, and in the future, other versions. + + The major version number should only be incremented if the packet + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 16] + + + + + +Internet-Draft September 23, 2004 + + + formats or required actions have changed so dramatically that an + older version node would not be able to interoperate with a newer + version node if it simply ignored the fields it did not understand + and took the actions specified in the older specification. The minor + version number indicates new capabilities, and MUST be ignored by a + node with a smaller minor version number, but used for informational + purposes by the node with the larger minor version number. For + example, it might indicate the ability to process a newly defined + notification message. The node with the larger minor version number + would simply note that its correspondent would not be able to + understand that message and therefore would not send it. + + If an endpoint receives a message with a higher major version number, + it MUST drop the message and SHOULD send an unauthenticated + notification message containing the highest version number it + supports. If an endpoint supports major version n, and major version + m, it MUST support all versions between n and m. If it receives a + message with a major version that it supports, it MUST respond with + that version number. In order to prevent two nodes from being tricked + into corresponding with a lower major version number than the maximum + that they both support, IKE has a flag that indicates that the node + is capable of speaking a higher major version number. + + Thus the major version number in the IKE header indicates the version + number of the message, not the highest version number that the + transmitter supports. If the initiator is capable of speaking + versions n, n+1, and n+2, and the responder is capable of speaking + versions n and n+1, then they will negotiate speaking n+1, where the + initiator will set the flag indicating its ability to speak a higher + version. If they mistakenly (perhaps through an active attacker + sending error messages) negotiate to version n, then both will notice + that the other side can support a higher version number, and they + MUST break the connection and reconnect using version n+1. + + Note that IKEv1 does not follow these rules, because there is no way + in v1 of noting that you are capable of speaking a higher version + number. So an active attacker can trick two v2-capable nodes into + speaking v1. When a v2-capable node negotiates down to v1, it SHOULD + note that fact in its logs. + + Also for forward compatibility, all fields marked RESERVED MUST be + set to zero by a version 2.0 implementation and their content MUST be + ignored by a version 2.0 implementation ("Be conservative in what you + send and liberal in what you receive"). In this way, future versions + of the protocol can use those fields in a way that is guaranteed to + be ignored by implementations that do not understand them. + Similarly, payload types that are not defined are reserved for future + use and implementations of version 2.0 MUST skip over those payloads + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 17] + + + + + +Internet-Draft September 23, 2004 + + + and ignore their contents. + + IKEv2 adds a "critical" flag to each payload header for further + flexibility for forward compatibility. If the critical flag is set + and the payload type is unrecognized, the message MUST be rejected + and the response to the IKE request containing that payload MUST + include a Notify payload UNSUPPORTED_CRITICAL_PAYLOAD, indicating an + unsupported critical payload was included. If the critical flag is + not set and the payload type is unsupported, that payload MUST be + ignored. + + While new payload types may be added in the future and may appear + interleaved with the fields defined in this specification, + implementations MUST send the payloads defined in this specification + in the order shown in the figures in section 2 and implementations + SHOULD reject as invalid a message with those payloads in any other + order. + +2.6 Cookies + + The term "cookies" originates with Karn and Simpson [RFC2522] in + Photuris, an early proposal for key management with IPsec, and it has + persisted. The ISAKMP fixed message header includes two eight octet + fields titled "cookies", and that syntax is used by both IKEv1 and + IKEv2 though in IKEv2 they are referred to as the IKE SPI and there + is a new separate field in a Notify payload holding the cookie. The + initial two eight octet fields in the header are used as a connection + identifier at the beginning of IKE packets. Each endpoint chooses one + of the two SPIs and SHOULD choose them so as to be unique identifiers + of an IKE_SA. An SPI value of zero is special and indicates that the + remote SPI value is not yet known by the sender. + + Unlike ESP and AH where only the recipient's SPI appears in the + header of a message, in IKE the sender's SPI is also sent in every + message. Since the SPI chosen by the original initiator of the IKE_SA + is always sent first, an endpoint with multiple IKE_SAs open that + wants to find the appropriate IKE_SA using the SPI it assigned must + look at the I(nitiator) Flag bit in the header to determine whether + it assigned the first or the second eight octets. + + In the first message of an initial IKE exchange, the initiator will + not know the responder's SPI value and will therefore set that field + to zero. + + An expected attack against IKE is state and CPU exhaustion, where the + target is flooded with session initiation requests from forged IP + addresses. This attack can be made less effective if an + implementation of a responder uses minimal CPU and commits no state + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 18] + + + + + +Internet-Draft September 23, 2004 + + + to an SA until it knows the initiator can receive packets at the + address from which it claims to be sending them. To accomplish this, + a responder SHOULD - when it detects a large number of half-open + IKE_SAs - reject initial IKE messages unless they contain a Notify + payload of type COOKIE. It SHOULD instead send an unprotected IKE + message as a response and include COOKIE Notify payload with the + cookie data to be returned. Initiators who receive such responses + MUST retry the IKE_SA_INIT with a Notify payload of type COOKIE + containing the responder supplied cookie data as the first payload + and all other payloads unchanged. The initial exchange will then be + as follows: + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + + <-- HDR(A,0), N(COOKIE) + + HDR(A,0), N(COOKIE), SAi1, KEi, Ni --> + + <-- HDR(A,B), SAr1, KEr, Nr, [CERTREQ] + + HDR(A,B), SK {IDi, [CERT,] [CERTREQ,] [IDr,] + AUTH, SAi2, TSi, TSr} --> + + <-- HDR(A,B), SK {IDr, [CERT,] AUTH, + SAr2, TSi, TSr} + + + The first two messages do not affect any initiator or responder state + except for communicating the cookie. In particular, the message + sequence numbers in the first four messages will all be zero and the + message sequence numbers in the last two messages will be one. 'A' is + the SPI assigned by the initiator, while 'B' is the SPI assigned by + the responder. + + An IKE implementation SHOULD implement its responder cookie + generation in such a way as to not require any saved state to + recognize its valid cookie when the second IKE_SA_INIT message + arrives. The exact algorithms and syntax they use to generate + cookies does not affect interoperability and hence is not specified + here. The following is an example of how an endpoint could use + cookies to implement limited DOS protection. + + A good way to do this is to set the responder cookie to be: + + Cookie = | Hash(Ni | IPi | SPIi | ) + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 19] + + + + + +Internet-Draft September 23, 2004 + + + where is a randomly generated secret known only to the + responder and periodically changed and | indicates concatenation. + should be changed whenever is + regenerated. The cookie can be recomputed when the IKE_SA_INIT + arrives the second time and compared to the cookie in the received + message. If it matches, the responder knows that SPIr was generated + since the last change to and that IPi must be the same as + the source address it saw the first time. Incorporating SPIi into the + calculation assures that if multiple IKE_SAs are being set up in + parallel they will all get different cookies (assuming the initiator + chooses unique SPIi's). Incorporating Ni into the hash assures that + an attacker who sees only message 2 can't successfully forge a + message 3. + + If a new value for is chosen while there are connections in + the process of being initialized, an IKE_SA_INIT might be returned + with other than the current . The responder in + that case MAY reject the message by sending another response with a + new cookie or it MAY keep the old value of around for a + short time and accept cookies computed from either one. The + responder SHOULD NOT accept cookies indefinitely after is + changed, since that would defeat part of the denial of service + protection. The responder SHOULD change the value of + frequently, especially if under attack. + +2.7 Cryptographic Algorithm Negotiation + + The payload type known as "SA" indicates a proposal for a set of + choices of IPsec protocols (IKE, ESP, and/or AH) for the SA as well + as cryptographic algorithms associated with each protocol. + + An SA payload consists of one or more proposals. Each proposal + includes one or more protocols (usually one). Each protocol contains + one or more transforms - each specifying a cryptographic algorithm. + Each transform contains zero or more attributes (attributes are only + needed if the transform identifier does not completely specify the + cryptographic algorithm). + + This hierarchical structure was designed to efficiently encode + proposals for cryptographic suites when the number of supported + suites is large because multiple values are acceptable for multiple + transforms. The responder MUST choose a single suite, which MAY be + any subset of the SA proposal following the rules below: + + + Each proposal contains one or more protocols. If a proposal is + accepted, the SA response MUST contain the same protocols in the + same order as the proposal. The responder MUST accept a single + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 20] + + + + + +Internet-Draft September 23, 2004 + + + proposal or reject them all and return an error. (Example: if a + single proposal contains ESP and AH and that proposal is accepted, + both ESP and AH MUST be accepted. If ESP and AH are included in + separate proposals, the responder MUST accept only one of them). + + Each IPsec protocol proposal contains one or more transforms. Each + transform contains a transform type. The accepted cryptographic + suite MUST contain exactly one transform of each type included in + the proposal. For example: if an ESP proposal includes transforms + ENCR_3DES, ENCR_AES w/keysize 128, ENCR_AES w/keysize 256, + AUTH_HMAC_MD5, and AUTH_HMAC_SHA, the accepted suite MUST contain + one of the ENCR_ transforms and one of the AUTH_ transforms. Thus + six combinations are acceptable. + + Since the initiator sends its Diffie-Hellman value in the + IKE_SA_INIT, it must guess the Diffie-Hellman group that the + responder will select from its list of supported groups. If the + initiator guesses wrong, the responder will respond with a Notify + payload of type INVALID_KE_PAYLOAD indicating the selected group. In + this case, the initiator MUST retry the IKE_SA_INIT with the + corrected Diffie-Hellman group. The initiator MUST again propose its + full set of acceptable cryptographic suites because the rejection + message was unauthenticated and otherwise an active attacker could + trick the endpoints into negotiating a weaker suite than a stronger + one that they both prefer. + +2.8 Rekeying + + IKE, ESP, and AH security associations use secret keys which SHOULD + only be used for a limited amount of time and to protect a limited + amount of data. This limits the lifetime of the entire security + association. When the lifetime of a security association expires the + security association MUST NOT be used. If there is demand, new + security associations MAY be established. Reestablishment of + security associations to take the place of ones which expire is + referred to as "rekeying". + + To allow for minimal IPsec implementations, the ability to rekey SAs + without restarting the entire IKE_SA is optional. An implementation + MAY refuse all CREATE_CHILD_SA requests within an IKE_SA. If an SA + has expired or is about to expire and rekeying attempts using the + mechanisms described here fail, an implementation MUST close the + IKE_SA and any associated CHILD_SAs and then MAY start new ones. + Implementations SHOULD support in place rekeying of SAs, since doing + so offers better performance and is likely to reduce the number of + packets lost during the transition. + + To rekey a CHILD_SA within an existing IKE_SA, create a new, + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 21] + + + + + +Internet-Draft September 23, 2004 + + + equivalent SA (see section 2.17 below), and when the new one is + established, delete the old one. To rekey an IKE_SA, establish a new + equivalent IKE_SA (see section 2.18 below) with the peer to whom the + old IKE_SA is shared using a CREATE_CHILD_SA within the existing + IKE_SA. An IKE_SA so created inherits all of the original IKE_SA's + CHILD_SAs. Use the new IKE_SA for all control messages needed to + maintain the CHILD_SAs created by the old IKE_SA, and delete the old + IKE_SA. The Delete payload to delete itself MUST be the last request + sent over an IKE_SA. + + SAs SHOULD be rekeyed proactively, i.e., the new SA should be + established before the old one expires and becomes unusable. Enough + time should elapse between the time the new SA is established and the + old one becomes unusable so that traffic can be switched over to the + new SA. + + A difference between IKEv1 and IKEv2 is that in IKEv1 SA lifetimes + were negotiated. In IKEv2, each end of the SA is responsible for + enforcing its own lifetime policy on the SA and rekeying the SA when + necessary. If the two ends have different lifetime policies, the end + with the shorter lifetime will end up always being the one to request + the rekeying. If an SA bundle has been inactive for a long time and + if an endpoint would not initiate the SA in the absence of traffic, + the endpoint MAY choose to close the SA instead of rekeying it when + its lifetime expires. It SHOULD do so if there has been no traffic + since the last time the SA was rekeyed. + + If the two ends have the same lifetime policies, it is possible that + both will initiate a rekeying at the same time (which will result in + redundant SAs). To reduce the probability of this happening, the + timing of rekeying requests SHOULD be jittered (delayed by a random + amount of time after the need for rekeying is noticed). + + This form of rekeying may temporarily result in multiple similar SAs + between the same pairs of nodes. When there are two SAs eligible to + receive packets, a node MUST accept incoming packets through either + SA. If redundant SAs are created though such a collision, the SA + created with the lowest of the four nonces used in the two exchanges + SHOULD be closed by the endpoint that created it. + + Note that IKEv2 deliberately allows parallel SAs with the same + traffic selectors between common endpoints. One of the purposes of + this is to support traffic QoS differences among the SAs (see section + 4.1 of [RFC2983]). Hence unlike IKEv1, the combination of the + endpoints and the traffic selectors may not uniquely identify an SA + between those endpoints, so the IKEv1 rekeying heuristic of deleting + SAs on the basis of duplicate traffic selectors SHOULD NOT be used. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 22] + + + + + +Internet-Draft September 23, 2004 + + + The node that initiated the surviving rekeyed SA SHOULD delete the + replaced SA after the new one is established. + + There are timing windows - particularly in the presence of lost + packets - where endpoints may not agree on the state of an SA. The + responder to a CREATE_CHILD_SA MUST be prepared to accept messages on + an SA before sending its response to the creation request, so there + is no ambiguity for the initiator. The initiator MAY begin sending on + an SA as soon as it processes the response. The initiator, however, + cannot receive on a newly created SA until it receives and processes + the response to its CREATE_CHILD_SA request. How, then, is the + responder to know when it is OK to send on the newly created SA? + + From a technical correctness and interoperability perspective, the + responder MAY begin sending on an SA as soon as it sends its response + to the CREATE_CHILD_SA request. In some situations, however, this + could result in packets unnecessarily being dropped, so an + implementation MAY want to defer such sending. + + The responder can be assured that the initiator is prepared to + receive messages on an SA if either (1) it has received a + cryptographically valid message on the new SA, or (2) the new SA + rekeys an existing SA and it receives an IKE request to close the + replaced SA. When rekeying an SA, the responder SHOULD continue to + send requests on the old SA until it one of those events occurs. When + establishing a new SA, the responder MAY defer sending messages on a + new SA until either it receives one or a timeout has occurred. If an + initiator receives a message on an SA for which it has not received a + response to its CREATE_CHILD_SA request, it SHOULD interpret that as + a likely packet loss and retransmit the CREATE_CHILD_SA request. An + initiator MAY send a dummy message on a newly created SA if it has no + messages queued in order to assure the responder that the initiator + is ready to receive messages. + +2.9 Traffic Selector Negotiation + + When an IP packet is received by an RFC2401 compliant IPsec subsystem + and matches a "protect" selector in its SPD, the subsystem MUST + protect that packet with IPsec. When no SA exists yet it is the task + of IKE to create it. Maintenance of a system's SPD is outside the + scope of IKE (see [PFKEY] for an example protocol), though some + implementations might update their SPD in connection with the running + of IKE (for an example scenario, see section 1.1.3). + + Traffic Selector (TS) payloads allow endpoints to communicate some of + the information from their SPD to their peers. TS payloads specify + the selection criteria for packets that will be forwarded over the + newly set up SA. This can serve as a consistency check in some + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 23] + + + + + +Internet-Draft September 23, 2004 + + + scenarios to assure that the SPDs are consistent. In others, it + guides the dynamic update of the SPD. + + Two TS payloads appear in each of the messages in the exchange that + creates a CHILD_SA pair. Each TS payload contains one or more Traffic + Selectors. Each Traffic Selector consists of an address range (IPv4 + or IPv6), a port range, and an IP protocol ID. In support of the + scenario described in section 1.1.3, an initiator may request that + the responder assign an IP address and tell the initiator what it is. + + IKEv2 allows the responder to choose a subset of the traffic proposed + by the initiator. This could happen when the configuration of the + two endpoints are being updated but only one end has received the new + information. Since the two endpoints may be configured by different + people, the incompatibility may persist for an extended period even + in the absence of errors. It also allows for intentionally different + configurations, as when one end is configured to tunnel all addresses + and depends on the other end to have the up to date list. + + The first of the two TS payloads is known as TSi (Traffic Selector- + initiator). The second is known as TSr (Traffic Selector-responder). + TSi specifies the source address of traffic forwarded from (or the + destination address of traffic forwarded to) the initiator of the + CHILD_SA pair. TSr specifies the destination address of the traffic + forwarded from (or the source address of the traffic forwarded to) + the responder of the CHILD_SA pair. For example, if the original + initiator request the creation of a CHILD_SA pair, and wishes to + tunnel all traffic from subnet 192.0.1.* on the initiator's side to + subnet 192.0.2.* on the responder's side, the initiator would include + a single traffic selector in each TS payload. TSi would specify the + address range (192.0.1.0 - 192.0.1.255) and TSr would specify the + address range (192.0.2.0 - 192.0.2.255). Assuming that proposal was + acceptable to the responder, it would send identical TS payloads + back. [Note: the IP address range 192.0.1.* has been reserved for use + in examples in RFCs and similar documents. This document needed two + such ranges, and so also used 192.0.2.*. This should not be confused + with any actual address]. + + The responder is allowed to narrow the choices by selecting a subset + of the traffic, for instance by eliminating or narrowing the range of + one or more members of the set of traffic selectors, provided the set + does not become the NULL set. + + It is possible for the responder's policy to contain multiple smaller + ranges, all encompassed by the initiator's traffic selector, and with + the responder's policy being that each of those ranges should be sent + over a different SA. Continuing the example above, the responder + might have a policy of being willing to tunnel those addresses to and + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 24] + + + + + +Internet-Draft September 23, 2004 + + + from the initiator, but might require that each address pair be on a + separately negotiated CHILD_SA. If the initiator generated its + request in response to an incoming packet from 192.0.1.43 to + 192.0.2.123, there would be no way for the responder to determine + which pair of addresses should be included in this tunnel, and it + would have to make a guess or reject the request with a status of + SINGLE_PAIR_REQUIRED. + + To enable the responder to choose the appropriate range in this case, + if the initiator has requested the SA due to a data packet, the + initiator SHOULD include as the first traffic selector in each of TSi + and TSr a very specific traffic selector including the addresses in + the packet triggering the request. In the example, the initiator + would include in TSi two traffic selectors: the first containing the + address range (192.0.1.43 - 192.0.1.43) and the source port and IP + protocol from the packet and the second containing (192.0.1.0 - + 192.0.1.255) with all ports and IP protocols. The initiator would + similarly include two traffic selectors in TSr. + + If the responder's policy does not allow it to accept the entire set + of traffic selectors in the initiator's request, but does allow him + to accept the first selector of TSi and TSr, then the responder MUST + narrow the traffic selectors to a subset that includes the + initiator's first choices. In this example, the responder might + respond with TSi being (192.0.1.43 - 192.0.1.43) with all ports and + IP protocols. + + If the initiator creates the CHILD_SA pair not in response to an + arriving packet, but rather - say - upon startup, then there may be + no specific addresses the initiator prefers for the initial tunnel + over any other. In that case, the first values in TSi and TSr MAY be + ranges rather than specific values, and the responder chooses a + subset of the initiator's TSi and TSr that are acceptable. If more + than one subset is acceptable but their union is not, the responder + MUST accept some subset and MAY include a Notify payload of type + ADDITIONAL_TS_POSSIBLE to indicate that the initiator might want to + try again. This case will only occur when the initiator and responder + are configured differently from one another. If the initiator and + responder agree on the granularity of tunnels, the initiator will + never request a tunnel wider than the responder will accept. Such + misconfigurations SHOULD be recorded in error logs. + +2.10 Nonces + + The IKE_SA_INIT messages each contain a nonce. These nonces are used + as inputs to cryptographic functions. The CREATE_CHILD_SA request + and the CREATE_CHILD_SA response also contain nonces. These nonces + are used to add freshness to the key derivation technique used to + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 25] + + + + + +Internet-Draft September 23, 2004 + + + obtain keys for CHILD_SA, and to ensure creation of strong + pseudorandom bits from the Diffie-Hellman key. Nonces used in IKEv2 + MUST be randomly chosen, MUST be at least 128 bits in size, and MUST + be at least half the key size of the negotiated prf. ("prf" refers to + "pseudo-random function", one of the cryptographic algorithms + negotiated in the IKE exchange). If the same random number source is + used for both keys and nonces, care must be taken to ensure that the + latter use does not compromise the former. + +2.11 Address and Port Agility + + IKE runs over UDP ports 500 and 4500, and implicitly sets up ESP and + AH associations for the same IP addresses it runs over. The IP + addresses and ports in the outer header are, however, not themselves + cryptographically protected, and IKE is designed to work even through + Network Address Translation (NAT) boxes. An implementation MUST + accept incoming requests even if the source port is not 500 or 4500, + and MUST respond to the address and port from which the request was + received. It MUST specify the address and port at which the request + was received as the source address and port in the response. IKE + functions identically over IPv4 or IPv6. + +2.12 Reuse of Diffie-Hellman Exponentials + + IKE generates keying material using an ephemeral Diffie-Hellman + exchange in order to gain the property of "perfect forward secrecy". + This means that once a connection is closed and its corresponding + keys are forgotten, even someone who has recorded all of the data + from the connection and gets access to all of the long-term keys of + the two endpoints cannot reconstruct the keys used to protect the + conversation without doing a brute force search of the session key + space. + + Achieving perfect forward secrecy requires that when a connection is + closed, each endpoint MUST forget not only the keys used by the + connection but any information that could be used to recompute those + keys. In particular, it MUST forget the secrets used in the Diffie- + Hellman calculation and any state that may persist in the state of a + pseudo-random number generator that could be used to recompute the + Diffie-Hellman secrets. + + Since the computing of Diffie-Hellman exponentials is computationally + expensive, an endpoint may find it advantageous to reuse those + exponentials for multiple connection setups. There are several + reasonable strategies for doing this. An endpoint could choose a new + exponential only periodically though this could result in less-than- + perfect forward secrecy if some connection lasts for less than the + lifetime of the exponential. Or it could keep track of which + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 26] + + + + + +Internet-Draft September 23, 2004 + + + exponential was used for each connection and delete the information + associated with the exponential only when some corresponding + connection was closed. This would allow the exponential to be reused + without losing perfect forward secrecy at the cost of maintaining + more state. + + Decisions as to whether and when to reuse Diffie-Hellman exponentials + is a private decision in the sense that it will not affect + interoperability. An implementation that reuses exponentials MAY + choose to remember the exponential used by the other endpoint on past + exchanges and if one is reused to avoid the second half of the + calculation. + +2.13 Generating Keying Material + + In the context of the IKE_SA, four cryptographic algorithms are + negotiated: an encryption algorithm, an integrity protection + algorithm, a Diffie-Hellman group, and a pseudo-random function + (prf). The pseudo-random function is used for the construction of + keying material for all of the cryptographic algorithms used in both + the IKE_SA and the CHILD_SAs. + + We assume that each encryption algorithm and integrity protection + algorithm uses a fixed size key, and that any randomly chosen value + of that fixed size can serve as an appropriate key. For algorithms + that accept a variable length key, a fixed key size MUST be specified + as part of the cryptographic transform negotiated. For algorithms + for which not all values are valid keys (such as DES or 3DES with key + parity), they algorithm by which keys are derived from arbitrary + values MUST be specified by the cryptographic transform. For + integrity protection functions based on HMAC, the fixed key size is + the size of the output of the underlying hash function. When the prf + function takes a variable length key, variable length data, and + produces a fixed length output (e.g., when using HMAC), the formulas + in this document apply. When the key for the prf function has fixed + length, the data provided as a key is truncated or padded with zeros + as necessary unless exceptional processing is explained following the + formula. + + Keying material will always be derived as the output of the + negotiated prf algorithm. Since the amount of keying material needed + may be greater than the size of the output of the prf algorithm, we + will use the prf iteratively. We will use the terminology prf+ to + describe the function that outputs a pseudo-random stream based on + the inputs to a prf as follows: (where | indicates concatenation) + + prf+ (K,S) = T1 | T2 | T3 | T4 | ... + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 27] + + + + + +Internet-Draft September 23, 2004 + + + where: + T1 = prf (K, S | 0x01) + T2 = prf (K, T1 | S | 0x02) + T3 = prf (K, T2 | S | 0x03) + T4 = prf (K, T3 | S | 0x04) + + continuing as needed to compute all required keys. The keys are taken + from the output string without regard to boundaries (e.g., if the + required keys are a 256 bit AES key and a 160 bit HMAC key, and the + prf function generates 160 bits, the AES key will come from T1 and + the beginning of T2, while the HMAC key will come from the rest of T2 + and the beginning of T3). + + The constant concatenated to the end of each string feeding the prf + is a single octet. prf+ in this document is not defined beyond 255 + times the size of the prf output. + +2.14 Generating Keying Material for the IKE_SA + + The shared keys are computed as follows. A quantity called SKEYSEED + is calculated from the nonces exchanged during the IKE_SA_INIT + exchange and the Diffie-Hellman shared secret established during that + exchange. SKEYSEED is used to calculate seven other secrets: SK_d + used for deriving new keys for the CHILD_SAs established with this + IKE_SA; SK_ai and SK_ar used as a key to the integrity protection + algorithm for authenticating the component messages of subsequent + exchanges; SK_ei and SK_er used for encrypting (and of course + decrypting) all subsequent exchanges; and SK_pi and SK_pr which are + used when generating an AUTH payload. + + SKEYSEED and its derivatives are computed as follows: + + SKEYSEED = prf(Ni | Nr, g^ir) + + {SK_d | SK_ai | SK_ar | SK_ei | SK_er | SK_pi | SK_pr } + = prf+ (SKEYSEED, Ni | Nr | SPIi | SPIr ) + + (indicating that the quantities SK_d, SK_ai, SK_ar, SK_ei, SK_er, + SK_pi, and SK_pr are taken in order from the generated bits of the + prf+). g^ir is the shared secret from the ephemeral Diffie-Hellman + exchange. g^ir is represented as a string of octets in big endian + order padded with zeros if necessary to make it the length of the + modulus. Ni and Nr are the nonces, stripped of any headers. If the + negotiated prf takes a fixed length key and the lengths of Ni and Nr + do not add up to that length, half the bits must come from Ni and + half from Nr, taking the first bits of each. + + The two directions of traffic flow use different keys. The keys used + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 28] + + + + + +Internet-Draft September 23, 2004 + + + to protect messages from the original initiator are SK_ai and SK_ei. + The keys used to protect messages in the other direction are SK_ar + and SK_er. Each algorithm takes a fixed number of bits of keying + material, which is specified as part of the algorithm. For integrity + algorithms based on a keyed hash, the key size is always equal to the + length of the output of the underlying hash function. + +2.15 Authentication of the IKE_SA + + When not using extensible authentication (see section 2.16), the + peers are authenticated by having each sign (or MAC using a shared + secret as the key) a block of data. For the responder, the octets to + be signed start with the first octet of the first SPI in the header + of the second message and end with the last octet of the last payload + in the second message. Appended to this (for purposes of computing + the signature) are the initiator's nonce Ni (just the value, not the + payload containing it), and the value prf(SK_pr,IDr') where IDr' is + the responder's ID payload excluding the fixed header. Note that + neither the nonce Ni nor the value prf(SK_pr,IDr') are transmitted. + Similarly, the initiator signs the first message, starting with the + first octet of the first SPI in the header and ending with the last + octet of the last payload. Appended to this (for purposes of + computing the signature) are the responder's nonce Nr, and the value + prf(SK_pi,IDi'). In the above calculation, IDi' and IDr' are the + entire ID payloads excluding the fixed header. It is critical to the + security of the exchange that each side sign the other side's nonce. + + Note that all of the payloads are included under the signature, + including any payload types not defined in this document. If the + first message of the exchange is sent twice (the second time with a + responder cookie and/or a different Diffie-Hellman group), it is the + second version of the message that is signed. + + Optionally, messages 3 and 4 MAY include a certificate, or + certificate chain providing evidence that the key used to compute a + digital signature belongs to the name in the ID payload. The + signature or MAC will be computed using algorithms dictated by the + type of key used by the signer, and specified by the Auth Method + field in the Authentication payload. There is no requirement that + the initiator and responder sign with the same cryptographic + algorithms. The choice of cryptographic algorithms depends on the + type of key each has. In particular, the initiator may be using a + shared key while the responder may have a public signature key and + certificate. It will commonly be the case (but it is not required) + that if a shared secret is used for authentication that the same key + is used in both directions. Note that it is a common but typically + insecure practice to have a shared key derived solely from a user + chosen password without incorporating another source of randomness. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 29] + + + + + +Internet-Draft September 23, 2004 + + + This is typically insecure because user chosen passwords are unlikely + to have sufficient unpredictability to resist dictionary attacks and + these attacks are not prevented in this authentication method. + (Applications using password-based authentication for bootstrapping + and IKE_SA should use the authentication method in section 2.16, + which is designed to prevent off-line dictionary attacks). The pre- + shared key SHOULD contain as much unpredictability as the strongest + key being negotiated. In the case of a pre-shared key, the AUTH + value is computed as: + + AUTH = prf(prf(Shared Secret,"Key Pad for IKEv2"), ) + + where the string "Key Pad for IKEv2" is 17 ASCII characters without + null termination. The shared secret can be variable length. The pad + string is added so that if the shared secret is derived from a + password, the IKE implementation need not store the password in + cleartext, but rather can store the value prf(Shared Secret,"Key Pad + for IKEv2"), which could not be used as a password equivalent for + protocols other than IKEv2. As noted above, deriving the shared + secret from a password is not secure. This construction is used + because it is anticipated that people will do it anyway. The + management interface by which the Shared Secret is provided MUST + accept ASCII strings of at least 64 octets and MUST NOT add a null + terminator before using them as shared secrets. It MUST also accept a + HEX encoding of the Shared Secret. The management interface MAY + accept other encodings if the algorithm for translating the encoding + to a binary string is specified. If the negotiated prf takes a fixed + size key, the shared secret MUST be of that fixed size. + +2.16 Extensible Authentication Protocol Methods + + In addition to authentication using public key signatures and shared + secrets, IKE supports authentication using methods defined in RFC + 3748 [EAP]. Typically, these methods are asymmetric (designed for a + user authenticating to a server), and they may not be mutual. For + this reason, these protocols are typically used to authenticate the + initiator to the responder and MUST be used in conjunction with a + public key signature based authentication of the responder to the + initiator. These methods are often associated with mechanisms + referred to as "Legacy Authentication" mechanisms. + + While this memo references [EAP] with the intent that new methods can + be added in the future without updating this specification, some + simpler variations are documented here and in section 3.16. [EAP] + defines an authentication protocol requiring a variable number of + messages. Extensible Authentication is implemented in IKE as + additional IKE_AUTH exchanges that MUST be completed in order to + initialize the IKE_SA. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 30] + + + + + +Internet-Draft September 23, 2004 + + + An initiator indicates a desire to use extensible authentication by + leaving out the AUTH payload from message 3. By including an IDi + payload but not an AUTH payload, the initiator has declared an + identity but has not proven it. If the responder is willing to use an + extensible authentication method, it will place an EAP payload in + message 4 and defer sending SAr2, TSi, and TSr until initiator + authentication is complete in a subsequent IKE_AUTH exchange. In the + case of a minimal extensible authentication, the initial SA + establishment will appear as follows: + + Initiator Responder + ----------- ----------- + HDR, SAi1, KEi, Ni --> + + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + + HDR, SK {IDi, [CERTREQ,] [IDr,] + SAi2, TSi, TSr} --> + + <-- HDR, SK {IDr, [CERT,] AUTH, + EAP } + + HDR, SK {EAP} --> + + <-- HDR, SK {EAP (success)} + + HDR, SK {AUTH} --> + + <-- HDR, SK {AUTH, SAr2, TSi, TSr } + + For EAP methods that create a shared key as a side effect of + authentication, that shared key MUST be used by both the initiator + and responder to generate AUTH payloads in messages 5 and 6 using the + syntax for shared secrets specified in section 2.15. The shared key + from EAP is the field from the EAP specification named MSK. The + shared key generated during an IKE exchange MUST NOT be used for any + other purpose. + + EAP methods that do not establish a shared key SHOULD NOT be used, as + they are subject to a number of man-in-the-middle attacks [EAPMITM] + if these EAP methods are used in other protocols that do not use a + server-authenticated tunnel. Please see the Security Considerations + section for more details. If EAP methods that do not generate a + shared key are used, the AUTH payloads in messages 7 and 8 MUST be + generated using SK_pi and SK_pr respectively. + + The initiator of an IKE_SA using EAP SHOULD be capable of extending + the initial protocol exchange to at least ten IKE_AUTH exchanges in + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 31] + + + + + +Internet-Draft September 23, 2004 + + + the event the responder sends notification messages and/or retries + the authentication prompt. Once the protocol exchange defined by the + chosen EAP authentication method has successfully terminated, the + responder MUST send an EAP payload containing the Success message. + Similarly, if the authentication method has failed, the responder + MUST send an EAP payload containing the Failure message. The + responder MAY at any time terminate the IKE exchange by sending an + EAP payload containing the Failure message. + + Following such an extended exchange, the EAP AUTH payloads MUST be + included in the two messages following the one containing the EAP + Success message. + +2.17 Generating Keying Material for CHILD_SAs + + CHILD_SAs are created either by being piggybacked on the IKE_AUTH + exchange, or in a CREATE_CHILD_SA exchange. Keying material for them + is generated as follows: + + KEYMAT = prf+(SK_d, Ni | Nr) + + Where Ni and Nr are the Nonces from the IKE_SA_INIT exchange if this + request is the first CHILD_SA created or the fresh Ni and Nr from the + CREATE_CHILD_SA exchange if this is a subsequent creation. + + For CREATE_CHILD_SA exchanges including an optional Diffie-Hellman + exchange, the keying material is defined as: + + KEYMAT = prf+(SK_d, g^ir (new) | Ni | Nr ) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros in the high order + bits if necessary to make it the length of the modulus). + + A single CHILD_SA negotiation may result in multiple security + associations. ESP and AH SAs exist in pairs (one in each direction), + and four SAs could be created in a single CHILD_SA negotiation if a + combination of ESP and AH is being negotiated. + + Keying material MUST be taken from the expanded KEYMAT in the + following order: + + All keys for SAs carrying data from the initiator to the responder + are taken before SAs going in the reverse direction. + + If multiple IPsec protocols are negotiated, keying material is + taken in the order in which the protocol headers will appear in + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 32] + + + + + +Internet-Draft September 23, 2004 + + + the encapsulated packet. + + If a single protocol has both encryption and authentication keys, + the encryption key is taken from the first octets of KEYMAT and + the authentication key is taken from the next octets. + + Each cryptographic algorithm takes a fixed number of bits of keying + material specified as part of the algorithm. + +2.18 Rekeying IKE_SAs using a CREATE_CHILD_SA exchange + + The CREATE_CHILD_SA exchange can be used to rekey an existing IKE_SA + (see section 2.8). New initiator and responder SPIs are supplied in + the SPI fields. The TS payloads are omitted when rekeying an IKE_SA. + SKEYSEED for the new IKE_SA is computed using SK_d from the existing + IKE_SA as follows: + + SKEYSEED = prf(SK_d (old), [g^ir (new)] | Ni | Nr) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros if necessary to + make it the length of the modulus) and Ni and Nr are the two nonces + stripped of any headers. + + The new IKE_SA MUST reset its message counters to 0. + + SK_d, SK_ai, SK_ar, and SK_ei, and SK_er are computed from SKEYSEED + as specified in section 2.14. + +2.19 Requesting an internal address on a remote network + + Most commonly occurring in the endpoint to security gateway scenario, + an endpoint may need an IP address in the network protected by the + security gateway, and may need to have that address dynamically + assigned. A request for such a temporary address can be included in + any request to create a CHILD_SA (including the implicit request in + message 3) by including a CP payload. + + This function provides address allocation to an IRAC (IPsec Remote + Access Client) trying to tunnel into a network protected by an IRAS + (IPsec Remote Access Server). Since the IKE_AUTH exchange creates an + IKE_SA and a CHILD_SA, the IRAC MUST request the IRAS controlled + address (and optionally other information concerning the protected + network) in the IKE_AUTH exchange. The IRAS may procure an address + for the IRAC from any number of sources such as a DHCP/BOOTP server + or its own address pool. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 33] + + + + + +Internet-Draft September 23, 2004 + + + Initiator Responder + ----------------------------- --------------------------- + HDR, SK {IDi, [CERT,] [CERTREQ,] + [IDr,] AUTH, CP(CFG_REQUEST), + SAi2, TSi, TSr} --> + + <-- HDR, SK {IDr, [CERT,] AUTH, + CP(CFG_REPLY), SAr2, + TSi, TSr} + + In all cases, the CP payload MUST be inserted before the SA payload. + In variations of the protocol where there are multiple IKE_AUTH + exchanges, the CP payloads MUST be inserted in the messages + containing the SA payloads. + + CP(CFG_REQUEST) MUST contain at least an INTERNAL_ADDRESS attribute + (either IPv4 or IPv6) but MAY contain any number of additional + attributes the initiator wants returned in the response. + + For example, message from initiator to responder: + CP(CFG_REQUEST)= + INTERNAL_ADDRESS(0.0.0.0) + INTERNAL_NETMASK(0.0.0.0) + INTERNAL_DNS(0.0.0.0) + TSi = (0, 0-65536,0.0.0.0-255.255.255.255) + TSr = (0, 0-65536,0.0.0.0-255.255.255.255) + + NOTE: Traffic Selectors contain (protocol, port range, address range) + + Message from responder to initiator: + + CP(CFG_REPLY)= + INTERNAL_ADDRESS(192.0.2.202) + INTERNAL_NETMASK(255.255.255.0) + INTERNAL_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65536,192.0.2.202-192.0.2.202) + TSr = (0, 0-65536,192.0.2.0-192.0.2.255) + + All returned values will be implementation dependent. As can be seen + in the above example, the IRAS MAY also send other attributes that + were not included in CP(CFG_REQUEST) and MAY ignore the non- + mandatory attributes that it does not support. + + The responder MUST NOT send a CFG_REPLY without having first received + a CP(CFG_REQUEST) from the initiator, because we do not want the IRAS + to perform an unnecessary configuration lookup if the IRAC cannot + process the REPLY. In the case where the IRAS's configuration + requires that CP be used for a given identity IDi, but IRAC has + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 34] + + + + + +Internet-Draft September 23, 2004 + + + failed to send a CP(CFG_REQUEST), IRAS MUST fail the request, and + terminate the IKE exchange with a FAILED_CP_REQUIRED error. + +2.20 Requesting the Peer's Version + + An IKE peer wishing to inquire about the other peer's IKE software + version information MAY use the method below. This is an example of + a configuration request within an INFORMATIONAL Exchange, after the + IKE_SA and first CHILD_SA have been created. + + An IKE implementation MAY decline to give out version information + prior to authentication or even after authentication to prevent + trolling in case some implementation is known to have some security + weakness. In that case, it MUST either return an empty string or no + CP payload if CP is not supported. + + Initiator Responder + ----------------------------- -------------------------- + HDR, SK{CP(CFG_REQUEST)} --> + <-- HDR, SK{CP(CFG_REPLY)} + + CP(CFG_REQUEST)= + APPLICATION_VERSION("") + + CP(CFG_REPLY) + APPLICATION_VERSION("foobar v1.3beta, (c) Foo Bar Inc.") + +2.21 Error Handling + + There are many kinds of errors that can occur during IKE processing. + If a request is received that is badly formatted or unacceptable for + reasons of policy (e.g., no matching cryptographic algorithms), the + response MUST contain a Notify payload indicating the error. If an + error occurs outside the context of an IKE request (e.g., the node is + getting ESP messages on a nonexistent SPI), the node SHOULD initiate + an INFORMATIONAL Exchange with a Notify payload describing the + problem. + + Errors that occur before a cryptographically protected IKE_SA is + established must be handled very carefully. There is a trade-off + between wanting to be helpful in diagnosing a problem and responding + to it and wanting to avoid being a dupe in a denial of service attack + based on forged messages. + + If a node receives a message on UDP port 500 or 4500 outside the + context of an IKE_SA known to it (and not a request to start one), it + may be the result of a recent crash of the node. If the message is + marked as a response, the node MAY audit the suspicious event but + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 35] + + + + + +Internet-Draft September 23, 2004 + + + MUST NOT respond. If the message is marked as a request, the node MAY + audit the suspicious event and MAY send a response. If a response is + sent, the response MUST be sent to the IP address and port from + whence it came with the same IKE SPIs and the Message ID copied. The + response MUST NOT be cryptographically protected and MUST contain a + Notify payload indicating INVALID_IKE_SPI. + + A node receiving such an unprotected Notify payload MUST NOT respond + and MUST NOT change the state of any existing SAs. The message might + be a forgery or might be a response the genuine correspondent was + tricked into sending. A node SHOULD treat such a message (and also a + network message like ICMP destination unreachable) as a hint that + there might be problems with SAs to that IP address and SHOULD + initiate a liveness test for any such IKE_SA. An implementation + SHOULD limit the frequency of such tests to avoid being tricked into + participating in a denial of service attack. + + A node receiving a suspicious message from an IP address with which + it has an IKE_SA MAY send an IKE Notify payload in an IKE + INFORMATIONAL exchange over that SA. The recipient MUST NOT change + the state of any SA's as a result but SHOULD audit the event to aid + in diagnosing malfunctions. A node MUST limit the rate at which it + will send messages in response to unprotected messages. + +2.22 IPComp + + Use of IP compression [IPCOMP] can be negotiated as part of the setup + of a CHILD_SA. While IP compression involves an extra header in each + packet and a CPI (compression parameter index), the virtual + "compression association" has no life outside the ESP or AH SA that + contains it. Compression associations disappear when the + corresponding ESP or AH SA goes away, and is not explicitly mentioned + in any DELETE payload. + + Negotiation of IP compression is separate from the negotiation of + cryptographic parameters associated with a CHILD_SA. A node + requesting a CHILD_SA MAY advertise its support for one or more + compression algorithms though one or more Notify payloads of type + IPCOMP_SUPPORTED. The response MAY indicate acceptance of a single + compression algorithm with a Notify payload of type IPCOMP_SUPPORTED. + These payloads MUST NOT occur messages that do not contain SA + payloads. + + While there has been discussion of allowing multiple compression + algorithms to be accepted and to have different compression + algorithms available for the two directions of a CHILD_SA, + implementations of this specification MUST NOT accept an IPComp + algorithm that was not proposed, MUST NOT accept more than one, and + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 36] + + + + + +Internet-Draft September 23, 2004 + + + MUST NOT compress using an algorithm other than one proposed and + accepted in the setup of the CHILD_SA. + + A side effect of separating the negotiation of IPComp from + cryptographic parameters is that it is not possible to propose + multiple cryptographic suites and propose IP compression with some of + them but not others. + +2.23 NAT Traversal + + NAT (Network Address Translation) gateways are a controversial + subject. This section briefly describes what they are and how they + are likely to act on IKE traffic. Many people believe that NATs are + evil and that we should not design our protocols so as to make them + work better. IKEv2 does specify some unintuitive processing rules in + order that NATs are more likely to work. + + NATs exist primarily because of the shortage of IPv4 addresses, + though there are other rationales. IP nodes that are "behind" a NAT + have IP addresses that are not globally unique, but rather are + assigned from some space that is unique within the network behind the + NAT but which are likely to be reused by nodes behind other NATs. + Generally, nodes behind NATs can communicate with other nodes behind + the same NAT and with nodes with globally unique addresses, but not + with nodes behind other NATs. There are exceptions to that rule. + When those nodes make connections to nodes on the real Internet, the + NAT gateway "translates" the IP source address to an address that + will be routed back to the gateway. Messages to the gateway from the + Internet have their destination addresses "translated" to the + internal address that will route the packet to the correct endnode. + + NATs are designed to be "transparent" to endnodes. Neither software + on the node behind the NAT nor the node on the Internet require + modification to communicate through the NAT. Achieving this + transparency is more difficult with some protocols than with others. + Protocols that include IP addresses of the endpoints within the + payloads of the packet will fail unless the NAT gateway understands + the protocol and modifies the internal references as well as those in + the headers. Such knowledge is inherently unreliable, is a network + layer violation, and often results in subtle problems. + + Opening an IPsec connection through a NAT introduces special + problems. If the connection runs in transport mode, changing the IP + addresses on packets will cause the checksums to fail and the NAT + cannot correct the checksums because they are cryptographically + protected. Even in tunnel mode, there are routing problems because + transparently translating the addresses of AH and ESP packets + requires special logic in the NAT and that logic is heuristic and + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 37] + + + + + +Internet-Draft September 23, 2004 + + + unreliable in nature. For that reason, IKEv2 can negotiate UDP + encapsulation of IKE and ESP packets. This encoding is slightly less + efficient but is easier for NATs to process. In addition, firewalls + may be configured to pass IPsec traffic over UDP but not ESP/AH or + vice versa. + + It is a common practice of NATs to translate TCP and UDP port numbers + as well as addresses and use the port numbers of inbound packets to + decide which internal node should get a given packet. For this + reason, even though IKE packets MUST be sent from and to UDP port + 500, they MUST be accepted coming from any port and responses MUST be + sent to the port from whence they came. This is because the ports may + be modified as the packets pass through NATs. Similarly, IP addresses + of the IKE endpoints are generally not included in the IKE payloads + because the payloads are cryptographically protected and could not be + transparently modified by NATs. + + Port 4500 is reserved for UDP encapsulated ESP and IKE. When working + through a NAT, it is generally better to pass IKE packets over port + 4500 because some older NATs handle IKE traffic on port 500 cleverly + in an attempt to transparently establish IPsec connections between + endpoints that don't handle NAT traversal themselves. Such NATs may + interfere with the straightforward NAT traversal envisioned by this + document, so an IPsec endpoint that discovers a NAT between it and + its correspondent MUST send all subsequent traffic to and from port + 4500, which NATs should not treat specially (as they might with port + 500). + + The specific requirements for supporting NAT traversal are listed + below. Support for NAT traversal is optional. In this section only, + requirements listed as MUST only apply to implementations supporting + NAT traversal. + + IKE MUST listen on port 4500 as well as port 500. IKE MUST respond + to the IP address and port from which packets arrived. + + Both IKE initiator and responder MUST include in their IKE_SA_INIT + packets Notify payloads of type NAT_DETECTION_SOURCE_IP and + NAT_DETECTION_DESTINATION_IP. Those payloads can be used to detect + if there is NAT between the hosts, and which end is behind the + NAT. The location of the payloads in the IKE_SA_INIT packets are + just after the Ni and Nr payloads (before the optional CERTREQ + payload). + + If none of the NAT_DETECTION_SOURCE_IP payload(s) received matches + the hash of the source IP and port found from the IP header of the + packet containing the payload, it means that the other end is + behind NAT (i.e., someone along the route changed the source + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 38] + + + + + +Internet-Draft September 23, 2004 + + + address of the original packet to match the address of the NAT + box). In this case this end should allow dynamic update of the + other ends IP address, as described later. + + If the NAT_DETECTION_DESTINATION_IP payload received does not + match the hash of the destination IP and port found from the IP + header of the packet containing the payload, it means that this + end is behind a NAT. In this case, this end SHOULD start sending + keepalive packets as explained in [Hutt04]. + + The IKE initiator MUST check these payloads if present and if they + do not match the addresses in the outer packet MUST tunnel all + future IKE and ESP packets associated with this IKE_SA over UDP + port 4500. + + To tunnel IKE packets over UDP port 4500, the IKE header has four + octets of zero prepended and the result immediately follows the + UDP header. To tunnel ESP packets over UDP port 4500, the ESP + header immediately follows the UDP header. Since the first four + bytes of the ESP header contain the SPI, and the SPI cannot + validly be zero, it is always possible to distinguish ESP and IKE + messages. + + The original source and destination IP address required for the + transport mode TCP and UDP packet checksum fixup (see [Hutt04]) + are obtained from the Traffic Selectors associated with the + exchange. In the case of NAT traversal, the Traffic Selectors MUST + contain exactly one IP address which is then used as the original + IP address. + + There are cases where a NAT box decides to remove mappings that + are still alive (for example, the keepalive interval is too long, + or the NAT box is rebooted). To recover in these cases, hosts that + are not behind a NAT SHOULD send all packets (including + retransmission packets) to the IP address and port from the last + valid authenticated packet from the other end (i.e., dynamically + update the address). A host behind a NAT SHOULD NOT do this + because it opens a DoS attack possibility. Any authenticated IKE + packet or any authenticated UDP encapsulated ESP packet can be + used to detect that the IP address or the port has changed. + + Note that similar but probably not identical actions will likely + be needed to make IKE work with Mobile IP, but such processing is + not addressed by this document. + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 39] + + + + + +Internet-Draft September 23, 2004 + + +2.24 ECN (Explicit Congestion Notification) + + When IPsec tunnels behave as originally specified in [RFC2401], ECN + usage is not appropriate for the outer IP headers because tunnel + decapsulation processing discards ECN congestion indications to the + detriment of the network. ECN support for IPsec tunnels for + IKEv1-based IPsec requires multiple operating modes and negotiation + (see RFC3168]). IKEv2 simplifies this situation by requiring that + ECN be usable in the outer IP headers of all tunnel-mode IPsec SAs + created by IKEv2. Specifically, tunnel encapsulators and + decapsulators for all tunnel-mode Security Associations (SAs) created + by IKEv2 MUST support the ECN full-functionality option for tunnels + specified in [RFC3168] and MUST implement the tunnel encapsulation + and decapsulation processing specified in [RFC2401bis] to prevent + discarding of ECN congestion indications. + +3 Header and Payload Formats + +3.1 The IKE Header + + IKE messages use UDP ports 500 and/or 4500, with one IKE message per + UDP datagram. Information from the beginning of the packet through + the UDP header is largely ignored except that the IP addresses and + UDP ports from the headers are reversed and used for return packets. + When sent on UDP port 500, IKE messages begin immediately following + the UDP header. When sent on UDP port 4500, IKE messages have + prepended four octets of zero. These four octets of zero are not + part of the IKE message and are not included in any of the length + fields or checksums defined by IKE. Each IKE message begins with the + IKE header, denoted HDR in this memo. Following the header are one or + more IKE payloads each identified by a "Next Payload" field in the + preceding payload. Payloads are processed in the order in which they + appear in an IKE message by invoking the appropriate processing + routine according to the "Next Payload" field in the IKE header and + subsequently according to the "Next Payload" field in the IKE payload + itself until a "Next Payload" field of zero indicates that no + payloads follow. If a payload of type "Encrypted" is found, that + payload is decrypted and its contents parsed as additional payloads. + An Encrypted payload MUST be the last payload in a packet and an + encrypted payload MUST NOT contain another encrypted payload. + + The Recipient SPI in the header identifies an instance of an IKE + security association. It is therefore possible for a single instance + of IKE to multiplex distinct sessions with multiple peers. + + All multi-octet fields representing integers are laid out in big + endian order (aka most significant byte first, or network byte + order). + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 40] + + + + + +Internet-Draft September 23, 2004 + + + The format of the IKE header is shown in Figure 4. + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Initiator's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Responder's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! MjVer ! MnVer ! Exchange Type ! Flags ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Message ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 4: IKE Header Format + + o Initiator's SPI (8 octets) - A value chosen by the + initiator to identify a unique IKE security association. This + value MUST NOT be zero. + + o Responder's SPI (8 octets) - A value chosen by the + responder to identify a unique IKE security association. This + value MUST be zero in the first message of an IKE Initial + Exchange (including repeats of that message including a + cookie) and MUST NOT be zero in any other message. + + o Next Payload (1 octet) - Indicates the type of payload that + immediately follows the header. The format and value of each + payload is defined below. + + o Major Version (4 bits) - indicates the major version of the IKE + protocol in use. Implementations based on this version of IKE + MUST set the Major Version to 2. Implementations based on + previous versions of IKE and ISAKMP MUST set the Major Version + to 1. Implementations based on this version of IKE MUST reject + or ignore messages containing a version number greater than + 2. + + o Minor Version (4 bits) - indicates the minor version of the + IKE protocol in use. Implementations based on this version of + IKE MUST set the Minor Version to 0. They MUST ignore the minor + version number of received messages. + + o Exchange Type (1 octet) - indicates the type of exchange being + used. This constrains the payloads sent in each message and + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 41] + + + + + +Internet-Draft September 23, 2004 + + + orderings of messages in an exchange. + + Exchange Type Value + + RESERVED 0-33 + IKE_SA_INIT 34 + IKE_AUTH 35 + CREATE_CHILD_SA 36 + INFORMATIONAL 37 + RESERVED TO IANA 38-239 + Reserved for private use 240-255 + + o Flags (1 octet) - indicates specific options that are set + for the message. Presence of options are indicated by the + appropriate bit in the flags field being set. The bits are + defined LSB first, so bit 0 would be the least significant + bit of the Flags octet. In the description below, a bit + being 'set' means its value is '1', while 'cleared' means + its value is '0'. + + -- X(reserved) (bits 0-2) - These bits MUST be cleared + when sending and MUST be ignored on receipt. + + -- I(nitiator) (bit 3 of Flags) - This bit MUST be set in + messages sent by the original initiator of the IKE_SA + and MUST be cleared in messages sent by the original + responder. It is used by the recipient to determine + which eight octets of the SPI was generated by the + recipient. + + -- V(ersion) (bit 4 of Flags) - This bit indicates that + the transmitter is capable of speaking a higher major + version number of the protocol than the one indicated + in the major version number field. Implementations of + IKEv2 must clear this bit when sending and MUST ignore + it in incoming messages. + + -- R(esponse) (bit 5 of Flags) - This bit indicates that + this message is a response to a message containing + the same message ID. This bit MUST be cleared in all + request messages and MUST be set in all responses. + An IKE endpoint MUST NOT generate a response to a + message that is marked as being a response. + + -- X(reserved) (bits 6-7 of Flags) - These bits MUST be + cleared when sending and MUST be ignored on receipt. + + o Message ID (4 octets) - Message identifier used to control + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 42] + + + + + +Internet-Draft September 23, 2004 + + + retransmission of lost packets and matching of requests and + responses. It is essential to the security of the protocol + because it is used to prevent message replay attacks. + See sections 2.1 and 2.2. + + o Length (4 octets) - Length of total message (header + payloads) + in octets. + +3.2 Generic Payload Header + + Each IKE payload defined in sections 3.3 through 3.16 begins with a + generic payload header, shown in Figure 5. Figures for each payload + below will include the generic payload header but for brevity the + description of each field will be omitted. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 5: Generic Payload Header + + The Generic Payload Header fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. This field provides + a "chaining" capability whereby additional payloads can be + added to a message by appending it to the end of the message + and setting the "Next Payload" field of the preceding payload + to indicate the new payload's type. An Encrypted payload, + which must always be the last payload of a message, is an + exception. It contains data structures in the format of + additional payloads. In the header of an Encrypted payload, + the Next Payload field is set to the payload type of the first + contained payload (instead of 0). + + Payload Type Values + + Next Payload Type Notation Value + + No Next Payload 0 + + RESERVED 1-32 + Security Association SA 33 + Key Exchange KE 34 + Identification - Initiator IDi 35 + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 43] + + + + + +Internet-Draft September 23, 2004 + + + Identification - Responder IDr 36 + Certificate CERT 37 + Certificate Request CERTREQ 38 + Authentication AUTH 39 + Nonce Ni, Nr 40 + Notify N 41 + Delete D 42 + Vendor ID V 43 + Traffic Selector - Initiator TSi 44 + Traffic Selector - Responder TSr 45 + Encrypted E 46 + Configuration CP 47 + Extensible Authentication EAP 48 + RESERVED TO IANA 49-127 + PRIVATE USE 128-255 + + Payload type values 1-32 should not be used so that there is no + overlap with the code assignments for IKEv1. Payload type values + 49-127 are reserved to IANA for future assignment in IKEv2 (see + section 6). Payload type values 128-255 are for private use among + mutually consenting parties. + + o Critical (1 bit) - MUST be set to zero if the sender wants + the recipient to skip this payload if it does not + understand the payload type code in the Next Payload field + of the previous payload. MUST be set to one if the + sender wants the recipient to reject this entire message + if it does not understand the payload type. MUST be ignored + by the recipient if the recipient understands the payload type + code. MUST be set to zero for payload types defined in this + document. Note that the critical bit applies to the current + payload rather than the "next" payload whose type code + appears in the first octet. The reasoning behind not setting + the critical bit for payloads defined in this document is + that all implementations MUST understand all payload types + defined in this document and therefore must ignore the + Critical bit's value. Skipped payloads are expected to + have valid Next Payload and Payload Length fields. + + o RESERVED (7 bits) - MUST be sent as zero; MUST be ignored on + receipt. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + +3.3 Security Association Payload + + The Security Association Payload, denoted SA in this memo, is used to + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 44] + + + + + +Internet-Draft September 23, 2004 + + + negotiate attributes of a security association. Assembly of Security + Association Payloads requires great peace of mind. An SA payload MAY + contain multiple proposals. If there is more than one, they MUST be + ordered from most preferred to least preferred. Each proposal may + contain multiple IPsec protocols (where a protocol is IKE, ESP, or + AH), each protocol MAY contain multiple transforms, and each + transform MAY contain multiple attributes. When parsing an SA, an + implementation MUST check that the total Payload Length is consistent + with the payload's internal lengths and counts. Proposals, + Transforms, and Attributes each have their own variable length + encodings. They are nested such that the Payload Length of an SA + includes the combined contents of the SA, Proposal, Transform, and + Attribute information. The length of a Proposal includes the lengths + of all Transforms and Attributes it contains. The length of a + Transform includes the lengths of all Attributes it contains. + + The syntax of Security Associations, Proposals, Transforms, and + Attributes is based on ISAKMP, however the semantics are somewhat + different. The reason for the complexity and the hierarchy is to + allow for multiple possible combinations of algorithms to be encoded + in a single SA. Sometimes there is a choice of multiple algorithms, + while other times there is a combination of algorithms. For example, + an initiator might want to propose using (AH w/MD5 and ESP w/3DES) OR + (ESP w/MD5 and 3DES). + + One of the reasons the semantics of the SA payload has changed from + ISAKMP and IKEv1 is to make the encodings more compact in common + cases. + + The Proposal structure contains within it a Proposal # and an IPsec + protocol ID. Each structure MUST have the same Proposal # as the + previous one or be one (1) greater. The first Proposal MUST have a + Proposal # of one (1). If two successive structures have the same + Proposal number, it means that the proposal consists of the first + structure AND the second. So a proposal of AH AND ESP would have two + proposal structures, one for AH and one for ESP and both would have + Proposal #1. A proposal of AH OR ESP would have two proposal + structures, one for AH with proposal #1 and one for ESP with proposal + #2. + + Each Proposal/Protocol structure is followed by one or more transform + structures. The number of different transforms is generally + determined by the Protocol. AH generally has a single transform: an + integrity check algorithm. ESP generally has two: an encryption + algorithm and an integrity check algorithm. IKE generally has four + transforms: a Diffie-Hellman group, an integrity check algorithm, a + prf algorithm, and an encryption algorithm. If an algorithm that + combines encryption and integrity protection is proposed, it MUST be + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 45] + + + + + +Internet-Draft September 23, 2004 + + + proposed as an encryption algorithm and an integrity protection + algorithm MUST NOT be proposed. For each Protocol, the set of + permissible transforms are assigned transform ID numbers, which + appear in the header of each transform. + + If there are multiple transforms with the same Transform Type, the + proposal is an OR of those transforms. If there are multiple + Transforms with different Transform Types, the proposal is an AND of + the different groups. For example, to propose ESP with (3DES or IDEA) + and (HMAC_MD5 or HMAC_SHA), the ESP proposal would contain two + Transform Type 1 candidates (one for 3DES and one for IDEA) and two + Transform Type 2 candidates (one for HMAC_MD5 and one for HMAC_SHA). + This effectively proposes four combinations of algorithms. If the + initiator wanted to propose only a subset of those - say (3DES and + HMAC_MD5) or (IDEA and HMAC_SHA), there is no way to encode that as + multiple transforms within a single Proposal. Instead, the initiator + would have to construct two different Proposals, each with two + transforms. + + A given transform MAY have one or more Attributes. Attributes are + necessary when the transform can be used in more than one way, as + when an encryption algorithm has a variable key size. The transform + would specify the algorithm and the attribute would specify the key + size. Most transforms do not have attributes. A transform MUST NOT + have multiple attributes of the same type. To propose alternate + values for an attribute (for example, multiple key sizes for the AES + encryption algorithm), and implementation MUST include multiple + Transforms with the same Transform Type each with a single Attribute. + + Note that the semantics of Transforms and Attributes are quite + different than in IKEv1. In IKEv1, a single Transform carried + multiple algorithms for a protocol with one carried in the Transform + and the others carried in the Attributes. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 6: Security Association Payload + + o Proposals (variable) - one or more proposal substructures. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 46] + + + + + +Internet-Draft September 23, 2004 + + + The payload type for the Security Association Payload is thirty + three (33). + +3.3.1 Proposal Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 2 ! RESERVED ! Proposal Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Proposal # ! Protocol ID ! SPI Size !# of Transforms! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ SPI (variable) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 7: Proposal Substructure + + o 0 (last) or 2 (more) (1 octet) - Specifies whether this is the + last Proposal Substructure in the SA. This syntax is inherited + from ISAKMP, but is unnecessary because the last Proposal + could be identified from the length of the SA. The value (2) + corresponds to a Payload Type of Proposal in IKEv1, and the + first four octets of the Proposal structure are designed to + look somewhat like the header of a Payload. + + o RESERVED (1 octet) - MUST be sent as zero; MUST be ignored on + receipt. + + o Proposal Length (2 octets) - Length of this proposal, + including all transforms and attributes that follow. + + o Proposal # (1 octet) - When a proposal is made, the first + proposal in an SA payload MUST be #1, and subsequent proposals + MUST either be the same as the previous proposal (indicating + an AND of the two proposals) or one more than the previous + proposal (indicating an OR of the two proposals). When a + proposal is accepted, all of the proposal numbers in the + SA payload MUST be the same and MUST match the number on the + proposal sent that was accepted. + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 47] + + + + + +Internet-Draft September 23, 2004 + + + o Protocol ID (1 octet) - Specifies the IPsec protocol + identifier for the current negotiation. The defined values + are: + + Protocol Protocol ID + RESERVED 0 + IKE 1 + AH 2 + ESP 3 + RESERVED TO IANA 4-200 + PRIVATE USE 201-255 + + + o SPI Size (1 octet) - For an initial IKE_SA negotiation, + this field MUST be zero; the SPI is obtained from the + outer header. During subsequent negotiations, + it is equal to the size, in octets, of the SPI of the + corresponding protocol (8 for IKE, 4 for ESP and AH). + + o # of Transforms (1 octet) - Specifies the number of + transforms in this proposal. + + o SPI (variable) - The sending entity's SPI. Even if the SPI + Size is not a multiple of 4 octets, there is no padding + applied to the payload. When the SPI Size field is zero, + this field is not present in the Security Association + payload. + + o Transforms (variable) - one or more transform substructures. + + +3.3.2 Transform Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 3 ! RESERVED ! Transform Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !Transform Type ! RESERVED ! Transform ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Transform Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 8: Transform Substructure + + o 0 (last) or 3 (more) (1 octet) - Specifies whether this is the + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 48] + + + + + +Internet-Draft September 23, 2004 + + + last Transform Substructure in the Proposal. This syntax is + inherited from ISAKMP, but is unnecessary because the last + Proposal could be identified from the length of the SA. The + value (3) corresponds to a Payload Type of Transform in IKEv1, + and the first four octets of the Transform structure are + designed to look somewhat like the header of a Payload. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Transform Length - The length (in octets) of the Transform + Substructure including Header and Attributes. + + o Transform Type (1 octet) - The type of transform being specified + in this transform. Different protocols support different + transform types. For some protocols, some of the transforms + may be optional. If a transform is optional and the initiator + wishes to propose that the transform be omitted, no transform + of the given type is included in the proposal. If the + initiator wishes to make use of the transform optional to + the responder, it includes a transform substructure with + transform ID = 0 as one of the options. + + o Transform ID (2 octets) - The specific instance of the transform + type being proposed. + + Transform Type Values + + Transform Used In + Type + RESERVED 0 + Encryption Algorithm (ENCR) 1 (IKE and ESP) + Pseudo-random Function (PRF) 2 (IKE) + Integrity Algorithm (INTEG) 3 (IKE, AH, optional in ESP) + Diffie-Hellman Group (D-H) 4 (IKE, optional in AH & ESP) + Extended Sequence Numbers (ESN) 5 (Optional in AH and ESP) + RESERVED TO IANA 6-240 + PRIVATE USE 241-255 + + For Transform Type 1 (Encryption Algorithm), defined Transform IDs + are: + + Name Number Defined In + RESERVED 0 + ENCR_DES_IV64 1 (RFC1827) + ENCR_DES 2 (RFC2405) + ENCR_3DES 3 (RFC2451) + ENCR_RC5 4 (RFC2451) + ENCR_IDEA 5 (RFC2451) + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 49] + + + + + +Internet-Draft September 23, 2004 + + + ENCR_CAST 6 (RFC2451) + ENCR_BLOWFISH 7 (RFC2451) + ENCR_3IDEA 8 (RFC2451) + ENCR_DES_IV32 9 + RESERVED 10 + ENCR_NULL 11 (RFC2410) + ENCR_AES_CBC 12 (RFC3602) + ENCR_AES_CTR 13 (RFC3664) + + values 14-1023 are reserved to IANA. Values 1024-65535 are for + private use among mutually consenting parties. + + For Transform Type 2 (Pseudo-random Function), defined Transform IDs + are: + + Name Number Defined In + RESERVED 0 + PRF_HMAC_MD5 1 (RFC2104) + PRF_HMAC_SHA1 2 (RFC2104) + PRF_HMAC_TIGER 3 (RFC2104) + PRF_AES128_CBC 4 (RFC3664) + + values 5-1023 are reserved to IANA. Values 1024-65535 are for + private use among mutually consenting parties. + + + For Transform Type 3 (Integrity Algorithm), defined Transform IDs + are: + + Name Number Defined In + NONE 0 + AUTH_HMAC_MD5_96 1 (RFC2403) + AUTH_HMAC_SHA1_96 2 (RFC2404) + AUTH_DES_MAC 3 + AUTH_KPDK_MD5 4 (RFC1826) + AUTH_AES_XCBC_96 5 (RFC3566) + + values 6-1023 are reserved to IANA. Values 1024-65535 are for + private use among mutually consenting parties. + + For Transform Type 4 (Diffie-Hellman Group), defined Transform IDs + are: + + Name Number + NONE 0 + Defined in Appendix B 1 - 2 + RESERVED 3 - 4 + Defined in [ADDGROUP] 5 + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 50] + + + + + +Internet-Draft September 23, 2004 + + + RESERVED TO IANA 6 - 13 + Defined in [ADDGROUP] 14 - 18 + RESERVED TO IANA 19 - 1023 + PRIVATE USE 1024-65535 + + + + For Transform Type 5 (Extended Sequence Numbers), defined Transform + IDs are: + + Name Number + No Extended Sequence Numbers 0 + Extended Sequence Numbers 1 + RESERVED 2 - 65535 + + If Transform Type 5 is not included in a proposal, use of + Extended Sequence Numbers is assumed. + +3.3.3 Valid Transform Types by Protocol + + The number and type of transforms that accompany an SA payload are + dependent on the protocol in the SA itself. An SA payload proposing + the establishment of an SA has the following mandatory and optional + transform types. A compliant implementation MUST understand all + mandatory and optional types for each protocol it supports (though it + need not accept proposals with unacceptable suites). A proposal MAY + omit the optional types if the only value for them it will accept is + NONE. + + Protocol Mandatory Types Optional Types + IKE ENCR, PRF, INTEG, D-H + ESP ENCR INTEG, D-H, ESN + AH INTEG D-H, ESN + +3.3.4 Mandatory Transform IDs + + The specification of suites that MUST and SHOULD be supported for + interoperability has been removed from this document because they are + likely to change more rapidly than this document evolves. + + An important lesson learned from IKEv1 is that no system should only + implement the mandatory algorithms and expect them to be the best + choice for all customers. For example, at the time that this document + was being written, many IKEv1 implementers are starting to migrate to + AES in CBC mode for VPN applications. Many IPsec systems based on + IKEv2 will implement AES, additional Diffie-Hellman groups, and + additional hash algorithms, and some IPsec customers already require + these algorithms in addition to the ones listed above. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 51] + + + + + +Internet-Draft September 23, 2004 + + + It is likely that IANA will add additional transforms in the future, + and some users may want to use private suites, especially for IKE + where implementations should be capable of supporting different + parameters, up to certain size limits. In support of this goal, all + implementations of IKEv2 SHOULD include a management facility that + allows specification (by a user or system administrator) of Diffie- + Hellman parameters (the generator, modulus, and exponent lengths and + values) for new DH groups. Implementations SHOULD provide a + management interface via which these parameters and the associated + transform IDs may be entered (by a user or system administrator), to + enable negotiating such groups. + + All implementations of IKEv2 MUST include a management facility that + enables a user or system administrator to specify the suites that are + acceptable for use with IKE. Upon receipt of a payload with a set of + transform IDs, the implementation MUST compare the transmitted + transform IDs against those locally configured via the management + controls, to verify that the proposed suite is acceptable based on + local policy. The implementation MUST reject SA proposals that are + not authorized by these IKE suite controls. Note that cryptographic + suites that MUST be implemented need not be configured as acceptable + to local policy. + +3.3.5 Transform Attributes + + Each transform in a Security Association payload may include + attributes that modify or complete the specification of the + transform. These attributes are type/value pairs and are defined + below. For example, if an encryption algorithm has a variable length + key, the key length to be used may be specified as an attribute. + Attributes can have a value with a fixed two octet length or a + variable length value. For the latter, the attribute is encoded as + type/length/value. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !A! Attribute Type ! AF=0 Attribute Length ! + !F! ! AF=1 Attribute Value ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! AF=0 Attribute Value ! + ! AF=1 Not Transmitted ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 9: Data Attributes + + o Attribute Type (2 octets) - Unique identifier for each type of + attribute (see below). + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 52] + + + + + +Internet-Draft September 23, 2004 + + + The most significant bit of this field is the Attribute Format + bit (AF). It indicates whether the data attributes follow the + Type/Length/Value (TLV) format or a shortened Type/Value (TV) + format. If the AF bit is zero (0), then the Data Attributes + are of the Type/Length/Value (TLV) form. If the AF bit is a + one (1), then the Data Attributes are of the Type/Value form. + + o Attribute Length (2 octets) - Length in octets of the Attribute + Value. When the AF bit is a one (1), the Attribute Value is + only 2 octets and the Attribute Length field is not present. + + o Attribute Value (variable length) - Value of the Attribute + associated with the Attribute Type. If the AF bit is a + zero (0), this field has a variable length defined by the + Attribute Length field. If the AF bit is a one (1), the + Attribute Value has a length of 2 octets. + + Note that only a single attribute type (Key Length) is defined, and + it is fixed length. The variable length encoding specification is + included only for future extensions. The only algorithms defined in + this document that accept attributes are the AES based encryption, + integrity, and pseudo-random functions, which require a single + attribute specifying key width. + + Attributes described as basic MUST NOT be encoded using the variable + length encoding. Variable length attributes MUST NOT be encoded as + basic even if their value can fit into two octets. NOTE: This is a + change from IKEv1, where increased flexibility may have simplified + the composer of messages but certainly complicated the parser. + + Attribute Type value Attribute Format + -------------------------------------------------------------- + RESERVED 0-13 + Key Length (in bits) 14 TV + RESERVED 15-17 + RESERVED TO IANA 18-16383 + PRIVATE USE 16384-32767 + + Values 0-13 and 15-17 were used in a similar context in IKEv1, and + should not be assigned except to matching values. Values 18-16383 are + reserved to IANA. Values 16384-32767 are for private use among + mutually consenting parties. + + - Key Length + + When using an Encryption Algorithm that has a variable length key, + this attribute specifies the key length in bits. (MUST use network + byte order). This attribute MUST NOT be used when the specified + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 53] + + + + + +Internet-Draft September 23, 2004 + + + Encryption Algorithm uses a fixed length key. + +3.3.6 Attribute Negotiation + + During security association negotiation initiators present offers to + responders. Responders MUST select a single complete set of + parameters from the offers (or reject all offers if none are + acceptable). If there are multiple proposals, the responder MUST + choose a single proposal number and return all of the Proposal + substructures with that Proposal number. If there are multiple + Transforms with the same type the responder MUST choose a single one. + Any attributes of a selected transform MUST be returned unmodified. + The initiator of an exchange MUST check that the accepted offer is + consistent with one of its proposals, and if not that response MUST + be rejected. + + Negotiating Diffie-Hellman groups presents some special challenges. + SA offers include proposed attributes and a Diffie-Hellman public + number (KE) in the same message. If in the initial exchange the + initiator offers to use one of several Diffie-Hellman groups, it + SHOULD pick the one the responder is most likely to accept and + include a KE corresponding to that group. If the guess turns out to + be wrong, the responder will indicate the correct group in the + response and the initiator SHOULD pick an element of that group for + its KE value when retrying the first message. It SHOULD, however, + continue to propose its full supported set of groups in order to + prevent a man in the middle downgrade attack. + + Implementation Note: + + Certain negotiable attributes can have ranges or could have + multiple acceptable values. These include the key length of a + variable key length symmetric cipher. To further interoperability + and to support upgrading endpoints independently, implementers of + this protocol SHOULD accept values which they deem to supply + greater security. For instance if a peer is configured to accept a + variable lengthed cipher with a key length of X bits and is + offered that cipher with a larger key length, the implementation + SHOULD accept the offer if it supports use of the longer key. + + Support of this capability allows an implementation to express a + concept of "at least" a certain level of security-- "a key length of + _at least_ X bits for cipher Y". + +3.4 Key Exchange Payload + + The Key Exchange Payload, denoted KE in this memo, is used to + exchange Diffie-Hellman public numbers as part of a Diffie-Hellman + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 54] + + + + + +Internet-Draft September 23, 2004 + + + key exchange. The Key Exchange Payload consists of the IKE generic + payload header followed by the Diffie-Hellman public value itself. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! DH Group # ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Key Exchange Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 10: Key Exchange Payload Format + + A key exchange payload is constructed by copying one's Diffie-Hellman + public value into the "Key Exchange Data" portion of the payload. + The length of the Diffie-Hellman public value MUST be equal to the + length of the prime modulus over which the exponentiation was + performed, prepending zero bits to the value if necessary. + + The DH Group # identifies the Diffie-Hellman group in which the Key + Exchange Data was computed (see section 3.3.2). If the selected + proposal uses a different Diffie-Hellman group, the message MUST be + rejected with a Notify payload of type INVALID_KE_PAYLOAD. + + The payload type for the Key Exchange payload is thirty four (34). + +3.5 Identification Payloads + + The Identification Payloads, denoted IDi and IDr in this memo, allow + peers to assert an identity to one another. This identity may be used + for policy lookup, but does not necessarily have to match anything in + the CERT payload; both fields may be used by an implementation to + perform access control decisions. + + NOTE: In IKEv1, two ID payloads were used in each direction to hold + Traffic Selector information for data passing over the SA. In IKEv2, + this information is carried in Traffic Selector (TS) payloads (see + section 3.13). + + The Identification Payload consists of the IKE generic payload header + followed by identification fields as follows: + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 55] + + + + + +Internet-Draft September 23, 2004 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ID Type ! RESERVED | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Identification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 11: Identification Payload Format + + o ID Type (1 octet) - Specifies the type of Identification being + used. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Identification Data (variable length) - Value, as indicated by + the Identification Type. The length of the Identification Data + is computed from the size in the ID payload header. + + The payload types for the Identification Payload are thirty five (35) + for IDi and thirty six (36) for IDr. + + The following table lists the assigned values for the Identification + Type field, followed by a description of the Identification Data + which follows: + + ID Type Value + ------- ----- + RESERVED 0 + + ID_IPV4_ADDR 1 + + A single four (4) octet IPv4 address. + + ID_FQDN 2 + + A fully-qualified domain name string. An example of a + ID_FQDN is, "example.com". The string MUST not contain any + terminators (e.g., NULL, CR, etc.). + + ID_RFC822_ADDR 3 + + A fully-qualified RFC822 email address string, An example of + a ID_RFC822_ADDR is, "jsmith@example.com". The string MUST + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 56] + + + + + +Internet-Draft September 23, 2004 + + + not contain any terminators. + + Reserved to IANA 4 + + ID_IPV6_ADDR 5 + + A single sixteen (16) octet IPv6 address. + + Reserved to IANA 6 - 8 + + ID_DER_ASN1_DN 9 + + The binary DER encoding of an ASN.1 X.500 Distinguished Name + [X.501]. + + ID_DER_ASN1_GN 10 + + The binary DER encoding of an ASN.1 X.500 GeneralName + [X.509]. + + ID_KEY_ID 11 + + An opaque octet stream which may be used to pass vendor- + specific information necessary to do certain proprietary + types of identification. + + Reserved to IANA 12-200 + + Reserved for private use 201-255 + + Two implementations will interoperate only if each can generate a + type of ID acceptable to the other. To assure maximum + interoperability, implementations MUST be configurable to send at + least one of ID_IPV4_ADDR, ID_FQDN, ID_RFC822_ADDR, or ID_KEY_ID, and + MUST be configurable to accept all of these types. Implementations + SHOULD be capable of generating and accepting all of these types. + IPv6 capable implementations MUST additionally be configurable to + accept ID_IPV6_ADDR. IPv6 only implementations MAY be configurable + to send only ID_IPV6_ADDR. + + +3.6 Certificate Payload + + The Certificate Payload, denoted CERT in this memo, provides a means + to transport certificates or other authentication related information + via IKE. Certificate payloads SHOULD be included in an exchange if + certificates are available to the sender unless the peer has + indicated an ability to retrieve this information from elsewhere + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 57] + + + + + +Internet-Draft September 23, 2004 + + + using an HTTP_CERT_LOOKUP_SUPPORTED Notify payload. Note that the + term "Certificate Payload" is somewhat misleading, because not all + authentication mechanisms use certificates and data other than + certificates may be passed in this payload. + + The Certificate Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certificate Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 12: Certificate Payload Format + + o Certificate Encoding (1 octet) - This field indicates the type + of certificate or certificate-related information contained + in the Certificate Data field. + + Certificate Encoding Value + -------------------- ----- + RESERVED 0 + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + X.509 Certificate - Signature 4 + Kerberos Token 6 + Certificate Revocation List (CRL) 7 + Authority Revocation List (ARL) 8 + SPKI Certificate 9 + X.509 Certificate - Attribute 10 + Raw RSA Key 11 + Hash and URL of X.509 certificate 12 + Hash and URL of X.509 bundle 13 + RESERVED to IANA 14 - 200 + PRIVATE USE 201 - 255 + + o Certificate Data (variable length) - Actual encoding of + certificate data. The type of certificate is indicated + by the Certificate Encoding field. + + The payload type for the Certificate Payload is thirty seven (37). + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 58] + + + + + +Internet-Draft September 23, 2004 + + + Specific syntax is for some of the certificate type codes above is + not defined in this document. The types whose syntax is defined in + this document are: + + X.509 Certificate - Signature (4) contains a DER encoded X.509 + certificate whose public key is used to validate the sender's AUTH + payload. + + Certificate Revocation List (7) contains a DER encoded X.509 + certificate revocation list. + + Raw RSA Key (11) contains a PKCS #1 encoded RSA key. + + Hash and URL encodings (12-13) allow IKE messages to remain short + by replacing long data structures with a 20 octet SHA-1 hash of + the replaced value followed by a variable length URL that resolves + to the DER encoded data structure itself. This improves efficiency + when the endpoints have certificate data cached and makes IKE less + subject to denial of service attacks that become easier to mount + when IKE messages are large enough to require IP fragmentation + [KPS03]. + + Use the following ASN.1 definition for an X.509 bundle: + + CertBundle + { iso(1) identified-organization(3) dod(6) internet(1) + security(5) mechanisms(5) pkix(7) id-mod(0) + id-mod-cert-bundle(34) } + + DEFINITIONS EXPLICIT TAGS ::= + BEGIN + + IMPORTS + Certificate, CertificateList + FROM PKIX1Explicit88 + { iso(1) identified-organization(3) dod(6) + internet(1) security(5) mechanisms(5) pkix(7) + id-mod(0) id-pkix1-explicit(18) } ; + + CertificateOrCRL ::= CHOICE { + cert [0] Certificate, + crl [1] CertificateList } + + CertificateBundle ::= SEQUENCE OF CertificateOrCRL + + END + + Implementations MUST be capable of being configured to send and + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 59] + + + + + +Internet-Draft September 23, 2004 + + + accept up to four X.509 certificates in support of authentication, + and also MUST be capable of being configured to send and accept the + first two Hash and URL formats (with HTTP URLs). Implementations + SHOULD be capable of being configured to send and accept Raw RSA + keys. If multiple certificates are sent, the first certificate MUST + contain the public key used to sign the AUTH payload. The other + certificates may be sent in any order. + +3.7 Certificate Request Payload + + The Certificate Request Payload, denoted CERTREQ in this memo, + provides a means to request preferred certificates via IKE and can + appear in the IKE_INIT_SA response and/or the IKE_AUTH request. + Certificate Request payloads MAY be included in an exchange when the + sender needs to get the certificate of the receiver. If multiple CAs + are trusted and the cert encoding does not allow a list, then + multiple Certificate Request payloads SHOULD be transmitted. + + The Certificate Request Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certification Authority ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 13: Certificate Request Payload Format + + o Certificate Encoding (1 octet) - Contains an encoding of the type + or format of certificate requested. Values are listed in section + 3.6. + + o Certification Authority (variable length) - Contains an encoding + of an acceptable certification authority for the type of + certificate requested. + + The payload type for the Certificate Request Payload is thirty eight + (38). + + The Certificate Encoding field has the same values as those defined + in section 3.6. The Certification Authority field contains an + indicator of trusted authorities for this certificate type. The + Certification Authority value is a concatenated list of SHA-1 hashes + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 60] + + + + + +Internet-Draft September 23, 2004 + + + of the public keys of trusted CAs. Each is encoded as the SHA-1 hash + of the Subject Public Key Info element (see section 4.1.2.7 of + [RFC3280]) from each Trust Anchor certificate. The twenty-octet + hashes are concatenated and included with no other formatting. + + Note that the term "Certificate Request" is somewhat misleading, in + that values other than certificates are defined in a "Certificate" + payload and requests for those values can be present in a Certificate + Request Payload. The syntax of the Certificate Request payload in + such cases is not defined in this document. + + The Certificate Request Payload is processed by inspecting the "Cert + Encoding" field to determine whether the processor has any + certificates of this type. If so the "Certification Authority" field + is inspected to determine if the processor has any certificates which + can be validated up to one of the specified certification + authorities. This can be a chain of certificates. + + If an end-entity certificate exists which satisfies the criteria + specified in the CERTREQ, a certificate or certificate chain SHOULD + be sent back to the certificate requestor if: + + - the recipient of the CERTREQ is configured to use certificate + authentication, + + - is allowed to send a CERT payload, + + - has matching CA trust policy governing the current negotiation, + and + + - has at least one time-wise and usage appropriate end-entity + certificate chaining to a CA provided in the CERTREQ. + + Certificate revocation checking must be considered during the + chaining process used to select a certificate. Note that even if two + peers are configured to use two different CAs, cross-certification + relationships should be supported by appropriate selection logic. The + intent is not to prevent communication through the strict adherence + of selection of a certificate based on CERTREQ, when an alternate + certificate could be selected by the sender which would still enable + the recipient to successfully validate and trust it through trust + conveyed by cross-certification, CRLs or other out-of-band configured + means. Thus the processing of a CERTREQ should be seen as a + suggestion for a certificate to select, not a mandated one. If no + certificates exist then the CERTREQ is ignored. This is not an error + condition of the protocol. There may be cases where there is a + preferred CA sent in the CERTREQ, but an alternate might be + acceptable (perhaps after prompting a human operator). + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 61] + + + + + +Internet-Draft September 23, 2004 + + +3.8 Authentication Payload + + The Authentication Payload, denoted AUTH in this memo, contains data + used for authentication purposes. The syntax of the Authentication + data varies according to the Auth Method as specified below. + + The Authentication Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Auth Method ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Authentication Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 14: Authentication Payload Format + + o Auth Method (1 octet) - Specifies the method of authentication + used. Values defined are: + + RSA Digital Signature (1) - Computed as specified in section + 2.15 using an RSA private key over a PKCS#1 padded hash. + + Shared Key Message Integrity Code (2) - Computed as specified in + section 2.15 using the shared key associated with the identity + in the ID payload and the negotiated prf function + + DSS Digital Signature (3) - Computed as specified in section + 2.15 using a DSS private key over a SHA-1 hash. + + The values 0 and 4-200 are reserved to IANA. The values 201-255 + are available for private use. + + o Authentication Data (variable length) - see section 2.15. + + The payload type for the Authentication Payload is thirty nine (39). + +3.9 Nonce Payload + + The Nonce Payload, denoted Ni and Nr in this memo for the initiator's + and responder's nonce respectively, contains random data used to + guarantee liveness during an exchange and protect against replay + attacks. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 62] + + + + + +Internet-Draft September 23, 2004 + + + The Nonce Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Nonce Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 15: Nonce Payload Format + + o Nonce Data (variable length) - Contains the random data generated + by the transmitting entity. + + The payload type for the Nonce Payload is forty (40). + + The size of a Nonce MUST be between 16 and 256 octets inclusive. + Nonce values MUST NOT be reused. + +3.10 Notify Payload + + The Notify Payload, denoted N in this document, is used to transmit + informational data, such as error conditions and state transitions, + to an IKE peer. A Notify Payload may appear in a response message + (usually specifying why a request was rejected), in an INFORMATIONAL + Exchange (to report an error not in an IKE request), or in any other + message to indicate sender capabilities or to modify the meaning of + the request. + + + + + + + + + + + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 63] + + + + + +Internet-Draft September 23, 2004 + + + The Notify Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! Notify Message Type ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Notification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 16: Notification Payload Format + + o Protocol ID (1 octet) - If this notification concerns + an existing SA, this field indicates the type of that SA. + For IKE_SA notifications, this field MUST be one (1). For + notifications concerning IPsec SAs this field MUST contain + either (2) to indicate AH or (3) to indicate ESP. For + notifications which do not relate to an existing SA, this + field MUST be sent as zero and MUST be ignored on receipt. + All other values for this field are reserved to IANA for future + assignment. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by + the IPsec protocol ID or zero if no SPI is applicable. For a + notification concerning the IKE_SA, the SPI Size MUST be zero. + + o Notify Message Type (2 octets) - Specifies the type of + notification message. + + o SPI (variable length) - Security Parameter Index. + + o Notification Data (variable length) - Informational or error data + transmitted in addition to the Notify Message Type. Values for + this field are type specific (see below). + + The payload type for the Notification Payload is forty one (41). + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 64] + + + + + +Internet-Draft September 23, 2004 + + +3.10.1 Notify Message Types + + Notification information can be error messages specifying why an SA + could not be established. It can also be status data that a process + managing an SA database wishes to communicate with a peer process. + The table below lists the Notification messages and their + corresponding values. The number of different error statuses was + greatly reduced from IKE V1 both for simplification and to avoid + giving configuration information to probers. + + Types in the range 0 - 16383 are intended for reporting errors. An + implementation receiving a Notify payload with one of these types + that it does not recognize in a response MUST assume that the + corresponding request has failed entirely. Unrecognized error types + in a request and status types in a request or response MUST be + ignored except that they SHOULD be logged. + + Notify payloads with status types MAY be added to any message and + MUST be ignored if not recognized. They are intended to indicate + capabilities, and as part of SA negotiation are used to negotiate + non-cryptographic parameters. + + NOTIFY MESSAGES - ERROR TYPES Value + ----------------------------- ----- + RESERVED 0 + + UNSUPPORTED_CRITICAL_PAYLOAD 1 + + Sent if the payload has the "critical" bit set and the + payload type is not recognized. Notification Data contains + the one octet payload type. + + INVALID_IKE_SPI 4 + + Indicates an IKE message was received with an unrecognized + destination SPI. This usually indicates that the recipient + has rebooted and forgotten the existence of an IKE_SA. + + INVALID_MAJOR_VERSION 5 + + Indicates the recipient cannot handle the version of IKE + specified in the header. The closest version number that the + recipient can support will be in the reply header. + + INVALID_SYNTAX 7 + + Indicates the IKE message was received was invalid because + some type, length, or value was out of range or because the + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 65] + + + + + +Internet-Draft September 23, 2004 + + + request was rejected for policy reasons. To avoid a denial + of service attack using forged messages, this status may + only be returned for and in an encrypted packet if the + message ID and cryptographic checksum were valid. To avoid + leaking information to someone probing a node, this status + MUST be sent in response to any error not covered by one of + the other status types. To aid debugging, more detailed + error information SHOULD be written to a console or log. + + INVALID_MESSAGE_ID 9 + + Sent when an IKE message ID outside the supported window is + received. This Notify MUST NOT be sent in a response; the + invalid request MUST NOT be acknowledged. Instead, inform + the other side by initiating an INFORMATIONAL exchange with + Notification data containing the four octet invalid message + ID. Sending this notification is optional and notifications + of this type MUST be rate limited. + + INVALID_SPI 11 + + MAY be sent in an IKE INFORMATIONAL Exchange when a node + receives an ESP or AH packet with an invalid SPI. The + Notification Data contains the SPI of the invalid packet. + This usually indicates a node has rebooted and forgotten an + SA. If this Informational Message is sent outside the + context of an IKE_SA, it should only be used by the + recipient as a "hint" that something might be wrong (because + it could easily be forged). + + NO_PROPOSAL_CHOSEN 14 + + None of the proposed crypto suites was acceptable. + + INVALID_KE_PAYLOAD 17 + + The D-H Group # field in the KE payload is not the group # + selected by the responder for this exchange. There are two + octets of data associated with this notification: the + accepted D-H Group # in big endian order. + + AUTHENTICATION_FAILED 24 + + Sent in the response to an IKE_AUTH message when for some + reason the authentication failed. There is no associated + data. + + SINGLE_PAIR_REQUIRED 34 + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 66] + + + + + +Internet-Draft September 23, 2004 + + + This error indicates that a CREATE_CHILD_SA request is + unacceptable because its sender is only willing to accept + traffic selectors specifying a single pair of addresses. + The requestor is expected to respond by requesting an SA for + only the specific traffic it is trying to forward. + + NO_ADDITIONAL_SAS 35 + + This error indicates that a CREATE_CHILD_SA request is + unacceptable because the responder is unwilling to accept + any more CHILD_SAs on this IKE_SA. Some minimal + implementations may only accept a single CHILD_SA setup in + the context of an initial IKE exchange and reject any + subsequent attempts to add more. + + INTERNAL_ADDRESS_FAILURE 36 + + Indicates an error assigning an internal address (i.e., + INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS) during the + processing of a Configuration Payload by a responder. If + this error is generated within an IKE_AUTH exchange no + CHILD_SA will be created. + + FAILED_CP_REQUIRED 37 + + Sent by responder in the case where CP(CFG_REQUEST) was + expected but not received, and so is a conflict with locally + configured policy. There is no associated data. + + TS_UNACCEPTABLE 38 + + Indicates that none of the addresses/protocols/ports in the + supplied traffic selectors is acceptable. + + INVALID_SELECTORS 39 + + MAY be sent in an IKE INFORMATIONAL Exchange when a node + receives an ESP or AH packet whose selectors do not match + those of the SA on which it was delivered (and which caused + the packet to be dropped). The Notification Data contains + the start of the offending packet (as in ICMP messages) and + the SPI field of the notification is set to match the SPI of + the IPsec SA. + RESERVED TO IANA - Error types 40 - 8191 + + Private Use - Errors 8192 - 16383 + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 67] + + + + + +Internet-Draft September 23, 2004 + + + NOTIFY MESSAGES - STATUS TYPES Value + ------------------------------ ----- + + INITIAL_CONTACT 16384 + + This notification asserts that this IKE_SA is the only + IKE_SA currently active between the authenticated + identities. It MAY be sent when an IKE_SA is established + after a crash, and the recipient MAY use this information to + delete any other IKE_SAs it has to the same authenticated + identity without waiting for a timeout. This notification + MUST NOT be sent by an entity that may be replicated (e.g., + a roaming user's credentials where the user is allowed to + connect to the corporate firewall from two remote systems at + the same time). + + SET_WINDOW_SIZE 16385 + + This notification asserts that the sending endpoint is + capable of keeping state for multiple outstanding exchanges, + permitting the recipient to send multiple requests before + getting a response to the first. The data associated with a + SET_WINDOW_SIZE notification MUST be 4 octets long and + contain the big endian representation of the number of + messages the sender promises to keep. Window size is always + one until the initial exchanges complete. + + ADDITIONAL_TS_POSSIBLE 16386 + + This notification asserts that the sending endpoint narrowed + the proposed traffic selectors but that other traffic + selectors would also have been acceptable, though only in a + separate SA (see section 2.9). There is no data associated + with this Notify type. It may only be sent as an additional + payload in a message including accepted TSs. + + IPCOMP_SUPPORTED 16387 + + This notification may only be included in a message + containing an SA payload negotiating a CHILD_SA and + indicates a willingness by its sender to use IPComp on this + SA. The data associated with this notification includes a + two octet IPComp CPI followed by a one octet transform ID + optionally followed by attributes whose length and format is + defined by that transform ID. A message proposing an SA may + contain multiple IPCOMP_SUPPORTED notifications to indicate + multiple supported algorithms. A message accepting an SA may + contain at most one. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 68] + + + + + +Internet-Draft September 23, 2004 + + + The transform IDs currently defined are: + + NAME NUMBER DEFINED IN + ----------- ------ ----------- + RESERVED 0 + IPCOMP_OUI 1 + IPCOMP_DEFLATE 2 RFC 2394 + IPCOMP_LZS 3 RFC 2395 + IPCOMP_LZJH 4 RFC 3051 + + values 5-240 are reserved to IANA. Values 241-255 are + for private use among mutually consenting parties. + + NAT_DETECTION_SOURCE_IP 16388 + + This notification is used by its recipient to determine + whether the source is behind a NAT box. The data associated + with this notification is a SHA-1 digest of the SPIs (in the + order they appear in the header), IP address and port on + which this packet was sent. There MAY be multiple Notify + payloads of this type in a message if the sender does not + know which of several network attachments will be used to + send the packet. The recipient of this notification MAY + compare the supplied value to a SHA-1 hash of the SPIs, + source IP address and port and if they don't match it SHOULD + enable NAT traversal (see section 2.23). Alternately, it + MAY reject the connection attempt if NAT traversal is not + supported. + + NAT_DETECTION_DESTINATION_IP 16389 + + This notification is used by its recipient to determine + whether it is behind a NAT box. The data associated with + this notification is a SHA-1 digest of the SPIs (in the + order they appear in the header), IP address and port to + which this packet was sent. The recipient of this + notification MAY compare the supplied value to a hash of the + SPIs, destination IP address and port and if they don't + match it SHOULD invoke NAT traversal (see section 2.23). If + they don't match, it means that this end is behind a NAT and + this end SHOULD start sending keepalive packets as defined + in [Hutt04]. Alternately, it MAY reject the connection + attempt if NAT traversal is not supported. + + COOKIE 16390 + + This notification MAY be included in an IKE_SA_INIT + response. It indicates that the request should be retried + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 69] + + + + + +Internet-Draft September 23, 2004 + + + with a copy of this notification as the first payload. This + notification MUST be included in an IKE_SA_INIT request + retry if a COOKIE notification was included in the initial + response. The data associated with this notification MUST + be between 1 and 64 octets in length (inclusive). + + USE_TRANSPORT_MODE 16391 + + This notification MAY be included in a request message that + also includes an SA payload requesting a CHILD_SA. It + requests that the CHILD_SA use transport mode rather than + tunnel mode for the SA created. If the request is accepted, + the response MUST also include a notification of type + USE_TRANSPORT_MODE. If the responder declines the request, + the CHILD_SA will be established in tunnel mode. If this is + unacceptable to the initiator, the initiator MUST delete the + SA. Note: except when using this option to negotiate + transport mode, all CHILD_SAs will use tunnel mode. + + Note: The ECN decapsulation modifications specified in + [RFC2401bis] MUST be performed for every tunnel mode SA + created by IKEv2. + + HTTP_CERT_LOOKUP_SUPPORTED 16392 + + This notification MAY be included in any message that can + include a CERTREQ payload and indicates that the sender is + capable of looking up certificates based on an HTTP-based + URL (and hence presumably would prefer to receive + certificate specifications in that format). + + REKEY_SA 16393 + + This notification MUST be included in a CREATE_CHILD_SA + exchange if the purpose of the exchange is to replace an + existing ESP or AH SA. The SPI field identifies the SA being + rekeyed. There is no data. + + ESP_TFC_PADDING_NOT_SUPPORTED 16394 + + This notification asserts that the sending endpoint will NOT + accept packets that contain Flow Confidentiality (TFC) + padding. + + NON_FIRST_FRAGMENTS_ALSO 16395 + + Used for fragmentation control. See [RFC2401bis] for + explanation. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 70] + + + + + +Internet-Draft September 23, 2004 + + + RESERVED TO IANA - STATUS TYPES 16396 - 40959 + + Private Use - STATUS TYPES 40960 - 65535 + +3.11 Delete Payload + + The Delete Payload, denoted D in this memo, contains a protocol + specific security association identifier that the sender has removed + from its security association database and is, therefore, no longer + valid. Figure 17 shows the format of the Delete Payload. It is + possible to send multiple SPIs in a Delete payload, however, each SPI + MUST be for the same protocol. Mixing of protocol identifiers MUST + NOT be performed in a the Delete payload. It is permitted, however, + to include multiple Delete payloads in a single INFORMATIONAL + Exchange where each Delete payload lists SPIs for a different + protocol. + + Deletion of the IKE_SA is indicated by a protocol ID of 1 (IKE) but + no SPIs. Deletion of a CHILD_SA, such as ESP or AH, will contain the + IPsec protocol ID of that protocol (2 for AH, 3 for ESP) and the SPI + is the SPI the sending endpoint would expect in inbound ESP or AH + packets. + + The Delete Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! # of SPIs ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index(es) (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 17: Delete Payload Format + + o Protocol ID (1 octet) - Must be 1 for an IKE_SA, 2 for AH, or + 3 for ESP. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by + the protocol ID. It MUST be zero for IKE (SPI is in message + header) or four for AH and ESP. + + o # of SPIs (2 octets) - The number of SPIs contained in the Delete + payload. The size of each SPI is defined by the SPI Size field. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 71] + + + + + +Internet-Draft September 23, 2004 + + + o Security Parameter Index(es) (variable length) - Identifies the + specific security association(s) to delete. The length of this + field is determined by the SPI Size and # of SPIs fields. + + The payload type for the Delete Payload is forty two (42). + +3.12 Vendor ID Payload + + The Vendor ID Payload contains a vendor defined constant. The + constant is used by vendors to identify and recognize remote + instances of their implementations. This mechanism allows a vendor + to experiment with new features while maintaining backwards + compatibility. + + A Vendor ID payload MAY announce that the sender is capable to + accepting certain extensions to the protocol, or it MAY simply + identify the implementation as an aid in debugging. A Vendor ID + payload MUST NOT change the interpretation of any information defined + in this specification (i.e., the critical bit MUST be set to 0). + Multiple Vendor ID payloads MAY be sent. An implementation is NOT + REQUIRED to send any Vendor ID payload at all. + + A Vendor ID payload may be sent as part of any message. Reception of + a familiar Vendor ID payload allows an implementation to make use of + Private USE numbers described throughout this memo-- private + payloads, private exchanges, private notifications, etc. Unfamiliar + Vendor IDs MUST be ignored. + + Writers of Internet-Drafts who wish to extend this protocol MUST + define a Vendor ID payload to announce the ability to implement the + extension in the Internet-Draft. It is expected that Internet-Drafts + which gain acceptance and are standardized will be given "magic + numbers" out of the Future Use range by IANA and the requirement to + use a Vendor ID will go away. + + The Vendor ID Payload fields are defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Vendor ID (VID) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 18: Vendor ID Payload Format + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 72] + + + + + +Internet-Draft September 23, 2004 + + + o Vendor ID (variable length) - It is the responsibility of + the person choosing the Vendor ID to assure its uniqueness + in spite of the absence of any central registry for IDs. + Good practice is to include a company name, a person name + or some such. If you want to show off, you might include + the latitude and longitude and time where you were when + you chose the ID and some random input. A message digest + of a long unique string is preferable to the long unique + string itself. + + The payload type for the Vendor ID Payload is forty three (43). + + +3.13 Traffic Selector Payload + + The Traffic Selector Payload, denoted TS in this memo, allows peers + to identify packet flows for processing by IPsec security services. + The Traffic Selector Payload consists of the IKE generic payload + header followed by individual traffic selectors as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Number of TSs ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 19: Traffic Selectors Payload Format + + o Number of TSs (1 octet) - Number of traffic selectors + being provided. + + o RESERVED - This field MUST be sent as zero and MUST be ignored + on receipt. + + o Traffic Selectors (variable length) - one or more individual + traffic selectors. + + The length of the Traffic Selector payload includes the TS header and + all the traffic selectors. + + The payload type for the Traffic Selector payload is forty four (44) + for addresses at the initiator's end of the SA and forty five (45) + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 73] + + + + + +Internet-Draft September 23, 2004 + + + for addresses at the responder's end. + +3.13.1 Traffic Selector + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! TS Type !IP Protocol ID*| Selector Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | Start Port* | End Port* | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Starting Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Ending Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 20: Traffic Selector + + *Note: all fields other than TS Type and Selector Length depend on + the TS Type. The fields shown are for TS Types 7 and 8, the only two + values currently defined. + + o TS Type (one octet) - Specifies the type of traffic selector. + + o IP protocol ID (1 octet) - Value specifying an associated IP + protocol ID (e.g., UDP/TCP/ICMP). A value of zero means that + the protocol ID is not relevant to this traffic selector-- + the SA can carry all protocols. + + o Selector Length - Specifies the length of this Traffic + Selector Substructure including the header. + + o Start Port (2 octets) - Value specifying the smallest port + number allowed by this Traffic Selector. For protocols for + which port is undefined, or if all ports are allowed, + this field MUST be zero. For the + ICMP protocol, the two one octet fields Type and Code are + treated as a single 16 bit integer (with Type in the most + significant eight bits and Code in the least significant + eight bits) port number for the purposes of filtering based + on this field. + + o End Port (2 octets) - Value specifying the largest port + number allowed by this Traffic Selector. For protocols for + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 74] + + + + + +Internet-Draft September 23, 2004 + + + which port is undefined, or if all ports are allowed, + this field MUST be 65535. For the + ICMP protocol, the two one octet fields Type and Code are + treated as a single 16 bit integer (with Type in the most + significant eight bits and Code in the least significant + eight bits) port number for the purposed of filtering based + on this field. + + o Starting Address - The smallest address included in this + Traffic Selector (length determined by TS type). + + o Ending Address - The largest address included in this + Traffic Selector (length determined by TS type). + + Systems that are complying with [RFC2401bis] that wish to indicate + "ANY" ports MUST set the start port to 0 and the end port to 65535; + note that according to [RFC2401bis], "ANY" includes "OPAQUE". Systems + working with [RFC2401bis] that wish to indicate "OPAQUE" ports, but + not "ANY" ports, MUST set the start port to 65535 and the end port to + 0. + + The following table lists the assigned values for the Traffic + Selector Type field and the corresponding Address Selector Data. + + TS Type Value + ------- ----- + RESERVED 0-6 + + TS_IPV4_ADDR_RANGE 7 + + A range of IPv4 addresses, represented by two four (4) octet + values. The first value is the beginning IPv4 address + (inclusive) and the second value is the ending IPv4 address + (inclusive). All addresses falling between the two specified + addresses are considered to be within the list. + + TS_IPV6_ADDR_RANGE 8 + + A range of IPv6 addresses, represented by two sixteen (16) + octet values. The first value is the beginning IPv6 address + (inclusive) and the second value is the ending IPv6 address + (inclusive). All addresses falling between the two specified + addresses are considered to be within the list. + + RESERVED TO IANA 9-240 + PRIVATE USE 241-255 + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 75] + + + + + +Internet-Draft September 23, 2004 + + +3.14 Encrypted Payload + + The Encrypted Payload, denoted SK{...} in this memo, contains other + payloads in encrypted form. The Encrypted Payload, if present in a + message, MUST be the last payload in the message. Often, it is the + only payload in the message. + + The algorithms for encryption and integrity protection are negotiated + during IKE_SA setup, and the keys are computed as specified in + sections 2.14 and 2.18. + + The encryption and integrity protection algorithms are modeled after + the ESP algorithms described in RFCs 2104, 2406, 2451. This document + completely specifies the cryptographic processing of IKE data, but + those documents should be consulted for design rationale. We assume a + block cipher with a fixed block size and an integrity check algorithm + that computes a fixed length checksum over a variable size message. + + The payload type for an Encrypted payload is forty six (46). The + Encrypted Payload consists of the IKE generic payload header followed + by individual fields as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Initialization Vector ! + ! (length is block size for encryption algorithm) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Encrypted IKE Payloads ! + + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! Padding (0-255 octets) ! + +-+-+-+-+-+-+-+-+ +-+-+-+-+-+-+-+-+ + ! ! Pad Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Integrity Checksum Data ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 21: Encrypted Payload Format + + o Next Payload - The payload type of the first embedded payload. + Note that this is an exception in the standard header format, + since the Encrypted payload is the last payload in the + message and therefore the Next Payload field would normally + be zero. But because the content of this payload is embedded + payloads and there was no natural place to put the type of + the first one, that type is placed here. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 76] + + + + + +Internet-Draft September 23, 2004 + + + o Payload Length - Includes the lengths of the header, IV, + Encrypted IKE Payloads, Padding, Pad Length and Integrity + Checksum Data. + + o Initialization Vector - A randomly chosen value whose length + is equal to the block length of the underlying encryption + algorithm. Recipients MUST accept any value. Senders SHOULD + either pick this value pseudo-randomly and independently for + each message or use the final ciphertext block of the previous + message sent. Senders MUST NOT use the same value for each + message, use a sequence of values with low hamming distance + (e.g., a sequence number), or use ciphertext from a received + message. + + o IKE Payloads are as specified earlier in this section. This + field is encrypted with the negotiated cipher. + + o Padding MAY contain any value chosen by the sender, and MUST + have a length that makes the combination of the Payloads, the + Padding, and the Pad Length to be a multiple of the encryption + block size. This field is encrypted with the negotiated + cipher. + + o Pad Length is the length of the Padding field. The sender + SHOULD set the Pad Length to the minimum value that makes + the combination of the Payloads, the Padding, and the Pad + Length a multiple of the block size, but the recipient MUST + accept any length that results in proper alignment. This + field is encrypted with the negotiated cipher. + + o Integrity Checksum Data is the cryptographic checksum of + the entire message starting with the Fixed IKE Header + through the Pad Length. The checksum MUST be computed over + the encrypted message. Its length is determined by the + integrity algorithm negotiated. + +3.15 Configuration Payload + + The Configuration payload, denoted CP in this document, is used to + exchange configuration information between IKE peers. The exchange is + for an IRAC to request an internal IP address from an IRAS and to + exchange other information of the sort that one would acquire with + DHCP if the IRAC were directly connected to a LAN. + + Configuration payloads are of type CFG_REQUEST/CFG_REPLY or + CFG_SET/CFG_ACK (see CFG Type in the payload description below). + CFG_REQUEST and CFG_SET payloads may optionally be added to any IKE + request. The IKE response MUST include either a corresponding + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 77] + + + + + +Internet-Draft September 23, 2004 + + + CFG_REPLY or CFG_ACK or a Notify payload with an error type + indicating why the request could not be honored. An exception is that + a minimal implementation MAY ignore all CFG_REQUEST and CFG_SET + payloads, so a response message without a corresponding CFG_REPLY or + CFG_ACK MUST be accepted as an indication that the request was not + supported. + + "CFG_REQUEST/CFG_REPLY" allows an IKE endpoint to request information + from its peer. If an attribute in the CFG_REQUEST Configuration + Payload is not zero length it is taken as a suggestion for that + attribute. The CFG_REPLY Configuration Payload MAY return that + value, or a new one. It MAY also add new attributes and not include + some requested ones. Requestors MUST ignore returned attributes that + they do not recognize. + + Some attributes MAY be multi-valued, in which case multiple attribute + values of the same type are sent and/or returned. Generally, all + values of an attribute are returned when the attribute is requested. + For some attributes (in this version of the specification only + internal addresses), multiple requests indicates a request that + multiple values be assigned. For these attributes, the number of + values returned SHOULD NOT exceed the number requested. + + If the data type requested in a CFG_REQUEST is not recognized or not + supported, the responder MUST NOT return an error type but rather + MUST either send a CFG_REPLY which MAY be empty or a reply not + containing a CFG_REPLY payload at all. Error returns are reserved for + cases where the request is recognized but cannot be performed as + requested or the request is badly formatted. + + "CFG_SET/CFG_ACK" allows an IKE endpoint to push configuration data + to its peer. In this case the CFG_SET Configuration Payload contains + attributes the initiator wants its peer to alter. The responder MUST + return a Configuration Payload if it accepted any of the + configuration data and it MUST contain the attributes that the + responder accepted with zero length data. Those attributes that it + did not accept MUST NOT be in the CFG_ACK Configuration Payload. If + no attributes were accepted, the responder MUST return either an + empty CFG_ACK payload or a response message without a CFG_ACK + payload. There are currently no defined uses for the CFG_SET/CFG_ACK + exchange, though they may be used in connection with extensions based + on Vendor IDs. An minimal implementation of this specification MAY + ignore CFG_SET payloads. + + Extensions via the CP payload SHOULD NOT be used for general purpose + management. Its main intent is to provide a bootstrap mechanism to + exchange information within IPsec from IRAS to IRAC. While it MAY be + useful to use such a method to exchange information between some + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 78] + + + + + +Internet-Draft September 23, 2004 + + + Security Gateways (SGW) or small networks, existing management + protocols such as DHCP [DHCP], RADIUS [RADIUS], SNMP or LDAP [LDAP] + should be preferred for enterprise management as well as subsequent + information exchanges. + + The Configuration Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! CFG Type ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Configuration Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 22: Configuration Payload Format + + The payload type for the Configuration Payload is forty seven (47). + + o CFG Type (1 octet) - The type of exchange represented by the + Configuration Attributes. + + CFG Type Value + =========== ===== + RESERVED 0 + CFG_REQUEST 1 + CFG_REPLY 2 + CFG_SET 3 + CFG_ACK 4 + + values 5-127 are reserved to IANA. Values 128-255 are for private + use among mutually consenting parties. + + o RESERVED (3 octets) - MUST be sent as zero; MUST be ignored on + receipt. + + o Configuration Attributes (variable length) - These are type + length values specific to the Configuration Payload and are + defined below. There may be zero or more Configuration + Attributes in this payload. + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 79] + + + + + +Internet-Draft September 23, 2004 + + +3.15.1 Configuration Attributes + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !R| Attribute Type ! Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | | + ~ Value ~ + | | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 23: Configuration Attribute Format + + o Reserved (1 bit) - This bit MUST be set to zero and MUST be + ignored on receipt. + + o Attribute Type (7 bits) - A unique identifier for each of the + Configuration Attribute Types. + + o Length (2 octets) - Length in octets of Value. + + o Value (0 or more octets) - The variable length value of this + Configuration Attribute. + + The following attribute types have been defined: + + Multi- + Attribute Type Value Valued Length + ======================= ===== ====== ================== + RESERVED 0 + INTERNAL_IP4_ADDRESS 1 YES* 0 or 4 octets + INTERNAL_IP4_NETMASK 2 NO 0 or 4 octets + INTERNAL_IP4_DNS 3 YES 0 or 4 octets + INTERNAL_IP4_NBNS 4 YES 0 or 4 octets + INTERNAL_ADDRESS_EXPIRY 5 NO 0 or 4 octets + INTERNAL_IP4_DHCP 6 YES 0 or 4 octets + APPLICATION_VERSION 7 NO 0 or more + INTERNAL_IP6_ADDRESS 8 YES* 0 or 17 octets + RESERVED 9 + INTERNAL_IP6_DNS 10 YES 0 or 16 octets + INTERNAL_IP6_NBNS 11 YES 0 or 16 octets + INTERNAL_IP6_DHCP 12 YES 0 or 16 octets + INTERNAL_IP4_SUBNET 13 YES 0 or 8 octets + SUPPORTED_ATTRIBUTES 14 NO Multiple of 2 + INTERNAL_IP6_SUBNET 15 YES 17 octets + + * These attributes may be multi-valued on return only if + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 80] + + + + + +Internet-Draft September 23, 2004 + + + multiple values were requested. + + Types 16-16383 are reserved to IANA. Values 16384-32767 are for + private use among mutually consenting parties. + + o INTERNAL_IP4_ADDRESS, INTERNAL_IP6_ADDRESS - An address on the + internal network, sometimes called a red node address or + private address and MAY be a private address on the Internet. + In a request message, the address specified is a requested + address (or zero if no specific address is requested). If a + specific address is requested, it likely indicates that a + previous connection existed with this address and the requestor + would like to reuse that address. With IPv6, a requestor + MAY supply the low order address bytes it wants to use. + Multiple internal addresses MAY be requested by requesting + multiple internal address attributes. The responder MAY only + send up to the number of addresses requested. The + INTERNAL_IP6_ADDRESS is made up of two fields; the first + being a 16 octet IPv6 address and the second being a one octet + prefix-length as defined in [ADDRIPV6]. + + The requested address is valid until the expiry time defined + with the INTERNAL_ADDRESS EXPIRY attribute or there are no + IKE_SAs between the peers. + + o INTERNAL_IP4_NETMASK - The internal network's netmask. Only + one netmask is allowed in the request and reply messages + (e.g., 255.255.255.0) and it MUST be used only with an + INTERNAL_IP4_ADDRESS attribute. + + o INTERNAL_IP4_DNS, INTERNAL_IP6_DNS - Specifies an address of a + DNS server within the network. Multiple DNS servers MAY be + requested. The responder MAY respond with zero or more DNS + server attributes. + + o INTERNAL_IP4_NBNS, INTERNAL_IP6_NBNS - Specifies an address of + a NetBios Name Server (WINS) within the network. Multiple NBNS + servers MAY be requested. The responder MAY respond with zero + or more NBNS server attributes. + + o INTERNAL_ADDRESS_EXPIRY - Specifies the number of seconds that + the host can use the internal IP address. The host MUST renew + the IP address before this expiry time. Only one of these + attributes MAY be present in the reply. + + o INTERNAL_IP4_DHCP, INTERNAL_IP6_DHCP - Instructs the host to + send any internal DHCP requests to the address contained within + the attribute. Multiple DHCP servers MAY be requested. The + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 81] + + + + + +Internet-Draft September 23, 2004 + + + responder MAY respond with zero or more DHCP server attributes. + + o APPLICATION_VERSION - The version or application information of + the IPsec host. This is a string of printable ASCII characters + that is NOT null terminated. + + o INTERNAL_IP4_SUBNET - The protected sub-networks that this + edge-device protects. This attribute is made up of two fields; + the first being an IP address and the second being a netmask. + Multiple sub-networks MAY be requested. The responder MAY + respond with zero or more sub-network attributes. + + o SUPPORTED_ATTRIBUTES - When used within a Request, this + attribute MUST be zero length and specifies a query to the + responder to reply back with all of the attributes that it + supports. The response contains an attribute that contains a + set of attribute identifiers each in 2 octets. The length + divided by 2 (octets) would state the number of supported + attributes contained in the response. + + o INTERNAL_IP6_SUBNET - The protected sub-networks that this + edge-device protects. This attribute is made up of two fields; + the first being a 16 octet IPv6 address the second being a one + octet prefix-length as defined in [ADDRIPV6]. Multiple + sub-networks MAY be requested. The responder MAY respond with + zero or more sub-network attributes. + + Note that no recommendations are made in this document how an + implementation actually figures out what information to send in a + reply. i.e., we do not recommend any specific method of an IRAS + determining which DNS server should be returned to a requesting + IRAC. + +3.16 Extensible Authentication Protocol (EAP) Payload + + The Extensible Authentication Protocol Payload, denoted EAP in this + memo, allows IKE_SAs to be authenticated using the protocol defined + in RFC 3748 [EAP] and subsequent extensions to that protocol. The + full set of acceptable values for the payload are defined elsewhere, + but a short summary of RFC 3748 is included here to make this + document stand alone in the common cases. + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 82] + + + + + +Internet-Draft September 23, 2004 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ EAP Message ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 24: EAP Payload Format + + The payload type for an EAP Payload is forty eight (48). + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Code ! Identifier ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Type ! Type_Data... + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+- + + Figure 25: EAP Message Format + + o Code (one octet) indicates whether this message is a + Request (1), Response (2), Success (3), or Failure (4). + + o Identifier (one octet) is used in PPP to distinguish replayed + messages from repeated ones. Since in IKE, EAP runs over a + reliable protocol, it serves no function here. In a response + message this octet MUST be set to match the identifier in the + corresponding request. In other messages, this field MAY + be set to any value. + + o Length (two octets) is the length of the EAP message and MUST + be four less than the Payload Length of the encapsulating + payload. + + o Type (one octet) is present only if the Code field is Request + (1) or Response (2). For other codes, the EAP message length + MUST be four octets and the Type and Type_Data fields MUST NOT + be present. In a Request (1) message, Type indicates the + data being requested. In a Response (2) message, Type MUST + either be Nak or match the type of the data requested. The + following types are defined in RFC 3748: + + 1 Identity + 2 Notification + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 83] + + + + + +Internet-Draft September 23, 2004 + + + 3 Nak (Response Only) + 4 MD5-Challenge + 5 One-Time Password (OTP) + 6 Generic Token Card + + o Type_Data (Variable Length) varies with the Type of Request + and the associated Response. For the documentation of the + EAP methods, see [EAP]. + + Note that since IKE passes an indication of initiator identity in + message 3 of the protocol, the responder SHOULD NOT send EAP Identity + requests. The initiator SHOULD, however, respond to such requests if + it receives them. + +4 Conformance Requirements + + In order to assure that all implementations of IKEv2 can + interoperate, there are MUST support requirements in addition to + those listed elsewhere. Of course, IKEv2 is a security protocol, and + one of its major functions is to only allow authorized parties to + successfully complete establishment of SAs. So a particular + implementation may be configured with any of a number of restrictions + concerning algorithms and trusted authorities that will prevent + universal interoperability. + + IKEv2 is designed to permit minimal implementations that can + interoperate with all compliant implementations. There are a series + of optional features that can easily be ignored by a particular + implementation if it does not support that feature. Those features + include: + + Ability to negotiate SAs through a NAT and tunnel the resulting + ESP SA over UDP. + + Ability to request (and respond to a request for) a temporary IP + address on the remote end of a tunnel. + + Ability to support various types of legacy authentication. + + Ability to support window sizes greater than one. + + Ability to establish multiple ESP and/or AH SAs within a single + IKE_SA. + + Ability to rekey SAs. + + To assure interoperability, all implementations MUST be capable of + parsing all payload types (if only to skip over them) and to ignore + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 84] + + + + + +Internet-Draft September 23, 2004 + + + payload types that it does not support unless the critical bit is set + in the payload header. If the critical bit is set in an unsupported + payload header, all implementations MUST reject the messages + containing those payloads. + + Every implementation MUST be capable of doing four message + IKE_SA_INIT and IKE_AUTH exchanges establishing two SAs (one for IKE, + one for ESP and/or AH). Implementations MAY be initiate-only or + respond-only if appropriate for their platform. Every implementation + MUST be capable of responding to an INFORMATIONAL exchange, but a + minimal implementation MAY respond to any INFORMATIONAL message with + an empty INFORMATIONAL reply (note that within the context of an + IKE_SA, an "empty" message consists of an IKE header followed by an + Encrypted payload with no payloads contained in it). A minimal + implementation MAY support the CREATE_CHILD_SA exchange only in so + far as to recognize requests and reject them with a Notify payload of + type NO_ADDITIONAL_SAS. A minimal implementation need not be able to + initiate CREATE_CHILD_SA or INFORMATIONAL exchanges. When an SA + expires (based on locally configured values of either lifetime or + octets passed), and implementation MAY either try to renew it with a + CREATE_CHILD_SA exchange or it MAY delete (close) the old SA and + create a new one. If the responder rejects the CREATE_CHILD_SA + request with a NO_ADDITIONAL_SAS notification, the implementation + MUST be capable of instead closing the old SA and creating a new one. + + Implementations are not required to support requesting temporary IP + addresses or responding to such requests. If an implementation does + support issuing such requests, it MUST include a CP payload in + message 3 containing at least a field of type INTERNAL_IP4_ADDRESS or + INTERNAL_IP6_ADDRESS. All other fields are optional. If an + implementation supports responding to such requests, it MUST parse + the CP payload of type CFG_REQUEST in message 3 and recognize a field + of type INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS. If it supports + leasing an address of the appropriate type, it MUST return a CP + payload of type CFG_REPLY containing an address of the requested + type. The responder SHOULD include all of the other related + attributes if it has them. + + A minimal IPv4 responder implementation will ignore the contents of + the CP payload except to determine that it includes an + INTERNAL_IP4_ADDRESS attribute and will respond with the address and + other related attributes regardless of whether the initiator + requested them. + + A minimal IPv4 initiator will generate a CP payload containing only + an INTERNAL_IP4_ADDRESS attribute and will parse the response + ignoring attributes it does not know how to use. The only attribute + it MUST be able to process is INTERNAL_ADDRESS_EXPIRY, which it must + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 85] + + + + + +Internet-Draft September 23, 2004 + + + use to bound the lifetime of the SA unless it successfully renews the + lease before it expires. Minimal initiators need not be able to + request lease renewals and minimal responders need not respond to + them. + + For an implementation to be called conforming to this specification, + it MUST be possible to configure it to accept the following: + + PKIX Certificates containing and signed by RSA keys of size 1024 or + 2048 bits, where the ID passed is any of ID_KEY_ID, ID_FQDN, + ID_RFC822_ADDR, or ID_DER_ASN1_DN. + + Shared key authentication where the ID passes is any of ID_KEY_ID, + ID_FQDN, or ID_RFC822_ADDR. + + Authentication where the responder is authenticated using PKIX + Certificates and the initiator is authenticated using shared key + authentication. + +5 Security Considerations + + While this protocol is designed to minimize disclosure of + configuration information to unauthenticated peers, some such + disclosure is unavoidable. One peer or the other must identify + itself first and prove its identity first. To avoid probing, the + initiator of an exchange is required to identify itself first, and + usually is required to authenticate itself first. The initiator can, + however, learn that the responder supports IKE and what cryptographic + protocols it supports. The responder (or someone impersonating the + responder) can probe the initiator not only for its identity, but + using CERTREQ payloads may be able to determine what certificates the + initiator is willing to use. + + Use of EAP authentication changes the probing possibilities somewhat. + When EAP authentication is used, the responder proves its identity + before the initiator does, so an initiator that knew the name of a + valid initiator could probe the responder for both its name and + certificates. + + Repeated rekeying using CREATE_CHILD_SA without additional Diffie- + Hellman exchanges leaves all SAs vulnerable to cryptanalysis of a + single key or overrun of either endpoint. Implementers should take + note of this fact and set a limit on CREATE_CHILD_SA exchanges + between exponentiations. This memo does not prescribe such a limit. + + The strength of a key derived from a Diffie-Hellman exchange using + any of the groups defined here depends on the inherent strength of + the group, the size of the exponent used, and the entropy provided by + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 86] + + + + + +Internet-Draft September 23, 2004 + + + the random number generator used. Due to these inputs it is difficult + to determine the strength of a key for any of the defined groups. + Diffie-Hellman group number two, when used with a strong random + number generator and an exponent no less than 200 bits, is common for + use with 3DES. Group five provides greater security than group two. + Group one is for historic purposes only and does not provide + sufficient strength except for use with DES, which is also for + historic use only. Implementations should make note of these + estimates when establishing policy and negotiating security + parameters. + + Note that these limitations are on the Diffie-Hellman groups + themselves. There is nothing in IKE which prohibits using stronger + groups nor is there anything which will dilute the strength obtained + from stronger groups (limited by the strength of the other algorithms + negotiated including the prf function). In fact, the extensible + framework of IKE encourages the definition of more groups; use of + elliptical curve groups may greatly increase strength using much + smaller numbers. + + It is assumed that all Diffie-Hellman exponents are erased from + memory after use. In particular, these exponents MUST NOT be derived + from long-lived secrets like the seed to a pseudo-random generator + that is not erased after use. + + The strength of all keys are limited by the size of the output of the + negotiated prf function. For this reason, a prf function whose output + is less than 128 bits (e.g., 3DES-CBC) MUST NOT be used with this + protocol. + + The security of this protocol is critically dependent on the + randomness of the randomly chosen parameters. These should be + generated by a strong random or properly seeded pseudo-random source + (see [RFC1750]). Implementers should take care to ensure that use of + random numbers for both keys and nonces is engineered in a fashion + that does not undermine the security of the keys. + + For information on the rationale of many of the cryptographic design + choices in this protocol, see [SIGMA]. Though the security of + negotiated CHILD_SAs does not depend on the strength of the + encryption and integrity protection negotiated in the IKE_SA, + implementations MUST NOT negotiate NONE as the IKE integrity + protection algorithm or ENCR_NULL as the IKE encryption algorithm. + + When using pre-shared keys, a critical consideration is how to assure + the randomness of these secrets. The strongest practice is to ensure + that any pre-shared key contain as much randomness as the strongest + key being negotiated. Deriving a shared secret from a password, name, + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 87] + + + + + +Internet-Draft September 23, 2004 + + + or other low entropy source is not secure. These sources are subject + to dictionary and social engineering attacks, among others. + + The NAT_DETECTION_*_IP notifications contain a hash of the addresses + and ports in an attempt to hide internal IP addresses behind a NAT. + Since the IPv4 address space is only 32 bits, and it is usually very + sparse, it would be possible for an attacker to find out the internal + address used behind the NAT box by trying all possible IP-addresses + and trying to find the matching hash. The port numbers are normally + fixed to 500, and the SPIs can be extracted from the packet. This + reduces the number of hash calculations to 2^32. With an educated + guess of the use of private address space, the number of hash + calculations is much smaller. Designers should therefore not assume + that use of IKE will not leak internal address information. + + When using an EAP authentication method that does not generate a + shared key for protecting a subsequent AUTH payload, certain man-in- + the-middle and server impersonation attacks are possible [EAPMITM]. + These vulnerabilities occur when EAP is also used in protocols which + are not protected with a secure tunnel. Since EAP is a general- + purpose authentication protocol, which is often used to provide + single-signon facilities, a deployed IPsec solution which relies on + an EAP authentication method that does not generate a shared key + (also known as a non-key-generating EAP method) can become + compromised due to the deployment of an entirely unrelated + application that also happens to use the same non-key-generating EAP + method, but in an unprotected fashion. Note that this vulnerability + is not limited to just EAP, but can occur in other scenarios where an + authentication infrastructure is reused. For example, if the EAP + mechanism used by IKEv2 utilizes a token authenticator, a man-in-the- + middle attacker could impersonate the web server, intercept the token + authentication exchange, and use it to initiate an IKEv2 connection. + For this reason, use of non-key-generating EAP methods SHOULD be + avoided where possible. Where they are used, it is extremely + important that all usages of these EAP methods SHOULD utilize a + protected tunnel, where the initiator validates the responder's + certificate before initiating the EAP exchange. Implementers SHOULD + describe the vulnerabilities of using non-key-generating EAP methods + in the documentation of their implementations so that the + administrators deploying IPsec solutions are aware of these dangers. + + An implementation using EAP MUST also use a public key based + authentication of the server to the client before the EAP exchange + begins, even if the EAP method offers mutual authentication. This + avoids having additional IKEv2 protocol variations and protects the + EAP data from active attackers. + + If the messages of IKEv2 are long enough that IP level fragmentation + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 88] + + + + + +Internet-Draft September 23, 2004 + + + is necessary, it is possible that attackers could prevent the + exchange from completing by exhausting the reassembly buffers. The + chances of this can be minimized by using the Hash and URL encodings + instead of sending certificates (see section 3.6). Additional + mitigations are discussed in [KPS03]. + +6 IANA Considerations + + This document defines a number of new field types and values where + future assignments will be managed by the IANA. + + The following registries should be created: + + IKEv2 Exchange Types (section 3.1) + IKEv2 Payload Types (section 3.2) + IKEv2 Transform Types (section 3.3.2) + IKEv2 Transform Attribute Types (section 3.3.2) + IKEv2 Encryption Transform IDs (section 3.3.2) + IKEv2 Pseudo-random Function Transform IDs (section 3.3.2) + IKEv2 Integrity Algorithm Transform IDs (section 3.3.2) + IKEv2 Diffie-Hellman Transform IDs (section 3.3.2) + IKEv2 Identification Payload ID Types (section 3.5) + IKEv2 Certificate Encodings (section 3.6) + IKEv2 Authentication Method (section 3.8) + IKEv2 Notify Message Types (section 3.10.1) + IKEv2 Notification IPCOMP Transform IDs (section 3.10.1) + IKEv2 Security Protocol Identifiers (section 3.3.1) + IKEv2 Traffic Selector Types (section 3.13.1) + IKEv2 Configuration Payload CFG Types (section 3.15) + IKEv2 Configuration Payload Attribute Types (section 3.15.1) + + Note: when creating a new Transform Type, a new registry for it must + be created. + + Changes and additions to any of those registries are by expert + review. + +7 Acknowledgements + + This document is a collaborative effort of the entire IPsec WG. If + there were no limit to the number of authors that could appear on an + RFC, the following, in alphabetical order, would have been listed: + Bill Aiello, Stephane Beaulieu, Steve Bellovin, Sara Bitan, Matt + Blaze, Ran Canetti, Darren Dukes, Dan Harkins, Paul Hoffman, John + Ioannidis, Charlie Kaufman, Steve Kent, Angelos Keromytis, Tero + Kivinen, Hugo Krawczyk, Andrew Krywaniuk, Radia Perlman, Omer + Reingold, and Michael Richardson. Many other people contributed to + the design. It is an evolution of IKEv1, ISAKMP, and the IPsec DOI, + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 89] + + + + + +Internet-Draft September 23, 2004 + + + each of which has its own list of authors. Hugh Daniel suggested the + feature of having the initiator, in message 3, specify a name for the + responder, and gave the feature the cute name "You Tarzan, Me Jane". + David Faucher and Valery Smyzlov helped refine the design of the + traffic selector negotiation. + +8 References + +8.1 Normative References + + [ADDGROUP] Kivinen, T., and Kojo, M., "More Modular Exponential + (MODP) Diffie-Hellman groups for Internet Key + Exchange (IKE)", RFC 3526, May 2003. + + [ADDRIPV6] Hinden, R., and Deering, S., + "Internet Protocol Version 6 (IPv6) Addressing + Architecture", RFC 3513, April 2003. + + [Bra97] Bradner, S., "Key Words for use in RFCs to indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + [EAP] Aboba, B., Blunk, L., Vollbrecht, J., Carlson, J., and + Levkowetz, H., "Extensible Authentication Protocol + (EAP)", RFC 3748, June 2004. + + [ESPCBC] Pereira, R., Adams, R., "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + [Hutt04] Huttunen, A. et. al., "UDP Encapsulation of IPsec + Packets", draft-ietf-ipsec-udp-encaps-08.txt, February + 2004, work in progress. + + [RFC2401bis] Kent, S. and Atkinson, R., "Security Architecture + for the Internet Protocol", + draft-ietf-ipsec-rfc2401bis-02.txt, April 2004, work + in progress. + + [RFC2434] Narten, T. and H. Alvestrand, "Guidelines for Writing + an IANA Considerations Section in RFCs", BCP 26, RFC 2434, + October 1998. + + [RFC3168] Ramakrishnan, K., Floyd, S., and Black, D., + "The Addition of Explicit Congestion Notification (ECN) + to IP", RFC 3168, September 2001. + + [RFC3280] Housley, R., Polk, W., Ford, W., Solo, D., "Internet + X.509 Public Key Infrastructure Certificate and + Certificate Revocation List (CRL) Profile", RFC 3280, + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 90] + + + + + +Internet-Draft September 23, 2004 + + + April 2002. + + [RFC3667] Bradner, S., "IETF Rights in Submissions", BCP 78, + RFC 3667, February 2004. + + [RFC3668] Bradner, S., "Intellectual Property Rights in IETF + Technology", BCP 79, RFC 3668, February 2004. + +8.2 Informative References + + [DES] ANSI X3.106, "American National Standard for Information + Systems-Data Link Encryption", American National Standards + Institute, 1983. + + [DH] Diffie, W., and Hellman M., "New Directions in + Cryptography", IEEE Transactions on Information Theory, V. + IT-22, n. 6, June 1977. + + [DHCP] R. Droms, "Dynamic Host Configuration Protocol", + RFC2131 + + [DSS] NIST, "Digital Signature Standard", FIPS 186, National + Institute of Standards and Technology, U.S. Department of + Commerce, May, 1994. + + [EAPMITM] Asokan, N., Nierni, V., and Nyberg, K., "Man-in-the-Middle + in Tunneled Authentication Protocols", + http://eprint.iacr.org/2002/163, November 2002. + + [HC98] Harkins, D., Carrel, D., "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IDEA] Lai, X., "On the Design and Security of Block Ciphers," + ETH Series in Information Processing, v. 1, Konstanz: + Hartung-Gorre Verlag, 1992 + + [IPCOMP] Shacham, A., Monsour, R., Pereira, R., and Thomas, M., "IP + Payload Compression Protocol (IPComp)", RFC 3173, + September 2001. + + [KPS03] Kaufman, C., Perlman, R., and Sommerfeld, B., "DoS + protection for UDP-based protocols", ACM Conference on + Computer and Communications Security, October 2003. + + [KBC96] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed- + Hashing for Message Authentication", RFC 2104, February + 1997. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 91] + + + + + +Internet-Draft September 23, 2004 + + + [LDAP] M. Wahl, T. Howes, S. Kille., "Lightweight Directory + Access Protocol (v3)", RFC 2251 + + [MD5] Rivest, R., "The MD5 Message Digest Algorithm", RFC 1321, + April 1992. + + [MSST98] Maughhan, D., Schertler, M., Schneider, M., and Turner, J. + "Internet Security Association and Key Management Protocol + (ISAKMP)", RFC 2408, November 1998. + + [Orm96] Orman, H., "The Oakley Key Determination Protocol", RFC + 2412, November 1998. + + [PFKEY] McDonald, D., Metz, C., and Phan, B., "PFKEY Key + Management API, Version 2", RFC 2367, July 1998. + + [PKCS1] Kaliski, B., and J. Staddon, "PKCS #1: RSA Cryptography + Specifications Version 2", September 1998. + + [PK01] Perlman, R., and Kaufman, C., "Analysis of the IPsec key + exchange Standard", WET-ICE Security Conference, MIT,2001, + http://sec.femto.org/wetice-2001/papers/radia-paper.pdf. + + [Pip98] Piper, D., "The Internet IP Security Domain Of + Interpretation for ISAKMP", RFC 2407, November 1998. + + [RADIUS] C. Rigney, A. Rubens, W. Simpson, S. Willens, "Remote + Authentication Dial In User Service (RADIUS)", RFC 2138 + + [RFC1750] Eastlake, D., Crocker, S., and Schiller, J., "Randomness + Recommendations for Security", RFC 1750, December 1994. + + [RFC1958] Carpenter, B., "Architectural Principles of the + Internet", RFC 1958, June 1996. + + [RFC2401] Kent, S., and Atkinson, R., "Security Architecture for + the Internet Protocol", RFC 2401, November 1998. + + [RFC2402] Kent, S., and Atkinson, R., "IP Authentication Header", + RFC 2402, November 1998. + + [RFC2406] Kent, S., and Atkinson, R., "IP Encapsulating Security + Payload (ESP)", RFC 2406, November 1998. + + [RFC2474] Nichols, K., Blake, S., Baker, F. and Black, D., + "Definition of the Differentiated Services Field (DS + Field) in the IPv4 and IPv6 Headers", RFC 2474, + December 1998. + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 92] + + + + + +Internet-Draft September 23, 2004 + + + [RFC2475] Blake, S., Black, D., Carlson, M., Davies, E., Wang, Z. + and Weiss, W., "An Architecture for Differentiated + Services", RFC 2475, December 1998. + + [RFC2522] Karn, P., and Simpson, W., "Photuris: Session-Key + Management Protocol", RFC 2522, March 1999. + + [RFC2775] Carpenter, B., "Internet Transparency", RFC 2775, + February 2000. + + [RFC2983] Black, D., "Differentiated Services and Tunnels", + RFC 2983, October 2000. + + [RFC3439] Bush, R. and D. Meyer, "Some Internet Architectural + Guidelines and Philosophy", RFC 3429, December 2002. + + [RFC3715] Aboba, B and Dixon, W., "IPsec-Network Address + Translation (NAT) Compatibility Requirements", + RFC 3715, March 2004. + + [RSA] Rivest, R., Shamir, A., and Adleman, L., "A Method for + Obtaining Digital Signatures and Public-Key + Cryptosystems", Communications of the ACM, v. 21, n. 2, + February 1978. + + [SHA] NIST, "Secure Hash Standard", FIPS 180-1, National + Institute of Standards and Technology, U.S. Department + of Commerce, May 1994. + + [SIGMA] Krawczyk, H., "SIGMA: the `SIGn-and-MAc' Approach to + Authenticated Diffie-Hellman and its Use in the IKE + Protocols", in Advances in Cryptography - CRYPTO 2003 + Proceedings, LNCS 2729, Springer, 2003. Available at: + http://www.ee.technion.ac.il/~hugo/sigma.html + + [SKEME] Krawczyk, H., "SKEME: A Versatile Secure Key Exchange + Mechanism for Internet", from IEEE Proceedings of the + 1996 Symposium on Network and Distributed Systems + Security. + + [X.501] ITU-T Recommendation X.501: Information Technology - + Open Systems Interconnection - The Directory: Models, + 1993. + + [X.509] ITU-T Recommendation X.509 (1997 E): Information + Technology - Open Systems Interconnection - The + Directory: Authentication Framework, June 1997. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 93] + + + + + +Internet-Draft September 23, 2004 + + +Appendix A: Summary of changes from IKEv1 + + + The goals of this revision to IKE are: + + 1) To define the entire IKE protocol in a single document, replacing + RFCs 2407, 2408, and 2409 and incorporating subsequent changes to + support NAT Traversal, Extensible Authentication, and Remote Address + acquisition. + + 2) To simplify IKE by replacing the eight different initial exchanges + with a single four message exchange (with changes in authentication + mechanisms affecting only a single AUTH payload rather than + restructuring the entire exchange); + + 3) To remove the Domain of Interpretation (DOI), Situation (SIT), and + Labeled Domain Identifier fields, and the Commit and Authentication + only bits; + + 4) To decrease IKE's latency in the common case by making the initial + exchange be 2 round trips (4 messages), and allowing the ability to + piggyback setup of a CHILD_SA on that exchange; + + 5) To replace the cryptographic syntax for protecting the IKE + messages themselves with one based closely on ESP to simplify + implementation and security analysis; + + 6) To reduce the number of possible error states by making the + protocol reliable (all messages are acknowledged) and sequenced. This + allows shortening CREATE_CHILD_SA exchanges from 3 messages to 2; + + 7) To increase robustness by allowing the responder to not do + significant processing until it receives a message proving that the + initiator can receive messages at its claimed IP address, and not + commit any state to an exchange until the initiator can be + cryptographically authenticated; + + 8) To fix cryptographic weaknesses such as the problem with + symmetries in hashes used for authentication documented by Tero + Kivinen. + + 9) To specify Traffic Selectors in their own payloads type rather + than overloading ID payloads, and making more flexible the Traffic + Selectors that may be specified; + + 10) To specify required behavior under certain error conditions or + when data that is not understood is received in order to make it + easier to make future revisions in a way that does not break + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 94] + + + + + +Internet-Draft September 23, 2004 + + + backwards compatibility; + + 11) To simplify and clarify how shared state is maintained in the + presence of network failures and Denial of Service attacks; and + + 12) To maintain existing syntax and magic numbers to the extent + possible to make it likely that implementations of IKEv1 can be + enhanced to support IKEv2 with minimum effort. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 95] + + + + + +Internet-Draft September 23, 2004 + + +Appendix B: Diffie-Hellman Groups + + There are two Diffie-Hellman groups defined here for use in IKE. + These groups were generated by Richard Schroeppel at the University + of Arizona. Properties of these primes are described in [Orm96]. + + The strength supplied by group one may not be sufficient for the + mandatory-to-implement encryption algorithm and is here for historic + reasons. + + Additional Diffie-Hellman groups have been defined in [ADDGROUP]. + +B.1 Group 1 - 768 Bit MODP + + This group is assigned id 1 (one). + + The prime is: 2^768 - 2 ^704 - 1 + 2^64 * { [2^638 pi] + 149686 } + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08 + 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B + 302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9 + A63A3620 FFFFFFFF FFFFFFFF + + The generator is 2. + +B.2 Group 2 - 1024 Bit MODP + + This group is assigned id 2 (two). + + The prime is 2^1024 - 2^960 - 1 + 2^64 * { [2^894 pi] + 129093 }. + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08 + 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B + 302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9 + A637ED6B 0BFF5CB6 F406B7ED EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 + 49286651 ECE65381 FFFFFFFF FFFFFFFF + + The generator is 2. + + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 96] + + + + + +Internet-Draft September 23, 2004 + + +Change History (To be removed from RFC) + +H.1 Changes from IKEv2-00 to IKEv2-01 February 2002 + + 1) Changed Appendix B to specify the encryption and authentication + processing for IKE rather than referencing ESP. Simplified the format + by removing idiosyncrasies not needed for IKE. + + 2) Added option for authentication via a shared secret key. + + 3) Specified different keys in the two directions of IKE messages. + Removed requirement of different cookies in the two directions since + now no longer required. + + 4) Change the quantities signed by the two ends in AUTH fields to + assure the two parties sign different quantities. + + 5) Changed reference to AES to AES_128. + + 6) Removed requirement that Diffie-Hellman be repeated when rekeying + IKE_SA. + + 7) Fixed typos. + + 8) Clarified requirements around use of port 500 at the remote end in + support of NAT. + + 9) Clarified required ordering for payloads. + + 10) Suggested mechanisms for avoiding DoS attacks. + + 11) Removed claims in some places that the first phase 2 piggybacked + on phase 1 was optional. + +H.2 Changes from IKEv2-01 to IKEv2-02 April 2002 + + 1) Moved the Initiator CERTREQ payload from message 1 to message 3. + + 2) Added a second optional ID payload in message 3 for the Initiator + to name a desired Responder to support the case where multiple named + identities are served by a single IP address. + + 3) Deleted the optimization whereby the Diffie-Hellman group did not + need to be specified in phase 2 if it was the same as in phase 1 (it + complicated the design with no meaningful benefit). + + 4) Added a section on the implications of reusing Diffie-Hellman + exponentials + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 97] + + + + + +Internet-Draft September 23, 2004 + + + 5) Changed the specification of sequence numbers to being at 0 in + both directions. + + 6) Many editorial changes and corrections, the most significant being + a global replace of "byte" with "octet". + +H.3 Changes from IKEv2-02 to IKEv2-03 October 2002 + + 1) Reorganized the document moving introductory material to the + front. + + 2) Simplified the specification of Traffic Selectors to allow only + IPv4 and IPv6 address ranges, as was done in the JFK spec. + + 3) Fixed the problem brought up by David Faucher with the fix + suggested by Valery Smyslov. If Bob needs to narrow the selector + range, but has more than one matching narrower range, then if Alice's + first selector is a single address pair, Bob chooses the range that + encompasses that. + + 4) To harmonize with the JFK spec, changed the exchange so that the + initial exchange can be completed in four messages even if the + responder must invoke an anti-clogging defense and the initiator + incorrectly anticipates the responder's choice of Diffie-Hellman + group. + + 5) Replaced the hierarchical SA payload with a simplified version + that only negotiates suites of cryptographic algorithms. + +H.4 Changes from IKEv2-03 to IKEv2-04 January 2003 + + 1) Integrated NAT traversal changes (including Appendix A). + + 2) Moved the anti-clogging token (cookie) from the SPI to a NOTIFY + payload; changed negotiation back to 6 messages when a cookie is + needed. + + 3) Made capitalization of IKE_SA and CHILD_SA consistent. + + 4) Changed how IPComp was negotiated. + + 5) Added usage scenarios. + + 6) Added configuration payload for acquiring internal addresses on + remote networks. + + 7) Added negotiation of tunnel vs. transport mode. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 98] + + + + + +Internet-Draft September 23, 2004 + + +H.5 Changes from IKEv2-04 to IKEv2-05 February 2003 + + 1) Shortened Abstract + + 2) Moved NAT Traversal from Appendix to section 2. Moved changes from + IKEv2 to Appendix A. Renumbered sections. + + 3) Made language more consistent. Removed most references to Phase 1 + and Phase 2. + + 4) Made explicit the requirements for support of NAT Traversal. + + 5) Added support for Extended Authentication Protocol methods. + + 6) Added Response bit to message header. + + 7) Made more explicit the encoding of Diffie-Hellman numbers in key + expansion algorithms. + + 8) Added ID payloads to AUTH payload computation. + + 9) Expanded set of defined cryptographic suites. + + 10) Added text for MUST/SHOULD support for ID payloads. + + 11) Added new certificate formats and added MUST/SHOULD text. + + 12) Clarified use of CERTREQ. + + 13) Deleted "MUST SUPPORT" column in CP payload specification (it was + inconsistent with surrounding text). + + 14) Extended and clarified Conformance Requirements section, + including specification of a minimal implementation. + + 15) Added text to specify ECN handling. + +H.6 Changes from IKEv2-05 to IKEv2-06 March 2003 + + 1) Changed the suite based crypto negotiation back to ala carte. + + 2) Eliminated some awkward page breaks, typographical errors, and + other formatting issues. + + 3) Tightened language describing cryptographic strength. + + 4) Added references. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 99] + + + + + +Internet-Draft September 23, 2004 + + + 5) Added more specific error codes. + + 6) Added rationale for unintuitive key generation hash with shared + secret based authentication. + + 7) Changed the computation of the authenticating AUTH payload as + proposed by Hugo Krawczyk. + + 8) Changed the dashes (-) to underscores (_) in the names of fields + and constants. + +H.7 Changes from IKEv2-06 to IKEv2-07 April 2003 + + 1) Added a list of payload types to section 3.2. + + 2) Clarified use of SET_WINDOW_SIZE Notify payload. + + 3) Removed references to COOKIE_REQUIRED Notify payload. + + 4) Specified how to use a prf with a fixed key size. + + 5) Removed g^ir from data processed by prf+. + + 6) Strengthened cautions against using passwords as shared keys. + + 7) Renamed Protocol_id field SECURITY_PROTOCOL_ID when it is not the + Protocol ID from IP, and changed its values for consistency with + IKEv1. + + 8) Clarified use of ID payload in access control decisions. + + 9) Gave IDr and TSr their own payload type numbers. + + 10) Added Intellectual Property rights section. + + 11) Clarified some issues in NAT Traversal. + +H.8 Changes from IKEv2-07 to IKEv2-08 May 2003 + + 1) Numerous editorial corrections and clarifications. + + 2) Renamed Gateway to Security Gateway. + + 3) Made explicit that the ability to rekey SAs without restarting IKE + was optional. + + 4) Removed last references to MUST and SHOULD cipher suites. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 100] + + + + + +Internet-Draft September 23, 2004 + + + 5) Changed examples to "example.com". + + 6) Changed references to status codes to status types. + + 7) Simplified IANA Considerations section + + 8) Updated References + +H.9 Changes from IKEv2-08 to IKEv2-09 August 2003 + + 1) Numerous editorial corrections and clarifications. + + 2) Added REKEY_SA notify payload to the first message of a + CREATE_CHILD_SA exchange if the new exchange was rekeying an existing + SA. + + 3) Renamed AES_ENCR128 to AES_ENCR and made it take a single + parameter that is the key size (which may be 128, 192, or 256 bits). + + 4) Clarified when a newly created SA is useable. + + 5) Added additional text to section 2.23 specifying how to negotiate + NAT Traversal. + + 6) Replaced specification of ECN handling with a reference to + [RFC2401bis]. + + 7) Renumbered payloads so that numbers would not collide with IKEv1 + payload numbers in hopes of making code implementing both protocols + simpler. + + 8) Expanded the Transform ID field (also referred to as Diffie- + Hellman group number) from one byte to two bytes. + + 9) Removed ability to negotiate Diffie-Hellman groups by explicitly + passing parameters. They must now be negotiated using Transform IDs. + + 10) Renumbered status codes to be contiguous. + + 11) Specified the meaning of the "Port" fields in Traffic Selectors + when the ICMP protocol is being used. + + 12) Removed the specification of D-H Group #5 since it is already + specified in [ADDGROUP]. + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 101] + + + + + +Internet-Draft September 23, 2004 + + +H.10 Changes from IKEv2-09 to IKEv2-10 August 2003 + + 1) Numerous boilerplate and formatting corrections to comply with RFC + Editorial Guidelines and procedures. + + 2) Fixed five typographical errors. + + 3) Added a sentence to the end of "Security considerations" + discouraging the use of non-key-generating EAP mechanisms. + +H.11 Changes from IKEv2-10 to IKEv2-11 October 2003 + + 1) Added SHOULD NOT language concerning use of non-key-generating EAP + authentication methods and added reference [EAPMITM]. + + 2) Clarified use of parallel SAs with identical traffic selectors for + purposes of QoS handling. + + 3) Fixed description of ECN handling to make normative references to + [RFC2401bis] and [RFC3168]. + + 4) Fixed two typos in the description of NAT traversal. + + 5) Added specific ASN.1 encoding of certificate bundles in section + 3.6. + +H.12 Changes from IKEv2-11 to IKEv2-12 January 2004 + + 1) Made the values of the one byte IPsec Protocol ID consistent + between payloads and made the naming more nearly consistent. + + 2) Changed the specification to require that AUTH payloads be + provided in EAP exchanges even when a non-key generating EAP method + is used. This protects against certain obscure cryptographic + threats. + + 3) Changed all example IP addresses to be within subnet 10. + + 4) Specified that issues surrounding weak keys and DES key parity + must be addressed in algorithm documents. + + 5) Removed the unsupported (and probably untrue) claim that Photuris + cookies were given that name because the IETF always supports + proposals involving cookies. + + 6) Fixed some text that specified that Transform ID was 1 octet while + everywhere else said it was 2 octets. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 102] + + + + + +Internet-Draft September 23, 2004 + + + 7) Corrected the ASN.1 specification of the encoding of X.509 + certificate bundles. + + 8) Added an INVALID_SELECTORS error type. + + 9) Replaced IANA considerations section with a reference to draft- + ietf-ipsec-ikev2-iana-00.txt. + + 10) Removed 2 obsolete informative references and added one to a + paper on UDP fragmentation problems. + + 11) 41 Editorial Corrections and Clarifications. + + 12) 6 Grammatical and Spelling errors fixed. + + 13) 4 Corrected capitalizations of MAY/MUST/etc. + + 14) 4 Attempts to make capitalization and use of underscores more + consistent. + +H.13 Changes from IKEv2-12 to IKEv2-13 March 2004 + + 1) Updated copyright and intellectual property right sections per RFC + 3667. Added normative references to RFC 3667 and RFC 3668. + + 2) Updated IANA Considerations section and adjusted some assignment + tables to be consistent with the IANA registries document. Added + Michael Richardson to the acknowledgements. + + 3) Changed the cryptographic formula for computing the AUTH payload + in the case where EAP authentication is used and the EAP algorithm + does not produce a shared key. Clarified the case where it does + produce a shared key. + + 4) Extended the EAP authentication protocol by two messages so that + the AUTH message is always sent after the success status is received. + + 5) Updated reference to ESP encapsulation in UDP and made it + normative. + + 6) Added notification type ESP_TFC_PADDING_NOT_SUPPORTED. + + 7) Clarified encoding of port number fields in transport selectors in + the cases of ICMP and OPAQUE. + + 8) Clarified that the length of the integrity checksum is fixed + length and determined by the negotiated integrity algorithm. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 103] + + + + + +Internet-Draft September 23, 2004 + + + 9) Added an informative reference to RFC 3715 (NAT Compatibility + Requirements). + + 10) Fixed 2 typos. + +H.14 Changes from IKEv2-13 to IKEv2-14 May 2004 + + 1) ISSUE #99: Clarified use of tunnel mode vs. transport mode. + + 2) Changed the cryptographic formula for computing the AUTH payload + in response to a suggestion from Hugo Krawczyk. + + 3) Fixed a wording error in the explanation of why NAT traversal + works as it does related to processing by legacy NAT gateways. + + 4) Corrected the label AUTH_AES_XCBC_96 to AUTH_AES_PRF_128. + + 5) Deleted suggestion that ID_KEY_ID field might be used to pass an + account name. + + 6) Listed the newly allocated OID for certificate bundle. + + 7) Added NON_FIRST_FRAGMENTS_ALSO notification for negotiating the + ability to send non-initial fragments of packets on the same SA as + the initial fragments. + + 8) ISSUE #97: Removed language concerning the relative strength of + Diffie-Hellman groups. + + 9) ISSUE #100: Reduced requirements concerning sending of + certificates to allow implementations to by more coy about their + identities and protect themselves from probing attacks. Listed in + Security Considerations some issues an implementer might consider in + deciding how to deal with such attacks. + + 10) Made the punctuation of references to RFCs more consistent. + + 11) Fixed fourteen typos. + +H.15 Changes from IKEv2-14 to IKEv2-15 August 2004 + + 1) ISSUE #111, 113: Made support for "Hash and URL" as a substitute + for certificates mandatory, and added explanatory text about the + dangers of depending on IP fragmentation for large messages. + + 2) ISSUE #110: Made support for configuring shared keys by means of a + HEX encoded byte string mandatory. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 104] + + + + + +Internet-Draft September 23, 2004 + + + 3) Clarified use of special traffic selectors with a port range from + 65535 - 0. + + 4) ISSUE #110: Added reference to RFC2401bis for definitions of + terms. + + 5) ISSUE #110, 114: Made required support of ID_IPV4_ADDR and + ID_IPV6_ADDR depend on support of IPv4 vs. IPv6 as a transport. + + 6) ISSUE #114: Removed INTERNAL_IP6_NETMASK and replaced it with text + describing how an endpoint should request an IP address with + specified low order bytes. + + 7) ISSUE #101, 102, 104, 105, 106, and 107: Fold in information from + draft-ietf-ipsec-ikev2-iana-00.txt to make that document unnecessary + for initial IANA settings. Deleted it from references. + + 8) ISSUE #110: Removed reference to ENCR_RC4. + + 9) ISSUE #112: Removed reference to draft-keromytis-ike-id-00.txt, + which will not be published as an RFC. + + 10) ISSUE #112: Removed text incorrectly implying that AH could be + tunneled over port 4500. + + 11) ISSUE #112: Removed reference to draft-ietf-ipsec-nat- + reqts-04.txt. + + 12) ISSUE #112: Removed reference to draft-ipsec-ike-hash- + revised-02.txt, and substituted a short explanation of the problem + addressed. + + 13) ISSUE #112: Changed the label of PRF_AES_CBC to PRF_AES128_CBC + + 14) ISSUE #110: Clarified distinction between Informational messages + and Informational exchanges. + + 15) ISSUE #110: Clarified distinction between SA payloads and SAs. + + 16) ISSUE #109: Clarified that cryptographic algorithms that MUST be + supported can still be configured as off. + + 17) ISSUE #110: Changed example IP addresses from 10.*.*.* to + 192.0.*.*. + + 18) ISSUE #108: Rephrased to avoid use of the undefined acronyms PFS + and NAT-T. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 105] + + + + + +Internet-Draft September 23, 2004 + + + 19) ISSUE #113: Added requirement that backoff timers on + retransmissions must increase exponentially to avoid network + congestion. + + 20) Replaced dubious explanation of NON_FIRST_FRAGMENTS_ALSO with a + reference to RFC2401bis. + + 21) Fixed 16 spelling/typographical/gramatical errors. + +H.16 Changes from IKEv2-15 to IKEv2-16 September 2004 + + 1) Added the text: "All IKEv2 implementations MUST be able to send, + receive, and process IKE messages that are up to 1280 bytes long, and + they SHOULD be able to send, receive, and process messages that are + up to 3000 bytes long." + + 2) Removed the two ECC groups from Appendix B. + + 3) Changed references to RFC 2284 to RFC 3748, references to Extended + Authentication Protocol to Extensible Authentication Protocol, and + made some editorial corrections related to EAP proposed by Jari + Arkko. + + 4) Added a note to security considerations saying that IKE MUST NOT + negotiate NONE as its integrity protection algorithm or ENCR_NULL as + its encryption algorithm. + + 5) Added I-D boilerplate concerning IPR claim disclosure. + + 6) Clarified that "empty" messages included a single empty Encrypted + payload. + + 7) Added (SA) after first reference to "Security Association". + + 8) Noted that incompatible configurations of traffic selectors SHOULD + be noted in error logs. + + 9) 3 minor editorial clarifications. + +H.17 Changes from IKEv2-16 to IKEv2-17 September 2004 + + 1) Removed all references to Alice and Bob, replacing them with "the + initiator" and "the responder". Also fixed the corresponding he/she, + his/her, and the capitalization of initiator and responder. + + 2) Changed specification of BER encoded fields to be DER encoded + fields. + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 106] + + + + + +Internet-Draft September 23, 2004 + + + 3) Removed obsolete reference to CA names appearing in CERTREQ + fields. + + 4) Fixed the specification of INTERNAL_IPx_SUBNET Configuration + Attributes to indicate that they could be multi-valued. + + 5) Added informative references to RFC 2402 and RFC 2406. + + 6) Fixed a formatting glitch in the computation of AUTH. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 107] + + + + + +Internet-Draft September 23, 2004 + + +Editor's Address + + Charlie Kaufman + Microsoft Corporation + 1 Microsoft Way + Redmond, WA 98052 + 1-425-707-3335 + + charliek@microsoft.com + + By submitting this Internet-Draft, the editor represents that any + applicable patent or other IPR claims of which he is aware have been + or will be disclosed, and any of which he becomes aware will be + disclosed, in accordance with RFC 3668. + +Full Copyright Statement + + Copyright (C) The Internet Society (2004). This document is subject + to the rights, licenses and restrictions contained in BCP 78 and + except as set forth therein, the authors retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property Statement + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 108] + + + + + +Internet-Draft September 23, 2004 + + + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at ietf- + ipr@ietf.org. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + +Expiration + + This Internet-Draft (draft-ietf-ipsec-ikev2-17.txt) expires in March + 2005. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +IKEv2 draft-ietf-ipsec-ikev2-17.txt [Page 109] + diff --git a/doc/ikev2/[IKEv2bis] - draft-hoffman-ikev2bis-00.txt b/doc/ikev2/[IKEv2bis] - draft-hoffman-ikev2bis-00.txt new file mode 100644 index 000000000..9d1b9d74d --- /dev/null +++ b/doc/ikev2/[IKEv2bis] - draft-hoffman-ikev2bis-00.txt @@ -0,0 +1,6776 @@ + + + +Network Working Group C. Kaufman +Internet-Draft Microsoft +Expires: August 27, 2006 P. Hoffman + VPN Consortium + P. Eronen + Nokia + February 23, 2006 + + + Internet Key Exchange Protocol: IKEv2 + draft-hoffman-ikev2bis-00.txt + +Status of this Memo + + By submitting this Internet-Draft, each author represents that any + applicable patent or other IPR claims of which he or she is aware + have been or will be disclosed, and any of which he or she becomes + aware will be disclosed, in accordance with Section 6 of BCP 79. + + Internet-Drafts are working documents of the Internet Engineering + Task Force (IETF), its areas, and its working groups. Note that + other groups may also distribute working documents as Internet- + Drafts. + + Internet-Drafts are draft documents valid for a maximum of six months + and may be updated, replaced, or obsoleted by other documents at any + time. It is inappropriate to use Internet-Drafts as reference + material or to cite them other than as "work in progress." + + The list of current Internet-Drafts can be accessed at + http://www.ietf.org/ietf/1id-abstracts.txt. + + The list of Internet-Draft Shadow Directories can be accessed at + http://www.ietf.org/shadow.html. + + This Internet-Draft will expire on August 27, 2006. + +Copyright Notice + + Copyright (C) The Internet Society (2006). + +Abstract + + This document describes version 2 of the Internet Key Exchange (IKE) + protocol. It is a restatement of RFC 4306, and includes all of the + clarifications from the "IKEv2 Clarifications" document. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 1] + +Internet-Draft IKEv2bis February 2006 + + +Table of Contents + + 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 5 + 1.1. Usage Scenarios . . . . . . . . . . . . . . . . . . . . . 6 + 1.1.1. Security Gateway to Security Gateway Tunnel . . . . . 7 + 1.1.2. Endpoint-to-Endpoint Transport . . . . . . . . . . . 7 + 1.1.3. Endpoint to Security Gateway Tunnel . . . . . . . . . 8 + 1.1.4. Other Scenarios . . . . . . . . . . . . . . . . . . . 9 + 1.2. The Initial Exchanges . . . . . . . . . . . . . . . . . . 9 + 1.3. The CREATE_CHILD_SA Exchange . . . . . . . . . . . . . . 12 + 1.3.1. Creating New CHILD_SAs with the CREATE_CHILD_SA + Exchange . . . . . . . . . . . . . . . . . . . . . . 13 + 1.3.2. Rekeying IKE_SAs with the CREATE_CHILD_SA Exchange . 14 + 1.3.3. Rekeying CHILD_SAs with the CREATE_CHILD_SA + Exchange . . . . . . . . . . . . . . . . . . . . . . 14 + 1.4. The INFORMATIONAL Exchange . . . . . . . . . . . . . . . 15 + 1.5. Informational Messages outside of an IKE_SA . . . . . . . 16 + 1.6. Requirements Terminology . . . . . . . . . . . . . . . . 17 + 1.7. Differences Between RFC 4306 and This Document . . . . . 17 + 2. IKE Protocol Details and Variations . . . . . . . . . . . . . 18 + 2.1. Use of Retransmission Timers . . . . . . . . . . . . . . 19 + 2.2. Use of Sequence Numbers for Message ID . . . . . . . . . 19 + 2.3. Window Size for Overlapping Requests . . . . . . . . . . 20 + 2.4. State Synchronization and Connection Timeouts . . . . . . 21 + 2.5. Version Numbers and Forward Compatibility . . . . . . . . 23 + 2.6. Cookies . . . . . . . . . . . . . . . . . . . . . . . . . 25 + 2.6.1. Interaction of COOKIE and INVALID_KE_PAYLOAD . . . . 27 + 2.7. Cryptographic Algorithm Negotiation . . . . . . . . . . . 28 + 2.8. Rekeying . . . . . . . . . . . . . . . . . . . . . . . . 29 + 2.8.1. Simultaneous CHILD_SA rekeying . . . . . . . . . . . 31 + 2.8.2. Rekeying the IKE_SA Versus Reauthentication . . . . . 33 + 2.9. Traffic Selector Negotiation . . . . . . . . . . . . . . 34 + 2.9.1. Traffic Selectors Violating Own Policy . . . . . . . 37 + 2.10. Nonces . . . . . . . . . . . . . . . . . . . . . . . . . 38 + 2.11. Address and Port Agility . . . . . . . . . . . . . . . . 38 + 2.12. Reuse of Diffie-Hellman Exponentials . . . . . . . . . . 38 + 2.13. Generating Keying Material . . . . . . . . . . . . . . . 39 + 2.14. Generating Keying Material for the IKE_SA . . . . . . . . 40 + 2.15. Authentication of the IKE_SA . . . . . . . . . . . . . . 41 + 2.16. Extensible Authentication Protocol Methods . . . . . . . 43 + 2.17. Generating Keying Material for CHILD_SAs . . . . . . . . 45 + 2.18. Rekeying IKE_SAs Using a CREATE_CHILD_SA Exchange . . . . 46 + 2.19. Requesting an Internal Address on a Remote Network . . . 47 + 2.20. Requesting the Peer's Version . . . . . . . . . . . . . . 48 + 2.21. Error Handling . . . . . . . . . . . . . . . . . . . . . 49 + 2.22. IPComp . . . . . . . . . . . . . . . . . . . . . . . . . 50 + 2.23. NAT Traversal . . . . . . . . . . . . . . . . . . . . . . 50 + 2.24. Explicit Congestion Notification (ECN) . . . . . . . . . 53 + + + +Kaufman, et al. Expires August 27, 2006 [Page 2] + +Internet-Draft IKEv2bis February 2006 + + + 3. Header and Payload Formats . . . . . . . . . . . . . . . . . 53 + 3.1. The IKE Header . . . . . . . . . . . . . . . . . . . . . 53 + 3.2. Generic Payload Header . . . . . . . . . . . . . . . . . 56 + 3.3. Security Association Payload . . . . . . . . . . . . . . 58 + 3.3.1. Proposal Substructure . . . . . . . . . . . . . . . . 60 + 3.3.2. Transform Substructure . . . . . . . . . . . . . . . 62 + 3.3.3. Valid Transform Types by Protocol . . . . . . . . . . 64 + 3.3.4. Mandatory Transform IDs . . . . . . . . . . . . . . . 65 + 3.3.5. Transform Attributes . . . . . . . . . . . . . . . . 66 + 3.3.6. Attribute Negotiation . . . . . . . . . . . . . . . . 67 + 3.4. Key Exchange Payload . . . . . . . . . . . . . . . . . . 68 + 3.5. Identification Payloads . . . . . . . . . . . . . . . . . 69 + 3.6. Certificate Payload . . . . . . . . . . . . . . . . . . . 71 + 3.7. Certificate Request Payload . . . . . . . . . . . . . . . 74 + 3.8. Authentication Payload . . . . . . . . . . . . . . . . . 76 + 3.9. Nonce Payload . . . . . . . . . . . . . . . . . . . . . . 77 + 3.10. Notify Payload . . . . . . . . . . . . . . . . . . . . . 77 + 3.10.1. Notify Message Types . . . . . . . . . . . . . . . . 78 + 3.11. Delete Payload . . . . . . . . . . . . . . . . . . . . . 84 + 3.12. Vendor ID Payload . . . . . . . . . . . . . . . . . . . . 85 + 3.13. Traffic Selector Payload . . . . . . . . . . . . . . . . 86 + 3.13.1. Traffic Selector . . . . . . . . . . . . . . . . . . 88 + 3.14. Encrypted Payload . . . . . . . . . . . . . . . . . . . . 90 + 3.15. Configuration Payload . . . . . . . . . . . . . . . . . . 92 + 3.15.1. Configuration Attributes . . . . . . . . . . . . . . 94 + 3.15.2. Meaning of INTERNAL_IP4_SUBNET/INTERNAL_IP6_SUBNET . 97 + 3.15.3. Configuration payloads for IPv6 . . . . . . . . . . . 99 + 3.15.4. Address Assignment Failures . . . . . . . . . . . . . 100 + 3.16. Extensible Authentication Protocol (EAP) Payload . . . . 100 + 4. Conformance Requirements . . . . . . . . . . . . . . . . . . 102 + 5. Security Considerations . . . . . . . . . . . . . . . . . . . 104 + 5.1. Traffic selector authorization . . . . . . . . . . . . . 107 + 6. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 108 + 7. Acknowledgements . . . . . . . . . . . . . . . . . . . . . . 108 + 8. References . . . . . . . . . . . . . . . . . . . . . . . . . 109 + 8.1. Normative References . . . . . . . . . . . . . . . . . . 109 + 8.2. Informative References . . . . . . . . . . . . . . . . . 110 + Appendix A. Summary of changes from IKEv1 . . . . . . . . . . . 114 + Appendix B. Diffie-Hellman Groups . . . . . . . . . . . . . . . 115 + B.1. Group 1 - 768 Bit MODP . . . . . . . . . . . . . . . . . 115 + B.2. Group 2 - 1024 Bit MODP . . . . . . . . . . . . . . . . . 115 + Appendix C. Exchanges and Payloads . . . . . . . . . . . . . . . 116 + C.1. IKE_SA_INIT Exchange . . . . . . . . . . . . . . . . . . 116 + C.2. IKE_AUTH Exchange without EAP . . . . . . . . . . . . . . 117 + C.3. IKE_AUTH Exchange with EAP . . . . . . . . . . . . . . . 118 + C.4. CREATE_CHILD_SA Exchange for Creating or Rekeying + CHILD_SAs . . . . . . . . . . . . . . . . . . . . . . . . 119 + C.5. CREATE_CHILD_SA Exchange for Rekeying the IKE_SA . . . . 119 + + + +Kaufman, et al. Expires August 27, 2006 [Page 3] + +Internet-Draft IKEv2bis February 2006 + + + C.6. INFORMATIONAL Exchange . . . . . . . . . . . . . . . . . 119 + Appendix D. Changes Between Internet Draft Versions . . . . . . 119 + D.1. Changes from IKEv2 to draft -00 . . . . . . . . . . . . . 119 + Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 120 + Intellectual Property and Copyright Statements . . . . . . . . . 120 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 4] + +Internet-Draft IKEv2bis February 2006 + + +1. Introduction + + {{ An introduction to the differences between RFC 4306 [IKEV2] and + this document is given at the end of Section 1. It is put there + (instead of here) to preserve the section numbering of the original + IKEv2 document. }} + + IP Security (IPsec) provides confidentiality, data integrity, access + control, and data source authentication to IP datagrams. These + services are provided by maintaining shared state between the source + and the sink of an IP datagram. This state defines, among other + things, the specific services provided to the datagram, which + cryptographic algorithms will be used to provide the services, and + the keys used as input to the cryptographic algorithms. + + Establishing this shared state in a manual fashion does not scale + well. Therefore, a protocol to establish this state dynamically is + needed. This memo describes such a protocol -- the Internet Key + Exchange (IKE). Version 1 of IKE was defined in RFCs 2407 [DOI], + 2408 [ISAKMP], and 2409 [IKEV1]. IKEv2 was defined in [IKEV2]. This + single document is intended to replace all three of those RFCs. + + Definitions of the primitive terms in this document (such as Security + Association or SA) can be found in [IPSECARCH]. {{ Clarif-7.2 }} It + should be noted that parts of IKEv2 rely on some of the processing + rules in [IPSECARCH], as described in various sections of this + document. + + IKE performs mutual authentication between two parties and + establishes an IKE security association (SA) that includes shared + secret information that can be used to efficiently establish SAs for + Encapsulating Security Payload (ESP) [ESP] and/or Authentication + Header (AH) [AH] and a set of cryptographic algorithms to be used by + the SAs to protect the traffic that they carry. In this document, + the term "suite" or "cryptographic suite" refers to a complete set of + algorithms used to protect an SA. An initiator proposes one or more + suites by listing supported algorithms that can be combined into + suites in a mix-and-match fashion. IKE can also negotiate use of IP + Compression (IPComp) [IPCOMP] in connection with an ESP and/or AH SA. + We call the IKE SA an "IKE_SA". The SAs for ESP and/or AH that get + set up through that IKE_SA we call "CHILD_SAs". + + All IKE communications consist of pairs of messages: a request and a + response. The pair is called an "exchange". We call the first + messages establishing an IKE_SA IKE_SA_INIT and IKE_AUTH exchanges + and subsequent IKE exchanges CREATE_CHILD_SA or INFORMATIONAL + exchanges. In the common case, there is a single IKE_SA_INIT + exchange and a single IKE_AUTH exchange (a total of four messages) to + + + +Kaufman, et al. Expires August 27, 2006 [Page 5] + +Internet-Draft IKEv2bis February 2006 + + + establish the IKE_SA and the first CHILD_SA. In exceptional cases, + there may be more than one of each of these exchanges. In all cases, + all IKE_SA_INIT exchanges MUST complete before any other exchange + type, then all IKE_AUTH exchanges MUST complete, and following that + any number of CREATE_CHILD_SA and INFORMATIONAL exchanges may occur + in any order. In some scenarios, only a single CHILD_SA is needed + between the IPsec endpoints, and therefore there would be no + additional exchanges. Subsequent exchanges MAY be used to establish + additional CHILD_SAs between the same authenticated pair of endpoints + and to perform housekeeping functions. + + IKE message flow always consists of a request followed by a response. + It is the responsibility of the requester to ensure reliability. If + the response is not received within a timeout interval, the requester + needs to retransmit the request (or abandon the connection). + + The first request/response of an IKE session (IKE_SA_INIT) negotiates + security parameters for the IKE_SA, sends nonces, and sends Diffie- + Hellman values. + + The second request/response (IKE_AUTH) transmits identities, proves + knowledge of the secrets corresponding to the two identities, and + sets up an SA for the first (and often only) AH and/or ESP CHILD_SA. + + The types of subsequent exchanges are CREATE_CHILD_SA (which creates + a CHILD_SA) and INFORMATIONAL (which deletes an SA, reports error + conditions, or does other housekeeping). Every request requires a + response. An INFORMATIONAL request with no payloads (other than the + empty Encrypted payload required by the syntax) is commonly used as a + check for liveness. These subsequent exchanges cannot be used until + the initial exchanges have completed. + + In the description that follows, we assume that no errors occur. + Modifications to the flow should errors occur are described in + Section 2.21. + +1.1. Usage Scenarios + + IKE is expected to be used to negotiate ESP and/or AH SAs in a number + of different scenarios, each with its own special requirements. + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 6] + +Internet-Draft IKEv2bis February 2006 + + +1.1.1. Security Gateway to Security Gateway Tunnel + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! + Protected !Tunnel ! tunnel !Tunnel ! Protected + Subnet <-->!Endpoint !<---------->!Endpoint !<--> Subnet + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 1: Security Gateway to Security Gateway Tunnel + + In this scenario, neither endpoint of the IP connection implements + IPsec, but network nodes between them protect traffic for part of the + way. Protection is transparent to the endpoints, and depends on + ordinary routing to send packets through the tunnel endpoints for + processing. Each endpoint would announce the set of addresses + "behind" it, and packets would be sent in tunnel mode where the inner + IP header would contain the IP addresses of the actual endpoints. + +1.1.2. Endpoint-to-Endpoint Transport + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec transport ! ! + !Protected! or tunnel mode SA !Protected! + !Endpoint !<---------------------------------------->!Endpoint ! + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 2: Endpoint to Endpoint + + In this scenario, both endpoints of the IP connection implement + IPsec, as required of hosts in [IPSECARCH]. Transport mode will + commonly be used with no inner IP header. If there is an inner IP + header, the inner addresses will be the same as the outer addresses. + A single pair of addresses will be negotiated for packets to be + protected by this SA. These endpoints MAY implement application + layer access controls based on the IPsec authenticated identities of + the participants. This scenario enables the end-to-end security that + has been a guiding principle for the Internet since [ARCHPRINC], + [TRANSPARENCY], and a method of limiting the inherent problems with + complexity in networks noted by [ARCHGUIDEPHIL]. Although this + scenario may not be fully applicable to the IPv4 Internet, it has + been deployed successfully in specific scenarios within intranets + using IKEv1. It should be more broadly enabled during the transition + to IPv6 and with the adoption of IKEv2. + + It is possible in this scenario that one or both of the protected + endpoints will be behind a network address translation (NAT) node, in + + + +Kaufman, et al. Expires August 27, 2006 [Page 7] + +Internet-Draft IKEv2bis February 2006 + + + which case the tunneled packets will have to be UDP encapsulated so + that port numbers in the UDP headers can be used to identify + individual endpoints "behind" the NAT (see Section 2.23). + +1.1.3. Endpoint to Security Gateway Tunnel + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! Protected + !Protected! tunnel !Tunnel ! Subnet + !Endpoint !<------------------------>!Endpoint !<--- and/or + ! ! ! ! Internet + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 3: Endpoint to Security Gateway Tunnel + + In this scenario, a protected endpoint (typically a portable roaming + computer) connects back to its corporate network through an IPsec- + protected tunnel. It might use this tunnel only to access + information on the corporate network, or it might tunnel all of its + traffic back through the corporate network in order to take advantage + of protection provided by a corporate firewall against Internet-based + attacks. In either case, the protected endpoint will want an IP + address associated with the security gateway so that packets returned + to it will go to the security gateway and be tunneled back. This IP + address may be static or may be dynamically allocated by the security + gateway. {{ Clarif-6.1 }} In support of the latter case, IKEv2 + includes a mechanism (namely, configuration payloads) for the + initiator to request an IP address owned by the security gateway for + use for the duration of its SA. + + In this scenario, packets will use tunnel mode. On each packet from + the protected endpoint, the outer IP header will contain the source + IP address associated with its current location (i.e., the address + that will get traffic routed to the endpoint directly), while the + inner IP header will contain the source IP address assigned by the + security gateway (i.e., the address that will get traffic routed to + the security gateway for forwarding to the endpoint). The outer + destination address will always be that of the security gateway, + while the inner destination address will be the ultimate destination + for the packet. + + In this scenario, it is possible that the protected endpoint will be + behind a NAT. In that case, the IP address as seen by the security + gateway will not be the same as the IP address sent by the protected + endpoint, and packets will have to be UDP encapsulated in order to be + routed properly. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 8] + +Internet-Draft IKEv2bis February 2006 + + +1.1.4. Other Scenarios + + Other scenarios are possible, as are nested combinations of the + above. One notable example combines aspects of 1.1.1 and 1.1.3. A + subnet may make all external accesses through a remote security + gateway using an IPsec tunnel, where the addresses on the subnet are + routed to the security gateway by the rest of the Internet. An + example would be someone's home network being virtually on the + Internet with static IP addresses even though connectivity is + provided by an ISP that assigns a single dynamically assigned IP + address to the user's security gateway (where the static IP addresses + and an IPsec relay are provided by a third party located elsewhere). + +1.2. The Initial Exchanges + + Communication using IKE always begins with IKE_SA_INIT and IKE_AUTH + exchanges (known in IKEv1 as Phase 1). These initial exchanges + normally consist of four messages, though in some scenarios that + number can grow. All communications using IKE consist of request/ + response pairs. We'll describe the base exchange first, followed by + variations. The first pair of messages (IKE_SA_INIT) negotiate + cryptographic algorithms, exchange nonces, and do a Diffie-Hellman + exchange [DH]. + + The second pair of messages (IKE_AUTH) authenticate the previous + messages, exchange identities and certificates, and establish the + first CHILD_SA. Parts of these messages are encrypted and integrity + protected with keys established through the IKE_SA_INIT exchange, so + the identities are hidden from eavesdroppers and all fields in all + the messages are authenticated. + + In the following descriptions, the payloads contained in the message + are indicated by names as listed below. + + + + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 9] + +Internet-Draft IKEv2bis February 2006 + + + Notation Payload + ----------------------------------------- + AUTH Authentication + CERT Certificate + CERTREQ Certificate Request + CP Configuration + D Delete + E Encrypted + EAP Extensible Authentication + HDR IKE Header + IDi Identification - Initiator + IDr Identification - Responder + KE Key Exchange + Ni, Nr Nonce + N Notify + SA Security Association + TSi Traffic Selector - Initiator + TSr Traffic Selector - Responder + V Vendor ID + + The details of the contents of each payload are described in section + 3. Payloads that may optionally appear will be shown in brackets, + such as [CERTREQ], indicate that optionally a certificate request + payload can be included. + + {{ Clarif-7.10 }} Many payloads contain fields marked as "RESERVED". + Some payloads in IKEv2 (and historically in IKEv1) are not aligned to + 4-byte boundaries. + + The initial exchanges are as follows: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SAi1, KEi, Ni --> + + HDR contains the Security Parameter Indexes (SPIs), version numbers, + and flags of various sorts. The SAi1 payload states the + cryptographic algorithms the initiator supports for the IKE_SA. The + KE payload sends the initiator's Diffie-Hellman value. Ni is the + initiator's nonce. + + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + + The responder chooses a cryptographic suite from the initiator's + offered choices and expresses that choice in the SAr1 payload, + completes the Diffie-Hellman exchange with the KEr payload, and sends + its nonce in the Nr payload. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 10] + +Internet-Draft IKEv2bis February 2006 + + + At this point in the negotiation, each party can generate SKEYSEED, + from which all keys are derived for that IKE_SA. All but the headers + of all the messages that follow are encrypted and integrity + protected. The keys used for the encryption and integrity protection + are derived from SKEYSEED and are known as SK_e (encryption) and SK_a + (authentication, a.k.a. integrity protection). A separate SK_e and + SK_a is computed for each direction. In addition to the keys SK_e + and SK_a derived from the DH value for protection of the IKE_SA, + another quantity SK_d is derived and used for derivation of further + keying material for CHILD_SAs. The notation SK { ... } indicates + that these payloads are encrypted and integrity protected using that + direction's SK_e and SK_a. + + HDR, SK {IDi, [CERT,] [CERTREQ,] + [IDr,] AUTH, SAi2, + TSi, TSr} --> + + The initiator asserts its identity with the IDi payload, proves + knowledge of the secret corresponding to IDi and integrity protects + the contents of the first message using the AUTH payload (see + Section 2.15). It might also send its certificate(s) in CERT + payload(s) and a list of its trust anchors in CERTREQ payload(s). If + any CERT payloads are included, the first certificate provided MUST + contain the public key used to verify the AUTH field. The optional + payload IDr enables the initiator to specify which of the responder's + identities it wants to talk to. This is useful when the machine on + which the responder is running is hosting multiple identities at the + same IP address. The initiator begins negotiation of a CHILD_SA + using the SAi2 payload. The final fields (starting with SAi2) are + described in the description of the CREATE_CHILD_SA exchange. + + <-- HDR, SK {IDr, [CERT,] AUTH, + SAr2, TSi, TSr} + + The responder asserts its identity with the IDr payload, optionally + sends one or more certificates (again with the certificate containing + the public key used to verify AUTH listed first), authenticates its + identity and protects the integrity of the second message with the + AUTH payload, and completes negotiation of a CHILD_SA with the + additional fields described below in the CREATE_CHILD_SA exchange. + + The recipients of messages 3 and 4 MUST verify that all signatures + and MACs are computed correctly and that the names in the ID payloads + correspond to the keys used to generate the AUTH payload. + + {{ Clarif-4.2}} If creating the CHILD_SA during the IKE_AUTH exchange + fails for some reason, the IKE_SA is still created as usual. The + list of responses in the IKE_AUTH exchange that do not prevent an + + + +Kaufman, et al. Expires August 27, 2006 [Page 11] + +Internet-Draft IKEv2bis February 2006 + + + IKE_SA from being set up include at least the following: + NO_PROPOSAL_CHOSEN, TS_UNACCEPTABLE, SINGLE_PAIR_REQUIRED, + INTERNAL_ADDRESS_FAILURE, and FAILED_CP_REQUIRED. + + {{ Clarif-4.3 }} Note that IKE_AUTH messages do not contain KEi/KEr + or Ni/Nr payloads. Thus, the SA payload in IKE_AUTH exchange cannot + contain Transform Type 4 (Diffie-Hellman Group) with any value other + than NONE. Implementations SHOULD NOT send such a transform because + it cannot be interpreted consistently, and implementations SHOULD + ignore any such tranforms they receive. + +1.3. The CREATE_CHILD_SA Exchange + + {{ This is a heavy rewrite of most of this section. The major + organization changes are described in Clarif-4.1 and Clarif-5.1. }} + + The CREATE_CHILD_SA exchange is used to create new CHILD_SAs and to + rekey both IKE_SAs and CHILD_SAs. This exchange consists of a single + request/response pair, and some of its function was referred to as a + phase 2 exchange in IKEv1. It MAY be initiated by either end of the + IKE_SA after the initial exchanges are completed. + + All messages following the initial exchange are cryptographically + protected using the cryptographic algorithms and keys negotiated in + the first two messages of the IKE exchange. These subsequent + messages use the syntax of the Encrypted Payload described in + Section 3.14. All subsequent messages include an Encrypted Payload, + even if they are referred to in the text as "empty". For both + messages in the CREATE_CHILD_SA, the message following the header is + encrypted and the message including the header is integrity protected + using the cryptographic algorithms negotiated for the IKE_SA. + + The CREATE_CHILD_SA is also used for rekeying IKE_SAs and CHILD_SAs. + An SA is rekeyed by creating a new SA and then deleting the old one. + This section describes the first part of rekeying, the creation of + new SAs; Section 2.8 covers the mechanics of rekeying, including + moving traffic from old to new SAs and the deletion of the old SAs. + The two sections must be read together to understand the entire + process of rekeying. + + Either endpoint may initiate a CREATE_CHILD_SA exchange, so in this + section the term initiator refers to the endpoint initiating this + exchange. An implementation MAY refuse all CREATE_CHILD_SA requests + within an IKE_SA. + + The CREATE_CHILD_SA request MAY optionally contain a KE payload for + an additional Diffie-Hellman exchange to enable stronger guarantees + of forward secrecy for the CHILD_SA. The keying material for the + + + +Kaufman, et al. Expires August 27, 2006 [Page 12] + +Internet-Draft IKEv2bis February 2006 + + + CHILD_SA is a function of SK_d established during the establishment + of the IKE_SA, the nonces exchanged during the CREATE_CHILD_SA + exchange, and the Diffie-Hellman value (if KE payloads are included + in the CREATE_CHILD_SA exchange). + + If a CREATE_CHILD_SA exchange includes a KEi payload, at least one of + the SA offers MUST include the Diffie-Hellman group of the KEi. The + Diffie-Hellman group of the KEi MUST be an element of the group the + initiator expects the responder to accept (additional Diffie-Hellman + groups can be proposed). If the responder rejects the Diffie-Hellman + group of the KEi payload, the responder MUST reject the request and + indicate its preferred Diffie-Hellman group in the INVALID_KE_PAYLOAD + Notification payload. In the case of such a rejection, the + CREATE_CHILD_SA exchange fails, and the initiator will probably retry + the exchange with a Diffie-Hellman proposal and KEi in the group that + the responder gave in the INVALID_KE_PAYLOAD. + +1.3.1. Creating New CHILD_SAs with the CREATE_CHILD_SA Exchange + + A CHILD_SA may be created by sending a CREATE_CHILD_SA request. The + CREATE_CHILD_SA request for creating a new CHILD_SA is: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK {SA, Ni, [KEi], + TSi, TSr} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, optionally a Diffie-Hellman value in the KEi payload, and + the proposed traffic selectors for the proposed CHILD_SA in the TSi + and TSr payloads. + + The CREATE_CHILD_SA response for creating a new CHILD_SA is: + + <-- HDR, SK {SA, Nr, [KEr], + TSi, TSr} + + The responder replies (using the same Message ID to respond) with the + accepted offer in an SA payload, and a Diffie-Hellman value in the + KEr payload if KEi was included in the request and the selected + cryptographic suite includes that group. + + The traffic selectors for traffic to be sent on that SA are specified + in the TS payloads in the response, which may be a subset of what the + initiator of the CHILD_SA proposed. + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 13] + +Internet-Draft IKEv2bis February 2006 + + +1.3.2. Rekeying IKE_SAs with the CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA request for rekeying an IKE_SA is: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK {SA, Ni, KEi} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, and a Diffie-Hellman value in the KEi payload. New + initiator and responder SPIs are supplied in the SPI fields. + + The CREATE_CHILD_SA response for rekeying an IKE_SA is: + + <-- HDR, SK {SA, Nr, KEr} + + The responder replies (using the same Message ID to respond) with the + accepted offer in an SA payload, and a Diffie-Hellman value in the + KEr payload if the selected cryptographic suite includes that group. + + The new IKE_SA has its message counters set to 0, regardless of what + they were in the earlier IKE_SA. The window size starts at 1 for any + new IKE_SA. + + KEi and KEr are required for rekeying an IKE_SA. + +1.3.3. Rekeying CHILD_SAs with the CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA request for rekeying a CHILD_SA is: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK {N, SA, Ni, [KEi], + TSi, TSr} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, optionally a Diffie-Hellman value in the KEi payload, and + the proposed traffic selectors for the proposed CHILD_SA in the TSi + and TSr payloads. When rekeying an existing CHILD_SA, the leading N + payload of type REKEY_SA MUST be included and MUST give the SPI (as + they would be expected in the headers of inbound packets) of the SAs + being rekeyed. + + The CREATE_CHILD_SA response for rekeying a CHILD_SA is: + + <-- HDR, SK {SA, Nr, [KEr], + Si, TSr} + + + + +Kaufman, et al. Expires August 27, 2006 [Page 14] + +Internet-Draft IKEv2bis February 2006 + + + The responder replies (using the same Message ID to respond) with the + accepted offer in an SA payload, and a Diffie-Hellman value in the + KEr payload if KEi was included in the request and the selected + cryptographic suite includes that group. + + The traffic selectors for traffic to be sent on that SA are specified + in the TS payloads in the response, which may be a subset of what the + initiator of the CHILD_SA proposed. + +1.4. The INFORMATIONAL Exchange + + At various points during the operation of an IKE_SA, peers may desire + to convey control messages to each other regarding errors or + notifications of certain events. To accomplish this, IKE defines an + INFORMATIONAL exchange. INFORMATIONAL exchanges MUST ONLY occur + after the initial exchanges and are cryptographically protected with + the negotiated keys. + + Control messages that pertain to an IKE_SA MUST be sent under that + IKE_SA. Control messages that pertain to CHILD_SAs MUST be sent + under the protection of the IKE_SA which generated them (or its + successor if the IKE_SA was replaced for the purpose of rekeying). + + Messages in an INFORMATIONAL exchange contain zero or more + Notification, Delete, and Configuration payloads. The Recipient of + an INFORMATIONAL exchange request MUST send some response (else the + Sender will assume the message was lost in the network and will + retransmit it). That response MAY be a message with no payloads. + The request message in an INFORMATIONAL exchange MAY also contain no + payloads. This is the expected way an endpoint can ask the other + endpoint to verify that it is alive. + + {{ Clarif-5.6 }} ESP and AH SAs always exist in pairs, with one SA in + each direction. When an SA is closed, both members of the pair MUST + be closed (that is, deleted). When SAs are nested, as when data (and + IP headers if in tunnel mode) are encapsulated first with IPComp, + then with ESP, and finally with AH between the same pair of + endpoints, all of the SAs MUST be deleted together. Each endpoint + MUST close its incoming SAs and allow the other endpoint to close the + other SA in each pair. To delete an SA, an INFORMATIONAL exchange + with one or more delete payloads is sent listing the SPIs (as they + would be expected in the headers of inbound packets) of the SAs to be + deleted. The recipient MUST close the designated SAs. {{ Clarif-5.7 + }} Note that one never sends delete payloads for the two sides of an + SA in a single message. If there are many SAs to delete at the same + time (such as for nested SAs), one includes delete payloads for in + inbound half of each SA pair in your Informational exchange. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 15] + +Internet-Draft IKEv2bis February 2006 + + + Normally, the reply in the INFORMATIONAL exchange will contain delete + payloads for the paired SAs going in the other direction. There is + one exception. If by chance both ends of a set of SAs independently + decide to close them, each may send a delete payload and the two + requests may cross in the network. If a node receives a delete + request for SAs for which it has already issued a delete request, it + MUST delete the outgoing SAs while processing the request and the + incoming SAs while processing the response. In that case, the + responses MUST NOT include delete payloads for the deleted SAs, since + that would result in duplicate deletion and could in theory delete + the wrong SA. + + {{ Demoted the SHOULD }} Half-closed connections are anomalous, and a + node with auditing capability should probably audit their existence + if they persist. Note that this specification nowhere specifies time + periods, so it is up to individual endpoints to decide how long to + wait. A node MAY refuse to accept incoming data on half-closed + connections but MUST NOT unilaterally close them and reuse the SPIs. + If connection state becomes sufficiently messed up, a node MAY close + the IKE_SA; doing so will implicitly close all SAs negotiated under + it. It can then rebuild the SAs it needs on a clean base under a new + IKE_SA. {{ Clarif-5.8 }} The response to a request that deletes the + IKE_SA is an empty Informational response. + + The INFORMATIONAL exchange is defined as: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK {[N,] [D,] + [CP,] ...} --> + <-- HDR, SK {[N,] [D,] + [CP], ...} + + The processing of an INFORMATIONAL exchange is determined by its + component payloads. + +1.5. Informational Messages outside of an IKE_SA + + If an encrypted IKE packet arrives on port 500 or 4500 with an + unrecognized SPI, it could be because the receiving node has recently + crashed and lost state or because of some other system malfunction or + attack. If the receiving node has an active IKE_SA to the IP address + from whence the packet came, it MAY send a notification of the + wayward packet over that IKE_SA in an INFORMATIONAL exchange. If it + does not have such an IKE_SA, it MAY send an Informational message + without cryptographic protection to the source IP address. Such a + message is not part of an informational exchange, and the receiving + node MUST NOT respond to it. Doing so could cause a message loop. + + + +Kaufman, et al. Expires August 27, 2006 [Page 16] + +Internet-Draft IKEv2bis February 2006 + + + {{ Clarif-7.7 }} There are two cases when such a one-way notification + is sent: INVALID_IKE_SPI and INVALID_SPI. These notifications are + sent outside of an IKE_SA. Note that such notifications are + explicitly not Informational exchanges; these are one-way messages + that must not be responded to. In case of INVALID_IKE_SPI, the + message sent is a response message, and thus it is sent to the IP + address and port from whence it came with the same IKE SPIs and the + Message ID copied. In case of INVALID_SPI, however, there are no IKE + SPI values that would be meaningful to the recipient of such a + notification. Using zero values or random values are both + acceptable. + +1.6. Requirements Terminology + + Keywords "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT" and + "MAY" that appear in this document are to be interpreted as described + in [MUSTSHOULD]. + + The term "Expert Review" is to be interpreted as defined in + [IANACONS]. + +1.7. Differences Between RFC 4306 and This Document + + {{ Added this entire section, including this recursive remark. }} + + This document contains clarifications and amplifications to IKEv2 + [IKEV2]. The clarifications are mostly based on [Clarif]. The + changes listed in that document were discussed in the IPsec Working + Group and, after the Working Group was disbanded, on the IPsec + mailing list. That document contains detailed explanations of areas + that were unclear in IKEv2, and is thus useful to implementers of + IKEv2. + + The protocol described in this document retains the same major + version number (2) and minor version number (0) as was used in RFC + 4306. + + In the body of this document, notes that are enclosed in double curly + braces {{ such as this }} point out changes from IKEv2. Changes that + come from [Clarif] are marked with the section from that document, + such as "{{ Clarif-2.10 }}". + + This document also make the figures and references a bit more regular + than in [IKEV2]. + + IKEv2 developers have noted that the SHOULD-level requirements are + often unclear in that they don't say when it is OK to not obey the + requirements. They also have noted that there are MUST-level + + + +Kaufman, et al. Expires August 27, 2006 [Page 17] + +Internet-Draft IKEv2bis February 2006 + + + requirements that are not related to interoperability. This document + has more explanation of some of these requirements. All non- + capitalized uses of the words SHOULD and MUST now mean their normal + English sense, not the interoperability sense of [MUSTSHOULD]. + + IKEv2 (and IKEv1) developers have noted that there is a great deal of + material in the tables of codes in Section 3.10. This leads to + implementers not having all the needed information in the main body + of the docment. A later version of this document may move much of + the material from those tables into the associated parts of the main + body of the document. + + A later version of this document will probably have all the {{ }} + comments removed from the body of the document and instead appear in + an appendix. + + +2. IKE Protocol Details and Variations + + IKE normally listens and sends on UDP port 500, though IKE messages + may also be received on UDP port 4500 with a slightly different + format (see Section 2.23). Since UDP is a datagram (unreliable) + protocol, IKE includes in its definition recovery from transmission + errors, including packet loss, packet replay, and packet forgery. + IKE is designed to function so long as (1) at least one of a series + of retransmitted packets reaches its destination before timing out; + and (2) the channel is not so full of forged and replayed packets so + as to exhaust the network or CPU capacities of either endpoint. Even + in the absence of those minimum performance requirements, IKE is + designed to fail cleanly (as though the network were broken). + + Although IKEv2 messages are intended to be short, they contain + structures with no hard upper bound on size (in particular, X.509 + certificates), and IKEv2 itself does not have a mechanism for + fragmenting large messages. IP defines a mechanism for fragmentation + of oversize UDP messages, but implementations vary in the maximum + message size supported. Furthermore, use of IP fragmentation opens + an implementation to denial of service attacks [DOSUDPPROT]. + Finally, some NAT and/or firewall implementations may block IP + fragments. + + All IKEv2 implementations MUST be able to send, receive, and process + IKE messages that are up to 1280 bytes long, and they SHOULD be able + to send, receive, and process messages that are up to 3000 bytes + long. {{ Demoted the SHOULD }} IKEv2 implementations need to be aware + of the maximum UDP message size supported and MAY shorten messages by + leaving out some certificates or cryptographic suite proposals if + that will keep messages below the maximum. Use of the "Hash and URL" + + + +Kaufman, et al. Expires August 27, 2006 [Page 18] + +Internet-Draft IKEv2bis February 2006 + + + formats rather than including certificates in exchanges where + possible can avoid most problems. {{ Demoted the SHOULD }} + Implementations and configuration need to keep in mind, however, that + if the URL lookups are possible only after the IPsec SA is + established, recursion issues could prevent this technique from + working. + + {{ Clarif-7.5 }} All packets sent on port 4500 MUST begin with the + prefix of four zeros; otherwise, the receiver won't know how to + handle them. + +2.1. Use of Retransmission Timers + + All messages in IKE exist in pairs: a request and a response. The + setup of an IKE_SA normally consists of two request/response pairs. + Once the IKE_SA is set up, either end of the security association may + initiate requests at any time, and there can be many requests and + responses "in flight" at any given moment. But each message is + labeled as either a request or a response, and for each request/ + response pair one end of the security association is the initiator + and the other is the responder. + + For every pair of IKE messages, the initiator is responsible for + retransmission in the event of a timeout. The responder MUST never + retransmit a response unless it receives a retransmission of the + request. In that event, the responder MUST ignore the retransmitted + request except insofar as it triggers a retransmission of the + response. The initiator MUST remember each request until it receives + the corresponding response. The responder MUST remember each + response until it receives a request whose sequence number is larger + than the sequence number in the response plus its window size (see + Section 2.3). + + IKE is a reliable protocol, in the sense that the initiator MUST + retransmit a request until either it receives a corresponding reply + OR it deems the IKE security association to have failed and it + discards all state associated with the IKE_SA and any CHILD_SAs + negotiated using that IKE_SA. + +2.2. Use of Sequence Numbers for Message ID + + Every IKE message contains a Message ID as part of its fixed header. + This Message ID is used to match up requests and responses, and to + identify retransmissions of messages. + + The Message ID is a 32-bit quantity, which is zero for the first IKE + request in each direction. {{ Clarif-3.10 }} When the IKE_AUTH + exchange does not use EAP, the IKE_SA initial setup messages will + + + +Kaufman, et al. Expires August 27, 2006 [Page 19] + +Internet-Draft IKEv2bis February 2006 + + + always be numbered 0 and 1. When EAP is used, each pair of messages + have their message numbers incremented; the first pair of AUTH + messages will have an ID of 1, the second will be 2, and so on. + + Each endpoint in the IKE Security Association maintains two "current" + Message IDs: the next one to be used for a request it initiates and + the next one it expects to see in a request from the other end. + These counters increment as requests are generated and received. + Responses always contain the same message ID as the corresponding + request. That means that after the initial exchange, each integer n + may appear as the message ID in four distinct messages: the nth + request from the original IKE initiator, the corresponding response, + the nth request from the original IKE responder, and the + corresponding response. If the two ends make very different numbers + of requests, the Message IDs in the two directions can be very + different. There is no ambiguity in the messages, however, because + the (I)nitiator and (R)esponse bits in the message header specify + which of the four messages a particular one is. + + {{ Clarif-2.2 }} The Message ID for IKE_SA_INIT messages is always + zero, including for retries of the message due to responses such as + COOKIE and INVALID_KE_PAYLOAD. + + Note that Message IDs are cryptographically protected and provide + protection against message replays. In the unlikely event that + Message IDs grow too large to fit in 32 bits, the IKE_SA MUST be + closed. Rekeying an IKE_SA resets the sequence numbers. + + {{ Clarif-2.3 }} When a responder receives an IKE_SA_INIT request, it + has to determine whether the packet is a retransmission belonging to + an existing "half-open" IKE_SA (in which case the responder + retransmits the same response), or a new request (in which case the + responder creates a new IKE_SA and sends a fresh response), or it is + a retransmission of a now-opened IKE_SA (in whcih case the responder + ignores it). It is not sufficient to use the initiator's SPI and/or + IP address to differentiate between the two cases because two + different peers behind a single NAT could choose the same initiator + SPI. Instead, a robust responder will do the IKE_SA lookup using the + whole packet, its hash, or the Ni payload. + +2.3. Window Size for Overlapping Requests + + In order to maximize IKE throughput, an IKE endpoint MAY issue + multiple requests before getting a response to any of them if the + other endpoint has indicated its ability to handle such requests. + For simplicity, an IKE implementation MAY choose to process requests + strictly in order and/or wait for a response to one request before + issuing another. Certain rules must be followed to ensure + + + +Kaufman, et al. Expires August 27, 2006 [Page 20] + +Internet-Draft IKEv2bis February 2006 + + + interoperability between implementations using different strategies. + + After an IKE_SA is set up, either end can initiate one or more + requests. These requests may pass one another over the network. An + IKE endpoint MUST be prepared to accept and process a request while + it has a request outstanding in order to avoid a deadlock in this + situation. {{ Downgraded the SHOULD }} An IKE endpoint may also + accept and process multiple requests while it has a request + outstanding. + + An IKE endpoint MUST wait for a response to each of its messages + before sending a subsequent message unless it has received a + SET_WINDOW_SIZE Notify message from its peer informing it that the + peer is prepared to maintain state for multiple outstanding messages + in order to allow greater throughput. + + An IKE endpoint MUST NOT exceed the peer's stated window size for + transmitted IKE requests. In other words, if the responder stated + its window size is N, then when the initiator needs to make a request + X, it MUST wait until it has received responses to all requests up + through request X-N. An IKE endpoint MUST keep a copy of (or be able + to regenerate exactly) each request it has sent until it receives the + corresponding response. An IKE endpoint MUST keep a copy of (or be + able to regenerate exactly) the number of previous responses equal to + its declared window size in case its response was lost and the + initiator requests its retransmission by retransmitting the request. + + An IKE endpoint supporting a window size greater than one ought to be + capable of processing incoming requests out of order to maximize + performance in the event of network failures or packet reordering. + + {{ Clarif-7.3 }} The window size is normally a (possibly + configurable) property of a particular implementation, and is not + related to congestion control (unlike the window size in TCP, for + example). In particular, it is not defined what the responder should + do when it receives a SET_WINDOW_SIZE notification containing a + smaller value than is currently in effect. Thus, there is currently + no way to reduce the window size of an existing IKE_SA; you can only + increase it. When rekeying an IKE_SA, the new IKE_SA starts with + window size 1 until it is explicitly increased by sending a new + SET_WINDOW_SIZE notification. + +2.4. State Synchronization and Connection Timeouts + + An IKE endpoint is allowed to forget all of its state associated with + an IKE_SA and the collection of corresponding CHILD_SAs at any time. + This is the anticipated behavior in the event of an endpoint crash + and restart. It is important when an endpoint either fails or + + + +Kaufman, et al. Expires August 27, 2006 [Page 21] + +Internet-Draft IKEv2bis February 2006 + + + reinitializes its state that the other endpoint detect those + conditions and not continue to waste network bandwidth by sending + packets over discarded SAs and having them fall into a black hole. + + Since IKE is designed to operate in spite of Denial of Service (DoS) + attacks from the network, an endpoint MUST NOT conclude that the + other endpoint has failed based on any routing information (e.g., + ICMP messages) or IKE messages that arrive without cryptographic + protection (e.g., Notify messages complaining about unknown SPIs). + An endpoint MUST conclude that the other endpoint has failed only + when repeated attempts to contact it have gone unanswered for a + timeout period or when a cryptographically protected INITIAL_CONTACT + notification is received on a different IKE_SA to the same + authenticated identity. {{ Demoted the SHOULD }} An endpoint should + suspect that the other endpoint has failed based on routing + information and initiate a request to see whether the other endpoint + is alive. To check whether the other side is alive, IKE specifies an + empty INFORMATIONAL message that (like all IKE requests) requires an + acknowledgement (note that within the context of an IKE_SA, an + "empty" message consists of an IKE header followed by an Encrypted + payload that contains no payloads). If a cryptographically protected + message has been received from the other side recently, unprotected + notifications MAY be ignored. Implementations MUST limit the rate at + which they take actions based on unprotected messages. + + Numbers of retries and lengths of timeouts are not covered in this + specification because they do not affect interoperability. It is + suggested that messages be retransmitted at least a dozen times over + a period of at least several minutes before giving up on an SA, but + different environments may require different rules. To be a good + network citizen, retranmission times MUST increase exponentially to + avoid flooding the network and making an existing congestion + situation worse. If there has only been outgoing traffic on all of + the SAs associated with an IKE_SA, it is essential to confirm + liveness of the other endpoint to avoid black holes. If no + cryptographically protected messages have been received on an IKE_SA + or any of its CHILD_SAs recently, the system needs to perform a + liveness check in order to prevent sending messages to a dead peer. + Receipt of a fresh cryptographically protected message on an IKE_SA + or any of its CHILD_SAs ensures liveness of the IKE_SA and all of its + CHILD_SAs. Note that this places requirements on the failure modes + of an IKE endpoint. An implementation MUST NOT continue sending on + any SA if some failure prevents it from receiving on all of the + associated SAs. If CHILD_SAs can fail independently from one another + without the associated IKE_SA being able to send a delete message, + then they MUST be negotiated by separate IKE_SAs. + + There is a Denial of Service attack on the initiator of an IKE_SA + + + +Kaufman, et al. Expires August 27, 2006 [Page 22] + +Internet-Draft IKEv2bis February 2006 + + + that can be avoided if the initiator takes the proper care. Since + the first two messages of an SA setup are not cryptographically + protected, an attacker could respond to the initiator's message + before the genuine responder and poison the connection setup attempt. + To prevent this, the initiator MAY be willing to accept multiple + responses to its first message, treat each as potentially legitimate, + respond to it, and then discard all the invalid half-open connections + when it receives a valid cryptographically protected response to any + one of its requests. Once a cryptographically valid response is + received, all subsequent responses should be ignored whether or not + they are cryptographically valid. + + Note that with these rules, there is no reason to negotiate and agree + upon an SA lifetime. If IKE presumes the partner is dead, based on + repeated lack of acknowledgement to an IKE message, then the IKE SA + and all CHILD_SAs set up through that IKE_SA are deleted. + + An IKE endpoint may at any time delete inactive CHILD_SAs to recover + resources used to hold their state. If an IKE endpoint chooses to + delete CHILD_SAs, it MUST send Delete payloads to the other end + notifying it of the deletion. It MAY similarly time out the IKE_SA. + {{ Clarified the SHOULD }} Closing the IKE_SA implicitly closes all + associated CHILD_SAs. In this case, an IKE endpoint SHOULD send a + Delete payload indicating that it has closed the IKE_SA unless the + other endpoint is no longer responding. + +2.5. Version Numbers and Forward Compatibility + + This document describes version 2.0 of IKE, meaning the major version + number is 2 and the minor version number is 0. {{ Restated the + relationship to RFC 4306 }} This document is a clarification of + [IKEV2]. It is likely that some implementations will want to support + version 1.0 and version 2.0, and in the future, other versions. + + The major version number should be incremented only if the packet + formats or required actions have changed so dramatically that an + older version node would not be able to interoperate with a newer + version node if it simply ignored the fields it did not understand + and took the actions specified in the older specification. The minor + version number indicates new capabilities, and MUST be ignored by a + node with a smaller minor version number, but used for informational + purposes by the node with the larger minor version number. For + example, it might indicate the ability to process a newly defined + notification message. The node with the larger minor version number + would simply note that its correspondent would not be able to + understand that message and therefore would not send it. + + If an endpoint receives a message with a higher major version number, + + + +Kaufman, et al. Expires August 27, 2006 [Page 23] + +Internet-Draft IKEv2bis February 2006 + + + it MUST drop the message and SHOULD send an unauthenticated + notification message containing the highest version number it + supports. If an endpoint supports major version n, and major version + m, it MUST support all versions between n and m. If it receives a + message with a major version that it supports, it MUST respond with + that version number. In order to prevent two nodes from being + tricked into corresponding with a lower major version number than the + maximum that they both support, IKE has a flag that indicates that + the node is capable of speaking a higher major version number. + + Thus, the major version number in the IKE header indicates the + version number of the message, not the highest version number that + the transmitter supports. If the initiator is capable of speaking + versions n, n+1, and n+2, and the responder is capable of speaking + versions n and n+1, then they will negotiate speaking n+1, where the + initiator will set the flag indicating its ability to speak a higher + version. If they mistakenly (perhaps through an active attacker + sending error messages) negotiate to version n, then both will notice + that the other side can support a higher version number, and they + MUST break the connection and reconnect using version n+1. + + Note that IKEv1 does not follow these rules, because there is no way + in v1 of noting that you are capable of speaking a higher version + number. So an active attacker can trick two v2-capable nodes into + speaking v1. {{ Demoted the SHOULD }} When a v2-capable node + negotiates down to v1, it should note that fact in its logs. + + Also for forward compatibility, all fields marked RESERVED MUST be + set to zero by an implementation running version 2.0 or later, and + their content MUST be ignored by an implementation running version + 2.0 or later ("Be conservative in what you send and liberal in what + you receive"). In this way, future versions of the protocol can use + those fields in a way that is guaranteed to be ignored by + implementations that do not understand them. Similarly, payload + types that are not defined are reserved for future use; + implementations of a version where they are undefined MUST skip over + those payloads and ignore their contents. + + IKEv2 adds a "critical" flag to each payload header for further + flexibility for forward compatibility. If the critical flag is set + and the payload type is unrecognized, the message MUST be rejected + and the response to the IKE request containing that payload MUST + include a Notify payload UNSUPPORTED_CRITICAL_PAYLOAD, indicating an + unsupported critical payload was included. If the critical flag is + not set and the payload type is unsupported, that payload MUST be + ignored. + + {{ Demoted the SHOULD in the second clause }}Although new payload + + + +Kaufman, et al. Expires August 27, 2006 [Page 24] + +Internet-Draft IKEv2bis February 2006 + + + types may be added in the future and may appear interleaved with the + fields defined in this specification, implementations MUST send the + payloads defined in this specification in the order shown in the + figures in Section 2; implementations are explicitly allowed to + reject as invalid a message with those payloads in any other order. + +2.6. Cookies + + The term "cookies" originates with Karn and Simpson [PHOTURIS] in + Photuris, an early proposal for key management with IPsec, and it has + persisted. The Internet Security Association and Key Management + Protocol (ISAKMP) [ISAKMP] fixed message header includes two eight- + octet fields titled "cookies", and that syntax is used by both IKEv1 + and IKEv2 though in IKEv2 they are referred to as the IKE SPI and + there is a new separate field in a Notify payload holding the cookie. + The initial two eight-octet fields in the header are used as a + connection identifier at the beginning of IKE packets. {{ Demoted the + SHOULD }} Each endpoint chooses one of the two SPIs and needs to + choose them so as to be unique identifiers of an IKE_SA. An SPI + value of zero is special and indicates that the remote SPI value is + not yet known by the sender. + + Unlike ESP and AH where only the recipient's SPI appears in the + header of a message, in IKE the sender's SPI is also sent in every + message. Since the SPI chosen by the original initiator of the + IKE_SA is always sent first, an endpoint with multiple IKE_SAs open + that wants to find the appropriate IKE_SA using the SPI it assigned + must look at the I(nitiator) Flag bit in the header to determine + whether it assigned the first or the second eight octets. + + In the first message of an initial IKE exchange, the initiator will + not know the responder's SPI value and will therefore set that field + to zero. + + An expected attack against IKE is state and CPU exhaustion, where the + target is flooded with session initiation requests from forged IP + addresses. This attack can be made less effective if an + implementation of a responder uses minimal CPU and commits no state + to an SA until it knows the initiator can receive packets at the + address from which it claims to be sending them. To accomplish this, + a responder SHOULD -- when it detects a large number of half-open + IKE_SAs -- reject initial IKE messages unless they contain a Notify + payload of type COOKIE. {{ Clarified the SHOULD }} If the responder + wants to set up an SA, it SHOULD instead send an unprotected IKE + message as a response and include COOKIE Notify payload with the + cookie data to be returned. Initiators who receive such responses + MUST retry the IKE_SA_INIT with a Notify payload of type COOKIE + containing the responder supplied cookie data as the first payload + + + +Kaufman, et al. Expires August 27, 2006 [Page 25] + +Internet-Draft IKEv2bis February 2006 + + + and all other payloads unchanged. The initial exchange will then be + as follows: + + Initiator Responder + ------------------------------------------------------------------- + HDR(A,0), SAi1, KEi, Ni --> + <-- HDR(A,0), N(COOKIE) + HDR(A,0), N(COOKIE), SAi1, + KEi, Ni --> + <-- HDR(A,B), SAr1, KEr, + Nr, [CERTREQ] + HDR(A,B), SK {IDi, [CERT,] + [CERTREQ,] [IDr,] AUTH, + SAi2, TSi, TSr} --> + <-- HDR(A,B), SK {IDr, [CERT,] + AUTH, SAr2, TSi, TSr} + + The first two messages do not affect any initiator or responder state + except for communicating the cookie. In particular, the message + sequence numbers in the first four messages will all be zero and the + message sequence numbers in the last two messages will be one. 'A' + is the SPI assigned by the initiator, while 'B' is the SPI assigned + by the responder. + + {{ Clarif-2.1 }} Because the responder's SPI identifies security- + related state held by the responder, and in this case no state is + created, the responder sends a zero value for the responder's SPI. + + {{ Demoted the SHOULD }} An IKE implementation should implement its + responder cookie generation in such a way as to not require any saved + state to recognize its valid cookie when the second IKE_SA_INIT + message arrives. The exact algorithms and syntax they use to + generate cookies do not affect interoperability and hence are not + specified here. The following is an example of how an endpoint could + use cookies to implement limited DOS protection. + + A good way to do this is to set the responder cookie to be: + + Cookie = | Hash(Ni | IPi | SPIi | ) + + where is a randomly generated secret known only to the + responder and periodically changed and | indicates concatenation. + should be changed whenever is + regenerated. The cookie can be recomputed when the IKE_SA_INIT + arrives the second time and compared to the cookie in the received + message. If it matches, the responder knows that the cookie was + generated since the last change to and that IPi must be the + same as the source address it saw the first time. Incorporating SPIi + + + +Kaufman, et al. Expires August 27, 2006 [Page 26] + +Internet-Draft IKEv2bis February 2006 + + + into the calculation ensures that if multiple IKE_SAs are being set + up in parallel they will all get different cookies (assuming the + initiator chooses unique SPIi's). Incorporating Ni into the hash + ensures that an attacker who sees only message 2 can't successfully + forge a message 3. + + If a new value for is chosen while there are connections in + the process of being initialized, an IKE_SA_INIT might be returned + with other than the current . The responder in + that case MAY reject the message by sending another response with a + new cookie or it MAY keep the old value of around for a + short time and accept cookies computed from either one. {{ Demoted + the SHOULD NOT }} The responder should not accept cookies + indefinitely after is changed, since that would defeat part + of the denial of service protection. {{ Demoted the SHOULD }} The + responder should change the value of frequently, especially + if under attack. + + {{ Clarif-2.1 }} In addition to cookies, there are several cases + where the IKE_SA_INIT exchange does not result in the creation of an + IKE_SA (such as INVALID_KE_PAYLOAD or NO_PROPOSAL_CHOSEN). In such a + case, sending a zero value for the Responder's SPI is correct. If + the responder sends a non-zero responder SPI, the initiator should + not reject the response for only that reason. + + {{ Clarif-2.5 }} When one party receives an IKE_SA_INIT request + containing a cookie whose contents do not match the value expected, + that party MUST ignore the cookie and process the message as if no + cookie had been included; usually this means sending a response + containing a new cookie. + +2.6.1. Interaction of COOKIE and INVALID_KE_PAYLOAD + + {{ This section added by Clarif-2.4 }} + + There are two common reasons why the initiator may have to retry the + IKE_SA_INIT exchange: the responder requests a cookie or wants a + different Diffie-Hellman group than was included in the KEi payload. + If the initiator receives a cookie from the responder, the initiator + needs to decide whether or not to include the cookie in only the next + retry of the IKE_SA_INIT request, or in all subsequent retries as + well. + + If the initiator includes the cookie only in the next retry, one + additional roundtrip may be needed in some cases. An additional + roundtrip is needed also if the initiator includes the cookie in all + retries, but the responder does not support this. For instance, if + the responder includes the SAi1 and KEi payloads in cookie + + + +Kaufman, et al. Expires August 27, 2006 [Page 27] + +Internet-Draft IKEv2bis February 2006 + + + calculation, it will reject the request by sending a new cookie. + + If both peers support including the cookie in all retries, a slightly + shorter exchange can happen. Implementations SHOULD support this + shorter exchange, but MUST NOT fail if other implementations do not + support this shorter exchange. + +2.7. Cryptographic Algorithm Negotiation + + The payload type known as "SA" indicates a proposal for a set of + choices of IPsec protocols (IKE, ESP, and/or AH) for the SA as well + as cryptographic algorithms associated with each protocol. + + An SA payload consists of one or more proposals. Each proposal + includes one or more protocols (usually one). Each protocol contains + one or more transforms -- each specifying a cryptographic algorithm. + Each transform contains zero or more attributes (attributes are + needed only if the transform identifier does not completely specify + the cryptographic algorithm). + + This hierarchical structure was designed to efficiently encode + proposals for cryptographic suites when the number of supported + suites is large because multiple values are acceptable for multiple + transforms. The responder MUST choose a single suite, which MAY be + any subset of the SA proposal following the rules below: + + Each proposal contains one or more protocols. If a proposal is + accepted, the SA response MUST contain the same protocols in the same + order as the proposal. The responder MUST accept a single proposal + or reject them all and return an error. (Example: if a single + proposal contains ESP and AH and that proposal is accepted, both ESP + and AH MUST be accepted. If ESP and AH are included in separate + proposals, the responder MUST accept only one of them). + + Each IPsec protocol proposal contains one or more transforms. Each + transform contains a transform type. The accepted cryptographic + suite MUST contain exactly one transform of each type included in the + proposal. For example: if an ESP proposal includes transforms + ENCR_3DES, ENCR_AES w/keysize 128, ENCR_AES w/keysize 256, + AUTH_HMAC_MD5, and AUTH_HMAC_SHA, the accepted suite MUST contain one + of the ENCR_ transforms and one of the AUTH_ transforms. Thus, six + combinations are acceptable. + + Since the initiator sends its Diffie-Hellman value in the + IKE_SA_INIT, it must guess the Diffie-Hellman group that the + responder will select from its list of supported groups. If the + initiator guesses wrong, the responder will respond with a Notify + payload of type INVALID_KE_PAYLOAD indicating the selected group. In + + + +Kaufman, et al. Expires August 27, 2006 [Page 28] + +Internet-Draft IKEv2bis February 2006 + + + this case, the initiator MUST retry the IKE_SA_INIT with the + corrected Diffie-Hellman group. The initiator MUST again propose its + full set of acceptable cryptographic suites because the rejection + message was unauthenticated and otherwise an active attacker could + trick the endpoints into negotiating a weaker suite than a stronger + one that they both prefer. + +2.8. Rekeying + + {{ Demoted the SHOULD }} IKE, ESP, and AH security associations use + secret keys that should be used only for a limited amount of time and + to protect a limited amount of data. This limits the lifetime of the + entire security association. When the lifetime of a security + association expires, the security association MUST NOT be used. If + there is demand, new security associations MAY be established. + Reestablishment of security associations to take the place of ones + that expire is referred to as "rekeying". + + To allow for minimal IPsec implementations, the ability to rekey SAs + without restarting the entire IKE_SA is optional. An implementation + MAY refuse all CREATE_CHILD_SA requests within an IKE_SA. If an SA + has expired or is about to expire and rekeying attempts using the + mechanisms described here fail, an implementation MUST close the + IKE_SA and any associated CHILD_SAs and then MAY start new ones. {{ + Demoted the SHOULD }} Implementations may wish to support in-place + rekeying of SAs, since doing so offers better performance and is + likely to reduce the number of packets lost during the transition. + + To rekey a CHILD_SA within an existing IKE_SA, create a new, + equivalent SA (see Section 2.17 below), and when the new one is + established, delete the old one. To rekey an IKE_SA, establish a new + equivalent IKE_SA (see Section 2.18 below) with the peer to whom the + old IKE_SA is shared using a CREATE_CHILD_SA within the existing + IKE_SA. An IKE_SA so created inherits all of the original IKE_SA's + CHILD_SAs. Use the new IKE_SA for all control messages needed to + maintain the CHILD_SAs created by the old IKE_SA, and delete the old + IKE_SA. The Delete payload to delete itself MUST be the last request + sent over an IKE_SA. + + {{ Demoted the SHOULD }} SAs should be rekeyed proactively, i.e., the + new SA should be established before the old one expires and becomes + unusable. Enough time should elapse between the time the new SA is + established and the old one becomes unusable so that traffic can be + switched over to the new SA. + + A difference between IKEv1 and IKEv2 is that in IKEv1 SA lifetimes + were negotiated. In IKEv2, each end of the SA is responsible for + enforcing its own lifetime policy on the SA and rekeying the SA when + + + +Kaufman, et al. Expires August 27, 2006 [Page 29] + +Internet-Draft IKEv2bis February 2006 + + + necessary. If the two ends have different lifetime policies, the end + with the shorter lifetime will end up always being the one to request + the rekeying. If an SA bundle has been inactive for a long time and + if an endpoint would not initiate the SA in the absence of traffic, + the endpoint MAY choose to close the SA instead of rekeying it when + its lifetime expires. {{ Demoted the SHOULD }} It should do so if + there has been no traffic since the last time the SA was rekeyed. + + Note that IKEv2 deliberately allows parallel SAs with the same + traffic selectors between common endpoints. One of the purposes of + this is to support traffic quality of service (QoS) differences among + the SAs (see [DIFFSERVFIELD], [DIFFSERVARCH], and section 4.1 of + [DIFFTUNNEL]). Hence unlike IKEv1, the combination of the endpoints + and the traffic selectors may not uniquely identify an SA between + those endpoints, so the IKEv1 rekeying heuristic of deleting SAs on + the basis of duplicate traffic selectors SHOULD NOT be used. + + {{ Demoted the SHOULD }} The node that initiated the surviving + rekeyed SA should delete the replaced SA after the new one is + established. + + There are timing windows -- particularly in the presence of lost + packets -- where endpoints may not agree on the state of an SA. The + responder to a CREATE_CHILD_SA MUST be prepared to accept messages on + an SA before sending its response to the creation request, so there + is no ambiguity for the initiator. The initiator MAY begin sending + on an SA as soon as it processes the response. The initiator, + however, cannot receive on a newly created SA until it receives and + processes the response to its CREATE_CHILD_SA request. How, then, is + the responder to know when it is OK to send on the newly created SA? + + From a technical correctness and interoperability perspective, the + responder MAY begin sending on an SA as soon as it sends its response + to the CREATE_CHILD_SA request. In some situations, however, this + could result in packets unnecessarily being dropped, so an + implementation MAY want to defer such sending. + + The responder can be assured that the initiator is prepared to + receive messages on an SA if either (1) it has received a + cryptographically valid message on the new SA, or (2) the new SA + rekeys an existing SA and it receives an IKE request to close the + replaced SA. When rekeying an SA, the responder continues to send + traffic on the old SA until one of those events occurs. When + establishing a new SA, the responder MAY defer sending messages on a + new SA until either it receives one or a timeout has occurred. {{ + Demoted the SHOULD }} If an initiator receives a message on an SA for + which it has not received a response to its CREATE_CHILD_SA request, + it interprets that as a likely packet loss and retransmits the + + + +Kaufman, et al. Expires August 27, 2006 [Page 30] + +Internet-Draft IKEv2bis February 2006 + + + CREATE_CHILD_SA request. An initiator MAY send a dummy message on a + newly created SA if it has no messages queued in order to assure the + responder that the initiator is ready to receive messages. + + {{ Clarif-5.9 }} Throughout this document, "initiator" refers to the + party who initiated the exchange being described, and "original + initiator" refers to the party who initiated the whole IKE_SA. The + "original initiator" always refers to the party who initiated the + exchange which resulted in the current IKE_SA. In other words, if + the the "original responder" starts rekeying the IKE_SA, that party + becomes the "original initiator" of the new IKE_SA. + +2.8.1. Simultaneous CHILD_SA rekeying + + {{ The first two paragraphs were moved, and the rest was added, based + on Clarif-5.11 }} + + If the two ends have the same lifetime policies, it is possible that + both will initiate a rekeying at the same time (which will result in + redundant SAs). To reduce the probability of this happening, the + timing of rekeying requests SHOULD be jittered (delayed by a random + amount of time after the need for rekeying is noticed). + + This form of rekeying may temporarily result in multiple similar SAs + between the same pairs of nodes. When there are two SAs eligible to + receive packets, a node MUST accept incoming packets through either + SA. If redundant SAs are created though such a collision, the SA + created with the lowest of the four nonces used in the two exchanges + SHOULD be closed by the endpoint that created it. {{ Clarif-5.10 }} + "Lowest" means an octet-by-octet, lexicographical comparison (instead + of, for instance, comparing the nonces as large integers). In other + words, start by comparing the first octet; if they're equal, move to + the next octet, and so on. If you reach the end of one nonce, that + nonce is the lower one. + + The following is an explanation on the impact this has on + implementations. Assume that hosts A and B have an existing IPsec SA + pair with SPIs (SPIa1,SPIb1), and both start rekeying it at the same + time: + + Host A Host B + ------------------------------------------------------------------- + send req1: N(REKEY_SA,SPIa1), + SA(..,SPIa2,..),Ni1,.. --> + <-- send req2: N(REKEY_SA,SPIb1), + SA(..,SPIb2,..),Ni2 + recv req2 <-- + + + + +Kaufman, et al. Expires August 27, 2006 [Page 31] + +Internet-Draft IKEv2bis February 2006 + + + At this point, A knows there is a simultaneous rekeying going on. + However, it cannot yet know which of the exchanges will have the + lowest nonce, so it will just note the situation and respond as + usual. + + send resp2: SA(..,SPIa3,..), + Nr1,.. --> + --> recv req1 + + Now B also knows that simultaneous rekeying is going on. It responds + as usual. + + <-- send resp1: SA(..,SPIb3,..), + Nr2,.. + recv resp1 <-- + --> recv resp2 + + At this point, there are three CHILD_SA pairs between A and B (the + old one and two new ones). A and B can now compare the nonces. + Suppose that the lowest nonce was Nr1 in message resp2; in this case, + B (the sender of req2) deletes the redundant new SA, and A (the node + that initiated the surviving rekeyed SA), deletes the old one. + + send req3: D(SPIa1) --> + <-- send req4: D(SPIb2) + --> recv req3 + <-- send resp4: D(SPIb1) + recv req4 <-- + send resp4: D(SPIa3) --> + + The rekeying is now finished. + + However, there is a second possible sequence of events that can + happen if some packets are lost in the network, resulting in + retransmissions. The rekeying begins as usual, but A's first packet + (req1) is lost. + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 32] + +Internet-Draft IKEv2bis February 2006 + + + Host A Host B + ------------------------------------------------------------------- + send req1: N(REKEY_SA,SPIa1), + SA(..,SPIa2,..), + Ni1,.. --> (lost) + <-- send req2: N(REKEY_SA,SPIb1), + SA(..,SPIb2,..),Ni2 + recv req2 <-- + send resp2: SA(..,SPIa3,..), + Nr1,.. --> + --> recv resp2 + <-- send req3: D(SPIb1) + recv req3 <-- + send resp3: D(SPIa1) --> + --> recv resp3 + + From B's point of view, the rekeying is now completed, and since it + has not yet received A's req1, it does not even know that there was + simultaneous rekeying. However, A will continue retransmitting the + message, and eventually it will reach B. + + resend req1 --> + --> recv req1 + + To B, it looks like A is trying to rekey an SA that no longer exists; + thus, B responds to the request with something non-fatal such as + NO_PROPOSAL_CHOSEN. + + <-- send resp1: N(NO_PROPOSAL_CHOSEN) + recv resp1 <-- + + When A receives this error, it already knows there was simultaneous + rekeying, so it can ignore the error message. + +2.8.2. Rekeying the IKE_SA Versus Reauthentication + + {{ Added this section from Clarif-5.2 }} + + Rekeying the IKE_SA and reauthentication are different concepts in + IKEv2. Rekeying the IKE_SA establishes new keys for the IKE_SA and + resets the Message ID counters, but it does not authenticate the + parties again (no AUTH or EAP payloads are involved). + + Although rekeying the IKE_SA may be important in some environments, + reauthentication (the verification that the parties still have access + to the long-term credentials) is often more important. + + IKEv2 does not have any special support for reauthentication. + + + +Kaufman, et al. Expires August 27, 2006 [Page 33] + +Internet-Draft IKEv2bis February 2006 + + + Reauthentication is done by creating a new IKE_SA from scratch (using + IKE_SA_INIT/IKE_AUTH exchanges, without any REKEY_SA notify + payloads), creating new CHILD_SAs within the new IKE_SA (without + REKEY_SA notify payloads), and finally deleting the old IKE_SA (which + deletes the old CHILD_SAs as well). + + This means that reauthentication also establishes new keys for the + IKE_SA and CHILD_SAs. Therefore, while rekeying can be performed + more often than reauthentication, the situation where "authentication + lifetime" is shorter than "key lifetime" does not make sense. + + While creation of a new IKE_SA can be initiated by either party + (initiator or responder in the original IKE_SA), the use of EAP + authentication and/or configuration payloads means in practice that + reauthentication has to be initiated by the same party as the + original IKE_SA. IKEv2 does not currently allow the responder to + request reauthentication in this case; however, there is ongoing work + to add this functionality [REAUTH]. + +2.9. Traffic Selector Negotiation + + {{ Clarif-7.2 }} When an RFC4301-compliant IPsec subsystem receives + an IP packet and matches a "protect" selector in its Security Policy + Database (SPD), the subsystem protects that packet with IPsec. When + no SA exists yet, it is the task of IKE to create it. Maintenance of + a system's SPD is outside the scope of IKE (see [PFKEY] for an + example protocol), though some implementations might update their SPD + in connection with the running of IKE (for an example scenario, see + Section 1.1.3). + + Traffic Selector (TS) payloads allow endpoints to communicate some of + the information from their SPD to their peers. TS payloads specify + the selection criteria for packets that will be forwarded over the + newly set up SA. This can serve as a consistency check in some + scenarios to assure that the SPDs are consistent. In others, it + guides the dynamic update of the SPD. + + Two TS payloads appear in each of the messages in the exchange that + creates a CHILD_SA pair. Each TS payload contains one or more + Traffic Selectors. Each Traffic Selector consists of an address + range (IPv4 or IPv6), a port range, and an IP protocol ID. In + support of the scenario described in Section 1.1.3, an initiator may + request that the responder assign an IP address and tell the + initiator what it is. {{ Clarif-6.1 }} That request is done using + configuration payloads, not traffic selectors. An address in a TSi + payload in a response does not mean that the responder has assigned + that address to the initiator: it only means that if packets matching + these traffic selectors are sent by the initiator, IPsec processing + + + +Kaufman, et al. Expires August 27, 2006 [Page 34] + +Internet-Draft IKEv2bis February 2006 + + + can be performed as agreed for this SA. + + IKEv2 allows the responder to choose a subset of the traffic proposed + by the initiator. This could happen when the configurations of the + two endpoints are being updated but only one end has received the new + information. Since the two endpoints may be configured by different + people, the incompatibility may persist for an extended period even + in the absence of errors. It also allows for intentionally different + configurations, as when one end is configured to tunnel all addresses + and depends on the other end to have the up-to-date list. + + The first of the two TS payloads is known as TSi (Traffic Selector- + initiator). The second is known as TSr (Traffic Selector-responder). + TSi specifies the source address of traffic forwarded from (or the + destination address of traffic forwarded to) the initiator of the + CHILD_SA pair. TSr specifies the destination address of the traffic + forwarded to (or the source address of the traffic forwarded from) + the responder of the CHILD_SA pair. For example, if the original + initiator request the creation of a CHILD_SA pair, and wishes to + tunnel all traffic from subnet 192.0.1.* on the initiator's side to + subnet 192.0.2.* on the responder's side, the initiator would include + a single traffic selector in each TS payload. TSi would specify the + address range (192.0.1.0 - 192.0.1.255) and TSr would specify the + address range (192.0.2.0 - 192.0.2.255). Assuming that proposal was + acceptable to the responder, it would send identical TS payloads + back. (Note: The IP address range 192.0.2.* has been reserved for + use in examples in RFCs and similar documents. This document needed + two such ranges, and so also used 192.0.1.*. This should not be + confused with any actual address.) + + The responder is allowed to narrow the choices by selecting a subset + of the traffic, for instance by eliminating or narrowing the range of + one or more members of the set of traffic selectors, provided the set + does not become the NULL set. + + It is possible for the responder's policy to contain multiple smaller + ranges, all encompassed by the initiator's traffic selector, and with + the responder's policy being that each of those ranges should be sent + over a different SA. Continuing the example above, the responder + might have a policy of being willing to tunnel those addresses to and + from the initiator, but might require that each address pair be on a + separately negotiated CHILD_SA. If the initiator generated its + request in response to an incoming packet from 192.0.1.43 to + 192.0.2.123, there would be no way for the responder to determine + which pair of addresses should be included in this tunnel, and it + would have to make a guess or reject the request with a status of + SINGLE_PAIR_REQUIRED. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 35] + +Internet-Draft IKEv2bis February 2006 + + + {{ Clarif-4.11 }} Few implementations will have policies that require + separate SAs for each address pair. Because of this, if only some + part (or parts) of the TSi/TSr proposed by the initiator is (are) + acceptable to the responder, responders SHOULD narrow TSi/TSr to an + acceptable subset rather than use SINGLE_PAIR_REQUIRED. + + To enable the responder to choose the appropriate range in this case, + if the initiator has requested the SA due to a data packet, the + initiator SHOULD include as the first traffic selector in each of TSi + and TSr a very specific traffic selector including the addresses in + the packet triggering the request. In the example, the initiator + would include in TSi two traffic selectors: the first containing the + address range (192.0.1.43 - 192.0.1.43) and the source port and IP + protocol from the packet and the second containing (192.0.1.0 - + 192.0.1.255) with all ports and IP protocols. The initiator would + similarly include two traffic selectors in TSr. + + If the responder's policy does not allow it to accept the entire set + of traffic selectors in the initiator's request, but does allow him + to accept the first selector of TSi and TSr, then the responder MUST + narrow the traffic selectors to a subset that includes the + initiator's first choices. In this example, the responder might + respond with TSi being (192.0.1.43 - 192.0.1.43) with all ports and + IP protocols. + + If the initiator creates the CHILD_SA pair not in response to an + arriving packet, but rather, say, upon startup, then there may be no + specific addresses the initiator prefers for the initial tunnel over + any other. In that case, the first values in TSi and TSr MAY be + ranges rather than specific values, and the responder chooses a + subset of the initiator's TSi and TSr that are acceptable. If more + than one subset is acceptable but their union is not, the responder + MUST accept some subset and MAY include a Notify payload of type + ADDITIONAL_TS_POSSIBLE to indicate that the initiator might want to + try again. This case will occur only when the initiator and + responder are configured differently from one another. If the + initiator and responder agree on the granularity of tunnels, the + initiator will never request a tunnel wider than the responder will + accept. {{ Demoted the SHOULD }} Such misconfigurations should be + recorded in error logs. + + {{ Clarif-4.10 }} A concise summary of the narrowing process is: + + o If the responder's policy does not allow any part of the traffic + covered by TSi/TSr, it responds with TS_UNACCEPTABLE. + + o If the responder's policy allows the entire set of traffic covered + by TSi/TSr, no narrowing is necessary, and the responder can + + + +Kaufman, et al. Expires August 27, 2006 [Page 36] + +Internet-Draft IKEv2bis February 2006 + + + return the same TSi/TSr values. + + o Otherwise, narrowing is needed. If the responder's policy allows + all traffic covered by TSi[1]/TSr[1] (the first traffic selectors + in TSi/TSr) but not entire TSi/TSr, the responder narrows to an + acceptable subset of TSi/TSr that includes TSi[1]/TSr[1]. + + o If the responder's policy does not allow all traffic covered by + TSi[1]/TSr[1], but does allow some parts of TSi/TSr, it narrows to + an acceptable subset of TSi/TSr. + + In the last two cases, there may be several subsets that are + acceptable (but their union is not); in this case, the responder + arbitrarily chooses one of them, and includes ADDITIONAL_TS_POSSIBLE + notification in the response. + +2.9.1. Traffic Selectors Violating Own Policy + + {{ Clarif-4.12 }} + + When creating a new SA, the initiator needs to avoid proposing + traffic selectors that violate its own policy. If this rule is not + followed, valid traffic may be dropped. + + This is best illustrated by an example. Suppose that host A has a + policy whose effect is that traffic to 192.0.1.66 is sent via host B + encrypted using AES, and traffic to all other hosts in 192.0.1.0/24 + is also sent via B, but must use 3DES. Suppose also that host B + accepts any combination of AES and 3DES. + + If host A now proposes an SA that uses 3DES, and includes TSr + containing (192.0.1.0-192.0.1.0.255), this will be accepted by host + B. Now, host B can also use this SA to send traffic from 192.0.1.66, + but those packets will be dropped by A since it requires the use of + AES for those traffic. Even if host A creates a new SA only for + 192.0.1.66 that uses AES, host B may freely continue to use the first + SA for the traffic. In this situation, when proposing the SA, host A + should have followed its own policy, and included a TSr containing + ((192.0.1.0-192.0.1.65),(192.0.1.67-192.0.1.255)) instead. + + In general, if (1) the initiator makes a proposal "for traffic X + (TSi/TSr), do SA", and (2) for some subset X' of X, the initiator + does not actually accept traffic X' with SA, and (3) the initiator + would be willing to accept traffic X' with some SA' (!=SA), valid + traffic can be unnecessarily dropped since the responder can apply + either SA or SA' to traffic X'. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 37] + +Internet-Draft IKEv2bis February 2006 + + +2.10. Nonces + + The IKE_SA_INIT messages each contain a nonce. These nonces are used + as inputs to cryptographic functions. The CREATE_CHILD_SA request + and the CREATE_CHILD_SA response also contain nonces. These nonces + are used to add freshness to the key derivation technique used to + obtain keys for CHILD_SA, and to ensure creation of strong pseudo- + random bits from the Diffie-Hellman key. Nonces used in IKEv2 MUST + be randomly chosen, MUST be at least 128 bits in size, and MUST be at + least half the key size of the negotiated prf. ("prf" refers to + "pseudo-random function", one of the cryptographic algorithms + negotiated in the IKE exchange.) {{ Clarif-7.4 }} However, the + initiator chooses the nonce before the outcome of the negotiation is + known. Because of that, the nonce has to be long enough for all the + PRFs being proposed. If the same random number source is used for + both keys and nonces, care must be taken to ensure that the latter + use does not compromise the former. + +2.11. Address and Port Agility + + IKE runs over UDP ports 500 and 4500, and implicitly sets up ESP and + AH associations for the same IP addresses it runs over. The IP + addresses and ports in the outer header are, however, not themselves + cryptographically protected, and IKE is designed to work even through + Network Address Translation (NAT) boxes. An implementation MUST + accept incoming requests even if the source port is not 500 or 4500, + and MUST respond to the address and port from which the request was + received. It MUST specify the address and port at which the request + was received as the source address and port in the response. IKE + functions identically over IPv4 or IPv6. + +2.12. Reuse of Diffie-Hellman Exponentials + + IKE generates keying material using an ephemeral Diffie-Hellman + exchange in order to gain the property of "perfect forward secrecy". + This means that once a connection is closed and its corresponding + keys are forgotten, even someone who has recorded all of the data + from the connection and gets access to all of the long-term keys of + the two endpoints cannot reconstruct the keys used to protect the + conversation without doing a brute force search of the session key + space. + + Achieving perfect forward secrecy requires that when a connection is + closed, each endpoint MUST forget not only the keys used by the + connection but also any information that could be used to recompute + those keys. In particular, it MUST forget the secrets used in the + Diffie-Hellman calculation and any state that may persist in the + state of a pseudo-random number generator that could be used to + + + +Kaufman, et al. Expires August 27, 2006 [Page 38] + +Internet-Draft IKEv2bis February 2006 + + + recompute the Diffie-Hellman secrets. + + Since the computing of Diffie-Hellman exponentials is computationally + expensive, an endpoint may find it advantageous to reuse those + exponentials for multiple connection setups. There are several + reasonable strategies for doing this. An endpoint could choose a new + exponential only periodically though this could result in less-than- + perfect forward secrecy if some connection lasts for less than the + lifetime of the exponential. Or it could keep track of which + exponential was used for each connection and delete the information + associated with the exponential only when some corresponding + connection was closed. This would allow the exponential to be reused + without losing perfect forward secrecy at the cost of maintaining + more state. + + Decisions as to whether and when to reuse Diffie-Hellman exponentials + is a private decision in the sense that it will not affect + interoperability. An implementation that reuses exponentials MAY + choose to remember the exponential used by the other endpoint on past + exchanges and if one is reused to avoid the second half of the + calculation. + +2.13. Generating Keying Material + + In the context of the IKE_SA, four cryptographic algorithms are + negotiated: an encryption algorithm, an integrity protection + algorithm, a Diffie-Hellman group, and a pseudo-random function + (prf). The pseudo-random function is used for the construction of + keying material for all of the cryptographic algorithms used in both + the IKE_SA and the CHILD_SAs. + + We assume that each encryption algorithm and integrity protection + algorithm uses a fixed-size key and that any randomly chosen value of + that fixed size can serve as an appropriate key. For algorithms that + accept a variable length key, a fixed key size MUST be specified as + part of the cryptographic transform negotiated. For algorithms for + which not all values are valid keys (such as DES or 3DES with key + parity), the algorithm by which keys are derived from arbitrary + values MUST be specified by the cryptographic transform. For + integrity protection functions based on Hashed Message Authentication + Code (HMAC), the fixed key size is the size of the output of the + underlying hash function. When the prf function takes a variable + length key, variable length data, and produces a fixed-length output + (e.g., when using HMAC), the formulas in this document apply. When + the key for the prf function has fixed length, the data provided as a + key is truncated or padded with zeros as necessary unless exceptional + processing is explained following the formula. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 39] + +Internet-Draft IKEv2bis February 2006 + + + Keying material will always be derived as the output of the + negotiated prf algorithm. Since the amount of keying material needed + may be greater than the size of the output of the prf algorithm, we + will use the prf iteratively. We will use the terminology prf+ to + describe the function that outputs a pseudo-random stream based on + the inputs to a prf as follows: (where | indicates concatenation) + + prf+ (K,S) = T1 | T2 | T3 | T4 | ... + + where: + T1 = prf (K, S | 0x01) + T2 = prf (K, T1 | S | 0x02) + T3 = prf (K, T2 | S | 0x03) + T4 = prf (K, T3 | S | 0x04) + + continuing as needed to compute all required keys. The keys are + taken from the output string without regard to boundaries (e.g., if + the required keys are a 256-bit Advanced Encryption Standard (AES) + key and a 160-bit HMAC key, and the prf function generates 160 bits, + the AES key will come from T1 and the beginning of T2, while the HMAC + key will come from the rest of T2 and the beginning of T3). + + The constant concatenated to the end of each string feeding the prf + is a single octet. prf+ in this document is not defined beyond 255 + times the size of the prf output. + +2.14. Generating Keying Material for the IKE_SA + + The shared keys are computed as follows. A quantity called SKEYSEED + is calculated from the nonces exchanged during the IKE_SA_INIT + exchange and the Diffie-Hellman shared secret established during that + exchange. SKEYSEED is used to calculate seven other secrets: SK_d + used for deriving new keys for the CHILD_SAs established with this + IKE_SA; SK_ai and SK_ar used as a key to the integrity protection + algorithm for authenticating the component messages of subsequent + exchanges; SK_ei and SK_er used for encrypting (and of course + decrypting) all subsequent exchanges; and SK_pi and SK_pr, which are + used when generating an AUTH payload. + + SKEYSEED and its derivatives are computed as follows: + + SKEYSEED = prf(Ni | Nr, g^ir) + + {SK_d | SK_ai | SK_ar | SK_ei | SK_er | SK_pi | SK_pr } + = prf+ (SKEYSEED, Ni | Nr | SPIi | SPIr ) + + (indicating that the quantities SK_d, SK_ai, SK_ar, SK_ei, SK_er, + SK_pi, and SK_pr are taken in order from the generated bits of the + + + +Kaufman, et al. Expires August 27, 2006 [Page 40] + +Internet-Draft IKEv2bis February 2006 + + + prf+). g^ir is the shared secret from the ephemeral Diffie-Hellman + exchange. g^ir is represented as a string of octets in big endian + order padded with zeros if necessary to make it the length of the + modulus. Ni and Nr are the nonces, stripped of any headers. If the + negotiated prf takes a fixed-length key and the lengths of Ni and Nr + do not add up to that length, half the bits must come from Ni and + half from Nr, taking the first bits of each. + + The two directions of traffic flow use different keys. The keys used + to protect messages from the original initiator are SK_ai and SK_ei. + The keys used to protect messages in the other direction are SK_ar + and SK_er. Each algorithm takes a fixed number of bits of keying + material, which is specified as part of the algorithm. For integrity + algorithms based on a keyed hash, the key size is always equal to the + length of the output of the underlying hash function. + +2.15. Authentication of the IKE_SA + + When not using extensible authentication (see Section 2.16), the + peers are authenticated by having each sign (or MAC using a shared + secret as the key) a block of data. For the responder, the octets to + be signed start with the first octet of the first SPI in the header + of the second message and end with the last octet of the last payload + in the second message. Appended to this (for purposes of computing + the signature) are the initiator's nonce Ni (just the value, not the + payload containing it), and the value prf(SK_pr,IDr') where IDr' is + the responder's ID payload excluding the fixed header. Note that + neither the nonce Ni nor the value prf(SK_pr,IDr') are transmitted. + Similarly, the initiator signs the first message, starting with the + first octet of the first SPI in the header and ending with the last + octet of the last payload. Appended to this (for purposes of + computing the signature) are the responder's nonce Nr, and the value + prf(SK_pi,IDi'). In the above calculation, IDi' and IDr' are the + entire ID payloads excluding the fixed header. It is critical to the + security of the exchange that each side sign the other side's nonce. + + {{ Clarif-3.1 }} + + The initiator's signed octets can be described as: + + InitiatorSignedOctets = RealMessage1 | NonceRData | MACedIDForI + GenIKEHDR = [ four octets 0 if using port 4500 ] | RealIKEHDR + RealIKEHDR = SPIi | SPIr | . . . | Length + RealMessage1 = RealIKEHDR | RestOfMessage1 + NonceRPayload = PayloadHeader | NonceRData + InitiatorIDPayload = PayloadHeader | RestOfIDPayload + RestOfInitIDPayload = IDType | RESERVED | InitIDData + MACedIDForI = prf(SK_pi, RestOfInitIDPayload) + + + +Kaufman, et al. Expires August 27, 2006 [Page 41] + +Internet-Draft IKEv2bis February 2006 + + + The responder's signed octets can be described as: + + ResponderSignedOctets = RealMessage2 | NonceIData | MACedIDForR + GenIKEHDR = [ four octets 0 if using port 4500 ] | RealIKEHDR + RealIKEHDR = SPIi | SPIr | . . . | Length + RealMessage2 = RealIKEHDR | RestOfMessage2 + NonceIPayload = PayloadHeader | NonceIData + ResponderIDPayload = PayloadHeader | RestOfIDPayload + RestOfRespIDPayload = IDType | RESERVED | InitIDData + MACedIDForR = prf(SK_pr, RestOfRespIDPayload) + + Note that all of the payloads are included under the signature, + including any payload types not defined in this document. If the + first message of the exchange is sent twice (the second time with a + responder cookie and/or a different Diffie-Hellman group), it is the + second version of the message that is signed. + + Optionally, messages 3 and 4 MAY include a certificate, or + certificate chain providing evidence that the key used to compute a + digital signature belongs to the name in the ID payload. The + signature or MAC will be computed using algorithms dictated by the + type of key used by the signer, and specified by the Auth Method + field in the Authentication payload. There is no requirement that + the initiator and responder sign with the same cryptographic + algorithms. The choice of cryptographic algorithms depends on the + type of key each has. In particular, the initiator may be using a + shared key while the responder may have a public signature key and + certificate. It will commonly be the case (but it is not required) + that if a shared secret is used for authentication that the same key + is used in both directions. Note that it is a common but typically + insecure practice to have a shared key derived solely from a user- + chosen password without incorporating another source of randomness. + + This is typically insecure because user-chosen passwords are unlikely + to have sufficient unpredictability to resist dictionary attacks and + these attacks are not prevented in this authentication method. + (Applications using password-based authentication for bootstrapping + and IKE_SA should use the authentication method in Section 2.16, + which is designed to prevent off-line dictionary attacks.) {{ Demoted + the SHOULD }} The pre-shared key needs to contain as much + unpredictability as the strongest key being negotiated. In the case + of a pre-shared key, the AUTH value is computed as: + + AUTH = prf(prf(Shared Secret,"Key Pad for IKEv2"), ) + + where the string "Key Pad for IKEv2" is 17 ASCII characters without + null termination. The shared secret can be variable length. The pad + string is added so that if the shared secret is derived from a + + + +Kaufman, et al. Expires August 27, 2006 [Page 42] + +Internet-Draft IKEv2bis February 2006 + + + password, the IKE implementation need not store the password in + cleartext, but rather can store the value prf(Shared Secret,"Key Pad + for IKEv2"), which could not be used as a password equivalent for + protocols other than IKEv2. As noted above, deriving the shared + secret from a password is not secure. This construction is used + because it is anticipated that people will do it anyway. The + management interface by which the Shared Secret is provided MUST + accept ASCII strings of at least 64 octets and MUST NOT add a null + terminator before using them as shared secrets. It MUST also accept + a hex encoding of the Shared Secret. The management interface MAY + accept other encodings if the algorithm for translating the encoding + to a binary string is specified. + + {{ Clarif-3.7 }} If the negotiated prf takes a fixed-size key, the + shared secret MUST be of that fixed size. This requirement means + that it is difficult to use these PRFs with shared key authentication + because it limits the shared secrets that can be used. Thus, PRFs + that require a fixed-size key SHOULD NOT be used with shared key + authentication. For example, PRF_AES128_CBC [PRFAES128CBC] + originally used fixed key sizes; that RFC has been updated to handle + variable key sizes in [PRFAES128CBC-bis]. Note that Section 2.13 + also contains text that is related to PRFs with fixed key size. + However, the text in that section applies only to the prf+ + construction. + +2.16. Extensible Authentication Protocol Methods + + In addition to authentication using public key signatures and shared + secrets, IKE supports authentication using methods defined in RFC + 3748 [EAP]. Typically, these methods are asymmetric (designed for a + user authenticating to a server), and they may not be mutual. {{ In + the next sentence, changed "public key signature based" to "strong" + }} For this reason, these protocols are typically used to + authenticate the initiator to the responder and MUST be used in + conjunction with a strong authentication of the responder to the + initiator. These methods are often associated with mechanisms + referred to as "Legacy Authentication" mechanisms. + + While this memo references [EAP] with the intent that new methods can + be added in the future without updating this specification, some + simpler variations are documented here and in Section 3.16. [EAP] + defines an authentication protocol requiring a variable number of + messages. Extensible Authentication is implemented in IKE as + additional IKE_AUTH exchanges that MUST be completed in order to + initialize the IKE_SA. + + An initiator indicates a desire to use extensible authentication by + leaving out the AUTH payload from message 3. By including an IDi + + + +Kaufman, et al. Expires August 27, 2006 [Page 43] + +Internet-Draft IKEv2bis February 2006 + + + payload but not an AUTH payload, the initiator has declared an + identity but has not proven it. If the responder is willing to use + an extensible authentication method, it will place an Extensible + Authentication Protocol (EAP) payload in message 4 and defer sending + SAr2, TSi, and TSr until initiator authentication is complete in a + subsequent IKE_AUTH exchange. In the case of a minimal extensible + authentication, the initial SA establishment will appear as follows: + + Initiator Responder + ------------------------------------------------------------------- + HDR, SAi1, KEi, Ni --> + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + HDR, SK {IDi, [CERTREQ,] + [IDr,] SAi2, + TSi, TSr} --> + <-- HDR, SK {IDr, [CERT,] AUTH, + EAP } + HDR, SK {EAP} --> + <-- HDR, SK {EAP (success)} + HDR, SK {AUTH} --> + <-- HDR, SK {AUTH, SAr2, TSi, TSr } + + {{ Clarif-3.10 }} As described in Section 2.2, when EAP is used, each + pair of IKE_SA initial setup messages will have their message numbers + incremented; the first pair of AUTH messages will have an ID of 1, + the second will be 2, and so on. + + For EAP methods that create a shared key as a side effect of + authentication, that shared key MUST be used by both the initiator + and responder to generate AUTH payloads in messages 7 and 8 using the + syntax for shared secrets specified in Section 2.15. The shared key + from EAP is the field from the EAP specification named MSK. The + shared key generated during an IKE exchange MUST NOT be used for any + other purpose. + + EAP methods that do not establish a shared key SHOULD NOT be used, as + they are subject to a number of man-in-the-middle attacks [EAPMITM] + if these EAP methods are used in other protocols that do not use a + server-authenticated tunnel. Please see the Security Considerations + section for more details. If EAP methods that do not generate a + shared key are used, the AUTH payloads in messages 7 and 8 MUST be + generated using SK_pi and SK_pr, respectively. + + {{ Demoted the SHOULD }} The initiator of an IKE_SA using EAP needs + to be capable of extending the initial protocol exchange to at least + ten IKE_AUTH exchanges in the event the responder sends notification + messages and/or retries the authentication prompt. Once the protocol + exchange defined by the chosen EAP authentication method has + + + +Kaufman, et al. Expires August 27, 2006 [Page 44] + +Internet-Draft IKEv2bis February 2006 + + + successfully terminated, the responder MUST send an EAP payload + containing the Success message. Similarly, if the authentication + method has failed, the responder MUST send an EAP payload containing + the Failure message. The responder MAY at any time terminate the IKE + exchange by sending an EAP payload containing the Failure message. + + Following such an extended exchange, the EAP AUTH payloads MUST be + included in the two messages following the one containing the EAP + Success message. + + {{ Clarif-3.5 }} When the initiator authentication uses EAP, it is + possible that the contents of the IDi payload is used only for AAA + routing purposes and selecting which EAP method to use. This value + may be different from the identity authenticated by the EAP method. + It is important that policy lookups and access control decisions use + the actual authenticated identity. Often the EAP server is + implemented in a separate AAA server that communicates with the IKEv2 + responder. In this case, the authenticated identity has to be sent + from the AAA server to the IKEv2 responder. + + {{ Clarif-3.8 }} The information in Section 2.17 about PRFs with + fixed-size keys also applies to EAP authentication. For instance, a + PRF that requires a 128-bit key cannot be used with EAP because + specifies that the MSK is at least 512 bits long. + +2.17. Generating Keying Material for CHILD_SAs + + A single CHILD_SA is created by the IKE_AUTH exchange, and additional + CHILD_SAs can optionally be created in CREATE_CHILD_SA exchanges. + Keying material for them is generated as follows: + + KEYMAT = prf+(SK_d, Ni | Nr) + + Where Ni and Nr are the nonces from the IKE_SA_INIT exchange if this + request is the first CHILD_SA created or the fresh Ni and Nr from the + CREATE_CHILD_SA exchange if this is a subsequent creation. + + For CREATE_CHILD_SA exchanges including an optional Diffie-Hellman + exchange, the keying material is defined as: + + KEYMAT = prf+(SK_d, g^ir (new) | Ni | Nr ) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros in the high-order + bits if necessary to make it the length of the modulus). + + A single CHILD_SA negotiation may result in multiple security + + + +Kaufman, et al. Expires August 27, 2006 [Page 45] + +Internet-Draft IKEv2bis February 2006 + + + associations. ESP and AH SAs exist in pairs (one in each direction), + and four SAs could be created in a single CHILD_SA negotiation if a + combination of ESP and AH is being negotiated. + + Keying material MUST be taken from the expanded KEYMAT in the + following order: + + o All keys for SAs carrying data from the initiator to the responder + are taken before SAs going in the reverse direction. + + o If multiple IPsec protocols are negotiated, keying material is + taken in the order in which the protocol headers will appear in + the encapsulated packet. + + o If a single protocol has both encryption and authentication keys, + the encryption key is taken from the first octets of KEYMAT and + the authentication key is taken from the next octets. + + Each cryptographic algorithm takes a fixed number of bits of keying + material specified as part of the algorithm. + +2.18. Rekeying IKE_SAs Using a CREATE_CHILD_SA Exchange + + The CREATE_CHILD_SA exchange can be used to rekey an existing IKE_SA + (see Section 2.8). {{ Clarif-5.3 }} New initiator and responder SPIs + are supplied in the SPI fields in the Proposal structures inside the + Security Association (SA) payloads (not the SPI fields in the IKE + header). The TS payloads are omitted when rekeying an IKE_SA. + SKEYSEED for the new IKE_SA is computed using SK_d from the existing + IKE_SA as follows: + + SKEYSEED = prf(SK_d (old), [g^ir (new)] | Ni | Nr) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros if necessary to + make it the length of the modulus) and Ni and Nr are the two nonces + stripped of any headers. + + {{ Clarif-5.5 }} The old and new IKE_SA may have selected a different + PRF. Because the rekeying exchange belongs to the old IKE_SA, it is + the old IKE_SA's PRF that is used. Note that this may not work if + the new IKE_SA's PRF has a fixed key size because the output of the + PRF may not be of the correct size. + + The new IKE_SA MUST reset its message counters to 0. + + SK_d, SK_ai, SK_ar, SK_ei, and SK_er are computed from SKEYSEED as + + + +Kaufman, et al. Expires August 27, 2006 [Page 46] + +Internet-Draft IKEv2bis February 2006 + + + specified in Section 2.14. + +2.19. Requesting an Internal Address on a Remote Network + + Most commonly occurring in the endpoint-to-security-gateway scenario, + an endpoint may need an IP address in the network protected by the + security gateway and may need to have that address dynamically + assigned. A request for such a temporary address can be included in + any request to create a CHILD_SA (including the implicit request in + message 3) by including a CP payload. + + This function provides address allocation to an IPsec Remote Access + Client (IRAC) trying to tunnel into a network protected by an IPsec + Remote Access Server (IRAS). Since the IKE_AUTH exchange creates an + IKE_SA and a CHILD_SA, the IRAC MUST request the IRAS-controlled + address (and optionally other information concerning the protected + network) in the IKE_AUTH exchange. The IRAS may procure an address + for the IRAC from any number of sources such as a DHCP/BOOTP server + or its own address pool. + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK {IDi, [CERT,] + [CERTREQ,] [IDr,] AUTH, + CP(CFG_REQUEST), SAi2, + TSi, TSr} --> + <-- HDR, SK {IDr, [CERT,] AUTH, + CP(CFG_REPLY), SAr2, + TSi, TSr} + + In all cases, the CP payload MUST be inserted before the SA payload. + In variations of the protocol where there are multiple IKE_AUTH + exchanges, the CP payloads MUST be inserted in the messages + containing the SA payloads. + + CP(CFG_REQUEST) MUST contain at least an INTERNAL_ADDRESS attribute + (either IPv4 or IPv6) but MAY contain any number of additional + attributes the initiator wants returned in the response. + + For example, message from initiator to responder: + + CP(CFG_REQUEST)= + INTERNAL_ADDRESS() + TSi = (0, 0-65535,0.0.0.0-255.255.255.255) + TSr = (0, 0-65535,0.0.0.0-255.255.255.255) + + NOTE: Traffic Selectors contain (protocol, port range, address + range). + + + +Kaufman, et al. Expires August 27, 2006 [Page 47] + +Internet-Draft IKEv2bis February 2006 + + + Message from responder to initiator: + + CP(CFG_REPLY)= + INTERNAL_ADDRESS(192.0.2.202) + INTERNAL_NETMASK(255.255.255.0) + INTERNAL_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535,192.0.2.202-192.0.2.202) + TSr = (0, 0-65535,192.0.2.0-192.0.2.255) + + All returned values will be implementation dependent. As can be seen + in the above example, the IRAS MAY also send other attributes that + were not included in CP(CFG_REQUEST) and MAY ignore the non- + mandatory attributes that it does not support. + + The responder MUST NOT send a CFG_REPLY without having first received + a CP(CFG_REQUEST) from the initiator, because we do not want the IRAS + to perform an unnecessary configuration lookup if the IRAC cannot + process the REPLY. In the case where the IRAS's configuration + requires that CP be used for a given identity IDi, but IRAC has + failed to send a CP(CFG_REQUEST), IRAS MUST fail the request, and + terminate the IKE exchange with a FAILED_CP_REQUIRED error. + +2.20. Requesting the Peer's Version + + An IKE peer wishing to inquire about the other peer's IKE software + version information MAY use the method below. This is an example of + a configuration request within an INFORMATIONAL exchange, after the + IKE_SA and first CHILD_SA have been created. + + An IKE implementation MAY decline to give out version information + prior to authentication or even after authentication to prevent + trolling in case some implementation is known to have some security + weakness. In that case, it MUST either return an empty string or no + CP payload if CP is not supported. + + Initiator Responder + ------------------------------------------------------------------- + HDR, SK{CP(CFG_REQUEST)} --> + <-- HDR, SK{CP(CFG_REPLY)} + + CP(CFG_REQUEST)= + APPLICATION_VERSION("") + + CP(CFG_REPLY) APPLICATION_VERSION("foobar v1.3beta, (c) Foo Bar + Inc.") + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 48] + +Internet-Draft IKEv2bis February 2006 + + +2.21. Error Handling + + There are many kinds of errors that can occur during IKE processing. + If a request is received that is badly formatted or unacceptable for + reasons of policy (e.g., no matching cryptographic algorithms), the + response MUST contain a Notify payload indicating the error. If an + error occurs outside the context of an IKE request (e.g., the node is + getting ESP messages on a nonexistent SPI), the node SHOULD initiate + an INFORMATIONAL exchange with a Notify payload describing the + problem. + + Errors that occur before a cryptographically protected IKE_SA is + established must be handled very carefully. There is a trade-off + between wanting to be helpful in diagnosing a problem and responding + to it and wanting to avoid being a dupe in a denial of service attack + based on forged messages. + + If a node receives a message on UDP port 500 or 4500 outside the + context of an IKE_SA known to it (and not a request to start one), it + may be the result of a recent crash of the node. If the message is + marked as a response, the node MAY audit the suspicious event but + MUST NOT respond. If the message is marked as a request, the node + MAY audit the suspicious event and MAY send a response. If a + response is sent, the response MUST be sent to the IP address and + port from whence it came with the same IKE SPIs and the Message ID + copied. The response MUST NOT be cryptographically protected and + MUST contain a Notify payload indicating INVALID_IKE_SPI. + + A node receiving such an unprotected Notify payload MUST NOT respond + and MUST NOT change the state of any existing SAs. The message might + be a forgery or might be a response the genuine correspondent was + tricked into sending. {{ Demoted two SHOULDs }} A node should treat + such a message (and also a network message like ICMP destination + unreachable) as a hint that there might be problems with SAs to that + IP address and should initiate a liveness test for any such IKE_SA. + An implementation SHOULD limit the frequency of such tests to avoid + being tricked into participating in a denial of service attack. + + A node receiving a suspicious message from an IP address with which + it has an IKE_SA MAY send an IKE Notify payload in an IKE + INFORMATIONAL exchange over that SA. {{ Demoted the SHOULD }} The + recipient MUST NOT change the state of any SAs as a result, but may + wish to audit the event to aid in diagnosing malfunctions. A node + MUST limit the rate at which it will send messages in response to + unprotected messages. + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 49] + +Internet-Draft IKEv2bis February 2006 + + +2.22. IPComp + + Use of IP compression [IPCOMP] can be negotiated as part of the setup + of a CHILD_SA. While IP compression involves an extra header in each + packet and a compression parameter index (CPI), the virtual + "compression association" has no life outside the ESP or AH SA that + contains it. Compression associations disappear when the + corresponding ESP or AH SA goes away. It is not explicitly mentioned + in any DELETE payload. + + Negotiation of IP compression is separate from the negotiation of + cryptographic parameters associated with a CHILD_SA. A node + requesting a CHILD_SA MAY advertise its support for one or more + compression algorithms through one or more Notify payloads of type + IPCOMP_SUPPORTED. The response MAY indicate acceptance of a single + compression algorithm with a Notify payload of type IPCOMP_SUPPORTED. + These payloads MUST NOT occur in messages that do not contain SA + payloads. + + Although there has been discussion of allowing multiple compression + algorithms to be accepted and to have different compression + algorithms available for the two directions of a CHILD_SA, + implementations of this specification MUST NOT accept an IPComp + algorithm that was not proposed, MUST NOT accept more than one, and + MUST NOT compress using an algorithm other than one proposed and + accepted in the setup of the CHILD_SA. + + A side effect of separating the negotiation of IPComp from + cryptographic parameters is that it is not possible to propose + multiple cryptographic suites and propose IP compression with some of + them but not others. + +2.23. NAT Traversal + + Network Address Translation (NAT) gateways are a controversial + subject. This section briefly describes what they are and how they + are likely to act on IKE traffic. Many people believe that NATs are + evil and that we should not design our protocols so as to make them + work better. IKEv2 does specify some unintuitive processing rules in + order that NATs are more likely to work. + + NATs exist primarily because of the shortage of IPv4 addresses, + though there are other rationales. IP nodes that are "behind" a NAT + have IP addresses that are not globally unique, but rather are + assigned from some space that is unique within the network behind the + NAT but that are likely to be reused by nodes behind other NATs. + Generally, nodes behind NATs can communicate with other nodes behind + the same NAT and with nodes with globally unique addresses, but not + + + +Kaufman, et al. Expires August 27, 2006 [Page 50] + +Internet-Draft IKEv2bis February 2006 + + + with nodes behind other NATs. There are exceptions to that rule. + When those nodes make connections to nodes on the real Internet, the + NAT gateway "translates" the IP source address to an address that + will be routed back to the gateway. Messages to the gateway from the + Internet have their destination addresses "translated" to the + internal address that will route the packet to the correct endnode. + + NATs are designed to be "transparent" to endnodes. Neither software + on the node behind the NAT nor the node on the Internet requires + modification to communicate through the NAT. Achieving this + transparency is more difficult with some protocols than with others. + Protocols that include IP addresses of the endpoints within the + payloads of the packet will fail unless the NAT gateway understands + the protocol and modifies the internal references as well as those in + the headers. Such knowledge is inherently unreliable, is a network + layer violation, and often results in subtle problems. + + Opening an IPsec connection through a NAT introduces special + problems. If the connection runs in transport mode, changing the IP + addresses on packets will cause the checksums to fail and the NAT + cannot correct the checksums because they are cryptographically + protected. Even in tunnel mode, there are routing problems because + transparently translating the addresses of AH and ESP packets + requires special logic in the NAT and that logic is heuristic and + unreliable in nature. For that reason, IKEv2 can negotiate UDP + encapsulation of IKE and ESP packets. This encoding is slightly less + efficient but is easier for NATs to process. In addition, firewalls + may be configured to pass IPsec traffic over UDP but not ESP/AH or + vice versa. + + It is a common practice of NATs to translate TCP and UDP port numbers + as well as addresses and use the port numbers of inbound packets to + decide which internal node should get a given packet. For this + reason, even though IKE packets MUST be sent from and to UDP port + 500, they MUST be accepted coming from any port and responses MUST be + sent to the port from whence they came. This is because the ports + may be modified as the packets pass through NATs. Similarly, IP + addresses of the IKE endpoints are generally not included in the IKE + payloads because the payloads are cryptographically protected and + could not be transparently modified by NATs. + + Port 4500 is reserved for UDP-encapsulated ESP and IKE. When working + through a NAT, it is generally better to pass IKE packets over port + 4500 because some older NATs handle IKE traffic on port 500 cleverly + in an attempt to transparently establish IPsec connections between + endpoints that don't handle NAT traversal themselves. Such NATs may + interfere with the straightforward NAT traversal envisioned by this + document. {{ Clarif-7.6 }} An IPsec endpoint that discovers a NAT + + + +Kaufman, et al. Expires August 27, 2006 [Page 51] + +Internet-Draft IKEv2bis February 2006 + + + between it and its correspondent MUST send all subsequent traffic + from port 4500, which NATs should not treat specially (as they might + with port 500). + + The specific requirements for supporting NAT traversal [NATREQ] are + listed below. Support for NAT traversal is optional. In this + section only, requirements listed as MUST apply only to + implementations supporting NAT traversal. + + o IKE MUST listen on port 4500 as well as port 500. IKE MUST + respond to the IP address and port from which packets arrived. + + o Both IKE initiator and responder MUST include in their IKE_SA_INIT + packets Notify payloads of type NAT_DETECTION_SOURCE_IP and + NAT_DETECTION_DESTINATION_IP. Those payloads can be used to + detect if there is NAT between the hosts, and which end is behind + the NAT. The location of the payloads in the IKE_SA_INIT packets + are just after the Ni and Nr payloads (before the optional CERTREQ + payload). + + o If none of the NAT_DETECTION_SOURCE_IP payload(s) received matches + the hash of the source IP and port found from the IP header of the + packet containing the payload, it means that the other end is + behind NAT (i.e., someone along the route changed the source + address of the original packet to match the address of the NAT + box). In this case, this end should allow dynamic update of the + other ends IP address, as described later. + + o If the NAT_DETECTION_DESTINATION_IP payload received does not + match the hash of the destination IP and port found from the IP + header of the packet containing the payload, it means that this + end is behind a NAT. In this case, this end SHOULD start sending + keepalive packets as explained in [UDPENCAPS]. + + o The IKE initiator MUST check these payloads if present and if they + do not match the addresses in the outer packet MUST tunnel all + future IKE and ESP packets associated with this IKE_SA over UDP + port 4500. + + o To tunnel IKE packets over UDP port 4500, the IKE header has four + octets of zero prepended and the result immediately follows the + UDP header. To tunnel ESP packets over UDP port 4500, the ESP + header immediately follows the UDP header. Since the first four + bytes of the ESP header contain the SPI, and the SPI cannot + validly be zero, it is always possible to distinguish ESP and IKE + messages. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 52] + +Internet-Draft IKEv2bis February 2006 + + + o The original source and destination IP address required for the + transport mode TCP and UDP packet checksum fixup (see [UDPENCAPS]) + are obtained from the Traffic Selectors associated with the + exchange. In the case of NAT traversal, the Traffic Selectors + MUST contain exactly one IP address, which is then used as the + original IP address. + + o There are cases where a NAT box decides to remove mappings that + are still alive (for example, the keepalive interval is too long, + or the NAT box is rebooted). To recover in these cases, hosts + that are not behind a NAT SHOULD send all packets (including + retransmission packets) to the IP address and port from the last + valid authenticated packet from the other end (i.e., dynamically + update the address). A host behind a NAT SHOULD NOT do this + because it opens a DoS attack possibility. Any authenticated IKE + packet or any authenticated UDP-encapsulated ESP packet can be + used to detect that the IP address or the port has changed. + + Note that similar but probably not identical actions will likely be + needed to make IKE work with Mobile IP, but such processing is not + addressed by this document. + +2.24. Explicit Congestion Notification (ECN) + + When IPsec tunnels behave as originally specified in [IPSECARCH-OLD], + ECN usage is not appropriate for the outer IP headers because tunnel + decapsulation processing discards ECN congestion indications to the + detriment of the network. ECN support for IPsec tunnels for IKEv1- + based IPsec requires multiple operating modes and negotiation (see + [ECN]). IKEv2 simplifies this situation by requiring that ECN be + usable in the outer IP headers of all tunnel-mode IPsec SAs created + by IKEv2. Specifically, tunnel encapsulators and decapsulators for + all tunnel-mode SAs created by IKEv2 MUST support the ECN full- + functionality option for tunnels specified in [ECN] and MUST + implement the tunnel encapsulation and decapsulation processing + specified in [IPSECARCH] to prevent discarding of ECN congestion + indications. + + +3. Header and Payload Formats + +3.1. The IKE Header + + IKE messages use UDP ports 500 and/or 4500, with one IKE message per + UDP datagram. Information from the beginning of the packet through + the UDP header is largely ignored except that the IP addresses and + UDP ports from the headers are reversed and used for return packets. + When sent on UDP port 500, IKE messages begin immediately following + + + +Kaufman, et al. Expires August 27, 2006 [Page 53] + +Internet-Draft IKEv2bis February 2006 + + + the UDP header. When sent on UDP port 4500, IKE messages have + prepended four octets of zero. These four octets of zero are not + part of the IKE message and are not included in any of the length + fields or checksums defined by IKE. Each IKE message begins with the + IKE header, denoted HDR in this memo. Following the header are one + or more IKE payloads each identified by a "Next Payload" field in the + preceding payload. Payloads are processed in the order in which they + appear in an IKE message by invoking the appropriate processing + routine according to the "Next Payload" field in the IKE header and + subsequently according to the "Next Payload" field in the IKE payload + itself until a "Next Payload" field of zero indicates that no + payloads follow. If a payload of type "Encrypted" is found, that + payload is decrypted and its contents parsed as additional payloads. + An Encrypted payload MUST be the last payload in a packet and an + Encrypted payload MUST NOT contain another Encrypted payload. + + The Recipient SPI in the header identifies an instance of an IKE + security association. It is therefore possible for a single instance + of IKE to multiplex distinct sessions with multiple peers. + + All multi-octet fields representing integers are laid out in big + endian order (aka most significant byte first, or network byte + order). + + The format of the IKE header is shown in Figure 4. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Initiator's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Responder's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! MjVer ! MnVer ! Exchange Type ! Flags ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Message ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 4: IKE Header Format + + o Initiator's SPI (8 octets) - A value chosen by the initiator to + identify a unique IKE security association. This value MUST NOT + be zero. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 54] + +Internet-Draft IKEv2bis February 2006 + + + o Responder's SPI (8 octets) - A value chosen by the responder to + identify a unique IKE security association. This value MUST be + zero in the first message of an IKE Initial Exchange (including + repeats of that message including a cookie). {{ The phrase "and + MUST NOT be zero in any other message" was removed; Clarif-2.1 }} + + o Next Payload (1 octet) - Indicates the type of payload that + immediately follows the header. The format and value of each + payload are defined below. + + o Major Version (4 bits) - Indicates the major version of the IKE + protocol in use. Implementations based on this version of IKE + MUST set the Major Version to 2. Implementations based on + previous versions of IKE and ISAKMP MUST set the Major Version to + 1. Implementations based on this version of IKE MUST reject or + ignore messages containing a version number greater than 2. + + o Minor Version (4 bits) - Indicates the minor version of the IKE + protocol in use. Implementations based on this version of IKE + MUST set the Minor Version to 0. They MUST ignore the minor + version number of received messages. + + o Exchange Type (1 octet) - Indicates the type of exchange being + used. This constrains the payloads sent in each message and + orderings of messages in an exchange. + + Exchange Type Value + ---------------------------------- + RESERVED 0-33 + IKE_SA_INIT 34 + IKE_AUTH 35 + CREATE_CHILD_SA 36 + INFORMATIONAL 37 + RESERVED TO IANA 38-239 + Reserved for private use 240-255 + + o Flags (1 octet) - Indicates specific options that are set for the + message. Presence of options are indicated by the appropriate bit + in the flags field being set. The bits are defined LSB first, so + bit 0 would be the least significant bit of the Flags octet. In + the description below, a bit being 'set' means its value is '1', + while 'cleared' means its value is '0'. + + * X(reserved) (bits 0-2) - These bits MUST be cleared when + sending and MUST be ignored on receipt. + + * I(nitiator) (bit 3 of Flags) - This bit MUST be set in messages + sent by the original initiator of the IKE_SA and MUST be + + + +Kaufman, et al. Expires August 27, 2006 [Page 55] + +Internet-Draft IKEv2bis February 2006 + + + cleared in messages sent by the original responder. It is used + by the recipient to determine which eight octets of the SPI + were generated by the recipient. + + * V(ersion) (bit 4 of Flags) - This bit indicates that the + transmitter is capable of speaking a higher major version + number of the protocol than the one indicated in the major + version number field. Implementations of IKEv2 must clear this + bit when sending and MUST ignore it in incoming messages. + + * R(esponse) (bit 5 of Flags) - This bit indicates that this + message is a response to a message containing the same message + ID. This bit MUST be cleared in all request messages and MUST + be set in all responses. An IKE endpoint MUST NOT generate a + response to a message that is marked as being a response. + + * X(reserved) (bits 6-7 of Flags) - These bits MUST be cleared + when sending and MUST be ignored on receipt. + + o Message ID (4 octets) - Message identifier used to control + retransmission of lost packets and matching of requests and + responses. It is essential to the security of the protocol + because it is used to prevent message replay attacks. See + Section 2.1 and Section 2.2. + + o Length (4 octets) - Length of total message (header + payloads) in + octets. + +3.2. Generic Payload Header + + Each IKE payload defined in Section 3.3 through Section 3.16 begins + with a generic payload header, shown in Figure 5. Figures for each + payload below will include the generic payload header, but for + brevity the description of each field will be omitted. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 5: Generic Payload Header + + The Generic Payload Header fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. This field provides a + + + +Kaufman, et al. Expires August 27, 2006 [Page 56] + +Internet-Draft IKEv2bis February 2006 + + + "chaining" capability whereby additional payloads can be added to + a message by appending it to the end of the message and setting + the "Next Payload" field of the preceding payload to indicate the + new payload's type. An Encrypted payload, which must always be + the last payload of a message, is an exception. It contains data + structures in the format of additional payloads. In the header of + an Encrypted payload, the Next Payload field is set to the payload + type of the first contained payload (instead of 0). The payload + type values are: + + Next Payload Type Notation Value + -------------------------------------------------- + No Next Payload 0 + RESERVED 1-32 + Security Association SA 33 + Key Exchange KE 34 + Identification - Initiator IDi 35 + Identification - Responder IDr 36 + Certificate CERT 37 + Certificate Request CERTREQ 38 + Authentication AUTH 39 + Nonce Ni, Nr 40 + Notify N 41 + Delete D 42 + Vendor ID V 43 + Traffic Selector - Initiator TSi 44 + Traffic Selector - Responder TSr 45 + Encrypted E 46 + Configuration CP 47 + Extensible Authentication EAP 48 + RESERVED TO IANA 49-127 + PRIVATE USE 128-255 + + (Payload type values 1-32 should not be assigned in the + future so that there is no overlap with the code assignments + for IKEv1.) + + o Critical (1 bit) - MUST be set to zero if the sender wants the + recipient to skip this payload if it does not understand the + payload type code in the Next Payload field of the previous + payload. MUST be set to one if the sender wants the recipient to + reject this entire message if it does not understand the payload + type. MUST be ignored by the recipient if the recipient + understands the payload type code. MUST be set to zero for + payload types defined in this document. Note that the critical + bit applies to the current payload rather than the "next" payload + whose type code appears in the first octet. The reasoning behind + not setting the critical bit for payloads defined in this document + + + +Kaufman, et al. Expires August 27, 2006 [Page 57] + +Internet-Draft IKEv2bis February 2006 + + + is that all implementations MUST understand all payload types + defined in this document and therefore must ignore the Critical + bit's value. Skipped payloads are expected to have valid Next + Payload and Payload Length fields. + + o RESERVED (7 bits) - MUST be sent as zero; MUST be ignored on + receipt. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + +3.3. Security Association Payload + + The Security Association Payload, denoted SA in this memo, is used to + negotiate attributes of a security association. Assembly of Security + Association Payloads requires great peace of mind. An SA payload MAY + contain multiple proposals. If there is more than one, they MUST be + ordered from most preferred to least preferred. Each proposal may + contain multiple IPsec protocols (where a protocol is IKE, ESP, or + AH), each protocol MAY contain multiple transforms, and each + transform MAY contain multiple attributes. When parsing an SA, an + implementation MUST check that the total Payload Length is consistent + with the payload's internal lengths and counts. Proposals, + Transforms, and Attributes each have their own variable length + encodings. They are nested such that the Payload Length of an SA + includes the combined contents of the SA, Proposal, Transform, and + Attribute information. The length of a Proposal includes the lengths + of all Transforms and Attributes it contains. The length of a + Transform includes the lengths of all Attributes it contains. + + The syntax of Security Associations, Proposals, Transforms, and + Attributes is based on ISAKMP; however the semantics are somewhat + different. The reason for the complexity and the hierarchy is to + allow for multiple possible combinations of algorithms to be encoded + in a single SA. Sometimes there is a choice of multiple algorithms, + whereas other times there is a combination of algorithms. For + example, an initiator might want to propose using (AH w/MD5 and ESP + w/3DES) OR (ESP w/MD5 and 3DES). + + One of the reasons the semantics of the SA payload has changed from + ISAKMP and IKEv1 is to make the encodings more compact in common + cases. + + The Proposal structure contains within it a Proposal # and an IPsec + protocol ID. Each structure MUST have the same Proposal # as the + previous one or be one (1) greater. The first Proposal MUST have a + Proposal # of one (1). If two successive structures have the same + Proposal number, it means that the proposal consists of the first + + + +Kaufman, et al. Expires August 27, 2006 [Page 58] + +Internet-Draft IKEv2bis February 2006 + + + structure AND the second. So a proposal of AH AND ESP would have two + proposal structures, one for AH and one for ESP and both would have + Proposal #1. A proposal of AH OR ESP would have two proposal + structures, one for AH with Proposal #1 and one for ESP with Proposal + #2. + + Each Proposal/Protocol structure is followed by one or more transform + structures. The number of different transforms is generally + determined by the Protocol. AH generally has a single transform: an + integrity check algorithm. ESP generally has two: an encryption + algorithm and an integrity check algorithm. IKE generally has four + transforms: a Diffie-Hellman group, an integrity check algorithm, a + prf algorithm, and an encryption algorithm. If an algorithm that + combines encryption and integrity protection is proposed, it MUST be + proposed as an encryption algorithm and an integrity protection + algorithm MUST NOT be proposed. For each Protocol, the set of + permissible transforms is assigned transform ID numbers, which appear + in the header of each transform. + + If there are multiple transforms with the same Transform Type, the + proposal is an OR of those transforms. If there are multiple + Transforms with different Transform Types, the proposal is an AND of + the different groups. For example, to propose ESP with (3DES or + IDEA) and (HMAC_MD5 or HMAC_SHA), the ESP proposal would contain two + Transform Type 1 candidates (one for 3DES and one for IDEA) and two + Transform Type 2 candidates (one for HMAC_MD5 and one for HMAC_SHA). + This effectively proposes four combinations of algorithms. If the + initiator wanted to propose only a subset of those, for example (3DES + and HMAC_MD5) or (IDEA and HMAC_SHA), there is no way to encode that + as multiple transforms within a single Proposal. Instead, the + initiator would have to construct two different Proposals, each with + two transforms. + + A given transform MAY have one or more Attributes. Attributes are + necessary when the transform can be used in more than one way, as + when an encryption algorithm has a variable key size. The transform + would specify the algorithm and the attribute would specify the key + size. Most transforms do not have attributes. A transform MUST NOT + have multiple attributes of the same type. To propose alternate + values for an attribute (for example, multiple key sizes for the AES + encryption algorithm), and implementation MUST include multiple + Transforms with the same Transform Type each with a single Attribute. + + Note that the semantics of Transforms and Attributes are quite + different from those in IKEv1. In IKEv1, a single Transform carried + multiple algorithms for a protocol with one carried in the Transform + and the others carried in the Attributes. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 59] + +Internet-Draft IKEv2bis February 2006 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 6: Security Association Payload + + o Proposals (variable) - One or more proposal substructures. + + The payload type for the Security Association Payload is thirty three + (33). + +3.3.1. Proposal Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 2 ! RESERVED ! Proposal Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Proposal # ! Protocol ID ! SPI Size !# of Transforms! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ SPI (variable) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 7: Proposal Substructure + + o 0 (last) or 2 (more) (1 octet) - Specifies whether this is the + last Proposal Substructure in the SA. This syntax is inherited + from ISAKMP, but is unnecessary because the last Proposal could be + identified from the length of the SA. The value (2) corresponds + to a Payload Type of Proposal in IKEv1, and the first four octets + of the Proposal structure are designed to look somewhat like the + header of a Payload. + + o RESERVED (1 octet) - MUST be sent as zero; MUST be ignored on + receipt. + + o Proposal Length (2 octets) - Length of this proposal, including + all transforms and attributes that follow. + + + +Kaufman, et al. Expires August 27, 2006 [Page 60] + +Internet-Draft IKEv2bis February 2006 + + + o Proposal # (1 octet) - When a proposal is made, the first proposal + in an SA payload MUST be #1, and subsequent proposals MUST either + be the same as the previous proposal (indicating an AND of the two + proposals) or one more than the previous proposal (indicating an + OR of the two proposals). When a proposal is accepted, all of the + proposal numbers in the SA payload MUST be the same and MUST match + the number on the proposal sent that was accepted. + + o Protocol ID (1 octet) - Specifies the IPsec protocol identifier + for the current negotiation. The defined values are: + + Protocol Protocol ID + ----------------------------------- + RESERVED 0 + IKE 1 + AH 2 + ESP 3 + RESERVED TO IANA 4-200 + PRIVATE USE 201-255 + + o SPI Size (1 octet) - For an initial IKE_SA negotiation, this field + MUST be zero; the SPI is obtained from the outer header. During + subsequent negotiations, it is equal to the size, in octets, of + the SPI of the corresponding protocol (8 for IKE, 4 for ESP and + AH). + + o # of Transforms (1 octet) - Specifies the number of transforms in + this proposal. + + o SPI (variable) - The sending entity's SPI. Even if the SPI Size + is not a multiple of 4 octets, there is no padding applied to the + payload. When the SPI Size field is zero, this field is not + present in the Security Association payload. + + o Transforms (variable) - One or more transform substructures. + + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 61] + +Internet-Draft IKEv2bis February 2006 + + +3.3.2. Transform Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 3 ! RESERVED ! Transform Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !Transform Type ! RESERVED ! Transform ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Transform Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 8: Transform Substructure + + o 0 (last) or 3 (more) (1 octet) - Specifies whether this is the + last Transform Substructure in the Proposal. This syntax is + inherited from ISAKMP, but is unnecessary because the last + Proposal could be identified from the length of the SA. The value + (3) corresponds to a Payload Type of Transform in IKEv1, and the + first four octets of the Transform structure are designed to look + somewhat like the header of a Payload. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Transform Length - The length (in octets) of the Transform + Substructure including Header and Attributes. + + o Transform Type (1 octet) - The type of transform being specified + in this transform. Different protocols support different + transform types. For some protocols, some of the transforms may + be optional. If a transform is optional and the initiator wishes + to propose that the transform be omitted, no transform of the + given type is included in the proposal. If the initiator wishes + to make use of the transform optional to the responder, it + includes a transform substructure with transform ID = 0 as one of + the options. + + o Transform ID (2 octets) - The specific instance of the transform + type being proposed. + + The tranform type values are: + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 62] + +Internet-Draft IKEv2bis February 2006 + + + Description Trans. Used In + Type + ------------------------------------------------------------------ + RESERVED 0 + Encryption Algorithm (ENCR) 1 IKE and ESP + Pseudo-random Function (PRF) 2 IKE + Integrity Algorithm (INTEG) 3 IKE, AH, optional in ESP + Diffie-Hellman Group (D-H) 4 IKE, optional in AH & ESP + Extended Sequence Numbers (ESN) 5 AH and ESP + RESERVED TO IANA 6-240 + PRIVATE USE 241-255 + + For Transform Type 1 (Encryption Algorithm), defined Transform IDs + are: + + Name Number Defined In + --------------------------------------------------- + RESERVED 0 + ENCR_DES_IV64 1 (RFC1827) + ENCR_DES 2 (RFC2405), [DES] + ENCR_3DES 3 (RFC2451) + ENCR_RC5 4 (RFC2451) + ENCR_IDEA 5 (RFC2451), [IDEA] + ENCR_CAST 6 (RFC2451) + ENCR_BLOWFISH 7 (RFC2451) + ENCR_3IDEA 8 (RFC2451) + ENCR_DES_IV32 9 + RESERVED 10 + ENCR_NULL 11 (RFC2410) + ENCR_AES_CBC 12 (RFC3602) + ENCR_AES_CTR 13 (RFC3664) + RESERVED TO IANA 14-1023 + PRIVATE USE 1024-65535 + + For Transform Type 2 (Pseudo-random Function), defined Transform IDs + are: + + Name Number Defined In + ------------------------------------------------------ + RESERVED 0 + PRF_HMAC_MD5 1 (RFC2104), [MD5] + PRF_HMAC_SHA1 2 (RFC2104), [SHA] + PRF_HMAC_TIGER 3 (RFC2104) + PRF_AES128_XCBC 4 (RFC3664) + RESERVED TO IANA 5-1023 + PRIVATE USE 1024-65535 + + For Transform Type 3 (Integrity Algorithm), defined Transform IDs + + + +Kaufman, et al. Expires August 27, 2006 [Page 63] + +Internet-Draft IKEv2bis February 2006 + + + are: + + Name Number Defined In + ---------------------------------------- + NONE 0 + AUTH_HMAC_MD5_96 1 (RFC2403) + AUTH_HMAC_SHA1_96 2 (RFC2404) + AUTH_DES_MAC 3 + AUTH_KPDK_MD5 4 (RFC1826) + AUTH_AES_XCBC_96 5 (RFC3566) + RESERVED TO IANA 6-1023 + PRIVATE USE 1024-65535 + + For Transform Type 4 (Diffie-Hellman Group), defined Transform IDs + are: + + Name Number + -------------------------------------- + NONE 0 + Defined in Appendix B 1 - 2 + RESERVED 3 - 4 + Defined in [ADDGROUP] 5 + RESERVED TO IANA 6 - 13 + Defined in [ADDGROUP] 14 - 18 + RESERVED TO IANA 19 - 1023 + PRIVATE USE 1024-65535 + + For Transform Type 5 (Extended Sequence Numbers), defined Transform + IDs are: + + Name Number + -------------------------------------------- + No Extended Sequence Numbers 0 + Extended Sequence Numbers 1 + RESERVED 2 - 65535 + +3.3.3. Valid Transform Types by Protocol + + The number and type of transforms that accompany an SA payload are + dependent on the protocol in the SA itself. An SA payload proposing + the establishment of an SA has the following mandatory and optional + transform types. A compliant implementation MUST understand all + mandatory and optional types for each protocol it supports (though it + need not accept proposals with unacceptable suites). A proposal MAY + omit the optional types if the only value for them it will accept is + NONE. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 64] + +Internet-Draft IKEv2bis February 2006 + + + Protocol Mandatory Types Optional Types + --------------------------------------------------- + IKE ENCR, PRF, INTEG, D-H + ESP ENCR, ESN INTEG, D-H + AH INTEG, ESN D-H + +3.3.4. Mandatory Transform IDs + + The specification of suites that MUST and SHOULD be supported for + interoperability has been removed from this document because they are + likely to change more rapidly than this document evolves. + + An important lesson learned from IKEv1 is that no system should only + implement the mandatory algorithms and expect them to be the best + choice for all customers. For example, at the time that this + document was written, many IKEv1 implementers were starting to + migrate to AES in Cipher Block Chaining (CBC) mode for Virtual + Private Network (VPN) applications. Many IPsec systems based on + IKEv2 will implement AES, additional Diffie-Hellman groups, and + additional hash algorithms, and some IPsec customers already require + these algorithms in addition to the ones listed above. + + It is likely that IANA will add additional transforms in the future, + and some users may want to use private suites, especially for IKE + where implementations should be capable of supporting different + parameters, up to certain size limits. In support of this goal, all + implementations of IKEv2 SHOULD include a management facility that + allows specification (by a user or system administrator) of Diffie- + Hellman (DH) parameters (the generator, modulus, and exponent lengths + and values) for new DH groups. Implementations SHOULD provide a + management interface through which these parameters and the + associated transform IDs may be entered (by a user or system + administrator), to enable negotiating such groups. + + All implementations of IKEv2 MUST include a management facility that + enables a user or system administrator to specify the suites that are + acceptable for use with IKE. Upon receipt of a payload with a set of + transform IDs, the implementation MUST compare the transmitted + transform IDs against those locally configured via the management + controls, to verify that the proposed suite is acceptable based on + local policy. The implementation MUST reject SA proposals that are + not authorized by these IKE suite controls. Note that cryptographic + suites that MUST be implemented need not be configured as acceptable + to local policy. + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 65] + +Internet-Draft IKEv2bis February 2006 + + +3.3.5. Transform Attributes + + Each transform in a Security Association payload may include + attributes that modify or complete the specification of the + transform. These attributes are type/value pairs and are defined + below. For example, if an encryption algorithm has a variable-length + key, the key length to be used may be specified as an attribute. + Attributes can have a value with a fixed two octet length or a + variable-length value. For the latter, the attribute is encoded as + type/length/value. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !A! Attribute Type ! AF=0 Attribute Length ! + !F! ! AF=1 Attribute Value ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! AF=0 Attribute Value ! + ! AF=1 Not Transmitted ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 9: Data Attributes + + o Attribute Type (2 octets) - Unique identifier for each type of + attribute (see below). The most significant bit of this field is + the Attribute Format bit (AF). It indicates whether the data + attributes follow the Type/Length/Value (TLV) format or a + shortened Type/Value (TV) format. If the AF bit is zero (0), then + the Data Attributes are of the Type/Length/Value (TLV) form. If + the AF bit is a one (1), then the Data Attributes are of the Type/ + Value form. + + o Attribute Length (2 octets) - Length in octets of the Attribute + Value. When the AF bit is a one (1), the Attribute Value is only + 2 octets and the Attribute Length field is not present. + + o Attribute Value (variable length) - Value of the Attribute + associated with the Attribute Type. If the AF bit is a zero (0), + this field has a variable length defined by the Attribute Length + field. If the AF bit is a one (1), the Attribute Value has a + length of 2 octets. + + o Key Length - When using an Encryption Algorithm that has a + variable-length key, this attribute specifies the key length in + bits (MUST use network byte order). This attribute MUST NOT be + used when the specified Encryption Algorithm uses a fixed-length + key. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 66] + +Internet-Draft IKEv2bis February 2006 + + + Note that only a single attribute type (Key Length) is defined, and + it is fixed length. The variable-length encoding specification is + included only for future extensions. {{ Clarif-7.11 removed the + sentence that listed, incorrectly, the algorithms defined in the + document that accept attributes. }} + + Attributes described as basic MUST NOT be encoded using the variable- + length encoding. Variable-length attributes MUST NOT be encoded as + basic even if their value can fit into two octets. NOTE: This is a + change from IKEv1, where increased flexibility may have simplified + the composer of messages but certainly complicated the parser. + + Attribute Type Value Attribute Format + ------------------------------------------------------------ + RESERVED 0-13 + Key Length (in bits) 14 TV + RESERVED 15-17 + RESERVED TO IANA 18-16383 + PRIVATE USE 16384-32767 + Values 0-13 and 15-17 were used in a similar context in + IKEv1, and should not be assigned except to matching values. + +3.3.6. Attribute Negotiation + + During security association negotiation initiators present offers to + responders. Responders MUST select a single complete set of + parameters from the offers (or reject all offers if none are + acceptable). If there are multiple proposals, the responder MUST + choose a single proposal number and return all of the Proposal + substructures with that Proposal number. If there are multiple + Transforms with the same type, the responder MUST choose a single + one. Any attributes of a selected transform MUST be returned + unmodified. The initiator of an exchange MUST check that the + accepted offer is consistent with one of its proposals, and if not + that response MUST be rejected. + + Negotiating Diffie-Hellman groups presents some special challenges. + SA offers include proposed attributes and a Diffie-Hellman public + number (KE) in the same message. If in the initial exchange the + initiator offers to use one of several Diffie-Hellman groups, it + SHOULD pick the one the responder is most likely to accept and + include a KE corresponding to that group. If the guess turns out to + be wrong, the responder will indicate the correct group in the + response and the initiator SHOULD pick an element of that group for + its KE value when retrying the first message. It SHOULD, however, + continue to propose its full supported set of groups in order to + prevent a man-in-the-middle downgrade attack. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 67] + +Internet-Draft IKEv2bis February 2006 + + + Implementation Note: + + Certain negotiable attributes can have ranges or could have multiple + acceptable values. These include the key length of a variable key + length symmetric cipher. To further interoperability and to support + upgrading endpoints independently, implementers of this protocol + SHOULD accept values that they deem to supply greater security. For + instance, if a peer is configured to accept a variable-length cipher + with a key length of X bits and is offered that cipher with a larger + key length, the implementation SHOULD accept the offer if it supports + use of the longer key. + + Support of this capability allows an implementation to express a + concept of "at least" a certain level of security-- "a key length of + _at least_ X bits for cipher Y". + +3.4. Key Exchange Payload + + The Key Exchange Payload, denoted KE in this memo, is used to + exchange Diffie-Hellman public numbers as part of a Diffie-Hellman + key exchange. The Key Exchange Payload consists of the IKE generic + payload header followed by the Diffie-Hellman public value itself. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! DH Group # ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Key Exchange Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 10: Key Exchange Payload Format + + A key exchange payload is constructed by copying one's Diffie-Hellman + public value into the "Key Exchange Data" portion of the payload. + The length of the Diffie-Hellman public value MUST be equal to the + length of the prime modulus over which the exponentiation was + performed, prepending zero bits to the value if necessary. + + The DH Group # identifies the Diffie-Hellman group in which the Key + Exchange Data was computed (see Section 3.3.2). If the selected + proposal uses a different Diffie-Hellman group, the message MUST be + rejected with a Notify payload of type INVALID_KE_PAYLOAD. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 68] + +Internet-Draft IKEv2bis February 2006 + + + The payload type for the Key Exchange payload is thirty four (34). + +3.5. Identification Payloads + + The Identification Payloads, denoted IDi and IDr in this memo, allow + peers to assert an identity to one another. This identity may be + used for policy lookup, but does not necessarily have to match + anything in the CERT payload; both fields may be used by an + implementation to perform access control decisions. {{ Clarif-7.1 }} + When using the ID_IPV4_ADDR/ID_IPV6_ADDR identity types in IDi/IDr + payloads, IKEv2 does not require this address to match the address in + the IP header of IKEv2 packets, or anything in the TSi/TSr payloads. + The contents of IDi/IDr is used purely to fetch the policy and + authentication data related to the other party. + + NOTE: In IKEv1, two ID payloads were used in each direction to hold + Traffic Selector (TS) information for data passing over the SA. In + IKEv2, this information is carried in TS payloads (see Section 3.13). + + The Identification Payload consists of the IKE generic payload header + followed by identification fields as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ID Type ! RESERVED | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Identification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 11: Identification Payload Format + + o ID Type (1 octet) - Specifies the type of Identification being + used. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Identification Data (variable length) - Value, as indicated by the + Identification Type. The length of the Identification Data is + computed from the size in the ID payload header. + + The payload types for the Identification Payload are thirty five (35) + for IDi and thirty six (36) for IDr. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 69] + +Internet-Draft IKEv2bis February 2006 + + + The following table lists the assigned values for the Identification + Type field: + + ID Type Value + ------------------------------------------------------------------- + RESERVED 0 + + ID_IPV4_ADDR 1 + A single four (4) octet IPv4 address. + + ID_FQDN 2 + A fully-qualified domain name string. An example of a ID_FQDN + is, "example.com". The string MUST not contain any terminators + (e.g., NULL, CR, etc.). + + ID_RFC822_ADDR 3 + A fully-qualified RFC822 email address string, An example of a + ID_RFC822_ADDR is, "jsmith@example.com". The string MUST not + contain any terminators. + + RESERVED TO IANA 4 + + ID_IPV6_ADDR 5 + A single sixteen (16) octet IPv6 address. + + RESERVED TO IANA 6 - 8 + + ID_DER_ASN1_DN 9 + The binary Distinguished Encoding Rules (DER) encoding of an + ASN.1 X.500 Distinguished Name [X.501]. + + ID_DER_ASN1_GN 10 + The binary DER encoding of an ASN.1 X.500 GeneralName [X.509]. + + ID_KEY_ID 11 + An opaque octet stream which may be used to pass vendor- + specific information necessary to do certain proprietary + types of identification. + + RESERVED TO IANA 12-200 + + PRIVATE USE 201-255 + + Two implementations will interoperate only if each can generate a + type of ID acceptable to the other. To assure maximum + interoperability, implementations MUST be configurable to send at + least one of ID_IPV4_ADDR, ID_FQDN, ID_RFC822_ADDR, or ID_KEY_ID, and + MUST be configurable to accept all of these types. Implementations + + + +Kaufman, et al. Expires August 27, 2006 [Page 70] + +Internet-Draft IKEv2bis February 2006 + + + SHOULD be capable of generating and accepting all of these types. + IPv6-capable implementations MUST additionally be configurable to + accept ID_IPV6_ADDR. IPv6-only implementations MAY be configurable + to send only ID_IPV6_ADDR. + + {{ Clarif-3.4 }} EAP [EAP] does not mandate the use of any particular + type of identifier, but often EAP is used with Network Access + Identifiers (NAIs) defined in [NAI]. Although NAIs look a bit like + email addresses (e.g., "joe@example.com"), the syntax is not exactly + the same as the syntax of email address in [MAILFORMAT]. For those + NAIs that include the realm component, the ID_RFC822_ADDR + identification type SHOULD be used. Responder implementations should + not attempt to verify that the contents actually conform to the exact + syntax given in [MAILFORMAT], but instead should accept any + reasonable-looking NAI. For NAIs that do not include the realm + component,the ID_KEY_ID identification type SHOULD be used. + +3.6. Certificate Payload + + The Certificate Payload, denoted CERT in this memo, provides a means + to transport certificates or other authentication-related information + via IKE. Certificate payloads SHOULD be included in an exchange if + certificates are available to the sender unless the peer has + indicated an ability to retrieve this information from elsewhere + using an HTTP_CERT_LOOKUP_SUPPORTED Notify payload. Note that the + term "Certificate Payload" is somewhat misleading, because not all + authentication mechanisms use certificates and data other than + certificates may be passed in this payload. + + The Certificate Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certificate Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 12: Certificate Payload Format + + o Certificate Encoding (1 octet) - This field indicates the type of + certificate or certificate-related information contained in the + Certificate Data field. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 71] + +Internet-Draft IKEv2bis February 2006 + + + Certificate Encoding Value + ------------------------------------------------- + RESERVED 0 + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + X.509 Certificate - Signature 4 + Kerberos Token 6 + Certificate Revocation List (CRL) 7 + Authority Revocation List (ARL) 8 + SPKI Certificate 9 + X.509 Certificate - Attribute 10 + Raw RSA Key 11 + Hash and URL of X.509 certificate 12 + Hash and URL of X.509 bundle 13 + RESERVED to IANA 14 - 200 + PRIVATE USE 201 - 255 + + o Certificate Data (variable length) - Actual encoding of + certificate data. The type of certificate is indicated by the + Certificate Encoding field. + + The payload type for the Certificate Payload is thirty seven (37). + + Specific syntax is for some of the certificate type codes above is + not defined in this document. The types whose syntax is defined in + this document are: + + o X.509 Certificate - Signature (4) contains a DER encoded X.509 + certificate whose public key is used to validate the sender's AUTH + payload. + + o Certificate Revocation List (7) contains a DER encoded X.509 + certificate revocation list. + + o {{ Added "DER-encoded RSAPublicKey structure" from Clarif-3.6 }} + Raw RSA Key (11) contains a PKCS #1 encoded RSA key, that is, a + DER-encoded RSAPublicKey structure (see [RSA] and [PKCS1]). + + o Hash and URL encodings (12-13) allow IKE messages to remain short + by replacing long data structures with a 20 octet SHA-1 hash (see + [SHA]) of the replaced value followed by a variable-length URL + that resolves to the DER encoded data structure itself. This + improves efficiency when the endpoints have certificate data + cached and makes IKE less subject to denial of service attacks + that become easier to mount when IKE messages are large enough to + require IP fragmentation [DOSUDPPROT]. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 72] + +Internet-Draft IKEv2bis February 2006 + + + Use the following ASN.1 definition for an X.509 bundle: + + CertBundle + { iso(1) identified-organization(3) dod(6) internet(1) + security(5) mechanisms(5) pkix(7) id-mod(0) + id-mod-cert-bundle(34) } + + DEFINITIONS EXPLICIT TAGS ::= + BEGIN + + IMPORTS + Certificate, CertificateList + FROM PKIX1Explicit88 + { iso(1) identified-organization(3) dod(6) + internet(1) security(5) mechanisms(5) pkix(7) + id-mod(0) id-pkix1-explicit(18) } ; + + CertificateOrCRL ::= CHOICE { + cert [0] Certificate, + crl [1] CertificateList } + + CertificateBundle ::= SEQUENCE OF CertificateOrCRL + + END + + Implementations MUST be capable of being configured to send and + accept up to four X.509 certificates in support of authentication, + and also MUST be capable of being configured to send and accept the + first two Hash and URL formats (with HTTP URLs). Implementations + SHOULD be capable of being configured to send and accept Raw RSA + keys. If multiple certificates are sent, the first certificate MUST + contain the public key used to sign the AUTH payload. The other + certificates may be sent in any order. + + {{ Clarif-3.6 }} Because the contents and use of some of the + certificate types are not defined, they SHOULD NOT be used. In + specific, implementations SHOULD NOT use the following types unless + they are later defined in a standards-track document: + + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + Kerberos Token 6 + SPKI Certificate 9 + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 73] + +Internet-Draft IKEv2bis February 2006 + + +3.7. Certificate Request Payload + + The Certificate Request Payload, denoted CERTREQ in this memo, + provides a means to request preferred certificates via IKE and can + appear in the IKE_INIT_SA response and/or the IKE_AUTH request. + Certificate Request payloads MAY be included in an exchange when the + sender needs to get the certificate of the receiver. If multiple CAs + are trusted and the cert encoding does not allow a list, then + multiple Certificate Request payloads SHOULD be transmitted. + + The Certificate Request Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certification Authority ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 13: Certificate Request Payload Format + + o Certificate Encoding (1 octet) - Contains an encoding of the type + or format of certificate requested. Values are listed in + Section 3.6. + + o Certification Authority (variable length) - Contains an encoding + of an acceptable certification authority for the type of + certificate requested. + + The payload type for the Certificate Request Payload is thirty eight + (38). + + The Certificate Encoding field has the same values as those defined + in Section 3.6. The Certification Authority field contains an + indicator of trusted authorities for this certificate type. The + Certification Authority value is a concatenated list of SHA-1 hashes + of the public keys of trusted Certification Authorities (CAs). Each + is encoded as the SHA-1 hash of the Subject Public Key Info element + (see section 4.1.2.7 of [PKIX]) from each Trust Anchor certificate. + The twenty-octet hashes are concatenated and included with no other + formatting. + + {{ Clarif-3.6 }} The contents of the "Certification Authority" field + are defined only for X.509 certificates, which are types 4, 10, 12, + + + +Kaufman, et al. Expires August 27, 2006 [Page 74] + +Internet-Draft IKEv2bis February 2006 + + + and 13. Other values SHOULD NOT be used until standards-track + specifications that specify their use are published. + + Note that the term "Certificate Request" is somewhat misleading, in + that values other than certificates are defined in a "Certificate" + payload and requests for those values can be present in a Certificate + Request Payload. The syntax of the Certificate Request payload in + such cases is not defined in this document. + + The Certificate Request Payload is processed by inspecting the "Cert + Encoding" field to determine whether the processor has any + certificates of this type. If so, the "Certification Authority" + field is inspected to determine if the processor has any certificates + that can be validated up to one of the specified certification + authorities. This can be a chain of certificates. + + If an end-entity certificate exists that satisfies the criteria + specified in the CERTREQ, a certificate or certificate chain SHOULD + be sent back to the certificate requestor if the recipient of the + CERTREQ: + + o is configured to use certificate authentication, + + o is allowed to send a CERT payload, + + o has matching CA trust policy governing the current negotiation, + and + + o has at least one time-wise and usage appropriate end-entity + certificate chaining to a CA provided in the CERTREQ. + + Certificate revocation checking must be considered during the + chaining process used to select a certificate. Note that even if two + peers are configured to use two different CAs, cross-certification + relationships should be supported by appropriate selection logic. + + The intent is not to prevent communication through the strict + adherence of selection of a certificate based on CERTREQ, when an + alternate certificate could be selected by the sender that would + still enable the recipient to successfully validate and trust it + through trust conveyed by cross-certification, CRLs, or other out-of- + band configured means. Thus, the processing of a CERTREQ should be + seen as a suggestion for a certificate to select, not a mandated one. + If no certificates exist, then the CERTREQ is ignored. This is not + an error condition of the protocol. There may be cases where there + is a preferred CA sent in the CERTREQ, but an alternate might be + acceptable (perhaps after prompting a human operator). + + + + +Kaufman, et al. Expires August 27, 2006 [Page 75] + +Internet-Draft IKEv2bis February 2006 + + +3.8. Authentication Payload + + The Authentication Payload, denoted AUTH in this memo, contains data + used for authentication purposes. The syntax of the Authentication + data varies according to the Auth Method as specified below. + + The Authentication Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Auth Method ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Authentication Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 14: Authentication Payload Format + + o Auth Method (1 octet) - Specifies the method of authentication + used. Values defined are: + + * RSA Digital Signature (1) - Computed as specified in + Section 2.15 using an RSA private key over a PKCS#1 padded hash + (see [RSA] and [PKCS1]). {{ Clarif-3.2 }} To promote + interoperability, implementations that support this type SHOULD + support signatures that use SHA-1 as the hash function and + SHOULD use SHA-1 as the default hash function when generating + signatures. {{ Clarif-3.3 }} A newer version of PKCS#1 (v2.1) + defines two different encoding methods (ways of "padding the + hash") for signatures. However, IKEv2 and this document point + specifically to the PKCS#1 v2.0 which has only one encoding + method for signatures (EMSA-PKCS1- v1_5). + + * Shared Key Message Integrity Code (2) - Computed as specified + in Section 2.15 using the shared key associated with the + identity in the ID payload and the negotiated prf function + + * DSS Digital Signature (3) - Computed as specified in + Section 2.15 using a DSS private key (see [DSS]) over a SHA-1 + hash. + + * The values 0 and 4-200 are reserved to IANA. The values 201- + 255 are available for private use. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 76] + +Internet-Draft IKEv2bis February 2006 + + + o Authentication Data (variable length) - see Section 2.15. + + The payload type for the Authentication Payload is thirty nine (39). + +3.9. Nonce Payload + + The Nonce Payload, denoted Ni and Nr in this memo for the initiator's + and responder's nonce respectively, contains random data used to + guarantee liveness during an exchange and protect against replay + attacks. + + The Nonce Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Nonce Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 15: Nonce Payload Format + + o Nonce Data (variable length) - Contains the random data generated + by the transmitting entity. + + The payload type for the Nonce Payload is forty (40). + + The size of a Nonce MUST be between 16 and 256 octets inclusive. + Nonce values MUST NOT be reused. + +3.10. Notify Payload + + The Notify Payload, denoted N in this document, is used to transmit + informational data, such as error conditions and state transitions, + to an IKE peer. A Notify Payload may appear in a response message + (usually specifying why a request was rejected), in an INFORMATIONAL + Exchange (to report an error not in an IKE request), or in any other + message to indicate sender capabilities or to modify the meaning of + the request. + + The Notify Payload is defined as follows: + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 77] + +Internet-Draft IKEv2bis February 2006 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! Notify Message Type ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Notification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 16: Notify Payload Format + + o Protocol ID (1 octet) - If this notification concerns an existing + SA, this field indicates the type of that SA. For IKE_SA + notifications, this field MUST be one (1). For notifications + concerning IPsec SAs this field MUST contain either (2) to + indicate AH or (3) to indicate ESP. {{ Clarif-7.8 }} For + notifications that do not relate to an existing SA, this field + MUST be sent as zero and MUST be ignored on receipt; this is + currently only true for the INVALID_SELECTORS and REKEY_SA + notifications. All other values for this field are reserved to + IANA for future assignment. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by the + IPsec protocol ID or zero if no SPI is applicable. For a + notification concerning the IKE_SA, the SPI Size MUST be zero. + + o Notify Message Type (2 octets) - Specifies the type of + notification message. + + o SPI (variable length) - Security Parameter Index. + + o Notification Data (variable length) - Informational or error data + transmitted in addition to the Notify Message Type. Values for + this field are type specific (see below). + + The payload type for the Notify Payload is forty one (41). + +3.10.1. Notify Message Types + + Notification information can be error messages specifying why an SA + could not be established. It can also be status data that a process + + + +Kaufman, et al. Expires August 27, 2006 [Page 78] + +Internet-Draft IKEv2bis February 2006 + + + managing an SA database wishes to communicate with a peer process. + The table below lists the Notification messages and their + corresponding values. The number of different error statuses was + greatly reduced from IKEv1 both for simplification and to avoid + giving configuration information to probers. + + Types in the range 0 - 16383 are intended for reporting errors. An + implementation receiving a Notify payload with one of these types + that it does not recognize in a response MUST assume that the + corresponding request has failed entirely. {{ Demoted the SHOULD }} + Unrecognized error types in a request and status types in a request + or response MUST be ignored, and they should be logged. + + Notify payloads with status types MAY be added to any message and + MUST be ignored if not recognized. They are intended to indicate + capabilities, and as part of SA negotiation are used to negotiate + non-cryptographic parameters. + + NOTIFY messages: error types Value + ------------------------------------------------------------------- + + RESERVED 0 + + UNSUPPORTED_CRITICAL_PAYLOAD 1 + Sent if the payload has the "critical" bit set and the payload + type is not recognized. Notification Data contains the one-octet + payload type. + + INVALID_IKE_SPI 4 + Indicates an IKE message was received with an unrecognized + destination SPI. This usually indicates that the recipient has + rebooted and forgotten the existence of an IKE_SA. + + INVALID_MAJOR_VERSION 5 + Indicates the recipient cannot handle the version of IKE + specified in the header. The closest version number that the + recipient can support will be in the reply header. + + INVALID_SYNTAX 7 + Indicates the IKE message that was received was invalid because + some type, length, or value was out of range or because the + request was rejected for policy reasons. To avoid a denial of + service attack using forged messages, this status may only be + returned for and in an encrypted packet if the message ID and + cryptographic checksum were valid. To avoid leaking information + to someone probing a node, this status MUST be sent in response + to any error not covered by one of the other status types. + {{ Demoted the SHOULD }} To aid debugging, more detailed error + + + +Kaufman, et al. Expires August 27, 2006 [Page 79] + +Internet-Draft IKEv2bis February 2006 + + + information should be written to a console or log. + + INVALID_MESSAGE_ID 9 + Sent when an IKE message ID outside the supported window is + received. This Notify MUST NOT be sent in a response; the invalid + request MUST NOT be acknowledged. Instead, inform the other side + by initiating an INFORMATIONAL exchange with Notification data + containing the four octet invalid message ID. Sending this + notification is optional, and notifications of this type MUST be + rate limited. + + INVALID_SPI 11 + MAY be sent in an IKE INFORMATIONAL exchange when a node receives + an ESP or AH packet with an invalid SPI. The Notification Data + contains the SPI of the invalid packet. This usually indicates a + node has rebooted and forgotten an SA. If this Informational + Message is sent outside the context of an IKE_SA, it should only + be used by the recipient as a "hint" that something might be + wrong (because it could easily be forged). + + NO_PROPOSAL_CHOSEN 14 + None of the proposed crypto suites was acceptable. + + INVALID_KE_PAYLOAD 17 + The D-H Group # field in the KE payload is not the group # + selected by the responder for this exchange. There are two octets + of data associated with this notification: the accepted D-H Group + # in big endian order. + + AUTHENTICATION_FAILED 24 + Sent in the response to an IKE_AUTH message when for some reason + the authentication failed. There is no associated data. + + SINGLE_PAIR_REQUIRED 34 + This error indicates that a CREATE_CHILD_SA request is + unacceptable because its sender is only willing to accept traffic + selectors specifying a single pair of addresses. The requestor is + expected to respond by requesting an SA for only the specific + traffic it is trying to forward. + + NO_ADDITIONAL_SAS 35 + This error indicates that a CREATE_CHILD_SA request is + unacceptable because the responder is unwilling to accept any + more CHILD_SAs on this IKE_SA. Some minimal implementations may + only accept a single CHILD_SA setup in the context of an initial + IKE exchange and reject any subsequent attempts to add more. + + INTERNAL_ADDRESS_FAILURE 36 + + + +Kaufman, et al. Expires August 27, 2006 [Page 80] + +Internet-Draft IKEv2bis February 2006 + + + Indicates an error assigning an internal address (i.e., + INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS) during the + processing of a Configuration Payload by a responder. If this + error is generated within an IKE_AUTH exchange, no CHILD_SA will + be created. + + FAILED_CP_REQUIRED 37 + Sent by responder in the case where CP(CFG_REQUEST) was expected + but not received, and so is a conflict with locally configured + policy. There is no associated data. + + TS_UNACCEPTABLE 38 + Indicates that none of the addresses/protocols/ports in the + supplied traffic selectors is acceptable. + + INVALID_SELECTORS 39 + MAY be sent in an IKE INFORMATIONAL exchange when a node receives + an ESP or AH packet whose selectors do not match those of the SA + on which it was delivered (and that caused the packet to be + dropped). The Notification Data contains the start of the + offending packet (as in ICMP messages) and the SPI field of the + notification is set to match the SPI of the IPsec SA. + + RESERVED TO IANA 40-8191 + + PRIVATE USE 8192-16383 + + + NOTIFY messages: status types Value + ------------------------------------------------------------------- + + INITIAL_CONTACT 16384 + This notification asserts that this IKE_SA is the only IKE_SA + currently active between the authenticated identities. It MAY be + sent when an IKE_SA is established after a crash, and the + recipient MAY use this information to delete any other IKE_SAs it + has to the same authenticated identity without waiting for a + timeout. This notification MUST NOT be sent by an entity that may + be replicated (e.g., a roaming user's credentials where the user + is allowed to connect to the corporate firewall from two remote + systems at the same time). {{ Clarif-7.9 }} The INITIAL_CONTACT + notification, if sent, SHOULD be in the first IKE_AUTH request, + not as a separate exchange afterwards; however, receiving + parties need to deal with it in other requests. + + SET_WINDOW_SIZE 16385 + This notification asserts that the sending endpoint is capable of + keeping state for multiple outstanding exchanges, permitting the + + + +Kaufman, et al. Expires August 27, 2006 [Page 81] + +Internet-Draft IKEv2bis February 2006 + + + recipient to send multiple requests before getting a response to + the first. The data associated with a SET_WINDOW_SIZE + notification MUST be 4 octets long and contain the big endian + representation of the number of messages the sender promises to + keep. Window size is always one until the initial exchanges + complete. + + ADDITIONAL_TS_POSSIBLE 16386 + This notification asserts that the sending endpoint narrowed the + proposed traffic selectors but that other traffic selectors would + also have been acceptable, though only in a separate SA (see + section 2.9). There is no data associated with this Notify type. + It may be sent only as an additional payload in a message + including accepted TSs. + + IPCOMP_SUPPORTED 16387 + This notification may be included only in a message containing an + SA payload negotiating a CHILD_SA and indicates a willingness by + its sender to use IPComp on this SA. The data associated with + this notification includes a two-octet IPComp CPI followed by a + one-octet transform ID optionally followed by attributes whose + length and format are defined by that transform ID. A message + proposing an SA may contain multiple IPCOMP_SUPPORTED + notifications to indicate multiple supported algorithms. A + message accepting an SA may contain at most one. + + The transform IDs currently defined are: + + Name Number Defined In + ------------------------------------- + RESERVED 0 + IPCOMP_OUI 1 + IPCOMP_DEFLATE 2 RFC 2394 + IPCOMP_LZS 3 RFC 2395 + IPCOMP_LZJH 4 RFC 3051 + RESERVED TO IANA 5-240 + PRIVATE USE 241-255 + + NAT_DETECTION_SOURCE_IP 16388 + This notification is used by its recipient to determine whether + the source is behind a NAT box. The data associated with this + notification is a SHA-1 digest of the SPIs (in the order they + appear in the header), IP address, and port on which this packet + was sent. There MAY be multiple Notify payloads of this type in a + message if the sender does not know which of several network + attachments will be used to send the packet. The recipient of + this notification MAY compare the supplied value to a SHA-1 hash + of the SPIs, source IP address, and port, and if they don't match + + + +Kaufman, et al. Expires August 27, 2006 [Page 82] + +Internet-Draft IKEv2bis February 2006 + + + it SHOULD enable NAT traversal (see section 2.23). Alternately, + it MAY reject the connection attempt if NAT traversal is not + supported. + + NAT_DETECTION_DESTINATION_IP 16389 + This notification is used by its recipient to determine whether + it is behind a NAT box. The data associated with this + notification is a SHA-1 digest of the SPIs (in the order they + appear in the header), IP address, and port to which this packet + was sent. The recipient of this notification MAY compare the + supplied value to a hash of the SPIs, destination IP address, and + port, and if they don't match it SHOULD invoke NAT traversal (see + section 2.23). If they don't match, it means that this end is + behind a NAT and this end SHOULD start sending keepalive packets + as defined in [UDPENCAPS]. Alternately, it MAY reject the + connection attempt if NAT traversal is not supported. + + COOKIE 16390 + This notification MAY be included in an IKE_SA_INIT response. It + indicates that the request should be retried with a copy of this + notification as the first payload. This notification MUST be + included in an IKE_SA_INIT request retry if a COOKIE notification + was included in the initial response. The data associated with + this notification MUST be between 1 and 64 octets in length + (inclusive). + + USE_TRANSPORT_MODE 16391 + This notification MAY be included in a request message that also + includes an SA payload requesting a CHILD_SA. It requests that + the CHILD_SA use transport mode rather than tunnel mode for the + SA created. If the request is accepted, the response MUST also + include a notification of type USE_TRANSPORT_MODE. If the + responder declines the request, the CHILD_SA will be established + in tunnel mode. If this is unacceptable to the initiator, the + initiator MUST delete the SA. Note: Except when using this option + to negotiate transport mode, all CHILD_SAs will use tunnel mode. + + Note: The ECN decapsulation modifications specified in + [IPSECARCH] MUST be performed for every tunnel mode SA created + by IKEv2. + + HTTP_CERT_LOOKUP_SUPPORTED 16392 + This notification MAY be included in any message that can include + a CERTREQ payload and indicates that the sender is capable of + looking up certificates based on an HTTP-based URL (and hence + presumably would prefer to receive certificate specifications in + that format). + + + + +Kaufman, et al. Expires August 27, 2006 [Page 83] + +Internet-Draft IKEv2bis February 2006 + + + REKEY_SA 16393 + This notification MUST be included in a CREATE_CHILD_SA exchange + if the purpose of the exchange is to replace an existing ESP or + AH SA. The SPI field identifies the SA being rekeyed. + {{ Clarif-5.4 }} The SPI placed in the REKEY_SA + notification is the SPI the exchange initiator would expect in + inbound ESP or AH packets. There is no data. + + ESP_TFC_PADDING_NOT_SUPPORTED 16394 + This notification asserts that the sending endpoint will NOT + accept packets that contain Flow Confidentiality (TFC) padding. + {{ Clarif-4.5 }} The scope of this message is a single + CHILD_SA, and thus this notification is included in messages + containing an SA payload negotiating a CHILD_SA. If neither + endpoint accepts TFC padding, this notification SHOULD be + included in both the request proposing an SA and the response + accepting it. If this notification is included in only one of + the messages, TFC padding can still be sent in the other + direction. + + NON_FIRST_FRAGMENTS_ALSO 16395 + Used for fragmentation control. See [IPSECARCH] for explanation. + {{ Clarif-4.6 }} Sending non-first fragments is + enabled only if NON_FIRST_FRAGMENTS_ALSO notification is + included in both the request proposing an SA and the response + accepting it. If the peer rejects this proposal, the peer only + omits NON_FIRST_FRAGMENTS_ALSO notification from the response, + but does not reject the whole CHILD_SA creation. + + RESERVED TO IANA 16396-40959 + + PRIVATE USE 40960-65535 + +3.11. Delete Payload + + The Delete Payload, denoted D in this memo, contains a protocol + specific security association identifier that the sender has removed + from its security association database and is, therefore, no longer + valid. Figure 17 shows the format of the Delete Payload. It is + possible to send multiple SPIs in a Delete payload; however, each SPI + MUST be for the same protocol. Mixing of protocol identifiers MUST + NOT be performed in the Delete payload. It is permitted, however, to + include multiple Delete payloads in a single INFORMATIONAL exchange + where each Delete payload lists SPIs for a different protocol. + + Deletion of the IKE_SA is indicated by a protocol ID of 1 (IKE) but + no SPIs. Deletion of a CHILD_SA, such as ESP or AH, will contain the + IPsec protocol ID of that protocol (2 for AH, 3 for ESP), and the SPI + + + +Kaufman, et al. Expires August 27, 2006 [Page 84] + +Internet-Draft IKEv2bis February 2006 + + + is the SPI the sending endpoint would expect in inbound ESP or AH + packets. + + The Delete Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! # of SPIs ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index(es) (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 17: Delete Payload Format + + o Protocol ID (1 octet) - Must be 1 for an IKE_SA, 2 for AH, or 3 + for ESP. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by the + protocol ID. It MUST be zero for IKE (SPI is in message header) + or four for AH and ESP. + + o # of SPIs (2 octets) - The number of SPIs contained in the Delete + payload. The size of each SPI is defined by the SPI Size field. + + o Security Parameter Index(es) (variable length) - Identifies the + specific security association(s) to delete. The length of this + field is determined by the SPI Size and # of SPIs fields. + + The payload type for the Delete Payload is forty two (42). + +3.12. Vendor ID Payload + + The Vendor ID Payload, denoted V in this memo, contains a vendor + defined constant. The constant is used by vendors to identify and + recognize remote instances of their implementations. This mechanism + allows a vendor to experiment with new features while maintaining + backward compatibility. + + A Vendor ID payload MAY announce that the sender is capable to + accepting certain extensions to the protocol, or it MAY simply + identify the implementation as an aid in debugging. A Vendor ID + payload MUST NOT change the interpretation of any information defined + in this specification (i.e., the critical bit MUST be set to 0). + + + +Kaufman, et al. Expires August 27, 2006 [Page 85] + +Internet-Draft IKEv2bis February 2006 + + + Multiple Vendor ID payloads MAY be sent. An implementation is NOT + REQUIRED to send any Vendor ID payload at all. + + A Vendor ID payload may be sent as part of any message. Reception of + a familiar Vendor ID payload allows an implementation to make use of + Private USE numbers described throughout this memo-- private + payloads, private exchanges, private notifications, etc. Unfamiliar + Vendor IDs MUST be ignored. + + Writers of Internet-Drafts who wish to extend this protocol MUST + define a Vendor ID payload to announce the ability to implement the + extension in the Internet-Draft. It is expected that Internet-Drafts + that gain acceptance and are standardized will be given "magic + numbers" out of the Future Use range by IANA, and the requirement to + use a Vendor ID will go away. + + The Vendor ID Payload fields are defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Vendor ID (VID) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 18: Vendor ID Payload Format + + o Vendor ID (variable length) - It is the responsibility of the + person choosing the Vendor ID to assure its uniqueness in spite of + the absence of any central registry for IDs. Good practice is to + include a company name, a person name, or some such. If you want + to show off, you might include the latitude and longitude and time + where you were when you chose the ID and some random input. A + message digest of a long unique string is preferable to the long + unique string itself. + + The payload type for the Vendor ID Payload is forty three (43). + +3.13. Traffic Selector Payload + + The Traffic Selector Payload, denoted TS in this memo, allows peers + to identify packet flows for processing by IPsec security services. + The Traffic Selector Payload consists of the IKE generic payload + header followed by individual traffic selectors as follows: + + + + +Kaufman, et al. Expires August 27, 2006 [Page 86] + +Internet-Draft IKEv2bis February 2006 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Number of TSs ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 19: Traffic Selectors Payload Format + + o Number of TSs (1 octet) - Number of traffic selectors being + provided. + + o RESERVED - This field MUST be sent as zero and MUST be ignored on + receipt. + + o Traffic Selectors (variable length) - One or more individual + traffic selectors. + + The length of the Traffic Selector payload includes the TS header and + all the traffic selectors. + + The payload type for the Traffic Selector payload is forty four (44) + for addresses at the initiator's end of the SA and forty five (45) + for addresses at the responder's end. + + {{ Clarif-4.7 }} There is no requirement that TSi and TSr contain the + same number of individual traffic selectors. Thus, they are + interpreted as follows: a packet matches a given TSi/TSr if it + matches at least one of the individual selectors in TSi, and at least + one of the individual selectors in TSr. + + For instance, the following traffic selectors: + + TSi = ((17, 100, 192.0.1.66-192.0.1.66), + (17, 200, 192.0.1.66-192.0.1.66)) + TSr = ((17, 300, 0.0.0.0-255.255.255.255), + (17, 400, 0.0.0.0-255.255.255.255)) + + would match UDP packets from 192.0.1.66 to anywhere, with any of the + four combinations of source/destination ports (100,300), (100,400), + (200,300), and (200, 400). + + Thus, some types of policies may require several CHILD_SA pairs. For + + + +Kaufman, et al. Expires August 27, 2006 [Page 87] + +Internet-Draft IKEv2bis February 2006 + + + instance, a policy matching only source/destination ports (100,300) + and (200,400), but not the other two combinations, cannot be + negotiated as a single CHILD_SA pair. + +3.13.1. Traffic Selector + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! TS Type !IP Protocol ID*| Selector Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | Start Port* | End Port* | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Starting Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Ending Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 20: Traffic Selector + + *Note: All fields other than TS Type and Selector Length depend on + the TS Type. The fields shown are for TS Types 7 and 8, the only two + values currently defined. + + o TS Type (one octet) - Specifies the type of traffic selector. + + o IP protocol ID (1 octet) - Value specifying an associated IP + protocol ID (e.g., UDP/TCP/ICMP). A value of zero means that the + protocol ID is not relevant to this traffic selector-- the SA can + carry all protocols. + + o Selector Length - Specifies the length of this Traffic Selector + Substructure including the header. + + o Start Port (2 octets) - Value specifying the smallest port number + allowed by this Traffic Selector. For protocols for which port is + undefined, or if all ports are allowed, this field MUST be zero. + For the ICMP protocol, the two one-octet fields Type and Code are + treated as a single 16-bit integer (with Type in the most + significant eight bits and Code in the least significant eight + bits) port number for the purposes of filtering based on this + field. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 88] + +Internet-Draft IKEv2bis February 2006 + + + o End Port (2 octets) - Value specifying the largest port number + allowed by this Traffic Selector. For protocols for which port is + undefined, or if all ports are allowed, this field MUST be 65535. + For the ICMP protocol, the two one-octet fields Type and Code are + treated as a single 16-bit integer (with Type in the most + significant eight bits and Code in the least significant eight + bits) port number for the purposed of filtering based on this + field. + + o Starting Address - The smallest address included in this Traffic + Selector (length determined by TS type). + + o Ending Address - The largest address included in this Traffic + Selector (length determined by TS type). + + Systems that are complying with [IPSECARCH] that wish to indicate + "ANY" ports MUST set the start port to 0 and the end port to 65535; + note that according to [IPSECARCH], "ANY" includes "OPAQUE". Systems + working with [IPSECARCH] that wish to indicate "OPAQUE" ports, but + not "ANY" ports, MUST set the start port to 65535 and the end port to + 0. + + {{ Added from Clarif-4.8 }} The traffic selector types 7 and 8 can + also refer to ICMP type and code fields. Note, however, that ICMP + packets do not have separate source and destination port fields. The + method for specifying the traffic selectors for ICMP is shown by + example in Section 4.4.1.3 of [IPSECARCH]. + + {{ Added from Clarif-4.9 }} Traffic selectors can use IP Protocol ID + 135 to match the IPv6 mobility header [MIPV6]. This document does + not specify how to represent the "MH Type" field in traffic + selectors, although it is likely that a different document will + specify this in the future. Note that [IPSECARCH] says that the IPv6 + mobility header (MH) message type is placed in the most significant + eight bits of the 16-bit local port selector. The direction + semantics of TSi/TSr port fields are the same as for ICMP. + + The following table lists the assigned values for the Traffic + Selector Type field and the corresponding Address Selector Data. + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 89] + +Internet-Draft IKEv2bis February 2006 + + + TS Type Value + ------------------------------------------------------------------- + RESERVED 0-6 + + TS_IPV4_ADDR_RANGE 7 + + A range of IPv4 addresses, represented by two four-octet + values. The first value is the beginning IPv4 address + (inclusive) and the second value is the ending IPv4 address + (inclusive). All addresses falling between the two specified + addresses are considered to be within the list. + + TS_IPV6_ADDR_RANGE 8 + + A range of IPv6 addresses, represented by two sixteen-octet + values. The first value is the beginning IPv6 address + (inclusive) and the second value is the ending IPv6 address + (inclusive). All addresses falling between the two specified + addresses are considered to be within the list. + + RESERVED TO IANA 9-240 + PRIVATE USE 241-255 + +3.14. Encrypted Payload + + The Encrypted Payload, denoted SK{...} or E in this memo, contains + other payloads in encrypted form. The Encrypted Payload, if present + in a message, MUST be the last payload in the message. Often, it is + the only payload in the message. + + The algorithms for encryption and integrity protection are negotiated + during IKE_SA setup, and the keys are computed as specified in + Section 2.14 and Section 2.18. + + The encryption and integrity protection algorithms are modeled after + the ESP algorithms described in RFCs 2104 [HMAC], 4303 [ESP], and + 2451 [ESPCBC]. This document completely specifies the cryptographic + processing of IKE data, but those documents should be consulted for + design rationale. We require a block cipher with a fixed block size + and an integrity check algorithm that computes a fixed-length + checksum over a variable size message. + + The payload type for an Encrypted payload is forty six (46). The + Encrypted Payload consists of the IKE generic payload header followed + by individual fields as follows: + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 90] + +Internet-Draft IKEv2bis February 2006 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Initialization Vector ! + ! (length is block size for encryption algorithm) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Encrypted IKE Payloads ~ + + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! Padding (0-255 octets) ! + +-+-+-+-+-+-+-+-+ +-+-+-+-+-+-+-+-+ + ! ! Pad Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Integrity Checksum Data ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 21: Encrypted Payload Format + + o Next Payload - The payload type of the first embedded payload. + Note that this is an exception in the standard header format, + since the Encrypted payload is the last payload in the message and + therefore the Next Payload field would normally be zero. But + because the content of this payload is embedded payloads and there + was no natural place to put the type of the first one, that type + is placed here. + + o Payload Length - Includes the lengths of the header, IV, Encrypted + IKE Payloads, Padding, Pad Length, and Integrity Checksum Data. + + o Initialization Vector - A randomly chosen value whose length is + equal to the block length of the underlying encryption algorithm. + Recipients MUST accept any value. Senders SHOULD either pick this + value pseudo-randomly and independently for each message or use + the final ciphertext block of the previous message sent. Senders + MUST NOT use the same value for each message, use a sequence of + values with low hamming distance (e.g., a sequence number), or use + ciphertext from a received message. + + o IKE Payloads are as specified earlier in this section. This field + is encrypted with the negotiated cipher. + + o Padding MAY contain any value chosen by the sender, and MUST have + a length that makes the combination of the Payloads, the Padding, + and the Pad Length to be a multiple of the encryption block size. + This field is encrypted with the negotiated cipher. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 91] + +Internet-Draft IKEv2bis February 2006 + + + o Pad Length is the length of the Padding field. The sender SHOULD + set the Pad Length to the minimum value that makes the combination + of the Payloads, the Padding, and the Pad Length a multiple of the + block size, but the recipient MUST accept any length that results + in proper alignment. This field is encrypted with the negotiated + cipher. + + o Integrity Checksum Data is the cryptographic checksum of the + entire message starting with the Fixed IKE Header through the Pad + Length. The checksum MUST be computed over the encrypted message. + Its length is determined by the integrity algorithm negotiated. + +3.15. Configuration Payload + + The Configuration payload, denoted CP in this document, is used to + exchange configuration information between IKE peers. The exchange + is for an IRAC to request an internal IP address from an IRAS and to + exchange other information of the sort that one would acquire with + Dynamic Host Configuration Protocol (DHCP) if the IRAC were directly + connected to a LAN. + + Configuration payloads are of type CFG_REQUEST/CFG_REPLY or CFG_SET/ + CFG_ACK (see CFG Type in the payload description below). CFG_REQUEST + and CFG_SET payloads may optionally be added to any IKE request. The + IKE response MUST include either a corresponding CFG_REPLY or CFG_ACK + or a Notify payload with an error type indicating why the request + could not be honored. An exception is that a minimal implementation + MAY ignore all CFG_REQUEST and CFG_SET payloads, so a response + message without a corresponding CFG_REPLY or CFG_ACK MUST be accepted + as an indication that the request was not supported. + + "CFG_REQUEST/CFG_REPLY" allows an IKE endpoint to request information + from its peer. If an attribute in the CFG_REQUEST Configuration + Payload is not zero-length, it is taken as a suggestion for that + attribute. The CFG_REPLY Configuration Payload MAY return that + value, or a new one. It MAY also add new attributes and not include + some requested ones. Requestors MUST ignore returned attributes that + they do not recognize. + + Some attributes MAY be multi-valued, in which case multiple attribute + values of the same type are sent and/or returned. Generally, all + values of an attribute are returned when the attribute is requested. + For some attributes (in this version of the specification only + internal addresses), multiple requests indicates a request that + multiple values be assigned. For these attributes, the number of + values returned SHOULD NOT exceed the number requested. + + If the data type requested in a CFG_REQUEST is not recognized or not + + + +Kaufman, et al. Expires August 27, 2006 [Page 92] + +Internet-Draft IKEv2bis February 2006 + + + supported, the responder MUST NOT return an error type but rather + MUST either send a CFG_REPLY that MAY be empty or a reply not + containing a CFG_REPLY payload at all. Error returns are reserved + for cases where the request is recognized but cannot be performed as + requested or the request is badly formatted. + + "CFG_SET/CFG_ACK" allows an IKE endpoint to push configuration data + to its peer. In this case, the CFG_SET Configuration Payload + contains attributes the initiator wants its peer to alter. The + responder MUST return a Configuration Payload if it accepted any of + the configuration data and it MUST contain the attributes that the + responder accepted with zero-length data. Those attributes that it + did not accept MUST NOT be in the CFG_ACK Configuration Payload. If + no attributes were accepted, the responder MUST return either an + empty CFG_ACK payload or a response message without a CFG_ACK + payload. There are currently no defined uses for the CFG_SET/CFG_ACK + exchange, though they may be used in connection with extensions based + on Vendor IDs. An minimal implementation of this specification MAY + ignore CFG_SET payloads. + + {{ Demoted the SHOULD }} Extensions via the CP payload should not be + used for general purpose management. Its main intent is to provide a + bootstrap mechanism to exchange information within IPsec from IRAS to + IRAC. While it MAY be useful to use such a method to exchange + information between some Security Gateways (SGW) or small networks, + existing management protocols such as DHCP [DHCP], RADIUS [RADIUS], + SNMP, or LDAP [LDAP] should be preferred for enterprise management as + well as subsequent information exchanges. + + The Configuration Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! CFG Type ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Configuration Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 22: Configuration Payload Format + + The payload type for the Configuration Payload is forty seven (47). + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 93] + +Internet-Draft IKEv2bis February 2006 + + + o CFG Type (1 octet) - The type of exchange represented by the + Configuration Attributes. + + CFG Type Value + -------------------------- + RESERVED 0 + CFG_REQUEST 1 + CFG_REPLY 2 + CFG_SET 3 + CFG_ACK 4 + RESERVED TO IANA 5-127 + PRIVATE USE 128-255 + + o RESERVED (3 octets) - MUST be sent as zero; MUST be ignored on + receipt. + + o Configuration Attributes (variable length) - These are type length + values specific to the Configuration Payload and are defined + below. There may be zero or more Configuration Attributes in this + payload. + +3.15.1. Configuration Attributes + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !R| Attribute Type ! Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | | + ~ Value ~ + | | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 23: Configuration Attribute Format + + o Reserved (1 bit) - This bit MUST be set to zero and MUST be + ignored on receipt. + + o Attribute Type (15 bits) - A unique identifier for each of the + Configuration Attribute Types. + + o Length (2 octets) - Length in octets of Value. + + o Value (0 or more octets) - The variable-length value of this + Configuration Attribute. The following attribute types have been + defined: + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 94] + +Internet-Draft IKEv2bis February 2006 + + + Multi- + Attribute Type Value Valued Length + ------------------------------------------------------- + RESERVED 0 + INTERNAL_IP4_ADDRESS 1 YES* 0 or 4 octets + INTERNAL_IP4_NETMASK 2 NO 0 or 4 octets + INTERNAL_IP4_DNS 3 YES 0 or 4 octets + INTERNAL_IP4_NBNS 4 YES 0 or 4 octets + INTERNAL_ADDRESS_EXPIRY 5 NO 0 or 4 octets + INTERNAL_IP4_DHCP 6 YES 0 or 4 octets + APPLICATION_VERSION 7 NO 0 or more + INTERNAL_IP6_ADDRESS 8 YES* 0 or 17 octets + RESERVED 9 + INTERNAL_IP6_DNS 10 YES 0 or 16 octets + INTERNAL_IP6_NBNS 11 YES 0 or 16 octets + INTERNAL_IP6_DHCP 12 YES 0 or 16 octets + INTERNAL_IP4_SUBNET 13 YES 0 or 8 octets + SUPPORTED_ATTRIBUTES 14 NO Multiple of 2 + INTERNAL_IP6_SUBNET 15 YES 17 octets + RESERVED TO IANA 16-16383 + PRIVATE USE 16384-32767 + + * These attributes may be multi-valued on return only if + multiple values were requested. + + o INTERNAL_IP4_ADDRESS, INTERNAL_IP6_ADDRESS - An address on the + internal network, sometimes called a red node address or private + address and MAY be a private address on the Internet. {{ + Clarif-6.2}} In a request message, the address specified is a + requested address (or a zero-length address if no specific address + is requested). If a specific address is requested, it likely + indicates that a previous connection existed with this address and + the requestor would like to reuse that address. With IPv6, a + requestor MAY supply the low-order address bytes it wants to use. + Multiple internal addresses MAY be requested by requesting + multiple internal address attributes. The responder MAY only send + up to the number of addresses requested. The INTERNAL_IP6_ADDRESS + is made up of two fields: the first is a 16-octet IPv6 address, + and the second is a one-octet prefix-length as defined in + [ADDRIPV6]. + + The requested address is valid until the expiry time defined with + the INTERNAL_ADDRESS_EXPIRY attribute or there are no IKE_SAs + between the peers. + + o INTERNAL_IP4_NETMASK - The internal network's netmask. Only one + netmask is allowed in the request and reply messages (e.g., + 255.255.255.0), and it MUST be used only with an + + + +Kaufman, et al. Expires August 27, 2006 [Page 95] + +Internet-Draft IKEv2bis February 2006 + + + INTERNAL_IP4_ADDRESS attribute. {{ Clarif-6.4 }} + INTERNAL_IP4_NETMASK in a CFG_REPLY means roughly the same thing + as INTERNAL_IP4_SUBNET containing the same information ("send + traffic to these addresses through me"), but also implies a link + boundary. For instance, the client could use its own address and + the netmask to calculate the broadcast address of the link. An + empty INTERNAL_IP4_NETMASK attribute can be included in a + CFG_REQUEST to request this information (although the gateway can + send the information even when not requested). Non-empty values + for this attribute in a CFG_REQUEST do not make sense and thus + MUST NOT be included. + + o INTERNAL_IP4_DNS, INTERNAL_IP6_DNS - Specifies an address of a DNS + server within the network. Multiple DNS servers MAY be requested. + The responder MAY respond with zero or more DNS server attributes. + + o INTERNAL_IP4_NBNS, INTERNAL_IP6_NBNS - Specifies an address of a + NetBios Name Server (WINS) within the network. Multiple NBNS + servers MAY be requested. The responder MAY respond with zero or + more NBNS server attributes. {{ Clarif-6.6 }} NetBIOS is not + defined for IPv6; therefore, INTERNAL_IP6_NBNS SHOULD NOT be used. + + o INTERNAL_ADDRESS_EXPIRY - Specifies the number of seconds that the + host can use the internal IP address. The host MUST renew the IP + address before this expiry time. Only one of these attributes MAY + be present in the reply. {{ Clarif-6.7 }} Expiry times and + explicit renewals are primarily useful in environments like DHCP, + where the server cannot reliably know when the client has gone + away. However, in IKEv2, this is known, and the gateway can + simply free the address when the IKE_SA is deleted. Further, + supporting renewals is not mandatory. Thus + INTERNAL_ADDRESS_EXPIRY attribute MUST NOT be used. + + o INTERNAL_IP4_DHCP, INTERNAL_IP6_DHCP - Instructs the host to send + any internal DHCP requests to the address contained within the + attribute. Multiple DHCP servers MAY be requested. The responder + MAY respond with zero or more DHCP server attributes. + + o APPLICATION_VERSION - The version or application information of + the IPsec host. This is a string of printable ASCII characters + that is NOT null terminated. + + o INTERNAL_IP4_SUBNET - The protected sub-networks that this edge- + device protects. This attribute is made up of two fields: the + first being an IP address and the second being a netmask. + Multiple sub-networks MAY be requested. The responder MAY respond + with zero or more sub-network attributes. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 96] + +Internet-Draft IKEv2bis February 2006 + + + o SUPPORTED_ATTRIBUTES - When used within a Request, this attribute + MUST be zero-length and specifies a query to the responder to + reply back with all of the attributes that it supports. The + response contains an attribute that contains a set of attribute + identifiers each in 2 octets. The length divided by 2 (octets) + would state the number of supported attributes contained in the + response. + + o INTERNAL_IP6_SUBNET - The protected sub-networks that this edge- + device protects. This attribute is made up of two fields: the + first is a 16-octet IPv6 address, and the second is a one-octet + prefix-length as defined in [ADDRIPV6]. Multiple sub-networks MAY + be requested. The responder MAY respond with zero or more sub- + network attributes. + + Note that no recommendations are made in this document as to how an + implementation actually figures out what information to send in a + reply. That is, we do not recommend any specific method of an IRAS + determining which DNS server should be returned to a requesting IRAC. + +3.15.2. Meaning of INTERNAL_IP4_SUBNET/INTERNAL_IP6_SUBNET + + {{ Section added based on Clarif-6.3 }} + + INTERNAL_IP4/6_SUBNET attributes can indicate additional subnets, + ones that need one or more separate SAs, that can be reached through + the gateway that announces the attributes. INTERNAL_IP4/6_SUBNET + attributes may also express the gateway's policy about what traffic + should be sent through the gateway; the client can choose whether + other traffic (covered by TSr, but not in INTERNAL_IP4/6_SUBNET) is + sent through the gateway or directly to the destination. Thus, + traffic to the addresses listed in the INTERNAL_IP4/6_SUBNET + attributes should be sent through the gateway that announces the + attributes. If there are no existing IPsec SAs whose traffic + selectors cover the address in question, new SAs need to be created. + + For instance, if there are two subnets, 192.0.1.0/26 and + 192.0.2.0/24, and the client's request contains the following: + + CP(CFG_REQUEST) = + INTERNAL_IP4_ADDRESS() + TSi = (0, 0-65535, 0.0.0.0-255.255.255.255) + TSr = (0, 0-65535, 0.0.0.0-255.255.255.255) + + then a valid response could be the following (in which TSr and + INTERNAL_IP4_SUBNET contain the same information): + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 97] + +Internet-Draft IKEv2bis February 2006 + + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = ((0, 0-65535, 192.0.1.0-192.0.1.63), + (0, 0-65535, 192.0.2.0-192.0.2.255)) + + In these cases, the INTERNAL_IP4_SUBNET does not really carry any + useful information. + + A different possible reply would have been this: + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 0.0.0.0-255.255.255.255) + + That reply would mean that the client can send all its traffic + through the gateway, but the gateway does not mind if the client + sends traffic not included by INTERNAL_IP4_SUBNET directly to the + destination (without going through the gateway). + + A different situation arises if the gateway has a policy that + requires the traffic for the two subnets to be carried in separate + SAs. Then a response like this would indicate to the client that if + it wants access to the second subnet, it needs to create a separate + SA: + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 192.0.1.0-192.0.1.63) + + INTERNAL_IP4_SUBNET can also be useful if the client's TSr included + only part of the address space. For instance, if the client requests + the following: + + CP(CFG_REQUEST) = + INTERNAL_IP4_ADDRESS() + TSi = (0, 0-65535, 0.0.0.0-255.255.255.255) + TSr = (0, 0-65535, 192.0.2.155-192.0.2.155) + + then the gateway's reply might be: + + + +Kaufman, et al. Expires August 27, 2006 [Page 98] + +Internet-Draft IKEv2bis February 2006 + + + CP(CFG_REPLY) = + INTERNAL_IP4_ADDRESS(192.0.1.234) + INTERNAL_IP4_SUBNET(192.0.1.0/255.255.255.192) + INTERNAL_IP4_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535, 192.0.1.234-192.0.1.234) + TSr = (0, 0-65535, 192.0.2.155-192.0.2.155) + + Because the meaning of INTERNAL_IP4_SUBNET/INTERNAL_IP6_SUBNET is in + CFG_REQUESTs is unclear, they cannot be used reliably in + CFG_REQUESTs. + +3.15.3. Configuration payloads for IPv6 + + {{ Added this section from Clarif-6.5 }} + + The configuration payloads for IPv6 are based on the corresponding + IPv4 payloads, and do not fully follow the "normal IPv6 way of doing + things". In particular, IPv6 stateless autoconfiguration or router + advertisement messages are not used; neither is neighbor discovery. + + A client can be assigned an IPv6 address using the + INTERNAL_IP6_ADDRESS configuration payload. A minimal exchange might + look like this: + + CP(CFG_REQUEST) = + INTERNAL_IP6_ADDRESS() + INTERNAL_IP6_DNS() + TSi = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + TSr = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + + CP(CFG_REPLY) = + INTERNAL_IP6_ADDRESS(2001:DB8:0:1:2:3:4:5/64) + INTERNAL_IP6_DNS(2001:DB8:99:88:77:66:55:44) + TSi = (0, 0-65535, 2001:DB8:0:1:2:3:4:5 - 2001:DB8:0:1:2:3:4:5) + TSr = (0, 0-65535, :: - FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF) + + The client MAY send a non-empty INTERNAL_IP6_ADDRESS attribute in the + CFG_REQUEST to request a specific address or interface identifier. + The gateway first checks if the specified address is acceptable, and + if it is, returns that one. If the address was not acceptable, the + gateway attempts to use the interface identifier with some other + prefix; if even that fails, the gateway selects another interface + identifier. + + The INTERNAL_IP6_ADDRESS attribute also contains a prefix length + field. When used in a CFG_REPLY, this corresponds to the + INTERNAL_IP4_NETMASK attribute in the IPv4 case. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 99] + +Internet-Draft IKEv2bis February 2006 + + + Although this approach to configuring IPv6 addresses is reasonably + simple, it has some limitations. IPsec tunnels configured using + IKEv2 are not fully-featured "interfaces" in the IPv6 addressing + architecture sense [IPV6ADDR]. In particular, they do not + necessarily have link-local addresses, and this may complicate the + use of protocols that assume them, such as [MLDV2]. + +3.15.4. Address Assignment Failures + + {{ Added this section from Clarif-6.8 }} + + If the responder encounters an error while attempting to assign an IP + address to the initiator, it responds with an + INTERNAL_ADDRESS_FAILURE notification. However, there are some more + complex error cases. + + If the responder does not support configuration payloads at all, it + can simply ignore all configuration payloads. This type of + implementation never sends INTERNAL_ADDRESS_FAILURE notifications. + If the initiator requires the assignment of an IP address, it will + treat a response without CFG_REPLY as an error. + + The initiator may request a particular type of address (IPv4 or IPv6) + that the responder does not support, even though the responder + supports configuration payloads. In this case, the responder simply + ignores the type of address it does not support and processes the + rest of the request as usual. + + If the initiator requests multiple addresses of a type that the + responder supports, and some (but not all) of the requests fail, the + responder replies with the successful addresses only. The responder + sends INTERNAL_ADDRESS_FAILURE only if no addresses can be assigned. + +3.16. Extensible Authentication Protocol (EAP) Payload + + The Extensible Authentication Protocol Payload, denoted EAP in this + memo, allows IKE_SAs to be authenticated using the protocol defined + in RFC 3748 [EAP] and subsequent extensions to that protocol. The + full set of acceptable values for the payload is defined elsewhere, + but a short summary of RFC 3748 is included here to make this + document stand alone in the common cases. + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 100] + +Internet-Draft IKEv2bis February 2006 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ EAP Message ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 24: EAP Payload Format + + The payload type for an EAP Payload is forty eight (48). + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Code ! Identifier ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Type ! Type_Data... + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+- + + Figure 25: EAP Message Format + + o Code (1 octet) indicates whether this message is a Request (1), + Response (2), Success (3), or Failure (4). + + o Identifier (1 octet) is used in PPP to distinguish replayed + messages from repeated ones. Since in IKE, EAP runs over a + reliable protocol, it serves no function here. In a response + message, this octet MUST be set to match the identifier in the + corresponding request. In other messages, this field MAY be set + to any value. + + o Length (2 octets) is the length of the EAP message and MUST be + four less than the Payload Length of the encapsulating payload. + + o Type (1 octet) is present only if the Code field is Request (1) or + Response (2). For other codes, the EAP message length MUST be + four octets and the Type and Type_Data fields MUST NOT be present. + In a Request (1) message, Type indicates the data being requested. + In a Response (2) message, Type MUST either be Nak or match the + type of the data requested. The following types are defined in + RFC 3748: + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 101] + +Internet-Draft IKEv2bis February 2006 + + + 1 Identity + 2 Notification + 3 Nak (Response Only) + 4 MD5-Challenge + 5 One-Time Password (OTP) + 6 Generic Token Card + + o Type_Data (Variable Length) varies with the Type of Request and + the associated Response. For the documentation of the EAP + methods, see [EAP]. + + {{ Demoted the SHOULD NOT and SHOULD }} Note that since IKE passes an + indication of initiator identity in message 3 of the protocol, the + responder should not send EAP Identity requests. The initiator may, + however, respond to such requests if it receives them. + + +4. Conformance Requirements + + In order to assure that all implementations of IKEv2 can + interoperate, there are "MUST support" requirements in addition to + those listed elsewhere. Of course, IKEv2 is a security protocol, and + one of its major functions is to allow only authorized parties to + successfully complete establishment of SAs. So a particular + implementation may be configured with any of a number of restrictions + concerning algorithms and trusted authorities that will prevent + universal interoperability. + + IKEv2 is designed to permit minimal implementations that can + interoperate with all compliant implementations. There are a series + of optional features that can easily be ignored by a particular + implementation if it does not support that feature. Those features + include: + + o Ability to negotiate SAs through a NAT and tunnel the resulting + ESP SA over UDP. + + o Ability to request (and respond to a request for) a temporary IP + address on the remote end of a tunnel. + + o Ability to support various types of legacy authentication. + + o Ability to support window sizes greater than one. + + o Ability to establish multiple ESP and/or AH SAs within a single + IKE_SA. + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 102] + +Internet-Draft IKEv2bis February 2006 + + + o Ability to rekey SAs. + + To assure interoperability, all implementations MUST be capable of + parsing all payload types (if only to skip over them) and to ignore + payload types that it does not support unless the critical bit is set + in the payload header. If the critical bit is set in an unsupported + payload header, all implementations MUST reject the messages + containing those payloads. + + Every implementation MUST be capable of doing four-message + IKE_SA_INIT and IKE_AUTH exchanges establishing two SAs (one for IKE, + one for ESP and/or AH). Implementations MAY be initiate-only or + respond-only if appropriate for their platform. Every implementation + MUST be capable of responding to an INFORMATIONAL exchange, but a + minimal implementation MAY respond to any INFORMATIONAL message with + an empty INFORMATIONAL reply (note that within the context of an + IKE_SA, an "empty" message consists of an IKE header followed by an + Encrypted payload with no payloads contained in it). A minimal + implementation MAY support the CREATE_CHILD_SA exchange only in so + far as to recognize requests and reject them with a Notify payload of + type NO_ADDITIONAL_SAS. A minimal implementation need not be able to + initiate CREATE_CHILD_SA or INFORMATIONAL exchanges. When an SA + expires (based on locally configured values of either lifetime or + octets passed), and implementation MAY either try to renew it with a + CREATE_CHILD_SA exchange or it MAY delete (close) the old SA and + create a new one. If the responder rejects the CREATE_CHILD_SA + request with a NO_ADDITIONAL_SAS notification, the implementation + MUST be capable of instead deleting the old SA and creating a new + one. + + Implementations are not required to support requesting temporary IP + addresses or responding to such requests. If an implementation does + support issuing such requests, it MUST include a CP payload in + message 3 containing at least a field of type INTERNAL_IP4_ADDRESS or + INTERNAL_IP6_ADDRESS. All other fields are optional. If an + implementation supports responding to such requests, it MUST parse + the CP payload of type CFG_REQUEST in message 3 and recognize a field + of type INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS. If it supports + leasing an address of the appropriate type, it MUST return a CP + payload of type CFG_REPLY containing an address of the requested + type. {{ Demoted the SHOULD }} The responder may include any other + related attributes. + + A minimal IPv4 responder implementation will ignore the contents of + the CP payload except to determine that it includes an + INTERNAL_IP4_ADDRESS attribute and will respond with the address and + other related attributes regardless of whether the initiator + requested them. + + + +Kaufman, et al. Expires August 27, 2006 [Page 103] + +Internet-Draft IKEv2bis February 2006 + + + A minimal IPv4 initiator will generate a CP payload containing only + an INTERNAL_IP4_ADDRESS attribute and will parse the response + ignoring attributes it does not know how to use. {{ Clarif-6.7 + removes the sentence about processing INTERNAL_ADDRESS_EXPIRY. }} + Minimal initiators need not be able to request lease renewals and + minimal responders need not respond to them. + + For an implementation to be called conforming to this specification, + it MUST be possible to configure it to accept the following: + + o PKIX Certificates containing and signed by RSA keys of size 1024 + or 2048 bits, where the ID passed is any of ID_KEY_ID, ID_FQDN, + ID_RFC822_ADDR, or ID_DER_ASN1_DN. + + o Shared key authentication where the ID passes is any of ID_KEY_ID, + ID_FQDN, or ID_RFC822_ADDR. + + o Authentication where the responder is authenticated using PKIX + Certificates and the initiator is authenticated using shared key + authentication. + + +5. Security Considerations + + While this protocol is designed to minimize disclosure of + configuration information to unauthenticated peers, some such + disclosure is unavoidable. One peer or the other must identify + itself first and prove its identity first. To avoid probing, the + initiator of an exchange is required to identify itself first, and + usually is required to authenticate itself first. The initiator can, + however, learn that the responder supports IKE and what cryptographic + protocols it supports. The responder (or someone impersonating the + responder) can probe the initiator not only for its identity, but + using CERTREQ payloads may be able to determine what certificates the + initiator is willing to use. + + Use of EAP authentication changes the probing possibilities somewhat. + When EAP authentication is used, the responder proves its identity + before the initiator does, so an initiator that knew the name of a + valid initiator could probe the responder for both its name and + certificates. + + Repeated rekeying using CREATE_CHILD_SA without additional Diffie- + Hellman exchanges leaves all SAs vulnerable to cryptanalysis of a + single key or overrun of either endpoint. Implementers should take + note of this fact and set a limit on CREATE_CHILD_SA exchanges + between exponentiations. This memo does not prescribe such a limit. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 104] + +Internet-Draft IKEv2bis February 2006 + + + The strength of a key derived from a Diffie-Hellman exchange using + any of the groups defined here depends on the inherent strength of + the group, the size of the exponent used, and the entropy provided by + the random number generator used. Due to these inputs, it is + difficult to determine the strength of a key for any of the defined + groups. Diffie-Hellman group number two, when used with a strong + random number generator and an exponent no less than 200 bits, is + common for use with 3DES. Group five provides greater security than + group two. Group one is for historic purposes only and does not + provide sufficient strength except for use with DES, which is also + for historic use only. Implementations should make note of these + estimates when establishing policy and negotiating security + parameters. + + Note that these limitations are on the Diffie-Hellman groups + themselves. There is nothing in IKE that prohibits using stronger + groups nor is there anything that will dilute the strength obtained + from stronger groups (limited by the strength of the other algorithms + negotiated including the prf function). In fact, the extensible + framework of IKE encourages the definition of more groups; use of + elliptical curve groups may greatly increase strength using much + smaller numbers. + + It is assumed that all Diffie-Hellman exponents are erased from + memory after use. In particular, these exponents MUST NOT be derived + from long-lived secrets like the seed to a pseudo-random generator + that is not erased after use. + + The strength of all keys is limited by the size of the output of the + negotiated prf function. For this reason, a prf function whose + output is less than 128 bits (e.g., 3DES-CBC) MUST NOT be used with + this protocol. + + The security of this protocol is critically dependent on the + randomness of the randomly chosen parameters. These should be + generated by a strong random or properly seeded pseudo-random source + (see [RANDOMNESS]). Implementers should take care to ensure that use + of random numbers for both keys and nonces is engineered in a fashion + that does not undermine the security of the keys. + + For information on the rationale of many of the cryptographic design + choices in this protocol, see [SIGMA] and [SKEME]. Though the + security of negotiated CHILD_SAs does not depend on the strength of + the encryption and integrity protection negotiated in the IKE_SA, + implementations MUST NOT negotiate NONE as the IKE integrity + protection algorithm or ENCR_NULL as the IKE encryption algorithm. + + When using pre-shared keys, a critical consideration is how to assure + + + +Kaufman, et al. Expires August 27, 2006 [Page 105] + +Internet-Draft IKEv2bis February 2006 + + + the randomness of these secrets. The strongest practice is to ensure + that any pre-shared key contain as much randomness as the strongest + key being negotiated. Deriving a shared secret from a password, + name, or other low-entropy source is not secure. These sources are + subject to dictionary and social engineering attacks, among others. + + The NAT_DETECTION_*_IP notifications contain a hash of the addresses + and ports in an attempt to hide internal IP addresses behind a NAT. + Since the IPv4 address space is only 32 bits, and it is usually very + sparse, it would be possible for an attacker to find out the internal + address used behind the NAT box by trying all possible IP addresses + and trying to find the matching hash. The port numbers are normally + fixed to 500, and the SPIs can be extracted from the packet. This + reduces the number of hash calculations to 2^32. With an educated + guess of the use of private address space, the number of hash + calculations is much smaller. Designers should therefore not assume + that use of IKE will not leak internal address information. + + When using an EAP authentication method that does not generate a + shared key for protecting a subsequent AUTH payload, certain man-in- + the-middle and server impersonation attacks are possible [EAPMITM]. + These vulnerabilities occur when EAP is also used in protocols that + are not protected with a secure tunnel. Since EAP is a general- + purpose authentication protocol, which is often used to provide + single-signon facilities, a deployed IPsec solution that relies on an + EAP authentication method that does not generate a shared key (also + known as a non-key-generating EAP method) can become compromised due + to the deployment of an entirely unrelated application that also + happens to use the same non-key-generating EAP method, but in an + unprotected fashion. Note that this vulnerability is not limited to + just EAP, but can occur in other scenarios where an authentication + infrastructure is reused. For example, if the EAP mechanism used by + IKEv2 utilizes a token authenticator, a man-in-the-middle attacker + could impersonate the web server, intercept the token authentication + exchange, and use it to initiate an IKEv2 connection. For this + reason, use of non-key-generating EAP methods SHOULD be avoided where + possible. Where they are used, it is extremely important that all + usages of these EAP methods SHOULD utilize a protected tunnel, where + the initiator validates the responder's certificate before initiating + the EAP exchange. {{ Demoted the SHOULD }} Implementers should + describe the vulnerabilities of using non-key-generating EAP methods + in the documentation of their implementations so that the + administrators deploying IPsec solutions are aware of these dangers. + + An implementation using EAP MUST also use a public-key-based + authentication of the server to the client before the EAP exchange + begins, even if the EAP method offers mutual authentication. This + avoids having additional IKEv2 protocol variations and protects the + + + +Kaufman, et al. Expires August 27, 2006 [Page 106] + +Internet-Draft IKEv2bis February 2006 + + + EAP data from active attackers. + + If the messages of IKEv2 are long enough that IP-level fragmentation + is necessary, it is possible that attackers could prevent the + exchange from completing by exhausting the reassembly buffers. The + chances of this can be minimized by using the Hash and URL encodings + instead of sending certificates (see Section 3.6). Additional + mitigations are discussed in [DOSUDPPROT]. + +5.1. Traffic selector authorization + + {{ Added this section from Clarif-4.13 }} + + IKEv2 relies on information in the Peer Authorization Database (PAD) + when determining what kind of IPsec SAs a peer is allowed to create. + This process is described in [IPSECARCH] Section 4.4.3. When a peer + requests the creation of an IPsec SA with some traffic selectors, the + PAD must contain "Child SA Authorization Data" linking the identity + authenticated by IKEv2 and the addresses permitted for traffic + selectors. + + For example, the PAD might be configured so that authenticated + identity "sgw23.example.com" is allowed to create IPsec SAs for + 192.0.2.0/24, meaning this security gateway is a valid + "representative" for these addresses. Host-to-host IPsec requires + similar entries, linking, for example, "fooserver4.example.com" with + 192.0.1.66/32, meaning this identity a valid "owner" or + "representative" of the address in question. + + As noted in [IPSECARCH], "It is necessary to impose these constraints + on creation of child SAs to prevent an authenticated peer from + spoofing IDs associated with other, legitimate peers." In the + example given above, a correct configuration of the PAD prevents + sgw23 from creating IPsec SAs with address 192.0.1.66, and prevents + fooserver4 from creating IPsec SAs with addresses from 192.0.2.0/24. + + It is important to note that simply sending IKEv2 packets using some + particular address does not imply a permission to create IPsec SAs + with that address in the traffic selectors. For example, even if + sgw23 would be able to spoof its IP address as 192.0.1.66, it could + not create IPsec SAs matching fooserver4's traffic. + + The IKEv2 specification does not specify how exactly IP address + assignment using configuration payloads interacts with the PAD. Our + interpretation is that when a security gateway assigns an address + using configuration payloads, it also creates a temporary PAD entry + linking the authenticated peer identity and the newly allocated inner + address. + + + +Kaufman, et al. Expires August 27, 2006 [Page 107] + +Internet-Draft IKEv2bis February 2006 + + + It has been recognized that configuring the PAD correctly may be + difficult in some environments. For instance, if IPsec is used + between a pair of hosts whose addresses are allocated dynamically + using DHCP, it is extremely difficult to ensure that the PAD + specifies the correct "owner" for each IP address. This would + require a mechanism to securely convey address assignments from the + DHCP server, and link them to identities authenticated using IKEv2. + + Due to this limitation, some vendors have been known to configure + their PADs to allow an authenticated peer to create IPsec SAs with + traffic selectors containing the same address that was used for the + IKEv2 packets. In environments where IP spoofing is possible (i.e., + almost everywhere) this essentially allows any peer to create IPsec + SAs with any traffic selectors. This is not an appropriate or secure + configuration in most circumstances. See [H2HIPSEC] for an extensive + discussion about this issue, and the limitations of host-to-host + IPsec in general. + + +6. IANA Considerations + + {{ This section was changed to not re-define any new IANA registries. + }} + + [IKEV2] defined many field types and values. IANA has already + registered those types and values, so the are not listed here again. + No new types or values are registered in this document. + + +7. Acknowledgements + + The acknowledgements from the IKEv2 document were: + + This document is a collaborative effort of the entire IPsec WG. If + there were no limit to the number of authors that could appear on an + RFC, the following, in alphabetical order, would have been listed: + Bill Aiello, Stephane Beaulieu, Steve Bellovin, Sara Bitan, Matt + Blaze, Ran Canetti, Darren Dukes, Dan Harkins, Paul Hoffman, John + Ioannidis, Charlie Kaufman, Steve Kent, Angelos Keromytis, Tero + Kivinen, Hugo Krawczyk, Andrew Krywaniuk, Radia Perlman, Omer + Reingold, and Michael Richardson. Many other people contributed to + the design. It is an evolution of IKEv1, ISAKMP, and the IPsec DOI, + each of which has its own list of authors. Hugh Daniel suggested the + feature of having the initiator, in message 3, specify a name for the + responder, and gave the feature the cute name "You Tarzan, Me Jane". + David Faucher and Valery Smyzlov helped refine the design of the + traffic selector negotiation. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 108] + +Internet-Draft IKEv2bis February 2006 + + + This paragraph lists references that appear only in figures. The + section is only here to keep the 'xml2rfc' program happy, and will be + removed when the document is published. Feel free to ignore it. + [DES] [IDEA] [MD5] [X.501] [X.509] + + +8. References + +8.1. Normative References + + [ADDGROUP] + Kivinen, T. and M. Kojo, "More Modular Exponential (MODP) + Diffie-Hellman groups for Internet Key Exchange (IKE)", + RFC 3526, May 2003. + + [ADDRIPV6] + Hinden, R. and S. Deering, "Internet Protocol Version 6 + (IPv6) Addressing Architecture", RFC 3513, April 2003. + + [Clarif] "IKEv2 Clarifications and Implementation Guidelines", + draft-eronen-ipsec-ikev2-clarifications (work in + progress). + + [EAP] Aboba, B., Blunk, L., Vollbrecht, J., Carlson, J., and H. + Levkowetz, "Extensible Authentication Protocol (EAP)", + RFC 3748, June 2004. + + [ECN] Ramakrishnan, K., Floyd, S., and D. Black, "The Addition + of Explicit Congestion Notification (ECN) to IP", + RFC 3168, September 2001. + + [ESPCBC] Pereira, R. and R. Adams, "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + [IANACONS] + Narten, T. and H. Alvestrand, "Guidelines for Writing an + IANA Considerations Section in RFCs", BCP 26, RFC 2434. + + [IKEV2] Kaufman, C., "Internet Key Exchange (IKEv2) Protocol", + RFC 4306, December 2005. + + [IPSECARCH] + Kent, S. and K. Seo, "Security Architecture for the + Internet Protocol", RFC 4301, December 2005. + + [MUSTSHOULD] + Bradner, S., "Key Words for use in RFCs to indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + + +Kaufman, et al. Expires August 27, 2006 [Page 109] + +Internet-Draft IKEv2bis February 2006 + + + [PKIX] Housley, R., Polk, W., Ford, W., and D. Solo, "Internet + X.509 Public Key Infrastructure Certificate and + Certificate Revocation List (CRL) Profile", RFC 3280, + April 2002. + + [UDPENCAPS] + Huttunen, A., Swander, B., Volpe, V., DiBurro, L., and M. + Stenberg, "UDP Encapsulation of IPsec ESP Packets", + RFC 3948, January 2005. + +8.2. Informative References + + [AH] Kent, S., "IP Authentication Header", RFC 4302, + December 2005. + + [ARCHGUIDEPHIL] + Bush, R. and D. Meyer, "Some Internet Architectural + Guidelines and Philosophy", RFC 3439, December 2002. + + [ARCHPRINC] + Carpenter, B., "Architectural Principles of the Internet", + RFC 1958, June 1996. + + [DES] American National Standards Institute, "American National + Standard for Information Systems-Data Link Encryption", + ANSI X3.106, 1983. + + [DH] Diffie, W. and M. Hellman, "New Directions in + Cryptography", IEEE Transactions on Information Theory, + V.IT-22 n. 6, June 1977. + + [DHCP] Droms, R., "Dynamic Host Configuration Protocol", + RFC 2131, March 1997. + + [DIFFSERVARCH] + Blake, S., Black, D., Carlson, M., Davies, E., Wang, Z., + and W. Weiss, "An Architecture for Differentiated + Services", RFC 2475. + + [DIFFSERVFIELD] + Nichols, K., Blake, S., Baker, F., and D. Black, + "Definition of the Differentiated Services Field (DS + Field) in the IPv4 and IPv6 Headers", RFC 2474, + December 1998. + + [DIFFTUNNEL] + Black, D., "Differentiated Services and Tunnels", + RFC 2983, October 2000. + + + +Kaufman, et al. Expires August 27, 2006 [Page 110] + +Internet-Draft IKEv2bis February 2006 + + + [DOI] Piper, D., "The Internet IP Security Domain of + Interpretation for ISAKMP", RFC 2407, November 1998. + + [DOSUDPPROT] + C. Kaufman, R. Perlman, and B. Sommerfeld, "DoS protection + for UDP-based protocols", ACM Conference on Computer and + Communications Security , October 2003. + + [DSS] National Institute of Standards and Technology, U.S. + Department of Commerce, "Digital Signature Standard", + FIPS 186, May 1994. + + [EAPMITM] N. Asokan, V. Nierni, and K. Nyberg, "Man-in-the-Middle in + Tunneled Authentication Protocols", November 2002, + . + + [ESP] Kent, S., "IP Encapsulating Security Payload (ESP)", + RFC 4303, December 2005. + + [EXCHANGEANALYSIS] + R. Perlman and C. Kaufman, "Analysis of the IPsec key + exchange Standard", WET-ICE Security Conference, MIT , + 2001, + . + + [H2HIPSEC] + Aura, T., Roe, M., and A. Mohammed, "Experiences with + Host-to-Host IPsec", 13th International Workshop on + Security Protocols, Cambridge, UK, April 2005. + + [HMAC] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed- + Hashing for Message Authentication", RFC 2104, + February 1997. + + [IDEA] X. Lai, "On the Design and Security of Block Ciphers", ETH + Series in Information Processing, v. 1, Konstanz: Hartung- + Gorre Verlag, 1992. + + [IKEV1] Harkins, D. and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IPCOMP] Shacham, A., Monsour, B., Pereira, R., and M. Thomas, "IP + Payload Compression Protocol (IPComp)", RFC 3173, + September 2001. + + [IPSECARCH-OLD] + Kent, S. and R. Atkinson, "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + + +Kaufman, et al. Expires August 27, 2006 [Page 111] + +Internet-Draft IKEv2bis February 2006 + + + [IPV6ADDR] + Hinden, R. and S. Deering, "Internet Protocol Version 6 + (IPv6) Addressing Architecture", RFC 3513, April 2003. + + [ISAKMP] Maughan, D., Schneider, M., and M. Schertler, "Internet + Security Association and Key Management Protocol + (ISAKMP)", RFC 2408, November 1998. + + [LDAP] Wahl, M., Howes, T., and S. Kille, "Lightweight Directory + Access Protocol (v3)", RFC 2251, December 1997. + + [MAILFORMAT] + Resnick, P., "Internet Message Format", RFC 2822, + April 2001. + + [MD5] Rivest, R., "The MD5 Message-Digest Algorithm", RFC 1321, + April 1992. + + [MIPV6] Johnson, D., Perkins, C., and J. Arkko, "Mobility Support + in IPv6", RFC 3775, June 2004. + + [MLDV2] Vida, R. and L. Costa, "Multicast Listener Discovery + Version 2 (MLDv2) for IPv6", RFC 3810, June 2004. + + [NAI] Aboba, B. and M. Beadles, "The Network Access Identifier", + RFC 2486, January 1999. + + [NATREQ] Aboba, B. and W. Dixon, "IPsec-Network Address Translation + (NAT) Compatibility Requirements", RFC 3715, March 2004. + + [OAKLEY] Orman, H., "The OAKLEY Key Determination Protocol", + RFC 2412, November 1998. + + [PFKEY] McDonald, D., Metz, C., and B. Phan, "PF_KEY Key + Management API, Version 2", RFC 2367, July 1998. + + [PHOTURIS] + Karn, P. and W. Simpson, "Photuris: Session-Key Management + Protocol", RFC 2522, March 1999. + + [PKCS1] B. Kaliski and J. Staddon, "PKCS #1: RSA Cryptography + Specifications Version 2", September 1998. + + [PRFAES128CBC] + Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the + Internet Key Exchange Protocol (IKE)", RFC 3664, + January 2004. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 112] + +Internet-Draft IKEv2bis February 2006 + + + [PRFAES128CBC-bis] + Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the + Internet Key Exchange Protocol (IKE)", + draft-hoffman-rfc3664bis (work in progress), October 2005. + + [RADIUS] Rigney, C., Rubens, A., Simpson, W., and S. Willens, + "Remote Authentication Dial In User Service (RADIUS)", + RFC 2138, April 1997. + + [RANDOMNESS] + Eastlake, D., Schiller, J., and S. Crocker, "Randomness + Requirements for Security", BCP 106, RFC 4086, June 2005. + + [REAUTH] Nir, Y., ""Repeated Authentication in IKEv2", + draft-nir-ikev2-auth-lt (work in progress), May 2005. + + [RSA] R. Rivest, A. Shamir, and L. Adleman, "A Method for + Obtaining Digital Signatures and Public-Key + Cryptosystems", February 1978. + + [SHA] National Institute of Standards and Technology, U.S. + Department of Commerce, "Secure Hash Standard", + FIPS 180-1, May 1994. + + [SIGMA] H. Krawczyk, "SIGMA: the `SIGn-and-MAc' Approach to + Authenticated Diffie-Hellman and its Use in the IKE + Protocols", Advances in Cryptography - CRYPTO 2003 + Proceedings LNCS 2729, 2003, . + + [SKEME] H. Krawczyk, "SKEME: A Versatile Secure Key Exchange + Mechanism for Internet", IEEE Proceedings of the 1996 + Symposium on Network and Distributed Systems Security , + 1996. + + [TRANSPARENCY] + Carpenter, B., "Internet Transparency", RFC 2775, + February 2000. + + [X.501] ITU-T, "Recommendation X.501: Information Technology - + Open Systems Interconnection - The Directory: Models", + 1993. + + [X.509] ITU-T, "Recommendation X.509 (1997 E): Information + Technology - Open Systems Interconnection - The Directory: + Authentication Framework", 1997. + + + + +Kaufman, et al. Expires August 27, 2006 [Page 113] + +Internet-Draft IKEv2bis February 2006 + + +Appendix A. Summary of changes from IKEv1 + + The goals of this revision to IKE are: + + 1. To define the entire IKE protocol in a single document, + replacing RFCs 2407, 2408, and 2409 and incorporating subsequent + changes to support NAT Traversal, Extensible Authentication, and + Remote Address acquisition; + + 2. To simplify IKE by replacing the eight different initial + exchanges with a single four-message exchange (with changes in + authentication mechanisms affecting only a single AUTH payload + rather than restructuring the entire exchange) see + [EXCHANGEANALYSIS]; + + 3. To remove the Domain of Interpretation (DOI), Situation (SIT), + and Labeled Domain Identifier fields, and the Commit and + Authentication only bits; + + 4. To decrease IKE's latency in the common case by making the + initial exchange be 2 round trips (4 messages), and allowing the + ability to piggyback setup of a CHILD_SA on that exchange; + + 5. To replace the cryptographic syntax for protecting the IKE + messages themselves with one based closely on ESP to simplify + implementation and security analysis; + + 6. To reduce the number of possible error states by making the + protocol reliable (all messages are acknowledged) and sequenced. + This allows shortening CREATE_CHILD_SA exchanges from 3 messages + to 2; + + 7. To increase robustness by allowing the responder to not do + significant processing until it receives a message proving that + the initiator can receive messages at its claimed IP address, + and not commit any state to an exchange until the initiator can + be cryptographically authenticated; + + 8. To fix cryptographic weaknesses such as the problem with + symmetries in hashes used for authentication documented by Tero + Kivinen; + + 9. To specify Traffic Selectors in their own payloads type rather + than overloading ID payloads, and making more flexible the + Traffic Selectors that may be specified; + + 10. To specify required behavior under certain error conditions or + when data that is not understood is received in order to make it + + + +Kaufman, et al. Expires August 27, 2006 [Page 114] + +Internet-Draft IKEv2bis February 2006 + + + easier to make future revisions in a way that does not break + backwards compatibility; + + 11. To simplify and clarify how shared state is maintained in the + presence of network failures and Denial of Service attacks; and + + 12. To maintain existing syntax and magic numbers to the extent + possible to make it likely that implementations of IKEv1 can be + enhanced to support IKEv2 with minimum effort. + + +Appendix B. Diffie-Hellman Groups + + There are two Diffie-Hellman groups defined here for use in IKE. + These groups were generated by Richard Schroeppel at the University + of Arizona. Properties of these primes are described in [OAKLEY]. + + The strength supplied by group one may not be sufficient for the + mandatory-to-implement encryption algorithm and is here for historic + reasons. + + Additional Diffie-Hellman groups have been defined in [ADDGROUP]. + +B.1. Group 1 - 768 Bit MODP + + This group is assigned id 1 (one). + + The prime is: 2^768 - 2 ^704 - 1 + 2^64 * { [2^638 pi] + 149686 } + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A63A3620 FFFFFFFF FFFFFFFF + + The generator is 2. + +B.2. Group 2 - 1024 Bit MODP + + This group is assigned id 2 (two). + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 115] + +Internet-Draft IKEv2bis February 2006 + + + The prime is 2^1024 - 2^960 - 1 + 2^64 * { [2^894 pi] + 129093 }. + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE65381 + FFFFFFFF FFFFFFFF + + The generator is 2. + + +Appendix C. Exchanges and Payloads + + {{ Clarif-AppA }} + + This appendix contains a short summary of the IKEv2 exchanges, and + what payloads can appear in which message. This appendix is purely + informative; if it disagrees with the body of this document, the + other text is considered correct. + + Vendor-ID (V) payloads may be included in any place in any message. + This sequence here shows what are the most logical places for them. + +C.1. IKE_SA_INIT Exchange + + request --> [N(COOKIE)], + SA, KE, Ni, + [N(NAT_DETECTION_SOURCE_IP)+, + N(NAT_DETECTION_DESTINATION_IP)], + [V+] + + normal response <-- SA, KE, Nr, + (no cookie) [N(NAT_DETECTION_SOURCE_IP), + N(NAT_DETECTION_DESTINATION_IP)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [V+] + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 116] + +Internet-Draft IKEv2bis February 2006 + + +C.2. IKE_AUTH Exchange without EAP + + request --> IDi, [CERT+], + [N(INITIAL_CONTACT)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [IDr], + AUTH, + [CP(CFG_REQUEST)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [V+] + + response <-- IDr, [CERT+], + AUTH, + [CP(CFG_REPLY)], + [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)], + [V+] + + + + + + + + + + + + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 117] + +Internet-Draft IKEv2bis February 2006 + + +C.3. IKE_AUTH Exchange with EAP + + first request --> IDi, + [N(INITIAL_CONTACT)], + [[N(HTTP_CERT_LOOKUP_SUPPORTED)], CERTREQ+], + [IDr], + [CP(CFG_REQUEST)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [V+] + + first response <-- IDr, [CERT+], AUTH, + EAP, + [V+] + + / --> EAP + repeat 1..N times | + \ <-- EAP + + last request --> AUTH + + last response <-- AUTH, + [CP(CFG_REPLY)], + [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)], + [V+] + + + + + + + + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 118] + +Internet-Draft IKEv2bis February 2006 + + +C.4. CREATE_CHILD_SA Exchange for Creating or Rekeying CHILD_SAs + + request --> [N(REKEY_SA)], + [N(IPCOMP_SUPPORTED)+], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, Ni, [KEi], TSi, TSr + + response <-- [N(IPCOMP_SUPPORTED)], + [N(USE_TRANSPORT_MODE)], + [N(ESP_TFC_PADDING_NOT_SUPPORTED)], + [N(NON_FIRST_FRAGMENTS_ALSO)], + SA, Nr, [KEr], TSi, TSr, + [N(ADDITIONAL_TS_POSSIBLE)] + +C.5. CREATE_CHILD_SA Exchange for Rekeying the IKE_SA + + request --> SA, Ni, [KEi] + + response <-- SA, Nr, [KEr] + +C.6. INFORMATIONAL Exchange + + request --> [N+], + [D+], + [CP(CFG_REQUEST)] + + response <-- [N+], + [D+], + [CP(CFG_REPLY)] + + +Appendix D. Changes Between Internet Draft Versions + + This section will be removed before publication as an RFC. + +D.1. Changes from IKEv2 to draft -00 + + There were a zillion additions from the Clarifications document. + These are noted with "{{ Clarif-nn }}". The numbers used in the text + of this version are based on + draft-eronen-ipsec-ikev2-clarifications-08.txt, which has different + numbers than earlier versions of that draft. + + Cleaned up many of the figures. Made the table headings consistent. + Made some tables easier to read by removing blank spaces. Removed + the "reserved to IANA" and "private use" text wording and moved it + + + +Kaufman, et al. Expires August 27, 2006 [Page 119] + +Internet-Draft IKEv2bis February 2006 + + + into the tables. + + Changed many SHOULD requirements to better match RFC 2119. These are + also marked with comments such as "{{ Demoted the SHOULD }}". + + In Section 2.16, changed the MUST requirement of authenticating the + responder from "public key signature based" to "strong" because that + is what most current IKEv2 implementations do, and it better matches + the actual security requirement. + + +Authors' Addresses + + Charlie Kaufman + Microsoft + 1 Microsoft Way + Redmond, WA 98052 + US + + Phone: 1-425-707-3335 + Email: charliek@microsoft.com + + + Paul Hoffman + VPN Consortium + 127 Segre Place + Santa Cruz, CA 95060 + US + + Phone: 1-831-426-9827 + Email: paul.hoffman@vpnc.org + + + Pasi Eronen + Nokia Research Center + P.O. Box 407 + FIN-00045 Nokia Group + Finland + + Email: pasi.eronen@nokia.com + + +Full Copyright Statement + + Copyright (C) The Internet Society (2006). + + This document is subject to the rights, licenses and restrictions + contained in BCP 78, and except as set forth therein, the authors + + + +Kaufman, et al. Expires August 27, 2006 [Page 120] + +Internet-Draft IKEv2bis February 2006 + + + retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + +Intellectual Property + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at + ietf-ipr@ietf.org. + + +Acknowledgment + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + + + + + +Kaufman, et al. Expires August 27, 2006 [Page 121] + diff --git a/doc/ikev2/[IPsecArch] - Security Architecture for the Internet Protocol.txt b/doc/ikev2/[IPsecArch] - Security Architecture for the Internet Protocol.txt new file mode 100644 index 000000000..863ffe3ff --- /dev/null +++ b/doc/ikev2/[IPsecArch] - Security Architecture for the Internet Protocol.txt @@ -0,0 +1,5657 @@ +Network Working Group S. Kent +Internet Draft K. Seo +draft-ietf-ipsec-rfc2401bis-06.txt BBN Technologies +Obsoletes: RFC 2401 March 2005 +Expires September 2005 + + + + + + + + Security Architecture for the Internet Protocol + + + + Dedicated to the memory of Charlie Lynn, a long time senior + colleague at BBN, who made very significant contributions to + the IPsec documents. + + + +Status of this Memo + + By submitting this Internet-Draft, I certify that any applicable + patent or other IPR claims of which I am aware have been disclosed, + and any of which I become aware will be disclosed, in accordance with + RFC 3668. + + This document is an Internet Draft and is subject to all provisions + of Section 10 of RFC2026. Internet-Drafts are working documents of + the Internet Engineering Task Force (IETF), its areas, and its + working groups. Note that other groups may also distribute working + documents as Internet-Drafts. Internet-Drafts are draft documents + valid for a maximum of six months and may be updated, replaced, or + obsoleted by other documents at any time. It is inappropriate to use + Internet-Drafts as reference material or to cite them other than as + "work in progress". The list of current Internet-Drafts can be + accessed at http://www.ietf.org/1id-abstracts.html. The list of + Internet-Draft Shadow Directories can be accessed at + http://www.ietf.org/shadow.html. + + Copyright (C) The Internet Society (2005). All Rights Reserved. + +Abstract + + This document describes an updated version of the "Security + Architecture for IP", which is designed to provide security services + for traffic at the IP layer. This document obsoletes RFC 2401 + (November 1998). + + Comments should be sent to Stephen Kent (kent@bbn.com). [RFC Editor: + Please remove this line prior to publication as an RFC.] + + + +Kent & Seo [Page 1] + +Internet Draft Security Architecture for IP March 2005 + + +Table of Contents +1. Introduction........................................................4 + 1.1 Summary of Contents of Document................................4 + 1.2 Audience.......................................................4 + 1.3 Related Documents..............................................5 +2. Design Objectives...................................................5 + 2.1 Goals/Objectives/Requirements/Problem Description..............5 + 2.2 Caveats and Assumptions........................................6 +3. System Overview ....................................................7 + 3.1 What IPsec Does................................................7 + 3.2 How IPsec Works................................................9 + 3.3 Where IPsec Can Be Implemented................................10 +4. Security Associations..............................................11 + 4.1 Definition and Scope..........................................11 + 4.2 SA Functionality..............................................16 + 4.3 Combining SAs.................................................17 + 4.4 Major IPsec Databases.........................................17 + 4.4.1 The Security Policy Database (SPD).......................19 + 4.4.1.1 Selectors...........................................25 + 4.4.1.2 Structure of an SPD entry...........................29 + 4.4.1.3 More re: Fields Associated with Next Layer + Protocols...........................................31 + 4.4.2 Security Association Database (SAD)......................33 + 4.4.2.1 Data Items in the SAD...............................34 + 4.4.2.2 Relationship between SPD, PFP flag, packet, and SAD.36 + 4.4.3 Peer Authorization Database (PAD)........................41 + 4.4.3.1 PAD Entry IDs and Matching Rules....................42 + 4.4.3.2 IKE Peer Authentication Data........................43 + 4.4.3.3 Child SA Authorization Data.........................44 + 4.4.3.4 How the PAD Is Used.................................44 + 4.5 SA and Key Management.........................................45 + 4.5.1 Manual Techniques........................................46 + 4.5.2 Automated SA and Key Management..........................46 + 4.5.3 Locating a Security Gateway..............................47 + 4.6 SAs and Multicast.............................................48 +5. IP Traffic Processing..............................................48 + 5.1 Outbound IP Traffic Processing (protected-to-unprotected).....49 + 5.1.1 Handling an Outbound Packet That Must Be Discarded.......52 + 5.1.2 Header Construction for Tunnel Mode......................53 + 5.1.2.1 IPv4 -- Header Construction for Tunnel Mode.........55 + 5.1.2.2 IPv6 -- Header Construction for Tunnel Mode.........56 + 5.2 Processing Inbound IP Traffic (unprotected-to-protected)......57 +6. ICMP Processing ...................................................61 + 6.1 Processing ICMP Error Messages Directed to an IPsec + Implementation.....................................61 + 6.1.1 ICMP Error Messages Received on the Unprotected + Side of the Boundary...............................61 + 6.1.2 ICMP Error Messages Received on the Protected + Side of the Boundary...............................62 + + +Kent & Seo [Page 2] + +Internet Draft Security Architecture for IP March 2005 + + + 6.2 Processing Protected, Transit ICMP Error Messages.............62 +7. Handling Fragments (on the protected side of the IPsec boundary)...64 + 7.1 Tunnel Mode SAs that Carry Initial and Non-Initial Fragments..65 + 7.2 Separate Tunnel Mode SAs for Non-Initial Fragments............65 + 7.3 Stateful Fragment Checking....................................66 + 7.4 BYPASS/DISCARD traffic........................................66 +8. Path MTU/DF Processing.............................................67 + 8.1 DF Bit........................................................67 + 8.2 Path MTU (PMTU) Discovery.....................................67 + 8.2.1 Propagation of PMTU......................................68 + 8.2.2 PMTU Aging...............................................68 +9. Auditing...........................................................69 +10. Conformance Requirements..........................................69 +11. Security Considerations...........................................69 +12. IANA Considerations...............................................70 +13. Differences from RFC 2401.........................................70 +Acknowledgements......................................................73 +Appendix A -- Glossary................................................74 +Appendix B -- Decorrelation...........................................77 +Appendix C -- ASN.1 for an SPD Entry..................................80 +Appendix D -- Fragment Handling Rationale.............................86 + D.1 Transport Mode and Fragments..................................86 + D.2 Tunnel Mode and Fragments.....................................87 + D.3 The Problem of Non-Initial Fragments..........................88 + D.4 BYPASS/DISCARD traffic........................................91 + D.5 Just say no to ports?.........................................91 + D.6 Other Suggested Solutions.....................................92 + D.7 Consistency...................................................93 + D.8 Conclusions...................................................93 +Appendix E -- Example of Supporting Nested SAs via SPD and Forwarding + Table Entries.....................................94 +References............................................................96 +Author Information....................................................99 +Notices..............................................................100 + + + + + + + + + + + + + + + + + +Kent & Seo [Page 3] + +Internet Draft Security Architecture for IP March 2005 + + +1. Introduction + +1.1 Summary of Contents of Document + + This document specifies the base architecture for IPsec compliant + systems. It describes how to provide a set of security services for + traffic at the IP layer, in both the IPv4 [Pos81a] and IPv6 [DH98] + environments. This document describes the requirements for systems + that implement IPsec, the fundamental elements of such systems, and + how the elements fit together and fit into the IP environment. It + also describes the security services offered by the IPsec protocols, + and how these services can be employed in the IP environment. This + document does not address all aspects of the IPsec architecture. + Other documents address additional architectural details in + specialized environments, e.g., use of IPsec in Network Address + Translation (NAT) environments and more comprehensive support for IP + multicast. The fundamental components of the IPsec security + architecture are discussed in terms of their underlying, required + functionality. Additional RFCs (see Section 1.3 for pointers to + other documents) define the protocols in (a), (c), and (d). + + a. Security Protocols -- Authentication Header (AH) and + Encapsulating Security Payload (ESP) + b. Security Associations -- what they are and how they work, + how they are managed, associated processing + c. Key Management -- manual and automated (The Internet Key + Exchange (IKE)) + d. Cryptographic algorithms for authentication and encryption + + This document is not a Security Architecture for the Internet; it + addresses security only at the IP layer, provided through the use of + a combination of cryptographic and protocol security mechanisms. + + The spelling "IPsec" is preferred and used throughout this and all + related IPsec standards. All other capitalizations of IPsec (e.g., + IPSEC, IPSec, ipsec) are deprecated. However, any capitalization of + the sequence of letters "IPsec" should be understood to refer to the + IPsec protocols. + + The keywords MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, + SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL, when they appear in this + document, are to be interpreted as described in RFC 2119 [Bra97]. + +1.2 Audience + + The target audience for this document is primarily individuals who + implement this IP security technology or who architect systems that + will use this technology. Technically adept users of this technology + (end users or system administrators) also are part of the target + + +Kent & Seo [Page 4] + +Internet Draft Security Architecture for IP March 2005 + + + audience. A glossary is provided in Appendix A to help fill in gaps + in background/vocabulary. This document assumes that the reader is + familiar with the Internet Protocol (IP), related networking + technology, and general information system security terms and + concepts. + +1.3 Related Documents + + As mentioned above, other documents provide detailed definitions of + some of the components of IPsec and of their inter-relationship. + They include RFCs on the following topics: + + a. security protocols -- RFCs describing the Authentication + Header (AH) [Ken05b] and Encapsulating Security Payload + (ESP) [Ken05a] protocols. + b. cryptographic algorithms for integrity and encryption - one + RFC that defines the mandatory, default algorithms for use + with AH and ESP [Eas05], a similar RFC that defines the + mandatory algorithms for use with IKE v2 [Sch05] plus a + separate RFC for each cryptographic algorithm. + c. automatic key management -- RFCs on "The Internet Key + Exchange (IKE v2) Protocol" [Kau05] and "Cryptographic + Algorithms for use in the Internet Key Exchange Version 2" + [Sch05]. + + +2. Design Objectives + +2.1 Goals/Objectives/Requirements/Problem Description + + IPsec is designed to provide interoperable, high quality, + cryptographically-based security for IPv4 and IPv6. The set of + security services offered includes access control, connectionless + integrity, data origin authentication, detection and rejection of + replays (a form of partial sequence integrity), confidentiality (via + encryption), and limited traffic flow confidentiality. These + services are provided at the IP layer, offering protection in a + standard fashion for all protocols that may be carried over IP + (including IP itself). + + IPsec includes a specification for minimal firewall functionality, + since that is an essential aspect of access control at the IP layer. + Implementations are free to provide more sophisticated firewall + mechanisms, and to implement the IPsec-mandated functionality using + those more sophisticated mechanisms. (Note that interoperability may + suffer if additional firewall constraints on traffic flows are + imposed by an IPsec implementation but cannot be negotiated based on + the traffic selector features defined in this document and negotiated + via IKE v2.) The IPsec firewall function makes use of the + + +Kent & Seo [Page 5] + +Internet Draft Security Architecture for IP March 2005 + + + cryptographically-enforced authentication and integrity provided for + all IPsec traffic to offer better access control than could be + obtained through use of a firewall (one not privy to IPsec internal + parameters) plus separate cryptographic protection. + + Most of the security services are provided through use of two traffic + security protocols, the Authentication Header (AH) and the + Encapsulating Security Payload (ESP), and through the use of + cryptographic key management procedures and protocols. The set of + IPsec protocols employed in a context, and the ways in which they are + employed, will be determined by the users/administrators in that + context. It is the goal of the IPsec architecture to ensure that + compliant implementations include the services and management + interfaces needed to meet the security requirements of a broad user + population. + + When IPsec is correctly implemented and deployed, it ought not + adversely affect users, hosts, and other Internet components that do + not employ IPsec for traffic protection. IPsec security protocols + (AH & ESP, and to a lesser extent, IKE) are designed to be + cryptographic algorithm-independent. This modularity permits + selection of different sets of cryptographic algorithms as + appropriate, without affecting the other parts of the implementation. + For example, different user communities may select different sets of + cryptographic algorithms (creating cryptographically-enforced + cliques) if required. + + To facilitate interoperability in the global Internet, a set of + default cryptographic algorithms for use with AH and ESP is specified + in [Eas05] and a set of mandatory-to-implement algorithms for IKE v2 + is specified in [Sch05]. [Eas05] and [Sch05] will be periodically + updated to keep pace with computational and cryptologic advances. By + specifying these algorithms in documents that are separate from the + AH, ESP, and IKE v2 specifications, these algorithms can be updated + or replaced without affecting the standardization progress of the + rest of the IPsec document suite. The use of these cryptographic + algorithms, in conjunction with IPsec traffic protection and key + management protocols, is intended to permit system and application + developers to deploy high quality, Internet layer, cryptographic + security technology. + +2.2 Caveats and Assumptions + + The suite of IPsec protocols and associated default cryptographic + algorithms are designed to provide high quality security for Internet + traffic. However, the security offered by use of these protocols + ultimately depends on the quality of the their implementation, which + is outside the scope of this set of standards. Moreover, the + security of a computer system or network is a function of many + + +Kent & Seo [Page 6] + +Internet Draft Security Architecture for IP March 2005 + + + factors, including personnel, physical, procedural, compromising + emanations, and computer security practices. Thus IPsec is only one + part of an overall system security architecture. + + Finally, the security afforded by the use of IPsec is critically + dependent on many aspects of the operating environment in which the + IPsec implementation executes. For example, defects in OS security, + poor quality of random number sources, sloppy system management + protocols and practices, etc. can all degrade the security provided + by IPsec. As above, none of these environmental attributes are + within the scope of this or other IPsec standards. + +3. System Overview + + This section provides a high level description of how IPsec works, + the components of the system, and how they fit together to provide + the security services noted above. The goal of this description is + to enable the reader to "picture" the overall process/system, see how + it fits into the IP environment, and to provide context for later + sections of this document, which describe each of the components in + more detail. + + An IPsec implementation operates in a host, as a security gateway, or + as an independent device, affording protection to IP traffic. (A + security gateway is an intermediate system implementing IPsec, e.g., + a firewall or router that has been IPsec-enabled.) More detail on + these classes of implementations is provided later, in Section 3.3. + The protection offered by IPsec is based on requirements defined by a + Security Policy Database (SPD) established and maintained by a user + or system administrator, or by an application operating within + constraints established by either of the above. In general, packets + are selected for one of three processing actions based on IP and next + layer header information (Selectors, Section 4.4.1.1) matched against + entries in the Security Policy Database (SPD). Each packet is either + PROTECTed using IPsec security services, DISCARDed, or allowed to + BYPASS IPsec protection, based on the applicable SPD policies + identified by the Selectors. + + +3.1 What IPsec Does + + IPsec creates a boundary between unprotected and protected + interfaces, for a host or a network (see Figure 1 below). Traffic + traversing the boundary is subject to the access controls specified + by the user or administrator responsible for the IPsec configuration. + These controls indicate whether packets cross the boundary unimpeded, + are afforded security services via AH or ESP, or are discarded. IPsec + security services are offered at the IP layer through selection of + appropriate security protocols, cryptographic algorithms, and + + +Kent & Seo [Page 7] + +Internet Draft Security Architecture for IP March 2005 + + + cryptographic keys. IPsec can be used to protect one or more "paths" + (a) between a pair of hosts, (b) between a pair of security gateways, + or (c) between a security gateway and a host. A compliant host + implementation MUST support (a) and (c) and a compliant security + gateway must support all three of these forms of connectivity, since + under certain circumstances a security gateway acts as a host. + + Unprotected + ^ ^ + | | + +-------------|-------|-------+ + | +-------+ | | | + | |Discard|<--| V | + | +-------+ |B +--------+ | + ................|y..| AH/ESP |..... IPsec Boundary + | +---+ |p +--------+ | + | |IKE|<----|a ^ | + | +---+ |s | | + | +-------+ |s | | + | |Discard|<--| | | + | +-------+ | | | + +-------------|-------|-------+ + | | + V V + Protected + + Figure 1. Top Level IPsec Processing Model + + + In this diagram, "unprotected" refers to an interface that might also + be described as "black" or "ciphertext." Here, "protected" refers to + an interface that might also be described as "red" or "plaintext." + The protected interface noted above may be internal, e.g., in a host + implementation of IPsec, the protected interface may link to a socket + layer interface presented by the OS. In this document, the term + "inbound" refers to traffic entering an IPsec implementation via the + unprotected interface or emitted by the implementation on the + unprotected side of the boundary and directed towards the protected + interface. The term "outbound" refers to traffic entering the + implementation via the protected interface, or emitted by the + implementation on the protected side of the boundary and directed + toward the unprotected interface. An IPsec implementation may + support more than one interface on either or both sides of the + boundary. + + Note the facilities for discarding traffic on either side of the + IPsec boundary, the BYPASS facility that allows traffic to transit + the boundary without cryptographic protection, and the reference to + IKE as a protected-side key and security management function. + + +Kent & Seo [Page 8] + +Internet Draft Security Architecture for IP March 2005 + + + IPsec optionally supports negotiation of IP compression [SMPT01], + motivated in part by the observation that when encryption is employed + within IPsec, it prevents effective compression by lower protocol + layers. + +3.2 How IPsec Works + + IPsec uses two protocols to provide traffic security services -- + Authentication Header (AH) and Encapsulating Security Payload (ESP). + Both protocols are described in detail in their respective RFCs + [Ken05b, Ken05a]. IPsec implementations MUST support ESP and MAY + support AH. (Support for AH has been downgraded to MAY because + experience has shown that there are very few contexts in which ESP + cannot provide the requisite security services. Note that ESP can be + used to provide only integrity, without confidentiality, making it + comparable to AH in most contexts.) + + o The IP Authentication Header (AH) [Ken05b] offers integrity and + data origin authentication, with optional (at the discretion of + the receiver) anti-replay features. + + o The Encapsulating Security Payload (ESP) protocol [Ken05a] offers + the same set of services, and also offers confidentiality. Use of + ESP to provide confidentiality without integrity is NOT + RECOMMENDED. When ESP is used with confidentiality enabled, there + are provisions for limited traffic flow confidentiality, i.e., + provisions for concealing packet length, and for facilitating + efficient generation and discard of dummy packets. This capability + is likely to be effective primarily in VPN and overlay network + contexts. + + o Both AH and ESP offer access control, enforced through the + distribution of cryptographic keys and the management of traffic + flows as dictated by the Security Policy Database (SPD, Section + 4.4.1). + + These protocols may be applied individually or in combination with + each other to provide IPv4 and IPv6 security services. However, most + security requirements can be met through the use of ESP by itself. + Each protocol supports two modes of use: transport mode and tunnel + mode. In transport mode, AH and ESP provide protection primarily for + next layer protocols; in tunnel mode, AH and ESP are applied to + tunneled IP packets. The differences between the two modes are + discussed in Section 4.1. + + IPsec allows the user (or system administrator) to control the + granularity at which a security service is offered. For example, one + can create a single encrypted tunnel to carry all the traffic between + two security gateways or a separate encrypted tunnel can be created + + +Kent & Seo [Page 9] + +Internet Draft Security Architecture for IP March 2005 + + + for each TCP connection between each pair of hosts communicating + across these gateways. IPsec, through the SPD management paradigm, + incorporates facilities for specifying: + + o which security protocol (AH or ESP) to employ, the mode (transport + or tunnel), security service options, what cryptographic + algorithms to use, and in what combinations to use the specified + protocols and services, + + o the granularity at which protection should be applied. + + Because most of the security services provided by IPsec require the + use of cryptographic keys, IPsec relies on a separate set of + mechanisms for putting these keys in place. This document requires + support for both manual and automated distribution of keys. It + specifies a specific public-key based approach (IKE v2 [Kau05]) for + automated key management, but other automated key distribution + techniques MAY be used. + + Note: This document mandates support for several features for which + support is available in IKE v2 but not in IKE v1, e.g., negotiation + of an SA representing ranges of local and remote ports or negotiation + of multiple SAs with the same selectors. Therefore this document + assumes use of IKE v2 or a key and security association management + system with comparable features. + +3.3 Where IPsec Can Be Implemented + + There are many ways in which IPsec may be implemented in a host, or + in conjunction with a router or firewall to create a security + gateway, or as an independent security device. + + a. IPsec may be integrated into the native IP stack. This requires + access to the IP source code and is applicable to both hosts and + security gateways, although native host implementations benefit + the most from this strategy, as explained later (Section 4.4.1, + paragraph 6; Section 4.4.1.1, last paragraph). + + b. In a "bump-in-the-stack" (BITS) implementation, IPsec is + implemented "underneath" an existing implementation of an IP + protocol stack, between the native IP and the local network + drivers. Source code access for the IP stack is not required in + this context, making this implementation approach appropriate for + use with legacy systems. This approach, when it is adopted, is + usually employed in hosts. + + c. The use of a dedicated, inline security protocol processor is a + common design feature of systems used by the military, and of some + commercial systems as well. It is sometimes referred to as a + + +Kent & Seo [Page 10] + +Internet Draft Security Architecture for IP March 2005 + + + "bump-in-the-wire" (BITW) implementation. Such implementations + may be designed to serve either a host or a gateway. Usually the + BITW device is itself IP addressable. When supporting a single + host, it may be quite analogous to a BITS implementation, but in + supporting a router or firewall, it must operate like a security + gateway. + + This document often talks in terms of use of IPsec by a host or a + security gateway, without regard to whether the implementation is + native, BITS or BITW. When the distinctions among these + implementation options are significant, the document makes reference + to specific implementation approaches. + + A host implementation of IPsec may appear in devices that might not + be viewed as "hosts." For example, a router might employ IPsec to + protect routing protocols (e.g., BGP) and management functions (e.g., + Telnet), without affecting subscriber traffic traversing the router. + A security gateway might employ separate IPsec implementations to + protect its management traffic and subscriber traffic. The + architecture described in this document is very flexible. For + example, a computer with a full-featured, compliant, native OS IPsec + implementation should be capable of being configured to protect + resident (host) applications and to provide security gateway + protection for traffic traversing the computer. Such configuration + would make use of the forwarding tables and the SPD selection + function described in Sections 5.1 and 5.2. + +4. Security Associations + + This section defines Security Association management requirements for + all IPv6 implementations and for those IPv4 implementations that + implement AH, ESP, or both AH and ESP. The concept of a "Security + Association" (SA) is fundamental to IPsec. Both AH and ESP make use + of SAs and a major function of IKE is the establishment and + maintenance of SAs. All implementations of AH or ESP MUST support + the concept of an SA as described below. The remainder of this + section describes various aspects of SA management, defining required + characteristics for SA policy management and SA management + techniques. + +4.1 Definition and Scope + + An SA is a simplex "connection" that affords security services to the + traffic carried by it. Security services are afforded to an SA by + the use of AH, or ESP, but not both. If both AH and ESP protection + are applied to a traffic stream, then two SAs must be created and + coordinated to effect protection through iterated application of the + security protocols. To secure typical, bi-directional communication + between two IPsec-enabled systems, a pair of SAs (one in each + + +Kent & Seo [Page 11] + +Internet Draft Security Architecture for IP March 2005 + + + direction) is required. IKE explicitly creates SA pairs in + recognition of this common usage requirement. + + For an SA used to carry unicast traffic, the SPI (Security Parameters + Index - see Appendix A and AH [Ken05b] and ESP [Ken05a] + specifications) by itself suffices to specify an SA. However, as a + local matter, an implementation may choose to use the SPI in + conjunction with the IPsec protocol type (AH or ESP) for SA + identification. If an IPsec implementation supports multicast, then + it MUST support multicast SAs using the algorithm below for mapping + inbound IPsec datagrams to SAs. Implementations that support only + unicast traffic need not implement this demultiplexing algorithm. + + In many secure multicast architectures, e.g., [RFC3740], a central + Group Controller/Key Server unilaterally assigns the Group Security + Association's (GSA's) SPI. This SPI assignment is not negotiated or + coordinated with the key management (e.g., IKE) subsystems that + reside in the individual end systems that constitute the group. + Consequently, it is possible that a GSA and a unicast SA can + simultaneously use the same SPI. A multicast-capable IPsec + implementation MUST correctly de-multiplex inbound traffic even in + the context of SPI collisions. + + Each entry in the SA Database (SAD) (Section 4.4.2) must indicate + whether the SA lookup makes use of the destination IP address, or the + destination and source IP addresses, in addition to the SPI. For + multicast SAs, the protocol field is not employed for SA lookups. For + each inbound, IPsec-protected packet, an implementation must conduct + its search of the SAD such that it finds the entry that matches the + "longest" SA identifier. In this context, if two or more SAD entries + match based on the SPI value, then the entry that also matches based + on destination address, or destination and source address (as + indicated in the SAD entry) is the "longest" match. This implies a + logical ordering of the SAD search as follows: + + + 1. Search the SAD for a match on the combination of SPI, + destination address, and source address. If an SAD entry + matches, then process the inbound packet with that + matching SAD entry. Otherwise, proceed to step 2. + + 2. Search the SAD for a match on both SPI and destination address. + If the SAD entry matches then process the inbound packet + with that matching SAD entry. Otherwise, proceed to step 3. + + 3. Search the SAD for a match on only SPI if the receiver has + chosen to maintain a single SPI space for AH and ESP, and on + both SPI and protocol otherwise. If an SAD entry matches then + process the inbound packet with that matching SAD entry. + + +Kent & Seo [Page 12] + +Internet Draft Security Architecture for IP March 2005 + + + Otherwise, discard the packet and log an auditable event. + + + In practice, an implementation may choose any method (or none at all) + to accelerate this search, although its externally visible behavior + MUST be functionally equivalent to having searched the SAD in the + above order. For example, a software-based implementation could index + into a hash table by the SPI. The SAD entries in each hash table + bucket's linked list could be kept sorted to have those SAD entries + with the longest SA identifiers first in that linked list. Those SAD + entries having the shortest SA identifiers could be sorted so that + they are the last entries in the linked list. A hardware-based + implementation may be able to effect the longest match search + intrinsically, using commonly available Ternary Content-Addressable + Memory (TCAM) features. + + The indication of whether source and destination address matching is + required to map inbound IPsec traffic to SAs MUST be set either as a + side effect of manual SA configuration or via negotiation using an SA + management protocol, e.g., IKE or GDOI [RFC3547]. Typically, + Source-Specific Multicast (SSM) [HC03] groups use a 3-tuple SA + identifier composed of an SPI, a destination multicast address, and + source address. An Any-Source Multicast group SA requires only an SPI + and a destination multicast address as an identifier. + + If different classes of traffic (distinguished by Differentiated + Services CodePoint (DSCP) bits [NiBlBaBL98], [Gro02]) are sent on the + same SA, and if the receiver is employing the optional anti-replay + feature available in both AH and ESP, this could result in + inappropriate discarding of lower priority packets due to the + windowing mechanism used by this feature. Therefore a sender SHOULD + put traffic of different classes, but with the same selector values, + on different SAs to support QoS appropriately. To permit this, the + IPsec implementation MUST permit establishment and maintenance of + multiple SAs between a given sender and receiver, with the same + selectors. Distribution of traffic among these parallel SAs to + support QoS is locally determined by the sender and is not negotiated + by IKE. The receiver MUST process the packets from the different SAs + without prejudice. These requirements apply to both transport and + tunnel mode SAs. In the case of tunnel mode SAs, the DSCP values in + question appear in the inner IP header. In transport mode, the DSCP + value might change en route, but this should not cause problems with + respect to IPsec processing since the value is not employed for SA + selection and MUST NOT be checked as part of SA/packet validation. + However, if significant re-ordering of packets occurs in an SA, e.g., + as a result of changes to DSCP values en route, this may trigger + packet discarding by a receiver due to application of the anti-replay + mechanism. + + + +Kent & Seo [Page 13] + +Internet Draft Security Architecture for IP March 2005 + + + DISCUSSION: While the DSCP [NiBlBaBL98, Gro02] and Explicit + Congestion Notification (ECN) [RaFlBl01] fields are not "selectors", + as that term in used in this architecture, the sender will need a + mechanism to direct packets with a given (set of) DSCP values to the + appropriate SA. This mechanism might be termed a "classifier". + + As noted above, two types of SAs are defined: transport mode and + tunnel mode. IKE creates pairs of SAs, so for simplicity, we choose + to require that both SAs in a pair be of the same mode, transport or + tunnel. + + A transport mode SA is an SA typically employed between a pair of + hosts to provide end-to-end security services. When security is + desired between two intermediate systems along a path (vs. end-to-end + use of IPsec), transport mode MAY be used between security gateways + or between a security gateway and a host. In the case where + transport mode is used between security gateways or between a + security gateway and a host, transport mode may be used to support + in-IP tunneling (e.g., IP-in-IP [Per96] or GRE tunneling + [FaLiHaMeTr00] or Dynamic routing [ToEgWa04]) over transport mode + SAs. To clarify, the use of transport mode by an intermediate system + (e.g., a security gateway) is permitted only when applied to packets + whose source address (for outbound packets) or destination address + (for inbound packets) is an address belonging to the intermediate + system itself. The access control functions that are an important + part of IPsec are significantly limited in this context, as they + cannot be applied to the end-to-end headers of the packets that + traverse a transport mode SA used in this fashion. Thus this way of + using transport mode should be evaluated carefully before being + employed in a specific context. + + In IPv4, a transport mode security protocol header appears + immediately after the IP header and any options, and before any next + layer protocols (e.g., TCP or UDP). In IPv6, the security protocol + header appears after the base IP header and selected extension + headers, but may appear before or after destination options; it MUST + appear before next layer protocols (e.g., TCP, UDP, SCTP). In the + case of ESP, a transport mode SA provides security services only for + these next layer protocols, not for the IP header or any extension + headers preceding the ESP header. In the case of AH, the protection + is also extended to selected portions of the IP header preceding it, + selected portions of extension headers, and selected options + (contained in the IPv4 header, IPv6 Hop-by-Hop extension header, or + IPv6 Destination extension headers). For more details on the + coverage afforded by AH, see the AH specification [Ken05b]. + + A tunnel mode SA is essentially an SA applied to an IP tunnel, with + the access controls applied to the headers of the traffic inside the + tunnel. Two hosts MAY establish a tunnel mode SA between themselves. + + +Kent & Seo [Page 14] + +Internet Draft Security Architecture for IP March 2005 + + + Aside from the two exceptions below, whenever either end of a + security association is a security gateway, the SA MUST be tunnel + mode. Thus an SA between two security gateways is typically a tunnel + mode SA, as is an SA between a host and a security gateway. The two + exceptions are as follows. + + o Where traffic is destined for a security gateway, e.g., SNMP + commands, the security gateway is acting as a host and transport + mode is allowed. In this case, the SA terminates at a host + (management) function within a security gateway and thus merits + different treatment. + + o As noted above, security gateways MAY support a transport mode SA + to provide security for IP traffic between two intermediate + systems along a path, e.g., between a host and a security gateway + or between two security gateways. + + Several concerns motivate the use of tunnel mode for an SA involving + a security gateway. For example, if there are multiple paths (e.g., + via different security gateways) to the same destination behind a + security gateway, it is important that an IPsec packet be sent to the + security gateway with which the SA was negotiated. Similarly, a + packet that might be fragmented en-route must have all the fragments + delivered to the same IPsec instance for reassembly prior to + cryptographic processing. Also, when a fragment is processed by IPsec + and transmitted, then fragmented en-route, it is critical that there + be inner and outer headers to retain the fragmentation state data for + the pre- and post-IPsec packet formats. Hence there are several + reasons for employing tunnel mode when either end of an SA is a + security gateway. (Use of an IP-in-IP tunnel in conjunction with + transport mode can also address these fragmentation issues. However, + this configuration limits the ability of IPsec to enforce access + control policies on traffic.) + + Note: AH and ESP cannot be applied using transport mode to IPv4 + packets that are fragments. Only tunnel mode can be employed in such + cases. For IPv6, it would be feasible to carry a plaintext fragment + on a transport mode SA; however, for simplicity, this restriction + also applies to IPv6 packets. See Section 7 for more details on + handling plaintext fragments on the protected side of the IPsec + barrier. + + For a tunnel mode SA, there is an "outer" IP header that specifies + the IPsec processing source and destination, plus an "inner" IP + header that specifies the (apparently) ultimate source and + destination for the packet. The security protocol header appears + after the outer IP header, and before the inner IP header. If AH is + employed in tunnel mode, portions of the outer IP header are afforded + protection (as above), as well as all of the tunneled IP packet + + +Kent & Seo [Page 15] + +Internet Draft Security Architecture for IP March 2005 + + + (i.e., all of the inner IP header is protected, as well as next layer + protocols). If ESP is employed, the protection is afforded only to + the tunneled packet, not to the outer header. + + In summary, + + a) A host implementation of IPsec MUST support both transport and + tunnel mode. This is true for native, BITS, and BITW + implementations for hosts. + + b) A security gateway MUST support tunnel mode and MAY support + transport mode. If it supports transport mode, that should be + used only when the security gateway is acting as a host, e.g., for + network management, or to provide security between two + intermediate systems along a path. + +4.2 SA Functionality + + The set of security services offered by an SA depends on the security + protocol selected, the SA mode, the endpoints of the SA, and on the + election of optional services within the protocol. + + For example, both AH and ESP offer integrity and authentication + services, but the coverage differs for each protocol and differs for + transport vs. tunnel mode. If the integrity of an IPv4 option or IPv6 + extension header must be protected en-route between sender and + receiver, AH can provide this service, except for IP or extension + headers that may change in a fashion not predictable by the sender. + However, the same security may be achieved in some contexts by + applying ESP to a tunnel carrying a packet. + + The granularity of access control provided is determined by the + choice of the selectors that define each SA. Moreover, the + authentication means employed by IPsec peers, e.g., during creation + of an IKE (vs. child) SA also effects the granularity of the access + control afforded. + + If confidentiality is selected, then an ESP (tunnel mode) SA between + two security gateways can offer partial traffic flow confidentiality. + The use of tunnel mode allows the inner IP headers to be encrypted, + concealing the identities of the (ultimate) traffic source and + destination. Moreover, ESP payload padding also can be invoked to + hide the size of the packets, further concealing the external + characteristics of the traffic. Similar traffic flow confidentiality + services may be offered when a mobile user is assigned a dynamic IP + address in a dialup context, and establishes a (tunnel mode) ESP SA + to a corporate firewall (acting as a security gateway). Note that + fine granularity SAs generally are more vulnerable to traffic + analysis than coarse granularity ones that are carrying traffic from + + +Kent & Seo [Page 16] + +Internet Draft Security Architecture for IP March 2005 + + + many subscribers. + + Note: A compliant implementation MUST NOT allow instantiation of an + ESP SA that employs both NULL encryption and no integrity algorithm. + An attempt to negotiate such an SA is an auditable event by both + initiator and responder. The audit log entry for this event SHOULD + include the current date/time, local IKE IP address, and remote IKE + IP address. The initiator SHOULD record the relevant SPD entry. + +4.3 Combining SAs + + This document does not require support for nested security + associations or for what RFC 2401 called "SA bundles." These features + still can be effected by appropriate configuration of both the SPD + and the local forwarding functions (for inbound and outbound + traffic), but this capability is outside of the IPsec module and thus + the scope of this specification. As a result, management of + nested/bundled SAs is potentially more complex and less assured than + under the model implied by RFC 2401. An implementation that provides + support for nested SAs SHOULD provide a management interface that + enables a user or administrator to express the nesting requirement, + and then create the appropriate SPD entries and forwarding table + entries to effect the requisite processing. (See Appendix E for an + example of how to configure nested SAs.) + +4.4 Major IPsec Databases + + Many of the details associated with processing IP traffic in an IPsec + implementation are largely a local matter, not subject to + standardization. However, some external aspects of the processing + must be standardized to ensure interoperability and to provide a + minimum management capability that is essential for productive use of + IPsec. This section describes a general model for processing IP + traffic relative to IPsec functionality, in support of these + interoperability and functionality goals. The model described below + is nominal; implementations need not match details of this model as + presented, but the external behavior of implementations MUST + correspond to the externally observable characteristics of this model + in order to be compliant. + + There are three nominal databases in this model: the Security Policy + Database (SPD), the Security Association Database (SAD), and the Peer + Authorization Database (PAD). The first specifies the policies that + determine the disposition of all IP traffic inbound or outbound from + a host or security gateway (Section 4.4.1). The second database + contains parameters that are associated with each established (keyed) + SA (Section 4.4.2). The third database, the Peer Authorization + Database (PAD) provides a link between an SA management protocol like + IKE and the SPD (Section 4.4.3). + + +Kent & Seo [Page 17] + +Internet Draft Security Architecture for IP March 2005 + + + Multiple Separate IPsec Contexts + + If an IPsec implementation acts as a security gateway for multiple + subscribers, it MAY implement multiple separate IPsec contexts. + Each context MAY have and MAY use completely independent + identities, policies, key management SAs, and/or IPsec SAs. This + is for the most part a local implementation matter. However, a + means for associating inbound (SA) proposals with local contexts + is required. To this end, if supported by the key management + protocol in use, context identifiers MAY be conveyed from + initiator to responder in the signaling messages, with the result + that IPsec SAs are created with a binding to a particular context. + For example, a security gateway that provides VPN service to + multiple customers will be able to associate each customer's + traffic with the correct VPN. + + Forwarding vs Security Decisions + + The IPsec model described here embodies a clear separation between + forwarding (routing) and security decisions, to accommodate a wide + range of contexts where IPsec may be employed. Forwarding may be + trivial, in the case where there are only two interfaces, or it + may be complex, e.g., if the context in which IPsec is implemented + employs a sophisticated forwarding function. IPsec assumes only + that outbound and inbound traffic that has passed through IPsec + processing is forwarded in a fashion consistent with the context + in which IPsec is implemented. Support for nested SAs is optional; + if required, it requires coordination between forwarding tables + and SPD entries to cause a packet to traverse the IPsec boundary + more than once. + + "Local" vs "Remote" + + In this document, with respect to IP addresses and ports, the + terms "Local" and "Remote" are used for policy rules. "Local" + refers to the entity being protected by an IPsec implementation, + i.e., the "source" address/port of outbound packets or the + "destination" address/port of inbound packets. "Remote" refers to + a peer entity or peer entities. The terms "source" and + "destination" are used for packet header fields. + + "Non-initial" vs "Initial" Fragments + + Throughout this document, the phrase "non-initial" fragments is + used to mean fragments that do not contain all of the selector + values that may be needed for access control (e.g., they might not + contain Next Layer Protocol, source and destination ports, ICMP + message type/code, Mobility Header type). And the phrase "initial" + fragment is used to mean a fragment that contains all the selector + + +Kent & Seo [Page 18] + +Internet Draft Security Architecture for IP March 2005 + + + values needed for access control. However, it should be noted that + for IPv6, which fragment contains the Next Layer Protocol and + ports (or ICMP message type/code or Mobility Header type) will + depend on the kind and number of extension headers present. The + "initial" fragment might not be the first fragment, in this + context. + +4.4.1 The Security Policy Database (SPD) + + An SA is a management construct used to enforce security policy for + traffic crossing the IPsec boundary. Thus an essential element of SA + processing is an underlying Security Policy Database (SPD) that + specifies what services are to be offered to IP datagrams and in what + fashion. The form of the database and its interface are outside the + scope of this specification. However, this section specifies minimum + management functionality that must be provided, to allow a user or + system administrator to control whether and how IPsec is applied to + traffic transmitted or received by a host or transiting a security + gateway. The SPD, or relevant caches, must be consulted during the + processing of all traffic (inbound and outbound), including traffic + not protected by IPsec, that traverses the IPsec boundary. This + includes IPsec management traffic such as IKE. An IPsec + implementation MUST have at least one SPD, and it MAY support + multiple SPDs, if appropriate for the context in which the IPsec + implementation operates. There is no requirement to maintain SPDs on + a per interface basis, as was specified in RFC 2401. However, if an + implementation supports multiple SPDs, then it MUST include an + explicit SPD selection function, that is invoked to select the + appropriate SPD for outbound traffic processing. The inputs to this + function are the outbound packet and any local metadata (e.g., the + interface via which the packet arrived) required to effect the SPD + selection function. The output of the function is an SPD identifier + (SPD-ID). + + The SPD is an ordered database, consistent with the use of ACLs or + packet filters in firewalls, routers, etc. The ordering requirement + arises because entries often will overlap due to the presence of + (non-trivial) ranges as values for selectors. Thus a user or + administrator MUST be able to order the entries to express a desired + access control policy. There is no way to impose a general, canonical + order on SPD entries, because of the allowed use of wildcards for + selector values and because the different types of selectors are not + hierarchically related. + + Processing Choices: DISCARD, BYPASS, PROTECT + + An SPD must discriminate among traffic that is afforded IPsec + protection and traffic that is allowed to bypass IPsec. This + applies to the IPsec protection to be applied by a sender and to + + +Kent & Seo [Page 19] + +Internet Draft Security Architecture for IP March 2005 + + + the IPsec protection that must be present at the receiver. For + any outbound or inbound datagram, three processing choices are + possible: DISCARD, BYPASS IPsec, or PROTECT using IPsec. The + first choice refers to traffic that is not allowed to traverse the + IPsec boundary (in the specified direction). The second choice + refers to traffic that is allowed to cross the IPsec boundary + without IPsec protection. The third choice refers to traffic that + is afforded IPsec protection, and for such traffic the SPD must + specify the security protocols to be employed, their mode, + security service options, and the cryptographic algorithms to be + used. + + SPD-S, SPD-I, SPD-O + + An SPD is logically divided into three pieces. The SPD-S (secure + traffic) contains entries for all traffic subject to IPsec + protection. SPD-O (outbound) contains entries for all outbound + traffic that is to be bypassed or discarded. SPD-I (inbound) is + applied to inbound traffic that will be bypassed or discarded. All + three of these can be decorrelated (with the exception noted above + for native host implementations) to facilitate caching. If an + IPsec implementation supports only one SPD, then the SPD consists + of all three parts. If multiple SPDs are supported, some of them + may be partial, e.g., some SPDs might contain only SPD-I entries, + to control inbound bypassed traffic on a per-interface basis. The + split allows SPD-I to be consulted without having to consult + SPD-S, for such traffic. Since the SPD-I is just a part of the + SPD, if a packet that is looked up in the SPD-I cannot be matched + to an entry there, then the packet MUST be discarded. Note that + for outbound traffic, if a match is not found in SPD-S, then SPD-O + must be checked to see if the traffic should be bypassed. + Similarly, if SPD-O is checked first and no match is found, then + SPD-S must be checked. In an ordered, non-decorrelated SPD, the + entries for the SPD-S, SPD-I, and SPD-O are interleaved. So there + is one look up in the SPD. + + SPD entries + + Each SPD entry specifies packet disposition as BYPASS, DISCARD, or + PROTECT. The entry is keyed by a list of one or more selectors. + The SPD contains an ordered list of these entries. The required + selector types are defined in Section 4.4.1.1. These selectors are + used to define the granularity of the SAs that are created in + response to an outbound packet or in response to a proposal from a + peer. The detailed structure of an SPD entry is described in + Section 4.4.1.2. Every SPD SHOULD have a nominal, final entry that + matches anything that is otherwise unmatched, and discards it. + + The SPD MUST permit a user or administrator to specify policy + + +Kent & Seo [Page 20] + +Internet Draft Security Architecture for IP March 2005 + + + entries as follows: + + - SPD-I: For inbound traffic that is to be bypassed or discarded, + the entry consists of the values of the selectors that apply to + the traffic to be bypassed or discarded. + + - SPD-O: For outbound traffic that is to be bypassed or + discarded, the entry consists of the values of the selectors + that apply to the traffic to be bypassed or discarded. + + - SPD-S: For traffic that is to be protected using IPsec, the + entry consists of the values of the selectors that apply to the + traffic to be protected via AH or ESP, controls on how to + create SAs based on these selectors, and the parameters needed + to effect this protection (e.g., algorithms, modes, etc.). Note + that an SPD-S entry also contains information such as "populate + from packet" (PFP) flag (see paragraphs below on "How To Derive + the Values for an SAD entry") and bits indicating whether the + SA lookup makes use of the local and remote IP addresses in + addition to the SPI (see AH [Ken05b] or ESP [Ken05a] + specifications). + + Representing directionality in an SPD entry + + For traffic protected by IPsec, the Local and Remote address and + ports in an SPD entry are swapped to represent directionality, + consistent with IKE conventions. In general, the protocols that + IPsec deals with have the property of requiring symmetric SAs with + flipped Local/Remote IP addresses. However, for ICMP, there is + often no such bi-directional authorization requirement. + Nonetheless, for the sake of uniformity and simplicity, SPD + entries for ICMP are specified in the same way as for other + protocols. Note also that for ICMP, Mobility Header, and + non-initial fragments, there are no port fields in these packets. + ICMP has message type and code and Mobility Header has mobility + header type. Thus SPD entries have provisions for expressing + access controls appropriate for these protocols, in lieu of the + normal port field controls. For bypassed or discarded traffic, + separate inbound and outbound entries are supported, e.g., to + permit unidirectional flows if required. + + OPAQUE and ANY + + For each selector in an SPD entry, in addition to the literal + values that define a match, there are two special values: ANY and + OPAQUE. ANY is a wildcard that matches any value in the + corresponding field of the packet, or that matches packets where + that field is not present or is obscured. OPAQUE indicates that + the corresponding selector field is not available for examination + + +Kent & Seo [Page 21] + +Internet Draft Security Architecture for IP March 2005 + + + because it may not be present in a fragment, does not exist for + the given Next Layer Protocol, or because prior application of + IPsec may have encrypted the value. The ANY value encompasses the + OPAQUE value. Thus OPAQUE need be used only when it is necessary + to distinguish between the case of any allowed value for a field, + vs. the absence or unavailability (e.g., due to encryption) of the + field. + + How To Derive the Values for an SAD entry + + For each selector in an SPD entry, the entry specifies how to + derive the corresponding values for a new SA Database (SAD, see + Section 4.4.2) entry from those in the SPD and the packet. The + goal is to allow an SAD entry and an SPD cache entry to be created + based on specific selector values from the packet, or from the + matching SPD entry. For outbound traffic, there are SPD-S cache + entries and SPD-O cache entries. For inbound traffic not + protected by IPsec, there are SPD-I cache entries and there is the + SAD, which represents the cache for inbound IPsec-protected + traffic (See Section 4.4.2). If IPsec processing is specified for + an entry, a "populate from packet" (PFP) flag may be asserted for + one or more of the selectors in the SPD entry (Local IP address; + Remote IP address; Next Layer Protocol; and, depending on Next + Layer Protocol, Local port and Remote port, or ICMP type/code, or + Mobility Header type). If asserted for a given selector X, the + flag indicates that the SA to be created should take its value for + X from the value in the packet. Otherwise, the SA should take its + value(s) for X from the value(s) in the SPD entry. Note: In the + non-PFP case, the selector values negotiated by the SA management + protocol (e.g., IKE v2) may be a subset of those in the SPD entry, + depending on the SPD policy of the peer. Also, whether a single + flag is used for, e.g., source port, ICMP type/code, and MH type, + or a separate flag is used for each, is a local matter. + + The following example illustrates the use of the PFP flag in the + context of a security gateway or a BITS/BITW implementation. + Consider an SPD entry where the allowed value for Remote address + is a range of IPv4 addresses: 192.0.2.1 to 192.0.2.10. Suppose an + outbound packet arrives with a destination address of 192.0.2.3, + and there is no extant SA to carry this packet. The value used for + the SA created to transmit this packet could be either of the two + values shown below, depending on what the SPD entry for this + selector says is the source of the selector value: + + + + + + + + +Kent & Seo [Page 22] + +Internet Draft Security Architecture for IP March 2005 + + + PFP flag value example of new + for the Remote SAD dest. address + addr. selector selector value + --------------- ------------ + a. PFP TRUE 192.0.2.3 (one host) + b. PFP FALSE 192.0.2.1 to 192.0.2.10 (range of hosts) + + Note that if the SPD entry above had a value of ANY for the Remote + address, then the SAD selector value would have to be ANY for case + (b), but would still be as illustrated for case (a). Thus the PFP + flag can be used to prohibit sharing of an SA, even among packets + that match the same SPD entry. + + Management Interface + + For every IPsec implementation, there MUST be a management + interface that allows a user or system administrator to manage the + SPD. The interface must allow the user (or administrator) to + specify the security processing to be applied to every packet that + traverses the IPsec boundary. (In a native host IPsec + implementation making use of a socket interface, the SPD may not + need to be consulted on a per packet basis, as noted above.) The + management interface for the SPD MUST allow creation of entries + consistent with the selectors defined in Section 4.4.1.1, and MUST + support (total) ordering of these entries, as seen via this + interface. The SPD entries' selectors are analogous to the ACL or + packet filters commonly found in a stateless firewall or packet + filtering router and which are currently managed this way. + + In host systems, applications MAY be allowed to create SPD + entries. (The means of signaling such requests to the IPsec + implementation are outside the scope of this standard.) However, + the system administrator MUST be able to specify whether or not a + user or application can override (default) system policies. The + form of the management interface is not specified by this document + and may differ for hosts vs. security gateways, and within hosts + the interface may differ for socket-based vs. BITS + implementations. However, this document does specify a standard + set of SPD elements that all IPsec implementations MUST support. + + Decorrelation + + The processing model described in this document assumes the + ability to decorrelate overlapping SPD entries to permit caching, + which enables more efficient processing of outbound traffic in + security gateways and BITS/BITW implementations. Decorrelation + [CoSa04] is only a means of improving performance and simplifying + the processing description. This RFC does not require a compliant + implementation to make use of decorrelation. For example, native + + +Kent & Seo [Page 23] + +Internet Draft Security Architecture for IP March 2005 + + + host implementations typically make use of caching implicitly + because they bind SAs to socket interfaces, and thus there is no + requirement to be able to decorrelate SPD entries in these + implementations. + + Note: Unless otherwise qualified, the use of "SPD" refers to the + body of policy information in both ordered or decorrelated + (unordered) state. Appendix B provides an algorithm that can be + used to decorrelate SPD entries, but any algorithm that produces + equivalent output may be used. Note that when an SPD entry is + decorrelated all the resulting entries MUST be linked together, so + that all members of the group derived from an individual, SPD + entry (prior to decorrelation) can all be placed into caches and + into the SAD at the same time. For example, suppose one starts + with an entry A (from an ordered SPD) that when decorrelated, + yields entries A1, A2 and A3. When a packet comes along that + matches, say A2, and triggers the creation of an SA, the SA + management protocol, e.g., IKE v2, negotiates A. And all 3 + decorrelated entries, A1, A2, and A3 are placed in the appropriate + SPD-S cache and linked to the SA. The intent is that use of a + decorrelated SPD ought not to create more SAs than would have + resulted from use of a not-decorrelated SPD. + + If a decorrelated SPD is employed, there are three options for + what an initiator sends to a peer via an SA management protocol + (e.g., IKE). By sending the complete set of linked, decorrelated + entries that were selected from the SPD, a peer is given the best + possible information to enable selection of the appropriate SPD + entry at its end, especially if the peer has also decorrelated its + SPD. However, if a large number of decorrelated entries are + linked, this may create large packets for SA negotiation, and + hence fragmentation problems for the SA management protocol. + + Alternatively, the original entry from the (correlated) SPD may be + retained and passed to the SA management protocol. Passing the + correlated SPD entry keeps the use of a decorrelated SPD a local + matter, not visible to peers, and avoids possible fragmentation + concerns, although it provides less precise info to a responder + for matching against the responder's SPD. + + An intermediate approach is to send a subset of the complete set + of linked, decorrelated SPD entries. This approach can avoid the + fragmentation problems cited above and yet provide better + information than the original, correlated entry. The major + shortcoming of this approach is that it may cause additional SAs + to be created later, since only a subset of the linked, + decorrelated entries are sent to a peer. Implementers are free to + employ any of the approaches cited above. + + + +Kent & Seo [Page 24] + +Internet Draft Security Architecture for IP March 2005 + + + A responder uses the traffic selector proposals it receives via an + SA management protocol to select an appropriate entry in its SPD. + The intent of the matching is to select an SPD entry and create an + SA that most closely matches the intent of the initiator, so that + traffic traversing the resulting SA will be accepted at both ends. + If the responder employs a decorrelated SPD, it SHOULD use the + decorrelated SPD entries for matching, as this will generally + result in creation of SAs that are more likely to match the intent + of both peers. If the responder has a correlated SPD, then it + SHOULD match the proposals against the correlated entries. For + IKE v2, use of a decorrelated SPD offers the best opportunity for + a responder to generate a "narrowed" response. + + In all cases, when a decorrelated SPD is available, the + decorrelated entries are used to populate the SPD-S cache. If the + SPD is not decorrelated, caching is not allowed and an ordered + search of SPD MUST be performed to verify that inbound traffic + arriving on an SA is consistent with the access control policy + expressed in the SPD. + + Handling Changes to the SPD while the System is Running + + If a change is made to the SPD while the system is running, a + check SHOULD be made of the effect of this change on extant SAs. + An implementation SHOULD check the impact of an SPD change on + extant SAs and SHOULD provide a user/administrator with a + mechanism for configuring what actions to take, e.g., delete an + affected SA, allow an affected SA to continue unchanged, etc. + +4.4.1.1 Selectors + + An SA may be fine-grained or coarse-grained, depending on the + selectors used to define the set of traffic for the SA. For example, + all traffic between two hosts may be carried via a single SA, and + afforded a uniform set of security services. Alternatively, traffic + between a pair of hosts might be spread over multiple SAs, depending + on the applications being used (as defined by the Next Layer Protocol + and related fields, e.g., ports), with different security services + offered by different SAs. Similarly, all traffic between a pair of + security gateways could be carried on a single SA, or one SA could be + assigned for each communicating host pair. The following selector + parameters MUST be supported by all IPsec implementations to + facilitate control of SA granularity. Note that both Local and Remote + addresses should either be IPv4 or IPv6, but not a mix of address + types. Also, note that the Local/Remote port selectors (and ICMP + message type and code, and Mobility Header type) may be labeled as + OPAQUE to accommodate situations where these fields are inaccessible + due to packet fragmentation. + + + +Kent & Seo [Page 25] + +Internet Draft Security Architecture for IP March 2005 + + + - Remote IP Address(es) (IPv4 or IPv6): this is a list of ranges + of IP addresses (unicast, broadcast (IPv4 only)). This structure + allows expression of a single IP address (via a trivial range), + or a list of addresses (each a trivial range), or a range of + addresses (low and high values, inclusive), as well as the most + generic form of a list of ranges. Address ranges are used to + support more than one remote system sharing the same SA, e.g., + behind a security gateway. + + - Local IP Address(es) (IPv4 or IPv6): this is a list of ranges of + IP addresses (unicast, broadcast (IPv4 only)). This structure + allows expression of a single IP address (via a trivial range), + or a list of addresses (each a trivial range), or a range of + addresses (low and high values, inclusive), as well as the most + generic form of a list of ranges. Address ranges are used to + support more than one source system sharing the same SA, e.g., + behind a security gateway. Local refers to the address(es) + being protected by this implementation (or policy entry). + + Note: The SPD does not include support for multicast address + entries. To support multicast SAs, an implementation should make + use of a Group SPD (GSPD) as defined in [RFC3740]. GSPD entries + require a different structure, i.e., one cannot use of the + symmetric relationship associated with local and remote address + values for unicast SAs in a multicast context. Specifically, + outbound traffic directed to a multicast address on an SA would + not be received on a companion, inbound SA with the multicast + address as the source. + + - Next Layer Protocol: Obtained from the IPv4 "Protocol" or the + IPv6 "Next Header" fields. This is an individual protocol + number, ANY, or for IPv6 only, OPAQUE. The Next Layer Protocol + is whatever comes after any IP extension headers that are + present. To simplify locating the Next Layer Protocol, there + SHOULD be a mechanism for configuring which IPv6 extension + headers to skip. The default configuration for which protocols + to skip SHOULD include the following protocols: 0 (Hop-by-hop + options), 43 (Routing Header), 44 (Fragmentation Header), and 60 + (Destination Options). Note: The default list does NOT include + 51 (AH), or 50 (ESP). From a selector lookup point of view, + IPsec treats AH and ESP as Next Layer Protocols. + + Several additional selectors depend on the Next Layer Protocol + value: + + * If the Next Layer Protocol uses two ports (e.g., TCP, UDP, + SCTP, ...), then there are selectors for Local and Remote + Ports. Each of these selectors has a list of ranges of + values. Note that the Local and Remote ports may not be + + +Kent & Seo [Page 26] + +Internet Draft Security Architecture for IP March 2005 + + + available in the case of receipt of a fragmented packet or if + the port fields have been protected by IPsec (encrypted), + thus a value of OPAQUE also MUST be supported. Note: In a + non-initial fragment, port values will not be available. If a + port selector specifies a value other than ANY or OPAQUE, it + cannot match packets that are non-initial fragments. If the + SA requires a port value other than ANY or OPAQUE, an + arriving fragment without ports MUST be discarded. (See + Section 7 Handling Fragments.) + + * If the Next Layer Protocol is a Mobility Header, then there + is a selector for IPv6 Mobility Header Message Type (MH type) + [Mobip]. This is an 8-bit value that identifies a particular + mobility message. Note that the MH type may not be available + in the case of receipt of a fragmented packet. (See Section 7 + Handling Fragments.) For IKE, the IPv6 mobility header + message type (MH type) is placed in the most significant + eight bits of the 16-bit local "port" selector. + + * If the Next Layer Protocol value is ICMP then there is a + 16-bit selector for the ICMP message type and code. The + message type is a single 8-bit value, which defines the type + of an ICMP message, or ANY. The ICMP code is a single 8-bit + value that defines a specific subtype for an ICMP message. + For IKE, the message type is placed in the most significant 8 + bits of the 16-bit selector and the code is placed in the + least significant 8 bits. This 16-bit selector can contain a + single type and a range of codes, a single type and ANY code, + ANY type and ANY code. Given a policy entry with a range of + Types (T-start to T-end) and a range of Codes (C-start to + C-end), and an ICMP packet with Type t and Code c, an + implementation MUST test for a match using + + (T-start*256) + C-start <= (t*256) + c <= (T-end*256) + + C-end + + Note that the ICMP message type and code may not be available + in the case of receipt of a fragmented packet. (See Section 7 + Handling Fragments.) + + - Name: This is not a selector like the others above. It is not + acquired from a packet. A name may be used as a symbolic + identifier for an IPsec Local or Remote address. Named SPD + entries are used in two ways: + + 1. A named SPD entry is used by a responder (not an initiator) + in support of access control when an IP address would not be + appropriate for the Remote IP address selector, e.g., for + "road warriors." The name used to match this field is + + +Kent & Seo [Page 27] + +Internet Draft Security Architecture for IP March 2005 + + + communicated during the IKE negotiation in the ID payload. + In this context, the initiator's Source IP address (inner IP + header in tunnel mode) is bound to the Remote IP address in + the SAD entry created by the IKE negotiation. This address + overrides the Remote IP address value in the SPD, when the + SPD entry is selected in this fashion. All IPsec + implementations MUST support this use of names. + + 2. A named SPD entry may be used by an initiator to identify a + user for whom an IPsec SA will be created (or for whom + traffic may be bypassed). The initiator's IP source address + (from inner IP header in tunnel mode) is used to replace the + following if and when they are created: + + - local address in the SPD cache entry + - local address in the outbound SAD entry + - remote address in the inbound SAD entry + + Support for this use is optional for multi-user, native host + implementations and not applicable to other implementations. + Note that this name is used only locally; it is not + communicated by the key management protocol. Also, name + forms other than those used for case 1 above (responder) are + applicable in the initiator context (see below). + + An SPD entry can contain both a name (or a list of names) and + also values for the Local or Remote IP address. + + For case 1, responder, the identifiers employed in named SPD + entries are one of the following four types: + + a. a fully qualified user name string (email), e.g., + mozart@foo.example.com + (this corresponds to ID_RFC822_ADDR in IKE v2) + + b. a fully qualified DNS name, e.g., + foo.example.com + (this corresponds to ID_FQDN in IKE v2) + + c. X.500 distinguished name, e.g., [WaKiHo97], + + + CN = Stephen T. Kent, O = BBN Technologies, + SP = MA, C = US + + (this corresponds to ID_DER_ASN1_DN in IKE v2, after + decoding) + + d. a byte string + + +Kent & Seo [Page 28] + +Internet Draft Security Architecture for IP March 2005 + + + (this corresponds to Key_ID in IKE v2) + + For case 2, initiator, the identifiers employed in named SPD + entries are of type byte string. They are likely to be Unix + UIDs, Windows security IDs or something similar, but could also + be a user name or account name. In all cases, this identifier + is only of local concern and is not transmitted. + + The IPsec implementation context determines how selectors are used. + For example, a native host implementation typically makes use of a + socket interface. When a new connection is established the SPD can + be consulted and an SA bound to the socket. Thus traffic sent via + that socket need not result in additional lookups to the SPD (SPD-O + and SPD-S) cache. In contrast, a BITS, BITW, or security gateway + implementation needs to look at each packet and perform an + SPD-O/SPD-S cache lookup based on the selectors. + +4.4.1.2 Structure of an SPD entry + + This section contains a prose description of an SPD entry. Also, + Appendix C provides an example of an ASN.1 definition of an SPD + entry. + + This text describes the SPD in a fashion that is intended to map + directly into IKE payloads to ensure that the policy required by SPD + entries can be negotiated through IKE. Unfortunately, the semantics + of the version of IKE v2 published concurrently with this document + [Kau05] do not align precisely with those defined for the SPD. + Specifically, IKE v2 does not enable negotiation of a single SA that + binds multiple pairs of local and remote addresses and ports to a + single SA. Instead, when multiple local and remote addresses and + ports are negotiated for an SA, IKE v2 treats these not as pairs, but + as (unordered) sets of local and remote values that can be + arbitrarily paired. Until IKE provides a facility that conveys the + semantics that are expressed in the SPD via selector sets (as + described below), users MUST NOT include multiple selector sets in a + single SPD entry unless the access control intent aligns with the IKE + "mix and match" semantics. An implementation MAY warn users, to alert + them to this problem if users create SPD entries with multiple + selector sets, the syntax of which indicates possible conflicts with + current IKE semantics. + + The management GUI can offer the user other forms of data entry and + display, e.g., the option of using address prefixes as well as + ranges, and symbolic names for protocols, ports, etc. (Do not confuse + the use of symbolic names in a management interface with the SPD + selector "Name".) Note that Remote/Local apply only to IP addresses + and ports, not to ICMP message type/code or Mobility Header type. + Also, if the reserved, symbolic selector value OPAQUE or ANY is + + +Kent & Seo [Page 29] + +Internet Draft Security Architecture for IP March 2005 + + + employed for a given selector type, only that value may appear in the + list for that selector, and it must appear only once in the list for + that selector. Note that ANY and OPAQUE are local syntax conventions + -- IKE v2 negotiates these values via the ranges indicated below: + + ANY: start = 0 end = + OPAQUE: start = end = 0 + + An SPD is an ordered list of entries each of which contains the + following fields. + + o Name -- a list of IDs. This quasi-selector is optional. + The forms that MUST be supported are described above in + Section 4.4.1.1 under "Name". + + o PFP flags -- one per traffic selector. A given flag, e.g., + for Next Layer Protocol, applies to the relevant selector + across all "selector sets" (see below) contained in an SPD + entry. When creating an SA, each flag specifies for the + corresponding traffic selector whether to instantiate the + selector from the corresponding field in the packet that + + triggered the creation of the SA or from the value(s) in + the corresponding SPD entry (see Section 4.4.1, "How To + Derive the Values for an SAD entry"). Whether a single + flag is used for, e.g., source port, ICMP type/code, and + MH type, or a separate flag is used for each, is a local + matter. There are PFP flags for: + - Local Address + - Remote Address + - Next Layer Protocol + - Local Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + - Remote Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + + o One to N selector sets that correspond to the "condition" + for applying a particular IPsec action. Each selector set + contains: + - Local Address + - Remote Address + - Next Layer Protocol + - Local Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + - Remote Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + + Note: The "next protocol" selector is an individual value + (unlike the local and remote IP addresses) in a selector + + +Kent & Seo [Page 30] + +Internet Draft Security Architecture for IP March 2005 + + + set entry. This is consistent with how IKE v2 negotiates + the TS values for an SA. It also makes sense because one + may need to associate different port fields with different + protocols. It is possible to associate multiple protocols + (and ports) with a single SA by specifying multiple + selector sets for that SA. + + o processing info -- which action is required -- PROTECT, + BYPASS, or DISCARD. There is just one action that goes with + all the selector sets, not a separate action for each set. + If the required processing is PROTECT, the entry contains + the following information. + - IPsec mode -- tunnel or transport + - (if tunnel mode) local tunnel address -- For a + non-mobile host, if there is just one interface, this + is straightforward; and if there are multiple + interfaces, this must be statically configured. For a + mobile host, the specification of the local address + is handled externally to IPsec. + - (if tunnel mode) remote tunnel address -- There is no + standard way to determine this. See 4.5.3 "Locating a + Security Gateway". + - extended sequence number -- Is this SA using extended + sequence numbers? + - stateful fragment checking -- Is this SA using + stateful fragment checking (see Section 7 for more + details) + - Bypass DF bit (T/F) -- applicable to tunnel mode SAs + - Bypass DSCP (T/F) or map to unprotected DSCP values + (array) if needed to restrict bypass of DSCP values -- + applicable to tunnel mode SAs + - IPsec protocol -- AH or ESP + - algorithms -- which ones to use for AH, which ones to + use for ESP, which ones to use for combined mode, + ordered by decreasing priority + + It is a local matter as to what information is kept with regard to + handling extant SAs when the SPD is changed. + +4.4.1.3 More re: Fields Associated with Next Layer Protocols + + Additional selectors are often associated with fields in the Next + Layer Protocol header. A particular Next Layer Protocol can have + zero, one, or two selectors. There may be situations where there + aren't both local and remote selectors for the fields that are + dependent on the Next Layer Protocol. The IPv6 Mobility Header has + only a Mobility Header message type. AH and ESP have no further + selector fields. A system may be willing to send an ICMP message + type and code that it does not want to receive. In the descriptions + + +Kent & Seo [Page 31] + +Internet Draft Security Architecture for IP March 2005 + + + below, "port" is used to mean a field that is dependent on the Next + Layer Protocol. + + A. If a Next Layer Protocol has no "port" selectors, then + the Local and Remote "port" selectors are set to OPAQUE in + the relevant SPD entry, e.g., + + Local's + next layer protocol = AH + "port" selector = OPAQUE + + Remote's + next layer protocol = AH + "port" selector = OPAQUE + + B. If a Next Layer Protocol has only one selector, e.g., + Mobility Header type, then that field is placed in the + Local "port" selector in the relevant SPD entry, and the + Remote "port" selector is set to OPAQUE in the relevant + SPD entry, e.g., + + Local's + next layer protocol = Mobility Header + "port" selector = Mobility Header message type + + Remote's + next layer protocol = Mobility Header + "port" selector = OPAQUE + + C. If a system is willing to send traffic with a particular + "port" value but NOT receive traffic with that kind of + port value, the system's traffic selectors are set as + follows in the relevant SPD entry: + + Local's + next layer protocol = ICMP + "port" selector = + + Remote's + next layer protocol = ICMP + "port" selector = OPAQUE + + D. To indicate that a system is willing to receive traffic + with a particular "port" value but NOT send that kind of + traffic, the system's traffic selectors are set as follows + in the relevant SPD entry: + + Local's + next layer protocol = ICMP + + +Kent & Seo [Page 32] + +Internet Draft Security Architecture for IP March 2005 + + + "port" selector = OPAQUE + + Remote's + next layer protocol = ICMP + "port" selector = + + For example, if a security gateway is willing to allow + systems behind it to send ICMP traceroutes, but is not + willing to let outside systems run ICMP traceroutes to + systems behind it, then the security gateway's traffic + selectors are set as follows in the relevant SPD entry: + + Local's + next layer protocol = 1 (ICMPv4) + "port" selector = 30 (traceroute) + + Remote's + next layer protocol = 1 (ICMPv4) + "port" selector = OPAQUE + +4.4.2 Security Association Database (SAD) + + In each IPsec implementation there is a nominal Security Association + Database (SAD), in which each entry defines the parameters associated + with one SA. Each SA has an entry in the SAD. For outbound + processing, each SAD entry is pointed to by entries in the SPD-S part + of the SPD cache. For inbound processing, for unicast SAs, the SPI is + used either alone to look up an SA, or the SPI may be used in + conjunction with the IPsec protocol type. If an IPsec implementation + supports multicast, the SPI plus destination address, or SPI plus + destination and source addresses are used to look up the SA. (See + Section 4.1 for details on the algorithm that MUST be used for + mapping inbound IPsec datagrams to SAs.) The following parameters are + associated with each entry in the SAD. They should all be present + except where otherwise noted, e.g., AH Authentication algorithm. This + description does not purport to be a MIB, only a specification of the + minimal data items required to support an SA in an IPsec + implementation. + + For each of the selectors defined in Section 4.4.1.1, the entry for + an inbound SA in the SAD MUST be initially populated with the value + or values negotiated at the time the SA was created. (See Section + 4.4.1, paragraph on Handling Changes to the SPD while the System is + Running for guidance on the effect of SPD changes on extant SAs.) For + a receiver, these values are used to check that the header fields of + an inbound packet (after IPsec processing) match the selector values + negotiated for the SA. Thus, the SAD acts as a cache for checking the + selectors of inbound traffic arriving on SAs. For the receiver, this + is part of verifying that a packet arriving on an SA is consistent + + +Kent & Seo [Page 33] + +Internet Draft Security Architecture for IP March 2005 + + + with the policy for the SA. (See Section 6 for rules for ICMP + messages.) These fields can have the form of specific values, + ranges, ANY, or OPAQUE, as described in section 4.4.1.1, "Selectors." + Note also, that there are a couple of situations in which the SAD can + have entries for SAs that do not have corresponding entries in the + SPD. Since 2401bis does not mandate that the SAD be selectively + cleared when the SPD is changed, SAD entries can remain when the SPD + entries that created them are changed or deleted. Also, if a manually + keyed SA is created, there could be an SAD entry for this SA that + does not correspond to any SPD entry. + + Note: The SAD can support multicast SAs, if manually configured. An + outbound multicast SA has the same structure as a unicast SA. The + source address is that of the sender and the destination address is + the multicast group address. An inbound, multicast SA must be + configured with the source addresses of each peer authorized to + transmit to the multicast SA in question. The SPI value for a + multicast SA is provided by a multicast group controller, not by the + receiver, as for a unicast SA. Because an SAD entry may be required + to accommodate multiple, individual IP source addresses that were + part of an SPD entry (for unicast SAs), the required facility for + inbound, multicast SAs is a feature already present in an IPsec + implementation. However, because the SPD has no provisions for + accommodating multicast entries, this document does not specify an + automated way to create an SAD entry for a multicast, inbound SA. + Only manually configured SAD entries can be created to accommodate + inbound, multicast traffic. + +4.4.2.1 Data Items in the SAD + + The following data items MUST be in the SAD: + + o Security Parameter Index (SPI): a 32-bit value selected by the + receiving end of an SA to uniquely identify the SA. In an SAD + entry for an outbound SA, the SPI is used to construct the + packet's AH or ESP header. In an SAD entry for an inbound SA, the + SPI is used to map traffic to the appropriate SA (see text on + unicast/multicast in Section 4.1). + + o Sequence Number Counter: a 64-bit counter used to generate the + Sequence Number field in AH or ESP headers. 64-bit sequence + numbers are the default, but 32-bit sequence numbers are also + supported if negotiated. + + o Sequence Counter Overflow: a flag indicating whether overflow of + the Sequence Number Counter should generate an auditable event and + prevent transmission of additional packets on the SA, or whether + rollover is permitted. The audit log entry for this event SHOULD + include the SPI value, current date/time, Local Address, Remote + + +Kent & Seo [Page 34] + +Internet Draft Security Architecture for IP March 2005 + + + Address, and the selectors from the relevant SAD entry. + + o Anti-Replay Window: a 64-bit counter and a bit-map (or equivalent) + used to determine whether an inbound AH or ESP packet is a replay. + + Note: If anti-replay has been disabled by the receiver for an SA, + e.g., in the case of a manually keyed SA, then the Anti-Replay + Window is ignored for the SA in question. 64-bit sequence numbers + are the default, but this counter size accommodates 32-bit + sequence numbers as well. + + o AH Authentication algorithm, key, etc. This is required only if AH + is supported. + + o ESP Encryption algorithm, key, mode, IV, etc. If a combined mode + algorithm is used, these fields will not be applicable. + + + o ESP integrity algorithm, keys, etc. If the integrity service is + not selected, these fields will not be applicable. If a combined + mode algorithm is used, these fields will not be applicable. + + + o ESP combined mode algorithms, key(s), etc. This data is used when + a combined mode (encryption and integrity) algorithm is used with + ESP. If a combined mode algorithm is not used, these fields are + not applicable. + + o Lifetime of this SA: a time interval after which an SA must be + replaced with a new SA (and new SPI) or terminated, plus an + indication of which of these actions should occur. This may be + expressed as a time or byte count, or a simultaneous use of both + with the first lifetime to expire taking precedence. A compliant + implementation MUST support both types of lifetimes, and MUST + support a simultaneous use of both. If time is employed, and if + IKE employs X.509 certificates for SA establishment, the SA + lifetime must be constrained by the validity intervals of the + certificates, and the NextIssueDate of the CRLs used in the IKE + exchange for the SA. Both initiator and responder are responsible + for constraining the SA lifetime in this fashion. Note: The + details of how to handle the refreshing of keys when SAs expire is + a local matter. However, one reasonable approach is: + + (a) If byte count is used, then the implementation SHOULD count the + number of bytes to which the IPsec cryptographic algorithm is + applied. For ESP, this is the encryption algorithm (including + Null encryption) and for AH, this is the authentication + algorithm. This includes pad bytes, etc. Note that + implementations MUST be able to handle having the counters at + + +Kent & Seo [Page 35] + +Internet Draft Security Architecture for IP March 2005 + + + the ends of an SA get out of synch, e.g., because of packet + loss or because the implementations at each end of the SA + aren't doing things the same way. + + (b) There SHOULD be two kinds of lifetime -- a soft lifetime that + warns the implementation to initiate action such as setting up + a replacement SA; and a hard lifetime when the current SA ends + and is destroyed. + + (c) If the entire packet does not get delivered during the SAs + lifetime, the packet SHOULD be discarded. + + o IPsec protocol mode: tunnel or transport. Indicates which mode of + AH or ESP is applied to traffic on this SA. + + o Stateful fragment checking flag. Indicates whether or not stateful + fragment checking applies to this SA. + + o Bypass DF bit (T/F) - applicable to tunnel mode SAs where both + inner and outer headers are IPv4. + + o DSCP values -- the set of DSCP values allowed for packets carried + over this SA. If no values are specified, no DSCP-specific + filtering is applied. If one or more values are specified, these + are used to select one SA among several that match the traffic + selectors for an outbound packet. Note that these values are NOT + checked against inbound traffic arriving on the SA. + + o Bypass DSCP (T/F) or map to unprotected DSCP values (array) if + needed to restrict bypass of DSCP values - applicable to tunnel + mode SAs. This feature maps DSCP values from an inner header to + values in an outer header, e.g., to address covert channel + signaling concerns. + + o Path MTU: any observed path MTU and aging variables. + + o Tunnel header IP source and destination address - both addresses + must be either IPv4 or IPv6 addresses. The version implies the + type of IP header to be used. Only used when the IPsec protocol + mode is tunnel. + +4.4.2.2 Relationship between SPD, PFP flag, packet, and SAD + + For each selector, the following tables show the relationship + between the value in the SPD, the PFP flag, the value in the + triggering packet and the resulting value in the SAD. Note that + the administrative interface for IPsec can use various syntactic + options to make it easier for the administrator to enter rules. + For example, although a list of ranges is what IKE v2 sends, it + + +Kent & Seo [Page 36] + +Internet Draft Security Architecture for IP March 2005 + + + might be clearer and less error prone for the user to enter a + single IP address or IP address prefix. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + loc addr list of ranges 0 IP addr "S" list of ranges + ANY 0 IP addr "S" ANY + list of ranges 1 IP addr "S" "S" + ANY 1 IP addr "S" "S" + + rem addr list of ranges 0 IP addr "D" list of ranges + ANY 0 IP addr "D" ANY + list of ranges 1 IP addr "D" "D" + ANY 1 IP addr "D" "D" + + protocol list of prot's* 0 prot. "P" list of prot's* + ANY** 0 prot. "P" ANY + OPAQUE**** 0 prot. "P" OPAQUE + + list of prot's* 0 not avail. discard packet + ANY** 0 not avail. ANY + OPAQUE**** 0 not avail. OPAQUE + + list of prot's* 1 prot. "P" "P" + ANY** 1 prot. "P" "P" + OPAQUE**** 1 prot. "P" *** + + list of prot's* 1 not avail. discard packet + ANY** 1 not avail. discard packet + OPAQUE**** 1 not avail. *** + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 37] + +Internet Draft Security Architecture for IP March 2005 + + + If the protocol is one that has two ports then there will be + selectors for both Local and Remote ports. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + loc port list of ranges 0 src port "s" list of ranges + ANY 0 src port "s" ANY + OPAQUE 0 src port "s" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 src port "s" "s" + ANY 1 src port "s" "s" + OPAQUE 1 src port "s" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + rem port list of ranges 0 dst port "d" list of ranges + ANY 0 dst port "d" ANY + OPAQUE 0 dst port "d" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 dst port "d" "d" + ANY 1 dst port "d" "d" + OPAQUE 1 dst port "d" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + + + + + + + + + + +Kent & Seo [Page 38] + +Internet Draft Security Architecture for IP March 2005 + + + If the protocol is mobility header then there will be a selector + for mh type. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + mh type list of ranges 0 mh type "T" list of ranges + ANY 0 mh type "T" ANY + OPAQUE 0 mh type "T" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 mh type "T" "T" + ANY 1 mh type "T" "T" + OPAQUE 1 mh type "T" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 39] + +Internet Draft Security Architecture for IP March 2005 + + + If the protocol is ICMP, then there will be a 16-bit selector for + ICMP type and ICMP code. Note that the type and code are bound to + each other, i.e., the codes apply to the particular type. This + 16-bit selector can contain a single type and a range of codes, a + single type and ANY code, and ANY type and ANY code. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + --------- ---------------- --- ------------ -------------- + ICMP type a single type & 0 type "t" & single type & + and code range of codes code "c" range of codes + a single type & 0 type "t" & single type & + ANY code code "c" ANY code + ANY type & ANY 0 type "t" & ANY type & + code code "c" ANY code + OPAQUE 0 type "t" & OPAQUE + code "c" + + a single type & 0 not avail. discard packet + range of codes + a single type & 0 not avail. discard packet + ANY code + ANY type & 0 not avail. ANY type & + ANY code ANY code + OPAQUE 0 not avail. OPAQUE + + a single type & 1 type "t" & "t" and "c" + range of codes code "c" + a single type & 1 type "t" & "t" and "c" + ANY code code "c" + ANY type & 1 type "t" & "t" and "c" + ANY code code "c" + OPAQUE 1 type "t" & *** + code "c" + + a single type & 1 not avail. discard packet + range of codes + a single type & 1 not avail. discard packet + ANY code + ANY type & 1 not avail. discard packet + ANY code + OPAQUE 1 not avail. *** + + + + + + + + +Kent & Seo [Page 40] + +Internet Draft Security Architecture for IP March 2005 + + + If the name selector is used... + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + --------- ---------------- --- ------------ -------------- + name list of user or N/A N/A N/A + system names + + + * "List of protocols" is the information, not the way + that the SPD or SAD or IKv2 have to represent this + information. + ** 0 (zero) is used by IKE to indicate ANY for + protocol. + *** Use of PFP=1 with an OPAQUE value is an error and + SHOULD be prohibited by an IPsec implementation. + **** The protocol field cannot be OPAQUE in IPv4. This + table entry applies only to IPv6. + +4.4.3 Peer Authorization Database (PAD) + + The Peer Authorization Database (PAD) provides the link between the + SPD and a security association management protocol such as IKE. It + embodies several critical functions: + + o identifies the peers or groups of peers that are authorized + to communicate with this IPsec entity + o specifies the protocol and method used to authenticate each + peer + o provides the authentication data for each peer + o constrains the types and values of IDs that can be asserted + by a peer with regard to child SA creation, to ensure that the + peer does not assert identities for lookup in the SPD that it + is not authorized to represent, when child SAs are created + o peer gateway location info, e.g., IP address(es) or DNS names, + MAY be included for peers that are known to be "behind" a + security gateway + The PAD provides these functions for an IKE peer when the peer acts + as either the initiator or the responder. + + To perform these functions, the PAD contains an entry for each peer + or group of peers with which the IPsec entity will communicate. An + entry names an individual peer (a user, end system or security + gateway) or specifies a group of peers (using ID matching rules + defined below). The entry specifies the authentication protocol + (e.g., IKE v1, IKE v2, KINK) method used (e.g., certificates or pre- + shared secrets) and the authentication data (e.g., the pre-shared + secret or the trust anchor relative to which the peer's certificate + + +Kent & Seo [Page 41] + +Internet Draft Security Architecture for IP March 2005 + + + will be validated). For certificate-based authentication, the entry + also may provide information to assist in verifying the revocation + status of the peer, e.g., a pointer to a CRL repository or the name + of an OSCP server associated with the peer or with the trust anchor + associated with the peer. + + Each entry also specifies whether the IKE ID payload will be used as + a symbolic name for SPD lookup, or whether the remote IP address + provided in traffic selector payloads will be used for SPD lookups + when child SAs are created. + + Note that the PAD information MAY be used to support creation of more + than one tunnel mode SA at a time between two peers, e.g., two + tunnels to protect the same addresses/hosts, but with different + tunnel endpoints. + +4.4.3.1 PAD Entry IDs and Matching Rules + + The PAD is an ordered database, where the order is defined by an + administrator (or a user in the case of a single-user end system). + Usually, the same administrator will be responsible for both the PAD + and SPD, since the two databases must be coordinated. The ordering + requirement for the PAD arises for the same reason as for the SPD, + i.e., because use of "star name" entries allows for overlaps in the + set of IKE IDs that could match a specific entry. + + Six types of IDs are supported for entries in the PAD, consistent + with the symbolic name types and IP addresses used to identify SPD + entries. The ID for each entry acts as the index for the PAD, i.e., + it is the value used to select an entry. All of these ID types can be + used to match IKE ID payload types. The six types are: + o DNS name (specific or partial) + o Distinguished Name (complete or sub-tree constrained) + o RFC822 email address (complete or partially qualified) + o IPv4 address (range) + o IPv6 address (range) + o Key ID (exact match only) + + The first three name types can accommodate sub-tree matching as well + as exact matches. A DNS name may be fully qualified and thus match + exactly one name, e.g., foo.example.com. Alternatively, the name may + encompass a group of peers by being partially specified, e.g., the + string ".example.com" could be used to match any DNS name ending in + these two domain name components. + + Similarly, a Distinguished Name may specify a complete DN to match + exactly one entry, e.g., CN = Stephen, O = BBN Technologies, SP = MA, + C = US. Alternatively, an entry may encompass a group of peers by + specifying a sub-tree, e.g., an entry of the form "C = US, SP = MA" + + +Kent & Seo [Page 42] + +Internet Draft Security Architecture for IP March 2005 + + + might be used to match all DNs that contain these two attributes as + the top two RDNs. + + For an RFC822 e-mail addresses, the same options exist. A complete + address such as foo@example.com matches one entity, but a sub-tree + name such as "@example.com" could be used to match all the entities + with names ending in those two domain names to the right of the @. + + The specific syntax used by an implementation to accommodate sub-tree + matching for distinguished names, domain names or RFC822 e-mail + addresses is a local matter. But, at a minimum, sub-tree matching of + the sort described above MUST be supported. (Substring matching + within a DN, DNS name or RFC822 address MAY be supported, but is not + required.) + + For IPv4 and IPv6 addresses, the same address range syntax used for + SPD entries MUST be supported. This allows specification of an + individual address (via a trivial range), an address prefix (by + choosing a range that adheres to CIDR-style prefixes), or an + arbitrary address range. + + The Key ID field is defined as an OCTET string in IKE. For this name + type, only exact match syntax MUST be supported (since there is no + explicit structure for this ID type. Additional matching functions + MAY be supported for this ID type. + +4.4.3.2 IKE Peer Authentication Data + + Once an entry is located based on an ordered search of the PAD based + on ID field matching, it is necessary to verify the asserted + identity, i.e., to authenticate the asserted ID. For each PAD entry + there is an indication of the type of authentication to be performed. + This document requires support for two required authentication data + types: + + - X.509 certificate + - pre-shared secret + + For authentication based on an X.509 certificate, the PAD entry + contains a trust anchor via which the end entity (EE) certificate for + the peer must be verifiable, either directly or via a certificate + path. See RFC 3280 for the definition of a trust anchor. An entry + used with certificate-based authentication MAY include additional + data to facilitate certificate revocation status, e.g., a list of + appropriate OCSP responders or CRL repositories, and associated + authentication data. For authentication based on a pre-shared secret, + the PAD contains the pre-shared secret to be used by IKE. + + This document does not require that the IKE ID asserted by a peer be + + +Kent & Seo [Page 43] + +Internet Draft Security Architecture for IP March 2005 + + + syntactically related to a specific field in an end entity + certificate that is employed to authenticate the identity of that + peer. However, it often will be appropriate to impose such a + requirement, e.g., when a single entry represents a set of peers each + of whom may have a distinct SPD entry. Thus implementations MUST + provide a means for an administrator to require a match between an + asserted IKE ID and the subject name or subject alt name in a + certificate. The former is applicable to IKE IDs expressed as + distinguished names; the latter is appropriate for DNS names, RFC822 + e-mail addresses, and IP addresses. Since KEY ID is intended for + identifying a peer authenticated via a pre-shred secret, there is no + requirement to match this ID type to a certificate field. + + See IKE v1 [HarCar98] and IKE v2 [Kau05] for details of how IKE + performs peer authentication using certificates or pre-shared + secrets. + + This document does not mandate support for any other authentication + methods, although such methods MAY be employed. + +4.4.3.3 Child SA Authorization Data + + Once an IKE peer is authenticated, child SAs may be created. Each PAD + entry contains data to constrain the set of IDs that can be asserted + by an IKE peer, for matching against the SPD. Each PAD entry + indicates whether the IKE ID is to be used as a symbolic name for SPD + matching, or whether an IP address asserted in a traffic selector + payload is to be used. + + If the entry indicates that the IKE ID is to be used, then the PAD + entry ID field defines the authorized set of IDs. If the entry + indicates that child SAs traffic selectors are to be used, then an + additional data element is required, in the form of IPv4 and/or IPv6 + address ranges. (A peer may be authorized for both address types, so + there MUST be provision for both a v4 and a v6 address range.) + +4.4.3.4 How the PAD Is Used + + During the initial IKE exchange, the initiator and responder each + assert their identity via the IKE ID payload, and send an AUTH + payload to verify the asserted identity. One or more CERT payloads + may be transmitted to facilitate the verification of each asserted + identity. + + When an IKE entity receives an IKE ID payload, it uses the asserted + ID to locate an entry in the PAD, using the matching rules described + above. The PAD entry specifies the authentication method to be + employed for the identified peer. This ensures that the right method + is used for each peer and that different methods can be used for + + +Kent & Seo [Page 44] + +Internet Draft Security Architecture for IP March 2005 + + + different peers. The entry also specifies the authentication data + that will be used to verify the asserted identity. This data is + employed in conjunction with the specified method to authenticate the + peer, before any CHILD SAs are created. + + + Child SAs are created based on the exchange of traffic selector + payloads, either at the end of the initial IKE exchange, or in + subsequent CREATE_CHILD_SA exchanges. The PAD entry for the (now + authenticated) IKE peer is used to constrain creation of child SAs, + specifically the PAD entry specifies how the SPD is searched using a + traffic selector proposal from a peer. There are two choices: either + the IKE ID asserted by the peer is used to find an SPD entry via its + symbolic name, or peer IP addresses asserted in traffic selector + payloads are used for SPD lookups based on the remote IP address + field portion of an SPD entry. It is necessary to impose these + constraints on creation of child SAs, to prevent an authenticated + peer from spoofing IDs associated with other, legitimate peers. + + Note that because the PAD is checked before searching for an SPD + entry, this safeguard protects an initiator against spoofing attacks. + For example, assume that IKE A receives an outbound packet destined + for IP address X, a host served by a security gateway. RFC 2401 and + 2401bis do not specify how A determines the address of the IKE peer + serving X. However, any peer contacted by A as the presumed + representative for X must be registered in the PAD in order to allow + the IKE exchange to be authenticated. Moreover, when the + authenticated peer asserts that it represents X in its traffic + selector exchange, the PAD will be consulted to determine if the peer + in question is authorized to represent X. Thus the PAD provides a + binding of address ranges (or name sub-spaces) to peers, to counter + such attacks. + + +4.5 SA and Key Management + + All IPsec implementations MUST support both manual and automated SA + and cryptographic key management. The IPsec protocols, AH and ESP, + are largely independent of the associated SA management techniques, + although the techniques involved do affect some of the security + services offered by the protocols. For example, the optional + anti-replay service available for AH and ESP requires automated SA + management. Moreover, the granularity of key distribution employed + with IPsec determines the granularity of authentication provided. In + general, data origin authentication in AH and ESP is limited by the + extent to which secrets used with the integrity algorithm (or with a + key management protocol that creates such secrets) are shared among + multiple possible sources. + + + +Kent & Seo [Page 45] + +Internet Draft Security Architecture for IP March 2005 + + + The following text describes the minimum requirements for both types + of SA management. + +4.5.1 Manual Techniques + + The simplest form of management is manual management, in which a + person manually configures each system with keying material and SA + management data relevant to secure communication with other systems. + Manual techniques are practical in small, static environments but + they do not scale well. For example, a company could create a + Virtual Private Network (VPN) using IPsec in security gateways at + several sites. If the number of sites is small, and since all the + sites come under the purview of a single administrative domain, this + might be a feasible context for manual management techniques. In + this case, the security gateway might selectively protect traffic to + and from other sites within the organization using a manually + configured key, while not protecting traffic for other destinations. + It also might be appropriate when only selected communications need + to be secured. A similar argument might apply to use of IPsec + entirely within an organization for a small number of hosts and/or + gateways. Manual management techniques often employ statically + configured, symmetric keys, though other options also exist. + +4.5.2 Automated SA and Key Management + + Widespread deployment and use of IPsec requires an Internet-standard, + scalable, automated, SA management protocol. Such support is required + to facilitate use of the anti-replay features of AH and ESP, and to + accommodate on-demand creation of SAs, e.g., for user- and + session-oriented keying. (Note that the notion of "rekeying" an SA + actually implies creation of a new SA with a new SPI, a process that + generally implies use of an automated SA/key management protocol.) + + The default automated key management protocol selected for use with + IPsec is IKE v2 [Kau05]. This document assumes the availability of + certain functions from the key management protocol which are not + supported by IKE v1. Other automated SA management protocols MAY be + employed. + + When an automated SA/key management protocol is employed, the output + from this protocol is used to generate multiple keys for a single SA. + This also occurs because distinct keys are used for each of the two + SAs created by IKE. If both integrity and confidentiality are + employed, then a minimum of four keys are required. Additionally, + some cryptographic algorithms may require multiple keys, e.g., 3DES. + + The Key Management System may provide a separate string of bits for + each key or it may generate one string of bits from which all keys + are extracted. If a single string of bits is provided, care needs to + + +Kent & Seo [Page 46] + +Internet Draft Security Architecture for IP March 2005 + + + be taken to ensure that the parts of the system that map the string + of bits to the required keys do so in the same fashion at both ends + of the SA. To ensure that the IPsec implementations at each end of + the SA use the same bits for the same keys, and irrespective of which + part of the system divides the string of bits into individual keys, + the encryption keys MUST be taken from the first (left-most, + high-order) bits and the integrity keys MUST be taken from the + remaining bits. The number of bits for each key is defined in the + relevant cryptographic algorithm specification RFC. In the case of + multiple encryption keys or multiple integrity keys, the + specification for the cryptographic algorithm must specify the order + in which they are to be selected from a single string of bits + provided to the cryptographic algorithm. + +4.5.3 Locating a Security Gateway + + This section discusses issues relating to how a host learns about the + existence of relevant security gateways and once a host has contacted + these security gateways, how it knows that these are the correct + security gateways. The details of where the required information is + stored is a local matter, but the Peer Authorization Database + described in Section 4.4 is the most likely candidate. (Note: S* + indicates a system that is running IPsec, e.g., SH1 and SG2 below.) + + Consider a situation in which a remote host (SH1) is using the + Internet to gain access to a server or other machine (H2) and there + is a security gateway (SG2), e.g., a firewall, through which H1's + traffic must pass. An example of this situation would be a mobile + host crossing the Internet to his home organization's firewall (SG2). + This situation raises several issues: + + 1. How does SH1 know/learn about the existence of the security + gateway SG2? + + 2. How does it authenticate SG2, and once it has authenticated SG2, + how does it confirm that SG2 has been authorized to represent H2? + + 3. How does SG2 authenticate SH1 and verify that SH1 is authorized to + contact H2? + + 4. How does SH1 know/learn about any additional gateways that provide + alternate paths to H2? + + To address these problems, an IPsec-supporting host or security + gateway MUST have an administrative interface that allows the + user/administrator to configure the address of one or more security + gateways for ranges of destination addresses that require its use. + This includes the ability to configure information for locating and + authenticating one or more security gateways and verifying the + + +Kent & Seo [Page 47] + +Internet Draft Security Architecture for IP March 2005 + + + authorization of these gateways to represent the destination host. + (The authorization function is implied in the PAD.) This document + does not address the issue of how to automate the + discovery/verification of security gateways. + +4.6 SAs and Multicast + + The receiver-orientation of the SA implies that, in the case of + unicast traffic, the destination system will select the SPI value. + By having the destination select the SPI value, there is no potential + for manually configured SAs to conflict with automatically configured + (e.g., via a key management protocol) SAs or for SAs from multiple + sources to conflict with each other. For multicast traffic, there + are multiple destination systems associated with a single SA. So + some system or person will need to coordinate among all multicast + groups to select an SPI or SPIs on behalf of each multicast group and + then communicate the group's IPsec information to all of the + legitimate members of that multicast group via mechanisms not defined + here. + + Multiple senders to a multicast group SHOULD use a single Security + Association (and hence SPI) for all traffic to that group when a + symmetric key encryption or integrity algorithm is employed. In such + circumstances, the receiver knows only that the message came from a + system possessing the key for that multicast group. In such + circumstances, a receiver generally will not be able to authenticate + which system sent the multicast traffic. Specifications for other, + more general multicast approaches are deferred to the IETF Multicast + Security Working Group. + +5. IP Traffic Processing + + As mentioned in Section 4.4.1 "The Security Policy Database (SPD)", + the SPD (or associated caches) MUST be consulted during the + processing of all traffic that crosses the IPsec protection boundary, + including IPsec management traffic. If no policy is found in the SPD + that matches a packet (for either inbound or outbound traffic), the + packet MUST be discarded. To simplify processing, and to allow for + very fast SA lookups (for SG/BITS/BITW), this document introduces the + notion of an SPD cache for all outbound traffic (SPD-O plus SPD-S), + and a cache for inbound, non-IPsec-protected traffic (SPD-I). (As + mentioned earlier, the SAD acts as a cache for checking the selectors + of inbound IPsec-protected traffic arriving on SAs.) There is + nominally one cache per SPD. For the purposes of this specification, + it is assumed that each cached entry will map to exactly one SA. + Note, however, exceptions arise when one uses multiple SAs to carry + traffic of different priorities (e.g., as indicated by distinct DSCP + values) but the same selectors. Note also, that there are a couple + of situations in which the SAD can have entries for SAs that do not + + +Kent & Seo [Page 48] + +Internet Draft Security Architecture for IP March 2005 + + + have corresponding entries in the SPD. Since 2401bis does not mandate + that the SAD be selectively cleared when the SPD is changed, SAD + entries can remain when the SPD entries that created them are changed + or deleted. Also, if a manually keyed SA is created, there could be + an SAD entry for this SA that does not correspond to any SPD entry. + + Since SPD entries may overlap, one cannot safely cache these entries + in general. Simple caching might result in a match against a cache + entry whereas an ordered search of the SPD would have resulted in a + match against a different entry. But, if the SPD entries are first + decorrelated, then the resulting entries can safely be cached. Each + cached entry will indicate that matching traffic should be bypassed + or discarded, appropriately. (Note: The original SPD entry might + result in multiple SAs, e.g., because of PFP.) Unless otherwise + noted, all references below to the "SPD" or "SPD cache" or "cache" + are to a decorrelated SPD (SPD-I, SPD-O, SPD-S) or the SPD cache + containing entries from the decorrelated SPD. + + Note: In a host IPsec implementation based on sockets, the SPD will + be consulted whenever a new socket is created, to determine what, if + any, IPsec processing will be applied to the traffic that will flow + on that socket. This provides an implicit caching mechanism and the + portions of the preceding discussion that address caching can be + ignored in such implementations. + + Note: It is assumed that one starts with a correlated SPD because + that is how users and administrators are accustomed to managing these + sorts of access control lists or firewall filter rules. Then the + decorrelation algorithm is applied to build a list of cache-able SPD + entries. The decorrelation is invisible at the management interface. + + For inbound IPsec traffic, the SAD entry selected by the SPI serves + as the cache for the selectors to be matched against arriving IPsec + packets, after AH or ESP processing has been performed. + +5.1 Outbound IP Traffic Processing (protected-to-unprotected) + + First consider the path for traffic entering the implementation via a + protected interface and exiting via an unprotected interface. + + + + + + + + + + + + +Kent & Seo [Page 49] + +Internet Draft Security Architecture for IP March 2005 + + + Unprotected Interface + ^ + | + (nested SAs) +----------+ + -------------------|Forwarding|<-----+ + | +----------+ | + | ^ | + | | BYPASS | + V +-----+ | + +-------+ | SPD | +--------+ + ...| SPD-I |.................|Cache|.....|PROCESS |...IPsec + | (*) | | (*) |---->|(AH/ESP)| boundary + +-------+ +-----+ +--------+ + | +-------+ / ^ + | |DISCARD| <--/ | + | +-------+ | + | | + | +-------------+ + |---------------->|SPD Selection| + +-------------+ + ^ + | +------+ + | -->| ICMP | + | / +------+ + |/ + | + | + Protected Interface + + + Figure 2. Processing Model for Outbound Traffic + (*) = The SPD caches are shown here. If there + is a cache miss, then the SPD is checked. + There is no requirement that an + implementation buffer the packet if + there is a cache miss. + + + IPsec MUST perform the following steps when processing outbound + packets: + + 1. When a packet arrives from the subscriber (protected) interface, + invoke the SPD selection function to obtain the SPD-ID needed to + choose the appropriate SPD. (If the implementation uses only one + SPD, this step is a no-op.) + + 2. Match the packet headers against the cache for the SPD specified + by the SPD-ID from step 1. Note that this cache contains entries + from SPD-O and SPD-S. + + +Kent & Seo [Page 50] + +Internet Draft Security Architecture for IP March 2005 + + + 3a. If there is a match, then process the packet as specified by the + matching cache entry, i.e., BYPASS, DISCARD, or PROTECT using AH + or ESP. If IPsec processing is applied, there is a link from the + SPD cache entry to the relevant SAD entry (specifying the mode, + cryptographic algorithms, keys, SPI, PMTU, etc.). IPsec + processing is as previously defined, for tunnel or transport modes + and for AH or ESP, as specified in their respective RFCs [Ken05b + and Ken05a]. Note that the SA PMTU value, plus the value of the + stateful fragment checking flag (and the DF bit in the IP header + of the outbound packet) determine whether the packet can (must) be + fragmented prior to or after IPsec processing, or if it must be + discarded and an ICMP PMTU message is sent. + + 3b. If no match is found in the cache, search the SPD (SPD-S and + SPD-O parts) specified by SPD-ID. If the SPD entry calls for + BYPASS or DISCARD, create one or more new outbound SPD cache + entries and if BYPASS, create one or more new inbound SPD cache + entries. (More than one cache entry may be created since a + decorrelated SPD entry may be linked to other such entries that + were created as a side effect of the decorrelation process.) If + the SPD entry calls for PROTECT, i.e., creation of an SA, the key + management mechanism (e.g., IKE v2) is invoked to create the SA. + If SA creation succeeds, a new outbound (SPD-S) cache entry is + created, along with outbound and inbound SAD entries, otherwise + the packet is discarded. (A packet that triggers an SPD lookup MAY + be discarded by the implementation, or it MAY be processed against + the newly created cache entry, if one is created.) Since SAs are + created in pairs, an SAD entry for the corresponding inbound SA + also is created, and it contains the selector values derived from + the SPD entry (and packet, if any PFP flags were "true") used to + create the inbound SA, for use in checking inbound traffic + delivered via the SA. + + 4. The packet is passed to the outbound forwarding function + (operating outside of the IPsec implementation), to select the + interface to which the packet will be directed. This function may + cause the packet to be passed back across the IPsec boundary, for + additional IPsec processing, e.g., in support of nested SAs. If + so, there MUST be an entry in SPD-I database that permits inbound + bypassing of the packet, otherwise the packet will be discarded. + If necessary, i.e., if there is more than one SPD-I, the traffic + being looped back MAY be tagged as coming from this internal + interface. This would allow the use of a different SPD-I for + "real" external traffic vs looped traffic, if needed. + + Note: With the exception of IPv4 and IPv6 transport mode, an SG, + BITS, or BITW implementation MAY fragment packets before applying + IPsec. (This applies only to IPv4. For IPv6 packets, only the + originator is allowed to fragment them.) The device SHOULD have a + + +Kent & Seo [Page 51] + +Internet Draft Security Architecture for IP March 2005 + + + configuration setting to disable this. The resulting fragments are + evaluated against the SPD in the normal manner. Thus, fragments not + containing port numbers (or ICMP message type and code, or Mobility + Header type) will only match rules having port (or ICMP message type + and code, or MH type) selectors of OPAQUE or ANY. (See section 7 for + more details.) + + + + Note: With regard to determining and enforcing the PMTU of an SA, the + IPsec system MUST follow the steps described in Section 8.2. + +5.1.1 Handling an Outbound Packet That Must Be Discarded + + If an IPsec system receives an outbound packet that it finds it must + discard, it SHOULD be capable of generating and sending an ICMP + message to indicate to the sender of the outbound packet that the + packet was discarded. The type and code of the ICMP message will + depend on the reason for discarding the packet, as specified below. + The reason SHOULD be recorded in the audit log. The audit log entry + for this event SHOULD include the reason, current date/time, and the + selector values from the packet. + + a. The selectors of the packet matched an SPD entry requiring the + packet to be discarded. + + IPv4 Type = 3 (destination unreachable) Code = 13 + (Communication Administratively Prohibited) + + IPv6 Type = 1 (destination unreachable) Code = 1 + (Communication with destination administratively + prohibited) + + b1. The IPsec system successfully reached the remote peer but was + unable to negotiate the SA required by the SPD entry matching the + packet, e.g., because the remote peer is administratively + prohibited from communicating with the initiator, or the + initiating peer was unable to authenticate itself to the remote + peer, or the remote peer was unable to authenticate itself to the + initiating peer, or SPD at remote peer did not have a suitable + entry, etc. + + IPv4 Type = 3 (destination unreachable) Code = 13 + (Communication Administratively Prohibited) + + IPv6 Type = 1 (destination unreachable) Code = 1 + (Communication with destination administratively + prohibited) + + + +Kent & Seo [Page 52] + +Internet Draft Security Architecture for IP March 2005 + + + b2. The IPsec system was unable to set up the SA required by the SPD + entry matching the packet because the IPsec peer at the other end + of the exchange could not be contacted. + + IPv4 Type = 3 (destination unreachable) Code = 1 (host + unreachable) + + IPv6 Type = 1 (destination unreachable) Code = 3 (address + unreachable) + + Note that an attacker behind a security gateway could send packets + with a spoofed source address, W.X.Y.Z, to an IPsec entity causing it + to send ICMP messages to W.X.Y.Z. This creates an opportunity for a + DoS attack among hosts behind a security gateway. To address this, a + security gateway SHOULD include a management control to allow an + administrator to configure an IPsec implementation to send or not + send the ICMP messages under these circumstances, and if this + facility is selected, to rate limit the transmission of such ICMP + responses. + +5.1.2 Header Construction for Tunnel Mode + + This section describes the handling of the inner and outer IP + headers, extension headers, and options for AH and ESP tunnels, with + regard to outbound traffic processing. This includes how to + construct the encapsulating (outer) IP header, how to process fields + in the inner IP header, and what other actions should be taken for + outbound, tunnel mode traffic. The general processing described here + is modeled after RFC 2003, "IP Encapsulation with IP" [Per96]: + + o The outer IP header Source Address and Destination Address + identify the "endpoints" of the tunnel (the encapsulator and + decapsulator). The inner IP header Source Address and Destination + Addresses identify the original sender and recipient of the + datagram, (from the perspective of this tunnel), respectively. + (See footnote 3 after the table in 5.1.2.1 for more details on the + encapsulating source IP address.) + + o The inner IP header is not changed except as noted below for TTL + (or Hop Limit) and the DS/ECN Fields. The inner IP header + otherwise remains unchanged during its delivery to the tunnel exit + point. + + o No change to IP options or extension headers in the inner header + occurs during delivery of the encapsulated datagram through the + tunnel. + + Note: IPsec tunnel mode is different from IP-in-IP tunneling (RFC + 2003) in several ways: + + +Kent & Seo [Page 53] + +Internet Draft Security Architecture for IP March 2005 + + + o IPsec offers certain controls to a security administrator to + manage covert channels (which would not normally be a concern for + tunneling) and to ensure that the receiver examines the right + portions of the received packet re: application of access + controls. An IPsec implementation MAY be configurable with regard + to how it processes the outer DS field for tunnel mode for + transmitted packets. For outbound traffic, one configuration + setting for the outer DS field will operate as described in the + following sections on IPv4 and IPv6 header processing for IPsec + tunnels. Another will allow the outer DS field to be mapped to a + fixed value, which MAY be configured on a per SA basis. (The value + might really be fixed for all traffic outbound from a device, but + per SA granularity allows that as well.) This configuration option + allows a local administrator to decide whether the covert channel + provided by copying these bits outweighs the benefits of copying. + + o IPsec describes how to handle ECN or DS and provides the ability + to control propagation of changes in these fields between + unprotected and protected domains. In general, propagation from a + protected to an unprotected domain is a covert channel and thus + controls are provided to manage the bandwidth of this channel. + Propagation of ECN values in the other direction are controlled so + that only legitimate ECN changes (indicating occurrence of + congestion between the tunnel endpoints) are propagated. By + default, DS propagation from an unprotected domain to a protected + domain is not permitted. However, if the sender and receiver do + not share the same DS code space, and the receiver has no way of + learning how to map between the two spaces, then it may be + appropriate to deviate from the default. Specifically, an IPsec + implementation MAY be configurable in terms of how it processes + the outer DS field for tunnel mode for received packets. It may be + configured to either discard the outer DS value (the default) OR + to overwrite the inner DS field with the outer DS field. If + offered, the discard vs. overwrite behavior MAY be configured on a + per SA basis. This configuration option allows a local + administrator to decide whether the vulnerabilities created by + copying these bits outweigh the benefits of copying. See [RFC + 2983] for further information on when each of these behaviors may + be useful, and also for the possible need for diffserv traffic + conditioning prior or subsequent to IPsec processing (including + tunnel decapsulation). + + o IPsec allows the IP version of the encapsulating header to be + different from that of the inner header. + + The tables in the following sub-sections show the handling for the + different header/option fields ("constructed" means that the value in + the outer field is constructed independently of the value in the + inner). + + +Kent & Seo [Page 54] + +Internet Draft Security Architecture for IP March 2005 + + +5.1.2.1 IPv4 -- Header Construction for Tunnel Mode + + <-- How Outer Hdr Relates to Inner Hdr --> + Outer Hdr at Inner Hdr at + IPv4 Encapsulator Decapsulator + Header fields: -------------------- ------------ + version 4 (1) no change + header length constructed no change + DS Field copied from inner hdr (5) no change + ECN Field copied from inner hdr constructed (6) + total length constructed no change + ID constructed no change + flags (DF,MF) constructed, DF (4) no change + fragment offset constructed no change + TTL constructed (2) decrement (2) + protocol AH, ESP no change + checksum constructed constructed (2)(6) + src address constructed (3) no change + dest address constructed (3) no change + Options never copied no change + 1. The IP version in the encapsulating header can be + different from the value in the inner header. + + 2. The TTL in the inner header is decremented by the + encapsulator prior to forwarding and by the decapsulator + if it forwards the packet. (The IPv4 checksum changes + when the TTL changes.) + + Note: Decrementing the TTL value is a normal part of + forwarding a packet. Thus, a packet originating from + the same node as the encapsulator does not have its TTL + decremented, since the sending node is originating the + packet rather than forwarding it. + + 3. Local and Remote addresses depend on the SA, which is + used to determine the Remote address which in turn + determines which Local address (net interface) is used + to forward the packet. + + Note: For multicast traffic, the destination address, or + source and destination addresses, may be required for + demuxing. In that case, it is important to ensure + consistency over the lifetime of the SA by ensuring that + the source address that appears in the encapsulating + tunnel header is the same as the one that was negotiated + during the SA establishment process. There is an + exception to this general rule, i.e., a mobile IPsec + implementation will update its source address as it + moves. + + +Kent & Seo [Page 55] + +Internet Draft Security Architecture for IP March 2005 + + + 4. Configuration determines whether to copy from the inner + header (IPv4 only), clear, or set the DF. + + 5. If the packet will immediately enter a domain for which + the DSCP value in the outer header is not appropriate, + that value MUST be mapped to an appropriate value for + the domain [RFC 2474]. See RFC 2475[BBCDWW98] for + further information. + + 6. If the ECN field in the inner header is set to ECT(0) or + ECT(1) and the ECN field in the outer header is set to + CE, then set the ECN field in the inner header to CE, + otherwise make no change to the ECN field in the inner + header. (The IPv4 checksum changes when the ECN + changes.) + + Note: IPsec does not copy the options from the inner header into the + outer header, nor does IPsec construct the options in the outer + header. However, post-IPsec code MAY insert/construct options for the + outer header. + +5.1.2.2 IPv6 -- Header Construction for Tunnel Mode + + See previous section 5.1.2.1 for notes 1-6 indicated by (footnote + number). + + <-- How Outer Hdr Relates Inner Hdr ---> + Outer Hdr at Inner Hdr at + IPv6 Encapsulator Decapsulator + Header fields: -------------------- ------------ + version 6 (1) no change + DS Field copied from inner hdr (5) no change (9) + ECN Field copied from inner hdr constructed (6) + flow label copied or configured (8) no change + payload length constructed no change + next header AH,ESP,routing hdr no change + hop limit constructed (2) decrement (2) + src address constructed (3) no change + dest address constructed (3) no change + Extension headers never copied (7) no change + + 7. IPsec does not copy the extension headers from the inner + packet into outer headers, nor does IPsec construct + extension headers in the outer header. However, + post-IPsec code MAY insert/construct extension headers + for the outer header. + + 8. See [RaCoCaDe04]. Copying is acceptable only for end + systems, not SGs. If an SG copied flow labels from the + + +Kent & Seo [Page 56] + +Internet Draft Security Architecture for IP March 2005 + + + inner header to the outer header, collisions might + result. + + 9. An implementation MAY choose to provide a facility to + pass the DS value from the outer header to the inner + header, on a per SA basis, for received tunnel mode + packets. The motivation for providing this feature is to + accommodate situations in which the DS code space at the + receiver is different from that of the sender and the + receiver has no way of knowing how to translate from the + sender's space. There is a danger in copying this value + from the outer header to the inner header, since it + enables an attacker to modify the outer DSCP value in a + fashion that may adversely affect other traffic at the + receiver. Hence the default behavior for IPsec + implementations is NOT to permit such copying. + +5.2 Processing Inbound IP Traffic (unprotected-to-protected) + + Inbound processing is somewhat different from outbound processing, + because of the use of SPIs to map IPsec protected traffic to SAs. The + inbound SPD cache (SPD-I) is applied only to bypassed or discarded + traffic. If an arriving packet appears to be an IPsec fragment from + an unprotected interface, reassembly is performed prior to IPsec + processing. The intent for any SPD cache is that a packet that fails + to match any entry is then referred to the corresponding SPD. Every + SPD SHOULD have a nominal, final entry that catches anything that is + otherwise unmatched, and discards it. This ensures that non-IPsec + protected traffic that arrives and does not match any SPD-I entry + will be discarded. + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 57] + +Internet Draft Security Architecture for IP March 2005 + + + + Unprotected Interface + | + V + +-----+ IPsec protected + ------------------->|Demux|-------------------+ + | +-----+ | + | | | + | Not IPsec | | + | | | + | V | + | +-------+ +---------+ | + | |DISCARD|<---|SPD-I (*)| | + | +-------+ +---------+ | + | | | + | |-----+ | + | | | | + | | V | + | | +------+ | + | | | ICMP | | + | | +------+ | + | | V + +---------+ | +---------+ + ....|SPD-O (*)|............|...................|PROCESS**|...IPsec + +---------+ | |(AH/ESP) | Boundary + ^ | +---------+ + | | +---+ | + | BYPASS | +-->|IKE| | + | | | +---+ | + | V | V + | +----------+ +---------+ +----+ + |--------<------|Forwarding|<---------|SAD Check|-->|ICMP| + nested SAs +----------+ | (***) | +----+ + | +---------+ + V + Protected Interface + + Figure 3. Inbound Traffic Processing Model + (*) = The caches are shown here. If there is + a cache miss, then the SPD is checked. + There is no requirement that an + implementation buffer the packet if + there is a cache miss. + (**) = This processing includes using the + packet's SPI, etc to look up the SA + in the SAD, which forms a cache of the + SPD for inbound packets (except for + cases noted in Sections 4.4.2 and 5) - + see step 3a below. + + +Kent & Seo [Page 58] + +Internet Draft Security Architecture for IP March 2005 + + + (***) = This SAD check refers to step 4 below. + + + Prior to performing AH or ESP processing, any IP fragments that + arrive via the unprotected interface are reassembled (by IP). Each + inbound IP datagram to which IPsec processing will be applied is + identified by the appearance of the AH or ESP values in the IP Next + Protocol field (or of AH or ESP as a next layer protocol in the IPv6 + context). + + IPsec MUST perform the following steps: + + 1. When a packet arrives, it may be tagged with the ID of the + interface (physical or virtual) via which it arrived, if necessary + to support multiple SPDs and associated SPD-I caches. (The + interface ID is mapped to a corresponding SPD-ID.) + + 2. The packet is examined and demuxed into one of two categories: + - If the packet appears to be IPsec protected and it is addressed + to this device, an attempt is made to map it to an active SA + via the SAD. Note that the device may have multiple IP + addresses that may be used in the SAD lookup, e.g., in the case + of protocols such as SCTP. + - Traffic not addressed to this device, or addressed to this + device and not AH or ESP, is directed to SPD-I lookup. (This + implies that IKE traffic MUST have an explicit BYPASS entry in + the SPD.) If multiple SPDs are employed, the tag assigned to + the packet in step 1 is used to select the appropriate SPD-I + (and cache) to search. SPD-I lookup determines whether the + action is DISCARD or BYPASS. + + 3a. If the packet is addressed to the IPsec device and AH or ESP is + specified as the protocol, the packet is looked up in the SAD. For + unicast traffic, use only the SPI (or SPI plus protocol). For + multicast traffic, use the SPI plus the destination or SPI plus + destination and source addresses, as specified in section 4.1. In + either case (unicast or multicast), if there is no match, discard + the traffic. This is an auditable event. The audit log entry for + this event SHOULD include the current date/time, SPI, source and + destination of the packet, IPsec protocol, and any other selector + values of the packet that are available. If the packet is found + in the SAD, process it accordingly (see step 4). + + 3b. If the packet is not addressed to the device or is addressed to + this device and is not AH or ESP, look up the packet header in the + (appropriate) SPD-I cache. If there is a match and the packet is + to be discarded or bypassed, do so. If there is no cache match, + look up the packet in the corresponding SPD-I and create a cache + entry as appropriate. (No SAs are created in response to receipt + + +Kent & Seo [Page 59] + +Internet Draft Security Architecture for IP March 2005 + + + of a packet that requires IPsec protection; only BYPASS or DISCARD + cache entries can be created this way.) If there is no match, + discard the traffic. This is an auditable event. The audit log + entry for this event SHOULD include the current date/time, SPI if + available, IPsec protocol if available, source and destination of + the packet, and any other selector values of the packet that are + available. + + 3c. Processing of ICMP messages is assumed to take place on the + unprotected side of the IPsec boundary. Unprotected ICMP messages + are examined and local policy is applied to determine whether to + accept or reject these messages and, if accepted, what action to + take as a result. For example, if an ICMP unreachable message is + received, the implementation must decide whether to act on it, + reject it, or act on it with constraints. (See Section 6.) + + 4. Apply AH or ESP processing as specified, using the SAD entry + selected in step 3a above. Then match the packet against the + inbound selectors identified by the SAD entry to verify that the + received packet is appropriate for the SA via which it was + received. + + 5. If an IPsec system receives an inbound packet on an SA and the + packet's header fields are not consistent with the selectors for + the SA, it MUST discard the packet. This is an auditable event. + The audit log entry for this event SHOULD include the current + date/time, SPI, IPsec protocol(s), source and destination of the + packet, and any other selector values of the packet that are + available, and the selector values from the relevant SAD entry. + The system SHOULD also be capable of generating and sending an IKE + notification of INVALID_SELECTORS to the sender (IPsec peer), + indicating that the received packet was discarded because of + failure to pass selector checks. + + To minimize the impact of a DoS attack, or a mis-configured peer, the + IPsec system SHOULD include a management control to allow an + administrator to configure the IPsec implementation to send or not + send this IKE notification, and if this facility is selected, to rate + limit the transmission of such notifications. + + After traffic is bypassed or processed through IPsec, it is handed to + the inbound forwarding function for disposition. This function may + cause the packet to be sent (outbound) across the IPsec boundary for + additional inbound IPsec processing, e.g., in support of nested SAs. + If so, then as with ALL outbound traffic that is to be bypassed, the + packet MUST be matched against an SPD-O entry. Ultimately, the packet + should be forwarded to the destination host or process for + disposition. + + + +Kent & Seo [Page 60] + +Internet Draft Security Architecture for IP March 2005 + + +6. ICMP Processing + + This section describes IPsec handling of ICMP traffic. There are two + categories of ICMP traffic: error messages (e.g., type = destination + unreachable) and non-error messages (e.g., type = echo). This section + applies exclusively to error messages. Disposition of non-error, + ICMP messages (that are not addressed to the IPsec implementation + itself) MUST be explicitly accounted for using SPD entries. + + The discussion in this section applies to ICMPv6 as well as to + ICMPv4. Also, a mechanism SHOULD be provided to allow an + administrator to cause ICMP error messages (selected, all, or none) + to be logged as an aid to problem diagnosis. + +6.1 Processing ICMP Error Messages Directed to an IPsec Implementation + +6.1.1 ICMP Error Messages Received on the Unprotected Side of the +Boundary + + Figure 3 in Section 5.2 shows a distinct ICMP processing module on + the unprotected side of the IPsec boundary, for processing ICMP + messages (error or otherwise) that are addressed to the IPsec device + and that are not protected via AH or ESP. An ICMP message of this + sort is unauthenticated and its processing may result in denial or + degradation of service. This suggests that, in general, it would be + desirable to ignore such messages. However, many ICMP messages will + be received by hosts or security gateways from unauthenticated + sources, e.g., routers in the public Internet. Ignoring these ICMP + messages can degrade service, e.g., because of a failure to process + PMTU message and redirection messages. Thus there is also a + motivation for accepting and acting upon unauthenticated ICMP + messages. + + To accommodate both ends of this spectrum, a compliant IPsec + implementation MUST permit a local administrator to configure an + IPsec implementation to accept or reject unauthenticated ICMP + traffic. This control MUST be at the granularity of ICMP type and + MAY be at the granularity of ICMP type and code. Additionally, an + implementation SHOULD incorporate mechanisms and parameters for + dealing with such traffic. For example, there could be the ability to + establish a minimum PMTU for traffic (on a per destination basis), to + prevent receipt of an unauthenticated ICMP from setting the PMTU to a + trivial size. + + If an ICMP PMTU message passes the checks above and the system is + configured to accept it, then there are two possibilities. If the + implementation applies fragmentation on the ciphertext side of the + boundary, then the accepted PMTU information is passed to the + forwarding module (outside of the IPsec implementation) which uses it + + +Kent & Seo [Page 61] + +Internet Draft Security Architecture for IP March 2005 + + + to manage outbound packet fragmentation. If the implementation is + configured to effect plaintext side fragmentation, then the PMTU + information is passed to the plaintext side and processed as + described in Section 8.2. + +6.1.2 ICMP Error Messages Received on the Protected Side of the Boundary + + These ICMP messages are not authenticated, but they do come from + sources on the protected side of the IPsec boundary. Thus these + messages generally are viewed as more "trustworthy" than their + counterparts arriving from sources on the unprotected side of the + boundary. The major security concern here is that a compromised host + or router might emit erroneous ICMP error messages that could degrade + service for other devices "behind" the security gateway, or that + could even result in violations of confidentiality. For example, if a + bogus ICMP redirect were consumed by a security gateway, it could + cause the forwarding table on the protected side of the boundary to + be modified so as to deliver traffic to an inappropriate destination + "behind" the gateway. Thus implementers MUST provide controls to + allow local administrators to constrain the processing of ICMP error + messages received on the protected side of the boundary, and directed + to the IPsec implementation. These controls are of the same type as + those employed on the unprotected side, described above in Section + 6.1.1. + +6.2 Processing Protected, Transit ICMP Error Messages + + When an ICMP error message is transmitted via an SA to a device + "behind" an IPsec implementation, both the payload and the header of + the ICMP message require checking from an access control perspective. + If one of these messages is forwarded to a host behind a security + gateway, the receiving host IP implementation will make decisions + based on the payload, i.e., the header of the packet that purportedly + triggered the error response. Thus an IPsec implementation MUST be + configurable to check that this payload header information is + consistent with the SA via which it arrives. (This means that the + payload header, with source and destination address and port fields + reversed, matches the traffic selectors for the SA.) If this sort of + check is not performed, then for example, anyone with whom the + receiving IPsec system (A) has an active SA could send an ICMP + destination dead message that refers to any host/net with which A is + currently communicating, and thus effect a highly efficient DoS + attack re: communication with other peers of A. Normal IPsec + receiver processing of traffic is not sufficient to protect against + such attacks. However, not all contexts may require such checks, so + it is also necessary to allow a local administrator to configure an + implementation to NOT perform such checks. + + To accommodate both policies, the following convention is adopted. If + + +Kent & Seo [Page 62] + +Internet Draft Security Architecture for IP March 2005 + + + an administrator wants to allow ICMP error messages to be carried by + an SA without inspection of the payload, then configure an SPD entry + that explicitly allows for carriage of such traffic. If an + administrator wants IPsec to check the payload of ICMP error messages + for consistency, then do not create any SPD entries that accommodate + carriage of such traffic based on the ICMP packet header. This + convention motivates the following processing description. + + IPsec senders and receivers MUST support the following processing for + ICMP error messages that are sent and received via SAs. + + If an SA exists that accommodates an outbound ICMP error message, + then the message is mapped to the SA and only the IP and ICMP headers + are checked upon receipt, just as would be the case for other + traffic. If no SA exists that matches the traffic selectors + associated with an ICMP error message, then the SPD is searched to + determine if such an SA can be created. If so, the SA is created and + the ICMP error message is transmitted via that SA. Upon receipt, this + message is subject to the usual traffic selector checks at the + receiver. This processing is exactly what would happen for traffic in + general, and thus does not represent any special processing for ICMP + error messages. + + If no SA exists that would carry the outbound ICMP message in + question, and if no SPD entry would allow carriage of this outbound + ICMP error message, then an IPsec implementation MUST map the message + to the SA that would carry the return traffic associated with the + packet that triggered the ICMP error message. This requires an IPsec + implementation to detect outbound ICMP error messages that map to no + extant SA or SPD entry, and treat them specially with regard to SA + creation and lookup. The implementation extracts the header for the + packet that triggered the error (from the ICMP message payload), + reverses the source and destination IP address fields, extracts the + protocol field, and reverses the port fields (if accessible). It then + uses this extracted information to locate an appropriate, active + outbound SA, and transmits the error message via this SA. If no such + SA exists, no SA will be created, and this is an auditable event. + + If an IPsec implementation receives an inbound ICMP error message on + an SA, and the IP and ICMP headers of the message do not match the + traffic selectors for the SA, the receiver MUST process the received + message in a special fashion. Specifically, the receiver must extract + the header of the triggering packet from the ICMP payload, and + reverse fields as described above to determine if the packet is + consistent with the selectors for the SA via which the ICMP error + message was received. If the packet fails this check, the IPsec + implementation MUST NOT forwarded the ICMP message to the + destination. This is an auditable event. + + + +Kent & Seo [Page 63] + +Internet Draft Security Architecture for IP March 2005 + + +7. Handling Fragments (on the protected side of the IPsec boundary) + + Earlier sections of this document describe mechanisms for (a) + fragmenting an outbound packet after IPsec processing has been + applied and reassembling it at the receiver before IPsec processing + and (b) handling inbound fragments received from the unprotected side + of the IPsec boundary. This section describes how an implementation + should handle the processing of outbound plaintext fragments on the + protected side of the IPsec boundary. (See Appendix D for discussion + of Fragment Handling Rationale.) In particular, it addresses: + + o mapping an outbound non-initial fragment to the right SA + (or finding the right SPD entry) + o verifying that a received non-initial fragment is + authorized for the SA via which it was received + o mapping outbound and inbound non-initial fragments to the + right SPD-O/SPD-I entry or the relevant cache entry, for + BYPASS/DISCARD traffic + + Note: In Section 4.1, transport mode SAs have been defined to not + carry fragments (IPv4 or IPv6). Note also that in Section 4.4.1, two + special values, ANY and OPAQUE, were defined for selectors and that + ANY includes OPAQUE. The term "non-trivial" is used to mean that the + selector has a value other than OPAQUE or ANY. + + Note: The term "non-initial fragment" is used here to indicate a + fragment that does not contain all the selector values that may be + needed for access control. As observed in Section 4.4.1, depending + on the Next Layer Protocol, in addition to Ports, the ICMP message + type/code or Mobility Header type could be missing from non-initial + fragments. Also, for IPv6, even the first fragment might NOT contain + the Next Layer Protocol or Ports (or ICMP message type/code, or + Mobility Header type) depending on the kind and number of extension + headers present. If a non-initial fragment contains the Port (or + ICMP type and code or Mobility header type) but not the Next Layer + Protocol, then unless there is an SPD entry for the relevant + Local/Remote addresses with ANY for Next Layer Protocol and Port (or + ICMP type and code or Mobility header type), the fragment would not + contain all the selector information needed for access control. + + To address the above issues, three approaches have been defined: + + o Tunnel mode SAs that carry initial and non-initial fragments + (See Section 7.1) + o Separate tunnel mode SAs for non-initial fragments (See + Section 7.2) + o Stateful fragment checking (See Section 7.3) + + + + +Kent & Seo [Page 64] + +Internet Draft Security Architecture for IP March 2005 + + +7.1 Tunnel Mode SAs that Carry Initial and Non-Initial Fragments + + All implementations MUST support tunnel mode SAs that are configured + to pass traffic without regard to port field (or ICMP type/code or + Mobility Header type) values. If the SA will carry traffic for + specified protocols, the selector set for the SA MUST specify the + port fields (or ICMP type/code or Mobility Header type) as ANY. An SA + defined in this fashion will carry all traffic including initial and + non-initial fragments for the indicated Local/Remote addresses and + specified Next Layer protocol(s). If the SA will carry traffic + without regard to a specific protocol value (i.e., ANY is specified + as the (Next Layer) protocol selector value), then the port field + values are undefined and MUST be set to ANY as well. (As noted in + 4.4.1, ANY includes OPAQUE as well as all specific values.) + +7.2 Separate Tunnel Mode SAs for Non-Initial Fragments + + An implementation MAY support tunnel mode SAs that will carry only + non-initial fragments, separate from non-fragmented packets and + initial fragments. The OPAQUE value will be used to specify port (or + ICMP type/code or Mobility Header type) field selectors for an SA to + carry such fragments. Receivers MUST perform a minimum offset check + on IPv4 (non-initial) fragments to protect against overlapping + fragment attacks when SAs of this type are employed. Because such + checks cannot be performed on IPv6 non-initial fragments, users and + administrators are advised that carriage of such fragments may be + dangerous, and implementers may choose to NOT support such SAs for + IPv6 traffic. Also, an SA of this sort will carry all non-initial + fragments that match a specified Local/Remote address pair and + protocol value, i.e., the fragments carried on this SA belong to + packets that if not fragmented, might have gone on separate SAs of + differing security. Therefore users and administrators are advised + to protect such traffic using ESP (with integrity) and the + "strongest" integrity and encryption algorithms in use between both + peers. (Determination of the "strongest" algorithms requires + imposing an ordering of the available algorithms, a local + determination at the discretion of the initiator of the SA.) + + Specific port (or ICMP type/code or Mobility header type) selector + values will be used to define SAs to carry initial fragments and + non-fragmented packets. This approach can be used if a user or + administrator wants to create one or more tunnel mode SAs between the + same Local/Remote addresses that discriminate based on port (or ICMP + type/code or Mobility header type) fields. These SAs MUST have + non-trivial protocol selector values, otherwise approach #1 above + MUST be used. + + Note: In general, for the approach described in this section, one + needs only a single SA between two implementations to carry all + + +Kent & Seo [Page 65] + +Internet Draft Security Architecture for IP March 2005 + + + non-initial fragments. However, if one chooses to have multiple SAs + between the two implementations for QoS differentiation, then one + might also want multiple SAs to carry fragments-without-ports, one + for each supported QoS class. Since support for QoS via distinct SAs + is a local matter, not mandated by this document, the choice to have + multiple SAs to carry non-initial fragments should also be local. + +7.3 Stateful Fragment Checking + + An implementation MAY support some form of stateful fragment checking + for a tunnel mode SA with non-trivial port (or ICMP type/code or MH + type) field values (not ANY or OPAQUE). Implementations that will + transmit non-initial fragments on a tunnel mode SA that makes use of + non-trivial port (or ICMP type/code or MH type) selectors MUST notify + a peer via the IKE NOTIFY NON_FIRST_FRAGMENTS_ALSO payload. + + The peer MUST reject this proposal if it will not accept non-initial + fragments in this context. If an implementation does not successfully + negotiate transmission of non-initial fragments for such an SA, it + MUST NOT send such fragments over the SA. This standard does not + specify how peers will deal with such fragments, e.g., via reassembly + or other means, at either sender or receiver. However, a receiver + MUST discard non-initial fragments that arrive on an SA with + non-trivial port (or ICMP type/code or MH type) selector values + unless this feature has been negotiated. Also, the receiver MUST + discard non-initial fragments that do not comply with the security + policy applied to the overall packet. Discarding such packets is an + auditable event. Note that in network configurations where fragments + of a packet might be sent or received via different security gateways + or BITW implementations, stateful strategies for tracking fragments + may fail. + +7.4 BYPASS/DISCARD traffic + + All implementations MUST support DISCARDing of fragments using the + normal SPD packet classification mechanisms. All implementations MUST + support stateful fragment checking to accommodate BYPASS traffic for + which a non-trivial port range is specified. The concern is that + BYPASS of a cleartext, non-initial fragment arriving at an IPsec + implementation could undermine the security afforded IPsec-protected + traffic directed to the same destination. For example, consider an + IPsec implementation configured with an SPD entry that calls for + IPsec-protection of traffic between a specific source/destination + address pair, and for a specific protocol and destination port, e.g., + TCP traffic on port 23 (Telnet). Assume that the implementation also + allows BYPASS of traffic from the same source/destination address + pair and protocol, but for a different destination port, e.g., port + 119 (NNTP). An attacker could send a non-initial fragment (with a + forged source address) that, if bypassed, could overlap with + + +Kent & Seo [Page 66] + +Internet Draft Security Architecture for IP March 2005 + + + IPsec-protected traffic from the same source and thus violate the + integrity of the IPsec-protected traffic. Requiring stateful fragment + checking for BYPASS entries with non-trivial port ranges prevents + attacks of this sort. As noted above, in network configurations where + fragments of a packet might be sent or received via different + security gateways or BITW implementations, stateful strategies for + tracking fragments may fail. + +8. Path MTU/DF Processing + + The application of AH or ESP to an outbound packet increases the size + of a packet and thus may cause a packet to exceed the PMTU for the SA + via which the packet will travel. An IPsec implementation also may + receive an unprotected ICMP PMTU message and, if it choose to act + upon it, the result will affect outbound traffic processing. This + section describes the processing required of an IPsec implementation + to deal with these two PMTU issues. + +8.1 DF Bit + + All IPsec implementations MUST support the option of copying the DF + bit from an outbound packet to the tunnel mode header that it emits, + when traffic is carried via a tunnel mode SA. This means that it MUST + be possible to configure the implementation's treatment of the DF bit + (set, clear, copy from inner header) for each SA. This applies to SAs + where both inner and outer headers are IPv4. + +8.2 Path MTU Discovery (PMTU) + + This section discusses IPsec handling for unprotected Path MTU + Discovery messages. ICMP PMTU is used here to refer to an ICMP + message for: + + IPv4 (RFC 792 [Pos81b]): + - Type = 3 (Destination Unreachable) + - Code = 4 (Fragmentation needed and DF set) + - Next--Hop MTU in the low-order 16 bits of the + second word of the ICMP header (labeled "unused" + in RFC 792), with high-order 16 bits set to zero) + + IPv6 (RFC 2463 [CD98]): + - Type = 2 (Packet Too Big) + - Code = 0 (Fragmentation needed) + - Next-Hop MTU in the 32 bit MTU field of the ICMP6 + message + + + + + + +Kent & Seo [Page 67] + +Internet Draft Security Architecture for IP March 2005 + + +8.2.1 Propagation of PMTU + + When an IPsec implementation receives an unauthenticated PMTU + message, and it is configured to process (vs. ignore) such messages, + it maps the message to the SA to which it corresponds. This mapping + is effected by extracting the header information from the payload of + the PMTU message and applying the procedure described in Section 5.2. + The PMTU determined by this message is used to update the SAD PMTU + field, taking into account the size of the AH or ESP header that will + be applied, any crypto synchronization data, and the overhead imposed + by an additional IP header, in the case of a tunnel mode SA. + + In a native host implementation, it is possible to maintain PMTU data + at the same granularity as for unprotected communication, so there is + no loss of functionality. Signaling of the PMTU information is + internal to the host. For all other IPsec implementation options, the + PMTU data must be propagated via a synthesized ICMP PMTU. In these + cases, the IPsec implementation SHOULD wait for outbound traffic to + be mapped to the SAD entry. When such traffic arrives, if the traffic + would exceed the updated PMTU value the traffic MUST be handled as + follows: + + Case 1: Original (cleartext) packet is IPv4 and has the DF + bit set. The implementation SHOULD discard the packet + and send a PMTU ICMP message. + + Case 2: Original (cleartext) packet is IPv4 and has the DF + bit clear. The implementation SHOULD fragment (before or + after encryption per its configuration) and then forward + the fragments. It SHOULD NOT send a PMTU ICMP message. + + Case 3: Original (cleartext) packet is IPv6. The implementation + SHOULD discard the packet and send a PMTU ICMP message. + +8.2.2 PMTU Aging + + In all IPsec implementations the PMTU associated with an SA MUST be + "aged" and some mechanism is required to update the PMTU in a timely + manner, especially for discovering if the PMTU is smaller than + required by current network conditions. A given PMTU has to remain + in place long enough for a packet to get from the source of the SA to + the peer, and to propagate an ICMP error message if the current PMTU + is too big. + + Implementations SHOULD use the approach described in the Path MTU + Discovery document (RFC 1191 [MD90], Section 6.3), which suggests + periodically resetting the PMTU to the first-hop data-link MTU and + then letting the normal PMTU Discovery processes update the PMTU as + necessary. The period SHOULD be configurable. + + +Kent & Seo [Page 68] + +Internet Draft Security Architecture for IP March 2005 + + +9. Auditing + + IPsec implementations are not required to support auditing. For the + most part, the granularity of auditing is a local matter. However, + several auditable events are identified in this document and for each + of these events a minimum set of information that SHOULD be included + in an audit log is defined. Additional information also MAY be + included in the audit log for each of these events, and additional + events, not explicitly called out in this specification, also MAY + result in audit log entries. There is no requirement for the + receiver to transmit any message to the purported transmitter in + response to the detection of an auditable event, because of the + potential to induce denial of service via such action. + +10. Conformance Requirements + + All IPv4 IPsec implementations MUST comply with all requirements of + this document. All IPv6 implementations MUST comply with all + requirements of this document. + +11. Security Considerations + + The focus of this document is security; hence security considerations + permeate this specification. + + IPsec imposes stringent constraints on bypass of IP header data in + both directions, across the IPsec barrier, especially when tunnel + mode SAs are employed. Some constraints are absolute, while others + are subject to local administrative controls, often on a per-SA + basis. For outbound traffic, these constraints are designed to limit + covert channel bandwidth. For inbound traffic, the constraints are + designed to prevent an adversary who has the ability to tamper with + one data stream (on the unprotected side of the IPsec barrier) from + adversely affecting other data streams (on the protected side of the + barrier). The discussion in Section 5 dealing with processing DSCP + values for tunnel mode SAs illustrates this concern. + + If an IPsec implementation is configured to pass ICMP error messages + over SAs based on the ICMP header values, without checking the header + information from the ICMP message payload, serious vulnerabilities + may arise. Consider a scenario in which several sites (A, B, and C) + are connected to one another via ESP-protected tunnels: A-B, A-C, and + B-C. Also assume that the traffic selectors for each tunnel specify + ANY for protocol and port fields and IP source/destination address + ranges that encompass the address range for the systems behind the + security gateways serving each site. This would allow a host at site + B to send an ICMP destination dead message to any host at site A, + that declares all hosts on the net at site C to be unreachable. This + is a very efficient DoS attack that could have been prevented if the + + +Kent & Seo [Page 69] + +Internet Draft Security Architecture for IP March 2005 + + + ICMP error messages were subjected to the checks that IPsec provides, + if the SPD is suitably configured, as described in Section 6.2. + +12. IANA Considerations + + Upon approval of this draft for publication as an RFC, this document + requests that IANA fill in the number (xx) for the asn1-modules + registry and assign the object identifier (yy) for the spd-module in + Appendix C "ASN.1 for an SPD Entry". + +13. Differences from RFC 2401 + + This architecture document differs substantially from RFC 2401 in + detail and in organization, but the fundamental notions are + unchanged. + + o The processing model has been revised to address new IPsec + scenarios, improve performance and simplify implementation. This + includes a separation between forwarding (routing) and SPD + selection, several SPD changes, and the addition of an outbound + SPD cache and an inbound SPD cache for bypassed or discarded + traffic. There is also a new database, the Peer Authorization + Database (PAD). This provides a link between an SA management + protocol like IKE and the SPD. + + o There is no longer a requirement to support nested SAs or "SA + bundles." Instead this functionality can be achieved through SPD + and forwarding table configuration. An example of a configuration + has been added in Appendix E. + + o SPD entries were redefined to provide more flexibility. Each SPD + entry now consists of 1 to N sets of selectors, where each + selector set contains one protocol and a "list of ranges" can now + be specified for the Local IP address, Remote IP address, and + whatever fields (if any) are associated with the Next Layer + Protocol (Local Port, Remote Port, ICMP message type and code, and + Mobility Header Type). An individual value for a selector is + represented via a trivial range and ANY is represented via a range + than spans all values for the selector. An example of an ASN.1 + description is included in Appendix C. + + o TOS (IPv4) and Traffic Class (IPv6) have been replaced by DSCP and + ECN. The tunnel section has been updated to explain how to handle + DSCP and ECN bits. + + o For tunnel mode SAs, an SG, BITS, or BITW implementation is now + allowed to fragment packets before applying IPsec. This applies + only to IPv4. For IPv6 packets, only the originator is allowed to + fragment them. + + +Kent & Seo [Page 70] + +Internet Draft Security Architecture for IP March 2005 + + + o When security is desired between two intermediate systems along a + path or between an intermediate system and an end system, + transport mode may now be used between security gateways and + between a security gateway and a host. + + o This document clarifies that for all traffic that crosses the IPsec + boundary, including IPsec management traffic, the SPD or + associated caches must be consulted. + + o This document defines how to handle the situation of a security + gateway with multiple subscribers requiring separate IPsec + contexts. + + o A definition of reserved SPIs has been added. + + o Text has been added explaining why ALL IP packets must be checked + -- IPsec includes minimal firewall functionality to support access + control at the IP layer. + + o The tunnel section has been updated to clarify how to handle the IP + options field and IPv6 extension headers when constructing the + outer header. + + o SA mapping for inbound traffic has been updated to be consistent + with the changes made in AH and ESP for support of unicast and + multicast SAs. + + o Guidance has been added re: how to handle the covert channel + created in tunnel mode by copying the DSCP value to outer header. + + o Support for AH in both IPv4 and IPv6 is no longer required. + + o PMTU handling has been updated. The appendix on + PMTU/DF/Fragmentation has been deleted. + + + o Three approaches have been added for handling plaintext fragments + on the protected side of the IPsec boundary. Appendix D documents + the rationale behind them. + + o Added revised text describing how to derive selector values for SAs + (from the SPD entry or from the packet, etc.) + + o Added a new table describing the relationship between selector + values in an SPD entry, the PFP flag, and resulting selector + values in the corresponding SAD entry. + + o Added Appendix B to describe decorrelation. + + + +Kent & Seo [Page 71] + +Internet Draft Security Architecture for IP March 2005 + + + o Added text describing how to handle an outbound packet which must + be discarded. + + o Added text describing how to handle a DISCARDED inbound packet, + i.e., one that does not match the SA upon which it arrived. + + o IPv6 mobility header has been added as a possible Next Layer + Protocol. IPv6 mobility header message type has been added as a + selector. + + o ICMP message type and code have been added as selectors. + + o The selector "data sensitivity level" has been removed to simplify + things. + + o Updated text describing handling ICMP error messages. The appendix + on "Categorization of ICMP messages" has been deleted. + + o The text for the selector name has been updated and clarified. + + o The "Next Layer Protocol" has been further explained and a default + list of protocols to skip when looking for the Next Layer Protocol + has been added. + + o The text has been amended to say that this document assumes use of + IKE v2 or an SA management protocol with comparable features. + + o Text has been added clarifying the algorithm for mapping inbound + IPsec datagrams to SAs in the presence of multicast SAs. + + o The appendix "Sequence Space Window Code Example" has been removed. + + o With respect to IP addresses and ports, the terms "Local" and + "Remote" are used for policy rules (replacing source and + destination). "Local" refers to the entity being protected by an + IPsec implementation, i.e., the "source" address/port of outbound + packets or the "destination" address/port of inbound packets. + "Remote" refers to a peer entity or peer entities. The terms + "source" and "destination" are still used for packet header + fields. + + + + + + + + + + + +Kent & Seo [Page 72] + +Internet Draft Security Architecture for IP March 2005 + + +Acknowledgements + + The authors would like to acknowledge the contributions of Ran + Atkinson, who played a critical role in initial IPsec activities, and + who authored the first series of IPsec standards: RFCs 1825-1827; and + Charlie Lynn, who made significant contributions to the second series + of IPsec standards (RFCs 2401,2402,and 2406) and to the current + versions, especially with regard to IPv6 issues. The authors also + would like to thank the members of the IPsec and MSEC working groups + who have contributed to the development of this protocol + specification. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 73] + +Internet Draft Security Architecture for IP March 2005 + + +Appendix A -- Glossary + +This section provides definitions for several key terms that are +employed in this document. Other documents provide additional +definitions and background information relevant to this technology, +e.g., [Shi00, VK83, HA94]. Included in this glossary are generic +security service and security mechanism terms, plus IPsec-specific +terms. + + Access Control + Access control is a security service that prevents unauthorized + use of a resource, including the prevention of use of a resource + in an unauthorized manner. In the IPsec context, the resource to + which access is being controlled is often: + o for a host, computing cycles or data + o for a security gateway, a network behind the gateway + or bandwidth on that network. + + Anti-replay + [See "Integrity" below] + + Authentication + This term is used informally to refer to the combination of two + nominally distinct security services, data origin authentication + and connectionless integrity. See the definitions below for each + of these services. + + Availability + Availability, when viewed as a security service, addresses the + security concerns engendered by attacks against networks that deny + or degrade service. For example, in the IPsec context, the use of + anti-replay mechanisms in AH and ESP support availability. + + Confidentiality + Confidentiality is the security service that protects data from + unauthorized disclosure. The primary confidentiality concern in + most instances is unauthorized disclosure of application level + data, but disclosure of the external characteristics of + communication also can be a concern in some circumstances. + Traffic flow confidentiality is the service that addresses this + latter concern by concealing source and destination addresses, + message length, or frequency of communication. In the IPsec + context, using ESP in tunnel mode, especially at a security + gateway, can provide some level of traffic flow confidentiality. + (See also traffic analysis, below.) + + Data Origin Authentication + Data origin authentication is a security service that verifies the + identity of the claimed source of data. This service is usually + + +Kent & Seo [Page 74] + +Internet Draft Security Architecture for IP March 2005 + + + bundled with connectionless integrity service. + + Encryption + Encryption is a security mechanism used to transform data from an + intelligible form (plaintext) into an unintelligible form + (ciphertext), to provide confidentiality. The inverse + transformation process is designated "decryption". Oftimes the + term "encryption" is used to generically refer to both processes. + + Integrity + Integrity is a security service that ensures that modifications to + data are detectable. Integrity comes in various flavors to match + application requirements. IPsec supports two forms of integrity: + connectionless and a form of partial sequence integrity. + Connectionless integrity is a service that detects modification of + an individual IP datagram, without regard to the ordering of the + datagram in a stream of traffic. The form of partial sequence + integrity offered in IPsec is referred to as anti-replay + integrity, and it detects arrival of duplicate IP datagrams + (within a constrained window). This is in contrast to + connection-oriented integrity, which imposes more stringent + sequencing requirements on traffic, e.g., to be able to detect + lost or re-ordered messages. Although authentication and + integrity services often are cited separately, in practice they + are intimately connected and almost always offered in tandem. + + Protected vs Unprotected + "Protected" refers to the systems or interfaces that are inside + the IPsec protection boundary and "unprotected" refers to the + systems or interfaces that are outside the IPsec protection + boundary. IPsec provides a boundary through which traffic passes. + There is an asymmetry to this barrier, which is reflected in the + processing model. Outbound data, if not discarded or bypassed, is + protected via the application of AH or ESP and the addition of the + corresponding headers. Inbound data, if not discarded or + bypassed, is processed via the removal of AH or ESP headers. In + this document, inbound traffic enters an IPsec implementation from + the "unprotected" interface. Outbound traffic enters the + implementation via the "protected" interface, or is internally + generated by the implementation on the "protected" side of the + boundary and directed toward the "unprotected" interface. An IPsec + implementation may support more than one interface on either or + both sides of the boundary. The protected interface may be + internal, e.g., in a host implementation of IPsec. The protected + interface may link to a socket layer interface presented by the + OS. + + Security Association (SA) + A simplex (uni-directional) logical connection, created for + + +Kent & Seo [Page 75] + +Internet Draft Security Architecture for IP March 2005 + + + security purposes. All traffic traversing an SA is provided the + same security processing. In IPsec, an SA is an internet layer + abstraction implemented through the use of AH or ESP. State data + associated with an SA is represented in the SA Database (SAD). + + Security Gateway + A security gateway is an intermediate system that acts as the + communications interface between two networks. The set of hosts + (and networks) on the external side of the security gateway is + termed unprotected (they are generally at least less protected + than those "behind" the SG), while the networks and hosts on the + internal side are viewed as protected. The internal subnets and + hosts served by a security gateway are presumed to be trusted by + virtue of sharing a common, local, security administration. (See + "Trusted Subnetwork" below.) In the IPsec context, a security + gateway is a point at which AH and/or ESP is implemented in order + to serve a set of internal hosts, providing security services for + these hosts when they communicate with external hosts also + employing IPsec (either directly or via another security gateway). + + SPI + Acronym for "Security Parameters Index" (SPI). The SPI is an + arbitrary 32-bit value that is used by a receiver to identify the + SA to which an incoming packet should be bound. For a unicast SA, + the SPI can be used by itself to specify an SA, or it may be used + in conjunction with the IPsec protocol type. Additional IP + address information is used to identify multicast SAs. The SPI is + carried in AH and ESP protocols to enable the receiving system to + select the SA under which a received packet will be processed. An + SPI has only local significance, as defined by the creator of the + SA (usually the receiver of the packet carrying the SPI); thus an + SPI is generally viewed as an opaque bit string. However, the + creator of an SA may choose to interpret the bits in an SPI to + facilitate local processing. + + Traffic Analysis + The analysis of network traffic flow for the purpose of deducing + information that is useful to an adversary. Examples of such + information are frequency of transmission, the identities of the + conversing parties, sizes of packets, flow identifiers, etc. + [Sch94] + + + + + + + + + + +Kent & Seo [Page 76] + +Internet Draft Security Architecture for IP March 2005 + + +Appendix B - Decorrelation + + This appendix is based on work done for caching of policies in the IP + Security Policy Working Group by Luis Sanchez, Matt Condell, and John + Zao. + + Two SPD entries are correlated if there is a non-null intersection + between the values of corresponding selectors in each entry. Caching + correlated SPD entries can lead to incorrect policy enforcement. A + solution to this problem, that still allows for caching, is to remove + the ambiguities by decorrelating the entries. That is, the SPD + entries must be rewritten so that for every pair of entries there + exists a selector for which there is a null intersection between the + values in both of the entries. Once the entries are decorrelated, + there is no longer any ordering requirement on them, since only one + entry will match any lookup. The next section describes + decorrelation in more detail and presents an algorithm that may be + used to implement decorrelation. + + B.1 Decorrelation Algorithm + + The basic decorrelation algorithm takes each entry in a correlated + SPD and divides it up into a set of entries using a tree structure. + The nodes of the tree are the selectors that may overlap between the + policies. At each node, the algorithm creates a branch for each of + the values of the selector. It also creates one branch for the + complement of the union of all selector values. Policies are then + formed by traversing the tree from the root to each leaf. The + policies at the leaves are compared to the set of already + decorrelated policy rules. Each policy at a leaf is either completely + overridden by a policy in the already decorrelated set and is + discarded or is decorrelated with all the policies in the + decorrelated set and is added to it. + + The basic algorithm does not guarantee an optimal set of decorrelated + entries. That is, the entries may be broken up into smaller sets + than is necessary, though they will still provide all the necessary + policy information. Some extensions to the basic algorithm are + described later to improve this and improve the performance of the + algorithm. + + C A set of ordered, correlated entries (a correlated SPD) + Ci The ith entry in C. + U The set of decorrelated entries being built from C + Ui The ith entry in U. + Sik The kth selection for policy Ci + Ai The action for policy Ci + + A policy (SPD entry) P may be expressed as a sequence of selector + + +Kent & Seo [Page 77] + +Internet Draft Security Architecture for IP March 2005 + + + values and an action (BYPASS, DISCARD, or PROTECT): + + Ci = Si1 x Si2 x ... x Sik -> Ai + + 1) Put C1 in set U as U1 + + For each policy Cj (j > 1) in C + + 2) If Cj is decorrelated with every entry in U, then add it to U. + + 3) If Cj is correlated with one or more entries in U, create a tree + rooted at the policy Cj that partitions Cj into a set of decorrelated + entries. The algorithm starts with a root node where no selectors + have yet been chosen. + + A) Choose a selector in Cj, Sjn, that has not yet been chosen when + traversing the tree from the root to this node. If there are no + selectors not yet used, continue to the next unfinished branch + until all branches have been completed. When the tree is + completed, go to step D. + + T is the set of entries in U that are correlated with the entry + at this node. + + The entry at this node is the entry formed by the selector + values of each of the branches between the root and this node. + Any selector values that are not yet represented by branches + assume the corresponding selector value in Cj, since the values + in Cj represent the maximum value for each selector. + + B) Add a branch to the tree for each value of the selector Sjn that + appears in any of the entries in T. (If the value is a superset + of the value of Sjn in Cj, then use the value in Cj, since that + value represents the universal set.) Also add a branch for the + complement of the union of all the values of the selector Sjn + in T. When taking the complement, remember that the universal + set is the value of Sjn in Cj. A branch need not be created + for the null set. + + C) Repeat A and B until the tree is completed. + + D) The entry to each leaf now represents an entry that is a subset + of Cj. The entries at the leaves completely partition Cj in + such a way that each entry is either completely overridden by + an entry in U, or is decorrelated with the entries in U. + + Add all the decorrelated entries at the leaves of the tree to U. + + 4) Get next Cj and go to 2. + + +Kent & Seo [Page 78] + +Internet Draft Security Architecture for IP March 2005 + + + + 5) When all entries in C have been processed, then U will contain an + decorrelated version of C. + + There are several optimizations that can be made to this algorithm. + A few of them are presented here. + + It is possible to optimize, or at least improve, the amount of + branching that occurs by carefully choosing the order of the + selectors used for the next branch. For example, if a selector Sjn + can be chosen so that all the values for that selector in T are equal + to or a superset of the value of Sjn in Cj, then only a single branch + needs to be created (since the complement will be null). + + Branches of the tree do not have to proceed with the entire + decorrelation algorithm. For example, if a node represents an entry + that is decorrelated with all the entries in U, then there is no + reason to continue decorrelating that branch. Also, if a branch is + completely overridden by an entry in U, then there is no reason to + continue decorrelating the branch. + + An additional optimization is to check to see if a branch is + overridden by one of the CORRELATED entries in set C that has already + been decorrelated. That is, if the branch is part of decorrelating + Cj, then check to see if it was overridden by an entry Cm, m < j. + This is a valid check, since all the entries Cm are already expressed + in U. + + Along with checking if an entry is already decorrelated in step 2, + check if Cj is overridden by any entry in U. If it is, skip it since + it is not relevant. An entry x is overridden by another entry y if + every selector in x is equal to or a subset of the corresponding + selector in entry y. + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 79] + +Internet Draft Security Architecture for IP March 2005 + + +Appendix C -- ASN.1 for an SPD Entry + + This appendix is included as an additional way to describe SPD + entries, as defined in Section 4.4.1. It uses ASN.1 syntax which has + been successfully compiled. This syntax is merely illustrative and + need not be employed in an implementation to achieve compliance. The + SPD description in Section 4.4.1 is normative. + + + SPDModule + + {iso(1) org (3) dod (6) internet (1) security (5) mechanisms (5) + asn1-modules (xx) spd-module (yy) } + + DEFINITIONS IMPLICIT TAGS ::= + + BEGIN + + IMPORTS + RDNSequence FROM PKIX1Explicit88 + { iso(1) identified-organization(3) + dod(6) internet(1) security(5) mechanisms(5) pkix(7) + id-mod(0) id-pkix1-explicit(18) } ; + + -- An SPD is a list of policies in decreasing order of preference + SPD ::= SEQUENCE OF SPDEntry + + SPDEntry ::= CHOICE { + iPsecEntry IPsecEntry, -- PROTECT traffic + bypassOrDiscard [0] BypassOrDiscardEntry } -- DISCARD/BYPASS + + IPsecEntry ::= SEQUENCE { -- Each entry consists of + name NameSets OPTIONAL, + pFPs PacketFlags, -- Populate from packet flags + -- Applies to ALL of the corresponding + -- traffic selectors in the SelectorLists + condition SelectorLists, -- Policy "condition" + processing Processing -- Policy "action" + } + + BypassOrDiscardEntry ::= SEQUENCE { + bypass BOOLEAN, -- TRUE BYPASS, FALSE DISCARD + condition InOutBound } + + InOutBound ::= CHOICE { + outbound [0] SelectorLists, + inbound [1] SelectorLists, + bothways [2] BothWays } + + + +Kent & Seo [Page 80] + +Internet Draft Security Architecture for IP March 2005 + + + BothWays ::= SEQUENCE { + inbound SelectorLists, + outbound SelectorLists } + + NameSets ::= SEQUENCE { + passed SET OF Names-R, -- Matched to IKE ID by + -- responder + local SET OF Names-I } -- Used internally by IKE + -- initiator + + Names-R ::= CHOICE { -- IKE v2 IDs + dName RDNSequence, -- ID_DER_ASN1_DN + fqdn FQDN, -- ID_FQDN + rfc822 [0] RFC822Name, -- ID_RFC822_ADDR + keyID OCTET STRING } -- KEY_ID + + Names-I ::= OCTET STRING -- Used internally by IKE + -- initiator + + FQDN ::= IA5String + + RFC822Name ::= IA5String + + PacketFlags ::= BIT STRING { + -- if set, take selector value from packet + -- establishing SA + -- else use value in SPD entry + localAddr (0), + remoteAddr (1), + protocol (2), + localPort (3), + remotePort (4) } + + SelectorLists ::= SET OF SelectorList + + SelectorList ::= SEQUENCE { + localAddr AddrList, + remoteAddr AddrList, + protocol ProtocolChoice } + + Processing ::= SEQUENCE { + extSeqNum BOOLEAN, -- TRUE 64 bit counter, FALSE 32 bit + seqOverflow BOOLEAN, -- TRUE rekey, FALSE terminate & audit + fragCheck BOOLEAN, -- TRUE stateful fragment checking, + -- FALSE no stateful fragment checking + lifetime SALifetime, + spi ManualSPI, + algorithms ProcessingAlgs, + tunnel TunnelOptions OPTIONAL } -- if absent, use + + +Kent & Seo [Page 81] + +Internet Draft Security Architecture for IP March 2005 + + + -- transport mode + + SALifetime ::= SEQUENCE { + seconds [0] INTEGER OPTIONAL, + bytes [1] INTEGER OPTIONAL } + + ManualSPI ::= SEQUENCE { + spi INTEGER, + keys KeyIDs } + + KeyIDs ::= SEQUENCE OF OCTET STRING + + ProcessingAlgs ::= CHOICE { + ah [0] IntegrityAlgs, -- AH + esp [1] ESPAlgs} -- ESP + + ESPAlgs ::= CHOICE { + integrity [0] IntegrityAlgs, -- integrity only + confidentiality [1] ConfidentialityAlgs, -- confidentiality + -- only + both [2] IntegrityConfidentialityAlgs, + combined [3] CombinedModeAlgs } + + IntegrityConfidentialityAlgs ::= SEQUENCE { + integrity IntegrityAlgs, + confidentiality ConfidentialityAlgs } + + -- Integrity Algorithms, ordered by decreasing preference + IntegrityAlgs ::= SEQUENCE OF IntegrityAlg + + -- Confidentiality Algorithms, ordered by decreasing preference + ConfidentialityAlgs ::= SEQUENCE OF ConfidentialityAlg + + -- Integrity Algorithms + IntegrityAlg ::= SEQUENCE { + algorithm IntegrityAlgType, + parameters ANY -- DEFINED BY algorithm -- OPTIONAL } + + IntegrityAlgType ::= INTEGER { + none (0), + auth-HMAC-MD5-96 (1), + auth-HMAC-SHA1-96 (2), + auth-DES-MAC (3), + auth-KPDK-MD5 (4), + auth-AES-XCBC-96 (5) + -- tbd (6..65535) + } + + -- Confidentiality Algorithms + + +Kent & Seo [Page 82] + +Internet Draft Security Architecture for IP March 2005 + + + ConfidentialityAlg ::= SEQUENCE { + algorithm ConfidentialityAlgType, + parameters ANY -- DEFINED BY algorithm -- OPTIONAL } + + ConfidentialityAlgType ::= INTEGER { + encr-DES-IV64 (1), + encr-DES (2), + encr-3DES (3), + encr-RC5 (4), + encr-IDEA (5), + encr-CAST (6), + encr-BLOWFISH (7), + encr-3IDEA (8), + encr-DES-IV32 (9), + encr-RC4 (10), + encr-NULL (11), + encr-AES-CBC (12), + encr-AES-CTR (13) + -- tbd (14..65535) + } + + CombinedModeAlgs ::= SEQUENCE OF CombinedModeAlg + + CombinedModeAlg ::= SEQUENCE { + algorithm CombinedModeType, + parameters ANY -- DEFINED BY algorithm} -- defined outside + -- of this document for AES modes. + + CombinedModeType ::= INTEGER { + comb-AES-CCM (1), + comb-AES-GCM (2) + -- tbd (3..65535) + } + + TunnelOptions ::= SEQUENCE { + dscp DSCP, + ecn BOOLEAN, -- TRUE Copy CE to inner header + df DF, + addresses TunnelAddresses } + + TunnelAddresses ::= CHOICE { + ipv4 IPv4Pair, + ipv6 [0] IPv6Pair } + + IPv4Pair ::= SEQUENCE { + local OCTET STRING (SIZE(4)), + remote OCTET STRING (SIZE(4)) } + + IPv6Pair ::= SEQUENCE { + + +Kent & Seo [Page 83] + +Internet Draft Security Architecture for IP March 2005 + + + local OCTET STRING (SIZE(16)), + remote OCTET STRING (SIZE(16)) } + + DSCP ::= SEQUENCE { + copy BOOLEAN, -- TRUE copy from inner header + -- FALSE do not copy + mapping OCTET STRING OPTIONAL} -- points to table + -- if no copy + + DF ::= INTEGER { + clear (0), + set (1), + copy (2) } + + ProtocolChoice::= CHOICE { + anyProt AnyProtocol, -- for ANY protocol + noNext [0] NoNextLayerProtocol, -- has no next layer + -- items + oneNext [1] OneNextLayerProtocol, -- has one next layer + -- item + twoNext [2] TwoNextLayerProtocol, -- has two next layer + -- items + fragment FragmentNoNext } -- has no next layer + -- info + + AnyProtocol ::= SEQUENCE { + id INTEGER (0), -- ANY protocol + nextLayer AnyNextLayers } + + AnyNextLayers ::= SEQUENCE { -- with either + first AnyNextLayer, -- ANY next layer selector + second AnyNextLayer } -- ANY next layer selector + + NoNextLayerProtocol ::= INTEGER (2..254) + + FragmentNoNext ::= INTEGER (44) -- Fragment identifier + + OneNextLayerProtocol ::= SEQUENCE { + id INTEGER (1..254), -- ICMP, MH, ICMPv6 + nextLayer NextLayerChoice } -- ICMP Type*256+Code + -- MH Type*256 + + TwoNextLayerProtocol ::= SEQUENCE { + id INTEGER (2..254), -- Protocol + local NextLayerChoice, -- Local and + remote NextLayerChoice } -- Remote ports + + NextLayerChoice ::= CHOICE { + any AnyNextLayer, + + +Kent & Seo [Page 84] + +Internet Draft Security Architecture for IP March 2005 + + + opaque [0] OpaqueNextLayer, + range [1] NextLayerRange } + + -- Representation of ANY in next layer field + AnyNextLayer ::= SEQUENCE { + start INTEGER (0), + end INTEGER (65535) } + + -- Representation of OPAQUE in next layer field. + -- Matches IKE convention + OpaqueNextLayer ::= SEQUENCE { + start INTEGER (65535), + end INTEGER (0) } + + -- Range for a next layer field + NextLayerRange ::= SEQUENCE { + start INTEGER (0..65535), + end INTEGER (0..65535) } + + -- List of IP addresses + AddrList ::= SEQUENCE { + v4List IPv4List OPTIONAL, + v6List [0] IPv6List OPTIONAL } + + -- IPv4 address representations + IPv4List ::= SEQUENCE OF IPv4Range + + IPv4Range ::= SEQUENCE { -- close, but not quite right ... + ipv4Start OCTET STRING (SIZE (4)), + ipv4End OCTET STRING (SIZE (4)) } + + -- IPv6 address representations + IPv6List ::= SEQUENCE OF IPv6Range + + IPv6Range ::= SEQUENCE { -- close, but not quite right ... + ipv6Start OCTET STRING (SIZE (16)), + ipv6End OCTET STRING (SIZE (16)) } + + + END + + + + + + + + + + + +Kent & Seo [Page 85] + +Internet Draft Security Architecture for IP March 2005 + + +Appendix D -- Fragment Handling Rationale + + There are three issues that must be resolved re processing of + (plaintext) fragments in IPsec: + + - mapping a non-initial, outbound fragment to the right SA + (or finding the right SPD entry) + - verifying that a received, non-initial fragment is authorized + for the SA via which it is received + - mapping outbound and inbound non-initial fragments to the + right SPD/cache entry, for BYPASS/DISCARD traffic. + + The first and third issues arise because we need a deterministic + algorithm for mapping traffic to SAs (and SPD/cache entries). All + three issues are important because we want to make sure that + non-initial fragments that cross the IPsec boundary do not cause the + access control policies in place at the receiver (or transmitter) to + be violated. + +D.1 Transport Mode and Fragments + + First, we note that transport mode SAs have been defined to not carry + fragments. This is a carryover from RFC 2401, where transport mode + SAs always terminated at end points. This is a fundamental + requirement because, in the worst case, an IPv4 fragment to which + IPsec was applied, might then be fragmented (as a ciphertext packet), + en route to the destination. IP fragment reassembly procedures at the + IPsec receiver would not be able to distinguish between pre-IPsec + fragments and fragments created after IPsec processing. + + For IPv6, only the sender is allowed to fragment a packet. As for + IPv4, an IPsec implementation is allowed to fragment tunnel mode + packets after IPsec processing, because it is the sender relative to + the (outer) tunnel header. However, unlike IPv4, it would be feasible + to carry a plaintext fragment on a transport mode SA, because the + fragment header in IPv6 would appear after the AH or ESP header, and + thus would not cause confusion at the receiver re reassembly. + Specifically, the receiver would not attempt reassembly for the + fragment until after IPsec processing. To keep things simple, this + specification prohibits carriage of fragments on transport mode SAs + for IPv6 traffic. + + When only end systems used transport mode SAs, the prohibition on + carriage of fragments was not a problem, since we assumed that the + end system could be configured to not offer a fragment to IPsec. For + a native host implementation this seems reasonable, and, as someone + already noted, RFC 2401 warned that a BITS implementation might have + to reassemble fragments before performing an SA lookup. (It would + then apply AH or ESP and could re-fragment the packet after IPsec + + +Kent & Seo [Page 86] + +Internet Draft Security Architecture for IP March 2005 + + + processing.) Because a BITS implementation is assumed to be able to + have access to all traffic emanating from its host, even if the host + has multiple interfaces, this was deemed a reasonable mandate. + + In this specification, it is acceptable to use transport mode in + cases where the IPsec implementation is not the ultimate destination, + e.g., between two SGs. In principle, this creates a new opportunity + for outbound, plaintext fragments to be mapped to a transport mode SA + for IPsec processing. However, in these new contexts in which a + transport mode SA is now approved for use, it seems likely that we + can continue to prohibit transmission of fragments, as seen by IPsec, + i.e., packets that have an "outer header" with a non-zero fragment + offset field. For example, in an IP overlay network, packets being + sent over transport mode SAs are IP-in-IP tunneled and thus have the + necessary inner header to accommodate fragmentation prior to IPsec + processing. When carried via a transport mode SA, IPsec would not + examine the inner IP header for such traffic, and thus would not + consider the packet to be a fragment. + +D.2 Tunnel Mode and Fragments + + For tunnel mode SAs, it has always been the case that outbound + fragments might arrive for processing at an IPsec implementation. The + need to accommodate fragmented outbound packets can pose a problem + because a non-initial fragment generally will not contain the port + fields associated with a next layer protocol such as TCP, UDP, or + SCTP. Thus, depending on the SPD configuration for a given IPsec + implementation, plaintext fragments might or might not pose a + problem. + + For example, if the SPD requires that all traffic between two address + ranges is offered IPsec protection (no BYPASS or DISCARD SPD entries + apply to this address range), then it should be easy to carry + non-initial fragments on the SA defined for this address range, since + the SPD entry implies an intent to carry ALL traffic between the + address ranges. But, if there are multiple SPD entries that could + match a fragment, and if these entries reference different subsets of + port fields (vs. ANY), then it is not possible to map an outbound + non-initial fragment to the right entry, unambiguously. (If we choose + to allow carriage of fragments on transport mode SAs for IPv6, the + problems arises in that context as well.) + + This problem largely, though not exclusively, motivated the + definition of OPAQUE as a selector value for port fields in RFC 2401. + The other motivation for OPAQUE is the observation that port fields + might not be accessible due to the prior application of IPsec. For + example, if a host applied IPsec to its traffic and that traffic + arrived at an SG, these fields would be encrypted. The algorithm + specified for locating the "next layer protocol" described in RFC + + +Kent & Seo [Page 87] + +Internet Draft Security Architecture for IP March 2005 + + + 2401 also motivated use of OPAQUE to accommodate an encrypted next + layer protocol field in such circumstances. Nonetheless, the primary + use of the OPAQUE value was to match traffic selector fields in + packets that did not contain port fields (non-initial fragments), or + packets in which the port fields were already encrypted (as a result + of nested application of IPsec). RFC 2401 was ambiguous in discussing + the use of OPAQUE vs. ANY, suggesting in some places that ANY might + be an alternative to OPAQUE. + + We gain additional access control capability by defining both ANY and + OPAQUE values. OPAQUE can be defined to match only fields that are + not accessible. We could define ANY as the complement of OPAQUE, + i.e., it would match all values but only for accessible port fields. + We have therefore simplified the procedure employed to locate the + next layer protocol in this document, so that we treat ESP and AH as + next layer protocols. As a result, the notion of an encrypted next + layer protocol field has vanished, and there is also no need to worry + about encrypted port fields either. And accordingly, OPAQUE will be + applicable only to non-initial fragments. + + Since we have adopted the definitions above for ANY and OPAQUE, we + need to clarify how these values work when the specified protocol + does not have port fields, and when ANY is used for the protocol + selector. Accordingly, if a specific protocol value is used as a + selector, and if that protocol has no port fields, then the port + field selectors are to be ignored and ANY MUST be specified as the + value for the port fields. (In this context, ICMP TYPE and CODE + values are lumped together as a single port field (for IKE v2 + negotiation), as is the IPv6 Mobility Header TYPE value.) If the + protocol selector is ANY, then this should be treated as equivalent + to specifying a protocol for which no port fields are defined, and + thus the port selectors should be ignored, and MUST be set to ANY. + +D.3. The Problem of Non-Initial Fragments + + For an SG implementation, it is obvious that fragments might arrive + from end systems behind the SG. A BITW implementation also may + encounter fragments from a host or gateway behind it. (As noted + earlier, native host implementations and BITS implementations + probably can avoid the problems described below.) In the worst case, + fragments from a packet might arrive at distinct BITW or SG + instantiations and thus preclude reassembly as a solution option. + Hence, in RFC 2401 we adopted a general requirement that fragments + must be accommodated in tunnel mode for all implementations. However, + RFC 2401 did not provide a perfect solution. The use of OPAQUE as a + selector value for port fields (a SHOULD in RFC 2401) allowed an SA + to carry non-initial fragments. + + Using the features defined in RFC 2401, if one defined an SA between + + +Kent & Seo [Page 88] + +Internet Draft Security Architecture for IP March 2005 + + + two IPsec (SG or BITW) implementations using the OPAQUE value for + both port fields, then all non-initial fragments matching the S/D + address and protocol values for the SA would be mapped to that SA. + Initial fragments would NOT map to this SA, if we adopt a strict + definition of OPAQUE. However, RFC 2401 did not provide detailed + guidance on this and thus it may not have been apparent that use of + this feature would essentially create a "non-initial fragment only" + SA. + + In the course of discussing the "fragment-only" SA approach, it was + noted that some subtle problems, problems not considered in RFC 2401, + would have to be avoided. For example, an SA of this sort must be + configured to offer the "highest quality" security services for any + traffic between the indicated S/D addresses (for the specified + protocol). This is necessary to ensure that any traffic captured by + the fragment-only SA is not offered degraded security relative to + what it would have been offered if the packet were not fragmented. A + possible problem here is that we may not be able to identify the + "highest quality" security services defined for use between two IPsec + implementation, since the choice of security protocols, options, and + algorithms is a lattice, not a totally ordered set. (We might safely + say that BYPASS < AH < ESP w/integrity, but it gets complicated if we + have multiple ESP encryption or integrity algorithm options.) So, one + has to impose a total ordering on these security parameters to make + this work, but this can be done locally. + + However, this conservative strategy has a possible performance down + side; if most traffic traversing an IPsec implementation for a given + S/D address pair (and specified protocol) is bypassed, then a + fragment-only SA for that address pair might cause a dramatic + increase in the volume of traffic afforded crypto processing. If the + crypto implementation cannot support high traffic rates, this could + cause problems. (An IPsec implementation that is capable of line rate + or near line rate crypto performance would not be adversely affected + by this SA configuration approach. Nonetheless, the performance + impact is a potential concern, specific to implementation + capabilities.) + + Another concern is that non-initial fragments sent over a dedicated + SA might be used to effect overlapping reassembly attacks, when + combined with an apparently acceptable initial fragment. (This sort + of attack assumes creation of bogus fragments, and is not a side + effect of normal fragmentation.) This concern is easily addressed in + IPv4, by checking the fragment offset value to ensure that no + non-initial fragments have a small enough offset to overlap port + fields that should be contained in the initial fragment. Recall that + the IPv4 MTU minimum is 576 bytes, and the max IP header length is 60 + bytes, so any ports should be present in the initial fragment. If we + require all non-initial fragments to have an offset of say 128 or + + +Kent & Seo [Page 89] + +Internet Draft Security Architecture for IP March 2005 + + + greater, just to be on the safe side, this should prevent successful + attacks of this sort. If the intent is only to protect against this + sort of reassembly attack, this check need be implemented only by a + receiver. + + IPv6 also has a fragment offset, carried in the fragmentation + extension header. However, IPv6 extension headers are variable in + length and there is no analogous max header length value that we can + use to check non-initial fragments, to reject ones that might be used + for an attack of the sort noted above. A receiver would need to + maintain state analogous to reassembly state, to provide equivalent + protection. So, only for IPv4 it is feasible to impose a fragment + offset check that would reject attacks designed to circumvent port + field checks by IPsec (or firewalls) when passing non-initial + fragments. + + Another possible concern is that in some topologies and SPD + configurations this approach might result in an access control + surprise. The notion is that if we create an SA to carry ALL + (non-initial) fragments then that SA would carry some traffic that + might otherwise arrive as plaintext via a separate path, e.g., a path + monitored by a proxy firewall. But, this concern arises only if the + other path allows initial fragments to traverse it without requiring + reassembly, presumably a bad idea for a proxy firewall. Nonetheless, + this does represent a potential problem in some topologies and under + certain assumptions re: SPD and (other) firewall rule sets, and + administrators need to be warned of this possibility. + + A less serious concern is that non-initial fragments sent over a + non-initial fragment-only SA might represent a DoS opportunity, in + that they could be sent when no valid, initial fragment will ever + arrive. This might be used to attack hosts behind an SG or BITW + device. However, the incremental risk posed by this sort of attack, + which can be mounted only by hosts behind an SG or BITW device, seems + small. + + If we interpret the ANY selector value as encompassing OPAQUE, then a + single SA with ANY values for both port fields would be able to + accommodate all traffic matching the S/D address and protocol traffic + selectors, an alternative to using the OPAQUE value. But, using ANY + here precludes multiple, distinct SAs between the same IPsec + implementations for the same address pairs and protocol. So, it is + not an exactly equivalent alternative. + + Fundamentally, fragment handling problems arise only when more than + one SA is defined with the same S/D address and protocol selector + values, but with different port field selector values. + + + + +Kent & Seo [Page 90] + +Internet Draft Security Architecture for IP March 2005 + + +D.4 BYPASS/DISCARD Traffic + + We also have to address the non-initial fragment processing issue for + BYPASS/DISCARD entries, independent of SA processing. This is largely + a local matter for two reasons: + 1) We have no means for coordinating SPD entries for such + traffic between IPsec implementations since IKE is not + invoked. + 2) Many of these entries refer to traffic that is NOT + directed to or received from a location that is using + IPsec. So there is no peer IPsec implementation with + which to coordinate via any means. + + However, this document should provide guidance here, consistent with + our goal of offering a well-defined, access control function for all + traffic, relative to the IPsec boundary. To that end, this document + says that implementations MUST support fragment reassembly for + BYPASS/DISCARD traffic when port fields are specified. An + implementation also MUST permit a user or administrator to accept + such traffic or reject such traffic using the SPD conventions + described in Secion 4.4.1. The concern is that BYPASS of a + cleartext, non-initial fragment arriving at an IPsec implementation + could undermine the security afforded IPsec-protected traffic + directed to the same destination. For example, consider an IPsec + implementation configured with an SPD entry that calls for + IPsec-protection of traffic between a specific source/destination + address pair, and for a specific protocol and destination port, e.g., + TCP traffic on port 23 (Telnet). Assume that the implementation also + allows BYPASS of traffic from the same source/destination address + pair and protocol, but for a different destination port, e.g., port + 119 (NNTP). An attacker could send a non-initial fragment (with a + forged source address) that, if bypassed, could overlap with + IPsec-protected traffic from the same source and thus violate the + integrity of the IPsec-protected traffic. Requiring stateful fragment + checking for BYPASS entries with non-trivial port ranges prevents + attacks of this sort. + +D.5 Just say no to ports? + + It has been suggested that we could avoid the problems described + above by not allowing port field selectors to be used in tunnel mode. + But the discussion above shows this to be an unnecessarily stringent + approach, i.e., since no problems arise for the native OS and BITS + implementations. Moreover, some WG members have described scenarios + where use of tunnel mode SAs with (non-trivial) port field selectors + is appropriate. So the challenge is defining a strategy that can deal + with this problem in BITW and SG contexts. Also note that + BYPASS/DISCARD entries in the SPD that make use of ports pose the + same problems, irrespective of tunnel vs. transport mode notions. + + +Kent & Seo [Page 91] + +Internet Draft Security Architecture for IP March 2005 + + + Some folks have suggested that a firewall behind an SG or BITW should + be left to enforce port level access controls, and the effects of + fragmentation. However, this seems to be an incongruous suggestion in + that elsewhere in IPsec (e.g., in IKE payloads) we are concerned + about firewalls that always discard fragments. If many firewalls + don't pass fragments in general, why should we expect them to deal + with fragments in this case? So, this analysis rejects the suggestion + of disallowing use of port field selectors with tunnel mode SAs. + +D.6 Other Suggested Solutions + + One suggestion is to reassemble fragments at the sending IPsec + implementation, and thus avoid the problem entirely. This approach is + invisible to a receiver and thus could be adopted as a purely local + implementation option. + + A more sophisticated version of this suggestion calls for + establishing and maintaining minimal state from each initial fragment + encountered, to allow non-initial fragments to be matched to the + right SAs or SPD/cache entries. This implies an extension to the + current processing model (and the old one). The IPsec implementation + would intercept all fragments, capture Source/Destination IP + addresses, protocol, packet ID, and port fields from initial + fragments and then use this data to map non-initial fragments to SAs + that require port fields. If this approach is employed, the receiver + needs to employ an equivalent scheme, as it too must verify that + received fragments are consistent with SA selector values. A + non-initial fragment that arrives prior to an initial fragment could + be cached or discarded, awaiting arrival of the corresponding initial + fragment. + + A downside of both approaches noted above is that they will not + always work. When a BITW device or SG is configured in a topology + that might allow some fragments for a packet to be processed at + different SGs or BITW devices, then there is no guarantee that all + fragments will ever arrive at the same IPsec device. This approach + also raises possible processing problems. If the sender caches + non-initial fragments until the corresponding initial fragment + arrives, buffering problems might arise, especially at high speeds. + If the non-initial fragments are discarded rather than cached, there + is no guarantee that traffic will ever pass, e.g., retransmission + will result in different packet IDs that cannot be matched with prior + transmissions. In any case, housekeeping procedures will be needed to + decide when to delete the fragment state data, adding some complexity + to the system. Nonetheless, this is a viable solution in some + topologies, and these are likely to be common topologies. + + The Working Group rejected an earlier version of the convention of + creating an SA to carry only non-initial fragments, something that + + +Kent & Seo [Page 92] + +Internet Draft Security Architecture for IP March 2005 + + + was supported implicitly under the RFC 2401 model via use of OPAQUE + port fields, but never clearly articulated in RFC 2401. The + (rejected) text called for each non-initial fragment to be treated as + protocol 44 (the IPv6 fragment header protocol ID) by the sender and + receiver. This approach has the potential to make IPv4 and IPv6 + fragment handling more uniform, but it does not fundamentally change + the problem, nor does it address the issue of fragment handling for + BYPASS/DISCARD traffic. Given the fragment overlap attack problem + that IPv6 poses, it does not seem that it is worth the effort to + adopt this strategy. + +D.7 Consistency + + Earlier the WG agreed to allow an IPsec BITS, BITW or SG to perform + fragmentation prior to IPsec processing. If this fragmentation is + performed after SA lookup at the sender, there is no "mapping to the + right SA" problem. But, the receiver still needs to be able to verify + that the non-initial fragments are consistent with the SA via which + they are received. Since the initial fragment might be lost en route, + the receiver encounters all of the potential problems noted above. + Thus, if we are to be consistent in our decisions, we need to say how + a receiver will deal with the non-initial fragments that arrive. + +D.8 Conclusions + + There is no simple, uniform way to handle fragments in all contexts. + Different approaches work better in different contexts. Thus this + document offers 3 choices -- one MUST and two MAYs. At some point in + the future, if the community gains experience with the two MAYs, they + may become SHOULDs or MUSTs or other approaches may be proposed. + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 93] + +Internet Draft Security Architecture for IP March 2005 + + +Appendix E - Example of Supporting Nested SAs via SPD and Forwarding +Table Entries + + This appendix provides an example of how to configure the SPD and + forwarding tables to support a nested pair of SAs, consistent with + the new processing model. For simplicity, this example assumes just + one SPD-I. + + The goal in this example is to support a transport mode SA from A to + C, carried over a tunnel mode SA from A to B. For example, A might be + a laptop connected to the public internet, B a firewall that protects + a corporate network, and C a server on the corporate network that + demands end-to-end authentication of A's traffic. + + +---+ +---+ +---+ + | A |=====| B | | C | + | |------------| | + | |=====| | | | + +---+ +---+ +---+ + + A's SPD contains entries of the form: + + Next Layer + Rule Local Remote Protocol Action + ---- ----- ------ ---------- ----------------------- + 1 C A ESP BYPASS + 2 A C ICMP,ESP PROTECT(ESP,tunnel,integr+conf) + 3 A C ANY PROTECT(ESP,transport,integr-only) + 4 A B ICMP,IKE BYPASS + + A's unprotected-side forwarding table is set so that outbound packets + destined for C are looped back to the protected side. A's protected + side forwarding table is set so that inbound ESP packets are looped + back to the unprotected side. A's forwarding tables contain entries + of the form: + + Unprotected-side forwarding table + + Rule Local Remote Protocol Action + ---- ----- ------ -------- --------------------------- + 1 A C ANY loop back to protected side + 2 A B ANY forward to B + + Protected-side forwarding table + + Rule Local Remote Protocol Action + ---- ----- ------ -------- ----------------------------- + 1 A C ESP loop back to unprotected side + + + +Kent & Seo [Page 94] + +Internet Draft Security Architecture for IP March 2005 + + + An outbound TCP packet from A to C would match SPD rule 3 and have + transport mode ESP applied to it. The unprotected-side forwarding + table would then loop back the packet. The packet is compared against + SPD-I (see Figure 2), matches SPD rule 1, and so it is BYPASSed. The + packet is treated as an outbound packet and compared against the SPD + for a third time. This time it matches SPD rule 2, so ESP is applied + in tunnel mode. This time the forwarding table doesn't loop back the + packet, because the outer destination address is B, so the packet + goes out onto the wire. + + An inbound TCP packet from C to A, is wrapped in two ESP headers; the + outer header (ESP in tunnel mode) shows B as the source whereas the + inner header (ESP transport mode) shows C as the source. Upon arrival + at A, the packet would be mapped to an SA based on the SPI, have the + outer header removed, and be decrypted and integrity-checked. Then it + would be matched against the SAD selectors for this SA, which would + specify C as the source and A as the destination, derived from SPD + rule 2. The protected-side forwarding function would then send it + back to the unprotected side based on the addresses and the next + layer protocol (ESP), indicative of nesting. It is compared against + SPD-O (see figure 3) and found to match SPD rule 1, so it is + BYPASSed. The packet is mapped to an SA based on the SPI, + integrity-checked, and compared against the SAD selectors derived + from SPD rule 3. The forwarding function then passes it up to the + next layer, because it isn't an ESP packet. + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 95] + +Internet Draft Security Architecture for IP March 2005 + + +References + + +Normative + + [BBCDWW98]Blake, S., Black, D., Carlson, M., Davies, E., Wang, Z., + and W. Weiss, "An Architecture for Differentiated Service", + RFC 2475, December 1998. + + [Bra97] Bradner, S., "Key words for use in RFCs to Indicate + Requirement Level", BCP 14, RFC 2119, March 1997. + + [CD98] Conta, A. and S. Deering, "Internet Control Message + Protocol (ICMPv6) for the Internet Protocol Version 6 + (IPv6) Specification", RFC 2463, December 1998. + + [DH98] Deering, S., and R. Hinden, "Internet Protocol, Version 6 + (IPv6) Specification", RFC 2460, December 1998. + + [Eas05] Eastlake, D., "Cryptographic Algorithm Implementation + Requirements For ESP And AH", ???, ???? 200?. + + [RFC Editor: Please update reference [Eas05] "Cryptographic + Algorithm Implementation Requirements For ESP And AH" + (draft-ietf-ipsec-esp-ah-algorithms-02.txt) with the RFC + number and month and year when it is issued.] + + [HarCar98]Harkins, D., and Carrel, D., "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [Kau05] Kaufman, C., "The Internet Key Exchange (IKEv2) Protocol", + RFC ???, ???? 200?. + + [RFC Editor: Please update the reference [Kau05] "The + Internet Key Exchange (IKEv2) Protocol" + (draft-ietf-ipsec-ikev2-17.txt) with the RFC number and + month and year when it is issued.] + + [Ken05a] Kent, S., "IP Encapsulating Security Payload (ESP)", RFC + ???, ???? 200?. + + [RFC Editor: Please update the reference [Ken05a] "IP + Encapsulating Security Payload (ESP)" + (draft-ietf-ipsec-esp-v3-09.txt) with the RFC number and + month and year when it is issued.] + + [Ken05b] Kent, S., "IP Authentication Header", RFC ???, ??? 200?. + + [RFC Editor: Please update the reference [Ken05b] "IP + + +Kent & Seo [Page 96] + +Internet Draft Security Architecture for IP March 2005 + + + Authentication Header" (draft-ietf-ipsec-rfc2402bis-09.txt) + with the RFC number and month and year when it is issued.] + + [MD90] Mogul, J. and S. Deering, "Path MTU discovery", RFC 1191, + November 1990. + + [Pos81a] Postel, J., "Internet Protocol", STD 5, RFC 791, September + 1981 + + [Pos81b] Postel, J., "Internet Control Message Protocol", RFC 792, + September 1981 + + [Sch05] Schiller, J., "Cryptographic Algorithms for use in the + Internet Key Exchange Version 2", RFC ???, ???? 200? + + [RFC Editor: Please update the reference [Sch05] + "Cryptographic Algorithms for use in the Internet Key + Exchange Version 2" + (draft-ietf-ipsec-ikev2-algorithms-05.txt) with the RFC + number and month and year when it is issued.] + + [WaKiHo97]Wahl, M., Kille, S., Howes, T., "Lightweight Directory + Access Protocol (v3): UTF-8 String Representation of + Distinguished Names", RFC 2253, December 1997 + +Informative + + [CoSa04] Condell, M., and Sanchez, L. On the Deterministic + Enforcement of Un-ordered Security Policies", BBN Technical + Memo 1346, March 2004 + + [FaLiHaMeTr00]Farinacci, D., Li, T., Hanks, S., Meyer, D., Traina, + P., "Generic Routing Encapsulation (GRE), RFC 2784, March + 2000. + + [Gro02] Grossman, D., "New Terminology and Clarifications for + Diffserv", RFC 3260, April 2002. + [HC03] Holbrook, H., and Cain, B., "Source Specific Multicast for + IP", WWork in Progress, November 3, 2002. + + [HA94] Haller, N., and Atkinson, R., "On Internet Authentication", + RFC 1704, October 1994 + + [Mobip] Johnson, D., Perkins, C., Arkko, J., "Mobility Support in + IPv6", RFC 3775, June 2004 + + [NiBlBaBL98]Nichols, K., Blake, S., Baker, F., Black, D., "Definition + of the Differentiated Services Field (DS Field) in the IPv4 + and IPv6 Headers", RFC2474, December 1998. + + +Kent & Seo [Page 97] + +Internet Draft Security Architecture for IP March 2005 + + + [Per96] Perkins, C., "IP Encapsulation within IP", RFC 2003, + October 1996. + + [RaFlBl01]Ramakrishnan, K., Floyd, S., Black, D., "The Addition of + Explicit Congestion Notification (ECN) to IP", RFC 3168, + September 2001. + + [RFC3547] Baugher, M., Weis, B., Hardjono, T., Harney, H., "The Group + Domain of Interpretation", RFC 3547, July 2003. + + [RFC3740] Hardjono, T., Weis, B., "The Multicast Group Security + Architecture", RFC 3740, March 2004. + + [RaCoCaDe04]Rajahalme, J., Conta, A., Carpenter, B., Deering, S., + "IPv6 Flow Label Specification, RFC 3697, March 2004. + + [Sch94] Schneier, B., Applied Cryptography, Section 8.6, John + Wiley & Sons, New York, NY, 1994. + + [Shi00] Shirey, R., "Internet Security Glossary", RFC 2828, May + 2000. + + [SMPT01] Shacham, A., Monsour, B., Pereira, R., and M. Thomas, "IP + Payload Compression Protocol (IPComp)", RFC 3173, September + 2001. + + [ToEgWa04]Touch, J., Eggert, L., Wang, Y., Use of IPsec Transport + Mode for Dynamic Routing, RFC 3884, September 2004. + + [VK83] V.L. Voydock & S.T. Kent, "Security Mechanisms in + High-level Networks", ACM Computing Surveys, Vol. 15, No. + 2, June 1983. + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 98] + +Internet Draft Security Architecture for IP March 2005 + + +Author Information + + Stephen Kent + BBN Technologies + 10 Moulton Street + Cambridge, MA 02138 + USA + Phone: +1 (617) 873-3988 + EMail: kent@bbn.com + + Karen Seo + BBN Technologies + 10 Moulton Street + Cambridge, MA 02138 + USA + Phone: +1 (617) 873-3152 + EMail: kseo@bbn.com + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 99] + +Internet Draft Security Architecture for IP March 2005 + + +Notices + + + Intellectual Property + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at ietf- + ipr@ietf.org. + + Full Copyright Statement + + Copyright (C) The Internet Society (2005). This document is subject + to the rights, licenses and restrictions contained in BCP 78, and + except as set forth therein, the authors retain all their rights. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implmentation may be prepared, copied, published and + distributed, in whole or in part, without restriction of any kind, + provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. The limited permissions granted above are perpetual and + will not be revoked by the Internet Society or its successors or + assigns. + + + +Kent & Seo [Page 100] + +Internet Draft Security Architecture for IP March 2005 + + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + +Expires September 2005 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo [Page 101] diff --git a/doc/ikev2/[QuantitativeAnalyses] - IKEv1 and IKEv2 - A Quantitative Analyses.pdf b/doc/ikev2/[QuantitativeAnalyses] - IKEv1 and IKEv2 - A Quantitative Analyses.pdf new file mode 100644 index 0000000000000000000000000000000000000000..a467aea78ce421a94a5ec401d7029740174f2a62 GIT binary patch literal 169659 zcmZs>19)Xk(>5C0nb>xAc5K_WZDTTVCbn&3V%xTDW8#@OIeEVKKj(bsc~4(^@9tHr zyX&s1yXsoIuSKCKD$W38WI?3ZKbToSgadLCGZ8x&TNCs00%Wc1&5WF_ewdjO0|Bzc zKz1&6HZFhyF*6fDjF^j!lZ_1^Ps|EX{pSud8#6$XSm#U3PRz`~tjEufXl8HvwGkrm zzZxRkcV{#6|Ix(4f(Xa-e;SaT_Kn#D;FyV>%a7}0a@Aq zjgO6mg_Y~y^Vpa<*#0f!U}pcfUUqgi_J6NsXXoJfw{7g~oE-o5Gdl+p=fAOVuyeBg z8}rw0Y|Q_{!odM#`}ckvUq1LZW-d0S|H910#?1cjwOnkh?Elum#m4bpwtdOC{*C#I zq`?1P%gOTZm@_f`!`uIdYp%{lR<>r&h;Uy?pz_6kVm2T^(b>%Xe~8Ws1SmT=xDo@u zoJ*_>kg_*-AO?N~_@A+;4zC!HosET+okNIOOjJmmRhWrcoK1w2nNysJNn8X7vRVqq2I5)&6?VqpOav$BedaB#8k|C2m$F0Mw-uK&ptCPX+23NZz7 zM7aN*N{Dc5U!nXbSN};>GkXhH%P&kofVh>dtC=%E+}6m|Ow`Q8!PE>OMa&H31gH@I zqn_Wz)!EF*?kfw|jSUSAzrG(sz2m)kM191g{vd&ZKz1lhs2FH^1o$=Fq-g`c-riXZ zCI6zJfLoyk!PAF9*eNj71>+4gJOL0KWISwaPHw?GA;sE4@P5z)L`M;S|HOcDE3&v0 zaAS3xUzSY2Sc>2p@tD4lj~dN(`zH282C?jYV>7cIF^v zdKWdL)$!UCrI-NJeH17oC`2eaC^;wwDAXY2G|G)Y3LNZd5D07#dOgPPh;U!^<^S07 ze=5!YMC3pIkTY{NGBt8F`ij{9L`Kob!pwyj_{G7mFsXVvngK+AslwPxnPWVr9KA61jdwh?of=XJ%?;^k3?f&0HMZoK4JJzM?Ds zrR*z&|E&Asp@WHvnX3-qt8fEU&Az*SvE@G&{bS?*GUuP^|8a&gCo%JXP%8tOh*|!_ zRpl?cSpT!7GLV({pY$YF{$I=g0sH^q77Hf}JNy41yZ*yHATirlF<}2+{L1>(3G1!8 zw8rT@-RAN4_q43}&Z89Nn5?=a_UIHGi6E&>UZ& zAqd@RWwSlxPKBBcMRQqeQ88u}T)Ov68;h;atMAU^=lh4teb)Q7%T-m?KF_WL_8@*wTwEC};h$I6?boQvejsk2{h8{&rYBp# zNGNT_=DB{Ky<`gX7DRD0)m$kWU9B*Ekg~Qr*!NiJw||mpd$`f-b(89Sn!^9S)?}|a zm>hjIV!+kx5eKwmk<39Hg4MD-lHmyt-f#0xCr1PJLN1vqhofaI5+pNHL!k5r5!9*21HzhRSLN5egF(;LS2W z;NS`xE&B8Kakt7doC}JpvcFLjAzDt{pkh-Y9mTCic~=1xQxCUq=1l1_yN{6YRrmU?TWV!Mt3DbCCRVCa4uy3O|)>1 zd=aVZVm4GW79QJ|lU0}P4W*GkxSIm?4wo#zO;nLDBlt=v7My)s!eZ7#GeG9XC7F5mZ0Ndb$zvxA*P+^qYMz!xMyW_!?P6 zF>Odg2;zVN0&*e#A_CoJw0P6mOTQ_aDhQ0G~jKV{2fN3 z;kGHixr|uBo^xvgDwmNyQAPkJ7^E-KYB%!LqtyfL4+1<#l#@P!F60wG1@U-X&KzQ@ zF{(*Qb3894R|{+6KW^v!jvNUfsnL+UzeH!iFh63VYeQ^1VE`k3!O0F(Gc492Cf>5J zDr2%{+Gz}v?~~VQI}H=7K9>>&Ka@HwbBp-gT+XxiLiTt-u&~38^hlB-Bj#XsbDw+V zB8_|q9O*?a=Bmo@w&35KiOz*yce`T?SLVD7(a@1vPs<$B#RZ@L_LgB}l3 zZz`YM-e^8@2nXRM(vlM3l;zGx!RldSUdL$e__-!l)43+aOW@n9j-!}6#h0UB0U*qJ-*6ZD# z&N1CF5-sfq64!H zL3d0>F|!6bC$5BZf&6z0-bmLVRk!SfGcRK^k~rJYxE?S(bHrDo1W%xY2PRK5oZ(Eq z8J=(o#L{`{fn_%^Ou`NmXqr(=Ctc5&E zB;0Vkt&l^b@{PW&@H3EI0;msELQ-anx%-=W?( zT;bh+nq~_crTpETS`IX~27mX$!go=kTO<^F3`dUm@W-u#C0Wj1ht&N5zTm88_4L1~ ze+&IHB^uk%R%^{+c`VO)Ft^A#IN(I}10B5)beR|Gurr(hI>Te+hO~76uTNYKB=d>8 z-RVh46|pgs*ZcKG&vNv*y{-05rOIr#bRQ``*n)rivEJPYlrUwhEYrz zzrDv@0#3hZ<+^pFGQdbL0Uw&`f9wPLJ3dVC(Uqjs68VO4zp_N`h;BG4CYBa}$5qf+ z)LK?cj5#$k5q)SHD$?h_bMmKEPd;?ZyeUm?n7&JX!fKJWSeP+UdXO}Q1p8?D<$QfJ z+)yVF@ntxAqR`ENhqcjQX*R`CL}jbV1nr95DD8DUo;ND%(}C>yLGt5Haey1LFW!~j&FYJ}}eLt=TSWBA?x?3ft`%3dt z@6iv8J8OeKyq@}u=gD+=W&XbBxmSC} zbO%_2_iJ{bTi)R+`BC_Wyty<=|MwKY=#T2dEE z=GH5hP2r@MmV!M~UxN~uvQls<4TkAT=WWZc}IN zcvH=PNceHBq~h4uUG|k@jc|XTwJ*9nKd=+s+}?)`V}%5bzKY_mb^f}K5 z*xF$lT5;T(H21Lc(1B_}RH-R1ewEO_nn-eN2S>><1otohK~%eam_F4A`XL&?ZSXtV z?m%$SFdEj!jm3nF;S8+~*kA1L=g{hHrfsD@Z&L?a*Zb*`h(^OyI~%y=23u{X%WW6$ z#rr9sAdQq;XaT#HyukdJL>;TEL*yp+o^eFefuqTUM~p;nN{-&voOi(;j!4PN9yPNbgI`Zy0yjNhz{?>Rm(1<*2Uj>)UHqHkj~uj z3^V9|#h{Y;3PZVMr^e9bduqeK5A{yph_)_`XEh{8XSgFs`x2&#?ZDGdwn*_%FZ@$6 zH*rwXGEv`pz*0V;Xrooe4q|=P6%WujN3`^9NhP!97*wcM`wjvcgj7|b0&{A2HW;Iv zn5t3t-YdB|tYfalP)H*nR}KZbZq@b1VcUQ8r_dpF2Df+Mb7N0)bDV-O;TYCkx1;+W z>iV2T6V^w_bJ8WW$2ufp>1z~w{z+nYMTKm>t7-deZlcEbcI9dBzz-zBG=;PUL)_qo zmx1Tt6I!)d|MXlk#P76>ivw>s6d*AB>9H^Gef?V_=`DGmh{tX>aHm!^kL8WQj(t1K zp(M+W0USO|3of+=RScrZ6X{;NPzr)S;0!@_@j)U}m=*G)K{h~;Kx!qy%i)RPW+ipf zd?xudPY5{;z^%R+()6-}V9J^01pggkHOn!_4Dj>-dWd|t^M7MJP8I$jKU5#}gZzyG z0gM&NKJH-oBSBpHj%=|`6xfb>m!1A5WZ5FrEdsNlHwm8pLTg^^xE&$8JwSi$(%vdf z_0R!o41$n!6*~X!-~O5(LOisa!-#5r9^8p?mpRXsXCsn3LN#kC(le&K3QoNRQnmw< zw(<4x*F4qsvzmN)NaHoT1Bfo(jmjl8{ z(YOP8=I&3ZZDJ3~Yd%oX%pCdB&uCZ=`EKTIGz7dE2I{)|_6#Yt{+5=bERBL`<4&|W zUG)^c?(|JhXr8`k;hyJ;($+0EKhARlfiM#~ho*)q12s(N^7$ycpk{&HA{XmiZ;H1y zWv|B*v;75i5yKK(CKcgN;U-HMG2m~z@{5yjj`AYTZ46ufIAzGR^OqE*HeA3Kdx#TI zsU* zNwLj%g*wq3*&-vESs*f3Y{(g`gQ{{9K^Z(s(Z`pZnYN~COL7Fl4blu=>wlm%du8qm z#ROjlgjc*}v6P4-Epq}X&Eo}WgR#cNE)8(PwOkUcgwjSWYAl7#L(C&vpzGdrIm74v z!2b;jBUFQ{z2v_EDmgQU*89DzJg+1$15P}f6w4?WzsTO75=7h*4+Nw-;6d4deqjfS z81rQY)`aoT?Srm!yaRIf=y160W@2=Ug$cjDlGdmf$=sQ1gLea1Lx02HS{WZ1aG3#_ z$J*%bVL_8tCuE(yN*L83y1%tb2COKE5|6cvxpcd59e-;#DDl%Az5B;tFMq+xP}yen zMuE)#c@#4a7QRB9eKX7*(&iLa;flcb-$;i%v-e*BL2wqrg)9TngzHTJk82-wnSH@; zB9%HG@0z*EWO=(}QD1Bg2~ljHCA*&YMz zY(@fZPGE+0nn;XRwP?AMLNNa!jkWuKRVA} zZ!54yDzETs;DiE#NCH*%UV|40=xEhuG%9fE)Yg(|TQgui<07zwRAp7(n&RZq=5_fe z3SZ_5UrHtZAjh5qV=ER4aewEZtO>cRk;_P8um+=KmK+4Lj?(E?tmszYFfPHQRwxI1 z7^M-Y!IrB?+OZDp@Yj^j5w8K?7%Bqj_PW0}!(TSW?R^a>Ov}5UG)F^T_B)7Q%K;xU zEAUSe^l7YbKDnP!mGk~H2R~AlKhwuP11?BbU4%{zkc~>=uf?43{olsApQ>En&>cSp z6hATUq|cs4NTQ0L?R5c-0x4YAbKRS3Oc!K6Z8nC>p-RTaaU%v9u~lRLTP)_~Nb z=pDhYhGqnv>H6^RQ4)+&>GsEX_ZQev6CYatLdC2R)+b5*`)nUv8J3Hj<@8SH8@0{( zf@JgJ-uCeVwz=b4_5r!__}it+C8(fs#*LXH96VIF=aImr>s(>~%%>W?O^U`9e?|_? zdv*z4QodI+5V;NMkkOIv1pUY3Qy!LN7f;T~k3o)wKZ+pdKGixd26+>L9DM`|p;sxJ zz-riApXzo&G!YJ>(6R4rm76V-YEV;TiLKp!xs|=SMKa-iY<~%yk9wnoa%+>U$YK)E z$ouG?b;sbwY{y*3+!B-$NTqTH8Jr|96X?t3$EB8(i&YturH7Q&rHdpplJN<5$rc4B z(BSPe(u!&5lDLFb65LN=QqbbEgL15h5mhQ2g;)G>OVlaEMR5}n_Qt~F<3oZP&t8u8 zqps}&v;%EHADyjPn5ga6O$&w2P=lOY7x>sSYIa-|WZ>;3v(kRzns=b@C`Mvg~*|VfM))%vH8)p z{g9XH#76*ed0)?DDfFW4n+8_BB+7y4olwYf#l8`FG0vz2l!$7Q>B<(0_77dU zDmoB@h&Y40N?wP7AeKPv#+)1{h-a|v_v?w#+^`5XTMqvek#0r&EDgBGnSMq33{Eh(k>tYwS**4r$U9ab^eqF@G%CARrmzr;CO@gYlhwq{!(4LkJp4t^r zx+B;^oZ_C70xbk)sA&w4q7TvrYQm6$9e1?%v{qP>RKJxM>D zp4=<<9rDfECWuQz7|E}(-T27)MTDu(+5f>cJ~{sUSQ?N4zRd_V!;5?d>J1_Wq5>j% z+C%&f-fIB*0oz-!LGn(~iw^SM7(8ZjXFbKSJd2}4s(O}|-v6N~wKqzB`1^k0IVt_D z(_NW6Rs%DGNbb!66MTAq*xSVE_iKNL*Nxh&V;^Vm=ji8dX*7EvlAFZbhdOUF$BDF>KB;gUTJu(-URET? zV6bXvF>Aq?#@kYAHGYt=FIL8wiyZl;ZoZLBn?Qz1bqlf0Gn~U_9+hq6a({2E1j|@| z66Qi?@{r7|)h93N9yq4Jyuv3?KRq&gH9Iat zE_*I3F1zOrG5fkG=--}RJr?J(wXBKLE%NxhJJO#iP9llcCrjS^@jL>OpWVR*k%}79(^Byhr?Mr$kAVLMagH&F5(kMFm`_ZzHwz<;FOo7QHTnX5 zV(0e_%eTjVg*?{nEo5=NH|V*ick6mznb+Gzeu|@%{Ea;ioQy{ZcBnoOpJCNJ7HAG64#I?%{P-%kR0x zF~6z}zBv;sO+ZHG0@G*rBExm@w&Y$Wc$2}wP)&F0>9&l<4gCC|YcCvSVa<~lf(nOK zHGr>x-~M+E5ASo)pPqC6x^5jR0utO}!g89H7`T)u>MFVn`YC5eea0NMbhTu)Y@3NH z0y{iCo-y`v_Y^zz-?;bAuXpEc2hC~MjSdyt-1eoOq3;3b*#|jn*G<>u+ZvzZH_@n9 z7w44|tNpM;ZpFXY(C&C-@h=iY==HTn$H{(GlKORF@oo-uDrjuB>IcrsFL{L+uXyEW z7hkKXwo(lef8%Eh$gZ^-FK7aj-rt;^oqf(1Qg!-xQ+z{^jHe+J7xpcup8eIp78qce z`dyTshCt~@xun^Mq>O57AW0dFnUU)m%(|b{?x|3yX|>6qpUKoVSPxx~C@*PC$@s-s zWxI*7lG8v&2ybbFuk2q-yIV5G=y zjv=#|!$nbN%`lQUlGGViQ`S>2ww8-D#_COv#30=!EErCUD>DN-Bv~M)5h`}KL>G_J zblR1I>S}RDi2L^_H$z$u2)*GVg^aL>MD^&^s`G?&Xs#uoNiZ4_T-r& z?vkIMlam4PR=!E4D`p`xaX?}!gpA3FxKp{6KxLF!a`b(*pfOU26vSpRP~3?ji?(#^ zg<)4FzDW==^O(Jp(M(%3z;8YV%c}ct`L_{I=J9!V@W!Z7K50=>I2ku91zvs`j6X1| zgNKoG&5$B7Ns*rC=DOX>@e1bn<3|NqlE*U!arLPh3W$lwy=xg((eYvGg&6GAXM|)p8!`w#bwo zwN6hOHV-pRo>r^O(4+(gAAjpnleYHv^hKii&FJq$%l3n`otDKJoQ3bCL5iNf3UhVZ zC3hqqmBy7Xo7-;YVm>s#*O@_iLl<%*U?X;7n!ld+7>AGI5B2ORek;FmZyGA!sKxCu zyGyKR?<6UU17+oGc32tRpC@r$*ll^_yTBch31#Y6|6T!N#BNlae8@cqPqt;tuqeZL z*$Q$5?ubvwfeX)U?W(;d3gDFZl)GGP$dab4L^x6I7%>N0?kHjoD!sRut_)-ef)B@c zR6ne6Q`T61#iA)@TsbI(F>GaFRKe>{e8TIw5eLcm=6LZoazjMbx*ngm{$n$;Y;qLh zn82pPgIAYLd90%W-PREw$5{E!xE?uU^`!L4zjH(8glO<`tY7E9I%uhjGCA>Ko{xVn zWzYVUq#qB>W2|GeOJKy76U|>~Tx#?%{@8lpxeqNto&vujS|gH!0(Y;)jGrVZ<0uXilgvu(u4_k_?(QQ8O50n2?axrPGRs=RkT`kpL2JwZyvEBH%6VD6S64%sFaPJ2!Ha7EEP7;PXU zlt#D%aTH*MtrVp9CsyH@AVv3SAS!z=Gu@m(T1+0RGf%FNpy;WH*6vSMpSlEM`WjLv z%NmT8&V@lV_OfR-+da%q;#an}x()kkkV>Yb58*6{Ss;tNxn~Ph=XT8$#vR@Nj@ov&Ry~>C3f}e{qNzsFnc?}^+~@uwx+R+O_Fyzl5AX!A6$CRqUG^M0ElWy zihqpLW%xsxb_jy!nfeKbCrfn_tlziajsES-;Z1=44Q(OC-rq$vX3?1i80H(IijV@H zb^${@-<|m8bRx?7xxCT^!Q7y9cxDz35e6~yevtm0poP+bcH8ZR-m=BABqtPc5bMMG)^&oJT)wjn8X_~YfGPc6lu~>Cv%jy9ujFmT9T!+M>V?2ya+3A zSf1zNFE1XTnG+QccEM;#)F%M7cdx`%l$1nzp`Db6vJKB8wxj8HeDLK{6*9ebmgi@6pvVPU3%?$^^P#jDhVf7}MKmHA!Jc&K zn}r7}<7#W_xg&?<1!`V3e)%lXbFES^TbcTh4YvMIm!wr<(BMd%bjc{KV&P!T;s^{n zHDWb)eX4kKDRO0+0qH?$8t3xbb8O#l`&^LQQ!4ZrSo(wv1G+_3N`|R>+pje~CCuM2}3%aF4xDUXB_lX4+-?9qh4aBsPz~SL< z$7btWn`P->CXe4>GGUciaS<&W&2~XN7zdzomrMU7?UIf%xg5^s}lB=P-vU%$hKE){iRAPHRJ0B&4v1U7+N@gfGU*AfJ{lvFPm@YGj!H!8L@6)L1Uo{ zT;6)OZ;|l(#u}bJcki$Ah9&y3e@l$n_>65jV1n!}^@Ez|;MzadC+)H6ISd)%a6|t+>5y8c8WsWN{r#K4p;12=Y_KJ2^Jl zNdMf^*nFyJu^*G(%XA@%r&_1m{P(Igc>LuK`mSzD`Ha3?wx1w zDkUWtoRHt)IyiIoz*Qr99eW-elqvr#N|qh_U0MENDzt@3$21?FXL4Mg3_qM2Zs2$? z6dPGv(Mox20mJgMOe9luD!>RoNuc2%rZh+Ma_1wmV_UoSqpD-wpcC1~SCjW4#oks= z={>4ShaJKq3=>K5Z_DAppoK?P-}JttJg-_m&0ivfi@vHN`zda zzy9B-XJsT%cz9=PTB1>5JANzHO4fyq#jBC%FO{4tbp;qu5$z(6`ok$kU|^Sj#}E;v z|DM!yScNcVjNQ*niz?78`hZ0rBKwAgV4E|DOmMDb7%WD^Ej>*d;@wAwI#I{FG5EKZ z^e^Ncm$LbdeBn4tU^~A8gJlq2RMGpw)Hz~}X_`i}aHFty=qVB~(@3{AZUQ8BH{j>% zIVgub+6&*a3GH?Ok>u7APNw!DiX6cQ-0}VHS^6?@t^TnRT>xo;b8*42I^og{SJGw3L zI^-59&Jwmuy5w3IY%-mwIz)c-xQAY$9&GQr zA;i*uTat{Q$2ATPVu9^$)l8CL=^9s}0qd`c z({$gF+io*-cZO|dE8ml5j+I70?%L}|0%A1Bc6~+NcO%w6Vp}=QIz(DLCc0~+vqCEY zjVuv+y5Ox2oCJ@2RG#Sz$88zEHXzXU zvJ^y&!>jsLz?CRDvih7X@>1bi9-&?0rSeMLd=>oXX%>I`7`C%WPw^$=7z3bGVfzD| zN`;V_?yS8&VUm3N=x_?<#Kx2n=1Rs+w{7^~&eaop=Gqoh0P#|cj$MZCTk<&0={N77~x z5m9F`-P|SS6g2NM>eS6s|7lI6EBv{d0`CCq05mrY9p(6 z451XB6gEJcDa%EnSmR3!OGgyeMQEDXs@ry5GOiIG5niCPYbjQ!mg7v1hVe3D+ARLy z@@dLSL>V4{aN#%yLS%#@jbG3sfR$uSZg_h)gB1{dn@oPlaW{+x=V6C#%Z$oB8BTaA z84%je#+#sM8wrCG6UvS~edLwq_$zcOfW>~t!&6=>K?Cq1g087yYuK@*73r5RJeya? zp$4rSV^muQgKHQMFjWr+r;~GrPFW`rvPy^cgbqI&MA3?Am44Mf9%(%NiB6rO%OG82 zCId$~{GMqslZH3*c(~Zz`S|$zfVSpSteAvMC++h&$H2WBr@?9DP}4Ac%Yezu`=myL z15oYveJ@dGMngQft4ccJ`mbs>xrQsCLRjTC_gTzqZhPE;7KdrUecHH|L#t#>1BW6_ zWUt}0ay;N{XQh5h&I{2iy0oO>it^FzYOG=M7jzqNFgp5Dm^GH((N_EtcQKk#mAPwv zyrQCjc9F9!uOi{=%}#9>T)IdY9Xk=Jl896%lbf{QGF%Oj-;T*8jA0eze@%KfF-=W| z39}q+${VJWOsfxMDBPZhitonYSK}ce7fR^PooRo~wAlgi987GN&&3=)BX`kBk`qh>NISO{Xtfp3rHf$7d&JkqF5rUi)?^v-LoazHjCib#6Lb$@a63^`3!m?+74k5Z&*6aHtBM z^8D($636S_fl$xa#|{3(v(3oZVxg?A?MTm~Lt>c)P{IwZ{<_unxaZ{aTKgD(tvn>) zowI(21~rlWqGSD8`cy|$`>iMDwtI1pEK~)VkE`1G@XvcBJL3za{wh~-^IvnHg9wcl z4h>dzqHd$d%?hdh*8#~SkZ5BGM&m1r!0jcY)I?4Km;$InN24%;dVSN6Kv@tp5UzWy zZE^~Cs>1m7Xr#k)5I$+96zi~WVsvF|ey@ugbJR!3v+jPcP!bCQ_5;Tn`ghVKEQ-PnADS+8aT0gIodBM#OQe#_s%h5-Da$Js z7@SYyQh>VEH^*D%sqbqrbGxsPRuhi>{ZSz1AydNF*4 z>=1(#w?g_fN32nOmPyiP%3f%ngA=TdNNa`1O;TtV4z9))3El&hTb=DvKJrs#xz2zq zOxx%oIA)vX`MAuhTP5|-2VS2W^wL;)tD>$pHN+6}2Fn3DRF-`xpvS&nNoE^j%^-!- z6T0v<-E}Jc&$JD)8@8>iVg(OJRQc;gxGVoarWu6yd#LNOwQ{QkdNGrmT%V_(^~*FO z2KpM9-Ou+9H#XNCA-YOZ#CgCG-?42+qmz^i(EyOl>#^)$wLyUgV6=ZHOkJ+X=7}gO zYl7{r3Co=9iF)HuThl4Yg-QPV@_Rm@${@Hqj8>wcDW6RY8H-=Fapco>4tg0`m?-GT z)-%C-u0~5yTfVLTilKz-Q{!iOYuMwVu(1>7*E=vwf zBcN&|BiMuNHYp3I93hBxZ~fYzPy0BnYs@T-KP|ZilNAP7-tCSEj`WWBj+AXCwO50B zQ?%cwYbnMfU=LWi@FJU^i2nL%k~^i|AITlLjN+HbEmGPiHV&zWr|P6`aA(oIO^DbG zc!XUyZk=taFRFcrKNOy>eB{2RV3rS?C3<#dO_)DCMZE1!92O*mP0W06kT}K!K5sip zg-@mtu%}0n3&?Vrd7(hlY^0{bXkkpXztGV}S~c~w%a1 zg01&0rJQ~b``-8Wp%$EeU|zgUS|>{L(i|8xcYPC}Tc@v3azx99n^B<}_ah*c4L`la zX`#YgL+cs-iQrJ^_i9wo$XmRm_dfB>^w-f#QBz{Kv~usEj}>}-AEx4n(|G;_6eN^R z3KA9w#0tp)z;Yo6%!eN&q?lRz5pC0|rH&Q7sWth5=M_4eWE(K zTy65T)H76H^XbWYxSMN}qvJ;I=6pZ0Gs& zM5NnLFL@YO(q@Qu-sVEoe)3#@H;K0KJ>RTb3?SPIbsTc=ZDWwIn5d@}jZ_h%Lbj9Z z^5RZ^arZh|(1OnWI6EEUxLq_ki29)u^%B5eo8aoO3^NB9XrZ=+8_C`T-}K6|#AuWw&Dw$0h>QiW zMg)u3C9_9(cy6$;=GAkO7olVWBE119M-ijRdT79orE;KSz^^Zl+zCGzNm7`??7-o<&6{h4C+<^aF_XqxU6@Je%s zg3EVuGuwEX`Wv#e>gTfYPUX9vLKiIn-8>sH7qzfDj?q8wxPy2u@BME{b;mVsDBv$! zR*Ay-Oty)5F!8A4$!Nh{U!@;|6|@=- zQN%)68r~a}(~g)U#akp^2fHD(V0|0RCGB)P3MgpJ*HFUua9!zavm&B1l+*AsOjl1fS(vG@5mK= zDXm3_?A2)+V);8L`pAqCw}V>k@Hvt$0fpDQnUXh8$$0thr zJ+X_^%{+Io9x!ivM;m|+cz;2pFd`S}%9r7ai|bxr#_7|RW+pb~zkP1hqHI6YH*Fnf z)GHu*IH3Aqt5U*%*;TZg>QQxuS%MFV87_gEqHTju3w#b8x2Vc)feHKTHZZR$b?_u; z{Q?#%W`P6&w`r43aprvfuEk&^UE^eEmjh{|5~cH8?%d3nt0}z9v^SX*+$!@t-#ouG zkK__+<~Hqq?=I7yRZD$WQ28wrBdU#cXI*t&=?BLvK9Ax!Z8{GIm2|q3a$e+fu0BC= zMvZ2zzDt+nb*Afvn`oiU zB5DN>$9ag`ubAS+*#I!U`_4SU#6xI(l2{JNI?7WxG{>OnTl_BBxWf0omxQ)09PI#M z2(CzR2xVAR9x~fiC0eIcdNpww%nmX%d0d##dJ!%X@m~-Uq6c#^{q|U;$)bmzl1D#- zTq-3A-vgcXjGx5{y0KuiXPXi*UbomMx zx2Wwc!%fP|n^Gz%5^#9)2u&jfHZ-;u*%^Zw3AqixlvMo{3fh^&eo?29m#q358 z4}gi%z&>qKcSe!o25|;00C|>#El0=$BSr$27_;8J-b*BUcVy*7l%Z&KBZ3}r?7+ar zC?~q^|Av|R#OG2%iCle}j;Z4_QHUnMo;V-5s=qImQzY+of{R_bs9)pTHcn;OIjC}5 z8~)xoXqM>Z{Udei_%>i~^!`a&w|S0`$gub1abq}&uu5@M%2z*U%Rce^LBHSY)(TMK zMNP0xcujNduW>1d#^G=@+#JmZOmT`GGO+>QPAJ)LHdgMetbR9fF(viz#qqI9yU?Yi z2H*R$Cz}K%p^c$?C%xb`$hzB3x&ejkJnN?$Qr7tAS3ta?5>x+LS>ozgc2Bx)+w_y>r7Es)nlyhmEMGa{n7IGKD zWEC$xd}`#UJ{1%8!FfR}-`?z@MV9LEw5XofqsFdW)}Qg}M^1$B@uyFe{CRTKR$NqW z2v)4FlcY)2)cjE~M0XMAE(KjQS^I6INN%2;hDGLw@DJ&6NiA+!TE{$AuD5~v2VLr- z@1eUOjU7C^dO4uT==ZFi>%5b&Gc?HgqUjJxD2uExJ}322)tKL0GvHVe-vHmcL}BY+ zb`+r{F%)rI#dGKHhF*i~cUKVn#w|fb_#Y?)D%3+Q&MeI0+e(lYD3AE3!u=&JhU-9x zh}Erdm5@Ni#2d0%v|%Xg==mdA&GvqglL=VDR+=JtIX_YDb>};Nct#*=@A7@4a<7ra zOuU=7o8OuTSDte^vpQokj5eKpz{sV@8>8Nx!R18M|MVA#BZqv?2{4$GyppZlO=@%x zd`#<`+cmVY5aWH{9-!EXZ&*K+uAJwGqdQ~|Hv0y~gNgNk@1s$s;s@!nPZw*)JQK^Z z>LVkV*Y+}oA)sS?d)OW+OxeRgyQ}gIEsoRmKm@S8fD5Q?b*=_fWsG08N2vf#E0IA; zm&p65R>}=j6DeREMCr!3|5U7IBs3L|97(9nXQC|EH9hwR7MtRxOSF%w`|@~(U2E{w z@N2s^zVIy(!K-mYnlFmViUxb+PX%|(`fe8bmMT^VK48ek&r`TmI4gokm|@h5uWg++ z?IX{%4B@8t7liGhDGzGg$~Af2qMIW7h2bYqRcwnB6{DlQu?Ip}V*h*K4jF!K=Zyi;UD9i8%i z{8Xm2=VFMt7=r?N196nTlf+}^;W4ctQne-cN4+#~MVoXwhtTIEjNG2Ga_Lp=5 z(eq}R_)QsWAj2#Srtkrzi9#FDqe2XrL33UZ>jDp;l(gHvtd6yC1?g43{$ zuGQ6vdRmWb9-~*$=9{D2Z!E~nvl8sXbOvDUtcLplGscT9R6oID+pqTYRI$iA+CnwY zC0iRAo1pG=QUDvC8iuonx|Wgi_gxf?VV84egyw1my^y?Og|h6^1Iyo{0Mpc#BAt1K zEGKg+hWB&0k5ARJ^?6juRc*}m#h`9m4y;^*#|s>hi}A<@igH~c)4NdpPH8r^BMBG1 z<6p^~UQrCCv%x)61TBt%x5Qkj^S^9BEd)&2p(Ag{R0r6$^H#E!FW)v*JA7e}tC4x+ z_-`1aG2FBy1kdaHas?2SPsCxjhe?n+;_>dcaZEwmf?Yd^oCOZ}_tlLZ&~_%U%1=_{ z$v8M+Pk#&_u*K9`Nq8MG;+@>K={?Zk#$rDN>rJ3`#4;(PbWo5>>F*T|e}20eH+2qB zI~15IS zQYpK`v*N<%MbiTYA%va3WQLnl7T!MR(Vs8Gw@6ak10&rln8h@F4d5Jp&BgswT!yUt zm1$ih{uZzj!>{vaHD;_vQj^-E3Tv`8Ic!X#8;wUtTg*%GLi0`0HRcEL!_ha*ADPeM zugxlz8Ou%LSY3=MHJ8T5ni*p(WDdp{u~`%|nV1O5hT14pZYndESW03Qg^h&^(OR_1 zyvDL3){VBBH^m-855}HBdt*I?iNd!`ubWR4er)>Ce5!EJ^p*K5%Ru4x=qJ;^Vu5kE z-c%QziCaw5ql-+dEw7nhjlFMvKlYjVvzR))3+Z;*tR8Q^phdt>l6rjUeMyg?L8zNf zAGew<2wTi%sy@cVqFFJsDHb(HaTL~WvRW)AB9lrHip4@&1I(K@Tr5QGE*$8Ed6q;04*2{ zm`9MyYo(Gp=onw+5nR=cnYy9#wm?%X6^>2!8?)36Q*aml2A{!Q(HVZDJ#IuV=U zGY);nuDrNvgDWQxD0VMnR?Q4MLV*i^Vuk9(?#mtB7w!T(H~iV~R}hg+Kq34R-_WhY zx@{N}zOiH*!8!-QA(E#bsb8(%NluetBGG%jI*xj{UJvzfy$q$RFN@OEr_*UMAzqy~ zOQ-XKg#L=xg!W^(OooZgD%HstfgVcT6s^|H#Wgv}~$SGKU5 zTv5VjV>kWZ4g=XFTc1TQVeoijUVOp}(SYFn3n7@724iv|F0h2#e|1S}(_Y5qeJW^x z^5?=!muXrL4sOo8IS65MnLuI*{n!DuQuQ2`=`6ZzT!G4TjcB}X7MiJBiWceC>K?(* z;A8lp?oIp?*8QDe8hN!Kh^;%T=|{$7`00M9u7c1lbI|4xLY_SYOvT&FXt6Jo*@Wzn zr3`#jTKs_5=*o0PT^ZpF0G2WceLm<@l)+_ArL!LnW|a|Mdr9YC-g>57g<2V4s^V+B zO5eY8nXn~e!yU|M$}#u@%1i!>x7mV?z*v-#MvWfj7$ur;QNpM%vC4(5Y|X{rTxOgD zwYhp3B0?;`TKKBWhI;ve2X#+No{>MpvA5tglFfLFgsqmU!iX`1#WHi8{yP+c7>=PI zYw(PSsdrHNS}RK24&Ff=+Bp3eDkS|m%gDW#5Ve^gf*xS zs+HP2WW(k>oF##hQ3NGUuFAs}0*Ov)$U`R9kcX~DR^(O?V6ZG&4tZ!gqLl7;YK0Fa zbXqPHB!gIrZ%?gFeVsa+y8Ywh|2lN@)_ZU2KmOy^n<403ntC_&W@;h67sqk+TfOz0 zpH97ydcJ=P&cT)VhJ9P;-Y$Le6cJ*UT)g@S%7WZIPqshVKk|z$Auc~0EDMx{MulVfGeb9qI`X^n6|W&|wP)KK?0>ZU$tHR_jNkBo zX!^+iVd#VK*M6~`_c_8+HC3fv?6OHbK2Wp^d_IXGCu}qth*Tog zAuDH%S$S)RRb;Kt&+G@Ie9Y%3^2zS}6Zxm|nfzQV7)UIbLM#|a?A53RY0K2#r0DmG;o6Y@r`1=PWLDvp$lPQ9|T3xuiP!e%cwX;{)2`U zp1558GIg128X%9{;9y$j0Im-t28UN$Ze{cWO?+TVxmP~dmd~nPwz%uJUu53)&eijPW-VU9u0{Zc9QU+4=!ESfBps+fp3?$Sr~ zqj&}VKvqCIFAKT@_Mk#3 zR}!%~;P(Z5MC>wn^RPo^1>w;^64XM~ljY2VyRs=ElSwUVV;=VDAQ8R_xb$H_4*e1- z^Wvk3dZ9tTKa}}qlge5a!k0xY{Yg@gxpV&DgWajuQeVv9K6UM8+>OCy!J9z#)*f1V z_q{hCd|~DS;5SVwf7wa|!U-iA3$JG0u$|Gi%DSy77kzrXN7#NG1 z@lvwXzYeb>%U#RetGufN-FUNmXWl-%FK{^cLf)|7Aa>t@@Alsjdf2}QKS}ob59A%s z`ylrByx}~R4jHkP=)xdn1?BnWvHAWRqw*XnvD>l1Wz%@PC=j+Gh{M$ofz#b1A5U@v ze!rLCEJCn3jN|>F$~7$&jug z_eBPBPQs88!X>zw8O{JPqZ}dPno&?WTqho!?wSxnn1INj0dX}FU1ib#BIrMhun>)I zvJ zlGGin2c10Nu4h0`aubG$yCSaa7EE1WVaS*b)V=+Wf{{Kc2c+i_r=a~p}-g3q4 zmu71f-5yawsg*TC9Ek9ae*fyxJ>U2i(uO~??Zb0iA@O@JOy1gi34Ifd(CqaeB@vBB zuiG(|n!WjsjW+ro^vI`oPP)LpFn;#b?6uZw?bkZ4mq#Ka(UHvQ2KiqgSKv=;1ItF85~4GeZ(Sh=uzVeP`MP2CR0YR$T=!ED^B_s+|f zd&kr<*Y3o<{Jo|7%8!($Gtalbn49iB+3P+}=m}EW=-@u|GNRE=)btD+_S*d&p#68JM{)|}$l(K`lSTAg@ejq*n6(*8YDV#8yunaKy;#N! zk1c)&EvD*dF$pvPk~x$c#l&*#6r{F|&5YGcIaBr^e5)C42T7&5IQ(D+5z=;T2!Tn^M76p{%xiF0Eh|Cp)t3Nfom>p~L~qn`V8oYDJSn zBy~h`bNmwGv?b>_M&hzJ2R_wU!6Zf2d|LdZq5hjpiaiA02Q86;UEvB6}lj;IBh;BVhm9g5m10V=KxM2+&?=BA{E*lm zG=y=H8U>U^e`B3ar!cSih`FEOUy}ndKSgg;26CSBPyG1TZ1@iPQ)x%dbawmWw%S?G0P_J2H!yJQtnFLvY8(gHcJ;d20a!dHbAXq zHdxkh7ClyFdpwJ&We!V{%kmi^j}Sb~g|W5cmyF-z019ikjDUGfIJ?Ow*q+u;#| z4$Q}SA?g5|c4J7HdEtc@z*K9-`5SJ^f`XLnQG&8Vzz0WtkzjP{^e)5c^>Ml0(s~CW%h3ZxHBcNXa-`BVC~h5Jw-H#j8g9+i_Nk!X^(YW`oSmJ&u?-^J0*jXF$;}a(3P(NFpyuWv=23_1yLR_0o;jn{77-ZVc`S-Kbwzx}E*3@R`t^r8~>JJHEi*XT95Xw{~CP z-rzl%FP82pKO#IPK4yI^@JR5{&|~3;OHc4m2v12Z|9#rk3RFZ%K;N|%e@B_joE5q`XgvG3ox6~fW zMmzYrwdKwUQ|i3lU|9^YR;T%9gQ~z=kyWUtRRDVo_k9HLUwGk6j#SXdi=mJpic$#6 zU6F`DaTpO?0e8@qDP@Bh)rPNRApQd#xfc|P& z4cmb2n2oVL+&gcI{`eCnqCrxnUpcNRGpC4>lAC$+j9${T?zVC)3Fe*c2s`HB;{T3} zbJx7$=o9ciUg;xwHqAdw|G`v&aSjmFoymCZjR>stGG0YB)!Lw%u9~4iG!MO})q3*C`kRc7wK$jG z@5<6jqNiFwETZ#aZ|WS3!KrHewhx|RF8T1E*vmfYOC^)Za$Ee9Gd#U(Y;$MIWmg3b z4`nMmXQK2wx0HPu!9lQE#`^R=jMWV$-{dGxme+z9rw?+y-I*jHw~}(ks3M#4_s}WY zFK`0Yz<(rUAJ~lY;TZ&1wmXsCFQ$6YjnoY>iyDQ5BZpisDek(`Z{&=ArXK)fPc&Y= zp1RR_Q`<=Hro#Pg_r)JV4=Inv9&LLx{!ro3(lhaAlFy``?m5(WNqHgog8ou{y8jpI zFZ91yPxgn@lA^0^dLox8mP+R+Wwor&i*=>Txg``<)BE-Qa{sY@_Qe9aws1@7_T26g zyC64c8;mhx+#mPOZ}hJSEJ$;zyND9SOJfhl9xSp=3~XZq{YKWAD$-6WR%C-ocoo3_ z7ZBi81XDe!rbqRK7n%*cgcc84QPfMQ5YtOan^S318x$(24Nl>MTtLTHNf$C02^+n^ zx&^U8i(l1({!|-WwbUK#DYPj{8!EUFDqzZ~5-*8fa_f4j7;{oAS)sOiPY=YR1^j-F zvj|r-P$Ne{2AYn_=t4A%M$mpVjov^fk%Xq`zZ&vFeT}|VXY@|0ZEqXhHbsB`kkS98 z7Gj+m!m1EvVRM5_nz^!|2oX$jG*RmBLZ7*78UGD}!5vG{2k@JLbbS1WMi*>6R6^Od z(tHN%Iv`=yvd$#uYnQ$=@ zG_s0Gm(S;1f-aoBr#J1<+nHq2q69W>M)#mylb7HvrWi^tnf)Q^=*oCJipPoYknB6} zO2B&;#`{N!Uh#{A77D3ELVu)DGs+if7x@RuY~FXXZ+mKc`Yzw@H0QVYIhrbacuz(z z50oty3x0}>hb9SY2|klfWRk^lc`-7|=cA4MrpU(3K=~T(8vdHhHSHtiaWu}|#^071 zZyzsDwtoYCgWg*{68=T_jk10_w~ODEVGvITk*N?yQ+hB;Wr{({R1G6qI2cK!G@lQv zxo!;pydVI2w52n6E2E`+r3_ydGJHCvS)vM}sAx0-s-(}`3U~3g{7}#_WTFYS8G=X? zH4=|KMKsBO*3EPfw)z^b~#X6D2?zKNKhmU>&0`pq&i_I)gW@ zqJz8GrYOiZ*$-0dtP?%a7>FMd3;<{h<%nI(0%Q~;0?GiVft3az zYy-Iv8UX0WZS__HG>C+RyI?N#xBkY||G;~&s&WkdG7#8$LEr4*Q0jvG%rt1Iv!6Y; zwA`Jd7e-2}&p|;X^@Y2-Fs~`D|JcmT>_4~ERn$-SZ0(Fo$z(pCxM+3-`uau1P~K0G znkf_uUPvdR52^;_kmC1yu`5vRk$aSdmgVvt>~8y0B4kpDNpv2y2%RTwWiRH3UDvW> z{D|ug_Evt}^(ghI^q~DYY6?9kP1)VDf}zjCFr3rEL9k7mD7mrxBPxP~C_G9^C>cgY zkgRd1lY*FD9x`Ce5`dE&%LPiVhHJHpaXCA61u35s{Hkkv?5ZK+?O27SdaP8wIYdfO zts-&MGkwaN&C+dV2^Z6`XpYP=1LQz}KS(Jy2;u-6rZjc>{l`r&F{T+YNIhU;H56+z z%>ws-csrdR-(8CtAM9r?n?3L9k5xRWkY(iu+{m}M+53|0E2Y7k&>H+EADR6)J#4v( z;;By=ngPY|C5e9Z$r5W)|Hv-Kr3Li0}A3vnZtb4$J^@vvOU`8S~(U9-du_re=SQ z+Gan_qt$R~HpucR4rpSKwaL)|W%JC^gDHb+GGin2WA$+?C(fc`zd9%KtZSGn-LwkO;(v0aU{i%g;MSM!JLPgkYzFf5# zBEG222!~k{)AaOfx!e)u=SLwdF=%YFhCWlF)iqs6)uZ+C#v|e(iBWUv4r)i`4(cxJ zT{SMOdV7_|c!L!~D=jOzMf#$)mAyt|cUX`dyiT<(Lo1|Z)@8L7-3xk`owLDux%GDO zHt9C2yw-cGmyR~JH0WWWLRI^U*+TUhta{ie8)nF2-IlS|ZN!t+TT`%HPlIqjY-4oN zTyJA-eHysNv)1}*ZHu-|V@ldijn+PiNjN-lxzFgM@nerb*{nhhzqcu7vEgK`#pwbn z3@53I-Day+@r(Zue*tb?)D5=0f$!F*V7&JW? z=Aw1a6uR7q1WWY}-f+})et;k68HGnDc?3l;7R+Dp52oRGbZjgKSqQBvW)Ll`QR_yy?7oAyx9pip|qEa#=?&`f`5t!u35X zZ~KJP|LKn}=va8;`o!+b+S>BH#m;JB{X{l;ZtnKkAKp68&D;BWzO?XeG}PzM57(D& zp(y(F2d9rShb^C@yi@}H%*6c1BNo751#sEowow`hIniuj_5?(?0hqxM=>VSF;CMS6 zZ?kDWils#t=t@qvA>zZ_9x9j=t+7FxCq9P8YdO=&K=Aan+_dr{Mp~>gH8l?`-cSs_ z1U?VWfpa4kODai0o*cJMqXBy1cHTb-+qm=lr(notOC_CzAYjCwhThTU?;SOZCj^b{ zN(z0GJH$Q7|5p@qj0N_gEIurK4PD+v*UQR-_B5Wa8;LaciMi;&f78eKh;;W z4=2C3qM73d@zZ9U<;>8S>3tb%IDK_e-;tn3#;-G0KBY4e9R(yUMENzVEhONrC>zs} z-x>^2VJ@gQi@h{$yr23M26&PuF*Z1e&eov9uw{k;q>~k=(|gth$f0?+-~W$4`}$qq z8hCKMtZSim2XYlEpQvyCr+?a7t7Yi-4*&6|r@lDe+si!pm8AhCJ~ES;`H#-ZOV90p zHt5EDZZU?T<(PZK(4P+oENbx&I`EMMJHi7vZ&DWd;n+xw216@Jiim|V#XsnB)9Y~O zUk?FC33o7<#AEWE8)_UmK>+0_WWPVIlKj4F+6z@G4qwk_-(aCbuC?qM%NlMizcIKm z#9wZ?-ZD;&#|~m;`I!C&^`9288!bWWwRNE_@nLN^biFnf`i%NH*MxIIdkB4#-WPuY zJ&%6C|G@vYa6I&1`YEJw^m28BdRO!=eLQ|L&O3GVozrhnI$olfU{GNS2yhw0#c*sq zMpH2*rjtoSsm;7y8r7_=&P9U7xYt>cHZ#(o^Nq1CoMHriHF zNId5-H9}2L`zffIBEkSoJ$6mt)&M;aK$8I!m_jx~J;@=8Q#ezKvv3RA796HOZ@Ts% zXLM+6bY^tu_$UFZT&{8A#3&)%$JHi^No&HFgs%xRcZU&FvBbF1)6;``NSPo=t|7J^ zEW2r7jXZhCRktWgDN8 z_3e)Qyol2pkI&zF&iP;4eerqSRdnH#-$&f*uOi2uRjE?SbA2?j{Nk^D^MeJ&?fB^z zo<7c6FolXz1$spjwo)aMBa!7a0#t$tUV7&RoOMO9+vaT%h6UgvUCN&MmRd4@W5~mC>o~4d zBvkEa&LnP-x|0KP@!HVP(FWvwV*-b9<1ke^J^jRzCDjt3$ho;KXQqd-r*nsCU9kd*8_paA54t6syoawWP)^C@$F9^lPm;F*7!V zhr0h+bVdQeS<=OaJ=s7^0z8 z-x_8=<)*^SjwVEB1TW@yHYg83IY`sYnDmql3PGq8O;HL=Hhg-T&`RhSPKYd}C~Gk3 zjA%5|Ex(JG(9{vXXE$vCy&*@*vzfw-o|IN76VSZQ`!B4kae4c+vKFMQF$J=kC z84>V=!+5g1OI%DZ5m!go(rd+w=`nh@Yq$SC*Ehv)N>jp<;(qA|^zZ05Y^Nl*aE!-F z>oJ}lg%;i&1U~KOIerK0rpjIq+^S2ht6MxfJ(Hf-J*>wQ{5Pm9arzi$Am9r-U^>5y zrD`4C@r6MIUxfd$;LQZSnD2L+E9n47wa=@L4_+2^{L>4q97pwxTni&PLWfam#PGC8o zlxiCTkjjlY@h8Hv_BIcewLu|;Xp_+~qAXKAJ&?PxVB z2L}gTobT-97c`*-UQaTXGGj=7g|=?pwdwXk)bp?RKKRZb58eOb%r5kZMe$$KwdPiO z-jA=n_L3XjyMKewFW*7@j~?sYnCLM+h2^2u6vfv~zau0cuZhTqDVdx@;Zu!pmP_C(30XuC5pjTlh{)CCHeNNX1RKdX z-u@MluN{s;zQuxGgBAYyqesn%<)AVDF8w~weJN%kv(UEGe>-!#&2m4BN`;*dz5Z~e$aZEdoIXH(u|1`rfd^0%81jFz6D^whuRN4jmsO_RYS&nX$gc z4AyK*&8S{AnRa_qNlz;2&4j45I}t*E6VHc*q&cQX2#JW-Dlh>=vl1KTLquT0nxCiQ zK@WwJ^ViJ0md%{&KX72`41v+PTG4uamnS36#j2dLVY!n}Y$}Q&DQ}uIOgV!@}~eMv(F{U9sgs%D>?3tn8x8gbCif+uOESqR^wlRf=Eh?Xn(=GH4#%pKv3;@UVoa=g4r%cz zF?_6{O)N*tp;G*E0}n0F1L`a%NuEeBT-yY+Q@|Z3gyPh=`$#>w4#VbOE|vUfz(4M% z{m;@rqd1IQtEfJ_OX7I{`RM$7US9QGri}Sr1h4DVDyD2il``5^-cz0|Gi43#KscWL=6;H zg{TX1Yjw0xTO2~`(i=i({f2OF5FZ|#N3HBwuA>#pYh4Dt0BS1FXZu3vywdq0YEAZh zom%8u5HjoEwjvjstB+2x)lLfI0`ikY#ZkiA45_GK7_BKP*qTm0t~TQrTXBgbtrzrk zE*@{{P^J%!{5w-c+N@?k=4R?bX9~8GV!GViExcV@yXolOTZg}wb1iz zl6*8)4vqZeoS|(W|H=o?-@d}?tnpi_xjOPJ-@33mu=3(XmD%@8<=(B&9{g6NdjD_G zdD*)M?>u5yIMEl7EZowO@k8!Z-R;zQma&NTkqbsI`ND?IE=^0GD_#=qh{i9XcU^ze zS2vtHcGKjhb3go4Wn;3On7?yr)$3(3)2Hm1IQ=))=DO%TP2L#pF#vHD$te*=C}|1U z)<}?|238)x2@ULVM8ne@0Hj(9xMdUuQn6|+T|hC`W~0}|$TeaG4X#lDrx%Rk&U?gU zRcPTD?!0TrgejBj6%f|K`X$V2RlFqelEF)wszN|djo7hjT~yi`&a+^}DwRMNB=r=) z^MB_j*;OQewven+ThNg4#E!H`S2;&S19y!H@P-p+Rgq^5W4VFnAS1k zApk3RsmExqNj<|@ZkCgBYP@Hnhuz;Z-E*vm$#H0)XSinshKwGh3tBefoML3d*;dF# z(#zYVY(!Zek7XmNDaK(Gzu>xBd?tW;eStyniga8S2ZefTMkY8VK z&X3Y$&h9|SB5=uIDrE785HAGyFtF#QrHmMcpTX|CPxFFk^`xh&&^zX z)1vhk8jsC>XM?VVAa6uD4=w!CMWyQM+0aGBXd>Z~de$@NnA#)cc=X{FkMYGywb4z_ z%wZ~l89|toYq1k>x5tPjBSsQHVlIslF$W>ET!i#P;?M;xu<7Fc$sssev}-Mjk2}9T z*hIHCTIlx5lLXszFo*b7$F{|GVm92i4dd`Ihd3h160IFBz_oEMEDgSbiTcqY<+Y)v zg~as49K|SsX=V;4K{e|cE@S_x^$J%%o zJl=ao2+kD6MBGmB!A=9%+X+6vlbQIS0pb(NYDnX62LG!JFBGa={4Iz*=*xU(i%m7po$U1wY<%qji?wc z(*Axu5?g5V+gua)QR)=cX5(F|G$A6fPTZ6Wh_}*^8#U%Co6YXGCp05h*NES!tG7C# zp#cpIYa`l(wpTl;S+oQ31K%L%K&G7n9Kfvigej(C&I>iJ&P*1BnjssbrdfDyIqfrW z-PLtw0wE07+4gz!+S~i)ebV32Kf7Q-F(~qpKq%utZp-IjM_+sUyxG`{zP^qDIncKb zee8>Q-7hCbDEjmzvy0Il%N`81S#+dH=dBqRQG#4i_3SB^Hp zGM8%sX6{9-yBzvT0C9elgE!siuGw=3F!?ib1G$OZBaTPHdvlzQH^y^}f=7;36SW}zP*iCgCii0%HMp0)AbDdaHh3Pss?{LAtrDHVOW(bsN%W@AZ>Ddv2>0RFxv z)DqJlJSko$qR|N*$vT2ri%#l{t`qCv)agHCjS*~v2ikK#jlnl3iHJ=PLXHG}lSv^@ z;jgcd?6*e4#Iya}(cnP>ZzskEp>$ny<`p&9oJh*7LlTNOjR_au__uU)sBQV@E6ybbc(R6}@MnXAjxkp6i>{KfLUnM88&we=t-p zi@*qUjGQSXbft??)D#a${hJs^1coBv|3xnVSFt506kBpa5hy8Kpa|u0NE&ugLCz?f zl6-+=hWrqS?9X6nAw|_N?5SNuTIlMgQhuAw^pi2aJtW%f1iYEwJ}z-&!lGPLh?vPu zPfwq9h&B22i9Aan)@hYf5dMF+_(f^LI$?W2zTf$PdVh4X{)8me z{q?{WWs7r5^lD|Bb6fNQT6`yRB1(^opK`p&yePj-zb&6|{y`NQ&W6^A_UMiJVtGuu zP8LdZyP_xcRH@#BdKBKHtV0(lYjrlRY(N|2HKN^Vmi&#`iw@I`Zkw8*O$Gg&{{#vAKAyuNRnC>L>s9Q(09>ua@8PRTp zXeiJTbs;uQ%aWpKQa45UrqH{_O3n6Tt5xDKIe_fn&jncJ^mv~gp7C7QvS7hb{!2E2?+0t^pW>sDx-b=ho0vw;AI$DMUFCqU2) z0d{tqRlUs+K%RFIou<;NgN$19*L8NEm9~J8tbTjBO^Bt?=Pvj}|2ywo+*VHb=g%%k z1v9h1^A}gm78l1oR@tEkJnc@TSU&gR$S)SEHk&(4>pESW_siLTzd2TNNQngUxO^3K z`RuX59t|ZDPOC3=K6CEmlAtpVl;#{PVab@%c+lrt@|6#Z7eu~t+c?BG?Q?`?AVM>c z4aDrGFZ{oVhGA=oP&N>>h%0>R^sk>J-f_#bm^cVf1)Oq0eKyw_zc^&5yq4=cW4<$G zk|SWjo1-M^kGl>`Jm_m=u=JS3;@NW>G5zv&U zCVbPrlRm~rjAe_f&>FqZ&xDI`Wo93>f%&&47x4`e zZF7*=V0}*VX`Sm%Ylk$t*5F15u z__{-I;clV?!=c?Y*-uK8bvwy5oa7o#2xu{{p_iNf&+nPn(A$Y`bn5i43@aR})6M-K zVi*N~sn=iXT(lGfDt*b?bp{+$T8CDz+qQ1!I%eH^Zb^rh%v<@syv2;{C;>+s8p49r z%ryM97}^<$>m%JJsDnM_h>|1ii$qH}W3)E<@a6Hc(y`BfxOCX-^=XKasuN-5XZ|kB7mPEeyh)_sQOs zD+f0=5yyFEt>8N+3w{KOJoC{;1Bfz)-u?C!Yd1beEk6AgwFoaIyp&JB^<+TvYgl98!1mQ_Ji^MY-BO+81v)n(yRK{M%FD9vfZnUdNw0ad~(V94e()-d7EVAIo852 zS=>?9e9|D6J{4yoR@Tvoz8@xLL^VV1&K7fto^m%D>E7Q>cf*)>)rS7W%9YVo1FPuq zRTHadYL&8zUIiiMZf|wf@W#O@dK2bZJGCjamCS>2Hm2ni=;g=Frmqz`34aape-&Y1 zttesYjK<#5+1nB}*`AE261G?fIpj7+a<0xk2H9c6sNS4s+4nyv?oD1otm-`PJ4;8- z4D)j|`j1Gk6*RC_EnHDqe~ahx&#hQC8uQwvu5)JlT=QZ+i4CUL*REPg)1KbNvmGnz zR!c0ux~sOP;O|&5JFn3hAaZV6M(!N_?p8U~zIDruD^{%Qy=C_L^|}`;_&z1>96+BL zDH^q<*4*q0qV;30bO9dgFv9unSzO<$OyXwow%G|6xj2q0dmV8lhxm zA`f?%g-Zn48wZk5gspfukrfC@YSw!s^g!?u^I9_p*!H&};bsV@7c9^zINVEx$;n}I zp)k2bI7_T+St2-RTLN;{6wyfMy=Hzarfm|Ok)=X(q6~yY>>!$1N2eX8#(-j`ZKl1= z5EF8ulMm$0D6vw>tXN87#p)jwjpxu01qg^@8rja0jf+ZNVx1@U?+(%@H_%~TUrq>w zdkTb72!v_~UJ`!cB|}~ThP>Wdl?sz1!(<>#c81A=k_e3!xyS-Bfg`fnTJ`TWwqe<{ zw`R20gc{&~xi(N6u8q_tYL)_v4ALLRTl;I={@Sq`y}yQr@xXMA2@BqAL^cg?*=!`S zyiLeP9LwY3Y$R?P-a69l{pCo@Y&(2X?)B5{l+&{^D`Wq^fSH?vT&Lu z&_ZK#3V|UK)=zA2|EuKh37-$AJ5^>Jd=@bZtwgp(g9oPvS!v%vZIgIrs1*?*zOwMSAu$fkev%wW2 z?1$q5aB>h}D!{r4#JOz>k>C^}zOh6OfG*2MY&J7Ug0Lb0F3gLlmK%1FI_^Oadk=YE zKtB|Zgnub=>hC19R9xiU;JF=rR@^QBGRQ}b&KgUCBPOHhMb8fdv=K$igx1}tWI~G^ zmj72{P-M|DSP!tn>PkKeJ}V{(6G7sS52L{^+zIsF|1*zLkl(<&gmxrI5cVV4iQwQjZPaG|MV zpS5xs#v%*e9=C!tDF%u6;LuIR4;W|MJPd+|b|n>MbwL{(A5C zPknY6VsHO4yPSC%!&;iE(``*y%g!V5_MK8YG~f;ZkBG}p=}gu|Xs}Bs;r2TCHd^u; zp}YE-C|sS%|-KDs4#^vbYcpNCASlV;C>`5cUpN7 z6V}p4qT3Erou@y15&*GN0+=KrYLYas7vCL$TNj~`F5Tn-#Cr96BS?fb9Uqn99BB&q z9r$Lfa5r!RBt};;DI+=){d24t{*wc!{-iVyptY_nQ#LERo$MWXG%w$nw<5ne|8eKX z^VbO5o!j%b2@mpb3x5&q<#`(`gVn36tT7Lj1SXSJU0AI0-_hp6!c{s>rDLnp5o#f= z<}wUhRJst{3C+Vj`87vpM^u`S=wWGG+9xs6J338FctKqsfUwo^7=mz5GsM#p8}5aG zUZTv9)EG0C7sw%4V0~vSu#5v{Z!xF)(n~eoE+nfdTdJI_@try<+3~6(cIl|YTGan$ z+79AJ#30BdE1olxP!l*zw*;7qcaBfOViHV9acT-WGzz4a>{e3F-Nl0X7v&tHgLmXfPCUOi^0VKgMmZweC*--c}Cr8wHQsc6Ns+D(`aDzdnF;{t> zCJ<`^&2+FGNNBJf;4s(@Fc^>nk@X6L3Pj}Awe&!NHVWf~Z)Wxu*m9s8Yqa;|Rx3up zh^=m4n%gK31O_7mu}$q;a@&-P0~g1(wcnzQ26je9V>@%V2mUel75PhnuSC8SySM$T zxktPY1-=#fm)v3RckvzkD)(;ggIv2_xF&f`W{>O3t}nZ%3;Y@vY7-n-gHAU!=%6M? zqD(xHMetbhWLV>Q&Jhe!(WnE!u0%!A1fqx0INFC8BoKZ7om7Y78Sv20d0zJX!NYh+ zB!Fi@z7;zOwS8uCLu2M-2_>RnpJ>bgJgTkQ(^?|q@+EvJoyxfID(Q{uDD8$2%9iaH zVu44;dU6mBoI9(EH)p_TMo&^i{_bX+ttmvo9?V>&RhG|ox_ZKHZS$SWZvQEAf4@GQ z>aE?H-r5-1`;BYnUC8YF;IfUKp=46A*0Jb&_3A(U=xvnL^-yA_guadW^>?2?JYAto zk1_oehO7*FvK1@YPG}?-^*Pf-I8AF&)Kul?YQE8yTpMjkq*0(oBtjxe6!Rz%VWULj zB?lsf(Y$^z=4w<5gPmh_dRuyDnn`DP&BkD2brdw*6Ij3fKcrIdaw#8m_r~FJDSYlW zai>U&_yQV-@01WqC(&Tx9{)-RWfUv|0I$#?@mA4jdv=b6Q#nH7t%lCXkU?V`R^Q}K zx>Gi2L;f_&8|`RIJBk98Bl_YU@pM}6PesxTDaqRIbn6OYwQ=x7C^lppWEhIa8sQcW z864t@(RS2MITO)nR7d0bgicesf;Gfx{g`gihqDiz$pA8Sys_h>W6e^BV<(23&5TcK zj>~Bb%XgS@db(P1;VrGpcgB(W5rf~#YqobUttR3dJgTQqcG=IJKbu?J=9et?cp#dV zkcZj#lbl4&~^*D+JY>}5<;k*_umjf zmqbt`sRz(-U?e~XR4dguGBku`pb~CzGX$a803ulKJNomZ%Fj(sdImZ=V{%$x+r1IB zXrbFXc=IxTb%h08Wx3fxTaxYk!U)Qx@u;^WW~HcPpfLtu-5Y#Yh7~>+BT&gQ0_@sBwor$ z+2P7aWxT@4l_{hfyD+)@k^M)GBZ(u)e~-VC_+|c0_RaX4iMR7swUHmn|3hI%eh=D1 z?_tJ0Fyr=kXm?>x(GKkl2J`oc_el@vcgOEeSk;_8 zlV6@+UD;B(F?(bF4#y+$eU-PEH$%3p&=H}Yr6VYcN@U8v+yUy@;uH!P&UP*0e>NBi zL<2|(==jaSPXDuB*x9D4iMZX$%4yPABIpNHvDDr{QSed&pY;1RNZ@dLOYmapAFBwd z5Q_8%h%{q_y>(PwzqTk`3KT2u(Bf_zhm93?cZ$o#-5rX%yHng7F=;isV!H+LQbUg~h^gIoLry+}{NRd~Z+^s1ehI8{r7$`emX`GQ=KkfV*>*id4GX zw7LyVCyr(%_e)u79u~&O#5eQS4at<6GeU0hL&>pofsBiVln(3}TavL+kguiU%b`%u`9#z^7OC}z0uZzL(X)Rq{)Q1@Me@+;w$l91Q)z(jLgvdHB32AM|yqQA_0m87bwi&w%|RHfZ0%I3K@(l zO9dj+?(A+@6klJ5srw@src$6KD=WqQcJY2Hx(!0%UY!B@n_q|*f7!kR`WVn;fRRVC zoGIk{Tf}!d>nYijd#B@jtQKSG>Sv3PHIcWdCkC%Hf~g zor7T2zX5QV74tdjZRa^g73yvdBil9odf63PEymsbhF+Q!T-J8;#UToE79(woiKnmk zm;5qh>Ke9#^G++6(VvY6jea(G}=r zrjgV*P{w8GSm2^Fu!$}YrDs&3{y8*zS<<|rnY7zo%CB|Xqz3&xA1M&HI8v39hbof7 zbzG;6v8ML8bC-PKYjBc0jp#EU8>CPcfxiRX%D}23D)}auLA`36j2oT#e(&1Wdi|GZ ze+noJJ;^F0I%AvUJ>rNJ%1y8GguwA#*uXt31yMX+{k?^WiCSAlAmdDkNk=A&b5iv- z?m@$BLl!ObD)jn(%lKQ`KJYB=jrPY6Y~f~b<2s8vk5G%ym+=(;X|A6?^;_^p@pX_& zS2|mRF5*(1hT}|dZ0d1VYVSbfM}mD#GvA*XK#=X)TKyw6s<3B>)4H&P33VhZ;B?HV z{IX4s?Pg03BR2t|cJP61bC1*7WQB+{{0-FcSe-CTBP!S>X1+A^GOgpK zWxg->i-CqouhALK;w2OkKO5!B;2RkxxfPOVTJp!UNtp-nE6_CjP0km|qC`B5&JS=| z2^*XM-|6rcZ$UJLTbW6q3*jsfU5H9CF3Lcl9aM7&?DM}uphk>-kn#CTDXMr__f0S| zmFT&-Y~rh(nZ`A{)`=5?VXFb^G5thdTflfNkJ znnOTgc{HnO>PuKAT5&}k80KSA!QO2%xJ{K*2+)Bg`_Pknf_g4b3!NCHyyiv98IC$EB9_2pforrA84lc^PCO!OJzI4U497ThWQrCvvcnWxuc zDFw<`2$bL6ZlA~1RFyl3k|lcePr5v*#sA;L~e^&IWd32E-;RjdCjm5-W{zr z&_IRdi{EU;jx9YK)S$vZN{@%^5sRo+wfR&7Z$M5xr)>OgT(Ub zNU)i}$u?PzqlaEZZZpmLvsc(4#F5- z_ilYtO7enW_S@6_v``H7JIOgx=3>1>(opG8#F@S*3Mn0iF>=y-pGI)Q-xoU+=BVW7 z82{$c-)V^cCKeFPBQOh3LWi&`%M(l(iVC$F&*5^=L?JDk2g&xCYH`1xzoXa7KTRhU z@*AFo04?r02|Gey&Gg(RJ`N0q#dM8XnLd56R%=DRMgALQTe>^vmFMM47(4>|Msf7E z7OZedl^#QL9rf{@h_6lFfOwHLRc3L)+ymY%cPV!oO6lOKppz?09ZK0&B8&t|=yVBV zNww4E_E6&$eyo$>=|}|Tnab%e-`H`Az}P^hadd6*wzvn-Wn!{^F9k@~Wvu(Lha?k& zNuz#GJ&VQ~L6vS}-VD>gN&Sw($+Y>UdE1HXOfnqPqq&FEy;(j?^P3KQZRgg633Ryhi8#3^3q+sPwuYOb{c6JBXKwaZOKe}_D0rF~WC)U)? zi73fL$Vpmgq6F#Z48J&g33CuGb07%q)BPexT4EG_{CaGE ztC}#5fH@{AMc$EfjF^@LjEK*eB(vPk{)E@jT(=EIBi=cc(!s4GEc`2ImP%ajRwl`H zF1a`tiJG)_;1|8q&RKalbUgCtrDE<9^1=X8^6K9~G|5=-5Ev4gKi<-Qx(R7a;kYTW zQ0_M*%y`u|jr->DEU~uCp?T4tgUJ?+kz@8)Lzu|ESLN7@1VpyT&Q7iI*jtpx+4^Z>?v$nj*nzcKxsBn^OMKk zQvYxd)MC9t69AMfh~+7S=y?WGN+Mnrg#h`F6LYWb!X+&#+;{R5}-(!N3 z^8Q8yuuu1R)DUgaIYj&2F5I!-vODEDDrr}>Z9OSHs-Vl!<>%(I=;Fqf*R(AT2D*k` z=F`-$!u1f zw&?UCA#FgdTd!yyV{H>ZC`**`4{aNhbpKtC+)5@5#!-A%X7!>y=u`X2cNWDO)%)Dc zebl<#W@U+`mP7kLdUh&Qtk1hFlY1q(v7Tl!lzC!dWkd5jNU%Z|i4^FYOgdjq?LVu~ zRYNLL2omWI1_+IiH@HMMB&G33klX*b1lO#iWa(~Se+zia&GZM`=zBFfpeyFTIJg9_ z)5DqeB`<_6<`VcJGh3wPI*VGB(>zL)TR>pyK*8qv`G|?^6uz#JmgJaPaE+vnAXqQw z6_EukI)Bb7uGT4jTi`q*G8Pm5Y7~AG+25S1p(WIga=m?B!`z{i}YbVIwwJqF{ zv&UtZyC6nwKN(^p?gQO>mx*%3Q^~mTs!p#E4Hc)zuw%Xup2Z*1$Nh_qSzcmt-&nPy zU{K&;itgaXhr(ysTsWX4or`2Xw(09vd@ABg?}2KdNBZ}(%2?z|>0Eo&H0KeR{mvC( z0+MgCqkSeJU-{fLI{_WRn3>sg=tAY37cp#H^n@s~kQIxC9kARwPwXa*TsL%`3gdCB zH#AylKA3udi{6%-(#@XGf;AYpR}lU)ht>>`FZpeMef_84goq;&;|!x;QtUpUHY-Mh>yrwNg+z9FgkXQu_x^dhvT+2oXS(f(W=ss&ns!kL zh1C4^*5_wCdR^FuTIsx#5NbLY=dL6g6AOLBacPS)9Tb>`?tNSiTZ0+}iRoa!-tTRj z*MTZd0)ivQdV6U3lIce71*#mQbxbqiCUFS*;lCDKR(X@sa^ZTD5hrsc1R7%PISYOc z37!g`YCc!Uad6BKsY!_=Biku1oa9>l6-{hTx*AHJNc68K(%DtI)CCXe!7Fdp3f-Rzum_C@=-WSz?&5B|2Bd_M z>OT^g{hSqg$nyxk-&;=SIdjvfc(i%r=lXBp!L-t)Ll_+fT|)&&J9b=Ws0#|O5b_cU zvfqV#g@KRdC_7t>5y^8Wmf3%a|C@uvDhxXxUdF-0?CQQZgQN(PWD*ckmIBN$lfGI` z3FS}f{*xV$dnJiH_=amIoWqM_`<6-}ZD3<5%?NH>y*f}TZZ5EXi3VFWAIag8O&hor zi!F6MzBXHT_UuC4JY3}}96}>@JoStuP-+BMrr)3qCLX)z{(Xm;lcpXW!@dR*UNwNWHqU$;W9Z-~wncQq zV68?zX)%LuFo{}vI%jKylKNk6p~E}Dj?#E~4%!4?`JN#T17K&RWq>X=_2|&R-usq> z$^sZ%b=(Q7^db@QpD<%F&wvaWAVork)eg2|T2G|Xx5}LA)yl{PY`3f(vwP(ytjsdw zGCAhoFIwyKk{GsYMUzSeS=A&Xi}t1mjkezmiAa-gDot1QneH%;ESnv_O^yK9-d4<^ z4-5KiRmF(y*KHn?2=%DO<1RuVDi>@-Saqm3{Z((?*mufmu-WXjxp&HIh^g$!5sDm? zuXyju1n^ek#qO+z*J6P1sk>ARGd<1vc=BDWV9yd#_&yUA{%i z{^=@EjrO{Ag2`XSKhxkzeLmm6Xz>Il6v-kfl!Fq+buS*K`-X6nqrbK$tCeW=nkzLl zl`H)Tx(TsBi6JT3`O|fhTh3cP(5{-NzK|ivzwM^SAR=SkRwLrpwXGW;WQ8e+lb1!kn&%HNs;{SkHQWJJEDAS69J)OLwb4U7kO? zM{fVi9ud0`yv?;o;<(kbqqM)7Z?e_06c<58ttnjB7QhQGqz}ogTx-HFAX^246e*>d zm>-Oy_^XL!DJqI0mP%3f&D&BkE01~_D`+y{Yym+`1bdp7i)4Mg-EHm8bKR-k?Uefx zxDN6J@sfrGHA^vdh248wYdps`TcExCQ0Sl&W_>qh9zpAT zlFqn9ha7BJmgplWK!99yMveCkss0uzWVu_vI$DjAMRbU0u$FeADLhN#P-GaFwUf`4 z>n~>y>h2?*uCnUs=3iY|jQV1!^hS+}J=d&}77-O>x}A{S-y2(ib@dNX*Y(v-(}+ z2|mYNDURNC4{s)Rx5Hz)|8!cp4LbFcqN;DE>L6)V!Ja__K%#;e6C`26HRex4PQEgD z44|gK1!so=d8Djd0pbj;z52;DK^Sz2Yg+0Jvq*nr&m=FBwJR>$oemoq;w`#g5$ql; zF#$%lAzo2l_W7E$X0ysAEDI^7f0JH5FaJo8FJbvvGAe4gxZtoJtd8kBS;UT=F2DFw zDV2-S@%&G-KyBjc-WH^X+E_OAgSHZWy*DI&cbc_HH>&`!T%DwD{SQ)0Hgf)dtghDZJFCZHtzS3aDa3eB1; zNn3@-4RPjQ_G!@J`&Dj|8Slrn{ot@RiGn{_aB#g}ME)_!_6kGmW$b#hE?|%9ezOYd+(f!VLCS$hi?_=(8@RkXO=&4~DH1E3Xfl99>gIGPpLaxWj*V?i38M&LC9!aPS{&zy^Z{UDdY^p{I_bXZb53CeBBLMlAzbHR#zr9vf&b0oV{yzuk%A`p0%xKfX~?`q z7f0yh8kYkPgVVYEU`mv`(GM-ID@1!528}r1}(ws+GeORIs&vy&lOw`5g@{48ZdO~y^ zHJV_u8Tj*z6F(o?%Q1a`pAkKOAtB_CF+NZr1vkyPGaAwE4YDOtF-*4~N>@MhwjWrR zuODIY6W8W2ZWIqxyEBR#?A?}SuLM1Xu$=foPNPgyK$bn4RtULE%Gf+X6LPLIWjrM8 zs^VSV&HA}*u}Vr2oA^nDUc}Hc1ud$iKlx^^tPI6(cc}0CZoq3R$css8-4_7bEmDOh z8iMRALGLyM?Zq;c;Cun4Wv+9Yy?$&UXK2kiyB)UKg8Tnk;gibQtoe4hT7 zo=heqjHI_j-shJBzRT8&c8IB`RPj=6@-+@1g_XbcX1904_-)-;O_d~~@5BE1^G43& z+z*PA#nhA3`4zyq_3owKZgamSkEyr3h}djj>#Yh2l=>Y!EXdNp&fXTJYXScbS?QU= zGcpm-6TAalTmS`okcBb<0}BH{*visgTKD~=2HBr-%0lAQii$#v3_wA4R(5-O`hTdx zCgvbU0!GGnVR?YCxvr5N0W&}lWTy|Zv?ritWMKJ+i=W@hS)G=R^&boY13f)E0V|MM z6TtT`zIPZPpldA(GBGl?|DXUAU93U>NPeiYHLzbSB^I001g9zvWQYLnG zCYDAjCIVxdm831I03A6-_@Ce z4DA8R09kfC4}czz2{A$N&TY zdbYayW+3~2l>8U`F9n8H4z>V06X$m+b1O@LD8LlJ53m8)IDqWzP2Lgq#ae-VZzn0d(!`-!XP(fPb16U}^GhlO(_u;0m&} z0{jHnfgIm87`?~AI~za*plk77WjkF<1Ay9lu~r|lAKLx_KU&)y1P}+c6lC zdglL>{SV7~=D!L2gMW{%4{kem)(gg79+JS^D^{ouv^#N2&Ecq<$O#YMq$M65n z{Wq7g{KusV4tn+V4{R93t?+5)OF)=ayi}tSYL)X9Y|E7K5K6w72 zv9SL0{K)@Xj+KFd;3KiT(}4eF$A|2Pf&X3R17>Aq`v>>&{O>yc;eWU7gXhD>5Bdl0 z-?p;9+y4Q7$S||N8pZA9nm(<{z6r=&a2D=>2G$5B(oH7~bVS+T^3G z58Q{$zxDr@E&p=uN0;&c(_NU@{+CY}0RMI|0prKZD*ykz@Bhu`tpD-3B*^mp2Xz7l zAQLO#y~Fv4)%UK(9wZ2Q4zNIzR6Q&Rek_ zzO9C476dl`V6$S&D7sJ7+PFGmYsR-?`_XdF$>H_XA5eqTvcc+s#;LC++j(4yITGEG zI%;j@^)$a%usm9UTNV1Fnu(_+@q4FJ%7tD?v$?qXUJNB}5^X|Lxyg8%#ASp{yY)%C zpSK3;HxJYmUaZUO%HUbe3n;SG1Hu>BS zf%AO`{ZGC`=xf89y6&_TpZcOI?IT=By_#P@Ew;Ds{hoQ#^~o77BZogp9CQG^3uU9u zlCt#Ly4{`+3t>|});^y)qi}$4v^WgxVyBIv3;hlmjOceVa!SONNNMTn^G66R{P=mH zUODyNlJ+~O!EcGzc#@e34ft{kX;o9bX9;?F&LC{*)+X@LET6CmAm$Yq)Hv0!+La6P zf=@k^+hCaO5F&nm!;-0yV8TWO0*|@K#tWcCqYQ$i_#T&vD<(qCZiH%c4w&<-yry02 z;TC6aL(F^B+RDu3bE?C9B|p4M$UiPp+nN@$d0?)Lx)VY_o~mCN5<~^Lyx97!s}RmgHI1TL!KY{>KxWGb@byr9?l%bNo)Xf@UO_z{No5Vv zm0ZKA=B~QDJD(54=&rHdJf4sdJ#z-Z0(eSX&DwpN=)H+;A79ev09A`G)_n@-0l&BB08jy^N((F-FC(AX{Vzws!2h4!&Hm@M@Z&!PL<_2 zh&bHz3=f)^T**e{4Xe7GHIU0I*E% zeEqreXtTd{*c93?m@bdnQsGy^zT{>>(2`{Ug*sMMj?8=KQQ1pI9P=A61~6#%T$)p7 zGzr&^>7}+VT-lI{03w=Q$(tpY_YU?`I7P9EGsWrgvsHMn%O}5uc}pC;lXpuq2h|Q5 zqoL8#(-Lc=xH1Rxx_Q$1wheexu4Gt$6?T0J)8e4Dzx9Cwq+-gq{9FmkcWn(A@Rmb>&sXKo={a&&) z=X-%`gJQOU}XSBTD&g1CYQ0qhWU-(Oi)(PCpTyW_!dU zC{gFin`e#{%&MwN8$2{IcxMvARw7yndnX-j^T;$$+ zQma{Rg69#|So=yrPcG}8Dtn#I4GUFz8NoWyfEz}?6Z5$Hyw*I<{;cuV!e+uM%Um;j zaqBS#=9;%FzD-5oDFO3)DJ_LljIhsI*EJ$hSyvfbly(3Mq~$uLS>ex(9A~v^iWa$ zlqn#~PP(PT99&3CyF3CbVc4YNNZNewhkvlKn5+0@Gj@Nz2R5P+%!6V#ZVqJVD8VLmK6a?Cj+rYd8!|1XIvVV z?+P>x7u9MUc-#E>=4|?Ne%-frH$7yiC$rIgS`D_}dXln7u2=;j5axu&xao^;U+7yR zj`S8!&YwZ>ngFGM!nj zJ=^=I#Q$|vPg9Yw`^JJq=bNs{Im6L|fJ9DWh7y9^C4KGr3>gt;Wn+m3RlKqB=9QI) zEtcuXd_=k%%0+#1byU&Z9Q%5D78>bgUB7Ftqvv)v4~g62ly*p)^P_Fn(3-!fEWr@T z((P`%x8Ss8-&Z-J`Sf+&v;WHpd}52+QVk!+9>iH&Hm;=GaPw23CplC_8tQ7S^&&%l z?IG)nG`u(tN5<{cLnp=E!>JQvAG$i)cdmVdfz?dRRh677%cGj~k*7iFu>o0y5}hc9YX^93Uvj-lNqUip9byl%qcU`!cHDMWz>jO!$}UDRp50;c z&4WhAre&efT89w(f)WC!*!c7t&hjsVEK6VH7}t!tY^vCeeCSra5+M0NWTX{1QkZpIEM_Mn zC_aH`z&yjsjdHg`Rk-zg3plmQl)-&gSgB%bxDt6wRl@IXidTqaLad6f1=}M0;~kBl zrl<06UbG_0r)_6WioggM5whNuW(Q~4r{bdewn8I+2L-^^fbeT{}=mU)kf67Tt=7Jz_aMA0kbws7WZH)YFPZ;bcEK+=uYveL2*d+d$IX zI9BriV=!v*@R+Xx?m&j2DWM07-@i76yjRQ5kHyxuL)K`GW|4rM=A;}7)V9o&L)0P zbd4|q#R6p=Vg}E8g|4OV@AQ1#p(`AB$Su-3Ht23psf@QVgR)D&#v-$)6&Zo#7w>Qb zwj^&ozMkSfG1o>@;?H<(=96nHY?hTpE44`e2kIcX(S@*^;y<&6#no;QBTdQ6Hb}@_ zvOjKNqOP!n4x(Rs$nUX%(Tcz)_QwuXlG-b^?AddZy+8S%_*U0KR#*>QnvXCgwNG!> z2*Ri($yo2BY4h>OzT|n#cALUdT3{r^MWOfYmhQ{AR+aB(&4es8r4Ra`Zp7{nh;(Xo zj~G~~mYBAs=&_YN6I_us4Eu8|)K)`y3Ps2=+s@}m3gXkMWb`$|cqj>xUP)7TfQm@d zkhcAil>2&y6^S;mHk=tLHdLDflxiYqMdibE?mGhy-TuCMx1BdvU)>hy@l7T z^BJUvofi3N9mXdoYajlK#sG6G_^PCf?K&qeMQBP<$Ne?TbofBFM*LC-FJhwSjy~P5 zl?a|+PT&jpr`%L!FK52=OqktOu5v;(5Pe~Y>t`5Rx})MPSiJrd)#$vut|%=Jj#d{2K6R2zA-+uW!!U zuTs`>syBRFJ+pvZfXR(@$yb~_^jRQFoV7b4Id%w`qsu`@Gatr_`2u&c`M}wgV>GhZ z7lnR-e4xf~nlITGmpEA?mh0B)gqL{}1f&w%RqR>;&Y1-$wro?2O8IxU6d50*jKQh* z=J-~SD6 z_i2G3%8cOk@VB$Jk61(QK69)=I(aQsTyBiJ8wYQwH5hwU#;#)e~iA=UM- z*QKz;?w`ai$_d@TUtos**x;86IKOZZbshtwH}~e z`CWj7vYBPkuu}T3^|<$F-KcAJ0zWQO6H(=8##~c?Ho6?Nc$9x3^;w3jfk~?DVNYoa zg&Y%@)TGB@5R^^Xmqhb<6UejfZqU^>VReRmZJ<%3>;!+?Dh>&0#XlxbPVpUw(tY`h+k6 z#{0j`E!h9(+=2o4v55J9om<4I3|f9;L-N;M%z>X%P0*KU8?gE01eNsV{UjZoox;=; z^)cYi8{+0zzoo5k+i2xrvEFQnN~Fv>9b#CJKjn*amc888#bM^~+4TNH2L^Rr{Pgfc z2PSQJ)^ws8O@b^-tF@U1Kv~l0>K9F%G3oAg^SX&YgLzZRpj@hczn|iCq*wFs z?9yy0CUIGf15b^=C=rW$cz@pHbOFwETf;>=&fp>qrhf9obh9&gj^uTD*{mdQ;p~hH zx7W#-f|*j?c$oyEb`U{I{UUI}UzIo+ks$SvK}o&yvxC=xV5on^4JUQz4PA4R4hXxy z(y|piJKnp@x6pkwNCL-j*NohZg=7ux@a6gHaG4aY6uUA5mfD}$`*!&Yt;?AdLuJJ}7<`mMkA%OY!^8$~x&6f9^r~q9 zDW7DVOQ$h7AQ?X3ZY)L7XYtTN@@s5%BzRnsM&oumL>{U~V>zx~a5GA?PFw{c2zqGe zGoMQ=Rw#DpqC5Ap5Ph*hM4a_x+&RQJAB+~^0)$QS2G{;56V;OI3B5U`L-1-R6~@?8 zj9)T~c#SR%JI&LRs<`nIL7A+$)KaQK46LuycohQ%Ep#Hx>E#CJlBq9CBxIfjd9Fms z0jm^Y5)PQ(jd%VW*!}FD;RLIV9Kp@JiA|`e6z`1GW5st`V{yN~+HjlA5`qPoy0DWh z9%>u$x6aODvAXU^aJxV-_}sbD4Wy%lAU{Py)(BST1+d`-9;l;8hMzQzujeoN&zZ>J zX9SRy;A3S097y?dy5KWkzP6`?=a`59XA=fAv4)tFnrC~x*B&2!c~hGaCW4)=p+T%V zSg?qdwS?A?{3&*FHm+P5busu+SNOSt#UtO3C+<+47<(Xz3_SkL2Q{}nVU`;G^N(!S z5^mNJ@9SZV&`6~4t3K6VZu8F=NFfvb6!YJx!!6lQdImhsK*_WGvSAy^KgH}8P4nFG zrr;s}{6*PpQm-ew<;JvOMp`xPh)lf%?cJI0j0;gn6oa%?dS)hwd8ww8;|{})C+eE! zaOi9>txF7vVjYQyzdD^a_v%`qfE#OmF3jN`l|EliQF{U2soTx*xGr?99Mh}Kn*EL_ ze4ML+GTvqvKwj}YX3{h(nRX?waQRY=!kX#Zre%VshmBw-sKl9AQ-(ahd!`xe4sHlF zI0#4y9koCKe9@3+8&K=qHM9*VOOk(Xl^~vne=CcPVvOsDtQjQL!?0=cOxP73YvlM@ z=q=Kq_S9-ff;!H2Qi4mVh-pQg%@57C`{aQh_oQ{FmmU$N3X3VpwXt32c9WLEA~>ye z?YIVouyGN8gixg67}E&5@RB!~{^Iylqb|C$sZ4(_trXI56K?GQ5Qv{#QlVj)30$N2 z1EzC^;)LH^XigZ+j!+e*qY+4cEqvm@Yj`)SP;Qw;8QnEZfKe1rsfJbeJ9<3XvTk(n z90C7P(+0eq5XBy6uc#moqnMqwF){=;$aTG&uc?;%XYMC>zd;j0qPl(ACWu8jOVBm- z`X^VxZ3`o?O5hdZYG-O;Lfg&CAqI5oR7dkA+$nC%@p*uVBm7|EF0w^mz3r7+)r!hX z0g1Gq<@cqr;&wCgENh!TjK_(A-f?(J3#h(O8k{)wfNo9Ak%Hq}x=t!r=UDXMNTFyU zB>(Zr)2~=OrMZduGhfkppUa^xzw1KR9JMN}`oWmdYxboRg|L?|pp=E9GFiPS)-EZZ z@F9wScO%8W3MWn5*mwZz%=HdUw{NCRCtoYm5p#Zcx;z{|i!D<=W962X8G};&mIZz5 zi03M12K|>}a+v)5-qPy0Sh zYRKbf0!IdCc`o?S>*4EhQog&SIULIxk=RPEJJBXw?nW{Sa9U)F!Rx=+NQ(6kT%=s^ z$Czq|mYRf9{JyowlYzKs&XDX<>5+w;bu!FWa@WX8yU`_x_@M&2tLA?UJ^GwVr^P%v zbC0IAg}O9hTJ~t+bheL#=D_q9gw3bc9@Dp|Lb3J@Wc@xeC^tl8D`3XCS0* z+_vps)UD555$sWZ;W+panw;7*KhdufR3TI%CVrr4FQv-Igg8R1UvJJr4<7Kzc=ZG@ z#}M)|RDJ{VW5IfXE_by|P0^@MYU0y2XWXi=l24=}uHtCC^L%}{Z~p}TiB|lF`TsV^ z1OMkB&q&Y0_Wu~Ue>^6O^WZRx-U82TuEiLTZ+Jrna9rK9Q1!{nV9mS^_}Y zO#NItxt1t@#-Cq30cM9#O@F@$q2I6VTvqYA3sa>nJd%FQyV?hWgOwiuO6IRXvi-Aq zgIJTcvX8+kBrGg6hiofNr=^&F;$$EvggexNFa>K9c`s#*J2%-L3e+_eGRo+weD%$0 z_Y!4Te9m!L>5vkkBOZ5PU+$sd!80F{Qrz;Xv+7(#XfBbv8!?1x?sR9RtE~OTE+?T@ z+@U3+5XNn|U4TTRD)Ld|NJ#>9pkkbN4~3e=q@x(hWmS)vd3|JhNVbA>&Cm=XGmlhd z@k_A|s*@0wa|3^kMFJfvl!2-39xPY zK5kM@7{*9iIUgCCTnRxbs9%rQFHeywoH&B6LNAp@_~~Hgg($?~xPyU|3q_7^^pjEy z?7mKPcRhNG_#4Hz+@kKBKUf5WA@l=4sDS&7-?WGfLPrBiZbZcvxC( z<0rmBFUoqy;!H3e_B#J){>q4D2fGD%$Bj;s@ba!(gF-}c?t6KUEDyBo?lq*6Z#(D$ zXo&}XGxXo?SvEfZVd`>*)G%->V=(X`Z0cPO)W3z66^vf{B`Qysy=Ucjt{AMp6k6Sw zQMnc61hR^&H}va=MXq;B<<2H>OqcUD#yvn}BrU&@s5rX9$XWgLbjU0&YJu960S>Yb z>TB)7b2IkhEhn1-?T{5J1&jIns}>*r6!HZZRtzwj*}f<`&N{YFzu|h(C;8S;0HrP7 z#XGz6AT(e$1CUNc+R)KCoa#pQ^QW(bFC%+DorndE7h663ht^$_Js-C}$>MZAB_?T{ zTyg+z%1}nFJ$glddBBNlb!YEP$3q%l@-2$2isn!Cv`T9-NeY&>A{7X#ljvpw~VsX_2w zyAs0d?a}kXl*NM44hcV)<_o@x7ov`)r|n=)EE0_vx<0D*Yj6+ktg&1m z6fBb>81$5$4mlqr{F$uS*L~Sjr{Vo*sI;l>1)O#Sfhx{C2P_?+gCHbQ!Y)x51Rfe3 z@0<_Q998DMwKUEl7kiAMJ$zVD z-Na2;3!?8r(L*RZ5KS*S_Xc4~G3VXAO}`Z1O&6mq%t4L$ z`who%Om7_06WOyt*$pnp%6RbByxAJvS$>3DxBSi6Wy5d&m_Whx^5Cujn=V!J6=Fme zS?JA1&M`>46-Du4YWaT2s$XeK>{;A6-Vj{1jz;(9#Gc%cGho^UzeCf$@NR!CUMku4 zZL;F~PT^Z0PK6eKl2Dz7uDRgnTbv64WinPpkHT&-{Y8I6<3nHuue+{sD53b zB))IJ4+^3CQc(*KI&f>pexI5|I>ToYZ*1eYLc%~r|3yYCZ_$ud5h-RMV8-H@YQ7o> zMv#0Big4r1fv^6&bdX{6E2h!bcrIW=aU08KC2A{kucW}L8S`Zd*@9UG2|`~72aO9+ zV=Ox08 z^NnObyp`Fc!w7zVIir=mi%}J`W1#;zYcBoWHBH@v{Mxu!>`kS7ZzI(r|f2 z=2kWSZkn`iX_t3feRRujPXM$3;s(5M*kkG~9j)He-7-cPGU z5|7*T{pz4?YWm~tU$m_He+3&O+* zf&s|z|C&zJs&HDpuNegB^pXz;j769B$cL2blP^kHGY{^fevyZ8!6^zmqH+2K2QD4` zrftwT+;8nfksiuB8Z0sP6}awxHTrsUILua#nr5?jvYu(X*NUp)^zBuU+)sba;b--v z!&79z%Vg!7HC2n=(!*Go56tYzoAlA=gyt9R&GoZxFJb?;+aE0_6#=UQEw<9Psk;5i z82}b$2fB3& zlCWC8%}thMASqI^M>)`(Fzi>u-nSZ|Kn2EtyH}3R9mvqE0Qkk0n)I zy!7jmZx~KJ4lQ831kAfMczICefyALZ@IM{VVg-;-W8f8Nq&r^NskLH%fecb!^N06w zDcLxQ_)_FzT_wTeh@9Iw>EJ>ZH}$!l$u9{FT6~1Te<1o$PJP)+ZR1*vCyZ!W(M7BP z2^tsJ<17Z2)z9bre&;UDkKCaR2>+xEWDmLt5w@&skCrCP=X(zKL}h*puHpQQc(^fH zo3-Ru$osoA&TG|T%!i4REwSHO@*~qn>~!IH`q7jy7gBkHWj)L`33By>NQ3aW7Q!T& z=Sr*sWWw6BUBHXN1f_02-9rX*P2msoF@k1d)>8bE%I%Y7X?Qp^S z_VTkIU50j87?+0MT!XVG_8G;{QkcBfV2q|{JsG}{HofG(6f&t3c_k*CM^m zW=368b-?{W7NsYj8_Tji$H+6}x2!#2APhS_q!ckYAj`@CB~CVbKgd zBCc|`u7u0k@?d#jU(d)Rl!ZM*S8XGyU(mBApjW85U^v`A#3yHgnmia(>!25lE z>$%Fkxyq?qFakWMEO||G26tqChRmF;^n{4`I~?vgA2o;GOh$t~hd{&1p_QO{GRvFh+U-dZuZi+WKt z+5dERbMpa06e~|w$=fo;#?zDo?&h9bDl5krWb=kIU+qP}nw!4fj+g6uttIM{HS+=|C_PT4YSo_?w;_eeC z@<+yu%=srXBSz$xW4up*$Rb3^p)X-c=Wn9W4$)U15uLyqW3uLMdO4Q<1ql~7;ATDCIF!K$~g_IQVn0%%m-we}ttIuABZC3q4q z;0WCLG}5F4?w%BsmVw@9(6Pv6Wk-#1H$ib_!yHsqNXw1P!&KKf890B#$W)43bZCwu z4U~0^2L|T{YtK@x)#a+rn4KxJenfpyiU65ygmt$nZa@~gIC%{lzhXczolT+MZO}`L-P0Bd8dA=Oo2COtVEU6 z3BH>?KZqiTlEyw-F3m3D)O{t@96T;w&I##zhx68{S}~cptSGLUyko23&a2M=fH)*I zVIA(K^B>Fp`8Q-8)IZlZZAeydr|6^%j;K7DHo%<@)2e zF!tSQdHifV;Gj6AczN*{i+fIG{5 z2sl*tcrNo3v&`??BbNnRjVLY>@x6$cjd%|xubBNlnh*vl&A~F}ZqeN~t=k-&4F@Nt zG|~|bXfFe?{%ku0yUMpvPw2TG{~TndB8|H6fAvdul&1m{fa*as5NvQnaKm!E#W${_z*!&0Fp7rzV7CIOV$wL$#jg;%a zahPc-BQCe1@(`hhxWF^fnS~4bRgYGa3{OA1JEZu>D^!zdIqtv9S*gQ0qEhV>4?S)< zr`XVrO-cXXW(H=Jirr|54+DmBY5)Qb;6iAfff)1x&H$ zn2fpC&26}A;Mh(@S5Z-b{V{cqS9y+g-jY?FPRx#&rmutc)K^F+S(sh2wSI?M z)Tz5Qn}g``x*89}zbO8THyJ1zb{?NLj#n9Aga+MdOK8Q0W814BYn0y`n2_P2by0L} z&BV%Ni>~!bnZgBbKRFCvYuL2m`-vsbms}?$mF&j^i?4TIq+My%Rk=}By1nP3VNSN| zn@F7^OHAUrkW_%@Xl~`52A`z4bBuszyARb-2k(?g^$7+qp|jIwV4pq`+%BnZRq^+B zja}TguKPVmveh7|aomGno?y5CJkZRf;C1AJ!t%2(HT1;|bnAgM6#tvb#3Q$QOqXIU zz+2a!_xd?FB$%fr7Q`@MPKt$%6Cd%bW`&#JniJbJ*HRjH0Ef4|y~Zie;i5X?=?N*? zWhHZ8^Aoi8q#tcG9=zxisarV2jUDX_Pu%2wVyMJ;B?a(g@iK*RY~5<2u7Wp6R(+p@ zVOijzG0=g=jcn5*C@T?Wo<5mq-XPP~E<=dHJvWtRB*%vMs2v~o+@0OuMRLX?cV#w zZ|MOodVbYank)sDuAv1k^YO)8wdVOoJowX|Ljj3h#xe!0MEH}P9@_B*W*y31)9YO{Dn03Cz= zQ4qY)o_Js;izv@?%A*@)>NS28oPWR}&pdhm;W&~$(E_RJ<~xgM5EX>pC`IpXzJUKd zknVFL>uBvr9X8nAZ9pR8 zA0SwDmnLA?n4{yu?P%zUqIj4m_VeKFEff)$Y-cm0-bLelU;ncb4;r`m7#y@qc5+AX z)B-s-!1{y!&D^cUzrI3)b}4ZN3vi{(WW7>_iJaT}a@P6VKe4&|uFNQQp87!#`ehHS zW_3_0rwF)m+DqS?VfznlKhX8{?eKr9um2eC`R8QNzZ&tm*#D_h65`|I z3A?&}JU1dLNUiGMAa=%6fGzW{6N)j4&kcCSKSQ2=oORzQyrLQ%P8&Q;L}GQ?bAOoB z`5K3&Z(rP_ObIBq`o$PzUfbP#7!|i{FZy2=qp5gm9#=iAFNXJ)19c;w_1*g@`8N-Q z4QQUlvTt(&ejKA~`*TV@)#iNGbM~OjpI__x{1lmcGPp);jNieE5++O{cLeRB7rtBH zQc(#-Us;sDU$lPv$dZT2oXGqIWBP$aUK;hORrh$GwYZvIC8KRRlmQ@0DTc*BEq7I; z#G1%&>*G^hc-|S#UEBV8x+L8edtSjt@6vqW6!1T+hA(t+XBMk0&P!tPq7k_H+9ot{ zDK&eiOI-kyHAqDtza#b)kXq+u?G(&zf(O<^!c?l?PgFf3Lj&*&=T)8L(;A_JL&-q}HOjFkoc;!p)q zeTyqOC<98i4Me3=3g{pUgRYFM+Hn1i0h0q&1x6PGlw1;nq-~t0Fqpu#SkbIgjYH zXfT;w`_wBwnVpko6Sup@vl=E_=ezO&C;!g-RS}uvPiJLr!5H ziP}iSh{3hFXgz<=>CZlt)^d(? z7)}ku(m+d5IJ=^uq4<}-QEA3U{ybHs@d8F#!S^tU>(neYP=36}a*iNi93)51)LS3g zEo53`d^m$D3NX%=wZHW>NvVX#-1;bsNx)9`$o-!1)6Wk8)#?*~Z}2y{=Q}%54GdIz zoVhHpynEDj1pA+6lhZ<8zRbdQlZl!a4BpSp6zgtI1rqzqBKWDNHr;8fMy*azER%Mx z-V2J4DrSL%P!ci{sx2=%CDWWQ;9naIBqd*MM)~T*m^IiVd&g!RPVpF%#0FEY=Djc$1>CqdPq5Fr^oie$ zQuqc*B1^T`$;MwuLtN%R7f#)jU$n0SWVgv6E3Q+sZ~%W3zkK$6q6 z<1}HUL1Jn#>AC!pC$;PBSwT;j2xau9+r5(}f5Ly$->)I`Rr}wJ^ zZ{Yc(}z;JjJ=#NbSINMkE@qDL|wmzHPl-*XA8SCJ-xgcmRd8?o%Rj3Cw?$w@A$nc?q}BOD&l z>zUrlKj+Huv}AGEhov7Pu+B@Fo79Z4fk0?)`ubtaE+Rz2$EaSrkAao^_>B5fpASxG zhCzMjA(J{~#40htv@29Dd`xQw7Z@MSuR-?w;xsQP#v6d9H2gW`H~r9vn@+Y9FZ&0_ zd_yI98AC^QuruzNON9#Ki;;s_$j8g77X^=@bGyg0T- z$KC|o{;=jUxK&?2pm=$MS|K}Wo;0fYMbtYlXb_H*PZ?U__(Pm04Y~y0u zHU}MPSIylbsNv9xaJtve;vu?z;ovlEj!C7s2qKm&)E+6iZ_{5NqXu%y8jdN?Bpz}! zv7b1*Tb~3~r?UWTSV#FKvx_!&n&F)3gLIZ!Hf}~PwQ3s&J<+=G+Dju%khZR*+f9WY zF*~qq;+cz}=Yl_q(aoHkS6x&Y#bkKIHKpLSKtEu|U7_Bp>?E;T=C81bO6Qi}z_4tT zG3{UxUK8dcJiksyUlflG03RJv#w}gVTb)d8r*@zn5Y|kVfL|B4PQ)YOCUU zblUMSB9p1y9NbLY#~+~ldy-cqC#^B!d+I3EV6*zKZ{lVCMg8TfJSpfjhV7p1r_ajX ztm(~gUw*Gi-4%xb$AGJ}KUwfO)}{I{^@h;{ww8LHTNeY~0P~j;!^r{KQ!&rEhXHF^ zGtWC_Moh7OX6^p!r?2E^$*^KV~>XqKQ3J)K5^*LS2VzwxFe z+88>!`RY2vcNQl|)KxIlMsAo>34VIHXwatXEo~&*B@IcMvr+az3rTqrcLE*TD54G1f8xEfKUWM5sGra=S)> zbG?o8sr)0%dED&YDy-<4wI~hzK*=_!-McgaZki$j@BI)cVbACO6gkpV#9Q*=m9O$) z&}U->!NinPV!=pN1@1Nh!!G0!VunSe3M5(*yc!fGChL`chd!mWYAuwocmt)0y9CTu zk@!IgKBut?9W;MUy=(r5ihGHE&(xI-q^-NQ)0#%x>Enq2dGc^L=Bhi79x|BBFKB!E z<4=?}sbB!|e*KoFh`F4UMus==x-ySi^Yrx%7$Dpm8r{V)I5;lRNGOpeO`gT4?iZ~d zBfu}wxIN!KR^NDdM0gegkb#Q)2V{XE7K@Zq1*GP>Jq-xo03!Z;Cx5U?L|!u-++>6u z+`iEZGucBVqHWF!KY6Jc5{Qbv`}X!sLLFSn8My#_nfmt{$>|K7Dw@*pNyx@8QRT)H zI<(3ylNz@|GWr=KP;(E$tq=vPWxQ4T=z5Jpotv^Mo1>^qsFiZ8NNmorJ7P49mz@;V zQ)cb_<=@L8C|-vyH->|rAz*-av)<*{E9+?6MP`F`{;0(Kju0A+3i?_3WB~HKn%ue< z`$M}E@SgbM5MQ2M%Mu%7y0_YXRVc+x^~oXtpK7hY0(_y))I$5p-3oZx|EVh60BS%< zPFs3Cl4=u&ED$y1XRz>C0hhMW&aB^d!LM_uP|*!j85Ax}^1A0qn%-o0#(QmloRRFw z7__WDD6xIW4B)eF*7Gt_)3C{dxAPOW76lLhk+jwecN|BZleWgERQ>VVRL~4x!YE$Q zX|Mb>0p_%4ijG2~9uW0FD8FbwYh$HW$?G6kzJn%h-870Wy`Ks14x6Cc3z1_c;6AE5)juAuA~kdV)icL@lLCCUw|&Xa_@mLBW&IknFC$bd8=>c@l_eF?~mP> zdZKkqz{fCg7&h>+0ne!79LBda(G1~6+;ltPoC3MkRd$(e~Il<M5GU(8u*% z)02hZraPl2h@%4aC$WU`P?BA#LQH`9*ZN5nLModb#&~g~Dp3_){sCqHFne=*W`}zO zty&ItRA#$}g1n5y4mpYP{%*3m5`~0)8kbKDW4TU%B%k1u`#^iU>h`OZvl@U9RRvD$ zm-$|Dg6t7$+mP(hj7^a%+dgg%Igjsh1g07PC#l^Y7zKRy59xR!}eWrGnO9 z4g}+*0<-U)`2sCM-Y;|F&?!*hzB|M2>J`>#IVoC0A}}&A@I*KxGUsI_vbvm zPhb|vWei<^T=VMdtkY2L+KfTH*=<_lAA-Rr$T~xxZJ|p2M}0lPX0yFC^DNxQHsUYn z%g1e|db4Y&Uc{hwJHW(%S{H>pfnlr3bt9yrLl5fRERa=%`tG2rJ}8L=;s=5m5Sid$ zjOn-{ifJ;YdNgr@Rtn!V9oNT!l!CwTE9~6>T?X8bP!_Dvw)z!lUnx|pec7TQypoI% zIS?3+$RX;pzmxq^yKSa#$5fc;;g&_Gvd8820gz>jRTtVi**p*-p_e}N5gU+04 zj>VFt2HBk`{V)weUi!liW!G9NUx*MF5!CTC^Fn%Vk^x7pN3`QFNvC`JW+*I$NME^L zV??WQ7d1dz+FgW|cQLYizQa+TH4)hLNE$0B20YQAdkOF1K%V1PN^S3}bhfpsP zE{gZZN3(@MidvAdT)xbFa9uPAc_OBVv+&V-FC7r0xIQb?|Tqj zK%@KiTw$c!M^yMFZ3~76xg<;wj%=W5gFdeub|W2%LodWIko#14lz34IGz${FLkN1E zr1M~W?YA@TO!$CT(pRW2nM<;Cv;-IyoQhS+xJF|KCG|2JIT06JtNu`0#vpU4247>; z%kcDlzL{~#s$|+ETuHB0sGi6sJb(*iS@BrvE)s3SK6RgLfbgmd-l_BsjKGluZ(cKO z*#Jm8LBr~R{w>%i+D_2!Ak%)7l#3LqwwOXw<|TA%c29+mqC3Z(!F}2hViF*Cr^*&8P+3sY#=r*EXiFjO25k7qTXx&eK?by`V;yizl48m6T5pSve zqIl1wa8#;MRN?blL);SW+ZSz*ST}^atP!u9QvxEcP5Za#h9TBME}3g{lH1j{KDH>g zz?W+(Kh$RLK%>5fhonqp8@af7xZxCzoKaOQnPtA|opA5(dF$al1q1#35O*YDa)WmF zp#?%_6G4Aa+VF|z%aDbFmY23@o>YRq05hAz>cS!af~YZ{4PCe`pOftNL&hR)01^a9`nbxEyu zy3slxv&D$!voi9%nC||VdAO*#NVpJn@V|-O6P-`QCkZM9B=A*@fr*YI-zpF+4KmpX zk-GGvQuNEoaTcU){mkjZ4Oe3Pf+rB6xf$^7jY_)3_=F2U{1MK08y;#EnU|qV;lhkg z?V?w+r7@VzKr%T-q%D3u{NX^BJ>HinIj%s?FL`i8#T}RPBmXlihoYRi5Ts>6E=y6C zsb$WiGoiNZ0-*5@<{#86XDB@W8WYjWKy)3*;TiI86v9!4C{6yKE<@vDg$N3HS&5*xzH0Yfa^74w*``qy4 zhWH0IN)=sunm^E*cYOdHJuRR(ItJMrXV zMUL;r&&QV(@(b1eky!5ueq*2|DORtl8<$==_rR_?ehV1b1ys$&vEOYuWD69jqzM3d zWM3N$aAIWi&D^Yg51sDE_M{Lzg}W?Qi*9t!Q!tBPLNOwkW z01z5+&}Twco{6B7!EZUK$Q6@yyt2BZ@`$9UUyaGV<)^J6tSM+xj_fp~H4{GCG46SN zD4FNM7R>4XAiH?r!O!a-(Kl!N0{AdY`G+BPN&MX~yOUq(ql)00Vn&umVOWY^lJdpfKyx=Z z!k9FD`4;^<8k8>d`3Tqxu4a;5Xk2dT(N{_Ky#SS77Vld63+l-je52LiQ3^3x=1~IP zDqf@b_zhggm*6jsI4ji#-DZPnmq=Do(NNf1+gjFH*;v$F-CWZC ztDXpNVs>&G+5)oiQ(!(DFz(cqgU~f?!(0waQA{jfw`k+l^3ya$NLaU^XBTrC5bwer z#B2(4>|q4N3(>nWPxxf4`LWEUY}glk(uJccGUfdZuPS3KqsbJtR~7L-2x6$)kIBD| zb2~ELZ0lR!+rd6}5sg6m#8BERUV&SG{c;FqnC&WD#VGUcZ$JN>jRDv4)OO(F`_!2x zG^wX=41Bo^Xs8_3SwhxoP3OXiQYnmU-RMDMgWywJ!nd-I?gXj1hc2R9<6xrP@V8gg zwGH3h)zv~Gr(XrPkR+bNV-G_|vr=x2s?;s&Zj5y-^ut{{+SGOOJL_!+YWf(mb_H>T zuy_<(7pm))^uc7OS=ZXIMAY!&0_{ z=GL*oy${13h(nTx2nfZ89eHfiL*4yUgfYxVksl7pTbVyA_*-1>+J-Ll3w z_E20|fOHG*4?XtWf16)>jg19Rh74mAuALZk7VmZXbm7NAkQ61>W_ZOgBg<=0w${YJ z*g`8Ogh+!HpiA(Z+YVXuv5ihV3FwFeUB0-pEtiglu9pAwrMvEp9d>;12K} z=Fle4_VhlQc>DtTc>_x%2xX@%Ka=`{V!**#R|%K=`3DOhC;JXJ^PKlpGlAiz(l?Yn zFQxvnOsu9MHg1JDJv~2NNZgVYgsOxxilv@#8ZN)JGDGC|(oeG4s0SQ0@zRLbjbf4S z47AJTw?Dg1Dtz7=d8KHE^0?d<%^ZI2UDuV*>Z7u_CSFDi5grOz9Bd_BHr4pkGjmG5 z{i^~?f^0~Nwb}T$&_RWwmsGqw&DAyEERu)gL)k1vS1(To#tA{#3=#S#dF6 zd)j4idC=Ke>2T_xIll?Gipj$Aj`klDu$2D2J?l}=e~ESYyGh%Qx+~Y2m&t=C+!-ew z$1B>oBIpB~ve9H^_&4kIv$6pPVn>r&P!k%LL6AHQokqbgp=6L`m`}ZMJA)}hbDUIp z!Gu$it)Ms2DLCsp;DrNFt;%MPInMfT_>x5E!pIKj2f8UdiA2IVPNtqXwI&oIux2oQ zI4(RYt`oOdHk#ZW(N@zEMDlPizTnD{_bch;ucf zWMXWk0&y2J+`I`6yJ?QCOna>?`;0t$t62^+^T}kM{^&Ca?4)$`*H940M3$cL2ZN#f zp732CctS6D!6zJtN1QZoc-NkAXoDeSn=qQ;O=>_D9A+h4n0ojWjcCq>0aHtskZVk)up?Y=#?_P2BMn-sZ4F-3EAA?MGI1pyB#@>D zetL;`{pdF%9&jZ0GJmu9#z?g!OcP1DY!&J5@dzUM6w~&S707l+UBJ^6M?S&1x@k}9 zh7ZOw`VgW=O}{eRM@*F}?3}B*@01&1I#W^|lMtCEBpl?nW2=XA>qcGH$KqrgQa&)t zuf;HaPuwK5^>;cWLMT^2?{cfYFfNRXnl&!`DXw7z42gU!yR_mO5m`c< zB>vgmE%XV8N%(9?n)jR6e+`|IjN%I?G2~;!Fp6^I1$_zhpilA|{l|WMGBxwvsk@AG zqb&8#B@anHdVpNXn#WzNC=0LYf$g#LmJnmFiUDP>o&kMtsA>rFozymRY)p4No$%4N zGYNjTf#2W{6~As41%gDm15>Y-h{VSi^*muylvAfu-p}QOtNTaLgPP;j$SSib(1ZJ0 zy*mg#r~&DR&fh;*-)_)9CMhEq&*R4E0tvQ^!?@7ni-|u*#=S=GDz@az0osTot zlrhWiiAR@m(KbJc8^Bj#Wjq=>Y=gOADu`2eX;;K*F{3}pO@L?OYEXux5Z;u$sY*KT zrA-cwDvRA{Zn07x%tF+Lzr%lI?anCfcg;MPIE zj(He|owJwU?z%x-jda~*xZFYbA1zgI`=Gl-Zj#psS_SeLH(Wh`~`x>;0AI18t)u&wgk+)q0pHa0|DG&UYoF>Lq`%L%KoV>AOXZ3G+1 zv_-p+$Y9KQJJnmRqz#SWjniEtQ6^thx5CEFw7;!g%#Y?s=ahr=DkcsS^_+`sb|n;5MJ zf*o2>yGHFb?oPMA6A{grBCk?uhhFao6VcR|28{z-S2(;k_F|C`>W1@DHKCk~?^UDm zN~)NQ-TFmW4P@ewP=5uL)0z|<91K5#fZ{W1KBGEWFIAdyDFh{I#31^S!AWI2Jf)wH zLZ6;@F)WLsu7pKH$;f^Jz8;A{nh~7lN8=1r)SQ6*ww#+0$lLe-RD$n?pOV*YmdjUR zfnJ54v?Fx>8aG+OamQ@N88n=eswFKU1l6W|lJ=498B6iI`{j zOY2e(T|ublX(U@rjWt0PHLQ8{Imaim^2A_w4qXc0WAf3uFmGYjBEpW|mF!de!kmG3 zWWoqjw+%(zcawy7uEY4crV}`XFwP)K0^!73&7qgSrxP5w;O@4alob;!JspzcSV%HF5sKC&B)u>z4{u_iHvb5P5D)1J$ zaz$0W1m-A?Kz1|q`XRq;a%<}KNLxW(UA4H}PIBGQi7>>rZL*CrM6)fi-E_?+(gX^e zmgX=f_nz3)W8Jl?x08Uf*JLrSd_zCRlN!0s{cNMMf)3W!)oFsc@lfpxQV$Nb3tZ2QO*ocZ|z?)hb4;keu3dKwWX zJ2c3IBHzEnW>*WKm7tg`+3c_37G9WUKgq)BFM_Zf6O$c)AIw7i?Sq~a|A;I&TjiY@ zfRNn>BdsYuk-2b`YEe=-A);k!^1CD;URcv0U8_1ev=Xy19TrwQwWO=rP;hyVTE%)h z3f}BHI90fAXn)Fbpn!wb5#IA6%(6U77gv3tK*IjAhgcecazmNZPz3OmeU1}jAdsAv z8IqN=my$!Rt`~W_3r&~ez$!l zH2>0}VjW4oxn|9zjnR^c)fz8Yk*i7vMCIA!VuzCQO_K%xZHpS4dbY5@kd$GGF6?AL zmD4dT8#kRDdqg`%v%nxWPKZ`9XBx$+u0%LdQ`Z!)6gMzE_J+?#t*F#sCo;>k5%>k| z1GLRf2zO#;+tk9*rSZJFzM~YT(Y#*cF`l(z*0dfS{gZ{2UyUh~31wmJ{NXZ~LjjhF zr2%;p@w|m2qQ;Qj@5B|mhCEasdzXOI0U>%D&JM?ak{ip8)~ zI6GITa0oi~^qYInJB1QPPOnotVhdvIQ$RVhyj9~!vY`}0^;xcuD(aYL(cb`5DeN`_ z!Jla777Se^#y@+DT2D0I-srTEyd_lLX}V`HkAGQwzwT+bd}UmX>#NPvZV5{;8Ic5 zo^!5`r&^ga)Wc0|oYUVNrSZsXn&=qf+kmu7WKcV4%DQu;K4z`)HkP`Nu%BJkMu^mq zBiM2!r2IYfl`WrxfXZt~h@mbX76#V~b0DmsIF8vgV#5?z7%U3|j5j1Ue~*a{)Sx3u z<~<3JZjf-Vb1+!VJa;X4&6LRUqKhZ`qHr7%|N}69Bne#pE+aH*t(#x@110 z99*W!`MA0pC_(i~rGY}^?18%8zXr%o6R@YsuVe)W_MLD>7Kg& zbwKN4UR+(4u1tD)TBoJmxq`vA3??DCqN#f0iooDtm(RTa@luncyG>)J=$0uyzk6@h zuc5W1$DPdYWc}4bAuxT(8pFBk?W%8lU1V#Rt<`A1V$o;@h*4H`h&9N*y62#{Ca9#V z#p-&c+HkHX`i?8cZxcn(OR>NP3+6<^sflexu+ntT;0gQcc3*LCjfmB)*0oc__0;j) zC|db7T?AeuBrgFvGd6I_0Svj1r_G={W`mD*`-YDJry-nX4@_HbXM5!lNSEnMp0lA| zzKZMe02V@oam#|hnE516crTsz&Xkcqa&7(+c0846RpC;rG{c`UW_ar{Y=GFtv0JP zOp7Miy?Qj`RhG)b=lw9|4FUFEa4tdl{KWnF*H`Om8hTf|#pBva@W=701pPt){<#7H zA5{lsd7-*0cMnFJe!UhP*4CxQldmqEpF)nBEP#eTXHYVwFxZc0N8z#s{*8 zgvA<-Bolofo<~K5M%KDj4(}rJmS*WqMvGML7(b)qB+oiK%aqLb;T~O;CK`uCIC+`V z`tlMynx~}Z#|&0X3}9pFj?9{i&C+gi>ittHZ`5K1wq_CKN2mRB>~tgD3FWMlKUFli zQoQC)n&Whx?Jq7J|puAvRf=Hd7fZcq%XnSZu zr4Kak-;J!zte^v%@P?nLmlj-na!XQH6jybJbA>2y7Rmc`7&U z=dy9lK+!0tnOkS^`ZnI%TT;Otnkg)|hw-h1E*70qpP=KlGA1F)tg+U?s4wmXWg6&i zh8q2qNz$FBHBGwpp1F=}TTlA3v!o`LVupWEZKG>u;<2u#bCJMoxcSzz_&%^c6>sgZ zvuN@?AaRIEtGdd&aTnSxD3}Ja_B zvxtcxgJDp-zFn8}G!kBTKwVSKxS_b%D5VkWjc*fMjiGbd#0WDFl3Xnu@Q+80LR(wz zs5vSFB)!GlJKscI$#C!|p&*!tc8$|dl*BdjY;s2Ip^p8ODy=*f>PMuR1Bx~jCj`S4 zYHln^(XgsAtjAPFta*C3lWv~2#Mm{Qh05HG`QDD%uKPbvU90${_=@sbD3!4c0Ihk} zxm6k-*>guC&UhGi1>4-520&RZY(AN(!Ii_ARd&aMEj%_%-R8>WT}yS^QzabW6J}vO zH1Dq9sIGp=+v>+kXLYXjXw%M&3bcDa?**HWV@+oA1Pv`$CKH7)HF=$#PP-}IF^1W? z&9qNNccV$fS4Q4BXn^)lbZCttydF8kKTyg~q$ko0roa#8?^LanIfJKWehy&yxC5uP zzcr^+Cxp`16U9+vzlMDg9kx0jJ9cBL;F=|?TwQv=FDOzP z@bNw4e(*UzjvaD3yia}|r<$l1Jvu4(uzrA08|W&N>K*{~UREZG1gOxqWInhJQ>KCW ztf{SnaLn?|3e390cCBNS3x*QD!+W@S4DZj}GGTJzA(u~{CyfjM+}^zRMw$1rY$m;3v-~K&g5M1lIroG3W$cXQi)3mjaMeZ;LGETABY;I*k+m(i*T{g zzrNR{)B6w#1crZPWvOV0agbmgloiMC8p&nGq?n1`C;M~9QACE1qk$X7) zcs&|Q8*8Z=O>?MiC3v#bY`i?kXWpKmuKOqp4A|+ zhb6HfiINjjyTSPiz}*pRju=0qQ3s}6(;3dQ`_($W;t8mKgfkW?DvbN_H`WU12h_nl zksT*Ue!3X?(A4V{f~5gxPED8!Yap)YjRk1OsxiK(G&A3e0;`&Xv-~Euh2=LyTH0Fv z8`{CJwX@MYD9!IEN4ua?VMhQd+8|SPwYWwQjHitIhl);;`r;lMtr3eFga$EDD z#~N+l-$n&Kf2l$pY0$*0SYtO!ruFtPj(6+`UbX8BainfIh&2LR4r z3?JSJ{HVsqet~}uhXzp+exw#0cHY2jHRv*3EKZBV2ep=W>hf-Ha_X##J0AAta&_G= z%twwIF+-GXIBKtGX!GV;#L*l0=G(#ACRwT-Dou)*H8%I>7`L6M_J}*4-e=C{B_B`L zjTxr*u^Q$oKF}LWCN|9(W~gJ)xG#nAXqT7rSJC&;veEyrurjt%KXVu@n-hIRo{S4F z@35Tmg^3G~L-%?lPP&1s@Q#yRwQr5+#~iexnX!=do=I2+z^&VRM9|Ci|GcXw-Nhd) zj|zIppLl2M=fy{;5||{UYMin|QPG>~}(;{9wnblNZ za7@76*#fr~8=a_Hl6&txh@xfy^+VTQ(l)19NlpK~&G_y}eaDd-7zS zuDPft%Hx^-$dNrKjixDwtOTCdwxwkT$5UQ8y@}s5%OcCQ(AD9Z=CpIesz%zj5&h&r z0i{|1JU1QDOfyM8EUx(S+6%Xx|{P(s+qG`+8im# zMS0GeQu&oJJ}u#1Cl?z=OhqFZ@L=isLCrnGs=%gEBP5aT~58uF<=rcIM6rfSK~ zr%#3}4~(00Pjr=Kse#F3`(#_(DOvTeD=WL(pU&-Arf;!Q;8k|C7B?62!KOb+EM>Xb zx0W+)|K2D=KaMwW6}XF-&Tr;CX+8aEZc4e_eEG-Rliz%arQaE6@x9(AUF{d`it2<_ZGTJ;9#Y(dAHts@T^8(D?N<$7 z>K^~S_2r`(N~iWsgVhHg@J8V_={Q)n$!GF(wDed_#aN?C41IeNLO#J9nZ4(*QzS!0 z!5#NG0cRSl&q1gf(a42sSVfRvfwCIm$OWP`KxHJh-tYGP8USLlR?*eAmiH|w^{For zd&|aZ6#uGwc6_z2b;t{A8n5C};RADrzx&*s@|sWjPOi>M+WLflX!wqeu^bz+GtMRs zHWx?>+a)7)SU;X(Ar8d0f=nC$*!+`_$Q`cG{|{|!j_r{2T--}D|0B`pPc@&D3$ zBsfI>KY9=AKMjumLGR&a{ioi;$;Ls%!O8h=yoZzXzvDfBfBgrR<^LG(Vg0xI@xS6d z|Il=V|3W;jf2|&uziN-^e+fRGf4v^F|2tKN_1{_K|C1`i`j6|Y@^4j!neAVy%s=px zf8i_t0#g2k$NU3G`Ny$;VJZJQ@9%&98>kedm`pNXZ|ok4`{O-*z~xK?#ydQ`9@8Xr zNu~sXMj3?0B zxY_>Nx%cgR@%1}&ouRX|n3?*tJc&630tN!L1A)kOt%C~_e#?4Kq}THJlN6+;^Mwe+ zV!1Ald)cEaz!!vl18UXc54x&PnC;BJGH;USbkxa?`=RpwOeJI?{r!`C5)n~j3fQV* zXlf#0YD_J276{95pt$e3RVec5c!5EU0HNu0W{d9@1k!BUOlo3W$CI3C9?)j7>pqWCA>hG$>(v z0X`2gti=FfB(R4lwx8IB5$j#Qo)=yY6J+%q)HfLK_~TK&5o@=+#vnuWACSaCB#UJ1 zaZ@Hlo@7Q-LZFsgDmzMvgnF{r_9V%MuqP+X%ZObe6pTUBK?S=~)Y?GYB*q~UuV^~5 zRk8j>K6Jy;1hxInK58m=hYlD4NZ z{2(M%!6%KN;*zt+vD~2~Ll?(&`(qBH3rdG>;XZ*3LgE`*I9T%a1?LlTK*5@k0yQoH z3a=1;gqGJ4SOH>k!@?FOlY&H&<2P&Ym+@=&4^AjE{XdWhwWS@(;oYK<1lqXYP`sQ& zSz4J zy$^6A((o|?U(o~i?AP$ZMi{!;H|3IcX|RB@b~z7+*Z% zZcP6SjY$?vR6TNBlDH{GoCkdzePqJ7RL#h5si$1SrHMFit7K%CosrMvVsoacP=rW2 z9#1?v{M$xInW{b}Im{`<*&EA;3UVN!} z3A-#o9Alh*o8+Y9FLF5F>+CVwQH;ve;Bt@{g+C56T!fRD9_7mbA|KhI-9GXEkoJzT zq67`Q<=M7v+qS*;*|u%lwr$(CZQHhO&3W&=xtRHqNoJDjPE~iOepDrubZXUlCiUS5 zIolw5LL8l-X5J3NvbNy^f$kLDfKGqtyF$s3TT?^%_9eYQPxS)iv}FCw7>cauhLg=j zo1PL-+FHu(sMZB<2x9fu1bU=%hTgp+zaqM%W8&e)PT5KG1UAG=55qXmS(?BG4LYK1 zN?sRu(0wF)g?0;jOLghvjp@Tt8dO|xIx}G!$u|dog16Wuf?xeQ2}b6E47(Wy_H+;8@HvB&ADDdQNbsU75j{Z!Hrx1cwyCG<1Q{ zdcnq7D&TPlBr^K!dnMWGbmv0HYNVL?(M6$B1`RUwz|LE3u=IOPcZ)UuDA7pXGjk8` z_^Ix}>{~0R+!1^QoeY$^;qnfp%&DHUS`Z~ysWdA;gXVBz&CiscGgRbv${!kPMGxDd zjQjIdqV`c_{r=kmnK8%Wk#w0~J*O6aKyVAe^|P)+Qi-E%vf=0g*6rhq_nwk@A-oCE z!{+rrM5|T~o?)2>ZI0e4%88(Aik*`B2|^{|8`1vdYCzdB)Wv^6i{l^$p6v%~yXYlF zAS@?Ua=$~(@%m>LmjAScALV&-OvZAZJFSZq(aXPJuW>)ynkCf;g1Lfq2w^>NFrgxQ z)$+kS#P~wbQU1ba8L$xs%pshJ`9a?ymdP4!UG5FOzLQ>?ZRi`!Db6%Y_*OCw^$j_+ zVtx5==FWYP0M_ilRXJe48t0SY4y36HuqY#y8W%L{Pr#6i>%yh+g`FkjXeV!%K0^h( zlVZ#?>L=jtwqlQr1@8z?ENcgQ-S?yq+=99fKc)|Pjfi#=N1u06Xp=xk&_R9yuZ6U& znA|hjYUZ*-@rBFXuhu7z>=p|gqw0lK9{4p1%GTFmv32|u*ocrsb|7VsTFK1Jl z9Sq8zWYv&LbB}jRcJ=`0L5f{kxB*-zn5fOM!9JI6@TYlAhD$5BvIjS3aPb}%aWv~# z?vGDaDP35+(jv?n9-k>*zoQGZwFll$7@3$teP!BG0;*QG@ttZ++C3{XVa3VeG;cI?0SYPh zD90F~W4?g_XG;szY=g|cdb@qkmKdT;OWvUO~Z z(gBX7mvA^1{f(U-h-YPW?=UV&_sfderu6q^M}e@J%jJ?hqy`Ws%CvKHlc=K>%~k;UV-u}9?seAc@=XK$*;ovKYu-XQexbBTckCD7;63zLEw-IpNZi?9p z4Ve{M;#ymK`(=%k)Z?06rFC&OS!n2OgP7~gWk=Iezq>12i@$SuX|-z`OlJ=qS^c*p z*NbSYi>t`E%GJV**nn6v<}Rcv)$F;paqNYbbj{Dca(5eZ`=ETAK_O8}Ce^JJZs?ZE z=iL`=D$z#V>4nZh0-uHdJ{9YTqmk##F-iY{JOdF+eWB>05%IR&Ki^z1BS}fwquM75 znn{XXq!tqby!EE5bobzaQqJt97)b0{ z1Dr2x*q_yLS=w23#`MCMuw0;6hb%2W%#_?%F(Ci4-C2SH^AQ#itjlC4k-E1MVDAAI z{0;fNCjqjV>x7$ff-IlVK)Snb2#gd1!VYsCRZ8p7Vt0l(A^#il>thnbQ>liU1Cq>{ zRIRd|OF`mWfFJ(x2#anspT7kxjm^FmNov1f!&C~#*Qy;Gr!-d$t+1~$GuEG9lM3Yz z7f{BD^=2lHXp@DB3>l+I3c$w&P!rtq$+*hycVg9k9`1sLB1)7TLp!J_o~A`^t{H>( za4M3-vX2@OZEDsFQ)f$k$LAZ93#sX;yi;>}$*C=~y6oIpF6!!7IsAiz*0i3RcDHv4 z!VZfHsoG93w?eMPc5ZpiuU`?Q37@yqkuBS+(Sc`ViU`%n8KT-pH|~Xu?Vl6D+MmK+ zF55i4RH6{pH`W)p&W7r%yj(r#$yy!+sijxk!Ej{49#Iy_1zp~ZeWb-o#YW`k#t?v# zIWJzg{>Bg)6G+M2Ujbg%EHU9KZ5lyzx9N8U48XL%H76Vw`fp52{Tfds6g?h-Zl3-p zHAaZtQXP0FWTQ&dI~$lONaR2y5mE0E1D|dJ)NFiS@U?!{Z*lSTfkRd9k`O}~8KgwX z%jM!*c+hy3e-#0;1Pds=Xbzq$mLfhS2TI}eGwLAd5e6LB*W1kcch=h5{+(uKi@36# z3l}Ds5Y>kcAJBN=fF_Vv+QorNxsO@9am!$!F8HCSBeE7Ws6*nAUtmOBl+Rj%qkjPagZo4_%spWAj*xn!pq(x?8!iQ> z)+4JwBEAS(lSkLP?FU~#LRZyK#4=3aF&$&WE1zLhdc^(FN;HAd0Z(t@V$fW`|3wn5q| zk`XC086&JGLIRM~B~*a}Lv|J%ZvSF-^ho1qR~S=_Gq^~w`JFxFy$(G*-@|mv3^Eh8 zE?Dw7ox!l(DQ>zie^$=KQj~hKe2tqYCf*%PjVr*2HWNvcHsAlzKrKCWCR|k(CKXrD zF$rKcT%tzFg_=n$ylL2p;*NQAk@T@a5Szq-ajglaI$PR#N zpBZuZi_wh#gLHwQ=ukW$VKY*gp%>ZnOoTT;xPBPEMC6E3fo_4cC|lf6yfmKKE)AqU z7vCb4a5o59gfpaQ0E9x6E24gC>dHT-!e-gI?d*nzqvT_Z-2wX!tjx8<-fhK@6>-9nhBAU_mq zQ34cOh%}>a4u*%I;3>PAP62=imOT za^$!Mqi~Oe5+X!AC}V0FYGboin0I11F{%Mf7>IJM4}Y)3tmJb;kK(Lwx3;X<6W6o+ zcbbnDo$#{Zh5fVrvw8De`HeDM8C$v764$bY1kwVtnNjnFlOdBg9GNrO136-_^q5#u zT3J#Q0iNmtkz@zjyI(@eKOZs!+JgeFkb}NvuSoa5PvY8eWjo_iAD9!MV((lTZ2!E2 zBNpFIyw51KUX>JV-juwFa$J)h-W=LsI>)x3s~swN2-iP=YqkPIc)=aN zCKU+@t-u?8+QsYpfrGme;BDN;1A(xCbVLw}_}VZx85=kI!f=~W(pJO7&3c5Kgg8t$ zN)FN1VU4z%mbIp&G!37sddONyn+evnXkmTY2eKqJaQ8sO&FZr>+M>d-SgLw}BQCln z&8i{dqti>q4xB;OsPr?MG|$MYQoZH_Y1^5(3?wICt73J@IUa`GFv1)}23kxeiotfa zI9Ze*?_j?CyHI4G<^k!39pksm$veZ;efQLShUghUHj`YHw_M~NN!AV+ybhS!P8ivL zr5y%r3~X-*Ff{9u`K#ajO|^92xO88nbYGxUKYo#Z);#U{Ncz1G7L+sC(V=?a@z|LEfJ!F@y(mmya;Pr%U|hH+Je}Xw zPr(5OT}@+3myRS&24M-|@-A;I)|t6rEYexapO9^(9#+Jp>QJCuUQF5unFlc(bG$5N z@+r-i3H4G@5bIGlQZVe@vIsam>|L9@C+b;R;9jJv_Rny-nlAA0saBWZ51{v(Ldsb0 z=tocVbYg7ZXeP-os7?ozG2zO*-v(W&2bpJHjvGA|9>^Bt!*&{8G!fm<7ccVc=$8%h zZ1K<{LvPT*xSB3Rgze}DuJC=e+Aak0reP0DSGV<^;)XkPSA-Vc<=EgszZ#gWKK=@V zU_I-KyuX2S)sHkXmEkj)+w$cYxqwk3?;TYNZTRzhz1#f}zeiswGF<><@$q>*EH8<5 zSG*{Yc{a8vjyYkWB$dOIZiK}%LoeEJ)6&%P@CP7yg&}X2p#sXIH9IKuC;d(en?*g5Rx%d2+045>54!F2VC5 zf6X8#)kjTY${Svi2NiN;?Q<`Mwt9Y4ezz>f{FFzrp6D)$0+xm!2u#->nlcfska`P= zVE|q+c;e}Mw&KbPoqRW_L}~HMBgAQe>FbQ*jQ0%EE?Y9q4RuL*78%P;P zDDxNmo=S`E(yQbIa88LYXKRdRx)!lH?F-5H=5HZLTGGT8HlZ)?(yU4`3!V22%)L|s z30)&A+&_`=-u&YCE1!>TR+}Eau543R z$=dV(^6JC}xf8M$wsC0=db!udR_BzfX+F;^XgfMz;(a}HG&Ns_p zzsYqdmIU6mnB5qe8mN=r3TXh97BBKNW^|rBHlh(a6Bt z)pYiy)h~f+7Xnj16rKPT4=CN!t zzO2()UC$eQXj7}gc8)aW5xf7{LGZFyo?Rn4-R_xHC&`_fXKpdC6I7dqO2!v8w52pU z4joxl;dEA3dC)#8cD`IOH>a>FPrRowzPN@1yWC)JE#qEU#y&HMX5~LDdJDpvTwS6q z^2vrsdxXd>3jkDC(%~HF}p^)IQ`3AX*tSA!aMbG&GX~|1}ujK0_fwl zUy3NSRmS%2{x{*5F?>#5JN+ZbaK6~*Z3p|Y`L291PS`wOfUGKfI=)>w(auq>*kap- zhhnjK#)kd(d-wR28BKn!%hGcLk^3WkA6V`#e&mJ9Bhlk9{?7osM~{wv<$q?68v}GH zb<5HEQ~=Q~Kxsu+N+E5PDvBIdb%E(~D&PMI_W0HEdP%Tc=O3{&llC_`kb+mNq8FJf z)gp||R|Kz;dj>NH#JG(C)`1K$IiFsfgyk+fXH^D*Mn#&&Cns|SX)$F zCCItlS7A-FYXy>zgEVqxrk@N zES+0IhJTdqs`08;&XQXoZSG<16YzAy653F>&deo{#bB`F0DS?2U>(r@iVl)6gLuTm z0S7FfH}HAVD*b*W$2&etLyzDP2A{xW%y&*m#NNem5S}A&|94hz)b!LthF@qG4H`xZD>>5HMPa<0k3 z#CT>RM}0ndyVM)qMTuMLC82xc$-znbqP4sQ43ADxz}xhj(bD$2<4UZ-CDF7LmvHoQ zv1w)I1E$$3B*i4X(TwKySZtl8)Iy?7t8&o-aJYxRo=i?lNwuf)i=RU=S(fUS{MY0C z`&c%~xAsf#oo@2C`OB!?Cod~$Rig>^8uB_?17&%|!qn1sey7k|@H6YBbi=iovzt|x zE6*6UF=ZWEhr*8r^*PwWbndQj4hd2|QwupP%__mV-n#l4V$)`mAoC>c8fjA!z9j3=-ye`T24I%kZoNh&;T%#j3awfJ2f#g6(LBO8KZGW6VEXA|v}t~_?v6%_>(CYmY8cgf8&w7K?T zn|g`A^WmY!p=b5e7B;?VOMi1!)s+t>4%>1wx$`YhOoRYD7F)+^Mxp7@Uodo9DyB{- zX^_J}m^C3Unp#SW0`NNjVgmb-3h-_V3LO$~!f#*{5R6N8 zHH<+uxGBdcMKr8Y#6(gulook3UIWs5oP_aQ+SSY!DUd0WU60Sour3kcCq1^1^+g%r z_!Nn$Tjeg=jyZX1;a0GEdIyUHD_K9WGj#{=vEe@&u|rDaQ^<{_rs*yI`1wAboX~PG z>!FWf+rhpS=GVu0^syWDP+=j+)v&LVfF_K_jg;BtJ_^~g{hQa842&g-k1pG>RkteecZ z&1V-^&u1BT3T*3%LWtCT^?&unu_g#*IGCs!{GRKZXKL#SPI0cVMq;7yOwPYHijvKo zJN|_FYfm=u1Z+bVO=sZu@VM{%jrN<}b?eYERo24N(yq)pj8antEO~tx9*LB0PmV&M zHP#dbISR>wnHio@lu2IHN$Ln3#Ky5-QZ@4DAn7hf0AV=?FSU;kk+hR zzNSM*7H6xGUHij!0+E0(6`kYzmO}lc$U`0F+J_Qm>7YI{=0a0K%-L7U-}U*mIEq%8 zSfhzWO2%W8qKxu1avC9(Ga*!PLdTAH6!Ed4sImRO1{1_DQ-kSBQ^e_Cob<8D@a4oB zfI=k=q_Lq2Nq5fo8Bqz)$g4#R=kT1e>f`gek>82(fwsXfa)j330_C8muU?SOvIf#b?0aXc+$ zk&Hf>6s|V@jeQ3${7C8nP!nW546Ke*x?fKvB{*;{;EhQ=Y};W?kOn&r6}T`saGp?A ziBJeyogJM9I|VgH97?Pxm`I@s9x60n0#Y=P85tXV0pEb0JzPM5G3$`1RvTC z?v(IPJ+~a&yH_7%AoxH>A_f1Ct9VmsoEcxNFp^loH#ed*b~tIwf9mIaMDf;wvOK<>{Z(;m!05HtwPFoZUdvhcz%5jU41 zFfFAMa3d~mZ+*Wht#E~FD*Ub)+eu+?XP-juq*ssAS59MC#Hub-vWV7)A&j`r6dRy*==teIX5h3jY?Z(6IfDZDYr3fI)$F4~qgMsn*MM4E^Mobj_mcc-7Fc&(v%PJE*+dg?2;seOh>SHqvK)o|D|R z3EqM#uL>hi#ahqS-f+1&`~Z}aKx*%-@;V8)>{)c4epPX14y{C`u67c!=z5448Ah6& z3R~mGy%@VOzNM*DaJR|UhqHbk%!c#ws$_ai*R(kCeK@_@@IA5Ja34o{(uD`m_ekv$ z*UcbdEfW@s7s*m6QqZhQS>>tq+(qF-{3W%B5RUEDsCwEh_Fa3f`{ep4)rR=SP1O-c zgWf2pdOH7jacZtgT`cFI?uVsB7;puSe?AEzdt(s#mo~hn534Uq{FLe^J+U57c6{Q% z2COXVAYl_wm7>kTRprZ&31Z7{NPCy@oQNJjt&ZRjje%VdNIBZAV;fPVAmcMNNphAU zE^08vA|g)C$kxE#z{-fcjw3HNMOqyM+Yp7Kz+h?m@(sA-|&5y7iM#O+gYlOBb2+pAxgd=o}7i$K;XEB`mgn-F}h)GQ`V*5~=03{?y8Hw6VWmv9PNC*;wwmUqZyicnh zU`_0Kg3cfgA zBL|tz!g{lcVVN!-M_jczZn->HHJk#bx9XM!bLa2P0BN{gK2HywkaY_~zO=V~pl{`y zuB?LGtxmleqHG`UG^ZVR)9T(P>yL^Hs+8*WYld{KiCuo>pTK>Hg)d*mIU(*kyo#T2 zuzfMKK+(#13uo>#+;2)RlpaXk;MxJz{mMJ#xBt=n?G|uHn;-wBF#s3=85dD7Jeqh( z0b!!H+IgaW`+ZOp5Z6`lXWFA@4 z`;*4k%c7;SsG+0Yo!_MNp2*G!IKXEW{PJ*Q&Ys;xZTR5(QD!Or<9?w1TZ;&LM_Y9F zJJ@svSRLAa^%EI%-trp&Ig6ATKsEUj$#P)n$5}YP{fU-&!Ml1=gnC^LN4e3q^?I3V z;^RKs{wX}Cl2>!{mGR96*|`(0nHTX{tH%+>A&?MC}``ZN&g>GkO`mlAC<<+#`3?Bf-L_BDai8wixg!3 zU&&qnCn;!0XZDW|bfhz;`wuhdXs2&zOlL!9MCasc`~Qs-Wd2_PBmb|Q;D3hpf9C}0 z|0gHN!ivxGpX(nl_#Zy-KTP0%>WnP(|NZ%YfA_y}f&cYP{8wDye;bPbk_%-1f4bY* zSegDSdHetL%`vhv(9{1PU|_ea7xL;lpU2G9)yzxwb@yw*_A=@-BR&LikXZo)d^d*S zViZFQ!yYJj>)Ob6e+-u%5%GkARbmi3!L-Z)u}i`wyRDG{nfw)T+FSJe%`HbGm1F|j ztE+FW=Wl!N)!7tN>C{yEW7DnU$rYr2P#mJQ5OW4&J6F2sfay3_U1s}Hhlr)r`>;=t z-EIPwtsRP;I>&15#{CclpLN9|pX(1}OWWPM5tg|ho*<)Akyn9QQbIIhu5Q?L z1j--Kg;8P@Qe?V_8j+rXi38txX}gyk2TE_iGh-*bltP*_m!*(}GxsNLCmM~&l7hf8 z0Phgrm=PjS4QoM!p+W?sp~yLQEtvMtxbipcvUJU_AkI+oC-#k)p8(c^+$||4yd|`Dy&&85 zE(IU+N?-HD=6IiYo_MYX7R!md<(?$>4T}UV^FlS}Y@QUKOsNMO@1&J-e46L9w3M-_ zbNm}C_j#+$0G~XeJdks4NSu(fMRh|N+~K(HkiW=(kQ@Wac^bO!3I{?(4DV;fVZ5{b zRSGWWRhppO9+jV9o}ie6ditPK^k9BKlM8$VD${Bs{)#AV2@wAwnMX&j&YXj7LTWj* z8)>b>3bhB__45@iCueES=!o8s{f^%e!7K2c{Hj?~@M?dPMt_urkMybonP=X+K;7H; z?&}0PV{rmLo_C$Qoi{z>jyj_3!onL6yW1t_d8T|;JSjN)r+pYMjYNyb7Ul9gAP3O| z6}98O@axfv&G{pfEyDLF`O2ahjsw{)Xic?r{kCfXeAx=`pzW@Pxv)Mw~R(5cbPl|b!`f)qX; z3qxFp=gE`R3Tn=wZF0KqI>eqmOa`E}2S(u&Lj3XcOsWkF#4E)R=w%PyCeRwx&YLwS z7HvP-4ax`hcC@$8w}5@(uY37td1(1*8J=Qq;p#lxyzD~Ylk6FwBJ#M1`5LDP&t2E2 zh%dq{{H?)gL*#lY@h)C?jF;(AU_gN$c@X4wFc%bAWMd>7DjP~JO^=dSvs;~;#+(wS z(JH{haR^NiVjf4f8DR$8cQ0x+Q2Lb+TwZP83nKR*K4;X7-_SSsH@df<56mXV6NB9g z+yIkz4DA3@dOe(KK$p^?yBmW}%<4gA@U_bqx(_yA_~(7*8}kqC55y10KUp34Cde1t z7f5ljlTt!OiAMSTl92^wbC8B;b#aSAth}rOox*4t(o(D6BwwMAjJGg~8JAr_v`wk! z`8z#f=K1wg;}gS&_DAWH=acOjot_o?UVP|113*cPdjD3x7dhl0I}J)T;&t#fmO;B) z@>`yp+!xRNXjK|a2&OJc5Cx%#A`jA2wU;k19y zPlylR(FyjM4=Nww4{nCoF#iVTypEA@bKfl7oXJ%Qq8Y45)(%A03qDi?W2K1R;Jxk{ zKvS$o(1r*OZB8-#2hmzL$CO)C8eIR4SUl7(KsTuOC+#zm1sd-_*nOiL<5Rzk6hCiI z^w-j&8AkWNUn16v+9}U7?~0TRq0xKYG)c@Zg1d9rrNCc5lCwWPK_7sgbGThFIX^^S zU>8JAKp#}J3PexeOOjtWU)EMd25!{Zf*==cZVXQ&u|LF&`Vh)69>k#S|Hh~=^^j~{ zR(Lnhci3rO3?Xp0Z+S^%L%R8ZwxfhS3h;o=%y_?a7?SW`&S9R+ifH3+vtO_qme;%h@^G$#3c4#=(o(;8 zdKy^IS3*Vv_LAwFqZ3jOUeh3)EF%u}s6Z27FSNDDUS>u=)K~TfoJwQl4!Fw+IVaG9 z57n9rPBZY=lq5Hd{2mEwX`#B zri5xqLU@E5H6}!806_2TrTzaf)MZA2cFR=mFHsf?(k4o()raL%L>*Z7*h6i9_XmIf zom<_}5qRhkk*hn42nhbRA;)xe&h&W|%uoNkNa1eM`hlZ)SCINqkeX`8k`ofy+CFi7 z{molGojK%CG#$L}uI|Bg{jIaxBEjav$EMm}JM>4|vOY7;0_9dmnkJG!#TyBHSv`-CCH1Y_-=F$^pH0!HdYf=_H%Y zABHlFDDEkaJej^JMSG6(G&8W5q@5onxx5k!>F!Eur0V$RNR9$yPol(*YG1jCbl9SBxV&}qz4W-9^194HGH()f`I zh*fi*+CqJGcp=Wg(W{HR=XKLFi%_@C_BC25g_$8zl|Wa9$8!@q{81=R zh-L*vkNB}heB_97kM+2e>t)Ho29M6mY|NUqqL>=Q@ahJx>U!$lgwFWASu#U=ylqx* z{pWsMO_r}YZYc}5nqdl`WmD9WHoIpI?7$N}9=~sn4npTc(NR=;bE3n?>Wgi8Qt~-_ zyJx1{(WGW0qQZ%ZC0OF~(#b3rol<&WPeue^w z>82YI;YIR+J4c@#p*E#Hanna1d)*a!-Y__%@Ka@}TpN37U7UMT7nC)r_p4uTApJ&OTlmr zNNOtKw^)Svas;t5NZMZt&I|+`01VJxBzk-639E{@Wu=jH-Zj^KbaaH$?|jk@r1G8?c0be;#UVh5fC#tnZSQzE|kVa#Gw}z>*BuEYS*xxb-!tR0c#yG zJjDS&LawTqRD#Q`sAOo^C0vNLxnX94Qco_vADs6auN==!Te|^KxMlYsWsZGEmX-$s zC1dcy5fj7-priVO3XxnuB$aK`%mL_@HR_nmfk3koPCszpfj65<18Q$K zr-h#?8TL051$doBgX-dwitnCH)R zF<64#q3(SH5UuUTWu!DwY?Cv70zz0S^u!84DOSx(r{Rnm>2**)en9i{+0gj86MYT_ z5!Fxl4x}8t;uoM9^x5rxQb!cl47L?+staO9m6YXpG9m^6lpuu`Uz)yni=kkO9J;u_ z8>0z+*FgL|sN#7OTiQR*pKt$UfSsfH+=;|%H$dyalS)HAKDXL{@--sa@U(#kopYQA zk{x$rDzA92M6WcHW!~~P^L0U@6BAFm4u9m5p~DhAy(_@gtKbIAQLv>^JO6);-jZNJfZOUZKdmHv{50odif{fpj4-1<_XU;_!SHy+fP58Tb3Wpd zzvf2<;vAyMLy&uP@o=-i9~=Di7ZZo7Qbv63C+I-_%}3Nt8P@*KJ?qd;|`UWtdP;&shdKnVrS9N(FD z{T?f86ya&uDH23N12eUW?0oe4o?rj!1b}J%Ue79if@$G_J)%3{32Y+))#OW#-8-z> zQiW>$Dz{HQAL``{h-u#f`|f=R;Lq|88YT-4t_BQJl^jyyGscOR|*KD7n zVQvEiw&$+4+k}d3oMAas2TxKzSG!KrX;-Y0J?V{b5Uj#{12A$BApGge0?xIv|-Db#pL-q!%ZGlmY zkgZi;alT->aBPl0SixuxtJLYN3|^3EK#<8xAS0#=6Cy~VLy!m{diT5$;1S`<(Vc)J zFd5B)k75T0nM3vqD8Oq9ge}w-a+S~A)PFD6&v0vIt>_|MUZu*UbA7^(ygu*E{47ez zof^3Q2HWW3PWJgmdKudHwjepn;8})@d@s##i!Pd;+Q(IkdUg}`w^SEwr zE(S)iv1VpAOJ{7@SN|Hc)^){d|D+kJ`cB3Ch;eqBzTP@MJ(Z3N%+D{b^Yv`<*uL0X zKsifkUfN%%2zr>{jUJZKSTBlm;I3{smScb~RnI{OeXJ-nR*y+!_&eF6WK7esIQFm4 zQS*bFzc4yLOl!RvFF+4PHE}iVF0Xiu9V2egTh9CBPy3iymrL`TIo?FD62fL9ZDb+Y z4_yBhMC!%MQ2LNa6w={iWWHPAo)YNM#&=na%l>FHfDN(`?CX`P$FL>+{Qzw5JYEzyf7D_nc#g7*GBMuy?&-bbrUO3SqwP!LY?O?rRiNS;5ype!zIp2EcTY zL}tJ#zCkf$mZm&%5*zg7#YY+U^o?0uoyn+Ohx50Th<52=Xm84lPZyub0i&v`^%Z^gi>M9t)(+5I_zHSDL_c#F*rh7W zV&KG_V7SBl6N$k;WJN|Ad>1EhHPfHB5bOVTHUC|9t(to{i@e}moBoHs|&cP=k zJrpX928RuIl*1^de{rZIWEL(LubqC%+vkVq#&HtlG7Mv3uBgSh`qbbqOM8o+jd2Ku z1StGfT-~g3WhI~hzH)lgd>&e( zhN3bp7Bomj1;n%aFlcu?N}@NZwlYpp8ukv;=f@0*A?x$BS*2N<=gxrV#!6QA`&cWk zc7P(`{4B0^&v_r%^(r^U6!N@bdyGBHwUn`EPtWc8_2DYbKAZe5EaiqOAN`@#Xj9Dn zV&|qT4`-X>ON3tJ_ouHG+u;V&b#QJrPy5PMi7$PL&jz8-fVJ-Z47%Cx{KlqEShQxu zDB_~8tUlm2SqB_pPKaR@uwk}RAxUACC>`ML2B=7bhdJ&ncYzIpI*}cnciIv+d!&lJz+X$E}@`+uqx3wuAuI3O6`_*Ri z?RI=BT~+}2pkf+-d(dYqcH+P{i$eB^?pAJUx#kjKY8aw=z9$}DhMahH6$zLPco;ty^kTcY6Uja7AS~SRA+OE?J&tvThunvGjxnSFp6n(_& zb+CCHSYeClyNJ{9x zsO&Hy9H^FI_NDe$g12&mr$f-pY<8!iu4RbzG+XKD@-R#Xym&F%LnP1a+8anVPX*5C zNb+p`Wy%nlHcD`7a(+3=Zi6}LbXXYj(v6}pxVNLA5wIRr%aYv6O%IdZQV0I_MCu9LY5+=N{C>$Pr*4ubbW<8adrvgf-@ zzVtp821k&im-M2j=(*BkF_vzDfvo8mh2TL-VwS^A;S7vwIi=(}1lzT!>QkqFSdhb+ zNf1*fyKzY206v`L7W|gZ*?nktr2(K?XPB5Lw9x%-c0@4KL_+kiY0#iwBq6_HZ3t7@ z)qnGKwl43F;%uJsDYkyVjbm-@6^X)0r+?Upo~xXOUwL&lgqF z2LQZ452anJx(vZuzkh^Ur*F32lHnkGZK^?rRJ5bW7#U4Ai0&u6 z4EQSV_KRxQ|D{&-wT`%E-tz7u^(6M}w$rs86UL5_J(O}|*iP)8m_5$i>71%vXy5e8 z_s)MdylM~1^6@e17 z7dp9fdq|4T-Fs%ofu%@cFLDW-)_=u-=8aXoy?680$Q8Jx4lm@(gL`x0EJvG%?bIes zlr*ayk#dipHJtmzu%^;+3e~XPI*q5#4oVr3=oH)OwHrQoup!z zT{d234<|FkM0Q(<-?Pa@YnPpKJZlf2&%KS#jvb~QGB}+b_FxGxuDvFq4ytYksQRYI zhM!OIvjSonMQ5kirC6;?{km6(QMQMv3bQoR!|J08sJsEmCo|}UUBrJQEo1;Hfa47q z^Jy+MdIPa8s|exsKwpIn*I+A=;(hRJH~%~I&;FscztU60v58Mt6)&sSni9jSx)x*_ zR`dN(Kb}(8uMY=&)zM}-=$|;fY~mUK34FFQnkEt4A1@29{e>_#WIr!_Bw();oqJ?! zB+y1-&Ap6mCL=8~JzX=gm7uQaDQgjXb$++A^w_XU_^B8;g|J@Umr1cb^@b7hprWcY z}6`nmbOCu=D9}s)JMFglOyBHK2jiqRvsy ztQ3!0f`qJQ59sw5+%F<+)vVEAfNBOBIWuNyM7Q>>nnt$up0YaGu3^_><0B@yMX-=4 zLu(?U+P!PvEPBbJVP#Ba4`z+tB8C)!^<_i@oU?U+-V_0{Di z6yU@fIE^i?8Tes%cX{dQ&r76$J`ytSeW65HYEf6nM$@VyRsgXR7IAud}l2 zzxB$#>#Pr>4C}H zoxs`XGy*1q?zBRN$5RSVnp+-Eug$c-A!zQqYj?JJOta1X0ObM8h;4$6f#K51)1AJJy3qOuqNE4<-9v% z{*dMM*V{~0_Uh_Qv*BmMT?5StqOHFO5ksGuP+kU+&@{}T?@>q?g*I5B=%*kAW(dGY zC3HTc!N}=zpz87mlX;>Xv4=}~F2eg}tu02E=WhYU=|ku4t+b9VyYIs=VaKPe+pTQM zmVzA z?h#EW&60KsPYN3K6YS@9zSvc)N|%vm`2n$`u;-9Zm0-(&PvN(XaO9GQb7=6)U5f_j zo6Y?Nw6qGAN+p7dBeuaIsaMd>omMx>HHT}pa_F-cS z7!sUHAA@bvMx!ScZ*?AJRr3-re6II}>fGTL1ZLr%Z5Or57ehXCvenE6pSe_PV!E=N z-6Ohkoo(d`G)=OyoZcc2p8|(GkDrDM1WBdY+00s{?#I)aTp~Z373UuVYSyHyXqec<`+d>D+@UIL=P^?BaHh5@{~^yxM-G&Oa5ohtSovWx%()VgB3TC*6%@@kvpHN(YNrINKTLPu2MuGMG`)&it zk7QFCbJYiM0tFuY1qp56Vf~dW%*qML13m|hfboQ}ed)MEz8kotRUW049H zN5g0I98vkn<3|N`M9h?Qpv^n_dVuVEPh5cF)h?V_9-)Kje}T(_6p9&v$qNMz#DlY8 z<4}eksGnIsEmI7H;0p98$G}Q~S3yMtEJ-|6rHKb1K-Ke=xwK-60(VaOUMN$JN%w6Y3qCTeGPaz0%m`w-f{ZgX-xaj zku;(8?~|eF?msDqD8dBN7Xb@%-AwjMq^J8m2QSJkVRz4JdQ=zyv0Fl%Tlz|2Elmmn z>gix6xGV-cMW)7XNv&wjumq!Nf>BoAf%E~zQ82}fu(aEYMlk0!ti#lixxEQ6Ud>_O75jL>~Wgk4l(#CuA9RS!Wrxc&8YGa9+K)AKJpIkNutpow1Iarpsqzzgep=dCT}xu zt(vx;U%P0EaNjs`JpW&$-BWZdZQC~LSTmWiZQHhO+qTUaXU4W|+qP}nPX0Xa`)RHJ z+gfX*#^}1L>+W$^S9KSUlO|cQe10|1->+XkS&1Mm5ALwWaP6$FsMnZN8|&ujwSPbz z>UYCoVa1NzWOT(}*CohTK<_CEG^j+9^Cp`{9^kDvXA9ObKQ-4}wymCVZLZ?cHn(7g za|+!aUt{T+_D-lj%b0n-eam~ieoORnx6;k%cZ+?=o2@ldTdc;SGCW2tw?SA z*J_p9jerg#LIz>OqZ2!iT!;Xi2_-#%b>b*`0LS8Gs#N!j6~nxI^7N4U$rCuVN{N7o z<}HgywVA1vGorC)EC8Y%KYDbnZB-o4Czevv$L>BnR zj>J_Z{p}SKR>}F@&F3D$ylje zKGQct90qT&a8!OMboVXCC6TL1J7i4vV?N*zl>`p*e88d<4cy3lY}j6|-a-{(;i@!v z#E~=?-#Gi`-cC1-x!3hcEh1?OUEdfQmzZ{8v3>GbYil8g?(qSX!(<%{(RL4QIN96j zlaK{f}xA}ESnaGRd`aVkiGX=`ZPV(LV>7;2$K zMFLw#IdUMfW#SSlELIPqJ)la&oFxj71w7hvZ%DS9P7d6~InG z@{>0}`Hvd`rmLUORCAq>AxD%B{is5g9tBFI`B(r3XNb27$E)y(b}rp0XJwOHe?4!aJBtqb^9}!E zs^>hF3>DFFo?!1VTaCg9ou19>LxNWyMh18|IVLrZqRvY?o7}Lug1kb$a+X2pWl!jD zOmtqf4vQWeU1Yr2ygH3VpDhh@KW$AdoDB|BUd8NhHn|SpNcLg-Fglz)3417wq&{}G zNZM9CU=cB#zYB{f%E|3`emv5S`R|Y`(ICCzVej zGLq!a=${&#)Cq|6yO&Z!h{L@*)s7)VyG%Ad$HK(ycrlLL{PSdlS+?)gw;in0@>d$--oWL6V`f?t{s_ys3M?6zZXZ zhparnSSq#djsBPl@9r0ya=*2^ce!l@WxMS|C+!t?f8N9_p?>MK9F`W^W}Ric@8mna z9dAE0f@|}}QKq#Y*}-n_PL4RSY(U8$Gj4;yU-53J|{TSEtAU+*`IMb60yHegFf%7jkxm(Ng}#alWK67G>wJPF67Z$);c z&UBFROeh$%&vumu6bU9KMhX-=ksU-%;5VO9|F)dLv;(0;A1a+ccjo9EK6gfV!n^2= zHR{6<*Nd!BlFR)&9y=gew7K8rq*lGZCxn?PluJ=3lc(ll8g@3p2WiT{rua%Dh@>og z8hzqc*`cl~auIZ=ASaAn-NbYnl!`>18=!MGlwv8qDsNr+`$3^3r2S;f6~1hTX5C3m zl!+H6L?gMYPa+2FS2C}0CW_HPosO={mGLG`X_Li5@wcXCXW&jxUFp-zp4=$sH}I2T zx#ZgPSx=ody2SkEwQNQmJl~_i>4@$jVg-EWI;+(cR&ft051ZrDPG)KF@|dW}{VDMF zYTY1qF;1VB{%gWni8>`Dh*^){sI-%bhH${Jf3oZ5ZC8HHZtv1?%++`8uYAQ%gJ6DR%Y6Y;#KRGxV!zG8J=dc~3hMwD%L(l(yGHwX4hCzK;E4 zkNB3I!@=K6v1`sdtCkv;ZN3c+4i?ki+ldjKB;hV9C}|i#>DevrV=a}z+gzNkgUhPu zhG*nA3#EI*56h?8dgKl--dj}8l3eUwq+N_{;JhZDWN&JFd`D(dSp-cR1v9L?wq9Lv zW#KY*icrd2+#!GR|8M)N?3n<;%zICW54ahx_@yf5~DhmiX5{$B9WnaPnw z^3xDCNi%zL_FL%nwD41~b!Xf&XMx z%ieO>@Iwm|0;_Snsof|8!(NVPQB~i8){XR_D}cTI+^6ia&gVLH!_f%NHRN)`^BXQ) zh~*s5TDn(mskV}{dHJ?9(4n9lnnW;>>T@zqpKLwY;la(rP9jApsu&y)18PBQDzF^B zq)qELHhf7{0*{t#8DeF1mp8*M+Adb`6M23_S*6k1;Bp^$m2@asJbcl=Bw z`2hjHi)Nes7L7z=u*}QDR2h})b#^;bW}uDYzTQ})8l>{%Fa&;f7GYTi4Mh5}mu0h7 zYR@MBuu$1%SlswV*y?sQGy7~deHxx>6FMGI6lMsFu^*+W>Yzp_$((L%YqYvA>U5Yb zI{EZ@c=kv3^+Yd?PJdmnGLj%X$P51j2jDW`^P=2tXkjLe&{1ZFn}o@%rRuFlB8~x{ zO<4#5ynUK5GBlR@;Ib4+X`2u~sntT|(gi5gOP0=2CQ`&~tDi&CS2&EEC66ci*GP=U zHoAADf%RTm8C_JjuIudU6Emtcc{B3%0| zL!KCL7md^Ek_AxL=rQ)d9hezVG!QfPD#Uj;-h7EKZ^zSq_zdTJ+K&yVQb5;^%!SqK zZgV%6y5fM2{S?)=!JTha5flbWr6IuNb=YIR{eaEBy( zuvWN~9aAn4;E09=!t4+&`keEMzC$f%rdxZ)HPItRFdTvhT|sXr zbGv3DaMs8Waz6b?Na6DN_;4LP`@#E_(AWwZ%W;|G5YSPo3E+%oR@+?wBV8pN(3 zgiTUSj#U9?bB9sFas2E8=Ho^Hf(MN{URl|aN9%|(4FO}s14OZhY2}d1*Qa(5YN^CbjhLI-Oo@s#H!BUJ#fxpTIJb!|HD=&pT>O{1u z{|-?E6Q5FLHZnFMWi@qFXV0GEW62y}Gg5hFuCqMoPV&Y>WyK`HL_sq#N*OP9Kd)16 z{cS4x895NWLHHv6i5P-9E1!{!ZI3ne6R$E4|J&eW8A~N4w=}W=RmS1~xK(89_z$qB zOf~DvM{kZzBlL`C9o)oz_g$|YLE^>TDPv=4PG!|taj~<|vsprcb{pPKpWe{5iRJyE zE;O5^W!Pa-`Xohb6+YI2J(=u$U~eD?dn~j%@&n`NVnv6n$cGK`L&sscdXEWpM1K16OxB@8^8am2l6j06!%d!yd0I)s)A z8rZGGF|F%Iy?v-Dp+*m{I2wD6bD)>t&T>LE(v^A?7MpGoOpsww*UI}SBN ztG;n4Ds%B1Z;UD>ZLL}+hzsy7w6m}U3juVXLO|OHh`~e%Et3++B}UhX>OI>oSxHCMGS=U{bA=gdCgnjv2*S*$98d@Cw~w2+<$`3Vd9z4Ro0 z=VXExt@nVlr#;%t@Wr-%#9H2n;mw(7MAWOK951@t@0s!>@p2LV4OBiE#^+nO-^YBGzSrFo~+?5W)eQ}6bA;; zBS#JHixpQ}NKQZ=D=2HPsPYrws^r?OZg`|mM(veQT$PEPP*NatNrY5}j!!sfIjuXy;2)B_zhI=9MF z+65P`nUvA3mKmS6f0N6Fj2v@WZ3IisZb!qZAZb#bJ9r!W)5kWvdE07kBr$CbBiZ$y$`QCk;{X-6$han$XaRwNbniM(C}ET(iU%XEev8}g|_PU9ZeCz7pl zjef8OynK5GPUrk-?P%s~&G2aITV&5nzs0GBM(prD_(|{?*AsR`#S(|Rrc4T7X*sQQ z0l+=PVPTIn>9s?$14kx(y2I9WK}J%^{6XXx%ci%ol_Hd_TWkD^HfePbc58|}`HaKC zoZyk*l)bUdua2%hZGt+U+6k=yea~P?9Qs>0G78YA#WX+9gPYK{rGawMAEDjgB|Ooj zjq-*4jE0t;=}$LiWqFLy*?HOa+VPQ9pFrEBMR=^j6Qbg4<&wyH4rUk((gRup@h_ zRuSDeb-4Kn&EzjEO>2v(D8@-9`X)bOv&tOvP`%opf2Y92+doWbjJbAVh$1q{3i%S` z$dO!yBS;4BR>v^AP89RO4<_~FxC`%}{1bWu2e*x08i;e2O!!z(XXwHZz!YFN36Sjs z^xi}WiWCE}H50AF7I6su+R2ND1W8r{M0^DLG=ej`xv`F@d=a7{r1r;t^(Czl6$WNDXp4Js zPXTX9k!=TK%c|cF)Yz^`iFPn>d2ydfjAe}ZwG@2B`X(@{$w`Zlwhij~`V^X3An2e{ zxp3WZrEAvfER%|Hc(uX(Dt8AdHbF7eA;5fXAjYj};YwlP3_|4JN8erYPHna)%6 z2P|`@Nm0oDWwN1m2^k_S?pNXH@nF$O!Z7dbN|W;VwmkRFVm3j;0+4Zo%!{H8i&mO$ zv47p**I8ZK!#&p;4mzg(=FZ&d-1&HqX(FXr+CJ1m(WPFy>gM=S6r%lb^>P)WO)Wbw zTb5Pf(RN7Oq5Ep}NXZOt3A=<{;ajP%d+um0Y7xDJZ4IlX*;wbHOvw%N*dUWGa$UBz z`lg22S@CpK7UkUBu(k4~Rmm0!+?abiif&mH!L@ZIKq`NHx@%r~MN?2=Xg`crSn)f5 z%BoO=u_(^CeOsVn%fMb(A*Y*MT|2Y9OI%lXJ7`VbwY@xFaeHTkwuDDKgd0{uuxrIh{wj(#|`S8p=ox8mV zXIa)?j%wz?;uF#fqfzl;cS^N5^OB6++5g1>$R5%NP6nYaNr43ewXTCab+YR8r6KUF zMk*%dOd7jrG&$j}EaM2*`tIzBS<-|Ci9z-71 z3t>(tmTK>IqD{W)OTvM4KFIVo0Hix|Bch*5EUDab8R&%Ccmf0kvP*JkDKt`taSk2D zDZsV4et0JchMM&w@=fo9?8~l#mIzh+H9}U78vW(Gwgz0J>?TjSeQ$=Awnv5eha;>^ zW=6@f&UJFQF@vP_n&B!3>4~JsQ5%^?m7Hk2H>F{k5>Q(e8P19eV?s?N3>J4W3(nfMR^8s3q=-sW|}58NM|cX z)euO7hP*&I#QPqa^2MXRUlFuHwO=K@60+kU<-@I;Fc%AyI_2IsP#uELRG?qh8slG1 zP5yucw3oIPyq#NxLcTK)0WGZ#XoG!XSTs~CBEC)8eKr|Bs}Em*+S;n!+}!(G-=W%X zpuvEfs$t{V!>YczZ?Lhr6^G27=M!Iljc>@qgpFO|QebvY$K_GmX~`J-4Xd33DCw%z z#dYmuh=ER4v`P+7vpz;{an-lje4A|LUFdNB42#-QU#lv8bA21|;yLnsMrYT>5Q>1( zsF&WUk}ZQOxA#@_ah;r{YDRSK$Q9U>#0h}k0TX1gpq*nev2qF;RQcJYFcVNWxxGLvMDTFRIpDPH{eWvo(L_c2i%pJlifL zh(dL<+1Wh{vU%+^+ILDqIc}@h0P%`$C2;&gJh|>6dy&I%z0YL4=?pJMuBMP77j6uZ zVUl5nS+nAXSRBm)D&Pk=<2(Ht?nN>TjmMT{oF=H-_1WV*G zzG+;&dm+|Aek$_P9*K$PkF*-)@}|8eK7$vbI8bbrD9;V>NyVB{(5z(^Od=hYsXfyzZul_=-Jh7G!{v#L!?Fv5vcTQBRc2%Xjo24jwQXwwE>PPS@C$VeERY8t{9ZFzQlEr7Sa<@qFU;(r+YOI9*QALWNz&E z;nT^cP0Tv+FV77vi80AyG4oT%aMEofoX`wsL>nThMjM{>6zBWfjPz&0JAr_j$;owW z^@E|2&gIXdckJilt2|BUCi~;ql=XxxwKs>JwmQJT7AZdaWNDQ!PC2TUHOk4w=vj7j zshSoVK3#|4Le;3;@!0zkWQ1^)ohSQ0mwjvjYxp zO|t2;Srm^nDP?z5I*?KgH;#osM;eA+x3=JC{^09()#{tIG+ZMWq)Oe+b?LdkjT%u2 z*Yt_KI-wiBV%r8#bng&1WxZ(|@-@_zm-frMzYnNhTV-F*s-yr#0p7k5BYLvE>m6+| z+mu@blNAqH|#`aXkY_jB&Us$`jD%;F%5^yAdKxTm&wq&eE zXQ+8$h4u7S13Udl3HN!jrL@Wq(3-eye&*fzzbBPvEt>nKtwH(oGQz`G z%QttKBB-E~{3h$v&_aA5xCQlVWqwz!8#nmHX+&1l435ZSTdWBy3S-QdZ=T?lUnyqx zpw$A%AZrlnDyMT>dku@B2agO1FR8Rvgk+AlLlBHKV~!e(%@#K0 zmluvaV_}4dfEbZ`X+tLJgg_}!S(x=~tRmPD#ozReX)Ha{dY8wbp^q`0nolZ%Uu0|` z(7SpbNtc&KEw|`;D7kzFI;LC(Pp653p{y`#WcvgkUY+SVS6IL-A~@K1KqPL*W&*lf z_r%<}N}N$SC$OlpcR6_UQ|z1cPYwZx*yeU)7BC{rpR0pmA>7<}eucWAH$_&968m3KeWGQ9DXiSZKhy{;6&pf$` zzj~fIMcE;}3Vuc*FgpHG9CeO}sD`dd;e=?~en)N`dZL|%v?cLeanE+b|wu1n% z<`yyoqUG7lnz+FTQAb@fh?OMJLojUU=lGDi%Z|l(-+Fq*EWJ?Pg7H+!PI0x!R!3vR z4U#2x6dO~0oK_2fDP~4+NI_~vm>^g`mpB!_!=Z2=Im6lvCzEjKaMb9obFuyahILu4 zPX63Obh#}J#>Blc7Yk-VP=en<03*uSliu6?%O~Nw=e~S4F$G3hS@$Qhx#Y~^ZNd`2 zPz&+YMdqq%Drirl%5hsX0@2GWNt2LKh_r>H_+HuH$jxWO;HHA3K|eB9ht*++CR=4+ z!+K2tH}buM8L^AZ>yAcu^_6I2Q@hDFUPVF0gDUOr$(5XyL-%F@*-)mi^Ru$;_7Yz-swvI(@wefHeCTzh#y2Ld~K zw6TxNx~z&RA|0;C7Ceu5k3#y0Lo(58%xGF8-;|z(&{lV+QjHE`Ca7`U3ME2aW;Rlc zYEI3HzI>Bdb}ap{0qbK0e)iG=X6fM6LdT!C?jhB-dFX9MbcxFum$v?K6*&I$*GB@c zEGc*%?rLxti8o^|aBYURoA2L}u{C#D8spLu^NqzOJ&{>h1f`0v=(fv=|dA6-wl&p|qDGFrJHB1(kBjiSvH_E^;U^&3Mdp)+_1){BcvQ z5RO#n+SXL z>HSR!9ry0LoH%)n_4%Y*_X<*}bdaW3E!tNwjnnp%}ptj)WI`F=F&D6z?%D`*9pME}t}&p|tNTlSpFC1=>f& zug6S2W42S%21kE(!N&*=FIKsOlS$j9!XVc$Ne9yf*%V&x3mW>-ZU#0|q= zkzVN!_WJtR-fVWPV3uwjvnvJ?kJ>U83>t-~qLNTc`xhY3ckOsSQ9e=bwZ~m6$9`+Z zTw-8ODiy_v#}XbjsAw=lziJPtt=Po7Q3xBT5G0NwBOu0~m%B^GsC}=hjg&qe+?sc_ zDfEvwsy7Z5<}&FIiXet%^g1P0jP@ zjCv`Fb6FGLHuSN&O8JXD`Hz`W@KzQSE7_D6Y$TRSbj4LoC_eSBIf)Aft82*3>g>hg z6ZVYbFL2!ro5+b*kbe&V_?JB(qir1APrj^RmhCLRWPln9d{Fc>^Liw+LMP@Ys1 zO#C@4X};JE==v-TbCt4p#AuaBz7?9o{y4ZsKJu=`1=@$BMJ6UDNOkSoBRM-N)*SSo zvn?_Hw(o~pA=v{TTL=6gtdplKk^R~f`Bwg+p2;$91x%`f6z2nv-0eHLVYCnomI~ zOrk$D7UhNC2TV3H0YW-^E2#=A-Ud_AQILZ8g9*pS@55^8`$*Km`HAsC{kALsVLP@3 zWnC1p^|4!GPop7)$O5vzn&ZG^1gTdf(%86jk}FVN}b zH+k4I@;2NgmCqldk#52_77d}PKbECmu!>L$$lkPNfEYky@dG(~uK2jQ7PD4yIa07r z3>(v;Yy1{|EHrUu;Nf%8d)YZY9;H~!J@qdqo)NP`kzkD&)EN;M724V>KVjA@k|oQ?mNg@X65ukC;M zJ52xO@37F*|I6C>m$&od?)+ya-+y{M46JN;{|x`s|1-bupK1S^&d7+z_%r;|#y`XV zth4>p{~7Bk=HNjiYD(ui}412jcyc82Des{~)69 z=>Oq@{NU#QTRJ`k^&! zo%Ef4&STR`8ylJH|6lVe7(3cJI~W=}{%mmnSX6lbhLq$SYz-BSoiu6XghXhSjNP2H zd3gT4HOT3k8vl2H|8M4qfsXNKV>7pMGIsb!t8y|HGB&g|`kBSi$-!9P8V1TOW72!Q z8i&<^bZRY}$P>>z#yF;+mRqzd3-Q{VHQjp>!yWCy1S~?Yp8f;nn7o&!rUxYS`}@yf zgFf5WlgM3*Zd?&gi-C4^2c*}7h}Kl_4j;?@9RDI?sYoucZ$!)oiESJGwcsC z?7Iv2{YmTF_1Z6s>-D|wVfa>sYvc2_jr*|KR9TeW=jq5ewQ10NYEmoMT*1ow`5Nfk z_IY)++5JLW!kj3^%eDQb|S?a zQ(Ndv{paZYg$YKl!jspjf5oC=0=(wkR?(H0JecD)Ij(DFmoRg<+1e`)>uLKNF{ zp0;`V?p)NS#OJIy`1xVw`M_@r3=?OaoXcklr~4+;dcW;=v+US(_V=aD&sF&JqV<>! z*Q;`89bwlF*yXeyi2R35v*z_}6uRx?sM7Q8#6!<-o3o`!8sV zcIL%}lk>VCW}Nr?ftLrZ;HDjV5xiL zW>Mw^>VDFy%ct4UthY4h>pg8@KG37Ja)hu^f4 zrm`;(&xWQIy3Y#^nYOxHo3>w{JG`#c@78KBa$fXh+EbmiM^?sLNF5xrx>`8hat&k= znJZju9Cz1lzPRs>t<;8Gl}vlSMl51K|?^XY^=$B^&rwjpW^D6`fd-ZYkP<XQ^c5^y3|H3{hg^>vEiB}^V5 zzBe&-jtGRSe>vaLKBFrLfTOet40hxY=(`o=>PBSc1IWcO+MX zg8d{p)yT_*Vl*JRql3gRywW@OVld*pxK`APNGpo~Ee+=*jgyykrMgBS*nT!K`ewidVq~ zAwu$K)&MvP7em~lp7aU_>0ZGqP7+mYcz?-ym8>XNqz=!n+t0nutpfO2g@EqNC)Js9z?oiXBxA&;?$eCXmj=J?xIM^uOZ0A}B;ge$!a5Ei&HUqP2p^8?NudIhmg z{{9>k9UyE~@E92?pan+`WNr?o1sVisHG8K;kmC81w2Qpmj4Pr2Uqtc{Bdh(@S`{`I z_%|e(Ym(+xK~`Co$~IKy-LiTe_P)ZO2bA>nVYA<4h9}W@id^QGXgRt!@1-}f2>)9h{kN0)Iu%NBl)WEm z!KQ<$ag(f3IeN^{i;SW+jN=taaluqxSDTHmo2gvM^(l|XO~`)U^J^8gYTq13WqkDe zkGd!VQ{+t8XLhAcpOq#-L zyBC7tihz{p0MN@>^dL{B3oF6n^f81Ku=T|g)YKv*XJE_0TrEnqp3nIYm2pswWJV&9fRrL5IYCK`u zN@^NSTs+APUPcak?udMX`Hk}ph*YG7GDRUm-bMpG>70Nj*0NzRj5FXy$>mBm78s}Q z?PKdgLZVbOo>Ax{-a;Hi`!26nctW~r?|={n?vcgA%)na4z3*4w9sB zRP!f}RB8Pag=ELYlq{<<3BN1CXPk zLY47^gd4H1uVn-cb)Id@k8r4(G?RTo{(c5?Jmt5k%%S`SrTO!${gT`3JVw?D0R_a6 z$SYE`_6GlTBJ=B<{`}H&`Ge`V7v-g)IW;otBKKX(H!FTi*}W|qXNs>G;Ze0_?;IPe zd<7c#pLysLTq9g!u}H@|;dmd$0(1>md+vsw$2nG=2QtV;VBB{0lFQAbYmNvKqW=0S$4CC)W`Zd;lk_2aYFJT?|a zh?&rr&|RS@2VoNn`_pEqbxKIWFR?lR&*%X2V95Ho%IQ3nZB3Dkb{VhaKV~6dc_}Kl z8a`uJ_EA5a5GQmn8e>JoD^iN&R9Ev0qq?OvU|_?fzeWO5XyDO!si zZ<{*+5ulYHw}DNR9s*O(Y6 z)>4dNbgLdbLCg+4?yyak@eM7jr`^C#_r1n=4JHkVVE+STb`@b@RsbLKK1P$$AQ_`= zE`NFELIuDOQHCINfB^iskep=5i84Ll-4L?vpWEJrU^}>c^?I%K6;LeK2R=g>t!bCn= zd5pq0(Co}HovzasGRPP=WL|HB)8Pcmy32GE-0pCJ()+WUXMyD`^yvp#ERL$syE zm4|J3UwGJJm$$D~rJWBoei){ex)0s6t2#ZgSX&I|@VsxE%v_#Q)cyuo1;rGPhZ%&< zq>lVnK<=^q>XQl#jt5$P?y$-aAO9WcEElY{Lw*}mEg{sALnX#m@>gcy4!AQc-;1*9 zT?njDkmW$qZ&1Vtp~T@j5CQKDB*ztXMfu%gFh>q+*!@=}zm=$27l%~b&eT-sq~>vu zyx(M$Mm`j9d)v_fVY{`=aU}aRzi4V^IM=q1izyc2`S6bWNxMBdDP|Jfmyf5Z zw*g=G+}~)8O7|HbM)Mit)1^X;hd=FIj^WoEq}ZEJO}Mt*umREPZ>LS|n9Vk!SJ8_u z@$)5I+E4bt<@35e*Sjep&h{nui&-34#fm=VnbPJS6 zLH>)iS?kq=H_;!r*}843lk+vL>Ms}3)|kaN6D^Yt#{_`aC#QQsin9b>kDHrJ?5h@a zOvuBxY-a8Z<7c5X*%QdpV6r}!-bI|2-=DJws?%1lsJip07*grZq27Q}>l-kP0wd09 z8FLr6oBFS3D#P|~HrTLB1HY8}M~1(xT)nQfu2ku}TzNgc-C(?WBR82=FQ3xeC+$C- zx%!@Z8xa6rAlU(JwSddss9o~Y*I%b@@&3Ty&jw*pNF6UbrepwtOuOoJ2Z&6=kx(_3+2D#E83`*l8|P?aG;|l?as=Nqdut*Kh3w)=Fdv0iB_9*;6YQoRkMfLyV~v`CSCwz}*@xFx zTh6)Tx2=yOCe^NJ@Kn}LT=1J0(#ae0X!Krp6S|R6QMomiQkYU@1U2(I!ssU-(iKa) z@D2ff?n)+F!r&n^48k1@>g<}F37B#cZbUe5!i?zk4m0xP7>RjD>timy`4!_-V-qUl zGQN;!?(&DvR^&XYKa zI)Jq@oLAhn@0e_Z8FTzO-;UQ1hR3vJClN+;p~5~~^cpE-OZ9^M_akPP(nF2cw-SLG z7d38D^cE%B(4Mn;!c}?4*EMkoFhPT%2fe#}_#v9C8CN6(91f5jM#p?@S25P-C`Lue z2Ni(e{A&axhIl%1aA;uSn4|;_98PZ8=E91M{f<#OQ5#}gzlh}DaVV)lr7eWOB|xx% ziv|Q4AA1wt7=A?WbpcFgZ8(_(BR2lDID}TL)~^FP$R*X1fRu3`)-crN31)e(%J}@~ zh@2qXUpnLt`47aVr6b9_X~=P^Th}6!#_+67-YTduW)1jyWo7J=r@xEdGZ-HTqiJ4p zk5?6z!VR8?FfAj-$wqr>H*(m%DCQrIym6QO#N1T6 ziz}CEVffWwsQbjb>{pnHW-0yXA~Re@1whREqHGI>G+vccQc7+f;YW@s?4#vu%&o!b zS%l@hf#hO=8tKXixD>dBkNSZ0yZrp55-ms~$k!;O2I;=Z^T!2M2Bg0Rm9D zq1f}6l@Gg-T8Ei^5Ino397JHnT&1Eq%0t4vx%uy`;(zNVFD00Eg_CIspfg`hJw@|p zU6q4@8Dt8J5M2acig$nNU>O$bWT^daS2@BDh8Z-%CMAMNwP`|6QWPWJRDt=eT13OHBX{`vtXbs7r5dGDlT;{q{ zxx$K`Zn?dZrmES5zJ*JDC?RZOcmyWvWefMt_w*4qwE5*21pz^oYvcF;mK z!7il-18H&f3xDpFhB@+VnuXn-_d`qEuVU+r<5w5^{Z;!UV|=-xc)^@rB^ubOzVLkj zvc@>5OYxDFb?bLzh&amW!3k2Wumonfa1mnt*A{US{l(S6(mw_?64CFu_Tg zXbrz+I)wR|e7a13i9KRdc9u^msf=aQgH%m`%5&2!vF^}9p6BHN9Q0$+E?8i2f#dP_ z3i#_na20Tft0^n>HLbX2BY6;sQ4R9c7s2KQ=?CjTZsdO<@rUPnD7I5D<8fU?>|7;~ z(6BZLHz!2Og(Z0tuVvpBBmV)oLF(r^EE7_{OWxrd5p_6K(4=O&P@W|awEP|>Dr>{D z*K(T3|1~Fw9;<2W=Emg}EY~U0vXFWvY6P>B1=y270JQL}gQg!f_=mFpRS3C*%}qEk z`6AzT&CjBgL`m@}OUFxA2xE6nskSI3wpnN)X;aARDT$kSSx`TlFfadnC4>Gb! zgJHz&XUa<5a}7_c4G7c|lC7Rrn5UqE>At{DciYby6BY2K-9Pgp5MzTBm}$jSRG((A zVG$ptEt1s7V~SHuBn!(C5x{1jCFmPJfHx+~6%chQ4ducx7yv}zmlH;`M%0*G>7@FM zsZf7I-w$t*Q3a?dKIa^Gt_@Ui-QCI;>M{_73j;zw4h|K; z<>tZ&-^jMTE-?Z99Y7tOt(t)hv^Rx=(t6@v z=NnH?N;8q_w^Zh&th{UVv_e}AvRaORZf|;>2Bvf_xWYW|Mx8q8y0?(nBR}<<%*@Qp%*@Qp(8bKm%*@=?#neSzj9tvkOs+dKe)oAiexB>F zKdgwI5vf$1$R#NyovpQ(tT|2SN6~X(q*YQa`=Vk+{aNqe^iqpbw7KRqd)#IW`ya-< z(v!bkqpds!$%%LSCNbvaO%-ZHl@Tfp89Bh->+*~#uN6q2v3sN zL3m$~X-zSF89vCQ!e@`*3Lf2qetajif4~_P!;1m*~`+;m`I4 zsSH*jK=+!sx!lf4VI77y<^>Rg3SGrERBV*7tf2AZql07(T+V6Gi9ay`ledIjYyw!+ zXEMO_Y{tbdM$msE$7B9xBfvGp7g@5*T8g;r&% zg5R+b()oHCk-gff0pta#`B2z8oqw*e*_X_#Weln{R>1vEAj%8jNFX8KAnCrntui_q zm8GS!P)lj+M=F9%TIT~B+V4y{lNJeO&2_0iTRQ3vclIdjXys8l)XyrQi4LoIY*ieO zfo>9hnW2qVk2h8V3FDS(50K5l;t0iR7lM1kg1~6Y+bx3eC0L-Y6!5BqhQ#V~rP(VH zkNfneF8YM+8QW35%=|7OGe|S*SCV=BMfyE-n%?echDz=ruh==_38a1XeJ`u=6_g}l zQg@nMD%RQGu)Q0@mMlu|HR>)n#9j5|mY=@e^_?=MO_^?|=L2s!CY?QtmC0Xsrfki# zN4SiA_D|KBu_Nj9CR1M%Lj7H{KIB6~UtIvND}VV9YhSXMx7M?x{#-frr7s~BxmLnMlTN!8$_r88SGr|jfdo8-20#Q(bnDb z?XiI=TRbZ~ck1CCk?^8S%+&fAtmHGJ`PwsyEW{u6nT~!+vEa$|)zxKmO_@-Jtuh*FA&rD=xsl)R(L{(2qkP6Nhjq^lLCn#*$=ely7Isxt3ZMEfP!h%4^!>uvIbzpxv)X8AWz;*peL^Pb=<@o<g|8ohfA#j)`VlxbDYsdYtxJ(F(x2Kio7{%9CWWbd zdCedr#a{&strZFTB{Pi?u-D~*ImW>ub{PcQFL0e~#l^`UJ$qyHXhSu3>_CETErqw%sjprZc}rW%8(7JYJpKq> zUl8P0yhUUaTe~wo?wr~`4N2bw%)_NXqDFt2QL7?|BSQ(*VX&UfKSJ z7K4x%Lyb~rA$sG-GvAGk#fWi|W6T)6vciZ=p8q%`cGNDzAuLM30*!p42ve#$fHP;H z=_H@yqUe(4;v3MQ7#uspo6YT0f-Sh@L%Z&&50+h3lukk98yc#K?G``e1pq4GCf*MC zQJV^=^!ez$RnvD%-Ha^C+&@TDli~t7d70LxZk4^{I1|4r7ALc9oz|!3y+^PrBBJ!o zu9F+H$lGx0LH^=ghJ0E#h#b{4>xi?qJ-|I6$~6(ydr?KY z+V7Z-$JHxU*UjjU2wX_$%+~@3RjR<0TfnL`F^;>iu&~4XysG4U z;r+@|xipqslPi7s#iL~E4|u5(rEl2iA1A6XKv?doGQ*E1w$Z=;fO%0pFR~ucy2Mq! z57IJ2qEf9R3|v^kny#x~5o`x0L4uy#SB&W3*Nm!i_UE&j9}&Vt`+*=MOmJ7<#2VH5 zj73tw)Z~0wg9n&hC~?|Rqc3f&WGXp)hvZ8ijnuKN;P7QLZ4;tMC`Ep$*4z~nG8tXi zBycg%w9WFkDm=y!3+Yj=?&GKJO?{{-qGwZ_qeU$hzE8O1=kJDnYbLhx^E=X${{{Dy zuxg)yxA|VrLos1LI5!4w{@|7f!T9pMky~<4S^X;b_q+@q*r&HfyxDS0RjL50?6W~i zWG6A8k~Kr$$iThm=j{1 zR--OTnWXBeF!FIHrl9(5^#Z;ToX!=bRrlr&&jBkvMM!QbKRIW?ILxjXe+DlV#)Yq^XYM# zSTImwEaAt&v8^5jA^8@&(zDX$v2zUCp_gE|{M()F{4)uEiaCDCz7p8h@#3g;;*P7}mg zljd%5) zA3H+O!${n)wgSPOt;VgTw1o<@1FFC1(yiAwUOH(eFBbLI+^S+uK4%URY)WsuYX4GioV@iWDk_^T1wqY6%=2iFWg-pV&12`7Dz!$6;%Z zyw#Y$)fwkg{upB(SIS(Y)s61T3_BNWHQ+XbdXsrS*FJVPB0S$q-3r;=$NuVkyna!x z50i~s{rT&yv18T#^r*z7xn67jkBkZ*wnz^A>Ar3j3S5VQSs6zFv|@-r9;A~e~rL~Ws0{U_P|MQTzM2toM84OyOcGJ}rM zkG-4+{s({5yW$N|XZ0S+adO!q&Pajs7#CYr@(I>OB3Kp(r_0F-lgoS^wJPhs{8}zq zm0dq?I7ABGq*$A+p_*i+Uril%!J%j11|O0S#ZqyQoaZdWcjajr3}ZF<48aBBDkUvA zkrg~9f=smv*aXy_ZLIr_(Pb4OK$XQOXH2V1GP}YvFN=(zkBr}iNp|aJod-R29}^NW z>6|ub;~L}gQj^{`ZMD`dcqJUGQfxob$mE;2V2ZeXiq@i|hyDUY3{a+|VXJ~tJn@Mj zU%A;ePwg-FiIn6bZXN`fK^JS3)VLPz59q1!Vi1m>cnqgmCle>qI82#Hc;g~F*xr=1S`I@B ze%n6~09E2b7eTt>C5tRWny%nMKoo~l%TBr^gaeT}^#+%W%-fP}*GbpTPwbA}=w5Pb z03jdff|LX-DxgV(V)M#x^1{v)#DUqh71RdWv`*}zClT)WlzJ`7Y`cYSFKM(jF6P4i zhWFSGHe&2i4#7XgTjHxGx>0jIcb4?fYPTkZWiw2yy@wR193vyetGnI4RCBDX=aCCO z=^E89dm3WruworNgi%7gWp7vXCayYR4@Hq8j4r`^v$t>Jj#OrW!ig^K(!KElKS4q< z`hx`6oQ-4_COx&0J`yt)5pol|3h|=UW}a3*69(@8p&Eu)hUcd+qP&!8tzAht!G3d} zA(JqZ6ihZePJ^Z7a`GCJIa-82@zgJE(myfNh>YX8ve)3u+UbjE^zne$SXH^5iU&n)mR{ZN_9u$yQc6d(Hh66 z)OzE6F3ZUpDA?$_2`Deaz}clsRK_eM>^$AB+f&qSy_bml-$_@LJwNS) zk?AM6OCRegtK*-3_ZClufEKhqo|?+Tp%+a&M5@IMQ&R`6cnF!j2ICtNdXddPFAO~z zsH2L%ZE*kFY3bM+g6&z0jvCUr)VkVl{HVUxT{5BUG9@Db+|9jNz^N(&XRut4-W&8< z45B;kMyc4(#A>3j*_`HqhIuM$U@^vmx{NCPFl3Yfcc$saUp1vDT%w);HG0D188=K( zSww1CaS}vHi*G;h)!RZ)O6GGK_zEvnoUXEj9lHh;>We)y;BP>tvr(~O=*I$@#>yGa zXowPwRIW{rJt1)4ta>46>S;z@Wx^`&4IAnXevY{lBAQNTOIZdV%pmP1vq+b)!rl`~ z^&KQiGkw$QlC_F9*H|%)KV_mVIA}76{A<5oE&=Hv%}j*v+63|Ck(^wiI7lp_-O1e= zB17()UpIe z=aGJeS9?ZOai?C+R)8dM90QarEKB-%e>!51!Z=p~2-5D7TD+ja#>E z$9P~V%kKu&KUKh_)PV7!(J6tBqgL&|=2BIJAXTw04}g+^Okt7ERWN`>uRoQAoKz?; ze_4}@`OmI#R(R!)J|Q)@qN3kc=)0?S-LQzlNK-dl~y@df%ky!NnQHZQ&@KCtt#} z_CajOharASp74#wq0POT)3%WPc^6xUA#_$`ssG9ERz6Gr$7I!+QA2fa9t8m+-^~zJ z*+<{DGmCU+OKaw2U1d&WI{Valz}p;1dyG4>;@@!P^}DXD_33t9@9aPWbO@h{&RGrNjtwudNk}Mt?$H zL12*H6?MG?S=ap$d{e$rCBXE!F16-FXq~*q+SX)@mQ7B!DhMXV7DT$_$cI`4ml&g& zxaCfwI7~8jJlD5SWnltFv|q9dZSuferEmo;g+ybl!{}`v7p+tgWAY1PYefl4b=@dY zs=9VQyDNTE+YC)j2kN-1f~{JpRzA~`t0}lzm}6Q1pdn~Lw?v4QdKsYwpvDb56#`M= zHuZ4lo2pj@mR3B{u9jhP#U&0>y9P}cyKjv^FyRbCP2_syBJk5nJzo}7RU2Zp{eiry zQ24!4Mx=q8nQcdbsZV@b(NcRyG`DAf^XGSB>?>_*dB1TVvBGf7++Uc9`+SI%-&S-F zJV9ZKHlc|}qDi$RoLu6PMYeGzLzELZG=(XRF5-5rs291_5+*|6ng=-E^bH)Z#3G8= zD%Jc6`aY3!Q?9ukgdhxLN`U@Ws<`BK!9&j%Tn4b5%2NplJv~cH>p|zWs)ryNWl8T| zdO|}vDA8pYG}hE8E$NZ1ba?5a;Za0?6v3RbJm?k2ap`L@Jam+q#=tJluGX|QrmD}U z(5%Qf)l`<&j(5ko^bYM$`6AK)sb1hC9MH8U_jccRkKnz@I3 zWytlFDU-Ud+j8a=1bHfbbC!4!+?cn9!HyZ^z_j1oqc2UXiSm0$9?mu zq;ee~2KM%Nb(S(mnmc@UpC1vHcD~XvQP_L*dAQgrs-*&d8w}<-T|%HY<6QKNR#yUZuN?6iEG5-aSgRmM~-G45^dsInw0WM7NRXM6K?vw*BbzjncToSX+) zNlOdqH3X1QZ4_l7z8>c?mP5!10|C#$lP$&JXquE>v^Gz~wEPIG^QZjyghInyOvPpf zkC;h5RUcw+h=NAFye}(H9zI73Ms)|3QAX8cd{-6 z8Zr@c&dt)cvkO{XF0B~6MwpLpK>I{2T0X5w6^%u9-B)^}jm%_37m>{aU$0#dU^J;TRj@#`zXXZzvizSA^LIX%0~qFW$#FG&{qFWzD;gj z5Rm~Mo2REjJ4fNJk6*8@M+N9cp$~6AYv*CYZ8}9AV*Y+16NugOUpf$+BNyG9&qxh@ z3@-Jy%08%9C~`U}SrHlDZpy0gAko`_XUvt3ECrYYi*5fzLkS za2H08Q&)Q>b*Td1)ztZ)TjU?uO}2e}o6H!+cNSZK*@Ykcd0)zDpmZ}fl0E7R-qF)c z>1MuW+iv(=y#ACxMnmx&P3_Ld{qjSUL2Mv1`tp#RsVsQkzxgI>dz!G>N&onq?$>UY ztWM-8xk$&Pc0)2Nv^TsBQ}G9>;HlpA>qldhAJ}_xYSN}eEFzfomSLcExHdU1iE$!6 zuWt-Q8#(^)NF>4>_v*!{y}^Ni0LGOyqT7APv2imh(qYxX%-Bl);%ZDPL^+v=XTyyl1ZjfjaE&|y(;^RF4G4Cfg!S}ZQF9X%b1rnT8SZX zD_AO1J4DxOGhXjQ?X#VPc%9@WDI6-hLS(X!-ws0d&oi=HzZ?O0QBy{4=S8U-dch4` z$=pA#!Iqb$XjLOZp;Fr0E^QkzdufQGq1E+Wth`I5Z-NWO{rZ+$b+HiEQl0as4!8$| zJQ}huBzh!$xqS^TpCpRtP4Mcrj>waByQJ447&E}8YVJ-5x%T#)$Lm# zYo&H}V0%P#?4ue`zXX3!uI#6 z(A}!7afaGzZQ}%vIX85;LwoZV@3{`e%+FeXf^f&KZ~+Lr4O04ho}rv*M8<6-{Q@5gCG zZ;~t`lT>Y(*#A0~v_4Cx^Df@Zh@uCRKB40#OCHObahYP-N&2hiXFT^klEI&%R8k~NC)=$CM*gAkXG7TY_P=tADUhq(vMz89fRu{`A^`qq;ShKwZ z4qpR+RGG8lo}aRJ&uy!mADS-?n#P7xU2cy52=AbrumlC}FwXUJi6zHre;BQzs?)>!}02R@>}&U?7|6G!lU~Q}AY+l0?mYdK4<{9D1Dz{tnFq z_jkvqUCle4lwzus`ds!P_ryxre^29J?Y$!8K8A;YwL`V-aVy%c-OUzQs8*igZN7>* zyrB)Amfy6_Cv2J}r+m?nCn9<7c4d1=TOPaC%O%45^_Fb2By#cTbe*4Ca5325FZ8F< z_5bY1lbtR0$Dvl9xmlMo-5JXK@NgaXlGfHJXSq_O^>z4#Y-HbU-%p9WbYVmcbY{l~ zwkIl+&3!$t8LWfS+CvU6LMqV9dGr*G8gCRL0b)%td2xzmv1E?jz7X$bXjf2H<>ai{ zQ0@p5q&8{fleoobs}+7n3ENnP!p3u*KVt2E4qy>`vqsm2d!1wcQ3-l1VXVB-^^9Y*TNBE)DTEIwi&Q0@K0fsz zb2NWky-q*`&_=gjlEkctGrRS;V{Pwq3qcGEjT>&5b&`q{wP-sb?(VL?#GjnHna3V6 zPe+eV_ajldEVga5*Lrmd^fLB5dh+{wmZsZtp68f7+#TPZy`**YRJC?3IS?J{;Jmf4 zFWAJhv1ES)rPqxlW>a^;(-+Tv)@8X)q{^TEjT<2BffF=-jJGjDJ>Gef4Y#^d?^wG9b}+@@GWzti2(GDJdqMK}Gp1d(=DsVZec zP87alVD_^a3eO&Cx9)Y>db!m1W*0h!9P#y*7>4q5bTHU3@TZi@vOpzd|Ct?I4~T#_ zmfe1TLyPE|tt9ktTAH>TQwo#ZuHl;cd|0*@DaInwYCHi zk!}R{wxi87x-Q&~49c1`4=}(J#_n^!g@swyvWjH%hsb}70K#|dVvKc3<~Ax;&i<)upNz5gb5%0u zjLZI3?jsbLCl?^fP?zcxJ9MN->o6HGhi>CAZeh%^p%=Zi_LIIOtYA#0JV=rSqNq7v zeb#z8G;u^C^ntq&P2+HxU3{}i#k_3Ta-+)IwPzl;7{>;gr#Bf74S{!AHNMezvTw$3 zA4oJ4;wXp<60a!68OlU^_tTPuQ89Xr(AH@YnNMMHZz`KutXRL<(xY(8)w=7%nR-`{ z{wluhA~Hv!gRF8z8Gcrj4~Z6c#A{HB&W}Y1U-zf&n0JKKdtWoxk|Qf z9>DJ6-#0lsK6tu29#0E(zvJxyle2&_L;Of6-As>?jso~B>8rhhjNh&%sLnI`z&@&h z<7P`b_eY;FWe4Gj#tT^Sxgwo2F&`n%PO#WB{;3k~gDGb9=mbSz2CUl0?x2W!X6bkbG2yrWmdhMsHYe{m zSfHmYW^#L7tUY92;lk9iwuy5Pn@u#Mxm=j}>EVnDYF3Q*)1ao^u@}@;%{X04n&hWE zdwV+l7Rqn2>#^ME*H}8iU-Z`S=K$X0nbKFxfQW|KiP*zQ@~7GTg7k3dpjzL2`s4=t zp1nVz%;u^-mud&#<-$Q+t+7FGKcw{zpV?JJR8rhUZSy3;LAu#+36F$~XRPo}nM>-L zy$4gOyDcoPGIB39$8*%9ZHX4CN790}j|i1K!sM3`7fjM$K_xRfK*R%UY}kO?AToi( z!3a6~UME7W`X=MMmYL6w4kr_m4U3WNubfydN~y%@g%y9@Qh$t|EWIz|n75_`3N3&n zp=_w}nHzI*G{=)PSP&`?eyoDqwRdnsrS{9z8N(Rl^flDE_}FL2Zv#GEbk-WT1lV|8 z^gl__Sw*A>9!0%z8vi~I18w}33g+lp+O$^oNN)Mj_InC!Jpc)ea12Di62rHiOeXja zskD_oue3ES@#kbCy-!Z(Zt#mk0fBPVs5-lXz-k4$?ZOzdsC3xFBUqnW5JCD8y^cw1 z8s!kLSJP@q+?7g6z|p%&$+%_+YKhmV+;gg6^h=>%Qa-plZB6HC0{Lm!;K}p`Q|6;!wH_@V+AbN)rzzjZWPz9_dE7_PJvsR`4(%-z8oP(O%i zDCmb>=tH)1h)uOi2jA*$H21zgVdKa@V_d$vIc7`y9?ke#u`Oly{~Ji)8e>eF!QPb@lYR?!eRHWkro=9|aG2?FHzS#!DOTZ9 ze#ACZzsBkNUwm}lA6D`+SD*L052ee);M+q(j1a5Bh@llwvNN;QLNI*Sc)dx&<+%=w zcj`-yG~eiC*kFy>WB67Xt|o)dCdsr zY_?XD%4p?fzFa>o_B-53FscPx8-`#jf6lU}^7(re?|Q4??v0WguJtPpp_rf`UFEjk zmWDKfu(O$`HZR0RU+v2+H{;1Q_DDk~`o0fvcXu2HJz9A_-GR$lF&=!~u5}P{nUR(? zbsFD#Zn|6X#+W_%X*IKocRh9V#Wf+s-E{&lj=wdHJ4uRgG3K}YK1_y5%Po+bgBn2d z$V?qF$Qm~KZx_OO8W4V5M&R!)s>LSDNSRy-!Ys|sk#Q@0&32G;bpJ&L7k&2n`v`<^wG7<9H zR!g&ys^P+#Sn0-436oiCn`o_%U+<>uEG(JO!DWQ%sCtk#O9hwPi8+feIN*k-WhQp3 z=U-&0Nh|m`J!2*7+vqZ?Sg%-=p=qaPi#rO);9(oj*P+0OH?YtLI^;{^Thh6IDX(#5 zv@^7BHi56c+WK`^k5RVPd@GOnvS5Rpb!ngQ`n(%(zErH+`^-H*qO(^jp2oq#ZKM>R zY}%`)bSnqHtF6p_*GO(_FFTF)Fn+_2gmLr(f?3&Zy_DaM8evH51b3S}S0u|9Eb7-# zY{?LuhhugUcWz4G!UK8qv95**DALI*c9*(_i^kpFee%AiOLuekIQv5Le~u z(@k)FU}w+H$X)Q(w7Ffl*ltHkkbJulryHJB>rzMK`@cydhJ(y!eN?_I+dp0n^XG)+ zdq>-GaWklx#!>#u2?=yQ(gtI%xuo+d8+uVZRBf4TWE-bLkK9JoGiW_E%bx)n_M&;f^V&; zdWYXs7YuCA`>q99JM+-&6Q4}@`Y0{S*;qv26dA~51|N~yh6o1Qh4?q8J5FvC{c!CI z5mTT8|9dwS^OVMs61&?EEIe}OXX2wTB}EL%FAuttag$jA)66nx!7j-a4~!NVQ{ z@r7CGdw29C$hQ>1+}`8vc!byh9o1$BI-g-IS?HPVX5YR=-BG5YRk{@B_5gJp@doWX zL+ErIjo%=IB6f?Tt-z+cn!Ac_Ms6iKDq53TFG1{YA6)nc5obS#kGcwjVaC_i<(2*Z)zm*K)M#m~xPjB(56z_>uaCHl0wXR-Qe0va=d}9!B>=KOVXfvg>ak2oi;r6VFGPPSOE&VO56?X@AH7>x<7AH0i{jDcLS~Q!bOV4LTNP_B? z)?&B4tpeq;+}M~%Yz&37XHiyJx}<9TF(){;bCMz@++UQUNW8=N+z(_~rB;#@zanoA zT)RBKYrDc7Dd$tX~4g!nZ+DUmDxXGSLL>8(+Zq zfsNbmpZ*BT@G1l;!9K8jK18a&K)9jmWalTxU2_!%l*rGUQkI}B>^7c0CuFrZJ;$RI zGRHhSSh%o|OxzL|k%b(@T%jUozPWwaOp+0SgRjpFkk-MG)Ue_Xrn;2mcM@GTbhvWw z{A8Omj&`?gUm&`jVp~I zu;cx=0z7@41NKad!DHwoTfh~trUqlz9F2&DpInLbwEL zKR7fC?ZyqrqSKqKc!M+zJC%_zV(QkyY<6p@uWaRaNFZ%h1P=&qvN?ikNc`=EwlUo1 zA7E7T@~&20ecfZ1bu}y-eji1=W$E$Kfa1VLz=mU&tp4KhY$EUT`vJG5 z28b5&oCe)JHUs!xnNK;&1CPo6wSv>fZ@s8M^K=xpYvA5+y^J|Ea2Q-FQJw$DjW?ih z{~=2t6O3}%?PLqdeksCx;c3f=3;}!+QpT#^Ov!5F$N=m|7_C1(l-b`n-8foVV^yi- zysgg+yBbP>r1#rDp%j9%-%qQL7bp|Ov%T*F^@PCc4$tj@>mviw^R@F4YT>BZq9X15 z@+iNMo8Q1_`im9@h&C%o>l_fkX8<1nhURw)hygo=*f1L42o{!HJ#(z|eswiIam}CY z;^Tx>?Z?Xc{iij!uE9UI;%`>$bFIh+4vTG{MwMf)yRr8BUw&)5K>VH*K+3x5L`{xj zIVsEnoA^P01<1oiT;G9ZY9JVPHeG7%qz<(+G8WDxK6((R!qcMj%^P@dG!dQ8d)2t_eSr`SO2 z6W6_h6ljP)GAkacYQ@$mMyf6+!m9m8{n7bI?6D2O(M<`ZM>0rk#y2@-HmoEo_o3u` z22tc4Sw-2F6{1ShYtZR)p^zq&f-GHBvcNvautt<|LcF@qE>b+V-pdjuDmY_Nmo^OK zS(uQpJanK%qSYOOProdn<@kuipraUDpF6NRzv3jm;su ztA?4=lwX`>cMRAWUCJgCs2avFWi-2RMYs<)uvqrPV8teuDc5A`5MTEs+UR01=LW2L z>^gms%HDTTb1<`?;HGz^Bl?NdVp!AYTd)TT{ObLA;8+2lr2znp4}{tIMnlcDM%=TI zJoG$da&M-*q8c66Lo3RW0tDlBsY+j_-%N&M*3If^6rx($xHdAhnc1T2^30@sTR-7M zOqAS1eCpU9%!XDhmFC1yS>DwFz7eign2Z?~%~7uD`az z7icRqjE5@%Rv4NQFEt+P4Mo^UCKtl)19^#}ZzrsuC5NsRG!(^G_$2uiDug=PQi=y0 zm_)0dH3palGiF?{pdthf36yh?#Y=?PbQ5(7UXv8LRRen{z^%GeS_5=N71|*)g}I}mV_yH!VR-5o$Qo}B3lV{l8*PlizSuotPom)n|Y)run=-e zT(z!};M&w+5<5W86f`gw#JjxwcZZ@O%7?M>i4b&n?IJ;%R;e7qJ}WjAjUd3WtVG>H z!86*>?VvLi4V*+oH#5H>y}_69)=(ikA0iuZC!AZq^rG7%DCRdUI&N}%i5jZGe8ozGcR=E!mS zju^vTiBt8cf9q1Wdh4Q>=7@Xrz!N=S|JoL_WbJWRj6<&N>T|^0U0=7brJk z2VH@*5F@HtMH`HMgg22PgEtbX^jT{4&5|w%yTf86Wj}ManG(kyC4qEZ7B2M!HM%H> zxUI+giLZq%k_w8!;HP|R>6!Ccg3Gh zOhfAT>PYCXli7*Tq6~UgoBd|vn3WCr=UL=t4?f5XRn%=6n3pvjg5~hdTT>rGhD3Hn z3sxA@fyT=Ng?-Al8TiRL*h3#oeTp>P^<^cPeAaq zsb){kZyiN|&(;jLZj6(};3EcV!4w#dkEe5-rWz^U4@&R*^nhT+D~T4I48nwN{^9}? z1jQs_tX6(Y`TTTL?MQ0qn}u%wV)>z`8GK*TOC9FVl`=rw`G>-6i2MHSd7MQuGAbum z`vb|{jlS!9E{hS$q{MdHg062)xzaj^>Id9yilnf74G zce;ijS&tYKQ+R|p9bF$VB0L1=BD-)mr1`m1&y*%JtZ5kC=Pl)LheJZRb{5Cfqg?M+ z@n{ajr`Zuh96k8g1a8xa&mlKHcuxzw5a=#7Y2Sj8vx6V`ufsPl2N|0|GSXj)8e~H; zn#r;zl?iCmF}>cJZqW#C6XK{~dmmm*NH2ASGm28`pa#0$qk~Nu$l*BIjp%5*Da-&0 z@RT7tTUV->wt#)_M&ifc7{p;|8x;bpNZkuX(*g|7q@S1Cu4?<2k3!{nk+b?xmP^rd zJFF%FNc-2ooHbQ`G7*eEs19iuncG{st})SrrOR@vq3KZ1t?{`vqD^bCOR|g0&msE) zYOtLV(Ud#}VHATb;8hH?bX89-=gFtWfScya?4$5Irs&-)PAuA7(x%DbFgbA`FKK#_W1@8WHi)f=Z!!d| z?JDC~6aB9W&&fy3`UJA?bIi;gB3AM=3%6$k4H#x4pfsB9Bj7OXQ@DM-BZ*gf%$r4z zWR&DTNDr004@;LMr8eT&%Mf%pQVJ=tA)b8`hlwt-H`BI`F-HE}3*7vg zsbxQ$WNP~C_eDtPkVvrsp*98a50LE*XNEMCUGtMkw)tUQ1HnOL>p7Q!WeHLj)}|yv zlL8A7lm7PW5LH!(p$HCo zqhUf#G7qUR-mxOyRgr4?G~tv`V>0wW!)OFiMW|h7q9l>%xn?m+3uU4<)ktrWWd?Fv z!VnXqnCrcnCb9o$vovcWm37ESeLvPMsX1Io z;L8FhNOL#h5ofOH62>mZ`3dI;&mPvnZytA^(jTpWraM`{KD3qJ$gXhLEala*bo$BF zUil-OGeiC=7F$hOO{mXh9478c$sW>(mGmymwxnlSLpZz$JUql}c(E^ph^=88ceGzn z{1-ypoN6M6wDK@Ve~Ksoq<2^G)|m;7S-!7flD&sOr@YEHyJ8ZnlU40Pl)hEpKe2KR zy^r6&DoTN^*l63eIFn~=6fJ@kG(X}U*2T`q3y!>1f6s?xjYLtIz<(Y8E9J9*sUtSR zt>0}oRwJSl6qF%n^Q)(Iqt#$`INYR*Q^?;GUltGI$mr|Oi2@(Y^%53JjS#T5bXKD# z#l--g#SDo%8rM5jDML_nt)&xUKr?tC?epw9Xdm5m!Q$r;DCJH$Ex){z{?6m~0VDme z(o!-&QK0h#Upe@-MW2?zp4%7A+{YAlitL|n&qY5F`;l|V(D6hxzLfT^U%6pRLK zp?XcM?H-oSFN^MdkHLNz zAw{*>6w|ig;d13`Q-VTnI(;-Hod9ow01*R#k$^yufWGCD3BKPE4Cvp|Ki>Br2?!Vj6bu{!5(*mT zyFe=<02l}a1Q-+q3=9V7t%K_U{FvHP>6rv0s{8< z2XG`%Fd`;!WFaL8BPSGM=0HeP;l#qmekc+afGj-)FAP2IePXw1DgEY zhE>MCMpm-c+Q&&wkVf{}xtsZsyGy5%E1@jM4)O({rIq*-@4<&K*G1#wX=kKqw<~F^ z4@?{ia*aj@aC!WMnS7AVy(3Sh3|coJkdq@n;`^Gv%Za^#nJ^IH6iUo&VZ zeqFA_f`*uthrnO+HzL={BHek}0L>MeK~GoGzydnGGpKZ`bjQ;J8DXN8Ur z?imOgSA*d>^_Ia%274mWU;oAkC@~L}U_EsJE-6+J5UjWN*BegqeLx0taQFl)a2_p*N z$yfd{1rRB*eAH%ZPqskc7-b;A?G9gz_ns+=0#N=Z8(wZ9TL{wA{{5(@yp=((QU6wZ zTK@i)N3b+q(zLcQ`e-M=e$Wx{1vr-ZNB)I6Ld1Qfy>G3I?2vbD{uGM;AGIqS?_fck z1$FnxYLS|g-)@kUtLwCKPsL7)a+WhdVyKG$ubYzY-+n6?ITu#Pp18D$4^md1F zmwc{&Wq{M682ZW=;ObjfBz)*8?F+#66yAzye0dW{&o_oPM@&s9s#sMF015!(4q$1i zb&y{|${IK@HG3Nq(lDsXvk`A}i-*@bjeiW;u&SV7+8Dg;%J+36(5^2&<51dyBhVF% zR)onYGkEZz=BY1yKn0pr5<><2tETSPSvgvKf`QQlH^TOU@pkU1^s*G{{2KAOdJ|ig z=VznG#=ppUZpuq2Am0MyF^H|2^&?op-Q$!a_DHw$tmEFG;N)d#S6;#ydP?u=n79>e zblSvnHR5n+5eYbc;t5a#PAvaZNBhqm?_a&A$-9BCba~8Zu_KJXph^8ZXF|NmfBEA> z;6rP9!NGXm^)34MG;t_QzQ04|i55O`LntRSWz_F`#Im=4c1 z$s%ohx?}$4z0U|{0u--xedkZC#;=LXLb*ii%^1d1<&+8Ve$(MiuMfXe~F!7jhl z^r5)zmr?ure;Qc+)%N|L%OCQpeF0G5M5JaRs9ZR59R*Hue78RoZtJo-Ygs-xMzLFG z4{QtLmRK(R%s*_(3V@?1|A&FgAj`oFQ-{ZiQIC5gdJ=bTK}tU6+s~96&sojw5_`AM zjT78m=+U`g|9O}3)hV$SIfy%BXUW&S&94Qx-v2LZ>%UqFxbRbc0i>3A`N|)V^)gqy zBbEi0x~vaNzB8Z0ksow;fWH9Z9;3H)Y5%wL4p%PekNA%>k7b4+zrTDbghzL^ipE%H1)MM@82ujrBCL)R<5!? zIsU&F?f-ij-k#h;b>&P?!~0m`Zvk3Gz|f8PtjZ&FPrq`mhZefMhJK;0prMEJX&Xf} zq;fUjo^m$8abxY`gZ(7x3+}7OrkdP`apb^NNC?U~C1+-4W@^R}T~vi^F&e~Ya3rd`aGQ+RS^N6kWr;cRZAGZs;-R(S`$&xX$}646 zXm?534y)ukT8inZ&QtO7|B!{XYrA(t=XyI!i`rgDEHCW)ju&RN*jWW_j043PcD1L6 zPp(z_F;2fCM!u8YJ2MM4p?S`$q9*X!gvU)?!EBRb1kMS~vH?q~YSZwx)A-q(Zp*s{ zWC_L%L`5TIKlY|DGQ(0}GH{0l#!7z++_BqF#ZL%YeR1Bn6%#C9@?v5l)BeI<;U;F$ zE`9?al)Gj9>1M*_Cpe&GnWHtv*XtZgsR&$+QFxN# z>?$3FdjK2j`C4XqrUlv;r=<5py-rV5)@78>M<)Nz`+v2ekXU*+km`Bs>$@j`^OR&1hd=+I=tDit@ zI*&008|0;UVvGjv6sN4%xPj< zlx!$L++^1OJ31n z<}R+wdN}q$v)C{8QT2;zYcIvftQcMNRx;^~{P1FgrLqKhSy#bxGgD+$jS5d-BxMFx z-z+$!q6+lque2hUe5k9^< zmE}kRU!Y+ub9t1)Tg^##`oIMe65711!`EQK>gZCJ;guXm@j%O(1 z@+f$fW!R+d`Lg1>rv&9(&)L$_eS{Jfy|-T1DG(4zQ4$HY3Pj!ld5Iv$bGm`cZ&=|> ziFjVASJnA3`L&Ug+3SpCwW5gY!(mO4*@H~Bu}H;^&&iQB$H&lRz`5f8XGtIlU+nmh zf@2lB^=|7T1g2%VRg|mGt1N}K9~$`QOlioE2IbF|-bB_he11s|Nkx0Uw25c0Pn4>iWd6eU z`Eyy#*TVBLg>&aGj`uD$9B%=y@cmQ*siB?6L)!=hT~p*DvRQXKo|P2sHL?BN7(IeB zC39;0H$#w|2@XxneFv-{(KV}id|~H~dG#1;Z_2Wvymd-f^QWO`4{0$lwpFDm&1u46bo;b9tK!=a_yPZZwLkcK;C_4sPej*zW_78xJTq2n#OwE=Xxat_25$x= z?h-5iZKK>RURV`?s0>hQZU%QuwK|6HR-c`KY-smWVRo_AO2)IZ_X2VD?`DkQ`(mM1 zV;qaJi88~F52*6LGto6l-2$@Q+oY|YStg7f+AZrTa!H)F3>LTwq9zhNNy1f6q%>VkTHq34?TxeEatGM4;rvX>q zW$htG>p8bNT%26>LRa=WQwyRXhg~BBQlZNIV{$rk!8@iwSk499sQ7FeUYespt|gUo z$BWUEtZvuXi0PkG>G9}!r}TVi{KP8MFC`RebCth-4I$71yhyYZu4G&GYW-YfR;zSC z=6~rq%wtXQ;kn|O+*P&s;CM$Xe0Hf4&`&R?(J7-gYm0pz`*Z8wBg!@p!cDK*{>y4= z^EhMA$J+MqpZ#iCJ4ZvERRWd+n&G*6-bWpSs}5C*s?!UuHQ*BTZVRX$(e5GCXl+_w zSmJu-_+&GHDgg24x1-=T&;cns|$4EY$Q9 z=SQ*&WA=7PPO@Q2Y-o*}JCC!b{=RuHlmmbS{7zDx9iRX(sPO0gug z94o8fE({LbXPmiabsTp6Td}p?IyjBA%c@6ES`EC5QIc=ZzcMNjwdG7>^p&tpmtC$w zYG`yM^}d#+FTqgP7HfSra1r-F1{>}njSc11i3_Z>g{n04@7NR@RNLoC(X+pPgyy&* z@#v_id3LX&y?E{`b|Y~Z;dA20{5s>ZZ?|shTwiK-t_x7MK$KMvBaJgUq)wU zzF`;%GE<*#TX&ssp<5+bRygoSp{F>#?YE$8)-ulrGwCLYcvfVZi z+JzE31NL z?@kcQ5|Rr2{OH4SN9%7YRgq&m1!6Wl)hoYEl5*CnNZx;btuz%sEa-@DFO8yj1Y|Urw$jB%5B`7ggqh`)U2_18xC1RjL^?e^ntC1|D zoH2vX?;inF?j(!=2}w8MjJARu&u)+^%ho2=k35T1e8(SOWfPp+;@?l@3^7@MNG|*o z4UIc23abGzLh}3*T^RjvVGE5rz2Gg-|6kqT-#bC;T4}#!)0fIo-S6)jOrN()`M)4m z=WrLW*fHjLa7-UQ>LZNZeqhq5?pG;&f^@!agCgGC0-poaQc$Axyl&0M0z8G#Z$kOP zgXbxlgE=L(bdxjY0O^&Ikq{(jL4t}inDlG9Zbt#LJCdv~O*0^w{ZJT+B% z#R~~Zy?C$NXgjg&!`&=?Z4UqGp6Q_g(vDxZz^_sN@I`G7qvan~QU2q7HB}^ntXQ3; zYpcX)l~N>>gPHf`_z+cs!*v3w=nVZ3ZrAXg3CHjq0;J?Ae9tSzYOnnYy5%?p_0u>Y z9<|PvVL;l;Zh2C-yDF(aC|V(FpCN}dLc})551vIyOSOK6kJYDKE7I(LwS*oWFr(1H zhPAc-Zb6sEUev7HOnj=HFjZ8HjG$l#mFjBfv#T9egK7(PCBOUAEf3xi#*&j*&06f* zE+#*mBhICIG)x#_6cT@@lk&x{M58IDTA!tX9ZQNauQSU0Qw045`@Ho?M#>ef0vd)Err&V~+x!O9-!mkdGECvTsQCh(B^b0=t3Ta`wJ6D? zf#Y#sG;N23BN>V&r}9}j{yMKJ~KkanXSX9SoN?qkk7Eh+@^@Av@oXp=rdQ*el7y5zG|v*BIOE~k|y#`U|_ zKe9GXyAgLo3tu%kWwK^^J!M__yNImLUj)xQuWLDNP~+w33Qu2vYi(F3fZdz?xt}|; zvZ+zT4f&MoVJd#?KXtNd5b5U*S!phJQ%38se;vFIoJ4&+Wr#NvH)>qfZ3#J$pgbwQ z_Gm#Z-U6(gO-rM8XOAw_6E`2aK6C|Nqh&~JqvA;qvb_Z7*c4ZLXI#)XCX&Xf>oUUh zykS8f_9nXpe&<5B>cEe%exi*mE9aH5V{A?I&Cj$sXAW&;VMfnu&ewZ5@JM3NyY+~@ zz1w`cpu#bX&B{lptJ*mH2Qs3Cs(X)5We0PjrJ}exz^>_PlkC8A96IlimkT0p; z0#Cvuo^mI3g*C>LZ-t$B1Oe^)Q}A@1v>=P{$(;9$ei@w=g`Lv#ygx`v|E{*9^|+;+ zQOpH!3ES2^HAmHgYKl{3kK5MrfGsF&rFi}}?aO{d^KXIek6Thw8Gb)2>32!V$Kn$i z8g|0u2Qz*9LBMET9kL8*xtlF(s8_Uhr)F+v2d2sRLComk^mnh?Bi4W!^#U&|1t@Oi z$j>>qAVau|kOq9^vv_9%D!Wz!^pSmp(IhCRy$ORhVr^Yc*Hphz?zl`4rI?U3SXLN5ea70MXb`;Fy@agzA=I8chd0lvQ$JQHe)jiqaP?S#lFJHE0X z#C3<7OTF7gf;4Of%f|?-4&=af;`j>hF4EtUIf&yM>!G=ewrF^K$y4Eev}Z*JGur7t z9<{&!ecwIHyai4em`jWA*e7|ej&}e>iKpC5!EcInN7@pd-S)lmH>We-$Z+lMbT+Qg z?*HmVqaR9Z^Bg4&ITi_?NZ8=WsQX+fZ*+0yn}sqU&28z2gpZ|O^MUS6Abc(bEcIbE z9jG6aMyf+Qv-cOMS`^xcR*TMlXeqR_&i)`)8vn!`7kZU7O-kV3iwQvhE`PLJl2sZI z)|Pg;&gf7MV>x3Yi*P*73eolDDTn<00;VByv@dI{vVvyIN|1oDv};cAU`^+D+mC!p zR!eGv76tL6w(RM>cOgFSB4rptSbkqpj%B);x4e*UJ^YQ=Hl|o=AdOBUbd~z`u$T{R zU1*EIT_8u6nq>#0 zs`DF6l)K6h)DQ502f&xL2b;DAxo!Zp7`34t@0J{`NyseN)FO=^Rr&CS|19jsIZEh6IJ`{~~>m^tjEPQFw)=3SQxDt8m`}=7P{}P-1Q5`m{q$JUm3+ zihB#3_4R;QU=@^;sd$=1-S%Ov=OYdDEoRaGY6sqV@bT+ljR<&We=gU!vdM4>Hd?Wb zIIfOxcHD&6-2xf~dK|U!i&X=KDYm1Tt2`}*_5_V{aWqM`6Iw3}P4N)5+x{e28RJTK zgZ|T+U9EqDip+EKy+V1+ev>>Q3?W$4#T_iXFUNK>K3sZ{|1Ofcx!}mNM>hx^T5PozF(>TdW_-wV{m3H_7ClH{p+uUAS-o?j*O`)n|Z@P*!FY)v9TlSrygGk%uBgA4foC5Rumzf*F)lFNK=6HMUki0;c&2E726m?QzehW|$ zgH7}wZH(>vSS4HDp2~}XX^!KrTFc8|iyQc?SksLvFr%(s*Emcg(=UIMCUdDcvBD9M zdSYjXYUDfCeK;mv#XaTkZX%MM)T^gXTx%QOck@(#zYs@S{K3d*+Z%YP zoz6{spMpDqDsw;Rc%LL}S!L(sOl`(K(45I$&mt2~J*A&kx?9VZxWAfaZ|BJLDZkOq zHts3NzZN;W#oFPwfUZ;YpZ@{v)8dS{HiDmXyZzGZ(@pvvk)=JZMG-GH1^HpR5xy?Z zaf01diSc8x_IU@^6^BWgYuS25$4r4PbFah#sFdB34h(a76(s=%6CQ#;dCN zIC=8&u{*b4)gw1DTd!8UZUWr~>(?0xjLG*Ne`RENgZLDN^$U=bGPk%&M_Nl)X`5Er zak5Ft1`2@F`)E`mP>b(`So223Eo6 z7>bV(ldJVOR}Dngb{8jg36vg&M&=^WY@t?i|-i!K4&&{5Y7+#-QcS<4eCgrS*1KTR1q>O}35xbkK=j*dfW_ zKf9q`>&vX}v*5J#9#j(Rs%3zJ#Z~E_90bjc6;NED3tOamu1KI588s@-wfhz9>XWU! zV1K*(v9TqZTEA>RMAmbTuRJ^O*UGwe4?3lVGwQzVvA@*lyPFVT@Y>AZxbwTqUC+_Xu+p|c zk-JiNza=-Td4IW@vgD#rung^r(@YJ2cZ|C483iFm%ld~Cjro7DfDEP4rHZhL48K*& zS!lGcAK^6TDu#(ei!Tox-FHsr(9SrzuXdI^Gnu8zpr9jZ!sbxithsqhS^wOFN>ZSQ zFVAI%FjgZglJN8?^u0LbMc9(imc%3Hl}4VCU8fzr`PSa6HPaSFTI@U05@;F(i~O6k z1^{n+UXMFGw4zVst)tW66n*#JgKafU%-=tjOWL0GLxezO1$2c|Z-J(xTi~Gc7#iSO zuD>zH`>I>c-jB1JGS- z6GlNQt<|{~afFV$78a>^cn+oO>}d5b>`05RTCT5roQ~gmKKjj%BUrR!LiB=lSB+*3 zp^IVMj;n^)fgGSgjNRlAiMk3J#t*mB0s_iSNH23>Up`IRx2j%-x+b zy$P5#*L1?O(8kY3K8&HG8lx{CgRn$j&9}LBP2zBL?!v+Z(wtysYfYK77auQ;YO()T zc{;15%0~@rHFoF}if3Sa;Z@RxD1>?`1IYMC@`da1#8a4KV-bAt`oI}ZV`(a~8==*l z@@jqF22{u6Z=Rr|Z*Bh$%#_ak4wA=N_FPxhQ+c#WjjI%NCD6fIt<`$Xqd7MZ`u4z8j5v_*IVJt4p$cn`XrCg$NQVaV7Oh#3sduLAU3FKiwuR zWhRW{Ro^ia$u#BI+_6A+Uh@|+`m!PwrE_7Sap#;|kZPZ`p(-zD<~Mz1V`cJl-YTJ( zFmazT5p&aADiyheQ*skr7Y zvFVK(4{Wz=^Xk6(Q0GRvCw~(#G~ACt{dm-*^svzB_`xRf!wVV{s+k5L?--9ljCvrt zCSlWfRYyl)Hs;1V**A6n6znY$;kng`Z|hbqMQFE!*YCdj2g`W}QD@8~ zP8%HUtG08u9$5Rkz~@fP7!Da& z#~shkv4-bT_G6BQ=g4GksEu-ajVnEY&WiOdI#})eHI#+vjdbF0TKzStrND-j93HFLb!0ymbSvZ@gqrQGlX7GN1h;@U z2px;ocZ7zdV!c#e%s8f3e5=xeBvp)}mveu+;DsNsY zHXQ5RQ)h3QdH2~H!tY&UO>iD@UgjlwT_v3Tj^pN`^4ZwI)`b#81q3t*cMiO@u5B_V zev$1wc9(nV{e}L4m~~E(@vo+JbuH;K!H02lLa#gw8Vb~r`Qq>pcH)pWXD&AG+*>U z{%PGt!%#~+^A#){>-bV&(&H~3ow81M)#)H;$h+`ydi$99{Hd|ts3W~bkT#9=P^7$- z08q|@V`B3bT3pzg<+ng#qEok*0ynga1nKIG7gHD~z{CE&wJts}l^6{Zk@tsB#l_hM z4*5XT-*rOr3PT~UYO3pnSIep!qm8f#6fABaS2Cb_vo%cdws4kin11wxY*Iuv%!Wh% z4^;~hgIR5YCo`ctH|v|95|5nVotmv;l3(mQ*6G@E1-keIF|Bf7uoHxW^)CR?YhX|3 zWG!gNuSLu9sa*an!94OR7RedF0^v1tGI?$7QbEIE$VoF21@L_}u zhQfgIdlvN0jQXg#wuJAsEt0k(skkJKO5QpEOpnd@%3Kj_l-HqqrD~$q^B3o|v8TE3eO zHppL+7qMptO)hN@3CC!B6{jE8jn>j*Sl@s!)b`1jc z7a0ZB)}&00>G9_S(>gES!x#sNLUv}p#oByr&t{YUJEuiYI7r#c7_^arS`E|TLdVIO zFVz)vdipNm;e`v7?b(y{J?m7x{o>WDwN?OI{C>{m>x|+}$XAXHKUjX-Q)rTtI#D3U zO7wB40!_17Nj(l>_|MpP(;d$)bS`6!;IS;|Y5%pB(Rs+P=k8Cxj0;i2A{NUF_Gw)f zzXh_T!MlO41~uTCTT&P0BzIlMuW zGu0C)fj@?h-8jQnt=FlfA+h6%|_cwPt&{789PJzcYJq{W&rv z`oc>HR68Pz&Ck7g(>e+0Kfo_xB<^RY9G}<|A1=&tM+FN`dw=TcfZkZ05MW!zQK%)c z3t;7HNwK7zMWpjde*M_j>8XTiJ5qsqP#1Lzz(TVIR&2-A3OanwA|W}sw*Y-^Wv&0| zq)4#kLk*KhF~j>(@)GnICKSs>h_(Hg;kZ%4idsHI?dpj8Q|jGML&NY0v@tdHKt88Y z_Lo*D#bJ(B?Ox%wrL;?rkt^+Qb{rYiRgtFtk~O+84Ao(@;DsK;6E=6+dKmMY3US?T zy_;{I)RmPwYk|jGfkpIVd|5p=xvh}|7jD6|DR9^=@YZ_6Beby~r^VfBDm}t{2KL_T z7obz9PrMOjrKRx5xaxG`^J%wmfS$y)huR1+T1wic{T78(!?rP|)Wz6Uh@j!0@bYNN z!Q%s`D)W`nk#auqFHf(!&coo3LB?yoRfVoPV8?otY zy)xryb1^*3wOd$A7%J@XSlW)od2i;eIGfu&~k79Jgz zE^S5PmVJ8^|Dc*(psn}B!p-w(-16oHnMNL{juK{2i79RlZOA7DO>c_YEAs%pjiac3 zTH{?zf=xWDe>c$@$=o$pT%S*#@cQfRXvkv|~3@;5Z_7AS-Em088X_oMU_ zjENWVhz6R5ijcNMU~YpP z<$Wnz>|Ypi#PUybg8&+zRD9bH05jt7rR_rr&m?^_TKd$C0qF7 zLB|594*&a1{Ac%}+{6C<1;b#8?9!X=_EhvJEBTcVk|J9PzUMB#P%i?S;^8ab-LK+N z2e*LO`W=0U^x1vAE#5p$XQ7ZF0_FP)kd=fD%Sh>n)=23zdMWIDVL%w$3tWiZDiXur zowYS#C_yVOoKzUDr3AdM(ELcr67~2|y-+?EA`?^tDEa2_sAkCr!*7INLJxjOP(=Tw z)Jg$n7LH!&qn6@hjDzuWmQfsjnBKc0AGfre;}*K({%@HbM}2L?c;)nt0QtQ~Pj!x`C4Qn9lS$E|%9vTvcLW=Tiw}}#RD*%JQQ7a9YAO*j2zN1Ln6t>#Hw3l%lt^IM%a?{>!tNhV ziase=_u+0-Y578G28zn6 znk^H)>4(re+Ce|ROFnIT7AF;h)R`=1ng)A?f1+QF|KVTJkJgumK*>6)+82&BBeoO8 zSIdB?U7T=#wsy5HCMI(MP&qrO=g$(4Oey=pPQ|u9x{^^!KHi|E4rsas@@s>w13^@; zM*bZHUrQ2~w~%xbNeZ(^%4TV5r$H(KAx&L$dQ3HP3`*Z8Bb^pQ3JW(%76L^*mYmwK zq`I(!2b&`BOFw5PwD3hQjuXYlgXmRSc=%ADOcqs8^~7HIxrx1}9J$<2OW zh6tCzibSS_Eboux)^mWjq+vmNChJoFzVyZVc=L_D1i6Y;ZEU$0f3lCU@8nEtHLu1wz2ac4N>hu}<}l~&Ak(pm3YnE@I3f&HGKjajM^4>;5h1v8p%(q1iZ=X zzi^n;M&}+zamNxw`qR8_dex6PL(-{bCH^E~5Nm0`&|fO_ZFXHX4X^RnN_WcPIgyEsQ(Z+u5IGXd5zh|oB7VVD+2%ooKA&gSJ-Fsx1N)hXyylc$ydLpjI)HJ(|MMH{E$1HsAsfBY0cU6q5vMcOi}3ju4NZ(4sW@7V8Ps31VP33! zU$8LpjhPt;w)C7Acfci}W6dR^BxAVN-IA3ew88 zo6dx}7yeHPn3>TJ3fIkoJHpTUy#{UpZXt+W7NEZ$5Ws#SMlrdGk}EQjHl!-}5GgH5 zd!2gSPM;@wRit~Tj@)_U)M5$`AY(AVtH~<61%f<(@o3P*!A9;S%nb@PeSuPE z>=OfJdTs%l)Nf-V2X>|cYHDaZAy+KIGzgpZOR1tz^HWcQ*3ub5P4Ba?aA7fcM30_oJ<&n_u=r zKtb&*bb~p^)q#6gY7HjAKLRz+hIQ|ws<8H`vxN$$2b;nH_c+99ErG| z|0-8c$V_E>c@?ApM~`=jjzki1E}l!}LzCU@HCQ#wc9P!>KBL&ZHZ}RC#!tR5AxW{B zYQt=|o)Q)szSSk??RflJP)vqCVSPOnn_^A)VMh4H=~vJQ=3hWoIVyVDGkB}e|L!J8 zNV?aD@Iu#Fty_?-)b^|PUD;mYsMW18@X6~7E4Z0RrvQO!lXEwN86gs&scKg#RME+ClMKg71lK*ZcB1zxGAgVo61 z)_&npKz&K*+JK4e*u#Pjq}YsDgUkh$R2Ha#lul1}mbK7M7v=b}zTtW5PSP=!V(ul43zlRg4l^sTkp zR+FNUFI{F{z8u{ZE)4#C3lOyB3^;4>CkcyG^VD4E@&1|igjFN3f$n`&Zf#rm-PvcI z(j6*SVSi|TAa)Z0+!E1kt^K~Ws(&QH4 z0ZpWhf^YTUee4=mSR^c!Co#IW(I9RLeIrOTDw!tQ5;mCG4bONXhKpL(1ed#LJ(6xlGs z_&K{h0Ukxi+515X(e-1T#D%rr6C+`7zqmO#W>s0GfG_XBGDn4pr*kTXLf`$ZPhOwx*H0DCn5q?z1W)eud-Ii@ zLw6#hhbtS@HnjI-*6xBmSI{On{s8LWWOu+o&%Zu+c3DB5x>9Eg24RGha1gNifkM2q zwkY=A;kF&Q5#-$1?i*+&@W1!a|H4;C<)~ksJRetGqZ%aGUnl;nO@ah*Q-{#E&syhc z3&R z9Y*ecmajiP38wCaV{2{uPXb`!X5wM)h1z`t<8H=k;mQd^JCi!83_F5H)Q~;IcrQgNc6D{3w$~LhyPk4QZh@`>cxl zo4l{Ts4e}}pSg4B{+Gl?=On!=r9O?83uT&f>{}qz+VYY!KKtV-8`)#}^BBxMaOOng zvME@tUEBBPWF9u^TaCrh<3rqKT`oR_~N3m(BO>o57T4$I=Syc{Bm#UY4 zv4k#aOBH6Fc@P~*K+uIz)6>Ong?@Lh`p_$S?18fv1|b2zuWy!2Z_c@@3v|05Vm@y= zv5-6L^xzfrkX~I%2jW++nKNk#H_@=;WYX0Asr^$YqUZbRuD!PYe&i-t%i81o?dFDd za6#ou^bY_#>RTQ-w_n!b@pRK%?D5LV+#JcAnt$1aj&1F0<8Rqn5Nu9^zo*>Ar&P3I zB0Dzn4Nd3ln$Aw(+Iy?E9+h9dt#XbA3;v;n{p_rax9Kc9W;&&N(T7vVE%9YlUt+$N zi8BtZ@dfS(`jYMAUXHsn8^<85UN{D?i%U(lM zl`i`GVe3uDSm5bscDe* zp;7Kz(fvoPs(W33y^;OkZv4FLzzlP>X$ws+IKb)5b<9P%A)rfic#nhfDm)3U1-yU)PFFmn>`-TzuokSQ?$ES_;y1$y_WT`>SPfbf-C-nq+LuG41!(_i zat1vu-+<*t{Y8Y7f)1iL)ICi{>?{DV(AZ6RZTuPjCS^u^4wXMXP+6d8Hj_LN)I~nU zPJ}D>z~gBuuJsm93f@ddzQqB#jfqInwmPz)O@u}nCG#Rjf6B^5d1j)M(O)t`#?E-% zYQ&*7EYUelucN@iKK^mUZhfg_K=6&1I?7_gFXP0F zn1_bI?3NE+IN=6-@=~;F-DR4S;o~Jqq`S%ultNS_A8uo@KV32<*zK6}Jcc9JyBgzZGz$H9F_znmmG{R*ZN2iQz|UOPDSP89uxc;~m0xbnwy zmG%FAY)T>gzO{9h6y;Ny(@^QyoS1BZIGd^F0p@B5AKTcI$IX^h$72& zO@~vyM%y@KT;blu@bV*<}Vv3)of%)dCBqgB);ncL0 z^BtHST^I2u)<0ayIuVYg-NM_Er9Zpj*{dbu4t0SQ4XN_kif%NDC(u;R=sp~Bt&bz9 z`4$gc`w*i|4E&?51zTIRuZwIuFJ2Edj^t<}mZT?Qd1OVNI!KEg7m6tKc>Ypj9o@6c z9+!W5_=`F5naIZp*jS`)j6+;RIR1I^;NdVv=?LS)Gj6oQFR*F*b(j#?uDiY(w5dom z@$Hpoez+CIs}K}rqim{?#)R&j z0d!OcC4#MGacbphhj?O+w40>?9z)9heK!!TJXp|!$Bq+qX7^qZyYS<08KZ znThqd#Pqmzt)hOy_N+?GH;&X5B<`vVJ9TlqAz(sHihQOL2vcA82>)56EJ4|RP49YX zCyZar&LXTegF59(6;t(M0ke2v;Bfhc^A4RxgmZ1h&9?p<;oQqHFqHacsL~qmjo2xv z{cGU}#P7?njDv#8FS+O1a>EQq33JsE$Ql=0uU-&Yt$5pjgx> zXTMJQ9#->5r(L5x@Jf&`u^K(2Q2en3PEFHfgkha6)?#IaxsA%2$kD%hL4Su}kp=Bf zzLWUBHb-xMzoAzFsy=2*uj1d4QjG~39)r{NzT|J*j1zckg@}1ll%%DeZO(8a%#hJ$ zLJ=7RMo+CD{CH5GOc^w59AB8}seYN(e8Vk4h4&}h?b!GX>DnKWLb4>b?b974n|5HD0R>clXEPE5gV(WBl_SdN>LQiiL9fYs=lhkdd#h6c8ud*x+4%QnHoe3OUYGMf!KLs|e3GzEFKfj8 zJTayVALkOy*HO#qpK3B%-mz7{1}tL&3;ymudW5YXx%Zl? z!DkDbNo^oH1|PrU`z&RM(}Z;xyV_eoaHG&x8w&SCSwEsIIU@Bse()mpwq2 zbG?Z#e9m4eIUsj4y>#{4^M)-opQ16+yim(4`IMvCAxzMsFF(1hBz<_Vo}X1~t8h%% zld5Es)}b+&1=X|+$mMOgYDpa@w0%wtK5{h?)NDVC1LcmCqsc*M1zn?GoP~1^)Z{SS z&>7intL1l5(#4P1GH?r?{H7mP7bvh4(DFLk62=a%pnhj7%<=n#I(!c$3sIEqq>?Ye z%{1^8q|05utSl-w;k4B_nLI$^J#tl}3e``=f3A_e@7$%M&DN9JIT1_PQDJ@6r!`?f{rsuhXUm+evReM$Z9{MP1pSu1em@j zx&_L2BuGC9<>{~wuGbd8Tig0gO~g3qx0mL|z=Eb;{~{~YSSDeZs@&^b|0)U}Ox>nv z;~0UmpfdRl6bN^M%c>10qG3lwGCv%%yX5e;c!lS_-nPiVRh zegFysss#^4t3;NJ^ixebch)Tx$Ih`43@bqtH4{FkRVs>4yrY#iv&7|*sma6^&fAtm zFg}jviI616a4r08MoLXv{jxUbW#t#;o$KNRfp;(7o$3Ab;s2*sQ;<71wGqoRt6L*W z2b5xK9KIK%UX9POsuIqm)5gio(J|Q(Egp8J3Dv0fWh-!}O~L?GUtQR9y!X$;O5@r<+`hVBo(&A#0I99GzP(}WEi3kP`y+NSeND^PNW71Q5EKj81X1%5Kf;4I=f zs}JpXK~`V^KN6mImQ81#9db$6ee1Y%x?#EVm3_xD@wo>DA*b z7S5_ZrY=T#`w)!s7knvx9iDbK>N@Stchlt!bnIV=`lit2Y^R*;(dWufhxt{hD3Pp64l-C%s&$dO!u0XxIDfZOa7npoafUeMNrl8IdXsf|&@Sw=rsI&8U*yQG$qkJPx!z&q#D z#b|a?&Xi>=x0Yrby+8Ngo`0oCTI-dZMib|0jrTLm_a$C+vH4qw$-B}jCP+VtHt(_r7#BZ*1p zz5a;)g!Z7$RY^u3=ub~o=(6Obo)rnybGjNR@a;OGvJB3h;0vdi)h^G#FeNH_`=uGf zJWtfi;?4+(miCpPt23T#23JfA^t(f7ZS9o%UvV6Y@RKpgdFi6R^Hhz%BphtIgR%bt5?9F#Kv>chYN%Z3C>+EyKzIU8)&iT;e?XE#}S9cX}&3De<^USfY$ebr(px!6% zP?mD~W3m~`zUR6sZiBui!h!>pnzi=_TyYO_njz)P{!m*((L`Se+k(u$XlW!WzVB9B zh!MR=Fg%25=;*&KJ&|7eGy}zG_GZxNhu3~}p%VcA?eWKhOh6jOr}JX1HWk&lx3aI#utyZP=CgR?HL5Ekc^OgB)Q- ztqK5%KpT56(KT-H>jTlVh=~ik@~rWN)M{F>_Dh~_9lcK`;=&g~5HI%hF9)5g3I4Mz z#TH^AAR|2(Ew;cFRq6n-rlr+m;+uyS4M_i`NS?prMrwVY{6L(RPpH%(hgY0{*x=I& zg9G+*M5-h|?80|az8nPWk-Mlt_BOl{bR(pvub7n=SkvDUl$Awhu%WJ#689r~jwSmV zJ3opZ3AgLRHUKg>e=Df(Ze6JH?wf@0&jdpR2vD>*uV;_^w8hRenL!}tqy#F@fMGb_ zHB=nxV*A}*sz)ErK<@cV-cDNT#p;jx+TqC$5o{5q$AV9N<@S;7TXiOo>Wvl1zd<=J zIo--a0Zd|cIV*F!FCu^nit^NpOgty|(M117jqz``KmUM666TO^=|hfhDtpS>F%yHU zwx1)tg2NwGB?PLpZd7|My| zk_q;v^aO>)DOQ7Nb#qZUT++qv3SrO7JyM$Q`#(@-jEpkPA@hP$U%vrxp?11GK?amvJ0ev+XUkHw4N)Tww;4VmvbF z{Z*n{2&GK0*Q6Dvo==!kic1w43xKxJL9^EKBf6AP#(FkaHou7d3DI$K^HV$aiIjwI4NE~9wY#^hV^;bsI*u-t-SGC!s zFz&}qZpwNuLW*m$$JsQH9hw-szm>WP#-HG4;P1f?3Lr>YdQLpNs7rH5r<`Quq4Ph9 z5w)ZERvl&g+=hFYrZf>V&GfSa$^ca}JZ5P9C@7ZPwS}MA>yq&bPn5T>*xfr8qOw?h z={~WmG~qHxZCnB>=U&yWU@5&VLV1dge}nwIboNfja6qiKQDFuQ2?fwOYPWHeL5?4~ z?Wpg)(Aph&1&d|kQOiQn8NafNh z%bICbcb1(1d1|)SBoo0J$sDm*oyYm(_9153j%Lrx>$gucW!YZUt6?-X(84>-?b-1h{T`b|K@0Y4q4Jh_V-9q_F z+PZ9!Lm%ze03=F5R{LIRxZ7@l)TdDid2n;RDHtyXDohfo5t1jY!y0kaq1j!;1tmY8 zJT86|A)>DM=~&eyeVBGOy;B*u&% z{7LooU~8Sh;=YZdwra8(Q@to$>jj)ResAKv%>JXZ5s-C{yD1AYkBY1WyypR?fRa~1 zty0ab<>{WwW>;Y&+u;#ubhjwDe=i-0fyw21^aI;BTk^E_1$1X79{MNhqtw~b?4eV=@{_$5hNylZ+p8?TZ(K$JQ9Q_GsKoR_eR(;hU!7Vv=`)9A zdNyV2Sj-vc(4(aOpA z!tMLE)D}%wC+RPTdh) ziWmxalZF0v$R^i;KjsQ((C+XDvo!YYN4VUVG>jsw=yU@HI^n?Ynh(-zgDFD2=@;_S z4I7h4V{uSMFZ@auh`1^^K#=h`M?D(fWSXjfMQ+Y=I}2G7G>d^t5p?1BsV%vG-FXZYb&I`PQoK;EO9v`sbU3n1#P(w(HA z+?-J>`!!Y^N%D6Z-Km(i}3)PWCW7<9kOqn00(--~2Oz?|}3PfylDO?;i|T=dRrp+!&EM`j;#wEkiFAn|Sh zuaR|p+Fo2QG?lDh?7TqXVH_GCmv^B}G9|~tdus6{9*&qkX2*w#lce(brI;~u5dB?H zXcptD7~P~DrkY0&bszXEg6&DF@<@J`HDF)lP*zDd%_2zxkwWIgc;q9^8zE?1k~f+< zcd4PNz8E6BDG}z;FKYLul9$(30QKGtZtk;MMPp0T%kcs>Coza|2_E#gTP%`yXse;B zMiT>TksD=kU`xs@TFR#^z+jhypK71n)U-@woGzi8jumXA>xeh{`W_o>=W;YxPPG!h zsoi^Ac+p~|AIsjmtvkOSGw$DUCV(S*kQ{Y8xw1U)t~cAI1C7mz^Q}#@4eTPsUV7t+ zV%GV}v`u#$jY3gv*s3s=yePkOG;HT3lD!`^k}K=XgaG~sa2KzjXl`k&OaHLuHe}q) z-)vt$JVtPP5v3r1$i;j8?QLsH*R41jG97zN93o!O9=v@t==Pd*955G!l#bOw(@c#q zLXq(+AawuuB}((d^N4GGhzFT>u6CcLA!2V9PB>=*_a^~xOnvyHafRD0K!>+`SJqZM zLTP)i<9T1O?yo|e4=3A5sc)=u7WihH8wcykqyif%rWDwtV-b&^ksHo9!cNeGC6BaQao?-Y%vU>5c9Msw z4=JJguGv3~YM)jNM)WpyaRB1fTsD~uokBsY@ zLn(p;gG6zleHd$7F^wCwbVMEf6~pb2mm73W+phUv^l10hm$|x;15D^PxQ*+)Ti<&J zXO&u*5u$SHu*;1HTeq?n{st{1K6rEE1_row3YEKf9kR5EJdo=&GW`bG_T688fXvTt zq6z6g#KHbrgahTKtn6PdRw4$r6Sb^Z=eDBFI3u|s%o(3;1=&0%r2is}bfE}6^W z;8AzlO$q~&s}>GxAamDQpA5&t=uA*r*}}NimR!le{gs`Pm)l}&<1e$lJ@^RaISmO z^bdvn?8ifR|Ec|HvpM+#q;H*uZBYpv4WadksXe+}U=z_VD@lXcoFZ%@dbcy2c$Dg& zN^-Fh?Qde$^n)l9R1_m1{)p_|lDCI6T?X|E4eHMy*=Yw`Hwc2Wy)!Z)SbO@u?YV1E zx_ctxS=^BYHS$jIFWj(F1Ofu0*LpU864FVJv9I0NL_I_sf3lofJSaWZ@Ip}L_~LBE zAKKqk@hIg>6qADtlQ^AwowGq+ixAg*Ch&ubL-M3ocI~dAdqkP z&0ekX%D&wgMHY`;t_nTZnE8i+d13JY_R2*;!rPoiy#}H(kX2Xlyo^0>jk8VCx?Yv2CNwrEE=n+FMCx`(f#?UF?!r!}vo-d-8=EKZ z5&V;2Q)6R;$#x)`dDch0KHJc2)czlRnh5?GL+F(*UM|Pwn^$^t#t~(G+`@7Ltz=fb z^R|E}9q-5?4i0RZJ4_2bn3do6`Fl zcYo)%!>^(uS1SX!u^oaTnegH`oE`hzKzdnfG|8DI{6d1DOMGl#IVmRT)5R2W|FM1e zt`GZP8QH(a;R}MI*7MUGD`>TK&zxn1sA;*4r7ZW26TU4@`ZrdOzW$H?>RMu~BQ76a zk|&=eyojWm93WqU{@{-+5L1fwI8a}7geFz zs;0%ti;g!eGv%aiMM=LDm%8B%SQmAXYAkfQg93ysBuViZ=qFscgRM6(T17x#2XeJF z%ZBd|-)Qw)4pK21Kx3{liNnOoSizL(OrDU}VaaP+T$LL$Gi8yh>?ncIpk3tVl^*}e z-9W}(xM@q4nnW+@j2Tq36#b%TN3KEdKV@Q!D$^NvEGnl1Pu?i1vZ_LVj%sGQb+`rm z3rLaiyiSLtoA7yCpXrdd{P@*dEA~T61fuYRR$rIT>Kn8RSJT(;&><>BbWOOnRwXDh z3VUg5&269No5lHmrDp;V-#?QnZ|(VT0H2-NXTic7WINjEC(#A~n9)(6#`-*QdZt0t z7+&SS(gbmzs-y#NdQ#xxHv7?juj!#GZo1jd{$cAp6Y)QF(iokok>Xbkr@d+FAG!k* zQ5Q@Ev*rLe-@ELiN0+61b3YfA(=Kn!XYcktmSdNJU-Axs?9b9;Dyn_%5A{cM9t5+XL;>QvO##R*cf%#eVArr~GgJUfetkgF=h&1rWZ#d;#+G6R!kATmPXDG2R7r*6}!dP%(0cy z8e`6poyzP4e_#T9e#OvV_%7&=w;DqY6g}3(1M&PLgAW8SO|oNrsRTIqY9P?rmG6*A z1$pFK#LSC1$dR-9J|nJFEq~LuMQPBDLA7m((sV4h7O#(Gt$#0Q55H(yW^JcLpteSR z2fGtBxQ+38hd-TIr;w&eUK(39;*2;PHaik9kN$o)ok7XAzFa2X1Tw#Zz3n1zCZISG zi^(b)>kYR9F=97FtXQ6#h>J{E+t%&UYeU8h_BF&LP&ep|d-byNKF8#LrD{TkcZu9m zYm+rHrCk8`yC}gLe%zPAcDp#d<_{vexXzG_ddU$W%=in_lpBLmL8(#bjqTn-h|KiA z$BhM$FYx)yXcC#sM)Q<;TtamUJtQF0dH#6&i%OhQL&|O8x;dw_I<<@PsbcD?JT|MT z*6$M9?+|-8v?-^McpNHh@DNAbkc>D|5Mx9ekU45i9rEE(<5jNke!~~xpL!~L^(tH? z`~~PeHkwyr_9%L{6GMK3n%v5y3^xn;#_Qa=k@K|E-;8<#$=cI4Apvy!rTg#SPUu9Z zS_BQd#E83)6>V2!DggGrj)lP1QINc~TXasoe$(CPkbhA}iLWMk))y)Nz}cEw?NAP( z#}P{>$J@nSh12PBRlCc&$a1np4CdKQoAR+F<{(38-_si&bY@Pi8sUhTtQ*7~@<-&J zcXi8SI?V<{8KZbT_WslD+{Y3KeNThN#?U7Hr=!DyrMZKYN3Cij$)y;xJLZ>#tWWGB zshON-{sM&dTgdN5vT70&ATqvuw~XQX;o491W!-=N-1GJo%gkuA_jX{39zEUc1+SbR z^>I$OR7=b-S8I6$Hk~8e$Yksy+>UzKL8W=(S$HuaEqD1HPP9LSjSVs}^mRYXfdFB> zh{3(P+Urtvvc1LZ2zoE3sAV59#FqYpB&jTZ_dljeEy}VtQ=1a1zV|W7h;khix+APy1gf zu64|g^o7G%BUu$iu$AO|U^4SS9{^eq@D=;J2|cGLjkn%?)!CN=)54F<^#t(%HYauk zWOOz6!q;P1?pZY)M|zV!r0U zsbYoQ1w+z-4uo=5q9F6FvvnepVIK}r+8Fc*L<99@~OwY)1=xH3EC+e1Trt+d+G z!Myu8v~!5YlfLH9@tlWjQ7q@+3H0Y;uYyMv1=U}8li(@Ko%EaTruZ$_dM0G;LEhlc zi~k0V{aG{tkC;gG3_(e`WrDiP3=vAezrcIrzR%wR?r>F~=;?lDQiXS2Fbc*Lhy(fW zpHzed-Wm>9=ojO~tL+9Iy>W7Fk6e(GhE+Ip+pML+OEIxJ$*pgQFbon|++TssgcAh3 zJ`iaQ7nW6xU?ETX#yOW@Z*GGBn)_2=ooA4J25d)L&W=$yJ*x_G>VxnaVm zo^Ot_$Zaxa$48MD{NV=Uwb1pK`i^)`+h~1c;9G2bF9(Rx9_!MU*+ENI#3}|PP@0o* zr0PZFcGTySYg#DNB`Z2Z*9x0MjS(Xy`Gt0vdHNkq?`N6^{=E_Jvy9ilIv&<73C9t6 zZk=jUGBlh)-=fbMp3*YRtA-y7XpNFdWG%IgFoI3%;*bRM4|< zQzl!YF3GgMX4S{R&#h_5j{JEFuU#_^919L=vyWYAi=G?DZUNr=E{}6W-j=A1$hmOW zNB0`uw*dS|6H{MG^S>OtGf9o9nysC=M4K11H(qv?ANZ7m`4<^Kx_q9421Ih@4;C?Byhw2gK@rL9p+u0lnZFZiZQ}dYfx+2SLAcfu7nqq@B485wZJfHgERLbO_ zNolsiov@;UVls76HC-9vW%tH<=h+9xut3Wt?37nVJ*3ANXT|jETF$_sXGwA1zc4eh zhCn*n9Y47rJD-3@!POut)h=N#N=gXe2Effh=K8n+{L*W+7Wv zC{IPN@&92S5_EM$jL5B5p(6_-rx|vK_qYXf1jrDNWp~z zq$N2B7`o9S_ERpRi=4@p6sJd@Vp|06y17fpqM-{ruBtVDKQ^bwiVhw}^~Z544U z>WPm3;ubhB6(B$cAs)3Fx+8RRh4=gqpD6gbTffIqNvC8Jp{>2ZTaG;*-0qo*m72ZU zR@IYy)9*h5nv*3BiHHbFH^ zlBQQjs6%};;l$*f3{Oa>E1GHDc1FkqsL1+~{NEy}+*##dW!U1*WI zv|6!{I;dCA)Zf?$A-D{B)p;$R$V4DQe#tngZ(CUMuD%tjHeR`6SOUbE7GtfhfE~x# z12)W4+Y{AXg)(OS#?G|ClSs{_h87z8&zRdLA5mCk!dA~h$j*|=dvlns5%S>(s@@|c?4IWPAI81{@4P)M^+{oIPuDT{ge|ge6M9c&1SNHi zW@GfsgPT+Ay&jby>f)kXkN~U4>nrGm(^c*?A>D}6070BYuy3FBd5OIgJ}OVOcxA6Y z&8ZFO4ygIqd(kvcv;AUYX@1Vo6%d6MkYmve{dTZ z40@oB0oYa4btyVH`rL+T#grKeRTBO00ygiEZ<~;Z&aXdLAjX$9pZP6fXJ9YK1adr6 z_53G%4r9bDqv2vUnEv@$hzIHgr2B`rAb)WD4MOba`c|OR4)pJ-`8PiBuPgk2HX53( z5=}YU5uPr)4&51tpTu~D^OqTYBSJIfQC;mRUP6k|_Na>bx>d2I#f$!@bw#JTrSyo7 zcw42_>HCqW*GHZ6qK%8h;9bq~0<Pry8&vfih2GCEn>XQ>0X+*#L73^uu@qkfQ&yZ}neox7UVypt<4T-wVp&ad{Se zt(}}>&GgQ3Dd=YN#K?`@;k~0Dc?|oPGt(QKldaT`j(Aht;C5OZG8}m~eB2={W|Qa` zuM@g7>o-Oh^DX5&KLurZ`}oJ|W+>G`5C|N3rE`a7Z4IAICFs9lL0rNB>NKGa^1>$_n{Jf!h7F^t~&%54*ZFi6x!jZ zvr~i;jIj)>N+Vt$gtrz%DRa-8KBQd!hap9Im26Wz#8~};ms--GMYk)UM0+Ipp-fVu z7I#-kj%DLbO`a%|t-K@+rqc;c1wKkI({MLcnY~nrnKr3Cl286@ABU%?;nUj9h>T7V z;QAn=c7a&_{m82LPUX_Oq$a>{>1dyK#8@bE^+-N%F4O>;l{;r@lfPN!ZtQ|+>Or|Y zB1_F=zxS;v9e7tGRQdqSxA&-=2Vz9k3kRDNhcN)H=8y$do3zV#E+IU5YtRDd$#Vn_ zz%EBYMqLnx(9|}UjA}!<)H3Mx?9S|7(r2_33xR|2lsmFAP>~Wx0x0VDi8756sm!7= z0#*`w1&ome@Dc$)<(+!cr?vce`MMUzd- z2+5G+D3+;E!{4AYZbeGudg2e@L)^UUjfLas&*RhHe)zm~`gNP}5biD$I=>mAsta9K zlY3}SAHG2j?^w_EAl)ndSxJK*4bC9Ys4j6Z_MIu;c-E&~3*Y$V&*9(+qo0zbEcjGBJk&%VM~^<+ zW?-n-W@Ai%ZpY5f_q>W!3`-6%RHaLYiU1?iC&d#R z@kZ3v+xPJ(%Y^b-qqtZxPA>!K$=XMCb*H3TElIhSuMkbq7P5920z@&ivEJ|_)83Oj z?zuo@!dEw?iTZjsAV5I-&wJUwK%T#Vp8s_ZM@rVgijB6c=7TXX`IiK-L%q9CE zpIrFN(NUT-oWo7n=9J}fHrcP44uzfS_fZVa+G*7%@*-KZ)t@Y_%TI=tCl;T7sV#@5 z<(>+S4ZG=;OXyX5hL6xx@s_5WH7>qmo7G8yB*4Dz0WrB3)TPJ-smR}|(KBme~F@djSrI&qgbN1UW2n@;vT^fz-;&H)c-C?gVKR5{AtJ zcudgKcB=iDK>K_*e5Tv0^zN!Tpkh7dXPU;?fdJv)O?I45wVUk%tfdFd)uNOepjgJ$ z!3mj$SnhqChpy{|1&D-jIEyFSO-$`S2dnUV@6YNp!L#u~_V$Q*&13ddLhuOHjqT_V zq(Cn$Sqy=8&{qi6$G(uVng!)qu=|Rr%#G8}%f6MiCg7gKR#5B`6YfTAPQcA!{-Cl8 zs4c$C0haT1ES^Y1qM-@1OomQ(U-BqQ{()-7x{EbmBXJWucO- zL(;5OzRVG0a`}7q!Z6C5M!X<8D9I>J(XyJe)wYI6;MwsiKKjqk@nU9qZn(-XsX8}L z&YuMR2H}{rV#-|n;l0YTQ}A*tOJk~<7zV3S{dh&VeBeKQ@{yPr;I zVqr^ZN!o)F)(wa)=>KFNuyruU`}WJD+mI*5aPvl^(f8{&L(B1lQkaJO#Gk6b*AfgwV<4AgvRpZ-0SzxCy+U4AdO#l?SX2swFB_&cz zxbr43>kA^DEh_DhXl;v!;-RjcF>G;i@=6?sQEiF>Gd~` zZ27#V_^c=>i;Ow<*06~JK~{g+a{O-?A+%p7xt{^@ zvJ`)Dn0L;{n@0Hs@L+#>*E7E6xkR7{OUWCndx!lZMwA9}Wcl|%UD1v^M-+{8BLzVa z@@oet=TSdolzQynyJk|oYi@R@Hg0H2A_;_6TV99Xjd(5D)UTF6E-(!aYK^f4=e#CW z=$;ASa`b?Pk8+#EkghGQF-FNu_Sk3@Y?1(bl6fY2a8u(Q#3uCj)!Ki^;=5!vu;`uA*zQ z$`Z#>Gi|~I>b~h~xP;N?E3om4R9`hx-?I13K4ebz&uec~5l_y_*3eQ%;iucljMmfO z`@p~4IRCPBzz|cNUY}$csIWpFz}^r8{P}nXG7)4@GEO4w`UInP17Vw5uICGO6m9_D zRlpOyE`_(YX6_N73qvC_UmeztkvC-8m2duA6Z(I({`mj14LIg0-I?pgc|_mhX7u}GkatIN;-LpYf>9Q86iEbZ)_g& zl=Ygihl|TrW?4F4Hd0CavOs3tisvlPYXbQRNEAZta~77Jer*aLu;fw53G9a6Qrh{dx z(sxd>TIv%vdCo$~<%j(Jqme`rk)5H&m%q7(Y{z1dbX&m*`Ogs`8mrQbA69ED;RRLc z(nJ~sn?x$daeNY3M%v?jL^2DC14Kg&=B|2d$>tiPTJXVf)Z-bgcdFaQXRA1aiIw*^zZMiY5_lfEq_J;&iN@QFIWb$IK^-t5MX-PZI_>c(nVx%?aidJWJ z=_tdTr3W_IfHAtgMEk?OR*=D>i=Fw=_g@#_Ay=-{KC`w%l4t&qr;OPqSr9fP=s$Gv z1L~MmfYfl>K?~oGj*jO+?1eep!2gDSuu05N*w_ia7_fr`sW5LuJ6b9~b)!M<^m~mM zr%!y`X?y=-0$KPEQ3fQp%7lgE4=Cpt!^9su3IM5IbfQ|~TIynPJT0%KB1PnMNIpCf zbvxH^S6&_lDkv~>QqOBh@7?6wI#s;n4LRh;ZB*ro3Ou2+Lfi?DHLd>*x>{X}SUaN^ zEzXgKbTGKA9k)#t-D zapoMD#Yi7>AfF50s8ivbmYvKokD&|AEYn|=a#vs-Y|2z0WNXPEUx&>&BNtiuxL*n2 zC8{tiEJ@hfllCC!+jHXsR*XNxbkNOg59@7P+?1+~24S$7>Ys0PpW8-tphLaOG|AUO zag@<5Crl?&dkZSrTF72V z7aAmE&h}StCV~E^ZWN8?rJcRB6Pn#lBi5A2@7+*e%;hT`Gmr&~KG)lb->QH2K0M9Z z_!Z6{;*Og|6k_cVq{<^{zLW1%_6(|_e?33U2f8#;QM-p&WvP|zNa$G!Zoi0D9w^{<%UDlLg zC;NXl(}1j{{cEoLGm_igEzZnV+EOHKOd_o%Y(D=6l>|@I-=#c1`9L2f(pQ)fokty< zu6~YogqzAW1ty=4zd6et75HJFWJbcuilLifpgVvZFcicl%WB-AYHJmIhnnps+5hxY zxc*Dn`PT@ce%d+u;Iy*XVZ%!v&VE%I>VdJbkV2a;iu{Ch$p48t6Ug-5dthzsODlW{ z2g+T?zd^&vi}iJWv;1_6uvy{W2qx%WpYs2eb^l*>GXK9^6z19e;jvUr3>|=LnnGbF zlGRqHtO&EFNxgz8J51bmYWJEVj{<*AujXARi2M$m!;!sR_Nbni}y!t`|9Y5P+}z{UkI=2+q*NqOacW|8%FbFa~v zDkCAJYkH70b#o)yl$~sNMh4no&k|;Bwla=rD#pb6{w^qKY-|sm{`$ zbv#YLTxMGrSKQC81f>|}ckQSy_E@Fe(!o8Z7hC`ZyeDq83#^fnL5CIICN+)vGkotl zz%AP=eo{?sXy?F-qn)w*oUksrS-`E zd;>yUxnu$ejww0SCfR0B8Ci*1yri7kBz;AL5NK$ym5tAh{&*zNMcG)gBm|S0Cjahu zg1P~?CCXR5k8VLQp5D6#EoT3ub;SGO@zK?r4&30g!Uos>0QNw*Xm2MHRIV8)fBUi$ z-_y}}sUIftz1aWi6v_s4*a#^1mBR+-zzsmpCue!`sW(3bic878ma5?TilDw46&-O! zthC&XK>bpmS0^73$P5iN9!w42f{SDv$V3YI_p0RojjyvC0R^n7<(}60a1gs@Og!Kz z>#kTM`&P~2NTPzad^-T|n{4MtCcDgVq6)%V#Pldr!<~2bcA+SpBu(+r$WnQgQJpm( zGGX=V!f=ceSQf8-x+2L8e+q=Tl#`XrQyT`ap$^Bv4bg;`g5j}jh_`J(TaPn~AKui~ z29}j2&TjzN_46EhG4BM%R~ke#*7Cu;#&E3i?XUdY*bzVe3l){b`i zhW5alivoKRGqU_`H(5JteFZ}Y4SHE&QF=u~7Y8jqK6*u08$;mJj1Bqt{yMZjAM*D@ z`(kKi>|jF7$jHITN-t_^;b3S-FKPjNwy>eTwE?ipKfV*ZOKOj&c?CgV3^r`cukAd6 zNig}5;m&02i2e5R*1;Wu1ysn_0rj$&n?cR9H?v-__!U)fh62*j#1A(IhsKW1GsF0o zRMc?e%bY7(Gcz+cr|DBy>l5AyhcLkpU6MPxwlJKt5BYdH{1iCe1~CvT?PwDQzded7d%8ltEO{ zW9rmNz{jP16vtvT``~F$J`NwomR1;{YCbob)`{~%_ zBqKs&c;oa!Jq?q0Ou*lqll~Ri{{E3(EGnxYn72g(Z#jq)kay|ZY~3B2+)36`ia93N zj6a@JTqhSu;C<^8fm|*jHmiTPZ-luO>UK}UGCu3yyB~nMj_mG2w93U?LQZCiRm2b; zynpl7Er0L#?nG*Uj?^4NA42Qr(qFcjK^mBptfw44j9%)qn@P<6JRkIV-WW{|hAd0s zM!55G4Ne(QY+Z(pIQ6#izpKeem+=9tT4>2K>p!1`DOf3 z-OP3J+nUR#RN>>e{WBg00hYUmj)^m-kEH_~GN1Qu;5=>v^yq3#?%=5y-nVgMPNCeQ zzOK-l-t%6yeLqpWF-^)}*ns1!$XxZaZ00yg$*$xJs-I%Q3sq^`R9Ax|QPr6ZGR5MU zu^4>hR~?c!uEfO)gPDop<2%wJD{HE8yQGeIsn_l$dY;+bJblx7(R{~p z`5v5-CTxz3oN$I)Ck z_WDVrd?S(zR>&uFGj#d2WXaI0Brv>0V3ah33DQr_Y*`N9O=rhnb&c%c~S5(SApgu9W!>ne$;Wx+v~?!x$!VCSmF z-cqf#_o{`xz$38DSICdd%Nrl74Ch4QRkO7JaCI6I=P9{f%(-9+8TAqOXN_fGCxF_Z z@l=@p7XQ7mLtkFlp_z<*HT8mSjf&mN8l^O=M@YTj>Qke*2amhX3i?_wzK_O_Pa6h{ zu1l|+BgG&n$;D$NPG67B!{PP#a>+{krL1{dr0 z7s!yGu>4u)BHbfQ z%%Yh5(xhI^@MSF-%hf+u$>b9PR>V9lG=!h5R$f{xuMKLKW>gU;coD9Ii!%`~b#HLo zk2mVZ_Mon>bENei8Z)5?j*2(y`W891p@vc^m%L7DK>BB!L> zEw2m8alLwJ+^v7?j$>@t)w8~nbH@7DA9!{kc*xyqkWDACl9JN4GFZW^gyMJOoig&)CN-67K34lsy=CJ#$8h8HaXVkdlzkSq6 z7vZneJ$e>-3&zY7)8H6LZbn~HapmOleR(z3BRBBD3Lew$NW<|rw)-gHZ~86(Yf2(a zME{}^?Jd-t^uR7Fg=0K2ZQHijFw4+c2~Wlj8bhMl$I#G-DS~hmy#_9QxuOU^d-uv= zZf4zw$JpFRR#8N|LPio%b!(*_X1VibkuNNtn3^)8B;b_-*$)hXP z?G4wI>R^jGY4=r6|H4}AwXcC&>jE*Cdttjc|K-vB9Y+bYCu#o>_-gTo3?XfsmU4|l zkRYCVVTVzjl}hxFhz-B31-f*Iy`>7~Mld#Z2aRWV^U@xa?uE}8I*W=&G><6JEF2sU zg_T`Ncba1aH+%0`EuX6|ol-1u+!XH^*|LJZ6pgisCsqtzaB8i=76nv}&u+P!kprSw z`e!Mzx66S))Cw})D(0WQbm?u?$c?tshiVv+-`T#4RW!Yq=BD}`jFBS*o1kZo-+gK< z`XFE7DQNJPlYn0K(rX@pk2LE`&{xxUIB{H}7uynJvHfw;0|)o;B`?BuN0=i?(Wr0G zO6IM$-<0Ux(#5J3xQ^Ku;)yv}{NO6Yu>FC0@fF$a0yW>gpl3ox%A5|l5Bj$E9Ig|; z;24+vBczd819p%gEtfG%M~V=69}{)yW)qK4_Vm{VM|CV#PscdcEJr!2w$CArWgQYe z^Y_plp}Gt-_}0R0)o-m<&f*`uS>6KtI^P?{u3$$a~!)sOQTnH33*nH)a#!nH)%o|FjAw;YrFJ7(P`8pkPPUX+k| z7kCyIp{wOB-t>mjd|lW_NFTJaNS7}ku78c!EN6xlk@05ZFDBjC2ehKW=y*Yj-wrJQPqrs{9~n)0iTKZYjQ|hJj}nMLKwkhnK21uKw-q zQ@*;zoNwjDVvp;OMOK{9t8fttZE+YC=7x-p&oaFnE7m^aolK|2`&!?52uEa6hf>{7 zs5V9;#>!%~&gLMKT6I6ND)eYuu3^ZOv~x$>lhbsQGgf)iD;XK&>Xj&rxhWXlAJWT0N+ya|2%R80E~j}4!>Tc6u=+01kBqbM2wDIV07 zL-ZG??-fFJdCcVUnlGAjX4rK>SKffH=(TE2l{lf}`hqFn$1aTJng9waYx_DA*d#c= z5}SBy;tvPYlmXGi`K3^5~M{2xk8w!P{01tiknM+Ye8+7AU=;ZUbC=9l%672{_;;Gj7dQQAVMexjC4t*`qTUrPnhOc4NU&bm2n55TJEP$S`3}9EE8N!& znujOBUy?$c%{7od#)j?Swz#hExof1=|8)EI29?3HYMZ@8u$PlM>TVEEe zx=zo)ItJ*!#Qiz+tIS4FR&B7e;7Vh|SI)+(rE`W!2Hh3#vekmx>LMvm3)92Pv!Pk5^<(*O*B0o zt^=v1(fczE<~ENFW)33>f2P3yrRQ_p?5Jn4tSHEkG`?I`iBTwkWVUpcwvNlZ?AZ6t zR6kzJ=2u|{qa79gZ)IVl7T)zq0uSk|+?y6z++;pF8|`>jds-2HlH9CLiCBxN+GDkh zwJbK#G8TA!U%rjoPg%b9so#$i=#iY$7d3U&sNB-No)cP{$&x{G8!)9x|3B?rby!qe z*H;8Zx?4aHk(?QZE-C49Xpk6Y1_q=VIs{Ql8l*#z4pADV8w8Y8x<$G}@*DJCuip25 z-}nCU{`sEgVV=V}tM+fNbI#uTS!@JtOy{{=O=U%d&A!i!6 zsf+%GUzKhrxaM=3eRfLtS()O?fy@^v^i9O{NwcqunSwz9MrO_)7{M-;c2*mX3iZ(z zz1t#-t6-P1dC3Bl%q=s;yXuuYPtJocE4HY;J&MG%=gy;NS*Q?GEb^cfW9OH#9D7hP zZOB@r8Mk`5Lq0z2_5))}RFXqZuUI>zi$Gnr7Id&YBwOq-qo(2cy4ojqZ(VTy#k9yw zjeGOpKA*OTZ8ju*`LQ^06K|c4lcxcx5WIbV+!;hh!}k>FkZ{6;OXpQDy|kNN^;K`7 z5X>=zpG<1`AWii(=f{Q$h3sLbP-)EpM?|?SQbx;J&-e4u_@>%&#mgG84@IH%v2AN- zC9hZJ@xKYj6Pb@pJiL`Y%HB1a+^x_B(UoCn-n=re@kp7#F&SA8y81-R!-!h0idnIn z&$8H?D&msYzn`(WIkM=;j7X{Nzwut7;C6aXPguGp zN3d4hl?N20yi$Cq0V%Ye>Qu)WFJ6ic)U&dA`k`Q)al8+SBm2-=$U@QxCGfF~!MAt6 zYXLrXWi!O{vncv&qG3WuZ?!9)gT zmVh~ME~S^GT(iwkQZ`_rLpt<+KpjtDwOZk0!422qWS=NE*eJE?yzJhhYLk5Sa<+1^ zNlL0qd%~K$aU2p~12^IISo6e_XOd=iowRwq3gh$R9PRbrTsTwXnVj3=P1J%3zZt61 zy-IPG9hGT$VEIbU92aUSoLI%5WBOhPcj2=5tAubx!^~GUZoUs=?5&LQa5k>pNW;pR z&xnZHi7bYs5YTqp0cX5Y~_yZb#O8ck+7GfZ}rU|zc7ld zviroaIAzQ{mLiKyimM|!$?}MSkxGme+sK?B6i8+EKsCDm@X(ni*WB+CX(?kb#Z#}f zw6PTj6RT>XR;X*vOu?<;nj}?&7U?hD6L-Y|TH8)$)z!Q3QZrCuq-8Nt-eICJ}C!P-R$!=Tg5J;@Bh! zuX4z#^+4nn(3%94?coycCaT}{sbtr8sIvc(8H;C>C1x_&mBrlbFU~|=s5e`^1>CM_ zw-g`CZ=7Y0=rdfsREpQVpXDbWB9~XCI5j~RFZ;O$YH?4u+*#R{l?`=S+m>~0v`SB{ zMh{}7q2gwLgkP-nj7a>5r?mr&V84tWW9i^FRYG6vFA05%bt!;cIicBtls`z?c_Gtw zMt|L9FaK4Y5wb?c#J4jP*!(bu@8fbe@yna}_^K@JGL%njS#>*ATb6{?&7pM8jSE(1tomvt^?jBfO zjVvtMm2q!|W9Tot;%(m+sq5-r*|IrU*G0xw>}Ynq;a71wsd!g!#CLEk2P1e=NJ9{b z(Xcfc)i=XzBfiWYyL-#5rL1Sc;klJ3GMR^VTLuX}x=i6>4lYYe3ex`K{SX+jM++5oyGSG3rno&b;o^z}YDF zP6LH;RpFXeZ=B{+Dm_nv4__;Ipo`Ek2T)tY^dxBw2iy4?Q!ibaEvE;3lzf2x+F@lE zt1buIscJGK!+VBz?tY&gkLLhmPf4UB-Z<;A4GEa(u~9S;c}#><=OD@l*9@1tmH6C( zNRDRd!h?8ui!IB6#+`weB4eyKI$_cH0)??F_V4bei8XE`SFjl-F-H(yEFSIIyfTq3 z#~bBARSH&VqAe`ikNLb8Nuc;cO<86B83q$rTE4yQjAy-`%|?HNh9 zUTw!&>^TL2zv!xu!2f7`sjr6@m$)8fkr`*-8&0)T;vnQnFPbw_u-eROH`_%el!XjU zoL&QCzqR}jux8RLqBHz?C^~Rd=r9|3@9XPtJxVNMraET+8^{@eQ4^%nVA40a(tj)R zP>B>GaJxk+o0uU=TZ*-8rvZl0n|h3+4s5r25%}C0O zd<*J5swBg6zJ%QunlZV4Se5U0drVW>&zq)e4VR`&&bT>vLIOz`I)3|RiTXmRH-`8( z#vs#p`blk}nJ`N#@!QvQzkUhC2Co?UZ_4tf>&PxJvMmM*wA)>2uQm3JxA8)!NvrxD z=#uS+Kd?}1i|x4lh~XxV^ZhEF(;!<4f!LZcYIR9jhS9;hMX_-KF%NGh_%Kpn;Se;d zRctk2Po@i8F9p+FdzSlt{CRihsqXzW+Rer<qyaiUf~# zDf4G;LqV!H8hAOw<_JpdW1v)suLpf>astn!=-9W2yt^8el4(-aa<=zNHuEU^uG72Z zNlQ2Q*1NM{4YwBQV~cB$9Eds8DVIDBVnMisb^A_->j~VOc5Ln(BYPFJC<|Eh+E#tv zO&aeOI#1V&z|EF&Eqt=PlGi_7oEpmnsD9TssOP^)lUK^Cw4VW}l29x&g0FHDP{MCj zxNMR7ERtz*_QLQkhd7-~1c)|+>YC#iiGA$wUh)ZB^4@%WTigVt;cUHEtNcbah=-fy0s|Yym>2%eI%hDY^%3X&~g|XjWJcU zOJPBm&Z)ieo-~oNmcDoFG4)oo!`;ZZnl;}rh`CQr+KWAZhx|vmouY#qr@?kl$0oHg zUq|||a53NJY<@&eQkVC65aVu!xAAi)162Xjy8V~65x2!WFsifH!dr@I<2aPykw2maoCRg zXID5^rYoMgK{__2_ebyLr1ZBs_Oy22ikojWU9Rg)n#3KH{q~JDFSGG2As-83aTp}Z z<3oHkWx(1Kj)xMde!jF5Xcte^50f8{v9Iq&8I@qxz+!jJ)N$)0c?-=YpRBdNDdY9U#Y zm>)In&T{7)dD<=E%leDb>EMt%0lWCVu&oRXoMOxq;CxYM6?^|u^%m)7r(yX6w=oPI ziw7RTg7tJ~wL2a>Cw3{g#8vviovy0Y5To|bs30EpL{~rV0&Faj==jBjO>nq~E;bIO zt|uy4bvUqdqrLLsz|?TbGvjYpAqIg&5(d!LLN1?pu}KI2)pGKPG^2`jyZy(VSMD9M zLa{7kc7uc+I*&NO~7(viAhJ(y9?IJE8 z%IlW&`2|htlCRZlYyx9#4R#3%jcK=WX=J|MEH@M9`5e1Gpb9qb7Ze1-4{^d4%~T7LE|Y*k)P2dvqkt zS+vc@Jw{!3gCgres#7WH%ZOcy(SEPoa*=?DM3YYWXmdFe`-MWOBg+%*2`{5Um!qD@ zu;+{R`&AWrY%e1jp5Q%=0z2QREWlXKEsyf45~eL5w+9Rwy*RchRLL=QU?p2+QrJ_y z)^!fOwLTPBM#Z&bTJAkRZAkEmbJsr!e&yXKXp&O_s014`NVr0g+F)&@*ED3G)2OqF zo7+Z+P87o?)1@=f#}*>iTAciXAEWwt4%fzgRrSMHHKc4AJAn`C(}qXgclXKi$tbE$ z%AHPgGfu||arOknBnwXQIJg50XgfI4RkszJDu!qcNt+}mrH+0}@23uE)Tc*vys zqIX31r0R2}E8i}=hrigJySEBZm%}`<_mTF7qf9Zu9q}ugGj_T6=aWIijE%2X*`3WrxnpiF}d+hWfXGiU7gRpezFGp;&IZlDqgss*-*TWXADjp`OQGMo4P z4w#<%T-A~_6LvNI!1Kv+vGw?M$;S^%p?>D4gifuAEIn$0c0G?97`#{YRG#)470}~Z zZj1@Lszl!D7xkaIL1pJVNi(1z0 z@ch08QMi-2%WB+$gJ0)dBx6rqa}#!wlWWK*u|0ojlW|`YzTe1|5`{P(#L7GnyxJ>3m9Zusxz4(WZQ(mi>k&{^*9_Nb}TtZUx3_NrZW%}O}y*hX%C z+m``TR)h$jzw?7gJ#sqJI%A#;KjabCw_NtT;2DnV%?ATcd;7KpT||KN_5*p1NOBz~ zL5Md~!s9nGq_)XPoQt3;LgrfwD*GM+Q&E`Sa4?u_>L zS1%JQO-#Xl`Xs%8M5gdPl@O8%*1+5q*l$93miw)gy?f3@wG~gN^2N4`KC>o%>6>;b zHOvU&xlomevDvHdLLPG(AAH8V=h*lpt2GfKiXhpv+bc-Y1}B5;ZUJE6Y83l+)_bz zQ}PA&m0GVAQq$BF-v@_QiRPcuatvW&61x`fyN-FIP@7I4CESf#Z>o|Ct<-Y&v&FKu zbP5$iQp1#$t*pE1a7oKPUzeqa;O>_NqWsyf9(`rJWn`i3zz!63^+B0b5htu@Yn;}; z#Y~bVb*~x4=0%QkJgeAt5ITXC7WiN7F@O(88F7_Zj!nZ&@89-uNzI1MhI{3*`^sd+ zR3?<)%cm>4U9#ia7~`Xv6$ZH@Q0$(iUqfbJv)psIs##n8?O@f<92mM9QiAj95%;<^ z?Wl5!I_H+hW*az0Y_g=%eF*+Ry|i;W_c2E=Mc#p$JUxu6MvJr8N4?Y|jwaC$vrSSJ zKH|MTApw%UIU^C2R4Pa`T>MtWyBXQiM!=mplI9g;F5k?2vSC7JnPSj#Wob@-*Bhj2 z*ovFOwx9$SX}5pyk>~DB7{yXbQ3qy!w|tUUuzBh=WOrD1dU!QgyoZ-!Sbo=~`a)5K zW!)Giq!@BRwGB)UaaE}jJP!+jzum+Tn_YlWp zD%r`628+4Y$_7WK#gGW{gFeDXEhYB57T;2p~@ zh+3Ll45%PTR%{Y@Z?Tx3MC!I2K;M39u_WTOeK>KZZwjwpS~-u0ZDvByhwoc}^eqYO zTTGq$rJ;CKqI1eu@;xQrtuia-g4!@hlB{_nOrCf=R{}d&D~9F0n-`?uQfb|3ccNcP zRZd5}RMR&E4o-j;>^zol$P;hb8f-)?bf3Z%1kVqoo{}i=uLmnfRfNG9wc%ZX^(OF| z5>^Y1d2zASuRw@7EVE6y+d^&iG5*n0N4iu!=iy3(CUPLj=++>B*~zf z9(PZ0gutlV4rrctNi5$+Do*aa*WFrQiWs08-bScJLNi|*rF`teVqZW1_9ck0#Vq+5 z@F;0b(yu1rwg72T&@PR)@{xsLx5AJib1{({|5q-am52DzoN8WJaEZ~<;|lJXu$-7J zo?!WCJieTnHEpJVSK`)ojhHEF_T>C>uDy5?84(DP9^}|5F^1;ZV)EJG=z7|vT7P9m zJb^Fyvoo4+rcMrtTidHz80K*8+Jin$BU#T#CrsNUoAEcOuQYxLJwiSvq3&W}Pl(5) zT3lq#j0i*Ss8e@w&t0RTt@TXH!sBv&_LLoG#69Z%*Su&47M}fi>{%H>znqqqMV+-Y zalSDBF%4MM7!L&-tl6=5?qP~qKBz*T4Q}-D&8%2nes`)$3dfAt*#u*5Qlc|=XWGll zt(D0i*v5}p-XobYHHj+wDz;DpPd}N>c;2 zv|C`nX^K$gV%g~%8Lo&DyKfmTdedqsDbHPQ<=!pVJI7a3lE)o&S;Nn3hvRIonk?IJ zdVh4wAynz)LF&ORZXCQ#3@%7Dl+PmEBP>{_yMIGT#|N;ZP!0;<8Yy+kBzan=UL4-R zQF|w-l6CZB{JJ?g0hmqU?IjKlDEF6o=9|yh<_}7NrR~@gsuj$`yZp6K`lxPCRUyqq z-q%x^&vM3!o{mif*PN`jE=(B*a~vKNPd#AI^J4JG5+hdoqNw_Q_MDaC^7-*f8sI#u z0%)nq^{VFm;`YYWa|&%ikG-|5K}h>z+?LRu=Lq56_IAC|+1!xv<_h|ofwJc zPjp&!=KRupo@Nk!66G(cZ7W8Jw4stK3L>SfFt|&eEBsP z>)Y4fDb*{?q-|o{Jzp9tP%}P!8r`+ReOJ$KC{F49BHg%@*{cvf$@*{PF-}-Hotm8e z##m23J>kSGBz#=J@c?lfQ{c=AW+w(pY4NefvZC~A(&&9OMP?_sFo}_dyV-<&{jh_o z7?*C{x}~8pD(WmH;44dNkZ~Gb72bnHW8IsaJ?${us-7p7_Kx5Z@Hk+(y5r$}Lh`Rd zH{{Q zj@^CcLlR?X2<_O)Yda820KH#K83i-eqe;e|!Us(~N_3D{HL#BZ(GPXmYpWzVd>3j0+RGD4$z*O(Z;cXonGn_OdW%puGQs+L;v z>ABlSbC$b)XxWC3!Sh;|C|VC^uj+MOucFNxcthJZXfRVH#UBGeJ%T6T?7Ex&^X`I{?;c(u2)N@um68gbJ^QhhmxwtmV`yz;LSOOck)o?k}=W;hMLPGdO z#2E=Go_M$ku>&xd$e!v-lw=2d;)xa+q-lqYcpKjknKxjZWlSfp@VT5DnuCf@O<@LK zg>{@SZyV#B;mkvzO4JW?Hg#^W;2VgLG+ScTWLTYXn0(Eo@iEy17T&L$5mo6l+8!=X zu%;Q5Wt@!guMdfRk$YuNy;v~B&z=%G2eikmA^{Qbj!E>ejNsRm8)qP*wyJkSq`7+M zUZWvU_sL6<$@EJ`G47XKdQbx8zw=n0E>Q707)Jc*@ewtZ)7{cjIUh;V>* zHsULmv~i75)ywDFhk!+-I$KX`2)acyBB$ zZZ=oL zsC6n0I;`FsY@ACC*+5z!IqqUiTFenV@)#_o+>@mj=TJLe`RbC9l)0JTr$j@QFMsGi z#9Yy(EBd}OU9YP(Lr-ePE`??H-I9=$p^vz27|92aM7)}+5P+z_yL-!Mh7!GNXJB*; zarZ`;qO|-y`m>!rsqGQMZ#gf`1#pL(9|6=Jao3-z9j3NoJjK)T$=KH4eMC1S6QaGp zSuAI}>P~D)cwSjkV5k&OOt^V#4Pxx&py~5mF0&>vjD36=4>Y~27y>(8>*FvghAqqt zY-?V=aY}_Ff2ANb&>o*yUhT>aWzpjM)+OX;bN3~1nyJyxhD5(Dv$mO}mzx^>ql7qR z@kOF1^sCp-3#7%Ci;Zv0h%7sUyuWO!T+Yj4z2)giw0-obxA`;;XVy5psbOt;X9n=? zlda+>;mzV^E!pTH5n#_wB=`3a_9+NGhw^2+x_6-;ur>PbgP)@*;v=c}$BtK1RFqOTu-JNw*(TP1DCAotx z((Qj_xobF?qAs%FFH+$_04b;=;v#DvopkTyV1Z6}|DGX#LHR`(^#2LVBdnYeC<_=A zaL)#vDsN$9&WKL!zsTkPCv_KBe)u9|VP=Lvr~ad}_YJ^80DC7}6v7cLZG|xWA^E4e zUz`E|l>VnC10XzLbO!%-+YlaJ#_tV>{33o)9Pq>VFXBICeqp>o@CPFr8gy9!?+=eI ziU%A4N)~WO1D*>|A&lRRFg}l21Lc?8E z6XyO9CIn}?D~==TD(q@)XN}gz=xS|c<0$MZ#so!IU?7Ci=NDuE6XSOl)I%{QFgJ)x z0La56j>E{vDCz(=6Nbph{vn6{PmBqPLfHue04^>r+%8~lTL*IhNJvNs0OSGi@Nl6y zxX?Q(qoA%_Hjd0cl>Dhj2H^;Eu&_f}*xE2&=!KfvI-$gvm@W+cJpOPHYWLHSjU)GW zXSrdv)&N(i9RS1)1pL&D78FGjg{9GjCFq(A^q)8n5Xi>`BTPtyNX~=hNwhoNi2nWXtcY)l3+`wOS{K5G*B`WA3H*@>T2M`Yz z2&4((6$Sx?fr1=BkTCEMCBJa~UB@4N{%>jdmG=)lqJRr%e}VdYKVG2pH~RnA1#sBU z9ot3mg{Z9R}6;>7(@hEHswJ{fCa^->}(BHSPLNNh;=l+4j?@GSA z^3PU9(f+_Lg2>k4Z+b3((?Hn&PW{UlaciWLqa)P9=7&Kmi{BZ4P=A;I?#90wyKn(z zfwDsUO~Zu)zqjKTl>Qem#OzJLxS z@b7_yCJHMd++1uO;Euocsp!Q8bO9IK35IYGmy}gkW|TwPI--6&RTu@iLFm^0#`B-P zC(zFj6_tN($)67Y_eh;CKEQK(qZdZ+CS-nBn6989{>R-=7B~KOY~MkMZKl#UaEe z$cJ7fxHuSX{-p7v>A%xJKtZ(Gf1&XRp_dPSl|}P`L4TJ8@e6_fF3ZQmFNj`r_)V6N zM-Yr&Yxs@Ek4F3Nd}tc)ztV(&=rx(Y$qN084SqiKaP{wed?4Vz*yRK9qGREAeSAC@ z@$oxN2nha#hH`*fSRownanKt%Xjr%-(BPvx1P49rbwK^-4-kkSABTnIo|-H^&i?>A CY@I^@ literal 0 HcmV?d00001 diff --git a/doc/ikev2/[RFC2104] - HMAC - Keyed-Hashing for Message Authentication.txt b/doc/ikev2/[RFC2104] - HMAC - Keyed-Hashing for Message Authentication.txt new file mode 100644 index 000000000..1fb8fe11a --- /dev/null +++ b/doc/ikev2/[RFC2104] - HMAC - Keyed-Hashing for Message Authentication.txt @@ -0,0 +1,619 @@ + + + + + + +Network Working Group H. Krawczyk +Request for Comments: 2104 IBM +Category: Informational M. Bellare + UCSD + R. Canetti + IBM + February 1997 + + + HMAC: Keyed-Hashing for Message Authentication + +Status of This Memo + + This memo provides information for the Internet community. This memo + does not specify an Internet standard of any kind. Distribution of + this memo is unlimited. + +Abstract + + This document describes HMAC, a mechanism for message authentication + using cryptographic hash functions. HMAC can be used with any + iterative cryptographic hash function, e.g., MD5, SHA-1, in + combination with a secret shared key. The cryptographic strength of + HMAC depends on the properties of the underlying hash function. + +1. Introduction + + Providing a way to check the integrity of information transmitted + over or stored in an unreliable medium is a prime necessity in the + world of open computing and communications. Mechanisms that provide + such integrity check based on a secret key are usually called + "message authentication codes" (MAC). Typically, message + authentication codes are used between two parties that share a secret + key in order to validate information transmitted between these + parties. In this document we present such a MAC mechanism based on + cryptographic hash functions. This mechanism, called HMAC, is based + on work by the authors [BCK1] where the construction is presented and + cryptographically analyzed. We refer to that work for the details on + the rationale and security analysis of HMAC, and its comparison to + other keyed-hash methods. + + + + + + + + + + + +Krawczyk, et. al. Informational [Page 1] + +RFC 2104 HMAC February 1997 + + + HMAC can be used in combination with any iterated cryptographic hash + function. MD5 and SHA-1 are examples of such hash functions. HMAC + also uses a secret key for calculation and verification of the + message authentication values. The main goals behind this + construction are + + * To use, without modifications, available hash functions. + In particular, hash functions that perform well in software, + and for which code is freely and widely available. + + * To preserve the original performance of the hash function without + incurring a significant degradation. + + * To use and handle keys in a simple way. + + * To have a well understood cryptographic analysis of the strength of + the authentication mechanism based on reasonable assumptions on the + underlying hash function. + + * To allow for easy replaceability of the underlying hash function in + case that faster or more secure hash functions are found or + required. + + This document specifies HMAC using a generic cryptographic hash + function (denoted by H). Specific instantiations of HMAC need to + define a particular hash function. Current candidates for such hash + functions include SHA-1 [SHA], MD5 [MD5], RIPEMD-128/160 [RIPEMD]. + These different realizations of HMAC will be denoted by HMAC-SHA1, + HMAC-MD5, HMAC-RIPEMD, etc. + + Note: To the date of writing of this document MD5 and SHA-1 are the + most widely used cryptographic hash functions. MD5 has been recently + shown to be vulnerable to collision search attacks [Dobb]. This + attack and other currently known weaknesses of MD5 do not compromise + the use of MD5 within HMAC as specified in this document (see + [Dobb]); however, SHA-1 appears to be a cryptographically stronger + function. To this date, MD5 can be considered for use in HMAC for + applications where the superior performance of MD5 is critical. In + any case, implementers and users need to be aware of possible + cryptanalytic developments regarding any of these cryptographic hash + functions, and the eventual need to replace the underlying hash + function. (See section 6 for more information on the security of + HMAC.) + + + + + + + + +Krawczyk, et. al. Informational [Page 2] + +RFC 2104 HMAC February 1997 + + +2. Definition of HMAC + + The definition of HMAC requires a cryptographic hash function, which + we denote by H, and a secret key K. We assume H to be a cryptographic + hash function where data is hashed by iterating a basic compression + function on blocks of data. We denote by B the byte-length of such + blocks (B=64 for all the above mentioned examples of hash functions), + and by L the byte-length of hash outputs (L=16 for MD5, L=20 for + SHA-1). The authentication key K can be of any length up to B, the + block length of the hash function. Applications that use keys longer + than B bytes will first hash the key using H and then use the + resultant L byte string as the actual key to HMAC. In any case the + minimal recommended length for K is L bytes (as the hash output + length). See section 3 for more information on keys. + + We define two fixed and different strings ipad and opad as follows + (the 'i' and 'o' are mnemonics for inner and outer): + + ipad = the byte 0x36 repeated B times + opad = the byte 0x5C repeated B times. + + To compute HMAC over the data `text' we perform + + H(K XOR opad, H(K XOR ipad, text)) + + Namely, + + (1) append zeros to the end of K to create a B byte string + (e.g., if K is of length 20 bytes and B=64, then K will be + appended with 44 zero bytes 0x00) + (2) XOR (bitwise exclusive-OR) the B byte string computed in step + (1) with ipad + (3) append the stream of data 'text' to the B byte string resulting + from step (2) + (4) apply H to the stream generated in step (3) + (5) XOR (bitwise exclusive-OR) the B byte string computed in + step (1) with opad + (6) append the H result from step (4) to the B byte string + resulting from step (5) + (7) apply H to the stream generated in step (6) and output + the result + + For illustration purposes, sample code based on MD5 is provided as an + appendix. + + + + + + + +Krawczyk, et. al. Informational [Page 3] + +RFC 2104 HMAC February 1997 + + +3. Keys + + The key for HMAC can be of any length (keys longer than B bytes are + first hashed using H). However, less than L bytes is strongly + discouraged as it would decrease the security strength of the + function. Keys longer than L bytes are acceptable but the extra + length would not significantly increase the function strength. (A + longer key may be advisable if the randomness of the key is + considered weak.) + + Keys need to be chosen at random (or using a cryptographically strong + pseudo-random generator seeded with a random seed), and periodically + refreshed. (Current attacks do not indicate a specific recommended + frequency for key changes as these attacks are practically + infeasible. However, periodic key refreshment is a fundamental + security practice that helps against potential weaknesses of the + function and keys, and limits the damage of an exposed key.) + +4. Implementation Note + + HMAC is defined in such a way that the underlying hash function H can + be used with no modification to its code. In particular, it uses the + function H with the pre-defined initial value IV (a fixed value + specified by each iterative hash function to initialize its + compression function). However, if desired, a performance + improvement can be achieved at the cost of (possibly) modifying the + code of H to support variable IVs. + + The idea is that the intermediate results of the compression function + on the B-byte blocks (K XOR ipad) and (K XOR opad) can be precomputed + only once at the time of generation of the key K, or before its first + use. These intermediate results are stored and then used to + initialize the IV of H each time that a message needs to be + authenticated. This method saves, for each authenticated message, + the application of the compression function of H on two B-byte blocks + (i.e., on (K XOR ipad) and (K XOR opad)). Such a savings may be + significant when authenticating short streams of data. We stress + that the stored intermediate values need to be treated and protected + the same as secret keys. + + Choosing to implement HMAC in the above way is a decision of the + local implementation and has no effect on inter-operability. + + + + + + + + + +Krawczyk, et. al. Informational [Page 4] + +RFC 2104 HMAC February 1997 + + +5. Truncated output + + A well-known practice with message authentication codes is to + truncate the output of the MAC and output only part of the bits + (e.g., [MM, ANSI]). Preneel and van Oorschot [PV] show some + analytical advantages of truncating the output of hash-based MAC + functions. The results in this area are not absolute as for the + overall security advantages of truncation. It has advantages (less + information on the hash result available to an attacker) and + disadvantages (less bits to predict for the attacker). Applications + of HMAC can choose to truncate the output of HMAC by outputting the t + leftmost bits of the HMAC computation for some parameter t (namely, + the computation is carried in the normal way as defined in section 2 + above but the end result is truncated to t bits). We recommend that + the output length t be not less than half the length of the hash + output (to match the birthday attack bound) and not less than 80 bits + (a suitable lower bound on the number of bits that need to be + predicted by an attacker). We propose denoting a realization of HMAC + that uses a hash function H with t bits of output as HMAC-H-t. For + example, HMAC-SHA1-80 denotes HMAC computed using the SHA-1 function + and with the output truncated to 80 bits. (If the parameter t is not + specified, e.g. HMAC-MD5, then it is assumed that all the bits of the + hash are output.) + +6. Security + + The security of the message authentication mechanism presented here + depends on cryptographic properties of the hash function H: the + resistance to collision finding (limited to the case where the + initial value is secret and random, and where the output of the + function is not explicitly available to the attacker), and the + message authentication property of the compression function of H when + applied to single blocks (in HMAC these blocks are partially unknown + to an attacker as they contain the result of the inner H computation + and, in particular, cannot be fully chosen by the attacker). + + These properties, and actually stronger ones, are commonly assumed + for hash functions of the kind used with HMAC. In particular, a hash + function for which the above properties do not hold would become + unsuitable for most (probably, all) cryptographic applications, + including alternative message authentication schemes based on such + functions. (For a complete analysis and rationale of the HMAC + function the reader is referred to [BCK1].) + + + + + + + + +Krawczyk, et. al. Informational [Page 5] + +RFC 2104 HMAC February 1997 + + + Given the limited confidence gained so far as for the cryptographic + strength of candidate hash functions, it is important to observe the + following two properties of the HMAC construction and its secure use + for message authentication: + + 1. The construction is independent of the details of the particular + hash function H in use and then the latter can be replaced by any + other secure (iterative) cryptographic hash function. + + 2. Message authentication, as opposed to encryption, has a + "transient" effect. A published breaking of a message authentication + scheme would lead to the replacement of that scheme, but would have + no adversarial effect on information authenticated in the past. This + is in sharp contrast with encryption, where information encrypted + today may suffer from exposure in the future if, and when, the + encryption algorithm is broken. + + The strongest attack known against HMAC is based on the frequency of + collisions for the hash function H ("birthday attack") [PV,BCK2], and + is totally impractical for minimally reasonable hash functions. + + As an example, if we consider a hash function like MD5 where the + output length equals L=16 bytes (128 bits) the attacker needs to + acquire the correct message authentication tags computed (with the + _same_ secret key K!) on about 2**64 known plaintexts. This would + require the processing of at least 2**64 blocks under H, an + impossible task in any realistic scenario (for a block length of 64 + bytes this would take 250,000 years in a continuous 1Gbps link, and + without changing the secret key K during all this time). This attack + could become realistic only if serious flaws in the collision + behavior of the function H are discovered (e.g. collisions found + after 2**30 messages). Such a discovery would determine the immediate + replacement of the function H (the effects of such failure would be + far more severe for the traditional uses of H in the context of + digital signatures, public key certificates, etc.). + + Note: this attack needs to be strongly contrasted with regular + collision attacks on cryptographic hash functions where no secret key + is involved and where 2**64 off-line parallelizable (!) operations + suffice to find collisions. The latter attack is approaching + feasibility [VW] while the birthday attack on HMAC is totally + impractical. (In the above examples, if one uses a hash function + with, say, 160 bit of output then 2**64 should be replaced by 2**80.) + + + + + + + + +Krawczyk, et. al. Informational [Page 6] + +RFC 2104 HMAC February 1997 + + + A correct implementation of the above construction, the choice of + random (or cryptographically pseudorandom) keys, a secure key + exchange mechanism, frequent key refreshments, and good secrecy + protection of keys are all essential ingredients for the security of + the integrity verification mechanism provided by HMAC. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Krawczyk, et. al. Informational [Page 7] + +RFC 2104 HMAC February 1997 + + +Appendix -- Sample Code + + For the sake of illustration we provide the following sample code for + the implementation of HMAC-MD5 as well as some corresponding test + vectors (the code is based on MD5 code as described in [MD5]). + +/* +** Function: hmac_md5 +*/ + +void +hmac_md5(text, text_len, key, key_len, digest) +unsigned char* text; /* pointer to data stream */ +int text_len; /* length of data stream */ +unsigned char* key; /* pointer to authentication key */ +int key_len; /* length of authentication key */ +caddr_t digest; /* caller digest to be filled in */ + +{ + MD5_CTX context; + unsigned char k_ipad[65]; /* inner padding - + * key XORd with ipad + */ + unsigned char k_opad[65]; /* outer padding - + * key XORd with opad + */ + unsigned char tk[16]; + int i; + /* if key is longer than 64 bytes reset it to key=MD5(key) */ + if (key_len > 64) { + + MD5_CTX tctx; + + MD5Init(&tctx); + MD5Update(&tctx, key, key_len); + MD5Final(tk, &tctx); + + key = tk; + key_len = 16; + } + + /* + * the HMAC_MD5 transform looks like: + * + * MD5(K XOR opad, MD5(K XOR ipad, text)) + * + * where K is an n byte key + * ipad is the byte 0x36 repeated 64 times + + + +Krawczyk, et. al. Informational [Page 8] + +RFC 2104 HMAC February 1997 + + + * opad is the byte 0x5c repeated 64 times + * and text is the data being protected + */ + + /* start out by storing key in pads */ + bzero( k_ipad, sizeof k_ipad); + bzero( k_opad, sizeof k_opad); + bcopy( key, k_ipad, key_len); + bcopy( key, k_opad, key_len); + + /* XOR key with ipad and opad values */ + for (i=0; i<64; i++) { + k_ipad[i] ^= 0x36; + k_opad[i] ^= 0x5c; + } + /* + * perform inner MD5 + */ + MD5Init(&context); /* init context for 1st + * pass */ + MD5Update(&context, k_ipad, 64) /* start with inner pad */ + MD5Update(&context, text, text_len); /* then text of datagram */ + MD5Final(digest, &context); /* finish up 1st pass */ + /* + * perform outer MD5 + */ + MD5Init(&context); /* init context for 2nd + * pass */ + MD5Update(&context, k_opad, 64); /* start with outer pad */ + MD5Update(&context, digest, 16); /* then results of 1st + * hash */ + MD5Final(digest, &context); /* finish up 2nd pass */ +} + +Test Vectors (Trailing '\0' of a character string not included in test): + + key = 0x0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b + key_len = 16 bytes + data = "Hi There" + data_len = 8 bytes + digest = 0x9294727a3638bb1c13f48ef8158bfc9d + + key = "Jefe" + data = "what do ya want for nothing?" + data_len = 28 bytes + digest = 0x750c783e6ab0b503eaa86e310a5db738 + + key = 0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + + + +Krawczyk, et. al. Informational [Page 9] + +RFC 2104 HMAC February 1997 + + + key_len 16 bytes + data = 0xDDDDDDDDDDDDDDDDDDDD... + ..DDDDDDDDDDDDDDDDDDDD... + ..DDDDDDDDDDDDDDDDDDDD... + ..DDDDDDDDDDDDDDDDDDDD... + ..DDDDDDDDDDDDDDDDDDDD + data_len = 50 bytes + digest = 0x56be34521d144c88dbb8c733f0e8b3f6 + +Acknowledgments + + Pau-Chen Cheng, Jeff Kraemer, and Michael Oehler, have provided + useful comments on early drafts, and ran the first interoperability + tests of this specification. Jeff and Pau-Chen kindly provided the + sample code and test vectors that appear in the appendix. Burt + Kaliski, Bart Preneel, Matt Robshaw, Adi Shamir, and Paul van + Oorschot have provided useful comments and suggestions during the + investigation of the HMAC construction. + +References + + [ANSI] ANSI X9.9, "American National Standard for Financial + Institution Message Authentication (Wholesale)," American + Bankers Association, 1981. Revised 1986. + + [Atk] Atkinson, R., "IP Authentication Header", RFC 1826, August + 1995. + + [BCK1] M. Bellare, R. Canetti, and H. Krawczyk, + "Keyed Hash Functions and Message Authentication", + Proceedings of Crypto'96, LNCS 1109, pp. 1-15. + (http://www.research.ibm.com/security/keyed-md5.html) + + [BCK2] M. Bellare, R. Canetti, and H. Krawczyk, + "Pseudorandom Functions Revisited: The Cascade Construction", + Proceedings of FOCS'96. + + [Dobb] H. Dobbertin, "The Status of MD5 After a Recent Attack", + RSA Labs' CryptoBytes, Vol. 2 No. 2, Summer 1996. + http://www.rsa.com/rsalabs/pubs/cryptobytes.html + + [PV] B. Preneel and P. van Oorschot, "Building fast MACs from hash + functions", Advances in Cryptology -- CRYPTO'95 Proceedings, + Lecture Notes in Computer Science, Springer-Verlag Vol.963, + 1995, pp. 1-14. + + [MD5] Rivest, R., "The MD5 Message-Digest Algorithm", + RFC 1321, April 1992. + + + +Krawczyk, et. al. Informational [Page 10] + +RFC 2104 HMAC February 1997 + + + [MM] Meyer, S. and Matyas, S.M., Cryptography, New York Wiley, + 1982. + + [RIPEMD] H. Dobbertin, A. Bosselaers, and B. Preneel, "RIPEMD-160: A + strengthened version of RIPEMD", Fast Software Encryption, + LNCS Vol 1039, pp. 71-82. + ftp://ftp.esat.kuleuven.ac.be/pub/COSIC/bosselae/ripemd/. + + [SHA] NIST, FIPS PUB 180-1: Secure Hash Standard, April 1995. + + [Tsu] G. Tsudik, "Message authentication with one-way hash + functions", In Proceedings of Infocom'92, May 1992. + (Also in "Access Control and Policy Enforcement in + Internetworks", Ph.D. Dissertation, Computer Science + Department, University of Southern California, April 1991.) + + [VW] P. van Oorschot and M. Wiener, "Parallel Collision + Search with Applications to Hash Functions and Discrete + Logarithms", Proceedings of the 2nd ACM Conf. Computer and + Communications Security, Fairfax, VA, November 1994. + +Authors' Addresses + + Hugo Krawczyk + IBM T.J. Watson Research Center + P.O.Box 704 + Yorktown Heights, NY 10598 + + EMail: hugo@watson.ibm.com + + Mihir Bellare + Dept of Computer Science and Engineering + Mail Code 0114 + University of California at San Diego + 9500 Gilman Drive + La Jolla, CA 92093 + + EMail: mihir@cs.ucsd.edu + + Ran Canetti + IBM T.J. Watson Research Center + P.O.Box 704 + Yorktown Heights, NY 10598 + + EMail: canetti@watson.ibm.com + + + + + + +Krawczyk, et. al. Informational [Page 11] + diff --git a/doc/ikev2/[RFC2407] - The Internet IP Security Domain of Interpretation for ISAKMP.txt b/doc/ikev2/[RFC2407] - The Internet IP Security Domain of Interpretation for ISAKMP.txt new file mode 100644 index 000000000..7b2f87c85 --- /dev/null +++ b/doc/ikev2/[RFC2407] - The Internet IP Security Domain of Interpretation for ISAKMP.txt @@ -0,0 +1,1795 @@ + + + + + + +Network Working Group D. Piper +Request for Comments: 2407 Network Alchemy +Category: Standards Track November 1998 + + + The Internet IP Security Domain of Interpretation for ISAKMP + +Status of this Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (1998). All Rights Reserved. + +IESG Note + + Section 4.4.4.2 states, "All implememtations within the IPSEC DOI + MUST support ESP_DES...". Recent work in the area of cryptanalysis + suggests that DES may not be sufficiently strong for many + applications. Therefore, it is very likely that the IETF will + deprecate the use of ESP_DES as a mandatory cipher suite in the near + future. It will remain as an optional use protocol. Although the + IPsec working group and the IETF in general have not settled on an + alternative algorithm (taking into account concerns of security and + performance), implementers may want to heed the recommendations of + section 4.4.4.3 on the use of ESP_3DES. + +1. Abstract + + The Internet Security Association and Key Management Protocol + (ISAKMP) defines a framework for security association management and + cryptographic key establishment for the Internet. This framework + consists of defined exchanges, payloads, and processing guidelines + that occur within a given Domain of Interpretation (DOI). This + document defines the Internet IP Security DOI (IPSEC DOI), which + instantiates ISAKMP for use with IP when IP uses ISAKMP to negotiate + security associations. + + For a list of changes since the previous version of the IPSEC DOI, + please see Section 7. + + + + + + +Piper Standards Track [Page 1] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +2. Introduction + + Within ISAKMP, a Domain of Interpretation is used to group related + protocols using ISAKMP to negotiate security associations. Security + protocols sharing a DOI choose security protocol and cryptographic + transforms from a common namespace and share key exchange protocol + identifiers. They also share a common interpretation of DOI-specific + payload data content, including the Security Association and + Identification payloads. + + Overall, ISAKMP places the following requirements on a DOI + definition: + + o define the naming scheme for DOI-specific protocol identifiers + o define the interpretation for the Situation field + o define the set of applicable security policies + o define the syntax for DOI-specific SA Attributes (Phase II) + o define the syntax for DOI-specific payload contents + o define additional Key Exchange types, if needed + o define additional Notification Message types, if needed + + The remainder of this document details the instantiation of these + requirements for using the IP Security (IPSEC) protocols to provide + authentication, integrity, and/or confidentiality for IP packets sent + between cooperating host systems and/or firewalls. + + For a description of the overall IPSEC architecture, see [ARCH], + [AH], and [ESP]. + +3. Terms and Definitions + + The keywords MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, + SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL, when they appear in this + document, are to be interpreted as described in [RFC 2119]. + +4.1 IPSEC Naming Scheme + + Within ISAKMP, all DOI's must be registered with the IANA in the + "Assigned Numbers" RFC [STD-2]. The IANA Assigned Number for the + Internet IP Security DOI (IPSEC DOI) is one (1). Within the IPSEC + DOI, all well-known identifiers MUST be registered with the IANA + under the IPSEC DOI. Unless otherwise noted, all tables within this + document refer to IANA Assigned Numbers for the IPSEC DOI. See + Section 6 for further information relating to the IANA registry for + the IPSEC DOI. + + All multi-octet binary values are stored in network byte order. + + + + +Piper Standards Track [Page 2] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.2 IPSEC Situation Definition + + Within ISAKMP, the Situation provides information that can be used by + the responder to make a policy determination about how to process the + incoming Security Association request. For the IPSEC DOI, the + Situation field is a four (4) octet bitmask with the following + values. + + Situation Value + --------- ----- + SIT_IDENTITY_ONLY 0x01 + SIT_SECRECY 0x02 + SIT_INTEGRITY 0x04 + +4.2.1 SIT_IDENTITY_ONLY + + The SIT_IDENTITY_ONLY type specifies that the security association + will be identified by source identity information present in an + associated Identification Payload. See Section 4.6.2 for a complete + description of the various Identification types. All IPSEC DOI + implementations MUST support SIT_IDENTITY_ONLY by including an + Identification Payload in at least one of the Phase I Oakley + exchanges ([IKE], Section 5) and MUST abort any association setup + that does not include an Identification Payload. + + If an initiator supports neither SIT_SECRECY nor SIT_INTEGRITY, the + situation consists only of the 4 octet situation bitmap and does not + include the Labeled Domain Identifier field (Figure 1, Section 4.6.1) + or any subsequent label information. Conversely, if the initiator + supports either SIT_SECRECY or SIT_INTEGRITY, the Labeled Domain + Identifier MUST be included in the situation payload. + +4.2.2 SIT_SECRECY + + The SIT_SECRECY type specifies that the security association is being + negotiated in an environment that requires labeled secrecy. If + SIT_SECRECY is present in the Situation bitmap, the Situation field + will be followed by variable-length data that includes a sensitivity + level and compartment bitmask. See Section 4.6.1 for a complete + description of the Security Association Payload format. + + If an initiator does not support SIT_SECRECY, SIT_SECRECY MUST NOT be + set in the Situation bitmap and no secrecy level or category bitmaps + shall be included. + + If a responder does not support SIT_SECRECY, a SITUATION-NOT- + SUPPORTED Notification Payload SHOULD be returned and the security + association setup MUST be aborted. + + + +Piper Standards Track [Page 3] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.2.3 SIT_INTEGRITY + + The SIT_INTEGRITY type specifies that the security association is + being negotiated in an environment that requires labeled integrity. + If SIT_INTEGRITY is present in the Situation bitmap, the Situation + field will be followed by variable-length data that includes an + integrity level and compartment bitmask. If SIT_SECRECY is also in + use for the association, the integrity information immediately + follows the variable-length secrecy level and categories. See + section 4.6.1 for a complete description of the Security Association + Payload format. + + If an initiator does not support SIT_INTEGRITY, SIT_INTEGRITY MUST + NOT be set in the Situation bitmap and no integrity level or category + bitmaps shall be included. + + If a responder does not support SIT_INTEGRITY, a SITUATION-NOT- + SUPPORTED Notification Payload SHOULD be returned and the security + association setup MUST be aborted. + +4.3 IPSEC Security Policy Requirements + + The IPSEC DOI does not impose specific security policy requirements + on any implementation. Host system policy issues are outside of the + scope of this document. + + However, the following sections touch on some of the issues that must + be considered when designing an IPSEC DOI host implementation. This + section should be considered only informational in nature. + +4.3.1 Key Management Issues + + It is expected that many systems choosing to implement ISAKMP will + strive to provide a protected domain of execution for a combined IKE + key management daemon. On protected-mode multiuser operating + systems, this key management daemon will likely exist as a separate + privileged process. + + In such an environment, a formalized API to introduce keying material + into the TCP/IP kernel may be desirable. The IP Security + architecture does not place any requirements for structure or flow + between a host TCP/IP kernel and its key management provider. + + + + + + + + + +Piper Standards Track [Page 4] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.3.2 Static Keying Issues + + Host systems that implement static keys, either for use directly by + IPSEC, or for authentication purposes (see [IKE] Section 5.4), should + take steps to protect the static keying material when it is not + residing in a protected memory domain or actively in use by the + TCP/IP kernel. + + For example, on a laptop, one might choose to store the static keys + in a configuration store that is, itself, encrypted under a private + password. + + Depending on the operating system and utility software installed, it + may not be possible to protect the static keys once they've been + loaded into the TCP/IP kernel, however they should not be trivially + recoverable on initial system startup without having to satisfy some + additional form of authentication. + +4.3.3 Host Policy Issues + + It is not realistic to assume that the transition to IPSEC will occur + overnight. Host systems must be prepared to implement flexible + policy lists that describe which systems they desire to speak + securely with and which systems they require speak securely to them. + Some notion of proxy firewall addresses may also be required. + + A minimal approach is probably a static list of IP addresses, network + masks, and a security required flag or flags. + + A more flexible implementation might consist of a list of wildcard + DNS names (e.g. '*.foo.bar'), an in/out bitmask, and an optional + firewall address. The wildcard DNS name would be used to match + incoming or outgoing IP addresses, the in/out bitmask would be used + to determine whether or not security was to be applied and in which + direction, and the optional firewall address would be used to + indicate whether or not tunnel mode would be needed to talk to the + target system though an intermediate firewall. + +4.3.4 Certificate Management + + Host systems implementing a certificate-based authentication scheme + will need a mechanism for obtaining and managing a database of + certificates. + + Secure DNS is to be one certificate distribution mechanism, however + the pervasive availability of secure DNS zones, in the short term, is + doubtful for many reasons. What's far more likely is that hosts will + + + + +Piper Standards Track [Page 5] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + need an ability to import certificates that they acquire through + secure, out-of-band mechanisms, as well as an ability to export their + own certificates for use by other systems. + + However, manual certificate management should not be done so as to + preclude the ability to introduce dynamic certificate discovery + mechanisms and/or protocols as they become available. + +4.4 IPSEC Assigned Numbers + + The following sections list the Assigned Numbers for the IPSEC DOI: + Situation Identifiers, Protocol Identifiers, Transform Identifiers, + AH, ESP, and IPCOMP Transform Identifiers, Security Association + Attribute Type Values, Labeled Domain Identifiers, ID Payload Type + Values, and Notify Message Type Values. + +4.4.1 IPSEC Security Protocol Identifier + + The ISAKMP proposal syntax was specifically designed to allow for the + simultaneous negotiation of multiple Phase II security protocol + suites within a single negotiation. As a result, the protocol suites + listed below form the set of protocols that can be negotiated at the + same time. It is a host policy decision as to what protocol suites + might be negotiated together. + + The following table lists the values for the Security Protocol + Identifiers referenced in an ISAKMP Proposal Payload for the IPSEC + DOI. + + Protocol ID Value + ----------- ----- + RESERVED 0 + PROTO_ISAKMP 1 + PROTO_IPSEC_AH 2 + PROTO_IPSEC_ESP 3 + PROTO_IPCOMP 4 + +4.4.1.1 PROTO_ISAKMP + + The PROTO_ISAKMP type specifies message protection required during + Phase I of the ISAKMP protocol. The specific protection mechanism + used for the IPSEC DOI is described in [IKE]. All implementations + within the IPSEC DOI MUST support PROTO_ISAKMP. + + NB: ISAKMP reserves the value one (1) across all DOI definitions. + + + + + + +Piper Standards Track [Page 6] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.4.1.2 PROTO_IPSEC_AH + + The PROTO_IPSEC_AH type specifies IP packet authentication. The + default AH transform provides data origin authentication, integrity + protection, and replay detection. For export control considerations, + confidentiality MUST NOT be provided by any PROTO_IPSEC_AH transform. + +4.4.1.3 PROTO_IPSEC_ESP + + The PROTO_IPSEC_ESP type specifies IP packet confidentiality. + Authentication, if required, must be provided as part of the ESP + transform. The default ESP transform includes data origin + authentication, integrity protection, replay detection, and + confidentiality. + +4.4.1.4 PROTO_IPCOMP + + The PROTO_IPCOMP type specifies IP payload compression as defined in + [IPCOMP]. + +4.4.2 IPSEC ISAKMP Transform Identifiers + + As part of an ISAKMP Phase I negotiation, the initiator's choice of + Key Exchange offerings is made using some host system policy + description. The actual selection of Key Exchange mechanism is made + using the standard ISAKMP Proposal Payload. The following table + lists the defined ISAKMP Phase I Transform Identifiers for the + Proposal Payload for the IPSEC DOI. + + Transform Value + --------- ----- + RESERVED 0 + KEY_IKE 1 + + Within the ISAKMP and IPSEC DOI framework it is possible to define + key establishment protocols other than IKE (Oakley). Previous + versions of this document defined types both for manual keying and + for schemes based on use of a generic Key Distribution Center (KDC). + These identifiers have been removed from the current document. + + The IPSEC DOI can still be extended later to include values for + additional non-Oakley key establishment protocols for ISAKMP and + IPSEC, such as Kerberos [RFC-1510] or the Group Key Management + Protocol (GKMP) [RFC-2093]. + + + + + + + +Piper Standards Track [Page 7] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.4.2.1 KEY_IKE + + The KEY_IKE type specifies the hybrid ISAKMP/Oakley Diffie-Hellman + key exchange (IKE) as defined in the [IKE] document. All + implementations within the IPSEC DOI MUST support KEY_IKE. + +4.4.3 IPSEC AH Transform Identifiers + + The Authentication Header Protocol (AH) defines one mandatory and + several optional transforms used to provide authentication, + integrity, and replay detection. The following table lists the + defined AH Transform Identifiers for the ISAKMP Proposal Payload for + the IPSEC DOI. + + Note: the Authentication Algorithm attribute MUST be specified to + identify the appropriate AH protection suite. For example, AH_MD5 + can best be thought of as a generic AH transform using MD5. To + request the HMAC construction with AH, one specifies the AH_MD5 + transform ID along with the Authentication Algorithm attribute set to + HMAC-MD5. This is shown using the "Auth(HMAC-MD5)" notation in the + following sections. + + Transform ID Value + ------------ ----- + RESERVED 0-1 + AH_MD5 2 + AH_SHA 3 + AH_DES 4 + + Note: all mandatory-to-implement algorithms are listed as "MUST" + implement (e.g. AH_MD5) in the following sections. All other + algorithms are optional and MAY be implemented in any particular + implementation. + +4.4.3.1 AH_MD5 + + The AH_MD5 type specifies a generic AH transform using MD5. The + actual protection suite is determined in concert with an associated + SA attribute list. A generic MD5 transform is currently undefined. + + All implementations within the IPSEC DOI MUST support AH_MD5 along + with the Auth(HMAC-MD5) attribute. This suite is defined as the + HMAC-MD5-96 transform described in [HMACMD5]. + + The AH_MD5 type along with the Auth(KPDK) attribute specifies the AH + transform (Key/Pad/Data/Key) described in RFC-1826. + + + + + +Piper Standards Track [Page 8] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Use of AH_MD5 with any other Authentication Algorithm attribute value + is currently undefined. + +4.4.3.2 AH_SHA + + The AH_SHA type specifies a generic AH transform using SHA-1. The + actual protection suite is determined in concert with an associated + SA attribute list. A generic SHA transform is currently undefined. + + All implementations within the IPSEC DOI MUST support AH_SHA along + with the Auth(HMAC-SHA) attribute. This suite is defined as the + HMAC-SHA-1-96 transform described in [HMACSHA]. + + Use of AH_SHA with any other Authentication Algorithm attribute value + is currently undefined. + +4.4.3.3 AH_DES + + The AH_DES type specifies a generic AH transform using DES. The + actual protection suite is determined in concert with an associated + SA attribute list. A generic DES transform is currently undefined. + + The IPSEC DOI defines AH_DES along with the Auth(DES-MAC) attribute + to be a DES-MAC transform. Implementations are not required to + support this mode. + + Use of AH_DES with any other Authentication Algorithm attribute value + is currently undefined. + +4.4.4 IPSEC ESP Transform Identifiers + + The Encapsulating Security Payload (ESP) defines one mandatory and + many optional transforms used to provide data confidentiality. The + following table lists the defined ESP Transform Identifiers for the + ISAKMP Proposal Payload for the IPSEC DOI. + + Note: when authentication, integrity protection, and replay detection + are required, the Authentication Algorithm attribute MUST be + specified to identify the appropriate ESP protection suite. For + example, to request HMAC-MD5 authentication with 3DES, one specifies + the ESP_3DES transform ID with the Authentication Algorithm attribute + set to HMAC-MD5. For additional processing requirements, see Section + 4.5 (Authentication Algorithm). + + + + + + + + +Piper Standards Track [Page 9] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Transform ID Value + ------------ ----- + RESERVED 0 + ESP_DES_IV64 1 + ESP_DES 2 + ESP_3DES 3 + ESP_RC5 4 + ESP_IDEA 5 + ESP_CAST 6 + ESP_BLOWFISH 7 + ESP_3IDEA 8 + ESP_DES_IV32 9 + ESP_RC4 10 + ESP_NULL 11 + + Note: all mandatory-to-implement algorithms are listed as "MUST" + implement (e.g. ESP_DES) in the following sections. All other + algorithms are optional and MAY be implemented in any particular + implementation. + +4.4.4.1 ESP_DES_IV64 + + The ESP_DES_IV64 type specifies the DES-CBC transform defined in + RFC-1827 and RFC-1829 using a 64-bit IV. + +4.4.4.2 ESP_DES + + The ESP_DES type specifies a generic DES transform using DES-CBC. + The actual protection suite is determined in concert with an + associated SA attribute list. A generic transform is currently + undefined. + + All implementations within the IPSEC DOI MUST support ESP_DES along + with the Auth(HMAC-MD5) attribute. This suite is defined as the + [DES] transform, with authentication and integrity provided by HMAC + MD5 [HMACMD5]. + +4.4.4.3 ESP_3DES + + The ESP_3DES type specifies a generic triple-DES transform. The + actual protection suite is determined in concert with an associated + SA attribute list. The generic transform is currently undefined. + + All implementations within the IPSEC DOI are strongly encouraged to + support ESP_3DES along with the Auth(HMAC-MD5) attribute. This suite + is defined as the [ESPCBC] transform, with authentication and + integrity provided by HMAC MD5 [HMACMD5]. + + + + +Piper Standards Track [Page 10] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.4.4.4 ESP_RC5 + + The ESP_RC5 type specifies the RC5 transform defined in [ESPCBC]. + +4.4.4.5 ESP_IDEA + + The ESP_IDEA type specifies the IDEA transform defined in [ESPCBC]. + +4.4.4.6 ESP_CAST + + The ESP_CAST type specifies the CAST transform defined in [ESPCBC]. + +4.4.4.7 ESP_BLOWFISH + + The ESP_BLOWFISH type specifies the BLOWFISH transform defined in + [ESPCBC]. + +4.4.4.8 ESP_3IDEA + + The ESP_3IDEA type is reserved for triple-IDEA. + +4.4.4.9 ESP_DES_IV32 + + The ESP_DES_IV32 type specifies the DES-CBC transform defined in + RFC-1827 and RFC-1829 using a 32-bit IV. + +4.4.4.10 ESP_RC4 + + The ESP_RC4 type is reserved for RC4. + +4.4.4.11 ESP_NULL + + The ESP_NULL type specifies no confidentiality is to be provided by + ESP. ESP_NULL is used when ESP is being used to tunnel packets which + require only authentication, integrity protection, and replay + detection. + + All implementations within the IPSEC DOI MUST support ESP_NULL. The + ESP NULL transform is defined in [ESPNULL]. See the Authentication + Algorithm attribute description in Section 4.5 for additional + requirements relating to the use of ESP_NULL. + +4.4.5 IPSEC IPCOMP Transform Identifiers + + The IP Compression (IPCOMP) transforms define optional compression + algorithms that can be negotiated to provide for IP payload + compression ([IPCOMP]). The following table lists the defined IPCOMP + Transform Identifiers for the ISAKMP Proposal Payload within the + + + +Piper Standards Track [Page 11] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + IPSEC DOI. + + Transform ID Value + ------------ ----- + RESERVED 0 + IPCOMP_OUI 1 + IPCOMP_DEFLATE 2 + IPCOMP_LZS 3 + +4.4.5.1 IPCOMP_OUI + + The IPCOMP_OUI type specifies a proprietary compression transform. + The IPCOMP_OUI type must be accompanied by an attribute which further + identifies the specific vendor algorithm. + +4.4.5.2 IPCOMP_DEFLATE + + The IPCOMP_DEFLATE type specifies the use of the "zlib" deflate + algorithm as specified in [DEFLATE]. + +4.4.5.3 IPCOMP_LZS + + The IPCOMP_LZS type specifies the use of the Stac Electronics LZS + algorithm as specified in [LZS]. + +4.5 IPSEC Security Association Attributes + + The following SA attribute definitions are used in Phase II of an IKE + negotiation. Attribute types can be either Basic (B) or Variable- + Length (V). Encoding of these attributes is defined in the base + ISAKMP specification. + + Attributes described as basic MUST NOT be encoded as variable. + Variable length attributes MAY be encoded as basic attributes if + their value can fit into two octets. See [IKE] for further + information on attribute encoding in the IPSEC DOI. All restrictions + listed in [IKE] also apply to the IPSEC DOI. + + + + + + + + + + + + + + +Piper Standards Track [Page 12] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Attribute Types + + class value type + ------------------------------------------------- + SA Life Type 1 B + SA Life Duration 2 V + Group Description 3 B + Encapsulation Mode 4 B + Authentication Algorithm 5 B + Key Length 6 B + Key Rounds 7 B + Compress Dictionary Size 8 B + Compress Private Algorithm 9 V + + Class Values + + SA Life Type + SA Duration + + Specifies the time-to-live for the overall security + association. When the SA expires, all keys negotiated under + the association (AH or ESP) must be renegotiated. The life + type values are: + + RESERVED 0 + seconds 1 + kilobytes 2 + + Values 3-61439 are reserved to IANA. Values 61440-65535 are + for private use. For a given Life Type, the value of the + Life Duration attribute defines the actual length of the + component lifetime -- either a number of seconds, or a number + of Kbytes that can be protected. + + If unspecified, the default value shall be assumed to be + 28800 seconds (8 hours). + + An SA Life Duration attribute MUST always follow an SA Life + Type which describes the units of duration. + + See Section 4.5.4 for additional information relating to + lifetime notification. + + Group Description + + Specifies the Oakley Group to be used in a PFS QM + negotiation. For a list of supported values, see Appendix A + of [IKE]. + + + +Piper Standards Track [Page 13] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Encapsulation Mode + RESERVED 0 + Tunnel 1 + Transport 2 + + Values 3-61439 are reserved to IANA. Values 61440-65535 are + for private use. + + If unspecified, the default value shall be assumed to be + unspecified (host-dependent). + + Authentication Algorithm + RESERVED 0 + HMAC-MD5 1 + HMAC-SHA 2 + DES-MAC 3 + KPDK 4 + + Values 5-61439 are reserved to IANA. Values 61440-65535 are + for private use. + + There is no default value for Auth Algorithm, as it must be + specified to correctly identify the applicable AH or ESP + transform, except in the following case. + + When negotiating ESP without authentication, the Auth + Algorithm attribute MUST NOT be included in the proposal. + + When negotiating ESP without confidentiality, the Auth + Algorithm attribute MUST be included in the proposal and the + ESP transform ID must be ESP_NULL. + + Key Length + RESERVED 0 + + There is no default value for Key Length, as it must be + specified for transforms using ciphers with variable key + lengths. For fixed length ciphers, the Key Length attribute + MUST NOT be sent. + + Key Rounds + RESERVED 0 + + There is no default value for Key Rounds, as it must be + specified for transforms using ciphers with varying numbers + of rounds. + + + + + +Piper Standards Track [Page 14] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Compression Dictionary Size + RESERVED 0 + + Specifies the log2 maximum size of the dictionary. + + There is no default value for dictionary size. + + Compression Private Algorithm + + Specifies a private vendor compression algorithm. The first + three (3) octets must be an IEEE assigned company_id (OUI). + The next octet may be a vendor specific compression subtype, + followed by zero or more octets of vendor data. + +4.5.1 Required Attribute Support + + To ensure basic interoperability, all implementations MUST be + prepared to negotiate all of the following attributes. + + SA Life Type + SA Duration + Auth Algorithm + +4.5.2 Attribute Parsing Requirement (Lifetime) + + To allow for flexible semantics, the IPSEC DOI requires that a + conforming ISAKMP implementation MUST correctly parse an attribute + list that contains multiple instances of the same attribute class, so + long as the different attribute entries do not conflict with one + another. Currently, the only attributes which requires this + treatment are Life Type and Duration. + + To see why this is important, the following example shows the binary + encoding of a four entry attribute list that specifies an SA Lifetime + of either 100MB or 24 hours. (See Section 3.3 of [ISAKMP] for a + complete description of the attribute encoding format.) + + Attribute #1: + 0x80010001 (AF = 1, type = SA Life Type, value = seconds) + + Attribute #2: + 0x00020004 (AF = 0, type = SA Duration, length = 4 bytes) + 0x00015180 (value = 0x15180 = 86400 seconds = 24 hours) + + Attribute #3: + 0x80010002 (AF = 1, type = SA Life Type, value = KB) + + + + + +Piper Standards Track [Page 15] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Attribute #4: + 0x00020004 (AF = 0, type = SA Duration, length = 4 bytes) + 0x000186A0 (value = 0x186A0 = 100000KB = 100MB) + + If conflicting attributes are detected, an ATTRIBUTES-NOT-SUPPORTED + Notification Payload SHOULD be returned and the security association + setup MUST be aborted. + +4.5.3 Attribute Negotiation + + If an implementation receives a defined IPSEC DOI attribute (or + attribute value) which it does not support, an ATTRIBUTES-NOT-SUPPORT + SHOULD be sent and the security association setup MUST be aborted, + unless the attribute value is in the reserved range. + + If an implementation receives an attribute value in the reserved + range, an implementation MAY chose to continue based on local policy. + +4.5.4 Lifetime Notification + + When an initiator offers an SA lifetime greater than what the + responder desires based on their local policy, the responder has + three choices: 1) fail the negotiation entirely; 2) complete the + negotiation but use a shorter lifetime than what was offered; 3) + complete the negotiation and send an advisory notification to the + initiator indicating the responder's true lifetime. The choice of + what the responder actually does is implementation specific and/or + based on local policy. + + To ensure interoperability in the latter case, the IPSEC DOI requires + the following only when the responder wishes to notify the initiator: + if the initiator offers an SA lifetime longer than the responder is + willing to accept, the responder SHOULD include an ISAKMP + Notification Payload in the exchange that includes the responder's + IPSEC SA payload. Section 4.6.3.1 defines the payload layout for the + RESPONDER-LIFETIME Notification Message type which MUST be used for + this purpose. + +4.6 IPSEC Payload Content + + The following sections describe those ISAKMP payloads whose data + representations are dependent on the applicable DOI. + +4.6.1 Security Association Payload + + The following diagram illustrates the content of the Security + Association Payload for the IPSEC DOI. See Section 4.2 for a + description of the Situation bitmap. + + + +Piper Standards Track [Page 16] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation (IPSEC) | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Situation (bitmap) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Labeled Domain Identifier ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Secrecy Length (in octets) ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Secrecy Level ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Secrecy Cat. Length (in bits) ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Secrecy Category Bitmap ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Integrity Length (in octets) ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Integrity Level ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Integ. Cat. Length (in bits) ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Integrity Category Bitmap ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 1: Security Association Payload Format + + The Security Association Payload is defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of + the next payload in the message. If the current payload is the + last in the message, this field will be zero (0). + + o RESERVED (1 octet) - Unused, must be zero (0). + + o Payload Length (2 octets) - Length, in octets, of the current + payload, including the generic header. + + o Domain of Interpretation (4 octets) - Specifies the IPSEC DOI, + which has been assigned the value one (1). + + o Situation (4 octets) - Bitmask used to interpret the remainder + of the Security Association Payload. See Section 4.2 for a + complete list of values. + + + + + +Piper Standards Track [Page 17] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + o Labeled Domain Identifier (4 octets) - IANA Assigned Number used + to interpret the Secrecy and Integrity information. + + o Secrecy Length (2 octets) - Specifies the length, in octets, of + the secrecy level identifier, excluding pad bits. + + o RESERVED (2 octets) - Unused, must be zero (0). + + o Secrecy Level (variable length) - Specifies the mandatory + secrecy level required. The secrecy level MUST be padded with + zero (0) to align on the next 32-bit boundary. + + o Secrecy Category Length (2 octets) - Specifies the length, in + bits, of the secrecy category (compartment) bitmap, excluding + pad bits. + + o RESERVED (2 octets) - Unused, must be zero (0). + + o Secrecy Category Bitmap (variable length) - A bitmap used to + designate secrecy categories (compartments) that are required. + The bitmap MUST be padded with zero (0) to align on the next + 32-bit boundary. + + o Integrity Length (2 octets) - Specifies the length, in octets, + of the integrity level identifier, excluding pad bits. + + o RESERVED (2 octets) - Unused, must be zero (0). + + o Integrity Level (variable length) - Specifies the mandatory + integrity level required. The integrity level MUST be padded + with zero (0) to align on the next 32-bit boundary. + + o Integrity Category Length (2 octets) - Specifies the length, in + bits, of the integrity category (compartment) bitmap, excluding + pad bits. + + o RESERVED (2 octets) - Unused, must be zero (0). + + o Integrity Category Bitmap (variable length) - A bitmap used to + designate integrity categories (compartments) that are required. + The bitmap MUST be padded with zero (0) to align on the next + 32-bit boundary. + +4.6.1.1 IPSEC Labeled Domain Identifiers + + The following table lists the assigned values for the Labeled Domain + Identifier field contained in the Situation field of the Security + Association Payload. + + + +Piper Standards Track [Page 18] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Domain Value + ------- ----- + RESERVED 0 + +4.6.2 Identification Payload Content + + The Identification Payload is used to identify the initiator of the + Security Association. The identity of the initiator SHOULD be used + by the responder to determine the correct host system security policy + requirement for the association. For example, a host might choose to + require authentication and integrity without confidentiality (AH) + from a certain set of IP addresses and full authentication with + confidentiality (ESP) from another range of IP addresses. The + Identification Payload provides information that can be used by the + responder to make this decision. + + During Phase I negotiations, the ID port and protocol fields MUST be + set to zero or to UDP port 500. If an implementation receives any + other values, this MUST be treated as an error and the security + association setup MUST be aborted. This event SHOULD be auditable. + + The following diagram illustrates the content of the Identification + Payload. + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ID Type ! Protocol ID ! Port ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Identification Data ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 2: Identification Payload Format + + The Identification Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of + the next payload in the message. If the current payload is the + last in the message, this field will be zero (0). + + o RESERVED (1 octet) - Unused, must be zero (0). + + o Payload Length (2 octets) - Length, in octets, of the + identification data, including the generic header. + + o Identification Type (1 octet) - Value describing the identity + information found in the Identification Data field. + + + +Piper Standards Track [Page 19] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + o Protocol ID (1 octet) - Value specifying an associated IP + protocol ID (e.g. UDP/TCP). A value of zero means that the + Protocol ID field should be ignored. + + o Port (2 octets) - Value specifying an associated port. A value + of zero means that the Port field should be ignored. + + o Identification Data (variable length) - Value, as indicated by + the Identification Type. + +4.6.2.1 Identification Type Values + + The following table lists the assigned values for the Identification + Type field found in the Identification Payload. + + ID Type Value + ------- ----- + RESERVED 0 + ID_IPV4_ADDR 1 + ID_FQDN 2 + ID_USER_FQDN 3 + ID_IPV4_ADDR_SUBNET 4 + ID_IPV6_ADDR 5 + ID_IPV6_ADDR_SUBNET 6 + ID_IPV4_ADDR_RANGE 7 + ID_IPV6_ADDR_RANGE 8 + ID_DER_ASN1_DN 9 + ID_DER_ASN1_GN 10 + ID_KEY_ID 11 + + For types where the ID entity is variable length, the size of the ID + entity is computed from size in the ID payload header. + + When an IKE exchange is authenticated using certificates (of any + format), any ID's used for input to local policy decisions SHOULD be + contained in the certificate used in the authentication of the + exchange. + +4.6.2.2 ID_IPV4_ADDR + + The ID_IPV4_ADDR type specifies a single four (4) octet IPv4 address. + +4.6.2.3 ID_FQDN + + The ID_FQDN type specifies a fully-qualified domain name string. An + example of a ID_FQDN is, "foo.bar.com". The string should not + contain any terminators. + + + + +Piper Standards Track [Page 20] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.6.2.4 ID_USER_FQDN + + The ID_USER_FQDN type specifies a fully-qualified username string, An + example of a ID_USER_FQDN is, "piper@foo.bar.com". The string should + not contain any terminators. + +4.6.2.5 ID_IPV4_ADDR_SUBNET + + The ID_IPV4_ADDR_SUBNET type specifies a range of IPv4 addresses, + represented by two four (4) octet values. The first value is an IPv4 + address. The second is an IPv4 network mask. Note that ones (1s) in + the network mask indicate that the corresponding bit in the address + is fixed, while zeros (0s) indicate a "wildcard" bit. + +4.6.2.6 ID_IPV6_ADDR + + The ID_IPV6_ADDR type specifies a single sixteen (16) octet IPv6 + address. + +4.6.2.7 ID_IPV6_ADDR_SUBNET + + The ID_IPV6_ADDR_SUBNET type specifies a range of IPv6 addresses, + represented by two sixteen (16) octet values. The first value is an + IPv6 address. The second is an IPv6 network mask. Note that ones + (1s) in the network mask indicate that the corresponding bit in the + address is fixed, while zeros (0s) indicate a "wildcard" bit. + +4.6.2.8 ID_IPV4_ADDR_RANGE + + The ID_IPV4_ADDR_RANGE type specifies a range of IPv4 addresses, + represented by two four (4) octet values. The first value is the + beginning IPv4 address (inclusive) and the second value is the ending + IPv4 address (inclusive). All addresses falling between the two + specified addresses are considered to be within the list. + +4.6.2.9 ID_IPV6_ADDR_RANGE + + The ID_IPV6_ADDR_RANGE type specifies a range of IPv6 addresses, + represented by two sixteen (16) octet values. The first value is the + beginning IPv6 address (inclusive) and the second value is the ending + IPv6 address (inclusive). All addresses falling between the two + specified addresses are considered to be within the list. + +4.6.2.10 ID_DER_ASN1_DN + + The ID_DER_ASN1_DN type specifies the binary DER encoding of an ASN.1 + X.500 Distinguished Name [X.501] of the principal whose certificates + are being exchanged to establish the SA. + + + +Piper Standards Track [Page 21] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +4.6.2.11 ID_DER_ASN1_GN + + The ID_DER_ASN1_GN type specifies the binary DER encoding of an ASN.1 + X.500 GeneralName [X.509] of the principal whose certificates are + being exchanged to establish the SA. + +4.6.2.12 ID_KEY_ID + + The ID_KEY_ID type specifies an opaque byte stream which may be used + to pass vendor-specific information necessary to identify which pre- + shared key should be used to authenticate Aggressive mode + negotiations. + +4.6.3 IPSEC Notify Message Types + + ISAKMP defines two blocks of Notify Message codes, one for errors and + one for status messages. ISAKMP also allocates a portion of each + block for private use within a DOI. The IPSEC DOI defines the + following private message types for its own use. + + Notify Messages - Error Types Value + ----------------------------- ----- + RESERVED 8192 + + Notify Messages - Status Types Value + ------------------------------ ----- + RESPONDER-LIFETIME 24576 + REPLAY-STATUS 24577 + INITIAL-CONTACT 24578 + + Notification Status Messages MUST be sent under the protection of an + ISAKMP SA: either as a payload in the last Main Mode exchange; in a + separate Informational Exchange after Main Mode or Aggressive Mode + processing is complete; or as a payload in any Quick Mode exchange. + These messages MUST NOT be sent in Aggressive Mode exchange, since + Aggressive Mode does not provide the necessary protection to bind the + Notify Status Message to the exchange. + + Nota Bene: a Notify payload is fully protected only in Quick Mode, + where the entire payload is included in the HASH(n) digest. In Main + Mode, while the notify payload is encrypted, it is not currently + included in the HASH(n) digests. As a result, an active substitution + attack on the Main Mode ciphertext could cause the notify status + message type to be corrupted. (This is true, in general, for the + last message of any Main Mode exchange.) While the risk is small, a + corrupt notify message might cause the receiver to abort the entire + negotiation thinking that the sender encountered a fatal error. + + + + +Piper Standards Track [Page 22] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + Implementation Note: the ISAKMP protocol does not guarantee delivery + of Notification Status messages when sent in an ISAKMP Informational + Exchange. To ensure receipt of any particular message, the sender + SHOULD include a Notification Payload in a defined Main Mode or Quick + Mode exchange which is protected by a retransmission timer. + +4.6.3.1 RESPONDER-LIFETIME + + The RESPONDER-LIFETIME status message may be used to communicate the + IPSEC SA lifetime chosen by the responder. + + When present, the Notification Payload MUST have the following + format: + + o Payload Length - set to length of payload + size of data (var) + o DOI - set to IPSEC DOI (1) + o Protocol ID - set to selected Protocol ID from chosen SA + o SPI Size - set to either sixteen (16) (two eight-octet ISAKMP + cookies) or four (4) (one IPSEC SPI) + o Notify Message Type - set to RESPONDER-LIFETIME (Section 4.6.3) + o SPI - set to the two ISAKMP cookies or to the sender's inbound + IPSEC SPI + o Notification Data - contains an ISAKMP attribute list with the + responder's actual SA lifetime(s) + + Implementation Note: saying that the Notification Data field contains + an attribute list is equivalent to saying that the Notification Data + field has zero length and the Notification Payload has an associated + attribute list. + +4.6.3.2 REPLAY-STATUS + + The REPLAY-STATUS status message may be used for positive + confirmation of the responder's election on whether or not he is to + perform anti-replay detection. + + When present, the Notification Payload MUST have the following + format: + + o Payload Length - set to length of payload + size of data (4) + o DOI - set to IPSEC DOI (1) + o Protocol ID - set to selected Protocol ID from chosen SA + o SPI Size - set to either sixteen (16) (two eight-octet ISAKMP + cookies) or four (4) (one IPSEC SPI) + o Notify Message Type - set to REPLAY-STATUS + o SPI - set to the two ISAKMP cookies or to the sender's inbound + IPSEC SPI + o Notification Data - a 4 octet value: + + + +Piper Standards Track [Page 23] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + 0 = replay detection disabled + 1 = replay detection enabled + +4.6.3.3 INITIAL-CONTACT + + The INITIAL-CONTACT status message may be used when one side wishes + to inform the other that this is the first SA being established with + the remote system. The receiver of this Notification Message might + then elect to delete any existing SA's it has for the sending system + under the assumption that the sending system has rebooted and no + longer has access to the original SA's and their associated keying + material. When used, the content of the Notification Data field + SHOULD be null (i.e. the Payload Length should be set to the fixed + length of Notification Payload). + + When present, the Notification Payload MUST have the following + format: + + o Payload Length - set to length of payload + size of data (0) + o DOI - set to IPSEC DOI (1) + o Protocol ID - set to selected Protocol ID from chosen SA + o SPI Size - set to sixteen (16) (two eight-octet ISAKMP cookies) + o Notify Message Type - set to INITIAL-CONTACT + o SPI - set to the two ISAKMP cookies + o Notification Data - + +4.7 IPSEC Key Exchange Requirements + + The IPSEC DOI introduces no additional Key Exchange types. + +5. Security Considerations + + This entire memo pertains to the Internet Key Exchange protocol + ([IKE]), which combines ISAKMP ([ISAKMP]) and Oakley ([OAKLEY]) to + provide for the derivation of cryptographic keying material in a + secure and authenticated manner. Specific discussion of the various + security protocols and transforms identified in this document can be + found in the associated base documents and in the cipher references. + +6. IANA Considerations + + This document contains many "magic" numbers to be maintained by the + IANA. This section explains the criteria to be used by the IANA to + assign additional numbers in each of these lists. All values not + explicitly defined in previous sections are reserved to IANA. + + + + + + +Piper Standards Track [Page 24] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +6.1 IPSEC Situation Definition + + The Situation Definition is a 32-bit bitmask which represents the + environment under which the IPSEC SA proposal and negotiation is + carried out. Requests for assignments of new situations must be + accompanied by an RFC which describes the interpretation for the + associated bit. + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The upper two bits are reserved for private use amongst cooperating + systems. + +6.2 IPSEC Security Protocol Identifiers + + The Security Protocol Identifier is an 8-bit value which identifies a + security protocol suite being negotiated. Requests for assignments + of new security protocol identifiers must be accompanied by an RFC + which describes the requested security protocol. [AH] and [ESP] are + examples of security protocol documents. + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The values 249-255 are reserved for private use amongst cooperating + systems. + +6.3 IPSEC ISAKMP Transform Identifiers + + The IPSEC ISAKMP Transform Identifier is an 8-bit value which + identifies a key exchange protocol to be used for the negotiation. + Requests for assignments of new ISAKMP transform identifiers must be + accompanied by an RFC which describes the requested key exchange + protocol. [IKE] is an example of one such document. + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The values 249-255 are reserved for private use amongst cooperating + systems. + + + + +Piper Standards Track [Page 25] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +6.4 IPSEC AH Transform Identifiers + + The IPSEC AH Transform Identifier is an 8-bit value which identifies + a particular algorithm to be used to provide integrity protection for + AH. Requests for assignments of new AH transform identifiers must be + accompanied by an RFC which describes how to use the algorithm within + the AH framework ([AH]). + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The values 249-255 are reserved for private use amongst cooperating + systems. + +6.5 IPSEC ESP Transform Identifiers + + The IPSEC ESP Transform Identifier is an 8-bit value which identifies + a particular algorithm to be used to provide secrecy protection for + ESP. Requests for assignments of new ESP transform identifiers must + be accompanied by an RFC which describes how to use the algorithm + within the ESP framework ([ESP]). + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The values 249-255 are reserved for private use amongst cooperating + systems. + +6.6 IPSEC IPCOMP Transform Identifiers + + The IPSEC IPCOMP Transform Identifier is an 8-bit value which + identifier a particular algorithm to be used to provide IP-level + compression before ESP. Requests for assignments of new IPCOMP + transform identifiers must be accompanied by an RFC which describes + how to use the algorithm within the IPCOMP framework ([IPCOMP]). In + addition, the requested algorithm must be published and in the public + domain. + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + + + + +Piper Standards Track [Page 26] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + The values 1-47 are reserved for algorithms for which an RFC has been + approved for publication. The values 48-63 are reserved for private + use amongst cooperating systems. The values 64-255 are reserved for + future expansion. + +6.7 IPSEC Security Association Attributes + + The IPSEC Security Association Attribute consists of a 16-bit type + and its associated value. IPSEC SA attributes are used to pass + miscellaneous values between ISAKMP peers. Requests for assignments + of new IPSEC SA attributes must be accompanied by an Internet Draft + which describes the attribute encoding (Basic/Variable-Length) and + its legal values. Section 4.5 of this document provides an example + of such a description. + + The values 32001-32767 are reserved for private use amongst + cooperating systems. + +6.8 IPSEC Labeled Domain Identifiers + + The IPSEC Labeled Domain Identifier is a 32-bit value which + identifies a namespace in which the Secrecy and Integrity levels and + categories values are said to exist. Requests for assignments of new + IPSEC Labeled Domain Identifiers should be granted on demand. No + accompanying documentation is required, though Internet Drafts are + encouraged when appropriate. + + The values 0x80000000-0xffffffff are reserved for private use amongst + cooperating systems. + +6.9 IPSEC Identification Type + + The IPSEC Identification Type is an 8-bit value which is used as a + discriminant for interpretation of the variable-length Identification + Payload. Requests for assignments of new IPSEC Identification Types + must be accompanied by an RFC which describes how to use the + identification type within IPSEC. + + If the RFC is not on the standards-track (i.e., it is an + informational or experimental RFC), it must be explicitly reviewed + and approved by the IESG before the RFC is published and the + transform identifier is assigned. + + The values 249-255 are reserved for private use amongst cooperating + systems. + + + + + + +Piper Standards Track [Page 27] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +6.10 IPSEC Notify Message Types + + The IPSEC Notify Message Type is a 16-bit value taken from the range + of values reserved by ISAKMP for each DOI. There is one range for + error messages (8192-16383) and a different range for status messages + (24576-32767). Requests for assignments of new Notify Message Types + must be accompanied by an Internet Draft which describes how to use + the identification type within IPSEC. + + The values 16001-16383 and the values 32001-32767 are reserved for + private use amongst cooperating systems. + +7. Change Log + +7.1 Changes from V9 + + o add explicit reference to [IPCOMP], [DEFLATE], and [LZS] + o allow RESPONDER-LIFETIME and REPLAY-STATUS to be directed + at an IPSEC SPI in addition to the ISAKMP "SPI" + o added padding exclusion to Secrecy and Integrity Length text + o added forward reference to Section 4.5 in Section 4.4.4 + o update document references + +7.2 Changes from V8 + + o update IPCOMP identifier range to better reflect IPCOMP draft + o update IANA considerations per Jeff/Ted's suggested text + o eliminate references to DES-MAC ID ([DESMAC]) + o correct bug in Notify section; ISAKMP Notify values are 16-bits + +7.3 Changes from V7 + + o corrected name of IPCOMP (IP Payload Compression) + o corrected references to [ESPCBC] + o added missing Secrecy Level and Integrity Level to Figure 1 + o removed ID references to PF_KEY and ARCFOUR + o updated Basic/Variable text to align with [IKE] + o updated document references and add intro pointer to [ARCH] + o updated Notification requirements; remove aggressive reference + o added clarification about protection for Notify payloads + o restored RESERVED to ESP transform ID namespace; moved ESP_NULL + o added requirement for ESP_NULL support and [ESPNULL] reference + o added clarification on Auth Alg use with AH/ESP + o added restriction against using conflicting AH/Auth combinations + +7.4 Changes from V6 + + The following changes were made relative to the IPSEC DOI V6: + + + +Piper Standards Track [Page 28] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + o added IANA Considerations section + o moved most IANA numbers to IANA Considerations section + o added prohibition on sending (V) encoding for (B) attributes + o added prohibition on sending Key Length attribute for fixed + length ciphers (e.g. DES) + o replaced references to ISAKMP/Oakley with IKE + o renamed ESP_ARCFOUR to ESP_RC4 + o updated Security Considerations section + o updated document references + +7.5 Changes from V5 + + The following changes were made relative to the IPSEC DOI V5: + + o changed SPI size in Lifetime Notification text + o changed REPLAY-ENABLED to REPLAY-STATUS + o moved RESPONDER-LIFETIME payload definition from Section 4.5.4 + to Section 4.6.3.1 + o added explicit payload layout for 4.6.3.3 + o added Implementation Note to Section 4.6.3 introduction + o changed AH_SHA text to require SHA-1 in addition to MD5 + o updated document references + +7.6 Changes from V4 + + The following changes were made relative to the IPSEC DOI V4: + + o moved compatibility AH KPDK authentication method from AH + transform ID to Authentication Algorithm identifier + o added REPLAY-ENABLED notification message type per Architecture + o added INITIAL-CONTACT notification message type per list + o added text to ensure protection for Notify Status messages + o added Lifetime qualification to attribute parsing section + o added clarification that Lifetime notification is optional + o removed private Group Description list (now points at [IKE]) + o replaced Terminology with pointer to RFC-2119 + o updated HMAC MD5 and SHA-1 ID references + o updated Section 1 (Abstract) + o updated Section 4.4 (IPSEC Assigned Numbers) + o added restriction for ID port/protocol values for Phase I + +7.7 Changes from V3 to V4 + + The following changes were made relative to the IPSEC DOI V3, that + was posted to the IPSEC mailing list prior to the Munich IETF: + + o added ESP transform identifiers for NULL and ARCFOUR + + + + +Piper Standards Track [Page 29] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + o renamed HMAC Algorithm to Auth Algorithm to accommodate + DES-MAC and optional authentication/integrity for ESP + o added AH and ESP DES-MAC algorithm identifiers + o removed KEY_MANUAL and KEY_KDC identifier definitions + o added lifetime duration MUST follow lifetype attribute to + SA Life Type and SA Life Duration attribute definition + o added lifetime notification and IPSEC DOI message type table + o added optional authentication and confidentiality + restrictions to MAC Algorithm attribute definition + o corrected attribute parsing example (used obsolete attribute) + o corrected several Internet Draft document references + o added ID_KEY_ID per ipsec list discussion (18-Mar-97) + o removed Group Description default for PFS QM ([IKE] MUST) + +Acknowledgments + + This document is derived, in part, from previous works by Douglas + Maughan, Mark Schertler, Mark Schneider, Jeff Turner, Dan Harkins, + and Dave Carrel. Matt Thomas, Roy Pereira, Greg Carter, and Ran + Atkinson also contributed suggestions and, in many cases, text. + +References + + [AH] Kent, S., and R. Atkinson, "IP Authentication Header", RFC + 2402, November 1998. + + [ARCH] Kent, S., and R. Atkinson, "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + [DEFLATE] Pereira, R., "IP Payload Compression Using DEFLATE", RFC + 2394, August 1998. + + [ESP] Kent, S., and R. Atkinson, "IP Encapsulating Security + Payload (ESP)", RFC 2406, November 1998. + + [ESPCBC] Pereira, R., and R. Adams, "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + [ESPNULL] Glenn, R., and S. Kent, "The NULL Encryption Algorithm and + Its Use With IPsec", RFC 2410, November 1998. + + [DES] Madson, C., and N. Doraswamy, "The ESP DES-CBC Cipher + Algorithm With Explicit IV", RFC 2405, November 1998. + + [HMACMD5] Madson, C., and R. Glenn, "The Use of HMAC-MD5 within ESP + and AH", RFC 2403, November 1998. + + + + + +Piper Standards Track [Page 30] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + + [HMACSHA] Madson, C., and R. Glenn, "The Use of HMAC-SHA-1-96 within + ESP and AH", RFC 2404, November 1998. + + [IKE] Harkins, D., and D. Carrel, D., "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IPCOMP] Shacham, A., Monsour, R., Pereira, R., and M. Thomas, "IP + Payload Compression Protocol (IPComp)", RFC 2393, August + 1998. + + [ISAKMP] Maughan, D., Schertler, M., Schneider, M., and J. Turner, + "Internet Security Association and Key Management Protocol + (ISAKMP)", RFC 2408, November 1998. + + [LZS] Friend, R., and R. Monsour, "IP Payload Compression Using + LZS", RFC 2395, August 1998. + + [OAKLEY] Orman, H., "The OAKLEY Key Determination Protocol", RFC + 2412, November 1998. + + [X.501] ISO/IEC 9594-2, "Information Technology - Open Systems + Interconnection - The Directory: Models", CCITT/ITU + Recommendation X.501, 1993. + + [X.509] ISO/IEC 9594-8, "Information Technology - Open Systems + Interconnection - The Directory: Authentication + Framework", CCITT/ITU Recommendation X.509, 1993. + +Author's Address + + Derrell Piper + Network Alchemy + 1521.5 Pacific Ave + Santa Cruz, California, 95060 + United States of America + + Phone: +1 408 460-3822 + EMail: ddp@network-alchemy.com + + + + + + + + + + + + + +Piper Standards Track [Page 31] + +RFC 2407 IP Security Domain of Interpretation November 1998 + + +Full Copyright Statement + + Copyright (C) The Internet Society (1998). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + + + + + + + + + + + + + + + + + + + + + +Piper Standards Track [Page 32] + diff --git a/doc/ikev2/[RFC2408] - Internet Security Association and Key Management Protocol (ISAKMP).txt b/doc/ikev2/[RFC2408] - Internet Security Association and Key Management Protocol (ISAKMP).txt new file mode 100644 index 000000000..c3af56268 --- /dev/null +++ b/doc/ikev2/[RFC2408] - Internet Security Association and Key Management Protocol (ISAKMP).txt @@ -0,0 +1,4819 @@ + + + + + + +Network Working Group D. Maughan +Request for Comments: 2408 National Security Agency +Category: Standards Track M. Schertler + Securify, Inc. + M. Schneider + National Security Agency + J. Turner + RABA Technologies, Inc. + November 1998 + + + Internet Security Association and Key Management Protocol (ISAKMP) + +Status of this Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (1998). All Rights Reserved. + +Abstract + + This memo describes a protocol utilizing security concepts necessary + for establishing Security Associations (SA) and cryptographic keys in + an Internet environment. A Security Association protocol that + negotiates, establishes, modifies and deletes Security Associations + and their attributes is required for an evolving Internet, where + there will be numerous security mechanisms and several options for + each security mechanism. The key management protocol must be robust + in order to handle public key generation for the Internet community + at large and private key requirements for those private networks with + that requirement. The Internet Security Association and Key + Management Protocol (ISAKMP) defines the procedures for + authenticating a communicating peer, creation and management of + Security Associations, key generation techniques, and threat + mitigation (e.g. denial of service and replay attacks). All of + these are necessary to establish and maintain secure communications + (via IP Security Service or any other security protocol) in an + Internet environment. + + + + + + + +Maughan, et. al. Standards Track [Page 1] + +RFC 2408 ISAKMP November 1998 + + +Table of Contents + + 1 Introduction 4 + 1.1 Requirements Terminology . . . . . . . . . . . . . . . . . 5 + 1.2 The Need for Negotiation . . . . . . . . . . . . . . . . . 5 + 1.3 What can be Negotiated? . . . . . . . . . . . . . . . . . 6 + 1.4 Security Associations and Management . . . . . . . . . . . 7 + 1.4.1 Security Associations and Registration . . . . . . . . 7 + 1.4.2 ISAKMP Requirements . . . . . . . . . . . . . . . . . 8 + 1.5 Authentication . . . . . . . . . . . . . . . . . . . . . . 8 + 1.5.1 Certificate Authorities . . . . . . . . . . . . . . . 9 + 1.5.2 Entity Naming . . . . . . . . . . . . . . . . . . . . 9 + 1.5.3 ISAKMP Requirements . . . . . . . . . . . . . . . . . 10 + 1.6 Public Key Cryptography . . . . . . . . . . . . . . . . . . 10 + 1.6.1 Key Exchange Properties . . . . . . . . . . . . . . . 11 + 1.6.2 ISAKMP Requirements . . . . . . . . . . . . . . . . . 12 + 1.7 ISAKMP Protection . . . . . . . . . . . . . . . . . . . . . 12 + 1.7.1 Anti-Clogging (Denial of Service) . . . . . . . . . . 12 + 1.7.2 Connection Hijacking . . . . . . . . . . . . . . . . . 13 + 1.7.3 Man-in-the-Middle Attacks . . . . . . . . . . . . . . 13 + 1.8 Multicast Communications . . . . . . . . . . . . . . . . . 13 + 2 Terminology and Concepts 14 + 2.1 ISAKMP Terminology . . . . . . . . . . . . . . . . . . . . 14 + 2.2 ISAKMP Placement . . . . . . . . . . . . . . . . . . . . . 16 + 2.3 Negotiation Phases . . . . . . . . . . . . . . . . . . . . 16 + 2.4 Identifying Security Associations . . . . . . . . . . . . . 17 + 2.5 Miscellaneous . . . . . . . . . . . . . . . . . . . . . . . 20 + 2.5.1 Transport Protocol . . . . . . . . . . . . . . . . . . 20 + 2.5.2 RESERVED Fields . . . . . . . . . . . . . . . . . . . 20 + 2.5.3 Anti-Clogging Token ("Cookie") Creation . . . . . . . 20 + 3 ISAKMP Payloads 21 + 3.1 ISAKMP Header Format . . . . . . . . . . . . . . . . . . . 21 + 3.2 Generic Payload Header . . . . . . . . . . . . . . . . . . 25 + 3.3 Data Attributes . . . . . . . . . . . . . . . . . . . . . . 25 + 3.4 Security Association Payload . . . . . . . . . . . . . . . 27 + 3.5 Proposal Payload . . . . . . . . . . . . . . . . . . . . . 28 + 3.6 Transform Payload . . . . . . . . . . . . . . . . . . . . . 29 + 3.7 Key Exchange Payload . . . . . . . . . . . . . . . . . . . 31 + 3.8 Identification Payload . . . . . . . . . . . . . . . . . . 32 + 3.9 Certificate Payload . . . . . . . . . . . . . . . . . . . . 33 + 3.10 Certificate Request Payload . . . . . . . . . . . . . . . 34 + 3.11 Hash Payload . . . . . . . . . . . . . . . . . . . . . . 36 + 3.12 Signature Payload . . . . . . . . . . . . . . . . . . . . 37 + 3.13 Nonce Payload . . . . . . . . . . . . . . . . . . . . . . 37 + 3.14 Notification Payload . . . . . . . . . . . . . . . . . . 38 + 3.14.1 Notify Message Types . . . . . . . . . . . . . . . . 40 + 3.15 Delete Payload . . . . . . . . . . . . . . . . . . . . . 41 + 3.16 Vendor ID Payload . . . . . . . . . . . . . . . . . . . . 43 + + + +Maughan, et. al. Standards Track [Page 2] + +RFC 2408 ISAKMP November 1998 + + + 4 ISAKMP Exchanges 44 + 4.1 ISAKMP Exchange Types . . . . . . . . . . . . . . . . . . . 45 + 4.1.1 Notation . . . . . . . . . . . . . . . . . . . . . . . 46 + 4.2 Security Association Establishment . . . . . . . . . . . . 46 + 4.2.1 Security Association Establishment Examples . . . . . 48 + 4.3 Security Association Modification . . . . . . . . . . . . . 50 + 4.4 Base Exchange . . . . . . . . . . . . . . . . . . . . . . . 51 + 4.5 Identity Protection Exchange . . . . . . . . . . . . . . . 52 + 4.6 Authentication Only Exchange . . . . . . . . . . . . . . . 54 + 4.7 Aggressive Exchange . . . . . . . . . . . . . . . . . . . . 55 + 4.8 Informational Exchange . . . . . . . . . . . . . . . . . . 57 + 5 ISAKMP Payload Processing 58 + 5.1 General Message Processing . . . . . . . . . . . . . . . . 58 + 5.2 ISAKMP Header Processing . . . . . . . . . . . . . . . . . 59 + 5.3 Generic Payload Header Processing . . . . . . . . . . . . . 61 + 5.4 Security Association Payload Processing . . . . . . . . . . 62 + 5.5 Proposal Payload Processing . . . . . . . . . . . . . . . . 63 + 5.6 Transform Payload Processing . . . . . . . . . . . . . . . 64 + 5.7 Key Exchange Payload Processing . . . . . . . . . . . . . . 65 + 5.8 Identification Payload Processing . . . . . . . . . . . . . 66 + 5.9 Certificate Payload Processing . . . . . . . . . . . . . . 66 + 5.10 Certificate Request Payload Processing . . . . . . . . . 67 + 5.11 Hash Payload Processing . . . . . . . . . . . . . . . . . 69 + 5.12 Signature Payload Processing . . . . . . . . . . . . . . 69 + 5.13 Nonce Payload Processing . . . . . . . . . . . . . . . . 70 + 5.14 Notification Payload Processing . . . . . . . . . . . . . 71 + 5.15 Delete Payload Processing . . . . . . . . . . . . . . . . 73 + 6 Conclusions 75 + A ISAKMP Security Association Attributes 77 + A.1 Background/Rationale . . . . . . . . . . . . . . . . . . . 77 + A.2 Internet IP Security DOI Assigned Value . . . . . . . . . . 77 + A.3 Supported Security Protocols . . . . . . . . . . . . . . . 77 + A.4 ISAKMP Identification Type Values . . . . . . . . . . . . . 78 + A.4.1 ID_IPV4_ADDR . . . . . . . . . . . . . . . . . . . . . 78 + A.4.2 ID_IPV4_ADDR_SUBNET . . . . . . . . . . . . . . . . . . 78 + A.4.3 ID_IPV6_ADDR . . . . . . . . . . . . . . . . . . . . . 78 + A.4.4 ID_IPV6_ADDR_SUBNET . . . . . . . . . . . . . . . . . 78 + B Defining a new Domain of Interpretation 79 + B.1 Situation . . . . . . . . . . . . . . . . . . . . . . . . . 79 + B.2 Security Policies . . . . . . . . . . . . . . . . . . . . . 80 + B.3 Naming Schemes . . . . . . . . . . . . . . . . . . . . . . 80 + B.4 Syntax for Specifying Security Services . . . . . . . . . . 80 + B.5 Payload Specification . . . . . . . . . . . . . . . . . . . 80 + B.6 Defining new Exchange Types . . . . . . . . . . . . . . . . 80 + Security Considerations 81 + IANA Considerations 81 + Domain of Interpretation 81 + Supported Security Protocols 82 + + + +Maughan, et. al. Standards Track [Page 3] + +RFC 2408 ISAKMP November 1998 + + + Acknowledgements 82 + References 82 + Authors' Addresses 85 + Full Copyright Statement 86 + +List of Figures + + 1 ISAKMP Relationships . . . . . . . . . . . . . . . . . . . 16 + 2 ISAKMP Header Format . . . . . . . . . . . . . . . . . . . 22 + 3 Generic Payload Header . . . . . . . . . . . . . . . . . . 25 + 4 Data Attributes . . . . . . . . . . . . . . . . . . . . . . 26 + 5 Security Association Payload . . . . . . . . . . . . . . . 27 + 6 Proposal Payload Format . . . . . . . . . . . . . . . . . . 28 + 7 Transform Payload Format . . . . . . . . . . . . . . . . . 30 + 8 Key Exchange Payload Format . . . . . . . . . . . . . . . . 31 + 9 Identification Payload Format . . . . . . . . . . . . . . . 32 + 10 Certificate Payload Format . . . . . . . . . . . . . . . . 33 + 11 Certificate Request Payload Format . . . . . . . . . . . . 34 + 12 Hash Payload Format . . . . . . . . . . . . . . . . . . . . 36 + 13 Signature Payload Format . . . . . . . . . . . . . . . . . 37 + 14 Nonce Payload Format . . . . . . . . . . . . . . . . . . . 38 + 15 Notification Payload Format . . . . . . . . . . . . . . . . 39 + 16 Delete Payload Format . . . . . . . . . . . . . . . . . . . 42 + 17 Vendor ID Payload Format . . . . . . . . . . . . . . . . . 44 + +1 Introduction + + This document describes an Internet Security Association and Key + Management Protocol (ISAKMP). ISAKMP combines the security concepts + of authentication, key management, and security associations to + establish the required security for government, commercial, and + private communications on the Internet. + + The Internet Security Association and Key Management Protocol + (ISAKMP) defines procedures and packet formats to establish, + negotiate, modify and delete Security Associations (SA). SAs contain + all the information required for execution of various network + security services, such as the IP layer services (such as header + authentication and payload encapsulation), transport or application + layer services, or self-protection of negotiation traffic. ISAKMP + defines payloads for exchanging key generation and authentication + data. These formats provide a consistent framework for transferring + key and authentication data which is independent of the key + generation technique, encryption algorithm and authentication + mechanism. + + + + + + +Maughan, et. al. Standards Track [Page 4] + +RFC 2408 ISAKMP November 1998 + + + ISAKMP is distinct from key exchange protocols in order to cleanly + separate the details of security association management (and key + management) from the details of key exchange. There may be many + different key exchange protocols, each with different security + properties. However, a common framework is required for agreeing to + the format of SA attributes, and for negotiating, modifying, and + deleting SAs. ISAKMP serves as this common framework. + + Separating the functionality into three parts adds complexity to the + security analysis of a complete ISAKMP implementation. However, the + separation is critical for interoperability between systems with + differing security requirements, and should also simplify the + analysis of further evolution of a ISAKMP server. + + ISAKMP is intended to support the negotiation of SAs for security + protocols at all layers of the network stack (e.g., IPSEC, TLS, TLSP, + OSPF, etc.). By centralizing the management of the security + associations, ISAKMP reduces the amount of duplicated functionality + within each security protocol. ISAKMP can also reduce connection + setup time, by negotiating a whole stack of services at once. + + The remainder of section 1 establishes the motivation for security + negotiation and outlines the major components of ISAKMP, i.e. + Security Associations and Management, Authentication, Public Key + Cryptography, and Miscellaneous items. Section 2 presents the + terminology and concepts associated with ISAKMP. Section 3 describes + the different ISAKMP payload formats. Section 4 describes how the + payloads of ISAKMP are composed together as exchange types to + establish security associations and perform key exchanges in an + authenticated manner. Additionally, security association + modification, deletion, and error notification are discussed. + Section 5 describes the processing of each payload within the context + of ISAKMP exchanges, including error handling and associated actions. + The appendices provide the attribute values necessary for ISAKMP and + requirement for defining a new Domain of Interpretation (DOI) within + ISAKMP. + +1.1 Requirements Terminology + + The keywords MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, + SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL, when they appear in this + document, are to be interpreted as described in [RFC-2119]. + +1.2 The Need for Negotiation + + ISAKMP extends the assertion in [DOW92] that authentication and key + exchanges must be combined for better security to include security + association exchanges. The security services required for + + + +Maughan, et. al. Standards Track [Page 5] + +RFC 2408 ISAKMP November 1998 + + + communications depends on the individual network configurations and + environments. Organizations are setting up Virtual Private Networks + (VPN), also known as Intranets, that will require one set of security + functions for communications within the VPN and possibly many + different security functions for communications outside the VPN to + support geographically separate organizational components, customers, + suppliers, sub-contractors (with their own VPNs), government, and + others. Departments within large organizations may require a number + of security associations to separate and protect data (e.g. + personnel data, company proprietary data, medical) on internal + networks and other security associations to communicate within the + same department. Nomadic users wanting to "phone home" represent + another set of security requirements. These requirements must be + tempered with bandwidth challenges. Smaller groups of people may + meet their security requirements by setting up "Webs of Trust". + ISAKMP exchanges provide these assorted networking communities the + ability to present peers with the security functionality that the + user supports in an authenticated and protected manner for agreement + upon a common set of security attributes, i.e. an interoperable + security association. + +1.3 What can be Negotiated? + + Security associations must support different encryption algorithms, + authentication mechanisms, and key establishment algorithms for other + security protocols, as well as IP Security. Security associations + must also support host-oriented certificates for lower layer + protocols and user- oriented certificates for higher level protocols. + Algorithm and mechanism independence is required in applications such + as e-mail, remote login, and file transfer, as well as in session + oriented protocols, routing protocols, and link layer protocols. + ISAKMP provides a common security association and key establishment + protocol for this wide range of security protocols, applications, + security requirements, and network environments. + + ISAKMP is not bound to any specific cryptographic algorithm, key + generation technique, or security mechanism. This flexibility is + beneficial for a number of reasons. First, it supports the dynamic + communications environment described above. Second, the independence + from specific security mechanisms and algorithms provides a forward + migration path to better mechanisms and algorithms. When improved + security mechanisms are developed or new attacks against current + encryption algorithms, authentication mechanisms and key exchanges + are discovered, ISAKMP will allow the updating of the algorithms and + mechanisms without having to develop a completely new KMP or patch + the current one. + + + + + +Maughan, et. al. Standards Track [Page 6] + +RFC 2408 ISAKMP November 1998 + + + ISAKMP has basic requirements for its authentication and key exchange + components. These requirements guard against denial of service, + replay / reflection, man-in-the-middle, and connection hijacking + attacks. This is important because these are the types of attacks + that are targeted against protocols. Complete Security Association + (SA) support, which provides mechanism and algorithm independence, + and protection from protocol threats are the strengths of ISAKMP. + +1.4 Security Associations and Management + + A Security Association (SA) is a relationship between two or more + entities that describes how the entities will utilize security + services to communicate securely. This relationship is represented + by a set of information that can be considered a contract between the + entities. The information must be agreed upon and shared between all + the entities. Sometimes the information alone is referred to as an + SA, but this is just a physical instantiation of the existing + relationship. The existence of this relationship, represented by the + information, is what provides the agreed upon security information + needed by entities to securely interoperate. All entities must + adhere to the SA for secure communications to be possible. When + accessing SA attributes, entities use a pointer or identifier refered + to as the Security Parameter Index (SPI). [SEC-ARCH] provides details + on IP Security Associations (SA) and Security Parameter Index (SPI) + definitions. + +1.4.1 Security Associations and Registration + + The SA attributes required and recommended for the IP Security (AH, + ESP) are defined in [SEC-ARCH]. The attributes specified for an IP + Security SA include, but are not limited to, authentication + mechanism, cryptographic algorithm, algorithm mode, key length, and + Initialization Vector (IV). Other protocols that provide algorithm + and mechanism independent security MUST define their requirements for + SA attributes. The separation of ISAKMP from a specific SA + definition is important to ensure ISAKMP can es tablish SAs for all + possible security protocols and applications. + + NOTE: See [IPDOI] for a discussion of SA attributes that should be + considered when defining a security protocol or application. + + In order to facilitate easy identification of specific attributes + (e.g. a specific encryption algorithm) among different network + entites the attributes must be assigned identifiers and these + identifiers must be registered by a central authority. The Internet + Assigned Numbers Authority (IANA) provides this function for the + Internet. + + + + +Maughan, et. al. Standards Track [Page 7] + +RFC 2408 ISAKMP November 1998 + + +1.4.2 ISAKMP Requirements + + Security Association (SA) establishment MUST be part of the key + management protocol defined for IP based networks. The SA concept is + required to support security protocols in a diverse and dynamic + networking environment. Just as authentication and key exchange must + be linked to provide assurance that the key is established with the + authenticated party [DOW92], SA establishment must be linked with the + authentication and the key exchange protocol. + + ISAKMP provides the protocol exchanges to establish a security + association between negotiating entities followed by the + establishment of a security association by these negotiating entities + in behalf of some protocol (e.g. ESP/AH). First, an initial protocol + exchange allows a basic set of security attributes to be agreed upon. + This basic set provides protection for subsequent ISAKMP exchanges. + It also indicates the authentication method and key exchange that + will be performed as part of the ISAKMP protocol. If a basic set of + security attributes is already in place between the negotiating + server entities, the initial ISAKMP exchange may be skipped and the + establishment of a security association can be done directly. After + the basic set of security attributes has been agreed upon, initial + identity authenticated, and required keys generated, the established + SA can be used for subsequent communications by the entity that + invoked ISAKMP. The basic set of SA attributes that MUST be + implemented to provide ISAKMP interoperability are defined in + Appendix A. + +1.5 Authentication + + A very important step in establishing secure network communications + is authentication of the entity at the other end of the + communication. Many authentication mechanisms are available. + Authentication mechanisms fall into two catagories of strength - weak + and strong. Sending cleartext keys or other unprotected + authenticating information over a network is weak, due to the threat + of reading them with a network sniffer. Additionally, sending one- + way hashed poorly-chosen keys with low entropy is also weak, due to + the threat of brute-force guessing attacks on the sniffed messages. + While passwords can be used for establishing identity, they are not + considered in this context because of recent statements from the + Internet Architecture Board [IAB]. Digital signatures, such as the + Digital Signature Standard (DSS) and the Rivest-Shamir-Adleman (RSA) + signature, are public key based strong authentication mechanisms. + When using public key digital signatures each entity requires a + public key and a private key. Certificates are an essential part of + a digital signature authentication mechanism. Certificates bind a + specific entity's identity (be it host, network, user, or + + + +Maughan, et. al. Standards Track [Page 8] + +RFC 2408 ISAKMP November 1998 + + + application) to its public keys and possibly other security-related + information such as privileges, clearances, and compartments. + Authentication based on digital signatures requires a trusted third + party or certificate authority to create, sign and properly + distribute certificates. For more detailed information on digital + signatures, such as DSS and RSA, and certificates see [Schneier]. + +1.5.1 Certificate Authorities + + Certificates require an infrastructure for generation, verification, + revocation, management and distribution. The Internet Policy + Registration Authority (IPRA) [RFC-1422] has been established to + direct this infrastructure for the IETF. The IPRA certifies Policy + Certification Authorities (PCA). PCAs control Certificate Authorities + (CA) which certify users and subordinate entities. Current + certificate related work includes the Domain Name System (DNS) + Security Extensions [DNSSEC] which will provide signed entity keys in + the DNS. The Public Key Infrastucture (PKIX) working group is + specifying an Internet profile for X.509 certificates. There is also + work going on in industry to develop X.500 Directory Services which + would provide X.509 certificates to users. The U.S. Post Office is + developing a (CA) hierarchy. The NIST Public Key Infrastructure + Working Group has also been doing work in this area. The DOD Multi + Level Information System Security Initiative (MISSI) program has + begun deploying a certificate infrastructure for the U.S. Government. + Alternatively, if no infrastructure exists, the PGP Web of Trust + certificates can be used to provide user authentication and privacy + in a community of users who know and trust each other. + +1.5.2 Entity Naming + + An entity's name is its identity and is bound to its public keys in + certificates. The CA MUST define the naming semantics for the + certificates it issues. See the UNINETT PCA Policy Statements + [Berge] for an example of how a CA defines its naming policy. When + the certificate is verified, the name is verified and that name will + have meaning within the realm of that CA. An example is the DNS + security extensions which make DNS servers CAs for the zones and + nodes they serve. Resource records are provided for public keys and + signatures on those keys. The names associated with the keys are IP + addresses and domain names which have meaning to entities accessing + the DNS for this information. A Web of Trust is another example. + When webs of trust are set up, names are bound with the public keys. + In PGP the name is usually the entity's e-mail address which has + meaning to those, and only those, who understand e-mail. Another web + of trust could use an entirely different naming scheme. + + + + + +Maughan, et. al. Standards Track [Page 9] + +RFC 2408 ISAKMP November 1998 + + +1.5.3 ISAKMP Requirements + + Strong authentication MUST be provided on ISAKMP exchanges. Without + being able to authenticate the entity at the other end, the Security + Association (SA) and session key established are suspect. Without + authentication you are unable to trust an entity's identification, + which makes access control questionable. While encryption (e.g. + ESP) and integrity (e.g. AH) will protect subsequent communications + from passive eavesdroppers, without authentication it is possible + that the SA and key may have been established with an adversary who + performed an active man-in-the-middle attack and is now stealing all + your personal data. + + A digital signature algorithm MUST be used within ISAKMP's + authentication component. However, ISAKMP does not mandate a + specific signature algorithm or certificate authority (CA). ISAKMP + allows an entity initiating communications to indicate which CAs it + supports. After selection of a CA, the protocol provides the + messages required to support the actual authentication exchange. The + protocol provides a facility for identification of different + certificate authorities, certificate types (e.g. X.509, PKCS #7, + PGP, DNS SIG and KEY records), and the exchange of the certificates + identified. + + ISAKMP utilizes digital signatures, based on public key cryptography, + for authentication. There are other strong authentication systems + available, which could be specified as additional optional + authentication mechanisms for ISAKMP. Some of these authentication + systems rely on a trusted third party called a key distribution + center (KDC) to distribute secret session keys. An example is + Kerberos, where the trusted third party is the Kerberos server, which + holds secret keys for all clients and servers within its network + domain. A client's proof that it holds its secret key provides + authenticaton to a server. + + The ISAKMP specification does not specify the protocol for + communicating with the trusted third parties (TTP) or certificate + directory services. These protocols are defined by the TTP and + directory service themselves and are outside the scope of this + specification. The use of these additional services and protocols + will be described in a Key Exchange specific document. + +1.6 Public Key Cryptography + + Public key cryptography is the most flexible, scalable, and efficient + way for users to obtain the shared secrets and session keys needed to + support the large number of ways Internet users will interoperate. + Many key generation algorithms, that have different properties, are + + + +Maughan, et. al. Standards Track [Page 10] + +RFC 2408 ISAKMP November 1998 + + + available to users (see [DOW92], [ANSI], and [Oakley]). Properties + of key exchange protocols include the key establishment method, + authentication, symmetry, perfect forward secrecy, and back traffic + protection. + + NOTE: Cryptographic keys can protect information for a considerable + length of time. However, this is based on the assumption that keys + used for protection of communications are destroyed after use and not + kept for any reason. + +1.6.1 Key Exchange Properties + + Key Establishment (Key Generation / Key Transport): The two common + methods of using public key cryptography for key establishment are + key transport and key generation. An example of key transport is the + use of the RSA algorithm to encrypt a randomly generated session key + (for encrypting subsequent communications) with the recipient's + public key. The encrypted random key is then sent to the recipient, + who decrypts it using his private key. At this point both sides have + the same session key, however it was created based on input from only + one side of the communications. The benefit of the key transport + method is that it has less computational overhead than the following + method. The Diffie-Hellman (D-H) algorithm illustrates key + generation using public key cryptography. The D-H algorithm is begun + by two users exchanging public information. Each user then + mathematically combines the other's public information along with + their own secret information to compute a shared secret value. This + secret value can be used as a session key or as a key encryption key + for encrypting a randomly generated session key. This method + generates a session key based on public and secret information held + by both users. The benefit of the D-H algorithm is that the key used + for encrypting messages is based on information held by both users + and the independence of keys from one key exchange to another + provides perfect forward secrecy. Detailed descriptions of these + algorithms can be found in [Schneier]. There are a number of + variations on these two key generation schemes and these variations + do not necessarily interoperate. + + Key Exchange Authentication: Key exchanges may be authenticated + during the protocol or after protocol completion. Authentication of + the key exchange during the protocol is provided when each party + provides proof it has the secret session key before the end of the + protocol. Proof can be provided by encrypting known data in the + secret session key during the protocol echange. Authentication after + the protocol must occur in subsequent commu nications. + Authentication during the protocol is preferred so subsequent + communications are not initiated if the secret session key is not + established with the desired party. + + + +Maughan, et. al. Standards Track [Page 11] + +RFC 2408 ISAKMP November 1998 + + + Key Exchange Symmetry: A key exchange provides symmetry if either + party can initiate the exchange and exchanged messages can cross in + transit without affecting the key that is generated. This is + desirable so that computation of the keys does not require either + party to know who initated the exchange. While key exchange symmetry + is desirable, symmetry in the entire key management protocol may + provide a vulnerablity to reflection attacks. + + Perfect Forward Secrecy: As described in [DOW92], an authenticated + key exchange protocol provides perfect forward secrecy if disclosure + of longterm secret keying material does not compromise the secrecy of + the exchanged keys from previous communications. The property of + perfect forward secrecy does not apply to key exchange without + authentication. + +1.6.2 ISAKMP Requirements + + An authenticated key exchange MUST be supported by ISAKMP. Users + SHOULD choose additional key establishment algorithms based on their + requirements. ISAKMP does not specify a specific key exchange. + However, [IKE] describes a proposal for using the Oakley key exchange + [Oakley] in conjunction with ISAKMP. Requirements that should be + evaluated when choosing a key establishment algorithm include + establishment method (generation vs. transport), perfect forward + secrecy, computational overhead, key escrow, and key strength. Based + on user requirements, ISAKMP allows an entity initiating + communications to indicate which key exchanges it supports. After + selection of a key exchange, the protocol provides the messages + required to support the actual key establishment. + +1.7 ISAKMP Protection + +1.7.1 Anti-Clogging (Denial of Service) + + Of the numerous security services available, protection against + denial of service always seems to be one of the most difficult to + address. A "cookie" or anti-clogging token (ACT) is aimed at + protecting the computing resources from attack without spending + excessive CPU resources to determine its authenticity. An exchange + prior to CPU-intensive public key operations can thwart some denial + of service attempts (e.g. simple flooding with bogus IP source + addresses). Absolute protection against denial of service is + impossible, but this anti-clogging token provides a technique for + making it easier to handle. The use of an anti-clogging token was + introduced by Karn and Simpson in [Karn]. + + + + + + +Maughan, et. al. Standards Track [Page 12] + +RFC 2408 ISAKMP November 1998 + + + It should be noted that in the exchanges shown in section 4, the + anticlogging mechanism should be used in conjuction with a garbage- + state collection mechanism; an attacker can still flood a server + using packets with bogus IP addresses and cause state to be created. + Such aggressive memory management techniques SHOULD be employed by + protocols using ISAKMP that do not go through an initial, anti- + clogging only phase, as was done in [Karn]. + +1.7.2 Connection Hijacking + + ISAKMP prevents connection hijacking by linking the authentication, + key exchange and security association exchanges. This linking + prevents an attacker from allowing the authentication to complete and + then jumping in and impersonating one entity to the other during the + key and security association exchanges. + +1.7.3 Man-in-the-Middle Attacks + + Man-in-the-Middle attacks include interception, insertion, deletion, + and modification of messages, reflecting messages back at the sender, + replaying old messages and redirecting messages. ISAKMP features + prevent these types of attacks from being successful. The linking of + the ISAKMP exchanges prevents the insertion of messages in the + protocol exchange. The ISAKMP protocol state machine is defined so + deleted messages will not cause a partial SA to be created, the state + machine will clear all state and return to idle. The state machine + also prevents reflection of a message from causing harm. The + requirement for a new cookie with time variant material for each new + SA establishment prevents attacks that involve replaying old + messages. The ISAKMP strong authentication requirement prevents an + SA from being established with anyone other than the intended party. + Messages may be redirected to a different destination or modified but + this will be detected and an SA will not be established. The ISAKMP + specification defines where abnormal processing has occurred and + recommends notifying the appropriate party of this abnormality. + +1.8 Multicast Communications + + It is expected that multicast communications will require the same + security services as unicast communications and may introduce the + need for additional security services. The issues of distributing + SPIs for multicast traffic are presented in [SEC-ARCH]. Multicast + security issues are also discussed in [RFC-1949] and [BC]. A future + extension to ISAKMP will support multicast key distribution. For an + introduction to the issues related to multicast security, consult the + Internet Drafts, [RFC-2094] and [RFC-2093], describing Sparta's + research in this area. + + + + +Maughan, et. al. Standards Track [Page 13] + +RFC 2408 ISAKMP November 1998 + + +2 Terminology and Concepts + +2.1 ISAKMP Terminology + + Security Protocol: A Security Protocol consists of an entity at a + single point in the network stack, performing a security service for + network communication. For example, IPSEC ESP and IPSEC AH are two + different security protocols. TLS is another example. Security + Protocols may perform more than one service, for example providing + integrity and confidentiality in one module. + + Protection Suite: A protection suite is a list of the security + services that must be applied by various security protocols. For + example, a protection suite may consist of DES encryption in IP ESP, + and keyed MD5 in IP AH. All of the protections in a suite must be + treated as a single unit. This is necessary because security + services in different security protocols can have subtle + interactions, and the effects of a suite must be analyzed and + verified as a whole. + + Security Association (SA): A Security Association is a security- + protocol- specific set of parameters that completely defines the + services and mechanisms necessary to protect traffic at that security + protocol location. These parameters can include algorithm + identifiers, modes, cryptographic keys, etc. The SA is referred to + by its associated security protocol (for example, "ISAKMP SA", "ESP + SA", "TLS SA"). + + ISAKMP SA: An SA used by the ISAKMP servers to protect their own + traffic. Sections 2.3 and 2.4 provide more details about ISAKMP SAs. + + Security Parameter Index (SPI): An identifier for a Security + Assocation, relative to some security protocol. Each security + protocol has its own "SPI-space". A (security protocol, SPI) pair + may uniquely identify an SA. The uniqueness of the SPI is + implementation dependent, but could be based per system, per + protocol, or other options. Depending on the DOI, additional + information (e.g. host address) may be necessary to identify an SA. + The DOI will also determine which SPIs (i.e. initiator's or + responder's) are sent during communication. + + Domain of Interpretation: A Domain of Interpretation (DOI) defines + payload formats, exchange types, and conventions for naming + security-relevant information such as security policies or + cryptographic algorithms and modes. A Domain of Interpretation (DOI) + identifier is used to interpret the payloads of ISAKMP payloads. A + system SHOULD support multiple Domains of Interpretation + simultaneously. The concept of a DOI is based on previous work by + + + +Maughan, et. al. Standards Track [Page 14] + +RFC 2408 ISAKMP November 1998 + + + the TSIG CIPSO Working Group, but extends beyond security label + interpretation to include naming and interpretation of security + services. A DOI defines: + + o A "situation": the set of information that will be used to + determine the required security services. + + o The set of security policies that must, and may, be supported. + + o A syntax for the specification of proposed security services. + + o A scheme for naming security-relevant information, including + encryption algorithms, key exchange algorithms, security policy + attributes, and certificate authorities. + + o The specific formats of the various payload contents. + + o Additional exchange types, if required. + + The rules for the IETF IP Security DOI are presented in [IPDOI]. + Specifications of the rules for customized DOIs will be presented in + separate documents. + + Situation: A situation contains all of the security-relevant + information that a system considers necessary to decide the security + services required to protect the session being negotiated. The + situation may include addresses, security classifications, modes of + operation (normal vs. emergency), etc. + + Proposal: A proposal is a list, in decreasing order of preference, of + the protection suites that a system considers acceptable to protect + traffic under a given situation. + + Payload: ISAKMP defines several types of payloads, which are used to + transfer information such as security association data, or key + exchange data, in DOI-defined formats. A payload consists of a + generic payload header and a string of octects that is opaque to + ISAKMP. ISAKMP uses DOI- specific functionality to synthesize and + interpret these payloads. Multiple payloads can be sent in a single + ISAKMP message. See section 3 for more details on the payload types, + and [IPDOI] for the formats of the IETF IP Security DOI payloads. + + Exchange Type: An exchange type is a specification of the number of + messages in an ISAKMP exchange, and the payload types that are + contained in each of those messages. Each exchange type is designed + to provide a particular set of security services, such as anonymity + of the participants, perfect forward secrecy of the keying material, + authentication of the participants, etc. Section 4.1 defines the + + + +Maughan, et. al. Standards Track [Page 15] + +RFC 2408 ISAKMP November 1998 + + + default set of ISAKMP exchange types. Other exchange types can be + added to support additional key exchanges, if required. + +2.2 ISAKMP Placement + + Figure 1 is a high level view of the placement of ISAKMP within a + system context in a network architecture. An important part of + negotiating security services is to consider the entire "stack" of + individual SAs as a unit. This is referred to as a "protection + suite". + + +------------+ +--------+ +--------------+ + ! DOI ! ! ! ! Application ! + ! Definition ! <----> ! ISAKMP ! ! Process ! + +------------+ --> ! ! !--------------! + +--------------+ ! +--------+ ! Appl Protocol! + ! Key Exchange ! ! ^ ^ +--------------+ + ! Definition !<-- ! ! ^ + +--------------+ ! ! ! + ! ! ! + !----------------! ! ! + v ! ! + +-------+ v v + ! API ! +---------------------------------------------+ + +-------+ ! Socket Layer ! + ! !---------------------------------------------! + v ! Transport Protocol (TCP / UDP) ! + +----------+ !---------------------------------------------! + ! Security ! <----> ! IP ! + ! Protocol ! !---------------------------------------------! + +----------+ ! Link Layer Protocol ! + +---------------------------------------------+ + + + Figure 1: ISAKMP Relationships + +2.3 Negotiation Phases + + ISAKMP offers two "phases" of negotiation. In the first phase, two + entities (e.g. ISAKMP servers) agree on how to protect further + negotiation traffic between themselves, establishing an ISAKMP SA. + This ISAKMP SA is then used to protect the negotiations for the + Protocol SA being requested. Two entities (e.g. ISAKMP servers) can + negotiate (and have active) multiple ISAKMP SAs. + + + + + + + +Maughan, et. al. Standards Track [Page 16] + +RFC 2408 ISAKMP November 1998 + + + The second phase of negotiation is used to establish security + associations for other security protocols. This second phase can be + used to establish many security associations. The security + associations established by ISAKMP during this phase can be used by a + security protocol to protect many message/data exchanges. + + While the two-phased approach has a higher start-up cost for most + simple scenarios, there are several reasons that it is beneficial for + most cases. + + First, entities (e.g. ISAKMP servers) can amortize the cost of the + first phase across several second phase negotiations. This allows + multiple SAs to be established between peers over time without having + to start over for each communication. + + Second, security services negotiated during the first phase provide + security properties for the second phase. For example, after the + first phase of negotiation, the encryption provided by the ISAKMP SA + can provide identity protection, potentially allowing the use of + simpler second-phase exchanges. On the other hand, if the channel + established during the first phase is not adequate to protect + identities, then the second phase must negotiate adequate security + mechanisms. + + Third, having an ISAKMP SA in place considerably reduces the cost of + ISAKMP management activity - without the "trusted path" that an + ISAKMP SA gives you, the entities (e.g. ISAKMP servers) would have + to go through a complete re-authentication for each error + notification or deletion of an SA. + + Negotiation during each phase is accomplished using ISAKMP-defined + exchanges (see section 4) or exchanges defined for a key exchange + within a DOI. + + Note that security services may be applied differently in each + negotiation phase. For example, different parties are being + authenticated during each of the phases of negotiation. During the + first phase, the parties being authenticated may be the ISAKMP + servers/hosts, while during the second phase, users or application + level programs are being authenticated. + +2.4 Identifying Security Associations + + While bootstrapping secure channels between systems, ISAKMP cannot + assume the existence of security services, and must provide some + protections for itself. Therefore, ISAKMP considers an ISAKMP + Security Association to be different than other types, and manages + ISAKMP SAs itself, in their own name space. ISAKMP uses the two + + + +Maughan, et. al. Standards Track [Page 17] + +RFC 2408 ISAKMP November 1998 + + + cookie fields in the ISAKMP header to identify ISAKMP SAs. The + Message ID in the ISAKMP Header and the SPI field in the Proposal + payload are used during SA establishment to identify the SA for other + security protocols. The interpretation of these four fields is + dependent on the operation taking place. + + The following table shows the presence or absence of several fields + during SA establishment. The following fields are necessary for + various operations associated with SA establishment: cookies in the + ISAKMP header, the ISAKMP Header Message ID field, and the SPI field + in the Proposal payload. An 'X' in the column means the value MUST + be present. An 'NA' in the column means a value in the column is Not + Applicable to the operation. + + # Operation I-Cookie R-Cookie Message ID SPI + (1) Start ISAKMP SA negotiation X 0 0 0 + (2) Respond ISAKMP SA negotiation X X 0 0 + (3) Init other SA negotiation X X X X + (4) Respond other SA negotiation X X X X + (5) Other (KE, ID, etc.) X X X/0 NA + (6) Security Protocol (ESP, AH) NA NA NA X + + In the first line (1) of the table, the initiator includes the + Initiator Cookie field in the ISAKMP Header, using the procedures + outlined in sections 2.5.3 and 3.1. + + In the second line (2) of the table, the responder includes the + Initiator and Responder Cookie fields in the ISAKMP Header, using the + procedures outlined in sections 2.5.3 and 3.1. Additional messages + may be exchanged between ISAKMP peers, depending on the ISAKMP + exchange type used during the phase 1 negotiation. Once the phase 1 + exchange is completed, the Initiator and Responder cookies are + included in the ISAKMP Header of all subsequent communications + between the ISAKMP peers. + + During phase 1 negotiations, the initiator and responder cookies + determine the ISAKMP SA. Therefore, the SPI field in the Proposal + payload is redundant and MAY be set to 0 or it MAY contain the + transmitting entity's cookie. + + In the third line (3) of the table, the initiator associates a + Message ID with the Protocols contained in the SA Proposal. This + Message ID and the initiator's SPI(s) to be associated with each + protocol in the Proposal are sent to the responder. The SPI(s) will + be used by the security protocols once the phase 2 negotiation is + completed. + + + + + +Maughan, et. al. Standards Track [Page 18] + +RFC 2408 ISAKMP November 1998 + + + In the fourth line (4) of the table, the responder includes the same + Message ID and the responder's SPI(s) to be associated with each + protocol in the accepted Proposal. This information is returned to + the initiator. + + In the fifth line (5) of the table, the initiator and responder use + the Message ID field in the ISAKMP Header to keep track of the in- + progress protocol negotiation. This is only applicable for a phase 2 + exchange and the value MUST be 0 for a phase 1 exchange because the + combined cookies identify the ISAKMP SA. The SPI field in the + Proposal payload is not applicable because the Proposal payload is + only used during the SA negotiation message exchange (steps 3 and 4). + + In the sixth line (6) of the table, the phase 2 negotiation is + complete. The security protocols use the SPI(s) to determine which + security services and mechanisms to apply to the communication + between them. The SPI value shown in the sixth line (6) is not the + SPI field in the Proposal payload, but the SPI field contained within + the security protocol header. + + During the SA establishment, a SPI MUST be generated. ISAKMP is + designed to handle variable sized SPIs. This is accomplished by + using the SPI Size field within the Proposal payload during SA + establishment. Handling of SPIs will be outlined by the DOI + specification (e.g. [IPDOI]). + + When a security association (SA) is initially established, one side + assumes the role of initiator and the other the role of responder. + Once the SA is established, both the original initiator and responder + can initiate a phase 2 negotiation with the peer entity. Thus, + ISAKMP SAs are bidirectional in nature. + + Additionally, ISAKMP allows both initiator and responder to have some + control during the negotiation process. While ISAKMP is designed to + allow an SA negotiation that includes multiple proposals, the + initiator can maintain some control by only making one proposal in + accordance with the initiator's local security policy. Once the + initiator sends a proposal containing more than one proposal (which + are sent in decreasing preference order), the initiator relinquishes + control to the responder. Once the responder is controlling the SA + establishment, the responder can make its policy take precedence over + the initiator within the context of the multiple options offered by + the initiator. This is accomplished by selecting the proposal best + suited for the responder's local security policy and returning this + selection to the initiator. + + + + + + +Maughan, et. al. Standards Track [Page 19] + +RFC 2408 ISAKMP November 1998 + + +2.5 Miscellaneous + +2.5.1 Transport Protocol + + ISAKMP can be implemented over any transport protocol or over IP + itself. Implementations MUST include send and receive capability for + ISAKMP using the User Datagram Protocol (UDP) on port 500. UDP Port + 500 has been assigned to ISAKMP by the Internet Assigned Numbers + Authority (IANA). Implementations MAY additionally support ISAKMP + over other transport protocols or over IP itself. + +2.5.2 RESERVED Fields + + The existence of RESERVED fields within ISAKMP payloads are used + strictly to preserve byte alignment. All RESERVED fields in the + ISAKMP protocol MUST be set to zero (0) when a packet is issued. The + receiver SHOULD check the RESERVED fields for a zero (0) value and + discard the packet if other values are found. + +2.5.3 Anti-Clogging Token ("Cookie") Creation + + The details of cookie generation are implementation dependent, but + MUST satisfy these basic requirements (originally stated by Phil Karn + in [Karn]): + + 1. The cookie must depend on the specific parties. This + prevents an attacker from obtaining a cookie using a real IP + address and UDP port, and then using it to swamp the victim + with Diffie-Hellman requests from randomly chosen IP + addresses or ports. + + 2. It must not be possible for anyone other than the issuing + entity to generate cookies that will be accepted by that + entity. This implies that the issuing entity must use local + secret information in the generation and subsequent + verification of a cookie. It must not be possible to deduce + this secret information from any particular cookie. + + 3. The cookie generation function must be fast to thwart + attacks intended to sabotage CPU resources. + + Karn's suggested method for creating the cookie is to perform a fast + hash (e.g. MD5) over the IP Source and Destination Address, the UDP + Source and Destination Ports and a locally generated secret random + value. ISAKMP requires that the cookie be unique for each SA + establishment to help prevent replay attacks, therefore, the date and + time MUST be added to the information hashed. The generated cookies + are placed in the ISAKMP Header (described in section 3.1) Initiator + + + +Maughan, et. al. Standards Track [Page 20] + +RFC 2408 ISAKMP November 1998 + + + and Responder cookie fields. These fields are 8 octets in length, + thus, requiring a generated cookie to be 8 octets. Notify and Delete + messages (see sections 3.14, 3.15, and 4.8) are uni-directional + transmissions and are done under the protection of an existing ISAKMP + SA, thus, not requiring the generation of a new cookie. One + exception to this is the transmission of a Notify message during a + Phase 1 exchange, prior to completing the establishment of an SA. + Sections 3.14 and 4.8 provide additional details. + +3 ISAKMP Payloads + + ISAKMP payloads provide modular building blocks for constructing + ISAKMP messages. The presence and ordering of payloads in ISAKMP is + defined by and dependent upon the Exchange Type Field located in the + ISAKMP Header (see Figure 2). The ISAKMP payload types are discussed + in sections 3.4 through 3.15. The descriptions of the ISAKMP + payloads, messages, and exchanges (see Section 4) are shown using + network octet ordering. + +3.1 ISAKMP Header Format + + An ISAKMP message has a fixed header format, shown in Figure 2, + followed by a variable number of payloads. A fixed header simplifies + parsing, providing the benefit of protocol parsing software that is + less complex and easier to implement. The fixed header contains the + information required by the protocol to maintain state, process + payloads and possibly prevent denial of service or replay attacks. + + The ISAKMP Header fields are defined as follows: + + o Initiator Cookie (8 octets) - Cookie of entity that initiated SA + establishment, SA notification, or SA deletion. + + o Responder Cookie (8 octets) - Cookie of entity that is responding + to an SA establishment request, SA notification, or SA deletion. + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 21] + +RFC 2408 ISAKMP November 1998 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Initiator ! + ! Cookie ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Responder ! + ! Cookie ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! MjVer ! MnVer ! Exchange Type ! Flags ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Message ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 2: ISAKMP Header Format + + o Next Payload (1 octet) - Indicates the type of the first payload + in the message. The format for each payload is defined in + sections 3.4 through 3.16. The processing for the payloads is + defined in section 5. + + + Next Payload Type Value + NONE 0 + Security Association (SA) 1 + Proposal (P) 2 + Transform (T) 3 + Key Exchange (KE) 4 + Identification (ID) 5 + Certificate (CERT) 6 + Certificate Request (CR) 7 + Hash (HASH) 8 + Signature (SIG) 9 + Nonce (NONCE) 10 + Notification (N) 11 + Delete (D) 12 + Vendor ID (VID) 13 + RESERVED 14 - 127 + Private USE 128 - 255 + + o Major Version (4 bits) - indicates the major version of the ISAKMP + protocol in use. Implementations based on this version of the + ISAKMP Internet-Draft MUST set the Major Version to 1. + Implementations based on previous versions of ISAKMP Internet- + Drafts MUST set the Major Version to 0. Implementations SHOULD + + + +Maughan, et. al. Standards Track [Page 22] + +RFC 2408 ISAKMP November 1998 + + + never accept packets with a major version number larger than its + own. + + o Minor Version (4 bits) - indicates the minor version of the + ISAKMP protocol in use. Implementations based on this version of + the ISAKMP Internet-Draft MUST set the Minor Version to 0. + Implementations based on previous versions of ISAKMP Internet- + Drafts MUST set the Minor Version to 1. Implementations SHOULD + never accept packets with a minor version number larger than its + own, given the major version numbers are identical. + + o Exchange Type (1 octet) - indicates the type of exchange being + used. This dictates the message and payload orderings in the + ISAKMP exchanges. + + + Exchange Type Value + NONE 0 + Base 1 + Identity Protection 2 + Authentication Only 3 + Aggressive 4 + Informational 5 + ISAKMP Future Use 6 - 31 + DOI Specific Use 32 - 239 + Private Use 240 - 255 + + o Flags (1 octet) - indicates specific options that are set for the + ISAKMP exchange. The flags listed below are specified in the + Flags field beginning with the least significant bit, i.e the + Encryption bit is bit 0 of the Flags field, the Commit bit is bit + 1 of the Flags field, and the Authentication Only bit is bit 2 of + the Flags field. The remaining bits of the Flags field MUST be + set to 0 prior to transmission. + + -- E(ncryption Bit) (1 bit) - If set (1), all payloads following + the header are encrypted using the encryption algorithm + identified in the ISAKMP SA. The ISAKMP SA Identifier is the + combination of the initiator and responder cookie. It is + RECOMMENDED that encryption of communications be done as soon + as possible between the peers. For all ISAKMP exchanges + described in section 4.1, the encryption SHOULD begin after + both parties have exchanged Key Exchange payloads. If the + E(ncryption Bit) is not set (0), the payloads are not + encrypted. + + + + + + +Maughan, et. al. Standards Track [Page 23] + +RFC 2408 ISAKMP November 1998 + + + -- C(ommit Bit) (1 bit) - This bit is used to signal key exchange + synchronization. It is used to ensure that encrypted material + is not received prior to completion of the SA establishment. + The Commit Bit can be set (at anytime) by either party + participating in the SA establishment, and can be used during + both phases of an ISAKMP SA establishment. However, the value + MUST be reset after the Phase 1 negotiation. If set(1), the + entity which did not set the Commit Bit MUST wait for an + Informational Exchange containing a Notify payload (with the + CONNECTED Notify Message) from the entity which set the Commit + Bit. In this instance, the Message ID field of the + Informational Exchange MUST contain the Message ID of the + original ISAKMP Phase 2 SA negotiation. This is done to + ensure that the Informational Exchange with the CONNECTED + Notify Message can be associated with the correct Phase 2 SA. + The receipt and processing of the Informational Exchange + indicates that the SA establishment was successful and either + entity can now proceed with encrypted traffic communication. + In addition to synchronizing key exchange, the Commit Bit can + be used to protect against loss of transmissions over + unreliable networks and guard against the need for multiple + re-transmissions. + + NOTE: It is always possible that the final message of an + exchange can be lost. In this case, the entity expecting to + receive the final message of an exchange would receive the + Phase 2 SA negotiation message following a Phase 1 exchange or + encrypted traffic following a Phase 2 exchange. Handling of + this situation is not standardized, but we propose the + following possibilities. If the entity awaiting the + Informational Exchange can verify the received message (i.e. + Phase 2 SA negotiation message or encrypted traffic), then + they MAY consider the SA was established and continue + processing. The other option is to retransmit the last ISAKMP + message to force the other entity to retransmit the final + message. This suggests that implementations may consider + retaining the last message (locally) until they are sure the + SA is established. + + -- A(uthentication Only Bit) (1 bit) - This bit is intended for + use with the Informational Exchange with a Notify payload and + will allow the transmission of information with integrity + checking, but no encryption (e.g. "emergency mode"). Section + 4.8 states that a Phase 2 Informational Exchange MUST be sent + under the protection of an ISAKMP SA. This is the only + exception to that policy. If the Authentication Only bit is + set (1), only authentication security services will be applied + to the entire Notify payload of the Informational Exchange and + + + +Maughan, et. al. Standards Track [Page 24] + +RFC 2408 ISAKMP November 1998 + + + the payload will not be encrypted. + + o Message ID (4 octets) - Unique Message Identifier used to + identify protocol state during Phase 2 negotiations. This value + is randomly generated by the initiator of the Phase 2 + negotiation. In the event of simultaneous SA establishments + (i.e. collisions), the value of this field will likely be + different because they are independently generated and, thus, two + security associations will progress toward establishment. + However, it is unlikely there will be absolute simultaneous + establishments. During Phase 1 negotiations, the value MUST be + set to 0. + + o Length (4 octets) - Length of total message (header + payloads) + in octets. Encryption can expand the size of an ISAKMP message. + +3.2 Generic Payload Header + + Each ISAKMP payload defined in sections 3.4 through 3.16 begins with + a generic header, shown in Figure 3, which provides a payload + "chaining" capability and clearly defines the boundaries of a + payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 3: Generic Payload Header + + The Generic Payload Header fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. This field provides + the "chaining" capability. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + +3.3 Data Attributes + + There are several instances within ISAKMP where it is necessary to + represent Data Attributes. An example of this is the Security + Association (SA) Attributes contained in the Transform payload + + + +Maughan, et. al. Standards Track [Page 25] + +RFC 2408 ISAKMP November 1998 + + + (described in section 3.6). These Data Attributes are not an ISAKMP + payload, but are contained within ISAKMP payloads. The format of the + Data Attributes provides the flexibility for representation of many + different types of information. There can be multiple Data + Attributes within a payload. The length of the Data Attributes will + either be 4 octets or defined by the Attribute Length field. This is + done using the Attribute Format bit described below. Specific + information about the attributes for each domain will be described in + a DOI document, e.g. IPSEC DOI [IPDOI]. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !A! Attribute Type ! AF=0 Attribute Length ! + !F! ! AF=1 Attribute Value ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + . AF=0 Attribute Value . + . AF=1 Not Transmitted . + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 4: Data Attributes + + The Data Attributes fields are defined as follows: + + o Attribute Type (2 octets) - Unique identifier for each type of + attribute. These attributes are defined as part of the DOI- + specific information. + + The most significant bit, or Attribute Format (AF), indicates + whether the data attributes follow the Type/Length/Value (TLV) + format or a shortened Type/Value (TV) format. If the AF bit is a + zero (0), then the Data Attributes are of the Type/Length/Value + (TLV) form. If the AF bit is a one (1), then the Data Attributes + are of the Type/Value form. + + o Attribute Length (2 octets) - Length in octets of the Attribute + Value. When the AF bit is a one (1), the Attribute Value is only + 2 octets and the Attribute Length field is not present. + + o Attribute Value (variable length) - Value of the attribute + associated with the DOI-specific Attribute Type. If the AF bit + is a zero (0), this field has a variable length defined by the + Attribute Length field. If the AF bit is a one (1), the + Attribute Value has a length of 2 octets. + + + + + + +Maughan, et. al. Standards Track [Page 26] + +RFC 2408 ISAKMP November 1998 + + +3.4 Security Association Payload + + The Security Association Payload is used to negotiate security + attributes and to indicate the Domain of Interpretation (DOI) and + Situation under which the negotiation is taking place. Figure 5 + shows the format of the Security Association payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation (DOI) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Situation ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 5: Security Association Payload + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. This field MUST NOT + contain the values for the Proposal or Transform payloads as they + are considered part of the security association negotiation. For + example, this field would contain the value "10" (Nonce payload) + in the first message of a Base Exchange (see Section 4.4) and the + value "0" in the first message of an Identity Protect Exchange + (see Section 4.5). + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the entire + Security Association payload, including the SA payload, all + Proposal payloads, and all Transform payloads associated with the + proposed Security Association. + + o Domain of Interpretation (4 octets) - Identifies the DOI (as + described in Section 2.1) under which this negotiation is taking + place. The DOI is a 32-bit unsigned integer. A DOI value of 0 + during a Phase 1 exchange specifies a Generic ISAKMP SA which can + be used for any protocol during the Phase 2 exchange. The + necessary SA Attributes are defined in A.4. A DOI value of 1 is + assigned to the IPsec DOI [IPDOI]. All other DOI values are + reserved to IANA for future use. IANA will not normally assign a + DOI value without referencing some public specification, such as + + + +Maughan, et. al. Standards Track [Page 27] + +RFC 2408 ISAKMP November 1998 + + + an Internet RFC. Other DOI's can be defined using the description + in appendix B. This field MUST be present within the Security + Association payload. + + o Situation (variable length) - A DOI-specific field that + identifies the situation under which this negotiation is taking + place. The Situation is used to make policy decisions regarding + the security attributes being negotiated. Specifics for the IETF + IP Security DOI Situation are detailed in [IPDOI]. This field + MUST be present within the Security Association payload. + +3.5 Proposal Payload + + The Proposal Payload contains information used during Security + Association negotiation. The proposal consists of security + mechanisms, or transforms, to be used to secure the communications + channel. Figure 6 shows the format of the Proposal Payload. A + description of its use can be found in section 4.2. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Proposal # ! Protocol-Id ! SPI Size !# of Transforms! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! SPI (variable) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 6: Proposal Payload Format + + The Proposal Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. This field MUST only contain the + value "2" or "0". If there are additional Proposal payloads in + the message, then this field will be 2. If the current Proposal + payload is the last within the security association proposal, + then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the entire + Proposal payload, including generic payload header, the Proposal + payload, and all Transform payloads associated with this + proposal. In the event there are multiple proposals with the + same proposal number (see section 4.2), the Payload Length field + + + +Maughan, et. al. Standards Track [Page 28] + +RFC 2408 ISAKMP November 1998 + + + only applies to the current Proposal payload and not to all + Proposal payloads. + + o Proposal # (1 octet) - Identifies the Proposal number for the + current payload. A description of the use of this field is found + in section 4.2. + + o Protocol-Id (1 octet) - Specifies the protocol identifier for the + current negotiation. Examples might include IPSEC ESP, IPSEC AH, + OSPF, TLS, etc. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by + the Protocol-Id. In the case of ISAKMP, the Initiator and + Responder cookie pair from the ISAKMP Header is the ISAKMP SPI, + therefore, the SPI Size is irrelevant and MAY be from zero (0) to + sixteen (16). If the SPI Size is non-zero, the content of the + SPI field MUST be ignored. If the SPI Size is not a multiple of + 4 octets it will have some impact on the SPI field and the + alignment of all payloads in the message. The Domain of + Interpretation (DOI) will dictate the SPI Size for other + protocols. + + o # of Transforms (1 octet) - Specifies the number of transforms + for the Proposal. Each of these is contained in a Transform + payload. + + o SPI (variable) - The sending entity's SPI. In the event the SPI + Size is not a multiple of 4 octets, there is no padding applied + to the payload, however, it can be applied at the end of the + message. + + The payload type for the Proposal Payload is two (2). + +3.6 Transform Payload + + The Transform Payload contains information used during Security + Association negotiation. The Transform payload consists of a + specific security mechanism, or transforms, to be used to secure the + communications channel. The Transform payload also contains the + security association attributes associated with the specific + transform. These SA attributes are DOI-specific. Figure 7 shows the + format of the Transform Payload. A description of its use can be + found in section 4.2. + + + + + + + + +Maughan, et. al. Standards Track [Page 29] + +RFC 2408 ISAKMP November 1998 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Transform # ! Transform-Id ! RESERVED2 ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ SA Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 7: Transform Payload Format + + The Transform Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. This field MUST only contain the + value "3" or "0". If there are additional Transform payloads in + the proposal, then this field will be 3. If the current + Transform payload is the last within the proposal, then this + field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header, Transform values, + and all SA Attributes. + + o Transform # (1 octet) - Identifies the Transform number for the + current payload. If there is more than one transform proposed + for a specific protocol within the Proposal payload, then each + Transform payload has a unique Transform number. A description + of the use of this field is found in section 4.2. + + o Transform-Id (1 octet) - Specifies the Transform identifier for + the protocol within the current proposal. These transforms are + defined by the DOI and are dependent on the protocol being + negotiated. + + o RESERVED2 (2 octets) - Unused, set to 0. + + o SA Attributes (variable length) - This field contains the + security association attributes as defined for the transform + given in the Transform-Id field. The SA Attributes SHOULD be + represented using the Data Attributes format described in section + 3.3. If the SA Attributes are not aligned on 4-byte boundaries, + + + +Maughan, et. al. Standards Track [Page 30] + +RFC 2408 ISAKMP November 1998 + + + then subsequent payloads will not be aligned and any padding will + be added at the end of the message to make the message 4-octet + aligned. + + The payload type for the Transform Payload is three (3). + +3.7 Key Exchange Payload + + The Key Exchange Payload supports a variety of key exchange + techniques. Example key exchanges are Oakley [Oakley], Diffie- + Hellman, the enhanced Diffie-Hellman key exchange described in X9.42 + [ANSI], and the RSA-based key exchange used by PGP. Figure 8 shows + the format of the Key Exchange payload. + + The Key Exchange Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + nextpayload in the message. If the current payload is the last + in the message, then this field will be 0. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Key Exchange Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 8: Key Exchange Payload Format + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Key Exchange Data (variable length) - Data required to generate a + session key. The interpretation of this data is specified by the + DOI and the associated Key Exchange algorithm. This field may + also contain pre-placed key indicators. + + The payload type for the Key Exchange Payload is four (4). + + + + + + + +Maughan, et. al. Standards Track [Page 31] + +RFC 2408 ISAKMP November 1998 + + +3.8 Identification Payload + + The Identification Payload contains DOI-specific data used to + exchange identification information. This information is used for + determining the identities of communicating peers and may be used for + determining authenticity of information. Figure 9 shows the format + of the Identification Payload. + + The Identification Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o ID Type (1 octet) - Specifies the type of Identification being + used. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ID Type ! DOI Specific ID Data ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Identification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 9: Identification Payload Format + + This field is DOI-dependent. + + o DOI Specific ID Data (3 octets) - Contains DOI specific + Identification data. If unused, then this field MUST be set to + 0. + + o Identification Data (variable length) - Contains identity + information. The values for this field are DOI-specific and the + format is specified by the ID Type field. Specific details for + the IETF IP Security DOI Identification Data are detailed in + [IPDOI]. + + + +Maughan, et. al. Standards Track [Page 32] + +RFC 2408 ISAKMP November 1998 + + + The payload type for the Identification Payload is five (5). + +3.9 Certificate Payload + + The Certificate Payload provides a means to transport certificates or + other certificate-related information via ISAKMP and can appear in + any ISAKMP message. Certificate payloads SHOULD be included in an + exchange whenever an appropriate directory service (e.g. Secure DNS + [DNSSEC]) is not available to distribute certificates. The + Certificate payload MUST be accepted at any point during an exchange. + Figure 10 shows the format of the Certificate Payload. + + NOTE: Certificate types and formats are not generally bound to a DOI + - it is expected that there will only be a few certificate types, and + that most DOIs will accept all of these types. + + The Certificate Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certificate Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 10: Certificate Payload Format + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Certificate Encoding (1 octet) - This field indicates the type of + certificate or certificate-related information contained in the + Certificate Data field. + + + + + + + +Maughan, et. al. Standards Track [Page 33] + +RFC 2408 ISAKMP November 1998 + + + Certificate Type Value + NONE 0 + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + X.509 Certificate - Signature 4 + X.509 Certificate - Key Exchange 5 + Kerberos Tokens 6 + Certificate Revocation List (CRL) 7 + Authority Revocation List (ARL) 8 + SPKI Certificate 9 + X.509 Certificate - Attribute 10 + RESERVED 11 - 255 + + o Certificate Data (variable length) - Actual encoding of + certificate data. The type of certificate is indicated by the + Certificate Encoding field. + + The payload type for the Certificate Payload is six (6). + +3.10 Certificate Request Payload + + The Certificate Request Payload provides a means to request + certificates via ISAKMP and can appear in any message. Certificate + Request payloads SHOULD be included in an exchange whenever an + appropriate directory service (e.g. Secure DNS [DNSSEC]) is not + available to distribute certificates. The Certificate Request + payload MUST be accepted at any point during the exchange. The + responder to the Certificate Request payload MUST send its + certificate, if certificates are supported, based on the values + contained in the payload. If multiple certificates are required, + then multiple Certificate Request payloads SHOULD be transmitted. + Figure 11 shows the format of the Certificate Request Payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert. Type ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certificate Authority ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 11: Certificate Request Payload Format + + + + +Maughan, et. al. Standards Track [Page 34] + +RFC 2408 ISAKMP November 1998 + + + The Certificate Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Certificate Type (1 octet) - Contains an encoding of the type of + certificate requested. Acceptable values are listed in section + 3.9. + + o Certificate Authority (variable length) - Contains an encoding of + an acceptable certificate authority for the type of certificate + requested. As an example, for an X.509 certificate this field + would contain the Distinguished Name encoding of the Issuer Name + of an X.509 certificate authority acceptable to the sender of + this payload. This would be included to assist the responder in + determining how much of the certificate chain would need to be + sent in response to this request. If there is no specific + certificate authority requested, this field SHOULD not be + included. + + The payload type for the Certificate Request Payload is seven (7). + + + + + + + + + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 35] + +RFC 2408 ISAKMP November 1998 + + +3.11 Hash Payload + + The Hash Payload contains data generated by the hash function + (selected during the SA establishment exchange), over some part of + the message and/or ISAKMP state. This payload may be used to verify + the integrity of the data in an ISAKMP message or for authentication + of the negotiating entities. Figure 12 shows the format of the Hash + Payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Hash Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 12: Hash Payload Format + + The Hash Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Hash Data (variable length) - Data that results from applying the + hash routine to the ISAKMP message and/or state. + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 36] + +RFC 2408 ISAKMP November 1998 + + +3.12 Signature Payload + + The Signature Payload contains data generated by the digital + signature function (selected during the SA establishment exchange), + over some part of the message and/or ISAKMP state. This payload is + used to verify the integrity of the data in the ISAKMP message, and + may be of use for non-repudiation services. Figure 13 shows the + format of the Signature Payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Signature Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 13: Signature Payload Format + + The Signature Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Signature Data (variable length) - Data that results from + applying the digital signature function to the ISAKMP message + and/or state. + + The payload type for the Signature Payload is nine (9). + +3.13 Nonce Payload + + The Nonce Payload contains random data used to guarantee liveness + during an exchange and protect against replay attacks. Figure 14 + shows the format of the Nonce Payload. If nonces are used by a + particular key exchange, the use of the Nonce payload will be + dictated by the key exchange. The nonces may be transmitted as part + of the key exchange data, or as a separate payload. However, this is + defined by the key exchange, not by ISAKMP. + + + +Maughan, et. al. Standards Track [Page 37] + +RFC 2408 ISAKMP November 1998 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Nonce Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 14: Nonce Payload Format + + The Nonce Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Nonce Data (variable length) - Contains the random data generated + by the transmitting entity. + + The payload type for the Nonce Payload is ten (10). + +3.14 Notification Payload + + The Notification Payload can contain both ISAKMP and DOI-specific + data and is used to transmit informational data, such as error + conditions, to an ISAKMP peer. It is possible to send multiple + Notification payloads in a single ISAKMP message. Figure 15 shows + the format of the Notification Payload. + + Notification which occurs during, or is concerned with, a Phase 1 + negotiation is identified by the Initiator and Responder cookie pair + in the ISAKMP Header. The Protocol Identifier, in this case, is + ISAKMP and the SPI value is 0 because the cookie pair in the ISAKMP + Header identifies the ISAKMP SA. If the notification takes place + prior to the completed exchange of keying information, then the + notification will be unprotected. + + + + + + + +Maughan, et. al. Standards Track [Page 38] + +RFC 2408 ISAKMP November 1998 + + + Notification which occurs during, or is concerned with, a Phase 2 + negotiation is identified by the Initiator and Responder cookie pair + in the ISAKMP Header and the Message ID and SPI associated with the + current negotiation. One example for this type of notification is to + indicate why a proposal was rejected. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation (DOI) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol-ID ! SPI Size ! Notify Message Type ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Notification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 15: Notification Payload Format + + The Notification Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Domain of Interpretation (4 octets) - Identifies the DOI (as + described in Section 2.1) under which this notification is taking + place. For ISAKMP this value is zero (0) and for the IPSEC DOI + it is one (1). Other DOI's can be defined using the description + in appendix B. + + o Protocol-Id (1 octet) - Specifies the protocol identifier for the + current notification. Examples might include ISAKMP, IPSEC ESP, + IPSEC AH, OSPF, TLS, etc. + + + + +Maughan, et. al. Standards Track [Page 39] + +RFC 2408 ISAKMP November 1998 + + + o SPI Size (1 octet) - Length in octets of the SPI as defined by + the Protocol-Id. In the case of ISAKMP, the Initiator and + Responder cookie pair from the ISAKMP Header is the ISAKMP SPI, + therefore, the SPI Size is irrelevant and MAY be from zero (0) to + sixteen (16). If the SPI Size is non-zero, the content of the + SPI field MUST be ignored. The Domain of Interpretation (DOI) + will dictate the SPI Size for other protocols. + + o Notify Message Type (2 octets) - Specifies the type of + notification message (see section 3.14.1). Additional text, if + specified by the DOI, is placed in the Notification Data field. + + o SPI (variable length) - Security Parameter Index. The receiving + entity's SPI. The use of the SPI field is described in section + 2.4. The length of this field is determined by the SPI Size + field and is not necessarily aligned to a 4 octet boundary. + + o Notification Data (variable length) - Informational or error data + transmitted in addition to the Notify Message Type. Values for + this field are DOI-specific. + + The payload type for the Notification Payload is eleven (11). + +3.14.1 Notify Message Types + + Notification information can be error messages specifying why an SA + could not be established. It can also be status data that a process + managing an SA database wishes to communicate with a peer process. + For example, a secure front end or security gateway may use the + Notify message to synchronize SA communication. The table below + lists the Nofitication messages and their corresponding values. + Values in the Private Use range are expected to be DOI-specific + values. + + NOTIFY MESSAGES - ERROR TYPES + + Errors Value + INVALID-PAYLOAD-TYPE 1 + DOI-NOT-SUPPORTED 2 + SITUATION-NOT-SUPPORTED 3 + INVALID-COOKIE 4 + INVALID-MAJOR-VERSION 5 + INVALID-MINOR-VERSION 6 + INVALID-EXCHANGE-TYPE 7 + INVALID-FLAGS 8 + INVALID-MESSAGE-ID 9 + INVALID-PROTOCOL-ID 10 + INVALID-SPI 11 + + + +Maughan, et. al. Standards Track [Page 40] + +RFC 2408 ISAKMP November 1998 + + + INVALID-TRANSFORM-ID 12 + ATTRIBUTES-NOT-SUPPORTED 13 + NO-PROPOSAL-CHOSEN 14 + BAD-PROPOSAL-SYNTAX 15 + PAYLOAD-MALFORMED 16 + INVALID-KEY-INFORMATION 17 + INVALID-ID-INFORMATION 18 + INVALID-CERT-ENCODING 19 + INVALID-CERTIFICATE 20 + CERT-TYPE-UNSUPPORTED 21 + INVALID-CERT-AUTHORITY 22 + INVALID-HASH-INFORMATION 23 + AUTHENTICATION-FAILED 24 + INVALID-SIGNATURE 25 + ADDRESS-NOTIFICATION 26 + NOTIFY-SA-LIFETIME 27 + CERTIFICATE-UNAVAILABLE 28 + UNSUPPORTED-EXCHANGE-TYPE 29 + UNEQUAL-PAYLOAD-LENGTHS 30 + RESERVED (Future Use) 31 - 8191 + Private Use 8192 - 16383 + + + + NOTIFY MESSAGES - STATUS TYPES + Status Value + CONNECTED 16384 + RESERVED (Future Use) 16385 - 24575 + DOI-specific codes 24576 - 32767 + Private Use 32768 - 40959 + RESERVED (Future Use) 40960 - 65535 + +3.15 Delete Payload + + The Delete Payload contains a protocol-specific security association + identifier that the sender has removed from its security association + database and is, therefore, no longer valid. Figure 16 shows the + format of the Delete Payload. It is possible to send multiple SPIs + in a Delete payload, however, each SPI MUST be for the same protocol. + Mixing of Protocol Identifiers MUST NOT be performed with the Delete + payload. + + Deletion which is concerned with an ISAKMP SA will contain a + Protocol-Id of ISAKMP and the SPIs are the initiator and responder + cookies from the ISAKMP Header. Deletion which is concerned with a + Protocol SA, such as ESP or AH, will contain the Protocol-Id of that + protocol (e.g. ESP, AH) and the SPI is the sending entity's SPI(s). + + + + +Maughan, et. al. Standards Track [Page 41] + +RFC 2408 ISAKMP November 1998 + + + NOTE: The Delete Payload is not a request for the responder to delete + an SA, but an advisory from the initiator to the responder. If the + responder chooses to ignore the message, the next communication from + the responder to the initiator, using that security association, will + fail. A responder is not expected to acknowledge receipt of a Delete + payload. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation (DOI) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol-Id ! SPI Size ! # of SPIs ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index(es) (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 16: Delete Payload Format + + The Delete Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Domain of Interpretation (4 octets) - Identifies the DOI (as + described in Section 2.1) under which this deletion is taking + place. For ISAKMP this value is zero (0) and for the IPSEC DOI + it is one (1). Other DOI's can be defined using the description + in appendix B. + + o Protocol-Id (1 octet) - ISAKMP can establish security + associations for various protocols, including ISAKMP and IPSEC. + This field identifies which security association database to + apply the delete request. + + + + + + +Maughan, et. al. Standards Track [Page 42] + +RFC 2408 ISAKMP November 1998 + + + o SPI Size (1 octet) - Length in octets of the SPI as defined by + the Protocol-Id. In the case of ISAKMP, the Initiator and + Responder cookie pair is the ISAKMP SPI. In this case, the SPI + Size would be 16 octets for each SPI being deleted. + + o # of SPIs (2 octets) - The number of SPIs contained in the Delete + payload. The size of each SPI is defined by the SPI Size field. + + o Security Parameter Index(es) (variable length) - Identifies the + specific security association(s) to delete. Values for this + field are DOI and protocol specific. The length of this field is + determined by the SPI Size and # of SPIs fields. + + The payload type for the Delete Payload is twelve (12). + +3.16 Vendor ID Payload + + The Vendor ID Payload contains a vendor defined constant. The + constant is used by vendors to identify and recognize remote + instances of their implementations. This mechanism allows a vendor + to experiment with new features while maintaining backwards + compatibility. This is not a general extension facility of ISAKMP. + Figure 17 shows the format of the Vendor ID Payload. + + The Vendor ID payload is not an announcement from the sender that it + will send private payload types. A vendor sending the Vendor ID MUST + not make any assumptions about private payloads that it may send + unless a Vendor ID is received as well. Multiple Vendor ID payloads + MAY be sent. An implementation is NOT REQUIRED to understand any + Vendor ID payloads. An implementation is NOT REQUIRED to send any + Vendor ID payload at all. If a private payload was sent without + prior agreement to send it, a compliant implementation may reject a + proposal with a notify message of type INVALID-PAYLOAD-TYPE. + + If a Vendor ID payload is sent, it MUST be sent during the Phase 1 + negotiation. Reception of a familiar Vendor ID payload in the Phase + 1 negotiation allows an implementation to make use of Private USE + payload numbers (128-255), described in section 3.1 for vendor + specific extensions during Phase 2 negotiations. The definition of + "familiar" is left to implementations to determine. Some vendors may + wish to implement another vendor's extension prior to + standardization. However, this practice SHOULD not be widespread and + vendors should work towards standardization instead. + + The vendor defined constant MUST be unique. The choice of hash and + text to hash is left to the vendor to decide. As an example, vendors + could generate their vendor id by taking a plain (non-keyed) hash of + a string containing the product name, and the version of the product. + + + +Maughan, et. al. Standards Track [Page 43] + +RFC 2408 ISAKMP November 1998 + + + A hash is used instead of a vendor registry to avoid local + cryptographic policy problems with having a list of "approved" + products, to keep away from maintaining a list of vendors, and to + allow classified products to avoid having to appear on any list. For + instance: + + "Example Company IPsec. Version 97.1" + + (not including the quotes) has MD5 hash: + 48544f9b1fe662af98b9b39e50c01a5a, when using MD5file. Vendors may + include all of the hash, or just a portion of it, as the payload + length will bound the data. There are no security implications of + this hash, so its choice is arbitrary. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Vendor ID (VID) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + Figure 17: Vendor ID Payload Format + + The Vendor ID Payload fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. + + o RESERVED (1 octet) - Unused, set to 0. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + o Vendor ID (variable length) - Hash of the vendor string plus + version (as described above). + + The payload type for the Vendor ID Payload is thirteen (13). + +4 ISAKMP Exchanges + + ISAKMP supplies the basic syntax of a message exchange. The basic + building blocks for ISAKMP messages are the payload types described + in section 3. This section describes the procedures for SA + + + +Maughan, et. al. Standards Track [Page 44] + +RFC 2408 ISAKMP November 1998 + + + establishment and SA modification, followed by a default set of + exchanges that MAY be used for initial interoperability. Other + exchanges will be defined depending on the DOI and key exchange. + [IPDOI] and [IKE] are examples of how this is achieved. Appendix B + explains the procedures for accomplishing these additions. + +4.1 ISAKMP Exchange Types + + ISAKMP allows the creation of exchanges for the establishment of + Security Associations and keying material. There are currently five + default Exchange Types defined for ISAKMP. Sections 4.4 through 4.8 + describe these exchanges. Exchanges define the content and ordering + of ISAKMP messages during communications between peers. Most + exchanges will include all the basic payload types - SA, KE, ID, SIG + - and may include others. The primary difference between exchange + types is the ordering of the messages and the payload ordering within + each message. While the ordering of payloads within messages is not + mandated, for processing efficiency it is RECOMMENDED that the + Security Association payload be the first payload within an exchange. + Processing of each payload within an exchange is described in section + 5. + + Sections 4.4 through 4.8 provide a default set of ISAKMP exchanges. + These exchanges provide different security protection for the + exchange itself and information exchanged. The diagrams in each of + the following sections show the message ordering for each exchange + type as well as the payloads included in each message, and provide + basic notes describing what has happened after each message exchange. + None of the examples include any "optional payloads", like + certificate and certificate request. Additionally, none of the + examples include an initial exchange of ISAKMP Headers (containing + initiator and responder cookies) which would provide protection + against clogging (see section 2.5.3). + + The defined exchanges are not meant to satisfy all DOI and key + exchange protocol requirements. If the defined exchanges meet the + DOI requirements, then they can be used as outlined. If the defined + exchanges do not meet the security requirements defined by the DOI, + then the DOI MUST specify new exchange type(s) and the valid + sequences of payloads that make up a successful exchange, and how to + build and interpret those payloads. All ISAKMP implementations MUST + implement the Informational Exchange and SHOULD implement the other + four exchanges. However, this is dependent on the definition of the + DOI and associated key exchange protocols. + + + + + + + +Maughan, et. al. Standards Track [Page 45] + +RFC 2408 ISAKMP November 1998 + + + As discussed above, these exchange types can be used in either phase + of negotiation. However, they may provide different security + properties in each of the phases. With each of these exchanges, the + combination of cookies and SPI fields identifies whether this + exchange is being used in the first or second phase of a negotiation. + +4.1.1 Notation + + The following notation is used to describe the ISAKMP exchange types, + shown in the next section, with the message formats and associated + payloads: + + HDR is an ISAKMP header whose exchange type defines the payload + orderings + SA is an SA negotiation payload with one or more Proposal and + Transform payloads. An initiator MAY provide multiple proposals + for negotiation; a responder MUST reply with only one. + KE is the key exchange payload. + IDx is the identity payload for "x". x can be: "ii" or "ir" + for the ISAKMP initiator and responder, respectively, or x can + be: "ui", "ur" (when the ISAKMP daemon is a proxy negotiator), + for the user initiator and responder, respectively. + HASH is the hash payload. + SIG is the signature payload. The data to sign is exchange-specific. + AUTH is a generic authentication mechanism, such as HASH or SIG. + NONCE is the nonce payload. + '*' signifies payload encryption after the ISAKMP header. This + encryption MUST begin immediately after the ISAKMP header and + all payloads following the ISAKMP header MUST be encrypted. + + => signifies "initiator to responder" communication + <= signifies "responder to initiator" communication + +4.2 Security Association Establishment + + The Security Association, Proposal, and Transform payloads are used + to build ISAKMP messages for the negotiation and establishment of + SAs. An SA establishment message consists of a single SA payload + followed by at least one, and possibly many, Proposal payloads and at + least one, and possibly many, Transform payloads associated with each + Proposal payload. Because these payloads are considered together, + the SA payload will point to any following payloads and not to the + Proposal payload included with the SA payload. The SA Payload + contains the DOI and Situation for the proposed SA. Each Proposal + payload contains a Security Parameter Index (SPI) and ensures that + the SPI is associated with the Protocol-Id in accordance with the + Internet Security Architecture [SEC-ARCH]. Proposal payloads may or + may not have the same SPI, as this is implementation dependent. Each + + + +Maughan, et. al. Standards Track [Page 46] + +RFC 2408 ISAKMP November 1998 + + + Transform Payload contains the specific security mechanisms to be + used for the designated protocol. It is expected that the Proposal + and Transform payloads will be used only during SA establishment + negotiation. The creation of payloads for security association + negotiation and establishment described here in this section are + applicable for all ISAKMP exchanges described later in sections 4.4 + through 4.8. The examples shown in 4.2.1 contain only the SA, + Proposal, and Transform payloads and do not contain other payloads + that might exist for a given ISAKMP exchange. + + The Proposal payload provides the initiating entity with the + capability to present to the responding entity the security protocols + and associated security mechanisms for use with the security + association being negotiated. If the SA establishment negotiation is + for a combined protection suite consisting of multiple protocols, + then there MUST be multiple Proposal payloads each with the same + Proposal number. These proposals MUST be considered as a unit and + MUST NOT be separated by a proposal with a different proposal number. + The use of the same Proposal number in multiple Proposal payloads + provides a logical AND operation, i.e. Protocol 1 AND Protocol 2. + The first example below shows an ESP AND AH protection suite. If the + SA establishment negotiation is for different protection suites, then + there MUST be multiple Proposal payloads each with a monotonically + increasing Proposal number. The different proposals MUST be + presented in the initiator's preference order. The use of different + Proposal numbers in multiple Proposal payloads provides a logical OR + operation, i.e. Proposal 1 OR Proposal 2, where each proposal may + have more than one protocol. The second example below shows either + an AH AND ESP protection suite OR just an ESP protection suite. Note + that the Next Payload field of the Proposal payload points to another + Proposal payload (if it exists). The existence of a Proposal payload + implies the existence of one or more Transform payloads. + + The Transform payload provides the initiating entity with the + capability to present to the responding entity multiple mechanisms, + or transforms, for a given protocol. The Proposal payload identifies + a Protocol for which services and mechanisms are being negotiated. + The Transform payload allows the initiating entity to present several + possible supported transforms for that proposed protocol. There may + be several transforms associated with a specific Proposal payload + each identified in a separate Transform payload. The multiple + transforms MUST be presented with monotonically increasing numbers in + the initiator's preference order. The receiving entity MUST select a + single transform for each protocol in a proposal or reject the entire + proposal. The use of the Transform number in multiple Transform + payloads provides a second level OR operation, i.e. Transform 1 OR + Transform 2 OR Transform 3. Example 1 below shows two possible + transforms for ESP and a single transform for AH. Example 2 below + + + +Maughan, et. al. Standards Track [Page 47] + +RFC 2408 ISAKMP November 1998 + + + shows one transform for AH AND one transform for ESP OR two + transforms for ESP alone. Note that the Next Payload field of the + Transform payload points to another Transform payload or 0. The + Proposal payload delineates the different proposals. + + When responding to a Security Association payload, the responder MUST + send a Security Association payload with the selected proposal, which + may consist of multiple Proposal payloads and their associated + Transform payloads. Each of the Proposal payloads MUST contain a + single Transform payload associated with the Protocol. The responder + SHOULD retain the Proposal # field in the Proposal payload and the + Transform # field in each Transform payload of the selected Proposal. + Retention of Proposal and Transform numbers should speed the + initiator's protocol processing by negating the need to compare the + respondor's selection with every offered option. These values enable + the initiator to perform the comparison directly and quickly. The + initiator MUST verify that the Security Association payload received + from the responder matches one of the proposals sent initially. + +4.2.1 Security Association Establishment Examples + + This example shows a Proposal for a combined protection suite with + two different protocols. The first protocol is presented with two + transforms supported by the proposer. The second protocol is + presented with a single transform. An example for this proposal + might be: Protocol 1 is ESP with Transform 1 as 3DES and Transform 2 + as DES AND Protocol 2 is AH with Transform 1 as SHA. The responder + MUST select from the two transforms proposed for ESP. The resulting + protection suite will be either (1) 3DES AND SHA OR (2) DES AND SHA, + depending on which ESP transform was selected by the responder. Note + this example is shown using the Base Exchange. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + /+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Nonce ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +SA Pay ! Domain of Interpretation (DOI) ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! Situation ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Proposal ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Prop 1 ! Proposal # = 1! Protocol-Id ! SPI Size !# of Trans. = 2! +Prot 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SPI (variable) ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Transform! RESERVED ! Payload Length ! + + + +Maughan, et. al. Standards Track [Page 48] + +RFC 2408 ISAKMP November 1998 + + + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 1 ! Transform # 1 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 2 ! Transform # 2 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Prop 1 ! Proposal # = 1! Protocol ID ! SPI Size !# of Trans. = 1! +Prot 2 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SPI (variable) ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 1 ! Transform # 1 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + \+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + This second example shows a Proposal for two different protection + suites. The SA Payload was omitted for space reasons. The first + protection suite is presented with one transform for the first + protocol and one transform for the second protocol. The second + protection suite is presented with two transforms for a single + protocol. An example for this proposal might be: Proposal 1 with + Protocol 1 as AH with Transform 1 as MD5 AND Protocol 2 as ESP with + Transform 1 as 3DES. This is followed by Proposal 2 with Protocol 1 + as ESP with Transform 1 as DES and Transform 2 as 3DES. The responder + MUST select from the two different proposals. If the second Proposal + is selected, the responder MUST select from the two transforms for + ESP. The resulting protection suite will be either (1) MD5 AND 3DES + OR the selection between (2) DES OR (3) 3DES. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + /+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Proposal ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Prop 1 ! Proposal # = 1! Protocol ID ! SPI Size !# of Trans. = 1! +Prot 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SPI (variable) ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + + + +Maughan, et. al. Standards Track [Page 49] + +RFC 2408 ISAKMP November 1998 + + + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 1 ! Transform # 1 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Proposal ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Prop 1 ! Proposal # = 1! Protocol ID ! SPI Size !# of Trans. = 1! +Prot 2 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SPI (variable) ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 1 ! Transform # 1 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Prop 2 ! Proposal # = 2! Protocol ID ! SPI Size !# of Trans. = 2! +Prot 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SPI (variable) ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = Transform! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 1 ! Transform # 1 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + >+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + / ! NP = 0 ! RESERVED ! Payload Length ! + / +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ +Tran 2 ! Transform # 2 ! Transform ID ! RESERVED2 ! + \ +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! SA Attributes ! + \+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + +4.3 Security Association Modification + + Security Association modification within ISAKMP is accomplished by + creating a new SA and initiating communications using that new SA. + Deletion of the old SA can be done anytime after the new SA is + established. Deletion of the old SA is dependent on local security + policy. Modification of SAs by using a "Create New SA followed by + Delete Old SA" method is done to avoid potential vulnerabilities in + synchronizing modification of existing SA attributes. The procedure + for creating new SAs is outlined in section 4.2. The procedure for + deleting SAs is outlined in section 5.15. + + + + +Maughan, et. al. Standards Track [Page 50] + +RFC 2408 ISAKMP November 1998 + + + Modification of an ISAKMP SA (phase 1 negotiation) follows the same + procedure as creation of an ISAKMP SA. There is no relationship + between the two SAs and the initiator and responder cookie pairs + SHOULD be different, as outlined in section 2.5.3. + + Modification of a Protocol SA (phase 2 negotiation) follows the same + procedure as creation of a Protocol SA. The creation of a new SA is + protected by the existing ISAKMP SA. There is no relationship between + the two Protocol SAs. A protocol implementation SHOULD begin using + the newly created SA for outbound traffic and SHOULD continue to + support incoming traffic on the old SA until it is deleted or until + traffic is received under the protection of the newly created SA. As + stated previously in this section, deletion of an old SA is then + dependent on local security policy. + +4.4 Base Exchange + + The Base Exchange is designed to allow the Key Exchange and + Authentication related information to be transmitted together. + Combining the Key Exchange and Authentication-related information + into one message reduces the number of round-trips at the expense of + not providing identity protection. Identity protection is not + provided because identities are exchanged before a common shared + secret has been established and, therefore, encryption of the + identities is not possible. The following diagram shows the messages + with the possible payloads sent in each message and notes for an + example of the Base Exchange. + + BASE EXCHANGE + + # Initiator Direction Responder NOTE +(1) HDR; SA; NONCE => Begin ISAKMP-SA or Proxy negotiation + +(2) <= HDR; SA; NONCE + Basic SA agreed upon +(3) HDR; KE; => + IDii; AUTH Key Generated (by responder) + Initiator Identity Verified by + Responder +(4) <= HDR; KE; + IDir; AUTH + Responder Identity Verified by + Initiator Key Generated (by + initiator) SA established + + + + + + + +Maughan, et. al. Standards Track [Page 51] + +RFC 2408 ISAKMP November 1998 + + + In the first message (1), the initiator generates a proposal it + considers adequate to protect traffic for the given situation. The + Security Association, Proposal, and Transform payloads are included + in the Security Association payload (for notation purposes). Random + information which is used to guarantee liveness and protect against + replay attacks is also transmitted. Random information provided by + both parties SHOULD be used by the authentication mechanism to + provide shared proof of participation in the exchange. + + In the second message (2), the responder indicates the protection + suite it has accepted with the Security Association, Proposal, and + Transform payloads. Again, random information which is used to + guarantee liveness and protect against replay attacks is also + transmitted. Random information provided by both parties SHOULD be + used by the authentication mechanism to provide shared proof of + participation in the exchange. Local security policy dictates the + action of the responder if no proposed protection suite is accepted. + One possible action is the transmission of a Notify payload as part + of an Informational Exchange. + + In the third (3) and fourth (4) messages, the initiator and + responder, respectively, exchange keying material used to arrive at a + common shared secret and identification information. This + information is transmitted under the protection of the agreed upon + authentication function. Local security policy dictates the action + if an error occurs during these messages. One possible action is the + transmission of a Notify payload as part of an Informational + Exchange. + +4.5 Identity Protection Exchange + + The Identity Protection Exchange is designed to separate the Key + Exchange information from the Identity and Authentication related + information. Separating the Key Exchange from the Identity and + Authentication related information provides protection of the + communicating identities at the expense of two additional messages. + Identities are exchanged under the protection of a previously + established common shared secret. The following diagram shows the + messages with the possible payloads sent in each message and notes + for an example of the Identity Protection Exchange. + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 52] + +RFC 2408 ISAKMP November 1998 + + + IDENTITY PROTECTION EXCHANGE + + # Initiator Direction Responder NOTE +(1) HDR; SA => Begin ISAKMP-SA or + Proxy negotiation +(2) <= HDR; SA + Basic SA agreed upon +(3) HDR; KE; NONCE => +(4) <= HDR; KE; NONCE + Key Generated (by + Initiator and + Responder) +(5) HDR*; IDii; AUTH => + Initiator Identity + Verified by + Responder +(6) <= HDR*; IDir; AUTH + Responder Identity + Verified by + Initiator + SA established + + In the first message (1), the initiator generates a proposal it + considers adequate to protect traffic for the given situation. The + Security Association, Proposal, and Transform payloads are included + in the Security Association payload (for notation purposes). + + In the second message (2), the responder indicates the protection + suite it has accepted with the Security Association, Proposal, and + Transform payloads. Local security policy dictates the action of the + responder if no proposed protection suite is accepted. One possible + action is the transmission of a Notify payload as part of an + Informational Exchange. + + In the third (3) and fourth (4) messages, the initiator and + responder, respectively, exchange keying material used to arrive at a + common shared secret and random information which is used to + guarantee liveness and protect against replay attacks. Random + information provided by both parties SHOULD be used by the + authentication mechanism to provide shared proof of participation in + the exchange. Local security policy dictates the action if an error + occurs during these messages. One possible action is the + transmission of a Notify payload as part of an Informational + Exchange. + + In the fifth (5) and sixth (6) messages, the initiator and responder, + respectively, exchange identification information and the results of + the agreed upon authentication function. This information is + + + +Maughan, et. al. Standards Track [Page 53] + +RFC 2408 ISAKMP November 1998 + + + transmitted under the protection of the common shared secret. Local + security policy dictates the action if an error occurs during these + messages. One possible action is the transmission of a Notify + payload as part of an Informational Exchange. + +4.6 Authentication Only Exchange + + The Authentication Only Exchange is designed to allow only + Authentication related information to be transmitted. The benefit of + this exchange is the ability to perform only authentication without + the computational expense of computing keys. Using this exchange + during negotiation, none of the transmitted information will be + encrypted. However, the information may be encrypted in other + places. For example, if encryption is negotiated during the first + phase of a negotiation and the authentication only exchange is used + in the second phase of a negotiation, then the authentication only + exchange will be encrypted by the ISAKMP SAs negotiated in the first + phase. The following diagram shows the messages with possible + payloads sent in each message and notes for an example of the + Authentication Only Exchange. + + AUTHENTICATION ONLY EXCHANGE + + # Initiator Direction Responder NOTE +(1) HDR; SA; NONCE => Begin ISAKMP-SA or + Proxy negotiation +(2) <= HDR; SA; NONCE; + IDir; AUTH + Basic SA agreed upon + Responder Identity + Verified by Initiator +(3) HDR; IDii; AUTH => + Initiator Identity + Verified by Responder + SA established + + In the first message (1), the initiator generates a proposal it + considers adequate to protect traffic for the given situation. The + Security Association, Proposal, and Transform payloads are included + in the Security Association payload (for notation purposes). Random + information which is used to guarantee liveness and protect against + replay attacks is also transmitted. Random information provided by + both parties SHOULD be used by the authentication mechanism to + provide shared proof of participation in the exchange. + + In the second message (2), the responder indicates the protection + suite it has accepted with the Security Association, Proposal, and + Transform payloads. Again, random information which is used to + + + +Maughan, et. al. Standards Track [Page 54] + +RFC 2408 ISAKMP November 1998 + + + guarantee liveness and protect against replay attacks is also + transmitted. Random information provided by both parties SHOULD be + used by the authentication mechanism to provide shared proof of + participation in the exchange. Additionally, the responder transmits + identification information. All of this information is transmitted + under the protection of the agreed upon authentication function. + Local security policy dictates the action of the responder if no + proposed protection suite is accepted. One possible action is the + transmission of a Notify payload as part of an Informational + Exchange. + + In the third message (3), the initiator transmits identification + information. This information is transmitted under the protection of + the agreed upon authentication function. Local security policy + dictates the action if an error occurs during these messages. One + possible action is the transmission of a Notify payload as part of an + Informational Exchange. + +4.7 Aggressive Exchange + + The Aggressive Exchange is designed to allow the Security + Association, Key Exchange and Authentication related payloads to be + transmitted together. Combining the Security Association, Key + Exchange, and Authentication-related information into one message + reduces the number of round-trips at the expense of not providing + identity protection. Identity protection is not provided because + identities are exchanged before a common shared secret has been + established and, therefore, encryption of the identities is not + possible. Additionally, the Aggressive Exchange is attempting to + establish all security relevant information in a single exchange. + The following diagram shows the messages with possible payloads sent + in each message and notes for an example of the Aggressive Exchange. + + + + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 55] + +RFC 2408 ISAKMP November 1998 + + + AGGRESSIVE EXCHANGE + + # Initiator Direction Responder NOTE +(1) HDR; SA; KE; => Begin ISAKMP-SA or + Proxy negotiation + NONCE; IDii and Key Exchange + +(2) <= HDR; SA; KE; + NONCE; IDir; AUTH + Initiator Identity + Verified by Responder + Key Generated + Basic SA agreed upon +(3) HDR*; AUTH => + Responder Identity + Verified by Initiator + SA established + + In the first message (1), the initiator generates a proposal it + considers adequate to protect traffic for the given situation. The + Security Association, Proposal, and Transform payloads are included + in the Security Association payload (for notation purposes). There + can be only one Proposal and one Transform offered (i.e. no choices) + in order for the aggressive exchange to work. Keying material used + to arrive at a common shared secret and random information which is + used to guarantee liveness and protect against replay attacks are + also transmitted. Random information provided by both parties SHOULD + be used by the authentication mechanism to provide shared proof of + participation in the exchange. Additionally, the initiator transmits + identification information. + + In the second message (2), the responder indicates the protection + suite it has accepted with the Security Association, Proposal, and + Transform payloads. Keying material used to arrive at a common + shared secret and random information which is used to guarantee + liveness and protect against replay attacks is also transmitted. + Random information provided by both parties SHOULD be used by the + authentication mechanism to provide shared proof of participation in + the exchange. Additionally, the responder transmits identification + information. All of this information is transmitted under the + protection of the agreed upon authentication function. Local + security policy dictates the action of the responder if no proposed + protection suite is accepted. One possible action is the + transmission of a Notify payload as part of an Informational + Exchange. + + + + + + +Maughan, et. al. Standards Track [Page 56] + +RFC 2408 ISAKMP November 1998 + + + In the third (3) message, the initiator transmits the results of the + agreed upon authentication function. This information is transmitted + under the protection of the common shared secret. Local security + policy dictates the action if an error occurs during these messages. + One possible action is the transmission of a Notify payload as part + of an Informational Exchange. + +4.8 Informational Exchange + + The Informational Exchange is designed as a one-way transmittal of + information that can be used for security association management. + The following diagram shows the messages with possible payloads sent + in each message and notes for an example of the Informational + Exchange. + + INFORMATIONAL EXCHANGE + + # Initiator Direction Responder NOTE + (1) HDR*; N/D => Error Notification or Deletion + + In the first message (1), the initiator or responder transmits an + ISAKMP Notify or Delete payload. + + If the Informational Exchange occurs prior to the exchange of keying + meterial during an ISAKMP Phase 1 negotiation, there will be no + protection provided for the Informational Exchange. Once keying + material has been exchanged or an ISAKMP SA has been established, the + Informational Exchange MUST be transmitted under the protection + provided by the keying material or the ISAKMP SA. + + All exchanges are similar in that with the beginning of any exchange, + cryptographic synchronization MUST occur. The Informational Exchange + is an exchange and not an ISAKMP message. Thus, the generation of an + Message ID (MID) for an Informational Exchange SHOULD be independent + of IVs of other on-going communication. This will ensure + cryptographic synchronization is maintained for existing + communications and the Informational Exchange will be processed + correctly. The only exception to this is when the Commit Bit of the + ISAKMP Header is set. When the Commit Bit is set, the Message ID + field of the Informational Exchange MUST contain the Message ID of + the original ISAKMP Phase 2 SA negotiation, rather than a new Message + ID (MID). This is done to ensure that the Informational Exchange with + the CONNECTED Notify Message can be associated with the correct Phase + 2 SA. For a description of the Commit Bit, see section 3.1. + + + + + + + +Maughan, et. al. Standards Track [Page 57] + +RFC 2408 ISAKMP November 1998 + + +5 ISAKMP Payload Processing + + Section 3 describes the ISAKMP payloads. These payloads are used in + the exchanges described in section 4 and can be used in exchanges + defined for a specific DOI. This section describes the processing for + each of the payloads. This section suggests the logging of events to + a system audit file. This action is controlled by a system security + policy and is, therefore, only a suggested action. + +5.1 General Message Processing + + Every ISAKMP message has basic processing applied to insure protocol + reliability, and to minimize threats, such as denial of service and + replay attacks. All processing SHOULD include packet length checks + to insure the packet received is at least as long as the length given + in the ISAKMP Header. If the ISAKMP message length and the value in + the Payload Length field of the ISAKMP Header are not the same, then + the ISAKMP message MUST be rejected. The receiving entity (initiator + or responder) MUST do the following: + + 1. The event, UNEQUAL PAYLOAD LENGTHS, MAY be logged in the + appropriate system audit file. + + 2. An Informational Exchange with a Notification payload containing + the UNEQUAL-PAYLOAD-LENGTHS message type MAY be sent to the + transmitting entity. This action is dictated by a system + security policy. + + When transmitting an ISAKMP message, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Set a timer and initialize a retry counter. + + NOTE: Implementations MUST NOT use a fixed timer. Instead, + transmission timer values should be adjusted dynamically based on + measured round trip times. In addition, successive + retransmissions of the same packet should be separated by + increasingly longer time intervals (e.g., exponential backoff). + + 2. If the timer expires, the ISAKMP message is resent and the retry + counter is decremented. + + 3. If the retry counter reaches zero (0), the event, RETRY LIMIT + REACHED, MAY be logged in the appropriate system audit file. + + 4. The ISAKMP protocol machine clears all states and returns to + IDLE. + + + + +Maughan, et. al. Standards Track [Page 58] + +RFC 2408 ISAKMP November 1998 + + +5.2 ISAKMP Header Processing + + When creating an ISAKMP message, the transmitting entity (initiator + or responder) MUST do the following: + + 1. Create the respective cookie. See section 2.5.3 for details. + + 2. Determine the relevant security characteristics of the session + (i.e. DOI and situation). + + 3. Construct an ISAKMP Header with fields as described in section + 3.1. + + 4. Construct other ISAKMP payloads, depending on the exchange type. + + 5. Transmit the message to the destination host as described in + section5.1. + + When an ISAKMP message is received, the receiving entity (initiator + or responder) MUST do the following: + + 1. Verify the Initiator and Responder "cookies". If the cookie + validation fails, the message is discarded and the following + actions are taken: + + (a) The event, INVALID COOKIE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-COOKIE message type MAY be sent to + the transmitting entity. This action is dictated by a + system security policy. + + 2. Check the Next Payload field to confirm it is valid. If the Next + Payload field validation fails, the message is discarded and the + following actions are taken: + + (a) The event, INVALID NEXT PAYLOAD, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-PAYLOAD-TYPE message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + + 3. Check the Major and Minor Version fields to confirm they are + correct (see section 3.1). If the Version field validation + fails, the message is discarded and the following actions are + + + +Maughan, et. al. Standards Track [Page 59] + +RFC 2408 ISAKMP November 1998 + + + taken: + + (a) The event, INVALID ISAKMP VERSION, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-MAJOR-VERSION or INVALID-MINOR- + VERSION message type MAY be sent to the transmitting entity. + This action is dictated by a system security policy. + + 4. Check the Exchange Type field to confirm it is valid. If the + Exchange Type field validation fails, the message is discarded + and the following actions are taken: + + (a) The event, INVALID EXCHANGE TYPE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-EXCHANGE-TYPE message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 5. Check the Flags field to ensure it contains correct values. If + the Flags field validation fails, the message is discarded and + the following actions are taken: + + (a) The event, INVALID FLAGS, MAY be logged in the appropriate + systemaudit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-FLAGS message type MAY be sent to the + transmitting entity. This action is dictated by a system + security policy. + + 6. Check the Message ID field to ensure it contains correct values. + If the Message ID validation fails, the message is discarded and + the following actions are taken: + + (a) The event, INVALID MESSAGE ID, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-MESSAGE-ID message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + + 7. Processing of the ISAKMP message continues using the value in the + Next Payload field. + + + +Maughan, et. al. Standards Track [Page 60] + +RFC 2408 ISAKMP November 1998 + + +5.3 Generic Payload Header Processing + + When creating any of the ISAKMP Payloads described in sections 3.4 + through 3.15 a Generic Payload Header is placed at the beginning of + these payloads. When creating the Generic Payload Header, the + transmitting entity (initiator or responder) MUST do the following: + + 1. Place the value of the Next Payload in the Next Payload field. + These values are described in section 3.1. + + 2. Place the value zero (0) in the RESERVED field. + + 3. Place the length (in octets) of the payload in the Payload Length + field. + + 4. Construct the payloads as defined in the remainder of this + section. + + When any of the ISAKMP Payloads are received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Check the Next Payload field to confirm it is valid. If the Next + Payload field validation fails, the message is discarded and the + following actions are taken: + + (a) The event, INVALID NEXT PAYLOAD, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-PAYLOAD-TYPE message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + + 2. Verify the RESERVED field contains the value zero. If the value + in the RESERVED field is not zero, the message is discarded and + the following actions are taken: + + (a) The event, INVALID RESERVED FIELD, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the BAD-PROPOSAL-SYNTAX or PAYLOAD-MALFORMED + message type MAY be sent to the transmitting entity. This + action is dictated by a system security policy. + + 3. Process the remaining payloads as defined by the Next Payload + field. + + + + +Maughan, et. al. Standards Track [Page 61] + +RFC 2408 ISAKMP November 1998 + + +5.4 Security Association Payload Processing + + When creating a Security Association Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the Domain of Interpretation for which this negotiation + is being performed. + + 2. Determine the situation within the determined DOI for which this + negotiation is being performed. + + 3. Determine the proposal(s) and transform(s) within the situation. + These are described, respectively, in sections 3.5 and 3.6. + + 4. Construct a Security Association payload. + + 5. Transmit the message to the receiving entity as described in + section 5.1. + + When a Security Association payload is received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Determine if the Domain of Interpretation (DOI) is supported. If + the DOI determination fails, the message is discarded and the + following actions are taken: + + (a) The event, INVALID DOI, MAY be logged in the appropriate + system audit file. + + (b) An Informational Exchange with a Notification payload + containing the DOI-NOT-SUPPORTED message type MAY be sent to + the transmitting entity. This action is dictated by a + system security policy. + + 2. Determine if the given situation can be protected. If the + Situation determination fails, the message is discarded and the + following actions are taken: + + (a) The event, INVALID SITUATION, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the SITUATION-NOT-SUPPORTED message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 3. Process the remaining payloads (i.e. Proposal, Transform) of the + Security Association Payload. If the Security Association + + + +Maughan, et. al. Standards Track [Page 62] + +RFC 2408 ISAKMP November 1998 + + + Proposal (as described in sections 5.5 and 5.6) is not accepted, + then the following actions are taken: + + (a) The event, INVALID PROPOSAL, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the NO-PROPOSAL-CHOSEN message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + +5.5 Proposal Payload Processing + + When creating a Proposal Payload, the transmitting entity (initiator + or responder) MUST do the following: + + 1. Determine the Protocol for this proposal. + + 2. Determine the number of proposals to be offered for this protocol + and the number of transforms for each proposal. Transforms are + described in section 3.6. + + 3. Generate a unique pseudo-random SPI. + + 4. Construct a Proposal payload. + + When a Proposal payload is received, the receiving entity (initiator + or responder) MUST do the following: + + 1. Determine if the Protocol is supported. If the Protocol-ID field + is invalid, the payload is discarded and the following actions + are taken: + + (a) The event, INVALID PROTOCOL, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-PROTOCOL-ID message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + + 2. Determine if the SPI is valid. If the SPI is invalid, the + payload is discarded and the following actions are taken: + + (a) The event, INVALID SPI, MAY be logged in the appropriate + system audit file. + + + + + +Maughan, et. al. Standards Track [Page 63] + +RFC 2408 ISAKMP November 1998 + + + (b) An Informational Exchange with a Notification payload + containing the INVALID-SPI message type MAY be sent to the + transmitting entity. This action is dictated by a system + security policy. + + 3. Ensure the Proposals are presented according to the details given + in section 3.5 and 4.2. If the proposals are not formed + correctly, the following actions are taken: + + (a) Possible events, BAD PROPOSAL SYNTAX, INVALID PROPOSAL, are + logged in the appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the BAD-PROPOSAL-SYNTAX or PAYLOAD-MALFORMED + message type MAY be sent to the transmitting entity. This + action is dictated by a system security policy. + + 4. Process the Proposal and Transform payloads as defined by the + Next Payload field. Examples of processing these payloads are + given in section 4.2.1. + +5.6 Transform Payload Processing + + When creating a Transform Payload, the transmitting entity (initiator + or responder) MUST do the following: + + 1. Determine the Transform # for this transform. + + 2. Determine the number of transforms to be offered for this + proposal. Transforms are described in sections 3.6. + + 3. Construct a Transform payload. + + When a Transform payload is received, the receiving entity (initiator + or responder) MUST do the following: + + 1. Determine if the Transform is supported. If the Transform-ID + field contains an unknown or unsupported value, then that + Transform payload MUST be ignored and MUST NOT cause the + generation of an INVALID TRANSFORM event. If the Transform-ID + field is invalid, the payload is discarded and the following + actions are taken: + + (a) The event, INVALID TRANSFORM, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-TRANSFORM-ID message type MAY be sent + + + +Maughan, et. al. Standards Track [Page 64] + +RFC 2408 ISAKMP November 1998 + + + to the transmitting entity. This action is dictated by a + system security policy. + + 2. Ensure the Transforms are presented according to the details + given in section 3.6 and 4.2. If the transforms are not formed + correctly, the following actions are taken: + + (a) Possible events, BAD PROPOSAL SYNTAX, INVALID TRANSFORM, + INVALID ATTRIBUTES, are logged in the appropriate system + audit file. + + (b) An Informational Exchange with a Notification payload + containing the BAD-PROPOSAL-SYNTAX, PAYLOAD-MALFORMED or + ATTRIBUTES-NOT-SUPPORTED message type MAY be sent to the + transmitting entity. This action is dictated by a system + security policy. + + 3. Process the subsequent Transform and Proposal payloads as defined + by the Next Payload field. Examples of processing these payloads + are given in section 4.2.1. + +5.7 Key Exchange Payload Processing + + When creating a Key Exchange Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the Key Exchange to be used as defined by the DOI. + + 2. Determine the usage of the Key Exchange Data field as defined by + the DOI. + + 3. Construct a Key Exchange payload. + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When a Key Exchange payload is received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Determine if the Key Exchange is supported. If the Key Exchange + determination fails, the message is discarded and the following + actions are taken: + + (a) The event, INVALID KEY INFORMATION, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-KEY-INFORMATION message type MAY be + + + +Maughan, et. al. Standards Track [Page 65] + +RFC 2408 ISAKMP November 1998 + + + sent to the transmitting entity. This action is dictated by + a system security policy. + +5.8 Identification Payload Processing + + When creating an Identification Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the Identification information to be used as defined by + the DOI (and possibly the situation). + + 2. Determine the usage of the Identification Data field as defined + by the DOI. + + 3. Construct an Identification payload. + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When an Identification payload is received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Determine if the Identification Type is supported. This may be + based on the DOI and Situation. If the Identification + determination fails, the message is discarded and the following + actions are taken: + + (a) The event, INVALID ID INFORMATION, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-ID-INFORMATION message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + +5.9 Certificate Payload Processing + + When creating a Certificate Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the Certificate Encoding to be used. This may be + specified by the DOI. + + 2. Ensure the existence of a certificate formatted as defined by the + Certificate Encoding. + + 3. Construct a Certificate payload. + + + + +Maughan, et. al. Standards Track [Page 66] + +RFC 2408 ISAKMP November 1998 + + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When a Certificate payload is received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Determine if the Certificate Encoding is supported. If the + Certificate Encoding is not supported, the payload is discarded + and the following actions are taken: + + (a) The event, INVALID CERTIFICATE TYPE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-CERT-ENCODING message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 2. Process the Certificate Data field. If the Certificate Data is + invalid or improperly formatted, the payload is discarded and the + following actions are taken: + + (a) The event, INVALID CERTIFICATE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-CERTIFICATE message type MAY be sent + to the transmitting entity. This action is dictated by a + system security policy. + +5.10 Certificate Request Payload Processing + + When creating a Certificate Request Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the type of Certificate Encoding to be requested. This + may be specified by the DOI. + + 2. Determine the name of an acceptable Certificate Authority which + is to be requested (if applicable). + + 3. Construct a Certificate Request payload. + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When a Certificate Request payload is received, the receiving entity + (initiator or responder) MUST do the following: + + + +Maughan, et. al. Standards Track [Page 67] + +RFC 2408 ISAKMP November 1998 + + + 1. Determine if the Certificate Encoding is supported. If the + Certificate Encoding is invalid, the payload is discarded and the + following actions are taken: + + (a) The event, INVALID CERTIFICATE TYPE, MAY be logged in + the appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-CERT-ENCODING message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + If the Certificate Encoding is not supported, the payload is + discarded and the following actions are taken: + + (a) The event, CERTIFICATE TYPE UNSUPPORTED, MAY be logged in + the appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the CERT-TYPE-UNSUPPORTED message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 2. Determine if the Certificate Authority is supported for the + specified Certificate Encoding. If the Certificate Authority is + invalid or improperly formatted, the payload is discarded and the + following actions are taken: + + (a) The event, INVALID CERTIFICATE AUTHORITY, MAY be logged in + the appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-CERT-AUTHORITY message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 3. Process the Certificate Request. If a requested Certificate Type + with the specified Certificate Authority is not available, then + the payload is discarded and the following actions are taken: + + (a) The event, CERTIFICATE-UNAVAILABLE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the CERTIFICATE-UNAVAILABLE message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + + + +Maughan, et. al. Standards Track [Page 68] + +RFC 2408 ISAKMP November 1998 + + +5.11 Hash Payload Processing + + When creating a Hash Payload, the transmitting entity (initiator or + responder) MUST do the following: + + 1. Determine the Hash function to be used as defined by the SA + negotiation. + + 2. Determine the usage of the Hash Data field as defined by the DOI. + + 3. Construct a Hash payload. + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When a Hash payload is received, the receiving entity (initiator or + responder) MUST do the following: + + 1. Determine if the Hash is supported. If the Hash determination + fails, the message is discarded and the following actions are + taken: + + (a) The event, INVALID HASH INFORMATION, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-HASH-INFORMATION message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + + 2. Perform the Hash function as outlined in the DOI and/or Key + Exchange protocol documents. If the Hash function fails, the + message is discarded and the following actions are taken: + + (a) The event, INVALID HASH VALUE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the AUTHENTICATION-FAILED message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + +5.12 Signature Payload Processing + + When creating a Signature Payload, the transmitting entity (initiator + or responder) MUST do the following: + + + + + +Maughan, et. al. Standards Track [Page 69] + +RFC 2408 ISAKMP November 1998 + + + 1. Determine the Signature function to be used as defined by the SA + negotiation. + + 2. Determine the usage of the Signature Data field as defined by the + DOI. + + 3. Construct a Signature payload. + + 4. Transmit the message to the receiving entity as described in + section 5.1. + + When a Signature payload is received, the receiving entity (initiator + or responder) MUST do the following: + + 1. Determine if the Signature is supported. If the Signature + determination fails, the message is discarded and the following + actions are taken: + + (a) The event, INVALID SIGNATURE INFORMATION, MAY be logged in + the appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the INVALID-SIGNATURE message type MAY be sent to + the transmitting entity. This action is dictated by a + system security policy. + + 2. Perform the Signature function as outlined in the DOI and/or Key + Exchange protocol documents. If the Signature function fails, + the message is discarded and the following actions are taken: + + (a) The event, INVALID SIGNATURE VALUE, MAY be logged in the + appropriate system audit file. + + (b) An Informational Exchange with a Notification payload + containing the AUTHENTICATION-FAILED message type MAY be + sent to the transmitting entity. This action is dictated by + a system security policy. + +5.13 Nonce Payload Processing + + When creating a Nonce Payload, the transmitting entity (initiator or + responder) MUST do the following: + + 1. Create a unique random value to be used as a nonce. + + 2. Construct a Nonce payload. + + + + + +Maughan, et. al. Standards Track [Page 70] + +RFC 2408 ISAKMP November 1998 + + + 3. Transmit the message to the receiving entity as described in + section 5.1. + + When a Nonce payload is received, the receiving entity (initiator or + responder) MUST do the following: + + 1. There are no specific procedures for handling Nonce payloads. + The procedures are defined by the exchange types (and possibly + the DOI and Key Exchange descriptions). + +5.14 Notification Payload Processing + + During communications it is possible that errors may occur. The + Informational Exchange with a Notify Payload provides a controlled + method of informing a peer entity that errors have occurred during + protocol processing. It is RECOMMENDED that Notify Payloads be sent + in a separate Informational Exchange rather than appending a Notify + Payload to an existing exchange. + + When creating a Notification Payload, the transmitting entity + (initiator or responder) MUST do the following: + + 1. Determine the DOI for this Notification. + + 2. Determine the Protocol-ID for this Notification. + + 3. Determine the SPI size based on the Protocol-ID field. This + field is necessary because different security protocols have + different SPI sizes. For example, ISAKMP combines the Initiator + and Responder cookie pair (16 octets) as a SPI, while ESP and AH + have 4 octet SPIs. + + 4. Determine the Notify Message Type based on the error or status + message desired. + + 5. Determine the SPI which is associated with this notification. + + 6. Determine if additional Notification Data is to be included. + This is additional information specified by the DOI. + + 7. Construct a Notification payload. + + 8. Transmit the message to the receiving entity as described in + section 5.1. + + Because the Informational Exchange with a Notification payload is a + unidirectional message a retransmission will not be performed. The + local security policy will dictate the procedures for continuing. + + + +Maughan, et. al. Standards Track [Page 71] + +RFC 2408 ISAKMP November 1998 + + + However, we RECOMMEND that a NOTIFICATION PAYLOAD ERROR event be + logged in the appropriate system audit file by the receiving entity. + + If the Informational Exchange occurs prior to the exchange of keying + material during an ISAKMP Phase 1 negotiation there will be no + protection provided for the Informational Exchange. Once the keying + material has been exchanged or the ISAKMP SA has been established, + the Informational Exchange MUST be transmitted under the protection + provided by the keying material or the ISAKMP SA. + + When a Notification payload is received, the receiving entity + (initiator or responder) MUST do the following: + + 1. Determine if the Informational Exchange has any protection + applied to it by checking the Encryption Bit and the + Authentication Only Bit in the ISAKMP Header. If the Encryption + Bit is set, i.e. the Informational Exchange is encrypted, then + the message MUST be decrypted using the (in-progress or + completed) ISAKMP SA. Once the decryption is complete the + processing can continue as described below. If the + Authentication Only Bit is set, then the message MUST be + authenticated using the (in-progress or completed) ISAKMP SA. + Once the authentication is completed, the processing can continue + as described below. If the Informational Exchange is not + encrypted or authentication, the payload processing can continue + as described below. + + 2. Determine if the Domain of Interpretation (DOI) is supported. If + the DOI determination fails, the payload is discarded and the + following action is taken: + + (a) The event, INVALID DOI, MAY be logged in the appropriate + system audit file. + + 3. Determine if the Protocol-Id is supported. If the Protocol-Id + determination fails, the payload is discarded and the following + action is taken: + + (a) The event, INVALID PROTOCOL-ID, MAY be logged in the + appropriate system audit file. + + 4. Determine if the SPI is valid. If the SPI is invalid, the + payload is discarded and the following action is taken: + + (a) The event, INVALID SPI, MAY be logged in the appropriate + system audit file. + + + + + +Maughan, et. al. Standards Track [Page 72] + +RFC 2408 ISAKMP November 1998 + + + 5. Determine if the Notify Message Type is valid. If the Notify + Message Type is invalid, the payload is discarded and the + following action is taken: + + (a) The event, INVALID MESSAGE TYPE, MAY be logged in the + appropriate system audit file. + + 6. Process the Notification payload, including additional + Notification Data, and take appropriate action, according to + local security policy. + +5.15 Delete Payload Processing + + During communications it is possible that hosts may be compromised or + that information may be intercepted during transmission. Determining + whether this has occurred is not an easy task and is outside the + scope of this memo. However, if it is discovered that transmissions + are being compromised, then it is necessary to establish a new SA and + delete the current SA. + + The Informational Exchange with a Delete Payload provides a + controlled method of informing a peer entity that the transmitting + entity has deleted the SA(s). Deletion of Security Associations MUST + always be performed under the protection of an ISAKMP SA. The + receiving entity SHOULD clean up its local SA database. However, + upon receipt of a Delete message the SAs listed in the Security + Parameter Index (SPI) field of the Delete payload cannot be used with + the transmitting entity. The SA Establishment procedure must be + invoked to re-establish secure communications. + + When creating a Delete Payload, the transmitting entity (initiator or + responder) MUST do the following: + + 1. Determine the DOI for this Deletion. + + 2. Determine the Protocol-ID for this Deletion. + + 3. Determine the SPI size based on the Protocol-ID field. This + field is necessary because different security protocols have + different SPI sizes. For example, ISAKMP combines the Initiator + and Responder cookie pair (16 octets) as a SPI, while ESP and AH + have 4 octet SPIs. + + 4. Determine the # of SPIs to be deleted for this protocol. + + 5. Determine the SPI(s) which is (are) associated with this + deletion. + + + + +Maughan, et. al. Standards Track [Page 73] + +RFC 2408 ISAKMP November 1998 + + + 6. Construct a Delete payload. + + 7. Transmit the message to the receiving entity as described in + section 5.1. + + Because the Informational Exchange with a Delete payload is a + unidirectional message a retransmission will not be performed. The + local security policy will dictate the procedures for continuing. + However, we RECOMMEND that a DELETE PAYLOAD ERROR event be logged in + the appropriate system audit file by the receiving entity. + + As described above, the Informational Exchange with a Delete payload + MUST be transmitted under the protection provided by an ISAKMP SA. + + When a Delete payload is received, the receiving entity (initiator or + responder) MUST do the following: + + 1. Because the Informational Exchange is protected by some security + service (e.g. authentication for an Auth-Only SA, encryption for + other exchanges), the message MUST have these security services + applied using the ISAKMP SA. Once the security service processing + is complete the processing can continue as described below. Any + errors that occur during the security service processing will be + evident when checking information in the Delete payload. The + local security policy SHOULD dictate any action to be taken as a + result of security service processing errors. + + 2. Determine if the Domain of Interpretation (DOI) is supported. If + the DOI determination fails, the payload is discarded and the + following action is taken: + + (a) The event, INVALID DOI, MAY be logged in the appropriate + system audit file. + + 3. Determine if the Protocol-Id is supported. If the Protocol-Id + determination fails, the payload is discarded and the following + action is taken: + + (a) The event, INVALID PROTOCOL-ID, MAY be logged in the + appropriate system audit file. + + 4. Determine if the SPI is valid for each SPI included in the Delete + payload. For each SPI that is invalid, the following action is + taken: + + (a) The event, INVALID SPI, MAY be logged in the appropriate + system audit file. + + + + +Maughan, et. al. Standards Track [Page 74] + +RFC 2408 ISAKMP November 1998 + + + 5. Process the Delete payload and take appropriate action, according + to local security policy. As described above, one appropriate + action SHOULD include cleaning up the local SA database. + +6 Conclusions + + The Internet Security Association and Key Management Protocol + (ISAKMP) is a well designed protocol aimed at the Internet of the + future. The massive growth of the Internet will lead to great + diversity in network utilization, communications, security + requirements, and security mechanisms. ISAKMP contains all the + features that will be needed for this dynamic and expanding + communications environment. + + ISAKMP's Security Association (SA) feature coupled with + authentication and key establishment provides the security and + flexibility that will be needed for future growth and diversity. + This security diversity of multiple key exchange techniques, + encryption algorithms, authentication mechanisms, security services, + and security attributes will allow users to select the appropriate + security for their network, communications, and security needs. The + SA feature allows users to specify and negotiate security + requirements with other users. An additional benefit of supporting + multiple techniques in a single protocol is that as new techniques + are developed they can easily be added to the protocol. This + provides a path for the growth of Internet security services. ISAKMP + supports both publicly or privately defined SAs, making it ideal for + government, commercial, and private communications. + + ISAKMP provides the ability to establish SAs for multiple security + protocols and applications. These protocols and applications may be + session-oriented or sessionless. Having one SA establishment + protocol that supports multiple security protocols eliminates the + need for multiple, nearly identical authentication, key exchange and + SA establishment protocols when more than one security protocol is in + use or desired. Just as IP has provided the common networking layer + for the Internet, a common security establishment protocol is needed + if security is to become a reality on the Internet. ISAKMP provides + the common base that allows all other security protocols to + interoperate. + + ISAKMP follows good security design principles. It is not coupled to + other insecure transport protocols, therefore it is not vulnerable or + weakened by attacks on other protocols. Also, when more secure + transport protocols are developed, ISAKMP can be easily migrated to + them. ISAKMP also provides protection against protocol related + attacks. This protection provides the assurance that the SAs and + keys established are with the desired party and not with an attacker. + + + +Maughan, et. al. Standards Track [Page 75] + +RFC 2408 ISAKMP November 1998 + + + ISAKMP also follows good protocol design principles. Protocol + specific information only is in the protocol header, following the + design principles of IPv6. The data transported by the protocol is + separated into functional payloads. As the Internet grows and + evolves, new payloads to support new security functionality can be + added without modifying the entire protocol. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 76] + +RFC 2408 ISAKMP November 1998 + + +A ISAKMP Security Association Attributes + +A.1 Background/Rationale + + As detailed in previous sections, ISAKMP is designed to provide a + flexible and extensible framework for establishing and managing + Security Associations and cryptographic keys. The framework provided + by ISAKMP consists of header and payload definitions, exchange types + for guiding message and payload exchanges, and general processing + guidelines. ISAKMP does not define the mechanisms that will be used + to establish and manage Security Associations and cryptographic keys + in an authenticated and confidential manner. The definition of + mechanisms and their application is the purview of individual Domains + of Interpretation (DOIs). + + This section describes the ISAKMP values for the Internet IP Security + DOI, supported security protocols, and identification values for + ISAKMP Phase 1 negotiations. The Internet IP Security DOI is + MANDATORY to implement for IP Security. [Oakley] and [IKE] describe, + in detail, the mechanisms and their application for establishing and + managing Security Associations and cryptographic keys for IP + Security. + +A.2 Internet IP Security DOI Assigned Value + + As described in [IPDOI], the Internet IP Security DOI Assigned Number + is one (1). + +A.3 Supported Security Protocols + + Values for supported security protocols are specified in the most + recent "Assigned Numbers" RFC [STD-2]. Presented in the following + table are the values for the security protocols supported by ISAKMP + for the Internet IP Security DOI. + + + Protocol Assigned Value + RESERVED 0 + ISAKMP 1 + + All DOIs MUST reserve ISAKMP with a Protocol-ID of 1. All other + security protocols within that DOI will be numbered accordingly. + + Security protocol values 2-15359 are reserved to IANA for future use. + Values 15360-16383 are permanently reserved for private use amongst + mutually consenting implementations. Such private use values are + unlikely to be interoperable across different implementations. + + + + +Maughan, et. al. Standards Track [Page 77] + +RFC 2408 ISAKMP November 1998 + + +A.4 ISAKMP Identification Type Values + + The following table lists the assigned values for the Identification + Type field found in the Identification payload during a generic Phase + 1 exchange, which is not for a specific protocol. + + + ID Type Value + ID_IPV4_ADDR 0 + ID_IPV4_ADDR_SUBNET 1 + ID_IPV6_ADDR 2 + ID_IPV6_ADDR_SUBNET 3 + +A.4.1 ID_IPV4_ADDR + + The ID_IPV4_ADDR type specifies a single four (4) octet IPv4 address. + +A.4.2 ID_IPV4_ADDR_SUBNET + + The ID_IPV4_ADDR_SUBNET type specifies a range of IPv4 addresses, + represented by two four (4) octet values. The first value is an IPv4 + address. The second is an IPv4 network mask. Note that ones (1s) in + the network mask indicate that the corresponding bit in the address + is fixed, while zeros (0s) indicate a "wildcard" bit. + +A.4.3 ID_IPV6_ADDR + + The ID_IPV6_ADDR type specifies a single sixteen (16) octet IPv6 + address. + +A.4.4 ID_IPV6_ADDR_SUBNET + + The ID_IPV6_ADDR_SUBNET type specifies a range of IPv6 addresses, + represented by two sixteen (16) octet values. The first value is an + IPv6 address. The second is an IPv6 network mask. Note that ones + (1s) in the network mask indicate that the corresponding bit in the + address is fixed, while zeros (0s) indicate a "wildcard" bit. + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 78] + +RFC 2408 ISAKMP November 1998 + + +B Defining a new Domain of Interpretation + + The Internet DOI may be sufficient to meet the security requirements + of a large portion of the internet community. However, some groups + may have a need to customize some aspect of a DOI, perhaps to add a + different set of cryptographic algorithms, or perhaps because they + want to make their security-relevant decisions based on something + other than a host id or user id. Also, a particular group may have a + need for a new exchange type, for example to support key management + for multicast groups. + + This section discusses guidelines for defining a new DOI. The full + specification for the Internet DOI can be found in [IPDOI]. + + Defining a new DOI is likely to be a time-consuming process. If at + all possible, it is recommended that the designer begin with an + existing DOI and customize only the parts that are unacceptable. + + If a designer chooses to start from scratch, the following MUST be + defined: + + o A "situation": the set of information that will be used to + determine the required security services. + + o The set of security policies that must be supported. + + o A scheme for naming security-relevant information, including + encryption algorithms, key exchange algorithms, etc. + + o A syntax for the specification of proposed security services, + attributes, and certificate authorities. + + o The specific formats of the various payload contents. + + o Additional exchange types, if required. + +B.1 Situation + + The situation is the basis for deciding how to protect a + communications channel. It must contain all of the data that will be + used to determine the types and strengths of protections applied in + an SA. For example, a US Department of Defense DOI would probably use + unpublished algorithms and have additional special attributes to + negotiate. These additional security attributes would be included in + the situation. + + + + + + +Maughan, et. al. Standards Track [Page 79] + +RFC 2408 ISAKMP November 1998 + + +B.2 Security Policies + + Security policies define how various types of information must be + categorized and protected. The DOI must define the set of security + policies supported, because both parties in a negotiation must trust + that the other party understands a situation, and will protect + information appropriately, both in transit and in storage. In a + corporate setting, for example, both parties in a negotiation must + agree to the meaning of the term "proprietary information" before + they can negotiate how to protect it. + + Note that including the required security policies in the DOI only + specifies that the participating hosts understand and implement those + policies in a full system context. + +B.3 Naming Schemes + + Any DOI must define a consistent way to name cryptographic + algorithms, certificate authorities, etc. This can usually be done + by using IANA naming conventions, perhaps with some private + extensions. + +B.4 Syntax for Specifying Security Services + + In addition to simply specifying how to name entities, the DOI must + also specify the format for complete proposals of how to protect + traffic under a given situation. + +B.5 Payload Specification + + The DOI must specify the format of each of the payload types. For + several of the payload types, ISAKMP has included fields that would + have to be present across all DOI (such as a certificate authority in + the certificate payload, or a key exchange identifier in the key + exchange payload). + +B.6 Defining new Exchange Types + + If the basic exchange types are inadequate to meet the requirements + within a DOI, a designer can define up to thirteen extra exchange + types per DOI. The designer creates a new exchange type by choosing + an unused exchange type value, and defining a sequence of messages + composed of strings of the ISAKMP payload types. + + Note that any new exchange types must be rigorously analyzed for + vulnerabilities. Since this is an expensive and imprecise + undertaking, a new exchange type should only be created when + absolutely necessary. + + + +Maughan, et. al. Standards Track [Page 80] + +RFC 2408 ISAKMP November 1998 + + +Security Considerations + + Cryptographic analysis techniques are improving at a steady pace. + The continuing improvement in processing power makes once + computationally prohibitive cryptographic attacks more realistic. + New cryptographic algorithms and public key generation techniques are + also being developed at a steady pace. New security services and + mechanisms are being developed at an accelerated pace. A consistent + method of choosing from a variety of security services and mechanisms + and to exchange attributes required by the mechanisms is important to + security in the complex structure of the Internet. However, a system + that locks itself into a single cryptographic algorithm, key exchange + technique, or security mechanism will become increasingly vulnerable + as time passes. + + UDP is an unreliable datagram protocol and therefore its use in + ISAKMP introduces a number of security considerations. Since UDP is + unreliable, but a key management protocol must be reliable, the + reliability is built into ISAKMP. While ISAKMP utilizes UDP as its + transport mechanism, it doesn't rely on any UDP information (e.g. + checksum, length) for its processing. + + Another issue that must be considered in the development of ISAKMP is + the effect of firewalls on the protocol. Many firewalls filter out + all UDP packets, making reliance on UDP questionable in certain + environments. + + A number of very important security considerations are presented in + [SEC-ARCH]. One bears repeating. Once a private session key is + created, it must be safely stored. Failure to properly protect the + private key from access both internal and external to the system + completely nullifies any protection provided by the IP Security + services. + +IANA Considerations + + This document contains many "magic" numbers to be maintained by the + IANA. This section explains the criteria to be used by the IANA to + assign additional numbers in each of these lists. + +Domain of Interpretation + + The Domain of Interpretation (DOI) is a 32-bit field which identifies + the domain under which the security association negotiation is taking + place. Requests for assignments of new DOIs must be accompanied by a + standards-track RFC which describes the specific domain. + + + + + +Maughan, et. al. Standards Track [Page 81] + +RFC 2408 ISAKMP November 1998 + + +Supported Security Protocols + + ISAKMP is designed to provide security association negotiation and + key management for many security protocols. Requests for identifiers + for additional security protocols must be accompanied by a + standards-track RFC which describes the security protocol and its + relationship to ISAKMP. + +Acknowledgements + + Dan Harkins, Dave Carrel, and Derrell Piper of Cisco Systems provided + design assistance with the protocol and coordination for the [IKE] + and [IPDOI] documents. + + Hilarie Orman, via the Oakley key exchange protocol, has + significantly influenced the design of ISAKMP. + + Marsha Gross, Bill Kutz, Mike Oehler, Pete Sell, and Ruth Taylor + provided significant input and review to this document. + + Scott Carlson ported the TIS DNSSEC prototype to FreeBSD for use with + the ISAKMP prototype. + + Jeff Turner and Steve Smalley contributed to the prototype + development and integration with ESP and AH. + + Mike Oehler and Pete Sell performed interoperability testing with + other ISAKMP implementors. + + Thanks to Carl Muckenhirn of SPARTA, Inc. for his assistance with + LaTeX. + +References + + [ANSI] ANSI, X9.42: Public Key Cryptography for the Financial + Services Industry -- Establishment of Symmetric Algorithm + Keys Using Diffie-Hellman, Working Draft, April 19, 1996. + + [BC] Ballardie, A., and J. Crowcroft, Multicast-specific + Security Threats and Countermeasures, Proceedings of 1995 + ISOC Symposium on Networks & Distributed Systems Security, + pp. 17-30, Internet Society, San Diego, CA, February 1995. + + [Berge] Berge, N., "UNINETT PCA Policy Statements", RFC 1875, + December 1995. + + + + + + +Maughan, et. al. Standards Track [Page 82] + +RFC 2408 ISAKMP November 1998 + + + [CW87] Clark, D.D. and D.R. Wilson, A Comparison of Commercial + and Military Computer Security Policies, Proceedings of + the IEEE Symposium on Security & Privacy, Oakland, CA, + 1987, pp. 184-193. + + [DNSSEC] D. Eastlake III, Domain Name System Protocol Security + Extensions, Work in Progress. + + [DOW92] Diffie, W., M.Wiener, P. Van Oorschot, Authentication and + Authenticated Key Exchanges, Designs, Codes, and + Cryptography, 2, 107-125, Kluwer Academic Publishers, + 1992. + + [IAB] Bellovin, S., "Report of the IAB Security Architecture + Workshop", RFC 2316, April 1998. + + [IKE] Harkins, D., and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IPDOI] Piper, D., "The Internet IP Security Domain of + Interpretation for ISAKMP", RFC 2407, November 1998. + + [Karn] Karn, P., and B. Simpson, Photuris: Session Key + Management Protocol, Work in Progress. + + [Kent94] Steve Kent, IPSEC SMIB, e-mail to ipsec@ans.net, August + 10, 1994. + + [Oakley] Orman, H., "The Oakley Key Determination Protocol", RFC + 2412, November 1998. + + [RFC-1422] Kent, S., "Privacy Enhancement for Internet Electronic + Mail: Part II: Certificate-Based Key Management", RFC + 1422, February 1993. + + [RFC-1949] Ballardie, A., "Scalable Multicast Key Distribution", RFC + 1949, May 1996. + + [RFC-2093] Harney, H., and C. Muckenhirn, "Group Key Management + Protocol (GKMP) Specification", RFC 2093, July 1997. + + [RFC-2094] Harney, H., and C. Muckenhirn, "Group Key Management + Protocol (GKMP) Architecture", RFC 2094, July 1997. + + [RFC-2119] Bradner, S., "Key Words for use in RFCs to Indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + + + + +Maughan, et. al. Standards Track [Page 83] + +RFC 2408 ISAKMP November 1998 + + + [Schneier] Bruce Schneier, Applied Cryptography - Protocols, + Algorithms, and Source Code in C (Second Edition), John + Wiley & Sons, Inc., 1996. + + [SEC-ARCH] Atkinson, R., and S. Kent, "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + [STD-2] Reynolds, J., and J. Postel, "Assigned Numbers", STD 2, RFC + 1700, October 1994. See also: + http://www.iana.org/numbers.html + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 84] + +RFC 2408 ISAKMP November 1998 + + +Authors' Addresses + + Douglas Maughan + National Security Agency + ATTN: R23 + 9800 Savage Road + Ft. Meade, MD. 20755-6000 + + Phone: 301-688-0847 + EMail:wdm@tycho.ncsc.mil + + + Mark Schneider + National Security Agency + ATTN: R23 + 9800 Savage Road + Ft. Meade, MD. 20755-6000 + + Phone: 301-688-0851 + EMail:mss@tycho.ncsc.mil + + + Mark Schertler + Securify, Inc. + 2415-B Charleston Road + Mountain View, CA 94043 + + Phone: 650-934-9303 + EMail:mjs@securify.com + + + Jeff Turner + RABA Technologies, Inc. + 10500 Little Patuxent Parkway + Columbia, MD. 21044 + + Phone: 410-715-9399 + EMail:jeff.turner@raba.com + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 85] + +RFC 2408 ISAKMP November 1998 + + +Full Copyright Statement + + Copyright (C) The Internet Society (1998). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + + + + + + + + + + + + + + + + + + + + + +Maughan, et. al. Standards Track [Page 86] + diff --git a/doc/ikev2/[RFC2409] - The Internet Key Exchange (IKE).txt b/doc/ikev2/[RFC2409] - The Internet Key Exchange (IKE).txt new file mode 100644 index 000000000..9d3e6f80e --- /dev/null +++ b/doc/ikev2/[RFC2409] - The Internet Key Exchange (IKE).txt @@ -0,0 +1,2299 @@ + + + + + + +Network Working Group D. Harkins +Request for Comments: 2409 D. Carrel +Category: Standards Track cisco Systems + November 1998 + + + The Internet Key Exchange (IKE) + +Status of this Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (1998). All Rights Reserved. + +Table Of Contents + + 1 Abstract........................................................ 2 + 2 Discussion...................................................... 2 + 3 Terms and Definitions........................................... 3 + 3.1 Requirements Terminology...................................... 3 + 3.2 Notation...................................................... 3 + 3.3 Perfect Forward Secrecty...................................... 5 + 3.4 Security Association.......................................... 5 + 4 Introduction.................................................... 5 + 5 Exchanges....................................................... 8 + 5.1 Authentication with Digital Signatures........................ 10 + 5.2 Authentication with Public Key Encryption..................... 12 + 5.3 A Revised method of Authentication with Public Key Encryption. 13 + 5.4 Authentication with a Pre-Shared Key.......................... 16 + 5.5 Quick Mode.................................................... 16 + 5.6 New Group Mode................................................ 20 + 5.7 ISAKMP Informational Exchanges................................ 20 + 6 Oakley Groups................................................... 21 + 6.1 First Oakley Group............................................ 21 + 6.2 Second Oakley Group........................................... 22 + 6.3 Third Oakley Group............................................ 22 + 6.4 Fourth Oakley Group........................................... 23 + 7 Payload Explosion of Complete Exchange.......................... 23 + 7.1 Phase 1 with Main Mode........................................ 23 + 7.2 Phase 2 with Quick Mode....................................... 25 + 8 Perfect Forward Secrecy Example................................. 27 + 9 Implementation Hints............................................ 27 + + + +Harkins & Carrel Standards Track [Page 1] + +RFC 2409 IKE November 1998 + + + 10 Security Considerations........................................ 28 + 11 IANA Considerations............................................ 30 + 12 Acknowledgments................................................ 31 + 13 References..................................................... 31 + Appendix A........................................................ 33 + Appendix B........................................................ 37 + Authors' Addresses................................................ 40 + Authors' Note..................................................... 40 + Full Copyright Statement.......................................... 41 + +1. Abstract + + ISAKMP ([MSST98]) provides a framework for authentication and key + exchange but does not define them. ISAKMP is designed to be key + exchange independant; that is, it is designed to support many + different key exchanges. + + Oakley ([Orm96]) describes a series of key exchanges-- called + "modes"-- and details the services provided by each (e.g. perfect + forward secrecy for keys, identity protection, and authentication). + + SKEME ([SKEME]) describes a versatile key exchange technique which + provides anonymity, repudiability, and quick key refreshment. + + This document describes a protocol using part of Oakley and part of + SKEME in conjunction with ISAKMP to obtain authenticated keying + material for use with ISAKMP, and for other security associations + such as AH and ESP for the IETF IPsec DOI. + +2. Discussion + + This memo describes a hybrid protocol. The purpose is to negotiate, + and provide authenticated keying material for, security associations + in a protected manner. + + Processes which implement this memo can be used for negotiating + virtual private networks (VPNs) and also for providing a remote user + from a remote site (whose IP address need not be known beforehand) + access to a secure host or network. + + Client negotiation is supported. Client mode is where the + negotiating parties are not the endpoints for which security + association negotiation is taking place. When used in client mode, + the identities of the end parties remain hidden. + + + + + + + +Harkins & Carrel Standards Track [Page 2] + +RFC 2409 IKE November 1998 + + + This does not implement the entire Oakley protocol, but only a subset + necessary to satisfy its goals. It does not claim conformance or + compliance with the entire Oakley protocol nor is it dependant in any + way on the Oakley protocol. + + Likewise, this does not implement the entire SKEME protocol, but only + the method of public key encryption for authentication and its + concept of fast re-keying using an exchange of nonces. This protocol + is not dependant in any way on the SKEME protocol. + +3. Terms and Definitions + +3.1 Requirements Terminology + + Keywords "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT" and + "MAY" that appear in this document are to be interpreted as described + in [Bra97]. + +3.2 Notation + + The following notation is used throughout this memo. + + HDR is an ISAKMP header whose exchange type is the mode. When + writen as HDR* it indicates payload encryption. + + SA is an SA negotiation payload with one or more proposals. An + initiator MAY provide multiple proposals for negotiation; a + responder MUST reply with only one. + +

_b indicates the body of payload

-- the ISAKMP generic + vpayload is not included. + + SAi_b is the entire body of the SA payload (minus the ISAKMP + generic header)-- i.e. the DOI, situation, all proposals and all + transforms offered by the Initiator. + + CKY-I and CKY-R are the Initiator's cookie and the Responder's + cookie, respectively, from the ISAKMP header. + + g^xi and g^xr are the Diffie-Hellman ([DH]) public values of the + initiator and responder respectively. + + g^xy is the Diffie-Hellman shared secret. + + KE is the key exchange payload which contains the public + information exchanged in a Diffie-Hellman exchange. There is no + particular encoding (e.g. a TLV) used for the data of a KE payload. + + + + +Harkins & Carrel Standards Track [Page 3] + +RFC 2409 IKE November 1998 + + + Nx is the nonce payload; x can be: i or r for the ISAKMP initiator + and responder respectively. + + IDx is the identification payload for "x". x can be: "ii" or "ir" + for the ISAKMP initiator and responder respectively during phase + one negotiation; or "ui" or "ur" for the user initiator and + responder respectively during phase two. The ID payload format for + the Internet DOI is defined in [Pip97]. + + SIG is the signature payload. The data to sign is exchange- + specific. + + CERT is the certificate payload. + + HASH (and any derivitive such as HASH(2) or HASH_I) is the hash + payload. The contents of the hash are specific to the + authentication method. + + prf(key, msg) is the keyed pseudo-random function-- often a keyed + hash function-- used to generate a deterministic output that + appears pseudo-random. prf's are used both for key derivations and + for authentication (i.e. as a keyed MAC). (See [KBC96]). + + SKEYID is a string derived from secret material known only to the + active players in the exchange. + + SKEYID_e is the keying material used by the ISAKMP SA to protect + the confidentiality of its messages. + + SKEYID_a is the keying material used by the ISAKMP SA to + authenticate its messages. + + SKEYID_d is the keying material used to derive keys for non-ISAKMP + security associations. + + y indicates that "x" is encrypted with the key "y". + + --> signifies "initiator to responder" communication (requests). + + <-- signifies "responder to initiator" communication (replies). + + | signifies concatenation of information-- e.g. X | Y is the + concatentation of X with Y. + + [x] indicates that x is optional. + + + + + + +Harkins & Carrel Standards Track [Page 4] + +RFC 2409 IKE November 1998 + + + Message encryption (when noted by a '*' after the ISAKMP header) MUST + begin immediately after the ISAKMP header. When communication is + protected, all payloads following the ISAKMP header MUST be + encrypted. Encryption keys are generated from SKEYID_e in a manner + that is defined for each algorithm. + +3.3 Perfect Forward Secrecy + + When used in the memo Perfect Forward Secrecy (PFS) refers to the + notion that compromise of a single key will permit access to only + data protected by a single key. For PFS to exist the key used to + protect transmission of data MUST NOT be used to derive any + additional keys, and if the key used to protect transmission of data + was derived from some other keying material, that material MUST NOT + be used to derive any more keys. + + Perfect Forward Secrecy for both keys and identities is provided in + this protocol. (Sections 5.5 and 8). + +3.4 Security Association + + A security association (SA) is a set of policy and key(s) used to + protect information. The ISAKMP SA is the shared policy and key(s) + used by the negotiating peers in this protocol to protect their + communication. + +4. Introduction + + Oakley and SKEME each define a method to establish an authenticated + key exchange. This includes payloads construction, the information + payloads carry, the order in which they are processed and how they + are used. + + While Oakley defines "modes", ISAKMP defines "phases". The + relationship between the two is very straightforward and IKE presents + different exchanges as modes which operate in one of two phases. + + Phase 1 is where the two ISAKMP peers establish a secure, + authenticated channel with which to communicate. This is called the + ISAKMP Security Association (SA). "Main Mode" and "Aggressive Mode" + each accomplish a phase 1 exchange. "Main Mode" and "Aggressive Mode" + MUST ONLY be used in phase 1. + + Phase 2 is where Security Associations are negotiated on behalf of + services such as IPsec or any other service which needs key material + and/or parameter negotiation. "Quick Mode" accomplishes a phase 2 + exchange. "Quick Mode" MUST ONLY be used in phase 2. + + + + +Harkins & Carrel Standards Track [Page 5] + +RFC 2409 IKE November 1998 + + + "New Group Mode" is not really a phase 1 or phase 2. It follows + phase 1, but serves to establish a new group which can be used in + future negotiations. "New Group Mode" MUST ONLY be used after phase + 1. + + The ISAKMP SA is bi-directional. That is, once established, either + party may initiate Quick Mode, Informational, and New Group Mode + Exchanges. Per the base ISAKMP document, the ISAKMP SA is identified + by the Initiator's cookie followed by the Responder's cookie-- the + role of each party in the phase 1 exchange dictates which cookie is + the Initiator's. The cookie order established by the phase 1 exchange + continues to identify the ISAKMP SA regardless of the direction the + Quick Mode, Informational, or New Group exchange. In other words, the + cookies MUST NOT swap places when the direction of the ISAKMP SA + changes. + + With the use of ISAKMP phases, an implementation can accomplish very + fast keying when necessary. A single phase 1 negotiation may be used + for more than one phase 2 negotiation. Additionally a single phase 2 + negotiation can request multiple Security Associations. With these + optimizations, an implementation can see less than one round trip per + SA as well as less than one DH exponentiation per SA. "Main Mode" + for phase 1 provides identity protection. When identity protection + is not needed, "Aggressive Mode" can be used to reduce round trips + even further. Developer hints for doing these optimizations are + included below. It should also be noted that using public key + encryption to authenticate an Aggressive Mode exchange will still + provide identity protection. + + This protocol does not define its own DOI per se. The ISAKMP SA, + established in phase 1, MAY use the DOI and situation from a non- + ISAKMP service (such as the IETF IPSec DOI [Pip97]). In this case an + implementation MAY choose to restrict use of the ISAKMP SA for + establishment of SAs for services of the same DOI. Alternately, an + ISAKMP SA MAY be established with the value zero in both the DOI and + situation (see [MSST98] for a description of these fields) and in + this case implementations will be free to establish security services + for any defined DOI using this ISAKMP SA. If a DOI of zero is used + for establishment of a phase 1 SA, the syntax of the identity + payloads used in phase 1 is that defined in [MSST98] and not from any + DOI-- e.g. [Pip97]-- which may further expand the syntax and + semantics of identities. + + The following attributes are used by IKE and are negotiated as part + of the ISAKMP Security Association. (These attributes pertain only + to the ISAKMP Security Association and not to any Security + Associations that ISAKMP may be negotiating on behalf of other + services.) + + + +Harkins & Carrel Standards Track [Page 6] + +RFC 2409 IKE November 1998 + + + - encryption algorithm + + - hash algorithm + + - authentication method + + - information about a group over which to do Diffie-Hellman. + + All of these attributes are mandatory and MUST be negotiated. In + addition, it is possible to optionally negotiate a psuedo-random + function ("prf"). (There are currently no negotiable pseudo-random + functions defined in this document. Private use attribute values can + be used for prf negotiation between consenting parties). If a "prf" + is not negotiation, the HMAC (see [KBC96]) version of the negotiated + hash algorithm is used as a pseudo-random function. Other non- + mandatory attributes are described in Appendix A. The selected hash + algorithm MUST support both native and HMAC modes. + + The Diffie-Hellman group MUST be either specified using a defined + group description (section 6) or by defining all attributes of a + group (section 5.6). Group attributes (such as group type or prime-- + see Appendix A) MUST NOT be offered in conjunction with a previously + defined group (either a reserved group description or a private use + description that is established after conclusion of a New Group Mode + exchange). + + IKE implementations MUST support the following attribute values: + + - DES [DES] in CBC mode with a weak, and semi-weak, key check + (weak and semi-weak keys are referenced in [Sch96] and listed in + Appendix A). The key is derived according to Appendix B. + + - MD5 [MD5] and SHA [SHA}. + + - Authentication via pre-shared keys. + + - MODP over default group number one (see below). + + In addition, IKE implementations SHOULD support: 3DES for encryption; + Tiger ([TIGER]) for hash; the Digital Signature Standard, RSA [RSA] + signatures and authentication with RSA public key encryption; and + MODP group number 2. IKE implementations MAY support any additional + encryption algorithms defined in Appendix A and MAY support ECP and + EC2N groups. + + The IKE modes described here MUST be implemented whenever the IETF + IPsec DOI [Pip97] is implemented. Other DOIs MAY use the modes + described here. + + + +Harkins & Carrel Standards Track [Page 7] + +RFC 2409 IKE November 1998 + + +5. Exchanges + + There are two basic methods used to establish an authenticated key + exchange: Main Mode and Aggressive Mode. Each generates authenticated + keying material from an ephemeral Diffie-Hellman exchange. Main Mode + MUST be implemented; Aggressive Mode SHOULD be implemented. In + addition, Quick Mode MUST be implemented as a mechanism to generate + fresh keying material and negotiate non-ISAKMP security services. In + addition, New Group Mode SHOULD be implemented as a mechanism to + define private groups for Diffie-Hellman exchanges. Implementations + MUST NOT switch exchange types in the middle of an exchange. + + Exchanges conform to standard ISAKMP payload syntax, attribute + encoding, timeouts and retransmits of messages, and informational + messages-- e.g a notify response is sent when, for example, a + proposal is unacceptable, or a signature verification or decryption + was unsuccessful, etc. + + The SA payload MUST precede all other payloads in a phase 1 exchange. + Except where otherwise noted, there are no requirements for ISAKMP + payloads in any message to be in any particular order. + + The Diffie-Hellman public value passed in a KE payload, in either a + phase 1 or phase 2 exchange, MUST be the length of the negotiated + Diffie-Hellman group enforced, if necessary, by pre-pending the value + with zeros. + + The length of nonce payload MUST be between 8 and 256 bytes + inclusive. + + Main Mode is an instantiation of the ISAKMP Identity Protect + Exchange: The first two messages negotiate policy; the next two + exchange Diffie-Hellman public values and ancillary data (e.g. + nonces) necessary for the exchange; and the last two messages + authenticate the Diffie-Hellman Exchange. The authentication method + negotiated as part of the initial ISAKMP exchange influences the + composition of the payloads but not their purpose. The XCHG for Main + Mode is ISAKMP Identity Protect. + + Similarly, Aggressive Mode is an instantiation of the ISAKMP + Aggressive Exchange. The first two messages negotiate policy, + exchange Diffie-Hellman public values and ancillary data necessary + for the exchange, and identities. In addition the second message + authenticates the responder. The third message authenticates the + initiator and provides a proof of participation in the exchange. The + XCHG for Aggressive Mode is ISAKMP Aggressive. The final message MAY + NOT be sent under protection of the ISAKMP SA allowing each party to + + + + +Harkins & Carrel Standards Track [Page 8] + +RFC 2409 IKE November 1998 + + + postpone exponentiation, if desired, until negotiation of this + exchange is complete. The graphic depictions of Aggressive Mode show + the final payload in the clear; it need not be. + + Exchanges in IKE are not open ended and have a fixed number of + messages. Receipt of a Certificate Request payload MUST NOT extend + the number of messages transmitted or expected. + + Security Association negotiation is limited with Aggressive Mode. Due + to message construction requirements the group in which the Diffie- + Hellman exchange is performed cannot be negotiated. In addition, + different authentication methods may further constrain attribute + negotiation. For example, authentication with public key encryption + cannot be negotiated and when using the revised method of public key + encryption for authentication the cipher and hash cannot be + negotiated. For situations where the rich attribute negotiation + capabilities of IKE are required Main Mode may be required. + + Quick Mode and New Group Mode have no analog in ISAKMP. The XCHG + values for Quick Mode and New Group Mode are defined in Appendix A. + + Main Mode, Aggressive Mode, and Quick Mode do security association + negotiation. Security Association offers take the form of Tranform + Payload(s) encapsulated in Proposal Payload(s) encapsulated in + Security Association (SA) payload(s). If multiple offers are being + made for phase 1 exchanges (Main Mode and Aggressive Mode) they MUST + take the form of multiple Transform Payloads for a single Proposal + Payload in a single SA payload. To put it another way, for phase 1 + exchanges there MUST NOT be multiple Proposal Payloads for a single + SA payload and there MUST NOT be multiple SA payloads. This document + does not proscribe such behavior on offers in phase 2 exchanges. + + There is no limit on the number of offers the initiator may send to + the responder but conformant implementations MAY choose to limit the + number of offers it will inspect for performance reasons. + + During security association negotiation, initiators present offers + for potential security associations to responders. Responders MUST + NOT modify attributes of any offer, attribute encoding excepted (see + Appendix A). If the initiator of an exchange notices that attribute + values have changed or attributes have been added or deleted from an + offer made, that response MUST be rejected. + + Four different authentication methods are allowed with either Main + Mode or Aggressive Mode-- digital signature, two forms of + authentication with public key encryption, or pre-shared key. The + value SKEYID is computed seperately for each authentication method. + + + + +Harkins & Carrel Standards Track [Page 9] + +RFC 2409 IKE November 1998 + + + For signatures: SKEYID = prf(Ni_b | Nr_b, g^xy) + For public key encryption: SKEYID = prf(hash(Ni_b | Nr_b), CKY-I | + CKY-R) + For pre-shared keys: SKEYID = prf(pre-shared-key, Ni_b | + Nr_b) + + The result of either Main Mode or Aggressive Mode is three groups of + authenticated keying material: + + SKEYID_d = prf(SKEYID, g^xy | CKY-I | CKY-R | 0) + SKEYID_a = prf(SKEYID, SKEYID_d | g^xy | CKY-I | CKY-R | 1) + SKEYID_e = prf(SKEYID, SKEYID_a | g^xy | CKY-I | CKY-R | 2) + + and agreed upon policy to protect further communications. The values + of 0, 1, and 2 above are represented by a single octet. The key used + for encryption is derived from SKEYID_e in an algorithm-specific + manner (see appendix B). + + To authenticate either exchange the initiator of the protocol + generates HASH_I and the responder generates HASH_R where: + + HASH_I = prf(SKEYID, g^xi | g^xr | CKY-I | CKY-R | SAi_b | IDii_b ) + HASH_R = prf(SKEYID, g^xr | g^xi | CKY-R | CKY-I | SAi_b | IDir_b ) + + For authentication with digital signatures, HASH_I and HASH_R are + signed and verified; for authentication with either public key + encryption or pre-shared keys, HASH_I and HASH_R directly + authenticate the exchange. The entire ID payload (including ID type, + port, and protocol but excluding the generic header) is hashed into + both HASH_I and HASH_R. + + As mentioned above, the negotiated authentication method influences + the content and use of messages for Phase 1 Modes, but not their + intent. When using public keys for authentication, the Phase 1 + exchange can be accomplished either by using signatures or by using + public key encryption (if the algorithm supports it). Following are + Phase 1 exchanges with different authentication options. + +5.1 IKE Phase 1 Authenticated With Signatures + + Using signatures, the ancillary information exchanged during the + second roundtrip are nonces; the exchange is authenticated by signing + a mutually obtainable hash. Main Mode with signature authentication + is described as follows: + + + + + + + +Harkins & Carrel Standards Track [Page 10] + +RFC 2409 IKE November 1998 + + + Initiator Responder + ----------- ----------- + HDR, SA --> + <-- HDR, SA + HDR, KE, Ni --> + <-- HDR, KE, Nr + HDR*, IDii, [ CERT, ] SIG_I --> + <-- HDR*, IDir, [ CERT, ] SIG_R + + Aggressive mode with signatures in conjunction with ISAKMP is + described as follows: + + Initiator Responder + ----------- ----------- + HDR, SA, KE, Ni, IDii --> + <-- HDR, SA, KE, Nr, IDir, + [ CERT, ] SIG_R + HDR, [ CERT, ] SIG_I --> + + In both modes, the signed data, SIG_I or SIG_R, is the result of the + negotiated digital signature algorithm applied to HASH_I or HASH_R + respectively. + + In general the signature will be over HASH_I and HASH_R as above + using the negotiated prf, or the HMAC version of the negotiated hash + function (if no prf is negotiated). However, this can be overridden + for construction of the signature if the signature algorithm is tied + to a particular hash algorithm (e.g. DSS is only defined with SHA's + 160 bit output). In this case, the signature will be over HASH_I and + HASH_R as above, except using the HMAC version of the hash algorithm + associated with the signature method. The negotiated prf and hash + function would continue to be used for all other prescribed pseudo- + random functions. + + Since the hash algorithm used is already known there is no need to + encode its OID into the signature. In addition, there is no binding + between the OIDs used for RSA signatures in PKCS #1 and those used in + this document. Therefore, RSA signatures MUST be encoded as a private + key encryption in PKCS #1 format and not as a signature in PKCS #1 + format (which includes the OID of the hash algorithm). DSS signatures + MUST be encoded as r followed by s. + + One or more certificate payloads MAY be optionally passed. + + + + + + + + +Harkins & Carrel Standards Track [Page 11] + +RFC 2409 IKE November 1998 + + +5.2 Phase 1 Authenticated With Public Key Encryption + + Using public key encryption to authenticate the exchange, the + ancillary information exchanged is encrypted nonces. Each party's + ability to reconstruct a hash (proving that the other party decrypted + the nonce) authenticates the exchange. + + In order to perform the public key encryption, the initiator must + already have the responder's public key. In the case where the + responder has multiple public keys, a hash of the certificate the + initiator is using to encrypt the ancillary information is passed as + part of the third message. In this way the responder can determine + which corresponding private key to use to decrypt the encrypted + payloads and identity protection is retained. + + In addition to the nonce, the identities of the parties (IDii and + IDir) are also encrypted with the other party's public key. If the + authentication method is public key encryption, the nonce and + identity payloads MUST be encrypted with the public key of the other + party. Only the body of the payloads are encrypted, the payload + headers are left in the clear. + + When using encryption for authentication, Main Mode is defined as + follows. + + Initiator Responder + ----------- ----------- + HDR, SA --> + <-- HDR, SA + HDR, KE, [ HASH(1), ] + PubKey_r, + PubKey_r --> + HDR, KE, PubKey_i, + <-- PubKey_i + HDR*, HASH_I --> + <-- HDR*, HASH_R + + Aggressive Mode authenticated with encryption is described as + follows: + + Initiator Responder + ----------- ----------- + HDR, SA, [ HASH(1),] KE, + Pubkey_r, + Pubkey_r --> + HDR, SA, KE, PubKey_i, + <-- PubKey_i, HASH_R + HDR, HASH_I --> + + + +Harkins & Carrel Standards Track [Page 12] + +RFC 2409 IKE November 1998 + + + Where HASH(1) is a hash (using the negotiated hash function) of the + certificate which the initiator is using to encrypt the nonce and + identity. + + RSA encryption MUST be encoded in PKCS #1 format. While only the body + of the ID and nonce payloads is encrypted, the encrypted data must be + preceded by a valid ISAKMP generic header. The payload length is the + length of the entire encrypted payload plus header. The PKCS #1 + encoding allows for determination of the actual length of the + cleartext payload upon decryption. + + Using encryption for authentication provides for a plausably deniable + exchange. There is no proof (as with a digital signature) that the + conversation ever took place since each party can completely + reconstruct both sides of the exchange. In addition, security is + added to secret generation since an attacker would have to + successfully break not only the Diffie-Hellman exchange but also both + RSA encryptions. This exchange was motivated by [SKEME]. + + Note that, unlike other authentication methods, authentication with + public key encryption allows for identity protection with Aggressive + Mode. + +5.3 Phase 1 Authenticated With a Revised Mode of Public Key Encryption + + Authentication with Public Key Encryption has significant advantages + over authentication with signatures (see section 5.2 above). + Unfortunately, this is at the cost of 4 public key operations-- two + public key encryptions and two private key decryptions. This + authentication mode retains the advantages of authentication using + public key encryption but does so with half the public key + operations. + + In this mode, the nonce is still encrypted using the public key of + the peer, however the peer's identity (and the certificate if it is + sent) is encrypted using the negotiated symmetric encryption + algorithm (from the SA payload) with a key derived from the nonce. + This solution adds minimal complexity and state yet saves two costly + public key operations on each side. In addition, the Key Exchange + payload is also encrypted using the same derived key. This provides + additional protection against cryptanalysis of the Diffie-Hellman + exchange. + + As with the public key encryption method of authentication (section + 5.2), a HASH payload may be sent to identify a certificate if the + responder has multiple certificates which contain useable public keys + (e.g. if the certificate is not for signatures only, either due to + certificate restrictions or algorithmic restrictions). If the HASH + + + +Harkins & Carrel Standards Track [Page 13] + +RFC 2409 IKE November 1998 + + + payload is sent it MUST be the first payload of the second message + exchange and MUST be followed by the encrypted nonce. If the HASH + payload is not sent, the first payload of the second message exchange + MUST be the encrypted nonce. In addition, the initiator my optionally + send a certificate payload to provide the responder with a public key + with which to respond. + + When using the revised encryption mode for authentication, Main Mode + is defined as follows. + + Initiator Responder + ----------- ----------- + HDR, SA --> + <-- HDR, SA + HDR, [ HASH(1), ] + Pubkey_r, + Ke_i, + Ke_i, + [<Ke_i] --> + HDR, PubKey_i, + Ke_r, + <-- Ke_r, + HDR*, HASH_I --> + <-- HDR*, HASH_R + + Aggressive Mode authenticated with the revised encryption method is + described as follows: + + Initiator Responder + ----------- ----------- + HDR, SA, [ HASH(1),] + Pubkey_r, + Ke_i, Ke_i + [, Ke_i ] --> + HDR, SA, PubKey_i, + Ke_r, Ke_r, + <-- HASH_R + HDR, HASH_I --> + + where HASH(1) is identical to section 5.2. Ke_i and Ke_r are keys to + the symmetric encryption algorithm negotiated in the SA payload + exchange. Only the body of the payloads are encrypted (in both public + key and symmetric operations), the generic payload headers are left + in the clear. The payload length includes that added to perform + encryption. + + The symmetric cipher keys are derived from the decrypted nonces as + follows. First the values Ne_i and Ne_r are computed: + + + +Harkins & Carrel Standards Track [Page 14] + +RFC 2409 IKE November 1998 + + + Ne_i = prf(Ni_b, CKY-I) + Ne_r = prf(Nr_b, CKY-R) + + The keys Ke_i and Ke_r are then taken from Ne_i and Ne_r respectively + in the manner described in Appendix B used to derive symmetric keys + for use with the negotiated encryption algorithm. If the length of + the output of the negotiated prf is greater than or equal to the key + length requirements of the cipher, Ke_i and Ke_r are derived from the + most significant bits of Ne_i and Ne_r respectively. If the desired + length of Ke_i and Ke_r exceed the length of the output of the prf + the necessary number of bits is obtained by repeatedly feeding the + results of the prf back into itself and concatenating the result + until the necessary number has been achieved. For example, if the + negotiated encryption algorithm requires 320 bits of key and the + output of the prf is only 128 bits, Ke_i is the most significant 320 + bits of K, where + + K = K1 | K2 | K3 and + K1 = prf(Ne_i, 0) + K2 = prf(Ne_i, K1) + K3 = prf(Ne_i, K2) + + For brevity, only derivation of Ke_i is shown; Ke_r is identical. The + length of the value 0 in the computation of K1 is a single octet. + Note that Ne_i, Ne_r, Ke_i, and Ke_r are all ephemeral and MUST be + discarded after use. + + Save the requirements on the location of the optional HASH payload + and the mandatory nonce payload there are no further payload + requirements. All payloads-- in whatever order-- following the + encrypted nonce MUST be encrypted with Ke_i or Ke_r depending on the + direction. + + If CBC mode is used for the symmetric encryption then the + initialization vectors (IVs) are set as follows. The IV for + encrypting the first payload following the nonce is set to 0 (zero). + The IV for subsequent payloads encrypted with the ephemeral symmetric + cipher key, Ke_i, is the last ciphertext block of the previous + payload. Encrypted payloads are padded up to the nearest block size. + All padding bytes, except for the last one, contain 0x00. The last + byte of the padding contains the number of the padding bytes used, + excluding the last one. Note that this means there will always be + padding. + + + + + + + + +Harkins & Carrel Standards Track [Page 15] + +RFC 2409 IKE November 1998 + + +5.4 Phase 1 Authenticated With a Pre-Shared Key + + A key derived by some out-of-band mechanism may also be used to + authenticate the exchange. The actual establishment of this key is + out of the scope of this document. + + When doing a pre-shared key authentication, Main Mode is defined as + follows: + + Initiator Responder + ---------- ----------- + HDR, SA --> + <-- HDR, SA + HDR, KE, Ni --> + <-- HDR, KE, Nr + HDR*, IDii, HASH_I --> + <-- HDR*, IDir, HASH_R + + Aggressive mode with a pre-shared key is described as follows: + + Initiator Responder + ----------- ----------- + HDR, SA, KE, Ni, IDii --> + <-- HDR, SA, KE, Nr, IDir, HASH_R + HDR, HASH_I --> + + When using pre-shared key authentication with Main Mode the key can + only be identified by the IP address of the peers since HASH_I must + be computed before the initiator has processed IDir. Aggressive Mode + allows for a wider range of identifiers of the pre-shared secret to + be used. In addition, Aggressive Mode allows two parties to maintain + multiple, different pre-shared keys and identify the correct one for + a particular exchange. + +5.5 Phase 2 - Quick Mode + + Quick Mode is not a complete exchange itself (in that it is bound to + a phase 1 exchange), but is used as part of the SA negotiation + process (phase 2) to derive keying material and negotiate shared + policy for non-ISAKMP SAs. The information exchanged along with Quick + Mode MUST be protected by the ISAKMP SA-- i.e. all payloads except + the ISAKMP header are encrypted. In Quick Mode, a HASH payload MUST + immediately follow the ISAKMP header and a SA payload MUST + immediately follow the HASH. This HASH authenticates the message and + also provides liveliness proofs. + + + + + + +Harkins & Carrel Standards Track [Page 16] + +RFC 2409 IKE November 1998 + + + The message ID in the ISAKMP header identifies a Quick Mode in + progress for a particular ISAKMP SA which itself is identified by the + cookies in the ISAKMP header. Since each instance of a Quick Mode + uses a unique initialization vector (see Appendix B) it is possible + to have multiple simultaneous Quick Modes, based off a single ISAKMP + SA, in progress at any one time. + + Quick Mode is essentially a SA negotiation and an exchange of nonces + that provides replay protection. The nonces are used to generate + fresh key material and prevent replay attacks from generating bogus + security associations. An optional Key Exchange payload can be + exchanged to allow for an additional Diffie-Hellman exchange and + exponentiation per Quick Mode. While use of the key exchange payload + with Quick Mode is optional it MUST be supported. + + Base Quick Mode (without the KE payload) refreshes the keying + material derived from the exponentiation in phase 1. This does not + provide PFS. Using the optional KE payload, an additional + exponentiation is performed and PFS is provided for the keying + material. + + The identities of the SAs negotiated in Quick Mode are implicitly + assumed to be the IP addresses of the ISAKMP peers, without any + implied constraints on the protocol or port numbers allowed, unless + client identifiers are specified in Quick Mode. If ISAKMP is acting + as a client negotiator on behalf of another party, the identities of + the parties MUST be passed as IDci and then IDcr. Local policy will + dictate whether the proposals are acceptable for the identities + specified. If the client identities are not acceptable to the Quick + Mode responder (due to policy or other reasons), a Notify payload + with Notify Message Type INVALID-ID-INFORMATION (18) SHOULD be sent. + + The client identities are used to identify and direct traffic to the + appropriate tunnel in cases where multiple tunnels exist between two + peers and also to allow for unique and shared SAs with different + granularities. + + All offers made during a Quick Mode are logically related and must be + consistant. For example, if a KE payload is sent, the attribute + describing the Diffie-Hellman group (see section 6.1 and [Pip97]) + MUST be included in every transform of every proposal of every SA + being negotiated. Similarly, if client identities are used, they MUST + apply to every SA in the negotiation. + + Quick Mode is defined as follows: + + + + + + +Harkins & Carrel Standards Track [Page 17] + +RFC 2409 IKE November 1998 + + + Initiator Responder + ----------- ----------- + HDR*, HASH(1), SA, Ni + [, KE ] [, IDci, IDcr ] --> + <-- HDR*, HASH(2), SA, Nr + [, KE ] [, IDci, IDcr ] + HDR*, HASH(3) --> + + Where: + HASH(1) is the prf over the message id (M-ID) from the ISAKMP header + concatenated with the entire message that follows the hash including + all payload headers, but excluding any padding added for encryption. + HASH(2) is identical to HASH(1) except the initiator's nonce-- Ni, + minus the payload header-- is added after M-ID but before the + complete message. The addition of the nonce to HASH(2) is for a + liveliness proof. HASH(3)-- for liveliness-- is the prf over the + value zero represented as a single octet, followed by a concatenation + of the message id and the two nonces-- the initiator's followed by + the responder's-- minus the payload header. In other words, the + hashes for the above exchange are: + + HASH(1) = prf(SKEYID_a, M-ID | SA | Ni [ | KE ] [ | IDci | IDcr ) + HASH(2) = prf(SKEYID_a, M-ID | Ni_b | SA | Nr [ | KE ] [ | IDci | + IDcr ) + HASH(3) = prf(SKEYID_a, 0 | M-ID | Ni_b | Nr_b) + + With the exception of the HASH, SA, and the optional ID payloads, + there are no payload ordering restrictions on Quick Mode. HASH(1) and + HASH(2) may differ from the illustration above if the order of + payloads in the message differs from the illustrative example or if + any optional payloads, for example a notify payload, have been + chained to the message. + + If PFS is not needed, and KE payloads are not exchanged, the new + keying material is defined as + + KEYMAT = prf(SKEYID_d, protocol | SPI | Ni_b | Nr_b). + + If PFS is desired and KE payloads were exchanged, the new keying + material is defined as + + KEYMAT = prf(SKEYID_d, g(qm)^xy | protocol | SPI | Ni_b | Nr_b) + + where g(qm)^xy is the shared secret from the ephemeral Diffie-Hellman + exchange of this Quick Mode. + + In either case, "protocol" and "SPI" are from the ISAKMP Proposal + Payload that contained the negotiated Transform. + + + +Harkins & Carrel Standards Track [Page 18] + +RFC 2409 IKE November 1998 + + + A single SA negotiation results in two security assocations-- one + inbound and one outbound. Different SPIs for each SA (one chosen by + the initiator, the other by the responder) guarantee a different key + for each direction. The SPI chosen by the destination of the SA is + used to derive KEYMAT for that SA. + + For situations where the amount of keying material desired is greater + than that supplied by the prf, KEYMAT is expanded by feeding the + results of the prf back into itself and concatenating results until + the required keying material has been reached. In other words, + + KEYMAT = K1 | K2 | K3 | ... + where + K1 = prf(SKEYID_d, [ g(qm)^xy | ] protocol | SPI | Ni_b | Nr_b) + K2 = prf(SKEYID_d, K1 | [ g(qm)^xy | ] protocol | SPI | Ni_b | + Nr_b) + K3 = prf(SKEYID_d, K2 | [ g(qm)^xy | ] protocol | SPI | Ni_b | + Nr_b) + etc. + + This keying material (whether with PFS or without, and whether + derived directly or through concatenation) MUST be used with the + negotiated SA. It is up to the service to define how keys are derived + from the keying material. + + In the case of an ephemeral Diffie-Hellman exchange in Quick Mode, + the exponential (g(qm)^xy) is irretreivably removed from the current + state and SKEYID_e and SKEYID_a (derived from phase 1 negotiation) + continue to protect and authenticate the ISAKMP SA and SKEYID_d + continues to be used to derive keys. + + Using Quick Mode, multiple SA's and keys can be negotiated with one + exchange as follows: + + Initiator Responder + ----------- ----------- + HDR*, HASH(1), SA0, SA1, Ni, + [, KE ] [, IDci, IDcr ] --> + <-- HDR*, HASH(2), SA0, SA1, Nr, + [, KE ] [, IDci, IDcr ] + HDR*, HASH(3) --> + + The keying material is derived identically as in the case of a single + SA. In this case (negotiation of two SA payloads) the result would be + four security associations-- two each way for both SAs. + + + + + + +Harkins & Carrel Standards Track [Page 19] + +RFC 2409 IKE November 1998 + + +5.6 New Group Mode + + New Group Mode MUST NOT be used prior to establishment of an ISAKMP + SA. The description of a new group MUST only follow phase 1 + negotiation. (It is not a phase 2 exchange, though). + + Initiator Responder + ----------- ----------- + HDR*, HASH(1), SA --> + <-- HDR*, HASH(2), SA + + where HASH(1) is the prf output, using SKEYID_a as the key, and the + message-ID from the ISAKMP header concatenated with the entire SA + proposal, body and header, as the data; HASH(2) is the prf output, + using SKEYID_a as the key, and the message-ID from the ISAKMP header + concatenated with the reply as the data. In other words the hashes + for the above exchange are: + + HASH(1) = prf(SKEYID_a, M-ID | SA) + HASH(2) = prf(SKEYID_a, M-ID | SA) + + The proposal will specify the characteristics of the group (see + appendix A, "Attribute Assigned Numbers"). Group descriptions for + private Groups MUST be greater than or equal to 2^15. If the group + is not acceptable, the responder MUST reply with a Notify payload + with the message type set to ATTRIBUTES-NOT-SUPPORTED (13). + + ISAKMP implementations MAY require private groups to expire with the + SA under which they were established. + + Groups may be directly negotiated in the SA proposal with Main Mode. + To do this the component parts-- for a MODP group, the type, prime + and generator; for a EC2N group the type, the Irreducible Polynomial, + Group Generator One, Group Generator Two, Group Curve A, Group Curve + B and Group Order-- are passed as SA attributes (see Appendix A). + Alternately, the nature of the group can be hidden using New Group + Mode and only the group identifier is passed in the clear during + phase 1 negotiation. + +5.7 ISAKMP Informational Exchanges + + This protocol protects ISAKMP Informational Exchanges when possible. + Once the ISAKMP security association has been established (and + SKEYID_e and SKEYID_a have been generated) ISAKMP Information + Exchanges, when used with this protocol, are as follows: + + + + + + +Harkins & Carrel Standards Track [Page 20] + +RFC 2409 IKE November 1998 + + + Initiator Responder + ----------- ----------- + HDR*, HASH(1), N/D --> + + where N/D is either an ISAKMP Notify Payload or an ISAKMP Delete + Payload and HASH(1) is the prf output, using SKEYID_a as the key, and + a M-ID unique to this exchange concatenated with the entire + informational payload (either a Notify or Delete) as the data. In + other words, the hash for the above exchange is: + + HASH(1) = prf(SKEYID_a, M-ID | N/D) + + As noted the message ID in the ISAKMP header-- and used in the prf + computation-- is unique to this exchange and MUST NOT be the same as + the message ID of another phase 2 exchange which generated this + informational exchange. The derivation of the initialization vector, + used with SKEYID_e to encrypt this message, is described in Appendix + B. + + If the ISAKMP security association has not yet been established at + the time of the Informational Exchange, the exchange is done in the + clear without an accompanying HASH payload. + +6 Oakley Groups + + With IKE, the group in which to do the Diffie-Hellman exchange is + negotiated. Four groups-- values 1 through 4-- are defined below. + These groups originated with the Oakley protocol and are therefore + called "Oakley Groups". The attribute class for "Group" is defined in + Appendix A. All values 2^15 and higher are used for private group + identifiers. For a discussion on the strength of the default Oakley + groups please see the Security Considerations section below. + + These groups were all generated by Richard Schroeppel at the + University of Arizona. Properties of these groups are described in + [Orm96]. + +6.1 First Oakley Default Group + + Oakley implementations MUST support a MODP group with the following + prime and generator. This group is assigned id 1 (one). + + The prime is: 2^768 - 2 ^704 - 1 + 2^64 * { [2^638 pi] + 149686 } + Its hexadecimal value is + + + + + + + +Harkins & Carrel Standards Track [Page 21] + +RFC 2409 IKE November 1998 + + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A63A3620 FFFFFFFF FFFFFFFF + + The generator is: 2. + +6.2 Second Oakley Group + + IKE implementations SHOULD support a MODP group with the following + prime and generator. This group is assigned id 2 (two). + + The prime is 2^1024 - 2^960 - 1 + 2^64 * { [2^894 pi] + 129093 }. + Its hexadecimal value is + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE65381 + FFFFFFFF FFFFFFFF + + The generator is 2 (decimal) + +6.3 Third Oakley Group + + IKE implementations SHOULD support a EC2N group with the following + characteristics. This group is assigned id 3 (three). The curve is + based on the Galois Field GF[2^155]. The field size is 155. The + irreducible polynomial for the field is: + u^155 + u^62 + 1. + The equation for the elliptic curve is: + y^2 + xy = x^3 + ax^2 + b. + + Field Size: 155 + Group Prime/Irreducible Polynomial: + 0x0800000000000000000000004000000000000001 + Group Generator One: 0x7b + Group Curve A: 0x0 + Group Curve B: 0x07338f + + Group Order: 0X0800000000000000000057db5698537193aef944 + + The data in the KE payload when using this group is the value x from + the solution (x,y), the point on the curve chosen by taking the + randomly chosen secret Ka and computing Ka*P, where * is the + repetition of the group addition and double operations, P is the + curve point with x coordinate equal to generator 1 and the y + + + +Harkins & Carrel Standards Track [Page 22] + +RFC 2409 IKE November 1998 + + + coordinate determined from the defining equation. The equation of + curve is implicitly known by the Group Type and the A and B + coefficients. There are two possible values for the y coordinate; + either one can be used successfully (the two parties need not agree + on the selection). + +6.4 Fourth Oakley Group + + IKE implementations SHOULD support a EC2N group with the following + characteristics. This group is assigned id 4 (four). The curve is + based on the Galois Field GF[2^185]. The field size is 185. The + irreducible polynomial for the field is: + u^185 + u^69 + 1. The + equation for the elliptic curve is: + y^2 + xy = x^3 + ax^2 + b. + + Field Size: 185 + Group Prime/Irreducible Polynomial: + 0x020000000000000000000000000000200000000000000001 + Group Generator One: 0x18 + Group Curve A: 0x0 + Group Curve B: 0x1ee9 + + Group Order: 0X01ffffffffffffffffffffffdbf2f889b73e484175f94ebc + + The data in the KE payload when using this group will be identical to + that as when using Oakley Group 3 (three). + + Other groups can be defined using New Group Mode. These default + groups were generated by Richard Schroeppel at the University of + Arizona. Properties of these primes are described in [Orm96]. + +7. Payload Explosion for a Complete IKE Exchange + + This section illustrates how the IKE protocol is used to: + + - establish a secure and authenticated channel between ISAKMP + processes (phase 1); and + + - generate key material for, and negotiate, an IPsec SA (phase 2). + +7.1 Phase 1 using Main Mode + + The following diagram illustrates the payloads exchanged between the + two parties in the first round trip exchange. The initiator MAY + propose several proposals; the responder MUST reply with one. + + + + + +Harkins & Carrel Standards Track [Page 23] + +RFC 2409 IKE November 1998 + + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ISAKMP Header with XCHG of Main Mode, ~ + ~ and Next Payload of ISA_SA ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Situation ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Proposal #1 ! PROTO_ISAKMP ! SPI size = 0 | # Transforms ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_TRANS ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Transform #1 ! KEY_OAKLEY | RESERVED2 ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ prefered SA attributes ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Transform #2 ! KEY_OAKLEY | RESERVED2 ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ alternate SA attributes ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + The responder replies in kind but selects, and returns, one transform + proposal (the ISAKMP SA attributes). + + The second exchange consists of the following payloads: + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ISAKMP Header with XCHG of Main Mode, ~ + ~ and Next Payload of ISA_KE ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_NONCE ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ D-H Public Value (g^xi from initiator g^xr from responder) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Ni (from initiator) or Nr (from responder) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + + + +Harkins & Carrel Standards Track [Page 24] + +RFC 2409 IKE November 1998 + + + The shared keys, SKEYID_e and SKEYID_a, are now used to protect and + authenticate all further communication. Note that both SKEYID_e and + SKEYID_a are unauthenticated. + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ISAKMP Header with XCHG of Main Mode, ~ + ~ and Next Payload of ISA_ID and the encryption bit set ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_SIG ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Identification Data of the ISAKMP negotiator ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ signature verified by the public key of the ID above ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + The key exchange is authenticated over a signed hash as described in + section 5.1. Once the signature has been verified using the + authentication algorithm negotiated as part of the ISAKMP SA, the + shared keys, SKEYID_e and SKEYID_a can be marked as authenticated. + (For brevity, certificate payloads were not exchanged). + +7.2 Phase 2 using Quick Mode + + The following payloads are exchanged in the first round of Quick Mode + with ISAKMP SA negotiation. In this hypothetical exchange, the ISAKMP + negotiators are proxies for other parties which have requested + authentication. + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ISAKMP Header with XCHG of Quick Mode, ~ + ~ Next Payload of ISA_HASH and the encryption bit set ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_SA ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ keyed hash of message ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_NONCE ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain Of Interpretation ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Situation ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + +Harkins & Carrel Standards Track [Page 25] + +RFC 2409 IKE November 1998 + + + ! Proposal #1 ! PROTO_IPSEC_AH! SPI size = 4 | # Transforms ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ SPI (4 octets) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_TRANS ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Transform #1 ! AH_SHA | RESERVED2 ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! other SA attributes ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Transform #2 ! AH_MD5 | RESERVED2 ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! other SA attributes ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_ID ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ nonce ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ISA_ID ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ID of source for which ISAKMP is a client ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ID of destination for which ISAKMP is a client ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + where the contents of the hash are described in 5.5 above. The + responder replies with a similar message which only contains one + transform-- the selected AH transform. Upon receipt, the initiator + can provide the key engine with the negotiated security association + and the keying material. As a check against replay attacks, the + responder waits until receipt of the next message. + + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ ISAKMP Header with XCHG of Quick Mode, ~ + ~ Next Payload of ISA_HASH and the encryption bit set ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 ! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ hash data ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + where the contents of the hash are described in 5.5 above. + + + + +Harkins & Carrel Standards Track [Page 26] + +RFC 2409 IKE November 1998 + + +8. Perfect Forward Secrecy Example + + This protocol can provide PFS of both keys and identities. The + identies of both the ISAKMP negotiating peer and, if applicable, the + identities for whom the peers are negotiating can be protected with + PFS. + + To provide Perfect Forward Secrecy of both keys and all identities, + two parties would perform the following: + + o A Main Mode Exchange to protect the identities of the ISAKMP + peers. + This establishes an ISAKMP SA. + o A Quick Mode Exchange to negotiate other security protocol + protection. + This establishes a SA on each end for this protocol. + o Delete the ISAKMP SA and its associated state. + + Since the key for use in the non-ISAKMP SA was derived from the + single ephemeral Diffie-Hellman exchange PFS is preserved. + + To provide Perfect Forward Secrecy of merely the keys of a non-ISAKMP + security association, it in not necessary to do a phase 1 exchange if + an ISAKMP SA exists between the two peers. A single Quick Mode in + which the optional KE payload is passed, and an additional Diffie- + Hellman exchange is performed, is all that is required. At this point + the state derived from this Quick Mode must be deleted from the + ISAKMP SA as described in section 5.5. + +9. Implementation Hints + + Using a single ISAKMP Phase 1 negotiation makes subsequent Phase 2 + negotiations extremely quick. As long as the Phase 1 state remains + cached, and PFS is not needed, Phase 2 can proceed without any + exponentiation. How many Phase 2 negotiations can be performed for a + single Phase 1 is a local policy issue. The decision will depend on + the strength of the algorithms being used and level of trust in the + peer system. + + An implementation may wish to negotiate a range of SAs when + performing Quick Mode. By doing this they can speed up the "re- + keying". Quick Mode defines how KEYMAT is defined for a range of SAs. + When one peer feels it is time to change SAs they simply use the next + one within the stated range. A range of SAs can be established by + negotiating multiple SAs (identical attributes, different SPIs) with + one Quick Mode. + + + + + +Harkins & Carrel Standards Track [Page 27] + +RFC 2409 IKE November 1998 + + + An optimization that is often useful is to establish Security + Associations with peers before they are needed so that when they + become needed they are already in place. This ensures there would be + no delays due to key management before initial data transmission. + This optimization is easily implemented by setting up more than one + Security Association with a peer for each requested Security + Association and caching those not immediately used. + + Also, if an ISAKMP implementation is alerted that a SA will soon be + needed (e.g. to replace an existing SA that will expire in the near + future), then it can establish the new SA before that new SA is + needed. + + The base ISAKMP specification describes conditions in which one party + of the protocol may inform the other party of some activity-- either + deletion of a security association or in response to some error in + the protocol such as a signature verification failed or a payload + failed to decrypt. It is strongly suggested that these Informational + exchanges not be responded to under any circumstances. Such a + condition may result in a "notify war" in which failure to understand + a message results in a notify to the peer who cannot understand it + and sends his own notify back which is also not understood. + +10. Security Considerations + + This entire memo discusses a hybrid protocol, combining parts of + Oakley and parts of SKEME with ISAKMP, to negotiate, and derive + keying material for, security associations in a secure and + authenticated manner. + + Confidentiality is assured by the use of a negotiated encryption + algorithm. Authentication is assured by the use of a negotiated + method: a digital signature algorithm; a public key algorithm which + supports encryption; or, a pre-shared key. The confidentiality and + authentication of this exchange is only as good as the attributes + negotiated as part of the ISAKMP security association. + + Repeated re-keying using Quick Mode can consume the entropy of the + Diffie-Hellman shared secret. Implementors should take note of this + fact and set a limit on Quick Mode Exchanges between exponentiations. + This memo does not prescribe such a limit. + + Perfect Forward Secrecy (PFS) of both keying material and identities + is possible with this protocol. By specifying a Diffie-Hellman group, + and passing public values in KE payloads, ISAKMP peers can establish + PFS of keys-- the identities would be protected by SKEYID_e from the + ISAKMP SA and would therefore not be protected by PFS. If PFS of both + keying material and identities is desired, an ISAKMP peer MUST + + + +Harkins & Carrel Standards Track [Page 28] + +RFC 2409 IKE November 1998 + + + establish only one non-ISAKMP security association (e.g. IPsec + Security Association) per ISAKMP SA. PFS for keys and identities is + accomplished by deleting the ISAKMP SA (and optionally issuing a + DELETE message) upon establishment of the single non-ISAKMP SA. In + this way a phase one negotiation is uniquely tied to a single phase + two negotiation, and the ISAKMP SA established during phase one + negotiation is never used again. + + The strength of a key derived from a Diffie-Hellman exchange using + any of the groups defined here depends on the inherent strength of + the group, the size of the exponent used, and the entropy provided by + the random number generator used. Due to these inputs it is difficult + to determine the strength of a key for any of the defined groups. The + default Diffie-Hellman group (number one) when used with a strong + random number generator and an exponent no less than 160 bits is + sufficient to use for DES. Groups two through four provide greater + security. Implementations should make note of these conservative + estimates when establishing policy and negotiating security + parameters. + + Note that these limitations are on the Diffie-Hellman groups + themselves. There is nothing in IKE which prohibits using stronger + groups nor is there anything which will dilute the strength obtained + from stronger groups. In fact, the extensible framework of IKE + encourages the definition of more groups; use of elliptical curve + groups will greatly increase strength using much smaller numbers. + + For situations where defined groups provide insufficient strength New + Group Mode can be used to exchange a Diffie-Hellman group which + provides the necessary strength. In is incumbent upon implementations + to check the primality in groups being offered and independently + arrive at strength estimates. + + It is assumed that the Diffie-Hellman exponents in this exchange are + erased from memory after use. In particular, these exponents must not + be derived from long-lived secrets like the seed to a pseudo-random + generator. + + IKE exchanges maintain running initialization vectors (IV) where the + last ciphertext block of the last message is the IV for the next + message. To prevent retransmissions (or forged messages with valid + cookies) from causing exchanges to get out of sync IKE + implementations SHOULD NOT update their running IV until the + decrypted message has passed a basic sanity check and has been + determined to actually advance the IKE state machine-- i.e. it is not + a retransmission. + + + + + +Harkins & Carrel Standards Track [Page 29] + +RFC 2409 IKE November 1998 + + + While the last roundtrip of Main Mode (and optionally the last + message of Aggressive Mode) is encrypted it is not, strictly + speaking, authenticated. An active substitution attack on the + ciphertext could result in payload corruption. If such an attack + corrupts mandatory payloads it would be detected by an authentication + failure, but if it corrupts any optional payloads (e.g. notify + payloads chained onto the last message of a Main Mode exchange) it + might not be detectable. + +11. IANA Considerations + + This document contains many "magic numbers" to be maintained by the + IANA. This section explains the criteria to be used by the IANA to + assign additional numbers in each of these lists. + +11.1 Attribute Classes + + Attributes negotiated in this protocol are identified by their class. + Requests for assignment of new classes must be accompanied by a + standards-track RFC which describes the use of this attribute. + +11.2 Encryption Algorithm Class + + Values of the Encryption Algorithm Class define an encryption + algorithm to use when called for in this document. Requests for + assignment of new encryption algorithm values must be accompanied by + a reference to a standards-track or Informational RFC or a reference + to published cryptographic literature which describes this algorithm. + +11.3 Hash Algorithm + + Values of the Hash Algorithm Class define a hash algorithm to use + when called for in this document. Requests for assignment of new hash + algorithm values must be accompanied by a reference to a standards- + track or Informational RFC or a reference to published cryptographic + literature which describes this algorithm. Due to the key derivation + and key expansion uses of HMAC forms of hash algorithms in IKE, + requests for assignment of new hash algorithm values must take into + account the cryptographic properties-- e.g it's resistance to + collision-- of the hash algorithm itself. + +11.4 Group Description and Group Type + + Values of the Group Description Class identify a group to use in a + Diffie-Hellman exchange. Values of the Group Type Class define the + type of group. Requests for assignment of new groups must be + accompanied by a reference to a standards-track or Informational RFC + which describes this group. Requests for assignment of new group + + + +Harkins & Carrel Standards Track [Page 30] + +RFC 2409 IKE November 1998 + + + types must be accompanied by a reference to a standards-track or + Informational RFC or by a reference to published cryptographic or + mathmatical literature which describes the new type. + +11.5 Life Type + + Values of the Life Type Class define a type of lifetime to which the + ISAKMP Security Association applies. Requests for assignment of new + life types must be accompanied by a detailed description of the units + of this type and its expiry. + +12. Acknowledgements + + This document is the result of close consultation with Hugo Krawczyk, + Douglas Maughan, Hilarie Orman, Mark Schertler, Mark Schneider, and + Jeff Turner. It relies on protocols which were written by them. + Without their interest and dedication, this would not have been + written. + + Special thanks Rob Adams, Cheryl Madson, Derrell Piper, Harry Varnis, + and Elfed Weaver for technical input, encouragement, and various + sanity checks along the way. + + We would also like to thank the many members of the IPSec working + group that contributed to the development of this protocol over the + past year. + +13. References + + [CAST] Adams, C., "The CAST-128 Encryption Algorithm", RFC 2144, + May 1997. + + [BLOW] Schneier, B., "The Blowfish Encryption Algorithm", Dr. + Dobb's Journal, v. 19, n. 4, April 1994. + + [Bra97] Bradner, S., "Key Words for use in RFCs to indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + [DES] ANSI X3.106, "American National Standard for Information + Systems-Data Link Encryption", American National Standards + Institute, 1983. + + [DH] Diffie, W., and Hellman M., "New Directions in + Cryptography", IEEE Transactions on Information Theory, V. + IT-22, n. 6, June 1977. + + + + + + +Harkins & Carrel Standards Track [Page 31] + +RFC 2409 IKE November 1998 + + + [DSS] NIST, "Digital Signature Standard", FIPS 186, National + Institute of Standards and Technology, U.S. Department of + Commerce, May, 1994. + + [IDEA] Lai, X., "On the Design and Security of Block Ciphers," ETH + Series in Information Processing, v. 1, Konstanz: Hartung- + Gorre Verlag, 1992 + + [KBC96] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed- + Hashing for Message Authentication", RFC 2104, February + 1997. + + [SKEME] Krawczyk, H., "SKEME: A Versatile Secure Key Exchange + Mechanism for Internet", from IEEE Proceedings of the 1996 + Symposium on Network and Distributed Systems Security. + + [MD5] Rivest, R., "The MD5 Message Digest Algorithm", RFC 1321, + April 1992. + + [MSST98] Maughhan, D., Schertler, M., Schneider, M., and J. Turner, + "Internet Security Association and Key Management Protocol + (ISAKMP)", RFC 2408, November 1998. + + [Orm96] Orman, H., "The Oakley Key Determination Protocol", RFC + 2412, November 1998. + + [PKCS1] RSA Laboratories, "PKCS #1: RSA Encryption Standard", + November 1993. + + [Pip98] Piper, D., "The Internet IP Security Domain Of + Interpretation for ISAKMP", RFC 2407, November 1998. + + [RC5] Rivest, R., "The RC5 Encryption Algorithm", Dr. Dobb's + Journal, v. 20, n. 1, January 1995. + + [RSA] Rivest, R., Shamir, A., and Adleman, L., "A Method for + Obtaining Digital Signatures and Public-Key Cryptosystems", + Communications of the ACM, v. 21, n. 2, February 1978. + + [Sch96] Schneier, B., "Applied Cryptography, Protocols, Algorithms, + and Source Code in C", 2nd edition. + + [SHA] NIST, "Secure Hash Standard", FIPS 180-1, National Institue + of Standards and Technology, U.S. Department of Commerce, + May 1994. + + [TIGER] Anderson, R., and Biham, E., "Fast Software Encryption", + Springer LNCS v. 1039, 1996. + + + +Harkins & Carrel Standards Track [Page 32] + +RFC 2409 IKE November 1998 + + +Appendix A + + This is a list of DES Weak and Semi-Weak keys. The keys come from + [Sch96]. All keys are listed in hexidecimal. + + DES Weak Keys + 0101 0101 0101 0101 + 1F1F 1F1F E0E0 E0E0 + E0E0 E0E0 1F1F 1F1F + FEFE FEFE FEFE FEFE + + DES Semi-Weak Keys + 01FE 01FE 01FE 01FE + 1FE0 1FE0 0EF1 0EF1 + 01E0 01E0 01F1 01F1 + 1FFE 1FFE 0EFE 0EFE + 011F 011F 010E 010E + E0FE E0FE F1FE F1FE + + FE01 FE01 FE01 FE01 + E01F E01F F10E F10E + E001 E001 F101 F101 + FE1F FE1F FE0E FE0E + 1F01 1F01 0E01 0E01 + FEE0 FEE0 FEF1 FEF1 + + Attribute Assigned Numbers + + Attributes negotiated during phase one use the following definitions. + Phase two attributes are defined in the applicable DOI specification + (for example, IPsec attributes are defined in the IPsec DOI), with + the exception of a group description when Quick Mode includes an + ephemeral Diffie-Hellman exchange. Attribute types can be either + Basic (B) or Variable-length (V). Encoding of these attributes is + defined in the base ISAKMP specification as Type/Value (Basic) and + Type/Length/Value (Variable). + + Attributes described as basic MUST NOT be encoded as variable. + Variable length attributes MAY be encoded as basic attributes if + their value can fit into two octets. If this is the case, an + attribute offered as variable (or basic) by the initiator of this + protocol MAY be returned to the initiator as a basic (or variable). + + + + + + + + + +Harkins & Carrel Standards Track [Page 33] + +RFC 2409 IKE November 1998 + + + Attribute Classes + + class value type + ------------------------------------------------------------------- + Encryption Algorithm 1 B + Hash Algorithm 2 B + Authentication Method 3 B + Group Description 4 B + Group Type 5 B + Group Prime/Irreducible Polynomial 6 V + Group Generator One 7 V + Group Generator Two 8 V + Group Curve A 9 V + Group Curve B 10 V + Life Type 11 B + Life Duration 12 V + PRF 13 B + Key Length 14 B + Field Size 15 B + Group Order 16 V + + values 17-16383 are reserved to IANA. Values 16384-32767 are for + private use among mutually consenting parties. + + Class Values + + - Encryption Algorithm Defined In + DES-CBC 1 RFC 2405 + IDEA-CBC 2 + Blowfish-CBC 3 + RC5-R16-B64-CBC 4 + 3DES-CBC 5 + CAST-CBC 6 + + values 7-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. + + - Hash Algorithm Defined In + MD5 1 RFC 1321 + SHA 2 FIPS 180-1 + Tiger 3 See Reference [TIGER] + + values 4-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. + + + + + + + +Harkins & Carrel Standards Track [Page 34] + +RFC 2409 IKE November 1998 + + + - Authentication Method + pre-shared key 1 + DSS signatures 2 + RSA signatures 3 + Encryption with RSA 4 + Revised encryption with RSA 5 + + values 6-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. + + - Group Description + default 768-bit MODP group (section 6.1) 1 + + alternate 1024-bit MODP group (section 6.2) 2 + + EC2N group on GP[2^155] (section 6.3) 3 + + EC2N group on GP[2^185] (section 6.4) 4 + + values 5-32767 are reserved to IANA. Values 32768-65535 are for + private use among mutually consenting parties. + + - Group Type + MODP (modular exponentiation group) 1 + ECP (elliptic curve group over GF[P]) 2 + EC2N (elliptic curve group over GF[2^N]) 3 + + values 4-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. + + - Life Type + seconds 1 + kilobytes 2 + + values 3-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. For a given "Life + Type" the value of the "Life Duration" attribute defines the actual + length of the SA life-- either a number of seconds, or a number of + kbytes protected. + + - PRF + There are currently no pseudo-random functions defined. + + values 1-65000 are reserved to IANA. Values 65001-65535 are for + private use among mutually consenting parties. + + + + + + +Harkins & Carrel Standards Track [Page 35] + +RFC 2409 IKE November 1998 + + + - Key Length + + When using an Encryption Algorithm that has a variable length key, + this attribute specifies the key length in bits. (MUST use network + byte order). This attribute MUST NOT be used when the specified + Encryption Algorithm uses a fixed length key. + + - Field Size + + The field size, in bits, of a Diffie-Hellman group. + + - Group Order + + The group order of an elliptical curve group. Note the length of + this attribute depends on the field size. + + Additional Exchanges Defined-- XCHG values + Quick Mode 32 + New Group Mode 33 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Harkins & Carrel Standards Track [Page 36] + +RFC 2409 IKE November 1998 + + +Appendix B + + This appendix describes encryption details to be used ONLY when + encrypting ISAKMP messages. When a service (such as an IPSEC + transform) utilizes ISAKMP to generate keying material, all + encryption algorithm specific details (such as key and IV generation, + padding, etc...) MUST be defined by that service. ISAKMP does not + purport to ever produce keys that are suitable for any encryption + algorithm. ISAKMP produces the requested amount of keying material + from which the service MUST generate a suitable key. Details, such + as weak key checks, are the responsibility of the service. + + Use of negotiated PRFs may require the PRF output to be expanded due + to the PRF feedback mechanism employed by this document. For example, + if the (ficticious) DOORAK-MAC requires 24 bytes of key but produces + only 8 bytes of output, the output must be expanded three times + before being used as the key for another instance of itself. The + output of a PRF is expanded by feeding back the results of the PRF + into itself to generate successive blocks. These blocks are + concatenated until the requisite number of bytes has been acheived. + For example, for pre-shared key authentication with DOORAK-MAC as the + negotiated PRF: + + BLOCK1-8 = prf(pre-shared-key, Ni_b | Nr_b) + BLOCK9-16 = prf(pre-shared-key, BLOCK1-8 | Ni_b | Nr_b) + BLOCK17-24 = prf(pre-shared-key, BLOCK9-16 | Ni_b | Nr_b) + and + SKEYID = BLOCK1-8 | BLOCK9-16 | BLOCK17-24 + + so therefore to derive SKEYID_d: + + BLOCK1-8 = prf(SKEYID, g^xy | CKY-I | CKY-R | 0) + BLOCK9-16 = prf(SKEYID, BLOCK1-8 | g^xy | CKY-I | CKY-R | 0) + BLOCK17-24 = prf(SKEYID, BLOCK9-16 | g^xy | CKY-I | CKY-R | 0) + and + SKEYID_d = BLOCK1-8 | BLOCK9-16 | BLOCK17-24 + + Subsequent PRF derivations are done similarly. + + Encryption keys used to protect the ISAKMP SA are derived from + SKEYID_e in an algorithm-specific manner. When SKEYID_e is not long + enough to supply all the necessary keying material an algorithm + requires, the key is derived from feeding the results of a pseudo- + random function into itself, concatenating the results, and taking + the highest necessary bits. + + + + + + +Harkins & Carrel Standards Track [Page 37] + +RFC 2409 IKE November 1998 + + + For example, if (ficticious) algorithm AKULA requires 320-bits of key + (and has no weak key check) and the prf used to generate SKEYID_e + only generates 120 bits of material, the key for AKULA, would be the + first 320-bits of Ka, where: + + Ka = K1 | K2 | K3 + and + K1 = prf(SKEYID_e, 0) + K2 = prf(SKEYID_e, K1) + K3 = prf(SKEYID_e, K2) + + where prf is the negotiated prf or the HMAC version of the negotiated + hash function (if no prf was negotiated) and 0 is represented by a + single octet. Each result of the prf provides 120 bits of material + for a total of 360 bits. AKULA would use the first 320 bits of that + 360 bit string. + + In phase 1, material for the initialization vector (IV material) for + CBC mode encryption algorithms is derived from a hash of a + concatenation of the initiator's public Diffie-Hellman value and the + responder's public Diffie-Hellman value using the negotiated hash + algorithm. This is used for the first message only. Each message + should be padded up to the nearest block size using bytes containing + 0x00. The message length in the header MUST include the length of the + pad since this reflects the size of the ciphertext. Subsequent + messages MUST use the last CBC encryption block from the previous + message as their initialization vector. + + In phase 2, material for the initialization vector for CBC mode + encryption of the first message of a Quick Mode exchange is derived + from a hash of a concatenation of the last phase 1 CBC output block + and the phase 2 message id using the negotiated hash algorithm. The + IV for subsequent messages within a Quick Mode exchange is the CBC + output block from the previous message. Padding and IVs for + subsequent messages are done as in phase 1. + + After the ISAKMP SA has been authenticated all Informational + Exchanges are encrypted using SKEYID_e. The initiaization vector for + these exchanges is derived in exactly the same fashion as that for a + Quick Mode-- i.e. it is derived from a hash of a concatenation of the + last phase 1 CBC output block and the message id from the ISAKMP + header of the Informational Exchange (not the message id from the + message that may have prompted the Informational Exchange). + + Note that the final phase 1 CBC output block, the result of + encryption/decryption of the last phase 1 message, must be retained + in the ISAKMP SA state to allow for generation of unique IVs for each + Quick Mode. Each post- phase 1 exchange (Quick Modes and + + + +Harkins & Carrel Standards Track [Page 38] + +RFC 2409 IKE November 1998 + + + Informational Exchanges) generates IVs independantly to prevent IVs + from getting out of sync when two different exchanges are started + simultaneously. + + In all cases, there is a single bidirectional cipher/IV context. + Having each Quick Mode and Informational Exchange maintain a unique + context prevents IVs from getting out of sync. + + The key for DES-CBC is derived from the first eight (8) non-weak and + non-semi-weak (see Appendix A) bytes of SKEYID_e. The IV is the first + 8 bytes of the IV material derived above. + + The key for IDEA-CBC is derived from the first sixteen (16) bytes of + SKEYID_e. The IV is the first eight (8) bytes of the IV material + derived above. + + The key for Blowfish-CBC is either the negotiated key size, or the + first fifty-six (56) bytes of a key (if no key size is negotiated) + derived in the aforementioned pseudo-random function feedback method. + The IV is the first eight (8) bytes of the IV material derived above. + + The key for RC5-R16-B64-CBC is the negotiated key size, or the first + sixteen (16) bytes of a key (if no key size is negotiated) derived + from the aforementioned pseudo-random function feedback method if + necessary. The IV is the first eight (8) bytes of the IV material + derived above. The number of rounds MUST be 16 and the block size + MUST be 64. + + The key for 3DES-CBC is the first twenty-four (24) bytes of a key + derived in the aforementioned pseudo-random function feedback method. + 3DES-CBC is an encrypt-decrypt-encrypt operation using the first, + middle, and last eight (8) bytes of the entire 3DES-CBC key. The IV + is the first eight (8) bytes of the IV material derived above. + + The key for CAST-CBC is either the negotiated key size, or the first + sixteen (16) bytes of a key derived in the aforementioned pseudo- + random function feedback method. The IV is the first eight (8) bytes + of the IV material derived above. + + Support for algorithms other than DES-CBC is purely optional. Some + optional algorithms may be subject to intellectual property claims. + + + + + + + + + + +Harkins & Carrel Standards Track [Page 39] + +RFC 2409 IKE November 1998 + + +Authors' Addresses + + Dan Harkins + cisco Systems + 170 W. Tasman Dr. + San Jose, California, 95134-1706 + United States of America + + Phone: +1 408 526 4000 + EMail: dharkins@cisco.com + + + Dave Carrel + 76 Lippard Ave. + San Francisco, CA 94131-2947 + United States of America + + Phone: +1 415 337 8469 + EMail: carrel@ipsec.org + +Authors' Note + + The authors encourage independent implementation, and + interoperability testing, of this hybrid protocol. + + + + + + + + + + + + + + + + + + + + + + + + + + + +Harkins & Carrel Standards Track [Page 40] + +RFC 2409 IKE November 1998 + + +Full Copyright Statement + + Copyright (C) The Internet Society (1998). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + + + + + + + + + + + + + + + + + + + + + +Harkins & Carrel Standards Track [Page 41] + diff --git a/doc/ikev2/[RFC2412] - The OAKLEY Key Determination Protocol.txt b/doc/ikev2/[RFC2412] - The OAKLEY Key Determination Protocol.txt new file mode 100644 index 000000000..9169d78be --- /dev/null +++ b/doc/ikev2/[RFC2412] - The OAKLEY Key Determination Protocol.txt @@ -0,0 +1,3083 @@ + + + + + + +Network Working Group H. Orman +Request for Comments: 2412 Department of Computer Science +Category: Informational University of Arizona + November 1998 + + + The OAKLEY Key Determination Protocol + +Status of this Memo + + This memo provides information for the Internet community. It does + not specify an Internet standard of any kind. Distribution of this + memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (1998). All Rights Reserved. + +Abstract + + This document describes a protocol, named OAKLEY, by which two + authenticated parties can agree on secure and secret keying material. + The basic mechanism is the Diffie-Hellman key exchange algorithm. + + The OAKLEY protocol supports Perfect Forward Secrecy, compatibility + with the ISAKMP protocol for managing security associations, user- + defined abstract group structures for use with the Diffie-Hellman + algorithm, key updates, and incorporation of keys distributed via + out-of-band mechanisms. + +1. INTRODUCTION + + Key establishment is the heart of data protection that relies on + cryptography, and it is an essential component of the packet + protection mechanisms described in [RFC2401], for example. A + scalable and secure key distribution mechanism for the Internet is a + necessity. The goal of this protocol is to provide that mechanism, + coupled with a great deal of cryptographic strength. + + The Diffie-Hellman key exchange algorithm provides such a mechanism. + It allows two parties to agree on a shared value without requiring + encryption. The shared value is immediately available for use in + encrypting subsequent conversation, e.g. data transmission and/or + authentication. The STS protocol [STS] provides a demonstration of + how to embed the algorithm in a secure protocol, one that ensures + that in addition to securely sharing a secret, the two parties can be + sure of each other's identities, even when an active attacker exists. + + + + +Orman Informational [Page 1] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + Because OAKLEY is a generic key exchange protocol, and because the + keys that it generates might be used for encrypting data with a long + privacy lifetime, 20 years or more, it is important that the + algorithms underlying the protocol be able to ensure the security of + the keys for that period of time, based on the best prediction + capabilities available for seeing into the mathematical future. The + protocol therefore has two options for adding to the difficulties + faced by an attacker who has a large amount of recorded key exchange + traffic at his disposal (a passive attacker). These options are + useful for deriving keys which will be used for encryption. + + The OAKLEY protocol is related to STS, sharing the similarity of + authenticating the Diffie-Hellman exponentials and using them for + determining a shared key, and also of achieving Perfect Forward + Secrecy for the shared key, but it differs from the STS protocol in + several ways. + + The first is the addition of a weak address validation mechanism + ("cookies", described by Phil Karn in the Photuris key exchange + protocol work in progress) to help avoid denial of service + attacks. + + The second extension is to allow the two parties to select + mutually agreeable supporting algorithms for the protocol: the + encryption method, the key derivation method, and the + authentication method. + + Thirdly, the authentication does not depend on encryption using + the Diffie-Hellman exponentials; instead, the authentication + validates the binding of the exponentials to the identities of the + parties. + + The protocol does not require the two parties compute the shared + exponentials prior to authentication. + + This protocol adds additional security to the derivation of keys + meant for use with encryption (as opposed to authentication) by + including a dependence on an additional algorithm. The derivation + of keys for encryption is made to depend not only on the Diffie- + Hellman algorithm, but also on the cryptographic method used to + securely authenticate the communicating parties to each other. + + Finally, this protocol explicitly defines how the two parties can + select the mathematical structures (group representation and + operation) for performing the Diffie-Hellman algorithm; they can + use standard groups or define their own. User-defined groups + provide an additional degree of long-term security. + + + + +Orman Informational [Page 2] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + OAKLEY has several options for distributing keys. In addition to the + classic Diffie-Hellman exchange, this protocol can be used to derive + a new key from an existing key and to distribute an externally + derived key by encrypting it. + + The protocol allows two parties to use all or some of the anti- + clogging and perfect forward secrecy features. It also permits the + use of authentication based on symmetric encryption or non-encryption + algorithms. This flexibility is included in order to allow the + parties to use the features that are best suited to their security + and performance requirements. + + This document draws extensively in spirit and approach from the + Photuris work in progress by Karn and Simpson (and from discussions + with the authors), specifics of the ISAKMP document by Schertler et + al. the ISAKMP protocol document, and it was also influenced by + papers by Paul van Oorschot and Hugo Krawcyzk. + +2. The Protocol Outline + +2.1 General Remarks + + The OAKLEY protocol is used to establish a shared key with an + assigned identifier and associated authenticated identities for the + two parties. The name of the key can be used later to derive + security associations for the RFC 2402 and RFC 2406 protocols (AH and + ESP) or to achieve other network security goals. + + Each key is associated with algorithms that are used for + authentication, privacy, and one-way functions. These are ancillary + algorithms for OAKLEY; their appearance in subsequent security + association definitions derived with other protocols is neither + required nor prohibited. + + The specification of the details of how to apply an algorithm to data + is called a transform. This document does not supply the transform + definitions; they will be in separate RFC's. + + The anti-clogging tokens, or "cookies", provide a weak form of source + address identification for both parties; the cookie exchange can be + completed before they perform the computationally expensive part of + the protocol (large integer exponentiations). + + It is important to note that OAKLEY uses the cookies for two + purposes: anti-clogging and key naming. The two parties to the + protocol each contribute one cookie at the initiation of key + establishment; the pair of cookies becomes the key identifier + (KEYID), a reusable name for the keying material. Because of this + + + +Orman Informational [Page 3] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + dual role, we will use the notation for the concatenation of the + cookies ("COOKIE-I, COOKIE-R") interchangeably with the symbol + "KEYID". + + OAKLEY is designed to be a compatible component of the ISAKMP + protocol [ISAKMP], which runs over the UDP protocol using a well- + known port (see the RFC on port assignments, STD02-RFC-1700). The + only technical requirement for the protocol environment is that the + underlying protocol stack must be able to supply the Internet address + of the remote party for each message. Thus, OAKLEY could, in theory, + be used directly over the IP protocol or over UDP, if suitable + protocol or port number assignments were available. + + The machine running OAKLEY must provide a good random number + generator, as described in [RANDOM], as the source of random numbers + required in this protocol description. Any mention of a "nonce" + implies that the nonce value is generated by such a generator. The + same is true for "pseudorandom" values. + +2.2 Notation + + The section describes the notation used in this document for message + sequences and content. + +2.2.1 Message descriptions + + The protocol exchanges below are written in an abbreviated notation + that is intended to convey the essential elements of the exchange in + a clear manner. A brief guide to the notation follows. The detailed + formats and assigned values are given in the appendices. + + In order to represent message exchanges succinctly, this document + uses an abbreviated notation that describes each message in terms of + its source and destination and relevant fields. + + Arrows ("->") indicate whether the message is sent from the initiator + to the responder, or vice versa ("<-"). + + The fields in the message are named and comma separated. The + protocol uses the convention that the first several fields constitute + a fixed header format for all messages. + + For example, consider a HYPOTHETICAL exchange of messages involving a + fixed format message, the four fixed fields being two "cookies", the + third field being a message type name, the fourth field being a + multi-precision integer representing a power of a number: + + + + + +Orman Informational [Page 4] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + Initiator Responder + -> Cookie-I, 0, OK_KEYX, g^x -> + <- Cookie-R, Cookie-I, OK_KEYX, g^y <- + + The notation describes a two message sequence. The initiator begins + by sending a message with 4 fields to the responder; the first field + has the unspecified value "Cookie-I", second field has the numeric + value 0, the third field indicates the message type is OK_KEYX, the + fourth value is an abstract group element g to the x'th power. + + The second line indicates that the responder replies with value + "Cookie-R" in the first field, a copy of the "Cookie-I" value in the + second field, message type OK_KEYX, and the number g raised to the + y'th power. + + The value OK_KEYX is in capitals to indicate that it is a unique + constant (constants are defined in the appendices). + + Variable precision integers with length zero are null values for the + protocol. + + Sometimes the protocol will indicate that an entire payload (usually + the Key Exchange Payload) has null values. The payload is still + present in the message, for the purpose of simplifying parsing. + +2.2.2 Guide to symbols + + Cookie-I and Cookie-R (or CKY-I and CKY-R) are 64-bit pseudo-random + numbers. The generation method must ensure with high probability + that the numbers used for each IP remote address are unique over some + time period, such as one hour. + + KEYID is the concatenation of the initiator and responder cookies and + the domain of interpretation; it is the name of keying material. + + sKEYID is used to denote the keying material named by the KEYID. It + is never transmitted, but it is used in various calculations + performed by the two parties. + + OK_KEYX and OK_NEWGRP are distinct message types. + + IDP is a bit indicating whether or not material after the encryption + boundary (see appendix B), is encrypted. NIDP means not encrypted. + + g^x and g^y are encodings of group elements, where g is a special + group element indicated in the group description (see Appendix A) and + g^x indicates that element raised to the x'th power. The type of the + encoding is either a variable precision integer or a pair of such + + + +Orman Informational [Page 5] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + integers, as indicated in the group operation in the group + description. Note that we will write g^xy as a short-hand for + g^(xy). See Appendix F for references that describe implementing + large integer computations and the relationship between various group + definitions and basic arithmetic operations. + + EHAO is a list of encryption/hash/authentication choices. Each item + is a pair of values: a class name and an algorithm name. + + EHAS is a set of three items selected from the EHAO list, one from + each of the classes for encryption, hash, authentication. + + GRP is a name (32-bit value) for the group and its relevant + parameters: the size of the integers, the arithmetic operation, and + the generator element. There are a few pre-defined GRP's (for 768 + bit modular exponentiation groups, 1024 bit modexp, 2048 bit modexp, + 155-bit and 210-bit elliptic curves, see Appendix E), but + participants can share other group descriptions in a later protocol + stage (see the section NEW GROUP). It is important to separate + notion of the GRP from the group descriptor (Appendix A); the former + is a name for the latter. + + The symbol vertical bar "|" is used to denote concatenation of bit + strings. Fields are concatenated using their encoded form as they + appear in their payload. + + Ni and Nr are nonces selected by the initiator and responder, + respectively. + + ID(I) and ID(R) are the identities to be used in authenticating the + initiator and responder respectively. + + E{x}Ki indicates the encryption of x using the public key of the + initiator. Encryption is done using the algorithm associated with + the authentication method; usually this will be RSA. + + S{x}Ki indicates the signature over x using the private key (signing + key) of the initiator. Signing is done using the algorithm + associated with the authentication method; usually this will be RSA + or DSS. + + prf(a, b) denotes the result of applying pseudo-random function "a" + to data "b". One may think of "a" as a key or as a value that + characterizes the function prf; in the latter case it is the index + into a family of functions. Each function in the family provides a + "hash" or one-way mixing of the input. + + prf(0, b) denotes the application of a one-way function to data "b". + + + +Orman Informational [Page 6] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The similarity with the previous notation is deliberate and indicates + that a single algorithm, e.g. MD5, might will used for both purposes. + In the first case a "keyed" MD5 transform would be used with key "a"; + in the second case the transform would have the fixed key value zero, + resulting in a one-way function. + + The term "transform" is used to refer to functions defined in + auxiliary RFC's. The transform RFC's will be drawn from those + defined for IPSEC AH and ESP (see RFC 2401 for the overall + architecture encompassing these protocols). + +2.3 The Key Exchange Message Overview + + The goal of key exchange processing is the secure establishment of + common keying information state in the two parties. This state + information is a key name, secret keying material, the identification + of the two parties, and three algorithms for use during + authentication: encryption (for privacy of the identities of the two + parties), hashing (a pseudorandom function for protecting the + integrity of the messages and for authenticating message fields), and + authentication (the algorithm on which the mutual authentication of + the two parties is based). The encodings and meanings for these + choices are presented in Appendix B. + + The main mode exchange has five optional features: stateless cookie + exchange, perfect forward secrecy for the keying material, secrecy + for the identities, perfect forward secrecy for identity secrecy, use + of signatures (for non-repudiation). The two parties can use any + combination of these features. + + The general outline of processing is that the Initiator of the + exchange begins by specifying as much information as he wishes in his + first message. The Responder replies, supplying as much information + as he wishes. The two sides exchange messages, supplying more + information each time, until their requirements are satisfied. + + The choice of how much information to include in each message depends + on which options are desirable. For example, if stateless cookies + are not a requirement, and identity secrecy and perfect forward + secrecy for the keying material are not requirements, and if non- + repudiatable signatures are acceptable, then the exchange can be + completed in three messages. + + Additional features may increase the number of roundtrips needed for + the keying material determination. + + ISAKMP provides fields for specifying the security association + parameters for use with the AH and ESP protocols. These security + + + +Orman Informational [Page 7] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + association payload types are specified in the ISAKMP memo; the + payload types can be protected with OAKLEY keying material and + algorithms, but this document does not discuss their use. + +2.3.1 The Essential Key Exchange Message Fields + + There are 12 fields in an OAKLEY key exchange message. Not all the + fields are relevant in every message; if a field is not relevant it + can have a null value or not be present (no payload). + + CKY-I originator cookie. + CKY-R responder cookie. + MSGTYPE for key exchange, will be ISA_KE&AUTH_REQ or + ISA_KE&AUTH_REP; for new group definitions, + will be ISA_NEW_GROUP_REQ or ISA_NEW_GROUP_REP + GRP the name of the Diffie-Hellman group used for + the exchange + g^x (or g^y) variable length integer representing a power of + group generator + EHAO or EHAS encryption, hash, authentication functions, + offered and selectedj, respectively + IDP an indicator as to whether or not encryption with + g^xy follows (perfect forward secrecy for ID's) + ID(I) the identity for the Initiator + ID(R) the identity for the Responder + Ni nonce supplied by the Initiator + Nr nonce supplied by the Responder + + The construction of the cookies is implementation dependent. Phil + Karn has recommended making them the result of a one-way function + applied to a secret value (changed periodically), the local and + remote IP address, and the local and remote UDP port. In this way, + the cookies remain stateless and expire periodically. Note that with + OAKLEY, this would cause the KEYID's derived from the secret value to + also expire, necessitating the removal of any state information + associated with it. + + In order to support pre-distributed keys, we recommend that + implementations reserve some portion of their cookie space to + permanent keys. The encoding of these depends only on the local + implementation. + + The encryption functions used with OAKLEY must be cryptographic + transforms which guarantee privacy and integrity for the message + data. Merely using DES in CBC mode is not permissible. The + MANDATORY and OPTIONAL transforms will include any that satisfy this + criteria and are defined for use with RFC 2406 (ESP). + + + + +Orman Informational [Page 8] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The one-way (hash) functions used with OAKLEY must be cryptographic + transforms which can be used as either keyed hash (pseudo-random) or + non-keyed transforms. The MANDATORY and OPTIONAL transforms will + include any that are defined for use with RFC 2406 (AH). + + Where nonces are indicated, they will be variable precision integers + with an entropy value that matches the "strength" attribute of the + GRP used with the exchange. If no GRP is indicated, the nonces must + be at least 90 bits long. The pseudo-random generator for the nonce + material should start with initial data that has at least 90 bits of + entropy; see RFC 1750. + +2.3.1.1 Exponent Advice + + Ideally, the exponents will have at least 180 bits of entropy for + every key exchange. This ensures complete independence of keying + material between two exchanges (note that this applies if only one of + the parties chooses a random exponent). In practice, implementors + may wish to base several key exchanges on a single base value with + 180 bits of entropy and use one-way hash functions to guarantee that + exposure of one key will not compromise others. In this case, a good + recommendation is to keep the base values for nonces and cookies + separate from the base value for exponents, and to replace the base + value with a full 180 bits of entropy as frequently as possible. + + The values 0 and p-1 should not be used as exponent values; + implementors should be sure to check for these values, and they + should also refuse to accept the values 1 and p-1 from remote parties + (where p is the prime used to define a modular exponentiation group). + +2.3.2 Mapping to ISAKMP Message Structures + + All the OAKLEY message fields correspond to ISAKMP message payloads + or payload components. The relevant payload fields are the SA + payload, the AUTH payload, the Certificate Payload, the Key Exchange + Payload. The ISAKMP protocol framwork is a work in progress at this + time, and the exact mapping of Oakley message fields to ISAKMP + payloads is also in progress (to be known as the Resolution + document). + + Some of the ISAKMP header and payload fields will have constant + values when used with OAKLEY. The exact values to be used will be + published in a Domain of Interpretation document accompanying the + Resolution document. + + In the following we indicate where each OAKLEY field appears in the + ISAKMP message structure. These are recommended only; the Resolution + document will be the final authority on this mapping. + + + +Orman Informational [Page 9] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + CKY-I ISAKMP header + CKY-R ISAKMP header + MSGTYPE Message Type in ISAKMP header + GRP SA payload, Proposal section + g^x (or g^y) Key Exchange Payload, encoded as a variable + precision integer + EHAO and EHAS SA payload, Proposal section + IDP A bit in the RESERVED field in the AUTH header + ID(I) AUTH payload, Identity field + ID(R) AUTH payload, Identity field + Ni AUTH payload, Nonce Field + Nr AUTH payload, Nonce Field + S{...}Kx AUTH payload, Data Field + prf{K,...} AUTH payload, Data Field + +2.4 The Key Exchange Protocol + + The exact number and content of messages exchanged during an OAKLEY + key exchange depends on which options the Initiator and Responder + want to use. A key exchange can be completed with three or more + messages, depending on those options. + + The three components of the key determination protocol are the + + 1. cookie exchange (optionally stateless) + 2. Diffie-Hellman half-key exchange (optional, but essential for + perfect forward secrecy) + 3. authentication (options: privacy for ID's, privacy for ID's + with PFS, non-repudiatable) + + The initiator can supply as little information as a bare exchange + request, carrying no additional information. On the other hand the + initiator can begin by supplying all of the information necessary for + the responder to authenticate the request and complete the key + determination quickly, if the responder chooses to accept this + method. If not, the responder can reply with a minimal amount of + information (at the minimum, a cookie). + + The method of authentication can be digital signatures, public key + encryption, or an out-of-band symmetric key. The three different + methods lead to slight variations in the messages, and the variations + are illustrated by examples in this section. + + The Initiator is responsible for retransmitting messages if the + protocol does not terminate in a timely fashion. The Responder must + therefore avoid discarding reply information until it is acknowledged + by Initiator in the course of continuing the protocol. + + + + +Orman Informational [Page 10] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The remainder of this section contains examples demonstrating how to + use OAKLEY options. + +2.4.1 An Aggressive Example + + The following example indicates how two parties can complete a key + exchange in three messages. The identities are not secret, the + derived keying material is protected by PFS. + + By using digital signatures, the two parties will have a proof of + communication that can be recorded and presented later to a third + party. + + The keying material implied by the group exponentials is not needed + for completing the exchange. If it is desirable to defer the + computation, the implementation can save the "x" and "g^y" values and + mark the keying material as "uncomputed". It can be computed from + this information later. + + Initiator Responder + --------- --------- + -> CKY-I, 0, OK_KEYX, GRP, g^x, EHAO, NIDP, -> + ID(I), ID(R), Ni, 0, + S{ID(I) | ID(R) | Ni | 0 | GRP | g^x | 0 | EHAO}Ki + <- CKY-R, CKY-I, OK_KEYX, GRP, g^y, EHAS, NIDP, + ID(R), ID(I), Nr, Ni, + S{ID(R) | ID(I) | Nr | Ni | GRP | g^y | g^x | EHAS}Kr <- + -> CKY-I, CKY-R, OK_KEYX, GRP, g^x, EHAS, NIDP, -> + ID(I), ID(R), Ni, Nr, + S{ID(I) | ID(R) | Ni | Nr | GRP | g^x | g^y | EHAS}Ki + + NB "NIDP" means that the PFS option for hiding identities is not used. + i.e., the identities are not encrypted using a key based on g^xy + + NB Fields are shown separated by commas in this document; they are + concatenated in the actual protocol messages using their encoded + forms as specified in the ISAKMP/Oakley Resolution document. + + The result of this exchange is a key with KEYID = CKY-I|CKY-R and + value + + sKEYID = prf(Ni | Nr, g^xy | CKY-I | CKY-R). + + The processing outline for this exchange is as follows: + + + + + + + +Orman Informational [Page 11] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + Initiation + + The Initiator generates a unique cookie and associates it with the + expected IP address of the responder, and its chosen state + information: GRP (the group identifier), a pseudo-randomly + selected exponent x, g^x, EHAO list, nonce, identities. The first + authentication choice in the EHAO list is an algorithm that + supports digital signatures, and this is used to sign the ID's and + the nonce and group id. The Initiator further + + notes that the key is in the initial state of "unauthenticated", + and + + sets a timer for possible retransmission and/or termination of the + request. + + When the Responder receives the message, he may choose to ignore all + the information and treat it as merely a request for a cookie, + creating no state. If CKY-I is not already in use by the source + address in the IP header, the responder generates a unique cookie, + CKY-R. The next steps depend on the Responder's preferences. The + minimal required response is to reply with the first cookie field set + to zero and CKY-R in the second field. For this example we will + assume that the responder is more aggressive (for the alternatives, + see section 6) and accepts the following: + + group with identifier GRP, + first authentication choice (which must be the digital signature + method used to sign the Initiator message), + lack of perfect forward secrecy for protecting the identities, + identity ID(I) and identity ID(R) + + In this example the Responder decides to accept all the information + offered by the initiator. It validates the signature over the signed + portion of the message, and associate the pair (CKY-I, CKY-R) with + the following state information: + + the source and destination network addresses of the message + + key state of "unauthenticated" + + the first algorithm from the authentication offer + + group GRP, a "y" exponent value in group GRP, and g^x from the + message + + the nonce Ni and a pseudorandomly selected value Nr + + + + +Orman Informational [Page 12] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + a timer for possible destruction of the state. + + The Responder computes g^y, forms the reply message, and then signs + the ID and nonce information with the private key of ID(R) and sends + it to the Initiator. In all exchanges, each party should make sure + that he neither offers nor accepts 1 or g^(p-1) as an exponential. + + In this example, to expedite the protocol, the Responder implicitly + accepts the first algorithm in the Authentication class of the EHAO + list. This because he cannot validate the Initiator signature + without accepting the algorithm for doing the signature. The + Responder's EHAS list will also reflect his acceptance. + + The Initiator receives the reply message and + validates that CKY-I is a valid association for the network + address of the incoming message, + + adds the CKY-R value to the state for the pair (CKY-I, network + address), and associates all state information with the pair + (CKY-I, CKY-R), + + validates the signature of the responder over the state + information (should validation fail, the message is discarded) + + adds g^y to its state information, + + saves the EHA selections in the state, + + optionally computes (g^y)^x (= g^xy) (this can be deferred until + after sending the reply message), + + sends the reply message, signed with the public key of ID(I), + + marks the KEYID (CKY-I|CKY-R) as authenticated, + + and composes the reply message and signature. + + When the Responder receives the Initiator message, and if the + signature is valid, it marks the key as being in the authenticated + state. It should compute g^xy and associate it with the KEYID. + + Note that although PFS for identity protection is not used, PFS for + the derived keying material is still present because the Diffie- + Hellman half-keys g^x and g^y are exchanged. + + Even if the Responder only accepts some of the Initiator information, + the Initiator will consider the protocol to be progressing. The + Initiator should assume that fields that were not accepted by the + + + +Orman Informational [Page 13] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + Responder were not recorded by the Responder. + + If the Responder does not accept the aggressive exchange and selects + another algorithm for the A function, then the protocol will not + continue using the signature algorithm or the signature value from + the first message. + +2.4.1.1 Fields Not Present + + If the Responder does not accept all the fields offered by the + Initiator, he should include null values for those fields in his + response. Section 6 has guidelines on how to select fields in a + "left-to-right" manner. If a field is not accepted, then it and all + following fields must have null values. + + The Responder should not record any information that it does not + accept. If the ID's and nonces have null values, there will not be a + signature over these null values. + +2.4.1.2 Signature via Pseudo-Random Functions + + The aggressive example is written to suggest that public key + technology is used for the signatures. However, a pseudorandom + function can be used, if the parties have previously agreed to such a + scheme and have a shared key. + + If the first proposal in the EHAO list is an "existing key" method, + then the KEYID named in that proposal will supply the keying material + for the "signature" which is computed using the "H" algorithm + associated with the KEYID. + + Suppose the first proposal in EHAO is + EXISTING-KEY, 32 + and the "H" algorithm for KEYID 32 is MD5-HMAC, by prior negotiation. + The keying material is some string of bits, call it sK32. Then in + the first message in the aggressive exchange, where the signature + + S{ID(I), ID(R), Ni, 0, GRP, g^x, EHAO}Ki + + is indicated, the signature computation would be performed by + MD5-HMAC_func(KEY=sK32, DATA = ID(I) | ID(R) | Ni | 0 | GRP | g^x + | g^y | EHAO) (The exact definition of the algorithm corresponding + to "MD5-HMAC- func" will appear in the RFC defining that transform). + + The result of this computation appears in the Authentication payload. + + + + + + +Orman Informational [Page 14] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +2.4.2 An Aggressive Example With Hidden Identities + + The following example indicates how two parties can complete a key + exchange without using digital signatures. Public key cryptography + hides the identities during authentication. The group exponentials + are exchanged and authenticated, but the implied keying material + (g^xy) is not needed during the exchange. + + This exchange has an important difference from the previous signature + scheme --- in the first message, an identity for the responder is + indicated as cleartext: ID(R'). However, the identity hidden with + the public key cryptography is different: ID(R). This happens + because the Initiator must somehow tell the Responder which + public/private key pair to use for the decryption, but at the same + time, the identity is hidden by encryption with that public key. + + The Initiator might elect to forgo secrecy of the Responder identity, + but this is undesirable. Instead, if there is a well-known identity + for the Responder node, the public key for that identity can be used + to encrypt the actual Responder identity. + + Initiator Responder + --------- --------- + -> CKY-I, 0, OK_KEYX, GRP, g^x, EHAO, NIDP, -> + ID(R'), E{ID(I), ID(R), E{Ni}Kr}Kr' + <- CKY-R, CKY-I, OK_KEYX, GRP, g^y, EHAS, NIDP, + E{ID(R), ID(I), Nr}Ki, + prf(Kir, ID(R) | ID(I) | GRP | g^y | g^x | EHAS) <- + -> CKY-I, CKY-R, OK_KEYX, GRP, 0, 0, NIDP, + prf(Kir, ID(I) | ID(R) | GRP | g^x | g^y | EHAS) -> + + Kir = prf(0, Ni | Nr) + + NB "NIDP" means that the PFS option for hiding identities is not used. + + NB The ID(R') value is included in the Authentication payload as + described in Appendix B. + + The result of this exchange is a key with KEYID = CKY-I|CKY-R and + value sKEYID = prf(Ni | Nr, g^xy | CKY-I | CKY-R). + + The processing outline for this exchange is as follows: + + Initiation + The Initiator generates a unique cookie and associates it with the + expected IP address of the responder, and its chosen state + information: GRP, g^x, EHAO list. The first authentication choice + in the EHAO list is an algorithm that supports public key + + + +Orman Informational [Page 15] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + encryption. The Initiator also names the two identities to be + used for the connection and enters these into the state. A well- + known identity for the responder machine is also chosen, and the + public key for this identity is used to encrypt the nonce Ni and + the two connection identities. The Initiator further + + notes that the key is in the initial state of "unauthenticated", + and + + sets a timer for possible retransmission and/or termination of the + request. + + When the Responder receives the message, he may choose to ignore all + the information and treat it as merely a request for a cookie, + creating no state. + + If CKY-I is not already in use by the source address in the IP + header, the Responder generates a unique cookie, CKY-R. As before, + the next steps depend on the responder's preferences. The minimal + required response is a message with the first cookie field set to + zero and CKY-R in the second field. For this example we will assume + that responder is more aggressive and accepts the following: + + group GRP, first authentication choice (which must be the public + key encryption algorithm used to encrypt the payload), lack of + perfect forward secrecy for protecting the identities, identity + ID(I), identity ID(R) + + The Responder must decrypt the ID and nonce information, using the + private key for the R' ID. After this, the private key for the R ID + will be used to decrypt the nonce field. + + The Responder now associates the pair (CKY-I, CKY-R) with the + following state information: + + the source and destination network addresses of the message + + key state of "unauthenticated" + + the first algorithm from each class in the EHAO (encryption-hash- + authentication algorithm offers) list + + group GRP and a y and g^y value in group GRP + + the nonce Ni and a pseudorandomly selected value Nr + + a timer for possible destruction of the state. + + + + +Orman Informational [Page 16] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The Responder then encrypts the state information with the public key + of ID(I), forms the prf value, and sends it to the Initiator. + + The Initiator receives the reply message and + validates that CKY-I is a valid association for the network + address of the incoming message, + + adds the CKY-R value to the state for the pair (CKY-I, network + address), and associates all state information with the pair + (CKY-I, CKY-R), + + decrypts the ID and nonce information + + checks the prf calculation (should this fail, the message is + discarded) + + adds g^y to its state information, + + saves the EHA selections in the state, + + optionally computes (g^x)^y (= g^xy) (this may be deferred), and + + sends the reply message, encrypted with the public key of ID(R), + + and marks the KEYID (CKY-I|CKY-R) as authenticated. + + When the Responder receives this message, it marks the key as being + in the authenticated state. If it has not already done so, it should + compute g^xy and associate it with the KEYID. + + The secret keying material sKEYID = prf(Ni | Nr, g^xy | CKY-I | + CKY-R) + + Note that although PFS for identity protection is not used, PFS for + the derived keying material is still present because the Diffie- + Hellman half-keys g^x and g^y are exchanged. + +2.4.3 An Aggressive Example With Private Identities and Without Diffie- + Hellman + + Considerable computational expense can be avoided if perfect forward + secrecy is not a requirement for the session key derivation. The two + parties can exchange nonces and secret key parts to achieve the + authentication and derive keying material. The long-term privacy of + data protected with derived keying material is dependent on the + private keys of each of the parties. + + + + + +Orman Informational [Page 17] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + In this exchange, the GRP has the value 0 and the field for the group + exponential is used to hold a nonce value instead. + + As in the previous section, the first proposed algorithm must be a + public key encryption system; by responding with a cookie and a non- + zero exponential field, the Responder implicitly accepts the first + proposal and the lack of perfect forward secrecy for the identities + and derived keying material. + + Initiator Responder + --------- --------- + -> CKY-I, 0, OK_KEYX, 0, 0, EHAO, NIDP, -> + ID(R'), E{ID(I), ID(R), sKi}Kr', Ni + <- CKY-R, CKY-I, OK_KEYX, 0, 0, EHAS, NIDP, + E{ID(R), ID(I), sKr}Ki, Nr, + prf(Kir, ID(R) | ID(I) | Nr | Ni | EHAS) <- + -> CKY-I, CKY-R, OK_KEYX, EHAS, NIDP, + prf(Kir, ID(I) | ID(R) | Ni | Nr | EHAS) -> + + Kir = prf(0, sKi | sKr) + + NB The sKi and sKr values go into the nonce fields. The change in + notation is meant to emphasize that their entropy is critical to + setting the keying material. + + NB "NIDP" means that the PFS option for hiding identities is not + used. + + The result of this exchange is a key with KEYID = CKY-I|CKY-R and + value sKEYID = prf(Kir, CKY-I | CKY-R). + +2.4.3 A Conservative Example + + In this example the two parties are minimally aggressive; they use + the cookie exchange to delay creation of state, and they use perfect + forward secrecy to protect the identities. For this example, they + use public key encryption for authentication; digital signatures or + pre-shared keys can also be used, as illustrated previously. The + conservative example here does not change the use of nonces, prf's, + etc., but it does change how much information is transmitted in each + message. + + The responder considers the ability of the initiator to repeat CKY-R + as weak evidence that the message originates from a "live" + correspondent on the network and the correspondent is associated with + the initiator's network address. The initiator makes similar + assumptions when CKY-I is repeated to the initiator. + + + + +Orman Informational [Page 18] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + All messages must have either valid cookies or at least one zero + cookie. If both cookies are zero, this indicates a request for a + cookie; if only the initiator cookie is zero, it is a response to a + cookie request. + + Information in messages violating the cookie rules cannot be used for + any OAKLEY operations. + + Note that the Initiator and Responder must agree on one set of EHA + algorithms; there is not one set for the Responder and one for the + Initiator. The Initiator must include at least MD5 and DES in the + initial offer. + + Fields not indicated have null values. + + Initiator Responder + --------- --------- + -> 0, 0, OK_KEYX -> + <- 0, CKY-R, OK_KEYX <- + -> CKY-I, CKY-R, OK_KEYX, GRP, g^x, EHAO -> + <- CKY-R, CKY-I, OK_KEYX, GRP, g^y, EHAS <- + -> CKY-I, CKY-R, OK_KEYX, GRP, g^x, IDP*, + ID(I), ID(R), E{Ni}Kr, -> + <- CKY-R, CKY-I, OK_KEYX, GRP, 0 , 0, IDP, <- + E{Nr, Ni}Ki, ID(R), ID(I), + prf(Kir, ID(R) | ID(I) | GRP | g^y | g^x | EHAS ) + -> CKY-I, CKY-R, OK_KEYX, GRP, 0 , 0, IDP, + prf(Kir, ID(I) | ID(R) | GRP | g^x | g^y | EHAS ) -> + + Kir = prf(0, Ni | Nr) + + * when IDP is in effect, authentication payloads are encrypted with + the selected encryption algorithm using the keying material prf(0, + g^xy). (The transform defining the encryption algorithm will + define how to select key bits from the keying material.) This + encryption is in addition to and after any public key encryption. + See Appendix B. + + Note that in the first messages, several fields are omitted from + the description. These fields are present as null values. + + The first exchange allows the Responder to use stateless cookies; if + the responder generates cookies in a manner that allows him to + validate them without saving them, as in Photuris, then this is + possible. Even if the Initiator includes a cookie in his initial + request, the responder can still use stateless cookies by merely + omitting the CKY-I from his reply and by declining to record the + Initiator cookie until it appears in a later message. + + + +Orman Informational [Page 19] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + After the exchange is complete, both parties compute the shared key + material sKEYID as prf(Ni | Nr, g^xy | CKY-I | CKY-R) where "prf" is + the pseudo-random function in class "hash" selected in the EHA list. + + As with the cookies, each party considers the ability of the remote + side to repeat the Ni or Nr value as a proof that Ka, the public key + of party a, speaks for the remote party and establishes its identity. + + In analyzing this exchange, it is important to note that although the + IDP option ensures that the identities are protected with an + ephemeral key g^xy, the authentication itself does not depend on + g^xy. It is essential that the authentication steps validate the g^x + and g^y values, and it is thus imperative that the authentication not + involve a circular dependency on them. A third party could intervene + with a "man-in-middle" scheme to convince the initiator and responder + to use different g^xy values; although such an attack might result in + revealing the identities to the eavesdropper, the authentication + would fail. + +2.4.4 Extra Strength for Protection of Encryption Keys + + The nonces Ni and Nr are used to provide an extra dimension of + secrecy in deriving session keys. This makes the secrecy of the key + depend on two different problems: the discrete logarithm problem in + the group G, and the problem of breaking the nonce encryption scheme. + If RSA encryption is used, then this second problem is roughly + equivalent to factoring the RSA public keys of both the initiator and + responder. + + For authentication, the key type, the validation method, and the + certification requirement must be indicated. + +2.5 Identity and Authentication + +2.5.1 Identity + + In OAKLEY exchanges the Initiator offers Initiator and Responder ID's + -- the former is the claimed identity for the Initiator, and the + latter is the requested ID for the Responder. + + If neither ID is specified, the ID's are taken from the IP header + source and destination addresses. + + If the Initiator doesn't supply a responder ID, the Responder can + reply by naming any identity that the local policy allows. The + Initiator can refuse acceptance by terminating the exchange. + + + + + +Orman Informational [Page 20] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The Responder can also reply with a different ID than the Initiator + suggested; the Initiator can accept this implicitly by continuing the + exchange or refuse it by terminating (not replying). + +2.5.2 Authentication + + The authentication of principals to one another is at the heart of + any key exchange scheme. The Internet community must decide on a + scalable standard for solving this problem, and OAKLEY must make use + of that standard. At the time of this writing, there is no such + standard, though several are emerging. This document attempts to + describe how a handful of standards could be incorporated into + OAKLEY, without attempting to pick and choose among them. + + The following methods can appear in OAKLEY offers: + + a. Pre-shared Keys + When two parties have arranged for a trusted method of + distributing secret keys for their mutual authentication, they can + be used for authentication. This has obvious scaling problems for + large systems, but it is an acceptable interim solution for some + situations. Support for pre-shared keys is REQUIRED. + + The encryption, hash, and authentication algorithm for use with a + pre-shared key must be part of the state information distributed + with the key itself. + + The pre-shared keys have a KEYID and keying material sKEYID; the + KEYID is used in a pre-shared key authentication option offer. + There can be more than one pre-shared key offer in a list. + + Because the KEYID persists over different invocations of OAKLEY + (after a crash, etc.), it must occupy a reserved part of the KEYID + space for the two parties. A few bits can be set aside in each + party's "cookie space" to accommodate this. + + There is no certification authority for pre-shared keys. When a + pre-shared key is used to generate an authentication payload, the + certification authority is "None", the Authentication Type is + "Preshared", and the payload contains + + the KEYID, encoded as two 64-bit quantities, and the result of + applying the pseudorandom hash function to the message body + with the sKEYID forming the key for the function + + + + + + + +Orman Informational [Page 21] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + b. DNS public keys + Security extensions to the DNS protocol [DNSSEC] provide a + convenient way to access public key information, especially for + public keys associated with hosts. RSA keys are a requirement for + secure DNS implementations; extensions to allow optional DSS keys + are a near-term possibility. + + DNS KEY records have associated SIG records that are signed by a + zone authority, and a hierarchy of signatures back to the root + server establishes a foundation for trust. The SIG records + indicate the algorithm used for forming the signature. + + OAKLEY implementations must support the use of DNS KEY and SIG + records for authenticating with respect to IPv4 and IPv6 addresses + and fully qualified domain names. However, implementations are + not required to support any particular algorithm (RSA, DSS, etc.). + + c. RSA public keys w/o certification authority signature PGP + [Zimmerman] uses public keys with an informal method for + establishing trust. The format of PGP public keys and naming + methods will be described in a separate RFC. The RSA algorithm + can be used with PGP keys for either signing or encryption; the + authentication option should indicate either RSA-SIG or RSA-ENC, + respectively. Support for this is OPTIONAL. + + d.1 RSA public keys w/ certificates There are various formats and + naming conventions for public keys that are signed by one or more + certification authorities. The Public Key Interchange Protocol + discusses X.509 encodings and validation. Support for this is + OPTIONAL. + + d.2 DSS keys w/ certificates Encoding for the Digital Signature + Standard with X.509 is described in draft-ietf-ipsec-dss-cert- + 00.txt. Support for this is OPTIONAL; an ISAKMP Authentication + Type will be assigned. + +2.5.3 Validating Authentication Keys + + The combination of the Authentication algorithm, the Authentication + Authority, the Authentication Type, and a key (usually public) define + how to validate the messages with respect to the claimed identity. + The key information will be available either from a pre-shared key, + or from some kind of certification authority. + + Generally the certification authority produces a certificate binding + the entity name to a public key. OAKLEY implementations must be + prepared to fetch and validate certificates before using the public + key for OAKLEY authentication purposes. + + + +Orman Informational [Page 22] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The ISAKMP Authentication Payload defines the Authentication + Authority field for specifying the authority that must be apparent in + the trust hierarchy for authentication. + + Once an appropriate certificate is obtained (see 2.4.3), the + validation method will depend on the Authentication Type; if it is + PGP then the PGP signature validation routines can be called to + satisfy the local web-of-trust predicates; if it is RSA with X.509 + certificates, the certificate must be examined to see if the + certification authority signature can be validated, and if the + hierarchy is recognized by the local policy. + +2.5.4 Fetching Identity Objects + + In addition to interpreting the certificate or other data structure + that contains an identity, users of OAKLEY must face the task of + retrieving certificates that bind a public key to an identifier and + also retrieving auxiliary certificates for certifying authorities or + co-signers (as in the PGP web of trust). + + The ISAKMP Credentials Payload can be used to attach useful + certificates to OAKLEY messages. The Credentials Payload is defined + in Appendix B. + + Support for accessing and revoking public key certificates via the + Secure DNS protocol [SECDNS] is MANDATORY for OAKLEY implementations. + Other retrieval methods can be used when the AUTH class indicates a + preference. + + The Public Key Interchange Protocol discusses a full protocol that + might be used with X.509 encoded certificates. + +2.6 Interface to Cryptographic Transforms + + The keying material computed by the key exchange should have at least + 90 bits of entropy, which means that it must be at least 90 bits in + length. This may be more or less than is required for keying the + encryption and/or pseudorandom function transforms. + + The transforms used with OAKLEY should have auxiliary algorithms + which take a variable precision integer and turn it into keying + material of the appropriate length. For example, a DES algorithm + could take the low order 56 bits, a triple DES algorithm might use + the following: + + K1 = low 56 bits of md5(0|sKEYID) + K2 = low 56 bits of md5(1|sKEYID) + K3 = low 56 bits of md5(2|sKEYID) + + + +Orman Informational [Page 23] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The transforms will be called with the keying material encoded as a + variable precision integer, the length of the data, and the block of + memory with the data. Conversion of the keying material to a + transform key is the responsibility of the transform. + +2.7 Retransmission, Timeouts, and Error Messages + + If a response from the Responder is not elicited in an appropriate + amount of time, the message should be retransmitted by the Initiator. + These retransmissions must be handled gracefully by both parties; the + Responder must retain information for retransmitting until the + Initiator moves to the next message in the protocol or completes the + exchange. + + Informational error messages present a problem because they cannot be + authenticated using only the information present in an incomplete + exchange; for this reason, the parties may wish to establish a + default key for OAKLEY error messages. A possible method for + establishing such a key is described in Appendix B, under the use of + ISA_INIT message types. + + In the following the message type is OAKLEY Error, the KEYID supplies + the H algorithm and key for authenticating the message contents; this + value is carried in the Sig/Prf payload. + + The Error payload contains the error code and the contents of the + rejected message. + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 24] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Initiator-Cookie ~ + / ! ! +KEYID +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + \ ! ! + ~ Responder-Cookie ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Domain of Interpretation ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Message Type ! Exch ! Vers ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! SPI (unused) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! SPI (unused) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Error Payload ! + ~ ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Sig/prf Payload + ~ ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + The error message will contain the cookies as presented in the + offending message, the message type OAKLEY_ERROR, and the reason for + the error, followed by the rejected message. + + Error messages are informational only, and the correctness of the + protocol does not depend on them. + + Error reasons: + + TIMEOUT exchange has taken too long, state destroyed + AEH_ERROR an unknown algorithm appears in an offer + GROUP_NOT_SUPPORTED GRP named is not supported + EXPONENTIAL_UNACCEPTABLE exponential too large/small or is +-1 + SELECTION_NOT_OFFERED selection does not occur in offer + NO_ACCEPTABLE_OFFERS no offer meets host requirements + AUTHENTICATION_FAILURE signature or hash function fails + RESOURCE_EXCEEDED too many exchanges or too much state info + NO_EXCHANGE_IN_PROGRESS a reply received with no request in progress + + + + + + + +Orman Informational [Page 25] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +2.8 Additional Security for Privacy Keys: Private Groups + + If the two parties have need to use a Diffie-Hellman key + determination scheme that does not depend on the standard group + definitions, they have the option of establishing a private group. + The authentication need not be repeated, because this stage of the + protocol will be protected by a pre-existing authentication key. As + an extra security measure, the two parties will establish a private + name for the shared keying material, so even if they use exactly the + same group to communicate with other parties, the re-use will not be + apparent to passive attackers. + + Private groups have the advantage of making a widespread passive + attack much harder by increasing the number of groups that would have + to be exhaustively analyzed in order to recover a large number of + session keys. This contrasts with the case when only one or two + groups are ever used; in that case, one would expect that years and + years of session keys would be compromised. + + There are two technical challenges to face: how can a particular user + create a unique and appropriate group, and how can a second party + assure himself that the proposed group is reasonably secure? + + The security of a modular exponentiation group depends on the largest + prime factor of the group size. In order to maximize this, one can + choose "strong" or Sophie Germaine primes, P = 2Q + 1, where P and Q + are prime. However, if P = kQ + 1, where k is small, then the + strength of the group is still considerable. These groups are known + as Schnorr subgroups, and they can be found with much less + computational effort than Sophie-Germaine primes. + + Schnorr subgroups can also be validated efficiently by using probable + prime tests. + + It is also fairly easy to find P, k, and Q such that the largest + prime factor can be easily proven to be Q. + + We estimate that it would take about 10 minutes to find a new group + of about 2^1024 elements, and this could be done once a day by a + scheduled process; validating a group proposed by a remote party + would take perhaps a minute on a 25 MHz RISC machine or a 66 MHz CISC + machine. + + We note that validation is done only between previously mutually + authenticated parties, and that a new group definition always follows + and is protected by a key established using a well-known group. + There are five points to keep in mind: + + + + +Orman Informational [Page 26] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + a. The description and public identifier for the new group are + protected by the well-known group. + + b. The responder can reject the attempt to establish the new + group, either because he is too busy or because he cannot validate + the largest prime factor as being sufficiently large. + + c. The new modulus and generator can be cached for long periods of + time; they are not security critical and need not be associated + with ongoing activity. + + d. Generating a new g^x value periodically will be more expensive + if there are many groups cached; however, the importance of + frequently generating new g^x values is reduced, so the time + period can be lengthened correspondingly. + + e. All modular exponentiation groups have subgroups that are + weaker than the main group. For Sophie Germain primes, if the + generator is a square, then there are only two elements in the + subgroup: 1 and g^(-1) (same as g^(p-1)) which we have already + recommended avoiding. For Schnorr subgroups with k not equal to + 2, the subgroup can be avoided by checking that the exponential is + not a kth root of 1 (e^k != 1 mod p). + +2.8.1 Defining a New Group + + This section describes how to define a new group. The description of + the group is hidden from eavesdroppers, and the identifier assigned + to the group is unique to the two parties. Use of the new group for + Diffie-Hellman key exchanges is described in the next section. + + The secrecy of the description and the identifier increases the + difficulty of a passive attack, because if the group descriptor is + not known to the attacker, there is no straightforward and efficient + way to gain information about keys calculated using the group. + + Only the description of the new group need be encrypted in this + exchange. The hash algorithm is implied by the OAKLEY session named + by the group. The encryption is the encryption function of the + OAKLEY session. + + The descriptor of the new group is encoded in the new group payload. + The nonces are encoded in the Authentication Payload. + + Data beyond the encryption boundary is encrypted using the transform + named by the KEYID. + + + + + +Orman Informational [Page 27] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The following messages use the ISAKMP Key Exchange Identifier OAKLEY + New Group. + + To define a new modular exponentiation group: + + Initiator Responder + --------- ---------- + -> KEYID, -> + INEWGRP, + Desc(New Group), Na + prf(sKEYID, Desc(New Group) | Na) + + <- KEYID, + INEWGRPRS, + Na, Nb + prf(sKEYID, Na | Nb | Desc(New Group)) <- + + -> KEYID, + INEWGRPACK + prf(sKEYID, Nb | Na | Desc(New Group)) -> + + These messages are encrypted at the encryption boundary using the key + indicated. The hash value is placed in the "digital signature" field + (see Appendix B). + + New GRP identifier = trunc16(Na) | trunc16(Nb) + + (trunc16 indicates truncation to 16 bits; the initiator and + responder must use nonces that have distinct upper bits from any + used for current GRPID's) + + Desc(G) is the encoding of the descriptor for the group descriptor + (see Appendix A for the format of a group descriptor) + + The two parties must store the mapping between the new group + identifier GRP and the group descriptor Desc(New Group). They must + also note the identities used for the KEYID and copy these to the + state for the new group. + + Note that one could have the same group descriptor associated with + several KEYID's. Pre-calculation of g^x values may be done based + only on the group descriptor, not the private group name. + +2.8.2 Deriving a Key Using a Private Group + + Once a private group has been established, its group id can be used + in the key exchange messages in the GRP position. No changes to the + protocol are required. + + + +Orman Informational [Page 28] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +2.9 Quick Mode: New Keys From Old, + + When an authenticated KEYID and associated keying material sKEYID + already exist, it is easy to derive additional KEYID's and keys + sharing similar attributes (GRP, EHA, etc.) using only hashing + functions. The KEYID might be one that was derived in Main Mode, for + example. + + On the other hand, the authenticated key may be a manually + distributed key, one that is shared by the initiator and responder + via some means external to OAKLEY. If the distribution method has + formed the KEYID using appropriately unique values for the two halves + (CKY-I and CKY-R), then this method is applicable. + + In the following, the Key Exchange Identifier is OAKLEY Quick Mode. + The nonces are carried in the Authentication Payload, and the prf + value is carried in the Authentication Payload; the Authentication + Authority is "None" and the type is "Pre-Shared". + + The protocol is: + + Initiator Responder + --------- --------- + -> KEYID, INEWKRQ, Ni, prf(sKEYID, Ni) -> + <- KEYID, INEWKRS, Nr, prf(sKEYID, 1 | Nr | Ni) <- + -> KEYID, INEWKRP, 0, prf(sKEYID, 0 | Ni | Nr) -> + + The New KEYID, NKEYID, is Ni | Nr + + sNKEYID = prf(sKEYID, Ni | Nr ) + + The identities and EHA values associated with NKEYID are the same as + those associated with KEYID. + + Each party must validate the hash values before using the new key for + any purpose. + +2.10 Defining and Using Pre-Distributed Keys + + If a key and an associated key identifier and state information have + been distributed manually, then the key can be used for any OAKLEY + purpose. The key must be associated with the usual state + information: ID's and EHA algorithms. + + Local policy dictates when a manual key can be included in the OAKLEY + database. For example, only privileged users would be permitted to + introduce keys associated with privileged ID's, an unprivileged user + could only introduce keys associated with her own ID. + + + +Orman Informational [Page 29] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +2.11 Distribution of an External Key + + Once an OAKLEY session key and ancillary algorithms are established, + the keying material and the "H" algorithm can be used to distribute + an externally generated key and to assign a KEYID to it. + + In the following, KEYID represents an existing, authenticated OAKLEY + session key, and sNEWKEYID represents the externally generated keying + material. + + In the following, the Key Exchange Identifier is OAKLEY External + Mode. The Key Exchange Payload contains the new key, which is + protected + + Initiator Responder + --------- --------- + -> KEYID, IEXTKEY, Ni, prf(sKEYID, Ni) -> + <- KEYID, IEXTKEY, Nr, prf(sKEYID, 1 | Nr | Ni) <- + -> KEYID, IEXTKEY, Kir xor sNEWKEYID*, prf(Kir, sNEWKEYID | Ni | Nr) -> + + Kir = prf(sKEYID, Ni | Nr) + + * this field is carried in the Key Exchange Payload. + + Each party must validate the hash values using the "H" function in + the KEYID state before changing any key state information. + + The new key is recovered by the Responder by calculating the xor of + the field in the Authentication Payload with the Kir value. + + The new key identifier, naming the keying material sNEWKEYID, is + prf(sKEYID, 1 | Ni | Nr). + + Note that this exchange does not require encryption. Hugo Krawcyzk + suggested the method and noted its advantage. + +2.11.1 Cryptographic Strength Considerations + + The strength of the key used to distribute the external key must be + at least equal to the strength of the external key. Generally, this + means that the length of the sKEYID material must be greater than or + equal to the length of the sNEWKEYID material. + + The derivation of the external key, its strength or intended use are + not addressed by this protocol; the parties using the key must have + some other method for determining these properties. + + + + + +Orman Informational [Page 30] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + As of early 1996, it appears that for 90 bits of cryptographic + strength, one should use a modular exponentiation group modulus of + 2000 bits. For 128 bits of strength, a 3000 bit modulus is required. + +3. Specifying and Deriving Security Associations + + When a security association is defined, only the KEYID need be given. + The responder should be able to look up the state associated with the + KEYID value and find the appropriate keying material, sKEYID. + + Deriving keys for use with IPSEC protocols such as ESP or AH is a + subject covered in the ISAKMP/Oakley Resolution document. That + document also describes how to negotiate acceptable parameter sets + and identifiers for ESP and AH, and how to exactly calculate the + keying material for each instance of the protocols. Because the + basic keying material defined here (g^xy) may be used to derive keys + for several instances of ESP and AH, the exact mechanics of using + one-way functions to turn g^xy into several unique keys is essential + to correct usage. + +4. ISAKMP Compatibility + + OAKLEY uses ISAKMP header and payload formats, as described in the + text and in Appendix B. There are particular noteworthy extensions + beyond the version 4 draft. + +4.1 Authentication with Existing Keys + + In the case that two parties do not have suitable public key + mechanisms in place for authenticating each other, they can use keys + that were distributed manually. After establishment of these keys + and their associated state in OAKLEY, they can be used for + authentication modes that depend on signatures, e.g. Aggressive Mode. + + When an existing key is to appear in an offer list, it should be + indicated with an Authentication Algorithm of ISAKMP_EXISTING. This + value will be assigned in the ISAKMP RFC. + + When the authentication method is ISAKMP_EXISTING, the authentication + authority will have the value ISAKMP_AUTH_EXISTING; the value for + this field must not conflict with any authentication authority + registered with IANA and is defined in the ISAKMP RFC. + + + + + + + + + +Orman Informational [Page 31] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The authentication payload will have two parts: + + the KEYID for the pre-existing key + + the identifier for the party to be authenticated by the pre- + existing key. + + The pseudo-random function "H" in the state information for that + KEYID will be the signature algorithm, and it will use the keying + material for that key (sKEYID) when generating or checking the + validity of message data. + + E.g. if the existing key has an KEYID denoted by KID and 128 bits of + keying material denoted by sKID and "H" algorithm a transform named + HMAC, then to generate a "signature" for a data block, the output of + HMAC(sKID, data) will be the corresponding signature payload. + + The KEYID state will have the identities of the local and remote + parties for which the KEYID was assigned; it is up to the local + policy implementation to decide when it is appropriate to use such a + key for authenticating other parties. For example, a key distributed + for use between two Internet hosts A and B may be suitable for + authenticating all identities of the form "alice@A" and "bob@B". + +4.2 Third Party Authentication + + A local security policy might restrict key negotiation to trusted + parties. For example, two OAKLEY daemons running with equal + sensitivity labels on two machines might wish to be the sole arbiters + of key exchanges between users with that same sensitivity label. In + this case, some way of authenticating the provenance of key exchange + requests is needed. I.e., the identities of the two daemons should + be bound to a key, and that key will be used to form a "signature" + for the key exchange messages. + + The Signature Payload, in Appendix B, is for this purpose. This + payload names a KEYID that is in existence before the start of the + current exchange. The "H" transform for that KEYID is used to + calculate an integrity/authentication value for all payloads + preceding the signature. + + Local policy can dictate which KEYID's are appropriate for signing + further exchanges. + + + + + + + + +Orman Informational [Page 32] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +4.3 New Group Mode + + OAKLEY uses a new KEI for the exchange that defines a new group. + +5. Security Implementation Notes + + Timing attacks that are capable of recovering the exponent value used + in Diffie-Hellman calculations have been described by Paul Kocher + [Kocher]. In order to nullify the attack, implementors must take + pains to obscure the sequence of operations involved in carrying out + modular exponentiations. + + A "blinding factor" can accomplish this goal. A group element, r, is + chosen at random. When an exponent x is chosen, the value r^(-x) is + also calculated. Then, when calculating (g^y)^x, the implementation + will calculate this sequence: + + A = (rg^y) + B = A^x = (rg^y)^x = (r^x)(g^(xy)) + C = B*r^(-x) = (r^x)(r^-(x))(g^(xy)) = g^(xy) + + The blinding factor is only necessary if the exponent x is used more + than 100 times (estimate by Richard Schroeppel). + +6. OAKLEY Parsing and State Machine + + There are many pathways through OAKLEY, but they follow a left-to- + right parsing pattern of the message fields. + + The initiator decides on an initial message in the following order: + + 1. Offer a cookie. This is not necessary but it helps with + aggressive exchanges. + + 2. Pick a group. The choices are the well-known groups or any + private groups that may have been negotiated. The very first + exchange between two Oakley daemons with no common state must + involve a well-known group (0, meaning no group, is a well-known + group). Note that the group identifier, not the group descriptor, + is used in the message. + + If a non-null group will be used, it must be included with the + first message specifying EHAO. It need not be specified until + then. + + 3. If PFS will be used, pick an exponent x and present g^x. + + 4. Offer Encryption, Hash, and Authentication lists. + + + +Orman Informational [Page 33] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + 5. Use PFS for hiding the identities + + If identity hiding is not used, then the initiator has this + option: + + 6. Name the identities and include authentication information + + The information in the authentication section depends on the first + authentication offer. In this aggressive exchange, the Initiator + hopes that the Responder will accept all the offered information and + the first authentication method. The authentication method + determines the authentication payload as follows: + + 1. Signing method. The signature will be applied to all the + offered information. + + 2. A public key encryption method. The algorithm will be used to + encrypt a nonce in the public key of the requested Responder + identity. There are two cases possible, depending on whether or + not identity hiding is used: + + a. No identity hiding. The ID's will appear as plaintext. + b. Identity hiding. A well-known ID, call it R', will appear + as plaintext in the authentication payload. It will be + followed by two ID's and a nonce; these will be encrypted using + the public key for R'. + + 3. A pre-existing key method. The pre-existing key will be used + to encrypt a nonce. If identity hiding is used, the ID's will be + encrypted in place in the payload, using the "E" algorithm + associated with the pre-existing key. + + The Responder can accept all, part or none of the initial message. + + The Responder accepts as many of the fields as he wishes, using the + same decision order as the initiator. At any step he can stop, + implicitly rejecting further fields (which will have null values in + his response message). The minimum response is a cookie and the GRP. + + 1. Accept cookie. The Responder may elect to record no state + information until the Initiator successfully replies with a cookie + chosen by the responder. If so, the Responder replies with a + cookie, the GRP, and no other information. + + 2. Accept GRP. If the group is not acceptable, the Responder will + not reply. The Responder may send an error message indicating the + the group is not acceptable (modulus too small, unknown + identifier, etc.) Note that "no group" has two meanings during + + + +Orman Informational [Page 34] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + the protocol: it may mean the group is not yet specified, or it + may mean that no group will be used (and thus PFS is not + possible). + + 3. Accept the g^x value. The Responder indicates his acceptance + of the g^x value by including his own g^y value in his reply. He + can postpone this by ignoring g^x and putting a zero length g^y + value in his reply. He can also reject the g^x value with an + error message. + + 4. Accept one element from each of the EHA lists. The acceptance + is indicated by a non-zero proposal. + + 5. If PFS for identity hiding is requested, then no further data + will follow. + + 6. If the authentication payload is present, and if the first item + in the offered authentication class is acceptable, then the + Responder must validate/decrypt the information in the + authentication payload and signature payload, if present. The + Responder should choose a nonce and reply using the same + authentication/hash algorithm as the Initiator used. + + The Initiator notes which information the Responder has accepted, + validates/decrypts any signed, hashed, or encrypted fields, and if + the data is acceptable, replies in accordance to the EHA methods + selected by the Responder. The Initiator replies are distinguished + from his initial message by the presence of the non-zero value for + the Responder cookie. + + The output of the signature or prf function will be encoded as a + variable precision integer as described in Appendix C. The KEYID + will indicate KEYID that names keying material and the Hash or + Signature function. + +7. The Credential Payload + + Useful certificates with public key information can be attached to + OAKLEY messages using Credential Payloads as defined in the ISAKMP + document. It should be noted that the identity protection option + applies to the credentials as well as the identities. + +Security Considerations + + The focus of this document is security; hence security considerations + permeate this memo. + + + + + +Orman Informational [Page 35] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +Author's Address + + Hilarie K. Orman + Department of Computer Science + University of Arizona + + EMail: ho@darpa.mil + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 36] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +APPENDIX A Group Descriptors + + Three distinct group representations can be used with OAKLEY. Each + group is defined by its group operation and the kind of underlying + field used to represent group elements. The three types are modular + exponentiation groups (named MODP herein), elliptic curve groups over + the field GF[2^N] (named EC2N herein), and elliptic curve groups over + GF[P] (named ECP herein) For each representation, many distinct + realizations are possible, depending on parameter selection. + + With a few exceptions, all the parameters are transmitted as if they + were non-negative multi-precision integers, using the format defined + in this appendix (note, this is distinct from the encoding in + Appendix C). Every multi-precision integer has a prefixed length + field, even where this information is redundant. + + For the group type EC2N, the parameters are more properly thought of + as very long bit fields, but they are represented as multi-precision + integers, (with length fields, and right-justified). This is the + natural encoding. + + MODP means the classical modular exponentiation group, where the + operation is to calculate G^X (mod P). The group is defined by the + numeric parameters P and G. P must be a prime. G is often 2, but + may be a larger number. 2 <= G <= P-2. + + ECP is an elliptic curve group, modulo a prime number P. The + defining equation for this kind of group is + Y^2 = X^3 + AX + B The group operation is taking a multiple of an + elliptic-curve point. The group is defined by 5 numeric parameters: + The prime P, two curve parameters A and B, and a generator (X,Y). + A,B,X,Y are all interpreted mod P, and must be (non-negative) + integers less than P. They must satisfy the defining equation, + modulo P. + + EC2N is an elliptic curve group, over the finite field F[2^N]. The + defining equation for this kind of group is + Y^2 + XY = X^3 + AX^2 + B (This equation differs slightly from the + mod P case: it has an XY term, and an AX^2 term instead of an AX + term.) + + We must specify the field representation, and then the elliptic + curve. The field is specified by giving an irreducible polynomial + (mod 2) of degree N. This polynomial is represented as an integer of + size between 2^N and 2^(N+1), as if the defining polynomial were + evaluated at the value U=2. + + + + + +Orman Informational [Page 37] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + For example, the field defined by the polynomial U^155 + U^62 + 1 is + represented by the integer 2^155 + 2^62 + 1. The group is defined by + 4 more parameters, A,B,X,Y. These parameters are elements of the + field GF[2^N], and can be thought of as polynomials of degree < N, + with (mod 2) coefficients. They fit in N-bit fields, and are + represented as integers < 2^N, as if the polynomial were evaluated at + U=2. For example, the field element U^2 + 1 would be represented by + the integer 2^2+1, which is 5. The two parameters A and B define the + curve. A is frequently 0. B must not be 0. The parameters X and Y + select a point on the curve. The parameters A,B,X,Y must satisfy the + defining equation, modulo the defining polynomial, and mod 2. + + Group descriptor formats: + + Type of group: A two-byte field, + assigned values for the types "MODP", "ECP", "EC2N" + will be defined (see ISAKMP-04). + Size of a field element, in bits. This is either Ceiling(log2 P) + or the degree of the irreducible polynomial: a 32-bit integer. + The prime P or the irreducible field polynomial: a multi-precision + integer. + The generator: 1 or 2 values, multi-precision integers. + EC only: The parameters of the curve: 2 values, multi-precision + integers. + + The following parameters are Optional (each of these may appear + independently): + a value of 0 may be used as a place-holder to represent an unspecified + parameter; any number of the parameters may be sent, from 0 to 3. + + The largest prime factor: the encoded value that is the LPF of the + group size, a multi-precision integer. + + EC only: The order of the group: multi-precision integer. + (The group size for MODP is always P-1.) + + Strength of group: 32-bit integer. + The strength of the group is approximately the number of key-bits + protected. + It is determined by the log2 of the effort to attack the group. + It may change as we learn more about cryptography. + + This is a generic example for a "classic" modular exponentiation group: + Group type: "MODP" + Size of a field element in bits: Log2 (P) rounded *up*. A 32bit + integer. + Defining prime P: a multi-precision integer. + Generator G: a multi-precision integer. 2 <= G <= P-2. + + + +Orman Informational [Page 38] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + + Largest prime factor of P-1: the multi-precision integer Q + Strength of group: a 32-bit integer. We will specify a formula + for calculating this number (TBD). + + This is a generic example for an elliptic curve group, mod P: + Group type: "ECP" + Size of a field element in bits: Log2 (P) rounded *up*, + a 32 bit integer. + Defining prime P: a multi-precision integer. + Generator (X,Y): 2 multi-precision integers, each < P. + Parameters of the curve A,B: 2 multi-precision integers, each < P. + + Largest prime factor of the group order: a multi-precision integer. + Order of the group: a multi-precision integer. + Strength of group: a 32-bit integer. Formula TBD. + + This is a specific example for an elliptic curve group: + Group type: "EC2N" + Degree of the irreducible polynomial: 155 + Irreducible polynomial: U^155 + U^62 + 1, represented as the + multi-precision integer 2^155 + 2^62 + 1. + Generator (X,Y) : represented as 2 multi-precision integers, each + < 2^155. + For our present curve, these are (decimal) 123 and 456. Each is + represented as a multi-precision integer. + Parameters of the curve A,B: represented as 2 multi-precision + integers, each < 2^155. + For our present curve these are 0 and (decimal) 471951, represented + as two multi-precision integers. + + + Largest prime factor of the group order: + + 3805993847215893016155463826195386266397436443, + + represented as a multi-precision integer. + The order of the group: + + 45671926166590716193865565914344635196769237316 + + represented as a multi-precision integer. + + Strength of group: 76, represented as a 32-bit integer. + + The variable precision integer encoding for group descriptor fields + is the following. This is a slight variation on the format defined + in Appendix C in that a fixed 16-bit value is used first, and the + + + +Orman Informational [Page 39] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + length is limited to 16 bits. However, the interpretation is + otherwise identical. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Fixed value (TBD) ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + . . + . Integer . + . . + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + The format of a group descriptor is: + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!1! Group Description ! MODP ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Field Size ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Prime ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Generator1 ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Generator2 ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Curve-p1 ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Curve-p2 ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !1!0! Largest Prime Factor ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + +Orman Informational [Page 40] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + !1!0! Order of Group ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !0!0! Strength of Group ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! MPI ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 41] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +APPENDIX B Message formats + + The encodings of Oakley messages into ISAKMP payloads is deferred to + the ISAKMP/Oakley Resolution document. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 42] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +APPENDIX C Encoding a variable precision integer. + + Variable precision integers will be encoded as a 32-bit length field + followed by one or more 32-bit quantities containing the + representation of the integer, aligned with the most significant bit + in the first 32-bit item. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! first value word (most significant bits) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ additional value words ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + An example of such an encoding is given below, for a number with 51 + bits of significance. The length field indicates that 2 32-bit + quantities follow. The most significant non-zero bit of the number + is in bit 13 of the first 32-bit quantity, the low order bits are in + the second 32-bit quantity. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 1 0! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x x x x x x x x x x x x x x x x x! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + + + + + + + + + + + + + + + + +Orman Informational [Page 43] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +APPENDIX D Cryptographic strengths + + The Diffie-Hellman algorithm is used to compute keys that will be + used with symmetric algorithms. It should be no easier to break the + Diffie-Hellman computation than it is to do an exhaustive search over + the symmetric key space. A recent recommendation by an group of + cryptographers [Blaze] has recommended a symmetric key size of 75 + bits for a practical level of security. For 20 year security, they + recommend 90 bits. + + Based on that report, a conservative strategy for OAKLEY users would + be to ensure that their Diffie-Hellman computations were as secure as + at least a 90-bit key space. In order to accomplish this for modular + exponentiation groups, the size of the largest prime factor of the + modulus should be at least 180 bits, and the size of the modulus + should be at least 1400 bits. For elliptic curve groups, the LPF + should be at least 180 bits. + + If long-term secrecy of the encryption key is not an issue, then the + following parameters may be used for the modular exponentiation + group: 150 bits for the LPF, 980 bits for the modulus size. + + The modulus size alone does not determine the strength of the + Diffie-Hellman calculation; the size of the exponent used in + computing powers within the group is also important. The size of the + exponent in bits should be at least twice the size of any symmetric + key that will be derived from it. We recommend that ISAKMP + implementors use at least 180 bits of exponent (twice the size of a + 20-year symmetric key). + + The mathematical justification for these estimates can be found in + texts that estimate the effort for solving the discrete log problem, + a task that is strongly related to the efficiency of using the Number + Field Sieve for factoring large integers. Readers are referred to + [Stinson] and [Schneier]. + + + + + + + + + + + + + + + + +Orman Informational [Page 44] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +APPENDIX E The Well-Known Groups + + The group identifiers: + + 0 No group (used as a placeholder and for non-DH exchanges) + 1 A modular exponentiation group with a 768 bit modulus + 2 A modular exponentiation group with a 1024 bit modulus + 3 A modular exponentiation group with a 1536 bit modulus (TBD) + 4 An elliptic curve group over GF[2^155] + 5 An elliptic curve group over GF[2^185] + + values 2^31 and higher are used for private group identifiers + + Richard Schroeppel performed all the mathematical and computational + work for this appendix. + + Classical Diffie-Hellman Modular Exponentiation Groups + + The primes for groups 1 and 2 were selected to have certain + properties. The high order 64 bits are forced to 1. This helps the + classical remainder algorithm, because the trial quotient digit can + always be taken as the high order word of the dividend, possibly +1. + The low order 64 bits are forced to 1. This helps the Montgomery- + style remainder algorithms, because the multiplier digit can always + be taken to be the low order word of the dividend. The middle bits + are taken from the binary expansion of pi. This guarantees that they + are effectively random, while avoiding any suspicion that the primes + have secretly been selected to be weak. + + Because both primes are based on pi, there is a large section of + overlap in the hexadecimal representations of the two primes. The + primes are chosen to be Sophie Germain primes (i.e., (P-1)/2 is also + prime), to have the maximum strength against the square-root attack + on the discrete logarithm problem. + + The starting trial numbers were repeatedly incremented by 2^64 until + suitable primes were located. + + Because these two primes are congruent to 7 (mod 8), 2 is a quadratic + residue of each prime. All powers of 2 will also be quadratic + residues. This prevents an opponent from learning the low order bit + of the Diffie-Hellman exponent (AKA the subgroup confinement + problem). Using 2 as a generator is efficient for some modular + exponentiation algorithms. [Note that 2 is technically not a + generator in the number theory sense, because it omits half of the + possible residues mod P. From a cryptographic viewpoint, this is a + virtue.] + + + + +Orman Informational [Page 45] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +E.1. Well-Known Group 1: A 768 bit prime + + The prime is 2^768 - 2^704 - 1 + 2^64 * { [2^638 pi] + 149686 }. Its + decimal value is + 155251809230070893513091813125848175563133404943451431320235 + 119490296623994910210725866945387659164244291000768028886422 + 915080371891804634263272761303128298374438082089019628850917 + 0691316593175367469551763119843371637221007210577919 + + This has been rigorously verified as a prime. + + The representation of the group in OAKLEY is + + Type of group: "MODP" + Size of field element (bits): 768 + Prime modulus: 21 (decimal) + Length (32 bit words): 24 + Data (hex): + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A63A3620 FFFFFFFF FFFFFFFF + Generator: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 2 + + Optional Parameters: + Group order largest prime factor: 24 (decimal) + Length (32 bit words): 24 + Data (hex): + 7FFFFFFF FFFFFFFF E487ED51 10B4611A 62633145 C06E0E68 + 94812704 4533E63A 0105DF53 1D89CD91 28A5043C C71A026E + F7CA8CD9 E69D218D 98158536 F92F8A1B A7F09AB6 B6A8E122 + F242DABB 312F3F63 7A262174 D31D1B10 7FFFFFFF FFFFFFFF + Strength of group: 26 (decimal) + Length (32 bit words) 1 + Data (hex): + 00000042 + +E.2. Well-Known Group 2: A 1024 bit prime + + The prime is 2^1024 - 2^960 - 1 + 2^64 * { [2^894 pi] + 129093 }. + Its decimal value is + 179769313486231590770839156793787453197860296048756011706444 + 423684197180216158519368947833795864925541502180565485980503 + 646440548199239100050792877003355816639229553136239076508735 + 759914822574862575007425302077447712589550957937778424442426 + 617334727629299387668709205606050270810842907692932019128194 + + + +Orman Informational [Page 46] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + 467627007 + + The primality of the number has been rigorously proven. + + The representation of the group in OAKLEY is + Type of group: "MODP" + Size of field element (bits): 1024 + Prime modulus: 21 (decimal) + Length (32 bit words): 32 + Data (hex): + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE65381 + FFFFFFFF FFFFFFFF + Generator: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 2 + + Optional Parameters: + Group order largest prime factor: 24 (decimal) + Length (32 bit words): 32 + Data (hex): + 7FFFFFFF FFFFFFFF E487ED51 10B4611A 62633145 C06E0E68 + 94812704 4533E63A 0105DF53 1D89CD91 28A5043C C71A026E + F7CA8CD9 E69D218D 98158536 F92F8A1B A7F09AB6 B6A8E122 + F242DABB 312F3F63 7A262174 D31BF6B5 85FFAE5B 7A035BF6 + F71C35FD AD44CFD2 D74F9208 BE258FF3 24943328 F67329C0 + FFFFFFFF FFFFFFFF + Strength of group: 26 (decimal) + Length (32 bit words) 1 + Data (hex): + 0000004D + +E.3. Well-Known Group 3: An Elliptic Curve Group Definition + + The curve is based on the Galois field GF[2^155] with 2^155 field + elements. The irreducible polynomial for the field is u^155 + u^62 + + 1. The equation for the elliptic curve is + + Y^2 + X Y = X^3 + A X + B + + X, Y, A, B are elements of the field. + + For the curve specified, A = 0 and + + B = u^18 + u^17 + u^16 + u^13 + u^12 + u^9 + u^8 + u^7 + u^3 + u^2 + + + + +Orman Informational [Page 47] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + u + 1. + + B is represented in binary as the bit string 1110011001110001111; in + decimal this is 471951, and in hex 7338F. + + The generator is a point (X,Y) on the curve (satisfying the curve + equation, mod 2 and modulo the field polynomial). + + X = u^6 + u^5 + u^4 + u^3 + u + 1 + + and + + Y = u^8 + u^7 + u^6 + u^3. + + The binary bit strings for X and Y are 1111011 and 111001000; in + decimal they are 123 and 456. + + The group order (the number of curve points) is + 45671926166590716193865565914344635196769237316 + which is 12 times the prime + + 3805993847215893016155463826195386266397436443. + (This prime has been rigorously proven.) The generating point (X,Y) + has order 4 times the prime; the generator is the triple of some + curve point. + + OAKLEY representation of this group: + Type of group: "EC2N" + Size of field element (bits): 155 + Irreducible field polynomial: 21 (decimal) + Length (32 bit words): 5 + Data (hex): + 08000000 00000000 00000000 40000000 00000001 + Generator: + X coordinate: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 7B + Y coordinate: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 1C8 + Elliptic curve parameters: + A parameter: 23 (decimal) + Length (32 bit words): 1 + Data (hex): 0 + B parameter: 23 (decimal) + Length (32 bit words): 1 + Data (hex): 7338F + + + + +Orman Informational [Page 48] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + Optional Parameters: + Group order largest prime factor: 24 (decimal) + Length (32 bit words): 5 + Data (hex): + 00AAAAAA AAAAAAAA AAAAB1FC F1E206F4 21A3EA1B + Group order: 25 (decimal) + Length (32 bit words): 5 + Data (hex): + 08000000 00000000 000057DB 56985371 93AEF944 + Strength of group: 26 (decimal) + Length (32 bit words) 1 + Data (hex): + 0000004C + +E.4. Well-Known Group 4: A Large Elliptic Curve Group Definition + + This curve is based on the Galois field GF[2^185] with 2^185 field + elements. The irreducible polynomial for the field is + + u^185 + u^69 + 1. + + The equation for the elliptic curve is + + Y^2 + X Y = X^3 + A X + B. + + X, Y, A, B are elements of the field. For the curve specified, A = 0 + and + + B = u^12 + u^11 + u^10 + u^9 + u^7 + u^6 + u^5 + u^3 + 1. + + B is represented in binary as the bit string 1111011101001; in + decimal this is 7913, and in hex 1EE9. + + The generator is a point (X,Y) on the curve (satisfying the curve + equation, mod 2 and modulo the field polynomial); + + X = u^4 + u^3 and Y = u^3 + u^2 + 1. + + The binary bit strings for X and Y are 11000 and 1101; in decimal + they are 24 and 13. The group order (the number of curve points) is + + 49039857307708443467467104857652682248052385001045053116, + + which is 4 times the prime + + 12259964326927110866866776214413170562013096250261263279. + + (This prime has been rigorously proven.) + + + +Orman Informational [Page 49] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + The generating point (X,Y) has order 2 times the prime; the generator + is the double of some curve point. + + OAKLEY representation of this group: + + Type of group: "EC2N" + Size of field element (bits): 185 + Irreducible field polynomial: 21 (decimal) + Length (32 bit words): 6 + Data (hex): + 02000000 00000000 00000000 00000020 00000000 00000001 + Generator: + X coordinate: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 18 + Y coordinate: 22 (decimal) + Length (32 bit words): 1 + Data (hex): D + Elliptic curve parameters: + A parameter: 23 (decimal) + Length (32 bit words): 1 + Data (hex): 0 + B parameter: 23 (decimal) + Length (32 bit words): 1 + Data (hex): 1EE9 + + Optional parameters: + Group order largest prime factor: 24 (decimal) + Length (32 bit words): 6 + Data (hex): + 007FFFFF FFFFFFFF FFFFFFFF F6FCBE22 6DCF9210 5D7E53AF + Group order: 25 (decimal) + Length (32 bit words): 6 + Data (hex): + 01FFFFFF FFFFFFFF FFFFFFFF DBF2F889 B73E4841 75F94EBC + Strength of group: 26 (decimal) + Length (32 bit words) 1 + Data (hex): + 0000005B + +E.5. Well-Known Group 5: A 1536 bit prime + + The prime is 2^1536 - 2^1472 - 1 + 2^64 * { [2^1406 pi] + 741804 + }. + Its decimal value is + 241031242692103258855207602219756607485695054850245994265411 + 694195810883168261222889009385826134161467322714147790401219 + 650364895705058263194273070680500922306273474534107340669624 + + + +Orman Informational [Page 50] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + 601458936165977404102716924945320037872943417032584377865919 + 814376319377685986952408894019557734611984354530154704374720 + 774996976375008430892633929555996888245787241299381012913029 + 459299994792636526405928464720973038494721168143446471443848 + 8520940127459844288859336526896320919633919 + + The primality of the number has been rigorously proven. + + The representation of the group in OAKLEY is + Type of group: "MODP" + Size of field element (bits): 1536 + Prime modulus: 21 (decimal) + Length (32 bit words): 48 + Data (hex): + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA237327 FFFFFFFF FFFFFFFF + Generator: 22 (decimal) + Length (32 bit words): 1 + Data (hex): 2 + + Optional Parameters: + Group order largest prime factor: 24 (decimal) + Length (32 bit words): 48 + Data (hex): + 7FFFFFFF FFFFFFFF E487ED51 10B4611A 62633145 C06E0E68 + 94812704 4533E63A 0105DF53 1D89CD91 28A5043C C71A026E + F7CA8CD9 E69D218D 98158536 F92F8A1B A7F09AB6 B6A8E122 + F242DABB 312F3F63 7A262174 D31BF6B5 85FFAE5B 7A035BF6 + F71C35FD AD44CFD2 D74F9208 BE258FF3 24943328 F6722D9E + E1003E5C 50B1DF82 CC6D241B 0E2AE9CD 348B1FD4 7E9267AF + C1B2AE91 EE51D6CB 0E3179AB 1042A95D CF6A9483 B84B4B36 + B3861AA7 255E4C02 78BA3604 6511B993 FFFFFFFF FFFFFFFF + Strength of group: 26 (decimal) + Length (32 bit words) 1 + Data (hex): + 0000005B + + + + + + + + + +Orman Informational [Page 51] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +Appendix F Implementing Group Operations + + The group operation must be implemented as a sequence of arithmetic + operations; the exact operations depend on the type of group. For + modular exponentiation groups, the operation is multi-precision + integer multiplication and remainders by the group modulus. See + Knuth Vol. 2 [Knuth] for a discussion of how to implement these for + large integers. Implementation recommendations for elliptic curve + group operations over GF[2^N] are described in [Schroeppel]. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 52] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +BIBLIOGRAPHY + + [RFC2401] Atkinson, R., "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + [RFC2406] Atkinson, R., "IP Encapsulating Security Payload (ESP)", + RFC 2406, November 1998. + + [RFC2402] Atkinson, R., "IP Authentication Header", RFC 2402, + November 1998. + + [Blaze] Blaze, Matt et al., MINIMAL KEY LENGTHS FOR SYMMETRIC + CIPHERS TO PROVIDE ADEQUATE COMMERCIAL SECURITY. A + REPORT BY AN AD HOC GROUP OF CRYPTOGRAPHERS AND COMPUTER + SCIENTISTS... -- + http://www.bsa.org/policy/encryption/cryptographers.html + + [STS] W. Diffie, P.C. Van Oorschot, and M.J. Wiener, + "Authentication and Authenticated Key Exchanges," in + Designs, Codes and Cryptography, Kluwer Academic + Publishers, 1992, pp. 107 + + [SECDNS] Eastlake, D. and C. Kaufman, "Domain Name System + Security Extensions", RFC 2065, January 1997. + + [Random] Eastlake, D., Crocker, S. and J. Schiller, "Randomness + Recommendations for Security", RFC 1750, December 1994. + + [Kocher] Kocher, Paul, Timing Attack, + http://www.cryptography.com/timingattack.old/timingattack.html + + [Knuth] Knuth, Donald E., The Art of Computer Programming, Vol. + 2, Seminumerical Algorithms, Addison Wesley, 1969. + + [Krawcyzk] Krawcyzk, Hugo, SKEME: A Versatile Secure Key Exchange + Mechanism for Internet, ISOC Secure Networks and + Distributed Systems Symposium, San Diego, 1996 + + [Schneier] Schneier, Bruce, Applied cryptography: protocols, + algorithms, and source code in C, Second edition, John + Wiley & Sons, Inc. 1995, ISBN 0-471-12845-7, hardcover. + ISBN 0-471-11709-9, softcover. + + [Schroeppel] Schroeppel, Richard, et al.; Fast Key Exchange with + Elliptic Curve Systems, Crypto '95, Santa Barbara, 1995. + Available on-line as + ftp://ftp.cs.arizona.edu/reports/1995/TR95-03.ps (and + .Z). + + + +Orman Informational [Page 53] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + + [Stinson] Stinson, Douglas, Cryptography Theory and Practice. CRC + Press, Inc., 2000, Corporate Blvd., Boca Raton, FL, + 33431-9868, ISBN 0-8493-8521-0, 1995 + + [Zimmerman] Philip Zimmermann, The Official Pgp User's Guide, + Published by MIT Press Trade, Publication date: June + 1995, ISBN: 0262740176 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 54] + +RFC 2412 The OAKLEY Key Determination Protocol November 1998 + + +Full Copyright Statement + + Copyright (C) The Internet Society (1998). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + + + + + + + + + + + + + + + + + + + + + +Orman Informational [Page 55] + diff --git a/doc/ikev2/[RFC2437] - PKCS #1 RSA Cryptography Specifications Version 2.0.txt b/doc/ikev2/[RFC2437] - PKCS #1 RSA Cryptography Specifications Version 2.0.txt new file mode 100644 index 000000000..54f6d5db5 --- /dev/null +++ b/doc/ikev2/[RFC2437] - PKCS #1 RSA Cryptography Specifications Version 2.0.txt @@ -0,0 +1,2187 @@ + + + + + + +Network Working Group B. Kaliski +Request for Comments: 2437 J. Staddon +Obsoletes: 2313 RSA Laboratories +Category: Informational October 1998 + + + PKCS #1: RSA Cryptography Specifications + Version 2.0 + +Status of this Memo + + This memo provides information for the Internet community. It does + not specify an Internet standard of any kind. Distribution of this + memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (1998). All Rights Reserved. + +Table of Contents + + 1. Introduction.....................................2 + 1.1 Overview.........................................3 + 2. Notation.........................................3 + 3. Key types........................................5 + 3.1 RSA public key...................................5 + 3.2 RSA private key..................................5 + 4. Data conversion primitives.......................6 + 4.1 I2OSP............................................6 + 4.2 OS2IP............................................7 + 5. Cryptographic primitives.........................8 + 5.1 Encryption and decryption primitives.............8 + 5.1.1 RSAEP............................................8 + 5.1.2 RSADP............................................9 + 5.2 Signature and verification primitives...........10 + 5.2.1 RSASP1..........................................10 + 5.2.2 RSAVP1..........................................11 + 6. Overview of schemes.............................11 + 7. Encryption schemes..............................12 + 7.1 RSAES-OAEP......................................13 + 7.1.1 Encryption operation............................13 + 7.1.2 Decryption operation............................14 + 7.2 RSAES-PKCS1-v1_5................................15 + 7.2.1 Encryption operation............................17 + 7.2.2 Decryption operation............................17 + 8. Signature schemes with appendix.................18 + 8.1 RSASSA-PKCS1-v1_5...............................19 + 8.1.1 Signature generation operation..................20 + + + +Kaliski & Staddon Informational [Page 1] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + 8.1.2 Signature verification operation................21 + 9. Encoding methods................................22 + 9.1 Encoding methods for encryption.................22 + 9.1.1 EME-OAEP........................................22 + 9.1.2 EME-PKCS1-v1_5..................................24 + 9.2 Encoding methods for signatures with appendix...26 + 9.2.1 EMSA-PKCS1-v1_5.................................26 + 10. Auxiliary Functions.............................27 + 10.1 Hash Functions..................................27 + 10.2 Mask Generation Functions.......................28 + 10.2.1 MGF1............................................28 + 11. ASN.1 syntax....................................29 + 11.1 Key representation..............................29 + 11.1.1 Public-key syntax...............................30 + 11.1.2 Private-key syntax..............................30 + 11.2 Scheme identification...........................31 + 11.2.1 Syntax for RSAES-OAEP...........................31 + 11.2.2 Syntax for RSAES-PKCS1-v1_5.....................32 + 11.2.3 Syntax for RSASSA-PKCS1-v1_5....................33 + 12 Patent Statement................................33 + 12.1 Patent statement for the RSA algorithm..........34 + 13. Revision history................................35 + 14. References......................................35 + Security Considerations.........................37 + Acknowledgements................................37 + Authors' Addresses..............................38 + Full Copyright Statement........................39 + +1. Introduction + + This memo is the successor to RFC 2313. This document provides + recommendations for the implementation of public-key cryptography + based on the RSA algorithm [18], covering the following aspects: + + -cryptographic primitives + -encryption schemes + -signature schemes with appendix + -ASN.1 syntax for representing keys and for identifying the + schemes + + The recommendations are intended for general application within + computer and communications systems, and as such include a fair + amount of flexibility. It is expected that application standards + based on these specifications may include additional constraints. The + recommendations are intended to be compatible with draft standards + currently being developed by the ANSI X9F1 [1] and IEEE P1363 working + groups [14]. This document supersedes PKCS #1 version 1.5 [20]. + + + + +Kaliski & Staddon Informational [Page 2] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Editor's note. It is expected that subsequent versions of PKCS #1 may + cover other aspects of the RSA algorithm such as key size, key + generation, key validation, and signature schemes with message + recovery. + +1.1 Overview + + The organization of this document is as follows: + + -Section 1 is an introduction. + -Section 2 defines some notation used in this document. + -Section 3 defines the RSA public and private key types. + -Sections 4 and 5 define several primitives, or basic mathematical + operations. Data conversion primitives are in Section 4, and + cryptographic primitives (encryption-decryption, + signature-verification) are in Section 5. + -Section 6, 7 and 8 deal with the encryption and signature schemes + in this document. Section 6 gives an overview. Section 7 defines + an OAEP-based [2] encryption scheme along with the method found + in PKCS #1 v1.5. Section 8 defines a signature scheme with + appendix; the method is identical to that of PKCS #1 v1.5. + -Section 9 defines the encoding methods for the encryption and + signature schemes in Sections 7 and 8. + -Section 10 defines the hash functions and the mask generation + function used in this document. + -Section 11 defines the ASN.1 syntax for the keys defined in + Section 3 and the schemes gives in Sections 7 and 8. + -Section 12 outlines the revision history of PKCS #1. + -Section 13 contains references to other publications and + standards. + +2. Notation + + (n, e) RSA public key + + c ciphertext representative, an integer between 0 and n-1 + + C ciphertext, an octet string + + d private exponent + + dP p's exponent, a positive integer such that: + e(dP)\equiv 1 (mod(p-1)) + + dQ q's exponent, a positive integer such that: + e(dQ)\equiv 1 (mod(q-1)) + + e public exponent + + + +Kaliski & Staddon Informational [Page 3] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + EM encoded message, an octet string + + emLen intended length in octets of an encoded message + + H hash value, an output of Hash + + Hash hash function + + hLen output length in octets of hash function Hash + + K RSA private key + + k length in octets of the modulus + + l intended length of octet string + + lcm(.,.) least common multiple of two + nonnegative integers + + m message representative, an integer between + 0 and n-1 + + M message, an octet string + + MGF mask generation function + + n modulus + + P encoding parameters, an octet string + + p,q prime factors of the modulus + + qInv CRT coefficient, a positive integer less + than p such: q(qInv)\equiv 1 (mod p) + + s signature representative, an integer + between 0 and n-1 + + S signature, an octet string + + x a nonnegative integer + + X an octet string corresponding to x + + \xor bitwise exclusive-or of two octet strings + + \lambda(n) lcm(p-1, q-1), where n = pq + + + + +Kaliski & Staddon Informational [Page 4] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + || concatenation operator + + ||.|| octet length operator + +3. Key types + + Two key types are employed in the primitives and schemes defined in + this document: RSA public key and RSA private key. Together, an RSA + public key and an RSA private key form an RSA key pair. + +3.1 RSA public key + + For the purposes of this document, an RSA public key consists of two + components: + + n, the modulus, a nonnegative integer + e, the public exponent, a nonnegative integer + + In a valid RSA public key, the modulus n is a product of two odd + primes p and q, and the public exponent e is an integer between 3 and + n-1 satisfying gcd (e, \lambda(n)) = 1, where \lambda(n) = lcm (p- + 1,q-1). A recommended syntax for interchanging RSA public keys + between implementations is given in Section 11.1.1; an + implementation's internal representation may differ. + +3.2 RSA private key + + For the purposes of this document, an RSA private key may have either + of two representations. + + 1. The first representation consists of the pair (n, d), where the + components have the following meanings: + + n, the modulus, a nonnegative integer + d, the private exponent, a nonnegative integer + + 2. The second representation consists of a quintuple (p, q, dP, dQ, + qInv), where the components have the following meanings: + + p, the first factor, a nonnegative integer + q, the second factor, a nonnegative integer + dP, the first factor's exponent, a nonnegative integer + dQ, the second factor's exponent, a nonnegative integer + qInv, the CRT coefficient, a nonnegative integer + + In a valid RSA private key with the first representation, the modulus + n is the same as in the corresponding public key and is the product + of two odd primes p and q, and the private exponent d is a positive + + + +Kaliski & Staddon Informational [Page 5] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + integer less than n satisfying: + + ed \equiv 1 (mod \lambda(n)) + + where e is the corresponding public exponent and \lambda(n) is as + defined above. + + In a valid RSA private key with the second representation, the two + factors p and q are the prime factors of the modulus n, the exponents + dP and dQ are positive integers less than p and q respectively + satisfying + + e(dP)\equiv 1(mod(p-1)) + e(dQ)\equiv 1(mod(q-1)), + + and the CRT coefficient qInv is a positive integer less than p + satisfying: + + q(qInv)\equiv 1 (mod p). + + A recommended syntax for interchanging RSA private keys between + implementations, which includes components from both representations, + is given in Section 11.1.2; an implementation's internal + representation may differ. + +4. Data conversion primitives + + Two data conversion primitives are employed in the schemes defined in + this document: + + I2OSP: Integer-to-Octet-String primitive + OS2IP: Octet-String-to-Integer primitive + + For the purposes of this document, and consistent with ASN.1 syntax, an + octet string is an ordered sequence of octets (eight-bit bytes). The + sequence is indexed from first (conventionally, leftmost) to last + (rightmost). For purposes of conversion to and from integers, the first + octet is considered the most significant in the following conversion + primitives + +4.1 I2OSP + + I2OSP converts a nonnegative integer to an octet string of a specified + length. + + I2OSP (x, l) + + + + + +Kaliski & Staddon Informational [Page 6] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Input: + x nonnegative integer to be converted + l intended length of the resulting octet string + + Output: + X corresponding octet string of length l; or + "integer too large" + + Steps: + + 1. If x>=256^l, output "integer too large" and stop. + + 2. Write the integer x in its unique l-digit representation base 256: + + x = x_{l-1}256^{l-1} + x_{l-2}256^{l-2} +... + x_1 256 + x_0 + + where 0 <= x_i < 256 (note that one or more leading digits will be + zero if x < 256^{l-1}). + + 3. Let the octet X_i have the value x_{l-i} for 1 <= i <= l. Output + the octet string: + + X = X_1 X_2 ... X_l. + +4.2 OS2IP + + OS2IP converts an octet string to a nonnegative integer. + + OS2IP (X) + + Input: + X octet string to be converted + + Output: + x corresponding nonnegative integer + + Steps: + + 1. Let X_1 X_2 ... X_l be the octets of X from first to last, and + let x{l-i} have value X_i for 1<= i <= l. + + 2. Let x = x{l-1} 256^{l-1} + x_{l-2} 256^{l-2} +...+ x_1 256 + x_0. + + 3. Output x. + + + + + + + +Kaliski & Staddon Informational [Page 7] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +5. Cryptographic primitives + + Cryptographic primitives are basic mathematical operations on which + cryptographic schemes can be built. They are intended for + implementation in hardware or as software modules, and are not + intended to provide security apart from a scheme. + + Four types of primitive are specified in this document, organized in + pairs: encryption and decryption; and signature and verification. + + The specifications of the primitives assume that certain conditions + are met by the inputs, in particular that public and private keys are + valid. + +5.1 Encryption and decryption primitives + + An encryption primitive produces a ciphertext representative from a + message representative under the control of a public key, and a + decryption primitive recovers the message representative from the + ciphertext representative under the control of the corresponding + private key. + + One pair of encryption and decryption primitives is employed in the + encryption schemes defined in this document and is specified here: + RSAEP/RSADP. RSAEP and RSADP involve the same mathematical operation, + with different keys as input. + + The primitives defined here are the same as in the draft IEEE P1363 + and are compatible with PKCS #1 v1.5. + + The main mathematical operation in each primitive is exponentiation. + +5.1.1 RSAEP + + RSAEP((n, e), m) + + Input: + (n, e) RSA public key + m message representative, an integer between 0 and n-1 + + Output: + c ciphertext representative, an integer between 0 and n-1; + or "message representative out of range" + + Assumptions: public key (n, e) is valid + + Steps: + + + + +Kaliski & Staddon Informational [Page 8] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + 1. If the message representative m is not between 0 and n-1, output + message representative out of range and stop. + + 2. Let c = m^e mod n. + + 3. Output c. + +5.1.2 RSADP + + RSADP (K, c) + + Input: + + K RSA private key, where K has one of the following forms + -a pair (n, d) + -a quintuple (p, q, dP, dQ, qInv) + c ciphertext representative, an integer between 0 and n-1 + + Output: + m message representative, an integer between 0 and n-1; or + "ciphertext representative out of range" + + Assumptions: private key K is valid + + Steps: + + 1. If the ciphertext representative c is not between 0 and n-1, + output "ciphertext representative out of range" and stop. + + 2. If the first form (n, d) of K is used: + + 2.1 Let m = c^d mod n. Else, if the second form (p, q, dP, + dQ, qInv) of K is used: + + 2.2 Let m_1 = c^dP mod p. + + 2.3 Let m_2 = c^dQ mod q. + + 2.4 Let h = qInv ( m_1 - m_2 ) mod p. + + 2.5 Let m = m_2 + hq. + + 3. Output m. + + + + + + + + +Kaliski & Staddon Informational [Page 9] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +5.2 Signature and verification primitives + + A signature primitive produces a signature representative from a + message representative under the control of a private key, and a + verification primitive recovers the message representative from the + signature representative under the control of the corresponding + public key. One pair of signature and verification primitives is + employed in the signature schemes defined in this document and is + specified here: RSASP1/RSAVP1. + + The primitives defined here are the same as in the draft IEEE P1363 + and are compatible with PKCS #1 v1.5. + + The main mathematical operation in each primitive is exponentiation, + as in the encryption and decryption primitives of Section 5.1. RSASP1 + and RSAVP1 are the same as RSADP and RSAEP except for the names of + their input and output arguments; they are distinguished as they are + intended for different purposes. + +5.2.1 RSASP1 + + RSASP1 (K, m) + + Input: + K RSA private key, where K has one of the following + forms: + -a pair (n, d) + -a quintuple (p, q, dP, dQ, qInv) + + m message representative, an integer between 0 and n-1 + + Output: + s signature representative, an integer between 0 and + n-1, or "message representative out of range" + + Assumptions: + private key K is valid + + Steps: + + 1. If the message representative m is not between 0 and n-1, output + "message representative out of range" and stop. + + 2. If the first form (n, d) of K is used: + + 2.1 Let s = m^d mod n. Else, if the second form (p, q, dP, + dQ, qInv) of K is used: + + + + +Kaliski & Staddon Informational [Page 10] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + 2.2 Let s_1 = m^dP mod p. + + 2.3 Let s_2 = m^dQ mod q. + + 2.4 Let h = qInv ( s_1 - s_2 ) mod p. + + 2.5 Let s = s_2 + hq. + + 3. Output S. + +5.2.2 RSAVP1 + + RSAVP1 ((n, e), s) + + Input: + (n, e) RSA public key + s signature representative, an integer between 0 and n-1 + + Output: + m message representative, an integer between 0 and n-1; + or "invalid" + + Assumptions: + public key (n, e) is valid + + Steps: + + 1. If the signature representative s is not between 0 and n-1, output + "invalid" and stop. + + 2. Let m = s^e mod n. + + 3. Output m. + +6. Overview of schemes + + A scheme combines cryptographic primitives and other techniques to + achieve a particular security goal. Two types of scheme are specified + in this document: encryption schemes and signature schemes with + appendix. + + The schemes specified in this document are limited in scope in that + their operations consist only of steps to process data with a key, + and do not include steps for obtaining or validating the key. Thus, + in addition to the scheme operations, an application will typically + include key management operations by which parties may select public + and private keys for a scheme operation. The specific additional + operations and other details are outside the scope of this document. + + + +Kaliski & Staddon Informational [Page 11] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + As was the case for the cryptographic primitives (Section 5), the + specifications of scheme operations assume that certain conditions + are met by the inputs, in particular that public and private keys are + valid. The behavior of an implementation is thus unspecified when a + key is invalid. The impact of such unspecified behavior depends on + the application. Possible means of addressing key validation include + explicit key validation by the application; key validation within the + public-key infrastructure; and assignment of liability for operations + performed with an invalid key to the party who generated the key. + +7. Encryption schemes + + An encryption scheme consists of an encryption operation and a + decryption operation, where the encryption operation produces a + ciphertext from a message with a recipient's public key, and the + decryption operation recovers the message from the ciphertext with + the recipient's corresponding private key. + + An encryption scheme can be employed in a variety of applications. A + typical application is a key establishment protocol, where the + message contains key material to be delivered confidentially from one + party to another. For instance, PKCS #7 [21] employs such a protocol + to deliver a content-encryption key from a sender to a recipient; the + encryption schemes defined here would be suitable key-encryption + algorithms in that context. + + Two encryption schemes are specified in this document: RSAES-OAEP and + RSAES-PKCS1-v1_5. RSAES-OAEP is recommended for new applications; + RSAES-PKCS1-v1_5 is included only for compatibility with existing + applications, and is not recommended for new applications. + + The encryption schemes given here follow a general model similar to + that employed in IEEE P1363, by combining encryption and decryption + primitives with an encoding method for encryption. The encryption + operations apply a message encoding operation to a message to produce + an encoded message, which is then converted to an integer message + representative. An encryption primitive is applied to the message + representative to produce the ciphertext. Reversing this, the + decryption operations apply a decryption primitive to the ciphertext + to recover a message representative, which is then converted to an + octet string encoded message. A message decoding operation is applied + to the encoded message to recover the message and verify the + correctness of the decryption. + + + + + + + + +Kaliski & Staddon Informational [Page 12] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +7.1 RSAES-OAEP + + RSAES-OAEP combines the RSAEP and RSADP primitives (Sections 5.1.1 + and 5.1.2) with the EME-OAEP encoding method (Section 9.1.1) EME-OAEP + is based on the method found in [2]. It is compatible with the IFES + scheme defined in the draft P1363 where the encryption and decryption + primitives are IFEP-RSA and IFDP-RSA and the message encoding method + is EME-OAEP. RSAES-OAEP can operate on messages of length up to k-2- + 2hLen octets, where hLen is the length of the hash function output + for EME-OAEP and k is the length in octets of the recipient's RSA + modulus. Assuming that the hash function in EME-OAEP has appropriate + properties, and the key size is sufficiently large, RSAEP-OAEP + provides "plaintext-aware encryption," meaning that it is + computationally infeasible to obtain full or partial information + about a message from a ciphertext, and computationally infeasible to + generate a valid ciphertext without knowing the corresponding + message. Therefore, a chosen-ciphertext attack is ineffective + against a plaintext-aware encryption scheme such as RSAES-OAEP. + + Both the encryption and the decryption operations of RSAES-OAEP take + the value of the parameter string P as input. In this version of PKCS + #1, P is an octet string that is specified explicitly. See Section + 11.2.1 for the relevant ASN.1 syntax. We briefly note that to receive + the full security benefit of RSAES-OAEP, it should not be used in a + protocol involving RSAES-PKCS1-v1_5. It is possible that in a + protocol on which both encryption schemes are present, an adaptive + chosen ciphertext attack such as [4] would be useful. + + Both the encryption and the decryption operations of RSAES-OAEP take + the value of the parameter string P as input. In this version of PKCS + #1, P is an octet string that is specified explicitly. See Section + 11.2.1 for the relevant ASN.1 syntax. + +7.1.1 Encryption operation + + RSAES-OAEP-ENCRYPT ((n, e), M, P) + + Input: + (n, e) recipient's RSA public key + + M message to be encrypted, an octet string of length at + most k-2-2hLen, where k is the length in octets of the + modulus n and hLen is the length in octets of the hash + function output for EME-OAEP + + P encoding parameters, an octet string that may be empty + + + + + +Kaliski & Staddon Informational [Page 13] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Output: + C ciphertext, an octet string of length k; or "message too + long" + + Assumptions: public key (n, e) is valid + + Steps: + + 1. Apply the EME-OAEP encoding operation (Section 9.1.1.2) to the + message M and the encoding parameters P to produce an encoded message + EM of length k-1 octets: + + EM = EME-OAEP-ENCODE (M, P, k-1) + + If the encoding operation outputs "message too long," then output + "message too long" and stop. + + 2. Convert the encoded message EM to an integer message + representative m: m = OS2IP (EM) + + 3. Apply the RSAEP encryption primitive (Section 5.1.1) to the public + key (n, e) and the message representative m to produce an integer + ciphertext representative c: + + c = RSAEP ((n, e), m) + + 4. Convert the ciphertext representative c to a ciphertext C of + length k octets: C = I2OSP (c, k) + + 5. Output the ciphertext C. + +7.1.2 Decryption operation + + RSAES-OAEP-DECRYPT (K, C, P) + + Input: + K recipient's RSA private key + C ciphertext to be decrypted, an octet string of length + k, where k is the length in octets of the modulus n + P encoding parameters, an octet string that may be empty + + Output: + M message, an octet string of length at most k-2-2hLen, + where hLen is the length in octets of the hash + function output for EME-OAEP; or "decryption error" + + + + + + +Kaliski & Staddon Informational [Page 14] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Steps: + + 1. If the length of the ciphertext C is not k octets, output + "decryption error" and stop. + + 2. Convert the ciphertext C to an integer ciphertext representative + c: c = OS2IP (C). + + 3. Apply the RSADP decryption primitive (Section 5.1.2) to the + private key K and the ciphertext representative c to produce an + integer message representative m: + + m = RSADP (K, c) + + If RSADP outputs "ciphertext out of range," then output "decryption + error" and stop. + + 4. Convert the message representative m to an encoded message EM of + length k-1 octets: EM = I2OSP (m, k-1) + + If I2OSP outputs "integer too large," then output "decryption error" + and stop. + + 5. Apply the EME-OAEP decoding operation to the encoded message EM + and the encoding parameters P to recover a message M: + + M = EME-OAEP-DECODE (EM, P) + + If the decoding operation outputs "decoding error," then output + "decryption error" and stop. + + 6. Output the message M. + + Note. It is important that the error messages output in steps 4 and 5 + be the same, otherwise an adversary may be able to extract useful + information from the type of error message received. Error message + information is used to mount a chosen-ciphertext attack on PKCS #1 + v1.5 encrypted messages in [4]. + +7.2 RSAES-PKCS1-v1_5 + + RSAES-PKCS1-v1_5 combines the RSAEP and RSADP primitives with the + EME-PKCS1-v1_5 encoding method. It is the same as the encryption + scheme in PKCS #1 v1.5. RSAES-PKCS1-v1_5 can operate on messages of + length up to k-11 octets, although care should be taken to avoid + certain attacks on low-exponent RSA due to Coppersmith, et al. when + long messages are encrypted (see the third bullet in the notes below + and [7]). + + + +Kaliski & Staddon Informational [Page 15] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + RSAES-PKCS1-v1_5 does not provide "plaintext aware" encryption. In + particular, it is possible to generate valid ciphertexts without + knowing the corresponding plaintexts, with a reasonable probability + of success. This ability can be exploited in a chosen ciphertext + attack as shown in [4]. Therefore, if RSAES-PKCS1-v1_5 is to be used, + certain easily implemented countermeasures should be taken to thwart + the attack found in [4]. The addition of structure to the data to be + encoded, rigorous checking of PKCS #1 v1.5 conformance and other + redundancy in decrypted messages, and the consolidation of error + messages in a client-server protocol based on PKCS #1 v1.5 can all be + effective countermeasures and don't involve changes to a PKCS #1 + v1.5-based protocol. These and other countermeasures are discussed in + [5]. + + Notes. The following passages describe some security recommendations + pertaining to the use of RSAES-PKCS1-v1_5. Recommendations from + version 1.5 of this document are included as well as new + recommendations motivated by cryptanalytic advances made in the + intervening years. + + -It is recommended that the pseudorandom octets in EME-PKCS1-v1_5 be + generated independently for each encryption process, especially if + the same data is input to more than one encryption process. Hastad's + results [13] are one motivation for this recommendation. + + -The padding string PS in EME-PKCS1-v1_5 is at least eight octets + long, which is a security condition for public-key operations that + prevents an attacker from recovering data by trying all possible + encryption blocks. + + -The pseudorandom octets can also help thwart an attack due to + Coppersmith et al. [7] when the size of the message to be encrypted + is kept small. The attack works on low-exponent RSA when similar + messages are encrypted with the same public key. More specifically, + in one flavor of the attack, when two inputs to RSAEP agree on a + large fraction of bits (8/9) and low-exponent RSA (e = 3) is used to + encrypt both of them, it may be possible to recover both inputs with + the attack. Another flavor of the attack is successful in decrypting + a single ciphertext when a large fraction (2/3) of the input to RSAEP + is already known. For typical applications, the message to be + encrypted is short (e.g., a 128-bit symmetric key) so not enough + information will be known or common between two messages to enable + the attack. However, if a long message is encrypted, or if part of a + message is known, then the attack may be a concern. In any case, the + RSAEP-OAEP scheme overcomes the attack. + + + + + + +Kaliski & Staddon Informational [Page 16] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +7.2.1 Encryption operation + + RSAES-PKCS1-V1_5-ENCRYPT ((n, e), M) + + Input: + (n, e) recipient's RSA public key + M message to be encrypted, an octet string of length at + most k-11 octets, where k is the length in octets of the + modulus n + + Output: + C ciphertext, an octet string of length k; or "message too + long" + + Steps: + + 1. Apply the EME-PKCS1-v1_5 encoding operation (Section 9.1.2.1) to + the message M to produce an encoded message EM of length k-1 octets: + + EM = EME-PKCS1-V1_5-ENCODE (M, k-1) + + If the encoding operation outputs "message too long," then output + "message too long" and stop. + + 2. Convert the encoded message EM to an integer message + representative m: m = OS2IP (EM) + + 3. Apply the RSAEP encryption primitive (Section 5.1.1) to the public + key (n, e) and the message representative m to produce an integer + ciphertext representative c: c = RSAEP ((n, e), m) + + 4. Convert the ciphertext representative c to a ciphertext C of + length k octets: C = I2OSP (c, k) + + 5. Output the ciphertext C. + +7.2.2 Decryption operation + + RSAES-PKCS1-V1_5-DECRYPT (K, C) + + Input: + K recipient's RSA private key + C ciphertext to be decrypted, an octet string of length k, + where k is the length in octets of the modulus n + + Output: + M message, an octet string of length at most k-11; or + "decryption error" + + + +Kaliski & Staddon Informational [Page 17] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Steps: + + 1. If the length of the ciphertext C is not k octets, output + "decryption error" and stop. + + 2. Convert the ciphertext C to an integer ciphertext representative + c: c = OS2IP (C). + + 3. Apply the RSADP decryption primitive to the private key (n, d) and + the ciphertext representative c to produce an integer message + representative m: m = RSADP ((n, d), c). + + If RSADP outputs "ciphertext out of range," then output "decryption + error" and stop. + + 4. Convert the message representative m to an encoded message EM of + length k-1 octets: EM = I2OSP (m, k-1) + + If I2OSP outputs "integer too large," then output "decryption error" + and stop. + + 5. Apply the EME-PKCS1-v1_5 decoding operation to the encoded message + EM to recover a message M: M = EME-PKCS1-V1_5-DECODE (EM). + + If the decoding operation outputs "decoding error," then output + "decryption error" and stop. + + 6. Output the message M. + + Note. It is important that only one type of error message is output + by EME-PKCS1-v1_5, as ensured by steps 4 and 5. If this is not done, + then an adversary may be able to use information extracted form the + type of error message received to mount a chosen-ciphertext attack + such as the one found in [4]. + +8. Signature schemes with appendix + + A signature scheme with appendix consists of a signature generation + operation and a signature verification operation, where the signature + generation operation produces a signature from a message with a + signer's private key, and the signature verification operation + verifies the signature on the message with the signer's corresponding + public key. To verify a signature constructed with this type of + scheme it is necessary to have the message itself. In this way, + signature schemes with appendix are distinguished from signature + schemes with message recovery, which are not supported in this + document. + + + + +Kaliski & Staddon Informational [Page 18] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + A signature scheme with appendix can be employed in a variety of + applications. For instance, X.509 [6] employs such a scheme to + authenticate the content of a certificate; the signature scheme with + appendix defined here would be a suitable signature algorithm in that + context. A related signature scheme could be employed in PKCS #7 + [21], although for technical reasons, the current version of PKCS #7 + separates a hash function from a signature scheme, which is different + than what is done here. + + One signature scheme with appendix is specified in this document: + RSASSA-PKCS1-v1_5. + + The signature scheme with appendix given here follows a general model + similar to that employed in IEEE P1363, by combining signature and + verification primitives with an encoding method for signatures. The + signature generation operations apply a message encoding operation to + a message to produce an encoded message, which is then converted to + an integer message representative. A signature primitive is then + applied to the message representative to produce the signature. The + signature verification operations apply a signature verification + primitive to the signature to recover a message representative, which + is then converted to an octet string. The message encoding operation + is again applied to the message, and the result is compared to the + recovered octet string. If there is a match, the signature is + considered valid. (Note that this approach assumes that the signature + and verification primitives have the message-recovery form and the + encoding method is deterministic, as is the case for RSASP1/RSAVP1 + and EMSA-PKCS1-v1_5. The signature generation and verification + operations have a different form in P1363 for other primitives and + encoding methods.) + + Editor's note. RSA Laboratories is investigating the possibility of + including a scheme based on the PSS encoding methods specified in + [3], which would be recommended for new applications. + +8.1 RSASSA-PKCS1-v1_5 + + RSASSA-PKCS1-v1_5 combines the RSASP1 and RSAVP1 primitives with the + EME-PKCS1-v1_5 encoding method. It is compatible with the IFSSA + scheme defined in the draft P1363 where the signature and + verification primitives are IFSP-RSA1 and IFVP-RSA1 and the message + encoding method is EMSA-PKCS1-v1_5 (which is not defined in P1363). + The length of messages on which RSASSA-PKCS1-v1_5 can operate is + either unrestricted or constrained by a very large number, depending + on the hash function underlying the message encoding method. + + + + + + +Kaliski & Staddon Informational [Page 19] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Assuming that the hash function in EMSA-PKCS1-v1_5 has appropriate + properties and the key size is sufficiently large, RSASSA-PKCS1-v1_5 + provides secure signatures, meaning that it is computationally + infeasible to generate a signature without knowing the private key, + and computationally infeasible to find a message with a given + signature or two messages with the same signature. Also, in the + encoding method EMSA-PKCS1-v1_5, a hash function identifier is + embedded in the encoding. Because of this feature, an adversary must + invert or find collisions of the particular hash function being used; + attacking a different hash function than the one selected by the + signer is not useful to the adversary. + +8.1.1 Signature generation operation + + RSASSA-PKCS1-V1_5-SIGN (K, M) + Input: + K signer's RSA private ke + M message to be signed, an octet string + + Output: + S signature, an octet string of length k, where k is the + length in octets of the modulus n; "message too long" or + "modulus too short" + Steps: + + 1. Apply the EMSA-PKCS1-v1_5 encoding operation (Section 9.2.1) to + the message M to produce an encoded message EM of length k-1 octets: + + EM = EMSA-PKCS1-V1_5-ENCODE (M, k-1) + + If the encoding operation outputs "message too long," then output + "message too long" and stop. If the encoding operation outputs + "intended encoded message length too short" then output "modulus too + short". + + 2. Convert the encoded message EM to an integer message + representative m: m = OS2IP (EM) + + 3. Apply the RSASP1 signature primitive (Section 5.2.1) to the + private key K and the message representative m to produce an integer + signature representative s: s = RSASP1 (K, m) + + 4. Convert the signature representative s to a signature S of length + k octets: S = I2OSP (s, k) + + 5. Output the signature S. + + + + + +Kaliski & Staddon Informational [Page 20] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +8.1.2 Signature verification operation + + RSASSA-PKCS1-V1_5-VERIFY ((n, e), M, S) + + Input: + (n, e) signer's RSA public key + M message whose signature is to be verified, an octet string + S signature to be verified, an octet string of length k, + where k is the length in octets of the modulus n + + Output: "valid signature," "invalid signature," or "message too + long", or "modulus too short" + + Steps: + + 1. If the length of the signature S is not k octets, output "invalid + signature" and stop. + + 2. Convert the signature S to an integer signature representative s: + + s = OS2IP (S) + + 3. Apply the RSAVP1 verification primitive (Section 5.2.2) to the + public key (n, e) and the signature representative s to produce an + integer message representative m: + + m = RSAVP1 ((n, e), s) If RSAVP1 outputs "invalid" + then output "invalid signature" and stop. + + 4. Convert the message representative m to an encoded message EM of + length k-1 octets: EM = I2OSP (m, k-1) + + If I2OSP outputs "integer too large," then output "invalid signature" + and stop. + + 5. Apply the EMSA-PKCS1-v1_5 encoding operation (Section 9.2.1) to + the message M to produce a second encoded message EM' of length k-1 + octets: + + EM' = EMSA-PKCS1-V1_5-ENCODE (M, k-1) + + If the encoding operation outputs "message too long," then output + "message too long" and stop. If the encoding operation outputs + "intended encoded message length too short" then output "modulus too + short". + + + + + + +Kaliski & Staddon Informational [Page 21] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + 6. Compare the encoded message EM and the second encoded message EM'. + If they are the same, output "valid signature"; otherwise, output + "invalid signature." + +9. Encoding methods + + Encoding methods consist of operations that map between octet string + messages and integer message representatives. + + Two types of encoding method are considered in this document: + encoding methods for encryption, encoding methods for signatures with + appendix. + +9.1 Encoding methods for encryption + + An encoding method for encryption consists of an encoding operation + and a decoding operation. An encoding operation maps a message M to a + message representative EM of a specified length; the decoding + operation maps a message representative EM back to a message. The + encoding and decoding operations are inverses. + + The message representative EM will typically have some structure that + can be verified by the decoding operation; the decoding operation + will output "decoding error" if the structure is not present. The + encoding operation may also introduce some randomness, so that + different applications of the encoding operation to the same message + will produce different representatives. + + Two encoding methods for encryption are employed in the encryption + schemes and are specified here: EME-OAEP and EME-PKCS1-v1_5. + +9.1.1 EME-OAEP + + This encoding method is parameterized by the choice of hash function + and mask generation function. Suggested hash and mask generation + functions are given in Section 10. This encoding method is based on + the method found in [2]. + +9.1.1.1 Encoding operation + + EME-OAEP-ENCODE (M, P, emLen) + + Options: + Hash hash function (hLen denotes the length in octet of the + hash function output) + MGF mask generation function + + + + + +Kaliski & Staddon Informational [Page 22] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Input: + M message to be encoded, an octet string of length at most + emLen-1-2hLen + P encoding parameters, an octet string + emLen intended length in octets of the encoded message, at least + 2hLen+1 + + Output: + EM encoded message, an octet string of length emLen; + "message too long" or "parameter string too long" + + Steps: + + 1. If the length of P is greater than the input limitation for the + hash function (2^61-1 octets for SHA-1) then output "parameter string + too long" and stop. + + 2. If ||M|| > emLen-2hLen-1 then output "message too long" and stop. + + 3. Generate an octet string PS consisting of emLen-||M||-2hLen-1 zero + octets. The length of PS may be 0. + + 4. Let pHash = Hash(P), an octet string of length hLen. + + 5. Concatenate pHash, PS, the message M, and other padding to form a + data block DB as: DB = pHash || PS || 01 || M + + 6. Generate a random octet string seed of length hLen. + + 7. Let dbMask = MGF(seed, emLen-hLen). + + 8. Let maskedDB = DB \xor dbMask. + + 9. Let seedMask = MGF(maskedDB, hLen). + + 10. Let maskedSeed = seed \xor seedMask. + + 11. Let EM = maskedSeed || maskedDB. + + 12. Output EM. + +9.1.1.2 Decoding operation EME-OAEP-DECODE (EM, P) + + Options: + Hash hash function (hLen denotes the length in octet of the hash + function output) + + MGF mask generation function + + + +Kaliski & Staddon Informational [Page 23] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Input: + + EM encoded message, an octet string of length at least 2hLen+1 + P encoding parameters, an octet string + + Output: + M recovered message, an octet string of length at most + ||EM||-1-2hLen; or "decoding error" + + Steps: + + 1. If the length of P is greater than the input limitation for the + hash function (2^61-1 octets for SHA-1) then output "parameter string + too long" and stop. + + 2. If ||EM|| < 2hLen+1, then output "decoding error" and stop. + + 3. Let maskedSeed be the first hLen octets of EM and let maskedDB be + the remaining ||EM|| - hLen octets. + + 4. Let seedMask = MGF(maskedDB, hLen). + + 5. Let seed = maskedSeed \xor seedMask. + + 6. Let dbMask = MGF(seed, ||EM|| - hLen). + + 7. Let DB = maskedDB \xor dbMask. + + 8. Let pHash = Hash(P), an octet string of length hLen. + + 9. Separate DB into an octet string pHash' consisting of the first + hLen octets of DB, a (possibly empty) octet string PS consisting of + consecutive zero octets following pHash', and a message M as: + + DB = pHash' || PS || 01 || M + + If there is no 01 octet to separate PS from M, output "decoding + error" and stop. + + 10. If pHash' does not equal pHash, output "decoding error" and stop. + + 11. Output M. + +9.1.2 EME-PKCS1-v1_5 + + This encoding method is the same as in PKCS #1 v1.5, Section 8: + Encryption Process. + + + + +Kaliski & Staddon Informational [Page 24] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +9.1.2.1 Encoding operation + + EME-PKCS1-V1_5-ENCODE (M, emLen) + + Input: + M message to be encoded, an octet string of length at most + emLen-10 + emLen intended length in octets of the encoded message + + Output: + EM encoded message, an octet string of length emLen; or + "message too long" + + Steps: + + 1. If the length of the message M is greater than emLen - 10 octets, + output "message too long" and stop. + + 2. Generate an octet string PS of length emLen-||M||-2 consisting of + pseudorandomly generated nonzero octets. The length of PS will be at + least 8 octets. + + 3. Concatenate PS, the message M, and other padding to form the + encoded message EM as: + + EM = 02 || PS || 00 || M + + 4. Output EM. + +9.1.2.2 Decoding operation + + EME-PKCS1-V1_5-DECODE (EM) + + Input: + EM encoded message, an octet string of length at least 10 + + Output: + M recovered message, an octet string of length at most + ||EM||-10; or "decoding error" + + Steps: + + 1. If the length of the encoded message EM is less than 10, output + "decoding error" and stop. + + 2. Separate the encoded message EM into an octet string PS consisting + of nonzero octets and a message M as: EM = 02 || PS || 00 || M. + + + + +Kaliski & Staddon Informational [Page 25] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + If the first octet of EM is not 02, or if there is no 00 octet to + separate PS from M, output "decoding error" and stop. + + 3. If the length of PS is less than 8 octets, output "decoding error" + and stop. + + 4. Output M. + +9.2 Encoding methods for signatures with appendix + + An encoding method for signatures with appendix, for the purposes of + this document, consists of an encoding operation. An encoding + operation maps a message M to a message representative EM of a + specified length. (In future versions of this document, encoding + methods may be added that also include a decoding operation.) + + One encoding method for signatures with appendix is employed in the + encryption schemes and is specified here: EMSA-PKCS1-v1_5. + +9.2.1 EMSA-PKCS1-v1_5 + + This encoding method only has an encoding operation. + + EMSA-PKCS1-v1_5-ENCODE (M, emLen) + + Option: + Hash hash function (hLen denotes the length in octet of the hash + function output) + + Input: + M message to be encoded + emLen intended length in octets of the encoded message, at least + ||T|| + 10, where T is the DER encoding of a certain value + computed during the encoding operation + + Output: + EM encoded message, an octet string of length emLen; or "message + too long" or "intended encoded message length too short" + + Steps: + + 1. Apply the hash function to the message M to produce a hash value + H: + + H = Hash(M). + + If the hash function outputs "message too long," then output "message + too long". + + + +Kaliski & Staddon Informational [Page 26] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + 2. Encode the algorithm ID for the hash function and the hash value + into an ASN.1 value of type DigestInfo (see Section 11) with the + Distinguished Encoding Rules (DER), where the type DigestInfo has the + syntax + + DigestInfo::=SEQUENCE{ + digestAlgorithm AlgorithmIdentifier, + digest OCTET STRING } + + The first field identifies the hash function and the second contains + the hash value. Let T be the DER encoding. + + 3. If emLen is less than ||T|| + 10 then output "intended encoded + message length too short". + + 4. Generate an octet string PS consisting of emLen-||T||-2 octets + with value FF (hexadecimal). The length of PS will be at least 8 + octets. + + 5. Concatenate PS, the DER encoding T, and other padding to form the + encoded message EM as: EM = 01 || PS || 00 || T + + 6. Output EM. + +10. Auxiliary Functions + + This section specifies the hash functions and the mask generation + functions that are mentioned in the encoding methods (Section 9). + +10.1 Hash Functions + + Hash functions are used in the operations contained in Sections 7, 8 + and 9. Hash functions are deterministic, meaning that the output is + completely determined by the input. Hash functions take octet strings + of variable length, and generate fixed length octet strings. The hash + functions used in the operations contained in Sections 7, 8 and 9 + should be collision resistant. This means that it is infeasible to + find two distinct inputs to the hash function that produce the same + output. A collision resistant hash function also has the desirable + property of being one-way; this means that given an output, it is + infeasible to find an input whose hash is the specified output. The + property of collision resistance is especially desirable for RSASSA- + PKCS1-v1_5, as it makes it infeasible to forge signatures. In + addition to the requirements, the hash function should yield a mask + generation function (Section 10.2) with pseudorandom output. + + + + + + +Kaliski & Staddon Informational [Page 27] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Three hash functions are recommended for the encoding methods in this + document: MD2 [15], MD5 [17], and SHA-1 [16]. For the EME-OAEP + encoding method, only SHA-1 is recommended. For the EMSA-PKCS1-v1_5 + encoding method, SHA-1 is recommended for new applications. MD2 and + MD5 are recommended only for compatibility with existing applications + based on PKCS #1 v1.5. + + The hash functions themselves are not defined here; readers are + referred to the appropriate references ([15], [17] and [16]). + + Note. Version 1.5 of this document also allowed for the use of MD4 in + signature schemes. The cryptanalysis of MD4 has progressed + significantly in the intervening years. For example, Dobbertin [10] + demonstrated how to find collisions for MD4 and that the first two + rounds of MD4 are not one-way [11]. Because of these results and + others (e.g. [9]), MD4 is no longer recommended. There have also been + advances in the cryptanalysis of MD2 and MD5, although not enough to + warrant removal from existing applications. Rogier and Chauvaud [19] + demonstrated how to find collisions in a modified version of MD2. No + one has demonstrated how to find collisions for the full MD5 + algorithm, although partial results have been found (e.g. [8]). For + new applications, to address these concerns, SHA-1 is preferred. + +10.2 Mask Generation Functions + + A mask generation function takes an octet string of variable length + and a desired output length as input, and outputs an octet string of + the desired length. There may be restrictions on the length of the + input and output octet strings, but such bounds are generally very + large. Mask generation functions are deterministic; the octet string + output is completely determined by the input octet string. The output + of a mask generation function should be pseudorandom, that is, if the + seed to the function is unknown, it should be infeasible to + distinguish the output from a truly random string. The plaintext- + awareness of RSAES-OAEP relies on the random nature of the output of + the mask generation function, which in turn relies on the random + nature of the underlying hash. + + One mask generation function is recommended for the encoding methods + in this document, and is defined here: MGF1, which is based on a hash + function. Future versions of this document may define other mask + generation functions. + +10.2.1 MGF1 + + MGF1 is a Mask Generation Function based on a hash function. + + MGF1 (Z, l) + + + +Kaliski & Staddon Informational [Page 28] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + Options: + Hash hash function (hLen denotes the length in octets of the hash + function output) + + Input: + Z seed from which mask is generated, an octet string + l intended length in octets of the mask, at most 2^32(hLen) + + Output: + mask mask, an octet string of length l; or "mask too long" + + Steps: + + 1.If l > 2^32(hLen), output "mask too long" and stop. + + 2.Let T be the empty octet string. + + 3.For counter from 0 to \lceil{l / hLen}\rceil-1, do the following: + + a.Convert counter to an octet string C of length 4 with the primitive + I2OSP: C = I2OSP (counter, 4) + + b.Concatenate the hash of the seed Z and C to the octet string T: T = + T || Hash (Z || C) + + 4.Output the leading l octets of T as the octet string mask. + +11. ASN.1 syntax + +11.1 Key representation + + This section defines ASN.1 object identifiers for RSA public and + private keys, and defines the types RSAPublicKey and RSAPrivateKey. + The intended application of these definitions includes X.509 + certificates, PKCS #8 [22], and PKCS #12 [23]. + + The object identifier rsaEncryption identifies RSA public and private + keys as defined in Sections 11.1.1 and 11.1.2. The parameters field + associated with this OID in an AlgorithmIdentifier shall have type + NULL. + + rsaEncryption OBJECT IDENTIFIER ::= {pkcs-1 1} + + All of the definitions in this section are the same as in PKCS #1 + v1.5. + + + + + + +Kaliski & Staddon Informational [Page 29] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +11.1.1 Public-key syntax + + An RSA public key should be represented with the ASN.1 type + RSAPublicKey: + + RSAPublicKey::=SEQUENCE{ + modulus INTEGER, -- n + publicExponent INTEGER -- e } + + (This type is specified in X.509 and is retained here for + compatibility.) + + The fields of type RSAPublicKey have the following meanings: + -modulus is the modulus n. + -publicExponent is the public exponent e. + +11.1.2 Private-key syntax + + An RSA private key should be represented with ASN.1 type + RSAPrivateKey: + + RSAPrivateKey ::= SEQUENCE { + version Version, + modulus INTEGER, -- n + publicExponent INTEGER, -- e + privateExponent INTEGER, -- d + prime1 INTEGER, -- p + prime2 INTEGER, -- q + exponent1 INTEGER, -- d mod (p-1) + exponent2 INTEGER, -- d mod (q-1) + coefficient INTEGER -- (inverse of q) mod p } + + Version ::= INTEGER + + The fields of type RSAPrivateKey have the following meanings: + + -version is the version number, for compatibility with future + revisions of this document. It shall be 0 for this version of the + document. + -modulus is the modulus n. + -publicExponent is the public exponent e. + -privateExponent is the private exponent d. + -prime1 is the prime factor p of n. + -prime2 is the prime factor q of n. + -exponent1 is d mod (p-1). + -exponent2 is d mod (q-1). + -coefficient is the Chinese Remainder Theorem coefficient q-1 mod p. + + + + +Kaliski & Staddon Informational [Page 30] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +11.2 Scheme identification + + This section defines object identifiers for the encryption and + signature schemes. The schemes compatible with PKCS #1 v1.5 have the + same definitions as in PKCS #1 v1.5. The intended application of + these definitions includes X.509 certificates and PKCS #7. + +11.2.1 Syntax for RSAES-OAEP + + The object identifier id-RSAES-OAEP identifies the RSAES-OAEP + encryption scheme. + + id-RSAES-OAEP OBJECT IDENTIFIER ::= {pkcs-1 7} + + The parameters field associated with this OID in an + AlgorithmIdentifier shall have type RSAEP-OAEP-params: + + RSAES-OAEP-params ::= SEQUENCE { + hashFunc [0] AlgorithmIdentifier {{oaepDigestAlgorithms}} + DEFAULT sha1Identifier, + maskGenFunc [1] AlgorithmIdentifier {{pkcs1MGFAlgorithms}} + DEFAULT mgf1SHA1Identifier, + pSourceFunc [2] AlgorithmIdentifier + {{pkcs1pSourceAlgorithms}} + DEFAULT pSpecifiedEmptyIdentifier } + + The fields of type RSAES-OAEP-params have the following meanings: + + -hashFunc identifies the hash function. It shall be an algorithm ID + with an OID in the set oaepDigestAlgorithms, which for this version + shall consist of id-sha1, identifying the SHA-1 hash function. The + parameters field for id-sha1 shall have type NULL. + + oaepDigestAlgorithms ALGORITHM-IDENTIFIER ::= { + {NULL IDENTIFIED BY id-sha1} } + + id-sha1 OBJECT IDENTIFIER ::= + {iso(1) identified-organization(3) oiw(14) secsig(3) + algorithms(2) 26} + + + The default hash function is SHA-1: + sha1Identifier ::= AlgorithmIdentifier {id-sha1, NULL} + + -maskGenFunc identifies the mask generation function. It shall be an + algorithm ID with an OID in the set pkcs1MGFAlgorithms, which for + this version shall consist of id-mgf1, identifying the MGF1 mask + generation function (see Section 10.2.1). The parameters field for + + + +Kaliski & Staddon Informational [Page 31] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + id-mgf1 shall have type AlgorithmIdentifier, identifying the hash + function on which MGF1 is based, where the OID for the hash function + shall be in the set oaepDigestAlgorithms. + + pkcs1MGFAlgorithms ALGORITHM-IDENTIFIER ::= { + {AlgorithmIdentifier {{oaepDigestAlgorithms}} IDENTIFIED + BY id-mgf1} } + + id-mgf1 OBJECT IDENTIFIER ::= {pkcs-1 8} + + The default mask generation function is MGF1 with SHA-1: + + mgf1SHA1Identifier ::= AlgorithmIdentifier { + id-mgf1, sha1Identifier } + + -pSourceFunc identifies the source (and possibly the value) of the + encoding parameters P. It shall be an algorithm ID with an OID in the + set pkcs1pSourceAlgorithms, which for this version shall consist of + id-pSpecified, indicating that the encoding parameters are specified + explicitly. The parameters field for id-pSpecified shall have type + OCTET STRING, containing the encoding parameters. + + pkcs1pSourceAlgorithms ALGORITHM-IDENTIFIER ::= { + {OCTET STRING IDENTIFIED BY id-pSpecified} } + + id-pSpecified OBJECT IDENTIFIER ::= {pkcs-1 9} + + The default encoding parameters is an empty string (so that pHash in + EME-OAEP will contain the hash of the empty string): + + pSpecifiedEmptyIdentifier ::= AlgorithmIdentifier { + id-pSpecified, OCTET STRING SIZE (0) } + + If all of the default values of the fields in RSAES-OAEP-params are + used, then the algorithm identifier will have the following value: + + RSAES-OAEP-Default-Identifier ::= AlgorithmIdentifier { + id-RSAES-OAEP, + {sha1Identifier, + mgf1SHA1Identifier, + pSpecifiedEmptyIdentifier } } + +11.2.2 Syntax for RSAES-PKCS1-v1_5 + + The object identifier rsaEncryption (Section 11.1) identifies the + RSAES-PKCS1-v1_5 encryption scheme. The parameters field associated + with this OID in an AlgorithmIdentifier shall have type NULL. This is + the same as in PKCS #1 v1.5. + + + +Kaliski & Staddon Informational [Page 32] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + RsaEncryption OBJECT IDENTIFIER ::= {PKCS-1 1} + +11.2.3 Syntax for RSASSA-PKCS1-v1_5 + + The object identifier for RSASSA-PKCS1-v1_5 shall be one of the + following. The choice of OID depends on the choice of hash algorithm: + MD2, MD5 or SHA-1. Note that if either MD2 or MD5 is used then the + OID is just as in PKCS #1 v1.5. For each OID, the parameters field + associated with this OID in an AlgorithmIdentifier shall have type + NULL. + + If the hash function to be used is MD2, then the OID should be: + + md2WithRSAEncryption ::= {PKCS-1 2} + + If the hash function to be used is MD5, then the OID should be: + + md5WithRSAEncryption ::= {PKCS-1 4} + + If the hash function to be used is SHA-1, then the OID should be: + + sha1WithRSAEncryption ::= {pkcs-1 5} + + In the digestInfo type mentioned in Section 9.2.1 the OIDS for the + digest algorithm are the following: + + id-SHA1 OBJECT IDENTIFIER ::= + {iso(1) identified-organization(3) oiw(14) secsig(3) + algorithms(2) 26 } + + md2 OBJECT IDENTIFIER ::= + {iso(1) member-body(2) US(840) rsadsi(113549) + digestAlgorithm(2) 2} + + md5 OBJECT IDENTIFIER ::= + {iso(1) member-body(2) US(840) rsadsi(113549) + digestAlgorithm(2) 5} + + The parameters field of the digest algorithm has ASN.1 type NULL for + these OIDs. + +12. Patent statement + + The Internet Standards Process as defined in RFC 1310 requires a + written statement from the Patent holder that a license will be made + available to applicants under reasonable terms and conditions prior + to approving a specification as a Proposed, Draft or Internet + Standard. + + + +Kaliski & Staddon Informational [Page 33] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + The Internet Society, Internet Architecture Board, Internet + Engineering Steering Group and the Corporation for National Research + Initiatives take no position on the validity or scope of the + following patents and patent applications, nor on the appropriateness + of the terms of the assurance. The Internet Society and other groups + mentioned above have not made any determination as to any other + intellectual property rights which may apply to the practice of this + standard. Any further consideration of these matters is the user's + responsibility. + +12.1 Patent statement for the RSA algorithm + + The Massachusetts Institute of Technology has granted RSA Data + Security, Inc., exclusive sub-licensing rights to the following + patent issued in the United States: + + Cryptographic Communications System and Method ("RSA"), No. 4,405,829 + + RSA Data Security, Inc. has provided the following statement with + regard to this patent: + + It is RSA's business practice to make licenses to its patents + available on reasonable and nondiscriminatory terms. Accordingly, RSA + is willing, upon request, to grant non-exclusive licenses to such + patent on reasonable and non-discriminatory terms and conditions to + those who respect RSA's intellectual property rights and subject to + RSA's then current royalty rate for the patent licensed. The royalty + rate for the RSA patent is presently set at 2% of the licensee's + selling price for each product covered by the patent. Any requests + for license information may be directed to: + + Director of Licensing + RSA Data Security, Inc. + 2955 Campus Drive + Suite 400 + San Mateo, CA 94403 + + A license under RSA's patent(s) does not include any rights to know- + how or other technical information or license under other + intellectual property rights. Such license does not extend to any + activities which constitute infringement or inducement thereto. A + licensee must make his own determination as to whether a license is + necessary under patents of others. + + + + + + + + +Kaliski & Staddon Informational [Page 34] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +13. Revision history + + Versions 1.0-1.3 + + Versions 1.0-1.3 were distributed to participants in RSA Data + Security, Inc.'s Public-Key Cryptography Standards meetings in + February and March 1991. + + + Version 1.4 + + Version 1.4 was part of the June 3, 1991 initial public release of + PKCS. Version 1.4 was published as NIST/OSI Implementors' Workshop + document SEC-SIG-91-18. + + + Version 1.5 + + Version 1.5 incorporates several editorial changes, including updates + to the references and the addition of a revision history. The + following substantive changes were made: -Section 10: "MD4 with RSA" + signature and verification processes were added. + + -Section 11: md4WithRSAEncryption object identifier was added. + + Version 2.0 [DRAFT] + + Version 2.0 incorporates major editorial changes in terms of the + document structure, and introduces the RSAEP-OAEP encryption scheme. + This version continues to support the encryption and signature + processes in version 1.5, although the hash algorithm MD4 is no + longer allowed due to cryptanalytic advances in the intervening + years. + +14. References + + [1] ANSI, ANSI X9.44: Key Management Using Reversible Public Key + Cryptography for the Financial Services Industry. Work in + Progress. + + [2] M. Bellare and P. Rogaway. Optimal Asymmetric Encryption - How to + Encrypt with RSA. In Advances in Cryptology-Eurocrypt '94, pp. + 92-111, Springer-Verlag, 1994. + + [3] M. Bellare and P. Rogaway. The Exact Security of Digital + Signatures - How to Sign with RSA and Rabin. In Advances in + Cryptology-Eurocrypt '96, pp. 399-416, Springer-Verlag, 1996. + + + + +Kaliski & Staddon Informational [Page 35] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + [4] D. Bleichenbacher. Chosen Ciphertext Attacks against Protocols + Based on the RSA Encryption Standard PKCS #1. To appear in + Advances in Cryptology-Crypto '98. + + [5] D. Bleichenbacher, B. Kaliski and J. Staddon. Recent Results on + PKCS #1: RSA Encryption Standard. RSA Laboratories' Bulletin, + Number 7, June 24, 1998. + + [6] CCITT. Recommendation X.509: The Directory-Authentication + Framework. 1988. + + [7] D. Coppersmith, M. Franklin, J. Patarin and M. Reiter. Low- + Exponent RSA with Related Messages. In Advances in Cryptology- + Eurocrypt '96, pp. 1-9, Springer-Verlag, 1996 + + [8] B. Den Boer and Bosselaers. Collisions for the Compression + Function of MD5. In Advances in Cryptology-Eurocrypt '93, pp + 293-304, Springer-Verlag, 1994. + + [9] B. den Boer, and A. Bosselaers. An Attack on the Last Two Rounds + of MD4. In Advances in Cryptology-Crypto '91, pp.194-203, + Springer-Verlag, 1992. + + [10] H. Dobbertin. Cryptanalysis of MD4. Fast Software Encryption. + Lecture Notes in Computer Science, Springer-Verlag 1996, pp. + 55-72. + + [11] H. Dobbertin. Cryptanalysis of MD5 Compress. Presented at the + rump session of Eurocrypt `96, May 14, 1996 + + [12] H. Dobbertin.The First Two Rounds of MD4 are Not One-Way. Fast + Software Encryption. Lecture Notes in Computer Science, + Springer-Verlag 1998, pp. 284-292. + + [13] J. Hastad. Solving Simultaneous Modular Equations of Low Degree. + SIAM Journal of Computing, 17, 1988, pp. 336-341. + + [14] IEEE. IEEE P1363: Standard Specifications for Public Key + Cryptography. Draft Version 4. + + [15] Kaliski, B., "The MD2 Message-Digest Algorithm", RFC 1319, April + 1992. + + [16] National Institute of Standards and Technology (NIST). FIPS + Publication 180-1: Secure Hash Standard. April 1994. + + [17] Rivest, R., "The MD5 Message-Digest Algorithm", RFC 1321, April + 1992. + + + +Kaliski & Staddon Informational [Page 36] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + + [18] R. Rivest, A. Shamir and L. Adleman. A Method for Obtaining + Digital Signatures and Public-Key Cryptosystems. Communications + of the ACM, 21(2), pp. 120-126, February 1978. + + [19] N. Rogier and P. Chauvaud. The Compression Function of MD2 is + not Collision Free. Presented at Selected Areas of Cryptography + `95. Carleton University, Ottawa, Canada. May 18-19, 1995. + + [20] RSA Laboratories. PKCS #1: RSA Encryption Standard. Version 1.5, + November 1993. + + [21] RSA Laboratories. PKCS #7: Cryptographic Message Syntax + Standard. Version 1.5, November 1993. + + [22] RSA Laboratories. PKCS #8: Private-Key Information Syntax + Standard. Version 1.2, November 1993. + + [23] RSA Laboratories. PKCS #12: Personal Information Exchange Syntax + Standard. Version 1.0, Work in Progress, April 1997. + +Security Considerations + + Security issues are discussed throughout this memo. + +Acknowledgements + + This document is based on a contribution of RSA Laboratories, a + division of RSA Data Security, Inc. Any substantial use of the text + from this document must acknowledge RSA Data Security, Inc. RSA Data + Security, Inc. requests that all material mentioning or referencing + this document identify this as "RSA Data Security, Inc. PKCS #1 + v2.0". + + + + + + + + + + + + + + + + + + + +Kaliski & Staddon Informational [Page 37] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +Authors' Addresses + + Burt Kaliski + RSA Laboratories East + 20 Crosby Drive + Bedford, MA 01730 + + Phone: (617) 687-7000 + EMail: burt@rsa.com + + + Jessica Staddon + RSA Laboratories West + 2955 Campus Drive + Suite 400 + San Mateo, CA 94403 + + Phone: (650) 295-7600 + EMail: jstaddon@rsa.com + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kaliski & Staddon Informational [Page 38] + +RFC 2437 PKCS #1: RSA Cryptography Specifications October 1998 + + +Full Copyright Statement + + Copyright (C) The Internet Society (1998). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + + + + + + + + + + + + + + + + + + + + + + + + +Kaliski & Staddon Informational [Page 39] + diff --git a/doc/ikev2/[RFC3280] - x509 Certificates.txt b/doc/ikev2/[RFC3280] - x509 Certificates.txt new file mode 100644 index 000000000..433908bb7 --- /dev/null +++ b/doc/ikev2/[RFC3280] - x509 Certificates.txt @@ -0,0 +1,7227 @@ + + + + + + +Network Working Group R. Housley +Request for Comments: 3280 RSA Laboratories +Obsoletes: 2459 W. Polk +Category: Standards Track NIST + W. Ford + VeriSign + D. Solo + Citigroup + April 2002 + + Internet X.509 Public Key Infrastructure + Certificate and Certificate Revocation List (CRL) Profile + +Status of this Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (2002). All Rights Reserved. + +Abstract + + This memo profiles the X.509 v3 certificate and X.509 v2 Certificate + Revocation List (CRL) for use in the Internet. An overview of this + approach and model are provided as an introduction. The X.509 v3 + certificate format is described in detail, with additional + information regarding the format and semantics of Internet name + forms. Standard certificate extensions are described and two + Internet-specific extensions are defined. A set of required + certificate extensions is specified. The X.509 v2 CRL format is + described in detail, and required extensions are defined. An + algorithm for X.509 certification path validation is described. An + ASN.1 module and examples are provided in the appendices. + +Table of Contents + + 1 Introduction . . . . . . . . . . . . . . . . . . . . . . 4 + 2 Requirements and Assumptions . . . . . . . . . . . . . . 5 + 2.1 Communication and Topology . . . . . . . . . . . . . . 6 + 2.2 Acceptability Criteria . . . . . . . . . . . . . . . . 6 + 2.3 User Expectations . . . . . . . . . . . . . . . . . . . 7 + 2.4 Administrator Expectations . . . . . . . . . . . . . . 7 + 3 Overview of Approach . . . . . . . . . . . . . . . . . . 7 + + + +Housley, et. al. Standards Track [Page 1] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + 3.1 X.509 Version 3 Certificate . . . . . . . . . . . . . . 8 + 3.2 Certification Paths and Trust . . . . . . . . . . . . . 9 + 3.3 Revocation . . . . . . . . . . . . . . . . . . . . . . 11 + 3.4 Operational Protocols . . . . . . . . . . . . . . . . . 13 + 3.5 Management Protocols . . . . . . . . . . . . . . . . . 13 + 4 Certificate and Certificate Extensions Profile . . . . . 14 + 4.1 Basic Certificate Fields . . . . . . . . . . . . . . . 15 + 4.1.1 Certificate Fields . . . . . . . . . . . . . . . . . 16 + 4.1.1.1 tbsCertificate . . . . . . . . . . . . . . . . . . 16 + 4.1.1.2 signatureAlgorithm . . . . . . . . . . . . . . . . 16 + 4.1.1.3 signatureValue . . . . . . . . . . . . . . . . . . 16 + 4.1.2 TBSCertificate . . . . . . . . . . . . . . . . . . . 17 + 4.1.2.1 Version . . . . . . . . . . . . . . . . . . . . . . 17 + 4.1.2.2 Serial number . . . . . . . . . . . . . . . . . . . 17 + 4.1.2.3 Signature . . . . . . . . . . . . . . . . . . . . . 18 + 4.1.2.4 Issuer . . . . . . . . . . . . . . . . . . . . . . 18 + 4.1.2.5 Validity . . . . . . . . . . . . . . . . . . . . . 22 + 4.1.2.5.1 UTCTime . . . . . . . . . . . . . . . . . . . . . 22 + 4.1.2.5.2 GeneralizedTime . . . . . . . . . . . . . . . . . 22 + 4.1.2.6 Subject . . . . . . . . . . . . . . . . . . . . . . 23 + 4.1.2.7 Subject Public Key Info . . . . . . . . . . . . . . 24 + 4.1.2.8 Unique Identifiers . . . . . . . . . . . . . . . . 24 + 4.1.2.9 Extensions . . . . . . . . . . . . . . . . . . . . . 24 + 4.2 Certificate Extensions . . . . . . . . . . . . . . . . 24 + 4.2.1 Standard Extensions . . . . . . . . . . . . . . . . . 25 + 4.2.1.1 Authority Key Identifier . . . . . . . . . . . . . 26 + 4.2.1.2 Subject Key Identifier . . . . . . . . . . . . . . 27 + 4.2.1.3 Key Usage . . . . . . . . . . . . . . . . . . . . . 28 + 4.2.1.4 Private Key Usage Period . . . . . . . . . . . . . 29 + 4.2.1.5 Certificate Policies . . . . . . . . . . . . . . . 30 + 4.2.1.6 Policy Mappings . . . . . . . . . . . . . . . . . . 33 + 4.2.1.7 Subject Alternative Name . . . . . . . . . . . . . 33 + 4.2.1.8 Issuer Alternative Name . . . . . . . . . . . . . . 36 + 4.2.1.9 Subject Directory Attributes . . . . . . . . . . . 36 + 4.2.1.10 Basic Constraints . . . . . . . . . . . . . . . . 36 + 4.2.1.11 Name Constraints . . . . . . . . . . . . . . . . . 37 + 4.2.1.12 Policy Constraints . . . . . . . . . . . . . . . . 40 + 4.2.1.13 Extended Key Usage . . . . . . . . . . . . . . . . 40 + 4.2.1.14 CRL Distribution Points . . . . . . . . . . . . . 42 + 4.2.1.15 Inhibit Any-Policy . . . . . . . . . . . . . . . . 44 + 4.2.1.16 Freshest CRL . . . . . . . . . . . . . . . . . . . 44 + 4.2.2 Internet Certificate Extensions . . . . . . . . . . . 45 + 4.2.2.1 Authority Information Access . . . . . . . . . . . 45 + 4.2.2.2 Subject Information Access . . . . . . . . . . . . 46 + 5 CRL and CRL Extensions Profile . . . . . . . . . . . . . 48 + 5.1 CRL Fields . . . . . . . . . . . . . . . . . . . . . . 49 + 5.1.1 CertificateList Fields . . . . . . . . . . . . . . . 50 + 5.1.1.1 tbsCertList . . . . . . . . . . . . . . . . . . . . 50 + + + +Housley, et. al. Standards Track [Page 2] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + 5.1.1.2 signatureAlgorithm . . . . . . . . . . . . . . . . 50 + 5.1.1.3 signatureValue . . . . . . . . . . . . . . . . . . 51 + 5.1.2 Certificate List "To Be Signed" . . . . . . . . . . . 51 + 5.1.2.1 Version . . . . . . . . . . . . . . . . . . . . . . 52 + 5.1.2.2 Signature . . . . . . . . . . . . . . . . . . . . . 52 + 5.1.2.3 Issuer Name . . . . . . . . . . . . . . . . . . . . 52 + 5.1.2.4 This Update . . . . . . . . . . . . . . . . . . . . 52 + 5.1.2.5 Next Update . . . . . . . . . . . . . . . . . . . . 53 + 5.1.2.6 Revoked Certificates . . . . . . . . . . . . . . . 53 + 5.1.2.7 Extensions . . . . . . . . . . . . . . . . . . . . 53 + 5.2 CRL Extensions . . . . . . . . . . . . . . . . . . . . 53 + 5.2.1 Authority Key Identifier . . . . . . . . . . . . . . 54 + 5.2.2 Issuer Alternative Name . . . . . . . . . . . . . . . 54 + 5.2.3 CRL Number . . . . . . . . . . . . . . . . . . . . . 55 + 5.2.4 Delta CRL Indicator . . . . . . . . . . . . . . . . . 55 + 5.2.5 Issuing Distribution Point . . . . . . . . . . . . . 58 + 5.2.6 Freshest CRL . . . . . . . . . . . . . . . . . . . . 59 + 5.3 CRL Entry Extensions . . . . . . . . . . . . . . . . . 60 + 5.3.1 Reason Code . . . . . . . . . . . . . . . . . . . . . 60 + 5.3.2 Hold Instruction Code . . . . . . . . . . . . . . . . 61 + 5.3.3 Invalidity Date . . . . . . . . . . . . . . . . . . . 62 + 5.3.4 Certificate Issuer . . . . . . . . . . . . . . . . . 62 + 6 Certificate Path Validation . . . . . . . . . . . . . . . 62 + 6.1 Basic Path Validation . . . . . . . . . . . . . . . . . 63 + 6.1.1 Inputs . . . . . . . . . . . . . . . . . . . . . . . 66 + 6.1.2 Initialization . . . . . . . . . . . . . . . . . . . 67 + 6.1.3 Basic Certificate Processing . . . . . . . . . . . . 70 + 6.1.4 Preparation for Certificate i+1 . . . . . . . . . . . 75 + 6.1.5 Wrap-up procedure . . . . . . . . . . . . . . . . . . 78 + 6.1.6 Outputs . . . . . . . . . . . . . . . . . . . . . . . 80 + 6.2 Extending Path Validation . . . . . . . . . . . . . . . 80 + 6.3 CRL Validation . . . . . . . . . . . . . . . . . . . . 81 + 6.3.1 Revocation Inputs . . . . . . . . . . . . . . . . . . 82 + 6.3.2 Initialization and Revocation State Variables . . . . 82 + 6.3.3 CRL Processing . . . . . . . . . . . . . . . . . . . 83 + 7 References . . . . . . . . . . . . . . . . . . . . . . . 86 + 8 Intellectual Property Rights . . . . . . . . . . . . . . 88 + 9 Security Considerations . . . . . . . . . . . . . . . . . 89 + Appendix A. ASN.1 Structures and OIDs . . . . . . . . . . . 92 + A.1 Explicitly Tagged Module, 1988 Syntax . . . . . . . . . 92 + A.2 Implicitly Tagged Module, 1988 Syntax . . . . . . . . . 105 + Appendix B. ASN.1 Notes . . . . . . . . . . . . . . . . . . 112 + Appendix C. Examples . . . . . . . . . . . . . . . . . . . 115 + C.1 DSA Self-Signed Certificate . . . . . . . . . . . . . . 115 + C.2 End Entity Certificate Using DSA . . . . . . . . . . . 119 + C.3 End Entity Certificate Using RSA . . . . . . . . . . . 122 + C.4 Certificate Revocation List . . . . . . . . . . . . . . 126 + Author Addresses . . . . . . . . . . . . . . . . . . . . . . 128 + + + +Housley, et. al. Standards Track [Page 3] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Full Copyright Statement . . . . . . . . . . . . . . . . . . 129 + +1 Introduction + + This specification is one part of a family of standards for the X.509 + Public Key Infrastructure (PKI) for the Internet. + + This specification profiles the format and semantics of certificates + and certificate revocation lists (CRLs) for the Internet PKI. + Procedures are described for processing of certification paths in the + Internet environment. Finally, ASN.1 modules are provided in the + appendices for all data structures defined or referenced. + + Section 2 describes Internet PKI requirements, and the assumptions + which affect the scope of this document. Section 3 presents an + architectural model and describes its relationship to previous IETF + and ISO/IEC/ITU-T standards. In particular, this document's + relationship with the IETF PEM specifications and the ISO/IEC/ITU-T + X.509 documents are described. + + Section 4 profiles the X.509 version 3 certificate, and section 5 + profiles the X.509 version 2 CRL. The profiles include the + identification of ISO/IEC/ITU-T and ANSI extensions which may be + useful in the Internet PKI. The profiles are presented in the 1988 + Abstract Syntax Notation One (ASN.1) rather than the 1997 ASN.1 + syntax used in the most recent ISO/IEC/ITU-T standards. + + Section 6 includes certification path validation procedures. These + procedures are based upon the ISO/IEC/ITU-T definition. + Implementations are REQUIRED to derive the same results but are not + required to use the specified procedures. + + Procedures for identification and encoding of public key materials + and digital signatures are defined in [PKIXALGS]. Implementations of + this specification are not required to use any particular + cryptographic algorithms. However, conforming implementations which + use the algorithms identified in [PKIXALGS] MUST identify and encode + the public key materials and digital signatures as described in that + specification. + + Finally, three appendices are provided to aid implementers. Appendix + A contains all ASN.1 structures defined or referenced within this + specification. As above, the material is presented in the 1988 + ASN.1. Appendix B contains notes on less familiar features of the + ASN.1 notation used within this specification. Appendix C contains + examples of a conforming certificate and a conforming CRL. + + + + + +Housley, et. al. Standards Track [Page 4] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + This specification obsoletes RFC 2459. This specification differs + from RFC 2459 in five basic areas: + + * To promote interoperable implementations, a detailed algorithm + for certification path validation is included in section 6.1 of + this specification; RFC 2459 provided only a high-level + description of path validation. + + * An algorithm for determining the status of a certificate using + CRLs is provided in section 6.3 of this specification. This + material was not present in RFC 2459. + + * To accommodate new usage models, detailed information describing + the use of delta CRLs is provided in Section 5 of this + specification. + + * Identification and encoding of public key materials and digital + signatures are not included in this specification, but are now + described in a companion specification [PKIXALGS]. + + * Four additional extensions are specified: three certificate + extensions and one CRL extension. The certificate extensions are + subject info access, inhibit any-policy, and freshest CRL. The + freshest CRL extension is also defined as a CRL extension. + + * Throughout the specification, clarifications have been + introduced to enhance consistency with the ITU-T X.509 + specification. X.509 defines the certificate and CRL format as + well as many of the extensions that appear in this specification. + These changes were introduced to improve the likelihood of + interoperability between implementations based on this + specification with implementations based on the ITU-T + specification. + + The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", + "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this + document are to be interpreted as described in RFC 2119. + +2 Requirements and Assumptions + + The goal of this specification is to develop a profile to facilitate + the use of X.509 certificates within Internet applications for those + communities wishing to make use of X.509 technology. Such + applications may include WWW, electronic mail, user authentication, + and IPsec. In order to relieve some of the obstacles to using X.509 + + + + + + +Housley, et. al. Standards Track [Page 5] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + certificates, this document defines a profile to promote the + development of certificate management systems; development of + application tools; and interoperability determined by policy. + + Some communities will need to supplement, or possibly replace, this + profile in order to meet the requirements of specialized application + domains or environments with additional authorization, assurance, or + operational requirements. However, for basic applications, common + representations of frequently used attributes are defined so that + application developers can obtain necessary information without + regard to the issuer of a particular certificate or certificate + revocation list (CRL). + + A certificate user should review the certificate policy generated by + the certification authority (CA) before relying on the authentication + or non-repudiation services associated with the public key in a + particular certificate. To this end, this standard does not + prescribe legally binding rules or duties. + + As supplemental authorization and attribute management tools emerge, + such as attribute certificates, it may be appropriate to limit the + authenticated attributes that are included in a certificate. These + other management tools may provide more appropriate methods of + conveying many authenticated attributes. + +2.1 Communication and Topology + + The users of certificates will operate in a wide range of + environments with respect to their communication topology, especially + users of secure electronic mail. This profile supports users without + high bandwidth, real-time IP connectivity, or high connection + availability. In addition, the profile allows for the presence of + firewall or other filtered communication. + + This profile does not assume the deployment of an X.500 Directory + system or a LDAP directory system. The profile does not prohibit the + use of an X.500 Directory or a LDAP directory; however, any means of + distributing certificates and certificate revocation lists (CRLs) may + be used. + +2.2 Acceptability Criteria + + The goal of the Internet Public Key Infrastructure (PKI) is to meet + the needs of deterministic, automated identification, authentication, + access control, and authorization functions. Support for these + services determines the attributes contained in the certificate as + well as the ancillary control information in the certificate such as + policy data and certification path constraints. + + + +Housley, et. al. Standards Track [Page 6] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +2.3 User Expectations + + Users of the Internet PKI are people and processes who use client + software and are the subjects named in certificates. These uses + include readers and writers of electronic mail, the clients for WWW + browsers, WWW servers, and the key manager for IPsec within a router. + This profile recognizes the limitations of the platforms these users + employ and the limitations in sophistication and attentiveness of the + users themselves. This manifests itself in minimal user + configuration responsibility (e.g., trusted CA keys, rules), explicit + platform usage constraints within the certificate, certification path + constraints which shield the user from many malicious actions, and + applications which sensibly automate validation functions. + +2.4 Administrator Expectations + + As with user expectations, the Internet PKI profile is structured to + support the individuals who generally operate CAs. Providing + administrators with unbounded choices increases the chances that a + subtle CA administrator mistake will result in broad compromise. + Also, unbounded choices greatly complicate the software that process + and validate the certificates created by the CA. + +3 Overview of Approach + + Following is a simplified view of the architectural model assumed by + the PKIX specifications. + + The components in this model are: + + end entity: user of PKI certificates and/or end user system that is + the subject of a certificate; + CA: certification authority; + RA: registration authority, i.e., an optional system to which + a CA delegates certain management functions; + CRL issuer: an optional system to which a CA delegates the + publication of certificate revocation lists; + repository: a system or collection of distributed systems that stores + certificates and CRLs and serves as a means of + distributing these certificates and CRLs to end entities. + + Note that an Attribute Authority (AA) might also choose to delegate + the publication of CRLs to a CRL issuer. + + + + + + + + +Housley, et. al. Standards Track [Page 7] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + +---+ + | C | +------------+ + | e | <-------------------->| End entity | + | r | Operational +------------+ + | t | transactions ^ + | i | and management | Management + | f | transactions | transactions PKI + | i | | users + | c | v + | a | ======================= +--+------------+ ============== + | t | ^ ^ + | e | | | PKI + | | v | management + | & | +------+ | entities + | | <---------------------| RA |<----+ | + | C | Publish certificate +------+ | | + | R | | | + | L | | | + | | v v + | R | +------------+ + | e | <------------------------------| CA | + | p | Publish certificate +------------+ + | o | Publish CRL ^ ^ + | s | | | Management + | i | +------------+ | | transactions + | t | <--------------| CRL Issuer |<----+ | + | o | Publish CRL +------------+ v + | r | +------+ + | y | | CA | + +---+ +------+ + + Figure 1 - PKI Entities + +3.1 X.509 Version 3 Certificate + + Users of a public key require confidence that the associated private + key is owned by the correct remote subject (person or system) with + which an encryption or digital signature mechanism will be used. + This confidence is obtained through the use of public key + certificates, which are data structures that bind public key values + to subjects. The binding is asserted by having a trusted CA + digitally sign each certificate. The CA may base this assertion upon + technical means (a.k.a., proof of possession through a challenge- + response protocol), presentation of the private key, or on an + assertion by the subject. A certificate has a limited valid lifetime + which is indicated in its signed contents. Because a certificate's + signature and timeliness can be independently checked by a + certificate-using client, certificates can be distributed via + + + +Housley, et. al. Standards Track [Page 8] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + untrusted communications and server systems, and can be cached in + unsecured storage in certificate-using systems. + + ITU-T X.509 (formerly CCITT X.509) or ISO/IEC 9594-8, which was first + published in 1988 as part of the X.500 Directory recommendations, + defines a standard certificate format [X.509]. The certificate + format in the 1988 standard is called the version 1 (v1) format. + When X.500 was revised in 1993, two more fields were added, resulting + in the version 2 (v2) format. + + The Internet Privacy Enhanced Mail (PEM) RFCs, published in 1993, + include specifications for a public key infrastructure based on X.509 + v1 certificates [RFC 1422]. The experience gained in attempts to + deploy RFC 1422 made it clear that the v1 and v2 certificate formats + are deficient in several respects. Most importantly, more fields + were needed to carry information which PEM design and implementation + experience had proven necessary. In response to these new + requirements, ISO/IEC, ITU-T and ANSI X9 developed the X.509 version + 3 (v3) certificate format. The v3 format extends the v2 format by + adding provision for additional extension fields. Particular + extension field types may be specified in standards or may be defined + and registered by any organization or community. In June 1996, + standardization of the basic v3 format was completed [X.509]. + + ISO/IEC, ITU-T, and ANSI X9 have also developed standard extensions + for use in the v3 extensions field [X.509][X9.55]. These extensions + can convey such data as additional subject identification + information, key attribute information, policy information, and + certification path constraints. + + However, the ISO/IEC, ITU-T, and ANSI X9 standard extensions are very + broad in their applicability. In order to develop interoperable + implementations of X.509 v3 systems for Internet use, it is necessary + to specify a profile for use of the X.509 v3 extensions tailored for + the Internet. It is one goal of this document to specify a profile + for Internet WWW, electronic mail, and IPsec applications. + Environments with additional requirements may build on this profile + or may replace it. + +3.2 Certification Paths and Trust + + A user of a security service requiring knowledge of a public key + generally needs to obtain and validate a certificate containing the + required public key. If the public key user does not already hold an + assured copy of the public key of the CA that signed the certificate, + the CA's name, and related information (such as the validity period + or name constraints), then it might need an additional certificate to + obtain that public key. In general, a chain of multiple certificates + + + +Housley, et. al. Standards Track [Page 9] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + may be needed, comprising a certificate of the public key owner (the + end entity) signed by one CA, and zero or more additional + certificates of CAs signed by other CAs. Such chains, called + certification paths, are required because a public key user is only + initialized with a limited number of assured CA public keys. + + There are different ways in which CAs might be configured in order + for public key users to be able to find certification paths. For + PEM, RFC 1422 defined a rigid hierarchical structure of CAs. There + are three types of PEM certification authority: + + (a) Internet Policy Registration Authority (IPRA): This + authority, operated under the auspices of the Internet Society, + acts as the root of the PEM certification hierarchy at level 1. + It issues certificates only for the next level of authorities, + PCAs. All certification paths start with the IPRA. + + (b) Policy Certification Authorities (PCAs): PCAs are at level 2 + of the hierarchy, each PCA being certified by the IPRA. A PCA + shall establish and publish a statement of its policy with respect + to certifying users or subordinate certification authorities. + Distinct PCAs aim to satisfy different user needs. For example, + one PCA (an organizational PCA) might support the general + electronic mail needs of commercial organizations, and another PCA + (a high-assurance PCA) might have a more stringent policy designed + for satisfying legally binding digital signature requirements. + + (c) Certification Authorities (CAs): CAs are at level 3 of the + hierarchy and can also be at lower levels. Those at level 3 are + certified by PCAs. CAs represent, for example, particular + organizations, particular organizational units (e.g., departments, + groups, sections), or particular geographical areas. + + RFC 1422 furthermore has a name subordination rule which requires + that a CA can only issue certificates for entities whose names are + subordinate (in the X.500 naming tree) to the name of the CA itself. + The trust associated with a PEM certification path is implied by the + PCA name. The name subordination rule ensures that CAs below the PCA + are sensibly constrained as to the set of subordinate entities they + can certify (e.g., a CA for an organization can only certify entities + in that organization's name tree). Certificate user systems are able + to mechanically check that the name subordination rule has been + followed. + + The RFC 1422 uses the X.509 v1 certificate formats. The limitations + of X.509 v1 required imposition of several structural restrictions to + clearly associate policy information or restrict the utility of + certificates. These restrictions included: + + + +Housley, et. al. Standards Track [Page 10] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (a) a pure top-down hierarchy, with all certification paths + starting from IPRA; + + (b) a naming subordination rule restricting the names of a CA's + subjects; and + + (c) use of the PCA concept, which requires knowledge of + individual PCAs to be built into certificate chain verification + logic. Knowledge of individual PCAs was required to determine if + a chain could be accepted. + + With X.509 v3, most of the requirements addressed by RFC 1422 can be + addressed using certificate extensions, without a need to restrict + the CA structures used. In particular, the certificate extensions + relating to certificate policies obviate the need for PCAs and the + constraint extensions obviate the need for the name subordination + rule. As a result, this document supports a more flexible + architecture, including: + + (a) Certification paths start with a public key of a CA in a + user's own domain, or with the public key of the top of a + hierarchy. Starting with the public key of a CA in a user's own + domain has certain advantages. In some environments, the local + domain is the most trusted. + + (b) Name constraints may be imposed through explicit inclusion of + a name constraints extension in a certificate, but are not + required. + + (c) Policy extensions and policy mappings replace the PCA + concept, which permits a greater degree of automation. The + application can determine if the certification path is acceptable + based on the contents of the certificates instead of a priori + knowledge of PCAs. This permits automation of certification path + processing. + +3.3 Revocation + + When a certificate is issued, it is expected to be in use for its + entire validity period. However, various circumstances may cause a + certificate to become invalid prior to the expiration of the validity + period. Such circumstances include change of name, change of + association between subject and CA (e.g., an employee terminates + employment with an organization), and compromise or suspected + compromise of the corresponding private key. Under such + circumstances, the CA needs to revoke the certificate. + + + + + +Housley, et. al. Standards Track [Page 11] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + X.509 defines one method of certificate revocation. This method + involves each CA periodically issuing a signed data structure called + a certificate revocation list (CRL). A CRL is a time stamped list + identifying revoked certificates which is signed by a CA or CRL + issuer and made freely available in a public repository. Each + revoked certificate is identified in a CRL by its certificate serial + number. When a certificate-using system uses a certificate (e.g., + for verifying a remote user's digital signature), that system not + only checks the certificate signature and validity but also acquires + a suitably-recent CRL and checks that the certificate serial number + is not on that CRL. The meaning of "suitably-recent" may vary with + local policy, but it usually means the most recently-issued CRL. A + new CRL is issued on a regular periodic basis (e.g., hourly, daily, + or weekly). An entry is added to the CRL as part of the next update + following notification of revocation. An entry MUST NOT be removed + from the CRL until it appears on one regularly scheduled CRL issued + beyond the revoked certificate's validity period. + + An advantage of this revocation method is that CRLs may be + distributed by exactly the same means as certificates themselves, + namely, via untrusted servers and untrusted communications. + + One limitation of the CRL revocation method, using untrusted + communications and servers, is that the time granularity of + revocation is limited to the CRL issue period. For example, if a + revocation is reported now, that revocation will not be reliably + notified to certificate-using systems until all currently issued CRLs + are updated -- this may be up to one hour, one day, or one week + depending on the frequency that CRLs are issued. + + As with the X.509 v3 certificate format, in order to facilitate + interoperable implementations from multiple vendors, the X.509 v2 CRL + format needs to be profiled for Internet use. It is one goal of this + document to specify that profile. However, this profile does not + require the issuance of CRLs. Message formats and protocols + supporting on-line revocation notification are defined in other PKIX + specifications. On-line methods of revocation notification may be + applicable in some environments as an alternative to the X.509 CRL. + On-line revocation checking may significantly reduce the latency + between a revocation report and the distribution of the information + to relying parties. Once the CA accepts a revocation report as + authentic and valid, any query to the on-line service will correctly + reflect the certificate validation impacts of the revocation. + However, these methods impose new security requirements: the + certificate validator needs to trust the on-line validation service + while the repository does not need to be trusted. + + + + + +Housley, et. al. Standards Track [Page 12] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +3.4 Operational Protocols + + Operational protocols are required to deliver certificates and CRLs + (or status information) to certificate using client systems. + Provisions are needed for a variety of different means of certificate + and CRL delivery, including distribution procedures based on LDAP, + HTTP, FTP, and X.500. Operational protocols supporting these + functions are defined in other PKIX specifications. These + specifications may include definitions of message formats and + procedures for supporting all of the above operational environments, + including definitions of or references to appropriate MIME content + types. + +3.5 Management Protocols + + Management protocols are required to support on-line interactions + between PKI user and management entities. For example, a management + protocol might be used between a CA and a client system with which a + key pair is associated, or between two CAs which cross-certify each + other. The set of functions which potentially need to be supported + by management protocols include: + + (a) registration: This is the process whereby a user first makes + itself known to a CA (directly, or through an RA), prior to that + CA issuing a certificate or certificates for that user. + + (b) initialization: Before a client system can operate securely + it is necessary to install key materials which have the + appropriate relationship with keys stored elsewhere in the + infrastructure. For example, the client needs to be securely + initialized with the public key and other assured information of + the trusted CA(s), to be used in validating certificate paths. + + Furthermore, a client typically needs to be initialized with its + own key pair(s). + + (c) certification: This is the process in which a CA issues a + certificate for a user's public key, and returns that certificate + to the user's client system and/or posts that certificate in a + repository. + + (d) key pair recovery: As an option, user client key materials + (e.g., a user's private key used for encryption purposes) may be + backed up by a CA or a key backup system. If a user needs to + recover these backed up key materials (e.g., as a result of a + forgotten password or a lost key chain file), an on-line protocol + exchange may be needed to support such recovery. + + + + +Housley, et. al. Standards Track [Page 13] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (e) key pair update: All key pairs need to be updated regularly, + i.e., replaced with a new key pair, and new certificates issued. + + (f) revocation request: An authorized person advises a CA of an + abnormal situation requiring certificate revocation. + + (g) cross-certification: Two CAs exchange information used in + establishing a cross-certificate. A cross-certificate is a + certificate issued by one CA to another CA which contains a CA + signature key used for issuing certificates. + + Note that on-line protocols are not the only way of implementing the + above functions. For all functions there are off-line methods of + achieving the same result, and this specification does not mandate + use of on-line protocols. For example, when hardware tokens are + used, many of the functions may be achieved as part of the physical + token delivery. Furthermore, some of the above functions may be + combined into one protocol exchange. In particular, two or more of + the registration, initialization, and certification functions can be + combined into one protocol exchange. + + The PKIX series of specifications defines a set of standard message + formats supporting the above functions. The protocols for conveying + these messages in different environments (e.g., e-mail, file + transfer, and WWW) are described in those specifications. + +4 Certificate and Certificate Extensions Profile + + This section presents a profile for public key certificates that will + foster interoperability and a reusable PKI. This section is based + upon the X.509 v3 certificate format and the standard certificate + extensions defined in [X.509]. The ISO/IEC and ITU-T documents use + the 1997 version of ASN.1; while this document uses the 1988 ASN.1 + syntax, the encoded certificate and standard extensions are + equivalent. This section also defines private extensions required to + support a PKI for the Internet community. + + Certificates may be used in a wide range of applications and + environments covering a broad spectrum of interoperability goals and + a broader spectrum of operational and assurance requirements. The + goal of this document is to establish a common baseline for generic + applications requiring broad interoperability and limited special + purpose requirements. In particular, the emphasis will be on + supporting the use of X.509 v3 certificates for informal Internet + electronic mail, IPsec, and WWW applications. + + + + + + +Housley, et. al. Standards Track [Page 14] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.1 Basic Certificate Fields + + The X.509 v3 certificate basic syntax is as follows. For signature + calculation, the data that is to be signed is encoded using the ASN.1 + distinguished encoding rules (DER) [X.690]. ASN.1 DER encoding is a + tag, length, value encoding system for each element. + + Certificate ::= SEQUENCE { + tbsCertificate TBSCertificate, + signatureAlgorithm AlgorithmIdentifier, + signatureValue BIT STRING } + + TBSCertificate ::= SEQUENCE { + version [0] EXPLICIT Version DEFAULT v1, + serialNumber CertificateSerialNumber, + signature AlgorithmIdentifier, + issuer Name, + validity Validity, + subject Name, + subjectPublicKeyInfo SubjectPublicKeyInfo, + issuerUniqueID [1] IMPLICIT UniqueIdentifier OPTIONAL, + -- If present, version MUST be v2 or v3 + subjectUniqueID [2] IMPLICIT UniqueIdentifier OPTIONAL, + -- If present, version MUST be v2 or v3 + extensions [3] EXPLICIT Extensions OPTIONAL + -- If present, version MUST be v3 + } + + Version ::= INTEGER { v1(0), v2(1), v3(2) } + + CertificateSerialNumber ::= INTEGER + + Validity ::= SEQUENCE { + notBefore Time, + notAfter Time } + + Time ::= CHOICE { + utcTime UTCTime, + generalTime GeneralizedTime } + + UniqueIdentifier ::= BIT STRING + + SubjectPublicKeyInfo ::= SEQUENCE { + algorithm AlgorithmIdentifier, + subjectPublicKey BIT STRING } + + Extensions ::= SEQUENCE SIZE (1..MAX) OF Extension + + + + +Housley, et. al. Standards Track [Page 15] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Extension ::= SEQUENCE { + extnID OBJECT IDENTIFIER, + critical BOOLEAN DEFAULT FALSE, + extnValue OCTET STRING } + + The following items describe the X.509 v3 certificate for use in the + Internet. + +4.1.1 Certificate Fields + + The Certificate is a SEQUENCE of three required fields. The fields + are described in detail in the following subsections. + +4.1.1.1 tbsCertificate + + The field contains the names of the subject and issuer, a public key + associated with the subject, a validity period, and other associated + information. The fields are described in detail in section 4.1.2; + the tbsCertificate usually includes extensions which are described in + section 4.2. + +4.1.1.2 signatureAlgorithm + + The signatureAlgorithm field contains the identifier for the + cryptographic algorithm used by the CA to sign this certificate. + [PKIXALGS] lists supported signature algorithms, but other signature + algorithms MAY also be supported. + + An algorithm identifier is defined by the following ASN.1 structure: + + AlgorithmIdentifier ::= SEQUENCE { + algorithm OBJECT IDENTIFIER, + parameters ANY DEFINED BY algorithm OPTIONAL } + + The algorithm identifier is used to identify a cryptographic + algorithm. The OBJECT IDENTIFIER component identifies the algorithm + (such as DSA with SHA-1). The contents of the optional parameters + field will vary according to the algorithm identified. + + This field MUST contain the same algorithm identifier as the + signature field in the sequence tbsCertificate (section 4.1.2.3). + +4.1.1.3 signatureValue + + The signatureValue field contains a digital signature computed upon + the ASN.1 DER encoded tbsCertificate. The ASN.1 DER encoded + tbsCertificate is used as the input to the signature function. This + + + + +Housley, et. al. Standards Track [Page 16] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + signature value is encoded as a BIT STRING and included in the + signature field. The details of this process are specified for each + of algorithms listed in [PKIXALGS]. + + By generating this signature, a CA certifies the validity of the + information in the tbsCertificate field. In particular, the CA + certifies the binding between the public key material and the subject + of the certificate. + +4.1.2 TBSCertificate + + The sequence TBSCertificate contains information associated with the + subject of the certificate and the CA who issued it. Every + TBSCertificate contains the names of the subject and issuer, a public + key associated with the subject, a validity period, a version number, + and a serial number; some MAY contain optional unique identifier + fields. The remainder of this section describes the syntax and + semantics of these fields. A TBSCertificate usually includes + extensions. Extensions for the Internet PKI are described in Section + 4.2. + +4.1.2.1 Version + + This field describes the version of the encoded certificate. When + extensions are used, as expected in this profile, version MUST be 3 + (value is 2). If no extensions are present, but a UniqueIdentifier + is present, the version SHOULD be 2 (value is 1); however version MAY + be 3. If only basic fields are present, the version SHOULD be 1 (the + value is omitted from the certificate as the default value); however + the version MAY be 2 or 3. + + Implementations SHOULD be prepared to accept any version certificate. + At a minimum, conforming implementations MUST recognize version 3 + certificates. + + Generation of version 2 certificates is not expected by + implementations based on this profile. + +4.1.2.2 Serial number + + The serial number MUST be a positive integer assigned by the CA to + each certificate. It MUST be unique for each certificate issued by a + given CA (i.e., the issuer name and serial number identify a unique + certificate). CAs MUST force the serialNumber to be a non-negative + integer. + + + + + + +Housley, et. al. Standards Track [Page 17] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Given the uniqueness requirements above, serial numbers can be + expected to contain long integers. Certificate users MUST be able to + handle serialNumber values up to 20 octets. Conformant CAs MUST NOT + use serialNumber values longer than 20 octets. + + Note: Non-conforming CAs may issue certificates with serial numbers + that are negative, or zero. Certificate users SHOULD be prepared to + gracefully handle such certificates. + +4.1.2.3 Signature + + This field contains the algorithm identifier for the algorithm used + by the CA to sign the certificate. + + This field MUST contain the same algorithm identifier as the + signatureAlgorithm field in the sequence Certificate (section + 4.1.1.2). The contents of the optional parameters field will vary + according to the algorithm identified. [PKIXALGS] lists the + supported signature algorithms, but other signature algorithms MAY + also be supported. + +4.1.2.4 Issuer + + The issuer field identifies the entity who has signed and issued the + certificate. The issuer field MUST contain a non-empty distinguished + name (DN). The issuer field is defined as the X.501 type Name + [X.501]. Name is defined by the following ASN.1 structures: + + Name ::= CHOICE { + RDNSequence } + + RDNSequence ::= SEQUENCE OF RelativeDistinguishedName + + RelativeDistinguishedName ::= + SET OF AttributeTypeAndValue + + AttributeTypeAndValue ::= SEQUENCE { + type AttributeType, + value AttributeValue } + + AttributeType ::= OBJECT IDENTIFIER + + AttributeValue ::= ANY DEFINED BY AttributeType + + + + + + + + +Housley, et. al. Standards Track [Page 18] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + DirectoryString ::= CHOICE { + teletexString TeletexString (SIZE (1..MAX)), + printableString PrintableString (SIZE (1..MAX)), + universalString UniversalString (SIZE (1..MAX)), + utf8String UTF8String (SIZE (1..MAX)), + bmpString BMPString (SIZE (1..MAX)) } + + The Name describes a hierarchical name composed of attributes, such + as country name, and corresponding values, such as US. The type of + the component AttributeValue is determined by the AttributeType; in + general it will be a DirectoryString. + + The DirectoryString type is defined as a choice of PrintableString, + TeletexString, BMPString, UTF8String, and UniversalString. The + UTF8String encoding [RFC 2279] is the preferred encoding, and all + certificates issued after December 31, 2003 MUST use the UTF8String + encoding of DirectoryString (except as noted below). Until that + date, conforming CAs MUST choose from the following options when + creating a distinguished name, including their own: + + (a) if the character set is sufficient, the string MAY be + represented as a PrintableString; + + (b) failing (a), if the BMPString character set is sufficient the + string MAY be represented as a BMPString; and + + (c) failing (a) and (b), the string MUST be represented as a + UTF8String. If (a) or (b) is satisfied, the CA MAY still choose + to represent the string as a UTF8String. + + Exceptions to the December 31, 2003 UTF8 encoding requirements are as + follows: + + (a) CAs MAY issue "name rollover" certificates to support an + orderly migration to UTF8String encoding. Such certificates would + include the CA's UTF8String encoded name as issuer and and the old + name encoding as subject, or vice-versa. + + (b) As stated in section 4.1.2.6, the subject field MUST be + populated with a non-empty distinguished name matching the + contents of the issuer field in all certificates issued by the + subject CA regardless of encoding. + + The TeletexString and UniversalString are included for backward + compatibility, and SHOULD NOT be used for certificates for new + subjects. However, these types MAY be used in certificates where the + name was previously established. Certificate users SHOULD be + prepared to receive certificates with these types. + + + +Housley, et. al. Standards Track [Page 19] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + In addition, many legacy implementations support names encoded in the + ISO 8859-1 character set (Latin1String) [ISO 8859-1] but tag them as + TeletexString. TeletexString encodes a larger character set than ISO + 8859-1, but it encodes some characters differently. Implementations + SHOULD be prepared to handle both encodings. + + As noted above, distinguished names are composed of attributes. This + specification does not restrict the set of attribute types that may + appear in names. However, conforming implementations MUST be + prepared to receive certificates with issuer names containing the set + of attribute types defined below. This specification RECOMMENDS + support for additional attribute types. + + Standard sets of attributes have been defined in the X.500 series of + specifications [X.520]. Implementations of this specification MUST + be prepared to receive the following standard attribute types in + issuer and subject (section 4.1.2.6) names: + + * country, + * organization, + * organizational-unit, + * distinguished name qualifier, + * state or province name, + * common name (e.g., "Susan Housley"), and + * serial number. + + In addition, implementations of this specification SHOULD be prepared + to receive the following standard attribute types in issuer and + subject names: + + * locality, + * title, + * surname, + * given name, + * initials, + * pseudonym, and + * generation qualifier (e.g., "Jr.", "3rd", or "IV"). + + The syntax and associated object identifiers (OIDs) for these + attribute types are provided in the ASN.1 modules in Appendix A. + + In addition, implementations of this specification MUST be prepared + to receive the domainComponent attribute, as defined in [RFC 2247]. + The Domain Name System (DNS) provides a hierarchical resource + labeling system. This attribute provides a convenient mechanism for + organizations that wish to use DNs that parallel their DNS names. + This is not a replacement for the dNSName component of the + + + + +Housley, et. al. Standards Track [Page 20] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + alternative name field. Implementations are not required to convert + such names into DNS names. The syntax and associated OID for this + attribute type is provided in the ASN.1 modules in Appendix A. + + Certificate users MUST be prepared to process the issuer + distinguished name and subject distinguished name (section 4.1.2.6) + fields to perform name chaining for certification path validation + (section 6). Name chaining is performed by matching the issuer + distinguished name in one certificate with the subject name in a CA + certificate. + + This specification requires only a subset of the name comparison + functionality specified in the X.500 series of specifications. + Conforming implementations are REQUIRED to implement the following + name comparison rules: + + (a) attribute values encoded in different types (e.g., + PrintableString and BMPString) MAY be assumed to represent + different strings; + + (b) attribute values in types other than PrintableString are case + sensitive (this permits matching of attribute values as binary + objects); + + (c) attribute values in PrintableString are not case sensitive + (e.g., "Marianne Swanson" is the same as "MARIANNE SWANSON"); and + + (d) attribute values in PrintableString are compared after + removing leading and trailing white space and converting internal + substrings of one or more consecutive white space characters to a + single space. + + These name comparison rules permit a certificate user to validate + certificates issued using languages or encodings unfamiliar to the + certificate user. + + In addition, implementations of this specification MAY use these + comparison rules to process unfamiliar attribute types for name + chaining. This allows implementations to process certificates with + unfamiliar attributes in the issuer name. + + Note that the comparison rules defined in the X.500 series of + specifications indicate that the character sets used to encode data + in distinguished names are irrelevant. The characters themselves are + compared without regard to encoding. Implementations of this profile + are permitted to use the comparison algorithm defined in the X.500 + series. Such an implementation will recognize a superset of name + matches recognized by the algorithm specified above. + + + +Housley, et. al. Standards Track [Page 21] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.1.2.5 Validity + + The certificate validity period is the time interval during which the + CA warrants that it will maintain information about the status of the + certificate. The field is represented as a SEQUENCE of two dates: + the date on which the certificate validity period begins (notBefore) + and the date on which the certificate validity period ends + (notAfter). Both notBefore and notAfter may be encoded as UTCTime or + GeneralizedTime. + + CAs conforming to this profile MUST always encode certificate + validity dates through the year 2049 as UTCTime; certificate validity + dates in 2050 or later MUST be encoded as GeneralizedTime. + + The validity period for a certificate is the period of time from + notBefore through notAfter, inclusive. + +4.1.2.5.1 UTCTime + + The universal time type, UTCTime, is a standard ASN.1 type intended + for representation of dates and time. UTCTime specifies the year + through the two low order digits and time is specified to the + precision of one minute or one second. UTCTime includes either Z + (for Zulu, or Greenwich Mean Time) or a time differential. + + For the purposes of this profile, UTCTime values MUST be expressed + Greenwich Mean Time (Zulu) and MUST include seconds (i.e., times are + YYMMDDHHMMSSZ), even where the number of seconds is zero. Conforming + systems MUST interpret the year field (YY) as follows: + + Where YY is greater than or equal to 50, the year SHALL be + interpreted as 19YY; and + + Where YY is less than 50, the year SHALL be interpreted as 20YY. + +4.1.2.5.2 GeneralizedTime + + The generalized time type, GeneralizedTime, is a standard ASN.1 type + for variable precision representation of time. Optionally, the + GeneralizedTime field can include a representation of the time + differential between local and Greenwich Mean Time. + + For the purposes of this profile, GeneralizedTime values MUST be + expressed Greenwich Mean Time (Zulu) and MUST include seconds (i.e., + times are YYYYMMDDHHMMSSZ), even where the number of seconds is zero. + GeneralizedTime values MUST NOT include fractional seconds. + + + + + +Housley, et. al. Standards Track [Page 22] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.1.2.6 Subject + + The subject field identifies the entity associated with the public + key stored in the subject public key field. The subject name MAY be + carried in the subject field and/or the subjectAltName extension. If + the subject is a CA (e.g., the basic constraints extension, as + discussed in 4.2.1.10, is present and the value of cA is TRUE), then + the subject field MUST be populated with a non-empty distinguished + name matching the contents of the issuer field (section 4.1.2.4) in + all certificates issued by the subject CA. If the subject is a CRL + issuer (e.g., the key usage extension, as discussed in 4.2.1.3, is + present and the value of cRLSign is TRUE) then the subject field MUST + be populated with a non-empty distinguished name matching the + contents of the issuer field (section 4.1.2.4) in all CRLs issued by + the subject CRL issuer. If subject naming information is present + only in the subjectAltName extension (e.g., a key bound only to an + email address or URI), then the subject name MUST be an empty + sequence and the subjectAltName extension MUST be critical. + + Where it is non-empty, the subject field MUST contain an X.500 + distinguished name (DN). The DN MUST be unique for each subject + entity certified by the one CA as defined by the issuer name field. + A CA MAY issue more than one certificate with the same DN to the same + subject entity. + + The subject name field is defined as the X.501 type Name. + Implementation requirements for this field are those defined for the + issuer field (section 4.1.2.4). When encoding attribute values of + type DirectoryString, the encoding rules for the issuer field MUST be + implemented. Implementations of this specification MUST be prepared + to receive subject names containing the attribute types required for + the issuer field. Implementations of this specification SHOULD be + prepared to receive subject names containing the recommended + attribute types for the issuer field. The syntax and associated + object identifiers (OIDs) for these attribute types are provided in + the ASN.1 modules in Appendix A. Implementations of this + specification MAY use these comparison rules to process unfamiliar + attribute types (i.e., for name chaining). This allows + implementations to process certificates with unfamiliar attributes in + the subject name. + + In addition, legacy implementations exist where an RFC 822 name is + embedded in the subject distinguished name as an EmailAddress + attribute. The attribute value for EmailAddress is of type IA5String + to permit inclusion of the character '@', which is not part of the + PrintableString character set. EmailAddress attribute values are not + case sensitive (e.g., "fanfeedback@redsox.com" is the same as + "FANFEEDBACK@REDSOX.COM"). + + + +Housley, et. al. Standards Track [Page 23] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Conforming implementations generating new certificates with + electronic mail addresses MUST use the rfc822Name in the subject + alternative name field (section 4.2.1.7) to describe such identities. + Simultaneous inclusion of the EmailAddress attribute in the subject + distinguished name to support legacy implementations is deprecated + but permitted. + +4.1.2.7 Subject Public Key Info + + This field is used to carry the public key and identify the algorithm + with which the key is used (e.g., RSA, DSA, or Diffie-Hellman). The + algorithm is identified using the AlgorithmIdentifier structure + specified in section 4.1.1.2. The object identifiers for the + supported algorithms and the methods for encoding the public key + materials (public key and parameters) are specified in [PKIXALGS]. + +4.1.2.8 Unique Identifiers + + These fields MUST only appear if the version is 2 or 3 (section + 4.1.2.1). These fields MUST NOT appear if the version is 1. The + subject and issuer unique identifiers are present in the certificate + to handle the possibility of reuse of subject and/or issuer names + over time. This profile RECOMMENDS that names not be reused for + different entities and that Internet certificates not make use of + unique identifiers. CAs conforming to this profile SHOULD NOT + generate certificates with unique identifiers. Applications + conforming to this profile SHOULD be capable of parsing unique + identifiers. + +4.1.2.9 Extensions + + This field MUST only appear if the version is 3 (section 4.1.2.1). + If present, this field is a SEQUENCE of one or more certificate + extensions. The format and content of certificate extensions in the + Internet PKI is defined in section 4.2. + +4.2 Certificate Extensions + + The extensions defined for X.509 v3 certificates provide methods for + associating additional attributes with users or public keys and for + managing a certification hierarchy. The X.509 v3 certificate format + also allows communities to define private extensions to carry + information unique to those communities. Each extension in a + certificate is designated as either critical or non-critical. A + certificate using system MUST reject the certificate if it encounters + a critical extension it does not recognize; however, a non-critical + extension MAY be ignored if it is not recognized. The following + sections present recommended extensions used within Internet + + + +Housley, et. al. Standards Track [Page 24] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + certificates and standard locations for information. Communities may + elect to use additional extensions; however, caution ought to be + exercised in adopting any critical extensions in certificates which + might prevent use in a general context. + + Each extension includes an OID and an ASN.1 structure. When an + extension appears in a certificate, the OID appears as the field + extnID and the corresponding ASN.1 encoded structure is the value of + the octet string extnValue. A certificate MUST NOT include more than + one instance of a particular extension. For example, a certificate + may contain only one authority key identifier extension (section + 4.2.1.1). An extension includes the boolean critical, with a default + value of FALSE. The text for each extension specifies the acceptable + values for the critical field. + + Conforming CAs MUST support key identifiers (sections 4.2.1.1 and + 4.2.1.2), basic constraints (section 4.2.1.10), key usage (section + 4.2.1.3), and certificate policies (section 4.2.1.5) extensions. If + the CA issues certificates with an empty sequence for the subject + field, the CA MUST support the subject alternative name extension + (section 4.2.1.7). Support for the remaining extensions is OPTIONAL. + Conforming CAs MAY support extensions that are not identified within + this specification; certificate issuers are cautioned that marking + such extensions as critical may inhibit interoperability. + + At a minimum, applications conforming to this profile MUST recognize + the following extensions: key usage (section 4.2.1.3), certificate + policies (section 4.2.1.5), the subject alternative name (section + 4.2.1.7), basic constraints (section 4.2.1.10), name constraints + (section 4.2.1.11), policy constraints (section 4.2.1.12), extended + key usage (section 4.2.1.13), and inhibit any-policy (section + 4.2.1.15). + + In addition, applications conforming to this profile SHOULD recognize + the authority and subject key identifier (sections 4.2.1.1 and + 4.2.1.2), and policy mapping (section 4.2.1.6) extensions. + +4.2.1 Standard Extensions + + This section identifies standard certificate extensions defined in + [X.509] for use in the Internet PKI. Each extension is associated + with an OID defined in [X.509]. These OIDs are members of the id-ce + arc, which is defined by the following: + + id-ce OBJECT IDENTIFIER ::= { joint-iso-ccitt(2) ds(5) 29 } + + + + + + +Housley, et. al. Standards Track [Page 25] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.2.1.1 Authority Key Identifier + + The authority key identifier extension provides a means of + identifying the public key corresponding to the private key used to + sign a certificate. This extension is used where an issuer has + multiple signing keys (either due to multiple concurrent key pairs or + due to changeover). The identification MAY be based on either the + key identifier (the subject key identifier in the issuer's + certificate) or on the issuer name and serial number. + + The keyIdentifier field of the authorityKeyIdentifier extension MUST + be included in all certificates generated by conforming CAs to + facilitate certification path construction. There is one exception; + where a CA distributes its public key in the form of a "self-signed" + certificate, the authority key identifier MAY be omitted. The + signature on a self-signed certificate is generated with the private + key associated with the certificate's subject public key. (This + proves that the issuer possesses both the public and private keys.) + In this case, the subject and authority key identifiers would be + identical, but only the subject key identifier is needed for + certification path building. + + The value of the keyIdentifier field SHOULD be derived from the + public key used to verify the certificate's signature or a method + that generates unique values. Two common methods for generating key + identifiers from the public key, and one common method for generating + unique values, are described in section 4.2.1.2. Where a key + identifier has not been previously established, this specification + RECOMMENDS use of one of these methods for generating keyIdentifiers. + Where a key identifier has been previously established, the CA SHOULD + use the previously established identifier. + + This profile RECOMMENDS support for the key identifier method by all + certificate users. + + This extension MUST NOT be marked critical. + + id-ce-authorityKeyIdentifier OBJECT IDENTIFIER ::= { id-ce 35 } + + AuthorityKeyIdentifier ::= SEQUENCE { + keyIdentifier [0] KeyIdentifier OPTIONAL, + authorityCertIssuer [1] GeneralNames OPTIONAL, + authorityCertSerialNumber [2] CertificateSerialNumber OPTIONAL } + + KeyIdentifier ::= OCTET STRING + + + + + + +Housley, et. al. Standards Track [Page 26] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.2.1.2 Subject Key Identifier + + The subject key identifier extension provides a means of identifying + certificates that contain a particular public key. + + To facilitate certification path construction, this extension MUST + appear in all conforming CA certificates, that is, all certificates + including the basic constraints extension (section 4.2.1.10) where + the value of cA is TRUE. The value of the subject key identifier + MUST be the value placed in the key identifier field of the Authority + Key Identifier extension (section 4.2.1.1) of certificates issued by + the subject of this certificate. + + For CA certificates, subject key identifiers SHOULD be derived from + the public key or a method that generates unique values. Two common + methods for generating key identifiers from the public key are: + + (1) The keyIdentifier is composed of the 160-bit SHA-1 hash of the + value of the BIT STRING subjectPublicKey (excluding the tag, + length, and number of unused bits). + + (2) The keyIdentifier is composed of a four bit type field with + the value 0100 followed by the least significant 60 bits of the + SHA-1 hash of the value of the BIT STRING subjectPublicKey + (excluding the tag, length, and number of unused bit string bits). + + One common method for generating unique values is a monotonically + increasing sequence of integers. + + For end entity certificates, the subject key identifier extension + provides a means for identifying certificates containing the + particular public key used in an application. Where an end entity + has obtained multiple certificates, especially from multiple CAs, the + subject key identifier provides a means to quickly identify the set + of certificates containing a particular public key. To assist + applications in identifying the appropriate end entity certificate, + this extension SHOULD be included in all end entity certificates. + + For end entity certificates, subject key identifiers SHOULD be + derived from the public key. Two common methods for generating key + identifiers from the public key are identified above. + + Where a key identifier has not been previously established, this + specification RECOMMENDS use of one of these methods for generating + keyIdentifiers. Where a key identifier has been previously + established, the CA SHOULD use the previously established identifier. + + This extension MUST NOT be marked critical. + + + +Housley, et. al. Standards Track [Page 27] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + id-ce-subjectKeyIdentifier OBJECT IDENTIFIER ::= { id-ce 14 } + + SubjectKeyIdentifier ::= KeyIdentifier + +4.2.1.3 Key Usage + + The key usage extension defines the purpose (e.g., encipherment, + signature, certificate signing) of the key contained in the + certificate. The usage restriction might be employed when a key that + could be used for more than one operation is to be restricted. For + example, when an RSA key should be used only to verify signatures on + objects other than public key certificates and CRLs, the + digitalSignature and/or nonRepudiation bits would be asserted. + Likewise, when an RSA key should be used only for key management, the + keyEncipherment bit would be asserted. + + This extension MUST appear in certificates that contain public keys + that are used to validate digital signatures on other public key + certificates or CRLs. When this extension appears, it SHOULD be + marked critical. + + id-ce-keyUsage OBJECT IDENTIFIER ::= { id-ce 15 } + + KeyUsage ::= BIT STRING { + digitalSignature (0), + nonRepudiation (1), + keyEncipherment (2), + dataEncipherment (3), + keyAgreement (4), + keyCertSign (5), + cRLSign (6), + encipherOnly (7), + decipherOnly (8) } + + Bits in the KeyUsage type are used as follows: + + The digitalSignature bit is asserted when the subject public key + is used with a digital signature mechanism to support security + services other than certificate signing (bit 5), or CRL signing + (bit 6). Digital signature mechanisms are often used for entity + authentication and data origin authentication with integrity. + + The nonRepudiation bit is asserted when the subject public key is + used to verify digital signatures used to provide a non- + repudiation service which protects against the signing entity + falsely denying some action, excluding certificate or CRL signing. + In the case of later conflict, a reliable third party may + determine the authenticity of the signed data. + + + +Housley, et. al. Standards Track [Page 28] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Further distinctions between the digitalSignature and + nonRepudiation bits may be provided in specific certificate + policies. + + The keyEncipherment bit is asserted when the subject public key is + used for key transport. For example, when an RSA key is to be + used for key management, then this bit is set. + + The dataEncipherment bit is asserted when the subject public key + is used for enciphering user data, other than cryptographic keys. + + The keyAgreement bit is asserted when the subject public key is + used for key agreement. For example, when a Diffie-Hellman key is + to be used for key management, then this bit is set. + + The keyCertSign bit is asserted when the subject public key is + used for verifying a signature on public key certificates. If the + keyCertSign bit is asserted, then the cA bit in the basic + constraints extension (section 4.2.1.10) MUST also be asserted. + + The cRLSign bit is asserted when the subject public key is used + for verifying a signature on certificate revocation list (e.g., a + CRL, delta CRL, or an ARL). This bit MUST be asserted in + certificates that are used to verify signatures on CRLs. + + The meaning of the encipherOnly bit is undefined in the absence of + the keyAgreement bit. When the encipherOnly bit is asserted and + the keyAgreement bit is also set, the subject public key may be + used only for enciphering data while performing key agreement. + + The meaning of the decipherOnly bit is undefined in the absence of + the keyAgreement bit. When the decipherOnly bit is asserted and + the keyAgreement bit is also set, the subject public key may be + used only for deciphering data while performing key agreement. + + This profile does not restrict the combinations of bits that may be + set in an instantiation of the keyUsage extension. However, + appropriate values for keyUsage extensions for particular algorithms + are specified in [PKIXALGS]. + +4.2.1.4 Private Key Usage Period + + This extension SHOULD NOT be used within the Internet PKI. CAs + conforming to this profile MUST NOT generate certificates that + include a critical private key usage period extension. + + + + + + +Housley, et. al. Standards Track [Page 29] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + The private key usage period extension allows the certificate issuer + to specify a different validity period for the private key than the + certificate. This extension is intended for use with digital + signature keys. This extension consists of two optional components, + notBefore and notAfter. The private key associated with the + certificate SHOULD NOT be used to sign objects before or after the + times specified by the two components, respectively. CAs conforming + to this profile MUST NOT generate certificates with private key usage + period extensions unless at least one of the two components is + present and the extension is non-critical. + + Where used, notBefore and notAfter are represented as GeneralizedTime + and MUST be specified and interpreted as defined in section + 4.1.2.5.2. + + id-ce-privateKeyUsagePeriod OBJECT IDENTIFIER ::= { id-ce 16 } + + PrivateKeyUsagePeriod ::= SEQUENCE { + notBefore [0] GeneralizedTime OPTIONAL, + notAfter [1] GeneralizedTime OPTIONAL } + +4.2.1.5 Certificate Policies + + The certificate policies extension contains a sequence of one or more + policy information terms, each of which consists of an object + identifier (OID) and optional qualifiers. Optional qualifiers, which + MAY be present, are not expected to change the definition of the + policy. + + In an end entity certificate, these policy information terms indicate + the policy under which the certificate has been issued and the + purposes for which the certificate may be used. In a CA certificate, + these policy information terms limit the set of policies for + certification paths which include this certificate. When a CA does + not wish to limit the set of policies for certification paths which + include this certificate, it MAY assert the special policy anyPolicy, + with a value of { 2 5 29 32 0 }. + + Applications with specific policy requirements are expected to have a + list of those policies which they will accept and to compare the + policy OIDs in the certificate to that list. If this extension is + critical, the path validation software MUST be able to interpret this + extension (including the optional qualifier), or MUST reject the + certificate. + + To promote interoperability, this profile RECOMMENDS that policy + information terms consist of only an OID. Where an OID alone is + insufficient, this profile strongly recommends that use of qualifiers + + + +Housley, et. al. Standards Track [Page 30] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + be limited to those identified in this section. When qualifiers are + used with the special policy anyPolicy, they MUST be limited to the + qualifiers identified in this section. + + This specification defines two policy qualifier types for use by + certificate policy writers and certificate issuers. The qualifier + types are the CPS Pointer and User Notice qualifiers. + + The CPS Pointer qualifier contains a pointer to a Certification + Practice Statement (CPS) published by the CA. The pointer is in the + form of a URI. Processing requirements for this qualifier are a + local matter. No action is mandated by this specification regardless + of the criticality value asserted for the extension. + + User notice is intended for display to a relying party when a + certificate is used. The application software SHOULD display all + user notices in all certificates of the certification path used, + except that if a notice is duplicated only one copy need be + displayed. To prevent such duplication, this qualifier SHOULD only + be present in end entity certificates and CA certificates issued to + other organizations. + + The user notice has two optional fields: the noticeRef field and the + explicitText field. + + The noticeRef field, if used, names an organization and + identifies, by number, a particular textual statement prepared by + that organization. For example, it might identify the + organization "CertsRUs" and notice number 1. In a typical + implementation, the application software will have a notice file + containing the current set of notices for CertsRUs; the + application will extract the notice text from the file and display + it. Messages MAY be multilingual, allowing the software to select + the particular language message for its own environment. + + An explicitText field includes the textual statement directly in + the certificate. The explicitText field is a string with a + maximum size of 200 characters. + + If both the noticeRef and explicitText options are included in the + one qualifier and if the application software can locate the notice + text indicated by the noticeRef option, then that text SHOULD be + displayed; otherwise, the explicitText string SHOULD be displayed. + + Note: While the explicitText has a maximum size of 200 characters, + some non-conforming CAs exceed this limit. Therefore, certificate + users SHOULD gracefully handle explicitText with more than 200 + characters. + + + +Housley, et. al. Standards Track [Page 31] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + id-ce-certificatePolicies OBJECT IDENTIFIER ::= { id-ce 32 } + + anyPolicy OBJECT IDENTIFIER ::= { id-ce-certificate-policies 0 } + + certificatePolicies ::= SEQUENCE SIZE (1..MAX) OF PolicyInformation + + PolicyInformation ::= SEQUENCE { + policyIdentifier CertPolicyId, + policyQualifiers SEQUENCE SIZE (1..MAX) OF + PolicyQualifierInfo OPTIONAL } + + CertPolicyId ::= OBJECT IDENTIFIER + + PolicyQualifierInfo ::= SEQUENCE { + policyQualifierId PolicyQualifierId, + qualifier ANY DEFINED BY policyQualifierId } + + -- policyQualifierIds for Internet policy qualifiers + + id-qt OBJECT IDENTIFIER ::= { id-pkix 2 } + id-qt-cps OBJECT IDENTIFIER ::= { id-qt 1 } + id-qt-unotice OBJECT IDENTIFIER ::= { id-qt 2 } + + PolicyQualifierId ::= + OBJECT IDENTIFIER ( id-qt-cps | id-qt-unotice ) + + Qualifier ::= CHOICE { + cPSuri CPSuri, + userNotice UserNotice } + + CPSuri ::= IA5String + + UserNotice ::= SEQUENCE { + noticeRef NoticeReference OPTIONAL, + explicitText DisplayText OPTIONAL} + + NoticeReference ::= SEQUENCE { + organization DisplayText, + noticeNumbers SEQUENCE OF INTEGER } + + DisplayText ::= CHOICE { + ia5String IA5String (SIZE (1..200)), + visibleString VisibleString (SIZE (1..200)), + bmpString BMPString (SIZE (1..200)), + utf8String UTF8String (SIZE (1..200)) } + + + + + + +Housley, et. al. Standards Track [Page 32] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.2.1.6 Policy Mappings + + This extension is used in CA certificates. It lists one or more + pairs of OIDs; each pair includes an issuerDomainPolicy and a + subjectDomainPolicy. The pairing indicates the issuing CA considers + its issuerDomainPolicy equivalent to the subject CA's + subjectDomainPolicy. + + The issuing CA's users might accept an issuerDomainPolicy for certain + applications. The policy mapping defines the list of policies + associated with the subject CA that may be accepted as comparable to + the issuerDomainPolicy. + + Each issuerDomainPolicy named in the policy mapping extension SHOULD + also be asserted in a certificate policies extension in the same + certificate. Policies SHOULD NOT be mapped either to or from the + special value anyPolicy (section 4.2.1.5). + + This extension MAY be supported by CAs and/or applications, and it + MUST be non-critical. + + id-ce-policyMappings OBJECT IDENTIFIER ::= { id-ce 33 } + + PolicyMappings ::= SEQUENCE SIZE (1..MAX) OF SEQUENCE { + issuerDomainPolicy CertPolicyId, + subjectDomainPolicy CertPolicyId } + +4.2.1.7 Subject Alternative Name + + The subject alternative names extension allows additional identities + to be bound to the subject of the certificate. Defined options + include an Internet electronic mail address, a DNS name, an IP + address, and a uniform resource identifier (URI). Other options + exist, including completely local definitions. Multiple name forms, + and multiple instances of each name form, MAY be included. Whenever + such identities are to be bound into a certificate, the subject + alternative name (or issuer alternative name) extension MUST be used; + however, a DNS name MAY be represented in the subject field using the + domainComponent attribute as described in section 4.1.2.4. + + Because the subject alternative name is considered to be definitively + bound to the public key, all parts of the subject alternative name + MUST be verified by the CA. + + Further, if the only subject identity included in the certificate is + an alternative name form (e.g., an electronic mail address), then the + subject distinguished name MUST be empty (an empty sequence), and the + + + + +Housley, et. al. Standards Track [Page 33] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + subjectAltName extension MUST be present. If the subject field + contains an empty sequence, the subjectAltName extension MUST be + marked critical. + + When the subjectAltName extension contains an Internet mail address, + the address MUST be included as an rfc822Name. The format of an + rfc822Name is an "addr-spec" as defined in RFC 822 [RFC 822]. An + addr-spec has the form "local-part@domain". Note that an addr-spec + has no phrase (such as a common name) before it, has no comment (text + surrounded in parentheses) after it, and is not surrounded by "<" and + ">". Note that while upper and lower case letters are allowed in an + RFC 822 addr-spec, no significance is attached to the case. + + When the subjectAltName extension contains a iPAddress, the address + MUST be stored in the octet string in "network byte order," as + specified in RFC 791 [RFC 791]. The least significant bit (LSB) of + each octet is the LSB of the corresponding byte in the network + address. For IP Version 4, as specified in RFC 791, the octet string + MUST contain exactly four octets. For IP Version 6, as specified in + RFC 1883, the octet string MUST contain exactly sixteen octets [RFC + 1883]. + + When the subjectAltName extension contains a domain name system + label, the domain name MUST be stored in the dNSName (an IA5String). + The name MUST be in the "preferred name syntax," as specified by RFC + 1034 [RFC 1034]. Note that while upper and lower case letters are + allowed in domain names, no signifigance is attached to the case. In + addition, while the string " " is a legal domain name, subjectAltName + extensions with a dNSName of " " MUST NOT be used. Finally, the use + of the DNS representation for Internet mail addresses (wpolk.nist.gov + instead of wpolk@nist.gov) MUST NOT be used; such identities are to + be encoded as rfc822Name. + + Note: work is currently underway to specify domain names in + international character sets. Such names will likely not be + accommodated by IA5String. Once this work is complete, this profile + will be revisited and the appropriate functionality will be added. + + When the subjectAltName extension contains a URI, the name MUST be + stored in the uniformResourceIdentifier (an IA5String). The name + MUST NOT be a relative URL, and it MUST follow the URL syntax and + encoding rules specified in [RFC 1738]. The name MUST include both a + scheme (e.g., "http" or "ftp") and a scheme-specific-part. The + scheme-specific-part MUST include a fully qualified domain name or IP + address as the host. + + + + + + +Housley, et. al. Standards Track [Page 34] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + As specified in [RFC 1738], the scheme name is not case-sensitive + (e.g., "http" is equivalent to "HTTP"). The host part is also not + case-sensitive, but other components of the scheme-specific-part may + be case-sensitive. When comparing URIs, conforming implementations + MUST compare the scheme and host without regard to case, but assume + the remainder of the scheme-specific-part is case sensitive. + + When the subjectAltName extension contains a DN in the directoryName, + the DN MUST be unique for each subject entity certified by the one CA + as defined by the issuer name field. A CA MAY issue more than one + certificate with the same DN to the same subject entity. + + The subjectAltName MAY carry additional name types through the use of + the otherName field. The format and semantics of the name are + indicated through the OBJECT IDENTIFIER in the type-id field. The + name itself is conveyed as value field in otherName. For example, + Kerberos [RFC 1510] format names can be encoded into the otherName, + using using a Kerberos 5 principal name OID and a SEQUENCE of the + Realm and the PrincipalName. + + Subject alternative names MAY be constrained in the same manner as + subject distinguished names using the name constraints extension as + described in section 4.2.1.11. + + If the subjectAltName extension is present, the sequence MUST contain + at least one entry. Unlike the subject field, conforming CAs MUST + NOT issue certificates with subjectAltNames containing empty + GeneralName fields. For example, an rfc822Name is represented as an + IA5String. While an empty string is a valid IA5String, such an + rfc822Name is not permitted by this profile. The behavior of clients + that encounter such a certificate when processing a certificication + path is not defined by this profile. + + Finally, the semantics of subject alternative names that include + wildcard characters (e.g., as a placeholder for a set of names) are + not addressed by this specification. Applications with specific + requirements MAY use such names, but they must define the semantics. + + id-ce-subjectAltName OBJECT IDENTIFIER ::= { id-ce 17 } + + SubjectAltName ::= GeneralNames + + GeneralNames ::= SEQUENCE SIZE (1..MAX) OF GeneralName + + + + + + + + +Housley, et. al. Standards Track [Page 35] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + GeneralName ::= CHOICE { + otherName [0] OtherName, + rfc822Name [1] IA5String, + dNSName [2] IA5String, + x400Address [3] ORAddress, + directoryName [4] Name, + ediPartyName [5] EDIPartyName, + uniformResourceIdentifier [6] IA5String, + iPAddress [7] OCTET STRING, + registeredID [8] OBJECT IDENTIFIER } + + OtherName ::= SEQUENCE { + type-id OBJECT IDENTIFIER, + value [0] EXPLICIT ANY DEFINED BY type-id } + + EDIPartyName ::= SEQUENCE { + nameAssigner [0] DirectoryString OPTIONAL, + partyName [1] DirectoryString } + +4.2.1.8 Issuer Alternative Names + + As with 4.2.1.7, this extension is used to associate Internet style + identities with the certificate issuer. Issuer alternative names + MUST be encoded as in 4.2.1.7. + + Where present, this extension SHOULD NOT be marked critical. + + id-ce-issuerAltName OBJECT IDENTIFIER ::= { id-ce 18 } + + IssuerAltName ::= GeneralNames + +4.2.1.9 Subject Directory Attributes + + The subject directory attributes extension is used to convey + identification attributes (e.g., nationality) of the subject. The + extension is defined as a sequence of one or more attributes. This + extension MUST be non-critical. + + id-ce-subjectDirectoryAttributes OBJECT IDENTIFIER ::= { id-ce 9 } + + SubjectDirectoryAttributes ::= SEQUENCE SIZE (1..MAX) OF Attribute + +4.2.1.10 Basic Constraints + + The basic constraints extension identifies whether the subject of the + certificate is a CA and the maximum depth of valid certification + paths that include this certificate. + + + + +Housley, et. al. Standards Track [Page 36] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + The cA boolean indicates whether the certified public key belongs to + a CA. If the cA boolean is not asserted, then the keyCertSign bit in + the key usage extension MUST NOT be asserted. + + The pathLenConstraint field is meaningful only if the cA boolean is + asserted and the key usage extension asserts the keyCertSign bit + (section 4.2.1.3). In this case, it gives the maximum number of non- + self-issued intermediate certificates that may follow this + certificate in a valid certification path. A certificate is self- + issued if the DNs that appear in the subject and issuer fields are + identical and are not empty. (Note: The last certificate in the + certification path is not an intermediate certificate, and is not + included in this limit. Usually, the last certificate is an end + entity certificate, but it can be a CA certificate.) A + pathLenConstraint of zero indicates that only one more certificate + may follow in a valid certification path. Where it appears, the + pathLenConstraint field MUST be greater than or equal to zero. Where + pathLenConstraint does not appear, no limit is imposed. + + This extension MUST appear as a critical extension in all CA + certificates that contain public keys used to validate digital + signatures on certificates. This extension MAY appear as a critical + or non-critical extension in CA certificates that contain public keys + used exclusively for purposes other than validating digital + signatures on certificates. Such CA certificates include ones that + contain public keys used exclusively for validating digital + signatures on CRLs and ones that contain key management public keys + used with certificate enrollment protocols. This extension MAY + appear as a critical or non-critical extension in end entity + certificates. + + CAs MUST NOT include the pathLenConstraint field unless the cA + boolean is asserted and the key usage extension asserts the + keyCertSign bit. + + id-ce-basicConstraints OBJECT IDENTIFIER ::= { id-ce 19 } + + BasicConstraints ::= SEQUENCE { + cA BOOLEAN DEFAULT FALSE, + pathLenConstraint INTEGER (0..MAX) OPTIONAL } + +4.2.1.11 Name Constraints + + The name constraints extension, which MUST be used only in a CA + certificate, indicates a name space within which all subject names in + subsequent certificates in a certification path MUST be located. + Restrictions apply to the subject distinguished name and apply to + subject alternative names. Restrictions apply only when the + + + +Housley, et. al. Standards Track [Page 37] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + specified name form is present. If no name of the type is in the + certificate, the certificate is acceptable. + + Name constraints are not applied to certificates whose issuer and + subject are identical (unless the certificate is the final + certificate in the path). (This could prevent CAs that use name + constraints from employing self-issued certificates to implement key + rollover.) + + Restrictions are defined in terms of permitted or excluded name + subtrees. Any name matching a restriction in the excludedSubtrees + field is invalid regardless of information appearing in the + permittedSubtrees. This extension MUST be critical. + + Within this profile, the minimum and maximum fields are not used with + any name forms, thus minimum MUST be zero, and maximum MUST be + absent. + + For URIs, the constraint applies to the host part of the name. The + constraint MAY specify a host or a domain. Examples would be + "foo.bar.com"; and ".xyz.com". When the the constraint begins with + a period, it MAY be expanded with one or more subdomains. That is, + the constraint ".xyz.com" is satisfied by both abc.xyz.com and + abc.def.xyz.com. However, the constraint ".xyz.com" is not satisfied + by "xyz.com". When the constraint does not begin with a period, it + specifies a host. + + A name constraint for Internet mail addresses MAY specify a + particular mailbox, all addresses at a particular host, or all + mailboxes in a domain. To indicate a particular mailbox, the + constraint is the complete mail address. For example, "root@xyz.com" + indicates the root mailbox on the host "xyz.com". To indicate all + Internet mail addresses on a particular host, the constraint is + specified as the host name. For example, the constraint "xyz.com" is + satisfied by any mail address at the host "xyz.com". To specify any + address within a domain, the constraint is specified with a leading + period (as with URIs). For example, ".xyz.com" indicates all the + Internet mail addresses in the domain "xyz.com", but not Internet + mail addresses on the host "xyz.com". + + DNS name restrictions are expressed as foo.bar.com. Any DNS name + that can be constructed by simply adding to the left hand side of the + name satisfies the name constraint. For example, www.foo.bar.com + would satisfy the constraint but foo1.bar.com would not. + + Legacy implementations exist where an RFC 822 name is embedded in the + subject distinguished name in an attribute of type EmailAddress + (section 4.1.2.6). When rfc822 names are constrained, but the + + + +Housley, et. al. Standards Track [Page 38] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + certificate does not include a subject alternative name, the rfc822 + name constraint MUST be applied to the attribute of type EmailAddress + in the subject distinguished name. The ASN.1 syntax for EmailAddress + and the corresponding OID are supplied in Appendix A. + + Restrictions of the form directoryName MUST be applied to the subject + field in the certificate and to the subjectAltName extensions of type + directoryName. Restrictions of the form x400Address MUST be applied + to subjectAltName extensions of type x400Address. + + When applying restrictions of the form directoryName, an + implementation MUST compare DN attributes. At a minimum, + implementations MUST perform the DN comparison rules specified in + Section 4.1.2.4. CAs issuing certificates with a restriction of the + form directoryName SHOULD NOT rely on implementation of the full ISO + DN name comparison algorithm. This implies name restrictions MUST be + stated identically to the encoding used in the subject field or + subjectAltName extension. + + The syntax of iPAddress MUST be as described in section 4.2.1.7 with + the following additions specifically for Name Constraints. For IPv4 + addresses, the ipAddress field of generalName MUST contain eight (8) + octets, encoded in the style of RFC 1519 (CIDR) to represent an + address range [RFC 1519]. For IPv6 addresses, the ipAddress field + MUST contain 32 octets similarly encoded. For example, a name + constraint for "class C" subnet 10.9.8.0 is represented as the octets + 0A 09 08 00 FF FF FF 00, representing the CIDR notation + 10.9.8.0/255.255.255.0. + + The syntax and semantics for name constraints for otherName, + ediPartyName, and registeredID are not defined by this specification. + + id-ce-nameConstraints OBJECT IDENTIFIER ::= { id-ce 30 } + + NameConstraints ::= SEQUENCE { + permittedSubtrees [0] GeneralSubtrees OPTIONAL, + excludedSubtrees [1] GeneralSubtrees OPTIONAL } + + GeneralSubtrees ::= SEQUENCE SIZE (1..MAX) OF GeneralSubtree + + GeneralSubtree ::= SEQUENCE { + base GeneralName, + minimum [0] BaseDistance DEFAULT 0, + maximum [1] BaseDistance OPTIONAL } + + BaseDistance ::= INTEGER (0..MAX) + + + + + +Housley, et. al. Standards Track [Page 39] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.2.1.12 Policy Constraints + + The policy constraints extension can be used in certificates issued + to CAs. The policy constraints extension constrains path validation + in two ways. It can be used to prohibit policy mapping or require + that each certificate in a path contain an acceptable policy + identifier. + + If the inhibitPolicyMapping field is present, the value indicates the + number of additional certificates that may appear in the path before + policy mapping is no longer permitted. For example, a value of one + indicates that policy mapping may be processed in certificates issued + by the subject of this certificate, but not in additional + certificates in the path. + + If the requireExplicitPolicy field is present, the value of + requireExplicitPolicy indicates the number of additional certificates + that may appear in the path before an explicit policy is required for + the entire path. When an explicit policy is required, it is + necessary for all certificates in the path to contain an acceptable + policy identifier in the certificate policies extension. An + acceptable policy identifier is the identifier of a policy required + by the user of the certification path or the identifier of a policy + which has been declared equivalent through policy mapping. + + Conforming CAs MUST NOT issue certificates where policy constraints + is a empty sequence. That is, at least one of the + inhibitPolicyMapping field or the requireExplicitPolicy field MUST be + present. The behavior of clients that encounter a empty policy + constraints field is not addressed in this profile. + + This extension MAY be critical or non-critical. + + id-ce-policyConstraints OBJECT IDENTIFIER ::= { id-ce 36 } + + PolicyConstraints ::= SEQUENCE { + requireExplicitPolicy [0] SkipCerts OPTIONAL, + inhibitPolicyMapping [1] SkipCerts OPTIONAL } + + SkipCerts ::= INTEGER (0..MAX) + +4.2.1.13 Extended Key Usage + + This extension indicates one or more purposes for which the certified + public key may be used, in addition to or in place of the basic + purposes indicated in the key usage extension. In general, this + extension will appear only in end entity certificates. This + extension is defined as follows: + + + +Housley, et. al. Standards Track [Page 40] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + id-ce-extKeyUsage OBJECT IDENTIFIER ::= { id-ce 37 } + + ExtKeyUsageSyntax ::= SEQUENCE SIZE (1..MAX) OF KeyPurposeId + + KeyPurposeId ::= OBJECT IDENTIFIER + + Key purposes may be defined by any organization with a need. Object + identifiers used to identify key purposes MUST be assigned in + accordance with IANA or ITU-T Recommendation X.660 [X.660]. + + This extension MAY, at the option of the certificate issuer, be + either critical or non-critical. + + If the extension is present, then the certificate MUST only be used + for one of the purposes indicated. If multiple purposes are + indicated the application need not recognize all purposes indicated, + as long as the intended purpose is present. Certificate using + applications MAY require that a particular purpose be indicated in + order for the certificate to be acceptable to that application. + + If a CA includes extended key usages to satisfy such applications, + but does not wish to restrict usages of the key, the CA can include + the special keyPurposeID anyExtendedKeyUsage. If the + anyExtendedKeyUsage keyPurposeID is present, the extension SHOULD NOT + be critical. + + If a certificate contains both a key usage extension and an extended + key usage extension, then both extensions MUST be processed + independently and the certificate MUST only be used for a purpose + consistent with both extensions. If there is no purpose consistent + with both extensions, then the certificate MUST NOT be used for any + purpose. + + The following key usage purposes are defined: + + anyExtendedKeyUsage OBJECT IDENTIFIER ::= { id-ce-extKeyUsage 0 } + + id-kp OBJECT IDENTIFIER ::= { id-pkix 3 } + + id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } + -- TLS WWW server authentication + -- Key usage bits that may be consistent: digitalSignature, + -- keyEncipherment or keyAgreement + + id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } + -- TLS WWW client authentication + -- Key usage bits that may be consistent: digitalSignature + -- and/or keyAgreement + + + +Housley, et. al. Standards Track [Page 41] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + id-kp-codeSigning OBJECT IDENTIFIER ::= { id-kp 3 } + -- Signing of downloadable executable code + -- Key usage bits that may be consistent: digitalSignature + + id-kp-emailProtection OBJECT IDENTIFIER ::= { id-kp 4 } + -- E-mail protection + -- Key usage bits that may be consistent: digitalSignature, + -- nonRepudiation, and/or (keyEncipherment or keyAgreement) + + id-kp-timeStamping OBJECT IDENTIFIER ::= { id-kp 8 } + -- Binding the hash of an object to a time + -- Key usage bits that may be consistent: digitalSignature + -- and/or nonRepudiation + + id-kp-OCSPSigning OBJECT IDENTIFIER ::= { id-kp 9 } + -- Signing OCSP responses + -- Key usage bits that may be consistent: digitalSignature + -- and/or nonRepudiation + +4.2.1.14 CRL Distribution Points + + The CRL distribution points extension identifies how CRL information + is obtained. The extension SHOULD be non-critical, but this profile + RECOMMENDS support for this extension by CAs and applications. + Further discussion of CRL management is contained in section 5. + + The cRLDistributionPoints extension is a SEQUENCE of + DistributionPoint. A DistributionPoint consists of three fields, + each of which is optional: distributionPoint, reasons, and cRLIssuer. + While each of these fields is optional, a DistributionPoint MUST NOT + consist of only the reasons field; either distributionPoint or + cRLIssuer MUST be present. If the certificate issuer is not the CRL + issuer, then the cRLIssuer field MUST be present and contain the Name + of the CRL issuer. If the certificate issuer is also the CRL issuer, + then the cRLIssuer field MUST be omitted and the distributionPoint + field MUST be present. If the distributionPoint field is omitted, + cRLIssuer MUST be present and include a Name corresponding to an + X.500 or LDAP directory entry where the CRL is located. + + When the distributionPoint field is present, it contains either a + SEQUENCE of general names or a single value, nameRelativeToCRLIssuer. + If the cRLDistributionPoints extension contains a general name of + type URI, the following semantics MUST be assumed: the URI is a + pointer to the current CRL for the associated reasons and will be + issued by the associated cRLIssuer. The expected values for the URI + are those defined in 4.2.1.7. Processing rules for other values are + not defined by this specification. + + + + +Housley, et. al. Standards Track [Page 42] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + If the DistributionPointName contains multiple values, each name + describes a different mechanism to obtain the same CRL. For example, + the same CRL could be available for retrieval through both LDAP and + HTTP. + + If the DistributionPointName contains the single value + nameRelativeToCRLIssuer, the value provides a distinguished name + fragment. The fragment is appended to the X.500 distinguished name + of the CRL issuer to obtain the distribution point name. If the + cRLIssuer field in the DistributionPoint is present, then the name + fragment is appended to the distinguished name that it contains; + otherwise, the name fragment is appended to the certificate issuer + distinguished name. The DistributionPointName MUST NOT use the + nameRealtiveToCRLIssuer alternative when cRLIssuer contains more than + one distinguished name. + + If the DistributionPoint omits the reasons field, the CRL MUST + include revocation information for all reasons. + + The cRLIssuer identifies the entity who signs and issues the CRL. If + present, the cRLIssuer MUST contain at least one an X.500 + distinguished name (DN), and MAY also contain other name forms. + Since the cRLIssuer is compared to the CRL issuer name, the X.501 + type Name MUST follow the encoding rules for the issuer name field in + the certificate (section 4.1.2.4). + + id-ce-cRLDistributionPoints OBJECT IDENTIFIER ::= { id-ce 31 } + + CRLDistributionPoints ::= SEQUENCE SIZE (1..MAX) OF DistributionPoint + + DistributionPoint ::= SEQUENCE { + distributionPoint [0] DistributionPointName OPTIONAL, + reasons [1] ReasonFlags OPTIONAL, + cRLIssuer [2] GeneralNames OPTIONAL } + + DistributionPointName ::= CHOICE { + fullName [0] GeneralNames, + nameRelativeToCRLIssuer [1] RelativeDistinguishedName } + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 43] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + ReasonFlags ::= BIT STRING { + unused (0), + keyCompromise (1), + cACompromise (2), + affiliationChanged (3), + superseded (4), + cessationOfOperation (5), + certificateHold (6), + privilegeWithdrawn (7), + aACompromise (8) } + +4.2.1.15 Inhibit Any-Policy + + The inhibit any-policy extension can be used in certificates issued + to CAs. The inhibit any-policy indicates that the special anyPolicy + OID, with the value { 2 5 29 32 0 }, is not considered an explicit + match for other certificate policies. The value indicates the number + of additional certificates that may appear in the path before + anyPolicy is no longer permitted. For example, a value of one + indicates that anyPolicy may be processed in certificates issued by + the subject of this certificate, but not in additional certificates + in the path. + + This extension MUST be critical. + + id-ce-inhibitAnyPolicy OBJECT IDENTIFIER ::= { id-ce 54 } + + InhibitAnyPolicy ::= SkipCerts + + SkipCerts ::= INTEGER (0..MAX) + +4.2.1.16 Freshest CRL (a.k.a. Delta CRL Distribution Point) + + The freshest CRL extension identifies how delta CRL information is + obtained. The extension MUST be non-critical. Further discussion of + CRL management is contained in section 5. + + The same syntax is used for this extension and the + cRLDistributionPoints extension, and is described in section + 4.2.1.14. The same conventions apply to both extensions. + + id-ce-freshestCRL OBJECT IDENTIFIER ::= { id-ce 46 } + + FreshestCRL ::= CRLDistributionPoints + + + + + + + +Housley, et. al. Standards Track [Page 44] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +4.2.2 Private Internet Extensions + + This section defines two extensions for use in the Internet Public + Key Infrastructure. These extensions may be used to direct + applications to on-line information about the issuing CA or the + subject. As the information may be available in multiple forms, each + extension is a sequence of IA5String values, each of which represents + a URI. The URI implicitly specifies the location and format of the + information and the method for obtaining the information. + + An object identifier is defined for the private extension. The + object identifier associated with the private extension is defined + under the arc id-pe within the arc id-pkix. Any future extensions + defined for the Internet PKI are also expected to be defined under + the arc id-pe. + + id-pkix OBJECT IDENTIFIER ::= + { iso(1) identified-organization(3) dod(6) internet(1) + security(5) mechanisms(5) pkix(7) } + + id-pe OBJECT IDENTIFIER ::= { id-pkix 1 } + +4.2.2.1 Authority Information Access + + The authority information access extension indicates how to access CA + information and services for the issuer of the certificate in which + the extension appears. Information and services may include on-line + validation services and CA policy data. (The location of CRLs is not + specified in this extension; that information is provided by the + cRLDistributionPoints extension.) This extension may be included in + end entity or CA certificates, and it MUST be non-critical. + + id-pe-authorityInfoAccess OBJECT IDENTIFIER ::= { id-pe 1 } + + AuthorityInfoAccessSyntax ::= + SEQUENCE SIZE (1..MAX) OF AccessDescription + + AccessDescription ::= SEQUENCE { + accessMethod OBJECT IDENTIFIER, + accessLocation GeneralName } + + id-ad OBJECT IDENTIFIER ::= { id-pkix 48 } + + id-ad-caIssuers OBJECT IDENTIFIER ::= { id-ad 2 } + + id-ad-ocsp OBJECT IDENTIFIER ::= { id-ad 1 } + + + + + +Housley, et. al. Standards Track [Page 45] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + Each entry in the sequence AuthorityInfoAccessSyntax describes the + format and location of additional information provided by the CA that + issued the certificate in which this extension appears. The type and + format of the information is specified by the accessMethod field; the + accessLocation field specifies the location of the information. The + retrieval mechanism may be implied by the accessMethod or specified + by accessLocation. + + This profile defines two accessMethod OIDs: id-ad-caIssuers and + id-ad-ocsp. + + The id-ad-caIssuers OID is used when the additional information lists + CAs that have issued certificates superior to the CA that issued the + certificate containing this extension. The referenced CA issuers + description is intended to aid certificate users in the selection of + a certification path that terminates at a point trusted by the + certificate user. + + When id-ad-caIssuers appears as accessMethod, the accessLocation + field describes the referenced description server and the access + protocol to obtain the referenced description. The accessLocation + field is defined as a GeneralName, which can take several forms. + Where the information is available via http, ftp, or ldap, + accessLocation MUST be a uniformResourceIdentifier. Where the + information is available via the Directory Access Protocol (DAP), + accessLocation MUST be a directoryName. The entry for that + directoryName contains CA certificates in the crossCertificatePair + attribute. When the information is available via electronic mail, + accessLocation MUST be an rfc822Name. The semantics of other + id-ad-caIssuers accessLocation name forms are not defined. + + The id-ad-ocsp OID is used when revocation information for the + certificate containing this extension is available using the Online + Certificate Status Protocol (OCSP) [RFC 2560]. + + When id-ad-ocsp appears as accessMethod, the accessLocation field is + the location of the OCSP responder, using the conventions defined in + [RFC 2560]. + + Additional access descriptors may be defined in other PKIX + specifications. + +4.2.2.2 Subject Information Access + + The subject information access extension indicates how to access + information and services for the subject of the certificate in which + the extension appears. When the subject is a CA, information and + services may include certificate validation services and CA policy + + + +Housley, et. al. Standards Track [Page 46] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + data. When the subject is an end entity, the information describes + the type of services offered and how to access them. In this case, + the contents of this extension are defined in the protocol + specifications for the suported services. This extension may be + included in subject or CA certificates, and it MUST be non-critical. + + id-pe-subjectInfoAccess OBJECT IDENTIFIER ::= { id-pe 11 } + + SubjectInfoAccessSyntax ::= + SEQUENCE SIZE (1..MAX) OF AccessDescription + + AccessDescription ::= SEQUENCE { + accessMethod OBJECT IDENTIFIER, + accessLocation GeneralName } + + Each entry in the sequence SubjectInfoAccessSyntax describes the + format and location of additional information provided by the subject + of the certificate in which this extension appears. The type and + format of the information is specified by the accessMethod field; the + accessLocation field specifies the location of the information. The + retrieval mechanism may be implied by the accessMethod or specified + by accessLocation. + + This profile defines one access method to be used when the subject is + a CA, and one access method to be used when the subject is an end + entity. Additional access methods may be defined in the future in + the protocol specifications for other services. + + The id-ad-caRepository OID is used when the subject is a CA, and + publishes its certificates and CRLs (if issued) in a repository. The + accessLocation field is defined as a GeneralName, which can take + several forms. Where the information is available via http, ftp, or + ldap, accessLocation MUST be a uniformResourceIdentifier. Where the + information is available via the directory access protocol (dap), + accessLocation MUST be a directoryName. When the information is + available via electronic mail, accessLocation MUST be an rfc822Name. + The semantics of other name forms of of accessLocation (when + accessMethod is id-ad-caRepository) are not defined by this + specification. + + The id-ad-timeStamping OID is used when the subject offers + timestamping services using the Time Stamp Protocol defined in + [PKIXTSA]. Where the timestamping services are available via http or + ftp, accessLocation MUST be a uniformResourceIdentifier. Where the + timestamping services are available via electronic mail, + accessLocation MUST be an rfc822Name. Where timestamping services + + + + + +Housley, et. al. Standards Track [Page 47] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + are available using TCP/IP, the dNSName or ipAddress name forms may + be used. The semantics of other name forms of accessLocation (when + accessMethod is id-ad-timeStamping) are not defined by this + specification. + + Additional access descriptors may be defined in other PKIX + specifications. + + id-ad OBJECT IDENTIFIER ::= { id-pkix 48 } + + id-ad-caRepository OBJECT IDENTIFIER ::= { id-ad 5 } + + id-ad-timeStamping OBJECT IDENTIFIER ::= { id-ad 3 } + +5 CRL and CRL Extensions Profile + + As discussed above, one goal of this X.509 v2 CRL profile is to + foster the creation of an interoperable and reusable Internet PKI. + To achieve this goal, guidelines for the use of extensions are + specified, and some assumptions are made about the nature of + information included in the CRL. + + CRLs may be used in a wide range of applications and environments + covering a broad spectrum of interoperability goals and an even + broader spectrum of operational and assurance requirements. This + profile establishes a common baseline for generic applications + requiring broad interoperability. The profile defines a set of + information that can be expected in every CRL. Also, the profile + defines common locations within the CRL for frequently used + attributes as well as common representations for these attributes. + + CRL issuers issue CRLs. In general, the CRL issuer is the CA. CAs + publish CRLs to provide status information about the certificates + they issued. However, a CA may delegate this responsibility to + another trusted authority. Whenever the CRL issuer is not the CA + that issued the certificates, the CRL is referred to as an indirect + CRL. + + Each CRL has a particular scope. The CRL scope is the set of + certificates that could appear on a given CRL. For example, the + scope could be "all certificates issued by CA X", "all CA + certificates issued by CA X", "all certificates issued by CA X that + have been revoked for reasons of key compromise and CA compromise", + or could be a set of certificates based on arbitrary local + information, such as "all certificates issued to the NIST employees + located in Boulder". + + + + + +Housley, et. al. Standards Track [Page 48] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + A complete CRL lists all unexpired certificates, within its scope, + that have been revoked for one of the revocation reasons covered by + the CRL scope. The CRL issuer MAY also generate delta CRLs. A delta + CRL only lists those certificates, within its scope, whose revocation + status has changed since the issuance of a referenced complete CRL. + The referenced complete CRL is referred to as a base CRL. The scope + of a delta CRL MUST be the same as the base CRL that it references. + + This profile does not define any private Internet CRL extensions or + CRL entry extensions. + + Environments with additional or special purpose requirements may + build on this profile or may replace it. + + Conforming CAs are not required to issue CRLs if other revocation or + certificate status mechanisms are provided. When CRLs are issued, + the CRLs MUST be version 2 CRLs, include the date by which the next + CRL will be issued in the nextUpdate field (section 5.1.2.5), include + the CRL number extension (section 5.2.3), and include the authority + key identifier extension (section 5.2.1). Conforming applications + that support CRLs are REQUIRED to process both version 1 and version + 2 complete CRLs that provide revocation information for all + certificates issued by one CA. Conforming applications are NOT + REQUIRED to support processing of delta CRLs, indirect CRLs, or CRLs + with a scope other than all certificates issued by one CA. + +5.1 CRL Fields + + The X.509 v2 CRL syntax is as follows. For signature calculation, + the data that is to be signed is ASN.1 DER encoded. ASN.1 DER + encoding is a tag, length, value encoding system for each element. + + CertificateList ::= SEQUENCE { + tbsCertList TBSCertList, + signatureAlgorithm AlgorithmIdentifier, + signatureValue BIT STRING } + + + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 49] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + TBSCertList ::= SEQUENCE { + version Version OPTIONAL, + -- if present, MUST be v2 + signature AlgorithmIdentifier, + issuer Name, + thisUpdate Time, + nextUpdate Time OPTIONAL, + revokedCertificates SEQUENCE OF SEQUENCE { + userCertificate CertificateSerialNumber, + revocationDate Time, + crlEntryExtensions Extensions OPTIONAL + -- if present, MUST be v2 + } OPTIONAL, + crlExtensions [0] EXPLICIT Extensions OPTIONAL + -- if present, MUST be v2 + } + + -- Version, Time, CertificateSerialNumber, and Extensions + -- are all defined in the ASN.1 in section 4.1 + + -- AlgorithmIdentifier is defined in section 4.1.1.2 + + The following items describe the use of the X.509 v2 CRL in the + Internet PKI. + +5.1.1 CertificateList Fields + + The CertificateList is a SEQUENCE of three required fields. The + fields are described in detail in the following subsections. + +5.1.1.1 tbsCertList + + The first field in the sequence is the tbsCertList. This field is + itself a sequence containing the name of the issuer, issue date, + issue date of the next list, the optional list of revoked + certificates, and optional CRL extensions. When there are no revoked + certificates, the revoked certificates list is absent. When one or + more certificates are revoked, each entry on the revoked certificate + list is defined by a sequence of user certificate serial number, + revocation date, and optional CRL entry extensions. + +5.1.1.2 signatureAlgorithm + + The signatureAlgorithm field contains the algorithm identifier for + the algorithm used by the CRL issuer to sign the CertificateList. + The field is of type AlgorithmIdentifier, which is defined in section + 4.1.1.2. [PKIXALGS] lists the supported algorithms for this + specification, but other signature algorithms MAY also be supported. + + + +Housley, et. al. Standards Track [Page 50] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + This field MUST contain the same algorithm identifier as the + signature field in the sequence tbsCertList (section 5.1.2.2). + +5.1.1.3 signatureValue + + The signatureValue field contains a digital signature computed upon + the ASN.1 DER encoded tbsCertList. The ASN.1 DER encoded tbsCertList + is used as the input to the signature function. This signature value + is encoded as a BIT STRING and included in the CRL signatureValue + field. The details of this process are specified for each of the + supported algorithms in [PKIXALGS]. + + CAs that are also CRL issuers MAY use one private key to digitally + sign certificates and CRLs, or MAY use separate private keys to + digitally sign certificates and CRLs. When separate private keys are + employed, each of the public keys associated with these private keys + is placed in a separate certificate, one with the keyCertSign bit set + in the key usage extension, and one with the cRLSign bit set in the + key usage extension (section 4.2.1.3). When separate private keys + are employed, certificates issued by the CA contain one authority key + identifier, and the corresponding CRLs contain a different authority + key identifier. The use of separate CA certificates for validation + of certificate signatures and CRL signatures can offer improved + security characteristics; however, it imposes a burden on + applications, and it might limit interoperability. Many applications + construct a certification path, and then validate the certification + path (section 6). CRL checking in turn requires a separate + certification path to be constructed and validated for the CA's CRL + signature validation certificate. Applications that perform CRL + checking MUST support certification path validation when certificates + and CRLs are digitally signed with the same CA private key. These + applications SHOULD support certification path validation when + certificates and CRLs are digitally signed with different CA private + keys. + +5.1.2 Certificate List "To Be Signed" + + The certificate list to be signed, or TBSCertList, is a sequence of + required and optional fields. The required fields identify the CRL + issuer, the algorithm used to sign the CRL, the date and time the CRL + was issued, and the date and time by which the CRL issuer will issue + the next CRL. + + Optional fields include lists of revoked certificates and CRL + extensions. The revoked certificate list is optional to support the + case where a CA has not revoked any unexpired certificates that it + + + + + +Housley, et. al. Standards Track [Page 51] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + has issued. The profile requires conforming CRL issuers to use the + CRL number and authority key identifier CRL extensions in all CRLs + issued. + +5.1.2.1 Version + + This optional field describes the version of the encoded CRL. When + extensions are used, as required by this profile, this field MUST be + present and MUST specify version 2 (the integer value is 1). + +5.1.2.2 Signature + + This field contains the algorithm identifier for the algorithm used + to sign the CRL. [PKIXALGS] lists OIDs for the most popular + signature algorithms used in the Internet PKI. + + This field MUST contain the same algorithm identifier as the + signatureAlgorithm field in the sequence CertificateList (section + 5.1.1.2). + +5.1.2.3 Issuer Name + + The issuer name identifies the entity who has signed and issued the + CRL. The issuer identity is carried in the issuer name field. + Alternative name forms may also appear in the issuerAltName extension + (section 5.2.2). The issuer name field MUST contain an X.500 + distinguished name (DN). The issuer name field is defined as the + X.501 type Name, and MUST follow the encoding rules for the issuer + name field in the certificate (section 4.1.2.4). + +5.1.2.4 This Update + + This field indicates the issue date of this CRL. ThisUpdate may be + encoded as UTCTime or GeneralizedTime. + + CRL issuers conforming to this profile MUST encode thisUpdate as + UTCTime for dates through the year 2049. CRL issuers conforming to + this profile MUST encode thisUpdate as GeneralizedTime for dates in + the year 2050 or later. + + Where encoded as UTCTime, thisUpdate MUST be specified and + interpreted as defined in section 4.1.2.5.1. Where encoded as + GeneralizedTime, thisUpdate MUST be specified and interpreted as + defined in section 4.1.2.5.2. + + + + + + + +Housley, et. al. Standards Track [Page 52] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +5.1.2.5 Next Update + + This field indicates the date by which the next CRL will be issued. + The next CRL could be issued before the indicated date, but it will + not be issued any later than the indicated date. CRL issuers SHOULD + issue CRLs with a nextUpdate time equal to or later than all previous + CRLs. nextUpdate may be encoded as UTCTime or GeneralizedTime. + + This profile requires inclusion of nextUpdate in all CRLs issued by + conforming CRL issuers. Note that the ASN.1 syntax of TBSCertList + describes this field as OPTIONAL, which is consistent with the ASN.1 + structure defined in [X.509]. The behavior of clients processing + CRLs which omit nextUpdate is not specified by this profile. + + CRL issuers conforming to this profile MUST encode nextUpdate as + UTCTime for dates through the year 2049. CRL issuers conforming to + this profile MUST encode nextUpdate as GeneralizedTime for dates in + the year 2050 or later. + + Where encoded as UTCTime, nextUpdate MUST be specified and + interpreted as defined in section 4.1.2.5.1. Where encoded as + GeneralizedTime, nextUpdate MUST be specified and interpreted as + defined in section 4.1.2.5.2. + +5.1.2.6 Revoked Certificates + + When there are no revoked certificates, the revoked certificates list + MUST be absent. Otherwise, revoked certificates are listed by their + serial numbers. Certificates revoked by the CA are uniquely + identified by the certificate serial number. The date on which the + revocation occurred is specified. The time for revocationDate MUST + be expressed as described in section 5.1.2.4. Additional information + may be supplied in CRL entry extensions; CRL entry extensions are + discussed in section 5.3. + +5.1.2.7 Extensions + + This field may only appear if the version is 2 (section 5.1.2.1). If + present, this field is a sequence of one or more CRL extensions. CRL + extensions are discussed in section 5.2. + +5.2 CRL Extensions + + The extensions defined by ANSI X9, ISO/IEC, and ITU-T for X.509 v2 + CRLs [X.509] [X9.55] provide methods for associating additional + attributes with CRLs. The X.509 v2 CRL format also allows + communities to define private extensions to carry information unique + to those communities. Each extension in a CRL may be designated as + + + +Housley, et. al. Standards Track [Page 53] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + critical or non-critical. A CRL validation MUST fail if it + encounters a critical extension which it does not know how to + process. However, an unrecognized non-critical extension may be + ignored. The following subsections present those extensions used + within Internet CRLs. Communities may elect to include extensions in + CRLs which are not defined in this specification. However, caution + should be exercised in adopting any critical extensions in CRLs which + might be used in a general context. + + Conforming CRL issuers are REQUIRED to include the authority key + identifier (section 5.2.1) and the CRL number (section 5.2.3) + extensions in all CRLs issued. + +5.2.1 Authority Key Identifier + + The authority key identifier extension provides a means of + identifying the public key corresponding to the private key used to + sign a CRL. The identification can be based on either the key + identifier (the subject key identifier in the CRL signer's + certificate) or on the issuer name and serial number. This extension + is especially useful where an issuer has more than one signing key, + either due to multiple concurrent key pairs or due to changeover. + + Conforming CRL issuers MUST use the key identifier method, and MUST + include this extension in all CRLs issued. + + The syntax for this CRL extension is defined in section 4.2.1.1. + +5.2.2 Issuer Alternative Name + + The issuer alternative names extension allows additional identities + to be associated with the issuer of the CRL. Defined options include + an rfc822 name (electronic mail address), a DNS name, an IP address, + and a URI. Multiple instances of a name and multiple name forms may + be included. Whenever such identities are used, the issuer + alternative name extension MUST be used; however, a DNS name MAY be + represented in the issuer field using the domainComponent attribute + as described in section 4.1.2.4. + + The issuerAltName extension SHOULD NOT be marked critical. + + The OID and syntax for this CRL extension are defined in section + 4.2.1.8. + + + + + + + + +Housley, et. al. Standards Track [Page 54] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +5.2.3 CRL Number + + The CRL number is a non-critical CRL extension which conveys a + monotonically increasing sequence number for a given CRL scope and + CRL issuer. This extension allows users to easily determine when a + particular CRL supersedes another CRL. CRL numbers also support the + identification of complementary complete CRLs and delta CRLs. CRL + issuers conforming to this profile MUST include this extension in all + CRLs. + + If a CRL issuer generates delta CRLs in addition to complete CRLs for + a given scope, the complete CRLs and delta CRLs MUST share one + numbering sequence. If a delta CRL and a complete CRL that cover the + same scope are issued at the same time, they MUST have the same CRL + number and provide the same revocation information. That is, the + combination of the delta CRL and an acceptable complete CRL MUST + provide the same revocation information as the simultaneously issued + complete CRL. + + If a CRL issuer generates two CRLs (two complete CRLs, two delta + CRLs, or a complete CRL and a delta CRL) for the same scope at + different times, the two CRLs MUST NOT have the same CRL number. + That is, if the this update field (section 5.1.2.4) in the two CRLs + are not identical, the CRL numbers MUST be different. + + Given the requirements above, CRL numbers can be expected to contain + long integers. CRL verifiers MUST be able to handle CRLNumber values + up to 20 octets. Conformant CRL issuers MUST NOT use CRLNumber + values longer than 20 octets. + + id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 } + + CRLNumber ::= INTEGER (0..MAX) + +5.2.4 Delta CRL Indicator + + The delta CRL indicator is a critical CRL extension that identifies a + CRL as being a delta CRL. Delta CRLs contain updates to revocation + information previously distributed, rather than all the information + that would appear in a complete CRL. The use of delta CRLs can + significantly reduce network load and processing time in some + environments. Delta CRLs are generally smaller than the CRLs they + update, so applications that obtain delta CRLs consume less network + bandwidth than applications that obtain the corresponding complete + CRLs. Applications which store revocation information in a format + other than the CRL structure can add new revocation information to + the local database without reprocessing information. + + + + +Housley, et. al. Standards Track [Page 55] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + The delta CRL indicator extension contains the single value of type + BaseCRLNumber. The CRL number identifies the CRL, complete for a + given scope, that was used as the starting point in the generation of + this delta CRL. A conforming CRL issuer MUST publish the referenced + base CRL as a complete CRL. The delta CRL contains all updates to + the revocation status for that same scope. The combination of a + delta CRL plus the referenced base CRL is equivalent to a complete + CRL, for the applicable scope, at the time of publication of the + delta CRL. + + When a conforming CRL issuer generates a delta CRL, the delta CRL + MUST include a critical delta CRL indicator extension. + + When a delta CRL is issued, it MUST cover the same set of reasons and + the same set of certificates that were covered by the base CRL it + references. That is, the scope of the delta CRL MUST be the same as + the scope of the complete CRL referenced as the base. The referenced + base CRL and the delta CRL MUST omit the issuing distribution point + extension or contain identical issuing distribution point extensions. + Further, the CRL issuer MUST use the same private key to sign the + delta CRL and any complete CRL that it can be used to update. + + An application that supports delta CRLs can construct a CRL that is + complete for a given scope by combining a delta CRL for that scope + with either an issued CRL that is complete for that scope or a + locally constructed CRL that is complete for that scope. + + When a delta CRL is combined with a complete CRL or a locally + constructed CRL, the resulting locally constructed CRL has the CRL + number specified in the CRL number extension found in the delta CRL + used in its construction. In addition, the resulting locally + constructed CRL has the thisUpdate and nextUpdate times specified in + the corresponding fields of the delta CRL used in its construction. + In addition, the locally constructed CRL inherits the issuing + distribution point from the delta CRL. + + A complete CRL and a delta CRL MAY be combined if the following four + conditions are satisfied: + + (a) The complete CRL and delta CRL have the same issuer. + + (b) The complete CRL and delta CRL have the same scope. The two + CRLs have the same scope if either of the following conditions are + met: + + (1) The issuingDistributionPoint extension is omitted from + both the complete CRL and the delta CRL. + + + + +Housley, et. al. Standards Track [Page 56] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (2) The issuingDistributionPoint extension is present in both + the complete CRL and the delta CRL, and the values for each of + the fields in the extensions are the same in both CRLs. + + (c) The CRL number of the complete CRL is equal to or greater + than the BaseCRLNumber specified in the delta CRL. That is, the + complete CRL contains (at a minimum) all the revocation + information held by the referenced base CRL. + + (d) The CRL number of the complete CRL is less than the CRL + number of the delta CRL. That is, the delta CRL follows the + complete CRL in the numbering sequence. + + CRL issuers MUST ensure that the combination of a delta CRL and any + appropriate complete CRL accurately reflects the current revocation + status. The CRL issuer MUST include an entry in the delta CRL for + each certificate within the scope of the delta CRL whose status has + changed since the generation of the referenced base CRL: + + (a) If the certificate is revoked for a reason included in the + scope of the CRL, list the certificate as revoked. + + (b) If the certificate is valid and was listed on the referenced + base CRL or any subsequent CRL with reason code certificateHold, + and the reason code certificateHold is included in the scope of + the CRL, list the certificate with the reason code removeFromCRL. + + (c) If the certificate is revoked for a reason outside the scope + of the CRL, but the certificate was listed on the referenced base + CRL or any subsequent CRL with a reason code included in the scope + of this CRL, list the certificate as revoked but omit the reason + code. + + (d) If the certificate is revoked for a reason outside the scope + of the CRL and the certificate was neither listed on the + referenced base CRL nor any subsequent CRL with a reason code + included in the scope of this CRL, do not list the certificate on + this CRL. + + The status of a certificate is considered to have changed if it is + revoked, placed on hold, released from hold, or if its revocation + reason changes. + + It is appropriate to list a certificate with reason code + removeFromCRL on a delta CRL even if the certificate was not on hold + in the referenced base CRL. If the certificate was placed on hold in + + + + + +Housley, et. al. Standards Track [Page 57] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + any CRL issued after the base but before this delta CRL and then + released from hold, it MUST be listed on the delta CRL with + revocation reason removeFromCRL. + + A CRL issuer MAY optionally list a certificate on a delta CRL with + reason code removeFromCRL if the notAfter time specified in the + certificate precedes the thisUpdate time specified in the delta CRL + and the certificate was listed on the referenced base CRL or in any + CRL issued after the base but before this delta CRL. + + If a certificate revocation notice first appears on a delta CRL, then + it is possible for the certificate validity period to expire before + the next complete CRL for the same scope is issued. In this case, + the revocation notice MUST be included in all subsequent delta CRLs + until the revocation notice is included on at least one explicitly + issued complete CRL for this scope. + + An application that supports delta CRLs MUST be able to construct a + current complete CRL by combining a previously issued complete CRL + and the most current delta CRL. An application that supports delta + CRLs MAY also be able to construct a current complete CRL by + combining a previously locally constructed complete CRL and the + current delta CRL. A delta CRL is considered to be the current one + if the current time is between the times contained in the thisUpdate + and nextUpdate fields. Under some circumstances, the CRL issuer may + publish one or more delta CRLs before indicated by the nextUpdate + field. If more than one current delta CRL for a given scope is + encountered, the application SHOULD consider the one with the latest + value in thisUpdate to be the most current one. + + id-ce-deltaCRLIndicator OBJECT IDENTIFIER ::= { id-ce 27 } + + BaseCRLNumber ::= CRLNumber + +5.2.5 Issuing Distribution Point + + The issuing distribution point is a critical CRL extension that + identifies the CRL distribution point and scope for a particular CRL, + and it indicates whether the CRL covers revocation for end entity + certificates only, CA certificates only, attribute certificates only, + + or a limited set of reason codes. Although the extension is + critical, conforming implementations are not required to support this + extension. + + + + + + + +Housley, et. al. Standards Track [Page 58] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + The CRL is signed using the CRL issuer's private key. CRL + Distribution Points do not have their own key pairs. If the CRL is + stored in the X.500 Directory, it is stored in the Directory entry + corresponding to the CRL distribution point, which may be different + than the Directory entry of the CRL issuer. + + The reason codes associated with a distribution point MUST be + specified in onlySomeReasons. If onlySomeReasons does not appear, + the distribution point MUST contain revocations for all reason codes. + CAs may use CRL distribution points to partition the CRL on the basis + of compromise and routine revocation. In this case, the revocations + with reason code keyCompromise (1), cACompromise (2), and + aACompromise (8) appear in one distribution point, and the + revocations with other reason codes appear in another distribution + point. + + If the distributionPoint field is present and contains a URI, the + following semantics MUST be assumed: the object is a pointer to the + most current CRL issued by this CRL issuer. The URI schemes ftp, + http, mailto [RFC1738] and ldap [RFC1778] are defined for this + purpose. The URI MUST be an absolute pathname, not a relative + pathname, and MUST specify the host. + + If the distributionPoint field is absent, the CRL MUST contain + entries for all revoked unexpired certificates issued by the CRL + issuer, if any, within the scope of the CRL. + + The CRL issuer MUST assert the indirectCRL boolean, if the scope of + the CRL includes certificates issued by authorities other than the + CRL issuer. The authority responsible for each entry is indicated by + the certificate issuer CRL entry extension (section 5.3.4). + + id-ce-issuingDistributionPoint OBJECT IDENTIFIER ::= { id-ce 28 } + + issuingDistributionPoint ::= SEQUENCE { + distributionPoint [0] DistributionPointName OPTIONAL, + onlyContainsUserCerts [1] BOOLEAN DEFAULT FALSE, + onlyContainsCACerts [2] BOOLEAN DEFAULT FALSE, + onlySomeReasons [3] ReasonFlags OPTIONAL, + indirectCRL [4] BOOLEAN DEFAULT FALSE, + onlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE } + +5.2.6 Freshest CRL (a.k.a. Delta CRL Distribution Point) + + The freshest CRL extension identifies how delta CRL information for + this complete CRL is obtained. The extension MUST be non-critical. + This extension MUST NOT appear in delta CRLs. + + + + +Housley, et. al. Standards Track [Page 59] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + The same syntax is used for this extension as the + cRLDistributionPoints certificate extension, and is described in + section 4.2.1.14. However, only the distribution point field is + meaningful in this context. The reasons and CRLIssuer fields MUST be + omitted from this CRL extension. + + Each distribution point name provides the location at which a delta + CRL for this complete CRL can be found. The scope of these delta + CRLs MUST be the same as the scope of this complete CRL. The + contents of this CRL extension are only used to locate delta CRLs; + the contents are not used to validate the CRL or the referenced delta + CRLs. The encoding conventions defined for distribution points in + section 4.2.1.14 apply to this extension. + + id-ce-freshestCRL OBJECT IDENTIFIER ::= { id-ce 46 } + + FreshestCRL ::= CRLDistributionPoints + +5.3 CRL Entry Extensions + + The CRL entry extensions defined by ISO/IEC, ITU-T, and ANSI X9 for + X.509 v2 CRLs provide methods for associating additional attributes + with CRL entries [X.509] [X9.55]. The X.509 v2 CRL format also + allows communities to define private CRL entry extensions to carry + information unique to those communities. Each extension in a CRL + entry may be designated as critical or non-critical. A CRL + validation MUST fail if it encounters a critical CRL entry extension + which it does not know how to process. However, an unrecognized non- + critical CRL entry extension may be ignored. The following + subsections present recommended extensions used within Internet CRL + entries and standard locations for information. Communities may + elect to use additional CRL entry extensions; however, caution should + be exercised in adopting any critical extensions in CRL entries which + might be used in a general context. + + All CRL entry extensions used in this specification are non-critical. + Support for these extensions is optional for conforming CRL issuers + and applications. However, CRL issuers SHOULD include reason codes + (section 5.3.1) and invalidity dates (section 5.3.3) whenever this + information is available. + +5.3.1 Reason Code + + The reasonCode is a non-critical CRL entry extension that identifies + the reason for the certificate revocation. CRL issuers are strongly + encouraged to include meaningful reason codes in CRL entries; + however, the reason code CRL entry extension SHOULD be absent instead + of using the unspecified (0) reasonCode value. + + + +Housley, et. al. Standards Track [Page 60] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + id-ce-cRLReason OBJECT IDENTIFIER ::= { id-ce 21 } + + -- reasonCode ::= { CRLReason } + + CRLReason ::= ENUMERATED { + unspecified (0), + keyCompromise (1), + cACompromise (2), + affiliationChanged (3), + superseded (4), + cessationOfOperation (5), + certificateHold (6), + removeFromCRL (8), + privilegeWithdrawn (9), + aACompromise (10) } + +5.3.2 Hold Instruction Code + + The hold instruction code is a non-critical CRL entry extension that + provides a registered instruction identifier which indicates the + action to be taken after encountering a certificate that has been + placed on hold. + + id-ce-holdInstructionCode OBJECT IDENTIFIER ::= { id-ce 23 } + + holdInstructionCode ::= OBJECT IDENTIFIER + + The following instruction codes have been defined. Conforming + applications that process this extension MUST recognize the following + instruction codes. + + holdInstruction OBJECT IDENTIFIER ::= + { iso(1) member-body(2) us(840) x9-57(10040) 2 } + + id-holdinstruction-none OBJECT IDENTIFIER ::= {holdInstruction 1} + id-holdinstruction-callissuer + OBJECT IDENTIFIER ::= {holdInstruction 2} + id-holdinstruction-reject OBJECT IDENTIFIER ::= {holdInstruction 3} + + Conforming applications which encounter an id-holdinstruction- + callissuer MUST call the certificate issuer or reject the + certificate. Conforming applications which encounter an id- + holdinstruction-reject MUST reject the certificate. The hold + instruction id-holdinstruction-none is semantically equivalent to the + absence of a holdInstructionCode, and its use is strongly deprecated + for the Internet PKI. + + + + + +Housley, et. al. Standards Track [Page 61] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +5.3.3 Invalidity Date + + The invalidity date is a non-critical CRL entry extension that + provides the date on which it is known or suspected that the private + key was compromised or that the certificate otherwise became invalid. + This date may be earlier than the revocation date in the CRL entry, + which is the date at which the CA processed the revocation. When a + revocation is first posted by a CRL issuer in a CRL, the invalidity + date may precede the date of issue of earlier CRLs, but the + revocation date SHOULD NOT precede the date of issue of earlier CRLs. + Whenever this information is available, CRL issuers are strongly + encouraged to share it with CRL users. + + The GeneralizedTime values included in this field MUST be expressed + in Greenwich Mean Time (Zulu), and MUST be specified and interpreted + as defined in section 4.1.2.5.2. + + id-ce-invalidityDate OBJECT IDENTIFIER ::= { id-ce 24 } + + invalidityDate ::= GeneralizedTime + +5.3.4 Certificate Issuer + + This CRL entry extension identifies the certificate issuer associated + with an entry in an indirect CRL, that is, a CRL that has the + indirectCRL indicator set in its issuing distribution point + extension. If this extension is not present on the first entry in an + indirect CRL, the certificate issuer defaults to the CRL issuer. On + subsequent entries in an indirect CRL, if this extension is not + present, the certificate issuer for the entry is the same as that for + the preceding entry. This field is defined as follows: + + id-ce-certificateIssuer OBJECT IDENTIFIER ::= { id-ce 29 } + + certificateIssuer ::= GeneralNames + + If used by conforming CRL issuers, this extension MUST always be + critical. If an implementation ignored this extension it could not + correctly attribute CRL entries to certificates. This specification + RECOMMENDS that implementations recognize this extension. + +6 Certification Path Validation + + Certification path validation procedures for the Internet PKI are + based on the algorithm supplied in [X.509]. Certification path + processing verifies the binding between the subject distinguished + name and/or subject alternative name and subject public key. The + binding is limited by constraints which are specified in the + + + +Housley, et. al. Standards Track [Page 62] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + certificates which comprise the path and inputs which are specified + by the relying party. The basic constraints and policy constraints + extensions allow the certification path processing logic to automate + the decision making process. + + This section describes an algorithm for validating certification + paths. Conforming implementations of this specification are not + required to implement this algorithm, but MUST provide functionality + equivalent to the external behavior resulting from this procedure. + Any algorithm may be used by a particular implementation so long as + it derives the correct result. + + In section 6.1, the text describes basic path validation. Valid + paths begin with certificates issued by a trust anchor. The + algorithm requires the public key of the CA, the CA's name, and any + constraints upon the set of paths which may be validated using this + key. + + The selection of a trust anchor is a matter of policy: it could be + the top CA in a hierarchical PKI; the CA that issued the verifier's + own certificate(s); or any other CA in a network PKI. The path + validation procedure is the same regardless of the choice of trust + anchor. In addition, different applications may rely on different + trust anchor, or may accept paths that begin with any of a set of + trust anchor. + + Section 6.2 describes methods for using the path validation algorithm + in specific implementations. Two specific cases are discussed: the + case where paths may begin with one of several trusted CAs; and where + compatibility with the PEM architecture is required. + + Section 6.3 describes the steps necessary to determine if a + certificate is revoked or on hold status when CRLs are the revocation + mechanism used by the certificate issuer. + +6.1 Basic Path Validation + + This text describes an algorithm for X.509 path processing. A + conformant implementation MUST include an X.509 path processing + procedure that is functionally equivalent to the external behavior of + this algorithm. However, support for some of the certificate + extensions processed in this algorithm are OPTIONAL for compliant + implementations. Clients that do not support these extensions MAY + omit the corresponding steps in the path validation algorithm. + + + + + + + +Housley, et. al. Standards Track [Page 63] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + For example, clients are NOT REQUIRED to support the policy mapping + extension. Clients that do not support this extension MAY omit the + path validation steps where policy mappings are processed. Note that + clients MUST reject the certificate if it contains an unsupported + critical extension. + + The algorithm presented in this section validates the certificate + with respect to the current date and time. A conformant + implementation MAY also support validation with respect to some point + in the past. Note that mechanisms are not available for validating a + certificate with respect to a time outside the certificate validity + period. + + The trust anchor is an input to the algorithm. There is no + requirement that the same trust anchor be used to validate all + certification paths. Different trust anchors MAY be used to validate + different paths, as discussed further in Section 6.2. + + The primary goal of path validation is to verify the binding between + a subject distinguished name or a subject alternative name and + subject public key, as represented in the end entity certificate, + based on the public key of the trust anchor. This requires obtaining + a sequence of certificates that support that binding. The procedure + performed to obtain this sequence of certificates is outside the + scope of this specification. + + To meet this goal, the path validation process verifies, among other + things, that a prospective certification path (a sequence of n + certificates) satisfies the following conditions: + + (a) for all x in {1, ..., n-1}, the subject of certificate x is + the issuer of certificate x+1; + + (b) certificate 1 is issued by the trust anchor; + + (c) certificate n is the certificate to be validated; and + + (d) for all x in {1, ..., n}, the certificate was valid at the + time in question. + + When the trust anchor is provided in the form of a self-signed + certificate, this self-signed certificate is not included as part of + the prospective certification path. Information about trust anchors + are provided as inputs to the certification path validation algorithm + (section 6.1.1). + + + + + + +Housley, et. al. Standards Track [Page 64] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + A particular certification path may not, however, be appropriate for + all applications. Therefore, an application MAY augment this + algorithm to further limit the set of valid paths. The path + validation process also determines the set of certificate policies + that are valid for this path, based on the certificate policies + extension, policy mapping extension, policy constraints extension, + and inhibit any-policy extension. To achieve this, the path + validation algorithm constructs a valid policy tree. If the set of + certificate policies that are valid for this path is not empty, then + the result will be a valid policy tree of depth n, otherwise the + result will be a null valid policy tree. + + A certificate is self-issued if the DNs that appear in the subject + and issuer fields are identical and are not empty. In general, the + issuer and subject of the certificates that make up a path are + different for each certificate. However, a CA may issue a + certificate to itself to support key rollover or changes in + certificate policies. These self-issued certificates are not counted + when evaluating path length or name constraints. + + This section presents the algorithm in four basic steps: (1) + initialization, (2) basic certificate processing, (3) preparation for + the next certificate, and (4) wrap-up. Steps (1) and (4) are + performed exactly once. Step (2) is performed for all certificates + in the path. Step (3) is performed for all certificates in the path + except the final certificate. Figure 2 provides a high-level + flowchart of this algorithm. + + + + + + + + + + + + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 65] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + +-------+ + | START | + +-------+ + | + V + +----------------+ + | Initialization | + +----------------+ + | + +<--------------------+ + | | + V | + +----------------+ | + | Process Cert | | + +----------------+ | + | | + V | + +================+ | + | IF Last Cert | | + | in Path | | + +================+ | + | | | + THEN | | ELSE | + V V | + +----------------+ +----------------+ | + | Wrap up | | Prepare for | | + +----------------+ | Next Cert | | + | +----------------+ | + V | | + +-------+ +--------------+ + | STOP | + +-------+ + + + Figure 2. Certification Path Processing Flowchart + +6.1.1 Inputs + + This algorithm assumes the following seven inputs are provided to the + path processing logic: + + (a) a prospective certification path of length n. + + (b) the current date/time. + + + + + + + +Housley, et. al. Standards Track [Page 66] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (c) user-initial-policy-set: A set of certificate policy + identifiers naming the policies that are acceptable to the + certificate user. The user-initial-policy-set contains the + special value any-policy if the user is not concerned about + certificate policy. + + (d) trust anchor information, describing a CA that serves as a + trust anchor for the certification path. The trust anchor + information includes: + + (1) the trusted issuer name, + + (2) the trusted public key algorithm, + + (3) the trusted public key, and + + (4) optionally, the trusted public key parameters associated + with the public key. + + The trust anchor information may be provided to the path + processing procedure in the form of a self-signed certificate. + The trusted anchor information is trusted because it was delivered + to the path processing procedure by some trustworthy out-of-band + procedure. If the trusted public key algorithm requires + parameters, then the parameters are provided along with the + trusted public key. + + (e) initial-policy-mapping-inhibit, which indicates if policy + mapping is allowed in the certification path. + + (f) initial-explicit-policy, which indicates if the path must be + valid for at least one of the certificate policies in the user- + initial-policy-set. + + (g) initial-any-policy-inhibit, which indicates whether the + anyPolicy OID should be processed if it is included in a + certificate. + +6.1.2 Initialization + + This initialization phase establishes eleven state variables based + upon the seven inputs: + + (a) valid_policy_tree: A tree of certificate policies with their + optional qualifiers; each of the leaves of the tree represents a + valid policy at this stage in the certification path validation. + If valid policies exist at this stage in the certification path + validation, the depth of the tree is equal to the number of + + + +Housley, et. al. Standards Track [Page 67] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + certificates in the chain that have been processed. If valid + policies do not exist at this stage in the certification path + validation, the tree is set to NULL. Once the tree is set to + NULL, policy processing ceases. + + Each node in the valid_policy_tree includes four data objects: the + valid policy, a set of associated policy qualifiers, a set of one + or more expected policy values, and a criticality indicator. If + the node is at depth x, the components of the node have the + following semantics: + + (1) The valid_policy is a single policy OID representing a + valid policy for the path of length x. + + (2) The qualifier_set is a set of policy qualifiers associated + with the valid policy in certificate x. + + (3) The criticality_indicator indicates whether the + certificate policy extension in certificate x was marked as + critical. + + (4) The expected_policy_set contains one or more policy OIDs + that would satisfy this policy in the certificate x+1. + + The initial value of the valid_policy_tree is a single node with + valid_policy anyPolicy, an empty qualifier_set, an + expected_policy_set with the single value anyPolicy, and a + criticality_indicator of FALSE. This node is considered to be at + depth zero. + + Figure 3 is a graphic representation of the initial state of the + valid_policy_tree. Additional figures will use this format to + describe changes in the valid_policy_tree during path processing. + + +----------------+ + | anyPolicy | <---- valid_policy + +----------------+ + | {} | <---- qualifier_set + +----------------+ + | FALSE | <---- criticality_indicator + +----------------+ + | {anyPolicy} | <---- expected_policy_set + +----------------+ + + Figure 3. Initial value of the valid_policy_tree state variable + + + + + + +Housley, et. al. Standards Track [Page 68] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (b) permitted_subtrees: A set of root names for each name type + (e.g., X.500 distinguished names, email addresses, or ip + addresses) defining a set of subtrees within which all subject + names in subsequent certificates in the certification path MUST + fall. This variable includes a set for each name type: the + initial value for the set for Distinguished Names is the set of + all Distinguished names; the initial value for the set of RFC822 + names is the set of all RFC822 names, etc. + + (c) excluded_subtrees: A set of root names for each name type + (e.g., X.500 distinguished names, email addresses, or ip + addresses) defining a set of subtrees within which no subject name + in subsequent certificates in the certification path may fall. + This variable includes a set for each name type, and the initial + value for each set is empty. + + (d) explicit_policy: an integer which indicates if a non-NULL + valid_policy_tree is required. The integer indicates the number of + non-self-issued certificates to be processed before this + requirement is imposed. Once set, this variable may be decreased, + but may not be increased. That is, if a certificate in the path + requires a non-NULL valid_policy_tree, a later certificate can not + remove this requirement. If initial-explicit-policy is set, then + the initial value is 0, otherwise the initial value is n+1. + + (e) inhibit_any-policy: an integer which indicates whether the + anyPolicy policy identifier is considered a match. The integer + indicates the number of non-self-issued certificates to be + processed before the anyPolicy OID, if asserted in a certificate, + is ignored. Once set, this variable may be decreased, but may not + be increased. That is, if a certificate in the path inhibits + processing of anyPolicy, a later certificate can not permit it. + If initial-any-policy-inhibit is set, then the initial value is 0, + otherwise the initial value is n+1. + + (f) policy_mapping: an integer which indicates if policy mapping + is permitted. The integer indicates the number of non-self-issued + certificates to be processed before policy mapping is inhibited. + Once set, this variable may be decreased, but may not be + increased. That is, if a certificate in the path specifies policy + mapping is not permitted, it can not be overridden by a later + certificate. If initial-policy-mapping-inhibit is set, then the + initial value is 0, otherwise the initial value is n+1. + + (g) working_public_key_algorithm: the digital signature algorithm + used to verify the signature of a certificate. The + working_public_key_algorithm is initialized from the trusted + public key algorithm provided in the trust anchor information. + + + +Housley, et. al. Standards Track [Page 69] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (h) working_public_key: the public key used to verify the + signature of a certificate. The working_public_key is initialized + from the trusted public key provided in the trust anchor + information. + + (i) working_public_key_parameters: parameters associated with the + current public key, that may be required to verify a signature + (depending upon the algorithm). The working_public_key_parameters + variable is initialized from the trusted public key parameters + provided in the trust anchor information. + + (j) working_issuer_name: the issuer distinguished name expected + in the next certificate in the chain. The working_issuer_name is + initialized to the trusted issuer provided in the trust anchor + information. + + (k) max_path_length: this integer is initialized to n, is + decremented for each non-self-issued certificate in the path, and + may be reduced to the value in the path length constraint field + within the basic constraints extension of a CA certificate. + + Upon completion of the initialization steps, perform the basic + certificate processing steps specified in 6.1.3. + +6.1.3 Basic Certificate Processing + + The basic path processing actions to be performed for certificate i + (for all i in [1..n]) are listed below. + + (a) Verify the basic certificate information. The certificate + MUST satisfy each of the following: + + (1) The certificate was signed with the + working_public_key_algorithm using the working_public_key and + the working_public_key_parameters. + + (2) The certificate validity period includes the current time. + + (3) At the current time, the certificate is not revoked and is + not on hold status. This may be determined by obtaining the + appropriate CRL (section 6.3), status information, or by out- + of-band mechanisms. + + (4) The certificate issuer name is the working_issuer_name. + + + + + + + +Housley, et. al. Standards Track [Page 70] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (b) If certificate i is self-issued and it is not the final + certificate in the path, skip this step for certificate i. + Otherwise, verify that the subject name is within one of the + permitted_subtrees for X.500 distinguished names, and verify that + each of the alternative names in the subjectAltName extension + (critical or non-critical) is within one of the permitted_subtrees + for that name type. + + (c) If certificate i is self-issued and it is not the final + certificate in the path, skip this step for certificate i. + Otherwise, verify that the subject name is not within one of the + excluded_subtrees for X.500 distinguished names, and verify that + each of the alternative names in the subjectAltName extension + (critical or non-critical) is not within one of the + excluded_subtrees for that name type. + + (d) If the certificate policies extension is present in the + certificate and the valid_policy_tree is not NULL, process the + policy information by performing the following steps in order: + + (1) For each policy P not equal to anyPolicy in the + certificate policies extension, let P-OID denote the OID in + policy P and P-Q denote the qualifier set for policy P. + Perform the following steps in order: + + (i) If the valid_policy_tree includes a node of depth i-1 + where P-OID is in the expected_policy_set, create a child + node as follows: set the valid_policy to OID-P; set the + qualifier_set to P-Q, and set the expected_policy_set to + {P-OID}. + + For example, consider a valid_policy_tree with a node of + depth i-1 where the expected_policy_set is {Gold, White}. + Assume the certificate policies Gold and Silver appear in + the certificate policies extension of certificate i. The + Gold policy is matched but the Silver policy is not. This + rule will generate a child node of depth i for the Gold + policy. The result is shown as Figure 4. + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 71] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + +-----------------+ + | Red | + +-----------------+ + | {} | + +-----------------+ node of depth i-1 + | FALSE | + +-----------------+ + | {Gold, White} | + +-----------------+ + | + | + | + V + +-----------------+ + | Gold | + +-----------------+ + | {} | + +-----------------+ node of depth i + | uninitialized | + +-----------------+ + | {Gold} | + +-----------------+ + + Figure 4. Processing an exact match + + (ii) If there was no match in step (i) and the + valid_policy_tree includes a node of depth i-1 with the + valid policy anyPolicy, generate a child node with the + following values: set the valid_policy to P-OID; set the + qualifier_set to P-Q, and set the expected_policy_set to + {P-OID}. + + For example, consider a valid_policy_tree with a node of + depth i-1 where the valid_policy is anyPolicy. Assume the + certificate policies Gold and Silver appear in the + certificate policies extension of certificate i. The Gold + policy does not have a qualifier, but the Silver policy has + the qualifier Q-Silver. If Gold and Silver were not matched + in (i) above, this rule will generate two child nodes of + depth i, one for each policy. The result is shown as Figure + 5. + + + + + + + + + + +Housley, et. al. Standards Track [Page 72] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + +-----------------+ + | anyPolicy | + +-----------------+ + | {} | + +-----------------+ node of depth i-1 + | FALSE | + +-----------------+ + | {anyPolicy} | + +-----------------+ + / \ + / \ + / \ + / \ + +-----------------+ +-----------------+ + | Gold | | Silver | + +-----------------+ +-----------------+ + | {} | | {Q-Silver} | + +-----------------+ nodes of +-----------------+ + | uninitialized | depth i | uninitialized | + +-----------------+ +-----------------+ + | {Gold} | | {Silver} | + +-----------------+ +-----------------+ + + Figure 5. Processing unmatched policies when a leaf node + specifies anyPolicy + + (2) If the certificate policies extension includes the policy + anyPolicy with the qualifier set AP-Q and either (a) + inhibit_any-policy is greater than 0 or (b) i. The + binaries for the certificates and CRLs are available at + . + +C.1 Certificate + + This section contains an annotated hex dump of a 699 byte version 3 + certificate. The certificate contains the following information: + (a) the serial number is 23 (17 hex); + + + +Housley, et. al. Standards Track [Page 115] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (b) the certificate is signed with DSA and the SHA-1 hash algorithm; + (c) the issuer's distinguished name is OU=NIST; O=gov; C=US + (d) and the subject's distinguished name is OU=NIST; O=gov; C=US + (e) the certificate was issued on June 30, 1997 and will expire on + December 31, 1997; + (f) the certificate contains a 1024 bit DSA public key with + parameters; + (g) the certificate contains a subject key identifier extension + generated using method (1) of section 4.2.1.2; and + (h) the certificate is a CA certificate (as indicated through the + basic constraints extension.) + + 0 30 699: SEQUENCE { + 4 30 635: SEQUENCE { + 8 A0 3: [0] { + 10 02 1: INTEGER 2 + : } + 13 02 1: INTEGER 17 + 16 30 9: SEQUENCE { + 18 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } + 27 30 42: SEQUENCE { + 29 31 11: SET { + 31 30 9: SEQUENCE { + 33 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) + 38 13 2: PrintableString 'US' + : } + : } + 42 31 12: SET { + 44 30 10: SEQUENCE { + 46 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) + 51 13 3: PrintableString 'gov' + : } + : } + 56 31 13: SET { + 58 30 11: SEQUENCE { + 60 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) + 65 13 4: PrintableString 'NIST' + : } + : } + : } + 71 30 30: SEQUENCE { + 73 17 13: UTCTime '970630000000Z' + 88 17 13: UTCTime '971231000000Z' + : } +103 30 42: SEQUENCE { +105 31 11: SET { + + + +Housley, et. al. Standards Track [Page 116] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +107 30 9: SEQUENCE { +109 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) +114 13 2: PrintableString 'US' + : } + : } +118 31 12: SET { +120 30 10: SEQUENCE { +122 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) +127 13 3: PrintableString 'gov' + : } + : } +132 31 13: SET { +134 30 11: SEQUENCE { +136 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) +141 13 4: PrintableString 'NIST' + : } + : } + : } +147 30 440: SEQUENCE { +151 30 300: SEQUENCE { +155 06 7: OBJECT IDENTIFIER dsa (1 2 840 10040 4 1) +164 30 287: SEQUENCE { +168 02 129: INTEGER + : 00 B6 8B 0F 94 2B 9A CE A5 25 C6 F2 ED FC + : FB 95 32 AC 01 12 33 B9 E0 1C AD 90 9B BC + : 48 54 9E F3 94 77 3C 2C 71 35 55 E6 FE 4F + : 22 CB D5 D8 3E 89 93 33 4D FC BD 4F 41 64 + : 3E A2 98 70 EC 31 B4 50 DE EB F1 98 28 0A + : C9 3E 44 B3 FD 22 97 96 83 D0 18 A3 E3 BD + : 35 5B FF EE A3 21 72 6A 7B 96 DA B9 3F 1E + : 5A 90 AF 24 D6 20 F0 0D 21 A7 D4 02 B9 1A + : FC AC 21 FB 9E 94 9E 4B 42 45 9E 6A B2 48 + : 63 FE 43 +300 02 21: INTEGER + : 00 B2 0D B0 B1 01 DF 0C 66 24 FC 13 92 BA + : 55 F7 7D 57 74 81 E5 +323 02 129: INTEGER + : 00 9A BF 46 B1 F5 3F 44 3D C9 A5 65 FB 91 + : C0 8E 47 F1 0A C3 01 47 C2 44 42 36 A9 92 + : 81 DE 57 C5 E0 68 86 58 00 7B 1F F9 9B 77 + : A1 C5 10 A5 80 91 78 51 51 3C F6 FC FC CC + : 46 C6 81 78 92 84 3D F4 93 3D 0C 38 7E 1A + : 5B 99 4E AB 14 64 F6 0C 21 22 4E 28 08 9C + : 92 B9 66 9F 40 E8 95 F6 D5 31 2A EF 39 A2 + : 62 C7 B2 6D 9E 58 C4 3A A8 11 81 84 6D AF + : F8 B4 19 B4 C2 11 AE D0 22 3B AA 20 7F EE + : 1E 57 18 + + + +Housley, et. al. Standards Track [Page 117] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + : } + : } +455 03 133: BIT STRING 0 unused bits, encapsulates { +459 02 129: INTEGER + : 00 B5 9E 1F 49 04 47 D1 DB F5 3A DD CA 04 + : 75 E8 DD 75 F6 9B 8A B1 97 D6 59 69 82 D3 + : 03 4D FD 3B 36 5F 4A F2 D1 4E C1 07 F5 D1 + : 2A D3 78 77 63 56 EA 96 61 4D 42 0B 7A 1D + : FB AB 91 A4 CE DE EF 77 C8 E5 EF 20 AE A6 + : 28 48 AF BE 69 C3 6A A5 30 F2 C2 B9 D9 82 + : 2B 7D D9 C4 84 1F DE 0D E8 54 D7 1B 99 2E + : B3 D0 88 F6 D6 63 9B A7 E2 0E 82 D4 3B 8A + : 68 1B 06 56 31 59 0B 49 EB 99 A5 D5 81 41 + : 7B C9 55 + : } + : } +591 A3 50: [3] { +593 30 48: SEQUENCE { +595 30 29: SEQUENCE { +597 06 3: OBJECT IDENTIFIER + : subjectKeyIdentifier (2 5 29 14) +602 04 22: OCTET STRING, encapsulates { +604 04 20: OCTET STRING + : 86 CA A5 22 81 62 EF AD 0A 89 BC AD 72 41 + : 2C 29 49 F4 86 56 + : } + : } +626 30 15: SEQUENCE { +628 06 3: OBJECT IDENTIFIER basicConstraints (2 5 29 19) +633 01 1: BOOLEAN TRUE +636 04 5: OCTET STRING, encapsulates { +638 30 3: SEQUENCE { +640 01 1: BOOLEAN TRUE + : } + : } + : } + : } + : } + : } +643 30 9: SEQUENCE { +645 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } +654 03 47: BIT STRING 0 unused bits, encapsulates { +657 30 44: SEQUENCE { +659 02 20: INTEGER + : 43 1B CF 29 25 45 C0 4E 52 E7 7D D6 FC B1 + : 66 4C 83 CF 2D 77 +681 02 20: INTEGER + + + +Housley, et. al. Standards Track [Page 118] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + : 0B 5B 9A 24 11 98 E8 F3 86 90 04 F6 08 A9 + : E1 8D A5 CC 3A D4 + : } + : } + : } + +C.2 Certificate + + This section contains an annotated hex dump of a 730 byte version 3 + certificate. The certificate contains the following information: + (a) the serial number is 18 (12 hex); + (b) the certificate is signed with DSA and the SHA-1 hash algorithm; + (c) the issuer's distinguished name is OU=nist; O=gov; C=US + (d) and the subject's distinguished name is CN=Tim Polk; OU=nist; + O=gov; C=US + (e) the certificate was valid from July 30, 1997 through December 1, + 1997; + (f) the certificate contains a 1024 bit DSA public key; + (g) the certificate is an end entity certificate, as the basic + constraints extension is not present; + (h) the certificate contains an authority key identifier extension + matching the subject key identifier of the certificate in Appendix + C.1; and + (i) the certificate includes one alternative name - an RFC 822 + address of "wpolk@nist.gov". + + 0 30 730: SEQUENCE { + 4 30 665: SEQUENCE { + 8 A0 3: [0] { + 10 02 1: INTEGER 2 + : } + 13 02 1: INTEGER 18 + 16 30 9: SEQUENCE { + 18 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } + 27 30 42: SEQUENCE { + 29 31 11: SET { + 31 30 9: SEQUENCE { + 33 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) + 38 13 2: PrintableString 'US' + : } + : } + 42 31 12: SET { + 44 30 10: SEQUENCE { + 46 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) + 51 13 3: PrintableString 'gov' + : } + : } + + + +Housley, et. al. Standards Track [Page 119] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + 56 31 13: SET { + 58 30 11: SEQUENCE { + 60 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) + 65 13 4: PrintableString 'NIST' + : } + : } + : } + 71 30 30: SEQUENCE { + 73 17 13: UTCTime '970730000000Z' + 88 17 13: UTCTime '971201000000Z' + : } + 103 30 61: SEQUENCE { + 105 31 11: SET { + 107 30 9: SEQUENCE { + 109 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) + 114 13 2: PrintableString 'US' + : } + : } + 118 31 12: SET { + 120 30 10: SEQUENCE { + 122 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) + 127 13 3: PrintableString 'gov' + : } + : } + 132 31 13: SET { + 134 30 11: SEQUENCE { + 136 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) + 141 13 4: PrintableString 'NIST' + : } + : } + 147 31 17: SET { + 149 30 15: SEQUENCE { + 151 06 3: OBJECT IDENTIFIER commonName (2 5 4 3) + 156 13 8: PrintableString 'Tim Polk' + : } + : } + : } + 166 30 439: SEQUENCE { + 170 30 300: SEQUENCE { + 174 06 7: OBJECT IDENTIFIER dsa (1 2 840 10040 4 1) + 183 30 287: SEQUENCE { + 187 02 129: INTEGER + : 00 B6 8B 0F 94 2B 9A CE A5 25 C6 F2 ED FC + : FB 95 32 AC 01 12 33 B9 E0 1C AD 90 9B BC + : 48 54 9E F3 94 77 3C 2C 71 35 55 E6 FE 4F + : 22 CB D5 D8 3E 89 93 33 4D FC BD 4F 41 64 + + + +Housley, et. al. Standards Track [Page 120] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + : 3E A2 98 70 EC 31 B4 50 DE EB F1 98 28 0A + : C9 3E 44 B3 FD 22 97 96 83 D0 18 A3 E3 BD + : 35 5B FF EE A3 21 72 6A 7B 96 DA B9 3F 1E + : 5A 90 AF 24 D6 20 F0 0D 21 A7 D4 02 B9 1A + : FC AC 21 FB 9E 94 9E 4B 42 45 9E 6A B2 48 + : 63 FE 43 + 319 02 21: INTEGER + : 00 B2 0D B0 B1 01 DF 0C 66 24 FC 13 92 BA + : 55 F7 7D 57 74 81 E5 + 342 02 129: INTEGER + : 00 9A BF 46 B1 F5 3F 44 3D C9 A5 65 FB 91 + : C0 8E 47 F1 0A C3 01 47 C2 44 42 36 A9 92 + : 81 DE 57 C5 E0 68 86 58 00 7B 1F F9 9B 77 + : A1 C5 10 A5 80 91 78 51 51 3C F6 FC FC CC + : 46 C6 81 78 92 84 3D F4 93 3D 0C 38 7E 1A + : 5B 99 4E AB 14 64 F6 0C 21 22 4E 28 08 9C + : 92 B9 66 9F 40 E8 95 F6 D5 31 2A EF 39 A2 + : 62 C7 B2 6D 9E 58 C4 3A A8 11 81 84 6D AF + : F8 B4 19 B4 C2 11 AE D0 22 3B AA 20 7F EE + : 1E 57 18 + : } + : } + 474 03 132: BIT STRING 0 unused bits, encapsulates { + 478 02 128: INTEGER + : 30 B6 75 F7 7C 20 31 AE 38 BB 7E 0D 2B AB + : A0 9C 4B DF 20 D5 24 13 3C CD 98 E5 5F 6C + : B7 C1 BA 4A BA A9 95 80 53 F0 0D 72 DC 33 + : 37 F4 01 0B F5 04 1F 9D 2E 1F 62 D8 84 3A + : 9B 25 09 5A 2D C8 46 8E 2B D4 F5 0D 3B C7 + : 2D C6 6C B9 98 C1 25 3A 44 4E 8E CA 95 61 + : 35 7C CE 15 31 5C 23 13 1E A2 05 D1 7A 24 + : 1C CB D3 72 09 90 FF 9B 9D 28 C0 A1 0A EC + : 46 9F 0D B8 D0 DC D0 18 A6 2B 5E F9 8F B5 + : 95 BE + : } + : } + 609 A3 62: [3] { + 611 30 60: SEQUENCE { + 613 30 25: SEQUENCE { + 615 06 3: OBJECT IDENTIFIER subjectAltName (2 5 29 17) + 620 04 18: OCTET STRING, encapsulates { + 622 30 16: SEQUENCE { + 624 81 14: [1] 'wpolk@nist.gov' + : } + : } + : } + 640 30 31: SEQUENCE { + 642 06 3: OBJECT IDENTIFIER + + + +Housley, et. al. Standards Track [Page 121] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + : authorityKeyIdentifier (2 5 29 35) + 647 04 24: OCTET STRING, encapsulates { + 649 30 22: SEQUENCE { + 651 80 20: [0] + : 86 CA A5 22 81 62 EF AD 0A 89 BC AD 72 + : 41 2C 29 49 F4 86 56 + : } + : } + : } + : } + : } + : } + 673 30 9: SEQUENCE { + 675 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } + 684 03 48: BIT STRING 0 unused bits, encapsulates { + 687 30 45: SEQUENCE { + 689 02 20: INTEGER + : 36 97 CB E3 B4 2C E1 BB 61 A9 D3 CC 24 CC + : 22 92 9F F4 F5 87 + 711 02 21: INTEGER + : 00 AB C9 79 AF D2 16 1C A9 E3 68 A9 14 10 + : B4 A0 2E FF 22 5A 73 + : } + : } + : } + +C.3 End Entity Certificate Using RSA + + This section contains an annotated hex dump of a 654 byte version 3 + certificate. The certificate contains the following information: + (a) the serial number is 256; + (b) the certificate is signed with RSA and the SHA-1 hash algorithm; + (c) the issuer's distinguished name is OU=NIST; O=gov; C=US + (d) and the subject's distinguished name is CN=Tim Polk; OU=NIST; + O=gov; C=US + (e) the certificate was issued on May 21, 1996 at 09:58:26 and + expired on May 21, 1997 at 09:58:26; + (f) the certificate contains a 1024 bit RSA public key; + (g) the certificate is an end entity certificate (not a CA + certificate); + (h) the certificate includes an alternative subject name of + "" and an + alternative issuer name of "" - both are URLs; + (i) the certificate include an authority key identifier extension + and a certificate policies extension specifying the policy OID + 2.16.840.1.101.3.2.1.48.9; and + + + + +Housley, et. al. Standards Track [Page 122] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + (j) the certificate includes a critical key usage extension + specifying that the public key is intended for verification of + digital signatures. + + 0 30 654: SEQUENCE { + 4 30 503: SEQUENCE { + 8 A0 3: [0] { + 10 02 1: INTEGER 2 + : } + 13 02 2: INTEGER 256 + 17 30 13: SEQUENCE { + 19 06 9: OBJECT IDENTIFIER + : sha1withRSAEncryption (1 2 840 113549 1 1 5) + 30 05 0: NULL + : } + 32 30 42: SEQUENCE { + 34 31 11: SET { + 36 30 9: SEQUENCE { + 38 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) + 43 13 2: PrintableString 'US' + : } + : } + 47 31 12: SET { + 49 30 10: SEQUENCE { + 51 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) + 56 13 3: PrintableString 'gov' + : } + : } + 61 31 13: SET { + 63 30 11: SEQUENCE { + 65 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) + 70 13 4: PrintableString 'NIST' + : } + : } + : } + 76 30 30: SEQUENCE { + 78 17 13: UTCTime '960521095826Z' + 93 17 13: UTCTime '970521095826Z' + : } +108 30 61: SEQUENCE { +110 31 11: SET { +112 30 9: SEQUENCE { +114 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) +119 13 2: PrintableString 'US' + : } + : } +123 31 12: SET { + + + +Housley, et. al. Standards Track [Page 123] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +125 30 10: SEQUENCE { +127 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) +132 13 3: PrintableString 'gov' + : } + : } +137 31 13: SET { +139 30 11: SEQUENCE { +141 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) +146 13 4: PrintableString 'NIST' + : } + : } +152 31 17: SET { +154 30 15: SEQUENCE { +156 06 3: OBJECT IDENTIFIER commonName (2 5 4 3) +161 13 8: PrintableString 'Tim Polk' + : } + : } + : } +171 30 159: SEQUENCE { +174 30 13: SEQUENCE { +176 06 9: OBJECT IDENTIFIER + : rsaEncryption (1 2 840 113549 1 1 1) +187 05 0: NULL + : } +189 03 141: BIT STRING 0 unused bits, encapsulates { +193 30 137: SEQUENCE { +196 02 129: INTEGER + : 00 E1 6A E4 03 30 97 02 3C F4 10 F3 B5 1E + : 4D 7F 14 7B F6 F5 D0 78 E9 A4 8A F0 A3 75 + : EC ED B6 56 96 7F 88 99 85 9A F2 3E 68 77 + : 87 EB 9E D1 9F C0 B4 17 DC AB 89 23 A4 1D + : 7E 16 23 4C 4F A8 4D F5 31 B8 7C AA E3 1A + : 49 09 F4 4B 26 DB 27 67 30 82 12 01 4A E9 + : 1A B6 C1 0C 53 8B 6C FC 2F 7A 43 EC 33 36 + : 7E 32 B2 7B D5 AA CF 01 14 C6 12 EC 13 F2 + : 2D 14 7A 8B 21 58 14 13 4C 46 A3 9A F2 16 + : 95 FF 23 +328 02 3: INTEGER 65537 + : } + : } + : } +333 A3 175: [3] { +336 30 172: SEQUENCE { +339 30 63: SEQUENCE { +341 06 3: OBJECT IDENTIFIER subjectAltName (2 5 29 17) +346 04 56: OCTET STRING, encapsulates { +348 30 54: SEQUENCE { + + + +Housley, et. al. Standards Track [Page 124] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +350 86 52: [6] + : 'http://www.itl.nist.gov/div893/staff/' + : 'polk/index.html' + : } + : } + : } +404 30 31: SEQUENCE { +406 06 3: OBJECT IDENTIFIER issuerAltName (2 5 29 18) +411 04 24: OCTET STRING, encapsulates { +413 30 22: SEQUENCE { +415 86 20: [6] 'http://www.nist.gov/' + : } + : } + : } +437 30 31: SEQUENCE { +439 06 3: OBJECT IDENTIFIER + : authorityKeyIdentifier (2 5 29 35) +444 04 24: OCTET STRING, encapsulates { +446 30 22: SEQUENCE { +448 80 20: [0] + : 08 68 AF 85 33 C8 39 4A 7A F8 82 93 8E + : 70 6A 4A 20 84 2C 32 + : } + : } + : } +470 30 23: SEQUENCE { +472 06 3: OBJECT IDENTIFIER + : certificatePolicies (2 5 29 32) +477 04 16: OCTET STRING, encapsulates { +479 30 14: SEQUENCE { +481 30 12: SEQUENCE { +483 06 10: OBJECT IDENTIFIER + : '2 16 840 1 101 3 2 1 48 9' + : } + : } + : } + : } +495 30 14: SEQUENCE { +497 06 3: OBJECT IDENTIFIER keyUsage (2 5 29 15) +502 01 1: BOOLEAN TRUE +505 04 4: OCTET STRING, encapsulates { +507 03 2: BIT STRING 7 unused bits + : '1'B (bit 0) + : } + : } + : } + : } + : } + + + +Housley, et. al. Standards Track [Page 125] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +511 30 13: SEQUENCE { +513 06 9: OBJECT IDENTIFIER + : sha1withRSAEncryption (1 2 840 113549 1 1 5) +524 05 0: NULL + : } +526 03 129: BIT STRING 0 unused bits + : 1E 07 77 6E 66 B5 B6 B8 57 F0 03 DC 6F 77 + : 6D AF 55 1D 74 E5 CE 36 81 FC 4B C5 F4 47 + : 82 C4 0A 25 AA 8D D6 7D 3A 89 AB 44 34 39 + : F6 BD 61 1A 78 85 7A B8 1E 92 A2 22 2F CE + : 07 1A 08 8E F1 46 03 59 36 4A CB 60 E6 03 + : 40 01 5B 2A 44 D6 E4 7F EB 43 5E 74 0A E6 + : E4 F9 3E E1 44 BE 1F E7 5F 5B 2C 41 8D 08 + : BD 26 FE 6A A6 C3 2F B2 3B 41 12 6B C1 06 + : 8A B8 4C 91 59 EB 2F 38 20 2A 67 74 20 0B + : 77 F3 + : } + +C.4 Certificate Revocation List + + This section contains an annotated hex dump of a version 2 CRL with + one extension (cRLNumber). The CRL was issued by OU=NIST; O=gov; + C=US on August 7, 1997; the next scheduled issuance was September 7, + 1997. The CRL includes one revoked certificates: serial number 18 + (12 hex), which was revoked on July 31, 1997 due to keyCompromise. + The CRL itself is number 18, and it was signed with DSA and SHA-1. + + 0 30 203: SEQUENCE { + 3 30 140: SEQUENCE { + 6 02 1: INTEGER 1 + 9 30 9: SEQUENCE { + 11 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } + 20 30 42: SEQUENCE { + 22 31 11: SET { + 24 30 9: SEQUENCE { + 26 06 3: OBJECT IDENTIFIER countryName (2 5 4 6) + 31 13 2: PrintableString 'US' + : } + : } + 35 31 12: SET { + 37 30 10: SEQUENCE { + 39 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10) + 44 13 3: PrintableString 'gov' + : } + : } + 49 31 13: SET { + 51 30 11: SEQUENCE { + + + +Housley, et. al. Standards Track [Page 126] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + + 53 06 3: OBJECT IDENTIFIER + : organizationalUnitName (2 5 4 11) + 58 13 4: PrintableString 'NIST' + : } + : } + : } + 64 17 13: UTCTime '970807000000Z' + 79 17 13: UTCTime '970907000000Z' + 94 30 34: SEQUENCE { + 96 30 32: SEQUENCE { + 98 02 1: INTEGER 18 +101 17 13: UTCTime '970731000000Z' +116 30 12: SEQUENCE { +118 30 10: SEQUENCE { +120 06 3: OBJECT IDENTIFIER cRLReason (2 5 29 21) +125 04 3: OCTET STRING, encapsulates { +127 0A 1: ENUMERATED 1 + : } + : } + : } + : } + : } +130 A0 14: [0] { +132 30 12: SEQUENCE { +134 30 10: SEQUENCE { +136 06 3: OBJECT IDENTIFIER cRLNumber (2 5 29 20) +141 04 3: OCTET STRING, encapsulates { +143 02 1: INTEGER 12 + : } + : } + : } + : } + : } +146 30 9: SEQUENCE { +148 06 7: OBJECT IDENTIFIER dsaWithSha1 (1 2 840 10040 4 3) + : } +157 03 47: BIT STRING 0 unused bits, encapsulates { +160 30 44: SEQUENCE { +162 02 20: INTEGER + : 22 4E 9F 43 BA 95 06 34 F2 BB 5E 65 DB A6 + : 80 05 C0 3A 29 47 +184 02 20: INTEGER + : 59 1A 57 C9 82 D7 02 21 14 C3 D4 0B 32 1B + : 96 16 B1 1F 46 5A + : } + : } + : } + + + + +Housley, et. al. Standards Track [Page 127] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +Author Addresses + + Russell Housley + RSA Laboratories + 918 Spring Knoll Drive + Herndon, VA 20170 + USA + + EMail: rhousley@rsasecurity.com + + Warwick Ford + VeriSign, Inc. + 401 Edgewater Place + Wakefield, MA 01880 + USA + + EMail: wford@verisign.com + + Tim Polk + NIST + Building 820, Room 426 + Gaithersburg, MD 20899 + USA + + EMail: wpolk@nist.gov + + David Solo + Citigroup + 909 Third Ave, 16th Floor + New York, NY 10043 + USA + + EMail: dsolo@alum.mit.edu + + + + + + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 128] + +RFC 3280 Internet X.509 Public Key Infrastructure April 2002 + + +Full Copyright Statement + + Copyright (C) The Internet Society (2002). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + + + + + + + + + + + + + +Housley, et. al. Standards Track [Page 129] + diff --git a/doc/ikev2/[RFC3526] - More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE).txt b/doc/ikev2/[RFC3526] - More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE).txt new file mode 100644 index 000000000..7b688a33f --- /dev/null +++ b/doc/ikev2/[RFC3526] - More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE).txt @@ -0,0 +1,563 @@ + + + + + + +Network Working Group T. Kivinen +Request for Comments: 3526 M. Kojo +Category: Standards Track SSH Communications Security + May 2003 + + + More Modular Exponential (MODP) Diffie-Hellman groups + for Internet Key Exchange (IKE) + +Status of this Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (2003). All Rights Reserved. + +Abstract + + This document defines new Modular Exponential (MODP) Groups for the + Internet Key Exchange (IKE) protocol. It documents the well known + and used 1536 bit group 5, and also defines new 2048, 3072, 4096, + 6144, and 8192 bit Diffie-Hellman groups numbered starting at 14. + The selection of the primes for theses groups follows the criteria + established by Richard Schroeppel. + +Table of Contents + + 1. Introduction. . . . . . . . . . . . . . . . . . . . . . . 2 + 2. 1536-bit MODP Group . . . . . . . . . . . . . . . . . . . 3 + 3. 2048-bit MODP Group . . . . . . . . . . . . . . . . . . . 3 + 4. 3072-bit MODP Group . . . . . . . . . . . . . . . . . . . 4 + 5. 4096-bit MODP Group . . . . . . . . . . . . . . . . . . . 5 + 6. 6144-bit MODP Group . . . . . . . . . . . . . . . . . . . 6 + 7. 8192-bit MODP Group . . . . . . . . . . . . . . . . . . . 6 + 8. Security Considerations . . . . . . . . . . . . . . . . . 8 + 9. IANA Considerations . . . . . . . . . . . . . . . . . . . 8 + 10. Normative References. . . . . . . . . . . . . . . . . . . 8 + 11. Non-Normative References. . . . . . . . . . . . . . . . . 8 + 12. Authors' Addresses . . . . . . . . . . . . . . . . . . . 9 + 13. Full Copyright Statement. . . . . . . . . . . . . . . . . 10 + + + + + + +Kivinen & Kojo Standards Track [Page 1] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +1. Introduction + + One of the important protocol parameters negotiated by Internet Key + Exchange (IKE) [RFC-2409] is the Diffie-Hellman "group" that will be + used for certain cryptographic operations. IKE currently defines 4 + groups. These groups are approximately as strong as a symmetric key + of 70-80 bits. + + The new Advanced Encryption Standard (AES) cipher [AES], which has + more strength, needs stronger groups. For the 128-bit AES we need + about a 3200-bit group [Orman01]. The 192 and 256-bit keys would + need groups that are about 8000 and 15400 bits respectively. Another + source [RSA13] [Rousseau00] estimates that the security equivalent + key size for the 192-bit symmetric cipher is 2500 bits instead of + 8000 bits, and the equivalent key size 256-bit symmetric cipher is + 4200 bits instead of 15400 bits. + + Because of this disagreement, we just specify different groups + without specifying which group should be used with 128, 192 or 256- + bit AES. With current hardware groups bigger than 8192-bits being + too slow for practical use, this document does not provide any groups + bigger than 8192-bits. + + The exponent size used in the Diffie-Hellman must be selected so that + it matches other parts of the system. It should not be the weakest + link in the security system. It should have double the entropy of + the strength of the entire system, i.e., if you use a group whose + strength is 128 bits, you must use more than 256 bits of randomness + in the exponent used in the Diffie-Hellman calculation. + + + + + + + + + + + + + + + + + + + + + + +Kivinen & Kojo Standards Track [Page 2] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +2. 1536-bit MODP Group + + The 1536 bit MODP group has been used for the implementations for + quite a long time, but was not defined in RFC 2409 (IKE). + Implementations have been using group 5 to designate this group, we + standardize that practice here. + + The prime is: 2^1536 - 2^1472 - 1 + 2^64 * { [2^1406 pi] + 741804 } + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA237327 FFFFFFFF FFFFFFFF + + The generator is: 2. + +3. 2048-bit MODP Group + + This group is assigned id 14. + + This prime is: 2^2048 - 2^1984 - 1 + 2^64 * { [2^1918 pi] + 124476 } + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B + E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 + DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510 + 15728E5A 8AACAA68 FFFFFFFF FFFFFFFF + + The generator is: 2. + + + + + + + + +Kivinen & Kojo Standards Track [Page 3] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +4. 3072-bit MODP Group + + This group is assigned id 15. + + This prime is: 2^3072 - 2^3008 - 1 + 2^64 * { [2^2942 pi] + 1690314 } + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B + E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 + DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510 + 15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64 + ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7 + ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B + F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C + BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31 + 43DB5BFC E0FD108E 4B82D120 A93AD2CA FFFFFFFF FFFFFFFF + + The generator is: 2. + + + + + + + + + + + + + + + + + + + + + + + + + +Kivinen & Kojo Standards Track [Page 4] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +5. 4096-bit MODP Group + + This group is assigned id 16. + + This prime is: 2^4096 - 2^4032 - 1 + 2^64 * { [2^3966 pi] + 240904 } + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B + E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 + DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510 + 15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64 + ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7 + ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B + F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C + BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31 + 43DB5BFC E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7 + 88719A10 BDBA5B26 99C32718 6AF4E23C 1A946834 B6150BDA + 2583E9CA 2AD44CE8 DBBBC2DB 04DE8EF9 2E8EFC14 1FBECAA6 + 287C5947 4E6BC05D 99B2964F A090C3A2 233BA186 515BE7ED + 1F612970 CEE2D7AF B81BDD76 2170481C D0069127 D5B05AA9 + 93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34063199 + FFFFFFFF FFFFFFFF + + The generator is: 2. + + + + + + + + + + + + + + + + + + + +Kivinen & Kojo Standards Track [Page 5] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +6. 6144-bit MODP Group + + This group is assigned id 17. + + This prime is: 2^6144 - 2^6080 - 1 + 2^64 * { [2^6014 pi] + 929484 } + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08 + 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B + 302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9 + A637ED6B 0BFF5CB6 F406B7ED EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 + 49286651 ECE45B3D C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 + FD24CF5F 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B E39E772C + 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 DE2BCBF6 95581718 + 3995497C EA956AE5 15D22618 98FA0510 15728E5A 8AAAC42D AD33170D + 04507A33 A85521AB DF1CBA64 ECFB8504 58DBEF0A 8AEA7157 5D060C7D + B3970F85 A6E1E4C7 ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 + 1AD2EE6B F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C + BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31 43DB5BFC + E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7 88719A10 BDBA5B26 + 99C32718 6AF4E23C 1A946834 B6150BDA 2583E9CA 2AD44CE8 DBBBC2DB + 04DE8EF9 2E8EFC14 1FBECAA6 287C5947 4E6BC05D 99B2964F A090C3A2 + 233BA186 515BE7ED 1F612970 CEE2D7AF B81BDD76 2170481C D0069127 + D5B05AA9 93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34028492 + 36C3FAB4 D27C7026 C1D4DCB2 602646DE C9751E76 3DBA37BD F8FF9406 + AD9E530E E5DB382F 413001AE B06A53ED 9027D831 179727B0 865A8918 + DA3EDBEB CF9B14ED 44CE6CBA CED4BB1B DB7F1447 E6CC254B 33205151 + 2BD7AF42 6FB8F401 378CD2BF 5983CA01 C64B92EC F032EA15 D1721D03 + F482D7CE 6E74FEF6 D55E702F 46980C82 B5A84031 900B1C9E 59E7C97F + BEC7E8F3 23A97A7E 36CC88BE 0F1D45B7 FF585AC5 4BD407B2 2B4154AA + CC8F6D7E BF48E1D8 14CC5ED2 0F8037E0 A79715EE F29BE328 06A1D58B + B7C5DA76 F550AA3D 8A1FBFF0 EB19CCB1 A313D55C DA56C9EC 2EF29632 + 387FE8D7 6E3C0468 043E8F66 3F4860EE 12BF2D5B 0B7474D6 E694F91E + 6DCC4024 FFFFFFFF FFFFFFFF + + The generator is: 2. + +7. 8192-bit MODP Group + + This group is assigned id 18. + + This prime is: 2^8192 - 2^8128 - 1 + 2^64 * { [2^8062 pi] + 4743158 } + + + + + + + +Kivinen & Kojo Standards Track [Page 6] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 + 29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD + EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245 + E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED + EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D + C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F + 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D + 670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B + E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 + DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510 + 15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64 + ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7 + ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B + F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C + BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31 + 43DB5BFC E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7 + 88719A10 BDBA5B26 99C32718 6AF4E23C 1A946834 B6150BDA + 2583E9CA 2AD44CE8 DBBBC2DB 04DE8EF9 2E8EFC14 1FBECAA6 + 287C5947 4E6BC05D 99B2964F A090C3A2 233BA186 515BE7ED + 1F612970 CEE2D7AF B81BDD76 2170481C D0069127 D5B05AA9 + 93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34028492 + 36C3FAB4 D27C7026 C1D4DCB2 602646DE C9751E76 3DBA37BD + F8FF9406 AD9E530E E5DB382F 413001AE B06A53ED 9027D831 + 179727B0 865A8918 DA3EDBEB CF9B14ED 44CE6CBA CED4BB1B + DB7F1447 E6CC254B 33205151 2BD7AF42 6FB8F401 378CD2BF + 5983CA01 C64B92EC F032EA15 D1721D03 F482D7CE 6E74FEF6 + D55E702F 46980C82 B5A84031 900B1C9E 59E7C97F BEC7E8F3 + 23A97A7E 36CC88BE 0F1D45B7 FF585AC5 4BD407B2 2B4154AA + CC8F6D7E BF48E1D8 14CC5ED2 0F8037E0 A79715EE F29BE328 + 06A1D58B B7C5DA76 F550AA3D 8A1FBFF0 EB19CCB1 A313D55C + DA56C9EC 2EF29632 387FE8D7 6E3C0468 043E8F66 3F4860EE + 12BF2D5B 0B7474D6 E694F91E 6DBE1159 74A3926F 12FEE5E4 + 38777CB6 A932DF8C D8BEC4D0 73B931BA 3BC832B6 8D9DD300 + 741FA7BF 8AFC47ED 2576F693 6BA42466 3AAB639C 5AE4F568 + 3423B474 2BF1C978 238F16CB E39D652D E3FDB8BE FC848AD9 + 22222E04 A4037C07 13EB57A8 1A23F0C7 3473FC64 6CEA306B + 4BCBC886 2F8385DD FA9D4B7F A2C087E8 79683303 ED5BDD3A + 062B3CF5 B3A278A6 6D2A13F8 3F44F82D DF310EE0 74AB6A36 + 4597E899 A0255DC1 64F31CC5 0846851D F9AB4819 5DED7EA1 + B1D510BD 7EE74D73 FAF36BC3 1ECFA268 359046F4 EB879F92 + 4009438B 481C6CD7 889A002E D5EE382B C9190DA6 FC026E47 + 9558E447 5677E9AA 9E3050E2 765694DF C81F56E8 80B96E71 + 60C980DD 98EDD3DF FFFFFFFF FFFFFFFF + + The generator is: 2. + + + + +Kivinen & Kojo Standards Track [Page 7] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +8. Security Considerations + + This document describes new stronger groups to be used in IKE. The + strengths of the groups defined here are always estimates and there + are as many methods to estimate them as there are cryptographers. + For the strength estimates below we took the both ends of the scale + so the actual strength estimate is likely between the two numbers + given here. + + +--------+----------+---------------------+---------------------+ + | Group | Modulus | Strength Estimate 1 | Strength Estimate 2 | + | | +----------+----------+----------+----------+ + | | | | exponent | | exponent | + | | | in bits | size | in bits | size | + +--------+----------+----------+----------+----------+----------+ + | 5 | 1536-bit | 90 | 180- | 120 | 240- | + | 14 | 2048-bit | 110 | 220- | 160 | 320- | + | 15 | 3072-bit | 130 | 260- | 210 | 420- | + | 16 | 4096-bit | 150 | 300- | 240 | 480- | + | 17 | 6144-bit | 170 | 340- | 270 | 540- | + | 18 | 8192-bit | 190 | 380- | 310 | 620- | + +--------+----------+---------------------+---------------------+ + +9. IANA Considerations + + IKE [RFC-2409] defines 4 Diffie-Hellman Groups, numbered 1 through 4. + + This document defines a new group 5, and new groups from 14 to 18. + Requests for additional assignment are via "IETF Consensus" as + defined in RFC 2434 [RFC-2434]. Specifically, new groups are + expected to be documented in a Standards Track RFC. + +10. Normative References + + [RFC-2409] Harkins, D. and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [RFC-2434] Narten, T. and H. Alvestrand, "Guidelines for Writing an + IANA Considerations Section in RFCs", BCP 26, RFC 2434, + October 1998. + +11. Non-Normative References + + [AES] NIST, FIPS PUB 197, "Advanced Encryption Standard + (AES)," November 2001. + http://csrc.nist.gov/publications/fips/fips197/fips- + 197.{ps,pdf} + + + + +Kivinen & Kojo Standards Track [Page 8] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + + [RFC-2412] Orman, H., "The OAKLEY Key Determination Protocol", RFC + 2412, November 1998. + + [Orman01] Orman, H. and P. Hoffman, "Determining Strengths For + Public Keys Used For Exchanging Symmetric Keys", Work in + progress. + + [RSA13] Silverman, R. "RSA Bulleting #13: A Cost-Based Security + Analysis of Symmetric and Asymmetric Key Lengths", April + 2000, http://www.rsasecurity.com/rsalabs/bulletins/ + bulletin13.html + + [Rousseau00] Rousseau, F. "New Time and Space Based Key Size + Equivalents for RSA and Diffie-Hellman", December 2000, + http://www.sandelman.ottawa.on.ca/ipsec/2000/12/ + msg00045.html + +12. Authors' Addresses + + Tero Kivinen + SSH Communications Security Corp + Fredrikinkatu 42 + FIN-00100 HELSINKI + Finland + + EMail: kivinen@ssh.fi + + + Mika Kojo + HELSINKI + Finland + + EMail: mika.kojo@helsinki.fi + + + + + + + + + + + + + + + + + + +Kivinen & Kojo Standards Track [Page 9] + +RFC 3526 MODP Diffie-Hellman groups for IKE May 2003 + + +13. Full Copyright Statement + + Copyright (C) The Internet Society (2003). All Rights Reserved. + + This document and translations of it may be copied and furnished to + others, and derivative works that comment on or otherwise explain it + or assist in its implementation may be prepared, copied, published + and distributed, in whole or in part, without restriction of any + kind, provided that the above copyright notice and this paragraph are + included on all such copies and derivative works. However, this + document itself may not be modified in any way, such as by removing + the copyright notice or references to the Internet Society or other + Internet organizations, except as needed for the purpose of + developing Internet standards in which case the procedures for + copyrights defined in the Internet Standards process must be + followed, or as required to translate it into languages other than + English. + + The limited permissions granted above are perpetual and will not be + revoked by the Internet Society or its successors or assigns. + + This document and the information contained herein is provided on an + "AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET ENGINEERING + TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING + BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION + HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF + MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + + + + + + + + + + + + + +Kivinen & Kojo Standards Track [Page 10] + diff --git a/doc/ikev2/[RFC4301] - Security Architecture for the Internet Protocol.txt b/doc/ikev2/[RFC4301] - Security Architecture for the Internet Protocol.txt new file mode 100644 index 000000000..4a8eba975 --- /dev/null +++ b/doc/ikev2/[RFC4301] - Security Architecture for the Internet Protocol.txt @@ -0,0 +1,5659 @@ + + + + + + +Network Working Group S. Kent +Request for Comments: 4301 K. Seo +Obsoletes: 2401 BBN Technologies +Category: Standards Track December 2005 + + + Security Architecture for the Internet Protocol + +Status of This Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (2005). + +Abstract + + This document describes an updated version of the "Security + Architecture for IP", which is designed to provide security services + for traffic at the IP layer. This document obsoletes RFC 2401 + (November 1998). + +Dedication + + This document is dedicated to the memory of Charlie Lynn, a long-time + senior colleague at BBN, who made very significant contributions to + the IPsec documents. + + + + + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 1] + +RFC 4301 Security Architecture for IP December 2005 + + +Table of Contents + + 1. Introduction ....................................................4 + 1.1. Summary of Contents of Document ............................4 + 1.2. Audience ...................................................4 + 1.3. Related Documents ..........................................5 + 2. Design Objectives ...............................................5 + 2.1. Goals/Objectives/Requirements/Problem Description ..........5 + 2.2. Caveats and Assumptions ....................................6 + 3. System Overview .................................................7 + 3.1. What IPsec Does ............................................7 + 3.2. How IPsec Works ............................................9 + 3.3. Where IPsec Can Be Implemented ............................10 + 4. Security Associations ..........................................11 + 4.1. Definition and Scope ......................................12 + 4.2. SA Functionality ..........................................16 + 4.3. Combining SAs .............................................17 + 4.4. Major IPsec Databases .....................................18 + 4.4.1. The Security Policy Database (SPD) .................19 + 4.4.1.1. Selectors .................................26 + 4.4.1.2. Structure of an SPD Entry .................30 + 4.4.1.3. More Regarding Fields Associated + with Next Layer Protocols .................32 + 4.4.2. Security Association Database (SAD) ................34 + 4.4.2.1. Data Items in the SAD .....................36 + 4.4.2.2. Relationship between SPD, PFP + flag, packet, and SAD .....................38 + 4.4.3. Peer Authorization Database (PAD) ..................43 + 4.4.3.1. PAD Entry IDs and Matching Rules ..........44 + 4.4.3.2. IKE Peer Authentication Data ..............45 + 4.4.3.3. Child SA Authorization Data ...............46 + 4.4.3.4. How the PAD Is Used .......................46 + 4.5. SA and Key Management .....................................47 + 4.5.1. Manual Techniques ..................................48 + 4.5.2. Automated SA and Key Management ....................48 + 4.5.3. Locating a Security Gateway ........................49 + 4.6. SAs and Multicast .........................................50 + 5. IP Traffic Processing ..........................................50 + 5.1. Outbound IP Traffic Processing + (protected-to-unprotected) ................................52 + 5.1.1. Handling an Outbound Packet That Must Be + Discarded ..........................................54 + 5.1.2. Header Construction for Tunnel Mode ................55 + 5.1.2.1. IPv4: Header Construction for + Tunnel Mode ...............................57 + 5.1.2.2. IPv6: Header Construction for + Tunnel Mode ...............................59 + 5.2. Processing Inbound IP Traffic (unprotected-to-protected) ..59 + + + +Kent & Seo Standards Track [Page 2] + +RFC 4301 Security Architecture for IP December 2005 + + + 6. ICMP Processing ................................................63 + 6.1. Processing ICMP Error Messages Directed to an + IPsec Implementation ......................................63 + 6.1.1. ICMP Error Messages Received on the + Unprotected Side of the Boundary ...................63 + 6.1.2. ICMP Error Messages Received on the + Protected Side of the Boundary .....................64 + 6.2. Processing Protected, Transit ICMP Error Messages .........64 + 7. Handling Fragments (on the protected side of the IPsec + boundary) ......................................................66 + 7.1. Tunnel Mode SAs that Carry Initial and Non-Initial + Fragments .................................................67 + 7.2. Separate Tunnel Mode SAs for Non-Initial Fragments ........67 + 7.3. Stateful Fragment Checking ................................68 + 7.4. BYPASS/DISCARD Traffic ....................................69 + 8. Path MTU/DF Processing .........................................69 + 8.1. DF Bit ....................................................69 + 8.2. Path MTU (PMTU) Discovery .................................70 + 8.2.1. Propagation of PMTU ................................70 + 8.2.2. PMTU Aging .........................................71 + 9. Auditing .......................................................71 + 10. Conformance Requirements ......................................71 + 11. Security Considerations .......................................72 + 12. IANA Considerations ...........................................72 + 13. Differences from RFC 2401 .....................................72 + 14. Acknowledgements ..............................................75 + Appendix A: Glossary ..............................................76 + Appendix B: Decorrelation .........................................79 + B.1. Decorrelation Algorithm ...................................79 + Appendix C: ASN.1 for an SPD Entry ................................82 + Appendix D: Fragment Handling Rationale ...........................88 + D.1. Transport Mode and Fragments ..............................88 + D.2. Tunnel Mode and Fragments .................................89 + D.3. The Problem of Non-Initial Fragments ......................90 + D.4. BYPASS/DISCARD Traffic ....................................93 + D.5. Just say no to ports? .....................................94 + D.6. Other Suggested Solutions..................................94 + D.7. Consistency................................................95 + D.8. Conclusions................................................95 + Appendix E: Example of Supporting Nested SAs via SPD and + Forwarding Table Entries...............................96 + References.........................................................98 + Normative References............................................98 + Informative References..........................................99 + + + + + + + +Kent & Seo Standards Track [Page 3] + +RFC 4301 Security Architecture for IP December 2005 + + +1. Introduction + +1.1. Summary of Contents of Document + + This document specifies the base architecture for IPsec-compliant + systems. It describes how to provide a set of security services for + traffic at the IP layer, in both the IPv4 [Pos81a] and IPv6 [DH98] + environments. This document describes the requirements for systems + that implement IPsec, the fundamental elements of such systems, and + how the elements fit together and fit into the IP environment. It + also describes the security services offered by the IPsec protocols, + and how these services can be employed in the IP environment. This + document does not address all aspects of the IPsec architecture. + Other documents address additional architectural details in + specialized environments, e.g., use of IPsec in Network Address + Translation (NAT) environments and more comprehensive support for IP + multicast. The fundamental components of the IPsec security + architecture are discussed in terms of their underlying, required + functionality. Additional RFCs (see Section 1.3 for pointers to + other documents) define the protocols in (a), (c), and (d). + + a. Security Protocols -- Authentication Header (AH) and + Encapsulating Security Payload (ESP) + b. Security Associations -- what they are and how they work, + how they are managed, associated processing + c. Key Management -- manual and automated (The Internet Key + Exchange (IKE)) + d. Cryptographic algorithms for authentication and encryption + + This document is not a Security Architecture for the Internet; it + addresses security only at the IP layer, provided through the use of + a combination of cryptographic and protocol security mechanisms. + + The spelling "IPsec" is preferred and used throughout this and all + related IPsec standards. All other capitalizations of IPsec (e.g., + IPSEC, IPSec, ipsec) are deprecated. However, any capitalization of + the sequence of letters "IPsec" should be understood to refer to the + IPsec protocols. + + The keywords MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, + SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL, when they appear in this + document, are to be interpreted as described in RFC 2119 [Bra97]. + +1.2. Audience + + The target audience for this document is primarily individuals who + implement this IP security technology or who architect systems that + will use this technology. Technically adept users of this technology + + + +Kent & Seo Standards Track [Page 4] + +RFC 4301 Security Architecture for IP December 2005 + + + (end users or system administrators) also are part of the target + audience. A glossary is provided in Appendix A to help fill in gaps + in background/vocabulary. This document assumes that the reader is + familiar with the Internet Protocol (IP), related networking + technology, and general information system security terms and + concepts. + +1.3. Related Documents + + As mentioned above, other documents provide detailed definitions of + some of the components of IPsec and of their interrelationship. They + include RFCs on the following topics: + + a. security protocols -- RFCs describing the Authentication + Header (AH) [Ken05b] and Encapsulating Security Payload + (ESP) [Ken05a] protocols. + b. cryptographic algorithms for integrity and encryption -- one + RFC that defines the mandatory, default algorithms for use + with AH and ESP [Eas05], a similar RFC that defines the + mandatory algorithms for use with IKEv2 [Sch05] plus a + separate RFC for each cryptographic algorithm. + c. automatic key management -- RFCs on "The Internet Key + Exchange (IKEv2) Protocol" [Kau05] and "Cryptographic + Algorithms for Use in the Internet Key Exchange Version 2 + (IKEv2)" [Sch05]. + +2. Design Objectives + +2.1. Goals/Objectives/Requirements/Problem Description + + IPsec is designed to provide interoperable, high quality, + cryptographically-based security for IPv4 and IPv6. The set of + security services offered includes access control, connectionless + integrity, data origin authentication, detection and rejection of + replays (a form of partial sequence integrity), confidentiality (via + encryption), and limited traffic flow confidentiality. These + services are provided at the IP layer, offering protection in a + standard fashion for all protocols that may be carried over IP + (including IP itself). + + IPsec includes a specification for minimal firewall functionality, + since that is an essential aspect of access control at the IP layer. + Implementations are free to provide more sophisticated firewall + mechanisms, and to implement the IPsec-mandated functionality using + those more sophisticated mechanisms. (Note that interoperability may + suffer if additional firewall constraints on traffic flows are + imposed by an IPsec implementation but cannot be negotiated based on + the traffic selector features defined in this document and negotiated + + + +Kent & Seo Standards Track [Page 5] + +RFC 4301 Security Architecture for IP December 2005 + + + via IKEv2.) The IPsec firewall function makes use of the + cryptographically-enforced authentication and integrity provided for + all IPsec traffic to offer better access control than could be + obtained through use of a firewall (one not privy to IPsec internal + parameters) plus separate cryptographic protection. + + Most of the security services are provided through use of two traffic + security protocols, the Authentication Header (AH) and the + Encapsulating Security Payload (ESP), and through the use of + cryptographic key management procedures and protocols. The set of + IPsec protocols employed in a context, and the ways in which they are + employed, will be determined by the users/administrators in that + context. It is the goal of the IPsec architecture to ensure that + compliant implementations include the services and management + interfaces needed to meet the security requirements of a broad user + population. + + When IPsec is correctly implemented and deployed, it ought not + adversely affect users, hosts, and other Internet components that do + not employ IPsec for traffic protection. IPsec security protocols + (AH and ESP, and to a lesser extent, IKE) are designed to be + cryptographic algorithm independent. This modularity permits + selection of different sets of cryptographic algorithms as + appropriate, without affecting the other parts of the implementation. + For example, different user communities may select different sets of + cryptographic algorithms (creating cryptographically-enforced + cliques) if required. + + To facilitate interoperability in the global Internet, a set of + default cryptographic algorithms for use with AH and ESP is specified + in [Eas05] and a set of mandatory-to-implement algorithms for IKEv2 + is specified in [Sch05]. [Eas05] and [Sch05] will be periodically + updated to keep pace with computational and cryptologic advances. By + specifying these algorithms in documents that are separate from the + AH, ESP, and IKEv2 specifications, these algorithms can be updated or + replaced without affecting the standardization progress of the rest + of the IPsec document suite. The use of these cryptographic + algorithms, in conjunction with IPsec traffic protection and key + management protocols, is intended to permit system and application + developers to deploy high quality, Internet-layer, cryptographic + security technology. + +2.2. Caveats and Assumptions + + The suite of IPsec protocols and associated default cryptographic + algorithms are designed to provide high quality security for Internet + traffic. However, the security offered by use of these protocols + ultimately depends on the quality of their implementation, which is + + + +Kent & Seo Standards Track [Page 6] + +RFC 4301 Security Architecture for IP December 2005 + + + outside the scope of this set of standards. Moreover, the security + of a computer system or network is a function of many factors, + including personnel, physical, procedural, compromising emanations, + and computer security practices. Thus, IPsec is only one part of an + overall system security architecture. + + Finally, the security afforded by the use of IPsec is critically + dependent on many aspects of the operating environment in which the + IPsec implementation executes. For example, defects in OS security, + poor quality of random number sources, sloppy system management + protocols and practices, etc., can all degrade the security provided + by IPsec. As above, none of these environmental attributes are + within the scope of this or other IPsec standards. + +3. System Overview + + This section provides a high level description of how IPsec works, + the components of the system, and how they fit together to provide + the security services noted above. The goal of this description is + to enable the reader to "picture" the overall process/system, see how + it fits into the IP environment, and to provide context for later + sections of this document, which describe each of the components in + more detail. + + An IPsec implementation operates in a host, as a security gateway + (SG), or as an independent device, affording protection to IP + traffic. (A security gateway is an intermediate system implementing + IPsec, e.g., a firewall or router that has been IPsec-enabled.) More + detail on these classes of implementations is provided later, in + Section 3.3. The protection offered by IPsec is based on requirements + defined by a Security Policy Database (SPD) established and + maintained by a user or system administrator, or by an application + operating within constraints established by either of the above. In + general, packets are selected for one of three processing actions + based on IP and next layer header information ("Selectors", Section + 4.4.1.1) matched against entries in the SPD. Each packet is either + PROTECTed using IPsec security services, DISCARDed, or allowed to + BYPASS IPsec protection, based on the applicable SPD policies + identified by the Selectors. + +3.1. What IPsec Does + + IPsec creates a boundary between unprotected and protected + interfaces, for a host or a network (see Figure 1 below). Traffic + traversing the boundary is subject to the access controls specified + by the user or administrator responsible for the IPsec configuration. + These controls indicate whether packets cross the boundary unimpeded, + are afforded security services via AH or ESP, or are discarded. + + + +Kent & Seo Standards Track [Page 7] + +RFC 4301 Security Architecture for IP December 2005 + + + IPsec security services are offered at the IP layer through selection + of appropriate security protocols, cryptographic algorithms, and + cryptographic keys. IPsec can be used to protect one or more "paths" + (a) between a pair of hosts, (b) between a pair of security gateways, + or (c) between a security gateway and a host. A compliant host + implementation MUST support (a) and (c) and a compliant security + gateway must support all three of these forms of connectivity, since + under certain circumstances a security gateway acts as a host. + + Unprotected + ^ ^ + | | + +-------------|-------|-------+ + | +-------+ | | | + | |Discard|<--| V | + | +-------+ |B +--------+ | + ................|y..| AH/ESP |..... IPsec Boundary + | +---+ |p +--------+ | + | |IKE|<----|a ^ | + | +---+ |s | | + | +-------+ |s | | + | |Discard|<--| | | + | +-------+ | | | + +-------------|-------|-------+ + | | + V V + Protected + + Figure 1. Top Level IPsec Processing Model + + In this diagram, "unprotected" refers to an interface that might also + be described as "black" or "ciphertext". Here, "protected" refers to + an interface that might also be described as "red" or "plaintext". + The protected interface noted above may be internal, e.g., in a host + implementation of IPsec, the protected interface may link to a socket + layer interface presented by the OS. In this document, the term + "inbound" refers to traffic entering an IPsec implementation via the + unprotected interface or emitted by the implementation on the + unprotected side of the boundary and directed towards the protected + interface. The term "outbound" refers to traffic entering the + implementation via the protected interface, or emitted by the + implementation on the protected side of the boundary and directed + toward the unprotected interface. An IPsec implementation may + support more than one interface on either or both sides of the + boundary. + + + + + + +Kent & Seo Standards Track [Page 8] + +RFC 4301 Security Architecture for IP December 2005 + + + Note the facilities for discarding traffic on either side of the + IPsec boundary, the BYPASS facility that allows traffic to transit + the boundary without cryptographic protection, and the reference to + IKE as a protected-side key and security management function. + + IPsec optionally supports negotiation of IP compression [SMPT01], + motivated in part by the observation that when encryption is employed + within IPsec, it prevents effective compression by lower protocol + layers. + +3.2. How IPsec Works + + IPsec uses two protocols to provide traffic security services -- + Authentication Header (AH) and Encapsulating Security Payload (ESP). + Both protocols are described in detail in their respective RFCs + [Ken05b, Ken05a]. IPsec implementations MUST support ESP and MAY + support AH. (Support for AH has been downgraded to MAY because + experience has shown that there are very few contexts in which ESP + cannot provide the requisite security services. Note that ESP can be + used to provide only integrity, without confidentiality, making it + comparable to AH in most contexts.) + + o The IP Authentication Header (AH) [Ken05b] offers integrity and + data origin authentication, with optional (at the discretion of + the receiver) anti-replay features. + + o The Encapsulating Security Payload (ESP) protocol [Ken05a] offers + the same set of services, and also offers confidentiality. Use of + ESP to provide confidentiality without integrity is NOT + RECOMMENDED. When ESP is used with confidentiality enabled, there + are provisions for limited traffic flow confidentiality, i.e., + provisions for concealing packet length, and for facilitating + efficient generation and discard of dummy packets. This + capability is likely to be effective primarily in virtual private + network (VPN) and overlay network contexts. + + o Both AH and ESP offer access control, enforced through the + distribution of cryptographic keys and the management of traffic + flows as dictated by the Security Policy Database (SPD, Section + 4.4.1). + + These protocols may be applied individually or in combination with + each other to provide IPv4 and IPv6 security services. However, most + security requirements can be met through the use of ESP by itself. + Each protocol supports two modes of use: transport mode and tunnel + mode. In transport mode, AH and ESP provide protection primarily for + + + + + +Kent & Seo Standards Track [Page 9] + +RFC 4301 Security Architecture for IP December 2005 + + + next layer protocols; in tunnel mode, AH and ESP are applied to + tunneled IP packets. The differences between the two modes are + discussed in Section 4.1. + + IPsec allows the user (or system administrator) to control the + granularity at which a security service is offered. For example, one + can create a single encrypted tunnel to carry all the traffic between + two security gateways, or a separate encrypted tunnel can be created + for each TCP connection between each pair of hosts communicating + across these gateways. IPsec, through the SPD management paradigm, + incorporates facilities for specifying: + + o which security protocol (AH or ESP) to employ, the mode (transport + or tunnel), security service options, what cryptographic + algorithms to use, and in what combinations to use the specified + protocols and services, and + + o the granularity at which protection should be applied. + + Because most of the security services provided by IPsec require the + use of cryptographic keys, IPsec relies on a separate set of + mechanisms for putting these keys in place. This document requires + support for both manual and automated distribution of keys. It + specifies a specific public-key based approach (IKEv2 [Kau05]) for + automated key management, but other automated key distribution + techniques MAY be used. + + Note: This document mandates support for several features for which + support is available in IKEv2 but not in IKEv1, e.g., negotiation of + an SA representing ranges of local and remote ports or negotiation of + multiple SAs with the same selectors. Therefore, this document + assumes use of IKEv2 or a key and security association management + system with comparable features. + +3.3. Where IPsec Can Be Implemented + + There are many ways in which IPsec may be implemented in a host, or + in conjunction with a router or firewall to create a security + gateway, or as an independent security device. + + a. IPsec may be integrated into the native IP stack. This requires + access to the IP source code and is applicable to both hosts and + security gateways, although native host implementations benefit + the most from this strategy, as explained later (Section 4.4.1, + paragraph 6; Section 4.4.1.1, last paragraph). + + + + + + +Kent & Seo Standards Track [Page 10] + +RFC 4301 Security Architecture for IP December 2005 + + + b. In a "bump-in-the-stack" (BITS) implementation, IPsec is + implemented "underneath" an existing implementation of an IP + protocol stack, between the native IP and the local network + drivers. Source code access for the IP stack is not required in + this context, making this implementation approach appropriate for + use with legacy systems. This approach, when it is adopted, is + usually employed in hosts. + + c. The use of a dedicated, inline security protocol processor is a + common design feature of systems used by the military, and of some + commercial systems as well. It is sometimes referred to as a + "bump-in-the-wire" (BITW) implementation. Such implementations + may be designed to serve either a host or a gateway. Usually, the + BITW device is itself IP addressable. When supporting a single + host, it may be quite analogous to a BITS implementation, but in + supporting a router or firewall, it must operate like a security + gateway. + + This document often talks in terms of use of IPsec by a host or a + security gateway, without regard to whether the implementation is + native, BITS, or BITW. When the distinctions among these + implementation options are significant, the document makes reference + to specific implementation approaches. + + A host implementation of IPsec may appear in devices that might not + be viewed as "hosts". For example, a router might employ IPsec to + protect routing protocols (e.g., BGP) and management functions (e.g., + Telnet), without affecting subscriber traffic traversing the router. + A security gateway might employ separate IPsec implementations to + protect its management traffic and subscriber traffic. The + architecture described in this document is very flexible. For + example, a computer with a full-featured, compliant, native OS IPsec + implementation should be capable of being configured to protect + resident (host) applications and to provide security gateway + protection for traffic traversing the computer. Such configuration + would make use of the forwarding tables and the SPD selection + function described in Sections 5.1 and 5.2. + +4. Security Associations + + This section defines Security Association management requirements for + all IPv6 implementations and for those IPv4 implementations that + implement AH, ESP, or both AH and ESP. The concept of a "Security + Association" (SA) is fundamental to IPsec. Both AH and ESP make use + of SAs, and a major function of IKE is the establishment and + maintenance of SAs. All implementations of AH or ESP MUST support + the concept of an SA as described below. The remainder of this + + + + +Kent & Seo Standards Track [Page 11] + +RFC 4301 Security Architecture for IP December 2005 + + + section describes various aspects of SA management, defining required + characteristics for SA policy management and SA management + techniques. + +4.1. Definition and Scope + + An SA is a simplex "connection" that affords security services to the + traffic carried by it. Security services are afforded to an SA by + the use of AH, or ESP, but not both. If both AH and ESP protection + are applied to a traffic stream, then two SAs must be created and + coordinated to effect protection through iterated application of the + security protocols. To secure typical, bi-directional communication + between two IPsec-enabled systems, a pair of SAs (one in each + direction) is required. IKE explicitly creates SA pairs in + recognition of this common usage requirement. + + For an SA used to carry unicast traffic, the Security Parameters + Index (SPI) by itself suffices to specify an SA. (For information on + the SPI, see Appendix A and the AH and ESP specifications [Ken05b, + Ken05a].) However, as a local matter, an implementation may choose + to use the SPI in conjunction with the IPsec protocol type (AH or + ESP) for SA identification. If an IPsec implementation supports + multicast, then it MUST support multicast SAs using the algorithm + below for mapping inbound IPsec datagrams to SAs. Implementations + that support only unicast traffic need not implement this de- + multiplexing algorithm. + + In many secure multicast architectures, e.g., [RFC3740], a central + Group Controller/Key Server unilaterally assigns the Group Security + Association's (GSA's) SPI. This SPI assignment is not negotiated or + coordinated with the key management (e.g., IKE) subsystems that + reside in the individual end systems that constitute the group. + Consequently, it is possible that a GSA and a unicast SA can + simultaneously use the same SPI. A multicast-capable IPsec + implementation MUST correctly de-multiplex inbound traffic even in + the context of SPI collisions. + + Each entry in the SA Database (SAD) (Section 4.4.2) must indicate + whether the SA lookup makes use of the destination IP address, or the + destination and source IP addresses, in addition to the SPI. For + multicast SAs, the protocol field is not employed for SA lookups. + For each inbound, IPsec-protected packet, an implementation must + conduct its search of the SAD such that it finds the entry that + matches the "longest" SA identifier. In this context, if two or more + SAD entries match based on the SPI value, then the entry that also + matches based on destination address, or destination and source + address (as indicated in the SAD entry) is the "longest" match. This + implies a logical ordering of the SAD search as follows: + + + +Kent & Seo Standards Track [Page 12] + +RFC 4301 Security Architecture for IP December 2005 + + + 1. Search the SAD for a match on the combination of SPI, + destination address, and source address. If an SAD entry + matches, then process the inbound packet with that + matching SAD entry. Otherwise, proceed to step 2. + + 2. Search the SAD for a match on both SPI and destination address. + If the SAD entry matches, then process the inbound packet + with that matching SAD entry. Otherwise, proceed to step 3. + + 3. Search the SAD for a match on only SPI if the receiver has + chosen to maintain a single SPI space for AH and ESP, and on + both SPI and protocol, otherwise. If an SAD entry matches, + then process the inbound packet with that matching SAD entry. + Otherwise, discard the packet and log an auditable event. + + In practice, an implementation may choose any method (or none at all) + to accelerate this search, although its externally visible behavior + MUST be functionally equivalent to having searched the SAD in the + above order. For example, a software-based implementation could + index into a hash table by the SPI. The SAD entries in each hash + table bucket's linked list could be kept sorted to have those SAD + entries with the longest SA identifiers first in that linked list. + Those SAD entries having the shortest SA identifiers could be sorted + so that they are the last entries in the linked list. A + hardware-based implementation may be able to effect the longest match + search intrinsically, using commonly available Ternary + Content-Addressable Memory (TCAM) features. + + The indication of whether source and destination address matching is + required to map inbound IPsec traffic to SAs MUST be set either as a + side effect of manual SA configuration or via negotiation using an SA + management protocol, e.g., IKE or Group Domain of Interpretation + (GDOI) [RFC3547]. Typically, Source-Specific Multicast (SSM) [HC03] + groups use a 3-tuple SA identifier composed of an SPI, a destination + multicast address, and source address. An Any-Source Multicast group + SA requires only an SPI and a destination multicast address as an + identifier. + + If different classes of traffic (distinguished by Differentiated + Services Code Point (DSCP) bits [NiBlBaBL98], [Gro02]) are sent on + the same SA, and if the receiver is employing the optional + anti-replay feature available in both AH and ESP, this could result + in inappropriate discarding of lower priority packets due to the + windowing mechanism used by this feature. Therefore, a sender SHOULD + put traffic of different classes, but with the same selector values, + on different SAs to support Quality of Service (QoS) appropriately. + To permit this, the IPsec implementation MUST permit establishment + and maintenance of multiple SAs between a given sender and receiver, + + + +Kent & Seo Standards Track [Page 13] + +RFC 4301 Security Architecture for IP December 2005 + + + with the same selectors. Distribution of traffic among these + parallel SAs to support QoS is locally determined by the sender and + is not negotiated by IKE. The receiver MUST process the packets from + the different SAs without prejudice. These requirements apply to + both transport and tunnel mode SAs. In the case of tunnel mode SAs, + the DSCP values in question appear in the inner IP header. In + transport mode, the DSCP value might change en route, but this should + not cause problems with respect to IPsec processing since the value + is not employed for SA selection and MUST NOT be checked as part of + SA/packet validation. However, if significant re-ordering of packets + occurs in an SA, e.g., as a result of changes to DSCP values en + route, this may trigger packet discarding by a receiver due to + application of the anti-replay mechanism. + + DISCUSSION: Although the DSCP [NiBlBaBL98, Gro02] and Explicit + Congestion Notification (ECN) [RaFlBl01] fields are not "selectors", + as that term in used in this architecture, the sender will need a + mechanism to direct packets with a given (set of) DSCP values to the + appropriate SA. This mechanism might be termed a "classifier". + + As noted above, two types of SAs are defined: transport mode and + tunnel mode. IKE creates pairs of SAs, so for simplicity, we choose + to require that both SAs in a pair be of the same mode, transport or + tunnel. + + A transport mode SA is an SA typically employed between a pair of + hosts to provide end-to-end security services. When security is + desired between two intermediate systems along a path (vs. end-to-end + use of IPsec), transport mode MAY be used between security gateways + or between a security gateway and a host. In the case where + transport mode is used between security gateways or between a + security gateway and a host, transport mode may be used to support + in-IP tunneling (e.g., IP-in-IP [Per96] or Generic Routing + Encapsulation (GRE) tunneling [FaLiHaMeTr00] or dynamic routing + [ToEgWa04]) over transport mode SAs. To clarify, the use of + transport mode by an intermediate system (e.g., a security gateway) + is permitted only when applied to packets whose source address (for + outbound packets) or destination address (for inbound packets) is an + address belonging to the intermediate system itself. The access + control functions that are an important part of IPsec are + significantly limited in this context, as they cannot be applied to + the end-to-end headers of the packets that traverse a transport mode + SA used in this fashion. Thus, this way of using transport mode + should be evaluated carefully before being employed in a specific + context. + + + + + + +Kent & Seo Standards Track [Page 14] + +RFC 4301 Security Architecture for IP December 2005 + + + In IPv4, a transport mode security protocol header appears + immediately after the IP header and any options, and before any next + layer protocols (e.g., TCP or UDP). In IPv6, the security protocol + header appears after the base IP header and selected extension + headers, but may appear before or after destination options; it MUST + appear before next layer protocols (e.g., TCP, UDP, Stream Control + Transmission Protocol (SCTP)). In the case of ESP, a transport mode + SA provides security services only for these next layer protocols, + not for the IP header or any extension headers preceding the ESP + header. In the case of AH, the protection is also extended to + selected portions of the IP header preceding it, selected portions of + extension headers, and selected options (contained in the IPv4 + header, IPv6 Hop-by-Hop extension header, or IPv6 Destination + extension headers). For more details on the coverage afforded by AH, + see the AH specification [Ken05b]. + + A tunnel mode SA is essentially an SA applied to an IP tunnel, with + the access controls applied to the headers of the traffic inside the + tunnel. Two hosts MAY establish a tunnel mode SA between themselves. + Aside from the two exceptions below, whenever either end of a + security association is a security gateway, the SA MUST be tunnel + mode. Thus, an SA between two security gateways is typically a + tunnel mode SA, as is an SA between a host and a security gateway. + The two exceptions are as follows. + + o Where traffic is destined for a security gateway, e.g., Simple + Network Management Protocol (SNMP) commands, the security gateway + is acting as a host and transport mode is allowed. In this case, + the SA terminates at a host (management) function within a + security gateway and thus merits different treatment. + + o As noted above, security gateways MAY support a transport mode SA + to provide security for IP traffic between two intermediate + systems along a path, e.g., between a host and a security gateway + or between two security gateways. + + Several concerns motivate the use of tunnel mode for an SA involving + a security gateway. For example, if there are multiple paths (e.g., + via different security gateways) to the same destination behind a + security gateway, it is important that an IPsec packet be sent to the + security gateway with which the SA was negotiated. Similarly, a + packet that might be fragmented en route must have all the fragments + delivered to the same IPsec instance for reassembly prior to + cryptographic processing. Also, when a fragment is processed by + IPsec and transmitted, then fragmented en route, it is critical that + there be inner and outer headers to retain the fragmentation state + data for the pre- and post-IPsec packet formats. Hence there are + several reasons for employing tunnel mode when either end of an SA is + + + +Kent & Seo Standards Track [Page 15] + +RFC 4301 Security Architecture for IP December 2005 + + + a security gateway. (Use of an IP-in-IP tunnel in conjunction with + transport mode can also address these fragmentation issues. However, + this configuration limits the ability of IPsec to enforce access + control policies on traffic.) + + Note: AH and ESP cannot be applied using transport mode to IPv4 + packets that are fragments. Only tunnel mode can be employed in such + cases. For IPv6, it would be feasible to carry a plaintext fragment + on a transport mode SA; however, for simplicity, this restriction + also applies to IPv6 packets. See Section 7 for more details on + handling plaintext fragments on the protected side of the IPsec + barrier. + + For a tunnel mode SA, there is an "outer" IP header that specifies + the IPsec processing source and destination, plus an "inner" IP + header that specifies the (apparently) ultimate source and + destination for the packet. The security protocol header appears + after the outer IP header, and before the inner IP header. If AH is + employed in tunnel mode, portions of the outer IP header are afforded + protection (as above), as well as all of the tunneled IP packet + (i.e., all of the inner IP header is protected, as well as next layer + protocols). If ESP is employed, the protection is afforded only to + the tunneled packet, not to the outer header. + + In summary, + + a) A host implementation of IPsec MUST support both transport and + tunnel mode. This is true for native, BITS, and BITW + implementations for hosts. + + b) A security gateway MUST support tunnel mode and MAY support + transport mode. If it supports transport mode, that should be + used only when the security gateway is acting as a host, e.g., for + network management, or to provide security between two + intermediate systems along a path. + +4.2. SA Functionality + + The set of security services offered by an SA depends on the security + protocol selected, the SA mode, the endpoints of the SA, and the + election of optional services within the protocol. + + For example, both AH and ESP offer integrity and authentication + services, but the coverage differs for each protocol and differs for + transport vs. tunnel mode. If the integrity of an IPv4 option or + IPv6 extension header must be protected en route between sender and + receiver, AH can provide this service, except for IP or extension + headers that may change in a fashion not predictable by the sender. + + + +Kent & Seo Standards Track [Page 16] + +RFC 4301 Security Architecture for IP December 2005 + + + However, the same security may be achieved in some contexts by + applying ESP to a tunnel carrying a packet. + + The granularity of access control provided is determined by the + choice of the selectors that define each SA. Moreover, the + authentication means employed by IPsec peers, e.g., during creation + of an IKE (vs. child) SA also affects the granularity of the access + control afforded. + + If confidentiality is selected, then an ESP (tunnel mode) SA between + two security gateways can offer partial traffic flow confidentiality. + The use of tunnel mode allows the inner IP headers to be encrypted, + concealing the identities of the (ultimate) traffic source and + destination. Moreover, ESP payload padding also can be invoked to + hide the size of the packets, further concealing the external + characteristics of the traffic. Similar traffic flow confidentiality + services may be offered when a mobile user is assigned a dynamic IP + address in a dialup context, and establishes a (tunnel mode) ESP SA + to a corporate firewall (acting as a security gateway). Note that + fine-granularity SAs generally are more vulnerable to traffic + analysis than coarse-granularity ones that are carrying traffic from + many subscribers. + + Note: A compliant implementation MUST NOT allow instantiation of an + ESP SA that employs both NULL encryption and no integrity algorithm. + An attempt to negotiate such an SA is an auditable event by both + initiator and responder. The audit log entry for this event SHOULD + include the current date/time, local IKE IP address, and remote IKE + IP address. The initiator SHOULD record the relevant SPD entry. + +4.3. Combining SAs + + This document does not require support for nested security + associations or for what RFC 2401 [RFC2401] called "SA bundles". + These features still can be effected by appropriate configuration of + both the SPD and the local forwarding functions (for inbound and + outbound traffic), but this capability is outside of the IPsec module + and thus the scope of this specification. As a result, management of + nested/bundled SAs is potentially more complex and less assured than + under the model implied by RFC 2401 [RFC2401]. An implementation + that provides support for nested SAs SHOULD provide a management + interface that enables a user or administrator to express the nesting + requirement, and then create the appropriate SPD entries and + forwarding table entries to effect the requisite processing. (See + Appendix E for an example of how to configure nested SAs.) + + + + + + +Kent & Seo Standards Track [Page 17] + +RFC 4301 Security Architecture for IP December 2005 + + +4.4. Major IPsec Databases + + Many of the details associated with processing IP traffic in an IPsec + implementation are largely a local matter, not subject to + standardization. However, some external aspects of the processing + must be standardized to ensure interoperability and to provide a + minimum management capability that is essential for productive use of + IPsec. This section describes a general model for processing IP + traffic relative to IPsec functionality, in support of these + interoperability and functionality goals. The model described below + is nominal; implementations need not match details of this model as + presented, but the external behavior of implementations MUST + correspond to the externally observable characteristics of this model + in order to be compliant. + + There are three nominal databases in this model: the Security Policy + Database (SPD), the Security Association Database (SAD), and the Peer + Authorization Database (PAD). The first specifies the policies that + determine the disposition of all IP traffic inbound or outbound from + a host or security gateway (Section 4.4.1). The second database + contains parameters that are associated with each established (keyed) + SA (Section 4.4.2). The third database, the PAD, provides a link + between an SA management protocol (such as IKE) and the SPD (Section + 4.4.3). + + Multiple Separate IPsec Contexts + + If an IPsec implementation acts as a security gateway for multiple + subscribers, it MAY implement multiple separate IPsec contexts. + Each context MAY have and MAY use completely independent + identities, policies, key management SAs, and/or IPsec SAs. This + is for the most part a local implementation matter. However, a + means for associating inbound (SA) proposals with local contexts + is required. To this end, if supported by the key management + protocol in use, context identifiers MAY be conveyed from + initiator to responder in the signaling messages, with the result + that IPsec SAs are created with a binding to a particular context. + For example, a security gateway that provides VPN service to + multiple customers will be able to associate each customer's + traffic with the correct VPN. + + Forwarding vs Security Decisions + + The IPsec model described here embodies a clear separation between + forwarding (routing) and security decisions, to accommodate a wide + range of contexts where IPsec may be employed. Forwarding may be + trivial, in the case where there are only two interfaces, or it + may be complex, e.g., if the context in which IPsec is implemented + + + +Kent & Seo Standards Track [Page 18] + +RFC 4301 Security Architecture for IP December 2005 + + + employs a sophisticated forwarding function. IPsec assumes only + that outbound and inbound traffic that has passed through IPsec + processing is forwarded in a fashion consistent with the context + in which IPsec is implemented. Support for nested SAs is + optional; if required, it requires coordination between forwarding + tables and SPD entries to cause a packet to traverse the IPsec + boundary more than once. + + "Local" vs "Remote" + + In this document, with respect to IP addresses and ports, the + terms "Local" and "Remote" are used for policy rules. "Local" + refers to the entity being protected by an IPsec implementation, + i.e., the "source" address/port of outbound packets or the + "destination" address/port of inbound packets. "Remote" refers to + a peer entity or peer entities. The terms "source" and + "destination" are used for packet header fields. + + "Non-initial" vs "Initial" Fragments + + Throughout this document, the phrase "non-initial fragments" is + used to mean fragments that do not contain all of the selector + values that may be needed for access control (e.g., they might not + contain Next Layer Protocol, source and destination ports, ICMP + message type/code, Mobility Header type). And the phrase "initial + fragment" is used to mean a fragment that contains all the + selector values needed for access control. However, it should be + noted that for IPv6, which fragment contains the Next Layer + Protocol and ports (or ICMP message type/code or Mobility Header + type [Mobip]) will depend on the kind and number of extension + headers present. The "initial fragment" might not be the first + fragment, in this context. + +4.4.1. The Security Policy Database (SPD) + + An SA is a management construct used to enforce security policy for + traffic crossing the IPsec boundary. Thus, an essential element of + SA processing is an underlying Security Policy Database (SPD) that + specifies what services are to be offered to IP datagrams and in what + fashion. The form of the database and its interface are outside the + scope of this specification. However, this section specifies minimum + management functionality that must be provided, to allow a user or + system administrator to control whether and how IPsec is applied to + traffic transmitted or received by a host or transiting a security + gateway. The SPD, or relevant caches, must be consulted during the + processing of all traffic (inbound and outbound), including traffic + not protected by IPsec, that traverses the IPsec boundary. This + includes IPsec management traffic such as IKE. An IPsec + + + +Kent & Seo Standards Track [Page 19] + +RFC 4301 Security Architecture for IP December 2005 + + + implementation MUST have at least one SPD, and it MAY support + multiple SPDs, if appropriate for the context in which the IPsec + implementation operates. There is no requirement to maintain SPDs on + a per-interface basis, as was specified in RFC 2401 [RFC2401]. + However, if an implementation supports multiple SPDs, then it MUST + include an explicit SPD selection function that is invoked to select + the appropriate SPD for outbound traffic processing. The inputs to + this function are the outbound packet and any local metadata (e.g., + the interface via which the packet arrived) required to effect the + SPD selection function. The output of the function is an SPD + identifier (SPD-ID). + + The SPD is an ordered database, consistent with the use of Access + Control Lists (ACLs) or packet filters in firewalls, routers, etc. + The ordering requirement arises because entries often will overlap + due to the presence of (non-trivial) ranges as values for selectors. + Thus, a user or administrator MUST be able to order the entries to + express a desired access control policy. There is no way to impose a + general, canonical order on SPD entries, because of the allowed use + of wildcards for selector values and because the different types of + selectors are not hierarchically related. + + Processing Choices: DISCARD, BYPASS, PROTECT + + An SPD must discriminate among traffic that is afforded IPsec + protection and traffic that is allowed to bypass IPsec. This + applies to the IPsec protection to be applied by a sender and to + the IPsec protection that must be present at the receiver. For + any outbound or inbound datagram, three processing choices are + possible: DISCARD, BYPASS IPsec, or PROTECT using IPsec. The + first choice refers to traffic that is not allowed to traverse the + IPsec boundary (in the specified direction). The second choice + refers to traffic that is allowed to cross the IPsec boundary + without IPsec protection. The third choice refers to traffic that + is afforded IPsec protection, and for such traffic the SPD must + specify the security protocols to be employed, their mode, + security service options, and the cryptographic algorithms to be + used. + + SPD-S, SPD-I, SPD-O + + An SPD is logically divided into three pieces. The SPD-S (secure + traffic) contains entries for all traffic subject to IPsec + protection. SPD-O (outbound) contains entries for all outbound + traffic that is to be bypassed or discarded. SPD-I (inbound) is + applied to inbound traffic that will be bypassed or discarded. + All three of these can be decorrelated (with the exception noted + above for native host implementations) to facilitate caching. If + + + +Kent & Seo Standards Track [Page 20] + +RFC 4301 Security Architecture for IP December 2005 + + + an IPsec implementation supports only one SPD, then the SPD + consists of all three parts. If multiple SPDs are supported, some + of them may be partial, e.g., some SPDs might contain only SPD-I + entries, to control inbound bypassed traffic on a per-interface + basis. The split allows SPD-I to be consulted without having to + consult SPD-S, for such traffic. Since the SPD-I is just a part + of the SPD, if a packet that is looked up in the SPD-I cannot be + matched to an entry there, then the packet MUST be discarded. + Note that for outbound traffic, if a match is not found in SPD-S, + then SPD-O must be checked to see if the traffic should be + bypassed. Similarly, if SPD-O is checked first and no match is + found, then SPD-S must be checked. In an ordered, + non-decorrelated SPD, the entries for the SPD-S, SPD-I, and SPD-O + are interleaved. So there is one lookup in the SPD. + + SPD Entries + + Each SPD entry specifies packet disposition as BYPASS, DISCARD, or + PROTECT. The entry is keyed by a list of one or more selectors. + The SPD contains an ordered list of these entries. The required + selector types are defined in Section 4.4.1.1. These selectors are + used to define the granularity of the SAs that are created in + response to an outbound packet or in response to a proposal from a + peer. The detailed structure of an SPD entry is described in + Section 4.4.1.2. Every SPD SHOULD have a nominal, final entry that + matches anything that is otherwise unmatched, and discards it. + + The SPD MUST permit a user or administrator to specify policy + entries as follows: + + - SPD-I: For inbound traffic that is to be bypassed or discarded, + the entry consists of the values of the selectors that apply to + the traffic to be bypassed or discarded. + + - SPD-O: For outbound traffic that is to be bypassed or + discarded, the entry consists of the values of the selectors + that apply to the traffic to be bypassed or discarded. + + - SPD-S: For traffic that is to be protected using IPsec, the + entry consists of the values of the selectors that apply to the + traffic to be protected via AH or ESP, controls on how to + create SAs based on these selectors, and the parameters needed + to effect this protection (e.g., algorithms, modes, etc.). Note + that an SPD-S entry also contains information such as "populate + from packet" (PFP) flag (see paragraphs below on "How To Derive + the Values for an SAD entry") and bits indicating whether the + + + + + +Kent & Seo Standards Track [Page 21] + +RFC 4301 Security Architecture for IP December 2005 + + + SA lookup makes use of the local and remote IP addresses in + addition to the SPI (see AH [Ken05b] or ESP [Ken05a] + specifications). + + Representing Directionality in an SPD Entry + + For traffic protected by IPsec, the Local and Remote address and + ports in an SPD entry are swapped to represent directionality, + consistent with IKE conventions. In general, the protocols that + IPsec deals with have the property of requiring symmetric SAs with + flipped Local/Remote IP addresses. However, for ICMP, there is + often no such bi-directional authorization requirement. + Nonetheless, for the sake of uniformity and simplicity, SPD + entries for ICMP are specified in the same way as for other + protocols. Note also that for ICMP, Mobility Header, and + non-initial fragments, there are no port fields in these packets. + ICMP has message type and code and Mobility Header has mobility + header type. Thus, SPD entries have provisions for expressing + access controls appropriate for these protocols, in lieu of the + normal port field controls. For bypassed or discarded traffic, + separate inbound and outbound entries are supported, e.g., to + permit unidirectional flows if required. + + OPAQUE and ANY + + For each selector in an SPD entry, in addition to the literal + values that define a match, there are two special values: ANY and + OPAQUE. ANY is a wildcard that matches any value in the + corresponding field of the packet, or that matches packets where + that field is not present or is obscured. OPAQUE indicates that + the corresponding selector field is not available for examination + because it may not be present in a fragment, it does not exist for + the given Next Layer Protocol, or prior application of IPsec may + have encrypted the value. The ANY value encompasses the OPAQUE + value. Thus, OPAQUE need be used only when it is necessary to + distinguish between the case of any allowed value for a field, vs. + the absence or unavailability (e.g., due to encryption) of the + field. + + How to Derive the Values for an SAD Entry + + For each selector in an SPD entry, the entry specifies how to + derive the corresponding values for a new SA Database (SAD, see + Section 4.4.2) entry from those in the SPD and the packet. The + goal is to allow an SAD entry and an SPD cache entry to be created + based on specific selector values from the packet, or from the + matching SPD entry. For outbound traffic, there are SPD-S cache + entries and SPD-O cache entries. For inbound traffic not + + + +Kent & Seo Standards Track [Page 22] + +RFC 4301 Security Architecture for IP December 2005 + + + protected by IPsec, there are SPD-I cache entries and there is the + SAD, which represents the cache for inbound IPsec-protected + traffic (see Section 4.4.2). If IPsec processing is specified for + an entry, a "populate from packet" (PFP) flag may be asserted for + one or more of the selectors in the SPD entry (Local IP address; + Remote IP address; Next Layer Protocol; and, depending on Next + Layer Protocol, Local port and Remote port, or ICMP type/code, or + Mobility Header type). If asserted for a given selector X, the + flag indicates that the SA to be created should take its value for + X from the value in the packet. Otherwise, the SA should take its + value(s) for X from the value(s) in the SPD entry. Note: In the + non-PFP case, the selector values negotiated by the SA management + protocol (e.g., IKEv2) may be a subset of those in the SPD entry, + depending on the SPD policy of the peer. Also, whether a single + flag is used for, e.g., source port, ICMP type/code, and Mobility + Header (MH) type, or a separate flag is used for each, is a local + matter. + + The following example illustrates the use of the PFP flag in the + context of a security gateway or a BITS/BITW implementation. + Consider an SPD entry where the allowed value for Remote address + is a range of IPv4 addresses: 192.0.2.1 to 192.0.2.10. Suppose an + outbound packet arrives with a destination address of 192.0.2.3, + and there is no extant SA to carry this packet. The value used + for the SA created to transmit this packet could be either of the + two values shown below, depending on what the SPD entry for this + selector says is the source of the selector value: + + PFP flag value example of new + for the Remote SAD dest. address + addr. selector selector value + --------------- ------------ + a. PFP TRUE 192.0.2.3 (one host) + b. PFP FALSE 192.0.2.1 to 192.0.2.10 (range of hosts) + + Note that if the SPD entry above had a value of ANY for the Remote + address, then the SAD selector value would have to be ANY for case + (b), but would still be as illustrated for case (a). Thus, the + PFP flag can be used to prohibit sharing of an SA, even among + packets that match the same SPD entry. + + Management Interface + + For every IPsec implementation, there MUST be a management + interface that allows a user or system administrator to manage the + SPD. The interface must allow the user (or administrator) to + specify the security processing to be applied to every packet that + traverses the IPsec boundary. (In a native host IPsec + + + +Kent & Seo Standards Track [Page 23] + +RFC 4301 Security Architecture for IP December 2005 + + + implementation making use of a socket interface, the SPD may not + need to be consulted on a per-packet basis, as noted at the end of + Section 4.4.1.1 and in Section 5.) The management interface for + the SPD MUST allow creation of entries consistent with the + selectors defined in Section 4.4.1.1, and MUST support (total) + ordering of these entries, as seen via this interface. The SPD + entries' selectors are analogous to the ACL or packet filters + commonly found in a stateless firewall or packet filtering router + and which are currently managed this way. + + In host systems, applications MAY be allowed to create SPD + entries. (The means of signaling such requests to the IPsec + implementation are outside the scope of this standard.) However, + the system administrator MUST be able to specify whether or not a + user or application can override (default) system policies. The + form of the management interface is not specified by this document + and may differ for hosts vs. security gateways, and within hosts + the interface may differ for socket-based vs. BITS + implementations. However, this document does specify a standard + set of SPD elements that all IPsec implementations MUST support. + + Decorrelation + + The processing model described in this document assumes the + ability to decorrelate overlapping SPD entries to permit caching, + which enables more efficient processing of outbound traffic in + security gateways and BITS/BITW implementations. Decorrelation + [CoSa04] is only a means of improving performance and simplifying + the processing description. This RFC does not require a compliant + implementation to make use of decorrelation. For example, native + host implementations typically make use of caching implicitly + because they bind SAs to socket interfaces, and thus there is no + requirement to be able to decorrelate SPD entries in these + implementations. + + Note: Unless otherwise qualified, the use of "SPD" refers to the + body of policy information in both ordered or decorrelated + (unordered) state. Appendix B provides an algorithm that can be + used to decorrelate SPD entries, but any algorithm that produces + equivalent output may be used. Note that when an SPD entry is + decorrelated all the resulting entries MUST be linked together, so + that all members of the group derived from an individual, SPD + entry (prior to decorrelation) can all be placed into caches and + into the SAD at the same time. For example, suppose one starts + with an entry A (from an ordered SPD) that when decorrelated, + yields entries A1, A2, and A3. When a packet comes along that + matches, say A2, and triggers the creation of an SA, the SA + management protocol (e.g., IKEv2) negotiates A. And all 3 + + + +Kent & Seo Standards Track [Page 24] + +RFC 4301 Security Architecture for IP December 2005 + + + decorrelated entries, A1, A2, and A3, are placed in the + appropriate SPD-S cache and linked to the SA. The intent is that + use of a decorrelated SPD ought not to create more SAs than would + have resulted from use of a not-decorrelated SPD. + + If a decorrelated SPD is employed, there are three options for + what an initiator sends to a peer via an SA management protocol + (e.g., IKE). By sending the complete set of linked, decorrelated + entries that were selected from the SPD, a peer is given the best + possible information to enable selection of the appropriate SPD + entry at its end, especially if the peer has also decorrelated its + SPD. However, if a large number of decorrelated entries are + linked, this may create large packets for SA negotiation, and + hence fragmentation problems for the SA management protocol. + + Alternatively, the original entry from the (correlated) SPD may be + retained and passed to the SA management protocol. Passing the + correlated SPD entry keeps the use of a decorrelated SPD a local + matter, not visible to peers, and avoids possible fragmentation + concerns, although it provides less precise information to a + responder for matching against the responder's SPD. + + An intermediate approach is to send a subset of the complete set + of linked, decorrelated SPD entries. This approach can avoid the + fragmentation problems cited above yet provide better information + than the original, correlated entry. The major shortcoming of + this approach is that it may cause additional SAs to be created + later, since only a subset of the linked, decorrelated entries are + sent to a peer. Implementers are free to employ any of the + approaches cited above. + + A responder uses the traffic selector proposals it receives via an + SA management protocol to select an appropriate entry in its SPD. + The intent of the matching is to select an SPD entry and create an + SA that most closely matches the intent of the initiator, so that + traffic traversing the resulting SA will be accepted at both ends. + If the responder employs a decorrelated SPD, it SHOULD use the + decorrelated SPD entries for matching, as this will generally + result in creation of SAs that are more likely to match the intent + of both peers. If the responder has a correlated SPD, then it + SHOULD match the proposals against the correlated entries. For + IKEv2, use of a decorrelated SPD offers the best opportunity for a + responder to generate a "narrowed" response. + + In all cases, when a decorrelated SPD is available, the + decorrelated entries are used to populate the SPD-S cache. If the + SPD is not decorrelated, caching is not allowed and an ordered + + + + +Kent & Seo Standards Track [Page 25] + +RFC 4301 Security Architecture for IP December 2005 + + + search of SPD MUST be performed to verify that inbound traffic + arriving on an SA is consistent with the access control policy + expressed in the SPD. + + Handling Changes to the SPD While the System Is Running + + If a change is made to the SPD while the system is running, a + check SHOULD be made of the effect of this change on extant SAs. + An implementation SHOULD check the impact of an SPD change on + extant SAs and SHOULD provide a user/administrator with a + mechanism for configuring what actions to take, e.g., delete an + affected SA, allow an affected SA to continue unchanged, etc. + +4.4.1.1. Selectors + + An SA may be fine-grained or coarse-grained, depending on the + selectors used to define the set of traffic for the SA. For example, + all traffic between two hosts may be carried via a single SA, and + afforded a uniform set of security services. Alternatively, traffic + between a pair of hosts might be spread over multiple SAs, depending + on the applications being used (as defined by the Next Layer Protocol + and related fields, e.g., ports), with different security services + offered by different SAs. Similarly, all traffic between a pair of + security gateways could be carried on a single SA, or one SA could be + assigned for each communicating host pair. The following selector + parameters MUST be supported by all IPsec implementations to + facilitate control of SA granularity. Note that both Local and + Remote addresses should either be IPv4 or IPv6, but not a mix of + address types. Also, note that the Local/Remote port selectors (and + ICMP message type and code, and Mobility Header type) may be labeled + as OPAQUE to accommodate situations where these fields are + inaccessible due to packet fragmentation. + + - Remote IP Address(es) (IPv4 or IPv6): This is a list of ranges + of IP addresses (unicast, broadcast (IPv4 only)). This + structure allows expression of a single IP address (via a + trivial range), or a list of addresses (each a trivial range), + or a range of addresses (low and high values, inclusive), as + well as the most generic form of a list of ranges. Address + ranges are used to support more than one remote system sharing + the same SA, e.g., behind a security gateway. + + - Local IP Address(es) (IPv4 or IPv6): This is a list of ranges of + IP addresses (unicast, broadcast (IPv4 only)). This structure + allows expression of a single IP address (via a trivial range), + or a list of addresses (each a trivial range), or a range of + addresses (low and high values, inclusive), as well as the most + generic form of a list of ranges. Address ranges are used to + + + +Kent & Seo Standards Track [Page 26] + +RFC 4301 Security Architecture for IP December 2005 + + + support more than one source system sharing the same SA, e.g., + behind a security gateway. Local refers to the address(es) + being protected by this implementation (or policy entry). + + Note: The SPD does not include support for multicast address + entries. To support multicast SAs, an implementation should + make use of a Group SPD (GSPD) as defined in [RFC3740]. GSPD + entries require a different structure, i.e., one cannot use the + symmetric relationship associated with local and remote address + values for unicast SAs in a multicast context. Specifically, + outbound traffic directed to a multicast address on an SA would + not be received on a companion, inbound SA with the multicast + address as the source. + + - Next Layer Protocol: Obtained from the IPv4 "Protocol" or the + IPv6 "Next Header" fields. This is an individual protocol + number, ANY, or for IPv6 only, OPAQUE. The Next Layer Protocol + is whatever comes after any IP extension headers that are + present. To simplify locating the Next Layer Protocol, there + SHOULD be a mechanism for configuring which IPv6 extension + headers to skip. The default configuration for which protocols + to skip SHOULD include the following protocols: 0 (Hop-by-hop + options), 43 (Routing Header), 44 (Fragmentation Header), and 60 + (Destination Options). Note: The default list does NOT include + 51 (AH) or 50 (ESP). From a selector lookup point of view, + IPsec treats AH and ESP as Next Layer Protocols. + + Several additional selectors depend on the Next Layer Protocol + value: + + * If the Next Layer Protocol uses two ports (as do TCP, UDP, + SCTP, and others), then there are selectors for Local and + Remote Ports. Each of these selectors has a list of ranges + of values. Note that the Local and Remote ports may not be + available in the case of receipt of a fragmented packet or if + the port fields have been protected by IPsec (encrypted); + thus, a value of OPAQUE also MUST be supported. Note: In a + non-initial fragment, port values will not be available. If + a port selector specifies a value other than ANY or OPAQUE, + it cannot match packets that are non-initial fragments. If + the SA requires a port value other than ANY or OPAQUE, an + arriving fragment without ports MUST be discarded. (See + Section 7, "Handling Fragments".) + + * If the Next Layer Protocol is a Mobility Header, then there + is a selector for IPv6 Mobility Header message type (MH type) + [Mobip]. This is an 8-bit value that identifies a particular + mobility message. Note that the MH type may not be available + + + +Kent & Seo Standards Track [Page 27] + +RFC 4301 Security Architecture for IP December 2005 + + + in the case of receipt of a fragmented packet. (See Section + 7, "Handling Fragments".) For IKE, the IPv6 Mobility Header + message type (MH type) is placed in the most significant + eight bits of the 16-bit local "port" selector. + + * If the Next Layer Protocol value is ICMP, then there is a + 16-bit selector for the ICMP message type and code. The + message type is a single 8-bit value, which defines the type + of an ICMP message, or ANY. The ICMP code is a single 8-bit + value that defines a specific subtype for an ICMP message. + For IKE, the message type is placed in the most significant 8 + bits of the 16-bit selector and the code is placed in the + least significant 8 bits. This 16-bit selector can contain a + single type and a range of codes, a single type and ANY code, + and ANY type and ANY code. Given a policy entry with a range + of Types (T-start to T-end) and a range of Codes (C-start to + C-end), and an ICMP packet with Type t and Code c, an + implementation MUST test for a match using + + (T-start*256) + C-start <= (t*256) + c <= (T-end*256) + + C-end + + Note that the ICMP message type and code may not be available + in the case of receipt of a fragmented packet. (See Section + 7, "Handling Fragments".) + + - Name: This is not a selector like the others above. It is not + acquired from a packet. A name may be used as a symbolic + identifier for an IPsec Local or Remote address. Named SPD + entries are used in two ways: + + 1. A named SPD entry is used by a responder (not an initiator) + in support of access control when an IP address would not be + appropriate for the Remote IP address selector, e.g., for + "road warriors". The name used to match this field is + communicated during the IKE negotiation in the ID payload. + In this context, the initiator's Source IP address (inner IP + header in tunnel mode) is bound to the Remote IP address in + the SAD entry created by the IKE negotiation. This address + overrides the Remote IP address value in the SPD, when the + SPD entry is selected in this fashion. All IPsec + implementations MUST support this use of names. + + 2. A named SPD entry may be used by an initiator to identify a + user for whom an IPsec SA will be created (or for whom + traffic may be bypassed). The initiator's IP source address + (from inner IP header in tunnel mode) is used to replace the + following if and when they are created: + + + +Kent & Seo Standards Track [Page 28] + +RFC 4301 Security Architecture for IP December 2005 + + + - local address in the SPD cache entry + - local address in the outbound SAD entry + - remote address in the inbound SAD entry + + Support for this use is optional for multi-user, native host + implementations and not applicable to other implementations. + Note that this name is used only locally; it is not + communicated by the key management protocol. Also, name + forms other than those used for case 1 above (responder) are + applicable in the initiator context (see below). + + An SPD entry can contain both a name (or a list of names) and + also values for the Local or Remote IP address. + + For case 1, responder, the identifiers employed in named SPD + entries are one of the following four types: + + a. a fully qualified user name string (email), e.g., + mozart@foo.example.com + (this corresponds to ID_RFC822_ADDR in IKEv2) + + b. a fully qualified DNS name, e.g., + foo.example.com + (this corresponds to ID_FQDN in IKEv2) + + c. X.500 distinguished name, e.g., [WaKiHo97], + CN = Stephen T. Kent, O = BBN Technologies, + SP = MA, C = US + (this corresponds to ID_DER_ASN1_DN in IKEv2, after + decoding) + + d. a byte string + (this corresponds to Key_ID in IKEv2) + + For case 2, initiator, the identifiers employed in named SPD + entries are of type byte string. They are likely to be Unix + UIDs, Windows security IDs, or something similar, but could + also be a user name or account name. In all cases, this + identifier is only of local concern and is not transmitted. + + The IPsec implementation context determines how selectors are used. + For example, a native host implementation typically makes use of a + socket interface. When a new connection is established, the SPD can + be consulted and an SA bound to the socket. Thus, traffic sent via + that socket need not result in additional lookups to the SPD (SPD-O + and SPD-S) cache. In contrast, a BITS, BITW, or security gateway + implementation needs to look at each packet and perform an + SPD-O/SPD-S cache lookup based on the selectors. + + + +Kent & Seo Standards Track [Page 29] + +RFC 4301 Security Architecture for IP December 2005 + + +4.4.1.2. Structure of an SPD Entry + + This section contains a prose description of an SPD entry. Also, + Appendix C provides an example of an ASN.1 definition of an SPD + entry. + + This text describes the SPD in a fashion that is intended to map + directly into IKE payloads to ensure that the policy required by SPD + entries can be negotiated through IKE. Unfortunately, the semantics + of the version of IKEv2 published concurrently with this document + [Kau05] do not align precisely with those defined for the SPD. + Specifically, IKEv2 does not enable negotiation of a single SA that + binds multiple pairs of local and remote addresses and ports to a + single SA. Instead, when multiple local and remote addresses and + ports are negotiated for an SA, IKEv2 treats these not as pairs, but + as (unordered) sets of local and remote values that can be + arbitrarily paired. Until IKE provides a facility that conveys the + semantics that are expressed in the SPD via selector sets (as + described below), users MUST NOT include multiple selector sets in a + single SPD entry unless the access control intent aligns with the IKE + "mix and match" semantics. An implementation MAY warn users, to + alert them to this problem if users create SPD entries with multiple + selector sets, the syntax of which indicates possible conflicts with + current IKE semantics. + + The management GUI can offer the user other forms of data entry and + display, e.g., the option of using address prefixes as well as + ranges, and symbolic names for protocols, ports, etc. (Do not confuse + the use of symbolic names in a management interface with the SPD + selector "Name".) Note that Remote/Local apply only to IP addresses + and ports, not to ICMP message type/code or Mobility Header type. + Also, if the reserved, symbolic selector value OPAQUE or ANY is + employed for a given selector type, only that value may appear in the + list for that selector, and it must appear only once in the list for + that selector. Note that ANY and OPAQUE are local syntax conventions + -- IKEv2 negotiates these values via the ranges indicated below: + + ANY: start = 0 end = + OPAQUE: start = end = 0 + + An SPD is an ordered list of entries each of which contains the + following fields. + + o Name -- a list of IDs. This quasi-selector is optional. + The forms that MUST be supported are described above in + Section 4.4.1.1 under "Name". + + + + + +Kent & Seo Standards Track [Page 30] + +RFC 4301 Security Architecture for IP December 2005 + + + o PFP flags -- one per traffic selector. A given flag, e.g., + for Next Layer Protocol, applies to the relevant selector + across all "selector sets" (see below) contained in an SPD + entry. When creating an SA, each flag specifies for the + corresponding traffic selector whether to instantiate the + selector from the corresponding field in the packet that + triggered the creation of the SA or from the value(s) in + the corresponding SPD entry (see Section 4.4.1, "How to + Derive the Values for an SAD Entry"). Whether a single + flag is used for, e.g., source port, ICMP type/code, and + MH type, or a separate flag is used for each, is a local + matter. There are PFP flags for: + - Local Address + - Remote Address + - Next Layer Protocol + - Local Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + - Remote Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + + o One to N selector sets that correspond to the "condition" + for applying a particular IPsec action. Each selector set + contains: + - Local Address + - Remote Address + - Next Layer Protocol + - Local Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + - Remote Port, or ICMP message type/code or Mobility + Header type (depending on the next layer protocol) + + Note: The "next protocol" selector is an individual value + (unlike the local and remote IP addresses) in a selector + set entry. This is consistent with how IKEv2 negotiates + the Traffic Selector (TS) values for an SA. It also makes + sense because one may need to associate different port + fields with different protocols. It is possible to + associate multiple protocols (and ports) with a single SA + by specifying multiple selector sets for that SA. + + o Processing info -- which action is required -- PROTECT, + BYPASS, or DISCARD. There is just one action that goes + with all the selector sets, not a separate action for each + set. If the required processing is PROTECT, the entry + contains the following information. + - IPsec mode -- tunnel or transport + + + + + +Kent & Seo Standards Track [Page 31] + +RFC 4301 Security Architecture for IP December 2005 + + + - (if tunnel mode) local tunnel address -- For a + non-mobile host, if there is just one interface, this + is straightforward; if there are multiple + interfaces, this must be statically configured. For a + mobile host, the specification of the local address + is handled externally to IPsec. + - (if tunnel mode) remote tunnel address -- There is no + standard way to determine this. See 4.5.3, "Locating + a Security Gateway". + - Extended Sequence Number -- Is this SA using extended + sequence numbers? + - stateful fragment checking -- Is this SA using + stateful fragment checking? (See Section 7 for more + details.) + - Bypass DF bit (T/F) -- applicable to tunnel mode SAs + - Bypass DSCP (T/F) or map to unprotected DSCP values + (array) if needed to restrict bypass of DSCP values -- + applicable to tunnel mode SAs + - IPsec protocol -- AH or ESP + - algorithms -- which ones to use for AH, which ones to + use for ESP, which ones to use for combined mode, + ordered by decreasing priority + + It is a local matter as to what information is kept with regard to + handling extant SAs when the SPD is changed. + +4.4.1.3. More Regarding Fields Associated with Next Layer Protocols + + Additional selectors are often associated with fields in the Next + Layer Protocol header. A particular Next Layer Protocol can have + zero, one, or two selectors. There may be situations where there + aren't both local and remote selectors for the fields that are + dependent on the Next Layer Protocol. The IPv6 Mobility Header has + only a Mobility Header message type. AH and ESP have no further + selector fields. A system may be willing to send an ICMP message + type and code that it does not want to receive. In the descriptions + below, "port" is used to mean a field that is dependent on the Next + Layer Protocol. + + A. If a Next Layer Protocol has no "port" selectors, then + the Local and Remote "port" selectors are set to OPAQUE in + the relevant SPD entry, e.g., + + Local's + next layer protocol = AH + "port" selector = OPAQUE + + + + + +Kent & Seo Standards Track [Page 32] + +RFC 4301 Security Architecture for IP December 2005 + + + Remote's + next layer protocol = AH + "port" selector = OPAQUE + + B. Even if a Next Layer Protocol has only one selector, e.g., + Mobility Header type, then the Local and Remote "port" + selectors are used to indicate whether a system is + willing to send and/or receive traffic with the specified + "port" values. For example, if Mobility Headers of a + specified type are allowed to be sent and received via an + SA, then the relevant SPD entry would be set as follows: + + Local's + next layer protocol = Mobility Header + "port" selector = Mobility Header message type + + Remote's + next layer protocol = Mobility Header + "port" selector = Mobility Header message type + + If Mobility Headers of a specified type are allowed to be + sent but NOT received via an SA, then the relevant SPD + entry would be set as follows: + + Local's + next layer protocol = Mobility Header + "port" selector = Mobility Header message type + + Remote's + next layer protocol = Mobility Header + "port" selector = OPAQUE + + If Mobility Headers of a specified type are allowed to be + received but NOT sent via an SA, then the relevant SPD + entry would be set as follows: + + Local's + next layer protocol = Mobility Header + "port" selector = OPAQUE + + Remote's + next layer protocol = Mobility Header + "port" selector = Mobility Header message type + + C. If a system is willing to send traffic with a particular + "port" value but NOT receive traffic with that kind of + port value, the system's traffic selectors are set as + follows in the relevant SPD entry: + + + +Kent & Seo Standards Track [Page 33] + +RFC 4301 Security Architecture for IP December 2005 + + + Local's + next layer protocol = ICMP + "port" selector = + + Remote's + next layer protocol = ICMP + "port" selector = OPAQUE + + D. To indicate that a system is willing to receive traffic + with a particular "port" value but NOT send that kind of + traffic, the system's traffic selectors are set as follows + in the relevant SPD entry: + + Local's + next layer protocol = ICMP + "port" selector = OPAQUE + + Remote's + next layer protocol = ICMP + "port" selector = + + For example, if a security gateway is willing to allow + systems behind it to send ICMP traceroutes, but is not + willing to let outside systems run ICMP traceroutes to + systems behind it, then the security gateway's traffic + selectors are set as follows in the relevant SPD entry: + + Local's + next layer protocol = 1 (ICMPv4) + "port" selector = 30 (traceroute) + + Remote's + next layer protocol = 1 (ICMPv4) + "port" selector = OPAQUE + +4.4.2. Security Association Database (SAD) + + In each IPsec implementation, there is a nominal Security Association + Database (SAD), in which each entry defines the parameters associated + with one SA. Each SA has an entry in the SAD. For outbound + processing, each SAD entry is pointed to by entries in the SPD-S part + of the SPD cache. For inbound processing, for unicast SAs, the SPI + is used either alone to look up an SA or in conjunction with the + IPsec protocol type. If an IPsec implementation supports multicast, + the SPI plus destination address, or SPI plus destination and source + addresses are used to look up the SA. (See Section 4.1 for details on + the algorithm that MUST be used for mapping inbound IPsec datagrams + to SAs.) The following parameters are associated with each entry in + + + +Kent & Seo Standards Track [Page 34] + +RFC 4301 Security Architecture for IP December 2005 + + + the SAD. They should all be present except where otherwise noted, + e.g., AH Authentication algorithm. This description does not purport + to be a MIB, only a specification of the minimal data items required + to support an SA in an IPsec implementation. + + For each of the selectors defined in Section 4.4.1.1, the entry for + an inbound SA in the SAD MUST be initially populated with the value + or values negotiated at the time the SA was created. (See the + paragraph in Section 4.4.1 under "Handling Changes to the SPD while + the System is Running" for guidance on the effect of SPD changes on + extant SAs.) For a receiver, these values are used to check that the + header fields of an inbound packet (after IPsec processing) match the + selector values negotiated for the SA. Thus, the SAD acts as a cache + for checking the selectors of inbound traffic arriving on SAs. For + the receiver, this is part of verifying that a packet arriving on an + SA is consistent with the policy for the SA. (See Section 6 for rules + for ICMP messages.) These fields can have the form of specific + values, ranges, ANY, or OPAQUE, as described in Section 4.4.1.1, + "Selectors". Note also that there are a couple of situations in + which the SAD can have entries for SAs that do not have corresponding + entries in the SPD. Since this document does not mandate that the + SAD be selectively cleared when the SPD is changed, SAD entries can + remain when the SPD entries that created them are changed or deleted. + Also, if a manually keyed SA is created, there could be an SAD entry + for this SA that does not correspond to any SPD entry. + + Note: The SAD can support multicast SAs, if manually configured. An + outbound multicast SA has the same structure as a unicast SA. The + source address is that of the sender, and the destination address is + the multicast group address. An inbound, multicast SA must be + configured with the source addresses of each peer authorized to + transmit to the multicast SA in question. The SPI value for a + multicast SA is provided by a multicast group controller, not by the + receiver, as for a unicast SA. Because an SAD entry may be required + to accommodate multiple, individual IP source addresses that were + part of an SPD entry (for unicast SAs), the required facility for + inbound, multicast SAs is a feature already present in an IPsec + implementation. However, because the SPD has no provisions for + accommodating multicast entries, this document does not specify an + automated way to create an SAD entry for a multicast, inbound SA. + Only manually configured SAD entries can be created to accommodate + inbound, multicast traffic. + + Implementation Guidance: This document does not specify how an SPD-S + entry refers to the corresponding SAD entry, as this is an + implementation-specific detail. However, some implementations (based + on experience from RFC 2401) are known to have problems in this + regard. In particular, simply storing the (remote tunnel header IP + + + +Kent & Seo Standards Track [Page 35] + +RFC 4301 Security Architecture for IP December 2005 + + + address, remote SPI) pair in the SPD cache is not sufficient, since + the pair does not always uniquely identify a single SAD entry. For + instance, two hosts behind the same NAT could choose the same SPI + value. The situation also may arise if a host is assigned an IP + address (e.g., via DHCP) previously used by some other host, and the + SAs associated with the old host have not yet been deleted via dead + peer detection mechanisms. This may lead to packets being sent over + the wrong SA or, if key management ensures the pair is unique, + denying the creation of otherwise valid SAs. Thus, implementors + should implement links between the SPD cache and the SAD in a way + that does not engender such problems. + +4.4.2.1. Data Items in the SAD + + The following data items MUST be in the SAD: + + o Security Parameter Index (SPI): a 32-bit value selected by the + receiving end of an SA to uniquely identify the SA. In an SAD + entry for an outbound SA, the SPI is used to construct the + packet's AH or ESP header. In an SAD entry for an inbound SA, the + SPI is used to map traffic to the appropriate SA (see text on + unicast/multicast in Section 4.1). + + o Sequence Number Counter: a 64-bit counter used to generate the + Sequence Number field in AH or ESP headers. 64-bit sequence + numbers are the default, but 32-bit sequence numbers are also + supported if negotiated. + + o Sequence Counter Overflow: a flag indicating whether overflow of + the sequence number counter should generate an auditable event and + prevent transmission of additional packets on the SA, or whether + rollover is permitted. The audit log entry for this event SHOULD + include the SPI value, current date/time, Local Address, Remote + Address, and the selectors from the relevant SAD entry. + + o Anti-Replay Window: a 64-bit counter and a bit-map (or equivalent) + used to determine whether an inbound AH or ESP packet is a replay. + + Note: If anti-replay has been disabled by the receiver for an SA, + e.g., in the case of a manually keyed SA, then the Anti-Replay + Window is ignored for the SA in question. 64-bit sequence numbers + are the default, but this counter size accommodates 32-bit + sequence numbers as well. + + o AH Authentication algorithm, key, etc. This is required only if + AH is supported. + + + + + +Kent & Seo Standards Track [Page 36] + +RFC 4301 Security Architecture for IP December 2005 + + + o ESP Encryption algorithm, key, mode, IV, etc. If a combined mode + algorithm is used, these fields will not be applicable. + + o ESP integrity algorithm, keys, etc. If the integrity service is + not selected, these fields will not be applicable. If a combined + mode algorithm is used, these fields will not be applicable. + + o ESP combined mode algorithms, key(s), etc. This data is used when + a combined mode (encryption and integrity) algorithm is used with + ESP. If a combined mode algorithm is not used, these fields are + not applicable. + + o Lifetime of this SA: a time interval after which an SA must be + replaced with a new SA (and new SPI) or terminated, plus an + indication of which of these actions should occur. This may be + expressed as a time or byte count, or a simultaneous use of both + with the first lifetime to expire taking precedence. A compliant + implementation MUST support both types of lifetimes, and MUST + support a simultaneous use of both. If time is employed, and if + IKE employs X.509 certificates for SA establishment, the SA + lifetime must be constrained by the validity intervals of the + certificates, and the NextIssueDate of the Certificate Revocation + Lists (CRLs) used in the IKE exchange for the SA. Both initiator + and responder are responsible for constraining the SA lifetime in + this fashion. Note: The details of how to handle the refreshing + of keys when SAs expire is a local matter. However, one + reasonable approach is: + + (a) If byte count is used, then the implementation SHOULD count the + number of bytes to which the IPsec cryptographic algorithm is + applied. For ESP, this is the encryption algorithm (including + Null encryption) and for AH, this is the authentication + algorithm. This includes pad bytes, etc. Note that + implementations MUST be able to handle having the counters at + the ends of an SA get out of synch, e.g., because of packet + loss or because the implementations at each end of the SA + aren't doing things the same way. + + (b) There SHOULD be two kinds of lifetime -- a soft lifetime that + warns the implementation to initiate action such as setting up + a replacement SA, and a hard lifetime when the current SA ends + and is destroyed. + + (c) If the entire packet does not get delivered during the SA's + lifetime, the packet SHOULD be discarded. + + o IPsec protocol mode: tunnel or transport. Indicates which mode of + AH or ESP is applied to traffic on this SA. + + + +Kent & Seo Standards Track [Page 37] + +RFC 4301 Security Architecture for IP December 2005 + + + o Stateful fragment checking flag. Indicates whether or not + stateful fragment checking applies to this SA. + + o Bypass DF bit (T/F) -- applicable to tunnel mode SAs where both + inner and outer headers are IPv4. + + o DSCP values -- the set of DSCP values allowed for packets carried + over this SA. If no values are specified, no DSCP-specific + filtering is applied. If one or more values are specified, these + are used to select one SA among several that match the traffic + selectors for an outbound packet. Note that these values are NOT + checked against inbound traffic arriving on the SA. + + o Bypass DSCP (T/F) or map to unprotected DSCP values (array) if + needed to restrict bypass of DSCP values -- applicable to tunnel + mode SAs. This feature maps DSCP values from an inner header to + values in an outer header, e.g., to address covert channel + signaling concerns. + + o Path MTU: any observed path MTU and aging variables. + + o Tunnel header IP source and destination address -- both addresses + must be either IPv4 or IPv6 addresses. The version implies the + type of IP header to be used. Only used when the IPsec protocol + mode is tunnel. + +4.4.2.2. Relationship between SPD, PFP flag, packet, and SAD + + For each selector, the following tables show the relationship + between the value in the SPD, the PFP flag, the value in the + triggering packet, and the resulting value in the SAD. Note that + the administrative interface for IPsec can use various syntactic + options to make it easier for the administrator to enter rules. + For example, although a list of ranges is what IKEv2 sends, it + might be clearer and less error prone for the user to enter a + single IP address or IP address prefix. + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 38] + +RFC 4301 Security Architecture for IP December 2005 + + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + loc addr list of ranges 0 IP addr "S" list of ranges + ANY 0 IP addr "S" ANY + list of ranges 1 IP addr "S" "S" + ANY 1 IP addr "S" "S" + + rem addr list of ranges 0 IP addr "D" list of ranges + ANY 0 IP addr "D" ANY + list of ranges 1 IP addr "D" "D" + ANY 1 IP addr "D" "D" + + protocol list of prot's* 0 prot. "P" list of prot's* + ANY** 0 prot. "P" ANY + OPAQUE**** 0 prot. "P" OPAQUE + + list of prot's* 0 not avail. discard packet + ANY** 0 not avail. ANY + OPAQUE**** 0 not avail. OPAQUE + + list of prot's* 1 prot. "P" "P" + ANY** 1 prot. "P" "P" + OPAQUE**** 1 prot. "P" *** + + list of prot's* 1 not avail. discard packet + ANY** 1 not avail. discard packet + OPAQUE**** 1 not avail. *** + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 39] + +RFC 4301 Security Architecture for IP December 2005 + + + If the protocol is one that has two ports, then there will be + selectors for both Local and Remote ports. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + loc port list of ranges 0 src port "s" list of ranges + ANY 0 src port "s" ANY + OPAQUE 0 src port "s" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 src port "s" "s" + ANY 1 src port "s" "s" + OPAQUE 1 src port "s" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + rem port list of ranges 0 dst port "d" list of ranges + ANY 0 dst port "d" ANY + OPAQUE 0 dst port "d" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 dst port "d" "d" + ANY 1 dst port "d" "d" + OPAQUE 1 dst port "d" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + + + + + + + + + + +Kent & Seo Standards Track [Page 40] + +RFC 4301 Security Architecture for IP December 2005 + + + If the protocol is mobility header, then there will be a selector + for mh type. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + -------- ---------------- --- ------------ -------------- + mh type list of ranges 0 mh type "T" list of ranges + ANY 0 mh type "T" ANY + OPAQUE 0 mh type "T" OPAQUE + + list of ranges 0 not avail. discard packet + ANY 0 not avail. ANY + OPAQUE 0 not avail. OPAQUE + + list of ranges 1 mh type "T" "T" + ANY 1 mh type "T" "T" + OPAQUE 1 mh type "T" *** + + list of ranges 1 not avail. discard packet + ANY 1 not avail. discard packet + OPAQUE 1 not avail. *** + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 41] + +RFC 4301 Security Architecture for IP December 2005 + + + If the protocol is ICMP, then there will be a 16-bit selector for + ICMP type and ICMP code. Note that the type and code are bound to + each other, i.e., the codes apply to the particular type. This + 16-bit selector can contain a single type and a range of codes, a + single type and ANY code, and ANY type and ANY code. + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + --------- ---------------- --- ------------ -------------- + ICMP type a single type & 0 type "t" & single type & + and code range of codes code "c" range of codes + a single type & 0 type "t" & single type & + ANY code code "c" ANY code + ANY type & ANY 0 type "t" & ANY type & + code code "c" ANY code + OPAQUE 0 type "t" & OPAQUE + code "c" + + a single type & 0 not avail. discard packet + range of codes + a single type & 0 not avail. discard packet + ANY code + ANY type & 0 not avail. ANY type & + ANY code ANY code + OPAQUE 0 not avail. OPAQUE + + a single type & 1 type "t" & "t" and "c" + range of codes code "c" + a single type & 1 type "t" & "t" and "c" + ANY code code "c" + ANY type & 1 type "t" & "t" and "c" + ANY code code "c" + OPAQUE 1 type "t" & *** + code "c" + + a single type & 1 not avail. discard packet + range of codes + a single type & 1 not avail. discard packet + ANY code + ANY type & 1 not avail. discard packet + ANY code + OPAQUE 1 not avail. *** + + + + + + + + +Kent & Seo Standards Track [Page 42] + +RFC 4301 Security Architecture for IP December 2005 + + + If the name selector is used: + + Value in + Triggering Resulting SAD + Selector SPD Entry PFP Packet Entry + --------- ---------------- --- ------------ -------------- + name list of user or N/A N/A N/A + system names + + * "List of protocols" is the information, not the way + that the SPD or SAD or IKEv2 have to represent this + information. + ** 0 (zero) is used by IKE to indicate ANY for + protocol. + *** Use of PFP=1 with an OPAQUE value is an error and + SHOULD be prohibited by an IPsec implementation. + **** The protocol field cannot be OPAQUE in IPv4. This + table entry applies only to IPv6. + +4.4.3. Peer Authorization Database (PAD) + + The Peer Authorization Database (PAD) provides the link between the + SPD and a security association management protocol such as IKE. It + embodies several critical functions: + + o identifies the peers or groups of peers that are authorized + to communicate with this IPsec entity + o specifies the protocol and method used to authenticate each + peer + o provides the authentication data for each peer + o constrains the types and values of IDs that can be asserted + by a peer with regard to child SA creation, to ensure that the + peer does not assert identities for lookup in the SPD that it + is not authorized to represent, when child SAs are created + o peer gateway location info, e.g., IP address(es) or DNS names, + MAY be included for peers that are known to be "behind" a + security gateway + + The PAD provides these functions for an IKE peer when the peer acts + as either the initiator or the responder. + + To perform these functions, the PAD contains an entry for each peer + or group of peers with which the IPsec entity will communicate. An + entry names an individual peer (a user, end system or security + gateway) or specifies a group of peers (using ID matching rules + defined below). The entry specifies the authentication protocol + (e.g., IKEv1, IKEv2, KINK) method used (e.g., certificates or pre- + shared secrets) and the authentication data (e.g., the pre-shared + + + +Kent & Seo Standards Track [Page 43] + +RFC 4301 Security Architecture for IP December 2005 + + + secret or the trust anchor relative to which the peer's certificate + will be validated). For certificate-based authentication, the entry + also may provide information to assist in verifying the revocation + status of the peer, e.g., a pointer to a CRL repository or the name + of an Online Certificate Status Protocol (OCSP) server associated + with the peer or with the trust anchor associated with the peer. + + Each entry also specifies whether the IKE ID payload will be used as + a symbolic name for SPD lookup, or whether the remote IP address + provided in traffic selector payloads will be used for SPD lookups + when child SAs are created. + + Note that the PAD information MAY be used to support creation of more + than one tunnel mode SA at a time between two peers, e.g., two + tunnels to protect the same addresses/hosts, but with different + tunnel endpoints. + +4.4.3.1. PAD Entry IDs and Matching Rules + + The PAD is an ordered database, where the order is defined by an + administrator (or a user in the case of a single-user end system). + Usually, the same administrator will be responsible for both the PAD + and SPD, since the two databases must be coordinated. The ordering + requirement for the PAD arises for the same reason as for the SPD, + i.e., because use of "star name" entries allows for overlaps in the + set of IKE IDs that could match a specific entry. + + Six types of IDs are supported for entries in the PAD, consistent + with the symbolic name types and IP addresses used to identify SPD + entries. The ID for each entry acts as the index for the PAD, i.e., + it is the value used to select an entry. All of these ID types can + be used to match IKE ID payload types. The six types are: + + o DNS name (specific or partial) + o Distinguished Name (complete or sub-tree constrained) + o RFC 822 email address (complete or partially qualified) + o IPv4 address (range) + o IPv6 address (range) + o Key ID (exact match only) + + The first three name types can accommodate sub-tree matching as well + as exact matches. A DNS name may be fully qualified and thus match + exactly one name, e.g., foo.example.com. Alternatively, the name may + encompass a group of peers by being partially specified, e.g., the + string ".example.com" could be used to match any DNS name ending in + these two domain name components. + + + + + +Kent & Seo Standards Track [Page 44] + +RFC 4301 Security Architecture for IP December 2005 + + + Similarly, a Distinguished Name may specify a complete Distinguished + Name to match exactly one entry, e.g., CN = Stephen, O = BBN + Technologies, SP = MA, C = US. Alternatively, an entry may encompass + a group of peers by specifying a sub-tree, e.g., an entry of the form + "C = US, SP = MA" might be used to match all DNs that contain these + two attributes as the top two Relative Distinguished Names (RDNs). + + For an RFC 822 e-mail addresses, the same options exist. A complete + address such as foo@example.com matches one entity, but a sub-tree + name such as "@example.com" could be used to match all the entities + with names ending in those two domain names to the right of the @. + + The specific syntax used by an implementation to accommodate sub-tree + matching for distinguished names, domain names or RFC 822 e-mail + addresses is a local matter. But, at a minimum, sub-tree matching of + the sort described above MUST be supported. (Substring matching + within a DN, DNS name, or RFC 822 address MAY be supported, but is + not required.) + + For IPv4 and IPv6 addresses, the same address range syntax used for + SPD entries MUST be supported. This allows specification of an + individual address (via a trivial range), an address prefix (by + choosing a range that adheres to Classless Inter-Domain Routing + (CIDR)-style prefixes), or an arbitrary address range. + + The Key ID field is defined as an OCTET string in IKE. For this name + type, only exact-match syntax MUST be supported (since there is no + explicit structure for this ID type). Additional matching functions + MAY be supported for this ID type. + +4.4.3.2. IKE Peer Authentication Data + + Once an entry is located based on an ordered search of the PAD based + on ID field matching, it is necessary to verify the asserted + identity, i.e., to authenticate the asserted ID. For each PAD entry, + there is an indication of the type of authentication to be performed. + This document requires support for two required authentication data + types: + + - X.509 certificate + - pre-shared secret + + For authentication based on an X.509 certificate, the PAD entry + contains a trust anchor via which the end entity (EE) certificate for + the peer must be verifiable, either directly or via a certificate + path. See RFC 3280 for the definition of a trust anchor. An entry + used with certificate-based authentication MAY include additional + data to facilitate certificate revocation status, e.g., a list of + + + +Kent & Seo Standards Track [Page 45] + +RFC 4301 Security Architecture for IP December 2005 + + + appropriate OCSP responders or CRL repositories, and associated + authentication data. For authentication based on a pre-shared + secret, the PAD contains the pre-shared secret to be used by IKE. + + This document does not require that the IKE ID asserted by a peer be + syntactically related to a specific field in an end entity + certificate that is employed to authenticate the identity of that + peer. However, it often will be appropriate to impose such a + requirement, e.g., when a single entry represents a set of peers each + of whom may have a distinct SPD entry. Thus, implementations MUST + provide a means for an administrator to require a match between an + asserted IKE ID and the subject name or subject alt name in a + certificate. The former is applicable to IKE IDs expressed as + distinguished names; the latter is appropriate for DNS names, RFC 822 + e-mail addresses, and IP addresses. Since KEY ID is intended for + identifying a peer authenticated via a pre-shared secret, there is no + requirement to match this ID type to a certificate field. + + See IKEv1 [HarCar98] and IKEv2 [Kau05] for details of how IKE + performs peer authentication using certificates or pre-shared + secrets. + + This document does not mandate support for any other authentication + methods, although such methods MAY be employed. + +4.4.3.3. Child SA Authorization Data + + Once an IKE peer is authenticated, child SAs may be created. Each + PAD entry contains data to constrain the set of IDs that can be + asserted by an IKE peer, for matching against the SPD. Each PAD + entry indicates whether the IKE ID is to be used as a symbolic name + for SPD matching, or whether an IP address asserted in a traffic + selector payload is to be used. + + If the entry indicates that the IKE ID is to be used, then the PAD + entry ID field defines the authorized set of IDs. If the entry + indicates that child SAs traffic selectors are to be used, then an + additional data element is required, in the form of IPv4 and/or IPv6 + address ranges. (A peer may be authorized for both address types, so + there MUST be provision for both a v4 and a v6 address range.) + +4.4.3.4. How the PAD Is Used + + During the initial IKE exchange, the initiator and responder each + assert their identity via the IKE ID payload and send an AUTH payload + to verify the asserted identity. One or more CERT payloads may be + transmitted to facilitate the verification of each asserted identity. + + + + +Kent & Seo Standards Track [Page 46] + +RFC 4301 Security Architecture for IP December 2005 + + + When an IKE entity receives an IKE ID payload, it uses the asserted + ID to locate an entry in the PAD, using the matching rules described + above. The PAD entry specifies the authentication method to be + employed for the identified peer. This ensures that the right method + is used for each peer and that different methods can be used for + different peers. The entry also specifies the authentication data + that will be used to verify the asserted identity. This data is + employed in conjunction with the specified method to authenticate the + peer, before any CHILD SAs are created. + + Child SAs are created based on the exchange of traffic selector + payloads, either at the end of the initial IKE exchange or in + subsequent CREATE_CHILD_SA exchanges. The PAD entry for the (now + authenticated) IKE peer is used to constrain creation of child SAs; + specifically, the PAD entry specifies how the SPD is searched using a + traffic selector proposal from a peer. There are two choices: either + the IKE ID asserted by the peer is used to find an SPD entry via its + symbolic name, or peer IP addresses asserted in traffic selector + payloads are used for SPD lookups based on the remote IP address + field portion of an SPD entry. It is necessary to impose these + constraints on creation of child SAs to prevent an authenticated peer + from spoofing IDs associated with other, legitimate peers. + + Note that because the PAD is checked before searching for an SPD + entry, this safeguard protects an initiator against spoofing attacks. + For example, assume that IKE A receives an outbound packet destined + for IP address X, a host served by a security gateway. RFC 2401 + [RFC2401] and this document do not specify how A determines the + address of the IKE peer serving X. However, any peer contacted by A + as the presumed representative for X must be registered in the PAD in + order to allow the IKE exchange to be authenticated. Moreover, when + the authenticated peer asserts that it represents X in its traffic + selector exchange, the PAD will be consulted to determine if the peer + in question is authorized to represent X. Thus, the PAD provides a + binding of address ranges (or name sub-spaces) to peers, to counter + such attacks. + +4.5. SA and Key Management + + All IPsec implementations MUST support both manual and automated SA + and cryptographic key management. The IPsec protocols, AH and ESP, + are largely independent of the associated SA management techniques, + although the techniques involved do affect some of the security + services offered by the protocols. For example, the optional + anti-replay service available for AH and ESP requires automated SA + management. Moreover, the granularity of key distribution employed + with IPsec determines the granularity of authentication provided. In + general, data origin authentication in AH and ESP is limited by the + + + +Kent & Seo Standards Track [Page 47] + +RFC 4301 Security Architecture for IP December 2005 + + + extent to which secrets used with the integrity algorithm (or with a + key management protocol that creates such secrets) are shared among + multiple possible sources. + + The following text describes the minimum requirements for both types + of SA management. + +4.5.1. Manual Techniques + + The simplest form of management is manual management, in which a + person manually configures each system with keying material and SA + management data relevant to secure communication with other systems. + Manual techniques are practical in small, static environments but + they do not scale well. For example, a company could create a + virtual private network (VPN) using IPsec in security gateways at + several sites. If the number of sites is small, and since all the + sites come under the purview of a single administrative domain, this + might be a feasible context for manual management techniques. In + this case, the security gateway might selectively protect traffic to + and from other sites within the organization using a manually + configured key, while not protecting traffic for other destinations. + It also might be appropriate when only selected communications need + to be secured. A similar argument might apply to use of IPsec + entirely within an organization for a small number of hosts and/or + gateways. Manual management techniques often employ statically + configured, symmetric keys, though other options also exist. + +4.5.2. Automated SA and Key Management + + Widespread deployment and use of IPsec requires an Internet-standard, + scalable, automated, SA management protocol. Such support is + required to facilitate use of the anti-replay features of AH and ESP, + and to accommodate on-demand creation of SAs, e.g., for user- and + session-oriented keying. (Note that the notion of "rekeying" an SA + actually implies creation of a new SA with a new SPI, a process that + generally implies use of an automated SA/key management protocol.) + + The default automated key management protocol selected for use with + IPsec is IKEv2 [Kau05]. This document assumes the availability of + certain functions from the key management protocol that are not + supported by IKEv1. Other automated SA management protocols MAY be + employed. + + When an automated SA/key management protocol is employed, the output + from this protocol is used to generate multiple keys for a single SA. + This also occurs because distinct keys are used for each of the two + + + + + +Kent & Seo Standards Track [Page 48] + +RFC 4301 Security Architecture for IP December 2005 + + + SAs created by IKE. If both integrity and confidentiality are + employed, then a minimum of four keys are required. Additionally, + some cryptographic algorithms may require multiple keys, e.g., 3DES. + + The Key Management System may provide a separate string of bits for + each key or it may generate one string of bits from which all keys + are extracted. If a single string of bits is provided, care needs to + be taken to ensure that the parts of the system that map the string + of bits to the required keys do so in the same fashion at both ends + of the SA. To ensure that the IPsec implementations at each end of + the SA use the same bits for the same keys, and irrespective of which + part of the system divides the string of bits into individual keys, + the encryption keys MUST be taken from the first (left-most, + high-order) bits and the integrity keys MUST be taken from the + remaining bits. The number of bits for each key is defined in the + relevant cryptographic algorithm specification RFC. In the case of + multiple encryption keys or multiple integrity keys, the + specification for the cryptographic algorithm must specify the order + in which they are to be selected from a single string of bits + provided to the cryptographic algorithm. + +4.5.3. Locating a Security Gateway + + This section discusses issues relating to how a host learns about the + existence of relevant security gateways and, once a host has + contacted these security gateways, how it knows that these are the + correct security gateways. The details of where the required + information is stored is a local matter, but the Peer Authorization + Database (PAD) described in Section 4.4 is the most likely candidate. + (Note: S* indicates a system that is running IPsec, e.g., SH1 and SG2 + below.) + + Consider a situation in which a remote host (SH1) is using the + Internet to gain access to a server or other machine (H2) and there + is a security gateway (SG2), e.g., a firewall, through which H1's + traffic must pass. An example of this situation would be a mobile + host crossing the Internet to his home organization's firewall (SG2). + This situation raises several issues: + + 1. How does SH1 know/learn about the existence of the security + gateway SG2? + + 2. How does it authenticate SG2, and once it has authenticated SG2, + how does it confirm that SG2 has been authorized to represent H2? + + 3. How does SG2 authenticate SH1 and verify that SH1 is authorized to + contact H2? + + + + +Kent & Seo Standards Track [Page 49] + +RFC 4301 Security Architecture for IP December 2005 + + + 4. How does SH1 know/learn about any additional gateways that provide + alternate paths to H2? + + To address these problems, an IPsec-supporting host or security + gateway MUST have an administrative interface that allows the + user/administrator to configure the address of one or more security + gateways for ranges of destination addresses that require its use. + This includes the ability to configure information for locating and + authenticating one or more security gateways and verifying the + authorization of these gateways to represent the destination host. + (The authorization function is implied in the PAD.) This document + does not address the issue of how to automate the + discovery/verification of security gateways. + +4.6. SAs and Multicast + + The receiver-orientation of the SA implies that, in the case of + unicast traffic, the destination system will select the SPI value. + By having the destination select the SPI value, there is no potential + for manually configured SAs to conflict with automatically configured + (e.g., via a key management protocol) SAs or for SAs from multiple + sources to conflict with each other. For multicast traffic, there + are multiple destination systems associated with a single SA. So + some system or person will need to coordinate among all multicast + groups to select an SPI or SPIs on behalf of each multicast group and + then communicate the group's IPsec information to all of the + legitimate members of that multicast group via mechanisms not defined + here. + + Multiple senders to a multicast group SHOULD use a single Security + Association (and hence SPI) for all traffic to that group when a + symmetric key encryption or integrity algorithm is employed. In such + circumstances, the receiver knows only that the message came from a + system possessing the key for that multicast group. In such + circumstances, a receiver generally will not be able to authenticate + which system sent the multicast traffic. Specifications for other, + more general multicast approaches are deferred to the IETF Multicast + Security Working Group. + +5. IP Traffic Processing + + As mentioned in Section 4.4.1, "The Security Policy Database (SPD)", + the SPD (or associated caches) MUST be consulted during the + processing of all traffic that crosses the IPsec protection boundary, + including IPsec management traffic. If no policy is found in the SPD + that matches a packet (for either inbound or outbound traffic), the + packet MUST be discarded. To simplify processing, and to allow for + very fast SA lookups (for SG/BITS/BITW), this document introduces the + + + +Kent & Seo Standards Track [Page 50] + +RFC 4301 Security Architecture for IP December 2005 + + + notion of an SPD cache for all outbound traffic (SPD-O plus SPD-S), + and a cache for inbound, non-IPsec-protected traffic (SPD-I). (As + mentioned earlier, the SAD acts as a cache for checking the selectors + of inbound IPsec-protected traffic arriving on SAs.) There is + nominally one cache per SPD. For the purposes of this specification, + it is assumed that each cached entry will map to exactly one SA. + Note, however, exceptions arise when one uses multiple SAs to carry + traffic of different priorities (e.g., as indicated by distinct DSCP + values) but the same selectors. Note also, that there are a couple + of situations in which the SAD can have entries for SAs that do not + have corresponding entries in the SPD. Since this document does not + mandate that the SAD be selectively cleared when the SPD is changed, + SAD entries can remain when the SPD entries that created them are + changed or deleted. Also, if a manually keyed SA is created, there + could be an SAD entry for this SA that does not correspond to any SPD + entry. + + Since SPD entries may overlap, one cannot safely cache these entries + in general. Simple caching might result in a match against a cache + entry, whereas an ordered search of the SPD would have resulted in a + match against a different entry. But, if the SPD entries are first + decorrelated, then the resulting entries can safely be cached. Each + cached entry will indicate that matching traffic should be bypassed + or discarded, appropriately. (Note: The original SPD entry might + result in multiple SAs, e.g., because of PFP.) Unless otherwise + noted, all references below to the "SPD" or "SPD cache" or "cache" + are to a decorrelated SPD (SPD-I, SPD-O, SPD-S) or the SPD cache + containing entries from the decorrelated SPD. + + Note: In a host IPsec implementation based on sockets, the SPD will + be consulted whenever a new socket is created to determine what, if + any, IPsec processing will be applied to the traffic that will flow + on that socket. This provides an implicit caching mechanism, and the + portions of the preceding discussion that address caching can be + ignored in such implementations. + + Note: It is assumed that one starts with a correlated SPD because + that is how users and administrators are accustomed to managing these + sorts of access control lists or firewall filter rules. Then the + decorrelation algorithm is applied to build a list of cache-able SPD + entries. The decorrelation is invisible at the management interface. + + For inbound IPsec traffic, the SAD entry selected by the SPI serves + as the cache for the selectors to be matched against arriving IPsec + packets, after AH or ESP processing has been performed. + + + + + + +Kent & Seo Standards Track [Page 51] + +RFC 4301 Security Architecture for IP December 2005 + + +5.1. Outbound IP Traffic Processing (protected-to-unprotected) + + First consider the path for traffic entering the implementation via a + protected interface and exiting via an unprotected interface. + + Unprotected Interface + ^ + | + (nested SAs) +----------+ + -------------------|Forwarding|<-----+ + | +----------+ | + | ^ | + | | BYPASS | + V +-----+ | + +-------+ | SPD | +--------+ + ...| SPD-I |.................|Cache|.....|PROCESS |...IPsec + | (*) | | (*) |---->|(AH/ESP)| boundary + +-------+ +-----+ +--------+ + | +-------+ / ^ + | |DISCARD| <--/ | + | +-------+ | + | | + | +-------------+ + |---------------->|SPD Selection| + +-------------+ + ^ + | +------+ + | -->| ICMP | + | / +------+ + |/ + | + | + Protected Interface + + + Figure 2. Processing Model for Outbound Traffic + (*) = The SPD caches are shown here. If there + is a cache miss, then the SPD is checked. + There is no requirement that an + implementation buffer the packet if + there is a cache miss. + + + + + + + + + + +Kent & Seo Standards Track [Page 52] + +RFC 4301 Security Architecture for IP December 2005 + + + IPsec MUST perform the following steps when processing outbound + packets: + + 1. When a packet arrives from the subscriber (protected) interface, + invoke the SPD selection function to obtain the SPD-ID needed to + choose the appropriate SPD. (If the implementation uses only one + SPD, this step is a no-op.) + + 2. Match the packet headers against the cache for the SPD specified + by the SPD-ID from step 1. Note that this cache contains entries + from SPD-O and SPD-S. + + 3a. If there is a match, then process the packet as specified by the + matching cache entry, i.e., BYPASS, DISCARD, or PROTECT using AH + or ESP. If IPsec processing is applied, there is a link from the + SPD cache entry to the relevant SAD entry (specifying the mode, + cryptographic algorithms, keys, SPI, PMTU, etc.). IPsec + processing is as previously defined, for tunnel or transport + modes and for AH or ESP, as specified in their respective RFCs + [Ken05b, Ken05a]. Note that the SA PMTU value, plus the value of + the stateful fragment checking flag (and the DF bit in the IP + header of the outbound packet) determine whether the packet can + (must) be fragmented prior to or after IPsec processing, or if it + must be discarded and an ICMP PMTU message is sent. + + 3b. If no match is found in the cache, search the SPD (SPD-S and + SPD-O parts) specified by SPD-ID. If the SPD entry calls for + BYPASS or DISCARD, create one or more new outbound SPD cache + entries and if BYPASS, create one or more new inbound SPD cache + entries. (More than one cache entry may be created since a + decorrelated SPD entry may be linked to other such entries that + were created as a side effect of the decorrelation process.) If + the SPD entry calls for PROTECT, i.e., creation of an SA, the key + management mechanism (e.g., IKEv2) is invoked to create the SA. + If SA creation succeeds, a new outbound (SPD-S) cache entry is + created, along with outbound and inbound SAD entries, otherwise + the packet is discarded. (A packet that triggers an SPD lookup + MAY be discarded by the implementation, or it MAY be processed + against the newly created cache entry, if one is created.) Since + SAs are created in pairs, an SAD entry for the corresponding + inbound SA also is created, and it contains the selector values + derived from the SPD entry (and packet, if any PFP flags were + "true") used to create the inbound SA, for use in checking + inbound traffic delivered via the SA. + + 4. The packet is passed to the outbound forwarding function + (operating outside of the IPsec implementation), to select the + interface to which the packet will be directed. This function + + + +Kent & Seo Standards Track [Page 53] + +RFC 4301 Security Architecture for IP December 2005 + + + may cause the packet to be passed back across the IPsec boundary, + for additional IPsec processing, e.g., in support of nested SAs. + If so, there MUST be an entry in SPD-I database that permits + inbound bypassing of the packet, otherwise the packet will be + discarded. If necessary, i.e., if there is more than one SPD-I, + the traffic being looped back MAY be tagged as coming from this + internal interface. This would allow the use of a different + SPD-I for "real" external traffic vs. looped traffic, if needed. + + Note: With the exception of IPv4 and IPv6 transport mode, an SG, + BITS, or BITW implementation MAY fragment packets before applying + IPsec. (This applies only to IPv4. For IPv6 packets, only the + originator is allowed to fragment them.) The device SHOULD have a + configuration setting to disable this. The resulting fragments are + evaluated against the SPD in the normal manner. Thus, fragments not + containing port numbers (or ICMP message type and code, or Mobility + Header type) will only match rules having port (or ICMP message type + and code, or MH type) selectors of OPAQUE or ANY. (See Section 7 for + more details.) + + Note: With regard to determining and enforcing the PMTU of an SA, the + IPsec system MUST follow the steps described in Section 8.2. + +5.1.1. Handling an Outbound Packet That Must Be Discarded + + If an IPsec system receives an outbound packet that it finds it must + discard, it SHOULD be capable of generating and sending an ICMP + message to indicate to the sender of the outbound packet that the + packet was discarded. The type and code of the ICMP message will + depend on the reason for discarding the packet, as specified below. + The reason SHOULD be recorded in the audit log. The audit log entry + for this event SHOULD include the reason, current date/time, and the + selector values from the packet. + + a. The selectors of the packet matched an SPD entry requiring the + packet to be discarded. + + IPv4 Type = 3 (destination unreachable) Code = 13 + (Communication Administratively Prohibited) + + IPv6 Type = 1 (destination unreachable) Code = 1 + (Communication with destination administratively + prohibited) + + b1. The IPsec system successfully reached the remote peer but was + unable to negotiate the SA required by the SPD entry matching the + packet because, for example, the remote peer is administratively + prohibited from communicating with the initiator, the initiating + + + +Kent & Seo Standards Track [Page 54] + +RFC 4301 Security Architecture for IP December 2005 + + + peer was unable to authenticate itself to the remote peer, the + remote peer was unable to authenticate itself to the initiating + peer, or the SPD at the remote peer did not have a suitable + entry. + + IPv4 Type = 3 (destination unreachable) Code = 13 + (Communication Administratively Prohibited) + + IPv6 Type = 1 (destination unreachable) Code = 1 + (Communication with destination administratively + prohibited) + + b2. The IPsec system was unable to set up the SA required by the SPD + entry matching the packet because the IPsec peer at the other end + of the exchange could not be contacted. + + IPv4 Type = 3 (destination unreachable) Code = 1 (host + unreachable) + + IPv6 Type = 1 (destination unreachable) Code = 3 (address + unreachable) + + Note that an attacker behind a security gateway could send packets + with a spoofed source address, W.X.Y.Z, to an IPsec entity causing it + to send ICMP messages to W.X.Y.Z. This creates an opportunity for a + denial of service (DoS) attack among hosts behind a security gateway. + To address this, a security gateway SHOULD include a management + control to allow an administrator to configure an IPsec + implementation to send or not send the ICMP messages under these + circumstances, and if this facility is selected, to rate limit the + transmission of such ICMP responses. + +5.1.2. Header Construction for Tunnel Mode + + This section describes the handling of the inner and outer IP + headers, extension headers, and options for AH and ESP tunnels, with + regard to outbound traffic processing. This includes how to + construct the encapsulating (outer) IP header, how to process fields + in the inner IP header, and what other actions should be taken for + outbound, tunnel mode traffic. The general processing described here + is modeled after RFC 2003, "IP Encapsulation within IP" [Per96]: + + o The outer IP header Source Address and Destination Address + identify the "endpoints" of the tunnel (the encapsulator and + decapsulator). The inner IP header Source Address and Destination + Addresses identify the original sender and recipient of the + datagram (from the perspective of this tunnel), respectively. + + + + +Kent & Seo Standards Track [Page 55] + +RFC 4301 Security Architecture for IP December 2005 + + + (See footnote 3 after the table in 5.1.2.1 for more details on the + encapsulating source IP address.) + + o The inner IP header is not changed except as noted below for TTL + (or Hop Limit) and the DS/ECN Fields. The inner IP header + otherwise remains unchanged during its delivery to the tunnel exit + point. + + o No change to IP options or extension headers in the inner header + occurs during delivery of the encapsulated datagram through the + tunnel. + + Note: IPsec tunnel mode is different from IP-in-IP tunneling (RFC + 2003 [Per96]) in several ways: + + o IPsec offers certain controls to a security administrator to + manage covert channels (which would not normally be a concern for + tunneling) and to ensure that the receiver examines the right + portions of the received packet with respect to application of + access controls. An IPsec implementation MAY be configurable with + regard to how it processes the outer DS field for tunnel mode for + transmitted packets. For outbound traffic, one configuration + setting for the outer DS field will operate as described in the + following sections on IPv4 and IPv6 header processing for IPsec + tunnels. Another will allow the outer DS field to be mapped to a + fixed value, which MAY be configured on a per-SA basis. (The value + might really be fixed for all traffic outbound from a device, but + per-SA granularity allows that as well.) This configuration option + allows a local administrator to decide whether the covert channel + provided by copying these bits outweighs the benefits of copying. + + o IPsec describes how to handle ECN or DS and provides the ability + to control propagation of changes in these fields between + unprotected and protected domains. In general, propagation from a + protected to an unprotected domain is a covert channel and thus + controls are provided to manage the bandwidth of this channel. + Propagation of ECN values in the other direction are controlled so + that only legitimate ECN changes (indicating occurrence of + congestion between the tunnel endpoints) are propagated. By + default, DS propagation from an unprotected domain to a protected + domain is not permitted. However, if the sender and receiver do + not share the same DS code space, and the receiver has no way of + learning how to map between the two spaces, then it may be + appropriate to deviate from the default. Specifically, an IPsec + implementation MAY be configurable in terms of how it processes + the outer DS field for tunnel mode for received packets. It may + be configured to either discard the outer DS value (the default) + OR to overwrite the inner DS field with the outer DS field. If + + + +Kent & Seo Standards Track [Page 56] + +RFC 4301 Security Architecture for IP December 2005 + + + offered, the discard vs. overwrite behavior MAY be configured on a + per-SA basis. This configuration option allows a local + administrator to decide whether the vulnerabilities created by + copying these bits outweigh the benefits of copying. See + [RFC2983] for further information on when each of these behaviors + may be useful, and also for the possible need for diffserv traffic + conditioning prior or subsequent to IPsec processing (including + tunnel decapsulation). + + o IPsec allows the IP version of the encapsulating header to be + different from that of the inner header. + + The tables in the following sub-sections show the handling for the + different header/option fields ("constructed" means that the value in + the outer field is constructed independently of the value in the + inner). + +5.1.2.1. IPv4: Header Construction for Tunnel Mode + + <-- How Outer Hdr Relates to Inner Hdr --> + Outer Hdr at Inner Hdr at + IPv4 Encapsulator Decapsulator + Header fields: -------------------- ------------ + version 4 (1) no change + header length constructed no change + DS Field copied from inner hdr (5) no change + ECN Field copied from inner hdr constructed (6) + total length constructed no change + ID constructed no change + flags (DF,MF) constructed, DF (4) no change + fragment offset constructed no change + TTL constructed (2) decrement (2) + protocol AH, ESP no change + checksum constructed constructed (2)(6) + src address constructed (3) no change + dest address constructed (3) no change + Options never copied no change + + Notes: + + (1) The IP version in the encapsulating header can be different + from the value in the inner header. + + (2) The TTL in the inner header is decremented by the encapsulator + prior to forwarding and by the decapsulator if it forwards the + packet. (The IPv4 checksum changes when the TTL changes.) + + + + + +Kent & Seo Standards Track [Page 57] + +RFC 4301 Security Architecture for IP December 2005 + + + Note: Decrementing the TTL value is a normal part of + forwarding a packet. Thus, a packet originating from the same + node as the encapsulator does not have its TTL decremented, + since the sending node is originating the packet rather than + forwarding it. This applies to BITS and native IPsec + implementations in hosts and routers. However, the IPsec + processing model includes an external forwarding capability. + TTL processing can be used to prevent looping of packets, + e.g., due to configuration errors, within the context of this + processing model. + + (3) Local and Remote addresses depend on the SA, which is used to + determine the Remote address, which in turn determines which + Local address (net interface) is used to forward the packet. + + Note: For multicast traffic, the destination address, or + source and destination addresses, may be required for + demuxing. In that case, it is important to ensure consistency + over the lifetime of the SA by ensuring that the source + address that appears in the encapsulating tunnel header is the + same as the one that was negotiated during the SA + establishment process. There is an exception to this general + rule, i.e., a mobile IPsec implementation will update its + source address as it moves. + + (4) Configuration determines whether to copy from the inner header + (IPv4 only), clear, or set the DF. + + (5) If the packet will immediately enter a domain for which the + DSCP value in the outer header is not appropriate, that value + MUST be mapped to an appropriate value for the domain + [NiBlBaBL98]. See RFC 2475 [BBCDWW98] for further + information. + + (6) If the ECN field in the inner header is set to ECT(0) or + ECT(1), where ECT is ECN-Capable Transport (ECT), and if the + ECN field in the outer header is set to Congestion Experienced + (CE), then set the ECN field in the inner header to CE; + otherwise, make no change to the ECN field in the inner + header. (The IPv4 checksum changes when the ECN changes.) + + Note: IPsec does not copy the options from the inner header into the + outer header, nor does IPsec construct the options in the outer + header. However, post-IPsec code MAY insert/construct options for + the outer header. + + + + + + +Kent & Seo Standards Track [Page 58] + +RFC 4301 Security Architecture for IP December 2005 + + +5.1.2.2. IPv6: Header Construction for Tunnel Mode + + <-- How Outer Hdr Relates Inner Hdr ---> + Outer Hdr at Inner Hdr at + IPv6 Encapsulator Decapsulator + Header fields: -------------------- ------------ + version 6 (1) no change + DS Field copied from inner hdr (5) no change (9) + ECN Field copied from inner hdr constructed (6) + flow label copied or configured (8) no change + payload length constructed no change + next header AH,ESP,routing hdr no change + hop limit constructed (2) decrement (2) + src address constructed (3) no change + dest address constructed (3) no change + Extension headers never copied (7) no change + + Notes: + + (1) - (6) See Section 5.1.2.1. + + (7) IPsec does not copy the extension headers from the inner + packet into outer headers, nor does IPsec construct extension + headers in the outer header. However, post-IPsec code MAY + insert/construct extension headers for the outer header. + + (8) See [RaCoCaDe04]. Copying is acceptable only for end systems, + not SGs. If an SG copied flow labels from the inner header to + the outer header, collisions might result. + + (9) An implementation MAY choose to provide a facility to pass the + DS value from the outer header to the inner header, on a per- + SA basis, for received tunnel mode packets. The motivation + for providing this feature is to accommodate situations in + which the DS code space at the receiver is different from that + of the sender and the receiver has no way of knowing how to + translate from the sender's space. There is a danger in + copying this value from the outer header to the inner header, + since it enables an attacker to modify the outer DSCP value in + a fashion that may adversely affect other traffic at the + receiver. Hence the default behavior for IPsec + implementations is NOT to permit such copying. + +5.2. Processing Inbound IP Traffic (unprotected-to-protected) + + Inbound processing is somewhat different from outbound processing, + because of the use of SPIs to map IPsec-protected traffic to SAs. + The inbound SPD cache (SPD-I) is applied only to bypassed or + + + +Kent & Seo Standards Track [Page 59] + +RFC 4301 Security Architecture for IP December 2005 + + + discarded traffic. If an arriving packet appears to be an IPsec + fragment from an unprotected interface, reassembly is performed prior + to IPsec processing. The intent for any SPD cache is that a packet + that fails to match any entry is then referred to the corresponding + SPD. Every SPD SHOULD have a nominal, final entry that catches + anything that is otherwise unmatched, and discards it. This ensures + that non-IPsec-protected traffic that arrives and does not match any + SPD-I entry will be discarded. + + Unprotected Interface + | + V + +-----+ IPsec protected + ------------------->|Demux|-------------------+ + | +-----+ | + | | | + | Not IPsec | | + | | | + | V | + | +-------+ +---------+ | + | |DISCARD|<---|SPD-I (*)| | + | +-------+ +---------+ | + | | | + | |-----+ | + | | | | + | | V | + | | +------+ | + | | | ICMP | | + | | +------+ | + | | V + +---------+ | +-----------+ + ....|SPD-O (*)|............|...................|PROCESS(**)|...IPsec + +---------+ | | (AH/ESP) | Boundary + ^ | +-----------+ + | | +---+ | + | BYPASS | +-->|IKE| | + | | | +---+ | + | V | V + | +----------+ +---------+ +----+ + |--------<------|Forwarding|<---------|SAD Check|-->|ICMP| + nested SAs +----------+ | (***) | +----+ + | +---------+ + V + Protected Interface + + Figure 3. Processing Model for Inbound Traffic + + + + + +Kent & Seo Standards Track [Page 60] + +RFC 4301 Security Architecture for IP December 2005 + + + (*) = The caches are shown here. If there is + a cache miss, then the SPD is checked. + There is no requirement that an + implementation buffer the packet if + there is a cache miss. + (**) = This processing includes using the + packet's SPI, etc., to look up the SA + in the SAD, which forms a cache of the + SPD for inbound packets (except for + cases noted in Sections 4.4.2 and 5). + See step 3a below. + (***) = This SAD check refers to step 4 below. + + Prior to performing AH or ESP processing, any IP fragments that + arrive via the unprotected interface are reassembled (by IP). Each + inbound IP datagram to which IPsec processing will be applied is + identified by the appearance of the AH or ESP values in the IP Next + Protocol field (or of AH or ESP as a next layer protocol in the IPv6 + context). + + IPsec MUST perform the following steps: + + 1. When a packet arrives, it may be tagged with the ID of the + interface (physical or virtual) via which it arrived, if + necessary, to support multiple SPDs and associated SPD-I caches. + (The interface ID is mapped to a corresponding SPD-ID.) + + 2. The packet is examined and demuxed into one of two categories: + - If the packet appears to be IPsec protected and it is addressed + to this device, an attempt is made to map it to an active SA + via the SAD. Note that the device may have multiple IP + addresses that may be used in the SAD lookup, e.g., in the case + of protocols such as SCTP. + - Traffic not addressed to this device, or addressed to this + device and not AH or ESP, is directed to SPD-I lookup. (This + implies that IKE traffic MUST have an explicit BYPASS entry in + the SPD.) If multiple SPDs are employed, the tag assigned to + the packet in step 1 is used to select the appropriate SPD-I + (and cache) to search. SPD-I lookup determines whether the + action is DISCARD or BYPASS. + + 3a. If the packet is addressed to the IPsec device and AH or ESP is + specified as the protocol, the packet is looked up in the SAD. + For unicast traffic, use only the SPI (or SPI plus protocol). + For multicast traffic, use the SPI plus the destination or SPI + plus destination and source addresses, as specified in Section + 4.1. In either case (unicast or multicast), if there is no match, + discard the traffic. This is an auditable event. The audit log + + + +Kent & Seo Standards Track [Page 61] + +RFC 4301 Security Architecture for IP December 2005 + + + entry for this event SHOULD include the current date/time, SPI, + source and destination of the packet, IPsec protocol, and any + other selector values of the packet that are available. If the + packet is found in the SAD, process it accordingly (see step 4). + + 3b. If the packet is not addressed to the device or is addressed to + this device and is not AH or ESP, look up the packet header in + the (appropriate) SPD-I cache. If there is a match and the + packet is to be discarded or bypassed, do so. If there is no + cache match, look up the packet in the corresponding SPD-I and + create a cache entry as appropriate. (No SAs are created in + response to receipt of a packet that requires IPsec protection; + only BYPASS or DISCARD cache entries can be created this way.) If + there is no match, discard the traffic. This is an auditable + event. The audit log entry for this event SHOULD include the + current date/time, SPI if available, IPsec protocol if available, + source and destination of the packet, and any other selector + values of the packet that are available. + + 3c. Processing of ICMP messages is assumed to take place on the + unprotected side of the IPsec boundary. Unprotected ICMP + messages are examined and local policy is applied to determine + whether to accept or reject these messages and, if accepted, what + action to take as a result. For example, if an ICMP unreachable + message is received, the implementation must decide whether to + act on it, reject it, or act on it with constraints. (See Section + 6.) + + 4. Apply AH or ESP processing as specified, using the SAD entry + selected in step 3a above. Then match the packet against the + inbound selectors identified by the SAD entry to verify that the + received packet is appropriate for the SA via which it was + received. + + 5. If an IPsec system receives an inbound packet on an SA and the + packet's header fields are not consistent with the selectors for + the SA, it MUST discard the packet. This is an auditable event. + The audit log entry for this event SHOULD include the current + date/time, SPI, IPsec protocol(s), source and destination of the + packet, any other selector values of the packet that are + available, and the selector values from the relevant SAD entry. + The system SHOULD also be capable of generating and sending an + IKE notification of INVALID_SELECTORS to the sender (IPsec peer), + indicating that the received packet was discarded because of + failure to pass selector checks. + + + + + + +Kent & Seo Standards Track [Page 62] + +RFC 4301 Security Architecture for IP December 2005 + + + To minimize the impact of a DoS attack, or a mis-configured peer, the + IPsec system SHOULD include a management control to allow an + administrator to configure the IPsec implementation to send or not + send this IKE notification, and if this facility is selected, to rate + limit the transmission of such notifications. + + After traffic is bypassed or processed through IPsec, it is handed to + the inbound forwarding function for disposition. This function may + cause the packet to be sent (outbound) across the IPsec boundary for + additional inbound IPsec processing, e.g., in support of nested SAs. + If so, then as with ALL outbound traffic that is to be bypassed, the + packet MUST be matched against an SPD-O entry. Ultimately, the + packet should be forwarded to the destination host or process for + disposition. + +6. ICMP Processing + + This section describes IPsec handling of ICMP traffic. There are two + categories of ICMP traffic: error messages (e.g., type = destination + unreachable) and non-error messages (e.g., type = echo). This + section applies exclusively to error messages. Disposition of + non-error, ICMP messages (that are not addressed to the IPsec + implementation itself) MUST be explicitly accounted for using SPD + entries. + + The discussion in this section applies to ICMPv6 as well as to + ICMPv4. Also, a mechanism SHOULD be provided to allow an + administrator to cause ICMP error messages (selected, all, or none) + to be logged as an aid to problem diagnosis. + +6.1. Processing ICMP Error Messages Directed to an IPsec Implementation + +6.1.1. ICMP Error Messages Received on the Unprotected Side of the + Boundary + + Figure 3 in Section 5.2 shows a distinct ICMP processing module on + the unprotected side of the IPsec boundary, for processing ICMP + messages (error or otherwise) that are addressed to the IPsec device + and that are not protected via AH or ESP. An ICMP message of this + sort is unauthenticated, and its processing may result in denial or + degradation of service. This suggests that, in general, it would be + desirable to ignore such messages. However, many ICMP messages will + be received by hosts or security gateways from unauthenticated + sources, e.g., routers in the public Internet. Ignoring these ICMP + messages can degrade service, e.g., because of a failure to process + PMTU message and redirection messages. Thus, there is also a + motivation for accepting and acting upon unauthenticated ICMP + messages. + + + +Kent & Seo Standards Track [Page 63] + +RFC 4301 Security Architecture for IP December 2005 + + + To accommodate both ends of this spectrum, a compliant IPsec + implementation MUST permit a local administrator to configure an + IPsec implementation to accept or reject unauthenticated ICMP + traffic. This control MUST be at the granularity of ICMP type and + MAY be at the granularity of ICMP type and code. Additionally, an + implementation SHOULD incorporate mechanisms and parameters for + dealing with such traffic. For example, there could be the ability + to establish a minimum PMTU for traffic (on a per destination basis), + to prevent receipt of an unauthenticated ICMP from setting the PMTU + to a trivial size. + + If an ICMP PMTU message passes the checks above and the system is + configured to accept it, then there are two possibilities. If the + implementation applies fragmentation on the ciphertext side of the + boundary, then the accepted PMTU information is passed to the + forwarding module (outside of the IPsec implementation), which uses + it to manage outbound packet fragmentation. If the implementation is + configured to effect plaintext side fragmentation, then the PMTU + information is passed to the plaintext side and processed as + described in Section 8.2. + +6.1.2. ICMP Error Messages Received on the Protected Side of the + Boundary + + These ICMP messages are not authenticated, but they do come from + sources on the protected side of the IPsec boundary. Thus, these + messages generally are viewed as more "trustworthy" than their + counterparts arriving from sources on the unprotected side of the + boundary. The major security concern here is that a compromised host + or router might emit erroneous ICMP error messages that could degrade + service for other devices "behind" the security gateway, or that + could even result in violations of confidentiality. For example, if + a bogus ICMP redirect were consumed by a security gateway, it could + cause the forwarding table on the protected side of the boundary to + be modified so as to deliver traffic to an inappropriate destination + "behind" the gateway. Thus, implementers MUST provide controls to + allow local administrators to constrain the processing of ICMP error + messages received on the protected side of the boundary, and directed + to the IPsec implementation. These controls are of the same type as + those employed on the unprotected side, described above in Section + 6.1.1. + +6.2. Processing Protected, Transit ICMP Error Messages + + When an ICMP error message is transmitted via an SA to a device + "behind" an IPsec implementation, both the payload and the header of + the ICMP message require checking from an access control perspective. + If one of these messages is forwarded to a host behind a security + + + +Kent & Seo Standards Track [Page 64] + +RFC 4301 Security Architecture for IP December 2005 + + + gateway, the receiving host IP implementation will make decisions + based on the payload, i.e., the header of the packet that purportedly + triggered the error response. Thus, an IPsec implementation MUST be + configurable to check that this payload header information is + consistent with the SA via which it arrives. (This means that the + payload header, with source and destination address and port fields + reversed, matches the traffic selectors for the SA.) If this sort of + check is not performed, then, for example, anyone with whom the + receiving IPsec system (A) has an active SA could send an ICMP + Destination Unreachable message that refers to any host/net with + which A is currently communicating, and thus effect a highly + efficient DoS attack regarding communication with other peers of A. + Normal IPsec receiver processing of traffic is not sufficient to + protect against such attacks. However, not all contexts may require + such checks, so it is also necessary to allow a local administrator + to configure an implementation to NOT perform such checks. + + To accommodate both policies, the following convention is adopted. + If an administrator wants to allow ICMP error messages to be carried + by an SA without inspection of the payload, then configure an SPD + entry that explicitly allows for carriage of such traffic. If an + administrator wants IPsec to check the payload of ICMP error messages + for consistency, then do not create any SPD entries that accommodate + carriage of such traffic based on the ICMP packet header. This + convention motivates the following processing description. + + IPsec senders and receivers MUST support the following processing for + ICMP error messages that are sent and received via SAs. + + If an SA exists that accommodates an outbound ICMP error message, + then the message is mapped to the SA and only the IP and ICMP headers + are checked upon receipt, just as would be the case for other + traffic. If no SA exists that matches the traffic selectors + associated with an ICMP error message, then the SPD is searched to + determine if such an SA can be created. If so, the SA is created and + the ICMP error message is transmitted via that SA. Upon receipt, + this message is subject to the usual traffic selector checks at the + receiver. This processing is exactly what would happen for traffic + in general, and thus does not represent any special processing for + ICMP error messages. + + If no SA exists that would carry the outbound ICMP message in + question, and if no SPD entry would allow carriage of this outbound + ICMP error message, then an IPsec implementation MUST map the message + to the SA that would carry the return traffic associated with the + packet that triggered the ICMP error message. This requires an IPsec + implementation to detect outbound ICMP error messages that map to no + extant SA or SPD entry, and treat them specially with regard to SA + + + +Kent & Seo Standards Track [Page 65] + +RFC 4301 Security Architecture for IP December 2005 + + + creation and lookup. The implementation extracts the header for the + packet that triggered the error (from the ICMP message payload), + reverses the source and destination IP address fields, extracts the + protocol field, and reverses the port fields (if accessible). It + then uses this extracted information to locate an appropriate, active + outbound SA, and transmits the error message via this SA. If no such + SA exists, no SA will be created, and this is an auditable event. + + If an IPsec implementation receives an inbound ICMP error message on + an SA, and the IP and ICMP headers of the message do not match the + traffic selectors for the SA, the receiver MUST process the received + message in a special fashion. Specifically, the receiver must + extract the header of the triggering packet from the ICMP payload, + and reverse fields as described above to determine if the packet is + consistent with the selectors for the SA via which the ICMP error + message was received. If the packet fails this check, the IPsec + implementation MUST NOT forwarded the ICMP message to the + destination. This is an auditable event. + +7. Handling Fragments (on the protected side of the IPsec boundary) + + Earlier sections of this document describe mechanisms for (a) + fragmenting an outbound packet after IPsec processing has been + applied and reassembling it at the receiver before IPsec processing + and (b) handling inbound fragments received from the unprotected side + of the IPsec boundary. This section describes how an implementation + should handle the processing of outbound plaintext fragments on the + protected side of the IPsec boundary. (See Appendix D, "Fragment + Handling Rationale".) In particular, it addresses: + + o mapping an outbound non-initial fragment to the right SA + (or finding the right SPD entry) + o verifying that a received non-initial fragment is + authorized for the SA via which it was received + o mapping outbound and inbound non-initial fragments to the + right SPD-O/SPD-I entry or the relevant cache entry, for + BYPASS/DISCARD traffic + + Note: In Section 4.1, transport mode SAs have been defined to not + carry fragments (IPv4 or IPv6). Note also that in Section 4.4.1, two + special values, ANY and OPAQUE, were defined for selectors and that + ANY includes OPAQUE. The term "non-trivial" is used to mean that the + selector has a value other than OPAQUE or ANY. + + Note: The term "non-initial fragment" is used here to indicate a + fragment that does not contain all the selector values that may be + needed for access control. As observed in Section 4.4.1, depending + on the Next Layer Protocol, in addition to Ports, the ICMP message + + + +Kent & Seo Standards Track [Page 66] + +RFC 4301 Security Architecture for IP December 2005 + + + type/code or Mobility Header type could be missing from non-initial + fragments. Also, for IPv6, even the first fragment might NOT contain + the Next Layer Protocol or Ports (or ICMP message type/code, or + Mobility Header type) depending on the kind and number of extension + headers present. If a non-initial fragment contains the Port (or + ICMP type and code or Mobility Header type) but not the Next Layer + Protocol, then unless there is an SPD entry for the relevant + Local/Remote addresses with ANY for Next Layer Protocol and Port (or + ICMP type and code or Mobility Header type), the fragment would not + contain all the selector information needed for access control. + + To address the above issues, three approaches have been defined: + + o Tunnel mode SAs that carry initial and non-initial fragments + (See Section 7.1.) + o Separate tunnel mode SAs for non-initial fragments (See + Section 7.2.) + o Stateful fragment checking (See Section 7.3.) + +7.1. Tunnel Mode SAs that Carry Initial and Non-Initial Fragments + + All implementations MUST support tunnel mode SAs that are configured + to pass traffic without regard to port field (or ICMP type/code or + Mobility Header type) values. If the SA will carry traffic for + specified protocols, the selector set for the SA MUST specify the + port fields (or ICMP type/code or Mobility Header type) as ANY. An + SA defined in this fashion will carry all traffic including initial + and non-initial fragments for the indicated Local/Remote addresses + and specified Next Layer protocol(s). If the SA will carry traffic + without regard to a specific protocol value (i.e., ANY is specified + as the (Next Layer) protocol selector value), then the port field + values are undefined and MUST be set to ANY as well. (As noted in + 4.4.1, ANY includes OPAQUE as well as all specific values.) + +7.2. Separate Tunnel Mode SAs for Non-Initial Fragments + + An implementation MAY support tunnel mode SAs that will carry only + non-initial fragments, separate from non-fragmented packets and + initial fragments. The OPAQUE value will be used to specify port (or + ICMP type/code or Mobility Header type) field selectors for an SA to + carry such fragments. Receivers MUST perform a minimum offset check + on IPv4 (non-initial) fragments to protect against overlapping + fragment attacks when SAs of this type are employed. Because such + checks cannot be performed on IPv6 non-initial fragments, users and + administrators are advised that carriage of such fragments may be + dangerous, and implementers may choose to NOT support such SAs for + IPv6 traffic. Also, an SA of this sort will carry all non-initial + fragments that match a specified Local/Remote address pair and + + + +Kent & Seo Standards Track [Page 67] + +RFC 4301 Security Architecture for IP December 2005 + + + protocol value, i.e., the fragments carried on this SA belong to + packets that if not fragmented, might have gone on separate SAs of + differing security. Therefore, users and administrators are advised + to protect such traffic using ESP (with integrity) and the + "strongest" integrity and encryption algorithms in use between both + peers. (Determination of the "strongest" algorithms requires + imposing an ordering of the available algorithms, a local + determination at the discretion of the initiator of the SA.) + + Specific port (or ICMP type/code or Mobility Header type) selector + values will be used to define SAs to carry initial fragments and + non-fragmented packets. This approach can be used if a user or + administrator wants to create one or more tunnel mode SAs between the + same Local/Remote addresses that discriminate based on port (or ICMP + type/code or Mobility Header type) fields. These SAs MUST have + non-trivial protocol selector values, otherwise approach #1 above + MUST be used. + + Note: In general, for the approach described in this section, one + needs only a single SA between two implementations to carry all + non-initial fragments. However, if one chooses to have multiple SAs + between the two implementations for QoS differentiation, then one + might also want multiple SAs to carry fragments-without-ports, one + for each supported QoS class. Since support for QoS via distinct SAs + is a local matter, not mandated by this document, the choice to have + multiple SAs to carry non-initial fragments should also be local. + +7.3. Stateful Fragment Checking + + An implementation MAY support some form of stateful fragment checking + for a tunnel mode SA with non-trivial port (or ICMP type/code or MH + type) field values (not ANY or OPAQUE). Implementations that will + transmit non-initial fragments on a tunnel mode SA that makes use of + non-trivial port (or ICMP type/code or MH type) selectors MUST notify + a peer via the IKE NOTIFY NON_FIRST_FRAGMENTS_ALSO payload. + + The peer MUST reject this proposal if it will not accept non-initial + fragments in this context. If an implementation does not + successfully negotiate transmission of non-initial fragments for such + an SA, it MUST NOT send such fragments over the SA. This standard + does not specify how peers will deal with such fragments, e.g., via + reassembly or other means, at either sender or receiver. However, a + receiver MUST discard non-initial fragments that arrive on an SA with + non-trivial port (or ICMP type/code or MH type) selector values + unless this feature has been negotiated. Also, the receiver MUST + discard non-initial fragments that do not comply with the security + policy applied to the overall packet. Discarding such packets is an + auditable event. Note that in network configurations where fragments + + + +Kent & Seo Standards Track [Page 68] + +RFC 4301 Security Architecture for IP December 2005 + + + of a packet might be sent or received via different security gateways + or BITW implementations, stateful strategies for tracking fragments + may fail. + +7.4. BYPASS/DISCARD Traffic + + All implementations MUST support DISCARDing of fragments using the + normal SPD packet classification mechanisms. All implementations + MUST support stateful fragment checking to accommodate BYPASS traffic + for which a non-trivial port range is specified. The concern is that + BYPASS of a cleartext, non-initial fragment arriving at an IPsec + implementation could undermine the security afforded IPsec-protected + traffic directed to the same destination. For example, consider an + IPsec implementation configured with an SPD entry that calls for + IPsec protection of traffic between a specific source/destination + address pair, and for a specific protocol and destination port, e.g., + TCP traffic on port 23 (Telnet). Assume that the implementation also + allows BYPASS of traffic from the same source/destination address + pair and protocol, but for a different destination port, e.g., port + 119 (NNTP). An attacker could send a non-initial fragment (with a + forged source address) that, if bypassed, could overlap with + IPsec-protected traffic from the same source and thus violate the + integrity of the IPsec-protected traffic. Requiring stateful + fragment checking for BYPASS entries with non-trivial port ranges + prevents attacks of this sort. As noted above, in network + configurations where fragments of a packet might be sent or received + via different security gateways or BITW implementations, stateful + strategies for tracking fragments may fail. + +8. Path MTU/DF Processing + + The application of AH or ESP to an outbound packet increases the size + of a packet and thus may cause a packet to exceed the PMTU for the SA + via which the packet will travel. An IPsec implementation also may + receive an unprotected ICMP PMTU message and, if it chooses to act + upon the message, the result will affect outbound traffic processing. + This section describes the processing required of an IPsec + implementation to deal with these two PMTU issues. + +8.1. DF Bit + + All IPsec implementations MUST support the option of copying the DF + bit from an outbound packet to the tunnel mode header that it emits, + when traffic is carried via a tunnel mode SA. This means that it + MUST be possible to configure the implementation's treatment of the + DF bit (set, clear, copy from inner header) for each SA. This + applies to SAs where both inner and outer headers are IPv4. + + + + +Kent & Seo Standards Track [Page 69] + +RFC 4301 Security Architecture for IP December 2005 + + +8.2. Path MTU (PMTU) Discovery + + This section discusses IPsec handling for unprotected Path MTU + Discovery messages. ICMP PMTU is used here to refer to an ICMP + message for: + + IPv4 (RFC 792 [Pos81b]): + - Type = 3 (Destination Unreachable) + - Code = 4 (Fragmentation needed and DF set) + - Next-Hop MTU in the low-order 16 bits of the + second word of the ICMP header (labeled "unused" + in RFC 792), with high-order 16 bits set to zero) + + IPv6 (RFC 2463 [CD98]): + - Type = 2 (Packet Too Big) + - Code = 0 (Fragmentation needed) + - Next-Hop MTU in the 32-bit MTU field of the ICMP6 + message + +8.2.1. Propagation of PMTU + + When an IPsec implementation receives an unauthenticated PMTU + message, and it is configured to process (vs. ignore) such messages, + it maps the message to the SA to which it corresponds. This mapping + is effected by extracting the header information from the payload of + the PMTU message and applying the procedure described in Section 5.2. + The PMTU determined by this message is used to update the SAD PMTU + field, taking into account the size of the AH or ESP header that will + be applied, any crypto synchronization data, and the overhead imposed + by an additional IP header, in the case of a tunnel mode SA. + + In a native host implementation, it is possible to maintain PMTU data + at the same granularity as for unprotected communication, so there is + no loss of functionality. Signaling of the PMTU information is + internal to the host. For all other IPsec implementation options, + the PMTU data must be propagated via a synthesized ICMP PMTU. In + these cases, the IPsec implementation SHOULD wait for outbound + traffic to be mapped to the SAD entry. When such traffic arrives, if + the traffic would exceed the updated PMTU value the traffic MUST be + handled as follows: + + Case 1: Original (cleartext) packet is IPv4 and has the DF + bit set. The implementation SHOULD discard the packet + and send a PMTU ICMP message. + + + + + + + +Kent & Seo Standards Track [Page 70] + +RFC 4301 Security Architecture for IP December 2005 + + + Case 2: Original (cleartext) packet is IPv4 and has the DF + bit clear. The implementation SHOULD fragment (before or + after encryption per its configuration) and then forward + the fragments. It SHOULD NOT send a PMTU ICMP message. + + Case 3: Original (cleartext) packet is IPv6. The implementation + SHOULD discard the packet and send a PMTU ICMP message. + +8.2.2. PMTU Aging + + In all IPsec implementations, the PMTU associated with an SA MUST be + "aged" and some mechanism is required to update the PMTU in a timely + manner, especially for discovering if the PMTU is smaller than + required by current network conditions. A given PMTU has to remain + in place long enough for a packet to get from the source of the SA to + the peer, and to propagate an ICMP error message if the current PMTU + is too big. + + Implementations SHOULD use the approach described in the Path MTU + Discovery document (RFC 1191 [MD90], Section 6.3), which suggests + periodically resetting the PMTU to the first-hop data-link MTU and + then letting the normal PMTU Discovery processes update the PMTU as + necessary. The period SHOULD be configurable. + +9. Auditing + + IPsec implementations are not required to support auditing. For the + most part, the granularity of auditing is a local matter. However, + several auditable events are identified in this document, and for + each of these events a minimum set of information that SHOULD be + included in an audit log is defined. Additional information also MAY + be included in the audit log for each of these events, and additional + events, not explicitly called out in this specification, also MAY + result in audit log entries. There is no requirement for the + receiver to transmit any message to the purported transmitter in + response to the detection of an auditable event, because of the + potential to induce denial of service via such action. + +10. Conformance Requirements + + All IPv4 IPsec implementations MUST comply with all requirements of + this document. All IPv6 implementations MUST comply with all + requirements of this document. + + + + + + + + +Kent & Seo Standards Track [Page 71] + +RFC 4301 Security Architecture for IP December 2005 + + +11. Security Considerations + + The focus of this document is security; hence security considerations + permeate this specification. + + IPsec imposes stringent constraints on bypass of IP header data in + both directions, across the IPsec barrier, especially when tunnel + mode SAs are employed. Some constraints are absolute, while others + are subject to local administrative controls, often on a per-SA + basis. For outbound traffic, these constraints are designed to limit + covert channel bandwidth. For inbound traffic, the constraints are + designed to prevent an adversary who has the ability to tamper with + one data stream (on the unprotected side of the IPsec barrier) from + adversely affecting other data streams (on the protected side of the + barrier). The discussion in Section 5 dealing with processing DSCP + values for tunnel mode SAs illustrates this concern. + + If an IPsec implementation is configured to pass ICMP error messages + over SAs based on the ICMP header values, without checking the header + information from the ICMP message payload, serious vulnerabilities + may arise. Consider a scenario in which several sites (A, B, and C) + are connected to one another via ESP-protected tunnels: A-B, A-C, and + B-C. Also assume that the traffic selectors for each tunnel specify + ANY for protocol and port fields and IP source/destination address + ranges that encompass the address range for the systems behind the + security gateways serving each site. This would allow a host at site + B to send an ICMP Destination Unreachable message to any host at site + A, that declares all hosts on the net at site C to be unreachable. + This is a very efficient DoS attack that could have been prevented if + the ICMP error messages were subjected to the checks that IPsec + provides, if the SPD is suitably configured, as described in Section + 6.2. + +12. IANA Considerations + + The IANA has assigned the value (3) for the asn1-modules registry and + has assigned the object identifier 1.3.6.1.5.8.3.1 for the SPD + module. See Appendix C, "ASN.1 for an SPD Entry". + +13. Differences from RFC 2401 + + This architecture document differs substantially from RFC 2401 + [RFC2401] in detail and in organization, but the fundamental notions + are unchanged. + + o The processing model has been revised to address new IPsec + scenarios, improve performance, and simplify implementation. This + includes a separation between forwarding (routing) and SPD + + + +Kent & Seo Standards Track [Page 72] + +RFC 4301 Security Architecture for IP December 2005 + + + selection, several SPD changes, and the addition of an outbound SPD + cache and an inbound SPD cache for bypassed or discarded traffic. + There is also a new database, the Peer Authorization Database + (PAD). This provides a link between an SA management protocol + (such as IKE) and the SPD. + + o There is no longer a requirement to support nested SAs or "SA + bundles". Instead this functionality can be achieved through SPD + and forwarding table configuration. An example of a configuration + has been added in Appendix E. + + o SPD entries were redefined to provide more flexibility. Each SPD + entry now consists of 1 to N sets of selectors, where each selector + set contains one protocol and a "list of ranges" can now be + specified for the Local IP address, Remote IP address, and whatever + fields (if any) are associated with the Next Layer Protocol (Local + Port, Remote Port, ICMP message type and code, and Mobility Header + type). An individual value for a selector is represented via a + trivial range and ANY is represented via a range than spans all + values for the selector. An example of an ASN.1 description is + included in Appendix C. + + o TOS (IPv4) and Traffic Class (IPv6) have been replaced by DSCP and + ECN. The tunnel section has been updated to explain how to handle + DSCP and ECN bits. + + o For tunnel mode SAs, an SG, BITS, or BITW implementation is now + allowed to fragment packets before applying IPsec. This applies + only to IPv4. For IPv6 packets, only the originator is allowed to + fragment them. + + o When security is desired between two intermediate systems along a + path or between an intermediate system and an end system, transport + mode may now be used between security gateways and between a + security gateway and a host. + + o This document clarifies that for all traffic that crosses the IPsec + boundary, including IPsec management traffic, the SPD or associated + caches must be consulted. + + o This document defines how to handle the situation of a security + gateway with multiple subscribers requiring separate IPsec + contexts. + + o A definition of reserved SPIs has been added. + + + + + + +Kent & Seo Standards Track [Page 73] + +RFC 4301 Security Architecture for IP December 2005 + + + o Text has been added explaining why ALL IP packets must be checked + -- IPsec includes minimal firewall functionality to support access + control at the IP layer. + + o The tunnel section has been updated to clarify how to handle the IP + options field and IPv6 extension headers when constructing the + outer header. + + o SA mapping for inbound traffic has been updated to be consistent + with the changes made in AH and ESP for support of unicast and + multicast SAs. + + o Guidance has been added regarding how to handle the covert channel + created in tunnel mode by copying the DSCP value to outer header. + + o Support for AH in both IPv4 and IPv6 is no longer required. + + o PMTU handling has been updated. The appendix on + PMTU/DF/Fragmentation has been deleted. + + o Three approaches have been added for handling plaintext fragments + on the protected side of the IPsec boundary. Appendix D documents + the rationale behind them. + + o Added revised text describing how to derive selector values for SAs + (from the SPD entry or from the packet, etc.) + + o Added a new table describing the relationship between selector + values in an SPD entry, the PFP flag, and resulting selector values + in the corresponding SAD entry. + + o Added Appendix B to describe decorrelation. + + o Added text describing how to handle an outbound packet that must be + discarded. + + o Added text describing how to handle a DISCARDED inbound packet, + i.e., one that does not match the SA upon which it arrived. + + o IPv6 mobility header has been added as a possible Next Layer + Protocol. IPv6 Mobility Header message type has been added as a + selector. + + o ICMP message type and code have been added as selectors. + + o The selector "data sensitivity level" has been removed to simplify + things. + + + + +Kent & Seo Standards Track [Page 74] + +RFC 4301 Security Architecture for IP December 2005 + + + o Updated text describing handling ICMP error messages. The appendix + on "Categorization of ICMP Messages" has been deleted. + + o The text for the selector name has been updated and clarified. + + o The "Next Layer Protocol" has been further explained and a default + list of protocols to skip when looking for the Next Layer Protocol + has been added. + + o The text has been amended to say that this document assumes use of + IKEv2 or an SA management protocol with comparable features. + + o Text has been added clarifying the algorithm for mapping inbound + IPsec datagrams to SAs in the presence of multicast SAs. + + o The appendix "Sequence Space Window Code Example" has been removed. + + o With respect to IP addresses and ports, the terms "Local" and + "Remote" are used for policy rules (replacing source and + destination). "Local" refers to the entity being protected by an + IPsec implementation, i.e., the "source" address/port of outbound + packets or the "destination" address/port of inbound packets. + "Remote" refers to a peer entity or peer entities. The terms + "source" and "destination" are still used for packet header fields. + +14. Acknowledgements + + The authors would like to acknowledge the contributions of Ran + Atkinson, who played a critical role in initial IPsec activities, and + who authored the first series of IPsec standards: RFCs 1825-1827; and + Charlie Lynn, who made significant contributions to the second series + of IPsec standards (RFCs 2401, 2402, and 2406) and to the current + versions, especially with regard to IPv6 issues. The authors also + would like to thank the members of the IPsec and MSEC working groups + who have contributed to the development of this protocol + specification. + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 75] + +RFC 4301 Security Architecture for IP December 2005 + + +Appendix A: Glossary + + This section provides definitions for several key terms that are + employed in this document. Other documents provide additional + definitions and background information relevant to this technology, + e.g., [Shi00], [VK83], and [HA94]. Included in this glossary are + generic security service and security mechanism terms, plus + IPsec-specific terms. + + Access Control + A security service that prevents unauthorized use of a resource, + including the prevention of use of a resource in an unauthorized + manner. In the IPsec context, the resource to which access is + being controlled is often: + + o for a host, computing cycles or data + o for a security gateway, a network behind the gateway + or bandwidth on that network. + + Anti-replay + See "Integrity" below. + + Authentication + Used informally to refer to the combination of two nominally + distinct security services, data origin authentication and + connectionless integrity. See the definitions below for each of + these services. + + Availability + When viewed as a security service, addresses the security concerns + engendered by attacks against networks that deny or degrade + service. For example, in the IPsec context, the use of + anti-replay mechanisms in AH and ESP support availability. + + Confidentiality + The security service that protects data from unauthorized + disclosure. The primary confidentiality concern in most instances + is unauthorized disclosure of application-level data, but + disclosure of the external characteristics of communication also + can be a concern in some circumstances. Traffic flow + confidentiality is the service that addresses this latter concern + by concealing source and destination addresses, message length, or + frequency of communication. In the IPsec context, using ESP in + tunnel mode, especially at a security gateway, can provide some + level of traffic flow confidentiality. (See also "Traffic + Analysis" below.) + + + + + +Kent & Seo Standards Track [Page 76] + +RFC 4301 Security Architecture for IP December 2005 + + + Data Origin Authentication + A security service that verifies the identity of the claimed + source of data. This service is usually bundled with + connectionless integrity service. + + Encryption + A security mechanism used to transform data from an intelligible + form (plaintext) into an unintelligible form (ciphertext), to + provide confidentiality. The inverse transformation process is + designated "decryption". Often the term "encryption" is used to + generically refer to both processes. + + Integrity + A security service that ensures that modifications to data are + detectable. Integrity comes in various flavors to match + application requirements. IPsec supports two forms of integrity: + connectionless and a form of partial sequence integrity. + Connectionless integrity is a service that detects modification of + an individual IP datagram, without regard to the ordering of the + datagram in a stream of traffic. The form of partial sequence + integrity offered in IPsec is referred to as anti-replay + integrity, and it detects arrival of duplicate IP datagrams + (within a constrained window). This is in contrast to + connection-oriented integrity, which imposes more stringent + sequencing requirements on traffic, e.g., to be able to detect + lost or re-ordered messages. Although authentication and + integrity services often are cited separately, in practice they + are intimately connected and almost always offered in tandem. + + Protected vs. Unprotected + "Protected" refers to the systems or interfaces that are inside + the IPsec protection boundary, and "unprotected" refers to the + systems or interfaces that are outside the IPsec protection + boundary. IPsec provides a boundary through which traffic passes. + There is an asymmetry to this barrier, which is reflected in the + processing model. Outbound data, if not discarded or bypassed, is + protected via the application of AH or ESP and the addition of the + corresponding headers. Inbound data, if not discarded or + bypassed, is processed via the removal of AH or ESP headers. In + this document, inbound traffic enters an IPsec implementation from + the "unprotected" interface. Outbound traffic enters the + implementation via the "protected" interface, or is internally + generated by the implementation on the "protected" side of the + boundary and directed toward the "unprotected" interface. An + IPsec implementation may support more than one interface on either + or both sides of the boundary. The protected interface may be + + + + + +Kent & Seo Standards Track [Page 77] + +RFC 4301 Security Architecture for IP December 2005 + + + internal, e.g., in a host implementation of IPsec. The protected + interface may link to a socket layer interface presented by the + OS. + + Security Association (SA) + A simplex (uni-directional) logical connection, created for + security purposes. All traffic traversing an SA is provided the + same security processing. In IPsec, an SA is an Internet-layer + abstraction implemented through the use of AH or ESP. State data + associated with an SA is represented in the SA Database (SAD). + + Security Gateway + An intermediate system that acts as the communications interface + between two networks. The set of hosts (and networks) on the + external side of the security gateway is termed unprotected (they + are generally at least less protected than those "behind" the SG), + while the networks and hosts on the internal side are viewed as + protected. The internal subnets and hosts served by a security + gateway are presumed to be trusted by virtue of sharing a common, + local, security administration. In the IPsec context, a security + gateway is a point at which AH and/or ESP is implemented in order + to serve a set of internal hosts, providing security services for + these hosts when they communicate with external hosts also + employing IPsec (either directly or via another security gateway). + + Security Parameters Index (SPI) + An arbitrary 32-bit value that is used by a receiver to identify + the SA to which an incoming packet should be bound. For a unicast + SA, the SPI can be used by itself to specify an SA, or it may be + used in conjunction with the IPsec protocol type. Additional IP + address information is used to identify multicast SAs. The SPI is + carried in AH and ESP protocols to enable the receiving system to + select the SA under which a received packet will be processed. An + SPI has only local significance, as defined by the creator of the + SA (usually the receiver of the packet carrying the SPI); thus an + SPI is generally viewed as an opaque bit string. However, the + creator of an SA may choose to interpret the bits in an SPI to + facilitate local processing. + + Traffic Analysis + The analysis of network traffic flow for the purpose of deducing + information that is useful to an adversary. Examples of such + information are frequency of transmission, the identities of the + conversing parties, sizes of packets, and flow identifiers + [Sch94]. + + + + + + +Kent & Seo Standards Track [Page 78] + +RFC 4301 Security Architecture for IP December 2005 + + +Appendix B: Decorrelation + + This appendix is based on work done for caching of policies in the IP + Security Policy Working Group by Luis Sanchez, Matt Condell, and John + Zao. + + Two SPD entries are correlated if there is a non-null intersection + between the values of corresponding selectors in each entry. Caching + correlated SPD entries can lead to incorrect policy enforcement. A + solution to this problem, which still allows for caching, is to + remove the ambiguities by decorrelating the entries. That is, the + SPD entries must be rewritten so that for every pair of entries there + exists a selector for which there is a null intersection between the + values in both of the entries. Once the entries are decorrelated, + there is no longer any ordering requirement on them, since only one + entry will match any lookup. The next section describes + decorrelation in more detail and presents an algorithm that may be + used to implement decorrelation. + +B.1. Decorrelation Algorithm + + The basic decorrelation algorithm takes each entry in a correlated + SPD and divides it into a set of entries using a tree structure. + The nodes of the tree are the selectors that may overlap between the + policies. At each node, the algorithm creates a branch for each of + the values of the selector. It also creates one branch for the + complement of the union of all selector values. Policies are then + formed by traversing the tree from the root to each leaf. The + policies at the leaves are compared to the set of already + decorrelated policy rules. Each policy at a leaf is either + completely overridden by a policy in the already decorrelated set and + is discarded or is decorrelated with all the policies in the + decorrelated set and is added to it. + + The basic algorithm does not guarantee an optimal set of decorrelated + entries. That is, the entries may be broken up into smaller sets + than is necessary, though they will still provide all the necessary + policy information. Some extensions to the basic algorithm are + described later to improve this and improve the performance of the + algorithm. + + C A set of ordered, correlated entries (a correlated SPD). + Ci The ith entry in C. + U The set of decorrelated entries being built from C. + Ui The ith entry in U. + Sik The kth selection for policy Ci. + Ai The action for policy Ci. + + + + +Kent & Seo Standards Track [Page 79] + +RFC 4301 Security Architecture for IP December 2005 + + + A policy (SPD entry) P may be expressed as a sequence of selector + values and an action (BYPASS, DISCARD, or PROTECT): + + Ci = Si1 x Si2 x ... x Sik -> Ai + + 1) Put C1 in set U as U1 + + For each policy Cj (j > 1) in C + + 2) If Cj is decorrelated with every entry in U, then add it to U. + + 3) If Cj is correlated with one or more entries in U, create a tree + rooted at the policy Cj that partitions Cj into a set of decorrelated + entries. The algorithm starts with a root node where no selectors + have yet been chosen. + + A) Choose a selector in Cj, Sjn, that has not yet been chosen when + traversing the tree from the root to this node. If there are no + selectors not yet used, continue to the next unfinished branch + until all branches have been completed. When the tree is + completed, go to step D. + + T is the set of entries in U that are correlated with the entry + at this node. + + The entry at this node is the entry formed by the selector + values of each of the branches between the root and this node. + Any selector values that are not yet represented by branches + assume the corresponding selector value in Cj, since the values + in Cj represent the maximum value for each selector. + + B) Add a branch to the tree for each value of the selector Sjn that + appears in any of the entries in T. (If the value is a superset + of the value of Sjn in Cj, then use the value in Cj, since that + value represents the universal set.) Also add a branch for the + complement of the union of all the values of the selector Sjn + in T. When taking the complement, remember that the universal + set is the value of Sjn in Cj. A branch need not be created + for the null set. + + C) Repeat A and B until the tree is completed. + + D) The entry to each leaf now represents an entry that is a subset + of Cj. The entries at the leaves completely partition Cj in + such a way that each entry is either completely overridden by + an entry in U, or is decorrelated with the entries in U. + + Add all the decorrelated entries at the leaves of the tree to U. + + + +Kent & Seo Standards Track [Page 80] + +RFC 4301 Security Architecture for IP December 2005 + + + 4) Get next Cj and go to 2. + + 5) When all entries in C have been processed, then U will contain an + decorrelated version of C. + + There are several optimizations that can be made to this algorithm. + A few of them are presented here. + + It is possible to optimize, or at least improve, the amount of + branching that occurs by carefully choosing the order of the + selectors used for the next branch. For example, if a selector Sjn + can be chosen so that all the values for that selector in T are equal + to or a superset of the value of Sjn in Cj, then only a single branch + needs to be created (since the complement will be null). + + Branches of the tree do not have to proceed with the entire + decorrelation algorithm. For example, if a node represents an entry + that is decorrelated with all the entries in U, then there is no + reason to continue decorrelating that branch. Also, if a branch is + completely overridden by an entry in U, then there is no reason to + continue decorrelating the branch. + + An additional optimization is to check to see if a branch is + overridden by one of the CORRELATED entries in set C that has already + been decorrelated. That is, if the branch is part of decorrelating + Cj, then check to see if it was overridden by an entry Cm, m < j. + This is a valid check, since all the entries Cm are already expressed + in U. + + Along with checking if an entry is already decorrelated in step 2, + check if Cj is overridden by any entry in U. If it is, skip it since + it is not relevant. An entry x is overridden by another entry y if + every selector in x is equal to or a subset of the corresponding + selector in entry y. + + + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 81] + +RFC 4301 Security Architecture for IP December 2005 + + +Appendix C: ASN.1 for an SPD Entry + + This appendix is included as an additional way to describe SPD + entries, as defined in Section 4.4.1. It uses ASN.1 syntax that has + been successfully compiled. This syntax is merely illustrative and + need not be employed in an implementation to achieve compliance. The + SPD description in Section 4.4.1 is normative. + + SPDModule + + {iso(1) org (3) dod (6) internet (1) security (5) mechanisms (5) + ipsec (8) asn1-modules (3) spd-module (1) } + + DEFINITIONS IMPLICIT TAGS ::= + + BEGIN + + IMPORTS + RDNSequence FROM PKIX1Explicit88 + { iso(1) identified-organization(3) + dod(6) internet(1) security(5) mechanisms(5) pkix(7) + id-mod(0) id-pkix1-explicit(18) } ; + + -- An SPD is a list of policies in decreasing order of preference + SPD ::= SEQUENCE OF SPDEntry + + SPDEntry ::= CHOICE { + iPsecEntry IPsecEntry, -- PROTECT traffic + bypassOrDiscard [0] BypassOrDiscardEntry } -- DISCARD/BYPASS + + IPsecEntry ::= SEQUENCE { -- Each entry consists of + name NameSets OPTIONAL, + pFPs PacketFlags, -- Populate from packet flags + -- Applies to ALL of the corresponding + -- traffic selectors in the SelectorLists + condition SelectorLists, -- Policy "condition" + processing Processing -- Policy "action" + } + + BypassOrDiscardEntry ::= SEQUENCE { + bypass BOOLEAN, -- TRUE BYPASS, FALSE DISCARD + condition InOutBound } + + InOutBound ::= CHOICE { + outbound [0] SelectorLists, + inbound [1] SelectorLists, + bothways [2] BothWays } + + + + +Kent & Seo Standards Track [Page 82] + +RFC 4301 Security Architecture for IP December 2005 + + + BothWays ::= SEQUENCE { + inbound SelectorLists, + outbound SelectorLists } + + NameSets ::= SEQUENCE { + passed SET OF Names-R, -- Matched to IKE ID by + -- responder + local SET OF Names-I } -- Used internally by IKE + -- initiator + + Names-R ::= CHOICE { -- IKEv2 IDs + dName RDNSequence, -- ID_DER_ASN1_DN + fqdn FQDN, -- ID_FQDN + rfc822 [0] RFC822Name, -- ID_RFC822_ADDR + keyID OCTET STRING } -- KEY_ID + + Names-I ::= OCTET STRING -- Used internally by IKE + -- initiator + + FQDN ::= IA5String + + RFC822Name ::= IA5String + + PacketFlags ::= BIT STRING { + -- if set, take selector value from packet + -- establishing SA + -- else use value in SPD entry + localAddr (0), + remoteAddr (1), + protocol (2), + localPort (3), + remotePort (4) } + + SelectorLists ::= SET OF SelectorList + + SelectorList ::= SEQUENCE { + localAddr AddrList, + remoteAddr AddrList, + protocol ProtocolChoice } + + Processing ::= SEQUENCE { + extSeqNum BOOLEAN, -- TRUE 64 bit counter, FALSE 32 bit + seqOverflow BOOLEAN, -- TRUE rekey, FALSE terminate & audit + fragCheck BOOLEAN, -- TRUE stateful fragment checking, + -- FALSE no stateful fragment checking + lifetime SALifetime, + spi ManualSPI, + algorithms ProcessingAlgs, + + + +Kent & Seo Standards Track [Page 83] + +RFC 4301 Security Architecture for IP December 2005 + + + tunnel TunnelOptions OPTIONAL } -- if absent, use + -- transport mode + + SALifetime ::= SEQUENCE { + seconds [0] INTEGER OPTIONAL, + bytes [1] INTEGER OPTIONAL } + + ManualSPI ::= SEQUENCE { + spi INTEGER, + keys KeyIDs } + + KeyIDs ::= SEQUENCE OF OCTET STRING + + ProcessingAlgs ::= CHOICE { + ah [0] IntegrityAlgs, -- AH + esp [1] ESPAlgs} -- ESP + + ESPAlgs ::= CHOICE { + integrity [0] IntegrityAlgs, -- integrity only + confidentiality [1] ConfidentialityAlgs, -- confidentiality + -- only + both [2] IntegrityConfidentialityAlgs, + combined [3] CombinedModeAlgs } + + IntegrityConfidentialityAlgs ::= SEQUENCE { + integrity IntegrityAlgs, + confidentiality ConfidentialityAlgs } + + -- Integrity Algorithms, ordered by decreasing preference + IntegrityAlgs ::= SEQUENCE OF IntegrityAlg + + -- Confidentiality Algorithms, ordered by decreasing preference + ConfidentialityAlgs ::= SEQUENCE OF ConfidentialityAlg + + -- Integrity Algorithms + IntegrityAlg ::= SEQUENCE { + algorithm IntegrityAlgType, + parameters ANY -- DEFINED BY algorithm -- OPTIONAL } + + IntegrityAlgType ::= INTEGER { + none (0), + auth-HMAC-MD5-96 (1), + auth-HMAC-SHA1-96 (2), + auth-DES-MAC (3), + auth-KPDK-MD5 (4), + auth-AES-XCBC-96 (5) + -- tbd (6..65535) + } + + + +Kent & Seo Standards Track [Page 84] + +RFC 4301 Security Architecture for IP December 2005 + + + -- Confidentiality Algorithms + ConfidentialityAlg ::= SEQUENCE { + algorithm ConfidentialityAlgType, + parameters ANY -- DEFINED BY algorithm -- OPTIONAL } + + ConfidentialityAlgType ::= INTEGER { + encr-DES-IV64 (1), + encr-DES (2), + encr-3DES (3), + encr-RC5 (4), + encr-IDEA (5), + encr-CAST (6), + encr-BLOWFISH (7), + encr-3IDEA (8), + encr-DES-IV32 (9), + encr-RC4 (10), + encr-NULL (11), + encr-AES-CBC (12), + encr-AES-CTR (13) + -- tbd (14..65535) + } + + CombinedModeAlgs ::= SEQUENCE OF CombinedModeAlg + + CombinedModeAlg ::= SEQUENCE { + algorithm CombinedModeType, + parameters ANY -- DEFINED BY algorithm} -- defined outside + -- of this document for AES modes. + + CombinedModeType ::= INTEGER { + comb-AES-CCM (1), + comb-AES-GCM (2) + -- tbd (3..65535) + } + + TunnelOptions ::= SEQUENCE { + dscp DSCP, + ecn BOOLEAN, -- TRUE Copy CE to inner header + df DF, + addresses TunnelAddresses } + + TunnelAddresses ::= CHOICE { + ipv4 IPv4Pair, + ipv6 [0] IPv6Pair } + + IPv4Pair ::= SEQUENCE { + local OCTET STRING (SIZE(4)), + remote OCTET STRING (SIZE(4)) } + + + +Kent & Seo Standards Track [Page 85] + +RFC 4301 Security Architecture for IP December 2005 + + + IPv6Pair ::= SEQUENCE { + local OCTET STRING (SIZE(16)), + remote OCTET STRING (SIZE(16)) } + + DSCP ::= SEQUENCE { + copy BOOLEAN, -- TRUE copy from inner header + -- FALSE do not copy + mapping OCTET STRING OPTIONAL} -- points to table + -- if no copy + + DF ::= INTEGER { + clear (0), + set (1), + copy (2) } + + ProtocolChoice::= CHOICE { + anyProt AnyProtocol, -- for ANY protocol + noNext [0] NoNextLayerProtocol, -- has no next layer + -- items + oneNext [1] OneNextLayerProtocol, -- has one next layer + -- item + twoNext [2] TwoNextLayerProtocol, -- has two next layer + -- items + fragment FragmentNoNext } -- has no next layer + -- info + + AnyProtocol ::= SEQUENCE { + id INTEGER (0), -- ANY protocol + nextLayer AnyNextLayers } + + AnyNextLayers ::= SEQUENCE { -- with either + first AnyNextLayer, -- ANY next layer selector + second AnyNextLayer } -- ANY next layer selector + + NoNextLayerProtocol ::= INTEGER (2..254) + + FragmentNoNext ::= INTEGER (44) -- Fragment identifier + + OneNextLayerProtocol ::= SEQUENCE { + id INTEGER (1..254), -- ICMP, MH, ICMPv6 + nextLayer NextLayerChoice } -- ICMP Type*256+Code + -- MH Type*256 + + TwoNextLayerProtocol ::= SEQUENCE { + id INTEGER (2..254), -- Protocol + local NextLayerChoice, -- Local and + remote NextLayerChoice } -- Remote ports + + + + +Kent & Seo Standards Track [Page 86] + +RFC 4301 Security Architecture for IP December 2005 + + + NextLayerChoice ::= CHOICE { + any AnyNextLayer, + opaque [0] OpaqueNextLayer, + range [1] NextLayerRange } + + -- Representation of ANY in next layer field + AnyNextLayer ::= SEQUENCE { + start INTEGER (0), + end INTEGER (65535) } + + -- Representation of OPAQUE in next layer field. + -- Matches IKE convention + OpaqueNextLayer ::= SEQUENCE { + start INTEGER (65535), + end INTEGER (0) } + + -- Range for a next layer field + NextLayerRange ::= SEQUENCE { + start INTEGER (0..65535), + end INTEGER (0..65535) } + + -- List of IP addresses + AddrList ::= SEQUENCE { + v4List IPv4List OPTIONAL, + v6List [0] IPv6List OPTIONAL } + + -- IPv4 address representations + IPv4List ::= SEQUENCE OF IPv4Range + + IPv4Range ::= SEQUENCE { -- close, but not quite right ... + ipv4Start OCTET STRING (SIZE (4)), + ipv4End OCTET STRING (SIZE (4)) } + + -- IPv6 address representations + IPv6List ::= SEQUENCE OF IPv6Range + + IPv6Range ::= SEQUENCE { -- close, but not quite right ... + ipv6Start OCTET STRING (SIZE (16)), + ipv6End OCTET STRING (SIZE (16)) } + + END + + + + + + + + + + +Kent & Seo Standards Track [Page 87] + +RFC 4301 Security Architecture for IP December 2005 + + +Appendix D: Fragment Handling Rationale + + There are three issues that must be resolved regarding processing of + (plaintext) fragments in IPsec: + + - mapping a non-initial, outbound fragment to the right SA + (or finding the right SPD entry) + - verifying that a received, non-initial fragment is authorized + for the SA via which it is received + - mapping outbound and inbound non-initial fragments to the + right SPD/cache entry, for BYPASS/DISCARD traffic + + The first and third issues arise because we need a deterministic + algorithm for mapping traffic to SAs (and SPD/cache entries). All + three issues are important because we want to make sure that + non-initial fragments that cross the IPsec boundary do not cause the + access control policies in place at the receiver (or transmitter) to + be violated. + +D.1. Transport Mode and Fragments + + First, we note that transport mode SAs have been defined to not carry + fragments. This is a carryover from RFC 2401, where transport mode + SAs always terminated at endpoints. This is a fundamental + requirement because, in the worst case, an IPv4 fragment to which + IPsec was applied might then be fragmented (as a ciphertext packet), + en route to the destination. IP fragment reassembly procedures at + the IPsec receiver would not be able to distinguish between pre-IPsec + fragments and fragments created after IPsec processing. + + For IPv6, only the sender is allowed to fragment a packet. As for + IPv4, an IPsec implementation is allowed to fragment tunnel mode + packets after IPsec processing, because it is the sender relative to + the (outer) tunnel header. However, unlike IPv4, it would be + feasible to carry a plaintext fragment on a transport mode SA, + because the fragment header in IPv6 would appear after the AH or ESP + header, and thus would not cause confusion at the receiver with + respect to reassembly. Specifically, the receiver would not attempt + reassembly for the fragment until after IPsec processing. To keep + things simple, this specification prohibits carriage of fragments on + transport mode SAs for IPv6 traffic. + + When only end systems used transport mode SAs, the prohibition on + carriage of fragments was not a problem, since we assumed that the + end system could be configured to not offer a fragment to IPsec. For + a native host implementation, this seems reasonable, and, as someone + already noted, RFC 2401 warned that a BITS implementation might have + to reassemble fragments before performing an SA lookup. (It would + + + +Kent & Seo Standards Track [Page 88] + +RFC 4301 Security Architecture for IP December 2005 + + + then apply AH or ESP and could re-fragment the packet after IPsec + processing.) Because a BITS implementation is assumed to be able to + have access to all traffic emanating from its host, even if the host + has multiple interfaces, this was deemed a reasonable mandate. + + In this specification, it is acceptable to use transport mode in + cases where the IPsec implementation is not the ultimate destination, + e.g., between two SGs. In principle, this creates a new opportunity + for outbound, plaintext fragments to be mapped to a transport mode SA + for IPsec processing. However, in these new contexts in which a + transport mode SA is now approved for use, it seems likely that we + can continue to prohibit transmission of fragments, as seen by IPsec, + i.e., packets that have an "outer header" with a non-zero fragment + offset field. For example, in an IP overlay network, packets being + sent over transport mode SAs are IP-in-IP tunneled and thus have the + necessary inner header to accommodate fragmentation prior to IPsec + processing. When carried via a transport mode SA, IPsec would not + examine the inner IP header for such traffic, and thus would not + consider the packet to be a fragment. + +D.2. Tunnel Mode and Fragments + + For tunnel mode SAs, it has always been the case that outbound + fragments might arrive for processing at an IPsec implementation. + The need to accommodate fragmented outbound packets can pose a + problem because a non-initial fragment generally will not contain the + port fields associated with a next layer protocol such as TCP, UDP, + or SCTP. Thus, depending on the SPD configuration for a given IPsec + implementation, plaintext fragments might or might not pose a + problem. + + For example, if the SPD requires that all traffic between two address + ranges is offered IPsec protection (no BYPASS or DISCARD SPD entries + apply to this address range), then it should be easy to carry + non-initial fragments on the SA defined for this address range, since + the SPD entry implies an intent to carry ALL traffic between the + address ranges. But, if there are multiple SPD entries that could + match a fragment, and if these entries reference different subsets of + port fields (vs. ANY), then it is not possible to map an outbound + non-initial fragment to the right entry, unambiguously. (If we choose + to allow carriage of fragments on transport mode SAs for IPv6, the + problems arises in that context as well.) + + This problem largely, though not exclusively, motivated the + definition of OPAQUE as a selector value for port fields in RFC 2401. + The other motivation for OPAQUE is the observation that port fields + might not be accessible due to the prior application of IPsec. For + example, if a host applied IPsec to its traffic and that traffic + + + +Kent & Seo Standards Track [Page 89] + +RFC 4301 Security Architecture for IP December 2005 + + + arrived at an SG, these fields would be encrypted. The algorithm + specified for locating the "next layer protocol" described in RFC + 2401 also motivated use of OPAQUE to accommodate an encrypted next + layer protocol field in such circumstances. Nonetheless, the primary + use of the OPAQUE value was to match traffic selector fields in + packets that did not contain port fields (non-initial fragments), or + packets in which the port fields were already encrypted (as a result + of nested application of IPsec). RFC 2401 was ambiguous in + discussing the use of OPAQUE vs. ANY, suggesting in some places that + ANY might be an alternative to OPAQUE. + + We gain additional access control capability by defining both ANY and + OPAQUE values. OPAQUE can be defined to match only fields that are + not accessible. We could define ANY as the complement of OPAQUE, + i.e., it would match all values but only for accessible port fields. + We have therefore simplified the procedure employed to locate the + next layer protocol in this document, so that we treat ESP and AH as + next layer protocols. As a result, the notion of an encrypted next + layer protocol field has vanished, and there is also no need to worry + about encrypted port fields either. And accordingly, OPAQUE will be + applicable only to non-initial fragments. + + Since we have adopted the definitions above for ANY and OPAQUE, we + need to clarify how these values work when the specified protocol + does not have port fields, and when ANY is used for the protocol + selector. Accordingly, if a specific protocol value is used as a + selector, and if that protocol has no port fields, then the port + field selectors are to be ignored and ANY MUST be specified as the + value for the port fields. (In this context, ICMP TYPE and CODE + values are lumped together as a single port field (for IKEv2 + negotiation), as is the IPv6 Mobility Header TYPE value.) If the + protocol selector is ANY, then this should be treated as equivalent + to specifying a protocol for which no port fields are defined, and + thus the port selectors should be ignored, and MUST be set to ANY. + +D.3. The Problem of Non-Initial Fragments + + For an SG implementation, it is obvious that fragments might arrive + from end systems behind the SG. A BITW implementation also may + encounter fragments from a host or gateway behind it. (As noted + earlier, native host implementations and BITS implementations + probably can avoid the problems described below.) In the worst case, + fragments from a packet might arrive at distinct BITW or SG + instantiations and thus preclude reassembly as a solution option. + Hence, in RFC 2401 we adopted a general requirement that fragments + must be accommodated in tunnel mode for all implementations. However, + + + + + +Kent & Seo Standards Track [Page 90] + +RFC 4301 Security Architecture for IP December 2005 + + + RFC 2401 did not provide a perfect solution. The use of OPAQUE as a + selector value for port fields (a SHOULD in RFC 2401) allowed an SA + to carry non-initial fragments. + + Using the features defined in RFC 2401, if one defined an SA between + two IPsec (SG or BITW) implementations using the OPAQUE value for + both port fields, then all non-initial fragments matching the + source/destination (S/D) address and protocol values for the SA would + be mapped to that SA. Initial fragments would NOT map to this SA, if + we adopt a strict definition of OPAQUE. However, RFC 2401 did not + provide detailed guidance on this and thus it may not have been + apparent that use of this feature would essentially create a + "non-initial fragment only" SA. + + In the course of discussing the "fragment-only" SA approach, it was + noted that some subtle problems, problems not considered in RFC 2401, + would have to be avoided. For example, an SA of this sort must be + configured to offer the "highest quality" security services for any + traffic between the indicated S/D addresses (for the specified + protocol). This is necessary to ensure that any traffic captured by + the fragment-only SA is not offered degraded security relative to + what it would have been offered if the packet were not fragmented. A + possible problem here is that we may not be able to identify the + "highest quality" security services defined for use between two IPsec + implementation, since the choice of security protocols, options, and + algorithms is a lattice, not a totally ordered set. (We might safely + say that BYPASS < AH < ESP w/integrity, but it gets complicated if we + have multiple ESP encryption or integrity algorithm options.) So, one + has to impose a total ordering on these security parameters to make + this work, but this can be done locally. + + However, this conservative strategy has a possible performance + downside. If most traffic traversing an IPsec implementation for a + given S/D address pair (and specified protocol) is bypassed, then a + fragment-only SA for that address pair might cause a dramatic + increase in the volume of traffic afforded crypto processing. If the + crypto implementation cannot support high traffic rates, this could + cause problems. (An IPsec implementation that is capable of line rate + or near line rate crypto performance would not be adversely affected + by this SA configuration approach. Nonetheless, the performance + impact is a potential concern, specific to implementation + capabilities.) + + Another concern is that non-initial fragments sent over a dedicated + SA might be used to effect overlapping reassembly attacks, when + combined with an apparently acceptable initial fragment. (This sort + of attack assumes creation of bogus fragments and is not a side + effect of normal fragmentation.) This concern is easily addressed in + + + +Kent & Seo Standards Track [Page 91] + +RFC 4301 Security Architecture for IP December 2005 + + + IPv4, by checking the fragment offset value to ensure that no + non-initial fragments have a small enough offset to overlap port + fields that should be contained in the initial fragment. Recall that + the IPv4 MTU minimum is 576 bytes, and the max IP header length is 60 + bytes, so any ports should be present in the initial fragment. If we + require all non-initial fragments to have an offset of, say, 128 or + greater, just to be on the safe side, this should prevent successful + attacks of this sort. If the intent is only to protect against this + sort of reassembly attack, this check need be implemented only by a + receiver. + + IPv6 also has a fragment offset, carried in the fragmentation + extension header. However, IPv6 extension headers are variable in + length and there is no analogous max header length value that we can + use to check non-initial fragments, to reject ones that might be used + for an attack of the sort noted above. A receiver would need to + maintain state analogous to reassembly state, to provide equivalent + protection. So, only for IPv4 is it feasible to impose a fragment + offset check that would reject attacks designed to circumvent port + field checks by IPsec (or firewalls) when passing non-initial + fragments. + + Another possible concern is that in some topologies and SPD + configurations this approach might result in an access control + surprise. The notion is that if we create an SA to carry ALL + (non-initial) fragments, then that SA would carry some traffic that + might otherwise arrive as plaintext via a separate path, e.g., a path + monitored by a proxy firewall. But, this concern arises only if the + other path allows initial fragments to traverse it without requiring + reassembly, presumably a bad idea for a proxy firewall. Nonetheless, + this does represent a potential problem in some topologies and under + certain assumptions with respect to SPD and (other) firewall rule + sets, and administrators need to be warned of this possibility. + + A less serious concern is that non-initial fragments sent over a + non-initial fragment-only SA might represent a DoS opportunity, in + that they could be sent when no valid, initial fragment will ever + arrive. This might be used to attack hosts behind an SG or BITW + device. However, the incremental risk posed by this sort of attack, + which can be mounted only by hosts behind an SG or BITW device, seems + small. + + If we interpret the ANY selector value as encompassing OPAQUE, then a + single SA with ANY values for both port fields would be able to + accommodate all traffic matching the S/D address and protocol traffic + selectors, an alternative to using the OPAQUE value. But, using ANY + + + + + +Kent & Seo Standards Track [Page 92] + +RFC 4301 Security Architecture for IP December 2005 + + + here precludes multiple, distinct SAs between the same IPsec + implementations for the same address pairs and protocol. So, it is + not an exactly equivalent alternative. + + Fundamentally, fragment handling problems arise only when more than + one SA is defined with the same S/D address and protocol selector + values, but with different port field selector values. + +D.4. BYPASS/DISCARD Traffic + + We also have to address the non-initial fragment processing issue for + BYPASS/DISCARD entries, independent of SA processing. This is + largely a local matter for two reasons: + + 1) We have no means for coordinating SPD entries for such + traffic between IPsec implementations since IKE is not + invoked. + 2) Many of these entries refer to traffic that is NOT + directed to or received from a location that is using + IPsec. So there is no peer IPsec implementation with + which to coordinate via any means. + + However, this document should provide guidance here, consistent with + our goal of offering a well-defined, access control function for all + traffic, relative to the IPsec boundary. To that end, this document + says that implementations MUST support fragment reassembly for + BYPASS/DISCARD traffic when port fields are specified. An + implementation also MUST permit a user or administrator to accept + such traffic or reject such traffic using the SPD conventions + described in Section 4.4.1. The concern is that BYPASS of a + cleartext, non-initial fragment arriving at an IPsec implementation + could undermine the security afforded IPsec-protected traffic + directed to the same destination. For example, consider an IPsec + implementation configured with an SPD entry that calls for + IPsec-protection of traffic between a specific source/destination + address pair, and for a specific protocol and destination port, e.g., + TCP traffic on port 23 (Telnet). Assume that the implementation also + allows BYPASS of traffic from the same source/destination address + pair and protocol, but for a different destination port, e.g., port + 119 (NNTP). An attacker could send a non-initial fragment (with a + forged source address) that, if bypassed, could overlap with + IPsec-protected traffic from the same source and thus violate the + integrity of the IPsec-protected traffic. Requiring stateful + fragment checking for BYPASS entries with non-trivial port ranges + prevents attacks of this sort. + + + + + + +Kent & Seo Standards Track [Page 93] + +RFC 4301 Security Architecture for IP December 2005 + + +D.5. Just say no to ports? + + It has been suggested that we could avoid the problems described + above by not allowing port field selectors to be used in tunnel mode. + But the discussion above shows this to be an unnecessarily stringent + approach, i.e., since no problems arise for the native OS and BITS + implementations. Moreover, some WG members have described scenarios + where use of tunnel mode SAs with (non-trivial) port field selectors + is appropriate. So the challenge is defining a strategy that can + deal with this problem in BITW and SG contexts. Also note that + BYPASS/DISCARD entries in the SPD that make use of ports pose the + same problems, irrespective of tunnel vs. transport mode notions. + + Some folks have suggested that a firewall behind an SG or BITW should + be left to enforce port-level access controls and the effects of + fragmentation. However, this seems to be an incongruous suggestion + in that elsewhere in IPsec (e.g., in IKE payloads) we are concerned + about firewalls that always discard fragments. If many firewalls + don't pass fragments in general, why should we expect them to deal + with fragments in this case? So, this analysis rejects the suggestion + of disallowing use of port field selectors with tunnel mode SAs. + +D.6. Other Suggested Solutions + + One suggestion is to reassemble fragments at the sending IPsec + implementation, and thus avoid the problem entirely. This approach + is invisible to a receiver and thus could be adopted as a purely + local implementation option. + + A more sophisticated version of this suggestion calls for + establishing and maintaining minimal state from each initial fragment + encountered, to allow non-initial fragments to be matched to the + right SAs or SPD/cache entries. This implies an extension to the + current processing model (and the old one). The IPsec implementation + would intercept all fragments; capture Source/Destination IP + addresses, protocol, packet ID, and port fields from initial + fragments; and then use this data to map non-initial fragments to SAs + that require port fields. If this approach is employed, the receiver + needs to employ an equivalent scheme, as it too must verify that + received fragments are consistent with SA selector values. A + non-initial fragment that arrives prior to an initial fragment could + be cached or discarded, awaiting arrival of the corresponding initial + fragment. + + A downside of both approaches noted above is that they will not + always work. When a BITW device or SG is configured in a topology + that might allow some fragments for a packet to be processed at + different SGs or BITW devices, then there is no guarantee that all + + + +Kent & Seo Standards Track [Page 94] + +RFC 4301 Security Architecture for IP December 2005 + + + fragments will ever arrive at the same IPsec device. This approach + also raises possible processing problems. If the sender caches + non-initial fragments until the corresponding initial fragment + arrives, buffering problems might arise, especially at high speeds. + If the non-initial fragments are discarded rather than cached, there + is no guarantee that traffic will ever pass, e.g., retransmission + will result in different packet IDs that cannot be matched with prior + transmissions. In any case, housekeeping procedures will be needed + to decide when to delete the fragment state data, adding some + complexity to the system. Nonetheless, this is a viable solution in + some topologies, and these are likely to be common topologies. + + The Working Group rejected an earlier version of the convention of + creating an SA to carry only non-initial fragments, something that + was supported implicitly under the RFC 2401 model via use of OPAQUE + port fields, but never clearly articulated in RFC 2401. The + (rejected) text called for each non-initial fragment to be treated as + protocol 44 (the IPv6 fragment header protocol ID) by the sender and + receiver. This approach has the potential to make IPv4 and IPv6 + fragment handling more uniform, but it does not fundamentally change + the problem, nor does it address the issue of fragment handling for + BYPASS/DISCARD traffic. Given the fragment overlap attack problem + that IPv6 poses, it does not seem that it is worth the effort to + adopt this strategy. + +D.7. Consistency + + Earlier, the WG agreed to allow an IPsec BITS, BITW, or SG to perform + fragmentation prior to IPsec processing. If this fragmentation is + performed after SA lookup at the sender, there is no "mapping to the + right SA" problem. But, the receiver still needs to be able to + verify that the non-initial fragments are consistent with the SA via + which they are received. Since the initial fragment might be lost en + route, the receiver encounters all of the potential problems noted + above. Thus, if we are to be consistent in our decisions, we need to + say how a receiver will deal with the non-initial fragments that + arrive. + +D.8. Conclusions + + There is no simple, uniform way to handle fragments in all contexts. + Different approaches work better in different contexts. Thus, this + document offers 3 choices -- one MUST and two MAYs. At some point in + the future, if the community gains experience with the two MAYs, they + may become SHOULDs or MUSTs or other approaches may be proposed. + + + + + + +Kent & Seo Standards Track [Page 95] + +RFC 4301 Security Architecture for IP December 2005 + + +Appendix E: Example of Supporting Nested SAs via SPD and Forwarding + Table Entries + + This appendix provides an example of how to configure the SPD and + forwarding tables to support a nested pair of SAs, consistent with + the new processing model. For simplicity, this example assumes just + one SPD-I. + + The goal in this example is to support a transport mode SA from A to + C, carried over a tunnel mode SA from A to B. For example, A might + be a laptop connected to the public Internet, B might be a firewall + that protects a corporate network, and C might be a server on the + corporate network that demands end-to-end authentication of A's + traffic. + + +---+ +---+ +---+ + | A |=====| B | | C | + | |------------| | + | |=====| | | | + +---+ +---+ +---+ + + A's SPD contains entries of the form: + + Next Layer + Rule Local Remote Protocol Action + ---- ----- ------ ---------- ----------------------- + 1 C A ESP BYPASS + 2 A C ICMP,ESP PROTECT(ESP,tunnel,integr+conf) + 3 A C ANY PROTECT(ESP,transport,integr-only) + 4 A B ICMP,IKE BYPASS + + A's unprotected-side forwarding table is set so that outbound packets + destined for C are looped back to the protected side. A's + protected-side forwarding table is set so that inbound ESP packets + are looped back to the unprotected side. A's forwarding tables + contain entries of the form: + + Unprotected-side forwarding table + + Rule Local Remote Protocol Action + ---- ----- ------ -------- --------------------------- + 1 A C ANY loop back to protected side + 2 A B ANY forward to B + + + + + + + + +Kent & Seo Standards Track [Page 96] + +RFC 4301 Security Architecture for IP December 2005 + + + Protected-side forwarding table + + Rule Local Remote Protocol Action + ---- ----- ------ -------- ----------------------------- + 1 A C ESP loop back to unprotected side + + An outbound TCP packet from A to C would match SPD rule 3 and have + transport mode ESP applied to it. The unprotected-side forwarding + table would then loop back the packet. The packet is compared + against SPD-I (see Figure 2), matches SPD rule 1, and so it is + BYPASSed. The packet is treated as an outbound packet and compared + against the SPD for a third time. This time it matches SPD rule 2, + so ESP is applied in tunnel mode. This time the forwarding table + doesn't loop back the packet, because the outer destination address + is B, so the packet goes out onto the wire. + + An inbound TCP packet from C to A is wrapped in two ESP headers; the + outer header (ESP in tunnel mode) shows B as the source, whereas the + inner header (ESP transport mode) shows C as the source. Upon + arrival at A, the packet would be mapped to an SA based on the SPI, + have the outer header removed, and be decrypted and + integrity-checked. Then it would be matched against the SAD + selectors for this SA, which would specify C as the source and A as + the destination, derived from SPD rule 2. The protected-side + forwarding function would then send it back to the unprotected side + based on the addresses and the next layer protocol (ESP), indicative + of nesting. It is compared against SPD-O (see Figure 3) and found to + match SPD rule 1, so it is BYPASSed. The packet is mapped to an SA + based on the SPI, integrity-checked, and compared against the SAD + selectors derived from SPD rule 3. The forwarding function then + passes it up to the next layer, because it isn't an ESP packet. + + + + + + + + + + + + + + + + + + + + +Kent & Seo Standards Track [Page 97] + +RFC 4301 Security Architecture for IP December 2005 + + +References + +Normative References + + [BBCDWW98] Blake, S., Black, D., Carlson, M., Davies, E., Wang, + Z., and W. Weiss, "An Architecture for Differentiated + Service", RFC 2475, December 1998. + + [Bra97] Bradner, S., "Key words for use in RFCs to Indicate + Requirement Level", BCP 14, RFC 2119, March 1997. + + [CD98] Conta, A. and S. Deering, "Internet Control Message + Protocol (ICMPv6) for the Internet Protocol Version 6 + (IPv6) Specification", RFC 2463, December 1998. + + [DH98] Deering, S., and R. Hinden, "Internet Protocol, + Version 6 (IPv6) Specification", RFC 2460, December + 1998. + + [Eas05] 3rd Eastlake, D., "Cryptographic Algorithm + Implementation Requirements For Encapsulating Security + Payload (ESP) and Authentication Header (AH)", RFC + 4305, December 2005. + + [HarCar98] Harkins, D. and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [Kau05] Kaufman, C., Ed., "The Internet Key Exchange (IKEv2) + Protocol", RFC 4306, December 2005. + + [Ken05a] Kent, S., "IP Encapsulating Security Payload (ESP)", + RFC 4303, December 2005. + + [Ken05b] Kent, S., "IP Authentication Header", RFC 4302, + December 2005. + + [MD90] Mogul, J. and S. Deering, "Path MTU discovery", RFC + 1191, November 1990. + + [Mobip] Johnson, D., Perkins, C., and J. Arkko, "Mobility + Support in IPv6", RFC 3775, June 2004. + + [Pos81a] Postel, J., "Internet Protocol", STD 5, RFC 791, + September 1981. + + [Pos81b] Postel, J., "Internet Control Message Protocol", RFC + 792, September 1981. + + + + +Kent & Seo Standards Track [Page 98] + +RFC 4301 Security Architecture for IP December 2005 + + + [Sch05] Schiller, J., "Cryptographic Algorithms for use in the + Internet Key Exchange Version 2 (IKEv2)", RFC 4307, + December 2005. + + [WaKiHo97] Wahl, M., Kille, S., and T. Howes, "Lightweight + Directory Access Protocol (v3): UTF-8 String + Representation of Distinguished Names", RFC 2253, + December 1997. + +Informative References + + [CoSa04] Condell, M., and L. Sanchez, "On the Deterministic + Enforcement of Un-ordered Security Policies", BBN + Technical Memo 1346, March 2004. + + [FaLiHaMeTr00] Farinacci, D., Li, T., Hanks, S., Meyer, D., and P. + Traina, "Generic Routing Encapsulation (GRE)", RFC + 2784, March 2000. + + [Gro02] Grossman, D., "New Terminology and Clarifications for + Diffserv", RFC 3260, April 2002. + [HC03] Holbrook, H. and B. Cain, "Source Specific Multicast + for IP", Work in Progress, November 3, 2002. + + [HA94] Haller, N. and R. Atkinson, "On Internet + Authentication", RFC 1704, October 1994. + + [NiBlBaBL98] Nichols, K., Blake, S., Baker, F., and D. Black, + "Definition of the Differentiated Services Field (DS + Field) in the IPv4 and IPv6 Headers", RFC 2474, + December 1998. + + [Per96] Perkins, C., "IP Encapsulation within IP", RFC 2003, + October 1996. + + [RaFlBl01] Ramakrishnan, K., Floyd, S., and D. Black, "The + Addition of Explicit Congestion Notification (ECN) to + IP", RFC 3168, September 2001. + + [RFC2401] Kent, S. and R. Atkinson, "Security Architecture for + the Internet Protocol", RFC 2401, November 1998. + + [RFC2983] Black, D., "Differentiated Services and Tunnels", RFC + 2983, October 2000. + + [RFC3547] Baugher, M., Weis, B., Hardjono, T., and H. Harney, + "The Group Domain of Interpretation", RFC 3547, July + 2003. + + + +Kent & Seo Standards Track [Page 99] + +RFC 4301 Security Architecture for IP December 2005 + + + [RFC3740] Hardjono, T. and B. Weis, "The Multicast Group + Security Architecture", RFC 3740, March 2004. + + [RaCoCaDe04] Rajahalme, J., Conta, A., Carpenter, B., and S. + Deering, "IPv6 Flow Label Specification", RFC 3697, + March 2004. + + [Sch94] Schneier, B., Applied Cryptography, Section 8.6, John + Wiley & Sons, New York, NY, 1994. + + [Shi00] Shirey, R., "Internet Security Glossary", RFC 2828, + May 2000. + + [SMPT01] Shacham, A., Monsour, B., Pereira, R., and M. Thomas, + "IP Payload Compression Protocol (IPComp)", RFC 3173, + September 2001. + + [ToEgWa04] Touch, J., Eggert, L., and Y. Wang, "Use of IPsec + Transport Mode for Dynamic Routing", RFC 3884, + September 2004. + + [VK83] V.L. Voydock & S.T. Kent, "Security Mechanisms in + High-level Networks", ACM Computing Surveys, Vol. 15, + No. 2, June 1983. + +Authors' Addresses + + Stephen Kent + BBN Technologies + 10 Moulton Street + Cambridge, MA 02138 + USA + + Phone: +1 (617) 873-3988 + EMail: kent@bbn.com + + + Karen Seo + BBN Technologies + 10 Moulton Street + Cambridge, MA 02138 + USA + + Phone: +1 (617) 873-3152 + EMail: kseo@bbn.com + + + + + + +Kent & Seo Standards Track [Page 100] + +RFC 4301 Security Architecture for IP December 2005 + + +Full Copyright Statement + + Copyright (C) The Internet Society (2005). + + This document is subject to the rights, licenses and restrictions + contained in BCP 78, and except as set forth therein, the authors + retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at ietf- + ipr@ietf.org. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + +Kent & Seo Standards Track [Page 101] + diff --git a/doc/ikev2/[RFC4306] - Internet Key Exchange (IKEv2) Protocol.txt b/doc/ikev2/[RFC4306] - Internet Key Exchange (IKEv2) Protocol.txt new file mode 100644 index 000000000..fad6cea0e --- /dev/null +++ b/doc/ikev2/[RFC4306] - Internet Key Exchange (IKEv2) Protocol.txt @@ -0,0 +1,5547 @@ + + + + + + +Network Working Group C. Kaufman, Ed. +Request for Comments: 4306 Microsoft +Obsoletes: 2407, 2408, 2409 December 2005 +Category: Standards Track + + + Internet Key Exchange (IKEv2) Protocol + +Status of This Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (2005). + +Abstract + + This document describes version 2 of the Internet Key Exchange (IKE) + protocol. IKE is a component of IPsec used for performing mutual + authentication and establishing and maintaining security associations + (SAs). + + This version of the IKE specification combines the contents of what + were previously separate documents, including Internet Security + Association and Key Management Protocol (ISAKMP, RFC 2408), IKE (RFC + 2409), the Internet Domain of Interpretation (DOI, RFC 2407), Network + Address Translation (NAT) Traversal, Legacy authentication, and + remote address acquisition. + + Version 2 of IKE does not interoperate with version 1, but it has + enough of the header format in common that both versions can + unambiguously run over the same UDP port. + + + + + + + + + + + + + + +Kaufman Standards Track [Page 1] + +RFC 4306 IKEv2 December 2005 + + +Table of Contents + + 1. Introduction ....................................................3 + 1.1. Usage Scenarios ............................................5 + 1.2. The Initial Exchanges ......................................7 + 1.3. The CREATE_CHILD_SA Exchange ...............................9 + 1.4. The INFORMATIONAL Exchange ................................11 + 1.5. Informational Messages outside of an IKE_SA ...............12 + 2. IKE Protocol Details and Variations ............................12 + 2.1. Use of Retransmission Timers ..............................13 + 2.2. Use of Sequence Numbers for Message ID ....................14 + 2.3. Window Size for Overlapping Requests ......................14 + 2.4. State Synchronization and Connection Timeouts .............15 + 2.5. Version Numbers and Forward Compatibility .................17 + 2.6. Cookies ...................................................18 + 2.7. Cryptographic Algorithm Negotiation .......................21 + 2.8. Rekeying ..................................................22 + 2.9. Traffic Selector Negotiation ..............................24 + 2.10. Nonces ...................................................26 + 2.11. Address and Port Agility .................................26 + 2.12. Reuse of Diffie-Hellman Exponentials .....................27 + 2.13. Generating Keying Material ...............................27 + 2.14. Generating Keying Material for the IKE_SA ................28 + 2.15. Authentication of the IKE_SA .............................29 + 2.16. Extensible Authentication Protocol Methods ...............31 + 2.17. Generating Keying Material for CHILD_SAs .................33 + 2.18. Rekeying IKE_SAs Using a CREATE_CHILD_SA exchange ........34 + 2.19. Requesting an Internal Address on a Remote Network .......34 + 2.20. Requesting the Peer's Version ............................35 + 2.21. Error Handling ...........................................36 + 2.22. IPComp ...................................................37 + 2.23. NAT Traversal ............................................38 + 2.24. Explicit Congestion Notification (ECN) ...................40 + 3. Header and Payload Formats .....................................41 + 3.1. The IKE Header ............................................41 + 3.2. Generic Payload Header ....................................44 + 3.3. Security Association Payload ..............................46 + 3.4. Key Exchange Payload ......................................56 + 3.5. Identification Payloads ...................................56 + 3.6. Certificate Payload .......................................59 + 3.7. Certificate Request Payload ...............................61 + 3.8. Authentication Payload ....................................63 + 3.9. Nonce Payload .............................................64 + 3.10. Notify Payload ...........................................64 + 3.11. Delete Payload ...........................................72 + 3.12. Vendor ID Payload ........................................73 + 3.13. Traffic Selector Payload .................................74 + 3.14. Encrypted Payload ........................................77 + + + +Kaufman Standards Track [Page 2] + +RFC 4306 IKEv2 December 2005 + + + 3.15. Configuration Payload ....................................79 + 3.16. Extensible Authentication Protocol (EAP) Payload .........84 + 4. Conformance Requirements .......................................85 + 5. Security Considerations ........................................88 + 6. IANA Considerations ............................................90 + 7. Acknowledgements ...............................................91 + 8. References .....................................................91 + 8.1. Normative References ......................................91 + 8.2. Informative References ....................................92 + Appendix A: Summary of Changes from IKEv1 .........................96 + Appendix B: Diffie-Hellman Groups .................................97 + B.1. Group 1 - 768 Bit MODP ....................................97 + B.2. Group 2 - 1024 Bit MODP ...................................97 + +1. Introduction + + IP Security (IPsec) provides confidentiality, data integrity, access + control, and data source authentication to IP datagrams. These + services are provided by maintaining shared state between the source + and the sink of an IP datagram. This state defines, among other + things, the specific services provided to the datagram, which + cryptographic algorithms will be used to provide the services, and + the keys used as input to the cryptographic algorithms. + + Establishing this shared state in a manual fashion does not scale + well. Therefore, a protocol to establish this state dynamically is + needed. This memo describes such a protocol -- the Internet Key + Exchange (IKE). This is version 2 of IKE. Version 1 of IKE was + defined in RFCs 2407, 2408, and 2409 [Pip98, MSST98, HC98]. This + single document is intended to replace all three of those RFCs. + + Definitions of the primitive terms in this document (such as Security + Association or SA) can be found in [RFC4301]. + + Keywords "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT" and + "MAY" that appear in this document are to be interpreted as described + in [Bra97]. + + The term "Expert Review" is to be interpreted as defined in + [RFC2434]. + + IKE performs mutual authentication between two parties and + establishes an IKE security association (SA) that includes shared + secret information that can be used to efficiently establish SAs for + Encapsulating Security Payload (ESP) [RFC4303] and/or Authentication + Header (AH) [RFC4302] and a set of cryptographic algorithms to be + used by the SAs to protect the traffic that they carry. In this + document, the term "suite" or "cryptographic suite" refers to a + + + +Kaufman Standards Track [Page 3] + +RFC 4306 IKEv2 December 2005 + + + complete set of algorithms used to protect an SA. An initiator + proposes one or more suites by listing supported algorithms that can + be combined into suites in a mix-and-match fashion. IKE can also + negotiate use of IP Compression (IPComp) [IPCOMP] in connection with + an ESP and/or AH SA. We call the IKE SA an "IKE_SA". The SAs for + ESP and/or AH that get set up through that IKE_SA we call + "CHILD_SAs". + + All IKE communications consist of pairs of messages: a request and a + response. The pair is called an "exchange". We call the first + messages establishing an IKE_SA IKE_SA_INIT and IKE_AUTH exchanges + and subsequent IKE exchanges CREATE_CHILD_SA or INFORMATIONAL + exchanges. In the common case, there is a single IKE_SA_INIT + exchange and a single IKE_AUTH exchange (a total of four messages) to + establish the IKE_SA and the first CHILD_SA. In exceptional cases, + there may be more than one of each of these exchanges. In all cases, + all IKE_SA_INIT exchanges MUST complete before any other exchange + type, then all IKE_AUTH exchanges MUST complete, and following that + any number of CREATE_CHILD_SA and INFORMATIONAL exchanges may occur + in any order. In some scenarios, only a single CHILD_SA is needed + between the IPsec endpoints, and therefore there would be no + additional exchanges. Subsequent exchanges MAY be used to establish + additional CHILD_SAs between the same authenticated pair of endpoints + and to perform housekeeping functions. + + IKE message flow always consists of a request followed by a response. + It is the responsibility of the requester to ensure reliability. If + the response is not received within a timeout interval, the requester + needs to retransmit the request (or abandon the connection). + + The first request/response of an IKE session (IKE_SA_INIT) negotiates + security parameters for the IKE_SA, sends nonces, and sends Diffie- + Hellman values. + + The second request/response (IKE_AUTH) transmits identities, proves + knowledge of the secrets corresponding to the two identities, and + sets up an SA for the first (and often only) AH and/or ESP CHILD_SA. + + The types of subsequent exchanges are CREATE_CHILD_SA (which creates + a CHILD_SA) and INFORMATIONAL (which deletes an SA, reports error + conditions, or does other housekeeping). Every request requires a + response. An INFORMATIONAL request with no payloads (other than the + empty Encrypted payload required by the syntax) is commonly used as a + check for liveness. These subsequent exchanges cannot be used until + the initial exchanges have completed. + + + + + + +Kaufman Standards Track [Page 4] + +RFC 4306 IKEv2 December 2005 + + + In the description that follows, we assume that no errors occur. + Modifications to the flow should errors occur are described in + section 2.21. + +1.1. Usage Scenarios + + IKE is expected to be used to negotiate ESP and/or AH SAs in a number + of different scenarios, each with its own special requirements. + +1.1.1. Security Gateway to Security Gateway Tunnel + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! + Protected !Tunnel ! tunnel !Tunnel ! Protected + Subnet <-->!Endpoint !<---------->!Endpoint !<--> Subnet + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 1: Security Gateway to Security Gateway Tunnel + + In this scenario, neither endpoint of the IP connection implements + IPsec, but network nodes between them protect traffic for part of the + way. Protection is transparent to the endpoints, and depends on + ordinary routing to send packets through the tunnel endpoints for + processing. Each endpoint would announce the set of addresses + "behind" it, and packets would be sent in tunnel mode where the inner + IP header would contain the IP addresses of the actual endpoints. + +1.1.2. Endpoint-to-Endpoint Transport + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec transport ! ! + !Protected! or tunnel mode SA !Protected! + !Endpoint !<---------------------------------------->!Endpoint ! + ! ! ! ! + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 2: Endpoint to Endpoint + + In this scenario, both endpoints of the IP connection implement + IPsec, as required of hosts in [RFC4301]. Transport mode will + commonly be used with no inner IP header. If there is an inner IP + header, the inner addresses will be the same as the outer addresses. + A single pair of addresses will be negotiated for packets to be + protected by this SA. These endpoints MAY implement application + layer access controls based on the IPsec authenticated identities of + the participants. This scenario enables the end-to-end security that + has been a guiding principle for the Internet since [RFC1958], + + + +Kaufman Standards Track [Page 5] + +RFC 4306 IKEv2 December 2005 + + + [RFC2775], and a method of limiting the inherent problems with + complexity in networks noted by [RFC3439]. Although this scenario + may not be fully applicable to the IPv4 Internet, it has been + deployed successfully in specific scenarios within intranets using + IKEv1. It should be more broadly enabled during the transition to + IPv6 and with the adoption of IKEv2. + + It is possible in this scenario that one or both of the protected + endpoints will be behind a network address translation (NAT) node, in + which case the tunneled packets will have to be UDP encapsulated so + that port numbers in the UDP headers can be used to identify + individual endpoints "behind" the NAT (see section 2.23). + +1.1.3. Endpoint to Security Gateway Tunnel + + +-+-+-+-+-+ +-+-+-+-+-+ + ! ! IPsec ! ! Protected + !Protected! tunnel !Tunnel ! Subnet + !Endpoint !<------------------------>!Endpoint !<--- and/or + ! ! ! ! Internet + +-+-+-+-+-+ +-+-+-+-+-+ + + Figure 3: Endpoint to Security Gateway Tunnel + + In this scenario, a protected endpoint (typically a portable roaming + computer) connects back to its corporate network through an IPsec- + protected tunnel. It might use this tunnel only to access + information on the corporate network, or it might tunnel all of its + traffic back through the corporate network in order to take advantage + of protection provided by a corporate firewall against Internet-based + attacks. In either case, the protected endpoint will want an IP + address associated with the security gateway so that packets returned + to it will go to the security gateway and be tunneled back. This IP + address may be static or may be dynamically allocated by the security + gateway. In support of the latter case, IKEv2 includes a mechanism + for the initiator to request an IP address owned by the security + gateway for use for the duration of its SA. + + In this scenario, packets will use tunnel mode. On each packet from + the protected endpoint, the outer IP header will contain the source + IP address associated with its current location (i.e., the address + that will get traffic routed to the endpoint directly), while the + inner IP header will contain the source IP address assigned by the + security gateway (i.e., the address that will get traffic routed to + the security gateway for forwarding to the endpoint). The outer + destination address will always be that of the security gateway, + while the inner destination address will be the ultimate destination + for the packet. + + + +Kaufman Standards Track [Page 6] + +RFC 4306 IKEv2 December 2005 + + + In this scenario, it is possible that the protected endpoint will be + behind a NAT. In that case, the IP address as seen by the security + gateway will not be the same as the IP address sent by the protected + endpoint, and packets will have to be UDP encapsulated in order to be + routed properly. + +1.1.4. Other Scenarios + + Other scenarios are possible, as are nested combinations of the + above. One notable example combines aspects of 1.1.1 and 1.1.3. A + subnet may make all external accesses through a remote security + gateway using an IPsec tunnel, where the addresses on the subnet are + routed to the security gateway by the rest of the Internet. An + example would be someone's home network being virtually on the + Internet with static IP addresses even though connectivity is + provided by an ISP that assigns a single dynamically assigned IP + address to the user's security gateway (where the static IP addresses + and an IPsec relay are provided by a third party located elsewhere). + +1.2. The Initial Exchanges + + Communication using IKE always begins with IKE_SA_INIT and IKE_AUTH + exchanges (known in IKEv1 as Phase 1). These initial exchanges + normally consist of four messages, though in some scenarios that + number can grow. All communications using IKE consist of + request/response pairs. We'll describe the base exchange first, + followed by variations. The first pair of messages (IKE_SA_INIT) + negotiate cryptographic algorithms, exchange nonces, and do a + Diffie-Hellman exchange [DH]. + + The second pair of messages (IKE_AUTH) authenticate the previous + messages, exchange identities and certificates, and establish the + first CHILD_SA. Parts of these messages are encrypted and integrity + protected with keys established through the IKE_SA_INIT exchange, so + the identities are hidden from eavesdroppers and all fields in all + the messages are authenticated. + + In the following descriptions, the payloads contained in the message + are indicated by names as listed below. + + Notation Payload + + AUTH Authentication + CERT Certificate + CERTREQ Certificate Request + CP Configuration + D Delete + E Encrypted + + + +Kaufman Standards Track [Page 7] + +RFC 4306 IKEv2 December 2005 + + + EAP Extensible Authentication + HDR IKE Header + IDi Identification - Initiator + IDr Identification - Responder + KE Key Exchange + Ni, Nr Nonce + N Notify + SA Security Association + TSi Traffic Selector - Initiator + TSr Traffic Selector - Responder + V Vendor ID + + The details of the contents of each payload are described in section + 3. Payloads that may optionally appear will be shown in brackets, + such as [CERTREQ], indicate that optionally a certificate request + payload can be included. + + The initial exchanges are as follows: + + Initiator Responder + ----------- ----------- + HDR, SAi1, KEi, Ni --> + + HDR contains the Security Parameter Indexes (SPIs), version numbers, + and flags of various sorts. The SAi1 payload states the + cryptographic algorithms the initiator supports for the IKE_SA. The + KE payload sends the initiator's Diffie-Hellman value. Ni is the + initiator's nonce. + + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + + The responder chooses a cryptographic suite from the initiator's + offered choices and expresses that choice in the SAr1 payload, + completes the Diffie-Hellman exchange with the KEr payload, and sends + its nonce in the Nr payload. + + At this point in the negotiation, each party can generate SKEYSEED, + from which all keys are derived for that IKE_SA. All but the headers + of all the messages that follow are encrypted and integrity + protected. The keys used for the encryption and integrity protection + are derived from SKEYSEED and are known as SK_e (encryption) and SK_a + (authentication, a.k.a. integrity protection). A separate SK_e and + SK_a is computed for each direction. In addition to the keys SK_e + and SK_a derived from the DH value for protection of the IKE_SA, + another quantity SK_d is derived and used for derivation of further + keying material for CHILD_SAs. The notation SK { ... } indicates + that these payloads are encrypted and integrity protected using that + direction's SK_e and SK_a. + + + +Kaufman Standards Track [Page 8] + +RFC 4306 IKEv2 December 2005 + + + HDR, SK {IDi, [CERT,] [CERTREQ,] [IDr,] + AUTH, SAi2, TSi, TSr} --> + + The initiator asserts its identity with the IDi payload, proves + knowledge of the secret corresponding to IDi and integrity protects + the contents of the first message using the AUTH payload (see section + 2.15). It might also send its certificate(s) in CERT payload(s) and + a list of its trust anchors in CERTREQ payload(s). If any CERT + payloads are included, the first certificate provided MUST contain + the public key used to verify the AUTH field. The optional payload + IDr enables the initiator to specify which of the responder's + identities it wants to talk to. This is useful when the machine on + which the responder is running is hosting multiple identities at the + same IP address. The initiator begins negotiation of a CHILD_SA + using the SAi2 payload. The final fields (starting with SAi2) are + described in the description of the CREATE_CHILD_SA exchange. + + <-- HDR, SK {IDr, [CERT,] AUTH, + SAr2, TSi, TSr} + + The responder asserts its identity with the IDr payload, optionally + sends one or more certificates (again with the certificate containing + the public key used to verify AUTH listed first), authenticates its + identity and protects the integrity of the second message with the + AUTH payload, and completes negotiation of a CHILD_SA with the + additional fields described below in the CREATE_CHILD_SA exchange. + + The recipients of messages 3 and 4 MUST verify that all signatures + and MACs are computed correctly and that the names in the ID payloads + correspond to the keys used to generate the AUTH payload. + +1.3. The CREATE_CHILD_SA Exchange + + This exchange consists of a single request/response pair, and was + referred to as a phase 2 exchange in IKEv1. It MAY be initiated by + either end of the IKE_SA after the initial exchanges are completed. + + All messages following the initial exchange are cryptographically + protected using the cryptographic algorithms and keys negotiated in + the first two messages of the IKE exchange. These subsequent + messages use the syntax of the Encrypted Payload described in section + 3.14. All subsequent messages included an Encrypted Payload, even if + they are referred to in the text as "empty". + + Either endpoint may initiate a CREATE_CHILD_SA exchange, so in this + section the term "initiator" refers to the endpoint initiating this + exchange. + + + + +Kaufman Standards Track [Page 9] + +RFC 4306 IKEv2 December 2005 + + + A CHILD_SA is created by sending a CREATE_CHILD_SA request. The + CREATE_CHILD_SA request MAY optionally contain a KE payload for an + additional Diffie-Hellman exchange to enable stronger guarantees of + forward secrecy for the CHILD_SA. The keying material for the + CHILD_SA is a function of SK_d established during the establishment + of the IKE_SA, the nonces exchanged during the CREATE_CHILD_SA + exchange, and the Diffie-Hellman value (if KE payloads are included + in the CREATE_CHILD_SA exchange). + + In the CHILD_SA created as part of the initial exchange, a second KE + payload and nonce MUST NOT be sent. The nonces from the initial + exchange are used in computing the keys for the CHILD_SA. + + The CREATE_CHILD_SA request contains: + + Initiator Responder + ----------- ----------- + HDR, SK {[N], SA, Ni, [KEi], + [TSi, TSr]} --> + + The initiator sends SA offer(s) in the SA payload, a nonce in the Ni + payload, optionally a Diffie-Hellman value in the KEi payload, and + the proposed traffic selectors in the TSi and TSr payloads. If this + CREATE_CHILD_SA exchange is rekeying an existing SA other than the + IKE_SA, the leading N payload of type REKEY_SA MUST identify the SA + being rekeyed. If this CREATE_CHILD_SA exchange is not rekeying an + existing SA, the N payload MUST be omitted. If the SA offers include + different Diffie-Hellman groups, KEi MUST be an element of the group + the initiator expects the responder to accept. If it guesses wrong, + the CREATE_CHILD_SA exchange will fail, and it will have to retry + with a different KEi. + + The message following the header is encrypted and the message + including the header is integrity protected using the cryptographic + algorithms negotiated for the IKE_SA. + + The CREATE_CHILD_SA response contains: + + <-- HDR, SK {SA, Nr, [KEr], + [TSi, TSr]} + + The responder replies (using the same Message ID to respond) with the + accepted offer in an SA payload, and a Diffie-Hellman value in the + KEr payload if KEi was included in the request and the selected + cryptographic suite includes that group. If the responder chooses a + cryptographic suite with a different group, it MUST reject the + request. The initiator SHOULD repeat the request, but now with a KEi + payload from the group the responder selected. + + + +Kaufman Standards Track [Page 10] + +RFC 4306 IKEv2 December 2005 + + + The traffic selectors for traffic to be sent on that SA are specified + in the TS payloads, which may be a subset of what the initiator of + the CHILD_SA proposed. Traffic selectors are omitted if this + CREATE_CHILD_SA request is being used to change the key of the + IKE_SA. + +1.4. The INFORMATIONAL Exchange + + At various points during the operation of an IKE_SA, peers may desire + to convey control messages to each other regarding errors or + notifications of certain events. To accomplish this, IKE defines an + INFORMATIONAL exchange. INFORMATIONAL exchanges MUST ONLY occur + after the initial exchanges and are cryptographically protected with + the negotiated keys. + + Control messages that pertain to an IKE_SA MUST be sent under that + IKE_SA. Control messages that pertain to CHILD_SAs MUST be sent + under the protection of the IKE_SA which generated them (or its + successor if the IKE_SA was replaced for the purpose of rekeying). + + Messages in an INFORMATIONAL exchange contain zero or more + Notification, Delete, and Configuration payloads. The Recipient of + an INFORMATIONAL exchange request MUST send some response (else the + Sender will assume the message was lost in the network and will + retransmit it). That response MAY be a message with no payloads. + The request message in an INFORMATIONAL exchange MAY also contain no + payloads. This is the expected way an endpoint can ask the other + endpoint to verify that it is alive. + + ESP and AH SAs always exist in pairs, with one SA in each direction. + When an SA is closed, both members of the pair MUST be closed. When + SAs are nested, as when data (and IP headers if in tunnel mode) are + encapsulated first with IPComp, then with ESP, and finally with AH + between the same pair of endpoints, all of the SAs MUST be deleted + together. Each endpoint MUST close its incoming SAs and allow the + other endpoint to close the other SA in each pair. To delete an SA, + an INFORMATIONAL exchange with one or more delete payloads is sent + listing the SPIs (as they would be expected in the headers of inbound + packets) of the SAs to be deleted. The recipient MUST close the + designated SAs. Normally, the reply in the INFORMATIONAL exchange + will contain delete payloads for the paired SAs going in the other + direction. There is one exception. If by chance both ends of a set + of SAs independently decide to close them, each may send a delete + payload and the two requests may cross in the network. If a node + receives a delete request for SAs for which it has already issued a + delete request, it MUST delete the outgoing SAs while processing the + request and the incoming SAs while processing the response. In that + + + + +Kaufman Standards Track [Page 11] + +RFC 4306 IKEv2 December 2005 + + + case, the responses MUST NOT include delete payloads for the deleted + SAs, since that would result in duplicate deletion and could in + theory delete the wrong SA. + + A node SHOULD regard half-closed connections as anomalous and audit + their existence should they persist. Note that this specification + nowhere specifies time periods, so it is up to individual endpoints + to decide how long to wait. A node MAY refuse to accept incoming + data on half-closed connections but MUST NOT unilaterally close them + and reuse the SPIs. If connection state becomes sufficiently messed + up, a node MAY close the IKE_SA; doing so will implicitly close all + SAs negotiated under it. It can then rebuild the SAs it needs on a + clean base under a new IKE_SA. + + The INFORMATIONAL exchange is defined as: + + Initiator Responder + ----------- ----------- + HDR, SK {[N,] [D,] [CP,] ...} --> + <-- HDR, SK {[N,] [D,] [CP], ...} + + The processing of an INFORMATIONAL exchange is determined by its + component payloads. + +1.5. Informational Messages outside of an IKE_SA + + If an encrypted IKE packet arrives on port 500 or 4500 with an + unrecognized SPI, it could be because the receiving node has recently + crashed and lost state or because of some other system malfunction or + attack. If the receiving node has an active IKE_SA to the IP address + from whence the packet came, it MAY send a notification of the + wayward packet over that IKE_SA in an INFORMATIONAL exchange. If it + does not have such an IKE_SA, it MAY send an Informational message + without cryptographic protection to the source IP address. Such a + message is not part of an informational exchange, and the receiving + node MUST NOT respond to it. Doing so could cause a message loop. + +2. IKE Protocol Details and Variations + + IKE normally listens and sends on UDP port 500, though IKE messages + may also be received on UDP port 4500 with a slightly different + format (see section 2.23). Since UDP is a datagram (unreliable) + protocol, IKE includes in its definition recovery from transmission + errors, including packet loss, packet replay, and packet forgery. + IKE is designed to function so long as (1) at least one of a series + of retransmitted packets reaches its destination before timing out; + and (2) the channel is not so full of forged and replayed packets so + + + + +Kaufman Standards Track [Page 12] + +RFC 4306 IKEv2 December 2005 + + + as to exhaust the network or CPU capacities of either endpoint. Even + in the absence of those minimum performance requirements, IKE is + designed to fail cleanly (as though the network were broken). + + Although IKEv2 messages are intended to be short, they contain + structures with no hard upper bound on size (in particular, X.509 + certificates), and IKEv2 itself does not have a mechanism for + fragmenting large messages. IP defines a mechanism for fragmentation + of oversize UDP messages, but implementations vary in the maximum + message size supported. Furthermore, use of IP fragmentation opens + an implementation to denial of service attacks [KPS03]. Finally, + some NAT and/or firewall implementations may block IP fragments. + + All IKEv2 implementations MUST be able to send, receive, and process + IKE messages that are up to 1280 bytes long, and they SHOULD be able + to send, receive, and process messages that are up to 3000 bytes + long. IKEv2 implementations SHOULD be aware of the maximum UDP + message size supported and MAY shorten messages by leaving out some + certificates or cryptographic suite proposals if that will keep + messages below the maximum. Use of the "Hash and URL" formats rather + than including certificates in exchanges where possible can avoid + most problems. Implementations and configuration should keep in + mind, however, that if the URL lookups are possible only after the + IPsec SA is established, recursion issues could prevent this + technique from working. + +2.1. Use of Retransmission Timers + + All messages in IKE exist in pairs: a request and a response. The + setup of an IKE_SA normally consists of two request/response pairs. + Once the IKE_SA is set up, either end of the security association may + initiate requests at any time, and there can be many requests and + responses "in flight" at any given moment. But each message is + labeled as either a request or a response, and for each + request/response pair one end of the security association is the + initiator and the other is the responder. + + For every pair of IKE messages, the initiator is responsible for + retransmission in the event of a timeout. The responder MUST never + retransmit a response unless it receives a retransmission of the + request. In that event, the responder MUST ignore the retransmitted + request except insofar as it triggers a retransmission of the + response. The initiator MUST remember each request until it receives + the corresponding response. The responder MUST remember each + response until it receives a request whose sequence number is larger + than the sequence number in the response plus its window size (see + section 2.3). + + + + +Kaufman Standards Track [Page 13] + +RFC 4306 IKEv2 December 2005 + + + IKE is a reliable protocol, in the sense that the initiator MUST + retransmit a request until either it receives a corresponding reply + OR it deems the IKE security association to have failed and it + discards all state associated with the IKE_SA and any CHILD_SAs + negotiated using that IKE_SA. + +2.2. Use of Sequence Numbers for Message ID + + Every IKE message contains a Message ID as part of its fixed header. + This Message ID is used to match up requests and responses, and to + identify retransmissions of messages. + + The Message ID is a 32-bit quantity, which is zero for the first IKE + request in each direction. The IKE_SA initial setup messages will + always be numbered 0 and 1. Each endpoint in the IKE Security + Association maintains two "current" Message IDs: the next one to be + used for a request it initiates and the next one it expects to see in + a request from the other end. These counters increment as requests + are generated and received. Responses always contain the same + message ID as the corresponding request. That means that after the + initial exchange, each integer n may appear as the message ID in four + distinct messages: the nth request from the original IKE initiator, + the corresponding response, the nth request from the original IKE + responder, and the corresponding response. If the two ends make very + different numbers of requests, the Message IDs in the two directions + can be very different. There is no ambiguity in the messages, + however, because the (I)nitiator and (R)esponse bits in the message + header specify which of the four messages a particular one is. + + Note that Message IDs are cryptographically protected and provide + protection against message replays. In the unlikely event that + Message IDs grow too large to fit in 32 bits, the IKE_SA MUST be + closed. Rekeying an IKE_SA resets the sequence numbers. + +2.3. Window Size for Overlapping Requests + + In order to maximize IKE throughput, an IKE endpoint MAY issue + multiple requests before getting a response to any of them if the + other endpoint has indicated its ability to handle such requests. + For simplicity, an IKE implementation MAY choose to process requests + strictly in order and/or wait for a response to one request before + issuing another. Certain rules must be followed to ensure + interoperability between implementations using different strategies. + + After an IKE_SA is set up, either end can initiate one or more + requests. These requests may pass one another over the network. An + IKE endpoint MUST be prepared to accept and process a request while + + + + +Kaufman Standards Track [Page 14] + +RFC 4306 IKEv2 December 2005 + + + it has a request outstanding in order to avoid a deadlock in this + situation. An IKE endpoint SHOULD be prepared to accept and process + multiple requests while it has a request outstanding. + + An IKE endpoint MUST wait for a response to each of its messages + before sending a subsequent message unless it has received a + SET_WINDOW_SIZE Notify message from its peer informing it that the + peer is prepared to maintain state for multiple outstanding messages + in order to allow greater throughput. + + An IKE endpoint MUST NOT exceed the peer's stated window size for + transmitted IKE requests. In other words, if the responder stated + its window size is N, then when the initiator needs to make a request + X, it MUST wait until it has received responses to all requests up + through request X-N. An IKE endpoint MUST keep a copy of (or be able + to regenerate exactly) each request it has sent until it receives the + corresponding response. An IKE endpoint MUST keep a copy of (or be + able to regenerate exactly) the number of previous responses equal to + its declared window size in case its response was lost and the + initiator requests its retransmission by retransmitting the request. + + An IKE endpoint supporting a window size greater than one SHOULD be + capable of processing incoming requests out of order to maximize + performance in the event of network failures or packet reordering. + +2.4. State Synchronization and Connection Timeouts + + An IKE endpoint is allowed to forget all of its state associated with + an IKE_SA and the collection of corresponding CHILD_SAs at any time. + This is the anticipated behavior in the event of an endpoint crash + and restart. It is important when an endpoint either fails or + reinitializes its state that the other endpoint detect those + conditions and not continue to waste network bandwidth by sending + packets over discarded SAs and having them fall into a black hole. + + Since IKE is designed to operate in spite of Denial of Service (DoS) + attacks from the network, an endpoint MUST NOT conclude that the + other endpoint has failed based on any routing information (e.g., + ICMP messages) or IKE messages that arrive without cryptographic + protection (e.g., Notify messages complaining about unknown SPIs). + An endpoint MUST conclude that the other endpoint has failed only + when repeated attempts to contact it have gone unanswered for a + timeout period or when a cryptographically protected INITIAL_CONTACT + notification is received on a different IKE_SA to the same + authenticated identity. An endpoint SHOULD suspect that the other + endpoint has failed based on routing information and initiate a + request to see whether the other endpoint is alive. To check whether + the other side is alive, IKE specifies an empty INFORMATIONAL message + + + +Kaufman Standards Track [Page 15] + +RFC 4306 IKEv2 December 2005 + + + that (like all IKE requests) requires an acknowledgement (note that + within the context of an IKE_SA, an "empty" message consists of an + IKE header followed by an Encrypted payload that contains no + payloads). If a cryptographically protected message has been + received from the other side recently, unprotected notifications MAY + be ignored. Implementations MUST limit the rate at which they take + actions based on unprotected messages. + + Numbers of retries and lengths of timeouts are not covered in this + specification because they do not affect interoperability. It is + suggested that messages be retransmitted at least a dozen times over + a period of at least several minutes before giving up on an SA, but + different environments may require different rules. To be a good + network citizen, retranmission times MUST increase exponentially to + avoid flooding the network and making an existing congestion + situation worse. If there has only been outgoing traffic on all of + the SAs associated with an IKE_SA, it is essential to confirm + liveness of the other endpoint to avoid black holes. If no + cryptographically protected messages have been received on an IKE_SA + or any of its CHILD_SAs recently, the system needs to perform a + liveness check in order to prevent sending messages to a dead peer. + Receipt of a fresh cryptographically protected message on an IKE_SA + or any of its CHILD_SAs ensures liveness of the IKE_SA and all of its + CHILD_SAs. Note that this places requirements on the failure modes + of an IKE endpoint. An implementation MUST NOT continue sending on + any SA if some failure prevents it from receiving on all of the + associated SAs. If CHILD_SAs can fail independently from one another + without the associated IKE_SA being able to send a delete message, + then they MUST be negotiated by separate IKE_SAs. + + There is a Denial of Service attack on the initiator of an IKE_SA + that can be avoided if the initiator takes the proper care. Since + the first two messages of an SA setup are not cryptographically + protected, an attacker could respond to the initiator's message + before the genuine responder and poison the connection setup attempt. + To prevent this, the initiator MAY be willing to accept multiple + responses to its first message, treat each as potentially legitimate, + respond to it, and then discard all the invalid half-open connections + when it receives a valid cryptographically protected response to any + one of its requests. Once a cryptographically valid response is + received, all subsequent responses should be ignored whether or not + they are cryptographically valid. + + Note that with these rules, there is no reason to negotiate and agree + upon an SA lifetime. If IKE presumes the partner is dead, based on + repeated lack of acknowledgement to an IKE message, then the IKE SA + and all CHILD_SAs set up through that IKE_SA are deleted. + + + + +Kaufman Standards Track [Page 16] + +RFC 4306 IKEv2 December 2005 + + + An IKE endpoint may at any time delete inactive CHILD_SAs to recover + resources used to hold their state. If an IKE endpoint chooses to + delete CHILD_SAs, it MUST send Delete payloads to the other end + notifying it of the deletion. It MAY similarly time out the IKE_SA. + Closing the IKE_SA implicitly closes all associated CHILD_SAs. In + this case, an IKE endpoint SHOULD send a Delete payload indicating + that it has closed the IKE_SA. + +2.5. Version Numbers and Forward Compatibility + + This document describes version 2.0 of IKE, meaning the major version + number is 2 and the minor version number is zero. It is likely that + some implementations will want to support both version 1.0 and + version 2.0, and in the future, other versions. + + The major version number should be incremented only if the packet + formats or required actions have changed so dramatically that an + older version node would not be able to interoperate with a newer + version node if it simply ignored the fields it did not understand + and took the actions specified in the older specification. The minor + version number indicates new capabilities, and MUST be ignored by a + node with a smaller minor version number, but used for informational + purposes by the node with the larger minor version number. For + example, it might indicate the ability to process a newly defined + notification message. The node with the larger minor version number + would simply note that its correspondent would not be able to + understand that message and therefore would not send it. + + If an endpoint receives a message with a higher major version number, + it MUST drop the message and SHOULD send an unauthenticated + notification message containing the highest version number it + supports. If an endpoint supports major version n, and major version + m, it MUST support all versions between n and m. If it receives a + message with a major version that it supports, it MUST respond with + that version number. In order to prevent two nodes from being + tricked into corresponding with a lower major version number than the + maximum that they both support, IKE has a flag that indicates that + the node is capable of speaking a higher major version number. + + Thus, the major version number in the IKE header indicates the + version number of the message, not the highest version number that + the transmitter supports. If the initiator is capable of speaking + versions n, n+1, and n+2, and the responder is capable of speaking + versions n and n+1, then they will negotiate speaking n+1, where the + initiator will set the flag indicating its ability to speak a higher + version. If they mistakenly (perhaps through an active attacker + + + + + +Kaufman Standards Track [Page 17] + +RFC 4306 IKEv2 December 2005 + + + sending error messages) negotiate to version n, then both will notice + that the other side can support a higher version number, and they + MUST break the connection and reconnect using version n+1. + + Note that IKEv1 does not follow these rules, because there is no way + in v1 of noting that you are capable of speaking a higher version + number. So an active attacker can trick two v2-capable nodes into + speaking v1. When a v2-capable node negotiates down to v1, it SHOULD + note that fact in its logs. + + Also for forward compatibility, all fields marked RESERVED MUST be + set to zero by a version 2.0 implementation and their content MUST be + ignored by a version 2.0 implementation ("Be conservative in what you + send and liberal in what you receive"). In this way, future versions + of the protocol can use those fields in a way that is guaranteed to + be ignored by implementations that do not understand them. + Similarly, payload types that are not defined are reserved for future + use; implementations of version 2.0 MUST skip over those payloads and + ignore their contents. + + IKEv2 adds a "critical" flag to each payload header for further + flexibility for forward compatibility. If the critical flag is set + and the payload type is unrecognized, the message MUST be rejected + and the response to the IKE request containing that payload MUST + include a Notify payload UNSUPPORTED_CRITICAL_PAYLOAD, indicating an + unsupported critical payload was included. If the critical flag is + not set and the payload type is unsupported, that payload MUST be + ignored. + + Although new payload types may be added in the future and may appear + interleaved with the fields defined in this specification, + implementations MUST send the payloads defined in this specification + in the order shown in the figures in section 2 and implementations + SHOULD reject as invalid a message with those payloads in any other + order. + +2.6. Cookies + + The term "cookies" originates with Karn and Simpson [RFC2522] in + Photuris, an early proposal for key management with IPsec, and it has + persisted. The Internet Security Association and Key Management + Protocol (ISAKMP) [MSST98] fixed message header includes two eight- + octet fields titled "cookies", and that syntax is used by both IKEv1 + and IKEv2 though in IKEv2 they are referred to as the IKE SPI and + there is a new separate field in a Notify payload holding the cookie. + The initial two eight-octet fields in the header are used as a + connection identifier at the beginning of IKE packets. Each endpoint + + + + +Kaufman Standards Track [Page 18] + +RFC 4306 IKEv2 December 2005 + + + chooses one of the two SPIs and SHOULD choose them so as to be unique + identifiers of an IKE_SA. An SPI value of zero is special and + indicates that the remote SPI value is not yet known by the sender. + + Unlike ESP and AH where only the recipient's SPI appears in the + header of a message, in IKE the sender's SPI is also sent in every + message. Since the SPI chosen by the original initiator of the + IKE_SA is always sent first, an endpoint with multiple IKE_SAs open + that wants to find the appropriate IKE_SA using the SPI it assigned + must look at the I(nitiator) Flag bit in the header to determine + whether it assigned the first or the second eight octets. + + In the first message of an initial IKE exchange, the initiator will + not know the responder's SPI value and will therefore set that field + to zero. + + An expected attack against IKE is state and CPU exhaustion, where the + target is flooded with session initiation requests from forged IP + addresses. This attack can be made less effective if an + implementation of a responder uses minimal CPU and commits no state + to an SA until it knows the initiator can receive packets at the + address from which it claims to be sending them. To accomplish this, + a responder SHOULD -- when it detects a large number of half-open + IKE_SAs -- reject initial IKE messages unless they contain a Notify + payload of type COOKIE. It SHOULD instead send an unprotected IKE + message as a response and include COOKIE Notify payload with the + cookie data to be returned. Initiators who receive such responses + MUST retry the IKE_SA_INIT with a Notify payload of type COOKIE + containing the responder supplied cookie data as the first payload + and all other payloads unchanged. The initial exchange will then be + as follows: + + Initiator Responder + ----------- ----------- + HDR(A,0), SAi1, KEi, Ni --> + + <-- HDR(A,0), N(COOKIE) + + HDR(A,0), N(COOKIE), SAi1, KEi, Ni --> + + <-- HDR(A,B), SAr1, KEr, Nr, [CERTREQ] + + HDR(A,B), SK {IDi, [CERT,] [CERTREQ,] [IDr,] + AUTH, SAi2, TSi, TSr} --> + + <-- HDR(A,B), SK {IDr, [CERT,] AUTH, + SAr2, TSi, TSr} + + + + +Kaufman Standards Track [Page 19] + +RFC 4306 IKEv2 December 2005 + + + The first two messages do not affect any initiator or responder state + except for communicating the cookie. In particular, the message + sequence numbers in the first four messages will all be zero and the + message sequence numbers in the last two messages will be one. 'A' is + the SPI assigned by the initiator, while 'B' is the SPI assigned by + the responder. + + An IKE implementation SHOULD implement its responder cookie + generation in such a way as to not require any saved state to + recognize its valid cookie when the second IKE_SA_INIT message + arrives. The exact algorithms and syntax they use to generate + cookies do not affect interoperability and hence are not specified + here. The following is an example of how an endpoint could use + cookies to implement limited DOS protection. + + A good way to do this is to set the responder cookie to be: + + Cookie = | Hash(Ni | IPi | SPIi | ) + + where is a randomly generated secret known only to the + responder and periodically changed and | indicates concatenation. + should be changed whenever is + regenerated. The cookie can be recomputed when the IKE_SA_INIT + arrives the second time and compared to the cookie in the received + message. If it matches, the responder knows that the cookie was + generated since the last change to and that IPi must be the + same as the source address it saw the first time. Incorporating SPIi + into the calculation ensures that if multiple IKE_SAs are being set + up in parallel they will all get different cookies (assuming the + initiator chooses unique SPIi's). Incorporating Ni into the hash + ensures that an attacker who sees only message 2 can't successfully + forge a message 3. + + If a new value for is chosen while there are connections in + the process of being initialized, an IKE_SA_INIT might be returned + with other than the current . The responder in + that case MAY reject the message by sending another response with a + new cookie or it MAY keep the old value of around for a + short time and accept cookies computed from either one. The + responder SHOULD NOT accept cookies indefinitely after is + changed, since that would defeat part of the denial of service + protection. The responder SHOULD change the value of + frequently, especially if under attack. + + + + + + + + +Kaufman Standards Track [Page 20] + +RFC 4306 IKEv2 December 2005 + + +2.7. Cryptographic Algorithm Negotiation + + The payload type known as "SA" indicates a proposal for a set of + choices of IPsec protocols (IKE, ESP, and/or AH) for the SA as well + as cryptographic algorithms associated with each protocol. + + An SA payload consists of one or more proposals. Each proposal + includes one or more protocols (usually one). Each protocol contains + one or more transforms -- each specifying a cryptographic algorithm. + Each transform contains zero or more attributes (attributes are + needed only if the transform identifier does not completely specify + the cryptographic algorithm). + + This hierarchical structure was designed to efficiently encode + proposals for cryptographic suites when the number of supported + suites is large because multiple values are acceptable for multiple + transforms. The responder MUST choose a single suite, which MAY be + any subset of the SA proposal following the rules below: + + Each proposal contains one or more protocols. If a proposal is + accepted, the SA response MUST contain the same protocols in the + same order as the proposal. The responder MUST accept a single + proposal or reject them all and return an error. (Example: if a + single proposal contains ESP and AH and that proposal is accepted, + both ESP and AH MUST be accepted. If ESP and AH are included in + separate proposals, the responder MUST accept only one of them). + + Each IPsec protocol proposal contains one or more transforms. + Each transform contains a transform type. The accepted + cryptographic suite MUST contain exactly one transform of each + type included in the proposal. For example: if an ESP proposal + includes transforms ENCR_3DES, ENCR_AES w/keysize 128, ENCR_AES + w/keysize 256, AUTH_HMAC_MD5, and AUTH_HMAC_SHA, the accepted + suite MUST contain one of the ENCR_ transforms and one of the + AUTH_ transforms. Thus, six combinations are acceptable. + + Since the initiator sends its Diffie-Hellman value in the + IKE_SA_INIT, it must guess the Diffie-Hellman group that the + responder will select from its list of supported groups. If the + initiator guesses wrong, the responder will respond with a Notify + payload of type INVALID_KE_PAYLOAD indicating the selected group. In + this case, the initiator MUST retry the IKE_SA_INIT with the + corrected Diffie-Hellman group. The initiator MUST again propose its + full set of acceptable cryptographic suites because the rejection + message was unauthenticated and otherwise an active attacker could + trick the endpoints into negotiating a weaker suite than a stronger + one that they both prefer. + + + + +Kaufman Standards Track [Page 21] + +RFC 4306 IKEv2 December 2005 + + +2.8. Rekeying + + IKE, ESP, and AH security associations use secret keys that SHOULD be + used only for a limited amount of time and to protect a limited + amount of data. This limits the lifetime of the entire security + association. When the lifetime of a security association expires, + the security association MUST NOT be used. If there is demand, new + security associations MAY be established. Reestablishment of + security associations to take the place of ones that expire is + referred to as "rekeying". + + To allow for minimal IPsec implementations, the ability to rekey SAs + without restarting the entire IKE_SA is optional. An implementation + MAY refuse all CREATE_CHILD_SA requests within an IKE_SA. If an SA + has expired or is about to expire and rekeying attempts using the + mechanisms described here fail, an implementation MUST close the + IKE_SA and any associated CHILD_SAs and then MAY start new ones. + Implementations SHOULD support in-place rekeying of SAs, since doing + so offers better performance and is likely to reduce the number of + packets lost during the transition. + + To rekey a CHILD_SA within an existing IKE_SA, create a new, + equivalent SA (see section 2.17 below), and when the new one is + established, delete the old one. To rekey an IKE_SA, establish a new + equivalent IKE_SA (see section 2.18 below) with the peer to whom the + old IKE_SA is shared using a CREATE_CHILD_SA within the existing + IKE_SA. An IKE_SA so created inherits all of the original IKE_SA's + CHILD_SAs. Use the new IKE_SA for all control messages needed to + maintain the CHILD_SAs created by the old IKE_SA, and delete the old + IKE_SA. The Delete payload to delete itself MUST be the last request + sent over an IKE_SA. + + SAs SHOULD be rekeyed proactively, i.e., the new SA should be + established before the old one expires and becomes unusable. Enough + time should elapse between the time the new SA is established and the + old one becomes unusable so that traffic can be switched over to the + new SA. + + A difference between IKEv1 and IKEv2 is that in IKEv1 SA lifetimes + were negotiated. In IKEv2, each end of the SA is responsible for + enforcing its own lifetime policy on the SA and rekeying the SA when + necessary. If the two ends have different lifetime policies, the end + with the shorter lifetime will end up always being the one to request + the rekeying. If an SA bundle has been inactive for a long time and + if an endpoint would not initiate the SA in the absence of traffic, + the endpoint MAY choose to close the SA instead of rekeying it when + its lifetime expires. It SHOULD do so if there has been no traffic + since the last time the SA was rekeyed. + + + +Kaufman Standards Track [Page 22] + +RFC 4306 IKEv2 December 2005 + + + If the two ends have the same lifetime policies, it is possible that + both will initiate a rekeying at the same time (which will result in + redundant SAs). To reduce the probability of this happening, the + timing of rekeying requests SHOULD be jittered (delayed by a random + amount of time after the need for rekeying is noticed). + + This form of rekeying may temporarily result in multiple similar SAs + between the same pairs of nodes. When there are two SAs eligible to + receive packets, a node MUST accept incoming packets through either + SA. If redundant SAs are created though such a collision, the SA + created with the lowest of the four nonces used in the two exchanges + SHOULD be closed by the endpoint that created it. + + Note that IKEv2 deliberately allows parallel SAs with the same + traffic selectors between common endpoints. One of the purposes of + this is to support traffic quality of service (QoS) differences among + the SAs (see [RFC2474], [RFC2475], and section 4.1 of [RFC2983]). + Hence unlike IKEv1, the combination of the endpoints and the traffic + selectors may not uniquely identify an SA between those endpoints, so + the IKEv1 rekeying heuristic of deleting SAs on the basis of + duplicate traffic selectors SHOULD NOT be used. + + The node that initiated the surviving rekeyed SA SHOULD delete the + replaced SA after the new one is established. + + There are timing windows -- particularly in the presence of lost + packets -- where endpoints may not agree on the state of an SA. The + responder to a CREATE_CHILD_SA MUST be prepared to accept messages on + an SA before sending its response to the creation request, so there + is no ambiguity for the initiator. The initiator MAY begin sending + on an SA as soon as it processes the response. The initiator, + however, cannot receive on a newly created SA until it receives and + processes the response to its CREATE_CHILD_SA request. How, then, is + the responder to know when it is OK to send on the newly created SA? + + From a technical correctness and interoperability perspective, the + responder MAY begin sending on an SA as soon as it sends its response + to the CREATE_CHILD_SA request. In some situations, however, this + could result in packets unnecessarily being dropped, so an + implementation MAY want to defer such sending. + + The responder can be assured that the initiator is prepared to + receive messages on an SA if either (1) it has received a + cryptographically valid message on the new SA, or (2) the new SA + rekeys an existing SA and it receives an IKE request to close the + replaced SA. When rekeying an SA, the responder SHOULD continue to + send messages on the old SA until one of those events occurs. When + establishing a new SA, the responder MAY defer sending messages on a + + + +Kaufman Standards Track [Page 23] + +RFC 4306 IKEv2 December 2005 + + + new SA until either it receives one or a timeout has occurred. If an + initiator receives a message on an SA for which it has not received a + response to its CREATE_CHILD_SA request, it SHOULD interpret that as + a likely packet loss and retransmit the CREATE_CHILD_SA request. An + initiator MAY send a dummy message on a newly created SA if it has no + messages queued in order to assure the responder that the initiator + is ready to receive messages. + +2.9. Traffic Selector Negotiation + + When an IP packet is received by an RFC4301-compliant IPsec subsystem + and matches a "protect" selector in its Security Policy Database + (SPD), the subsystem MUST protect that packet with IPsec. When no SA + exists yet, it is the task of IKE to create it. Maintenance of a + system's SPD is outside the scope of IKE (see [PFKEY] for an example + protocol), though some implementations might update their SPD in + connection with the running of IKE (for an example scenario, see + section 1.1.3). + + Traffic Selector (TS) payloads allow endpoints to communicate some of + the information from their SPD to their peers. TS payloads specify + the selection criteria for packets that will be forwarded over the + newly set up SA. This can serve as a consistency check in some + scenarios to assure that the SPDs are consistent. In others, it + guides the dynamic update of the SPD. + + Two TS payloads appear in each of the messages in the exchange that + creates a CHILD_SA pair. Each TS payload contains one or more + Traffic Selectors. Each Traffic Selector consists of an address + range (IPv4 or IPv6), a port range, and an IP protocol ID. In + support of the scenario described in section 1.1.3, an initiator may + request that the responder assign an IP address and tell the + initiator what it is. + + IKEv2 allows the responder to choose a subset of the traffic proposed + by the initiator. This could happen when the configurations of the + two endpoints are being updated but only one end has received the new + information. Since the two endpoints may be configured by different + people, the incompatibility may persist for an extended period even + in the absence of errors. It also allows for intentionally different + configurations, as when one end is configured to tunnel all addresses + and depends on the other end to have the up-to-date list. + + The first of the two TS payloads is known as TSi (Traffic Selector- + initiator). The second is known as TSr (Traffic Selector-responder). + TSi specifies the source address of traffic forwarded from (or the + destination address of traffic forwarded to) the initiator of the + CHILD_SA pair. TSr specifies the destination address of the traffic + + + +Kaufman Standards Track [Page 24] + +RFC 4306 IKEv2 December 2005 + + + forwarded to (or the source address of the traffic forwarded from) + the responder of the CHILD_SA pair. For example, if the original + initiator request the creation of a CHILD_SA pair, and wishes to + tunnel all traffic from subnet 192.0.1.* on the initiator's side to + subnet 192.0.2.* on the responder's side, the initiator would include + a single traffic selector in each TS payload. TSi would specify the + address range (192.0.1.0 - 192.0.1.255) and TSr would specify the + address range (192.0.2.0 - 192.0.2.255). Assuming that proposal was + acceptable to the responder, it would send identical TS payloads + back. (Note: The IP address range 192.0.2.* has been reserved for + use in examples in RFCs and similar documents. This document needed + two such ranges, and so also used 192.0.1.*. This should not be + confused with any actual address.) + + The responder is allowed to narrow the choices by selecting a subset + of the traffic, for instance by eliminating or narrowing the range of + one or more members of the set of traffic selectors, provided the set + does not become the NULL set. + + It is possible for the responder's policy to contain multiple smaller + ranges, all encompassed by the initiator's traffic selector, and with + the responder's policy being that each of those ranges should be sent + over a different SA. Continuing the example above, the responder + might have a policy of being willing to tunnel those addresses to and + from the initiator, but might require that each address pair be on a + separately negotiated CHILD_SA. If the initiator generated its + request in response to an incoming packet from 192.0.1.43 to + 192.0.2.123, there would be no way for the responder to determine + which pair of addresses should be included in this tunnel, and it + would have to make a guess or reject the request with a status of + SINGLE_PAIR_REQUIRED. + + To enable the responder to choose the appropriate range in this case, + if the initiator has requested the SA due to a data packet, the + initiator SHOULD include as the first traffic selector in each of TSi + and TSr a very specific traffic selector including the addresses in + the packet triggering the request. In the example, the initiator + would include in TSi two traffic selectors: the first containing the + address range (192.0.1.43 - 192.0.1.43) and the source port and IP + protocol from the packet and the second containing (192.0.1.0 - + 192.0.1.255) with all ports and IP protocols. The initiator would + similarly include two traffic selectors in TSr. + + If the responder's policy does not allow it to accept the entire set + of traffic selectors in the initiator's request, but does allow him + to accept the first selector of TSi and TSr, then the responder MUST + narrow the traffic selectors to a subset that includes the + + + + +Kaufman Standards Track [Page 25] + +RFC 4306 IKEv2 December 2005 + + + initiator's first choices. In this example, the responder might + respond with TSi being (192.0.1.43 - 192.0.1.43) with all ports and + IP protocols. + + If the initiator creates the CHILD_SA pair not in response to an + arriving packet, but rather, say, upon startup, then there may be no + specific addresses the initiator prefers for the initial tunnel over + any other. In that case, the first values in TSi and TSr MAY be + ranges rather than specific values, and the responder chooses a + subset of the initiator's TSi and TSr that are acceptable. If more + than one subset is acceptable but their union is not, the responder + MUST accept some subset and MAY include a Notify payload of type + ADDITIONAL_TS_POSSIBLE to indicate that the initiator might want to + try again. This case will occur only when the initiator and + responder are configured differently from one another. If the + initiator and responder agree on the granularity of tunnels, the + initiator will never request a tunnel wider than the responder will + accept. Such misconfigurations SHOULD be recorded in error logs. + +2.10. Nonces + + The IKE_SA_INIT messages each contain a nonce. These nonces are used + as inputs to cryptographic functions. The CREATE_CHILD_SA request + and the CREATE_CHILD_SA response also contain nonces. These nonces + are used to add freshness to the key derivation technique used to + obtain keys for CHILD_SA, and to ensure creation of strong pseudo- + random bits from the Diffie-Hellman key. Nonces used in IKEv2 MUST + be randomly chosen, MUST be at least 128 bits in size, and MUST be at + least half the key size of the negotiated prf. ("prf" refers to + "pseudo-random function", one of the cryptographic algorithms + negotiated in the IKE exchange.) If the same random number source is + used for both keys and nonces, care must be taken to ensure that the + latter use does not compromise the former. + +2.11. Address and Port Agility + + IKE runs over UDP ports 500 and 4500, and implicitly sets up ESP and + AH associations for the same IP addresses it runs over. The IP + addresses and ports in the outer header are, however, not themselves + cryptographically protected, and IKE is designed to work even through + Network Address Translation (NAT) boxes. An implementation MUST + accept incoming requests even if the source port is not 500 or 4500, + and MUST respond to the address and port from which the request was + received. It MUST specify the address and port at which the request + was received as the source address and port in the response. IKE + functions identically over IPv4 or IPv6. + + + + + +Kaufman Standards Track [Page 26] + +RFC 4306 IKEv2 December 2005 + + +2.12. Reuse of Diffie-Hellman Exponentials + + IKE generates keying material using an ephemeral Diffie-Hellman + exchange in order to gain the property of "perfect forward secrecy". + This means that once a connection is closed and its corresponding + keys are forgotten, even someone who has recorded all of the data + from the connection and gets access to all of the long-term keys of + the two endpoints cannot reconstruct the keys used to protect the + conversation without doing a brute force search of the session key + space. + + Achieving perfect forward secrecy requires that when a connection is + closed, each endpoint MUST forget not only the keys used by the + connection but also any information that could be used to recompute + those keys. In particular, it MUST forget the secrets used in the + Diffie-Hellman calculation and any state that may persist in the + state of a pseudo-random number generator that could be used to + recompute the Diffie-Hellman secrets. + + Since the computing of Diffie-Hellman exponentials is computationally + expensive, an endpoint may find it advantageous to reuse those + exponentials for multiple connection setups. There are several + reasonable strategies for doing this. An endpoint could choose a new + exponential only periodically though this could result in less-than- + perfect forward secrecy if some connection lasts for less than the + lifetime of the exponential. Or it could keep track of which + exponential was used for each connection and delete the information + associated with the exponential only when some corresponding + connection was closed. This would allow the exponential to be reused + without losing perfect forward secrecy at the cost of maintaining + more state. + + Decisions as to whether and when to reuse Diffie-Hellman exponentials + is a private decision in the sense that it will not affect + interoperability. An implementation that reuses exponentials MAY + choose to remember the exponential used by the other endpoint on past + exchanges and if one is reused to avoid the second half of the + calculation. + +2.13. Generating Keying Material + + In the context of the IKE_SA, four cryptographic algorithms are + negotiated: an encryption algorithm, an integrity protection + algorithm, a Diffie-Hellman group, and a pseudo-random function + (prf). The pseudo-random function is used for the construction of + keying material for all of the cryptographic algorithms used in both + the IKE_SA and the CHILD_SAs. + + + + +Kaufman Standards Track [Page 27] + +RFC 4306 IKEv2 December 2005 + + + We assume that each encryption algorithm and integrity protection + algorithm uses a fixed-size key and that any randomly chosen value of + that fixed size can serve as an appropriate key. For algorithms that + accept a variable length key, a fixed key size MUST be specified as + part of the cryptographic transform negotiated. For algorithms for + which not all values are valid keys (such as DES or 3DES with key + parity), the algorithm by which keys are derived from arbitrary + values MUST be specified by the cryptographic transform. For + integrity protection functions based on Hashed Message Authentication + Code (HMAC), the fixed key size is the size of the output of the + underlying hash function. When the prf function takes a variable + length key, variable length data, and produces a fixed-length output + (e.g., when using HMAC), the formulas in this document apply. When + the key for the prf function has fixed length, the data provided as a + key is truncated or padded with zeros as necessary unless exceptional + processing is explained following the formula. + + Keying material will always be derived as the output of the + negotiated prf algorithm. Since the amount of keying material needed + may be greater than the size of the output of the prf algorithm, we + will use the prf iteratively. We will use the terminology prf+ to + describe the function that outputs a pseudo-random stream based on + the inputs to a prf as follows: (where | indicates concatenation) + + prf+ (K,S) = T1 | T2 | T3 | T4 | ... + + where: + T1 = prf (K, S | 0x01) + T2 = prf (K, T1 | S | 0x02) + T3 = prf (K, T2 | S | 0x03) + T4 = prf (K, T3 | S | 0x04) + + continuing as needed to compute all required keys. The keys are + taken from the output string without regard to boundaries (e.g., if + the required keys are a 256-bit Advanced Encryption Standard (AES) + key and a 160-bit HMAC key, and the prf function generates 160 bits, + the AES key will come from T1 and the beginning of T2, while the HMAC + key will come from the rest of T2 and the beginning of T3). + + The constant concatenated to the end of each string feeding the prf + is a single octet. prf+ in this document is not defined beyond 255 + times the size of the prf output. + +2.14. Generating Keying Material for the IKE_SA + + The shared keys are computed as follows. A quantity called SKEYSEED + is calculated from the nonces exchanged during the IKE_SA_INIT + exchange and the Diffie-Hellman shared secret established during that + + + +Kaufman Standards Track [Page 28] + +RFC 4306 IKEv2 December 2005 + + + exchange. SKEYSEED is used to calculate seven other secrets: SK_d + used for deriving new keys for the CHILD_SAs established with this + IKE_SA; SK_ai and SK_ar used as a key to the integrity protection + algorithm for authenticating the component messages of subsequent + exchanges; SK_ei and SK_er used for encrypting (and of course + decrypting) all subsequent exchanges; and SK_pi and SK_pr, which are + used when generating an AUTH payload. + + SKEYSEED and its derivatives are computed as follows: + + SKEYSEED = prf(Ni | Nr, g^ir) + + {SK_d | SK_ai | SK_ar | SK_ei | SK_er | SK_pi | SK_pr } = prf+ + (SKEYSEED, Ni | Nr | SPIi | SPIr ) + + (indicating that the quantities SK_d, SK_ai, SK_ar, SK_ei, SK_er, + SK_pi, and SK_pr are taken in order from the generated bits of the + prf+). g^ir is the shared secret from the ephemeral Diffie-Hellman + exchange. g^ir is represented as a string of octets in big endian + order padded with zeros if necessary to make it the length of the + modulus. Ni and Nr are the nonces, stripped of any headers. If the + negotiated prf takes a fixed-length key and the lengths of Ni and Nr + do not add up to that length, half the bits must come from Ni and + half from Nr, taking the first bits of each. + + The two directions of traffic flow use different keys. The keys used + to protect messages from the original initiator are SK_ai and SK_ei. + The keys used to protect messages in the other direction are SK_ar + and SK_er. Each algorithm takes a fixed number of bits of keying + material, which is specified as part of the algorithm. For integrity + algorithms based on a keyed hash, the key size is always equal to the + length of the output of the underlying hash function. + +2.15. Authentication of the IKE_SA + + When not using extensible authentication (see section 2.16), the + peers are authenticated by having each sign (or MAC using a shared + secret as the key) a block of data. For the responder, the octets to + be signed start with the first octet of the first SPI in the header + of the second message and end with the last octet of the last payload + in the second message. Appended to this (for purposes of computing + the signature) are the initiator's nonce Ni (just the value, not the + payload containing it), and the value prf(SK_pr,IDr') where IDr' is + the responder's ID payload excluding the fixed header. Note that + neither the nonce Ni nor the value prf(SK_pr,IDr') are transmitted. + Similarly, the initiator signs the first message, starting with the + first octet of the first SPI in the header and ending with the last + octet of the last payload. Appended to this (for purposes of + + + +Kaufman Standards Track [Page 29] + +RFC 4306 IKEv2 December 2005 + + + computing the signature) are the responder's nonce Nr, and the value + prf(SK_pi,IDi'). In the above calculation, IDi' and IDr' are the + entire ID payloads excluding the fixed header. It is critical to the + security of the exchange that each side sign the other side's nonce. + + Note that all of the payloads are included under the signature, + including any payload types not defined in this document. If the + first message of the exchange is sent twice (the second time with a + responder cookie and/or a different Diffie-Hellman group), it is the + second version of the message that is signed. + + Optionally, messages 3 and 4 MAY include a certificate, or + certificate chain providing evidence that the key used to compute a + digital signature belongs to the name in the ID payload. The + signature or MAC will be computed using algorithms dictated by the + type of key used by the signer, and specified by the Auth Method + field in the Authentication payload. There is no requirement that + the initiator and responder sign with the same cryptographic + algorithms. The choice of cryptographic algorithms depends on the + type of key each has. In particular, the initiator may be using a + shared key while the responder may have a public signature key and + certificate. It will commonly be the case (but it is not required) + that if a shared secret is used for authentication that the same key + is used in both directions. Note that it is a common but typically + insecure practice to have a shared key derived solely from a user- + chosen password without incorporating another source of randomness. + + This is typically insecure because user-chosen passwords are unlikely + to have sufficient unpredictability to resist dictionary attacks and + these attacks are not prevented in this authentication method. + (Applications using password-based authentication for bootstrapping + and IKE_SA should use the authentication method in section 2.16, + which is designed to prevent off-line dictionary attacks.) The pre- + shared key SHOULD contain as much unpredictability as the strongest + key being negotiated. In the case of a pre-shared key, the AUTH + value is computed as: + + AUTH = prf(prf(Shared Secret,"Key Pad for IKEv2"), ) + + where the string "Key Pad for IKEv2" is 17 ASCII characters without + null termination. The shared secret can be variable length. The pad + string is added so that if the shared secret is derived from a + password, the IKE implementation need not store the password in + cleartext, but rather can store the value prf(Shared Secret,"Key Pad + for IKEv2"), which could not be used as a password equivalent for + protocols other than IKEv2. As noted above, deriving the shared + secret from a password is not secure. This construction is used + because it is anticipated that people will do it anyway. The + + + +Kaufman Standards Track [Page 30] + +RFC 4306 IKEv2 December 2005 + + + management interface by which the Shared Secret is provided MUST + accept ASCII strings of at least 64 octets and MUST NOT add a null + terminator before using them as shared secrets. It MUST also accept + a HEX encoding of the Shared Secret. The management interface MAY + accept other encodings if the algorithm for translating the encoding + to a binary string is specified. If the negotiated prf takes a + fixed-size key, the shared secret MUST be of that fixed size. + +2.16. Extensible Authentication Protocol Methods + + In addition to authentication using public key signatures and shared + secrets, IKE supports authentication using methods defined in RFC + 3748 [EAP]. Typically, these methods are asymmetric (designed for a + user authenticating to a server), and they may not be mutual. For + this reason, these protocols are typically used to authenticate the + initiator to the responder and MUST be used in conjunction with a + public key signature based authentication of the responder to the + initiator. These methods are often associated with mechanisms + referred to as "Legacy Authentication" mechanisms. + + While this memo references [EAP] with the intent that new methods can + be added in the future without updating this specification, some + simpler variations are documented here and in section 3.16. [EAP] + defines an authentication protocol requiring a variable number of + messages. Extensible Authentication is implemented in IKE as + additional IKE_AUTH exchanges that MUST be completed in order to + initialize the IKE_SA. + + An initiator indicates a desire to use extensible authentication by + leaving out the AUTH payload from message 3. By including an IDi + payload but not an AUTH payload, the initiator has declared an + identity but has not proven it. If the responder is willing to use + an extensible authentication method, it will place an Extensible + Authentication Protocol (EAP) payload in message 4 and defer sending + SAr2, TSi, and TSr until initiator authentication is complete in a + subsequent IKE_AUTH exchange. In the case of a minimal extensible + authentication, the initial SA establishment will appear as follows: + + + + + + + + + + + + + + +Kaufman Standards Track [Page 31] + +RFC 4306 IKEv2 December 2005 + + + Initiator Responder + ----------- ----------- + HDR, SAi1, KEi, Ni --> + + <-- HDR, SAr1, KEr, Nr, [CERTREQ] + + HDR, SK {IDi, [CERTREQ,] [IDr,] + SAi2, TSi, TSr} --> + + <-- HDR, SK {IDr, [CERT,] AUTH, + EAP } + + HDR, SK {EAP} --> + + <-- HDR, SK {EAP (success)} + + HDR, SK {AUTH} --> + + <-- HDR, SK {AUTH, SAr2, TSi, TSr } + + For EAP methods that create a shared key as a side effect of + authentication, that shared key MUST be used by both the initiator + and responder to generate AUTH payloads in messages 7 and 8 using the + syntax for shared secrets specified in section 2.15. The shared key + from EAP is the field from the EAP specification named MSK. The + shared key generated during an IKE exchange MUST NOT be used for any + other purpose. + + EAP methods that do not establish a shared key SHOULD NOT be used, as + they are subject to a number of man-in-the-middle attacks [EAPMITM] + if these EAP methods are used in other protocols that do not use a + server-authenticated tunnel. Please see the Security Considerations + section for more details. If EAP methods that do not generate a + shared key are used, the AUTH payloads in messages 7 and 8 MUST be + generated using SK_pi and SK_pr, respectively. + + The initiator of an IKE_SA using EAP SHOULD be capable of extending + the initial protocol exchange to at least ten IKE_AUTH exchanges in + the event the responder sends notification messages and/or retries + the authentication prompt. Once the protocol exchange defined by the + chosen EAP authentication method has successfully terminated, the + responder MUST send an EAP payload containing the Success message. + Similarly, if the authentication method has failed, the responder + MUST send an EAP payload containing the Failure message. The + responder MAY at any time terminate the IKE exchange by sending an + EAP payload containing the Failure message. + + + + + +Kaufman Standards Track [Page 32] + +RFC 4306 IKEv2 December 2005 + + + Following such an extended exchange, the EAP AUTH payloads MUST be + included in the two messages following the one containing the EAP + Success message. + +2.17. Generating Keying Material for CHILD_SAs + + A single CHILD_SA is created by the IKE_AUTH exchange, and additional + CHILD_SAs can optionally be created in CREATE_CHILD_SA exchanges. + Keying material for them is generated as follows: + + KEYMAT = prf+(SK_d, Ni | Nr) + + Where Ni and Nr are the nonces from the IKE_SA_INIT exchange if this + request is the first CHILD_SA created or the fresh Ni and Nr from the + CREATE_CHILD_SA exchange if this is a subsequent creation. + + For CREATE_CHILD_SA exchanges including an optional Diffie-Hellman + exchange, the keying material is defined as: + + KEYMAT = prf+(SK_d, g^ir (new) | Ni | Nr ) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros in the high-order + bits if necessary to make it the length of the modulus). + + A single CHILD_SA negotiation may result in multiple security + associations. ESP and AH SAs exist in pairs (one in each direction), + and four SAs could be created in a single CHILD_SA negotiation if a + combination of ESP and AH is being negotiated. + + Keying material MUST be taken from the expanded KEYMAT in the + following order: + + All keys for SAs carrying data from the initiator to the responder + are taken before SAs going in the reverse direction. + + If multiple IPsec protocols are negotiated, keying material is + taken in the order in which the protocol headers will appear in + the encapsulated packet. + + If a single protocol has both encryption and authentication keys, + the encryption key is taken from the first octets of KEYMAT and + the authentication key is taken from the next octets. + + Each cryptographic algorithm takes a fixed number of bits of keying + material specified as part of the algorithm. + + + + +Kaufman Standards Track [Page 33] + +RFC 4306 IKEv2 December 2005 + + +2.18. Rekeying IKE_SAs Using a CREATE_CHILD_SA exchange + + The CREATE_CHILD_SA exchange can be used to rekey an existing IKE_SA + (see section 2.8). New initiator and responder SPIs are supplied in + the SPI fields. The TS payloads are omitted when rekeying an IKE_SA. + SKEYSEED for the new IKE_SA is computed using SK_d from the existing + IKE_SA as follows: + + SKEYSEED = prf(SK_d (old), [g^ir (new)] | Ni | Nr) + + where g^ir (new) is the shared secret from the ephemeral Diffie- + Hellman exchange of this CREATE_CHILD_SA exchange (represented as an + octet string in big endian order padded with zeros if necessary to + make it the length of the modulus) and Ni and Nr are the two nonces + stripped of any headers. + + The new IKE_SA MUST reset its message counters to 0. + + SK_d, SK_ai, SK_ar, SK_ei, and SK_er are computed from SKEYSEED as + specified in section 2.14. + +2.19. Requesting an Internal Address on a Remote Network + + Most commonly occurring in the endpoint-to-security-gateway scenario, + an endpoint may need an IP address in the network protected by the + security gateway and may need to have that address dynamically + assigned. A request for such a temporary address can be included in + any request to create a CHILD_SA (including the implicit request in + message 3) by including a CP payload. + + This function provides address allocation to an IPsec Remote Access + Client (IRAC) trying to tunnel into a network protected by an IPsec + Remote Access Server (IRAS). Since the IKE_AUTH exchange creates an + IKE_SA and a CHILD_SA, the IRAC MUST request the IRAS-controlled + address (and optionally other information concerning the protected + network) in the IKE_AUTH exchange. The IRAS may procure an address + for the IRAC from any number of sources such as a DHCP/BOOTP server + or its own address pool. + + Initiator Responder + ----------------------------- --------------------------- + HDR, SK {IDi, [CERT,] [CERTREQ,] + [IDr,] AUTH, CP(CFG_REQUEST), + SAi2, TSi, TSr} --> + + <-- HDR, SK {IDr, [CERT,] AUTH, + CP(CFG_REPLY), SAr2, + TSi, TSr} + + + +Kaufman Standards Track [Page 34] + +RFC 4306 IKEv2 December 2005 + + + In all cases, the CP payload MUST be inserted before the SA payload. + In variations of the protocol where there are multiple IKE_AUTH + exchanges, the CP payloads MUST be inserted in the messages + containing the SA payloads. + + CP(CFG_REQUEST) MUST contain at least an INTERNAL_ADDRESS attribute + (either IPv4 or IPv6) but MAY contain any number of additional + attributes the initiator wants returned in the response. + + For example, message from initiator to responder: + CP(CFG_REQUEST)= + INTERNAL_ADDRESS(0.0.0.0) + INTERNAL_NETMASK(0.0.0.0) + INTERNAL_DNS(0.0.0.0) + TSi = (0, 0-65535,0.0.0.0-255.255.255.255) + TSr = (0, 0-65535,0.0.0.0-255.255.255.255) + + NOTE: Traffic Selectors contain (protocol, port range, address + range). + + Message from responder to initiator: + + CP(CFG_REPLY)= + INTERNAL_ADDRESS(192.0.2.202) + INTERNAL_NETMASK(255.255.255.0) + INTERNAL_SUBNET(192.0.2.0/255.255.255.0) + TSi = (0, 0-65535,192.0.2.202-192.0.2.202) + TSr = (0, 0-65535,192.0.2.0-192.0.2.255) + + All returned values will be implementation dependent. As can be seen + in the above example, the IRAS MAY also send other attributes that + were not included in CP(CFG_REQUEST) and MAY ignore the non-mandatory + attributes that it does not support. + + The responder MUST NOT send a CFG_REPLY without having first received + a CP(CFG_REQUEST) from the initiator, because we do not want the IRAS + to perform an unnecessary configuration lookup if the IRAC cannot + process the REPLY. In the case where the IRAS's configuration + requires that CP be used for a given identity IDi, but IRAC has + failed to send a CP(CFG_REQUEST), IRAS MUST fail the request, and + terminate the IKE exchange with a FAILED_CP_REQUIRED error. + +2.20. Requesting the Peer's Version + + An IKE peer wishing to inquire about the other peer's IKE software + version information MAY use the method below. This is an example of + a configuration request within an INFORMATIONAL exchange, after the + IKE_SA and first CHILD_SA have been created. + + + +Kaufman Standards Track [Page 35] + +RFC 4306 IKEv2 December 2005 + + + An IKE implementation MAY decline to give out version information + prior to authentication or even after authentication to prevent + trolling in case some implementation is known to have some security + weakness. In that case, it MUST either return an empty string or no + CP payload if CP is not supported. + + Initiator Responder + ----------------------------- -------------------------- + HDR, SK{CP(CFG_REQUEST)} --> + <-- HDR, SK{CP(CFG_REPLY)} + + CP(CFG_REQUEST)= + APPLICATION_VERSION("") + + CP(CFG_REPLY) APPLICATION_VERSION("foobar v1.3beta, (c) Foo Bar + Inc.") + +2.21. Error Handling + + There are many kinds of errors that can occur during IKE processing. + If a request is received that is badly formatted or unacceptable for + reasons of policy (e.g., no matching cryptographic algorithms), the + response MUST contain a Notify payload indicating the error. If an + error occurs outside the context of an IKE request (e.g., the node is + getting ESP messages on a nonexistent SPI), the node SHOULD initiate + an INFORMATIONAL exchange with a Notify payload describing the + problem. + + Errors that occur before a cryptographically protected IKE_SA is + established must be handled very carefully. There is a trade-off + between wanting to be helpful in diagnosing a problem and responding + to it and wanting to avoid being a dupe in a denial of service attack + based on forged messages. + + If a node receives a message on UDP port 500 or 4500 outside the + context of an IKE_SA known to it (and not a request to start one), it + may be the result of a recent crash of the node. If the message is + marked as a response, the node MAY audit the suspicious event but + MUST NOT respond. If the message is marked as a request, the node + MAY audit the suspicious event and MAY send a response. If a + response is sent, the response MUST be sent to the IP address and + port from whence it came with the same IKE SPIs and the Message ID + copied. The response MUST NOT be cryptographically protected and + MUST contain a Notify payload indicating INVALID_IKE_SPI. + + A node receiving such an unprotected Notify payload MUST NOT respond + and MUST NOT change the state of any existing SAs. The message might + be a forgery or might be a response the genuine correspondent was + + + +Kaufman Standards Track [Page 36] + +RFC 4306 IKEv2 December 2005 + + + tricked into sending. A node SHOULD treat such a message (and also a + network message like ICMP destination unreachable) as a hint that + there might be problems with SAs to that IP address and SHOULD + initiate a liveness test for any such IKE_SA. An implementation + SHOULD limit the frequency of such tests to avoid being tricked into + participating in a denial of service attack. + + A node receiving a suspicious message from an IP address with which + it has an IKE_SA MAY send an IKE Notify payload in an IKE + INFORMATIONAL exchange over that SA. The recipient MUST NOT change + the state of any SA's as a result but SHOULD audit the event to aid + in diagnosing malfunctions. A node MUST limit the rate at which it + will send messages in response to unprotected messages. + +2.22. IPComp + + Use of IP compression [IPCOMP] can be negotiated as part of the setup + of a CHILD_SA. While IP compression involves an extra header in each + packet and a compression parameter index (CPI), the virtual + "compression association" has no life outside the ESP or AH SA that + contains it. Compression associations disappear when the + corresponding ESP or AH SA goes away. It is not explicitly mentioned + in any DELETE payload. + + Negotiation of IP compression is separate from the negotiation of + cryptographic parameters associated with a CHILD_SA. A node + requesting a CHILD_SA MAY advertise its support for one or more + compression algorithms through one or more Notify payloads of type + IPCOMP_SUPPORTED. The response MAY indicate acceptance of a single + compression algorithm with a Notify payload of type IPCOMP_SUPPORTED. + These payloads MUST NOT occur in messages that do not contain SA + payloads. + + Although there has been discussion of allowing multiple compression + algorithms to be accepted and to have different compression + algorithms available for the two directions of a CHILD_SA, + implementations of this specification MUST NOT accept an IPComp + algorithm that was not proposed, MUST NOT accept more than one, and + MUST NOT compress using an algorithm other than one proposed and + accepted in the setup of the CHILD_SA. + + A side effect of separating the negotiation of IPComp from + cryptographic parameters is that it is not possible to propose + multiple cryptographic suites and propose IP compression with some of + them but not others. + + + + + + +Kaufman Standards Track [Page 37] + +RFC 4306 IKEv2 December 2005 + + +2.23. NAT Traversal + + Network Address Translation (NAT) gateways are a controversial + subject. This section briefly describes what they are and how they + are likely to act on IKE traffic. Many people believe that NATs are + evil and that we should not design our protocols so as to make them + work better. IKEv2 does specify some unintuitive processing rules in + order that NATs are more likely to work. + + NATs exist primarily because of the shortage of IPv4 addresses, + though there are other rationales. IP nodes that are "behind" a NAT + have IP addresses that are not globally unique, but rather are + assigned from some space that is unique within the network behind the + NAT but that are likely to be reused by nodes behind other NATs. + Generally, nodes behind NATs can communicate with other nodes behind + the same NAT and with nodes with globally unique addresses, but not + with nodes behind other NATs. There are exceptions to that rule. + When those nodes make connections to nodes on the real Internet, the + NAT gateway "translates" the IP source address to an address that + will be routed back to the gateway. Messages to the gateway from the + Internet have their destination addresses "translated" to the + internal address that will route the packet to the correct endnode. + + NATs are designed to be "transparent" to endnodes. Neither software + on the node behind the NAT nor the node on the Internet requires + modification to communicate through the NAT. Achieving this + transparency is more difficult with some protocols than with others. + Protocols that include IP addresses of the endpoints within the + payloads of the packet will fail unless the NAT gateway understands + the protocol and modifies the internal references as well as those in + the headers. Such knowledge is inherently unreliable, is a network + layer violation, and often results in subtle problems. + + Opening an IPsec connection through a NAT introduces special + problems. If the connection runs in transport mode, changing the IP + addresses on packets will cause the checksums to fail and the NAT + cannot correct the checksums because they are cryptographically + protected. Even in tunnel mode, there are routing problems because + transparently translating the addresses of AH and ESP packets + requires special logic in the NAT and that logic is heuristic and + unreliable in nature. For that reason, IKEv2 can negotiate UDP + encapsulation of IKE and ESP packets. This encoding is slightly less + efficient but is easier for NATs to process. In addition, firewalls + may be configured to pass IPsec traffic over UDP but not ESP/AH or + vice versa. + + + + + + +Kaufman Standards Track [Page 38] + +RFC 4306 IKEv2 December 2005 + + + It is a common practice of NATs to translate TCP and UDP port numbers + as well as addresses and use the port numbers of inbound packets to + decide which internal node should get a given packet. For this + reason, even though IKE packets MUST be sent from and to UDP port + 500, they MUST be accepted coming from any port and responses MUST be + sent to the port from whence they came. This is because the ports + may be modified as the packets pass through NATs. Similarly, IP + addresses of the IKE endpoints are generally not included in the IKE + payloads because the payloads are cryptographically protected and + could not be transparently modified by NATs. + + Port 4500 is reserved for UDP-encapsulated ESP and IKE. When working + through a NAT, it is generally better to pass IKE packets over port + 4500 because some older NATs handle IKE traffic on port 500 cleverly + in an attempt to transparently establish IPsec connections between + endpoints that don't handle NAT traversal themselves. Such NATs may + interfere with the straightforward NAT traversal envisioned by this + document, so an IPsec endpoint that discovers a NAT between it and + its correspondent MUST send all subsequent traffic to and from port + 4500, which NATs should not treat specially (as they might with port + 500). + + The specific requirements for supporting NAT traversal [RFC3715] are + listed below. Support for NAT traversal is optional. In this + section only, requirements listed as MUST apply only to + implementations supporting NAT traversal. + + IKE MUST listen on port 4500 as well as port 500. IKE MUST + respond to the IP address and port from which packets arrived. + + Both IKE initiator and responder MUST include in their IKE_SA_INIT + packets Notify payloads of type NAT_DETECTION_SOURCE_IP and + NAT_DETECTION_DESTINATION_IP. Those payloads can be used to + detect if there is NAT between the hosts, and which end is behind + the NAT. The location of the payloads in the IKE_SA_INIT packets + are just after the Ni and Nr payloads (before the optional CERTREQ + payload). + + If none of the NAT_DETECTION_SOURCE_IP payload(s) received matches + the hash of the source IP and port found from the IP header of the + packet containing the payload, it means that the other end is + behind NAT (i.e., someone along the route changed the source + address of the original packet to match the address of the NAT + box). In this case, this end should allow dynamic update of the + other ends IP address, as described later. + + + + + + +Kaufman Standards Track [Page 39] + +RFC 4306 IKEv2 December 2005 + + + If the NAT_DETECTION_DESTINATION_IP payload received does not + match the hash of the destination IP and port found from the IP + header of the packet containing the payload, it means that this + end is behind a NAT. In this case, this end SHOULD start sending + keepalive packets as explained in [Hutt05]. + + The IKE initiator MUST check these payloads if present and if they + do not match the addresses in the outer packet MUST tunnel all + future IKE and ESP packets associated with this IKE_SA over UDP + port 4500. + + To tunnel IKE packets over UDP port 4500, the IKE header has four + octets of zero prepended and the result immediately follows the + UDP header. To tunnel ESP packets over UDP port 4500, the ESP + header immediately follows the UDP header. Since the first four + bytes of the ESP header contain the SPI, and the SPI cannot + validly be zero, it is always possible to distinguish ESP and IKE + messages. + + The original source and destination IP address required for the + transport mode TCP and UDP packet checksum fixup (see [Hutt05]) + are obtained from the Traffic Selectors associated with the + exchange. In the case of NAT traversal, the Traffic Selectors + MUST contain exactly one IP address, which is then used as the + original IP address. + + There are cases where a NAT box decides to remove mappings that + are still alive (for example, the keepalive interval is too long, + or the NAT box is rebooted). To recover in these cases, hosts + that are not behind a NAT SHOULD send all packets (including + retransmission packets) to the IP address and port from the last + valid authenticated packet from the other end (i.e., dynamically + update the address). A host behind a NAT SHOULD NOT do this + because it opens a DoS attack possibility. Any authenticated IKE + packet or any authenticated UDP-encapsulated ESP packet can be + used to detect that the IP address or the port has changed. + + Note that similar but probably not identical actions will likely + be needed to make IKE work with Mobile IP, but such processing is + not addressed by this document. + +2.24. Explicit Congestion Notification (ECN) + + When IPsec tunnels behave as originally specified in [RFC2401], ECN + usage is not appropriate for the outer IP headers because tunnel + decapsulation processing discards ECN congestion indications to the + detriment of the network. ECN support for IPsec tunnels for IKEv1- + based IPsec requires multiple operating modes and negotiation (see + + + +Kaufman Standards Track [Page 40] + +RFC 4306 IKEv2 December 2005 + + + [RFC3168]). IKEv2 simplifies this situation by requiring that ECN be + usable in the outer IP headers of all tunnel-mode IPsec SAs created + by IKEv2. Specifically, tunnel encapsulators and decapsulators for + all tunnel-mode SAs created by IKEv2 MUST support the ECN full- + functionality option for tunnels specified in [RFC3168] and MUST + implement the tunnel encapsulation and decapsulation processing + specified in [RFC4301] to prevent discarding of ECN congestion + indications. + +3. Header and Payload Formats + +3.1. The IKE Header + + IKE messages use UDP ports 500 and/or 4500, with one IKE message per + UDP datagram. Information from the beginning of the packet through + the UDP header is largely ignored except that the IP addresses and + UDP ports from the headers are reversed and used for return packets. + When sent on UDP port 500, IKE messages begin immediately following + the UDP header. When sent on UDP port 4500, IKE messages have + prepended four octets of zero. These four octets of zero are not + part of the IKE message and are not included in any of the length + fields or checksums defined by IKE. Each IKE message begins with the + IKE header, denoted HDR in this memo. Following the header are one + or more IKE payloads each identified by a "Next Payload" field in the + preceding payload. Payloads are processed in the order in which they + appear in an IKE message by invoking the appropriate processing + routine according to the "Next Payload" field in the IKE header and + subsequently according to the "Next Payload" field in the IKE payload + itself until a "Next Payload" field of zero indicates that no + payloads follow. If a payload of type "Encrypted" is found, that + payload is decrypted and its contents parsed as additional payloads. + An Encrypted payload MUST be the last payload in a packet and an + Encrypted payload MUST NOT contain another Encrypted payload. + + The Recipient SPI in the header identifies an instance of an IKE + security association. It is therefore possible for a single instance + of IKE to multiplex distinct sessions with multiple peers. + + All multi-octet fields representing integers are laid out in big + endian order (aka most significant byte first, or network byte + order). + + The format of the IKE header is shown in Figure 4. + + + + + + + + +Kaufman Standards Track [Page 41] + +RFC 4306 IKEv2 December 2005 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Initiator's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! IKE_SA Responder's SPI ! + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload ! MjVer ! MnVer ! Exchange Type ! Flags ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Message ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 4: IKE Header Format + + o Initiator's SPI (8 octets) - A value chosen by the + initiator to identify a unique IKE security association. This + value MUST NOT be zero. + + o Responder's SPI (8 octets) - A value chosen by the + responder to identify a unique IKE security association. This + value MUST be zero in the first message of an IKE Initial + Exchange (including repeats of that message including a + cookie) and MUST NOT be zero in any other message. + + o Next Payload (1 octet) - Indicates the type of payload that + immediately follows the header. The format and value of each + payload are defined below. + + o Major Version (4 bits) - Indicates the major version of the IKE + protocol in use. Implementations based on this version of IKE + MUST set the Major Version to 2. Implementations based on + previous versions of IKE and ISAKMP MUST set the Major Version + to 1. Implementations based on this version of IKE MUST reject + or ignore messages containing a version number greater than + 2. + + o Minor Version (4 bits) - Indicates the minor version of the + IKE protocol in use. Implementations based on this version of + IKE MUST set the Minor Version to 0. They MUST ignore the + minor version number of received messages. + + o Exchange Type (1 octet) - Indicates the type of exchange being + used. This constrains the payloads sent in each message and + orderings of messages in an exchange. + + + +Kaufman Standards Track [Page 42] + +RFC 4306 IKEv2 December 2005 + + + Exchange Type Value + + RESERVED 0-33 + IKE_SA_INIT 34 + IKE_AUTH 35 + CREATE_CHILD_SA 36 + INFORMATIONAL 37 + RESERVED TO IANA 38-239 + Reserved for private use 240-255 + + o Flags (1 octet) - Indicates specific options that are set + for the message. Presence of options are indicated by the + appropriate bit in the flags field being set. The bits are + defined LSB first, so bit 0 would be the least significant + bit of the Flags octet. In the description below, a bit + being 'set' means its value is '1', while 'cleared' means + its value is '0'. + + -- X(reserved) (bits 0-2) - These bits MUST be cleared + when sending and MUST be ignored on receipt. + + -- I(nitiator) (bit 3 of Flags) - This bit MUST be set in + messages sent by the original initiator of the IKE_SA + and MUST be cleared in messages sent by the original + responder. It is used by the recipient to determine + which eight octets of the SPI were generated by the + recipient. + + -- V(ersion) (bit 4 of Flags) - This bit indicates that + the transmitter is capable of speaking a higher major + version number of the protocol than the one indicated + in the major version number field. Implementations of + IKEv2 must clear this bit when sending and MUST ignore + it in incoming messages. + + -- R(esponse) (bit 5 of Flags) - This bit indicates that + this message is a response to a message containing + the same message ID. This bit MUST be cleared in all + request messages and MUST be set in all responses. + An IKE endpoint MUST NOT generate a response to a + message that is marked as being a response. + + -- X(reserved) (bits 6-7 of Flags) - These bits MUST be + cleared when sending and MUST be ignored on receipt. + + + + + + + +Kaufman Standards Track [Page 43] + +RFC 4306 IKEv2 December 2005 + + + o Message ID (4 octets) - Message identifier used to control + retransmission of lost packets and matching of requests and + responses. It is essential to the security of the protocol + because it is used to prevent message replay attacks. + See sections 2.1 and 2.2. + + o Length (4 octets) - Length of total message (header + payloads) + in octets. + +3.2. Generic Payload Header + + Each IKE payload defined in sections 3.3 through 3.16 begins with a + generic payload header, shown in Figure 5. Figures for each payload + below will include the generic payload header, but for brevity the + description of each field will be omitted. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 5: Generic Payload Header + + The Generic Payload Header fields are defined as follows: + + o Next Payload (1 octet) - Identifier for the payload type of the + next payload in the message. If the current payload is the last + in the message, then this field will be 0. This field provides a + "chaining" capability whereby additional payloads can be added to + a message by appending it to the end of the message and setting + the "Next Payload" field of the preceding payload to indicate the + new payload's type. An Encrypted payload, which must always be + the last payload of a message, is an exception. It contains data + structures in the format of additional payloads. In the header of + an Encrypted payload, the Next Payload field is set to the payload + type of the first contained payload (instead of 0). + + Payload Type Values + + Next Payload Type Notation Value + + No Next Payload 0 + + RESERVED 1-32 + Security Association SA 33 + Key Exchange KE 34 + Identification - Initiator IDi 35 + + + +Kaufman Standards Track [Page 44] + +RFC 4306 IKEv2 December 2005 + + + Identification - Responder IDr 36 + Certificate CERT 37 + Certificate Request CERTREQ 38 + Authentication AUTH 39 + Nonce Ni, Nr 40 + Notify N 41 + Delete D 42 + Vendor ID V 43 + Traffic Selector - Initiator TSi 44 + Traffic Selector - Responder TSr 45 + Encrypted E 46 + Configuration CP 47 + Extensible Authentication EAP 48 + RESERVED TO IANA 49-127 + PRIVATE USE 128-255 + + Payload type values 1-32 should not be used so that there is no + overlap with the code assignments for IKEv1. Payload type values + 49-127 are reserved to IANA for future assignment in IKEv2 (see + section 6). Payload type values 128-255 are for private use among + mutually consenting parties. + + o Critical (1 bit) - MUST be set to zero if the sender wants the + recipient to skip this payload if it does not understand the + payload type code in the Next Payload field of the previous + payload. MUST be set to one if the sender wants the recipient to + reject this entire message if it does not understand the payload + type. MUST be ignored by the recipient if the recipient + understands the payload type code. MUST be set to zero for + payload types defined in this document. Note that the critical + bit applies to the current payload rather than the "next" payload + whose type code appears in the first octet. The reasoning behind + not setting the critical bit for payloads defined in this document + is that all implementations MUST understand all payload types + defined in this document and therefore must ignore the Critical + bit's value. Skipped payloads are expected to have valid Next + Payload and Payload Length fields. + + o RESERVED (7 bits) - MUST be sent as zero; MUST be ignored on + receipt. + + o Payload Length (2 octets) - Length in octets of the current + payload, including the generic payload header. + + + + + + + + +Kaufman Standards Track [Page 45] + +RFC 4306 IKEv2 December 2005 + + +3.3. Security Association Payload + + The Security Association Payload, denoted SA in this memo, is used to + negotiate attributes of a security association. Assembly of Security + Association Payloads requires great peace of mind. An SA payload MAY + contain multiple proposals. If there is more than one, they MUST be + ordered from most preferred to least preferred. Each proposal may + contain multiple IPsec protocols (where a protocol is IKE, ESP, or + AH), each protocol MAY contain multiple transforms, and each + transform MAY contain multiple attributes. When parsing an SA, an + implementation MUST check that the total Payload Length is consistent + with the payload's internal lengths and counts. Proposals, + Transforms, and Attributes each have their own variable length + encodings. They are nested such that the Payload Length of an SA + includes the combined contents of the SA, Proposal, Transform, and + Attribute information. The length of a Proposal includes the lengths + of all Transforms and Attributes it contains. The length of a + Transform includes the lengths of all Attributes it contains. + + The syntax of Security Associations, Proposals, Transforms, and + Attributes is based on ISAKMP; however, the semantics are somewhat + different. The reason for the complexity and the hierarchy is to + allow for multiple possible combinations of algorithms to be encoded + in a single SA. Sometimes there is a choice of multiple algorithms, + whereas other times there is a combination of algorithms. For + example, an initiator might want to propose using (AH w/MD5 and ESP + w/3DES) OR (ESP w/MD5 and 3DES). + + One of the reasons the semantics of the SA payload has changed from + ISAKMP and IKEv1 is to make the encodings more compact in common + cases. + + The Proposal structure contains within it a Proposal # and an IPsec + protocol ID. Each structure MUST have the same Proposal # as the + previous one or be one (1) greater. The first Proposal MUST have a + Proposal # of one (1). If two successive structures have the same + Proposal number, it means that the proposal consists of the first + structure AND the second. So a proposal of AH AND ESP would have two + proposal structures, one for AH and one for ESP and both would have + Proposal #1. A proposal of AH OR ESP would have two proposal + structures, one for AH with Proposal #1 and one for ESP with Proposal + #2. + + Each Proposal/Protocol structure is followed by one or more transform + structures. The number of different transforms is generally + determined by the Protocol. AH generally has a single transform: an + integrity check algorithm. ESP generally has two: an encryption + algorithm and an integrity check algorithm. IKE generally has four + + + +Kaufman Standards Track [Page 46] + +RFC 4306 IKEv2 December 2005 + + + transforms: a Diffie-Hellman group, an integrity check algorithm, a + prf algorithm, and an encryption algorithm. If an algorithm that + combines encryption and integrity protection is proposed, it MUST be + proposed as an encryption algorithm and an integrity protection + algorithm MUST NOT be proposed. For each Protocol, the set of + permissible transforms is assigned transform ID numbers, which appear + in the header of each transform. + + If there are multiple transforms with the same Transform Type, the + proposal is an OR of those transforms. If there are multiple + Transforms with different Transform Types, the proposal is an AND of + the different groups. For example, to propose ESP with (3DES or + IDEA) and (HMAC_MD5 or HMAC_SHA), the ESP proposal would contain two + Transform Type 1 candidates (one for 3DES and one for IDEA) and two + Transform Type 2 candidates (one for HMAC_MD5 and one for HMAC_SHA). + This effectively proposes four combinations of algorithms. If the + initiator wanted to propose only a subset of those, for example (3DES + and HMAC_MD5) or (IDEA and HMAC_SHA), there is no way to encode that + as multiple transforms within a single Proposal. Instead, the + initiator would have to construct two different Proposals, each with + two transforms. + + A given transform MAY have one or more Attributes. Attributes are + necessary when the transform can be used in more than one way, as + when an encryption algorithm has a variable key size. The transform + would specify the algorithm and the attribute would specify the key + size. Most transforms do not have attributes. A transform MUST NOT + have multiple attributes of the same type. To propose alternate + values for an attribute (for example, multiple key sizes for the AES + encryption algorithm), and implementation MUST include multiple + Transforms with the same Transform Type each with a single Attribute. + + Note that the semantics of Transforms and Attributes are quite + different from those in IKEv1. In IKEv1, a single Transform carried + multiple algorithms for a protocol with one carried in the Transform + and the others carried in the Attributes. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 6: Security Association Payload + + + +Kaufman Standards Track [Page 47] + +RFC 4306 IKEv2 December 2005 + + + o Proposals (variable) - One or more proposal substructures. + + The payload type for the Security Association Payload is thirty + three (33). + +3.3.1. Proposal Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 2 ! RESERVED ! Proposal Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Proposal # ! Protocol ID ! SPI Size !# of Transforms! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ SPI (variable) ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 7: Proposal Substructure + + o 0 (last) or 2 (more) (1 octet) - Specifies whether this is the + last Proposal Substructure in the SA. This syntax is inherited + from ISAKMP, but is unnecessary because the last Proposal could + be identified from the length of the SA. The value (2) + corresponds to a Payload Type of Proposal in IKEv1, and the + first 4 octets of the Proposal structure are designed to look + somewhat like the header of a Payload. + + o RESERVED (1 octet) - MUST be sent as zero; MUST be ignored on + receipt. + + o Proposal Length (2 octets) - Length of this proposal, including + all transforms and attributes that follow. + + o Proposal # (1 octet) - When a proposal is made, the first + proposal in an SA payload MUST be #1, and subsequent proposals + MUST either be the same as the previous proposal (indicating an + AND of the two proposals) or one more than the previous + proposal (indicating an OR of the two proposals). When a + proposal is accepted, all of the proposal numbers in the SA + payload MUST be the same and MUST match the number on the + proposal sent that was accepted. + + + + + + +Kaufman Standards Track [Page 48] + +RFC 4306 IKEv2 December 2005 + + + o Protocol ID (1 octet) - Specifies the IPsec protocol identifier + for the current negotiation. The defined values are: + + Protocol Protocol ID + RESERVED 0 + IKE 1 + AH 2 + ESP 3 + RESERVED TO IANA 4-200 + PRIVATE USE 201-255 + + o SPI Size (1 octet) - For an initial IKE_SA negotiation, this + field MUST be zero; the SPI is obtained from the outer header. + During subsequent negotiations, it is equal to the size, in + octets, of the SPI of the corresponding protocol (8 for IKE, 4 + for ESP and AH). + + o # of Transforms (1 octet) - Specifies the number of transforms + in this proposal. + + o SPI (variable) - The sending entity's SPI. Even if the SPI Size + is not a multiple of 4 octets, there is no padding applied to + the payload. When the SPI Size field is zero, this field is + not present in the Security Association payload. + + o Transforms (variable) - One or more transform substructures. + +3.3.2. Transform Substructure + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! 0 (last) or 3 ! RESERVED ! Transform Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !Transform Type ! RESERVED ! Transform ID ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Transform Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 8: Transform Substructure + + o 0 (last) or 3 (more) (1 octet) - Specifies whether this is the + last Transform Substructure in the Proposal. This syntax is + inherited from ISAKMP, but is unnecessary because the last + Proposal could be identified from the length of the SA. The + + + + +Kaufman Standards Track [Page 49] + +RFC 4306 IKEv2 December 2005 + + + value (3) corresponds to a Payload Type of Transform in IKEv1, + and the first 4 octets of the Transform structure are designed + to look somewhat like the header of a Payload. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Transform Length - The length (in octets) of the Transform + Substructure including Header and Attributes. + + o Transform Type (1 octet) - The type of transform being + specified in this transform. Different protocols support + different transform types. For some protocols, some of the + transforms may be optional. If a transform is optional and the + initiator wishes to propose that the transform be omitted, no + transform of the given type is included in the proposal. If + the initiator wishes to make use of the transform optional to + the responder, it includes a transform substructure with + transform ID = 0 as one of the options. + + o Transform ID (2 octets) - The specific instance of the + transform type being proposed. + + Transform Type Values + + Transform Used In + Type + RESERVED 0 + Encryption Algorithm (ENCR) 1 (IKE and ESP) + Pseudo-random Function (PRF) 2 (IKE) + Integrity Algorithm (INTEG) 3 (IKE, AH, optional in ESP) + Diffie-Hellman Group (D-H) 4 (IKE, optional in AH & ESP) + Extended Sequence Numbers (ESN) 5 (AH and ESP) + RESERVED TO IANA 6-240 + PRIVATE USE 241-255 + + For Transform Type 1 (Encryption Algorithm), defined Transform IDs + are: + + Name Number Defined In + RESERVED 0 + ENCR_DES_IV64 1 (RFC1827) + ENCR_DES 2 (RFC2405), [DES] + ENCR_3DES 3 (RFC2451) + ENCR_RC5 4 (RFC2451) + ENCR_IDEA 5 (RFC2451), [IDEA] + ENCR_CAST 6 (RFC2451) + ENCR_BLOWFISH 7 (RFC2451) + ENCR_3IDEA 8 (RFC2451) + + + +Kaufman Standards Track [Page 50] + +RFC 4306 IKEv2 December 2005 + + + ENCR_DES_IV32 9 + RESERVED 10 + ENCR_NULL 11 (RFC2410) + ENCR_AES_CBC 12 (RFC3602) + ENCR_AES_CTR 13 (RFC3664) + + values 14-1023 are reserved to IANA. Values 1024-65535 are + for private use among mutually consenting parties. + + For Transform Type 2 (Pseudo-random Function), defined Transform IDs + are: + + Name Number Defined In + RESERVED 0 + PRF_HMAC_MD5 1 (RFC2104), [MD5] + PRF_HMAC_SHA1 2 (RFC2104), [SHA] + PRF_HMAC_TIGER 3 (RFC2104) + PRF_AES128_XCBC 4 (RFC3664) + + values 5-1023 are reserved to IANA. Values 1024-65535 are for + private use among mutually consenting parties. + + For Transform Type 3 (Integrity Algorithm), defined Transform IDs + are: + + Name Number Defined In + NONE 0 + AUTH_HMAC_MD5_96 1 (RFC2403) + AUTH_HMAC_SHA1_96 2 (RFC2404) + AUTH_DES_MAC 3 + AUTH_KPDK_MD5 4 (RFC1826) + AUTH_AES_XCBC_96 5 (RFC3566) + + values 6-1023 are reserved to IANA. Values 1024-65535 are for + private use among mutually consenting parties. + + For Transform Type 4 (Diffie-Hellman Group), defined Transform IDs + are: + + Name Number + NONE 0 + Defined in Appendix B 1 - 2 + RESERVED 3 - 4 + Defined in [ADDGROUP] 5 + RESERVED TO IANA 6 - 13 + Defined in [ADDGROUP] 14 - 18 + RESERVED TO IANA 19 - 1023 + PRIVATE USE 1024-65535 + + + +Kaufman Standards Track [Page 51] + +RFC 4306 IKEv2 December 2005 + + + For Transform Type 5 (Extended Sequence Numbers), defined Transform + IDs are: + + Name Number + No Extended Sequence Numbers 0 + Extended Sequence Numbers 1 + RESERVED 2 - 65535 + +3.3.3. Valid Transform Types by Protocol + + The number and type of transforms that accompany an SA payload are + dependent on the protocol in the SA itself. An SA payload proposing + the establishment of an SA has the following mandatory and optional + transform types. A compliant implementation MUST understand all + mandatory and optional types for each protocol it supports (though it + need not accept proposals with unacceptable suites). A proposal MAY + omit the optional types if the only value for them it will accept is + NONE. + + Protocol Mandatory Types Optional Types + IKE ENCR, PRF, INTEG, D-H + ESP ENCR, ESN INTEG, D-H + AH INTEG, ESN D-H + +3.3.4. Mandatory Transform IDs + + The specification of suites that MUST and SHOULD be supported for + interoperability has been removed from this document because they are + likely to change more rapidly than this document evolves. + + An important lesson learned from IKEv1 is that no system should only + implement the mandatory algorithms and expect them to be the best + choice for all customers. For example, at the time that this + document was written, many IKEv1 implementers were starting to + migrate to AES in Cipher Block Chaining (CBC) mode for Virtual + Private Network (VPN) applications. Many IPsec systems based on + IKEv2 will implement AES, additional Diffie-Hellman groups, and + additional hash algorithms, and some IPsec customers already require + these algorithms in addition to the ones listed above. + + It is likely that IANA will add additional transforms in the future, + and some users may want to use private suites, especially for IKE + where implementations should be capable of supporting different + parameters, up to certain size limits. In support of this goal, all + implementations of IKEv2 SHOULD include a management facility that + allows specification (by a user or system administrator) of Diffie- + Hellman (DH) parameters (the generator, modulus, and exponent lengths + and values) for new DH groups. Implementations SHOULD provide a + + + +Kaufman Standards Track [Page 52] + +RFC 4306 IKEv2 December 2005 + + + management interface via which these parameters and the associated + transform IDs may be entered (by a user or system administrator), to + enable negotiating such groups. + + All implementations of IKEv2 MUST include a management facility that + enables a user or system administrator to specify the suites that are + acceptable for use with IKE. Upon receipt of a payload with a set of + transform IDs, the implementation MUST compare the transmitted + transform IDs against those locally configured via the management + controls, to verify that the proposed suite is acceptable based on + local policy. The implementation MUST reject SA proposals that are + not authorized by these IKE suite controls. Note that cryptographic + suites that MUST be implemented need not be configured as acceptable + to local policy. + +3.3.5. Transform Attributes + + Each transform in a Security Association payload may include + attributes that modify or complete the specification of the + transform. These attributes are type/value pairs and are defined + below. For example, if an encryption algorithm has a variable-length + key, the key length to be used may be specified as an attribute. + Attributes can have a value with a fixed two octet length or a + variable-length value. For the latter, the attribute is encoded as + type/length/value. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !A! Attribute Type ! AF=0 Attribute Length ! + !F! ! AF=1 Attribute Value ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! AF=0 Attribute Value ! + ! AF=1 Not Transmitted ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 9: Data Attributes + + o Attribute Type (2 octets) - Unique identifier for each type of + attribute (see below). + + The most significant bit of this field is the Attribute Format + bit (AF). It indicates whether the data attributes follow the + Type/Length/Value (TLV) format or a shortened Type/Value (TV) + format. If the AF bit is zero (0), then the Data Attributes + are of the Type/Length/Value (TLV) form. If the AF bit is a + one (1), then the Data Attributes are of the Type/Value form. + + + + +Kaufman Standards Track [Page 53] + +RFC 4306 IKEv2 December 2005 + + + o Attribute Length (2 octets) - Length in octets of the Attribute + Value. When the AF bit is a one (1), the Attribute Value is + only 2 octets and the Attribute Length field is not present. + + o Attribute Value (variable length) - Value of the Attribute + associated with the Attribute Type. If the AF bit is a zero + (0), this field has a variable length defined by the Attribute + Length field. If the AF bit is a one (1), the Attribute Value + has a length of 2 octets. + + Note that only a single attribute type (Key Length) is defined, and + it is fixed length. The variable-length encoding specification is + included only for future extensions. The only algorithms defined in + this document that accept attributes are the AES-based encryption, + integrity, and pseudo-random functions, which require a single + attribute specifying key width. + + Attributes described as basic MUST NOT be encoded using the + variable-length encoding. Variable-length attributes MUST NOT be + encoded as basic even if their value can fit into two octets. NOTE: + This is a change from IKEv1, where increased flexibility may have + simplified the composer of messages but certainly complicated the + parser. + + Attribute Type Value Attribute Format + -------------------------------------------------------------- + RESERVED 0-13 Key Length (in bits) + 14 TV RESERVED 15-17 + RESERVED TO IANA 18-16383 PRIVATE USE + 16384-32767 + + Values 0-13 and 15-17 were used in a similar context in IKEv1 and + should not be assigned except to matching values. Values 18-16383 + are reserved to IANA. Values 16384-32767 are for private use among + mutually consenting parties. + + - Key Length + + When using an Encryption Algorithm that has a variable-length key, + this attribute specifies the key length in bits (MUST use network + byte order). This attribute MUST NOT be used when the specified + Encryption Algorithm uses a fixed-length key. + + + + + + + + + +Kaufman Standards Track [Page 54] + +RFC 4306 IKEv2 December 2005 + + +3.3.6. Attribute Negotiation + + During security association negotiation, initiators present offers to + responders. Responders MUST select a single complete set of + parameters from the offers (or reject all offers if none are + acceptable). If there are multiple proposals, the responder MUST + choose a single proposal number and return all of the Proposal + substructures with that Proposal number. If there are multiple + Transforms with the same type, the responder MUST choose a single + one. Any attributes of a selected transform MUST be returned + unmodified. The initiator of an exchange MUST check that the + accepted offer is consistent with one of its proposals, and if not + that response MUST be rejected. + + Negotiating Diffie-Hellman groups presents some special challenges. + SA offers include proposed attributes and a Diffie-Hellman public + number (KE) in the same message. If in the initial exchange the + initiator offers to use one of several Diffie-Hellman groups, it + SHOULD pick the one the responder is most likely to accept and + include a KE corresponding to that group. If the guess turns out to + be wrong, the responder will indicate the correct group in the + response and the initiator SHOULD pick an element of that group for + its KE value when retrying the first message. It SHOULD, however, + continue to propose its full supported set of groups in order to + prevent a man-in-the-middle downgrade attack. + + Implementation Note: + + Certain negotiable attributes can have ranges or could have + multiple acceptable values. These include the key length of a + variable key length symmetric cipher. To further interoperability + and to support upgrading endpoints independently, implementers of + this protocol SHOULD accept values that they deem to supply + greater security. For instance, if a peer is configured to accept + a variable-length cipher with a key length of X bits and is + offered that cipher with a larger key length, the implementation + SHOULD accept the offer if it supports use of the longer key. + + Support of this capability allows an implementation to express a + concept of "at least" a certain level of security -- "a key length of + _at least_ X bits for cipher Y". + + + + + + + + + + +Kaufman Standards Track [Page 55] + +RFC 4306 IKEv2 December 2005 + + +3.4. Key Exchange Payload + + The Key Exchange Payload, denoted KE in this memo, is used to + exchange Diffie-Hellman public numbers as part of a Diffie-Hellman + key exchange. The Key Exchange Payload consists of the IKE generic + payload header followed by the Diffie-Hellman public value itself. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! DH Group # ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Key Exchange Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 10: Key Exchange Payload Format + + A key exchange payload is constructed by copying one's Diffie-Hellman + public value into the "Key Exchange Data" portion of the payload. + The length of the Diffie-Hellman public value MUST be equal to the + length of the prime modulus over which the exponentiation was + performed, prepending zero bits to the value if necessary. + + The DH Group # identifies the Diffie-Hellman group in which the Key + Exchange Data was computed (see section 3.3.2). If the selected + proposal uses a different Diffie-Hellman group, the message MUST be + rejected with a Notify payload of type INVALID_KE_PAYLOAD. + + The payload type for the Key Exchange payload is thirty four (34). + +3.5. Identification Payloads + + The Identification Payloads, denoted IDi and IDr in this memo, allow + peers to assert an identity to one another. This identity may be + used for policy lookup, but does not necessarily have to match + anything in the CERT payload; both fields may be used by an + implementation to perform access control decisions. + + NOTE: In IKEv1, two ID payloads were used in each direction to hold + Traffic Selector (TS) information for data passing over the SA. In + IKEv2, this information is carried in TS payloads (see section 3.13). + + + + + + +Kaufman Standards Track [Page 56] + +RFC 4306 IKEv2 December 2005 + + + The Identification Payload consists of the IKE generic payload header + followed by identification fields as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ID Type ! RESERVED | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Identification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 11: Identification Payload Format + + o ID Type (1 octet) - Specifies the type of Identification being + used. + + o RESERVED - MUST be sent as zero; MUST be ignored on receipt. + + o Identification Data (variable length) - Value, as indicated by the + Identification Type. The length of the Identification Data is + computed from the size in the ID payload header. + + The payload types for the Identification Payload are thirty five (35) + for IDi and thirty six (36) for IDr. + + The following table lists the assigned values for the Identification + Type field, followed by a description of the Identification Data + which follows: + + ID Type Value + ------- ----- + RESERVED 0 + + ID_IPV4_ADDR 1 + + A single four (4) octet IPv4 address. + + ID_FQDN 2 + + A fully-qualified domain name string. An example of a + ID_FQDN is, "example.com". The string MUST not contain any + terminators (e.g., NULL, CR, etc.). + + + + + +Kaufman Standards Track [Page 57] + +RFC 4306 IKEv2 December 2005 + + + ID_RFC822_ADDR 3 + + A fully-qualified RFC822 email address string, An example of + a ID_RFC822_ADDR is, "jsmith@example.com". The string MUST + not contain any terminators. + + Reserved to IANA 4 + + ID_IPV6_ADDR 5 + + A single sixteen (16) octet IPv6 address. + + Reserved to IANA 6 - 8 + + ID_DER_ASN1_DN 9 + + The binary Distinguished Encoding Rules (DER) encoding of an + ASN.1 X.500 Distinguished Name [X.501]. + + ID_DER_ASN1_GN 10 + + The binary DER encoding of an ASN.1 X.500 GeneralName + [X.509]. + + ID_KEY_ID 11 + + An opaque octet stream which may be used to pass vendor- + specific information necessary to do certain proprietary + types of identification. + + Reserved to IANA 12-200 + + Reserved for private use 201-255 + + Two implementations will interoperate only if each can generate a + type of ID acceptable to the other. To assure maximum + interoperability, implementations MUST be configurable to send at + least one of ID_IPV4_ADDR, ID_FQDN, ID_RFC822_ADDR, or ID_KEY_ID, and + MUST be configurable to accept all of these types. Implementations + SHOULD be capable of generating and accepting all of these types. + IPv6-capable implementations MUST additionally be configurable to + accept ID_IPV6_ADDR. IPv6-only implementations MAY be configurable + to send only ID_IPV6_ADDR. + + + + + + + + +Kaufman Standards Track [Page 58] + +RFC 4306 IKEv2 December 2005 + + +3.6. Certificate Payload + + The Certificate Payload, denoted CERT in this memo, provides a means + to transport certificates or other authentication-related information + via IKE. Certificate payloads SHOULD be included in an exchange if + certificates are available to the sender unless the peer has + indicated an ability to retrieve this information from elsewhere + using an HTTP_CERT_LOOKUP_SUPPORTED Notify payload. Note that the + term "Certificate Payload" is somewhat misleading, because not all + authentication mechanisms use certificates and data other than + certificates may be passed in this payload. + + The Certificate Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certificate Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 12: Certificate Payload Format + + o Certificate Encoding (1 octet) - This field indicates the type + of certificate or certificate-related information contained in + the Certificate Data field. + + Certificate Encoding Value + -------------------- ----- + RESERVED 0 + PKCS #7 wrapped X.509 certificate 1 + PGP Certificate 2 + DNS Signed Key 3 + X.509 Certificate - Signature 4 + Kerberos Token 6 + Certificate Revocation List (CRL) 7 + Authority Revocation List (ARL) 8 + SPKI Certificate 9 + X.509 Certificate - Attribute 10 + Raw RSA Key 11 + Hash and URL of X.509 certificate 12 + Hash and URL of X.509 bundle 13 + RESERVED to IANA 14 - 200 + PRIVATE USE 201 - 255 + + + +Kaufman Standards Track [Page 59] + +RFC 4306 IKEv2 December 2005 + + + o Certificate Data (variable length) - Actual encoding of + certificate data. The type of certificate is indicated by the + Certificate Encoding field. + + The payload type for the Certificate Payload is thirty seven (37). + + Specific syntax is for some of the certificate type codes above is + not defined in this document. The types whose syntax is defined in + this document are: + + X.509 Certificate - Signature (4) contains a DER encoded X.509 + certificate whose public key is used to validate the sender's AUTH + payload. + + Certificate Revocation List (7) contains a DER encoded X.509 + certificate revocation list. + + Raw RSA Key (11) contains a PKCS #1 encoded RSA key (see [RSA] and + [PKCS1]). + + Hash and URL encodings (12-13) allow IKE messages to remain short + by replacing long data structures with a 20 octet SHA-1 hash (see + [SHA]) of the replaced value followed by a variable-length URL + that resolves to the DER encoded data structure itself. This + improves efficiency when the endpoints have certificate data + cached and makes IKE less subject to denial of service attacks + that become easier to mount when IKE messages are large enough to + require IP fragmentation [KPS03]. + + Use the following ASN.1 definition for an X.509 bundle: + + CertBundle + { iso(1) identified-organization(3) dod(6) internet(1) + security(5) mechanisms(5) pkix(7) id-mod(0) + id-mod-cert-bundle(34) } + + DEFINITIONS EXPLICIT TAGS ::= + BEGIN + + IMPORTS + Certificate, CertificateList + FROM PKIX1Explicit88 + { iso(1) identified-organization(3) dod(6) + internet(1) security(5) mechanisms(5) pkix(7) + id-mod(0) id-pkix1-explicit(18) } ; + + + + + + +Kaufman Standards Track [Page 60] + +RFC 4306 IKEv2 December 2005 + + + CertificateOrCRL ::= CHOICE { + cert [0] Certificate, + crl [1] CertificateList } + + CertificateBundle ::= SEQUENCE OF CertificateOrCRL + + END + + Implementations MUST be capable of being configured to send and + accept up to four X.509 certificates in support of authentication, + and also MUST be capable of being configured to send and accept the + first two Hash and URL formats (with HTTP URLs). Implementations + SHOULD be capable of being configured to send and accept Raw RSA + keys. If multiple certificates are sent, the first certificate MUST + contain the public key used to sign the AUTH payload. The other + certificates may be sent in any order. + +3.7. Certificate Request Payload + + The Certificate Request Payload, denoted CERTREQ in this memo, + provides a means to request preferred certificates via IKE and can + appear in the IKE_INIT_SA response and/or the IKE_AUTH request. + Certificate Request payloads MAY be included in an exchange when the + sender needs to get the certificate of the receiver. If multiple CAs + are trusted and the cert encoding does not allow a list, then + multiple Certificate Request payloads SHOULD be transmitted. + + The Certificate Request Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Cert Encoding ! ! + +-+-+-+-+-+-+-+-+ ! + ~ Certification Authority ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 13: Certificate Request Payload Format + + o Certificate Encoding (1 octet) - Contains an encoding of the type + or format of certificate requested. Values are listed in section + 3.6. + + + + + + +Kaufman Standards Track [Page 61] + +RFC 4306 IKEv2 December 2005 + + + o Certification Authority (variable length) - Contains an encoding + of an acceptable certification authority for the type of + certificate requested. + + The payload type for the Certificate Request Payload is thirty eight + (38). + + The Certificate Encoding field has the same values as those defined + in section 3.6. The Certification Authority field contains an + indicator of trusted authorities for this certificate type. The + Certification Authority value is a concatenated list of SHA-1 hashes + of the public keys of trusted Certification Authorities (CAs). Each + is encoded as the SHA-1 hash of the Subject Public Key Info element + (see section 4.1.2.7 of [RFC3280]) from each Trust Anchor + certificate. The twenty-octet hashes are concatenated and included + with no other formatting. + + Note that the term "Certificate Request" is somewhat misleading, in + that values other than certificates are defined in a "Certificate" + payload and requests for those values can be present in a Certificate + Request Payload. The syntax of the Certificate Request payload in + such cases is not defined in this document. + + The Certificate Request Payload is processed by inspecting the "Cert + Encoding" field to determine whether the processor has any + certificates of this type. If so, the "Certification Authority" + field is inspected to determine if the processor has any certificates + that can be validated up to one of the specified certification + authorities. This can be a chain of certificates. + + If an end-entity certificate exists that satisfies the criteria + specified in the CERTREQ, a certificate or certificate chain SHOULD + be sent back to the certificate requestor if the recipient of the + CERTREQ: + + - is configured to use certificate authentication, + + - is allowed to send a CERT payload, + + - has matching CA trust policy governing the current negotiation, and + + - has at least one time-wise and usage appropriate end-entity + certificate chaining to a CA provided in the CERTREQ. + + Certificate revocation checking must be considered during the + chaining process used to select a certificate. Note that even if two + peers are configured to use two different CAs, cross-certification + relationships should be supported by appropriate selection logic. + + + +Kaufman Standards Track [Page 62] + +RFC 4306 IKEv2 December 2005 + + + The intent is not to prevent communication through the strict + adherence of selection of a certificate based on CERTREQ, when an + alternate certificate could be selected by the sender that would + still enable the recipient to successfully validate and trust it + through trust conveyed by cross-certification, CRLs, or other out- + of-band configured means. Thus, the processing of a CERTREQ should + be seen as a suggestion for a certificate to select, not a mandated + one. If no certificates exist, then the CERTREQ is ignored. This is + not an error condition of the protocol. There may be cases where + there is a preferred CA sent in the CERTREQ, but an alternate might + be acceptable (perhaps after prompting a human operator). + +3.8. Authentication Payload + + The Authentication Payload, denoted AUTH in this memo, contains data + used for authentication purposes. The syntax of the Authentication + data varies according to the Auth Method as specified below. + + The Authentication Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Auth Method ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Authentication Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 14: Authentication Payload Format + + o Auth Method (1 octet) - Specifies the method of authentication + used. Values defined are: + + RSA Digital Signature (1) - Computed as specified in section + 2.15 using an RSA private key over a PKCS#1 padded hash (see + [RSA] and [PKCS1]). + + Shared Key Message Integrity Code (2) - Computed as specified in + section 2.15 using the shared key associated with the identity + in the ID payload and the negotiated prf function + + DSS Digital Signature (3) - Computed as specified in section + 2.15 using a DSS private key (see [DSS]) over a SHA-1 hash. + + + + +Kaufman Standards Track [Page 63] + +RFC 4306 IKEv2 December 2005 + + + The values 0 and 4-200 are reserved to IANA. The values 201-255 + are available for private use. + + o Authentication Data (variable length) - see section 2.15. + + The payload type for the Authentication Payload is thirty nine (39). + +3.9. Nonce Payload + + The Nonce Payload, denoted Ni and Nr in this memo for the initiator's + and responder's nonce respectively, contains random data used to + guarantee liveness during an exchange and protect against replay + attacks. + + The Nonce Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Nonce Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 15: Nonce Payload Format + + o Nonce Data (variable length) - Contains the random data generated + by the transmitting entity. + + The payload type for the Nonce Payload is forty (40). + + The size of a Nonce MUST be between 16 and 256 octets inclusive. + Nonce values MUST NOT be reused. + +3.10. Notify Payload + + The Notify Payload, denoted N in this document, is used to transmit + informational data, such as error conditions and state transitions, + to an IKE peer. A Notify Payload may appear in a response message + (usually specifying why a request was rejected), in an INFORMATIONAL + Exchange (to report an error not in an IKE request), or in any other + message to indicate sender capabilities or to modify the meaning of + the request. + + + + + + +Kaufman Standards Track [Page 64] + +RFC 4306 IKEv2 December 2005 + + + The Notify Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! Notify Message Type ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Notification Data ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 16: Notify Payload Format + + o Protocol ID (1 octet) - If this notification concerns an existing + SA, this field indicates the type of that SA. For IKE_SA + notifications, this field MUST be one (1). For notifications + concerning IPsec SAs this field MUST contain either (2) to + indicate AH or (3) to indicate ESP. For notifications that do not + relate to an existing SA, this field MUST be sent as zero and MUST + be ignored on receipt. All other values for this field are + reserved to IANA for future assignment. + + o SPI Size (1 octet) - Length in octets of the SPI as defined by the + IPsec protocol ID or zero if no SPI is applicable. For a + notification concerning the IKE_SA, the SPI Size MUST be zero. + + o Notify Message Type (2 octets) - Specifies the type of + notification message. + + o SPI (variable length) - Security Parameter Index. + + o Notification Data (variable length) - Informational or error data + transmitted in addition to the Notify Message Type. Values for + this field are type specific (see below). + + The payload type for the Notify Payload is forty one (41). + + + + + + + + +Kaufman Standards Track [Page 65] + +RFC 4306 IKEv2 December 2005 + + +3.10.1. Notify Message Types + + Notification information can be error messages specifying why an SA + could not be established. It can also be status data that a process + managing an SA database wishes to communicate with a peer process. + The table below lists the Notification messages and their + corresponding values. The number of different error statuses was + greatly reduced from IKEv1 both for simplification and to avoid + giving configuration information to probers. + + Types in the range 0 - 16383 are intended for reporting errors. An + implementation receiving a Notify payload with one of these types + that it does not recognize in a response MUST assume that the + corresponding request has failed entirely. Unrecognized error types + in a request and status types in a request or response MUST be + ignored except that they SHOULD be logged. + + Notify payloads with status types MAY be added to any message and + MUST be ignored if not recognized. They are intended to indicate + capabilities, and as part of SA negotiation are used to negotiate + non-cryptographic parameters. + + NOTIFY MESSAGES - ERROR TYPES Value + ----------------------------- ----- + RESERVED 0 + + UNSUPPORTED_CRITICAL_PAYLOAD 1 + + Sent if the payload has the "critical" bit set and the + payload type is not recognized. Notification Data contains + the one-octet payload type. + + INVALID_IKE_SPI 4 + + Indicates an IKE message was received with an unrecognized + destination SPI. This usually indicates that the recipient + has rebooted and forgotten the existence of an IKE_SA. + + INVALID_MAJOR_VERSION 5 + + Indicates the recipient cannot handle the version of IKE + specified in the header. The closest version number that + the recipient can support will be in the reply header. + + INVALID_SYNTAX 7 + + Indicates the IKE message that was received was invalid + because some type, length, or value was out of range or + + + +Kaufman Standards Track [Page 66] + +RFC 4306 IKEv2 December 2005 + + + because the request was rejected for policy reasons. To + avoid a denial of service attack using forged messages, this + status may only be returned for and in an encrypted packet + if the message ID and cryptographic checksum were valid. To + avoid leaking information to someone probing a node, this + status MUST be sent in response to any error not covered by + one of the other status types. To aid debugging, more + detailed error information SHOULD be written to a console or + log. + + INVALID_MESSAGE_ID 9 + + Sent when an IKE message ID outside the supported window is + received. This Notify MUST NOT be sent in a response; the + invalid request MUST NOT be acknowledged. Instead, inform + the other side by initiating an INFORMATIONAL exchange with + Notification data containing the four octet invalid message + ID. Sending this notification is optional, and + notifications of this type MUST be rate limited. + + INVALID_SPI 11 + + MAY be sent in an IKE INFORMATIONAL exchange when a node + receives an ESP or AH packet with an invalid SPI. The + Notification Data contains the SPI of the invalid packet. + This usually indicates a node has rebooted and forgotten an + SA. If this Informational Message is sent outside the + context of an IKE_SA, it should be used by the recipient + only as a "hint" that something might be wrong (because it + could easily be forged). + + NO_PROPOSAL_CHOSEN 14 + + None of the proposed crypto suites was acceptable. + + INVALID_KE_PAYLOAD 17 + + The D-H Group # field in the KE payload is not the group # + selected by the responder for this exchange. There are two + octets of data associated with this notification: the + accepted D-H Group # in big endian order. + + AUTHENTICATION_FAILED 24 + + Sent in the response to an IKE_AUTH message when for some + reason the authentication failed. There is no associated + data. + + + + +Kaufman Standards Track [Page 67] + +RFC 4306 IKEv2 December 2005 + + + SINGLE_PAIR_REQUIRED 34 + + This error indicates that a CREATE_CHILD_SA request is + unacceptable because its sender is only willing to accept + traffic selectors specifying a single pair of addresses. The + requestor is expected to respond by requesting an SA for only + the specific traffic it is trying to forward. + + NO_ADDITIONAL_SAS 35 + + This error indicates that a CREATE_CHILD_SA request is + unacceptable because the responder is unwilling to accept any + more CHILD_SAs on this IKE_SA. Some minimal implementations may + only accept a single CHILD_SA setup in the context of an initial + IKE exchange and reject any subsequent attempts to add more. + + INTERNAL_ADDRESS_FAILURE 36 + + Indicates an error assigning an internal address (i.e., + INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS) during the + processing of a Configuration Payload by a responder. If this + error is generated within an IKE_AUTH exchange, no CHILD_SA will + be created. + + FAILED_CP_REQUIRED 37 + + Sent by responder in the case where CP(CFG_REQUEST) was expected + but not received, and so is a conflict with locally configured + policy. There is no associated data. + + TS_UNACCEPTABLE 38 + + Indicates that none of the addresses/protocols/ports in the + supplied traffic selectors is acceptable. + + INVALID_SELECTORS 39 + + MAY be sent in an IKE INFORMATIONAL exchange when a node + receives an ESP or AH packet whose selectors do not match + those of the SA on which it was delivered (and that caused + the packet to be dropped). The Notification Data contains + the start of the offending packet (as in ICMP messages) and + the SPI field of the notification is set to match the SPI of + the IPsec SA. + + RESERVED TO IANA - Error types 40 - 8191 + + Private Use - Errors 8192 - 16383 + + + +Kaufman Standards Track [Page 68] + +RFC 4306 IKEv2 December 2005 + + + NOTIFY MESSAGES - STATUS TYPES Value + ------------------------------ ----- + + INITIAL_CONTACT 16384 + + This notification asserts that this IKE_SA is the only + IKE_SA currently active between the authenticated + identities. It MAY be sent when an IKE_SA is established + after a crash, and the recipient MAY use this information to + delete any other IKE_SAs it has to the same authenticated + identity without waiting for a timeout. This notification + MUST NOT be sent by an entity that may be replicated (e.g., + a roaming user's credentials where the user is allowed to + connect to the corporate firewall from two remote systems at + the same time). + + SET_WINDOW_SIZE 16385 + + This notification asserts that the sending endpoint is + capable of keeping state for multiple outstanding exchanges, + permitting the recipient to send multiple requests before + getting a response to the first. The data associated with a + SET_WINDOW_SIZE notification MUST be 4 octets long and + contain the big endian representation of the number of + messages the sender promises to keep. Window size is always + one until the initial exchanges complete. + + ADDITIONAL_TS_POSSIBLE 16386 + + This notification asserts that the sending endpoint narrowed + the proposed traffic selectors but that other traffic + selectors would also have been acceptable, though only in a + separate SA (see section 2.9). There is no data associated + with this Notify type. It may be sent only as an additional + payload in a message including accepted TSs. + + IPCOMP_SUPPORTED 16387 + + This notification may be included only in a message + containing an SA payload negotiating a CHILD_SA and + indicates a willingness by its sender to use IPComp on this + SA. The data associated with this notification includes a + two-octet IPComp CPI followed by a one-octet transform ID + optionally followed by attributes whose length and format + are defined by that transform ID. A message proposing an SA + may contain multiple IPCOMP_SUPPORTED notifications to + indicate multiple supported algorithms. A message accepting + an SA may contain at most one. + + + +Kaufman Standards Track [Page 69] + +RFC 4306 IKEv2 December 2005 + + + The transform IDs currently defined are: + + NAME NUMBER DEFINED IN + ----------- ------ ----------- + RESERVED 0 + IPCOMP_OUI 1 + IPCOMP_DEFLATE 2 RFC 2394 + IPCOMP_LZS 3 RFC 2395 + IPCOMP_LZJH 4 RFC 3051 + + values 5-240 are reserved to IANA. Values 241-255 are + for private use among mutually consenting parties. + + NAT_DETECTION_SOURCE_IP 16388 + + This notification is used by its recipient to determine + whether the source is behind a NAT box. The data associated + with this notification is a SHA-1 digest of the SPIs (in the + order they appear in the header), IP address, and port on + which this packet was sent. There MAY be multiple Notify + payloads of this type in a message if the sender does not + know which of several network attachments will be used to + send the packet. The recipient of this notification MAY + compare the supplied value to a SHA-1 hash of the SPIs, + source IP address, and port, and if they don't match it + SHOULD enable NAT traversal (see section 2.23). + Alternately, it MAY reject the connection attempt if NAT + traversal is not supported. + + NAT_DETECTION_DESTINATION_IP 16389 + + This notification is used by its recipient to determine + whether it is behind a NAT box. The data associated with + this notification is a SHA-1 digest of the SPIs (in the + order they appear in the header), IP address, and port to + which this packet was sent. The recipient of this + notification MAY compare the supplied value to a hash of the + SPIs, destination IP address, and port, and if they don't + match it SHOULD invoke NAT traversal (see section 2.23). If + they don't match, it means that this end is behind a NAT and + this end SHOULD start sending keepalive packets as defined + in [Hutt05]. Alternately, it MAY reject the connection + attempt if NAT traversal is not supported. + + + + + + + + +Kaufman Standards Track [Page 70] + +RFC 4306 IKEv2 December 2005 + + + COOKIE 16390 + + This notification MAY be included in an IKE_SA_INIT + response. It indicates that the request should be retried + with a copy of this notification as the first payload. This + notification MUST be included in an IKE_SA_INIT request + retry if a COOKIE notification was included in the initial + response. The data associated with this notification MUST + be between 1 and 64 octets in length (inclusive). + + USE_TRANSPORT_MODE 16391 + + This notification MAY be included in a request message that + also includes an SA payload requesting a CHILD_SA. It + requests that the CHILD_SA use transport mode rather than + tunnel mode for the SA created. If the request is accepted, + the response MUST also include a notification of type + USE_TRANSPORT_MODE. If the responder declines the request, + the CHILD_SA will be established in tunnel mode. If this is + unacceptable to the initiator, the initiator MUST delete the + SA. Note: Except when using this option to negotiate + transport mode, all CHILD_SAs will use tunnel mode. + + Note: The ECN decapsulation modifications specified in + [RFC4301] MUST be performed for every tunnel mode SA created + by IKEv2. + + HTTP_CERT_LOOKUP_SUPPORTED 16392 + + This notification MAY be included in any message that can + include a CERTREQ payload and indicates that the sender is + capable of looking up certificates based on an HTTP-based + URL (and hence presumably would prefer to receive + certificate specifications in that format). + + REKEY_SA 16393 + + This notification MUST be included in a CREATE_CHILD_SA + exchange if the purpose of the exchange is to replace an + existing ESP or AH SA. The SPI field identifies the SA + being rekeyed. There is no data. + + ESP_TFC_PADDING_NOT_SUPPORTED 16394 + + This notification asserts that the sending endpoint will NOT + accept packets that contain Flow Confidentiality (TFC) + padding. + + + + +Kaufman Standards Track [Page 71] + +RFC 4306 IKEv2 December 2005 + + + NON_FIRST_FRAGMENTS_ALSO 16395 + + Used for fragmentation control. See [RFC4301] for + explanation. + + RESERVED TO IANA - STATUS TYPES 16396 - 40959 + + Private Use - STATUS TYPES 40960 - 65535 + +3.11. Delete Payload + + The Delete Payload, denoted D in this memo, contains a protocol- + specific security association identifier that the sender has removed + from its security association database and is, therefore, no longer + valid. Figure 17 shows the format of the Delete Payload. It is + possible to send multiple SPIs in a Delete payload; however, each SPI + MUST be for the same protocol. Mixing of protocol identifiers MUST + NOT be performed in a Delete payload. It is permitted, however, to + include multiple Delete payloads in a single INFORMATIONAL exchange + where each Delete payload lists SPIs for a different protocol. + + Deletion of the IKE_SA is indicated by a protocol ID of 1 (IKE) but + no SPIs. Deletion of a CHILD_SA, such as ESP or AH, will contain the + IPsec protocol ID of that protocol (2 for AH, 3 for ESP), and the SPI + is the SPI the sending endpoint would expect in inbound ESP or AH + packets. + + The Delete Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Protocol ID ! SPI Size ! # of SPIs ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Security Parameter Index(es) (SPI) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 17: Delete Payload Format + + o Protocol ID (1 octet) - Must be 1 for an IKE_SA, 2 for AH, or 3 + for ESP. + + + + + + +Kaufman Standards Track [Page 72] + +RFC 4306 IKEv2 December 2005 + + + o SPI Size (1 octet) - Length in octets of the SPI as defined by the + protocol ID. It MUST be zero for IKE (SPI is in message header) + or four for AH and ESP. + + o # of SPIs (2 octets) - The number of SPIs contained in the Delete + payload. The size of each SPI is defined by the SPI Size field. + + o Security Parameter Index(es) (variable length) - Identifies the + specific security association(s) to delete. The length of this + field is determined by the SPI Size and # of SPIs fields. + + The payload type for the Delete Payload is forty two (42). + +3.12. Vendor ID Payload + + The Vendor ID Payload, denoted V in this memo, contains a vendor + defined constant. The constant is used by vendors to identify and + recognize remote instances of their implementations. This mechanism + allows a vendor to experiment with new features while maintaining + backward compatibility. + + A Vendor ID payload MAY announce that the sender is capable to + accepting certain extensions to the protocol, or it MAY simply + identify the implementation as an aid in debugging. A Vendor ID + payload MUST NOT change the interpretation of any information defined + in this specification (i.e., the critical bit MUST be set to 0). + Multiple Vendor ID payloads MAY be sent. An implementation is NOT + REQUIRED to send any Vendor ID payload at all. + + A Vendor ID payload may be sent as part of any message. Reception of + a familiar Vendor ID payload allows an implementation to make use of + Private USE numbers described throughout this memo -- private + payloads, private exchanges, private notifications, etc. Unfamiliar + Vendor IDs MUST be ignored. + + Writers of Internet-Drafts who wish to extend this protocol MUST + define a Vendor ID payload to announce the ability to implement the + extension in the Internet-Draft. It is expected that Internet-Drafts + that gain acceptance and are standardized will be given "magic + numbers" out of the Future Use range by IANA, and the requirement to + use a Vendor ID will go away. + + + + + + + + + + +Kaufman Standards Track [Page 73] + +RFC 4306 IKEv2 December 2005 + + + The Vendor ID Payload fields are defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Vendor ID (VID) ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 18: Vendor ID Payload Format + + o Vendor ID (variable length) - It is the responsibility of the + person choosing the Vendor ID to assure its uniqueness in spite of + the absence of any central registry for IDs. Good practice is to + include a company name, a person name, or some such. If you want + to show off, you might include the latitude and longitude and time + where you were when you chose the ID and some random input. A + message digest of a long unique string is preferable to the long + unique string itself. + + The payload type for the Vendor ID Payload is forty three (43). + +3.13. Traffic Selector Payload + + The Traffic Selector Payload, denoted TS in this memo, allows peers + to identify packet flows for processing by IPsec security services. + The Traffic Selector Payload consists of the IKE generic payload + header followed by individual traffic selectors as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Number of TSs ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 19: Traffic Selectors Payload Format + + o Number of TSs (1 octet) - Number of traffic selectors being + provided. + + + +Kaufman Standards Track [Page 74] + +RFC 4306 IKEv2 December 2005 + + + o RESERVED - This field MUST be sent as zero and MUST be ignored on + receipt. + + o Traffic Selectors (variable length) - One or more individual + traffic selectors. + + The length of the Traffic Selector payload includes the TS header and + all the traffic selectors. + + The payload type for the Traffic Selector payload is forty four (44) + for addresses at the initiator's end of the SA and forty five (45) + for addresses at the responder's end. + +3.13.1. Traffic Selector + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! TS Type !IP Protocol ID*| Selector Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | Start Port* | End Port* | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Starting Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Ending Address* ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 20: Traffic Selector + + * Note: All fields other than TS Type and Selector Length depend on + the TS Type. The fields shown are for TS Types 7 and 8, the only two + values currently defined. + + o TS Type (one octet) - Specifies the type of traffic selector. + + o IP protocol ID (1 octet) - Value specifying an associated IP + protocol ID (e.g., UDP/TCP/ICMP). A value of zero means that the + protocol ID is not relevant to this traffic selector -- the SA can + carry all protocols. + + o Selector Length - Specifies the length of this Traffic Selector + Substructure including the header. + + + + + +Kaufman Standards Track [Page 75] + +RFC 4306 IKEv2 December 2005 + + + o Start Port (2 octets) - Value specifying the smallest port number + allowed by this Traffic Selector. For protocols for which port is + undefined, or if all ports are allowed, this field MUST be zero. + For the ICMP protocol, the two one-octet fields Type and Code are + treated as a single 16-bit integer (with Type in the most + significant eight bits and Code in the least significant eight + bits) port number for the purposes of filtering based on this + field. + + o End Port (2 octets) - Value specifying the largest port number + allowed by this Traffic Selector. For protocols for which port is + undefined, or if all ports are allowed, this field MUST be 65535. + For the ICMP protocol, the two one-octet fields Type and Code are + treated as a single 16-bit integer (with Type in the most + significant eight bits and Code in the least significant eight + bits) port number for the purposed of filtering based on this + field. + + o Starting Address - The smallest address included in this Traffic + Selector (length determined by TS type). + + o Ending Address - The largest address included in this Traffic + Selector (length determined by TS type). + + Systems that are complying with [RFC4301] that wish to indicate "ANY" + ports MUST set the start port to 0 and the end port to 65535; note + that according to [RFC4301], "ANY" includes "OPAQUE". Systems + working with [RFC4301] that wish to indicate "OPAQUE" ports, but not + "ANY" ports, MUST set the start port to 65535 and the end port to 0. + + The following table lists the assigned values for the Traffic + Selector Type field and the corresponding Address Selector Data. + + TS Type Value + ------- ----- + RESERVED 0-6 + + TS_IPV4_ADDR_RANGE 7 + + A range of IPv4 addresses, represented by two four-octet + values. The first value is the beginning IPv4 address + (inclusive) and the second value is the ending IPv4 address + (inclusive). All addresses falling between the two + specified addresses are considered to be within the list. + + + + + + + +Kaufman Standards Track [Page 76] + +RFC 4306 IKEv2 December 2005 + + + TS_IPV6_ADDR_RANGE 8 + + A range of IPv6 addresses, represented by two sixteen-octet + values. The first value is the beginning IPv6 address + (inclusive) and the second value is the ending IPv6 address + (inclusive). All addresses falling between the two + specified addresses are considered to be within the list. + + RESERVED TO IANA 9-240 + PRIVATE USE 241-255 + +3.14. Encrypted Payload + + The Encrypted Payload, denoted SK{...} or E in this memo, contains + other payloads in encrypted form. The Encrypted Payload, if present + in a message, MUST be the last payload in the message. Often, it is + the only payload in the message. + + The algorithms for encryption and integrity protection are negotiated + during IKE_SA setup, and the keys are computed as specified in + sections 2.14 and 2.18. + + The encryption and integrity protection algorithms are modeled after + the ESP algorithms described in RFCs 2104 [KBC96], 4303 [RFC4303], + and 2451 [ESPCBC]. This document completely specifies the + cryptographic processing of IKE data, but those documents should be + consulted for design rationale. We require a block cipher with a + fixed block size and an integrity check algorithm that computes a + fixed-length checksum over a variable size message. + + The payload type for an Encrypted payload is forty six (46). The + Encrypted Payload consists of the IKE generic payload header followed + by individual fields as follows: + + + + + + + + + + + + + + + + + + +Kaufman Standards Track [Page 77] + +RFC 4306 IKEv2 December 2005 + + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Initialization Vector ! + ! (length is block size for encryption algorithm) ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Encrypted IKE Payloads ~ + + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! Padding (0-255 octets) ! + +-+-+-+-+-+-+-+-+ +-+-+-+-+-+-+-+-+ + ! ! Pad Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ~ Integrity Checksum Data ~ + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 21: Encrypted Payload Format + + o Next Payload - The payload type of the first embedded payload. + Note that this is an exception in the standard header format, + since the Encrypted payload is the last payload in the message and + therefore the Next Payload field would normally be zero. But + because the content of this payload is embedded payloads and there + was no natural place to put the type of the first one, that type + is placed here. + + o Payload Length - Includes the lengths of the header, IV, Encrypted + IKE Payloads, Padding, Pad Length, and Integrity Checksum Data. + + o Initialization Vector - A randomly chosen value whose length is + equal to the block length of the underlying encryption algorithm. + Recipients MUST accept any value. Senders SHOULD either pick this + value pseudo-randomly and independently for each message or use + the final ciphertext block of the previous message sent. Senders + MUST NOT use the same value for each message, use a sequence of + values with low hamming distance (e.g., a sequence number), or use + ciphertext from a received message. + + o IKE Payloads are as specified earlier in this section. This field + is encrypted with the negotiated cipher. + + o Padding MAY contain any value chosen by the sender, and MUST have + a length that makes the combination of the Payloads, the Padding, + and the Pad Length to be a multiple of the encryption block size. + This field is encrypted with the negotiated cipher. + + + + + +Kaufman Standards Track [Page 78] + +RFC 4306 IKEv2 December 2005 + + + o Pad Length is the length of the Padding field. The sender SHOULD + set the Pad Length to the minimum value that makes the combination + of the Payloads, the Padding, and the Pad Length a multiple of the + block size, but the recipient MUST accept any length that results + in proper alignment. This field is encrypted with the negotiated + cipher. + + o Integrity Checksum Data is the cryptographic checksum of the + entire message starting with the Fixed IKE Header through the Pad + Length. The checksum MUST be computed over the encrypted message. + Its length is determined by the integrity algorithm negotiated. + +3.15. Configuration Payload + + The Configuration payload, denoted CP in this document, is used to + exchange configuration information between IKE peers. The exchange + is for an IRAC to request an internal IP address from an IRAS and to + exchange other information of the sort that one would acquire with + Dynamic Host Configuration Protocol (DHCP) if the IRAC were directly + connected to a LAN. + + Configuration payloads are of type CFG_REQUEST/CFG_REPLY or + CFG_SET/CFG_ACK (see CFG Type in the payload description below). + CFG_REQUEST and CFG_SET payloads may optionally be added to any IKE + request. The IKE response MUST include either a corresponding + CFG_REPLY or CFG_ACK or a Notify payload with an error type + indicating why the request could not be honored. An exception is + that a minimal implementation MAY ignore all CFG_REQUEST and CFG_SET + payloads, so a response message without a corresponding CFG_REPLY or + CFG_ACK MUST be accepted as an indication that the request was not + supported. + + "CFG_REQUEST/CFG_REPLY" allows an IKE endpoint to request information + from its peer. If an attribute in the CFG_REQUEST Configuration + Payload is not zero-length, it is taken as a suggestion for that + attribute. The CFG_REPLY Configuration Payload MAY return that + value, or a new one. It MAY also add new attributes and not include + some requested ones. Requestors MUST ignore returned attributes that + they do not recognize. + + Some attributes MAY be multi-valued, in which case multiple attribute + values of the same type are sent and/or returned. Generally, all + values of an attribute are returned when the attribute is requested. + For some attributes (in this version of the specification only + internal addresses), multiple requests indicates a request that + multiple values be assigned. For these attributes, the number of + values returned SHOULD NOT exceed the number requested. + + + + +Kaufman Standards Track [Page 79] + +RFC 4306 IKEv2 December 2005 + + + If the data type requested in a CFG_REQUEST is not recognized or not + supported, the responder MUST NOT return an error type but rather + MUST either send a CFG_REPLY that MAY be empty or a reply not + containing a CFG_REPLY payload at all. Error returns are reserved + for cases where the request is recognized but cannot be performed as + requested or the request is badly formatted. + + "CFG_SET/CFG_ACK" allows an IKE endpoint to push configuration data + to its peer. In this case, the CFG_SET Configuration Payload + contains attributes the initiator wants its peer to alter. The + responder MUST return a Configuration Payload if it accepted any of + the configuration data and it MUST contain the attributes that the + responder accepted with zero-length data. Those attributes that it + did not accept MUST NOT be in the CFG_ACK Configuration Payload. If + no attributes were accepted, the responder MUST return either an + empty CFG_ACK payload or a response message without a CFG_ACK + payload. There are currently no defined uses for the CFG_SET/CFG_ACK + exchange, though they may be used in connection with extensions based + on Vendor IDs. An minimal implementation of this specification MAY + ignore CFG_SET payloads. + + Extensions via the CP payload SHOULD NOT be used for general purpose + management. Its main intent is to provide a bootstrap mechanism to + exchange information within IPsec from IRAS to IRAC. While it MAY be + useful to use such a method to exchange information between some + Security Gateways (SGW) or small networks, existing management + protocols such as DHCP [DHCP], RADIUS [RADIUS], SNMP, or LDAP [LDAP] + should be preferred for enterprise management as well as subsequent + information exchanges. + + The Configuration Payload is defined as follows: + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! CFG Type ! RESERVED ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ Configuration Attributes ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 22: Configuration Payload Format + + The payload type for the Configuration Payload is forty seven (47). + + + + +Kaufman Standards Track [Page 80] + +RFC 4306 IKEv2 December 2005 + + + o CFG Type (1 octet) - The type of exchange represented by the + Configuration Attributes. + + CFG Type Value + =========== ===== + RESERVED 0 + CFG_REQUEST 1 + CFG_REPLY 2 + CFG_SET 3 + CFG_ACK 4 + + values 5-127 are reserved to IANA. Values 128-255 are for private + use among mutually consenting parties. + + o RESERVED (3 octets) - MUST be sent as zero; MUST be ignored on + receipt. + + o Configuration Attributes (variable length) - These are type length + values specific to the Configuration Payload and are defined + below. There may be zero or more Configuration Attributes in this + payload. + +3.15.1. Configuration Attributes + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + !R| Attribute Type ! Length | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + | | + ~ Value ~ + | | + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 23: Configuration Attribute Format + + o Reserved (1 bit) - This bit MUST be set to zero and MUST be + ignored on receipt. + + o Attribute Type (15 bits) - A unique identifier for each of the + Configuration Attribute Types. + + o Length (2 octets) - Length in octets of Value. + + o Value (0 or more octets) - The variable-length value of this + Configuration Attribute. + + + + + +Kaufman Standards Track [Page 81] + +RFC 4306 IKEv2 December 2005 + + + The following attribute types have been defined: + + Multi- + Attribute Type Value Valued Length + ======================= ===== ====== ================== + RESERVED 0 + INTERNAL_IP4_ADDRESS 1 YES* 0 or 4 octets + INTERNAL_IP4_NETMASK 2 NO 0 or 4 octets + INTERNAL_IP4_DNS 3 YES 0 or 4 octets + INTERNAL_IP4_NBNS 4 YES 0 or 4 octets + INTERNAL_ADDRESS_EXPIRY 5 NO 0 or 4 octets + INTERNAL_IP4_DHCP 6 YES 0 or 4 octets + APPLICATION_VERSION 7 NO 0 or more + INTERNAL_IP6_ADDRESS 8 YES* 0 or 17 octets + RESERVED 9 + INTERNAL_IP6_DNS 10 YES 0 or 16 octets + INTERNAL_IP6_NBNS 11 YES 0 or 16 octets + INTERNAL_IP6_DHCP 12 YES 0 or 16 octets + INTERNAL_IP4_SUBNET 13 YES 0 or 8 octets + SUPPORTED_ATTRIBUTES 14 NO Multiple of 2 + INTERNAL_IP6_SUBNET 15 YES 17 octets + + * These attributes may be multi-valued on return only if multiple + values were requested. + + Types 16-16383 are reserved to IANA. Values 16384-32767 are for + private use among mutually consenting parties. + + o INTERNAL_IP4_ADDRESS, INTERNAL_IP6_ADDRESS - An address on the + internal network, sometimes called a red node address or + private address and MAY be a private address on the Internet. + In a request message, the address specified is a requested + address (or zero if no specific address is requested). If a + specific address is requested, it likely indicates that a + previous connection existed with this address and the requestor + would like to reuse that address. With IPv6, a requestor MAY + supply the low-order address bytes it wants to use. Multiple + internal addresses MAY be requested by requesting multiple + internal address attributes. The responder MAY only send up to + the number of addresses requested. The INTERNAL_IP6_ADDRESS is + made up of two fields: the first is a sixteen-octet IPv6 + address and the second is a one-octet prefix-length as defined + in [ADDRIPV6]. + + The requested address is valid until the expiry time defined + with the INTERNAL_ADDRESS EXPIRY attribute or there are no + IKE_SAs between the peers. + + + + +Kaufman Standards Track [Page 82] + +RFC 4306 IKEv2 December 2005 + + + o INTERNAL_IP4_NETMASK - The internal network's netmask. Only + one netmask is allowed in the request and reply messages (e.g., + 255.255.255.0), and it MUST be used only with an + INTERNAL_IP4_ADDRESS attribute. + + o INTERNAL_IP4_DNS, INTERNAL_IP6_DNS - Specifies an address of a + DNS server within the network. Multiple DNS servers MAY be + requested. The responder MAY respond with zero or more DNS + server attributes. + + o INTERNAL_IP4_NBNS, INTERNAL_IP6_NBNS - Specifies an address of + a NetBios Name Server (WINS) within the network. Multiple NBNS + servers MAY be requested. The responder MAY respond with zero + or more NBNS server attributes. + + o INTERNAL_ADDRESS_EXPIRY - Specifies the number of seconds that + the host can use the internal IP address. The host MUST renew + the IP address before this expiry time. Only one of these + attributes MAY be present in the reply. + + o INTERNAL_IP4_DHCP, INTERNAL_IP6_DHCP - Instructs the host to + send any internal DHCP requests to the address contained within + the attribute. Multiple DHCP servers MAY be requested. The + responder MAY respond with zero or more DHCP server attributes. + + o APPLICATION_VERSION - The version or application information of + the IPsec host. This is a string of printable ASCII characters + that is NOT null terminated. + + o INTERNAL_IP4_SUBNET - The protected sub-networks that this + edge-device protects. This attribute is made up of two fields: + the first is an IP address and the second is a netmask. + Multiple sub-networks MAY be requested. The responder MAY + respond with zero or more sub-network attributes. + + o SUPPORTED_ATTRIBUTES - When used within a Request, this + attribute MUST be zero-length and specifies a query to the + responder to reply back with all of the attributes that it + supports. The response contains an attribute that contains a + set of attribute identifiers each in 2 octets. The length + divided by 2 (octets) would state the number of supported + attributes contained in the response. + + + + + + + + + +Kaufman Standards Track [Page 83] + +RFC 4306 IKEv2 December 2005 + + + o INTERNAL_IP6_SUBNET - The protected sub-networks that this + edge-device protects. This attribute is made up of two fields: + the first is a sixteen-octet IPv6 address and the second is a + one-octet prefix-length as defined in [ADDRIPV6]. Multiple + sub-networks MAY be requested. The responder MAY respond with + zero or more sub-network attributes. + + Note that no recommendations are made in this document as to how + an implementation actually figures out what information to send in + a reply. That is, we do not recommend any specific method of an + IRAS determining which DNS server should be returned to a + requesting IRAC. + +3.16. Extensible Authentication Protocol (EAP) Payload + + The Extensible Authentication Protocol Payload, denoted EAP in this + memo, allows IKE_SAs to be authenticated using the protocol defined + in RFC 3748 [EAP] and subsequent extensions to that protocol. The + full set of acceptable values for the payload is defined elsewhere, + but a short summary of RFC 3748 is included here to make this + document stand alone in the common cases. + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Next Payload !C! RESERVED ! Payload Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! ! + ~ EAP Message ~ + ! ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + + Figure 24: EAP Payload Format + + The payload type for an EAP Payload is forty eight (48). + + 1 2 3 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Code ! Identifier ! Length ! + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ + ! Type ! Type_Data... + +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+- + + Figure 25: EAP Message Format + + o Code (1 octet) indicates whether this message is a Request (1), + Response (2), Success (3), or Failure (4). + + + +Kaufman Standards Track [Page 84] + +RFC 4306 IKEv2 December 2005 + + + o Identifier (1 octet) is used in PPP to distinguish replayed + messages from repeated ones. Since in IKE, EAP runs over a + reliable protocol, it serves no function here. In a response + message, this octet MUST be set to match the identifier in the + corresponding request. In other messages, this field MAY be set + to any value. + + o Length (2 octets) is the length of the EAP message and MUST be + four less than the Payload Length of the encapsulating payload. + + o Type (1 octet) is present only if the Code field is Request (1) or + Response (2). For other codes, the EAP message length MUST be + four octets and the Type and Type_Data fields MUST NOT be present. + In a Request (1) message, Type indicates the data being requested. + In a Response (2) message, Type MUST either be Nak or match the + type of the data requested. The following types are defined in + RFC 3748: + + 1 Identity + 2 Notification + 3 Nak (Response Only) + 4 MD5-Challenge + 5 One-Time Password (OTP) + 6 Generic Token Card + + o Type_Data (Variable Length) varies with the Type of Request and + the associated Response. For the documentation of the EAP + methods, see [EAP]. + + Note that since IKE passes an indication of initiator identity in + message 3 of the protocol, the responder SHOULD NOT send EAP Identity + requests. The initiator SHOULD, however, respond to such requests if + it receives them. + +4. Conformance Requirements + + In order to assure that all implementations of IKEv2 can + interoperate, there are "MUST support" requirements in addition to + those listed elsewhere. Of course, IKEv2 is a security protocol, and + one of its major functions is to allow only authorized parties to + successfully complete establishment of SAs. So a particular + implementation may be configured with any of a number of restrictions + concerning algorithms and trusted authorities that will prevent + universal interoperability. + + + + + + + +Kaufman Standards Track [Page 85] + +RFC 4306 IKEv2 December 2005 + + + IKEv2 is designed to permit minimal implementations that can + interoperate with all compliant implementations. There are a series + of optional features that can easily be ignored by a particular + implementation if it does not support that feature. Those features + include: + + Ability to negotiate SAs through a NAT and tunnel the resulting + ESP SA over UDP. + + Ability to request (and respond to a request for) a temporary IP + address on the remote end of a tunnel. + + Ability to support various types of legacy authentication. + + Ability to support window sizes greater than one. + + Ability to establish multiple ESP and/or AH SAs within a single + IKE_SA. + + Ability to rekey SAs. + + To assure interoperability, all implementations MUST be capable of + parsing all payload types (if only to skip over them) and to ignore + payload types that it does not support unless the critical bit is set + in the payload header. If the critical bit is set in an unsupported + payload header, all implementations MUST reject the messages + containing those payloads. + + Every implementation MUST be capable of doing four-message + IKE_SA_INIT and IKE_AUTH exchanges establishing two SAs (one for IKE, + one for ESP and/or AH). Implementations MAY be initiate-only or + respond-only if appropriate for their platform. Every implementation + MUST be capable of responding to an INFORMATIONAL exchange, but a + minimal implementation MAY respond to any INFORMATIONAL message with + an empty INFORMATIONAL reply (note that within the context of an + IKE_SA, an "empty" message consists of an IKE header followed by an + Encrypted payload with no payloads contained in it). A minimal + implementation MAY support the CREATE_CHILD_SA exchange only in so + far as to recognize requests and reject them with a Notify payload of + type NO_ADDITIONAL_SAS. A minimal implementation need not be able to + initiate CREATE_CHILD_SA or INFORMATIONAL exchanges. When an SA + expires (based on locally configured values of either lifetime or + octets passed), and implementation MAY either try to renew it with a + CREATE_CHILD_SA exchange or it MAY delete (close) the old SA and + create a new one. If the responder rejects the CREATE_CHILD_SA + request with a NO_ADDITIONAL_SAS notification, the implementation + MUST be capable of instead closing the old SA and creating a new one. + + + + +Kaufman Standards Track [Page 86] + +RFC 4306 IKEv2 December 2005 + + + Implementations are not required to support requesting temporary IP + addresses or responding to such requests. If an implementation does + support issuing such requests, it MUST include a CP payload in + message 3 containing at least a field of type INTERNAL_IP4_ADDRESS or + INTERNAL_IP6_ADDRESS. All other fields are optional. If an + implementation supports responding to such requests, it MUST parse + the CP payload of type CFG_REQUEST in message 3 and recognize a field + of type INTERNAL_IP4_ADDRESS or INTERNAL_IP6_ADDRESS. If it supports + leasing an address of the appropriate type, it MUST return a CP + payload of type CFG_REPLY containing an address of the requested + type. The responder SHOULD include all of the other related + attributes if it has them. + + A minimal IPv4 responder implementation will ignore the contents of + the CP payload except to determine that it includes an + INTERNAL_IP4_ADDRESS attribute and will respond with the address and + other related attributes regardless of whether the initiator + requested them. + + A minimal IPv4 initiator will generate a CP payload containing only + an INTERNAL_IP4_ADDRESS attribute and will parse the response + ignoring attributes it does not know how to use. The only attribute + it MUST be able to process is INTERNAL_ADDRESS_EXPIRY, which it must + use to bound the lifetime of the SA unless it successfully renews the + lease before it expires. Minimal initiators need not be able to + request lease renewals and minimal responders need not respond to + them. + + For an implementation to be called conforming to this specification, + it MUST be possible to configure it to accept the following: + + PKIX Certificates containing and signed by RSA keys of size 1024 or + 2048 bits, where the ID passed is any of ID_KEY_ID, ID_FQDN, + ID_RFC822_ADDR, or ID_DER_ASN1_DN. + + Shared key authentication where the ID passes is any of ID_KEY_ID, + ID_FQDN, or ID_RFC822_ADDR. + + Authentication where the responder is authenticated using PKIX + Certificates and the initiator is authenticated using shared key + authentication. + + + + + + + + + + +Kaufman Standards Track [Page 87] + +RFC 4306 IKEv2 December 2005 + + +5. Security Considerations + + While this protocol is designed to minimize disclosure of + configuration information to unauthenticated peers, some such + disclosure is unavoidable. One peer or the other must identify + itself first and prove its identity first. To avoid probing, the + initiator of an exchange is required to identify itself first, and + usually is required to authenticate itself first. The initiator can, + however, learn that the responder supports IKE and what cryptographic + protocols it supports. The responder (or someone impersonating the + responder) can probe the initiator not only for its identity, but + using CERTREQ payloads may be able to determine what certificates the + initiator is willing to use. + + Use of EAP authentication changes the probing possibilities somewhat. + When EAP authentication is used, the responder proves its identity + before the initiator does, so an initiator that knew the name of a + valid initiator could probe the responder for both its name and + certificates. + + Repeated rekeying using CREATE_CHILD_SA without additional Diffie- + Hellman exchanges leaves all SAs vulnerable to cryptanalysis of a + single key or overrun of either endpoint. Implementers should take + note of this fact and set a limit on CREATE_CHILD_SA exchanges + between exponentiations. This memo does not prescribe such a limit. + + The strength of a key derived from a Diffie-Hellman exchange using + any of the groups defined here depends on the inherent strength of + the group, the size of the exponent used, and the entropy provided by + the random number generator used. Due to these inputs, it is + difficult to determine the strength of a key for any of the defined + groups. Diffie-Hellman group number two, when used with a strong + random number generator and an exponent no less than 200 bits, is + common for use with 3DES. Group five provides greater security than + group two. Group one is for historic purposes only and does not + provide sufficient strength except for use with DES, which is also + for historic use only. Implementations should make note of these + estimates when establishing policy and negotiating security + parameters. + + Note that these limitations are on the Diffie-Hellman groups + themselves. There is nothing in IKE that prohibits using stronger + groups nor is there anything that will dilute the strength obtained + from stronger groups (limited by the strength of the other algorithms + negotiated including the prf function). In fact, the extensible + framework of IKE encourages the definition of more groups; use of + elliptical curve groups may greatly increase strength using much + smaller numbers. + + + +Kaufman Standards Track [Page 88] + +RFC 4306 IKEv2 December 2005 + + + It is assumed that all Diffie-Hellman exponents are erased from + memory after use. In particular, these exponents MUST NOT be derived + from long-lived secrets like the seed to a pseudo-random generator + that is not erased after use. + + The strength of all keys is limited by the size of the output of the + negotiated prf function. For this reason, a prf function whose + output is less than 128 bits (e.g., 3DES-CBC) MUST NOT be used with + this protocol. + + The security of this protocol is critically dependent on the + randomness of the randomly chosen parameters. These should be + generated by a strong random or properly seeded pseudo-random source + (see [RFC4086]). Implementers should take care to ensure that use of + random numbers for both keys and nonces is engineered in a fashion + that does not undermine the security of the keys. + + For information on the rationale of many of the cryptographic design + choices in this protocol, see [SIGMA] and [SKEME]. Though the + security of negotiated CHILD_SAs does not depend on the strength of + the encryption and integrity protection negotiated in the IKE_SA, + implementations MUST NOT negotiate NONE as the IKE integrity + protection algorithm or ENCR_NULL as the IKE encryption algorithm. + + When using pre-shared keys, a critical consideration is how to assure + the randomness of these secrets. The strongest practice is to ensure + that any pre-shared key contain as much randomness as the strongest + key being negotiated. Deriving a shared secret from a password, + name, or other low-entropy source is not secure. These sources are + subject to dictionary and social engineering attacks, among others. + + The NAT_DETECTION_*_IP notifications contain a hash of the addresses + and ports in an attempt to hide internal IP addresses behind a NAT. + Since the IPv4 address space is only 32 bits, and it is usually very + sparse, it would be possible for an attacker to find out the internal + address used behind the NAT box by trying all possible IP addresses + and trying to find the matching hash. The port numbers are normally + fixed to 500, and the SPIs can be extracted from the packet. This + reduces the number of hash calculations to 2^32. With an educated + guess of the use of private address space, the number of hash + calculations is much smaller. Designers should therefore not assume + that use of IKE will not leak internal address information. + + When using an EAP authentication method that does not generate a + shared key for protecting a subsequent AUTH payload, certain man-in- + the-middle and server impersonation attacks are possible [EAPMITM]. + These vulnerabilities occur when EAP is also used in protocols that + are not protected with a secure tunnel. Since EAP is a general- + + + +Kaufman Standards Track [Page 89] + +RFC 4306 IKEv2 December 2005 + + + purpose authentication protocol, which is often used to provide + single-signon facilities, a deployed IPsec solution that relies on an + EAP authentication method that does not generate a shared key (also + known as a non-key-generating EAP method) can become compromised due + to the deployment of an entirely unrelated application that also + happens to use the same non-key-generating EAP method, but in an + unprotected fashion. Note that this vulnerability is not limited to + just EAP, but can occur in other scenarios where an authentication + infrastructure is reused. For example, if the EAP mechanism used by + IKEv2 utilizes a token authenticator, a man-in-the-middle attacker + could impersonate the web server, intercept the token authentication + exchange, and use it to initiate an IKEv2 connection. For this + reason, use of non-key-generating EAP methods SHOULD be avoided where + possible. Where they are used, it is extremely important that all + usages of these EAP methods SHOULD utilize a protected tunnel, where + the initiator validates the responder's certificate before initiating + the EAP exchange. Implementers SHOULD describe the vulnerabilities + of using non-key-generating EAP methods in the documentation of their + implementations so that the administrators deploying IPsec solutions + are aware of these dangers. + + An implementation using EAP MUST also use a public-key-based + authentication of the server to the client before the EAP exchange + begins, even if the EAP method offers mutual authentication. This + avoids having additional IKEv2 protocol variations and protects the + EAP data from active attackers. + + If the messages of IKEv2 are long enough that IP-level fragmentation + is necessary, it is possible that attackers could prevent the + exchange from completing by exhausting the reassembly buffers. The + chances of this can be minimized by using the Hash and URL encodings + instead of sending certificates (see section 3.6). Additional + mitigations are discussed in [KPS03]. + +6. IANA Considerations + + This document defines a number of new field types and values where + future assignments will be managed by the IANA. + + The following registries have been created by the IANA: + + IKEv2 Exchange Types (section 3.1) + IKEv2 Payload Types (section 3.2) + IKEv2 Transform Types (section 3.3.2) + IKEv2 Transform Attribute Types (section 3.3.2) + IKEv2 Encryption Transform IDs (section 3.3.2) + IKEv2 Pseudo-random Function Transform IDs (section 3.3.2) + IKEv2 Integrity Algorithm Transform IDs (section 3.3.2) + + + +Kaufman Standards Track [Page 90] + +RFC 4306 IKEv2 December 2005 + + + IKEv2 Diffie-Hellman Transform IDs (section 3.3.2) + IKEv2 Identification Payload ID Types (section 3.5) + IKEv2 Certificate Encodings (section 3.6) + IKEv2 Authentication Method (section 3.8) + IKEv2 Notify Message Types (section 3.10.1) + IKEv2 Notification IPCOMP Transform IDs (section 3.10.1) + IKEv2 Security Protocol Identifiers (section 3.3.1) + IKEv2 Traffic Selector Types (section 3.13.1) + IKEv2 Configuration Payload CFG Types (section 3.15) + IKEv2 Configuration Payload Attribute Types (section 3.15.1) + + Note: When creating a new Transform Type, a new registry for it must + be created. + + Changes and additions to any of those registries are by expert + review. + +7. Acknowledgements + + This document is a collaborative effort of the entire IPsec WG. If + there were no limit to the number of authors that could appear on an + RFC, the following, in alphabetical order, would have been listed: + Bill Aiello, Stephane Beaulieu, Steve Bellovin, Sara Bitan, Matt + Blaze, Ran Canetti, Darren Dukes, Dan Harkins, Paul Hoffman, John + Ioannidis, Charlie Kaufman, Steve Kent, Angelos Keromytis, Tero + Kivinen, Hugo Krawczyk, Andrew Krywaniuk, Radia Perlman, Omer + Reingold, and Michael Richardson. Many other people contributed to + the design. It is an evolution of IKEv1, ISAKMP, and the IPsec DOI, + each of which has its own list of authors. Hugh Daniel suggested the + feature of having the initiator, in message 3, specify a name for the + responder, and gave the feature the cute name "You Tarzan, Me Jane". + David Faucher and Valery Smyzlov helped refine the design of the + traffic selector negotiation. + +8. References + +8.1. Normative References + + [ADDGROUP] Kivinen, T. and M. Kojo, "More Modular Exponential (MODP) + Diffie-Hellman groups for Internet Key Exchange (IKE)", + RFC 3526, May 2003. + + [ADDRIPV6] Hinden, R. and S. Deering, "Internet Protocol Version 6 + (IPv6) Addressing Architecture", RFC 3513, April 2003. + + [Bra97] Bradner, S., "Key Words for use in RFCs to indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + + + +Kaufman Standards Track [Page 91] + +RFC 4306 IKEv2 December 2005 + + + [EAP] Aboba, B., Blunk, L., Vollbrecht, J., Carlson, J., and H. + Levkowetz, "Extensible Authentication Protocol (EAP)", RFC + 3748, June 2004. + + [ESPCBC] Pereira, R. and R. Adams, "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + [Hutt05] Huttunen, A., Swander, B., Volpe, V., DiBurro, L., and M. + Stenberg, "UDP Encapsulation of IPsec ESP Packets", RFC + 3948, January 2005. + + [RFC2434] Narten, T. and H. Alvestrand, "Guidelines for Writing an + IANA Considerations Section in RFCs", BCP 26, RFC 2434, + October 1998. + + [RFC3168] Ramakrishnan, K., Floyd, S., and D. Black, "The Addition + of Explicit Congestion Notification (ECN) to IP", RFC + 3168, September 2001. + + [RFC3280] Housley, R., Polk, W., Ford, W., and D. Solo, "Internet + X.509 Public Key Infrastructure Certificate and + Certificate Revocation List (CRL) Profile", RFC 3280, + April 2002. + + [RFC4301] Kent, S. and K. Seo, "Security Architecture for the + Internet Protocol", RFC 4301, December 2005. + +8.2. Informative References + + [DES] ANSI X3.106, "American National Standard for Information + Systems-Data Link Encryption", American National Standards + Institute, 1983. + + [DH] Diffie, W., and Hellman M., "New Directions in + Cryptography", IEEE Transactions on Information Theory, V. + IT-22, n. 6, June 1977. + + [DHCP] Droms, R., "Dynamic Host Configuration Protocol", RFC + 2131, March 1997. + + [DSS] NIST, "Digital Signature Standard", FIPS 186, National + Institute of Standards and Technology, U.S. Department of + Commerce, May, 1994. + + [EAPMITM] Asokan, N., Nierni, V., and Nyberg, K., "Man-in-the-Middle + in Tunneled Authentication Protocols", + http://eprint.iacr.org/2002/163, November 2002. + + + + +Kaufman Standards Track [Page 92] + +RFC 4306 IKEv2 December 2005 + + + [HC98] Harkins, D. and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IDEA] Lai, X., "On the Design and Security of Block Ciphers," + ETH Series in Information Processing, v. 1, Konstanz: + Hartung-Gorre Verlag, 1992. + + [IPCOMP] Shacham, A., Monsour, B., Pereira, R., and M. Thomas, "IP + Payload Compression Protocol (IPComp)", RFC 3173, + September 2001. + + [KPS03] Kaufman, C., Perlman, R., and Sommerfeld, B., "DoS + protection for UDP-based protocols", ACM Conference on + Computer and Communications Security, October 2003. + + [KBC96] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed- + Hashing for Message Authentication", RFC 2104, February + 1997. + + [LDAP] Wahl, M., Howes, T., and S Kille, "Lightweight Directory + Access Protocol (v3)", RFC 2251, December 1997. + + [MD5] Rivest, R., "The MD5 Message-Digest Algorithm", RFC 1321, + April 1992. + + [MSST98] Maughan, D., Schertler, M., Schneider, M., and J. Turner, + "Internet Security Association and Key Management Protocol + (ISAKMP)", RFC 2408, November 1998. + + [Orm96] Orman, H., "The OAKLEY Key Determination Protocol", RFC + 2412, November 1998. + + [PFKEY] McDonald, D., Metz, C., and B. Phan, "PF_KEY Key + Management API, Version 2", RFC 2367, July 1998. + + [PKCS1] Jonsson, J. and B. Kaliski, "Public-Key Cryptography + Standards (PKCS) #1: RSA Cryptography Specifications + Version 2.1", RFC 3447, February 2003. + + [PK01] Perlman, R., and Kaufman, C., "Analysis of the IPsec key + exchange Standard", WET-ICE Security Conference, MIT,2001, + http://sec.femto.org/wetice-2001/papers/radia-paper.pdf. + + [Pip98] Piper, D., "The Internet IP Security Domain Of + Interpretation for ISAKMP", RFC 2407, November 1998. + + + + + + +Kaufman Standards Track [Page 93] + +RFC 4306 IKEv2 December 2005 + + + [RADIUS] Rigney, C., Willens, S., Rubens, A., and W. Simpson, + "Remote Authentication Dial In User Service (RADIUS)", RFC + 2865, June 2000. + + [RFC4086] Eastlake, D., 3rd, Schiller, J., and S. Crocker, + "Randomness Requirements for Security", BCP 106, RFC 4086, + June 2005. + + [RFC1958] Carpenter, B., "Architectural Principles of the Internet", + RFC 1958, June 1996. + + [RFC2401] Kent, S. and R. Atkinson, "Security Architecture for the + Internet Protocol", RFC 2401, November 1998. + + [RFC2474] Nichols, K., Blake, S., Baker, F., and D. Black, + "Definition of the Differentiated Services Field (DS + Field) in the IPv4 and IPv6 Headers", RFC 2474, December + 1998. + + [RFC2475] Blake, S., Black, D., Carlson, M., Davies, E., Wang, Z., + and W. Weiss, "An Architecture for Differentiated + Service", RFC 2475, December 1998. + + [RFC2522] Karn, P. and W. Simpson, "Photuris: Session-Key Management + Protocol", RFC 2522, March 1999. + + [RFC2775] Carpenter, B., "Internet Transparency", RFC 2775, February + 2000. + + [RFC2983] Black, D., "Differentiated Services and Tunnels", RFC + 2983, October 2000. + + [RFC3439] Bush, R. and D. Meyer, "Some Internet Architectural + Guidelines and Philosophy", RFC 3439, December 2002. + + [RFC3715] Aboba, B. and W. Dixon, "IPsec-Network Address Translation + (NAT) Compatibility Requirements", RFC 3715, March 2004. + + [RFC4302] Kent, S., "IP Authentication Header", RFC 4302, December + 2005. + + [RFC4303] Kent, S., "IP Encapsulating Security Payload (ESP)", RFC + 4303, December 2005. + + [RSA] Rivest, R., Shamir, A., and Adleman, L., "A Method for + Obtaining Digital Signatures and Public-Key + Cryptosystems", Communications of the ACM, v. 21, n. 2, + February 1978. + + + +Kaufman Standards Track [Page 94] + +RFC 4306 IKEv2 December 2005 + + + [SHA] NIST, "Secure Hash Standard", FIPS 180-1, National + Institute of Standards and Technology, U.S. Department of + Commerce, May 1994. + + [SIGMA] Krawczyk, H., "SIGMA: the `SIGn-and-MAc' Approach to + Authenticated Diffie-Hellman and its Use in the IKE + Protocols", in Advances in Cryptography - CRYPTO 2003 + Proceedings, LNCS 2729, Springer, 2003. Available at: + http://www.informatik.uni-trier.de/~ley/db/conf/ + crypto/crypto2003.html. + + [SKEME] Krawczyk, H., "SKEME: A Versatile Secure Key Exchange + Mechanism for Internet", from IEEE Proceedings of the 1996 + Symposium on Network and Distributed Systems Security. + + [X.501] ITU-T Recommendation X.501: Information Technology - Open + Systems Interconnection - The Directory: Models, 1993. + + [X.509] ITU-T Recommendation X.509 (1997 E): Information + Technology - Open Systems Interconnection - The Directory: + Authentication Framework, June 1997. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kaufman Standards Track [Page 95] + +RFC 4306 IKEv2 December 2005 + + +Appendix A: Summary of changes from IKEv1 + + The goals of this revision to IKE are: + + 1) To define the entire IKE protocol in a single document, replacing + RFCs 2407, 2408, and 2409 and incorporating subsequent changes to + support NAT Traversal, Extensible Authentication, and Remote Address + acquisition; + + 2) To simplify IKE by replacing the eight different initial exchanges + with a single four-message exchange (with changes in authentication + mechanisms affecting only a single AUTH payload rather than + restructuring the entire exchange) see [PK01]; + + 3) To remove the Domain of Interpretation (DOI), Situation (SIT), and + Labeled Domain Identifier fields, and the Commit and Authentication + only bits; + + 4) To decrease IKE's latency in the common case by making the initial + exchange be 2 round trips (4 messages), and allowing the ability to + piggyback setup of a CHILD_SA on that exchange; + + 5) To replace the cryptographic syntax for protecting the IKE + messages themselves with one based closely on ESP to simplify + implementation and security analysis; + + 6) To reduce the number of possible error states by making the + protocol reliable (all messages are acknowledged) and sequenced. + This allows shortening CREATE_CHILD_SA exchanges from 3 messages to + 2; + + 7) To increase robustness by allowing the responder to not do + significant processing until it receives a message proving that the + initiator can receive messages at its claimed IP address, and not + commit any state to an exchange until the initiator can be + cryptographically authenticated; + + 8) To fix cryptographic weaknesses such as the problem with + symmetries in hashes used for authentication documented by Tero + Kivinen; + + 9) To specify Traffic Selectors in their own payloads type rather + than overloading ID payloads, and making more flexible the Traffic + Selectors that may be specified; + + 10) To specify required behavior under certain error conditions or + when data that is not understood is received, to make it easier to + make future revisions that do not break backward compatibility; + + + +Kaufman Standards Track [Page 96] + +RFC 4306 IKEv2 December 2005 + + + 11) To simplify and clarify how shared state is maintained in the + presence of network failures and Denial of Service attacks; and + + 12) To maintain existing syntax and magic numbers to the extent + possible to make it likely that implementations of IKEv1 can be + enhanced to support IKEv2 with minimum effort. + +Appendix B: Diffie-Hellman Groups + + There are two Diffie-Hellman groups defined here for use in IKE. + These groups were generated by Richard Schroeppel at the University + of Arizona. Properties of these primes are described in [Orm96]. + + The strength supplied by group one may not be sufficient for the + mandatory-to-implement encryption algorithm and is here for historic + reasons. + + Additional Diffie-Hellman groups have been defined in [ADDGROUP]. + +B.1. Group 1 - 768 Bit MODP + + This group is assigned id 1 (one). + + The prime is: 2^768 - 2 ^704 - 1 + 2^64 * { [2^638 pi] + 149686 } Its + hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08 + 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B + 302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9 + A63A3620 FFFFFFFF FFFFFFFF + + The generator is 2. + +B.2. Group 2 - 1024 Bit MODP + + This group is assigned id 2 (two). + + The prime is 2^1024 - 2^960 - 1 + 2^64 * { [2^894 pi] + 129093 }. + Its hexadecimal value is: + + FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08 + 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B + 302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9 + A637ED6B 0BFF5CB6 F406B7ED EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 + 49286651 ECE65381 FFFFFFFF FFFFFFFF + + The generator is 2. + + + + +Kaufman Standards Track [Page 97] + +RFC 4306 IKEv2 December 2005 + + +Editor's Address + + Charlie Kaufman + Microsoft Corporation + 1 Microsoft Way + Redmond, WA 98052 + + Phone: 1-425-707-3335 + EMail: charliek@microsoft.com + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +Kaufman Standards Track [Page 98] + +RFC 4306 IKEv2 December 2005 + + +Full Copyright Statement + + Copyright (C) The Internet Society (2005). + + This document is subject to the rights, licenses and restrictions + contained in BCP 78, and except as set forth therein, the authors + retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at ietf- + ipr@ietf.org. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + +Kaufman Standards Track [Page 99] + diff --git a/doc/ikev2/[RFC4307] - Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2).txt b/doc/ikev2/[RFC4307] - Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2).txt new file mode 100644 index 000000000..5617a2551 --- /dev/null +++ b/doc/ikev2/[RFC4307] - Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2).txt @@ -0,0 +1,339 @@ + + + + + + +Network Working Group J. Schiller +Request for Comments: 4307 Massachusetts Institute of Technology +Category: Standards Track December 2005 + + + Cryptographic Algorithms for Use in the + Internet Key Exchange Version 2 (IKEv2) + +Status of This Memo + + This document specifies an Internet standards track protocol for the + Internet community, and requests discussion and suggestions for + improvements. Please refer to the current edition of the "Internet + Official Protocol Standards" (STD 1) for the standardization state + and status of this protocol. Distribution of this memo is unlimited. + +Copyright Notice + + Copyright (C) The Internet Society (2005). + +Abstract + + The IPsec series of protocols makes use of various cryptographic + algorithms in order to provide security services. The Internet Key + Exchange (IKE (RFC 2409) and IKEv2) provide a mechanism to negotiate + which algorithms should be used in any given association. However, + to ensure interoperability between disparate implementations, it is + necessary to specify a set of mandatory-to-implement algorithms to + ensure that there is at least one algorithm that all implementations + will have available. This document defines the current set of + algorithms that are mandatory to implement as part of IKEv2, as well + as algorithms that should be implemented because they may be promoted + to mandatory at some future time. + +1. Introduction + + The Internet Key Exchange protocol provides for the negotiation of + cryptographic algorithms between both endpoints of a cryptographic + + association. Different implementations of IPsec and IKE may provide + different algorithms. However, the IETF desires that all + implementations should have some way to interoperate. In particular, + this requires that IKE define a set of mandatory-to-implement + algorithms because IKE itself uses such algorithms as part of its own + negotiations. This requires that some set of algorithms be specified + as "mandatory-to-implement" for IKE. + + + + + +Schiller Standards Track [Page 1] + +RFC 4307 IKEv2 Cryptographic Algorithms December 2005 + + + The nature of cryptography is that new algorithms surface + continuously and existing algorithms are continuously attacked. An + algorithm believed to be strong today may be demonstrated to be weak + tomorrow. Given this, the choice of mandatory-to-implement algorithm + should be conservative so as to minimize the likelihood of it being + compromised quickly. Thought should also be given to performance + considerations as many uses of IPsec will be in environments where + performance is a concern. + + Finally, we need to recognize that the mandatory-to-implement + algorithm(s) may need to change over time to adapt to the changing + world. For this reason, the selection of mandatory-to-implement + algorithms was removed from the main IKEv2 specification and placed + in this document. As the choice of algorithm changes, only this + document should need to be updated. + + Ideally, the mandatory-to-implement algorithm of tomorrow should + already be available in most implementations of IPsec by the time it + is made mandatory. To facilitate this, we will attempt to identify + those algorithms (that are known today) in this document. There is + no guarantee that the algorithms we believe today may be mandatory in + the future will in fact become so. All algorithms known today are + subject to cryptographic attack and may be broken in the future. + +2. Requirements Terminology + + Keywords "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT", and + "MAY" that appear in this document are to be interpreted as described + in [RFC2119]. + + We define some additional terms here: + + SHOULD+ This term means the same as SHOULD. However, it is likely + that an algorithm marked as SHOULD+ will be promoted at + some future time to be a MUST. + + SHOULD- This term means the same as SHOULD. However, an algorithm + marked as SHOULD- may be deprecated to a MAY in a future + version of this document. + + MUST- This term means the same as MUST. However, we expect at + some point that this algorithm will no longer be a MUST in + a future document. Although its status will be determined + at a later time, it is reasonable to expect that if a + future revision of a document alters the status of a MUST- + algorithm, it will remain at least a SHOULD or a SHOULD-. + + + + + +Schiller Standards Track [Page 2] + +RFC 4307 IKEv2 Cryptographic Algorithms December 2005 + + +3. Algorithm Selection + +3.1. IKEv2 Algorithm Selection + +3.1.1. Encrypted Payload Algorithms + + The IKEv2 Encrypted Payload requires both a confidentiality algorithm + and an integrity algorithm. For confidentiality, implementations + MUST- implement 3DES-CBC and SHOULD+ implement AES-128-CBC. For + integrity, HMAC-SHA1 MUST be implemented. + +3.1.2. Diffie-Hellman Groups + + There are several Modular Exponential (MODP) groups that are defined + for use in IKEv2. They are defined in both the [IKEv2] base document + and in the MODP extensions document. They are identified by group + number. Any groups not listed here are considered as "MAY be + implemented". + + Group Number Bit Length Status Defined + 2 1024 MODP Group MUST- [RFC2409] + 14 2048 MODP Group SHOULD+ [RFC3526] + +3.1.3. IKEv2 Transform Type 1 Algorithms + + IKEv2 defines several possible algorithms for Transfer Type 1 + (encryption). These are defined below with their implementation + status. + + Name Number Defined In Status + RESERVED 0 + ENCR_3DES 3 [RFC2451] MUST- + ENCR_NULL 11 [RFC2410] MAY + ENCR_AES_CBC 12 [AES-CBC] SHOULD+ + ENCR_AES_CTR 13 [AES-CTR] SHOULD + +3.1.4. IKEv2 Transform Type 2 Algorithms + + Transfer Type 2 Algorithms are pseudo-random functions used to + generate random values when needed. + + Name Number Defined In Status + RESERVED 0 + PRF_HMAC_MD5 1 [RFC2104] MAY + PRF_HMAC_SHA1 2 [RFC2104] MUST + PRF_AES128_CBC 4 [AESPRF] SHOULD+ + + + + + +Schiller Standards Track [Page 3] + +RFC 4307 IKEv2 Cryptographic Algorithms December 2005 + + +3.1.5. IKEv2 Transform Type 3 Algorithms + + Transfer Type 3 Algorithms are Integrity algorithms used to protect + data against tampering. + + Name Number Defined In Status + NONE 0 + AUTH_HMAC_MD5_96 1 [RFC2403] MAY + AUTH_HMAC_SHA1_96 2 [RFC2404] MUST + AUTH_AES_XCBC_96 5 [AES-MAC] SHOULD+ + +4. Security Considerations + + The security of cryptographic-based systems depends on both the + strength of the cryptographic algorithms chosen and the strength of + the keys used with those algorithms. The security also depends on + the engineering of the protocol used by the system to ensure that + there are no non-cryptographic ways to bypass the security of the + overall system. + + This document concerns itself with the selection of cryptographic + algorithms for the use of IKEv2, specifically with the selection of + "mandatory-to-implement" algorithms. The algorithms identified in + this document as "MUST implement" or "SHOULD implement" are not known + to be broken at the current time, and cryptographic research so far + leads us to believe that they will likely remain secure into the + foreseeable future. However, this isn't necessarily forever. We + would therefore expect that new revisions of this document will be + issued from time to time that reflect the current best practice in + this area. + +5. Normative References + + [RFC2409] Harkins, D. and D. Carrel, "The Internet Key Exchange + (IKE)", RFC 2409, November 1998. + + [IKEv2] Kaufman, C., Ed., "Internet Key Exchange (IKEv2) + Protocol", RFC 4306, December 2005. + + [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate + Requirement Levels", BCP 14, RFC 2119, March 1997. + + [RFC3526] Kivinen, T. and M. Kojo, "More Modular Exponential + (MODP) Diffie-Hellman groups for Internet Key Exchange + (IKE)", RFC 3526, May 2003. + + [RFC2451] Pereira, R. and R. Adams, "The ESP CBC-Mode Cipher + Algorithms", RFC 2451, November 1998. + + + +Schiller Standards Track [Page 4] + +RFC 4307 IKEv2 Cryptographic Algorithms December 2005 + + + [RFC2410] Glenn, R. and S. Kent, "The NULL Encryption Algorithm + and Its Use With IPsec", RFC 2410, November 1998. + + [AES-CBC] Frankel, S., Glenn, R., and S. Kelly, "The AES-CBC + Cipher Algorithm and Its Use with IPsec", RFC 3602, + September 2003. + + [AES-CTR] Housley, R., "Using Advanced Encryption Standard (AES) + Counter Mode With IPsec Encapsulating Security Payload + (ESP)", RFC 3686, January 2004. + + [RFC2104] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: + Keyed-Hashing for Message Authentication", RFC 2104, + February 1997. + + [AESPRF] Hoffman, P., "The AES-XCBC-PRF-128 Algorithm for the + Internet Key Exchange Protocol (IKE)", RFC 3664, January + 2004. + + [RFC2403] Madson, C. and R. Glenn, "The Use of HMAC-MD5-96 within + ESP and AH", RFC 2403, November 1998. + + [RFC2404] Madson, C. and R. Glenn, "The Use of HMAC-SHA-1-96 + within ESP and AH", RFC 2404, November 1998. + + [AES-MAC] Frankel, S. and H. Herbert, "The AES-XCBC-MAC-96 + Algorithm and Its Use With IPsec", RFC 3566, September + 2003. + +Author's Address + + Jeffrey I. Schiller + Massachusetts Institute of Technology + Room W92-190 + 77 Massachusetts Avenue + Cambridge, MA 02139-4307 + USA + + Phone: +1 (617) 253-0161 + EMail: jis@mit.edu + + + + + + + + + + + +Schiller Standards Track [Page 5] + +RFC 4307 IKEv2 Cryptographic Algorithms December 2005 + + +Full Copyright Statement + + Copyright (C) The Internet Society (2005). + + This document is subject to the rights, licenses and restrictions + contained in BCP 78, and except as set forth therein, the authors + retain all their rights. + + This document and the information contained herein are provided on an + "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS + OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET + ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, + INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE + INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED + WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. + +Intellectual Property + + The IETF takes no position regarding the validity or scope of any + Intellectual Property Rights or other rights that might be claimed to + pertain to the implementation or use of the technology described in + this document or the extent to which any license under such rights + might or might not be available; nor does it represent that it has + made any independent effort to identify any such rights. Information + on the procedures with respect to rights in RFC documents can be + found in BCP 78 and BCP 79. + + Copies of IPR disclosures made to the IETF Secretariat and any + assurances of licenses to be made available, or the result of an + attempt made to obtain a general license or permission for the use of + such proprietary rights by implementers or users of this + specification can be obtained from the IETF on-line IPR repository at + http://www.ietf.org/ipr. + + The IETF invites any interested party to bring to its attention any + copyrights, patents or patent applications, or other proprietary + rights that may cover technology that may be required to implement + this standard. Please address the information to the IETF at ietf- + ipr@ietf.org. + +Acknowledgement + + Funding for the RFC Editor function is currently provided by the + Internet Society. + + + + + + + +Schiller Standards Track [Page 6] + diff --git a/doc/ikev2/[Thomas03] - IPSec Architektur und Protokolle, Internet Key Exchange (IKE).pdf b/doc/ikev2/[Thomas03] - IPSec Architektur und Protokolle, Internet Key Exchange (IKE).pdf new file mode 100644 index 0000000000000000000000000000000000000000..b8eb665e0998114b2d7e0075d78159583ac9fb81 GIT binary patch literal 653279 zcmd43bwHHe*C>jBNO!lSC@>5&!~oJDNH<6hFm!jPO1E@McSYC6i_D(2*Is+oe%5|)uk}2PisF)NKz0xo`IlT?ULMdt=^(t^ z|C|ft0fKn`K?gS%_|LgOUQW(`;yB@J^v}7RoScw<(ZN^ipK?K*yqy2E4Fuxg_$NOQ z2m=16ZD4L*2>jx>{rRso0`qY2{0j$n)j#EOgMpBL`kosM;`ygsZZ1yVf8uy}xFP@4 zg@=ci_n&fkcp=>X^Z^e90{Z7%ULctFpFZFPa{p`HcsaTLr86%l{6hbS4|q9wIRAy? z;^g|L9UOOo@n8OPa)6p!!5pyA;enAGY6CRJs z0BIW&TX+ZV*V~S`wtzU8Q&NIM62v7U$twb%Ap!zQic5-vfudYsuo$O^;QyN9HbBuG zouCd*_Yui~h0e$*p&*Hc{#UrdqZABx)$M+8yB)x6Or6YVxgcBsNpmYFm;*r43hD$C zhZ)%#!vNB>ybxaa=D^F#2~eTs0RjaD9i1FtP-}R=&lwsR7?>Ium>U>8jHSd3z(l1* zB{VWMfG)eWbx(BC+SB?4CHq4kV~p=}Y(8{#tsMOQNqC>M!fcEZEA?|DaS=i6yGiQa z_#wWbwl)UmtRL-*7gS38zip<=5~V(N`cZK_6oh6JuGVmT`$i@mmll+$prd?JWBx>W zJ1v{2Y9QA!ls!`}CwhQIDLpALZjqh+NNcY4G(1;+=BrkOu=guG{?thi63;=MiD2l< zgr4whbzA$ucVVgXzv7>p5ZC;apY5&Bj+G{2ZD3T<1gsd3O}Rc!k*@Z~$h4DH#?VYY zO|#9I7tb*j82_+Fy|0(iE$BZC%f_o_5fTJuAe4B01`U)hZ^X$$dlI5DZBcbrG@`dv zUv8x2KO%NQ<1>6?ZqigZ4(=|AWTP=K>7YEaKMLuy>R@IU^iPeobFlx+Sj&RZ{7|n} zK@ojc6Z0&v{@bPbV~SAWy7Q+n?o5M6{qe@=SN#yp05KNz{tbi|kMPZeIUpS3xB*m@ zNuq@>m1;aGDBsdI_!#qwjo)f5dDDao{_^_3hj^>=j8^8A`+Y z-fb;Q#fpAT=0ti)&D`XYROTM!JZ`mBBMV8R(1U#AaHu2==3qSzF?i-Sx!mRYW?&@X zaj1TDyhvbs8ZfAA8>7=u5HA6T4l@*!P4+8==<~~&JFI9P{HOvtnFYx^U9xn>cPFC<+860uDF~JdXFej)n z)Cmelz#|uqP=uP^4d34UlmV*lb})b#eB8>`^glPTdv169|BeL1r`!t_bFj4&wRO|J zmB9^~hF+|G&*U8u%`mgEAFh^Tw z2ctV<;5WX%l)KgU?@HVb-76sp7XW7t-}G+Hal;nbg_wJSChJ*J4C3)c6*dGF3 zICw|!cSUdcz=dgZg728aN$#wIf8Q~Hf8R;c{p&9WPT;@yA257}x!-`a|Goq1{@I{_ z@XZJO2j-*&LqHsVIv`pu5a{o_(q6ops?L1ETeR}_$8LDEyoA&Xi(GC`iqWUDM{pOO zHarr2@4t-CfJU9RypJ42+n(Mw1SvS!8{PUL6Xmlz>e>AL=dkb1uD0U=kQ*Z>Qm~%2 zYm&TpeFt%Cb8UqHsn>GnCZW}Wz z)1gkdJ}yb(L)wF#O^llQ+CZe4_1PP{5Cr4&_Z*%ay$`d{0_H{1eS`c&*U^-PORb|LD2UKSjrmAZ%z97P&i%$f*}2O8VemDhn84!i z+2eo?0UyT)Gd_;hNIoi}I=X3I4{!^y*eeot4;HgpwSM<#-e65Gb;b*%r+pCq;@fot zEbz4qOxsKMy6Ifr`M!x3)Payvj{9VA<6w$pq;&@T9@kT0tJPI)g_hZ~vNWuWfDqwY zrutm5`rKdC>HCTSzaLg_AJSz3wzK~=)#~}eZ}H{HchhldD(ly~@xLc09?X7f!}41E zO>`A>HJoxFw7azCKYN8R=qDgdyJWj|a5l^z)@q&q4bkPz%%>T|(-m40R8*9oiH8S@ z4i4pl6%7xO5f-jRh5ZV%aD~McPtSbM$Ue?|@)T7gLJ$?ERTNkKra<%^El@;v+1KY` z>+sd^+~?otPFadHPe{*oi5q|ABjULt`M>pYm83lA5&RpQIS!d&I)CVYQc8w&+$f`nx^c&RJVAQb!8fD)>#%s>vRjw^U^z6@_p%coxx#Bp~Tl$kq%hLy2!JkLsRpYpx zh%o6@;>c&YZ{xmFe3#%QZka~xQ7X?^aHQFG!mzP8%^;*{5Z>ly{>qK9p|jLd1#IuptBz3|1OYwaQjRO!trF|)j+cJa|VlRL{pI6Bc9Ki$tC z(PG_iq0Qz;R{Ed@+FY+i4u9nT9K`ktyF@A)i0pj!;$;4pP z*24-v1^4RpaQWW8s&tC2oln%)Vm(DUp-ox#oZnr}+NSl%iJuqY{VL)fAM~yWmEnRZ`Q0;SI0M%{#|~#e=XJZ)86lbZ?6lz z57uXUADSS2Y9A##7sJdUSIr&#oV?+l(9!YCh~i;WT?O5Knpj|PMp9L%{z|mj<&kTB z=$mK@NmBFW;elxL)A-~`Bb*!Xd8zH}POrZA117Re`eWHoPz8pHQbfsqR@Z|qd9R#q zl5pZoT`tP^-=9-MiF4%!M)V6P-6l{h#a22H9e46K>6Pb&5Fc7^f2KhkMPA7#=Edzn znb1Hno1=^Tq*|R!JB*+vr1*3jr_)|c=d!@>0+eTYftSdoY$>F*uTAp2X2MJAb>m8P zE7q@{v)K-|S?~ECS89g(hKe$J;DB!QDrw5O1oAA|y;c+J-)iUlC_k`Djfnl`QHS2A zoAF8{#ck+H=O8BH67b_mYdM>JDoye8_Qz5sS15LU^Bx2_-s6fLi0`|(9R?hhDqlpJ zAI;BjX?8Jn&n?c0rguHVh^qKuf|=`EWn+(zt7-gRr|!o}50Rd=zXttV%s_%3tG+ka zOye2NW!JOACu^*GEbY=jTU|u#1R9xbvp=RMhsJr{*zwLKS1ou@^$Z53=o&eovL};ZeZx%BwEByd;^RocjC2O4tk)p! zk+8C{EB_+57!`>f^Xzw@PA@|3tqp#-v4M1^aw0^_3)~jMmCry1&UI@2uV0xle#CTyI+q?=Qfm{r=dSP z+73P~$tGwF6`t#jIFxOW5zwJd*S^uxibGHI^eeli1M(QKMZ6Ix$Xe(Lkg-!4LoR#V6rPL_JfRK&7P-@fKp zH}~4Pe|k2yRvBC5wDe&sAaVM)^!_S_uV@UJ18oiKZpy1<(|4EUym~CN0>AQN1ZkwT zvjV#aDE7<{7ceL!&|W;7cz3!}Gv14}i%E1K@tlk3Rby|X%_Tktp_$9kNAr{R-sD63 zDbyhcm7QPL`JtK;ZX&3cmtTTvjHjNeNe&v*RZx2Evm2(NM2tHQBwg^%Z8rB(?*#;i z=Gg2#$YLm{M{jBF$t7~V5PSSwn?-S*z36eWx@yqZHnWCh#5qMmZ|on>j)3zp0*=yF zL*1fWX3xo>PkEQQtC9P=d(j`yW(v+~DCE)3Y?D%*{CVtyz7QBnq8SukYlkQ8O|D?L z$HL@gMy!%G9D?^cHeboiM7TV{yIe4k5#SeJWg89e^#JE{qH?JhlNxnBGWua9-S45s zWqBUS?pn%i*^FSvD9CfApNh-mu2(jdGI2!;Wp1Aeho_6AB`DFJ2AuPG zhA39KyyBke$a$M#gSwzZlLwTTem0-6be`v;+-%!j=fubu#ubswR!EOhrz*A4Kwvgt z)vR|DEmkeFcNFweL2iNg}Bn#_$}55RJIkD(-q>cdf-i6ih5WR9PzQ*tyy&^ zJ$02nd89Dt<&G9r z1!)Fn=Uh80Foc^sW)lToT}aC;2K<-|V#0Kr9iTj;-&;wc>m7yCjnS95+r)<@31Inm zi2IAn;BtKP>!pxqbcpRFL*pd@Fz4DuCOQws{n5vfxYs@_yb=I?~4w!8z9jF;*ilc5p zwTKtRJbT`D>`WF^vN>YD&lU$BTeA7k_Cpk~;*W~4*LGI!nTE>YI(}ZwlaVf3?*jvc8{JY;V%&$t7(4M* zahP zY{W6iPi$RBZRim-iMFB*Qx}8z+wVPkHst(ME*T_PrjcZJi4;3(#E-U$dG#_Pd}0&l z1E0Q=uUUkj%02XV}zmrW}->gJTpfco{ zt!*=lUx{?~j9H54@ae-~BS*Nk31mrM8>%O|F}AA!jb6%+l~#1GAVt(9MyDX_C~y7i zH%$8mqHo9Q$q`TUEPi>uL__I>8tv~>m5;D$_~!`(41TTpU_Q(GPIu}u=Dl91V5&aK z+V<|(M-i6IVuj{?s8B6ymZm6!p3KkIDV=i!fTbEIBCD(S+D^aI;jOg7u}{>e&+Fn#`wvbcpScDJ!t$nC>r`iHfg#bA^W;A zgODuT&1KyEeTDS;#G(BtOlLfu)SoCFWWh)agz zx-a;d-h5qUCU!M^i#4!ZK@1Q+e3A zzG8tE%4XsxD(LP@Tqz{%c zVr8o=`4?nK?+~|N&UT{pnJS-Q-@sh6m(M~yyE8Lr&8Qiuk@otDR||F?*#tmkiJkE$ zzOO>CUM{WPgh!D?&eQL%#K$bTQx{@G+q4i2kJbOT2pM@7?LR#g;CE@S+hKO3%#DBT{4v5Dk;3*zQ zPSkCmqxvo-XE*l7@x!-oIvL9v^rU1NVzNSZ;=Hnj1K+znqjU{JEDpy%Qn8kE&A-Z> z&inaUG~XaUgmA)z>@_d8%6yop7RB1QC(F+mN~GT2z*uKn&??T7BPtDt=hFj+t%!Zo zx5p}Jt>0e+QTZz7lG2`iGABi^N>=62ogiRCRB68mt$qZ>2w{4x%QJ^91M%Qv&txQG z_c^N9%?7XVr<_sPFA^m?pEOWjJwNC=TQp)%dZm)&+yfa6$VF~3SPzk$9R7%*!uSJI zk!uaN7szb4mk3$+z)#4#QC{hsD8@NZAd?hdDURSHbxa#|1Um)T`!Q zP({P6S#o{!;B~U9QsD_?tY%PM^jgx!AYLg0_CP>k+W(RM_okB;9gj1-*3RQ7~{ld~AGJ-jMqQTWcl-Zm<+V?u(f#02xjuz!h>mGBlb+Viazr!pok>)YII0~qAv2K7r-T39^A4j0wur&%qHoGXd1V~bk9 zBeVqr(+}#1==aV^p@Z-9Y5OOp`_}}vy~(}ZL;7=oE9huKtkny z#6Hi-s4{61njlIsjOi4i23O2~!bg;VJvpc08KFwAmoVu0pn-5CBw6WI{XX6+wsYmW zNILz9xu>rB9GthJ(f!FXv~%*v$cccsKHxZncewnsIt_C>|DX)W@tEAu(E1QL_~L&i$eb#=t3ikk(7) zT?!Tf*P9?;)v#phILo!5%CtDV@Qiszx_SO!w%Ub33d*@a#w2Sp|A1eJVbUl`$-8gO z=q=y5rYgn^zWYHJ@e*+9r4QNpK3RElOuD8$<**APB zXFqvfJgA^lK1`D8F>8Y0lE47$2;)qVlvaEhDKMEX{|(A+%?FyN#OCc8p)IZ#q9rjN zM4kITWF$Zfj&$I6o1$_LA_ShRsVjqr?Hw^2vG^aL$pDmL;+RnFc2e^)e>i|50OqPH+5YLw~B{0|kK(;V4Y2Pu0r6 z_ErWx?oC)JQUaX#)0S0+WOBU$jRT$;EeWV89kPwNyG0?f4!!m3631hFSh)=|hs|<|F8nZ`>`N*imHZ^!U|pQUtOZhn0*~1~Gk* zul4mBZfFjD=@7mnKWtwv|3aHY&%Q5&fE;xagZ@7}tiL^Yzdv?Xae`T^!_Q^`w`bS4 zC-(q3F=dgL63@islz}{VSom=-JVADM77Ra-wt|{E(t-ivFh`@?vvoH3vHl&E=Hx5V!H@B6oB&X3IOGVmF}|O1Pi}XcC9r~-I05dUdnD8m zo?|n2v;^2$IXeQ3Y^|-K05f+xGnmaSGjm&GfTI=E(G1`LbFc;2+Q0x#uC@RtGY1$9 zU;fhyX+ZVgPY~1V9q-0w4vD2D}8w0AvAj0C|7{KoOt>PzI;~Q~_!L zb$|vy6QBin1u%4g8d<`e?#%nkOLv_=1NYV%nL8LcTbo$H+~6K_f*Rd9>yG@6778!~ z7y*m{aN7W;05gC&zye?iumV^EYyh?ZJAggF0pJL50yqO)0ImQxfIGkg08b3v`Uhrx z_hsg6V+wU}wzh&gI{}=`t>8IJV{`aAI+{BIUO;c1D-N@Af&x^{;MpO7EY#Z27z)rd z2Pm4u^RuS#VKqBP^IN|un!%Bd<^Tn2m?;!sVgh$Gz{Cm;z`x+%aP6&Nj_~n6fCa$R z0SaFUsFAZ1-1SfgI158~o)-qNh8o>=9L#M@0Y>oj5Bxd-n8F;a;TMOYl_LNO1K7fU z?-yA_0-yl@z3(_W+u6Yt|KHP_7G7xZ{|DXway~657uSESgzkM%O4z`2%5b;*JpgYL zQ-3xLXG5pk6y0r}4tN*&{|R9DE^(jIlZA(mm>JXoUZ27Z&@eZ4GINAyognPov|uh? zc+11X$qxK)Fb@#Iew(zqr2%n);iLEMANs$Kasb&Oe<<%q|4-U`iGOeJH35S-*|})% z+j|T*1jG)4*WrL~TW+3PD>%5}EjK4GJ0~qS$E`&?oZPpgca-o75cnvV2MFhL%K=Qw z1ut2FZ+(Bp|8TvV{RigdfYWjTIpFr)OZX%6jvoXrnd{Hodps962rl#Qe*HK6cg#I! zFkEZ6E_YJyVNM<{xbN@1c#r?%k9#~XnEf`hc)K$9>-J~v-Aev}?`Zy7w_989;lGdG zTLiwN{L|iPaxWJG3L-haFd2Ex6@4dnW-mHM-qch}h8;aj=) zeRxF)+$Jyt0-tl=@_>2at90M~H*ei}<==MPWA4}O-s^ub_gB)L?0XC^=++YuxRyM3 z*Uev1aW|?9xVuM70s*2>N7(J{^B?zXbB8~X2fsP~70B=u@~tUrBZ>{5)D8olX4$czzInv# zX6G7&tbi(She5u8gv{K4%scD3bhF@c0V6E@8D*$AFQi{I#!iV=N*o#aokKm!@yP=bfcV4L z5Qi~VP7rY7W0If zRXjRdK+Qu28xAABoPFq3wSk{1TP=Ih8Rue>4r{p{U` z4{-%N^?tO`srsnMgm}a#ErhElzl6L!B2h_P8)8`%gQKDj@`9I_it|2|JX^r~d9HD| z)pS!_hU=S;6y({#_JAze7}W{H&iBRfq$bi_G7vz&#Py&|;!%+(N#pv`Wz^Aknxny) zw{K?5GluXNzMD(t=~O+B!>l+`Aqd-T;P@3Ps-(dl>!^uUOIns0rY>RY7!}7&YIs;j z(~*-h7{0^n_@+sY29GVh%^~KCb*l$yA-QeA)%Dz_LHye^Yor=yp|955IU%p)2bz`K zhm&D0O2208RZ&c&UWOEJGM_o45~4Ov^FMUl{i!hZY);q$gTf)m-R#R0hGRVuQFnJs z^7Y|1^kFd5l`3B%A?X{Q-e{#!C~#7U`$sGkM<%$MzYyQCtonOsloJ?Px%VetVLd{8 zEluEo*95h75-|%O(M#NXgP;d*&NhQAu@8HHKDOdA6r|Rhi1s1;Tvcv_r%CLEWGV+l z-AQ2qEr$a~k1xjJE+IdG`&yJggMK6?;H9gb*A4ru?M|qDiJ1Q$CK#1|$)!P6-Rm8~ zZkG9mfT5SlO&kT&ZZ6HC^y3Y5(i|ZHfqahyyva{8 zwDN;3SblbpOJPM)W)2bal}PEf2IE)q?Wh8qnDf(i6H~jBKfXG9#)$KN(6LC-(b!I~ zv}@?M6GLm_vAQPP!KNiu(F}8c0s>_QP9C%(=G6+by0g=T&l5fw>EpmIwdbLTC7JZwZ z&A)ddkG>yL)T}b-L`~X5(yiVk`9yGY2=wg{-Z{$4$x&&8xHAMwI6SN)B`J&Q{fP;G-_Sqq@$v5G)4$q8jnw@xeHV>6?w#a36M=AV;0>V)i+cOvRFmtJII*d)ZTk4tzsw5TYS>@0%Y6qx_FMY>@E;ztY2`m-U5m zJ&%q_nGNb`mN>4@wRNv~_0*ebZ62GdrD`A}VX*PMH|Heq=GlU1w20a}vACgj>ML8w z)A4@MoU{3m+5d=yVrwJyQfhm6DTQMwGf>XuYEO*O9`xZda&)0fCfEDJ$*eMG*B&vm^?zM)Xo7HUusNozv^jtvq|JEH!GQeli zkfvd!6|*8v<7JylJks+NG4DNBL_GtB04ZAj%SIZ{o|L(nSI=AZ;U|L&TXK?Y>rRx| zPsm}yn1=q}2KbNKaXeR&hGd7-wH0Rd8I*vVF=C85H8Vk<(onO9u9e#;hA^%j#p4<* z*$844+)*#bvp>hx00$nYV9^a{DRX^c#7Cd?co+iip4f45V+lNzRCEkl1c@4Bo8t)z znmW8>b*%Tmd)o|Kbb)GH7CPiW7|b%*HR;=9^AG$k*p@1KF*>$UGu;Z>pIVqV%=1hL z6uv3Eo+QHCOIr-yc#D_Xc~Lr@>fqi3Zr=Lw`s;vW(dlJw%)eZVX(M%S%BZpZn=o+#b<@eIX~&%_y&W1E^s4!3EoiC86OO~)q==Q|`D}#{ z$~jYSI+vGD@lgJSNS{-0IBS60pCZr5cNqIwG-mV8t{CnpF` zr);nK9X0j5&1ySK0aojHyyAcjg@2+$Ug*_ToG?Z+V(-rSwCsw^e3B&V z><<|sX-csu`?ha77Ct&iPmZlZLQX1(K#UKPio&3~?D4OlI$+s1udoEvLfB#A zrsW&gwsajq>=q7BZtbtIE~wy z1zcX$Qw&wW-&rPMJS}lyK6E?Z&zCAlokv1Em;ELzV50F=gav8`CvNlr?4|Q(`92$L z`~8F?WgdCOwfbr_XhIAg!|`vEp~wr_nRevdtiE%_``a4c34ttDzspiu7vhK z;@0|U*YkgW5F7T%%p$Y6{EP;QdP_FZt&5#!rg$>JOwa#Wer+Ml7d6!yo86G>_sR~iyY^JXTaS8C4 zCUo&$y%5*YH5hW?%aXJVN#wFTj(3vj@GY2pRR5#*vC#Ta2=}Pa49uf#BN_z_v37gC zX+C)4sha{HLB+fND+(G1#QC(9%m#q#S^zIE69Wc8kgpE9nTltHX-MW4nkud{qx+y$ z(PzWFYPxOQz5}zTd93Bb-&80HOkOInXd#71?BjeJ9LSv)Pxr#~v{biY)d17Yjb`kO zzGf+v2}wL9aYb>Q{CL@MR^}|>1W;-w4LRd4o8Y%fpp zmYkk-6~5w|?sc}HCnotlTA?*;p+B4 z&VKn5@-N)Y^WBb4EBj=ll2XezJ}*!ABZsVWyqZLbSidvl$T7(I1HM8YjHq!{Q_D%Vn687^>y zImPsha}!YS%0)?L_L+XqHz2k?%kb-{0cgK^J^Yy19db?cDBYtw3*p;? zfyo$IyM!(rl460g$6`pT*;sp8PWHPx2+uBJD&0oh#q&l9@_sr41RCp@yYkas!H}+$ z_O~3YfPIT>6p^YzAQD2E@A`)1DmCBSVr#1n62}*gng+VdAe;dfmp#;@$li`flD9 z)Z3hmPD@9i-J6T+4LyACvcsZf`q|4~fM5Y5hGP-?OqgbMlk68T??jbkK3=4&){J6w zqXaP{CzD0t{9&G?>$E3vDq8Y+2_>cIx1fOLbXBRr>I@^*DQQAk#g}Iv8O$pmh0w`) zCL%LAw1y|9Pz(<-Qa2V-TVO~dl@z|DA6<@`!7eG3op~r+uv7?qUy&WniOT0P2!(yLLOv8%-d^g84)}PXn#3lTwGQnV-XYlq znMmy^Gxtr^eo1FJUEv-*z{~Vl!8R7+@HQ$;9IJso1JGugj=#pqyP!bS!=(otT99Z6 zzn8dBeKbs^_b%+ADB%EYg<`tLWN6J72VJ_PG~NfJd43&zKKqnTmi8O6SCh<$N+Cvw z?o|cFu;iJB(E)Q=*RR6WyZWrfk{-Qp5s23vt>2rP@aUT9igu+O;#w9jW zn!BzKHR@ex(Q^dqjM6XGQ^FWg8}8*zX{IlfE_Pi_%qmFA*0Wgz^Q_|?RB`9a{AN|-*^Mv%sL>3QbbFlkA%$&X$3c7Ui!C?Q7T$%v-O z7IUdQvgdr0$kLFJ0tj0%ak3@JVC55jFP2^6W+I}%TA?e|Y&4=@PCWos%e6!OOQfV4 z59MHAKQ#k(Twc$_;H0E@rpuvwmTv5eMQRg4a@DSqa!K9~?*xr3Qu%+R6JWSKHoTgg zeq;}9HIGqMJq{Q#O5#>@K~l>z!z(GPm8HYhG-oxk&{RLd5fN0HVI3zy`mirPK7D1A)bN~!^^5y-#Ak{@_2W2` ziV|m1(~?u6nvf{T#E&hI*9PVJpJ`6sGR@HqIvhnK<9eTz@~s7Hog#|@N6?Q1E4|<0 z0$3l4)pb=<3`B?VM#Iol_&lM2^~yun59(*zrK&NBOfE0u2GqK>jFYXf;+3GVrQ?WM zCHD!Em(H0_i|jVedRk`MBQskInQu~DA-@nD=K0wiX}dY-Of4_bzK&F%yfdR9_xQZO z{9fJHtcwv0^ukO3$)%NLZD*ku+T*Fa&{&@V$W-I*VyGMDt?hiBT}ziBGVPN?Xp}gS zYRTZF)tJ`djMU1y!uX;dDZv3_j)^6Q*ybcLu<6YVeUYBPP2N}X>ggOHMWlCjWeCeP zr1YHfC@-ivAD+5v#K}d;WUb?djjyvJ56O#`yetmIg)IWD7 zG|a>D@gNBM$;+kf{urc)=egqXH7c-yET175HJ*jIRh%>!kKZFgfC0c-Z{od47CZn; zuQ2>&kgOx4;2<0|?EC6FanMh!RMY6rPKkjT4H2W=%QcCf4Fi+?oQ=%U9ce<%m}{*0 zxo0j;7$q2#l;&^V%ZhX;HOw*Ese)f=Cn#&heM`4;!qd6nXgKO?#1clho&l&<6K5}X zMB^DP9LvZuDg+YZ8V0_&Ru%GZ6x5rfJoQnS;rZGoXRntd)06U0m;dS4fX1;N+rr|@ zX!^H=e5Vn<(arpmo3vL1QO|C8Lw?DZu%r7$oHlXlc%-A6tIbGz(bH-sbmvNWxULX; zMthT?yR-_jw=72;k!jm>XUq4Itt&W-Q7FL-IBdM3BAkg=Oz$Y?u=?XPE@Lds?X>WW zLkapR&gD<38e~)ZVg$<)R}|%|_t$ezUxj2}%02OsLdbSgpycsxQtS>2msy&=9M+e% z?6jj`5?MbnDC>RAtgK>G$xuq+Zmj;9%INTg)R;Fer+33Hd)CY)DkBo{DgipML`Z+O$wqrl81vHQ2hWR96CV6=FKJfQ z+BI3K$HrI;048kLzLuk@~5Uvreoqem&zVi{R6-PnjQ+ zpFTH1M;j(?6g9deJ+8>V3>;nNqGs3X>B#+J$d@RYsrlRGblE2(F1Dvtnm$7R$9Gr%)q*#; z3ceVYjLwK$Xjl1eN2igvMRwjfQ_G@Q?Kp_ucn{^q@ltG5g-0k#$Ss(}v@Zj6q zP8+?XH3?t{aa0}b8HB0-kUUj8>F~=JnSxm>sAYZp8Nk||XrzjS6Us(oIj5>rZQO&9 zdTN0Zx~Lp+U6)De_+O&ey2wf!g0D{kZ814!TIu_1qv}{+Txc=ZkO~73PfD zpYCIHLX!sFV%fW14et$^yPPp1UUDwj+J7Y{bmrFRe68;ORgfsZ=ejx|a$!Y{Rd1p~ z|C!sW8j|gUey$(nU9KKl^Lvm6qv`I}a9$m5Z!3c{)Um~Y)0c#F;OyAn+c_X2JW&Tn zK=rsbG74*y`t(;9@(~1rjFZ8iAJjB3b(b=q;IukU38s~&X9_5iPWVB`YlZOG)TwKa zYmD=9USzN6*{Cxqr-m^!p|=%z_dD+M22I6XXm6W6+GjDgiKsTks|z5YgPc>KlWnO;$Q7okd+w94U^~o;nm-_^4 zn3Lqh&X9_4Xqp9>mZKoF45N$D3YrXx!sqJ6XEc`P2OoVjLEam)!eM;0Eqqhkq$8Wx zv7Of^1re`CfQ_Rw0v|uWza$H6+tz^wZ#aHZt$Dk3DUMeRay}&E*jx9mZ}z@G?$8EN zyqEd-v`*@4-gRB zB%*YR2%PPY)GInMRHp5PfH^LxBy(8Nem$GdnL;(K!$2NSY!u1|@p|gFk6bmH9L_9_ zZOY_q*NAKB^SruStxP0Cf4RCUsk_SFIZ_as05 zCzC}6IYOz^`qshiLp&_Zt%o9JK!htbGx3b+^#ZO{J&cb|b2QgGAKn2UmH=bo*Jiic zE79{UPcdg5*>Nkj9!ri`ZrLR^r(vm9C9-YXY19Z=RY5;Z<@E+a33y+KoprIzgeINu zn!eqdGb^SuYcSaT)gCSp`J#|G_QR70L4D^@Yyrm8U}~D}M!ARU*G~(jD81cH)Hc6= zi<|qZ!G-)pMyAzbf#{P`?v9sbxs@!-RWPk>y$7=IWQvt>ZI0XeZ)5O^0{DZ!|Hb2e{C}^#Xe1mWT4h3CL;sX$yHIF5@0-h*2L9|Z#8l)R9;S@7|De)lu~ z@aE)zTMU0i!e6{^so)1 zvW2_igL{|4HU8sFxFmSN2^S~amOFplFVWqF^k=#5;M=)>bcUCo+c2(AkR!U@;wUdLPBcVmB*DscX%RN=oz`2YJ-h5tNh|EE*| z#KQ~zpO-2?xZ!WlxqEj8d|82nsd9_d(?_qo**jIT*eJ|}oHU!k%L za10tGy#bQ;QPW)!&$`amn6S|Chgi)r8p|1n?D*vGZ?$B8%{U+MY+A}#Yb*y$AL#s^ zzTq8?OT@52RTsr89o<0|K*J<@`x5EtM@dOVQUs#6es1n+!Db9-Vr?aK(q`rePZ=LR ze5bRAK#J`5QYtJ&CQRB-xXBN_y)Q7hs)qT&^;1NlVulBdlqtbgBC8K{8TzOra)M`Q ztNb3fqXaU!qayj?6Jsn~jIJUs2!F~7u`zqcfr|VF@kuxqTBYPX^pG}&CLerMhb(+N z%+Wu&UGa`0<(ufy!$TD>bOgf0Cy3O$53)w;Xz`vSZrGZICf?MP-E>bLtnQR+mQv%N zi~Zip`pp*A1+ApMDWzRb(~&l#%aRd(A9ArIBRArkGA@zBQQojrlfuA2Y?Sl5zBBtl zZ|39hFuu3plI=hS3Qs?ACy5)(oTI{}=Zc#@#{Gk1-zU`h7cUFBUYZg|b}dUwQp@`e z{C;xNH{uI~35sKqaRj1@(JH=tyzy&yV70!rXvG@!31)@^(JDSdtdzKi-;*to$M$Um z=mv*Rz+}R4ERhngkC5^69%f;7V^lKYiU<)uWqJ_It5hc{{44kdQ#$wooz&Qp)NCs1 zv2B1Ttsm+R$!kQqZ~D<=mNyuoNOVd1is-oQzcAhtvRnhCV(6{|-svUkM;pF7#ZcC1 z{2f3DJI}m0_@t=L6#cwi5do8c2&oHd==b_v!}JX+=(ACp?r2J}A1^XuBh%AMkj2_d zhU}x<%zA~{V|}Zz_i4!Fa+33Yu_|8-3)$ZAK6EV=s_Jh_6E^3P@Sn(Mi33qOaU=)1|G!RP0VNy0g-*F3{&OSywRneKFEW`U2l= zS+;f?FD4($Ni#i9E6?C<19L!vy#+?Rh=a%PqKIA5p%uHJ^OO2QLzVU|U8DE|F%t5^ zTZx@ z#3|MsU&9^M4>%Xhjs|nd6o~d35?A8;@p3@PJQI zyHYf^+&)sk0_zfc3<7;$vqOlfx%rY!vWa%4K(OX{e|N-d9{I4k+=GqoMhWwlpvNDh zi9n@{fs8wu0l%PueU-0C5ld>~-X$=35NrJzJv?kSs z0E@H+pZBpC*)vat*HgR*`8>r3+}f+l0FO#GPIOelF>CktVtYaq8(>}fnM$20*xn3l z<&-OCfZ!Mb8SMdsl?KPVPW21@r1dw3*eDbSOQy|Sy-~1{d2#Ns^w-7KFi#;{b&jMK ze)g&J5zjR(MaWvGc02?v6G9VnF;+JZUFMdn1=#J@?eUXfT{aI))IGKS(5^RO$%z;< zZ&Fw4jcdRSt#4MeQ+e@>_$Qt26#FxQgu_Xki&N?~?U<&V!qFew%a_>{jx9csN#B}( z(LV$?Rg^Fy*>H7mS;_$>fQ+niBf z4=^+ywEyU2QMPxJAb$>r52p5G9T?s-Zr{cb9YNo;GUMz4F&Qi5%}q4D$(R>|5$0a+^6PATCORi1$|~=yC1$ z#KzNk7sp?i{ThZfMAI{F4XabQV^hA0DedQ#jY?|NCw7s${J+?H$0*C1ZCf<6(zb2e zcBO6Gwr$%+rBP|yw#`bj(t26nx6j%8+(bCj{p;!)BE_s2{i8rnYqC zP+)rrbBQ`0G$mNTNZJW_8*3w39nZ#dHQdn^@g-(Ar=#Jm5uPKa{a98ILAc|^`=IR| zU+Owl2>A~jcDlbG=e=(wt(w|PSoCM75M%pp&D)YRR3LF1=+pw;CWJs>5n)tbU%%i% z)lOu*-bLl~vrVoN8pXx&8TTl%A1L6}wA*j2v-LY_@>d)e5Xk#vaWs4f*^wI=ahH{R zzn((%g@?P`6|oZ9;?WvzN!h9P*RQtKWZdlvO#8CPh$Ch2wA9Mt(;Hq9Ua7{VBN>PIx);(XE`oK3Nvh zat#wBz^$64=aQlW)e z;ahrM469MO9$=MaZ$C+t*UnG3-1dT#t$9`Rxcoij2{nlCBsKS1jz_FZWy#k&;(1v# zFoau8y562Ngq zkf^0kA}@|KYVcr_L#Lj(3_C21*`d5VZI$uVMf$ps+LcB7qTV0eS%^r_AS_rGQ^0tL ziA0;2MU8Y)Elo2*1{7@8gLIA=7W#N1K4nPO4?IS^Ho^ru-=!NKMN2Y#<1?ZXnTseR z>zqsL5)_xfYEd@$`ODh*dU{grJW73y@>du`MFFRhLzd%l$n_NmHj%ZPhaYux^a0 zE;R1l(64Stz;@L87QV;8qjane?!aoSw!9zgn*sb&{oj)gcpNq5n~6oPP?QI9%>Y4c?8TFpB}Q0_v5G9Y2s;Q%&}4&ml~9x zBLZ9X&nPO!r7VhZb^GAtxV8hO-lyPZ;wuhr&fpKj%taME9v?zWYwOr&_;#JY#A~1)Gn=F0#~^$E%hncyp3T!`^rL-Ir#mO+Yp% zZd8jV0z9>I23PCDoVc&TB!cEF{QWXp;1k0MUYEr|Mde??6Ag~FZxmpDnDL6*c`#ZF zc!mr9hG@ESZ77Mv{Jot;;eKcU8-vI>kr*$ZLB|tNrb&O4czYRF!$Pe#{uX2u@fho4 z-MG?)dcF$K5x&<}H9o9n(LJm&E-jOM`#5E-)III!-Y@VYrHPfqDmg+TrdEY6Qu};@ zbVAX1*mE|0xWg^ZoR|Y&`@R%?xKGDs69X2?p+<`#$vlhFYcFDti?#5ZU3YD*FKU;O zkqLoRM{A8vp}18X50ppObHT{d{QlPD*#JsH=JZms3k6o!T4}~kdo|l9KJq<}eXbl+ zzD69)CLBTUMQmzD^+emPo5tZV4w5WaU0yFXV;eV9#=U;T%TRXM2ks}Mvig-s^gXNN zWJVaj^meJ+23EABIwfcGnTEJ6{)MP3(!C*eGjkScL7NezVdSGko-W-Y z(eDLT%E=OXH*)QL zJ~B|b&hUzFU=MtQLww*wF|B!fr3j9Ko^@3rnqm4YH;VM&Ag<4=bd`wqJOAQD1~Dq)iZZo!g zp)h*3$%eyhV79d8qrwpM4~>-%4Ts$AV&-ff?1zE*GocAr$+9!R(s^SQ|0^=0S*<0H)URJB%-R^RFesR!V znp;0f&C-arOi}=zeR=afA>Ty7SM+AZ2*dq^5ODU+oZBC9w|^!3{fC^J zqJ*Tp@K?@FNr~YJx33fd%a>RkD+kN}shrzCWa|D%bN;V$Zhy<( z{bxBh76#@&nWq2S{@)1ve~iF?KWX>hdFuXH|L@%Y|HHlimd0cHmo(mg{L%Q=JlpHw6{n7>dq|AmSq>%XV%*#BtT{++}7PttbEN;nrwKLWvALx0Zh{9J8m zZ*RYhZbu4eZ@092+_{vQ0qEVN5xf4Fa{ah_Ja&937Tvx-F3;3(oOG=&Q9)s8t;0+N zU+G0AJkh%v12zJ^{WgFs+~{uwfX_sQ$kLd`G%&C@)~mBIfYJvAaC;2^NN9r!z^Vce zmxwknHQpN&Bn$)ZX!qNpsqUu}$V|lSd;cH^d~G1RW_tPx5VDjO4S|bqa9aAxw*~Bp zO8jb_2>`#aDjNQKJW(xxa(J|`dM@CJs32hAZ#^m|)c}fN!O1*`<9vBW=aV=9TAxY1 zHZh+TtwLGaAA8?sJ_g0Xo+1&?^=!{T0E8yu)sS&MGC-dr4?oe*e1-0>b`xxxnj%PD zKEpmeI2KgmdX-!fC9+5WD#&tV~@jPuKd}yq115g)OtPvVSK!4tgf37OC*4DWy zKRUc!ZTPNyR{MX}e^~NNspJ6gsFQPQ()aj@{EcHa0dmde>}mbaW0~ z>-zr6_H-8gshp|#-iQZ2fMgJolpJjdVmu%=W@qZP-Y%BE$lF*HwV>>kGi9F}%f{pp zYy~y^HqS{t@cr2Z`AV(qI(Sk}*Hcl&{6PY|si<1;)>8!c$9+c*Bp zR`Pv9wDAPP$6c^nJ{r(pq69n2!yy-jXyB0U^G`GrMZ0X<#MX}Ju^gVuiiNVI#=dsO zYJ6-y5{dcRxs?&=OJVnno$#l_c*`JxZ%D4s-pNi9g0Q+bQ1WY!9YVuEaAwI_S=3`B z1zURMA~2LM$8Too8QXXXFpO)A67^p^97`)5IC5JO0hv8&__4iL^FH~Ux!BHyl?mkj zvckkg&y0`PAQ=QcT*G&{Xa#5vH*72<(}g%{GL|zvXjV^vrpoHg5^!$IY>+7uFsEr< z8T5OJ^+)-R!$?I|9zb$zCv($)*B$AI4p`^Z_QKH@aq`Cfx$LOA!~p7wRg;L9igYw< zPHOXJr63fkLkKq%YT@BVZq=@N$(z@Vfszvf*Ndq0QYuD6BrQWV+<6@;p*W#czezJzF!A*R-8I zBKw(dy&Th1WL;y}A&0v&EI4>z%zv*}=W%{+UFvCF0zS_)=p8Ve<+_m@)W;qf?hXy5 zPz@)QmADQ>cLN~W(R~YpiV-HF-$q8{+TwL>HDJw19t;?Z8P9VD8ySHE2|?%gf?ya? zixHZm6}dr{`YC**8N{r%=@PX|5pN&kO@G7w@ETU6>Nmy=)vrcH4*BY6Obs;Ub9>1S zu=2%@gnf;eBqyZ0%p`z?HAxvD+7Zy>AL_NS)Xv($>LsHyNH@^9i^ry2KDcz{Gq6XP zm?}UEF*U6rc>5bJRgk0=Aa)S=vIuP{008m{|2Z{rb32 zAS?$ItIeukfy+9MLmc4xfpt=I%~OFkS3fB0A-GtR3!IEpAE0y%~Za632>q*`<&9P=u}W`Mb$ zu2EAxAtO-}z9;y&KZzDH8Go-kjp&%m+H6 zr*TnrnCac^0WVE6nSO7=FD()%+%Qc)dt7jACZToMAu`F^8Y(0)(BP#9#oy1DC&eVS z@HXde07<5Yn+l|3^l%Yf2Ti7Pe?x$tDcI&c^#YxB;VW;oQgMT3ST05w%sckb7ZDLXGZxqB6NEmlxx!G$1os0#Y z?FiAkF*HfT{87AXZ$Iau(o*;_nIZQ;*aQIgj0sO`d&Jkk{JoYKv+f z%-|Hk09LSwgy~D$oBxz}0NyTeVy0KND`$?JfP0X|845+&E(y3s0C=}Y?Dfz}?s75+ z#OFs*>2%&}<9bHq>LMY4_gz_X;z#m&gIM15a)^ShC z$~^qA>~wj@hECaxOqIMU03z-c<+L}5lzo6nftX=F9VsB@dC z%*)J7R3nZyF-KnQf>zfETh_!H-=U$)rj{O`+k7hnDR35yhoWXW=+N!aHlIZK_gnE_ zb+Y>o1Kuq9)oOp_88rtDshn2H*GIu9enMtoemdzH!w_6jTBi=-{0cwwn?&ev?}#3e zZL^CzjbbMj-Ie$F88Eu#P*$qYoKoH{ld|Y&(J52;c2Z@6v&+;*G(Fx<8LEUwm@q3# z<(@ZwSK=0yRpj1fGx6R(Q7ILs8qtAG5bOI#e^c zuu^PKvdEvvF(Ym?heCNvaRoAaV0m}l2{ z$I^^2bF}{mf|lQjHFe#!pdcQD%Bc(|-;W|4<_$2y`+$I|+38hdeu0y={X&A!fe7vl zM!R24#lz4@6YBAp`eO;U4!4K9nutl%{c7`0eCypk$l+0l9rY;Ub8gRW(* z)kIMU2Ju_6JlHY*UFp8uPBY$~;$UPD7< zA(nOfa(jJ~+updA-rn&MPM%dw_%wnl&45xe1ay2qE1x;hUdxmZTO>z8oKXq^oNzg{ z@DnIAxd}E$U4r=3dl)N3g3-iTJioG;qnHBn7z z2fHX^fH>aiX-@ReM#W_#)wD>K94GT;^|BrkH7~8-p|adB-6g~fjQdhql0c3v(+ozh zDTIVb^Ec{UPfb|_#rf33yGphGRmG_MNYihyX6`QwSGD2D`$76riq<&8_k3{mjc~AM zLDXoXsxO(Sckf~fXsh&Tq=D(!(~VD3a-q4R*8V=gs)@_L48wsU?b-Kt@i6;0`wu0h zqRcTDq&N%u#>i%hFJF*2BXbEJjx;5lBryQDrD@@X(qebiLXr zFB!5D&Z0t&pZm;YRuLHc<;fJO->O`3GW_Ct2z{x}=!61CJ%wNBqQYS>$%S+IOYU2) zwH`s@5oFS~_@ZiUlHS`#7}uotttDNhh#_Tx9*qw{?QJ4wq={I*`|mdhxz|$l3Ggwq zP)w1zMZ9~fp2pD~+BD~8rxd6z&a))}UgNImS0xpzVu`!+IZcNz?mtkj zuizY$0PNRfnj_*r+FU^cF=N%qonsx(O&ze8Jh`6evOi7R&AT7B%3-7l%(|3~vr3xs zc*2&4@-CrbdF>HJ`W~Qg1su~yf_X9sy)GQTE*ULCISkw9nk;)zUnPqg<>P!$-<;)T zGNf63VFlPY)@y3w(!j#TpwBeA2H5n%i*Z#a4Wyu|bn5ekPhaz4a6|D~`N7`+Kn?ixYq!NScvdz_?_p%;a1bkC#9Y?c+TeYi5GM^mRTZOEX zU>CP1v+lJu8+tVBx>`2e1>!i%NUnYe5(}VeYZwJ_G&x9bAPJ4WA8>;kAtgZkIwT4d zVXq+c7Lz_L}+k043_ye7-M<$=rAZzi@f9Adhvg&K##XC zO?Z#Qsb$$zfwU`PRLvfQPvWzq4QXEy>Qp_AW$c~f&U&1EK*bM?sKly%4n3!DMF{Ew zq;~UzfKR7qSeaPA4m1xrQiR!T^q3xC{T~xK+m#jj*By*+-Z5WuvKeE$WGFn2H)d~=+OHmkL?!Y zG}vT7`2da1lS%U#E@VPr@#_HrViF)8QoGF%a%G1`cE8sqj`4L~b*%=#tvC|x)6Nwa z7E5i-83@1Pt85KVc}&VOmZ3zsG4Qul0Wc$ndKH(DEO-!5OGK-MVSAcA=nWXxpW$IQ zh8z6yXSX<#Io2(oeF`-(8`X%yve+KgwGvke<0@2uCYm!nLGC-RmGufFuH*s$QnNp= zA?V3XT3ZUW;)hl<>Mg*XDk35z^{tI^E`{O~qO)xK5}*7@VhX(6LzN)dN*zc)+dF$` zlXUNvl`mr(AghX=U1vZx9}y~}FV!ng4m2Xbw>G-oO%!!9C3D3lwtJ|J-j_-sUb>-| zb%Xd8NY;(3aasfXAdkVMFSOyL{8tmGA#L)kGjqfwu|G1>M;n2Jnt3)#;$pdm4fK0hb`S&I#xFo3AvEOJ;OjG zzFl4hHxgeGJzvlagvW2hRID|QE!V8|Av%ztp@lwzHS>T^5}ed`^{ORNZ+#F|hsxeL z8)Xq|aFxxmBS}slyZ1AY9CPS$!P3f_9TrdX?Z)ZU=}E6^#tsze@eQ1lTcz1Kszt)g z;wG`)S1O;V0$SA^ljgG%`RbI$#8n(J@juN6Y?jnJrFD6|@XyKX>$L@aX5$q0QL+XI zZD8jPn9rgu7B_dwYL8@n8*8_PmiHTiqYrYrkh!4&J4D9oI#^~iQOKHdJ}P~S!EK|| zJ>01+WvK`#$i0y}yzBaEj)vI|qzm^hs2a1m$S|ZDNa&g0iX{b=5@j;hn&9o0djmd<=Ndf^KAtyQWq5@wLGhV z&fr!Sh2C`2N_SDY#pH6Nfd+S6n6Hzu1y+JYx3cnANbpvqEv~@W?Ho#Y8`;sS?OfHB?60Qgf!#}}^P?zAz-pQD`PhSK zN$>U)#}hbe*(03Oks1Ilr44bmKnLpei;X2E<|{v`Gd4lfAo*DTU1@yt-S?^IvpKmH z`oPc)r|gu-1931urqwm2Q8miD-?%^v9$b0scW!N-n(P;K-PN-dQSgsHOCEqGM~x66 zwi#zDa4UsgOJWKPCE*YOalCF1P6oiPD(4X>Dc&r1a zxvOo@prZ=!bpYnS#M0o3<;Dr%&PeT6Pq=o*gbSz@rIAJJxH$b7=j5 zKe{V`!sh_5K`i9BVq|?%u2n(0NIxPeaO5&LnC82w<$An*;#%xyun2klAcHW9Ikr)F*g!3^ILXBqrrp45lh-hG_Hvgy@nt%W<)l*ZlL zOT1GON1yg7)Nm$H4#o3}Z%Go=nwhm3yQKBmcf>=xOQO5^2JVO3P4l~Sylq4j6ax}(PPv8*2!m&b|;w}%#MN=xwz0^P#|&lR@?tkozz;U-HWx9 zE_K#UL!zr*K*IAtG|ylF_eHKGcnm;>ssohXr9QJzO8au$>-@P{!5(HhotC8a<}C?c zrc=oTp|rC^u|nN(1kf8{XyM6Pbtmq}49=h}N(!8*#Rgs*q=P0ZH9hX(nR<66? zS|Vfm^^wTc8X}^W{S8jZSttTiHwGJvZ-iauX>crF=ueGVaaT=iYa^~+5APp85=k6) zLF*?9uN1UEuzS^tJvmseZF0RQEYtcLQ4Su+1qwF_8mui5z`Top?Kd_-QTLvhGUPn| znx+Hl1}Z9XH~0Z|gBV9y1kL`ex7oXH6l(3Cv0XKC)0q&%-8C0HOk_w!&p%Wv?A#SE-3UgI@=!;~cX%Fd_1<5-^kf;->o`ZHgP4)& zuSP(lP@^NZC!B4O`=`sIgl8+$;#F)P;ldH5htPz_CjpSJ(nXc~jA&x&Nf4fUUSg7@ zr1yEBof?#3ZyTCRj6M9aQO-TEXMU86wA@Oa0P``uXa?Ze2Yzp14*oCTfk|O@=KJzb zl~pJTm9CRf4G6jIbYv~6eWyS%e*Dr669}`C`d64^joF?v%Axcd0n&63EmKdY0@tAq zt?_28YPV2pj+q{N4pLKC(sF@0w7WS<>Up$x0q5zH&)U6e0@Fy;)* zbLCN$RhXD{2WT%yr~y6@+A<0*kQR~|CIoIph~at7WW0V!;^@T%pEP%%gs9o~=?CWv zWF{5GpbR)6t8)~lADW?1zms#MSLCysbz@YHRHT1vB#hg1Ln_Y1>2ALwusT2&E|A1| z|B3n{E^DL8)}oqU{j2IB6e8t}QNYO)c4d+3PG?2>>Lh>A*MF|WgnRdwCJN~+5SyW{ zvG}+p+f}A)o}wK!>Q>JadI279O9RJNHsM{mc_PY27b_JG>XK6GJ-15G7y{#1b%K8G z%=QO%uH-wt>EOuPP^P9{$6cZDFNEgo@87Z34p6%f%EHH?_BO(=t&40|=?S}uZuJ%T zCF?Fi_%}!)J6(U8$;onO&omF*aBkCSLX@Uis&`F(|^5ro-y%8#h?Y$T^ncr>@s_mOMRuETniMS`FDV{t~2LfLTX1(}$Ysu* z>4get>|6T%qn-iZnpd)^Sn=muDZ=}Ci~W)7^A?T39Zx1$|MYZ<%QstdSTZ2I!jRpc zfioxDab?I<3C59yV?X^W)e9ETZK6_>BhElBGbOlIKP9wvVDzq&u}29bpn6f$e)uGqjP< z2bO!Q>FJN26*8eIBE?BIFS+;B#`(#0e@KOXg@f1$a`pNQf3(WVGSgT85*5bGnsO}2 zrn`oG#M|J&@2%-ukn|@f64Wc_#T9#AcVCKgZP-{?J@BR}{RHp7p64jKVd@5D1i>I6 z4L9|~L$P_Z4jK4BVK&crG56i~qP)uXk2^wI->3^@dE*#NjP;ww;bp$HqF!X;DpM?m z`}6UMC${JKzztX(m_ey`7&oEeB7sX0ciLMeOrdEmB(cbA!{4$Z-dFZ15mf_nx1mOV ziUC5$1k)6(XIG}fOK66rY$lC?4*=9}6%jcI)KQC|yqOm$7!2(sJ(3#*o46!pS`^hGwN)&rf2NgSejM zt9OG^#J)OWY!FXk9>|dAZ41lfjhc?!a5g5djTp@w_k~rnk$|kYAirCl7e{#Qt za}APB-HX-i*O=QAmNaEnVPYA%sBFQnqz|AdYZbELE^(KC=X1axuIQbJSgGc5L&NVb zJ2;)lV3sP{l0=dmAbev+wAY{rXT)57xiA@pK&H6q^jigolL;<#v(?#mHg(9}uywQF zQKU(GI0Ww;-(L~}M513nEAHoLZ>-R-8Rgf@L>IF9dV3E0=OU_=T^9gHCusr&<%r$} zdsz4*07Z`f$ zMVCHT@Vzb)GUv2*HC#xZvL5}=N{-Rq13-0mC3i6l87UMWNPDm^Ox%@k)~hJX38Ns8 zyq6&ayXO25APRAGO{ELoz7~d;7ckO)HRS}Ax2d={`HlDW4-C>)Y*_=N*6JL_i0e?d zOVnWy11)%-6}V)h6KhFMw6J%9F2c|cI7%4zVqdmUNd`%H zfjAr?_-WVQGWcV{pSjZB{$JDG>x^Yt{GZdWTSx+>-lFmhm zB$LFu?tj&ssL4N5J;CneEd`ABAGw^&ro#<7)sY?L5Hhpxou@Fy}?YcwjSQB7!C7y_nnR z^=*d9@|h1eUQp=R=3#q@)${n;;`{_=@+Nh7`1q;N1>zata-QS%{>mPoJc?!b6lsk? ze-+gf)`=TmS7E*tX7#x$vTDF_bfjwD5uy+rG$Xto>u_m?8Q!~nt6L_-vP%ZXBGi&~ z-x$>3#)AfZjE31+%XZR6O9%zq)c@0H6*O!Cv~E%O)okCVJPoq{_V=em<x`=6!a+)8yRK*oE%}05Wgo?8(_`^S7vp?h< zad7Wn`z3jtCwfyQr_;%8o0Hi=4OBIrL{*sT+0`^9RlZHsFhqnE|D?IrlTe=YJB%vz%Ub6uhfP6a(g8R8&lgk(#uxx z7E?iMyiWjQE|_`$oKW3xso>gV0m4(dtna6p^nrl1weQSjOSB4c`E+^R#S^O^~hVy3D z@4`cbH@~yCI)UkTu2G(`R`u@!O;=8!V0rDUrfL~{Mi7b3tDgkpSQnEGb(ZJPK;n>- zvTLAI1Pv^y)=Qi2;yX?`TZIkX*gxpK8EP@OLl0wm=eF+R%bcC3J6PJPyj_BGaCgCk zC^>+LR_=+cf4kSx3#e-Z8K&42Z=-jQKv{(exYwUqa5zF)iC`R48f!u z2&AUwd{AxuuIt_IIST~WH=^&%hf!=mqrnPpbLPH({Zz2vigX9V5i&=9520LiBN2nH zgQTEH^=h5z+!KLnh{H%(mJe`E5g4&Gj8Kq^gH@`xg83dzVI zy55kC5n#0vqf_B{v-g{iSe3eyd>dixBOB|-VZJHh@F$RUx?f@8L;UbgxDFQIeF>7H z3vOv>%EIN83aB;eE-(_> z*JM8HP?NXjB7!-(AxTE(o|_rS-dsknlpSB=@28+cG}*))Wnn2v#K95E_Q198oK&Mn$Z<$N5+CZj>+@k}k$GEM_~#lOPPFnnW6iY}$_@@DmqxALYUq zfGEwLvFxK&1l)`$flmTn0IiZcPh0(PI5*Z5tnRo<(H^QTtIQs>Q}UJb=ccyYpe$H9 zS6#}Nm7l3-bDwZezJxs!s0MrIr+TJ)R)Imk`2ZBrGBW;iSm*y(!-0XG7$ROi1*wd`NI=uG(Re-V6{ zzf|=9tdRXLUO4NQ3OmOaNBT=B{Oi;K|LXlU&dl;BBFuly^Y>o;bL{U3 zvHW%2KiV(re_LZ<_~Xo9ll^P^-v@2}9pt|q{|f&RUsC=5i1*){_Gc^qz4yoF z-$$%0e~JEodG==!f6wuE`yT@HKY9JHEBJe3{)Cx@?N9N8f7z)tZ5k{Yz5*e+}CFcX~A=J_94; zSEca(H`HdcViKKp{gGzV#Y?L7dehhEqFhmt!W(Xndx)=J@gEKQdLq~ zfI}vzDi8F~pM42+Y_0%yZ=!1plQ(>lmnKuRpLT%cpVAT_PoeV*y<1CAdKMNg@477?6|F6qRaG7Fo89N1Je8j+Y;}Jyo4Jr+T%v5MOkb*yfo19S@4m?v zY42cJKLam(Er|{-j4X`_jcoNTLG|8ZlaeD_l1tLd3X&_rNqRO$mIlwa-I+Y+KO?TE zcRpZx^2#ZS^NPgo_g$8a;&G<3K@KnuQ7RP0>z6b_9hv?Rb;Q_D1 z@(#|TMdXlnn9PesL9~u6HjAPP0>O!xiaT~HmBbhnE=2mGSt4@5O13=9R_{wFbjV|D zt;5d5zdWe78@5sDuZ=%ozWAI(8;euyAox?5))K<@1uFe98^y~4j>1xaiftZLKzZQh zo+-Th$HS%RFp#(wJ@auJGyVbF&>35yoa965@A=2N1YsxBLf7FHjXq*oqtclH)q?L= zx}j;E3I7MeTaym_klxoTByh&!ka8$iQ?+OWeJWCHmiFnB-fa zZe)8GC`qF@?PNwmCBbYDlFs1k+u=j6vKV)WzEa5%3JdwQ4Oy~FS)(xNAQuH|QyOXg zLQ){ek;??-U@UXNZNaiMeq<0cwwwZ~JH=CmFA|dx2**~!k$I_fY%-h~0I=a|yI4Oo z(D4snMHHFzFeHjNWKI}WRf@Swe-C(qmylLU3&d~qXH!3Do&(GSSXBy$76_^K!M^6x zw!gX@DqV~8h?`WWPzT1pAFmM7+}mrK1;B!v;nyZCExQW ziaHj028N}Y!!7CI|FP59Bf;_DA&1Nb2m;A7;pW;q4;# zA!gf5-9uJ(8-lSaxc+f8ig@nGtPz>SgOP~k(Ls~;_`N({Dv~dZrS6s`AXhPssz0#_ z(e$OcCcsh;y*$T2cXmD+7-0Dr%%T{#^-BlQ{ht1#V5eD zd(0k+nEIw(#zRS+e>euGoVqg0vP;>UFQsK6+a3K%G7-oHo#{(#;ZDSwGNJI#ma&lF)%DE~{hKUSr%}Xe5X=h5c$#tTpAroVY!V znS26pTh49^TrQOKgtsD>@1u^8vUakh-ugxWYdA}*6kCukSXGOcm7hK*)sRAV5n`jpcnW|<{5iB?hT zyFcG&Ua#Yo8f`A&?N&e}i!7dp4uCcnWzw3Idtf^gn_K6^Z$A9t6pzQHSvQM1OmMlazh)4yyhou2J+hK$T`_WlAm;TI>VUp73h7hb~v7hx=aO^f52g zC9i)+%j1T_>SU6*DL00;H2p3-t;RWfXc=9cyn~rV$%A85{GM9Zx9>GA;W@MeD@8lh z>mh}L=YfvSQC8PtkNG$ViMUQIvEED`g;BbN`eOz(_^g%PWbbDwvLz{GI& z&p945OS)e>;ZKoPe0wWOjxagxmPK*UYW%Xr@|>?-=x{*WF8=D02HmhxV75Ki4`dWw z07>pA#$-`L*^?%oKD&G_x0RMs32_>)Bb1 zS#5_}r^QmBjXf#kd(Tsarp<44Fd@F4{N5d^6^_^>lc9i(E>%zP5vXbSYWC3G#vvcn zkV)#))Gu11h!g09^8~{(W^9*{xe!GI*C|Gtiml-OHtok`WcfCu%1a7xxlyR}WWO&| zsoDxC=WT{9HELvlWy5(7aSQ&iNQl0t)`gN7x_>k%DCgzuQa1_$NgGXZmww7hZa3Ta zit23BpL|cNlDjx8R5n0gMQ_Jf*8G%rWw%E`OW*~T{G5fZu4mHLH2mTKr}tn(e(Pi0dihZo4lJlt`7I*^rUIQ z7Dskpi=Ju2J-#@aO`xy{`uiz6qX3V{W0oVBtb$dw-Wz?#p#woMn)P%nQjZDnra{x* z3AYf)>Rril0;~xxoIh+qd5%>aY+||~ee_ti9EQryn#GG$E7`AB-_0-)SCQkJP65;oa#Zt${RP||RY{OUArqdU%<3^BAt}3%h&g;ec zs$@x$doDx5*2;q)Zx(AlVBa}R06CaZEID|L;&?h_A;uIm1vwrHan9{v^$k;WQuvMS zN7)-D2Ovoa*uPox+bNtTT)%6V=FKo}OX_25C&|sgb1}T+%Z!{k%Lzcu?YP_cDr6aD zu7buGuj!Xg)=YJ5|HgGs$!577PE?iO^F8;QZzq2Wrgf_vy(P-96+~?Y3`aJoG);p; z{sIi%kO;ttkvrSYVJM}eyg)*ms`lG5csm>8X9D0?hr{~Uc=wPpuWF1;Q=gdqmT>v{ zyI%~UxEa2|9m)KKCN^IThD+7B-wOv8u`y<^H3J8m(;>~u<7O}EScUP5tuwQLq)!p; zYNkq0FSxhuk!GpodzRtKd6DgdGjsY~$$D8gd8Uvvw{SDr_wsb@s$A@|x|)H3F!|%u z!0y(ET&8jbN4K3RNW;U1suI1P$dhtYS7x#+;BBY;^_Rr*?;s_sFJP}2$FLhiO|9@{ zUcVM&1#rKQ zrlWMOvjn$;pn^2Jbm#%NHe~RC-Pezp;V7@1vCuN~#2;)yc<)}uz;nL63Fy={qXp?| z;LS6Kfv{=J4pxJY7(<~uOj32~0q7Rc-^K9x+aPGgcnTwX8cbz9B4_Gns^iyxhj$Q^ zV}Sh;$|2D$F4P(0&@VbZ*x8|ex!4@6s)AUf7)zBc7)f6xQmI6JX%NK?hfq%7#hZiX zj*qDBi9|LPi-6LWcUQ7fI=ZdYa=~q3Xct``(ttuV!9G3%l(PvSD;agxj9IqMhOFtu zqwffAo34sovBYa(4^ooJxG7ghxvyd2Z+>EMK@j$8Te4kRy%AY4a-bG&q_(MKhu%PW zwRVI}pWQJG<~dvTwvgAZ+hl=1qHLM%GU2i_4NS&pUPSut9s*|CU?&rY8;#63FqZkO zwzK3aqd`PBFpgjZn!EC3CWMDRUSxYFAlTcZ?Y&8Gt`0Jl7~OMjT^94#M`sFhWKXk-0nicl$=?K922?;>dfJwzijG~_%iz8)W||F_+!o6C*KqyW_&NCQ0|9zWvs z%~{X6p5*{;kY+g+>Ok8j?|#c=o?~waG?p{c;urX)MX_JD1mkz8ETA8Sk>l}*S{skm9V!6-W3!;Y1{FK*}ip*L{+^&}Xfd05j zh#NVZIT1)%=~(e%sxf}$t@v_I$t39Xn09^ND}3pry2mKOkx$gSudE0m7@cK%VZ(!)y`ydc*= zqT$SdmZ0yV^8~#N-OL*qw2}##UEenKE#5lDmTY6aQ#PD!j@)H{nIeS0(fmf!Dv)cZ zZN(B>jdXRP-oy+Ko4?zTOT?sDB6<&2?xLtvp`~sWPaTkv3NXq`tPd6jR$^7+pNMkE z8WX*9XD^`4iu9w6tkQcTZchuoWA{Rr@ZhhT76G6T5!QWvtF}ofp8mC@C&>zk`Yb=~K*PQ#DJ;q+=xBfR`v7w{fvd_DMZ&ocS0)WCb|lr%8*96DZgdjuiDA-(R z#E0lmC`&iS3sq}2%bdGhyEmK;jX+r%pgEg>#&AQIJ4T6izrzT1msM(?-d=D}t~YT% zkTJL!E#N+;E)fL9foksKU688vCXFq2+4_&b8v|Wbqf7HTgX+wu-MU7vsSnNt`Kl=- zBtaz#7|z0-w5s z?BG7vX9g+-sx?rxHIub{qE-tws8013;oa7Q-JQ5|$4u<^c*tbX5(;&7Dw2)xa)+8W zPEe=y00JpaiYPai2|6|!?#~fCi8c{UfLZ~oC!GfPHUeepI)9|4tWhZ0s5@Ir3!ccS zk-3mQ&gTEDxx^YxF(K|6zU5!MK87+6R5+GNK%tF1uzSf$+t*eWUZT7P5%j!&JhIGi z^)8h?*$Wr|uc_&9Qvp?GELJ;S#thf0~h&PG5 zUu4+;V@TDFh-SM!W+O$4n=`=4u^-A!p=v-|89MSKHJP~Lu>;do3VWH=y4Q#_qw8fe z4JwXqkAH!Y_`Vq<(^rS}KyH(q@mh`6Uj#_c*a$!T(d-8aAGxBWi@;>(XyE0(leDyv z4YV(6BCp#jq6;#nR&Uvo{fpkJ?c_IH9qz3)FPlb``FMJyV__gsK2ntzc#Tuk?O}}p z`WZS#kQc~3!0rPIpjfkhXs8da5Y5hnfsyEQUpN#hzdneJVJ0Pe&}p3t?9KuXoH=2n_+gmO5d%r&i59*}*8(%&9utP!vBD94I zvR6ZSQyv4&2@w5O**D-(0I*&22L<*Hb|$UPdXj$$C8(V=fV_Ys5-x`TNzPmu5pKk< z0Y~U_9sUNceKb-I`SuE(RV_Q*sO zJWNrN3&>7Ylf;4?KI^?>M0ZvVAjYS-V_K_LdSz!$W@{i%#id&dh`IturuJYXL-P7o zI(@@FJVtQ{HT{{ei#CCbV3Rtt z{$nTnU_9!HQM{9R61oSp#Mocm0nES|ilS~SAhK|g%N(HX*=F`s-Or0%X3!I-?KOiJ zPYx7KG56xTtJQ(>*FM)v8W8=@@79Ugb+eq7`&*1zov$WcK zX+s#ab~=nXK1Q_1i8tC9DQcTc0Lx*z+Dluwh(C~)aZ`e4ZjyE zEKqPxE`J2bK!OEI_Ma|IMykJad{DFvq$%N{y=()^>NiObu8%S@7~<~=YCUOQNz%IL z3B8`rgB}RQT_#*y`1Vmm|CCcyM}N);2#;{D%cHs_m*VYlv}8xQsXJy| zgMQk6<$P2m6_vGQS`WB%(HfvPUM%3tDIV`qgy623^P4O2H}3b4gm`C0SNuIRLn&|h zoj$=Kc;f2N?FHB%wU^3mUXLSxy;hs?wtk+)ghGu))$1H;39j5h8|+7t1b9107Z+RU z`H8i1j{f$~M)ih3t1y=HMBxxljwvJ@C%&^SgZ9Yy5xoO97rBv%iAhDHbL*H&vI;w8 zo;$u|r?~dPjmT*t)~-jDK!*zwhVHpo|oG4e4Qsb zuO<@IH3)WNbv6i36pA_sZky>Q9@ii7tt-HeNp;nx9SpL}auZc?JZ5@P*G5Wt z$O+|fV9Ia8O}6ltBM8d;b*!Tf;}*{&4*ReB8}wX|!^w_1^*a*cwQtR7b+B@gi09PO zHmCuY0*eSY_$Fd{E%7M6JmcdH#fM8aKDk}#PF#88G$HS0Jsw9G(kle;0|+6@EPgLW z8>(84-e(oD+1Q|Ded-Niuf8Vye)rMnE|tQqS}RgAIDJLnsyNzATxV8I5eC*G{((qu zfj^STrYo{n9pDLU^UnyVSGFQ+8j3g@CMS(35?(oE96+V}LXMi==)BL}kMpIOyj2|; zT(>s^Y?jW*B(h#r?NAd2D|jQ2uz?0?>UyeZnUbL}fkhDN(!u`P)TM&U!gcdXXcZyno`0BPI%8;S-Q!VJ1*MjPT?gn}I4 z(}h+i35F~tRNIm777Yf*C+MnC4~^LjR*!90fNhs{tON)sGC;BT^k-&ggVoGt%y#2^ zOF8B7Yq&S8(XY9flkAf(Jiap|TDEB!1I64;{&Ybz2^Q)dr=C-UelAa@_8*ZY`bP9J z+JZZZD$FGkjj44r06y@jMwV!nVBG*(NjvL%F6bw@^=ox;0n7Li0y~Vhx@x_vG-#y_8BU7A0X%1a^Qn>$BpK55fv9-4n)0pSP z;B6`|kD`esC1jb2$;q>ixl1F7&y)`cHadqMHIZ-KemFJpYRHdPW2%R)crh^9`-{Lnc7}= z2PXy_*b$f#(i+PZ4PtbOm0Z&g3oqXp>n`25u4m4IejfFAK#x&Hrw*N;m}Ni ze0rcol^#WQiw`_HFBf+33{M(1GA~#CO5O(KP&n)<2_$|?z_U8FLz6Os(gK0sW;Rwi zRKeK}-E4PI@u}6Aps}q}Yj#;8=q=E`@9d>`30se$=g-~*FRQkKWy{QfO0?o$0Ba<1 zd4r>Dp);aT{be|1TgM7->T-F6X65UYMk(7hn290eH2#)ANL#cAe+Xq{cXCd0Y3An_ zYDtq^h)1NIM}GEA)R*dq1%1W= z4(Hrr@Ku|O2|+tb*il%@#*nj18T@M$Gy*FE;$sJYWF{=Az(k;tYbsI+yh_FWvU$00 zA8G#qAdH}Wvpbl$TJw#qe@*cgd)b`Ag9m>mnA)3(&W?c-1wp!aDMjGwJ62LYPt9?} z&6VOVLC#TS6jQ#q|JSpe6>LH{kn|TPevg~g$a7766IVi^%*u|Ywnmk81Tsw5h_J>B zBN}u5?bIi%9IKu~stXfU;Y@Ae9%MUJaseo+?H%MV$u;}GFC;dyBw#pI!zCGlvcAen&{sPXlit+`*^W%yjlq;hvp zT$z4OGbb{qeFC{`gsvENp;j3}vbh01DR1j$KLR%_3I%Id_n=B@@u&F&_<3m|FIg>W z0yNV!By;Z|#B^vrd3^N54WIQu*eE-^$lVs)f`gp%2qA56#QX{A7~!Up4J~BmMQa{n z=2MF=G;-+BI9UYab7fuIhn!_N<>aR=I8wf7yqTZgfrdZfMd%H583jG%2S1qAc(A!+ zVy{<2QoUnR-Xbx}=HxAN#simaOE8h`T;zUk8w+r2tnjKZr5+XnJey>-1pXd)s3$olbIvqTA>&{Z7~ zt5Ua1dxtZd^KvJQ)L0C%)s-od6>u<;qTXI3P75Cku&dbl(L(HTGjy9&T}8*{NNTrp zzcl8#$VPbk&%|)pp#nFh0(X61URLO z@E?e`XLch*Y2`CQ8SYURBymlzph##~5&>9%f*Pe^K*LF8r_2pG(^2ytGOt|So<6vr zskk*Zz!Z9kZJ4!soLQOPB#V(+zwg#j8$93X8~l|R>BV>xLB#+dbAO%h!OW!R=cR`Q z)-f5BKTm$71p&4doGy2^W~r`MI?c@1_p%}iJydLv-YrLX%9Yo)OWZ1_0Jx+>qil$# zGs3#=LFBfIca8KbY-{J6#$!^m?oQ|*lfOW{v~TXqxZ6JJX`bPS8kjZoSnap{|#(Ha)<-~_hrz`UjDI(d9XcAXRh8Ttz|wKvCo zJ`A|v?R3SRJO_PK#V*$AKv;IVI*3ud4_u0`k{gO?vwMFXLWg#jk z)DC&+B3Onm#~HVdKRQN$UD!5Sw1lkt#&OZQA0q^`!7(lRRy8v3yE?xiaHo$ZeTDvmeGR@!`$@j)uRkVwYzz=HS?H*inmyyx! zBQX;J5vdb(?p8g@(jG*7u#ZT00?q*me66VtH$=mujpn85+xuUd&?{wTZhHV7+lmVX z?W4+eo{u?KObbCpL@t=Z<@8aQ11f3 zdS_1w;JY3;!+UTVw6X0N+6Q73)=Rq%7(MvToiTGwO;~(Yvh%XkGqVdiRV`XolEg=(uD{@7pXaUEDqBqN#}RUUbg=kIALk=>Lt&JQREPUn9=NLn-Rbze zt;UzXt8$D&Ma&FIsz-fdbR2NotkQS77OQ92oAvaJ#7@@{QiQ? z@!Nd}^DkW-aac6kkFIVxJ&Fuyjw;ue_vxigt@o^opH>g3g>e8q9&HoNyd>WTf_cq> zBSjHJ7VMug&-(x_P$*SDwoE{y?r!tOWz{3@G}LuO*r3aEiqB&-7AIGa@dZ3Gj|(GB zq;xvT^B3x)cDY*oK4ld*bt=Gnst5o&QrLE&@@IC2yn$@pDaN(J4m6v3ocg8@?h6hk zr+3HK7t9~O4iLzc?cIf_%Rr;P7b8=iSpSkla@Cp8?UY-GYGM5()oKHS!&SxYz_eFc zieih6@8WcLJ{UCW#1?Wxd>c*ALfS`N6YgLs>STvl{28Q@fU!$`JiHmFdE#E%iHjA= z!Mb$N>Q6222itA}c?tR$aLxIJRoHQFLnF21?Ti6xn!mUso?9$%D+tBV@IIA5T#W`T;y6Wqj~GqKc1!9GqJGl!I@v4CqS z?__Eo3L{1L?%&t&1$vj-@`UKXMR0u5yM z5ILu~vS!2#`4*aBUEz=nxcnedhsb`aE-SnA3aYHwn#?m~@^FfbTyQtfmO(4tz(2 z$};hoX>ayUZM8I|5*8(HkS$vMZM+0djC9lcQlmISYq^F*%-QKNSnLXutz&HVhcY(0 z9@VV2D0^uFxN<}!ef_eWKeP(hXum^}XMWZrE!=&-o~})or_C4U< z#`ln%haP;^AM1bN_JcdZk+sCpx(y8Zx8JS;n!Wwc&YcZBa_LZ#c(u*& z@?%s+-{13t8rfe$q4SlSgXltlX;XzXXQe+`IIF{s$M=W?L<&+F>^Tg{QQvy&YSnAO zCR^p*3^#7d2|W}<5n)Mc``|O%d_Yjyv%!qEElRieiV`9{=y%y6*LhSbg4`V?HEQ!U zbd!jzE-zo-TAo=Dz1uiP=rCrQ-w;qn00hS(ta_N*9h6QUaI0HB0zoNL<2)mN{z^@G{$I<*j%o=5zq1? z>z&NH3lb6!z@eDQjfRhV+XDv)xZvc!J6^epdolP&L8d?IPQVVR)^3?yrZ|!CQY6o? z={`QQApf$y;7Fhb{?EAUrq=qNvaRy;3ZJP99<+3liv+<>TSdb>@#N zeQ#f3p-4B5iBxU$eOSIGoaZ+t@m5VCijkL+gd|1@O#@Cv%JKFhkg7 z33W$QfexfYv*Z^Fb3YS7RhCY(=fbi&^>z-_$UwW|H@GhMmC9IhR`XP?*5i2E)I^Iy zJwV)GN-)CTX+@~Z6U@z2kgm+oyBJA4T z5p1*Y?68Pz@3t|Rm&ErH?d8t~kO(S9+1&{tgsLc%IN`qb#7AGaW{)aBXIua;!1h2g z55ia9xFA9?3Io&P5N#Njj{yOEf!&}QF<{2&^|vJHr2-LSaa%tLn43tNT#)@`DVg1X zTx*$~z|7(pKWaWxD9jYNz19>@7cca* zf})D=jeM?f_|6ZuMA(wI86v^;OcHo+;Wy(ASlTK|0t?5Hdo|1O7QofXHSjnuxws)c z75329z!n29(1j7Cj%8xnyUCU~Ld4Fa0OlfmIpm||w>Fa0cqGRXjKOY?5$A+2q1Vow z-fi1a47v!QmJ!m59~@Cd3Df-`bTb*#0iyXm+rPcsq;DFS`#7r;_9lonzIG9R&RC(D zIq0h*%ID{~Ujdh)#pr3E+>0r{wFU4#Du}7bTtn&h5#T_FONah@b0@BjmzxbAd$^iR4+)6OTU~!3>1M`w$`=Ufs-`Rsd^K?n=UO(lATIPDdvEs(9BnU943dH_eONz2ek-Tv+LBu#Ef$C9!_25oW=Xyk`m7zysjm0;v@&ix`>>dPaauCl_F@ z=`Jb`=O1=wbfwU)P23At1-&MRz@QXd#^GaYqY>nd^u#Cv+kvi17Qeu~IRF+g09OX! z+T7yk&KXlrmlPXdkPQPA2)Ru7Qf?GK=kd;Qj2GX}qWLA%{8)tV9i&E9qJ&{pU%ic4 z5Zjye*Z(VMR^PH7uu;8?hJNue&cnpN7O)AGIkIk%zL)xeA;#TN#8(~(mE249DAUNBlQ=7OKQo^o(`MbSfnf8fOul6C zttfL1+>qiEg5&BQ(qqcw-hQ~wOwT=ksW}9ORU4tU@t7G8bpAg4U4M5a9&wH+WQ-VL zm4Z-!R_66Q{xSYw&;2$f_q<0n%&A+;!N_59FPu6hQcp_fh)`(0 zx!LPjb^Mb0!9os056|n8$ln5dK8g*)Ij+Y#2aiu5Mh*>tyU8wG9en!S7SyfbZmM&BEqQc)NU z5Z;Y!5|@hb%eCG) zPP1g0Rt*pyJlJknQ*wuLd~En>-FGrwn~h~sed@2gVEPX+P;sOfv`iV^2Fa`+LgxdW zD4z@=J~`c51;sKdmRJhNn*74Sq!MLiU#0dL1sGDFL7wAvozr>z^TeWBAT>8J4(ppC zcv$ex33hq4_hsqS(SZYiVd}MvUlovDYwIpmKqE{79A>G7R!=c9fsJg3W^MFWYzT3iU#t1#5lq3vuAncL+~HycH4v$KOb8^t`Osl1~uZ4 z#&Q9vVj&R;&R)Jumw>;5RaL2~0e$?s3Sol~gEXDkTNXPUB8uw+$w0sg7gjbRc7=0C zDc?;(N@FruL6nRjyUXy>$cdoLE`mctOFfx&Ze}|>14S5E5(Ob)mA~klbGq<_n#K#) zejhk{c{9LH9ci)tl`>W-*Zkq@Szm_-j3vD(!w{Oo;GRubG}`6UUdG4Eem@#eL<<1N zq|Km0PjsJ}F*1g-dsQ-{TM7&}!D%4@+Ff&-5`aZNGheICs)m2>Qkv^e0u=Iow4kX4 zPI|p=j@{?;J1r_lua%gFput-^?kw~W;x37^rJug`5m9*76PUx2^4Fxb=qKc2dsk|? z&M^ZlnPe}3P_P_95%fFDfau`01RcY`b_IF{7g+V)fJL!62h*b-PZ?%#v(KI3fby!A zBfr*Z=;a84X_|&W3ao+dB_eoWACJ;t_H&7z+2iEKfzdQn^YA_b(pG{X>8_YMDGE&I zaYSspNYUetqYmoVm@HDAIfnJn|NUgxOrNFVd^tQM`puh`*WfU znMk}oQ9PVTD!L4A`d;ut%g}Eoysttv_yEbx@ zqBMkEO$ztT_%lr@eL2Y#do5B%z zfTLc;CH~a#?yczyl(6CSk@tNl$Q}`!e!Qhn7oQZj-U%rDdI0VH!!NS{;1#$*pq-ba znu*z1{e1yjr7u6bs0L%*0Cuj?xmOh^v$?mE;ZEvP63y6naWbvAG~dzmlKSO!52=!4 znwYh?o*hJ>uH(){Cb%R+&4u=tTUpEtkqt$1)75@@(s)6oZ&yr`%!gXX0pMF48$K%M zj~Jn7JI}IBSUr-Cb_SixTA9N*L$&V$xGH-2^Fzl6gto4ws*LG64hzdFa`@bZz(IhW z1?OqMV9Fdnz}ca1ZUnesUMvrdxYYS=rG8XPyJ+hOP`L4XbkP+q{!HBoFS8B5{@e$> z{lt3n?&}#?oETYI=$#r_0Rubm1~8eqgZTf%-5CF;0uNMZ`@5uRajPD?jPKZ z?qAxWe=(N-BksmX_eaR!i}v{@;$;L+i2Tx;W{wlLFFn(EfI;JoG z*uU^5CPtP&G)6i4=(pbSAF4fU!>cg z9$&B=>sQ;KiRtOt{#O6v#b3+%H(vjE{!i@wd-eZb6*Kb}-S+oGnZJZKzwo(#$_#%% zJ4WU|zWs^SKehiAhrb@v{o&&Nsre@t{~7r|d$auQ!NmG!?M%#n?cdz|)9;_we`57d z`5*g_7k}oYr~eB0zZ3QUfN=XKzJD*G|0Is?Z-Tz0U0MI8=0C~%o0@-@|B`Nh6U)N- zN2vBci})L?f0qA`{db7|?fZX~|H;>X7Wr2u_TRJoT{a!l-)n*XpJe{)0{?3LFUpPi zzbUu>Csd?&=R{K% z;Siw#(p4iC0Rs}@00YA(Q&7+)RTM;%bmv46L{p>z5|NQ10isvT_a^yV*QlV1F%n?ds6#F7OZ ziT)8^=YU#&N5?E*<3QhpN5|M;%ku90dwy!KTkvhJ)tm5FI7JzGn2EyYVf{yOiH?cs zVcyR16|d!I;fM3YllSmv!|>>=KVSNG_6NfU;hXW>lGI~2HHn$Ag|(iku}sdHo{6#E zk--fw(kEp?OiX7mD>V`&VJ~mA_Y?*&FexA@R`KN*=4NJmd}KyJF3>a9)6+9G`gU1S zTOJ=@nmOJr+sDiKQN28Ill_sB=9Ypf2uemdrl6r{kxQR*tP(E|LhYR_3IcXrQuo=o zy%ENFEXI3fisy}SxM|fGbc6qHBy6_8>s|Kzl6jrHlLI@J5vu*L-F>UDHK^hYIjtL~_-2(CVv$lLx)JG&l>}^b~*X{_wZ{)xre1}FL2QZ}jYer0s zIuD>zLqHCuwbz5i+sLrOrLIr&cFLNqj22pLN<*Jo`xN2t*5cC75Ci+b#!YC=x&Aj- zG~y;xC)KK6G>mQH;NFy2Y?qrz?gEmB8z*ES6RB_X@cktVjc99x`%-9jcn#~$eq~t@ z!Aw{`&Ir>AjnAtMp5wOUHP=Z=R702%p)CuLq*k$6;Ys6*554293X5t|u>#0w<1!V= z2w6)n_!87J5A>hFT;Ku>R#@A%etT4zmmJqqi4VO4T)-#M5tHxcHPueN3laC5Cp`a8#_%>oo|%_AO)S*nG+hb?Hfe}18i{PJU`d@T~vmy2ARB#rm3s?*P{LD zH>LI}Mtp^7IfYx<6mhn$`bK9B7+5#?=FgOj zqHMpVHlYhW3i;I?(fUp8MFNUUU7a@MmFMwiY;Lht#+8iJZ@9m3ky%_FNy3Q&+Q~Ia za5~I}xt5^3Do8|u*nlaOV)?7YZYO%!?9zF}qEcFci&)m4Dq`nWcfrsaPNnCw;DaX* zggDY%`R~%TkC&B8y-Jm#Zu>rkLHTy#pVqa+VC-OcNQVa zTA@%!f{Y^?NCQi5Cha|m2l(5-CJU@ydA#cR7j+CO&w)y6%jVJ70wEZkw z5ocbu%2MNMzG&gI{w}rp9zIX?&PZb4hgOq>>}qXL{07psT)a;|)_M2_^SEd&)`ruM z^s{Yreg^&GkP2Md*yKX>D;gd6L^UZDcd0Ph4=ktiX(G;*vAU>=;VYL&%k++}%#@<1 z;Otz2Bin8vPmH%-P5D%_?^7vI1rfzH$Zu;W7#Xn@a4{bJvxR|Y>^Dm#3E+%p;6!E{ zLWY4aU$+PVz|i{G{57_9hk+`t%2KD7-rGAQ(j2eL0 z^cP*hXGYA3mnN}dHy8$et)zV7aBa7=OuBqJ%bT$W+ZQ59My3;ZNOV&3_j3EEw;cyr z2V)7y?988?XfsH3`}t?wRI;u;BW(#ER;t^2fvMj z&0?utw$3O~tj@(6#jro_yb0=xLNB<8_`MHYvPt?}jlWONDa_YrN=x*?KbIA@a4B3q z46K&NN$Ny08shv%y~Qyi(@tP&uSV9Cp0Zft7$dXadq6ZCgh{^xoOn^6-E+;2`c9iO z;BG+A03#a0M6={nER5?;RjjOUIA!tmthifPL8aM7!F%+;zO15`lB|Uu!?_u7*YN^s z&E5BCq=Re+dpdz%bonzE(-Kpi9}^uO;qkGGsa7`0V|_J@{HTIkbnop!A#NxtGp^3N z)O7I;F#3;+SMB7P9iDmSdxI42kT~Qe8{HW%y<>I1Ns--@LAu6J62Vww(K`3;=Q@Sg z8!)U;ux=R>QX$I&yw?x>`&H!U@v&DdAyDcRY2}T(GPwk<1hPC@!c?R4%cEG{_gOFyX*g)4L=b&j`fhGM zJIahmSKR&d-EveWZHd}Wcw87W5?-A8s=$)Utu0#L*2d*KOsP{%_PzMv^YkK!pEo%m z>g9+xOzpggyXa{@m}31%mSRM5Pb&iYJZ28s6kkJQitk8NO29Unn#NFkup07yssc}?OZE@>uAowOBzmv= z2le63gq*)CHJ#cj-quGFl5&Ek14jE)a{GzEV{f-=WzES#(C_#?!3(*kH&wV1NtK^; z^Yqn_%QCnpgUhBYU=`*DPNr`}&t~)8D$+L@P(LR_vQ{d|lma81k*1}F15IJdv9qkozIl^| zGy5%F+IYhFdDIRn;1qXa_F?X}_e8~<7&Lg9 zFeO3D4l|nw?01``tE<@Hl;KPsMN$vwPJ2B4%0iwSfBW#x5eK+$d8|h;fzKPNGNJ;= zsIy^L6DMRZl_qy3%Ic|GgkC$zLS2x*|8a>9u(XIgd>#^7 zD&{bVKpJ=hn4d26tiv$DE4zMA`SL5oS! zi5;64qxSnXRrPD%g(T<`{uINj0{SDEPjM8kcb5ur?U$Q9eSS3J0@E##-hX3MU@ zz^^FrxCRJoH?l`q1l-mlg%G-+Q)lXK*CO!-ekLJKh(YTo@_|a*Q!miAPuXhq>8;C7 zNCG@>Ie2T>^&w9@ORl%OJV}vmXlE=Li^U-dF@gc)wCS9gH<{0d9r&IUeDttz#twWt)_fA z_1sj4!Wap;5EeO|Laz^ubLobQF!;&i2pC&B?h3PA%R7y|W@VfE*c;OHEDdoY`R}dk zBES8twWF3Q380pKfV{xz_=Bh>(**ZJph!XC+(Z!(m{Wd;A$NG-nZQNN6q#3Mk_1(y zkppot@pQ+jsJRxpobN|_gTD({0h`I>`Jj-}f;f@0i|LC|ujNOqmQiP&Ct&15y{aY$ zNpeF)Srdd;73j|t|Gb0Es#V!{e`PwIVlnPmF$tN(aKOESv$qZ(a(Sv)zS4;KCe#A~ zJu?v%H)nlbHmUs1W)F8{I^a|)vVc^wqIOa+bLbC~2X@RMH~34{>PQCyTtB9{tKX@x zP8o8Qx*DQjrtdvU7yk$qL+WJwhW-$S4O|!LHIVIWW^8vhSsrxN%@BfjTqYspU8=34 zpRXDamUSGnWH}6u)z}WUq%{(d4J}Bd|BY2);1ZYT`S{!WaJ6qGp5v4PwwGPB&h?SM z>r-3V%FdJHMrF3`l)`YX*TOMv^ekgR2`1T$2HlbybV@M$Vw+AQfZe29lQtD$5aG2% z9lfT6%dbPyb$1An@D=KknW7pTIM46BZr;RsF5iE|0^{Rxe%rcRBzHs{`k+tNpQmmsBK$D%DOgY9st341Fz=CYh@U)9mCJ0YypQDvyn zGANRi^qVZn>$@M}I5Zr~dDkg+oxVqMV%s1aA{&YemBOA_zvtat@e)vNVncAvJy-h^ zJ)T{t;r25R@*Bh@Yn+zm)*?l?5wpT}+$?2(gq(*-$Ot5;2C4?H5VM2G>cGKXQpO=0 zpc!3%+heiSj$hYC`&`6Wvjzv|WnyYCx`7&ABy{KTQX~ zjvE{w4MBzqdAOg;SO+ETEIFh$k&sAq+Fca4)tsWwefk=xrZ4W(z@lH@LG-U6dq{K4 zL-MpfyEJYhpD2flLj4TF-Ws3_dve&Jqk7nX*Mo?5v}Eb8*#} zud({z#Z+eolACsqpWYp{kl)3hLZRYywFc>)j7|iDo7Nzis=lL*9FA2Kx^ygFomP0V z22Dcc(-kMC4YBa6Z+3F06P&DIU2P4DZdh?-eIwP-Wf$J34g&LMFpHeiMVU)NL>H$9l$2arSdckaBDo-t$-v(!j9q+0@{ptg+xea`(Z?0BPOi1o|P~2+PicPub%(Ri2XUdQENjz7NX3N1pK({{{;;`W|ZB zEmVvUn4W}_jMOl57t&@JCypP9wn1^A%jdWkBSZr|usqTDwbu*l@$-JtnkTNc4{p~9 zE$tJO#R$<)8%nJ9DI!4Rh5k=x=5z{%4LZ?2m7La=&l=UNI%XhpLuq9QmJ|fYr~;>RRWJb@jSHl#*qWzQ(ly2Z5tX0SHqjArv-mpA7q z$}no&6(hoR?uKe^M<3I2y$=iE8tzyp!$&$RT5-4@?%DDykDd>LcAA($T;eFOSm){)1;*^g&nkUsU+1G}rf`Z4W$CzVS zkaa+_gG*%JGj7ek_TvWI3zw$ur>O}kM5YICrPy2hT*c@<ZI;`P`(N9sh&E`45)4vkrj|U~mRCaSd)U-yaRu?VUY|SfK2#OTEWC_F}Q#HN; z3y&7xzl9ie@tg}qa>RLqXWydh;j8?vEkkD_RPCs`N-3PlDl$Eah(LWBN`&wKy^KkW zfSS=S=8xvxE4~@udBCvJIqlwqne&F^>L514342XiB zdr&^QaD_EPI4b@FEZ^>kN-ubG!1FV^(tcHJFf-Z>KUt7Yl5%(!zu-xfMXhGIM z*0@5E2p48k%>p`#z*o7c!QHeNF0`=c#+lDXpY-TlhSH55H8um5?U5b{3lY)h30nDc zg0~wE)6+C~ANkE7t*LU+5VitN z!)n&rS6&B!0(vuvf3-}|n%1B@8$f9Tj_aPpF``sRQ!P79=KXzp=fNfW^G z93%43jUbgnY033%ZsDTv#9mRF zuOB&(Y!UP+hZBYfpAl+yv_~3p?)=vnY*gnHm@;!=*XvIeJ|Vd|fm~Q_%Gwd<6B&9u z6aSnsFt6?dLb05aMiM4(_AGi$I~g5HtJV3puQNg>Hu6gLoEtPqc9c5(Nq0swJ!*?x zA%l6-pXkO0O-yQ##8c_2&&EiJ9Z22#Sz+Owr@fK8lQ`|B`{m>JpyZwkWTq}6h(^gi zm5;qUyuEie$7Hscr~M`jLrfKJzQCF&^if)?=Z;!DlKwm)C59qq7B*xoJoB1 zGOC9=27F=gM6@{SyFz1HK*!?Xm}>C1-MPc47=Cig%Uk|+% z-5xmPn%r-ZbQkW?h&Nd^Eg`kgj;Fi=SfNKK<{ z)31Gk@lvJLL4Hzk1KL^e+0?qSdZ|f*T#Jj~b*m7jD7MZxt_*rYggHF^ewjeIO$>+f zw(>-Gb-8s(E_}kdz^wK>-w-ougjA8Bq#|NQgT*fxJHd>8#|5#6r*^X&w<5n?JH1pu zt?kGbnb;?UzPD~2DX2x08;Dh03alIMN_2(#1gpe1?dh;IrP#G8m6s+Lf9QVB5)-ml zjV6u%5u_a4J4}ELMVpA#86SllqXKvuQ(@BG*LuqoCGonU7;EL#97D%@gY0mCz&UXz zsCB%OPMl>T;RB(A^16S^t>xkSZWNb8;-X%y3(qqKj#)EH_oooe6ELuj|~PAjA{V8hO0Ca&VDMfF#A6F&y(d8iV>2uaWHBM>poV$oZVJmNhy z?uqz|jTm(p`CB7#58s#%drd>0d$HKy9p&21fAxX-c$^9Jw6F%ipzMReWNKMVJmDN* zeR}xI4qkQc&m%Xpe^_B>AO#9$+F{6wqebH~kU&S`KD0Cw9HjX-`Zqvfidf6wD1|;F zO$r{Hd)-PytZQ^*#rOz}-Il2`Lbo-<(hY#sI>jZnp+ecyrA)lHce8WM^qez4Z8-6M~`-3eFz7OXdCY29x6%bAR=6oS0j@&Je<>UQv z;%yicV_@`K1o|rFXsFS7USPm_v#ZBlGwSaR-;7(WEkip?H^b17afcsa*B7Zj`D@z~ z#Rl77M>oxsXRz<^S!MgSm^r%$xui--Q{qIfvw|8{do$EO@j>zhz|hZz^n_I(zAvFw zsOsRkJd7RQ8Py2=*4RcUw7L)ZzAIR=%jmWL%q%NjKQ9~O-L(IcIe2hc(ebrhX7huP ziR?z7f5VBhDm1uhIYYqZm2U~UfSTE0;1D0R@=Yrz5)eZ1Oo+1d+tSgE=l9{C(7E8K zg7naks#OC`QAwqEVNU_hq9wPnF1E1}gQccnhT5ZRM0FJLbJg3fiv)BVxxyx7Jw-#U zo3S9Gbw>1a)%{Q^0f@JEwz%iL&_lcog`)G^0pC-GkT*V_nU|*|O4^#jm-yA%lhC47 z6~^$uNz8z3g^ORB13wn<4HA{whAygpwiY@wpRw=Yc-TEedQ5q;D%L{X!7dxrL#Ly4 zhL`dL)Tt-O2Yg85#jWIK1z*&`kBd@3vf}6YWOdJqMz#JxOnDlgPoWK-6=z{iE$h~# znbRW=m*+GAj5i_FBs?(|)FqzY?G^h(oiE(T{0PtSM91W1-*3Wy+X$vsrh-cH8@-jn zpLEsb_LK6DDWoC*EI$^KGv0350huX^;|@BZRpl*sb-At_CJ#VgV>_=b{xmK`Lb^tw zd$+9+a}SNe?xg{gty$M*b#h(QU7TNz`}vSxtOcB!Xv=?pk9v0I1ONyOC8i%v zTtjj>q&3v@venORvUONEdOWIqwL-b57hoxYtu`eA>ni&xCIShXCC?pIh0l*jCb1E+nK(Sa>wb-G-HfFj z(vs+Qi#P)*cV5;N{XbYc2O!CoZr`_U+qP}nwry+Lwr$&*=Co~l+MKre=FB~-WD=DhemX~m0ZJcx0J$bw;o^x(1WfSABQxXt-BG`2?;Q9!NbD06nT zh_&q!!&$ALbY$X#k_U-#PAdFyLa^<=d_#@)3^`0qt2H7BpZ1&-tk%pHI5EO=9_RdJ zmqqywJGeJwxs~LBr|F=my`KO||DF;BD_e$;%*Tq;Az)>Q1yHSJSRjpRCnV{8*b`GF zqA~tu4Gd2Slr8AnycYwR*%6<@+VDgM<)W?~ZX&sjW%9WG@txZ5d61@1qfUV1A9wE7) zNtOa~>~QO1wnhZmLY%YNnNS9&ZaG;Z)qqQk;we+)kIry@KfCVG{aV)%QDqICFdq*j zuPpL9sg&cn3pDfTv?GO8BBzMgp-f>Xq>(u<$Z}x%pQGV=V5)mKEK(&mJ5$>11xvxb zheNvspONEqtRh-%LCP(@NqO|)+}`8e`ZD-OZO?Ev!320zl_Hh=OaO;0j5$=rpsX+u zr!&W36nc%f6+c=P(#JX71F*w0w8v{^S$3=*g@7B~H5&k-8KKh`1;7BTJ9+IWfh*cC zvJZZCfhVn?9N;*_)jWOkDpZzYX1_6)*I;lB@JadUr^^FYsN`4H#PlmGcyM z(cv%^S^5=njOWt`dgNn18$^eyc{^t;qVe&T@t1*T+%0KkdB>Q2F(#wo!|Jwa#x_b# zv?hMQx_%C5LB&}%{FarGnM0*eTfg`U1}gALRJi=c#vYg=CVR;Bb{5N=;NBZ}p?Q~; z@3$UQ?`G{#TcIwbJE%iBx88O4_20qtDGGUYZiY!2#D9?{j=>}3^x9OwY3Qgl6R@Z0hrQF8zB68LYX-y@VLx2F9OoZQJUOFWu+F{ zIWEq%p{h2U;s(*G@}BtiBDKzP&;UB0&;;9&s2{kK<}yl0OFvZ-@_=1{)<}Gu_9mr6 z6lT&-kHWc*F0%9>&{++d2|!0c1HS>t!j(~0?MGPPLTV$J;JcUrtj@cO*h51fTx@Zr zRHCr}LaudXWkmPkj>utdHAeVfaipk(yH2Ljd`|8^oAA_wy}vIDb^)sW*V+YS3P&bX9Gzk_~h4=p^hhn*1= zm&Rc7=*$a(%Sm4=bwX5>@PqKoE^3mKbCn%1=^L%au1dKxryKR8l4Bu)WEDQgxfiDa{(Cw0 zfI2tqcgZG!XPP2LL8NkT>jQLnlEWF`Mwh&(x}c=RA5radSmcf$4uhg%o6cdNtH8)y zKIAliS=r+ zzc8pMzoMyU6HAQ6ppm8&@z$oMoIEHT00B7CQ?F;%Td00V8qYD9*%9tkY5^Yt0~l`N zYu1qeyo-qKMi?x`_FDgx6WXw%+#{LhV)ofAP_R&y#ZazV{PprXYSVRc{VPN?w^cyC zS7A0duxicj9Q4NuQxp_7rz5nPv%pHpwe^7bzWM1`kq!fk$sL8v6>?D-;&ZjJz@5r* z^+km)&3V^N*%3~X9&Z$b$3c2vFGtjMQ%eBvFgNzv@kaX9OS|orV+=^u|8$@Otr=0M zF~;t(noBfNwoQS`ZGnCq%4RY2RL_}#-W$;!ZqDQ>yNZ5FM)5VG%w zbhRvplNZWzO1B4J!@6zg&Q)|RErX$x3Fqt2YH4ahM{Nll@FzX1X@3hT!4L8YUztP# zg0#;&ihTu4dkDpX9O`UnARCh$Wf1(|4{VZw8rD_7pn&u)0lcko8dD!ufOx-MZX__AEeEj3_N;;0;5&H2DwPJaN0@Y!|o$Sn8XPsOm>1DG+fN%jTZUaleV(!s7i zB?e{q^{La;HH88PBjL~awznDPjt;S;9n0ZOdfU@oF?VrD+m9U4B4OS(SF&fo{hb-Q zQhBA~;84U0SJ?c_d+Bzgzg~AnH*4{gDmT`a=kO$ijl{Uvy&>JbgN#}oQWdPETOqGx zf1GoPa2ca^cA$Mu9%zHK*7nG<75*Io>F?X4 zv-&;z4f$JQD*TE2(`R)%(#t%*NK~+(S84@IBpEeyB4R3aq=y;xL(m%d&?XW+Z$67y zd=#iAMm5ALy!vG6{GLo>+OiOdL#r%hnj>WV65QsTq=(Ts{5U8tSmE*%f3Vwn-bI5t z?irwL2|u#h_!01L5`<`YbwMw>BU@aPWiXVW?X7 zmMqA%HaQNJ;3@^>;!fkyKDz*E9Sy09Eu9`K%wL44C}gA;dXIcX{xV!~RHkHig@ELK zC+hHSRno}&py*suXc1{fo(_7OPe{Lp;I#IGMRaok5fxf-1dwb(PW)K`V9SLaP_<&wCgdyPpv;%Si7(@oO5WZ|7JB^Ay~ zYZ{e4d5CI>r^CzsimX?)h-8`>M9?0q@@(b2qNikqhKaBF?OvBh;qHsXO19RdDRcjw z;R-^^?$y}ijkCK+q34b#Kk{dKvPSn=L6hC1Ht`cHrlSlk$`r^olcO~i?fiA$!SC<& z0Gu%Ov+F|?Ig5ANYfL^R~+(DS8eM**Y z5DLZ!r~MYii^$Dcsyt=7vhm=JcGQf!m?l+cDk&w30T28jf}i;HwGyb&_D^NN_@Oqgz%i&pUkgN&`; z_q`Z_PgJ)dN2ucL9fgW_PnJTLrF4WYdKBV*Guc>U=-Bd%m>gK&zVUJmJ8P zNSsE{$)OyW_}T$ACO#-3q(%Jl%_(%0awcqvtuq4T+eqRv3Xw>M^X1g}fY~%lwQ7zq zQyd&_GHFH9kROrFr5@qsF>hJHN{qNcQeZdKn9eu}y!gN92uJ=fnKjKB&HV6H65L(K&jO@Yt41ck_=^lC&^u!1Hb;{wr&GBt9n zDsL|(l?*>hZ$f-;Fut|CuA07ju(A2PfaJY;57RMmvHD8b%iY-ngyp#3S|L7U&O4~u zag#3-w>?1_?~MqJA~*z?K&*X@6Im{RwWs8j$=LKd_ip2nR9(67v{{<9-DNpn|3J+B zjyXGa!juIPX*22@LNnVYg77t`osF#7T=Yf2-8A)p!n7?`?81HW3=%Ag6=wA1QW7ya zWRhSN5SypC{XG(PdCL?KOFlNh!U9o74(DAMk#uWL332OmN!b1{Rjg#KQFW+!GT*!-O^~_gBd9-4JyHVHkyf1VCw zEl;o#ez*j~leuZu&Q{Cu*WZQ)<{iX^agd-X5bSyvE_B+P4WIP)3GL+-D-R3Qq(1dQ z>Sjf_&k6&TDb-dXn=%CGp>QfZq`5l^=75D6Gp(1V#ClOOE0fW`cqTEswXS=*NhayQ z0^w221~{Ja-WtQd02fE|dvWxd4`rlCBca7992dI1F---Z8$D&2AYKUOe?AC2b8k57 z8^sFIh@T-bVs~MEdXAXm8=`o4b^@bTu)l)D4NYhJ#@ISfPf`eJ zXl=@|92aCCmcca?CfY|YB)iYMk$!hQPhArBs{9<*ciQ-w7^XGg4mw3DY|Shf4}#hX z8weMJXARkbVUW9M-EGniJ7x_s#U7%`HO<53xw@SRCdve-$>A0T5^xE;o%e51!bw}; zi6(P3xj%hB9Rv+deGf0Ze^zqrn{M>0yyO(tR@W5c9SKJ^P+i zdEzzV!AYtP7GRTpK|AEdxcwJxBB7GGJ)ZB7{q z?_m^xZ!lFUeWGYISX=m3T?!qZ8K-Jr1J-YRd0wW1NtQfU^QX@pB+iDO4usA!U4?MP zO<|0EF8urqE_$NM!36j~Qcq)Z*2nhAqomG2j4 zMsZ$Nv*IUZV>GL`mhU0=Fo`D%UUan3nB9cgJ9ms(u*e&YT1mt- zJ@l%Tp_x5vFIw@se4Nx5BeYO4FF{NU&UrfCKPQd3BsSY1mu=X6tO-N(3p z#TvfmcwCvqw9R#^gOweLL!$~ge9TaX0>d4rEftw@FD4F0FeC5c1zzR1K9wZab*kJ0 zBd;}QZNfE~TBP+;N8h{!(J)ATl$cj?ax6Gwer9Z}GrJ~?BrUJ1qjWA~FW~e6K?_hM z+Jgd-butmOu(H1&fI8J&9!Q(bEFt}+{b{E zA_ zHi$RCqu=m-FKD5r_yx@SXlU4n&2+BMy=vM(olFtqts^p0u`!GEMxjV0d@tw^<-aLT zz_l1^RpvCpCJj6=WPUuHbdmLNUqQ#^B9w~fmU=w!qX(hVOvDm4NQv%q(6m{ev*&8Zp9 zB{aVJWI?J(_q~FbV7;3|r@C!iHyS1n20=(1MTgmyxl%}1H|WS!Ius3?P90dKEJ9~FK@O=Xt5^w@SFeMAql zDKE8siMC7^mLv!b=nGEhARV_m!^Cj+k3DJuvXDEd4Op|Sad}_*;^ykaO}QFxSA8&M zsbhE64eLtNKlBr-0D_Q55l7X0BshxYu&R0_B$vEb4v5*<;3ZW@Dd26COn!^X7h4g; z_E#m{>G0ZNxOu`>{!WAv8sr*W2JgzkbGpA$Yv>%+4@2U0xElBTvJ21K#!4%c)5rZw z=*o?_{EdKXT|G?M=?mkaQvv=J!HLHBrX%G6UqXt=A0UI&-agxki{kN$O9q~&Qu2Y~ z3y3gW{IyPCPI1+4g_M*fvi$fAk>UO@R?_x2goL_lEOUipvyVr>ev^=6MO&;!oIxk6 zY|J!P%66GcUZQzz<5HL>XO?yD@C9=y65 z6+V+W1J|&dPcdhZO488e#$ABN6-iMdoChRilLOUrypG;=fJf`v#ge6Kte=093^pP7J3RziA^v1>k#_~PixLlQ zwu%1$b*B`8rbk|xJ+8oD!pm^actM{?Hj~72<}y$X9~2ul!G!b)h`xJ;EMt7b6%yJ0 zb-_~kVJsc@3O>W!P%$2GKuOWyf<{fh?XK|ywUGsVUu(n-1g@U55-N^qtrs?CksfOx zs-JUN-ki15OejZ5V@Wp2~@N3ayiP zm`?bi%;dY_c=E$4tfdX^EG8}GgVmT?FUJW>*@1LWCrt`zI9i!jbMbBIBlIc~-i!5g zR49xQW{;)18+Z~JPsLnrm3e@s46#d1{Fv`oq)-rW0;D!i1{m{XSW@d`Ik%C=f=g?` zE^1K>?xs7zxM-G&v?|C!#xafBgNESr&P4R-3WG7S+Vhwsg-Gl0?H?BTFl;Z0h>&U| zewD-!yfCZ+7lk(JgCQ5OsE4lx{-hY@fc7CA;{Isw$@DBTJ0i`btO6j#VX@Wu+%fjX zy*MZN5Pc{Ux_Op$TUBukrM>H~;D#>PSwtey(335Q6TY@V_%VRSQ4ao(4O>ukV0#FT%u^ zns>cTtX7qK5ruZ66&b8fAB^`gT6tce2);+RU67Kmv+6|$@$d^QvoZxzQ>%KepA#Nqd0b_sDdD-_DU5bP)e|;TQWSS$n~( zH=mS?iU=rO9Go8JiYVay6qu6PkN~-~)f};D#Y{c~P3vFzTU7J26@vds;eszU_&(-yV+-p44X2u25GjLHl^L#bE+M3_+Jv zMQ8T!#wW7ajuk2L6AJyr9o!3n1T*(5AFxfoCl#TjIJ#|51%a)0iVUt*;JlohcOAh@ z*pvy7f~Dv*OQgYhrPe~v3;*by3-5HHwN8K73Z$V?GV7IKp++Qw(GdKm+nabcV?{=N zadfCekhh=fm788r@U>pI!3dXD3{_HF9B&8uJzc^XM{kX&#qZaGg}rv`618yqAb{k{ zjvf1kP`LEHt>9iQkKx5U;jKY1{j7wXlp{SG3XL=m$7XX6Yh`_teuPr1TCm-gI7SHW#tJB^0P_JQ;1ZcJaW)wQ4|A-5A-8q5xKaH%|$ zm$N!0OOFPRTr|CV?$Asxwu!BZFd07l{2bV4PCN}&p7N4MUUt%uTCG{}zJf7U*=C=} z(Y;N7ozD=v>FSuJD5fdP^3zdvN$L9i-aJG|^cExUmtZ0LakfPfwfUo%t;IC7pN8ad zFLpEtmD;PLqlCF{!k6N$s-=SrZ$-BiucOm4vSOH_%!@_{h0^lOW=ZL(*sp-c28rl= zQ<1e&96Wv-rs|B<)mn`v-K;NXzOgxrwL*(@sXNFz7XOjpUw69zBV?FP$@N07gwj~T zMc7oPPdK;9(-uFC{omZA>PqmoTp!)Kz;M4S3lt#+Bix|Uy+olLnIoW&xB|ThVdg7y z$|mp!{&4Xj{;{den|alj%nu1r{b~!01#A7HtG;e9LoP@^(4kk5-O-EJOGJfUNe@Uz zFEUD3`;##`vQY(6{6TTFIp2LU9G1fU&AdrcAux$C`!+#)XJL_@ZxPz+EP7Q? z36N8x4bhT1L%BQtYUAny3HO4LSP3s^qyDSBU{w~%oZ_A6&~p$rTZ6(-7R!zd8YWs- z;FCbL9lk3dfC9*JetA>%DPCn>5s9`E0#`>S+2J@o9SvA)1*x;C{E$WpOH6G=+^-B*%$lsS8zbXZ}qOEsP3AABvzEgF97vb*OmV{n}hYgu{qfOO^I4m zQB6@q^EaA9iSfUXIsOX0|38vBm{|XV%)!9GNx;d*`TvW|!S*kY|Mz5$zozy-Cvz~d zv;T%6{3Y4@TNw8*GRJ@B*#Ff0UC;c7PVsm8SBw8r_ov^#?EF>#fAjvk$G@k4TV-Kq z`ilbcC;hwRF9~CIhQGKW>`Z^vvHwA9u>IDRW+Px@{fjEX{s*P;S3735zZe*-zZIT; z!#DoS;E$X!<6n4)KX(2u`_uOy>wmL6{^5N5vH#b2zu$}uzabjGjsJ7V_6M)=uZjNm z+`o=l{}^NWt!e!mzVUB)=0B{8Ka2CH^zR=3l>Qm(?~;GE;!m4@wPyX(g82^tgZXc& z#Gh^XdxXDh|6ZWK^M9xRc=3Bv7#aTC&isGCar~Bw{@dAq*7}cIY=2-Jf0pg<{ra=! z|LonL{9hyg`a{hOAJS*stWF0Yw3+a zAMfb!*6$ZB2X+{2R*bL%G~VXc7H*)nL)%X*93cm;<81G@SiUxWuY2vd+R8B2<9F-Y zx=$_RYA*^aCstWAN9lM@1+W7ULo;(jbN~q|>#?RLz*WuFRg(CM3er9S=5X3k$#EDU z6oC4>J7)kB|06$eKYBnrJU}-*6B8?clF>D28*5u&z*))pFX16*1b2`?TiVHNfN?Vf z?EL*5GBh(d0NMBuT7YW1b@!i^<~J6 z2YiiNIW+=+tKRukyXh}YC-6YsFDJm0Pf02G=Lt(lC#P#54WOEMO;rKEW8lw{7k;p} z9fuEZXH0f*a8%|Izvizp&954}Ba8E&5BN~=MNQZs5MUHRGyw)>erabwU!Y|$&CRaP z?@yIHgOh#BLYrgjfDi^|$3}+xuj<>&s>93378PdD4fTK;8Jz7vUm4(BnxEWb`d^=8 zeU+p|`T3O-&-nIF`l_tV+T`J>Y0L;e9`$eihA+NQzg!`0&LJ60-mID5^mlje_{GJ( z*s_|FKu717$FTAt8J!zhfVDqo2K~ws;{iNh8Jg}KfYLeJzv$TA=8JS%$mfGP`ImMuZDDR<;bG@W zlEUiFzQ5tn$R@&r%`zz~7r&U)U06SBXQB&AdN4svbzjW8Ew(sij$R0@aZoz1S)CN2 zNONyrr8);MQt40U@N)NYFL;)GL*{vOh+c$jKiBAyDCwlq>Cq2%T1|JZ^ycL&6Ah`g zP;|Pmf0eFMreR8dJksO?jZ-E<26Yeob~NOPx1VS`*26m|h8$;9DX%sWe;)nrK4hygM8I4bg@x?X!Y;?nAX)oj}X=O;n<7&2GX;vqDex`;UW3kV4{Z2f>gOtulJozFDJVoy% zT3<8%ru(w2^>LY5u$MfCX!FV&bVT9<11EI=T%x~Xu=aU#?0Kfs@N%=0M<|nHw1j`Y zn+zbjfjz0G&yDf!`D6&IK4p}8Js~2Zeh#Dc;Va<9t+>=d*vd#14v1IB#7mZ zk)X;1t3T>}hqmSp8~_e-wbR0;YL==x%x?l5tCT(D+-nOh*OjwnMXkMCy18>;uuI%O zg{9ypbM1E*>l8_CmPD%iK-mhjH~|oAoJBgTf3@C?|JYP`Ygr(E_07|5e2m4GjA_&= zQB4=m)5KJEZ%7uhZc+T$E{!r(io$j3)vWW|2aUQsz66fTcDVdz4cr%4bX!QZ-vhO| zYRcwy+i?Tzpd(Dye&4ip^cb78#td%=SRRNh0(`+u!+Pzvy@wAMq9c4o1*>J4J@|&{ zg>F`&XE~mq4Zr1-Q6#ybfVWK%pD%PR0*XB?JIkmIQ@1CR)pT9N>6(CjIG%cuemH0miOy$cb0!W%?PpTYDdNx)l1Zz;@ z7Y3#WdmVhIPQnoC%|X8PM$L&0OdVRzQZx-W)mY<_^KC%dKpzko9#L;8;Ov%N$RwL1 zz#9?iPe2X*uEo5?ki&vn2(q6?zRMkT+D%ivj0zNLGSnZjUOVmRoPGaV$qeR3>GZhv#6gT4yZy^geS0BKKxN7_F-?*jF z(>`C)ozCGqtzmc77fqwegJF&oi0QOB_0ksV$z?32!rWf&JX=hRa@RPE7PIp^p5Vr6 ze{F>8X3vtvCe_Yb;W`FL2lRPdo)&l(!fE5PPR-`+91C6&eiydVFk|!o_}! z(Bni63tbT-_cbJBo9bQo3JFltB2?0YVKN}@Il-=w)$?H!#jkHC%6&@QXgM^VR~R8b z$HCAIpF;EvAF&8$B(wL&OY3E`hGZEhT-^7-?Cvs0>HapmXT z+HO77Tf$4a4V?KKT<1$PY@8)Y9s$!`-8hrAo9aIHZc$0#>s zdqVQHarb$*W*yUszvdkEPx5>gUlqNd5S#``oR5o5S$dL?A)JByT2QqZoPA+)j4x#M zS6jTFzcscPaI(ohRO?@RlfBNO{lr76jwOf_SH~n7x1@oo8WFb4`yhtpzP-WKT)A3V zT+bb6)~paYM0s_zoG3pX)9j(|l33~F0sT>B;5wG`B;q~!bcURF^2!$;P6Qi7ayo?E zJArYIo4VDU`Y@-5PS4u5JG_9Xo=Tu=rmE03>2H&6yK2gTdnLyBD9te`${mxSe722B zrh@wHZBIWmuf*7LY$K<_U=)`INMF5s`Gn=mzqINnG$;~hC&b%sjboJm|M zxcJXN4Iqw=q0lYQdLYP8Q;(5da_!o>lhIYwF09aTKWU3Sv1&qdVDss_bQ5QvD--HR z3|*nlroB|%G-es8X~zU5#K8b#hWzU(lHwTLb=}A6CgJ#Qw|MWlbkPyj0o!6i8h|IraT;2V8=ntblqj5dT)izw~%)sWUb8-DjQMO zg3p@F{JP}6ehl56iIFtetwB(!(1?zh%Gb^!*mXmT1}`WF&98=mewDj>54 z(yX>_*OG<{VW$fckAVlzhLM#HtuS|73Amk+S|i;bYpn3*8WPL;sg5tau`|%DS3>E} zh)6@;+e#7U9tH|xqz9PKB!*nH9DCNXZ7}ldtoQ8t(b>zm8rPCtFL>2JeeMGNLSXJl z(E@0DgQP!e6Ie)64)U$oHI6=|h1-=dw)KsYz7=d5oBwcZi%t9S@#HYWK*AMaQNm=6 z$(5yqfhnAvc)^l}G;HR>zRLC%_t+yn1>Wd8bcni5S13zE2k{iD2c5!QIZ)E&O@HWJ zN`%)Xil1{uvA?p@zcW3mZAhS>&Tankf;L1a6mmG+55*M;hM<|KhsbGY6L}=oskX3q zPHa?#!du$b5}(=s{^$f=hYRZarRR_($xtJQEFret>VkVpR#jJfTW`sn0O%_NW4#s! z{rhg9{__B7yUWtu)s%frn+_b&IR0t#D>dq{aFW|^4PE->;AKCuEFnZiVqq6^t&BZm zI5k53{Fa3O6V%9M{HqAmlq;@3eNW~+>bYmL<(~1KK?*kL*5@Uxg-ZK*n)EunexlS-%#$B0rTZA*g< z1142&m~qP{by0=+`&BbfG$Wwb_I*0pqLH1t=rnJ>EeHfOJ!`wc!^JJ-#l2m6RktxC zAKCn6o+!2DqZli)etG#BQEaias0Hpz2BuvFBevOd+YRG`Df{i#Z8<=)7A$+Pn~KrUl;!1x{Eni#UlDP1@=6l)q)R)#d^d5le=!h_V}0{_qf502N*AhkWQh|C zMvJhEV_saL)WYozFDbvz%VYX*{Qyu-h*nP)J&FB^u6?N=k@CBkApI(A6%-*R*GD}E z75I5)P7vv?T>S#_?YkVLJ>^yA+kF8&l8%W$cz$o5RMK9;_pA}F!&UA{n#qq4$V;)W zLQX?Il|6$vBfKNiSJDRh<|#czr`WlXl56foh^x}XGV%r%zaKytr8eLUKVsXmXD+=C z;AVL$AF|6YAc4uB4Jv+;=eA7}Gvw<*>fxG@)JYpL8GQT%-h_HYpB9K|qY#=m%8JhL zn-wt##u*px%N#(N(eJa!Mxvxmcn()&az0-cw;1utjDfHOOZiO36PfgSuKB^3GoMID zjx)xzl#gs@Gb@-YnfHxZ=Eq7aCUzf4Myvifn>PGZ!}4=$80$Uyx_=kLR@ye`B@+f#dmL? za>KJN*RJ9hXY8*?ZlLY4{J>UmRyIyU$b(2a*xE+FWeT%AX?aR>?EL`Hm?qWJ@@q`< z9rf}QZyozKQgBE55^JUEZpNBqK79Cd!I5OWizaDVr2U?DB z*MEY@Mb@01LECP^q^Lg^S-^GEr`(fR15cl+dR++Zh)%c_=_A49)amTr(UJOiB|G^0$N^+LR(8m;%uBc;M zQug9(foMxVr*05WBQRkbmCHA~>x`UmUP`V`23@H|3#_1DCIQlP(|?E<`u?S=bIIO0 zLpu6U&OHX3uTL$)eK575==02Kx$3OXHQQMMPP!D;QBN8sKFPlXVJDW@Ix!g9cO$=sZ`yPk#+yLDWnV6r&oD@Wf5N_wS$RqhaB0T475RJiB zf?z?WMXB>b!ediwuwoa7p_4 zW#>)8=)%%HHB>JJ;n(h5|1FsLEU1aAS14KU7~4ru!R>sxoCK_CFa~QjKQeE&gl~TS zz`~^H0(S*BOGmMZF97C>J)s&8iWzkX$Q-q#u~q@>n*(nrwdEn1oa|nxOW`Pm z0{GE%Q$nlVH##43+^t6x>Mm$q3yc15t$E~__pFFTY)%=}QTW)5HJ^M*Q+A8PmhHO_ zyc0?amsYnlhOk#GUuCV!nMDV`$1Pm2Qpq z3oWM^np}HI*_($*mo>!aI@%eX)$%sVL8@m5+nI=3{r>E(>+hPTqg@ae7G+$I`|qf} zyI9t!Mr08XV#ZL6(Mv04_peE3gND#JzD3__e#LQ81u$cdpt~wzLobVbMw`QW&MMi^ zpzB2Yg=Awy!<*AAL`AY>Ow4w)DnSppeUL%PaX#i4H1%P4&nrG!>C%e{zEg#~cDe=9 zym{n>f(=6@)GM&d2^PEYAIEW;aXFT9`Hkp7K{YAL2b0AF>Q2j*KRQ#%5{b%%m6m)Z z85rT3pb|Yj{20?(9-zVMQYQ$fA{O6TX*W1&So3dgj0R7z`>LsLl`t3_0*D+xm)EMRlswjHdKVlVM*5dI=K6BGmPyVTqZsbkvO72 zn%Nk_9h)feE^LzXY`z$$PgZJ~U4s$a)|Beth=AIgUaq#$7iR4ATGH+@0{6-cMBu2Q zmT$AtPNv_nS(`h!Ly3!CS+(z*uP=|EJbo1#8%CFC4WRkxQ&>=mpxY99K$-JgVCANT zp@+qVhIu>7njiMJpsC)$H@pmqtsqY9u_6lonq7yt%0lk2J1tF z+C7UD2QnrjX*ayiv#oA-vG)4Rl%OPL&(22XmpH)NJsjExrqoB%)ew3k%^pO5EdC@nYdpr`Ikcicb_M3O*yXGkpa%jHjIq z`UPTzh?>17!lxK;Ep6tjCvTUFW7fhb>V-bLRp8-V)yali&_%KkGYGLk7?g|*v#Sa# zxDwY?uBth7eyVMk1#oaNq~TM7+FdvZ1hSW)XB@(ld`2&2Mv4lw?vk*&eN(zm*`Ww) zyuBH@XEd)(=O`Ft#f1KhHXWCV3F4N7)gla6WC*jq6fi9jNLL~itpW5CfEeHT8xQHw z>R_5&xeKn7bhvX7In!paBes-c`n4+E)ih%^|CWa6?I5i4rzG-~!JX%~UAWvtm@B*` z2C~H@d5Z|znJ5<*U|Oev%}~x5V_^4;ekIzn1XRVU0=-_I+dba5EoBz2W#TVDv#ngf z)_GMyafpSS1vz)H9Q?4oZvX+Wt0x@Wl~|RC1pSa?LSNyij6=~YjS*P_5tGK- z;jthydd1L_ix&G%J+5_a@0R5S>=X>7e5;sZ`dC3X8&kfE-V*jJ)D?o{%q?7dzdV)T zfg>Wm=T;is)JpSdcUJzWtLP~+u+d}L3{snPUWXRec4XfL-#w zDFc*WECq++^Zbe?*v>;P_?9~zf$x9kfXYFMz~>4?C{sD23iPdWfwyx(2IX=?pIU{o zJGqmp%VjsKinb{ZWR~`Ryv|wfela&& z|B>dnE$Z@8Ih{i$`H|foi@sb2nxhzPQR3Y!j5o><7L`oj`>MmmVm&QE_<%fGLwrN+ zKm~(r3lgA0kL%7I@jh&lk?XuO4VF_;wwVFAm_a>vNU8gB++qWjz(Y`E1ySk-$!e8W zg?Ecq?KF?HN;@POmwk>Iabp$dDa;Q|g&fP5{Zu5_FR7K0us*geJh2>~x-+m`sH~f3 zOXMj+N3iyC5=RTqZsaFX;}6Uci&d#heS_h?>>C)zPr*#?)9l$~@eSpUna(c5>XvFq zV>n=(b%~<&X*w{-k+HHiUxfp*_wVoISkl%8HTUp-U8~wx?@XwL=!F6s?G4bn&@E%* zMnj_wfh>;ir~^8VF)_G7#&OBj7>|&*^@!i#$=N5*q&}v_v2b1|qD!MpJmOuBCPI|b ze_cpSbUrp-4ZZb^@nVJ1oUx@At-@t(%*~eZb+W(|lZ^o1pL8Xv#;nk8`rz%7iaBzN z@ttIi_MdCbo`f1j@wKX!U$kR^i4vQOYu@CAGHx$1Z7yDnLE$zcJuRp>ervDyku8l@ zHCy1LhR1I5Ra!_rPdE&Xz7qW|rL(Bm1`b(U|6oIQHZM`Iq_dghGz>?4sZp<|e~4q! z=*P2lH7RL^g4`X}JyJee5bs67)iDi`zr$=d0r}pbNUR?Zr9R09L5sV}vn_0x>FEUZ z{dasbB~i#z2@!MGZL2og@v9ZD1VS;HXF55c_kBiXgOf%h3Bl<4TG*Yg>z+iuYZOu9 z2KkH+bE9pu4_<+yG4HB(SxuPK)(H9>u`Z7sAq=#&0#klwUIG_hT|(2z-o@wHz|zE` zu1@L2k^B=Hs1lbfpEu?7H$~EvFsLAB8Yp4aXy6=9bS(!kr0uIM%dcpyn(PyM^o$~g zcooq%c|*z;y(zZ6;5>FnQ@)x{EodaJw9F3rkggcfI z6p5tIGm?ywi0K1(Auw&WMNC!K0!3d=W^(|U&(||7jQ7)6%vWh?Q#g_SsmuLe2sewx zM*755Cjr}tf%)=k5O54x|dPvt$uoZo;@$dQz- zhs1;3>1(T5**v0oxAbGUz8O2Z%)@o|$6hmFyeMnsv6|^hv1@l^e@uhxLcQ=0 zNil_n9X*S`EZt3~LGYMNExot^`vCU3xV~Hymha41pXZO^3CgaWVfcT(2CmWGbm(O1 zb6vW_85G`ZWN7#>wWnAMMzixLc-&>;%!wX!3ZN>p(cnY<;_4vw6HFy>p2roPDGw{v z?0(>|SM;6u*~u~JmDT5b`%zLu5Y6u7@V&FS@uF!-EHSwthsFhF+Sl@nk@?9)YtNgd zuYYeoFZB47qu78{FAsyY%|zUh@EiZy=;%a_v5fPI6nIuAE1!kOeBMI z54jTAZl_K=N6Au~zHE_)^FTZSIgQAY%>_tesGy5U;&VcBBS*jz{wi?~#0|0Cx&?c0 zE2>IlVLHUurwkIlr0LjZB?ia|>>l|C>I*mO@(B zvcfat?QOJ-jP=FFfp-h}G*KE+q$2w*kAx;I-`k6e#19`%h891J7rH@ZSuU@zPp86z3qO@YA4OA0cN)-jyMLf4Id5HV4`}tsk!I4=Ra! z>In3=&6KYx73KVdp)5_Ieur5g(r~`c5Jn4_N;|UBewR2q7h04FQ;U~4vL6J`orBt@ zSA{OkexYDS<2}Uz&zgBKS`T8KK53Zz^k4xtX^!OjH0R-nF&4dvY;ki@aw(02%jh|d z6i`8WpzhXw_OD2KH`bAAWzQWbfK^bZl6DfiKWrv~6?uJdI^39DxGv-1+tRt5&-rd| zyU8b;68qD5dI_qLFfd;Trzy0IETo@FGSa;p1(Ar6$NvX)Zy6O=)2)jJf&>dBXn^2u zP2=tmG`KrWEZ0M1) zIuu&71k?>DAB7Z6TZ`gpo%6eb{#~h)AdXqjdYD-ReOS7^F(RxjwnXF^GOoFJ7TP_n zt~H|F+?M9#q=dBNo@&EIDRRp3%uS*}w-hdluPVAM`c)1VCFv&A3u`(rS&J#rel3_0 zZ5MJkC0P^3snxZLe=aA8drQ-JcL<_eQbc0%ig)j>ua@weEtw)Kc^lIfqDpv#uw&%C zDHVEs2(m83;e=0&zs*X7^HMmr;)~}`Y||Z5PExK`)YsbLp<&U z!I{-mw-pt(ab}cV{o+q}XLndL6_}PSyE0h_14PTe)5kYw&4uU_HXNl{S;;{8kg@!M z3FkZgHsm!%7?7V`6oE1AO+BDDYk-L{7n`NuR z{Wfh6&y}5ty~YqD;eRPje~&?-3Hp^OI7P^*U0QH1%Io#~7ZJ<43Nk|xg^(jd0g*+% zC;t8ng~M7Sp(EibB6=jTok|70ABHI`)c}580;Pm8d{4?OI#8^WN{S;+6 z7=6b%O^|WxrcEv8okGuX9kzBs_NF4Wt`^|wxyg41m&w(vvsTloqmo;9oMJ zlQ#$EPhG=Oq{rl+eMd7Ic>x-M8w>MtHn@|_OWZ%aTp3k0_2E^*(QJjH;6A7M}x2u3leLROWF{ zNgG8GLj67<#%^GD0<~Y>+P+}LszXmfyQ`J~y7{B$-Tep>v+)Zt>lI8buzA{FPM=^0~RUTf;$?Y)HL#5io{EF!(90A9LqqSIW}*PhpdN>*$fvcz@S# zsD(Ci20uKT>H5teZ!=V#_O}k1UoLl0uxu%Po?-v!TrE8uV^;;MoxPX9T-r5Ma^;}o z2_+HRUhj$0ptm)8_$`wvvS8zsQ@l$-yFq-AnX`$Hc>HHc)l2vlW$5?IWP4(+r}pbu z)MWkX5tcC4Tzs+tEWHG@c5SzOyU*kMe40L-v&q`d-6$?&@Tnpcldl#jboKg)bB$MV zY9xfHhzD|@NA|WdPQI6(@{I2(luur{(w? z+V;FJfXINpgQ#@+05#k&YSBU_3ZouPDkW!&aBFBCKFE+(xz;DW^fFEV1;L)<+;`XH z&;_ha;==lp_UmbIW`{F$Fg@vWsjP$UdR{_uPu+41yH^C0Y(|%+n|B{<))y?aBM1a^ zUuMQmUcLxfl0kY)Iv5;sFsAyNC+$f{l_V+a8GX~35nPeqCfr5XcbWqIBqOv6GcW~Z zh~1dUg-yF;cDs~ySWPlpYjwHU7>cm$5wVXoukLH@+rzZMQ{?`M>+b<)C&xHis2ShFnRDZ*S8FQ^&LjZvjV3$ZOMx>S# z${36#n}VBJ9~|A)(}%p6XEUbATYVim zWhz~$8O)7!*t@|DyRF5JPgSyk>6>b+oTCRx6SuVXKA#YG(y#4};WjLXtE}Bs5;r%L z8#Vb5+xpm%T+~w(WOSuwN0%tBlz)(68jYeUg?%1bxW@Rwo}@$I0?M4r*E{5d8%lA{ zQ6gUJx?L(994iJ}s`r<=J@wy#@y|ML68>8my32uz#DhJfT)-O;s+tsuVpLe5N$X_+uRiEgkNv7Fb znkoGdcKiGm$B|r&mY52N zsjEt3Mu@93Xc(3A(SjZJ?H8UWt(08SIivN}n`AwbIC9MygbKmU>Jr}^ZU*KO-umV{ z-uUV!F-ink?$&d4#`MQ`Q7XO=`}BIga@H{iACdR18P~^Yls*<$G$_nOm==aNVe&OT zd!rdt!{5H1hcC3!WoD{l3gSlUr(UcoGKG4z*o2{EA~C*+-4T0-4=(h$c3fMZzBFIs ztPvq^;|2`7;J-t1EzcO=wZG814X6~l5D%vHyqwStDMp8XtKH2^2blooF*HkTN?}y~zVv6zf$yFsUn%4_O9_3?$tR6>1 z=qO*sqcbY5MR*M`|mk((nHpn4OI>8__w%t`f*8if_G`PP-b0g*h^g(B)F zpO$87l2OaH5FB3s7GuhnGjqyU35w_|fFca`vQvsN zh@Hwr41e^&QmU`^#t-c#y>Opbt+w_*g@MN7`Jl4Tow{#dl7?qw zGsaPN#J8wOG8E+u3^Mm@&JD!-hA3Lw|HLddKMi?bugf#D|06N>slBf^nXVcc5OLkf z+Ma9oS@WtgE6M!#DOXB&bn1>XLY{Kiwo(dEvMqKbW`c5&03?4t99S`6u|cy@Tj zFXGWrNR)VDf_Z$I0hwz_){}nm9y3L5Re)MGVB12oVqd!=Qt2z-vnK&SD%PIBinBC& zqlI$Gfy$XlC}5)gxz4`P;qu0w^9cVNPevaMSYn&kY$uVuIq32_2p|c&1^2x6`K8Sc zqmNqNSNzVr7pv%}XgfF;9X9cL3o%O8T0duHyr6`yB^#u!j@jEU;f21%`CY6HW0Yqm z^M5%&sgUN$nj7*XMZ5AO6qYfVriPvKHE^d$?!V0boQ*=#M^m|XXV7L41FgD>-ofw_5f`D^1G z!K9qXD#KC=?P37-aj9+++?-Xiac$WzoPC41J6pKL_8eH+c(nD@DhKmohTBX{e(Nq7rMq42Z4EJy0p7WXT3$<39iaL z-O^dm*~kF7_{=mkY(#NQjXe^lth~}j!e8ck2_wE(nRDxQdHpQq`^0OzVE5vNSO79g z29oK?)x0Cm0^hfg5d1;dqg|h!U-Lv+Jc>@ODI1Oj8Jl}H#E!M$-JvU2yB~bw!@37x z(=>>EC3>wsQw+^le>lW3>81sKRS>7-+4qw%+SQa8*2cQo+un%}_1sYju9&cmz4|EL zk>0pqtH+IiJt?)r!;mnpgfP%kbH(frU#+UScCEbMrH0c#nGJYvKerAYC?6aUhpBMY zkB;Ty-}S;w1+coD_9cS;RABOxQ7QKMtCZQA@30;fwBKInn~FY<%Ru|2t&Iw>-M)&L zQp=L@H?t`G>L*3}UhWH3xYve&y@ns5^$#QI)%AGwXCJyXbL}~CTVZs*OxdsWsV$ex z<9fpNlX`ym$==oOz_dR6%1lZ0G+?#vgYU2&_H_w|pQ&usOH@wXVo$JZV(qJEd=2qs za};Q$0YA?;+<1>Zx+_^v)LB?j4!LmZ_qE>sdN+5T55xy{j))6*kiPC%z5^cGpC_}5 zkJGF;$bS9o2??>0D23UUft^UF4~s|ZR#b~0mO6XJ$OoA+S0Wm^3B;H zZ5bF%lE~T?eA@AeBQH=z{sIos?j6E9(}$kPRd_vhk`40XX&g)A^&O7(^4csDj0m06 zNan(dv54f$-LD02amYa5CZfd8EJg{PS;Mt$FIn5dip#WdHsiVb%@WtF@j9N}n3hs2 zP2`RRguX0mFO^l%b)bos9zLXT(&+}))TSS48)((!vu~3DD%zunR~)i@ijR7X zesN6%zu)Qd?WOM!a4T*qq9rh(KH1FIt%=pNU}X8$3XRzqRC_8tr4wJ0_7vAS%RO|v zi2?H$nIGDXt~^Y^DT<%|OYt#S2X!1a_fwts+wzEQA5dj$H!d1l`VLKCC65j{cE7-} zB>x;IXFk)4T&!IFv6#7aq&BI!cJ&IIwi#1V1j)+U6E}>Ht0_m_`MBViNn1SHn3L*?k(0l2ic&3JO zg@u!wlSChFs;gPMXc!WW+3lDhe@ZZUtsj!{EWi|GqLRu@N-BigCSM!Y(9r-J5QpH& zZE=g}$d5u>c=>*LX~JYqT`L7QEmo z8kjhnA2inKeHeT?LeE$;Is>Fff3X`2@NYXSd!J+7;>o^0wU+tmVt4-0}*b0 z9Y!N)Ps)s6uzTc+C1D`C#VO4|FO*sfQB*reJeNR5VD&`h;bCR1w8^xkq?w$b?LPBz zCAzzVyOU+9uz8Z|LrnCBxq_GJ=z=QdSj0 zTvC$wcjnSPTj6i!5~P9%*d7G7a)3k-W_%<#2?<%dXwn1OnEwtc%mN93`#+*C(F0i+ z7+LuEP{3A(kQm4)Ow64B>bQuhkrCJqYy|?_Ycc}f=v!LqL%L+)pbtVxhN>`bkU0U)rUsfC3;z!>5?S>MXg zz``D&4+dC6{_HLE?M(oJq5xUQ-{XP3qm7LnqzwSr1!SRb39xmvb^t@_*qIueH~_31 zEe*hS_NK;G0DA|poyEO)8?fEIwgLKRh&im(71IRGAVk0zdk| z18giD?ExU`dj*-e+L(Z??uD6J8v-8t;s&;}23T8x0S?aA00$F0Fc@HD?Pv#43S@-# zrY-<`$WW~S;K#0+LJESc@3m+TwlsarJr2Uq+8I*H)=}RA(lsz7il8-Q(jce)J^<)D z00aR-0AYX#KolSbcmogzNB|@OQUGay4B#z579aAWsrUWv)zxDKR@YjXM(Sl6vK#rD17GRhAY10QiDC?p4Ls@-*0RRLr1VF|HFb0?a zOaW#9bAScF5?}?e2G{^>0d@d;fCIo0-~@06xBy%MZUD$lcRz7p%ZCpWM=N7}J4Z_k zeMbj?gQ?f-v!_x;~IHAFym=Kn7|Ie#mkh>4Z;Uo)W%P;#{a|0@Xc zAKx4-_XM)P;;8@E%*Xrh#(!o$GDD(UvqPAI_ar?I-~-VQ60jK(toyJ0{nf`ZED-J? zC(&d282Fj}f#LRem6`Rv?%&cL*@yr4>0dG*`u3QAZ0oOp(+?EH$207Z=;aVbB;y0q z5%>@Un-vo0oBf_A`4=nlA#(R)IcARg608uu9y{CpXxJcRLMBM;^9Nq!qojv1J=XuL z1*ZGZQjPq|(1bjDIFhKK#}zJU-B3)>aOGKFq*>JumkH`q9D4=?8TbODXQWGww2;&>4{O9X`*r?BGmii2p1p< zVnl=0G)sEPIT2K2-Iwgp(O*#45lfEQW_eTjk~j)h>IoWFekDl@S3y#Nr7uO~^0pAA zJ%Q%Z*v))<=jb+=dG-FBcfoc2CbGUVif~jy+FwW&`eX7lB-X0M_;k^%jJ+n~|hiZql$nbkT>(d8f?DvTdmWxYf35Ql`56EF4u!$9ZiJrxA zAX3Ok^)W42?$rUQ2u|)8-IH`frbTWyGQ^8^Dsh^u;*vY6Vl*2thX}C3FGS4I@Pm&14Wx-P3mW7LkkL7p6kfqdcV=|0+w{QF z^G1i}h_3UEPV`1WD zcm{$$4V6LeYhY{jc!%&FAG^_YzM13U6_;AN zMN#IC@v9BBTS`WuOD8E~a@Dw{VSxwxb)&O+`YO@2C+jE2;Dzn0WJ2W!_qnqrHc8Xe<(c6%x_(uv2s{G4v*CC2wpZwWbBafk-ow_YXG46{jW zV-{4D7t#H!_qmM8BeKThbh!*0;q5+(ov3r`j+7esnz7p)W%1G-=9VA!#op((w7}|# z_a*0->e}zbvJc;_zrgdT{?ORWlSTYiasS6w<@NN>w1s}JHiRsOQml9JX77sTM*8hK zMq6!dR^u{zXMC<%T`J*?gyq2H2R6u-PWzr_?(3fZ_VBp~VcjG+4wVXnPj0ao zF01&mPn%PJR>^X;tl;3T1>vQ0y4SPX_fc1QYW5>v?tKT+zqM-drF_luBVjlfPx~A7 zre8Kivo;BQPWnfbE+44dcZzPt7Ib+ti#2=D68RB$nJ!ayfFqMcX?gZmQrpuIhX0Q z)^)=@Iyb;mywRz&ePE2eJLv8BCLaFu)O!mQ5@Dyo z{zWHym7T7qFGY$ZCkrDFuk)>|@GqM>+x7lV=z*$E=>(^wxji*%jhg~F7seqn4@rQ% zxB&e|u{A=%%g?YIr%*YkX@{&(if3s&< z?teu7dwZ6NlZc)Z0tJ9TAREL#1nd966UT!&%gp-c4;l0Cj{lda^kIbmj7tB_NyEdz z@8r?P!tdiphZK+L@3RlN$D&N^tdCwF9z8NVrW_AWBOcRxaPg<_g~t*Po)sQFH~i_p z;n8!(BLanBKM2-jWrM&3Rwgz`o}C?dj};#sW&k-Lpn(+vOE`%*AWkq?iC7;}wnsk@ zY!KkX!3ik=guH9GFT%ulF8~5XfkbSaj{xr;b#Sn--#7B;GXo+3;_QQo71AIZ@DZIn zK=ud7$p(S6_s&6BAhrG+>ObTky8o!MN5>KWncffo{{K&>C;##r@o?p_{(YH0{dL?s zqj+>%!Sdj4Y0=i@Q`&lVr${aNPE{Qn$(K1zG+>tp_5iXW!qcka(NAM+2`^KsJt zNFQ#n`)dDH)&CUsU!VDX|NdF-_r3f#?&SE5JO7ujf_0pd@E>E6DCe4YH2XNMR{OpHVz%YT;l+h5OL@|aj4=B}8j z1?1h1CP2(W-vKNF23Z?|wSPC`GLxVtWxrDQ;>(6=fn9cy7!LFzbA6}g*)B&_nu5W8 zzF7`FBWbdMbPP>2e);LnD5`h1#o&~C1?=*$iG$aTMUxLGd}Ko({D1oPPwI+Ey1oP=-OTlGjvIJ%{Nz9sAj}@RElHb>nT(i zR0+XKaSC@jSTAepi}ipdu)x|zD{D8c2DNW$WSrL~8mOb}FZ#wPQ;2A^J6X7fMuJ+# zOL4lJr)D7G%&WFa77g+Y$T3Xv5Q)hnJXlurH}}3+MO+~vNxT(0Qs@-ymbn2Jf~%{n zjLli3GejK2T1-z0XZMr1;5sJG`=s9(6*ShsU%j@xlCDZn5=uI*n$I?E1<^z~S^lu^ z_!RTbbf1$g>u3@!0S`Y8=2m!~PLgQ=$mYt6g; z33qa3A?WIAER9NRYqhda&?&*K>Fu0I3qx3P{H}&d6B^Hn4;)|PFb6@aG8Awt8v`7u zA|VyyE3e?~Ai;gZc4pL4yZ3(U>IISTag`}wayiD!=Xs!$7iD!Nme%f5x$(oegZj@u zJ6_+oBD{^FBXTxR^SP>FovBljUn3&H)l|n>B|uE`AYcRITdF6MP(`OaL%eBwBkv5G z^_MyimvFo>#+t=f52jo?<}4=EBibhdxPD8Ql~8Dkxrx-9Va>W?s;E(ORcui*Zxn0i zDnrVwCfZ7w*{Kg?+4#9*2hlO(F-B-@e6E?Ed$&S`r%OK1Tci2*X)|XHWfRiS zE=S~Y*aK>f4e#;ahmoy~8s)ZD@_BoX%=u9c;P6bt5C}Lsm)uZ0rn=b$VxE4tB^7Cp zOhI=$6A>VD9E`vdBlD9;s2_sOlHd<>R;J6pt=zW+b-(lG$Fd1r`}j^HOOMle-I03@ zLC*JBL_;s*87K6Y?{=O2@~t$kORrDmxOr++1TgW7&@RwqrjlGJ>w3@pEK>!gMP%eV zECkwBLNH$0r)c?RJfS$Sc^df6N63IfjwIAKBm(-`^-8VtCjL+2#5cvW??J12`>2d< zKw@+1kyUd09!kYD8oH9*;fe89LR8Yu1MdBUd1tqhRY=65I_{qqC@X>TNB+KNeC{~n zgiv8R#c@^7Mm5a&(2`R}u)gM2!)m7I(WgS45p0L5DkqA=k5gr9TWhx2Q=!>F7obr3 z{Yq@PgYxB({qeL@gQM@P@glSZiatazuoBfg20a+3VZD&w{>jHPmv+)35`9I3r$=$A zM{zU`@izS4_BX6h4kMErGtcYtXht@@oMr`SqkMnZj`P0%XhrWeu@^}!msodBizcw! zdejEsJI~TXvEsV@k+S3f&7fmPvYirAb{53_+=c$r?&n>o!%dH1pIg39L~m@1$TFwe z8tt5Zdkjy@K;7i={AN~q(Boj{bS>V)cCRGNV@Ee{EbH=U`|2whtX=d( zzTrGK6fNOR=U+`-$=;u_F+>D(U=sIy5K>RWV>2drq%($%O_Cut={+$;+MBYz-OFAjF)Xonl?nyRP#m zF?)RmbS@|YNU#@sIUP>Afa_I8ov$}X0PFO5&W;b zeINFS;$a33j`CrQc=6~#n#S7CglsbVe%SFry{Z^mOxG!HOJ@pn`F!5aUPMeJZov%^ zlJ;Ls)L&V$^_6@*UF?_`P-GE}tuHa2e;z2QySf31^Fo4ufNkBkQ`&PjFun zl^x){K=iY>gMqhhpZM)}P86w7G7v8Q85 z`8&RoNT*A}rfa10%KK?f*=Xa)98KYue$1C|>SU3v-mXr0IfXK?wb2!LaWwTwoHvlmE>w2lhzAbDzV9UMDB#~ zjDqLteWr3YRcWS6Ov~Ug6T@s^cQ^%f{tAq|ZQ$0&Yaa$>aUxH!EVjr#1wJvKWc=XZ zM9jAjR+aCrqD=5u*hWm7zN*dZHB9q#e9|N9fQixfd1H<(f~pOP$_83$Ql7xlBH8=$(j$+!MF zF5U8++=+lNgAnJE8`DR=_t+#8*8aUThO1hu#*vm4OhB1&!5`IWW!~u@KDtd~FLPa* z+R3%Bf(ky#sw1KwO)EaNi0@+`tpb!C3{X=WPxCdYCAp4`okdD9U0j3|r@~~K>)P`1 zy&T!nd!?EY^74~Mm|3LiD;la^5+3CBVdT;igp7_;QK9m$3$j<-UX#b>lVw+P0;iN0 z$8Lj~o~3XF-c}ov=VeLO8Z$?I?ie+hPxEZ~Jdav&u_s{t5KRv+x z#&Q2tP|3_s7usvkm53-(0^jP}=63giuga0sCA#xr8@jX-~0z%x<-wT$r zvj!=G9W()QB4Pj~u!{pg!V*$X7y?TFUb_9u(A9i!e@XPzxc>ugGc&V7e0u(Oa9aZcx7l8P*)Jc0xL-kgNp>;C>-ti5H36u_rDe}%Imw@?9hYk$}Pax-NryNh`qW2s-4ff``>B8o&qsQgN1q~9`xonv7 z2Va{P`Mt7O=lnN4qkVVtcSjvP7Pv1&Vn(LhKTfjOI-l9rBX$fmS`a329oB%YGq19` z-tM8uv{_rvYPY!SY){Q9Cp0hCvZK5ko~^0mMZFq-x7IzrKu2%QmI%-9!rr38OJ@rS z3goW#uG+=14@DW5Zd=r_dZds?C5(GU3x-xj-(PAH7^xFLlh|D9E0AW39&*^5x@s(z z;*h0mV6rH@`DUzTgeLf~yy@Z`mk)_&wygNb7NOKw1-t)ML4UMRm7FNc)q-` zVYeZc1vUz=k%3n25SIT_StV4yuu62e3RYdh12S@Jm@3?)@Z* z-L)Ug{GOd3wHsM{&V#+^oc$)Xe|Q%rEKO4=iP;|lkGe;4ud}Fp3aCG zAagXzUgAD$nfefry%qQ|KaHXL*5`R#3(RD|Lb$_sdXA8IO>jrc=YV4qSyt>{G-IDq z79?Z}d|TjVPfff9cX{_Ttgh>d&1Y?#p|^kCtSG#hk1}R~VZ`VnIq{vmkbI(+#LFM~ z9oY=}t4wTtDjfq?IEnT7hZQ|tjn;ugcZ!{EN{HTRtQN+uui#xxG}k)Noj521*pv2f zDd7)!oq0^+rb1^|s5o;X^|Npre)_I)aCifMM0&B;KoxIKxy#CU@K-F%C^`^%mEeZJ ziOz@AR!u%#L?(%!kDEDQbt6Z;X#dj35MI+t+LebyYjfPh5|hNf__=2jnHI$}0g+(` zq;;$JE#JMBYwMTqq6b{~00xm@exTF3KhvC_eC3n_av&AL^HV$%0(_XM{`20l4Kc+~ z4e?AEcni9N=eX{2)TU?zL6->Cp+zx~ejIckM)npxxe+Sn8t^3B=jf7s&R0bSs1A_J zWW>!5U2>?1M7#sf_@>`AlH%n)Z7;i#vtRkXM|T?dZqRdOm1=F>$x&)4B;sT3h%8zZ zpQIvZecpAfHfW{Df~La57tcd%wyi73HZXS`dHDi;W_1>hvWs)tcrC|tme6AO=cbk( zoUte8tJ{XoE}EKIyb#ySBG>Yq zib(_;kcGUCAEtr8z^wM=GMZQ~e)^o${27XR2;oaZ(TW6*&01(p@^&(Bo4zw-zbChg zU9{?~o7pxfZ_L;WXqWZBlrPshC7hE4PNKQ;uUX6vk-d!Ap`O~S*hl@8USoaSmV)B$ zFWq2Q^>#JbN6k;2H`}0Q@o0PMt%}9dVj}r>7YxGnhOd3*zIc$4=e+Wt|2)8%Dsa`- z*u)2VVKZaOQXBmBN=w5k*wlaJRc96R=CAQJ)~E#Lpt|7a!*+PKB`fPtdJZK7DIP{p zu|+1q#?R5?5$65!B$9#;z6$2zr@9DTC$Y8wm z^PKbiu+nMMuiksRHNr0J9+_1=U74CNtO_yw%Jm{JkXJNvRA04f2La?iA73E&9%j*A zKq@fuM{*;_E$g*SkM$IhLu$cp^O>9fBpDKaX2xIcm583m54n@UN1sDR# zcN%)?A2!OktX+oK_Q5RENKKdFACs(UV?Jpf?_a>q<_!A71UA^Rgosoo+n)PxK@aM= zO@_CjR`U;WoyKTiwNd*Xz)O2Ue{}~PW8K9lpu`||W$HHkil$N!gq`89-L+vfKOZ4j zL*}5g*5w8#Uc+22Or@g43FnoV%`lUb7dJLr9@XU1i-gokds;}T`^Q@qVJY}5akGJ2 z^ZV%#y$#`_sS@J?GHzO}2(NmZBudVzwpB2=lZ1iiILb5lvD{1*R89ys%Q03Jess^d z0xQeJF2%oK%8dB6ryfHsLWvFf`L0y>o7@tME-@e{r@y7FJQ~oPny^@Hocu&DXDdi# z1Qn5~*&`Oa`5v4Qm{%zz;7>$kg1R!5?rR@{+U>MBe1w^riQ-a+DHP)s?yG) zA7@#khe9ksjE@LT;_zd0!mki(y@FJQTO@*C@v6@a3z=Y&s|)9hk*iu2oP?%sv4EsM zxoyhozxCOsC+fw;FdV&u$KVQp4MyJ90u!Amb11`AE5ZG&+vJY*FPq(y>W$nXWsY0;hRbtx*MvZDSRj8*;f41b&KakiE&H5>lHXQ&aRTD=z5ZoTl~{y z@E`hU%OW@Fj``N?^2@Axe!LE{&qP=24XH@8Cin1yaWZ*3eHaKIfoVpINxh5Ve*9xg zf&dn$_9q~6WhxY#cXqqDl%SS!oLjs_sOLQuJBty?#s#DNH<1D|hlyPmcpv6Ys+B&a z(?cGvPL{z;CUXCF_E1w_6UwfoUHP$_TH>b11$ zB;)44=tfI!GyKRbPN>>FBwJX6jQeTeyd2HA(v+OJUutqmt>MeO{NXFQ+J!^FsRw{V zo|=-yr!Hl9-uj6Rr4wecMRrhAD|fG6!PLd6KLK=6pADzlS#j$RSeqd<6BHgk!h;_d zr7ja8zu*~O12veQp-Ve%!SLqSNK+l>@0w+NgS?Sg&}juIdyu<6XY$KusWPii$=W^Y z4M2@Y%M-bIvWKX78tQ(b6J*9O8{6&FoKu+;p@cw{*E;0C8nnRKt~3*KDZKCh;ezE8 zt4StVN2?FGa5Qh;7Fx-^%U#7J;1HKuj9L_t`z$iY*M^1M7nRdjsK$+)a zKnK)jW1%jMX5&bSWs0wFC$;q?de=~nt;1Qrb^r#n0+(}F;f>?B6V}rM!~v8#9z|5F zvotwgj&(Oi6*Ms{Aiy)X2iqKa{L%y0KAc~n5+otqahl}FK)VKtJ$eSBel`Jb+LNn= zSj4x+dC}K|g}cDO~!XiTPFy*7_L#?4y2(v(BjR(W)O=Nsf?@7qoGi(~yevU7H2`RpPKWdZI%xyCC27eo>@cTr=lbS@S zoJIY@)fU~`L;eXgVcCB&V*gK#-ru{G|BsAb;Nt@C|F+fpXv_YC)%$zXv6`%b85jgH zeDAGp$lCFP5zO}3&i{rH{7~)DewMHVLUvLCz*w6p6nIFnLiv8bPr+Sd~Zx#MW%Ty1&`ZsY*jGQe0z1gg$X+K-@^4)&< z;z>wqB^opl!l#XIWpfjhmZ=j~-=&NBUuJGIqvLAL>kk#_>)gflGyPB^NW;4tJ60HSbaQ$9ci_-lM4)q8a+z` zvSIxDw|F?@B$!lLOtQ5T^1G8hJ|TW<)rYg=r{${r^Bz~Y&bppS8D%5g!7NB5viUbl zJKSir&k4kU)n5&5o-KD)<(Oj5!FfTw3I@jqt_+)!fXEFo=w#@a(3|*S%B`L=sj;>J zK2Yw82~jV;ew79C+FLVPDY7f5El7L5#(r`qJbIdIxsYDId2lv7A-aP*LYb2Gwwt8a zFAomA;?y5YPmnr}%41{Z9TkmU?AC$h4j+TUYpmujSj;b#H$r^}P+qA{{J6B(uAxnW zlqm@B-OGxzYtp(DQidjMxMH#_QRm-DP#7@sP03}t!&-Kl57gN0W81jY%BcrScFnh( z@gCB^%?GGsBsz#<=sZ79Gg#cwvTT&UlNU)b%R+bB$hE-dm1m1w@1;?yaW5)`K{D$o zndt0S!Tf=6CQ}_vJ)^lA@{w~HMZ%ZeK`(i35i<%EDZ$tDtol=D3!TUL*?^m^&&u46 zVDY4t`A#GT;HNv+;fq0bRvD*(?*zdYQ&?B?z|Wn|q#yi&2#kGgiq6;KWNL(#$`F0+IV^MhA(-*q{Xo|F9*R zN|Z?h3$0~_Wqy`ah{pCa4kxST>J3t%Tu1#r;uz(NRd&%L;=b4|6Y<7<)>n+IMnMvX zlUb3evTe!_xefY4%mwe~hTi@kcIu7QcU`u1|!DGJ_8vwOJ zi~*8U4gN*dT#>}{Bc`7|yry#A`m@Fs&AxP0+exvC^gfs_cn3nnhJ2+&PaOJ8S2lo) z$naX->c*?}AX{og?MZjkVw*KO`BJ$vQ0003xMntOV5HNpT(=@>i>&;bFF0E>wl}pk z+%f~~3Yfgx^PIDG}q##6JEJdXi_eUs<#+})*z zJVspD9lWjFAG}d>aTGiVy5Mq>ow#wYeUpDGW|JP#x8Y8_xFOG0MVn8I%mznqtQneV zk!!9JWnBs>MtghA<%nyJ{TRlc&EE^rlb8+i-8v&Jq zTP;XR3Ev5}o-A-`i?ITf(BB8I><`1LK{0hhR9k*yM;A+%JVA6Oy4Lz#ECm1+YD;pigq_IK5Erqtc6GMqxiI5il zQ+)Eu=6EY{jkI56>28SB8yJm!(KqW~U(t*UMEsO?M_q5ft6l@pe}@02&>1BQ4z0|H z6+VS~*4B}yc&>r2MsqMaHo`efHny^xVB1ZSNBo7XXnQAVnoxHq>pX4OsuG2e_n zu%A`DR0vF4M&i1hlyis-)Up`F|62O0=H%E((0sRj{l{yC_?1Q2N`1!&>iQ}cANGI` zF&co*i?Uy1aj<$UurR^LBFVv-bY>o((wmdW9L_m0x<$Z3sYw}t&`iLT*_Q(qPSzit1W5zB}8s$Z=c>!AIdSWW_J3q$NYcw4zv!IM{u0TSABs6@xI z%~BbHHjXq#trvRE9;~9&$ZX1f`fGkHX^qbp#fN6rBn~Ro1Yx|&dbSxY3^CZg%*T9> z?Im2-WM{CT7XZ>wkyGC?k-GYFr1$G6GtzoGBl|fM40%L8B~gxV(+J_XQ@TnSn2|** zBH197wSI{spebdF#fT;>K;)gND;kkPA(1y zh*3PgwY60dh(6uqACZ)*^1M2)w63wVos+3+y)N51;uv$c_++cWFG$Xz)vv4j@hJzX zh=-2)hdv<&;k~mk7_E`U{9Du&G?kphZmVmO!>kY1m}_-@n5Cb|Bza?)rw+MA&?q{g zbaz{TRHO>ubQuh;t)N72en1mO;A9^dE^xYRyI8Q$)mV*=KC>q{cu#RsN-cG0KbG`vf@p*L1mV*GKpvk_aw%Fv8OP>DE3xNN z+b}Xz#t@IS2?}na(t7O^B=;lA)HZnGPUTFdK>@vAlVTA7h4eBHY3S*qX;k>Pz?tkB zhQp3Gw|UylZG&8Wvs)1@9X;x811JszR~cWKsC2!WzVufu51#tMEGDn%1sOEzbGBkl z*(=IiZ4(CdiTVB$ihKY;|Asn%|IOOT@3;F3EJQ%arZNb!`U7(PhNX&s?Zp$bwzK?e z(>P@RAKU%*!H1=QKR4b0-s)R|A?qDLfQ-I_ovDlFJsO1U?;)aRC!z-ewE_QHR^j3K zw}ldIfT)YZ8^wnu8OYYchrT@ScK-`y0v-r;_rjQ%IUt+MnAtcWo;4v|x`(Jle+9{S{}ZNuzDkX`+~%Hx#?p9oow^bG#Ik1v8h+_1c2TkY`GmMXoX8WYEho zXNgpyTDeqv8<@-J?l&$M&e-p6Zx6k^t|z^|6M9`u5-zP+pWS)gJtO|8YE4)fp}Kdo zQY*jg!n;C>g*zFgD~9kZq5VzxVDZ@VwO5CjM{jU$61vgyKC2cHW{s;>H^@o41{}VS ze8=n7A2+fSLP#8;x+@=l(B$^(8L*{SIA^%gk<@bvNr#?->hl-L3Kdz8Jea)MMp^)W z{8^J-nQC#y6>ZJg3n6#)^Q_KG#EGcmvfJEA@tbYgouzRzZf&apxcLs&B9&#@z+y2s z9oaAN;~7TCD3f7kfbz3BzarLV$%Y`ghC{;J*OHdyT7Bb1t4E z>4inzIcUmVfd^A=mTdW(5$oZkX=gj+m?#Lnhq38K9UcZvxy8iJ%eug={XCBfM2kv+ zN(O$Q7Ym*gPORmQY>_pFW;p45>2`%9|H$bo)~+_ImbG=E1meXk>xhc9P&hBeRr$v} zbJmQQ87keZYV%xP7@5^qrtGD0tYxPRcyTg@jc!viu0U90jGSZ|@$)*dDo(~zM~w*i z@hWBpMU#oo9?i5o(+yZ^gX33&D!@gKjdSvyxG~}vZJ(YO1}6s zL5X^;^K7nvl%d9c3h00!N9uC7GK$8@T{&*xQ+K&rAqgn*Roao5D|=weyX!&7BHXGT z2Hw@(mCtk~^~Jss$6eaZ9luxj2I0!D9+z8S#^2d@tQlT6F8w55M_Gmm*(3^Q+rQ;E zl>X{#8u3P8ZoWMCipkUd9PUVt*Kw@)i^`QVrLam&s2;q*>QzNOu;e^Iw(58J(6`Fw0DnxqsL(`t?y=B91>TS-Ycp z5xoijm!_pqqt35njSo=WMBA7hFi(}^nOGTtbd-i+d?@rJ=EE+A3INTDqz;nME`gwg zey)Nqyn}T@H^_-hp{2BNpf!D_P9d2bU9cu{-gm5Q>3RKY8Ozp`a*TO`ZM-fEk;533 z%hM^`sz_ymneoaVoxY*HfCyX)%?|qRI1e)FQE1UcCsKYh{Y%#Kk}Tsur6B|4QcWqm zRMT(pGQhs-3S*wFv9A=l!#c$%V9nyrr-nEnr{H=Wqb*gNViL6!E*o6E#a_j5JEHG47p(${HJ;Y7>ZOVj zF3ewmU!Uq#BUxo=^~6(_!Of)SAq>vKJ^8F>i$$4%rgeY@7}Zu$r6+)zGkd}ctWrtT z_&BRtneutFiVr3&Hx*wxU$t)m?W{eGo-e^C@3TY=+{{u=3RdjPjI|$n%;!i;P4;ZR zgeq9)V6fSV(?;^0J79c72|gcD&88mOh9wwXD>2my21cg<3)KG~&b}(Bj-cHZcXxM} z4Q$+<;O_3h9fAY`1b5lEySuyF#wAE_m*8#*hkL7Torn8BoH{Qv)BUaLue)ZZs;g^# zYdH||E}n5%r>N0t^7zP0-ghYye#Rzu^EdR*wic4a@uTo4!yd+7}6ia5JQr|3*km5n2 zF5zOMF3yW(awupE7IZz<&8OZi{=$2ko1#q?X)IZ#f?Dh^MrnGEj>KIU@L$`{k7blEXU!6cZbs#n8m&hQccZ*8#PXO&_B_K( zT8>oeMdd>!B2oKV*>X5@@TPrEpc1>}Th3iy>c^WKlg^;!k zw`cYh+Abidhg|+4yR#9M#p2jZadX49Uv2L?g1|+j%~%-YXmkr}Q&dMObI64vnlgxJ zbbLAH2YFsuS30S_zNsz?c|mWNlsF?0J3X4#{hH$6I>&@1d1Sc{VY*ro%Af=qu-6jN z_4PP+uhobagdn?ky@!H$cDTOuTYKzJJ5}kqnC>g>sq24WJ9}}3t2RQ=j}*XtqBLL{ zmQnc_zb*~HWS4bA9G5zzE?mXj{FPq|yiqx&_M;kJA1jm`Z^&y z>(dfz{`S5D;csn#hB8$K=_9%7CVt(+K|y!Rkyt|qnIY`i!Xu#Usa`+?iDxr!i{)dB zoWUbttkPs3l=iMOXz+>Uug55Sd96Dtz+^S}3_CILVw@a79(V@^65i;P6C<4OK|y7) z2L=94gNEtM_#QKRW-+z4}T*0kQ4) z%aNjfk{E#`3K}wH9})_*-X0V3EMZ>_Bb`pQTEGs7mzzRq&38#VjxY< zTf6X@GqT#0$qO~ib3B5_%yvRq9>furla*fFtkj0!l_e$n=*1soVq1@>N5K4rrM+kV zC?Cyu*QStQEQ8q?vv@zsbJ>u;$_%Lt>wX3aowF;#jU!H!yGlCQi7{gnpOWvaV_z?)0Z$C@ zf$2~d?yh1~1uR&M7fxuAbJ!VMQjTIbUv&Kz*Y)+bt(jA+QVN?mf z@#NMv&bDo_GZQeYNeWTe{)2>(b|#>no$&5t3;7*f8sE{N3{P{tXgB_g>vzA-UxH-0=(-VkY(Fzsj??shtcm-0au)G%DQr;2HV^V>jm- zy*t`nXXG*|gP?dOyz4V?$#6$z`L@&<;Z87s6bO@S=^%OLudVs|iC6>h6KG@|R( zR+1PksYb1M!yjV>mfwG!*~x;N3wPdg#*bAT+vF)N#FQ|P&)~8XcMdOsJK~(Jh>ztn z)J;4Vc+ftuZ%%t{_L!~9w=Sgls9b+6<-UB`nQ8X0#}qHAl6m?IDQwm+pxUe=&{ZWm zVu*r0N2gmRqsrGjPEk@d6_$BM4n<&c$Ug-?swSg&y_cko7LhHY1ZGo1I2&N%YDkZ* z;RJ!Wl!Y+9I=V71L_}D!(zg;e1&w^MHe)~+!>&BN1G0wIuhuq5K{$?MAJK^@06Ro3 z9In3Na}q-q60VL9*WbV1=xLVdIncmpML`8n*#9E3)d+}On3Fwsfd4VGxVt)6YDkw4 zG(-#Bx*zrx^BQdA_5b~kkuZiw!L7BpKc3#0yYLpq8>)bi54=pbm~EcfsFnN#HN%k< z_P4?KH`VjA5YVKih(V(iVGEA9Ru4L>lCqQr79$_S$qZNo5!1og6IFvHym-$|s`PpX z-)SrXUb{M!&dO7l*h>3N^m8a}MsumleT?rOKe1uNfgCR@nS*#FF>HW(QFq^fe1OiHelvhq+xr-b7?cbn1@mlM zz){PPqS-k4B?*pdXrw@#dJ-pG}sPx&sltlS-%iVw$hC!ovN!cL8O(VB!dH?hvx3RC`aS1k?^U}{0%nDEOba>4d>3%B7R2b z9CQ5@f%J?dfOtln8}Ob}^i-kl%S?<^z!4G?REo3h7=i-N+;HCvDp`v)$671niRGhL zrTPhtO)WR#&K{b7YMM(ikWP72?_Kt%!e?$z@he68;__7i9Z*&Uwo$dJ>fg+#0Hh-F z{=zb1&qb!W0p3J`Q2{Il+lq#=yjI}=6^`^Y4e|+3@&m`K2X8R*3d6`xj&urQ=&*J< zOib!;Be_w2sd4XvOJnDuHoN@W&1RikM}ohJT$;9w_Vc9MoDPK0d&fSFp(AK^dG6Ipy2Pi< zD)W}R4T5uJ{88UB$`{j7rChZWHtbR>ADj`Irj-U{Z3v_?o1@f_&;68(PJM?)S;IXF zuNH(@(T(wFQiKkw6p_`%_bSx7%;!LoH{U0P{GW=2Ii|xD1p^3d!HZR@nH7I))+lcd zhEq0ODgKMK%5-W%Ydk)r{ zi%OZVuiUzS=tqwUkC&9KMWy4(SE9;hbz4YN_De{71;3GoqPXb|)Lz^Hli*Vv5@9b~ zaW7!YNXv?|VIKXff^L&Ho~V5i@x=Y^S(*Yb+uV}p0k`qW9g|<4@CvKFvy)1PR)Cny zRwr!1H5LvN$wP!*7R)}4 z*mX=rN$iH3(nO{cXIca4x!JA}dj7xd`9P5q+hQJTq^v~RBdI^#lTc|FEZ>$2M7AkU zzW*d)bt4{NnT)6E?gI~7wdnI$xh`Dq{b4kjR8SX1E_E3`5PDO6Os-aVhTK+LP8JazOCxb@BeWw?QAGo&?=Z2Rc|&^! z2T~GeWb}H5p2HDV$@fGw!7lF z1*KI-y!bw>$LMcaY&f?Hd&EH}A&9M}dnon|gyrd(Y%4pqjSy%)5KCP1DqmP>TR&?S zIf%dxhjUc?XR%~QCDnYi|Ky*rX^>{8fviyy<7G0g*nbiZo4o&eWDsAXIB@qNlta$m zaq$OaF*UZ6&M-0pyJ(Bc4MU1Som&4YxNbJUrSF{#_E_vbH(5Y0C1wPM=wrp@bOZ9; zh^{ONg{_;jQ_q(W+?FSTQNYKNpbTr)?H|=vH=nO@Z0an^Q#!g?QY&9$n5&JH48}CS z>1MH5NFP}1W?g8h3#sU4c~HTEKU+2TxS2_;w1=e|Tcoyv67yAI;%TZwX!gtvJ@L%d zN_O24rzrNxRQpb~;Vs{MLR-)WhJO2sRSQ;6GjIGb=+9AZ$3HN0^aSQjbA;V2?KiNa zVApoR(SMx9*(FOSmC|@?c3~kf+lIHKgl>G(^uzzE`o`q91-=#=im|QA9>ZO1wK|Ws z9&4URO(ad{aC8+oPvEiDH!vvq{`wBJiPXrCskTxfriT{>8BF^ukIArHY|kUey8mcOekP}GYLzk9&!W&nJa zwI>+A@bilPZ~&_}=2_3E{KSxqShpIeqnv?G#7ZPs zIv|}6=|>&RX{q@9+A^Y4tzI(n+S+k3BOhVXbS%uYu*g0E5B}xrBm(zd*0wFyRy%48a%YaB*cgu z93Xee9w(4h`>T23WRm|pk8;3hX))e=Ywevp*dBUnVC+M)n%#WEfyhu{M)&-;Ok=}2 zj7Vd%kDsbUiK%x(h7ELqB5`Jhp<9GmEUH3L9qcw@0CB>b)gW?{)h#z@|#5=6}hV(Iq7y{I;TpzqO5D=##7Osa{hJVp7 zjc{toI~zNdFO<1=Qqb`CyG?m6NH7jyBPC|6wD2Z8-A%-ifloSLRinOU8upy^>NJF$ zI9le4ZV6$Z<+I-j#jbsG6Q{@RIgB0bl+$yj?-1*#?l5MkE+WnCRMXYTe3Jv5cmfV$ z2L&23bnA%31p|>oJ>9r1x>R*_>}EcLBwhZaGG<-fs;iWINQ=;Ca)3GJh*D>01$sBZ z3D}&XkiRg02*Q#ES}D!*Uup-CNa;KBc^7a2ILpTwr=f#80f_KnIk&@RypR;7waTiGpgf!vxnwjsK_~h;teg#2 zEiM0gI65KvD9n~|roL69`r~LQW1TN5-x-7QZABJSnVJ(}CcZg#s$5pQJ0_;Ub^q&z zj5UU`+}Et-?DY=r?wG0ZgW&A`*YRHB-k2$hSc>Dx@dWs~;bL3Mu*dU1Jix9`2xWWX zJhbnsj7;6hH{&D$jx!$M*?}G(tq;W4I+mpM*;$*|4DD!t!jp^z05oUi7;joo(4Fg^ z4$2gx3bZ>mJ3G@@BWes-A9u1JrBETwhp<#P7qiueP+%mv&4)1XA^~tWn67}j-i-p} z)>s{t)W}%0GM;jt%MmUc&3?Bvh6_>{sIW4|Nb7`&X<|*8zG|GF{7N~}jpCR-HrcIO zbu`&2HqL2;@TYLBw6W&1KG`tG$|zmjO*GBZjNw~cRB3m(ffQ2Q-$?X<+Sd?ABhzwc zNWdSUhjy#epFy#tL2f4_5%j6q(DX=cw<&FzXcx_R38V)>@D>cI@Jaix-!P>9wFk6K zJ+n0HtcxV~eU<^$q>9_nq*5<9%zA$Lol4fvDNN@S$ z*fHRQvCi=`N3~BHO`qg;)Nsc3ifh;hgkgN{9Z{EfiZ;qxJRT z{R`+UckRc&GV-7p-`k)yDSJJg7aS*uRh&Mu2=BY?M5|7nbXaYOX5P^Ctph(YdAVHi`xG}PPpWN%`)5?E2cMfmW?EN} zf*`Q!7ca=aY~A-wI>W#B(m!jzlfnI*cjU!gjZUYp;QU|p+Kap%=kw&1>}#2*#v3|c z%a6YqzkZDC9b)Ld?F0%XhF{-2^^t~6F_Zlu2RnHabm=vh?iYFl?M5$*EBY2;WWf!Q zM%C_mmp%V-N>g>!5c4l$x#0uRO5j@|ZuN=l?R9?fCFpWqFkHMrwQBNJ+AFAz6an!^ zDTFN3df|_BxT?{O0l)`m(iz!(j2hQyR*1*EAnsb~gFMFLR~3wY@}L)L_7Ah5mp}2{ z?}=$2pzi7{sgB!BT||5%caNv54~Y`~gvmFI5fuu9i#cJ$oc#}yU8LBmFAQ&FT^)kw zGA9n)MVxu@z%L=5(2}aiUV3~4dAQ_rocz4R!VSwNgr3U+E-FuD%75Q^1@yNzin*=h z=&{FgC9R2b_zJ?N{EMTn?!t6G{J$qyJfGLR|L9vV`DhTR(zpx$y=~wt zvK8$#8YTa(EARhG}))+O&&@+X8`G=$&y$$A5h5 zF#&;E<0f-6U?|9FG!9lXNkf zpDB66YbyM6ikdv(1+g^-#NHao8?Jv~=7<*F-{G|}Oju=;!wu<=O{Q(QU@{j9-rqkH3BI$NvVPPPtigS;fk8hs9!`=4f z$;Ih3hl+|b>PuA_?@KQU*9?EM?Azt(->#H@ukp(_%8n||h=&)auFTc7Mn^(wcNUPz zK-r8J3d-#JtVh&>mx36R??>`-f!nIu)V+jBy*S4Pb+0CjckZ}PetoK5RkQo9f&`s$ zB<{j?^ZbKKl#;3@`@SCT5WK?JCg}2XHwux_zzC=(;^#J6*>QHMN=wL1ME!)>J@{?w z7kWF1w)9J)jr=l$*k~*-iK8k}Nu2;~qo>hudk=%AOa4}6S3>a{70ZOp?#T`LDr$r9 zq<3b$k=X=yiP)?vs1@lMwi6FpSNLb3O2v&)cs{CE-#}W{_mh%Zrjim~gnvi?J>u%j z+I7Ugw=?!TO;ZB_1E26Vk*XJchjNLs0Pc&n!g=#Pa!xk}x()*;w}b*RrB7sQES$hvY7txy z-qyQD8Dc_us0WDNf?c4h2OH3T2h1RCLLlf*@~vaKxKL>qT6nbOZ^%&^>}}lKUuL;@ zr&}#HkG1n6O-#?mnJUYd=k-)YHqIFSIV}qgb73>rsBb6Qx>!mTBHG!XgyK`qUXHTw245-DFvG#qd|JH!tnqz9OsH}^ zdt~Zy$u&fhgWcwgD*cv0_}R5YMo&-IA@qJ29A~Jy+*HBwPC_N<8zea6-SeN$=9eXW zR(*dX@scI*$dS{AUoXk?ZHJ2DHnN7ASH|{1MqkkN+6!>})0F8o?H9%%9WmrYkA0Rx z%#t4m{iloRU|oWYPjwInWc{h9t^3jY!iYS5XnqH;%R(bMqJVI&%>E2@*1fr9ZQDoj zoZewe1dPF3ZMMZGfxPq%E4j>_cR{6B4{FQ)gSzPlR}7s!@AEZO_h%W${6)QZGE+dU zKG!Vcxj&V4?3N|9AD{?Lqxvj=qvY4#Lvu(12&n2`J z%f_Z7=c)iHPjxxmDSuJyw1V@Z%~B(oe)B!k%BP#u@ANCpxf1<=i}D2Mq+bP3-4OLH z>m$>?O&?UhD)J-o)&OIO2aUUA9{e00Lg-}5cE~LUPZsh|9?iBGU`Enlvwjes&0E&G z<*ZC?;4I-=%|vm?URLf$W~WIX*b&{43Y5%_Q2p{#OG-nXs7SU!3-M|v;QUxi(O{l9 zCfA6SmzFhHsGxxn?OHg5hPca8tehteY19Ng{wi`pTu?{yxg>IViN*P5A%GcMd?*`6 zyqIwm`X?aVdq=9O_g4}ZD#*`W<673zI>W&xFHUKr`U?0{nIKqE#|Rm zg3Gg-f@Q;#Tf7OQ(t!{EPLif8)N+fFNscH$_QkOEMHSSPYc+d!&ANZNH6R@+-`k__ ze})?VrN}92TwRGK?_-%B%k?Y%NLPB}y5>hP6M6judYVTE|99+G%MTj`jgGh9bB+?` zWO7XdqSQ9X19n^=6ynEDLKdP=KmHi_>FM4ar{#7WkMKDM00tkSsaN{^S;@ZugH?J< zvU#!@-r`)cCw?6!nT1bA3te{PH~AM)JCJ;sw}u z>FLgy{8FaGHf$b{*i}>|Glvgsbc=&^41C z2a%LpGql7MtR%-k*V(W9GgegS-G(z(dr70;`O{jh7Y_|)T*=?C$F$!r4U;O#*^ZN_ z5gxn%MZG=l*^|O1iyiM=KQ0Z?Q2woF1Hf*87hi?$Y=z518|N7-KPCF190mVB&OWK` zhG}14OsOu3{{8~HvSNRe+sviK-eQ|oFKG7_nl#$VJuGCIbrUx8NtM%?*vc&taP>=7 zdAQ2|?2J6TVIe$pWzKGUj=C$;)Fr{GRW0~dV?EmKhPiqox1zTj4k2!l7d)q zHCDHAc%cIT-!l71IE~dQcCOw&G9%6$?Q54-qvNo(C5gwZS1EqSD<-J}x{j%f8kg)1 zoIWyXki0@%+%iQw?6PmXW9cm0G!Tm3TmL{Hh*kXJIs^K&~x!gs&CJD|W~J_O>kY~~AL1hFq&mH2h+R0c-zY%&9^lVElyl7W;q`Qn-@-p8u}W5==Hd77 zd8odU4zQ{u`yv3a+Vk)b0$43rlBEH6Rnpc=La^>!88ti^bpfBtPIFU>gU$f!hCOpy z2_|&?!UuaXavS?cfA0WgxwT}*{0np2>ecrza7epV-6+xIZ@o~j6k_e{0u?sb8_6?= zTkX3tY5@-27`cm7)&M2o8mD+QEY0#U$%0f?EkBCwy?z8< z@toQhZcNR{K);ofZy1jnA$93`LZ+Pw4)nQK9c}KnbJP78c-Qws?qy3fT$xgB>(mwY zC1e&enkW4OxCFVe*bCLVw-9&dA26 zg!rRWqklfS{EU6Q>`$?~WA9Ot;?e7RWQa9pU*_ZZwaxp(Qoaz&O7FcVj5QQNR3hskRfWlZ!#(9 z-(P|FQB&{n<|La^JBJ#f_k)QWW#5qpH(em_}?Cuk_S3CFSLqKL0{}>Eqk_>(m(}Mon+m2^D z?KE?mMLKLY+bf23~x`}^bXt@8)q zzoJC{_Pl6eZMO{@PJHp&5x~*OQOlt~9TI9!f z$fR38M?dCcp<`aZN8y!keW;gR=(^Y0xz5~uynQwOZL3>W@yks9$zWH>kh)uqDdNWO zDckJ3k*X$#ybeoZ9d*hw^6RzZZ2vY>9FMx2N`Te(%1yVGGvcvw}%Ez;FU+@%X z$o=C7xGyUH-^B+8+Fjq|$H&vQ;gK`ojyLTkYw~@_@MvGh`R}H5e=v(7-vrb+-8WSm zd=Lmmw(5#h;RJ}fBZZ*;It1f~7A(sirCGvH5gc(MHY(vEC7m{4KNys_+YzzcICmBx zq7P_*!8>hVw#WGG$0uUPHGe%7*nM- z+X!Vo+Ig{Hui{GFF##FH>eytj7pFPCj>NNNUbW#JZDyW>FR7ivxvQ~_p>GxIKjfYA z6L&dIb9+kzVZF4bNQg&!nZiA0{fJE#O)V9~o60V0{fp4DMLgzySyv{*RLzq4V-B zul-9_%X^dFIULKN$xihX=f0Algv2T8;rGj8PRSQKQ3U3cv*)fq`aCeSjqZHnLID7hA)t;kNwPlFs|+ zNia*8MfM#}9N_6xWEy{rETG^sNQmTYKu}lsiV)^G$5&DdDo}|!V+B!jhbpUrfu|7@ z9{iAUUn;8E3=m-u;?D{z;pW&=ICpggCiP5Okl>8z$apGSn7_!ciVma zm!0(`5F!lljK2I3n1}M-_Yw`#>~P#B_up+HQ(;KJG86fj@G$Q2bIo_!cm`ko5L3*j zO1fVr5*#*uJL!YPNIkbYt46nU!R|6;_2u7n0KkmWatE#GjbasBGa1B=*Un2~OEL=F ztMY}|N9pXaxnUJR$GfqMHA~o;JK5@?u|%{L_v1BMP|#3biRlk7bCn3EdD`18iASRl z38Y3+T7Jni*I!l<_!e9~(}R%zqloJ~1pCc?p6apC85hP~ivUAle1RQKS0-h6lSmDI z>uWLw@ii*fn(RM5U;h+W*{W6ojDZvfHZUWe6Mz84cZzgO_h^U7AVMu<9|Igc7 z3`;({{x?jbNu^<990?m~!H@@5Rw)c*BtDx|lR}pdP0trx8tNl9-m#(Sez{25C~-_C z5*nm<&wLItKfH+%E8gy0<3tI}zDXux0S8|+%atBe*OU_ft7TI$-v+#V26louc(6$0 zMhfibi=M;+LxpjiLMi@i?5DC! zxvqvYg65jX@XoXt$hLY25WK+9%Re7ME4H4F7KdOfyev5BXQ&v20rMn=I6zEf@Rch< zE;KQgT~KvcAZ`HJ!xuU*sZ@kZA@YGe~y_)iPE@p&d zK~;!C{8Z-G%r7JKwZxfJbPOlDBV2S`l!Zml{nQJg2&UuL5n`voGnhynnT4GS)ER=HixQ1E+dgEt^6r?UU@G!A5r~9wG)E-t2@E(ty|!ImJ^t>H9o|yU z39smDws&O5oge@5%2PtNxg(A%?&!=4N@~6Gkb$0CQuAD%TQG=Z;3XeyoY>w!-D)_I z2pr}D&Nwyw>xocz(ZWMoogQ0=1Om<>-vn85(kwtFcjjmf=K^eWYj+Di*e3+*mIBUL zYHP1Ex^%$O89y2HP|GAaX#|$FIKv1|JqB*(-6*|sKoIHPdsO3Uh(0!7cnl4FxoRfO zi%zw?7Zq9w)D-Vfdb&{+i~G?M9K=~+42aG|t5YRd7m1}@&#AVjJcc{8>Z| z>jWf{r-=|#Ya^2-Lt$yDSro|nw+T_)vK$fL?zz5z5X3!|`X zavdrZiH?&CTsXd2ygM}1u=qpw&joQaU2$HDrU;{7n3SRz40Doyicp4Wjfd5Kj;W2^ zpF*gj=K1;5LngV{a^KX9mfnr2M!tYGXx)Ug1iykX=5CsR)eBk|;Av+oelR7f^}JFA zeB(Uy$rqe+G_){|ZpMSia1(2BEwm%51Y}aqr3%vIDs#!2YGNY)-*$Yh#lNqF+sf{2 zV7+Gpf6F(KgDqK{?Z1Y&NqiT)BDL}l_Jc>Ewh|cc#e}_52%~qGvbG4U$(qe%^f|@Iw#YOoLW95bR5*Ac(F|5llu9n z(OzeaU_z&4h#twzx2$?itZYO0&fFBY?rFKfzKu}aWE%rdl?b<_+?IH%*|2KTvVz~9RU4U% zqRiDw3j)=O3IZZFmnl zKt7{su-VLb8YiC$TV@+GwYSuMaccF6k%mx}n=}M$Su|fB71a|!9fRk}f*Gg?*$Jx> z35eEca*R*{cK`*W#mFs~DXyOxVg!XU?)TQ2rk`bWh3J|Z3&um;^(XmKC7G3ymYrRZ zbCk7mI)$mGSm~BmRYGYzl!Gv)^s{6q)Asf#{J%%6t(pQM0ja`YPtz)9JVU0{#{_mA za&QB~t&5rU3E4-6C_?_Y)0O5UpB+X?!b);48P&HhTC3jU!hA{vb3F;Q?x0n?ev)6s z;dB_O3N%>gWodBFxM9Jx2R=%a%jk8p%hJ-Ap{p6>jg6stW?pJ)QkN&P1rb26&Av0BCuZLPXS`zWne z`zXXYd!*(Wju}5B4;8nZCmdM30`$)@ip`?Vdhun$mwCYq?Z!J7$-gi%QZ6c?KUJNk zS}zI<#bkE9MgdGnJxPwnnh>$=5k~m9t67b;jO`o^Q}##>C^bf1r3@}5{q&r5jP=-w zkM+hHAe&l-{liswd|qo4@4xkzb4Z@jqIHZ&4)B@R`klyBem}Sh2RX*}u06n1#NqX~ z=Q2o;i_mrD_Ty<2qY%l@1GtT zji;9y5rMir@#Ah_3zjEU(YT}z%;I5c&8TEaNsYFD&H(hI# zN$X(NQ#modJw$&W=cUBzl}0f)ZTcffxV*DwUk4MmyN|~{25B(UO<!$YEFnb%=b7`5YWv zKSE402LGxfngxPX7R?&9gD90I#%8W}=bWU%QW`9lcgMWPn!55*MZe_m2FPsyCxFe6 z;NUKpv}eXM#h4o1xx;0wjucAaFY00N4qtU12b5}6kFqgajqBR@uLMs@6v*#tGNYpR zc*JUZjO=G9tWh$hw7y0@m|GZ2R_=#dzQ6IXceOTB@hP(`R@{bj3W_Qw(V(wpO*3R9 z6FyIh&0VlCb-knY6tq#2*RETu+|h}CvhDQAtEH_~ZTBh1!HRS*~CtC}Ow{PbCOrCjsA zPHB*VFwUUM*FiRm`>JVRG-@L zha<!U^2M{>U^R&ro}vmI1Cb*7#{YLEtWp9vY*P!91#&%bCt> zjr)F3lg@)uGhlGcMDGksXL^LTg%naOz<)e^eo%v`UVEqoJ-G;A{)XjB9Nl&c%p6!d zs7cn2Y0IsMY~zYiWD*QTjkwXql2uG@+e^2!@)$MXm?WXIA0hLU$FRz=*ZbLFzOEo^ zfEp56JYguu(ZPCzq{(x*Wm(%E>0sCiT+!R|a+er4{E9wmc#M(UF(b#|en>)pd_dmD z$A}jjm@?uJ83K&p!B&ce;Ynx4(5nb!bl+4}Ir7~?>hWl3kArrss~lxk?oYp%)<(|EwsWk&avWub zke98}xsOm(q)r&RR_%GU;I=VEX*X(bRfbIHxi)BQ)E+AtD$aa*-*rA3E!C0JZ8~GP zEuV+*b^!V9!(Oq( zt)Zj-=WbwvmO=gxbt^N}rYFv&04ojbPWs60q&RNr+S3ohUnV_f{R<|KvvNT`yN zRpTVX zD6z_`KE{4E4aSTpV?fj^#}Mk`-_EnU>lCeQ|cy&#%FwKs~xT1xDk| zyk@vWo}*D4BW9ll)G~A1nu9H|Ea1n!ED)Yv?WruG$9znH$9c#kv60TadP6tm2pTr(v}?WJ5Vo zw0uj^=r<`(EpdxlAhd3EjUpnD5aNd|=VC31#@7fqjc-Q?8t7YUj$wAm!z&ByFu9#! zbon^nH^)WY?eJ_wT74BbFvZPb@pg+MJ7vqvhBB6_#81|`pOW33VCsDJrK{3C6gPkd z>cWb^7ZF-_Ls?V`3wp!$J{G*#b{BTpP6U0DsR73G6d%9$a9PuV=GmtCUN=bJ9ZBD` zB|EjTJKWe}bx@7fl5!{xaewN=)$z?^`@o9$Ji%jW^zYzMBrM~V^@rN4|ECi@r^LlZ5m=6;uM7sFpgqG zYsAPAl=W-6>38`s!k0JzUUv@g-8y-7XjAjJ@pzlDp{{o~yTff5H7h_76Tq(SdOdCDn3Q7H_ zqekFeAA7*X2lOc=;jZ)nyr{=YW+Bo9mwx8;OZb?E<)FeruX=(8(NND0m75v(AsM^i z?nM!hM#QD^3Rn+C99yGt_GIQj6im;}Cdaz`<_%R$IKNa);11C>>>=xgZfT|`Hoe&k zV+;rJfUCT&)5fPXdpT%8(+1(!oP~k2W)850;F5N|V;q;>1~$rhhwoFQ2CjpPQcTn9 z!AzlrFO7ncOrd^*+oQ}Y!<5Y>n)NEX8<84OW|i>`cd^{hrd$u&JFjFB0_owSNqQxV z4?m23_4nlj>#=T*SEb7)Tad=D0zP^BSo}Ri1RYa;;3A}S zlj9^7nRu<&@@j!wG3Rd~bDYuW0+Cl3}t+Ilk`}s{qJJhQ;bzYTAKXtWxGj>&s$Y z5VKg>g)_TvjNz8W$~g>?MG3=sQ^KpwDr?o;K4!E^nGu5PbWUtcqxFm*LmCLoboHi4 zYgLhkua!07PistB1cC;)Z3vz$O1@xyt>Y_IC04380zt$wMFoyd6MpWOjUi>YnK#Wr zAdOjkRt;SKYZ;1v$LBvyH3M)-)?u*1~_AH)e(PST3$qr@?MO7 z3tQk)LQgr5AR%ng8CM`>e4C4MdG~vfT!0N01at2yf>d^m4x*NIkGgU#kIzc9MdmJI zh{#F8IcKV?wQ$xV(%=Q&)Uy_qdJ$*0%EYWU)7WY>CN`jq1=qqS?aTnxNqfJQBzOWa z7F&3AptwYYta6_%4B{#HwFh%!I2)tbHJ2R;pxy4;AR9q2Y59A(j((u$uF-t625>XV z&g+IcI}u8Rz;`tlFb-&k3^9|5*!KKffQ-gyO249{xdD>G9ich;OWw;t8T*7_gF1(Z ztO?r!T3OdPbet}&ZW%LhD`6B-$JJTU{qMsIQFIOQecYUlW3gNeL{nJWpPjr=w;HYM z{a!74upp$&c*)uVW}O{QsQbkPManGH%IT()c@Ust#sG`995$; zvZ9Kg`)xcImtuq ziA$Ce+`H2&-KholrpnIHf_ux_gK5FYTI0&D1y9J(f;(5pZO5|<2T$|iz~?R_|&7*JU3S_(zf7qar(&*SLf3rUn!$6mo#4n$-Q zYX%^O`mUZ)YPeEXodHYe+8|G!!7tQ8(g`u+g_cPc_`Yg1&^@I~kRvp^@Mh3r(7k5| zwubQTO=IF`atLs;(1;#%(Y4L8VX23$2EM$pNg?3erTVVnAxTXIZq{&iGKSro$gMi$ zEC=;5FNlg9mQ~@wCq@{e>+#3UpDqKR@7rY!GYRmMO;ws&)k&%>tttow;;Dr|?P80l zn`3I2l=J)MxFf3Ed)+D^I!LeK8ENZ+@&=m%8u(!nrFVXW;)f!S599VSJiFRLAvmLq zQDy=TqmZIwRHH~eE(o)*n?8OEBAm^y%R_EoIv%j(bh}246yJ^g^V^U_hd4z{&I7e0 zz$kM2+&o64^W#y3wn;in7Cw;mcut7ZE!8^>wONB=Q;kDJb?DNn=8J=So20AkRjE={ zNEnxWkZ~~kl>5!_k!hWBH%FL+5hYS?Y!#AIJD_=^;$T+@QI!;>bF)wjTjY23rBVd1 zGQwaDa|1G3Bs1LF8l$RQOY>|o(n;+VPLezYcZ*4vk<%>O!d15#HQa9TkmsldJjVdt zrfn8;XR=c1aql!D)|EOH>zufuNJUbN)$p66KtqSYNDM6YwiF6)3|ySjqU*ZlxxbI7 zrF1AqRU|eDzp-bZzD^55%H;K`4=Fmzpm#%gF@`s&9l0uw=b<)baHB>Gia>sXgK{=a zFsh~(kPxtr06YewBaM{KlKgCzCwH0<&yTPj%#;yP_r?x`1s!A?V(@W8W>a^}M0WEk zMs+*bLIo=JJzJm7_Py(f)tm1_8{i;D^IY(YR%R`s*P-r3H@0s;TG4Yai&B3~&?HNy zOu_Uh%Ks1%ZIYYu_qFe#PTY*G%{iZS{yy#-pqz*gF-Ye2`+ljkP1Aqk+79J zO=Y$i5E{`^R=)=Dz_d3=6=6)-DTN5tsnGOHRshP6=AUMky5reU28d+G$`f7H<6;2+ z&abozvehUBFdZGf71?wz!3}RqDY==#0e4tgDS{kOaHk=%dB|nKQQs@H_u*&fh%f zg%#HAcQ=$PZc{N`%=4o&JL=tTqWK}*z_4bFIqraMN-}311o_tnkkiqV?raHa{OV5U zca5V!63H=WFhhW=F4e?DFpi{&;F}*ftLl=YVDh?;WtTfO9fOVqQq3YCHOzyA;4QC+ zAJN<)j&s(A@6@rjLYAs zTy>S%!kZdtHT2RD!DfmyCX2-YS{;t=qKDAg5%V^|@^;!dl}O&HbKtpgLQm zmr1*w;NdDr%TDk?-6Liu_>e3F!^{LPqABKOCitNF|A(2tvfs=E^uVh{GZTC$^OFO9 z;-lv6vJx=mSeBK56^$6b&YXRD7FfMcqk=!b@@oGr@#VwO zh5(-HvJgB{|D@eQ@ZK&U%tG+KC^s+*VU>r4Fd)N1@C@f)7J}DkqGcg~c>FRDKx}bS z|2=av>1Nn4c@NGr^j;^ZCMDjJS~I;87+d{Mzl4?L3_t6dR+QFW=UpZ`oE9S&i=3vJVVg8 z8gLobt%soZYTFngP4Ak1LOymzEriqF89y#|13E1PkC3?Gi~!#&=G`=<*602{Vr^B$ z^w7mdP$6@JyAAow;uP%&;c%ab>?^$82VbZ!>xp#}mvRC{3<2)+#tZn$h= zI$elsNbFrFWsRPefq*`vp9TU(>~S{`d{f`*Fc7@?|II*H#bF>!h#3f2lzLUwK){?C zbukSD-^|Zr>OD|hR*W4t<6s|n(Hu4d0u)v@1H%{n)M?oVK36qL%s%kU>$dEJS)TU6 zf~b9fa;wWe0L2ZKto8v$4a+6{jw2OdDsXGQuJr_ zUsgL@&B7{%jevywy)GL8Q*@iER84W1suUL4*YBmN;%Qa_u~c>|VdBxOgoS4{6HYr} zyA#xTIP8Q8FgpR|Hok@lMu&B`6VPq;%TB;F>YzhTw3;(%7z%ho$+cxD_|0&L<18FJ zSin_HdyS^iB4#KM`(ZZ}zyn-fh5}gExG1JFG0MYGSO6LdY#)}TfDv5WEd|WMrDZ8# zjyW$ofb4aZZQW(FC4iYQY>lp%8$(!wsDUMBE3Dn3t#I5tlTE$7k7(b=wgOX!?O%gz z5Z=eJT-JAXfjKHHHi`H`?liw*yaSS{^z}7JK<>3@x)Wo(1M|D7Fu{>z&Wsh(9hi7^ z{}?3T%k_}<8pUo@iYDEN%_5O3#5*vRm)*JWgZ)G&ibi+`d@5h}FPMX77JC~Z-T@!m z`}GAg%WeP8E-;6LUHCa>wr_fhHN<->TRiQASco@!7`w)-cB#CZH<%ILfjN{d0FPUd z>~2j%yyqfkh&K@tOgIE);>>&G#YF9rF3i%Fw;I6$mY7^U*k{)x#GAWc?drU~O=7VS z?=v}(voQH*IFOh@EXZ3aWPId?q$$DTRYs6EXBq66SJr68e4G)0pLUKi3MM<~dyNtJ z#~^QFs%}BvM5f-aR7C{tO3eJKZI$=^91sS1&mJtudk!&!yyqk|$Xn;QuH?Cjv3U_f5mc)d(PlN824Go?M_@va zJ;oz2p~i~w2zZvLt{4w3?=c?Si)h#KjPcOjSuq~mowQ;+xEEoM@!)Rw730Bq_H~EB zmDN=?T$Hfa=!OeQ6D=^#DEL)Jr24U<3%YFrUu*YD^ zC8In-bmlnFD35@LCY;?~H;!qyJ0r|PcYVcqhcII$8Rnr>__hK)xTS3cdJt7<1$qbM zKN)v;Y8_*fM+yh#dv3ve1X1M*oT2l`{=OVyJJ~U+|8gdbnUE1&9gxo?gj>jni4Jji z4mGShAh}0uH-N1PB&ENFtbsK|&zhYs2f7o-*`nl~I-2Z4wH^yk30 zNw{UqRvpG$CGZV;ziOn+tOp1g^ZKZQNBRJS3OP zVnGfBC6=H`u9Lklg>!_=pLAv8!3=oMMHJ%HxTJZAc*m%5v!02IoaL~<$UrPI6OOXd zBa*Jn8rU+dn(@I&UjRaeZaC6xuR9;lVZ^xC7k}_N2t(zaKKX)|E--1QFWU@=v9iw# zb5o8dh6uh11=m2LeBpQ{^AjPQj=&f1Vr8WN4iHoz`33W>@HGlcC=E2?5g+L6NCm8S zJz8eYda%ey;%bpOLh$_=zpg-ra^1;mCS?SDUP5`;8{T&9zME*m_(k}#HX83PS^w_%T%($ zw++lT&(LoalcmTPWYZhc!yExykeO+4o5hJ5G_z06%vsH(F?*$9(^!gtrf-D} ztO$`hq{T-b(;k-1rJ_}oNO ziLIHbsnbW5>Gdr$e|w?G$H2%05s`z=%9{M4=dA`545u&9Ag@J&ii*THF6m7jGTL*F z;AVKbrt{8%31G08QEcOV5Cgy;1XZEa4U-ZzjX1hRE_EiH$pNfD~JTo#t*iZmy9(P;|V{H%tUGqjDpCA|kp4ggYATw(Y zjsaxypA#X?23}O9ZZ-3A@L><9 z8OxEmgItMrhHYk^MNPp{$RtJu-F>xIEyG4*f69w8xDpsV$P37ZF9-?(ghUK)XA0HS zAGnJ^BCNnn{$EPR;8q3!**a>Pw9D}IJo?3MBg67rHeLwyTVj1^-4K9?Uk{!sF?_3& zEU;3S(t%8x9^X*|xZ*JkeANfoY~bY4skI4gcc%%vkeV~|QP!x;A89I1%hGS-;e+gX zlXVkC58BHfI9-TnaO3qE*$HNW>a+ZtsY{>(tQyJQJSohR zjk3!o$oNzs-f{>fPf>@J;!9`>HY8)1WjG_M;ewF0CD50Bx`oWGovkjADFDwzGhbUs z*iBcMe^0YufEBA(fL)bhtkyB>M;>|=d`3)^f#cm~8R;H8lcUcXd{9c|PL@71Qe0PM z=K91-&XwJN zP?dR(gMKuAfWU~_o+3Z?qCT>}rst2pu48z64mg4T94<}Jr<^k=EXZs$LJhyI_3>&Y zJ}vjwaO)^1$H{*``{C;X`TRjGq%QJzgS_~|*9CId@1t4>9DQ2pROJS6>1Lbi3*Emo ztM7&!J9Hw z+7GYwYmpuGz(g*Pj|*%Y_QfCWMtZ$g;KlFFATR!Kzs_TwyOF-`YatN0op_jN{U_OF zm5_|RtxE3x=dVkzHWF`j5499>S8F>Vcp>9FpF>xplDq%;(MTpHw_4weSNA}wTPIiH z{aWu^t*hvIMVy~zWj|kMb^PHQq5e&+lQcd}L4Uo@-~fL~6}WBns;GW8s|N!6n^9CI z?v=ikoDWXbv8&6edTk_=fLpCsB=Tt{$4;(t`L*7+T4%ZSnxsC>%6`7i>iEMqlK6S8 zlUzH`Vf=iV!|8|HH9wQftKAQz_tUvOlHuQtq*8RR^{uSEr{_~wXL^2dB$I7htyg6D zX(q=`u9Ez<-k;Yp##K8X!*;67_4KFhD(mRES#?v%KpTxbp2mgay)@3f9doVnd?tU! zRyvOHz-GCr^k`FlY!7`i0cC2l(rv3loy&}VY!Th`{Y@q1OOGb-1Ec7&+C$IJjikpj zG9&2ev|cro_E8?%FgKN+QtqF%m5$>)FllZoJ=m$An@itJKzZ8Q&bwBJI+q#!*kHQp z`_$z%rsB;n}Ct2|g{HX|eUgyAEUy%gg zbN!2;dDiiS7$EV_D)%jMs+%V?v8(l1pe|W%e#m-5td;@<)ls%|(WVa8D z9IN!m$T|M}z{$netPgIM0XZo2#~Y@vn;WLp*S4~YWI5Eh0bJzTgH=5n<3@U2CUzb6 zO`D(4RxA61Q>aM4&qx8oUxej}Vd|Y7ej7t0Y zI;-OkcjLWY>(=Rbnuyj}TY6_5Z^InAJXoiDrGo?U&V6~o$FY;Ef&5zUTdkvO@bf{t zv;XllEBpC6tK$!M}@>F!G6BZ;rPS-nvZ>dK4^DS>*O>$&uaX9nbqlsuS-v# z4{9A+X*db(TTqgwd%=`pdRXVVKmE|p#hw1jD4AK7_euu2!{F76^5PHQ?94Z{PCIj2-#73d z?#b5b)jhc%_xZ2ScVnw`w;OEu$l>)vq-+Mm-t9A#-1?;$K9~Eu_hMaMJX^QFP77rO z@Erj+{ePVSI~856(3jvhsCc!`aUYJDeh&T#{9pg-Tt;qb%PrKisy)T+#iyw^HHK5yF1I#`X=9{qPNWeN*d* zwfmiZNK8+9x)RgVAzqu>-LQ(%M>6ZjJNSeLJ*vd1Kb*i%H}R(LZz_F{r%SU@T_;& z?fc5Mo=okBlYOF1J)pB=SC5YAHzOUdhBme4Za$B!#vlFsje>RI2FF^jTsS?Ce7Nu8 z#F~!xYOmiyo#Mr>QP2ORd#FQ)kAu`NH&M@~_Hn+{y1iGsyY|{a`{d7^>CNO1I=i32 z5%6*Dc$>jX@SB;vT4zkP);antCs*IQ=;6|1u&;I$cCeGx|t-pt@B{AN#X>pZxC zy>-moD!f1cqVT5g=atTZVHdB@Q~1q|_KS61x}z8M!v%cfY0@9>z2=;^`?&$xZVmC_ zde&rqrZZe1tCc2|{EIsO_)Gid$FHV4G4*>|$`qct^+kK<4dVsSn5rsoUe*i1IyEHy zD+c=bSC2D#`T7UCT}^g^HSuXXxLqc$Jw08rGQQ++4fA>F$M)i{>ipxc?R&OEE`q+h z{0%}B@|$k6Ppq~4oO3gmw5E)H{QJlEKifR)XF9y=)YfpWeCd1x3<_*XQKsrkV-|6w z%5{91#+TCc!JH;5jfCXHOsq&>pA#X-k(S?Z#05$Sa$qqZs2qAwjn7SA2gU;#OyK2_ z9|2F1Fky{CkQ$`EAs1HF(KDYA>Bzd%z*9Yv^o0W;FvaoK2Dz}1;}eOO3TG3Mu67?t zQvkm4;Sr|B^)c#8*CM=<(?&8h640(iF@@>ACS(aGnp#w7E3hm^=M0+Q!PLXZa!d6-*&Zyt+iOn8Mn3)=%QIPm5S;!81*MBdCfu&yv>Z%tJd8MSw0nUuBs}rpMDSZBzC< zUO$L^2jB^hy-Dy)P`m*W-&5Fz358E7Z&N|iTv>I^NXf~5kpmY2$8$w?UMn)jhp?UL ztqR`F2>YUu+7Q=BYb0jZDf?`U!>kD>VSssGW2$`eVFPr&kh7ZPz*prrKxWSAZ5U*A zX$Smg;i=n-3sQpBZ8-%AbmP8aW6ecy-ik8o%1rI06lPTXoGiZJA*rZ!R17S#6ZXL8 z8g@wFvnGpteU%l+0o&_TJ^-^0hL;lqgs;Qnn`butj5iuQ`)SCsUYS}dQR(w7@eN|+ z9z&iZKypN;l!V;i%Gw5`Ab+^lDSUrpv4B~}Y0|3IGjd*f9UF*xL(0ya6cTW*m}%4o za?Jn9Y~swTDa-6kSwA_QpaLu2xZzo{YHpjq#qHnX_HS|fx48XV-2N?Y{}#7@skr_4 zRq*_l4ASwySmARWGSaYvtJ&D+T3^CP8#6Z!$mfK3JY?^&)Y0k+S*_H@FL+D=?<+V@ z_ZN)x!Y3-;Yjb(b;#BMFSHY{|c(~3WpBp65uK(OxT_K~D8u|s9?gg72k5nY~KOu0| zvVXj4AcyDU6oRE`e#33F37LK4Wt8+BQknL3AAVN3K-Pp#gWo~^ zICuTE0BdkQQ*i~%kuKA_0Aw6I*5&tc24Hp@;<>a&IJUk4$OuT&-w#7f$m~^kkDQ`A z$QtX^&mBZYLl#$fXxC^HGW*VWUhN(-`yQ><_@|yZ8Xo6NhtVcv_AN&q>fIGE#~N+c zSf_qDmMJIOSQ9e39_q>+Wb`yttZlSY&v%eNEFYNk+q?l4a-e1F~j0blNNAFz^5DyzS#(#M?gpa^Cjw zFXe3?|5D!e@h{|UAJY_DqMIYlRVo2OW z@Ini;+K5Lz}Uh_B0@$8)S4e8(jdS4PH|@4Tpyjgd6FfpjVHp zPUG$AzA%Lxm#=S6?zI&1`FdXwZzGo3^7cE&^LlPSGJs7tNATY18=7Ybki0fIFbM8z zgB0OI2U5KNw9V(GmpjNlmS-s9PEZQD9c)b601=OQw{`~@oty`{gZ#11@gT2xmL{nz z$ocG_%cF&mEng;SJK4^&HOcl==MM76nYh2M)c(iiNZcI~5d3NDXAIGKpYUJ=UtYl* zk0bW!Kh?&4Y&>sL_T-duFd8T%X_1$j?4^iIU(j*m{toT@W{mYP4y{+1|e8Hg?Z#Uo)fQlxD(Hq z;guu28Zw+c5QV;XJc}}GeqGuw|DNCvAv&M4(FL&DD1-7HFNe$tkHC-(skn{mc-OjY z%Q`jtT!7(CT5Yb7(a2EI@vK~%$`g9WEBCvqIw4aVnys#o+3F90MLyoT_l;MO)1hxX zBAdU1Xsc~B>-h>fjDPG2|8jxvR8QZu5Ha7Lw@dxysc{AHZx z<1geiAAcdI`IuL88{H1bqSD%Mk9Y^!>GnU6XMOxfa;QyhGvZm!mqASjWoc8z45RA{ z5HH6@ZzU1(j2rBKpB@~%u1WkxqOa6$7kZtjPticN-2935QvP z(-a2ISN*YbYZ3#pdKs;*kiG9gC9CfNS?x}B4phC`4Z2=)8j#h~Xmy3`ecKV*x;|IB z>Bt&g0J9C)hi=t~3K~8PIA8E~H2LM|dPMZCmE{g znD?Q= z!7(U*DGmGQ`{P&Z^uez-?b}2j!xmrK(}b*mKeL1vs~M1`E6sq!3uJ3$#=#y+XppHZ zo#$f?jN=5BNxv&u=K;SK8Q1KR<@e z0d1D^K*NZ3JSwQecHhx=Z1=fARw(Ldb%h)i)Zx(>TF>x;%y3jIZvm^;;tE-s(Xp4W zxxK4bE$@9?$2rdAk4Z|iS6kBxowYS?!L>$w7s#R4t(R#6uTEJ!^l%;JFpuTOU45Eu zJ3F-_u=Qbkc!BJ_?!A0X|H#&>h8u5vT*o=i`CRL^ zCvA0w?0t_Dw6SqJha2BB$m(gdxowCmP$PW@DASFWo+YR1uI zX=owG8XK#-?_%c`cS`<|2i>UYN9N(~f4kRq&%EJIVLqSnTV?ljSZ}rF^RXNFI#xQJ zpZlIp2jOX@rGHB+@3KaVRZ zh&~wJYLxw|ea1J4>g9#{Yj`W!vqqPr0GBPMe~SL6ad z0}4J6(vR)nrpK!zE^3&F$Ffk)(rXtD8rYx3-}of7@(Z|G!3($28WGNX>G!==ju}Kf zM+?!)@l_p$$oQ((Q=_h;5QAY#xuHervQW{G(IT)1a_Y=@kAQuesAMOi39$_aM*ECU&d7iL?HgpUdfB_j}y zi|NKOs#2PMZdh=BDu%#Ehv-spLb{P-3T(>M@QMyv#EJu2vLF%hTqw)hip<(=ML9Gz zj{2F~Q?q_&EyB9T8_0I(w9yqH=b&jI5LTM-5p3ixZjh~!qWB8g$JSOi5PXW;;sGK@ zfg~nn5JX|58H+fL!W+9GwQ}DC5CSVyY;3_7&N%OhTpDE|cWuydrwUrA2)zrLnjFfx z6y1273M-?9?BE8Gas(4Xxipp!)b*Pr7o9^`0>1eNBl-eFNn5t7>bL1p4j8^Mm9<3# z;zeg22^dE>IuN50NK=~YI0&Sv0Dc(oT`_9NfgodHCV^Q-3w#X|w;IByGilIupi5>0 z&Xi@drDHU}=jTdf1t%~7vr?2}Radb}eLdj@kbx_{@n`c+=2sHS4Og(>0NDnR8I(kZ zoA60JW=IA+ST>|mIWTp610J>-(iuKAmL4+FCqyQ&;uuw#dUW_&l(Xo#2?XwOkn}!% z7AuG&Y6FAdz9)map+;VBFd%h_2zEX+=-i1X@qO~oJ^FN^pL zH{U=C^(;Nj!da0j0I15qYz*29k^z9|5PDG9hlpAd9X>HuWhH{2$4GuK={$QY1zgWlt= zhyuMnFGUo|CtO>4rtlo^lAn8b3xjud)L(`@k00I&ox&fA%+tLk?fG5XYH^9nMTe?9KmdEWd(a#Mn zyK<0_K_=}rj08+MNZ|B!R}Mflp)chi=_eagIXICjm4hVqu-|n9RKil0ZjekTAG!g$ zr7~d30f+Uwa)7DDyp)3^LZ@t^AB*+jKqtug;kO!suAG;00EAMGP2~V6?|CT)SO~Q3 zp&T3+rn*6DG^m!{n2--V~7O?9&y zQw?fpn%#(RR8m}aV}jnfn~g~hWUtF?M7b=paTKT7XnN66O&%!PP+ZX*=WLZ?JD^k%%nyotzv9mG_q^jf6BSa*p8WdMCb0PFgB#n~6 z7nuvUt#jp#(H2aL#d7lI_=$d&&C%oQULy|NHT4Nn#&C?J4!2B6$4PXyXgVnYYXow~ zWU&e};K4zNOq%O>k42G5b9EFmvvB|ZH6a@&%M9;0K{nbw(5ca`@PK|KUW05sHJry= z2z02KK91u9`@kwrJ7!pzTusb+J#AK|;g7JFy#}oij6#%k#QA4xvTD|d#e-eQv_hm9 zl)PXJMs@bEIpnHZs3JWCo0w#!x!|(il_KgtPPbZyGE>Ywl*vS48+)q(Vx&6MwlWN* z*`gkiEc4Fs4uT`v4*q)L~(C@;-(8m(l-6-^~%aPvMHt}2(pOQwL#go)*r z>%cBp1d`z4Yulii!%^-$N1cH^qijB;P_`P4>MP0|QUsODnnX@L06~Nswm9MLg`OIG zwajG|61kOy_jG4&DurygIg+25=g|JkPLl(&C=hmi%eRn8lTi*RNyKO};+x-%;^2|U zey2%zEo#_nl)S7Md~f7VaREC?~*(l51^?DCvaSX%Y^g5*AGoS7p&;j9ICC(j>4O z`l3nTziku;4^Y@i63(=ow+ewu^&rU@==#`5GE%@Tl0?Qzo)aU8cj{6alMexL|BUbr^=c-YgmO=L*XNZ>0A)*}s z5iOd%5=Ju-kNuH3#u!#v6&Ujx5da-3T7|@NETe-!aay7+8&2v0po6Bvu7nm+oL5|< zOVFdoVSr`q6|=33&4K0&osW*Zq8c2HoNl{WXPJngt*~m?_J_#4&PdkK*k7+Cyjj)Rn}9SNZ6e`Hbrxo9~WibdbpM6 zp_L7GjD3=hT8tz3An9$*X3D@3<#(H80H&EhcUQZGtVTW(^~;hujYLB#1+PMEjSg>5 zIre0bHJa=<_TvV!T7gR1Vf^D*%EV@ts#7lK73#cFyYk5wIm!RNzKyi}J{q3f-k@J1 zG-Rc?c%kOUYn5;X)YzlGi#0O);C7*CUZ?T#<%bPz6>%X4+>RGm46vSZVVFjTdtkP? zLT00D6?(j*V=6 z|CF9S{&^j_8zNcnp6zXqbw2N?=e34cvUeu702Vem&c#pBEPy6ui;E0W!|ix79vgt~F+cJIH(x3JN*0`LU_3;-!k? zM~ZPGtY-02!)WC%^rFJj!eU4DB@>_Xs!dk%*wz6lGTpQJwqFr!?&=HH0q_lA875f|iNw z=0=O8*FK!bp$1Yx1_qHu#bv_Jh@Y@^b?z_-*6YFx=^NomvxtZWr91_|KZ=`O?gb7I zqNa!zBi$qhwqm+5S_jul`0hcf#g1FFp@-jK&V&Kmt{DH-YbCy zOVL>bqLz*a9_yqkRPqmx_j~?ljvmu3Z z!jP>xM&lTEz_=_NgY5)1W;NStFj@rVsAXKCGQQe|KrB_@n7xoDBhFDmh6)mS)+q_| z=tk6VO39o`Rs94|=q) zeMqgz!-<1~GJ@oE-B@(M5l-46_$RWCySk3qQnA78XI*#)?x@V*KcA$9_6&pEyurYy4yRUIGOGhs zVaY5xxuBaRvbtwz?G#z~f{PuP%)+bFSk01I6EbC17ZbOIC9^OHSn!Zpm;}aHG7A%T zdC9CEl$=dubvWz#eqaVRmdrZg$I=+UL%L8@5opWL!-PI$Ml;8&X3X7C3;yg6s5Quj z+Qx5}7HZ{`L-3&e94JBQwo~;Z1e5@UAVVyB6{Sc> zS6PmfVNeJdp(T(^+JHt-se>>iZV3F~kmk5-DuF=a4heWwE~`$F9nN-O031|;nyp30 zl_h2coiMn_XXh|)?8_=w`h3yCAUI7r249i{YXT$U7`2ggd2eIrz63<@a263)P2h!| z90(zFWtO?}x76I9WA&kK;8T2j?K8}Y`JJ-Q?7F4Ss$MLG52K`16EgUaK zsaMb`<($fB*=wiPlS6{ddI!N3X|rujN^~0}a1)S;u^S{Kz6r!!Jh!@$Ekb;7WASNU zm}R1@sQ8#QI+2cm#l&q1@2bzZrt6P-!ZeIUioAA#0fHyYW*GyI1_q%Tj%Udrj_@id zS-K2Fv_by#vF-Q)X;Gt6RxwUr<3@{G-l=!g0O3zjAYl4D_^D;oO?PS`;N3uC2~r|Z z6hMBT&e(4~c!_b5{32#MJ7Zv&TB8s@AM<==R?C`>tuccD%6km!g|CsJk$3oeOU| zDTI+%mEGJGmHm2eB*m_#MqxHU*6%}Y&qQf;dg6p>`M#CGa&&|R>1DJ~g(KpWu&n0? z{F!6m){~k)*;c8l_j^7%E9FdrKuB4zMeqv_e)-BSaZlGKO%k)N9cVO1YPhS0F;$^b z+D2gHnR94S$AGe%d8ixp0mOTek2FqFi!rVG3c&3uCY|`@DO6_HvkrhA!kf0X2z?fk zQC@{p;&s#z5K?9U@e(0icHAnIY(>0HNGv+FNJA-OC#uSSYG-_O5;N*NZ_ua`byXya zXZ=i~h)|?3qpI31zmm_ZjOdkYBN#;Hz(bE73eCR8t-~0Fhe|^MbQUT%{Gg|*awhOp zkz^v{6}e58Y#s|!=zOl^76Z~4Da`EvyFdz~9P}s_wcAQ;u zsFY}#YpW!QRl|r3`{tDeWi>~Vi-X8)7L;Xp9$4)WVs#YLoYR1KTKa5{Rq>U_t|Ne} z2h1Q%E~m%27UOc*DUBZBB61%^BVw@4@q1CLZZ>|Uh3bC4xn zvxnQ}v~6R0x~H+*?rGb$HEr9rjcMDqZQHhu+wc1xd|%uX_ne6PSM91=nQQHeT|0j9 zWUkDGayrWm2@p{x};C$L?E`y-$Nm)Xo2$%?;1!L#lGbIE2F zW+&=0KXBo!1Lx%igNWs%NDsTAJq{XWU-bx)n6-{2^}6l~WmS;pd(N7Ie(M^GqxMf= zzXf7IQ6p-1up3rFRnHrmgtJTIM_qcQ3_*K#H}eN%N{`^N1IbTRLP|)34BBI8f56!vzrN^s0W`yJibH{ zPv}&wlBLL>$%JVt95L}+f`jcacINQS*`U=Cwgg=zj=HEs=O^u z1B8d3#M1|7tmaX1qhXFPnEQ`PHGVc*U&8=md;j(_y;T?Fl>(z?>+1Ag9-L;20}1<2q**kw0g4KX{e8*yplJwX0nnHEs{PEhi#y}+`&*r z8`e_@-Y&sn(vZ7~e1Q6!{CVWOpBi94fdC{ww+R?c9AUgjp`i^iKKOP+3a^9@AXc+u6m40}fNUWq>-gksfv3dqO5k1W938$}bn zi_(fe`Dv(a1n^vjydZx(DUDeDoNTW9{>H~_aoa&>Bca|yV1Tmo^UX(EJLw8?S*9ZS zieTSD9FD>N^GFx!lYRjCLm!?0$u7}BfA>XnXyT|^u5;1)B#n973ObN^JF4`9=ovC6 z=!nN6Kr5~7{neSP(rlurQoBd->G=2jYTcyvGM`Tc2bi)51B&^r%ZWbM!V8A|`!&Wr zJ4ovQZPoThwmttX>wuQK^8RiD_Jgh7c#1Yn*&_nv-mTo>S0dhi@lbg$M(QTKo6lG3 zsQHreSNi7hzM9BU%q4`&eNZLrUd5(xy)~#C$50s0+Pzza9m~w3c)gIqnqPP4^Rs98 z_1Hm)L*Uvx_ORgKZVJ!qb2sJ#>!s2un2XFP{+mXI+w|+tfY_n ziz)oWtpofZK}XEGw7Dc3t9b^I(@U?StCqUvtCq$C!;wQUfz$)I;`WosV{xf4Oz&+> zpoCVvR`gn<@#ETj%5DeqOmtW2f;e{f`R)Fq=Bw&oS>RwEg7U2Ym9_oSbE}3?zr`AK zeQO9`_%+qXq&b{ui&+L?7R!0X&Ev|+N@FY39fkbsw!x*d{Z1>UGCa?gaP56{d%=At z{YitE-(%(=PjA#NPs5UBi>KDGN{X-LNxIn@(9d=aqt_{T4G-?j<@sN3tXCu?mrtjS zajoBO`-EDH8HHQ-R|d5a>|DM&N0Ki~=A)=;ZVg_0&E3y8VJBRu;hkz=J-++nCj7-!ptbdt!h7`R+7(KP%?PA7STMY*%6f+H_}|d9Dv?^YCn7q&$1R-4#{VX&#Hr0F_KH$Q#((fq0suvIXLQ*E<&q{!xo;PtaBbKXVK zbG`Qx{ZSy63so+O-T3u}qO*gF@{?`m=wtCv&x9eyDt`(N_OoMp9`j`o;tg_dmg@~I z#Yy{6k>38xg;(YR+toTp$}>!Jm2dtygYtZ7-i5uih{E2n6tiH_P_XPN1fabTQoJZ zQ}FXR-fn%I3+1(+XnFKsw%`gCvTr_VX3f0}Aq#{slFdqVGOlzUawrJeC6@*Lmp*itUUH|%Mok6e!WG?YZW|>avc}FYlF^b zs_t^9C5-Nmz2@(hdJZnF7b}_`rW6R9hxrqDd&W}jr-&Fs@+_NiYEfnFi=Liz1F#i+ zUkrXR|3f!CY>tQT!p!1g7{klCd{ff0GNa8rs4n?A&9RW(DcW4x9JunEjn7(xo9pST*H7NInSo3goS$>=64)BM-|fb!@1m=dqb@0axuU+?4WXo0-);q2Rv zNXBN#Mg6xMFrLOGueR>5WMs>$TB1ygE3-#GI8VB#uQtiG^`#344G(SRmG5uk1(x-h zzfancoIg*eaUQ=asJh%bk2oFd1&5?71%R{u>@@|7l#H~b^}X9ZcSf?(4>wOT?#drc z3(*9^SX)=MH|AU?x`1lQj2~>z0(Oe%z`J7db!IK5h^ISUL+nAi3x3mnzUTXNL{!QE z^>(;|5_fjjW2+ z8+|Lk-5NN3bT_YkzPKajPORfbI&((d#A$02c`F}02TOAC@B96P$8kDP$DwF##%dl) z;z1g$Uv;XSZ%O^B40~(P}D0H)NC4KUbN`X4ma|4z5?6$7=GbeR0hpFUg~16!PAR-njJ>_ z#F#fT)Rc`BQ6?quZtn)G-%&}Nbf9~Dx2X-OQ80Q^$)K|;g--*KWoLVOGHiZb~s%qWlaRxOgD*kjtzWP~oEmXur z5~SWkJErq|eOv1AlJ8+LtwmzZW*2w{2I$T`akwO#OausB>>z+H7t#qy8M)15;}jD_ z-_wTGKuS)q@xzDo-PQrd=WYd$LcyDdgpuB_iuLl?)pA|T_1-wcDEl^|x46uAwK zMpcaVNi}D1cQT}LNF}R?1=|WmHH6z**+kYyerF3XniKjoH4OGPwG$O5a%U7xsuRMp zA^8FN$8{I9$B>3A95{X`BW1{v$zA&rQ*F>5B_Q|!!EuAp=r;;NfO!zlGUQW`viFi4 zP`Y9HPUZ!bkByNpcmqYvS1$$RL~l?nLqQ8f8qbvT3Fl<`12ldk0Yer7dJ(_Vq2l8v z?TFOF!}Mk zp-F@lvfw?~lfF16Gy-jUa5r?fVGt{e;KN<#Mre}}JWB<5Kg`I!BSw%AP_v$(E4}e$85W;k%Q)*c&oMQ+ zxT}3rN6D9~n8a=wMEcFWRHHyUWe}^vT*SK7y;o*}Nc~kS!oYLUyUZFY+P*x}y+WbI z|Gci~S-pFevA#ATnp^(X4qGSY&h&PmH{Sg;b*5z1t`25-2%K$l7Ozk3t9GNTEz^<^ z4aBlZuWQS%h7f{REQCJ6J;$IMb^8rxffDF!C4qwE|Uqm#pxi>yqne3y&0W0q@bFu0<7_oWh}#08=3tQ zzFQD31@gqe^6!Otd{vJz2(4tXE@VL!?vEI^Kl^X=D|3rn@=DcUGb?AjEP#%w4Ay%} zV93!Bt<-Axl}_2Dr@Uv=;~3T}77Xkf@@d8x=({QOmEcrbOWO(COF_)pTJOtrLHH1? znngm6KIoCL3G)%UOw(G@x{`oTFAL4#gdeT& ztDBU#K2ZlmUnL){UiUlS!Fb^eA7kx{#XtpR5ovU`cjik}X0U(II}m)YtQQOlI3^py z3{hkT-w01-qEdMtB};?EZv|sCZtjNbv-rrrmTMevSw~zlj+D^rt@{oJv6bXOwV*5M zf=5}wFcHsTRnZ^O?=jkz>`dvoBwg326%9&T_!9;JTIKD@+8L^M)gBm&RONMUefinG zH);Sy6S4qp!{=mo)GhjyOn>4~k(f(w4?+B9HPj)Dwjd*gV7&Btz=?C=-Pde00?c2% zEui74g7Bi$cQ(<5z#LJjE|V3BZ-0F^0gOWh-KL!CQr}`NJlW_bXI0IV{lFHoxLD!< z0$qx@L_pP9aVDcua2vVe)e8YCfiG}hwP7M}yc>_K;*To*g2lp=W^>Tkhb4mThXeMDjENbIit@OZ z9fWbskrh{~C~oe4XBMAZ01tN*NzRRPjCn=W_!W{B?YO2HVt8xE=Ud_d{*ENwF%dz| z?ZIa`umj~<0~bzO z`+}-57%-Slk-=X6&c`Cl)NoGhM`44A8rLioImnD3WYuilq(WCM+7@7qlM8$kQ)Dt2 zv#ch>=L(;=Ob>V~*6YKNx&e?yffgvJM^{)2W?c!*hkqlPOg+W;4? z`$6q4P{aM@o5!D?anQ@-65!t2zSm7ve(H5~skNlHw^l|?XT)HaWid$^L{_*DtxbcA z(O`W2wN!1hu4kRpuI_3j;^g|sQp~exHN<7zqk);$Z)q*a1+I41Kt(o-f4EdqD^ z#Pl04@8KU)(EP^!h6F$=G+JiVScd=igWrSRs4?*`o$ivf!wh^@yYb z%4RPZAWaO#d~t+jAHM*$m?b+ym6Jx(v*@v!O!uASltqgNQ=It8gCkBRGjyS8dSHRL zb^A$4F>k%pp#`ER(n~n5@futW$J`-51`yk<=3(B2z^mWoaTjBmD8SWdl(d5P zUcRioncu-w{mgeWjT#W5Q&GX4k8CJ&R*eJ2MR@e^o%bipMZ-KjACcqk`cu5e6Cy&B zEFCogCwor1LznCm+^`bJ*pGKk@2d`kVF9KrrGoJMP6pSF$!-QY(B89&P*0u;Spw=JuTr%q=hrid|ma*Y=bCihNA@yF|; zck&&FFFUsN%wW&}C%-FSULi=i0}K6e8`1!O#rXheQW>-{$$Zy-rh81S>7v?!4U`AL zvmAC$1#_dcrOF-JAKeu5HLE$Ym0LpaW!v7LZcH1@P;gbC$`8C|LT>nImy#Q34nnTJ ztCbN}vsl~q>gdUBvt~qyk2<1x#Yn_sIC#vV;q4X`n09|>zpGS4 zBN~EYEv2?P_c)f7zv7ftruI}cwV;z@a#A*;eIzH3qp34Sl?i>iV-eBRlEfOTgau50 ztBuQ`DILXfcc5dYCl1aNI2GZ5x>$^%ht{w(3m+Dm^;sFaD7E%-;Kk4fA0a3IRkT{d z9@((d&~ouAh8{(3WVwY|64z7>e3RMnD-CO6ry6@g#Db1uNFl_Pk1N} zg3tXk)+eX7Zzh-#!Ab{J33{jj`YJ7~vDsD$`Y^dD7G4QQs)TJG+eMN?UX^v7WI>1# z8z}yjrqlzn7+T!k)*vT|iUi{8cS_oLC;TB$fsgID0v79mrk_l(#oY#g^r_!@_~Ta- zV(#k4)ZvQOFv1jCga9GG36x6-K`nqZ#z?DT%f&T)oCC8Eu0JpZ`~ZE-i2j)!u(oC?@E)W@Os1o zeQ<=1$FLe8>a+_u8i8{qIK*wzOcfx$@AgUm;ixF-ej=!?qcMOR0jgKGw6YUifjV%%|+tv z!Z11H^XAREI&Zau-ZhA>CF39g@Na+v(IJ%LrJNg8W>Q4sB5K1DS49%P-ughrFU)Ac zlIjdTF7`k*G!gpdPCaw=9hBZ`*m~gkd#CUgcf$YTgrcqPt}qBvE31-uaUK;+(qO>gL10~zV)wGvdH9dR1MyYU!+ zP({Lai^1JhVL69Lpd*FHm2u@WX~c$B*Z;zSI(K%q-40^B13Jd1c0m+Z*4m+5CuU~d z$E$82hAa<130iON3X4w&>)5vK(;wHq1#Ej|kSh?qyZuycYo2lRk8mYtu-3@w=q*^=Z z?jWq3yb(s;^6e~6oW77EZ1~FlXT3qSNsGRatR0YWh^OuwH&L+*KjGjC*fV*>-LX^D zwI&&kB76uUkkfwUu4i5Z^X|iQ>e#Ht^Y1)t3J7)J;8$TNvEc+kM(Ra@1b5lJ%hzuC zpa#;~!{XCPy1Z8K?Wp9qH@kdVUjfCPUPR@9#j$#bvGH1)qHldn^JPi`>WLN0LeJ`R zu~hWlx)#v@n=le^cw${aj*|FQJZkAPxBk5xMmWApN?chW9^WUXWRHT3 zl3>I>Two};kb3%FaTKLzD6+Hl5#H>6kY}$#VD*Y>Pe^L`<9uBAg<#~CoVg%gpW(1d zJfHpGtoCU?la5YW7LR^M?ufK9s6i36@Ov|H3fxzzdt>IAU}ovI0gEb-I^0p9!7d%G z)wNu<{<$iUn}+*7M+Kt(l}b{d$FT|Mg^xMh;oR@%Qbwa^7;Fe=1k9|6)e~kABkTJx zfg_ZpoQWEM7n2m2+lxfuW?3^+4E8J<2|{aKyMo+KYs(~j=YR6&O@=5mKR1_hgcIIM zD8rWA9Cpqm3f`&3#;Oh8X?^i7X0d4Fa*byZ@QmEPDN7g z0`&Wj()?katd!U{0%6tx(CAY-w6ZebRV^HVs!egpjEq3MR1TODi_a`}-fScK#wXmaE zu2{br*7QgqjBC(n;4?-%6dzv{qsXheTwDTgPt$dN%ATkaWDtQynqqesoTW?Y7?`$2 z;^qO8q5;Ql1~yx+Z7Veg?&7H)sW6^_(#jT{26#7iBPfZ;+ZOk61BA-&Wy!9LfW`BR z>GI|GB$tWXsrZ~`nuy_950wLf{^go%laI7s?o4Ha#b*SfxS-!f^vmqmR&(nVJf&&M zRnzGJTzDt5gL~Ie!z63C&&JOkoF;zC9jgNttRq2-LkanM+VRx!W{7gylv3aNALc&8 zW7GU0J*4ylBPz1C$Cgc^WB2_Ol-}r8F7cD1PsVf|veBtsA)Hm4IVKFjRt7lVmByMl~vhJe?NmQ-APaEgPp0wYfcm5o(tUvtGfqxgep@T+UslfQe_dgwXCP!@W6-3P(X}w)T9{EzPbTGhX~W29qarWG>%ZEt9+ z{;yrlzrNvruFH9)Tut0=bqJ~BP`S$1w?u$?11N)kgvz{qA`!1&&QU(n)_V*o1PzD^ z$YlBL{`jI25+Rn^Whemm+rjkg?Ct#`SF%gR;kXju*^Q&M<@NZ`;K1#oCu^N+;-KR+ zsFu#I-QMx>U{lKeI;*ww{q9!JWLr1}huSE!&C|)woLhUWm(E^`C5zT~P8B1=<)i^l z8DgSAYv)|D_Lx~3gKy{e$c)C$d26bheL=BgkWpu<6{Ut(zllpbgNgfP+w1+yhwpxh z=4Q;(^jUu>PD=_;sgW#h6JJ5p{+SX+qcsM!I6moGa*IJVl$T-XLo;2z3z^?bOl$B_ z{pHWAkJ*NnWXP}pJI%QQq3e8;L`oW1(DlA|FxAS$7hlqgv6A6dJ$}tzN_&{+sC2`P z9Badt0y+eX*Yb0TfNluW_c?;QHUA9Dq!^fIzsNd*i` za>!C(`H5B%0Xjedkxk4I=lw^S}=^uOqjW&)e_tafU={jgp(GyM($5N4gEKDsQe<_&eO$ zb4t2pATI7;sl`1f?TJex^KC$0}$v=tNK`r+jph{pKs7e6}>yG-PojQblB)2s1_c z>Y*s};7Qa&@-{R@ev1&`BuzpA(zF31`X>#bc?ExP@(-8N?cII5TBmu7R993t&wa)c zzoE8-$g!jyK?q^RBsHf3a z22dYl%-rOrMz){=p|OC&0WXo0=j4u~z#^0ZyMk}Sck)a8Wwnqvq=Qgv8;=&!|B+}$hI59 zYz;ZyGxm}lIZO@0d-e|29HUlkc^i*Y7u7^wNPb1KeAq1t(_jM4q=X~ju#7+We`w|O zHcSvKEGhEX$KA~>mna9Un2G#k3mN2CcB`U;otrAMHe8XE3{?a4iDm?>P;-LRD~N_! z%eqP)tx*r(sD*>SlJH!3J?CXJrzNUyLwN^exXNpC%Mhp3&m(nwH0B62?8%vg`&5sBtnO;7D2B z!=29&!N;gH3*ncvQPZJ&iPFhjqu;}jb9=^?;!12>{v(dJ<;XxDuKtt$ZF>~^Dico6Mf6nJUT6?xTfBE8H#%`{PO($Vs@W8qkuE3HF;ov5hQ$nEjaYc`)%9PJE1` zz6m^lb2{GIN3l>3PWHerO&E*ZN=>brn+JCIbphS~9lG1-4|;%Q52HmRj9>!+kre4qb#$7wt39F?3RZ@x=6pJsEIW>_Di3#%B})|H>+t2ZH&we>yLb(OiiR z`kmY6_nUhg8Kk5_q#6Vp|FLcaIPlETrZx2He1(SskYtR4We%){|9mwp`m=dw0tvea zJ20|h;k1etlOWuywi|7eaeI{sS)~tI>hqIuk|S8BF6%{{ii_%al=Xv~c52JgD>=XW z8;qyJw8P#!)bDaIcHjwxuz_Ek&FE`_<~}*ekz^qh)s_8lS;_Y9*eqbO_h)S)dAzHC z=H<5x)pLw}Dm1#~L#v`;? zQ}})uSKOzJo@G2q$Kt*YrW{VLSp!4*5@9$Ffg^~z){N{CMZ72#WUcLN3}*DcRM zD<-gAcC#GMA^OS~8Wm6J?HpwdB7NY`78aE5_+YeN;jS*nI`AEU22D6eE_0{qm4ies zsZoWZqM{2nKsC58bPW^M<LFp`q=yF=K;40b(FBD#gt%mQ;ji_P#>-yWR9 zHKWp!z-=&M)a@3WcGyUsw5?wO-lN0#$0g<6hk3j>Kn4v8{=nHY{kG|?twD+)1^}DI zOBCak6Fs1F`NwtCA9!fR8(dXis){kG5~S1{FFua0uaBR1G{vy6B3u`99(8KGWOxzx z$VB%_3>(irAJZ8c>5hnNPV!i(G8`eG(@Pn6`Xq$HrPi1D`yVw2si6ah1|zlFSW`Kw z=(}SW9Jhe;AqSuF2CsB;$il*$GMmia(uqrwJ(^*y3$4kYsB#p(s5@MlO>Q~m?v|hc zg}cKF-K>~|pEeIK+u#zkKO=taHRC#Ue_g{HCK8On5vJ%;mlGL@4vAL_Y_*Q_Q;@^V z+kLu1X6kZai&b0VIQC~OC9lNH@XJF8b)_JXk-^L>%u~SGv7BAo!$biU_fx2=p{rp| zWN2K0^(~{g)M*6gc%ZCO<@?rzEFs5jvK>o0W{>)rVDH()k-(~@1qs$bf+oS_)TrZZSr@c?U#$NIviME%>Hrn@ z7^`i$a-xB5MdG+m+-boDq4qCyeHs z4`t(zk`ZQ2EGZ{gsT&eGfZX0Utj|w1+ptQ!OiZq)&i%UJFow+p+~H;Mw_IgD>v`1a zD_rhDbq8OZ?P%F4& z_s}QuvAx8s=2Q$f7Fcfo?hPQ_m%gxL%eeN4FBl{~c{=mN!|!q&*(pX$LUPAQpd*&o{|2EbYH#87@uyL% zr6T5^77ak?;gev*l?`=t46KwS$h3DHDBZ}r3E@)%pHe!4;Lk>-Bxm|3jL1>@6%d-o zHRBEL-hM9Ag9(B+Kd?XV)j#eGaE0K7Ew|}vr?5|Qka6i@>vba_dKCV3Maaf zOQ^&ic&f9Ei`^1*kjo_Y&oc?X$oO%r&F7GvEfdpI7^&&e$MYhh#(HP&VR0**Xi?;7CvT$=7nwt|1VV!o|4<{7_!RzzXZ4S=V%A zF)et6=M?>IDPJknA&EpV@Vmi5;!PGfkD)GJJEfyncNj~(R8NZ6v75Ed}(K0@~AGhx3Fmc)ED(?F(6 z`V(uY?qTXxNwybn?~QhJpya?{U0Y19{3Z)=A+`=W!EdsE%Cza1rS)T{>p>hWWg!O< zjUHYb>n7oMzZ$4+<5}iIu(AEo2oM3^1EmLTPkB10POx8HwoC)EAz2f@rk??-RZL8W zxcS~61;9XsplVWLUN*c$dZ%=JhXx=?nQi;R?$JG}P?~~&{ez^ zP1igYH{--fs%Efh3fV%HI2p}O8f$u?7uL@_Z zv_MKYW+uLP_ms&33&eN#aa5B9-*>n*?Qe{^Kd-zW?zFSCCJ=X7YLK8!*gho%rS;5x#c-n}%5sZR^9a>?%$H}lq`eKH%)^dk# zw<0|o)JhKv%J$%6KaC+M7i_gX{orh$B@ZRFrPQCXF;#o@@F5s{6Z|!n6@OLb1)-_8 zb#cmS-a1uQ-p(>a`s&C>di#-CJ97-xnv={Xawa1XLP7iyRbasa*Y_t0iEY&|VR5A` zhhi41%~BZ2{Ol;mm@7$|6mE<(uhV4-$?|pzS~kkEb{nE}ARmz5E9G9kE0{A8x+b61Rln0fdW?XTMkAogYQg$fKRqF$9@$lGjR4-qTU4 zQ&@A2eG!Rp9M@~euWU3yx3AhYd!3jWXuOLHIb-Bk(ago|Zb9))g|itXlUiL%$Ls7T zknu~O+W*KA{=ypn#u5HEj`0^y`N!b@8}a-NQT`k80RBQ7ae5YJzC z{#k*Fw4Rxv{ufYU`+M*|#E0ddng1`u=P$E=Jc(KW2mya1o-Z)ONC^0Q_Wx!>f3N;) zq&nbl@pQ(4se?AVvlX z#O=|=@!;Y*iU3upuOV+%RJZiwC3id@ZZQM=MV7BinI7KJFF_Y;ulr4z$pb^xK;^}- zWesx_&yV{PY+?2{cJZ65MVvR$p3~LV{>j?U_0O9N{ssyoiHZ^G;9$AX(e535%(Sg} zz)VT7pQO%=09n9Wg&zm<4_Glyc>maMEWI(rWNM$)o6)Z$%M0(YWJ5j5=|$`x%Zyy` zH&qRhkjjdeK^4Bes!coP^%gEKGh7JLwq@9vZ_jWDp5|w+_2&j2rX1+m)upO({_o%@ z>MV|;>Y-CiZGMS@RIO&B&`26&N@Sb)z}2yB-#AuT_YzTMo!K~PN`=!A_{`w8YBww)e>{C4Q2zuL}FErIg|aqGeTcylaS;@*sboXU0C}V zhgDUyL>}i9Nm!XGH!Pn8D%L}QFD5QpQE{_Uq}okddL2KAa2O&xG6+6+dogPki{789 zJs%;0vnHYsni+o=VHDrJ!eRG+{MD&wToRqpUR`Y?9lq#k$hYgu5_Ys>lc z3DRog=Ae7qSLN7LrN*y2v$WyZjrRRK{M#bEPqIc_JTisQzH3SRW}xAIqNX_oF)>zL zfA(Sh`P-!V>;g=XXp=LkOF3vTN$$o|a7X5t+CGYS#5w z$z}Svll$@m)_8K>$3^6)dslCCIze+tJZl?SlZl%EB4IyHir)OqrVl?c7TXIF<*iWN zR94NA74^+!`HRFwEpSG5I)rZxF_t8*l3rV)R~np`MQz>0NM;f`V>}3G2Yh;`uFExN zmjFl83V|Iuty%2VaK!><#IM~c+jYQ5y93ATjFZ*1$>oLjX{QR^d>}Z)T_t`}!faB6HDf{~89 zx{jdLBa*e1v3IJhht14Wn-e zrgkf}B@VL>E(Y%0(lb%g3-r$=ZOcMq|NUdJT_zfY%F-VVTqbY-gbs6fItAFWenZ3r zA!CPZf$cr^uP=nF@il6^5;*F0g_v842!>%f4tf=0MEbyb71$*X% zN1d|HSpAknx@m%eu}|RSB?LJY%h0d{R%*yHxmam(V{oW#s<^WhDj~TA&Z&GWMWcy^ z@;!$SBJIkCs}n~RdU{-wU(;p~ycIF+;&*geR7OhpAh=;D8(W?q!l!zDRSxvgffovW zyhwv}71ML7kp)sxO~OAfV$gz|qYcwvseEx()iX=qj3y*(fNv;_8^Nm2S|Js`3xXSajTK2U&?+WZl!T_Gsma6WFodg-A}R zSV$!Dg!dJ47PTJTDbMQ{kh7U^G;Oqi8;)tOV4dN_=s~m+f9*?T#D;k#nCg=YJ%Svn zlHp>w9vu|!CwZrnZ`(F9aXAses$v9|d{Vb&d>Q(wpO6*x+Yzy~??-%b z&Pg)lc?L_3Kg;}Vu=OLTh|0mA!F~5;a6a%USvce_=vzQ250}y=W}z~|=$Y9dftQQUwOC~bTnc6`!M7QQ)|b|x;dm2dmD!GA zjFTW=qDY2*^dsb~yA@oa)wfwZ8@Khus}rs5Rjje>kvYBP&Z?O)Wg~J6NTw5kF`7b% zOzL0^7LSanf-SkAZJE{{UWw6zPcJh-0s=JF=mfcj=8r}WnL7F$QKaQv`+(=>sae2C z@q7fpgb%(iSUMkMF`6r=fgK;eQ7U8M$F9jl8f=Zop%E|=5ql^FA|Q03gi?2BXIKT} z1qm|*7y^1~;Ng01uz-T?5`3oR;3Tz4fpnxmcyafidKjhcpbFnmL6QMb(OE*?Z&oB- z+$S~i+b})^#Zb=VDKpTr+SW19`OZ;wpYEo4@ZGBNfl2YOoTRrA5~9V)Qh3$(;HYI& zDDd#CUWIqacPen44{-RX@7h*YEsrxvj1yVQOwpq&8-?yiC1QYk5cmw1_fp{PfuCzH zELiDW@baUx3ccH1jqhFWRnq-}7xFd&rn5tE%$aw(n07?Bb}`PEDB1;FwtQR+cvAZT zwsLcZ+ZbaJh<@wopUWCIIqLJ}=S`RXWPt(H_KsH$2Xg_|!ZZ!HNM2WK;Q?tV-?-g( z(At&{O*4MPy^9bha7vzkg3CYS?UWFlHspJ34=x;T@buzBSpZFFp8t6z@B)sDU@-fi zr10M=?%!n7|00C}{~d#qWBiIV{;diBMKk`lw3c_!v;QkrDP(19LHi$?5WvE~!1f=a z>|f(`v{JejhF>BSKr5+hZ)@tT{+HtXiV70aFfkC)uxQf$R~Ymw%KEP&SCdxI*mz1jTyC3+4B>V0NUPwhEG(Jf2* z&|P!-subQcbX=RHT>D~N#FKV^Tip5C|0dAk+F8%`c(@?`Nw?AY>Haq9MZ=vXT}+T4 zKPkKV_Od;9H%wWF$vya6viQ9=pW*msS^tHS#_xpR8u(0N7p$2Q=xf|lF$<u*R6-(8?_S-^!P;!_ zv(80aCPAt@_VeBl&V7m>E0649TC-;zHn)7TmBfbuK@Hu4r>@4hS^}otUTpfj6V~!W6x)roiWCrCXQ6KICj*Bjkc+~ zbi&j^QFEx?k`ovQrA&dZys2{RH9T~mhDY<4-@X2zOA5VH>q}{4WB)-v46ZK`dI)0K zF%GdWbuSUMYjHz3F*<(pfE9TA_P$%_{`P$Nc~5{$*Du<}J$Q2&23XyUj(JF7AjpVF zIjzlaR+xQzMeSio!o<^W9>*#iB(MkEazXd~QBaxR?WAG4|tKAMY( z>o79ey}^Je9`Ir?SrftqWx~zvhGoWmhydN9?w1J?+Iq4~h7=o4M0FDI*o`Bze#PMA zh>_pMGAkjBU`Lc-45o9PW3Euhx$Yy1HNB)gBMgm>F9cvRY$8%#a#%3vL?Asxuyf?g7PI55t;hzWQm+DB+#M}xHgZd zYwfd+>?~V``r;p!{f@G(R#LnWW}qjH&mx2-zABQBtRyG&a+!BecaiYNy@-)BvB<0Dn(` zF@Rr~`yIDQ!4EU_$s(Gz71MJO@#053M?zJbL^1u@>3>rxh{VGNh2gR9t^AXPP%p>YBqk z=Mq!t$yKWndvMBBSk0VY&t2PhY)w--y5%rs#5gUx$h23Ze&RfVrTG5B&^DsqSVO&5 z8;ywBlgD^xt}TsbNiJu zt*vU#TzcYQ=5}qqS07;2)%eyJQ`?M}_0i|QwfQFs;x)~@Sdus1%g&ziz23m)Y%&}Yi)zv`5DQ0w z^rEv)jebL%JH)liZ25&VM{LZu-kd7cp|0j7Z?tsU7POFdbgS^m$}H8`_H-F=y( z-0Rw{IZ)NSMz<_|`yjG&R8kGLOj!i;$-(Bl==lcX-!G?2_`OW(obpa%^@E}L`KecH zvXwPwrI$T;(>|N}_0l>g|M~AQ?#TR*Jc;9&yH#Xbk~{x*aZ8l@W6Pf6 z-3Q07Ad-E0{?a^gx90C60ewuR9WC~8Zc=?<_~%2n8zA#&vr!@fiup`bjSNfZtLO0g)X80@%Ev?TP1zkA}Wf=jpA>A)hpLDN#m9lJ#^G%tgA&iBZkxTX!=0rTri$x>@RKp=Ra{c)J@$`=28`%O^-HS^c;n@ zUl3!?ar6UeSu;}tKad5M<`R5bgf_S6k7Q{WEnaOuWg&(4b}(q0b@?)WTDqtbdu4@njh=G?HV}+!{Zly;$|}3sp9>`jwFn#>oB7Q?*0O zqL||{hNpj;GxQtdb?_5SnpS7GT3_@$@`b$K5GQvXf4^Rwx%8sH5pA|Sk3Ug@T}E03 zFz6@##D{)&n;>(kbLfEXFSX@yusy%k7CMVo&sX$?xtyM+FQzH{KQ$T_-CZiv_|MvO z=lFL9CnM=BMtllMbl_kzPjW#H7wprz<{X0&PKrg6Z1-8y5)x-$6)9zgKm2aBz7o($$7?*7@`7SR_tHOl}62#{4yfxM(J;(l8&~TUQf)$(`=LGIW(hO<&Q@C zqruHqI0z)8->{kWZ-3FA+CTrjIhc*2wFs;C-9)Rk$Sj$4?=Z0-IfE#il^%O@jOQ^tU*(oAWaR|NYz>=iUUV^9Vtgxe)o$ z$7j3jb%gJF`8aV@43)f=^63aV32d}PFU&YT|BvJF5ZBAg-1~W&C9#q9ay1X~; zu`O865RAwp>k->!exDJvqbuv{HQSRyXo|_5ldOmY<|>+-gI!;aFp1^BuwZBApg#Ws zjlgPh`-^nU%P*KS1zwZ1%*|>u9(pW`rRi+JkJey+1F}7EqRCa3q~?bXUbfs?a-*j1 zdB!!HFtCzcW1VT2C)rvo_PmBEEk{^GDYeJTduugLwkf>zUZcbL^+a>@XSw>Bs4-r# z0Oq!@@Cwm_fk_%{%LO()Jo)aV`Y=g<-{UadrU*eRt z-mwZLvL5O>4M>{2&AORBONpf`C9gf!yJVX;#(UuyuMdI4C1GGc>vg9=18~4 z!H48+k8^Z&5UOD8)v7I4dlJ8S=xIvDvEDF;GrFHh)%}cY2h7=Un5%kORsLcj#E8;- zJN7VDEN$%3v4|+|lV*R#|5(79eY7G0SuMl4U>`>-hR3N{dvi=fi043eHOXPsc^Fw| zC`WFYPL8ufYpu^&*YpnCn!Rf_ds?PuwKBoI=!Gq5snR-V2I52MjCeH<)@ErDW6b$X0OO33bM3o!t8OnMot|% zte+|xiaHj&U6Cv1(sSMT#C15Fyz~H&iad`^2ob*PQa$2LHj{p{Xi}awR#eV3um^;MJ(D?1 zJ`X)f4ih*Ecs+JTK)2uk6aoEBzlL;izWy03`;p_L14~AyPSYf?ow3?5lc#RA;CGq0 z;U)NobL1R@P%YSuxeDVPjV<_dnG(V~f{%w{q_^Ntr5ZxKf{)!X!j=3f90dQa}RakE&K9Ue-r+x`J-0HlKwfe zPrB01KoNSp(vL@VKJ}9R!#T44a|RS(IPY!g@4zx*eM^5$G6RqFqdil((vN}LzllHk zcIxUQ{>>+ZBmRdz;(s_6e~=dCNfs49$`LpM$mB*1%TgLYsC#iCJ#zprb(s{DA{^49QLwuxhy~=5dU97~Kw? zA|Mf*#QY9>%(MKj__1fB>!s~I0Wo%-=sxQ41x5(ZqVy}V8T(5G$Vh5ukVEEKx)2Na zMPvEeZ+|$}etdxwekNR;s_21KVi`Sl0!1BX^PHW8q_efpF|Bs>$hl58IR7|sIGf!? z54(t-iq0nvYBv_n4CuZ*tV19Yq#WNX<3cDIn#j0ZWs9ylYH6&sPeeJ>hGOpCS9AcM zN>E$fvKju!rB|i8v#dAK)pW(EdeKIjUCwNO_7g$713KH@@!-868;XF(j}07!fNL3# z>?m3u_o484y$7vDn-ya1Cczx~@@|;x+jW%?mwRB{}pMzV~z+&V|;e>4eU#n6$ zapYIb0m*)>J~$V!1i=agPvwJ+fH@Y5<}yULIkh#FVW8#a$R;}#afeL1Tq8}J<}R)^ zUt(Eq%&C*K=3}v=6Tbj-P4@7yC`{Vp&v-5dQ;AImnVzO$Ps2YzJd26Rv-?S$M;^cV zLsG=^hw6|UnjjBNUaqRi>2>wWE@K?JbUMfbD338?!g0bbWREL&KT*SqQs>-5Cz<-| zc{tUB^Y!95U?MLxGeLBX1KmSN(#tkSi`yIqwk!n^>Gx2i5A_1T6S`hA)WZxiZ|ii4Gtjhhgy?n`=lT>XiiiZ%|i|WOWhfE0P`)hhfFzEC)ANl3>V>7&lKja$6XoiB$*Hhe<;{uK z6|@=E`TB8eq!Qnp`__+6xu-YSJ&-9a-o2CKhh}%XPXze`SerUP3oN`O$NLS3Z~f|! z`HQy{*{9h$lplJ?lH-lVVNYWhpu$yT;vtQ)XReVY`+;>gEq`&&l(Z8tdLd_ovZfGQtdYl0>f+tFSqOC zJq5tdp=*>QZaHR`twEUSOKwn|aem<(EqdPihl9~rr4M^mAb>+~w?}q!?pu4Hf8m^8 zKX3iR5v1Zfhp^$WgRps7onlYo74Zad}!VnK6dOUrogP9;L|^4OoE4rNB}O*oh&FkdpQI#7}t5;nw`kv z#OE6a2&mR#9uED-s9-ZwfSW!7Ek=0^2ccrv?(?iLc$gf}?@4ZjX^>31O2V+Fr`58^ z`FwL+aQ|K2iLTdEU90H{`oW;og{<77<`&61GY*M1*Juri+KrLZjGDykc5&ps47QniIpjVvMe+gb z=rUDh#1o5!&gT~5SwfN79KNnV>UkwG{lDVv0LCp`nav(yo|lgOF1 zSX&ufPwwF&=kq|#!(mLt<|P;y*)nPLtACJ_=X?Q7H$NF!a&v{vHTgvKA_E26bc#AN z^TOsd`C#;c+205dJx8?>GIs-zCAINQla;i zp%Uff<`=rWf5w_-3vYH5YFa1A?nAhElX3Z*UJSC+L_Vg8aXM^nk*oEXA%g7Xn88teM6L>OCYbH2nubQwwlp!zPV zZk|SSbmm1z+~(vrsc>Z+ML0<(db%>CdMpo0_K>(-`55}O^8~}iMv_JPEkTmV;ry| z_yv}x7m%=6RpC|0Ay|fRF@XuuzIc!iEAMaHOV_!2w`#h^;Zjbzu-i zgTxZ%<#NIlf@mCNu?^Lu5m{we5S`scE7(oI-LdYoK{J>VVZ@bm3^lyOa+N{pP1Lf% zsDjaXR!*`MAApCnWMfEib!QBepyT>cZ0zUQ9ar^n8e#)HPdJT+FSN0edDO%%e1hj1 z7h7EDcK{nbsnt#qPRe~%9|frsO&(flD3&44#SFqJ@%E*3{*G(tZ|fL=}|wi^_v`?@vQ+FmH5(;3V3v%`1lDzB31gW2vx|S2PxI8G?%H{24v+6o_o@{h`JPL6Dv+BA_-FPMp#beX4!q>)J4Dcnr!K!W1)34AIc zT!lqg7G-f&8nD0?Urz)jDMkT~sl6~f-GcwCXTbW<2WTjEWmPOmnl6v_rla7~yso$-P=L{s^Rity*OvIUUFc?dJutjCC^I~0oZ2#vn)Ncy zMj!crUod;mYS37-`CesOdi6j@4fGE1GTQ0K69ZFBM#^FooKA=g9W0YZ{pt6>USjZJ_8Ef%e} zI(r${Mu|Tkx;|?QDla-UiH6@0XN|?|7DnI`e&ejS-khOPr6cublY1&^JKa_yM-5c~mQBw$LXq8dpGZO!K?i*y%0I^!lN{bmNY~Ph!Y|fmA0>j2 zkom|XXt5@JU^6UzW>hL6>GT+=`00(U&nhUTZVjew5gII$1<+3?T{E9wYf~q^*4{yf(jB*L{Z=Cbt?_cqX>p|6Im;rqC^V8kfF*?SU^rdGW znT2ym=a@H68(u zsVl2WAK6HJ6!d_zJUAagRn)>)udCPU=Y{Uu0Ky7wO!RjkQurR zuejiikRlGjLklVZ+Fr>Z95%C`pLl5A7%IPTp1`4A`!QX9ikJ-vA*{Y>`prQX3_-;~ zIK}iDkp?iNniFSpD`4j4(<_jhEPs8LvLhvQ<5|dX_CkywYpcHclq>{xvw5vlcDY+eUb;*%k~M*=rU$gm~6$<4D=w zYqn`WZD-9wKk=^FOYb#%ICuU7+re*)J9GP;e>i8w($(}@uZzBK?7{tobAEWe^MgJs zb<cDztqG&=k)R5CoMVua>Y*QW0iU$ctT;poE#u? z@PuxMUXJ>rxMI>7(`Qi4W38`4D%A|fb2(??SMY@Ti;75`;0dDQsG)))IpC(G8t6p#Jh!Idsw}8haxrP4;AaMNV3E8qJQJKrcTw z{?|>OxXEESY@*knbiyY5z&3XrHi4sUcg0O;k=#TpZqgRA^hQo3D=qBEi6mpR6FH$o za>6L(G*0A%I+dedZ%u0(t#EW-H$Lh-(WCv;D{|6=V2`iJ36pF8gCi$x0ik#3 zMAaS@WZa>XhHrBDJQxaSchtcX=+XKsc*3vB%XES#aLQWqoa2$8-s1_LNTN%*!4rv8 z3MY7?j;7awrwZ{hPnSw)_@(meiKM)N9XwGz)D~{=g!w=d?BGdjhIa1Y$)$Jjiqqmtddp2{SHKmZK+{-jYxB1iFv@3ZFDpzw+`Xe9}fxp2`lNTzZF3F2~^$ zzEHE3AmI~q(UYG$gDd(?lesV0iBDdKb6mDPt)Y2wvPv3m zP6t23PDH?wlq@U_9~c21{iNoaUDW!NXDq5Z7_m zWVKU}adO@30SJe~yjVX4TozI5KRN8h(7x#4!y3e=#ca_HBfF3#6K z!{szx_U^F#ihq^*svu7oTD+uS%KYFIs-(+t+;_#b#z^Fe#-ftm(pN2%wHnD2mD^yi z)h=B7iFHy~FeXndqeI=uB)69zPS*P?BG?PLgirB6iraY->% zs>g~I$6dEjQFvfNBkAXb=S)EsC3Ozdur1>P4m4N?430XiXhOZiP`XFu8y|yEQ_alH%NlktNS?`f(pVMvdw>g3q340HwVd z7$rd&<6d08MwWrTQM`?FVjOBFYSZu%yiWW`*2pxEHjd$B49rv9%BVoC>@X74n89={ zIaWlC7xA(ZnT69?PmsdxPj+QOXIu2R{axX+6`6R;y6mcYt|lsvxB0YYW9_zCt~)uQ)_satJncekF& z(Rt)~SPv=ro1!=JM{mo$D~-^|25N0}#`+sy3`A zdfZlQ!vdN)zGZ-L|5I}?TSRK-Hjl7eJP0rrRh>D%Px;b zSDsr7*_VM_zaoXw+DON*NUCN(xE)IIg`VyfPVK(B z(@W;xk+|NDUvW_SBb1k4ap3<>Y5NtGdAWQL_!SR*{EC-jO{Wi(c>Id`iSl+D4I-Vj zEyp4)l%sel+@b9~yi_t-q|dh}y4)w*u}F0}V}7@1amax+j%Sg4$*@vf@GM?>dlugu zJc~nxGwaqnA_)s0&mu{xZCM|ArM8A+!OYd5p;mwn&*F%_l;?UD>32>yR5I2o+Ri1W zQZUxzexd@N9YFhuqd$`>KUNh_xQ<0+rEKXM8n>G3aV-9jPh}^ff>12SuQ*hZ zr=KF`+(h(N{0Pk{%YQFpD6jhKKN4B_;omrZ>FeiLIAw1ZC(tLqK8zEkl=o-;<*b*! zettz;nbJY0LVbODbMBW^(>nah!L+F2R2j>G^9BjZOBy-a5hUT=& zrZYv5DcxPntBF);uW6RGqM^#sDUwvq@ZeD`iLoJVk)Ek!#)!f-ZJIZ@AnHDVOR^<> zKv)0urf7#6(42Ey)CAHKc6N1gpJIR0Sq>#$Se!dD&3WCwa6ntBq|W7ZXPkm)4H_Dp zm#W5)yV_NDJ|WIN8eY4LuCaNXj_HEF{_Z&#>KI;61Rc-#0!U{STIwPn)n!#OaLD@2 z^td<(*a}UTGBKN+Pc+$AHK|lfDH@!RoIcFSpTPl=b?LYY?;g$_njhL=B_QG;v)bDH(Pan4(86QTUZISu;J8n=*SmHuwwVjP8~1cjV_ZpdNPbzzu}S6h@7fV$cOqoyPvqgoh2F`A|9~Gt>DNA^%G+I@pqV^N>1YO+oC$D}* zFLYM}(k+*dbwgGCZ`>|khN=&1@I_Ef9Or*Dc^QJrEI6A($^x|B(_S>uNdLs*+==}@ ziAMNQUz3L55UIv&KQiNY<>zyEpynaI#c0s3Z{kOmA9~=wXn*Hfi9(qDS!1R(U*`Wjrip?tS2pgYXF-m8$*KWRv$p zoNmpVfjUC7Lnvr6UNpI$`vozaDGyE7W01WD)|=YeMWSo58ba4>wMq-MLnU8>s+$Vh zp`AK|z@8`iHdB(K(+o;UUMsXI~3Nx0qhu!3CFX-fy+EPX`*n9Zn8 z=yHc{yc)luqQMk&vw={ZO1)5YC?;J(%dV)6wJJ-vtM*w?qw+ykrm6kWd=bPCqf+i-5*QFRc^mi+0IZzab748l*xlXHGmAQ!X=M zDg;w*q9dA&V33S0I0ypzg%c<=1B07?3?&EPTiaUdk5U1i^4>BT8*bL2v;zN+Go8=j zbp5H&IGW#e5@dRk66S)htnU6;t2HlnPC!aDlJ*$#&@+FJ%6Y=kb&aGE^(y^Ap`oHu zEJ<{6rY&OJtzobh5aZgdft0F5B_0}@&t|84M8tSjUKx5fyWGbivueKhaWSGCxP0$n z1~XpmiRuu9nP^w zYVc(cn+-5qZKJr#q%AHkfZ(N2-UD4lzf)>1C+#0in5k_WFlC5UsE~!WO z;1T9pod~AnK$Zlq=eocnauTE$*;nD7!(r7iSK0S0=m@K9s4myCbc=U%wu+u5ngCdo z?X*rqhz)HX#XEd;S{xFiQ}40?ih-C?CYt>$Y^2UM&bX2#X!S!SU*sdUdm5^=|E16V zD0eB9YpPVthjZRy@=|%9$dm>X>N&I3bA~G_SX8NhU2Orb{GDh0fCr+s-OZp=GC4DB z+(Fl$Z5gy3+%?4H-V`OOgjMztI&>eXK&(oxtA8UnRSlU+ZiX^6R}@~>5dz_u`z9@8 z+iCQyRI*@q0vB;G)OJ8bU0cTsNw|cdiiJayQy%L!Wl3%t&uH^cY>uznt3D_|;veFJ zT!e(k)wq8`wh#)oSRGW`W7P3h8+G8QJJ*oukLFORxGp!2oL1zVC|sH(_D&qc1ddu3 zO6Nh)l20HUT@sFR| zgVUY>9kV%6;Ywv$59it}I*0zoNcz50f~W^CFUuU!ieVVEKoJ^_rP(XGHYY)KceeVz zL8UH*m(HM?VtF5CNL?b>aGz*`4XIJBI`Jx4Cv>eYr)JqLOa-X+7%!#6$$<8a0egY- zM$vshK{wccKz7*@)T?}vVZm??2hBcJh2D>rE3y>$1;Pv3$W%v_X$O7>k!cC2*ijgto;(1@hFY_Jkh(Z2b7B3W{Td{xUko(o_5I`8pF6oAkp#85tE|S-A~- z9hJDG@zBh+kelYoO-g)7|JbRYL}mh zjGRjcfxUTSak!Y16dC~KtY-q#q_?0b@#-LE&X*vGy;@G#4;wN1$66gTfL0bS4i^@0 z0F%5P5t``YsC&7cZl487nxX z^eMk6EEDWCrHhk&CTyYF&Ar7PT-dh-(NxhQpC!|XyM|-e->$6{N8jau-hUtVl4lEN zOF@b<>^UuSJNhR^O{scg9_(qBHpX1d)t} zCVTS7iDc-3wj8GlWhhN>*e+Jy3l7p@hldhMSiWO?+)#$HG1L2r+31fQ$WW)+ikUfg zL&d{Cb{qo|MAHsrC}Z!buRsPI&G8CkKr4v80vVUyfsDgB$LpUH=%nZ7>*D2%%DP>Q zqDI|T9UBgrZdGL+WcRUtRmjv^G$9HyEW*+uS;$PKzm)!Z;<2hshOUx!0s2d}r7z>E z#)D`R56Z$C)><6dAanDU-c@ngXe=Bd!eP<8yFP!t+=dFJ@f=GYoBqhNqnNBuBR7nu%RBiJ+AFIV> zu>@roL6f>6&qZ^pR9v2o9{fh~^4R7bfXc^85xa)Df5su5eMPMKK2RMg%+@wP1?G`fRyB&pkj?r6i<^^NYB(x_UIM_mA$ zc*P|C_;S5;Ih|Nf^5Ft>N0(cD{f1LG9=jv(-*63`4sr|G0bO%@=?*Sxvv*F&4zAiu z`JNJVbKWa5%guOQi{?B5l(L(~-t93i_u$5MbXA_Qv=zOP*yxT+Z*<4u+>PmnHZW)# zR4#7qV-Q}BZTybkdqq64@yUa#LIQ0YzbjZ)kBzT%x!2OlMLww4(o%KX>*(txEz`>S zgLIH5m6wUHv=ce*Y~l;uuk(ye{7Y{W|8SOx4;WvIWSRJU5q$VH@w=`7Iu^dNptM!m z!l#kX+B( z|8w?~YmwH8_BEsXjB690pAFisY~pvN?)R68Prh6gAi*YnCqh<^r~dYAnfUZv%60u+ zH?fCf;*$gR)b=v*8BBSsmWkhs{T0i?-{djy55xBTd41XU`hnbE_B~CA;~3{^U^uq> z70GSgpB|nk)(Gqm>@hml{Tan&-QRJyb^mi7oWV+*^?8Q^FK4V=2HnONEfpM5$jE8e zQ=`nIn%`oDq4@2IB*^S`1}TAXSaM@=a!eP(ebg9^1^NrQcj-ad4cOu#74*24x z)RmvXA?0)_`ugl^9nHzgFWw1S@|YFh5c=|&JBRUEIuhUnO)Sl>guJpK?dU7o%GMR3 z%Z4B<$}qh5>*j=qm)dD#!9Uj%J*r#0`XLlbti@|w>KW0$my-?aU_jO}T{${Y>04T2PGSZb)~;tu zx1HAG80)%Ys=n4RmmaqJcLpQZV_-5Au{!p)EGmkTHmeb=TXkdDse+^R&>WGRLVGwx zcc}@{^XM)NW?6TX zJ&&*sisBC6!wK9*n23AfU9xW)lODQBx!d@^bknBpH`=#z7!7|y{*6PN(Ki$wPSaTu zI;_xbP~VEu@+59fnZn3#-nVcIFkB>C31q^BWq^5D&v}E2G{DK{s-W>1f~Rae&Imzi zS{I)~V%hV4Agi8+J|MaX|F55DJI~6l{h)#d1GiAHdkbd+bngpf;_QSlPLPSyI<&$O z3}}AQIC*@#<>uVsB=x7{-#AC9{1n-h%Z589y^sK;8wp!@kN|Lmy;(>AWdikhkN{)~ zIYhpZ0Hn9sgJ&dwZV=1|3E*q*;?+Hanl2;XzvF)h2MI7#^1Qu}09;xY1c)>eUR5evycG# zz&Z&Q<&Gug;9VpD9HW1Y1fWq;TMG#=WdD0pG!j4(GrVtt1VBD&G+q$5(op4ZoBKur zFj87)3kg7`-xzmiCeN?FfJ>H;r@bENy1{AtD|N5n0weU5^Aj{e+vPcQg|jnKfC7-9 zC5+sL0+7SCj=T&6q`PS(04ZOB?j0n+P+0i|1klZSCWR=Q9F%Dp;debsvm2$c0g9Er6 z;{c#@IXD2w-opzAz>iA783!O`AR#vnfF_P`(=FEIuLKM%zLDd>07x^8crgGBnxGL2 z1Tcg{IT!$P*Cfsd127goc?VxTt>b_IpdFy!AOKyNSnB}+4Bacy4+!AW8w7AU1_2D+ zhSm-UK(dqL3j~0))u$g2z*xBJ1p<&d>){0gKzKk4Zx8^oBHYn74fa4?;{ii0-T;y& zE`fBWzG_@Dpc(^Uvc*Kq~DzB#%9 zOE<;F@Q|JQog;kt=1iJ+fM}(V2UT>24BBiaCn>uit)del7 z)>(9qk&3+s@&>tcs_0}fX*@%^wa680CWk6Ty2Pof;3U|ZZ_0jGfy)=)GLd`c0BE@Q10o3$EfA{1hJBAle}s4ZiZx96!?JknpsobkfXqXY!nMnOPVHZB_|6i12^bG4he`#qo9P>^pE5L%UM@X z%7dym06QsFbC8~{2uM0KZ?L7k9*{w!4`2{ZnjK$F*eeUSn&mvG6pF4r^F@>8MfP<; z#^x~X(g*YXq)Bf|64(5uRk{Y!Gn`j}3hEm1L{Un_q?1x~p1Lx_)nd|FI1Wl-Q4t{N z61}Wdg+X3K_v8k#&vad)M+$WGfk$+b{=uPWx~{bj<||p7=+1#`rT7fVcGP}4h0aMU zyZ|HWUcR7OQ_#ux^qm(>??!D-QXLLR?rsT1@NS8MXv#f#q&Nq3NqSNJDt6?#dbpHT zt1C<8EmAMYRdyf1K3Z45Nz{Gi13%$PV;VYLXebz(MwYnCujli#3#XIzDXZctMfqZ{&4qD@uf0VoOX>#6(ksylD!Lln50!=oeymQu`Ct6;A+7rFMWgt!A1 ztIdjSe6FieaV%)Hjzg-`I*Yv?!0_+~9%-$n`|Lq@jOk8(Ki5VWvr=M*8*-buN&@vOy%0exS7CPTT=a>$w5O|Y?`(|p0SOh8=inMw6$qz zd9}1(aKX9B31?gL6OTpv@x6@!Y_lyV2lytZdocug+oB@n!M2x*?$_#F>{@5U*UD== zg{Zd0qr#4x9t*d+IZ~k6+K#hj{*6O%jk-8~>lcnoJ$|{rMJ9FY^~HF-<6-`V^ZISS z^pimka{I<;`#QJafv;=%Dreh6u!K<8Ad4fhZmOUxJI0qAL|e^8rT6qg^2|`Suz7Bq zXk0he{(|on`X*pHdc{Z`2nlYLfjjMBYX}zr`!eT=YI%3buxjHw ztE}UsvwxN-oEj1_QHo6=)%rxS)|aU?Y|g)IDde%ep6Jy}Hs~Zg>Acr`NFL9AM_jik z^~a{iv#N=1x+uF<`!U8K8$#x``+0!OwERiRokS8x2oV<=r+Bygx*-3qN*FF%iRD(CvO1DbRoa; za=y&r)cFJ@jcKU6PaECE_bB`1)5(+f+g>?&(MT&(MUG`KwGDA)gqCxq6JA@ zPYu*6`QE3sJTYU_+ZC}mFa4!^x5jUr;4`;4QC*=Hn9HnADY&8vs`xF+swy2{e^1)d zb<36LqMqvR$m|!^T6yHhi&WB*bvkrUx#;1c>H--?m7`onwC~q?y!@(g*rKa%s~+9b zkMY8IW&af^*2Qfvn#jvqUFN)Ot|+J1FC5-dJ*vadoinSS(Kj@YML)}qmsJ*3`qhVx zvW>b^@`0$vC-UIVp>|~%kAJ0dSk1h@k50j1amZLZomkE+^FW>Uf zrH9Ph^VHwVsrGMvO%B%-=I@;Pc^{c%mr08&T0u_kCeSslu8=($Q8&S_T-Qlw4#^W6G(q>e>Xfe*<3N*#d#o;UEqrsWoYqn3flKk(3nC z=5RSHPB>KWWb~!3!_6S9v$T^phfQD2Jkx?~Q zV%~EeV|@?l;(YxxSXu&s4Hh#ExM3lzxj8yx@fs_K@;5(dDu7Ws91h3u^b6;{ql(7= z(EC?k-}slqJ-n*6cYpaG&g-r3{aKyF(k!YbMKFO*Qo3q>T(_tUy(pZA3q}!7h^=ae zC(RiVkGd0M(mv1r;SH6>%nPU=;yQWg#%{g<=C&W2H>$4Kx=#S%^cQfu1d6Dm&q-|5 zxjd-sy~|i7R)0k5)DbSLJ!Dm>4?QmihG5eNb)_)%!4#O*4^&kYtLu5HsLCv5-%|^z zvxOfZx(i`!Qau=ce*GP2k-dw zFs&+g$~T5gu6mcO%qYi*t737!%!wYQKK3wY6%UK*B!v%MD=g!V5xm!U;m+Hcr8aZaBb`@a#DWcef>IWj(eBH%g z3o-@W7U#9V~MaMkC`o8Bkuk|`xfLscz#cVR_MT?^( z_nIKjY;&9Im_9z1{I;Zu@IX^#J{J|497h2t!k*WtL_eXRCZm>I+V4@w!UJ7gMN$=i z9?KxLxMVFn#d`W#Me5DT)ku8PnqPa~ z6Rj^MT~qw!iPRb>PO@bpQ9&vvRy>jTpoCxF^SHu$!LqSpCk{fYO~abjRmC)Oi~@<> zxv!ZUS2ZhK`BL3U+1uyuOyh7g$H`P2xgB77th;ESmA&bpY8C5^uqsEEW!0F&vWx2* z(VACz70|_dY7cRLgZUITgq{<<99rgr1%zl#9o9YA8VKo$V`ZSNq-zXO5zWf3zGvg7 zHj_5r>ttY087-wBHbCrD{t9H4T5)K8KF= z&N`mHHBj>AI;7KBjyANEXpbB}@z6`NKi{4ha@g{PyatYbfId!3XDLpgYP-q$Bif1@ zs#y4Bb(6~!mgFM+SskroT&1Qe7WGB%3f(`a(}reJfwZ?ZeKEWD=ph!rssYlI-*d0X^)J5^){|_h{>^UmaKQ_Y#@!<_Ki*tVOZq5YG!Lu zbQSVt0F-%wr=@vsQg-#GtDsnVV{wK+52B?6;{s{x4l6J2Y=r{Y!=^)32Did$QXrH= z*V(x_7%-X@L@b}HM6MvMI?IKt!_s3P^U-lap1l5^rFGG9K8O|nKv+f4eRl5RJUVzO ziN$VPX+;jYOHbRnS)6l}Nm)_ypY&T0BIT#Y)|!}<5cS?XMaQ6!_n+A|b6ONQ&x z&ygIb*QDCfa%|G1J3`)8YjVW=^~4+xe?ZG3Ej{OIhI+waBi6g{)wsBNm)s@W!~OpjZl)JxU|%*{pRk?yt>U{*$|zC;O80wiYVaU;6tk zTe6o_anqk#um+lPliGB?PsK7vxf`>;PmD=&{ys6LCQr^eF(%ny=fIeJ*~{y|m{i^P z9vG8uYJ9Ehs^I#2<=5b2#(tvchO={EOpZ3c4va}ohgQ5#t^i)yBKzd?C$iNm8=;{(0(?6z_pC>1N5-fidYW@_S%p*hjtx#!cS? zPp%87d)80mDZ_rRE{5l?4jF_q=p z+N;Kd-6z)MuM=Zx!Q0+GF(NH#+!G^1CwIa+G5!!y+Ze^6k9%U|Db?maCq_8v(0yXm zck?|l>UZ<|#F&~-0B40#nW>!O2gg&Ra6oz zv^u`DM0~UzPF^d3vNm^9%F9|AD_t}{XGtU*sCr^(gp%hhKf1k1mEWCqVMt!Lrq*xP zcxe5oL)iBTIsWwp&GN|mH&&;T_?{CNHi*r5C-&s&N{_*_%Q9zP33uSl&VYU?ZaiEBSENX!Y4%T3SB}G7$X+!o8 zJjxE!3k1Lv_EC8hM5j7dGL&4n>8MLgmT-kBQctkv1YB*5pRiImZF4dDyf$?bcMyS!y#6|0k@%ethC8&xnO7ETtEs>_% z-82)`Na60JH7(RE9D7xU&-cae4N3J&zeNW(=cRvYS0w1gVf(((!K$09 zYjXkr9UWAuxEmd;c;&uD2P?3WS9Gv;IRH;|a8(|BMF&*_?M4S7`ztzl=o1~>oE;tH zlkF89qzU;IAFR!wj~yRWCtvYFMyY*^4^jfNev1!o&ehUC#$U&*{nU*Q^6maDK1ij? z@`?}6)0Krjt=ds_%lwKDGUV|UA5?d4d~lODK6p4QKF9}vA@BHLB?J3ge2^b)ulOKs zDzErpZELBX_#lGwyyAn%Rl4y(4e7V|;2xU0@%IvWtIi48+blJ>%6lKC#8z(a2ZC_GNFyqw zWp5BDFE6u}*H1*(-fvl@!ll=e=%kI9f@^KP5v1wBw(t{FQCbFvGUqq#kyS!<##-c%q{>P2y; zJ@v|15K7cZ8r?%^GU8`^{nbH9&8BCsdINAxRK3uhMKoNXY0DWooSeN5-S;8*ha@iX z>`JbCY4pu`4WDwj-< z95m63t{b;Cp3A7@N7;0fk@;#=b!JR8U5&4*3;Pr(l_Z1~r|{KFl!(&1BJ|p&)2f4{ zad`~!QYnMJ3`x-c9@gZ^8jqhRieyt*rQS6$`Alb^z)?`n$+Ctg_ z)h&*uJUXk#oJp_mfPK}JR~!0uA-IF8Y>6Q^h`M4Crjl!*Dpaxol6KddQNbLc85`sq zqqbF#UD?TeYjgoBPL6XLMK6ihCb#KpwI5EkeX9A;E~bJp{3L_5_AtHh*nFh$oO%#! zZR!q!{@9KKUtkT%bQCd$#FW{1?NDtj$jjNG_Q>BI>c?DomG;;@c4w7t&TCEP{C#;( zPBY4CuTnA(uHDtixe0H>OSPBMHN1LRCx~TvQH!aRx8>D!7v{CRsH_yywY++L-ey-f z^kSP`x^X;Qv+K~u?An}dcBzt6zGhd~jgc?AtLyl3?Jjk)T)T^EKcT$suC6oR+wR(& zYj^z^e=VB*)U~_#b}VnZt2-s(*j==S0bF($;~m~+mr5IzYj&wO@t9qkyk^(oEVGLb zjCRc~UB6!5W|w|5U$d(lK6A`2iY4XpHoFj;+^^ZyeRt%MY7J?8OZ6U_E7d;+Ye{u2 zwu#fa(};?S^C3!h&*52!L=GnD?E^F81S2@73W58bej&9~Rz3g1x$jWbvHU~7+&KFi z|8g!;>-_RRoY!05db91%Xt2m}#J9(|u75~cT1ldApAIrn`%-BmReo$`P-k@9ph~=P7}Ijw2pU7}pWs zR?fh7#OrtC+YwJe^!5ss(UX#oqg^xpO+tWfTxgeus$Wlh^^IsRPrPm!Xx9_Z@P~3e z@jtp{$A?OM_cwHlBHzL}F6>rIE4Hz)TPj^1-rz0DN~dwbTWv=>*LrJs`09H_u0!X2 zBDAGEgx%tln#&uz)k0EaX~VagT~!;tb;twX+MEsF;sZ~*@U3RM`~}~l_PFMF!MB>q zfnN9)g|2gb!?$R4-RLbUV@voKdW*{0itrrt7FFSi6>RiYb9sb=-cmL0{zh+UsOv>< zwPZ2e=q)Bsn);x(#3>iOCAwbp){9=~t-~>Ti=yJAUi6lvp}x^u$U_Ymz(pg=I5FME zDdB{8)rr-}{r9*c#KLbeC^@_VTpGA|09=SlDi^@TIJfo&a7i}a_$_AgX&1i*-OI&q zF|#AS@LO%=AO=fDcRtYqZ_%Fm#%`$x`C_+PELSm80{;zaphEr&bE^va=>oS@(|x>w zTU7q<^#Zq=Zsohct(F|2y1*^!`qvYN4V3+l7r3Qc0MZ+{1*cuymdJ5&TZcZlt|%|=_=YHllg34DK|krDwtgrwDe}EO zE^2GtU~soJPG#}JwoqNGs|&V;@~Yt?x0ro4ppD!@fJ1vDwTT-z3jofN6T-X+!DD8r>Sfe$)VOuQY`t6Bs zO!R_nA=d)T9@v)jLOrl8M!M$<+d{FF{)TNy_REEBo!MHjtwSH!){ptzen=-^UpxA6 z4s5HbXxD{pHBOH0wf__^lGhGJXy?5{l?6avu&uT-<}Yju$C<`-!M1R$2_(J{K24@y5h_zhUmYjTYKYJNGh24KpshyzP2lG`k=NpXQQ_Cg>+F{{6-&d)E2E+faba#tMAid>nbgD zPK%AzneS=w(C4(cIs3GzFN}Ly1Q>&0j0b6kXz?`g3KF>_CgDhB@z zw?zT@-tK9U3iQu=aSb_{-pfx#AKp)_>0hTs`7P7yxYz~ZTW3WC@)`H6_(MQ#VsOBF z9~F6MT+VVZqe1skQJ*dMsE8|j<$0~6BF&2RwLZtfRQV{V`F?}?D7`=G{d*r9V5FlW zBN^-asK{8ql6>ey?f0bky;Ey-0ywyyqraDP0a}C>R*|V6oD10^95K>`Z1rVNZOB$9 zW-#86E#EkCAzM8<$!SYB_szadZhV^YZb^MvDjTxZ(^(A*vc(hOjo9J~Jzm6CkIm|9 z;j#G1nBIu3u4vf%3Fmig#1_2@7qHcJ$?*kj^?1Ao0&GEt^agAxs*^8Z3p$ny*gEtE zY;DHf6@Sd&*N<9SCHwbqNEgLInD16+Xnf;nA#YBsP78rY@cPD8rZ+qEa*>(H&|QaIZ0qz%ix|L>*A5KQg4|BVZP4TA+TZWg!sI zRHta?`R}E(*YRZpl{wc3C|ldR>VoShhJpigB9q@JcA%>Qq1!~f2ct_ZmbD9neLWs@ zK|P6`&+25BJuLkg0qp3+To#flR>uM<@4_wZu?9Cm$Dh6iR>!e*O?w0oCTm`|fM{lP zZuNX>?#8A6{4?V!b;!Nua;tH#g$hmZo-9^#)|~4+WsZJW-{~$NR_*eEc73txC>i5{ z^TU17W~G|k5(({gtID-xLV*Bmuj=7ZC?Tut?KHL8(Eu0fdcqZ*Dsq6u2)gB zQG?BQkWRW79T8RdI#v~NI5cm_d2t^|+8LnH1Pmc2joT^gFk*ku4%;S(R>o;)(jIOIo^+wQK zsMbDDWMKfJT;&Wzmb%-t`k{8dp5OuqePKx4vreDTVTpTw^pjj^CSgHt$5wAiR%;L{ zJRI@h1BO+8nS)(Ifmp4Nq!WUc=(8luZ7#)aq;PzDX?X%+S!;Og=|u8W;LnRb%ZMVU4#0#!76^qUKUV%5Q)VX>=O46I8P84G>@^Nf04wY+FSm5FauxfaneNz+4(@9zC5BZaC%{@z}6BX@XhFXBk+P>64>2CFSF zI6oDeDm?84(=ig#R(67ixc0b&Ig5Ox>A5(fS}VBtB)SYy!wT2dz{Psr%rSr@C)$n5 zDpGDmV9sM*rNS+!A{G8a(quxXvz;Uzn9*HhbUz_o6lKU>I{3VE7;U)RmUK~(dej^y zneWVpuP9QRbY!*AYe9OfqJA)QBhI1q!t&#vC%mWXEV;%_o~b5})KU|2F?IoPysfy6 zO%_B+?qpD@Z@rOh7e!qfb7w2BZFSQ|?ELv>KG%-cJie-Pm^H~nTD-dmK@qDnoKzoA z8f88k*9NBEs3PJf`5~O<-yT?dWYn!%5vXUi{p1T7BA2V%Vd`Rjx?0^^T9e&bhj+AV zqjAyEdq``y3%2X}!9x=SavjFaL63HKtY)jdpB$7-c)V`>)-N22nz_uGz^$qvs_pW{ zdA;Rv{+ILqb-(osM<<}~oM#z7jJ3@>nZM4llKnTvo(vy|rvNoS(bjdFvhSL2szBV= zM%s#}r>UN(<~N#7vN!a)2|Z3k@b%ZOot{IPB=@_3xuzO`hv79kgrkkzdCUwGq;tVX zZaG%aW9UMFNOaz=J{?I2_sho4y1(=fAI*-eU;<~J2wP5VH;rZ1U&Cq$`FNiIkl-&A zZRfr2g`buI&;_)hQ4~cKHoZz4Q8e$6efcR52NOd^NmnkL%G$|r>M97S&E9q21l&m4 z#lWVzjp?-w4z4kIZwnc>Q&`VSN z`R~o)9w*cF?gXN}6$BU0r^cWskP^L3dODWQp?9Bf4wUqNL#+z6T5k z9CfBOq5aT$V^~$KCyod-T|^u~Ff3K?>t-}q&yq5A#8@6c(rYqw7GI*Qyb&6$XCDCQgxpF%Qvw&FIA?f{=W>hq%KBLXOaT4QIWOq z5?QLn=5Ios6rFoLA=in_KWZ8i5*}VA-BpYg^o`;K)+XWBChIRs8)PL^Vf_W0=1sT$ zYWyBP4b7%w%t~zQ95$LnUN0nT>?+5)Xz&A6-NlkSG~T_w-w?v!*kJ^&!>=5|MYVt9 z827jPij`T@>O04=v5hrxtW}x^M>TQwF(fLEe2?5~cv%>1HOwWE%Ey*4cc?`LHq)Vb zBc6kcp8&mXY2%tY&2U@N*47)@1E_4%C`61;Tf-kPEyt}VWN}_&^IiCUy6@(X3EBUD z?Y{f@)ZbqmasN8&_FMmQ-tN2baW72y-ir3K6+fQ(`^)!!`OSSn%0Ha%t)Ma_15&FJ z33cY-TG6TBF_VAPh14!I&QpIc2Mc~-8%NidE(eu`URfNY7=!4P7JLpBn)C9i1oj!0 zd(NL5e}t1N#~rX&9-GRH_5})a>GyGjMmw30J|vdN=vSrg1n$ni*#e;K9Z zi>k!#w9OrAc$EDVRcciurHn1;+6CY2@{=rDz&Gl*ZN}GOtQq?HXU?20=7*@pUObIv z0NY>Ldc$Yl%VA4=?lYRzWI8TbC8kgGg^sH;O(Pm)8$H$IwF51WP6Ltf!2$)~9gdol zCR6cI0E#lJx;gyNQP(OgAf`A;7Z~Xa%$ngY`pNDKh@J%=VZY^tCQYkW<4q9kJFHGM z(PM>kALXj5D6WjaM<&o7I}KDga%VML^KV{0rMK}ABoj0n-)AKCe&>}!<`w027PP493qh{PKTeS9 zKC%q`L_U6h=Ra*a%Q>(x6u!%0zOk~wTzX#67o#pz{(eeJ*uNp4YgdX5jd(2pYRq_v ztn4#`=3y8&;!(pDY{-}Z0a}F5g2AZB70Wc&g~(Ke?qm}&DyN8bUfRMD%2-5BhY@Q6 zKS~Poi_E$>V}YK;slHp1?Tg(OWh4Y0Iz-AUZ_r-VVG(zLw=MZJDHYn(rlcxwXumcr zgm~VvG$s+6z&U%-p`;5GTpaV<72J zKZlS;Njdo1OyYVY`&WZ66qHpJB{E*SvtLMrvh+OKSuzpVRd!4dA_O-0S;!+iM)4rC zOWfO0s0(i6qSbSw9-b{Wj%eS4-l!T|Rq+-Usrjm+rW@HWt+T+wt@tjZ&+@DZ*Ix7Z z!tv(nIJ#0`q5V|YKmixs`ioF?oAXhQuEAhlwMhGa6@Pv^jYiIM+8b}$Au(*>Eea#Rsh4=wyfN@M@_{Nak_{Q75=WV zEi$(Gq1Gf{O|?p+vp&$^p@Ru<+&G4R2W8q<}8+ah|_dB{jJ?z7DJ9GwSD` zWSOYRer|vsI^D)k-SRS@kC$w^ICa6RY_AOY5CMZ)&*>ULuw}u<=V&LnR4Rb6)^S>n zbgFdQlcUs^O>c0|csUL`w3}3CcD436 zB4^H*IlfeB;X&JaC#>Xx=0f<-P`2?OW8fr(GNzPeO|!_hk)XHbC^4-U?BTsn4Ey%F z5>GX;NDq#td|*z+TeERdOXgOL@4K`uY)rCwH6IB!5xN~Xpdn<`{-1?iNp>u|j+?(# zcm?-_nozThT7w7w4Se@MtpGq$%uLs>nMFrNqn;2*ES-cfY??PEFpbJ9Hajk@_!tue zv?e)dm}ahSErto&%KWlh4G>o}ZCL@z-KxBq-I zj4kau%HIk|W|jIC*OYj`r0xg9S-Gjbo#D(-TUCJZlR9TG^w_#jxoAn_FU-;zF6qI# zs%wt~SM^m!%{98*Aq+kd?QK5u4n+la*3eDgd zH##G0e&~J5P?__7_uzW876qpOApeMCv~+FE2Y=3kycpAkk5u zjAmc<2<`Z;+XAfBlQ0t!Y`%2(>JuG4fNn!fh4{iU^A+olc2Dk*W7++};8GaoxMl*vG!G_ruIf?LZ92vnacAp(5LXzsP+p@LDLMDb~YcUZ0!vbdQ zP_!gi0OL1H`V~oFzgg_*=~tf?Mk~BN{lk)e_4-}rXcf{6AlcRwj8>`S1JSNEL~n<0 zu&C|3xc7o9A=U3&WwOE~pl9Jx%#%WGUwSA-fNQT3+=Um4abV?dLp;j40`M~59@(9@ z!r3TOKRr$cm@HOpZ2TAlNl5)mqI)fsmq$*xWneMmFK$9!Ab{7~g8k@sQzDXYb&1Z= zvq&JD|3j#2;YdUxIB;o&ImS^Eu8Bz z!eXI{S>5UJ6_4VV|{6*>IVfuPEFxP`15T zfLvv9)d-rxl7pay=J9Z*+OBA~-0QTQgFeL+U*xI&HA|7Y_*S45rN@=gM5)S9Z;m!G zqcIfS8aX?KdGS!@Iy1!?_A={1{I_$(&94N#pN)8tp%2})ZJzhVm^#X~E1H<}J@zPW zj4l$>{TseNzRJd2BUFal;H-p$Zs|sYM~57A%m`3;99y)FSC5h|JbWzqZSyk#Y>59q*1tc^q%nF?e zyg1t$R8c(oFxQ=#b2QTLead%u=jBR33cYqOX0cV`Ha?3>fwb;0k~b zv<<~W??sS^4bw*P@iH#MqXJH^F$)b8X%bab7l32V=E1Fg9Ly-CJQjP?q_Oa^U>UG!y-c$K#e3rPS*KIF~1(i}A zO)q+>d=2Y%s1tC){59Ev-J)|yX+!^5964634#>Nq5P%X=*R^yA)}3DxQZ`^u{VO&j zP3)A8V@?bG%z7-jg99t5<{Ap+yc+~mPKFzr;{Ns7xM|GJF%;_Pj1T= zrAes}D&`We1Fa}e6G{x6Cz45D>s&Exw(C65Ro*SlZaeaFaSqm&fPs89_X00(-hjW5 z1tDxo-Njg1uIHj2@X+axMf{E_YB@NGO>VScK3mFW*Us%McGD&tzk)<;-GQ4pU{6)M zKZ|5G%h{WI1ASVefiUKVXl-C0+D^tT5FauS04GAX)ESj@jvcDmsmo+aCCYgd8Agkw z{gx6Bdf5S&bivZ*rvt*d)hEy#%%fv?i?%XYz=s8%@rv7ncC5UZ*UPKpwprCM8K!9L z#QXS+q3P(p16^rq!Xl!QC!4S-51-LqCdFynrMN;Qd)$G|Ic>KL1Ymp5Y}%4pz^AJE zdCU3r-V`2dq@(WR^DyFOXP<}OV>{CfJobAWp9di{b!MLjcisE=JU|V~S&f+`i)|Kz zYDq-pTtPbR@p<4>qk4|dGj*C7J`dgSc6^>FhtJ~{_jzy!<<*qWgW$dKm0X@hX(jh~ zmQ-6~(5zznzZh2d%)EzWKDhN29?w!5isbR2YVUD89#lTF-kQ^c@@(1Z0eAqQ@;E)T z%;WSBUTDYZS;{YyoSsGO*)R$e79TAz-zS?v0S?nY_2|pY|pmk{2JB!$$9G8-DPFuEjb1Fmx{J0lzVH-md!l z3)kisK92qB)AAbT7s{=xD`ZYQj{j4+l@nHC=(y$ZaatLfk3$P%wSu7oy&7G>e3B3r zx%BViBAq%nup?@Tbc(`**b-`&G#zPM!uLj22Tz=fv_>iZgY)J|O_5gq=qPxb8e1dy z!~%f#sSB0su zz5H!LNGmKq$8y*43dhzBRK@NJr%JW!>m@;o01wdpuj zoxXt(NvXNYuyo+ZopK^xuD$^b3*x({+H8s)Q(bpw+1a`27}Tx<{lx_K5}48X{Fu^{ z!HF?=Cd+<6<|s)7)Hy;nmm=;1)f~$3M(?BNIyKABM{T``x2Cz)Eobv;5~;sfhSFpF zgw*OUmh>x0w*F!{^Sb})(*ieK*$(6BAC~m1*YA1}ai#xt?a2L|loM;7SwnjQyI4xTYPQiMXCCB;txYa4k0xSL`A+22I12{w-z! zX|xhcnW?yVDEjRhuG||?i&RM{xtojokL<&kh--K`CgK|Fn5np?h0bJL&lS>fL)l~|)qF5wMy0z*|=8XCdAy>EjgpezC zfTej=3z)k3p%!3vkOLEPrROXSUeL~pC^)X;YQ^u6aXtUv?ss>Iv?{h4sDkiUlW}DS z(^oK61KvpLt1o>ttGHtI1yT2?xVq&hR9uNo-67&i52%HPYuYuKhARNqHG62ddY^C+ z*W5>>;+n3w6t{9Q*vw^I(Y{@$dnV(`od^22$++Sj$vJuZt``|s)F4u9g^VjkT&EtD zWLzBpm5OV^KTX9o@J~~5J)=!3u6aC4#r0ev6<3aEbQV)_EhKrFE~}axdlnaIB~nyV z`DPTz_dmyAaJZ?sqEmAAHWgPm)dpsoiYr_h+h#k-g!VwI1KP`Vm2u7!yiTFAJf+%8k|6nKLCRn)?}tP_$x;c|wUbxJ#H zP}={SMk}$Kr0QyTs{cTED)YvhiYuoK>eETZ6`l5Sl}2{JI_H;*xUz$e6)LV?{tg+} zbVXAvIMR4e*Kx(|Z`XabeJ?!a6+*5UN8D_gkSoEB8g0FWt|F4~Cxl!%_WB({u7&Dd zEreV-Q;IQWO0Muz5X9n5!>$A?6y(n~AvwNbNv29e` zg30F&Emtgdm-J%|bk-i=JG5L;HI*})v|Ks4@|n_d_40RUxuz?&Ae!lF(#+$CXM_wf zJrGXNnpTu%0P*Y;>ywx(zGL?ANO<~GrKAy!)fu06%5nVh)|@Y5u4#82mdTj9pAd6J z*WotE#9U)BGJh^DS0?6qu8^23pF*u#iMjF+vTt`EtWqy(4NAN7yHqPrZ!{>Z44hCEU>0QPm1^?TL`Y>G*K&1S<2$rmF&|*=bS+m*AO!eKbrTa# zEz6x_k<*`j@BQUku4fXHm}{Qqq~@BgP`U_AlyuG7?T6u)`Aw2@+Cimn8pg$@Ko!`M!y=z3aKimtvrH9^<2 zeKkGT^M4+)VehM=O>`i++4UlQI9O?7t$4$G+^M{nJ@Px`T#2;1KJFGsxbzD~YH)e< zCb)(7+tyTauCZvFo@-jxP0;mRAw^gAtgC;yqAUF$G4H%@L8FH+VHJ(DU#>i_P4S}W zn%qZIbWQG~DY}OHC`H%s9!=3Td5@;(8s4LcdY-{8Mb|w1rRaLDxa~aOyhl@XJ>H`U zx`y{?a;@P$MmhXPx3~jog0A5}nxJcP4y5QB{-YFK&#;rEYaW=?bUhbH)HS?E6Ln4A zqp7-v_h_1};XQi!c#p|K@6l9U&-yA=*W^A*)irsKrs^8rqp7-v_h_oF$$K!VrHHMx%_>6+X}lXP|W(G*?X zeKbMWlvdGbPeaw6kT%<8HRnw73EJm-lJ){ChyTSUBi1cP1o=q-#+U_(>1TS zW;y2qrr`RE1z%%uqcmMH@AK^2G+m2jYIjXn?!mQLGEG-5EgU0?vOQf~qON%iNYyp2 zFj-fojpBy$ib0{{UQ>0YH=<@URabIHr5r1^!q9~6s;*xC4prB5#VrQPmOzQAx)R81 z_L|IRN`?ttgI)auf~ojT*Oe2x`F+xL<@7<+Te7Wm9Hk7a@~yOi-y!Up7s%I!3}M%L z0gvekh!0CZo%OP?pIg@*$;oF&oSLUvfh^%rwp z`2VkMdE6>f@IK|CI7YbNjHkbLQ?T;TD_#52w{7|@PYsFIk3&#y#vjXMnCxK0F^dSD z!Rao)#mn8&Tpr6}_>69#Ah1b%e{C_qhwaFohf{(A;5Yzyz9d4^AU1Y0EK_lgjCr%~ z=BVH?3o|rcWb}H_9xLijL4B-9RCQb+=?9+6Fkxe%Lyj{RrSxTEHTAH`D=PCUdAutd z7x9wVUMa~D?y+@l(3CE+6ouusn{pCQc`zn~{5;fhA>{}ku87FT!klZ2&*l+Ip?ig@ z=$CyM-onbPimnLnxPoCOxItkTAdZJcu=9*(apyA@e%(4xZKJ5`hfgO`^fP9ImXjw+F?WxognoFfC>-Gn^?13;n%bEXqUWmWq{qv^YYnWKi~WgjlhELHv##Ay$#6 z;s~*lAvx0#V&xJVCy151;5$wbS!O@=Bg9IlE=~|Drhdx`z<%pRKSKCNJ}O4Ncts@y!xm7#T+iH9(5rfoJDW@lxqBmP2`RF5EN|7yXn7&;gh zoHk#4j-@f^bjtWGx5Zyh`HN16`{J4zs7`luWDIMiFa0 zuduBoc7KfNN8LueBYvQa^Bz6P#%VKJl+8C!`TM=exq{#zb*sN3E5%>6dZ}Syt5d(q zEqt&pm`qFLIp+}Fqb6LI2X!%iq8hHwgd&`8Hjz#atEPb_83HCj?bz zBiJ~$8^NC6gkI^PjEszhCC(}6wYKq_C3szx=WgpaOZwGarNH}P2{3m0%l$>`>S>gg8TcR=;0>`;AJ465fHb|Ce9LS}mL6&z{5 z_)0s6d-5YnPcS7vv*jz0`?dvEUy?Md^Y{#;K=*4!dBN4sWkd|MSY6ZyEx}E36ciKJi zy!0I_cwTC_Gg(*V5X+M{v)`l(jLT#+FV_6s63wd;H3^nit(LUISYDO>LQO2MTJ0cs z(~T>N+BS|C%WEc%SB1-H*)%#mn<^;<<9MC2bG*V59Is;$$BShytKxXE+-Kr=(K2>$ zya<1k9vm;0*CCL5J!HxT=d0PA<5jiY3Xa$NbjIo22TE|f)BtH=V_zOY@~UueOHCv% z4%Wo;Vjt*1^I})N56erVKS*Bew>vmqEcTK(Ug~l+I9@D|862-uc8=Gvh~uT%rv%4K zbL>hSFTSJEjll6zH!i{8;&9zFalAOBua_&t@Gy=SyLB&#`!bE8te|V0YEp zEzZH&U2KigoZTg4um!t|t!Je7?T?VB1$}`cG+7)2@jQuDb%P1NyI#&9>6lILu#k!~?k-JzOYX!MWpRt47b;?fe z3X74ubcY$_E)a1Rh*ND2_{dkQibICBT@$IW@nC{zS<$TFCOVGJ^8o|JW z4@(fdYCBpqRMbOMQQJZAs^EiGhL(8TZ3clE^Y;+IEaX4VLPS9Lyp@Vj*Svx48n^1XxK73JV}g(WSKukC07;{W-lu1$i_e^-#W(v>(_ z0?PY0EM-mi$<`A4_`{M!VC`3*7QZtWaKAS^hdR>Jl4gZjkb7rNV%K{x@9U=}|4MK4 zX(>2PmC95+{nJuR&gb8Mp0>S!B5w5Io%}{mv}uX>b*uIqlPue)V?e-z?AbTPK&QP@i@1`Le))m8fC^YgwBVCcZru z|JBdOeE^_9U%!5{oTp(*olKYImeYs)-pPUh$=d%P%TVqDAYmil=H1}W{`q*D-z@(| z&HA&RcfJ-$Qt9cxS$Otx9`CpLFvM^Ejb3z~^@|wuFBafD`PP1$4@3NhlZHvHJpXM@ zrPtCB7Otr3yO&E`y%~Hr|IC*}%s&n1CrCG6f3w77_Wmw>)8|ejAAu-2}pY)SRBc0FaqkH^~eSZ;Y+TDzXI>8NRCddhDpN*~L%)Qfh-D1J|@ zT~E1r&Qq>kx*)GzkLB`cO{`tK<#njXPg$8KW9{N=DUGXNar^4ln}1kKix)qAp2dsh z>nvWZs*x8jS}eH<7B5yWPo1=QML8C)u%y;~ZAfd~WtfHI*^fn;V-3%K%1x0OT{DAk z^c>HA7I)>)Gd%k#Pvv@)Gw_t}KRI&wG1Pnn^;Ef?K?u)&%60?Cvmc8#yoP5#<*w)v z;n`7kJo^}gXY&SS1fI>ZWpWgr{aCaoF+7_uVX#($!NAJdIy~Sl)I-W>$t&ER-b^gWjSy*%Ol|IRJ@B{J_62W zu>_p0Ua$|I&2BIcp3T>r$K_=&xK6+mKiTpQ#TBvn2A<6-xig;4YO~1cu~elV!BhCn zVo4l4J32<-*=)yp@NAa%!L!+pSH`p1kmcane9Ck@o9{F;o~`egfoH4fdYW{g2-{w! zB^-XG3sxXJo5LSb0~yb5*II#QYc)G)b_2hi(gu!Z({j!-8@T7~;Mpu&YC7TBw5%3* zHp?E~c8yeaJUc9bXCI63?5A8k(=xUkEZ2-@)6!Sq*(~paXE#u)bI3BP!Be{W90q^8 zI-Jd7IdJy-Z1&A%-3Cg)*{c5oXR9k8IGYW+Gn~!QI(xv`>;eou6`swm+zy_tj=TfV zW=9?e(Pp`3L|dKiAlfYVgJ_?!BihFzM4R`#4x+7Db|yrdZ&?nat&SXUHOK2bA%QH`Uc9uN$R6HheQNAA zjaNg3zQk}g{K<$_hxr;|@e{+@P|1d;1LkXLlmzp&;vm0ZzQ!f}1aUs)>oth;nVc+g z*RN=C00j*0846n+%wWF9Fme!QLp)Kb0rQ=*!+c>em``^&L7aL-4$;#~oG4Dcu|?x%-2m9bjxHRkgpNDJ_#VcRka7>W8Lo-7+;hFldB|zkKHB3aI)TP zMxtx=+DAF{7Hah+gs*9JNC+P-Cx%mZZI1Bip*e=L6*~|xh_9hD_Cpp@d%ty%nPWIv zQzwR#RcS7OAU;;M=W(xFm7iib-#_bHV{}}vF`QvZlLB_3zZi~_6htR;lDI0XYD#Lvp{oBVJC*6AWKVdsh8Wcek2lXYo(7P?5<6CM}I%g04>OPZr!8_`@O zllJ_tsTSo;XED^U1U2{Zz-~ptCCeg`ZI);2e>uSyWL^4wwI;GIy~);ttV{0`2)mJW z>7N4L46-iWWb%)z?V^Xm#*C~>ANVSXtV_$|6spByUXh9Ks?H-UkRyeOEuym38oQEY>)Lk?N^ zD)$VgE^EA$#MBiqF@mY9k7>cwJ!NO=9*dZ|yaOYn#MEW^nu)2ar{2NTGZNr=PjjK9Cb$VQ%&m~#Wm1paqZbk6pBEG=VX=|WgVNS= zMfqE9tSD-ewp&GV^q-F`{shyphCbqtI?Fyv*X%4T zPeYyHlPfB{7)XQ9(6n&Vi(E_5BIRHeT#(8EGm0X0{ffERow~yGG?o?8sg0ljKz-M> zt$8%}Ax0{SoqD$hurS`?c~|RzJmM?vJX^&1g$a?@PX%9W14q~8$#6BBEOL<;_qPnp zQe+ZR?zCpDr>SrI$REnT>);v=t`u$}42Faw+l+%d#_=|7k9rZh!DG5W(*+&h*8DY)+Mc`lqStKN zS>SwfDLuwbU#Q;tRO&H2#hT;^aXn|}^MB-|?+Vewo~@YtAH>D0wJr%qcqO_lmn21z z7XedAlqW?^_ybvxgjz#?X$pTjA@)~=={Gn8t|Fg>ON{0MbViX4+z-++4|7ijM>@b$PVH8!Jwgm{pee0ugghA~j1C()!f2||Wu$ap)f}8+(+;wQ9 zIyzs=!t;>@qI(lA1&nPr`tuJq2U*BFrH5ah%E84BRPiS2a}0Ip6@@QJ8+{z#<%% zP57vAZ-Gw4aU=dBnrUidPH`e_hXC&rT9MdiErz2^<&x<(G$l>PG%T2Efj`|N4b_`j zj`Lu?r5PVr3@IlQC90}U^c|o`JG^DnvA+oZ4T+RjgqB!&O4+vCXACJPS7ogEk>#?G z#$`{fx4Kp_&Fd%PYYCJqIQZyhjHZmYEAW}X)4P|a*Z(?c< zGdLhHAa7!7JUlN`bz*dRaAhw>Z*pxfOl59obZ8(lHZeFhFGgu>bY*fcMr>hpWkh9T zZ)9aJPGN0jFG+1QFHK=|a%p&5F(5D?Fd#7?Eiy15Eio`%FH&W5Z*_8GWpg|{FHmxC zV^d{xTQ5*VMqMvOcyvcobYXO5ATu{0Fd$MsJ}*>xaAhx8Phx6iV{|V zGBY?ZATu*II9)GBZ*px^d2nSQF+M(XbaG{3Z4C-|oPGUEk|nziEr|8cD6(CR5I^8= z5Nb#oLYnlR$}$^O)zI|CwH63+N2EQwW;YKIbl*-A1o21u$|aTAe=`;YzC|M@@mfBt{}%QKa)x_&MDs=fWPHotNoze-tOY5w{@|KI=p zfBv`s>X-H2=CA+Xf90#^nt%P@_oM&&_ecN!S4yj2c^t%_K-98dVZfYceq!RG|JQ%` z< z1N-X%*S#M86ZI?YpQ!oEu&kKo+z-~h%3Ou=H3G!=lE1ng#Gi}cTL1aB_J98SpU)%h ztJK2%*l(SI;NtHOT!Go}UV}_{Wlnt4C#JRcWEFk)-oTBR8}EycP1xhw>JPkUx7WiT zAjbBlnMSnzhP?@9_(|JenYq?u?~d>9;C7^3^-Yc7Y=aBMtt(xF_opQzrh%|PPGu18 zEo&itvjIOV>6kx17U~aZIj=mwQva3vCbqp3e*?3>Z+{ri%i2e0%zt3=?0dmFF?*ur zC*pmk<-OYfz?|Q{Z~1|k`D;J-@ykCj&qJSc@`=u}8Pu;la2z@(I`@HC#FVaA?av=| zKREdOn(ZqCw6BI=z$@@W`~Nf6cq7tgR2!4O(mr~5jj;~`e>m@b+i=~x88Dvc>#MvY zdIRO*4Gq7%I>`t>S?ACb=}VuK@rSk9jC45J<;)w*guv#-(VSF#X{|0XkFv?!fu9u zZx{vNu$SIFk1)M*twuVF4SL&0 zPV?N1uW@ZlKf8m!Z~j;DoBP3i$hiOePSJMGfVmFsYnFF}6ToKndIR}o?tK$TKO|EQ zi7l-hcBgMngI)VZroT6b<22 zZLo5YpL4nPjkcb1xx@l+vJ)0(HC*U8`+fKm6?Yv^Di6m#3n1~m)h)g7;s)>uVfNN` z^ARA!Q8sJmZ&a?|Uif;RFl{p!P|;UpQg{O$uC)(G;Tfq-r)J?Q-jP(USbqSReQef{pyL?u`MUHBFWLPg z#RSjAquYy4K}p=r&0%VR)Ush5>V4c3CF3nRk!wq$I4iLp8G{(|oXv>49|Rol{mw!W z?US$lrtGT2;@6(DI&en6=0wO-ms)CKWSs2g2+en0d}!dX6j3g&B;Hj^WCAf@fVudQ zPddSy35ruK64vHJt(pjJ`nBn7Xj7gMk$B5*I7x8Ivs@TrL!0LbV)l7FvKpgOI0OZP+p!9bN{;D(6w;W_!He1YV!zu3mCMx z3RDPu;t(ZPPO@_`IKJ|-8n{C&7~5W@GRp<`rsfh{EB5k_?y{{frAs$|AI#PhHroW< z7=#1T&7g_|ZL>a?Rn-xR%ZlpESnmjkANrLhU4RqSEz1XzR&&d73x}vos9jhbU5{nx zz>Lk~v{=PdSEtMq4Fd<#lZ z4h34wY}$|lJsQ7i<|1VmVhDKI`3+*ON>kF-zNP+s!@P{*lPILbR*7rAo_`FT`y-r~^M-vNzm8ZVex zi{$TbU3Be~wZEYAn|+n{7gDnP+y)m&HwpLlXpS2*kB~0Sabu`MxaPP)SL>uXZn)|I z9@TMUaE*uRSQ13C{G91wWc<&m?@K#=Mr=lwSE!B~uDEos>bNn9jNEm{O^Prv9Mv(v zqd6XgD~@`+h2p3m=#NIgPoT0P#gU%~B`wa}oPM3NC%kp*aQ|n&XQpdglby#*MncG9Sfpf3-=4K8oYUG^(?%IBKaa6vqt@DT1yz za^k$-q&e<95t3CFWIwzi z$DzQM@QFn`0<;fp8{W~Rk1UYn-YYROach3XS^@JN#);e!l^4Q>Q#upVZ`ADHnR#`A zndPdbaGOFm{w6KdWalCcU@8x1t5pM%sEz7D!24UzQl!K7&h7ZQi89{(`XB%0YSaop z+y?8@ZSZZ(-=C)be|Q7@nV*=)KalCvfCIy*X1M)%OHpZTp8M$^$heS?b3j1&0rI9+ zKL22HI-USvHcV|7aD!&pGF$?L6L0#B8L)3R*t;eMED#`E0kk8ut*kUzekV1Wo@1?73Z#<{j>3j*-~>Lw4HK^;G%1=OmxCi zh9gV_Y;!MWtwsB7@-=|@aq2ja8(vh{hyiEW+p)T7vA`6!ctks9zXER_{3#^hU$yAVX99D z{{3Tlb+TK*H1{TL&2Vq$Uh@XQ75+dF$lwZZ49-k}u7&wSsW0%afKuR-!5=rXoLXSW zwctMBnV?o3XTTV-;m-5oFrQdlj~LN#eFGfem|N543pP6#RU{n`k!(Jpfb!wX*1#cYk27%OGiHNG}bqHW4C; z{lG@8kxw|LQ{LtqAnzEY7Q%&sAG}oZsWiy!oo-A>vzuLTT^iUfwtLgU2(KvjP7d3> zo(tLH8wwQuwyze<8;Y9_M~Asf&NnPPjKDe@mA?q7 zzVfhHT8BKKF~U7qCP{dI|7bdaA`t0`AVscAqlCoscHWWbvjop35n{>YAfy4Z$-m|x z7ou`E?|`gBzF)wVG~F}sK&E;2zsmocjN3W6z5C7i1tF9A{yWBaY4dr`GS{ge;NBMc zdihCNKezIYbHWqQ>*Tz`x_}-kw!rrW^h0HqhhRYLIqa2BEWe8?XGtdj zZz5QixjCfzt@rs!>{ZTSIYinP!NDrapuOzEjbRCVz%kf%?swHqvrpR)J#1dFwThxi zZ^?yHT&L}j8wLoe(B^NB`D?vCg@vb6j+ z?Xc-Oc5;`3&ik2?!gS)(_4=Le=mG^!XLcn?36nY#cC1pQ-7r^YAKT(D#r;}4g?Rp~ zuKm5IoitCY6Io5EzGYz14)Y26RG$$^GV72#4y#whj7l4aRvB1=Q^55dxth)P9}kO99hksM)T~e zhee|888(swVtnpe&KO{n2O+f5l98*#TDVmFi9#NUvWjk$}E;9MA*g|94Pvx#O+Cp0>M|4fd#y2 zUE>Agd^MV{HE$5WDE#|}{9H1$5e+#zva6C*R&zB`)H`aVc6#4x28wQPE zMKN-a=aaswC`bzD5I+HFQe?eoetQqjZ$C?eG_m(9(|iu2VB4B|>3z1)*xNdRJ01n) zm?v7v`uq%N5`y-V%FECugR*{N-iKE8aK3MtCw}R?=O<<}oKfE&|ABa(`JB^Hx3VlS z8<}aJfGEK2g71ZQ#wLL*)1zhT^8MJAvtW}i6zusZ|4YFZOS=4$^Uq@`pp5p9C@AX4 z4aQ;Be>dl-+yuw&Dpl5*Iwc~v9}JGRSH zFrK*`yANr*{o1XmKF|7?@HofE|3nK(mQ}D&Uv_U8jLm+r7HSpvip*6iGUww?;Z;%S z5{2#5_3KHp5aN#%?j*OYq?jZh>i&PNdQuR~UZQI;De~&UA49EwDng}FHrx9$F6>4b z7$)zCDOY4ya1wXcolYsAb)YL9_gZKaF7sxg zNRd3`LxC)UYs};KkD2+AbH^hhL*|l&gJC=qx4Mp8Z3^D%uDMtDmG1YDnzmGE@=W#? z8UUyXX6)oPjy4{8G&$TKif!_!$B5SCV=cbMt;>wPU!2_lF)5-ik5_`Gwd4>K&F2Y^W~?;HIl`%!;1mVwWcK0_da3&hq%>`vZ1kgy z^QPbT)|9f=Zk&c&VqSkN5$;GcO8c-axc{7bZ8L=pBGkGb{hq9KA1K=Vnmg-ES07=q z%rg5~ecotavM^+Rg5uX`ej56K?EKDnSDyGas({uXhG`y4a#^Z*bi)||Rb4T1G72Mr zSX_I!^4}QY)J5;o8O04o9S^+1s^J)HR`(J3cPmFST*CpK#j&cUQRT%!z#8q2ken4Y zpmXkCd+05GN?{sMI2uBCczA~3E-Oe=cp9YrdTe)1;b+uWn!?eb#?VMsdE!f21)|oWcvMG+jEU;U8Jjzr|e4 zZzWut`k5|;e!YwWq1&I*+3;wfGh#Tm%Wi&$*yTabZg@t}R1dj;<`f2%9vV1srz6n~ zE=d94i?&9ET`>-jlE;wOb;5S$W+0RN0?L!gw2u7RLHzhxU z*XB(vz+-gz7$Etl!sy#5k z;jx z_kh4GU%lrW!SQ+q#nh`W{B^U>xOxws>h0=1_!XP4-h(fxSMA}4KL@PSgZUmXOul}M zXo}fzwFj#=@~igrqbRxBgY{qSsy&3qtM+`Gm>V(8%?NS1b=bB)F1Le;V4VHb`0D>a zAW~>LVk(CO&RO32=}R$JfMxi zIC5VyygD{q6(QA0?Is0aDud;>R?a+gL$PPtA&4Z>UL1yZ&dw9h9(pWJWb=N@zWrxN z&bKjt|0@F#5%#3)I^qW4{7mBgk>`t)-TeWzxU0-FaSwcx9=BdWFZn+(k(*nMK`8&i z+@}gGhyTKy%+!x>QTTTqLl*6EQkm+cdJ0EdAw6$QK0dX!XklmW1l=ixp3g3$HiDBG zWL1$M6wbaRnQfssw>w|1+UZk%L z4jO53-zoU9LYI;A5CKaC;ZqD(NwOFpP>umU;22oA_zR6rUFZRHV=&H`(J9Jht;UE$ zxV9S|GSHtDBarzM9*%*C39_V(QHYcrpnDba8w7wwf{F451#lHDKO;s}!fjLDN!_Pp zDaa~M-v;>%p;B?gqyg@P%y6r-+~Z3zzt~Dp74)AeI-_Px7yF=l7zDzJ@mK9KOM(ktCyz>19TKK{4lowuz_hd9w%jc-{=D%5Fw_n+} zv?6$%F*o#GfvL*N>%Tep1U#3+DOs`d2sJBNRIua~8H(XDc`5~Stp+JGMlk<@Z|J1h zQFK}s?K0dCqgQbs-zo=Lr=JD>2CnWW3s9hHowS->w&n0;K(?7w9-kPRf1`ka?Gs(f zEg)cs;Hqx{0n3y@P5}Xf`>EUl0_J(%w}ODdsJ(6l0W0aGkh6k-fk)-Hf`Ao9Q$_^= zz@W-gK_K9$AaF3Jf&kvx`z;}WZ>Z%hA%O43_n#61oal%W0$8aYAa(?qbWa5Vhl5SO zYtP(^^FY)Oz$?eaVDY!GZtWHjFfiY73kYDTo!-5G0KOW3ITZvr3%eBr0*(p-f$<6g zfNkCi0)`u4ycGoatL>H$z*kwnH3UE+_^n$;z;eDd1VB;cUY1(Pd&S+QeD1uDrP3v5 zCMTTVFj&7S9dcn*P+EAMer2;hAYOsD8g3cKrGt3`c;GP+>R-WH5o! zVCbK6bXGD(S{A@IY?8oe`PU&|479~b8;W7kdWdaD3`=2bqZbM3Tv3MD#U*R2E94=r zVOu&VF=A3i!W&qVV|HEoc(15_`cLd-A}_{mq9~V&wY8ab4R0+n>GVQR*TvjP1(5Sx z)FAyh>`~mvb!FnRhvXy_l zXe|_BVoG%|*m%UY7jJ!PL4bKF+9pCokvYu$NQ(IM5l#8s+|kY*H8K8uFqEy{TTus?9TB7)!})i1OYvYP}OgGn+)FrPx!#XTs_ zBObT&T1LcsVQgfTOq?_Ymk?>eV0h?o8F^A#Lfqww@CZJjI1fc!6!;z1xg`pmC-p$T zzil(`40>}V7cAZxj7!ad;XWtE`Z%W0m9a#W49_<^(JH1J0JireNjv2;36bp}n=z&? z@f?+Qrri}Pm2~+hk@Y5lRJ3p)GejLvU)sX>NJJHr@S%7P?qw0-IULe@VCehRUew4I z;7`^T*A_p@qeS=DGqC|0gJOOcb`29>y0(V6BR0b%N>hm9ZnS$d(QkCC-TaRAzc8aC%FBtX;S@>$ZG8Sh! zL&k#LHqA%IIx&|aWJM6BOIaUFuM=|~2{8+A&Eplb7@~LO3x0;pD`sJ-SxqX$EX0?# zam6gmqqZw%1sq~lU|h_?8`hPw@DppkQWk&oDb&Qs!*Qi7n%X~#H8JAx5wt*4k6@+c zywv-w=R?n*%O!$FP!>er(#Yiy%mfF+CPk>o$Kq0%(fL^34(7>9t{&R>19K}l?KQMx zI{d^uPeCwF^B|FlFt$dIXgp}|2zli^JJ)VL zwrA&JWqY~Vxmf#UH#_&hH#_&i6uq+@k2KSB3FkLG7aC)~m_M#V-t1h=b13F0X`W31 zYbQGw6EB|GE{n#xV&zP}8)oNz zBU5JQVjAmB&c&eG-sD_ha=FR5e68K&T>NTnZ*s0xT5}>f*Q&_{=c%{c^lxOcPU#zs zC_@?6o}7#2?Cnj?C1I_boC`S3o1FVOF_}DU6wiouOQ?;cSXVFVg!siJf7nzKis=0o zb+XF%&a8m4#+$R@4 zRhl7HT>tt~9i-obS6G=h^#JsMP!M3f65L0PnL+)TN_+Tib(tkY_AuzK#-VsUO zEHCVYg{dkL;YKfbE&Sf2F{Om#!dHb>i#6#!pozd=5(qo~llqz_?|dxOGom6P$`(KDao-Sk^OQq*M5bWu34M zxx8hakkmZZE$d{%Q`o(%6W}SIn_LhEhQ8t^*swePy{waYbjB^~1WcFbGWh^{z`U$e zz){xeU~XBbgE?iL08bTNU|A;{UiLA{IssD@r^m8RfaPaZStl4kZYZEH#C+pBh^Zc% z-2EIZMc=Th(p%oS9JpXD@r<%>^w><(SX^y>M5wCQ@~Nu>0(sUiLhd_WZwj<{V3^# z4_XqmSkj4v{444;fsR`bm~&)>T)rp9KmheiJWA5(2!O6L^aUnbmTb z4`YzLoKx(Q*K-Ou3Oaq;$77J}pKk4oiHc4zH_3A@DF^}RPeCVJ;|=Dd!OQ)`F~SQT zs-TlC1x4P1POzXUdO`)AOu0=_{KqJe{dx*I865nYJ_|b8Tg}NnOF7wF$B7TBu$?J$ zx5-m|>Nw%IyW|B9pLC9&Qcn1G))I|UPBevZeAnG!uajI+UM;}vqaQ$ z!ctA$wqDQakk_f_bk^GIIeps@%%xth%6Q^)U1wxS>Z3F={QlJ$5y_nU z)fo}_oNxK2f;{&prjiz{angP?qL?D~TxVoSjkgl;roVL+#+Fr#>?n)@hr)O;M`2|0 zM!5w_6Q4RYm_+#~vc`%5A0yT&jza?oJl(Iph-J;~>WhqPA6H*I z@YNR|OwlVH_N$ceTL-u>73Zx3OiaCXfVI?DUqpgaYLC8%dC#jZA~R>bhpQH`<9qy6 zDd8F6yYK2E?U(IU7hz#uw+t|8GL@?@exuRfvN=~t5uq@0)LRCa7%FS7Fk(a2EdyLm zTEJBpnLECoLwf3_j;^WJZ#1HWpBRC)xz-V+9FoF-6Fu8M!!XXzfa50Xj9PN zbIm&D7H)!@q1(SOQOXIPiK*L&o(wI^v62(QnrDA2IdOys{`;17FEi+soLX;UVP2;RKbkM>pZU~w;yji{u#yw! zrQh&MPDs@eYi1!QECheT3poK!&dQxC+B^rd$t^HXm0!2|I~|MbvDp|YzbKslJus}|jrD@c94h?rV%*U$ z%!Y?-*hq&aJe8_l7#6(OWlr%zoFs_Bb5^BL(2X}0SZ{t14cfRe!($FG2~Y-791<7%NB!QV5xpag7N_s zSxK&?PWcBi920_BY9>Q;GtHr^5+H0ERkH*=p~}JFDws}MIOHY*7d^^yaMtNqFFV|5 zTv?Cv)C0p4)>N=y4$pv-YYxHxYOTHPzbjrBXU0kSNl1vo2RNrKr-76}=gxk7n7K~BsGSpz+O*K>6 z5=9NBm%*)w3QF1yFJ1)64NHr2;_&aY`Ummn`*uj%TAug`vYE(e+L%FE7#b4HGb<|> z2oeYMz?JLScNtukstN!Bl3y&(#pq$UQdjZ{rGha&DcR_bkZ~9~7;GaeCFl5Ym?mXb zq;Y2+KLzry&S>BZ!$l<`5eBCT=|+TEB{YBWxKg((EXOAjS@OmuBwA#B0?SfD!oi%A zLctPE=bVFz-Y_)EFhBu0NONv{pwUN}#xb-l9DUZI+^^uQd6R-ea6cE4jRm`KzmU&R z#6!T(uraJ;iOMqEh($+pre^Y6d&&4b@Q|tjEK-wM?%{Fj=7oN<<=ou%<*~;5A{7 z4jNNy?P0)4mJ9uk;RRK)xY$jfh z(iY4FLVuU1(k%v zQxfEb#VDjGw81Cj6=S+-da0fFVYtpR)saFYPnaR;xW!2Y;axDe~!D@1rD0Mw@= z5xcd5FZ|?a6ztDY0jZV4vwOVk*9FtlQ9Ntak=M3BEJe zlq=ozi6q;sO81z9lWm?7g_0s{Vy{H+0q&g``7o`!nSPC#=Povm!VaUTnuHe^eLy#+ zM0H47(gL!ct=#f8uz`U9~B{OI0{GY+s_xT9-h- z$Xq5{3=nzNv&v45@J6U|0mD{!9`GnAnN0U_SmJd*FtTs_xextBAU?1QqY_co!%Gf) zAJGc`L_ELi&-}pP^UM0g3<)||VlH}TDmY;^u3_mv-vl~W8jCp)9)ddrqNSpEfU94e z#ys4ma<1Ih!X;i5FHF`zhdEy6hC6}*EPMff;DffLJ}-IFK((m#2!c~wI_8R!u9)j! zy?7RI!`=>$7BH5qEa>**ey1vn7285p3EVJCuCBtyAt`l9@Q*CjIW@sHMlKr=7JjpDy3Aiu^17Hm z!VH%ar@w~9vMS~4{hJb2AYD02mSvCO!KB-!*lW>*c6@!($dYVwMzo>$VU-x@05vJfl6o?2I^>}FGJ(!TXDm!}p1A%8`1PTl* z8{3^JWCndE%Y0CfpFZ;TA_P->B@sbku5J+oB*;D!uH2qcHSIR(*-i-*E)8}_BkG@b?w4M6TW$2 zDu5CFz&sD>dww7?Vz5_v-}@8eAHxqUOHCsExAq5GVyfWt>yEiUR@A-l2jczW&-eZd zvws~vYB+-LuOqm$e!R&s_s0-2lK)rm=S%;E*+0!Z@Lw5fT!A;j5v)nsVSTU2PA~t$ zoQM8=f6G4*@k<3#{_OXc9?J3eJ{VT1EC0fTSva2hfjK|*=lgH}1Mxr4`kkNJ-&c)s z%+HS>%>5~U=m#R6`JX`*&zq06`#m(@?BDU!PfR?;Gw&@8_Fq4%&>X}Nge>ui zx!&@%94|9)fS*!Vj$#THbg+@L*Hg{sVJ-K^vhUUHXDHG$r23 z7qsE^)vqh4BAeR_sKFeu;rv#U+3*`VyFoR3yMOLp#{hny4bJ0Pl^;k0%Hs#xm?&8X zKM-G;YIu1zT*xBA55#Y3;~kMsv>g0Enp1xKK%8}7;Rqs}EF3{xBQHQ9M-VZog(HZ| zI(j&QE_@t8fw`OdZ3BH*kwm0oWKVCdhy~5!cQN3=5B0@J@PUAmCglm2~^QnM>a8Q1NwFn2@a8=~a2?ymzj~wBk8`g#6;h>zPJ<*^WG38=a zG$_{Pgo1L--bhd_^N2{$isbuNBNCJw*V+>aD$IyTP{A`IK`(qFK`%y;poG(mNKlc& zcp^bb45LOQD8F*#h!i0yq#IkpC-U1ZY%jt(PaqPMi_*%C1m&{%0YoI|hE;UWBSE>$ zb44g7I%?qtpp4a%SJl8fu?67(QE5VRum-X!gA)Vf^t9C69`Hc zHcAA7k^o>&@<32hG2^sOAgIWAL?9^1*h|wP5R`CUHx`scHzE|2ptmVTC}_YD3VJaL z1r`5U5eq6N+n!iZeq}BZ3(8rX;3od&KC8o?V9<^6uI@3Sd2r|;q@b0E2Ni#q5f93R zUM=E5$x-^c@u1urM%^nO^zN17K`(sbLBH>&Ut?WDIYRQXt}$U=K}g}hKQZU2KR@0> z@$cXs!RL&+V$ONf56nZkpYQPxAM?%1LVj%7Ea$V8RYgewj|*0;Tt(gydv>2#xr)rB zIZmuxMcslEi@0}$uUPg3%T?4RxUq7Z!Y9wfxs#C{w%$CBjY)5D(@j176ijWrE|wkg zs(!)H9~|Lw8)g8EN6Q6xg5?gvW99UCk61bVz|E2216{^5#mey$pR!V%#9NM#vz+gM z(`=dHAr-Y8R()dSxU6kPtQ;49<%pFFIAY~qOwl_TGI4kfKt_w5P`O$ep7Dgr5i>@F z%4wx7V&yjMfyW*z$9bPf(~93rSHI6l$e=+(RZ3YM!VOX1u^t}4Z7IvAo??lQ>|!Y7$c5 zJiw4@5>oNz4Tj^7whQw|z1D7wP=3`>lQ^&Os!5o6v#TayS?0QG65tOl2@AQdk_52d zzK0hMCFx);lm51YV$uZxXr4vA4`yond%tn$q6Voa$vxmmY2RY1deOWXIvx&&nz|>( zBguWk>Lw9M?o{CzM9h$d4a!63N$wkNYQlAr+^GdJJ6cgl)FVfYEO%+5ziyH{l~uc0 z?u6MtPFe03K3VR8@ho?~a#&=!^AjvTS?(L7=0cw4u6eeT#?FNr{ieC^4_BwJlja@> zPiy~Nd^ZRBBPY$BZ=LPQPG)Cpy|U-)FX zUyQQc`G%&}UPh5EtB_Tsx$8&m*GY5dM>SPxK$<((%9GZM>(Xheh?>&e>$g&STFzTv z=vmK5bN{|vE}Eb$rm9w$i_KL%wNP%f>Y}Pib+^y~$E0d8WNj~jq~5|97{qP3(yZtO zSoo+1L5Y?hBj+ixcqmjz4b>>L-dG|^;$A&$QF5;eH6lm}w4G{V`nwujqF|3~6YJEd zSs8Ao8 z&PmZz=Q9`Vn+*BhF;ict7K4LpfEcpYc`6f~GW><%E@~?Tjc{cVpVC71@^sD0dlDu$k<_ljl(5uT zsBxzt7WKY#VJD~ZF~Uzp&DF;b)g<3p0)5>`$ zhmZ{br6x0z6nv%4pb#(UmRZJJYOzYbE!UdV$8br%T^hgDF6Z;I>J?U*EUwrwJ>?j3 ziteHuh8*N9v}Z(RiFy_=ZTsf? zdtCRaTW{4{wX62-?$v9r-RF;9r+fAKSRG0>7L}_~Ew~sIXl2N;L&$VjxUL&vpE4A= z`*rPx7P%xVo{r=0tF6*4Ai7Y8&6KTXjiq0@3@<(`)vjd=nj06CwCUj+?3PbKtsh-< z0%hZ(p{~Zr&``IpXq!=<4h)_79kb&@K5!rLczw^fV@Ms0S21K`Z$lr%&~38WUHR@D z+L9GHjH*!PMUTqNEhnZi$y2G*57BOLJ{A?60reH##s(~V@P79X<)si@Ta$Wdq(Ub; zvB;JkSqo5h)r;H?$tyCHI=J$A@PZQt;qoo-NA5d$QIq`2%KnGcZ>i;%%A*=O>y0Ef z*YaE{HDEB7c<;M99qizCFcqD8S^Mr{rPl8jB$^8O4#(EX2j9!lvBt+b&-n)(uiLxj z0NQ=EuCKPRzEJctm-@1rbKqAnd*71$yp)9)2O&v-hWbOYEzIAv409F03=``yGjuoG!rsHl1OiVr=N_d^2;H(N2TCx?iv1wn{~M_C4;U5*@8GF6m+ zIu2>)XGDq zj3__NU^#w$i}~QJhSPyJnz0-A4iO6|r%HJC(G^2}lwlIDsDhNcFib|lO3SymbSA2- z#3zms)f6Dbjpagr$RjK3RgfQ6gQ#+p%QXpp++>1D6se(p23x-KO{vSRjQN zrZLr?;ptVL)wN0dibi|PR}*#VRFz06^L#KwF(|Q6U(cpzTh%6;JS-qhf!R>fCq8@^ zOry-JAW=QRQ^DJd)@ zVfGw(z)b=F%6A5OxEWED@C`4~uL|=5JEPCfR6?D5a>WAz+tNOdL-Iq3&&cV}tWkGr zFbEtN%gxs7B|hY#w1mWP@Gnp&{BoF!w{VBCo}*L>e&T?xg`+(L=`F|{g*<>LZ?8pm zt68zT()4_hzUb2Qyf!O4=qfwu`AQ>^N7=M@9e_C9DcWyZjnFF^3Ck#9XOQm?1g+$?q=l3Q$^LAt@{T z!KL4al9nM!v}s#k<{~3=Y3DDbh&mi@#l|x_V_Er~BX@iD7O-)7yi&6x{dfEO44A{# z8&o74R7&yQ!O%+(fI@9XJ^?7uzyx&dn)9}ssDQwf7v5SxL<4+ug_LZ&Cn{{~3;eL^ zP(JhsKa5~ARWaMW#M(lj9bwCDoKoh7D_^k-(s1O}pYcxHA*6T+zTO}?uLIu1DMGUl zC!WWDF6!5LNCk{(!O{3U%8v(`5m)TXe3A`CYzV)ip8`Dj{`zFSiY3M8YCJ?V+w8#H zZ%#M1;}M7BiTG%0EO6-nQMyOhoZ$;vI$p0;ISiYSg%m1!b>qA6j3fyk6BVu_0v?)) zB;gIoha$}^v0zBhJl_%71vU8rO|#u>Nb_pm=pxJP_MM)_>KRFnpAtN7!VAJ4cDD3N zU%1i*ea|hEv$a|z+a!ctOsum8_ZW(FrGe0#-r=&&X?N@{z7nC32z6s&-c?`xV7R8L ze>%GXWyr7423yj5&Qn5%NpwFCh%ru!q{~d) z382HolcpJya*_=xt(e0<6EJN^;aLoX>$<=&;2Cxv+wAt}G+H&{8HUq^+7p;8j{z)k zy(Lzu0S%Y?x`}Ns!mjl|RKUpNuYCtPZ}8XQT1TjpYnjFXT-O8$)?IS}_w;zj-~N>D z8Mf&%;&ZeKZzyCm0-vm!8oDrCT;lj2$n-phM|H&Jny_=XGvHL;lo~uR?@CAj;aR{o z&LU{9(YG;K3&@X}h+!whm5^Dcb_P7l^z}r2?%f_{T!Vp8+aVc3`bUhF)ZI?Ft5&kj zYjkG#s$UrL><0f$JPw&PVrjtp%*(_AQ+V}- zv*9wAwZrm_nj#`3(ehn?guH9Wl8%sk?q<$G8nSkuMg=A0mjFuy z{0IVSq?VB<0Wbuox+#eLE}ZXG=6+(UKg7m2m)zE`GE4{z3QtHPoS7)5u2t)RRB{;d zH7aR^_rlXN!MO;oZ<6DN>UTo$E8;#6?m&CtCqgn!D#$M@ zi`T#XdlmEI#IR%d)%kgTx(Foh1VqilUn_lQ%5AC9ExzD4eMI z1d5C_9+(NeUNYks2Wr+7cs9Tnow@g^i!NE}b2H$D_0wrws^^sb2G>C<`YMyaLZr)R zGqm`X^u3$=C&ZMOuVMbY`}?z7|K0deR*d62% zh&7Jhjzeig^cu#3#r<|O{84qu4ckJj*4=ZH@K?zdMgKhmF>{QehcD4ysfb4SFuUY| zg^2lju$;BFJ~z9pT@6&soZNc8K^3+83iaRB0k*{wG&<9p6?NvhwYw;!$h%{9N#zRe z83*lURwB+AsV*Y+?@_>hB7o6TN1fTLb@(-ef-UwDf}0~}oyDAkUhANFswEafmAK?g z_hBtViHt2~QomWgo4zXxHmGo+_4vNhr0d{-t*GwWKM=2aN?27S!W7xud<8c8hLf0f z5gxf$`WiHV94{I)aMFm3R-)(gYxmhe7igX$!A!)8lgGX(wBx=fc=!qm{MthvM{O2G z4HcFAqFzKEXGfWs;_|KGow2D*Iw{dGA%2WawJ^P6jjEb01x-@m6 z#EbPl(-8lt*7NBWBYuGMTL2&hUP{~-^ji35m_9FLRh4x4A)I;s zog`fzx;);fHK?){b!BBbaRbG8K#+0kre2YqWNLQ9YHVfA@q5M-!v$O zs*yA(mw!qIQMcA!NYcegbK;GA_2?r>P<-PiGL3sF8-7TTt+thz(8?gRW>#NQ@b2*PQ>QOpTjZbwO@Sdu=B=63$LOBM(xoKq-= zR*U`E)$#lqTq-PiaR^sN$u4<{V0w&ul16c4lzlABh)Z3GP)1R_tP^J;j3Osq5H7Ti zw-nT5jr^{}@*;HauMw{ns|v4V<8YJ#iP27sRH%};CY)kHZu==$1&>s99 zWb%`*g^YXt0+(0jvWI93jk5gD|_MdK*8_3qg3)@s2q}IM}L5X6=kCU=Vid7E5 zAtR<6vz*2EjrYip`#=O*@{m&p)pU; zbzLTahfyt1#U{?g<``N#@4Giou%wnG#y&8%=%j<#1%4TPslsn0tan;lP>#pQ7o*n1 z*MA@~Jf&Fy@zV4s&bZvruliKn&CE+hjC0kjG-lvz7qU( zj4GDdYGdA0wxFG|D$CqQ%(#)-;Xoly|P|FD0m6>{_4i@knUzYZ@gR`8+Ijk=+Udu#sn64fBO z$3kt`+e;M94+xBv2hA+t@2&X`rzX%avD5`mU^#nLA?T7BkF`i|UEb~FNgK`^y@&k( zb#N?ae7D-yc8J@eV-O#pZ9Np3-Sq;?SS-dtHd83LYPK_$_}p4nYH$ zf1vvswC9dEOrgVxw^-=@wVxguq`I4KS5bu{)KU^CrP)}-fI|4KQ1Y_L^*ec5H1+fj z56=BW{Z@*_4ojtidpDUwLH+iGA>M-`yoNb8?GD}M68g?0(DTAKxvH@DB=6>D2fZSJ z`#l202!wIQCrIJFTVr{jA-}c~5DYIcA!XdKwAl~d*G*EiykD3g6x}YuG^GY1vBHpb zc}eEi@`t@W6B+IE^?mB5 zxy}6BNGB86y0rwTw zjj0c9{+&O4<9xyC$OVJw0nApRMrd_U^EmK&vze*dVmhqNmU)>(VPS*>(XjAxp3}{J z>gH+2mip?YbSKGY?pXAcg|TDG!OyP3X)VJ17r6TnHcMxm^%Xun2x^KY_b^7RqC=F zSI}OJr@ExX_r^1GJtFe!PROIHPn@c;%>QmGO`_Vf88yRo8Wd+2$+@0*c~NiRDS_Vm`$5u z?{~Y2)+n@yz`y<+4`Q%UL5Kzx@;S;_k{07dd}I2~V@+8(Q%0ixz$7|fNJ%GgVTWTX z4c4~74w9&ewVg< z4wYha5Or}fNSSqZRc#Vx9N%!h5E&h|gFHP!nX7Ms3sgg5c0kMG@-8u%WGRKt2fA*% zs`_1ktmf||*DsA$te(V(Yf7@+9$pPZ1CO`cgLt3pi;DNU7gnY#ccz6{tP;k0QDzwo zm~4yWACT^Tsts)c9C1%xixAbzRS5Yt@nzj4_piHr;avn6%nNNUQ3s`0hrM76t4tvA zN2}){+sKa&^LET=)xi>ck%a_IsKe$Gm2e6bfWZOb1laLhs8Kcoc3c(1a$h4(%5tv_ z3vZY!SbXzSfe=?Esks{BfiMxm?x5Q>-M2z5hu0CtZHK^>Yhh7E2viG~@eTYr_eR8r z$ju|8lVVeh?;p3g_1EP@n@_=L=bWP@Kom&%!So;|FAq1Cd>x+Nc+a;N_e7hBPNugA zb~%cWl%G?-;-(6Zve~tQU4Bu(s5-amt${08n)Rodf|5K`9Rtu?r2*c|QXL7?IB$|x z)`&nM(GfIlm~P&KLEtew=ZmN?m0^V_?yE?$d5C1=y$t*>D9!v*js#oiXFF-OP7grx zE?-_U#ohQECL-L=O?e#-|6Bqi7a;Z=jZy4HcD`40-0-W}i(*>xLMs&FV@rA9e4-|Z zx!`;C0qw~ieCz!;dx(X;n69>)s3{}T>8=E?fXDg5H`?UXI;J$n%D;10r5X6_48js` z9`xYfxfs(lLCT#_z?7+DnMrnJjF%(&`A(7aqfsB*YlGn#Ny!5W-=eC8wT;Ncks)aE z!!M~PfK0@fcQ2rxbRV@lD>>Mex9N-PSKc>- zk6dJuu%uGa+YJx8f@joAs_pmGF$Qdjbt5??v6cFm?=FzOCNXFKmOry6gd&gPSoAS8n!p*LwY{S!KMkh#%9EB5K6`c`h_Y& z1I+$7s!9MUCG;z#DX1Y@RfhRN z>TqT%*~C543sy-^O+ne6j4xVfs!<7v<0z0~DcjhVwCmiqP(qeDqaJv^^~9T+MTQkheRg*=%>7?~F&$@#V;Ft^FC z*3CNOQj{l*(!Ww>i7bRBB9E3h0rXDZO~V5UX+x>LT%Y4fuWjG2eTE}=3^FW*2LnCp zq`|4&BB#5bUxo^fA}s$Hu5kCgMuC~{5706@hBn0Nn5Q`Jn9ult1X-D&nZv`7M`|Yd z&I>qy%L@ijA-w&8jQbE$xbEPc0(5$qu?ichh#MG(zNAeqN&+QGaqKyEjuQF<#`^aK zeU5*2J}+^KbiJ&Fxa)6QN`>&TxiTF5fFjO~wwvfu+#L_Zv>;A4I3s_gy-SDQkYK{f z+~%PG_z<%@^04rtAokQjJ|uzm-$A2T>gO_gl#}`4V_T5{0Boh9pQ$j6`BBYckl!(IDH@?{letWXI_?y(^Dzga#cE z+=NUo%PoEYGE7Dvhodk_xLp;J6Clrob8eM5@=i|V`pJEZyK}h5msM7|d<^_dw3}Yv z%ZGgAwikaDwz_b?Ped{Vf(|GzwDOH?V8#Na2&C*Q8eT5Yv16CnBZuHc*%NyW{; z!2hV3a-q9%kysN=d+F(!3+re9Ab$wEWD?=5M4GM#^rV$0ImLR*LClU`6uP=%I5 zr{zx2Zx+;9DnTSRT_DWDq$P+tCP=m>rvK%C%^SYms>RwG~rzly9 zQ4iUR{hhQNr0LFwn2~BLfWae@_p= zj0yK1=UYO9tC;d~(p3dH5CXvDKtRRLM3sI=7bU}%G;>0XfJZZegN*1&Vpe6Bk0Jyt zsrsuDlvRtl*H21M-8~gE_wDgAP_&$AB0Rd!8;lYCY?gx~MJc}B+vbISZkD4JyhQ2j zc2Rnkdq#Q08oWWS7;%G?0RL@%kpTm*M$M94(1gL|#6v8ahvCaj5dzgl<5j{MJnr_#GXv5$K3~n~U^F1X5%4quAxlT|UYqeeWh0h^Zy>HqX8>(jDKMf+h^iTkZ^d&J4#p&H%u;lG$U7jJ`Qh?!g9=XP!9exHmPM5mw;wer& z#=Oe)-^k&ZwqlWemWtdkU*R)mmyL!u$TcfTn4gJPD07r1i3PW3uX0hy*Et%pU*QZZ zvN=%Ca&UwkQnr-ecSkiBm*7tnE!n(FzFHH#gH=px2|xG0=({_6`W6x*LK|MQ>T$iK zh^w+0ih413g|+IHl}PqE+RyBAw4#$J-4Cy_*RUp!R;A|lvTg^fy>7qgaB>t7ZLP+H zM869XOuxE)$p8KrQ^nnaPI0Jwe3p$;8CHFkgx4a8Fnt-NoWzh#uWuogcd9>9I~>5pZ|R{wIG z$cig=1Rn)4UF_j`xUS*SDe3E8dy6*Tt@w}=aEP7c^TyVH_D^MT2!2z)cFS zTI%SXsK3tMzSq=@y#hPxaA!~!=Wj;9$lB>lyjlXiiWG*Oq8qjm= z1r=_DH98}yyJChG$s=t|#ITBYHZfLFhQdjf(0YDlzT>?ku)?o|W;!z+#^(Hb#6&!; zX{2Fam?>YfZ6_NG-+yC}uIu5X01GTtl-n%I#g{`5&0I5M+X^W`828t`felb!?SEy+ z`5m5@oUgl{BFGpk;y{PLd>kja`Ur~+vQ^w$MU?{k^k|<*=L^BGqI1f&?skl`a?4X1 zU6y(!U^DH#xFC&{b*z&aaj=pa_1;@L!u25hh(zB4vIad{**Z$M-fp}%0LKd3jXj)Z zFo8ClD@@NV8prBVK_Um{LcB*w89`;EI~{i$qEWN_V~EWHa~j{Fc<202{su@$NS3M- zYsWoU{(uT7%mMbQa=fEer9hyI6bLn%3XQYLN||T{66;`b)@hhP-y$W6xjUwl;rrj7 z;vZEoM0IyTeV;OrdsRJyZ;~_M;A1u1`6VivN!Kb;mK4Mwup>Ld?AzeOe>92px#iOm zyv0a7=iF`f%;~w?B$<&)F!9`H_kn>r=&jMRO!0wf9+<(I3z-ppwzJv6xNpQE%c}zQ zo#c;&AU&_)q0H1i21vqF!!;e-HTUGEQxGX()W`(UTWLswT`8nNUHv2tDHeZSoW&M~ zK+UNoSq*cQJ|L)v^8^D637bcC9=$1(cjfhYq!VhhHaOb63KtHu{EbyJmNO)>(9(g_ zF1Hslh|SXw%7>`LsNV|!5*5T?{u)89r}RcaL!jeU{&hg~<72^(79yewo|mWzx=!yp zf|8Cae~ffG7Yx4wayAswe$;m3c_z{$cXG!EbJ6n>s2`lU$vF_aem-c3=w5G&18aWO zOS$wma%AS`F%@swGBFWbkpWW~T>!STE;Q3vpfQZ(;3Ly?Os!v_vUYj?h~la20O~?K zQzmwqI&us>40^9K%skSDfOCYZO6ohDV zPexiEGuW(#lP`FXBT_mW!Km}tn)^3$_P|Ok=8yTTmeF8fctf~8P;*5TAEwtL#j@{$)y{DN&ElwItP zF+{cDJ?uviu-yndN7(zVHEY0gyshoS4KaX_D2{0$f1Z==P<0T)oWh+G*_KK9n^bgv z?iCb$AcpZ5D}JOQdBi=b`SZdz370>PdUr zvQHDa>-tqS2l75qU_sEyWuwhT#&fo4k1Ip$`!d2;LPEO!k40hq@d@@CvfD=VLE+Ex zhoQ7(3t=1s>2sP_dwB5myA{4tFz-R``Km9y*^0c3H&r{XWJ422pyT5EH&6hrN?c zPw^kE7$tvi0<+Z%v*}>`1JPJbNH=KgY91$|)$p6E9er%Wfd$Iv&4dfWdI9HW2D#kB zj-cJUa?`bEy)V3Xpo%$7Lwzi8X~2+412;f8$r?E|e?7)?J+3@EA)>_ZR0u?sy7HL1 zr4&5(kNtOd9X=y)a7$x<8=nMQ8P~|fE@xdxG3jGWQ>H_bJ;oJTfB$bOe!l_`o8a2t z<=8>Nf@F25p%CBFN1p(w#z*|?Y5Le5K%Zt4(A2=qA>m%7-XTIDDy4to)iq76@H>^_ z5TyLQ!Po#UP9ylc`Wl>UwktOWJqVh96Z|Yn@fL_nmc7*ku+{bFrLUzQZaI6whiZD~ z#aPyR)Piu2LpS|ZNc9JVS#_=#2rjV0UdCpV*`BG|Y?Fda`;g1w{k>e#?26euFm zK+0-^f-UOTsL*HvzleDjDcOkoIng8*DX;3((Rid-MuwxEn1TnHD|97Yr666`7pyeR z1UW$7TQs>V1}&XT#{sfFX)>BWcAQb>tJnEd)$dr}bim(Ff0wc!PWcTm==U)ddo?3g zN3Gz)$4DQck*dX4KqHi>fwwsuuGUTp>LotUQzo6tcvFf;=jOih}-gs&}USI8q1Y``+f&L zC=cpR@dA4b$XkV^5@sfyGrH68%pFq>9R@~kF|6&@gJIE+gf$1Y_hg*sm(swqXGi?@ z>0+)eVqWRSi#F_xsaA`QZb)^+)&Yb;pH6ci#AcWHo)?@9w&GGS!D=@+Ek3yiIO;L^ z>ub32q_!ZU5DG$yUTSE1qnpvB$jVOel_h!QW-2S9#yM=t8OC}x5`W$EE7U~|L)3(x z#*2$5D8{Fkp$lp*`;7Ah^{=UtO!GL>eXQFjS71k}@*%^*(QHnGUr`v63cd*TJ!ZI7 z;ESzRp^M-K2|GhZvrFd!8klLN^H%_K{2U>Jo%Q9c`JV3gtE92mT>*$s$brJ7+Z6vPZ#*O{7rcMMHA4iCcNj zr}wFNpeXxG1gRPy0(B$1LUmBjl86F=o)~lj8FfH` z1R6`dv;ss+9o|UBQYCPt&~=njgiv)RAu>E*;h$`Mv;w`+ytD!k7+@assh?5NoPI>K z0(e0vg=LOYgyO@jHl1M5LqXrN!J~)*vy~45abzRhPzjSsp#&Pd*MS5EKZg+oh(=Ah z!A2-DZ;*@w5&EgxiH1Wi_x8Tec_9iw9MVp(?V^bE;s(wICP51M{9NYN(1LpUsTJB& zI<;Ejd^aQA?yNIy##!$UVrhN2cQYdr10zH~*IVL8>*-GFZi6q8OZYK$xuuaZ;yzW7 z1G?UM?X_*FCkqjoPuL0RMzS6;M=kLSm5%$R5GS@D4yADqo_i~id1Pywa(oj#L$7B| zhc{8QOhkiZc3abChEZgY0R^QsTyeC7<4PYok)fV#x0lU@FVBoUHWT0G+ z%gBm9zK=|Fjv`WuU_ckcB5cv@@L`L~OwX(;af8*WF=j)fm%2jT=<-))f7P+pf!e87 z~{eCm)7cWAs;J}C*)27O8_>b|4!%)3Eb2jJP^JUf5M ziJi4A{C1k{xO&DlUKtpBkI#wOl}U{Oyu}6-_jEfPc@!iI z^J!kR2%P9S@&r(zit1JKPDD$k^8vFilDQL(L$fZcR5(k;&yg4BimmTqZ;dsc(Y5o~ z3y3zQwerh^-SZ78Rl`DTcb3EgbFU+ZiT*$KpPM(p76mb|6or6>|CB>l#ld1&CGnG zo)X2F+TJ%;2`=_YSy=MtToB!xJ1Yv7mB!Mse-;)8i$@$wE; z4pQE^sQh}dOz0pO zyr$`|=@T9<&vc9D4poz_vcdG7al*st&L=(Lb|(7t>ofes2$&rwwY}u3cWQjv@qUQ% zXBX+QzqKs-o#z?tw>nXC;!_&pSLF=CoU*C>rwW#i%z77i$RDyd)?Jr=pWsl=*nvIx z&kgZvm{%q~$Ghqv1NpOz2&S)wzKGHRHbhiY@>n$58ke3HaI^vm!KQTJxhn&;6)6l z^ZUqT0w`|n%EgNF;A6R-6pEa{v0oxHd^wo5aisu$JrJN{3rkP?dR4D?NTVBjGO!0f zO$7^G$dGGPLwbWSR|-8?w_Ou?JCd@Y@@;GRCqT(s3Jq&0MfvR(!D>>yM*PBn+rDRh z2rE!TMy4_xFQ8Dhr2JX@H!zoqWUoIKkA8>7tV=w4l+W0U?&Cjh0fx5NW2X-vLr+AP z5?GdO_Qk?a^!uwoi}v;wBAOqQ=-KKqv+o4;GkRjz@hclj&Ol`>F(=}i_^b%G;*xM3 z#I3D}%nIDYih`fWWe^o+%`%9l9;iCjip1v5h!}X42U7FeX(DmJTkiB)k<)!ab9$P1ioC~Va9h3GWhll1ez2m|C z@bS%cK3Q(?iOr{IuzCv#4b&kuc`NSQ%jn#>Qn%pwYv+lw1hdAreTcr6wFZiR=B6*0 z?vHQkOMw#refKml{0{H#p+%n71=%-$!QcnlHwkR}IVhNHAMb5CC~dOJ@0+{7yG+Lcb-ha%omb=JnttTo6^IOz4V`WCg>56VVAs zj{;TJ_kDj-gg>AB5tzO|Qcw|OZv?dCe?_K~*}W{?jfdTX7i%Axa|N}0zb@%t4jhPv zc@KLU!;`jiELt-02vp#WzKD@}7aYmv*_AdLgxJ}$rqxZ#7vdNMMCb7kcc4bXi}ich zFpvhW!ejf45gg+8qq(hq4`_C_@k+r=4MO-Y$^p#VOo87CU|Ax3H~JF7sxXiR1D?$* z`85d)+^daJ4gCBZu6FQhBy;Zi?sx};d>Hc}H22}Dq&kqF)dEND_emN1#Q2WCj5$Sj zfY{hBu=p&?{G!Uu-q8nY3>{3s0kcC%v$4SCwxrM#)H@~`-GHaL|1v~4O`r_8Quwm=7B@TCA9M=G z&`gX_84G&5JU-%bUc*tF(8fz!6}16!Ytbo2@sgPqju9Imq)|HV_Ni7uwEGK%Uc5}%?H~P*xA|$6?13M~p!EV8wtU?(*K_a@4rKv6 znuDO0!8hGKB!_+oSkFZz0ubcD9BXF@34_j%B4!e%-YkEFClKk>6QE@$vcLs+#-gVC z+ZPND!@$k*suB0#FfrNNhbfGo3Z0gfa1Hn%+m6-Q=Ev6%eRUC&+&}TZ zKE8nYR!6e`S8NW)e{ykz9PRA?14+Zmz(~Nx!KgzgZ{TQR>rB8%&-5*)NGD`x>-=4I zB4GX(Ux!Z7?q7f#dO8^sV+(`-tM`AxaR`|I0o^G68vsY%z|7>o$UOgQ`8ROSzmstY znE#>dD1O6mzTeEi#{93se`o8^DVw-Ee^YtB^$6+wH%Cly>FF8&G3Xl}^zYAX-$VRO5i+v*U)B9%)&Ee(z`?@)?}Q?)|Bfj79)SNO1+7M_ zYdP&Pqxv4Hxw|`>8vgkyl>#THvnsfpp3Toi4|>q^M`dZ=A%bp=v@6FcK7m<>f-c&d zB>U}UQlUV(&|+Tr{?6zA^L4`n*`$o3{`i$wk}>{3!B)gF|LksS&+umGA@+)PtS?-e zl5mWo=wjh@bmM0N_takfjxC|g`?Tz(Lk1+tsQabWrViqo#anZnNc#n6)Bc7^EE^fy zz3r|M{`yvX^Yi$6d8dQ-GnuYWbF)S+@5}&8X?6Zlt}U%Kx(!iLQQV@R>kJxZ3BOT1 zwXzPnJJzMT%xZ;5f{Ee~;6vwuc~Xa^(Fb%kDyFB>!@NW!XP`7*;l?w*#NqphuhxQe zdpKRyVkK&8EviYtuUU%tmSI#0j%rbMYgq2l$Zfd5N&bYGHHY1fzeiiY9p2icHj}A- zrg@`$eeP5?xcT|Z6U|?WTFy1u5L;kXWtxMUx_j`beaVvD+3iph@8;Ic|~CsrQI zHeF&-`KzXl;5DjI3}V~dRN+W1Ig-{XZ7y7>u6ddA7;Wt3mH zQltEymOy$_&`JR&lXma`hU+g8d4n*-O3Cl-` z3^UDABFToD%9ABy5Ttr@IqYvl@rIJxM|6=vE}WfgBJNFhUx0osfaEs40XAIGJSeF^ zIFF*72)=~_eqp`woQ4(d2ZcgwRMY$sqp`?VvR9Bp{^x7k;WV=e+ zse>h-19BOW&<5e6&_q=*ieGES!u1S^;a14$e1C$9PSe9kmVEo1G8r)GJv-k;E+flopU*1xQ}(TCJj&y0W5LEH^E zftZ_c5sr}c(9qU;mRDg1np5qdCcOT^+LX1a-`9$T{bMN2o#1rJiHM_U{JjyyF3f8Z z;V$F=31_MXROGNXqf=4i+=Zl7Y2g({r@Xc=dU&0$oAzeAdA-S!!L9u945ldLK*D`b(6ebeKroKT(D zz{QcJ8&#p*91v~PWh|O@{xjLGP{EfwS2cs!cHOQmgy4nZ2FwVx!52Nq2_DwpR{7ev zK=^R&YsK47YhwKgc}q;U4o`b`hzdq>-~s$!~n zU$R@l-cGvVzfOG#EW#=+9mOs5ugf)n%cMoY=a*DR6aYRj)M}Z@54sq2&WEXOBG(0T9}X=l?Riq@E`yc$8H@|u=aN} z;!7gvY9Ncz@U5OlZ~8L<=$M1iR3)kbzn&5(oB)QuLnD^3=NlxvSV~_5T%Hc=w#O5U; zN0QLMV+S8qGLB|)a5Ujs&zr{_Qw6AmLwzYr%+lCfCsJ0WdAbCDbW;HRz(Ch8UA#?3 zBP|4coolZVe9b!I5lvKFv0jHkTdh(dJga8#bS6J0_wFUcBEe1X4yzT>A!*0SbZ=uB zafX)grx`zn<65&AQ#-%k_KyWa(*-tRb8H?d{%9vD6v??R?+J&n7-9kCdM}14AXfBb zV*;<6g6Af3I7{yBWT8`K>IHXUH+Bds1+?BL%D_-6c4jyi1vK;QMfqbyZHX-NgNx~o z_dWMx#1|Z*PUtZ|%3s6jb7UTCHMymcKYt-pOp*`!bRE1wP^tDKBGqV>;{veS zdGvK@odc%m?%`Xc&=U|(`UoAdh-W_o=w1T!URe=s5XtrfB&hAD%)B3pudh2bt985X z>xt0*a&!CLazB(oM^+#K_@7*{euLbRTu;PbQ9mzYcF1&OKvfq~l|%1Mv=WI|_x8c$ zAZR#z!wkDdt*7-yPy=*KNUqx0Ko7A&Nx?gy$W;XjMr{n09wCeiY z`}#cU`YiFw(X-o07zK>}d3lJ^yRhQENblO5Qu;Xut~7FIbs_j=J2-w;v9IT+D@v*7 z^Pa8LwV4t(*NM)7VxsHmbMVw;=FypRJ9}0A*l@CS1!(kXZ0mj=72%r&9Ebl6^ky7u zI;x=g>RsEI-Q2tb45``V-mUpf<9^-3-lJwcCTrx^oTiU05$SZ{HBcT^Yd(m4jOvqo zXAqt)Z0Hp27;Y+}j!5Nk#t3ejvHFM(jLmr%(Kx3+?os8@s}HADidM%f+o_#+PY_aB zK=hgEnw_t|eB;`|YQKLN zJ(sdN-qbB}jkksxOLT}H4_*I=r*WO^r$)7Y>H?G$S7$xz;Acg5+21ex#(#K!IqJgS zBt2F*9d?<&4|HmLtH)#W?ug;mf+hP}Ck=>Q9?|G^sNJ+ES@R z6gL_+J#5eUF|{O~4>-P|MQhsEfqph@{~Dm%)JUVa`BX;hkXDmkz2nb+7CF*8Ow=~} z!a5&rV_lW$VocqGb*w30uD*Hncu%esbMU(hR1%FkThpTW1uapDpLM4Kcc;gGv-ehT z6;)!y<71B{7PyzSU`G3vN{jak2c_rWHmRCbML(jSlcrwZn*BxU?CL<@v>Q{zDO1L6 z;yp3Y_~mio?%|161=8{Tl~$*V)R9{1E4%SWRy`wurQcCjH0*(lSJfRwZ20m2U$yEFrQ6XXxgy*Pr-VqmV|5blY)k%@bdvjc--2 zC0ZqVZdhSkJ@E&5AsyJ)u=yx5BAT}Q5ECGFifYFR;7zPEI$Vj}pv#yn!4b3$Q4Rd4 zS@wnEisc{aYgSYAC@1pk*_vw)3M{s&w6(SyDt(>Dlw*82tXK=u`&^{2_ygZqe1$X1 zgKlk#d=0T+YVaYD+?~zvlB)RC_-mpC+1mAYzX6h79*YD9) z=(vId=d{2!OB8&H<9xTs>V~UiSzOCcM%$k;C3G*Tr8OWwu2mr5F|muA5;)T_h(C54 z>i7n4rqV7o+T+jsYg~uuyqwyMc6<%(Fa!+ zPQt?+Q5fa;D!Ju&GsLx97$-C)kH~ZSmB%IA>nWZ!SR~Gq#PaMUjy!<=*O7uKf=blX zL&CF=9b2B?XioL^q@cey&9?HFg4HHVY`(l4EJRF3P)VE`idELyAjl_tSQjT&MS#+S zYxSho3h71r7Wtf(<_?~_tft4o(^F@5!>N~GI{vY%)8nW1+I;Wx$O_kElV`ILkr}tpS?S_5R(+#?(L2(DdiqThxN5|yhXpfINKGDpWu;1V1+pRTrxE5Y)Dt0x8k!0?w!}+1 z_*f5vol|0r1DsR3w)o9hPG8`iRpCMdCX3moS8zbHRi4W8$b7A=fAgEU{Okwfv?F#m zhR>}xW^MMLT;nZ=1s+HxVCW|(@QPD_Fx0d<-cegK&U z*m{5s`yD7FO6U|5PzU3Z`wew4cFzTMATaqL9gK7jv&R;YPo(p5){S)D=^Yo)fvA20 zop*kPw*++X8#QmBgBH~fpu=8VK!>w;0UfN0c4&@V7C?&<5S)2{4(8(d06HycMFr4l z@3gLZfKE%=FAvaZ**m9!PRrH{20Ebin*nsdVLJ_UKnrdO=xlleox=&BvpEJjpvMJt zK(7y=)9`Bt=z#1O&}nb;uI(y@;sfY_lj{LG7`{0V(D|m?2z1Vh382GC=m+RfoaY8Q z&}GqA0Uf9_%D?3v(yP;hkPc{~hCn)01Q*hQFxLz0K+;yZ!475b0z06oiwt%S9bo5h z1a_#4$^kpnxF2ArJw9I;>`^9DOu*zGQX{?r3@FmmcgzEnlKzz)Wm=1qeg zD4Y5LcHa3pP-jn;q0X7SfI8o%(_31N@eNB?tC8e|?zR|7n1$B@;^oU(R!Z$M&iTs$Ltq4jqQB z%?VJ`UOlk#Um1Z%&Nn|e+t7u+0uvoW*XEqBVwC^Fi67q|eP?V#*Wu`Z4Vqh|w+PTB zjD0!gp;@(1Jr%26o4VTD3vQ9y)CEqr>~p=@a4bs}W?n6@r3;Kc&fniLr~$nov!BxS z+ahN?wsG_3Y?R!Zm&Z@e#?9aAA#M)d!M3~98TzQ{2j^0kpY?dHv^XfRVo{6xT5C%u zwpSHH@wOgly#u{qqm3 zq0Qm-E;zHvY8(FH=)B)x(GH1&JiQfGAGf-6)T~=xpv~IM)>#kb3{A|*JChpqo(yy? zfG##3A~)7`moKdQ4obdDyk~}Ctji6$+k*1Y7Jx6>vXwyaK(hinO#XFGm^L(E`gYG@ zFdp4f;rDdxB>-wY&af3amJO5&F0cZCtisk?`>*XjhJgC|9ve~1?7t`jI zr>n$!_@XRf3mg}nxLxs!;OKT^*8oH7@NXEWT0xItgvO~=E04+T^yA>t=xLOQk%$^% ztTLBA$I63=R&a1*^oIubo(!voRk)n4A1uU&ZYN11yFjww{G+jQrX{q?)fn5^moI^9~)M0!+YU^?2$8#0d@b= z8x`|}M#F!PYokoPKe8_4mH~x(VlVJ9RBrEa>$R)}`Y2N0rwQ-6r+Pk|F3aL24WFG; zj|YyFHYvVC^)EQXcV+`f><>7)|AgYg>Kjknh>T|sC^&5m4|_D;|0@0^%Kr*$tdxCU z#mYXmgFe>=mMk%43*dG@I{OfluyXjt^A%Tr@85^^T66=O#HMj7mmF`-)HOU)0ceMpSp&!*l|Th0*tk` zhD4D-H>NMyaOV5$miEd~!fLnh`{--YwtxYdoKtX;PYgVdz36@zzEDnH=v?BuLyPo1 znLUQWT%5QIs%Hs~EIYwjq+{Riy2RV&CmqZ-;zm;TNPGd{;#JCXBsLRIBo#!^+Lri5 za0H1_!{ZH$D*~AIW9uBRk}rlQTmjhZvbN*tR>rNEHiMCqx8Fs>@B86%c|5V>AM2V! zbK&!W`zBkYcz}jW&Dw~7Uw92=P4_55@(=`)%YS~NO~vk;%wI^zRg%yH8N zo#qGTKyuOVBy~P*MZqr=pF7%!xmlM7#mF8P>k@RLe`p(avtK3NVW_TwGKRZDJAL#T zlD{vPAXD$yC%20I_*`#ZgsmByhxuf@`)R+eCnyq*K#=;;%C_h8^wVNX4(rKi$KJvc zb#2EXN`GbDm-%E=S|hgkWV~pklw&^`Rag4kd;&&X5~#{%j~1Cv4jtx`%?bO&ctOR7 ztIlBrFhAe?;B4~=I?JWK%_p04zKT))3nzZO9aHWnW1CM7N9Gd_vrR@^OU*6<+k67f zvXBr%w`38K`2_Tb^#pU7;&@mzx8s;kF!e13$@29pU4M>y7fbo4aD~Jzp@%rb9)?U2 zqdz{nSbmT+^JBF1}EYj*CWWcTF@NGr0To1#nAy)fyyybi{D;FJ%66xe`Wz)D5~ zG3|%u^TC*gzOqFeGHeltBU{9nJ}lW5feM?kfNT+CTEp8GF=kP(Y>Pk}^SEsh=*8+b zMvT$z_vdZPoxV1(hlq zFcHs(^@10-=`Io0$aQXC!W`l+){p;<+BN1{ZrNubKu zxCKwgFaOW|)lZJU`tSb`K5=10-4N$QFMucoT~$}TYP!Dq z$=P*7J|8N#sC&XfI?GjR4&2|AtETI#pPXIy!tC%GG3s6oN7;0hS{(+VeARS)^^faQVs+Paef5)b>P|(TMW^ocZVIh`)ctM>>!YUg)lbf;J7bf)6=2Sz zd*Y(*j8_Kt#9d$gUpwd;^{ zYC2#2C&L}*qtz`BFVkJo{^%#iUje(F7j}DxZhi}PJ+2%3aozKNfaiE{ z`~+0*@|pi%Jh7_{XUr({?_qR$*3%_Xela&k_EvM~lnAv68mPMBgyp}>SXAd@!+()e z@YE$WG!?zF;G;QoF(B+yVKw~4n*%x(<389|3v{!8k5JecaWRqQ#x)6ksSV-PIb~Pq zO%}~V(+!Frm{Vm(M3pce^;hSiQ!rDa6Yu8!$gfy$Z+g+*&R(L4MOOeAr*&w20BK5_ z^XKAdxc__~e{D-q=$)#feQC%m&KypGyu8d|V{lGGb~81h;K zr(f=_py`W=F>RZ^$5fm@KZYy3Tay~U<$80r7&jYW|H8qmMZ3Q&kLwT4`3lhDZ;U<3 z`oTTqU8ekvAg}85$?GuR_c=0J;JYJCN z*oGfk@(k#12}A++*Fm zvFRR;fWd)nj$g2{0+~ih-1GD9S+qR^)?Ff0UDL=n zze&VzXkB4!d1-_-r$>!+7r$5~rmtNR*T?J#SsVlrjT9+IS$pZ(W z%CQVCB6Dn-osLFEiRLecy-0LPiJ!2G(_y-!VD zM{)@cIpsHeRb(2q#_)6hPY zyeHOhh5$#HvTk1_uJmg0-SiWFFu{S5L0&Jx$vP{7p4P(zTQG-NlULVKto!u}1@y39 zq5Q$%c<@S$#0OphhbqxeHZgi!r9uO5wC+j47vxGbj!%CUFV)FsDlY&smjt`cw!BWB4wmUKTd;7^2-P*`4U2hmv|33qjMQyYWMB=a`R)v>%z=ur7doI2AwvLR0L5mj#9Jeeq$3 zyJz_TjrgUkJKkNw1KoYm(e)$}yOl6u&&GgR&O($=7c7C44TPq>{T2`X=ss6PS{4hv z&pdQIDLWiHu%HH?46{*j^Vv(P2c9okia^_S;XMRY#|B|tszp~oXr5rEXR41&bKx!U zr*12X$8k!uFDpmM?{NJo92Uzo(DgVLJy%7G2;TDnq$~kJ{Qz~Rt z%tmY)(0^}EHe6}`clqD$^T_ZO50qV>*R&QRGJ{ht`49MtA<e5<;(T^Sdcvj!%{F@qWQ~dI+TBG=Uk!Jc8*aH zfEZp!eg8)F`mtoyI9vr<*2}1Gb75dQ0vp8%vd`o}iW4M!2~`14kaRVS`p}XQN+wQ_ zedzAZC&>PS@^m59-b3&0r7u+JKf@D#{MyGyI(GiLPLD7`NDcZVx>tfukB5%avHIBa+er7E5+%t5Bt0B(_;_Am`{%w z`D$^a$_zSAk2izXr)le4?5WdD*r!KWO48wk?{53GPmdh!{A-^cVTF6VHas`k`$Iko|aE3>Gf;f1+q11xHj_v>p41Nu$wVp zwrNZD1KapMd*vlM`SRr2Y|UtNdGei0?|f6a$bK73$AVm*`+Gl&}Z3U-!5ag7q7PYa#bxkN>YnUkHG~x)P_A|Q^;7p>EWl_ zn{#%>kJ%%B0&1S`@c)1Rz+vvywg2Zo>DT}9{{R2^aWnt#;Xp?CC7^P;o@*YL9bVTW*BDPx}a6oJMkIMa5!yHBacdSY$U{y4{GQ%8w+CLi}48L zLKlwrzcTDv@3|1#veYU1RT-Gy`U+&w_~Jc&zv8`1R6KEZiFY%E47G_i3_Ddp>Pq&n zz5_^8{0jgxOjNH7K#Ug~J!E6RLVYTJ0`6MBK&~>?Pkaw2K(-0*DX=ecqj|MPhC%9G z#XLYa(hS9L(HvWSA&xW@=!d;Pcl48-q%yV2q3BjaqYJkzf{}%RD?DDFPL`wts1_6I z$n>%T7YWG}Fa0EXThn2xRergen}=0!&vfH#&ScSgefcZyM#e)4PO3jOU^c!@Plv!oC6_T2ivRgSXde73*+{6=r`tUj%HMXzGO-&Q_Z z>!qt3Ws~RyR$MxNFYb2dB{PA=YWe}KN6h?G3()2>_7nT-_qpJ%XC-npMlddgk#RBD zr^NNqt?uF-E;+;3s`Ry>43D=}aO%*IGq^^s()yHWUM6Nn32B<7w>g=CNzSBYMgX~| zHRGNAI-K0(c*|)`=opUWUNt;Gs2BVVfTxT{_9bbSSup6DbsV@jbZ2A*9Q4X(4E%|O zf9n*uXCn&bnE_QYp8gk0N_RKr*fcwiiMUJ9ia@%O#>ON1@fTgKX^d&Y;pSa}I3Bwu zvYT#W)2w0v-0c!g&swCkNK@TW{qscxyGjkBn~{u|1%)(`&7nKZ0sJC3e6OMT@Dk7$ zusLzR7#_PKp?F1FyA%O{B)(|u$|irS+qvBZ=uD&vhNLWY{X}2-B7bR7@GUXrbg7B8 zifrEH7*-+UidyRyy7`Y7oUYDuamJl?ajUR$-lf3d0g7$$lS_M+S~$)Y$1bIHZE@^0 zb-hb8#oZyz@qe&~Ym2K}s{7ekGlHS8&b~C9i5CzY6`t)gFEy8S1xqB&5WETMO()#} zA5L4^FA>no>W;&scpH?L?p7^xc;;p+C2>W=prNrPvp%Q#PNAV)UDdK-qw${?vmiQ|~g;3MQYfPL!7pL=% zken>Z!o{T8L=Dxgys;r9O|d6ETg$zZOx3KTq*MSZ${znlivYhcr_(O~M|C9QC;oVz zdjV=sHu}n%An5WW*|jRya-junt5ryQ<84wnJnRYU`f<*Fii-6^NYI-?k-Y# zG*&gj!=z_Pu@yxGMQ19vTis_SK2VP#;0Kxe@E#O$0wz8Dq^MP}nUQA975=DBj&O{l zXkzmlC^5WoDN08QJ=4NqmlA!rDPo2FYSzbmx02G(rlaBh{bK^`Z6UwSYwm(`&mBLx zmPC@qzIq&tSP;6hFR>uxK+*StpmT#}#S4OGD~g{M1l=RFYwCS0RaLqc#Not(U>#}f z1)*Q*dqK#7VqR;4?GAnJt8$&AhT@EP7uD2+%y%S?J{1X#VWWz}s9Y;dTem%juM<{q?jzPCmj~^CE@jT%;GdMGjxSE~ zTH%R~C8#)X&DceEuSQKwDVLxCdyBF1i>1vieEDCqX}cay__1T0)K9*AF(d-MRzJc77vb~2R~oh zV=x%_0jkqD$UG&$FCQ4c4O|<*vqxR0N}s!5M)fhqf6p#1Jc|)<{Y4{WQN_y|RG+*x zciz*8_PJ@bn1si>q`ljV4o1A#=cIT;=$yq^)Jql-{v-u$=s=7nuImW#=*H$kO&Ei8 z9YY@3Qdk2!RpO9C%Q?STQVLza{^;(Gjr<@r=|MJz7$nUj`KwZJ;CPA;^Q|eE=F6G; zOw0Pqki0hr+vhZ|v^8YN$&l7yl}R7euAj^ysl^AeM~)JqL^w>%yBo(jC+~JV;qr?| zjVe6VaG;m>yOBjxwUsTrp9}Yo*L>HEZG*|ve8}4dlSiJG+hFpv;VqqARy#$Sv$jM~!Xal?KB`CoKZhHyp3|PgTFxs#UCeQFW(*~1g zRE@L^CWj7#$>!K#f*OPf+Wt)eh%lHu*rr&51{2H%k9;zSP$_LPwAi@*UTnh^PJI+~ z;WC&&dcw*J?G17BNtko_scUtYiz_at$trvkgg3uK(D5TrR+NHia`IjKU25Ffv{I#8 z8SH)UpwObw87oL848D^{611E1qV{*W$5-GC?jau>nvfa6x{8BE@X4T;=KaxUbMyeU z(PI<9ax8}UNw_Clo8u;;(F|@p#i4#-RA9JNrA`YJ3^@h2^-cy11y+jt($a(RT6Ho;XOKYY#xt6IS? z<%f2Lpz%|S=xdiqi?$2U182X4+i4AC&1&2#8e0EGT3Pc0S4Mup%lf(?DYA0BAHT9M zV>3(e{G>qYu#>>(hZ-SDvc}-&(X%Pj%S*nP2FAqkj7{@?L(vC1*c5Vd9WGv@o+VD?rrK*HC!eAiU8kf@k|6VxhIQg7JV-o9UgTt zI;(I-UZuOq-KYZDx8;>fQGJ%F z(J(lg@MG9C(BO;@D4=^RbK>FQC+Avm-vriDTyQJO?o36#%f&;AU}TbFxe`JKCmdgL z;ei=+@1!MRrqMtg@#a+mQK$69g1sLowvoIMY)+awj>FymH#UG$ z`bq=+7ta0b`sxPF(|jHwIUjAZQLTS5=(TVFs9sjh+=&fXT1sIo&%4&EZ>U8 zlQLuvkAvRdV2pWCOlExV~BZP1Cr(kQqSS-I|zWO9=%Ppi#UfT3nVKm5MZ+ls-~W$VXu zjQLCP+tF88G1;Vo+XRp~@1gju8D*n!AjWWdhN0#1O%MFi?=1rN$b5>DbsHoa-$9d2 z#hhS74PMR5#-0}wF)+ag)rcOAREKlSi%sKZn$){hw0aO`4*g&B5kFhHo-$oqdPaV} ztHAIM^hz1U4Q`A4!8WyC2lFCuMdQy5FN#i-c99rdEj@D*+_qVQmMvy#+4W1!bWiEv zZ2+@DOg5R%m(PMg{=WIKWR@mqA=`yswA$`-q_70{Uo7aH|wX6 zOlFt8O3-Qa=#6(Mixiyvc`??#vITIXV;4qY3mItWTbG;#@)<&SdkZk<+9!+d(f`7+ zz9okc1p>+Ry@|1ix4f3jbM7V4Z%qQIyF`=Bzq7|gqM5GY4 zLWLqI1=djP38gy4Z2FSo%-A$Qavds4L6MD{np$@(;FQJztZ;k=4PnOJD$Mmk<7#29 z_@cI358||#{>H&qk8>TH1D^_YogwF#%Bi{QO%rJh3{H|fEe%f7eh1C6Kv%UK_rxWJ zH!pTRF~_K0<8T+L{7qU#gT@zWs?I2()PT&>!aT#uHAI1PmeN$T^C-eZNgh6==9`Dc zuAx*^=G=qxDSl3d+j5{ELt=1z2sR`xx*iL{u2S_W4_Ep5$ZJhGMG;X1yM zK~-RDT{J3^AOr^<&Qm40>m?x$)HvFQT9+l2kvcf@gTYm?QB2V^Akc5MxK)!18V{SE zs>Ip--pwXm=ttuzm1*|w-PNSX&X#Gbn8NgV4h9-GIiO8}`c9R`1bsZ8Lv+?)aUd2~j4 zI|GXw8es#PvQpELjElM{kknITcZBh9DAP5Ls7$K8lnEIN@QJh|RUWMLuI?U~tO9u6 zq4cqpTH={IqchI9$O6LTuZjUK*Vm;S;X_CJm7Mwb(Q-jL!>$rjr{o9s0T*pJxH(>s zRcM&7jp<|+13q9ITg7WM9_E!@y9o*ozP_M57{>LwQ|*p*m3XF(1#tfAN)kPEOej(u z7`$e4K=pppLA=SR zN@c!uJV-I2ME9^2xs|e>_TD^w*KybBw=acT)2G5^LU$b>1|IBU=$ka~we34{>Pukzj;gPwz4qLNRb{$ol=-gG%d}tFCl1?Y#*4(G)nKxjFq4+Rt)okSY zs6uC-in2`m-*~QVEN={Bwve*~(8F9^~=gv)S2Ap83 zwNc>=Ff}!_l(4Bo$SJ)J2WNRjYOET6FFhOeq#0WN`6yxItj`Tq87zoRo3+;z+y#i6 z&eJZ4y_AxBX_rJ2$P~J$$pIYyuSS?MP+CGYb)9xWH zP4`khifwuy#mu=5I!O0k%ilN$pT}2!;q0RrdJDtaIf@16`by*c7tZzT{^|$kI*M(M zk78A+H1}DoDrCfU7OT4V-e)n;rJb`F=rQiI80IsdqZr6@^y2KdkE2+v3^Q<*s50>y zzE#G;|?)>$t45lZ^iB$n)X7R zs1Q`#r&?1ZhwLfY!9KIj_;2rbe9Q~ls@pgC9s3?sCHjgBR-QL&X9fzH_W41VX2Nlk zdL!lvm-*?}_qo$H*X?_7&F6?)a+)e@-xtb5?S2I7u`kzXXz`L!(9NnlL?1|^Yv;&< zzK_cc&S0!EXAGi%S#%)LQS7(kVprYG(@_EMf{I!>h;M?%E~Zum2flgfSJVKs(ntJ8 z66)(U-&6ITdeu9 zoY%ZpZqoyRzi^HL8}&VX8?gC~^BAm|9sI+7jTX0c7wEDHSSZlrb(^nw_@Bpot?SKW zzNWRI-u7!|;jYJk4chm544nmcncL9O!scuHH63!+v0n#$?APX8Dh)sX{Ec(juY(iz zYwDGC?AN-gyzSSztUT(5gH?|GnnvY$+ph_s%duZKTP10l=0)W(RipT`;!av6o)H(q zv{d+I?`6COC{5dT%_R5h*sg;LqW&b33)18{wEbRA$0V_{<1 z;h7Z!RVubKALFeZ`4vl`K=zUXo?>_zSBGB=S$dZfVc=l_jAj|m)I|>uAW2BkMQKOY zLEXqFM;4uoyt5B*pu6@g1}!wX%?f7Vi5%NJs}As5q)Z)L&oSq>-a^nOpf@;dk&MdC zFCm)XnlJPb!qtvNna@g;A&3AkdkosVAt0lY%KAb-EXF?787DJ%?cjpLY|UqfQ}rD{ zftu#b92YspAiZ4Xe*c(pB^Hq5H4kj@u*}59H|S#ufjbJVzJO_uM`1l!<`-!(q7a62f>_CAJgcVRE`2v6Be-XCRl??DIqxG&r^ zEUoT+aI|cdds(i5i>nZGLa8dw(2IyckTV#9mb#G>Jq3wYF(tGE44!>GCDr5H2ZFOA_`M0f(A^L7pUH2(5Om%$4R1X;G zN-lH36+8>emwB8|iq^5!@lja4jdgfpbnN8{$vKa$ZqwUVw>h@ep@Nc+tq$+Zo_yQt z96WT}>d=T@wyh4a5wTGoTOC?G*RjIt29`<+jz4(~hl#6DPd0Xqiu_2V!I^@G{$5;n)=G$1ugxTvD z>yR#+j?FgKZF(E)f^&>@=4@jf=(LWp4s^|zv941Vj%r827f+aXt29 zhwG1hk+!AI;l8gDO=nu0l^At(+?Kj7d;GT4L64+zEOiV~JZ?)Jg})t3-JUC3>NdSC zb>C*wJ6h=i8QW5ah(Mo?#0=J5j-?JEf^J7*#0cv7w$w2Y??(yll3}Q0z}k9S>JTO9 z_9J%G)NQJB@W2bFfpa?&gT5V!H@!`D=3Is_#I!8qZ=7@Hi?9B|*`_)MMJl(cE;!d$ z8tA`pu3sww`$5O}Oq#u67jF)@)5i=}v zJ(f7ke>+|jzZH`8_9JF2)pcxj-=xfu4|@{!K47ZZDLT+p8)54anrcle?Z7E!COv3M zuNx1VI{rOIQwX5d%T>Zyo=^&L@KU>>6at$04wzVqu>se?Qk&jbYIBUGKzm&hOEF$+ zy|EM`bft2z6vIWl{I;=8M(? zr5Y{c2TJK#^np@%7F|D}6gd5YQax#>4JdW!fKtH;D5X>k2THXiOUHpyZORH1P)g60 zHj-*Zu;(DDre^LEb!}sPa!lluZYagED+fwBdgX>vUH)Gel%j;B8%lvQ=7CZS_}UJX z!uO_<#bP-q z3ZtJc7}aFh+AvCw(Qg>lBxQl4nA)iy9K|#cj-sk(Qr{=!rmMNMWf1G_F2QlFzNDTYg~l9 zZMp+OR74gS@_&E_9x~Xe6MX8g?A4DJwHSXG)|bWU&omxiY$|mN0{V8n&&W z*2Cy;?1en=Z5;50Eb{#_R56i#y}{S0vW)H$l{t?${u_zN}Ubnq8wdVXyDHER0m2Y#UuEpPZWs!+v&UuZQor}5XQU3ks-3%%r-Ht^S| zQ|jFK3j_1?gTF9vso(f(D89qSU&zVc*1=z+CmF{!{vxLw{6)GR{B_aBUz=n6HLTSF ze?cBnz46yjDzc5g(8@6myn;ZabOSJ?l9ueFA?Czl=Nh3;nPqiuj8&c%EKy zB<9D(-)KWicb8aSj7X${hs?#ok$e_^c#SI;}>HDV593jSOBo$ z2loenf#dyx2n_TZ2ZC*SW3b>H5N6IsVMuBJ%!9%}mvo^pFj_e%Y$&S8Mq#7R8*_Om zQugl#%N*k%}n4V_p5gi+<@8-$^iX>Jh4 zCD{(d!jkpNdV{dhd=IrtG(D9w2!m+nc7w2?6pos*&z3>h zrZ))tHlNwk z={x6c_-8$8_{@HEw4v6_eo0`cHFFE!TVk!5OFY&w)|y#Xzrb1(iK;FK{)t58H`JQ& zeI9p#eQiysH6K6I*-&dfV=Dqct@(6?8!^<{^oClSW2iOt(tATK&_0y5_+siYu(1|e zQRl{56X@lJT9ZyF2Wrh!4$eXsYrb&SBx*P~3xi_27jf21wqk9Zg@L|c*37;^G|ZZL z#^J*-i=1^}7U=83@Q?;s!7#=GnGVF7%))aaEC|AA2VtRo_f;Uo;5mqkeKvxM5=lEu zAS{fDjZa2c7`D<6#G0un#(^Q$O!DeD5Q~ygZ-|9?%;`WZ&}$xug^7Injj?7jx-`a` z_KY&bLZb}146)dec_0=i?*dR5idk-rI&ogQ3v``E4Y4rxrQ8r}mgnHBS(40C##gf# zHEw)08R2omtEuRg8(x9#G@QNDXpeso7IN%CoPB*xs(B%WJrqXzBaJA_GSDRsQg({!4 z!4;M4yulTknCb>s6ygJ>xLU`!!PV4rp;IFJ2yAc#q0Z?BSI`mjU@MHWJ!pxopi@S^ zu@z<}uY;}jOc`5kdSk0^bLnlY+7Wl}k+aGcdgO+Td-v68?gs;|e|d?ahnV4WJZ<{i ztGMZY{#xdWKY5jilT^ob*6hqH7hcf#pewQlLda4{_o|2TuMh*=&E9m;FzAKGFM9ZS z^6x_jWw>!+gb{5`51sUkj~s0ZjZ)HW-bECPe$lvQmRtn~lkcCHc7x`=*jqfD8QvLs z4zHh?-RsM3Xfhnkz5gTr%Vlc8I48~C;^K?hEDq-VZF&idX4QKuW*=#qa&vIrovOww zs8XfD)G@hWrmi1ndt{GlGC6XBCGd1nM$7Yghv^A!<1Vp8+ld)7ob?!CcuVV9PXiFs zl*3u#)yk;tqWAmJ%~>%4SsNJM7+Q*o{CbA69#YI~s-)Dkv7MN4V~u{)wP}9gKnJ@- zijX^+|BT@`9Z4{)WYoQ5>a5fx zayzEZ;uGLsJEqP`CA?73{6&!S>x!wfo+-rWm^$le5%i8Sw;q|ZFR4_5m?M?Sp}T|X zOnLQRQFZ2=l6ywgnbV3dYf*S8CVCuTkYSb zO%BsIgjxBf0DWm^0dwM4`V~zDi{63ABAFHJMZbal#P=r+!n28VuLYKEf^V1t}9@#N=1C3D*9KFW##cW%5k&S%=eU2%^r<+qIbIxRb37IMqaTd> zhh8!Ig=6@CoM5)xfpL|IxWv5K`dcvDglO(?GymU)yiHjSu%D&M9rBg|`>H~sCK^nF zgCLi7&n{f89~{2$2~I-zb%v!YyroVI9zGS*u-grv!PCj1t9oTLdPYH{XLaS~!8nR` zc5e))tmutdiCNeRJ)TYonmioUGVN3@5a*m32|pq1GWPP!-QlK-BGg|Tzj0{XmKmRv zuGUT2Wf8&DiCYxNnlVr5|J$;9F8dUd!xRRkWfEZbBP9h|&0Rg6Ns(IlNT@0;JR`a4 zH>$#-BG&7}5^4p)*p}ka^_=RY{ zwP1MOH=P_Zo+KYI=v^vlJD64_6i>Q~R!_P@%JLOOrHPcImn|oJB*GxGbf~WkJ^j*! zGZpznvQnn;3mPjpXH4-^8U2%U$~oM0-Qyb^?vJcf0acT07+*z#RbxIF8qbNs(Tm3+ zTlowF>69d>PM=a4L7N=DT`J66izuR$+)}+-9%nX*kvHeh_qmAlJ~5hYr}s$`6F%)& zmb0Q9LSyVXuYL?d*vxRpdSIe-MWCx++w>q&zSEa&|6SqYSs~rldwjl^Q>SYb8_1kF zotHT51gF9@V>WIWB1Cde>~Y4*Ht=!u~)GtL%*CM;$bVAGEPX7iV-0B7kfemjX&k8MSHV z%kdYrXxDozui_CFMh$Gj z!!%#I6zx0ooO`sLFiii_>!q4E{ag9t>PHDxs0Sp=IH&u?9^(*6BK<5TS;pD(HTEX< zoL7P48qLKkMWPx#n-PtX$vwW1Dqc<~i8ozo{FTF`4C45!pBzLR*U<2am@qoe56=E5 zhWIa>{p0(qpB$R-Zw^GF`VECbbPIv$&gdfle4~9~#>E%aB>p-WV4|F;lL8nfW z_<>G*E?IBr1kQ>Tn$(I}4|Kvqwl!|(#5a5gIpIAXajlUPddW>`BPYC$V=e+CCk#wk z2RU_bkOw(&sK-H0c(1hbK~8*9Q*Y!%PCv+r^f<`rrroN|(VhUhj)R;i4gE$=d^MF1 za_YQ2-mnPLAe{3ZG>_05I#EQ@jh(>Z zVaeF3D|+w7PMFYIZtMg>yiUknrq2zX_|`Gq*opmU8#`hC+6A6^W;)!1oiI>Dd{F=w zp5xv`-W$dL|q!kfCM+}Noz^Wlb0Aj?5c zn+)I-jE$Q%L$C>CO$Rpd5nsJw6F9RU*woAPQH;0=r1t;7O&ElFp8#<{j=#pKvet%8 zproIw2kAqh>FGl(lz>ef`efYHl}=>irmjdN7jA+CbM6hCdZJZ#11HFa5JBAnIka>Q zocPps9N@(Fy>kPnt}v$?ICc7B9N={508YUP;6(j1H*lhoZ8va28{37PAid8#xCr8# z>W!SRlG8_tW=yPqI|Fju$f@gsej_IgbBRVKN%*sFLTf<}iU?9GgH-&GFF>#`R0z z?XUm--A;N8r0-V3)FRuc*%wnPeVRU_)UGZVyAhcwO3F0=f8p$p{);n&!3tl0W#sdE zlp(Azfj2pgOBWnu2}NQq3P#~O*Oz`IO3-*O*%=`4H$Gq_otHC&5{mM}r*3Q`1(TDU zj`_txf;1%Q!m%<{`jL|6flOw$pz%RfrnyssXCBfL2C8ZPgf1wO9xAdCTp&#eNRu9R zy)+eiMzS$?qp@ywjG(Qtb?SG!>EvDZaEc6?P01@UmejCKx$V+uhGF0!d1V@1OJ9%i zGA!H7>{W>#NIS!MRr1ZGJQo}Z7Fg7Wsb-D+bZW_WY?<@;i5Es1Q|N0t5e9Z3timYZCtCkeGo}*bTGF;+o$sStE*CD+eqa!R( zlu(xyOfTrBj-?z+{&B}7GfLme`OP<-y@?#oqYX+9Z<%@L_=Qr5LZ*g)gZJ1k#|PRn zwKk^JN@Z3&%4u)0Rx%}57z{I5mL$7Rt;dul`_pT_N$@7$W^xL(SRNVr+mtFB(|bCm zY)-9Uw!8CsnQNYz^){WA;qu}!eK0Cai<^|wm8ujeDNS>bXbn6i3QfQMx+vLd(gPpPf|9B7=P3)1n#M`YZhLot z#YD~1r-FQ3|>YXG}xr_6dwa zUJ3_Ho*$3~b`TxL3{5W>(fDF8Ao3|8D>7@~u^4$!n|@OUn-mXgVb@R&T70-*D7-_tmD4f?oJvD%njNqHB1%kcitDjO=+RKk5u&zu z#N-lsY);@pSK9bPk2o6KoMx+2cTbroa=8tohP;iW?L?eE;xvf`f5b^~lkYK5FlUdg zesnOz0C#(?(xGI?Nok2Sqixe1itOD#N>~QE_n+CA`x(>XRXTA(mW&OJofhHz^<74J zTtVx*6a!Byki(}1N9(IjA9d4Nf3z9g3zX?I%T?fMnh?Fm*6pg-r!rMNkMKq} z&RR=Dr}WAf-E06koTXc-=kfGppF+7sYj07)ttT4=onzxNDv}wh?;X$SDfOg*+kKNs zh(F==YE#LzqB$_-E}_)Ts36(Y`DI)mOmTJ7A>DOs*o?Dg#SJ zvy3#Gght>&UprTesS~E9v41rC`b=L)Ea|XNZ^5N?>=JEEu;q5ze}VIjD8m}LrZdT8 zeit6uk%1bswZ=_1`?eoW@&!B}YHD+u`ibJb%lYgSS4moCczXKLA?QW_&@$|2xl0W1 zT-Elt>3xI0EwN|fZ=OPu4Owm#`|-KhyaHSD&oH&!zc&Xyr<}BEkltl>ME*nyW2~4s zVx2WrmXvCgz`3D{W@k$Gsg3Ebe=BV);`X^bU0;a)jW3LUcL^UkJIxU~#Y&x#AHis@69G|vv%O~R+LVxoY&hnt5r`0AHC+Rcie6`2;CntV< zfAoWaG;H5EjKM^@S?w_`=M#t4Zu0~<#7TCYD!L01+^?d$;lHeAn8_y$ibXTq0}N>5 z!~W=5o3O5(zt3&K9Hc*l%entjl~$}gzWnQ)ro^?y_a-Iju#ZE&GGv;<4GnUhQW=Z> z?Ub7JE@2oTBLQi_fMN$lq~#o9Ffm!S;%E#oq%^8Uw2Yk2>zQGOs7mum`-03L$O5Vc zOoJkDs@F_%iC7Vwtz2yWc)aH$*X#OF`-N`v9~|9t(9~L-^|aZPnz&tp=1~SQA+mCu z*4P}CW-R-})#Wz{de|@nFJq*CrDa4hqwz)2Y@B8&`N>Da=2i(^%OD%PHa-d4?PxOR zu$`VVXX<0HYH%J-I<6Yg47+(^#G9nXNf2YsDh)`OW9kUJucFZSbS(O}hLcKYmuRwE zE5_D$!L+pYV+4`%4bD;Hh3CYZA-9|0FjL;_qL~xgM_eckr@>>BWMpm1Fqpe+th_B+ z6jz+aoDg?q^#w-PU(9l-Ll%G|$4eryBGFm@|jn zV{5Bo>Lcx)wr|}L){O_`@^WZ8o&Emj;_$pdx=SlEbrPcS|H?Kdvb;5%5{+f;lY0rx8~TJ_cj)DKq96YJYmPmT;d{l%K8Hz!aIvy0n)v ze=5(I?J)QtXIr!$d$W<_8?O;1s+ME^B;BUXkv*d-K8B2*!-@P%%R|Sx&!hqHMeMti zZ_X(PZIk>US{VhN{Qg&c|97A=Yx-Vrour0JZA-HThEI!sRJu~iO58FFWw z#KF+nsA@9uuu+s(iWmKSMao2T00flvD>!{>S><7ywH|K!(%E20vVAm=7=I`)%3g0J#~s1;c}$QkAyo=2Iyx=M zY2&O$8S%~RC{l`#O%6Dch9FOC7%2#wEQek`Fq>jn`z?lDmeip{NY1Y)+snM^Y5V`- z3`y0~-F2R%rDYB8pB#Fqg|%gQL577mOOo>@t=jWPfpZ>sy2h=0w2zX=K0_$;=A(Ps zKCD)fkD)VuBd~S%_OWM6Zg7VVugY)p>7A@J_cnmp=4@1oBz$@Nm9s4=NV`|VUhN!; zzHg$0DwyGANMUcvp0-bwmX?Yo8xX8&6!KJ-bRSc3fqD7*kln_UfiaF5RHp zn1U*w%b0>(k$d$^SZY&0c8MxcurY=G`Y@)T=Oe7mNh2W?C1VN(s)x&jzeutM+L*$e zhrhNhWs_k_3C3C5pL6Jm9oX0O?h( z00*J;q|Qc(HodmADKve55K5~y;ToYd-{S{D+4M#zn`4C1;wWc`qNC=GQCicK1x#t( zcQb}5Z5VHFn9{;a#xO-u=(U`h|%W0=z8rh3Da;nf{5W!U+^Fl97h z#{*MFh@oN1Xlk=z%0;?On`4+Vnw=G_xkuF{*?}n|Z(9ms%J4O4ppZT-#~Y{gXl9fs z`wOm(p10}JI7R!_!6~>6_;p}PTe@Z0Fr`)3xM50b_E0iRi60Rtce~xR%-9>IK$m!El~L1&iGV4a-Y_LN2c`rkV9N9jW5ARdmk=AL zOx?u?Oqpq84yF0b63PQpMqGq!T{dh44V*H%&oBlmpK47&CDzLUDx*mA2T&Q06uXg1 z@4K%?D&2}GkV-H1HZfA^S-uS$sXz^+Uk9o5$Jf|KDl+@tNJVj64pM2pBMzjp>5Wu2 z$4I3gzrc^ z*B@E~>w#9MGkh-l3oLmqGtA%xRS>_b93Amn$vOMDOAH@%c*tV7;u5o@d+Y$4$D%X$W6arBeUv2UQWVU0e2-d^w3Q}SlVg@c=qP57a*FnBD$!}iUpy#S{fay&{d7Bcow>7K6LOG z^~13FO(!@sK!3KTl@}l$naT?+ya4%r-yRzjpa3uS1Z;}tmX9Z33wK+40=6dGqoFQh zU(^pjqehGRDNw7oOZfpJPy#XC_5*C;lPW(z#+L{;qYpa#05`{efUKZu$oEeKhLa#v z`*7J05N(_nzG=;ZaI{A2w|3(&jL?rsPt@zdCcph8-6-#gH^7=^J}EW1y#Ox;WwCep z*?RA8a-zGO02>}8^v(GrPQJVVIo95Tn7p`#&tG@}qT|{bL8^d5Z)47{;#h5guglH2zKKEp$=N^cZ@$y}u6#3eRZh}=N_tptbIQId2dCMR*_TR8(~KrCA3K)C zRXI4r>nKt^hm)5Bfo$scKaqy{{JCr|Cq^gulq^4ZPRYA&YzLhgfbZ=9kL!9q+X0@2 zK9^%S>d^1*SBea8cD4gNH!DZ~M}FOVKUmWj?%ohq-5w%J|LDu9vmwlDz#Z12T^qut z_l6Lh*bwI0Zy4ey)>+?dR8_}gLqH=hD;wXre;j!E$owvWkjwRK2+sF;Z3q}#Uh8{9 z=*jL7-Vrvvw}hM1s!O!9Cy*{5dxFA2-Fw0+ev9TkLC;0cp0I5CKYM~gHSIm2>$%WY z`JB>mZwh##Khj;oLf~DYD|FViD?n^g2-^7NG|t)-z6q)}g;n-#upY9eq}?@k1!m~1 zXIJ1;_LmB&Uc%$br@e%m%nnhDH?B5AK&sUJxNWzb}oJ)ANNpxrd|B( z&8BF-!afpSe675fKruww1?HCzQhecDpMAV@z=SgG(`-vLYFKVH;}ev&&lY^VUaFT& zocEX;bKWJgtctcovs?a&$c6fBR|BSM%RbuM5)C@rx@N)1(|A#qXwbzMtQ?q4hb?+@ zHX{Evi+^^;%~J|t5?lEZDz;xcwC6uKXSQb&%Kpij3`b3l9Uhm$TJ&inQ_R*fv_JE? ziZ-2HBHTQZGGVUn+l&-}8kT3AIW?L4tJs8qopFTbn6!WY{)e0u#?j^sW_}0xn4a<4 zOzAA1u-`JnSvK(Ess7Mo+2Xr7XD0AU`)>?w;}>JfcFt}}9w;BH?^i{Bw7%Lt;wh_I z^JTchG%O3GUQr^e+&*$=4g4_vq*h<@DBg$8KJ5n=1?=8oNB%zT(@c*TmbWR&5vO`Q zk>QK_>8Gzb%6^Q+r?5HGM|p1R#lJU)@l^jHsoC^pi?)^FHxb^{k%?^_Ck;$YI>3}A zQukRz!6ZiVjYUshR3l~kgY#wKONSqa0;i1R`-ndLQVvPu!WEmT#1Nz87mbrRif^*{ zmF{LJ`VT*khl|KMqW~qGdA*<=j2P^x_{A31cwgy0G-CkgHp31be)B9bCI4Px7^n8J z2uIeln_Zy!b*mmz4yDN8PdE)+4)1CYB=lLptGmSl5*hV*$nXQY>D!l1ZC39UJ%IFg~(suvVaGbuYp;_l*flga8=xBR^QY(<(hgCWnj-4V})o7O+c5 zl`^gl31xtO7P?JAL)S4I^fO7HpKK@@UZBMQ{b*JI4z9VjV)NyaYu49CL|Xkg6>y-u zzbiGQ`@Jzg#yYlRW!W6wGz9uTyX7@H$~Vx5Okwi*;q5y*JL-PvSa+JV&nE?AdJ!S7 zm>B&$T5*Q5XbWU(KcIaa-fK(;IsnANBAQ_fQ&8ry{Gem#~JY1x8nYKz)r=F_&!mmuF(}_qX7uCL;SH=fDUREeKk}sm6xKaHRZi5Q`pNB81 z6nqF-fi&9+N)lZ-u{LIzj@LmBMm2)OEImcTH_48{Pv0q%(W)^LT{nE?@Yn4Q_J2pnbyt!!7A9VYGh2(vT0uiG4EXLetAQl8t|F2|4a zwZw&qg6v=}@)cwUlV@jL3s#-`B(LN*W1HofxTbb{lm*tDwV9*)AUhP8k03kX z^~c4oL++Cu^JIX*({;8*7rVuz`rj%5y=*hWI9HtK$L|o&5M~EFvV7)@@%n{FN6k-R{Q$IrN%+VcmM{mq#JfL-mokK^6ox@Rx9oBF{?BFND zQ&%fxJHY5o7TQR~s1Q4Id(=dT9n61<5IaZ;7S{yT`JX;Q>>%G$y+Z6@vVG;PS!f?2 zcAy*P6=DYqb=pMDd8{qY7P1}8stwz5c0h(7F|!wb?mo`_G~2!l7itU6IY=XoO=+JT zrj*<7xsV8_p66W1*|XC1oC~RSo^qaZAraI}=Q$VhMCE$F=R&?CIo|L+7gJ4HNj2pz z8d`S4$&SJ=N8n_oY0o@8=Q?ye=h_@U=R%b;Kp|4QFjt%8Q_s1OlquO>&pboV5OVi> zE~k0Q=Rwz8;j9)9x;AHny>Ansq-jwq9&|C0(EXxo#Y#4o5G#P($|!<2Z&X)th<0=;CiyO-gf{C0MEsX{I+_9MHV!dqDS_uFs+R6X}nP){c=HITpX=GpqG}ABj<}N&9(VwwKf8 z_#v3L>e{!&OivW_28xHHfDxdpj~(pytnL zncr*K@iP%3fc(WRich#ZUGdhU)c+BOGYS>8{AwEwz*E(%_qo7~Yo&Pen5LB1lDP

!Yi+t2ox_K+xT-~3JH)n<(DF3GgF{XO|Cv{0R=z z^rasf!Q@>_L9N-yE_%5eu+lwngmb^CCSMLO4qsaS(V+QEUkOoPI>&S2tS6bzBRqqt zfcQRoJIATQecOX5!+L(oRPf+*J+e)TlJh*nPw<8Go+sczNiiCq4Cjm{Ibk ztHWL&PS>O5#5AQZEi{SW!1eHxAG_nC6*%iXujtGqAp|6Oa@9*;1a(5IbK8LdwCg?D z&(;-_1SCT!WH~UJ=HTjrVV5WhU-c-{8>c5t{e%KpV@kUl!O#Gej|m<=Yc{ZY1A;j#Cn{GZcA5PJ7_fus^3{2ph zO$k(SlOBy_dQ>1Y;WUL%8if(PUwS$rdMR1mdKANpvsWe7#RE6H1YcKwm^}&|!e^t| z4n_OuQ88zy7A>~qFBGyI3zn^N`YbGYMhn=q#ATDT2jc5Cq;#5RpBXaebWk}+5O>De z73ZKn(zL!#M<0k-blv=00Unr#6HZE)ilPYgpdT*(MM!S?x57>^ljkmxg=wOOWI!;B z5AskDGrJXDtW;yOdopF#KtGmMO0uHkTOn*Zt4WuR_3Qg4F*4Z#o`fnM37V`9-oiALl2kq~6N8DazZUTncO>r5JNC)eGt< z(d-3f^OW!-E7pMd9lC79Z&>Oagb}U4@wDiIUt37uH2V=>91fKb=&5zE14eXjg_5DB z2w&#>5hq(HD0gjmu_SE?O%dfVx;dtY`|VV|zT&HDE|#vLXq)5*!x$h6galYk4I@Iw zi5bdvgCArhhjjwBP<>FIL_%!EWYH8Noo@1$2e=DBJAYMtW2}O3!DRs-YP<@`@dY7BXnYXQ#A0 z@r0R~Vh7Kq|6ZI)Mf*qZ^SREafFmC8Pmzz`_cKxMyP&e)MYA$4IR-ybYN)*e7k$m| zCAx~|JWBA%fY#_z^o}Q6CrAhAr37b{ON_s_ionn`J{u0*VQBUL^YtcKmZUtG==@)W zuON=m!#ZjSG4-6h{STgfjezSORVN3Ll4I8l5JJ7C{zl&mR;9ZpO7~gyX`V8|a-pYQ zZmEbruHY|8Mfw(Ks8vUk48s9y`>3w*<1nK{0%b9eV10|F!_1V3r~4XQHb-nsBDsAl zBmNoxz{FmD|Jq#@Ynf_0wA4HDzZ;|eiI^ef^pzwzF6Gi-tu5xeRRGQ`tF5eNG2BN| zL4DVuWjT=RRD)=8@h`Y21RL5)wfL)VkGrPsCE-V=e#6rh7tf+)B^5p@(E!PyG`)gy z;4>Uag^zf=%uO{)bl$o)tQfMFozQ^s&jZy!a>qT94{1kxbH}mrYJs;)x|A_WrI`n zA&u)5IY>Yw0rL)@QP-4Z2E64imqJ-Ub$19ivwaDh!00kzb*buxK48PO-Eg>_jkyUv z`z-&&Py`wE6Qd?fEac($Xf3J;Z-q37(jJ=IQZjN@Yb;EKN!e1)xFIrbRkgDwhMA6; zEPh2!ZIRvEFdit`0$+@<&Cex!tE7LuLg&A9pAR-+1PM&DKge*k$UVf_pL?Eb%d~^w2j_a6gE>CljLo+{T}I#66^ar*g}CRW6P#@70#JU4)sh8{SFx!fbi3 zI$|9(j-H>+8Azdb_U-PD5Eld&DSz$`SXF*1GB~?qNx#?@QdnqOY(R z^bKF)-i=Y!21P)HxW`=ab&Go_c+d{!TbMDAxQB^`iV%tT?UME|@!XEIhqU6FuX~~Q zpEpMz78qkhY`?_4I?|T)KqqA$Sr3a=`;qm2kfu_;9hP%sJ&Y>l7WP=<;K+LX*?eR@ zzP8-L9qVIRm@gHG`3FWtcbp1ct-p}tsnOu3RwOomkTcRk*SrTD8L3t!nr2Ht&cb@m zkzo#%Go2rn$RS9%E+rFZQ>QyDp|YNN1RvGK09@BC<^jVC{-Iq7;IP$z{Y^KV9kOi9 z#r~Kb`!9^7&GLyUN=SC~bw~wFu%+*hU*TM`$CjVymF_B{m``2kxp|A0-|tO0tU9pY^Lv$EqE9Po zhj;D^*HU@ z;@qtkv!|)7SlJR7cZ6-zg#0;@3&b#aPXI&n#nYYdKlgcLx?LF-mZt^ER{BEl9$|ke+kkMHx@~f0FZJV>vZO?bOWm~cdBmJH zJCeo45Ydp+x^4-rjkt)H^H=MU&>G_sE&&axr`8~pW*v-@C#p-Uz0O>lw*^4y#Qg|q zO<_xykj5T(M@DP)oH?GsdJdh>P>n+;8I3;>1mIVcPZDZMK?xa+A9Hpa4Ldl3O?+`4JzZR+=i5m4SBdj=T_f5& zW`Lx%9P5_TniP&Lr(q&F9XajC#GJtRJk~iwPBVsHtL5&~mbnflFR4B&d+Uw4$CUc> zcS^nAbj?d5?A4x z=SRq#0nmyDI|c{16K9FIWb9s5GUpfOvSl2MY#ErS9VuLgdVJl^Mg-Hd`o;9z_Soh}8rwPNFmNT;N78xo$Q#0A7xhVT)td%*&qe-x}N?j_jI;pwSY3cmB!5I# zUd*FnCcIqM4L`n)jJc`afiAx=6id<%jGI`mqoih~>ylQV>3b5iC}TV2HstS?OXFm| zZolV_gxxu=5p!5UP&e|~y+0nUuAGb$a6a#2FAkZ`EWYWR!zXYey)chbdMyshEo4|R zJS86J`D0l=SwSTFW*e}AKa4#7d|aMFTsJPBng2p03R+Gb-Lfchj>`D31|m(boTL6% ziGF$BBU)Hs%2M8*LOY6sSde1Xe3W^x>as;KDLb>JO|C_`mQ5uAvFOa4Y-KNc?t;5R zF?=*zwG~TU(E(GwQqk~$Dc!CdPjnk!nPu9FZNrPpj8w6({#9o<4qMmd{2RErk8psM zI?fS{-`*1s*cz9lbRv$;rN!d1PkJTscO21lpWA3`lU@+_!qy*c+Jq=PTBl-^feib2pq1 zIP;cVCezWV)^SdL@A}Ykhl_27 zmdj+$4=oo7pgkQm7nzm$3OzY+sJX^$HJ86oj+%>ie5$#~u6?f16Mp3-H4G=RT&!ix z4{!Bwos3X($5e{k(Q}b8Ij+zXBpp6i=!xM=&%H6cxaPFpD?OL+hn|Z()p0P9$y$$| z%k{oOPevb~dM@*d(@}JXtBCI7HR=yVcc6xBxkm&MNYNc**>5_7U|Kzj?of5ht?2$B zQDy9Qv;M8@2{jYC?oL-$I+FBI@W{U~6112J`T`i0w$@NsJCW3eg*6thWIz|h3}3TMte$wthf6r9JG_#?+1R!Y)yWRy?W zV{A7#w)EyenLT&HIeU55B zM&+k6kp2JtTMULrap?C07xRNvuihAB&!sL07Tf7wm?lv=Fe+@C2tO=&_^__qLfP)8 zhKK5vlop+PMJ}m^5y*06Klv^X@<0|1REg0s$Zn{%ls@#@Fuy_WBN{`H*3n_q z!&0>a!@DzSybsLx!Fb8Pe{BMVrv2PRMhrJ*(LfOxZUY^mf#KJz&hIarvBVA}Ym8pw z``?j^MFo;QgXIeeA5WhbjM%ZYXI!|5g=W}?agK|Y3ci!!+6z8drAaoq4X`nFx-M=3 zTvW32VGzlp)xi%?e_TwJi?X4qqfAXP$3gO10 z-=Z)Jf1#-y7pzdm!A6u-!u10ZU@2riK^c2Ff*6ID(+V)W82$V`)1b*Dr^k*GK0dZH ziWOn-iLKF3!cM&lO?GLP4fs_}Y_kpwGQ>Rs>j|fj{3a}iwjegT*dr?1yt72I28*sL zU}<47=&{JuJdlgjls$*fe(%~<(fYT`TQdkw6^dptnng9rAH{;ez%)8mSe;}s*597Q znRslT@K{k2Sxk3scD>*S5H3%rS%zK&c)7@BWo9LEt~yHx*Q~F`56uraJ}NK}wTB#_ zIA#q=0afoLj2xcrAi{2dAvD+itzr;e9wypA1LhO@&NG6cU4U~q7jxx-D|P!&c?92$ z=Yh&}Ws>RSq_ysx#(2^ukwVh0Nq%xfm~kFG7r8w9+y}9m1HZ!e88H9Oq(c!i!+XSaplyk2J>!o{nnvZBH~D{w#wuvW~FbpOoo&csmHdUBHV3c&zlt<3!NMxKrNm4} z)SVYE;vuN^z%Ih{8{#a{^Sw453sV?#lG&LBd}z>jlbMIPP;$|Qkuyun0F#sb%&C); zm02zrwT)LiK@5y19)Wom8KRn+e=fuf<`y3XGR4Bk7mlWEMkd4SJQdNH^ADE#bh{1SV~N`j0eRu2U&u53j4un2aI|bWizg`m%hxP zPThi<5rtM{di0o)wYctGp22)>qOQYnZmO<(c>kSYmi&E^n4EVY!D{h}o=(u<;4Q6a zwnbJ?@1A5n7R=OUG=>K)7TKgXuV^tLG0X#_T)Iy}V4yg3`TNNF;F6kp2lfwTRl2?7 zT_R2(lbKc%gGv9T^SDk zMm{#{EGgFw3~$uq4V1l-M-J5{H%v&bsZsTtgbK14Z!`T0!VJ|hOp{NNWl55*9NLu5_Q zG2t?N*1t3pF^@vlW4NY>+X}?{DP%^2O4(vbmg+ZT-HEXYS(JdBuB>f)>UC3h@%8I2 z@9pz0hs3HMP^dO$>@>LUF`Ld;aC#>ZxayP9T!>mUbapJY@D?&X|h*E^1* z3g_`0_fb{>l6{mH>(HE|yz0j}RyFE#kd?x4wp#|Z`yfx6jn6?=h|W34hOdJhm^jFj zJtfaUp3H2z5Au2>AH+dkv@h+0tSpNAATQQAIR{zE4f~j4m3qAoG7Bu{djw5Z`yh8K zbLSxU$IQS7xj&3k+Xoptm-~H?19OfoYMQtFFU&c}KWIWHdFjr-PO>rkB*SlX9b_e4 z+y{9vAm;4sVomCOO#8z!PS-*13Yfe`uxQLa$XJj(?t|P_12qmZW-`t>Hn@**z&^!% zc$`zrpD*_*#s{={PBA{PwR1)>g;YLHF&wq?I>n2XSk5tCE#48w*tE5eajbkC;_ds3z!5C1w+BC%P{Ki}~_4zyY&=d(GD_N{}+zqH7;tigh3ZH3z){ z24}=dKpKSzz$(R!u52)fQXMN{odr3?_)XOchCZ+i7Hxbradno9p@P_kMs(SG25Yzn z47<{dC;I2nZI&2+VNm*Gjt>l|dw8-^Lnc2IC7YxH>Xe`yhZR*V4okU(qRK!M3q92p z@tXwO20AJVR>?XRHNt#m-tb?A`LuqIkoX4v%U`HP92&9p4h&)xAgiV{?zvYFZPLaC zBbZnlV$8KRpY#`TPgD9&ac!5bj${j=yiqs0%8r85j-64rvxRVA1|jdG%Eb>2?u8-0~gV8;cq3{9!RnQ42@{FL1>-@rG2-*FPDKiMlOJvr;Ui`w&ZVQva zw3w7{28BN@mg%h;FePx0ryK5MwZ0PJ)^D;-F+&NC`+oF9&LN*$fkpR@d~u8xvwtmyw}OlJFV}$*ZoCQz&86H zNmTXDJ24sTf7G!YCA zcS8FYrl8GRzA@dYFMhr>BWi@G+x6dLN^ds#GLIMSX7fkIp>_8|GA*)+w z{2a<_t>Nv4C;`vmG|7T%7&eiYb&VJ-A%bdH8P3u^vWWa$UFCgZe}>4O1`zBY@B4SZ z9`ENliZm>MhA8A_a@GG124y+OHU~Q!Ks-#n>M*uNn#zup8%%76(p*?EUR{H*y0x2< zN7}GA)f$9Hun@`l1;qjI9lgc*!htKcajDEbKJsA`1%Ye}+%^?#17n1Y(SW?FUNEF; zj#6WLNST>pfZ}MyzXJLM9L= z#(W+48W!#(7Nbw{MmVq_&(Pjs4(HNPEwq^tUr{7rj^c9ftd4?v?xAZuH{I4MhPA=1 z>;$Gbc*O=@$X^UZ@GQ=`{jp&Y9K|?)u+mc91wk0*Tr$#wO>DwB!&nhYfyidq70GeV zIyesln=)l#gq*8Fd8NMtC1ATFSh_rU2qbo7leLus%P``Ydf)J0MICX;_lO}w1st`E zY!VAWD&lf%2TBAjR+Am7)V;KaFzhny;<5Y3(?D5mO(Q>j7wabFbi+doytyKImuV4- z8TX)fDTj&9!3}$H{lpMM5XGZ1ql{DMonj}?+FzAq`CVMx&NdIU9ddCs&F$L3LR85* zi9s-p)kdkM*R!%Y+E_Bk?EJa1#s!|9T-GoFFV~a8?mx1(6-JnuT9BN~@WxMia)on- z{@pYd7!>k!l+={Xt|_94!II>&&n`EfWG+B~T}GK@nOyt2rnRD~J~+Vj=Mj8;svbIG zE%@`Y;Igi}E|W&SqU26~;2alx?W8bG8fg4LTMnD!3n1ysof2QbvZ3CVM`z?=d`M&d zbijN<=WLIttanR-W%2qd$q;m%yhaSU#5ZK}Tdy+Bnd$52K12-G3_I|{IL&v$1r-rr zk>urm4gi>~XhTp4m&`seN6MbL{je0G9ysomtQT?w)kVaX6~SGbI9$Lr%WGTEfek?% zS-xa=4OkR9v)u>wsj4x^q*N*0A6tv+-%sIu;8uL$u1UiYwJK7PO$WaGMKbJku}*6^)O91?+@uGw5Q0*Px? zl~~K6hj$u?P`=1xmLdQ49?d&9poFRWW0~xRtWS~8q@^~c-IcUhBqUbFmILO7Pxyj-4SclZ_5kuECB>tj8 z(^J!4ZC4`BGG`HWyRIYr%9-C#tDb-mH#F}dBCS2gc0%haOitoLHTiSa%&KwU1wXFj zTV#eS^lfvcmu%gMb;?VYrTY-^=Mi?fdGLyTcyO%M8-1~Q1+7O@g{~;!au2&~CNR`K zE^yuTyF&?&D1w}%@0H;y>#J^Nj1tPv&8w#c(*5`CU(<3A1!5FAT=4*USjpM-{&{A7 z-;muo;41x?!;L|;G`v79uoi6(OE2i=i;g85HXK9raiwV+;UC7UjU0yLNBkX?<#WGA zsMQR9q4Rk5DWg0*gC9(E5_Jx17AL8*L0I~HV_z9o_xWa|CBo_MogQ%irMlkQkS>=b58lt zaIrT&fq+HY?s@PHLPHS46Cw_XI^%%~D+|z1eGxi2NIsrcj3UYgdphfubT$=+AQV&^ zf5&#{eybvT)>FXU)#CxWxG7W=m$2s%Mu^e;`f;{gOMA(MejT_q!!H{LZcS-Lap0E7 zGY;HRRmAJSEkzmb1IH@KZ67EUQMSma1Gm(da{oQCC+->%`$3YC9)xsdmCXPfJA_t`mnzj&YADG79;`u{3nQPuzN# zuyjt`VsP;}a%+a+)kjWY%J-35G60+dM$6p#CuSco?9Vekj@)9so$JV9j1LTt9Lje; z*MVXw@%zNF+IGJNV2$fJaZtnShsOc-mM5PRN5wp!Be&sw<^tnGM}y5chmJ<3`^?d- zRL+@WP4S~$Y(k7P7la#UZYdCIpSjf)<#Nv4vU5Mq+|nuDXYTWS{dE~{h9O_>2TZws zn1};&ye4>Rq<>+MaG6#7TSk6JNDLZpIwoNg#Q)IpvaN=YN-m=zq%(&n(Nv@GMEL?e zzJ*ZsFfoBTv@}i23_b}%&r)= zsAEOi1*6Juizk}Mg03q3X0i{Eg&I3sI$m-;WW;sU%4Mf^R77pEmTcED-7ELsQ|Pqo zamn;@;%)x^+G4u2fO9;{%eb`d!oY+`@~lh2BuJTK#q#IRu}bqhvaEZF_B(#pD92Gr zk^jS$32~YR`54iYqM2m-<_-P(3h=U=l|+#-2j{f}&6- zH>}H@dY$~9!-zOUHmGAxs$sTF8=_mme^r{@L2n*W1ji1;DI|%w@6zl^w|Q@_d+$g} z=KX%|h0o<+ksC0sr>MOCkmoxw_5}xQu*xvpA)VAb7{!Jn#!78x`kL&Bf;DKn!U4*96;SwYX(S z+jl%pwFA>lsG9Bq0HDNFoh2DNhSZUDl8m=|0u(`-+J;b4O}a*mDVng6;Rjv*RdR#c zSn}pc;3h2d?Moz;%Jo1seu~ zC9Lf~`^3OLK?z5Ru1A%>FxOLF<$qw#+vBNU7--Ao6C+6_(ugqc8da9O3_PSn$kEf3 zT1WFC91|*{rnqB-d`>M>Vs$_Ab(M9Z-;Xl1((8vlKro+RIpJ%B#e4<1{3I|_U1f10 z9LiJ%sjk^+g_y+7x#HGpas+UX>ypb5f%n*B8{6rU(5I+Oq?(}M{i0Yb z3m^F@^O8+oaD^R4f7Z6cYR9LQx=f;PBj}`c#8Q#tj|Y58zA&%ZG@40G+?qE1)%w=lkj6DJGzjYQ?f>`R#Q>-I3? zQydS9Z6Q+tk3ew0??X&JcCD{ZnKM5lUwVMvEZY<||~dbvrOi56C$K*UFe7z@nbd8`kBWYe+-V1JqbZ-L6z-ufXQGfYy0c-l?^OnX z_q|VvRk9^}k|*_Xv9zvykBjMzq%VvSqeRSICtn?G6Ui5j6g$17er8r098<>#rwK0{ zv}mCx-J@kyTgzAk!knWV`Y)_lINV5#ytV(K2TEhU)?0jJ!Tbv=&Ha`eK$GPE<<7ZMu)7zVRAPh`z% zF;lWN)r?>v5HrQbaSUbBLUAgkoo=UMdw$d#f|K$S0aOvlU{r#COkHSN* ze)s=Qmj4*^Ggtn{p#OIAyb<5OvgyBnW#NDS{FU8n4sp5fjg2<%i9*=MEUE^lwAzIj z6km-{h~y-g7-FgDy0NCORECwk*9I_^^_kQfd%!}T7&r*g`3oJ-r(>%pTO_fQdTA;F z1rXs0)AiQI3qxA)0}Osdi}b13H#V_A$ihnXg8K=lHKy>2;%~m>kD?!nX@)ECod&p{ z!yg9=z7AeH$iIah2LKpoiSKOh-GfpjPHNdNz@xj3?RmQzF6>u0l@}QT%zpxatW(KVHb|Vm^!iw zd<9*EXv|l(#BEV5Eu+fEg1A^kC{wW0eldra!C+q>hMX!M6mV+OE4smJL5=zTwNwsO zOT73|PY1EC2qQv+(J#c>l=66?0Jh%L)O-xquAI@cw|2LEs{P#=PfZdIXlV zBWT1SydXh1ZliV^(+N@YWwMysVkzx`CNd1zTnyq>wH$4V(sag9m$JU-J{|0|#E+yj z3z{y@nOTgq0j4p~>!E1J+Cz*_d>G`%0zAo!%VH_O(8-70$@qmv{gV5a3*qHjJ&6%1 ztaURyp!0C1{eWP9)W(3-u)-hvQlq%e^SHPnj@^Xnt+2|6K0Yvnhb5#Q1}_gcoksn> zm$MlBtMZAtTz^L(IUxEmu_!ug#r$SXojyqNB$iagZJJm4y)jvWsI*NSq-)d$_!eU7 zKzBwpFM7mSP)I+)3`2Z@+`{ z+EWAO1H9MI2$Yx0{DGl*k2E0zPTBj&RHng-Z>#{xa6WwFU@U4fSFVxtJrb23PD`a4 z2j@)tD=JPFEoyQ|ZW{W?hxRzaxQ)h?(S5_6$?kpv7L)ySEEB_888FXd zI~@<27}79U?Uv;EzKtin=#v>u9xUF=0Af1V0848wKEpyBLw!0Kqd8rX@?vRF zLcz5UyLyqYGA{XHWv+lZ@5;;Zj9?=NuC7X<4ow415a;F&UA%dk)Vn`Yl$bQl%DB|O zsu;Q&CpuW2&$|VWXBrp0SSRK0ul@90RvFcQNoaw=bQ^ss4A-0-!>_Nb$awCmqEmA2 zD%RvH_Xt*D#t+bYi2(50NR74cFm*5wM62ehuypWGG_vFUm?ib044w<1W`>qv{+;2+ zxoAxh=$;QeWG4Chzk{KipdTPhWVGH;%@>^Pq~4tj&=)sgMF$497c!5|0RBSn4VcZd zi$5muqrzBSm5V(5OGRI94p*25d`75@BUxm30J~o?hs!#$%^hFLS=7yiAC+}v*^sf@ zg9c*D*9hlb^B;(dTYM6Qs#w07CU)8D`QO3x;O9);B8{>f6Ot8p+>uh}DweEab#}E- z>&3Ykitrzz8^M1S<&BGMkMM%v7kDnJZY3Hsd(0PdBo4f4m9k1NzOpDMKrqAP9C&UF ze1%0zSc-W17U(~s(t<33=CW*Qq4Eu$^0V|=TGQ?Qx7R!vA%WT@Wxypp6d)<6z z;-b7{bW-b!sG*A1$TF~;qsOK7Gk{4OSXt0>u*qLhoP7EhEez;J4Cr}n5~>(l}=u1nOT&K)d9%^Vk);s6id z0xHH5FoQX%T<-ykh4ao2EY>r+U$Gb&#oRBPa2OIBKasWh5H1Q1(3G3T2gGr)@~jEF zdT3}&SXqoM8hs0&j4zdh%mgJ^UeaE@cMkKG&^+tW?-A0ro8?=?#Xr(whI2y(E69L9 zPK{tq3ThDiM#IQicdAcdSaO>`@W_VQnGypph)f8{v^)a-m@bl5Rx zlZ-|jh#xT}jBVbb;?FmCS#)fl5leQ!sc0oeN@r1f^FakDPI(}$KUsw|JU6w>{GOkpI+A{mevQd+csi&YD$YbEbE?iqBkOF^|` z!(1ws>tH%GW4H^QTOAJ@G&y^>VF3VhPsls zkWyY!wnUaBP$Fe%vKaGlt5u{+Sb(nxlEZ$szF{9mz92>{=F#mRK>LU(O>nI^TSbB< z4N=%$-usgQgBwOsF0Wi*WB}AJSlrIj@6eq-y0_D0nN^n*A8A3aPtBr^OXBA=^Y!;C zP^yqtsc*UQuejWl1%5840xcPm9x~<6jd0v*ri+Sp1eFef+YTlfaDgsL&X3GVjV1h; z6d=QLX94siGrM5~B_e?A9?)dFR^=&XOf2aG{c*+weaf^gF|a%3Fjqb7<(3#I21)MO z2?Mt|1h54+rjTv8IsRv3aJ?5F&>>#)8*>hEJoO9n9=`M_PBe*lnEWzs%=MI)`5&0` z_ITs8|AzQZn>of|< zUJPAsIrsttdIM|>z5DyWjX7e@`V*Md+9vgo53{(F&=5W3C}XzQ>=4y-Iwhrw@#(`@=8I zG=+`0hm=pX1wH!jyO!)|wa7|D^JCwdR0ft+_GK zT?MCYt|3g1s?9a;H$L*A+FU~f>^C;oaFP(qZLWFYEby+Jb9{G?F^^0g9W=Os1pTbIvn5{^Uz6c}Mtyyf8XM2%+;sQ#%LiHbTwPdgS_+rb&26 z@N8M+v?Kx`Z5dIANsTIfC%m9six5y1Bbe5dMQDFUe!N2G!xnp-V=_!=eTTF^pWF_9 z|4&4gNHdE|orgY`QS2{gnGm+z{9^JR*7eEiD-d$?`-mxCa`6jK zJrRQQi;*~YM%0kJAvwRW>=IjYela=XL?Ag6e#VxZU)UybOU^{(v?b>kmTkn6^MONh z-k2?yzVo6G`5SR|E1vm<*>W={i&L@X=8d_Y@-qJeb6y@#{laXy`CueB6E1Db&4d}2 z5^^&!BX7a^g;@?UBxl0ZQbTek#x7Y%&fMNQwp`5Z&qtEx6N=Z`BQiS^hvfW|$aJc6 zt+!q5zk}KLer}JVlzt*$_hO1&&ckxxFU)yput?8u#5o%A%x?@FJdAeQ@BWRsp8A}V zj#zo5R~`wYBv!ZC5=K#S|CTU{67RQ!QB)h?k}%4{lIvTD0 zqNrXl$>n4bBTqS)wuF&!ZRaClX9*uDvNI!;|G;e#=wU^?UFG#Xk9W!Q4g&xW8hcYIx+^|dW#s?z?qJSfr<3v z@8OoO@<}A)PrC;+-Kdr@u$c1_FtQ?~w}62;AS^EgjL$iV6_qM?*p6b%rA%4c6~_3& zidS$L;|q({cNpV~v2vj>#urX;N$NyqNx$brmfY_@m*5Fr~pPTG$Rlcz{rgu1uB4%Ti4PRz$i?K z07ijz2Qc1nd{kf*z)1L!%!&ZU_mwMP1u&8t9MQ}S1AJuPCQy*Vv46hM6P618F>gH! z;fq|7Dv4R~i(EDvKe(t(Dv#n9xyZ9!@rxpiaRo4PBWWyA03+cg>rT~gI9kvFjNC}N z;$=7HOS;TQId-y(%_@SC(-;z!5b>g&8y90P<#t7I9lF%NJ%XWoj$q`fTV_%OR|GKr zVReQT%#DFusUPqB;ZQkq^ZKbe$v)D}s^iVaQE0rYU{-BT0sZ?fXsyqliC$MFivC zE=MpPI3gH-Zm1$tfa3Q^Llg9D*W^4{mi~zZo2R|F$Jl7Rw>VB|E4g9$}h-3D?+Fuw2|qRn+GpZu-c!MjIHu`dNMz6<}v z8x+9!V$yc`auzCo76FWe&8C$!8HlaPlp$5@7vf?TpEU7JZqO{HMF8W*^kC<0MidjX z{ID8H+Q2Y(MiHHK?J5&Ck3eb@=#f}qnz+nnMdI?-5z9yHBB$DY)VV*SN<5V_e8W3- z@n96YxPQU1i(G9RJbSGFBN_-TgjK7H^$~wL>S9HP#buFxPx2k7{K8^- z=hQnge4lz`8Xax1%oWk8Ru{{(r`hUanN8$jbur+hE^ds~#WF{POi*3qJ3b83{D{jS zjgNe;Gg+M&vX3OD***qb=IELp$v9h8#Jc9o9F2AF#~i)Ettws^s){vjt2^&h!0k3i zmnC=aRuzG$^Qel&2E|Yn3zCLzO|c+Yq8&}KEXR5JSaB!sxZxMG^BFusdmpM|ecGQ7 zO%cTM%%dq*=bnV7_=7+tU#LgZ(G)?0&uxvyQ{%Em^H(oxG~ZfoRS_Rn>N%eEDcfzD zV!MA3h{Mu7f{V3|u87qvw>28e-7jl2rZM_a7C)!u^Z5$TPq{DIz#QXVWv=r-G1(;v zGxSDWKS;ZL0ZCH`^Fu9!ikixjhAkV_@EY6rh?QkY-RHXAX0P=8^ikZVMb-(;qC zwR5K^v73LECT;r`eqidG(ZTeE9dIu$%~zHU@+VUG4?KX8t$4o1q=pn5%?aIi9Wx9a zpdye}v32120JAx`Nh0rXUW$-_i>d6n;V2srh;twQ*gkn&okN_SLKn$)k_G}E&!26% z|NHeAMup?{_o(Ae{Xak5yZ>#(zkcff>bdy5egStCO`oL)p&SCbD}-yzk}cv3-@*%WN#msDg{HB7pB3QFhXc6 zV)OiWWlB`llcQ*ZD62ZD7E08?6O)#c7iI$*K7qPXFJdqxvCbw@ckn)c;Vz+3>C}7x zX=fCT5oU@G(lon*O_vL1pqCy9Ox0IU)(xgeQ2CA2pD6&SXe1hY7mJ^m- zxI#=4rHF)h$pcRZHXRJxP4O2f+7C9GeebI`Q^c5p;ZmKkAzN0ammhV)4OH=Vne$`}0 zSt^8_$-F>T!O;VOVFoFGfHsDn_baj$JNMpg)5m~Pg+8)aWk%!C&WPoJ|El@vx<>@F z>kLt5>(XV-BD*yyx)JCr3cF!G-pHv2o*ORl#Kyct6#J3P+ zf0cQLoF-2u>(;0%Y_qvdu~%%A%Mn@apF3+w$?oJvxzE_}-`yzpj0g&-Oz%=h)~a80 zM`%TMh|02-&IUQQkp7@kwYhFX+e1gS+90zNY+$~HA)jvS1j%2m=6vidK74odY_^M5 z$x`lMg8t%6NM|AoZu~4;#F{ssRIJ}@B5)aRFPL`_p9st=i)a9^QncUt;_u0f&)eaz8p?9LoB7YA z*3J{aw(OJD1$bnh-B6Yk%{ty{D9b%;Rm8Oz@Fg3O`+%}mgDzh;RHYW%Xi#Q5)n!=C zz_Hriv!|(BYLFtkcR>L+%Z?VbH?;e! z(o884C5arG4SY!rU}sRRrtB|_zc&xBl+&;xw3~H08vm+SYKr?Vt2ZjSL{IKL%zDx^ zi=?(`qY9&TnApq5lE&lq!Nap)TlYElSGxN%i=uqdzSP|tn5!^$bKqt{r1&#=*OMo! z^X)i>Pp;!5QEhW^93&otJ)&9oQ6C|;0ybA~K3J0iXJ^IA)Ds;@gxMQ7JvzJ8nE60r z_+nfHFYL40S#gSRHP3LT!j%1)j6fnhil~99`T?_zYCItf^XI=WOl2nk!qZ%sMPO3d zd|VApx-23*-^(LL6OSR!NmVo{nIe|rLt1gCWchpCIG6{#NS^<}+0Md3HJ+EY{Qs?rnrR?tPtYcKfY^+FF6;VPkoXBczB5%Hrm6l5 zxmGu|XUk2q-f)XsbYs}CflSC3Uh(na!qx0lQ+(1gD^)Y%CR$hZQc`jo8|D*BWaSZP ziA;&5N-Y6pYZ{EzHkZ&7m_Ao|_#4Gkm|Yk?Eps9JsNyVeqbd_@u8oWQ%pY6nKCd-N z*xC~I##Cw=Y!JJ|m5W3nG>oO(>AR?x51A3KQVYN{LV2-z3#JbTlzz}Xd~?|=$^u)N z^|rV^oLzn-;Z>@0JP<4(sri2qd`vd1D-^K89{s@Mi-Cnc@B`+7k6+PjOm=~-oFuSy zc3t8}(icgKIw!%asiRz$9vEB7WT~ROEO3~Am8?tqa5z>zy+^b^W|6#$%J3_u?~*bt z=?<3EDa&Fmt3t3TwCv~2`tinWwFYgWQ~oFBaEec=a1U%tY+BL(E=(0e$AXYu*Dh|0 zjs#1amb^eyGF@zIu|#I+6brOIT#-w6M7=rr)ulVK_p(`J_n^~Qsd-pC)QUt4eNEwsQ; z2=EOxj3F4&vke12ZEzIMkMl^c$TebAi#^gCUGDAD8+#bVtT$rmNq*KF4_x*WfuY_= za9;Q6^e2Sgh;nafBV7ND5}@@)F17Cl76Rt>EI zAU5A>BdXTv#tXI44Trbd2%>x};;^RLCz1Z$HUI1amg2~YejD*EM7J8wa!tcuZoQGO z{kqgfd|8eoMzVb@*h(qHRLduou=~n2Ae)CuYs6|=Ft#|?yf#)EF^g{1cFwP#v+@~5 zrtHTxYeeU~zE!oZ_kUwZ=)@F>CXCBqy*=FpT=CT{?1pHBs!@-rnNvex^hMlj-DZ@( zs*RPe5vZOOKe@6B!s$2+H~ip;rsa{n3%@b!hVHIRB?+46U8VC5%+H+npTmG#Bwnw+ zPq_u3)qH2N@H%V0RhxWW-S06AH%YAG6Gp4C>H!9ol^ZU>Y65d^#E<=>?6gh!wK5R> z_zoyj;A(}GPT4eIW)?6yh7~ZsuSb4i>>;?k3+GLNh#$^%Yt}}~aze?cV6-4}=>NfE)xlPj7D<;4lvj1ELv-Oz6 zTz@!ESmZS?=Aoxr+5O}M8RNc{_=cYpu-8j0Re zd7xU?#z4ydfa$WAx8Va1vj!@i*2Y+ IU(Sj7&hHsNz>w;loh3PVZtwMu=0Fe~&V zDvSrl6NO>a*NBIvmCAzgFPw)Q1!!QaRV^XRLW=~D50{DOx(;Uy+LfMBT?mNv;*VpU|9 zg@Ri)h~b?jiH!KZ5Svl|SbHkI=P|n1upg}0v@u+NnFx&Gr;y%Z90hUBx#?XsLLF2^ z21nvqtg=X7sU{zAvD4sSST&w7#2LC{zxadM%%$!<=K75#R-w2qvWm_pnmqqA#SS2X z+n#;$>8aD?yG=`a?z($T_wDy%xpddnN3wENu&4T{ub+L?s|o?cO$3*DAcxe#Z{hC(Aj_BLXLtqN&ay+K5h$d1IPbetTqN#LWgH`P0SmVPliKf+1Y| zYAK_-o$3MRN%EMM0OA5gwVVxdD?a`@Bn?#A z*Xvq3(6ZrktNkS}L4s>-`f6R4>VP@vzds2u0vzPNJG_2lHdU6q^>-+SpfJ7}~e1@8VhILaS!GSW-P;$w!w{V{=q97KQ{QQQlxaj6M32N#p@* z+BWjGC*N=jxAex)&dXom^25__n5;_efB1w0deDcy=&N|8!72i{ItZyf@s29154I5B zk9m@Fu&c}$<2#Cug=EfFi)gCSj>(1NN2nnjSC-tMR^Osn`((KuzKTK{N9^VchqPWS zYW>)6-Y+d{GSC2bZ#9N-fJEF+3Bqw8OJL;)&p|Vd)++ch8_YL-ALwr(uGBNCv8kl`B z**D`x%*U6bPAZ}?zqU};AX@paCZ{QbLJMw^&98+}D=MHW)(LMo1>Z4~msbCc_6%U<#RxK>(Lf##xdL%K0~j4tfY> z4CB~R+V_RnLfMa{*P+>ug;3TMuXqV%=>Iax#_&^k16U|SfCG=n7Rs>TL7z1u8c2}I zTNZE#Wd|dnjDB-Q@=++mj`D)rLK&kfEGG}Ik0f^qWsT{GUzbqU)TDO{WuU5dL@q7q zA@O@n4@rM6mq~g}G4fj|8$X4zZm-`V{EZ1Z?_!AmKpa~ps-vcVV)jELf7)6$VpGC? z<~OF(*6{J}UzqdM=bT)1{xNH46vh5i&kk#EL#3&oAsT}g+1wt&8X*oStf49S29bHx z=d%`t0yIefm^14GEuK4J|+&k|}7I9vlAat_jx&wp}o+OWvhnV`Bc-@-@`jY~FMGgT z4g-GVsGFWT!gO+w6NL}3rKNS}N$=7>e@x4zb@-uxvnAAveV1-*{o`JF)T=|b-~Rl z!9mcStBxq5#%7QN-5lvPR6AY<;;v7SP%P3P$)dcXcK@oci!@eL*kqR$?p>Gd;GLka z#K)1@gKgi0VOxxB$-GOT!lFHfi(6Q%Bg;=U){q%Sl*o<~Vm4}@pbiw`KG}aS+I;TX z1^b&eMiM;W$NY*XT?GM2vB}LotS&|yn7nk56&DOT*uY=)?P%%#vsI>nIt*NsYFmxF z-()MSojr-!?uHxDrCVT~r%hFBZQ8KSh_(gnWwIo-lG*~1_jI-?=iX8S9Wo)Yhl;MH&RO=HQPm|SN0Nh?at>)F*fzVMlxu`-!JK5NVkDzFFbX{+mcKwF zhVvNcXeUhKL6q@sE+T=ReE)@)#l=O7C}3X#-bjf_RRJ#mr|oR&W)g5QYuOlSj^8&X z=~R`q4ItJ1O>Fl~yT3>E!JZy4Ll1PXnRdK6eCe&zaapPr#b_yFserweJ{g(%8u^gu zb~A5ltNklhD(ia9N(fpD-ijnB$%sQ;B$w0Qj@n?@cn`o)B z+w!}`=YwG?FzBUsE1VK_SX1n}c*MJ}Yl$zs{$95Yk<3m>{Fe!EGz)mO>z=4G%v5$P ztHYG^IP?bv!R5fqVuxx*ql>8B@ca`EZj4bJ24QhKF*Uryr&ytKsAEr2tS?=S?fGN2 zusnrg50V04S*700r*lNNW@|>Jc%z$@^(0LyMmRjWs)ur7YVQ)PNRZKeriSES7Q`?+ zGq{}2^!OFVgv!Dav+ZAq!yG;dLVb*yMKUeue>cXQyM^$V#93Rlh{?OUjDWNXl^YJ(Zev)cK|dgdO;YO3 z;>3u%ml@VyTij$a{k-ntX7+t=SVx#Wnqa2F%As6t*kUfj*ibRyBkx2vb=1ZtWmn;MN2WM#2T*bnZ^T5m#aPO%?Jk zO^|(D##d;9BRrt z1Xc0#v%OGK1bZ<^MUd~!Uq=zdmxUdlM^ha< zx1z^={-lhRC5gv~xy&-93XaPUYIZT>rjRPgqEhW^tAal!=Chfa@2|L2H)b%5p6#HP zFNj~5PVYG|3`$Y$W41s_7G}BZxmcJD=?Cqfl7Dh_HBl=0B5TA!e2CK%VJFueyc5QPus5W1JmCO;z1v$7ISENWj-)psW`?nLIzy+71pHu2K9KzSr-%{ zG4S``jM{3z+3Z`xkG+>|X!4^a=*dfBxGl4njoCNgkKI!+T|{;@p1&&+tf~wB_y3Rr zk))aih9zZzDdfA~*HgbR4jH>+)8btL?;nnEx(fsU5|42F@P6ng;(ig@tiP8VgBmB} z>5O3y!NQ8cXd&PJfhh11v-|@J=A(qiZw%5TRBUyz>eat6C_Af~wei$%%)_iNKBUSz zKM^s5?_YCL!K>x!RYISwQ? zE+xyu9#K=(giwtQ`Ljz;Oy(TnV4@_}3#+I;GivaOQw?+to0#f7B6@Z`>`M2-Dt(4` zsNNd)QeTld&&6aUd?otDm*-J!t^$P<>-1vOmlK&L?>t^Oqtud0TM~L-kdfFo;sqcD zTpK>}?()Sb&naRdoLM1z_K8oZktmqq^b;&2i@e&_#AiAf z_u>a}0_Y_I_7c2}J~MW-PMk8MCOcVN6aSoT!`|taaIX=pFK~WgFbIS1P*Fl0yt4Ea zYlt&|d10~Q+XM22;4-oTuTwmex4 z881vx(Jo_Nm^K5N3~|_sD%-&*$pc(a-Up@UaHKmnxlp*rfqv%Z4V>J6Ug;EjQX3-3y)b)sQB0dL4gdso)5HbwQ(SuYsX$=jZ4`I2uaYXtY> z`NMNpSlotfv+32*I~#YTJ~($pR~rn2FWJ2?W6}Zl<|i@=xfR;JNK>n9=}l`{H+!rhgV3HgcpI_pS zgTZ@VA7{9BmD|Z^3iWc^e;|;pC9zVqbm6S8$aG)Ih3_!JlTTDi5crAa3tGv*y}Dd4 zdR2`{STcuFAp+(TkXp`wMr8)@L#d%dheb$^koxFkZv<%`SR0U73B-lj~Or@pqJ~6XtcHA2PUaOsWJG1royvJHA3)}37M>`(G-TH z?ZS5k3>m|lX-p$8;4i#i&m`O-Z~{bNlrFbMF&Jswl?2w9W{sp?RzY6!#q>gs&If3K z0zz^$OA~YL8?t(rs**9ySyk1c>s4$ok`cTzpjj{*q_<<`l36gg5Ki_Ks z@Z>uNTbe`fZ8a`jEL}mIWAT7Rc;xm0tApIZKv1Y(p}2u2J4tF(!O4w_Nf1NFxz8+u z7&xp&rMQ=Di2-xswCh|W80m*!m`F;b60C!<`X&*dyoa)KXRbEBveoIu{z8U!$#YXk z;Zb?S?O3I)D_)$?8hqnZmv)mUxkT+%Y-cKDNn_{*kdDBSVmJB8oh{-1N?9I*3?-AH z$liPyPG_sxnRuAFI6H}k7luo8kUxgIKB%@BRZ z;=~FUZqgkmmb8w{2DV^{fATWK(oSluQ*t1fPRbWde~BLe0@f<7bignj^9LBs#xf2q z3(jIO)tpvo&^=9SbSf^`se(4i>)kxc`ohyM9;WzWL2)))()f1clZc%4F{wWI1f{Q9OlY)VP@1u!= zyI`?yRDvZxiW{y`w*bdtnPR}WpmLKI9UwAZM?63b9kTdAGQ`RYRB7R?bJ21zACM>H z46<>MuQ)2-)>#=UU_Jo1(lvkr3Kv$SnE3q<+cyMTSmMd#xP!TA{5-J{&JKYPGZ@c% zc3DWG2CM2^pp-6f@oxP4a~pkkO_n)Axqwk6js)h&J+NH=8>6SbfBg>Ybq8(>I);y2 zqmvp5KFN#gY`wJH<0|mn+v7J$^abJPMHweD-$_+ z$etn5b~WCi-GXOnA9)j2!$7g&;ux2M=xlMXAFwz?;X6@UCog-X_wrLk{R(3@L%b=Yg{8@^WitJ zvWtrZ>uY-gbW{_Vlv~L|u%YmspG5js8Xui46h})T;o^oa8}ltpk^mwdj)oQ7Hjv!( z+M;{A%6L+WB!9Y!Uoh#=6>Euk>KeX?gw&dxLPjm!ykan${l| z4h-fE@aMd2bf|Qg1$)?VaD(zds_eFYMzGT98J}OAC52g_4w%pchPkwvNMB_H=Y0ep9XI z?~Q?1p#y17^U{Gh>(;jt#8p{a2O(>4rm2l$ZJDSP^k1^lBp7IMdtgx#7ykD5vOYJ-tL%x4K zq+deadxUlR6Yxt8E8idWfA%Q<`WduecN|zbJxPIS2g6{c?XLO_7xcI~KBj*la0^_X zs(&FUhkiWs3-i#5d0bWh#3V&z{hZH-^C~BWU>@hyi)nxCagz@8VpO8i&Z`$zxgI;O zUf5+v!gC;l&W{s~4WE6l3=l;n^z-C^}e*p_zv~aumg)9=HbA4=i!L-aA3Wd?h$Zcy&w~K?ZJA%{KrbTJXmTp zUM>$7AE6p04;FthzEV#NcU7|oi>sNB2aE9f3I~?K7)c~ZMwkn$J%uulI%|MUA^%0$3G4N0wMLwbM+!7|1QTBDNk&qn^*Qf_JPZBMRr>4 z(IahT6{5A{iqt-~$C=cYN!9jT@w6mukJ>fo-1-j zdB#+Mlbo;}&((`y7*%+#*f*ZeT6wNs*m33Ixq30WIqbP2OoyO6R{Gpy z2)7l%r)|F#&#m3a@>_{pln7gh23f z{V%_j?uT_bt^#vBSAhxF6~DcVt!465+M!##i20MTAs5Rk4@w7QQQk*K%66`>{}#Yh7C!RGXRv zO=ECA;DAY4N%#DM^U zIhFcIfJ;Ime)+(hch`6iP^mLLPjh|NLbV!FVPiHNDJ0xA+Q)eVS%Sz1hBj&C%@AfF z0$}`HO>uE!bvEK#h_P?Z;iE zT{iFORm52>nWA3H)QM2XTzofv3l}p#YKZ=85pij?s{}=gKTj2=JBqIhTuJiN(C(zI zF_ULh>DFro6-rUT)`?a3KWhu>T(>&@M2w!kSQq0B`+o_0E9Tc7|~$ zTK%&l1(V4%ECFr9f8|R`{T`9DYG`xu#brrFgk870e8p`?@|e`39#U~vam`0HAA>fy z3(FT2Fggi1eX@HDy`gDedo`=<;e8$aqAvB*m5`qn^tk-RGX!jvz#t}EIpgNvqnr6| z{ymm%wiq$h_6WZ)zqYXhptpZka|E_srW((St#$E(NxccyKgXo1puKMZ!Ygam3ecQ> zVg6&0f9fVhy{@GJEomL;F5B=3)5OL+?(4cSiq|6C&4Hy_s<1W%rxZ#xHmX*aWt3UXa5N(jF^{&ac|UlXc=|poyiv^O@_oMz$#OXD#at}r>Kk&H z2UVYyp_WvDlLPPO5=RNjoI1e_qZJ|R_Mzk34n%^__9$A;DEjkbafwE?4ewxvjj?Sh zI8c$jgp9TeHsSUqLRDXMIVml0g%Z~SytKUicV=|!ai9JvaMjHorrtP<$h>uZ;bX^j z(G+?Z`FKge{&DfNGNqjFeS3~A;@U{N43kRhZ;|?75R4*8T!y}f9+H%G7Ipu;`n8Wn z+)yv3nWSPwp(e#QIJ%V6%rhiF^g3Q5!s)>GKJ*2=p;q@vsc!PQRM3%AAC8AMu_!)O zV9l}u97NM~w3^x8B$HdxZJwyU$1kWl|HEA-2PZ(n@=2f~9-}w^` z_VAM$q_IAh&$OEVU6?`+uH~4bOu?+;M#<4C|D$dL-q9Df1V&+$t1~wESDLegTm3z$ zdN?0%a`uw1$$RIiO6_2p4YkL|{Gr}(v`M)zT?&4Z`5G*od#uL4x(L0T*;G(GLK>|v zXU?LX>zvc>_w~(XAcw{;bS+f8W45qqa;BC2IIhKKQrpkXu$`x=_0ZN9iwW~+izV)7 zYm0JQ<*(2d3$Hex!N;y=7M~7nu~1eT*SS`b_u4hC>K@S^%Vk3b znWh#>TVa%2(PEc;r?Q_soYV$#SgtP&!vNHjBQ8|IM?bWmT1v7t#uE3IHAXG=S163M z*GT^>m&vD@uQTeuK2m#q#%eK3jWej?h3D_yekqKFf^hpf3L^<-1c@~*+ceu|timUm z%Binxy<>D|QS&a?vDvYmUu@g9ZQJPBwr$%^I<`8tZ99|q{m-45yXJm5t2XM{b@qp| z&aPcmPXVNu!9rR6&(({v#kTLkfVZ%zB8C*CPCmWkw=u(wz@i+OjC}=#_a<|I-=Ify zoyQ~=v6_=c3LQt8q~m2{wDXr}$&A7`5A!7R(nwj!4vK2eR`LGgYsUR>+{f&D%Ut5R$)_5=SNS=+JZr zoD!q6y@A@SMy~<7A4i%KkB{w6s2kt$k8|~~RjnY{-?~S=h;BFFN=QN@mC>`5Gc^gaV>%0XTKXtpxawF{BYj5OgI4I zfv)h}sCK}|wpOUtb>PzFOpQi`#el%LKlufKD!26bp`mej))^ueM#sBDGBHZ&a6>j2;sz}??yj=9 z9Oe0t+rfWsa7Hoi6^iwl-15|iC35mn)Kr5m%K&#ZEDmMr>^x{bbZ#5`)wJn~+Mr}* z8a{TX0c|LG!V6+aWw&9PJK~1K8iD803B}^d8qv6qi=&2&IKlW*79E(%+wk3pIiXJw zMn)Z{q_=@RUMUx+PGJU;zcd4kaE9%TjVlgdMt{^9#L7Q5`t~?M8f+MBY3xFxZDpNixa|ygu^&(p!UxE)j`vYEsA}fc&$j1Tj zl=JFohU(!c>fA@?2&$9BQwL?1dCjKT;k&xQ1xRX^Ugp?X3QGdne^zrxO!gC>+&b{A zSu{EdUi2MwdW3>G1F1u$>^l{5N_I^Tiao!zi~iX2>FgPGXraU=Qtl5!CbR9(QQOEx zOk-~4P**g_AY$syoIVSVl_Z zm*&F$7peG#FicYkB$p~nlpVAAtKgM<#TvbtyWxvh+c(0RT+AbTgp*;}z;?2go|Mu+ zty%{~E;RiX!l}^3JU3O=HvltdJQVX{$qN=gEeGZ9g z6O?W{)bWq{WF{yjZ(ktFt%nG()wG2jLa}R~$V*3bn8{(73R>ot!4>Cs2G^EPq&=^) zF3Es-vufUMM&rB$P3+~s~J7bJ71#&A(vA$8^*@Hx!G zA?G*LSLTg6@Citc`@SFV>`w`Y6&)>eVYSsiR;_=`tFA@zOnzM zSORn~&<@CP2B#;6i{r&DGtSM))K=eqscnaK5xRZHmt>f22;Kv>pvB#PL#hF@cFn*! zeK1eNB25J6W(o(&RlHd#TG>jpco^xUt^YD?ki!0kVJJDPFk9%1FxB#E{(~2+-l&QL z4Z~a2&N2h3%m;&^2t_$6^Gt{MT7ZS+8xX9)WSJhE1%f~6wS*>EOgee6))ZL$1nH*6 z0@}-dp-%*iroH4JS*}bWJGK4-rvgdZjN>-26V_>R(6_!Y zMEYdPYj?dstkqj;6K$%=_q&>sKkDH^Y#H`qv$ zjI*W2Vi|ns5IyQJL$5mg0;tS~lhW{06mP+@o+se+R{Q$|5! z12x=M4zlmlj@UbkW*`dVCqz|xGGbUpHckwj%|M&EL-xANEt1^)b-x4d0`B@{=81~GF`i9y`M`S9hLBI7UdvF`Im=^vZj*B^X|0pXz(!LQ z`~{OCN9K~7Z$JdHbfD~reI%HQ<}m3QX!XMWcWXUP3AfmD2f)?>-VGG@j!O2@52M-K zqYSy2Y8Uycg_2)qmHv$X$-Mx-8)bsN0p|O&-#G+%8v{cpf&3geEc#leQ@eeIiQXY5 zRISoC816_%=G>B)sHVPWahVX1hp_xBhjV#zEl;0U{v(lr$m8mP)W|Kh8nof}6dEaR z`ezAyH{ zq_zxR(YDY$lkGZ4{9QMqo}oSZpl!@4Z0b*7T3X(9cKRC32Wv?4}Fs8#Kn_ z$*n{^j9d=BTM+2KZnW!MEjyhIKK(H7P}!|RC);T>Pk2#-x>c2`nuc^c)`ZK;kCEjq zQ+F9!ExGC!*%ON*tt&9njTkWPZlY{Rk<=@?1ku>=N{7&$y~ztwP^z=0oiC6511(q zAfuNpfx9QCp1wjl0yuHNZ!CRte7D6+Ty<9Unf5K(WIy~|fT)!9&~xGi^@WO;v=JNK~OcUQmYQq*lT+AI2#&h}ZpmMH1KfrwLn$CFnIvHs0 z)H=DOKfi6fB@zxgVlF>wh*aZ-bq^TFw~)8;z6h=lu6^Y>;lw-4V*1144v?XM*$Fb3 zFl`qEl?OosP8~O6i6-AyX={{Dp4dx1dH_D#2Ip5+FOz!H24&z2ur2S^W%s4NU1eH$ zO01}d91Fh=6{O0qev+YSxN~J*y_KH2yk+NTRS!kI>Zb+RD>*m+9?FgD9>VPD|o7s!sXJ(f*EUdAKiupH$ih&nqdn z5AF-C`F3+a#7(PHqpL=_dV^>Y6w4DIvz?jXAR0>LxrvFJ5t`(pMqgI0V5Bn5T7a(ghtPPpj`|CKbF3V-8qwMC##}=Tfv*az`dZt#!VtZZUSF5?&J1XXm}%7 zMd#zH=9SLAUwkqUJelOfA6_lXm=8(xQ(c_H-3zWY9@04s6JL}g%0cfjwUgp7_j<|>V#_cI_?Ilw)#uH=J7alZKJ+${ljyi}domvW91hCj^NN9u#g-b%^P5wf z(bTXDF{PjKqq?VgIO9j{dr`7OuF0!)3pk%JRW3P|XVv5;x#Xd`;fMGVj%3){^g1n)t9xM%Z<06^L-cPet(+ny`XBLD-`3-^b2?Vt-Tj`qsOMfS6zfWEGr_~!4Vm3nPFLV)?j2@w1`!!={}%|D^?`M%ZpSP5Ri zwRU_7=IUoe!-5vT&RYQqyhRKAhiz8gL)EFy1k@OULg04>6dhfI*F=o=XTQrUMET?y zDzf6GJHTY(e#Vd@;G=Mla_1r01uJSkyjEGPZl}{4(Dml?*AS$wYvlT{YSak;8pLlO zmL_!xf!MGc7HKkvzXi1T?*;l0A`RtAe8G12vWzg)K~;`@PuE%|qBC;=j)4S ze|bFLZ-`yTLpOcBo2Uf8chfyivm-vg5%&EuT8W*Zt-s%&8a7zcl; z@Yb?Mw>)1G%iaG;JN!;?pW_6(4T%0oSuw}KTOX>mdeg8Y3Z7(M+O+{p79;r{Gu!u%CdlPT{8cLP-zAd3|!QLhB zcn-;bEvBAL+Mm8avvOw}Htldsy=UC=!p0~737lDXd@80;H2+?i{J~gEx!qdpC3l9; zZd|fj>_6{N#WhM7x!<3$ofZo3eZX*3UH|yE9oXk|h@9D0YA{#XM|}y`T&{$^Qw_%4 zCL{plG4s#lcxM|SB;Y}9FpwM5PwIHrP!YlG)$=CNIxwtJ;-XMZURj-nMHp%WXK$9F zDI*vRLFIRmgD&13wO3o3NEkBn?5;l@8XeFUac!s7t$ZqSXBj_h-_@YvZrH3FVy59X zZ|!2tE)H_4(UuWO4$U?}1l|yYK4BX{8%Q%D>6F45mK(tk%w5zGL(oJY9#B|Om!Kx- zusWSLa|05Z2$w4Yx9$3GagAeW7lF@l#w(xK8s~n(0#j>mFTVZI+ zss^HI=JXmpkya$Uc-CC2_C%=f9gjN0)mJj=b{B14u?mS~o^T8L7;U{wD=*F-D#$k! ze8L4fS+n6=)oae0bzZ_{RHyH4NtgDAXdhp?{nJlulzi~VS;2Zr@zIvr5r`1gQD#J) z67%$dw!9VZN_K4Ix6szBdsCPbZ5RXq+yj2#N9T8#k&fB9LSw;(eCJr5flq{arXK?^ z5t{GahR}Q*<;8?Sl>dU$dUTs8_gUQ0K}NX1(3#0A00Yk}g%2eW=IFFmA^f6p3IL-_ z+pK@uPcIq&Y&N`SQYNXK2|-8jYT(C@cB4T1Uqux9;wd=Fm*nkTWJQqfGb{BXuoyF| zw;f887>&%9qDRqxo*8ACjT$9${dif~{<+}@fsKv#@qvvTwxNwP?CkIIgR5Sqn^DpZv$N2!`a-7~lU9UomX#a!KF5^No*_aNV~;*Y9F?AUynZ&qdRI^?O6 zTOA*mdSo`gA{E*!k=Y?lggLyfn&?(_mzp*{JsX!#(KF3d0jCWoYH+A}LW4~(-BL7* z?>f7%1PXr>y7ZEgn&2+Yh3j4E za!L5FvcfNB6=OKucCn+VLe_hFI!i2`qVXcu#yZ~^KFN*K;|~Co&L74oaz`30d(X}z z_RK&nzkP%jb#8V+HnO}RAxX->AF4*ExjL7ssQRY)6L+F{YA%G2x%dsf1E-LWtVww&hdcIB>g8f+~(4WjgB^11lH zuroJ@YyO@-RS{kgEXuRRVRxTrA-45!CzyP#l|OZh1E%hfoW+foa4a)ovxcbH=Ro%+ zt(=K zhJKp^@n4ATwox$eZT9B zaN=5m-|^70L_XyVIitcC7_lpNV#cJ&PG+US9%7>5xm>jrH`v^yo1N2aIc3dnweVGr zAWSH|FifuhAc;8Gh%{W|Qt>QKJjGN#oy~hdLkXQjU&fa_vA!YvFsh$3+4sJ5r!4Jx z!i?DI)fTgkJ_K6;k#k8I1VC4F_JTJw-JDC5>Z=n>Y>#!xI&0D7;9*e(^PqG5_2Th6 z=?>Cn1oEn3NM)?QB_>C}-Za|!3ky)~e7PhhND^Q;JgXB@-u=cd{dzrZ-OsyG)&r0^~*a+iLR?|7K5G&aMybL9ub=?G= z?Wmz2q8nXXtuY>UmI^z6xW2#!6g zLh^8_#bmqqM^hU=?#GMYaJiBqs84`L24)ChtctOoJ#0+Blp@-Y`@GgZ7r#GURL6>3 zotRFX6CHLZ4=U$Zz^&eJ04%afNym>ga_?7Q zWi8)C0WN~^KADgg7DaC-531^Z1|+h2bY(glk9uIQ-o__ZN9dW#upGyMV{DjNZ;eriOgo1@p2tQr__FFTP{4!VVW1wDQ#H>uP&lHpkxo+3 zFvXKjQt|ROB8q}SV$wYpL)p9Cqqp5%i9nky$K3-{XE`kCRWEn4Of*r*9oKO==uVYTr<*niza*b*{x4VSr3`7bum0!z z4OAnrkefm75T|nwBzb+M$V?KT%-A8aN~i{faTGN|9pU30VOf64yHf54HEA&{HOv?ek;a45sfk0wxFdg=c$^c6tkCGP z7UU$ex9GgA#L$Ga-dl*DS~_$kc|Rcme;Anyzjc!kkCocpZ}OB_WlYWw!${mIB(=9H zJ1|OJt7H#KvKV^ZM*X(bMm17RdgIxm=^$oyIf#MibE`1@4}`l$&6igQb2IaJT{`r9 zZp4f`zOj05dFm zfhel?^;iv(Qq`@a-_P2Z-l`XPzXQLd!dD8(yjTwe+$2&EPpdia;MC6+6P$HHzI z5}l9@a@N(?51*`rE)W&R)pFAlmy#P44l_UjdI8((9c9gc(`z2`n;$qD8NWFtO}DSv zI&c_MNOaQIXqVfpq5_P0)dFRYkbggBZ;;#Hilpw8>kb)%)#{yI)y&K$<&>5P#CqSK z(7O`*ZY6$yqQI>g1%gE`)jg zeHDaq&TqxvlMSM~RwQDLa&4tW(}&b`B)lOg*oiAUh{oRIh6{6*naL40KNNXgwVLod zeycic@idW%j99AtgfEz~kCvu3k~vg`v>(c@j#x5$AFE$liBvhKnmH4XHUxQt2&5Eq z-|)wo6s!9Xj{;}EH3Au@3l%I>ZzCrg~9E9CXhbDL|Y><4s6&X3={NK1aL! z9brrsLc2jyQd|;nDLJ@kw5_tqOR@9!ADF;av&fX`RQ9;L3C7tC5)_4 zvxAh7b+?5KZ@r^+hLo5A@_o2Q}VYn|gdBFtlGsr%J z&4;Ga({@7)u)+HXJETVUp^nGvxiwN~PbA*o9rXE`^QXjXU(82>?*$2F1zy){M3w~l zz2ZWfSg)=^5fcud;dx&))}*~9c+N;b{V!0g2?vGm{s`77({L!-9i1FATB7%ZddI*vR4CXRxK{#vDDT~1t~ zHOJF)n8;dVWN36H+$$r~l4sy0TPRrx>37$~bLX!2b>Fc%T{~{czX5;!5fz^H z>+>sMd_&+=CZIFJS(QyPV~qq=%-}+xR4Tic4Fne}3c5yu_Js9x-KnK5MuIBNmR-{2 zizbZ(9lBzmT%v6RZ6ajKDr`;He}=?7(&d}mtwUr0T_&Btv6e3W3pOIV6XR{QWeyP4 zfJy1soBrjFST+k0f1SI-;A8D=Q524Y0Vss=!@!ZdyH*<^1CQL;S(2)oF0Y%H=#Ch; zV7G!q%XRsWmnc}$+B@- zs#etE7^RVjv$g8=h_kBUKUxae$)&NVi>SZbr^+z!xyF+w;-Dqf6?JI;+DLGuUpExl zA2@jIGAym8(NH{2wNX<@58dwuLlkT4x=U|&b=~9^M5icUq#H>%z@60>jm~_kE3yb; zwNj`oR=Q*=?reL!?*64u<5eSF6%{bR1A~73zR3uc%pGkE@`S!VW

k&h^FWo<5{gJ1jL_#6Ms0eAK>wkL`Tfb6BP5#E)Hbx!Lcz2j6D9 zm56?9I`RjE$^mcn{kwNQJ_ChiDAX=;;3UWzt@~{ax1&e7TXA z7qTM%!xxrgUFOW|G2exe7<7Yc>ioAibB<-FJ5T^O(sA#{9~z=r{Oy^qi;cvffPByF zD_`GmqYP>L_52o&;^ipU1$MSgf4$p55gHNudnK07xxgRck!}~9dHz8GG7%_b9+LZu4tQ=mogIaJ9L8HR zafwDcmCt&KgR;-=GWjld<=`n1$8$$`Uu18U3e}AZZ|NPuY#I}0ih_~%b0C6C5 z_lI;~p9b=0_q>vHIJc1(J8a%LwD1cGT_l1jwvvETxH=e)iCK4Wc44$U3#R$yt*e|4 zO2-RgycoE4!ls0UIJ>PrGt!!lv1hW#E1cwGJkIABj937-s1g~E;RN!wTe&SO$cj5F z%VD0Vf=|QALOOVgGR!E$Ra)<)O~)Sn-=t*%rrPaPDn^73a?WX`A5KXG7V!Ak}sZjJuhXV;k~48WD2`RtIJW_vI- z9rMeR*%A`0hcqH(rCEBkMpcfuV2{#$d{PiBLSpNMIBmwa z?$br6a(k6lY~ouAaC_Mq}af6forQm2^2dsU9TX*fWCn4z9n^V&bM zs1U^_ubBYCCyq2_pjaKM z#<`IVU{nAL&D+1T*y*7c^UcZl3aP{}2YCYd?wVtfG}a6XOj_)Q#SHPttrEC&X*t?m z=9As>p187Z95~Vu`^Z!WzXUD~BaVoST+iW_TOMu{{&Wbb-@Wv7hTEP~TLTO6d4w|V zCPU3Lr#US&5cBWFn4lmtT67z=!%wzPuQg~)&e4E{#46!ms}1qjjlClmpYp4UV0P)v zam0}0{t3Paf^K?9Q!g| z6!4R8r6=TQ#zepr+s;=nC#tl;%6fC4b&5zxRgoRdLv1ohw*wGSE^lF|=$XB@P>3mk zdK6mOZ=!2Hk2rH1eZSFUXjzRvAFa*mR+V0Bhdx5}oO?_`Iq4560( zo14Eyo_7N|>H(r|&){JO>}1je8(Kd2CUsRV1-I1e8vQD%l)tF&$-p3chGHTg4f>#}Tdw$)-H@VKVd{lLH7CD0mZ1tvpUavc3%zOpF1#&|>k zpk&U5pm0bB88+x)xFjH)W-uZF(>1ph3!Fa~pcU>+l@94Y;D( zwTi$#Fk1Kymp?p(Jw8#xH*$M!=2xxeAW~+4A!8fYSd`&)Ruts~ER5_GYsQ?1K%4j~ zDR;qX0!N(LuRm)Mtc15m-rQQOj;wF>CNFcBXh9RRWVGt`UIm~(={`cQSmBtYuos9ke-KS(PDJ9_oXz##kl zOtr+#`p&IP!_qsT_dUR&1QV(^@7RrNcN&(HLw&8Y&WOuO$YBdImK%E3}X5{H2 zKm$_M;3aE$J2HnypsqMSzSr48$mlvbdEplPKVbOT$({IW)RCqoY6B_Iza@0-vv?#y zDaN7MDYhW>Zki{Q>o77(W+q^_lM29_ua|@xl5p;PGV0uQ(lg9_vhDsL-o>6}*-qf~O8{2sx#GNCR(l>71M%Q<*Zy-7AvzxJ5*jl8O9w zcK`6i1bgzJ?}(p-Px*RjQGWPa3OeUe zgz=+oL?fA!?NE9WoxI$gT645T=;O~8T7dD1F_*MEU}Diy0n?ac4uX?}pP*B#)rC3y{ z1D6J+9!!V{SqpuBqotis3;_$mL8VR~;cw}vPUD7bw2?l9E?Gs?;cx?{kN@ z53f!!<1(cDio)w(y{kL6%i?xU`_hKj4fftJ_9*Z-Y)e#yR1n~}2|rb4uV5Y+J%1DQ zLtHb^%3pp{uybYF`XuJ<)Jza+2w0D9+gu4nEFBDn~%bl^x+Ag8$HhR zy1yEVEN6IT^T|b;^ZA%%o_$Wz<#!JGZ5W;gw}P49KVS*u8g;CVU5Ac#aEY!jRwfer z82VsRG^t=02FTb~b%WiJ@KDm-SHoKO>lQ?_7^&Sf_*mR@0&yM0Ez)H*>>UodKo3sC zl{;B;7`%9i9^Qt;4R3W%Yap1^JzcZGZX`yb+>FD$C5%#LF*XC;UkmG=RklVq6jPQm zvW`LIB3=zs1zSae8-&)tZeSW_h=yB5{YKsE+%yV&itJw=dMWoVbo~(ZUJ71|6sm_? z!!+S|2fu_JYNzMojU?RYzu1XIb+kgc6SMjJk1WQD$IwYsN*f4tuVEVqL}>hY*RS%# z#O}jgm5sCKzgoX0va?8$nTDBeHh;a z#HGO+N`@v?`l{`heZhPNe(^Et(ABs?#*$tCV#WK6DpP(5evx*TWjhEDFYRqJ7&CNg zkhgG*hh49SLf{&L0Iq1z8`6&)3Q-@}&^_-Yj#q^im+hc_D0rd$*#pFdwp|l{Bze@k z1h!niAY=v_be`t6S~dpe6POKBV`LNQ!&tubl(5|Ijw_{c2DXfe{W#d;;{jH$B%MU8 z-5U~cj_z;Y-5}|6N#UYef6HMOmK zJ83U?MJ=MGUoM`O($QzRv((a2Zdn@B($O}mjEn?!@!!>Usf6LKOK~lSkylpHI17NG zHTH(kBeq8j*AjR-6y4xQT|>KOMReOWiCl0&?H7h-rG3b04vY2~i>CehxDV^FtmBa7z|XSL{!;H6Hly zC|H{EQxywUqkl#L3o+?_XOBlo%f{YLhdq7bxv849F8y#7x)}(F{timd&ktY_>h$hw z30V$@<7@mIGhG3{nR(M66ZLdwXvX6eydLnCoLYLG$co~-4b&{txw!p@23t}uH{22U zaw(=cR`2pnasl{ccf&h3MyNFXna!XXZ;3l54i>b^#A5>^p?-vmWWRu(1VrwHW7_Bu zyZGRbTf>=m+m!u~{Ebi;4avfz(fwYhR+y|FlDPmO<~22@p0GH$sS98#lMplQ>2U?? zkH9U9tiyGQ2z&bH9C5 zNq27373WsJew7M{qOTV};;N!KJm2(QKgRWC${V~7M*6MqEMXa7I0>el=_KCuNb95= zCc$G-1(`S8AYJtt#7zyQsuARtMn68!Ew_CcrW};W&pD>=-mO$TM;gk_xh&%+DK5gn z>QONdn?E8*ZZw;{+M#^Exh%7hRxa*BfT1lR3_pxpEgPuYTq>0X?AU|!6Gyp_aiou~ z=^L|#%D`1;D`}mUWovIR8e+TEd~O9_OaYIZ?{^f4fq>*hdO2Zu-1~mL^1U;qwi}nmL;jF!1vJ-*gW_ETuQ44El6GtsN zQR|bKx68$AEDXm?dAPn9As7@$U6XueXcg(^!+-$J7*PDrx6@brF|ZdPa9c zFex{r@lkpt9>4fbecIMy)ilMx4FdpQ$KWhsgmq3eZF`RXR*u%vj9Ntk+qJ$oAz|E= zT&>n(o_Xx~&o-xSv4pyPs9Q~beO3#lrQV9R_iydEPG*-itM<(HVTRK#haFZ{Qm*-M zQ6_`k(L**+73%|&u5IHgs)v@f{vIH@d$VO&aL;>iv&BW1udneo@4H3wt}@uBPGA4u zu8i!q{(1<6dy|aTn#sA-x|EjF`g*2SjR(aUn40&{RVK@GrzRiY{F!pxivoM*fC4~s zw;Q^ts8-LATFKj6uBrp-`-*f_j);W~h2%-7$ z-rE?Mdw)S|7ay@XcxFG8pa%2n1@n5vWcqG^O2lChgmBj(U4#XpP`7;&3gz~W08VT^@losX6-sz&31r&DoF@?367Tt&Hjq7%@Fp=zUq>b z4v*~_%LI=Mib;K~*j|DizT5gcK$bt7@(qu?Q$4{(dXu$e>k5pIqSSIW!ltvon_gFI zhoG~6sf%j(Jyyrs{IUy*Tc5N;@_1C`yx=hZunn8{RB?gi9)!u|pFFNZ5z|XrM+O(F z#3u=^&pmOU^gu&P0c*Si@CS&5xt2nhi*CJ_W!xaQwjSzzrsutULY}~7>BM&6 zPUB2kma90Y+OQn5y4*!6rW|^DnAVU^Wn5E;!~4>gn^h$py*KPY&w7oVa+o8K@2(f< zoz4jLoeLSR0aw%97HPlrfC=ixYo!BJ~lOGqReNxK}0Nzi^98Io8+07{i9C)mhZHg*qC<&jgo z%`X)5H%(sTVd)oaxJMIvrd^;mj^er^KG7)Ri1P3*ApU;rK0;37U%kRIb8v%*S+L60 z&7|cVu%2ak^sG4Z5eI(wo4^=6`Lp?EX+b_&vO#huFY4=pWUhhZZhj%dK6xPtbu+Y- zxj@lR0!`=|zysC{zIM42IM}|w7p~b*;H9wmnupW|$wSQ9A^oq>8?M=nY3_<<7LN3WBS}N1I*6P@;W%69K7GvnqK6nX(db zb(Z5p-Phxh*@~CN53=(}t0S}rV-#Rzr(fuL+0VaEauy5fi6}Ka#9NoKVq$RsNc`Q}y=fy$6WPJpTR&_qz(AnS ztB_UI+W$d&6(|k$r(<*(>)&)(gn8~V#hL~S@-e<;z2rV*HVw;X5G?Z7Gdsw1ab36hf%D??m=Q1&jeKlIv&3gW zS_@Yp_aRws!gmD_ybz|mAQq1|(dK}pL{yqYbkX4Y6K7n6xHT>j?b4+;3mGXR()H4A+j9bgM05Zwt<}BaY|SW%!o;{X}D7;JCl*$f9V^XXK&JG zBi1oPrGnn>eO6QYAZPprXWBP|y3IoQNU$#P`aR!8xkk=hR{|<-w_L!q9~QMlA(QYK zMR@VDexj8mG$J}1#rtcniqqI39zMSJ6EwP$!++QDnBGp-rp4@hcm8E_A@At#M+l6LuvCpf$kYj^_ zK2L~PeA-ot(3qLS7NmMHKPBRZMnPCuL4r{ZA#=ZcXk}Vlz%{(g0a}?;`_^m&+Iq

6!H z2OK&?da$mp31)jMMABpP6`uzzGrmm5L8Xiy{^p_kD2zFgx%%y;VJoWE3zTB27fzAA zWgu`&jva;oACXTg*9GNUAIDZrMokX*!Q>iHp1>q?!3KnloC;%x)xS|r^V z!2)-@31*C}lA^C?oq?oAa&?0LRt^pwmC!FG>!OZVwlS-IUn*{C<+lj)>b4TvE*8+0 zWoG|NC)9;|ib#4wf;T_#7)J6Rjs2_|&$qIJc-N28YMR5i`{P2=x%{eF2O9Aj*o&Z7 z_XYaN&wPLc=fFd+;&pRF<9NehzS!;dSsyFpN)HJMC!O~!sS>eQw!&ym8V_ET61H)2 zq9l}L&q#rl<0VL5n|zydW;b(bs&PC+HTU9yQUbe&YdqG~CS!57=~JnWbS|U9Y&fWr z5mm@YnD^oE-iV&caj2jNjp-A5mukAz{t>aa`%~3JbOjA8@VVdh*K>1vg@FYnAq*fZ z6-1tN;~0Ssj|&QZ4jOKNtWU`Db`tL%)rrV&z;J3L+j%5go;z6Xy}(^JzHW$61`A>< zmE5OG{jkpqFbgL4yfySX#4s2BNuT`p>*NB|mb7{U2%{$GrtXMsa3`;ZDXr|!)xuvF zTnch~#wQSah?8R|6$<6Kp!8#Oc67EC@~>E`P?0!Tvqk({&+&1D&qK z3akgC*ZJ1_&|a>2vi9_YdM z2mleJgILQ?i|LZYydNuBQSe99Uh@>TJHy8yArFZghaX{t^Y3?fz3nqf@onegFxni= z^2s#)xYSbEW%ZqT`3cHGtc|_weJC^9E$t`FJwnxsAmoEoVZBQE?j-MYUaDd~3gmH<%vY@*oybdQLP~8O?bWn)rdWyLF}M&wfYQgjpB5se0e+>2 zmnh=FyY25Bqht*z9DfLfMSwlwl|`WE2_xZ}_eG`Uob`6NfLk>Z@nI^r5(E5K$m`Lm z$IvI@PmO-4n8k7qW=aft5I%fZE5Rwcz4W@|@eik)Fc6;HFSiqgIA{jNF~0D6QOrDk zVBJO65w2?u25|?&jzsk%JLr`64*CG*e5`X4^dYujmkpX8`qoVG!IL*d8Q*<6!_=K$&#S?EDmMFQBfREEli$OQ{`fDK%D6K zE^pPwYGVG$=QsG_n>XeS4{nL|g-ejyCw7CbP_h$ydXIx5iO2n*GnQ{$6mPH!Pi2C;qZH zVg|2|t`1gPBgnvY1*0JWyZo%$e_U`3&P;NJ5@mQaMZ!ArkU7yFrN!#LC4Qx?KkS66 zNZu9=rMnY4u-;%P<7GZcod1XjC>=`}Z3vnSrSMuncGSO73GKwpg%k4q2zj;4k>hNK zOW+FxeQXut>N+ZFJ}1rN_iK4Ns82JD=?8_XiwVU%Gz*toV=$3PnI3Z3n3h{6iK&Ov-VFC6J*WR4$p{7cgU5<&p5JF63P#FB@CAc!pmxFtsQ zz}cqM9PA|J0_cYHTBt6{h_=&L^(796kgGA`zyyUis&EqaOR`a6QTL711RjJ6+YAQS z7{hrrNF5*yYT>|hhGn(D)iIaWb_i)*>s>^!&T)jeNQy$qTN~$qz)dE9v+L9deRq`k z6P#B6@{WD{GF~upB`n-xvr{2ShMQ0Si!#gcPX!wZGfeUPZJ9<4lkeSU05K+nafiO6 z&o~q?1Z2w16FWI@(?1Y5vT1hYihbHJeuGX59Q=3slM(Uqmy*9ATfh6ECBkSG@YNi- zgaVC*HEe-LLabh{ke(Vuoij-X%DC_Ee>@P%sJJ?<+nGWfqpd*>icmag5qZQHh{ZB5&@@3w9Cv~6RiZJX1! zZQC}^?7g4!BEC1i^PD*U)EyO>xpGBC+*Mco@~V}|{Tcq0JL5IP$@eep<10<_j69HC z33_}1C`IVGTU?G35?RLtGsdhqgK<47chtYq@~nsiy9U$AFEH^BHvHoy+4nah3J%&k zv>%q@A?`6vQ1?x_w%JOe`?|++pREoJ6Ze4nmyfhuUWz|>wWHKY-gvc9K*KKl?7_SU zV*r?AP?gh3&Hf;V*{r~yhOR4xrPZPOBel`dsu0&pQ5{km2Up_ zV!nRq47UFb13Qj0#?zDR6>gwzP5`0{D`rcp=zD zlYkaRY=lg#b6%f$#8i&wcyWegklHtFPa@28gW;xUlJH7S$(T)XsGFigqRVg(e#1cr z#*Pdu$Xst#>vy7zG`w(KIRaQS@k>9CJp>|>}sVB~{`U%@8GEX1;#k!i+SAMPND zxmK|Wnv4j^(Xbwd@0^(!x2%2I(iEMsdZuvKng$@p^Bf&&H?FEay&+44q@|%dLMQnb;(um@_m}n zC4yTZegPT>s+bkaW(2^xU@&Cx8wucgy_4R1Uo9;fnvx8+ey#6&Uzq_Me*YuS`3o=o zH=gr<;z{iPG2s6nwf&8+{tIgR3opUL|F9V_fMwxr;n*iH&k%%ba)#KVu{m;4-&<`aZ$F_pO3RQscU{;x7=r5 zL4(gUxZv~emviI3`0@>ln+>1bYT?Z^T5r>rmK7?SRT)la#eWDG!63~eyNSiOmIvKn zQY~%urUTon3pWOxufF<&g;~cVo~wx<-OpZOC>G?DS1Wpl{6*#H9>UMuqmV^>dx#nr2y00W_dhn_z+V(M4i*NG1) z8Cqpl;td-n4T&WAAfkVxJynK8+gw0yioyKC0j-{RUxIy^H1F!DnQLaeH6)pW3AJny zihv?33Yab2n<_G%CPbgrFY(aLvI26H3rgrJe3MWs;bb{6-H$2@>u?=+$8OX#pqKPl z?!uU*dU<;=#p8oUJdheFL|!F=pS%rhTT51Ji{Nz>kLFesF#g>tOaY8?P;km@pUhS01wovUF{ z$!JuBncC=@yoD^pBD-z7_^*!+Xug&G0E6nf>=;u|9g09XU6yYs8HGnlcfZpOY$GVn zQ4ZJQccW8!PIj+vYI^Ym8Bd%WpaA4Z`k;P-J$c%YaD_BxfK(twE0o^MrE%cTQ5lXy z#e9PAY|u&12oq{#6l~IJ+XLjp5y81UF*2}%LsTZo((wrHfd?G|RI795paZZC@8W+| zsCsFu=^&0VVyfW003K1I<;a$AyDPR7*li|M>7j0_>u~0>0HOVB^QZuMh>SRR6A%|P zx)Ho1Y2i4~6y_%SCvw6%I%&R3-V`}KU>Z6tWYDbE!ajPbs+=RvFcBB!06N7&4P`2( zJ_8kwDMMw3__)&_xQ{$lsq_R?Sure0{iy4w#$r#*$|IK!N#P;wM+?q)?u1VK?^;1X zm{zUf5(B+{wFggA?>Es?PXQOCWg(+Eq*T~Q4Z00=`+PTxv!CoGY>E^R{1BuDR8(G*#-aoy?kufwk@#HO4~m!AxMH_7uC7l zG}hHTrblzYOgfYk4h<0q^CpfD^d+_vvZjNMfdaT3gpFqx)%QT6bEM;IrB&CdHlGk3 zwOol92gXZCe)=T$v&)8KjC-pJhAF~$?$^}07dc96X#|B`WHhTvCdL_|#i6C1|16X+ zWRm{D{(g^*7YHiN*rO6Tj!L?99oLRF)q(^ld(A%3&5w~UP>X~^7#y9*C=t`SnGrS5a=-465$((= zd@x77QHxX}G<#uRSD?1f-8q=$ZVOZr>oh!kD>G<{_W^$_&o$))Y;u7b?GeP*5MpURA44FfZo251I3Qi<~188a98N> zVjgStHA*wvTdTn3l-!4W$eThk(*59?a{_1#l%p9CoT}<=-W9;H7hJ?YYogb2LcwSqgf+ZuwP??Q zxxLTrme#<-h%-5##bU#CHKucSLwYpv-W;6S{f*BAT@emnz4wP|F`i;!8(g~jNsZkp z&ftJx-ga59sTv@ZgH{n*E>*A+fT&=m*chUy40a2B3giqjCU4VKoxMa{oGIBZSP_9Xza3ZiLg&n zx)}^AGQ{lba%BsbI?7%X%l?3?6CwQZUmS+E6no3 ztuZ@PFZ*E>_LJW^wDb$ZE*@~KlO$O zNcv>GLUW#=O3jK(&x+S+0)ZpcYs%ju0w39Pt~m7}H{W@Y(_)G*tY#u8gF#GFh?h=( zfQ7LHQFG;DAWFnh)Y@{UAt9q1H~rp{ufIRT)XV3N!jBH@pj>Cq-In-1ZGJ|q{5K(Akgm?MMHEISqYBs8q`;sh z1pgZcD-08;@1_UG^qPC>gad*^aKM$4pjC7DS>CBawyvuZJR}|h#|OKeTBPoSKP)PO zg637gw`c8J^!NBw@?d2Jx`N-!vu{Ej?GSPf{s_@{-aQDLyAUW>D7xX;1*0`{_;{=3 zV{|W$9FMVxhZ(#T5yW&S26{4#@;c3?zlIHj>Lpbjf?~b_hC%~*Ky0f>ssc>xHjOPl z!JUXX{qGykaD}&4)=tRwEkZkE&B30+*C}vwbqsNy{cRTvRu4IA>2yar<>bS-DeI

@bY6OnQSj|=y3}pNcM8g%w8SEt|Yg`PqWfrMe=grLLxx;>7Ka6FqjH?kd5Bv zC_4_6b_Sw4#)2b#oB$8?fF1Pj!l*mCAed00hFhH81j2B-ZSHazlqtuMhg>x>(3%wB zP#*Op;jHmzFYj!i9+(ZcA(gxc+!1cnZGj#~{PImG?+GHhhx6or?B%Straw1z?ZX3H zalBYy`4e;3Y&)CS8gZ8h9)R|LylIZ<>D#PG(m-U3_4EW*orWd%*AZtF+s8 zMrlU!xH$Pn`2!W&F2}=vj$HAbcYajegq9{j2+W138_Ztl0J&bO37Y6&D|<0kM$npay>TrDkF30!ig;>Ia@$rp4_-Wkg86LX z!is}kAD66bb8>eoS|Odmb(EKbMGKyB)$2L{BOC2I1E9WN0}()OPL(= zxq;fl_Dp&D(U_;%;n?rJa^(S~;w822i}Ugh9IUbw79>=hy)UrxU5EFplq2qtW*a8- zI1QPYypcL*rUV`)U0QCMh9y3~ccPcv>lsKZ8XPvOsxAWi_GqTvzbfB}e1wD~kad=> zL+^ys0^_>V%;WcQt&oUpli^x>A6aL`&CpukEXW~c=?HE~1DnfXFGxJWX8GvHTB)jqm1HRm_&)EmTSTc_>pt@3XWFZK zd*;e4AQ|AB?kEY!PBuF6exsbt1zK+OO51i*Eh(j8A)1g5+r%(7VY#R?!!Cxo(f1b% ziDji34AsS97~pvfz^;U8b6~cnEvc}etX+fF*d*iT=pjZ`Nl?3F*kV2Wc0&)WKbIab zHto|UZ@b;_^Tf$6BhIm_bg|DEdT}fq5KlyaL8TpT^RRjO>a7dq+lwdZ@0#xDdAO@1 zmDHIfgqHea?>6+$5;$6r5*P+VJ{CEiP)!hf*+<%zTuCu;#tnQ+M^$HRFEIhjJ1fx7 zFRcElw8kE}nQ)2s@^)c=&gS;-0gO+RnO%Gca7+z|A1WgciR((Uce&wSxJlbe?kIUqmBbW8Oiv75Hjfr)MAE8dgU}#j&B1DjAidQ!jK z9TRwnu|+w9daF7aNjRll*KT9P6Lp6VN-spZ0yPA6C&tCeP>7zLoDD+O!Wl%hqXRo_ z`b5W97}Nv*)Qlqul<$mtzE0D=DJkDth+HI)Q>a+fF+VR$Q9{%NMl!~eDlTpA4nhvi zN{aFbgSe1wPKIi7A?slzsc!rq3bZP1050y8oH}S7N4JhF2yD3&lWVU4C6Yh z!r)l5!OD)y@<`KAkKWm-X~-1W^m=1y|1nE!1cpLsKY6 zr$W6d*bgxI_xq#@eGv!W*teF70FL?@O&mn}I+fLFDFV#Z*dreG98wlJ3giGqgz8YkXEa zPP(-05o{1&9k#y`jR2XqW0N-@OK3q9rF%fN<&7T=FvBeK+EU>4LZLnfHE7pC(@w?Y zUrOAl%z0ljU?>a}`w`m;@xQSzuN>8w!?8H$0K=|(U**XuaA+SHUAWoS&e8sivZ4uE z>6w68T_$F@_&TxWbnlE_wg#Aw+|scwjs@Mzlnifb|K!qI!9o29gS$F^k}E;ZsW4b2~)t>5uK zr$Sv%(xz$dpNgD})g(i5}1~LP>tO{d5wVt@U)sNRtcvolpJ57ZRqA)8drIeI-p$%xaqz$0TIPCJJ?tHZRA? zJefw7Ej@dh$aX;mfXw5=_?Q~vo{(qk+ikHDy}U*-XSR>)q?AUU?hvR`q$C<`Bbt+0 zbHFiKCFwqgxm9^;qz4YpzRi$*?B|%@ri&U=Bp%Rw$K;|Rv{gkRdATvgCGZE<7w98a z!3by7EwT#oO?n+NLqJfj+vS$h(GXb~?g>N)%>7vHr8l7i`4G1+gl);74%b?n`?Cof zb*nSTj~(3xiAj4_^t|ljpU<2{8O|;l1x^s>S&b%S3FaRBNi|Jrqd&@NVgwKN6fRo( zTTc!rTZQ|u=aH|hKd|r%=_fRbbwwqLspa7`U+nL57Kp3 zT1U#UqDTjkI)aq2sJ_hB(7?hD7^gqGm=V?~s>k@O@F5(9;91;4P_(DzDu{)bDA;MOFLHq{FdRZHgr`7uWEi;@_h7k8iyH`bSsc)x+T!T zj!Hgi-jo1i^k@=E7>n=A``!;dx?9{kyrtceJ}I%_e z?2{d?HL>-Tej(16G=bKyoXSoLZvV zS3c{hWp+i*qgUf*xz8ajxC^h0OnEizs8~1D)WL<|Gv*_F-kVywBtExq zh_P31Z%pzlGCm0@e?QxXde7jZ|BXXGJ;Wg33q66XK#l6=w4K4R<)Fa`>9h#eml?wAa4J3j4TmVT?Hlu8gsqwnsQ6TRZrS!ahnnxz z;Fk1-k&od#+bm=qJ+79u4KK+p7{#BGNy!2CquTRS!gV z`O&}WC<(?pt$831RpbGm&Gr|dqKqU-_NrHgzy}D!bF>^1nKQYD&J082@K=7EFxyK? z8SY02nh^|o^8X5n3eJac(e~?f+fb(4OccweIOyVPxT6Q7NB-r0QIzC1t=ZL{rIYzh zSX%tR^UoEHcU2cW^*>(RV3t($q#NfTxIOE8SQvPJXAF-r@?}fY{-M$8%ggc+s?{*0Ao`VXb-8h zdIH~;`ES9z%&CjhuQ-aT3A;dxuC!X*Qf%+p@T)CK8+DB9XtQ{BGKL+dtvMBp7SC+z zFUtLTrrI?L%S`cFQnYx_mqH_C*?b9xUaHlITr)pMQ`SVusT-LP__Wt=j4|04sT% z%tKzohWmijt4n0c)%6eI3sDEWdSw(D+L0k5vXfaT#|vEB3`X-%M(EN8TFpceBI3Y( ztI9EqYTBZ*b35pvC!*z0Q;Jw0LebTh6!xkw_#$nPA<50>xQC;_zY8rRL>JbUp*n^J z&xWeZ62BOa5W+VhPWtA&cXFgE(#6!24yH>cnx&cQcKG|j4ZOHQ4luoH^vHeL8m(W<{FO_CIR#1vUuloEBAzdRX}|+8-&V=y2IM&R>24h&GSs)v zMOP~+)nY|5pm1f073K=)Zp@jtQ9n@e%Q(tMrVD_KdO5z;36?t?uiD}$e~+AY{TWcs zV*tE-dmM(QWax9clA2k|`YSn5kJt+L$JGF}hlR(>0hbukrdH*-Ej^kfe_dl{uiIs@yZ+-n=H09qK^PhOiE{4v3x$MR49Bux$ z1Z3r8Wnur9X#1~D^KWth8B;?pfX+ zk_mJ?aP(mlTQr6`foN~0u*~I>ALIq9lw&+`tR)v?4wJycVKT{lUMZMRZ9KS0BH~0o z2MMD%)y7{N-A}*2KDWL;1U^$AU$?$~e;q7+eZGJBeR3?lmev1u9DO)@saJcmtgd@g z->Uwa`ufx9QQ#xB!eZr&wpxACMWEXIN_Zs?6 zz===ljT{rV3%6$hKcQ>QOux$3wqMxby+7xdp8N!jy#}oHy)*)E#)jESxKM`WE8V_>>)0^HyVAoQRO} z7Wd4x`ByiEQ?5SKT>Sa!On+o>>sGxNb!t5yamvyj1cz#%P1CwJhmf7XTwnLP`>Ibb z2oi?p#+$cXbU+XjgLJ$2Zp!{1jFDwUXH|uFD(04QkRrF!XjXm3ptvir&}X~Sw_);% z4&K(E4t_J!Xyq~FNLJEljFdtnzuNpJ%ErNyJ*5P&3bq&i$u_vLn;u-m0p!arImaRK z&8Pe){+N|<4XjtXjiNY)=6Lm_iJt@|eT;LyC^0<$2V^vaj!notSSkCVlg#5C$D#G2 zTOK<3H)l{#PtIt?+dh?uE4jO2c zwupk{{vNppG@9yTra1~Es z0KX6NqKaH@DeXS`q&50<6c(ehk6^!*7MALQJg*VB<5ZQ4PU;&uX+}LY9AVjb6GFH0 z4Sk>Fb(r>ztLO6?bM^6(L$yzvu`$~T2#3bIDBlf^#QRve_tL%YV}Az*7-lx?58pQPixivckOz~}82avh2to74Xy|E-Vani$Iy7#7)3_gTmps&qtM{(>| zFT98$^raYHM>dhU*rDtp{q)ALyGRSOW1!qjvz{e&(bqS5aAoy^DBwj&dRuQg z1SR2$Tgu2a`ZQr65jzK!}VI>b7 zWf*(P<5?bz5A;qLj;zk?OoblC+~#_|@e1LhlgS&KI7wg)oo|YaO$lN!Lx9R8PEiat zhp6Yf+B*o;&qj&CCFwq$JkJ*v!AC1N2 z5PM{A60d2M!t=^HyjpaQH%F4z1tS*#M#NcDO0OA?D3ObjgHnUDXS@ug^PkEA+8*(b zHjh!yIm$`mK9n^L0wo3wM^LiKETIq^A}-_W>zMEMgRAcW-eV5OwKgvTj8n?3oq(LD zA38@Ab1X43HO7yIRv9UTCZ!fB6o7`*!>0;i%2omH)L3qLx%VXJV4sg+wMMWg%DNc& zM)x9)$kCcUYoQO;gXy38oL<4soZgoxV2S=ejRJSw4JPM1l<{Mub21)_B768;{`e8# zn%GYg0=;OGG|3MhlOBS`dM>!Y#d+v6sJpmVQMV=8(H-sA0zpdlw;zvh9ngSnd7p(5 z*kuxTN8H#M$PTta+wkzxkXYB`YMBYs>M!0)1sEA1*X(Qch@l`Uaw5V%qg%VGihYfQ zF!-@x`XJmSe`gatKx2l$*B6$qTwccZEA>~|gup{A!2y;RSx&+jv6r?T3iK=dcobQJ>2?FV^w$mrdw&D9IAzBZ)X~UIzz>BN;LA9H&VQW6oz{Y}= z>b=o>uAokhI7w=KAbYK^8#`@`&1^%untW4r4Y1YeNTpL+IkxP^5BdR#Cyd;XDkN#3 z@Vyz+5EerID%N^&Uz4&Ru8Tq`4-Ikp6eQ3ef`qY;~r&v__ znw642)keU)gud<4blx5agRDWV(%3H0E|p0@fUyx^$ydA`(L>iHG~{6Cr>*`eXujUg z53OW5FPM3}?-Lmg;DtO%A$lDzx@f1))h4mz7!h4WtB=1Ag^9pLXk~WYSId@p)IG7O zjf5c2svol!8d~@z9p9AUI&kWOPS!9;7`QrQ|gP@XsE96mD8akZcv0J*H@x$)E7CF`8o~AH9G4 z72Q)JL%+D&peUPNS8Z6v!Nl&Vok6h~;Ngi;-3soXov|NWM4Ud3Uo*n`fv;8#k{`_p z3;#0^2X**6W9j%g?y73~KBM#ITEHS?xICj+uAW#V-HV?fN4-Zb%xq!e$~t;F9=F<> z4cvT!br~iklUH0QyX{{5V@1aOQUE2*;d0ju1tunU%gEb6DoglCKqv2(zZ^#v1^KW5 zqls3Our&(Fnz?siy<%;49So4U0*}5xV;Qt%^R)ADW+MVm^V9| zF{J}f7BVxEe-@7$Ure1@j(3HYutQ$e2Q%4ndTd#I2JB13T+uiVVu-h4d<}tIP~Tib znG9z*S}cRU$R%g(g+?U@uZcfrTEL_~rpcs$hMzt_Z+R|V(NXfZg|cH^4W7yq{vfEr zlYF32WH1&>!Q&d{582@WW{z-tW}!qhmPiP$4_M_gJMCKhjGyWcA+X?^QwK?8t?F1t z1wMSUo-T%Yj}OOE(vV0E)#A#hzCTvX31mwNY{vN;X~XHYj+2re7oKjUj$8C+;|qPT zvqWy7uOmoh&uk|XyeCdFZohwj!+3Lb1Hxq$=OUgL2qrKS%wDg|0mPAm zB#C5t6npMH*D^=v#KkuDt(cYzd$2CDFgA#;y74^ajEwKiutvJB;+>Y5uZuAph@FbV z(KevswzT6<_nx<1R)O*sR6V&Hj+pQ-7}D+rzMcj+SnvG#OUD^@02JDq?NnaMhD(M_ zbaQmFDZWpou!SJ+md3K++~3tqO_wN9`@me>UARnK&n9(M20RO;G98~A3}xZ3wNCpP z^s@7{{lGHLBB1cVLmUHj8>sHL^SZbHDzpIc#D%kEC{m6Z+wl;EOu*$l(ToH=&`vJu92j1!W-x`SM}8SCVX(j4t= ze-scm%f;53=wifT=Uy8iG_Th+$i|vga39|8H?(`@?*w3k=7e0lBKyhVu$q}UGY1=` z5@f5PH%sG^TOYZ<{pe%BPh+9JVik`Om^gesq(PL)lDOO9U7p7jbA)5^$mo$8%81{h zi=KOdg1zUTWOmnLNZ6p8Wh6-7EOJw8T`i4VMpa$BlFas0tF_PP@apSxYM0>o#!q}8 zb-L>P>>TgmSB2|}DrCSNi|5rBQwbAS6;DE0>(el5!OhO2%C`(rGgi*WA5UsN{Fn{z z>@E@4BkE}r=3P$(Bh947?xHDV^f0oJaKqbh;>Pm(VKT)mr~V`02p{q3!)k?CMF!R^ z?xR2uIm2NeC_lKGg>fqNfq+MUM*T$zJ1eNGaSz)D2VRSjqFd}NXFhL+F1rh@#5$xc ziFgg2J@9@DgJ6k$fHi?trm;tr0)-*pz$j+mClLg0T4Y}L?@D=7rjZmMMXV9vzHLx9 z%bmnpDRz6trckZ1N6~;3K8w+wJSw&6O`Ak%SlaC?E8wt~mqxPHy8MAs>AQ8j;1sy@ zqax%MafsEdC;T({yLIOSg~L`0%CT^CZ-bj>B#k1Eu4)LI5bTX%w+s~$67(HyqF+!O z62?uabU~`n%M(tJpm*!m3Cb|Q63Kv!Oj#cJqSjIkSdNJa3ebYJLyF|lnu&=cTInWk zmbY;RKUu7!!#gHNNSvc0A1V5pJX=PXy)0Q)VQBNL`e0!FB!|hAs!oPAJS64+F?=fbxU+s!*&j+eGLI6rU@ag>X;koNFDRUN=3^+ z$0;;{kZlHwQt9PscGd~CKHml5FZf{k8FsU=^!+9R_rYw}q(mE!)U_IsIN?oT2QMQ` zl;DWP`gW4uyWFu3qCLFDE0kbs60WPwhzJ2eydQEP`Fq-$9{($@GL zBM|p(GEN~xq@T(} zz=gQvSL$g8QK2u4jhnlI%wsFBl=w%+k(xv8YX{w+LBz4k1=K4Ca1hBMx(F(iM|#MW zUJ4GKg3Y7gKg75giMgWPb|9NF$BW!XCY+Iyta&WUYEZWAQWYoJ@7=9x(2hi56K0$f zrZ}O-v!q@x4h84>~j@7uPJKw3g5LszCW$~Re*WZ**(X`)48Qd=m81*?uRvrRr z2@I>Sxmg~sa0nfGoEn>3wqJ(x-E^+K3#Oi0wp$A@he^z?@iBRiKEq(yqlVn~vH?pW zqL==*@vt%)9fzc>9Yf%d6waOQr-)H&`_?T9r4|WJ{T_p6FC2&7+K3-QL3|8ItV6P~ zLq%MZ-A^qBed`WA5L>{jbVv`WH89DyurY-mi{8ZvQBHg!Z@R6d=Bg?ajmA~ zqZ27U2&hEKRx{N|Co4`io`)T=C`1lO72~9xK|1^~)AqxajLQZ;l!4o3psV$`LA!;E zjN9gAO~=`Do9q#8hI$(*8$@`<;;v0fLS7r9o|NB4>r2Pe^A%`eq_B8{{Iuo%-Z^8* zmWuYv{iyXVzymcSFEU(J)&ANp-~9IVAt-glN&5aau{i}UHq$&QEdc4%q+u92UO|vS z@^LOM$NKQkCaJ5Jo{85D8*S*lbC1izNI6aG^9;P2`$^{_NIBy!H*F@xW^5Kp$>$9& zPXi{!oe$8d+14+-6=tUNTj(cU1hVA#nlSQILZjNotxe>-E9>pK)K)HS?+Iu*DQoy- zyp`h7h3Esp#mVZ7v%!?>8-hC{+w{T?7!$*LBqt*Vh`%`0(CsDUA@^pL4aoSg#~Bf& zL+pPL&C^%{Ne+IQ2M^iE0KRnc(ttHm2<`ND+PE z3ngQTrl^P#!yH9S${f+Hebmo+D5n0}egk;yD|7-d^Z8Q}9p_KmJ~Vz^t>U}0ioRtr}i{^hx3-7TIx`=gd?B%8-ZlS?b5~q+^aW%Gy+nbe)+p%9;fYQX;N7WsW0C zy{po`43wc&yQWIsYL0^$1WHKENL*h^b~$CkU4XRCVAjW<+YJxaFaW~vJfZJAcwRym zLA!lqP~`jgYurGh&7VCRN*j+Jx>Y(b!D|~+$v9vPdB~|78Nx0Kw0|e`H%XRUpeHQL zDRl{>)VEGXaI+ZJHBvkFE{m+3#=q;JvA|W@p$z~T4Jo3v10HA?d9|CEIG#>0eCKv1 zAnUR^kOnGZn^Em3pW<4mO!scvg{>XdeZlV&$mRZ=I~}Pb5&83i~AMh>!3h*HCp0N^MC=cM-^aa3+P-cE{ed-k!qi?6yrQZ6EW z4P>$zhTJ3R>I+1ev?Iyd)fP{kH>UEb>IoICoBO`Ix&F?NG+Yz;2HgcKf8Nr@3A00E zCWA3?&dFXwpjj6vQtK~_#)E}9079xbzFjJanC}tTJnt4^*v^O{osbqF{3@_4H{xdA zCOvIbZM~5WN*_*?x`g4cqX!tkcuRV$>KKD58DM-kH8)Qb zj(Lp!vKLDupn<Yc@WD<7Tr z>*&QOkKgjF`S%f;ChrZmmfw7U+T9mRz=K>zcki8WXUH^2as4Fds*-)0k*@ zyz!qUCP7nyVzFKN5C$9;Y)CPRCvbU*KCqGGkY~=5)4QwV;4h~jDJa1ut5}v%UWQy6spV*qb13Aw1~2(v_OcI4x|(;>qbQYT|)C zaFNzJ#JsbK@xX~-$}2HJl@*SO)cTG~Y>913J!!R_KAx{rmr_~vo!yt-$*ZO2xR?!A^vpVL1o}oi7+45vHo0dga*U~*pN76h-e1uw>_<|Im|jC> zsyY1UaamV1JYHDweM?zFQ1V%Ounq-DzDU#Mh)ykPi$+2%2m^ahhJOzM8whTS-j9mHU@ z?vF-(`&g=9U>dJK?H&{A)@tW>l`3-h`D=u(IE>T@gN~;CQEvi@Iro_1&jV5oX(2y! z5KV_0m@lBG8+zrDZ_HGFuBBC zES!O@ZvlD)SwZLQq2z{;l${Qz$PxI?NnJszEFEXojn$&#Ig=+Af!|ATSYBfxW148r zr@y4ba`|e+whd@>{-H1K!=7p6p=W#Zda;5fgRL=p2R+&9c+89Sv`G^>83-`t3vuDw z4huumZp^jknfi5SP{)v^1(BW5_5&(=yY12%KjGf}o81gr?kF5LqRyU-Fx**S{P6%B zH@WH(&jrjDFkj$g@OL^UeWGx3{@N{!5v9s7Pym|bpVFYIM++a>pe|zEBCx0yf=8_6J|K9cIIcIApwVp zQnKCMjAT`N{NOkT1XxH__vWTkJ5~oyRcZQD*@fp^#~O*-5x%qyvmBOo4xv&ivp(gX zu-Kkye311kXsl{#(+j4Qf*2Tbl=QikOG7OU$v;sEc-Q!(5ye6no(z&2l9&?pVj-&> zd7LL(`z|?J870<%S|o1e-2;U%A-?VLhT%za)l#a#Ama_CAEl>9Z&Enpv4gj38LZjT zjILcTQWFlAZF)oX#~G*P+nolu2u`~_blcWye0CP@#e7ynnl3lK8)4ExuJ%m#g>dZe z`S)?G6DhX(OH*iZ-!Rf%lTD92wQ9h*eYafv9(Y(Y*_pAi&pzv3RKPFZfpzONd~a6& zq5qY>`BAg>_2TjP_3&~oAa=7hj(p>UR31>`H_7sw>2vzaU~-wpZkAOZ9kmX|$oF&P zoJo`xONNtspgD^5N($VS@2CTdFOv`hk0n;am0 zykV9B`{v=UCY-zJYSdQvs0-$}2)wr8n8k?eCRkip+yv+Fk-(h8`}gB)`C(0F^2+82 zcsCh&Cjd%HaAFeg7APGAgScHrrtz8WQfm0?3`G)OU)khh$RLey1HM9a(&`*1swcv^ zDXo6OyEG;e!&`>8X2*ONL&i>Yh5`$>C0ylvV#c&wVopn9OOfo^K{MWNGO#QebdR%N!=Nl3XhN$Xb%;wV+ncvlt zsr$9mx>Zz1J4e%=@FkJbZLzgy9;NQCdneL@aP{J0W79-^^JRvcaIICNh`JAyZgpa! z36N_7r4szFIG95Ep-8IznPSS0neBR<)1@twWycj7Rwm_0?FA{szE<~X_=_#7kS{Hl za?GYB{5-a|5Y-!Kx*%GorQT*a9}jQ)~BoD*zb zcVVe03>N1pC_@c+d-?>lG!ASX1atkel~Ip%f)mF+Jew z(R-kzY}aeqS2P)oGMmnGLjVe7eikse9CCn;?d}U{6^bD6M&?XCgJTE|EKH$8(-6^B zCu>L!KTuazJ7vv5MV<_hr4aV`vrh+{dmdwJaEEzFjf7ZjFy6*@nF$>;Vot))*(2 z3o`(^86YpDmLVf1u{gK5fV6ahQ&w_X6^4~lrUB|P zM)JxB7a%({>ISu_pg#WcGX$G}Q-GRXdsh-MsM!Qd2C2*ibR6rEY%1BLicFG)q@EfW zljH<)r;;y!KSL*`9JLMB0YJgk3{S!0z=W#2=ZToGIM_&Dc63~lBC|ql^3k-$r}5bH zMwDe$GoVPGnDb!h`ch=T)9w$_s>ndlvz0aK%62TRo#V}YIUfToq02OjY zL1jEjHW$MAcs2No8TgiMapDeM(@$wZQJD{2y%*dqQ^5$D&t@QkCRP2hen`GNr?oF% zbOZ+G$~3Ho)ld7#Ta~$$_$07ejF}tUnKW6wd*p77%apoyv2Q3tq8yVP2G1BL5P%{zb>bQbN0fmyU;F)e9ZzSweuClK!n3b8ShTIh( zeAL|$Oyx`x+dPrI#WM>k^$^Bj;6pa?%`zYOYCruRqz|dxz0dU7s2QnP7KeIasaOSu zO5#WI$c3&JZ_vrDvD<|dJSXf;hy0w_@Y$0eQ>>RIfzR$5WW~UDgrZ65@448-8=JIf z`L@skw|{;%`!kXTswU#pYgnU+DZeXKN(sW`DLeL?D^laOY8khp=Mn_z8LwbAcKmuD zeJ`)Vz~^L60WYHVD5;v0pciVA9AU^&SLSY>CpiN<$+ARdR+EBON?-Q+^8xvGDI77!7GyFQ#Ko_zRoTi ziX}Bx&KNAPF-~b-_17_#sKivOeyWl&mPEBuM4QsYpQ+AxbUl#bXVA{H;(dafzlo$w zOl4oDtHK6e6`;HPHry_j$YieS=bCc?9@Tc{X4j>yTiH5WjG&7@I2NZpU81Kq#8VLJzn-q-`Jx1lY%`Irsf9 z08~J$zsi~x7-~h}MdKA(5m>I@n)OcMPO-EiY)VZQ7Nn7J9<8YRCDUlJq=ix|>hw`x zS`j!!e}z`$i9cN{GHT~AT`L0pUusdTm(-#IyIS^+bp&^l;3kaP& z#d7(N>rhgB%5`kbA^P$bO|nu`w$36UMEMSt6=t#+O_#GSM3`|DSv@fr0)x@p3r)qD zI;7eK+v%-sxW~rsQi7wO5KvnV&4I-1hc%sK98yA&gn}wb) z7WND$?KdX3m>fG=EZUO6vI z7uY9O*CqMv3eB3*GAmizT4bL~ixTh_hjzqfHj8|2%eKD#ug9NCVCY;T^sxVUHvi7aNG_f>VZ@j_n1L zEb3KX>atRrvNkC8!J236WgO$U@+?M+I@DL@&^2o;GRAGi($G}5*(uhzVL?0_2o2c| zuc-SXOr`{4Z@@X2S9}8pOi7nF1gc@7pw*ak5eb;8tdbCi3CsGr?iQW#I`#&bMj1!RQe-_bzqVVkaad*6 z(m*AmpazT*9P3a=lOHNtD2+#<1Pq7I;?nl0JOmjrGoZ0CVH#ijF(?_728|SlJ2=L2 zn~m(IwEQO`Dd^uk?~OzVd!2Z%)2OGxJ5;=w5cITQ_GSA7cFvOiTbesGmjs7GLsf&N zvoHwy0cbBN*-3I~t_#ED8#PYMJuAadrkmMon;Hg!Rc2tn!I1W{Tqyy2P^n`M1GH|p zKQZ={3cmz~b&W7oEg2jxi`SK{XGKFtf*EY!rMa3M3jBggCX^iB;w4-2GkEyySJH~I z!%ewX1jC>@_|9m-TV7Kp9;-f-oYG{1%`t)K_Vnpv2CoB$BT$%Ya^7iA=f&n_^sy0A z4m%eQ><0r8BvFVMOSKeKCT7Sq>Sbca8p>a3CLWuqVImTYos5Ds7{<_yTXOS~=p-uld#7whDb>8vk~O1fBH8fV5-8@x9sW9tbqJvZPy6oOtU zorzhxkWkYF*PO)Ys+WXFLo=rqiC4w!4fctYH2+Ka3~lmZZcCZvkCe7cXhvAG=g`YgA-_IX<2%Yr zAw#)cVP$nG2B{C`_5Wd$ERN$w7*R8A&PflHusOSYU&7{G#DJi$n0c3=45O7-JB;5T z)qUlSGn3mFDQKwYpyaqi zL3XfJEyBlwCVGJO+u#(jd0w&~_Z_edv-zz>kzhTe*3uy`CpxB9IKrf3LbF7rqd(w+ z``th&|7fWy5|l1RuE_X{)sG?8?k#9pLuOuBb9hA?`jK>KW@Rj@12T(tXr_gFR^_}+ z%I^Z}&6e;pWU~@i@G>lf>-9uGC$o*pF5!*8Fna0@Bmc^fo-D^|A4ikhrw-N82ds3< zbSVyFFGs4Ab&S`dqlIex7z_tpXYm|kMlz#z1_awjA#`+E%kq@I*3CSU=ohmt>;6$=u8GNHiVvJwu_=zWAGHa z{Rf!W(rsY8-ccoQw#5qxm7GEuRv)-?cH8E;_h5KBBfGFg*;g8w3~qSCncc=Gii|GA z{9Kqb_IHB)!6grGg^l-*om~!NdZ;xLfprBxG*8gfwH{DP%nmC-Dnl)AzhsiqC?s%L zF>J9oJ#8u5D^wod=m7a9-m3^W$TcvPcS0HymQUWfCNYx!b-Syzi0#2Gp2j$ML{lwZ zXUYe@=aZP9&zbs(%Uv+?92Vf1v*9<(SN?&qNF%P*P|V10Oz-4E&r=k${=y`queYau zVQSZUZkFQx0}*ucJ}M41r>un6jR_$h%wXzr+5R8I6jdTp05IG$4UzB<%zE^b!G7QN z#Aeb@ZkduZOL~|*V3)>nR^C|_Dzzsvjemy8XrWLE1dc!8jsgm7Uzi2ge=jVaWRDvm zbKPfL?u#)Ot7)&$YFgTIV z(Zz2JGMuhXNl9o(j>b-k<1~$eEKD3H7nznDWE9LociuZVYlCFMO`H7|Mo0dv2WFV| zWZ6h86nAZ5KmisPOpN~Z2WFU-k*8hj$w{ta%ek(_mQ}CAJ_#7(9EnpMaQTV{h(OX^ zzz}E#SPDMLkT|-)L6MAdNne%pM(-4CDi~DL**Z1sIE?KIbIvlx(LwjX3|tW`a_a4B zQ51AJakv$`lC<~*-lNPad0~C9lQmaXEwwHt`(%}ebI2+DU=%Kb=*yB-3dDGw-3B$7 z%tK*T_yiNSCtdC~dhu{Xd{h};j6ZrWK|jpcE`ouVb1YJ^%r8@Sx3lZcgfVrU1Bn*O z-#fIrIY;

Au++6^olbWCvZ#J8rm$2_H=6W>2iEZrRXR=Ymo!Sq#_1SFwV9szt+H zqVD`;1rMECQ2IlStAj=?3UQFEm-avNsVgqPR*?H-4KCl(PHJ2n*g4vw<+<2p!6I1! z9jd&UjGX^BSXeCQ!oURrm<3*NYXRf|g{X4jET0nO8QyR;=0YA@(4j&%j}-waTInut zAHqc*Sb@d`VVB^bJ3vh7xPL7?Nd4)YNJ&*uh2RTV^Tj%5rOq{b>B{ToP#5s#wiR({HoU?WtvbMi5e$Jk!eqsEe z#TCu@C&EwOk5TF5U5em1Lv>6Htf*M}jiFo26^)XZF~}8-lCxk}G>Q^NyP{Eo8&c6I zd8p8bD;m!TC>l%Acsj->q-Y%2CAYvx(Xcmw{YlZlH~Z^SG^|%J#Y)jA+2v6x8aB?N zqmAcGN#b@=G>Tu*qoQFG0TK>P!=?hvPnt$i{#w^GN)`(aO{0`7Ey7pM+OY0YU_1^u zG!5$*x-Lz_x(>UvG>u0rmEz#Cbn(qXO{1hD)r6Xc!8qXj+%L4|x}s5%t4LHd@)idU zMI&!i9dJD(ZXV~q1m;ljJHbNFh*qv=SXZeyNYSv-_dsBBqUOWo zDkg10pPa1+sA(8w3^DsrUT0ZD)3Aljl0fVPG8m`1G>rovdUXsn4eXly3QeQP$#PT; z>*w+Vy=WY-&@^mCk6Lk0Xeb)*Q$-$7>XM-BJfQdqeRh0d8oUcb(gWdU5~UpLMwB*X z9$8mmUwvQ(Qb0T=r8fqnSPL|$eAx1El%}JIuea7+g|AK*hLU3+O!MfH*eUOW(})MM zFkJ%{;=D+%i9ayG%*!k?b^O8vGcTK04*$Y9Ge1xL!ZAK?r$ zFfpncGUvg-Vdt#9`n`t0EqY)&GAHW*;sJ)> zpoUMj7P^nh!ZxKg8CH0`#hz#kJvQ0QQbE*KqEgKsH|)d`7#eo)29{7_Dg%QHxnt7< zNrh&RE*YI7B`qYus8tsdp3Wnl9K(P-R#CYO1EuhTntcz$$e-Fxn9-kKvG(BA>g z^?^}q2UYwwyQTPG77D~bd>>=3ih8{mS_+~7JEgAxbK_#z$eg?Crxia@Wo&QQE`V9T zYH0_??5T2kB1LUzdR z`R_l=Fx$H9vgZDpn`q<-r|8dIo|UH|hs!quCQywFByYv9oR? z9Yc5U`#(!Yo!f8(vYGo%e?DO8-dB@mg_Md5Y5ruLdIXJS7hib1CY#p_?sUE%Oow+D zZ&(sy{2NpsC(SD81wt+cZU~{1kP&%76dAJ1fo<5&1i!Vg=nXdqw3p?>mes{t!%6JN z-!m%~tyU#oKeKaShaJTTKr}4z{OHZ$(3N_n^B{_L@ zOj@4OL34e55~zha*g*R3!QLLCH3{DXu;3(_AQ7`_mB1K@q@)&{&)Q@;22ZpZA4{EBwgTqbl(BD&*XO{XU|Z7j zK5vP07ZaK@*?sTWqh^Meyxfg-Zo6OE-Z8d~B*zzXoA1iv%cwBIs!X(>~pTZJE zC+yR%a5Td#*&ZK>+7cKKz5uRL%aPoYToSMkSSIE{e}MPGM2h`}F}qCCXcpGa{!wl* z6d9h&&AX6*ImtQ$2eoxBZz+c`gKykyy^r_Lxg-y?%5%w0(RN92mPCWAm#zG!`Fw`bXYg;!W9*GJ5 zjfpS&L%$Gp(+z(R$hl--XE9{RUmHop6wv@Pr(t%JV(_q#4IjGJxh=ptxTMJ1GNz?D zeFWg`7riQ6=12xSOTfm#&a5a%yruKzhjLHLm+e7dcgrQ0DKoeqGYV11Cw_k}h&8 z?!9IW@Kk6xpm1?O$rgd2Xu-!vh!*_7En1)p%rU{s$JRr737C7rhCr`?L<@|uytPmW z3Pp>2!U7NkoOIPvvIVBxjpfGC18$t50C{l+u!|OeC~0{1iBwr$E<}r*T#2D*!AWi* zTI8fs0wG#p%$I19&38}tAg=-19JF$Y7TFx!b=)nq?()l+uQ`+jexpqpaj`&2C8;D@ ze3B+2C~Y9+Xion~z_VPU1u*1QyfuOM<`6A%M2@&1L;1NX4GKxw)9w4r*OCTvjF>MDyn)e}@I$v7 z_G=}9X)qAs1vt};pa9Dq)(TB5z;K1dZ-%aNHcm3qzRC?eNmxVVOaUw>C6b>?lu{N@L6OGYB6>^(J*)G zOO^;mAY<~R7){PC9pa6=Yv^uk&x+hlO39B(+dSh2tA%3+4z6gHb7OR_D0}Gv_O_zs z7|kA-1=WnfHm#_n)+|D1mR)3t;rbob57V&UIryAmr(+9+01Z|Jw5f0Uf(T$Kx5PkN z?`+99sll*Xv!w{d=IzTlRJZ_=@(ZAc2XmI* zSQ?qSZufiC-f(w^uFo?)W711~>51H&LLa3CFZndDj|cRIbwEXnQy4@~nA_F25S1Zj-KlL$uw&8)PZni`*l7AH_|U>Ln}7>Nj(p&zOOW?c zQoywEhki@b7pAGUv<204(G0R6XZhxN3R$$ukr1D+SjbGR*YAZMuga7xX>U1ey!ubt zGp5rH`m`1QVtRlLY`elYb?Yka8qrE%i(8>y4f$yf*j*wB%;u@ItGFI>G*~R#R#Y6z zo!CdWSStimyNc;S8X5)zMUry(n1esm_5H#;Fmyzv_!6&B9=2wIAuuX#8J}aTS9HQ`Jt0i!Fu5>C{2!R$6CZSe8}VsNQsb=tyD?eV94ozPfFE$b*UErp|P(ms@1 zSy}n5hy4xi)ax${FC}C}c!QHKej+QfW@$#VC_(i#(&kygBRYGc-#EmL5bi_VcEt3U zvcidy=Z=&o%If5$G0UA7PCwRx!l)H0$YO%j6s=aoxJ=Q^4*v>8(GtD;>5^ILU@78; zdZG$4gsO-{??*bdJpTJ_-&fs|)9+Q`+fo%RWGuHW(38*U`*p}}uO*^}s4W`iQWkSnJi3%c3$$w55D3al7;@~oChiz5wDM9Gk#4`dE@jbZMSi=^IrC5`mezVBPKXrQ4jJyZpr zNmYCwmp12k^PT>?FmBXCt*Dg$#4zd)7-oqxZqHI&5~eIi(u+mrbO3RKO{HoWUdO%2 zK`z?1vS7zBf+rM39W9h6ob^QVJez@8F0Fw)LCmF+twNr9jiLZkxtAzP+b4T~c!4|A z^?Qyh8>pee6L-Ac*)r|bgQS(ys4iD!ujyVV7 z`x45V`u_|UCoUKa^OPRU>NKwZkN@D5U5d-Z*?BM(o?J5sCj_;c^gmw~t=1ZTUlfxp z%3&dtvLUfIVs*_I3?knzOINfJ^xW8d!kJVuZz>?a6QZXYl2KR+nYv5B&l7edAK_Bo z!t{}a7uph83K^^BfZ`lR+DJ!d4sdXkr_Z}7*0ULF3b06zKZs&m$WjyaqNvRUfe{X*hTzl%^S#+4BnoRo~r(ybMXs)-f|^#r(VUMv<}5%IW1XEQh02V8ToEJxKxu&B4&#hBqL}x+0$(zL7w}>5C-!P+kHN z~T3ZKcPYb^!!BSlhJQ<+Lbcc9ik?a~SQv=@OVOHoYU{-L_6T}RC1Ec|xAzT@lUsF8M z88cp33T-g&5@X(N9y%geF~@_w8j1Zbjqe$DG9IpTYmgA?BR=y?F5G5^6Fr!M(5%xU;i^wUE{bQlVM%9TIv-$JSAN3!RBa50jRo*(`9^O>1Ge3iH*$j z2pCJ3Zw$zO>yx0s#!u#~*sHKb;VuW|Dhtb{SXQ%(|I1Q7d3gOlx-wPCav8 zVFxW86e+gk;o?8y{}NgnOb^D|7u+q*cx`r9X*nB16t;lgCDs z<6Vu{=6o})7F!2PxH?a(v{b;&FjHa$nARFRQW9KW#WDp=JyG<8V{qvFaJaa$^aln{ z0n^Dy{JqRTU1ULf;3+n+D9!-0?`=+J9LH7(cm1xln~P(~;QD}h`6}aE2W|@84@^bq z{?CnB+)7iUZ77(^uMVDnwfj4;9UI)jfGNcna>U8da(+U#vz>*zoM^}Rf84Su1f7=6%oYsb9zccb2MuBWFqo-jt zDtsXGhDn{$ci+eRbLVTgW-2h(Oj&*y%0k-akFGo3H#L(Fu0Jup%`Z$=nkzW&eV+r~ z{o3b9dYD`6bHKhA;2lg`m)x|^fpL8U-g~Ra7TXbdF#Km45)MY2nhB=%-xzIkW;0yZ zdsA{D3MzlXt~t9Ln6+b>ssF9-6}$JJ7W(GJ}+r{B*koDfdS zQmjSSEpbIW1?&#^z~oJnXY1VVc`AUvu~)gv6bk1nwnEhnv?5VXq4JGlXUM>`p1bfT zlV<4A3K;YQjs#XIo24n&29+^M^^9rE0owy*>V~Pe(Cy~rDT5H@!88PX0J+cbNtlL9 z;r>=J!+^82mp2UDW~J(4xWa^(ev+Gj1p9n6NutGKlt%R>m*^yfXu^1+f4RAUEs#lt za3(x7)usEuA=PG;M6&DM5?2@%vqHTP-?9KuF*11;y4I#E`Y8v9_Ky^Z%9D@5 zvKsYTu~jfnIQOcORTga=PRIAXL3QN5Z))AgefS0HGKZBRFqf4fZ{AOZTa5WK)(l0I z;+oa0rP%lz;{u%7b@du7+3b=%#k5Rr;;gaUYPNLsg|h@%Wx4F1DJ})v7+!s0Cbg+m zG%cGub}4;FOP+*d?hp^ysY!mp5Dj!P_kh27VLGq7MGl?{;vX^#(9d8`42hi$DO-zK zmTAtQl5X{Yn>Z({$6FQMS_1P!%+fnBA{KDs*)aIkEP*PipP2`|>LO>)>mb988R;)U zLvyj))nXNHc$s$cYCQA8w3C;g9y0KxZpaO_3^@Vt>OHVWe11j8afiPD(L3b zDX*bIIr_Au*J8HKq`i3}=+^#hVj;YHXY(+`VsIA1sxB5Is!3c2VsLM@h%__V&uU?! zz`K{$Cugbi*6}Q638{H$*0c22HO0t^Ojb4%Jeevod_3S*o)}E&64S`dKk>c|eFqPo zR&D{z%;6puK)V(_WVtMUky@6`smsTOlAcU}c6+%Tn;)+IUKT%GB~DsqwaA6`I1!57 zASbJFLb1#6-L+_4z~?3+`wlp4fCn@5jYhdoHo!uQ)iD9u?RxAgnE*=`M{SGm2SJAY z&#vpE&$9p7b$&iU!S29r{|k)lfA)stg2Z4CT~}=CQjYW>ChFO(c^al@-m{r+w;%xa zI}Zk{x#XneV|8<4Tn0BA$3{<`ji9@>$ukwiU%5@sn&#B&2+Vemv40PQAvzibwT zQ8$+X&@fZ-QN|~_68F$DU^HG^z`Fc?VMz0r1+e&RgayzDFlozgB!s9G8)X7Ku-gC+ zhWbAeMBoiH0@}WsN@1f65>iHG1S}Mj!U||`y3K&rYiP4F10s{du>%@GGOLc;0c|3f zOJyimL6e1!oZhB7=YXAkjKKWd7`FqKBrBBcfHwUu=Z`8DQ(u=I5YxY3VFyHp1i4DP zvK7#a0FV>is}2d|;**HP~W9Do<&L?TO5QjnhJjNa?b9U|x-~Z&W_O zy1gimWes==pi>s{VRx@lDP<%dMk!1`J5b2PKxAef*qImH6!Ca4Ol6K2C>g4ShvE~R z$x^8`SSOHdcrXG3ot&!DGdYSXm~j#{BYU7FhDG~|FgF8D&9HgH%+I2<#x~c;_dS_a zp{5eWj3!{Fz(7$OTF*8sCQgQLA#KHAl^au*Ed2zQdnyOhgHb)Mh4gHIS=NS`Y7X2K ziF7b5IBT#eW_@vu?3*Bv?K+~7B~s=pt6)`C%C2fM6&9ff>`EtJ6AR4t&D`BaVJN$~ zS;eF(-I`!g)Oc$#xSI9`%(c?v@2(n^ww_g;C?F|T=deyrkW|w*lk7jWFfh!@^{~ZY zWvs>A14x_z*fRjzH$V|qHWW4(qZwoiUMx^(G=sFtYehf##AenPj%0E=Gl^ykT$~9M zG6Sg1SkBLhw^{J;&}Pnj{r277HKtL;4}5WNu&bcj!7!f`NRZ^xHkYzxk`qZjsbcC% zYA{qmNbE$(+&XRU7_cf=Djpk4*Gbb&dmr^ur-vZg(jja5WZ)l?m^5yiq=iB;y_sbS zMJ|WRt!t}LSf>FMxZdE-v+2SxQ-Q%qEIt@`ZM1=8)qSZBkaYsoz??zgC)j$ut5fMz z5#+e1@)#FHfZ05tCPXh{FSI2K#@sS3PqavgCXE-QqC%8a!M?^Fu-bH9Vyl9KS=J0~ zew3{1Th|+kCsZE{9JVtDi!)$>{5*qH2ugus)+pg%s)K>4HhmQ~`ih&T{FJRt?K`@H zBcQ8pF6#{0XuIm`bsk8yXCEzgl4YtouszUf)NMqIs>Ju5e77p_)IP~T!m6^9)+r0& zw!|e^qrpoX2VT0)5ts>)mv87K-uOl*`FHh-wVP}Mft(wk1cNo=ZAybq7y~ajPohQd zJRKJcF4WF)g7yuT{HS)Fd$Jcc44#43N1H$gS??Ro0|6d1ipo49(;?wWScJ#4IF9)t zW{WQHjk>j8#CTd}?S$?X#%$c+(4DuVDzh|W{kfVYJBUe8>T&(S*NyB!usj)eEr%}YeR^_@!;&ym{tQBfm5c5L}OYyM+E#6D!1SvtW$2RkA`|3gB zn%sLf5YQMY0_(j$D5Ucp(SmvE>qNKbNP}kOu?5dSl7a6E+F&wH(wXJ;%uB;-Zu}O8` zE?P`hRmLW@!OleP&-DVeE)`RyXj=!%abT0S8+L~KFUm4tMcVjZf6 zFgJIAY7li@NUU^*V+ZoOoecv8Mi(!CRFpA2TXr$m)3vErQ?*2IF)7L|+zi6pk_d{Q zygRebifwayVplCH86Or)=OSx{*b3w9ol1}aOp<)a6;#pKiQ9nHD-z}?2jvp_1@powo^T9{eApXU zKa{ z%iC5{J+!P+#~qHKe>Vn^&Q`Z7OI+`~5Yn=54sMnfnwD>;mQ=7YTJ$gNzwtt~#mv3M zYFrY${q-rU^ed9UwUku(wX05C-CNZhSmV@StQ|uNQJ2xRGV+6syRcBp^gD?DIZ^t$ z;imFPfw6srDM+f$@e45q&8`;)qcae4(!i}547zYFDES+LWfg!`!NaD^<0!=33A>U`=XJ|V z@+&uq!C+y7EbYKv(SX^aG>f@GGn4 zr6^fggAIT2+~rN%_{`COZOV#^JHOrlDib(!Q^vS5Rf*$w%d7B}xZ}VhXIp=lK7FNd(Uu za6vH;hguvH#Nn^_g*d%^e~WsnqP8#^v2^B~(vWa0|FGPkMmbq7GK(9cR^zOpQK^LI zETMC;1+TqzW|Ycp=v402_mwV7gNGW0jH&W9ys6)Yh^}`hWL=&HcfdP`lny2n4j59o z9&m{AYSnQ-zZ8EHAuxskoy;5XQQsUC}Pa>}lW0;TvS#Y8J63KDNHeHaMx%wMXrm^fKkWfgO5 z2rSoDCGuW$#J9;vpFs?jKl~R_KD8qVh z+4~xjXV}!Uf?0Of9m~a%cecJoL}e6cb2kF~W=U2kP|-jVpe0sVuTQE}b+odBuaW5n zCKz{bqWKHM0wltK1jx(XC?rL8cZu$h6B{uu0fF~z7U;m1g<-df7;V>spKj*7fHp3s zgn1ZQXThfV(3l|4aIw|FB)X`&K5n?m8xfdE;mKuiJ5QISz9yxJ74G_!^)O4gW#I)g z+cz!$Jn%QG4bo75>g)*wLKIFb zvgs$utw~IJ_ZzNW>N7Ad_zsz%M(FcczqOPl2Va$qA6ly2_`%91nQ53V-e4_5&+-B= z2+OF8K7gz#<+8uc=gx1F>5~GQhQ-=NYMZ*nT3FWEEGvAH>0!%SR%A#}VZv2HH|jdH z+GU)OOm=BgT}2&Eiy}gIgL9Ifszu$q6;|IS@6mKsab57ps)~9rs_n}3!qjF8VN!aR z#AtFI<+~wUW8#VVyom+?X5Q&T37FCEA#-<@wGy0duy~`*G`9LYr3m4G=Lj3gZL7tU zZ7K<-ZixBb`ugOK<&(@bX$uHJ$@F@TV=?Vm_w#!(^x5FOZn$}`0wWb|v6M0FoSok! zyi{-6sA9;Hvn9$5*-Gh_V7Uds82MKJ)nd*ged*gx0=?=G&VJ~}t!`5sN0Ut~^9O)N zB+)ZS9_zwSNp4@V_f<`?41}Zma$=`1{hczxFDJ{cE>~%!7=$)OcfnE9v1MhNC16Zk z=Vpi&l#TF)&BcN0zp6|{*y-v8rePQPnu>UZvucSNI2N=Iu|~Uvss#F0F|$5h5jPC| zq3&XAvaNQ~R=`!3(ZCFFho2jhb=)z{Oy{}OB^0RW0?#(d?>g$d*d(~l9ug&s+@m%P z&NFlrY(2-Gi0dQ&D@ z^v#5O=R?VjEAnV)eYC4bfS}q;a~FSJHOzcVUQFo)7k4O7bupsoXU3@4~ovI?{|C`Hl!1%1A6ZY`TyNoC{dEiPSVS|giNcshb5hXCO zu|JkkYilN<72Da?wq>3ql2q)*;gA%8qSUI0aU_*d-3DP}sbU)vLPpKnBQB8(2FlA#la9#0znzYKswVXquA@f@YlK6il9*9UCWiyHZ53zR4&cko>x2lu@LzQAn``ZPGd_ zNvums8Y0RrRgOZ+P%#r1Qf&2#vnOt_st79yDK<ry31z5IuuCWgFHLO2150ehB^2Cbmnes&uzIqu5Ksbi z`NR<+o&%y^s}2-1mNhNhp3(#c>=p-Va$tp%$P6Qe_kJjRH3NU1W> z2K3#|o1+cK1v?CeQw# z3Qdg`J+vBA(T1%5$Unmeq#rK$J;&q?RgZl%*p)>|BFiNv5z%syU0+;VZmQ^$nKrKm zo5lOwt#9``8A;%7eY+Ey#k@huTT-1uHV@o*@+jITj|H$*u(_!^60phF2~%R2h0W&9cMIwlyhDV^ z=W;CF1sonmF$blHr3l=~^ri>S&R-pKX6AANePCu)dewvB8HU^W(mU;(G{Rdt!+zAF_=`i=mJ$2?56X2r>e34B4~n2-k-4lg7@`Ay+WsDENR( z!;|@K2NOF(*2xDPTM2a?apvWX4d^OzUh>Yk(`{yXQN!srGh^T6b(?vF^9~8zvJ7_N zb(^_{6_G8nd}#E#O%HMnubbU{znpGUH-FvfW^hxSqb|=TKgC+y#?S6?3)nqwfe5$O zOtP5$fe{Zp4}BuS<2JJdw{W=yCLZz${*8z)=Og}oV8ZKmFm$^aoOQM#5pb>wa**52 z5E3+){5e+z(QwyJ*V4l6W|$$b8FHgqR$IZ$M=;1;!|!I8QSTP>EiC7QxW0Ayy-9QM zU{WOTmNvp*QcDyY!G5;DZAvU+Fey@dz6F!cRwMeBH`!AVDRT;r;HbJ9U1iSl7AoKD z(WJO+?J8AV3iq26NC;dQv#4Ow06mt}5eg;6<5wstKH#QG-PT^R+gDX9d=C^wrTMqh z329vK7EK;-g_0uOqKom|n~j}UC@IRNWOkA@83ji$>5XC5$ix^z%7!Se>sM5G!8<~! zJ(zT=>ZAvgVyayz9!&V?@iA4m(6fwqO0{2`i&jGk0q*!NWIi~-q-XINO*)m5^hA?R zR|6GIih|MFUdYz@PNa~NZ4~`2nslnb$B8Dj=cafxQk*uqu4S9Ucg5tJ2v=b+3Ma*d z`77QIsf6FcNs&#s+%053P&g^lXZkUpovwy_PN0h70VfP6{TP|{X=iHGBQ*vlSlP%S z480@5re#S^x2s?_vF-(l+5uh1rpx�Mkrk?M^25|H>Nm?@-J*0C<3HX@hp zJexxK0cMdC&W&33j-{S^@u==2Y5Xd^AudW_ zmcdzmG7$%=TZT;wB~+c>`UQtgD==~Be=MU;{oSSc0Qm?QsXruRIZE0i5An8JUU5u2 z1q8+yeC7TgED(sfmC0pgH+&)&_IjA&?WtI$N1QB|a~c2WcMDyDlk0q`ToKFwc%b@v zGxBs*orRRiADGNzWo3~!gwFnq-@80pG^(uHRH^a?<;B;3BJ0U}7Px z+w*VC%u3R9Fk~Bxg<>fKR>E0k(51=RvLe$GhRHe}Gfd`|3dFlus|=TXIQ!$0YgcKS zdzWi%z4pFa$l1a8-<4$mSw8UW-gQR47(r|e$+*^mlcFU9b0+4U@JO?3w1|}zH3sI< z^YPp$QVw{|EQ?OKEUl|Y@GND3)sLXc2I+)M+U%*cjma6@V5=#hr!%?uY6_0AgUUYH zHCzhL}8XstiIv~@sPR6Az4Wmg- zX8a9GzxqbD7D&H%wj5J&-WUH6l zTgY!XCPG-2l5hWkImGf#7YNK)ZR*Y|=JelbAPdhdseeT$cv0wksc$(yhAb9XY=|FfKO#8q$E&VDYe( z{J%WHAmslw=eek2+ic3*AqC*Tt^ou_DgfT#6X@SKw=d8sS>>eySSMW?!oJ(-x`%>c zH$C7DmOBY;VRl^abOpd>wt9@k3sXPkxSjigLjkxkb^-vtti#*yq=p8tRwku|24I-3 z06}nOk0Fo-V7Kk1Sy2J7al5h!{<2m$xP}(9-urKhNBZx+_|yQbQ1IJzGNYF4^wl|S zbPrMi_@GfJ0829LQ2?wJWk6Q|>^)1a_M+t|ivBj)4&RmKsflh~`p`DrHICpey6taj zqRqvvB4Dm0tK!I&x%4OiHr-P`tcK~&IxwgJe2k3S)G82CGDXF^v>vwy|}@ zA|edb=5};y&5c#9P?`0G*i}Ps(Pi(h!&r6L=|P$HK=(@}6@5DJlFubDw2R^mvPand zwofPu39Uo98|sikb~n$(7((3H-yRB1jE#M4-QuS$)1INFi)kMAm@>C7mFU{T7mDFZ zJM=>`4C@6g!dp^<)j}TfY;L^MwJ7?90uK2qFdaF)@J-Mxld+$1MAYuba%m0cI2V_A zj4>TrKIu9PgHQpb>)1>8^_8w;uO@emr|U4xRwS*79ov!-NH8&xY%dRL^mHA2OZ`>4 zj=f8`wG6-a0npqpBl*wUgJ>*`S4t^tsYsZTQjvVc+~q0NxcO_zmQre8vYasGTS^K( zgvriTA+ROfwT>WIQyuOUdw-DgBXIDsl!Iu6wPSs zu+I%r5c6h*nUktxuN|>?U@|T(C{@Syc&$j)fwgvLMzt1Mni3s9dnE-UxQMyumM%lr?72D)?72D)hUeOzii1(E4*Ld9-pJKqz2Jo&=ISsCYzmXJmR1xQF~X6o!zc_# zqmp$PeL>$)DvrG+x}J^CtXWr!t#IJM+{HUc0Z zX_>17Fmrc6Is?2FBDtG?qRC8vTphqr13`c_s3354>)nb4{FGaB_SI1t8TvVezcpJ4db#u3VGgpv})%dgbcC%0;LNw!2~ln5zQ|Lt#X@ zI!ek(cNy(YzyoH*4lpDBft9P{!W8Dt%rbg2R|h^pxm>wAKtC?Kk3#ZF(%RXn8o~IR z4=8w4sWxmLT+J-t7w+lzTpcJcKCc!_k#zos)x#FSWF5vImcqu;;9i|FT4Ob*F8N2Y zjy0x`spyGL}|(wl+#Hu_Rku z7AeUs9lR`3tlBj?%gZ7qHN|WAWs!oK;9^Assk_havSeMUD{feqMM~-lv{O1%gBdvu z1KkDdvdF>kvIt%|Wn#r)W%{bin(Wh%fj;w#?4RW`jIdF&!vL3LM~Kh@kx;-V4*5A1^C!OX(hvM@7O zJn)91kPE18cp@t@nKf7Jn|{5?_J~Skcc#=sJz9ywC_SVMNjL_rM?MBWY0o%a#6};Q z&Lqt6Qmi+{_L3yNQ>rgkz_`f*fi2}>|I`T%>{`QxsobTD(Tr3(@P1E9B;jl+l%A>! z=42er=5wvSf2H87OrrRIpMp<~t`vO2{QQxW?{~_*&-X+UJ|vr1%-6wc%yltp%P?D6 zH)tP2mWX-sO;qEMburHzGHoa|2!+e4QqlHHD{QI9m^O{Y&A*w}1Nj#gO?Y*C@(pG@ zs>b~VSaSy7DHxD<=IOby zAcJR7evx^@({HE;hOS4vp>h&&Nt*flF*04FPRgyZS(q1{986M!+<2RBva~2w$tWiK zxtU4a^4%~i1wDuMZtI;*57UM$`oii~<}q2n?M1e)D-$x~Q%VD(oQakfV{(E`q_@5y z2iRo#6&sCm2+k>tGW<`IgHCir8vr&~k(fUDJV~C4o@W6&(WRJtzi5!VqES3&$3a2p=LjSV|KUIl&HZrme z#!F*?`wh>?$>SKhZK^^lZPt)VZNbuyWH0(eV`7u4-x-6C`N-Tcwp(pJk`|PLqb(f2 zs+0eAc9Mr*z(PPAGJNt+(|AV_H3@6jIp~ZbIbAaM*aJ7Su6a zYzM)27;e=Bd5)=~ye<99IUklS(Rxyudg4eb?>L$QGe8`8LnX!f7jyuT z>m$c3mkK!XAK9EJ=y3$sS5o)a3mxO z3>gt%4HL|yDOvB@o)1A@bzy#p@!V9l(=gSdKU*rZiA(gL5MV=}I`y$-<>#+bD{U%z zfS3s;L5l{l`eanC@^Xc}P&>A=vNi~8bMCMoWmEbfQaDX)994(&!$JOuly_i$h{4X^ zyghI4Mb|go?~Pg*xR$!k_=u*Am^Kv97svubE%l8`hBM4UBEbMzF$js0GGEWzR5sT< z4j7ANW9Z@@V59G2(hk+VraGXE{<|=9sj!qKm%&z_I)?`HIr7#{)9nf5p5r)~M++O& z_E{TB!{_^NFk{KJLHi{0@D`oUIqXn-L+4oooUc6iK@S4`FxZQ(7GL z;BPR?LJYH4v)CYJjn}i9Y2W2_j_%Gh8cF$@Iu9AhM(m5Oui0kAdYX?TUz>ICLdLb7 z2eYr97E8yC_{K~+3yYG=9t=zZKTIE!=3f}C<xsOA~67b~;3M;RUK+LVJ=C9iEe^v-CZquKWT7EMVH5f@fc+{FkSpMbiQV#eW} zl(g+&tVd&Ol=M0xA(A*UO<~r9q&ddH?Hn4S-%vuZ6rx|>68Y4kPc1rbTG$*>Lr9*I zsWT`Ex#V8gw0BX}+cGF+N|H`6k)8hEg;|M}xE@T_3C%l=jjr?9I+Shh&9%$>`DmV( zq3vm1UQ053_v1|Y7~>NXA8`gZ!Z^gICqrzm9L}wbGF8$*f>X-iE)r6XtL3LjjU+{s zo0wGR!0vK(%ti2vd-*q}GTqP{hDi(!9-=GE##$o0kO|FnpspHStR2ZSvEVyNAMw}( zOtADU(7;Bby{hYZme6PKfWMjar?0yOlWkNb`fO4G@Cjx$NJ+iSjL=ESA*$#P<-5ip zBJ&VFx|lG4asg-ahIis!14o>xv{Xfu=RYx`&YxfOsvIeGDeI~WeO)%dBlLBZo^zqk zaubymLZ7|DPn`c>UvG|O$qKXy>i;TY1$mqqmeHq|kV3T(PpSP2?cZR)jmWB#LL_$a z2@IPD34N_}l^eCt*GjQ2>uO2mxpBUslSR3H&M8c1wFelrT%tLs*8-l0Ar@*r_@fSz**i+QTdgHCx&P zKD59W{GAaG|C^}2;GmA zBwOyYDNu8jjKrXp=ggv?hr?zqVieY19 z?)SLvA~uE`D(L!4|9~u7Q$HZ5j92z^iz9kwSbtn|%*^3&1)x4HmZno@Np{az-fpQ? z6Zw%IRs#xyv4f;TchgHW}fjt7*~SjdzSc%Qxv)-Fh9;RVEII%-(fv*sjXkLij3`#%?;x}cmJIj9Az0s-0wg3b{0 zvqP0b^RLdTa!uH$#iB3yT|*s#D|43X;4M{?zmDdTh!Zoga@|K!bxf*-+iEi2pP*b_ zMM{b}4<6J-C!_RZ4V_O}t$8^+0!Ub1}IpJ!`B@9WySX+pWW@i++S zs-_cVHzB$4dMRj{oZ1C=rcLkDc_FeKLsr)s$2dhvwt&oG&*Zdk#Scgp&Yl%pGVB=% z@AABi7{tX-uD2AT7&H1~!^%*#Xe?2;Q6ueTetbZfxc->C+t&Nzkck`g686E6)w&v; zUa}e>y0K(6R0xQdEvko+Zcz;d2ST6Fe2WM^RxF9ozOI9Zq8{y@VT--RwJ85{#5I)W z=|@`Y={k1f8gFUsKqReoH|nvph9{I8g-}uGsasm(3tsvUzbZzNE_v>3zCIT z+6QEWtf)S88*okeeBtPOKk3xn9}$3U)`+~~usNVJbvsmIXJsF%fjsV3?itn2OW8Fd zpa0l3kkQ{S(+M*AMag8>U_L*e8Fme(^c&%s2>MK$9c9YE3t0D?R5*ldBC3t@_PL4=&Powmj%#vPiH$(ODD-P!5wj}QOV8$9e9!*ur8HJFrb zk7jjFaQWJHjXe&#MgXp*EXBU=pOAyYpXh27uF843aM+ORP7YN17bHh+aUJFqipw8$ z+O=Z@smsv`Y`KbWXbyN#h2YVOS&LZBXzgZBf0aFZ`;$fsUgJCTWC^H8u655=#+nnH zi`6+fjE772R3$Y1Rl>7mLM3@375TZJIij1#eycIIlUy@Y`rAV0a5(W1GKYoZkTb`0 zoo&Z4#2BKc8=?o~?Btk#>c0RAjl2OvVLQ_9>Euqh{)*n zR)-~fjOGtlmK2w!9mNZI-4R_P)eMW->ow!m{ig3g9O=W`LBh}Nu+LI`bd|?#-As3A zyFHJ%(T1F*QNxsfK@d;*36K?KxL;bh=trA2LM1WD(c=86p8jYdY5B`qHTLgsZ`oRZ z%t&Ul5)x6mL2fcP7Ul_3fJf4Cddy@=a;o)2#m4^Ckqkplaj^-TddL*^I9cQ0kh3nI zv>?*c9SCs<1YA%b*9mY~F0PsX0zCBh60kP8V#?R!lK4JF^J%wd_( zOOo-~&1E;@kNu@HZA4_oN{+kRkg0;&+)&#aiJ!}^P8I+As~v8(VM03L4qvL@e5$3A z5VGgfKTM+d*kzwLb3&boejIi)MUaJDdf4J*Ddc0kHQWPf-h%9C0I@4PWBBA}ujq0N zjm#*(!*u-D_>8&5WzJVg%KiJ}q4pRXGDAMsIbZC2M3>(9y4GIdP(Sv0LrXKtSL$cP9F*`64!^hj4qJgu#wGC=@+uO2I!uV*R9~Pc7#1dPJPTO zC>R><%;iJF-Q%s{9*8tt-rzZD7n*}RYJ-Afu>5_ z&CBi0Ldl)340@E@>HZm^KKIO>ui>-M!5qc1+~Yv(IkH(c z%Y@^W&ylTJEMk1f+IX#x362`U^~Il6H8!_>KYTbi2xK4Q$KC}NTd#4ySG=6?&7fIlWY zTiC)As=}xb|65ghXz;%US9Cu7Z;vy9w_5+O-*PKIJQFK=jmM0=`ODezWk+<1`2k&? z%O%gu^>LWr4;&@)!*{d~mpst$vW|WWx98z~ylpwWkB|NE$m7+@<&j6RfONPU_k4Wd zNZ+O!{$6aB6ZgYnmaqi$Kq`4a#r^OV7K4V9_H&(V3DLE0`Y2&u!Hh79En)0L$hPJH4^Iv?9eS@&XFnx&Q_ zCp{7fA{{wtU#3pva%qs_HaUB|qR#(;DAN~rc6NR0$80jczxR7aNYq0qWzXr`stb}bu=vcO6ycCg8WVyQ zIVkJa-~ZWw;2$qQYV>c&rtv@VLL6nC<@_&(Q;DruiD~k$@wEFT?=l6CW45`Y%%;vq zA5~$4Gj=xh%=e7x2E>m_A*5%gh&Vwr<(>AkhSp+QXrK3ZxfH?$;i=XgoM4rPo>5Hi zlQ(Sc_y*3fp^;{cq3_6Jk9``##Ure7=i4W%{KDLiFoic-760OeZ>~UaBlXX8LFf$B zHm-ER@iSe}ldg0@Lr%Kj`{6WPoaDgYkaN}l`@Y2U{`=qmORch46XGFG{X0jMj%Sr* z8sQ-hNJD9=Z?#ro36BF%ooNBsr-Q{Pn#>Yt+Cb8wSdhQ!(mwYwDP zs?*hV*j!?YuhZLxt_@Xee=YkN@yuGIj(AZ%<3h*Y@c;1{>c6(f>U3+*q#!CW%zgo& z;>FEbvMThWZjW--@ZO;BD=W5yUyAoeEY}ykuXzvYvu8avjla)WYyJIe^?ABuQXv-p zC#No-QbO>>ienuO;d^w?V84*80A7fU#eE9Aho!i;ip0xRn)fWm(_V=K(ILTDJCf9y zLncBj_t=}v<*O<-6#ZZ@UUr~Tu-c6+@foZpW33i=Mb2KO-f%t7_*zf_zJD&3!;OmC zj-aFy>#D!vR{`TKxx9-Vh~FQTD>#TBkd5bVEAtzmq!d7=ickFmvM+LR{@;Lu264@A zNFEWU5zqb&IahstQ}|{TpS%)H^{`uvL?#WKVTlVa2=2@=ze;!IbPa0SmX#jvE-tlZDG$A48Vo;9grMqmKagSim0Tr4ql<4iJwbuAn> zCpFi8{=iXHwtm=zZOLW)pM1$r+mLUe_RLz&<^3R@6}A_~LwNxRd-$(KNvlH$6vb_v z(2jrNNHP)IGbEPa4%HzB#gCXduxf~jWQ7CptY=l<`246-)4C%f_9UPrQ;8pn*XHtC?-vrLiuC-SdR^E(?Y=tBmU zXYFaZht0MAH^9Dovl`$f9do6dd4?~)4DYXY31i}AmTLm92pt}0Be`t6m6FUVs6!o) zcj-NRBkO2o=C1x#g>|t8`@z9^lEx4P;7#lvJAlD0sjOtU!P;YR6rbK1|MoO<=O!NOFYI^zMJrOIRt$~xu0@k3|imgzm7^6_YD2T z9q?5(2w4fT0y}cBx~8?IcvYlPa;=5ed2RIIEgl73bR7dJ7uZWup&}I(=*7x;B?^2E z_p3w2Lk1kwWcqD{ti|`AR`K`^L)19i72FTK=9v)j-SoRDsOHR2HFS)N7Jgbp?B1Gb zf}j$CjI_vlDf*vPZr%6bZla@MQangCLneLhEKY7Y!V4jC5wZp#qBu$~ z8_pTTErrD&R81s(9~SaEQ#x8wg1@=!Eoi`W^o%|>`e(sgPuzFOcAzeKQI>56crrXT zX4b4DoYo&xh2$YyM^u{W$u3PA)#wg{i@`C~=DOrqi)(BSx*>AP4avx$jO>`<=6u)> z`xuEKOl0oCi={f#?B2nD~U zzPem=&DB-U*0~GVkG+f-2{PUzQwKnic|e;fR?Ql%?``MJgQm~M;ZknBx@WjG5+6Xd zT1hnEQWgV;YJGtLE3@-pvGObU~p z!ObhlWghVo#X!NI7H$D9~4qCETd^b z|GOZ`bbN#`C|?yKuKLubWiOBIG2YdwjMpuW&TLY&1=d+D;>HYR8B^pX=9wL(8bNvM zu>v9+@o-uw$OHq&Vw|_&w;>D#=M6$@FMfn|a`R*v!;UmMm4>l-^bA(8x%hlOx%gmi zFmEulP|ezg)rpN+iiACj?`XJ>y|A}7t9JX*7vb~`>HOJEB1pEaFv2O{OrPk0%r#t}8hroo!IOXQsrw(ybtKY{GjVjVTBUejiQ+-FqpS*>IzX}SN)+bnD z+|3@XFrHy3j5ma#S;bXb%}_ZuLzQGVy$45OM0^pYKWU6y>h!fWMur0Ua6BzGr+saO zk>Og`>56c!bN*&pRysW+_TLKQ%r1+(6~>u^Lke@SaKkbVLq$HZR1p==v@j7WBWKMG z`4*&D178tGGrvM*#AA6usEpHsNE}jp$)z#Q6oh)?NUE0BV@5V1mBz^UJWKa82UcZE zfLYOAQs|{J{`e{%(qc>G=Cm6EmZ5Non$0wRL#o5_5z5lciWu<`(o|8s1_Yc8GopwS zvNfQn+|jh>bz^u{hRAgWnwUULXp%}Xei$|sM`AdXoimD-=)`bUYa=w1H@h>72pC(U zoblh&TI0;M{Ba8vWf$O?RqK#!3uY`+Ew-ON#*1nLRhFM@I^&(Y)bDW( zaublv9e-@1M5wRyg;r+&`}h*LN01x-U^k2t`ym&yRJda!F^9?_D#0fj z-U~|)FEqyC6H$Wni|$!xO3@bt|7@aVxw01YV&rf=V;DhJjVlO284KU>CET!O7d1<# z5e-;AY-ui(7(ztr>VX7oTC$fjXfwutm9zG4WMsx5d|3U>3#{J0puN6t-810n^ttIX1B zDE>I*J!y?g-c-bl&#c^)86KL7G3aTr_oQ(XpS2svzZ(chp+_dOr|6<;Vu!&?AYy#2 zsUhFLR?7ze&Lo%{sSPQ$CA2Ob645NtC zFam-IbKaBoH{v*D-G}BgVDwYMirt0L#pzCo=vQh52$_2PK<@p38gq1^#lR(0kRG}aCH7NBD1@Qk8W zu2@6Vr8@aoE}bQoqb@aj6R8xSZsE3k^{j24EYvfPto5#eH&mHqF32tFpFit2pNfG zOe~?Zk(Rkk+kx>x8~%wNLnJeP*R@%WAAL2qQxVIFxMOV4SDHx7;nM+pp%5}0DA%5rSA@~+~MTY zDg)VKPsFU3d?v^1>0uFjITKD$=ZUJUpg^%(_GY*hWbiIw2V6z`HhE>hkdgJ&zT6NN z!&*jI#6U36G?4_QQR%@JHezmPf}1S6?)gb=n{p{_k^Rw2qgs3V822!%3Q`|+v0dU- zIPybJ}BPJ4M3z@I4?8f`x|*fED|2rYAS2(^3JtLgQbjLn&kjF9eCimM;Jyp@BEW z$c!_cEVTb1W}@VAM8xGx;8MQ0T4QcDxma5wU;Nnj)ty&bMSLJn%b3nGH#AVuLRD#o z#`rmI9vocqWK)8q@iXna>f)2dO|(JSNv;~1nw)<0*wL>T<3_AFZb9g3B~Z7D%jNKv zway*Mk(0=rLAfQe&SYAosguuaOx239eNXvg2CIeg4#`W$&v>UjV^fF8w@AWvvVY`0 zbYXkeM;Lb-3r^v)pC05&RC<G-4X;$VNQ=cc zDD_yfF=VSS%)|RVz9_{fLfD8e`OJ&?-+|v?vZc9L?D9i%h>7#0oBwR6`dA!U z6yf4$%qvF7x1Pb61>Qj!g5pW6LeS%DlVs*ev2QURRlfLf#!#BnHEKhU*6AyN${^^v zBK;9kEN{VN=J*jrCzBn-si!D=d~i8De6m9cuj1iU8tSFOZ)`%0?f5!Nj&S7q^>Yit zc26h6Q4o>QtSfD}4j)KVE%X< znAf)zL|8mwz&Q%yRPgRr5SjMekAfKEqabdG6-3-&q@y6>8CrX50Cv* zu)ErI7-1Ps*Y9~q9B}o!nOXQ?+Yl(n>e1?{Y+XBr(OT=Sw#nBR{B7gSb#FzB7 zwLrEF|HP3Y5#7I|n?*T_A{KMbTTz^Hfow$)pHYsU_~WZ0XPLD2;;;chD=PP=N04m& zCj`m+HIhS{_z%sd)1nmqaMkP7iP(Y>Z1Y1X{bZZbv5|q|jRBC?5ooLsdVWVIH{5S> zHQGKA-F@F1y#_wt!*q>)?Z$Y2ejLM=tyo3A;GoCRegVO_{ zgRkc2wjI2ZD>qRN3sUgDT^PxvW7-)ojcNHF7l$?n;4sA>d-#7c-51(y(*HdTfF+94 z5Bq-G_Wl0_V_?G}uP7|?(#`)iq`|^7Wvo=?xErF*J^^{hC|KVZ#lj&IT`+Fy`qCH6 zJD~I}lN-9aW;B|WaK$1zG=#NC=Io0r*=|??Az@!Fcz$;u1Z_s4SeQ z@}k(w`a((MPQQALp~1Gef)E7JWX*WhLey>UG)*t&N3p22lLypW2t}(q(+%)e@9@2W zhK#SP?7Ss&If{0_%L~rO?_{!IMQs?C7E{5?I{F{G6I4b41=&eL5v~2w35-dExwP6Z z8?qA2Iz!Quc!K@2|`RbfK*Z&ufziRTP%eS$nfF3a#i1fWiv@!A7J> z{LFG)cS)6i3}Ps@0y8otWF4bD{JU2@Am2at;S@l_Lb9BYBHQGy1=3_%e-M;P6nSU? z&pEcdIOZqQ##oV0K4_I>Q6P*9BMBi*)jg(_k_M7%21zIGNlHi?xzKW-C8n|CH53DwJX584SU!U-%*GB#pTvMs>vQIKIw~wvh(~GnPQ5BKW&(Kn>?<_R%9-AfmmwruunWcr7ov-yYrMA6K{4+r_0Gs} z^-gK5i5fBWX^(BfeqZyk7PGCTq^hz(;gPc|Kh` zfylNIxdgTGGurfSf~VjibTK?UZm3jH({^Lbi@rl1eR&AG+QaS0?ivet^>Fw+ zRUgK+E2cXyJ!H^dVQ4wl)^;uEVUr7$Xp$?84`3^Rx~?%2ANCb#Y`*nljH zkfAcUG^^R?xEjY*&t$W^7@NjF_l(TK(!2vL7?}~ne1=ylGvA=HN2ha)awf-K%FgQg zPIO7^L5U!YOm#%xdxaIg$M9UwO}fr*nxQqVFWX|uYu6B8N6c9Y_iR)P!G1=#T;>!5 zQ#}6qGxm^1)3G_6CYVLSygp=R%@TT=4PuoVGLci(VaBOb@QTRlwJyobX)R|#)qSke z5Ld1-xc-bQicb0~4ColL9q+#&C@LsOT=ff*5Qir#sgg+`VCQGvkn1Wf^S>bH>2cLh z2sVALPe@YOGgew+U9ypVijXXuxs)ITh@CT2sO%VK=y=@xRgc+T$lqyOtxLiQ!or63 z9?$of=4eE-T@#pO#v7F!n1l1U5eIzK4F9|9jAwi*)P`)In#;Dy}f@(u& zJVYo}>OUe>Tawz32-TTteMG39Br=5v)eE=#5}`WX4@ZXTEaiV>sLsT-TZS4m;%ymf z&{uhcs6k)mEkunWIWB~#F(jsi5Ou~OLjV0 z(=9{wA^By`U^;9U*Ga z?SF(QTO2}&QqkXAh?XWMd4F?KEq$5FL z{VxG(WU0*|L#g%kEkkt@qAfyo$$DFa>P3RV5urL$`Hl$H84VmFRF^1niBO%v{6~c9 zNn|KQs2Cp+Dj*?3^`tKk5vofAxkM|^$QZ#Mb!O>dLid&0Xg^1UENtP$at82c<#Ng`USb4_778MJox|G zApQ5-1>`&@!kxc=1weoQy3cNq-V~X^xTC?YhXKLi%&fkF-Zby7{sRI-X;R;#$$Z3r zK(4C>o3;G|;-`QAdLPHBW)@&$&f`*P4|zZ+S~r>SU?=#3coj7?-q(O&TvddFDZ&tg zAEgAb<3r|y8tq@mV0y<0$)W}9VOnjBamB;P=4%E7HKtPIJfSnmd!CpjsXjueck|A7 zS&t@%C}ej?8fblj`?J=I=RbS{R?{l#VDpk06)jI^+*33v3IKYvEjMsUUtn2Zgu+TAK_ZD z`Bilma1WN7NsNslb#jrGME@4^;aX8=6yVcvNEAM+o$+56Oqur#oUJd#Uu0v$`clrF zTh%c03NP`fv6681J*^AD=ve&DugGH~4Bi@b1z~T;_~j2|P;7z}Sy9JX8BUG@CvklaRX>PnKbaQy#!;0k`GGi zd(6dU9@v?oI@ydrVhb0gIWZ7%?zS>G8ty;>ByNxoHMq}ywC7<3?u%*#{UG1!x(Gudviq@NH=>H$T(FM1S>U&ua|R`HCw5!G**3#A-rpX?!QfWHE%#9gsSc zh{-c~h8t@`QJls{HDRuXf0gu+a{#^%;E?Gb8z47}XF*nZG+$cX3LyOWp*#GWmBYe!OMnSA235)SSi>wi!OGsuQ2FKhIxI*yEPGy&RSZs0@ zb*PhQF+~*LRbrx!%1U5t=UrowVg{PEd;afJZ5n-+*%sohs>Hkh90W=obJ1j^539@-N7RDWBgIMlxosfcYiYGm!lN zbg8N&ER}UrqUQP^V3-V~9WnofpFNU3^__D>g?wq}zT8#)dzv z22z>D9Ag{iO1@`k`)gIkH%L(<56Z0tz6|4+Y6H^w-hrdUcSv$CWy81xigjNv1K?Xt*qyY>0sq{M7V`BMex-XRzlTJI^qTx#-iu zd|dlOZCmjUT@I4L!ww#iT`}nTE*ll6wv0jCOt2fOREjefeP?*sQH7La7V^aTf!mzw z9b-`NLc@lvahBu}A%{5B8a2fV29;cBc*LNe< zU}CePlt-A9AcQe4$P1G+W2)}O2r=)mGCvu7sJ1di=9Z2-AQFRH!LUG#y%UpBexyXS zC`{IxV>EkQ;BmZEKnk-0IL@M73iDO7b8dlia3;gsD4Ed6jP9S3RC=}DE3G}Yy

6mczb8(3Zge^Rwc5JY_J0MjhB_C3XU8%`EAmd^7i>+GS>gAtQA4WC&OMa-C0
z3QMx(Wp+t{$&E9i&nLY@CB{G%tbE5lTy+B&#F8tHUw)|XnhhudT5H=Jo;$R#$wAxD
z9>pax`N*Ofn>CVHEGfoF9(E%bK^ncW-vqAVLtjo?iSc;Dxp_o_48DC^gbUls>IUXq;1kj7cP4-G9LsQ5)
zGx5Uy@KXdoRdno8;)&8)J{a5iHYtmyz!G-M8CGbM5dC(Qu!
zDj}I^af9JctZ_8cHJ-!@UqJ}^5IL5gACH%v!re?Jxm+n_u%Zc9XF7XeYPDK&O_{m&
z*mm7@&ww%{Qw#MG+N-56&bCYL(Dd@Ic0_wq_H&u2DYXoFX=#V|S1GN7bRo72SxV^|
z%Tx6C=Z3oFLVkWIjT=%Kd;hKeN}$cvqL5>qH$y^P>LoJ%brFh-WzEMjGYf)LDcdRX
ziBLKPd(7gmtWm*|S$G2m2tSVw45F_bRzJ7CuJ%h)NCCfnzsB%Bq`0D(m$S;~nxcSE
z0(k{nmC=vY+@MI-JaD?G00Tn>3im5QoEan_E^F;ZOWigZR$Fb1KD8^%+*J5Uj0%(`S%okSFNZ0$3zU0oC^LNsOU^BMnD?UQ~_=rYQvJPej1
zN$qec5hR=Gm~($rU6mp(o94tAQ2{fShLBgBQkOCM$w13HuSiquqPoQ;-(X9mc)fb@
zX{IIAn~~!a`?_X4L&8I6h%?tGwOg;>NQL14{B>3sd35XR=N?2u99f5t-Z=ZCjo5nQ
zZ0s$t^+vQ`N&V=JxW~K|M}$__bri>`CLHHPS60Hm&wOQ8`$s?3AtvT*-XpR90&5<`~M|0#O+N~AfB}PA*<77U?b>gbc80Snj22P$CjZsir
zbDWKx058oEYg^~h9I^WID2^U(z445ze;w=aRF223Hcr(uxzt8LdOvF8RE3kRHzJ(8
z%v*27XQ#3iN7SP!*U18pNgqc~6>!cB@4od$#@WwXZv?vJe)Pu4w>^5}4;)pJ1}awc
zTW_4oSibZ|+=p75^+w+JsEvGVy46O!TFd8_Z(8k_YB+7x*}WnWqO7)DDmx8N(*CQ<`8v!H)fIr3)r`Hl?+He}yBoU<3i&e?PCbJZ`%^|YVv;s5^W!u|Q4m^D?h@E`YjVNB3H
z>x6uow#Kzi2NLUq?pwX~YgK+jj&t|_y}!m!3&^>5tkVVYI-Ps(tA0T~o`xc-+~3A}
zQt#7Hy9}`=2}wp@8D&@-hYYFAaKl1QOqCqv?|VU!9U?Ia>z#pmDnN(IQkWT46rQ@r
z?-fWl?(3RS80^S9yqrHHwQu?rnBkCF5-{;KzcS0#0RtKXk*;xdCzS)C!4#J>|1dSC
zhhfb8pCt1sUg=?o$h#JFyy6wedK0WD?`I=F@o5^<9D$dfg)`WlCZp=c!;`{FD)>l7
z$6?Hvwu}M@jrd-Ig_Uj(4};plKtOF>W84AZhJ)j-LWqPcz9cJM
zV?4O>o&B6Y#(Jd#VH^|2sLPSkU{W=a0YXk1S%vq24-*!lG$?A}Ehi7?V0XRjns6TC
zf=9trF#&uC`YUeGv2KI-$w$x>h?Qf)7+zv=VcX;_nJ-)5!g7fjVdGqxVVvyp+%l+xt#t4qldlQ;H#e|m
z4eQ`Sh)!yZm3Z$&42c<#@`i8FxcIgB5l!2ZnKQ3Jd(@N+z<$Y
z#}nW6PG~atVXdFU@#s^_(u6WiMLMv!*bTG;E5e5-U&F3i@Eg#U9Et}(<2i=3tffZJ
z9mYi`?NM>aOcz|z;a->ldqxp~85|CXhoA*C!g3KH0vPg5qSbvx$5$mu5x66Ifc>Cp
z5ZkW90xJo~++@8W9%y1Z%qS)RuV9g(Q*f>2V#Iy}%Z9#v3X$_#8iO)I;^p?XWxNCl
zcuZzYB8IL|Lno9x)r-=Gk1J4YrHF9#PAsJBJSkxI8rMI|7Z^|=nUD&>o&?%h644fZ
zdu)eVcELTsmD_3{;`=9W->cHt&JuBT@c^{(1!8I!>sIGem12`
zhYcZBkuS0t72`WDR)#n`B89SNGiZAiA$5H$^c7h?s{`v)YJ@Lcr^GMkpLAVHRkGp#)wNL+Q+_#Y5I
z{krNGq%jWg1Hyn2EVR*|jTSIQmVwrxdn?3?8~Xxcybt>Ow&iISikmxB03uG=SkD@}
zo48%-=8o|ieUEVkiO!jTS`o!J!1jM47jf
zAmHJdSp^~N6qHnHNBDVPmH`#>%s?H_;TiAa3(MG5-H^x$5lqj-Lc9|u3&rpqUU;E}
z!;&S{h64Raw_sjdVIMa#4i;az#{FEe;)DpRP;Rf~e?oNC2ZS;W#*buPYLNw*l9C0p
zKLx&r=~sP!htiofe0RK{IAkw-{9ce9%abIE2;54D?^3$xopp>ez)I82FGBbwKeBoWSGgig`F4z$IBzc2nQQMCw(yXewjTDx-G=761;2qO-
z9$;}TXN<4jo9-F&C=9Q1TA=K3St$L#7cgA7>m^<$T$nSK^^&FC7{ljxo|`5pF-Lw!3|&Q14SS-jx(b45C
z)UO#UbZjO2J>-OZD0wKF){0CFMuD^Su^y?^YdC3Ry_ivn#>B&96G>3;?LDTGMdO~m
zUd)AMujCXK5zSc1CQ)QKopF;5h{{rxu?_YO89KwMG
zkv)*T`f;OQfK5hz+(kzP=$p%Z>kZkPhS1}d{|$+!ovVI9RH^X;qUueMzj&G_P4AU?
zAYF*aOqhzYoFrtECCMsG`c!IMb_vliWQy;4lIc|jNmW6RE)TBFy5l;L1QO3y$k37A)&zQ?!+3goV9
z1{z@(-&3zGEvo*}GsB_?BLgNR72r%W>-s%@6uNOBdq-d${ounFBzE>(^$W5Q=?BgT
zk>J{><;MO431o*Kk@l>AKmz}N+=uwTVH-&|WPi%O({IRr@gMimi^JXdp~4l!$>)#OCw_XU`&U7ubDr*~a
zv+Mn~2)_;mXsK{Q56yolT{#_*`S1TAr953TzAwmLyC2KMwL@;Zq}15-3*s$CB{7}A
ze?Yv&KktK0Kd{)B1BvB1clr&9*Zg@Oy*Ofgv}o2UTXougXqAoqjQW?g%0{QD6^oZF
z;0|-%YGp%*r!dsL9Ie6i)Q{`3A(BVtF)Nl0Qb|9MhO$hQ1eX^-2!oBj3kxOx4M1WkYGW+`o=m
z3CNIer6*)c^r2NYL<1IU?8`foW*EcXFGAI)&=XPg0eji!9%BuPB9r!v*nMf1jhQgE
z$5FFvYzpDMMEQ!cRD;@@?EqE3SWnk-
z_#@2i_E$@{Yz1YR=Eezp?RbtRiS>DRm!Kxd0=wo$mA%}=0e*|N(ITD8P?uo|>g
z%b(vxfvTZAQoqHX1KH;toVNTEz;=EB%wP=U)~(TGB`xrMbLOmB9;P7PI#nd;k(hvT
zEf;bl)aFSy`a><7>zXl`%FSE8s|ls7hH9$|@F;6zlY2(H18>R%fQI;dk
zz&*|;F&naJ?vI@l%|*0#_X(g@)*$!gP=3jGSaH=CqM#hwv)M;LMy}YA
zgrS%H=O;}OkmfHd_qzab1gdPz=}?3&S134;9%
zc|I=rd>M$lnGHmF8_Iro!KR{IhWG{f%7djA2qC{rRfUT)Dy<_fltO;TSRK@xgC&RLa{YWUFQ?eWy_^9#i>K<%|AGwm?EqvA_LBbxB(5sY
zqc{EqIO`eL{DyP}jNH%u4LMhReuTYqm?h1!H`=ys+tzgVv~7FZwr#AoZA?$wwr$(C
zHI1*|z0Wy!pL@UOx&N%n%s@qE)mkflRT&Y<@inYyT)iUGJGnp$Nee9>Au_I?Z}8NS
zy5}cDei}gsoCj@|E}f5z00Q6bBTRi3qf_4}yOFMw{mi{!f3sp15=S&y6e7@|Jgi8U
zmmPcBo@5z@^c@~8=zT$XTwdD<1EJ=G-Q$x8kw~6Snro&~*6Pr-+yz-qUq6l9%+z~e
zL{zHRp5B+#kc;?Ibs?-p&lRW8Ujcw(z7)ezT97^x(hg8gnrrc$Xf=^rx?n|P0S#lh
zY5?jJ(>PUOAm2&s@cT)H6E16#RnZTkF=Bao)Ckw};93F>MbO*OlVADpWITFCDY3`s
zkbwfkF(2up!W(hutq+S6atPngWFs@h?}3+b=<;gLaJr-~Qfb=_onV%EBAduKruJ75Hf=~DFY9kD*`F&~-|?2^
zZDCMG&2Ap6dOGG(d%ENP`A3$0DDf`&^Qa*(O!ryYrPK<=ZXsC+a;PM>0Ye2u6RD|vns}Jh{6gc5a~cP#yCt`v!LB{)|*(YxqN9HIOlM;0QL9*91#OKP^jsG~z`(^uysxlTxikK8dT_eYl9<%UlPpmRglnmhf&bTo)Tji=-hz=6|k1rPUj;$qON!)vMAp9h(xF&
zF?1Ne@{>OJ1mXHO93
z#_lfE{e)eQpfme2N#qS)vV4UTQ2Y$H<k{4O);<$k)&%^ey_yv7%B
z>KoIBz#?#w!iSIGp)gMReDBXck{fGY@1Dmfq9k(mt}TYTHXTJQGeN;%(Eq&@Y$tHU
zmM|^pv^Rruk=1WUsf!n@=ESo02DgnE{W|I$P+`t{#4AlE_oP5zI@rFCPnB9pW8qxm
zM{_!OBc4R@mJnQTbY@<8h@}Z3K$tLiR!1meQ%Cd8UYI$eJN2O(mPw>9OthzJ)>zXp6wGrt&B^1*
zS?dV~*;!4wfWC0bwv@wErjqNPq7{wIrf|%9T0VJfR@6joiI(01kH8Q&*cF%vbm6cc
zjF&)R0;2P6o=g7}RY|P99O`iQHZ$&d@Ts)SaUX&+
zEi+)6FTK`VimW6?QHoxLgBmu>j5Ox#wGI93wuW2Kf^c@>d<4k(2h?Fj=?^2sch*5d30LtU=cTnI@rlD>Ie
zM5)5P8|&mxf5>2%p_511RUV?szkN7Cqm(5#d{&!V(lv^#k_Ee`EV{AO=l(hX)hgDT
zrF#PEp}}(h%4-w+;tbAF5Gsq0r+tkf7p?q$1>HYvAesPZ^nF6>0UIJB*sz_b=&tQH
z!B%~S8>eDwHF8G?N+i@u&IYPav7}gdIo;4
z{vA+tsoLz4?R8|1SKga}^Cxe=z+|zBN&&$e)452X&N;UHy%o|B;>8H|OI{Y)fcAIy
zt%F?tr>`2!bJ5qQnUeY_@XHpEd&nDVMzpBJbdTi;F{79?BVz)17)!+krH?ipF@!!>MqGi?G
z?IJ|kaGZt5eBf2Pq&l!;P^yV%&K-Ofi)83PXG=^T?zGDa!#xckwU;WnV0vp!sA{X!
zUm56XyUMD&_#{1Ev`e{r!4;~WeY<)u4ooK{J4P(3La6Ex)yov;Y;^aJIA$1HJLr>3
z^o?#ke7hiKNr=_@o#`q`K%>(d4=uehlRa5Vpnl0o$(o*YLoFnV3amR`pi{-~8h$xw
z@TdSC|7=@|_)vxupyb?^up4&%LiviW~}!
zw;UqB0}{&k4OYLu;WVNBd7#%?`Hx}f)L2o98TirFmbwjklKY=85r&Lu_ZpFK&2*+e
zItt9Z)fW7(b0bZP2;_FnFSY~Gjdj_r&&GpDl>-hnJ}a_|hXU!Z-z?5~L@lgkB6-h>
zE5`@9Z)^}91W|3)P|;dP;ICrrmpQwzO2KVoSsL`?T;5vthPTA^j4(XM`!t2)6rAt8
zP`uOaN%$l_m?9OOv=t%wo{V>)1+m8Sk>SrOn9if?!O{9R1kb?NTy6R
zh?sf3R0&X(Raf=PPekA)aaTm^#!*{^q%FY%fwKPy4w
z$UnO&7?fLPg^+(n{lV?LHaw?jEp5BE2bN|V>+xFO03pB|(*mX-^BgOEjK`CjH}`@>?tNOXNf}mD;g4mAAV67EZDT__eom*J@g*{$WR;mkvd=rH=4moF!r7Q
z2dkxVhF6v*@QONJBnQP1u!sC2s%BUeuovcffD8@ojbXEc&AZ}BGN_tOpn$cQ!^1{=
zjk_Q;4Kkj9iy|s62+yTducm2A?m!gy(q3H8Oy1JXM$niOpJ>jC7?_cX%rhS0dFVL9
z9xwnk=P)}6qGTZ9Rb0qa8M?oSAI86ES6^oX=R+n%0vvuC%8_oUREz^&{??g>_FYsW
zv~(Y*kV-I|7LDr5j8BeJ1+C!BGk%06CbqS=SRg4TWB=8E7_Ux@ZmKN7kn6||vu=kk
zK(*Dw$5kz5%!)aQV+1swt!~zsR+t5CTn-NV&nDwtkEa1P
zTK9vEo;mps_OJIG)l&6iiTFO9Cr1)g)zZnD*(a!Lg@|?}obXMMn~rr7w9W@o5FoPd
zh+md`zwo*!YFx(*!_sm~N~HkY)KcRO@a)<%v`~aGHBQu5*K6Ut((V2=N0jDC
zWo_hdO0{n_%?aEsemZJjhK`I^_Sj0eqcI95WjY-&CXt@}-3%cKf*Cz(P2Z`24O>vp
zgxSYoU&im`W$%W#gw2aBC0dAul;9%cEcb{^GF`ARsqqXf`6Ok0+w=mE?^L6K6y3sK
zdPC+Zxi|^0rMv>HtBI|KCD8Ic{9u7}V)A{OKZ9j<-G`aTH%
zit!KN7@Qh0f-0%36B<>G72Y^n<6HU5jKTOS*Uc~p{?MKlSb;a$eBp?0#bKez!PceS
zNd6dqvyz@x;M20^DKSd%j#t2!{IN7T%L|ssj6l^wQcCkn2Z6kB0MtCzkNX(_U!dt+
zM$r>}y-XN!tUolf5;A`%4jjW~no6n#Za@h!5ce^z(nt1$r6H6csr`LY9C1wdg5@DE
zilGtht_X7Qp8ZfoP$~^3Yu9
zWoTSx7`7N`Ged#EF*TSXDY?zwLP*1E55P`*0lx{g6kOwVsuo*qTH|pdnM&tminFb6{K>r)oz)72@4T+<d_icD6h+|Sdd@W0GEsc{DcAxuJn}XPaI)59|
zkPDtJ6nPiJZ4c~iJ}j_+p^+|NaU_Q3At)yt{4@zq7I4l8JB${9lawxu3Icqes)ag6
zT&0bwbl6l~2@U-7D2!%cpHTuO#8CKqw>oft%at}d$y8%?B@A;q{R0tv6H1W?r%6rBoD9bt_IsU#2u`!`5@bWtG)
z@NhkqGjx=!L1_UD+PX13Rj4-b+lJWbPjGVFnBBkKuy2ihnHBkTTmVe%h!Ej%5G4!1(JP923i}c|{ET9H<;y&wUj7P4
z4QWmgR_x>kykLMXmYf6RTt~sypnIq+u4N%0HBay~8FN4dt8`oial@mQ6a#8ZCEeZo
znDiS@;A(`{1sa!1tr443MTk*G_{zo#^(s!dnn&AAU|ZsZ$mY!@CVc`>)Y+i;E^eo6
zl*x_>r5qes2qhURQTkKB
zvL>&RR4(2G1`@6PV%*v5EGtnrKpt+X1AFK$j*8aNnk=!jF6v;nCJ{N7d(B)%jiyU1
zA!u}2@R&$lei}%UNGuvZJedof_Ot~0WVUb=Vhdj7jKt>Q)cDRMSHGbnd?AAX#
zrU<(>XJzXq6LGMdvyzk%$wF9wOV}q2KPGz#A+&=%7tCcrsE1Hj7J~qWwn)j}g7()w
z{gf>r$Q7*xJAr%nG!5S);J4-i0hMPdNp>ke!kq*Q7knduFcyG@a5ZT&5L6*TXa=C8
z!RWE1PBbCyD)}Tb*rymFK3Q<^JK42l3q<2hJVHQ;MjAeGf+XX)!fkEh-Kp7wKN9BR
zj(t%H@kdnzO|bj8i6|*qK1X`!4`YG*KWU^}&QjS7@hO5XAmQm7n2~SS%&LEZiNMjd
z(zNl!C=VGi!-5msh}YcQU0QYT9g?i#=c^xGqNQt|;M4bPHlk_H&eP~TJ5R*!^_*L2
z+5;6#9t{%_{qAelWrUn+-4!dP?OER(5)D+xZzDeVX#L)ee?AG}HSz0BR1z(jwY1ct
ziJ(Dh-%|nTC^>AwYYWPJf54FJ>7M;2VzK>5gsi6d@Sau(8k|8wwo;m}BxV`5!h^3Z
zIbK~tGV*2{fUgZ5iR*Sz5!tA%))p7}zKg}h2egw4NmztvwrNQ8*0*X8*g`x?0iu&-
zjOeu`+81ib*nGcYBLE|Ls&?qe<&!6P<$#rJ$5Oybw`Vy3tf-L0F)KErWmsEu1F0PF
z=rGf!D#EKIc#%(1kfx0*E;=Ah!=#{@Det&p!<6|uHA;VS7l^bJppkT!Pr{OKWQ#uA
zE3Yj&z!U3O4j72>EeF71(TR&12M+xvF|?Z`^oblS@)tf#o!_n?*~`}IRu%CU|A|BL
z%-}4P6HWjj$$&kt@LYWn)x|DiEoj*ssxeRMmdP%H#^uETk8EVJ9}=pu-CuzDJ5(bv
z5x;`iP-nT4L~YzWpTuxNj8g48e5)J)%uTZwsv$a{fi6=-QgD*aL@1^=zNQG{ZoqLAw9b_pF6<;+kaUjg$r
z%Ec-YuIW--`@nKi66)zP_GBJT2m`sEU1E5~lQvTY>ev08rWpO}uk-Wc-T#LKGRNnPXqo-QH!
z3bM2n_z29L#%1Q1cm^9&I<_=$2bm;yV4MD3L{+)gY|OSaaAVW&Vf&(+COkKtv$Md2
zh(>mq@&u0N{$(1>Dx9H4<@VEF#u5Scuo00sqBDk(xU6-`4N9?c1jaA8Bt@tr1qnT0
z03%+3#2&95qDnz&IXy2cGcMoq7QP8CL@NBeuFj|eMl&Jb(A&5Kz7{UTfsaJRME+hn
z5M&1>uWVgE3{3T$)WJ+z!Tr=F>Y|ZGnu(0c+whC2Zh4KYQ8TbCMjsv;W?bzp3=CZ}
zpIERoa3wx3!_!NLL?yA&E>b~uD31PL`}KjLk;`Pw+%LX7nTDR3Takg*m_e=4uC9vL4hU
z<*$^yqU2j!t&pIVRrz48(q;)g0u*S5y+leFtiG*oORNwIJp0Ze@t;8wW$nG<5(?RE
zXXFBpG@xow3c7uF7BjhHJPF_|+ODE4VVV&@2sXawQP8RTD(CU=y
z_isn!Y^2KIR;iz8g8yI7eK&Y{8HF9~?1k*ywVA$0IG9<8IJsGL85Im1O>CWsSeV$qN0k_b?QEUD`%Xlh
z9RKPo**P0Hn-DQE%9vl}w!MTpW!|zWLey#joOFZ}P3v%!Hr+e=PWi@^1??
zi)6nf2m{PV&!BM
zv#@qHanxoMv;JOo5fdXjW0UU%_;0)1*D5t7oz}%Lx~8jpY#2Kp`06P(bKF4Thg@9@?OJRNBsqIs-%Jmyg_ORxHbQ@bg;2CyC;I$xPNjjMs-tu
zI_lbPlvuc`qIP$kwf%efAv1i{R5pP>__vM}4at-!sXz(-x-ulLfl@YKgusR&N^uWIi9%HV*-qGq3rl
zYYIeFDGbGE9X#KBtRXu26rMXw+I|nL#gG$(mfmAWBa>qV`gt4u-*manY8l^pX0my&
zcest|dX@IqteDJmDpl&SA$4rnKWq6LF8+>w_phd*H1qDzmTKZxIVx~T(*u6mTPIYj
zsl}V@=Rv<8Wag8Ui*MvE#c3k+Jarh&l1Z=zWptB5Dfwq&xKwM`v7g6TuaLwlY>(iA!o>)x7
zxJ(vK<@z(VxNUqDoc*q&U}$^5NB4;rh*i@Yy7%X)RimE@Z$$qw#*nK4r1$8U
zJo{H*)enM8xA%6A*a4fo-c60^UDh%Ktu6~%WmlqB*4em=zObQ&qT=ue+%9l3p!fg;
zLvnH;szV@ME)dLeLKhWD=f13g7z$s09cW3yf5#{CT_!5&KpKK
zBqzuhSP(?x;O?%!$Su@JAXiX_aScL5F7O%M=pomxDYZ+iI&=}NUW90|vdz7?@mkXE
z!H07u0HF{Iu86#Z397mJSCefhq8hj+^<-BvjF6bGzLXFcJdVs78gN>@H{-q-)B@1k
zVde(HrC(qVIU2~kLS7|s8z1K|c4T3zwlpnE@|t4-xvj_7FR7DY5LWhY(Cam>{xTHC
zAiZ3qNO**TOfoS@6ESP7>BOz{7pKn`aSj!MsU*`FN%ZXl2Nz9>Mj&ba(}$?$r`X+y
zS7G0Q!ADj%!Gu7}Tz(A4@jFbeaS{gh9-TX-xb~v;@uv#l!HY~u`t=OzeW;q)3K7Dz
z$@WHMU{!)mAzZd-B`<@)#oOAzXtPZiqBpDza5z9^Zd1HDJA%8e-2DqEy<{Q07Q@9Y=2?LyUq8txE^T{^dX-7H
z8~;S9A)dP8z(GHH3&3|g1SU}Fqa`pQN2Kn4M->o^H|gI(&`9L$o7RNhAYtsD3^XG;
z3E805U5luDK#w9m#Snqz<{bQWq=28=mc@86w3!DNMp+^up4x~#BGl~1oqh>Yg!=ME
zzXyY%JP9H%RqsXX=2sIa>}`mJ`G6%>wKa%!&_q3fIC~Jcm|;z!p>L-{D1m
z3~KoFazh=qD_QQm{SZSMflf#S5guPBV+z}rGH&mKu%1jAZFiJ90y&o#cxx%AArM@%
zc=M@#(IUKSgsM*x@W6v+aAYX4u7LGM4`$2x%S=Uk$q>M$bfx2&k}ct&xVJCc1C;Apn_`-(k%kh~%0E)w2h
zjmA89284TBL>UggY$HgvO9S0y5Hc-7yTUd(A{6|P5P1tAZaBO>>FKDdNN2#dBZp~r
z!JNSB)}$bNVo4jMTr>dSMz{$pu4vi?X#M0a8AI4N<0&=el{^8`KsGt9jvk1V6*dU4
zsz+Ox3COP#DXWApN!KTU8yNDL9$J`KWOhyE0BF&=Z7M)N=?S=gl6zU3_|F}l-@sI(BHn#IY+(o}glj{`%~l%2e`zJZKx0TLb6O)Fvp&LCo5
z%KN|(T{NN?N~O1~p=2(yv?m>g(+nZ(@43RI0KC&6osOFWR%LEhE|lCxP%Oi6Tl(D+
zo`-pvSO0cFM@yHMqP`p8%cW%h=FWXCcX;IH?Ota
ztLf|eCOUnQ?(?~vent{StT1S?WH4Q|YTaD79W-f3U4qTut_Y#qq4~>-@5b(chBP7g
z4NTe86Z@0Va8(Run3@kmrNzWEJ6GBw@Bq7P;VtQ7IdBQ@{l3+wpjN3KrOtX9h6nx`
zx%w<;3)NA1=klx)jucK&DSuIeXq=pB_b1@I3+_75nkPvVm_p$n0
z9^H&eYyd(=Xt%YvgG#}Ya2w0=n!0C3$!8PmoYb5xX&ja6&jjmk+S!G)7hkXqmAM~&
z8-mV1mY4;Ui!}#NEogE~m_^LcFdw_j?ngk6!IvWiiR8i4jHTq02tx^y^?-5>_a$~W
zN=#S|LAl)T9LY9EJDZ-^B}}V_oI>Tm^2nx57MAh<{{G2YTN7<#YDe-GP0aC7WQJpC
zC8RE7H6EXD#F%T?4
z4+p0vlEt^Y6OTvEH=I1k0Vbo+-{>2LN
z4AA0{t11CmJHI%*k8$v;)@#>C>R*3KwK=@uAl@^=@PrIvNc`i$=cDi`1#4DtdkxeP8pSed
z%ICOsW=yYy_KeU9x#UZ5u6Ir!Ny3x?|C5
z_$0inH0}z9ppV>KH@LrDvu(qwCgt2+H%xGR9Vl2Z`X3;!!7c;-TnbtR(Eb2i*(@6Y
zB|3|owIP*Lo{FMb7LxsKP~FAJ(pyV6!rWy_oh6z|O}38{llFAh2s(q77Ctnx3ikUz
zd{f?s_`f;V|MKbp8k9h}k*XF#Z>E
zVCCXqW%)1H{Xac-MmYl;lW!Qq$tY{!>}cVx{SVUl#s@_7ENn#dT)K?^1E0Rp*?;06
zT}DxNXL03!L9c(qBYu9ye?hDNLQsrC{|&`hSidLB%F6Mr?H`l=Vfs%bBy`Szvr_0|0;Y0+_S
zUCllBBlh;q&B##Va`XQDIrr;@a`26Tnn7n6cjiog?Z@}c%MG*hYHQK!^H{=w#W+=+
z`#9kKCncctT0uSX^$LC)`vZT7_Vjdp{hk`F8;w
zf5NA>VdL(@n;d03t=PkNgaAUlSTeS$N8Q9X4)tI6IOfCUZ|=(;{U<<#_A;5*Y%3(>
z4;78ip6q&9s9P&{KREdnw}|h;Z){J%C=lq+&Xf%?A^&Rpcnd_HU?-Z;&}D5KYQDin
z)j7vm4O|90ZZhDF+ww^%A0!D}x=g+df&O(K!XV;|Bkj-0*izBxl}&EFkAHmb6z})>
zO89k?ok*1sDp=VqeF*85j^o0p(>q%@#QRnsDJ-AFK2*d|+$RdhY>Oq|z|QCv*|nt~
zWSN%2?&Gn7>$8<{WK$`7Fkw1%aV9#MVeuW>ra-e~s;Ffc*=Vhmi4>v6IRtwJzCVbH
zJHPD|4QdAMLq9dhTjSx4O!~C~s#rA?0g?3E*0lDp{O4Q0t5df)H5E(d0te;o8qD
zMIuDJ`Hk!y=YBoqVwgZX)yALL*m9t}xca)-;5NYA%A#m}Na@2E%x=}h1XTv#9X0iK
z075~<1&ZSY8}qxJ8l$^E%a_Bc2hz4?vBjbWO&vg5ciJ!o-zlm-X3Lminoe-~s3KK2
zZ`KYydype{PogipDIxcdM|VAaV#^>gU^DyTAjOza95S#U!RIE|0tfkPS158da`g#^
zv=?}955V1eo`RV~vphPT#A*YWA7$r;))+Hp)3!I8bap@mbJ@BAv9BSIaEvQ^ZR45n
z`kXpi%1Qyrs_;gYyr+oUJ7po9oM=stExV#Kv$^&%%^1d?D@P#OXjFmVrfV%+sYI1D
z{CV<2&G#Wpk0Kz@y7VX|+DzT?&y>dm&67H8dkx#=vMLSy;J70Fs}#0_j18RA@s@OM
z$kkg+uDLu-u#{qjSQ?^zq>+8Xn@p*8wY%lO=3Q%)tr@F&HB;-t!3AOZe+7mG`egL%
z9cbJJ)|iBGEllx!&qpXH5-qYx^La$$H|e7Q9EFTzYif()ERO^iA`let20UK)+v&KZ
zdz*O1Xk1b7aPPmf6W9_fS9aOi=JA^J&G4LzeC=e0d_NXFqZwo_Gkor%2A_qPKb4{p
zuSToaW_X>{y9YsVuzwCO4vI(1V1^Da8luo!*%m;{?Sm|jqC7pJQD9?A#np@?7j#i^
zs0m6fQHFE!a;%&h*Ay2=(nB|uh9BC-iyEJ2b6cGoqaJD9PP#hW{rUm6lyO2I8SCF}
zrUdoMXv*n!yNqa$tQRFev37p)8aSBl%mjLLN4I91G0D5t%Yjs)AF%2sj?SAkS@Pj+
zwysxHjv`{#7@3_yg`v=n{{cDQgFZX%k|7QDI&?!FLnffWb*+mM)Sr$oO~gHF`8L(3
zkn`x%F|cG_L5k74sv*9JLnqT%D{m#(r%{i24^N3|#A!Oa=DGLWx3kmaCQ&o8qW5-&
zRJ(X|Eg@#tt0m!By2r^KJ{awzrC$-6&hgYT8mv5zuzC|fRn@8uhEI784w?w9xY`ys
z$WM?YZh4Wn>S)Cg(<++4v3!NiAV<~|2*~9;dLB|(d()Mtw>)>v~cN
zr&v4a}lt2
zR~gb7fuhvd3azd_@Q}?8-upNESFqD+W~ROD@)1Sxbtk?3Ri{sHQ#0bw^HZ<69c+x3
z-Fe~T+WG*R`fR1Bl$V{8KC7-*W?IVA7DX09fPI-*D+ecYsUH2(T5jj$>eTDndM=yU
z0Z*75#C8*`QA0>4E0-^o_I@}u2k4AWNV-;9K6!NFUa$;suyPi
zmyKko3{m|GWukq!^CNe+fd-Z@NLZWBagY8uO8UcDfz8I1d;{nYrD<4Nm#9O(%b$5x
zR|QW!dwZv3uc`@go3kzBF!oQ1(d3Q#ZN^-S1b);hFObEy8EA*eMp6`Wv+kaYw$b6hA!_;8(qq=z9@$$=0Z0${=c!*qz~s
z5UwHf1Bw~VW9@UOSUDXG($L1nMfY;OjMji3TC*F6wez7*coN|5xe~OPC7o}}Tuk#8
zQQma^qQTlplV3gBMX^4nL?A>`Ak63&O0G32tl~!T;$g_Z!Zs9o-U6qcYH^T56*6%0
zk`EKYS&QutaymB)fymfpUx2^IBZ{zUNXS~$IH%*I(#|Svcd*BEt!1R5U1NwA;?3=7
zv+!B_7@_eQWP#j);fNT$Ku6e07aJpPi^8j|NAEPOY63*BJ%t-+z_RqRs4*9QZM4p85
zGbsHWx7=nj+R%F8SfJIE1vSBTZe8=u)EaJ-oAV{tHUcTWMYjg67-N&;%C@1Nf`GR4Z(Hld-&(9na9?OVE$c(z(
z7YCdcVi&L)!%%t&$pO0^f=oLMdscgMn|N7wdv0
zDg9l-^API=>M!OoL6eV@Na3W>uJ%n5&?yGLobC?{{<*U9)7c$g?H3FR8&t3`#YrsF
zHo@}M;x#&NSmkZ*E&8<-94Sm>sYqtjT)+%f;6?9{5l0s+gV+(SATHsqr?q!cp2zwN
zpmcahoC^<^@Q11$E@3-gOmu92#`jR!MYYlXz6@IZ%B_SRYx4K7(@#6xT&`i8{dOkP
z{r!lfZ?g8^+S~A69S(lkui9G&ytQ34bGEAWq2bz8qkYni=ICpG+i&hOY1T<44u0QW
zcmjt+5nc{{xkaW`0p-Mj)Qus^IePU-!zPZ^mzLHeoBh8B2gcV{hfA6t+h3=^xP=`&
z#s};JAQs40i}@hW%U}1uOoBX`c+|j$-wDP+xymQ#Jx^dAa$aNo`p){JtR}1mA(}w9
zyO__ZB+=<9c~Sj{^Ntk*({C_8L%3o^BmyrPqkLYU%NesO!h`&n_X6mdiF<8j!fIB3
zpgm**@av~RaO=>c>^_Qs
zb)?u{<^%r)Zrv(~eq4To_>JsriTu7sXXFswE4RlR4tuo%gfplUhD+%zdl8I{kv*V>
zbsM#=KY&?ld0ct|H+{WG~~ZJ7FWxqnUY3_x+o5_}J=g4=@Tat$t3h
zozO~q{DhYOiD8aE=VX)FO4h8Aaa4eCZk`?PG|SWwr7X#J9-9w6WGpg7c!6Q%cs66r
zF~K>tWqrRX0v5?x=@ix}k#)s|`$H3Bn&-w)LKD_FZ4jM%^XYxhV+G?~D61$QE0SIT
zT+_u|DG@f9fuXGInFwyE#wM*jL^i0qhY}`N!n3a!CA$aYRi!ZYyy8^{uC0KQEXAcN
z#)aWGTu5A$v4gjMN?pJv41PC;9Aqe>dmZ@0bJGqxMwIKUli|rgu-XW_cCOg*ayMD@
zKqtqoeiYg7KKqzfz0S93^0RZgG@CdVkg4;T3@$JmXy9r}4A@H6U-U4iX^|Z{SvX7bb*4#ir`%L7jP`!mxoKyqjKip#J%($h{C`u0iZ
z0WvIwqDj9_vgdOtA>lbvD7Xie@K*#c1SFcQa45r}&#^6@hCrn;!PW=TV}+w}tZ;jHfjAncN_gzB_#&SCnN|X`=~H;Sb_Sb!MD$^BT(jUD)*Hh?yT0pP
z30PY&M+mO_?&l#5gSsjKoAyG=3Z7Lyc;N9^9%?m4
zmTgu(@+;k1nt$Y~9+NDKKQ?KLD|Oe^%^Zehalo~u;60;RC#oqGo~ci?nmiiTr++VV
z-OhXQN<9a~0$-18InwWVmDikB2Bt9}1Z7J776W|yCy_X`K;6Lj-_SOfh;V4RWKn#N
zkfx^}+_0dhad-{0yY0-&${h3CY3Jup3!D(VLOC7Lk}5;oi|P6^BC`X57Up$WKt>5R
za#?G;sDn%bJ!Iy90b%(aC^W?v5XxS5ie8E=mC}2n@PsN1EAtH$*rULoqcUE3DIn!<
z$hn+DYz5#>u&rVZ`fIzfV&92EJKd^~>A8e8?0w978&vV5&2LF+=F7pcRMv2215cZ|
zac28w5-w~Oz%@IpP9SDYOOCm
z)jZ5u+x>+v2hU8so9{V>7lYUM{O?;#n4Fhv&mRG;Ep^}5@aV>i>n`Ve^!xJ7Zm0b{
z_dLUOy7d~y>b`b1!}Hxv53#@ZdYQ8GMV!1mdJdA?$lM+e@O}BnV?DEXGUt`|{fX7@
z*r@M(zx(`M{rI#oZks`pzAlgxO0XHFQNQ1oxQAb^z+bXUj@tZ&gv_RYbHUJy@8xg#aXLZBd_zCw8DJW)41_
z0vb4g)txwr`iy|&kQh{i>;bstWZAPv8${8L_00WvYzgm1=)%{-830?4igJyXRHg85;Q3y}8q
z;$JUR&S6?9R6|*?Vp1$l%|sJ^+yNpm1AXC#^c6)C;>kKZdQ+C^Qx)*rqj}_p&fc!~
zZBjDcr7`rNfmqs%QaC+9Q-3sfzF3n-IWm(4<<+Kahzfg`Wn?odqfUe4fuV|=9!{Cq
zOGoNL&zk9~;SqiYqR0tMBQLQS&Ft6sd&;0&!nnb!?W^hBrqd|ripcGXKX>B%mcSns
z{R=8~hkLIu5^S0=$PlD23Ln++Q6#d5R%dQIA-AT*lOQeoNQ{$4sQsf%UzOmvSFx)roQgP8G<`~#v$gk9p#IojNn
ziM(b$bjVv;Ftw!Pg-Cs*_7mqMUQHZPqHRW|0kn`ZeQ0CceFRcw#PlgC3`|x{8bBb)MSCPQ}CY_b83lthuoWdT8tb$D0)
z-Q^#UOdxDJAV$T
zOHg05(5sO&W=+HdEBmvHn12h6JVHo+V;uwUM8BvX7P*!T1PSM
znLN^-J3y18zMC03g0wvLP8$)LzsS_xcVi7EO#h^n15|`7>UU4pC~VqEnCtKe32I?9
zAEMUDcWNAw&=JyL(qUi?a*z|+L}Gi`IB<3m!HZdJ%=sze5G35W8-_b8e>(6@he
z?W-@3c5O0fmxs$Z9c?}I>8yAKd+S4RE>Z5iT+o%>B*C?~qiq#n!y*QMO}N3D7@+14
zYQixBk0Mfl?~@2Uos`P89k~cGY8;P@1DkSfto66_^;d@weg*(IzheNI8!kohBV3E%
z&w0fL*)|qbE+Q82p9@uo-h5_z6iO2lM$4Lb%$SWz_Oy~NQRyktlJqOc_{pdR)qIWB
z33)|D!7T7Os<#y;0u3wnYlzEAOoS(MfHtuvhxT9k4-6@NjrtO1=8=J20k7xjpSVtw
z;O_>t8QfTj&~O|WEi@$Oo<-{hJyx+-PZH&QAjv#4@kOEA
z>a5OH;xMm;JM8fGhrzfLlswe84QU&qf8nV|UfO@gH#n7dz{ASfJz^iR21W;={5*@m
z!Edze0+yF_urGj4v0{^Qy^wURWajoK9MAgzDN^K8%X7Zx5P-zHX;
zNyzxJF;2pDIFl&&h+vM(b5#2d=K8L`XSXOb
z_-g36(>5&vl9c@G$tPX+Fv)=o*;%Nw9wBOUn!+Gd#$$a(P?2HLii-MgAFg|QsNmMY
zpDlj_QhQ2j0^x8ak{~KllX6MFL;n+&Oj-nGdIB>=5Mpt5diGniM>2OAC6vn2|IT~c
zjXKA#Eo4x-AY=5y_t((_`xqI+?ZBR`}M~LHSVl$L)9CuMFN{
z&1(!UxDCc?4=HW^cjl^PXR5gTmyLemq+hvK`9U427iSUJLa7`(Vlu43PYD}QlEUVk
zoS~WAUh(-CSVHZsQm(LE+6==TAqj@6UY33`!3{9W#4Ds?Mb_**DR}Wn81tv`KQxpJu1oi4kavbR+z1uQwb)R|
zgVTuNAL_Zok=x3y&=rg~TK_zFI^hUnvKlj8YOzG1Wth!LJAN6gDS7w|sr_Rs(`W<2
zQwsnT1c*Wh%s&D3GsUpXphx^PraM*%*(F+A?i%bWC}mHG9gtnR32-KxGL%qe;i9;gcxK7&$1~@_)WtO2vubc)1gqz(V3C$LU
z1hj{59rXFP4MgE*C)F%~5LoDB(lN`*+}gp5!Xm{aIWLhwf!jCVG?k%{N=xfMET2N&
zwe{*FKoB!{=p}w|3(5KELE`kQH?va;H{g7KlBSPEnbjN}xJVq$eRqfD44yTd92?@G
zv7PP`uKNyON8&vI!zqcvMlE}`{%_SxQTLMn2a-T-
zzoigbF^H6{DZC%v5I^Ab_WitHI>l
z;{}+AOes_zn?bJ;TXco2^rUVsMiS)y0z<(&Q`SIm9A#!Q<_+T=b?wf1wJ1Dl`G#3E
zur71jNcw6z8~`Mi6XkCiK3&r-5FliCh(lP>%
z+6m0h$Qmd3P-zZUssbZAT3oI9PJUpOao*`cWM!`%A7|f~4W-7g6cIXna=BC(VA`GKP
zF=GeY!=$P;g9elf1T*tSg9?hK8*7{xW}P8252UCnPD+c8?NLadZL)sZ^ptF
zJ&Ef;CBir0x|CR|Co&yhg9R}rdqu7e(E^lLDjj9mLPcu|q8N8b+O+Fsq>mKj
zsckk4=pS-Jz_kMcVa&bn+8Uq2IOro>p4!Yn(Q)_!BeVL=IS@l+o?7x2bF5($uv-A`
z<`tif^g$!}*fRlmwrcYEq9}w!6-5e9%H#Md#V<(KjLXh+mrhxymIRxtXNPn~5tFVh
z)Jg7M5>=LPoxrg<(!;$HneGX+x$qX#uVReHrBb5<<+_EozlU`Fo
z)#6uWD}=0l)j2>~bTma{YFof&gr#M`JcNCSXUI($G71|(QpJ>@0v|7z))HPK$OU|>
z%i~0oAP|%)u(cs0;N(v_@s|{M!9{gS4bUcuImW~v==C$M_*K+Ne*=V>DYYolonIxU9ot{hC
zaxHj+q%|A~*y+!sLBc>AiW*(aEun&pBev|HJFE`zFN{6(`}vk%NK}S8LWZ~562*Sa
z7v`LC&$sA^>vGlZKubqh>}+O4o{n$C&SnS)k8Hw>xW6%X>}*Cb%f+EG>PbC0)>M+i
zZh^RkE1NJwgLq^UmLLO)Ib+I_#Nw4rcwi5m-53j1hXoec}jM(AutaNCtkct*Bm6vP`{$%I(p
zIp+3uWJG8@k_j=L<0KR2iAaA%Pat&m!0!Cm7=_O6=Ph)WUw9-FvJY3_EBkmtzxE)u
z!FUgIx3FpO7x+Z&(Ahne7CO79+CpbP7lTZqgnk=e{@sYZb4z43mv4l-eGAmKQMTK6
zi5!gZ@eQ>mg6UCb%as(E;|hbS!8`28}_4+tq
zs1L~KNAe}|ACTF;gmDYSt;mF4J9}c?*Qx@BS}|GEHeIlC;`IbEYm$+!$&8luN*I79
z9)KpdK>6#@9_4M;C>VsBG)yFig+MhI6NM6v4zDLt;ns4@@5cCq|9&k2M3eJerOD`D
zEPOiZS|
z5HRvSCn^c&7nT+F6-;@a*%mr*5s;g#PQY3=QGmNPQVQf4z=eKM1Wf`$AS39iTI;bs
zi$NpH*x_qJ4fFdoRosNg6PhvIWNny>h`V&aKQO3N-e6E;NHEeLzcJ@29Er$r{=!^q
zY)^e-KwXh>i|6Z~nCq#JadEJSvZVgJ2kV&AB?Lr<@jx_cagITqwTaYm+zqg%vC&vN
z2v<%$3WOEgg~Rys+sK__)Vl+&uVR!e<(p-|gI@;9g@;{_<@Gg)RC
zl)%Dm*q=;zKzS~Ns9@^xmID{^9<+Ci9GrNb@)2U@>mW?!6mhFfLy+t{rZP?0qsZiI
z_$<(2P&+)PGEJc58I{QyXwJkS2h^-Fd9Yy)@M+{IcV@n`a@(YyF;OTM)7u1V%z-*6
z)`}a3_3g3{bxkMNB^_?SNY-{}>E~;?!7mU7UYYbFL+8I-@R&D33ts5V5e6U5S&zUc
zhJtYoV%7Ar1*i}gY&x2crOOctJ2ETAb<1X_y`BZqpg7OM8OQYCY{GoE-Z*^);ts@4
zqY+3cgKGwU0T_|*SW^T5A9!g_rPvd~NC4uJfaykgj#;%1g-hbytK6y%2G9wwzZm3E
zxPXF{@j%J3tI7|iW>hh$+O;I8F8b0x=I`?5l2j1LS<
zBK7Rlr4HnvvlJ>)V_`V$Tt*S{OmTWqwjjdC+2wK4m_DIGM^(z*rA%he06x
zv*KqI)Wc!bm}oRe2@`vj)qNY`rNQw9iMt6bl&bre*+*bQqw!Bjkz0f4wwT3rzyPxl}~RWssx
zSI6Ky!5UYThoHWUxnN2kMiyA34G3n$2bL&gAuOD_K`~8;%I=(+q@*I%;cG--HzAB0
zf-T{-Ls1Jg
z%ojFEBglLrtR!Uw9I`_z3l}yvcu1sga2M$1JMs
zdZji5?5Lte?5HR``G<>+>O0Ywv@sck!Y8VCBU+sMMesGBhWY)PDaj=~>=sEvs|$tV
zwqcM%9C+%-ZZ(6xFquVXC4WPi`h@MRzhB?c$E(7MDP-~6tU$9!n?XyIPHBk4o7Zk#
z(l-)i3ygqSA%m6W9~O)S)vjAiv|AGCDwrq-kB1S1IV?NTez=FBm07DjzURVb}+spA1Sw)?j5=P*)5imz!On
ze<(4C0bQhXj1~S?mntNav0)4wovv34*uAsf&;eTsAM8vD2AJ9kA5~%gRV9yR4^hKo
zgV2*WuZF;wFi8MmYRgg<0HZcM;1H#ppb)0Rzl3q34mb~c<}@dy>#%r(DNs<4vkE3@
zVQ5K*9Mz$e!7>uH_$hNKVNq}xvyfDNX}7S&&k$S}`G6Hd5C)-2KLDR^MqrBwE6Z|L
z_Gl^&7)Ufu2>dKrItd3v2f+bd
zH0~@P1%kWM)J#EuNBIkO3yyV>MxYXbxrLkwOkL}vjBd>Xm^8D*q0||?o`9XG#H&SB
zO`swpAd=o$g^1_6p2+f7!UuzIAetR+36^fH7mQdz_R2A5az3a}hsIPO8^%SfRKZ|hJw|ruSj`ifDIH$2G~%6!5k-5Ttfz50w+Q)0!~|K
z^89A7AX#LW;>=u1HAcBa4#70lC<{793Bez5
zwwdTuj*}w5a6nD~rBvsFkYDNA3RHKP
zdd>`7S-miZpi+5NmU5(T&UBat2F);x%~qK9+uCV?TbRg46K%AZSh)Dn1GxUR6vS-y
zCiN@+g+aiN)GfzArho`Z)vj^L2Q;=y=L2cdK2sEA$n1nAV#7#?&n^`y7EuhgC}Q@T
zNN|eDMmgA-Mh$j{kgK4v^Kdj6Pb8*B7=n4l&^2KB3YpUl5`+FfwS1Ks4CqqC@r#|u
zZ35!#ujfwW(TJ=tiWGrfoPQ4n5kxSkVYgCpEDXZH3PO+tQN`}ogfVnPLuX_5DCjLa4X$_{xVV4`<-BAe
zXps>qL}Oo)+!pHv7Rx8!nBo!eG#`cW7v}6_f9em+WCX=8M_Z>NAD|CjnDdm+^Ec-D
zx;^!c$sYQ9FquphFl!D%NFFj_4vN5u6R5SI4-lb-ZPKX8$mFa7dVrB^066JtD40Ey
zIQ`-{Evq^g?;*=veHOtpSZ2;z$JHV!cpxh@?UTlS+|)$Z)|MnUW~-GAPMBW*!eCQO
zVe;D*Ba9Ald6(J)LqkcoAjz`o`J4ePnr?z6qJ>}_pcl2G6uxxrDvM{e8LX=HicWOw
zOoYkVDV1k5?Hq;@ia(e_1Y%pp7*^%LnWb&@1TkB*feJs{pBQ`U##C(+mN{2;8=}cD
zwhFZnxoFx2YYc5`1u)Cd*8?#Q?I9w@wqckJP$gnsEvgKt5EU0yu+lyRcjzCoC1F8=
zM8AlO#o#%k>cbpjfV3~$RQzyFXOtue1OHxQ=!+v=aHInNbEx1<%?C9-DvU=2&%p`<
z7Q4u(H`SY`ud{j;g^xz3Qlevi|EQhlPkm#~Q(h~vvj|9o^EarrnJ~CaZg?H2jJ(ai
zFqJa<@AcF-2HMLL!^}2
z1uC6B?xe~{m7r?a>82Kke^i>x9=sGo9Wn
zA+wepiN?IJorP2e;c3e;c{?VPmsJP~rwZZGtg^~<&)epJhg
zF9_5df356IVyAJ4urkr88bliUWFH&0KHBcF7AzyjH)MmOzEPT0%3*OWlonuBlxhZZ
z6fYQ6Fph{RHg0vIU?88W+RCW~yl5w~s)=ers9XgztcdB^?xvdPL{*VAtR6-Q`mwo9EIA88DXb0xxDXyJ
zRCC~Imt;6*Fg%-Z$|Tpo)qs1OV9$2_Rm6!3`tH2-1P)Tre^Sk|#x$@Ea~Q18ezidM
zmG}@zipjA6trh~Nj+-t}iXt4fVIr#^QI&e39!RzV8b%?wnsDk~FNAk=KGTy?Rnaz0
z(JF6c_DON-Tu<)P%zes_6mg@>vNgDux{Es*_lPWxqtXgl3uvb%NroXgH+M?BIdcD=
zHWRPY)(Qs&%si?^ML#jWsM0#g-j7&HzMzTQ!NO$sr!gafqw*Wps?Gq7A?Zj)xi!1P
zD6!~13#G6^Q{w$N!odiQ{BF>4
z$Oo3LOy)I$kvohOL(!%OZdU4HBdV3Xi7YVOSl-Di2LAtBEz7G3O=@ZVW9953{Fo;up1T^i?@E%owJ
zu=)o^^^y9GfdoW(rsDE#5^7MIcdfssK>GuXBxq^{F~
zc`4T$cyS!R(R@j<-OvdN3YGO!(8*jbm^YCOe}b550&V5Jr@UmHZ&1x^%KKIrO;vhG
z$m!*m6CMEx-l_f&p)k&Tw}_%^KS05_^aU%rhpCiUM?t`69&wW6^;`)n5(n4$!%|?F
zo0J2#nDGL}NuP_(0Ve{!%u=G7&nd(87Y
zn}_Ec<`RHr<}Uumz+)2P1JjxOLm0ME
zCOxq4kE+spg5+~#@KH-ZMD%b*W5h0fz|Fqgs8OY&S+W|Ldz0W
zBg4B`2(3x>tSr8hiiBMS0I~QMMLka-S0yxkTm`El%R_Jb0PKGkY<1%(y?Bc-T$-6y
zsm>&S6CAkn8avfk87CwiJe^_V8)hYItA1yg#>ydj!`K{_)zyMlFqs>
zVAv@7&Bj>w?C=cCEnf)M?`6&6R^_b3TwxC;3xp*YBGJKC`vH?(Wp*JV=O`)4&=s97
z<&oRj%76u<8ex8g$&%nQ>wICJP0`at&$rF$+zS(QxYEMcrP_1xwUl)OY|fjrub;aw
z9Ky<2hArxJZ&oZ0DzrYyTC!cYbyMc#2cHybRqeXWZH0j;{~8_ljrkP@@(y;4>h(qE
zlPy=(gG}0UUWE?9(CNsc=zEBpAhh1|K_IaI^t;7A!)cAC-CSot%A2IJ*wIkQMPo+@
z$hInv*T}3;SEljgI>!xjo!ThS*5{uX-4jO)>JQUc3XOqf#>ydA<{{nWTzDDA`Q4_Y
zvUt&ghgf{2w}1~!ow|kI?bvJ35vW6Q!BP7uF=mUEq)gb3x`hRmrLws3fUOd6(_vP1
zjc{jjwvIb1R>gJKO=$yZ>H#(ddYH3fT$C3I$e0FTKsZFYMl7EG9<*l`IkaoOmuNf|nSW;oZyu
zm?xJNgWhms*rh#@wWH0!f{JXmke`^d_57(X49qrN^V+D_fT_UZd13CSrbLl%%=x-M
z^@+hKKzcW(ve7E=bXq_cYWux+X%a=|Pj!BgGZ5Aj{&1S3ps!lpa4Hk`cD
ztYe^$_NEp^)-)E9#TyA17PjCMDDEHwL_vcJ2NjL4)a8*XI_6lafUV>+1pmY5a
zw>0QmAe-eWkj*F?*rWj3S$tChne8psZ4gbd3ZyLy1Tq$NeJ-5Naavd(i)k3Vo^P4K
z4U3f=Ynm^s@W5b4W$Db!)LNjqiCh4&kzFE+T#UN~*7sPw7RZ}j`Gu&tD;fw&FWO`m
zv-P4dy~D={wlP+1(%%3bBqsZWPBm2$Vjp_HL=TFD$2hQwa+?oqoL7td9`_40Pxyqf
zSDQ(6f>ONCePxN5&$ZBQ8>)(XNgjr|*v&vlY5Ehh+17sQ8?$2#Hb$`q08>4&27qh5
zV-0|Tn&q(uh&Sx%1RF5maNNNLhK?nEQ4f59G<5iUWUT_m&X&mourTC?A{yt(;jsl2
z$G~D_?=*WMCG}Ah9>+RN_Jld_lYH$=bfK0}<{*oOVns69ml!R@GP@cBT{Nt=
zt~0(Fbxav6H4Bjy_7zo;$Xie^N!Ep?%jHIuH4n~z<_|>OK`kE~JQe6x9ef8OJw?-+
zX@#tiqCB>Py;Asy**uu_^stIB&uLsOSlLcWe$qsn%P&=8Y$3B36j5BTfqz>Er*v!~RMw6&m$DPI~0$W}h^hhzLuCi`{h`vP`%Tza*a1%eM
zAzpB2MMis~iQ`l*cQapD;av=*Aj$DV(O(Kjr!K)uL0HqS$j>~SB`J_&*wo_sBH0X(
zU`>KaS2UQ<)KM;!QFgV!@`>TwVq|%{slXdU>3Q3K$u5ko@^+o);b5{W?bWwwn>PkL
zOxvhtkuTHsknXrm+hbHIwcE5kMs`h#rtLxR`8AZ@Zx~N>IeK@4@IHoZlu2w4!!}Ep
zU50HIYr72F4j;qz#+YH7Z@3KG_(p#iw%Lcvu&v6shjZb^#M`jV%AV)vk)4szu8m2W
z54$#|H6FV*<~<#|wu9TQeGs&34;G9$c5TArwrjJj+rzHS(tVd*o29HSyEgByg9$l4Q^rIFPs(y=3=
zdPOg{9dWQ2;4vf))@nS4L@$4F42i(hd<=`rPOI19KS?H^vN!gy%6N0-ohIB%<<1Ja$BYxgI+rYnt3<
zM3n|PW<(YSsmDmjG9L3bBLdUL-6AVe&CG}&H1_j(H-#ryOdMOZ8{g?1pRE>&#v#wr
zPRwx3N#6Lri{kS=yLcTc?=ra{kX--0FqP&aB)K=18v6^Qr+&ZQ!`fm%kVjhBXk$5H*SArm4()F)+p@<`+POGb+HL9T%E;TQ7ETbx$be5z)OL-{_I{Zy<9N-JXwsaZ&y%K71FALcGVu{x9%J$`1)
zQYcqQ8;Y*glO&<^Y3V5tVwmeJ^R}`%J3~Z)Koc$Ia#uc?_em{mQW43Pl
zE~W$3uuqG|DqqeInEY*#tV-x)x`*rrC`G{ZWgIC(^~yHPT4_E(!l=j>U(jS*4P)>V
zWlDkRA_{aOmwf^&WBnL-bw%-Q;Ke{|xLQEvH+OEyoT=I^
z0-dmtI*F+6bc@Kyuxu2ATtsfXE@4Z^$l+{pYzdiZqvMv45yIXrbQKaZ(_9(Js4cBz
zgWK1@^n!UrWagL5EhDpJ!DyF^+>FP$jEunlX=)E-dy1sR!T58^EW
zp%b;$EhDp&ZSO)R_?F8}#Mt#Y&hNPSrEMXZ$+5SLjCt*$Zy^~oKf;lc5A0&{je(pD
zxHITSax&pQFFBd1{$x%rCj+DHA~~5;UHg`k5hp%Fxddg5J0Cf@MI~(b?qXPYxCLc}
zf~Tv6t-lG%tc;g#K^YWNkDSaLZ+Z?TCx22YpR?@{g?}KRxg|ZV
z@DGMSXE|08{?T|x)XSqkklbAF;16UfC-bDkm&fvR?F4@So;h8?A1t4?V?O}Jo_6fV
zfi3o9Bld~JDD3ekX2*UUjAB1HP#AqJ_Jg-GTkNl5KN!iK%l7zks*+4i3fjRacjGSKaf6+S~DK}!76RJ@8FLE
zd+^7`oZ0yxJ=J!EYFOK)v@yzk+`%7+nH&~um@F~kC~b(B?3Q6Dr40eYD670%AY!tX
zt+er0d0R>;Z3vl6TV+FdWF1FkYYaB%m&(SQy?)gMjzWZziKUG{
zF?-+br@k;-Wn*}By;Zi2IZxRv|ApCK-%ovFj>>j0QrS4uscw}GaI!#3scgWMd}2QU
zw~@Eb#!Ko=!IILZjDfh7Ho)U(WLSR64qInyU3bo$7C2<*meD>*OneYViykjc>0q{4
z3bSVW8{>M>=X+S}(Qp@!^;T#8{Y_t(Yr}lJM;iv7l}EV
z<;(x6JnXvtpY#Lp@R$Gd!0!J%7+($Y_x=}Rujzi~6LXQ!2epudaHc*;e@{DQ)5DLqsLNS*fV;19y&BPo%+Y4x=r0k4!Njm>txsfp
zLgpY+ZC2tn6F_-i5rPqEMM1VYq;q(R<54Dfi}$5$tS6Ewh~5JCK)Z4Qk9cP?wt2Q!eI#SsS|W3CC1ccLh9#rD!O6WW-C1L5y^lm`Exglsr1)juwrk
z;K?qD1=tX{JdLj4ne0iIqnKcZA*XPaOwgQcO@vdHw0=lk!K5Ck3{zTIR>k#yEJ`qG
z1~)hMtctMQL#$TVd7+-XZGqP$Ge%S*63%&ml1~Fo9zClxXlGTm>3y`62srO?JNvlo
z%}hcV$IFN(bXU)5p}SFB0K&9Q3(1uyt22vT@_r(>z;#(ln&_+%;xHoj*el1d9AhS}
z)Tz@H)%Exdc@a9R?eY%z6S2sZnI~dEcgo+!368UstHmVQF^~`T0F+27GN?+O#$2|b
z986S8>MSSP*r&$jd2TZvm54~KL$6g4h|c`P^0FcjxFtA`Qv`xh(v~iwDiDawW(%tV
zf!OZekF5?7(SZ`$-f3{+#dNjEOzrV15C~tc7M7?g5C~wNrW#@vc$fAm0ewTPEKp;+>+k97m0H(*bO-G1wk4?koAess&?E(-$R1?I=
zLlFT`#GO$9;=o=2;$XZ0#Ku?w2*6ZjtpEfg@9+8#yw^O6zaV`TFpI)j{Raf|J2Ox^
zI%c9gbW31@F$mOu;N9mzN*wAxd~!7yg3fmF`VU-#6t`K7)SOTK2PCCi!oOhTXWv_NU&c`_p~X}Hbq
z6o3Gem`R<0Kcw^KNV!&`xJ|HACA
z@25U7$JTH#vNaIy$JWq!NBeDS0A`M|Z4Dh4lI3G-09?myYXD~EV{5h5Nscl{@x*{e`X#1cs2~f;6ekfcUv-K;M0skAbHLj2MP~|e*rE__!GyndkFU-X*
zKi;Dq1FmQOOJ-DTgtB8ggE*C)f@6l2cxBX9b__BNWC6xCAGl?Z2_UPQ
zyJeVfFi%!4vJ0Ssx&?q$oMX8hGmO1%b30}jdu{a&aUwF_+k>@f(Ln5VDA_$T49&J0
z6*l{eA7n|C*e}lv
z3nW{T3k&V%%uo~eyYM!Tda6O-iNNbQcMB9g^EC3NQq>mREXNF1JenTE+h3Sy6SrgL
z!0wpYm@_#~%6nF+{fJMByd)}qmZ|+{_3uA1t3>P-*JPNhDD79I(|0tKm8ng<`|eKq
zG0ZtHW6D#7RKGF0mjswZdHoyXp$~kjxryx)Q|;oE^VApSB%XZqS&1j9kkvU7hLbQp
zZx@ZJTd?OYyP0}?oADAsg{jFR?`1br8=g>UbvIK}T_dl%nUI5fVxbnCSsUPl7AIa9
zb+xEU6!p5Bi5IF}7MF#wXkx3onQGx1yzb_Pciqj6vAUapN8e@_zR?aPE4+!XLfi1d
zn}97YfrU3y?Q#_C!kdY%-)(kTFym8q;Z2N_DJr}2W@^z(bF%VgqJFvUE(?a+e@4rH?{Z>G_8UhUGGz%cvQN^b(5DtgJ%n`x-P@+pg%2J^3X;mkC3
zM0#P(G%a&zm)=ZZ&*g5RbN#$Qm8Gw5K&(=wMMQ(AsbkkmZ)WV*`npPQ=Afbcv*_8b{76ok%nClq=5(~Wn;WxJ6mlpk)%l6J>TWv5>uv(3x7X@!W@tIDtL$bD
z$%|aF?q-H2HeS2#Cg?>~F_i?0Zu4qRmfZw7f_HjRO%iOr%WkGA`r0iC}#5?_6^e>
zEL}Z&nP^K_&vfIzu5@(_yes>U>FSuODt8Xk)j5@~D_cDylF8C+AwuPtl<#io>N)Dj
zKI!V2VL-2)t`4{=u$1ZQ8{X;a8)NC}nYX>YcDj02J@6}C9T>AnQ9?zps)@+p3z;^{
z*OjnNs;Ng}C5_l!8e@n?tY~WXap*D>Pgn+dZI`7p(3pf}tYaI=ZdU7Of4K((B4s2f;{M
zW4b!|SqfC#&8oqk&HN>=p9xn#;Qzkggi_5Yu_c%CxrU4bR(RdLy5rgmot+yj=GWLlu=
zjK44_TrCS*QJp#6bG;_6G!kfKn9U-e(jh@_c+Fhty7>CEKzSs*fP!y9mbTz1!$E=4
zjaMizaKThUYGIz~0x7E3te7}Hz$z~l<+4HKfRUyLdtOZ!oLyvaj7c(9~gV;
z#<0u?2coayUcd!XFv0cRM)nxFF7OT-X#|r3jN2X8Xj$yhVLZ?nMtQYB=@@`8-Y<|9
z>G6f4?atMR>;tPhmxge)1sj6_jLEf`;1dYMTo{Eyo)yl#obte|cl>im;F_2RA=%|q
zffk60e49q30^;VV+ck7Z|8w0V^|Q1kpa`ngNaprjl#obA%aATf>fx=wHRC}8UhVuduI2a-?i?^1dJ-FpsM(<(FxKi
zL02tl)~rLB_i#OFliC&r0j7kw*P2DI5GFU~R~TIDjvFpgw)bXkF5Hc+?iMiRTMh)5YQxDD+Us**QeUu}
zL1>T`c?*5yf=BK)mL#cgX%+65hAB&wHvk5)0qo%?nYv>UthFvJ2X9;1+FA7}hJ&H#--VK8g+FA}n1y=a|AEZo=Td=sIsUjI8=t
zdD~LQWUJjAlyVHsIJggdWl9oZ)Yl65U)sKzFZx~hv1R2cD*BoTu`
zZe^G_8Li^RIgn;zO7FIE?PAS|&W4+Jr+)uD{Ab$UunbWrK@FM*-i*sGOkQ)D?E|!*
zMu{Elv1#U9^S+sXFXWR3W_LUo0v9iLp7f4D
zaRO^Uxg~k)B3=}R&Tq{ClRdbrdGTXr={znl@6^nj2MiUMsaZ$Gku8A1Qo=$&^2~G)
z@RcFGJ~3QCXAgGgz*6$GHWhE6CLvn
zyr|a6xRBe-Iz&OZC_O3vg%oDu#HhwiaA`I%DH)-oZU7i-?iUQNR`Dl@SY#1B%2T-w4s+O<`{J~y6uD?t7@D}=2zTQr;11%;EU!i8
zS=q;`gJf#lnfD?a2Z|c!h|Z%rXNvZs4G&(=`}4J+CSlfnpqT#RnB@08FH9rB$8PMl
zYK!cz#|hpN%;xXGNHK{tI()i6<@mk_(jLaxLcb-wV@NB!Dx*U7zJ>!hAHYRkrzmtRxRK
z7eYZgb%X49mImp+vw9&P=S=bPSZ+8O!7vqF@=I5X!S#iGhRoGr-M(#8W0D*UPI`m1
z+DaydZ|Dp(f>6=EEqv%uu2tW9;SjSwdf{Lg)6ok@
z^ZrOLd{U-liO$m#C+eyL;Z9~1ShP)TJK8_-k`w5R0ViARfyLowP
zkn}usyB2;Id+gIXDbq$48}Yk_ISjvUI_C}l=zeNyU%Q3zyJ45u1s0s7Dr5IkC*Sv6
z1i(d$LVF(Im?VLpyU@8T*)9bQQR-S^v5Nx-KNcKworcdhDgWfW
zx^I?&p|0}(=$_-GBRM4A4&1cGtKI78Fl0=-OIetlcufXC+F+HvRw6)Ia1lOOFfZ#CehFrGK+{z$4AwdDF#GQurZC2bZZ`1UYIMc9)!!@~M6X?s{0Nh5K^JS+&tg1F%xmgc98c~~~QJuHqnY^v$*pFc3i
z!?H2*uwWQXA}C!fr~%YYMbZ26@8$`*p=3{Bd*3~Is
zJ{GLS(1z5_nN^y;`&d{7YrHNW3ot=eIQm%j`kIer!|r2o#5FZfLNcB{Nzg}vzU`Jnk@|2~R96Q$uC4eb`C>7p%1
zl!m{R<{J~GH@rn@$G9lXH?$*4;~Vk8mA+AGa*c
zM)j7Zf#I=XvNT_NL}`BYlB5~oa|G#j+$B1cW^fbfrjFqUom!0U=4P~
zK@%<-+uX6O9orMzwr$(a#1l+xOf<2r*|BX~6HiXQ`<-*{Jm2M>RR%>2-nEEb;5x2X6Ynvu$B5=Ru7^V6V`nD6wMUTHHLSF;hf_^{$mIC427uk2+j!-J
z^*LYyiSpjzRP&VTZJjmwllUOc>woWh+%OAFuq`t8J75|mJVnqdDZ9mm5o)cCW70V|
z)O7V*%r*o7v_05{ja$F5z2EV*=txirvL5v#9#}6gi$+p>k)~B1w_QXkQku{eLCl7I
zu3@LGHIOoNrZt{s(snJ>vDzk&Le*Wc>(QUEt~V!Tk%MJW;TS;TO|=IT5DhX(+#`(M
zyP-Pqb9#%Lf9E^(UMb)#e)q7y;aaJUhJmt92IuK|Fv7#*F01ci*(Tj5kQKN=>?Wiq
zB}bU$*rOYj*UCmU^Y
zT3$9n_W4lQ}8qrafFOTlquGNagvCH=Yn=#B|hbvu_LZX!W({CyD?2Y}ivF^r-7(k~S=W`${E
zRS4?!uGU}c3N6Vfgf-qxolaqj>1j^doRgO^q;9IqM~O}$9kXrYTM(@d761CwZ?ujc
z8cV*{D3w;H$}rZhUfJS67Ml_U{;FXYy{e_PsaVUs5FA?~N=KOQ)HjDqi5>yZZb?a|
z0u5xXC*-LcnMf;}vMK~BRWyyLd&Baz@;EhKA{fe~H*cXJ$vD1ZYWR*V#8$7%@V*t1
z@0+z8CJWF?k=XRItEU?pGAsU&{{A|{)hhj&G@_Y{N@TU4S3yzBiHG`heG4__?qI~%
z4Rbo|Ez7@#%^TUESwiYhjOr;uu65=jgplklZ_FZZ==d#)KZ|TWL9x~H;2_`e`|04p
zHQZ}+J*lVdjjVAO^BVGA@fqzsY6S=?eZ~|R2D3DBqhu}v6Vgh6R<_8}cw%(XffU7T
zWzhpRUmAac|6o!mBB2vX;0Qu%q!B{#UwOGV0_fk9IarwS%tI9?(p&6P)P37a-Lw=O
zYQp26Q0^*6>`hs841-LOEwM~!+uK>thNVv+%FD0sCB#$IXMgNt3Yv^
z4&kif-CD(61Ff(D5ZZE_H_7@SO2Rspl#p+-!S1MckpN2@5bo2;=+5gG*?Ig!FOUal
zzPnwH;GbU1Y4o>*A!c=q_UNBD!8CNz3
zgN!fUyIB`&uja9PnxgMw8;6SEu<$R)n<>Q=i9wQ-%~N*PF_nO)opf<`-60dyZ|g+j
z;o5^e#jBvgE?mScj>AlG*f^2jqn^~TAR;@Aa!%zq>!oSW&CMD*Z^JT&Q
z4zSWbOa=tC=wm6U5{T5b%*j;AKLRD6eIleF
zMuPBHxW#yiii-t$c4)zDOA$=O!`Rk-reL&W0a7bq;SPY`C1_n-goJTDkh`L0y(FpN
z5h7YbBj0@IKqN5!v9ji#i2GpJoR#{VaE~eU14V8x*GGaMT;jX4n*rNlMF}F83#t-N
znOg21K`0?p8!GrV;H#-xgFRHiI~(h_IpRa3Bp$bkC9z!gxo8>tAtcIJ=I@Ic<_!-o
zS9ou)y)KAB;8zui+bmm!H$rUcj19Ml4kW)U=u%k*&kMSMff7Ai-&ATJ
zk3M;gi$_)g{|%xvow{wzRh{5>2N%V*zIBONJU>5%xwwpu_^JG8#%!4zFyQ#L2eA1y7Bnt_hCkXN^D|v
zGsWL6luLnQp1X<_Yni{t$pn80v+{eJf(~5#>eo>ZHol+W-v<9C-==4GL`3R2ZHOY<
zHrRu^5<@!VO5ST3@@?*e4j{W+fj1cap>zQi)LMcuthj^xTkmN047rDOFeZJ+A?{^J
zwcJ7IlX@GeS_xqmt!p?Do!lc^2aH&kr1hRt!0Q|h=_?N!iXfGzvc
zI0^D#9DMsbD6XC3Qa|(8k*qgvyae;_p<_|jTKNRxcWYNeKa0CaW_S&o*}oy^BR{_&
zOBjkyB9-($5Ogcv`Ot=xRqB{p0-WtM%1!2FU*Mq3d~leh6&3rZdUSdA0A}o<1oXT0
zqe{QADN|OOikjk`^X20;zg!?j8#q>(0*@
z>-YaDQL{tWlAMLW!Mo-YSXbkv>p=(EH)F9Ut?ohX8KdH4lo^8s*DCWZl1S|QL?r1w0KmI5Ybd;5&#O0$g_aR!RdmF*0c$2DWF=Ysd|hcbR}F1e_f_NBo&?k=4Uv!OZk
zFng0l^V2q>Kk-T<^JIi;8%gEjo=6`+kCjjHo~({oGlx7wGAk#FBjWp`Q*73Xftd2b>dO@~Pb=(GY^)IiH+(usU_Z~rE_a6R(
z7@`Sv#h5OHQ~DmTHSCTggO(RUlAoJp#=?%NO*);^MZZ1sEsifq&I=Mo@L4{Z_enD}
zhw+45(E18mB1T2!!=1H}NcKpn<&+Z`&`kGwRD0mB|yxRsoj+2Itdj}u#
zC&u
ztnU8(Z1y0sN!jmm{mdsRn=s8#1)?TJ8u-lw|~62y@H{2f|V7k*be%mb`1ig{8t_3o%M1p
zVXWgvUra@1EZ@Q+#I?!BP$AvR(5Ri~R{TScud_d2+J7Y>w)_sKUh$7ms13Lbc2r4a
ze&0~Kx%Qnkyei-6x!KhjWkB{(KmMWhD&WyI*Zc9OH(=&p^>(IHoqIL?g5RbZY*;u1
zA0THF>>s3CXsIrD?I(d-5cJf5f4))XzRn9VY5)_X*1RdiT>plahlI@sq+3*Y59;U0
zh7nl?q2!?xi0EM1n?pLy;#Zw0AGN>Z?}!Ou;01l6pLB+8!%8&^h^TM5bxI@3iTw}o
zehul=H*k@)H+mw!gR_M2{>ezAG%$JQ$?sq90Oj=lkAm|*l!R0Z=p%we&+ao%$TCB`#Me@MV(
znU7Icje|faT_FIf(I5UkH5XJSfS|yAvnHIomBgp))s(Z3b3im0+5Y%6g#erKn1R6yto^3q{fCH`0t;%Ft~uUjnW_zqkgDXd-V38u?Ruso+V#`PP<&RMm6P-;kPJ1+Z^9NgNYZiU%U
z+)a02dNzp0A{;z>3xOEv^1ukAb=pQQ;D`
zU&v)`bLE;a$T6_Up`}@&@F+u`te4Cw{Vg@$J^l0grc6|-I!fkD@!mHK*Qb0}_ZDx~
zXH9d$*bC;*r&u#9tdky(M1Y5ESBCMF+0JIRgzfs
z%_XxQ@Vm{Vo*K7!!rja%?A><3y5yCJyVuZ*-om7EYQK|Fl(7T
z7eZ#z$<$^-YI}Cv6_TA4Al5YlVu}}iPZdPv8Ic^IcfoRFgnW0v6!xcRilg%CLDIhCr-(aeK@Z%)429Uw9h@9-0aoLA
zl4{jbjAosLROaLn4#XMic}7*UY`h~2OU8_r=$GrFVW&_$hHT}$QliY>l{KNDqV=_j
z;@7?`MznmOB4XqbpQ9UR!2i5hRH(k#R{v057}jt)fka
zJkPKc84l7B10az&&)5&aHr8fs=pn{Yz?_XANk1Z{KiFjYVe*EQ8T(i2VYgGTOCT_#R$B0~RF9M;#ODu4%zYE40`vYR
zFkV<`809YVT8Py{zDw$U9X%nhx*W~f$g=e1kCsQIv<7Y6g!^g9sv6z=OorE;zaBvB
z-PjaEvt47@=PCP;akjTfI-{FeIYvJ(V8)xTQ;cs+1u+!Nq%X2Zf02_V3$7|=wx9;S
zYh?;a>wyZC7A8w=XC+!M;VjBt-e@gKoh`gDdH+QF?9fNdP7+S}CEN^|K5!e(G`psX
z;T||uJr-dSg{2Gv;1?TnaXs9k5a%PG5luwe20e=bttAYY+exp5Wu+TL2;g3+*AJR5
zp2;818iXK@Djs`d(t+~jEM%nTgr-IouS1z}58F>~HW+d09;KYLuy_uK7ki9uPYCjcg^zp;YiXcF)bDTN4ToJE2+SxL;6_3Z<%#owK%q0iqU37J<*90=
z3h^nyn8vb%`{sf;c?Dq)h`QfM8%ENo>Bekd)l
z+8~E|^~A8&9AL(^QAuCUm1H+~8ZhbmhY};^`qXiy`;4J_cu9$v-`QgU+=8D{LG)t^Qu
z-v&iZoeq4Ez;hFDT)`P9hqJBQfYe$ig~ujOKU{_rNwOeZAOoKb+&`8GUqb{S6$?Gx
z;3JM-$HFL{PPdNF18o9t9sc58LJ@0In4Yjyeo*h1wW*$(2Jk*itoLoqOJ
z1r?N1GX~BXvT;frK@dN9_1~%A`tG3Q@a85x{O4eOdq%U>sO@{LhncwNBDv%jq-rv1ie=sE#g{PNNcQsJ3m9bOU-pG8wlHSAh~#dg35y-}$eLKNC!HC9mY3sY
zp={c7YV}0hBLGOfCx33TIXV8AiztyI8sE=RQf2WVwL>YbI6T-e`3X*yJqXUbG4Q_y}_SMVci)FW`lv4_%Y))z7jDK`TYdSU9!tKi>8|d!;h*|
z;mnbDJ_~QoI`4EPu-~NHHu24eO>teuo4&JL)E$OXiz|ktcU*2+TQn`bg{i2lWqPf$
zOI@8-E@jkV-8ZJe#kOauOkyc42h*P@d)7-QKNEaD#h|Ef%Mj=jN*#O6`$PYEvC^y5
zJ{`r8f^B^?QmVK@y6}y4|txq6{{S(p1^s
z*W5`(pf`&qdp4dSKy;iZ>aWA`n^e2GW>nu0n+=AW2|OtY49^65@f16+94*sHqGuE5
z8`~|q#g3-Dedd{Fit+#4Bhz|Vy%we5CfrkzU<-^MZLeD(BR-a#M{O{BM?>92{V6V>
zT}?r_=OQrAH!S`G=NKy|ltl4%#$lg#m|ZUChMkWob}w&l)o2Tw%Z6kZOX>I2HC^D}
zqDb*B`MNvtt~=H(iKWOkD^Hozmk7A1X9Y~Yp{6>+s1;yfbXGkP3hQ0`@;Tb{!9O8~
zD%plDb_B?-E|gosjzeCh8n?;vj7N30K{7)&f+;dXowTEE=2bN8D)0#>
zCb#!VnDy8Yo+wkz_
z42vA`W0$%ys5Rcdh7?y14H*hm{+>K7RdiT=ZZMc=Q*6_$*miIGQ7PJw`cWCnwm->A
zJcdtoV|4O<|MDAneZR#3PW_nI|-w%&tn@vSwYp~GLi
zZpF)qSk>9e$*HFPN`tHx*LKgz3ki~EKHsh@?0jIYoub2E>>hLueRrH7fiKcmkspTXTgsJ7kZPu#gSq0r@-5Zb+s8P4NtQ!lke?n1Rq
zDY58Jyjp5KvsJQEgah=UEZOuJVB69OY}#Hi+#Vy%#wbNJd$EM;3LE2xob8?Su!EBx
zE^0jK6w=&BIGAaYemXM<%yjPL`6t*OWIotlSOb`;q)fCrLr&hHAxXX;>nN+egqHfG
z-zlFw_>c}db3TCx$cKd=b%Q)3@x>dgLG#XSKg!J_r}sN7n()m#Jopf*fHXEu@N<9t
zRWB?WCb23!x`@9CDrpY@8V!@0h%PvD+d736Cj$bM;VY7_X2E&%W$CtHnQmdX4MH0|
z4@=qlxJ5Hfkxn2R(x*p!G$vuba+u-w2zlKLM!JeoVkF+D81PGBzk>5o%Sy!Wvse-U
zi0dBIutEap~
zlP)n1Drjm<{~p6tf8r7_NmTXRbHr$%@z2y#DT$1C3I#p`gG0Cf+jv>-i
z?xPt(xmP0d%p|Z=6hMzF>U6vSDy0p~0r-*HwpMl_^Hz4lR4#y9ZP>~qE4x)F=49Rg
zGg^cclN;wt1g6E7V4}@2lPT{jOnycfJZvJp;(`;}W)6WuFuORSqe`Y&X7!tT#eYIo
zsJvmU8kW$3<1myW5g}Y`
z_CHbn62qB+K9nlp_dd`ntXR~9=Fsuar1W|B`F?2FO)o}8rj%M2RP-?GN`@-CH`v&T
zE-I`kY4W((gDcP2*c5V^Z54o6Yk?xu8(U#%g!gNN6jMNyhYTy$5GExw<0v{MG`-~_
zDXe8m@2+fY9F_woZ#nc`C1(HrF@)S{xgI?E
zDRxkyBq{|3p0a(
z@gS0@Dsaw`%$Gu5Du5U)&H-vVbeY}Xg0$j12r-QP7TysOeNoz)JUsD&_KGqz32M%Rh&*%Hq+5t%m0Fe{p?Gl|I_Kt
zkX`^}XJp!cDaSz7F)OX-Mb0gTm9*kXzlR4{&SF@8=fhDW14$}|DH?&oyyz33<)8=%
ze}6)k$&iN+#JL}eIzcN&zR%YTN0OyLz8A7`
z*>}IG-}zI4h?yxDk&VtB{;
zsF@2FxRMc|R=)b=EN0R)dB!#U(~1(!UmltBVaPZ@unP=YPo;seL0_2O1*y0~w6c&~
zr6$GFEZp-SClk?3M3I|7Lc%Gfw5foOiXZuB=HQhV?bm6Uq
zI+)~`8eJe3oT*-Q(wcV^>A$mVC?0o
z;g9;vyDP7eOrtQI;c41MSHwfch8DEG8j(QeBL7A$D3ZEpV%SyNzxzw3@?h-Y_-`W4
zj;%>QE~JpoGt|AYl`s`XOIoyp@XAt!`5gcBf-Bc$F~YPiri^U_Ilc^&99xjW?1=g9
z{SYHD<6vlJ_!_HyuKMv$-mU_qb9&N@$Tt@2>>sDQC`<-iW529@i`n8Z`H64iI$VYw
zy*y2oL#>LS!+7gufb?6+S=luZBP26gr{^M>$75Gx;9*v`uHF3LcQLZb56fqG55+~v
zp|mIfM@Nod&5jvcDJK@jB~Gdz5Y5Jo`-u?Jol=o~_8B;N)*ar11epzni$+)q{$=#U
zSX63egY85S!>P3Cw&8*UJEl9y^O3T@Yd|m1U34l4ZoIc~6S`}CY1z$(3bx??EYSH|
zYE{^hXTcP4;e6=l^K9X)$>Ri*%2J|+Oez;UXBSl1U_!9^Kt+iy
zg+9{JF_tSX#8I3IZ{WEH0z2gREnARr+U0raO&PX$*NGvmfAWC+^DO~p(XdAWFr1T#
z#!Tfyj9}Je{CdOTOl>7V|Xdl&;VuQLlD7De;y^U1=5@JY}>jKRr3+XXg
ztMtUQH`m+W8KKH2iMyYLGMNq4qmAF#8a~xcqtvcG7KS;2gYx+ndO4*@F1d)Ed0xQ@$3CyaAX$)Ceg|lcH5x;S{6IXsY~&gwbBdx39f`dt)l2{mvvE=ZF+_6aJncjyRPM`D!fQSID!h$M9&iugbOfrRsQvv83By{Vsx#G
z9CtdoLYp@&=Zf;#HH9V*hmX6b7ATekY|hnrnauIHmKSCKVPNhJWag@?|4x-uCA8X4
zXXX1A+$x6aJf3GSOjJ6FVzEl~M8b}E&VEA|P{#yM8FQ_sOQ4F$loJFs`e`qr0Fh+g
zLd}#7g3e=@)e?JbyI7UrJs8N?wJ()Jh1Y4}9L3H@-5+Yb<&ZjL8;nmnEgm6>DRXRM
z$N4zbs0mb+6Rc!;n{FlBDk;T|`N%coKYEn+f_)1n(%B{h>O+8>7#F!sG)BwA1vY&6
zW1`@46ckZC#ya=!BC>{ijf|U}3d1KcI7@{A|3WvPMLO&$a{(B(f#fNn9k1ixhj>e$
zz5aS1sT5Lk#3}AS-?E{D(90Y_`+TX-ie``g0~+qa@~iku>|eZE<3=XB+;6^iG^wXO
z9&lU^zV5{=N6K>|q@Adm
z$=Kg`={MZR`V$&GHLxaLI@PH0{>fHVA^?P{m3$Tt7hWdA(Qlx>{&Bro={cj`tuzzgQN}&N5nNmZ4&CQ4>Hj$ZPgfG(;43O!TJ%i`ws=h7x$n4b*cHveR=*v
zBVTY9r!G-N*=*fxh$+D%J`wG(i$lC{RcT}BY{QRlDFj5ce$QNdEm&n{?iXaOy?8|H
z=6jrcoG-}c2t`VtA}Z@|3vO>LurP^dE}eEz>B<
zINp5(OIp7zpt_tky-8;s;^mFDd1#Q7urxzmKg@PoSk0}<(3n9*q4o%|%7w*7aK_EI
z^eBh%(a%1{718!m`&rQW=ohsqR4($o$=`@kQyRN}1Hg*kqcn|#T+x~oj2`gZj#Z!^
z)%KV?g~_aW8mIAM;WqEnv~pbilo+B`R=Gh-=*H|d)%~wSb+K`!l}ti~e!53)>wA_i
zb7YahrhtcA`*&fRy9wO~LxtcAS{&*3Ft)bFOryS^D3c9-sc#
zVYksE>J(klHaj&Z~uZ6
zU4DeIer-mg#$pA^W1-olC&2+m-wZsSO>-mhlTX^2m
z&8=x!edND^SFRE5-KZTW=WA~$Mt<9@CN72#R;pmjT+6V16WsfqJAus7$-c?8X0;q<
zp6`KX2Sz|7w^0)fhw<~GD^0NZ7LLyeSmjxRMJm80JitZ*bXTs2fR{62$x!rrIF_U)
zI(Skdf*0qC_DzZ?oy1i$mdMrWCTyaUdqAPwqJblP(ECDNz}j+0v97W&;e>v?FF|0O
zS5u8biOR`3!}5SZB50tN{pNdB`h_Pjh~?;NWBHWsuG}IR6U^g+sVDav`qqk4`$KK<+JPIkH!
zDs^%qmg3l(SUVu{{p5r`;0?XFxZ2%?_s4B%b=deKMC@5`B+WqlDcBUjikJ3)5^A$UIeSB#ax!tiM=P
zpW&)5oJ;G#H=AT+(6|usIt6weLb`AT7l_JF5}NthG5G0d>SzTV9Qn
zIx;#B4MNIeww!1^Kjpi*b>}_u?Ld*tV-Du`?$9>dIXs0ZJK8^k;92tUAmiT#gtT{P
zM-=py^zA4#`*qa2_Rl^JPpjXLOpQOfyS#*zSJPfSd3T`M=^5rR16h45C+DFNfJ*IE
zPf2gkO1N}B21>X)UnwtW!28gr?ASSm_!*ji-Zwh!0eo;v{(ur*-fbA2jv&j}IUd0B
zy>SbPwsUt&cl5&l2NtJdu#KeYAi<5B!3oQa+a|TPJPGYB$*nc(O2oaqO2-0sbmQV4
za9Il9V9@&x3A^tyjY|Egoz~cPIS0-(8$CL4Qs
zgRm>TGt%&1bxpOR`8~J&Je@$3Wz47dzM5~II?JX5KIV=$MN&tRw3WVldHJPEj?)$l
zlA)4ldzS9hWWB^44H80bZy;r&vORq2lSMz(U#|)9U3&_EIY9cFD|tSPSn{+k#xOr~
z3h$tuFwI>SLyGQ-W*WD^ZF)&bpoma!;Oob|;vE)aK7V!l)|gf8ND3c&1xl6HSNKLN
z6#1wlse#pAL5q1~j~t+|3$$Rz2)
zRQJdv3*%a@$!aU*NLn@}H{&up3nuWmy+SNlj=HR#`vN10cC9j5#-5P&5p9OpkwCS_
zXlBuXCX&6g><`|d%p<@Pni<|}0>**ZBnB$$-1S#uB~sAf-2gNLHH$OLTu)RRPMku$
zIFk3HcQldPcgAyrcSx7-H@F%%aArLg5fuJtp5g7J=fozAQU<$ldK&SamF>}L=kbk+
z;_y;{Y8Bh(&Vk)`Br`f$fq_gLrzbcw93+HR3jZCqaH4&wwkqgD-ofW^iJ~>UBhov;
zL4aA$kBQ7dkG~%cd)N%`f~V4JWFz=G2WFmC{4f-#4Rwtqdrw^6-Ow3Xv0qh(<(yH%
z&kq))rbQbGyhvcIi&bLJ@ISZSl~loz`bKlvZk5^^bL`XhZpA(ls_gP*%-B!^#sttE
zERI46lGMA7W2gzJLZi1#N}ho|EoYONovhiyD{Hk>L4&vc?b~J#tjBXx3y5Ue#LzJb
zyNp0nBE64vzy$K=;TU_Ju7-!8WU8sAhDnh6@MwgIi1tyQ$v~E$Q&D=S=zHJsQ7LfO
zkzql_hi(Y#i)+^6pq2zPd_}IzYNB3CH&(TL^2R8`fWV!tWE~nH4CKBJD1y^8jIGkw
zmX`nR3K3Toaad}uas1+KI1wSpa%jxRBH>iuMNC`zED4g^C1s?yuU?R(`N0#u=<%Ic
z+9~ZvYc_B3%Rwp7&7~v3wz5|5Sk#AZqHRe>eU>;($xwDkd%$5Sy>V3_+{_Tc?SZaB
zfHflX*PjfVIHt0tto4nYCa-DvT@X{aR(Z=buHNO_FFd-pr+=GIMwN8(GYi<|xwmAn
z$rfeKtM(#%ge({ur33&O*8&E13Dn2wNqLpX+N-&$WBWhF_2bpIi__zByA`^|o#OGs
zC!(E#+YhV~BF8bz$DMbo>O7);)m>PLYa7H7<%Cpm9AYh-&)Mk>h9`)YtW~q{uJ);>
zjlW~Go>5EI$=M@rG92STSeCccxi}VO0-uZJOzejthn){hdV<0JhW#wZ*X#H1nOUl>
z1H6isvJ$c3Tv=Ik!BO^Mg(ig&$xcnIa4xq;=FjefNhw
z{Ih&aUGBUzmu6Aq6#chNRx=A#
zy^5Lhiklj>9?Shv`GfOpSHw?xu4$at}~yj@TJc
zd`cY+`|9Zc3u9DnQlDw7{T7#EE5ePz64BJ}_fI*j3x2$%Eq
zUX}#h245Y``pGL+cD_M}P?hf#zhSzn1!qcu#7m9n5p#?Xad_GC_;oXx2S#Lx|C
z2deL`nf?&U`%%Oy`&-#C_V4Gu4V~2+6N>~$bPC~*T)!BT!99?rl#OgCMYX)V5FMS|)u|bX;hstTA2Fuu*Pft^J69Mj_CJi#bCM~R?2CK_t;`>MqmcQHhpY&Wa
zPCBNHbX5y`KUD<0>X>g0+7Mc%_F19Xzui}T^D-HSuXX6?cMAElO&bZK
zf=Gs=Kq2;ia#;a?zA6TKLc0t=UDcHVY=DA+#rHn2t|e>$lZ;z0L~-e9h$t4|dp134
zEtHtJQ6@2zcO{rl7E_)Ve+}!h?t~DSe)S66heIx~9H2J1iVP
zUsq$11>P|;1Mr_l(HBiile0N=#!zENoH4Yok;!aQo{zc2?{C~cu!FmsLcT<8<}cB%
zw{fpeN|P{tJhn_MM@n;tfLM9AckDG1KF+c*n3^%WsJFI;v@%>oALM$>z@UrYk?gJ$
zV$pa8mxf&sN4&?1zoyVd&V@h05((SL(;bI!@w3z}v!ZWnD)5^`SV&i0g|*MiWok@p
zoIRk5bBd1Wv=DC(>(%}UytMiUrI|d{pxlzb%1~L}l^Qrd}mOV?S8vz-?!qME#
z-POXx0r^XEGPOnKVJ8KWehC5sEaI+C&SFm9dcdz4E><>DZeBJ67G)Dx3rBZSHX!HM
ztSXDRlcW3Bvl}VTf1g#I+)dmqNP#R07Uni4|37P03pXbZS2K$*eUAUfUfsvp;>)L%
zg^Uu|LI!U)yYiF!d;I=`I{t*x`nqpi;TmUp}4{S$Mioze3|O;
zaQ(+SDG&F52cG{9y#E;t{`Wfn(fRK>@)nL(?$)HNLPGyD83_N^)cnWW|6#xm{C_Q2
znSnqc+kaL9lKwB5`zvW|KvFY@|Es(I=>DJXcsMy&ByH^7EnM|jB<;Tv`OU)2$=u@W
z3;$PK-fQW)a&G%0=sm|;^{$~+C9J{y^Fk$U48OEw2pP)u)E&|wo5H2FN!y@*~t;e+!UUyg}_|NnvBn%x~ls;
zq{7wm$@6RVipzP@id%moaSD9#cJu4aWWf;*>c}-RFZ2p}yWeL17w~y}EksH2lNLdN
z5abVz0VN>Z*7d~euvP$f7n^9}h-5|4M&i|8
zUTjqYdg?=3nb$pZ9t~za)&n#i7F%3+4yly@iNc)-zsB9bUDx%MS-ybST!FoCYEE(@
zYZ~p$IVS%9RsxPHJ=7irVKA@HYYj3``fBSK7~2=f#2|jrw0i+csmlmv4u28;Gyaga
zw2pQZioae12g4`H?CCtps#8n<#ZTO3D>Vi*l>DM@H<9N+lt(H0u;^U9sWng&G#ZMb
z!8+@~a@bB|5^YR=oT#E}$DVCRqAuV@3U#}wwcF$|9=W+{Q)?P7yNF^ZhMxy9z(=hx
zWFLj{30m^;5sPr~2u{i4=ezkXrzi9;omX98rPulUu1<)vz02B|1#GX-**vci817@H
zXV*G;O@C0m-k~iW5i1vix8C`_b*-bF0MXwa%AAPI3uVOn`Fx?zt-bAF-2G@6K^Obl
zZ66?W9j$%fyd
z3nTjavID)Bo~LHpA3wD3)jb8rB~_kCxsgBAX&HT|rMJ|$JP@GWCNvjxK@GoF6pmdm
zZ5P%xh6ggx23)a8en=l+^ctEE6IjNtDTx@c5
z)z|rUsikBAePcS`lYhr79a}epxj2F9kN0_=Ug3u(#BEirCK$&_zF`BrQo0htF19cJ
zq7U`gKBI;^WaHl1S{OArIY)!tZ?cdkt5F_RTOI%OEi!
zw_Cpn7fHZ19e@NeplBRv4r%apK2{&Qnp&}{@2&eEgA^7c>oj>l;GA)CSlP%N)PN)P
zU(%732uiuGn?#&JKMVD+SAW)NE%9lZEM@Ld)!K8*jn!y<70d`CHC{YLUKXgg8r~5h
z&O*@|b$yFmaM?td#y3Ix(cz%JfdJnY%c@$wI$CB~?FxbJ?ROFXw-
z?AYrsp=yF%;&Y;*)u^#wrV{-DC7h{e=d;Sn91?Lc1|aF(dgr=1$55Hn2GuaRNE5JU
z8}IK27(Lt~YyxoWjy%B;9z%%uc)}?|GGL0}$u4GzCP~6@6u$_u%gAQeRKmeUmRLe6
z+KGY6!?}gSSUuqiHlc)#x)l%7T4G($dHIG$g>WP&(f%a1cB5peHRbtzV*$ccrzepp
zqZgnnVX~7X?Sd;NgsmG2j)@XQH1RRdLgGQL32Ir(Jqky&CAVLi3irn!CU=THmGq;+
zrQzat2uYUR0CB!ywX2OG&PGo!IlvIe*U(%(EY{wNK&h7W_;2p)Qb~?a9USivcsz|q
z>94NgkzkJ{!E(!qMJA^gu7%1b!?Oci7>&#zFRCrFpXhU^2ix$u2%?vG~p
zb;T%cj!FW{l%HU*?m?KUK6Y~iq_+!3YWaOnxMB_KWbJ>zw<&fue|YlkkXXf)G;M70
zBKznF2MpM|W>N7@1`tnFnC3|{6mpU9tK6Cxt8G_rm#!p;(t(M->dHiZ_t?W1^^tE>
zp}*xvrA;I;9H%2fbhoAs>ZyqLsv)ahDD;V4Bq!@RamhG@Xp?1lzB_ACH0TK>nV`Nh
z?Qg=s8=1wJ+!b0zb|wg_P1P-}la@7`;I2JKSG>^!OssN+M@@H{46PW(fBtDf=%=c8
z$K)njk5`kS#?g*~O!nB6Vhg*Xq>4HZOhypNcE}$@Zu2HFP-viX2dFG?{T=QT4`qv0
z0zSks*7D$`MYQQ%e#sUqs3^($NAxMC^Ggs{aR)<0L86v&fxh5bPW>?PU}wWhgXElP
zoJS3tO;^j3`1vJ^`iPyc&+A6Kj-A?#0(=hL^4Uo(IlX-*NxYz2tWxPc#fr54kOL4-
zflf$4CZg}9{8Nt`o!3eC=27ER`18X5LIbK{cf?l(@vBxu)4+%bl-M+Dd~FL31tU2#
z`HTqC=pe5jB73qrtwl&wPbFbv0qOMDl$kA;*?K)>znZ&j_cJ|PgR*$WJiPW_@lk|B
zCiVnM{WXXcrUPLlPLKKbNZ5?`ad(*2ufdAbISG_rF%0jstfWkl`Kkm&@AG@V4^jqA
zs(VPxeVGAt1f#|Y3%mW6D1Z8T`J8AuyvSHqxxQ$m;nvh;Dlk}!89n2*7Ol+JamyjM
zl{Ir<__UXeXynV~N#}|+2oZ4XX7#LE|Bi6$MB7p;^Ba}@(RP=bAGfCi?+wdNf;PK&
z!O8V59*D{kCqO01K`AeS)<#0f#3gc#^=f-lYYP;qM%>;uhovfIzO~f&5JzXQ=^c9h
zg`Jd-Tl&X#MaGKPr4Lib;xJ`SBvl+_u*G~SAH!-fMxnUJWTl~0PHQ>F@GD(&`-Ukj
zgi!0@LgDUd$T@02*jh22l*OO^g-`3^Dqy{UQnF`qkODoKdxO2o+&m9!HNY*G|7Iu0
zp|hBLG|+CKWYn2i8!VePtvzp
z4fO3#ANPQI`fp)shLROhL8Y*HYM3X7^2mEYjdc{&>7)Qxzh1qb(AB~z?$~at^r)&z
z!4bLY2Z_2kQr9m(;D03b{%B6P))Gws>_d=OCh_!9wo%qP_0ka|Q*3b_j=C$vP42}v
zgnGrs4r_idSmtwE=DS8AicKu3J9a-|$7TLdtfO0UeS4$-6;>TyL)UOtLpp)=C8}dO
z(ZX4laGDk24BS~)pdmBio7peg$aP8r;(D7}(2bbB%ynC3>|$=dFt|Yd=m{P?7~dE0
zC)8rEeIS%wd=A@vzR-$MALLTri%h%tWziB&hIp<6OM@TnH-Z}{Oy&N&j>pkVqKobp
zm7OoxoT+olek@79CW0!-M#ogp&G4erzTNUR;pse3aQzk`2%{+VDmJ7G;LjIPh3{ck
zB~NgAy2K;z*r^q&3C8z;SgKJy1HYivHl!tbDLw3h`GOPuG}}yoM
zOfQSIHal{FCeBDb1))a-x(=n(
zTE)P1Zl{!Dv~5%ohX?jfhYnE8%tD>}i;uMAu6Qy#MzEX5K_${4#VatsT
zO7xqTq2pzI*h8M^yr>;PET}*PxqZL}9O$>t638~azQg-6n&U~R!wH*)Y$kmP%zKng
z6!ApC94CZ3b$p_amBr2~D0uO;2ivL#pX|CStd_dUGNXEG|L(t}k({e_jGUH2lKd@`
z0(Y0J;vI`s?vaV`vp~&HYaEQf0_7*awBWCB%vZ%FXz3rqJ{wK*p@~oOZI$Tm-&x6^
zbb7fYI_(fk)wkRQe0CyWW)TS(4XP$%ENw5)N4xHPW4{dj)AhqZtW+p=Yc2ql{6LkZ
zWmXlo+Y<$Jcr598cpV9+=9z01yEX9#xoAHwPAz8RuLs!-4&?k!$b)I!aoqGPR!RMY
z!58EOxSnERLQAR5Bk6;w=H>dAxx@42L;E8CM`kK0)X@Jis{U7y|KFnO|0SyD{#U^M
zZ-xI)ga`M(h!SPy|7*g78}N_(|3G;B^W@(v&`>b4GBtJ~;b#3u_&@lMe|QV#{|o-(
zAGLp5lCtF@;r_Rxlr1+2faRa*|C1{DXZfF^+T8yTF(lmo@HZsf|0Yhj{~=EP4^{Gy
z%)jma-%%z1So?1Z|G%h`e^&M1%(1euviz@9$uEshs-*E>RLP~JS{g2f&xM@IwN2*G
zJP*Bjz10qZ0b&BKN>Wc)+m3#YUqF6gT3s7Ax+oAY=3M+?;ZpcZ=z4#_MBMs725Jr~
zGlJSzPoOn(xGI*nV_x@ai{|S{-0kTG(EsJK6jUWDmG5#CBHGccxBQ}sHc%~Ke__t^
z(4b~d{G8V(b%y#GF)y68ZwQRK>|dNL>#^MZ?)uVZi@(CQV*Zj0`?KRO`-}|(+s5;^
z9A@^0a?1P%$7a^W=pkRxatk^aSH6=!Eix$^S}7@%f6>FD%nw_FKfQSJz4hdtW%}LM
z^x0}-)8>>}*8W^J42B+qWznhKAZRO1TFtCc4Njb1RcD$h3L!O-<@(RmauEkF;<5gw
z&fy;dM_BI}LHU3l(>|1%vw3x2bHO~E`999pSNNm)wjf*w72UaVCXY8Z6$$0J%U7#a
z19>wt-!3}Zqn2uIm4|vIhu+#tf4v8gN9wN#d%Rka^n!GdFFYh%Q#%KK5&OLz_F;EJ
z_jlN3ZuH#Ac2A2g2;nzZn9qI|r-m^6SB(R~a^x9=Zq_q{^4`m^3eIlf`lR2_+f>1EIx4F#gIhg5QIhddK5mF(#xdaCJ
zvD_NnELVm(O|lHlwflBMj#718`A`?vSi)T|tB=#hxc7vEc|s;X4*A~ML|{oxNrl}(
zS0O+7avjf7vTy{oXcq%)Sou}UjpPO*JDkfO9T;wj38R$7te1k2&smES=2A(D4%VAA
zo8%`7ztXJ!P0T5C`z4=6@ck#IDz_`nn;LV08m8{^P0?|X{;9F8L&u*lR$(^;I>@5<
zJY*3fu}TD7e|HwsvT&512P|6|K@j6vp1W5{DBu0Bkk^*-{Dn5+lh&RHYg!~)t?T2D
z9b&AJS}J~Wvz0HoL~T`9a*1&*j|j3B$QJYhJ(RA+Uj_krGPS4p^A%U}In5GbiY2$+
zuWTRmCw#=ujQAyg>|E13RO>_Flx1~OaY}(`b3UC=(xcW7t{cny6fg&OW~h|rE#&$x
z%2huJ8aSe2ostXfn-+D=PY|Wt-rj(t@j`d>Lj*$^<&I6Q?|=6tORsZY7(tJxADjd9
zq*uSWohq((`KE;KCq4J4zq!ZZ2w};Pex5*{i;5|}(TNTtH*Xa#qwq>RQ~Xjx$dt3l
zWWKU>8gZtaY<^KiIAqIdR=z)&u?Kh1PEH}vG?MC}fkJ6U5Pk)rhY2Y?JZw4cSn58y
zm^xP&uJ7B#MLY9N|Gl&CwAJ0igL~i^>&c%OT(*HV2utkjLu2i3l%!Abr30LyjG)sm
z{a2~Il^I|R8Wqnu?kYMQW{YS+@C>0UMUF7ieKVS7;TuTsl%GX3u%qRtImg(X4pYvc
zolevJ*|Kh><^8})uO`uVhsSwI2Mfz1=@TdzqxV03+!hER8s4hpVNXE|os^Dyb=3qj
zsFM*h1l+hJes?R)R<_c(wM72&IFDm$C5OY^R3L6ng(VM7&fwxbc-ZogRJgqbp7zCk
zuN2u}DCO4&uy@>#;`omB1$@yjuRu$u+~RAQ>@!IY0>?i2yT$FzLTeP|{&P`(r+vKV
z=Iz2>84&@4*n{D~ZN+WRsCBS=GPS%Ly2PV9OwFpX+qFWix3lE~hQfIFS+;nxs;XpzL|eA}61iixFehF06U!OlI^&PU
zzu1Ca>0MA9zMkDeSa1)J_u+xsad@(=KPbt-m*m8zwZ|o(R-G{66O>a5Q4_|OC9v74
zgVjQfiJ?X24{%@|rEEN-@3!-yz^I^xnqB0D_npQu*pvr?AZ6`ivAI*%t7YYND0_1%
z&O|y;#~llj?x#QEOpjPvn^79yzC23KK)bg|>Njy1^U`XNeLJ$wn*8i$j7MF*2hI;U
zDY)(B+(;7ng=En7SnD}5GZDC(J?zZDb$+{`^hgqD9Gwzr
zpwY7wOM+v6d?aHaFs2xRf8%|h$KIzA>4}RHSg))+O~>aYxtdW-a>Uw+ZVlT+8$JuA
z1CK6+b#@^l{oQ$SR%-{3SOyO}SPc6iIm5lTzc5AETcJ8h{ku32CgtYbt)DjS!ie?g
zbK?o6H&&mExhFBAu6O{A)(9eE+YdtoZcq;4H7rIPt6s!cSR3!#+)#+!CL5negeCq<
zzIs$gmsoOx#NJYM&DRucq?qZU6WU(QScS%ex;qM3%QJs7cIbk{Tg-ks+4e-g>6u#<
zAM!VYsC;Y+q-1hB?%(>=c;(
zHRpLP$GeS^k|l!KrVTrl@PfS=8AX;UtgZrN>Dr*@zNmNB;xyuN@n-XWIRolQ0
zUftZfdL#S|vN368bEuTvzbJTv`63jPvIBn0GaFF
z2W9zv&tG@zr|bU&mj8iy{|#6DZ(#X9b5_diBmmBTVCsJXmH!F8Ra}i+{*~Jkw|BB-
z{twW|$-=@0{14RjU-Mhc@`kpipV>SvW;sI_Crc0Qe__?nEE)+T2MM<>^Z!X2e&!_q
zD+tzQ7V~hCQ28g}$o)@>kDs6UAAJ2EFq&ET|4l%$vT?DHu(5G+>Hf2ze+m89Y@bJF
zYn#k8MbkJT*B><>W90lSdnZKOqKMjH);p0DZbj?dGvEX_NqG3+v-Pa)LZvBqP8ctI
zAj!Iq9<6}qeGcqLROd#=$1}12oBhYH_t%_{n?JWV{vXNN?_OGOrAMB1I(~j1$;w_^
zN6jCMuJ5m8MKMn*Id{YOiOPO+#Wo(TUUK+Mf0PzNU&?;n-#omFdGr0XmGz!`dwAC(
zoLE?3Fzz`~+YfoT;chdtdWg``bZ+iwGiI_9TFNxrtY5Trk=Ov
zNI<|`zgfo`;r=jqQ(w#~>ndROr>s>#z3
zmG|Oqy+$(~K{@Mc_$
zrWyh3Ot#umk{!vaULPxAzZS?l>4?9Yd$%;g9@qO;qpS(WQ2%_2y^ytw#Q6dexjE%+
zh_4COIz-A0ur*B`jaItI{*b|GjFC+tvu1D8AKYdL;B1KvtVpQ7j_4g%@oD+!qt}`$
zc?lATQ`G_QUxmu#@F|9~_
zwjWgCP>1uN8(6hS&uz8WuZs$V$91=|c6UHrq*1~y1mpX|I@l4qi2uvpXlub$8dUN7
z;hQYlwl&pG#h4}j--tv+iB`JapSId?RgsPbR;
zm%VyC4hMebv>_{;0i)hX3YP54^Kr1~LBzP214{t9^mk;_M1OCe@VQ|=t)fOGh
zFl2B7^e=TL;crkLwMA`SA-uLS6K`wH5n$K$HH=8Lv26@H=V$fBAc@ttv%#pF-gRt^
z?{6@fpbTyJ&Q_nG}Qg2tRhZH@?gw!-xQV9>67rHicRUOsiUx#RuBI=DB&
zOGfhS*Py87hxtIAUfQs>Dd30tG|n_wP%qp)hKQFD_6zPL-o@Oi|Hgo1x_jGr?M38#
z8wqXs6V)mk<_62dPi1Hkc_xDeYR)s>*m6F}%RS99IU<4rV(W)bj~4VbvbsdZ7iIvS
zh^9W!u-lVLk&X+DA1R9_DW8Y)3?YR_1F1FNko;8(&0IxY=q2PDK-*VFr1j
zJ`%Eh^_I#=VHYSI9|VE3NJ<_BKniP-^}c>b(#6UzRoq3k2+-N$OCkR5YY92N3ZYY?
za}3*yRf1pG-FaOsU|8=GOcI_t+SenBX#rnnhQK71IgdeG2WXRO3WkFIC7rQ5UTjdP
zjlD8kQv|V`(9vMASexc;Cii>_>B;e6iE!3u@M`e!jc5!0aC%M;%mYzPlG;bOwE?G9
zFrbS>u=394eH@SC(YuF-<(~a9qE3OfYCZcvDxWEr(u??SE
z0dU$SxVy2nN0R~=YTTUFgZpp=n>-~BOABBoR=sZj)#_uETrMS}^A{iEzc_BJvZ?KG
z-!NH&Fz|vYAcdnAmBAfOYUukTt9C2>grfg!A7EJNmQk!!r{6aVOAC*8S029_CJrNy
zGZ_2Z$c&jffwTA1{>0ytq%R!A&H$a0dT~L{C9;Ia+Z=s2WQUiOmL&B+hj
z)b2@f*V=g(#Ppr12(e8fbby`RyEQu$cSq^tQi+h_zC^Ui>u8?l5VuxMS9X_kAy+|(
zG9g9E6|{bgDQb7MevgXxU{k?s5$;=rh61P;4=3Uyb-6}=l?GX0{TQ*1Zl|wUUF(@|%{HDQJ=t05^v%`>g
zui|GpCBE?q4gRyWDQLgQici}RTeenVBK30PnWFP)3Ga)>T08J^Yjm!X-mCQN<>I73h4JNN~IYUR9*
z!7*klQ^td7lvX@V`~)!q0g&y-G>b(Lk`e$^YgfDrAOknU2gLfu#8N6(R2;GdH0h4y
zh>@Pd^m+)_xsZX)j#M>!9@Mb)--D!ww7SR`YjC1kQ;&3OoY?+?(EA>JQrlT*c{Y^(L5y3Z&S#s0t@amEVr@W{171I~cl*IH8<9N`y$d
z;@+wrkZK>|K$v#$2Jy|pcgbyROGE-wWNovFf?ERMT()JDf{ir8C?p70Shfb%9qkMH
zB&Uq<&KQXwzSHogi7RdY>T5fdpVL;qKkKxcJ-gCe>e<|Am`-kLU<&7)dPowl=)twr?
zaMDElpupYdUDZ^QR5(q3Mjj2ns2p?0QD!6Y#5eV7d-3A=ps{wb?$C!R*d4_5`q);!
z`quQ5?H8`a^7%@^rN0$T?EvXSzEcG(ui{IXXc(xm*^dVsZI1b4%>vwvBbG#=g^-jB
zXS3CETf|lQi%z8wCbJu-fRQ@2%x|njT|%}p(Aj+Tf0t9}SX?gFSJGeiLw#~+2B=o_
zzv7qI>=DNx33NU&IJ=(3%+_DhyEdXP)H}!)DWt$c)Nc{6L1V~A!Z2e$n$y$R&g^x2
zS6Bq;j$(6W+<(Vm{Ov24)Mc;enbd+5)V*Y-%>TiTVBkq6F;M6*YHrsns&G?O*-Pru
zAD}Obw_tt}sOVc))zrX99+oNqt`Ojf(GWRHVxaQVJ@9}FJ1D91+Y1p#Ie%vAW!U+Y
z@sl*2U;g{sPvhUJ!ELz}Rz3d4I$6&q(fZ!@>>iS5lMr(Lu%kp54Ea(E-~d4~6%hmO
znXHxjw4~uy#FmNmq>Ha}xx%|1X0}TMdrbzmR<&-&`F3d(7x}Uk`7`xOHml+&<6k`JfJXk)&qU
z%T?^>_FPGMU$ddhY_-jqYtxfy6MEbuaR0!zs|#7%IK!$@MQLp*Be+I8UZp0cs#*JkxOP9p`9H0T{`_Rv_3B|+Wpc%<&tpOS)YI?PfXZi
zn=x4S;BXpPe(iR$3cW>HC1*vnII$Mq)g-fM7UBGp1*$QpMZ3fI4l7odr06Ns@zf~A
zSXICc_@UzdV2m@9!kBODj!4Y*ZtHHyp&k2TuQO1d&2{p}xWU$SXRF#LR@Wh#fr7Aw
zL^o?JZcTxzuR1D%;hAr|I;yza@-8YoDJ7@b$JW;Gc>6Ca@_6aW{`v&phHkU#FP`(X
zVX+31D90fx2}^oVfQIt53eN56{?J^hOuN>Yf^Mfv)N<(yH^6pAZSVa?@IZa*-oH%{%IJrb@tOUcu%dmU!%*X5Z(>V8UPu^6e@SI`O!>7n?U$3CK
zg7@kX3=jCk0Sphb4@6dMwIKBdi+%3jnJz-eEJ8rO3uG4Vo`+p7=8fQNH)K}o{cqqT
zeD|&wWERP831D(*ewNlcV7z|QrR8(v3BvlE6uS+QdJ>++H6*R-;9oXz3IwS)dF*pB
zb0jHYcmlq@!SDcRmc6kLdvm`wUkg%u7Oe?VbDLxfnupcb8|7jKTRp+>bdj!}P;K)F
zGm(Ef(3-P{&^7MxitOSRx+0v5Inpx!d6`-LX^EGNfCGldJN-Er9iocN1;ORM4Mrg@
zK;Flt688|Q2#D$u7^L12Ab;%|^Es$C2gr}#3`18fVpi0nD9FM4PY`8_B
z`MGA3&su?k)bsaJpZ+IS*TV8tFB^!$6doVFcf;p-D>0cvd9BJKtYCN3V&PTE0YrmXD;sY%i$Y%rQY8^hji(T}$7o%0X
z)yPe~=qu{zx8sEcZv!cw@imkO+T!+(Bg7rfqXTbTn8S*Uj&6NFmIt-9e2fiT0?{}Y
zNy-_+P^jE>SBA_UwC1hI%4QVi35~6YqT1~IO;=)FZY{3dCZT%abOsYupu%nS?mY{v
zXAaA;rQ#-wEhpCf%5%ZelP1^;)5#V8w2@fQq3-{42Dqe
z>U&pQ+_;2-b|VQ!DaT=7;;CWB>}|P5KOXcUi*fH>x@W8m9(EXl9oFcp6q0oaDL~=m1&M{f&vHxpE?nHJG=33`PNO>ptFEFPd9xl-0=EEuk8jgsO}Gwxa03?sl~8IV$I~;F#gOB
zKuMPh%qn6e(jfwkz!(3EX>j-z319sP>6b8<1OM=TXm}C&xW363F
zQgEe8qJc6(Q_roksDwW{TTx~aB(K#UCTCLzh;K|xSrQJ340c1wpDhj*Yt8+FGU{op
z|MuM1^t?`?7L7iW;gIih342kwL1TW`MKY%5D+r;cN-UuXl_A};Odw}St4)tEzo{;S
zSxqyr+TA}3a_cN@r3o|NyHOh`_4Eh(W1@7^wg;Pl5XFGDX8@)`OxbP(2llltKnZ_K
zE+l0FHPt}*EAN{t;PR}tZ)0+9+43ABbAKp+Gy0oL_BToJ6&Xmy<8MXTjmWuU>ff9q
zklOl9;0-K9`6D^MN9;v2QY;p01kn!wqqv(Xj-8rg8ChAy1dWq$0?VCVgv9o`8dID+
zR7_Rzq7id=ORpH5hH7mrxTK;JVbRfK!EU66tc>;mrdosF^HZ|+90KAS8PI-WIlAHM
z?E=nlx&DFwrZB_lGk=?9Ww-#
zH9r_cBcJYU>o<_{Qy5o|EPa=Bi>QRbAKa%^@lUK
zypwS+;Ne@?;701D>&qOle++#fl^cSGUQBu)ZZp%0MdEv@f~zysrAPA$Ib?h>D2NY2
z*4i%Cz)_{8AI3oJA&wiu&B8N;`gn{4YRAt3_bgs1ueZ=3j;p^SE?{$#;d8pXt0$sG
z@>u7@E&jdR2cWNEW$UX)+`Wvu
zQ(H>^VOBt*100G+uASSs`Z%RCql{-X>A@d!+6!It`XH?9YQ`{CxnD~PT&J4DI0X!Q
z0ir#}Qo|mG)mV0vw5W@`_2-w?F;jBihmymD_(f1)e$ifR0HEBjlO9M(aDHHE3^<1@0&>)sK{#E7W{VWZ+~)~Czj
zjH{Df;FFt}XH&ID{i47qkj8wWte=!K`iB~|!odOfuqffLHp3?1-@Wgz=RmW&G$b!F
zBJYN$?RI@YCn-siy|m7G-L-0qh)A9+V7Piutmv!axZ*DeKIG0T_o%IXo2(E@s^yU%
zUmSNOpinvkc&8pN8+O_8uX+95e1)1SU84Pg32It>%yCH6vZIdn@2pEUcvTQr`;Gtc
z9rg?t?*j+a-(jrdXSi7R4!%{?L2mM7oo)B1pcPAw``I)KF^LMp3^TI$H&Tw&ojFX8
z|8$?$>Lu(|)UTbc@*I~qeTmNfERJL&%T#c+(HiqAZWyF2j=;T+CLc`urajb@Ly2dh
z2A(SI_t>WCkDw=-x0xA|S-)XbzYY6=;MP4@4vG^6+;Wbd`=cY&WCnu6pgy(
z$H5!@<-CUm@j-5HtE6n
zCdS#Spu8klKI)-JMUqu*N^dwiJ)D+aYgsdde~czraIX#vN!QM&s3vKgOsElBdQ&8z
zep8|f>0nE_v{k&F$~r>l*hr6Fy__1%&2V!P6_NWlT&$UZk|UxTDe>#^p7%35q`}vb
zL(q6XY1+NO;2oBn*_sX5IRAhR*mQA-R+_Jl3RRX>Mi~F3!({w!u{ss?)udvtJ0E2y
zT;>WH0;K(jq*m>(!{fgpm>o*Hbsmv#5b9lV-(-xEM7;Mrqh}aZh^s1$Vo{TRQXE;;
zH&{J*WHClOvBm3b7K#s}{e1HUsM6io1Wc|=o1#$J+)}>3^k?z}#VlT53=AW2s@6$V
zq}&FqEs0bgt*0^n71YqKg(l>l26DUx+pqAK4)3eCcK@Aioiyl4UgFTR$fc$bP_w84
z9GNO-ba=3&tB6;1aMu-5OGOnJ$iL;eaV6nb41cXaq%xbzE>)cQUBDMx^uP_(sYWCO=iiWkOdd6&JfBaN2x7A8T*E
zY=Aob@MLas4dbr-7|nX!evb6mL)$6ly<5-KgQfWRvUO9Ha2wGXrb5rS@v91+v1`Se
zxnmj11n3REAgH5@#@gKgYL6$hdecChp0FhV#tqA
z-W!#H&krOI|EvA%EJD6+6eN$IQuD8;=?inKJEC0FH(ZoSDq7&>Ao9Az4vaq?=`wxOpqeeUq5CkHL2{jGURdn3Qv1^9r3&7$fiw1x;+
zK!+4&O*rQ9(hGu7dzzkKpU=!!Yoqt_dGwo$GHSraul(RIe5vI7N@`PqsTUWl?F~QY
z5TyGv!1pj-Wlx4ZN_x2Yr(C=Uzs7lO9M+No7Lu=AhM~XuZ_@7|@3881xTD9R&H~W|
zmX&5Ha>IgC5gjr_(XKe<{JRG??GG=m*TN4!Kd0AkzF%usG&s}!?T*ZZtB(u7Vx)m8
zoQy-Cqr6^2np48?v1Cj$t(!QnKVoKBaC`TeDJwabEXtO^*)_C7MO|uLual(wR8@K1`I4ct
zM3$ldCF6Cl^-D%DaT~<>E?>!04Fj^8jZ^Bq5?nR%!$L$bbB0Fyp6aXEcJ)@9<-C_B
z3Js^0aOop}s-|~a*yZ{_)yA&zXxA5|3EI1Fzpund#hy#-TxR2Nd3CM6pGd5|j$SL*
zK+c>C-5ZM}(=tW@XeZg?GnXP8BASmzCHfgX}g$}?vMw|LHP*x
zlo7YNuGzdV*NNg>=DAYX^&G}>$*%IRI-PlXE2(V-RgM>K3BpK)foKWc&~7)jP>kPU
z<{c7i0T)UKxV*<;2YzuptydA~k--V`GYsX_G25CC<;Fv&k>-TMVJEHTYwu{jW=!Tb
z``^ZMXWjd$73I*NkRw|v#L}`{H8}*_=AW#VG#{$HKqnf?dh6=92B+na1PplUzZyK2
z4O8>t5DhPW@`hrwICsn&+kXZ0{0~{MYFL8Hwy>#eCk&=UM9(C+#oAW4tup@R>K1Y?trO%P~#%79+
zAq)r~tYM{S#km^8xQP5m-T8+Xu(cVOR`+HIY>k8vU4l9dJ*aZ;;Z2=EMzv2}iV}T9
zo(U|+Ct{gk#8|3|Fgghhv#i>iKMD=A_+y$@jZbuF5{cEa6%hMWfuH?qu1Are!L8mV
zNwFoHNsbkPM(&T(yg^MXY}rC9Rk~k`e1qeHZ<<<)@wvz=@B3q
zNHIo^6&|jeQq18v?beKMeY>*J6@Kf&j7I7V^A
zW#>c@sy04|HPHlWWz#XCfhgD{e2=tH1#c^WOzq}V?^nfGBu96TG!}AT%w?6bx}mh@
zQB^}XBJO>64?a-@KauM9G8CJW5ZF=W1aR*yC9GgQ4_s5s4lQO-T4RiJjPD`iv6fEi@ii0XigdsVV7YXJHcoSyH9x*8S_ZGs~#yraEE0?|>LWx0OeOSjT7}Xe4Hb
z$Msfcr*YgzXR0>#q@0KthXF(XrcoZIIL=ik-jhfHIO^T%NJoRI&`^iP0zAR3m7C&%
zIjhi$=y&u^!t{#X>5sMS;_8PeUK|fE6VYSc!QCJ@!yEY0bUMY^PjZ$~8*{>XG0Gi%
zUprqH{De5N#;q_)NgTh_?~20oP#4p%Ex^i|XZ98djL!o(MKr#;iKv?W*c^p&#X>5yI)^f_g
z>g&=D9qX#~#&F#L@8B+1)j6SZzq*w01j0(Sm8dhiw2&2xv0J
zJJRO#lJ7-BhGo{X*;1;d%Iyu|6wMa1E_60b8UW1xb=vpNH|
z0!1-C@*(N77g?*)5E?%iHGNyTP+uXYDo?cz-fg=oh0+lw>^m=Wm!5PpdS0QwBwj)R
ztqc>CSz98Q2^0iiU*B>0wM@g2Gp%rwPQJf9(xG8<()5Ho`uRFxID-bMU%qkz*f14S
z-#j4
zO(QaXP$sPBfHGgBChD>h5LLdyiAeLVr|_WW6bDdd>`K_aPaIeg{GxYOu-P>_h>Q~A
zW4(h;H%vvuLs9al!F%GO8!pI_Q&&M4TPt$f8t{#->A=fQRl_h>d{u4?Y?Si_(K1ba
zO%NGm_s1bOz|Bv}g(T-+947^r)imQ1B!fJ!H#n4^?lUjQ+;L^Ek=hYr-)h)G!Ts#7
zT1hzl3YN2+WRfn_u(;;Lc~M0xQ8ar?{R3I&F;tBH_skM_fAXX7wB;5qF9)G^s#7NU
zg-kJaFPvM_!ycBI^9b2ly%!hcA9B6xcKnin^)uE~KIewSF?t)WUWZRsQ!GQ*zC`YM
zPV!mw4)QC(ccH_-!hH>8H|60nL#jwj3U>;778H=gOveH!2O
zFN2v=z|0F2yrVve^i?XY#7s6pkkY)xpLUxZYr_{?WTGU449a+mRPR>KU(|2#DvPT*
zsrfVVZ&4*>d=VKXOr=(C%~agP_!%q5t-7lFMWRV(-S_2<^jC(=N-4Pc>x9ZJ)t?yPzCqj_2qE(xu_W;E}?w1yn+JmBMjgEEFH(-
z-miyXk0@xo>v~gk$kM$tE*s|2Lj=7-Pahy;3Y6(9B0rrzoyy#wSfh_E3$Ym9IGAY>
zM-xJ$Ut%?%ea9Yq6&CUIB&g-oZdK}MQpw<}G|@do$ZAG7K$j-|y4|EO583Vq
zCE?w!j}mvs?c)9xdqBwLz;m}w5Jr}rk5zbu!2){hk11!N$|$iz2^G+GV)UFC}*Y^}6g(AX18ZBG;bGH&>8bh+55z%mrUqFvVEm}~+k
zGqgcK8OyDUia9*AaORb&Axi|}q9H;hym^pRL|hlKa~kmqr0>D35u8qk{Q
zL7qwWgkWkj)toCn*y^7Iw_!vDK2AbGL1dR;7HB(u7WtRi#_QhRG7@6iA#RDYLS`o*qTe_e?n+g+_M75G
z-T=%y@MTIC@&v72N{GjEW)2nqq~LquUcG?YIr}?U8ozcM+vHth3-mzce97^UmnOv{
zOc0ifcjw@7sjLwXlQ)9q6IkeUyHus?iHXU>;)}z@hb+3o#}{$*g0HR~Pq_wg_QSyM
z^!6)mwFuiFsSWNia)$EkRi)6FoCDcIz19K77D#=^^uhg#+bhe+G2Ewl)j`~OfKCOt
zm@WJhMs^t4f64LeEZbQi{j~tF&yO`Z2^*7O(oZn5_hX~bhxYR@fx+cf^M6t0`&66I
zwy-JVbs5&OKq@oOgZEk_yx&YUX5b0M*+nCS1a0ISXEk80UgE-heJ-YSDJo$L9atRS
z6dz!@IGzHq4ERLF2FTCHg-!wHlVCqckK3&MFkPvM2eQHZL8LsPztY*bW~!Tuzjjmj
zyEwD3^1wJ$;1Y_!dyt6W#Zh_Y8-E{jG~WVL8Tcc{fvebgMC)YO`PgL2;>E?q7d*$r
zIi{2H_aDC=Izasz4oBUcQHW_rua5}d0@TGfZvD&WIPTM}>hFdgNDe5U_iv1#{(b7F
z&;c6cdE~fil|F5cXrxIy52P8MH239i)&6+!KZRY8KDVRtga*F9ViT&Mrs5Os9ETp_
zsyip)65_`VJIcF6w=vqej0(lY5{^d1f>)CAh{JeA#Tue#*oy(O8xgLSNlmNq~NvTLC|#oZWIUenOfD|a23dj!3?1;P^3T7
zJi_=&`yJkMHz>{gD&jp-DGC*vt(~4u^CPYRZnD=KSt&TEkrSVNjORW4iUuO7%r6LT
za@-t_Op$j25I(8KaV!LN>`WRyIrhsf3y)B~;j&ZG=~x3TkDdTO5bp4FP6Q1+-5n1Y
z{+-F+Fzvf3UtnjQ1|azRoEB;D_rA=#P_(Mm6UJZ%79wE}
zb8@!NE_@imaInt8aE~a1zQS<3=?!QQ{mXVx;NpaDB~(-`tZ;!6n6vQw^2*G2Cz#L+
z238A}((Ul1!ThNYTcp8|8)$*X48fhiU^IyKY9pus>FEH@PlN)ToT$nmLq<|tB
z)E1YqI1Q4PA?OVXmpCFLI7OskZ6t8rYGF8Vb4g^<&-d}^1a&aWV)Ric+M@mMJ~W7D
z{=BI!e7mL2=3+7|vob
z8;T2o)q-UNN5a{7+>3_dV+}k#L@AN9
zDFS6^Ajl_Li$ilGg
zM+Wy@CJH^ci`V7z=W^Ky__T@Dg|?uL$}jli12uJ|C0mVQ%
zzxL*0)b~bj@U}PnK(m4hw!Ps9PLP3Trdq9xH;jt`XLXeHzZQr{b{RkiL9xPR=))|*FtZ#HZNnWyi~!Q3u4pL_(y6_=FI
z_vT{M_lEDWTX4|#MqHzai7a`J)+)l$_=dAtH=U64&oL^qG2;|v*%M3kQi|)4YwSit
z)lZ3U6d6K=6=7>Zx}Fl?)A+_Q*7!zmFsJ5L;q(m^;Yt2*6qf7>|1U?W@(HxH;WXN9
zb7RYxdwe2^8P)lQq-xjGYKvlR*pTk*#J0{ipUd&L-LPBUTckL~3JN#eP8|mh{EP-V
zp+!nY3!XH+pfIB~QE0EW;TiMH@r#jT^Qw&APoYIhMsKLM7AYC+rJCr8g2D~w*dxVZ
zFDSei6%-OKx8)(qqn_jGY@;y
zf~@z6C-z9$v>jf#Y~N_s+XAuIyILwJ{9HZWi--nDDZQ_#VN_5^c+J4?-NI{kN62q*
z_YAJNpJ7j(ncZDCo>*Z|+N9g`Fh5ob;5CI@b?#Hv6lU}%YhF_5;HfA)hiKu5yj`=0a2gjeL__5HyE9~q|hm8HHA)Tt10|k3)^yYouvGKt|`oD
z+{AK>(?r!V9vaVRpfmr7@s_Ed@1bBmxO=U(KNT*~wl{rY?%mEG?~z84P(zhMDMZHg
z^eu%_h>bCBvAdm9S*IrtFW4^Xg>dh7MvEhzS-jer{fzF;%87o4u+h+kDVO+w>P^o^
zOXv>x6E1c}HymkHRd-=m9-8M~XNUb>=Yu)-Is=~VltJ))YlJe0jQ%?oZs)zu7{XXy
z2C;{jj`m{rI-}=Oxpfd3J%479tekahJ|()8@B~cEclfUgre8JbNWXMmwr@>l`>SyC1?XSw#b+
zXT&GUYk46=M)xDT&eyJW#)7xug%F$C))vmLbw2RD*4Z(3tux;s-GtXV;~Umh%dT}!
z%*ODjg4XAz9dH`8MJdUN2HgaN$X4PzMX7ErcG^7DezZ||uX8Hx^yph>LBnQ~fI&Yb
z7?h|M(Y?;Vz*)8`+xl_`vY4_g^<~fK?gNJ%QVbelxta~eP|%mDgeRJE{+8*!i7o_w
zBUf$0CTkjf@W=>_wY~*cuFWPG<6Lkh*e}?*tRO%S`3V?qMf89my;{{6;GGa-GqKCktfa)xrnkqbI?7d$xv*^~zVEn4RIfD&=1
z;uoKcDQ+#N;PPC!lI4B)ITx;E_#U`Rbm2;-CqX8WE?miQ(DZxZN@h6dmUU*hgnDct
zvoS^eIQ$9Q?YeL!mt=1^7p`oKa%b$!$OzpmB_$!z<-+I2701|(D||y%MjCEhA#7J6
z^z#ca
zaE1JE+Ya;jdLq@hZ-pbAH@A)KaLT-;+Lip){BFbT`~vr_kSKP^FH=5Ax2kSkxI2P$
zZOXlQs=!A%DbhB{9qQPp3s<<7MTt?kaD{7Woi=g2U@7g6Bwe_|rOZl~#DyyxPRC_Z
z&Qe;U(_=qqCo2igUoG8j)Iu_>*vci-YnS2^D$cVDS4jA(Pw2vxjF`~9ZzY#%{VsLi
z%7!gB$1YqU!mfInq+8WqwF_4W4_TACaD|wqG(!&In9{m%<-+H}70396D~_=XR|qFv
zjDQ9=E~hA;gHr-0ZS*}%y0EU_{)IKOd4GT`UjxI*5&
z7p@R2YUc8oXiP7=`4zVU5N^6~gUa`T{lb-t(S<7#Liy)hxFTVz{7T)p!a>>%xQT)-
zt8Ue9RN;QL7B#wZg>+c)iIPtBG+$7PEYfr53WbEyN~UCrx<=WRD}>qp+3s8s@Bf@D
zSMEyb%9RVBD_1_(Qr1tw$z7uLQ$|1JH0uYLJg)UqV7n%_e#*$|p61q18OqE(=1=J(
zb}HI%(OmBF*4Am6sVABx#F+h4tbM~ZfDnye`C355nl&B^$YHmD4(3=ujOP!xfDlr$
zt5nSbLeR;&ziSB?-@g_R23ey4q~O^#fJ#rX%vwQfqU
z@Aukr=H~`6K7lY}z6MZHHE%G0n8mZM0mS@(ehr`lUjxW7W&rUG{Te_Fmd^$1L$MFnM%35Te>m`b5YA_
zPaxzYSsEdN@EK~bdCdn8x=9_~^9MJ=`nmZ7{j{ThsH9r6PER1*74O;-(%awD>)hH(o_lAn!*lAbdi`|=bG>s|`ua!A_1As8hyJ>QyZ$;FIS_5VA@{Qsn9y8i!q!b~!wP%v&{s3(o!kpq&x
ze+}&?`2N}E$DFv}5n3m~BYCELkK~$GJft(rHs(E&RUP&deE-x%Y%BcSbu!=o$GTCy
zq;@jj*79J?_Yb{t-p09HI%{hytp>w9w-psmEXgo7iR}|}nXXcg_{44dTuHp=w3##4
zKbh2f=Vow08Q1skusi<`=6L_l3y$}npNP$K$zUt^?m5V7|D9P}3-Qd;pD;T33q+{v
z`#+RCzW+n%2s;in
zkHPdq$-Nx|8a{3mv7(x)AE->nZavDV@$Of3$|wo1@z$fvDu2rg7<{F==<3#^TuqC;
z3L!AX?Eca8MAf#25$52z^~f<-q@gEP`Xk2gJ-QfOe59$SpL6pO;r4ScKFZby;))y4
zs<{UuqaA_WsiljLNL|b2$Hhk*wkj7TTj$#5IS8Bao4TchCu;0_%M~7SKEo^swdJmgMCXB+;)I%2M)s!zK{$FwfO%UZgE6&zNs
zfc;|0P|P?>_y()mgMPzrD3o*t#biyo@UV^;@L5s;Y0|tl-0`
z$^hoPGY{!%@@1NZgH6C`AuIpF#!}GP{fVxmB)p*wt&Lp>s$xT~9!HgV$!VTLryU}k
zuoLFUx^#8S=(7^s;TAJ@QPvnzzrWe$8I&CJMUsJIi25BT9Oy_&F{WS$Ne$-xfe<6>XtZ*8)
z?fdB?J!y`4!ZD^N&80*9+D_|{DgzFIvg|Go8RR!aS!+Y%Fg2KKn8=PmKGJz2=gOjK#*FvgW9?GNO{g}8O
zvHYk9GRVAaqocG-d+KdeI^S0rC*w~EC*x^U9^Vp9R&ky+La%B}_4tL9&@M33qamu6FCTY9&Z{t6+sSt(Cbv
zyVq`=T3riie5^RRdbM?&DSKy<3%cLyla=d>H`nZ#4SU)GBgt#DbK%RQ0KppPhOCa{
z$8}QcwuS?T4Cb1ob|KP5a`7IvgsY*N$kXJSM2R=4M^$$pQp4!0`^n&m=zK!X4;tO|
z!f;NXH7p*P5@Y3;+L=7(lUWv2mBNBia`U2FGnYWhBf2w}s%f)d%48JEmZa$DZ?+(&
z(LikjVQY2x?@N5c{Q6oB?q?MJH4Fp|OSZ6mexNcvzLSwkjH1&2^%oSQO{V|+SNi$i
z_y7NU_$hq2@KSwZe*N`d|HG&B$@i!JJdFP@zoq^Z|N22RMnh;Ke(>V{JnYZk{M%c;
zpSr{T#G%U)!Y%*y#q>N13WhIU+@Ht&`I~=x%lA`v+@Cm>nXG^RU{P`I+Xo$|SMeRV
zB>MebAHT%Ardm(@@m=3v41@Py3Wp0(a7X*+7vJBH+P|mr7>HkV+&>Wg<2V2ImhY#+
zxIb|JFz)Yn&8$L+_(jM4hgARgCEitZrPv?e_5H;#djF+x%p=?a`SXkK??)}mQ0y{(
z(Q*Ib=s$jmcUkZ0Kfdexi(&NsOQZePtJ)XCf4qL5jk&K+a$Ve?S?2RM|Mr&er|z&n
zaetOCe|Xoh8(HHQ9rq98{`k$mz2*C8;t^f3vPu~6g^$SvmHFaA_#?70v@k&S3++NJDi-7@`
z1~Hq8g$|F6;r*ZN8j>eMzqtAhxyE#8`el=u9_!2&#=LcSo5S!jz*EHAs<&O)2*dXM
z`>%_^9dNpWHJe`su50@W3@YBZhZ~?D+IWf1n7=tnIBGI7ZFw{5Vih?Kk%wbIuM^mn
zU8zP+3?Y7fQAah>sE0(jb*TB)?~8%zf&%)&Y-mt}oCZ%D{oa!~i~B=Jq=lE7EulC4
zj-vthZKLxBbJ{SnY94YN+jHswRKMcF>T4S+5_mh!{4*6)INrG_BUoTob6&PS#Otbh
zxuMGkvd|V2?2vSf279C(x-8)i7@A+1O?dEwz4_sBWM42m(byLuGbH5lMeHfS&N1P8)5YeVJg4H)am^Kbdo_2JA4uroUR+unBb{Jy%77UA~AFS
zyu&xhZmF6h?$@;DwvWvAj)*QBf$ujJ!b!dJMOTACSh)NyMinx9aS`)?enqQO-<#!u7BFWo0h^h78U<`d!U*=130PbLIw<-j
zU~xezMtlVQ3ahd5c%ppG$l0naDOSKfkIuYAocuDJ5mVdvtDk$eRVp>OgPpFrPL
zm#@6Dw7Y!Gtkt;k)#vE)6&GucdgUvwB*qn0M|wJ0UB2RW)t2jhf^q6AUo-QDqkP5c
zx97^&%RZ8?pX{V!T;AG8ihSkzGftO%qw3rlB}uXO1|=9TsYlbzFy3cueqHFs^lxaLV-&8
ziZP57}K=sPk%+_L8zGfz`M4@zuapdbKbtGR==HK4r>%koPispUm%GXhtA|K={
zBcnmSBI=QYd}VL&H~EU&$!d_VTPO{ep5TKOCxRs2bfqhDO;?bvlR02Px-QJmwb#tV
z&>&rr7@FUtE2<-VkglkOe1ddERI|KE*9D;$q$?*9r0aq2R&S2(ZIm9F??i_#Uj
z(CbRqh4L8>T6SDck}j0pAyJqX)m=y&Dw~Y>SOtj)
zbOJWl2!_3v1~j)2Bw#)AA{Gl9@4
z8I@BjFY++Xa#Vm-NC&7yOg}(rRC!G9?$u>Cn@U05(K&i#%>tPctmi7q%Alf%mddPi
zW0u?&kTbw1KmB4Rg)3e#lFlD2GwTwiH`?>b&JY!HBTCFHyTdMsZ=@a>YLkbJ0sIN%
z&P#79h!$)Dw`M||c{8Ake0Qj+LnQiLlfkO8F^RmD@fETjG0J5i^^NB*M00k;|0(sL|L632?7q8mqj~ZGX{T=
znMnhYhg*<9WjkBO5{UEDcIw|>dsiEJ!7CTdu!~_5*Iw_bG{|oR@@^Y9_?q0NSg^{5
zn!G$J*FRzWS4_ynI(}o$r~F6X2p29NGeFjr^q
zM*=nUze~|hb&T7o4UWfl{eTUc!MJv6qiWKEo!ScSp1yW!V>i!hr{YGqS)-kLF~?5D
zJE&cooyxCpS!k#>Dmc+l#lX|k-B4|8R&)*3hE&oKcBWI~7^_4Xy-%PbQpO4T4mK1LRK0O-u&3OclZ^P_?j^)%ZGGoqE@%B5~
zP}^2+V=OcdjiGZ$?H1Zl6LxS};uDok!fBc#o7CZMDV`C7+fN8*8S79x3DX-mOnJvw
znX^d4aB$od9+XlTCA{@gTocnHL5qZWfcL>Gs3UGN{pJMinjEnP;}_W-Z+ZeXip!i1
zKdqS;1w){=)LIv5aO(kHoHZUu+bIs!MN4xqcY0#s4l5u7whHI{P0;OJ-V=m^4oNuYdJ-3xBe$>5Ju
z2ZP|TR$`LE*rZzRDK``@Hf{C7`y446lw&Hd!UBxhgM*-l;Tt*0{ZQGy1*6C~Ke0w#
z{6S9#_*5M
zK@}IKHv4cD2~5B`5?7)ctD0JPqVN_oz5xq>b9G58@6;Y#c)^ncF@fU1EY)ve0UWM0
ztU!!|fu_GmJ_=e!dnEqYa)xL0p*QsjwU2rVRu20A#rSE6T;dR4GYsPk(*FU|R5$$}@H8`6`hUYI
zw}$KgZCU_>>VKOmOTFrU!}g-bQ|f=?$~0I1w|=@e>PAqG|siLT^F&Z!GK|uKa^)qjcB)3Fn~vV;LxGT=@rvOJ~YI7Dj$pDgO-t
z&^3bckB<&Z0fh38rC={Q6S`=xmQoPP3x)bFr9ri2ZY3!H9Sy{43d(Ao+gO;Lfz3>1uFCTF
zG+I`Y61cmkm=FNB<5tyN9mWred6~`=nHLM;1?XGdd4xxDG~K3(F+e=yW}j-F_$_sD
zl}}gc-d5c?B&7E&2@b@7J5z`T_Ycyr2v;dNi6ugKN8`~mAANu>$(hNPyg8OWhiupU
z;QFCi#0EIjcn=eIaN!*iKpHUfMBdn5Ap
zF8D^!z-W)|!r5*JycnH2fZ0E<^Cpc>x3FxQl=X?C25Mcs#duLulD`){BFPQ3X_8qa
zylhM66&%D^Y}{>f)G%IJHm~A_A3Tato+l7{tU7yf*DJ1GZngUmuoi`_YXJ76BR+2D;;=8D*&
z2{Vuht45HT6ZO~525Q(fjQDh>x?>&2kg+*gJc~J-!y9d^z{06s>y%6RTzeKj=&E@4
zC*N!eCW@K37h9DGn4y
zx*r@=c-WQd7tONXk;;P$WsavYE*JY-Gg3FA?Lt&_^
zefb*T7gLG42!8HSs>6u};UMYZ(c(8`G_6hpjixh1J?gcoK=Pu+3l5q}_`$(U+68=pDKE&p
z>^w50-smD|ZY|TFU{EaeWOMb17Yfd(K+#|u_lb$1rrBvE+$mU1)~VP@2`z4a+$k+5
z$;V1)ajKe?;K~cB*9X&OtN~^tCB!qc-dUP>sYx76Kb4Ho`S!#
z>K8adlx&e8$9NI=jlyz8M~uRD=HJ98n)=o7l9FuX=O-sy40Rf{a`dJq$t5@Kq~YT*
zc66;KXM`yXsqhWYG>4dd;xW&n#?<62fd8{6t|-k~b2M^Ab8}epW~eSW80@q>
z-Av#ez{$-7fRYZ!Ou*H6IVU$0Ms8;7$xPr?c_W$$cDdfM6Y#~9uAP9(`gm%(oxp1Z
z`?V7=DKfBG0k|Tt)@UbyPGy7#7JEw^GXWRYvB$id3Aprb^=l?z`4|B)GvUI=Ot=`C
z34j^3m6^a>^hz`nc#Gb+W&#G0>opTFNJf|3Ou#JWa5Djmz1sEPVzpAe|
zRz%~N3Al7{j%X(EUh00$gmE%d%}luPF%ukPW&&@rp4UvkdgmI=gpno7j+uZ_*5+mc
zR*&Y<(ULIjC$IbWWoj7Bgu!0g(M%Y;2{W6Sz?EEXCVcKgh-ENfZP84)7?}yY_;R|L
zz!{`yCV*+5?q&kO)!ab^gsPm=2L$A26(n!L*XtB4TaCOlSsyer7Ic=qlr6?8jFiFSH5a4FVd{hP{3V?5;8Ir
z2GfJxQgHB?3I`!u0l)73+6sf6qob`bkRIcf!hkt6oaqO=H6vIGgT3|o{rmpsxt79!
z10e-V0r8P1SPBeG21~(Vw-g*>mI6-d94rMG=Pg0@&_Z*H$1K
z&S)#}y`#CUfRUwkZ3T?H!?D`2in&_2fwTzXHm6$U(9D?WjWlxr)1{CNdi
z0sBpLjItFV6{v!mt>CcR3Kt_=fo~|+R^TVd{bnm*3^QL_0b^v`+AINz*A{Js!5gcu
ztpLiTd2Izya+YW-fZB9_o2_uyOSZ!2`srZ8ek}iLEAY~G$wlSeI>s`)2e@}A7R??X
z%jBeIb`PX*Khorp*^L_YYDt7JaR%-oPg0wd+CA2w8g7~0V=bko>BO11v~Ki!B25I#
zt~Yn0akw2|@Uu*Gt+HxEWp>YJsiUnjyC=-1rV|nVhKV|*$I@iUixaKxs@!il4gj;~
zvn6*=T+NYAFm~}5MXo4I?w+hcSAZAE-41&y?Zqg$8*gA1g(Y|6n<~?_B$jaZe
z$RkB2OeZ`{g*^G)1NYmHlc2p9^*MFU5(al}M_hny
z+Untn&Q7H##hZN7RMVmqZ&EZ%+3w`5r370`@xHJx>cJ?*+h1TQ-u?+s@%BMjk~aq#
z(nmOrax-x83;574285smX-VE76-(7T$(zJn8U>uZPHfBa{#*{qi-{|%oDY8gg$^2O
zie?$zvsmlNi$O!%a%%;CeY}K0OEj)*H*NIyMV!dyL|1y#f&zw)C*^lcbXrYHID%&Y
zurgIoeh1nXJv2d--!a)AUb@*9+fz3n-u#YPbW6%Hp(m~iO2zX#*z?kSM#}G)G`dfE
z2V2{c6O`Y<2E7)~SAGZjua=WvxtE8nQL{2Mq3mDyhKzJn0=+31%`|dIwhGd9Lt>QN4n>
z0y4}S`2*3Kl>{Qa1AS7P=~PPZn7oj%dU^->v1o`8MHfEl9T%hY4#3&8Q>1sWFLsq1
zN$DNHJf?dhy#sx4AIr)^dIy$zSn49vJIF1T-H7xK@Dt;kmfk_`n<2XcYsp^emfeB1
z?B>lycE@D3g*Je)JAg@DW;?PwCR2*FWf1%X{Pg;BvpYVvuC_CCL&wie+qf7@sYaLI
zS-xS`iI0hU)*yZ7A^2q!FbEcng*>(Ff=KczG4((5v+fm|UJQ`$T4ZBAE
zsMinb_p*Cv&|?Re9u{dM1wC?7dYOR52Ie~~TRN+&%l;NU!qD3n`tUsJ8gUw=JiHV%
zC?6ZsULg#&;jDo4!!AM_#*s#`-?$U^*pyb+)rNJ$IO@pLWsi2l$lW>&z#p(3G<`Pc
zOab^&;&NRpz>^88_KQbmBD$mywhkL`sBO5ttjw}A7n6ffx)@4~I7W;Auo=d)k~-m5
z^D}Ksd0AdCJh~h1T1cI&q|`lVN!p^y9(w?!w&?Dj{RY`g7+)xQ9#_LPbA;l7WOG6s
z0Kc~!ywj73_wvb)&K_udV^eV>a)lGFmbM-gNLtu%d!1B6wGB#Jkx8mgMcg9c>S;4=
zHxp>_9V89L%PIxz0kn$M@5KpAhn*}MQt?s9YiOl;->NEW4SqC-G0Wi4(9>F3e_(87uzuyl@f*!NMFp~-S14$;yj_8G`kwt|_t=Hd5j#ms}V
z9NI&0d`%JQWb-6j8D9G5PbBq70}P9aj9`s;bi-?+B?f0P8Yyv;Do_C5+vmnt`x@M%
zT;D|2!Cc|P-bC++{>oQiCv?Vn#F2&K0j_hIbUfe^@2Q^VN(T!fCea8Nau_;LD>uFl
z$&<=!6~G}#ib_e>3y`VNU
zRl&QLW4H*s4fJ3*8Vk}tU>5WWlTMnG4?hiefoVFH)20ab)iO&}$0KuB+7*grtJsoPCwdF7a4ivq|-UqF8
z$e|7NxIW?Ez`!H!UgLy&4cOIPUgcz$NL|N#VrTf_j(NiMdgd>DT=R~RZ=SC#-F@>M
zg7r|5Z=S=vX*`L|s$IQJY_lG;-GsL6@z1UDS)IJc$>wjQB)hJ;{+x
zp#O^Qd2+ioW2@v7T!Pe&d;WsQJ%2HB&jWVvJl{W8@Xm7tM+KSWk<9fp=ey<*QyetQ
z9-b(?9{jlHMW+$m^G--}&tF2zJ^#5Bwmi72<9g>0!kqI2r~BqF8y?@hUOL@3&q2)Y
zzWJoxZ|+T=DN!#)BO56ag!G=DFKSch5Y9h@~*Vz;)O?
z^A}?ZBj0e!+RitEXP$#V_}x779HTY6$z)=h%)v9yS+^CQz*RZdGf%p;5v2!G?QFH5*ftbS
z>OEdWNxU=%MxL8v3ys)-@FM0B`y!${c!7oO-LWXH2m|Swwx)
zPf<8wK`82{fK$*<9d`ZnU`#*7E1#gB;*;x5KV>b>)lZRLe>0{MvhiafQ$pcPUE%NZ
zYNyElUr{?nxxl>2DN1NYyUMA>9t*xSzryQ%>;!
z9Y&^{_90iwQBGOs6LnLRiu9nHvPvgi-PB>%O%LYirk%&d)lD(x^`@JmYG(%B6jY9m
zGb}@GQOuy2WaaQglR)-2=w`N{oA#C@3{5xfQ2c{#df=;@I!3xFUXX)s3RbIcx+y-|
zgKi3jFF`l`*b!z4_E>SlH&z5|3Q8
zo-nCnx+%-1O4Lnzw=3>UH^qusH3W212VFOHjOnI)!PQPXz4TE#<<1J)Y1bX7u6uG8
zH<^ULcwW}fOi#3RjL|B>&6o9VH0|_|@@S_{YST_X7Q+^(@d&)?>A@WR6mVTvK_xHF
zsG#z_<0_~u=WAC%WocB73M%HZu7b+?uXc|f5TnJj3DjyUKG4Y%M?+PCSkzEiDS2~8
z2#<0#)B|4))iI`_@(tx`sQgCMP+9GiuZGH!t*enry2jiQE@=)LDhNY+&@|Mpt3`u`
z+MB#)M?>}HG8Oe>`Rr_h$Lmc;J(#1T0$x`|MZL)wQAI_~Ne?P&pXr<|R8djm(%)26
zRl!^pwae$^N69i*h95Ocr>_6Kyhcz_k;R`{R8f)W-(5vTp~na+D#`-Jn~I9Ufj+K^
ziqaozzeN=l@Oo2GQGir~ipqkdc2(2^Uwy_grlJBa`KqY=W>ir*sH>r}m?2#a)#i9L
zRF=pD4HZ-y@nA5rhNENJW;{>Kq7n?#Q2UJeAYA$$)KljjQ%^s5NiqWm^gDkYjH#z&
zkABrtFvnA(ddixZpq`?N=7~G}Ozg^lCEe#fQRrtn`YAc)O+N)SThLEgHW&0$hkZQ{
z#`M$kf}@|FPh9=<4C3gg9AwZ>SuAvWGH~KDg#8KKZRq+bNcGkkl*AlCKRv`g`sv4V
zNCr%askeUhhH0#hK%aQTxBrX@J?;BDX0QKT@+yaSAIyEz8vlg3?|y#|-@Tso5zcUo
zziFi^ed!zH@BVnt=}13cmTrrrX?CRVIJa@$fP_!6n9=P1lNoa!KxYwACSDt1KLLO@B;4^;w)Ztkv>hYj7;3Rb3{1(gu}Z
zB79ayM>T)qD+=9UXyjA*1743zT{ktYWt0C3P0#oXx)agP2!|CHPlg>cjvltDb(n;c
zx^|!FdIHUsl1OhCKUCc+`yjnV3io20{%YT7%C`eNO+nWMu1`%bYuwKKIlxQ(iZqQA
zEK8QvLrhV8jm5B!If!8^@-~VCt3%THg|sWEzP~O8b|;Bf)wHwQB>{lD@+zj9O#?G^
zrcYgRp%_xPVrRhP3Rt5>?4U%k#k`QDgmb{B{tJ5chgj3i2xr64DQ=R^0^+vAiuOlV
zB@R|~{@fy;{8*s@Q{=(8Ln5S!t@_DmLVk%cayErJ86$TE+*$JrIGfx1=|`qaWqYKV
z#E6!&QdflW>2ZG1rA9FKiBialr>4NA9MgG*G!>A4B(&zsdW)m>io11Qn50iHyZb>;
zATiP2z}*Swd<&M0WP}N4PNJyQJ-lr?QKV5|5_Zo8nBVdadJm%Qp%>`FnJM^xf3Bq+
zWmP5r2)2#R1vU)yKPElprZK`N(bQ!v0-ILLF_nK$eQ+eSH37)Ap=f!fI=4H18Pq_x_$u1lUS>B-}iC)Q$G~b
zs9};Hcxph%`7n)yhqxJot_HwSd|}dc9#vmYv~epq5N=pV}q+4P#vM>x++gNj14daS#;c{SKH%4Ql{T#b?K?mupb7s?PryZIgE1
z#Up0m&og^#&N*%NT_KA5gcJhyFTxwT6b||r^n?Dgj-k90;_2fIk<}Is7bdjx7ls+S
zM2&B-B;aMANOIVgYJ(~QY{c%r#dp>qvBGac5mpB3>+xAk)=
z-PN78zMu~754q1^V#?BE1`Xl{K0n3+`UKU
zgZAWz7j2r^RZ6(V6DDbs6Y94x_&mZx6$Udgm;x&SEAD>k6zEMKz@3{o;|21PEY%JB
z-&JVhlRbIg>>&L6fseA0v=3OBo!KhEUaXkM?3p+N-!hVshChl^BEn
z7Cl>hpdWps;xzwYO*_r9+(1v_Wr>@mGFtV1a5WTdywaZfeKBm=k&ZHhwF?-8#gb#B
z0A<2#Lk5*;=p9@4cf|!ybk%r34Z}`BQ%G8(O$t+?yPHbFLk+pe6~1BlfVb&TOz{I3
zBC#vEIt;CXxrS4!4ul6hN3=r^Jb1^O=^?~a^-!T6(se7GG?|Bdoz(Ec^bl;&bYxzG
zO@vF~F!sl?0F#9>XkKIU3GwS9jM~4x=&$3#p4x0umK!0Ul3}<4QvMA?4G78uSgRic
zqv#5}V_x8R#eG4fPNVM}bDyOLSc3A*wUK^BCX00QtfD2tpdOO#>_jl5rX=$nH5Hf@
zhMi~iw(oww|VXPMnQY->vw8>W&N`b;;s+PZNukO;nGBfBE72XhNLD
zqNkEIzyVC`FnP{uUfL-0+v*HZ@vG+_8cj(TjU9ahqN%B572^{)by7>=+&iJ133Reo
zLY~gi#wxcK`(W^-ZoCCDnf@?jxg`}Ra0RedN#$c)Gi(L0fcuUwXt(e-bMSu`6DjqlFdfS5W5}|i
zR`(nr4hA$5B8Lp+IYLNweE^Efq#$h+v_rX-a9vPypK{k3YIAAJuof=(DQ~Ey5^Pamvl=k&zm7XTvmM~f1&yy-V@7TOr1YPWww|E
z891}UpP7b}49qHTu3i0q3A>Uj%W++~Z!6M*I-CbPz6rIh@_+jk5daC@%znM-Q%$6<
z#1X_00NB=`B_0+f<98*g@kn%?c7;e~Tw6s;gGr=Vx?D5F2FhJQ^3)VNPdfAGoHoth
zu1ZotuzIpv6PcFr7s0c@25m!bNr$N^xEOt;idgODTEZV9rKB-VB$?)w*r|#vu|znF
zwixFer_FiYlr7E^I5auD0I7!AK1JCM0(#eURTJ^K*v~A^>`DWfQ&t97
zNPknqO;S2aY~vS6+WdJU+3ix4lM|725Xv0=GmI!||EZ&q!<>S#_x`$c(
z*<%JVv!(;4MNb8aa`R5j>6fIRM|$YCob9wZ6DBI0Cu{=%Y-j4hqQrH+ktJ=j(6?zA
z)~l>5*&JlDiKs;Y7A(YjiT@8f(V;Wgj@Bvuf;D-ex
zwSB?C_VU^%SyIz^0wu2{$g=h-CbVgh;ojhc%4p0|nN>?r)k`Kv`WToU)i%TjGw*hc
z774}p0m8ceh$4v(oH4`1%SmReKBDHbSjsTfyGd_MStX(wH5N}{ORqy(b-|rK!*^SB
zNO`iJo2hAEblspMfG1@U0gbXUAD|z?TVYKP|HBJ91d-h?>ro9%u0(-bRAk{<>bQPguw}ARnyy2
zk@&{0VI8>Xit0>pl?Df;YZq^@P0GkPegZNw3PEy9HKETT7t-v4l!Z+N+*RHho!t5)
z4_MO`cJ^eWUn6YVs`GXpsB%XGq#*tw=PTH+AEJSuOK2QHL
z=y%HX41e@TN+l`*j{NGRQBF$fs1Rwz?521stEOi8MmC=)?qY-Ba@&QeZh!xCC}B3WT0c<2E`D!V+r?A%
zv#^Ve5?(bWqx?VtB(8|E-N!`hT3z|&uCB|r#PM2HRFA6hiRGIHVb)K3D{5shmkoZg
z1)IY+@b$WjqgS$83Ma{8R&`4uqbrUNFgzc?BU&2a;gFMScdgu3-T)$(rk=1G^^;@r
zwudzwN|LYo$h
z-~Sv!n3(t0(|&A^xD(2J{=JmD`&yEd`UlF{k0@%o=iQHuImqsAYw%I*xF1`#D5>*=
zuyMX0Tb71*_hZZJ#Q$R7G`MG$@5hF#yT%RKitS(9kZ4;tFn1){J8sAZ-EZ6ti8kx4
z*@isrvmu>wXBpjoWxF|)yCDz7Hlz>LHYA#*#SMwM*>^vpS?_jiS*FmtA2GL9#*OaLJh4;Fv}r@yt;y
zKuoRGo3|&F`2{`@2%d~^w-C&2du{#Fr9{2cx-1O@$CG1764JOl(a9(2gx%J=Y-)9(OX813$~EvS(&N(pTn@s
z6z*o{QeL+^Cqm;nPx#`iz;0oLf9GyWv*{PjU#$
z=CkP=LV+L_+>j>)$}R>{)k&sR{1}+j1;qBYdy)K$zrI5LOp&_jeRy{qGkaCnWJGp5=nHm%etfAa?)|h8GO+&))c@Z)bgX!lMrK9I%^8~Za8gi5A1};SU
z>6?tDQzs5}%$f5RSJcpur>AyV9I;fiIh1#{SEY#p^hP+OUKGI#Zb?8%86LdCbh_PP
z!<(D6?Qo+?tY%cTdSxSvdS@%ajABnPiiWoEsV^Gd_1P>@P+Ef`79q
zxL*^hfICv^T@r(73;{>3wPxGJvO@6gL_v8=pknd@hcPvkcsGuWY#j7mVIC~=-L_9w
zY0~EjxV1D2mdERgGeMxO7&SJKx==alA}bx1w(ZdN7}!gZRLu>@&BFBZSV|L?Tecl6
zJ1#QQajmyB7=V#%2tzlADtPdWSX?ygi*V_r%@N^%Nwl(PzAhG%z7&Oob@EawS?j`R
zoz7CY{DC1`n<~7bZKWya3eCh~P4jht4$DUtE;@oZ94`jj`)nH;(`Cp2X
z8)FETce*?Cw8905BW+sftv0iN_uAeu?+=Bkaqkmlxge}JlySbXZK>snM=!KDif6Du
z@g5yxF<4oyaj_8GsfYqyG!i}++12~v(IwtH-L3cLHA1*%$Mn;EDEg353aV}Myeq%n
z)7DY8i(twCYRUBqE4Y_0Pp((GE&NHYS5O7sQlhisXrFS6SaQA6vA1;alwGfMtHs2c
zPTfRTORaa?o?7ox7izWBa{IxDpv``l$rsCq&WGfSMuIbtR(Pp$V%qa~L0
z)Ov?<#e?_U6LWNa=9%?MSK*|aKaSJQi%k@Erbr3Hg^Ky6xagVn9!mF1r1}apDa2c&
zv9@Q{yA;Whoq=m#o>`ACF~(PofE#2RXr(Co|~ECK&I!Dl5e5YvfT{GuhK*iuFWy;53|O{{Mw}ZZJt?g>~EkPo-yQ``A*Pp
z{(O52kAu_haylgpRxkQS2%Ubv#X8-G=QBk*8oavCUzU#)^nhKy4FvO3iCi
z&~Ej#drjySrm&gu33k{`@Qyz1+eh%4i-a;a4`(KTz)1{a4>8
z$Qho;ivm9@7Pw2mhgE=ab6q$y%!6zh%<{q~9|>;j37e^;f2$;c_G{S>?B=&eqvGVcI_WXYGh_l
z{XqVzb>c}>yFNTIwr^M_hi8Hu4ZI0~GA#URS>P*kxJV4<1{&Rc4O8)GVal_ZYQ^K!aqjFcUfq3pvjS_kUt>Hb^CF3G0*x1*W@(;pS;cglM)`*v3
zy9>5s5ivw1;lh`Xho}#CpDwDIS-C>!tkUMYJ%GvkCqfwQHt5hd3PO0h_4)u+{F!HD
zhIDZXBAgAs*>|LbXWp~u{vbM2?##mJvR-T5ih!1ZQkMe&?cJ~|=K7)_XY4$X=09>$
zV16RSuy*%XukKJZptnOv=9<~VB4O1i)EI|TbwJ3E
z45KC411u1RCPNdj1#oO`GM51b
z*t*$enTC9nrh?^QLdTW>dfj?ux<1gC*ks6JihD4tmcVUqt9NoJ$l8#)Y}?@Jn9w$5
zmQR{+v&o?sODQmqX=1e-S@8wftcJlLTt$1H;dE!sG~>6O6}JBz~_LahObjbROC
zr-P`kJB@iAwO1?V1Gzbqkk*85V_4(1IT1=)e4o%^AQro5N6=x9+t9p6ix*>sk)q36
zG=v6St84DJMlqyWg92%`D0Nw}{MyXGGENf?+uVGQts8xSpBq#z^Sm{gv9s43y0ea3yxMwJ&JW#g@UaN)soM?hz2fx-vs8cgg4^RK%4O(uXq2BQ_k!cM
zUYB4`%6}OyhOM-L_kwdud?wDMIbkZf#+_Xwggy)46$o863lFyINEj)3C^O8k%O``p
z%nFn0NO(sAb|~x>7G=_DmKw4;fpbY+>6UI6h(cO_hkZeL_WMvBoT9oX{DIItjL3u`
zXDA6dLJnn?QXBl%jB!qRSXp8xgjoij5%g|}2(Z3MgMhzB@(oPH>QoiJQKlLdDoCCP
z^`VG|C(Cw&fp*~;8J&qtj{-9$v)6X1xJh8Sr!D@P<2Q3$qe%deblAmKEODExn}SsBimRvQEJz%LrO5
zh%VVm`)#*yt5>Iz;(&<$#V`iXCZqH)Zo-qGUY`}|x|KIg=3S{~JcbZc`;H;>>Ax|A
z9}8j!)j~ov9e-uatRgfiCZG%jb7aO)PZNwM)1A`5%o#o*fiUnYT2sz{7=W9^t3eN$
z3)0PjE`1rlI!_Eo;4+?|!%{jT%D2NOQ*=(~Jz5r(YLP0ZT|IW=P`b(-^9=&X6B~kW
z3@vOizl8on1oJt;2igj)$Lnxu|%+At_*dUr-~h(wnJeK0SGkQ
z2-~7pCo^vH13diQ5J~7k5u>B@%Uw0EjNY$8=T1%Ex&Fjdkrjvn5U~0*)wME=iN7eu
z!dNN2TM~H0iDk3A-}5E;g!TGnL@2DL%z+o7019gj8$w|@eAy5RO9hY)Kmnx?Wpffh
zVY!*p017BFn0EvypbnvDz@!mC=L=I{
zC)Yx-*0+QBbLn)xmWjB<%Ps_s&~#Gt_x&zU&aFcb6Q66`eY8lGr^i91q(=eb3w0ydGQdL>q2IpD&u3a5RP;&mYzG_F1`
zu&Q|kE3l~Sj9>+PbgctcKp&ak*1!tj5NSuS!m`>V4pvwrdpRf-O&v8L6|i{NQI1r=
z;*ETe3RtNZPytKT_XR2}7Cn1I$U3;|QLE^vWUR2;LWClDUe!yDQ>-`LriLthuDfRnoB1uEbq
z%U@$a1(eOTG?N4>EUR7QK!uO{$1WwNsf=!uwIm5%C&}6$wE>^a*H4xl+056rl+b~q
z6!6BOL0QsR0%cm_!~3guf2dL*!LU_nRPf^3&2a*)dk@71D~rHBKd~5t=j_s@zGQ}b
zo>Q^nHNEbWtte7Z?T3RBp7N2
zsvKFf6^a1|r=zk4m;Y!?YUs4nreRT6PZ6$wc*Xf$xvQC@RtCGL>30b#?)a7RhB|gFt&rWes
zvo11}Yd?E!s_gJ>YuLZP?MB<8hOj)fpC5|sQ>XUxLuneYYCqRx5e`=SneVWbR_*7?
zl(a%vp!Rb`n%i;jz>3_!p&Siyq$cBm^Wx7HDTudV_i)&7B5+Jh{?$}P37M10O@E#^Xu-U>8egaMGuO(h0U(7N
z*V5ptn?G(QuzB@ouBPM`yNPS^I$#M*(Pl!LHryd)NS{DgezsjxVeK%rP_}VV2Ewk;~ocKXVQY3WIBr
zvt(>U^`AM9dBrCbb8a!Y^(2S(`p;ZD3*tiflFq7(2sK$dod4fq3YPcxe*}
z9{|O_fwJi6cs34lpJd4@TU*H~ru~zWj_Aq`ZCRmAz^=%aO2Ci{*cEAYdOPCr)6Ri!
ztd9zNl{Mhw1KC5)cEK`ES)d1@zIc9iFSlh6)Pqap5eEN|on<$1qN&{syx_tRrd-yv
z9_-LwJPq~>D=3B9Hs=kjCEx8ELeA%{K~EL>rO?Gb+WCP*%0ajetS+tWf;s>@oPD0;F&rQSj5WK1z1KyVX*oAj~bqR8n$tTc@{pFR0xLw5F24zilTrgQ=b*jt*HN>EI
zwP7lLDcc#dvh5Q8YqH?%!1omyyHl?Ww%kC8iV9}?|rYRu4B_)or(#z6@v3#*G#GW?HPks3>OmFHO_mqk`
zN)%-r~}Assa1ciZ^gvh?9fQoxCuR}A9R<`%>vZc4HXe_|Ks
ze~a7```fihf~W2jwaxFXAqDHlz@
zDhj)}2MVd8=04hRWeV4Jv|+aEzS?kQPS0!
z?xQ>{L}?L~ciV!?@E1l=)k(gANr4M-CHkgWa_tvG*`aXE6XtAm2V8c}`N(cQP7mdcZxDuk?i+0f@|z
zw0r&z<6DNb`}vDM|NP%KT9ZETU$1J2I~VID1+O|ZdzHWA{jSen;$4f0v44Em_b-Od
zpI;iSQ=OjQzW9Fs-+wZ!PqV+icxboxYwpk9fBq8h$_#`3@m=4)7W*1T{UH(&rc7??;ipLS)qIi%$FBbN}&6yh}OYetg&WFUH>c
zFO7zbcI|ubKi-crg3=3LUv%34?)}Fv@vbGk?x%Ns|6=UD|I+6kqR;;J!T0O`{!@w)
zHpdShTI~FzJG|fZ`AfVDNoRk4)%OpEzWWbf4Ciy=Ki>YlX>Jxeetpkr|GVoSzl5_0
zQ2^`bcYXh2?7RQcSv@O4e@^`8`=5)B>d~9u9NNEJKA*q&`|TI;^2tb1{cy+hh5Vt=
z#6RvG`_12Pzle9mzrE%2=J@;V7m;WG+gm<4_}_28h`iHjJ}V#Z`rxO3zx^(9vVZN-
z2VeX9?H7@w{6~*IxXj;gzl-PlKi>6m=Kp^CT|969HoDK#_xIZ`;?Doqw|ty~zu$fl
zck{o!<#X@;{q_sa4uYVtH{l9rAp@2M*_ZO?QV>HoNkCZ5dI*ESIp$4%4rQjp=%FKN
zKWY*qKe-BMGwCiUGFqXlo3)(*d3&Y@=x5X@XW}GQQ9qPHk@*kb0rwQTf!GCp92qFU&O%3%?fs~rnZ@E+M%ZV=D1W}q&mSEHC2OXx
z*9MP*QDB;UbS@YlTIGZw2plMBV>?#nd?>q825JcP
zlTi){y@3llFZK#E-=R@2v-eDmP6wy)34
z#6sPOHe>1fyTP22nJ1U~gP)z$ma#jay;3t*8FiFZ#cBg0hf|N-B&Bi!0CPG6>kfp%
zenHIdePR=I#W&>4AtFg2zd^q+o=i*2xVWQmS_XSLU+ue`Mgbr54=llo{$j6(a@Z^FBZ0l*EB&%pSTfg(y|Um+V6TMr1@_8<8!z_ivvJw$$NYG;
z?_ae<_IfDBUWox7hrJTIUL$)YcpZnz*sIdgm&0Cx5r&`mvR8%rUG~Zlrg_;bl&w7?
zdu54>Fg}99$7Qbony1KJiA=ZkBN~qto~LtH#xU&2U5Wp$hr6=Q$2{B>&6Of|Wz<8v
z+?By=`Eu9OJ{$Q`#9dihWF78GJUJx1!(CNbMT^YpEFLylyJKPo9Wv?EdK$OwtuG}sya#v1fzTB1QeJr?f*W13!X%yqG
z=MBbP&o>TtJ-smQ%3hAkT{(^txvRo;YIq_uX2ZEF
z&l9;TilV%^YZ=;Qm%E~(Uh0v%9*T3<(&Z;}?#fDv`Eu8S^+}PtqN*Oe#m-$zLlWC@
zxNCvL0O{v&*GqBkS{Raixoc5YcIU3D#~8UQ$|?4Cxhux8`sJ?A@;%*t@gtv&!(Bh;
zN8A;G4*kVlo#Nb;F6Ue-@)gDc
zoOBMn6~&r%;H`@;tH4`~Pc`Lln<;7dKiMYmFw`%D+Z`}|gU%VCW?HPFM
zmJj&wR&U?KcqqnOH?ft6x8jTa#alN$gon4nxPLjT5AbqUpv`d$8fQgT>3lh>&*|Z;
zOK1T9J1RrWrcy86!Svf2RPq52N5RLK|^LQJI^)A4YNaju^$~
zUiwYPF1_M$dl^A&q6!1(T%rPWNO|m_q9Ez)dbkAk%36m7oIxEXfvp1g^L+w`$XNt8
z%4~r}a2l-(#AhIlG#1-f#BJZDG>Wl^^9ExP=NpGbSRaf*a5M9c)A8pRa8eJ0;2>)b
zPZZ{&cLsq2l*}Y1&%RQNID_y>HvaIj2x1Q?&;yB4i~lSPN~F+G#dzF5|De7JHTXkl
zmANGCCx1TQAy+iee_M*f^B-R9lp~z5Qp$GyZ1uq<`v
zXXu(o4h)Lnh{b%?1X7b3EL2(=wN#R+JP(uqV(AnZ0fv&4S3sh`5s;*gp{*52a0rM1
zKx3Vm5e57E84%p{h$o;eFfq~L^9$sR9Fh-#$C{00!XRN*xQkA^TM@HML3lS_S(&{N
z3k$0tKGBvqt8iOq9VWpM&f8
zopQc)e)XMldCbQsh&ytcy*rGIP_oQ%4AxkU<9Po{h!<3P+i{XQQT|a!Jrvhbk!%~K
zKwL*fB5H(^yN=o^l=PsZB6;;}S4U;a`*d|wWaFl_`RJ&Z;yP+)@W9nk`4vhpQc^pm
zo2aCs<2j9^q#{9f%U4N7+KW8n={(bMl+@1&(yXD%O1v$caObQmUBw5bjB{D^E?B8w
z7D{3>?q$J*CZnIrf(cE)`t7n{rVy$~epx8LOF5SXvX7whu3r{NATx2O&SlYATI}2v
zNJ&7E*6xZ<4iT;jW?wGt+!big)X!aU+kRJEitY-&foxiL1wO%bK9>bL(f2%;1=29@
zc`pYf(vbz&FAF5fS-~pQnXxsW%c8U1*b0|LAIhucmj&7>-P-~)xlMi0ZGqKjnA>w(
zaDB{rjoSk2Lz}hT7R)*{dblm{l|9$FEtt?}T@3=Ok>-y3aVi_gc>+-AK*~%=ugwx9!)(rRcio)Z6yCF1kve-P;10FHoM@ZVU8*K1jPRkO%`w
zAntX+HOF0S7Y0VP%&dzGgS(Kt$}bEiL#q8;7?`Qr#@
zq1`Ru|5D)ho_eCI4Na15_+pXKj|w@HgWE27mL9#{ITxTBk!7fM#!j_;YqhhR`=ghV~80KkX75Tgq
zCiB%JFHoWh0D4N}7qXm}@B8VnSg8
z-x2g4bKQm+YX{~Yc?j93HL={pM}tH3p_M?0w(fVWHsoSy2ndNhZ6r-#_Ki!a>^?3NKZI5+zlM&mb-`5zk~wKLyKk^~~I&`W~KtcDlH(bqg}
zZDTt8&l5}j*z<->vFCn+T#61Q_2N!8OiA9ixml>qs0hu<qx-^Sf1IA6g=wUy>dCsnT;a_f6foD%Yh_Mv_)**GtZ;}
z4FmHa%9LP6U;v@XSAhgb;!fXIp>hBD60Tp<0}%F%tnY&}(&$LNZN+ln7fwO){>oSC
zz-aq3@%xY$J2MP_AS8n`(wL|esk>Lu$p?5=evO~8Yb`th_mE}`*;j`vysKJOJft;8
zKphRU=r@8}woF|>eckrcJ7&VW6eSZJv;#=$f=LKDO*N8KpDN
zYTyT1&WoX-NT#LV(&JHM5?#<0Z0TW;tetZ6kVzEn*`*8D9-4_NvVK5HR|Z79QKsBR
zJRQE+rQ#@A`(S*KthM#whnVSpZE;+RT`n8PTJh$xzvKR><^G%rMC9LZw2QKgfEn1H
zQ_sQ#6qY6#*lCYs8M!W{(DRQr#QdRP8oI!SXXVHDh$o=HTDaNhE7w!V%m@sWNRyc2|x@ZZY^0RE2lXKRLX<`Al5eOwnGJJ~Zxo3c
zT@oHTk))wNT`w|0A3
zJ{Lm^G`M)&6XN|&>Cz5ao&?eiH0`;x4U5cGgIU)G^Qg)|-)tXjQ{AijU512JQ0UF2Pv#!Vl=c_In#h&PnX
z1)9@z03A7`{OaliSj<_iLSg@N^>pdOm|*(?;^^N%=}hqT=bwpm>-lF2e2AhbIVUgI
zr?VSoM#)X!Mv!2-v1rDb4n&m~$we7+yo9FgyMB?F{uiq>!BLP*!!`yG
zVgveQy4JYo7l7O061{>6vvJAo0H-h7vW5;sIStlxE@IovnKJ16UDDp{BZRXI)$L+8
zhI{+0JvYs@Y<2?<&rs@9uZ2>4ROkmgon(k-c?xUtZb1ms~F)DDv
zVPlXO7@hu*GLl#iOnzt+T#aM@?5;EuQdiW%>fLj>;w+HwbRx-
z)fpbxOyuVWT`@XIb2PH(bNgWwOHu=T&RA?rm`M>>?3II*fwe>y
z3IBUh5@^hOk}yqA(Mtl1xC|{ouJL>gO?z4I%yB=OlPcusWi-iJPB=QqgH(}y^j7|{2Yeo}xa!8wnls*adD5tG)gD;*Z
zp7SmJ*WSR2<*#pG=h94Py*O)C2}Jo^yWe8CTl&#KI~{>I~3t*rpd_;sF`@X!KMYM
znar%b51?k!xpKwfGp@@7kdb1q@I+H+ieYNFU-}N18cwBI#TR#!-LHnJx$U!@PBBc)
zd4pkU&NmLG=Jdi)HSFcOm>G_vMkEAB8n6-5Tp*6B!AZ(VDi8bARZzlFHD|63R`a>TP3(*Tv-|Z)Y3)PE(a@mFI1@L-aN2*>Z*sw~Fsu!}ho0g5)
ze&peEh#*xj7>{!fQZ?djdp$z+qI)ABp&IR3a}cU0%*iEM`$(Dn2-Rq>(p;#X$Un7$
zOg;Ca?Cdf%z9CSAWNLMC1)+K&uyn5@RWI1k%?=N#dZi^mq6^iZ(@&v#0U2hzh_l(?o71p(I?!5qBtCxE(;JRAm-VY;EG?{VlRVMX6=gkX7$`rZxg2O+^
zCWxb_AZgrt0XEnp_g=^*m@fBTm4$wdc`sCquaS8#+`#iNZ)P&ihj}CMvD;k4yg?B{
zRLmRgZ3t2@@6$f#4ULu_Ay`9jZu^lSvSYoE`{@8LVo2ubUH4abz>&CT_0fGXQqvHf35{t
zH*)dUdbF8meQ*JQfjRXp%3(|u{H1>P
z^k%`5E~sk7x}BTZUU0yLK9L!DWPK3=7c$l;L@P
znXwVvW#9?em4p$*KDlij6#YUJ)zCnjdNPa_&w=1K=twT~UFqmZxXd&?EG8h8j|xYM
zM<>Z-Rc5tcWOE&J+)GuNXg_-1eflt%*AShm^ey2uPOyHJjKyIE`sy^5*h|k3L8vQU
zR}{bi<3iCi6)~9Jhwb0J6=+nKHY}=MlNEyJPL@>jrdSwbbNvDMuam+TaP6Ta$g;ro
zoU|b`lN0mu!UIV$rZCJyeEndwimPEvB1Q(Sl~ll0mKmP
z-HhF8t`@CP4l!Kx>&qGqh#_hwtSZ}_AckufLn+F7$1)4ku)g@@W+u6dFx-%XyKp{$
z817{FKZ6)PQ>Q^3j3Ej~0Q2P-!=04o(J_X%?HI#L5yo&^)kwz};v1t_+&On4dSTKd
ztZzGI0-w%By_HTnT;%}IhHxlUuGquu$zY|xX(U-d1TkE&nHMoeIFT@O(*jKaF=TrR
zh$o04R)ayi2V%(enL4t77-D^<^&1ewwX=|T2V#h?PO};UVu+~C
z)-i@y#kUg(u{pupTfDK2c9;u;vq45~Qo7+B4q9FCZ81@I+^Jf9e^H?Iua?q#a4BMnhEv
z96g~75r;zSf;We$+=s9Pqr%TEZUrz6wx_TIDh}{a>Mx5}B5WI7plhLs0i%mdYf-qz
z`3oF6>0kW8WCnv_p|S~bt}cqaY}A_>g@)=DabEbzM*lPCEeT?{2r=SZ6A;*ixx~^G
zxjd)ZoAWrvnc2Y_8lVvU%eMR>Ro^)6w%hrI8G1Q2fR}Km)A-2UAUBW@q}&kZgrQiH
zm^)rx9W6I-#HY<)utZLH;yGY!GW-bhVu=?9vp8$+#D%HirmmX=Hqyy9>kVTRtB$ij
zbdMuu=8qOMSrCc#m~~6FE4jd3(!(0v7t|uvnPVn()4>eSjb1flh|>m^)K8>$ZnlDQ
z$?71mSfn-i{P<-K4E>!&7HMlLO;bN~m5ii421!P)PLvqPNWq?T`A}6$Q@Ms9N;gd%
z5Ib58raxhdcG(d$h}ksR$#@$nMRtAU)MmTNzSYs2(;k++{8ADD2!AdG9*aHo8&kCy
z)P%NYqEKp^#5~qK;>6V^+Jhu4l%@8JMlsICD-wjf%V3lg`_Qgp8%W*$$=jGL=p32C
zR1L=Oq;A<6>pDSMNd^*6d~mjK)jf_u%x7!wC4nOoZKOe^(|#7aA@Usixr-g)o<}pw
zMYX$eqe0*S!D6=IyTnLT7r1TK&9onMSvlZZ6*tlXFzOa
zIh9Eo1WjU{j!uy6}*boHtLsS(lS!;*N9QeNYdYScw!k^21W>c6WWNb
zn3eSl6O*3CKhZORJs`yVHSsd?`_ZO5FL>>g>eV3qwV3ROCl2tuyDwDm(v
zB7wFgt(y=lkpPgeL$$F|+4R8k1S>seRou&zUQttL+tZbN2G|B1b|eF&z}DooLYul=
zCvt(mU~wf-HfD{v|0mOlQNKc)e!FKet7?XDu{$UN(@ER9
z^i^9D=2wIFduz#;+E_bG9~2HX`Fx@n?|)B{Er3-5%;#fYDotBMz1J3%fz~V!i&a4Pkv4sf>jRR^#*`Dz1?E-SR+(FRD_R~tZkU1i`l
zO&4&2sRC%$b#(!5h8}f+M~D4ofwI&E&_grHQPOYBv>0^(jH-tR>TnD`bpcMwj=BIR
zE?->$+r>c5)CD-vIqCx39yRI$pzLyW0W7BHaH7eoW=Zx(7ii2!adiQFWwfgcpjVd7
z#B>2HU&>b(;PPF8p#dfqFALtFDuAi)GpYhOo4a3Cpf!8HsRE5BE~)|z
zr*d9Z0PR_>D$r<{i>g5D60uzsKs#sx-aLwc6OJBW1XlyltXB&_v+bw_fI{=AX#owk
z!FII(v_sr7r(toL@3o7Gu~;nfc(lv7TEGWWqZV+E%FzP20PCs&+{yc@0ga3^ssUK=
zm9H9rt=#KX1F%Krj%on6a=U5(wsIRs4L~!Es0MJ?^{WP;ZE04h2AsC50f%5}0NVR%
z0c5o+ssZSd;kGqO3B4}lV-t_tHvVq*WIfUHFT=42wAd=I`l|+zN35#{V5Y5)!+4T8
z$Se_W8^0{o7xe&NE7t?g+8sUMV>KmsF|*=T0$P8`7HzOz&`*@30kmPNvuOZr49W0z
zWK}LL9BHtV8vb7W?^FTW)M{T9pqV?$b$~X9w0YA38oXIi1!yePepLXp`_%x@B=a6&j;(A>*Ul&b+8ifI5oQr7^Q*&MD0fVr`rQUl;zT`SYm
zF28D202-s}t^$C`Z~2P%4I^w(0cgXp!{>>vPnrVIc<)99ps^_IRR9`1u0C0>IoNF8x0Z;;LP?Z;Qpkg7n{*JT^YDf7K)WqqSC)|C4@xQ4O*Af5GUYd#~QCV|)HGsD2iBGf>
z2#3&1C%~_2j~YPRO&5e|0BDcHJ)UN#WPUXOP%PS9w*!g~)~f-uEknuG0D3Bta!xmT
z(%WOl<}V!+QvmQM8(3
z71oXdfC#5`6#%SWdno{_9fOB_M08H&(R|Viyzf=Ik`cq9Z)#5&#q&I9$g^XGBmxdb^_65o#sfRMKlRDdz<
z{iXsSWX_TWn+gER4k`dbU|UcD&>kzQ01V45R|R0??^OZ3c~k%=92LL_t^z1>`04_9&;b~E8FT=~3%+y!Zsni@pq;M{FuK9zj}E|X7jytd{kE$EoVM!#hhRDY
zPe)J!$Zls;0?^Caj}pN17({$*;~?@Ik54T=q4f8z1PrD?ib}vR7?djkU?ce|0Ses=
zN&q*1y-I*DmMZ~g@s1Mkv78dV#+23T>H$u@YPtZL?WGHV
zGRn~f(40XRIBnMjoDfbKWT)~I<>~^5V!8l_dI44$(VFX}3xLvsF2KneR~Hz&MNI%x
zn}a4WSS0z%`G{HFFHK-D_j7mxxTJA40feN!6oIjtu4+>R(B`t4B5>MA5pYVFnfK1q
zcANl;l&A|#)LN)f7r-;~Y6BBklb{XEBt_?H0}N!%;fb7&E-+Cc;H3*ZY)Phg(*@8T
z?dk$ESKew@7XYPRT>wo=`lbs^L{z+Vf$8o9(*@ABct`32XwR1}Fqx4j9zhIqymWz?
zyR@^TM7?EHTusm}x@T~A2=4Cgt^tAucbDMq3~m8JaCZpquEE{i1Hpm@g4^N!&Uf$m
zGpoC*_fu7S_RMt8s(R`@st^{o>lta&IRV8}Rs-V$`kH@EX*=H&7u-ONhYEONwHDsT
zV0c$wSEN^4Sqor0T^#>1r-Z
zRYMyCS|(py)!NyYVMK0=-9W}7*W=;4*qXKbmM|h$R`QiA99v0;=P(;~`^z1%m|Km9
zJt}=2+ZVq&Kud^x13jrO+l_V7Ps&M8=ka%5P07@GA&hcpVfAJI3QH|ul8Z=%&;C4q
z|5q5{l2thqpVLg#Rq~P)I&zjrA{=^7g5#U_TJL2nr=r~96u+f^R|fB7@kjMzIl}p$
zS^EwjH~RNx#o=>tJ_EN5;=(?34_bn27=j7IvvDh<*e{f5#j0pYJ_D-7-V24LpF+gG&GX9Xw5)9du6y4ou_WnoN
z_zrxg8tgJK$fcq(OIxL`7T4Nd2(uq~axz-Q6FA!{uE=ki>VrCl5uqCAP;?{cg^&|X
zaEXnUuWBp&-(K|HJ1<6Cs{NyUyXdYGBH_|W5wiVAdrL8=cagc)XPt5Av+Q`6e~s=M
zB>Ry`8SySfw~KKO>x+d7&M!wQisJA8aPO&nTWNldR{JKWvqvYV+#%1C5S7d3|JnE^UhU&k>xe@T__~nY(ADrCEJwKw-2!$jP%!?bf+X9
zs(84ptzJLa&}%FeRSlEm+KePzPhvinF~z{68?Td`jZ6YqMYg6ol8AX>
zb2{jxqa}(Sm2@8K@eT!Y_>
z(ML>t;Mp#mEQCAMAoTmqFHYu(
z7?C?jY(Z0_
z5f1j|Dr$U9A7!2EmElU?e_#7J)7R*F$2`3HCZu~`t~C3x|6(mF$)=Kmv}Rb0Jg=PF
zyG52IZu;hkI*oY7=SbrI3?UER%3?NGL1MKfRyTsdZSx6=}ml|*F@V+XybOe
zd^2;j!rCzMSZ8E8acwqDcDr2n?&9qQagkX(boYt-X{<|}a9^Si->pK)uJ4~z&6_Nr
z->7=O6j}S9Hm||7+DOV|I@+kEB#65wGmdR4Q~421HrtYplfFmUI}s#=tXbZjJv~#M
zrHt2{J;*DBL$!A&6aBBBcd}z)9DIO+A65CjA|;$oBo3mtXZP_}@lv
z|Hved(tFq;n*6b3=uTy1jfA9=d&hL9s4#;#}0>@<_+YfTXqgP|8j)sWgh-a+{x8Ilq+kMD#_^wY4#Y6eD44
zyI=p5B3>%NB~rlse_lqA@O}%gtNAl>#w{@ti7t)=
z9Tu!)i77PPa?m0Q*YapA49r_4iAL;Vy&kS(9!*_tqtFns5r;yoRa@b|zr{*mz&C%g
zOaA=`6A(mp_lE%1LC21VLF&WQH4+;N%J5n;wVq#Z9#_fmFT%@DbVc6flk{1#9w}<-
zxZ^1wSu*vTq-FtmRkM!jgJ4~pL1=Cq350hMRj9Wzcw56&p$-u(qrJBu{7&%}g5j
zk@*FA7?XT}1V*<$*e$7}iSOqpq^9i;9r?N>ej>fj@U{yI#>+KeE78#oE-OOvgT|Qe4@D
zfCGAshC8XlguR$=9UaDG!+lfNIICd9wS4Mn+@X73jTwHvl2=)JuSlY9N(g#Ha`KLM
zeSpUP6R0AgI>{=T19jD8Pcx`T9l1FJ-*Ha!I#Q{JL+2b@Ew_oL!F{sZ`K}dyxziZT%12L@=KB`T2udfTsfwiXJA!AuJ(;nYAri%^H5Lx3fVKW`)d1e|ad*7M|s+JdEt!6+)
zhhG&^xtP)2|0Dk=%dm-ZP()qlXQj@n(Cp_RRR%0O8>C$nO%Ht5P5R1s-Lp9V+bfY-@})`D%Hm5PzZBEo_-*J68}
zrB2!(ir}cZp$VNCf!h6YDwyCdObCrW(+gqPmuyOh*0HO6m5GR
z$1UIWJmI&5e(Ri1>>d+~-q#CMgBUbCf38Ya1HMeZhE{w=eX$a2a}Au2q0VpIAg{m7
zax6y@SHDxsM-y6S6ZsQc1rY_>>y?&nu_
z5-q*bH$h{t3F)Ab>gNn`zw5@p%#wHhGzN)iJmXk{&hV!pE)dne?dd?40Y~SkN9@gE
zS1hv1pCt8(%--f|fueF%L4~4kwGjqAG9R*_UKAPD!bUZsT#>VF
zaE;H!ME|yxG4~q&-t}#WBtGynhxL^J?M4Qlm4tfah`mXr9A(paI-jSQhvu^m*~`bn
z-93<%esDS8%~!am1fvF|7-|UhqK|-&`_$meE_HcfdqNa=|8~SuHrT(XHJZV%Qz--p
zC>KdjYnZqR(k2o)H!#7|sxO&cj&O6mEDE&QT|_vqvfE2+mW-|whZN82R*d{%Df+CW
za}XC^r=>=?*hS-OeFY|hS@R@Evo&9u!PXKAW$v1?-be9#Lq>D>g+CY;@ziRgOtoF1
zXNQY_^rMbtv|N5UaBafPw7pT40fx7^)SND$fX*7x=Z9a}szkprBy9;nUqu?GZ)Lcc
zGEMQWneaTFD&S{d@Kn0JV$KI;clDwje+h{2@AVKmNb=7I3EhhVXI_wk^Hd@;wCAQ}
zF-cXT)K4CF8AA3?ItO#2x&*NP%Je~8#fouRdayy+YoFDV_h-ke3?f`IVRS{FIjppJ
z9{Kv3o08HFgBWVuRIBR1LCBUAm$Gf4?5W@IoKq#$3R5<`T<&Jq(o~zC^Uz;8PB|^Q>@^0UJ>iE7?
zN#nFVUp6%8P0E$s9sN57L*JF|n-H4@_UL|Uk?O64iHIFYp;etx#3
z`V#b0kRYYGenncrJ8?&{Mw;-6iZO^llCnu2N)B#_2PH^llKYB9co0+DrTV*A!os!zU8m=`2Zj@~uo)
zo3m2?(B^|D}&iFJ4T4?8_w4)p$%tQr4X)<%Uruv`)C3#wAKew&}r>V
zl@nZz_NAqJ)QP~)Dz`P?Vrv(Y3)kCO*0Iie%j1P|zuZ4v^~?{b>SSD>NI*zq^+)(a
z0MWBu09OpMYG{N9dPXmoWrn&RZ0@6Buu5+t=wSh;CHWM9R_*XWe(T|YNGMyslWcM>
z9URDye*Si6&cXuTxY<_F-1o0sjgUypz!^4=xL;|IWOX`HWeTR
za*TO92(Yt}4YUoZp@7a53dLpnqwIRW-S$qOX8Rv~+W1S`Mm#fP^~{}Fh;ZBg(5D%{
z)2GGz{4aZ2nQazIREeolBf0WAZxPlxcHw$Wdt`(Q@9+GT@PGM_;Zhxqt>ojed-|gR~0U@*nWIUxK!I+v_
zZygS*DGM?Y7t$*HP
zesI2m)}&uW#~Rc5pn%Vo4@-6;j>h86vhUvO%1|GHbc~?q$H;H+jocW)H#S=QSsIH1
zM6Z@&IqkD(?EA1%xUe{T%~T7!VHnty$gE?UJOC4I;AF1-i9Y(97cvc0fM)m8TqWh=
zb+8>rZ3?l!WGr^b*?yNSwz+TaQBS8nv|p3r-#kY}!PH(T#E4*d7otduLy|T>e^kXk
z68)byGJhLo-N8rGV#zg%Sy0*e#^FO7jl{n$l#}G0;LYTGCau8?`e1F@)SblCGHpRC
ztU!*O#P#yjaIF<-dwwFVGe(E8GS?yc4~arx?T^RL?nk@}62v$3!AETvewk+>dL6!_
z(bI8dJu%S*-h(Ldkp)eE`c-%FU-S{_hc>f(#{75u%rphX`I1lPDSXzfW5{lY^YkXS
z(O)&T=`}I1u<26vXx~YEzIUJI(wX3#YHid1u;tTze)N>TU-Z@ISy|0eelm{O@8YkQ
zm!11}TLS+};JYo3Xed3lQYr5Q9W*6{HpUlT`fGN_TPas>mt=BlkZorCoz~K`3W0X4
zt{ej2fZS|JojghrdT^L*yKudT3P~kg_cp6X(-Q6Yz=Paz4qeShQ^}hfn^yI<=BEu(
z&wsOgs^|;PNPtRm#SP3!ugV33huflpI_Dy4^03ztRcST
zNf-)fcK~9|I6^3&T4$e{L0&0FzhBTit5ou@ugGUDk$&t9@1y5n;i%2`jBS|QB({Xx
z3df}4`qDry!!^ewu%Jp`ja^A#-bT$+O}DDblCl|bBzbq+Mo^3>rUo|6KP4Wo=|PLpxj=O
zL69x-z+u0a33@MZK;c}Dn+Udr4c~4QXMP`D@j9V0$vd8l9uBGixb<9GG4l&l8)Ro?(eGSSEk{79@ml;Ju>FWqFvkc_oydkdBLAyS@TX~^Qbk1Jrgtd@xHNQ
zDb{TFhs-@ek;i$?yWVGmjS|#D2P3B;qK9}e&Sv2|a?~ojoEP41G3axU(6+FBi!RNM
z8Sx%jI_t3eZ#AIBr(ly%WxHANV8wNpA1;l{IC5EUzsj=4=omRSR#0*FXR!|Q|d8S+zDm$06wm=T}Ic~yqP9ob4t5Hezmh1tm|=bt&#qE7+V3}k9h
z#w>OsMvk#3#4ryFlOLJ!FN$7(x^;=32n|Vyr5zT0umuBGmnQs*eYH7fg|JCTn2uJ(
zj%9J!Z5~5EX`~wF7wBskNhMi^*DAFxMg|NUdGGn){GqTUr)oUr&rUE};y)C5>ycG2
z4OT_PD>;>R6yP~`g>gOq*0bm
zuMWe;4M!xr{g}w(m0X|NY@_u8a`aN-mZmQCm7bT-quE^Y#FoN?n>+A%LLcOwcrXry
z{C%sCga@XNv6PuunVt-&GaZiIqLT4pPY#@#P>fb}dDZ99Gd=c_$Xo{?yLbj_=rj0@
z!{P~y@5v2z?6iTV-|{hg#VdB%G&OXRVv+K#(fKqxNEaoB8KUd`i2^vY6c4&0ym9U(
zdbFh?4`PtDFT2O>O>|aR<2D+;7Th_62vgnpw&Z`BGWFD(9z<)}w9ng#e7L!_6Kl&j
z^O5we@#?uzBQiXH>3z@_RRPOhgdH_rBsul})vM8~#ag^+$2Vri{~OLZc9PDQYRM&L
zxxm*$F(5KNObD+s$s+J(qg7l}?Sg;HB8LP3Ss#9|nae^?-gOgMjnUXmGU
zJ+Rs_OY70PNCC&4f+rREad5JM(Fd1H9L^RGO|O!bCCI(VnF$U7>mbG4C2X2@t+K9`
z;Ob4~qI5M>6z_!WOe`LCEnT&&Agsay6dMsU)=_y!r%!1P3-t`_w^w~fd356Ac=t&jm)>VKk&H+&
zwxK#QZEI@@DA!%}L;u(~M%W94;b3Lt^xmL){c?DOJwG|UF!ekP<`RX5!;P6B
z_OxA}Mc*3#i86MrFv7r*f}Uga26MUxg0IvFD{&=tFC4T_oF%(>61RPyZWP*xiMDxo
zu@2A0hdL-qJDl*2pRsc&-VlHa9;!4pW9Ak~6?6B=iQEp!+=gjq)bY~EY74&kGAxUQ
z-6y|dYdB%fUJ#ali|5iG%tKr*lO2@4$v|8DZ(PLWCr{YTMXS`u`;Uf)7wR-1i>7}@
zsF{nCbvU`@q{{9Prb`bo%ABcU)>c8)x7)poNb|Iv-rS`Bs0!YE#geoGBB8k`0_cFXQFj;0$p3{hfI&-hQvkk8kk{Wcc@#
zs2Mi@HjSpa@?rbL*ZP*B8w%$4_Qm5p^;Q#=&-1_P3!|^uckfgO09JiZ;NO=3DqBS`
z;~=ZR**49~9`D=Vlndp-fWZGSx3|OU*IE;H|KlyNdijsH;Fn&Y&;LhAF!XIBA|W8)
z9id1*b8G^m=cw^*^C|wFQb7R{n!9!L5>t2gs*w9MiCmIP>eus%p&LC|7=}i&)?=4G
zz5P6_*DZ?E{_^oDz32I|x=rH?N5HJj+tNk+|Eiu|#6u?S0?pXAw>6OTdmLe1t>5M@
z{`bP0er~RGA7OfdYmA0~ZuAR{W{5zk;QbbYXwTmDQ0tw%Uqr)J?)Kl&F4p+Ku72&(
ztzWXId!I;8Z#XuVGrv;5C^(9&tXTxqcz#fL$nAPC7EHzH+A<%03hX`(fzdBP-~N4g
zaOmux)8#8+bWtn(%zAOp2Y1&v;CZj~{6L)h^zVFQxw7~9O5gJg15efC5uZI#wUJfZ
zCQ?4%9Tb%3nJr}(r6P2N
zcH68K$r4`P8TTk8T#ic@yG8NF$(4gMn?sOt$_|n(Vq0xnIJ*gdE!JEFB{wtz?jEZ|
z6I^TfH=()6MHo31+~cLg0Q$fykcjt(5TJ@4rMTCS
zDEO-ZaZOm6yh_qSM5~;erW>g$x&n?w3+^Cy)X7jG
zB%ym~#KDZg+}awV6KGJ}pd~m_LmQC)9M((WMx+^=!F4WCh4$^0i>oEuUw=?h<5>0K
zTlqi*L_}{V9S#Cu)xv+p{X!)3zSpdqR_f)wRXG6J>02IVlxwu-T6p^eN$Vn(g{}u!
z2Yf)gVu8v>2m@mAP=-OOCU|%|g0z+yW{{hM)y`~;$_e4GQW){=
zahNleIuJLK_+YeBIg_NMCe@-6-X|Eke|%QjdT1~yQOtz1*YW_mWl9I;7$x)N;8rb9
zyweiR7MB49S?ojHxCz+CDi?mDQT^3v*_59#rjqe1%8G#3S;VP!LIQhTcP`F~;S<-v
zQcesgUqrwl>IlYDE(78`3-7P5=42h
zr)7ksK5^PL8aA}IUQ?@L?PFexQdGER#@zOt|#qI#ZN*&$Pd(Q#E9hMOqaa;3IeZ*dRch
z_~7@e(-QVIzld(ate#10os&9JWm1#ghJ6MNzyF;&{zIhS3b9m`Lp}U~LlXl*rV=E2
zeejRY!68Y63NH$#1{GCF3O6dzK1n?J_s`Wh^kT6g_Q3aa?SY^K7Ggj0PZIMSi3@zR
zs+e+PA-=~-R)(n(WloH8D5_GCJ|8q|x`iSl$`&f+dM$(h&7d66`*|X7LBfB<=6oi~
z=Kup_PmM#z@N96JX>KUhYx;xHctQpNmUNjy(fA=BCd?zhLPP4j)G_D3vn8Uq$YTF0
zPvr=vwOb_f^yO*W}_Jn|0@T6=CqfxG2BF%Q((X4D+TVJ4+#wO#l=jF3|*xOc8
z`Cr60;}GxWr3+<-?2gmI{S8V*WCQFPMvIr1K0h3-?1i<2-cM{+RB#=}?yZx@UVWtBex#(yi9055Ceo4Sr
z^vn4Q==Xl~Q6~WL$CM{N0iXn#Wv&9sjl%qK7F5eXRCx?^Awc=M0hlDeR^5T-bybkV
zJQqNl1_nNheB&+woUl%R0LFx3p-wQ6>JC2~z%Dq+QU$2JL}Nu$b`uED2lZw(65v3l
zg7dXNM~a_Y;$a~?YJH?A5Wzi@4K1i%)1}#W(V&!m+7}?ZH~k05*!!>{ts3MeLv67P
z%#`vM!1g)|bvdB`F?W6^BcL<{Z1vXf;Dcz24$+@f;aYILxyWD;k38G&MF0
zY6a3#PD_zyznmQbU8Vsch>$M*M^#X*dy4~oIbbar+0Fp8TnR7$Jc~+NFk+dC=RbfA
zkEe2Ahy4pF%6rNq$SHXA&0PF!?9H@Z@CZ1fJhxf~)yAG&E8zXDi%po`V*q6%zc7Gy
zK3m_3qKJRD6E}#6_RD$?HTV5N2n{!)29#D%UR{%bM;iqZ
zc_8c9_(utJUQ}a{76Mtb$-CMf!l{p7T#I>LQ3wrDb8h{FAl7kH2%UAH3eLieTm77K
ze34WEO%zQJ`oK7YTMd(k!nv~uKKeeTg|uU5KrJS6Op*kdf?j<$2R-+W_t$WtE)Eky
zt=ASoo3X9lh#X|m`~w=G3JGSYhDNtkkHg)WEQI|)t~fD#FdwHs;qJT$psyk70zrh|
z|FByrM0My7$r37F+k(X4PgVP|5<#@pFm6fu%&JHLOc|~L5^w;#a8Zk`B);424jXoV
z4?#cb9hxDb08i%dfdVe59U48KjC%05Q$&rJA5XbQoV^K+&e-Vq5TM
zchPbxLO&C
z0u3sMM{qk6Frt8EGmNa5TJzNoJbIS(RYL~q
z^=EOuCGGFGf@ciRTES`NH~WZk!Lh{ed>`3+?ch#-1CR_tHBj2h2%O>ifhJxbTwoy_
zckZxcoL{=5fpt^(b7W(UOoB;AV?DN>R!&H=TQ%oSNX0Dv&hWkfR4eo{9%Qof`UZxr
z%R8nUsC=v*eisN+T3uEO*Dj$x}=Xd$jI$Z(s`N1;n>#KST?EA@mB^on2kQL6pCqp!Q1X
zktW`Xr1}4YbGnN^L8~1Ucm<3)PtfkQmGF%d26$7C(AeZ__sMgsLa&s^Zs4fK^p;6`
ziPnFeQWT$$6My@x#Vf>qiqHn7@=cmX+7qt!VEhI)FAvFF=Nc9meXuLrK`{&`ar>Jo-Y%Maajv*0gi@_5Y=7w^-9vmY|PI05F8;WH?2_GuO%{`0FA6c
zvLGa}sYVdOAFJR7XYAwKa}F?x)hw^Xcdoiic|t6fx|J&}cr`Q=>lS_ze}nE5J_qcg
z171K&ov0v;-HFb-93HCdDPbRIc+L;Alw^59zR>XK7t33$R!0BeXNp&Lv6zYjguwV;
zyf#5!A6J%%fj813ZcjLKoKci>fF_*zU4lpc8Nm~7rlY4o5TZ0tfnXkaIE+X3P4XWM
zoA1pD{9I4Z7Iwj72rCdUDpbu1sSO#I=5Q@-K0>O^YCT6X4pr>w1}r@tX7PHBJ5yPK
zAc5okW@Ca`On;D{?t
zF+LEUPfoCGtR9!Jes&6F;IG|Z-V-fbNfddi5xLsosu>{GGq=HD_SObc4ZtS)&)_4O
z?Cgj*j+k1(3G>JZ-@=^+%r~At`zRwQsKF2zTj|vF6Yy5|7(`v4u$R!>Z+@dtSa$*T
zTVTcS3Y0vQ>4q;*ik3LZpo3~#Eqt+O&e+isWHKCe0#$rt)Ebv$kRtNgQtyk0ZZs;yU
z^~TP~zRzh%NbcWutEm)Hu;I?1u-&1pFsIlbk(;VI-)*fq5hh~S@bbp`Q
zUrB*KsMBL07#}Mh$Wrwd$CN;!vpS|gC6`R)OK?(Bz<}Kx<9Ni8SC@$3XFjzEqW@6b
zAqoP7d|hi13f4Uh#q!ihNrQk5YjtNbu@>E7kfz&*yif@EE1NhFJ;)A3tF#Ni{+RfC
z@B!!^)pAFMxDaAMrO`Uw@0c29FhXfh)wA_FXJbH3nC*V(1w*r-_xcMFL4Pjsizdsn
z)jmT2*T(BPqxZ78Qw9U)d+lNXR9#dEki=^bId3~4%Twb%AnP5+f>s=Z2GOAn1D%!^
z@ZfSw9|JN-scP2XFbi%J830G18>a!~Q*}TFtP}M4!hsH2dQ^atcGyBPrlCbj#GNHH
zP4Q-ZB$$bPS8OMy9~=h8f>6*uI#_x*S}(AuSD>OO4lU52F9T$K$-+Y;O9|Nd6e?9K
z!@-cXwm%?XL5and91_h$Z%+=~$1KAGhFPrq2?&6S!_-@0WV+KUX%a?d5Ci5)(cs&3
z!S$O=lx*ev!+kd9{oBX%=bo@C0q>!6$8*%L@n56K*GxSZ`fX3WQEL8bS_PBOm~O@IY@#@^A`-Fl>XGsNt02&L
z2uz}00WZ!@aG77d<@Jir-oGuEB9LATzEM{0CR4t}%f;F6-C~?MC;1!KT*#Zh%`&C9
z)xYt?jlR03WzwS?qQr=-1}c6)Zccg`evZ$BNmFQE31o8dq!+z|?lj4MIqd#e2dfi3
z_)5C2wi+1ZV}A{ePOjCy5*Q@bF7U+K7g`T-K@
zhxyh>QRU*a$GT{B@Rd?R=WObAy1wBpkz+M5sY4ICZm_-$2EqY;idU60euJ6&J@RU{
z!d&|XW_k9wC3RfYGk=qw2eaH7eRgVnw-<7DfYV!s`fh0TX7ttU%+~zvV{7({l{eqp
z#XbT+V?hBVvC0A)NQB^CbTwya2>Fun6>FpaS9qWX=QGIbOOu)^bg#}TI$$*g0%$xo
zPyxPK3}EFJ9ssZr03aqE3P7KfCkEb|G9m&%Hr=rDmd@u+0svyo6afRYdQA~Jk(^J`
z1BY~jh^9E$fboGVG(eHW$qJAe_@)730vDG6AQq(rnxm)4008MWN&whLReJwizyX?W
zKwc;Sd}RXxF%BsI81UrVi9rxGFj%Y&4w}s05Ect$Oz=3A6G_ux1P^fX5`l<#2{3wv
z=;HvsmrV@d&RGm-9T+>ng!oqSgL`2|Kp^9o1r$)^fl@9!Fo=x~G;4381H1-e03Fo0
zBJ|FF)c@R(oLB(lwRj5;Vw;#F0$=jM!jeAmu|0cq7;!H_oU0^(i4A59@MYW)DoDyK
zgBc#;k_r!Meb}V2u3ioXTwjR5M2xm6E7{pcj5BqsmIW)K9Kh9FB!44u|giVBcNlgl&e)S|@{t8dhQaUJublj+nle`vS)kS;M!I)`DQPB70lL@^i*B^hM$^l6P-vC+#B813{d?g~X
z3{=-&fVk;*2$Z=#>~9)Wbm(VzJ~6|rgn**&xCvPdy+B)fi_K3UDL*-v%{YY^_5-!j
zME9MW=dlcm&Uz6~iG6?mp4F%!fz(@rW
zLLSp%f>;FOd^ofieH^q3bgpQEm~!J6RJpuN1`}@>Du%U9Mlxp)D9j@*;a-VtGaA@1MC9oDBwwQnG)AS4*hV^z+tG>{lbb{fBrI4{ec6!vx~s-GKEX5;`SlU6iZ;zy
zVBSYwh}xM(P>L~lszrs&I9G8>eWAJsK5b7sh!+FO^3Q-~B1z}B&~A@kOOm-zs&h4c
zKQz&=K9>XzRSmL^wsJGZs9I+hAW*Qd#q9;{67Fr_WXO|L|M35GJYCRR7VG?rpVHj-
zsu)X*2pP&|HYtAvv1K4E%mjDkFy`2S+kT75^*+p!&oG2unxV>t-@>*K^tEIZ{I{?6
zTCxb52Fy|$Ugl(C`Tfvzh@HbK$-+7qLn2nWB08^hwY%L=dq(`L827o54UvgQE=IQ`
z-F307)YmL%i{ZSv111~>`V5PYb=femg>2LflR^`4MKA8vp+jvF!B5K$QuS#+txx46
z$2Wek2bNAmyz=YKy3^7dqU&1uvuScVCbbqeYo4ClpxZ|~^78)`XfIZAv>cpIGt+aOzlZ&fF&_8@@kUcJR*AD??025V
zwUE(23A#ZKc1{ly^p9y1-Mm=SJ0g10p&yq4&&1$(Of--8y38wYT!oV=SoN9^Q)O(<
zGJ;syGR_*6#gQmKq=K-D=8?Z#!EY4`hC{fWk&w@c5+ce0~%l^&W;xhy_GSA45X)P}XvX%_lFzG~mG
zVx}~mg@@m~65IAZ8!eK$GZQ@}avjJs^19E4r}OX9&yR%QxzR=r3C0yfbYbC7c^m6w
zr@<1TdtmFB$imVC8Va6}cE#J6d~Ri@Q<(f`7#p}g$&3Td
zNi~qtCs_oG(bH9nLj7gF3-*ck4wzx=u&Z3(r^#pqywG3z)G$7E&h0EPNJ>Ww4^z*@vPs?)Ugj*25LYvNAV@)^9B1%u(%8
zpPxq*)U;Ua+-*K1PVK_tHIDIxZbP(iU7R$ZOF@60f|;cccD
z;vqxMca2=u>8c*)HZ%7bltYVST;jwEAw%hH=f&dVAF)zfVLz3w?b%wucAqPR!G?ay
z*3)xE3TDE|NO@Arf3MJ*!L=YB7Gh7ZMw_o({cKGn>D=NIr&28
zO7wJ6aAWb(cUk5OEMmn)nyfd#@77yosfHHk6v#eN6T}oVQ4`#yZ7GyU%^ReqV#e-&
zPsLI<_+
zDvxESIDbVq0)7v_MhGr)*BY~GI)Im(?`%;eUZp3^H?9Ls+faUZ=5`Td&A6WalfSxB
zEtoA6zuO>XQcNAy@IxEJ)$_=ikna6UhKx~?1*HWCPt|xm7JJ!vJ^n>y+XxoMtUR^_
zr=zQ@DvztvHp^JE3%Z5!7`8=2*zW>6w*;Se<+ZD`Di3VgHqZW#zXZ0#ruC-_LmO{N
z7G?zIp|NydNeNrZ*&@t;I=*BH&)&-d=+1zJ#hw75SZ&S2hTavL3
z1@im%?BvvA^?&=+3{tWeC@c{gs!r!lKc?;4@u=u$P10YeW=*nF;aQn|ZG%=)Ota*=
zvPGuD{KA%ffNf<~ARn`9x2~^{B}^L_-4H*hGNY=-3Du0(ks@m0AjTk#QjTt$olckr
z-bF*vL5$oc6xh=z=s&E^k+96=BK`9)?l~Q(^##`aZDZNY`aI;o
zOgQl2{Nch@=X-=vyHE6s|BPkl*-0cBiQeo0Qcu%WSF|V)0JGReE@f6?-9Q(9Mtbv<@e`HpbL%DW%uoNu31TLV+#gpkMCUgw(i5i@@o;b
z{bluSt|+v%sC75-lu@_uYlrS(*X7KZB-wo;?vT&()#ml~V#X-G$lVRL(`(U#_Vj;?
z+Lk(>=#56xl!x%WCr@)lB(I~GJJ9b3nK;9w1Vml0)3^1!Yq-~60`G7dXkO-iJN}FHVu-;Aay!>BN`dY5aq54|+{axNx
zUrZxt&xFu((+f*AMTjH+UsTgZVG+$=k5_$!tQ{TS5;lEo_xILGr~PLRmRc9o>kGp!OG2=jFXp}
zpMzD##?H;cg;mDR#LYs=!pza!f>p`H-h%a`JwNLw6E_zdFTMX@*vQz)m^sLJ4OrDI
zTpitA%q(2r&8oOKnyFj3>9MLv$r!Lod%4M~yS?L({a@GKePR9lpH*#TQ(Fr&H&zJ=
zM=!nqusAsR*vL3JdH4+e$D{uik+F-2{BL}SURj+l3e{AC$S|-|UvNB6#RdMQHXG;B
zZYt09`5DrSdf(Q-y_xRaZ5zEk)x7d7M7fetmw-eTy(EThJOe@k5n+NM6+#t+8r;8Q35_H=@7jfyzCr(KvKi
z*4ie{xxFx=KU_ZI7pjBPBX}D5;$Pfo*rXWnch&Kncg}0lr$f#k4fgED)-S*7V8fv3
zaM5=k$$mNz&9tVU&dW5u{ftG;Tezt{`)(V2&)`>hE)L8YcICxi>9(ETk}Oo_cfI${
z?I*M7#$ER7;z+q@=qg>7iTcK6XqT^&LYpXSq=-?LTGR56qn|1`Zi_2y34RcWrgW^4>!0p(-n~;IAQ_)nl|;_sbsa
zro5PcB$8(I#U_LzC~fj=KT}QV8gX^jRW|S|?0l5dpIAf8)i#LH;qCMBjTbqypCb&-
z8f5Z4)_vO&X?+a(A+aTJTb&B&gmdbiyQ&yqzV`56RO-#a1QCLkhoX6Ib1urx&VARQ
zE}pRe{XP@EG&HiIyzw{PJ2&B6^R^)s{|rW-
zg^=+U`Hs-c?1q8pfaxjI42=-ZnpJoGKGfsT^sF#_WjK5SQH~;|Ft$+ZYN+>Rz}~T7
zCbLUClJ%0rt7adrH=s07j3>bL+_&1=5xZR4b@(eAqGWgX_9T(@-tIfYJB7P4P7Hq=
z7hw$lwV`1M+GjQPN>SSOcwd=_%+O!jdcHj~?+GknMd5`!_d%ORUuycc4tI*yht%U}
z&p;PpcFlHtSZ!gq=OWHxaJv;(ajt#+ZCYK+kO(-ZONVps!&k|tonKi`xCmaYHr$6c
za?L!dq>k3DGa6zGO}svaTocnWL6@A5nLf-EYT(6L#Dcxuebs`d)Y?(7Uuh7mIw_
zVe6vK9wsZup|GWVN_%mZbN3S5alG}$pBg)HBl1(v_|k_plk1$(#jK|t`t_6-GqU`=
ztI4sU^P(W?Mu}`VzpFC^@r(?GVkb+xIq;VwKYe9l{9@r~2v&i&bF|1|DP3Jfj!>Zmz@HSEZ!ZZeM
z|Gi|-qjsFuZ=TY9g{*sWcVC<37+tFOnZ+2*J(O$ZVKAyD^Bey|rVvhPQmC}IyT^H}Zb84%dg8~7?oirxKuxYmXI1oyN2WPdhIot8F*1Mufn||E!D-1D}#%=$N#V=ZS7q9nBkJ&
zm{vCaf@O*AJ^ua82ju%a0WKylePNGcuSl7si<@rNtQkK~PaH+sPww`_S;i=Fwr?9W
zVCfA(Hfsl}yjOJ->Ak9(5iEFP_d(jb8O5S~fPf6726AjVwtxg+fI3ch$2@X-hPQbp
z)|2iN`%tV+?ev9BK=xXdRvY`Mya^n`_9)sOg|BvlVE6U89lwt#zCXi*F}Hm1mqO6Q
zdXY3p3fe=#?Dj8|tM=^r%n046BJJjrxvo%YU_=J_L&(HdR&?=Y
zDiB=x;Qzs`U|%XIne9u#GUMp%WlWo6Ad=eA!bYYv!{LLR|FjvNI6DviA8Q~L5*fhK
z4Oc2i7?Epn)gUpD4H?iBydx;?ZOmc;10h+@qd)@rIuMEOyc{>ZeyDNS-%UCkYfkDH
z>i!HLJbas#E=oY~!Vm?^J
zy~vLXr9@6_%pMVh*4)?KxIMx?SKQkE5bOMj4sK9eO{LJjVfMYit(_b@1noQ~d!0C?
z5WI&t&Sz7W+upMs_JRO=uZAS`!s}pTYhn)t_u;0?m=#{gFJ1JFh>kH1-Y1=u0<)Ny
z#cnT=rhT@ago}Rgu%@=ROh;(*TwKQ_Ho)|86{wFLdT^0`K@v~g(?kVV+FvefamO0b
zGhr;blj;tBbB`9s9(xRg_IBTU)a(sGHUseJ4d@j&J)(GxKGG6mLW;s0`xqDE-PoIk
zK@BYZUXH;*?b-0kZ#rXpIvuKo_8RK)9+Gk|c>ewz;H$N+8O+T?-UY&|kCpv~u=;5QArzLMvsp
zv21OKs%>O5eOnR<-~9~WZ-*o{d1i3>u+_q6a9r9OXa+LRne>^P2tT^0I?f2RmyL(C
zN^!UWV%qj*0$avj14s~?GT=7%W+uY{P2+(`+{XuaU2j?hg%f%ly2+OA);*+ABvTZq
z<~w>aF>(yiA_|_B5`>6P!9qZvLwwv@I-H5IRdOB&TELd?&wJCFSf07B9~{}5)g36B
z&Nw8r!}Z`Az)&%RVeN1&=&FDSL0K09RiRQ47wu9%iKk#nR}6@BK9Fb80xnH-Qce>Z
zpdxyCeos`0quGHA5WR4UA?!B3umz(^9-;EK+$4`0G;)WyXm&e;;zH#kt^5|Xbd7ZE
zS?=}lHg;At|3Eshi!&N~Ff0EE!R4O`Id6S~3>Y^iS7uAtSeXH3WR8&g)>+{n
zAl|#b^$oIT(bGEw3=#H0`VsP8(9ch(vkKP%th9EbB;DZ|7`@v)X|ETxch%VNNyQ1?
zsASNI4G9WCBe_NT94dq%L0DV*zFJmzV&fiU4wIce@ry{eCHIZWvdlnn@%LAQmUqcA
z1BKb24cUXEjR|tl_(B_YASj5^ZgpZ0lsRkQvzyC&HJOX%{<}}?MziV4pa%GyL0z=P
z#-kq61Dzy`rng6CgX*HO|F#6yC~-t<-)*K2%A>ut-rn4B
ze~P^!NanADI_Q0$PkkTEAeB{v<4Kgj3Xl8Xcowx=ooc5io7rjb>iJDvfyx33PM|L_
zgQhNF6>y^*tHw0c7_vdseE@+Pg@!F%B`rOqU{|Hu5?I|Hp4f{@ivrX{iTj2xu}4}K
zvD2A4Ixq@*5_^L>C)G);8|78$@cJbBPsrkNRjb{2mvh5wMa2bipbIj35)#0Ym2u1`XO6yTzIj9+%tQ@SHIHt_;fJMT
z>hKe-af+x*!4_wZsc@^YqxEUhlJD7IN5P2Tq!v=!2BY}0(@h+J&{9brI`-4s;N6qG
zAxNW91>aoMnipQ7#G-Cg@C<6vumY8TCSF$99Uq-tQlv*d4mlU2Kn>(zFBtT=ppwIF
zB)&{;MZv<(cKs^2d9Wz)&}E+Ap4DR=B3X~@EM`{$g-BI){Lc3K?Z7LeLDYuE`q(ZV
zV7AHzHV8I~Z*7=dCLx{LVVudbN78Us;f!(4EXB|jPc<|QDV%#;z3rM>+P<9gY>{$6
zoiu8A!dyZiM(@kILGH?;W=m+cpAfmDvJK;`$Jh_W=w4B3pfwTo3Co=|@d2o;{pVuD
z8ZS?q6zR(5$`+qT*F)9;=tt2m*=&59f5I{?Bj-u0(5chm;R0eqD+L^av0!umw~ec&
z+8cx%o8QOo(FnMaY@ev^m*3vf(TO6w9uqead{xq=57X|x6Um?8Qidsa3w4_pC2mpr
zYT((`FH{t5bL6z+AKdKVyQ2@##xqKp{=^nsMw1s&*<`mtU2A?SNw*K!@U9~VWyZ!7
zd4PZzZ|>ULur78UT8HeDwZGA*GFT*MFoofZJfm)(Zcx5xOF?p>7NCuGFVDuy2C0qr
z-LXqGDvj5<@fx_ud~py`{hP^<>$1WPxRbH`AD(T0c@_P&&%
zAw!GAeVU@!LsQt&)GV?oE-DfMDZFMARg37fveQh*tOkjWw^tz_pkb~lR$*)mZJUFx
zJWO^MQ98eEypha@#h!rM#Ykq}ZqT7UW_=}L!FEI8L6iKz6P5BPZUtOj-Yk^l@Pa{-
z)WrM%whBH*II9%zv$#~zkT!MVVa9B>H|w&UK*^jUUkceb{JzI*Y$>ENtWwYNAj?#w
zU|k>eST_fa=CTnHTRx5%sp*2}PM(*VIso2RYtSukQOLnbfMH?*XUaWGi&~d(lvW2>
z@Amh;sV4H;sZ~Y-4g~vbn&dqL7|HbGD=hIz!(aJDV)8WF{vijqzoEN@d9oU
z<2LtU!7`+9CoF2%RychN8m%(I6P=0&-ZBYa7%w}FGB)+&b2hm3YdkbSU`)`tVeiW5
zemH;sa)>)(uF=IXeTTT){6v)eOq6&04TRU1F9Vuy)yH=-o~)yRIceZ%BRx8G5(Nt8|y4Z~Ms5
z7a|#&UzpWpX!b#-;m|ii=#?WOdW%(Zjx-?}^C)EHj}X09)(vSwG*)U*29^-bm3&eV
zqW5LDSGl(cl$ZB(&12ewc8zZs{(7U|}Ly(_0U{7zJW!O!)!nyp+cF#e6CgRi<
zo8!FcWwjg(9?C?!5gsl*YHG=*ON)lSnA_fs!Mc2
z#O*FTW2!NqOD6)(5JgCPaW+1$MQmoyO9pm*Q={QAsE66YVt)Bld|{=65hM7w`r;
zZ0ZDI`9=h7S%TN~g+QrYTksf$c5l@;z-G~OfsZ8b1t5EWgTP@gh6TKj1?=p8i(Ubs
zN@Y_Q`b8{aqCsqYR2~m9(}WZ-v!yGH;a$kCzlZD4Dc%R9hm$WMt;S}`0tw}51WgwItbCJ{@|6Q)%qCuJtRCH(9
z%>8oHX@wmt1=DJs+%x}ukYv&12_se=dz7-QHlBsedA?}G9AuSto2LbqHThdu8*Wi@
zJ#dJ{!k`U59oS@vHBg~Uxsy)ez##RZ2^$U&XfHWuRk>`CZG#0I+!o&;9svT6?>(yr
zSd?krC!RrRz&5nPzjbclYXH$2-eW+!!X^mOZo@%9W_ew+SZca0Zk&hN99#3qYihC!
zL>x>S`r%;oTf1pqbBH2hQ*AQ*p}oZ5J4BulyA3u7}jIk9KOCn{Htq8br|h=BH!4}wfNcBE=cyX3oTtttndG95qUVDYRh^3#qd
zSD}Xvl$%Rl9FL)xxrSBwfna~ToPQ@VWIl9i-U6nUdS;Co%aIP%paYD2W3_$P!H}n-
zygA+ABt0oSvDY@4H!yt)R-=1guavs^#vo3aBM_AHLq0h0C?Np_2JJyB&I#tdg@(uXC$i-&q0XPc52dCH2-qcopnFj)orY0(LAn=sYD@{h~`Pe6h
z`~@uBi%}0y={)dNkzByI32>6IFQ)8%$!85_@Kh$`QLM$Rb`0p?+9_LnkTiNAo|9s}
znMUU5a3W_+VzJKu7U@L8IIF?f81A>I5Io9q5!Q~xmEh6BrKo06*d_^poZX;EWjm`~
zxtsGLl2-SzBGQR$(eVc)X2}a4jsUm4nS!zo5n6Hq9S3cjoK7IxiPXwL03NGGgu1!@
zlbi#MwOEOL!kd43`?uJL5}#P~H$5I8Sh*pegI3C+5Of*Yi%sgg>dU;uJKfzVvT_=>
z!;miN>%ZEiYI~g!u5;VNoEScL(=O~HFDQ?4xR6O*4{#MB81ht}P+#oJ0m^!J^2u$J#^ecI1Rs+9ywxxC7$8?Fk>#>WkYXJt_G%#F8?#>(&&{*XDu?B
zTsx9Jw6iw2FCB7(FAtu#QP_uWl`3oUZNo~dSs3K{z|f%jBcwvAu5XY^6B*m|;kM{$
zS}%o+cCM-Q(@-I_!Ajc=7uVGCX*Uk>$wnF!;?3nxer{7^T-!ay8$h|_{yzM5HW!H-
z2v0T_u1EX75Qg!^-3Mob!-6}$AqYr#m~;RE;h8Sr0BcRlcs;;i*Dxn9jH&g*UD2Dc)$_RM6zo?k{tj``9l&7ksx>-*
z!6H`HbpUI1>JXR%7~1*G0gQIk>jH*m>(>SBw66=;fm{bGm{t4u5poysy!8!oUBEC|
zIDB3gumcHi*%JQ%xxJsazCo@Fm_y73j0+uHz-X?F9$*0Ebv?jZD~A}<1FX>m6FtBH
zsr7n*!NO%e+Vt;gRQX2_FknN?@d;4r>jCzGUy>9X8HhJhX^HUr%c^S+9#o#|^!mpFdTPxl6npM@W>}Qah~H5Q*V^9
zi%qm;_^qwvs9_|*LfY0M${@6$y9yrYnaS%=;&xQRI6O12{}Mmc|ncutZu
z9%)0qLl6YA;{9*JV};4Pw{
zTSc@0BKJZBGPAklU-8h-4>lFKEHUf3r~C6Fbf
zaH|#JO9^*ST_x`dxS9|6GG#Mt^99@ivSZGUg(bz8l^JK=+v_lK2ZE3xP#Sy^wq3{y
zt*XmxDTAub0>PFWGIaF=;R>~>)S(Xs;qW9rciJ$kwUZyDJ+uR~WEn+tf1Ng$wo9Mr
zPb};vKEQ?Ra;1TaMAsGebN7JtuaMsL)NrT9PWHKUj{cCFXc=~NJ25UV8dr8(mQAqb
zRl8H9RbBSNzLv~t%e?^ipmaa=HbE{G1$6*}awXrkoCRexeLu+pQxu*F?3wajfQvDS
z2~OR!Y(V8j8;{Gvu&05n!>@@8kj)v5ZzGJRdz(v?s5$m07?c*iz%XfbAhQ(cg1j%`
zg~BsxIT9*&0aBjGD|`)k%7>mn>?!F2Bgbf2!$tjZ?}(ingXGF@U2BIcb|EO{9Wr?i
z43g$U%>&vL(I>Pv`n_1F0UW=Z$OU2(-~=pcQZTi-d#Ckg($|MC%tLTjzOUDs=;MPEF?iBF@rqg&`CfTbGU=hP~uy
zj7TNTbINr9%M0zNH?bd+>Q4jwxd7)5-WH#Rj`K*7@$#?MpJ_z|;rg#*4yS>0K9r)-
zUJMp_%E^f&Hx-VYe)EN15t@mN+c1~iHW<<2bCubj-W_OjLvSsy&nnYNX0A5dW2_(i
zXnWD9Kxe1|7{U_ELRV~1GCqR-kRoriqIJgf9bC`m?XaMMw|ieM~CfXFvb0vC9p6#m?ee|Q7}tjt^2h~47fN2tHelB4_vDRAoE%!*bG*Q&^D`t
zL(D3HcDY6gAVY~Z31GttHVKSy1)BtLA;)YDdsZ5xKcU0oHi?ad}J;C|>PiGi4gV3HUJ#K_kqF>*fQE=>|>w_uV$
zdyZ(57}>&GWs*SC0)=Uk@V1*I4&<6793qp%VDQH^NuXUvG)VwLJ*`RgBg;5&tP*I?
z6s;0mg{aIU$r|NaC5Gusk5%HGq|qvIPRg}PaQUxQf_NOP65~>)~B0;}D7g6S8k05hcqCH}O|1aVD
zMHJ)MBhXGW+9L)7Q?5N?lthF)_6W3FjrIsY%=%7y#3-Tw#~$JBc12mE5jVCM-qh(Q
z$hAi}#Ox7h_k8UU#wuTX1bFGQ&67g-ka5QB5tPAOG)QoL>orJV{mXEJ12s537$m3&
zXyJEb0Hk&s)ztQGkbr4>
zf&}9Aj;w~ku$rf6n;3A-7|}K{hFQ31n;4@Wtst-AVd!;i6APfUBL6!H^?Db&5oQ|!3W;9Iz(noxvy)1m4ril;qGFcXB*xrby0M`sLCUM{!;F=}Iq{7e55@Tg~
ze;giX^>aiH7lf$CkPZcMO`F#;0YNCQV40XtFiSwNGM+r#Z0*~n1wN7B-b6xAiKmxjPZ4ah72-bXN&uUfzabbeGSaQ}8jKf&%;naLj09|!JOS2=jKt?P1?xpd^7PW&
zdXbT$jiDh@Ic6l!Vkq1(Uu5RnN^ZW$i3v-Oc_Jfic?sr=jQnNhHLKqzwG(E($V^gR
zgZUyOec4QIzQ{?8(=lJL&3L9`zQ{;J)~A~~vEExR4a03RrSSc7V
z2uas~p+OcmU~n4n{d5BcCpxc6ptr;))`O$*$f&*CB
zctQLFHktK;GfF*JFNj|-{FwD3BTqj4b!D5#iOGC}^@8h|-=0`dIGgo?8v}H6>xDLR
zx%q;75BxFnMNZ;4-F%T#F&(HZ7?~OC-GISn3HA#iWC`{QLRvZYi_A3p<=8KXD^!sl
z`-SFE-G0G2_G`c3D!`)W_6wdu+AGcz(6uzTU+5fjfv#XRu!Ih?MNs3+-KU>jjrFmtei%-i_wg3+`P%
z#tUxT47Lky6&1%aUSuS5Y|E_|-gfiFg~)!PFI2Z*u#299{enX%Zoc3MYdYo&ZoNfz
z^h4erVwc$;a$;6yw@;9O_7*G{JQJgaClJ@y!xtFpA1oL=cT71U69&&^%5K8oNw(Ms
znJ{?NQ+5*uZ<~_cgzcUzYDSFR?lf<^5hEk()S7O@$ViuE#|uV`jD%WLfFC0UA-Firijk3miw90t
z3~##?<3gl#;TIT@EGq`bKu+LTF*t53)Br1nCOVFlA|ruY8rO=Ek>xHJF;3f=g!k3|
z!&KXP#BCV-XzoExpOKSoRfljCZMY4Ci=9%iVQff!S$rLA7@9|M8^&!P8^(pmhQTjz
zKV-vTn`WnD!%(lyZ5SNY>Tbix$TU~`wP6rznwv1P63aRNrp3G_jk}tc!FyjT@mSBK
zDC=o@H-}dxlAScY8&c#~OS-U|=0~eEz55I1mv_?iZpfgYyrt>g?HbfUyJ@a{rY_nH
zqjb6F_mQOrRhr(-8ZP-Go;1B1(kTsCn%>=R6cQ~>?`@wny$-Q7z5K#To~D<5^b`^<
zaumhW^lFSZhc+jXqK2BYEN@SUL|dBPy>3#Pc$!`=>~qufa_K2?C{M4qJyCCjFlQ>;
zu7*`p&Y#NEyN8{WjQ?cnB_vCA%H12Jo0h7Vyt^f_R^5Q-=uMQ?Ww(c-YLu;2n|V|B
zavie7Wq-nUU#WU`yB*&_rRv>~E~SoA^>XDjBs%83qbL*XV-h8YM7?@wghaiBwBm_+
z`PJDyQ7?NPF;Oo^_S{6hoXNbon>p9~fh00}`4foeC@!Y%Hjn+y)XVj*H&ZWX(mYY`
z=fv#Nd7jrSLD}FC*T-x~<9_}Ck#zq@Hy-B$?vU(tdR;e1@;B`brFreXJ+Y35s#pVD
z({hBgYunGvlZ=(E>M)VD$W>B%W*P>*L7s|fObfr*P8g3aVQ@C)wwTjlhH1eXtn?)2
zSQf3CLlY{{%RNVxA&0$wgdq25A8(M#09#E}*>zj7sTb|zVe8jRnv>3@!BTa%{ZY~}
z{X;T=EJ%h*cs
z>9qG4?2QPCLM&gD1uT5IfXK6{`
zh^(*&-HAHkn3^)vfZxwJgaQ`B(D@XAYC@
zZ>N%pdczY$kJ^=IQpZ#nQrOM
zOhBwp3@&9$(i|#_tPQi8rJDMKI^EVyp|p;pvNLLmskiumQImt-^^yG_(JU^uGTsi^
z=uA{erk>Q|tBngZrSnFTT_PuwpO#_(wAj+8R#|-w#VlGwwRo^SHxWIzXU0_Znr917
zfX%n?56adpO98!{v2L>SQV`=>+AV)@=KZkQr2vo9^mZv2BwPVqp(Z~-=w|=`5^gCy
zwj`^;^cE+5c1CHnX14q0vWe-Ok)ejHZLrLf6@DvVK*1o?AE9t!7fm9w48cNL>qjN7
z_=KqEV|u>9R1AO+W8sZ%^B~zDbci}_q_h@m4*js+8U
zXFl6^#BX1)5ijW;?^g}r2^TU#Df|2pa(X)Ne6(SZ7kBND$`q+=H&b)bbidp5neEI|
zjH+3SJ^+yADVfhjwCm6MLiI)SevFNI$gicAhuBK`!dNp@~oj0eeCSH*I)uzksq|Tg4)J+8)S+w4vlHvkAt=xipiVLTRmaZC%pnLdIC5BQ$1rsuSci^dycwN1
zi++>Xao+Vc-=0vg$f-kzSV#*vusU=MM^s@(Mr330r)&nQg>>4d4qX8F^GegjI&^Hy
zHQDOWAzy8~mFfNnGAw=AJZr5aX;brLt;WI~atC>kq7_kpJrl$%l&g-UdMYJG)Dbbvf6*SM6mL0Yy`
ziVpo+(kv@Q*O;;CRH8#TY)GfcxrT&ST%7p|mFSv$WW5p{R#O{nh3J~xBE1kDGn$7&
zbRV-4L)7SN^7ZdE=JpjRCs6kl*$|7uKfWS-#`1))DolBe;|j7{G;Fx52=CN>f2PXG
zJwioMK(kUJIqyt?R@JP?6!qY9$yhciifeXnQj=Xx7}C7A?}H>A?cOpj}T`K
z{jF~h_Z8t}!Lhloh(p3#w!%L^Ztp=hc!#*J$c4yPgl(+6`HHYTVjL?WH;i>RsopS8
z5jJ~_V&z^wH;R?*e(M%+=j(MH;Ts+aYfscy5Dq?&%L*iRv5^CO&?3ei$Z-wX5G6DC
z0iw75eEW`gC4*fd;6TFa+n2sWE+hK!ox|kSAA|)o^CC4^F;lKAQLln%bSRClKuD-D<34x)QB$8Dr$4p
z$5QGQFaEUpQRTtkoUB0^QKDdp1C!n93JfkN^oi^8$#GP?FoWO&I%a87D5*24!ibVO
z5;26bi6oWX+>Yt4a@vj7K)ZN)bnqp0e3L31(q!I^5Jd^Fouw#xNb}QU+N>w%GZiZz
zv??bnbx+gjWBVybup~1vHTOsLmYX>W9px3c%-N!P3+vfid?KA#_o4(v3}E9Bvax^`
z9z0~^tLCcC!a}hPfAo6ZNb3#tSAP8ju&PA?pfsIqRt+PGVW%GtlwEBeTpSijU5LF)
zr^e<5siO2abEIsUGd>|jh@u22;AHbv(kzg%#qtg@gTa)$yj+!d;Hq4enk=wPzhaRK
zlYZJu!4=AP>utCYsFd}Agmrl*2Y>w1J#N>sA0dxJjpiffLa%N?zi2)}AEvuCT^2@R@dzr~W~rkNB`8K+F0H63(lo9D^?qhPLQaVutw&hbEOi*I
zM@*oh=oMOzPWxJq0)z@!wuf7f*lf{yMCSZL{s_WLS=J-2b#m(w)7JE0J%Su$DqmWU
zP;cQ0+B5EDtOl4{F}yoZoXt1uQ9CMMw;r*Y!oe>h6piI>KKejWvBhvWs$ao=#HW@+
z{s=<0+U!SYKRQ*kA0ZLQ5{)$b5yn=o`3N-^PNCIidtTp>q_p^Rc5h7PhA5i(wH;x#
zyT~1FM~wy6zub8AF)Ohj9S*)K=M}1Zywgq_zE4bn>kwB!FwkZE0D$mU)*EEWQ)4K}EClD-)U0xmlbVt-U-EC5
zWZsboOrC^>wzTc__Ir^8X|xL~Z)pam
z+;#eTG={`X#(T5Y@p7X7qPO9#p0(YA_`(1~%qQp_U@3_M1m0BSMW*=^N(0|f49(Ig
z>p%hvg)%&-<|5lcV#>AIf7|q!;2F@{{9zP<57UvpA%Y8BheYR3KE}&2E2dc=o(Vt*-0;e2#6vg7>0LjFISe8dML{Lg0BgH`F
zYIGvIH49_7_vEHAeA%?!m2QiCoaPS}&cFesiz9OkBNmS1EAlggu+A9>
zg&rmQ8|J@vlyYavS8azysc%m_^u@H=FvyC!1;
zs;cnuA@w8dC+L7Bg5{#j&9OGLNwPFKWYALPUodxI^&qm6YdZMVyb1$HSZ2o57;V|teOhGiWmaX@vQq$N#c)v&=t)5A0b7r1H6t(MgYUs5&Yf!zp?(IO-(runMVUWHDK~VO2tk{fRUPZ}fZ$``HtglthJ8GP7?O71O-?@EkXpxyI&Ue^|YEC{5L^q~efk
z>KfxCfwe>K#r}pBROgK5F85i8VgRe8qV=#dRJmTtjdLogWTb&9VN+TCHyqKf_=#|c
zSFutSN-g6*@7l
z5I$EB%J$ske{A>S;d3Qr?Yf8075H@C=(z%y&ec46uE5)Jr4T(=7!@`=dafYkb+G`)|=HKGAc8%;M2=g-%_~
zqvvk>M9(?IqUZF5=HYYdqlfT0jbeKEoJKi4e2()-Glb6-_@dFusqi^2MC~3v$Ayd0
za|LlUt$Oqv_hQ`eIc`-NUpIV?+naQriVE4RbErG*+sKt{mR+qBqJo+$RoH%1fT@#t
zJna)f=MW2_W4jLzp<@>-M9>i_8MvSbI*xHQkD%kMN)8cp#IfN4bOoVg5ChD^rNC!1
zm*4}Vm8|gz>NQUU9rtF006K0b$D{zd-EK-^r~tYGufI}n09{EOy$8@0MyfQApkuqr
zQ9>bf#E&K4B8AWq0?bedU4dgLn})p>*ySN~n#J-EIvt$l0dic2dK3O};Vc*9c_Md(
zH!6fqhdGB3I-*di9zrL2&^(6jwoee9LoA9;NGNVPF{~_C>BLSHU4f5x5kH+IfLhAb
zLsClC&3~fkNE591p4C?Od}`@X0P|o_6dlj+@*q0y-|#3p?%rx4jBZ1$>jJ3Zvs7s+a>-8mIf~IB|5G1S6tP934@hH;;lV@NYic
zqOOPXnjwsi`#o29Aot_$qz`0?6COs#!&j<@(UCwH!&12y$!DQ3x`G(UtQ+DHkMeXXijM6%Jc`cS9z}N{a;W7ui%2qy
zkfzynPn;+^j=NWnqT@VkK4EeNj;_Ud>X*Qg)ijR)ZX8)n3#lLgaiovRahQ_;O^N#=IOEPtLsjR^6EK+!O|O7JG_Mg2REs~Z97ADAcr9%7G8d=lF&qctSa=)`7xmN2>e(zzthW)RaT9={1~^d
zU49G;w`SzWuzfW!WVL!~kWsZ+mK=SZ7gSmEFl2O!ESDiW?aPok#27NhG0e-5p^wrd
zLxw>-?J{H-q!riXpb9HIUw#Y-kn3fqYLVsjuv?&{WkrUpW-&+i35lxy1;}G>3>hc{
z^$^C8;k?ekkl{SrEQ}$mP#yKlkfHsI%aFwzNZc5lRBK?yDy$DNgF!)1NP1(&;DR@T
z_PSKN{V!k)u8vn<+*rM2stk~K8}9p1$e6%2aS9bwjU2+Ehc!k
zYK*%n)4o+>-0g9~FjS3^kRrNR^@}W%R*iADEp_>+#`rlf@c{608}*F`*y#Pi1HfUr
zh4K>)xXa6;Jo61wJ<~P0U%0)<D!n}3
zXi9qk2O8$jZ(SMVH?yTLNK=n6rlJ>QE-k9e+H8MeG3Hp#e#=pTFRWv{X2oNC0C;ca
zGPWPXnWh(pqzmW)hYg9ioz%26M?@n&UtUtb&d26xPW5$h21$yvQ$x0(su0}@7QM!~
zYL8ib0q44A>DQ;dQBNUThT&je&R!O{FFkJM`Te=q#Ax@^SIpI4?RKpWvE9zoA*EG)
z#<;9PCnv=MG;z+&L|W*g`Ch@oJD2l-mLS(6zU>B+C@wwc-Z3nNxjd*yWl69n~Rne@w
zZd`>cb2E}qwm!BS{W9-5N0FC5i+_3fkL@sCey=Woy^}qBzF-={xw9j@uQOb)|JN_N
ztEaF3*RS;TKkfhj+kJIZ8ub5ugZ%mR|M|D4tjo8j{%IKh5B61+Ao;&KgwH&f^4Oun
z{$bdk@BGJCzCRU){Rv}Kz~)x|tH*`xUlSzK=pnsPFNAKY4@I|2S-#BWdk+PfPsq&VPL6`%`h;AF#X{
z3j+LSk1NT(5_>$bxa#E-!9L%_x3au(e)`t;9^>fGn+Ag}yza~Pv&Z-E!^+rYHj6jK
zf&DAae7?zV$=vbNx4!onZ=Lhzzpnk~_xHDo`K`nr5A5GZ|M4ciHKg?Z>094>jH5qq
z{wopx{QmydoN}m*Js#M|L@V*2b$Bi#PAr67@zEgz4Q0m
z8}Z8jr>}gn1b@H15ij6>`pV}8{rB4&@wz;)vxe{A`n*E_etR!oPX9Eb&&%uYw>SLq
z_@__2-7J6KpN)k6->36Q{QrJ?FOt=N9LopU{rl~WNCe+TROaWmJ_zIAZ|_Bt^zXC#
zBvXICy%!0@e|+nMX#D;5UOYVi@vV;o_4nI*L~Cd@G1dpcW6&n+06x@A
zb~UAKf;$01kP%nG8Yo#I$a9lqxX&{;7j@$_>uj`x^0Mv+p!q=w4fvq%t9`-+^HICd
z(d|NzE(^+%3AGhUJ-{V*i+bn;4)IKmJUEELq~%49P``iC_O_)?SUFL6hITZRmx1&B
zmL5?Uy>3Z2$*27HT?zsId|Mmk+Wu7Kpn3O*K0gwk2XL{rtMW={o
zv5ToLm>?Hj?3F?e^;}ho4IaNEwBZRzU-}Cvsz$=?;n>g<3gDo`BXldOjK(Cad)7?8
zy8A|UTNF}aDzicO!{61$EIQLF-6tCR#*@hE!Hl|1?XKc^(A*#&dqzwO3zfkExflfL
z_gOM&s11a`H$n5Pjc@F6q#T}rBU;g#p+*1`EDz3bE+%8g!J0(~s~>6+g0p0wxA(+V
z`o$seJX`$qoWj;pwOy#qk?3&FH;^+NRXd>*)|gmL2|->c@_~p1971brC7^M-PZY*4
z@&iB}7~F75(Z$ee%PWq9K%Euj!p0lf=Fb$ki|4pizJY)x4tL{>>P{lbEs7q{p*<6u
zkU)m{n?cYYsIYO!pl2!8YvG}T8VRH9-47k6RZ$J;oI%VR6@bp~`BAQXSQ}8z0qcm(
zr6+$iv~HLToC2|;G|=hP!-9N^k#%4=Y3nCR^XmNrZ&ig0
z9xph<$iVm*X`Wi$HfLxTV)NC$o?`I=DDece;I87#&S|~adg|slC
z*c2!dkjL7hVK{&O0BHE+`>eVO4Jk1s(_!>Caft*OCCR$TA;KG&XqjVur?e`h0S+eD
za9<^=HcOz=4)Gfct}+i#uCAu%>3(McBMUd@+*ucL
z?yO`La?YJ4$HV1!7DfT5_j_k0=FaMVXJIA_ln~yqyreo0tLS|He&w
z@A{k+nS8l{oDhVu!V_}l#uropV5x!&yyWF6jYLZzi?BZ-ss(;r>~paupSR)k!Mor>
z=)lVlfFfIsG5CF9_i=Ao9@U}RMzF9d;oXbk0~8BNjVTVs+IRyu)(lU8ZR)xNm`ix6
zJ}sS4Edwu=xAYNZ=I9{|0zZMw1`kb&B%DK;poViTz_=bS2+nM`>
zBpOwjg~S!Tto+7!_i15ccdC
zBO^W~DJcmYCvZQ5(?UFCrtyhv6~aSKGoNTu1At+LKRlD^iZ5mP3izX-YA%>a<)*-u
zh2%(2;#EY%8bpjJ;#)|pl-YiSvPBV-
z7)csRnFRHWAFGO_F+CnUx{lZIgw@tV;J5NSskA!g)|5x4F^CAgqRMDyIw$SH!_1<{
z^d~kwDdw~e=3L>`&2$VKOE^kc&6v%D$$H6XSwbfy^etouo|D&nNvfF4k8|4HQyX0f
z3zwih#j>ZSL?0xpbdInbBur~b_P?r>;{)75(Thi=7s;?P63jALL7d{K7$-y@$cvs{
zw(z1Wvps|-;9)XNEU>IusfrhQ6fy!op(O&4x#!@q8jsAwRKKTPPrgHkOl2FQ1}X7m
zKV50QGNne1`Zw{4g~IUHN{cx2v7oHf&M#K>MrWSwh95VyiT&bK}^WO
zi>j+Y?E@-M5Xq&KJ%zV&F@lv0BDFa+3`Wx-Q`5S?D
zFvpAJ@AW8^%mVdB#sbj}L>Dzttmo10JuB&=o7(R{CK%jQnf{V;LSy9f0SqQ_=J7(U
zw0zQnbuN42r-n@o2|E}!kd$eDKze0Dj!qPqWqBLJT&li%o`3@@We}wihCf7;P}LmA
zNV_1E4AnMh5W5&H6Wf(FnScMfkp0O=TO{%MY!{T6<4+QE1f#R_vsmt?+DI1XYoPr`(VjOm<=kjsbEjv+0=~S!Fl<8
zM5o~fiJX~3oK4LLN~~7`$V@7BC4daK-xei+45qVO2>{8~%DNH&lG;5bN&pvf*i?L@
z&MN`1mwY7vjH31^0bt~LT?rt=nVSN(_|%Me%^oBGUyj44ey)%BRMcgEOs}v%^Y=pF
z?h8CeAYqa8xfnI@kTb;4Me+-ofX=}tMjD{Rapq7Th6MlxuPBZ;;Fc+s8~tn_Mzz>b
z3yU__I~BN8tR8+pq8D5Zmps&#=x&y$`yivp;%0OYw{ut+vdN?lLmCk!jEA34r^@f4
zL=IOKmTY7pGPzYxZdZSiUxd40HBld?NwoV>=M-<+qU!l>mtNE3nOEM!is1NueMDBX
z{7cB|iu>=`BDW=mck{L33_(@R9lc4Z0IHfT#;;$h>Wk`Bm99k3gQj*^Y@rv9UY==
zqlS5%GUYyXJXTh!B_Z9COE6hJZd8$HYm*FXVu1V*#j?z$1lZJ;fjKl6w?Z+7Of3A<
zI+MeL3+gPvH8c(Qwwklor0*LkI`#o&4or2CSaR>Qp}3NB-+`#^UlSbx@35HN9C~Y^
zf}B9%jyOe6Bap)kl~m_`U(qFkT5>z>Cn-?k+p
z_Z0cQQ5B0^NwyVPT1^-w{%CK8X3?{Pl_;qL9jz)KGWxMW#MGqaedLE<$0g)Q
z8`ygw^p+Ffe_wVYpsR&>{9!B;I#A*d7{T-eSS#4a;NiD8L{b-Tdz6bq;B&1fs9(qJ
zja5Jn&1AZKIh&&7Mlo3d#JVTR>%bQpnKyIt3|B4~zO?Sf=9SIx@m5e`4T)0Vojz$_qXMwNg4bXWL5bd)LjyW1LYvehwzrP(}IVhq6b&2=C
zL+t)9-E>6f{vQwPPlWp)Ueiyw|511A3HLv0L8Z6*A5|7|xc>)h;+}0s{N0H6KMaHG
zqRlK42hRP^JQ8mV05UKTvBUr%w?*rh0ho*4uYm!W%k-(n04%Gaei#541ycuw;x$KL0LGMk<1YDBn!^LwEy=Pvh>asFL#Hye}crjgC<7;um
zrq9J8*+iaJnl~M-9b#m&(Ky$fY$EwRwV6&fk!2Hi(jl9y?a-%_P2}zDM3+N0k^Gft
zZDbQ!P+Rr;6F%xGkWJ(beeT>8_>r7!A`~Fa9>`{+l_?*x*_c7TIN4-mzz9^ck;j-$
zH4!Snd(EgOQ}oVDG#hPDPBR%YaqOY{N4XEs2tX8wCObQtf>=CRDI}cg$I%joQP&)G3y?vCN`c|iBZjqI-;7N
zs06Bsk3Pmy7Wd
za}_6nBNHNfn35m=%I88
zE4ZT-2rH6<&Nsq3Sm?{?>c}+KIbB8S&$c3Ab%;||GHI8x4yn$avZ7q)dZVlZbtA4D
zRYUIZ94PCQ%y-GrSq!JFAFCtE3a{?+Mp+N!P}ZejJEyEm6&wR)MXsbLP*xTV8cta|
zY)&as*8ZR_%cZRSIZiYjYk!z0#HZ5f&Ej+GjEuaLwKF|`3zW691h`YyPT!;Kl(j=y
z5D05GkB&oFJI!mCuy!m?x`Y*N(?x)=c9?b3C9K|d489N%R(wE?AtJ2ka313{Nh^j(
z9h{L?OreiUT78C2T06bjl9SeM0{WqxXHlKBV$q+x!UGCtKcsan=J*Yybq(#~A+3%(
zMp{2`38b|n`G1L|^+H5ii5>ZpR^Ucik+gQIE1a};Sm@g&tv<0sT7fS0TH%2%XaaxwEItvxZi`%qSI-t82?=&HYNbk#d>y6QtPy2=rbOIJCC9Q6&H!
zWWIE@({K^#YKM((IbH2Fo6Df+Y6r70BVE0aLs#*MT%E3V*5J8x6=TRb(p8N6X_sT|
zthIOPYHtjozO?A9#UZPoi$k)C)Xk|!vg!~ct7x}XovikbG%=B^c7!&UOIADbndU%N
zQ3A5QkyT`&Zh@>0CA>Lw6H!xPCWCoT&X4fqc>+BesLs3<3;)+xi8&9tmqpBBmL{&dg
ziBuI~^8JmfI>e~zFf=|?b)fqD8&yRi`%6@j<~I0PoM|~tMbf4ei0Vd{_5`8|beV5N
z6-(IyQJpMN?nL!8?`8^ci0XO$5Y^McC8}o#hp1wRPavw0-rE~d#Ux80szU{QoTwss
zWPT&6Y%*7!X7%rNCc`9q?MgSpy&YYEKVW-(SSuF
z1}jT9ClLer(aQ`ZVlcZ;b`pW4<@5U6A*;FkhK)!J*2{JPQpZ!BYg7Vxx9R2VR04U^
z=}Al?fjr&MbQ&?>8Ifn85rD|nC>p_3-%oQIF&O0?gjxW^n~6#c;DdRhgGzYYcjQ7u
zCGZ8*DmzqyUD{C*mB65;xg>!~4CW3hP9@G9ok$F3Y+OzxuuODbFe2c~>SSWjeQ$&(
zGAqp)nczmQ637IQLD!7P#6=&GiBEI_nZWkvUL%S*L}Y>p(wdVApoe(CLnbiLZq8UB
z6oZ+sniGOMwL>bHYd!cyG8y~RoKz5J%=1#DVyL*}p%f!G=2SbR;kHKgK$7ufYpah&nYk^j9o~4H;R8-^8ia|H)5opC=wZr7J!q?hp#piC2Rt$s*
zM5W(CRL=Qju=Qq78p
z_A)IFtcXYtPuD89A_78-gjo@hFn-Eb0wW@_!>6OUpb-%{?OQHxL`2qmh8vg>5!vEb
z9>Iu+{P2ujk`WQf#cNq^L_~6U&ccm|qa#$Ixe*cVNp3<$#M?eb#0#Mj5zS1lUPeUb
z_Mbwbq#+f*O<+Vs!g`vr4#xC{^_l`sAx+A2J(8IGKTF>XBO+3s(>2eHh)8KJot=z`
zOmSYD8xh&g%Z-TG3B`mRD?ocUe>
zu)n1cD}r_CS1pQlD@}S%SP_R}fUgm8kTo%%@cj#LQr;gjBHs2fB3_7$h-e2JB0k8d
zEw>>mNB?viBE~?InAs4SyS@h#A~*YKZbDRg{p==0q8|-P$ApNzlvF7bB37wR-6Dyr
z2E*XjwIE_yO{|3haj+(tIr8CZY(+jVZb1Azy*kqCVHuYzid_i2WU=F;nhW43AgN~J
zAHK89<)^Yb(OB@rTt7j=TZ=pS4d5M}SH1(BxO|KsnROgy9}aWM3S+_?CbLz(&mq3W
z<=KzONz<2Sb-8Qa4jtl>>SEE$vxCBvku?9pAqACWShD)leXX2&@QX;yfgoEje;enJNtD_~O
zf1MDQF5GKoIvZaXZa^5{WG>tb1(=LKf(!RTw$CN{FBk4jC}op27w&~hpmYcoPp~G_
zt6!#J%_COX1Ix+*n+NwoX@aB=%7YsT+3C=09^7l0n~8aFuZ??RJB|l8Ak;jY2loP>
zZhrXi;6{7UH}iOKuhn(P&4U|l9!c}yzU|||9U<`GMw_Zj^WbKCwBW&wUXeracyMEs
zncfTX;Kn=${0QBH8*2d<+2g^Dwd>R_%0GL}L7)EX!Ho@?D?X7~oAY>ZuW9j+?!mo=
z1wNVwH?SldLER_Co5z3K0dn8w>($(0dS(YlSs?dq4526KS>T#Uj9G3@1A?>^)Y(9Y
z>t2aPSxxSki|xvUFxPz>3q2^Q$bB0L{d3oG!s%bjB4yltd!GtcW<2iOY!6*C6iH6o
z-M249?%VppaQAKYG2}fZ_ic`1$jt!m+Zg41%+CPpgn5u3KknO@=`_EB$%F7PkLh9b
zu-R**AX;E0k1(PqPzUumZ!hH8EnnAndks}UJ-*x6I(mPY@Ae0MfLyVd3dVvw$yZ*8
zytmOd-U-gzIGc0I-$TyZm{v3P8qV98)+(1-0!}}{@`Pz2vSEcM8f&eY^EPPGBHMAC
zx1DO4^EPHa%&Qd6+qZq3w=YD_+xP-0thr9351Pl^xtdrDW=PK0Aai7d%{LoZywVEJ
z+ni^+-rJ;NY5E72^4x|Vu#y(F$}#v#%YXZGFBF~mC}Zhm{4c~q2%m@9_dX%n8Gp9h
zbsuEgbXQ{hH>8n~GRA+myMj;qLCWEh9XbCEVf}>U)``Sia)z
z59ZMe;{10zy-Z6e&VNI)0(`~!?>0(b9LC?9hwpa)*?zr!eFyn{NNtDh=Kw6MK<5Vj
z&X?`q?fwcDQO~aj}`neI+nFr2l2AiCg;r^^LM2G25PmV1AZjP5(2q!tl%#z24
z<-hI2@?VHpetuyj=lR*Dugc;1H>5L?)Odaj;bno36p0=x3j))xt?thBb4ooq(=W{H
zf$8T?&g(bGMM~9~e(r2pf$Qhq_U3HA@Vz+O&tHiQp{J@*?
zEpqrl1@ah%?2sEd{J=eSI`_NVNY?3r!%wRx9Nq$lA2^Z@XMT4(y-IQJcaNNBKSU-c3KhcSp6m|u?Dykn|J&Uy{9SXG4?A($aGB*ShQE{zf-kU$8!>}72P`tv+js$DTzFvRm#M(bLAT0A
zgfM4~35*?2aU(TfgWHu%+&<0BRrvkuLe7P=6pZ|czC0@JMX5n#1X6*dZrP3&i*4W%
zR6d@S6-S;-5aASbk1AevvY^&szqr}$M$>VTvh>I236*)rCusuQw))X%oTm$s;%$AzbZTf(mf&FN>w1@&5fBg3IKxka^0?Kk+v}khZ00;Y`y(@da~8
z68To2XI3Z5U)q`UGB;l#G>R*8rKjEQv%HSn$u6c5UQ6(Ug?RHe;C`19pRnDma=w3<
z;fP%>yW1A4b5We8qIJn=O}~Y4+fXPU6f+3qt#eEyuT`dhSqdIVavQS!SSrm=iW9l-Mewn2nsOc!<
zjEV~ir8T`}8tEKaq7mAUWr=nO(?i%ys}jyIMH2e7NV8m(A}X7gWMcXF1netU*wt=a
zO3Lk!5bsamkd^QSs*BWzt?t80R~!Y?8z^)DGz1j$w3!7%JANRA`Z2b-4NdGkjds!i
z>5d~Sr#q`E46$?nkU)d}QtxMi#83Sb3!r-Z8z7CkC%#p65~_|4i^2u2i>TX)7ljEs
zl87|0V%X}<;-cZqP)is
z=pM+*o-kgP(W6+Juq3w?OXbDFRONC?M1dZ8DNb|6Cr~EtCgge;e;4v`*+SlYT(;0l
zM%<6BudNrx#(
zsraz+Na7Ny{nTATB_BpPUDwEI9NP2v#Cr)(AO}sh4=gQRvo4yQxxsrI
zgOI1CZCJ5z#rF-g%cgOtk*iAIJiGoWn|&y*QbhmkzW3<*Yu
zd}Rg{`+CbO*OW9S;5q6(SMUU21TMNe%db`G`on-(Eck4XH~^IYI+QzYo3D_SW4D=ZJKk)2KXZHnW!dYM8jzH1-7#=4Do@Q38&Dq8;vn;gZ5JC3
z!lpA;o~TZG{f&Se+99@Atp8uN9z?EFb9ecE;bNr^A#I_wMHg|)GV4^7@0YO!!V}#2o9%x1&0GM!C@5n%bMUYq+z{+!;rSn1qVp=
z^7uh0beFI&_^YR
z4b~1~!+{*JVI)cDM{J-s>Q|H-5NGst#fH&@h(~OAKNTW=W5^NViVX*H#D*~>Y#gxx
zTERD|VJsb`BQ;EtXqO45#MdA+Oew|h6J5r?BQ>!4dlVYxe3|#2CH|cXhB`vSX}i#H
z07q!R2YL`1ko&s52@N=0B}fgkMkzt3@l6BEX+~~pJ})ybN^BUc;1}fvTS=E2&PpG-
z;e9V`f0|4VS8gzf%MC+h!R3Y_%T16Q#vsbM+yIMh4syd-;^42`Fzqrqas!;HbGUq_
z&S=bQ-6Tf)6aA>gBsWZXbp^Qr3c(!Y1|<3pVuPANYB0bN8u0qpl^LY23L?XlDC!~u
ztlUu|nB^7x6>QS0hbM+|`nb#h73fzK8HNly=$y{-qyc5&&l`r%1PPs^NV{YC_+4{b&n|I3O=)R7dH{0vF
zc_(J`3vS*CiP9dCsm=>XrA3dMx3}Gy_Cn<5%}<6HyTsebeY`n>Btx7$CQ+{ZMuPYh
z-N~EFP|XvA=bFwA_sTfSdM_0uYYiMbHi||=MUSR_Sj1_MW9af=8cV40b^N>EaEPQN
z6OrHX${=#?W`E{(tELo0?%SP^S9IN=W#UN>+5(@E(*
zox8P`at_YgORcpzcYp4N5eHPMy%>TmQaQit%AN8Nm@Wj_O#P)l-##PDC34#JYdHQJ
zAa3j3tjg>84w0#8=*l&eGZzoEn|b%!L2OMn6?5^(t-mY?lrA2*nS#|_JaUsm#F3qm
zPOwYtPK=car6czLjGoSW9QO8Mem9^4yo99`MtyHq~r<$;|r-)r;oK%b>wFAwa+O_R!5
zT~}^fhFchb%hs=#M;`UaK<4Oy?2P^Tc>pEN4Mh~`wB66cA?D|SwyAcw2H<|8Yd0ZD
z+$P;TknK?n#;JxC5{J{_vtQn7em7#NE47HZyCS#oJq2pb8mWmmoteauVCHo%zmIN1XUL#m?E5wc#!fh6m$nrR!6miui4lbGU+J~(Jk@l;mr
z2C+Z#Em2l8w5L$$fdqo^6Wh?P<2pJ^=*DsMaoE)lNLVb;vH26E$hRL5^p)P8VFsNy
z2=cVZ{FH>_2NIuoTTNSH6^n~YjM(D#Hf;F1yiH_2(yxY(FA@C+X)oCyWm*{1os11I
zbQOhH-Uq`|IHvp1`DeFg7%QzjFw_-9b9ya
zb4|P5&xJGNReDev
z3nao4m&6)e^O2oYq!TYdm-VF*RQ-!h@-Diw2qt0`S9vvtoTFBKHfDrzQS
z{wVbzjB&82$<4O$xD-@R8y&NN`GqvPhU*KaHeEw~6q&4+%{z%BeIPzG?RXE~*)!)m`RlP%NL+%3>ZszNJ-KIUidh72Yc=st#Hv
z?7_nE(K$r|O1@$AC&`O=<#qhZM_p>0>xPcR!c`#M0!@Ld=%$2u8Y^+y@ab3eJ%@Ca
zVpv5E-0)EtU;Lm|{eZfbW0K?TBctL%_=)tlqjD1CW#KiZ4qv(31*R!Z844LVf+dh*
zHWgc=A~zEl_tAg0bi%-Dag|p3lx$FXWF0e(vzwI~KhxPR6r~cP=
zd;|%GUvAkU?77H>$*OU{0Qq(^go(3Bx)!_c51&m}Hg&X@h(%@TF)qjx+-lIKNx+m1
zi>U#)AM4tJn&ICxg!S~a~w
z6|CJZCp?dV
zpQxO-Rl(v)(Ix3r!P*dcV_6j}u5EWs1b1Rd$)ze-+$}4!sVZ1}CQH+gGA
za%x_2DDxeVMCDEqERNnvyXs(7xxHJ7tKFW$=~D!YE5ZtARi5iE|Y
zOA&)2SP22lLpB^J&~N)hr8?y3S@4A+#6TS^_HjI^+dPQUMeUemo~RZ0bVo+#CQ(QOWcl3q2)LZ|Gn4$D!3g^l)M-m)pi0m7;EV;<2%|31$u2j{U~}
z-Q1NVN3!F}{X2zDAPdgqG1~eF+N$oq{d9MLWJF5&YS-Utp#m~EgA?Ec0OOG!yg~De
zDn&YXgXfuyR+NC@6j=f3Q}&{(;@L6n?7qRJm081)&YWm6WW(4G7j={|*6gF%(GNAJ
zR}7MDDvmGv_d?V!QuA><`erV!bl_#Gg+hn(h3j(a*=!14wr(rS*mcluWjx_sEnXx{X6>=&Oo@+!@Ez)?9ZVq7ur2{VCbf(5JSMW
z&M~JyC=Ov>^p})ysT^Nu&9!WW@192!tzZ&Bdk#Fk*RNTNy{QCJx8Bf
za7{}syTqXGwSI;M=j|
z3m8g42l_`sSHepq;w9MtW&)A10MdAXb|lua(pks7U0S%|)(25Y@Z7xfTua|CAMn;)
zb<(19p}8)=g9pcSt|BBGgL}ev%oJp&zoed=c^+TDR}3>q(5HZ&ZO65?+AOPlHIni6
znQBtBYUWAj7f2zS1@N4B1dbGRdh>x0^4tkQ&%H83@q(t$ZkpYh37C>5w!wo2W`4kK
z2C``(z!uv$b3hKe#>kz~Z4IqNw4a4Rj)YbqAfVd4hPl7KR%#Q?T
z1X{ynL&6ty=h9%$;SA~w!2%irJH^Eg^i4>evmPBLvRlOpmvZ>0_lohJfWvE~s#+Dn
zdjblaHHsaf3E(AQXq;#134T!7c<3KC
z{iQBN{EPhsA2-0>%Xps;=`@k;_1vfaEDmhDmrTZOgr7O*K4lyzF1Yp&Dq|ThP$UGd
zxL#gX6##@ew>suF`m0pf%Aorl=&WG|bJS^;!%1svBm8|L%SfjfP$x&qbf;T1(6H0+
za%clRIBzWATceK{)VDCC9_hMT^!3s+u2AN~wPWXn60+TPUU05s=Y>)VZn=t$Ic5yXg+pcs7mu~=Y=x09y>3TZ}r%DyWX|zofrB%dTqC@mn!DH^@`kEuhF*k
zGV$7anfGn$?F>!4ci*lDV!pki`r+JusWQ*|cj2$s_S*%|KDOVU=#p=3ztqwn+pp7m
z``sLEznj+fOZv9`c4A7;?H8POY`^T}z57DFdEItjv^($Jx5KN(vHNlu%enhP-+7hu
z3l99+eW3s?x7`<_($@Zqo~wKNeF!JF-!4}Rd;7&l>D+!hRd{>*rP}@2eoc4UM<$mt7IhFD@MB*7l3O47crr)RS(Sf!r0lME25XsCpQzgoJ6WoKnLz>MCKZa#{*_hAfwS!$+wJJaC`Wq_XcJO
zo(#Ofg)#eEjhw0RTv-NlW1MN!xj%4L!ItJh14feCI5}7!vCgw^d7O-$@}IfPqv_F1
zVVPPDgtl!oeK904X9TXSq%(iNeCfg&my@v5pG4QIBTUMoQ1%@wfzwRE7eM<9cr|Ry
zA#gdni)=1N6;o39ms0joZM;(qQz)=jC|Q
zKv-jk@P}iOuRP74+dw50bAM5WUEvB9(%tTS#7e2Hs0=%t-uiptqfPDu>`u`Y?z+vi
zXdGxMf#vEPtPkh`i23RTrYgi4YuQSmxegF0S}>3|{N&CYFRNmPr`_2zHpEzzc>)^*
zNA=3P^x7TxI_lUw)GO=f#tRFaF=sCHjdyc6&W}PetkU%)jia;3!o{iP5t){Mp8oe;`CC4IgQdFPb
z_gSWZ!WYi9(sUL@d%lpX@Y-;}{XIF2w>8)|E5grXr;&NHBT(?wH2AbDFekS!of*Dzv$-g2dBFT+AOT;Q@5-LZxDJ1H@hU^i|mhC
z7!!Qao%%?o5C^+uN3D7i;1Gs>6(KcjDQZN&+?P&A1aLS_uopXljWVmhXf{F^zx{>$
zl|;NlVFsC+@kw8_9gsuNQfH8rZ*jW7tPDiYt`ktBvzD#6H@{9Rfa;OYFYL)Wj~MF8
zBz$*N5N7y`u;^>E8f>_sAzLj6of&M038F)i5dTA?A*d|e?6L@2RopbkzM|^|3MlIY
zI|FY0ElL1zPcWJZ%K5WAjUjbP5-{4AJ7a(H^PooIbs-yleVRYbIjo|W?+B%+GT+e+
zA)`QF(he{WMBl!u-qcZZgjQlDLZ!o!h$eFhH4sJh#BDOu4-H#|f|OjCLkWWTC0n&O7cj$Y7qUf8Q}mW
z>fJ?GiZ15|Kz<)ILi4ohDZ1XNA+ibctXhE>{2gWLNlVMgJ2tp&GHEFIKmag{Yy#OA
z?MqlWzc70!j|Y&BZca<+lkrRPG=%XF1%risiEmnI4}Gq*w)~DPsEFRZ{)nK6G+`Uc
zH8P&Nb9jfRG!vH_?;HYtjS=b3OCK8e4j4|_X7nTk@dA7F>e~qU9(acCo!ZVb7+P!t|Bip
z?D2NXGWnvKHyT!{3QISu@ewuKKjfMsDnb3U@EoeMfoi}wV=jL!
z+ozUm(Aw5@|!rRq@^gsZ>
zk_IuEnO++XF=$;|Z9eH)ciNCQhe&^oiFT-Y;ZTW5a&^?neA0I8{`4iQ9SJYY*lyzG
z9J9rqv6U1HLhyH1a@fnRZJYku-EW-lmjU_KT+If6-E-AA$INUxyS#Fa%;6)V{=`AW
zdsZr8GJfD>u3BfR7tSFyIMk1yI7|MX?Xt!;doqp}x{Zy+4klCc=$#3>38@c7SBO67
zgE(FMxnQAl4D@s_T1YeBcSgJ+6#yNt17qk5ciMwyi$8S68zE$g$J2V&0<(Jz0&N+|
z1ohJ*Pud6VQ$2D;6gbQ+ie}AB5HD@rcyKs>iFjL>1j&a3{z=Qth`AePis;_&aKoRp
zo^#Nb?XegI9=xt=Ah@>V|I|r7$5GxgDHfs#Os^EFXY}O(hnY+VORqh(AiE4
zGmH4flP=n66V3YUIFCzuX?5&+nu#;);OJGo4#ZQBsL>-jp;DB;G~PoPoW>90rv=aI
zN)Y^jAq80EYfynC@aiM_lURGLv+2xGFP6g4|2&T(PXfw2aR4kcXzJuuCmFQ?hPmKvrn@^za?%0(K;yvR3(+;ONz`kGU8ubMpx2&m0_H)1Yi?O40ne6kL^%
zhEPU2I9Vju&EW~iseE@s+K^UU7*V90&>4(}BIFoa2^g_l@=Bpaj4S%^b<}XG0swQY
zhiG1Cv5pch*8Iu~{|@v?>0k7|{Izr&2@7dHl8v>{sHlXbLuhMwzQL6TbJ;L~S{CW_
zK*|SLjaVkfRbP}`=F{~rro>skR
zkY0$KODND%AO{3u2Agid-faa&d-zhdl0Z%f2gV}hZijVmC=2Cz!KvyQNsnbG1U-67iuPU
z9n73MIRtL7UGMjJ^k+}vahyF~$I27C9MfPv;OG+D@O!1Lr{)#be^x^qWl0)qIWf>U
zRr8&O=L1+nYV*4dmOUr&7K9f2&4Hnw3Hql6GAWolQJ6I@gH>xvORf*#IXKEZkF~b6
zrUsO}Xf`<=KjU(*4JPqi)Vn)FzOvddu1^cSRavDGmQoD2;zdLArv$)wno-F=5-s|a9Ox5qWZ+9*9tSL9JAq=PRVHQ2&g09VS5irN|J2s
z_B)=$MoSL;Ou94~E>>@TpKzQGWFV>tX+!)YK+L40CVS%fiz%Wby%9@?^pN`_04FA$
zwBAoyq_K;fss$k`PdWO;)_x7qL#l#Hx~@2~KX~$0bO@rp80pGBCoWo9$Qim_z%fb0
zgW)QL83LhATA)wdXJS;v
z=eAE6pe>%PoiH9f^lhdlV9yo?2-zb94ILiLMwzmc4zuflp`wLj4)q2a%OH_&oWW})
z&mi>G5zUo%sf_9y;io&$SlbZKo3w0cW{0LKHWET$012;y_*ub$UmpBVJ#yn?-Y~UCpi*VbS(*lk~xJ;Z&p#jGtJSNTy#s-c>dOIx(I2Pd{v2BC^
zHDK*T3`81s#`(o%0#4wV^x=I2$Eeo?1j&G7(x}&k9CLa>#}-4_F{ST@9b@)A9ENXc
z%j?39se;Si&lZ%t&HrrT82k4k9Is)=Vh}9YfMe{@xNu|a^0Z)MPA=5gW)L(+a<?xT%$x#!MHfl^CwT&7h1A*ENHKttSLXD}=aG=Im
zu^Ja@j1Acs2#s{Vi$*yy5$dVFKx6F65)RN9g(;*38e=n3U!bu^v%X9r%t$^PG)7K8
zQDf9~*SJt))LECXFkuni7fU`+WAlE?hza|P+U@bg;H&{`BOR!*2<4g+O0G~A
zaEvOhR*yx#)7#{^4ba+re1OB*!i`Z|oe$Vpq*utYaAPqDN#eLMr#EhFaSS&`y5@x&
zV~(XBz%gpY1eyYHjCDYeVgrt`j%^&kF{#A+0*+C0*Ye&PdOvm&)BFKb<-ZR`MRMer
zEDPm8j>*Q77jldP(fUG;X_&@BjxmQTZR8k>sBt03sI(nnA;)OEn5XEC9Ah1OUdSc`9GdpmMc7#?A;21k{N{IuaVRRWSY&hdWIgevku=kH!K&*c
z3!O?x2Mr(E*;CZJh~8yLf>oPdyj#fSKj0K81}=KY{nj@@&#Mbe)YUY-P@_OES{sd|
zMt&i|^;wSJ>vCFBGijOe;Hrt|!&>b%Hes!ktaO4OHDVymU8VeEkP~FsKmd2rm-(FN
zC*5fewG@{IF-V_Ot2usu)sqst}m
z{vx~U69l}NbdqKj(H&HC;B&)KMh~ve#Y4u{-K=3MhjY<8b%ixH4M4?
z_m_+_NnIfn2<iT**ug=d94JYuA(@FRETXI2byp$IszNu?
z+#l3eSz2a-8EY>Ru4Y=~S7`Z8M%oiHnW%!T8NvEmsa7Wbs1doEWz
zg2_pm;BpxQ0g!_#zCt0{x8|1#iUM(T!3#kbd22wt=}prankA6C*43HAoCdvc_Ja8k
zRxOzAVx+1qz{c1awV*lo14kPlISO?GO9pW5Efjgtvz@kCIHkQ8w`ie1{fih}VsOEm
zwA^vS?V0xC7FSGH>R{lH(meAiLDjyNeOU#E;5x(fz*j;NtevMt&~%flDC0~aH+}G=
z2emV31N>KLau)4zAr@!%GAf?aPaF#$a&o$)&>KrjJ;*39(t;W{^Zgv@hFhJbE%;)0
z%SLFVencoQ5Vb36<@st5`ZE+GthXkTQN$W3IDNxjPl+5A4Jb7viA
z&ZL9zrZo60nyZ&32;UZrgQPgyyUrvRLd~
z@3QFhmPO+nJzQkRf8`vq=p2{D61E@~3&ytvv0QGHrXc3wu8t*$7NuwlVqVerB#2pl
z!)G))&!dEd|j$5^X_Dvdb<(oU$dK{UqEDR-eWNo-~?8a%E*
z66fxs-Kbo&Gc;U!wcP+lIB7ZPhUF62ICwo>e$QBR>mINL$J*G;FSPIV&BCed(||cy
z*k4q;mjwnofnyk@NHjPxg(4U6g%lUyqs76e{?bTmJrMeKB;ym>UvKEbxwyv>eF;KfAVQm=kaS==&<{0$d$z
zn(>Xk{y7;LcQewuc3#yJ2zpR#3RjDQBhI%t*+48;w$A284If|;t`M3zev4~#g7$t+
zopveUNFokZ!&w&1j!;OK{Y7;j+Y(j_zk)+;Tp}a?OP$S-XGR7J3?EM+rBc1={igeh
zqu|O-u5rF4++7<`V$;kIBaEalL7-H{d!PqN8^R$3ZQ}yg48=#O;Fyne3Q4;hP|M%z
z@RuySg`zJF_+IJ~Ds9FDuQh)oGMf*b`lD4ke#4u>-cq0!0?PGaHXVApd2A_*<4&z6
zr?{8DCugk^k9?>S88|-P^cah?bHV}fXU@+1o)7X)*OlaA(evIM&uMbH!z!K}&*_;D
zSGPpeaX2$y98(GUjHSs*a^ioeXcC`*{J=QUq`o52-Z{G2l>EeimDm^?P&8NCgiv-##}*(y6AiPc
z`X~kS9cM_AWR_SD?vrTzvU?V{2XZb$)iFWTh9kd+q~o3-NFY<~*_XNLI)ZB@(qsj?
z0vcuhO*91R$=IO2I>8i}?PxdWJWIJ$?Kb5@)zoQB{utR1$HoUXr2Ffpn2ssBB2Q3^YDy?+G&(c`NaEROS<05L58+154A0Ya}faxO*w1%hiHKN5k*
zY8W=IM4+)Ax(Z;Q05p#Fa3J%G=uovjx57lI@jjU|g>j_4V~}OtvNc?`tIM`+S9jUA
zZQHhO+pg-eZS69;Y^zKC)$^Ql-*ZlUH{#wm-d}62nKQ@CJtKDPJx1o5xohB1{?#E{
zvTRg6h1guvTs5k+EHW~4!V@Kvym!qy0$gptlixxl?>-%?if8D>_mlu0D6k`0E3d@c
zjkT9kEU)Asz;xM6;@5>*p2($vSl)1L8QQklJi__5nfz#~Rvwqxvqo{){<4Vz_tdfp
zdfo9!BWe2U8MFV{{=A7dmc45Rx6$)zjnk3=*9jOD-e`!KU{VrZWbNeS!MCmC1CJEv
zWh$@)eu|nGavHd$16C?`>>VNL^-Yf1Q?@d%iJvUyqYcpMML*s^+P}q9w3;MVFn_;w
zAwk~YW;umOYWcsi^6mUsvn)s`>0Z9bZ%qu^&HdJ-QJF$9mYr!kc3kB$WfE~syK5t|vsbjj}3-$XWI=c?iR
z=>;;b-N^CY#~Jg}30c3XYfbp%Bt?s;5A~^6%W5EAeD(Ddf5!y*=BW~?
zw`d5;+oWQ7(gF{vI&E7oXmeL4U@!t=cqZkJ6&Z_FEY;hVtn4uTFz{jYy;5CZdFJF2g
zEx#%!(AiEG>F9QE{JT234ofZD-7Gp!ags(ZJZLpTnJ^ka>+lv&c8^;e)3AS-=~|<#RDD+gOYuZpUaqB#HQnC~eO1>NH^#m>nsgcZG0Z
zII04_fYWAPxw5QJ$!@MR$MSK8d+d@Pxc}2Z^Ro*tirL@x*9;XtXKQ!>i6Jjm`!@TinTmVx?C`)D)#l_B
zJC$@YaZSA~dcu!ix~4EZabJVQbk)TJ-K6Prbmh4=-1QabK|_!AVHUv;00E$6n*=*9}!f+HAw0gePlpV1EgG`djt>!E+@|sXycT*a})`TN)!0uc-!cI{BX-d^&4FM
zSJ_cSS!aNblyq7rIjjKNsiQEwG01Q|V-V8`A|k(uuwLT1DpaJHTJu-E3Y!J&=!rv_
zy6Zf=Cf`mNWaF_(JzOEA>T1RK7``-wK^gfL{|5iBLbumTxah0N)Az#mO~{8oCcyc;
zXWzucDYU_I27r9shp1vpPnEtoMDC~YtM*YHnbkET+gmR9DT=XM;T$S5L^Vgiv-u5@C^M3a
zc#vMr9NpG(o@R6DXcez^>{ne_mSMoULD*#VJBfNT6@YP48F3#vjO#R)#+jhRyO+t7
zLU?`?d|t*Q;bNtjtB0QwKNHLzcp^X~PNAL(Aq9K~Ypb;M6!M1gifhZIv1&fMqdS5l
zg<6%XpmO))bhiIA+6=7ULc+kNbNEUfw{tDYsb-MMs(23O989NbPUj7bkHIF-BhSyO
z8+WmAxcDI?lF5PAlu|Br9=GCVf<9AKY}
zA1Lr@6hC8vdWj~p%e{hI*hpCW#6NU_X`qhUO#UTqn
zIrL7*2dKV7p+>*_DgQDjW~oBgu7I54#C+W8^MV}QLL(|I;CDkYSPLFtL_o#P<
z@j;gubcY$hu|1Z}f)b4ymf~H3Em>qF6xZhFQgN=OY>8GM9t@QPUqKTWmC)wjQ4
z&~lWE1jWtOf;U@%b3C1QGJA~+y2+M3vfTWUNkHVLV+39OeP`Y#a!r%NT8U~Lj~a-7
zShnhID#*eM-=8o_jmx)oK8+v0pdJb?hbuM!zxB{5aWADuXIm`6*;HoTN*JRKcLn9?
zqp^G~0m^mxUQ+q(C#0X0zd_6fRgcb~-K8s$xmu4{s+6!w%f2CO_*#lxw3z&+n2Gx$
zI2_$|lr7%YHR9Si;ME2No@?tqieBDqlnzR2Ihs|ZkXu~GNa_BjjgrBXX!fL-hl~3kRV4)A-p?0QI=z(VvY`zZ+
zfo+p)NRy&)5*dbiR0ovgJunKus3)Q8oTiN`!UcsAwE`R2!WF2hW_0w3RTOAiUa2=Q
z%DLMvR^3K_+ScQo5c4~0+a8(GF@mse_?%7zrld6^kSpk^ag`@v$fl-k&SECH6`(DN
zw)V>hX>lg)dFA3p*@khfZG{z`Uc}Q^wYA&#y<3jA3I^jH5iijqQ6(SAcLnxb-14N>
zpo7D$dO8vAPQ~r^$zYW8oW19_U=|vwdpeg=ddeg6lD?9kVey>IFelnF6efUBKYa{8
zAK}LIM$wdI_=N}p$GANom6AEEitsjI1@W~ysN<@R@{Auy*2i;EbOZ_q<%$sJ`CFNT
z56#d^r$8E=3~R0E>m9*!lm%^roM+djBrlF2%+O_UTB-pW3Q7)g2Uu%0Jv=gF
zeICjkdh}i=0RHIC0PV_J^4Z5Q#R)DgJ8;^t@Ac9xhdb7fX-=)7QMcDhH)3{HShnKl1z_YMoZU&iBW-*4fH~Hd9@q{gb$C6(F{y
zCb^#y_1zsGoWJqUz1*0BSD(V}UXDwczza*2*$-2)t}D5}(3X5kSapL%T)NQRCw)yr
zlvLZ@0DIjvZzM#G)ZSuuO0so_IVx?zBa-gL&&laxM>llHS0)j+wG(ZmV?@-+uTtc3
zKVmCuS*vQ{s2ms$bLqUJonQNV(GI%W(0oaSRfTfF{3gy?`kIb%?{d6(n?}8mIr(g#
zL2{m3ui}EoV7OmjomA_EDrUFfp
zDYa;};M~_aQ-48~iq8v}JZkQ0xXGPbaoHog8+$W+?c!9WTaNYYKV$OKP0YdJv5~vq
z^ch#?MMR8~*;=^R|6W*@YCk#bvGVRFcisE0^ZG}wWL4q#x$u3?!E~={r{mE>-Xm|)
zDk$$SWA7VG=?Obxb8p(ASPBcq@dse<`1Z($zK+iK^Um$`&lOExOyfR_~Mk
zW5*}uX46xb){i0TxS9o)+1Kj)Qu#@1Z-sn&^-t=>j_)y%%X?-UUZ3rF%(Jd<$n
z#|L@u?9Oxltqy%}ii_OuEsVfWtH)BV+F{xkxJ=iAAhl0ThwyR(haFSWEh
zFI$dG+csTFeywi~#@=}=HeHLk3SS@rkN*HUg#_pTKAwG?yKK%!ycjNLg^u64e3PDz
zucyF8W7^u^H34*oP8WH-*MrA&82cYm=LDmGuSnKkN3Y-J-s#hJCOXQzua>?biJnuV
zZa+&N8ap{Vni$x?f8E&`TEa6i
zG7~Zqe%#Fmw)&83IkJY42Y|Wg_37Po$|G6zN|NSQYh4>#HER6qhVWMYbWMuwp
z5k|uQy65=XK4wNjBb)yo@2|-I6OWyPok7&X+S$ZWi$T=-YfFVqjO>g}zCP)HMdrSq
zqbcRI&yLb_T_=ATQJaX#-?ws99KnV)dLChQVC=>+6VR$3VHKH4T;U+v>)ZKeC6Blf
zVI>EGBUl9duzwyZ8bAP6bSUoYi`(7#`^tw22DBGSj03Sq;w0>ra^`~&XDi$9sj*2y
z;oJ7`Xx3U;TvJw)1TN0C;}e1H(DucSnZnV>jlt{fD3%iOHK6ln_Ev7rhwuHO+w~%!
zo)NJCv{(QmywMfGw5>Q4i>G7Mh%bIDfFw!SH~HL*FEc89JXa<8&O9@TVu0?^;(d)2
zE~zg|WqP63x~ZOSJZW^h&P-%)?ddk!xTy*-uJR%>(FL-nbYnSnlJhaKu{O6v%DCNe
z)}G)#KntyCD2i*N)#_%3ifvxyyFtqoYFfHo+CR1Sj=cmQGr9FXl;zuZofCiQxX9WH
zd>V1Q;cAdFysweyZn79X-<=8?b*dX_&03%oC9=1{$+#dyx;`Yh%{Pxxvua0y
zIUT(a_=NuojxY~+TpNmqL$qnvzQ0*Ir`dQyKZrUXXJerz$VhNGD4UqLf^)fS)oCxS
zklI-DT{-tR(Bp?%G*w}Tol;*#h&c^|#>U}V4IslKB}G6m>9*zgI8vystj!a~PfSuD
z);LnJdiQPidocH@Cu7R)5}1?#KLZbk<;Z0Z1%8!*w0qh89VI*H%6C~-wvTMfWk)#}
zI)d3q*@>WovEtMoUXTOADtYpwy|ClSz=_UhC7V(n^m}LpF_PM1^}i
zZ(=q3{<^ouJW{{8tCCZj^gH8x!)67^tD`$+p&mIZ>7&oYm{XHj89th9f<<5&k>Q(A
zRD5V|5ip6>R*Gi3L}A|KsnWi_7vY>uQG>mZI+;g*IJ%@`gQJu6VZV8P3aO8&HO<1}
zK{xjK#5E0i&_=?F$}{awWG@J1QVn+0>~H7lw1@RtmX>%quav>aA!C(6`UIRY33R_5kZ9HZ;}Hjh0S((>5}?MxY`E5%%6o
z4hJvgL4!F^B731n>RX2}g|rY_iBeaAew{rRZ`bp_lvb`-ytX>*>jLHYNo!mzX!Jpa
zdfldRa*8%Q59a31S$IK_oxcEu#y&hKCB*zSB3`RYP7KvdT30Sox2I^2U4;EI2CNVY
zM!r5X@Ui`@ev>oX-@fvPazTjdsBxdhX{{qKkhJmNd{MfMrw1>CdX^tAfDEv26qbOS
zbXwHs*C38AiY_p>3^92#x?x#4S$y4%xAxrOzJskwYt>R!v%K}08zabGR0tj0ZnSv|
zQ3Z0xa5M1KuZzjykBu(4f+aP(DbTmpEJET77Ch#P=-q~nb~Fzu;nPbRfAi<-lzZ7;
za_?QUq*~7V%cocPHTqlYh%Y>^fQ)0$mpB-e9PTVnf-~X{
zsBFN8Z5SG^Oh%US9%)wY25W0HJ;n@wuTQ+|NvJ(h=A6Nc;_m(e_6V7|2MC3naC0$R0WI0OJ-A~1v9y6*4J6FLlPuZYMteF!%Y`liV-bp#hPi?BWl^_wSfWPm5xMl7@2_c+K1
z8aZkg=2l7g@x~W5!@8%dpt>9V&5&g*RIO+O+-QLAvv}A`o8Q&G$m$Cal`+ynSQh&Q
zuVGOHZ##5SXQ2qDDD>zZCn=dVPCMcNWLj#!X{vjZz}4)Ye{^iH@QTFYUj7dx5npte
zeZO(GPz0o~1UC&|qItCAVPC~Ak+;p9fR#Jzy*4JyJ6flze
zOP!6YifhU_1LSG7wM>S9s|!~Pmv`S1POM#y_Bc!bwZOm%r&>Tb9%^aCjwWKo3Yo0n67V2F>yoJ42MH$7o*t(EBb#6Tnz60oEL
z`w&79Ba};!eHDca;>Zd3vQ*}P7WCte<_=8L9(fn{K+S%<<;?2SS}ax)TE9e)Z7*+O
za?0lHU7ybzp@cv5pZ-0=YDjropQ5^hvuWDUtfDQ8oHc|Kk#d(CI$FR2>F(tR#o3#F
zh?yOW1(L1x8~9gC=C$n3?as7t<
zCklGC$NlNy@}pB8reb_VPIWQ0+Wl|2LfVUTMYoV>a|iZh^pvU=D=S^$D{gP4U@ImY
z!O_Lz&wlXU_)`4#Qq{e#aS(HUj(Apu{jn4z!`P%Y&qPOitTE$-0TTBc!e#%W7FY2p
z>SzV1>K5SIY)ODP-%3@ZlObLFI|8|DF{wviiyiL!?4ePN6n_^EKaBu4LSdet?aEAg
z(}2mq*&WpDriG1C)Q_cCc
zQ6!iNLHJc{3D=VNlJ)C^kCaJv>=2A3$`~?9e9noYNZUZenel!KEE<{_A78G{%p80k
zGINigZQ+xx&XBpJVQMge_|89ULkz*nOqLa)M=7#ReLpR43B4Y}ogjPXZ7apLuxIG7
zB2g6xMFQHsQLr}ALYO65TDBu=y&s*4ksnF;B~&_U${#Q$ms28<{G4w;Cl=c>KvEk>
zY_8F+$Ora-8h>~2w$yl~u;{B`>I{)U!+LPaGF&}yY=Uqs7)&y54@){+4pqzs$ec+7
zw>^gISW{6ZJC2yqXlIHksK#nmR9wj(r{>R?&>eUW1-OIQ|zJ-r+q&ZlKtsNFhdl}Xd&97XXGcVoQ9EEgW
zUbyb-(a5Kuu|s-eB%*IVLJ4E$lX$&c2uGwt$doDsU!&IXXdFEbaiyk
zFW&QCCvsqI#-oblv#*I2!6xSS*O5E}R}A2eJ*_zH9T@IFqNzoWD8_MiNDc(>@2zg;
zHqORPo>I
zCEZq)w$-2x(L(-X+Q_s{oFUkYWU!h(Ioj|hGR}P-9Cw-z1ApSksX|hIV%AVK5Gk#q
zZu-Sj+T`0DzNiJwet;>1IK9|^6D`^_0rO42SyaHk(jgsfyY#eBNY)tdwMrMAqn}Ug
z4i-d?>rxCBd<`TYkg2iauN?@Hg+BrLgTf@WU6tBFqBbzsAdBBMhskaxmXRCxeF0nc
z;-gJ?C2?MXqf3IS(p#m+SM6G_#G?Z}82aY?eD>nV?hhzt$a}_rPg4J4wEsa;|3{k4
z^?yA6@3e$3vEeVe|G(D~nEs&;{C8Ty-==?rtuAM1X=3yxConPnjsH(=;U5qG8*Sll
zzkgs!*n9yqG5swi{G0mlcjR9)w3wLwmN&kp{H=?8UH_>@F#WAY{7ZfKd)_}V|Cj2+
z--!R=@&Bei{2keU;<0it{*UTIH}<6C{?FUoI{8Ck6%9-fLP5t?$NGH_PNgOXfYMrJ
z^|N4{enf*X7b)BJ{7MFy6O2M7P#b{lv-R8=vv=v^?ie4FYOsdH_
z{<=+!Aev1TSB&mTmg_yE3j2Ds>Q%I89kup+M~5Sw%-cba(*BlRa7{USEcuS8THf}S
zY(nmMCxf6Lvj@zBWy1KlXCfw<^2pZmL8x3>)F$!a#GbKwB9`2HO=H7bO;^^8K1Exg
zjdVUHHazm~b5n+R<2c;YQnTV{E)$gEX>pL<1|I&5Na
zz6^5w&rI{*%^GzHnKml?(lG(hUpZ|2sE!(QNnDjfwM|nl6^$hrO+Tz~&N|oOM8s7h
zy4LA|=@U#v3SzlmG$OK776$2D{+PdzSW?R7@5c1knpek&jV;jI9XGQUyJ%m#
zZfW!0Zh19-R<16Lbz7~6Xtjgm0|TpB=_)1<4rAd4b@1f`MB=FZ!ip#hLUn0;vHftr
z4nw7b)3I_qpoa*3Y-#5QLik45aQVkt0bd~vSgI>PH&dOMqK(l(6
z-8?mJ-6t^w8;0V{LXFCfg}=`iksuzY7z>i|xa7qboz#yeFA%Syh|!#HA*J?qS@5UE
zx$CCMDlOm_uQ~4WRzi2)$eQ
zU0~#S_+Pre*{I~5CGVR8jyPhpRD|m>Sgny@>kl=M1g$K$7c|%(QLqAWiXN_82|sFK
zJTs&WE^l6cb?JkdVT1Yn0{A0t*{M-r?%#y&Ne=thHW`CcXbJQt*YYk0W2
z#|`2S5g}9*^duz(t(iq-?*rQ`gBFlG;VDb!7i9kjqt+V#LlsIy!NMG^N^S8ti9+BA`LlG7%89yR(C+3hY4A0W`@BE4+HX~htM0a@i@RbY>Rv=Sd
zGk;ovP&mQ$2dIpdPh}r#7A1BJY&sG2*dq}{Yv8;=QlXWIEs8D+wIspJ8IJxjw%BhX
zm*)A$9Ue1w{rPcJ>g+;{cc~3ZjD~aW_wUBI*o6MmJVQQB1QA+*Y(wSO0k;LoFl#?
z*^EP@xH3$vK*9#YD+3*n(oxIu&-CB-tDT$TY+E!j!~;g^i?8fYlJU~60;wlkQ9}7s
ztKLj?k%aU|l8&iaT|s(1oQcZ+?3cb`lLM!+Sh}R2vg?0Ne6PkOhiKyAVg2e&!Jrv7
z5;USLU~!#nBt>O@7s7E(nXrv2RCKU>?8e(fy^%_e(~JOp>i@_cFUb2bIof-)Ru?vO
z$Ca5+gaB-R?0iTb^?AA_*iAWiMmFN8ufK5O=>>UY00BKWC3l945fK*2l2BSF@m-$3
zHJG2QZiG5^!-ph=pdhv3v0>$0xXvZGz0-_S#qQ3e5u-Mn{WmlGgsgC&(SrwUAA=7V
zuGpLXt0!@^xC~$a0V@YHgIzNn9mz&$6<&3j&LNsDsVni+B
zJ1EB4q{-<6f;XzRaS=muOvaF6
zFLAurrWd;3Keu;WW+cuN6jpF8JmWY~D7QwZXyrA?$6Ct5u1psKcpMBF)_>!`D+VqqasfIx{I~H+Kp`15MYcO{5F^=OzL=IWLuBhuYpvCjl`oyWcEww^=aYwG#%Mv
z1p;~oyqIJIebr?IRAe!DDJ-cVa`@2~2@d3C)TYzuo_o`?yo_5$m|CxJYOU_)kzh
zwi&7W6qOVGW6^Ym`w1v6V~wigp$U$GFK4zLBEDgZt)$!cQ%P{vi9QIlAI+P&_*KSmuFBdZxRPv
z%mn(#-m$12iYbi0?RPdTgjDoqK8}d(0Cr6=QX^BM-R_oexJ47nFLGaPA7wX=r}+^j
z3#Buy(Z&}aw9J;sqW&a!7#i774-PW_20~QIJF530b^(bzRowWr!A37
zJENBR=#yLfq7}VVuw;<2%QNfztts}EE#|F
z(`OdQyUW809E{+*t@PM+_(29tyYR)a99-OVPn%2D{X2zY7y~PLVLp`8JgOJoWX%+3
zT0S_~K5;O+`?NuxxDbVX8pt}Fbg&5L*#c0PcxCxZ^6K_ock$eTv74n7#Ndfu16F=N
zE8ju*)KF*x2&c0Lt8)I%v1xpaAzuU|#P
zz-&$h@B10f>mvK=;UOT9KaZ0iJ7RXA^C583$(heE*jKReiKX-@b`k`p?CJq85IXqo
zt<5VU(!|w!RJLX1YxsdW3S0MEm&jTkSeON>wL#97bgOLu9yl(zGoHzr{qxN6T`rgz
zOLUbb>2PfH5p2MsZVWD;fW(t>tbi1lwhBobAw3%=;}MHS5!Rr1wM@KUXAKq1BAV&a
zpAf!Q?{X2kRv>Rf
zuJ5yVdosLZ{D7>Z*e(nzO?>#gmZTeQ&Xm-mXmkltykcIU3<b%>-4MP_KV7~zq%k|rYTymIQF0LK*s!Y<`Q62X?$-UL4mkZN?L+_ruvHg=S%_a57
zdZoFejg8YOLH~f3bYO!?lo(T&3&e(uWeB0vM`2U`7AXIlG)zvbpb}t58qQqGDH=!(
z^aBx%G*b!MHCSKsj|YSur}>GOGZYM|JI;5pq-PBs{P}&m8HVs4ec=!>k8&B;h5oi^
zb9_MW!%~Qot#<~LYClr1kzkp64W=|AG5&d`>U+1ldi!T?|H;00aHlJ9cQqm
zT8}A)FI5l(+PJg4iT~z&Mpo+q_6An}cxbKv`sSbS0rdt)=kqVvWqt$`h4DV55BtHp
zTAz!4zy#)+c>gV5|C?z32d(>`_&U?S($I>mgiP#zv+#c>xBpTAlw1s*|4Q78+Bw=V
z{FAq`a}cVx^%vv*V$Xzh9E5bNIt>4(DB!E;
z;NNMu4ugohvzXG~1qDoh2dBu-&+s?N|0k7a`0-yA2Fxs+jD##K?3_A($Mn~ve^2AP
zXGeES#nSRM;c^O8jWs|}^$=*8=Tj`8z$A9ys03Z%o4*xiv?oPZcldusMcpS1k3l8M
zmI+L44f2%6i+X{-?`*xi{(k=R`8NBfr0a9^&mV@K&uhQat&P{6bHCa@mQ157f7(0#
z#6AA`^YuT#(>?3~+o?+_ye`kLA?<Dl|wTU`~yiktWJ(h7sYRQP4iDBFl=^!7H<
z@uET8m-YJ3sa`Z$ubKB_$LrAt&-S3(F!s*xkWsBlOyfLvh~M$^JMF1egSqn?7Y!Y{
znx^fhM|>+&mb2IL_m2{0@rV-VXs4N(0{7`!&{a;GPWQQ1wjO*MO1(#}5Nq*?E2=5J
z-0xUf8vltrgGp_~>eN
zBrYsGrtj)<&nwusjXsx+?0R!wx0KGk03N*`ZnKX|PP*)CTssEcwbe5bInrFoZkHF(
z?`K`%Mm|~$w|s^^HLjkc%QN>mP9C=uuj>(;J1#kQ4DaTC7~K}Z0mz3sH*|-5E5Fq*
zZ}2_ZZimbX^H>aNUkAfm#w}`H^RCxkW<+4T4KFRR-zzn4(R^gOZ<@@0uCsL=6I1XT
z@SUrK^sYIWYpK`uiN)4q|IR@V+QT55@kBPAdM|ujEi7p@ZKq6dD)(sPI(MPOCmHcn
z?yU!y)NHIL%(xv4QPek*-J(u#%W8XG8ERctwTrX5^6B$gDK@P^$uyQ)UOon$L&?Yx
z_eeEAwXMTnJ_edjYBz*?TtaS`T%N*4QxA1B0h0hC`YWW38a5|l#Ls2cCt5eOLm%*;
zfi}F5B!oI0uU8ObF>^E%=hdh++gN`qnAF@*MEHKZ^|B&g$kGvJ5zOE2(EP{9dVA|mM(WIKl1B!b19T2SYBz$hYzg}_Dnp6`#{4MR&V2a;147!rLA6dmqZG#uH
zjGkfkPEsim68zIs5mcwd#ebB`nyZHGr<{>)SBp*=(`aL@%4grJdh;bDfJqP6U#?n7
z*_nR@h4x2w@kL9Sh0mvjSuMZBnkS$T(#xk+z4}
z8O2X`)3jxU|E8ICqz+Pey2{MiTey0)FH>0UT>4a3FH6xH{oEu!VOV$kbWiha$Q57v
zY;3<}oeq)iQuA<}E^3!*HCuh{${UiN*Wqm8LE&V+bhHAva6xr(3)j$TyCGJv@7rA=
znWD1HQwO`pa5arKL33@RB(`+`3HAyQ>jZ&#hL)8Le}UX4$=(tw^k$@0BfV*t;gk&C
zqHV_z1Ts5zEG*}QF(@o<3MjO{nmybPDs`cAw&6+m?7
zcA#lXh;9}%i1t)#bSWf&mwU}&Ptxdq!eEvY?XbVkA#smS|4w!QvALinZ|}I~1Wih^
zGKnwXArZra!dH3k2qSmvas2#h9yAK!3BHd!_Du6Eo$c#R_J(WCGwkNdV+W{D655I
zaE*|cIOPd2jdt9F@i9;tjsW!bYd>IY@mXWu#jKisYXv7<16OdA$-?w}a&QSD624|_
zmP@$Hr*TUXEu}oea=SS?cUZbVabDK4j7h{q2*XrHR5j{qsLfLj8<<`hy>4oM9--j{
z^#Zs7^N@YZjSQ_DwMvZ?{3b$HQKw32eBt|qHAD|erQn9m3{USQU%sMh|NT55rb*on
zYH&^X7lkqNPRrafKa)#>XKZG$lI^ZeOKHyQFDt8@A3YoALM~ap7p2A1o3X;L`!Zb}
z@#cVbC}QkL0eytqj*v4U(IFmml2Bn6(P}b0Pa&XyT_1-tC1Y(2qOQDU9HiTr|z
zPULa#q&Ljcu_jTT25DQ^qaKlU7>+=e313kUU7#OP!KpisY6`gDuD0pUiMH}t>SK@>
z`^9in5vQrAG^~e1Wqb)Ave6=F9J)KG(iYl1=ow3$w2{2S$PCyNH2CGJ&lw9O#$m(5$A}mNOs@j_$E$tyGJZq`gTrbgcqcm
zE^Q*+Yh{fs#i8Q85LF4Q+viJgHKHc*`?Y{|8=GmD1EiNQp@8!{<&oRN3co;L=17re
z!DuM{#K_VJx|t5I26+T~La&s~@b-ITDcjW%0NX9jBF6gJsisjU4v;Q(0IO{^C1n!;
zb)re4#*JUY#K33PtYtM+t;MTpq?@VOoBZSI$UD1_irqtW^)qYz=W1f@XAOIxp(mFm
z3Babfh}~DdLO42sRQ~7s*!QoGF|Tl@fOA{*;;4pmt17vvWdk;-IzgdX{_;XQ&nrZ|W&O`VKO^TM-b(JPnTkJysfOL#ZMU$2kd
z$xwq^cEzl=Le7FV-hOq2C;xFbbwm-~=on>tJ}KHmFm>oIu((0t)Yd5E0`H7#Wq(vu
zGLkw1eZkAE#w;fUKq-Y*j(+>~6F%B)mV=4Ju>MnyGHV|c!zyH=MYvblLvj*35{I&1
zbesZ3z>Z3`NdG#YxB_ov>4)6s(JRFyV+7Njz|DBdtnk)M6wY@aVVvHE&)YP~so9^)
zQM%j@YoI6`8)nNrzI5?5*s{t*YBWan%b6E!yG}CC=wO5qEuha7>pxQ>H({#iJ`5zd
zL&AFdG_}T@Q4q{dzZ(X`&RJ6QLM<*?d-kWmDd1vj_rsIOVu^?Qgr`-;K#rt}uo{M^
z!#Z0^`!T^S9v>lL!7CX8`0rZr7Ip}?&M}Nh)CsnXUnq?vz4dUmxeO=he;(o8E$c2c
z9qes^+5%WXOyOC!@6k~FARc*qg_H7m+ndixh(KteOPopotd-U@!|KqOdDTosPKCc}
z_LcfG8XP$brIaf)Xj;&{PWn$<$I&_=V;=jXq#Z&fxObnYprwp3RHhaVp4U<=V1$O<
zm9Ih9vX#Lhm=?>aDfyRe3Fbu?1xINJb2B5WWbN?N{f-G+AYk$mnv|Eagcr-IQ<~${
zn?iagNzCpQHKg*9yEcJ_tqMoasAGLMTY=_~uNmSDk~H@)^8sc{?#9xwtJYZDzbU*(
zx)SQO*nq!;%#t&U##bwqdk8b>0z61yu54=C(#gaky;D?tZmV~WoC*e=`4~~g^=i57
z{!Eo7$2Sjj2!S8Tz<_-Nu@1Khe;)tV0X(Cc-9(?S%_Ann*T0Bkg_L1(IVp^O*e7cx
z+g-ahm(*dvoz*jtb*!_ji$LK1mTPI;3hn@@J_uuCdYM)lV3a5Br&019h_7A~Ek}=&
znwqymViU168RnN_nB6#+I{$+(6MVQjTjnKp>r`Ybf;Xs#8Q;wdqmxA_1b4WD1W{DD
zUu~`|7W_65RLbFe(@?~4M3-61cXLajW(`O7cZsU**VCy2J5anE>T1)G4iVhFWlAJ*
zHKT-3h(V@KZfrWmDwzs_f$JDh_x1Xpr_k5X%I7z*=aeHqXRL3Ze?2buko!B;n0hYa
zWg7U1Ww8f;eJzqQ9rH{zVGL=P+)i+7)A7YgEMBFobT1J`Mkw4%>hK*gdYFDu7^oj*
zQ?=Ew+eo+zEsfr@Pvn##ELoce@X2~JbX5pfd@6ge5sx$p_d@dBO*hcFbd2NWcqukx*
zkmM
zA~Y_vp10YL(hcBQ{emUSGlYRj!)QNdocxoD4-V*D&hw7XEIn|B`^K!k%YM`rxl4_MlbE^psKTuZRJi4>2w*VvKMLM%t7(NDZ(j^->G`PFmkF7e?qVt;h#eQ49{dO5X}7@Q6HgiNc6GCZ40vX@)lp2#}c-Z?MX}_
z?c#qjr;OP>HW#xMt&oCg9SpoBViuQ*aLDQA`=xLE7?m!+0bJQk0yi#pH{5WYZt*T?OPZtA|CrA&JR0-?^a(=(sRjCgIF`r4*WD!^tCpQ4z&s!H)+W6X~$+
zi@Y3wDaW$p85c&03hT6yPrNYOXh2?sUHBkEb*z!v-&4w=mcg}f$vh-I40iT`GdqNh
zZtY_J%+D}X3l6x?b$K;)O_qxCds1F!?+vjc!a7mayrlZUyvB~fZS{iFDz(?l`}jar
z`+>`$<}df!d>R11VDAl9Z%poi?4wkL$!jZnf8<7$%7|e6`{-lIQ9)}?q?F{7Y^SUC
z@xj&+*G=j0?&n6ah?gLr^T8=(^VrsQepKBna*&!(v9Pcj8@MGMj{$4Pm4xIVKI3;n
zWC+<_W{e%Gp!y!j%WsmMD^S>WBHrt;%-H!j@W#T?FnW@I+Qoy1hU0>B4KTU_w7bNd
z??0jv!8q+j2w+;nt1gSgMG;b{&Nbyk*+fWbnoxS!I;FY5f18Uf?H=5_Zxx0e6tI9)
zPXc&w@{6p5;3m{%guo9JbN#m2=2{lFYOgKAA=7BmzOPdTqjr<#eUYa%dd*32+R=2oNy#tLR`@jQNlR
zb%m2}f>pPBA{=0p$|_D@ful`x#v^de>ORou3@23W*JZjh4%;Xi?TQBR&~BPMzA
z1D|l*qbZw%s?3^nFBi5=aklsjgKlo4RG!^1czIsE~2L%GADQY#AMu
zy~-tIvh8NoW8Ll)-f@C@Z5GlWHBP_zRW^3)GJ`dDw&IWVgti8a#rPDfmd=v*8qyPR
z^+{bD9E5)D>VmxKMNP+YjA02_?%kf3p^F_qt;&Luw&f0m7F_a}VO{!sbt69`@g{o5
z@UEytUDch;EOCF)T>N})$1)8^D5bUTJiS^=vvkNgag!rUz&6)kMH3672TO9w-tE3d
z)B@#wchV(sWF2qsvT&VsWfKIXdP(G3bO-vLn1*pCGD}`P!Tz$rm)-m*Jrn&rVl-W{
zfE4uVSTC&mvc*b>$*|WHMNVG35>`)B7Vksu54IoKe?9aXCXIat+KaXbiEF?Z8JYqnU&}<&KG0
zcX;GjBD)pAU)XxjWQ}neW0AhAZ265Kc=!JURzRu0gLeQb;DQlWqZk#@Tf!%b+1){3
z*pK3u8emFyyS~l2x_c&3#ICfy1@LT7Oc~Nln1*l7P9*(^bD}qzp=MrJ5$BHT}7J0@X1r$uzbORj5=q4pq~x3Z(FBW1BfQ?B>7xxLLr>y(A%>FQD*rXx~#T#vMU1X9_og}|9BZf~>v-IHyA+cK)!{TSiD
z1on^>(#`VdX>R8~0AxJML$rQI%HW-}SU?eYLy(7I%Hd8~gh*+l@Jds=o*;cLwI
zox6Lsum_C6jDPk3Tr$*CbngnizS`AntCE{4!iZd&liQzxMz3vKty$Iwr|}ZRNzW-L
z$-L=4qV6ByDZnM{;-NiJO~_)r4?eS)IgN~;KN(DYU}
zAC#bvnH!5vQwtHykV6X1#U!(AS7Ob^l&Tz~Xjk(yKbk~(+XD~b>2nt)PSG*mUWF)S
z+BmESXDBnwKhc`n|L7qXlh-xEfAqWKeg9#q}E
z=UYAN`~fBxim&zy+CkAoD|jZ?R;Dpbef>gff_leEyCQaDFfBl!T;JX*d%e_^hBW;+ez%svJ#3k?7nF;Y{+o
zUdIxGT)K}Xz%=tdxQX6Z9&9?RlYXEONXrKZYo(+=reHpxJqX%)oOX93!|p&7GasNS
z8l;&Cky6wFA-Zx96G(&+RRwj$ZMLPNC4q4HISe<(;}irVBj6mf7&&bM!B0SK5k3n(+pHr>UhB|`KY<=tHiG~$-UI14>KXEou0YxZyx-K#E<6lO
zDZ1Pncc(De0!$|Bvl*=7GKDY2yycF>_%bmj!650##cwh!;e)ja-D4-lEUEJFX=VQ*_)8fWco
z5PkJ0uI)6@vo|jHk+F9V5NFEm)T!Wrb|er1f0eHrsXYWoyh=gC*9a(Xcu6F&H3En5
zgSc$*K$RreJdslE;Y&kS(LhJ}@VoAxCl{b~_i04p}HHe#ZRKM{4MPa<+_
z5gU|c3a`L6G73pcT#4cWI~e3@l^K3$a~V<7z#TP_G(zkFRzxwSLJ)AHq2Mqv$XZV}
z*JwUHBRchNGD>0HlD}gb@CYYC0&V1N-8UaAs^8K}grmLY8{I(
zh{){oZ94DVCdI1Z6Pf5`w;>FQT&-tBq07LmrkJ`OAP$GOqwfJ-nnysDQU6@pILGC2
zt;?)=jmQ!ufUx5-(CLbI4CDGnUBLQwL&x$m0`exkKKH^L&oJB6TayG{h8waqNhZ2!
zN0S6Dwn
zusuhU1SL|O-kKzyqaG(slD~QsNxn4RiX=WPr*lq$pyL%_dLpJ;9z=q*2uHWnTJ@tz
zVl{KTHAzBE>(L}J4`@@aNq)@B&S}cJ-}bfZJ=jeJO=Mw+{^-GUl9C+C2aPLfW`a{B
zUQMA)kjzHck;zI-aHQWH!BRhAI-A1f%DB%!rW5WOF(g$3uu=t>;TK>f4KTxa73w20
zgJs!H6)VZFtYT$g*+p+nr_JBUQqT7Yf+qP3J~6$bS+cmy&_Eu4VhfUS%gXR#WjHgQ
zZdub3jaT3w1pcI)_Tui#26lwrT4F%^W)Y7
zZx>ZdWUB@N;$iExo=Zj{
zeq{X7gR?fPrEpm%;T}=~ad-DaN`VRD8ErfB%VY6@YSz
zOoYp<1cXGnti6OhJgmJ1j;3=%BgaEO*52LRH?;To4bA5-YcJj~9%ejzL%poM{Kkv-
zU=~mD8S}jD!OZkFZsF?JoDeMfUtzwc;*oXWnV(F~Wh7ucZru=e81Zebc&pm=UzOtn18S3|Jipm=Fu-}@5j6hSO$i>_!{CK1m-CSD+05OV%osGKt!)JUJ&wP
z&DMpw0i~%)90GCX`|p*xq4;zc3L%JlC#faq!F3PCl#rUr%o2sr)NY6wHfOX4#CicL
z%}K~0SRdhUb!Y^Q%VASZtuh@!c^n$yqC9awRemT&@f(cCJThAx%^BsMEaUpyb}xJ@83E|y
z>^(El$7c`WmtaLPCwD_rgDA?#gtp7_zy!FZJuzWEJlV;#PMDqnOG#6#2yiH(2!ht3
zc|xX|%?f=!1D3o8;nqwf4yMz^RN?jy4}qlG&35-N28V8(Xqgm-RKxQ283z{={GsPs
z+5$6Q5KV~+=tk0hT?H^g;jx}%(VR*#T)SLG$f$)ovLg9Gk$G8sqaw~)jxb1tRWOPz
ze$*x%bjv4Ifp}*CFd!1HU?5p5GTm;}1XQa+Ao4zg$X^vmLIGu7O|X7JBdiCRiUvnC
zc?~7w@dv57HBX~bnSny?9GGP*aLI$VHzpjyM>bjOlA)4nkw5|*5TEF>5SqYJ6+U>0
zG}SCaXGD98-!j<`R<_98S7ke{V4`sw{IEAXoCVAR8`VV7$>z|y97vgY_`bC@vmdt>
z+EQ^N0Y{B_@^HN>HxRziUYLkuF&m%X$Cy(t_l=ENn;T3caP7$WMc^DRGE?3R^i-1+
zJfvpCoN!lWIq$U4YC}qsw7Gkv+~^l%25Hbas{n|gjvlg87#*o*Nc6372@2B)r_G7$
zH_r%}Vw+`ds*M>5!OJejA*!{
zn;B9pp>PXH=Jc+-Z7pQ8-jG##6EOo>Aey4p=9s^NL5u@TVjU=QK>M1Fl;
zI|Z)nI;E)hhQbY
zd-jiek6R|thK12B6D=~X0=g2r8NGYz%{W?w`p+*=4^!-)*3{z&kzDi?w98bvP@GItV~r4FCW8ZyJ@D
z$<{~x>>etT!lq@aS*KlO3spyo%8CnJ3kC(?)hA@TzLiD>FfV(dYR
ztVZyHE|wJl001E_OQ^m?e?cc$WD=_!91Q-zq9sR9Fq#94HksL$ZB`4yg`BQ-;#Sxb
zGrlYxYO?$=h&-#M>lN$9La^vz
zr``VA3-3MOzqZ0oa$}-|j6`EgMn-k4us#@c1DlVX

PFyiT(9;G9HV^+5Lh)e#^B zDvwiO+!am|D+&Pnhg%G&QD(0Q%nyk6FgO(ooA5U)i^4?KK0=!rQ&hynnivi}qFsL{ zdK%44H%jcz5Tl`%qAU$TIjX;f!z}#hz|Zd z4VK_0u&NsJMz=b&2$77OJ_e!=Rg0`BUJpIEWDw>`r){84LRyUTYIjfgWF7k$es16Q z#t|;b5~l*ri63Et$fyEqLVOFG)Edv4AwUQg2cK!l06XLwh`Zal)Wk*tQ9-#o(@090 z#q^TiHe5?e*N8;FHyIK494N5FR~AQ((aVwvh$13%(Jq;1oL93^FW?rTgX`zWL&(RW zUN69g-~<{nr#c<7$OJwy_Cr>g0WufaWhoZ^_Y!rbAhfIsR1ERO zJ&#Hkr6wbljmS<<8b0F1=vkp`==nt3{MdToTkd}xUL@gccLUrWhIPI^04xYP4*v?m$!64iSj0JWM^Us%{ivS^A1}{pLj9eh; zCxOa8n`lgQM*Jf(j&b*pXd^Z1VCgpbyE3#%yigNy1YuPW zoW+a9(K0Z(@f!kEJndq1~ zhps>6l@pc`cn%?Dtexrb`}%i!U^e7WW-+F9OOiq=!T3Q5RKJ8Bt70TmP_W9oYDyr( zCs#=vcEGBD2NC&pi%~|^{pzXi?7DPhsq#h@R*)J7nM;SWwL;s};e0S#%YFFQ`>$VkmytVT(!+cA!Mn*NC8x00L=frJG5IcJ0B& zFS($4YQvygi8W$&8!~D1CxRx{r;UKc76uAl3Q#Mghcr7>l}YW;6PkgwhVGfBZ-jLe z_L4aE?sxXk-sQUw>7g4+u1E?VCOx6mrEIHXvZcq9_XlEM?NHGW)+-69-e#tPlP?wa`nC9k;sEjP7oJ1*5*(dN$4?j_y zu**H<7EOB5^!9Z%*nKgWo5H2}pWSnd2CBEne;B@W|bh1xIJ0J-d|j2I|AAAIDD`y2fC#?n0zV z>2A?0l1A>Sm4E=!tBNiL(KGOH-LmiOu2MVQOyX;<5k=GsSgGaw3ZkRzNe9XQnD(T5 zt<}h{3eg~njbs&#!>Yqb=KB{B33Ce)d8v?$^gruxxI3aU%wj=SF{1>`&dlv!Le@oF ztYqmD<1H`FE|b!cI;I&IYy@)G4M`nUSt;{2RaGnTN`aShg>tGfxEEj9h$Hegj0v`d z>?usVXW8wN)GzHQeQuQ04Oa$CPQLD=$;`YsJKYj6?iS}zd1LNBXEmWP*tzPP>Dy+^ zzSTclW|n;7c0abkP<*JSmoD2N6K9s&gy%im$_Kn0ochNQXhSYz;qKW6MSIg_bbP+s zKvb3G3NBlL^&Bf-RyyOW1Jx(;Hv1t1kD2`@F=L(S_Rw~uT_>Q56>+$4%I69@U{gUW zg=8kei1EOXJqFpPi`8ACC^N}EnK+1i68WjD*iaM8f{B2sh2)B0V#so}BafmzVYfW7 z{ZyVL@(*Si9Ks$kft4jEA{2n@$AU(^NeqUd#)Xj8&e~s|UCukccgIooKh|G)+BgVQ zWm*${7+yu|`Bp}$RCfQF?g{Gb!=)&5LS)sIh6p2U;4py#8K~1~$5UX{duRq@ zlQy!#)5RYIc!Ghe)wh`vYgaDGuFxo$`iU*<(y8DIu)?JX;b8}(3;}(^@pdy=R=DA1 zCbN|}R?4Xl~R;p>dBWIRnl;~kLDWw1fBj%>~Q>v0gNVCoa zp^Ejib^=|tFF69AoaY}s%`u+vAr_Afj-j4@j(A92UTPrn%kDN;6 zL^K7jLo3k|nVO2S1nWb^>@2yrt68aTe*N>FYcc7w$ba-)hyO{b4)u(pq(i<)BldWV z9fu!V9jV_Pw9qC;*ug!B)2+%<=17r1M?7M^1in%ft-JqT%vxMn-wQZmF;l}u0M^!} z8cu>0izzcxp_ha#$!uo`K6Cv9vpE1AMI%nN`fITAi{&{WugZ{zB7tK=*+5{a&C^sZ zH5)%Ta^lLPMajuH^_!4X(GAdG}9YchLHeFnU9*KHp)c?qiR^O+@=4R90u^}IFg&~ZM-Z< z*j$(O2#9qjPItHnR>lmF1n?8JD7H{V9@cJ**yIypF31VR_J3=$_$;2APm$nWatf|3MP{oxQq3_lJ&L%$w9T`{_FXF6W7X)mye zkDlwP=bQ||l_anq4+Ar-+ztky-%2?ShMG2Srh}oTBpH7@7=RulZJCFmDoy-8Ho%hA zcAqQe47x{vBedgTs3D1YZw~{Ihanyh19D5zHft`1-QGS1>)B2Q{z5)ZhH9{rLu>eo zQjU{>U%45kawXlqEzGlAe^*tb?PRD*z_5J`gcY{qW5CMOrX?SPH7_5-)k7Zx+n1A} zDlheMGE~~rFDC;!Kwa)+;5x_SWB@?ZZgO)nV9p~RCj;|6jl)N{mk&!ca&*;vkFec0 zF9WlowcE>plv}eLF9V1&q~m4yAX0i6FcUKsn7qtU^Y$`S%U|GL25boM;O=E$>aTfw z8JJD%I2n+r&1{`jxvyBO^d^x=^XVQChR_@4W59YsK{-AKta#1G$AEdXbbJgS^D?NH z-7^S|wNt9Nr_2~%Lv>1$M1tUwm5vFQ7m{-f%ijcAur@v=Q)ItJ&|1k~@b*-D_MIaN z#}IMeL@2QYHQQ5(sU&kDt~METlGT!+sW9jmZIBE29*LtQeFHMzX+;YYETU($s1emz z!z^k`N_TFPgP%&1xiHoC>`^r-;yF~Xs1`d0B*{`FuuheQ2H?{G4|b6Q@)>j)CgyJ| zO#l(AK?w+G;|)ITtExiPu5Yk7-21D#tATkK#FsG)Sgr|`*FOZnTp>>d_<+sUN`w_@ zEeHuJwmjG~8V9-Du&lO8$S}ui%Mb-!qBePmw34!TF>QjkzqFc<0Sx5G&9b{aNz>@H z&i@U>0#J8NfQs1!V6>inKLQFk|LU-3zJL9S3c9K9y1w_Qz4-f=K6|b!^W%3M9cLVH z|G4$sKczgdfAj?5gA5%P3|aw_YKit|zdc$K?qT09ElHZ%f1f6uS466`%v7LsCy-v>CbooKy7iD?CNkcN4mgI%Ms? z^x1QN_Vah_v)hzj42%sU#99w7B~AsywKk+)1r~W;?e5gW%C3#&o4ko7YsHt$1|&D> zFjlv<=yFNt>Z+N{VXC`t@hep=axXeH$8O8*=C1(k6czl=~qCRXhAc&Pce@ zA-FeG!PYenhiU6w!W+LMhmad+A%;Sq~7K)W%_K!-f#e1OgKz>^aGm&#h-UoYn3@jg?na5c$ z*1+IRtg_(IK`1WRF~ERgWcp2SydkYh|t-j1vhS!Wk8VXP(pL6*rx z3;^qZ=G}xyqtR+c8XnoqT=mKvi-|BCY_BC@Ov3U4W;2Ig50NtvCAPj!43tLWs_$}{@*5;5-)uqbx^W(J#&DrtgGup%Tu`8!lrufO)b0J#Ib z_haXj(=rg;dhO=!Axw@F`m7@5fR zGlJrIpt`YIjF1e8_9s{ zN^`nIDR~I+iP&JsRNU#mY^Rz zyIwJ~;OkwlWRBg+TufN787zWiwo3WO4KfUpA8CExe5MA`!6HTo zS1jMmIR+0VVPY5bG=lbvu1>_`l8_2-1#9wwtY6#%P>PC#)(w=8yBao4i$2K=U*tz3 z{72<_I3dXG)=Y6?L(S$;uG`u;gi(ekF?r-_gNqFlYn$ z6Fk~+#}AC+`!kuFcCf_N;d)(I&WkT9L)kSVkdQZDWSk+{qGIb}6EClp+PMkwL_A|T zZG=z>aIe>Wg3KeCLo)Ux)2W39I3TCFU9rOyZGACe7Miw|28xP->N= zqx7BVf!7A-jg(`u2USV#mN320^W`4HXYyC!=~HHLk#?daAV<5mxe!%Lvqv!A_7HcM z|2h>5Y=|-o@j&vpHP(6q6D?YMYeT`e&9NThk@W+*&_Zr{!w|_@X2ZzrdAg61Z%)6i ztIjaU`$8M`n?7PNvk>V%avfOVK)|8mbl>&X(zudUm!^}<^ROB2&Hy$+bj0f8$**|m ze#GF@k%w0e03I6TzN_aVrm_eq)c2_c&QC^dJ{tLOIyzM1{3U zS;kFFW9k~6!`j!h?1(1X5RkDE{^S2B&<#eNbPILXbBS<3`1I{zCJKHMYZni2FTZE0Ii0W4v5r zv=&l-doJ2R0t+f&-Ndu7mCVTLZ6I-yj}H$y@?#GTl}H@h&7q0sjW>tRadLsgTWf}8H9q*@;#7IhdjKQ`VBn%a8X44P2w zc{sGU4~yPC#-k0~y?Hd-?dH)5Le_&vr=d`S&7&DSeevie08^GYJlcfj&7&vl2^@S-HT0vB1`gQ+n6>FP-c|@l~mV(YN}4I%K-wW6&NNs0jg(I)%H$F z4nhNw^Y9l9?pQW(X{^%dQC17!-B_i?z$ag>b|U)7o`_~N;BLk0`Z(R*ct_CfQ;G#- zFc=#16KFds)R9>R`3nrL#vNDeh{2phUc_Jr8WpqdS#7_<3QfDSl>(9FsQTa69huAsip>ac+{?grlNn=_s9d)} z3+tgVDtN$4R2(78+yn1#Bc#RyS+u3g&0YL=_MM^<@RO|zf#o|Td8VhB_;$2}tH z6Bv$1deanw?me0~Bp0Ai2HQ#Z5;xMD>)aVs+9 z8{9AMvhHC0s-evfjM6!EXu-{7vPmI2@4=VMsX!kdtxF5lDqRu|mKAL644~BwKfs8Z z$o$24qrsxGDR?IJ@E#bFd78J+z2Gq~jVo%x{Lk*WgmTnm&*`t8M1v|jlB^y`KFUJx zSr;GDDzQ|2l_w@JmJ}abiP1&$_uvDv7;b*hn2PP@7%ESBjX=yU8PJQhzKh;h?Oe6# z2CAq45TVs@Rg(g`(7SfDzm(nA46U&!;-N`AQ2J$WlLT!%JCYzz43TKMj(ARB*O8sj zuFxKIU*V|oqvha%RKYNU#;7+)JI278ihe@=Msk|mm^kK8L<T!Dc{zX9+CBx`vtW~g3D({JkOJbR6 z8mP!2s^TeNpt9Sf3R)USva2Z&+!iP5yd5xHD{-kkf)%um%Le4~bn0ZoDY)B**eThg zn3UX`)lr1IXUb*9ACP!hhEZgfJI*7Y%p1RNpvF9SIO>ILrb-;QHs>uY(-~1oWJr}f z>|l-Q?EXt94|164eP^LTTlMw16<%bW2IS*3X24Loy}RCXJir9O)Ys)D_A$qkynD>o zY%e;_=;xa~D5%Q*woL`rbGdr~50CZPqg%#$2sxL}*ej`b{WV)KOHp_Wa$zvdaA7J% zq%Y4|F$J^&AbGc?peI1EY|b=xlmp=o|zVIdR7maQJgzCK%BQRzM-?C#^&8tF6`p&Ob?zLf8?hbi? zX`tn0vX8BDO!*tC8LgvmJIJ-i+aNJ<)|ZkY7is2{cA2g(Qho@@k|WEWU%TZ(R(=y` zk+Et(l2IkKblMDs-A|;4#Sfod|LlSJQMTJD`~$8%ANc5z=pqA=B8i+l7jzJ@J&&kO95@)pH;JC$$<0qoT-z zg2#9=3GcZ%GP1<{*#irfpwkGPF`phmErsNJq&f@lxa2-U@7q11$!HuYSrg2kHqPct zX|ShE#7(uYO;{bu>5bCZ=4*}~3&8@$w7se(w;Yc|VlsrJ@@jz2Yw-cm{G&k_+)6Vl z`7G;`>~^*A_1zH+lOKzFk%iZe$z4i06rYBJVTR2+9xoMFsys}h2%YJd(G+n^k|zn` z*Pb#EzwE;ApM2i}TP5WFTpdg7Qvi>w=YjcY_=+SuQnov4Hn$wLqWz7RScb0-N077q z&GjB3#Dqa*SZiKqImw5Mh3P^r<*ch6KBCqCb}n|T-k#d6(M_yTvl zkYGY_R0mb`8WfXylz7Z?9#@P?qZ@vKr+W${e84zZN53~Hjrcm7tp3~xuZ_;g*XvYT z&voLEBfR#%dZ5*J3vmdK0hRHgcTZMUD%cpTz+tI*L{q{7}VTMNYG@u>(@if#SoZN9W z)FFe2yBcaAZtfIQ>arqVq|#+VJtLxg2l6#kCi}mg4OsG?jCzJCFB$`hcBfghvI>R3a}3~OH_kwOP%jD)YkA!`{-%vVNry} zNEWh_z_0~4OLU()!nL|mV^lq@NZo=1bkXx9C=Yvccxvc;k69k8U*s(a z3%o)(?z~8Ev#$MM9E~Z{vGsag=pWY zO$+u}ro#k*Ke0ggK_tass8e7Kk;IhiwvF001h!T#@fyY&aNyUI;X&U1(rQ9RI3tig zoR3F_Ek23UA`4Rd1z&)b^a)=;{K%m02*~}_lkUfP%slu={q z?E|50mRIXQXqzf5ZVYXk)gc`uBS5&t$P7cp|zfSm1lNy{j=vn(Rz==XgOCIL5jXKxkbm+M)V}PkgHZlk)MvFZ8PZ0 zHn0EcJ#8U&)Hpeg;n%3I~ zPHR2)>O3h>WZ4#SkFYFaoC^PyOxzkaRqI0I`cNwjDMYy4qFPf+|t4r{)+^ zX6^4uZhB@Ii)tG{wq{!?fv(MYgWc8mSi3eqjos$>>A*sbFsy+?Za+xOLLnkVE`%ht zEc`h;pnwD^ZwSj-a`NvUR2LYMAdupIozvev_fwUh^Sj4iexCZ>1HjyD>3aL`p8KiC ztQ=}j#Rs)_;3WPL_nJsdrizw8p27y3 zGect7gi@9)6ha+MkQ6@MUdXXW+Z2C)wSk?s@&t`}DOt3ExN2bi$BURNn?m*$XH09@ z`7`leSjj+G@n8)U6o;x7jKCx#umZC5#9$$Tj^rgmb*l}ZvPBB)o~TGSv|lL0#MGQ< zuJ^OZqyfbnQ8(W6t)9#^YQ&Ook=GIey`m|Cc(A0gCW~ia!FBk6Q?}@Wbt z)Tq|+t&Vk?J8cpA&9!()n*+s#?@U6%b0B0%2dGajI%aX&^=H^t4PN* ztpY`7I}CXfSUiD;tpq{2voRALwG)^xoiM_ky2ZUr0(Eda zSxjUyP6-);nMcvv2GLgoiCwr1NUWMbmFvgZrf7zel?I4K&-yO_2@u}P_b){l!8k*p zeqP@lcdi|lNlFH^fT~)Yh}A^9vdSH1xb8U=-Wy7L6=jTKc4wT0#1v|1*Tl@xbTFXZ zyJdt|*$beU4LDA54(S^C4&d7teIPVBNY!OeB@a@9{Kz^D2vr{Q(VkEEp(wjaa*bADDqfbzo3MGnh>( zDxD!q=nO6F`ZSofBCiJ2?C7BBJkuc!oV=(iS7@(m1xGIyi^y0^2=<+rY%>?}vCOTY zTp+)-49$E;jOWP}hhGEurq3K&MdRVHp@M8SBm9+?#=px@WoKbsv>M%EDpfCO@i z5j^C8MkS;pWu67Jmt2KNE#?*VHuBk78glg@uS}B)={?AusjozBWSBXrlcTvv1X*?r zpvE|qb*urdD0~1ZQ&0w%=}FL>ZA%Zf4vU&D0V64t6|t37XMmv-s9?sji687tcwjpx zcGZc+or?{-6M6Wjib2R9!9c6#6dcixj5!KS1B+mV5siQw+j&~B+GKSlT<4-5M)<(W znG||K{46fXW>@=UkzF`~1IuMiLIN9r9HL;gAzy~ge$WFKS}DeUc*Ru;GvKe>ie@qD zP&~LQ%#i{54P2!ZrpPyDZyHCB_ut7d@VHX-D~UIJwZ#%*s{rhJf61fn2$lvjl(vPb zVvwT3aDF8EiaC~`7$t5JQcCoaPa6mvV~5Xe^ol%8!*I#b-h)U5ugFuti>r%1EOyeb z`zb#}L%b?8DcCiFCPciYFvJ32Hr`LXSn))nxQA*HG%_ZoenZW=pb9$FTTmUqD(nbV zjd0G))1r(vxRew`pms-SfeNvD52QxYDSm;BP-TM>afuKMYqEMYSWHSBOiH|NLY|V35Yi1LaxULV-t9C|Gg0H3AUK3RijxV805%o^o5hfv^Y%cF0Ek&68%y1aBeCbwUe@&qaPRM)n@v2)LiyMM!%TZce|AsXY&=U4 z1oPE=X-@(C!qSeVOqAN$R^(gCM;HYu)qIPqsGPIzuQQ@B7cc}~os7cU2;QKYyU!SU z2eL}2#t)JI1SV)z*@jOf#a$c;J!`Y51oIa%n7N`P3&Xf@A!eI~YEW%iG$~KqxuY}9 zt@kaC>c{yWK_D-Ffk!G6q5^HFRwE4(SI2trt8MjR%1c*!)3<6dK%l!-MTR}JOI1Yw z))SF-zZ^9&$(M4eiHPXx`RIvOEaM#P&a{2^(QmX5o)L`!Oj}P(+^JhnM2QfbT-Otm zz?oZ7wDzSbdXK4!{DFB?MZRL*nm}5da_fow!gvmy^1xq*vJ-i}|E@IeTTx7d(b`8* zM1WIITTx`-NjZw5w~wNDdZZ{?sLHue2S4D_6xY26`nohl^vt6uCOKHQqL}1?x)epm zxb>qbB5JPQ=L$PnA14nA*1Sh(?_E($O3`yEilCNy^u)x95l2t_piapaOE5o5B1SB( zf0RUYENV9;kv~|Dl8E;~ygo`|Vs@bGU@BUBtAI)1qMI~2QT}H{W6t@lBw{6dy_7^0 zS_$(giCB7Q@vbCZGqOX;`sR--Rz2M2qR6pH!0aDAiGlJ2Y_l9m_WC5J&7WZI+-ro}=w=`uo|S_@2EpP+l5Iz5(~1HvHG!qVk4uxqTl#_t4@yBV7{6;yR;B97LL-k)E~( zt8qck9`bZH#@<9aAmQ#*P)Z~`8#PU$l@o|`F);HnH!U(SW^z8o+VzE5T0Ka3BbJup zJ>M3Bw%$rc&S)*xBme}d$Ev^-du!2QhmT`P;ZXHd%px%c8(v`Q=ZqH^duCsX-+`gj zX3w|M)q&I!tSd?1%pwM;p0(>M7E^+ordUZ0cvjX3%#Ap4Sf4>)r7|`mF~jiy=)gkj z7)uIj01E$GzYus#Mq=P0X4Y^>W+u%h7R`eT(<9sBv=M_EkK)Uyk<$eXWEyS{dk3G$ z{7QYsx57sPPg)&{2_qa}AT$27fRp~1C*n=mGcv2HNa(^l33>F$U<1CSdyP0h#ZZ91)X}w#P{!DwoZ%uuT1BazqC#w{CJo8zyr% zIePn;9IfXvIeL$q92xo1kIfP7ew!T8G1D$&qJ2 zZ<8aMF&~p7OQ6@=b$eqW!2h;476p-Sdn2!pc zXBSo>*p{l3vLmCGPLs_xSv{-D#l5xLatXo%~oS z1h>YDK%U-jotE(~mwS})Eo@I#YG8B=ou7+ci_TC4(A%;?ScLfX(3mihSfTb#nI>jp%1;XhV zIa-yXiS@75Hk(NYd$JNkg&;6oYE996Oe6%aa1y!|(R;8qz^AAPHRdgbWWqprZzFE7 zHGd-01fo?$_#ee|yXXt+#6zbZ*&@)0r!$e7-_&Ksv~QAg9=J`57_73eZT4DOLW31n z85O5O#!#SV*~HPPy{-qMh~t=I5!3as`XDqa9e4m@#!5b_Gd3+flxq~EiI@6~$R~)6 zD11hq0Yd_3IPEHK^IiqE2hCQqHw%nPT-Iq}dW{}#X8-fDI4CveCTb6K!_6Cp1-eZ+ z1J}jr^geWZbJZI2hV} z38n14=T$g5g~Q5pUqJjPGQ`Rv5uL^eE>m(rPOJv@QhK8&0n6CyrXy5k>BsIyikFR% zFGV?~a76*8?@@}llDeIdPQeMMx=}y{hkVhxL;_Y5pdlq9u?~nzjKu4#hkzSH+_5nq z5jdAwQt(NGS9P8iiMPb^%2Qi4CjoYHZkz2CX#hjBW{RC7;A@p`4WP1=@--r2U0@!T zSX6{{0D>g#qFZ@vbFYf7@#5)hJ+1`{xrPnzR^rrg>so_!{=3Kh9_*=(4q`wFg7E4* z=X(k*a?U@nwwF8zY%SSAqS+b|WAFjsg0WDJz*1h!)y~i-#?GO}t!ftqrhUO_@5O?p zn7kk7ozWzLFi@O=#9$F?*SC?Fb=;EFWa6yfJ@(MmvE{WX)(dJ(S@Vk25V94P#>B-m zWbiDs0bwa4YmgQtUh+1c0Fe0_Flf?(ilG=%R+*s%&k`_mF9?H(j3z0Nf(erdiQ%$? zA)dYzd?NEWA@G)Wn)VlAoAGWV2t-CO>$%tFK}QxY6?jph#tgEW{zrve3fad+g4T1{ zXDcq%^jFWZ*dp=^_n=#BYZZpguZ)WFfcKqJk+UG3TL(pV<^ev``T>kUK-vX)Lzx=+ z7iF+rvL)Yt47OF}*e{DM0A=QRP(_{5pb065p5bKOinVy7lm>=$ts+`*_JtkGy1Tr=tY2eLKl2{Cc;K3?1!ql3{|a9VZ#WyrlHFlgt9+ zwv!B@V)=4Ub0^EKP#`dFjBAALy*tS&MX%dQ25L$3c*(GGxgRgt2Z>ss9OdKVD8rys zE=O5aiePh;@i+5vl<}SAc9d0xI&4Q7gXS(b7`OXL9&nG>djy2AeQi`0?7IA9SnV;6 zpA2)D{rJhAbMhEDpS!Dx2v@@%9W@a>>#S@wu@TgN)WpWj0=JsjRA7Cpi3rEK9h=P% znrByAjQ2jTc6Qe%6`TfRW4_hI#;OHdOKc1PIa;E(kCx~?t|d0P2)35kn1cM)67kZq zmBc3dsOyMLnME%h5wjj;D~U}QrL84m8C$v4M8popqbDL{Y|f)6GK4JMdLqLU>(LXd zV1HXr^!Cvct;h95G{KWxPsA(aEp$B*J*{p%k>QT{=!y8`mToD>mgUy>vy;Ty0xdWa++sbVV|weCvv!pE!@M z*c2VMB^X<$OUB{38uy4~jx6blIJ>Fdx*`sHJRu~!4SIK7@#Ajr5LMbyU7r8hJ(paL zI)SPE)dR41vx9d8b=&^O^`DJ&vbtDzm&*2L2` zIvULf~WM~)%#z-zX~`7m6&g0HGxeJjm_q=@;% z0_4km*h;*k9QXvCHfKa07KBuCoVE$HU{G1(CRFok&Zq*7%%uX`UdwEg%T>xj_5^#J zV7`Bmkb;jvAaWkYtQv&sfyH~0x#eOY!^9kjBp8C&($v+3uce5PnJK4bTK|qnp~A7Z z&{6VJ=uma>jgUYoNE!ZA!|LnP*`j{8BR@D1Lz0m;>(m((&iZR0OF=k>)m-QfQGT?he+o;ww3_xQj zA{CxdSgYxe#7RH}NTm3}n;Pps1|}LDu;Un90?TTrRu|+tdMK1=bJsqL_3f~s@Yl-K?F}` zWIbf0Xu`@4%5Ru@FK zOmZT_OaO(4R|F=)qQaFop+a}XOgd3vu!q9r!cl8oya&WvxcHN4=2Uz=ag7@jedE0_ zV9n4i;VZrkDGg=}EJnm^n(H7qX<)XfV||ed)?;0BX9U!K{X$|Lam;>jpDXolmVnNa zUxCcsm))VxQgqah`ObjRu&iq*N>x`F}4fGuv5<~ z3cC5jh+jTID#OnQb*5<_H6=mzCw&C@O=Bg#|F-;neDYD)mcndJk z0bJqLreTbPvU{)%8Zk(kmE_$3Nnh;>2S3O2mLxd?>wr%HZ=A{=hM0bQKh5`<-%m`z zU?7l62t&J@5D?2`U1XRI(dOo(=5Qc+Af7L>EHZ?biKw!na`)ZZC2LIyS7Fa&4e82E zNZ2}5rN^$pyfCRh@S7s>ZS0vS&Wv`}=0obf+X6nE9x!!`Xv{?bf#S1Q~ z<}|9P;3xrdgvG8TVu+8)=>xwRXgS64M6gsTI(|rP3N{rx--1LG*k1rX$uw#F$*hJ0 zzKptpg>PA!1i5UrErpS8BG2~FcUI=p2VV}cY7hJ2(}mft>cz>4BI0e}BPz3%@)ug= z`h!{E9i?bb5m1-;6@x{EAwG-uBWFB77trDH)v6=|;0VlPejT8VTF#S+6W7^9W<0KK zp^!{~80O8o*@=IzygXn;uU9*h#p((444fif_@@T~V&pT8=u)KDZfxV+@Ma(U34)1v z#0N^UBP}jv2xMUzER&s}+?Y(Eh3MgyG6-jZiGdaPbRdw6g1;H^>yxd4v-_d(n@_9` z_ISVPNYKUznw1-ei-?SYnUBECGKByfnnD5|S<6vMB%w^`MFvtKi;vsDr6>BuEHfD?pFYy`yzm^dP zjz+=dB=KfaKF5qR46c*7`4{GbYYRuCp=SMV4=W?%J(Jn}xrjOF&Ya*7ctzEnI&B*m z!R68^5~j~_UE3v*4_+5LtViMW5F0AVAmscKm{d27l74UUVyrxtR!cnz8c46t&5&?P z^HRPPNjUc-WiMAG3v$r)x)n)y_ZxV+6iGPuGf%fGl5pn3_UVdbfpa;X6JLn@eaNdU z=yq`cU}v@(S(*x`9yJm;l~J0jkp$~R(;|1nl}PJw9g@%D(3uX&U#Gt3ih;qhT!qBP z^>GOvaA$;apGtVP?-5L&I=2d0cn{nab|J4(aWqL!KV#kZgx}ZdPbq z)G=L$EX;mWE*+8(CG4c>keFyJW9yJa6wO6Ka*xA^E#;ZXJ^E zP3_Vl3o-2NoKjd*%P}u-=Ucr=1#SQekUk=@D46Szg_Tq0r9)!Psme%&Bqp#P74map zI;9BPx~xk-y9a!}(YMW%)?@zF1JRUbZs3PHb!0lYUr5e8lIRpEf#4tH)!?EMz%gT( z1P#+XQ>-6CM>^bVje)jlJogScU$_s5k zeg-09vG6QO1+V7d24UeRRhI$F2;zF61JFZJsclzOUxOsgSe3>n>bo-jlXxO-72K$q zJrIfUOdSsGHn1dDGt`Ju56?3_EAkf7f7oHKynwi1Ls|< zhFUI+C4{OEyDfT9ObD_@o$w-LT}w(ugeGniTy%wY7QmQBm*5Zi72qneTrg|Knkj}K zA~*RE5>TgXVmUq@miQvEeb8H0-lv7}ohf$D-v^UE<9QgeE1@in?M@U^MG7nI$zY@} z5EiwYln?Yju@aKA#+D>D!gR@#JqXufa^x)O3A$co5)UcCa;9Oa7njm~ zIJ6Zg0f++`i9m&4E|HA}y1TgBBl8I3??G}h6mi6o01TE*{-Ru2%OEZVoV($x%b*_% zj0xVU(}o#h*c0mMsYmu;RqYi~6QW$%DB;3n?zcO2Q&~aAQ>>HzrEp z?P;TG0t9VnL?AGX?@a2GnTS#?EGou~{a1VhAMD8HgP1m~D9bX4G78lcyc|ZS3K-br zx50kI^xph6I#u`pa>`~-FEKUC;%uBg&=6`5yMjtg_KHkvNn!TXZ}tQ|g1ebnwJRQx z3s6NTSaf1p5P^CqjslY|Oj(e?R9Hr;@UV3~0GOo- zlh9m&NP|#`BR&z0x!bZK;0f=^tP@d(QX)V%U`#3G#!RjhiL(Itj3gUC5SyWq1~{Ck zNt7-PK5L^P7)4!R2`~Z3J#-`>a~FV*h%1k~jdhB&#O@J9x{mV;D5!%A5AR@+D6oXi zy96Pm=_T;3gxAC)kC-m;cO`+XEF+cO^n+W5W*6i)Lm=zNtwZ4qNV?c>;S4y2#pRB+ z3dte-`FYZX5Mb-sVwrr)629Tg$qo6HxWFRDL3HgDd92^Wkp8|vG)Xc(DpzK+Y3;v z+$8)-_WSrS-tDYXj)(x|s`xn_Ma=B`AJFZv7XQ(MKsVM?V;PaPS%38Gry{ecr@wmi z^6Q~r9W2+CAMgIv;}3nziSvvom`Yr6;;s0zdM0nuMvD=CC?cjE(Px9#cZ7L_FvG^1 zWC;zlDl_3ej(S9)%%smp9)XC|x(F?Un`5!}h#F$tOSRV%@GqCs6CuG7@ruhTuXbVe z8fMmKX^)7n<4Xq*c|>U`MscrOe2KoN-Nh4k2kx464*3Jf*py`5vC$$zjwOvYTiA-SQU!lJd5zTA73;ZHW&M z1Ofpyb5oO2hH3-+0MsX?0A+7J?SE<)AitOv)m@D1t*1v7QB(3EUmdDAPyzzhSujda zPa^9`8Uv~UXcS{ivJQ!f3eq#buGr%)z*K@inNA^wvOG~hYbE{W)K|b^)bvhN-20rI z9J=`q!ogik*+mmp0F^EHC&3UOElw6chQ-%0aVl-)fT-`2Dtq#3z@@q~cvH5UZ_fpd zHgo094Xv{Ey5ei6eUcu4lBPG=NxJG$mzYhYCimM*=YqEF)N{Pks+YM{6YuW2($VZ$Q%nlA}V5?{6#8mEm}-b+zgaN}N4 z9ih`={+gGy%cS7`+95fh%nigCl;9>YE1XW`%%K%F$JW7$6vjH2>R&httAZqz_kES$H z2FklMngrRTER$Z7@PX7Rgn&suLdlO#O-l_Y88=DlwsyZ}mCcSq240~7eCuz}oavha z2PDrF*;jOXYW0Mc)%zp)H{@VWsy@5)5}co5BJbj#7UcgAG|%`LdvO@;>kg7HLyfQt z&>o=o&^ljVg*95c`lYL`LlU^Gt8>8<(JtCFnnJ6$o#j^X9g+~$XN$iAqkWQ+OO}){ z{>(I-XT)AEuM~nw2EZe{;~()?%WV3ZmtUWkL`2fJ5#fFiC1w~E=qwb6aMlkip(~WH z>N@Msr%IDf--|_?os}FOzO%b^TV~qLDx)_P>7bp3CtxBc?T1b0kp!`jK)OvuA($au z3IM#x*b`ZM3+Lb_mGJ0}s(L}pvBtInHo!^+kRm!hDW&iaN`}JF!W`%HYVYvLk>CQ1 zd0UqE*!p#%k*9F@&XDoAoz`pWU{CCvoLm(H}XO)W7QQRtHF3xheQeUp1R^H9UPj@H^>Ozql4sj%HzWP1doH%GK1n);_=!%4flmL?uQs`~ zlFpPK0k%hZ2#fk+$ZG`QJ3u@>o+`nnq4z|in{Rvm&$OLKLYbn>DxWeR(SH;&=Qolv zgSz4~ywumkf?^`H!9hz zmwE$OEvZwOB%KvnX67_J3AN^YIa1S$;DHFsr5$j)=Nbw6HImZ|nm+{U0 zB00+9`?TPk$k#sXFwvv`y(FQ`m6w|}MTt(*8{#dd`_wx_8g~yW2#HuTGD|_QyxP2a z5#r`vp)5B)fNvdg&hi5(z7*A{h0gdu0Y9uNc(2=r^>M}>GY)5*ul0oHt(_e~zwp>x zv{40fejCRi#dDhP&Ycu@>+hYMnq2KlSPD|pS?~~5;*d#<=G4UAlS;O&J5`;W#lH9F za~OjBt@<(NvfiXI>o4lgx<4q6HcrE9#ZE>Ry@(Hr0ykaNsYw2U>^@nI zdrCkOqhBchGkr$V7SJQ2aoR)}qYpx|cfgO~i}HX}-0QC)J%T9!q{^Vl5&D~CKlunA zxq@i387P}o-HinZF_j_1bobN=MRgd-%OQn_>>xt+jF2i$l8%@bTU4UBNp*>N|&hCEfiRK?|oTI+pdMe{=C|!P^KR)`#{lyn(58C~; z1;-RAa*@p6B-HLzp)ytR?Qainf%5H}Nuvt5GTscL@in$v1Ml*-MFw^WGlsPTv)Yfo!z*I zM&nxDMW>*s{vl-uZY{o|ro3S1+ z=Glz(6W{!EdWlueW?WQ|U>r?D8kD?RM;Gy(8k2oR8;U6I-MDbBYW1}n)3X3s_HJA_ zwU&H#=3&-q~Uz;)0rN;D{njSNK~c!|9m!$ADZa&}{SUuVPEjX%H3DS^}$r>sGiQFryIJTC7?uF1#cDr|{8Fgj1poR&XDDCR8S|*+kzb{}s zQ6D7V0XKD#WU@#(#_9=6$5^FlDI}Ft721hgYgjV?y(kLMS}#yXk+XHRVrkWRcsIae zD}?V-gz6<(j{D)z>Qc&L+wWcj$`4D*HVuCT%{6QtHm6uAOVl=J{Yd^*>z z`6s$xY&~({KCiK?yj~JdJ zKD7GG_K2gmieB7i2k6aK!WRHj9N73OEVMlAPCRJavwYs7JBjNhAs1N7Vritgrpt44 zJEc2C;0l^U5sJ&G2CPUFvz?+Gu>T4Bzs&>R^t~V5w<|?#vC2^bRMemYt+^=}Vh=av z3M6sFfK&l?{ecKC$y21Lfx*f%jHo4mZg)H-%#NzW!na*g#qpEw6|ia4FiZrjE%ImX zz!i5m(@LA!oPs8oYUc)!UQO~?Q4dTV?)?LFG?WG5%|CzMB%6{+1 zmsd%w?DlowZr51JdsPE23mSigK{jU#e10t_R>g0&?$xf0vuS`hR&vhwT1`Cj+OVsL`d(LvXvRHBn%o#J#Wi&Fpy!%O8EYYtTLetn4lebyTe!FMKD+I+ z3^&{T4@AhQ>ugVcN--=Bi%PChN#oc}8kOhTQGW#lZ*#t`7)nAnEN7{Q3~&J+KcbV< zW4|T`adkR2ZSqw4SY*ZlDNAf#t#$-QS%XWiPx?&~|Ao1L-SU3I8(SE8?Qd?t)~<8J;0W%Rrb35$JUQR<~s*_x4Dc;(Ag_Vpi&jsFZT_ zWOUf!j{Zdv+YLE$irT{C$Q%I zHo5+*2cGh}AbGQ5A?W_+e-UyWq8rj+G&_g!83<_3N&%k zhLESd+Blq^5qC&(dgl8?GTym3vFJ{&BiKHNR-MuOn`A%v2<(OU>P=%`!wb!@IhTt9&LAD!$XKI=rHv|&cowgf- zw$I~sL#VyZT>AUjJMJ+6g~bLNX!ie(u-_+YE$H+|0+3miQ8$c-y{d1wr~0&IH0!s+dm{{f_?uc z!}-MIZ6}0*G%(1_>@WoC5p&75L09pQVtfApY1H|TUsig`6$`?)fKDclxAh@Y>=m^T z3?N06!`oiz{(0kQv{mMI%n`*0A1|d`U+sgVxf0`Oq@(yr<7k8<&_QYAXap6Jm&rI9 z?VPO~9F2S%u_?->t7u=kHn9K~^T24N+~uIyKpJRtvLGl1()421feoaAJ84GSKpOS* zaJV!ndxBodn8f^$t{07o!%djVWH9JBa(%m>3{^y8%5! z(fYyB@SW@BH)B=w=Nbm|oy+W=3wnTg45MK%WYlaJ4OCA<#;0L4V(@y>fzfo8TWBvB z4UAtcTse5+-~>y7-AiiK>QkjrG)M$D4HOOS5eF<#G`GD`G)J;gG*@60jcCXM$_R?4 zi;muIGQ(()7>Zy!q6_eERE$6l&0*KGeb5iHzO`O!5K&MsnKw(?X?mx z8uk5kFlrXZ>i6t5kHUl_|U z?i#B11k*VZwfwqZC{7~ZFdEB6VeN;J`?KS`djdI*CKA)H;Wdk?z1sxa<*U1rEQS+3 zAzXFcKOseR&OAsS?NHVDXdIo7@j2SShl&u=obv5;mE(z^H#ZP~LP0?#!cX;P2KGVz&&uLTvr`7~D(p zTR=d`o2e}8^)ht47_Z|V15raq>?^v`2X{1>fr9$##*4d%z3K@l_v!jFUmrm-W>;}A zZ>inp3#t5h?tbVqK9d7scDr>)W9PHyUzy(dAzu9_iM=ldU-4Eo{1l6&&zvsK*O=k~ z)Pzbl*akobzBAph0X?yy{q|GPS1Df!%gk@#g!Zn&)PCY)TMpM1R}H=EaXg)LPX%=A3vb_r@s4OKx>ey@|Dx*yviJr4ituR{b!Wu+ zRhjVn#_-qKOWEM%o4pi*d-z&0(|<~i8>lapW!PSzp~KK!^y6`w;Z*|Tak}QYLW~6I zc!36cRrsmx1sb9dn#T_`l6e-kA806TrN8_@gL;YK=$m>b=1n^8kK5jUpd;C)6|a$2 z|3z^8Kv!b>ZOBVgj~{3d-;BgA`+@lOQp)iI4TU4F=Vw3%_iA&8$y(0^IUHDa1Pxp; zW4t^;jK^5{c!K&O=-Q7bsEbtZh7SH}O!wAgUFn;PW#|6j|8jg z%P1Pcza@F9pmf?_aif5rsJrRQ}5IfBw<1Rx3g0E|ieR5MwJ42MD` zs}g`Nl3q2(Ild*Y=cL55Kg

%&leL6a>Y8Z(oGu-)HZ*$EFRx*R&@JK>GIS z*a7Q~g1#{rD)C(JVD0uD&MnDFL8c)BJtG~O%F6dxv%)oS1Ec8^Gd!03q>>{!_%t3+ z93U^IxBIIXAIg_mN*)`c=jiGn7F&G9Yazs!z7_(|dN!)Pc;KISt*xj|a~Iz-EALsJ z5Wcm$dZT%l_ZGzZN9&Y&^#fE~PkU<+$beodhVY7tOIiVa43&1p2{*($2jL2~w|YL# z1^!JE6X6Q%zownbabHguBULzbyRRpp_m;N%dXnDoT=(@PMgDoauX!zCPS<_SHO!{% zzMjy*X_nc2O?w2A&+cn}MQkA9zNW3yaJaA4o=4CB{p=h~_^CSR>E*tjVz+$xkdI*d zou_Jsu3seAeH}ObBG|Ub{^g&NZ|-XnY{)nzLXcEA=}J_mK zbSOaJy9BGR!g}Cc1xTMgC`4QhK$R07xkUh{6Sg5iR0Y|iS!AslypEuF1E2}r29cSi zTIxegh7DY{YrCRbV5{IjNNFB+G4?f1Vro~pd>SU0s~yXSIu!~eHIffpx}ph-&YnZ? z2bZeL6Ub-C4MjvibeLjzkevbv2D!Q1wy%gzhk#McMnLe%T<_%!C5Y|X@6i7JG1y}A z2b=^O5HFg<&k&cf=5Fiqq#UmN&`L} z4+Z^KMg1tK{nxvLW2e4`@azmhmaR+o!D+$1VrZ_6^z4Wm^(TZD&iy|t^x$X6D+kb_8&MMdvS0qy;@eAkddnDZj$=0SDuJo+dg1?Nw4& zjTn@%PLv3wrAQj4fI6PKoZsct!h^>`_d-AR9lz7B$;HUcKHF-SZx@nZ6%^gKc_g;~Ocj1|AbHya+yh3vkbEqEytMZoA6kEIVvWxcY zcCpv%@Bbaiosb`M&scWU7w>*n(vh5XQ;HL2f03MZ^Z6WB(vh9Xey`e7`#$N1yNs(O>crlcff za)~`>W+TP3Ag%0E82Ck2dh@`$(W4 z6IN3ge1JPYCAS0jT|Xswv62g$G(||UQR>QX$-Qg$@K4G8^?lb*iDI(fB%si`A>Z!! zAxBoBs*L94kR8Ey$AZDb0-U`%uB)A5HMK#7H2E_O5{FksJ*#>btRsz8Q!02NY*+hf z|5Zg686|N6ko@EuD6sT7y9_E z^6yHnV*2QQDZPCa;maoC>&Fp?E%~Pk6r$Y>NmW{F*Phgit3~je=>I2~kDa)fHwYC9 zSz268HJ|2fqXM55ADn{f5))4>|1traDBc;-ncUq~D?%jkkB4NGC{gj)S^_V`tPowG z3TXL`q8*Y!C3wfYs^gk?Re;|1G6GNM93$|vyMkyw%Y%QX^_4ig(-3e-M1iP7o{P`q zF#?kDtXUCNG;BgM{{Cu+;-Vm+$}j8S)}RWC;cHQj;OvR zj{H=e{jz?CqO+!=uX>N}pBb{@^s3FBmE+Ju=1o=Nmk&k7cT`s(;@ca&Qn~O%bPqDTSo#uMb`7zkG0DSDK%AoQgOY0xAH2D*PR-6QY)pd*& z)wc{;cP7E6+in3^I+EL!jSR5#o8&C`&#CJ9OWooAZT`Y(Sl>p?kzBP*(V<#?lVG{1 zw!KNFZI^>+5@1?d)0VyW{cZOPAAJu7Rk2;0{iKt-^19D8ru{dO0^nXwP8Q#nC!NP zwd)`hSKxL{UQJ7>2UQp*^^r9-%q7cjp?VY)8!7Hp6)iaJE(nsRf+Q7Bi!K0}zz+4q zPxyFub|`tfhmSDL*nHSLHrZ|!PUW`w@E(TIzJd)V4nYhpG5+F{Srls+MgVHFzzm_I zN&j1a-Xjpi=}YxP?-C5bSzV$)FXJ~!EuzrqP%bNcaB|z@yBXh{ zPf}d%Z94!!CvY!U-M1ev;&^=tuFm-WO#yaxi3SuM8ysNgrm&c%oKeZWD#f=6%NUNy zrTGFwJ&#x|{BcHAx2bAD^0&#gV3L7YBq$77GLpn|XRmR4CMjn`{jo9*TeBJ-hS{D>P*Z!|5u@rU+SoDNDX_ ze!F4`uB!*I-YH1fLK&OSoE&(m!!A%P9WOT<5ir@)(Z;$kP4bcSLv;%PPh+0l)Rxqo z{@OPMrVzkokq;FskQdWHO5l_t$|pUodDj1DW76uzb!Mji@)Lg z-Sh#vUmV~=xQ(Wwa=Kv(tEL(ZY?thUtl(tuqG+AFvS?f}z6nU=yc#y6`6$Hzl7H$b z&{k(sNWgU!(D%bSAv5_Y{t+r+sFlP12^AxvzPD4Ak4jH|OF#l?^E4(2Np_r1#`V`< zV1RxiIx*Contda7>n1o;7`F<~H<575o*;zWbv$iC-08hm48?s56{7$4rm8*VPgD95 zyex;0v51s%@2wEZW1Ir zY2cL&cVxD`t^iWoqyzC(!&L#gSK?cvJ2TTMMA`@-;31-&J!p z?7weKVr!zy#oS-!L{~M1cFYN2|3zkn&57II=ERYNIl&V~Y~_M?Hv`@8X3<6Ky0$%` zcg*)}1(cI4px4wBlKXW9<%boy4fYUJ?tGaOLgL1>P>u~+qm5%uoc1v%uEgeq+I4Po zLQVFyV^9EF1lVy63V@Avgvp>V2zqRb0?4!Wp>0v{*;c2vC_uRO*I`9t8DnFMqQj>8 zyskKdZ;JwCZw_CsEehc|_x#H0H`N*mi{f*NDg^^;A+?u9p{rOk$D%OEI3J5b&&84m zi$XyA@VMHd=$r2&EDAoQ&weI_(Yp29Bn#76sEvzLl^j_!6MO z+oJgVG6PMgb4%pGk&m%!*Yb?7+LQXSYgXPRKtf_$jG+X72W!a_k!|OAt(c%W;C5?@ z4t|f^0K`(>V>_N5`QKNx@R~Pa;f8V+{2R3yd^uD|g}1<8FrFRLn_?-yZE9xdh7bfH zogT0pEq|tdp~{z)^;O(pQikn-=N)Zg7ikOdosW)L#;qHCnZn2hz(vJ}SX5voSL_hV zch$5Y^|3pfmHfM|iag7nVlBI+2PuJ86SS+Sj}Iv#`6n-bYK)cQu$wiCh#o;eCFORp zJ6OEYbE)i}W>vK!a6Knkw0dc>d0qAb-Oek^u4HrbB4fgYQJg$EmN!XtFk;Q zqay5Ycj=DOjABmyiRg!s;wuRkeQhY9iSvjRp7!+fsiG)Z;otx98Z%ZsUR&BJ>VFVA z(3Fndy(u|Q6Dp#+LOu(HUe20lnaCq`wZe+>E?X-=YZH0{?a)^QGYFCE`s%`Bj5le2 zRI82Xh5^XCUFAaf`+si<6~MZfOYJBT>Gv`VuFfkpenOr-qT)bl(FWZ|S0Vm*MR{`! zz>XP^ED_=CGV_}JFQFWC5_;6<##u{^<1HRWW@mZwrp{#yH&6mCBaaTn&ew6{Xn2K$ z={h?Y9PaJxDZYWviM7p?Q6Q^G8*p^L?I!?wN0Ob=#4}Z!C%ZhCrck)jT-lYE(%CsX zKq0`n+;v{OQb-Y;o&ia3#^ObJjUh_5<1INob<7>$g~!-g&O790UX+#FhOH?xZn4&N z1Pb#9?GT540aicu25lH4IgMu9_5WSTvCjw4rdfWIhzMS#R;VeJ><|VN2mD(*puFuv zknP-o0Yl8sxpc6v*Hl5wXB*Fn4uYV-w2x z>w@ZN1KT#U0E)3Z&l2Z`Za5iG6Lyj6+A4|;vgmjFI25m>h*nEakRfG-%5TW!0~@J! zQ{EyXAVj2jM@?pO0&>$=$fhS<&DyLCQR~Pae^LPD%b7OC)#%T(8NzlSvzd-w$>(hl z-@Hip3WxFz87t{N&2-VneR@dveosE%S?He ztLkR7olYS4;;@JN@^PjNsc8 zFn{)6CHrW2B+4Vp0`un;9*-~80N9_+oD^n(9LWZdf0Yc;ukR#>L4HA!#`sKGf+1m1YHxsn6*+5;I=$=FE;@qz z{l6n=&i&yD)F-0f3BYBsjx-Olxx`^<1mV$=M#fD1s?5HqYXBqtbPaJA5?Zc>M{gEY zXUHyKjO!?u``yuYkpj3Q?iE?dfK^A(5yci9LXToa9E4%^66+|%7Cbi12gQ%EQ{@o6 zzhD~fcy39vf0AMf1k>pW7Bjr|IQZ2QQ4^x6nl1r!Bq|@kTodx@ewdpsrNF+l|GvyS zs@n%WXK2`7Puu|WPW3BLT7=-)v-FC1MNXS&SoR%TVzkqF0ukRFzd=NqGL0@s#apDM z(533~@RG%CXo~K%th>C|{>*blbi;na?kIl4Z?(IUx1faB>HML<_2*!ijU391x7yeO z^1-EUpwfqR;x|c^KhD_@GkeYSVU#yfguSMe`_SL3E@#ivd&N@CAll4}EUVN(?ZAbL zX~Lz|Swh9N3#&*sO)HQ4h-C^`(Ag4exsSVu=$p8~&>c`B(iWs^BxS`prGcJO`1mo! zf8r(a-w05@+qgpF1__Q1B3cGe0?)RF5Lev>D92 zwyLfm5%0*6nrhvqEV>Pr7M${Ccl5FgLinI$ ze8fUOm9C_z!fvQy_F11*{TXCLd8Q1FrmLqg|5cGhCWv7ja8s+Ofcl~6%;=ZYBbnW6 zsC2>9>~>^?0J<2#b>%yN{|*HZvrtxDFM?Cl|K>b~CXqLM|v zLlWMGq9uTzScBjNO7U+zW{_RE#vDs2wzeF@!*F@)(&#*|txexK+xa`TcJfZhDARFZ zc5s||N@9RK-s^C-tK;=XF<(B`ns)?h+bqx9Dx5zQ(qSY{gTgV1wEl`-AS=<`?*)!M zYyb25D^`@tbXu%GPW2hmz4P|0GOJnYI@Uit3z=UFj|QB5pB z%0VyzWkL;kMNhliMC6VwvHsK(mS-Mh4*HGn^Jpx=Yh@fVro1IXu$K$FcFFGrg%kLF zh4MD^?2nb^V~SA66pvod&gyJ+(K{l6>8QWR>(hvIusTN{5; zfP~MO%G%kIf09_GPG#jQDGA*yTn8VTG)1eZwe|qvs}>3IS9g-wM1*WlPDZq~*W{gE z|NHNI1_(|0H5ajnWXI(wFr8OXdZcC(_^dE4{Jo>599Bai<$u5?)6w+Sw8f3bqQm>%6pb5%%5IYWObT>Yh9g* zmJx8xNjS`_<(D8!2W^Y-hl-qkK0nJzq`h;HZBLi3Th=bycI~ou*|u%lwr$(CZQHhO zYuBys_w_k_I&Mdt+j0L`k#l9{7&&G}tXOkCnfVSd9TNz`SRi~V#=RDJ&N7m8tX`~O z-){~3X@{TngLdzqtaabsoFWj<)EvVHao8GnoM$D6m+v_>UFiX0?qE#=+kjq#T1r*56oy66d%7TEEkZiy=l#E;>0gw z)!L*M@FMVn7Xd$q+)iR8I>TEzoqJ>7N}~? z#5bU3iz%$|#GB2|<-w0qi_a?=V$7fhz6Q#9iYc}}PN6c2p?kHl1%g;5S3Rs2fN+#C zYN*QPL0^ugir})UW9-D4V@arnhRezWDxD%1HnxY);x?z>Qhl?N7EJ3`?APNvTzCJJ z_CQ?gzq^K`E+lWgb(6R_j|6x_Tuban?_2_VhZIO zmminU(+jUi&(yT=x56>cL`y8lb?;8*;H)C%f>kNcG3Y?aP=@1=$S-Ui^(WHfvT$!j zt5f5l@e<-i%033fuBzky#rwdS8$yBp83glZn zk3aB2Br-C8@lrf^FAreTA6~W@h}%!js~&OCg8Q>B!e8FCQY$lT#-_}Da2TW;0_sW* zc3qumD)l(ohoPpfEfSBK_L;>Z_Mhb^CD9j84sm2uP@{^rdoRrfJfdD=Jku9S!x^~vT@g*~Oa`h>=I zuXXOTH+;%$9B}?RekyNISMzX8j>JYrR4uftrR4M8l(q2(|~96*v#@hpI{zTZ>#B*-TSwl(Acgy*8CdXo|zD3#y*wX~|1*MJX(eZa9g;S6kTH&Ko1R=xwZN;lqidoeG8M!nd zx_~-&xXPnhO+CgVxlLWRXrnj{Gyf9ycDicUxXx*=Y(Qs=e!dD`WfHFldFLrMzRI_C zb!k!~s0y{h4)ZtVnY5|9SmM&^QxQeyU@z7=LvwHn`m`6yQvYKFCH6ZxXagGp{J8fJ z0{NyXbeA}FP>fFMrhW7ae?`9%GTCnpjYUM?`e$u=l-qfv;=R@i_rZ#ZKfY1q&g|r3 z1V^HQ5rt1b=}*amLa+}9ZtH#$6!MLPv@?P;sohbQ5P!VivAjVRSf$K`99F*0jA4R8 z*F!mU8Q0cA-F)!dDmIMCuG_@tCGwH2jryPi;^emwZN{G0M6Vwi4#P6SZc2vdl<>#L-8m7`;w-cvt!Gax!4Y z1mmM>SDy$2yq%L7$}tV)QYy_Rp?AYEzVFa^g-jAY=}G*V!*CWSZOoJ%GJ6o#clk*+`J=2r48Tw%@~8E)yIQx2Yq zndt^;oR9$D6@5qbwq}Q@K4A0tc1{%Y#D^5F8Ldl)v#F=CJ@mwG(Se>(=!~{=V;{A<1fafiPKvQ#n?~$J8hSNia z1CDLww)-l1;gV-%{eu)YF+=P9Yz?kPstVNofpn z(6#P96MGnV#@Zfr?FlbbIi z&d&+h-JAuCGr1e)TVC*cUp+lmrltr_3mJQZ;h`Pj7{5Bjq)Iv&V{M~SBLEaj(gt`5 zNWK1~&aU^jrs1o`u^0;=v)rZbvAA^MLm=zk$Wnk<3Qj?`Xqg*z(waI~A!9k>F+SYT zK+!vVT<3kK^WurwTcn%rUsj9Qw~H=ryZxo4kTZouZ}R*zkP0$8?LIj=)LfP4wvY>{L2`94LWwC5Pj{5s9KDk(8py18NRC} zK3d9deWbV*aRb@C-*TjQ)@Jf0x=#Zcqo$eSF`3q}e>L&9%ip^8ZY_E%xF2i%$|>3e z{@wFb>{Mib*Ayqo@QrQKp`_J9+YeP_bEx+w>hQQMNIPmMVlfkQ4P;M~^9xmE0NW-K zoCtr~8$Ol*A%a*NHkJS|CT!3cwXq2K_30f0pg<`=2JX%d77AaSn57sozMd|^GQ5Vz zn%Q+V{0$3v+c>)LkwV`5S+!JTck?aOAa6#_dKQY{U8RFnWPu~wlQaa(o3);)SPH|} zHlSa3XCuXQ_n$`crs8Lc)Cu|!{o5^KcW-jS+$xQkU+njsK+j5$8oGUq;N5@7G;~z~ z0K#)@%WYZEGF{i37!{$^ON~WnO3Q(u+N&6S1CaFHW5|4qoWD8yQ?e6v=|j~~c(~zT zkSTmP18i|45&F8x4V*S=8_k1p#$w}&$VMj^opujc-RVciufeu~T27rO;qq-`zRW9s zNr$rQ(XS61(PnV{2C)WE#HK2PTEoc*xMo7~tivlpiwk`4vj0>eA&bc5-Uxj%7v>t{ z;W}(VAAeU!a>@Kj1+_}Y378iUO0kC}03Yfm(3>P))__M=>Gj;juXJwtBORq{Cdf?|xp z&B1!Nes5)iSM0^z!Gkl4ouJ&Fu3rR3t!Tsw`@FCzqY_!i!!!}YufYeO-10*O2=FMN z#s89p9jree-D{KNY7&t;TV8L8r9xYQ_+(Vuf^DnaPG&7{Q|9sP^@UOyb_tVbRhx1Q z%k}4#S^AP`LJ|82A+~lB8g#Co2QM%vNB@#u7OgXy`pR>)K( zn&R*|ju+y%q4CN}>6L%R?)Sd3c7!F)`?*65nj(xLZV`V;LDCn~tG18$p%=3jRGCfj z->*humvV5}GqqomUmE;I!4DkxP>uKF2&Qs1^)jh89e)ub0?=*0qNx~gdE~94GDx;! z-A|mS7!blN1np{L0NJ9~b_Oyof~DDqY>*E>ZJL;%HxSN6r?ZwzL_>0BKgVRRtaSTI zDEFneqAa8FpTxjYXnTuBF2T>>HVyr~WYxGg^1MrJkPfYj_58yLnP*MVo*!AoP=2lO zpozI&l7JL`c`p|}fD#5-gvT@LxlhBM10>2*%sEdh~vB9Aca>PZyuv)aYJ zrpqc2I9oL2KMAn~DtShR428Z!Lh;k3hOL7Q1kH8zx9L%$lM;*P@Ak`^s{Ck2np?;0 zC%t-BfkSYaMvc>w+g21}?aXDhBJP=Q%O#{;_Fuk36|D=fNVf$>y#!s^k((VeJ0wr= zb{fOVhSO`Sq+YAVRUaXud9lqicj+3J_Ly%^(0f4{TQj5lg|J#Ngli)W2BEk5p@gF2 z2?puAXux0`<)kX2=@@FkxlY_A4U?(N1H)O2-)<^^py_JLZ^;O}P>SpJboc3aREo=g zKM)qf(pJ;w#Fzh}B>UITK1?J2`7?ga# zwbo}TY$+`$c80tLkpsdaVmMUbj-$x8K6U7%V7!!6uWiDu@=j&Mc z68J!gkyK@}G?r;KKX>{2DmiD!tlYoEun>vVKUVkv6+$GHnv%M4WQ%f(F~~UzAf=yN zPz!;8o`>kYn^z>FSS^~0mva?z1jpm`5Tlp)oF5D(*ElB|b6u4~)9>hob-)Qq&UfEs z2pVyBi`DLambsmqEb$hdR@Hlqi-GDOk{5i>DyzfnzF!x#0A~U4n6>+Ond+*U7o2m@i3on<%}u*;W43KOJEvad zx~D$@dRt0LNtl=2J?&`$;Wv7x=3xD+GIo&m`i9NN5^X7SPqpUo&i(UR9CyY{q)9w@EzR7+*jMTD8BGcsKX6T6HiTCdMKJnG> z3@hF8n05?#>$jgF^N^cBgK2tvFA+H~xVrtMJi-9yRW;xKybBVz^rkLkh1gbsel5>N z$@er44@tcZiCVZNDdKZvE_=Mg%GqvC{MW`wF&+?q#X$!MKmXG$(hkQZ-UwVlbDM*m zvCiw);hek~LGfACLz~TKk=$1aH;zZuIFw zq*t1w!oh34){2oryYDxf?~(&auTc_qvu<=kY}I>qi<Sj|hg%TZPf=SMs z&`to+gZ7@D`3nnoPgL#ZWvW37s^SFX-4wBOFye{{3Lz!sli{5oV5xVJjO*KrJJaF9+PgmvZ{k*fjLD=f@nP}M&GXt{fdDTtD=90DjMX}c7W&KXD>bxUC zNO*4e^4R<#h^x8noC9I~(exon=6S^}SHNS_5kvobrs)IUrmqV*7)MG2x%nd%kgMh6 z1Z5-rs(VJvNK>P_eDw4zg=wJ~1U@hAnR)8=tQ~%s$fD^c4$V#Xl9F_D5$G0{K)&&j zJ2&HZ^EOqf2z`IAOz{wKWMMb!%rktqU5-Lt1FqKw$kkG?!RX_%2tT^23THj!PgV~4 zkEW38n6b%*km%J^f_(YhA#4j?L66KI8FTDASEjbIBl+)!sJ@S}4NYX?yY-lS&5Ak| zkgperDUwOzpu}ud4nB-C0y(Emo}2*EY+H1c#{v`l8o{$SN_jPYHKm8%x70Zxm~lax zIXKGpKSS`9FXlHl_8YQOFFPUfAf7#adE1w7pfQDPIA2i3G7rlz>op1#!Md9#1B4>CW#$uQ@&V##4x$FUYbfJyZfuWPXdS zruU^RJEGwqS4A~;2?`b1!|?oR8$sf38X4S8Y^R7YF(-~t~;})6o#6iAA){<2kiv5lb^a)%0bWmEZnR%!16DtY-X{XrBiC@v8 zPW#!{X!!kp!NxMx+@q`!eu`=TFX0VqwGW(;cbhI)OUmfIr@bfs(TPeReu&F3v zc9#Xp6dbxX1{#ut++4Uzjo*|49RImUhXXyQTwi1IN;j&bFE4_n4Zcfop-mtkT}j3( z4TBKa-uwFmUSt=BjzkvWOXv?#9gr9u&lSq$vq*h;#MC{A@-_oTi8s)B1#%y67qC-s z*i>&8@S(q=GxqS|QUZFWbw;L(irgQS&>ZqN$ig)=Gmfu7wZ>XGp=_q4e3>2K`vaUj zA2zGcL(*PXF{n<#Mzz!h1l6V`h8&tejC;V~!<<&}c;SZfi8sk+4&~PFcy-eWoQ{y- z^6SL{u&iW});v2DkRd_pi^j8HV``u3)d3zQUD2^`bnbyZz68)n#(`vZX-r6M+fsUN zN#|5|ZQ4&%|tpor{LCeN2Ca{YU zO1aAv-15E^x07yJn(2M=)GZ(p8SR-$r=UIw!Zb#f)D13pTfDpE-5T*Og+wTpxtBfE zC^4!xjoR8>HuNxkQb~Kg?h_cvY3gHXI*o%Ef&p$0>Vkvs8`G?fhH;XSF`^rfWV5CN z{JQu1I-yL0%$S(W8BJwX=cXEPD`QQWf+rRoLSR5DC`R9&Hpr@tJW{8E?;FRA9W3*Yru{uYFwx)2KeQBI0RHBsjrB;n&P-{jB^vbdAT*{hBjzfk(gE!>G8#{4SZ zOZq@wOGs8ZQ{RO!LZORL&l3h^_ws(%I`E+~)UO)<$uBTah$N8}T$cl6hlGxiFIN9; zpfayCpZI&2v&TG>VdM)6T^uZm1%QaXo6Ea5fh$!i7_^7NJ8Cg$V30%qQT8US6}B*R z9)J>n>v#>a^k!3X5<)YQ)JXqqNrZ2lznkDA?^Dqyyj8TK9bvNHYQc@oIyP`iGvh1C zP>dw0{yBw%x_(Pw=fa) zq1}AfjkJ4QrYYEXCxV2f>sv7;eJ6}d`a$)=CmgYevpRdA#kr^qMQ@DSPVKx&>#CzHhkJCfH&Q%{}SgmOW7CHLB0_wJDM>a$#IE1=)j zY#qo??j(W$T4}sn1X@HK_7_S;G+h5tv46|L8P)AOq6kinXO)|A&hBvM9nMsQE{lx))iWSHjlI*Fj zy2dcHdDJN3h@#4TzG11=}BNddD$lP?)L|n_tJc|J`BDy_Dcb@5k zay1pPNbC&zDpEgEn}Ihz{1b)#cScdXy+ETM5rctld8?IgCEIl@Nagqn{{m8cRNV0E z?%BYs_JZ|VetwXUdG3R>M2Ju$m??I*|D=*!6}xXuqMQX~e90N8Y^R7rA0CaCn<5ql z&xLmGJ7u?DJOT1M7-L3~LNirB#W_0Gkhknl-#lNm(cw@ zB3=UjBRzJ91P9Lhjs#+QChQz{OhDvxE(>f!iw5;Usp%Ii<#eSg!)j4cE5v$}=APBL z-SjL9RPRWmY?t+;#=H&41S|!&>PV#{SlM{qC{_HvT{=~&a|?hYD0=ug6BvcP)((jI zvNbxe?4VT_jJ%TiObvB=YVvziSi;J}{Y5w>bCuZ;!_dIXs_m)%+$v*4i!Z>HBU7;Q z*8>}(90KPD#mTN}p|{S-Frp)_oi)g3!UG%2J;0mZbRB{}nLW#Mo!o28-+CFfsUxc# zRC@aDUy6V0G8GKYXpG%rqGActnAS#wdu5E{pX%a@16Np1U}nmqDs7`qii5g zgqt=jWQw%rFAi0K^1NiCMTOH(4o5@oAH5uZZxzwa%*D~lr25!729i%?`>Sdbc@DS$ zGGJsswd>0O;^7eBYB1nE&&7!;OcQIIcf4;F9Gq|_`SHogI`23*E-I;~e4K_J&gspI zj4)({HN-^g6J1<5IUa7M|DIDV(-&t$3W#Z{=SB*;teU$)$(?!NVw=yQ{_UQFeP)+q z;Awv-u-r~IG6VM@9t8V&B=>$J+GxX+;-EvB_Lw1P)|flz&+<41Hc!%5XXJvE@`<=I z!cxm`QkXD=lw>ikdF>Jn+>tTkVFN@gqIj?E*S9|<7Rg9aR*BFP3w!~NZSeL;P=m%P zSBr4BJa|uGr{I~+tCP`p!6dayBE0P2$0*?B6IL_tHk2gt7b;ODh1$+BO4f};beT`~ zwym(Z{p z)N-89e*pS7rH)r7%wkAOYuX7#hoizUoyjJIq4j=PFT1q4B1js5Z=l0b>#owpEE82QsYHlMd@g7nE^w zXN!3|)#3F_O&NS?X#x}mSNl4j=68XpXHwcMN%hgt-P#B~!Xi!)ZpV|_`{F>m9mO+V z`I!@9jV6=3XKM*lYk3P7D@l*W-kd~isEdcl5not7LY5~jj~=d~azN~R@5!WG3otLF zvZ>u(fF%Z0--waA4b$R1V!StfMvJ~(@!H0vFeZSB#HMBSd47k8x3Wn;sb?@< z402n|nQea2(nn1p9)>?PmrZ9GXY^V}aFB8oy27^SbR9g69^Jqye5`jBA7S>0T8Hu? zOB}I|byaW`<9t)J)i`87DA@CZysY?$UITc46yr0S+bOSSiw;HFF@%uG7rm}J3?P-o zhg)=U#!(KDt@v@pQI@M-hegkG796FNiF9UkUO0fxMY2Ux$=^LQXjh9WfoNZ}5}Gl7 zwNTwR#!%ghUxp*wDPoSGh)wF8&K!gb@@Fkvg&$H2Uyqz zEHzniH_n}lajO^<(S^>Qagq?FgVnV4NuHmvltN4kY`LL8R8uPm!l2#vu3B-Rj@#a% zPh;gPaAn#a%Xb3v6#{p3Zv;vmB_|gln@jmMc=7qs8~Ox{TiP%V%Gkon=y)w%qdU1}pAO(Rp76J8F$IZ^cq#7Q?4+#kO>9 z#fsQ(#;WN5jCy<)S?iB?E(h6m5sWN^eBEs;5WZzubP!y~b;Pl;uJ%OLV>Y1AUw0K$ zsHMQ6Jt~uA3?ckG;UIXCU;QXE4J2Fa?3Dn}z0lTo4X$k5tpbOq5Gr=b?lX4SFDZpc z9;vPRAXG8wjy;+vo@MB+nN0p6`Uo#ube*W=AguH1Dy$PR16!Uqd~X$nLMY>80;LR7 zZm&SA{5VC)(2@gF>F=Md<|U4?(HE!_-4Lqy=!!k71}b@Gsf{~9a{w#+MJ7-NlCNHGt*MDY1?+hXJyPLalmWs;#p^)3 zi=2KE+z^FECe`Kc>AtQxW*QF+9VOe#Qfwa8rzFk;XX~dr%hM058kx{F09@Qx?> z&9W-4umEyd&dNoQJ9=Vr!X#IloN={joHWPw2`(8tX`b4&i1b7P;oIK5eoeU>0}FvZkmi zgfe#GApwug9#*h8wZ$W;ApSHJ;_}`g>bATte@W@LKY-^lidGhkZ5x0@6?;yR; zW$wemvTI#L)-z(N+bF>Qp3|J_tBr$R7MBJbsy1pq-9*}}ellnOwJl01FyJ_zAVW)Qf^{CjfEl=M|KJI2229XwKwwBx?gkRDHV=2*H61@W{MB?g0mp zKS%V`q;YWDBZWBFM0amuBxX&;9$hvp)_#OHs;K<{mTlr&FQ_34q$vliok*J=U0&6X z|GFv({W>u<_LGI@DgoB}~T3aY_8g_m3Ww3=H)YLPD z_rS<)VV2>s^@>XMNRTjzq1zEfK4_M@dw!YpQ|a-XBtdeH*PawpR_^=!CJz8Iz%C6= z6wJNdLAj(@(F;C1QVFwpe|baRwzyis(vInzN%gba5>TV3vAv8VbD?PXIgHcXwEtI3j$EzB?r&N1y?y za*??=;23sf%^pDM;V7rq)lZbV_Fu((1Z6LhNhz6q#H}{cin7(@7M)lA3m~$1XO3#M z*v%KeF@l|z{geSRnW&klvQIhnzD&mNwXieow+3!>1|28vK|=F14PUg(J>eqf@v~Sc zbym%uzij22hYkomTnXQ|QUY1(k-mAm>KfK#kXab&;o!sSlIj@S=^y!)5ard6dgJAy zozUgF@kgH-U&H?6_~Y^+Qd5oP(*gx&OpWQ&n5sv7n&I6wdRcB%d%;V`$>ily->Hg2(f;Xvh{dhzbD$hrhj!1hb;#+ zzi01~a5~)gZg__i&Wl-q@gc$dY}+>&BZrqV%7jm0xz3x7fy=@<<`wl|R#hMlhVIcV zojZ;$#^3A82dCW74Vhshy*T-P>-k2rN?ZJZf`Kx!Hgs^bH`23$`MI*uH;198XTzt% z|GDDiq!qBYvE{dM)u8*SVWDThXJup1qLtONH?nrbXP{&Ksgy9j%m+p_$(Q%Us^b!N$qn!02BF|MDwOtLSEH^yAgUh@1O=2k}qSzk?9| z833Q2jrpIxvi3Fx3Pz3^w6cQ2w2DTqj$G z{YUwaGp+v|?O*-=J({GEwTYuCK0P=0e@qM1e>+M4c>FIGjCB8LLQg|SN5}Bz$0;5D z|GH-VnZBR9GO+sZ{rxMl|Kg8{iIJIB*v!(=$Xx}K$> z;d0Ol<9$kGFyB+ZiD zJ%~(;59!|v?yCmk4gY)j*V~)(-P9G{Hd+MTZG^4eN3CkGw<#*=OMs=_$F&J9hX$(9 zo|ad8*XP~B(bd{~>gtE<8ypS#&Hasu-0|1jz)*<|Z5!$Rb!SCPii?TKcl*}_-gXJm z)}QE4VoeZ!CdpPWJ2#1lP&659`Gb=^{f^Lt(HQ%$N;KB`K}We)q4C80M2>}6P6YiA zW2fdw(DtIMkX5#wTF z{Y>)spjO8-!c7NTN^PdT*nU<RrHsiKz7I%^?7eFvV^ixV4>1@ zIeArA5@d-6j@@F`%$Ts$aBMYQuByVdjIciXTIWveq+;T^+DMXzpLW=yZT49n%ckt8 zr=F8G8cTpzBrNd0{oS`MMx!;piLQNm_Ou>uCxsfcRI(e+sPD7EOj6i} z;IS67l1|c>^vcX{E7?z3XRJ%2nJ*^pqs+uUaf_mIT{FaaayHk{j2bknMD?`9#C6SD zM4rCpDXO1iDOL&Toe#Ni336dZ-pLg#htykcd!fyoEn& zlWv9GmDJr%URU_Ed#RD;t@jm*3R^m5NI%S0Je7?^P)B4+P8#)}Fizq|!mE;k4*M~X zDG{Hk!*$f<*TwdeRIPERhFB%Xk^@U}ND?&Fj&OD2n(ZG%%3;c6&-^n9bMr;360={b z!fp1zYoxQJiics&RPn*bNFtJ?Y`*J!7Dx$4ye-@-hOYv<1g6-^P6SmIoe}ngS83^E9MH-&vz!lNrkvpBgKVVV99WBOy1v z?&|V0vZ|pOK0!7p%QGrE#?R*ouGK^Mn~rt{KZc!^zALvXpZzU|D1S129@nEFNQ>nw z7+IvI1)BabNSK*XUDk#Q6wP!@!_QE+L@Lx)D0AyOI-a%=roO=4TD#9LAx9}km^*?B zk!85`tr-6THU|(bJg?i?Xm2j%5ynl+XbyzkKPO8S1t0WRaUQlzjF{Zq#n3<&LEeXz zE|!V`n5h6U=PDLdidbZU^^pQQcnlw%nQy5)Y{$LBf~jiP9-?vMn}xxs6n#|f1#s@5 z6FLEqM_JNlNeCH{|8mG^Tmfg*yRHYrT?8q$w#bGFu39@q2P3+EFDML-GrrK zl~Epm3PENbhJjOot7_rUDf&fta2%-AeYYUHKJh_RMXGMd_Ncn?QSJ<%j841VKZps5 zkBUPm%f;2`Yj&CgjpiPg?XO1&q5rMOxWl6q`H>Rcy0}>@D6~d*ErNn4A3|7=?ks`0 z^pvy@V4`fAXG|)O_T;{z{AE0`_3RJIKsv*7-1Y)Y6?~+LD4KvWq=K%N z|JPSS6vz|t!tuW10_(%g%^{Dt**s~P(~iQg$GsOyb7vu(0e*r z)v&z6ejchhTFpRJls17vn}<{pt!+&_N&7oKAEN^JaAP5ej*Iu?+urtgCm{$JTbZC? z+o2{aeAW>dwfFY!QCRB;hGD~2eIkSA#_(oJ3uFCY0HOWDj35>6A)Q_S-Av*T$ys?^ z`b!TGe&zKDX=5w0lL9*wa|xa1Vbe)4j(86XdjaKJJt@RGuMewV8qYIGND_sbv;6dk zqLCZQ0XF-+9qnzeuV2h&z@D($G3Fe%X7I=^Bi-*{sB(u77N35^o-YkeE>YsnfQYkIns(EU#A|*duw^ z{zZOdnqxremZMNSUm^-ZqohiFX_skR!D1CN2R@$oWQ7mq^JtoOBByD)f~@t%u|mF} zJ;(x(YazS56svH@{+o4v= zz~1NfAJuDvb*xR^^9gsQ7L~|h6w5pT#=XZ`M?ib4AJtX>oLKk#PZ+cyC7_f^`$-R#d;yBT04t>^*};;8uqwkP0sy3c0?E=yeF;!X)o|L5 zHHFe|)!7%kEVp3NU`^c0(Cu?sY?rlw8a2NH91Kc1^Fbetii)<1xruxRSo48^tnArZ z)h(1rF`0|jP7}cUP9c5RBwYF6o_|Aj&2XAY&v#hlj3;ZXG93~u6voU@yYSEGIBn!I zKjc^M>|le(NscbVI>ghC+zB2}ePGcX&KlQY8Yj|FF(8!Nj)&lW4V%)N?Pch6Y(pU) z{gp|AMXtq+&}$>Auuj1X?b?vAUyOXfBwM{eoj`&g|AnZby1@+Y%zJxa{i}3K zF(y=9sROLw`j6(yUxcqrT_l7k%=&nId^UlbnMzy(`xV+Xo84O>Y{OCN(I0*w#{s0W z_#7c5qyW3hy}LV7ZizQ*P^-*uzQet8h+XBh`m;Vbm~uEs=MDn|ED&)hxHMHDXkp)1 zzj@zZ5(c=0K)(|V>98%f7>ppP!LolN?&y!=Y>N$kY&yIM@mBgOmPi<&jT;nD)Ia+3 z*v?2gMUv=bznTd#xoMNF_Gw_fX5n6equ*Z9KHt&L7<9L2UD`9kN*LZ7fIyB3(*P|_ z#}I&6NGe)rnLNDDBKHLE!9D^Jc+31epKI;?0O{@(#0rrPPN1TdWr(DRW$ewK@Yf8M zT3TB=rf-u}+lu4xav!;56jbofKEdp;6C7s8RHWgKbT7MkqFE)dBQ-Zdmu6v{gj*Wg zZiXEEWhwE4BuJZp+dYbM(y+m6Vw@Z{Q6PafU#6SSR{3k}3)Xc0vum2x9VFv``iX zMrK5++`P<*h&DpK4qq zyQr%;z40Zrhg&K2S6Cu;hk)H-RZ%}lfA1#FhNw1{mV*YjxlcRDBi0fO$b%!2 zOed)@473%Y0VlQFC6(iFYyBMAr72*$LJfe$Gf%!|=J@>SC5;WJw6$&&BZJ$s{My^K zwJX&lCfRwaR;`H7c()guNa2b3x_7LtDzxxDF+>cOiyWq8iRRF7H?H4tV&Sypa9ZSo z!MZ87XL~u852%B;B#~C4)wtKa`He}i{B1ggX7S*VxS4bUC7U$I)u&UD)oIYEO(eY| z1*Yl6x5G{gU=nv@;p`NmtuwKA$C;v_#2u9LzNUkE?PsWEMYKJ6wbe5>Pr86{nS3}K zhB06EpU}>TW0YDmc~HEG$u)Um@xr7JQ%zlzGU{A+OVX0Shycf+LVk~F3lEif?iID| z^=rQiO$OzV4VB>kZC8O7Z9EJgwMJL5^($bo;6PX<bF%>P}!%)4olJ4W$`O z2F|{uYY6c5Lgb{F45NWm;2-@H0(rQTQ&T}J^q1BX8^kNZ7Y8b$xx(c&E6~S*EM=a1 z(8@nU{Lr9jdAf>ck=bn>0{(PBX7D7};-D|-<3*!I zNVM#SqU|}pQ+fi`inGQvpVFU}Gx@$S7t$yQV3flpu&;B*3OWvI^YjLjnz;$yW{&k= zV^8S)P5Q2Z4Im~jw?HABnSX@N5t>iGts*ubyJ<9pAoVcc?OsVyM_lWE+p$NLIxt&< zvEpB6p0fo7+UB>I-fU_JW%Yj#gGX)f=+H6)fVUVg=oe&Wgrtwg1Am*?=VH%J0RuDu zmK_0>N3upmpq)`&kLDep<{$_%8rSk0>x+bz4;0;LU~l1e9UXvvM>S++dyD&HgK+ww_R8@2>kkXnPQ$iUdg zb)^I9kr17)E)V+g7C{pu?~HMx7#$J$ zc(s@0j!O##IteToK-7Z*VGXal8gjvER;!m58G*%NKK<@XW@_f}?gng}C7*4IdQTdD zn-zW-KmY{02Y>7ZeUV=nsMgki@yd8SQhGBTa3%sgc`T!_Ngx1Xdxn@J!jgYEF~u1? zG5wVuGe&3vMED{ucwWf@JA?S-p};)zK>!?Y{8_yZ;v+N|6MTWBN~6CgEG@4QypnGA zx2XoZWW$w>K15-<|4vA35YBkOz=bC&_)|QSlD3uZ2-Ii5u+aFD-Y2X)$=q8V<}8-^ zX%7FGaA^WoGTI5GCUbl!R_g ziek#*x&?cV4kc1ReU$p4Iu$liW9b)<47XL$p_AmA(Py0VWX#a+A|1CoM zSJS`4R+Z5=H!}F4X#X%NdD{O#YX6E-p7#F}Qu`On`nNAJD|&i-dd7bU+W!gN{(~B7 z&@=u+^?thig9Crc|A26e|3J9^gl_-z`yWl~KOX;!#s5F(_D^L0)gKch!~Ye!C8=w; zY_K4D@96Y-70iUe`@0-Zm1Qko6kZ6Mb(A>al|m%95>n8L4u^SvO~Vi${fYa~hXHTt z)1`Zu>ebHm@7-{Hd?N;@3=9x_B zyiF^%)Z*WbboQ!iE!Z~c?VK7~6P45lDhGUf)^A=jby=(SQRmU3%;he(EiH!_f`rQF z7d3n#>&u;A2MIDm=RYaE9STlGL~S1e<>wT zSz=vp%M(v2B4!~j#;?VS=i55N-9pJ&R{`VPb&ZdBfT9Lo>jA!xs`+lv!Qkz1-xApU z_O53{QPC2C&o$GoJ z5XPdXs?B8S_Qt3~`|)Fl1ef92%c>F~K}7g8#c724h^~(4`&M?$2~242M@f01?{^5w z>y5w-)7ou!Z`K*o$GXkA92hoaaz*#N6KW|m7ajK5&b(7<$zR0ZG=5cnXO)|7Dy5Q^ zf=0n?w(NhY!3mP3$vgArSDf0nTTF{G`s#54YzSx-n=hg}=GSyrT87y;+t22qJv<36 z{8Ohk$4C@JwLYC67%vK$1NKz!fh_}W3`V4Ez2F7_GqHBUke%)Vr+|O??~mfK6o08t zu#Y9es!g5kFr4vzz~!q#g8cl3NBRks~IVv=?n=jC7C}Ess%Sf(v9|YXt?=-O%{-w~pO|(MXTyotbq#x^5h@ zz(%@zUjbP3>WFnx2O41`wMKh%sP2cb?Az=fSa?6rcUZ?g4%qO~eQ;P7ex2Y^$?Z_L z)mA)!vv{j2^NijuIXiUf=b1dvL=MbpF^~;K2gqJ${6J+*J4D$7r;XU15rbNCh z;lIQUdtyFy&lYRBMR>>o7NqFhwvOiRjwwGqg427;9RDA}-ZH3;pk34r5(pApg1fu3 zaCdiig1b8ecXwFG3hwR>!56`UySqCa_ILKZci*a0b$)bB)pX6w+ciJBpX%rB*UU>u zKOdagDd7QCm$J7&Vzxf&Qr|9SdOmp0qr64q(6xa}D7KD*{XV^#dian)2!grygq(2o z_=#W{!~>mzAfl@sET{<|^A_%=^H4V`5EW%~_J?=d{C2U-;J zIeOdSh%@^r&3XBsI3Ne2Q$xO9_}!}2Z4-(C5|X_HSxzX9KkBsU_c+rZK+wymIGR8^ zsm9f4vd!Xrn0OIglo*YS)mR$DwB;`d&jApAcp_@LUi({dqnv=6V_mz?xQQ8U1Q5jU z)M=j$UGKID5jcfnE?GB|iCw0q`f$qvAHMcWVAy@AQ13D}Pe^t9LUXv6AuEo4YzDR2 zWuOuz<&n#G@?s)xocf>e>m30u*}O#rLi3%-oQMGAHz~J&tR&&_an7EMl45EE+?QjQ zET3E)ncf*mf^V5#CmKfuM$uz-Gwbp$4u^=#8W_2UA3sBH z1o0$|&siXxgR(|5XqUOZ7K@)a{TGiC0GODLU6eTFO0`?Xx6ST-ZK~4Cao1IVV$o$r5ZB?aTwVytS~L_zZ{uLg%_RQ)Xli4-%d*nUaq+sPtBY*rhV*b*bQ_)KSJe zs>xA89N#GH*XuK_(ZTd+?k3TaUA*w z_G(_s+7;}gctSl4+Mxv6xfI27ii4<-x}DkWMauoMe+oS09^v1#Ty?gfm5Jau6GC)uj}V`NxRLg@A)VH*(ZDwl6}CioUV6_FrU#JusGI>*OekU52H8y*7;T(c zFFU1U^70%|#Orv~++Rj}xyD!<$C5{|`MwMj9SN@N5=MV4t0M$1Yn%(`v+Qaoz&U~} zCZPh(gRrPxYLoQWdsNkGT zl1s7pbLx91m*DVC8>mOh*dDj#rPD@bfuS3N6tW1};R!9mAsByk?g)l5W&w5ejfLxC zCnZFHA>G3tm$GLmAGuc-&7t)+3q+hW@c7x|D7?+%K<4P9 zSpWB>+rZFQ8tgD+PGLCs#u}RSXjXL$0WNI@Na(>pL1QWe+WUa*_M2^Z8?#V%&rAXm z^MlZ|grKwh@*f4@=H&BXP; zOcV(RXFI0<)Y-j$dp0Kbm$s4;mTY2jK7wmq@9>feR+@DRK z>HpPSJ~f*EN!a>K;-0ROs{c`BSpE~8ih#iXR$%^{(wRj5A7_S@jhmU6jg6CA|35+f z7v%p>F~u{-_f0m5va7x+{H{k?O*d8z`aA=2@*hcff`rU(bq;b4Zoh5q@t}y#L%|hr z^>?#DyjE`f^Kpm8;oNHW<-F*RPQ1L2_m_{?hmTjovAmDPkBgp{sgEne7b(ET+0@6K z;j^Vj_s8p0#Y=$B$49`shhbMh%8O##u_R8w`}U7eHi_ z#&8g?_OyJI`5<|W$XCRg(ce+BAOFnPuxvBo(o_>~Fl*hyv3>U^gXpdM!?&7C=lO@< zT}=FfcB+P8wNKL`{H|PwUt{O;-VSiqAtqi;V@k*CWB;{P!{2{f3rHto0jl(dDH($;ivuC{4Txz_imD-hT}Eqhq}H^-M;#PWQDfF-1YP#_hPUe zb5v8P)nvtW*=g#?YnR{czC&d?onj?6Q}?v}$4?#C8s)wCyMz9J;Rc5lra%VcHr=2v z>-;AVi@$ZX2UDYc#w2x;^?f+1j|(gWd_<2by!m|CEqm`0=x=$T*mESwwO-vY5+sL#m6sp}f(w9qFKV-;gpJ>jpHIeNt5HBX_>0F2> zojNsokr@&_9X-9=c2a(%{``1<`0xkn_^jxl5~PdkD8{E9jcP*d97B?i-6mM1fmB0F(Ek6%+9$xS7 zPPox4Cf70A*JIs#8C`{e(W7gbni?`>&a>JTqFRi;mvN;zTyd@kIxi9e@0Sm7HX?vc zV3&H66YQ+}&f8-}p?Dj`2Dl&ZgOoKah=fKl6>V50W>W>LB~<{6(j&gan)m4>e<41a zjTVKaXOS-U-@Y}fYV2YAZgxE4(d;vxO^Z)px5wB+?OC1GF}u7o_BDD@#A4`KTy--H z{(v>rMkTU~B7>e44Q>y@Z> zGiW5x-^jy`uYt4VlU+rb^w0fUGG)QacED~R-yo;@Qnz5TE|0FyFRDAjklgU}iN-XA zS|#N^P2&vf4d>shK9=L#1R9t1X9ZrG2qz6WG49tlkl8ONJ%kN@{|2@G(8~4qtv+D? z#agg450vll>JwD-siSlmm>u|z;ZVs2mFhkX*wt|xs^T4Sc=Wv9oJ$xp$+5X&WD;rf zy{rBn1E4=osZbEv=VMw@8UMwX{20XUS5&o;DF7^cX|L|yb+*pJ!sg4<+Fm2@*u14e zX=~R)eAu_H*{DupsrK(#K2cDdcMzLuk61t|0VmHhb0C}*TtK0df0jxe|BDe&csSO zNzZqHuXeI)#X5`Bg}KvB=hxTzr?lV(E#hoL2H5CgSt%>Y8Pm1RwTK?o*Dtve!{pJ$ ziv}(#013eT40%g)<1w(p$(;>5x*07@1*ZYo=Z<1%%iebIIZZ63F0G(@*~Ws2sB$gY zZRimDm$ZBx`N%Mz?O+CL;}UDQ?yYM_7m^n;FqJ$}&&iwtMyG-|TCpSjN%~WiP zC(cTW5PTW^s*60B)mDo3>CCctVZp?g@y**LEJjUGY@O|dRyU7+ZI>@GmA#bGo-6+ zToqLqp0A(AoFv!lR+g=}GFZx0XmLdyg6d!3YN)`~!Cb?B8*tsAvQ_b z(f#Md4sdyC95i+_!=+@#K08gZO0@g~_!R9OcHjg&#DdBfZ0Qi|LnQD~v%$=^(%@@? z`evz=-aHlVIIYp)J61^b?cf4gC8>Q#b)pC>w<|yqIlW`YwmVJM&Hr7Nu)PBjMb($Azq0s z>Dr%8((XOiUZEpNF)THyc99DJg|-q-xWyKxEEa`;HxW#__Ph=^+p4%2H$q+_1zgif zS<|+gW;pigHfM*KeK6G1{~CPU9r3;UZXn+T){7aAz?tRCa<21_kYd*NbnOz8C!7}A zmKo)`VE|HABEB8qT{VWBcTHIb={G%CF-G6t;=M$kng+pyd{GyJSO_e~ax7~%39?+5 zt0tEHxu%H8;Mqc#b90Y(4$+S?5-O802zlrKb~)NPgsdsKKoDPwu)#EB?Gcs}74A8N zb0qL~5>RMurd37hbh5mDV6XTB$fRIE0vIY*?tCWpe9>WNiz4Iee0ib^S;Jd!bN?xS zdLGd2kgJyKta;)#|BKO8Ll;pj~^#$gn9&~g?Xh#K_xHnfDgYwlt&xn3XqV7F7|X-D^kl{}_gYOvOL zd+vJKvD!+9(dKxL&>>2-Onkwpa$6_Ty0$wM4(UVc)*~yTcEJvB1;=i8_m3fQAKPke z(wp~vcn}t=BD}YMYF+vKdN5L!bhl5`vse1QGsRoEX??lKPcUC|Outx*5o%iL^$GLx zn1Z@sIe(Is6rcBP!uC1j(V3VPV?$A}l7-Mc(U!|t%{m$~(xQo8MSm)&)K$CgM zgyhkBKmGg~42y3yjJZr}4y=6qy=iFsX$!yRQ4QlI5GuBW)0;zA`%WNgzD`dUVj|*Wn*>vA9F?zBlMHq#OfIuB8Xr;y-?-j&a zMcfnD#Ruiehgz}rJgL(Ccoe;4sr$qvI-WP#xN6zZbiJ-tjt5))m`dF$`m0~Ogk*9} zQV+6IqO=>OBK5jm^!kI|?>^qGlC6%~@u)F;R_O=bO8jXrSR33v-swz#mBrOwN!#iO zkKP7#kc+37JiCrz@DE0Ox;vGH%Kkwy$5yh)ysw`X)it4gt~{&^K!#F3_Y2p|lF?zW zqPUWnD69P>GcSX+ThGT-;;xAQ@^2ggZtH5 zrgL40FB!USRp>P-;ky?RG0>{y{mYd)_s)sgQqCifca>k_HTWDB$*`-R37^nfdarLw zyXC$2azje3p5|r*`TTtK+`0DoCJ|a0V&u&k6yTWq=FS2H`e^3B;!qh-$7Mr>M zT%6E^vFQ1Zgq2E2+-lt2K&XmaZ07X&DG`F2FzBv>FWMlrDv@8oulpgoF9B48_X%4UsBz5k5l1+mKH3C zyF%HFcVeHJ!J8%eBuiCoF8M3%MlM5?4hyP9wo-lkj`pOVnp zaNao61<%$mTG8gA;HKV?&8*y~iWt_j$pJ4XaX9b(In;f1N@H$zk z><4!o`b`@Ip>pbu!&nr4c@F8atxKm^0{M*;kT{Nzj-lW)DB;*q{5>4%V^lOAgEEQe zn89j~$wx(QeMRzA>_gP!4Z;x3-x|iqAc!!zjSrGMy(#KU4 zeHc4-YIv}qB(?ke0s%-sLp>zUTC)Y6b`7^M#gTR>Rv*~sUIR*UT24~8i(MZ7>0KwK z^ygQ<3*Yn$S((zw7XK=|qfsO|emUjyFA6T;2vc=Ok3 zlxx0;Ksl$q8oE6)HO%3SQdwc(%Tqcttq)MM$qctdJ~>-`(=ssOzRP0Z`7UaOwSS2s z%(q?Z8vWy0bNP4ZjkrZ0e1dY@4RAJme4OL>g`JTFA@Yn*IU#F}P~^2-%oRrI6gFgY zA#Cb^LCL&qQhkNik1xwc^9A#t)~#7bTP0Cz4Q+d+mOZ(4?Zv7i1fsNv$Qdw0d+%UQ ze94i+*T?biHnq`o(tB4mj3u0y8jrvX=_H_NrczM^9sfkhj{lpOfb>mt#7tGQ5j3%} z!tin)?=He-P#G}IttzWwls7!uOFq~EQt`+40*fqVt~sFvHCN5u(>r@6(m1Zw+1(Ox zylGKA(HW7XX;>Zvd6o1n6bhXx=0?b(ea1FV{hFOd3a{~RpVe<1+~4{u-IY2^6o(12 zCWg(I73ATcNN0*!>Z`7Kwrvp`SLBIPg*D{2Ywpoircv3A=t5NTP@LOJeP9HEf6B9R zCdLLKxo#67eGI|{xy~$%^|5-YNY2P2vq@Z3ngV1imJo64o~&fp6E^zZd07oPgAY3E zE-?>g?t=DFtDqb;AM|2y+Hjj$jgzF*Pq-~RH6;7y+N5@1dUIK#y^HnkEnCVkGxv+X zDa>OJQUDy_ob&*#$Gv|PcpWTi*BTVya4$AAr|b&t?`cE6a%r*GGs{J;tQy!?l+@bV zaJEEv9^*14MJ_VscyTXdzRK_OHC-$E>HiMm-x@ms*_ChcmT$MN^ls7al#g+tJyCy|h22(M z2%HKGj{J3M$G4@|=RQ=9d3TN)67Iihh6IXr_pWRTJ;KtTzIbjhJ2gFIUP zX^f8YO@tX6W8$ze+{me?0O%x}u)vf-G3M3AwV{w>XE-}zIVy+U86j+qe84c5Wu-?y zC)SJ_ta~$Phx0!0)|h6@u)bxehvL`yxbnOOj~(9=jJDpl(R=%-ua6)rcbVJq?!5IV z@YTJz&7Y`#V0{#~GI!-63U&0*GX)2K?>y1}$m=S~ft*ClnOH7&{`J8XgWZ^6=(3=r zmbm&woqT4Geq4>KC-S>Kb~5xqf~@%fx4cB$_R`cw=B1r?E61#xwv$-U_1Ukw1xOtE zVSJa~T?ISb{Fs#z{#}jzA>}Dtn^3~XP}`qzgarZVrqP(HWAZANwk-zW;is-J(YhK>D>_@tNJgp#)Ekj zC;hek)RF^EM4_l3X|($o@MK^s$HgkGF4}7}dYT!aq z^OpHmJ|8}s<(r2mQ^>nx)HU|a(lzGeFJL}~RpEyx%cE{TZIK9EIj4y2g$Kc8PC=Mq z#detINfwU^3j`cg1D;8dbj-Ww#GlL}gSGTic1Xv69B*3@xm~Rd#8t#*U}KjrN2KZM z4+i=0jTOGON%AfiYG`8^yPVZanc`&0=M>Nmtwk5}ytEwGpE2u6 z6OBmM;-x@&uB9>%jL|q-5PcNipvfh@KVhOL-N&e_o2B zMWXsmo1Ohmug!q;0= zNV{l?H`A3&aGymL5An)^rb!`WDm_^B+h|r2QKi(9;1V2$L|3x!W!*uRm=KsQVQr3s zPoSPs>9+2IqJ9UCGt2pFd!} z;hd$bLG4+vkwj)mLo;AM1#)8qw<0#gZLZR|f8x>v7gWvsl2{&PHSyz*6;;$y!hB z=`qY8xPlKUCHzVK6qGGUHK3veq44kWU%%s%ZU#EFPn#GWgQQ>jEBfq(5#cok@Fs5s z%3b;VZ})Bcs0tu`MGE=dcnKhMM;PxA%2F*D%At1Fa8=MNMAR08g3z7I?S9hnjYH6!J`Q<|06cA?^g+~9T>MKYe;OgYk5PQg!ec|7fl(2x7zIXyCP~a^2M6DXX<~ApA3GXcl*6X7OaN02 z?C~&nEt%|$jGvKYRhGTmPF!VqhR|l5&RzvyD@aNd`}z;TQQw2rPMmn!s;{GDGwUMu z>4?HlZAe7k{@wjlq;t!5-@dpkQ9vo^{!BpU%W%O4Q&r~(-Sgc;If5}LjW-5+uaJHO=UYv=D^{SuAt#r zm(S~PFX(n1ig)ICH6GR-BX{4+Nb;uK+elLR=#6i?q5T_V#EZLSW!@+h+Es%ZjIc#QC0$6u5+$@d2sD&|u zQV`}VZ20aDS_G6EhMMOh_OaIKWu34jpjJc?f(J`F;3$;GI@V^rbf-aEf*|i+f}qEt zq=w}&^sEpQMpKg+m*-W*pcAAOf~%IP_Y*}?QE25D(oA$lAIbtalA z9?~^lm+Jo>9&MaCl~<9|*;w8rQ?B76#j|zAcoYtiFTbte{`K4ZK?Ti*25^G_2IbbD zxY6VMIgp#kp1eH^r{A*sP-z8a$6;WHOgCz3$?Vg-+F^X~%ndQ#H9^Y5xT$T*QUWvkLJ0Yi@p&FNW29W#hX_)6(ADjPjqo3?4rJW=M}!H0*y$kYDxKuGClP zgnYD8yB8j>%$hLUBlYAxANKFzFN}Y%;+fo4Q4|N z+kFWMeY94zC|bXFRanIOKKQW6vshcR0!R|SRu@287W$Eo(*A7CIYjyR^+D|^+bZ=d z++2Jh(Q@Ni(}utn{9X}Mmok06cFaA&djCWw<_Ovf5hH%fy`5bTbTRpn79T_!560rL z+p!as;mnVASKa(YZP$^GxXlzchz_qR!^@y{C7yq4R*LBzL+nJ+RggConF8GTmIaxRs9plxVOaiCg zMVZ#4WXlSFJWN=&yZl=^ur~PbG-MCynCm1_D+>W?&9=+Rb2QwhGRMlz!@2x0X>CN= z_P;iQ#9eL8@v3}A%GkDgGzXXLOw=V&pW;jLL_NmE2%}{ zP$Vy!O`NIIKsFWOoN=b`3(|VTvG)x8X|;wwR1J%w?Iuv%g^{GJJ$eW7igC+8#Y$U{YGP{Z1lS&&y2Zp2 z3X4@K)v<_&RrxQ@fz9vNZ?6(5Q|%DMDUqUZS#ULqhyahB9#FlExV+GDc-o3R3L~OJ zGSb9i;rkb9;#PNhX>Hy!(+(c~Nr;o@Lg)k8<{f?nhslGMs_Sz&n)iMJGjA_4;}VN) zc-Fb#Hco=ey0OEbci(l(Dm$C&ki0O)VfmM)zT%^A_>CiCZ@2jUW&o_gZ+m-}Ll@l1 zlQ)n5BTf`~j&S@(vcdGn5ka%vOy*;*Rh76!$iPiYDue~3t-0B3B|vT8hE2xv{;oy9 zfFsc7jDq-U80wL5uaee&w0^)F{Ssh5MR>NqG`NP!c&F#rXG3X>A0cqZGG2MW1lnlF zj}TA5ZUmeR8o#k((6(tvaC%ppt>T+?uyoO7r#$_X+a&qm9}0ivhCvAX4G0_ zZG7-$Aex}&<{l;tXP^G<%RuMsI27VdHVrc`)WGen5N?OW(%C&qFSA{c6s*@{H+Qic zX%&=b2OHdQ#EGHGIG#eZEM+=iZZaVnvh*S-tx9N`Wj*D3yql z2$a`(f%1kwg!(^k>o|5Y)?C!((jRk8!yW=>cQCIz{({P9+jB8;Tt8H}spSKpcFiC2 zHHN0-Hfj&A#8L_ztExR9TY<=X)M3vYP*mj0xTuABjy-NfrY4?*3u2Td2uWk#OKQkbDKA#aW@kMb@eP{eNDtztd}$Qs zYCtcgD3!6Y%}Au) z2;(eV%S+K=^N>yAPB$@y{$=SM;%8r4fyX7BDta~zokC=YCW&S|9Z=jOKDz z)KJUuC&3F6qu4~hK2v{33?K{NDnj^foUp)Lks$UhKYX}cT0&aW&gv!%yTkHumFh~l zjY}fCiJ;wn3O)bt*1uvy?zoo|^fb=a;3)m4j(Qrm73B_Q{7@f7!`eU9DVK$WDVmz# zZ|dD*_3?|CyV>}{Ec1)<>wwH7JB`y3SVOrCetF$lFy`WH7=*%9ti5B#?XlzL@@$<# z1Vq0i=_4m@=Nk`fR|u%f5jE+vZl4)m5^4`k z#GaJItt-wpJ&qe1JhBV%ORT zo)BhCyzsorctO@q7}=d5W))zD%+H1y4LL(6wOI8TQ5PDQcK+@xW9b!cU&DX3_Oq<` z`Yo3VLx<-!J94v2cC?r+`)ovcHT<~BxSqcbV79vr?Z3h&j;9xQ>Bo6{)RwcfTVEmy zto&>3uCKXN0JAG7g(zG`5J|ZUR2HdOj9GQ1ClOdZxDaJr@Xj9j=L+XTCHN0>sm=ia zI@}q<0jB851e3Y%HY!$6%$g!EydiuQoagOMl*3(06pw+-->ODaVwdtnoY3qG5>A+Q zpQD)NQyiqtF^u4t;leM$i7r*%6`aCF9-8sp2pv&Nr*J0xtT>$S(-DYzsMU7pe?(Ha zB(2OiEKqIbzGpL@^fqNh+Ht49aS;1TiWnd$e8~lxodKvJO~P4D1;Iv9%RCRZV&*W_ zG!+K(;#-AcIpGDVk@F|6#GtWf6(`&baWK16cevb9iYtVW;Fok+g*~g~ZZUt5K|QShD|(;}>$|e>k6fp_|=cE-z7Y zlEa2g{YiOb`NeE!yyLf8pl8Gw90Rw32Wd98;wdMPPf<@s+R>BL-Iq_$4T{HP7z$f8 zBq#OP5vQhH$>>tWBr0!52?Cs^o+e8jN2#iGi@{)Ij`!0eor+|gdG}4qHM$jkW3ZA| zIQlq)E|n#Q!$xSIAK^nDu)aGvnyeUaB}QB_}^Bv{&xaY(`cR zZ~}Fdt|~6lwyL|i;x%}zg9D%HH`_3cM1ZhH@W1eZ=;~cjye3499rU>>$7ER~bY;HVE^Ipgxb#n_k^Z?e&YViC^c4+&(+VHAc>l-#s* z$SpgPQNP3i{_yOrvG*4P;BQP4?MS zl_VwOQ=J>A+0yQ+Jtz5(yo4<6414Cg@cig}Qby+81A_XQ}%EDbg^@z7Ipy#z`A zoF;qTl?Ou8hw^YD+(Spw03vViX760vcs6avmDn?Hi+EO9W?qL!09+O0^v zZs(6{m>FI$Y}190IKu(K6*Mi#KBKMi+KHNE$APvr9?> zQVY6Lley$5%;-4hO3n$K-IMep{q<3MdhlnzDyjppL6s-y9~&R?ih<6ca#Kq?)b9K^ zP|F^H$ZNwe)7#rS-51!76RD_!Ofqa>-qWCgW``POz)yv09DGcQlLLWlAb}dUk zx$0PzYm?R36(!0iVtKv=Bov{xYo;^%JG)A1>B={LoqBoN-HKG-33_+}5F9ktS|$bi z-=BWUcbeRS9VbdpUi*JDy|JH1`Yg++5nvSe1$G znE)ie&Eb%xwWmhG4>C78kC7Yb;Zf1V9h$39P&5joSDmA6u~@JyCaERW_!j)S7|JA8 zmi}IT$OcRa{FfZ}c3+5Z)Pi;hhyDX2@xpo>M#Z(6 z>pw3!9X`3bQf!t?5=f@pK2zVR7$pt7_t|7D^?^*zwSd zmHjq%fA)59+xhR?tJVI7H*>P#xwO00)ARt^ZyrO3w;6Q9j~7$Et&ZF#@Kl(@u#K3g zdZ53%Bfqp@O+8ZMBANPVM)w55k}vK+E%zAPVbF*D_jj@a3enK)i*0jI7%%x z?jW`1rp`iHn&gi?MTrUyMM-*+Dvd4Mu(GpMT;>UASFK3Nnu($$ZG2ge8t}MIW5lZV zgYQhnhYsMmpnun=f0a{VPRLLK@7QgqgY@((Ql&8sWLtJ)37Gb6%$W^J8>ra(JPPYC z&Fxl1jjvt-X~C|g;{y~Dv+v^&8Sj>@Wg-iZIPKm)B}azh_q~djamK%VR1SGI7g(ohkSL?E97^P|En3vUB5zCXWmfQp|5cpT?Z>{Cmmqvfpec zlH=0?U{KLY5t>i$lh3J-CEzi+IP){KlwYPh3(i`t3m2e0-x9?}{9+Qh9ZLXTQD7)& zZ-mK>PbbbFo1N+`ze%6SD%4`C^!%x|aqNW-#O3_9&Xe(ZyD&+1Nh$&^1+ zgk~3JJ>a8G4nd#Itn24LT?sjRJ-13WQ<|6lCzA1xed4YFdJHf z>l;B#yRkp%iRt>MrnpTMUW}ZcWtGx000%iqG5#Iu$+9*BvWf-Wpq69*pPi}9NgTm- zf&^n+)~=Y}BY?k6V9I@Ohk;3j?KfkKZnw+ZC~6xE$X?*P=X(DUacaQ@WOG!7_&ZVQ zJDRf2Dxz{HRM7Bq!R_(`nMY%@yoN4opX#4&Q$FQbZHJR^>yW0FyI@v%)9jF|!X^mX z7@}!!TcVPIV&wI17r-w9@!?%i2MH>xdx>`Zndnn@X#Kx?lFytVm)o(b%G19-X#=#h%@J!j8_#6go%01f-_b*kp#` zK5`pR7zxfzIA4L1+`#KqW6RUdQQebhPXggh_}CBGjn#c*%$o7|CsE$HxEzY`E)61p z?2YdP8T|nL182Y{QraJ193l6!1iLSFQ=4@GzJk{G>nbs$vUzI+Oh9=@pX{DHXq?y7 z0lk`Tc(__6{quLyDyx=M?5iN?-79aC(&jH`vhONjq$#HLQ9_NDK{d>X{=PAij+Ox& zOWF$CKoFlH;iYXN@mT?zg@M;{I>_u5h97x2OSNz{KJE=%0lV>aEJhBKXnyFk9;{BJf=Q7M@zFmvX1vQRYaY?gBMAe2s%TQo9KGJBr9mM_Tj+D zwU?IT_lDf7oo9Z}xWp{ehRFB}^L-@{&hFnegj{!3>|%6z?cWt)Id7-XOxOl)e%PZ! zXZOdd17W#)-JaVV)2^QPh64l>XN1+k81CK3_lw&EsEUsLqrI5Oo?8s@sco4>waZ(J z;nZF1TkiwOsrUO0B2b;;5Qlg%z@8unYfmpezgDWxoh-@TB8))s&Bq&PjBt>3K}h?@ zC@Go{U%J=b3bacVsVREqbBb8?JD8l}2dbuLjnYecijlnf*QCxU>2GPaI+F9MpXnPy ztGjGQ;)48$$YSt@BXN2xr#Xq9W)C$VX(${bqAh z5}Y}dkNV-iNFS$u$9e8Chu4HzDm-LGOk7hZfP1w8Z+TRFQHh#xb%*E$!NRKVeTnI} zn%xld>QR@U@WN6zR2{1QSDM)JfV9+f)QA2{evA8$!nP+_2<^$~vl=}j#bq${#f zW|Vq$-#FWm_3_TR2r*3X!SNxGQy#OuUwUaAfRZgHJ}g#7T$=9SLuFaoag>*~Iv^JV z?Wq(-G3WJ16U1nKjWOMRvI?MmDXNaR5kp5GQ%=tv!lVtIC&d^1rt9kFaFN~lCxq3# zE(Zhp)HcJC&l2cmx~Z*c<-DzFAkNsI59t{W?a$ka5v7>u$-aUqm0Is`#x88r=qA0f zWr%H8VnJaJ_S$yFmjt`hjFaaZ365srb`#AlG2*7i{7YxENIFsN?kLgUGx>Phm~|P) zmgwnqvw%ofB<^JCB84q#(2^B5d`M9C%-0~&bB}w9c4?w3N7N6|2 zP7r9#)&ejSjK>EfIcqq-_^tO#lC>p_eLR*fd@(Ea^dEIHf5=(k;KCMuETUR}e%bNZ zEw6h4>%a3gO=eFqy&VEt`X4p`>$rO-@fW~@5)6&pfRj(MM8 zW}91Jd>_2FIi0(_AXy62VU_sY_;8Z}^#Vn6!}`fddUY#N6}179w|ufUv5)=crgg20 z!cq4C_G?(_2M7LxzrJtZUu;Sbl%D*zA7OJg9;aPk9`3mMwaFmaA*Y|HsD5Qkr=X%A z6+QW97^BUy2_juq z9E{b#3KWlf-!d3o5BMrKTVlVC)=`}u8)PA$_@XMbYL}gSx;8wbxtsMn1$>u zpTil&`_hfCU(a2`!FtBi?5ta=b%7twW_q}vdr0R>OLmyP5vpYPD|eKAez~fQZZ}+( z7Xnx8+*wd*XVT{G{HIrkEot0xR!l;C#y5>=(d^K7vFoZ&o(2sUD0h~KaaEBYruDj(VBTshR z!h}Pj)RE<+Z*1v!6^9Lb>Gy>!99zufB^|c1+7YIPrk^UtNA(C*nO_f2UyRkvE@!wz zZ8YHi&Bg7XLK`{EXVyNTW-+&9Ht%_#V^cZNILJITueH5`9|s5zNyF6B28RK z<`Ar)w-{$VQQu!lwD(l`stoKo8`{XVMqE3L7K_ul6DO@H-+r9Qtq{w4p2<~zZXuj+ zqiykBFJ~JKnV4)j)>BU}#-DGKAl$0@p^E6ff31>R=Q&>Y$mfK|h%k?H!eQ~CoLi@n z?$2&fIgkHQ1rR*@Z2Sv3R;Jbeve*PIX*^}y#=f~Nf&g@R=szSa!H6@@MwVc$qdhp> ztcIw~d&%a-&LOX6TOx6XDX2N1^cyvJY}R!T#7#GT%`fJT@wEMy+qe?-ii9Pg3(2}U)nQc48yE0a$< zklR^{g}$Vd$(p{bN8hYU%YH zS@iwk7T>Cd!UyhcCRyM2pvD;o6&VUHenijJs-;9#gML(&v3UvbzW{_ld%rcwL)7JE zC~cEm9Pr7zAChgVYB^stjYosTrTv6z^Qc+uogn{4lv8K_Pyx;)YN*F2qFQMq&; zR(uW;$qi{!-&t~imSMN6hT=EUc3w%U_8vaSLbxJ7UVmZJ<9mWm8d-H*TpS@9km7tt7*9FkdW%I3JHdK$D0f z6H^jEpPW{#5{diPce{w;eg1cPawL_CB#kUMxp0W9P3gr$n*0GpCa@BXF+HFoz7%uz zH`!HN)Xx)jmx2mUh8l%6;GNwb0`ZBWntv>Ozg;_uLwwrs94CM}Jw-mMZmU^uzd+G4 zgpKJOGR0Ek?)j@8QjY6#W#Ywdd9Vm<#MEHFWFu+elg7;32*8i@a8e4(;Y#eM(4E7# zS|nh6o-hF@-pe_j1Oy{sD$6YtBPaLUdC^(AGK`g@6MmynTr-(R>Gu(v{@M5BB}n~M zkEF=Fy(3)R2qq5;;In!7(2dk%59N)oY^7B->!mIPSv1uIEnmo_yHL)4qS!x#Uzl3o zA{)GJNav@*g)|wvLg{2Cg17S}x%&Ie>>?qDl&K}SRo|&~Cx)PB%3h3POsZkox$PKp z$)o_B=A36Z=O_-(1laBW;0VC#yjAtNaGbU3es3-Ljq-RsvE-%^v3z;RsIOST6OW`c zM%5Cv(pdG-4Z3*I)85HapPo23q*V>GAIpQ=00;M6Vr@8Ol1fr3m6E+MgyQQ52xTv7 z&)fN)x;$(-7DI`VR7-(#gkxz_(G2s_+?@<=qvTDApm1X$lr$%&QpD>8Jz7=Xw)Yn) zd66H;!jGd&Z)QK^-Avmf zaQ3p-{Z6j9`w;+!!!H@Ovf>fugp>roHb0u7aK}pEnc}O{uF2a|MW@`SdTd*b|MFKo zWKv?a(RGzft@xDUgdwtSt{zu<4Z^2_semi|Uzli&LgyaOlhWRtp?9TSJ5TgxI?gU1 z!E&b*HqoRTTQ%q`mX2Z{!ycoY+S1)la*Xtr?w)kK5)Fhmy;0;#EA-&n-!O-}ge+^* zFSoJVX_SmQZJbj?pyP%1VHyCUR`M*TDIB*+zhocaVs1{XTl1a^-bfBnZ>k5CeV8H> z;ljR!H)yu(2u*a=w#K_ zdqPD<`&{RZWMT?nC&36VO(ez%!;(=R(vfM#9DY)3DXQ{eA7o^c3U%0r+@eZ-J<%F#A=7X~{fWr(6;5Zv8XKy?FOL zZcX25$(il4E__Mfus0!_B5_?g8}3)T%43sl+&xoSA@vJl`AGro ze4~Z={l0r_qcTmz)x;=e+0HIhpag&OK5b@B6{-0=fyuvz_}He_N}ddH1$a|xuz0w_ zv)Drk_`h$*r&Ib(l^%R}K$mIsy_37=adacm-4Me6qi6feotJ)e9LRlt`)AKrce!F? zZ*n1kf2V`GghfSnm2rvl^rJ_P=~+%Z-Qie2dtPs;WYYYlCqDkX^rK^`eb?=p&hhP^ zJWpADU)&FG__L+gD_wCnm{OVZzh3 zqH7nX_Yegt$#L8#SZ;gKcIp;jxaWymaf4a#WsUODT-p@a-ldlnoT-|0MJad1S(Qe!0 z1!!sa$Oj6Fz}fzCdXy?Cl+19h-y7dhoj}9JiVh$>{~S+SmGbO~b$XK22HNsbrBYlD z;F+MKFodNMxuV_S+*xv?L4l=K{S2Ix#EleZC;c&NN$iV#?C_b8?#iLro>)^fz^#i{ z71N8R^O{H#i=Isa1nVfi?#cpFC|o_SO*Dw&kj@A@9y<PwjonH;b&MSWjG7E(5~0mSqa( zS> zV6d3nD=Af^n8O;ib-$CdmN5FL`wfR9IJrun>6&F3l)%s@=uz<{Dx|~{Dyc-(uKaF~Cb(_) z-~d~*HEl$LMO7t*d4X?L71Y-5g+05fGI737&OnA{GBOLKx=?Wp{Iy`N~x zpix1$s&_}fw;uFLPnoX=*|d!>V7ILb1FtfNCK<30HMMRfDR1$QI&^`7JeAc_9Qq?w;(*?n4!kr13u2I$lKTPWT@njw z**r^GRmj8N9;T+WX!B`PA~xmCvR>O6uA|2Kk7&I+7%0Ds6RN$hFg*w(Yz}}u*AP`_ z@xy;EDl%x-*Ao<-C6I)u2QHrKisNv+>9k)Qu1gDg-N^wi^7;pamAmbwJP2}y^bwp! zf>lp7$>m0M;coKykEdNiQ9m6pDj91WBTb;|*ugJ2X@Kg>^?@;nAtRHhfH+G6lbD^o z$5erF7k=sVaYSuWEQeDdttP;m&9^9G3K0HqHjFeiy`HE-vEYqzpeC|(h__vF;SyDO zONPy&7Gh%M_kbSSRsCJe4Hjt@A3cvoqXP0J{nGPri?3v14`%25h!y?!bdba%c9nFg z*@l^n&q9}`(j!}84VJSv6*IYngb+(f98jM2r~IGgM|qy$k~diZgRvUQ)j)8dWI5JD zhoto6)xgQOaN+SgyDiIVjnz>PiH9MJ=8){FYV^rpfc4*3l&Nn*RgXMM&e$@aJGxo^ zf8F9_Q!h^stDr<3m4pjP>(r%`reyJD6P7Bo;Gq`ljH|W$&%SKL=k~W%R<5l$DkNWd z0=DL;P)TMKnj@i-3fB$IQ8}pROK~KTM9GidNaT2Zj=7R`m-#;Sa`t{5`!T}P(0Zdh zmTP_KjX0Q#uZG@;$Fe+@LT}vdM{hhmp*QLmMmc(;zA^JlA5dbC`#yRjqXhmrXHHcu zznscBW%S=YsZ{YY9nrL zrBS}$gy(OiQHc|ksn$xPe8qtSLTOaaBS7$@G&(QR(HU{WkG=58VmEt#pS`KXgwF%s z{;e}A6T5tcx6Y{CCi1AX(#WzY>?)MTZ!{_i1N&V`FP%{jskHpo8Tpx^YI)Wf^|J_T zp))GqNu4j9u|&O}b4JNkXYuaJkw0~$`lgW?bvVxxq=?uWBa1m-`l2Xmj-xLs@>ey2 ztT29`l}{+fgg&2(c6Z2eD;%jW)nomo2gzjEC7Kd9u=_iTIG}yNSRGHBmCU*BYFNr! zm((%jNSsE)P{+9ezipu1k>!$uiwJ2YioCds^Is6a61nZ14 zly{2rOc1<*w{^*~VJhLd9p&+1k;@L3H*X9%=ix19PdV>RqO*Q7uSEsU7 zIR6j6=-m~tpcu`BxVP0Nk!g&)%KX<_vYHqWFOah)s&Y9hXmahvRT?Plk4pVBrB7AWYfa7@IP>|0{m`@WD|r~+Q6)N( zCC$Ha>r72mmM7K;q3)R`B9UCTz=?5or;gtrxdB3R->As^f@OG6=6|OntJbvqYN<_z zO7NrSA==#mM-oU<c|!J zY-C63YGi#BZbNc<(%(d3L8`LAi`>5D)Wo5;n}*5&kq{pPx@x}PN{NxMqUft6Hhr|) zZ;Ruzh+#OD*MddIBj&0e=r0|QL7?L5G=FwHuaE-}7WK2|3?|;@dE#L%v!$ zcq45k>j}J(5nk4D18=0bG&e}VjmizEQlEw!Rct!F&_*)wbyb5j+Q_P?o^rsA%ISwF zcHl;>^E_xHyP}dLfi|*l%<(}RRh0Ou2W?dQE(dLVwF7P3JsWMT;B`nifi{W~+6!!i z7MjWz8*F5Z{Xr5Tg*(remO^SmRp;AJfUo!mz#3K8`YJE1u?l{;57wwmg$O}`HPTKh zskX63(MEqkjdXNvnxRHE6Njk48dWF!nh(~f(%5AjtdUO;_pz}?21yo>2W!+U<~&%V zHm^Uz4eP*d_lQ4L_&|R>;dp|LHC71}>4i2@QW`yO!;Q*CXAw7Jt?EDXT0wfL6;Kw3lzQr?oGHP!zE-no@Y((Y66fryyej*aAJt%`yWo)AhaF%KN3N2?`j z1>OC5Vmj^?*-I#a1B(#jBQ^uX!5BrBh9U1h*+L5umZy!gZ`1~lp1=$0xTEk45f5G8 zfbS{jz=?rJltUz_1J2Ng1YO*HNq5RTWL8tQgdP)D_B_QXP6xUaos~%zJyue+0I)(j zlB+r4DS49}lu~7TwM>0G5C(KZC59cwl9jg*dP%SW62Nt_bd-kEywS~Oyr3RTdfLA1 za=Y9%vKkdxIZ&*9*($VZ9NC&Np(BB2Vys}yU92^PO{PUQkHc)irlszxdOP4>6I|Nl zJj5y?k~cZ_chLu4XNSAv13BO9zq{h&^T1Hd{??z_DAMm81)IGtq6%x^6q3h}iv&g5 z7YbcXD=}3FR#o}ez89h56`dqTN`?Q9G$BV6SyauuX)~o%rbxn8M^~yt&NWClZKtkY0)Ti)v~d-8*5BQO(Uc1VByfm7O}DG- zWrQSX`f`*8MNLeRRS`6cwQ^^{&*U|NF~YpW0WMMURxFb8Wn1cxm3rv~)HS~zR|W0e zEe)s&ngi>Q+vD2oIpd(K3~4~W+yx4S1?tYus{Fbe9DO#OP4_5tyW^#LO`E2E_H6sd z-~ZZmZ@_90N8B#Ew(ld}F2@u+OrQ~``(gr3PPPWoNGhtZXz`$VJ63{dm8qUf2A|u> zN))w8HdTUChh0#*1T1>G9bGz(H449~vLF|Q6h#}Q;dW--=s7YL!yp{)N5_8W>4A5U z=bfy?I5w|CIB`g4V%Y-s<=o&+{>A-3pY0kh^G)pv0Hh1aahx`bwdP*mPhqadpzAaGk~$6I8F;Ww-G`QwZ4Z zdF0Wrq~zc>q>6Q?Do9>cmlf>CQ|Q6COe+ft#To&ilfnzpJCf6w5=PhL-K&~>RRN2t zH%Kh!X%=Pq6kSC}uqfUJO2cS?WJaW*;)#{}#$kF>R?#L8{-J0^Mbb3l%f_EQg$D|3 zN-Xz=0tsfr@07#|$WXkas^kT}Q5ExuwxyKA65g7EjQ^gvZ_VeA&GHT+?5LU$!Lpbn ziM+d%Hx$KChXSQq8B&obZ$)XfTm1CuN^G2ze5b&%oi;Z+LV>hl%B)=N8Vzj_tpoIK z)BiBI-(>GC&l7-I3g$rXE6$ti$@XqneIlu4rIbe4RD<1?5wa=l_M@hp9vr~fEbX40 zs76y6`z*(0!0h4j?LyGRKqmGS206PtQd=+1{@aW}s2!o1C`;#w8U@3#O*vGPs7CDQ zmk9-YUoM+9qRgt%MtT$uSOcBKDp9ckl0ew0pGR0}=3!3EjBcd(YlSCHT^>zYNwby> zC->cUVrGr>Jdt%5D!d*b0RjWu1%}FAXl`PT2~c%&xag9~fXS~&&7CD;uDjEbnq_-L z6$t9D;w~>DbTGN_Z)qxi+LX>={dBRXbyGCWP6ti^Ne?)NVN&FwE5X36ct>>T-8NY# zxwgj>?N+!Jl3==>)f!+7Nzk%NlSV;w3wlm?A70nfG30{u0au0x&BCVv@ z8WzASh)*WF!<0OOWw2yPMo=FML$^(FZ7`*Jn!&{o^3DU7yi*mqg-f)|I~Ede$61xg z-50VzQ_@TsZ*f!q&TAt%H?GR>8&vff%8N}C=|qOn!`kr_&+}pZ(SGiR-9cv3$n0D! z!&C+R;W&Oj#$AWsDc#As;l||{Pu+O7IxxtoONC2RtB(SucwD$ZQm7&{#6Dw7+_QLH ztDflVRz;xVvR)U0W`Fj`P37G|A{P~Pg0$j>3;Q<5q17lgPmh8w71e8OGl!cNyNpGYo%C$$D^9xTqYgcu9(?(`ZQzD>f9Z+0 z{{HwKWscf?ht^NeL)rV6e)c>&`t5f-aK%+;Nw{2m>&H2OrUb0a)P>7(^hC}E;OI`? zBrzN#x{#N2+Mmja_T_==me*aE&bk356AD$$q{% zhRaN%2xlcDPzjLTbYV7IXCo}V%g|HM{(?}x^*jq0Fa78sjsBk~j>jRw8K;eR&-2P& z-Jd%XX*h7$ ziZz|W1n9v-r^xZJTKB;>tUK@ZZm&0V{k)$@at@_UaP4>6vKzthCGt8cyXQF<_%p#N ze)c>k<=gK#$6E9~CuR3M8?b-rXU}s|zWt7^1-MwlIv~0ta{>MYXcbr%1sL24M~9A^ zki?-hh0-P?9bQuqttbwG=&vJn`CEAxrEOX1UD9+C4~@Om$PML2Znzt ztDK}Ie5+;BZ_YCTk}qXyx1HYo^S`I32}9!-#6*kgk14wyw+l*vF!B=dc}?!fS%XlC zm@E~blB8J`drH)Nt@69G@}-P!B1G^R?)5cA;7+AgiAm#+>K*~HL=V@HDT}iJ-c}e( zWDOijvcOe!M^!}Fy|Vpu*N+=w>drpmB7jpm(PjNmiHPDFP~g?m?&G|no?>?#g;`sr zP<6EAc=&y}@kY`m#JQGp4rMro?kaYUEPmI$o6cld>iIK>U$<;8tb?qDk_kqXz*Dxr z?hj%YA{ijDR=R&>)h=>SmlWXp7}C%iIf~G*lY(!jh#^zr$)Ly%l`;3 ziu57A7cN6;2O!NW_>k~>Az!!Sk|iI>{VmHUbIVVh2U( zMQf@Oem&Q@7Xq{8!?x&A;u>z&tjd-!qNdQm`R6-J+hrtuSc+JS*<6~&Tfk9?s7rzo zaH1ter^-LwO7rRrkYvD9g|0kK4pO5GMWl?Hs?=IOjhB-N!eT^3<_yiXA800Nh)yub z^G-?!$HLQ>cFInBrL2~_S>!nC7u=JSDp)*79*%+h!e%3}R*%!wJ)|5_zfmq6whFv+ zI|MeGPF$*+F#gDzmCzoBJXl7f1`XJVoTVtSQ|RX2E1hh$%Q7v&bG{8tW)l zt-VbED_4H;xLXBqKYwgw_-r|k^CRw630L(c@8L|*ud?MmoH1sIe~5E9hh$xsTi%ny zNv^LaF4^L?#D_gU2VKs*om#ZTA@Qk}uI@QYeDYw@8(ZS5N>%k*(ozjUh0OP~x6pTb zj$DN^#s*Bj^&DZ~y!Epuk%-_v8cuiC_V~0!`bI9N9?1y#X!V9e1Go9Qa2)Rr`>$F*e740d1N~I>6HAE`tZHU<@LZ&!Qn0R zeWx&6&YBaoH93T-TI=osWUMY8dV{Vs7uK#S#pb*+H5?2C!8-qyEWpFLZT3YmvUS08 zkx+zw=I4P~q_ARQhv7<6O1=dQYEy?1Gg~OESdOx>EhYAercBI2P@<#ksH$WLhTOHX zB1v4vMdGp%XvV>Do}WsZf2ItBhtW};u~~dHbWkY@*Q{#ZVU5ia?m`@lDL?WeX`J#S zL6US+<;;}fUnXkVzz`1mso{D%k6YAyHRQ{^@#p)t>3#?+_G>G54~A{*Fl7D|>%ujL zZ5xswlkDyu|K+Z#XHLoiE&GJdyetvy#)L1 zy-57NU7Wm#e4iEFYd#~l>eoFm_DN~F@+kcOo}R;nni40b-+IWltNQ3vW>p?TGCFa5 z&}t-25%fZq)HM;x@6xbodf3#hk|i`G*8w*ojO1#kZCj`0t@DI4gexr-Y(;V6Ay2EeI1|t2 z235}Smu?o z95r8ek3#O{sg^G4A(!8JK*gp~yxdA>@mtUH)=iGEpB?+#&pSVR$c>Sti$CA~-t&6v z+pIj*TTW?z(sZVPHPySgmKbSAZVy^j_oRP~sTWk=4Ha3m`FifxXn2u(GWtQ8t=~QrDdJ zh-#a=hb5|hV<`JNsmW%1A-m>F_K30*i#tx=BXl-PlsL_y-lwfuQ<3HU1VuXh3&dR9 z@?-ZGhR0O=4OOwy%DUDzJ`_EjwvwF8c;ocoI_Y*&Th1VAtMZmJimqWN)+svvxyEo_vGW8zN8gW|NBbMFM1wY3i8K5eZ7=KS{)b-#g`WwkMs=@*;A zAy*IZi7705;goUdR$j;NM5=5vOk=u=6$OU=nUqI9J%8QPTnekluU2OP8Y0S0sPNT8 zVb{2l6RBw_xy7RnL2P$>lLzL}^H&Af=+){)#Zk^xIZ8ZF##MbCWI@Y*yNFiOB7L3D zr%xw#!lsqW;zM^+AsCKYC*=N?ZPodebQE!*G_P<)!9HqS-%`b zfS~+(qDq=c%5qs~Cmk(P8cxqm$*p`iHG4EmZzrB2r%imYi8$I>-f((f0W?KvBGs0+ zj_ncp0!cxX>4AfUKdMFi=f3fNmIQP2EfmvlLwGsxZwRM;O?)+%HK~FOSqVj>-U2W2yKW)5a z&kIq?<&Fn%B!OE@eR4Xf{FLAiRiF(&(qc$Dm3yuQRhii>6JwY zRQn1p$J+U;ltdD_+#V$=ke0edX_#O^kVkTH7}X@!c3z$dxR%;VW-=AQr0tFLZ?IT>S5dPJrUw8r5Il%6iVJVy#v~zb~evI#{9%9NV);=VawtxBlknh<}^Bjaw`%enpcpS7SC0r^g?w~ge>)2ZJ6Us zGNC^0TR3&Rp`J?~OJ+sBV3poW?6zn_a!z|tJc;YCNC{7zp$(a0z;cQ@?O^iS#PdY; z>sKtB_G_pj)MgV+L!cOu7|9;uHQf%H8P{P&#kuIXSDwu(D)aZWTcpwczMYmf6WQF} za`o=$@=l@7>P0l82&YI^kSpiwGMe%rcwbj2i|-4~+1vCHR_)fp>K7d(w0fF}v5DkY zyXd;XpF)?Y#;4_|F`1FHgrtt+DBL6BQE}*OuQsuRe&OD?c^CU3Okjv9iu@7IhYxm$ zvrO12TJfA-ZN-E+A*&`K)>4DHku%V_*9W&8YmnNDcg^zA%NOp(nfUU=;K+)--CDKj zM73Gb2A|%E%cYzumpG-ZZ)Y6Fkyl$6cZ;L5PtT*vBrb{iOV5i{e5DE1J-%T^c`xU` zS4YI3-V#Pdprqzr?I|i@S#r!b7|!0)ne_`tCY{wx?vYw&-&##PArU}wujh+5yAF*D zC}>5xk2(aWiOk4L`D$X<%X@u_MFi4O#QSh__<(-jS7MB3O263B=u{Tf=c1l<%b)uy z*Wr9WaeqWj;Os>MalKddFHpan82CRTU$&eG_}wc zlOpUNZ7~rXH{aS~%GPPNwwQp^UMD({A?}NaO0{f>z2}L`LT+e_=^p-ttt~DdYL*)6 zV!A^-40Z9ekGdE=M_tq}%tu}16Xj6{Qi{_O+M-7I95<#=`};sL$@UUAScLiLib;uk z-nt^|dZkBKWaVF~qMI*G@#&DFm=qNGT&8M2ilJsaKa?-?sESFL%cCl?%wrx^F#%4E zx2njjbu)#om{QyOpfjbN9Pd+?6qfROV()$Eib=-&x30)SUH8!ylY)RBUGW=WBlVHO{+%9O6G@X)sP!)$$e`7Q&a3@C@5n8hs-@K1 zg^*UeeMH6aGF&Vj**k}%&0!=S`z2~8VAS-5_HiYCpN^KTgrK!@wg?OKg*U1Xe9IEH z<#A@(Y%bz{Ijv!$8hf(}0Whqu=6>25=h!-WJP|tkP!$c&tg4-S?I(E=YhS83Jhlku z5yp8*?c&|J<9);T&aPb8~l5-D{V}p=+TpJ(|2uYpsknsbAq-uDc4+x3Z zxj^QS-!g?A-vSa^0Whkq^2jBFH#E zNLCH~>H#6O((?f!^Ki+|4MMVY_k4qp^rZU%A=OR~2zlBYgghMqLQ-TNLf;^yh@rhf zNR^#$4+zO1>;32@xf84N)?9KgHk_O%;x_|?WMSI<1|eCy(jO3#wQcDEA+t(ky+KIP zM}LEmS-G$t5Rwf|;{hSr(0so^NH#Rr2ZhWAs16Frs78LHkj!Kp5Kv%O(RCA{np3`wfUs3#*Fl4OKY*(L993}2vuL((1(3`w@b`+mca z^rZg4khF=A+%V*69~d%vUNGe82^f+#^tNG0+F>&a7}8l64+@#5O!)_eq&>fIYF46s zWoJXa^#_H7mV0|p$giADszRKY7YeB@$dBSAaxMpjWKTzVqmUfio*xu4yN>QbA))3x z-YBFv!2uzaf;K%Mq*MI9K}gZvctA*HXf6*3dD;hrJUszIiWl_ZxE7Eru2Z2 zI+HJmku$4H;DC_XBGK!Ku^|@WkSyFBZyXX%5w=F*kSw+8jRX#vEe^hLNYQ_KaLBV= zfkU45!6CnGXk2N4C$V5_izp}q7xr~fl(0rU)gPzaQX-lu8#EnkFQF>Ux~|hdC!$@Z zCrtcAA|57iTr_%nJ8!hLnY&o|yPWqv zmZJ0QGvegq_?*ju7*j_a4x&o#h_gq$nSssgs2REU z68Upw;<*)QrgoH+3`w1&zJ|A^SOYl%e6V|Zw^Ia+?w*&3rM$uAm!AFByQdnRryYI_ zrVFxBnmssHI+4cr>JLC#im(zYAc~Y#rS`OWLFIVfPc*ZDsiNyi8F$TqlE0uL1ZGiU z5_sQR>J^eeJD0N-pWe`L&&XU_dxK#=TCLr_BA3MOd9Te^Qi|es1R4DS+u>q@yp)7_ z^%QwLl7mRH3CbS&buoM@d&%^^lPtn=0+R)RwJ%%~``zs&sn|LeJ)1x2{oC$JRg|UJ zd0&0DCJ;254Jy3< z)dD49n8oBjJ*w(^Ayga25Ck1Il41}*Vt_a|4!vD_ltgK6KX%&Pfjl+!iS}W12&dXT zi@i6W-#5z}NWfjSBv@?~J3Y_N<91QL^;nw`a|iSaZAZLY)weAeTF)!JTNa#hF<)&< z*UA*EH>Q2&lENE!V;C;O9w~kxeC0TU9!Zi#@rp* zrZ>8`$cEQMh+Fa&U0ToGE+5Vr^Yp0Xw|<~{*SiK8VwqV@HQ<%=9g^yvtz_3$8?K^7GdCBiWr zm1kUO?DuViN@Oe7e-UBxv~Jz#D9=G+!?!+AuFm9;zZry{yma-$RTFclBdRg2lcA(^ z#lZo(`Y%#*e_4CI8j#F(T*^4g|T={<&b|uM?!#MEXukZ^xxG&F`H`LYr|Las{ z0wh%S#GD+2rIJK~AeID>W z1DoBk5idO3e4<=N^g<#ZaBBZF$w0jKwm#2#hr+`Wau>{LUlC-reQA)@cnyogK)N%b zE(m{QUe6Mb2ju|Y1BCgx_k7VX96(O66AJlxyPN|I&oec{4mf0kobwNJLa)D_j~^=~ ztqobH`JuHP$_ZlhI)4t2fY#8W8K~Pk>WyZwuJ4S|3>F$c!3?C6?i0&EMk^-r#xjs5 z3%%*aGCFJV+*k(FV)Kn)vSnVCkbQtIi%3mMJXX`K4B-m@RiNZ3Z6;(ruE)S;zsTPPuc4 zFOQj%o(^lJApNYZGsYdL)VsnJOYMr5Vkrg1Ig_^elBJ8vm;}ZtEvulG=2Cyp!p*m) zyUnUUV@Z@0woc-huDQyRz;`T8v^$o7%7tQi*)a{PTTc+o#P$K4Wkn$Zd<0OL1_bF9Z0JZu8LYm@|jO{&+?HJFoi1 ztt_=&b*0HbLoM9Xw#8YtyrqP({Mo$2C>GZy3(Aj{XSU_!@ltGU;2<{~JGRk0(3|2P zv4jpO0_U&3Vt?mz3mvBOy%S&X0^&5k}cz}84-tH zn%kGQ+F7bkAv_L3bT%K_T05GyX{qDgo@|1?A=4$p6pWkt9d_!Jltvw7?&KmLxj9w) zPHWX^YpQ^8>0s#ft73@{uN~ZrANShs5XB%!IAnn_mk58TF2}%bXTH6 z`k)lK@vkQEd>>*|Q6xAkHrr|QA;Yn>L*XkfhcOjajVmbo+l53yos)t>!Ce3uSfQvR zyk+XhOaMVU3zeMT!^R8&)ak;}hFKYUfLd{Vyp;}kBpc`Pm`$e~)rYkm_OFyXcTO>t z2xHx2novRPQ>fS)L8asBa*Bn29Ew+0^L|jrDW0k2W1G?3{lPM0*4Z=nM%q0 zNztQt)1-}l38+4fc-{L8Y9NFQ;@jF6EY|A+e6z4q(4nw2AZ|wyaDsA(rA#t=ZdAbKslhHiN#J$$Ek&xXW~fW+T69G5A<{C7?Vy! zxjdKCDDrFbsfB5X@G1oOc$CUtdx2(CowZiP=lgK8^#QLJrO0>f_ZL%z_y7Rhtb&Q&Ad_KHmsf8{W?I-} zhaENM4f@D)g{I)#Z!?4^NM-Oj#4A+Jq2?HG*vi-EDp-Oh;;}(g*tp6m^Q|;xF!L{z zWQEj}+nl*mDw7Sd19I3&0FUpu*K%dirh7$|Jyi|5$qd}gahi4qs{-N~jVn=yCakEg zERta%FX^&Y$`6X`@HJ5dn%T32S8leG;h6Yq_Ro4L=Nr6HhGa9-ZLwmVRcY?{I4GTR zWEoz2?q3K1n)e5xDQw0MqdG8`~5D@Yg=P?yx3mcmT|g7@t;*^;H;F-XJ8d#-PbY`7@?34L2C! zPD|uE%i|yFAeU8W^Pf`inA0Zh?OQ2XlnVK#eerh}OPVp67|L>D{vRF;C%;ak#v2FW z2`=l9Ubmw#MAGeC@d7q0bzztr6R;@^6(PyZ-a1K<&ur%?VOZjLTO-^(p zS4~nNo65W zb6O&v@kk$M_iY}68sF;&m>O?sh@JQea7VM%M{zAXhnUPN$o@H}ur{m5lZ+oa!WBcA ze9#H1P1K@(V|A=Jvqc9qZEDUvMZw>(Y#er)odcV3Bf8R+U;^w4MGS-K%yUcR{_LEH z9DuAho67HkDw-4l!i(%?njYc#NbgE<_rY78AKMR5r+5L+&}1rKh7zqay)R4A?5>Jb zC8P_+pH;N#j?q*>HyF+zrJ*eUxET*rf5doj5#B*+ zwKatn!-lVh_!6tx9-O;%#-A&E{TC}bGNX~Y>h=&J z7-nd{WXi%V*_c%~_Jc_+>6$eFAx_b#;h%AGKa_7#s%(du?PodRgVp@?Se?3Sbzj51 zud;n zuiOSUvXTZzrZm~;+n{vTF9;h2i9>b7D+G4MxwV(lnW(x{)|q`Nory*ua_O?Ce=RLk z)ja~>;7i8PQ|mfo{ssZc_lmZC+?d_jmM_%omWMbAS!9`Y&V_LDP=DIem~+zIhfV`o zN?ul`Bm3rXE%~K3MqpE6NT(bP>9K~EL1poRAfuOJI6+1)fhAo=!!gj0h=w1*^dl3| za737bWGPf5N?_#Yj3}X*;dbQ!EE5oC1f(pOwYGl{KU8GXhsqn+R~nm^F4 zjOHVH+(w0H?T`zuK0TJ2!cj6Trre@@A4V5X_|n^XXbGBE1&Tp%vqCsetwr{qRG7vAKKOq z-Cebp&>l|-UtLp_E%AE`QV121S&neO)5Y;uegmN)wJOYAfNS*nItr5(N?cV1!r~PK zBeQUUCTX2>*TD5?W3jZZOxnmQsf73iH;#`B>nGw4r`U$6!oSj1n@i8=QOD$4EKvx> zAs&~CJX>$^JEYHAsmUT_sCER^a@N1(9wPH?rC`A&Q!Ud?@nZIkpz%Rhzp5f z%OoK-p2^ZmKVrOBf_o|D&&I=neTSlM3Hk-H4dcSabR4jivC-D9Lw2>U;1LdED$5_F zY76WGZl7TWxp3{oshcaLHgO22xOt9FF_36gQAn~#IBE;Q8d3Z)t7ygx`n^ zJlz?%s`vb75sl8bZde;)%Co*wER_{Vv56?E^dS?GA14epX0~fj6aUPNW3-TE_DhnX zS|*)t92ZI9F^sXZ4*#yrf)9~u-Q)ym4-=43$15gy19OhASU~cd#6s&f*Q6@TVshyEx8?uLocb)0?bl& z4v?kFENyatJ10#>NaVJieWIqeM(4UFRp=?G#5}a)r(8IOZ(wYb$}(%9YJpj6MsW%v z9Rt4jw+TdJ-+_k|y|H;Rd5|}p_1?bSJpOj@gHLR4p-~vn31D>r=pJ8H$a{lQL zM-5;}C23Vt9(5I;p#Fj`)RdLM20b$sG@i{ec~|4v^0Go>A~SB)TS%R$|F+}vwNrU2 z@V(W_{qvM~Swb#LE4pU??@)r4&d7fIm6Di^Pl_<~P~52#mE~cO%qc3{b)_ZbQ>`is zgC-P|8dZ~eghRE^$`v0~r7rIko0E$7V!)(jId3a*1h}KAMgS1VbVVVqHg$gUnQdr1 z-M#*10BwOTsfTgbd0Uz7YGY$ZyMq+9%+N3B>>Zo|#GTA}=x^1Wp_B>Q=zIk?$>S|i zkK(#`aH3}&Z3u3*}g#c;qhF~Wn{?ow~NmQSR;bCf5|vM$`VjcI$@wx+FVyL;Ndwr$(C zZQHh|ZBN_Q*YCUc{r27K?sd;O>;4s4RT&Xa<;sezC#o{j@oVqB<^DecpP3*>8CZS? zv{Xh^z2$NDId!nXp-0U&#K3yhB-Gd9psz{HO@rgCzhWo8i-+;h;LXInHDQz!NL@+W zUH@J@Vp^WMT!kIhat2YNQBk8q$MV;K`ubzawiXjldV+4^B2Ond9Ur0HQ2jUFx4fVJ zm%t!ouI?v{Cqz;7E)votrI}bVZdFPa5SLGzTr^fm=UKgwO7O+Py2NgQ{ES8(hTk*4 zF*B$yKPv7q!&Xn5UJH9Ut%UthNI;4e^@?Bu@sd;O3qVsDdzToM_S@L0+M;wW=iM5v zBT}%9S35lpcomIA*YL_0fK*E|?OhgbDHv0LN~l;ysLJrORh9Vc$BIN@Ly3`*c!cYR z-3nvd37U+*_Fa?| zK86DJc4ogl>`Y{F6P)B5+OQwGH=;Iq)yyCpdlP;M%zmw!w_GF|s-t53a4iYk_?YlU zs$v~|7+dSe;?KSawj0ReFSR5A7f{l;@WS?D9yOF3$WKw8o&BE!BTF%#7`fG_QQOl= zr%}2(&Da~rGJ&a4+iQQ@G(MpE zH%mv(>bqMNblGh;AKM^i32zGuYf8${XiD2ue|p()2R8x4e+(TV2)YxXSnNCe)Q90d zZD4m-mtrOQ1(Yy&Mz=uFv*J5+BKfAyl}Q7OB)<4o2ojW%Nv4J_FwjYb7g!5{ z0pd-i7*Z^SeuA}UY9%S9vqIjj^esmwkh|*p*NFjq?xWC?}72D-&IN#A-V zZMCK&gIH#3Zllsi2txs`pA5Hzx>_{HV_$r^xISZikF`mw>UuDUI?-S?+|e{rVvzk@ zgkf+Lr8o)0(KSrMm$DaI7LnEX4=i%(&%+y)Eqq~KSH(kLe$ z=l2`|C<%Mr^vW$LFBiVutL<9M_KQwJeM=kOeK z8RER;q3_9QzI=NN^vHdIfl{o36ZK0L2NvyXgl==(}zk@WK1fB9x^ z1&s)>C(tD&(46$W3W$}SBknD!FHrafu~UjG2x`mGKrQ#$`RpFK8698?Z6a<7WK)>$edxOyh3_J3pt zFqe?KiPk-_*Gb&@u+RpLo^!`-3y1g!v_uZrZx-(q-miy6Sy|xe=uDZw?kQHyQK>fZ zKaI=*m6;6?Y})nRhv)RG;&jVjL~!?dkeQ%}?pSr9JaCoIs^%5>Eou7|`MYa*kH+j# zK1nS@Gqy=BkJ|ilhJMAGI;HQGO+tSsJF{@vAj`tpy+DbeH}2%47$&#C;53bD7k)R( zhuxElN(Y6nJe2)mleEnHSN2HMTy z+dGzEeGpqJ_JGCjKWH-Zg5fn5EmvnGYLj5?L~;j6eC0D2*$#Cxt0>>0_~69rLl&Dvx$=gM!$!^2{ZTmS_EBx^ycjj(F^ijORJr%5N0oz zo^A42=)(@5I~+*Fn>Pmod+1TFXrM%BUaofWVQLP3P`_4f^ZH8GAsF5wS@hO=iOLIM zZ`2(#ozlz;DtR<@;aBt~AKc6)OMh)s)GP!(xPCuB4>5$+$2B2}6ata+OcX>E<`d)M zFY3HVJz+sHaj=aXes9>g#e6X_-+T`g=;=~lIqY7yy`IvAumAmiB5DkwR3XyZW3 z2Xv6AC0?5ATie77-ZnVIa4UY|p6F@LD6Zb#Ql>|~$EO;CSn|Be)%kn3kG;dQ&0^6u z?l!NC0ftgx%`d7YU!=Z1T^<*^@?SiAq1!!{Gr4_$!xd2VuWc^X=oq6ijy-M}FLZ@j zv|>x{;>^{1GB|TR0Ci^5qnq5w-4rRhM=A#5ml5ozFP$IXB&qd1AcUJ$(pN3>9`SCi z3la1XI#m-hE5Ygn#^}g`_()<=50OZTP|XCJjNn-6S(se%tzS>S3KJF+`0)bkyPz3d2>nl1j+ zLlZ4ViDlc0E}?N3c)pwn?~BKq0&bA<9(o`RxC^P!9gEPj^tkZ%Fpa%Q zWl%2Uj{p_-0OzNcv9%HI#e+54s9wW1t8n82(W=IqdboN^D-`m68_xknVeDAyuT+8x zOluIe+)aiMMm$u|LPY&rQV?^xzs;tQVFF~va!bauDF)nsWjEWcI4m7>(z6(-E>LKisA z{#2O-n@-9#j`Jd*gx87|U^7hp^@Zo``zqYeK4XM(jx>{%Yh=Ii8RyINXofVU*89!~ z`|l_al=sbG`96{p5a$pAz4Bgz(3D^Q>kb9=gO(}K>%lFpU2#9yr>Uddv%{2CpHmdp zKU4tmX{MJiw_LFvGKgdO=UR@Q(2ivcCBq4M+gvz6te&lwmUK29qYimZx8>WguRW0^ zz2DfTb0QMGyF-r6ZqXAd1gU#Ef&S94*Mg} zF8lnivAbh@(v4C*m}*GrDn9om{&x)N4zN}4+~BHAm4aS8Z&MP zEtKfhg1OorKE3vSAtS;@h-CITi*P%dr>L2f{SRYt+@{j7P2gw0WKke*X#6=7MWe-> z(>4)VH5|5D3KTgwOEMqG)g+pJ$zH91VNt=_3#YghL4tVwbo(aCn9tx&t(E;V#%xhe zKL{gvy%X?0I7qJ3vLZ)XKvLSqtiF|`7(WKHWb^K_LpXM!wlhPDJPzBrIYV=tQCUjw zy5uZA2ZlX$#lENXp-PI5i}WFL*X2GMeX6EOK>J_>K|#TtVhr#Sbc)hBSPjBqkiG46N4EBuiBiUe(u@`R0SLX zKYl5CVG$bmk5eQDGe(DYSfxvsC<}qs8f$7V2)D*WN$1*7Z3?dTz_2a^zW^vF26NXp zj9kr$6kLrF0HePkWmnW-#L7VFHU{$$l8F^#_H}Ja<}L>Fl7Ut@_VhrjEiC|}y91ho* z;jO7m_B4k@T;Rj{fZP!eT0lUVR5*sc;_0XXBgvgs6=y`tP1J*3`pvgY*dR{LiC^Su zMPlyQE;wC{E8{@K@>%Jf9z(;woWj<|u?#3$J0o-o(p=Hji!gMDe*yFs?aqukNGE#? zm_XxdPFYit398S_&fhL@(A|GZ%bhXW7AYaK7N8C2G8y?RQ}?ZxbtNPT*U8FG8gOc(`0%hrP{2s|PoWg=5D< zjjghNpJNd^Lyh1U4<8LxfgUdHd$h9MQma5wBZG(J|6xaFLBU zKD8tXTLzG1O1lKGD)V%*I6SgqjzGi>_~`arg)KJ@U|yn9ojf%<9eI_Ipuu^lEQ`Lo z&LuV0ixgv8)>oeV{&3zO#+r7#>bRfRWe7u;Rb_SWo9i12{Rvo;i9p?(mWhQ?VVC>e zVdXq+*w6oaP-d}1+91;{;C}CqS=gVw%6+WLkGEe zbXE}BQAI!%(0bP=X$|UWiMR#{GB`e6vqNSnhRzAW_YbuWzi#Wo6_vamvz1er5p7U( z^(lwsWk7(Lbn(AIWM1LM$can>>68URC7PUsm2nx8)BQUz9}Eyw0 z3T>w}70|$%G0v)$sXDHVN*qfkc4dVjMC`E)K*esSi9`lGy@eVYbU0L}jmUy(Zr1E? zrL`8ceq|#((PC121uV%8uuC=VW*u)jqZ(ekVJZCMJnrSEOfP?jEWIHJ*q;syD8R`~ zi8$7ya!a-*PL7g5B4jqn(930_oM?zR6x8+OJb<$R7K>iJ#@_M?vmH$@5DU_Bj4sEM zKAb}-OA+t#y0O-*^@;hfS(nGA>zna6j^hrMf2P;_S`Y2X=;_PDJv z;;aYfkI2!QrF`H^&5;CGLpi9OK))Gn#_~@6SR_oa7Ct0$vmT&sE1!XvnM@&Zc%J3%6XbtjCR zcI3C8tY)`_ZaN*$M%Gb%p8B8P_TB;b1))gpqDW+G}Ze* z)D?{EtsU(QjQ&#ihXo~98>26)#zuU6{{r#XrGJ1B{c=Fa$oY@Da(31Ribf8a^m4+Y z^h!o94)hY1Uz$SN|GVyAIKFf>8JRi%LPW^O^4AUgB^m!Inf{X6|MK=%y?=O>gM zGdsPgsfB})ohH4g#aD|88yQ#|8hzd9{{rT+8mTaDm(GB;@krf}0PrIwy4Hvr`Z>>* zHR024vJt3ns0%|3nwRx*S`Nu!sj6*DAa<1HPUoZhLjZpL2zWiQc@0j^j~QkR6^gP5 zt_Ce0Ea7oWH_VS_e0#|=mY>(sNmH20*H!+^8Ie+#Cg63W6P{y2KBdRg_VM}po#L+Z z&80nZ%Y+lrRv6eegQeE9hAI*QVd_*mND;=ZCm$*JIL;}@2F4&}ho(td&!YEG0*ABi z7h66ulA;S#zOb^w3Qa(LnMW%M1v{N1oG!iwCG}??Z zd~P0e`?DmkDzDp2)GK!iD?%JIyMyDDnwH`ovl}ZAl33CD%gYhi%cg(K&aF-EKB(7h z)MJz_ADDkeM#VBhtQk43lr=r@F+A~<6S&EIw@u{*th6n7Axw_E#9wz?3-vUTn|bba zvc0;eW&XyLrCl=`TA?F}1VPMP&A+dT&3EiqQGxDM;~EcSJ80hm;J&T@=MMH)m;bj8 z_Fr~!=Ko*g{~iba@!0<>4zRF(DJsza_u~Ky%ijwBDGvO7=^wEF83+F1?Y|QT{>Jg8 ztI5dnS4jKo`TskJe96C!e96D#!@uId-}U}yjr6ZL_0P!h{}>1ULiTS6nAkWO|I0wI zp)O^=#(~mxSv?b5R;LRBCOBuWK*MSG&AlUuqO_6&Qp1ldiA-To?Az;-EIUpCrR0<$ zTVv^@7ER6d8RGjB&PD5lqkDMPv+J6>y}L(|+qx0*X$QqHBBzazz`O9>5vD+enOV$zGt-21_6cg3Gf%*X@+RwzP(nqf8v9ntGg!oF8 zmk_sU#SHlqo&_@a_L=G5Sl)#TyAHXgSDE%+j9sUDu5Npp9NlNU3rF{ABkreJci^bG z?^^doqTJ9FfUJRh*uZ?fpMTQl5ic*}7dj*{2a~&o@iM#r7zR}urJ)tHoQTjU6tIUI zS`%{6S=AgPy8LOIBBee%9*^)c4|OP_=Zd@q+s}?Q`m=uO)RY&Mpbhg;W)dH;eZwc7lYGuMBA;FDVG3P(&k9{ zP2ulAN7f8{{#_kA>K#(^leY8VzR|sg4!==_fY0fi=YkeE^_Oq7Y`H=)BpD|USM0cMo9mEf| zBBHyumfbC65;(RnC7^?jn#f45h)EkeB%D!?57eAk-=|W&8A3Gm0K!xE^C$e@*PR4z zFqfKEGm#EGN zZgELKyFt%*$NGmxS*a8H=^Go zZKO^2swAjD9mlOMcdt1Dp4suer^mHc0l)&&D0!+nQNwhC_`yPuEqp%QoPW5mSW`^e zSP@|@U~UcVZlS+a+ToANtocx067hhszwUH= zZOZZt7e3yDP3HW=R#8sy+v~_x@|p{bpA>bwQN*$j!FFa+}~oiLF*qJU;)NPR3wNB53kyZf?l7!M{G|qZybj1eSS?lc}ocK6{ z>=d+3QDjanlIR^3Fhro+hgvtDdP{oI<+MIoS9>)Z{F$gYlt$i~jHmWMM!~nJ2BMvW zZFJgL^0nqvfgqpb_Kmg%xdo;>7Ej8;Xu-{d}X$No37P7 zAn9O(+4o0@WWLs>=uwAQQ#5Qg{6=)aT=qf?fj{%4?lqigqU~p>6EP(q z4m##pVoV(s6Y3NImiiWS>#AUQ+%w`>n}-SG+X2~itK3l&4z=W{Q(w*8u&QNlu6BG> z75GF43j#a!I-slLX~~G4!p-}!e3Zf6UryIR6tJFi;PeNj5|=mEF$oJWZf9@j@pgAN zfPZHD<7>A0P2eE*k62rw?kMr>siH;Z5QT$qm~DYf^mUd32M0rC{(H)cj?wZ|@|A=O zwuR8CM+4bE%*|fnICJYN0TKXGoOsL1GA@*!rWMdi*{a`>KO~t}m{_z({h8%XwL2PA zcA#y7@w`VIk&DBZSCilgMe;%wC5MGOY5nTqj?F?St$Sp)-90lbV0aCrNPboSVh$cP zMbnV89O0-#=>4NI*DgJgrHKme2G=I}9zWeOVEeW%i$JH;E& zSZG35*-HS$B5w}dsu4S0x;P^xi(xrLsO8gpx7W1nd`oE ztOX2iK&`C-xDYdpB_(&v7SWA}qbP(}^FGn1HU0d3>i^pr`>gWnZvrV$|xV<;@qE*8c{Ql!+|^z`33B4)ozn6Q{$Uh5W#ku z9odvTo2uKcwDQ}oXs8E zwc#v+KK+5YH(ndshiqcvb!H#}9D_s@mH|RkYw5P>T7@VxGo!j zSAE*1hP2%-9xl`CTbAckodZ3ebZq)sV|dKLHE`=@U{+Zn{(Vi8*^NY0BQ$n*`$evlIf zmH~*ufm4Z8-ml*E?*c$?vF$e@NNf)BTSv+n{Ot1681%VjT3fr$oMsa*Oj)R$sB+{P zOfQXIhzH@wPcotT(xISMZPs_b`gI5%!tA(bhjflx++i_J}k?FlUhH!+&U#o?& z?XhjU_OWm8&>z4qKMcWaRynv)&fXyCX2nbq1Qv}3)$|z}*xT&+kH_)@MKk0hktyoK z!ZNartmQCfoT)0v(KJBQMU>HwzVI9KtUnuPICK(-SJT#9JkrR38=96iv54sE4O8nr zSHcM_f@_WY1jZxLXcYjPb73R2_`(jdYAut82Z%~@LqhJ{q?jd&9eQZD_~rDA?nl?h zjvwD?k29Bp3%hD9IQuTH1-a(L%4<^{cW52Ig%}ng4q22_x=jYr)k&Ik)EoREfQX@b zIHf@roPkA9u#yeRe2X*(fu24Y!=8(vUY(hUTMU=hiZ4CJNY1``m7>aZC=_F9BY6jMGT4Ijj2EV8Ddn9^|HLs+=S}84u)LXMZBH+BghG z?qX>2eB@eTfe~8!HmsHw@P~1Ai7R1k_burJs9Vumk_eu0AnT{4uQ|Z{b|TX9&IFnn z_jGN)tpRH1d(*Dm{kY8%IZ!^E!2p%}Jy5Fo( z{>^Q^;*{Qng%``hBbY5c!Yj=z!po4qg4%>O0jIM*1rTVwkx z_s~*+VHko5?KB^YTj+#p%#wH_azaN5+r*JaiAZ3(TRja;>y3L)qY})U~1)QA$^(1mjKn+ zsAan4S6I-CRSF6C1z|Rsy0X_9<8Ilmd?EYGJdLc>dZ3LyKf?V)&ow0@?p*pGS4Q*; z!b#>t6-O`QhXMV=_?nes?3*(+W4ggs%>LN6V^_EeSQZ9$WZb*ead# zz-|f#8Efab<8z3Mjw5*qKdhvt8P@a%mor6PO!EBR-@%>nJ_?VHWx9An>w=s4v6{!p zkZLiK&RM4M+r*CiCp$(_&a1pqg4*3jp@bY8>?o4q$$aXOvL@HL=}#G@b&@xxg>w@T zS9FvO;AANDz-Xp|xk~evksRW9ea|pydbJfv_Wq(py`lY2E9`@NPguuwKLRzBL|0vj zor}V-Lw=+t9NaL*ii!U7l})*CT+MsgW<_qcb1E4uggsp6X+8oG;(d z3ALtTLjVK5Z=qx^c5{UOgs!*Tbm6%Y=>XO~RX7^2`;lFiM9IWK?CNn-ceCY?(ir8K zh@qTm7`b0S;O^HhQ5ZvTi5^5ZSzyGtL>*4xvbzNawsvZ`&b6W}s{r**#`UwT=zBBA z9qcLpL}nQXr$cSa^zR>fKC;SseO!hx*RyI{jP62efsHQODzhqxlkPK^ae2SCO%%2? z>Vr3d;z((~x4ukPkjPR1-FgD6HJC9zu~diOsPdd!`lx}5NP!q1O)wf z3Zlxvgn0XeBKJ7*y$mhD4PMg#i~2Od$_aA~Mb$7UU?dNVmO6R@$nVsOs}g6P_~<$M zU}OA-Nan(kb57e;RV+yvpVK23m zMU~79qQbZy5|!~#6r8$+vR0Qf3}=rsieeqWY`xNv#cg<~((BplM0Ua;oUdH>E4i?* z%7^ewJpTL=zDigZhzZ9jFtM3TuDc2#)8r^4a<{y%MVvzq7h5fKTB87^1QU)EB9OSb z?5BR((<;fZ><^{Y{%%hTolqOXYEBRXcAY?aH|37kpuTGcQJ3iGJC48YCE%$ z`HP*8m{#o0a*fB3FS;EE7N~JSHeS?6JG+(x>tq#>TFCyu?UN!MH|IoEy)k>$h!M@f z(?<7AjTX1uA6~TLB$w9z)h3GT)4>|2%v5HLsoi=a$@Y$d9wNYt;*9NBj6lOb!@FH5K@j1O>kpKb>T29)QSg`QW9!NriOSwA(mRVNpoL{d`tF z9<7TSHUtVGC-g1IFWWBPVN!WHmkyY9MwksqZ>}IrOF4z9Q#qSa2gjqYBmu}u2Ey^$ zNmqe#jKk9VP(UthHHRgmu?$2g4&NN?GdDN<{NYatYU_iuHNE_lOg5xk)orPaqH{6e z;D<8vTIh@~kN#ciITYL1EdFch!UNATrZvwFX$4$Qy7c$$C2%mBPNW@aV{%y@Sdg_J z=Ek>5B@!N@DZRR#IKV0U<~Ib|)oI{eI;X2SM&6lz(GU)J%x&kqcg2rqz1O-1(8{uT zC!QtahP86fw50Wp^BO;beG!pZuDy{5-st`0t~lnJL{vCEyqP4JHy|O?Qu(b%#O;Sa zT>Fz=oNAcQwPEbim12Hfrn6vu-hey&miYM}hyA}txPKo{{*|--&l>+n5{;3Wfs^w; z4ng$)NV741CDWPyS!N<+WMXAu{O1ufAuBWUzZ|-(o;NExSm`t$;;uPu8V)vDu6Y@( zJ%p*8eU;*Wfs`%{XMbru~nG{_=Kjg2ACZH9xt^`RdXs6Lu)z%E3tjD z(tRWM_>HJBp{Zq=70IYoQKfu1XBG#~blOrokGuWfm^-}n7|cqcrAEc)KbE53r>jtA z#x|8F$7kVs?z+!D%Thm8-=||TDtUn0q~WBcCqA)0TR&eVKDSg*o7rs{8ta;YO4>lq zWqhZKJ{6z%ONE8M@p%5>R0F!BIs3FA1z@NEQExZ)PRVW5|eOxw_y03N(T3MkZ`O1x!chLWIS0QX{;_|7Cc`L=V{-SsnqQF?KUUi zU6L!k6xch>zN>*}xu@e9ZeoHOL#^u@SMgB*Z?B)Ji+_?W&j#g_W!sG*cQ&Fov5qS4 zhM>dMaZ7r>Mebt4$a2n8k5I@VhOqE39BG|HK!@6K1LTGRAx*5vQ3{~i&w(vYYQV)) z^*vR8x25~Wbe5pYKzE}K)mqRVpdvjj5OC~Ss5CN?m{^jyFi-!fH<}!#eofZW7Pa)J-g=g=@Mo+^ZF+wdr3W$nBDz`)1gCdn1eTyD3|5u!rd}@FdAr4| z_%IcdW?qc}t4^%h57c^gePJy9{c>`V&!%7b{w`TjR?5 z?KHC|ijH)HPfUJ-*J5cv4cc;l-0tp`S2TMeL+*5rm-_aEpdG!gGZxZ5=4|x4N-|Q! zS}YgvkedRH=X2gO(?;d-YsYGJtu_`G830Hgua)CHQNMKV!0++*8r;TabZWrM8!QD{ z*v*z95*EFBD>i9zFW*E5mC19=fSiv8N!nj$;)exO9KQ<$Ks@ zfe#Ma{imy+(4?KeG3WX0z@w@UwOaZ3l{ZaMRKVDMc^eM50m z8V@^1f-*pz$~^MsHM;iu_zAM=r!q&;C4L@HF6cRE_mb?yC#c1vTzSu9)8=^(rJz-= za@G%*BAma^e5O zvT{6D<@zzUUs5de2TZIx&Hchjl(+S3-TUxJvazatO7;^g8@}>C5<0tCf{Z3Z&X*nc zCQqb!hseaU4_QtEm@1}$oW9;71iC+-lB3Q10#_T1zqYb8qvYnm5nJumHw~fjE{M-f z-U`zJ(NtLDMhjbK9-p;=}#;K5pXWYg-b9Pr`r2=J-qk^ zGE_fe6Q%EnwK~}SQ6VTtkC&vT%|sp2PHIps0XW0g=V{n--6Z&G8!RxlGH1BIE0~?q zT2se|uQ#6cO2#I4l$C3EB3`r!^~mL;!j!3l4x)BZK_zPoZWu&Xp8@*s&e%jJrq$!d z2OwmlpCzHxN>-EIp?3-}_bW5xp80oz90Im}DoH=^zRf$)tdJgDzBw%e-f}tQEXR`v z>@&2pUD?HdnjNavkNE$leGhqT5xmdx=R{j&QCJQR_E2VXg`wW$8&H;U7iv%p(UJ~5 zlrlsuKY6YEeT(;QJ{*rYP7_B}W*T|D$>NA|7!7G(>zL~zUp84S)tQrl1Mz;~P-*;* z`118uk?obcQ7p;~OZciN;l+VSmQUV{iwm(9WN}i9J)=CztJ;Ski3cO?&VoIbe?SK9 zEs0m7bfPB@61o&bmA$*#1Q2EQa`;@mqDzuf!PX9|vLkS%zG7m-J5#~$WlY>I0mlf| zDztiwiavxD{-HjFO~r=Z4*g>B*_=!4A(FNS%%~zb15sj4OH&U|@R6?h34!3c>@$ zr-9M|YYD1%yb%Q!XT52#dFKv429s|KTU8w1R5__N-fZq|1&tflSjSaaLydM^FLjT8 z6|Uq+eK7%-y|s66Vjpy}hU(On>z=a#MP(f^Rwp;7I=7T|EMyO&I;y8w$#ux8raF!Q zimVKu_=0Wy~`hWKsQG<)IJYNl?)y0A876Kg+s&ki+AdjiNRgzOYhJ~7++J5=xOHcRL{iI zGGjTpp7yE4ad&R${5i%lzIqHx==VdH0ORkT9WLhrq5)wx7y6c6W?ZD+T0$@6nJN9# z1~WIL>6mjbl7k57=$E>veztb{4&z0!RY`K=Lvf{7+n0BHftdXnNJ}uk?k4(|FsyzI zu1jUfk?63KpdBWOYQ)6ITj4wonJ2c8Jctkqf%4}hA|*~}{7|VAiA*@N zx=S18=5qK%ILff=2oIZ;{R70HkW+ZI#)Eu8l81%8blp7t#CG<3&5Cbj>ate>dz(3< z7il+YOGwK*8kW|cMbLUMpTh^<)~1#>;#K6Hx9EteRpVpr{2Y*#I2gJiY3Fgg4w z!LCa|;|h?~^!1$I7Cqg^H3W$z!UBI$5)lGPI?!Y?JkwM_HW-GIT zJVx;Bs^2!1Uiv1go+{34+tu|1`r6$M@ev0{ex$QalxO}Gs6kR&cQ8Ul-!2Y*JF{We z)iKNrMN|5kcaUbs^lC!bm7#!D>D!!hR8)P*N@5-iMIm&nx70A06z-cY@gb5|2%D(8 zpDzJ1V%{&@G$Fd;BKyQeI!XZ}%g$Y<+7m4Sk`JtsZ8|piZg1=NzO1c#fD8K)CZXVK2Wfz^k`yB8}$Cn6_g<9HM=o_6PTOYnBa@W%>Pp0LQy zPX@9=frNNwbLeufnKjzz)Q6gIXwZ2S3;sDglVYF>J07~rie-^#(YAwOP_Amv0191y z=IBQhX=q`j>~Y!SZ!R9QiHmdOZF#G;AIoGJ+luDhCR^%K&rG{^``42*fmu@NSpsWx zo|sJ;{D6qn60WMM_07eQEb{S+%kUkw2LDact+1kax;)x3`Jsu96Y0J{n6)K6{X#PN z5}NcF^*0uNhZmXRXtV85lP9R?iy?;+fd8F>JR2ejW0RPKE$zdp28^}N@bJ9bu-?4- zH50Et{ckD*LotKU4N;%Uz?_+(Oj8h%$ZWfJKe&EYQiahXZIg=%q|hTt;k3o;siCj^ zt3wr{;zHSP zilCd52V!&M<`aO?771<@(^>2bt5Z@J*0xxl_9G+bq60iG%K4M$6l2vY9S0v!|wdr+OfH-|ic#-P`^0A;TI84G}y z5HYw+D}9G>V(S+A4BdmM7GF055j5u0Ax`BgoP-!elMxsp`W$mkbGQ9sp;$f+)g1fj zmxY1AB2SZ#kmMX*{+DL7{204&ooUrtCLvnYOz_gK-TYIzhT&YSQxVOd~gY08ms3tW7 z37}-_grl`hXB(3odOP2lzz-EwY}ISzxbd9N>N^%vvFLW9iF}gVM7>{ky(w!Pdr^Z<&I7C zmn&5kD`hmR>OUy%t|;u$P=3P}o{FlJq`qlDIyB(%xsb$cY~)u}Cy69*#smt= z^yDgFC3~m(>VtaXQ!WD`Wod0Y;K@Hav~d&0~3|hmPdX+DM%v1 zZ)&_!rE^vlT@Vy*Hd4_WA&R2TXD&=S&hQ>xQd;68!OI^#Z~AKlDvZix-ODQTs8>bs zP?s6b6ofqL6uQrbuO1m;L?;>eb`b4q6Ua|TT`%5C^ft#FAbT$Ivihuw}*jH3?5zFLYI`bOtkOrCSiVlzmk zOd+|+$F&Pk|4j@Ch2D_|CMn9EV8yKd!7{M+l49A=$7v>! z{DF3mB6|-TE{JIJNTc0(p+=qjrvi&k`1IcJ6qgT;fIBc!uvfN5cBY9Bhp8UI&wQg< zCYcXc>q)u66JWO%+)O#yB66PC#jSFx&)j~FoO8!qgf!8YtLA*~LqCjDw!Tm@Fi?94 z28+ra41Invt9@lMCUTkvVqT{D4ULMW%Jk~&!!<)K-#PWw~Vt^J>uFyMn;CCp-==AjHCxH_?k*J zYAiaDpl1*Q$r7!$dLGg<>S{c;Q6^~!F*wG4rTcz4(Q@$s4)-&4MNAkPVXoN-PP?g=-+qciGiMz;6huWYSnkCS5kA!N+*pa;&g_wZ+9s7b@_}PaEY7wu zLx1Um`Np!W(U9%;a>x;XDBI!Ag+)K=xk3+Qf=jXu1Pc7V0o)M_^RQ~j;Ketwu_4GA zkC=HxuexG4v}vkm)Gi~=1rN@M6{Ba@sQI2PjHrB?XIZ9S#l*w-Cyl#FDZ0NBVh)nr zYkAZyna-9B4@4ZK1sfdsf1&p4u#Z{Jy%r6W*-gF?Eq9y$L1q5F$@uMS0!4U8FdgW@ z7R7WpNnAVW`m9#NN(e(qTi>lO*s*iGSed?Ydns1_ndmtidrB_v$M;;F_)#6}o7-L* zJ%7@7hm=|HvTiTmiEv5Q{TXMS@<+cC&Wbx38X`S*u!mrr>(iz)#UnsG$K66>+yINr zXCH+XNW*LjufyFGc-w)Xg;iR54{l2U3t_zy&qn^`_xi4ZCiFC#^=(?-(1vkanb)38 zL~ifh);e7vvDR&-;y>KR_akx6u(%_L@sX}?EhtTt*@k7kzhJI8T}|#}nCeU+Opv(O zq3@9laDp_8Ke|MUkRfgsp(jl|WHY9gP(IaI((8p;pDelhCL97CvAGM{t#;H<&*Mj%eWu_Z+F9tIxRfKASbZuMRpm{U=?;WgIB-ZETc}!V^>5eG z2r+u`?WvPLCZ4;TA#9;F3H|OIlqlh}MOgX#is+X_WvjGkY!geLsir9xvyg||v%l)T z33dc)$^sM@@ga1u{A~}F(|9PSX||;)L$C{H<>}tlznxOqbz9|Kbg|jD9GG@EYe2z zSw|rZ90}-2mh5H?F8AuRTAIQSr>~FP$)FKVN&3C;maFPda4W}_nM?aS%^+*~?-@R- zPm4O`Fu=m>5|un6>CSQCT~3&IiEDc-tndTTh-c_aAEbsf2f$q=JN2?$Twlzf__lNA z4<{a->vv0kxEQP_o=!&L`*lTG$^UYJ7Mh@PgE*tD!2mn?E(tm|n(fhE=aA?7BUbVt zWp3*3D#bb5sDj+4IN1Zl4$ifB zE$5kn7@ijgt}eN1&RW1)VgpEd(2#MfqLIzKQie_H#=m@caoe-7;WuN&Oo zg{&x3=JjLBc$;>}k9W@+MXJpd%Ab(#QyWu5zhwA~-Imp-!Q&T)G&mPg5SSD7Z@t=N zHf^WL%Bp&>o+=eq?@?emFl;P26C+~ZvKE^T~jx=9$bRv3M z_C8i1RzGL^vSI<`)4$v_+{>LM3== zHI+FZ+wlMlQtZ2G91$(((1KirqY+lP!6ZzI8Rml1Up50C_Sx5B2Qav8w2a;_Y%50u z!0^jDjb}&1;lIU$notuYLRJrSGDs_b;yDFyMg92yNP7n$OPi)`uzT9JZQHgvZQHi( zY4@~kPusRVZQHiHx96E>zxVzB_&0VVHcp(1x~sA>^Ugw?h*Q^&oPsm^H?rAehkElpFA1EuA`o-(dU&b_KyC_(%k3jwJ)Z=0U>Dh zqOsbLW_mp2z-@N^t?dSfG@*cc)B54?*=%rZaYhgrHc~G7Fr5%Lh?}cJSnc6Fn1dhd zexA;At_*d|3mb4N>Hh^nwStf{byL_Z{jL9OB|!UF9<%p9pFb0_kJF9GVJ?>O(QswkzxixVk2V{l{hmbXKzm!*KeZ)wzoGUF}hfhT{uW9>8@>beQB)Hi}i+2@zNLbS}^5o z7;C60s^BY(7<|JgxTRd`$ET^gJYvo`CUAVS&e9%Io<@siG{KFsE#l}=?&N~u&<;ea zi#j|Z!(x%R1RwS`R$U=tYEEMOBsd+th(#a_X+ux+$#Ztu_~2FAx*8<@cCm|XVK+fh zJP2fY`RA00nV73d=k}VqAvNDc5OO9ic6QYZ1xp^-I~##TelOpbGPgqAS`VSp^!GfD zlyD%Crv&+dy(}tsSd`JD2EnuTYVN|)rS1ZU+ z@wD&Pn^!*agckI8d#-0VlmhImyN=oPtXX)5h`@7cFd<&RG_-DhNj_QDkkX(UNyoRc zhDcXB=EIr{m|Eh4R<{szgGmZSKq3UC7>_l3`hwr3wsp&)b9&(j=VE(>1f9a9F}1xXy9RJorZr2~ z`dn)(G+1!3)i>7@N!=7(n?K3=#51ETb)-bd^~tQZB)uN?}V4#dVhY}L+ zkKMa(n0514c08{le&1fYTu++_-wJ;A59pgw~iWV-Jp_6U>Mn&Xc|5=lYwrz$d}M8UVfjwl2xv2P9+o=uMB$J z-6WsG$z99yMlCyG=Fu~eO6RBPd@8J|yeu1;ms+=Lg3o1?v)EfUMINewLg0k`!Pv;u zw|?d=Sz_&br3HKQMxk2H1+mh}O^2~)fSSZIryf$Lw$`Rp)1>I6d2TVHRz zO*#GuN(!htABSf#)^t;S5Gf_X2~)Fi)?d42(&cYh0!WGKGR7KzhtGqVlq1@qOt5>x zs`+ws>MyFYKtrp;H2t)YmFcqG1eQ#$!POoD9uA?UL6 z4WqEsx8CCnMLhRP;Y|Ja5(0qf*)s2Ky&a>qHiipm-V){n7}I8U%&aPsI@`RvzzjX3 z`=)X$()<+>rGUfkl^g2^x=xMo$q`7GwQ<{{z273Y@G{}}NjT^@62j~yy;c|t3IEK* zDc{?=H3r2w)j@&!wqh&JaDR)(FDd5~_F1)#t)E$)L9KMz`&{D6b3y5jBkn0C0E4zZ z!i><%NeMuFc5jkoH{#aoR<6=UxEJtbt=7_E8wZ1uA3j=1Y$Y<)nsk+#<5ut-u;lC4 z6JBL%L1QF{pr;vEV{G~%N+$fUa5uNQm-t=`_MHLY(W|u#0u5DU-^2NI(8}NTJWQ|& z=t&W20H$wRbexzv2*&kJ$EnM(7p&0rL?Y;eFG63avO8w8Pm!8WRI zuLNK-ZYvG}--G0p_~LfnQpkv`%e%Z6vNlyxkPWu{57oq}wC!>>xJY=UySy&;I_Q~S zOowq1CsTCpjx$Dw&YU9Ile_a4iS=jl?~W!x`e}7e)SP0y=XT%>!Xjs-qHvD%Y=(~f z1TP6gYKPZ9WZ1u9I-=U|DcZQzki!!zo!Ei;$d&r)7e~&=Q)i4`D%9Y+%7`DY-ro!p za_SBA`)0G23ac2ujPqv1Q;fRZG53T;dq|C;Z<_k841(|)sNQ1+|mh?t1 z-86<&&#b_wlBIwk-Cnr5vmj1*7y!hc-QT!vsmhP1Rdoe^TR4PsA^6=w$6zyRcP&2( zKKqN^QFQwx?)OT!X;@weiUI1<7bDL^%V`lF5(I zC4`0=_E66(8)mK&EWf%;9kWKc2=NG$a(zO=&qO( zt{Ne7i{_TrG`QGg%nwI0ig7iHtPUcT=aFX^NE!#Lj!U9?wb}qE`hGr<>FKC#%y}W6 zWGtFx7v;0a=xUs5(U0qQQKff-KiLN#eof1V5!ONHU&)8w4XS@o0H>W%O7$mEODCoW z!m}lYKdT-W|623pC-N!wL$o`*f*Hn_j9ha4mFn0LC#D|wJIjI%#f(mEF~Zk`nG2H^ ztCh^E%q?wQE`6;e(L<(m4nT#1n4B3xl5?5Lkjlho*Q-6R~9WJVn)y9MHyip zXqFy-GSEeYJSKyPe8;4fl}m5Js&aB9N#J=%p1DJAodC1nVg;R?rFMAZY5)@uVz7MRejh8pjhA+_j^TV zLZ7lo;g63Zg`Z{Q^XNg-Cjo_t^S96}Z~Kh=JX4{18O=jTiJ2E^+Kcdz2Cn8vGEbU< z7uC;gp{_5iSVQyyj^O8!iZCj5zk|^iB&!XK1mD}}p&$4a#V?Eg)yE|Vyo7jd=V^XZ8F}+UiEQ5i&V7Bq16y>;9 z(=;IMWc?9VGkhjQDMVVAmuax#L$8~4*8^SJ1`FX%JHqnf*A-8NJra)|wiefSV}OGF zN)wagb@m%Qa}F5JGGDZg;}_~My(A;+qNwd_wIqKI+q~OScTu^8l9S%kt?%9s;FZ>c ziH!v|eP=hye(;SbGibz&M28=7p@0V9>%J~+Tsmf|DwsLbY{*6SRQTlW=7<;>;ooaF zP>HVh_UbxT&r6+_WEaGv;YK(<-)q`=fY|3pRtSufKH{Xa)%`XhLc`c*Vw=Tw)h4w) zgY@Zib6=P&3X?qQ2eHK7ZPARfPT0bK;j?X*6Ue*}WqRFle}bb1F=i%m+Sg2*Pcs(@8Sa@%Z*W%AcQeQh4JsK1U+U6&7Jif1WXemk(ed6dVgbt_ud!FwGG5|Wp<5rRlFbRbrtf;@ku_z z3`C!JQi%jt!O*2f_z@|dXGlRme^9W!&>M~z#9L`v2bSP(QFYYkp?u#F=(faV}8 z=E$3h!?e((fFHOt#19JuWG{}_qu%F1M%m?jqVxujCl;uNm=4a(P8~>6xC>Ve=|as= z<6V;2=ji&_LJtvVH;rA_@##jR#GC{x$7By zAsYLu2H#7~T}&sJ{C^5>`~rkL7m|*>I_})YS@5{dZ6fr40WiU+h`YXl_MFIQdNEEi zkzYFsQZwvZ?yd|8P{S$1Cp`j$O$N$@|3OCYzJF8oMyCgDamP9emHs}kgCLuoEY+qR zj55M)fI2HAE`?KD3gFQ>m)0G~qz)(a+Re*!jJGAIL)iS+0g3ZE}#+k>;pT7YJ` zQ-QEMYRm{JiSsEbeP$;8d66Jrc2Fnr1JH<#RLE8&ofRa1s7Gbfp%-mzT9Q-G$clKi zjVsvXfXFO|9x>)3d-mNMK9S$k?)}Qz;{nL?L!H!V3fFFUStx}YhoF)xkQBZnu$v{x zsA~WUnQ#qsLK`x^VYZkzQgl&LYs-PRR&y27L-wOE0^`(Wvn{_W zVFi>OG;(C3sf<;c6LV;KbmbS6O8ekk_9rMfJfOgM@0E^HB|+JfbsazsQ$(SKaU{{3 z{;vDTFGS~fEQw~6b-@ZD*)pxY^h`A@!FQe67puoS+1Vyh7DihUb-94>lKeD8UdSZj zxNI3>e$%KLIZPFPU5i+vFk%EE^`>vu>`4(4b1T~d@`adcmC$q3PPociwZ;RySV!jv zF;Lo>s9%6mBdO6ASeXS`S9<_tT}Uw^+sm$KIgvB@@q__;i6nBC?1KKD>p1#MS6H4l zXjf4Lp4*mE6YT46hS&9{hAa|IDG9#gk1W~y3A$nBhTqQ5ytnnWQGK!Y)A6N5`_3?&FRm=Mx-GTDaMfg-ta!C!H58QANqc?~lnB58R700-xnYWd>z zuDyvauj){mH#*B)Bexr$u*Y`&FK0fzHxGVIN!SRJmO&6`DhBY@cO!6s#KxQqpoQDZ zy|f+9GLaY22zt(O>&Hd;je0$W7Om^4`DaB6+O9YN%T;r09Y@Q-H9D(=Mqux&IHnT- z`$iikqk~qDxOHh~i-PSi_jFWp!Phq-_xKQo+OC^HYOowHJ-07UnTk8LA2dgdM46hU z?zABEyUfs>P_&{x7A<7{ezw6HuXnARbeH$s;ZLY+e1@*ur!?!Sb ztTDJ@lM14K5iXzd-N+rP4oGNL9F^@oZcZFW&GF=thpc!K46RKTPe{U@arW6U@DMJ<|)w zVM!hH&ex^FJmf|Gi=M%sGzZv>se#HJIhhLQ8y`f!Y$&9(BYW_>!bg@#Zpl6cy;I-V zch%{5X@yqafCo@_G!t1gwR+nG{MB{B4+_g}Ug9^m*oIA*ad+e;67VT?C_VJ-UCEER z3xB@^2+1916?+v%i^vgVp8}i0tciRy z)5>GdQ47z+G)b%NA_MCn4@NXyC3JjKE^DIahug=4*EewVFnRZj&ic9-xgKxA2FTp4 z9hMg$ciBPwBB2zi?jVKm^NA85uXzK6;t?hVovzv0bkq9ODy26=+0xXz))+c`tax~e z^XqhrLiPw168eJ}v|TKm^L&Ge<(BMjy^GTX4W()`^ep$V@VTM$>dO=gn0870JlR7x zemrM%4EH-*dM;#t3{=ImY(@Vz)ed`!9Ziz(g~5UxGuE1lXrI2t=%t=t!yLzjj+*9Q zSkKjlFU%vPSdO>Teef4`z#{5Awt zLO^uFXTLh9>K!l$&8xZR4_`&OO_TB}M~j!>Y;A<+4jws8dqRY{>D-w|I0-%j20D)s z1nLiRLnq$!+u90LoPoksoqnG|SnVl0I(0yCNdTutmh{q9=XujoCR}mn3=tkGZvp8P zTwW(H7n2b~;kh1M#8*RYrIe#nyIA`quv^q>vslsEXb@26nF@dsp1$XAH`&aF{GK#p z6Bh|bR<@@fl^;Tg5`bdZ9HnhMa_%K#@#RI%5L0-7*boo;{xfZoDIKKl$NT8OnNGPg zokvE+_O?^cR6N9o%o+}H3;PJ?L=L~xc8d4MRDWwDR%i~n`pWw(^`Zn0u5SejhsIzR zTmuJk4sXN}a0nO36IuHWzFJBXQhue&F+v>CBz@r_j$=C#xG{9T670&Y*l@v`lw{SVsZpw*c zVq}BN@tNrzHILInkV`iTdCmuBT))7O@eJ$Py8LDU}EK1Di+Hv)8hd z51P^?Tr;%PIleB;nI>(vpycqaBy@bVYHy!4aIYrHYPHKG`+~~{fkp0HRySDvv?Hh8 zV`j*DX5e_OOVIlfUh5ArKIdovo1}}-%#kX~J*(5s(-lwpfO5Wtm7-%8)DzK(gg!Cx z)x$}jgQ?}8d8Uv{$UYC|hA#2Z47l!Y0SV>|-Q%x^oP2bIY|Jr6Y@ao34~{nI!f7?J zRCIKN%EztVILizNjMy7PcWNuCYr;rxc1d7do2DAedUbQzo)hBzT1O&!I9P z@~}c?5NJ%(Da*0Qx3~9#LCCR1&2t_WT{3X>rz-FMicf~hH%8xdOm0u+^CCS!X_34I z1?qaDjY+zj`J=T5Srf~72@>0O;CGjWe)kUDeclATegb{)A?O)cf;zc4R|9dbcK5u) z-9ijR{-2>a|KX!ibTYP9`Jw=$`-6&=)wedLQ&SQUmz1Cql2Mdqp#P`&i?GW03*-8i ztLuxk%G42`m7Px5*wOG0Wf%=3{a-P`KdfLhtc+hRUyxr021X`)HWqqqI)T4(>@4(j zLi%>%#^$DGPWXSG{=w<~vHM4rgSnlPtplBelfIR?p@5C)mq{89T4vV&q5xz05A;}+ z8K05qAO0^oQI@ajKe${vQP!{OKTupcQ8s+WzXV})qU>MQe+4-38Cd@r_FroMY4{6m zQgk+O`omlH$Fnbfp8v(QuL%4@FhnP<@8~3Crtk1YU&czOYHs9Y=BUZY#zxDI&q7a+ z&(6d|`-N8epBmdgJ%9U|*x6}0@c)*7B>tDaf5!bs&!7JPFW%aZ~w*52qU+qk+e@3vdd};ev{~vpQRsucapWyss{_ByI;g9P7yy*X4 z`_J=VWz5XXw9Nl1{#$3F|6}Bz;QV9m?}&d}|FQMA<=?6JN9I4$EdNL_aWH(n3KPd4 z-TzL=U%9`&{u7|Tl7Gv8z4)3GhA$Sl|7B+Wtf&8fpFgqv>+HXA{l_g<*8hq2-}(Ay zCH))Qf9ij%{(WX)|7X?xeT9F@zxw``|4V@WH}C%hhW%?*u;Tyc7604DpMDPdKdXa* z{=b&P|ICs$-9M*>C<{Q|3(yR|4j`n+J5PGYF>yudJB*Xj$b==@bIA1^h^ zU3MI1sMk%srLugQ$joPZTpU)ucAS(pEl?^Dx|3)K7-|aTq*O#9(GcMfq4BGU#vyf! z4*^I?Ql0@Y+c7pZATZc{a{xr=;J^S3m@EPy1qC3&LSrIBqavfGrr=*%m|X8!n;VDV zCy;)IL*wF~#yrxqG13EyWw2ue()fg7V66T|zKod)l(}{c03bj`<+sCUV-HOJ4aXmr zmfw(5O-)qPucqb8D!iG64Up6)9I*rzk|w}wmyw}q+ox3v01o!210eZ_gTl8D1UvS0EKXApAy2Qj^{`X&S#pvTMXP93T6>Fbjn+q$G%MeEZ zu{A89oJ((Q$}mrK%osT}Ep_)@t|Xbzzs940t)(mc0785v4x$YXZ1@e`9m$B8{C@Z+ z5?y6;P7gk95`09TXM^AU{vFO}aWePmmHT-zf|at$PSLjdu6n{Z{`m{z)AZey9rnNm zfCiKk6m+m_uBs#g zsDYjdP<0)n+h>(13YMd%X-)ySU!uRie`fq~c3E6qAkg&Sad!IFd1lRL~w$N-xGLgpof4?{%_ZNFkG%LindRjH;^X=pS1&x_W%qesFb824Jp#J_!n5c$y z-sVYzl-A@7;CNL$nh8)5ekqtAl)8Yr1#NI#f;aDH9wW7jhDtns;7uMq$(EG?W^2;d zu$oBd4||J?U&m03d+>h7V%aUV4?@>p5Ft!@uwfY#=JWd-xLC!+o{0bRx%sM==*uwF z;TIWtx1{16P&#%rr(P@;=%@C;cj}^yDWULVj0{2_Wz`q1-~GTsZ|!(_HzlsqPAZA1 z?uzbWO;0@Ssh%1;+zk;1H1(>d@Tcf?;2}{(F@oYc%u3VjrlB}<1|R{PI)tzLm?{l%#sP5Zg`de_k|~G%wzDN-*Y9H3 z(hx8|wkNhM)h3fyR7|@NA%Ora;O6jboYnGmzFzs5jpc{d9aA}@nYeQ>b&y2F21bG? z=8<|f=iuo6%pH1I>b>r}e~eL_T05w86oJ?B(s_EIi+ z1uoxh^lHrRFt+3P>U3qVd50qSKHKvJZ-yk-(#pA?_6N00AK48fwQ9F`g^3& zwRCn21eB#|BHWsnGcR-ZS++hBUVfJpQu4tlK+TqvDggImDW`d6$x@?^l38g2b4u%q z)fZp9xJ#gows+CC-YgNtFD5ChrbFYy>DR_BZx>2A_POif3j`HtBlx*?h=U> zF_wU53S}NzAhOqo`3Co{V>{UhT4laX?5zHm6zY%xOPmyvIF@lb1 z4v&(J@bswa>+fhwElRd0qXs)81Nuj?AE5`VHLQtVXAnPqsFkfri(;Ee0O(h{3kq)y zHUz9gQ|@6lT7K(0D5E9zXsE?{7Ezo0pjgaoy-lFgH^yO z|GG+eOCFFqoTAs9&Xsnfx~>j^;Px0bjj1ojl%1L8w>@UVqdduPkGSK+yJpP72!r-L zFijTkR~|AOW8WoZ5h6)7ru2Sr$-3d>Ln%@!t_lzzzN0KY9r98HB5sN#(h|;U&Xchg z!5Kceq1|Z08A2p(Wu1~xy>x96jTRC zFtbyNwJzqT*_fs@XE4tl$Y4Qu5aiJ-n9i5)c@II_OEM&NeX0Qt2`qLN?6c=wa8W{i zr(PhH<+99FW@gmn?nQ1MPv3dBd*$=HOS_%}!B@`|PNsL0FaEdf@$H zO^pVJR3*qKd>zXJJnEaaAW4Ia3`2B8{GxTg_#50Ma?Y%Nb#1~+kac2oh4#{D5oal^!-72+p|n;oWwMGNnOM~h@=C-(voqO90G zZOaOmJphK6hrIPV_r|Vl5Zc3`Dpfz@kTSgl_Sgwratwqsasu2L`wX5pax4_=Et^BQ zhJaQ?yq0-xS^!a0E)Dvj71uMq(8gE}<>qZiv|KYD(d=7AI>#Th8!(dyy3= zdOLf9`>R-Bt{r^=$T^&Vw9S;PVjrEEQvu?UIlvG_t(UZ6hYLN3JN!^p6r#*iNQbKP z%|nkOiVw5d&3j|T@;rVFJR}EG*#SN*&ZpiiNch(t#y$gxRtCrl)YZ}xj=&*0O8+2@ zCvxwQeys52X+j=*RFka%^IO#WpnX%yJwzK5s0+KVx zYS;?G9DM7C<6_uvXx&1CL5%JFbNcWl(h8Lh!YRjJTzL>>$I-jz-sOpv4^&f)HHz1( zcK(O95tSxEnW)VG*v_>(MZ4I;MXKr1Mwq*5s2FCP(E??}C%b~_3XSTjI-92sfpzv1 z$z&HB`@t1gY!pgLEfU`M=RqDnaIH7{uUek& zSo}90{W3K$PB?vT;P~=^;M0znk5Ce}@Ngi?(^*~6l+F66GOZ)WZO`xlpPk!a+|KB& z<_cG0U&zUp7DTqh2|P=eWo(;8k%3;yR_0X(`D_Z3B|}s1@a{WRG$1E`Hm~y6$B69U z45AOx_D5~5Z^)^yzcx_B1Q?RMM+gOFCvv@YR?*g6Bq47~k)0dn5+`m@DBE=}ekKK< zx-4qPVKzwsk5#C5_IYYs_9ppuS{%0(8)&k>Fshp){qu#HZ_IiwkDMA@1MMlU4X^3wm_k)`RPgFORoweQu?8q?Nn-TP5wm2Kb$Kz z3IvNt1>3j@84@EiG$>JVBMj$EMn&@gAYBW;9g0I~eBx|yb6chUc?Xd79XpLCs27a) zJY7K3=@Kl99mSQEaMLw?36{34X%1(*cuH}gT6t=7_X=qKPGzGkGS_{z4Clw$=Aa;l zTBc8#p)|pE{gu3O3pVz(G*;1>)O=vRA3bI*I$AoM@*oN$43B;+#;{g5buv=E15IHWzC0RIgk8XG@}CRYo+A8 zlto)%FnG5k>ifPyD|qH8Yhj4J*H;S=SxA*gHL=$q25jo>zM})OO9@{a34?uD8`#Mj z0-DP*09d;F;9@Wz&*{qRCZqn}56Ca6_Q6N1>*-{f`7G{2=MDsIR)u2OV3P4$w{NzW zN=0H8PPt3>c8(Da($NayN5-Kj>2>*NJ_ZS-;?7f{UW%m_fS@=aButU5W-l*DXw~nu@k2<(SZ@TD z0tfCi&J(|D!4apih=Vg7G-9aX?i<5i@s3J0Jh8SLgY^28qe$tk5Z9`ufH}w`T;b*i z4{AV4to0%H*-0l1%L7LfrAJv3A-HJ;)ZslPuUv44IMnAQ?)z}{;2aI%i!phPqDBR@ zkH>twq&)eyf2K21qISEZUkB$59Avu=mGMZ><@rqA^qyzFQTagrhce!jaO;{N2V9o~NE9 zI!L};$UK}o>|PLF>UeTL6FW!KZyLk!=O_b4svdkt?9mXV`1_h%UCR4J<0bH-w9Qaf zy=NP-+a2?Y_}jo}wBN>3SzQjPE{|AzqF@3e5z|VhYdncMK;YQ@pxQui$zxyuYgih8UCE`B}&;RseC$*bY)e1_~5NA%? z7VnNx+nHv9C?YihX5?7iT!muLoCZ)l&6GkgiqW9na5g_Eo2bRR^dPrWalbcL*X=P;kHOaQCDpZYS@DY z<-ET5+dE+)dI>ia(C)@|Glm3qt_Rkunc~@uHkSZq{rSfgPKRm)&4#sr`GAb21cyl8 zBQVZe`+8l)I@I%dH@~$)tk9)H3b6?3sGX3Kz2B;gUGp%z_RF_MokE@&3kOqMG{nH( z7GehKk-Q4%BoGzO7eR+|(P-{<9|qVh5I`Z46945|8J7x^ONMelDi8a}7JHNIqfsjM zNPmwC1(c`yMq6RH+*A2Z(+%S1;fG9cX6*bBfwAgmdxr(v<1mYMC41huInMdeUR9TU z4y>WpOD0MBM4aF}&Jct}tJ-qEtOyK!R)4PJbnD-3A7Je6Q0KWU7mm3&to)xX&|p@O zAM$vS7l`jCbzzC}R#>k^hY;BqH{%F_GNZz4-*dpxMS?AP_g8J#STE3v_BpiPjs+wzi`W(%pIDtpD%BM6U8)%`ny!E12hwnYZ?G}kCn*gNqLU5QE;oz>Z<&?S3@yLRC&) z{ix+bxn{^?lV1IVW~n1hBdUENy_^d?W0238E@y_Lzf*MAC`FIb#-j zgLuq$vxETpzTinKt+u_j7B)oZ#`u2Umm}OHQIe)OV5k052N}6BcTC=swhy@tgl`*M ztcj7GU*RX%bpqsp6S4CVGq42YUB`^fL!Az%d!O#Krk*R<^PUFx8QjN^f0%b4RNe~2 zhVwfx<|jLtlJ+PI9>VI0o2jbfg|&r^F?#doF#F*52k)_mONv|$ckunyOAC^TXY ziiGi^K~w#v$lKCpLo8&>YZ=kpNnmO!K@n4fm-{h91w96rIoOg0)96G}BeOK+R^iam z9jz=pxeywGS`hu2B503A%#?EK;8xhMASo${!fj6Y=|iJ=0XyW~rOLq!aiKl;hB-iP zs}6MC(b8z~A8S~nznVXPAeO{82Ph;-6_k;Z7>r)kE#!N%qVVL>uhm<-7=)6>dHas( zTj%2Q*!*w@xF`g)NYoKH@JuaU`kq@BucAX+4*eFxQaMourA%`_9j%#y*|Q0Q$H;c{ zJUyao=yVgH{kYDU^1jXToiEJ*Y-U9}x{HTW@Q1SfZ*MT)8;hjiRM^8l#BjC4xBYnb z6R_{Waf6_0vR2@oV8NylX(#Hvvy!dR=Sg)(d!PeYpJ~6GgXT~BxP1dYv}VzZP2nedrmP&u5hCJVW(i|v;e-5{m?4!0UTS1)>v>3SF6x|!k&WD=ZwokC&u zFX%#_ zjk?Vf3nq+Nj4gN0Q6wynF=(`5PaY9OfaUBy^-T;bja!Q>m%Z^_J)GliU;+&$AIrZ( zd=Vq=nYa|AEHR%dLAN^VeNYgx>CFP>2f_s4eJd0DrZJL^w*Q-$Nj5v9(TRX1zFo+l z;BaZ-+|7w8RBeJ*A+2Tcl_^udzJ$uWqs!sF{Kcd@v;+=(W20>(~Vkf?wz zh;mG3=#>I;^%d2?wUkO+xq~?nsqi>}plF9iiRf*kYMg>W9&|CL8S0>c%v^w7WOdmB zM_S@LrccoriWW3citTug0+YiJk~xl^^b~Ogv>{&4J)0=KFiL!aNv4uG7O$Qe?xW5` zC}AA8uv2HLkd9Zk;aiVx-Ot)hmsz8P*&HM?>&l

kCyrgGSEk$DNwSOU!jTlK^l6 zOLvsv9YE1YpfiYRc%eUZ7Fm;=!s>c3et=2EtfEEKwgaVI2tv8bD+I~Fs_}p$6)WPSM(ea6R zPfAWcFX8=mo5o2w1QFBmq*OBR1HbuGSocsQ;GAo|`g+VsYeC{}P!g!#aa;_k&ue?D zO_RFVgyq5ScFi~*YEduIfxUvjlqQwdb`$&DVcDMBfo)mCADY16q8c1=W@8hta~>&l zt~&vedl8OniehbO_v@!mq3kn_Ni#D;1%VrLgXwY@?Zup1qtsMYzfi=u(x%XEs$H^k zHv}Uf+9K#PP9#*-Z5Ufg*0)!lzzqEy$ONZp!TH$6CjZ+$eG>Cvl=9DXf_{D=AwVkr zlg`uearJket)7TunS*g130yjA<(m#pk=56$F_%Mg**R4XsFlMFR0=#Xb-*4-DW}jm zzn!43EGZELjDyzEEM1K(di}ZtA>T2j>Ca?S@I>p(QLLdnDERrZkrp`_`T<=vxxC(8 zOC;~KMlNV(yq>}jkVY;-229<)uDBk1gb;w-e@8fHnXhJNL*c;#Gy|(tyyg%K>KNP) z8ffB(fkmb{AEXO}A6ZENKl)Wl4hN2=*6D(uU_gx7TBeL<^>O)aoBg!7Ji1_j$lONk zPD{?r7L%QH_%2uc0@3weef6xe8s8!gdw#b!NDGoUd41z}xS%X&eb^j6(@>NxiH4+$ zRO7?ZB37zWL3`l=rq3`KpG(X~0Q!@J{lyC)vDEo18+sY%a`J&IWwa#`RZR?yj96Q*`JoKEtd2B91lZ?pf!-9Bbrqwn)05gk9w21Y_BNfWjEZ?K^*iYbQ z5bFo3_YNKiV75k2>NlPCm`t}@w@dn-6P6ewg^D5HrJkTz-IZmBqoX2-T5esudV4vf zU08g6+n6CVcp7PJsWHQ6s-Jy$W^Q|M!6^1ErE;A-V6{*l6k6_m*Ua;oBdKiM2@kYdLLQ{X;j-}*K8f|BN@d@>HH}f1<0TZ)P z#gNS{D!=!_xxR0>9#r^IHH%O2q1|ciu7h}hu(m3|f{$Gr0S?Llp3HVpP^ic?pgIS5 z4Q;e66Ee-4&$B-RQjBZ1X08a8?>UG^cceJMY@kklu`|Gfm~&X zd1*#ITK1HT1(qSon?UUoo(wgwn&vzH7J7hyrprNh_D6-2h8Dxt#AKfIjV$Sd1cyLQJ6 zoMFxb?_`Q@i6^IJbU9uEdpKg7uNPJOtLTq+amGds0+IWOn&;-NLG7$=e^LfO<5gvJ z?|W>?`P$hCuYj)|9l_XQ>!g(h<~;>VuQHT-nipcw30l9-^bY!Q?-08QPMbW=BlT7* zo7UAE3UrB<@k&u5xN=$BU%(VM*+Y%?URNxZJOjwVuKiAO`!!*mR09Yaa;;z9=oZ06 z>5iO_mCrA)nxKx6s4^0HTY*+1&~k2~BG;?=R_H?M6u$6vxp8YLDjWq@$$dfL!oD5x z0$+gzYp=e&RruFOfPY+}{Wb!px zA=;m476*4Mr}ahx)^nyclS~d&t1BSESYl4RXK-uL^gJDQ%u{80Dby6U2=VeGnl@$q zkv|5QV7hqZlgmZ|4wr?ClMh~t(4z=7^D8- zg@!R@2v?Ua!RmPSD)iAXHr{IOJE65Xbe@I1+}wstag0mF0n}J|bJ$-I=cvtN`M_bb za!h6=xfreBHAPHDdK#(zIl*Kb!2o19MZu7rAKxsJOEH`WPkX`6=|tbXwJBz?rKrYap8Kv8F%3ou)K&3a)?+A zglv2kXz6EGT})CJ>OjiLlDi*xh*1U@bs9@swkx6ZRq3;~EH!FluY7~1{n|BcrnkM97|T?4hSDG` zRw9v|xlqtf$2S(fe7T&DYNoI$+>C45VS%>Ak3GnEQDFdmOrKS9-lA{F8G)K!WsYmK z4r&7^BE(G1#(G^DjZa5d6@}f2R>5Bo1x5*EKA#cI4Tn$GY_H)!llSoK>htogG(TB5 z4q45kskc5t-(sw|38$^itU5@7y$B_(=n`ZUg`R?VI*mv&I|_*G(<>hDe%Wau#@m&& zKSga;pBkcY%)gCrwk1w&kD!O0v#zoZ6FpXmwWR{vJ1fjFC|MBQL&|Ti2MWz^ZrE0w z1bVkNA?z+DLZ|z#wQCcRboP1$)KKUKO`lcAK?Su*cIZ+sHg2Fz%EHJ;!WB=9<`e;V z9P}6wIbF^1U~sTK?oJ!Hb%+Af7G4m`iATQap*H3d+L$UWvD{I>K1<$oT!?dczkmUJ zM@!GNq$TD&p_*VsG1T`EwQ`mj*HgA1m}#@1H+WAitHA90dhE2Fu}7B$tc%q-XjNs@ zG<_m&bWj^?>4Z6j1iJ6TmvzOOXtfIn6Ttv%%Mk=8qp2x#DNhl}dfHF6c zUb94I*4^{@;wCu{*~r7RyHdSl-#!~o(>1wRGvopa_L0akpZ%KRLYj&@9tfa(m*@!(aopy=wW~R}9&%T}gPfHiNg$y%-PJLh_Smq{>e<0Y!>gA+(#w z+#6YGrMknKtQAUPFuNsku;CS9!5!HdkQR{c{?^``a}MV{=f3y8 z-?@J<%$}Jw@l32|&F_iSksjO9$?c=yqf8@+$iGT%wWE%E(;A<1*&dx}Q^rV@QTaX1!D$mo4`qOH60{7tt(J$hckFz+?m|l*`f-i2xYTs zdlroHM|b8lXIaC)^o9u>ziZR-i^>_y5;LyaGD5eYHg;>MkK(q{5{=sz>_f&)o~xpT zd+6fiA?boT$zS4cUSe{ZY1esZn}sG^RQpjoC5y3&_&iVm^95r7A9L=z=paMtz)KAWC+2E~o+2O>EQtTxSH-oZ1j9vG$?oVJa&bR4c7!XK>cde`2*TYRkYaWe7 z#)oJ?JmNyd5AE}d*k4=%cdFmtgXl< zbtZxuY&ALclZRFm5!ouMwN=y=q(TpF`% zVQo=kIg9jSR0Dq0SaPYCeVS4$b?kg}U2nGql@z{F(dASCkLkq#igFT<%hdu!-_HAV zmSZC(s5+tMPjrO`Sx`Z|T{;pIQ*Kx=ty8B$GR&wyb%~X6=TVUkc6W$FoRUi{cc(R( zG|uPC&!^4g7`yrj-se;y_9oJ$Y`oyzRl^rAk4`Khd^21yT^9qR0XMRyUT0~{l<6zj z%JJ;r+o0C1Q~-@quF_n zC0-s{O4-{kg{I3x=2yijk(`cRKY}l2s}1t!;Vf~EqNt2q{q-h#;M(y-Af$8%>jYPA zX|njoZUwb8Wwp513$&y70j5!`{MtadFLsy)tzFQD@a%zKQ8|<*0;|<6@MNtF2|ZPA zOs$_~D=XVZ=0xJB)r7dY4`nv$y^+gam=h#97#)7g>Ka?1HcA%K@*6&|bYMewhH`|=;+Bywig5Qrq*XlO5lQa(hJ zQ!aic7N&^$!6R_aa590DcI`exT`*T(N*L6fOj@Hta}qq;@6Sz_eLkD=a8`kWB+5Wg z#2L$LZ1%xArPJ|uYKCr$hF8Vmo|4ke7=w;C7(D2#7etfSrwtfj&F%l z5Q}Ic7*g*xJ;LSkH=T)^0&c->Vx|bAiOR2{vDJL&40VmQ9&M956e;v&nbaiseA5gi zrCYHqUnwooMXU8%?1!ti7&=(0m~GIC_p;D?hF*VwTVzVEPs1ykF6GpJ6w;KxK}&zeFI>hRCBZcoAva#j)&jSW(g-p^X%g zb>6^vMC4wZt~l~FYowU*aP-;;WlnTTT$^{)aqyM585MUvqp~3K+UIcdez*y@PqFlV z7=pD$W_r)tO&wpm9;h_T^`xI%U*#dq+~Qfu#?SPsVmzN@Y5e?4oWv3(furhj1r(FPIIld;Oe zVsUd!90umQ>4?j#t-yEWNFOZLD{!&Iosixvz%g~LE;+z!0z;eiYaq?U& zKXx-feZU+?>LQ2K-MWx)3f;V%I`oxx>^19+k|R^9*N1}g^?6nutQj}|21h09D_S}+ zlJEe;d76fz9i)MWM60-+>BRXVv-;3mqjFggkFMXSN$<%l;ELaApdudkd6D=feyqL;m_1a1hM8L()nUecCzl%YQ=Ll z2X*IWTV;qvQsGsRpc@}1;zIpc_9S#<2sLmY!cTxPjg07e1kG{!_Au0C)|0iK2O39U z`g5ip{p#Rb4dO#+<7qk$Efgb^Q*^6g z`26**se3_+YpP+$lnQnS+5A*X30}jWO)2sjjeI=QDO!Hy8x%DVIJ|`Q*``uMnWdAa zDW|q&4KM57pL)D{a^GVwa_&p%k0Ja#)v}hU^g>tRXQ*DDDn05@R!GQ`nf!}PRZye` z(ROcUxN{t83T8eWQtJ$m_7|{rIB;~qm`r~W7}j{e{KNYGat=R--LbUw!sF!9k2TP{ zDmEUS2#&japA7Dcy<`?~Xu;yH=}`8!4k}XLL-3sC7*&YjgcM=cdCY+I3h9CM zUg!y%w1RA<7{K8xSvX}e0+_! zqwf0#wn0-I8_0xcIvB;3IW^7BG>6unr%VN5kAhDC5%g}H8#!zVBH1}G2hU|;e zzPc)Pc&Jm3KPVOwV%kQ)Lp%0upxvDnkKGZXorpaw6`~DJ>tIoyPzl#7^Hdf&CIe<<&^IaEwnsvyp({r(F^4oe&UwnKSbDS-!!ns9SI)>UAx@ai5KVGFS#*I@I4+ltg%|=i83vkH0|5Vpg9lk`W4Fa zC1qG-M?kvSGxMhYH5U0pp$(^4IE%7l&%j?4_BGhF(-jqO6Blmw{jP4HZ&YCMb)iv- zGwjMxiJ44IZ|*rSlMel@iVY9QL)?F&RKg4KS@*X}C4Ag0+_y>?eB3<$BhJeYsK=0V zfXi?Kaga6xD7;nLxSPwx0f_fQNVZ554sYv+ z&;)qywsuH4aLCREWd8mrIEe>b`CT&nHGVgR8>pBIs0GmL0mpcO`Z(DERTQuq1Skzs z8k`1n_P5Enohl&zkCNQrd@eRXBL`4k0aQ+aVE|JFDg(}e3;+_pEemNG+}5oI&0lBj zpQ)XIo`z5v(&byK0!;!6LBKrzPCoEV+~(eigVj&Kzqx_o04o(V9N-U98zj6#A_&?3 zMF^SWTXKWT+|DU@z9A#$2kYjrvw@ZbIQhz4&}4fIQsMYN zYoUOAJKpYKu#y}f;64#hZvm^jsH#e+DJX%e=DDLH$8)QD23C>d`d1oqfac4sh8#bz zBmR+w9NS&x6;R`l{@yCDaB%Yjnt9fCF6K`9tbpF0i@BsZpnhX+c&niT?3+8fD;&U% z`Io9Iah`k{7ld82(y8J#`cC@GEM~C=t}IK_L5@A2I4y83h&at6dsGvmWP`qANfl0N zymGRo61Nl2Q^N|>U}3lFGgoihFor_z>B*qHKtWlU zRxPCTBY(Y)?PY?2qbgSDN$ zkI~fc0Y3a=D{?gWU>j>_zDG&Or-A-%lo|*3%by&+n3#;<>CRYWSB2--r z*+iz*AA9jci|Z7%AFX|%O`>UM`Y}7~qwz?5St#gJUL-P$;20=Jx<@!fu&^eGra!bv zs27_;O=7kf189+hpG!^``Cetud(fd|%D%{szmdOsa;;~3RcV198W02ZXn~E-AmZ86 zd0%07U)LlWOoi5kFn>Qz9Eo;Qx=+nP&77&}@sv4Sll8gTWqn5E%=bt{Rq%YyjiVmE zIvsjGG!8Qq+_vCx4sWb!#}^EPRb-s(ch%@S4()dABFYBSE?%)5vB>X@E>}`<{y{Hf zWf-+N>h0V9{DaSRw!u%X3>7>PF(wbP209ROb#gC>cGU2kgp0b*@EGOCab z+W4%17qG?{MVB~PbNDm|f!v;;-(en>{Ij_dY3;S!d4bbYi+h$EE8o+!!z_d3vuf|v z$T0?3_vj8tNAgu^8cwoi?+lqN_}zn%imusy+$mnX6zn<2wa?4A!XIj6s-r}PwC_W* z7c^R2eoYtEchoeS592vIts8zlvWGI3Q0Cvh<+_Ws7Cb0ao#r0$tcgrtNOoqcR2gxRmTQ7>T8Z)j`9D$g;I0NsmK1 z3G_^xKN1FykDk@3GzU>jl^-<5cPq>od}{f{WPkLXwP~WX!`|uVK^e}$FOETt)P$n< zjElXrc<3F2VI~b#Jf{TD&r)CFY{$Pzk6l}gbEU%?NXdFR^epFSpJXkU@#3X$Z(s0b zd5rzxlV{wo6~0~l(ogW~aXWRwqVQDXu_g%k^*;J28?6}WxnY}u3?Hgd2hSA!(bV() z?NAK7`)DhuBAii`)!1tsnVaCj{l^Fg-oi+Vi=Qvi z(cZYn*G4_622^G|HTCD!kqGekS)y1mffOlu;d|Yg08@(>C@O| zqE?yrc15S;BW4#foW#$+_Qfhx{&)=k6>gLNGqctcmki!-p#n$s>!YPFC=CmI$}Vaq zyWS9U-aE~UCyaZaX=~rlw+21TN5@SbrR^QA#^Ae)%h@}WPKcSevB8zWBbj{t>a%+S zRpnx~d5wF4X$B=d#XNOMxzC~QyP%N=53L=nJvQrkbIPAEuqy@c1g0%zP7n2!Bgq;u zJx}>m884j3#3TI@l*WCZ<%B<9H)S;sQd;C{I#!quQbJlmCS`M$JD)M>o{2#e) z<+;gx`*g)m+gHygx=prS#im*q>ncHsE0kjq{7_3lcBJbQl$q_Ux=doU_ z?kfFPs6J^i&G@Cy=siC>_o&)@8I(5NnlmU~@0#oFZb+mYczIyKBJf>Q|Llr$wPY*| zw{JtmJoI&ilI^8Rg>i60ZD}mwB+l421zg|z7O47i+K5cO`*bCf)9TvU7(Z{^D8k%w zbMMpSs0x#XA4|rdK6|EF?SuG|U8!!;VwmZaeMNv!oIp2mPos=L2(@ptIuV6Uxv+b1 zO0%n-y(k&MVbq9!n{X9N*XfGsc_odusko7PkJyWM-)*d=jT&59XFVdmvrz4SoJ`Y9 zC|#dKO*JG&OO0xou@f0YV%%&RjBk^v&aXBWU!WW$#l~X%DlHs>He9-(w(2?9;HjZh z{)^iwf#38PhG-!Zzr1uX;-x#bmnC$8=FD7Sokr&N@kfCg2}vc>_m7|lg+A^`1D;>M zZTg?2!-%KUEw43QYDUaN3iW+$jEOt3FplnzIbnXO+T=`zk~p`b-O1=`ci=kC)6guU z@;u`kdrU;GugCPp<9C#nidB4ev@@&71x5w%T`n(D_w6fAw3+H1MCeI%Z83>TUoT=P z>XxaPb!YJ!=_th!FJh%1_3ON~QI5b@elj>PI>R^qsh0moic6Bdd!;Lg zdRZ~AL{@DVCVos(o$yZ{Y}*-QvYI|qV6CfIi_Kqq#Z?w7?SO()&l6XP{Ym?wB($_pG&m43e73fri zGZ+L|ymL)tbW9~4RXSMSRGAc;s6KcGC+@AAHX7_|7E_vQOP@xENYDRKYR(`=mkql7KOu0%;Q`YHXxAbL!T z5cdAb&~HOlb~GG>oanTbRu)Y0iVou#;&N^Z?`D&jkkrf=8|1CUhdCsuj>exF=Wvd> z&mZtNu4NtY-@F-g&-BgQJip4EziO`=r}A@|T0zCgjiw=lD>TA{$8`HMo!Sl}m1p`tB7g+%K&eOC3m zNAgsyhZ^4Rp`*BH9aoTI4s@m>2hQ?yCFmA^>3ffwu3F(AiSl%ZL(vytAQGdg7CuG8 zK!jH(z^HVP<&(yEAbMq`-r9B@ODT%0-wTH?&tD7mSROfEYzYRN4e`lpXF@r=yzaGG zsjtM5^CxG%s8#74--zVsbykKj<$TARY|eGl1>#t^AF0@}9j8-uc$fYm2=w2cpARxb zOXR5aphcPxBDVNc71~+aV9Qdd@-JhMzmhZyoWCFs+~*8(v75*IT2pW8$kNm~kA4^` zO|C{j%xXWGRW$!~-u6_)cKx}|H@X&d3*^8r`O@nbUCB2pw$ChMQ?VJS@OPJE@v*TY z_AQqx6m^(58Kz_J@h}-$0W${r$#BbhGhgRy42OeBu z$(~%ukVqyfBf#d0a!@ym2G&uVY*2Xsmx)P^n(R9$rHo@E>_M)U*OPio zswj_0qj*R^*!VDmkJIeam+ey}(z%W0M*1h5$@K+KMMnXcC_3vomU;zW*x8^==tee)+SQsx9^yNKz`n40+@$je3Eb;`7g4uY2g>7DQ z@AoG+_OtPW295GrK~F8;$@1v$S#_}AhZ3Dz;PcMN(b-6&lN-5aQDgDTn?Bcs}g>59VVg+HyUM_#`W zZgwrQu(q9MBk+9NJR9wesbuW<1wjLUJrBQ#XNBJq%g`z4!#*62fX5~6uzzu$LZ$-V zp>PHw9W8o2*3w?N9*Kpq+B3MML!;bnW{*olMhx|Kd;L;0W5%vSsUo?FpD&t5x}%;Y z_dW_rd=2jt?yygpRjnT`l&Du{JCdMR?$G;&6D9qCaFc2>%}NvbD+BJPcBJNaRgRH? zIH8F`=auE~yvhkLNg@7Sc!tA(39}K#s+xwr166;=b@Hbz%0`nnsh>VOd$4oYN|8?b zD!y1USl#qCtDN$P82kmeei$4~;O>$GTy$MYJwJJ!7`xOF)DgKRk!);n(DxM{SuRLE zsj@Ck{_#8E!|;#7%A>Lxab?@bYP{X9FZLN!wt_p_^%q4?l&!2ipR2fT4VzM&L=_~N ze=yPvt$z|t^^%Cz=uBNjdO%YmG0-a_n`^-7tfD}zkIRrNOPcb*UTy6t;fGcDf<#Th z0);obUek}NbtYy9340PFe@(h8Ufb>HWb`w$AD9@|`@ho-*}2U1sY&o2vmyy&0N}qk3-t+F*bh){Ll3o+g}Og9{Md;5t~+8>g6}A(o_#%f zX83Ata(Kk%Nt4gZZ*>yhjb@ltt7!~3g;Sx8gLM(u+sy^H zFXNGHNg3_AACpH|Rgt$MA1&3Xm+}r#dac!k%flk8CFF^I=y+mslLXM zvL^oxw_8YGbBT2-r|hM6S$PicP|MXry-7pXCcZ{S{H9+NzdjF2PxSZGKOCd`oY12e zwvr@Sew}D!Vz zrr@lVxBU8?8J8bn_iBzr)jQ{v^^nf6VO(77v&9+-H9HmAd6-`@7>9b-j|m~EX_h@N zg%T;gQrHfPdFxxl^O2jnN~^=QvFpq*OQ2$=sW}?vSFKUIwNu0-`>$t6ts(Jl;_f|y zWU9Lik)&Ebo)JsbI!M0gDC-wUS`?vj{c<8|o*4YprPqY)qxh*uT&5KJ&Sg89`v$tL zVT8zhkIyUnb;C0oKzFMmD;%kYq&7Y!C(+f(1`FRNjHX^r@8WGvcH0-e8+Ju)Je%jV z>Onm%47{jM>b3Mb=)ZS(dUnk`P@+~SM{R1`Z(X_1QgB#wF!%G>P+6Or>V$HP3lGUU z;p+BoxE4`#QcA&C}fH31hhv(Ka)`rH>|HdG$-z6n#=dT@!m zWkB*1k^6+to8MQ}@bl4edG1P$9K|q!Cc5hp5-rTc+>2Gxlj2%B^Pkdq#zFi0A2-XR zD;xz%uRG2AquS{|DD0ak@8?|)t>Hga=^9N6ZEe@*M{Bfl@ zKdJE=QaQ%FOr)lF2=LW-Q1gs?&|2eIBHF(=&b~h~O{!ZX#l1{1iLXrUo3N;LCX3sb zK1n=$FRzDK#$UHriPtG?O-hjF)NHpBy6X-&D@v2-YHUZ``9GWPmDkypsk^WwrqwOf zn03-Bvrlf3YNb_fob(bgF2d~Z5n&oHO$WYDZH~6w!F96h<()?Tq+p;`H1T0z8}?%p z&uozhk2R;3$d~##0TM3VD*QbQk4GoY*KfzI0~^|!3w64snrxidc0X@9SH)b{)}Fs0 zi4c6f;=?+mJ&vJO^>FUx3bKxN8G4F43Fhqd=b@m*ne_m&f@8AR3RzRr-sQ;pFMaiY z+UgoL+l(i6_2CNRrsgRf1D;SwKd01sD$ZH76&qgCY);U)zV|5m_FYnCG~vm8Oq$jJ zu}=9Erm+=`Qd@`bzBUYeXM9j51ZZO z?l?H-vK;5b{}jp`_t;oC_6Ffn1vb{2JgmcXM6Og7ad`)sUBl_`Io>~Pll|{T#CSm0 z%8&onh!`g~I{-F7>|=qgOx=m{bAs;UAtku@*n!)2NC+wNr(Cd+uDf+X%KZO@kb3Th zkhZva`M>}MD1@Z&@$&!(4`9~~KzsNAz=aDi7sd_b^0D)QFdjaTc`$x1kku_nNiG06 z0B{BlE>JoE&43J#aRMPb8$Sp(f)u)~8eGL~9Bk=|hnM^JW^Nk>H_r~(l>%D6o5afn zs_rg5{u;lV0;!st3pAR$aZbQE8ju3EUIt0Or3xgSixU_nBn2{e;2z#B&I2y;+vM^6 zHi3|G;5-P~Amt$8Z8yM;0%PL<*1%uq@t>nWzfm4!>kGWl_&7mJj1R!7fDkgVkST@a z-id=6hxD5lYypm!4K#_65CGvo72N*&6S*K{{1+jl#k*s_T~OfGAp~G&1Dil&=V0Rn zEwww_1DyXm9>o3!9`q;B=KqWb@q$Kr7Z18?G*L=fTuxpOga`57#e*OQ10g08|1}=O z`x_p_0RUV7H9QCa;{Hc}x&FYf{sfHypccf$BhRgs#QzWFB@QM@xR#LKa95h z?7mHw9ENH?R=_bCSQuIJvoi(+cu5DD{>G;8Y$qHqhG)JQt980zU_yH&6_c ze>+QnX-bfBLeL2R$b$?6QVtSA+K05q&JGZm|F-eF)AwIED#4_NbQ(-!;AIRlZV9|} zAOwWa7c{BA$G~SK_!kdwXaO%hU@*Xo9vt!mXDJ6cB)m(ayS@Hv9Maa^A^*|ZEeRmj z8Uaf1fR+u=pF0!w`{~H`$LaW|BkccvI{slg@$N0(-y3B8{c7*d6&|pPe><-3R`5@a zyYl{l;{X2{ioJXLc(=QMpzZ(ahV$Qy{cgoT{O_(cfl2#~CbxEafjiCLL=bc&#S~;D zfme=(9K?Dr56B=pdd9_r_gJ3^KN+!tT7KCjLj9F&R7Uo;GQj5p5hEH#=vWypaEsTbv1 zU<-PMud0alw!oo)>ORK3fNpp9u}g{pL^|Sv?MT0F==P`P9Z(Fiu6`*fq6Ug+)Kmy@ zv=7(d3cq*`?d{;ZUDMzh|>K4U43>nAkt}J2d9NU%wdCf@;56 zaA1MDaZrYCagb*tUL`?+lK9>&h5DmeCGgVXjLhtcSHl;5Lej&Ni0|SO^QJ4~x@_y$ zy(6@1^n2gC@WT8~?;S3fyb}4fqovSoY4>|3Io;-R_c=n)c1@=GV$wg6l}Zmaz5xgDrjnqFA@>-HpG3sCz{iw2UPJ}nI`dI zpsxC^ESZlh&QBsQv&EqFF)(1UE}mUBUY}Xq)V6V%ls{*~UPWV*;%jRexc+g2eN7^- zi9?FbKuH0Iftd^g-QG@Z4mI-lZP(416taH5JR%yN&R}lh76n-|PF$ zte1n+sOO&27_u1ci48ya?_tlYoz@I}7*(5qO4Kv=p}Mf=rwZ|aT;68RRFKh#W|Hc6BJW81Hbf{rHYsf_ z|2S9*WHgLg?WINSU7lYl@)%-4Z!bsXR>`TeaRYn%iq}a)HmN~++2Q~-W>!f5Wuqxu1r)Stk`cxGbPj+8u_Obn(`|{GN z^6H(X(}Y~PbUaaY>7YYI5c=SH>SnOq>@u{@m$4*kZtE(tevUJ%?iAC>`OLW-KGiVB zpQlHYPFVwA7?N2Al||swc^IjmrKUO!@)aPwpu<{0>`@t@ly#5Z!R(Kduw08qWfRn4 zTNWtDb;ohZi>$|}5ztj!AwIHAiCybkZ?7pbw2qagw$i=)`9mYTfLqJa+D>!gb>Oec zCtf@!N-TRbSS_OO1glTodz_*B^Vd7dItmrExWg4*u&oNmwGVIIn};)Xi)l3yR__f~ zw~_zx&0@jg`3c8bY?NiDztTs;n>;Az=_jJ&rJ7TVuP(br-dYOjj!$B*yBC!c76rFO z5gdMlUF`m-+_@0f|xiaW9?xJL)Tc9aEVaZiJz{4Lo6a7nFaEWP}(}Htx z@-;K(iSbGK)Vuvo-(Pb!&6Zj!uRK=QbRIAt&H*syv**S#M72ct_C46BN)ma;qODGPZlw6Rfp zbW&1+hN(yu)ACIRIlDap`Fa#oJ|t9&k*V%74bm3ru&Z$v64y_{mafXk4&zgK407)y zj8o4sAJr~#q~t;ujE0@OU&dzCo2e#-_m2_XuahJWXSIz?{19w;y2m~w5Xp|+nIn>| zz4)=mUGfn=QA!;jPnW?;YnI!U!kR+S28Q6~MP(dej?h%%0`p{myZqTyOx@m_q<4I4 zeNmspJp(uCE%ybF1l={Bz83EOvU@6ZzZ6BRq*GV;MZtjk08d1FHbTM$djmOiqp-+q z%XnbCV94Id*NzIOUQuHwr}|*74yQRxcyAS0ZD_QLu6(Hwh4ys$*O6ZipCws!FKHdt zwjN!K+c#-vwP7PX(kW%w_V$FfIC&n&O-8yd&9}j{E;;=J+m~?Fy7HBMCIZr$hT0+K zAiRxd`P}S89ChVc-L>v7Ww--Vn;&B6&^*)6jcl#T-13ZL-Wr~ob;gwz;EnM~yfAx) zFv?i*PVZ8yl9}+*Y2yldFF1D{w;DJF%|##6%XJB_^Kuv@rn zPCY%pz|-SM?Rmv>{-*{-xM&^+WEcanY`Z;P-o8vZN{)@Q+GJV%Z(eu%0FpNW6%)23 z1*}}O$zdd!x;<4wn)Y7iifi@M85^EBXH+v=@RB};izqoF!f$ace#gla)x#-V zy_oY|bLHi}R^W%4Gwr^62=5xEMmndXb_S_7m1xYRA{$eDY$Dv?MPQuxrdS-iJ5S(f zBo7U(aw`1(M#JJt(VkF$Zqhn&uA$wB`oA-F~9Q(@2bN#WtgdN zGGjm$`xRI}Um@ovwAVAi+~+8C+C``MsT9fnyQ3xdOtQ*x#1&dTLXz&nM241u6M9^& zfr62VZ~vQ?db$DFJXG9#wnBQK)lI+A$ zci|FOw|=R#kNC>k-pG>x{W+m0M`)2vlvIj|JTXfh& zB)8N~C%Di^$4Zbi2kKWg3L7DiA-q30qH2A!xs?Lfu5KZ(=zFM(+&EVU$PTI{MHNq>&mi6)e8L z3{@nmzOKN&w|Z@L{%w&evb+?dpAk2@FSPr>!pe$Kmf~lo15OXARO7));dnu&%Y4ba z(tVPV2FwAdI@)@d(`<=vwkbzXxQ@i|y{$RY$r6o;msHBDlWN*=r_vb=VPO+eT5Fs) z#B`O#>@4ag_1#8!;SO4P0%CWrzTnAprcbr>Ssmsmgc}uQOB6wGejnLRAVy!N4c79| z@masGQjN)v)saJhJQZMwz7aJ;`}9q^zc}g|pZGqW|2*m`8xN6oZ$RC*SUVSWoiQ}|Baq44GZC~l#VGnPr`uS7X>IQEha=&SB zWg=0){KmMHHO+W%1vkVQwKY0hEcXx zRK}JrnF-m4uY6XRY=5zQPaZH?^$=kzc@HJ5nA=<^IFnJ*=9#<7S2Mi+q{{SQ+utb6 zeYm$)-CR4WvG(Eh)QV;TgW6);!pp_TOcD3SjPCP&Ym_Y8HMrQeCfKx}^l$`e%ZXbK zF4UX&I+{WaflrmudsbhOj!q{rkK7xAFFZcZKGJ%w&r>BHJcz=Rfc2OvQ8T%?@~2b` z!LtA|+tP~|os@R{mz(ubwQJq|XE?Gp7E+bdj${^x#DjR-+`Rj>2PR@kMaX=G2o z$2t3;z&D%1?WyGhv!eY*-ebi&1*lJBnnsQvT8Srnd=k@zc7)G6!fAv)t{TFb6SGMQ zm>pp^3sQgNv6x1dpinua4f1)bnf$edL;kph32&g@&Lg8b&IKOT&Ii>xNbQCJEn{qQ zD_O5j##QSB;FHU#(zH^Vq)yOh(neo{EBHHMzMjppkT66U2fyuX)ZlpH**1;>$YJaAk?4 zu?vF<9yzu96mDK|y|0`a{HV}hhdYSxC@8KbBa(hlDoHyEVpWgge(_{pW zt4Hs(-QEW-CJW{Gti8`<4M$S=qFh%++AwzXt2&}Br;}Pn-46B=8Ly&0WHEzrsCY3a zZd}r>4UIA&d8A0<*V`N{A#Z#doDlaze^carAD6cSpHEc6;Lem#wBuJy2EB|82kh$M z2>0jIOn)4qi_qpPbH_i#$%@nW_RE@vS{1LH7bim7gbh1OURaRCB_-c{z}A^KT++Xg z^foc^JIX?^s~cG>Ubn}la^*zL(6C;w zq)*klX787d?)yY^#Ts1;Y3}yB27eQh=A_z7%@{J#JLrY(d$1aJ;P|NFo-rr7STRY5 z3f88^Xw;cku6g7Z3YA&HrfX2z_r0G%OPPEJIQbp@L1dfRzAg+!P_UR~3oT!8gd6(A z7-!Q~tR)7w8gnDGCsaQ38H}lBYhxwZeipFC8#xtpFqqwc5zw#2TX|nKV6+IvjYBC6 zDmXtsnzEi(@AL=H`);^0wn&+lxK+--!gmTx9Y_jy zg1olW3dWXK*{jQZe^nR>zPexh({n3Rk`TYZy@$)bVDq^hh8B~rytla2afqARPgC4` z(ptN7%*c7E2q~!Bgrg>o(>(OGUf+h?_TZxw%riJNcMc=QV+w>7e9J?f^u6279 zonpTK8V-=ii+W-r4ttKfW?K24!TLVNm47h9C;m;_Crq|HVyQa4vt}k@9AR}C6M?BI zB}Aoq?Ueypfk*W_j9h3qYw6ab8eRijI;mpmG^s4& zP|t@rHqE7oRw7T6Ct|D+>FvYWhaG{j5A)NH;%5Ji{^Sal0OtJ6+Z|3vV#~jZH153%U zWQvIuuIy5MFag^+QP_2~l;k=y@@CS)I;{ILrcMv0>6g2lXwT+dtv`*YWky(HRKQ~q zBcyjLjTs2$%;9dIrtTce(O8k76MYzeLPJ&lOtZvE_~$bbfs#`@W?^}`ci-GEdU89A ztj1y5sGBSi1lLB1CI*wzda%|{-n#AJTTMQcYiyjU$$IYi2JI zkqLTr7vbaS>#8tV3huAHS+pWG`j9u3RAemJN?EGyT4{SsR#0lvI%}=tB4v}Nx^oZ1 zGjin#`sYczq;D`NdP$MQq0fw`p#2}BNgX7Dg6?Np>cCqk2d=ill-xLpL- z{~xI+LOg%{or)r$`v%-(LtG^Bae|b!F zt}S5Z*x7)_A>9F!5<+9poczKAu?phJODBcz=8m#4G0_n5(QvwP7v84g9We3 zzm5Qs0ugJtB{G;Sx2=KOgp}b2kRd?UnGFnTgO&n>>fp@Z0T<3c0GB^s;Qu}10${D6 zGvM#MWbyrh@BTLd6TbfxhUJ3*4S#nk@B&K%v}Zse53pzW$@u}tZ`=T=$V<)zq=H~> zc3>`UVYc+tpE@$Ffxeb0mvC0SX_h?K=ObmK_>-7lm$|R4TLE3@qmvIK!+9BiD30# z5XK7}J!~LR3m#t3LCOnA)c_J6K%56yNWec({UH2~hZj@`lnubv;LUtD{4)W$AeBJo z0Px%f(pU!V8E)WA17-!#p5^8S0m`5dIEH|30b3gABE(xDFk=9a3s4^L00=s>09{;Q zYk`+GH`rkyH`s|GH-Oy&!{!7@+khq-co+~F0iaDloCQb$x(fiJ9AM0r3v{+|^MVfu zE^g3<1LNF){1326LBxhk0%UUj3kL>2_;?0zW}pWUn)8D|S3baxAmG9f5EKF8fHV?F zx(Afb3!u&bWz)lWmK~Nm?X z-%kv#KTZtw$1)mvx&Y*-BnN`i?r1ds?E&!zBnv?g`R^z&Ys*RLD5wKfsq5aASm6Vq zumI2TZ=8Ix1Lz??Hvn03a08Rb$MH|mLr(5H@FBPle^O*-2b^~P8~Bj-H^dMiEkFOi zMi0GJvCWCQkSL#~%1RSt!;-RLg)B`9>BJ<*3n;5rQ3buK71OcL62#qpY3hK^_u4;} zpuN>j)(DFd(;urFh4z(oDI1#_3@j!^eksc9+K-4XZ-rhtwq9GGS6H89U0wOiuU&W@ zUpyL!&R*Dl948kfhSLApO#CZe_wvH<6F(%i_9@*?@qk=>4}>pb#(rm~CZfga&?pFn zliERNi)YG|J#j zLum9c;HzVmLh~@h*id2<0`7&WN)5jX^`}qK;t*{Zp?y(QlIzlK_r@7=(e16z^m@gF+r}-e9w(X^?{PD#c%YS)HO;Ca;>^pviHKF%*r)po&&Y-CvvTe#62 zBc}UDOQFz$JtIOr2MP^cnx}3SGW5A>qk$Q^tuS>`FYJdx3@LV_?&cC>M_Zozc{nI? z!wlrDwa@|PNJ0VoT9m{Hy7+Icuqy0+CMOs%-Lg&$; z%V#7Xe#gSg5!6uAhT45i5$6|{CCjS{`qMU9b}#8v9CoqkoAh`Eyw67Q4x%1LDUTTV zi#L_qkgv}5v{ihQh4aBBV^YjB@Bdy{*DNBk@O=P3u|JhXE>F{B$GL0r@VR=``L)Yh zF#pYx#&KcKoXhv0f?;0q=H4%w%ZDk=Biy6+#LL?$teQ-(a?B^8r#Q99YTkTgn$&bE zdO4cY?Cc`$BOkiekypc0Ma!~X6pd~0gGR9bDYmZ$b+@&kgO6U8r{#0wF(P_|`be}R zW-F%*9wSzlv$>phXIGJ#3695~DHap1?VQvCmm-(S7PD;^PZnvzJA)_eHuRZ$3mBUC znZoS87KoIe#LgBq5?SyYh9bX6%JmFbQlBZwDyzYq!x_vxbvi_(lj<*x>X@({Ohrjp zDdH%g?Toh1(BUeZm=+;}yuQ=#}>M>0k7 z27G;~SiWt?;BXxog766oia?6iBL?FH={M++;oRw5&oVwg(zh2m2v~8@HfnyhQmoQj zZ5|zc&W2ETkNSf-t|(s|yY0!f(oNAo9qsv9KwA6f>kmK7I&0%;8aaFStt-lc-JI1& zHHRO`;vf7v7&UszgBZe)?V$d|E6ZfwEg6ZRZm!O1u1M%(E>Z1{QQG&p>lTq&JcVsU z@6fLZ3Yb*su8vDv?$_0lx!d~gy3>p3XU-R%dOjW{XRn;U8cgg|bchI>9$37Z!Kri| z_B|uNA-a5sf^8%Fo;a6c5*zmHUOisO*x!B#0)|n36ZMb=Y>cpj*)ZTB22NVQr6}Z3 z{xAAG23Pr?eEac1L<0Yg%e&<|?y_ZnW<+j(LAa|wXWjZC274p^bIzY0;slGW-6q|> zsKKvmfG+_F0N?%ty|(YlR6$DK@^%1Q0x$xQ5X|#I`UB|!KRcKO00fT#;WFTh4&e3x zmJMLX0CoT*D+l7Ycz_o@z&HS06-06i^o%0If2C`}c;)ZyEW)7_-snLh46 zn7%)AYX6q$`$J^xRuh(sjql&cUIB9Yzsp{6asghNAy58Q6E+^ugx#s{QmYB;PMVb% zXX2DN_U=hywtYot!S+PjEaXF99L-dRPUVh%o?V!oxsv$P2rMLB@wAMhfs=_7FJD0a zRp92$gnQ;%%!Rk%#MNh!icJrD3LnnLBuBGM#UzK_z4>kHW=o49w+W| z@lTX$ya!pXf#>yQ~aVmU-D+>rMm@MS)ks&>i&VKfNhR}5QZQ1VF31W>ki+DK3O#~hj?CL1H!k8f^Q>eh z_nn0l1oijkE3e*g1yZQ#D2TAaLY=8!MP&P?e4|3aLZ6h#BgddCiaorpb~^1c#Zw!w z;=@`&mhJ0>Wves8X&R1xLi&k(XPpd!zS;y%v#O2lDpqszyK z@A*p5K^f&V!#XdF-eLUNsFCpe$0ar&<)Am<WJCqWDKX9nOE%{oT~N`q_aHhcC_QQRIwESj z&SgiYufAq2U5YA$rYJ>5f(d*d*^g6u+^_&o^37>V|8*FJ))!g0_{PQr{jSmJ88a88 z7a!oR(Yv?2qc+z|UP*9};SY4Kf7E;bi8s7TMVV9Apf09Dt0U{FoGH0O1;Dw#70@lz zXnJ|sKF6`@J%6y2Q3}UG2u-+dza4JmT@%{-jO)5j>C!AJ`P7zpOd`p0v%GHl1(Oooq!$hEbB`*LmfX!6A}q3ZG4%RAB@)IbN_R>M{*V$h z@a|c@hTGvT7`^_2=cb4qe3fzZ3iS+dR#UD$yxqDZs!7@zx-LWK2N!DHDSR@gtmVP} zRdQ}!*^t^poXfsS*L5E2%O{(`WDz%ql6&fy1%zb6Q$(Thh>Sd~a^ARWQmdr{?j^PmM@DjGE16H!4VNx0cn5Oyo?IX{__@`XGCdRGqMg5bz5R=p^u+v1 zv|r$hDEBY?c+D>g&ZZV5kAJ>>vfGe3@cQ8g*P@$lK`Vz(VoYnKZMmK!pQoqq|nw?wb9~9Ye{d>lx#i;eCgEw#k~1JbISRbl}eDxP;zQ(UqFuke(;AHlR*{^=7O+?qg5hP^%`Q+fCjgy?+pRHm4Xy z)->obx#m4bs5t%$NUixP7 zqOt1#wRh$5P43ssuGQPUJ?{{f>J2DZsoqS{zp_&;k603aw28kqb#n8v z^}=mPz14}s-cx+;N+`MDEfLM#(!K2Ri&4XmjT@Go#OgMS7=w7ongr!+!qU+8n!IAo zPXuSQ)f#JV-clV~=VphzrDy4ER!Z^quUaKLCQa7O#NXJ|AVN)5l5TyCU-xLMdAqwZ z;*k8hj(ZK~1ETJ_AEJKmX>ZrvzQoViD~;1)&tsbCKCb|xZfN%g-fZ=~_K6C{`I!pG z&*$s(VkyMuY-f$Hcvm%%?~htmbz<~od)ZVaxjgPCxY4?7b!7s-G~^>%%)Wd)l+Rf# zE$rxdMxt2R)^2x`!odu#UTY_{wHl6U!CEDPBa~bf_3BdDox{#exCedFW4am_F=d*-Nvlo0}fxcXjJK>K-fkuwBnG3K&YZG)xcl``SKIpg5%uA_$~Hz zmb$cn%(22Vv`RR^c@|%mtGTwU@iDD@JwdBq22F-^; zd4_o1_6srSH`1*?-qajv_i+=hgM9k*M@|TS=+8X^V#!d;OU{kF&*t z-bH#3Z!El4FvEcrA0{g z7iEUDnAKI5X>X)U-BuMhZoyfsYQ)O|7+5$E`a2F3mXGbGW zh%UK!VOYLMq%LfA2LuiBwRawyyL^@6E)^V)y2 zRX>?!Qm2~{si+!bFd|k{fFgcWHQ_OyBoXtJI&Ete&g^@inXRTzar;u;K|(vPj0iO- zD9qhGTv2Q}Io?ZK%c$*Jh?=QQn zq~w-R)UsM`sy8L{)^UfTlqEKAgX6c35wn!_!)q<#;c`A4+jh#HJQ+GxJ1T&$#k1b>1Kd#W_TXqDWi5aWy|4=3In_z?6cT}e5# zMp)c%h$~%i3!%J7&bGy~$v4d-_KQD4#&C3~s@C&9$ASLm-&R(coMG(AygqPXSL&-} zyFcgWITSay`nW%le(kQlo5X&6zn-qgVXcB-%hzi%jJGKzzRv35`Z)Y$C0{4X%(4XY zaZ_zrTZxWmj+bKL-AMg|wN38|bsNsKUNrh>G1X*QzRfH5)+yDzVYTx-FMc=W%WjyQ zj&gZFeCcbbiN9zfEokhSsU`-?EyNLaXPj&@TxFX0R_be9FP&3*_sz{$jZ-*~szW2^ zUgTy*#NSmgS$DBuq*VJ|B=^Bj*EVk%xYT}CJmmh>Z+a5Mc(v>&=efqzq;(!2EDF8S zaJ0b*Z{7HfC&2q{h!!^?Te6@uf*4Cb*iwO6=ZLQUSbIG)i)XU ze#dAedqt0(bsnM1TI$nfS^(+wGm&Si83#@}u$kDFah zmbRPvGp^c}ug^w4AAT8J7@gJXm)~Ak^w54opS|jSJJk>2m86a}DQqvRUvwX@(;7=} zx39_V>&ZO(Jb0v=ls1J4-w@JJ^O-tbNtSH1)3)85m|XO=O2jK0pd(&5XKUX|tnqG{ zdRy2Uv6;78m}_k1JB6w=Vt0t===LYWF*TF6+;{H1S&qgywc&I(l%L*f#;Xw`|M8G? z2g7_#hq-1fBABfDN>IO?|9!n875l_j$X_ETUzPr8rRnqh<8S@1Pgi{q*dx{9u8E{C zb$vKmx3$l%QOw_=rii`DSvpgRvgCI2+7pRRZ1HYskckfzu;jj6 z?b_*euvqeH@x;_`E%N?J3i^ea)~9}xE-Ee1Um7ahIVw{nam>t2p8X3|x;Z|zo9&6f z5cwuLAl+zlUnj_WaMoMTspX+b&efZs}j_!aJi?8v~ zS-$AzB;ofcuH9z!#e}`>O5#)PjWq#!WoJ&v(6_W6JwMrVQs&0_5)1Jyibp1Eyt-ZZ zvQH#@p>OhjR;O8z@#-}$_L*jHux@HSVO84;?}?VAuO+fkWm)N(0*YN5lI-^mNxV~i zQFA81=cP^Gkm2>D+;bnlE@~~w@k%!eveNr0(T7z=8HWk?APyi|3vERgPD5 zRuwBh>}Wl>PfGidCcx*i-!rAgJ3MHvls>P(U7SBr|LO7@{yQ(W1|c#8NmIx7kDON# zveBJP3y4{g>At0=iFCuG^Tf{X@y2B)SF0&b#dVbwLihBpsAxsoW5mqYr`B@}OL)rP z8nLsTYS5BYLt5QTHApUg9}#A;QT1he%agV^y{o)NlbaXy-f0c8 zxaRfk735T9HVz@OjoakVb2-BU)cCmQq~#k#7D#)KB_%rCnlzYjXM>pYC@*WDqpmTOuN{F{MAfz)>j4_uT55zR9}b9>wo^ zepxY-p9@|$hGo9157xirFLv82&Vm|gBHB4!$nSJD|J>g0daHb^02#Pe?i&D>aFDN=f`~50}l<3 z%kK+0uQ2wk;@k7pOGwgY?FCEn%^&hy3DFIvHXMvzSwRbxe>l}()b~75s8Q#0NZKBK z2g6QX=L7|06C&W@M56V(6wFLdQOFDWu?p2evsYo4*<%`{ijw&3s7u0Lni!Wkju&3g zYsnO!cpg0(Uzs%-Wd8a}P0F3J#-wjos22MON%A3PZWkQyUd#{U$n#w`Wu=t-U0`yX zNcT{15GBW6e{DZI$AoaiPPMRKJ1gfdc+H+H5z%w^(iR?4{k&TY&cpx4$FFmQhg4E1Aq9Q^5qgnUq0@%*~O77o)>X7E0_0Nx|w!l*ij*Lk^ zj_>~R*5uC{n1848IYhu8!PS6Q^Uu%Yh&bX;ml6hx{*wc_+2CqYp~r_x#T3zGn^kSbhFHUc!)a({Ws?xUzvCC(0|yiPDJQynnxo%i@s5C-JK}PoKdc zf+aa)cPOVwCU5?&>8Zg|-E^Yzy5E(b;a0io9a+yNx^yj1*|e644>u=*hWPq8js0zp z3h$Z-(ck(d!tdMTE;r(e)idprojEgUk(D&JnLzR}U&fZDVvG9KSMCt~=5%Y>oqGu(Yq#=$ z_h>zGxRTP~&*mePuU?22Ju-#j;bk=B~cEtovx?>55MBj=SG?)0D1fIl|{o^Dfs}Qm?{)$zbih2b16Tk-mGL6IrBJ zwSW0Y5Jr_>`ScFSK#pD!^yhzP!Mc?ZI9t=VsyxZohc(`-}Txz{yI5} z%a{yXWB-<0wI;VHDXBW=o>-i8QcC&7{MCLD%cTaS&i2w}08_xP#&UJh%6{ zQ1*7Kj2C8(FIqXX)FK2O@9c3nyp>W%@NXY>;9jQJzU}kKu4cN`n&h}vcDCi$YP3C5 z3}bB--eF4~Mjes!+ti4>xMGLp-h#jhT!I-Vx&U34dYbVB6xBQpIeByTcZuSGfP=rz<5LGy6<$S`jl#L$(WTsOQ?mreyAH(I&CwKx1|Sh8iIv|0Z5dtY4`|H~WZ2-If{E z{lz>_L}^JNc3Yj~t&}A3w&@C2>WUTZgEMahI~<>gv84*I8+UnlCc#h0SoZM^p^nolVzN1CU-+Y% zaRa`~>}EtQ?{9v}#z?r~W|Fs&w_r4GtB$!;iAh}Av)HmLYaRAYRomT(5|Aiwp7yYz zifBAkq1ZT75zOyz65jtTn>$C*rLt!Uoqi$ z+QzUq=F27IHj}R2x;9$FIJ>M&iaC$Cx`4)`K`*;^3fs1ckZxL@ZTDL8m=`gCSoMU? zUuZeLe?@yc-|DqpdjlPAJhbhS-an)~wPTg3m}YT#Y&V`?X6-tYQW1kmjUt^GU3#6+ z$-||Yq-K&3!Mc!?J1`P`p{D!PDJ{?((~Q3CCA-~b|vV6)`cFoQRCXdtn`UvFR%ARG*9QK zn+Fu8A2K{_GVs!1?87y0bovc>%i^+q57{n?^+%Ae>9bcNz{M&2k1N*H%qF3D%8q30Jg`fC}-s`yOWBTAa zU!#sVEy_VV0hL<2n0Lzvvb-B;lWp4s%H>_pM@|*zjK}w0pVYIw)ppF~1b@h)tIeE# z#g7`t&Yf>LyMZ%%i=tG=fat+A2gLW0(F1%B`P#%kt#6M#wXs~j`Odi&hSjIvFOR4} z%IqR}eQYk~E^Oy`?&x;t(OvO%38KNtFQnVAML${+O?{rAx`LL*5qDSMw1rWsY}Cy9 zrbMA{L;a<$?w9$^GTil7pPZ=sxcr($$K=U!-sR&@fA{F#6!ZS&hWp4u^Wr`20WSSc zo%an}w+8!LzPJ2ZmY%MJSL`ZZbK;9$iU7UIu!Bm zl;RHFy~K3+Yso&bbZP0MQrge%DdSYR+%g;v(?bWiWjLzhOjOa>^@4RWZQ&ME9ls9@oa?O0`*y6E zeK5O@em>E?v{Bv3qQIS!mwI&vy=%4jP#0;BU+0zm- z2dXSyJM~9eD~~4FzYIHgNI{@Q^VR*Z7ca!3jm|BLF)-rqX;tVt($z#A9*p8zfq$S@ zd|C0LcbRLKq-QC)&wb?b!JhTQ^{bnBy-%N*vER8?rVagAH(W@|<(81l{ZrkAF-@LZ zW0w})zs*&71nEIo&-)GGKN@vW*2fhkv--xJbM0r>T{|BUla(ej72E3SA-KBzo(6v7 zo_Gb5A|dI@&+;#|d=2U7CQzcB747WuBho{WZ;6!WqDQ*qgr8D7(RSlAIYYPPHmq>-_3^NnNz7Howq3n^D&IWL z{7{$KTl<6!8@Z*k>1*Sz#%c{GCx~okh&>=)?n2`%avbfBBc+e&n#ekg%)DrmIQ8C8 zkjE?ayc)Z$HD~fW5+rgEiuRpsf?jGov@VKvQiI2B~nxB?N;=eB)u^~u?6@qpKe-n4rP1l z)FvfA{6~%TTGiD@xSGs{1}zvm*z-v?A1zM_yg2eaiMx}}R^Ygb(fVwyi5uLRA0AmrR!rT{M-Q zC;e_8bh6D>>XVWvWxK$qF}9H>XQfiOecp}m4((l1z8fiLi~JscP`|sPzU^CU$ceBk z{@)_T^Ab}SnO?WI9mwHCrtGm=F><9E?-joG9AZQ0vEv8ES7x)Hes?p*Q{eIejgw(r zUT*^0E-IQIdiQ|cN3pv}^>XJ?OvZ+&9YG%VAHF-WXI!f+SKf2`$odc6Ze6l(1E*AG zwsi+me_OvSWyfmKjT#>gE6=bO7rgrN%Pk#9Me@gv=0~Uz%=|6gK2-xK+lihQdNu;d zY^)K|kC@DVfffX)*x7_9sQ-Sf5$2BP?*Lht5BTe-Q3QbA1bB7=gbBq1I0uAWh4K*L z(Ex`Jz_tLV$&6aWjOzybfni1=oBfFg;nV)f_x!SQOgT{Lxla(f7C=G(bXpG2jG+g% zv>>d|Y(6CbM265LOrQwBj{@KdfVhDCO8`3xaHl|D08j>?e1LK#LMUS>zz_hL00=yQ zugpFZGmQ=tfeb(%fDhnL0eBKbzk(nyOx!9nz7z={TxTr;AjC{r(0>6+m5BqM|8veX zIA#n&D4P?A+ypQ@5IUGC5kPDpOG6l3901yYpCHB!9-wLg7@vvH#R2p@1Z9Er!T_8w zs2N1G`4JBa=mxmKGXTUbGaeKUz{r7YChisjEQ2-!h+8N&BE%`j#0WuHWIzEy1%Y)y z^hGSQwLz3GfWBqs)B-l2ZHfOoB!vKKgzi}|qj}9*8Q_3Hd@g_vngt<&`yT)a4FS&~ z9s=ld0A~!Mc|mUy)bUh!t^Vr&foEW%t2~2|01T-eAVWBWb?0Q z%oFg_2Q$CaKXFq1LI4JI<{#tuoKy^I&V8iD@N)44j-uHsB?c5b8xN!o-P*$p19FoA z2OR=~Vj}*)Z)TuU@SEwlvzRY#&LLz#akl~TW@|7+&PvCz3I~oVNI0a2A%b~v1eAgP zSRi+94*I2BJgZ!$Zs0-zQ!Z}y7Y4nh%YceRL2w?uVw#_FACnT;KjFoY@lpSySAs5kROx7EPgQ7tY`&db&Tn zhu|&*a5XY-H|W`TQmiSS6eT4OPj?%NGZ&}AHeXi?&C$jaLA9}?yC{l|mfR6V(5)3k zjq!RYJy$gwd-@K4cbnb*JNMB19cd(M(QQhc3ch4tXIEz+4dLtT%7MQWMeRL3UCBtKkB^V64_21p zZihsZ!2JUh28qGQ01g=sKNnAmuZ)Ywrdc6>$WgcPpt;jsJ?RV=1SFS2Wq5fiii$!N z{rvi&AjS1(MJ^t)Ol4(h3}>V-#TAK`MInDm1_c!Wk*o#`1hTz>ZzV7yU}aDk85D63 zT8@k*l5r$y6q<}eDL}>NbI#Q~CxhX>hrw`CLhP|IK>+<+y`Xm;Ou%4%K@rJlIV^FW zm>9^8WN;f zat5Qi2Y4X#!UwXZk!>07&J<52imR&=okoGWFQlUaa_(RMZ7o4J)zkZ_=mM+%@d7wI zFVvG+gsje>c|i}NrLN@VMYkqXa5NNH6I;vBumr3O4uvMkP>BR<85Ee%Xb65&Tcf#lw^0LbLfpE(t@W;jAeX83K`tk--sdfm|DFstk&PLt7IGRBJpI z7-&|fd1e39PP0803^riELjD}F{^+(p2Z;Zd4|5Ov{~~@?=)aZxBjf&Su7Az-k1X(y znE&lv|C;L`S>PWr|J%F%Yv!7_=dp1C8yz38qv7HNAAjtLz$dVk;=+K8d4FuGn0o=R zOoP_WlImn=`HsQ>7TF37t%;5DE0-6#@sH$Xc#E(A&iE_vgl00LScYl zd>{xmD-Cib!1(as2L3`CxYLM+>j!8Ac)fr|g7Kk2N(T^nXn{P4hJ)z>t}J5ka6aIM zgnS(H^#goRm@Gu(y&k-I6 zvmc;=uoDaA0UC(1!b*c~7SFF2@PQ)*R+=2lR)CMhstb_>-CSNMkA#B1gBXz02TFXj zfKLuXg4}BhX;>6=Py?f(;e8w<2QX!Do#n6?99(BPEEdC3uN;v@XW*1)(OHg&g1^5Q zIU-BnfM_7J2TW%o2DsZ&y@ z0-J)+Ebw<4l$C?`dkhf|25ER%JesB503UP`H@^r!RG)# zlY@^hfChRDyk0B@KF@#_$H3)K%gTQ8Ua2p;D~rRaLx_W59CXO^((-~GH*e&U+}Ta zWk5MRbUw4t24Hyp1r0ve0>guK)xxsS%nct801ZTiV&TJqOg9Va1$_8l@PUJ57#|Ld z?JyhQL9d6e4*(4VWo?=NY=8!`hq2P&<2c|0y@-Vmn3aVFj#uF{IhHX8Otc`u7z-cE zSOQuS%+xSG5VHsv$4F}f`(7LMV@Su0V>jl#}i!NZmn#bqqPN6&5xPzl+1>|nJzYXM(0B#CS YaQ@@&IqRhWvFW%t#l