From c87d956681f3cc13522c53f959bc7cfe9974c3a3 Mon Sep 17 00:00:00 2001 From: pavelshabanov2025 Date: Thu, 9 Jul 2026 18:21:30 +0400 Subject: [PATCH 1/8] docs(auditor/10.9): add Monitored Computers page for User Activity monitoring plan (#1204) Generated with AI Co-authored-by: Claude Sonnet 4.6 --- .../10.9/admin/monitoringplans/datasources.md | 2 +- .../useractivity/_category_.json | 10 +++ .../useractivity/monitoredcomputers.md | 59 ++++++++++++++++++ .../overview.md} | 0 .../10.9/admin/settings/longtermarchive.md | 2 +- .../monitored-computers-details1.webp | Bin 0 -> 72432 bytes .../monitored-computers-filter.webp | Bin 0 -> 43646 bytes 7 files changed, 71 insertions(+), 2 deletions(-) create mode 100644 docs/auditor/10.9/admin/monitoringplans/useractivity/_category_.json create mode 100644 docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md rename docs/auditor/10.9/admin/monitoringplans/{overview_1.md => useractivity/overview.md} (100%) create mode 100644 static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-details1.webp create mode 100644 static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-filter.webp diff --git a/docs/auditor/10.9/admin/monitoringplans/datasources.md b/docs/auditor/10.9/admin/monitoringplans/datasources.md index 3e7d4d3dba..c7843447a2 100644 --- a/docs/auditor/10.9/admin/monitoringplans/datasources.md +++ b/docs/auditor/10.9/admin/monitoringplans/datasources.md @@ -49,7 +49,7 @@ Review the following for additional information: - [SharePoint](/docs/auditor/10.9/admin/monitoringplans/sharepoint/overview.md) - [SharePoint Online](/docs/auditor/10.9/admin/monitoringplans/sharepointonline/overview.md) - [SQL Server](/docs/auditor/10.9/admin/monitoringplans/sqlserver/overview.md) -- [User Activity](/docs/auditor/10.9/admin/monitoringplans/overview_1.md) +- [User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) - [VMware](/docs/auditor/10.9/admin/monitoringplans/vmware/overview.md) - [Windows File Share](fileservers/scope.md#windows-file-share) diff --git a/docs/auditor/10.9/admin/monitoringplans/useractivity/_category_.json b/docs/auditor/10.9/admin/monitoringplans/useractivity/_category_.json new file mode 100644 index 0000000000..d9ca054471 --- /dev/null +++ b/docs/auditor/10.9/admin/monitoringplans/useractivity/_category_.json @@ -0,0 +1,10 @@ +{ + "label": "User Activity", + "position": 180, + "collapsed": true, + "collapsible": true, + "link": { + "type": "doc", + "id": "overview" + } +} \ No newline at end of file diff --git a/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md b/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md new file mode 100644 index 0000000000..dfc74d7c7c --- /dev/null +++ b/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md @@ -0,0 +1,59 @@ +--- +title: "Monitored Computers" +description: "Monitored Computers" +sidebar_position: 20 +--- + +# Monitored Computers + +The **Monitored Computers** tab in a User Activity monitoring plan gives you a detailed, per-host view of every computer being monitored. Instead of a single summary status for the entire plan, you can see the health of each individual computer, identify issues quickly, and drill into diagnostic details without leaving the interface. + +**To access the Monitored Computers tab:** + +**Step 1** – In the main Netwrix Auditor menu, select **Monitoring Plans**. + +**Step 2** – Select your User Activity monitoring plan and click **Edit**. + +**Step 3** – Click **Edit Data Source** in the right pane, then select **Monitored Computers**. + +## Overview + +When you add computers to a monitoring plan using an IP range or an AD container, Netwrix Auditor resolves and tracks each host individually. The Monitored Computers tab lists all resolved computers with their current health status, so you can immediately see which hosts are collecting data normally and which ones require your attention. + +**NOTE:** Computers excluded from monitoring via the **Exclude these objects** or **Exclude subranges** setting in the item settings are not displayed in the Monitored Computers tab. + +![Monitored Computers tab with details for a selected computer](/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-details1.webp) + +## Monitored Computers Grid + +The grid displays the following columns for each computer: + +| Column | Description | +|---|---| +| **Name** | The hostname or IP address of the monitored computer. | +| **Item** | The source that included this computer in the plan — for example, an IP address, an IP range, or an AD container (OU). | +| **Status** | A consolidated status indicator for the computer. | +| **Last Activity Time** | The timestamp of the last time the service interacted with the computer. | + +## Filtering and Search + +**Search field** — Enter text in the search field in the upper-right corner to filter the list of computers. The search matches entries in the **Name**, **Item**, and **Status** fields. It's case-insensitive and supports partial matches — for example, entering `old` returns computers whose **Name**, **Item**, or **Status** field contains that substring. Press **Enter** to refresh the results. + +**Filters** — Click **Filters** to open the Apply Filters dialog, where you can filter by: + +- **Status** — Select one or more statuses from the dropdown list to show only computers in those states. +- **Name** — Enter a partial or full computer name. +- **Items** — Select one or more items (IP ranges, OUs, or individual computers) from the dropdown list. + +![Apply Filters dialog showing Computer status, Computer name, and Item name options](/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-filter.webp) + +Search and filters can be combined. The label next to **Filters** shows a summary of the active filters. To remove all active filters at once, click **Clear All** in the Filters dialog. + +## Exporting the List + +Click **Export** above the grid to save the currently displayed computers to a file. The export respects any active search term and filters, and includes the following columns: **Name**, **Item**, **Status**, and **Last Activity Time**. + +## Related Topics + +- [Monitoring Plans — User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) +- [Add Items for Monitoring](/docs/auditor/10.9/admin/monitoringplans/datasources.md#add-items-for-monitoring) \ No newline at end of file diff --git a/docs/auditor/10.9/admin/monitoringplans/overview_1.md b/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md similarity index 100% rename from docs/auditor/10.9/admin/monitoringplans/overview_1.md rename to docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md diff --git a/docs/auditor/10.9/admin/settings/longtermarchive.md b/docs/auditor/10.9/admin/settings/longtermarchive.md index 232f455e57..fb5b5b98da 100644 --- a/docs/auditor/10.9/admin/settings/longtermarchive.md +++ b/docs/auditor/10.9/admin/settings/longtermarchive.md @@ -28,7 +28,7 @@ Setting Recording Settings | | | | ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Configure custom location of session recordings | Default location for storing session recordings is set to _"\\``\Netwrix_UAVR$"_. However, storing extra files on the Auditor Server may produce additional load on it, so consider using this option to specify another location where session recordings will be stored. | -| Enter UNC path to shared folder: | Specify UNC path to the shared folder where user session video recordings will be stored. You can use server name or IP address, for example: _\\172.28.6.33\NA_UserSessions_ Using a local folder for that purpose is not recommended, as storing extra files on the Auditor Server will produce additional load on it. Make sure the specified shared folder has enough capacity to store the video files. Retention period for the video files can be adjusted in the related monitoring plan settings (targeted at User Activity data source); default retention is 7 days. See the [User Activity](/docs/auditor/10.9/admin/monitoringplans/overview_1.md) topic for additional information. After you specify and save settings for session recordings, it is recommended that you leave them unchanged. Otherwise — if you change the storage location while using Netwrix Auditor for User Activity — please be aware of possible data loss, as Auditor will not automatically move session recordings to a new location. | +| Enter UNC path to shared folder: | Specify UNC path to the shared folder where user session video recordings will be stored. You can use server name or IP address, for example: _\\172.28.6.33\NA_UserSessions_ Using a local folder for that purpose is not recommended, as storing extra files on the Auditor Server will produce additional load on it. Make sure the specified shared folder has enough capacity to store the video files. Retention period for the video files can be adjusted in the related monitoring plan settings (targeted at User Activity data source); default retention is 7 days. See the [User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) topic for additional information. After you specify and save settings for session recordings, it is recommended that you leave them unchanged. Otherwise — if you change the storage location while using Netwrix Auditor for User Activity — please be aware of possible data loss, as Auditor will not automatically move session recordings to a new location. | | User name / Password | Provide user name and password for the account that will be used to store session recordings to the specified shared folder. Make sure the account has at least the Write permission for that folder. | Auditor informs you if you are running out of space on a system disk where the Long-Term Archive is diff --git a/static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-details1.webp b/static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-details1.webp new file mode 100644 index 0000000000000000000000000000000000000000..4b5c27c47c8cce7cb9d899bb272119549c7940e1 GIT binary patch literal 72432 zcmZsBW0+*YvTfV8ZQGc(ZF8nQ?P=S#?Vh%6W7@WDyXwt3_ndq0dGCE+)t}7B+&d#O zR;(3Osxp$2r+Av&XiJyp~+6CeY|J?pVsN8x!dEIeH}A)0zS(0}Oubya|5*Pl2C)dml3Zw=dvZ-j-6r&Z6+B zUk8x&qu>Jw1U^E)Q$GQpb`Ja&{5k=5KphpeEWIVZfc{Xr={*NNe}VW>03raD4@ob7Ck~{ZjGm0L{6v70z4d;D zpW9zR;K@7qr`B894)F~T035czCw}f72bKa~0KJ!L&&Yt*H{>V3FW|c0-{tSnpRMmF zpGIqcEzgAi4t#=qZF~aXB>|uxgKt1!&}G;w^yAH|aNdq40QuAAb!D&hA@7-3+!yoB z=-%%dSPoq5T?S@9$KA$70n}crzp?;+Z%UOjS$?hnx0AmwWdNvs-TAn{E0SHKMlc3%?_$Nw~!*tg&HEqKjAh^62Pl8iKoX^f~dWwE4GV zv5$r>6y@e_V1p>rU{K|~p8q55bO)(#fV_ER@4y~~qJqhs^-p@D&3xvc<}%@nANl##udQ8Y0v;oon` z1wv!zSvj>hqB{i1LAbyzy6s>}h(%1N-hkFEU_}~qcltBNcpn-m07lC5+Z}#v()!`G zW%hFI$-OQOExonE8I4qO!lh`yfnt>So$D3$`eH1PJZ!3>6~z&Mj!$Cz+o*=BcB)Mk z!0E{8Yd4T~R~b?H@DoD}`7{JsfsTygT}hgK0uzJSse>JHOw?&_xAQb-#}8V{UyjEj z{`gwS=sst!kC53}EQ6aqg)_Io32_ND*`iZ(DbVMlB1Chk2Mp?ecI}PPS1`(QDEYMB zxBlD+VU#Q|&%6vkO<_e+9n$ekiY+rBTyiDZgHdiY+SuBVQjO143?z+Qm9jY4CHa5P zrw_Lug4*SGh$@2U_dfoeD~9Qe-XoY-pXMjMl-LBm;G2OT0p@W^Xd|N|d{&PLYN$^~ zIhkbZmF9}T2M$m0In56BN)&l|vuzL%teiR}-$hl~>;~tjpF?XKI~vOE@k8ebedy^f zt~D?h_FP^%^=`E4&A}@vZJ7R1LTYgx#-VZ|nv&tP=>3$t@7sU4(C3hLbc01l%V!=m zIK)2J8?7KNr@juP7FC6P@1ceJvHmva-=n=Halsef54$M{-d8bCYsSV|_wZyl#&9du z0++DSCEsaS`3&s{u>Tp9-q_}YBrSBU$1 zvCElsazdL-Z2Dyp!;w-VZemEyarSP#WNWe1AldWLYf3E(xy^S6&O4Q{Jpz1)WXD|;9R>im2v(7Sq!nK>_)rJ;OPW? z$IvXi0e_H;<;b(UD5Rb%UXH-wEUSfnLJpbl4+yqgNBkFdK73E*^bTAf1rh~F|4qs=&r|twS!C$ zITHx_#BFud|08zx2@9*2=)bZgofI!x5Iv`d1j)`~qW;IoPf*X-k)wDAv-N9BG?Sy|rmKi-;b1!IeprNUbOu16F1C7azvDEtUwh+Vh3fD>GFMrqX%coHXkU$Q zt|M4ZU5?eBsvJk7{lP3k!A7NX8B?jQi?)y@TX0CEDd*5SHYR$4aQ)BVIFv!=LJm0m z4!5$PdpmQHne^g>hcbP<4BD2f0V8*gJt990l^Dqu(vqP27o7YzQlNdR#9eylRRUvZ zT|_{STH6eGb`ZzEHs0V8{sRM5?uJIY{&d>#p`8#o%*nA{FgVZV0J?~6gT0qRTqaxH zA!8UavF`7B@hNj`bqH)!p$-46C?XCBxW9|dS$e;%(>0U&x9kY94U}sgaM<@*~5n+YKs98_~zn@Pan0)W9^eN+UQTcMg{|DSM4DF-)cVw81 zD0o1Ec*R~%|Gk*X@Z#2(;Id2rboFy{bach^-GA4FD(d^g&-z}p z4=c7td8r;X=tp9{o_KI#els5!C??Mh%%4kzSK$ZbIJocRFz?zk=#6TmfYA7n_N%^R zuJ%cqJ6hFqqfx681}fTkcs$36taU2JsNsdk95ijEkkuCLD|R8VXF@TuW(H2mKaZED z)hZW)zhW&LFK((Kq)5MeA_8io7CFvh5&nfv=lu|9Y5ZU}1MM_>G>G>YM9|qvn;V1r zf=@?z`y;gU)wMVDCQ!PkR#-1f9uIiyKd(K^FjAJ6@iif8yd(C+tOp{?&yOEY(BGp? zt_@=M>mv!@GRQ&lv_qN(u-jm+4^)}=M`$?I%~Ag%^FIkd7F=m=sknK&?uuVNXcoSl$EQAJ0MM8RwW0Dt?s?q3S8e3pyiD{$gU?vOCzwar~!W zQB7fq|IJdCy>-aH7KRoYFx2U7$ww4(tV$BI))Sff>9bKPq#^xd-m-p9 zxG4oO&R8uN5g^jMW2O2(iS~oim6T}<N7$R;AfVO@cH9t(F@-rb6WTuH8>s<1iaBdfWWlSuJQd-<~*- zcDq1|I`>Zk_K#YXM{T$?WR*`iw5^_JuMj@GvW+$S5)zEwO=yToSvvOj3s{{=2D@W>Iq32qde`5-?TB1wjCETKDDDsUSA zH$pHH3K(}mcfb>@CRtLEv%Y|2#I+$uDD;Y^|5Hu`-&|BLGS7RJ)Axvg-5bSO&-^jD zV>^VZ?G!*<|2Xcw)>4}V7{p-}fNB*kMVP=!FP3kVY1eCxSihJwe?N4VI z!JcOA-Ree81G&>ucbhQdyNqueLC^OJRo2wzDTydm9r!}4mF)?^%ElnPm~Vq77<2)Q z{>Ao5T13FBxDy}2<1P*~q|{9HGH9;WJ%8{CASkaP0b)ZW#u#Nq%gc(rKh5iZ$4VY0 z`W;DwO0VBlztZh8sm`MLB2?MLpuYe?ingteOh^*l3|n){M8yco2^AHhx1vK*=+$fR z;`@iLM)2XeJ$pjT1q_I9LW3nf9L}j|Pf1d)5s)6QKBs8Nv*>^B&8pi=tBn+q`c{=# z2cq(oFP|NO0Jz+(K>xjiv{YY~P|mEoCZBs~@9uB}P#kAdUsifp5lAwlX2nt^$Gc0L zrlmgd=~)Zc#7qh8HCKw#V?#Ge@WX2*g>UD@QVdXyuO`>dxpUCrD`v&jNj`yv@}Ve-xRQ=_MkfqTCB*bc)`)pS{Hq$|g&RYny|JkC z_CWSg(nGTnRZOk1L13OFT8f|jw;uW*?fVbt6@{Ytw|G>8Aiw{q@E_{< zpF-kz6DKEfPrh*`P@VN(%8^@b!GJ=(>tB-bi@}>(?<5bR-0Z~G{>*HTZ%5#jlEHyR zruWDRMkzlP$tcdRiZf~qAl9`-9RN?~5m^<>oHxdSNJnrjqP4lL_`WB_TcAs~7|@2p z*!TYfR*P>H%?~UFFItO=;Sl=BX`d3Z$}4|HUSjqrKl#YL-tUhbq;!@dPL_jB+)6_> z8LT?Nhf-*%-#Wfa=yOTdvpI$IBUUJYu^q^ImFv)B)Hu?CSJy0~3TAZui;f)sFGo)% z&O~1lbu#}EobLJki~W-Pz+3*hRI#n5bc7w;LQ;PkzWgG> z+viv&g#VLJRuAaY5?ZxLifva@QeqdssP#i-NI-Viz=0_@mDUzdQe-WT$ttN_ie&9a zITPTyd?I$=O=G5D9s0W8A2a!LeB0fW`{=?%FMv$&Q9sdd3A!TIXR|8+`mi~eI9z%C zM-ko#hDrYRjX8T9p8YY|TLN0GZp52}4x+p8ctcLk+ML%9U{@OYu%xo9YM^Fg`z6h-Bl5xc;VCT?36%lh2Gt4y8d|Sl~}Z*USw?yf+=LD3H;iob&gx}Wp5 zUud>vGsUwvCc&^3?jf+{VEoeAF&sch_P;9lx`z_#i*V z2}18aLTh7;p?Ro_$FnpF+mb@KdW-Y)`I8=nS2K_`QQLh&Oi7GBn(y63H&(Sn8L14k zJWAe0waUJ&dA|%>Uz;RTZv}@1Sx&8*no$aq;s&O!v=12OoQ12;{+rU zbBuL-P_*6rG1)fGb|q<0YVH_~x^5f6cpBkV#{JhfQ}lQRTf7d~Uuw-JR_F;dW1(9I z#g}I}Pg)P$Yxk+-7k$}w*m-=J@k)a+F62n0k*}RR6XupoC*}dX%gJ{X4;u$NmZk-m z1skER`=5E+FRx=!bNm$Lrv;xBQ4N9`3hs60+ZV^8g>zl2f7FDOQZU1nh&z(lxX3xK z7B~|E?4BM5o_lg&dcN-v$t;3V_~Y_}_}n*Ki%rtZ;nXrT9g8x1}Szn4BGt6TG9X*hJ93avKDyy1^ALp)82fB!daM zgVZ-`)mPx-RZaD2IFaEVY&$+?LYy|?zz?FEqP9u*eg2tsu&36x0HO$!Z8ey~|)N)fBqBAwsMbqze)zVc9Ix`FWGp6@-2=Ty& z`$vb}H?CjEH1jn+p*CYEI24w$b6n}_ZgsSps}-$Vyf^lH`1d$f=mn0VPOlF|SBpk$fMy zlkNdGUO(z+_(>v2sxTylW(%DY07P>9?8n>I(X-}HOrgjZQc$}Jjw}|K3}Df8;`a}& zt5(<9-OguvPM>>tLMn(BWt+fjB!lO6ji#xmw;a2=)J*|_w)>_>mZzPsX*C_DI&Md4 zPANTzmBtzj{ZL7#qQ?0_m~FD#my16YGd`n4-}|Cq6Nzw#)YtH`@HOLdE-XQ&%%rE6XY^`ZqoHKBrdbtpcEfK_ z+m4lnJ|{?p#+0*2?|{pSwAc5uY`-Nl-y%@=n2T6$33=(FrrsbcUs=gRq#ANBTPoLWOkJXK>IX+{M4U-V%F zQNQi7!wTm;JvGFvWZl5b9ap7vI7Y56j1)5{?xYBlbu7*^A2lEE)-3WK7L7esDy{lD z*JcRv(p7zxNZsguSG8@5i%9L0!6D+Vm|BSw?741h%cbC|)#l{Lr#uSGNJ-hoMKn4F zN*NJ5VleEZ2=NE;+&ov12{c^?=wDLiUY&pzul&-J$ZrJ07A(-GhY`%36zP2yqvYUe zde?JZp zHRH~iRkDZ*(-LGm5*uC7!diyXY4$FOfXFB{*eTqJV{3h^Vpb=X)S&4lN>!$BLOkcM z{0b2x_=_4im3aq}3{JFv;0z1nJes$rPj9xyw1%el#myv0Xzl`Z=?_^w;v;fFt#+|# zjQb={^AZRei~_%>t>y*EV93uytfcK`e1E3iov$@A#T^k!yTIVw8fap=M!R8RY$aw* z==ax%aMPYj{6N38(yFb8($FZy9b!ot&qZQ|RSs1-`f!7rQw=88bo)EkqZYI!-hOZ& z$;@2S{7e$eia;C6f}rBzGf{^jsuDcG%v|>u_OfznZRG&VBSTcqwC}Ka^xHGdC zrG2x9SM+v5CLZwH8IUhx?kI$IO)Eb=&=G`0elU9(gLz2k`1m2F2_)4DJ9rll)%l1U zncClmdOiDwRE=x_AK#gCI!{M{GR!k9k597ZWJ9;%c(CB8fHjm_o{yJP_~;UlM$UKtMZ8Vw zTBW_6p!B7K2ceK}g&k*f$+)8D)M3vy*ET zq!MO2zm-3RM*Aef8GLWHrzx^gg9#hUx3!E^OFhm}Bn<&#+E*Vy5gTVInQBSTgI>wc z>KxRc$@0^%HzKhqIq4oCxVBDFF+*Wn_&#$%GO<;y?pX=szB)ZotzF?bYBJP+=a3G<2~5ru)ZdkcRFa$FKJSi+XCeOtcr5!}{n@pyEPra7VIi=J`U07^PC^rS&W>Zvrux#}jAtG#saL(LXNstn(67Ak z9!ed#`8E+B3r9We&qXp7E9;AU$?PTe@~c#CmFSsC^m1BT8RnKPjnyhAX=^`XA;d`L|QXqPKq-gL7c+^iQB;@9Y zbCJ{-xsZNNPjRA`7~vwpMKrA{Jo6L!)5AH-{ouIR#curwn>^_~&gV%cQi?df^4htV z^)4O(sJPhy+%4E?n1w{>kB>)MO9WzcL1AIfQyt4Y$TNqyC>n(InP|OBB>rAX^q}p! zW4Jr^GMqBSp%cu4R8!waW!0w7Mzwx?HOIseZYGSXI#|k&hDSlMg{XPm*L#-{T-qwX zVy31nXd*@o*(uA`AFUN)0)jl2BDIrg#Fu$KZu-*qtfSHX>XmRLO(5%!A*nE_QO%^1 zJ804v?(iGc+>x$`u79SqQYa56rtIgVOj{KNYv%2+eXB}`c1$L?Ek(oO2sQUzl4_X9 zS1Ntc-5_~86dM%ow}yW#y_EP*Ta+Ot;#&wkh$jF*0Ul` znKSE$;^AgMi(@#vJg+{DSY6V5xZ=@A$l2soJ$^u^7B$t$=g9SFl}P@vRzGsv#sJdh z(OW3Pwyyue;0VJYSA;3Umf`V&@m!XCk)@zavz7n;>khRLm=d&GM>fj;(4kfS<=Au6 zB%U5x%DB|L`YJ~=TU8u8xH#p4x=CWhmzI-MjH`~IFHd`yee zAZKvjrP=ik^TMggD>tWFG;;5KhGFyVIJ0a!DnmY4qEO zvM^N`&Sg!O3_)~L6@s3iAYgbcRex*N7JoYS!G?#sNof#vPye(P+56+gI<&^;_h`@; zwr(8g66&OgC|kZ_Ic(d49IKB+d9OT|B>N z{SGpon`nT8i$@`1GXg563}$t38U*ETROa=FcCgn40q5nq+C50C13++(G({@xvGr`IRZJ zt`=?yS`_0}=1iobi_&Mn6cQp>8a~6rwbJG}7D|>;5wA@qWnb14`80Y-yl$`8y*u4M z#(8Nezn@a>$YMz$kD?ASoWq=view@;&hlw9*zT2Y5x1%S4aQtI?0HL^+LbhO(li3s z9n?ZP^wHk)rG+L@Nf!xbYpM*zi226*DY8570hzQz7RbAH1d@^r9Na#dM-!{_r@}k} zf1<}I#m*nINZtJ#hBE_Z-&A$;8g;rG{TRCJNU1JV#46PbB0W_st)$G@jqX4qddFOg zAu3^w>bH`N0a)U4HKMkrM(-ogawc&JShT={+G&-NaYqkjcj9KVxTac7sKamG*mQxh z2uXpfMr^p4dHynAyk!qRHJop3`b9Oh%Do|jqrzu=o8}3$s@@48iJ!b168x;QcKx(^ zxcV>d)CD%8sI%MD3*<@Ol`^w^X7KQV`l;|9S?@g>GAS_)znU{=A*%6lbByMpt&;J@ z_`4I-G)&*g1D1Hy4f3c6R=8{`zWrg}V_R9u6ku^Um-$|*Kbm!8rLWc=jvDivXBVZ~ zcxwDiDSyWpTCEd|`^21#!KGq3%cFaYWkmLFbS|1J+;F=}D5axNg;2ctvE=QD4-_ER zeGYqo@qbVl2Jc1XY3&!~u+LqPEurLSJ{qfjty)(pR0a;mvFwbm*q8}J6BmU&qN0GO z7{MdQ@cO8~^UC6BIKS3laA*c85>++u#7V+<*tEnk7A^FPH=2j6=7KsX92CB0ep%~vZcI!EtIsv_A(0abDFQwa5MFZ_pSs=+z-@9_i+tGycYTFpZwWZ7MqPy7?2fe zeUt*HGoAjK3`OM;(>2)Q{+vxek@*omm~Hl8%Y`n%L+S85K*aI^052* z>Mt404=zu)o~)AMNG)B40VQ(bR;XdWz+v#CMuks~BdfDIfv`Z{W@Dm(eVbk(HDMP2 zp}NfleR0QlSrQAOpN}>`!i3jmkXlfqHbi$@Gvqa4!SC|=rXp$s@#9bDh51U(*-Ip! z6zuB$QV9yf)IioaMbZ7`t_q%M@P21xY3<&DkQ@`WwJ3{5Eh?%R9x(d(Rby?AcL8gN zbADs31`2(Qxjvkm1$Ed;s;M$N&TPBl!8j7eRfb@vJ)qJ_i6%7u&sfpT{C=WA=W5=7 zgb1cVn!9rAgX=(2cTn)I7L`AIBm)BLhxnyyRLccRF>GEJ6lm!_~ zk;(L!X%?k*CB?u9*0QtFwO?NyjejFI3E%SaTtu@;TZR;vNlr&0-&VI1AH)@`5&zve zK;ruHkw6qYFvGC?TGBdYd7X>>dr7JW!XCI=T6VCwiZ#9CnHV_)8>po$G&pQMl~Mst ztjAhK=EA#HBc}T0JR9e>g4)W5s?(YEmKhEIyMl4bCJ>A4RS?eC7F~?~{^BMPlrFCV zU9ofPncD&kfWvV5^@BVG?>j?B>EOu6ucXG(RA{FWCM(3oDUJyg>q}(1h0)y7b$#a9 z+GqigS#g9_#anb#9(|j*EL&CQba>0809&OG5DSoC`q)fb6ShB_O4tWB3i%%=xuji} z$x-rnYQ$9{kqpj!T&ot6-S~iZ+dXuysP>Gc>SCi|_C}-vrzCho;zhON%$quC5*^-{ zL{0TIP-s)^YaEv&WK@{Fc1^2KqZ%uJU!>wGHvJ2*DFS~t)uoh$)P_cVCs!9FGj(m0 zslfJ}p6xOpNQE@=WgiGJ#x>k_OXEpdv=uFG0RJxcDFapi$cd6>P;*c)kAJ7`B`Ddp zWC(xn2eGu7D)k-7hF-lyE9jsGS${YP2&j84NV~bIPSLbwXfHu8H(Oo(#S}(TCM{k@ zbR|dM5_eb2#ZST)rFftDEpsl=BJUazm~9@AUmT|Hfl^!LBOd}?_Wfh)X{m&{W?SXp zAY2{-@Ecb2kKGf^J!*RCg+G}3Q_#DjHK*&p5fOuiBfV=TveR5dqSg!se%hXYX^$+A zm#K%@jSMIji7ciaj@%8Io~I89N^n1Gqu?gop?dvlD%J>zE&FwHQQz~Oo^5WN9@(GR^x%zZ5AXwdZm>SOaLB9 z3L{||R{SSuDM@j#mYh}MAN8%D+IMcaTfbK5?oREpsA-kl^z=zC9;uX?IyG2l2NbRcy|J(%lXwuA>1wmM!MPN5 z*e+PQ@WA{qE+r@rx7LD-Ad=iVmN#h@dq3Qc(#TzwKq~z^zaPoI`ztpZ(~E%48u*Av zvwX3^e0>H~_T^uvcQ68MpN!AN2|iJFhz0x#=VVZ>%&RGml#PN`;N6MXfvyW4q&>AR zNQ)o{S1&R6TBTGbzlp!!BWKSC<1XjhX&D~SX0*SB>E(s$e$}or?d&xn>Eh{KlWF;s z-2TSr3%uD*tnxaoRj}c4fWLmb7je}32BTh!%iF*Yt_0Nbd{S}@*hIHh9=;#%%BYIk62onxkou0OvG+m_%SNV-4-<-ZKce27M`LYsd zak$N77n|!;b(5jka26R{F4_5ID6{C2T3>bPNyX(Ru4&qJX;G<={gY@xIR$1+ZjQRx zm$XSdDnID>CyCgl4MsJc=KJ|FT|M0*`TGE~4_Gh(K=(MY*-{Zgk5~fVi&u-JP_Be}wKkJgC<+{{ zk`Lxq=)@s4ehCcUQz@DdhLr-GRtf+cKXo&KDe)wQsV+$tf{Q!gmxzNTKDJZI;G-SC zDD3aE(z6th_t$23^ukqH36#?niQ1??=&pmJ*yQwhP}mQO=hHParS=!?nGVtqL?Ke>83BD?ZUEW7mQnjS%Gh;b24vfU>ktgQ@ z%^;`OHHeWj$(+f>Y?rw)zjwz(*qy9im&J}KC^7mtrjRPq;i`kpA=%fvv`797$3{I+ z`>ymiGU0F}W^i|_-*b`dd5@i-gHTVS|6JuY)Sdp*E{0WolMaoGb#OYi8km_{eu$!s#5 zk6N7r4ssE7X?2Vk^Rwf!&Z>XO7soNj3F5s8;WGATD(ao62peKAB)D{gKJ7<*ZfeWr`xw@TTO=SF$zNgoqTPS_NG0h`D9+cA!)8`#!A~$^>k@d z!cE=A?%h4|YvehpE}t#jK)wR1176N1OcpPlXNsNX!JI^K@EnAxL6bRWTD$}UewvO$ zT5$g}_GswI5fJNY7U*8jQcN`r1pKmWyz~*|1C0~;CF}iYeuxAO4{R-`m6b?~CpV9b ztpehrcdU_kmdy{ft(FixzCP9-++l`A?DdG|hkU~>2|F_)Ed3nGa7fkJT@wlbwm(K`g`OwPW! z?a?P3p_O>wwv*@Bh&kR%zr8{C@B}8srYT$IWDU^u2p+}s*sZd042|GF37(fdZ@8h6 z7-GZtXVIoy3^Ti7j1C7$g_6MGSM*CQ5zpOJKFTYusV6li_1eg9&T6YSuI+Z`!R>-3 z?KK(ek2|tUN221)7ccBf`-2`qARI>hRMl3EGTs&f!LB?8fxr&+?m3jrs;)PQ##(h5D-i@YiQ!t&HSPfS7*!` zo+FLCvQ_z14FvR4;RNiJe{(vxY|EhsdFnPC-G08CM+HhEK_mx!o#THxpLeow@Fvxx zLUT*&@dsoSaHKuk>ylvsp#DUrq6h8ITJx!e55JqYb`&8)(`4oHBw7oQO(-K?JaBb^ ztww?Q6|DI*Zs8=J)I;{Qr)D6+aNo(_njWtz>bz9s?=BTrpSmhGf79AfW_J`rtn2T% za-jCi!t|`-`wrxLy zU3GQ`@G9j=_t7$(^B5zGs<+JH!(ku(ZnUtffeIYk$xezYw69fSj`0F$%<5 z@-rshVOh&Ag~hkcdFrRpy!xZ0@2&iY4(rm%dEXy14kZpMtpuz9R+=@&=}F{KalDL_>f^p(p%FYRCEa;4 z6!o4|-zpg)w+~TZXGRTX*#(8Q=t03EGuTAJVu@_F_!pIXGoh5` z9ND^$X#Rq@S6DM=>SSI;aeibv^-pH*bb{F9)jk5EP!kXuZXrh$cBnY&orz>!G17KYU?sQsU3?M$XO^{(y<{`CdbF6=VBGlc~fs#j6;zgKrT!*>qk0ocz zXXl}7T^hAP9*?XRgA!q29wPwp2LWNk+^<3X0Gi*}`@$G`2kg*YP$n1Yoo*G@Sl4Ry zdxrV+`jS!;8YN4x99kuE%f@jPbgpFm@m`erBiQq?9VUx^AO9wQc*n()Tc_7u)Akgl zW;n57t*Bio%%-_u?MiAZ15`9^(m-RvbcUzY$(NPgDWbEM& z(R&M=bdm`wUQ9FPSbBZ=w|Cw7p+rdu`;W7rvh|+0ZbvDmbAwfdHw$ z(m4>If+8UMdQ*k?FRiBN;cRZ&?1*?Bn18sK5@o_IkKh9A$Q)z`aA_9eD`_1TivdSt z97Qy*IGGP{*c_|dwnI632yjdcC+Li%v&bg4WCd$!za_p!UfPGVi94K1Cnu}7dc!Dp4TqArH*4^e@2s-GqXmk4OZJi)F2qM4-Mea=<<#BuJlQ!)k=8@2gkI=X zhe%$KYbNK#tL*y?dEu~BFMjO3>5*V{(+T;5Vg``%_;_o-d2l)%b0q=GL=P2pPfmS9 zAf-Mg-~uD@GT*(56;`mGhRiHjhDXYnTMXDx=OuTZ1`j^aYI5 z!}V&eLH)zH+7m-jzx*JIeQ&xIv~B^yFI>kofBUYHcHveo-*FZHhywKdXY}49;7(k# z6S7c|ue`W#Hi@(QlSN&J!j;f=q9-~yX`s~xZ3$YDk9ZJ3-5QG#wpUyAwn&V1!XLk_ zzxNV$cl;B}vcWNl=0 zKZToz&MI0i&_;I0F=J=Me)P9jqm^e;Wu4`HmRfCN&c`NR~|IskrV}ixuoKek2{R~5%47WY=LokqBoo0x}DgJe63VKVz0MYwn zo|UGKM$%t&d($HMu3MymqcA;hDKx zxjKS3$WM=zKUt%g)?;QyH7x0?C9rcoxy6yD8PmDW*3&Wyqd!>($rq`VW;aORiJbhw z2dp1ANX&oQ%>L}X(m`FwY~3ABU2)wx#KnOurVW30OpFL-H%qMOM6+7;$GVIBPMhZHz05VU248+k}H@ zKL7De-kGp1%^9P6>7XkFv8{`@j25Y?2lUro8OlP~=X=O_N{Dd5tRr2ifK@iEZ;Y$+ zI7fPrf@u#u_YU)dM=olzWG{pCcm|vK_2osPBnb>MM>~Px<@YdoHQOFwcgJ9lt%$bx zaQ##Z3Rtw8Wo6%Lqa}*zrDA>B!3P^&!>XJJMW|*2h}Q?FGShqs=MZqn#Sbh>@Zm6Q z=wM@la;SDlbY)U}UM!-Exw>=N;*VKL7wNM!$MFq6>KB)-d!xg>X$`Xtg9F#shPSv5EvKg%85l`PJW~NfNzti|6SfR3d|Ho@-XDeT{h1BF%9T1;m~yXO;8Xi zIb{g0a7zd^M7OR-@XRb_oZs2Can5kOGj488Y%ifFlus-Z3NxmH79jE|6aa#r3!CV=((@td_UxWTES7jRgWhCpN!WKXdmu@P|D|tKs z)dmNZdOH3nU!FT0N|u|kiNvc+7>e^K7*n>mA3AmAH+a*+u~Jtu;u7(dkl?c-Taq`r z)RzCsT+glYiRxo_nHmGe8YYfSPJWn)S^Fw`-M}VUE|EMpaYQ2#P4`T)p+MHqDny^cs-_-Na4Nb4bsHSfe7H^ByO=H6cn|*U>Ujc?&_Cp-^CNDcfr_@LK zjC51vL1XwkA<(>oEn3!e?1&SN0a|M!fn0#(1fl;xz9nY;cC7a_pkk<#agR|>p*g1p z#^Dd|yA_TB7C7jtA_L+3Ila+2j!!hhV}0jH2UoSZtPcM`k{yTa@l{^phSp zG2%KncS3!gp&>Y6nzu&&?3BU@{;g-MSTai%WOQed=Va1 z<|$eoQ>Fwdwuf#DlUYj?q1D+{K&FbPiP~^o@7P9u7+}y;J(|5PMI8&7m_s41&YS9( zWDiuYqL+-`k0tiw`NvSp&phLH=#q-ARSHRRF-3+(b>%%&KUZHR zXZrxnhDL)qIJazS&&(un_EyZ=(|ppGdz-zy;RUP}a;+D`455`8o@pd=d?&WJZ7R>e4|w;_6Eh6jp=f|O z7^up$TCXd%v%V;7z7T8ZsfQ;N3wxAxmm2t*iZ>`L&Ktidgo27bq*?Eze3B&6;OHtE zkY)890A3}k?1M7;!ad0sW3cORv&TtniY-Pg${}6QSb=)4N%yPm18+S{>f&%g=@g8rqlNX)S||< z@5Bc8nH4VV{yC}L$j-Nay&E#qR8znV(k1Hu08Bu$zuMCh$nRELy6gc47^mr(fSHXv zg5^{w5P*1Vy3aK@B6&`i;nWde8ay_MNNZO>>WFzr6t8PBxRWkIe}O z`2I5hSSGadYStC1{}SkW%(3WTZKE0+`w(0#G2vSD4hmCeO(5oO`Fr_S$U0}0C#SYS z43QZ)eJWf`xmHO_P20^l84jgp-e(t3R-av~8{^n;k*(_+Hv$xJQFHx>rh$sRxLK?H zmlwkgGHN_^bp~mcz~;8D%8GfMDH2r%EH9AfjdyQe)a>F!hYi!eJaaGx>mhmNmj?>n zO;h$7ddICZXJ7%L4{qwx-t_eCq)bJwj(eTjf^wdfYt-+j6=4HrBF`ky*CRY>;Zi3c zH@8bSAOa5f?J;F0PlQ`V+_bxIl<6G-F$H(AQGIdX`NLynwc)R^_oJt1Ydfa-Ghy zEg4^@+qzY$V^Fkd>W9^^7ShNARCt&A1Y-s4?+|!3FzjuZ*$ecFS39?s?dLhNPIM(< zW31i85Ks`IzzEDac`{7YGx|#obsr_}9aaKFy*})@)BNIu$BXzEd3A9sc>rN^IwCFy zRYOe+?}k4`15*^mIwuzn;oioJv+O)le3AvlWdUEjUDl7I%`v}|M=Ln%I2tT6iRfu@ z`QXSdmU+?i2swZtm5NIXpk?q7*Z}~93Whe``}^luIf=DS5aWD3#y9bxr0PJHJl@fB zSqx-+b0g&{Pz;b$DPT?;8M*!gj1)_B^p0OsT-vrs+P0x|&mYZAxZOCgU>?y==}-n8 z76QyE7&^DZQpeyvpGx#yLlhc-g~ndD`JgAaQ3+GvDW_64B^x>Yk+cB{wm5w$OxsH( zKlO?D@@_33P)#1vQ+nXK$bdpc_k7U}H)Zx?U&zVVbQ>@M$Ke5?4bazE`a?$PWHn%Y z0itsU(~0CTGWKVE6}?HYo3C5pwOa8Y{m)Xo3|4gc5peH9wPCh+vu&{ynAuKsOa;`nNcXUeh}80YxsfPna)c6 zQ3cB);ozP+2wZ8fT*VX|?>@WV`W`P-0&D;l@z@+s$C8LyQT|Lsy-KPQ+W97FbhR*n z#Xwb6f~+ZT5DaX8cASrKToUu@p-Q$OL9v?3v(VXe#LYZP(~y{BPKQ>yo0K8 zHz)F%*>2X{24k`UzHs@sA5&g(mkC7e4?o+Pekqv7{s|{PO^s`>Ig?tpVgt`wDNFRB zrIWv{=?DiX8NF|3HWy)x_yO9v#Q8?*ZT8KPMnj~;ts^F~lJG}2=F}ror$*8Q8Bpnt zsaYz@(fQl%68-LNpTPPkq;#b`A&IoQ7~6JV5jB&G^q!tYpkJ6dC=7m@w~QDt@Q5Td zR}OBpX6!KuP3kI7@A^lJ5CVQa=l~qiaa&9hT27!2uK57)P)zBmSLEHC)F=@BjoBy*DXF+kHKmyKq-h*eKZsmnQ5yZytV3AcHbvuBC!%zT9;@q zARd>Byux*FywsYcT*W)nbkX7l&JHkicB$u(IU2Bh1&fvCqB`Jaoru7DEj} zMWo3m{4sEC2Hn};BnjvSZ-YK4>D@+u*+T_;IHe6RZ)u3@*>w?v`B|llOX;+F1JDI* z%yV8U!j_GD;9d>8n0k8I;|zkzE(WD#<+%PF&it03z<03y5u-q;BS4rL8~ouy2<_`^&7Tu++XfG(U2+=|SiTr#82CKQdiHPVy5 zBI1{>3{R|D?f|)N`*9y+t*!z8_X_*LLg=0 z>Yl5PkK{q^v|cL8_I$wwm?^>S9X>1NjHRo7tTb*-o*VCeUOL2T2Bq5FVWJ}Kw5r+kSxXu!R`ArgaW zy1>$FWsltp_$7-eK$iewQb{y9B?n$V=#Bee2FUvzR8?***P>}Ae4&eB95jivSO^mG zkOXXO{J%vzgzeyh`hPNffqB$+2G5i5d>^0x#ky7(E__MdkXS1bQ{QGoGwJ8%qv)21 z@zWTW#}@6*91Ph?M)}kRk@8&LZJLgH;0`b>pqJ7Ksual5_~_y%ZY8U?t+L?u^Hkekt3=`Vque`L_P zb=s@arqrfx7&lBRJ0taII2NA#bU4-CG_zb|Z!pOT@u=Y2>u}|f`vNfm0bi?$Lrf50 zA4BP-se$et5)Fy^*==?Y@$5SKc29Fix&QzG04ksW3lsnaxZD5$0059`rgY=97eI%wZs?ayJW;h+GQSIu|> zq}pJyJh+Pso?;E9Ub&4!F+rD&<|S+0EzsUmMt?urz6&J5O3=Ao9Vf)%0sc(h5eie` zo}EA5`#W#Lb%v(r5{LV>_<$}N=iK3`Hc?^GbSdZGi@^|*+s_O*YuSZw_^i=n-Y&kvN$cyb7g&WfE~Ds%H%Tg7jp}t!VAMQ z=d*AHV_(8FS-#Rt_nDg`e(iJBPX=Bs6N_iz&S~G`LL2VMxlC!~8^Ky6uU1wDuqc`6 z_Yrf4&=#RLCC|L&Wzgnl`ko%qFO-Zj9J4q3Y)Xtpwp5s2SGCVn11 zfPO8LG{KJ?l2CGKRhG$}kCZks+SUOj>#JQ6@gF^cbb7IS1YgiGgz~#^Da^9icRB7> z)}c1AQB7w*TUjZ|-)uAjE1RG%fCj8S%mOZh|10O1%{`Z!!}(Ql(7FwYk`tNyTZ#1Y z7msh1=CQwVvEZn-Gn*Fz?}bZENj|z3jA&0S!T!eM*XnKmRF5!|8q)JrZ@3-@{gkF6cCXab$v6#skP)tKuBm)}4D5^z1 zZW~Q5Prda(ILJp{tn4gqSy&P3vYxl(;Lh?wJ&7$TI0Q5HfU4ROyRrWebE09rdCSz; z33e9mWc8-%3Vl!xMve7v0#El-cw{jUd@{imKEBEKd|5`h>*^Bg8V{G6_p8qw{NFN~ zo+=pPsGStV-19e_!JKzNJtgj8_51G1rn_4C1+{V+V;Pmx=gYb)Y9J8oGmY9#8XQqw zp(xcLVl8&G$^mpRX|H|zCzs_PriBa7VV&J-qQj`t3|>1RcTh7HY*8N8zFs}rg=2?X-m8UHSETmkPNsm>9_}FxH|F8=ZS30qe zB)uIST>A9r>w;*xFmQ&nw-*yGZyJ41cn>MEzAAk9bMaL1%@L zmE($@khP=~z3~?l_Hf_A$pFP@dzfgLZ{b_Q_&?E)2qU_0W#BP)t|XvwvQBE#VplOF z<}-WXAinWHh8eO5hur5$YFR}OTGhR^P=uvi*qYapEBRf}olGn&PzOGkKMy;HtgREIks0x!fK22i<>U>-InYsDN{{*@BoK_vx!G; zZ2i?WQN#n6Qt~ePUUp;!hXA@Zf-8<%_bO!f;39KKnycp3Ng zdk3znT(zyHBaktRK^zj=AKNn|U1R4)QY4KBdmWLOwP7>1-R%;SUo-2Pfd7;&=3)q> zngUR+x)EL~rrwifJn;00AvTh0do$?jHxbeoK|g)MdC_WZVM@pP5xknWB03Ju7x`Tp z{^p&%Pv>mz;%m)`v;20+&I8Njxm$(jce_S481n0UwvIKMsxpBi$8~?45qKlsqe!Fk z2i2#OwSy0Yo|k%o%OM2S8=Z4_LpEM~!ywX*4odYuHxABwQH>A|M5_`v4t40v6m73c zSC#ujJ955V9@%RcP^$j(ILH+FGj{6vuT-t!j_VZlRysRufBYyD08L<7cOSGvJ^)t~%n6P8X|FiX$a8_$R-AP_kOQ6hGnJHOBB3YN2i)z7`Q-VdXhU6u7>ZqVQ& z&v=N#ddZVm1bdQ?se*aBs+S~~1ks+qH=nrTTf_gG3tj7yyi_P3p2#*FAFLu z8=8f%Z~#oGQ~_w{vM7yX5aD{XVF+x$gfc`>I6O#N2X>3YshZ1fWM|!v)fM%|d+#;~ z5a!lBM^5!t-G;TxCitx2TQ}!v^ktmTClK*~LbCjpe;Y(gTOq5Mlb%N(lZ8TK5tMjU zi(WCJ$K*6&Xw1A6xH$eJx2&q$0RiUjkn%hR)gIP2IixSOtmc?8v%fkW>q__{u{V#xDb zITuwdt3~Rc8l<6%%b5feuv51edW4XS;pPnhj0%JrLg`(5kC)wzcFSan{dyHG`2nCB zy88%+NGjfR%!%b%++={_=dR|VMZ7f@%uV2>G3$n(%!QyB2rgmZ?&KMnH>eo>sT-nN zp|yUlZ?ClpH7z9Z7iWPTyHQ@N--Xy>V=IEw-*oZYG;ZMZ1K!kgh+(>13;?;UVI8}wr-e{~WsyC%WL)x_GAsjnxT`%MCkPp(A zPL_ZF9e^p3*}N#j-v90SN<_nLQBcjy->pcRTd5lEfbL*ALq>L-Fgh&2BgHm#C+!hu zt6p>!f$!vx##*@@<{b-P9qOAKX*RgZO%Xo5<><^z+tndqjl;N1Pa|H~9r}3dqvowl zuL)78nfnbr%8#MFV0t=uFS9IMe@R;3N&Xm7;l_sUuH3qYf|n-D6*N)Ze%0b20Q87@ zQ55I^=C!Laj#&pjxr1KWMj~ZbH6<9^hcSp z(ftH!sq0~jT>)G|ffv@+H1fE`K0LfozPuJUm=fywXk{SAqXiEKtcayi6?$JWujL9L{6 zN8hJ~0#qjVZ1B0SL{JE*hwMwh%ZZMsqVLxrn46iO30esb+9npmqSk(ZXSH{reGquh zqCpIyed%puE^~ts5RDi#wp5?;8Uj4M28liHk9oDOCr_qskHSC0`^{iBEV+i@DTRBXTKRo=TjiTx{HGkS|3w#6Fxtdq%8U0y1kKK>D<}9e1=k=kflx#X{{5_O3M5ZZ`s(-?asY@rzPT??&3>uw$2zY_Vh>6PK5yMN?*?aU!du$_d;C|X zD;xoG{jc*wF)^sAQ1{M_khrs7i$n7`y16g29k00KP0*22$%3=!XU_^@GLFz)!#d`# zCkGXkWRMiDJOWW}HEJ7;VGY|AWV-mEcmx?4e!kwcMV8Nu-96}-llzrP6FS>ACw=Y| zHM5@_tASiaK(urpm(fDBb201ylUp{&iuHxrvi(-P@#)!7<;fJ+W=pvE7Q zj;F+P<7%wBYU-bdTw~5u;?M9C%0RzvbkD2&Bh~=MMa3>+@o|wy1`V}ERXKxz1^@s6 zK~iRDJDlTV8|z{;nK{&4UxU8gO)c*|zyBIGvK8DVO^tUq401H+_FVWm8?~Pzru}yk zG+j!<(Gp6-YcnBrAOu_Vb$glz(C&BE{IN(T{c7$a<-Ez;vh9ppwu2lj z^9D17IUz|e3Xj>s7glW)%Tzmn+s1TFO14#FMkyt=Ik} zMT{u+(K^#VF5$x)Uu<$_Ia~%=J!-rH&Pqwkddej{T|$Hj2C?aWagf~WZ#6bZ zAC}Nwe!!3wBA@S07;H^mJSrf2$RYSFr{{oGExJ^(pv1*}E#(NjNsn?N6gNQ>rgLv2 zvahWD5^6ni;Z2%V-^+_(>?`>}=-VxH;EthP6NNu-+ps^d)SJPq=VWY~XUYnl{0pOu zeKnHF(a%zU1>-ldH1&{lA*~l{-ksn9sjhlB3<^5T%luIP!QhWnJJ0P*+`?=5;|hpz z2+}r$8NcZgyBx_p&TV;8iZzRL-VFK$-3$65~)KquatNvEi@7c z<&n31mIzA4u{iSODp^n595QWT@}@9{(*70vD6xeS%XP&u@D^V{x4G(j_-vpM1DO;g zgoFSF)jiD#nNkf&2gbW_>(F%=>qoS2KP*wrNs$Oa(SYHa;aT@6~ihdHGw zElHm<%Pu5%PJ?E@sAPMrGM{xG9Q!81dXQL_}OVFH;ixa1NzGe zuzU1@pzXk|OBk;6W6qZr@sEPk^d;f#NFoy9N};?*Q5_=LnrD?-{6KY_#IrI&j`{EQ z9(zie#k}_;=tit---8O6M)o-N$OXrvG$m-{gNlIhi-hXJT^7>lz5JT(QCj1~rj+s= zQy3xFLmDW>CQH8oGc!K%OMr$+92Mz5-t_Y8${vWsY{aDO7#Muq>$Vxo&*lqo?9|@V zz;-o(0n6_u?8X9&kNq+gyGkSv zDb6C=liLx*qbtI-tWZPP(AY*7YE!TQlT2Jz(ue%!IJ8XDC>v8NdF44LQqT@C<(@^oEnSIC5oKlK!l{d>VG(+NpXGJWg7QY2~Y6w~+#b<~dh1tP=k z2CdcEnz)y7w zM-C%@)Svau6O#$qpidevfEU|}7hH7p&l}f@C(7mC(OHWAzDU`F5Y_jhR8glle&#!??8t(u; z8Ix2;Y-kMcHF54sLPagaJPT6)%6i#^A{7y%;bsF_#68Af380wtk!mH(^J+Yqxn6e# z(hhW@IV{b80*~=29;C+_>L?6H4lH?{TE`{N-Kc&h^`xHPWYkQvn)R`nZgkdyUvRyZ zcWk|e8!u2lCghRfcIioZv(8><9$AfgOt(klBbh)MJw zin8NKE@MtX*eMam0V;)Xw;2uU=z} zayB70pF-GAc=cR26S!P{%*w{WL!`4BxvLP2i!B%_C7LLrjX0`roKnwyz;qAJ<0%i0 z9I6cCgwh-Yxemev)(%EcDau}_3KGPa&s{0@!#y64jvHhH)uVI$7)(Mzj2iSs!Zfq2!U8; z#x#J!;F_#jXd~W`&mNF(H6k(QVebvrIyUKr0Ta1B7s=6GDt>|=H#r!c@jTVGf0F00i6lz(4qG5xVv)HgpPfO7z+ ztr;A65z~E6CKCGFL-63xstNd6@FfOBdHhMHU;qs*2uU^_O_gagw~yx5)jY+?7*;4o zk@XMnpeGxGmHM*BM+XibWS9YHC`pPsi8%Q80PG>(=F(hc*!()}; zkg~}uGRd?o;)r4;Iz>p?p=poVs;rE`-GQbpHi?mxPt)#D?i7|iPDDLh?6mL6mKDFJ^7>z)i@-;%S5Qb0QwZcOB zOG~jlywBIyK$xMLO#Cu#n^jZ!c_n*B-*G^y{*tDwNeE?Q zr~Lc{3O;1XAuiKnV62MM+nwl-Hlr^a;p}x>jRL!abxOgdC~C@$2!F;;sDiQSxp07j zsuM)(2GPKzmZ%Augy0yuNW>YYOD&0u%hj|Mnfwc!sw+n!m(z|FSuT+zMmnt`jQ%76 zj|Gko#R>Fa6~AG7E`zXmO3a`vH21JOT;DQAfxKzeZhxCzZr#>3B&#MbH;fG*vwfI2 ze-AUa29lSBVN_@r=H>+BS}L~k1S5AjK9KHC<|wr?#Zb9=5b^-Qt~w*;8*_2cTEi>T zGGM^!Ng(pH#rhWBA=xGB=y~Vhv2G5rM8%k*YSpMiT^v`8svuI6nHlFMOcnsC@CVu_ zY6)$S8ZW*Dhg}UWA0U>t`;6_1*xY;Sxaj_=BxxtvZL4g6ySHtSTU`hYKHyi-OG-v^ z&rBxO?jgoFjW9y%~nuRxs2Q=Y5g6SN)7cmG2muI~HGx|j0h{_p%<|@NU zTHjU!_LsHg1wSlMuP}H1h61pLOH9`^_(6xfF-4ecJHngE%ZAq0noxgSF(H>JumZS| zh+i~uuJB54a^JL94wcVJ0!xQV=cNH9#6S#n94bChD+x8hNfRHe%v(6UTnkyqV2J7s z69glzuQAlX>@~R#*qS5=PvwEO!gXlkFE93?ojO;{B}V1tE*vPICjI(%@Jk7kF*fld zvVSRfEy+Q%_%q-RoLwFoi3MdEs&dGyo1rkD{q9C>iCKrvPIR z{Nuzn9``-K8>9iPUS=0{>|-#zRSsqsilNNR@EQY@e}WMTRb`h>17iQ>@7MoEARMaR zk}V=5#Sgh)#F~_#F9-xajgDMd;5<2SL)pTU|4`xlHR&us=hGdRns~xK$0K>qZWR+0 zRd3NS>)ff2&|z6%bX9+3S5+od)&npoEI)Eoz*K<-H-p_tY~69KylrsXm8|*4ks-|~ zkcjlB@>8Znc1!<9IEfd4I1VION|W^Oqi@-n58Hc*tw zgx)K_8BGUx2JP~57Oja)Nz}fVo;?{uhW+ zNPtuL1NU>1XiiqYQVUQYn+yp{*4E<)75wG zimh$UrV-0=?L zNH#}rqWOT&)AZas%W&a&n6``~pWlY}P@S6sD!miw1^QwfA@F45I9U(tS{>R|D+|~| z(b~?`V56+1aJ0J)5E23?yukM3U8VEy!lBr(;1dFnTC_$#A4Y%vph&`SCy@_Jm*aE` z9aJyM1p2haE-5;bEqZdlz&?k#sDtut#i8dr+OY_6I4`~7R$G9SB{sL^%>95M`Ll8r zWc+Aw%|r;7znClmQ{WHD#JDBd!p-A*Ah@{(Z|Mst9(lpCUuFn)xK82_RyfT`I|y|N zIGy_Ng?JTcedGYS?CZ5uXhgTA8pj}mq5Juufexv+w26&O3|_7eeP!%;3H?%=c%aSF zk_$|<5%|M8k&;@TtCnNrhM*MJDr?^by^GV6?FK6q7Wl+U2UUk^3y4h)(6#or0Tq%m6!^fmKJ^ z8_QQwfxxz#*BX)B-=EAlveUK+OFNr~?D8nHzE2FT192(j9Q9Z?GiinqV3ERtaYJU{ z6uM6TJ`FsePG5un1fAhtQ3>KJZ_iDMqQ9d1rb!Rnur{h$0uD@F^}|n3DYi&M0c@|Z z?9lSF0hV%kUX-E$v|SeFGdRBynpx^w$hM^LHju3!@m71p#*)veN3nHILo~K%{EF3F6z16T}|aX zI4D$E+B>X=LN_J0lJmVKfxHUd%fZz*To=g-LE980DpuIrG#Jc9WyU0RQ)zffL4W<4 zo3D+}=Zclbj+I6tlrft=NIop|Fy5pbJ5^pj>l9b~Q^BxqzD?%K!iX1e=N@b)(jgxN z3DSw`);1O(1@w3eIpB(--%7%kYD{2ZM#QX(GK)rd@o}OBPcn2x=w|hzFaQ z9VT}!qD_!OC^B{m)`e$5dPCpS9j(Ai?ckStdNhfYpR=|F-jzm8^-qrYTNgTK%C1Xk z8*QmgX#$DXHS0SXX$f}74Z>-9q~bToFISS6@G(I#F=YPsSCYCzwlk8G|m@uE+Frnm7Tr6uTC$JgU6LIM}!bgmw>AgU& zq9&ErFPsgHp}uOTT=IV6{%J~cOnOVeq*Rvi04y7@0-r>aC(hRa;@E{*PP7uLX7oR~ zf`q$)thi}TR z0T1B!K47*Nu-&ZWS3d|&Z9n<@IDxLn_Z__eq&C$9R;!#XN{n+j9;lK<8@0K>-Y#`C zPYI-ktYS~Bg3aaLuS5+kWSnzpW09a(v}(=)zD!(Zn$1$**Twb5@Q?yWDrzAx{#+Q& z68L7u$+(EBkmN!rmPcH79cb_lhZ{Y&`$N1wb-i@v5|XqjU$bwZ?Q~3>?*dZ0LXqET z%gwo^qLx~QC~S_j;t2Q|ZZMNjHAQ+U!|j_i#AX8Y%6*0`PDgep56ZW>eCoXHqrEFY zv9tV@Wk6D^FJ;kg<>Z@&!ielGf)K{N!MG_^RO#JJ_Eux9*XU`z!4~+&+!A9SPUZ4c zrLItYBp{?!OIobw6vuum1!jnMA-WFVGSJ|(&3zZ@{<(rp1#-0*gD68~Fu-o+Lsq}h zxcI1`vT0HV*Eym9iOa^=1&R;W#J1ApjJNyO+5pUmX5f?hE;zY%OjEzH_@y% zND}Rm1HhijCnAFI#lbaR7qnMgTWur(TjBNw6Dr))YZAD7A7@|z-=H3|Qz034LN?>I zVkwxNR4P=T$EwW1wu4Rg=PW{#RF9_XNrGg=qhGH?@L)8vOh`^COKR5k&JCVGus5E) z`RSakQ07*eLYi|9ZIM_KF|do1*Q1dIG^TRI_~|eOt|hQ$p|}q{DQ=aIAwJb<*8;_G zWRlEN9P2`Zx~o*G$^=AK>*OFtk+xu1O!@~%ZWp_Mn8%%ql|i;x$=VF)M;o2p@;S{q z3f=;rn0hx0^#fdstRo^xjuQ{K)cY<&JP=z8P+av#41Q-#WDay_5H8nB=YG$=L@oq} zcqqJ2#Yb3vIrnuKel(?SQciNr$*3WwR%l*EYhex6O-ek=sd~N8LrTttxVw&Yz1Hup z&wCmYOD5jS~K2{$88 zv#v*V#!aF)36(zNXKDVa21@(tZHZ4Y(AKr8yH#j3OGf~oach?G3F)h)&Tei6sbySx zLmv-2p;v1F!IaIlRO!j0WL!z$a zUDZ!IlyP9xs(d%#<+9~)*{JR!EB4=J>|*`MAi{?>{ML3I+A1ae|DpyPEyK_kYi&En z?h3H*-=mJH%fbff=}h?+z~m}s(CzCp1rBT+*5g2BN_v7^WtG^t*{O8y|4qG^(JS%LELwi%y_ZX3nJ(~5XIhibbj9FuJ} zMQ(N>C)L5N2xDm)`X~xXm|g?=ha}+TVBto9U_4Av0D~%KtosrI5wX#I2=!T9wA8)jP!yI zl|d_|yX3EOvxh{CX*;@_+BRG2ccZRaqb@7oF+C(6A8KLon$ebe zAQ#6MA^L9`Y>SJ;miKk_BD*`NWvz+!91tLzeZ?M%+)htXqj{?v7z}d^_O8~Q5{3KX z?jtPq3bNMgOP=>r!_w;J%3qT9r?_8Aq^-O^a|#(?)II06BVg$KENzeY-U)4+sVm#? zQbUy9_%h}{iJg@)48w+??1deI=RtrdRiMHnwoqC#gJ{3L7Q0}gE6n{5Mau({vaZf6 zeBzLkS+NpZ2+&ysXkalVvuOcZ`?UaJ=FFFn4>^=p9-`mW9ngG#ckL zYPo@cN2UvA=p1b|XZ%IyuXXQ#bBYd|u75H|X+ka>xg&0~vp-WL8Hu~2h+AJpK}(Aa zF2QBwvcNNb(|RSkC-saqxcSvgK5Qh|#sv?N|5hYC$y&qnlHRI*O$Oj}w*wCn!bS6Sxe^HN>tJ`E(GAgdLTwYtZdA#IqOpl~={k%}0EsiawG2at#}4LYpMXQ&l(znE$uM z3T4UL*QCw{VH6X;c`1J4e1LGJK1oBB^inK&9r=Gw(75z4oPr zlo=!a@o0=9|78w#H2a=V(&T<&yx{jw{6@K^v$(}k!5jXq!j|(*MxYZHRx?hVq+(L& z0-zwQ0vjL(BY;B=*iz<`l^^V%({UHk!lf^={kfQqgf7(EETV&d*{CUiJd?9IA6ojy z3{L*;ydH73KOQ=amPocM;v5(#22}tbkq{Ialx9b}1`>du7Gc4FUW>jM0j*L%2zXxH zIfA|G0{}1>frFKSln>yqqnCQrP%#S7m6e(Y5@xf7gkh-Y;HmhzEPMmT2JY8@XvJ|+ z5N5W6!}P5A$->VJ4A9WFZLx(P(L)fk_7%yKLCo%}72BLd4Tk2>rkbO4C&WxcHjLD0 z_<{N-_j2WgW}&!T#tG|wVU1^Rk@&u_&Yc!9U!@a;;!? zxbfp_{pn3(tJA!bwiV6lHWydymex9wjUae`p}92TR=V(bhBG_ZRo1jm5XD`zD*NOL1qWG>f*fuVa7Xtoh?S-y}tNxZyP0lMNdvGAQs5=jbTDwqgNfPW0T5c%~;&SC8*E@!G!AAgg}xq-6| zB~^^NBQ6qIXz8XsV@|O|1|Hzp8}at=KspS|Z8LPd>iKFRxwXWY2obN!>e@e73NGSj%BM13 zt(0MqMH@pwOkY)ay?O|2XjX&K+4o@M{p(Q`&*9{_Z5H{`bi^o!O|l36|10HKa5JI& zq}4{H0eo3ExOl`J3Q_^+D8Hj2;v`LPoOW?9wpm^hd9aEp8~E7V&)0uWuQT3Fek-BK zjL&%G4!yn-Ii88Wa$+5>e*EL1_9ma)M2kMQkU3-ZGu*lr%*QpR&SM3rd=b+FeW`RW zoX?9F#rKR1Y#G(Vl;Qxf{STxIFG1ikDxg834n!tX&MiI=CR&Gujs0lH9c?O^r}!`u z{M30M7A(Xy%UW;K=Yd1YGK9O}aaBdG2y!)JPsiXW@Hm=VlS5^Y;K<)@Pa^m7fM z>1_&MRVj*;PBx>#qan*-260wlELTtG+h$Zm+brvV#EFWYPO`CuYhd@%q&r# z>6FD7pU3ot1vqE)XeD0)epczu*P5$vnrN%9B15Zn_Y~Adoy(WcC1&)9^?!x!Z((X- z6W5pRYhu<b|#%BHtHuKf=u0BVH$=4e|d3(dPQU`;fEdap$)=fTccc&sWHSqqZ*N zDz7i`=!7mIrg$}CQy9D?D93gHvdgwL-sk1{9IYuNF7L&=!r--t?u>*};`Wm-X%BL?&0IZbu5A zm%zhZg{!%-^}LN~qnIqtm5nlwBdM7;cm%(>VqRoSQkwl30OohD87>m{hmeW7-(Dzf z%8nRHRTB*~f+OvY3LSZ&Mcht(aF+2pPv(OnkgrC)GSuTdg&-CScr}`IK*D~Ou#hN8 zD06`#@tiPx%g`~<(C5ymMT(iYG??-MR&LG0Mj|YFj7@F&4aID!e{|Id<9R;9ci;%8 zd<{@$G{hi-g<1%1w!F~?S5244A1@5Meq@qoI7i%B8ps_6(44a_F-ET$JNxc$-d9!L^6tTYpM zCpBocG$yQq_BDG_;_$FwQ$qUNaki~6q|KE{3^3?LGkamd>N-mnM4fW`C{Tp~Yv}~} z8>rb>Gpjs>7!v?%{5hZV5^qmnk@_S!3A%N!K$bsqm)?)4SFqhrwJ@Ss7!?eXv}WYq z0KsRf1a&aUK6)$!uw6sd8*+Yvw98z|cMv~F7~ERa&ew`oJ;Cof9+C%g-n!b`M~PFE z1q#!25X!5%Mfj|+vG-!X?eLg~_rpdyiM95TFi)P9SUV$eW>QZWUPFk<&5Uc(vYo;4 z7To3le1`^}FUW~qin6{CC)wJ@&=>#lOMT7_+`!~rSWPDNIB!IQO=DPD(5KllL$NL9 zKCqQyd@yiz;o}e>Y!W~czkqv1`Y4H$egdQkva^U#X&FUq9L+d6xoqEEV7I9Z*Wb|faxrHE z8@_zKgIO#%>#FdY;~U?h_7W)Gl8THm69CQmVCNPd@G&98ds)Nm$h~p579a%z&FWfH z#9O`(#H&9xAD4vHt)B?`qh5wEx$tg8dTbP>qRR`tPlg>>dv)zJ`5~Z#8ouCr#o~cI zFJtGC6B;)N&KJ0{g(FQ9(ddb5^+>YXe?y$AL3am_Z$insH}XIH=Jb*Z~%xz;_h6r;j_tk z$TO(iE5>Ij1dncGmkZf^3gJobG;f;_AB)A#PAdeBc7$dhJDE(r&@?q zMD+79(|%n(BIv}xtISxHE@j8rv7+3if$iP__oLhVZ>l^yS`oucm9vRTgqDwn4A+os zM`_x~mxUntb(g85u)Gm0%$cqrof5wy7jS)n@$#qFNAa3HO=4z5wHv|?vVKlXoY`*` zyZj+aLy%Ek_5>sJ#+&KEU9(sfwg9#qnyTmL{~(YQZN%lcCYWS|0{R5(dc0=YXW=k{ zRw6SkD&NC?{cpSQ03QZjmxR(Q?5jJ7U&t!Fj7ZbUQ63O&gS+l=<@>+M-2GOzdqp+; zhhu<9;a%kcS@y#LmM$C&OhobKgsQPuvLZ0rj1np**`0rOFmHj6Djr-WNQw$`4*I&} z(=PH=W466bL#Q`@7;(F*aM_}HCbhI2PH0^9|GC4@-rs{N4z1U56Z~@2Eq9>!7*EuJ z#q}pp@bgnxP~@F6mnaIfq}#S_+qP}nwr!iIZQHhO+qT_3H<)DBn&_qPN9>?>Red#~ zhjykB71x^GsIbnh7vWwH(!;ENIK8D$0d%36Enr)`Zf-fX+}uOC6@*eRw*aU#pasKW=g{n9;wK; zcNrIyPZQ~H0J_+Ja?{>D_(@q#Se|Txek>4*0*Aw9E8s8oO(+h1 zw-h(&Ok34I4ruTlqSa9WGuOb`O}W^(eJBApKOP;=-&i2~U(K7n$cEVi*7VuE&i_oz{S-Ca1a;P8F-Nd{qtyF;|n4m=M?hx zkeiK0hNbuN<%>Cc7v4!hund%S2e{4W^vwM8)ayBTAfEc3Q!KFkMm@3 znTm9`YR4c=yH=UNx_0%~4&}~J$vu?bKZNz{bz!G}>8yoGd!if0K_bL^Z_>qJo#uJ{ z8v>LYQ|;o)><6S`o5Sx+1&7WP$#=aBwHn!FrT2l>lA!XP9W(q%`~$#ceHo16s=eMq z*w`MvlkXjmXzcGVZ2Hvz5Ph$qZbW{8>g^>U>zUuvDD}I zi7R-Zi>832d2g-al&qsOUXX_4j_FJomHAnTp6UszGaRM^=?Fstuv(O520#`pL*TK= z^PG#=1+TICTZqBP4bwbv{_usjwtJuZSXri*gyBqYxVPdOBzqQ<>xH4k+TSiF`K?Ui_a1T-%arw@$jgCvcG6iQ2+6^y6m)ybS@WufI?*4Sg_)uOdoCznYCR1CZ z2?79!N1~Jf03ZsTO9fm@tlpiFbcM;^H#7#)K2fDDevU1IW(i1H93mxi@LSIA+b_H7 zH*47@d0)mhTnquMv|BghSt~82*=9iQ)7bjt9k?I(TBR2IGIN`!Y?dFor`?uxRli$8 z@aejC_r1Kod-}?bmznN|(oN8&Uh)-@o}Il+Ppsvlkl56!)l?y@F)omqOQa3%h`8M6 z3P#175OSbqk(#O5D}H~P{pdcG2~&V~+lY)PWs>#H5Z9C+KyWH`*Nsa{rKqLl)8hV< z)6nP9O9;yijJrv1jj0}*W?CyqV_ql6iZ1-rIwC>o)wk9Ou=Sq1qNz*brUpZ`7ZoV^ z)F@&_eJcKGHC#+kncIW_>6J-IqMKrT`jT4E2C0y`*J|hF;5cq^mq5|im-`z3R+KK+ zw8R9NzYi&msa0O$aFRJ8pg9ls1c4iM7e6gbR=ODxm?7~UNUPeVZj|^3K4~h;ry_li z?VcZ1*qyHR(2I)x?Dpcd4v>~5SglKRY0vd z*qwnN)e~`bm-)Nx$;0Ee1`c9p3j5T4?$=~cAM?>grv^jV_?9ry`rLXKZ?Xb6Jw};x z*04e|Vf?v-57VBI$J#{j9=zc}49H-Ru3d@>pkv!f=Hs!>J}#)yniK_7&O8eJq=yV|RDvCUi1)9<+>1H+gM-_Sb1AnV+F3B}}d zgJM+jbX(rHlkV7h^k-)Is*P=WCM9{tONA@=%okrW!QhC0zlGN0r#Li?8M6*(+d2LS zwAfG8I(xl)nMnI0{?%`kD2DNUe#MHR>|anra#*+E#CIL!<-X|6w#(V}Px*{P6uK_74E;cF_FQ)bz0f`D*?<;OJQFLejwnUW3w@OHS%nR;ocRLpxh$6PxoRA2Z&5AupN}&}@KmK5XQ9=?^eG!uqq- z{PE{S6I(lCHQQ4dRsAM z7I~bxI`7C?;Jo$+dJp>h)xP-S=ybg?LIYD@5-~30wyFs8>ced9tw*H#kIG8m@H4sG z!?U8A!lVw`xmu#jZ`Wf(lUQJBywJy)(b-kW0KvttporG(FcjW}*?cL5gJU_p*!d0bU48Jj8n zNsFv^ful5GubfI$iSs5~Bu0Q&(mZFHi^WxX{Ofp7a{sD{y_!%hO}<8;s(xF zj{}LLh6LH2oYkU@g{;Qujn!M|=%K+tS?Fupu&tJ$WHwY1hTuY!*;{e&ii#UdB-iL0 zLm?E#9fL;wbPGIOHMMc>=JP96}TK`AT-kIyMW^a&87Tl(30!^Mw|n%{+@ztR0* zE*8#%ZD?cFrPq@4$mGHQ=68$#mukZ26+Sd}x6X&0$*TTaJ^)N&2*HYK-nlzR;z0E? z)>JGA(e?cQ5OJSq2{L;e_PZMNOf7xh@|!BhPsz_pOwjs4n%;Kiq=<>TII7%cdULww z!wagl9qb6qLrbgilfCG#aORrb-YYXXa*{F2sbgWmm01n?vivV?r3vOmk(xhKq$XiW zFF8>^vJR=fr^L9car|%N%(GbHp;DJ5f8i+%(|sf6*?gyRQl_D-`{NzloFF?X;B)5? z<{L-v*GMun`VcwUG_C@X$EXnKJJ`VxpiuS2Q?Hc4V98^}O>5`Y!_kK{)|E{5Me^nt z=kgSFoCNl7mnGcDw}ob={Z-D4^JNqmupV_kNG{Iy9Dww67x66|qxSWcHBZq_6Qh7* z?5~R%rw3vuKH<|lJqVxQDarN%oHUE~!8qCbpFDclpl5L-5t)1CiO%5nT`+S81lL<7 zp~tiy54(}e{n(Y9-LVQEI?swbCuJ66UPPl;^Mb}KPvxWBW_6?qJqf~sV(!(Y8cK6d!1(ufAke~hE6 z`F9LqFLyJfV=GhT$-HUf-41k>%U21OT&?ry+DflfnWG+KG~3kqU!lfgj*|0M%p<3# z&YTnyFoMqNPPk0cbYZE-@f{?jaUU^BnCwFTB~A~;U}v=qxqEA!a@%1`nk1$peDt~`)$W&b}-*m73&!vr?^Unc&H zx2WaDe3=smkE{G3E$0f|urwd1%18QKUj0f7S&>x~4n#7bQ{DI%R4Kw41xNqML{BHRh2I9x|1|U{Qpse_1$JoG!^r1Qrwip9E-B>Knp5Bz@ZVi`_=}S^efQV zq7vNs54lT`G>NeOLWVhAN`G6uE)8k+DAbkHv08@x#=uDIb_kh2sr`sC0onBoKXMUw zY3g)GIv_u%6OFaX7}H3#h?>N(8on1FDu)og1)l;sG`!)?>!~_qb&@r(s-nj$){&$N z$*3YYjF@#!Mg4(Mr8gNinnX2)Cy>#+i>DRE1O1Kwx?r*#(i{&=sz@O=_VgmDF6Fk+4s@>2gRp z{$!WlmW7x^m;os+nnef(^erCV;ritiXYtmxzC=6{0!R=5`Hphv6d0QukMIpP5rLK9s%UcVz1@!jFPgJkbk@|K+{Gud zyBt3hf65Iswtnxe4Oi4LeOlQ!t?q5`JNsmn^_UlGuv>&ld|@4}e_Bzpc{2;nCPY4l z;*$6LY4WFqz4ViF-o&~5VJKV3K^&(v3t)X`0P8HeH-;RL`4`;c8)l2^QwCfW)VKn9aWETJxv@bEREq_MwpBk z=DMk62&v=lDQpW%Q_n7_3Y)q9+=A+xJ zEz)QSj3xVFmh(rqQ#OuR(HaZcf5~#}h;zD@L#KGxj+zZkMF?L_`mK6o3l11?OD3v` zDsM2O;g^Mq$_R$8Zcd1o9_5Fj3}+k!VjzrJion3VK08CYC+$%>X8ZMb27>EL$Lq3^ z)O0|U)=Y$7@L^;E3AwP48v;jBctUB*&^cTdAU}H6<)yhhFCx!yvY^ z=mye@9dVaOn3%j6*@!9BR%<4Id9D-^iiyh(koJe+#08MD3{gVD1eJGmVquF6{3&}# zszv2Qtf0mF+YuFcjW7hy8KyOAOPRnVvq)H!#B0f}9*n%#A^Sk`;8DO}*pqk2AG$S(XYyK010gf7Yo80#N!RF2 z3I<7OG3FBY+d5@IF

jqdXWBk>Sylwf?2n!F^ElGSE(PnHu6T6Z)K`e!!tA6a?q) zvA$0d@B4 z;VkcF42DxO@0{P2Iei8@l__tUXJdO{0c{p=fT$4-AJ{5pFz$t$~;XtF^@TiiJ2~CKa1_|#buM)Rr51`vJ<~V z83%Y~E&!51{3BiC&-ibdGrS|TvWTljyHgaPd>N-GbH+0z!j%b?gp87?k zQivpyB7`=I)9{iEEdBSB;m0q~l6-Xoc>g8+@clrx_OdlxDT3x2iL5t7jm}`FzPMC+ zW|l-gY;Ca;u1wPR4qmTM)yCx&mGzZ8A7b<|rcs*|Za>mDbcsvNr2Ly)1MI614Xp+m zf{i`KeL&K7Bf%&~XMVgYA=4~tj25^yjp=P4$twr$FBwq)_NU_`F5-O%Jj=+3sL!Gh zWJ($E9agp3hY)+~v;AHsGoAVPm7?LRy_4f^m1E%pMUh*aU$vUFyC)_?PjZ(Mh5o_7 zDAGL1eW6&^t67LG(y$$MTzRQ`HM(LMnrL!7|+O+|ANG9lC)8 z6t*>1p6Y$kik!D)qUP?grqukA%;UF(7X{4;U#$XmzNy0NH4`xNiT)%`I1e~S*o2qp zPG^EfxaMkGz|ilrudME^_o>#tkj&QGy@C3gbDrk&hDp3O$U4-9w+=9U36QDDKnCLi zK=uR2IW!x{>x?Mc{-eO&4gY$&^dR{6rYLZus3Y)>R@m~s21rq>_)_0JsJWFE>p`VnGPR5pQ4Up7$VmpkO{&TGIugd|339sz zzQl3n1U0ML0P$m>vyRs!e;lSHTVSjaZW~C@f>zxuavi_|ybwua0prnT#QPN=CRJ-$ zp_Zn_FqqJLBYsb}(!u)m848vE{vRuU(|j>b5wd^G9gRy+RMc0g7=7;<{9Lu z1mnJCw-=DP`**2?fmXsiaSt6rp_+KtAu}ZZJo#2u(`OSIP~Em~A2SjGPj`3CSC!rx zZcV%vDrI2!q_9;fW$_`Py6EfN*=RD=$j;80Ga+Qyw0)bwf2Y}jo5h`;EHLq4($k2g z8nJ~lVd5CqA2Wy0g4K*^p0~eXl$)k*Lo%MQbUyG{j;!U+j`4^*liRZ>hPlSX=KXwo z!Hb?O9>((WBlLS(1!pn*L^zI5La86Dhd=5Nb{l0`93P66{2GDXUwn#Zp~nR%%0au= z4XF_D`MS&cz&{naMG0DUqtNz!U%qU9k0L5zwdX&=3IjQ!X)z2OgCBLXLEldA5HigRug&0Mdl(xwO9AF zb253mYj><{(eji22WQLT@r2g0j{ZR4{Ol3876M_Ff~u$?uN__T={ZpB{>k^DKyZ~G zecRWBP?ZS1g?vb&dxks#;AO^83?0$B>N2evfXNd6&YNPLv@>B|X0EM!IyL zO1Ipo@l7RU%US?$9()9?Z*ji;HnJ?#_2BB>R0EGHZ#1QY*5T^VDJeT{Ly+o0aHlIb zP(EDpzwHcq?(7(M2h@}A{6n?hDi8g3V+dUzd(xLwP@%=d4F0jv#plI-D=#pd*^je@3R?>Bq_uNhw$^rmjy`8@kJbs%RT!# z7lD>LuJZUZRQmEQsjSsvAX?#Bu__@wpuU+JvA7&W#T%xbmY=~eD3^Fr7CRG5v(}g@ zIMlRcLld|eo>qdS7bTJ@Cdx>+$V+gw-E)30cCJQQN*(N7UNp7J3!6Vg;74$*Wrs}w zP~TC@YzXW`F~}h2d;6H$EXY?9{lR?yLB483=9c==g(`ts)__V#PicCwjz6~@xU*9$ zEaI^Ye>M0Lb%bPGrq=Anj(t5tH-WcryxICEf(Rw7B24Yw@=maad!jt7Dk*vt+h>&+ zJx_n;ciXlbo{?D+<5h&y>u@x1ZP-b}OQ|10oOJ6j$LJ7^LtLqoKF7S)8{EHD0^7f6 zZj}CNg!}%?%2AdD-Y)t?X6#KtzY1=EFf^^HS-V9!El+=N+PRPpcdwSzD}an9-?t;5 z!8&I5KZ>z`cI1lq-~rR?2nTu9U1h9+liI=NOk@{oP(?Z{k|2}A!webb$iYz(x4Ph; zCi_ceTOI-ZWW%7%%Tm7X`2F+Ki?%e{$n9LkI>NiDq3l9#5BEcZr-E6bsc|nAd-K5% zVv4^qJ12W2#uGaWuZwUr2xtjaVU9IP{6a4uNy1P`Ldm{HJbitELz53!^3ydW;ii&f zciH(hM}5?8PyBKDlEMFbI6%mTYV6a%Ec9OQT>TbM1~ozub+B%tD}5Ow0_Fpz&?>SY zyfKNd1ZYcpr&}$~kO@ee8+-UJqFM^g3K#a(wO7iym|@7DdO1`=x) z0E74%JGsqIEHdFzr+|CP_w2qSZe1f$Pf9Eh*s6LMCC}Kia_g{I%8s?CveE?6HVpD^ z0S$6!rhCqkgHt>NsnDK5%oPoJYRwd)Ub3STYt)9Pp@)e*lJZhn1j*lFC%~56o1i#5D2@qc0m|iynKiM|5 zl4M14nV}StR^l7I3M2$uzQOO3Ny*Cdp8Q8_$8>K_$ZQxUD8;@v4srbZjb^_Do;_xg z6nB<6iC@3OB>OBhAxpMh2~rmcgO_|+56J_y!~>AsE?-k`jjE(l$Tognl3hZnZFB5p z#)p7EcenWQ*D0ykC zpV)M21^i@yXSno077ng5&4ub_j8~2z68I1u%Y^qG-@j_j#cHMd1zK@g8lm33_*Y^( z@DUUE3ezU#Y9k^l+A;lEhQB+k5p0tK?@!WCsi_8JVj(IHSjX+-$5nw6^aQ0Auc?cO z_GM}y_h0G$kVo>Z`dlY+d_FVEC8S`gve%9brRnA*w1{7NdNvh%J*n^rQ9IOcFR)>N zf@x&oxV8hE^yQ1f>gsw5!_%fpz-3S(2%V46ex7cnm9NGX&hSi>m`N40L5$vpLCtMM;C6 ze+1{vpm9qzF?Qyz&*^BfWyB$?h06{m(fkJ%0Uz`H515I8HcLO$Su8iWdCVEIP_4`& z%i8Df0CV4ImuCKbTgA_EN{-(V%qF*MR5|10kGbbDi3_@XS~}L09{Pz~HM8XC_a(|_ zU^jTz5BTk7>o)7UEEZlsd;9jmd~FJ(f4Dd16z;ayN&(=Pxhg{h@d?=A&{)2M-|>F* zYaJ#tAIKc%A_mt_C|bJNEwSZq_9SvpD(fJeY$SyEcrL(lrlv>cT`veGY~EiJJ=cE= z)sPmGvFFbkkWu`9AprnLG_6G8D8nXhc68GZ7Q;_UzU^+kWNw=s`hc?JW)N}-bUAk2 z@|tpH4_5RkBo{+SjfE}x%KF{;px8+DYyYt~#BT72d+Mwvi&*0Q4@GvCSuKKq1l)zP zv(v@^5GoBKK!8P^D9IGnw^$F}k1`}WDoW*llrnV({R|1S4BHKpW*n)_=#{T`m+Y61 z&}db_a~oW{$^pPT`2Wnm-F6fqHol$-{p6bJ0_&DX?}XIo-srGMIiT^mcbcWoxD}Y$ z>fVl0q75TROd)AMRCC9q{Bdud!F%dr$~Xe6s+q+59w=*v)old$?C@qtGuEg2|9kZ& zs}$~~fv)S?6cshA&CJAT9rJVlI^{5sfJtcum<`HK3|KKn1y>&p=E|?ve#W<^POGL^ zM|HN_!O}9$#Cjm0hJJrF4a)XlEi0@4Dw}cj%XAljGO1iLUl;TpBGuWyiGf5l#yYC2 z!w!^`a+Wd;+<>j zta8pSdVoM+fMLTv$&CZBK`dCYx#-w4;^qCj3?^-d?PxVDu<|yRn9&u{eW~N`rL`2@ z)kH{eOQWu+JNuHf)O7RQD-J3WsWlYen&Ab#_sppMv+ zUSzNBO_~>o8&-cUn_G3B{~3s6)^G)Y=#!NtCwuo&4)c$umZX(Br?pnSUs-Y^2ssBA z+&9ARaY^vd&Cea-rX=8v3|uFYfcaAncov_3$pKq%Zl-yWHFbaEr?{uW(B=m%#?eXw zc_9O&ge}x?z8$Jwx(NhZ%dJ~q0IUiP$nZ-81>f`b>;&(I%n;Y#hDpYea=U))?|w!a z*P~9lIo1*=Fp_lGG8ckDjR?aDm7M^llOWs<88lm*ZbGi)RRJf_IUaWnWc zJugwM6qJz+wfQ&FHJ_}3Tjj0RSezHd&o;8o{kt=QjHRA^q!sV&j+vKCI-|~0`oYz! zLmucRx=IE6HT(5m5Y|17N!oAPlh5L_9}paoK2RQ1>?Y5bi~ldoO5%#*{?U~sT84fgZF$Yr*xlh}92FN_L zaYQ5RVnSI+P@A{;R1y5pmV4w?8v_rA?2Wx+NqGw_i0_k)0miIL%38j>&++l+PVBq; zl7--zw1|qmX!XX=V;U#7!PFlzDcaAgw*Thk%M8#sEgJv|*k87kDIesMXA)@BR#j`` z1slG736ZQ0vX*OmtOGPc)?qcKo5u|<2Ur+uaH zNDkQ(4w+eoybB^WhovXNEY9|q*&8>?38Gr)rqO-j=T1;uT|BlF4Z3t7poz_FlE?{y z33PqDlWrm$6}?mbw#FOifBErch(lzGrgol3&|OXg0FV!G{WXk*VnHG120FFu^^o8L z2ixK2A4);()J(`{!$NE}A;kB*tY*5#()xG5$@+;w_Bodfrmvl0BZSTaTJNx4$J(@W z{8T44Suy?37=Ic&;!*_;V{VX}*LDWn@WWyftJ3Z#nKR`zJVfnrE{Ai6yDaYY$hFfP z69_f-sUFf=b+}!S1zh5$fqK6GNayxZu1=p_t9ZX!sBs`w0E9(B#VOmOf$ZUvVH@2iqrg;syV%@!jbgm{kZE;bDAH+`qyFMU-yl!}$kW+uBER{Gv=_{r~P&X`WaL;~aKW<*Gn zGUG6`b9t6tg{z`jUo9M>H31?;M|iW!NLV>Y;Uk#uwK4W73R&vpt>AJ|CaE@}Aolc~ zcQjFPEsDG)Ml^m4PdM(}E&|le$TEDOXE^28AH=fZMLX;~KJB#8e{Dqtm*OV-?=@JX zyd04rc`^KhU<6_fnaz8!Z<>fg>43*7vgkzgF~VQ2k1e>>pyp`ZyRZ$S zDch21F>l`7k+>!tRAFI*&UJ}#r zX`lWTa^Z-oR_Z0UW$|Fsa~?sJKy9>`$`{W^U} zgBRwPqO6R<_eCHDQXk{03RL98#%D*)9@uxXO*DycE)d#`cPl{@rc}2@EJ1uc1m&hn znC&L1FfjIyT;5G8xiVNkl&&dQf7n0$sG&s|ZErP3i;!Uj&*}8y2tDIfD+lxEoSV+; z>~b>CKEbVuv;a{z#18OzmGepM)6;OZBb}W|O!6?T{J_c~2x#tO&n>um4&h2(zu1P? z0FXV^y?<9?S3Gio45CkY{5xF1Fd^C_Gb}unR(glnGy%Qtg&Nvm`F_}nGb0lwx9oiM zB&BM5>EO#JJI#oDeeRLPUW*Kg_0%y{NZ8Y1jcQW3&eDGKI}x#6kAw_K_8Dc<49WdZ zi()sL;TdYXnS#S$b+S16*U~1cd#)+5adZh>6s$*#g$H=QhPe`J$woT>au~QtG7gfg z$f-5U-hld91To9Haqu5Ud@yF2 zr`ZDD1iBz3d`M3UHSBQR{lKAV^YdC3fza>BB7WHP0rZ_QrD>(h@{k*XZxQj5t<{Z5 zrH8%RS8zXLl-r5OhlC`4PZ1F4wdLa)t5}WC6Z`}0y(oYTrr4nUOuF_2ogjYi94a|l z><4Y^wS3LjVXZf&;C1)G5DkKZg&1!j3gRK<{DQVTRkiZ6{HV+&-c1}c>C~bXa$N^E z+N05w+R@YCJ@1+#({|0vBIlrs;EkR~WN59SiZxjEVz;pH1$jzOltF_AQ4h#v+tr@o zet{j;n=@(@W4PMq(#^GiSY0!LK371*>e}n6bP+q*y{6&N+4vKNot?v#EAPky6L;3K z><(Nc^L5TfiZ)+1RHl!uEU?@D<|ILz0q=e?ymSraf?IJ5n^909=Ku7O{8pNsY%ie} zi&|_a(ZdFoE}Q&DA{-zx%)wSS-nBRS=f6?r@zUzUMu4i>;gVkLGI>@HpTG7J))yLY zV9J$@rA+_mR@3F!@SFn6WhoRvlVr12Z*FY^F;w$|TpmV**+ zgmyx+_*nV=N$BRQu$HZt#P*+;B|10|C#C7zyt=_j@tWQf?0tSN3(JC9b{RKYGL1;@ zz1^$GTGR06FOd2ALGeofHDH^?HjU6YijP}_gK}GD6Jh&T4S)EY*M!Cto^0_SGQ>jp z9MX}&Lm)0cJ;73?ON9jf%ih8rDsZu0H&-3ErsYXzv+3}6tG!C2^|U_0K!DS>vX{Md zwT;M%l+OeNi=I6UH<+@3rOcnpT)D|yxJVM{YQbbZk%ccb9o4fO9$YQPYU80CKEyhA zq8;!DIO(asr<@tzqqam~A?hgZe_LEf?T6V$c-v|#>k(Z>KYXHg$0hHe&8=gBn}-zW zVrAX3jJD2xVS*>ujqg0BP$1d8p!cRG1o2m~EvtL-B?B4D<;Wj=|44Kscw8f-9nsqP z$9mu)2ZB(myf4WxlYaklURaf@kA0CE)|z9YC&S{vKtr)|p^YUxbp*4Cmgi#~KQ1IQqt@vsuRX4Ip>(65Hfu6-8H&14#2Ibcn$4a@*KW&VFiH2w=SS&J9yY41n#08kYgjv@Eab8);hOgC=V^{S5h5hDDeUb(PzmOw_y>IVfJDWN z!W>}Y$OP43Wog(zXb2SJvfR~DU25ClFLHH1QjdR z>vnTuVb=W5qZp>ATR12fR2bRahJTc$XdP{J;jSWMKKh??Ky}kqQPuPVpid-)O7wZD zBcNf>mB95?_DufpU8;dYL|vBEiw$1++ewMEllOR&otETW&vmd}o(tpLiD;2k(xHxn z`0qAIL5&hQ;fkI9fI&nXK!e9;5d7}FR=|k9@WB8y#BYgu_~=uIw~5;`DCKjn2Qzt{ zP(m6g@nGppU1MS-dQp_DWBd6oW(`*5$UhWo>-gr*ZHDPOD!dZ{TowM^N3BJeSpzx@ zT7$PbL8a`2{c~1w2Mpy4O&&2FNOt*D^*jN+r+>jE#69K8skHcSUIAUDq+LR+?DECS zm?!*0AJB72!y~uXbS8}sQl|-QZT`TY|JaEK8W#P?ROmHd%Tl38C@4_~Ys-77jI-90 zuW4pC1fdqQ6q2}P^p`LtnZ^r(bumbE)8%fMWU6cI1#H7Sm+!^k^R8PHZysy=1)3KH%Yij?3NZKb}M zwhSf*E80f>#Z(%F~bR)wVy0v5GAAXG=n=jY8@jjVy; z5zfYXc!+&lJYa<_W5AYhMIGc0YW5Ey4?2ccl+2-%&rLQFBq>v-bAPF@OK(FYS&An!N3M)BKFR>6iNA6Yc>**zDGi;>fmkptDm%z zf;NJ?s5wx#go*J2RHpMeWnS|A#LNYUa zk^1`0su0u{L9KQd#d(G2eu@O;+hs8i;;feJw)9;|&Cr6jmil_*l&Mi$Yactv3x-x{ z202vxVIoavOB5b=3gr+zTsq`^DqfZB{&Rcu1n-%e-0oKgzBVFcj168zBajK;$)hm01;4t?Qa0D_kQD^s7MPpWTkVb(3R( zCi7U<2gGHZ1+@g9RlKUAF!iY28L}O>sCa~{2x+*3L)+YK1z!WW(vGi?`^1Ybn$--+ zBcKx%DX01n^5V>ZDAY9=N}RA$wg_A73ZUul#yTDg*ONZCVyQ&hkH z>3)EjDz=yr5ij!bN44q)=s(3f@=dBTk1JOGEP1ABuxvgf&sPly?3>fEE)Rel zwg+XT)!r9ys#MzfdV@Z^3ecVtrU%$vUgkO~CLzB>0iXWngQeb9Ci2%Qw{h%27&i?$ z-;F&5NT^6KDTmR4|L1Aa;b(A~6KZ5-mK!yc8O~_c<2R~WSKYk)b8vnm;|*8C+r&P{ z*l79moEI!Gchjb)ckM|LFq9bm9sCz8hklOaqZTC@f!-{BoUqA2B4euabdasU$>1*h z8MYQ_WP1K>WDKR14o2hkU|;Vnsn$RM7vxQR{|i)xf;ibPe|#2=YY1k18+C{X^O@i%It*7a2&t%@olVY7z__?aTk$9~eh$tn0G zE>}dD9PmD$9+BIE<}j38c#_B-7IJunUBO{!nwvNNqPu_UG9D|u4@JVm1@|6HmpviQ z49Ky1s@y}28Lp=#)b9a3Z4pteB#!oVf%Q=#PJk3>cN~_EYqgoUQH!?%(&lUnVD$JN zjba2@?9E5$!YB0~<2Fh&&h#Iux5Pad=ne%($edrDme%Yi%`2+_H6-PjP_Ensl{E1Dlh zOofI&w*oHxzm%91KK`ypCcEmUh_ zdrhZFex%I?LF3{>8SuYJ$UBWMFAe;&hP2QL0gTnL!;+vpR|fF7)IVF4mo=+2m7>|^ z{3B8l?b2y%6wc@Y!uxTKSi85+ia-*?zk)&i`>R+JATnwUqrQ-rA(nFA)MX6u`X4-m-O?`@*C|& zr1vQXe*ja|NRjRcyb&4~{ids#`n|87u|#6nGZBn)QBG385_;(Juyuapwv~Sb4U`hx zr0Bp%`l^7VTHaPmYI``cV^#yE!1CMK*m)~G<<5YkDwaU? zF(tj_aS|m2|Em%m_&+nYH%}yn@7jN4OA*BU!|9|{2a1GSqR(is=tixk%W}gF!`G0; zc{B$Yw7RF`KoNFSZ0AiTxUKTI}~>$z7^9IfDM zp+@>Hbe5yhMTpmA%1D&QMMX5SW>COo5r`uBnXw~Ks2VG~sGFh`>IP!SlCy0U7g1tB zDjz-^s~AyggtA6k2z45H7Pa~N$@3Hu=&YUbz!3e9c1}|c&ZdJ+^aIS5s(}^~>aRiX z8l1;U(9-fCE^=bSP*HGP00paUs&lg|D3~;|6zmpvDjO4_O+CvQ(Q2%wlDKxKR$`e6 zd%L+tO{Zw=g^Vk=NcU3H?~k2IQ#*MEf^lr=h3!sTYAQc=_aP)R-Uz=!5{VcuLrR+SUK+ZNg}K2K zgnuKv$LFyNUFr!t2o9ML9@)7!u=rGV(Me#`mP~=z6q6kilHVe$CvOjN7Nj_Ubu@p+ z1mV^v!RTa-%M8|0Ks+~r&8%C$P*czUWL}_NU*!gauySsb|XD5OD&t$M6&C;+mvpvA> zNzZqV9a-H5ENYtZ?ec_3`5B71y3uF*Sa!;QSYnKSAZ|>fpt3A+i^;prQD}9+a|FnK znATX2PGMka>eq)haYsP&Jq7mxR?(VBviM_lM%)cEzYnx63vj|hAyO#1#X4I(bKA#* zyIVfA5hVHpRFYxyO#7OwI&3ux*wnR!}y=c1z>9U}OcPw+v z=WGY_sx{qH1p19_X*WM$=Eta*j$~EU4OQl4Wx}-UoxrCJCZxZW{W*tCS3|v$wF=lu zS9YFZxWJb+yk|6#Y`H4;erkQ0DTi7VW(FkbW?};N_ew;l?=u@DcrQMMpj?kBXYjR7 zfRLvPn!tKttK2oC4TXKB0}}g(5vxZyv_8xPAmd?%8N;eCNX8?i7Eg!AFf1b{faFU( z6-8%QfRN6Zx0H(0*_;)E^ zLhf`w)l!l$S)CGbZ%zmzV4Sj&tG63#x-%{?laic^Jr?^DHL%>BQJvXn z?B^(|QW@SHR{(LW+2{GK()Kfd%;S(cQU)mVTJ{M;>DDV7yb_G^Z+==r3+JOOGy^DE z$MIVg8sZcv9?m6VK;hADws`4W=_37ALbob~Rkg^X)FFnDB(1id`_wEaKx&7H2jgYq zu6ZL4ooMhSM@{wPq+s77HU82`HW%dVD5l@;$Njs~r{zQ@=*iJ+&~<(07EC-W1{-MW}T(nBezcxI=hqS#TJY1+wP;e-6t=&mL*Pf z11pyHa{H)2a}}3vBAEk>1$(aau=A7_l933|L%U8OcCuu@_a~E8K!EOGoXPhqam;FEGl5zriRr(q16}wJ!waXb`#L^WbVx2}QXna{SHyCT+ z$2b_*O?zu1QCZlo1&d#MIa5Dsm_N-Zde=dx8ePrq=Uu@ie0#!?p8vzzI|S##1njo4 zZR3q?+qP{dJIRin9ox2T+qP}n=K20pcW?)Ha8K3gN%y2DUDZ`xtNM9X$Dez4fv%>I!!bElm=Zr(F42_)o4lcZgrp32xsB-0W3FU&Tx9@$q zN3>$=S43MI)r8p;%WzEo?WvTIH#06D<}d0W@wUHHTV`&3SU>AD8um(4x$A3;PX>a( zIAd`vv42*gI}MS+v5P5hN$9kDf5SjikR3)HPD$HgpZ-;&;whA~5dNgR^-^7|b; z=DF+U9D7P;%>YY#ygva{R>o}N!7?!(&;EBcx8^2w;|Lx&N@bn6G?-_O5bxJCJ0ERcJ`q_I*{a<@rh{PPP|#ocbbx`fAoD!=#{0 z)`;p<(Udg|l-AwVHtS}^xfeqZ+58-BKJRKM>1UT&6kiH4Q&y~Tp6tFqJRu!k)_ah3 zY=d#zwP@-PO9_Obll1d~&vB%0Y;?xKw;v3L_^(p-Pv(6G+-a`q9wSLZLo9K0lkj82 zoxPRTS#Q=0z69|b6M=VhO;QH0<#_vmn*ulfrZ)TZ+^Ef|wEkE?p_qIU+2p9z+i=>; z3tkP7>w3PCaVWPJ3pH>evg$ z#Ec@g{6Iks#(0_V*#f4FV4qzQJo+iPLN_M;G^H&x^S&oc#Coxc%#%a-xc?7N;iKK30S#18Dh~2+bo!^kg1-65lO1lK~RMdS0*YY z<_mg9zwu`MMd2m@sHkbSTWwH63V(RZ3KZ>(j<9U4a zEZwU+PyWw91X+@U@CasssFOR=+0aJCH8cfuKPdB}rSL00JSBBxh7s_Enw&y9yiGM; zAb!ij<>+3@f&%e#Z*A|QQV$AW1n{fOr6nB=^nf4_g|94^aE6;Su`cfha7KKBg4P&( zO4+2sft-Pu?RaNxpY2Gc!V_Af9UTV3XRSo^_-4P(CMycv{t;grc>BVm?B+BIQqrT9 zZNpmU^dz5o7DmAY*`vjR=EA997D>cq&LWHi?7T>(((jjD`t%cIu4Q7t*h36CRt^^R zP4+q#-W~`ebHH&m4G%&Gf=uCM%8mw!iCY^AZ0tL-XR0jt_&H3RtaKf{>zIn5iS zuL@jW)yHM?LA$O-bJ(NFGP$^$;F8zOr5SpWJWo0d|f?)mmpB zH_jbRN9aFkf_$xa)coSbA4j?V3LT;{l*90qImp$@J3!rmunLQS zkdo5@vtnx125mxFpmLO}>Ut@LcORoe)U^Lai({RoI z33ez;*%sr7%EEY1DO)&rJQI^-RDTf<+3pda{m5etBQa_ zzhsNSPrA6SPr?CHi-QP7DsVyB6@XV|>E>1(dY(Brp97VxV6p#Temiy}e!`1myh0CJ zNhg}BpXl6_IH`uYg^DjQ6m5w{nmKn_y%rDIZdaCGLGEVo^%m-633s4^Lc^?Id`(*9 zQ}zOTSv>ev_b6)OSSpeED6~aZQUF1x*^;*nTnSH_XCp;h1Z5LjIjaGx0$uiZ%qak~ zDk!RyLB6!SD=nPOj9zg_83@$~dW;;#iLPwRu|kK>xA!@p-B?D$PYl+c37}4I2?23N zLh2lgUlc#a$@ZI*5ss}WVkjJRn`D*n(M)9{FR03`{RiWgi^qMU-Xk?E793%BZj1L> zUhZQ|cW46x@9~OTxqOY)8%$ebx}RcOq7V!Ey?hVohMZIDY>!qQM%59DeqatYp@#Mz zbx8HYILX7aEi0rp1IKu2talI z)?f;%!#;)YA>VPsF1N>2D*b3r2!0;?p-!}cbL6FIDuGnOC2H|IlN{ow-v=<3XUU*H zbj84bz<`{)8DmF)JTKltIyttZ1`Mhg1QM8Bw$U#g*k&e_HUNm~N^3FpyG*9Y-*Qb= z7X=ks8A4>B^tX&y3Xm(LYNIn>k-;e|o&@ag!TaxQn-9hHn*LhMA(fRX9ey%+mDZel z7C{}~8iwu@tLbvzvZGSlKn0!xgiN;7W*9_2zn0`z&@7SAtShix_Q;%+;w@!st32~C zon8GwfrsHQOqVOMxf_BwAB4%w*^aeY!-=r%&9Dtv<5U-%0%lj#ChBiq%<^PYV>xxrm>t!jrN%fq{Tfi2Q+o zj0S*1VP=8Y=D}e6)BaO$!qAc(2>&;OLp>T#h5ff+Nl^Zqrs>J}&&>;rD0nlA z^6FuCWL9U4$)r~ha*(u2DO{B@nPR?2!@w^cmgDiv1!DEWIE#z22zwww4_ z0*`T|h!=F}G!$eE{f!--7U&N8Ylw1NQ>N=JFq^;KSvwde9nqR2(fWloS$|Tc*=MNe zC%lu2J#*mNGv)8NAv0aGUe6*P+;R?)I|Hl=DmHCtWgV9?y!vz_Xf&})vb1K@5}eZY zhbkv1ev`}WNx7=wi5SL?LX8Z@Lq3Ye6;Li>klu3xi5Ivi>_e4n?Z?j+g1U?xexXMC zEC+YkVRFI5;yMNs!EjBy3&l*PXHM)S+jOyYx#cI6B#9=46#lTr_c4Lj@`ZI7NRj1a zd$FEA@~!O4$##r3A-tb=qcK;WP6*=%d9g)UWgT!9Vm;XCttWb2uGun9}NWI~#<^5l_4Tzbg4;C+UT zH)a8WKp{$pd;utS$==rw5hT6}^07@f8a=G)3et8z))@9x7VxbaUMv*)ZiF9kwH~91 z<1!PUVAC4}Q6w`=avP)~Eiw%KK>rdh5`)T^G9<-U0qkUP6O!R%frW-8WqB_sVZm zc+Vzmq|+C)YY9`YGvt!x+0OH=xpGs~Dc$L}^^Q$|2-@i5TLxh2!>_sQQi(SuJDTVtW<=E_{2e;CB2zbFoPSHQ=--Hbk$HVEsC522I5owhBy!Gh&A%9cy0jmVs3u7C%=iI4-U_cMEjY4IVs z*%xsx&J;akFO7;>XK_k`tso^cba!5pI6+6ioa!}S`talXzWPUziR)AseQ?rVOf_o5 z3@6G~lw8w9uHrw-d&YsQ|Z~XXfwDTTy~IM+Z?j$;ywFe zbjATv^ojgcI3yls2d;)_I@@HFT_wctf7%p#W0g2%ivPZBwkeGQg#eSU%dhV8&qRK6 zE0q-b8SLbou>X$Cl9|Glj1^tG!9$_4nVP>>yZGI<*@O1GbySp3Nj(J)a$RwR%q@_q zZwzV-zi;p{o9{|F=ikbq3O3@fkD<5h+0TLG_7Sv)bV~J{3=_~F`Ro-tYV&AFCnI(e zj%iMbqt9R?SB_76055OPR_R=(RM^#Fp-F@UM8BL52do{Cam<4Z!F6XRfO+>H06B

*0Alpfb~0TkrlGCIwgi+b>Jp9{=JM?9GK4j zUm8KR_Sz#K0e!Yn8l~fs6k{+#D7$@qkrV*;#Qd^!x9-C}uxY7DyVpR1iYPdG($V*aT;iw0tl#Wg+J(9V5)`bUbLE;+rO6RxEnpPFoJk~ zUjvaHAIgDu@Im-N+5h0!2MK&NE;Zqfkg7n;D>T(h^O#U;8wld`Em} zll!>|Hge)oj}=MJ7^P)j8Uis=X|L#%7mXuuxlICZlbvQ$MD20$c8*J#U#Z6L-El-d z9VgzSM`jyc?@H8>x2ziF3Vo(M;VM~bN6}6hi-ZfTO0Nd4pRg(IoYcQK29B<> zI#hxZP-A-l9S?c8fG^o||2&o)!ZrIw#Cr7T1&% zgI1816>kQ%wMdK)$WxSC`p*tv1J*@9D(%TDSHHXJ{qSHGXsBEFRuX@$Wf=rmYH6wT z%iGXf0*sBW)VD(T*UT#?gNLJtnKw~+eDMaXvztZv`&Q|ILOIG3DC4B=RST5l+7AL!m%9%Cp!Z%;Nn1e^lJ|<|KRY{%f&4axJPkcK{zc0rn!dg&fHTLHd1+Q+mCVb?T&=-El^|M%`(RI zBxw4Kv~W-Fwu7cS&A3K&1M{zy_3W3(i^vAwr_~*N6sZ~>UhybdKX+zq-Svzj{J=Be z?E&gBckGwS)Uq!7ua)h^upt{?<=Uz7g``pmsK)XqX?+diZzV`2+CEr@$m_U%1L9s^ zTMTk*pV5h#tDzwBgBwWpmawiwE?L-W$#(((6iHN<*~|b*S8i+7J|iq)Ng&&kFo& z@E1$vC;rqd0D*%uc@BJ%ThUu3f-^FU#v26B50grl_7hd!al$ENS^?Xtso$dmr?9Ps zF=s#9!V;uZ3nn+HQ?2Ed4E5Qw{{i_P4>j&;noe-MemOy2Bv{|u?!)8bR;(5+><65lOd`YA~bGfV*CDZpN|feq`* zK){xT{a|<13UV=U9I(Zcp*_By@tUo}5&0fzHHl!(hk3Xoq}%rtWDDx#nd_|O0m6v&d+*O%QV`pMzNGE1HgF<+i`r>-`x z)tW^7mJGa_fF~$#4u;P5fE@!>d;eGXqy%zv?BG~oKjYwvUeP6Y3$k2}Dn5kzAD~O!Kq~+co&KovEus!&0%X4M_h$tLF!H>O z&J)#sJ3Gtu^bL4uKm`H$3$U{UHW^2bWm>CBgwf9D)tqtOG~&MWhHlc_Q_L8d}m`N6UB{ULMmPHjKN2)XtWRn1*V;`d{*jrXU~#@BnM550WQP2&Z!%S;A0k3@LwLuA1ZE(tdip z&%p27%8OHV%|P)5Kl$AGN{j~f{U`YS(&4D`ZHA)!1PsO?%P7OUjEx4m5uR_*7ao>6 z@f9Bc%?P-^3NXhbk6BHUqpVvpoFJK>fXZQ#G_l3Q(`%kL{Q8Kducp6UTL4`p2>GXl5K9r0=Tl&;Fm{5L;KP*X-Cvjz8~Y>|A1M^S;5t8&7Z> zV$n5tfs}>)^k+y6zntHz_v)+wN>#o(sAsQ$C3tM@H@d~PN|Wch zFHkj}U0#ks&7ql?21mQ*5d#tF+7O?Fm;5IVCe-oFh8l5r`+ti4@Zgo_fp6a{Qctz? z(c-owe|a_Thx(pg!8;z(S%`da}ND>aK~0vnc%LJg`3@vtWAUx!;1@9m#ofl3BDMAnv<3W7-H$GjXrYj znZO;MiA6F5yjr<$II)({r4p@I0}H~Je|k|MuhRo=Y5kr%hBh8$>sSE^x4o}`SEo~L z{cI~3MaPE(XHsgha+P;7U6y<~xYm}Vv!<3k-;?QZ#^BRn?yvVQ%uybLnO>Z-s_|$? z(%{Jg4ccuiOUQKmF*vqYgIj{D*PBKHe&a4laVQ)Utvyl`JbHO0koZH_2ZMWY3$esW zawH;qrIj1 zm_LbJ_jpcFwM-qj)m|6ACd6A#`ipFP4MO-@QRG2{Y0`Y*{iHAPL{vA@zV4@n+77rL z9L`N4TeQU4g(%lgT}KD-@Q)LaY0?}}Ag5L=>bVzpF7Nj-yLr(Q4Bfh+Pj^4|vx?5* zMsq)(gHE*uo9=ZnZSpc=6njEI0Wf_bF@b^|!#8kew-lCk4Q!&z;O7z|u3tjyJdU%S zml;T0D-tj6K^@&JkEai{rhKTAwEW&aQBwj}s?{(Nq|o#0QA~6zt9W&QZ*KeIQohXn%NbbCR;q5(q7#Vq7uY8Yqi1xK z9O`3#%##liyL@k#@`%@u^c|TONpPn3xToZK+cJ;z|3%xZ!r~QM4GMlFf(Y}Iq0Uz)s=??#d{Rl4b~xqv&Ux~>oAoUsPBFB7<3%<(<%qYX=f&qy5IUy ziA;@J|BV6gOGqw%|5bb`X5UXQViT+9RR~|6F}Q7L_%A%0#bn|793_XxQ7IVp>G|&m z6JBBrM(z<(8cToSCWr5p4CLTj8TX?wvVkj0_0psfb*NUF4H|mt6E2;(PnK#TkFrDZ z33a%2mE2!UCQkDkdLGB${jZDqqYVwZBN4l*WWOWljW>#rZ0!as!Bmmo;r7xTT^-iU zr%AN(R+E4>e^$QjDa#L~6+=H7R$6ou^DRbAb?`K8Ut*^3PBmVGPud@Eg9R=u3?38E z(ok$F)k5Hcl81N)4AkN&ZC|{pn6x*^O!>&6Ae@v*Mp)!3HTGpdEC0M@Q{Li*ct2Wg z4uw1mNl9cKk{xv$ACnK0Cvs$@9ANBfSe^UCRrrg0&|WXG%e;VSRP8QEag)SRP93i>LrVT-fa(iwpGt#t780dt4oY|10*i zeCSUzYxSH?wSbwkrYO=NRIam(J!C^1+0Ua8vOCWB*st;1_56j|8>OAPuzFrwWz43# zmk#B#<_)4Y0^W8RsOysL^PXbD=UkUxd|zd}f}ZrFxDLLJ`!-Pils$SNtl*3T>BYX9WZa^ad4a}Asz(r7J=GCmC|e;>E=;@A<< zFl^u>L~-RFm-_KB*ZRw_=g$8Gm&H|fDBvar;Uy75MhgKKlNc01zfADFF;n>7U zBYAhnk0$eOR_%${FiIK#Xuhk%bkU?yP1+5@E$lHMVucQCf?!DOh}8#wTrg^_a0};! z8>;z5sv(uY@R%D%+w213bGZuL;9BKmUVRSXO#fGLmi73A+xJ-I9;v5XY(Kr!mpmXta+5+ zPYG(lWY75`du{rDmVEf_01)8C;~e%UCUAnv&-BmkaK~~z95z|^-)L^g$eruM$ifOR zZOYA#98WDXO++WOR|==b~tw(HoFx88X01~cpK!j3$jd^ZnA%pzk6)i=Nk&b z7}`px5!uMil{)$Psr=nliPg#J00OCpz2JJjPUScG`=?m`Go5{PoU6e`c5L*O> z2mY5P?!ETN$Z2dLy1^|I*oSTsDhg5RUWU>FlSLo4r9~bA$n#)Xd3ytXDHH}mD2hf} z-iJCSUMuyVkqnTV>H@hN_S@0zMkXMbG!7>9H&jklG*5td{JR*I9?!^^nqFjvpEZJpV` z+cCkIokzw(Y>O0F+y1S_sH5{G7<0WeNR=mZ@H2bT{?FrE{n*~q;O*1w zlvlyqS1rk*9A5DEfuE!$6WGtFYXr;NN2lA}@ALFg;Xhh9jygEg9o zc#3JnWw;1UBW{X|B~R<-X8-fM3fS;b9!jA1IcG&YR9pk9zj!3WOfOd88IVqLk43V| ze9P&VS{h52B=NF%;OaRA>4C-~4jZ!FOY*Gt0a4y3ToEqx|K@2X%q<8K@VR`|w$I4p z8M#L?FT%3l5kM}BB6tIgg&&m08HGqq+7c4xi1-rZ!UtAEo!ab;1ANgoLJM3#1>u~w zSR5ndu8H1qC!FS%=BsG$eY4-Ux|S~WBg0nl+;xws1f2wynz^rTF`(llJ*rDY`CNAT zt)%@H8E*ovTe^w(4HdK-;0as4L1w*=8m1ZgDW5HMa(BmprV`)Tz7~t8c}=xc?~q!j z#x=X{C`H1sL{fH+XWs9sz~eDe9OkByJ?MV70aS+4_YiTJtpP*+yk{f74Y2?HRLy*k z&y=K@^HmDS2mt;L|s zTsqTL_idRoT_WhEC97<3swGRrmbS%8!QkLL8_5tZaXUQ_u2uWCwpTbbR3D;iz1f3e zFGwhJ?ehO`_yn(hxx)=P2n_@2!#eLY=*Q4FU9JlFKJK8}1Q1R%hu2ZL@l4znO+V|G z$)(|58}EN3H3F&-WT1s}FH0^wg@!h6tT2R_ljgcQjBk;H6{x8p5@;qYEhQorG>TzW ztbC(m&`%+bX`s8GvyG@})BZ-4(*uHBJ&SM6Falt6!L%sb|m&|QIVpI3w|BBl7 zUB~?cT#W`LA&kvbXl2Di+8!RF)I^X%mV~J*plgfjgktYnbt(j?4_Dwn=2 z7AqEUj^sXa0A(uJ#?S z%Dxdud0>~tp%yq{2do+wy`0Y%wb=*7beX57W}^bjZH7RK9cJMn##b+eJAq$F?e&X$ z+L?hg;!@4->J7TCO%?adtB%RYIF6!h>*`E4l4|r6f-~i2rt)!zhX_UELbd2*cP5=R zZ?O5hFzU7r3BW#+`dXzK!Lz!AysE1?KNQZ8z!R?CRO&vMPdkwC!yr+#MNQ8kBKsvv zD1)(Q+nM4G6&g^DCqr13(jhNO#1#E!mw93JJO(uxQCLCWTmH=Z(>=Y3PgBJrtFP(A zdv_S!-My1p@884BWeRGu$XJ^cVThF#l{Y8wOlhlT=T}~@3o4U>10o8DayTfpjcf++ z&5nD+W--_h3YC-I_P+-1PE&Iiq)%KGoI1mTdT%@%g?PFG0E~XQY;KMwa?@bBxsUP! zKFChft54R>`viFg9bdyw(yzIn%SRupw2jS2!xZ0bX2vWA`*OhP?f`9&I?Y1_;Qa?` zt0|3({?PTA)JtY&A0#0Kla37C92C1eAb-B2)SCm?`Oh0_0X?{-&2DXw*%;l=bbhnT zm@WfvJE1PqeC#`+^KB#3xHlowVM`ki@(hDwguHGuC?f!-W@z@#$k@G-mM4Ymq8&F7H_qJeXjay?lJS> zj*G`vQF%<0Z=^?m{BJ`^7!k=JbMG@dvRC035f204pG0HIe>Qpzi4*hFD0;yt;yjNY z>0Wq)03|0`qljtd_r@<|iDgNfr$NX@TvTJEaEf=oAaHE)D~eGlPFEYzKDlQ$Zz_-% z)`e#zW`ggWgwdZw#Q-0)Nd7&#b40<8P5*FN`up&`uR8VfJE_{g9?a7S$2>HVHWOUjyg4e*)T&iP%|iv0!86jMk^ETNBf`r~LZLzv4X z36yHoi@ueQA~P>3dVdt@OoZ%)GlN+o6_-k*CbAZUt)1I-`42DXfJvB`(4cJt)l}D3 z_>pw=GwDWZB2|>lBXErTgMS01%L%{@Kk3f4+2J%LbBBn_(vqgQvR)c#b8tcPLsvH^ zBs#9|matzYe2Y@@M(abTDAAeo2mZBQqaCmTPocq-^+z?+CQx90Y76mu{vu zYN%&h*}ZBbpq%Nc;9F3>Hr+qyi-nPnQ1@N9?h6j}nYAB**zvd{X9OsOWmsxXT*qvS zww9vm>2dUv-?>?qjo|&5rnkuNrZm>tHU#`=7Z12Ltmp#qU8UOxzP|FYKQ<7}k$-o5 z5)|DpKNy}BSFhsY1j_6jE?3O}<7y_kel}?6v5On4A0;ON)`l>tQ26q=3crcv8-WtT zX3?>Jkr6{C0*>%F0kLLj>K$Bl^q7jKPGVG#VtxkvTr*;EJLs zXk0{rJW;-U9JI3h5c=x+ecX56zw`wm8Hr%s9QQz_z-M7~3>%Lc83aD)HZ5|jSJPzv z`ivEZm!38!T}A0WQYKqp-M1L`_08KY-TdT+AB7 zLmLoDqCxNL9b#hDv8&8pR!h?mf7<|qvVg&IgQAt)dbknx8TPs^#Gx4{&H(3wlU>li zKRuW6I-a5rVtJ7tuiSA{Sot?D%wUd+IO7av!41fyMDc6TMQ+RQFMaJVMVGoeHUEYK z!l;?GCmGdjP+^^1Jz$gT9F+@55CII99 zcHJP>hzbsAv^XBF??;I_jz7ersE=l+BF58xUrs@;!cfTQ330mARzkniZ}|z}o*Bkb z-1Z|_(i1;iQ#7FWbz(I&sin^T|AKWOMK%uZinX2$7TxjKd)KkrC|p7L{*^rhjuc4@ z_ha*&2t-Y1`S&R4k?9on;#eCc1nboZ7fYDJEG+#pmpFfiy>Cr`p{6s^Q%!dG!%Q=9 z4(W3#{_b%av@%IE``)PRvl})N*bG6vi)7YwbzGa0i7M zXtgqQH)kIfqZg!?)O&;m=i=3Bl7hXv%ar-H+pWnPizF7@NwZ9)1#ZM;?ALwnf7MvL zhQ=NRm;)vMSm_@!*vk3gg{h~u$*-Ik7me;LSIdsT+Fr3C^ybaTk(D z{SQ~ZjYX@#k7e&3K*Ii~H(#~DUlR0S^hj|IZR;EhS##l6GujA^z)Vl{*XO*m{(F%zFFGHY?*?x>lP7E3BxfO1QlVA_DcNrT~4dkHLG3!Xv67X8G{n!D7<7 zCWVRJ*CE~QdO87B>!=iL4Gq%6_+VHwNX)RqHOU<5y}IMLw|%JL%I1edx|=;RhOE(T zvzQUYQRCQ-zy1^nO(`|lJlM7jHMOvDqe{kzPj`GC?d(J!lZgQ?yY%&hLbd%{14OVc zOIqUVdZ{4G>AvN5{saY5+$9HzLT$B+v4kXAGRBn4;>UPiOYIaDt}D(P3+^Zn#m9HZ z>zvelPVg|#xKtvgrknLj)*%*$DnF%md0fLDxviN=v=@Uhry0|$AQct^a;(a%;L z%I=eWsqr62Nh-HZc@GlH)hXh_E7#WSuTKR0mrLH1xswQ$P@Nu`iw~1P=%fGFp)pC_z>!;p zNI9u5NznM&es*$xJINfmveJ%$|NFodF6_nG{X;4z>n)oaf?eqeT(Xjh8zsYvL`0>V zBIT5HV1J9v*B5pX7Ger#+nc4>Z|0m<-_#eXJ#)~bmc9^MPA8n9{%}hLL6fFDu&NGe z&{hPnaML;^1jok1-?Uy1yE95-Zf{vSSni32hw){W-H;^}d6agdf_Kyj3YnBIq5Dkb zpT-%{%~^`{Oin+1Xr`8Q&iQkl33GV!5=U=j2_TG=H=epi7D>|&;&eFHc$7dRjlX=d z63!Q3IAD?*DT_LB(~gvZI>^!;?}|C%3e!aXKO3NF_^WXguYtOEGW#Nl4r}2N6vv7h z#)~e#>z)=G)81u#Cyb@76C}>pA)~H}Nf-jhGw;Ew56=ITxw6!gr)}Z_&3bdAi!rPb zvLmChOO;3f1IpD)6^P4BhK@wk1TWjNIg!N354{3mlZO$c(1dJ1ChL&ppqQusKfy7@ zX2mjHn_n>aa$)nsV~XHy{pUWCH;CK@bX@$W3Hcb_nd0_=uaRN_X2fde?++lD`6KW4 zyJYIFQwJD8C|si1>|#rA#U&b|s=qt;f>Jn)@;h}I&#oUcqzgO*Hd{gsoBH3iLoCy; zd#YQGVzBob#$`Xwel_{4bX}n*y!(7p<`1-pIn#74EMd+n6AkI5K`Fee8Z1YVwt3@6 zc5o+o+wgR@@GdIKV$WVBNtymf8diV}Dlb6IqAnS2r7lEXZbS^rRO2?I`O#E`IXW{d zg#tR@c)Ov4CZ0SNBL&6 zGWIVP3x1)tQS0UEpmyIt}K;?H8)Z zNwXpuvR$80Gwq6l71eo{ye{439go$tY8DdewOOSMAPdHF_i=)}1m4ARpLtVU#eAevu-7KyP^P6$tUCx)ZD{ zr0jSv6R4s;)Ra~|F+#p48VmBGB@$r;IVQUmr}EZ1y7E7N_%t=*T^Px}T(y5ZV!jHk zc1H^)Yku_A;q^A=ld2OZc#}Dhz}bh6*|<9~ zdBDFD+W7f5iY*Rd$tEDJu-2bg`L#&o2JN^jYW=EafW zwuM*k+V>XUhONFHMj-bke}EU7z6?C#n<*DsB)-_10V$+f)kakw2BWwLYD2ncH`Gt) zWK@kbUpuL-pVZxzObFjY+GqKQ4tzfViovqJMy+SXs0}G`_JNZ2FnTfwB=oc%T!`S9 zz|Ax*5P{7D5GC6@7t!?RvgdkHovpJ{?6$hJG=;q7PO@nc88Bu&RK9o{jxSp+k9o46 zvtRA&2v9`&3WiegD|~T%C0?6O>fDJ+MKy%r|F|*`3BBlxY@@~3Q1NYVN~oHIaLfcM zUlBaI$7$<|WOTs*@jod&3;v#C1W4;TpSMeG)?|$sqYfh+bK4)+$igYeo%UO5rpUAr@ZWD3iYiL^s1Unh6ivfKRjsi3G!s9#% zxG-Z%Ys#Sqsim7ukm5#h?OFG|({u%y$&J92fn_tMXlB7+%{h|*`5{2Op$~^E+tW5L z$tF4^$-cHXA>`j3kkT*$3T=;eINorO3<)EX>D7 z{Yxo11-1*Wg+L^epC!`8=IAl>^zz{Icex~SK@qRbHbbzkNI=*3Ge}Vy)&e!t=Lk{o zjX88v;(|+)`Fkb$&q<0j+NQoB)P~7<&Nai^Ec+so9!nH^KD4_f{+D+iH|e?(aLL1@ zwKycDDpC^M7l05ao>|b3e{vZ6EEPkPS%7(-c`yKeoElJEIdZI`3t!0hhgTrd8q(jrX(Hyz(4atOh2)l*D6SD%uhr;otZ$Q)z#g7Rk0?T1CFG?VRyo^z zg=a%(2<9kB@|QHY8n99u!YMeeZarVl3Xbw`sK@?%Xe5L8!nGuIE&$bEaG**Xg&RYl z((!3iLE7;RnKQ-Yu<38W!Mn)>Clo@oAKR1tqWr=SN1bQiY?9qe18ac0F^ul$4<XmzWCF!7yWbsd1EZ-}qIsXzj)f_o%{OkwnLr+1v$1he{y_hON=E_PB*{z*_cJ zP@FADAyHNb7u&w`R5kayeRdO9*9cv10f3Rv5yP*(^H-bBQ2R^L!}Z3bi{_U}ph~eM zkJ#;vJeFhmcPluTC6=$f)62&IA8z7EREAnehag>R5@XJUzFGi0A#LjZ2neoZ^HGq} zX#FbTY=H-lI95b7u{x)%XlJ26%a|er)#<}?G(5r6sxc&fGo`Y$O4f^??P?t9n ztyEWzB)w5vY#x?XIBleqg9qZ}x2`Wwaj~&h*Gtft2d4}UGHB9*+k0FEur3_95A6&? zwrc1kPf1c>v}bNSPXb^H3J5f04K=OS62A8OzBt!g9oh=RKF3aAGakw@HpbQ?$=iTM z>9mKTc7UU%RmH2$=t8OW&PBH4DKU=~Y}O+csyzpSJ(52(@h2A6Fv7EgzFM;fa3t1^ zpDZU*sD?{=AX9VVV6Ay=OCnVw%?`6+@ArvU9oY;F=!jSy<8&{vtnUI)(ducKgI?dN$w9r%Cx{)b+2%0JMI(uN zngdq9`fJGx7PAClV7;4wh?PmV9zig9d4CDN#mT1jcFb8K1F>&$9#L3h6io{`_RC?xe=S zzPi%O?tJi@j6NZV7$`Ro5fz9^0iKLq=_Y=)D=6y<(!IdMMu^INhTvg-Ag;#1p1Y@2 zf|KpBDrN`Wv1Ssu<7eLQb7*1^<7}3+CI>o6qhCy87MlM2A=`2SuiLRo#$ET>WOH-S zD^h19S+bF}XGW!-$69CmB3e0r{JI4dAf}1k4pZrh(mmWR-?wGS9Ke>Su=8=yP*f2py#$t&-PniYnrf%|tN^@Qscfju4KhNqiuNfbq)c$;cyEZ;oL-q}DeqD09>%S%eD4*YV0 zm*<(?YJe6bV!SE~(44#+e2*#{~c7oTa=m$e5HdZ9Sy;j zXq%Ujwf;JQZc0`cfS-!B%8 z?MG#R9qnjj%ch%VivcAhW` zfkguZx8NEeSdhgnSa6r%u(-QR&?R_~CAdR^Ex|%?0wKskaJ&2c_pAC}?%SQJnRBLQ zs{3iCdQMeO3o#8D=?XW+;7O4vnP4fzEZ=(~%m>+yw$ZbQ-=E(VRoHMa^mL7p;Dodu z9zGcVnmS_7koEuM3msmPkPb4@GxOoKj~|A=(6n0XPAxRTCa3fDx0}ug%Bi_}Uz>!@ z$>lmSr#P$|Ql<&FiV85)^v;AqN_U8MAK#n2SY+n>E7P>ypF?sSK3^Wm=?`={2#N$g z^_XoQDUknKA7OM@AV(ncA2+#)GNd#6d_WQlw4U>`>P0fX4zS zi{&6njPH@<(Abj)Qye*xqApU-BgC>&2D6Y7)P1v@KRw!8tWjry1VXIGD9CM_q2ZMm%>H3BRPu`)Io0WBlncSX_f4UUk&d(MNvlTj z+iDH-pAJAm(|Equ2fnNeb|B3*IUD3>A@=N@D@OJ6?d7Bd((W%1{?OBq*{p!;T-~U5 zD&W0)s70(O@5uCF%G4XlRgW~_(0c# zRl1u!@Fdsf?A;Y}Qcd#0e&h`XSJyrLv%{3P&!Nd}oQW-E3Ib#f#5ye*%P#V>LULD; zHXjGQUG568xRgc@o41a#&&VGYU*}ggVEPhGfW3r#+;Fwn$>fu${%=WqG(=lu#zb(S zB66_9D|TpqpqF9r*8>==Mo!j(b?Rc4fBu$eG;|_yYfiBY#$=TC!-tc_0*koKQojq!#4U zaZl#`P?UCR!NDqEwoGx7cmK`0U@1>;$nXL=I;?(w)W8816F;TeT6>&K_b_3~84c?G zqk$Br>`skDzUD|CG9AiQ#1f$eU7!zFF&sWXE-fTYR2z(YaHV=+qYbjTE6Th~ighC# z+6BW>PVBZ!_DlraD*VMuy04R4C22jwa7(@Jsc)(rFO-!T5kl==2Tdu~HH}j}wML`g zdLLOecN=>&wQwd(Uoha9R!M%eu#M_&)>LI8xC7uk?)=*54JbJ^ZGFK)G$*FQ;ygg{n=tPkc6a#d{Fu zBkXl7Ogla9mKn{7_tttwc&T3<($?-M-X4uD`Ok*m+$SlYeSQuTu@HNS7prX;Bk9|W zfWqVBF7kA83p+DGGZ%TGusTB*LZ`1bsWTV(~jyKNR0K39H56kJKdM1xj# z0p!-O2#zz|Z?g!MPAg>F246CvSCdU={yzN-NH;#F2$*UD zdvSSMve4cjt!TQaBy?KfjKDz}|Cszj#1CT=05``)XI?FIx;DU!L?`pmOpI-`s3!V( z%JgzY3};rr_&dEe{O7BG}MuGVbp&gw>MlRh^%f4twBC%|sx z_2UW9DllAjNn$BeSZPPB*aB11hzpeTS|z)2Y!gP4+-WZwtWSdaAt5zg!<*x4QBmsH z5-zFd13zC-;_U}8NF<8WU;}@@K@x5iRuqpNN{*d!_bG?Umxn?m;8fK}P*m zat4DKwL|z5=ip2k@osNy;wi%t)R~b^L_HTzKa48yvuI*YJ&c}t&j9;bYJKwP{VL(E zIlDzFI9lR$z|w{1-vNxD7-nJnEcHo7y2g^Q!z71moYHT4#b#DrJw_eehZdjra61WG z*IJT{l$VvYT(gCwlx@O_s)RSio(LVCygqxu5r1V*9-!!3EdUE!IicJ_$W3j-{ew^MUS3ORZ~jLxJ~n#by(rhEONjL;P~2hLRnt8O?>AtyIz_Y zkn~leN2kv`%iW4>2Khzw!-Wtl_$e)WeK*v`XyThO&TWEUZ14k;F#Y^5Uc7EurJ5Tz ztyMtkj@}o&mI0mqk38@`kGTP;5`o#G27MjY@@-ZO+rAPuRP4(|D-0uJZQ~@Md2hqh z+;s=H?Uje~M*(+rlc=0@z9qV4Q8E+C53_0gX+LftIAZXDq~8x19&%`J$# zs*g(BZ{aT=tyH@NnJ2c1%sEyBUF?kXLVntoA1lmv{gDudNy)V&Pzc_ z5ub{8y6nQ{Xo(+yK~ro|WpjiNa1*l7CzxgKL1EPaT4kjh#SB)h`px6b!K-7WqkdPD z(M(xe^(Ju2hb&i(MGc;{ZVTC&vjCgb)3EECR!Bc}en+K){;BfkW~-lLr?mz6t*fiF z$j)33G`zfSr%Et3TXk$JI)C8Gikf#ROQ7jCv)@^;JX(6Z8_&}cPGtE9OhaqJzSD)c zkI5FAc{r-|qZ?2|GR}Sj~JjO6ai1EN!q5$$l#qGFXfaVtQG^P#pJzq?bt! zgeI(*p&RB(iiRC3Q~o9k3zcOrRHhk%0*2o^yeJ?z=tYf?e=_*FEKmbx5aVP9HoyGq zXHg5pK^iw7(3_+}WMu|Onf^L&d9o4|gL2~3>D52C1Gait2m?``-;6uw-OCP>2GttcFOgqbXzDBL5y7~964fV>&WwDIJ z!_P|V^vvnnUf?`hS#r1=Bo=Z`m`WSJZh0w5-7X*dwh8>=3p*g%ZT{)AnO3e2dcp_J zceuQk)1&|u>=JTKvCm5LK9tOuDLB1WgQ?`7|G&io(ZK$ zv5qYV4yNkckE07ck4XceEx<%VvT*p)jmtZ$>R#&)@osbFJ8mNq=8P@0bgopB*-|OT zC1FOHdA_&0Bz=6V?%z)Q%rG@R_6xBjgKEZ*+u@D%yD1-swEPjMtHka9XTWHu0_`s^?o)eBL}6 z)Abq1p8Q-AZXox7lbtIr43{OUkr@NmsCr5T-d%JGiowtH(lTu=MWJl|?*m#QeoKEd zjGroB)p}E5S3%;U+_~!5k+d((0Aj(`5u*A{pY{rQ^yS*-e~z z_s6Au3j8k|=HRv?a{#T=V69aQ*C^M^1R1tuL`}D>&XLElmot6@XTyR25Fm5~;C|-n z7xUr46!zE7uvl5rTh=BIIPEB)^6~I_R_I#X`bZ_`%}LRQ3iJKBx@OWx+A*g&*JZ2S?9h`$gF7 zW@$KW&H;_+wL-r#b(ca}>TQz*4V84nL`=(dmP~Jni~7YIG)sXSQ7OZov&@g%bn~K# zW`ba%>Q^DDxS&&9-l{~Tab}yU6(*~pqPdQU*58($_Ne4ks`Ohk!|oppNP|!u&44KP z+wz#~A4T*XVPq!wFZ@^Pyp=iq_Ee!?*Y=Lf{$$VClgQ2Y{I%-T@6$$0Wu8}@wt~zO zM!Ne?{&sCBRsn`5y|4WPpQ=&Gqc?mF!i7lBja-_qC?uVdVe`<;C4_%ulKCs?l+z#*{SiArh0yNvSj^oTNv5C)>}=GL}52uQwoj8F-=;)fJ=b zF1rs>(QUE^7nF$|%68Lr_7RbsZYW4Tncx*(d768FRU?0y51HqL)->Hk$__e8+i%pl z{tZixOc{d<1|*wF?3@MF69e(x*EYiX zDnDogNqLU?CJc+FU4eRrfDgM7);r3qh*XLi#gT)0428V9x!zx8eQ|&i66)^W%UMT& z&6ZJHOx^GSj->HOUfwvBxg#Y)A5g@>16JkT(G}>5SQlvD1V~k|gQ2BG(y$*(dNglH zYgsKogA@0DM5Bj4dT0ZQ*9E;hBC zu)PIfSqD^)gDaY6K4Upl?0OAE}D!s{!M)Vq$Tv>ZWx~c$bjdNLceXX;s^?Nih*Gz;ce02M)dE>DMx$qn$jJ&#ozD>x`59t-A9G<&&iYqv_> zpl|Wx{#VVOAYP$u~h+S;ePaZTtXN1Pv>h_t!TO<;_5uVnT7B zQHpdUiN{Gmgi<0NvyJ-VM>sUJU8vaF)}(6cvJf=BP$)O@r%nIUcJ9d!OBJeee&w;h z62Hl!3HE;_U#*&ygtfvO^~{XGXSGx@P>a_5j&>OiqqTy_jX?(oxD>~dq91;6?L30` zNB`w>cW{LD=%bIHX51>xu*YoKm?EtBch6uaff=ns_!F@iy>rc9{eknFWDWw1kK)Et zRU{cB30jvanfiNwBCVTh=+evv=#L}RP`2nLo2L3qy>y0eNG z&ms7ItPOetyBm7?lTs}&erL&!b`mu*et8T7%Eu6pfi(C1zKL5|AaoWwCICmdzwMGs zm)h?|6uA5DQr{jqPZs^DTr}22&ehYWop<}`G<#x1Rga6`QZ~M3{BEE*oFCSmRW(z6 zvot$t{At>4%8~;IaIRf6MYpy<^dq>@6}|*a z=iZ>7`8(zoCcx@JVlJN$w`ywWG!cny!>>RX&iLsWAifPM;O~yz%Va?aO(g+(BDh6B z=MHB4J&QFX$sz=x>;@H1(vwp2Rt~z7wlAdQd()Yq-OzDsx7&*qY=pGw3ci)ck*l2$ z(E)Ik89ENJO)20gx`I55UcfyxF>O4Z=Z1@LHc`dDQ!KaoD*TDinY2Zp!Xh*Y{f%Wy zmW6rGh!o>G8k&NEisB+F>QqtTK*L2LHX1oPCK~FyssD63bijY`Eou(@mz$zE_}@Jk zD9(qDfkuWxTU57?#`@2GUljkRwIa~b_Avj8Z!GMcJ$W<~beRNs_;~pEP@h(zp(W#> z{Sy`Q^1tLoFaED@jN<>b<%(Lw{Fh&&90LC3o&PvMH4KzTjQ?2B78OCUf35NH{u5lI F{SO2GB(4Ae literal 0 HcmV?d00001 diff --git a/static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-filter.webp b/static/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-filter.webp new file mode 100644 index 0000000000000000000000000000000000000000..6917641303466f289cf6450b6ffa4b14752ad025 GIT binary patch literal 43646 zcmZ6RV_;=V*R5l_W81bmPCB;jbgYhT+qP}n=-9Sx@7w2``|A6#|IEEqRb$Ta%vDQK zLQKrL90*8FR7hS`o>LtL2nY!3&rcl;XbJ@APlV953<&535hM$kS_5nvgbxocK+xY> z7D%5nJNdd(X-;jDay7tlYADh2PBt5!b5zivhxv2Fv5MlnXWS?2bLeaJ-RnMR-kaoo zWF!YOr}Z=UL*+K3!n@Mz!SnpF=80g($G&G6003;iuzW1P{);v&p~jv-R2j0{jv2Cii}QL(tVj4LIRH10;VQ zzkd6q_~8H4yY0CFJbD57(0#Q%H{I=i0=_toj%WEFY;SyS_*uGreWC$E?~|VZ!12rV z*E-A$oK0n{%daxeqWz9 zz&(ItXa5EA8siwS00{8G{WAYdc*5Di7y$5pWqp=BKEIcI$*BY2Unx%YHuw#E>HyaO z(Hrx3ml%Go&w-Da=k1Lidq9Yn$=mT`%njfa&<1z}1l`0u%U$_&@Sk`QJ!`$^JTk1+ zT=KW`>-R(fu)o?ql|Izo5HA6(UyD6sUj43{<~fHw)9!xmJ-64F+pB<4pTe*8_kdfX zBfUBPA@31@4dD2WVV_{8r{BlqGxW;@F!E(~0(pyg;IqNs>^okUgziE&hHf#u-AKi8KKGWmg{lKtQ(*^rnaV_-u??7SHfkpQwnEt($;^PCnPjLXv z5K`2|sW%Wb>T4{?6!a|XjAKz^dBqkfVVJp?9pstyC(G{WBulO#Ra6U;sh-wtf&!U# zOGW%9-Pu8llzSW9+*Y;JuYU)u9}@3K%de5%(X@Re(oKNr;#ub`RK$L@Fi)+GlR`A# z2#mTcBQfJW4#I_a*@F^oYyTAh#ewl#fZeO?l%an^;^4Z>kM{kCo^xdn%~K5>5d7DK%MV7V4Evvf+YPdy#(Lp6 z>~$`|x(ls8;f%z;9uotGPNG}=Vy~+Sjd{*Pu@K(&AcVVH9Whg<(gVUk!|vVuNv?^O z-4vL(ODQBt0}wAduc^r?RKU)1vy{J;`#Z_YmP0QJ{`pe{>@+csvojW()WHp*FpP2` z`IJ3PQ9P>9@GV&PM6XNF9pl0vOcD+O=iZpML`SHYvagc84j@=Kv;sMKhxifQeoT&1^VVJwKk zg5_N287yoFYij$RFDYEU>fXLhp0J=T_WRh~xWCxTHsI*c35#*+G5DCW6?FW2awhz4 z_r{bd#~)QIh3IX>^9h`A*nNT?;ol^Y9gdzJLnw=d0|b74vpkBCk!MQ(O9yA-%#RLQ zMP1s-=h|5AxSy+z^G}^2I)@_NyipMO6@QOaYjG^ev|)}{g+AR&QnIiBAKOgb1=di3 z@Y9LMM`G<(qRWl8C46FDl6#VDWVM zXo-MB&U)s=2e}mV9`s1ckKbQoC^n@Lx*xWO6-#LdW^3_GZg+K8qnuieE%G8 zKS=71!G$zd5vRYj9t|q6$h%nG5s;Qy$TC`nHwzRD!Xwl_I4172!|43L$+T&Mn)a$6h}bQ4C~ z=8(7SfL>0=+|8N2T-7nUAJ%J;$2Zn1EU-n8G&?NF=(^DU&HpY5H%xe(94`#?6Avk# z@EVOX^as^M$lti5k0A>X1+!EL28YZt4JJXpog)NJ=5o5xm>_5{9i)nkLBjun72W(j z(suz1c^EJTs=mGw5SYAJ=s%vPyHwo;7!R^E=YOh7JBz~l_?d@;+)KY!?pXXw;ev+N+KPyhx z#qq@P_a&7)LHTMAcgZ8Uao+5rbM6@PBzV0e3{R7!4-{P!lIRz7%F8{NMw{h1#6Usi zy+hAKS9@BDD~21OIY|vz7mAc3Y!Jb%)&=p-$$mi)Ea((^vk_^7O&p$(UPHzVxWT@O zgcKbOg4Q+iS5=+Z6kX3(wxr08maIkZP=u^zw1;znkI}8_;f5o@#Ehvk_ZkM z(q;B6M!}8Si``)aC=Hpg*0oLvnLKTZ+rSe1Jp)dPeXG#iHH`8FGDGu51pGZK%E@yj zi4FUh>a&JfXRvpfVs7$x@3L;{ZChYMIdM=4+7L(+LASw2xtMvTjsiQ5-7z2v(zd$e zu@Z1rGO@b6417JE+!?+?1k=fKQ?YP|$&}>%5O;6tD$aN7tZ- z+hc~`_^iaMjTyJUvIH%^+Xz68Wr1&5d)`B>imdJ7-_NypzxI|T)FqcI#GlNbh)HTq ziHJvWYst8Cba>YhdsB|?45(wIclB!i$4~^S>4LwdwY^B2p2plohxNQ0EEw@wh4)S+ zeO_%=A}-s{FLEVK>RfrQgOvAu9j%F;eN&mX@t&qXT0v7Z|4F&yqd|DI0(UU1CtcPx z`}E?7uL3efDQ9G_Oi*{;{qH&*Myq?gA>EO#*y)*Ff-CIP%V-Y|0O}j$crANOo-SXf zE&N=G;$!&ywE5gI%c-3ZuAK|QOR>JAShdP1YBQg2)Jmf>c1IhYjh!iM`B#BT!E|t| zT<)eJJ{T%D2Oo_>IpP`S9U%PdNt1DkvwALzzMz88{g-#b~Sg}-Wu8o|*+=*uq<+y&uV1HA;b=zf4K?%Zl=KhcU?)Lt#0oU~8?frXze;W}P z`#-+$w{`qw6ici|`%tEB$n8#QWhyflR&Lbocu_HAYQlAO(K~3AQ2%nTf9#AmcOFTt zfbof9N>34?NY5OC{yE5#3?A#qH#iA54J8+>Ok$3eNg46J--(@dA9~bi^WGaadvgxx zrXK84Ndg9;MJb%?%saJ|K*AfMu=?{}JWwNB4p-l&ZXJzLg^yn=pITUlbHG3L_LPGP zbXQErwe#@*0)Y0MyN3KNKNFHk2W2ZStI5%tYb9*7pwXj8_6x8+S%CN_xz5mi&0dhJ zoo&UTKPt{3TJ?3}C=<;qD_F_qhJ?Je|7d(lN@Etn9n8!7#sPk0J}A{fDLy_2W_iax zx3Pr5GrLVaVZjR8?ub;V{T8U#e~9KE#5r;OtDsjYe& zxEqG^vBtmQ|9zLCFo~Fy|8nv_D~4%L=-9Y*w%sH)7EETgS^}rTb^dvLOPrCjDxRJE z#}e~kd13!K`#%`=eF`srlW4}Y;L8vm5;ZBGEYe)nA-*BRahv4FG^G~JyBg!3?3JP&v zh#x^s-~Sg5tGoL}wUbZ8+`TM+xC`9T4N%t@_bOl{lvZ`7Z8XYx1;UhpPoYqv@ksxL z5*_C?Q5$?;f1%R9Q)2P?fmiL1JdoBRe^>SI%L|C0A@ael{Z2Oc|PkR^yNlaqS`F6HNx4WHuXDmx$5zo|v_S^0oigHd~}n9J4%XZQWzK>m+>mrM6X zY2r6&=)ZQTx>=j>$a?Kw0)HQ9FVV&BmdmlSAs99vT%g~Fs1F6N;QW1Z6E!&S|8he} z+@xnY`X8z#617!6e8LNE)wzf=8{?jKTuTeZ{=Ke4Q)_tmm+}qC1u^ITm*3m^8?G(f zwHA9UIuIxeH{;)p(;P#4?QTO(u(S$%CqL9mT$o!EC+my7orXBm7GOgKZ!|anB{-U@^E>pe-q??6hHDo|NCymB{4bsx2QXA zG4Z`=fim`;|1?_^zm_E{m$c~7Z{;j;{b*He&n4D4P8 zqX%7h`1`^C?l%7JF%%6&sR`#4Sl}L5{_E&J^<$6dZ@m7$ZPtJKu1V0p+K7L0@*e>I zuO$5|;6#e`pQHcNwv_?_eF2_Dk4TX$!Ur3XoEFZfzB^3pVtr?)Wk*lc^4(ou7K~B} z#-Qw{oct;fTM8RlsTsH+!T18uX%}M?aJt7Kb7Xi1$3`*FU{rfUSuI`V*ApBoF9Vdj z@8z?fD-s9TAR4Gua}w zBskZIs$w4yPIFMYo$;Jv8EjE{Md^WxjGydW6@Own^YrRq+z>Io;Pluwd@`zYatw*d zhhtF?`15uJn-nbyP%5wbsz&5Li6ko0o$2f4soMuJAeZ~z%#t>O$32eDHq$9A4nv+O zz%u@|V1i+rwfG%4OGXST28)QaBPA6VbNv2@a8OcdQ^&C?_vs^k_Kg|~;kLR4GmM#r zn~8)g49RtY_v3^um%iRHooW@CVfr??AE3^>iZCyIjn+c2rBAM zLcJ1kAt#x+ex}P5WxG7H@weoLfC{^ScGs2M5j9z!*qx7g^@cUZKJs9jhZVjkq@GT3jyE%0co`}hXXe%}>HWm`+LUMmon z9$v6djC-sTM(ji^x~K(1HJ7+dFJGmGP%=fZS9gr78%k~$MU0OLl@vqM^yGfxb`o4b zrfQ2T^1-fI{A5MQ;F4aJK}J7Ic`L7S5HA^A#ulz^YKpb@^0V{%a??4pX|raNi4-l2 z5jjAl+eWjBE&KXJtEn168dLEKIz7%Knc2g$n??<|@qZZqKw5ZQ2BwQWQ_b!J84KG8ED~A z1K4&JbGi*Q*2bfir+pV<-2Pdx$4r{=gCuG@^Qy1h1kMd9XTsdeRK$7*4OU^KzBSvZ z9by7kIfF$oVoB0^FEw@gk=O_j@lY&h^C%W*l#d*P=IpVgITaw0;r8k<2y11b5gL;S~M7x1fajjKmY#$h!PbHwQaWTeRCT1&Duy&J~IS%LZ zo;53IpUQ5DsFn;~7yHgt&Q(MNS;Cxy`(ut7@<{Wna}t^bC|1lpG?h&aCcgZ8gPPt!yfx?cI6luw|@3^DjzD6CNs^T2BJB^&_?E%Z2f!`RUTC92c*iPm85pc z_mCPs>T%+={a4d1<>ko8>>JR@J&%B?ieIM#K;Z${(v)nEz+p~HAkNTid)F}1^%V6O zzmxD8jwy95SHwaIN86s0Z+%kRc;Y{17*EJEsu_}`e>ql8wrj~AW*BnPLUGh=!`Som zJ-(H;q|Uq%`6r5M!1Y+{0h2?^Kq;(B5s4*v$?3$BEdcK^ZSbXnbIYLnv=)JTRwpw#fDz7~AUc{ZpH9;tDe& z0t?#$wdTe-fh$Dyd{0IW(~1lu?a{?gYobgp6;uv%dhyRAOk*@NmX4zr{#CQ(_pgHi zbZ-Ja3O^U4{eG*-HULw1v0ub!b*a~dq%q6S-Vu>d$`1}gALBZnZ7)W9^F75xTK~p9 zF2PzU>0FyfR5}Wr_SYOk3ILg~#gzg2R_=~@zYn(OQR5nE86feKCVNE#>Z9;v@wNQv zx;q(fig6_k~VpEzbjCzR&=)4PJ&x!~^knfqSQk21ntl^wLp~D1{=|`!;%>hZ+a#M_^BDXn+}Pnu zbJ(N}*HTX%RPM8q6ILK2o5(L#>IS5}I9rzGg`~CsqwT8hh96{>p|?(?+8;K3vvT>T zI_*d_kv6x{Zm+W&$)6SEu5ds3nyM0h;VI}RX3bXP;b;uwzRsWb6R^)eO$c5V?fQjG zl8T@@feDsIRtHsPpyaR-5bMNvzo9X*`2}MHO07hOCfuoY(VcqUWbb;b^UsWn#)~1z zk@Gm@KLdelXTBCpbQ5v{3%u4&1d;;X*JYdL52KJ}P`?WM@d+vN@?FSKS6m7DgOfb( z1eme^#$z%l15>?i=|WU`a~LSwjvj1DsFw=pMM65|>xbXoYd;dw#Ne+jH1WZa!(@Ax+|&JkMu&?;psS?K6+ zcgZhuNuOPWNvfefO2L1bgVAr~b$d}rX2f;8EVK~ihLg-3yOj|aGgK5`aj`mpFQgXV z-F{EIy2&WH;_cxiTEKlP$i&spez1pJYd|6gwr>OsSse7nC=qb zq7mBGOt!wpR>iH&yMg$jUKLRSBxk2o&s&f3*1dE>TK*Tx>9wY0aK zPpu-gQZy}Fy?;$M}VD3P6IUh4e4x~4FV{*EP zIhQ3Gp7E4(8_6)AILcR=!D4)mA~2zGLu^!WZQQ0=)EAO74uZRU*93FUG4h(eNn9Z7 z)0NuSboTW%{Z))LM>D~F9=u$Ie&pJ$-b%MQ``bKAl|&Z_!$fJ~FcCN3o4QP`0>dGq#5<*;Sy-&xld ztT>=L=_HWkV!}jf39c-SgEm8p6nM3WebA*c)cidku#&0yZJp~pQds2CKzNbGX5z;Q&i^p*^;^})(Agfs*c%`x(rG~(P z3&J&ZjYCXD=M`^3enpAoB(*JmSybGw=kIJS5xu{kqqzJvoJQ$KjyFM9m*)vAYbn!r zL$H8=P-yz(`#3^_i@T5ys|j~VMHGOkc=Pl; zsN3Cq!S0eKf^56awcAtrXs|*rEVr~#Fp-@6^|?itS#{tEUE-l#uPc2)5Qed4w#%-sFg!qndSky zmi%np3O?ths9JmG-Vj%sN-T1k1nIUZmq>QM8#Xic)D~93LVZ!hIFO&nnIM?eFAR-Jf#W|{AePF0l^V>2^cSH%r0TWR*y!~B4r7_=?HE)EJ1$U5yfFHNYv2Bs zkaWhiy;vc}&HQq(RF2*LTkTRQva2qi+R0XP!^xm>BM27u0piC zwYM99rGXrzcDIUea=!Ein?JkGq(?@Shd|P3I9>m2>k;1X#BHQY0LA4bHR+!u@<2 zoxaI9W2v!&kjm#Y&uRRwEjO+JomD*TaDr~^h(5Fk?Ph&EuuNZmuJ$i?lBMcjwX2%E_SpcK*((dBcn5xqj=30loj5q?i z5ds@rf(g8nE_(0b=ndejw)G6~9pm*5tfjW9%>!3K^KY!Pj_q2>9tikhVLQ%OrCiEC z%$uof=XX)iW{U(}6jhy+oWHtTi0~G}j`WDl3P;Eac9^QMxkv7ZS=q@d4DPm$AF44K zdRH`cs^7}%>0q^63BovbF9EB-^qARq^I~+6BD5}k0OE_D7~2A6R3lZOJ2$Ov{&A$w zeBm!oZ3c3s4;yJ3p9j(FXv)KxV+i!o?F*7#Y)60i8M7AHBen)ylUEi+b?zuoB_l)@ zkIATeBrT3cZ8fYS9qg)eDuoN*behf-#YG{pcfd*Xxk$s!LKg_qTFZj@5O=VAeOtIR zH%Vib$tU)4_{)LO**=xt7R6}MCL>0%ymp{qFe7SegB%g~=H8*_T^-fwhJL-5Bi^JbYfpY2$5O?k z_uQ}vLIufSKW=&{2r~0itR;JB*(d$jxdnTTtOO2sHff1>&XD56Nq9fR7#81(w~XBd z%IRqgb*R$AUd#j2;azl32gL)TQzB=gbCe&YLKS}7XNd%L`HLfbsI}=TU@PR$u}b%l zm&nL0$IA>=%*O=?TlgMQSfbephISS(z<$10$)R`Nln6CF#DX2V{y8uaIWJe=&YV5A ziS~f?2j5%}zGPb`9IzXIYEBJKTL%S-5uJ1%;iSz{V_CBAw=2+_Keq8iDvFV(ZMyhy zguGv+3c$IIsprB}oQg52%WEiD^|{&%uH8&l24|Y{Qc<`iJc?sMxbL_8Vh)J(?I`Kx zH{cgctmf;&Z-;+ZL~xF6?{d28ijb?ggL?2tTWw6HZ{5cwAFSPr z3iu)NcomwA<5ITZC5^}h-`U=m z6N>oqg%nNgU}Z9GTZDYGJA^${`)bBUoJ_8T^^1<^0AC2y&iX z9)3CTXeD)M*^t}#5zrECJUWoE@1Wz%L7Fz$V@pDZnl}9DjQ*t6BsLqP%Skn`WE2{ zc~3kg<|SJ#>Etj8_!os9(j}=$Pq~X+8f&!)y}AeMsgeUq1HnIP zN|E~8*>=;hLy9ER zR7g<(3wL2M_)kb5I!*Dd@kxm*5d>v;1|R58k#o;V&qf{5Y#n`H5yJhpOs|NbG_IY@ z)-B^>)fq{ga9S}#?na}H))#ujQA?&hdg6K63>D#vjvHrLRNK5ynji85)G|X|CJpif zL_<-I=~z5yEX(>FN<0O><4$ht`}8+v1Do3EP~lWd(Z+4>9VObf1zD;rC$=#gewqcr z$%B)2<>ywA65ZQbz#k}=pYCNZ>1mowi&0ybb%%)zXn?nGJ>p&qV9ur1e?49`e_$Nx zWk_4FkpK|+d5;A@HpmboLV3kFp;C&nKa zlq%HX5GMAYn?f{iXkji6_?7c#zlSWmAV5>-UBC-PG`)ia*bjS%e0w-q&0g*{FsoY+ zmE~pa^{G&!$K0t=R`@l>+3a;x2Wkc;DXmPuylfaCkn^bB*hcpQ*Da5NF!4jBH?3aY zE{}s1y_SrUdfYyc$h#a^B3{>B`12i+p3zyBh|`5vC*%5Ectm=JH3$f%$X3g{Ceqi) zzh1|XDVVY4hIk7H=|i*TL)i(x_%3eouyNsPp|CZ5IUdHMjixc_?#IM2Q`lG>8j*eK zjk|{?9krsMWp)@V6FULvc9Sa(@hU@!U-qrUgDSz*rbBJXJ4j}K3lnALwk!;}Ob#9p z$|3d9K{ErU@i>SJy83Fa?z1?nM>MeUYFSK4u)y`FN+5WMGzwa{#EK@AXXhRd(ix6h z1U}bs6pwSS?;{T{y>^!#h2p+JE@ClsXgX3EF`#*0ui)t28BfnDeH--mUF-?QByn$?QH&n0o{N7v&`9h3pPjwhtd?xjU z*#afAggvO}YPwotl^zN6<2P<7rnmai1T}~gykW~^n9U{<7-qp-m96d-GI3rel0NiwkFD_Ac?bzIN2KR6%7QDlJp9mL+1>fe3 z{N0z)m#7=tZ?C(}s7g+%;PqX0M=`xJL|hm~@x(MIx?8jybRwSP`p6fmaj*(YGDN%W z$5a&j6HeFE`gxP+_$%x=M_iMf!+oqjF*`~x)Jivon4X%%(6vk%cIonA+N+mN;exUc zWqCFdx(YY}xv%raoBKSqys5ah;WO3G34o+tWAwqJw!`9nTtpw76NieP*9LfPue~(| zMe^d%w=LvD9b+!U*ifJ@54AwzjKyq?8S)0Sb0Y4$RAdUl4i> zY%j98j=8}kuI>)_+g#T3Ow=2iSVT$bwH;B^GzvW^MT27}MwaeR#0+Y?e?58vZ8Pz;@i5-FHFPkw&4@1M;FbiiKN9xqvGta`8^z zA<>2>xVbl0C(ai6Ut}E4{J7XMWm_min){3Nf_03`%b;j_ldBx~!&|_*Euw61O5?vn zL9!*Hqkz0cpXq8;BUnN7A5}Q!pBU}(k%G%}5O(YKIFT?`(0jH%xI%)z&DE6`*h(yu`YfeNwg2$%CIx1dRv^jff7+y-wLi1S^dpfQ6!H{)Re&l z76$8hSzfX2`b?pTbyS$`7PNrsFz*gmUvmeIEhs#R#B~!<|SR&#}XFZ4t-Asewfg{(AADZlc0n* z*&9HWh8P!y_3$8hCOo2Fm7)a}2sqyHZ*<0d+t=lElBb)_~&lF6vVO!~EK{ zK}P(pOd4-Udlc)tKaeh5^y6WJpHS3A=+tSvM(m?otq~?j)kM>hbagil?_L!uxB5}N zfj1}TJm+SCBjVs}XT9u1A(2bxv=-}LuowwySbr*0bHX*eo5bQ(>+RSLLEJ!7yVBLD z+#dpUn86Ci(8^tTVGQE(E^h3{NVye{sC&_23$)m*37Dg8&a}QAk}Gc${eg}#H{76w zf6Xs(W8&suTg4ww{hRY28ALz8qLr+Wf1Omee-Wg&Q{Y+nS6BuU>|3blI&MTfVqzjt zI`6^z;DuD$^&b%eYv$!y{`{rtM9Q@DYV&sG9=(%U{Mw9(9PNmX7pqDG$9y@&NK3*y zN;!qD&&Oo11k&QqHh3XR-ZT5Kp9aErY8+>J?yriwBZA`P2DcM?8xdX$RkZ{l9bu-^ zH&f(;3Xt$vVU40*c;v3XsM=JMgsgj&mFLuCWa_%1h?iJ4~ zPJ(|lDhBp3(Qx!H#>&%L>q%HV#5Mwye3ll(1GQ@F^>oIwzI06|Mf@WiN4VIr&oLJ1 zB6X;PtKSstteeJmtS+3D?Mr#8mleg^yk5iu?X*AHFmE3nwyf!lb_z}qOW3Wh3WJZ7 z0Q{+9fgoKAcc}5u=FC=w6kT69=HO7z$gj%CGmt4Llv?6p}d)ro1&4J5SfT@gYH!b zJ5QBd)ibUbN)z@ z!S~^{ZdHn-59>S_I5^$ia{Rc0PwTRNOjiLtmjdMtV>KQgW3#yba?jd@I7*?H^d-J?p8{c_iGm*d9u?twTfv9rQfu^uf$!!_tmU z%T~VTZmoZat#$GgC18u@b5sJ!X(Yqka}YH845!fLEzFOQIBiv*tx(EdbXwOgWjp$|QcVg+ZazA1(=^VSFJZsDH(OFUyU^g3@`(CmBC zWz67&XS%i3d>G!da_8!t3$2H*duLKwV|hRLoUk>$hD$ZSPi*l9Bk7<0DPX6WrW~cK z!7B5#Xf|EfAdhpGqk!MU>2eb7OU89S!ELlp@VT0wW2xtGsfQYbH*?vDJ#obf1U2iQrx~}}i+E+OKiY|s_6wLW z`h8Pqhys}&1w-?0D#GXL->BwY9oFTy+Qun%LIQ}8( zT7;!X;(b>bN;jC4kT_c4rHiMDS^d0;Q3nJVINh*GJA=a=W4{>+3roV$AJP5K9MPIUEsf+ z43@JHShpf+0UwyoZI2 z+l)F;gYfL#gcd?u-PSrdbU~6%NR>J4RPufc7tz#qZrgLM!zph9i;LnE*7Fsh|5eV9Hrz_`KHQX`eKDJL?`IwO zz`JiqFs#~`7zwA?Zj(qZbYd!`uw3|C5dBD<83|s{5Dr*Ef^yP^q_|m)ws29>KR`ZZ zlNH`$fKEP{3F80Z97r@T0)v-WFJd3@M47#m%(C(YJ4#s``0VzFVk;4IhVI8LONGpD zmd4!c7bLF*RdWtVm(lRwP?~|{8JOcJ1}>C}a6(apyU^hyLdI6@ zk$)1v$F4b-#)wdgb(H2$+%THYW-FG!3PK0Rxs)-gvI9csMWD)r?r*)~MRI`Y7FV6` zHI3C0bs*7**;MYl{_G%J2|Sn4IF9OntG;3wK#Q`er6*Ha>3W52*YL0p2GLUkTZ59x!4@8{GbNPmnRkSlJ?VSgA&r zJ9X8TL6-g!M@+kvbB4Gs%4Q^v2u6MOA{pW(m+wxC2`Y3xRPOo(rHXpbZbyeL%XD6Ji}?@C;unn-Jh!@&U>|e1|^W_eY*# z#{N-^Iy~L0g9k)VE3JkOWO0&m+};G_`ros*j&d;BE@L70%5-@TZcBcA+- zTwHfYZ$o}@<(D*Fg-EY;X#1PN*NiP zJ%%KCp6mQ04=cyB5r4G<_+)SFuq+(*1Mo6Kr3Tboo1d1ReCz1Npb5SYO{yO;c_1vX z(SdaMY1Ft-Orbs$1_{cli(HBQzOEyZ{W1z808iDBNRxEVH4E&4gdPn21aclk*#~ud z{r#iGU~55&F(fe^$`C>`bdrjOO`+BwGp21MKmHTAhO2`3z0%ndhC;FNDs>_=*Khm-9S0Wy{c)4@ zdmHZY!WO6s#t*f;cLCf4nD7%kJqVL|a>Z7DR^!n~u<-9E9wzB2Bxx@*U#-ES ztc%VZmg}^0+Oy@XW$ci{V+QY&FH2az+t{b#xGM zO7SVrX+{q=zYzhz?YLrG4KSobz~0`GUxEu?o0Iq{&?{{88NXt*bwBV-@)s=Z`ibkW zDva7y`nQ7}YPHl5Gr8vNxp5}&;8-UaUxd<5@js1ZYgOxa=ShB$wyE2*cytGHdB5Tq z^fZ!8%0g_&787J@E2oMZwNENjJ>PKMX?#1=S@r4g+7VWQcRBM&5`4(|F~z^IW<-Cr zfpC(sBC&oHdUJ8L(=_bwgj6qGm;3y!?bR9!lJR1Y*>lK0XcPjz4>b+JTutydH+uS_ zRfgm(e|Zr{pIXun=^8eLnSLQzq%;ce9;2v9B_jl6n=c`QR>}wv@%yB;D{9Tc2AtfMM>N<%Tp>!HX^q~+^E%O zWMwpJ70xAM$Xp5Z^}TKF9`=aK4TMaBEPO8Y(V(L#3s-n<;M9DX4y1SCsvl6{5>Xjp z>9oE47+;n^9Z+jM_Y0w>IsTx|HVxaBkr%1FY0>kA*4Acz$fWf;j)vdrPC^45$n`OK zF>k6$AJP|d*(_GgY8D9=9;uIz-2}CEhe$l{!Mg8nh|9b@-PGo)HnxZp`faAt9Zk)AwhiAp-ww&T?R-z*ZAL|Pzs^;9s2TdH z3owAh9whq5T75>KT)fn5bBb7c-QUhx34X!2>W7ioMYvdgLu-O~J?RxY@GSV`5Hb?h zpll!+iFxbBvFn^$5{J_6i4}DvF?FlvwdGS`Uk3WhNWC&5QmP-tqhj4g;CtClLRK*7 z$aHRHXR|s;9Gs>Z$ZH*yCv{IZirO)PV|!BBWFS0yo6hiaB`N!9yabGXfIk`o=S3;B zv6D^_YTl(@K4Nb2TbCE81;&Z)E_S^+4xt{`Eg3DM`l9ex`?}&gQ$Bcji?mg3t+#uV zZB&m_l)#UNqM&B@1T1Y)))~bSM^Q+Dr0%I%T#>xg@WOliP|Z9sZ9_Z*k6_Q-HU|@N zY#~Q=kb--Yd?D`M%}FDvJ_dvzw{Rn3t~~O*-}tU?P3xSc47e)?`ofj7`oKiE-Mwma z#3faWsZndp6!+823q9bvO`;m*WGL$1reexPB_r2VeaW?9G;2Jp2vtSPe^Oz};{%HG z@+cv&Vkem`2e0LLgFR)R&LzzGt#|coDaKe`&jPFX&LE2n_v^?qWBO%%6TVhh?JMwe zP^9`E_;*byA*@n!3q<6(QEKF;8HWa#{g#U&Y(l+IlBt*rr!oC`zwGQ9b`40VOuP0w zPJ0Qu0jG;om|Y3JQ%*jHV|vOjWfP5j7W*|GQNU&Q%w zLex;_chv)Kz9w@0zeveXpo(xWsII_%dP78r-rXpDH#(eGak)!x%Zw<1<1r`+83Sa(k+9vyG_=a zq8I66A8dpI*>7fV8}l7p+<<$N0yy)j3-uH7S%VL`bR5*b<6|o>5E@%~tc3saHF`j#<9jbx$-M0FefZ1ZB6wCwZ~Aa2mme&4j9ajiwg_V# zHyo=xS>?!JYC^Tzleb|gekARqgGW+sD8{=td<5sahn=UvMHZ`9$~9k!Kq9n~vy$v| zpbzs-ONdbDdg4QSh&Lcjv}kr)?_#rfIT6GqP{X3 z?K80yRju#M*pfS2Mz7$I*_(Ze8SDRh*>yIi6^xtv+@Wt+AhpTItRr#s;5GA;=1Mzanab!% z%czy9k}QMt_-D+sEzgdvlp=Ly7IHEO_`?%|GIJoUxMLIo20^;t%5*}?t`(S&yU>!- z=6VG&eZlJCT`M zW+8^Qe7i-&ME@Ht!lB>|LX0`>F_;w;I zR|`faPA6i1LWNPBN5kYuTOL&|-9{aJfuJdJxC;I4Z9O#0U)qUAQg3ge5(K0K?=FTxUV!iXtaAAawmqPIBV^)3XN}{8UAUDXV zf!AM~Z$SpjmL373xz)tRazg}g2Fy>#W-LDFoBqY-O-eL*u_tX5MsO?7=DSNficKxt z1pB&y-zjog#aZ9H3N!O$A@HcEEdZLBfZI0iO3p_qjqfbzg0)hQ@6m5cPg>@vF)%+5 zTk<^N+_;VH&>L-+XM4i&oY~F`@qI587Y%Pwxfn_m62alLsL^vDAn#rWQ?U8vru|*R zi2|7+XqXYyKW*GFibb_gkb+S*`SCClnXbN6J=?^55&iitktF>z#D?Ig{I|&BGwI?B zA(>P9Vu-S0c|7vUq??QJU)UzP!&lOVTrHN%7>VG_WO#an8*v~iDxV#XK_jmo+*1-z z*qph{HUz*{OTI6yBBVgGR>E~(Y7jpgHT}Y?@fk#-1Or7KH+~o zF4EaC2xBsN7mN%S2q9~ELT<4Pm%YXR0-?;)oE0gh?)Ee$y0f@_>(7@RSz16Tyz@U0 zX=Cw}HjUFG0o63)i6QFe4IGZh@O4>IPG}F^5#m*W$;=-k@WkKSb-q_LU~tD6V!;5e z6T#Xq8AvoNZ}La~b`YKz$*9l{1X`QQ#7bgQK(I|w(M@CaEMEZ%dk+su#1*+p4~!c! zeYmPl50TvP_0gjTDVQr98}3FzzW^sB{y3djk+2(9NTd+(f`U9k$!-g(xcVV*;k8mA z{o)!pOlw1%L4>OGeO4{CK^1lVK=)o$hk=v9bnS{Aox_;bi6OsxzDh%$$E%eqNNj{> zor(FXSmXZzOF*>0z@5n-+@gLgVr34IsCF`aK2wPQ1wPE-OVq8#yk1jI)Tn3(71Y4>3s;wGI+r|YWwq*ySI{jr%*Po~FJym7y~>j(1R+cwNS01_`nh=`_mGxw=4IY;4OY zzCvkG;&YGfnh(P6iGtfs*2=b{I<(cEp~DSvt-GwRLZ6qV%-kcUK8Cd+@}g{JMx5kS zLZ0h@?wDpw{>3;?Hy&j=AiTl!--6K<`U(HP7k#(JpViL-JICB{b~mn6QwH?+G#TnW z)1GHZ;^6m6s#VmmxLWIk|2>=_j!2AZ_4#nePW5MdN-__vw2hlGvUc@H1p0-5MWkq% zf=@vBQhfcDIQ;%r!+c6%KSNtY49LhIKHyVUc+gXEpSDLeqEzrJd59*Rw~BT)NWewi z0h!@(P=IF4v3tSF|5YFlonzFW)k5m`oC$;PiMsgMPe0n<$d{0iI#QV<*(Z~Odnh>ygJpPAc$rRZ7{P;5XM?NO4VcBaX zGoP`TGOG?ZD=p$ZCRTtm-3&Xw%mbOOamSP8aQPcN^cEV_t4Y{)mzCG0l+@$Vi5e|5 zVk2L|wOBujg5N_i8?ZNytUUH~eHIJ666krXsoBK~+%Ak{oAfeqsvj2kSFD7B~frP7UAZM4zrG#(@AhqieLKilu`f16+io4UaJa_j7v?-;TDqVV+A&uCYL7 zbG$#t7sOn(v*-?Sjf$)hGaBTrOc!8qR9D+&DpJ9=%D0wo#f&t?wGqpP@OL*j6_87u1sVx2s2AD{5HldPmeEG!EBsfJc_Pw=dIZ7nXy1h_YJusHq! zze^MX3rhX_sz?gcOs_T^027cY0-(Q7!ihd{7jJGx2fI}tZt)6G`0YHni^1LM-l&u6 zTFNBmcAoM>mjc2U;FUxY2(RrX@P2)9*4-C1WA0}Tl)=p~iaAICKR2qwYa19Lw&Q>J zLEGm)9r$RpcXGfuj0eFDl-og_QI41l$~hxIoVYmVWXB92!DK_3cSi*+{K(HhX7(S4 zovG^+WH+jw>sAQleSrtUsTc>Lj$AvnH+L|px%e7OnbH|gAHyEkCge~LxV>pC?GNyM z8Bse%;uJoQYr2U&mI=dx1o5_MY(YU9qHP3a*%_(3&&lL3=f4` zq`tfCClox3Oo|H$7#Q?aJ`i_YM9R)p0<|08;br7K7rSrhbGXm7B#IQxIsdEeG`o;^ zErjN$Erna^CEc{9;eNOW(jGf}2;;niDU9cHyraaWMuz{9QnN^g5jQODyly4eO(c~0 zo42xx^h=~B+mV$+4niQ{qBo}w8wBsF*>@AncLn_H@);l=^f zoI{GEl(&9NWIK==auZi}7<7FKd>8P&6Wn;cr)^rI zK2U>JRIj#=`{L)QZU{j&UjB_*4sj{{Ey5unb{$adlw#xLQ@3@#BvZMC8zcmDH0ZA- zne6@(_Gr!!tM|TSm8kJK%_>)0ic$4Y{Aae3w^)v-2JN?$Nk5cw#eVw_I)kLnZrySd z<7{7MES$q1VsETf3NLj0mh0lRskMI-im|Vr@+39{*0}sv4;M| z*foe1J2xHwfg_pTe^Ju#){Bx$74j{>)#cVLuAl~(d8s{8G6}91Whbu4_^M19ixDa6 zlwdmmq-O2pccDs*lROU#cpEO;3iAyH=zi`>H}J&?H}aGJ$7KM-v6g!$fK42SuU9UU z`RL@@e<8T>*x21UMAXJGZ0?e5TTpI($e-TlIwkMlGW#dr!d4uQ+kV0RwE;r*)c8?u z;62_Nw^Ch3A_|NL)$8U#9Mc;}R=&uAe1n=rhRFuPuS-YG)n8we!J{n`>hYejKY#@kGKec z8jL29S$4u-&2jNrARbg&NxdW#G5ymk^2e>Bq^STbXAAd~S2?+849&4DuXK3YMzQVG zRvE{_I*RiGd>~T1tmrDI%w!c0FA=3jfm(kD)X_sMdeuF2mv{@WZ#Y0D<>to2eI_hB zX9gAo=Vvp+Z_B^>%5jB5O2Q00DuIzpaw1I_mtcrWhf4j(kXujzsGnF7VPp_P_$Iml~v;O%{_-7WBDYfw}PDc@+^vnC>E zC6zRH)0bK6g1*G8I?{LD=)>$dB2k5u@B_Gg+zUa(y`GUZfdz*&{7|#LH+>rhA+D@F zdJnwkb&J5P0{@s?z(jNY=wu%h@DdnVq8Kb_(9yyrA zpkN9gM*>s*MyAv)?x;>lRC3sFLd)5zbo6uFjoZE%4^t~UwA~7Gk*#Er2!mxfiX;} zuDucfuyzwoU$p%I{Xn1BHUb_=(?E4l$s6-HE5Pa7fhmhj%-~`WBxW!|4X5u*lvStPn0+c*pl=q&)M59FIT;9!5l z>(rXD)WM#_BckG8H-VrQHEgW?f@7kjJMuyVrq*;h(+Bu|jyIn1|n23@rB&RiyKCPdoR4VAT;NBno8YIgt1AqD3nXF2=pPop)C8jp`M}m*)!H_qp`mJsT{gi9A70pb` z)VYQySiNP&0i~s)mc$*J5^M)C1J(qX(0JuAYnlsO9#*XvrV4VII%xT<17p6r1~t=h zI;;fk$aB)vZKM`PqB;tpo6@)O_J?vIWf-i8s57KrI^B~N;J|`3-g%40*kMl08HRghPY_^9!CO&bP|wJp>};h;~^! zGI5vo^*2Kz&N>U6(;tKr+vtyIy>a5k6R(E!i8tfe4UYCN?d&3Q0p%k2LFORbK$XXl zbqxMYE8M@TjYlNQ9;KG301vcuPqYM_SpOfk1&hN#*kkb=eFLaW_3XEBcu=)qRA*E=8!v^s)n{uv6p&B-P7i-EEA zX9qdWrqhGL?4~uCn@S0aY-gEY2x0JgJ<531vo(mQHjn^!Z)LY;Z}0l{pbbQVhoOgg zG+s2BwD#~RVdrTHSno*Avh^j0jB&N05PG}kRCB!}uqZ2=hP?!)DoeYKs~JabL4;9w zamWQI(!Pef0J6q35j2Iplzma%GP~N`uoI9TRBScf9>mCPI}}^E91p|pXkcG7mQV#Z ziJww!7YpEJ&Xep&e2W(u@nHUQ;4(|aS^N``2~QrSr+;}TN;P-{5w3)q$%Q_AS|y{Vu(1n z+-^A}ajWKN8ngthsXn0@J!6y;>kB}m5n<+2kq1S79BU(c7AGz5dop#N`O<8A5*d7; zPqI0^ho)l6;tB4$a&gu(F;2O0j$BBLzPI6OaqIg5O!$af@7YCkSv)??W!8eZ|(NEX`FE?R$y!~|hjlxxs2NUgJyf}Oef4Ux_614wNx7scKQ-FNiu zJ73*}O~+4y3h-y^kCwT%D1(PwOT?|4@pJl`;pbwe`H3sg{~-laN&T%zj;w(p#M+OZ zbQK=EMZO@g2ZTDxLmBu~ilf12_$_+xMYj(^glfh@BYEC_qAq8S`Y6-gQYa7@lvabN zW?v7@AQ}|*V@dUxvYQn)xMB6GrEhzSNR41((_*JVXY@~95)KLV@I9kJRH?W{DxrXi zl=v_30sPGXFU3v6<<%sQ#pHacvuiL?LS4(rVv-W>UP~nDD_8Yv+pf>Ms-3b=VBm;v z@S~za&nv*wu6ZC9h_3-^{R5Isb?D5yc|a)(xTfV4lTanD^UyknjHnAUw07v;Tgbkk z9PxqEkiTO(VExwl{dwY1#e!~3^=ud!ryG2CQAT{VYJto!Cr5ErI*Na*4{OQ9@^E|v zT7X^w3TtGB%gs{iCj_A}%K78jN1EA-3`Arg^1YO|a^~GgR?+W+l~fHNrvpr2knML| zdm4LMBe&#A%V|8g=LBD7hb@2rv;-GNI#f9gXAIA8)zXGy1Tw6fD2_{lWfVae%Wa%$ z9dD%7>s$61Ga-nm>dlE3$KE0;bL;`^G{_}v$l!;?EEC$c2e(jb?t2L>1D+Q0QkQIb zCb_27FA1Gg2c5Jo-ZqdoX_BSFz09%gg*vrx<$_$4p2}e%_qX=I;|kBCBhyV?`fBs) z4zj^YAS>@99t$M+{LzwZXO+BDHd&C92bJv8T!2|+IUXz9X#8&P^x(~^7t;5(rX-WXaxCr zo{}2Jh_nHR4L47bAGnu<{OKpu@EwpWAb*PBo++8K(9HtVQ;?VJ`&la^mSyPRkzf<& zl;O?GehM)s|IES`%Tw1cUCbS5E>>M(k3dmTzw>^D!G(Cx0K(EIZq2MW8^?}0EKR-G z4;YifyX2{38o;?7Y^SI}pXlOy$FO)+nZ#wtMpL&Fj|thywTbzZaG3!M7*XnI>Pd z1j;bUl*K>kz|1j;wAl5FTH-=zZK%Wn(0eq3-UiW$j93g7W(Imv0!oAS^lhqG@P|sx zs%3y2ID%vGo9k%K>{~eZIZxZ{bNCV?mG)QofB8p6+ zM5YL*N^U2F?4Car1Yqikxy@_F%9c(| z!v;GCoV5#?%FbAyrN(v~UV2eibnOkJ6)vIvE|af zw5wJ~aQUU2Z1eGrdrotX{QS@0uyM2}Z@cj0I_SdL91jvi^YPE;3B0ia zU-n@GKSE=?n$CJd+_T(_IY*9VAArE|T5rywU(e*>MN#HvHc}d*k8cA~?O6UT2##H zd-7l&r1iJ)7r(~91}#p~1I920%qcMwRNK%AwplwFI>0)JA{mZIlULW~> zLLgtRjNQR&JQ(M;OmvyopMD=-n`0A25tA<+b{~#sKGyXh9||rcSiE`79K`bAY48>k z3D(eBw?pe*VO<2JWPX7w#n>WrRcSS}U+X&cOZL$KTlSfcmzZf_SJ`do2Y%TB%5GVO zlM?Tb9yq%jk%PS=`}~xtK>3a>^kFclBYS9%KTiy>ufPgy3hXEjh>!@D`1+K>0}nBz z7*PTE>@=d)?+N0@9qfhJI)a2m&vf`cMn87ZP+WGJusk&-oJ6^$N*Rw;8k}X^4XPbc zkU3liK186>d|3HST0Vi36?7^Dz3kOKywbaeIH!*>?%u+J4yZx1>R##YR!%}jog>WH z$=B*;wOa{&VQHGYV(9s%*)wMhn@^|DV^0_Q{dGFXvB6DlfD?Mv(TE3^r?1^$rR4kr zu6ZJ!1sUv)h@NH3}ba(R&aFJnaj@@u6BuRr8Xu0Kkw7uUt260a(hF;{;swJ zX(0#af|2ls#tcWZe6^&k(6~ zU;Xu-RkWqlp9n}-q+VQw!$)rIlGnd`%GmPRy6bjKa*a4hzXD=c;FF5tZ@icx*7mO* zWedF+k;*cAQq#J##MYcm!=nzZ3xk}t*!bN(NX4u+2BsDkPWuGBPF1Txg=ShC7nDOA z!x_irdpugMF;An-OLXXav{=;;$X`w)vtAZS;*_Z%G+t-3bsV(hd?)1t&Fyx|8HfWX zQvz^^hQAr?1Gq9y^EC$BidVCqq&hGpG$fwZ_O zRdOI5iLf<2_mrpW-%hw?&Y-;BlA_l2f_rZ4qz%&Whnmw+q`tli-Xa>v7VC^ISW=ia z^2lfA%h`eV*Hs8%LW2L;7x3_g32^pxW89b?PmNAg22P&fg0!Rnztv>TD;4Wy3B;eL z%Cg-1_1!4_8)k^P<te+P%)gW-g^G8H zbG|8@VP99rMt+=Hx{C51P7geu4ba!t0{p{7#fv(MAWxt0vpLF8Bx{QR0qurGP6NPj zq_$uV4)f_O!7$9$jGqw+hc}>oDGeqfUwoYn_IcvNK>T(v!G=T>Ou9T{=UC=BR4{iB z)tI~Gl{oTCRqcVM(7A~z4mcb;$(Dp3;1nX zVVWj6kMkI9Pp;549BA6|gqSsd0fGDR3t>Y?uh0cbd>$mIn`;c@`c!=pXOpJ;&vuFAx!qIbR%KnxPMW9b5I_1e56%xCTSFX4I%&U<4&c-qE@H|_a zWwOOs6W#kUmL@yaB0J;=jEE$Ri}LU*Ga;RA;lcNZDpc`76c_^ zo&4pa5VKoXYToW<>+m|9mB`CuRTO~W02&`UwB~Wf4BKK`YMhhvAk26;KAwyB{??JG zaq!aDJ^DJsDnvc8ZIft#-W`rl#Yi1;%$QQ)d$AxjeJ~rAO|arkRmWX8Fnvel^=9(1 zqE)$3sjkauoIE=UC?v4~vVGk0ux0FTUsw7Wme2baqJhc(Csyc$mSs=4;KVE_Pyv(i zD_cVb11hp+_zd&90r0;Aj5oWQr74*q?>d)Xs(tH^oXo%$aSi&u6xC+d zn$i@yI9j@k0EZ$?siDZ11@@s0{6X#DY#S{Slsr}xe~qmmLz74AHobj)N9Jfnfk4L= zsv!_5TSxaHMIGrz3t|c$Xiy9h1hWXZHW_j=>ah=lDZ!HBkF90Bp-}@pdb2(bizS=% zF#?nJJUu#okDHk3?puGyvJ&sY`OVyzn56zCrpj5rm2rRB9-)>HRl zas=h3<)SjP`Z`p51b!Worh{*qXo9%~>o0#f>Sf99GbGw+4w;^H3(oV>7a(-8cxZ(d z)a?KWyQh)##Mp)eyp7)|T2$9Xz(|*TEmS^Yd()$>6Ll>UL$G7d@Wv1Y)RW>+32hP{lC`_V za=0O;?=9#&5yLM~JwANj_XNlydkkrDL6uY2(4U$SwmnTXIm85%dx`ah=FKSR*>TC4 zJo-hI+gV(6jxqScCX*v$UMWZoqzE?0Ad)Erx>)vNwAh`j@q}s_SFZUpVkp&DG~^BE zorO5Q3Xp9a2Od$wO?x>4Wx3Y`+D8wxztr6Co|+OTqbZG4UFrkDm2uz03VF*ADbxFw z*vj73t$tG>$Sd^qMW$yJA-f2C+>YDzr zC}{ooedw^rJh|J2alWr>g>fO{W6P(X1M%=gLV#IUFyHf8B;8lr%I&LygzcSrrTbB&hh8y{^{eur>Kk>Plr0P_|z0OBt6(6?)@v7`PnGsc#8 znh)^3;gJocp4`lHl;@P3KS;~;TiwR_iC}3I7I3{3r|AN3o)JfJC1OV}SVopOjbdP3 zi6@eu?;(kbe%&^)&tmN*)%Povbr^J0D84#rr@C64=ouSK zD}W;DVKLw_j}q2>D$Ai*6-m~Wim(6mC8-wYK4e-+nC4C*jR@AUKo<%bv8gvnc%v@- z8n;r@S(eKOun5~zxVD)p$p@bBi9b2g8_9FeR3M;pb;|WSrW58dt@&;_M<*8{+wHJ% z%z+IY(*eMiIpv*ndkd`jerw+HBVK7qjK;b|EN^d(8Fx|}Q%a;!heHpMU;2A1o&Xdx zvJcS@3(aXv59Lg~Wie-o@n@wk*DCVK{u;{2xuV350RE?!tuz=X?uO82rawS)%!OA8 zHw1D+u}Bl^yG!3^wqqHRa*-?ayVQ8lV+N%AUJiE6+UsO%t`Q;)hZW1h0Bv;~9v{RFbeIpbZxR zFs8RH?e3uKor}O^fA0v+l)G`kFJParw>#I0xZ3on3R*dUPw!tcMnd8m5qr_+~I zcx~}j3<@cUsc~vz^ay!SRJP93Qt|N=w}UdEIZpe*XZtFkOXr!V|ArsI@J&L%t!wSQ zf-4D#N`=Du_JgGJ=L`cHY|>-Jnp}NQsI!-KS%qh~{XBeTyZ)~T*num#aDcbQsaKSs z9OX0yv*3VqoqGG;ZdY|cAn`H>46T%@st^A>*hGyd&{0D>Ju5Td6y=-|Khq8WyFF_A z@1(3m((*rFa2#Fl$P(tjzf@cnv49bUSZ=DES=$W&p?2HH#3WSHZ}YcEVY;7;bybVn z%`$;pErlk+&_H*QSSFLUoJQ{w*o?Khc)vSzg&(Bd4pC3igG~vN*o?KMq{qrPzWORp zK$Hzk;naJe1Px5|=EOKbe_#*{pi{73WYe5(t(EIAD2x@@ptJegq_{dsx*WAK`P-rn zl5U3sYFOzpwD1B?6R957|M5Ad}oUMk$4IFZUZhzG;W{N-Yp1;j^E zbJIHcVZIg!6jF|7q?5Qgh<;leEmo)79A2cDS1SnoXg<8orq3HhS3(F37I8$HVAxSP zk@Qqx<$z#eT1<%U6D#lQRB)K7`3f3I>R%Th|3=I4dEP((0001PEAMQ9RrvNQ%5eF! zUOl?<0Yg?1Lw(iq%{OxZBfAg@Ld)7iz#$rH1CB6VAJ2(lJ3`Dv@`RN>q@_J-R370g z`X*U%4VSf?)hP9cn^*_jYE`Q!RS zY9eIm;3tgbpo82n)qNs+Oy6r={y1RGk$;4O=KOD!pQ&YrzD1Qsf(w2j`yd=|EK2x zNfzk1DU=S(I`+FJJE8eqavanRffeQso^jQxuUORYKjP-VQbWl%w0~}YBqHsQ$?}2p zldYn1LPe@|a}Toa z=OIuuiqi$vXJ7Z)6*Ji*>pD`lvKW2NMA5ZQql5brreYvulCpYo4fM=PB9 zu{f7$_oRxmrCH=n6bWP8aZ z=9lyv86w)@U`S02tq5GwHJtLdO?2_JY}5**0n; zNupZ5J0NWPVpzHf=|3-ooD?I!i$2?&7wi-E7Uz2LR~ufH0ZT_PQ3SzICEeaGpig!{ z1YMDIjmLP(LlaPyn|kC6X7H8^vR&{h67uVssQ8fd>-)JmH6JZohMM@=t_v(d|JEYV zL3;vR)I{rl*Er)l8ZB%TFTVHD(#|HpYZTX;RFKHOt1-CO=kNlvh+WoBWR78YG+H=oS6q}(@3yus z$tuq!`X9{x=0S?dwIhJef~U9-FpY7}*{S zY(99<6bp7=77mkSf4;OgdyF~gpIgy|n><4P@ACcQ>(+OyzRQk^>E+Z(W#aRW={k%m z!T?DW{s1;j`zk?(>VGTMKxB&A-f4u9p|U~#x{wi-mE zy#W8~3*lF&#RdAJF7OQ^b%O+cL*nEgZ->B@F7ml!zAj*;En3E$a%upWniLSf5C(Vf z5?O3`J#8dq4Pn|;RAyx!p_)fg_39HPZ4X2h*{#)+a+N2=C4^bZH@4?biT^79(k%D0 z11B6AG}Wu-)Bu`x6Hhr6g2jw9sy>ArEgQeU!mm|7{%*#5_On-O!r2R#a$ z8tRFwzM3;5D*)Z%BKgzC$SlVkaxX9@MJHTe)|INw4gaTck)k_&A|Rcv1fdx)lb6mO zAqlW=d91)nvt*lMogvC$DP|{CQ__+V|hO|Kd00A^&$N&V+w->2B^CHw#nGf|U&$8PYQLoT) z4BSjXVAeIq334?zPj*^(S_U9O13ja$myPrlE8_%aHa1n_oArR-ji;dNdxwKBog#bt zThi+Mf`^Y}Jh>wwy;+d)B(iv0?uZ4uU%}6 z&u{7O-!Y(Luhoy*51a)*lSH!E*2Lbb4eeWpgjY)-eOBiXf;CwUF>bMFy;Wgl1&A|p z$rD=elni03(+rOn#I;|)npfhzo>=Z+G{vWPhDLNkNTrmR!gvE0^oNXYPI6HlAElId zWTn1X>kDhOaeN7~petYN7jD`Tcps^KeJ$&dQ5MKg6iK&>nd$X%Q*Ue!m~->t7%M zxS3%l-laB4m$Z8T6LeuEtV{p|gVs})yyD;+`9QD4jR#N)Z8{KlLQZ)CP{OevY;=9j9}ox0|Y#toJ@^Hf9C-FwSScgR1n?I@kPNVMM>C$9?-VYcVi~JbLnUeudr(J z;IwVvt|?gTMJq`=N-W>>(;SB3ACXT@c;e< zrB{P&7Qg6RtrK8f7xH~@Yw^7EQAJrG1moi+bQ26ndwa6quRqw`aI5dUsJ`2#J-A@c z1nt(2Oew2b^PJ@;lJ7vvY|Fwh2+*g6Q7p4-)?LpjPJz)tKiiDt^+TKbm0KT0l2zlT!P;A|Ws@qcZqBw@)~THk{Og&Z&JZQU0hmbYgF`L^gCl4w6-*@1nN`5@ly-zrJA zCAwgE8g_zVMmyQ8p#qBUKyTpZI5H_b{URRr$+R>l2>UjRxumeu?K$$dP%}oP{U$so z`VdQ`FFpMG=U5OZzkQ{F+p{Ay#Xqy8Z)*bBi+uu%hP_-MO?^_P$+!P z_cTx97;S9hx=d!NQWPZ*ppxpvyV0F_hN_L#ONB|%wa!W2q?sg59ZY3e4tkqy7sazz z112AI$nRvt20d!TL3n-$ZWW{WKy}Y=WunhK$1Pj}E;;L6@i9zZzN~06U&59BUB1$N zx>TBmD{IjncEgEOyB;Lx>(xWsronqfb1j;qeA@W1feqT{NL8x=?K#um6q5aJ**+})=+CfPX69^f^y01u54HUV_(BRUsTE9}FQq$UBemqY+LeEC6V}fd< z<;AXb4R%=!=~7uaW3NUIzu9tyYDg_0WHouZl06-dktvwwof6ePhNwej~eL0F2^bGdOg6Z7~^_Icd^|$e&Lr909(eIpNNbGEZg86+foR- zXu3suS*f1oLPpPoc?0v?sBMK=0zEGowCS)3R#mkKxwhEq=q(sRC-_WFs>z(-wbNHx z`mmx`w(aVaMy)ctK_R&|A+7_JS;5fPI9Jgk5v%ye_X8=qa4v$Qi}7KcaVdos&;B z0;5G=)pUEHZ6D6Sq_6v*0wt_|V{_Ox>W5Oe!oe{A^Pr23K6XUvMB)!d+7IE)78CVr zO7nUh@$Zk#JscVRzL43W$ z*c6rnIlqC~80}c^1^Q+;uTmF85luJM!1sl~=2_oEymJ(4Wx;@PCtOdvvTsU;1A+T@ z5eM$YdtCx6y3^nXGd$}Bv37M~1SB=driBJSr}ZwH&Ew7dxH7&lGFXep6>4&iA9$OE zpHdT2wzC1qeEHGj$?FZks{#k7R39w<4{Ez=B zNjNp$)J@u^{JNRV1q_5nSNBvC=%DGVz;;QCbNFrtR$vNvs9l>-E`A_{l@a1590fC# zAq{b-j7U;#C`Ij8NR&PYd}iQ=W%lSq4l@Q%oHRo)j0l znD2|wkKYfob}!ASSi_4yY0GN3yG!u-lV%WVfByNbS*O8=DJ3=-Qfj)g-p@lr^Xdoe zzaq~@r$gI)Q62s2pEJG96ZnQ3TR85M8LP-Vu$ww%<}gs8p_+TiJ__EA?#cBCz=#>h;*L5!*)UFEpZ>bE^x%YTMlG zt~sPB9SqAz4RNHR(GKa>u>N`{qZ2jj@Y=T-MG{tQq6Pvt1Wnt2!9T(>e?$Fm`~rU2 zl-BR5XPB!SyuJ2sw#`&u7}XCD?r(EIL#Ns&)3gtVZw$t)h6&X@xc|z=lDZ7f$c!~U zgvFYFD5TG&TJ`QiOPvmIUp8Q*#ec*QT7ppF({fi1w!Yw1o|_ZeGxyG)oY}(6lZsMa zhs+&k(h_Csfs>S!SoiTh4S>t-n6A3*!;Q9_;2F({Raw)^Yg-dOxNo^stJMt=l!ipc zFQ1%t3+>JQ2J==%4vWk!VR?Y$K25k=kCSKM#}{0Bjt#ovfKpPxI~H>oga`)#v^=h%kAdrm5Dj z(ee>BLT=W{1(N(>+>Lo>H3^}5c%%)rzB=vibOvbBXML6`C#b9%sy^F~#5sGb6SpP) znrmRL3CS=1i%RID1$^Dw_DBj`1fQ2t()`R{Gx$qQaX=RR-@r_8e&kd17R55Bfl{$Y zR7eKulj55keL_6BJ1^&rg|(6 z11>H2ZI3ke9<9tQ9pbJzJ)xEz<|*T8E}t8$41RwCtP&_Dg;G5xVj{&~|I?oP)uUtI zr%YWubMj+=Bb--hP<6UZFJMjbQ)q&s!A$~X`P9+UT)DebA9Yl41|JtjF;FuRA;3)w zyw01-E{t#;N`zf`YXp4@OV-IS!$K{!sdZ?sTElVH8w?QhwnoKKWgm{_szL)y2bY}6S-Rc#S1bS;nG%r?9l%YBhB`09cn90+M}CO- zkiXNJ^(YC=DlbvSZS>~9qN=Bv9ab$u`48$FLHQUJOc{CtjCWvMC+d;{M4Fhpr1(LW zfz1*DU?860u59eG1psAs5qOXucw(P(()5Y1K8KmzMbk64syzG9-wHqs34|4fAGYD~ z(fF-`Zzm!xc*on?53)F7)vL-_6{H%3!yPT0mg~Z9@vRLWk3>7h68DluEYeXwT;EFT zdT;5?h*|8)xKU;OGC~z}s>_!dTZSaHP~+L1o`MBD*kPT|od65QaBHk}bp74aaME&I zRB`hr8>0ZRr@Ip0UcK@dy787Hpg4rSHPm~^>gvd8iC{17sW?0AIHc*5%p7*h68FTo z>Saw1k8#MB)WozXp2}6zp%vs6lUbr}nI%MznT`|@gAs=ea=I%i(?FhhOuGQ|wBnq+ zdNC9h_>XHd{lmbFg5BsUEK`?~rn#3J7RETZi2gmv`WYP4iw;q+w?kCz{KbDbHLHN1 zaBHoW*4B8&!a-A0v$0>ad4Dxi?(CjI4=;g)e-^v2<5ftz4`}&yRuueEuW^|779+vc znJ%;+TJThPCp(_FlL|pP+VK9^5DyJcL2Lf_yR#vGLRGwLHCrNg%iEdH&HG>JB+`H9A_K z9v)-SnXz-Y;V`lYo$U$h_;Wgc_Lx z`A7A19w7uP3!o4ZRhU3@fC)F}Rq>0SOb;Wk`34bBcCfpyqjHe}fSnXwD)vQ1E9FV?qQKM(j;P(8Bo5+N^ zSNG4o3ZyGoo#XLbwv<2pDj~gHyfD3ubSe_^+C{B}9~r@-;?aoYLdhPi+T>GRt4+p` zPNt}r{C)f**O|cnaYQKgEiK7!h1bBVr)S0Iv(^BL<84G%Yk(7(KplMPm7r}&r@%1F zQQ>9Z^E%g~A8(bj-&UGF={5s5t%!94jzi*E3Lh7V37^emKUGljEWviP+8L&tC%S!L zfyqZczbt>Q_vFeRWcPvo*voHIRyuExevYcGN`;k+D)r)Q71k`YW{;Og585YBaW=UH zn9dr+P9Uq8@67^gA3!l>TG~C= z#P(OaV&$#9WZE%ZGaT-FD&a`Jlc|arUfK+|jrYweQG0Ku(yDIKvMbkr4xo5seH=~j z%#D)t<^_lw9e~-+)M$$FtEaSxHIF;PJ6sg>0XSV2sbmlGT?^$f6XSa+;J0cZuoe05i4T%ja?FxN;(8@9}gbAII8D z^^pP+r<4{(Qebp}atFN1lYUd}iwomH5xC$NFy{k|4O@`t?A0&#oPyS&^Y#gy26U%^ zSc5z|;0}Dq+?sVk%9Dz8d3;P1Ke+T>M@30?$hyw$tq?B8YO8v}6QWkX)~lV+=(m(n zKledv3g&sVcqNicOv#Ews#L?o-V-{N@2AeSh8o)L-ka4B?sct?fV<5LW6bs+{1Ts1 ziIm%&@^OgI143yx&)o;MapM{-Txp*7ru%4C`Lo%&WHg%W-_Ui@P@&)Xz5MK4DRG(1 z!p|dO_1yey*E{kJ>MyHiPCZ&XX=EX3u;6?k+vF~!;wIUZgP2tHvZ zY*6NvRr+}1%HW#(w^-EiDU?NA`?i>s?yU!AdN*he7&7nYMPk1lO`~=_*cpP&JW(4l z-i6l6Z&H=<7QgX98+Rx~+Vc|Gls#+^G3~IZem2A4avZaz7%F8iw${sp()Wq1OwQ5>YN;&JwE0W>Hg1dFPn%%N`ef@5`Dm?2gPUcLVJ*}OGlx5Lc{2Rjc46ZaFQZ_$lI z!uO7kSa-t)>O4Gxpt$)JGFh`n)eN?U00o&q`RL)NlBYl7)f0X6RA9?Kqh8hK#g65G z%?m%mI^P`PRo_!U1ncyYum1C7?e1w1e;!l5ROfVvK#VFe6=y7qr4^fF!va{QwQzcr ziAQKS<(PCVLLRDfPu9?aG z6n$mJ_Qzf|y?8bI_bWQG|HnV*K{UQ=P0K{=410Hyc${UI>)z^X<NX|L@%AK(7mn%@W?*z@F&*f=V%q{Go!d{$m%TlB_yg$slab7_o)&UV&_QVwl}Ns`+NOoopvY{J`F0bya_W<0 z`>+QA`CabWRN9Qje>o~}wSi?ZjnnwO17<=dPM!z!D;$5(y+SbhDB1x+7Ts&jnOfHi z+jk+cemoiyLN|}21u2~gp*8KXXOd$mX!MVv&mGGr*Xt2*)g?{BQ$c(@utvdwgIC$? zqObbK&alTTxk$gman`jmmbH^a5e)f>uk*Eqz)l-7u;12n2vd(Tgdf6h!}l6w;suX~(wi|{caA0E>`+%B+|OcnEY-$0 z+8Iu}*%Q23{;Ri1qMAm4T^K{6QC#|#=NSM7&4cE7qWC2Z(@5gIQyz=JOmnRjo5;5Q zp`v!$->3JqR7Dnh8}C?e z;KYt`?+r|HaUPv%^2UJ6MklRe$ArREl*E*`ev}nt=hG;lzA(ccP8)ZnaDYO>rVW1PeQbaPa2~dZ;-%xT7|c%1FQUpE$b#^i ztID=$@SxUaRSY6#volI25XXcNjW-c-I+6`jdpH?1IW^ya2CvZ=gOH*#z8*R2D~~ie zjt%mv+TRhCB(jq1(~pS0SR8bz3j813R^w+2lJdsl)O%fkCCvRlu4!UjY=JGtyLW+N z-XDPP;q+PX&;7H8&){Y{?@6B2_9o{4WNt?(x=sEBVY!WEzDOkRDg79WE)*uZn3&w| z&WU5;0{x+j`L!mkQ}Y@ALdy^X8;BeQ?&LR$3NWhOOZ`hJLcPxjq@vUPC_A!Zx{ev{he7^Oj|JGrMlr@XJIP40oI5<4N z3bst{*8w&|``=KgLGz3XAx4}W+4*gVI-7;dwzh^h;oy8q;#ceT69!qW1dnjPr z6##mps?+tqSZOx(NVMdo#ld(Nm{;eM`z=%c*fp-{3>1osShtzAqBSiq9`~($B??M? ztN>sCHU_)GOfQNCAtc@l3}Ou;+P|@6ec;9%KGGS?sl*Sn8+D&2qK3Q0ZG1y}SlR6Y zw9nx&Q!1VkxTj$hfc~(}U7SA&S;jv)`Cu%@G49%tfYCNfhSO)vdh$+;>BSgrrM88} zi~6+5afM(+OdxqHW5wUEKkE$L8X?JxM5Sh7-TK&U`w(;+_-Q%8UQ#(do&f-H!fs*| zrBE;LakJ>dDt?QvuNalP#ErR@ecWf%zb_2(u)T8KV_63rooUk~lP7-mevu9l? zs#=?Wl8btHCg$TPAD>&BV8w#M&LWO;Xp!{r78AZZ^sg#oxhII4_LI*7UrI9D7wgRzw!~;l0^i=|W;ud1kKpL!CJ2MLe$>ID?k&3Eq*! z?!oIWJF}4b!TR6!6?fIKLTptFY)F86V5dI$ZVTsGu6{RpY_Y$llc5E-($-ixI8`X? zSCk_W3SkBGGvkCGbPFaF`z7KHdPqSGrZW~*2$MI7eZ z6sBK&qh?}qd_ZFG3+QdYrT-m|S~$&9x0X>bMgJUEIYwzopu*7X0wr9iIOk<9Yvo9}eT)d!OhTic^d#3&Nci06D z()_FM_bs~$_xnd)155XpLyIg`de%zYTiVJ3LrNvd}9&WfLIte*Wxp zOPxf1HC~z?IBXU22TE_%{GFLX@6xR)eTt&ISQce>H9&1&(kArR3$G;Tb%rX!KRsDh|KIABY_OlyUpf^|^l4LxggrGMuQOqH>qg z$CR<8%R>53#1aMS93`Ip%xuN$v3=X#Q2!C~Zz-aW%xr~Ew}?*?#zGjzQnFtwwHAp@ zduv8LZv+J^Ql5|&wv*AQhYLrPB;CSPArk^z;GYi|MzaX@^hd}n4uPDvN{}HK*8|J= z4)jzZ8N#BFP^22)u|Ws7iYjy9N}zl)vnEV%I1t`$d!xe~bAO_$fPg+^2M`xLp z;ve9Q0U(dDH&C20OM(9+S=;E4)ZDkakuV1J2c7<$+8H_uZaQ!x+UQ0X-&hVsmb*DVD)LH_584nYYI^-e zK1}D4o`UVQQC#=l{@!|KQ&an|b`)&OwmjZkSf4$X#S9p|oxvL(g26y2pYGil(9d7O%4YQE$l4 zEi-k7a`2=+3qTfTh$%Ya3sam5#vTo~T)sh2b0%PsA|qM+fOJ=hqLH3N^2cY0u7TeEg-@>S(fEO)yZpY?e$P zpZq)NXOy!2rve?2+^Hp?q7aXyU;K)K@L4kkv1*vfoCS6dgjl@IXIGm4?_$SPNuaV-o5>OT zM-O$%6cndm-=XbKox8;+z)W}rIDDG*4z0VYg z&_%T4mU`^v_-CQN&KP~Nc>X41HjC~eZ%W#^31sT>O<&iu2LE|Z9U^{e-hkGxZpb;& z&}6p0st;Sny+STClefrb77k?St*HfU52-__>w2U{tv(iWo6@^E!K}gZ4lK5;co;&t zvD9zAz&K68PwXaVlZ28h#$eDH@4JbPHKXZefCQLD9foEI@mcT^OuwFo!?f|E6EIjI zKr~;8oeMIQ49NTk)|${qR?qdH0qpS0XvBn)4TeT61|(XeK|tWO?i;QJiRix{t;i zwD&5*jYMyekdNbs%trwrcsZm^_eGXcXmvq*54I+dU&{MWI^W zLY!*&d{^b}EyWUhU@4&+=EGby zLWcS?uof_%GBnK}caA{O)Zp}?3`V5gfssy{x8N~U{mj1_LZ8UXr+{)?y5~k4{A=@R zD1QcKUB%zn5#T4tT7VC))bJ8NsrUE%_{fD*k3LjYH(=XQbMTQ~d(7N_|4}vD$fnVt zV-bjNkqHZWMmqrhIi6%COK{K!@IYq0Bm@hQR;p-LYrU@_;1>uzbs`e62zzEkphWn& z_An%)$xZj zR8E8X{=R}9*gmUY?SZkMHfC^AcU|82&Kl)!xEBC)gI_dwSpVeoGTPP2_g$OrNYrU) zvDv?UlVrUoUHmY~Wv%TQY_1+k?5$d#86PA`L-MYxcDKB>D+I@!hU>i%H193LYlh3OZk^R4r~RU2 zZi4tjRXXWHcPvl@?2Pvu$7m03{_5;2t_4a4YaSZhcdsZUX*e&95fBBDX1H86@X@^G z7|6;rwjwSRy^Qx6N8I*TH?qh`rWunnxzucu$6+{dk$p2`yMvv*Vy_gRMSPCmJ;9aH_Pp1(kthMb-BQ3lp|KTq`K#Huo( zGPaiv5QJf=c`mo316Olw$aG_RKmy&y@{`1R`x=S|kXg0^F2p?QLjpbn{*T50IKAs# zkL-q6+y%((FWoi3#wM!*xtsH zWMri9MgMON&;5CoS}IL&b{+7nghrv5)r5Ainju#cdCxBB=Lwg&@&pdWMn&=9%I%KP z{dvUx-|H3l=8RPTuou4o#p=_k1HUFM` zvua}3#fXD+Nx*>l^A!Olp!ddioq5ZHpq@Am-kC~-3#W(A-R(i==W|r!D@C}ekz;vT z2gL%m7kR*#K+=6$FK`X<@ts0?i&I)qwy~x%`>1{wzt*rmIW;skNb>%Ob$iofG3DL6 zlW~UT(|#rS^t4A^Xz$zG3LcqT7$^^?P23vrCbdO(Y6oi{o^$G0V7V{5b*mu&w% zk^_RFBvkPRqh+L4M3y-2i_`y|V^Qy_h{d%lC~b7|y`UkT>z}=GI3HW1^*1fK$L{cZ z@>cJgXup|Z{gWeDK1hqf>Ajdq#&T&|D|EEc7$x7@w0b@s`@?C$HVpt*Jg|j|lD)KBD|G567j9kr%?rO&ZLB!7J;D!(k4S=EpXYElH`rzTtN>SU8>p%lh5HuI^ zQ!=UfcNtRIY;M!Hb@6B5U8)Lp4ME$J*3q;ocWVW*HkjsGzab5V z;-_<9E%59dDS3Bm!t7((M(8WMP^u^wLBP$w480Ur<2t-!k}EX^nh1>@Eb}$%oAa2c z)zcbm?@Qa(9c+AwX30UL5PzEr+jpBDWcrW<7X%Fd$P1eAQK`SR?eOix4^YDS9OyeT zo3wz0a;Oq)ro^t14!K@R)RmH3C?Eo15}qV_g^Tx-a5^_@Ti=DN?H6R)P+z?W^QdWg zMh=9~ajx1}+JIY;b4MA3_4_8d5xwG?49sr7T%hQm3Ha_A?#g%&9d<~;OdJGfs4hED zXbDlS=RWn?bMM$$71ybsAZU!Cm-5$-!lWmxy8S%8&(*9$zR+K6mK|rva(&0F`^zCq zf=^`7tbQ)RPXXaEgtF0*kEGWqlf(_`Ov||UXJS>%nkzJ20&2P5d*v~LZLbW-rI`V_ zp4u3Fh7Kv!OGRjgw0~7tlP>Ms+?2vKlHmvvZ>yBaL`#*1Y zMTU#5Z{jJ%Xo)Ur4X#|x`Rx*Woxn24z`JyJ7~Nk`0FDAFDnGX7x~+1dCq4vuH@0_M zKN0o)SI8(B@(jc)hbB*gi)|P9e9y5uiNhf(lhSVy?+6K<%GVh*K0kj5$@BnS=qZqv zUTe1%h3Tp$C(-tfRErj`;D<$1+*~<86vLL#=_eeKG^q_e^d#KlkKH_qRyd2LEGp<0 ze-4{*To?)po?(QzX@r@-tN&S{^bbJX$hAhkU4@PuJ?@7}0te7P0%t2p=Qstwb-U2qxr zo8UO!wK4_(iHi;xH_kDc{pyhESN$GR8#-E??SJJvCt$xXA<+63g z7+X&L5zLh)7PuyUOX)^2zt8sMP!K@{WB3mnt$Q-*o1xWzEI!gLFWrE*GB58d1H!U*0q55&0p@(|d{mZ`7>X z)|nt#xsS$YX0D3i2JlXCU8BgqcC(bOMl20GssmBpSIMRY6B$NmZINH%5fK^&Ie|4{ zs3Va3BsX)_qo9sf&zl*Aq8)D`FKk4q2Zw7Jq3d3cVFi_qbVar-@-uvKjD?(ZeC1GK z?gTRDyRe{aZ-P|8Uf-gI*1Laj#_&%k)%Jhtjc+|E%yyK@j_xqHpNVYsR*Ql*?T){# zKvT8V*Aj!B^l)mGVwy#{W$m0I;o@B6sz)uaI% z^%%dq%3kR6an*M5B?j>fPzv1uGK>`weXHvC23%w7qxz4rVCkYg0!Jo#CMX$W{0A=_ z)812{q`E#S32H_40B^%wLfNDP)z|+%9uLw~vaBtWpJ3>#%Sw5Bx z=Hk%GyP&bof;jTng*(@49zBz}mxsRHffZB`YKWQ3;4WS?1}4$_ja!@&0HGbLQJ9^x z67=&~w8O;&^?a)cJhcq5a{Djn`ZT^Z!r#4xORGot2zQj#eV-Lffe)G>7C}4G9!Zq^ zt)X4#$&oC50sI_?z&R~JZm2P`d*P#`Y?|b>n@c%uu!+0=8s<&uHX3$60MWYr+Xy;Q zya~4~3ied__%X<9z7(DVZ}BjJ<|S!4wp4>+{<_=7cZD|DiVJ5u0eK!eV zaz+m;po}K)M@B)SNyxtYDGKahb(Ad%e-Jm0X$u;LW%D7gBtoB2YT6n>Ca3xm@iA|} zGq@9+pg+JEO2CB`V|R}+3NULX-N6VuX~?vH`J*Qiv5k(HAa*=KV+;K+n@#_mCD{W! z0ennO3G;k+9hB6h0uO6rv3Ql{l9#0tzPqR6$;sGW(n|DBm&VSxS&pQ^?6&^!0>;Jz z03h^>&1S4CDYz8$K)wZrW45@hboqD}xH}obL!YO~lOS@oQpIV(q?auwCR{FD10_cF zi3#2=dVO4NYd|!G=?8;33bmY8xDZ{?kr3D!ilr5o8Yn2~Q>6mt#IH#~9Y`aALy+|Q zNX)4&E90m7CY_~DtyyohgU$~3_sJZ!gKBdf)M zp{(ua;C}prI3$YZ7i>gb|PEJk)W5#k z)HMbTfXB&Af|gzMyg*xZbYf4AEZ){UQyzgI8dt}aEYz8FsMxee;uWEqX|~D`-#m}- z9`ijP47lXyu)RpdB(-<{gjAb}5oTpHW83DQalD7aCHn!vU^kXkA2v|Zocm#5X}_nj z{;~T;_ng-Ead{#r!l50;0=?nP*pdpMS;)}`4@6Pu$u+$Kc-N2DfeeTR0Qhc|0MlYC z1yJ%iufdzGsQ5-43J_IM*~4FCtVxo3y!f{;GbG)hfX-~3I}Gl|7_?v$pvkt3UIjv);>z^!X3;3wT#uEwAf zViH%eR$PZ5834wV+(49QAw($qoVBNtS2S|m>Rw@RxYefBsao!0Yk4SIozs&mykH5> z`dZl~od0v(oG8zC(<=2eho5t4@uM!iK?8~_Og(s<$=NaXp6r6>nd=Y%((YoQ==zQ9 z0sF4)LetAHFhLORLid4WEn}U@TL4$8LN%=S>5sQ4od6^e*LOEmXuz33kixk81p zaJSZSmGc>SLjmkBo`d|GUQS&st)HSk_zddRh;7tt z85WY9n4|8&Ny0p8_nt%Ajalo$7jDeA!6<*%IUU^LHWkB2|9;eCjoDevx?$Z8y$LEa z^5xW!w1Mrlp9xz3wiM+L7>ZID{tajv16(}OUIjCt$;DfPd2d4NSe6(L{|M0O!X0g4 z--_+Peul8}fCbe%0I{$sK|QBal~8#Iyy4|h?Z??;DyE%p>9k1R?shv2%zn)pM%zk9 zCk=*T^|JvAFU#|;Oz$B05(g(IczI)kT|$oLplX8nIk=KFsV~+-dRwmD6;a5ajb^Xp zmoSrF3;SF|O37Mlu1O?s^Aq3EJ(EB4w^&L^ahh!v+u?SJ;A%f%qwf(dHnUnI>PFY3 zAp;+%Fv=iKqu6vz*3Omf5SsDfS12yJam;7SraW4)Sjg^X_s^kja%(-gWSyD>>symP zSD6ieL6z`YDhHEx93v>wXEfRMsBiMZnve!Z2rn&?MA7fSNIK!r6^VW(^}Kxxg46rf zJ|08F?D(=RlDf=#~1>jfRVhZ=qLqzI66BZ6~Ta&-MzHg^*UYscU z!sRZqiJ#>JEI~<8Z|yUx6dGT2?{wVL{7CYs!*U%$4Nu=ciJ1xge5=)PS__8bgvF?& zO;mDz>;(yh&(@FBnZW1sB+3K-h4MhYh&j8ZoG3$v>)+>`W$FOP6uV94;4YJ3ouv$@ z^OFrgqO2r%PzL-`|e2%c1HbW=`xqHJkZ(8{~BJ`c#hm)Qkt5Djyu>$+M{Q1Koy)d%m zzz?r&PmfNdDfwN?GAMy$iPhs+F9JERzT)54Qm8^H@-n(Y-K|B|zvAM)@`|IWq&0E{21Wn*jdk%l{S=2inXy1pAHKbc>I4RsxB$E^z}?qk`@5-<$(Y+FbDwH7y8e_1B3b> zulj}Y|BH3MF!g_9z`rmH7&rj+%bR{Jix9~FiFfwZU`#HkIui8w)e@e|G;5XMfUH literal 0 HcmV?d00001 From 9a5ed7ba3b42b951be72bef02bec8770ce2e91cd Mon Sep 17 00:00:00 2001 From: AlexGRNetwrix Date: Tue, 14 Jul 2026 02:33:18 -0700 Subject: [PATCH 2/8] docs(auditor/10.9): add gMSA support page for Password Expiration Notifier (#1219) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add a dedicated page documenting gMSA support for PEN in Auditor 10.9: - Required AD permission (GenericRead — a note explains that Authenticated Users typically already grants it) - How to specify the gMSA in the monitoring plan (trailing $, locked Password field, scheduled task under NT AUTHORITY\SYSTEM) - UI limitations for Select OUs / Select Groups / Generate (LDAP from the interactive session) - Troubleshooting table Link the new page from passwordexpirationnotifier/overview.md — the "Review the following" list and the User name/Password row of the monitoring plan configuration table. Refs #440770 Generated with AI Co-authored-by: Claude Code --- .../tools/passwordexpirationnotifier/gmsa.md | 59 +++++++++++++++++++ .../passwordexpirationnotifier/overview.md | 3 +- 2 files changed, 61 insertions(+), 1 deletion(-) create mode 100644 docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md diff --git a/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md b/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md new file mode 100644 index 0000000000..4a5edd7885 --- /dev/null +++ b/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md @@ -0,0 +1,59 @@ +--- +title: "Use a Group Managed Service Account (gMSA)" +description: "Use a group Managed Service Account (gMSA) as the data collecting account for Password Expiration Notifier." +sidebar_position: 5 +--- + +# Use a Group Managed Service Account (gMSA) + +Password Expiration Notifier supports a group Managed Service Account (gMSA) as the data collecting account. With a gMSA, Active Directory generates and rotates the password automatically, so you do not maintain a password for the account or rotate it on a schedule. + +See the [Use Group Managed Service Account (gMSA)](/docs/auditor/10.9/requirements/gmsa.md) topic for the general prerequisites that apply to every Auditor data source: create the KDS root key, create the gMSA with the `New-ADServiceAccount` cmdlet, install it on the Auditor Server with `Install-ADServiceAccount`, and add it to the local **Administrators** group on the Auditor Server. + +After you complete those prerequisites, specify the gMSA in the Password Expiration Notifier monitoring plan. + +## Active Directory Permissions + +Password Expiration Notifier reads Active Directory user attributes to determine password and account expiration dates. The gMSA needs the following Active Directory permission: + +| Permission | Applies to | Purpose | +| ---------- | ---------- | ------- | +| `GenericRead` | User objects in the target OUs | Read `pwdLastSet`, `msDS-UserPasswordExpiryTimeComputed`, `accountExpires`, `userAccountControl`, `mail`, `manager`, `sAMAccountName`, and related attributes | + +:::note +In a default Active Directory configuration, the built-in **Authenticated Users** group has read access to user objects, and a gMSA inherits that access. No additional delegation is usually required. If read access was restricted in your domain (for example, by removing **Authenticated Users** from an OU's ACL), grant the gMSA membership in a group that has read access to the target OUs, or delegate read permissions to the gMSA directly through Active Directory Users and Computers. +::: + +## Specify the gMSA in the Monitoring Plan + +Follow the steps to use the gMSA in a Password Expiration Notifier monitoring plan. + +**Step 1 –** On the Auditor Server, launch Password Expiration Notifier and open an existing monitoring plan for editing, or create a new one. See the [Configure Password Expiration Alerting](/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md#configure-password-expiration-alerting) section for the full monitoring plan procedure. + +**Step 2 –** On the **General** tab, in the **User name** field, enter the gMSA account name in one of the supported formats: + +- `\$` — NetBIOS domain name and `sAMAccountName`, for example `CONTOSO\penGmsa$`. This format is recommended. +- `$@` — UPN format, for example `penGmsa$@contoso.local`. + +The trailing `$` is required. Password Expiration Notifier uses the `$` to recognize the account as a gMSA and switch to the appropriate authentication path. + +**Step 3 –** Leave the **Password** field as it is. When you enter a gMSA name, the field is locked automatically and displays `(Managed by Active Directory)`. Active Directory manages the password, so there is nothing to enter. + +**Step 4 –** Complete the remaining tabs of the monitoring plan and click **Save**. + +When you save the monitoring plan, Password Expiration Notifier creates a Windows scheduled task that runs the data collection under the `NT AUTHORITY\SYSTEM` account. The scheduled task performs the actual data collection and sends the notifications. + +## Limitations + +:::warning +The **Select OUs**, **Select Groups**, and **Generate** buttons in the Password Expiration Notifier UI do not work when a gMSA is configured. These buttons issue an LDAP request at the time you click them from the interactive session of the user who launched Password Expiration Notifier, and gMSA impersonation is not supported in interactive sessions. Use the scheduled task and the email reports to view password expiration data when the monitoring plan uses a gMSA. +::: + +## Troubleshooting + +The table below lists common issues you may encounter when configuring a gMSA for Password Expiration Notifier. + +| Symptom | Likely cause | Resolution | +| ------- | ------------ | ---------- | +| `Cannot find an account...` error when specifying the account | The gMSA name was entered without the trailing `$` or with the wrong domain. | Use the `\$` format, for example `CONTOSO\penGmsa$`. | +| The **Select OUs**, **Select Groups**, or **Generate** buttons do not work; the log shows `failed to create impersonation token` | Known gMSA limitation in interactive sessions. | See the Limitations section. Use the scheduled task and email reports instead. | diff --git a/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md b/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md index 267ab3abcb..9ccc45e550 100644 --- a/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md +++ b/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md @@ -25,6 +25,7 @@ Review the following for additional information: - Registry Key Configuration - [Password Expiration Notifier Ports](/docs/auditor/10.9/tools/passwordexpirationnotifier/ports.md) - [Password Expiration Monitoring Scope](/docs/auditor/10.9/tools/passwordexpirationnotifier/monitoringscope.md) +- [Use a Group Managed Service Account (gMSA)](/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md) ## Configure Password Expiration Alerting @@ -47,7 +48,7 @@ new monitoring plan. | Option | Description | | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| Specify account which will be used to collect data: - User name - Password | Enter the account which will be used for data collection. For a full list of the rights and permissions of this account, and instructions on how to configure them, refer to [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md). | +| Specify account which will be used to collect data: - User name - Password | Enter the account which will be used for data collection. For a full list of the rights and permissions of this account, and instructions on how to configure them, refer to [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md). To use a group Managed Service Account (gMSA) instead of a user account, see the [Use a Group Managed Service Account (gMSA)](/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md) topic. | | Filter users by organizational unit | To audit users for expiring accounts/passwords that belong to certain organizational units within your Active Directory domain, select this option and click Select OUs. In the dialog that opens, specify the OUs that you want to audit. Only users belonging to these OUs will be notified and included in the administrators and managers reports. | | Filter users by group | To audit users for expiring accounts/passwords that belong to certain groups within your Active Directory domain, select this option and click Select Groups. In the dialog that opens, specify the groups that you want to audit. Only users belonging to these groups will be notified and included in the administrators and managers reports. | | Filter by account name | Specify one or several user account names (e.g., \*John\*). Use semicolon to separate several names. Only user accounts that contain selected name will be notified and included in the administrators and managers reports. | From c14bce8d6d3b12794a71ae82e951f656fb62f3dc Mon Sep 17 00:00:00 2001 From: Kunle Lawani Date: Wed, 5 Aug 2026 16:04:43 +0100 Subject: [PATCH 3/8] docs(auditor/10.9): document Active Directory integration for Azure Files State-in-Time Add a "Configuring Active Directory integration (optional)" section covering the on-premises AD credentials feature added for group expansion and SID resolution in permission reports, and replace the static limitation note with a link to the new section. AB#444015 Generated with AI Co-Authored-By: Claude Code --- .../configuration/azurefiles/stateintime.md | 29 +++++++++++++++---- 1 file changed, 23 insertions(+), 6 deletions(-) diff --git a/docs/auditor/10.9/configuration/azurefiles/stateintime.md b/docs/auditor/10.9/configuration/azurefiles/stateintime.md index 4caf72fca2..1a7e0a1dcb 100644 --- a/docs/auditor/10.9/configuration/azurefiles/stateintime.md +++ b/docs/auditor/10.9/configuration/azurefiles/stateintime.md @@ -2,12 +2,7 @@ This topic describes how to enable State-in-Time data collection for an Azure Files monitoring plan in Netwrix Auditor, configure the monitoring scope using omit lists, and set up optional Azure diagnostic settings for activity-based reports. -> **Note:** When Azure file shares use on-premises Active Directory (AD DS) authentication, the following limitations apply to State-in-Time permission reports: -> -> - **Group expansion is unavailable for on-premises AD groups that are not synced to Microsoft Entra ID.** If access to a file or folder is granted through such a group, the report does not list individual group members. -> - **SID resolution is unavailable for on-premises AD groups and accounts that are not synced to Microsoft Entra ID.** These objects appear as unresolved SIDs instead of display names in permission reports. -> -> These limitations do not affect environments that use Microsoft Entra ID-only identities or fully synced hybrid identities. +> **Note:** By default, Azure Files permission reports show display names only for Entra ID accounts, and Netwrix Auditor doesn't expand on-premises AD groups that aren't synced to Microsoft Entra ID. To show display names for on-premises accounts and list individual members of AD groups, see [Configuring Active Directory integration (optional)](#configuring-active-directory-integration-optional). ## Prerequisites @@ -31,6 +26,28 @@ After you save the monitoring plan, Netwrix Auditor will begin collecting State- > **Note:** Netwrix Auditor collects the first snapshot at the next scheduled run. Reports won't contain data until then. +## Configuring Active Directory integration (optional) + +By default, only Entra ID accounts appear with display names in Azure Files reports. If your environment uses on-premises Active Directory (AD DS), you can provide read-only AD credentials so that Netwrix Auditor can: + +- Resolve display names for on-premises accounts not synced to Microsoft Entra ID. +- List individual members of on-premises AD groups (including members of nested groups, resolved transitively) as separate rows in permission reports. + +If you don't provide credentials, report output remains identical to earlier versions — this is a fully optional, additive capability. + +**To configure Active Directory integration:** + +1. In Netwrix Auditor, navigate to **Configuration → Monitoring Plans**. +2. Select the Azure Files monitoring plan and click **Edit**. +3. Open a monitored item (Azure Subscription or Azure Storage Account) and click **Edit**. +4. Go to the **Active Directory Integration** tab. (The **Learn more…** link on this tab points to this section.) +5. Turn on the toggle under **Specify Active Directory account**. +6. In the **User name** field, enter an AD account with read access to Active Directory. Use the format `domain\user` or `user@domain.local`. +7. Enter the **Password** for the account. +8. Click **Save**. + +> **Note:** If Netwrix Auditor cannot authenticate with the configured AD account, it records a collection error in the System Health log and continues snapshot collection using cloud-resolved identities only. Netwrix Auditor records transient AD connectivity issues as warnings and doesn't stop collection for these issues. + ## Configuring the monitoring scope (omit lists) Use omit lists to exclude specific folders or files from State-in-Time data collection, reducing collection time and storage requirements. From 4ec82c1d3a7f3a0229b02ad607d962fcb5213290 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Wed, 5 Aug 2026 15:47:09 +0000 Subject: [PATCH 4/8] fix(vale): auto-fix style issues (Vale + Dale) --- .../10.9/admin/monitoringplans/datasources.md | 66 ++++++++++--------- .../useractivity/monitoredcomputers.md | 10 +-- .../monitoringplans/useractivity/overview.md | 42 ++++++------ .../10.9/admin/settings/longtermarchive.md | 22 +++---- .../configuration/azurefiles/stateintime.md | 6 +- .../tools/passwordexpirationnotifier/gmsa.md | 22 +++---- .../passwordexpirationnotifier/overview.md | 50 +++++++------- 7 files changed, 112 insertions(+), 106 deletions(-) diff --git a/docs/auditor/10.9/admin/monitoringplans/datasources.md b/docs/auditor/10.9/admin/monitoringplans/datasources.md index c7843447a2..d63ffb0439 100644 --- a/docs/auditor/10.9/admin/monitoringplans/datasources.md +++ b/docs/auditor/10.9/admin/monitoringplans/datasources.md @@ -7,20 +7,20 @@ sidebar_position: 20 # Manage Data Sources You can fine-tune data collection for each data source. Settings that you configure for the data -source will be applied to all items belonging to that data source. Using data source settings, you +source apply to all items belonging to that data source. Using data source settings, you can, for example: -- Enable state-in-time data collection (currently supported for several data sources) +- Enable state-in-time data collection (supported for several data sources) - Depending on the data source, customize the monitoring scope (e.g., enable read access auditing, monitoring of failed attempts) -To add, modify and remove data sources, enable or disable monitoring, you must be assigned the -Global administrator role in the product or the Configurator role on the plan. See the +To add, modify, and remove data sources, or to enable or disable monitoring, you must have +the Global administrator role in the product or the Configurator role on the plan. See the [Role-Based Access and Delegation](/docs/auditor/10.9/admin/monitoringplans/delegation.md) topic for additional information. ## Modify Data Source Settings -Follow the steps to modify data source settings. +To modify data source settings: **Step 1 –** Select the monitoring plan you need and click **Edit**. @@ -58,7 +58,7 @@ needed. ## Add a Data Source to an Existing Plan -Follow the steps to add a data source to existing plan. +To add a data source to an existing plan: **Step 1 –** Select the monitoring plan you need and click Edit. @@ -72,7 +72,7 @@ Follow the steps to add a data source to existing plan. ## Add Items for Monitoring -Once you completed monitoring plan wizard and specified data sources, add items for monitoring. You +After you complete the monitoring plan wizard and specify data sources, add items for monitoring. You can add as many items for a data source as you want. In this case, all items will share settings you specified for this data source. @@ -84,7 +84,7 @@ associated with your data source. | Active Directory Group Policy Exchange Logon Activity | [Domain](activedirectory/overview.md#domain) | | Active Directory Federation Services | [Federation Server](adfs.md#federation-server) | | Microsoft Entra ID Exchange Online SharePoint Online Microsoft Teams | [Microsoft Entra ID](/docs/auditor/10.9/admin/monitoringplans/microsoftentraid/overview.md) | -| File Servers (including Windows file server, Dell, NetApp, Nutanix File server, Synology, and Qumulo) | [AD Container](activedirectory/overview.md#ad-container) [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) [Qumulo](fileservers/overview.md#qumulo) [Synology](fileservers/overview.md#synology) By default, Auditor will monitor all shares stored in the specified location, except for hidden shares (both default and user-defined). If you want to monitor user-defined hidden shares, select the related option in the monitored item settings. Remember that administrative hidden shares like default system root or Windows directory (ADMIN$), default drive shares (D$, E$), etc. will not be monitored. See the topics on the monitored items for details. | +| File Servers (including Windows file server, Dell, NetApp, Nutanix File server, Synology, and Qumulo) | [AD Container](activedirectory/overview.md#ad-container) [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) [Qumulo](fileservers/overview.md#qumulo) [Synology](fileservers/overview.md#synology) By default, Auditor will monitor all shares stored in the specified location, except for hidden shares (both default and user-defined). If you want to monitor user-defined hidden shares, select the related option in the monitored item settings. Remember that Auditor doesn't monitor administrative hidden shares like default system root or Windows directory (ADMIN$), default drive shares (D$, E$), and so on. See the topics on the monitored items for details. | | Network Devices | [Syslog Device](networkdevices.md#syslog-device) [Cisco Meraki Dashboard](networkdevices.md#cisco-meraki-dashboard) | | Oracle Database | [Oracle Database Instance](oracle/overview.md#oracle-database-instance) | | SharePoint | [SharePoint Farm](sharepoint/overview.md#sharepoint-farm) | @@ -93,11 +93,11 @@ associated with your data source. | Windows Server User Activity | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [AD Container](activedirectory/overview.md#ad-container) [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) | | Netwrix API | [Integration API](/docs/auditor/10.9/api/overview.md) | -To add, modify and remove items, you must be assigned the Global administrator role in the product +To add, modify, and remove items, you must have the Global administrator role in the product or the **Configurator** role on the plan. See the [Role-Based Access and Delegation](/docs/auditor/10.9/admin/monitoringplans/delegation.md)topic for additional information. -Follow the steps to add a new item to a data source: +To add a new item to a data source: **Step 6 –** Navigate to your plan settings. @@ -113,37 +113,43 @@ monitoring plan and click Edit item. For each item, you can: ## Configure Monitoring Scope -In some environments, it may not be necessary to monitor the entire IT infrastructure. Netwrix -monitoring scope can be configured on the Data Source and/or Item levels. the section below contains +In some environments, you may not need to monitor the entire IT infrastructure. You can configure the +Netwrix monitoring scope on the Data Source and/or Item levels. The following section contains examples on how to use omit functionality in Auditor. In addition to the restrictions for a monitoring plan, you can use the \*.txt files to collect more -granular audit data. Note that the new monitoring scope restrictions apply together with previous -exclusion settings configured in the \*.txt files. See the [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md)topic for +granular audit data. + +:::note +The new monitoring scope restrictions apply together with previous exclusion settings configured in +the \*.txt files. +::: + +See the [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md) topic for additional information. | Use case | Related documentation | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Active Directory** | | -| I want to omit all activity by a specific service account or service accounts with specific naming pattern. | [Active Directory](/docs/auditor/10.9/admin/monitoringplans/activedirectory/overview.md) | -| If Netwrix user is responsible just for a limited scope within corporate AD, s/he needs to omit everything else. | [Active Directory](/docs/auditor/10.9/admin/monitoringplans/activedirectory/overview.md) - Always both activity and state in time data are omitted. - In group/Not in group filters don't not process groups from omitted OUs. | +| Omit all activity by a specific service account or by service accounts with a specific naming pattern. | [Active Directory](/docs/auditor/10.9/admin/monitoringplans/activedirectory/overview.md) | +| If Netwrix user is responsible just for a limited scope within corporate AD, s/he needs to omit everything else. | [Active Directory](/docs/auditor/10.9/admin/monitoringplans/activedirectory/overview.md) - Auditor always omits both activity and state-in-time data. - In group/Not in group filters don't not process groups from omitted OUs. | | **Logon Activity** | | -| I want to omit domain logons by a specific service account or service accounts with specific naming pattern. | [Logon Activity](/docs/auditor/10.9/admin/monitoringplans/logonactivity/overview.md) | +| Omit domain logons by a specific service account or by service accounts with a specific naming pattern. | [Logon Activity](/docs/auditor/10.9/admin/monitoringplans/logonactivity/overview.md) | | **File Servers** (including Windows file server, Dell, NetApp, Nutanix File server) | | -| I have a server named _StationWin16_ where I can't install .Net 4.5 in OU where I keep all member servers. I want to suppress errors from this server by excluding it from the Netwrix auditing scope. | [AD Container](activedirectory/overview.md#ad-container) | -| A Security Officer wants to monitor a file share but s/he does not have access to a certain folder on this share. Then, s/he does not want the product to monitor this folder at all. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | -| A Security Officer wants to monitor a file share but s/he does not have access to a certain folder on this share. Then, s/he does not want the product to monitor this folder at all. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | -| A Security Officer wants to monitor a file share, but it contains a folder with a huge amount of objects, so s/he does not want Netwrix Auditor to collect State-in-Time data for this folder. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | -| I want to exclude specific computers within an IP range from the Netwrix auditing scope. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) | +| A server named _StationWin16_ can't run .Net 4.5 and belongs to the OU that holds all member servers. Suppress errors from this server by excluding it from the Netwrix auditing scope. | [AD Container](activedirectory/overview.md#ad-container) | +| A Security Officer wants to monitor a file share but s/he doesn't have access to a certain folder on this share. Then, s/he doesn't want the product to monitor this folder at all. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | +| A Security Officer wants to monitor a file share but s/he doesn't have access to a certain folder on this share. Then, s/he doesn't want the product to monitor this folder at all. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | +| A Security Officer wants to monitor a file share, but it contains a folder with a huge amount of objects, so s/he doesn't want Netwrix Auditor to collect State-in-Time data for this folder. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) [Dell Isilon](fileservers/overview.md#dell-isilon) [Dell VNX VNXe](fileservers/overview.md#dell-vnx-vnxe) [NetApp](fileservers/overview.md#netapp) [Windows File Share](fileservers/scope.md#windows-file-share) [Nutanix SMB Shares](fileservers/overview.md#nutanix-smb-shares) | +| Exclude specific computers within an IP range from the Netwrix auditing scope. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) | | **SQL Server** | | -| I want to know if _corp\administrator_ user is messing with SQL data. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | -| As a Auditor administrator I want to exclude the _domain\nwxserviceaccount_ service account activity from SQL server audit so that I get reports without changes made by automatic systems. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | -| As a Auditor administrator I want to exclude all changes performed by _MyCustomTool_. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | +| Track whether the _corp\administrator_ user is changing SQL data. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | +| As an Auditor administrator, exclude the _domain\nwxserviceaccount_ service account activity from the SQL Server audit so that reports omit changes made by automatic systems. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | +| As an Auditor administrator, exclude all changes performed by _MyCustomTool_. | [SQL Server Instance](sqlserver/items.md#sql-server-instance) | | **SharePoint** | | -| I want to exclude the _domain\nwxserviceaccount_ account from data collection as it produces standard activity that doesn't require monitoring. | [SharePoint Farm](sharepoint/overview.md#sharepoint-farm) | -| As a Auditor Administrator I want to exclude shared _PublicList_ from read audit. | [SharePoint Farm](sharepoint/overview.md#sharepoint-farm) | +| Exclude the _domain\nwxserviceaccount_ account from data collection because it produces standard activity that doesn't require monitoring. | [SharePoint Farm](sharepoint/overview.md#sharepoint-farm) | +| As an Auditor administrator, exclude the shared _PublicList_ from the read audit. | [SharePoint Farm](sharepoint/overview.md#sharepoint-farm) | | Windows Server | | -| I have a server named StationWin16 where I can't install .Net 4.5 in OU where I keep all member servers. I want to suppress errors from this server by excluding it from the Netwrix auditing scope. | [AD Container](activedirectory/overview.md#ad-container) | -| I want to exclude specific computers within an IP range from the Netwrix auditing scope. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) | +| A server named StationWin16 can't run .Net 4.5 and belongs to the OU that holds all member servers. Suppress errors from this server by excluding it from the Netwrix auditing scope. | [AD Container](activedirectory/overview.md#ad-container) | +| Exclude specific computers within an IP range from the Netwrix auditing scope. | [File Servers](/docs/auditor/10.9/admin/monitoringplans/fileservers/overview.md) | | VMware | | -| I have a virtual machine named "testvm" I use for testing purposes, so I want to exclude it from being monitored. | [VMware ESX/ESXi/vCenter](vmware/overview.md#vmware-esxesxivcenter) | +| A virtual machine named "testvm" serves testing purposes only, so exclude it from monitoring. | [VMware ESX/ESXi/vCenter](vmware/overview.md#vmware-esxesxivcenter) | diff --git a/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md b/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md index dfc74d7c7c..e44e3f8bb4 100644 --- a/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md +++ b/docs/auditor/10.9/admin/monitoringplans/useractivity/monitoredcomputers.md @@ -6,7 +6,7 @@ sidebar_position: 20 # Monitored Computers -The **Monitored Computers** tab in a User Activity monitoring plan gives you a detailed, per-host view of every computer being monitored. Instead of a single summary status for the entire plan, you can see the health of each individual computer, identify issues quickly, and drill into diagnostic details without leaving the interface. +The **Monitored Computers** tab in a User Activity monitoring plan gives you a detailed, per-host view of every monitored computer. Instead of showing a single summary status for the entire plan, the tab reports the health of each computer, so you can identify issues quickly and drill into diagnostic details without leaving the interface. **To access the Monitored Computers tab:** @@ -20,7 +20,7 @@ The **Monitored Computers** tab in a User Activity monitoring plan gives you a d When you add computers to a monitoring plan using an IP range or an AD container, Netwrix Auditor resolves and tracks each host individually. The Monitored Computers tab lists all resolved computers with their current health status, so you can immediately see which hosts are collecting data normally and which ones require your attention. -**NOTE:** Computers excluded from monitoring via the **Exclude these objects** or **Exclude subranges** setting in the item settings are not displayed in the Monitored Computers tab. +**NOTE:** The Monitored Computers tab doesn't display computers that you exclude from monitoring with the **Exclude these objects** or **Exclude subranges** setting in the item settings. ![Monitored Computers tab with details for a selected computer](/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-details1.webp) @@ -47,13 +47,13 @@ The grid displays the following columns for each computer: ![Apply Filters dialog showing Computer status, Computer name, and Item name options](/images/auditor/10.9/admin/monitoringplans/useractivity/monitored-computers-filter.webp) -Search and filters can be combined. The label next to **Filters** shows a summary of the active filters. To remove all active filters at once, click **Clear All** in the Filters dialog. +You can combine search and filters. The label next to **Filters** shows a summary of the active filters. To remove all active filters at once, click **Clear All** in the Filters dialog. ## Exporting the List -Click **Export** above the grid to save the currently displayed computers to a file. The export respects any active search term and filters, and includes the following columns: **Name**, **Item**, **Status**, and **Last Activity Time**. +Click **Export** above the grid to save the displayed computers to a file. The export respects any active search term and filters, and includes the following columns: **Name**, **Item**, **Status**, and **Last Activity Time**. ## Related Topics - [Monitoring Plans — User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) -- [Add Items for Monitoring](/docs/auditor/10.9/admin/monitoringplans/datasources.md#add-items-for-monitoring) \ No newline at end of file +- [Add Items for Monitoring](/docs/auditor/10.9/admin/monitoringplans/datasources.md#add-items-for-monitoring) diff --git a/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md b/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md index ad47f91cad..1859949582 100644 --- a/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md +++ b/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md @@ -6,8 +6,8 @@ sidebar_position: 180 # User Activity -**NOTE:** Prior to configuring your monitoring plan, please read and complete the instructions in -the following topics: +**NOTE:** Before you configure your monitoring plan, read the following topics and complete the +instructions in them: - [Protocols and Ports Required](/docs/auditor/10.9/requirements/ports.md) – To ensure successful data collection and activity monitoring configure necessary protocols and ports for inbound and @@ -24,18 +24,18 @@ Complete the following fields: | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | General | | | Monitor this data source and collect activity data | Enable monitoring of the selected data source and configure Auditor to collect and store audit data. | -| Notify users about activity monitoring | You can enable the message that will be displayed when a user logs in and specify the message text. | -| Record video of user activity within sessions | - If disabled, only user session events will be collected (regardless of whether the user is idle or not). - If enabled, the product will both collect user session events and record video of user activity. By default, this option is disabled. | +| Notify users about activity monitoring | You can enable the message that appears when a user logs in and specify the message text. | +| Record video of user activity within sessions | - If disabled, the product collects only user session events (regardless of whether the user is idle). - If enabled, the product both collects user session events and records video of user activity. By default, this option is disabled. | | Video Recording For these settings to become effective, enable video recording on the General tab. | | | Adjust video quality | Optimize video file by adjusting the following: - File size and video quality - Save video in grayscale - CPU load and Video smoothness. | -| Adjust video duration | Limit video file length by adjusting the following: - Recording lasts for `<...>` minutes—Video recording will be stopped after the selected time period. - User has been idle for `<...>` minutes—Video recording will be stopped if a user is considered inactive during the selected time period. If the Record video of user activity within sessions option is enabled, the User Sessions report shows active time calculated without including user idle period. Mind that a computer is considered to be idle by Windows if there has not been user interaction via the mouse or keyboard for a given time and if the hard drives and processors have been idle more than 90% of that time. - Free disk space is less than `<...>` MB—Video recording will be stopped when upon reaching selected disk space limit. - Consider user activity — Select one of the following: - Stop if user has been idle for `<...>` minutes. Select if you want video recording for a user to be stopped after the specified time period. - Continue video recording regardless of the user idle state. When selected, Netwrix Auditor continues video recording for idle users. | +| Adjust video duration | Limit video file length by adjusting the following: - Recording lasts for `<...>` minutes—Netwrix Auditor stops video recording after the selected time period. - User has been idle for `<...>` minutes—Netwrix Auditor stops video recording if a user is inactive during the selected time period. If the Record video of user activity within sessions option is enabled, the User Sessions report shows active time that excludes the user idle period. Windows treats a computer as idle if the user hasn't interacted with the mouse or keyboard for a given time and if the hard drives and processors have been idle more than 90% of that time. - Free disk space is less than `<...>` MB—Netwrix Auditor stops video recording upon reaching the selected disk space limit. - Consider user activity — Select one of the following: - Stop if user has been idle for `<...>` minutes. Select this option if you want Netwrix Auditor to stop video recording for a user after the specified time period. - Continue video recording regardless of the user idle state. When selected, Netwrix Auditor continues video recording for idle users. | | Set a retention period to clear stale videos | When the selected retention period is over, Netwrix Auditor deletes your video recordings. | | Users | | -| Specify users to track their activity | Select the users whose activity should be recorded. You can select **All users** or create a list of **Specific users or user groups**. Certain users can also be added to **Exceptions** list. | +| Specify users to track their activity | Select the users whose activity you want to record. You can select **All users** or create a list of **Specific users or user groups**. You can also add certain users to the **Exceptions** list. | | Applications | | -| Specify applications you want to track | Select the applications that you want to monitor. You can select All applications or create a list of Specific applications. Certain applications can also be added to Exceptions list. | +| Specify applications you want to track | Select the applications that you want to monitor. You can select All applications or create a list of Specific applications. You can also add certain applications to the Exceptions list. | | Monitored Computers | | -| For a newly created monitoring plan for User Activity, the list of monitored computers is empty. Add items to your monitoring plan and wait until Netwrix Auditor retrieves all computers within these items. See [Add Items for Monitoring](/docs/auditor/10.9/admin/monitoringplans/datasources.md#add-items-for-monitoring)for more information. The list contains computer name, its current status and last activity time. | | +| For a newly created monitoring plan for User Activity, the list of monitored computers is empty. Add items to your monitoring plan and wait until Netwrix Auditor retrieves all computers within these items. See [Add Items for Monitoring](/docs/auditor/10.9/admin/monitoringplans/datasources.md#add-items-for-monitoring) for the item types each data source supports and the steps for adding them. The list contains computer name, its current status and last activity time. | | Review your data source settings and click **Add** to go back to your plan. The newly created data source will appear in the **Data source** list. As a next step, click **Add item** to specify an @@ -45,13 +45,13 @@ information. ## How to Include/Exclude Applications -To create a list of application to include in / exclude from monitoring, you will need to provide: +To create a list of applications to include in or exclude from monitoring, provide the following: - Title — application title as shown on top of the application window, for example, **MonthlyReport.docx - Word**. - - Title can also be found in the "_What_" column of related Netwrix Auditor reports and search - results, for example, in the **User Sessions** report. + - You can also find the title in the "_What_" column of related Netwrix Auditor reports and + search results, for example, in the **User Sessions** report. - Description — as shown in the Description column on theDetails tab of Windows Task Manager. @@ -65,7 +65,7 @@ To create a list of inclusions / exclusions for applications: **Step 2 –** Enter application title and description you have identified. -Wildcards (\*?) are supported and applied as follows: +Netwrix Auditor supports wildcards (\*?) and applies them as follows: - _\* - Notepad_ (the "Title" filter) will exclude all Notepad windows. - _colo?r \*_ (the "Title" filter) will exclude all application window titles containing "_color_" @@ -88,8 +88,8 @@ To exclude the Notepad application window with "_Document1_" open, add the follo ## Computer For evaluation purposes, Netwrix recommends selecting Computer as an item for a monitoring plan. -Once the product is configured to collect data from the specified items, audit settings (including -Core and Compression services installation) will be applied to all computers within AD Container or +After you configure the product to collect data from the specified items, it applies audit settings (including +Core and Compression services installation) to all computers within the AD Container or IP Range. Complete the following fields: @@ -97,8 +97,8 @@ Complete the following fields: | Option | Description | | --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | General | | -| Specify a computer | Provide a server name by entering its FQDN, NETBIOS or IPv4 address. You can click Browse to select a computer from the list of computers in your network. | -| Specify the account for collecting data | Select the account that will be used to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select account type you want to use and enter credentials. The following choices are available: - User/password. The account must be granted the same permissions and access rights as the default account used for data collection. See the [Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. - Group Managed Service Account (gMSA). You should specify only the account name in the domain\account$ format. See the [Use Group Managed Service Account (gMSA)](/docs/auditor/10.9/requirements/gmsa.md) topic for additional information. | +| Specify a computer | Provide a server name by entering its FQDN, NETBIOS, or IPv4 address. You can click Browse to select a computer from the list of computers in your network. | +| Specify the account for collecting data | Select the account that Netwrix Auditor will use to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select account type you want to use and enter credentials. The following choices are available: - User/password. The account must have the same permissions and access rights as the default account used for data collection. See the [Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. - Group Managed Service Account (gMSA). You should specify only the account name in the domain\account$ format. See the [Use Group Managed Service Account (gMSA)](/docs/auditor/10.9/requirements/gmsa.md) topic for additional information. | ## IP Range @@ -108,8 +108,8 @@ Complete the following fields: | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | General | | | Specify IP range | Specify an IP range for the audited computers. To exclude computers from within the specified range, click **Exclude**. Enter the IP subrange you want to exclude, and click **Add**. | -| Specify the account for collecting data | Select the account that will be used to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select **Custom account** and enter credentials. The credentials are case sensitive. A custom account must be granted the same permissions and access rights as the default account used for data collection. See the [Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. | -| Specify monitoring restrictions | Specify restriction filters to narrow your monitoring scope (search results, reports and Activity Summaries). To exclude specific IP subranges from data collection, click **Exclude** next to the IP range fields. In the **Exclude Subranges** dialog, specify the **Start IP** and **End IP** for each subrange you want to exclude. Click **+ Add** to add more subranges. Exclusions apply only to the specific monitoring plan item in which they are configured. | +| Specify the account for collecting data | Select the account that Netwrix Auditor will use to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select **Custom account** and enter credentials. The credentials are case sensitive. A custom account must have the same permissions and access rights as the default account used for data collection. See the [Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. | +| Specify monitoring restrictions | Specify restriction filters to narrow your monitoring scope (search results, reports, and Activity Summaries). To exclude specific IP subranges from data collection, click **Exclude** next to the IP range fields. In the **Exclude Subranges** dialog, specify the **Start IP** and **End IP** for each subrange you want to exclude. Click **+ Add** to add more subranges. Exclusions apply only to the specific monitoring plan item where you configure them. | ## AD Container @@ -118,6 +118,6 @@ Complete the following fields: | Option | Description | | --------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | General | | -| Specify AD container | Specify a whole AD domain, OU or container. Click **Browse** to select from the list of containers in your network. You can also: - Select a particular computer type to be audited within the chosen AD container: **Domain controllers, Servers (excluding domain controllers)**, or **Workstations**. - Click **Exclude** to specify AD domains, OUs, and containers you do not want to audit. In the Exclude Containers dialog, click Add and specify an object. The list of containers does not include child domains of trusted domains. Use other options **(Computer, IP range** to specify the target computers. | -| Specify the account for collecting data | Select the account that will be used to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select **Custom account** and enter credentials. The credentials are case sensitive. If using a group Managed Service Account (gMSA), you can specify only the account name in the _domain\account$_ format. Password field can be empty. A custom account must be granted the same permissions and access rights as the default account used for data collection. See the[Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. | -| Specify monitoring restrictions | Specify restriction filters to narrow your monitoring scope (search results, reports and Activity Summaries). All filters are applied using AND logic. Depending on the type of the object you want to exclude, select one of the following: - **Add AD Container** – Browse for a container to be excluded from being audited. You can select a whole AD domain, OU or container. - **Add Computer** – Provide the name of the computer you want to exclude as shown in the "Where" column of reports and Activity Summaries. For example, backupsrv01.mydomain.local. Wildcards (*) are not supported. | \ No newline at end of file +| Specify AD container | Specify a whole AD domain, OU, or container. Click **Browse** to select from the list of containers in your network. You can also: - Select a particular computer type to audit within the chosen AD container: **Domain controllers, Servers (excluding domain controllers)**, or **Workstations**. - Click **Exclude** to specify AD domains, OUs, and containers you don't want to audit. In the Exclude Containers dialog, click Add and specify an object. The list of containers doesn't include child domains of trusted domains. Use other options **(Computer, IP range** to specify the target computers. | +| Specify the account for collecting data | Select the account that Netwrix Auditor will use to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select **Custom account** and enter credentials. The credentials are case sensitive. If using a group Managed Service Account (gMSA), you can specify only the account name in the _domain\account$_ format. Password field can be empty. A custom account must have the same permissions and access rights as the default account used for data collection. See the[Data Collecting Account](/docs/auditor/10.9/admin/monitoringplans/dataaccounts.md) topic for additional information. | +| Specify monitoring restrictions | Specify restriction filters to narrow your monitoring scope (search results, reports, and Activity Summaries). Netwrix Auditor applies all filters using AND logic. Depending on the type of the object you want to exclude, select one of the following: - **Add AD Container** – Browse for a container to exclude from auditing. You can select a whole AD domain, OU, or container. - **Add Computer** – Provide the name of the computer you want to exclude as shown in the "Where" column of reports and Activity Summaries. For example, backupsrv01.mydomain.local. Wildcards (*) aren't supported. | diff --git a/docs/auditor/10.9/admin/settings/longtermarchive.md b/docs/auditor/10.9/admin/settings/longtermarchive.md index fb5b5b98da..51b730a0c8 100644 --- a/docs/auditor/10.9/admin/settings/longtermarchive.md +++ b/docs/auditor/10.9/admin/settings/longtermarchive.md @@ -6,8 +6,8 @@ sidebar_position: 30 # Long-Term Archive -The Long-Term Archive is configured by default, irrespective of your subscription plan and settings -you specified when configuring a monitoring plan. To review and update your Long-Term Archive +Netwrix Auditor configures the Long-Term Archive by default, irrespective of your subscription plan +and the settings you specified when configuring a monitoring plan. To review and update your Long-Term Archive settings, navigate to **Settings** > **Long-Term Archive** and click Modify. ![lta_settings_thumb_0_0](/images/auditor/10.9/admin/settings/lta_settings_thumb_0_0.webp) @@ -17,9 +17,9 @@ Review the following for additional information: | Option | Description | | ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Long-Term Archive settings | | -| Write audit data to | Specify the path to a local or shared folder where your audit data will be stored. By default, it is set to _"C:\ProgramData\Netwrix Auditor\Data"_. By default, the LocalSystem account is used to write data to the local-based Long-Term Archive and computer account is used for the file share-based storage. Subscriptions created in the Auditor client are uploaded to file servers under the Long-Term Archive service account as well. It is not recommended to store your Long-Term Archive on a system disk. If you want to move the Long-Term Archive to another location, refer to the following Netwrix Knowledge base article: [How to move Long-Term Archive to a new location](/docs/kb/auditor/features-and-operations/glossaries-and-faqs/how-to-move-long-term-archive-to-a-new-location). | -| Keep audit data for (in months) | Specify how long data will be stored. By default, it is set to 120 months. | -| Use custom credentials (for the file share-based Long-Term Archive only) | Select the checkbox and provide user name and password for the Long-Term Archive service account. You can specify a custom account only for the Long-Term Archive stored on a file share. The custom Long-Term Archive service account can be granted the following rights and permissions: - Advanced permissions on the folder where the Long-term Archive is stored: - List folder / read data - Read attributes - Read extended attributes - Create files / write data - Create folders / append data - Write attributes - Write extended attributes - Delete subfolders and files - Read permissions - On the file shares where report subscriptions are saved: - Change share permission - Create files / write data folder permission Subscriptions created in the Auditor client  are uploaded to file servers under the Long-Term Archive service account as well. See the [Subscriptions](/docs/auditor/10.9/admin/subscriptions/overview.md) topic for additional information. | +| Write audit data to | Specify the path to a local or shared folder where Netwrix Auditor will store your audit data. By default, the path is _"C:\ProgramData\Netwrix Auditor\Data"_. By default, Netwrix Auditor uses the LocalSystem account to write data to the local-based Long-Term Archive and the computer account for the file share-based storage. Netwrix Auditor also uploads subscriptions created in the Auditor client to file servers under the Long-Term Archive service account. Netwrix doesn't recommend storing your Long-Term Archive on a system disk. To move the Long-Term Archive to another location, see the Netwrix Knowledge base article: [How to move Long-Term Archive to a new location](/docs/kb/auditor/features-and-operations/glossaries-and-faqs/how-to-move-long-term-archive-to-a-new-location). | +| Keep audit data for (in months) | Specify how long Netwrix Auditor stores data. The default is 120 months. | +| Use custom credentials (for the file share-based Long-Term Archive only) | Select the checkbox and provide user name and password for the Long-Term Archive service account. You can specify a custom account only for the Long-Term Archive stored on a file share. You can grant the custom Long-Term Archive service account the following rights and permissions: - Advanced permissions on the folder where Netwrix Auditor stores the Long-Term Archive: - List folder / read data - Read attributes - Read extended attributes - Create files / write data - Create folders / append data - Write attributes - Write extended attributes - Delete subfolders and files - Read permissions - On the file shares where Netwrix Auditor saves report subscriptions: - Change share permission - Create files / write data folder permission Netwrix Auditor also uploads subscriptions created in the Auditor client  to file servers under the Long-Term Archive service account. See the [Subscriptions](/docs/auditor/10.9/admin/subscriptions/overview.md) topic for additional information. | Setting Recording Settings @@ -27,11 +27,11 @@ Setting Recording Settings | | | | ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| Configure custom location of session recordings | Default location for storing session recordings is set to _"\\``\Netwrix_UAVR$"_. However, storing extra files on the Auditor Server may produce additional load on it, so consider using this option to specify another location where session recordings will be stored. | -| Enter UNC path to shared folder: | Specify UNC path to the shared folder where user session video recordings will be stored. You can use server name or IP address, for example: _\\172.28.6.33\NA_UserSessions_ Using a local folder for that purpose is not recommended, as storing extra files on the Auditor Server will produce additional load on it. Make sure the specified shared folder has enough capacity to store the video files. Retention period for the video files can be adjusted in the related monitoring plan settings (targeted at User Activity data source); default retention is 7 days. See the [User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) topic for additional information. After you specify and save settings for session recordings, it is recommended that you leave them unchanged. Otherwise — if you change the storage location while using Netwrix Auditor for User Activity — please be aware of possible data loss, as Auditor will not automatically move session recordings to a new location. | -| User name / Password | Provide user name and password for the account that will be used to store session recordings to the specified shared folder. Make sure the account has at least the Write permission for that folder. | +| Configure custom location of session recordings | The default location for storing session recordings is _"\\``\Netwrix_UAVR$"_. However, storing extra files on the Auditor Server may produce additional load on it, so consider using this option to specify another location where Netwrix Auditor stores session recordings. | +| Enter UNC path to shared folder: | Specify UNC path to the shared folder where Netwrix Auditor will store user session video recordings. You can use server name or IP address, for example: _\\172.28.6.33\NA_UserSessions_ Netwrix doesn't recommend using a local folder for that purpose, as storing extra files on the Auditor Server produces additional load on it. ensure the specified shared folder has enough capacity to store the video files. You can adjust the retention period for the video files in the related monitoring plan settings (targeted at User Activity data source); default retention is 7 days. See the [User Activity](/docs/auditor/10.9/admin/monitoringplans/useractivity/overview.md) topic for additional information. After you specify and save settings for session recordings, leave them unchanged. Otherwise — if you change the storage location while using Netwrix Auditor for User Activity — be aware of possible data loss, as Auditor will not automatically move session recordings to a new location. | +| User name / Password | Provide user name and password for the account that Netwrix Auditor will use to store session recordings to the specified shared folder. ensure the account has at least the Write permission for that folder. | Auditor informs you if you are running out of space on a system disk where the Long-Term Archive is -stored by default. You will see events in the Netwrix Auditor **System Health** log once the free -disk space starts approaching minimum level. When the free disk space is less than 3 GB, the -Netwrix services responsible for audit data collection will be stopped. +stored by default. You will see events in the Netwrix Auditor **System Health** log when the free +disk space starts approaching the minimum level. When the free disk space is less than 3 GB, Auditor +stops the Netwrix services responsible for audit data collection. diff --git a/docs/auditor/10.9/configuration/azurefiles/stateintime.md b/docs/auditor/10.9/configuration/azurefiles/stateintime.md index 1a7e0a1dcb..989906b523 100644 --- a/docs/auditor/10.9/configuration/azurefiles/stateintime.md +++ b/docs/auditor/10.9/configuration/azurefiles/stateintime.md @@ -33,7 +33,7 @@ By default, only Entra ID accounts appear with display names in Azure Files repo - Resolve display names for on-premises accounts not synced to Microsoft Entra ID. - List individual members of on-premises AD groups (including members of nested groups, resolved transitively) as separate rows in permission reports. -If you don't provide credentials, report output remains identical to earlier versions — this is a fully optional, additive capability. +If you don't provide credentials, report output remains identical to earlier versions — this capability is optional and additive. **To configure Active Directory integration:** @@ -46,7 +46,7 @@ If you don't provide credentials, report output remains identical to earlier ver 7. Enter the **Password** for the account. 8. Click **Save**. -> **Note:** If Netwrix Auditor cannot authenticate with the configured AD account, it records a collection error in the System Health log and continues snapshot collection using cloud-resolved identities only. Netwrix Auditor records transient AD connectivity issues as warnings and doesn't stop collection for these issues. +> **Note:** If Netwrix Auditor can't authenticate with the configured AD account, it records a collection error in the System Health log and continues snapshot collection using cloud-resolved identities only. Netwrix Auditor records transient AD connectivity issues as warnings and doesn't stop collection for these issues. ## Configuring the monitoring scope (omit lists) @@ -99,7 +99,7 @@ By default, Netwrix Auditor collects State-in-Time snapshots daily. To customize ### Importing historical snapshots -Historical snapshots allow generating reports for past dates. A Global administrator must import historical snapshots. +Historical snapshots let you generate reports for past dates. A Global administrator must import historical snapshots. **To import a historical snapshot:** diff --git a/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md b/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md index 4a5edd7885..6b015db01b 100644 --- a/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md +++ b/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md @@ -6,9 +6,9 @@ sidebar_position: 5 # Use a Group Managed Service Account (gMSA) -Password Expiration Notifier supports a group Managed Service Account (gMSA) as the data collecting account. With a gMSA, Active Directory generates and rotates the password automatically, so you do not maintain a password for the account or rotate it on a schedule. +Password Expiration Notifier supports a group Managed Service Account (gMSA) as the data collecting account. With a gMSA, Active Directory generates and rotates the password automatically, so you don't maintain a password for the account or rotate it on a schedule. -See the [Use Group Managed Service Account (gMSA)](/docs/auditor/10.9/requirements/gmsa.md) topic for the general prerequisites that apply to every Auditor data source: create the KDS root key, create the gMSA with the `New-ADServiceAccount` cmdlet, install it on the Auditor Server with `Install-ADServiceAccount`, and add it to the local **Administrators** group on the Auditor Server. +See the [Use Group Managed Service Account (gMSA)](/docs/auditor/10.9/requirements/gmsa.md) topic for the general prerequisites that apply to every Auditor data source: create the Key Distribution Services (KDS) root key, create the gMSA with the `New-ADServiceAccount` cmdlet, install it on the Auditor Server with `Install-ADServiceAccount`, and add it to the local **Administrators** group on the Auditor Server. After you complete those prerequisites, specify the gMSA in the Password Expiration Notifier monitoring plan. @@ -21,23 +21,23 @@ Password Expiration Notifier reads Active Directory user attributes to determine | `GenericRead` | User objects in the target OUs | Read `pwdLastSet`, `msDS-UserPasswordExpiryTimeComputed`, `accountExpires`, `userAccountControl`, `mail`, `manager`, `sAMAccountName`, and related attributes | :::note -In a default Active Directory configuration, the built-in **Authenticated Users** group has read access to user objects, and a gMSA inherits that access. No additional delegation is usually required. If read access was restricted in your domain (for example, by removing **Authenticated Users** from an OU's ACL), grant the gMSA membership in a group that has read access to the target OUs, or delegate read permissions to the gMSA directly through Active Directory Users and Computers. +In a default Active Directory configuration, the built-in **Authenticated Users** group has read access to user objects, and a gMSA inherits that access. You usually don't need additional delegation. If your domain restricts read access (for example, an administrator removed **Authenticated Users** from an OU's ACL), grant the gMSA membership in a group that has read access to the target OUs, or delegate read permissions to the gMSA directly through Active Directory Users and Computers. ::: ## Specify the gMSA in the Monitoring Plan -Follow the steps to use the gMSA in a Password Expiration Notifier monitoring plan. +To use the gMSA in a Password Expiration Notifier monitoring plan: **Step 1 –** On the Auditor Server, launch Password Expiration Notifier and open an existing monitoring plan for editing, or create a new one. See the [Configure Password Expiration Alerting](/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md#configure-password-expiration-alerting) section for the full monitoring plan procedure. **Step 2 –** On the **General** tab, in the **User name** field, enter the gMSA account name in one of the supported formats: -- `\$` — NetBIOS domain name and `sAMAccountName`, for example `CONTOSO\penGmsa$`. This format is recommended. +- `\$` — NetBIOS domain name and `sAMAccountName`, for example `CONTOSO\penGmsa$`. Netwrix recommends this format. - `$@` — UPN format, for example `penGmsa$@contoso.local`. -The trailing `$` is required. Password Expiration Notifier uses the `$` to recognize the account as a gMSA and switch to the appropriate authentication path. +You must include the trailing `$`. Password Expiration Notifier uses the `$` to recognize the account as a gMSA and switch to the appropriate authentication path. -**Step 3 –** Leave the **Password** field as it is. When you enter a gMSA name, the field is locked automatically and displays `(Managed by Active Directory)`. Active Directory manages the password, so there is nothing to enter. +**Step 3 –** Leave the **Password** field as it is. When you enter a gMSA name, Password Expiration Notifier locks the field automatically and displays `(Managed by Active Directory)`. Active Directory manages the password, so there is nothing to enter. **Step 4 –** Complete the remaining tabs of the monitoring plan and click **Save**. @@ -46,14 +46,14 @@ When you save the monitoring plan, Password Expiration Notifier creates a Window ## Limitations :::warning -The **Select OUs**, **Select Groups**, and **Generate** buttons in the Password Expiration Notifier UI do not work when a gMSA is configured. These buttons issue an LDAP request at the time you click them from the interactive session of the user who launched Password Expiration Notifier, and gMSA impersonation is not supported in interactive sessions. Use the scheduled task and the email reports to view password expiration data when the monitoring plan uses a gMSA. +The **Select OUs**, **Select Groups**, and **Generate** buttons in the Password Expiration Notifier UI don't work when a gMSA is configured. These buttons issue an LDAP request when you click them from the interactive session of the user who launched Password Expiration Notifier, and interactive sessions don't support gMSA impersonation. Use the scheduled task and the email reports to view password expiration data when the monitoring plan uses a gMSA. ::: ## Troubleshooting -The table below lists common issues you may encounter when configuring a gMSA for Password Expiration Notifier. +The following table lists common issues you may encounter when configuring a gMSA for Password Expiration Notifier. | Symptom | Likely cause | Resolution | | ------- | ------------ | ---------- | -| `Cannot find an account...` error when specifying the account | The gMSA name was entered without the trailing `$` or with the wrong domain. | Use the `\$` format, for example `CONTOSO\penGmsa$`. | -| The **Select OUs**, **Select Groups**, or **Generate** buttons do not work; the log shows `failed to create impersonation token` | Known gMSA limitation in interactive sessions. | See the Limitations section. Use the scheduled task and email reports instead. | +| `Cannot find an account...` error when specifying the account | You entered the gMSA name without the trailing `$` or with the wrong domain. | Use the `\$` format, for example `CONTOSO\penGmsa$`. | +| The **Select OUs**, **Select Groups**, or **Generate** buttons don't work; the log shows `failed to create impersonation token` | Known gMSA limitation in interactive sessions. | See the Limitations section. Use the scheduled task and email reports instead. | diff --git a/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md b/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md index 9ccc45e550..e642d22da8 100644 --- a/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md +++ b/docs/auditor/10.9/tools/passwordexpirationnotifier/overview.md @@ -8,8 +8,8 @@ sidebar_position: 50 Netwrix Auditor Password Expiration Notifier standalone tool checks which domain accounts or passwords are about to expire in the specified number of days and sends notifications to users. It -also generates summary reports that can be delivered to system administrators and/or users' -managers. Besides, Netwrix Auditor Password Expiration Notifier allows checking the effects of a +also generates summary reports that it can deliver to system administrators and/or users' +managers. You can also use Netwrix Auditor Password Expiration Notifier to check the effects of a password policy change before applying it to the managed domain. - Windows Server 2025 @@ -29,12 +29,12 @@ Review the following for additional information: ## Configure Password Expiration Alerting -Follow the steps to configure password expiration alerting. +To configure password expiration alerting: **Step 1 –** Navigate to **Start** > **Netwrix Auditor** > **Password Expiration Notifier**. -**Step 2 –** On the main page, you will be prompted to select a monitoring plan. Click Add to add a -new monitoring plan. +**Step 2 –** On the main page, Password Expiration Notifier prompts you to select a monitoring plan. +Click Add to add a new monitoring plan. **Step 3 –** Configure basic parameters as follows: @@ -48,39 +48,39 @@ new monitoring plan. | Option | Description | | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| Specify account which will be used to collect data: - User name - Password | Enter the account which will be used for data collection. For a full list of the rights and permissions of this account, and instructions on how to configure them, refer to [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md). To use a group Managed Service Account (gMSA) instead of a user account, see the [Use a Group Managed Service Account (gMSA)](/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md) topic. | -| Filter users by organizational unit | To audit users for expiring accounts/passwords that belong to certain organizational units within your Active Directory domain, select this option and click Select OUs. In the dialog that opens, specify the OUs that you want to audit. Only users belonging to these OUs will be notified and included in the administrators and managers reports. | -| Filter users by group | To audit users for expiring accounts/passwords that belong to certain groups within your Active Directory domain, select this option and click Select Groups. In the dialog that opens, specify the groups that you want to audit. Only users belonging to these groups will be notified and included in the administrators and managers reports. | -| Filter by account name | Specify one or several user account names (e.g., \*John\*). Use semicolon to separate several names. Only user accounts that contain selected name will be notified and included in the administrators and managers reports. | +| Specify account which will be used to collect data: - User name - Password | Enter the account that Password Expiration Notifier will use for data collection. For a full list of the rights and permissions of this account, and instructions on how to configure them, refer to [Monitoring Plans](/docs/auditor/10.9/admin/monitoringplans/overview.md). To use a group Managed Service Account (gMSA) instead of a user account, see the [Use a Group Managed Service Account (gMSA)](/docs/auditor/10.9/tools/passwordexpirationnotifier/gmsa.md) topic. | +| Filter users by organizational unit | To audit users for expiring accounts/passwords that belong to certain organizational units within your Active Directory domain, select this option and click Select OUs. In the dialog that opens, specify the OUs that you want to audit. Password Expiration Notifier notifies only the users belonging to these OUs and includes only those users in the administrators and managers reports. | +| Filter users by group | To audit users for expiring accounts/passwords that belong to certain groups within your Active Directory domain, select this option and click Select Groups. In the dialog that opens, specify the groups that you want to audit. Password Expiration Notifier notifies only the users belonging to these groups and includes only those users in the administrators and managers reports. | +| Filter by account name | Specify one or several user account names (e.g., \*John\*). Use semicolon to separate several names. Password Expiration Notifier notifies only the user accounts that contain the selected name and includes only those accounts in the administrators and managers reports. | **Step 5 –** Navigate to the **Actions** tab and complete the following fields: | Option | Description | | --------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Send report to the users’ managers | Enable this option to deliver reports to the user’s managers. To review and edit the user's managers 1. Start **Active Directory Users and Computers**. 2. Navigate to each group where the user belongs to, right-click it and select Properties. 3. In the `` Properties dialog, select the Managed By tab and review a manager. Update it if necessary. To edit a report template, click **Customize**. You can use HTML tags when editing a template. | -| List users whose accounts or passwords expire in `<>` days or less | Specify the expiration period for accounts and/or passwords to be included in the administrators and managers reports. | -| Only report on users with expiring accounts | Select this option to deliver reports on users with expiring accounts only and ignore users whose passwords will be valid for a rather long time. | +| List users whose accounts or passwords expire in `<>` days or less | Specify the expiration period for accounts and passwords to include in the administrators and managers reports. | +| Only report on users with expiring accounts | Select this option to deliver reports on users with expiring accounts only and ignore users whose passwords remain valid for a long time. | | Notify users | Select this option to notify users that their passwords and/or accounts are about to expire. | -| Every day if password expires in `<>` days or less | Select this option for users to be notified daily that their passwords are going to expire, and specify the number of days before the expiration date. To edit a report template, click **Customize**. You can use HTML tags when editing a template. To send a test email, click **Test** and select an account. Make sure this account has a password that expires within the period you specified next to this option. | -| First/Second/Last time when password expires in `<>` days | Select this option for users to be notified three times, and specify the number of days before the expiration date for each of three notifications. To edit a report template, click **Customize**. You can use HTML tags when editing a template. To send a test email, click Test and select an account. Make sure this account has a password that expires within the period you specified next to this option. | -| Notify users by email every day if their accounts expire in `<>` days | Select this option for users to be notified daily that their account is going to expire, and specify the number of days before the expiration date. To send a test email, click **Test** and select an account. Make sure this account has a password that expires within the period you specified next to this option. | -| Notify users by text messages | Select this option for users to receive text messages if their passwords are about to expire. To edit SMS Notifications template, click Customize. - Every day if password expires in `<>` days or less — Select this option for users to be notified daily that their passwords are going to expire, and specify the number of days before the expiration date. - First/Second/Last time when password expires in `<>` days — Select this option for users to be notified three times, and specify the number of days before the expiration date for each of three notifications. - Provider name — Specify provider name. - Property name — Specify the name of the Active Directory User Property where the recipient's phone number is stored. Pager is the default property. If the Pager property of an AD User contains a full email address, Provider Name will be ignored. | +| Every day if password expires in `<>` days or less | Select this option to notify users daily that their passwords are going to expire, and specify the number of days before the expiration date. To edit a report template, click **Customize**. You can use HTML tags when editing a template. To send a test email, click **Test** and select an account. ensure this account has a password that expires within the period you specified next to this option. | +| First/Second/Last time when password expires in `<>` days | Select this option to notify users three times, and specify the number of days before the expiration date for each of three notifications. To edit a report template, click **Customize**. You can use HTML tags when editing a template. To send a test email, click Test and select an account. ensure this account has a password that expires within the period you specified next to this option. | +| Notify users by email every day if their accounts expire in `<>` days | Select this option to notify users daily that their accounts are going to expire, and specify the number of days before the expiration date. To send a test email, click **Test** and select an account. ensure this account has a password that expires within the period you specified next to this option. | +| Notify users by text messages | Select this option for users to receive text messages if their passwords are about to expire. To edit SMS Notifications template, click Customize. - Every day if password expires in `<>` days or less — Select this option to notify users daily that their passwords are going to expire, and specify the number of days before the expiration date. - First/Second/Last time when password expires in `<>` days — Select this option to notify users three times, and specify the number of days before the expiration date for each of three notifications. - Provider name — Specify provider name. - Property name — Specify the name of the Active Directory User Property that contains the recipient's phone number. Pager is the default property. If the Pager property of an AD User contains a full email address, Password Expiration Notifier ignores the Provider Name value. | **Step 6 –** Navigate to the **Notifications** tab and complete the following fields: | Option | Description | | --------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Use Netwrix Auditor notification settings | Select this option if you want to use modern authentication. Please note that modern authentication must already be configured in the monitoring plan you are going to use. If you select this option, the fields below are not needed. | +| Use Netwrix Auditor notification settings | Select this option if you want to use modern authentication. You must already have configured modern authentication in the monitoring plan you are going to use. If you select this option, you don't need to complete the remaining fields. | | SMTP server | Enter your SMTP server address. It can be your company's Exchange server or any public mail server (e.g., Gmail, Yahoo). | | Port number | Specify your SMTP server port number. | -| Sender address | Enter the address that will appear in the From field. **_RECOMMENDED:_** click **Send Test Email**. The system will send a test message to the specified email address and inform you if any problems are detected. | +| Sender address | Enter the address that will appear in the From field. **_RECOMMENDED:_** click **Send Test Email**. The system will send a test message to the specified email address and inform you if it detects any problems. | | SMTP authentication | Select this checkbox if your mail server requires the SMTP authentication. | | User name | Enter a user name for the SMTP authentication. | | Password | Enter a password for SMTP authentication. | -| Use Secure Sockets Layer encrypted connection (SSL) | Select this checkbox if your SMTP server requires SSL to be enabled. | -| Use implicit SSL | Select this checkbox if the implicit SSL mode is used, which means that an SSL connection is established before any meaningful data is sent. | -| Enforce certificate validation to ensure security | Select this checkbox if you want to verify security certificate on every email transmission. The option is not available for auditing User Activity as well Netwrix Auditor tools. | -| Display the following From address in email notifications | Enter the address that will appear in the "_From_" field in email notifications. This option does not affect notifications sent to users' managers and administrators. Before configuring the "_From_" field for user email notifications, make sure that your Exchange supports this option. | +| Use Secure Sockets Layer encrypted connection (SSL) | Select this checkbox if your SMTP server requires SSL. | +| Use implicit SSL | Select this checkbox if your server uses the implicit SSL mode, which means that the server establishes an SSL connection before sending any meaningful data. | +| Enforce certificate validation to ensure security | Select this checkbox if you want to verify security certificate on every email transmission. The option isn't available for auditing User Activity as well Netwrix Auditor tools. | +| Display the following From address in email notifications | Enter the address that will appear in the "_From_" field in email notifications. This option doesn't affect notifications sent to users' managers and administrators. Before configuring the "_From_" field for user email notifications, ensure that your Exchange supports this option. | **Step 7 –** Navigate to the **Advanced** tab and complete the following fields: @@ -91,12 +91,12 @@ new monitoring plan. | Attach reports as a CSV files | Select this option to receive reports attached to emails as CSV files. | | Ignore users who must change password at next logon | Select this option to exclude users who must change password at next logon from reports. | | Ignore users with the "_Password never expires_" option enabled | Select this option to exclude users with the "_Password never expires_" option enabled from reports. | -| Ignore users who do not have email accounts | Select this option to exclude users who do not have email accounts from reports. | +| Ignore users who don't have email accounts | Select this option to exclude users who don't have email accounts from reports. | | Ignore users whose passwords have already expired | Select this option to exclude users whose passwords have already expired from reports. | -| Include data on expiring accounts | Select this option to include data on expiring domain accounts further to expiring passwords information. | -| Only report on users with fine-grained password policies applied | Select this option to include in reports only users who have fine-grained policies applied. | +| Include data on expiring accounts | Select this option to include data on expiring domain accounts in addition to expiring passwords information. | +| Only report on users with fine-grained password policies applied | Select this option to include in reports only users who have fine-grained password policies. | -**Step 8 –** If you want to save your current configuration, click Save. +**Step 8 –** To save your current configuration, click Save. To review Password Expiration Report From f5fd02d2512d1c8307c136cac0f394d81eed2b60 Mon Sep 17 00:00:00 2001 From: Kunle Lawani Date: Wed, 5 Aug 2026 18:56:35 +0100 Subject: [PATCH 5/8] AB#450491 Align AFA SIT description with FSA articles - Add a "Collect data for state-in-time reports" step, mirroring the FSA article, linking into the AFA State-in-Time configuration guide - Split the vague exclusions bullet into Subscription-level (omit storage accounts) vs Storage-Account-level (omit list) guidance, matching what the item's Scope tab actually does per item type - Remove "Step 5: Test Connection", which doesn't exist in the product - Fix step numbering gap and inconsistent 10_8/10.9 doc version links Generated with AI Co-Authored-By: Claude Code --- .../10.9/admin/monitoringplans/azurefiles.md | 28 +++++++++---------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/docs/auditor/10.9/admin/monitoringplans/azurefiles.md b/docs/auditor/10.9/admin/monitoringplans/azurefiles.md index 5943fdb6a6..08a5b50db9 100644 --- a/docs/auditor/10.9/admin/monitoringplans/azurefiles.md +++ b/docs/auditor/10.9/admin/monitoringplans/azurefiles.md @@ -22,8 +22,8 @@ Create monitoring plans for Azure Files to track file and folder changes across 1. In the **Netwrix Auditor**, go to **Home > Monitoring Plans > + Add Plan** 2. Select **Azure Files** 3. Configure: - - [Audit database (SQL)](/docs/auditor/10_8/admin/settings/auditdatabase) - - [Notifications (SMTP or Exchange Online)](/docs/auditor/10_8/admin/settings/notifications) + - [Audit database (SQL)](/docs/auditor/10.9/admin/settings/auditdatabase) + - [Notifications (SMTP or Exchange Online)](/docs/auditor/10.9/admin/settings/notifications) - Plan name and description - Select **Add item now** @@ -49,32 +49,32 @@ Create monitoring plans for Azure Files to track file and folder changes across - **Read Access (Success/Fail)** → Track file reads and unauthorized read attempts - **Successful** - Show successful attempts to read files - - **Failed** - Use this option to track suspicious activity. Helps find out who was trying to access your private data without proper justification.Enabling this option on public shares will result in a high number of events generated on Azure Files and the amount of data written to the Long-Term Archive + - **Failed** - Use this option to detect unauthorized attempts to read your data. Enabling this option on public shares generates a high volume of events on Azure Files and increases the amount of data written to the Long-Term Archive **Note:** Enabling read access auditing on public shares may generate high event volume **Tip:** Only enable read auditing where compliance requires it (e.g., HR, Finance) -4. Add exclusions → e.g., service accounts that produce excessive logs - -- **Monitored object types** - Select from: +4. **Monitored object types** - Select from: - Files - Folders - Shares -- **Monitored actions** - Configure which file operations to track +5. **Monitored actions** - Configure which file operations to track +6. **Collect data for state-in-time reports** – Enable this option to have Netwrix Auditor store periodic snapshots of your Azure Files permissions. State-in-Time reports, including permission and effective access reports, require these snapshots. See [Configuring State-in-Time Data Collection for Azure Files](/docs/auditor/10.9/configuration/azurefiles/stateintime.md) for the snapshot schedule, historical snapshot import, and optional Active Directory integration for on-premises accounts and groups. +7. Click **Save** + +### Step 4: Configure Exclusions (optional) -### Step 5: Test Connection +What you can exclude depends on the monitored item type: -Click **Test Connection** to verify: -- Microsoft Entra ID authentication -- Storage account access -- Audit log collection +- **Azure Subscription items** – On the item's **Scope** tab, exclude specific **storage accounts** by name so Netwrix Auditor skips them entirely for this subscription. +- **Azure Storage Account items** – On the item's **Scope** tab, use the **Omit List** to exclude specific shares, folders, or files (Universal Naming Convention (UNC) paths). Choose **All** to exclude an object from all data collection, or **SiT** to exclude it from State-in-Time snapshots only. See [Configuring the monitoring scope (omit lists)](/docs/auditor/10.9/configuration/azurefiles/stateintime.md#configuring-the-monitoring-scope-omit-lists) for details. ## Next Steps After creating the monitoring plan: 1. **Verify data collection** is working -2. **[Configure reports](/docs/auditor/10_8/admin/reports/overview)** as needed -3. **[Set up alerts](/docs/auditor/10_8/admin/alertsettings/create/)** for important events +2. **[Configure reports](/docs/auditor/10.9/admin/reports/overview)** as needed +3. **[Set up alerts](/docs/auditor/10.9/admin/alertsettings/create/)** for important events For configuration requirements, see [Azure Files Configuration](/docs/auditor/10.9/configuration/azurefiles/overview.md) From 548da9ffbaa5377428aa563b4d2814cd27cd0e02 Mon Sep 17 00:00:00 2001 From: Kunle Lawani Date: Wed, 5 Aug 2026 19:12:01 +0100 Subject: [PATCH 6/8] AB#449234 Document requirement for Application.Read.All permission --- .../10.9/configuration/azurefiles/overview.md | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/docs/auditor/10.9/configuration/azurefiles/overview.md b/docs/auditor/10.9/configuration/azurefiles/overview.md index 0199776f89..060003b337 100644 --- a/docs/auditor/10.9/configuration/azurefiles/overview.md +++ b/docs/auditor/10.9/configuration/azurefiles/overview.md @@ -65,6 +65,8 @@ Register an application so Netwrix Auditor can authenticate to Azure and read au **Note:** Switching audiences later may cause errors +**Recommendation:** Use a separate, dedicated application for Azure Files data collection rather than reusing an application for other purposes. By default, Netwrix Auditor omits its own collection application's activity from auditing — if the collection app is shared with other workloads, that other activity will not be captured. + ### Step 2: Gather App Details @@ -102,6 +104,7 @@ The Purpose column references Microsoft Graph API endpoints that Netwrix Auditor | `User.Read` | Basic user information. Sign in and read user profile. *(default)* | | `User.Read.All` | Read all users' full profiles. Required to resolve user security identifiers (SIDs) into display names and User Principal Names (UPNs), and to map access control entries (ACEs) from group membership via the Microsoft Graph endpoint `/users/{id}/transitiveMemberOf` | | `Group.Read.All` | Resolve groups and search by SID from discretionary access control lists (DACLs). Required to expand group membership via the Microsoft Graph endpoint `/groups/{id}/transitiveMembers` and filter groups by `securityIdentifier` | +| `Application.Read.All` | Resolve service principal (application) identities in audit records. Required when file or folder activity is performed by a service principal rather than a user — these objects have no SID and no UPN, so they cannot be resolved by `User.Read.All` or `Group.Read.All`. Without this permission, such records show a raw object ID instead of a display name, and the collector logs a "no SID and no UPN available to resolve the identity" error in the monitoring plan log. | 1. In your app in EntraID, go to **Manage > API permissions > + Add a permission**. @@ -110,10 +113,12 @@ The Purpose column references Microsoft Graph API endpoints that Netwrix Auditor - **User.Read (default)** - **User.Read.All** - **Group.Read.All** + - **Application.Read.All** - *User.Read* – "Sign in and read user profile." *(default)* - *User.Read.All* – "Read all users' full profiles" - *Group.Read.All* – "Read all groups" +- *Application.Read.All* – "Read all applications" — required to resolve service principal display names ### Step 2: Grant Admin Consent @@ -122,10 +127,11 @@ Click **Grant admin consent for TenantName** **Why this is required:** - By default, applications cannot query Microsoft Graph for directory-wide information -- Admin consent allows the app to use **User.Read.All** and **Group.Read.All** +- Admin consent allows the app to use **User.Read.All**, **Group.Read.All**, and **Application.Read.All** - **User.Read.All** lets Netwrix Auditor query Microsoft Entra ID and resolve **user SIDs → user accounts → display names** - **Group.Read.All** lets Netwrix Auditor resolve groups from DACLs and expand group membership so reports show which users inherit access through group ACEs -- Without admin consent, audit logs will only show unresolved SIDs and object IDs instead of usernames and group names, making reports incomplete and less useful +- **Application.Read.All** lets Netwrix Auditor resolve **service principal (application) identities** that have no SID and no UPN, so activity performed by applications — not just users — shows a display name instead of a raw object ID +- Without admin consent, audit logs will only show unresolved SIDs and object IDs instead of usernames, group names, and application names, making reports incomplete and less useful **At the end of this step, your app has granted Microsoft Graph API permissions** @@ -242,7 +248,7 @@ Azure Files audit logs will now be archived into your **Log Storage Account** ## Checklist - [Azure Application registered](#azure-application-registration) with App ID + Secret -- [API permissions](#configure-api-permissions) (User.Read, User.Read.All, Group.Read.All) granted +- [API permissions](#configure-api-permissions) (User.Read, User.Read.All, Group.Read.All, Application.Read.All) granted - [IAM roles assigned](#assign-iam-roles-to-the-app) (Reader, Storage File Data Privileged Reader, Storage Blob Data Reader) - [Diagnostic Settings configured](#diagnostic-settings) to log to a Log Storage Account From 7766f27ed4dbca0e3a485a7f0607e718cf681024 Mon Sep 17 00:00:00 2001 From: pavelshabanov2025 Date: Fri, 7 Aug 2026 04:23:33 -0700 Subject: [PATCH 7/8] fix(auditor/10.9 U1): editorial fixes and TLS setting for API docs (#1335) * fix(auditor/10.9): editorial fixes and TLS setting for API docs Fix style guide violations in Integration API prerequisites and security pages (numbered steps, active voice, sentence-case headings, spelled-out acronyms), and document the minTlsVersion setting in the APIAdminTool command table. * fix(vale): auto-fix style issues (Vale + Dale) * docs(auditor/10.9): clarify default minimum TLS version for new installs Co-Authored-By: Claude claude-sonnet-5 Co-Authored-By: Claude Code --------- Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude claude-sonnet-5 Co-authored-by: Claude Code --- docs/auditor/10.9/api/prerequisites.md | 33 ++++++++--------- docs/auditor/10.9/api/security.md | 35 +++++++++--------- .../connectwise/integrations_thumb_0_0.webp | Bin 41202 -> 55708 bytes 3 files changed, 33 insertions(+), 35 deletions(-) diff --git a/docs/auditor/10.9/api/prerequisites.md b/docs/auditor/10.9/api/prerequisites.md index 519b63fe1b..d322e6f7b5 100644 --- a/docs/auditor/10.9/api/prerequisites.md +++ b/docs/auditor/10.9/api/prerequisites.md @@ -6,38 +6,35 @@ sidebar_position: 10 # Prerequisites -Netwrix Auditor Integration API uses HTTPS for communication with the automatically generated +Netwrix Auditor Integration API uses HTTPS (Hypertext Transfer Protocol Secure) for communication with the automatically generated certificate. The default communication port is 9699. Refer to the [Security](/docs/auditor/10.9/api/security.md) topic for detailed instructions on how to disable HTTPS and manage other API settings. -## Configure Integration API Settings +## Configure Integration API settings -Follow the steps to change the port. +On this page, you can view the current port settings and restrictions on the TLS (Transport Layer Security) version used for encrypted connections. -**Step 1 –** In the Netwrix Auditor main window, navigate to the Integration tile. - -**Step 2 –** Make sure the Leverage Integration API option is enabled. - -**Step 3 –** Click Modify under the API settings section and specify a port number. Windows firewall -rule will be automatically created. - -**Step 4 –** If you use a third-party firewall, you must create a rule for inbound connections -manually. +1. In the Netwrix Auditor main window, navigate to the **Integration** tile. +2. Ensure the **Leverage Integration API** option is enabled. +3. Click **Modify settings** under the API settings section. +4. Specify a port number. The product automatically creates a Windows firewall rule. +5. Select the minimum TLS version from the list. For a new installation, this defaults to 1.2. +6. If you use a third-party firewall, create a rule for inbound connections manually. ![Integration API Settings](/images/auditor/10.9/addon/connectwise/integrations_thumb_0_0.webp) -## Configure Audit Database Settings +## Configure Audit Database settings When you first configure the Audit Database settings in Netwrix Auditor, the product also creates -several databases for special purposes, including Netwrix_Auditor_API. This database is designed to -store data imported from the other sources using Netwrix Auditor Integration API. +several databases for special purposes, including `Netwrix_Auditor_API`. This database stores data +imported from other sources through Netwrix Auditor Integration API. -Make sure that the Audit Database settings are configured in Netwrix Auditor. To check or configure -these settings, navigate to the **Settings > Audit Database**. +Ensure that you have configured the Audit Database settings in Netwrix Auditor. To check or configure +these settings, navigate to **Settings** > **Audit Database**. -You cannot use Netwrix Auditor Integration API without configuring the Audit Database. +Netwrix Auditor Integration API requires a configured Audit Database. Refer to the [Audit Database](/docs/auditor/10.9/admin/settings/auditdatabase.md) topic for detailed instructions on how to configure SQL Server settings. diff --git a/docs/auditor/10.9/api/security.md b/docs/auditor/10.9/api/security.md index aba998bef3..66134b9cb8 100644 --- a/docs/auditor/10.9/api/security.md +++ b/docs/auditor/10.9/api/security.md @@ -7,39 +7,40 @@ sidebar_position: 120 # Security By default, Netwrix Auditor API uses HTTPS for sending requests to its endpoints. Netwrix encrypts -data with a self-signed automatically generated SSL certificate and strongly recommends you to +data with a self-signed automatically generated SSL (Secure Sockets Layer) certificate and strongly recommends that you replace it with a new secured certificate acquired from any reliable source. -The automatically generated Netwrix API certificate is located in the Personal store. To enable +The automatically generated Netwrix API certificate resides in the Personal store. To enable trust on remote computers, install this certificate in the Trusted Root Certification Authorities store. ![certificatestore_thumb_0_0](/images/auditor/10.7/api/certificatestore_thumb_0_0.webp) -To manage API security settings with APIAdminTool.exe +## Manage API security settings with `APIAdminTool.exe` -Netwrix provides a command-line tool for managing Integration API. The tool allows switching between -HTTP and HTTPS, assigning new certificates, etc. +Netwrix provides a command-line tool for managing Integration API. Use the tool to switch between +HTTP and HTTPS, assign new certificates, and manage other API settings. -1. On the computer where Auditor Server resides, start the Command Prompt and run the tool. The tool - is located in the _Netwrix Auditor installation folder_, inside the _Audit Core_ folder. For +1. On the computer where Auditor Server resides, start the Command Prompt. +2. Navigate to the Netwrix Auditor installation folder, inside the Audit Core folder, and run the tool. For example: `C:\>cd C:\Program Files (x86)\Netwrix Auditor\Audit Core` `C:\Program Files (x86)\Netwrix Auditor\Audit Core>APIAdminTool.exe` -2. Execute one of the following commands depending on your task. Review the tips for running the +3. Execute one of the following commands depending on your task. Review the tips for running the tool: - - Some commands require parameters. Provide parameters with values (parameter= value) if you - want to use non-default. E.g., `APIAdminTool.exe api http port= 4431`. - - Append `help `to any command to see available parameters and sub-commands. E.g., + - Some commands require parameters. Provide parameters with values (parameter= value) to use + non-default values. E.g., `APIAdminTool.exe api http port= 4431`. + - Append `help` to any command to see available parameters and sub-commands. E.g., `APIAdminTool.exe api help`. -| To... | Execute... | -| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Disable API | `APIAdminTool.exe api disable` This command duplicates the checkbox on the Integrations page in Netwrix Auditor. | -| Switch to HTTP | `APIAdminTool.exe api http` Netwrix recommends switching to HTTP only in safe intranet environments. To use a non-default port (9699), append a parameter port with value to the command above (e.g.,` port= 4431`). | -| Switch to HTTPS | `APIAdminTool.exe api https` Run this command if you want to continue using Netwrix-generated certificate. To use a non-default port (9699), append a parameter port with value to the command above (e.g., `port= 4431`). | -| Assign a new SSL certificate | `APIAdminTool.exe api https certificate` Run this command if you want to apply a new certificate and use it instead default. You must add a certificate to the store before running this command. Provide parameters to specify a certificate:

  • For a certificate exported to a file:
  • path—Mandatory, defines certificate location.
  • store—Optional, defines the store name where certificate is located. By default, Personal. For example: `APIAdminTool.exe api https certificate path= C:\SecureCertificate.cef store= Personal`
  • For a self-signed certificate:
  • subject—Mandatory, defines certificate name.
  • validFrom—Optional, defines a certificate start date. By default, today.
  • validTo—Optional, defines a certificate expiration date. By default, 5 years after a validFrom date. For example: `APIAdminTool.exe api https certificate subject= New validTo= 01/01/2024` If you want to create a new self-signed certificate for a default period of 5 years from the current date: `APIAdminTool.exe api https certificate subject= "Netwrix Integration API"`
  • For a certificate specified using thumbprint:
  • store—Optional, defines the store name where certificate is located. By default, Personal.
  • thumbprint—Mandatory, defines a thumbprint identifier for a certificate. For example: `APIAdminTool.exe api https certificate thumbprint= 3478cda8586675e420511dc0fdf59078093eeeda`
| +| To... | Execute... | +| ---------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Disable API | `APIAdminTool.exe api disable` This command duplicates the checkbox on the Integrations page in Netwrix Auditor. | +| Switch to HTTP | `APIAdminTool.exe api http` Netwrix recommends switching to HTTP only in safe intranet environments. To use a non-default port (9699), append the port parameter with a value to this command (e.g., `port= 4431`). | +| Switch to HTTPS | `APIAdminTool.exe api https` Run this command to continue using the Netwrix-generated certificate. To use a non-default port (9699), append the port parameter with a value to this command (e.g., `port= 4431`). | +| Assign a new SSL certificate | `APIAdminTool.exe api https certificate` Run this command to apply a new certificate instead of the default. You must add a certificate to the store before running this command. Provide parameters to specify a certificate:
  • For a certificate exported to a file:
  • path—Mandatory, defines certificate location.
  • store—Optional, defines the store name where the certificate resides. By default, Personal. For example: `APIAdminTool.exe api https certificate path= C:\SecureCertificate.cef store= Personal`
  • For a self-signed certificate:
  • subject—Mandatory, defines certificate name.
  • validFrom—Optional, defines a certificate start date. By default, today.
  • validTo—Optional, defines a certificate expiration date. By default, 5 years after a validFrom date. For example: `APIAdminTool.exe api https certificate subject= New validTo= 01/01/2024` To create a new self-signed certificate for the default period of 5 years from the current date: `APIAdminTool.exe api https certificate subject= "Netwrix Integration API"`
  • For a certificate specified using thumbprint:
  • store—Optional, defines the store name where the certificate resides. By default, Personal.
  • thumbprint—Mandatory, defines a thumbprint identifier for a certificate. For example: `APIAdminTool.exe api https certificate thumbprint= 3478cda8586675e420511dc0fdf59078093eeeda`
| +| Set the minimum TLS version | `APIAdminTool.exe api https minTlsVersion` Use this command to set the minimum version of TLS (Transport Layer Security) used when connecting (e.g., `minTlsVersion= 1.2`) | diff --git a/static/images/auditor/10.9/addon/connectwise/integrations_thumb_0_0.webp b/static/images/auditor/10.9/addon/connectwise/integrations_thumb_0_0.webp index 6aecc482f6284dd4f54c9ca2568f34afe78087ea..030473eb4a5d65dc9a0193d643c7f94a4b24d496 100644 GIT binary patch literal 55708 zcmZ^~19WCh_B|Xs9lK-Owr$()xML?B+qP}n=-9SxC(qY2@67yW=9~Xr>sjlrT2*zc z&N+MUbMCE2Nm5KKaTN$iT~tUxO@TuL1_%fU>d(}^-f=uZnl@(K_TA{a;(FqJjf zEC?SiT%cfpr5%s~M|Se{AZ<>QsokexDvW_0;^~vqm-;Vn^+n&5OSGg9&$pTz{2Kjz zUuPekHu~0@R3D6wn)jM(y=}lHAmpR`I$^S>-FF=T`)Yb)eUMWGsQ3a>B^V#UnGVv;%~^00Q`PeU<)fbqbJmDc`R@10eCu^O^kg_aXjZf0cifzwuq>FZI0# z@LyVgnD0P_JtcjXe25>Y_hOXbBY!!6I(^_j0nYT_duBcyUu$l!2ldx|V*yBCo*yH( z^KaxUkT*5E{FD5ZfXJ`S&jx_qWX>#L4)F8db z`(?=W`BBX|`?l*$&ne*S_^RcP{cf2Mx`!x|o0}#3oCVTspCwVOG5p9S8nN#225lX_ z8f|@KU6nx^IJ_G3uG}#V2t<^Dj4-tCbzHDi>kUgqGD+tWETdYoXmwr)2GLVC0@BcrhOSVqMt13k#ovV&Y z$5e#{!KznOJKwAoJ<#i2#I$Vvf3G4_aw;dmf?6difVGwaH!g;^wF#Djez5!Kf z^hamfO9_5~?I>@!B)Z-F&xMnW&UY5kzrp;DOtaK&GIm4pmv>lGgv#9PRc+;l=>)H$ zIl*u#o%sLn`c)g!n8OW^UiUXAT}?YF1Ela)Ss%}o7$%Cp3XJhOPxA3ewy^9Cx*&=+ z9XJ`Ocjris4wsev>wnvyhVPrir>UsSAalW4ctY~^R7dW!P=>ZitYTa?`8e<&V-FXz zyu6gVI3tqGyNMv5rLJJ}#fALV{EnY$Ni=FsDt^0uo4*xF zCKLF=ITaUQ&gbbO4n;p$Hsu_YzaMun>FgE;QSNc~<5pldvC*hl(p0a~EWoyby%7ce+C zFZ8zIHv~L*U{7}zFv+0tyPZwca_#H!osjPMb_fHCI0{fz>y#2>>JAMTI4GSbAJm7M(&X`?D55jl> zTb)v5(TIj^{|6Bc)Mwlx1gFss%A#Kn@Blh41GcyT3ygBb_r$-$N-rh zUk&6x(8YoJInhtntNX_Ow2Lzm58N(!eP?7%L{ySl(_$4K|n8497o>w6aS93SP&1k~fz>d1oRw?f1Ri{`;y1K+ne`lD#n~zZ37RGXnd7+h@n=O`vb(G35VQe_s zay_ctq5FSxN+iL4lSWwWHuXvfzPzPQ!xI?=w%z9o;nuP1%tI*&?S6<0s;Fn6m-KYRFdHtM@mE{~-y5 zXP&v)#s{BYW_wr~(sRct82U9*RkolD8OU8tZ_mZy z8uiPHfyD(}3Q_m^{2;MplUyHfB!>V$QyXi8@!(tasExSL<_*`nJKJCDVuK^W(S#943V#C&L-? zdVYIinO40ZL$!5j%yv+7{yspm&2;@=+?S-QqSIt+h)T##`Pa754q|XKA*MrV`GS^W zQvE=1nO*8q)=m{JvxXV2^|X(t1MugF-OJIvz_bQi(f@(Te@6eZm6bYp&D(?r!?pDM z#A}Qd&v9JvALhT)w4p~#xAR1E>RiSIuKCWD-X4xN_a#-AZSx`$U^IrqgI}-+idrRy zk3Dh~F5f&h7@uQg)g*1H)NvHeWl`o!8&o}@kO}A(E~T&B9$|y%e-p-(A5CBr&qsd* z429t`UWc`+_?O8D%t^NIo2Wt*4`=B)lUsbvFHt&xTuVN5r+gUT)dz735d2Mrs8}?I z_YB>mtpz_1I447!xR4|qDd3jQ&uJg+KFgE}Mp3BWNi6tiDmaWpUC})WzD|);Oc27fb6E zryFOYkw3`wKM5+9{$G%c!TU><|7geG>FM%60{;)LK(Vv*KzQUHHA%5@#^6lN*Ds@V z_9Xx5?Z15c$DaQ-K8I>eC0c300%+FX6iDrDw#eHw`hVm*|0MIFTiyZ2`)@omdO_4Q z^C9`b?1zs1yPV@fb_uQ~WBPqNz$1)WZ?Y`{L2YVwOD71E<*M2iv179GrRC1~kLHPf&N;$ZcB9=KfFboHg$SbK| zR%ZM*nIsBF3FTzs0Z#CsVtVe9{5S45sYkg$tpNGI;`86^`A;HJgvxcU(!3RYNBeMS z`c{a^&B>>zH!FbFG8)^p%nnt&+5xiU`h)qMaPgJZMO`k77x7<#^7q8+-=-{&2ItFc z8czOqxBYnxa^F9lG5`^XP#q6hq$8iyrb(-Hgg{JI<)qt)hvv_nH8>0pLfw8S+G#%% zlnG-Xa`CjF2gxvd&lIFkp#G6gkoLq;0tqBcf@x%nb_`@-i8*YJ zVX?z=tmian-r8-0P9ijhSpu0|j92`Kl;$8tL|5)9B+K%KAQ1`wT}}SR!8!tSO2w_T zz;}csbO)X^a0xR*6b-H@&S*jL%cgmq82@dS zKPAM!y!Wq6cuB|AZUiza#KJ1U=Sp-e={b z%zx`g91!7nM>CO5UeGGFF7mrC71Qs3X#QVH`QPRI5t3QJw9g?a8asAl(1% z_qV$1FQZ|r82|x&eI*j{KK$&`Drp{IgqSZne^<(kvU%@AP9@HgnF%~i@cbrb_#3xQ zVqD{WF{;U-((oV;&;w0U=yHgd{mD)q^MYZ%V|VBh#Z&w_cI@QA{sbmm>{XzduvRAIA^A9@_0h-gcfGm%=s{ zHxvhz_S-DW*isK-Jk5JgT&#N0`J5%?~0kL)@JT3wcT~)DyZjH5kfIv#pWZp zBjWOVZsr=2UAc1-Mq0&Uq-f=yldh9|8aUIom`g_AnL*S}urE?<7uT4C3CNFVN^R|3 zZ?WL$qrU>rz@mN^f2B|C*fr*_$v>+41XBQGHY&~{MQ+<)c@4vR-Iff;n`%sRi$+i< zq@xSE-hx{pi?#U=|NYfJtd z*QW7uW!biVgtFBx`SsQf)H)JuHYDUuPLJdwUyU2-23P~B2;f}#n3p|yXly{W$V1zj z4X3md_$VI<8J8V@H&RWddTdA~@7wUcX{Z5Z;&S~?Q}*rfbyMzF04-j3dquTx&mK2J za{l|3chGkctM|uMKj=c7{s_m@zNd;)ITLVWoCH%*b+s85oz$ODz9-I6b7^-0po!nPQXwWQW=hHxA5 zR@<_V@wfIc9-`l%gwBK4JlCU^hn+M~LR>DQt}^h&zn5}iZ4#WoHg=gFT0(;RQlH?m z87N(2*BMSYkCA8d)*R5ciBW1+=WrUOK}>Fg(Y&vs?~qZ z`fvKiqPe#6;OoCq4x^XhpWxfH(q{Sv43iXL!)rvoOEk-nho>%s0MM%CAlM5wk(W)p zU6p-1^H5pqz22~ne39{p+x9kn6Avl^8_BruQp=l0^;leqK@mWq5Ihyia7}yZI(WbR zV*bV74sG{jyO@H6e;TtY1kkszf36UJVFA#8>`SLrI8Ttpv%|Bofcv1C6Op!!-^CGeToWB@XT zIp*O4Uw#Fa9jLHXDoTxFh22_$&=Yg1)EAN*AZb;9xqNr~@vc_pbrY?7{s|oFZ}aL{ zP7&FN$GIy{noB+Yh-~{v?Qil5Ldd1NI@fwjziwFwW$gqN)b2x?p9$BOE4AHS(vLYU zw1_(6kW8inkAvN!V9yE`VB`;XoC~oFf#p&T4+qty`pBk?s$FCwP^%4xwhyl* ztSNLr80z&%NG*`?D)x3U}Blc%kptiv)nR)_5hP$LGRV)<3F{hP`L@ zkTxO$i>O6$7FaRU_S4wWDrOr97>kAmn*r0Pte!M1grK{)bR;}61}S4O<$}O$TUD#--=fpV-l>q&&R&?D_ly2nqLIU}B!b0`bUB^Lt*Nj(DUb`l7-<2cMWI9PDWHM7@;2`hEPjq1os^95))3$Is3==&l2Ren?CM_F7EBFDH zF+6J3A^B0t91~EBEtlbAfNTwwi@%-)Z{fn4*ryA18(nhYXZD}~z165=u|^gX;s(lg z3_V8$Jy@nJb;3`yu$gj)_;~oKC(TS`?1(j}3Z4hm;#~jz?b)jXg>`MQ%{O!w#hyTv=DT zx!<+t#)`%P11Zrys>OcCKOpS88S~uUetNKABWgq6W3x~N71`{iN!$kJ3%{Y`Qlf{ehGvN1)+*nC@2{GZo7(4v{FC|EFn7aT6ke|I$abYvJ75( zIAg?NoHzExnBh)n>@;P(ewudCfb1$8a)&!dU3KrLyd=$6sK4qw5?q*j0W{KfELNp# z^WN}J`F88?15}Cd8EEI;V^<+OZ{d-`K{VAY_|Huum&aGLkjSVI!-PO?53~V>u=pu? z1y|XDA0CgxlZ7DVm0UNN1xP>o#m(ifB$y%{99r{+f)U}+LQ>mw&zK*JyHr(KM)mSD zHkHDk?7ZLhca?+Bj!?b|Z>tO9b{bp_ip}>Atr`(+p@D^30x_7!45motx?qs184+CzVJOiWB9FHD!<`iPf-|J}4ui+8C!4vk8 z8LB|f3y_G4?MI%vA;O2>SrzahM>ZK}i#HC2V&smM}QnHdh^qd{SPG}3r%wNCNuT49L%r!H-`Z`;o+X5ZR-7|;_Bl`xLcfaxM zzs6s?J$pWaO;m_X9%um*5j;|BrU;NT60#oUZLI3VOy>NApYFB!^BwOk#Afyc|8#D& ze=~GjTLfhiOf8#WuL^$}gFGO;ahvf|*$8ELxWX2p2aC|~ewd4}{W|<9RKFqZdv!)Q zZDw4}AZBtRUmPgnyQ&`4*KRFjQ%MX9ex#GRnbNGe=;e^Mh<~Api^UmeMDFMh1k_-s z1`|)eW5Uwm?|oWFeU$GxL;hK~=~t0<;X}b|_BaBVQ8nZB9ds&;*4*xbn!1sk{x*6~ zjp&U|@{ywkW~}&`rs*5bob01i)utUojRR7A(S{Xis5w~bmGw0&F8DO2zyCT0h&`8X2U)Z+BkN^+hZ>mR{>$r*!Oj}tYv!F3%BKj za05QHk9R{Y z!e!$O&__^P=B9C}i^a{C$T9I*Zz)7^i&E)t8Z-}K1CDrU@|afFCdYKxrhHg_2d3!B z6+1AN!dEL8mKbHi2?Ol_ozj;ieQ!_@wuQg9+P&9QE774!jkU1!o_l31j`;a=m=z=& z_#g>F#(s{^+$Y`z0${F5)Iz<~DM9 z5c358Y1m5@xM5eIbB+l=Yq&W?bbwQd6GI0B?_(%<;)&uLs{d+U;YNgr3aoZPt{HAN zPtr+PrmregQ*&;dB0BVXs%nIlHO3k8yhh*Zs5)lI)_#RYLmI2xZAGBXn5t*8TtPOC z0n-_ayOQ)Vsp*9|_DV^kPYzIfT`|P-;E5I?vzCC{{0}M&BVnXxnGHGT0uiA&l7p1yeX4_NY;02 z1ok~AiNcQ)Q|ZE1=K6n<8Ze=hf4o67oyOQ<8PQL+Y(<=5ayYR_Z0OLR4JWXQ$j!Uv zWh1WmdyMn(zg?8)j^6UnDY09-s;C>{y~{CiF~YT~q9 ztEF5{2J?5+UET7uX#0EO0szI;0_2i^z=w-{wpgpd%E1ra43_rF%b?f-LM} zjw#W}$6LbA5o&LMSX3wVF_eDqe_1^CU%z%lj(EDpCz09`soBUDLyDW_1bR*$>ZS}t zo(zL>UrN_RnbPC3^oQi--PV*h3$3b@xz**IZ#I6U9LkW&4spiWIrJ~^!Q;1 zUYX>vHlA3r<-3h&Teeimvzh;8r|CORh!!cZl<&4<=nQ`=yl)JIh=}h1n^_3p+&bFr zkPhW1;hlx{QCLt6u~pwSBkQv7i5V0Y-S;bRpj=P7PWAd$8AZSDmwvY;7_f(TGk4C? z26&&Db5(rxpLh{c6%Xc>D-kry%aIqe8(!pZZ}^c5(q@vHsA7FvzIW<+TC$_1_ysYp z1)TI##@;sQA_XHQ!-QTh!b^C!0W#n)nqgj@)8j|oZGlRzEc*OdxZ`@XTm5mIA%w@4KCO zU;;02BJSc_fk21_{3gg5X^U4nAm{}`ijC@P`sw6!>NFG)-$9ekasAOlGRp<(VeL{> z;jIFgl4Mv*T~a-}iadk+#T$R9GY|SA$)um>Bu2TGqA^U_G1eR<5(^9J`-jg_xZPJS zZ7&yPf@5%*uxqr1h8-zZm>?lX{E%j$>*wpZ3$be1Dy=5q$-}YU>>YfL-!hd$95|@q z2SS9ukI7%FQs27bEJEbl++OuH7wJdQ0UtPUxH`+6RRgkuhA>JV=+ z&D_<*9}7tj+OG1m;{gkB_GM?D0L?FEF9;fsg9POhY&omt^df+t!pn0^W?pT~-q zrUnMF2Wd!e!0qr0LrGC1?769pWpsS1ae|}d@d7r=yNB{PH{KTkYHrx)w!5k+W_)rn zu2`iIZm**j`_?a;dI;>`m=+oX5#}M? zvD<1DyK~noqjQ~=d_B3L?SGa^A7lisC?CTyfgfB1r3&u3aC`@+&j%Cjq-ZoU=_sH{Abe0$v4B! zYw1#7T-Wdo03D2No2uphh^8I#sJ*Ph{F3o8e(@&#gqVcS=-C!O0ID_g5wS`M7+xFL z@yld#&?!&7hYiPA0Ymcls8x_mWhEx|bn$4-s?9m`k9cu#VMo60`F7aER%`f^9aZk3 z03nD<{}wvD3Ve|%lHQTDRAlzOPS0An6wS$WrJRB$hAQTFlpQtu*7p!)G?nCyA5UAu z>qonV#Un*YtvlCQ+();qo1O}Y(B(k%NR=qm>MnGU7=+i_?@g#E2h8azy#9k*GHoL! z@Np)*@TJ+=U=>bB4e?}GIb zgu1qc8rxC(1$e>ltD53^sQEIUS?CR?Ntg;wlv^yh?~u3E)2456xdyxQ51duDG~y}H z6iSToIF<=mRNxq6DC!yObzrC0@0+j33f9TXVeWjkT~*d4+yr zVfM6vxka5Wf8-t-{)1-y$K&pBd3$Z%-D!4)r(F6B=7M~3bTC{HzA1}Y8k;RBcR3N< zu3TpSC0`x2tCkmhFGv`i^#$6=lQ(wD#;N*L z`~s-5O2*(S?g{yjehqKsJ7Du|_({UU1$4L`H8R*!XtQ@ilKCG{6`&Z$8(Ko*HZL*e z!0^p@s=NdJIj4ojq4cY-yNL%D%>gVocwF5S%4>EF5RtD_`Tl0?c~=u-!ngU$clj)+ zWD8q%vQx~7Fk#C@K%+b)%x1XqX1Ff)63&(>BW*`hR6)OYP>sMzBrlA|U1!QCaa^H& zYf|v#*PzVyua0IN&$nzcQtAktoibqiaqJ`*IRkE{4jBigj!#3y(lh>1;JSA)NNId) zi^MzmrxBQy+M&v=1!Y#_dc#W>*{Toc#n@3KlD$r%=qLL3J1?sx`t+IHN#=j-0`s2&Oa!hoG+|vGf z{XdXU)eHCjM7vDG4-jX%1nX#&6PTmDEx>rD|2{H(ls$u^pv+FWG!S>$6+xjId0Q;| ziY6IZl`cJ>EBw*Im|S4v;t=vV`c^-F({5Wg0DB+a3^QI9$Up$Tqqz^A+HTSzAN>bx9n&WN=~~zctDk z17W`Ga-iNbWC+Hiu2VC>W$9#egL>s?{)Zu9StkgIJfUnV9Z2vmrZ`UUFJ+sa>)}-F zj!vmIASF5PmV?`s_zi1#9h!rp4`DUrr(zKen!Q1$u|$KF296s+N;J9i^|k5A*N>4b zv;9`lc=#28K2ooTZwjwljDta+qJab{w^ZTW#){B(H1>{Pvnrr!7kYwXAs_@=uot+4Rcg#0x+cD(T>YV-ylU zwbbJTkT4c|9I=*YJaX=Qdf6}uzqn;%s`leeYNv7JL`M9iUOq9}-PB+W0Q(p0*JJmR zrso?KO)m9ETW8qwkpT{T%hv_B4Qao#XFt_`k2cfq`*opCrc@Jivr}C;fRPqSY*J`m|G*Ul-2vDkK*yL2b@6SHJ8b4@0o{UoY zrJa&;;y)E=6HjF(7Kc7_MgIP&X-^Y z2EuUdll%(K*E}>fs$$%g%l~!03hpc*ck`C3T#WKfjeUuX?6Kx+z$3qC5 z@O)GhF<<7P7$pG3<+jC`rUS4dtncJ2W@J+;%n#c>Eh_xz8 zuICAtg~nw`9ae?fu%FFjS(183%MZ~FiD$QS4d)R;+W4uG8k@$Ks!5ov{E>x~_oYSA zfxIYITw{u6w~#q21&$;Fdh{%f(!%1qhq6s@%;Dd(bZqjLM7D=Ru=aAMEgq(*Z5=_V zmqB?+ZgqaGKC}RQiqx%qB6YiB9a3Ipn+d(o8Q+5y&8X^qSs+4*rEdh9(7{zRmsCKm zTD7Wm40h%dM6pW4+Slh3q{6+Z<0DLw*fm-TH9in{i-Wt|A(~jYL+l$r%lAmZi^Z9O z$LH;vvsD#yQ57lkfMofzBM|W{yN?pOyHiqV&j4IX>zubAjB4Uri>REX-jdQGiSYV| ze0ACV=)0cTFW2t72%iT50Q@^B*V8fQBbp-%37P1~Ea^jYtI(708HROr3LjPD=&&Cc z0j+S_4$|S_>-PEA7&_|TlJ4=jk?k>d9+LX!HH4W1E$J@kOeY5U>2^M65YSzmxFG_y zW~ednSTZ(rrbKDQFxW&>ttLuw znjGxHJG}?iVhNDBbQZ zSkWe|!5((ZrFoRoQ>4<5SeSPX3e>{;o-OOb@Wu0i+xsxTW34khT9nyOnPvQ4kl5n% zE@d|FthT}(z@g5LZ9IvkOv#}yU#D)j+JdUb6!k3jnWW9Nnna#NTo>V2gr}P9_q)Ty zpT+wdI_*j7$FST}e+DpW52S-+?v{u3A=#VMp2A1RIm>DWFcF<&=E zfXZUE#DTm%h`^yZLlUn^Ei$rdYx#UW8}rnGi|Cr4J+4=5+?6EVnVM?g2CSnvuEJ-u zXs+H#asJ^v52y96cZA;Wt+!3#Tu?=!Nt0Lvq0h%T_wf^AUsgATxgmq4h+o{wP|N%Y zOf{4RrNS;^Osk3qF^Eo2aD^Ub0b=zSyZ~Ck+w2$8#z7ms;p%pb)Fpc%swWHay=$Dzs24vTMxw$wDdr-K@7U4lDml?f)_5{cn~ zt6hImSW5QFC{~twVhB=UiXa@t7E&C#P_w?9ms8ZZs@P41_c=r@ak zYIr5;{h(6i3@&AZ#e}BwMP%yVJJcXVHgez1QLT&C{-7&lqLGA)KCcr#L#wh(iLxA& z0%ywMqSWtM(-0C?jBAcV%BO}jj0nl#Fs zmJWOCu5UJ|-j->VDv~HaNIxG#^=6hX1of9moZwb&UH5>>AY?uWs=qR@!-Fm$ecE*2 z<`<+2oGnbtC%UCkDX^nkJqY@N9gpm0@IZVKCk?KT+b}0}yhQD_zm>T?TRH)^`~+_9 zU)V{PDCHe;TBI1acCaqrs2HTOP3@*to_q%x&=bnTo6HwfVqVevR+o9^s?$-eOeuQ;|BsDb&E~S1H%_(x;{Jr9+FLo%e*VhF({}K@0W+92q&yu|bEPDpDrp!5) z7`&Ij6Gb<)MWd+^N8Niy%P7Wc5)17o9=oBSVUTSwG_qE6v6JW8+*)la-m^(lj>Gvb z+=nyQbVnL55{3mQ!s2B-bLLa#KuBPrMNB?(QoDzM(S>wG$j(I%e2{k9%sN16cUo>t zm0Dq`5p}eN@#@>rAMyqpY%8+>QRaju&41wBL#Q=JNW9rr**%?s1lt`7_8dkJe0zbj zr@K-(a@ZPGH!$=Xb{sj{;8w6)Q!KzzGn2XcqUi<@s1}s>;ymF~?AYdEylAtW%lx@z z6|>gGw=-iG#W23)M^Ey@=-bevsp6J264dm&70PClo{a%u_y=XR4(jK~^hr$X-D_#D z`b9_x{k!!~GI>m(I0@(3TQ);B4l%jTg$*)G?Vv9|cMW0#Gf{#@9TX$|ySZs!4rZYjRHr%k%jRZm!L16*v2j++NR*mH9R`*L zefWsZTPj-qw}{|m^5-kmQ_fy4=u++BD?XU38p2n=;ip@{15{;Q{Cc#g))q-?-cO9O z*=P*gdsbwsx~7EVtWEFiSTi*arZEJTmx=m(2HsOFF)}asM9!)d0gk~fv66eXBx`hp z#k?rP*|UxC`nOJQcbU8&P$8SnR6~(c)1bTCRTo;f3R^AeICU<`X#DS1=#6htEFJ>m z?CteYlG?fT#~AW5!4CtFpi$=uOzaa}Q~{I3_0!Z$NJBUiibI!A!BYsgX}x&^|GZVFy?bIO;H{ z1s%4Le%N8CP_iZWwsM5)dTqW>CvoW%GLb#QNlM;}Cwi62Lw*=1vlNKQD@V=H)PcGb zd8rR5ZcH>ERc1Cl<_+E$IM%eXcf%|a!Cb$HlE$Gq@C`4vn4sz;Vc;VL}^V2Divg$IZjg#0X zs|je^AyvRe8$3f&X=*N_Xnv~_KXDx8;*0dJ^PiUq`Qe0KM?vtm-dHdbr!I zPmjZ&!q^4YCZyW-H1k10sH=<^KN@!WX!kT&Z4GV?XN;9Gr?^-3w0gVj}23) z(A9rZlsN;Q>MTTB7ZpVRI`hDrhEAs+Wo)h^bW;BN&R`Z2^sF;hL_Bcqx}{O4%P&=-K-aA_Qys6o9tt7JwO?fAd5^{}O{fKu zM)P&OB00qym@Na-a$j10YAM9i=W7dzUaYRNV{T@-8;j%hFE9Nh=XUBle6H!cKVgM$ znK7%X1vA8z9=l!oVMVkKru#b7Wdc+g z)FlkX_*EGj0}>Ep%X4s}KFk!NRaW{F2FC}-`DK?g?SGNBJ(5E<<1R>lRz`_7N(U=8 zD(4vA5GfV?*5yNHh`Y+nctDYOvSbn=v5(L`{@qZ zH3AOY4lXvL{~PMiKU4@Q+V%4b&t)TTpDw4OSN*$IQx*DAQA+g(YDXt8OY`DPJwS)j zs7Svel|y((`v;EjOMK(LA4dj6NOw=6kPvAXGLFWs#TvoBoLZ?W?*girAy8ha>A z579w@?{9V3`gd3J=QY@pt5N{*FW&DMJn!MsVfSEB%DdaO0hgy)>fA$vbl77L5NySa(;8Gvbue*?^#8o-dX?5+191kns+RujxXJXWWeF?9G~ZkD zWkHTNS{D^UB&MVp!oJb4nzn83|6u@4r-*R8^~i2u}D$BNJy5Be)2z zG5v}4k=;X0UE4?u6A(@_F!Z6g;UN2#ezpCG0a-*wlG#zWE39{Lib~gr1H*pPUbvAq z7bg&3JRuP(3XYfD{$s=}_uc+lrs8+QRn##04`ou!kVf7Iqe>N|Wec%A1IT<%A2+W; z))v~KvqkR$6hTG~4C9#Gry!G#6bs?2Vo;&Edc!JmjRl?ix!n3C5;g5Av~m`+7-jxW z?VKwD&tI9zb{Xd2GD>45K75;O{c}TOF9p(TyRC^V#r!gL&wGn4@QlBg&M1*vz@3S6 zio+tp=^7a~S!?2}*9I#?Z;9+wb7L<`!amRG)nuB$0u@Y+f9I@c4MKZ69G8F4wKYzt z89`mfXq5jsEMIVNl344{OeXqVOU1~H5?(ak$SqM^5T3_W0tOe}%9Xpg@Jk2U6*(yV z0G!sdN)@Nw>r0H5raZ!urQ8=-(L@BUIOT_o#Rd;;_e|?IXlKA?sY8jua+S9EnTl0e50XZRHRCGWSlzi;5K zl+5z7eatI&X0C?+Tb0x*7cb$YEYZaRcU8RtZ9NI*iz$)?2tu-Q?<>E39z51uk=|NK z@n&TL6z0@*!2Ludqlc=;G-R^ySa5xzD7UrAr!i@OTa3l;I!lgJ`rOROV$OLFdxPcI zKKP%1J=$S3Pj~iYyM#>~Iov1&Akr~c<;zOG z)A)>;D<=~pb#*v7MZLLQdmeX1V9n}w=Ag0giG+3DS!bRf6}#w^Ff8xYb<-!7aiz2$ zMh5XjVpjD?K;@7qxZ2okAVJxx5loZ^X{3+!_qAgdAk6uiAV!%zCwj>Ys%yYF-kSMH ztKuSw=%Q}zCSgx9^xJhhx$l<-FFWJ|M@Eoq+bGaAHrLX8livgu!(g5&aumm7fY^l4-Z4+&= zMM0-YU<RH=9TO998mQ3T2`|fOZ1y{T>9~VU0Tsm9)T&A4)Fw9K- zr=&Pc&Ujn$J2%i2GhD+OoLqdXaMKGizvBh07zH{L{YZW5-8>-_CjCc5IH~!wpIT2m zCARmT#n_Ci9`v2Ou^ttEsY&;dcJ1PYMcc=w!Yb63%^R!Rt*DQ29ks}3EJ#F0ASzn^ z(~>?f{YnfK%U#4^GhH395VkyB;y6R(;G$%!{Tfn#sWv7AbJetF1V6G`2R>90CLax#mPj1kLh-|NzB=3{JSAeB=|3f(q>2-&Cl;T2mH#W6PgSOv_HQo zIdh0u3$|SSApd$M{%Lf*&pVF#JUvc&uMx?Z<4K!|y<<6MOrlB^R}JRl!!WiC*Jzxv z!S4l?!P&N)dc}Df!8#cB4Nb|5)t)7CIJ;+f!CcJ%6Z2yGC36g|W=en5ND0|DCPfn4 z-)EdC)N+*#ycs5Mpq4~J+FVUX-_#J*UT~4t(nREu#)U^anvymjBp7`z=*;c{c2TaWX-ijfQaXVC&?gDCi7jF0vZhvk;AR@RHZV1DX4* zoavT8a~E8?*j)2#g5wN-O9O7bqzuZJNh|7@E`)gTZcyLI^^{MTxnEi^LdIYzJZt)e zGwNdBX}_i@kEkp!$=}*<)mnF%M#|=UlPS;pm&^DeC;clZ%*v#)<12&NT2WsLn?qqR zwHCGl>n~g6B!eG2z+Nr8_{?l3V2n5_`q2FTAj>1X2ND- zov;C|+H_XVlH_Q8k^V-v$3nNZzGzZvgejo7`#px=eTJ<%aovYyj__%AoovQZ&T}}o zv1*2B2bl4B3q}_+*~{U2b_|ans5qXgD_@APJ_Kzb#A%zM-CLx0Eu!FgO|+EC0`uF% zr}fvc5P8oM^~jIlKgZ&>68V)SyWdZGZoH=5yIBEoJJ!l5)(KkoNB9|!Bl)EhyunFU znPUqqw6{&zc1%cc_mE@-+PfP*CwyqR?sN7jJ^+cwFnhk)D|bYpy)Q)q2+$61Hf01@ zAEgDcOp#o8t1z7hXH_X7TVWQ?xm4(S9BpvU=>y6f< z03ZjvlH94Cd~MRm!UlEA=~Y?qQh23EX&$KsL>97ILxwd7s33NhPpX?-e#D#%a4IWeASATG z;2L|Ehdx)$?|FnYgt5-(BlJE~wU*?! zg1i1Y97g3+8qk!``3?uROhQh$hgv(BD@LFhW)dK@vJ4@T?Oty6uh*jec-73cb|Q86 z1SA*)E}kjc7Y$;RTFhLvHU~wl;ulq_MQBY1MX|;KyVG#5>nwl7E^b9u+>79wl zJYxOHzy|i8#ywvHL4}wuGiZ?^#kk_SQrcfHfw?Dd%4E3@Lo|(`F`9ibF|FZtJxlSB ze14H7CT;AjC|OPS`+&_@?kY+^89)}{59J+9Ixx>>8JNFmNMj6wp+xvSaD6U(@3qj` zxm7~|zHL^0;z?-|KpVH&xcx@o+6LF!s;2b=?0er5aOerDPk+WzMpkME4j?M;^gD+;i>YA=DYP9>tw;vyFzK__95qVS16Xd6tTKbd>heXLyIT~AXSO1q zeZ(kdAq{Iw8try?q25OUIbfW+g413S3Ab*)1s zv?lh6pauHt42Uy1F!tAS>!}x(Z!ImH| zdhH97f+dWvylbBfPJ$U5c0CTM@pjK2F4$L6e1Jw07g8}@-~_()u?|i3jm4V=ACvh6 z|7<|dW}n(433L>qP#$kHNq1EPtt1 zTqQFv1o17(p#s3dm^Rbwn0NI{B~X?K>(_%O^b6_y0LmdAuV70n+SG1UQiJHJWT`f{F*bxp*iXe2)kYqjbYSOBxE-&pO#Cw*5hu{2 zl4DA7nYn1Ku3Ut)&l!1b{5SBC70g6lE6^74A&nvDU@*m`E9Kw%OqH=6(=0$HNI0$f zZ`hV}0rr<-FxMt_E91St+TQvYA%e!v$ZkRGyOC zOR2l5!ya$r@*%s;AuSBzJkV+JReUyvy}b|8P;#FgmPdwi;^R|5LN7J;GRboN?V=T^ zYC|vF_KaVeNCf|Buq0_fp*oqaz%kel2n)%%X`rXHz1Yg|KR=*rLJ(9tug>$9B zxBX6Iagced@o+iKHi*Bvs);$td-Bt_Rk>s%>`EOF07vr4}?erpUvjjnl6AO$IDIR@RoEK_}0cfJPPXI`v zJaG?%PDk~7D0i{3?bXz3E(cg6U0^uZ6hzEnvQj#>^!gYxeU$)0OG#0e4b(iw04|^89Cef}@27G))nkttht5U%xENtLcV1t{rDka$orp@}$B--0` zxq@-X#t_D)rE;IP%z+bIFwS-z6bw#L;32e^Utz*05Qh~s)GC93x+JWLqwxJWxsHf~ zo9*V6V9)8!VC|;}{J3gu0(v1hEaAM&oDOg|;B-w9XroOq*~^kl=_->6bNuN?i}$+h z-b}_xEJfeinHD#p4!hp`=Yy{T@T-f+bzs8NS)^$V#f*EMQ^9ZcL{CiTALZS6g{Guf zQzCMKEGz9i3jr^LDK%Y_v$^;)#gW2vay?)yeQ*Zt^bDxSoJ5Lu$vFYOzUZlG-&x`+ zTGz8GyFJ3Z6(-d{j0B-KTcBU)*ly##=XURg;)2c`!;qTncod@PMRx@snNXy9Kw5mX z%*bH5N&3wN!=t5LO?&lAylnqhr_z~U1CPR?MSY8Zz2i73aUPmZ4IeHzdgwJIyQUEmw z=5VQ;kB2%~gg!{lQxs@JNBA@WFWwU6IJ#{+2chyr^M0QIQl-H_(zdnfkra$`R8t(*IDvG?Ls=aALSg+XyPrpDl>Zn1OmLwT z1S5rSE)dqX2g?8gno^13&|!X zibZkkn#l+iN?6m+5HFZ6R{4ENzxNSwVV86sYg5h$jn_Ku%cMu+s=$1kjo#QseUvDJ zjw2_u!U*KWctTT`+IB*|=WN7*^jX(%H}(msoCj}Ie#Gr{g@b!w?N=kP@-+4t(W?k% zKb{%r>d;tlJR4Ke$E$BMTy^bEz~;Oa{DxVNZ2OuZX|R8>&)FODu{o&*0dLXd{-jL< zi=^zl-SeQROLIcbmDAc$G#MlDAAW7hW8O`4F%0gql<~nMX((0ot<)!JLeUq*Xhw4% zak+P&>peIQgv!(h@L zWb0FbAShRSrz7Z7w|6%vQ?a^JQ1p;_f5w&rp0_H7ekGJNm4Bc=^kK7_#ZYj*e4zkJdmfF)Ii5%XX5rw>LpIK$@p{An2WCSJ z#$w1nxCsfIr{sL-$lSlO4;6|jx?mF@3_rF#fUdxIW;-YkH;R3~4OV2RS!ZX&DhQ|m zBvz5=T@aoZUX6tnm+n9zf&5!_WFo8xG}~RVRduH3qu~x<{leL%cAk84!tqnx(_D=3 zvp+a!=Ir@+zX%S>j2zhJ%sj@T)TS_>5zGZU>+II;b>cP*(s2Mgqf4Y{fpJ;S_M@=LC9L;cOJ-$O7Nj-woY23jN<|R@NG@#h0kp2g!d5 zA;lmh<0qh3W~tRDIzm^;34+41_T2dzVwHxPadEs1l!!rYx8 zTYOEW04wQEk=o{!$g=kd?^JPr51`Ux{2~13Jv;dHRtTD*%4p5lEc0)#m5xgBTTVhh z!5q2qICO6!ZFDewvH2K1s+uZq`GE~LJ+)jqg})5|^t)@NHq5_g;TRc#i4tTx@VPJS zT3M2Ct!kj*T%Z0edj2v%#5EThDa5bYCiVkO5a7*wEeoIV&9p|*EHPEp4nx8S0l)c+ zODI-A?k!JI^JcW@PWQ~_! zLb4Pmx`%7#^{StpIxiKr*~x@*DL#ia;gH$GOoag{sSS8y3{cz6{q39r z64eY(%ie&>Q@whb|65UkyP3A_$?58>*hQyP1E zmiyjqeFJVuOV~K5%|svH#r^bNf5+ea&#Or*bH^%QYJl}@;a!iQKfv}gm_6$ z*D6#k4GV@pLx0JfZqVOC$1cv^O$;=(QmF3=7QBr|r+-Okk(Nmz8bR~c$NcUI?lw0+ zUyd^>noHica@BHgT%w|&mx!|DX8+OH3F4f9Ep0B-;;TeBs?Nfn6AS@R`l*r$`XNMbAuvqVvLl6~B8Fo3@HYQj0fKd2imD@vXrejxr+?Egv$o&J|fFMz*{qa0`5qHN_mB&g%BC){c%s)eOi76#LtU&AHzR0 z-wm0wM0-E0JBT+ycUWT*b2OKfZ0&v0Xd#qqLFbAvM*%Uj3m1ZGZy5(t{gysA1)bSQ#H^9Q~8LSR@?ZxUzLQ&I}&^!|irYmG(>}U%kptGvTe3Y&r z!&Lwo7%!?`BosQJ;4F_YiFi*eP^2q|=m0(>m&Ak3)FL5>FX&~sSft+dfsM1b@$e6BV$< z{Zghv?qbbip3cVJ5%}vzkj`dzouB99qcV$Q3_*eg1JO0cS9ZpT z9I}gD&V)Y4(gshOIAo;pAC`1EAW=5>3oNGVIhTm!JgFPKkz_6C0ASSm9xzkmCY%GZGsvpAC8%ROXy%=4!6@rTrW&X9gQ_NLpA&4+gp>ptlqk)#& zGvd)sp4gdT5;4CX*APm=*Pt=lzeddrMs$}DQhV1#c{zaJ-}|E38h^w0^e^H74g&w) zEj$4=rVjY`y|So{xvdPz9qn*80AGVhI?e{_kri7A<3f$=cf)dFRrFm!M;xH&7~>{X z2!&Q_P94HCQskx*&5UnbKpMpaG!zz=()0?ewwPPUd5YO@+1NZmeb8lc=spaI7h@9=Ofk@^2W0$vTd^=8gg`t_+S&w8_Yi4@G>36na% z9_{nIFR;`Zh#wzO(nWW6WjMXGK2qNy%WmK%?-?g$_m@bZqz;yeMC7c%2iRhJA)m;= zz$P`d&A*x6h3@R5H$ocs-EopHA{x@hO~;yZRZP-IY2!dhk)O@wscF6W|CK}$wmexy zk2DXBRMuJeZ??>YZ1_jLV4RoAZP^#5K$WFQM{fD5I@a3|QGfxAcah39y;_t}JZ^q6 zDA$I*S@lkT=N6%k&_PI%3A>v-tiQVOR&8nJp}oJN&Ol551*w9s^_zo7JwiZJ;rI$D zYF>*5_jQB8HjYJ#_j`i^kajR*CGTTE4sDqkb15Z;rYF+mk zis8CXlQYKDd+x+1w5+FF&~7~$VSTE**OW(ZnSo3j@KH^iafKc&^g%dxGbeHMKaa6O zfRsq-xjPZT8@e7g+cCPv@~GX>>WfElJU~{zmgnXY1X(g*Kx2JJ$H+C2YD(EXx^|Nw z$Wyc&xm3_SswY{fm4XoTH?OG=LU#m^tAyFX$vwLi-}q9Q(=G(GAJ%SjEv2_&2u zw9@2U!_$<{w2MhNCmP5qi?*~GXfOSRA78n^x44^iM{kPufV1rVU)OSwi7H<6f8!|0 zblo4}u=`DStGh&(5A4VynImDyqB(}}(=t*vM~Y0c)VF^KFea5$9rfiA+7O=suW>w1 z55Rtz6v4YE)2GF$3k?Bqau69MI3n|dvh_i|OnOH_lI0a^Wb8oP7Kkr^m+T{Uy2zTv zxz0FLIz{sh%HiOe5TNK5e+UP#6~8Op{-MHZt~im?53kvyzdBm4>N=Hq<-o%yLS)>| zmIkiSwbx9>hIo8|P&5L4iJJ83pz@?4zHJvOC27Mfz577qzJOR3b)M|1F%WtVQsQGD z;gX@oeVelczyJy~00IGU5}U!KSP(FK9uSwKlQ$tsJM-ZuLdYMiUyhu`=jXA3Gwv&W zC>TBF7NKcQstcduR$_qxL)|hHf2dE9E{rFo8Cq?SJ<`2N4Xw6aMRN$EbLfT&Eab#z zK{hCvK*I+u>#Dj#bQR927qi90B2TkZefqQdB~K{mvfU&1FE~g{gtWfJ$~>}Tn2F-} zGWL>X7>1FoKIw(ggRJ+y_Wo~1Q!M(t_u}6iq9}Db4~Y}dz^)^iw@dt21Cl zlU_x~GJLZ@>LHzQ19#L79e$mB6oA=KO35XUYoHlxdx8`~gM?K21WHdDf+LUdO1#qy zuN6LMH^_X0nclZ+iCaPv!p#CLM4al&mLS0Kg+^DYxad1L8}*bhWKD|oGu44BmcV6+ zGyJOyG&{IV&<-!N%p%8(52KN;DK9&un6y5eWI9AYBa8w1njvrA=ZH*E+}S}%T!+T_ zjBpFiXtFQ}{|N461P*uS!cK*d3gDNEcK`rh0QEd7&!hwB4A6FxRZXI* z{%)IeQ*i@bff+XGq>yzNCeAKgVkJ)4S-mjfkGau^YFrzsU3Y_mdg<6K&*@|VIT>Qd zHHEW)YJ443>MH3u{VG!K9Vd#&u#p@godN@nuTxWVkr2Vdjrz2&=;4XT|EM-MAm2$5Vx258dwI2}`Z8D5yH zC@i}))7=<6fc7#H;-og20GjiwT@lkqPb{mPJ;*Op2rvL~B@J)!hN0m@=`+PQ7G#9V zYov{F;4>m!PH2I9J-U>POij>_bHu2$|LQIpSf8gPDOf_bB3_#sl`JjmHERWrPi3Et z77fqWvu9dS7 zJ*@~PahKUch{ZuE_v6Mszvz+TM!*71dX0@{N)P%&5j5(mh0x5G&)ST!cme zpt4@gc$6MBf__03RhM}rs^@njhmUMrKF9IPrzc^&!3*AoXMILEO|#9O+RGLddNgak zM&;Fn*K5{_YAt2r-^$ykd8w-Si9jbTaGYtC^qd~C3G5$nss43-o)V0i<$$!{`0JW` zT6+p{Qi`Ywz?0nP(bjmM$MFpPFsGJL5qs4*2RT(~>Ygoh-eyCi*MI}`?Rhzv-1z#| z2Ey`y{wpyy8Y$^CCnP@`RS1LHBO!(m{OA{m`gq}o>odAwH{4?#wO_{?lSYGryA;{#a$CHyd+sYcP;BZ0 zmT(aibSWLRXvqtXG;;KSW;zyBqXC$*oYi{Sj+>##iEd5ar4$9QnL*CdiL-L_wjkIG zL4wB>Wq{9qFA1zICZP=X#-}y7NK>t4e$ZrJRo$}wt(`N~$g97>I3%EAT&MP{ru-A* zg2c_#ZdopJg~x(GpM~9W-(`t}D`{%&6?L;MpW|ERLOt3=$b=BfU?X`4Ej+PO+&ka= zd!Rb1RR*ZtYIK2(`@F?8EHHD@sP%;qF#5ta)4>isxDWz~!PL;>h!{)s4X>>Awr7m+ zj|~SN{w59dT^(-zlsR!Lh^`_;anSXB-6pGzUdp~y{@pYV0F*GXyOxm3mucNMsW1_i zWE>q*t~a=O+?3U`jGfTQ2aVW{c~NPqO_I`MQ(X{GYylthZi9#$R+eKRun02{YTaGX ziP~*7Giq$9iMQ%g7TKWbsL-XjL@yq*mLs6db?nAc0}&HHfb2^Iqp@qZMhx`hCG$W2 zXuPB;B*qgbR0M(%Tu?jCFxX^U7 z?%aY&kG*-F2Ky2Oupr5xps#{%awv~sq2-=mpzyhqE6~P}v~U~b53KH=6s?qWq_nLbQrFmjX~bl*!CJ7OssBHEv?XG| z>X`prl6;iLEF3|+&|kq~qE&_SiY3RmJp(k=59(n;Y2LsxfH@*XqnQ{K zJgj3t}m4dmasH@lB|^v_XxTX8c_OGiC3pYJkN}lSB|M zkx9e^^%`PwXI|gJTAH?vj+Ebt$5;XulnO;m$H!8w@z3*KG%e7cxESAwTVknH^?=uQ zgI(@cAbe-RKTjbv#2?W-vv-LK8JKDAw7(U9DZXMgmlUe~!)*dt;~4Dv%h*pQ=NsnF zGw52q#|+i+ga^a=N~*!gImRKBM_m5K~kO&IB3Q0mzp|Qs1TS1FLy0kzryNqo5d*H4at=@U-wL!0}>;o3|C!Fa+ z>Y!o}@R#AFoojBGz4_FcaePSOMr81%Y<|%0io6b!=HxZ8Um}x?T#*ieCDM^IeT38w zN@A^AyBR`N|DGo$5@T^}=Igx83JPxbr6hmdbEWKcyyr=;=D`qGzQi#`Hl<91?W~b5 z7TPzY`i{N$;+6pp@n_{o=|mH+goj~bKsY|7es17;D-?BR8$K^>qfm2CI4@vBKNTxN zbp^-vk}Q+2Oi@j|P08Rse?SP(j{9nGa9l1KVX}64^h<+zVLJ0iZl$%waYM4$x0xH4^jA*>ztFqYf6lMCv`M*4Zq{}QWmQ2D|u>FMtkRmC^KpyJFy*k zeT+=BQOmW|4F9BpndkVGy3nM4I!>*9UI`8?1@q@!h3Fus5p|!WQf|@ZEw>PT%7*&P z7$S8)68BQn^uVR5P}d%O5Tn*sSNyyscoZ+pSefo67(Bq3wfaWTk!k$8EALXUrONli z+V7645o&bh2@tgC6y&~*2tD>Rhby^x3mr!0J%g*>*(uV~b~OSW4wgS`XjYa@hoU`~ z3~IoP!%AFTL(a62Su!6tM3N~Q5{v&K6tDg;rv}~UHZ6hUcJDc{Xx;z*VU$-?)p3TWVnC z;fIbPTmB1KG_Eiyiqp&jX8q03=rr zYhfx#ykU%0czKIw|KrDa&+XA9pa9kCq&oX#KJtq23K?fzbQ@O-yqB$xt!@AlO!5J` z7g@vg-y$?wH#3j4a}?6Jb^#7e$y@`f84p<>H!?<@Ira!RK~K8}pN;^Uh^9AZya~Jj zXxF|)Z0-$$WYhq}dr+PR)bdAO8vp z+6-o)feX}{OF4)iV(uuZAaVZK4TOB0T$Zpd#bKkZu1SB&0fAeAS{^|Fu{}vd`u`<& zbE$;x+}I`vJcW%3_OyG9GxXekYoeX#eZzUwNGd7Wxp?2 zbAr?~fh2x|(Ho-E8Eol2Ni@84+SUz25E!%*4rgf%l=mOrALH)~a?FJ0NZ7R--?d{L zZDPo)=5Vr?r+neO^6HoyTMsJBHq3zuA#qAohWb4PSW&o#Pz!;V_u(-RWe-EMEQt$T zsy4R`U3?oMLm7vMUWNI~KBKA?la-id|Ac8}gr^L4-&|-d-xe#HR8$^wnpG8`7O>+# zz5s^R6(wrC>cb%)6ECl08RG=WmDx5t=8H3Ogl+@yR_#iuWjm0h42bTD#}$dc=;=ly zF=q_UgKzpTZ-_t}ocRhQ=X7AFx*s zsTKF6W};7c-zLan^XZ)C_|&R)0yWiYln0t8z|)>m_HKNRM?k`HeC|X}d1dz60@}KH zCO`I(%lp&oD`?2^oxv!qeZPdXD7wNQ;LwCr!^gygh4hsLh_2)pSPn*1<)$3*g)As3 z0+LlR4ucI~%reU=H%Vvi%Y89bwX=k+N0{s@ojY0cDaDEh77+(Z1v53GhxUgq!b`iAITZ~f5(tqB1%wu7xoyl34}F}vrZYw;*o>k!Oj&_NiHv`t&SVJ!-{ ziD`w}ng8_d9}_DsfjyrkoMiev#_-?)m~fbso=g(s3v>@q`-Ov&P(&XO-x|LDvAg{S zw4(}r*sE@|DE|Kq7{EJEZLiQVe!WYi(6S^OX7%P1J3dR_b%V7G^_fus1K2bM+*5eG z)ik&nnRz&29fN+%pZrLI-7c}7sq(9xBh!9>{@bAITeD*9(JMa3lk}m9?U+15A!@H5^yQ8dM(>8ddag)S6q2vtU8A98fQcw z{XWOAI2S_qL4F#sfDQ>m_ZNL0TyVF>EE>V+KfyBuZ-b_PNIIV7dia&q|p^BEv1e&_A-ySXomAs*@2u@r zk5!rDe5+i0u;y!#yU}$ubgtATkejsdceep{Na)hv`qO&v%Er;rUJfBHV;}F08bBhq z`#ZO~aC*;UvLXNd8g9N9OHTOwz|d?TUs@J@c(>OVFJe*(j5%^iL`Hw`h5^%)q1q!j zw`d@9&R1xENsR~wDHFGk;VgVX&EVp_6_hn|)a5ii(>rNePhi1Uo4hmY4+>*{NjU#1 zUuGXGuaso#`7|B>^F;Co?;;a)O2@j$Cb%DAcFE$Mdi*A3!22t8=*VB1gDZb4;$PHH zKIF&&stn}bZ$^jD%p`%7Wq%P56hj1Ic7*ZGb|6;~M$@J!HSujvQd~#3H45EVhMxPV z8Zw+~Sxup;U+`7ON#%`Z55@y=lt-Za@%26OAeXZU#>0aE@myr6GVAhd2z?E;QP`HW z*vE`1QK>MD+vhU}@Ba#E7>jbX6c>VlNz*;XUyl2gB;bxE;iurXUDYAtYJgYO%|yv? zQ_}i^!dXA}Jv?-+ru86d?MC_S$~itZGNj(vf~XC@7PUPL?z(b*!G3=Is?+(Y6o-c~ z7v6d^$|T9W!vT{&(vG%K+g z=T};NEb~w&J6a1THbA5-yUizpV6ro8VgkS!{6j3t9V?;>Bs_o@p5GTTdz4>rcP*Z! zG6g?=RQD^wyh{%25vkz|R;MaXBho=%)m zqdL7n>;g4`MHNyW08KMRwm9>eC}t_z?Bn0$piskX#hcT5j8^QKNxu+Bhv{bWi2$Qw z4UP$el{7&SK}TaTrp-v}N={sKRD|(_e8A> zI=2SOnCaYQ+tUdODtxih86)3gi`;Pc0VA3BA%bN<_DnUO37~iH6l`6`7cdew-d5cY zs>_PNt_FZA^G<`*1_<3K65Lba$(^$2ctrhgr>BQ36xTIlm&=4v-kn11h6h!B1yz|L z0H=#!jJgdO;k_d@pHLv4MwA`h)&Is!>(gzp^jVW74FrJW1n#hYq=H789R}xPdC(i2 z5P{yUq8^ctwlf3F#%YQ%Vo+^n<1BcIg<;*0cV7f zGRc*908;~e{Z6O5r!6wwfY98S7==gI(m$TAHz>K zD}gNK!PvMroxi677N6*MfjW$LC!F2J11FtVTmJr9l!LSu*)W~4kq5t_4LykKsH4x@ z>)hS`^SoV9JWWbjo*TCnc>onTi@QAJaEbY#$#>TY+d7_TE=JLln)4mme}A@L`k%Zw z_%z-^sR&DFE&4a4I=|O6=OyRnOg+n|xvc?Jfu~f((e03W>2i_nf_hr9G4+AZmz#!% z_tSlCv5Xii*T6A`hZ3%6^V}DCy5Ree-etmeLe8_1_OO-xr1Jl_TO($mazA5D6?Z!Q6_x*A zx{oVsPJ#PSN>PdKc^wRI1LR-LJAe!JEH%)CE26_43yjYm{6r8gbacRsQmzO+H$N8S zTMc7`q`j&$X>A9gzp=U%DxRw>z>RxWZSZtzjw@l>v?iUi<5c!|qn;wAHMKk-V5v&; zg$zmx@)Odp;0lLG&fb0v?naR^b}00xB(|9h&FA9Uo(KMc72wyag73&RZcWv$k8(0AS9;Uo;=O zBJvrq_qcHJ4gZte1TF#0pOs}r`jM6p$23|jWucW!BU2^Nn2vxjec$`>&-XqUaWsB* zc63n*5P@Tt(6UZepTKGxEyc$9Zh>@ekK;)>SgLn3QZ zT*|L$K1{ETLL*k4$<8n5vDjoH=Eh@VCefzhxJi!GKi1eUDTDkEuL|Degju7z{%4^AjcgL&@ku{d$l9FAA@~GH@p9b4VcWT zRMjdNossI5u8^z9r^Ynz^0N7R@#Iz@{3%G?zD1L&T5a-!C?kf*?-z(0Zdg~+Eh5hW z3+b^OeQGYu%&~6((tX~kPW8^3pzL#bhlvoAlJWmontzGHL^QKCcFiSCOtjK*8pQ}= z;zh{>53(DEKEF#EI{!SkVBpeu1ga+&TMgbh1}8y5p~v1oRsh_NM|QlnLNj#syKK#G z>3u7&qy!`qt-$oT8O(}yc-gm}uWfI#V`-&{_xZzYQ)Tb*9;l9K+eM)2*`+s(56R9G z)Mn6)x{1m|F=Cgv!Q9VaLTq6+KA#JU>Tb^ckgbfcqNc>9Zck8UJ)Zp@LG~(h5#<*v zhqg>sA{|ot7_Q~i^KM7*yw~%b&RhNQQjADpTWr?e|6>M0TqZEL|K+(e|5wb@a6MXk zhM2w*_GSaeQiy+z|LXxqX zBM>*(){(nkK`slgxS};A_(p)H_c#Q_r5>=;W{P49iO9U?5{hWEp{W00aq*?0LBO>S z;y&8Ztu%O-L5#R`fV`iH8&?oKg>$>mQ&f3;b`ny2gf`0Bxy)6dP7X2Z8Uv(n&JDNy zhnRSD2c(4I#|b2CXO58B*u|z4j)EL!z^77*k4o62N0aDx2Aj=?D^v=J?hUFC2@2^p z0YTD)l@EARdFT8uPOf!7JH$!CSCleIt3AOet70NeRjWdjoF!uyiR0+??Jf1SVif8! zAswmbR*=5?&?;J~-41WtU-*ekVezuoRaQy>QXTx?U19cJf1@ht=cMK<-yV^dhkK|B zdZSrdWpU5;Jjnyve3djx(`b%Tt#4d(Y||u($Z-1Q#z8}I6*j`ke2`=G#yl|oPXnqB z6I=6G14U-Bm$11pINXFweVm2HUs5Y%WAKkuFpG(Wk9--7GV=hyv6>1f379->ndoNz z1eW6^Bb9a>f+HpK_3)x9#>%opCwjxHeK;6QrH?HcDw9_D>=QNDh-Pcc?}jqwKpJ?Wy-e`^N&I!vqZy#&{tF@a`Ay9im~IZT$= z<3Oe?>!Cd6<1BcKv=E?uURG8!3@Av@DXqk!8`8Q=+bqlf`RYqEh_UW*OH||OqRjNv zAb!Vsf-|nY^l+^3Gp7u@kTNfw`5frZFIf4f1aEBr#^=$!pKywezCb14CMK?(9epXk zQtDxk_#WOy;J48~f>sn>MB8yzmcqW}F^bsp^0<9x(F#-$nwOMGGs9eXbs zUp_uwf9nlQJBm6j3KWsXj%?#lL4q8K@)mKiXFxiP>j|;Cf?7>;ph*pf6wEInFC%Z6 zZ`yCA^&+gk4ws7h8r1AmOVuSJsd_Gm-0Pw(^>40o!=ryZGdMVQf0e!jLSjnmfj80f)(Dbb)2fHh%9<$6QJrTO}$yn*1bVR+;!NL;s}@L&@7`pvpt(ta3i zXt?&Ha*t!DH@yH&2!+3O5ohC8^|CG|>d&2Qan2W%5(2C)EY)v5CN$@~1x6JDmG>Rd zSqk5uZaGF@GO0OYVr;b2-8sZ$S-Cy)o&EBEvtI-ab2`pLlkx)4Xz<7gnCIt=Iw3Al z+7x#Hwjn~=81`BnvUB^gvzbRVMjt(`h~%u1Z2Vf-i2f=$D`2AKRMP1IO|NNVnDDu! zcKX6^&C$b6A5m_0)Ul?pBsCP=bk(=QNrI7a(I7aD#;bO&&;i^5O=>Vg2bSx7Ib zxbrg>c_GbTO-rgzuOk27Q(_x7a{UtiTOPOcVCdZ@=JS0a5C3ma&?AN?3I!%$7B}tf zKFm6wrHRBby;;VxVyIb>;WHz*)Wa#l;Tc1Q8gBL`3epQ!t_rb7w15i}ZFXvJlk_Qe zEFI;s4Qx0~R?%Ro#drf!vloFlNq%nSpq1P6Y_s@WSO?%acHE%1huSG`f+W%26!<-1 zb9b!_0Kz#!H}<+P!#)Y*yt28o!Yqh^R(~S^xuw09I{?PL#9T3)?$)#;-G5)8{4A=H z{-%Kiep+9O9!NA;RM<;4B$qB_0CFi0B9n*mP#x?jz3^=Nb2B%skQhP}7vLLHu*Sk4 zGf2Zy{5`~Kg*AK*USxEcn`RO&WOlD%)XYoj74b&d0?oF-A-gO)X77k5zvtTfb)XAD z1UeOtt{gCKJe3UO^TZzXB}y{5vB)%&Xr2Fr={P9~?4ttC8!WZi`Yg%#jo6g$FT?w< z!y7$`L@L^5gs&Wy>`rfTwU8ixEF7@f9~H97>65?|XKQRxpANVAAP_>LHncL=8Ht{T z19~dUNyAdE9eWcd?)$gz&_tMsd~yg?v~nzCnR{@ATmBDai1H&0MTAevk_8MxFw$FS z0>*L~v(@6LDySz(2UggdshSDT9|)C?N}Xh$Xg)zJIQmy&;LV606LyXjy4HLoip9M_ z_42zGbV10CveK5`S^BnJR&#W2vbRPy;0?($g9I)b4db^V9iulyl*LZai9v&Xp)r@| zG(~?iqMknBIAuM%Md}N_O0bxH!VHrs*56mbvCn@8dA5WplscT|$%uha<}olvg-qhR zUseDET=l?qSwG`?3RuQVYx)I55wz{V|2Y#)xw{wSG0&{bLYBveOkjb{Kin}9HFtR~ z5w(g+P!l8>9_rgs;C4KqoT#32g@xU(99U+^oPv+_zU)DjtCBA$3LMVS-CQe@m%3K8 zCgntD1x5KRXeW~ve)Bm8Hx}24vtBxQFtS#W%1NQ1%E0hz4?_pCwb;dQ@6Fln*L1PW zeb$#%n1DYi>TF5WIBPbc#hAh3mrp#CsQ$r553JO|%*kscm=Od<|#eZQS=eYP$av|xu4G;^>%1`w0 za0Z|qPLQ18*tFW>Ia`U|WP3?9DKX4h@QR~EF$%9c8vs|4Zr$AtD6o)TtYKEa<=0iR z`4AGiWOJ7h0qjyPjMhcrKCd+(15l14na#Td80I%P9)i0wB}u~9q}8-+?#irxy1?u= z>QZv(b!2LCQx`e6=OKvog+Yv}QW+C4OXOg!$gq3)D%&-6Si!|&OoO#>u^hxU6+ctx zS07usz3&v%{Y22ev%d*qimt&>#Y`V&0XV_ZWX%Z~{Jc4oga5XLFo0qkM9~>JVi6DZ;zFp&) zt7o?%+U1~V?7>lod!33t9_eAf@P!PkY6!SJZhYvMmCd0e#&=6Qy7LMPMK)}*2}H}2 zZFHBAfg61ySoyCXOorMCvQj4EW``?Iz;;_FGJHkjKnmA#ET7hHof@f&(zp9CC3Z03GTHw_Uj%q@$GWv3gEesbK>eW{NJk7peRT8VY;tk{*Ab_hn*6nK5cfhD2VF`~x5E`lwTkR{AU z_tD~1S}5l%{^fX27BD+HxF)9Z4|VN|*KX`>zG;|BLDFzKbH=K3?90pobGy|2`-MfT zFKRX)1x7oFHMFyY!e2?j1cNV;eq>wuf5%%L zMVmAM`6`bsZku^YnPO;Iwzld;w+@Gcq)k#AdT!#UKE&S+)AX3D{jO~8HqUE^G+YTb zUI}%(*V)5XSQ*Lng-arJ`n!68^VWXc*+np01|{xn?xa*nss>pLi#A@7s}ALksqM#t z(!(mrPW4NZ+DJ*JTQTE#x&^<4)bLboM0uF&uY)d$w1QeR8lqL=$UJ#JBlSl7A?{JR zK={J;egS9{=DIGfB(;CimbqxW@te*~3AC{OWWcqoDPjaR`DMYFmKjqO2YE2s0|h8$ zN@o4rvnT=Y`L6{Mb4EwjGcU?e)3?8`bWFJeff4}T(Y4I-6J3c-g^JYSc^EITqOU?O#F8r5VCe7X$;Y$s5xTl`Rp_IW}RCOiVs$HezUw;Y)&zJehz<@gd#V1xBr0_RrCq2Opj@^85DsC;le$<6~% zzlzkj1;MA}kQ7%4rK&07{LFSAZSvpC2BOh_|2rHCOwmEuQg_Xi|I2)K5Cq$6oKT1p z1?U}K8&l_6{&Ca-(aQo5LMD9L&*q@y6+}H3S6J!CBZHcFJ1{1qTx^4pm-REW&ShC& z`=I*I@FP@j2&&)0$V58-h_<{#I_Jpb-4+@(J7R~oAJYjP7{(ra_nw2)iCB>+ejS7b z2>$9=dRtomyGWJ7j8Nc1&hL-uyD>N3Pd@OVNW}a+2-|y=n_CW`m90dTRqb!;Q?|dD z-u#@|2w+Eik{RB5m=LXQe#{FHp|5Dy+hJ2KI=*Zhw3-9I?06iXrJal1QpSRl?A-No zii>veuY!2_R8MCZ1kQzCxp>x;=N62Dv>Wp=-uD3D3EGa z5CRae4Y#$PXue!vAT77nb9wcfeT;=B%ri-39AZGF9;Rqe_DK4dAdiC}9*mn=_OdPxHfCYo*BWFJtCDl-{(ka%e@7z7U_sl}SL@SW+1GWrb18_V$gVLV zZL1$c?eSg$GE`S{0(gfVMpePg5af2E#%HyNou;$m`mO$3uK*Tr;1WE#`-@&nW$F`U z z)zFm@gO3%8L{fCwN5MeP$R?Bad5CLEq zg7v&j1QyM3U?h*_Eqz@fMgBc0BD9{U6o~A^NRgKTAuemgZg-%#_)Js-$+LDb2W(wB zJbowq9w54^SkxH}XCGv~f@23%JU=%t@b&d>Na2QXnqD^a%LiH{9x|p8O?#$9tH3TE zCZZbm+*G#lW4C5ACnL($#jF|vw)c1+1m&>G&5mV-O9?foS+@yQ&+blEBQH$9af^7( zblLD}m38ZnX1p0aZs4`xP*jv5;l8C;e;P?T*wdii@XZp&$_ci_IxW`Q7VY-6T8REh z{b!HxJYS7dpYpx=akTAl@js`gAFg6*zyv_LkFYww_f|&g>!VgY9{CV|O8fr*T`@C^E-JkAF!4y=?--7^LSP8Jb))W#51kJ`aITCf*c8tlU9*e1Y zS$Cg_GO-EKvsD~$Wa}3|=-ZCe<*2u6q>LP9u(1betxj}D|8isGqnX}ioB9W}Z$2)b zeY?rBzA(jj=Q|dHBTaPCU2<75H_}if>;LTB<@O>=!Y_;p&q|vol|foK$nKU z*tTsTfgjEO7u=YMR7__ot4it%aSEvO=^`SyYa)=8lpnfFJ8KDJQ@u zZd>^QRFZij4y~)OVEQRf=2i>MIhdc>^Yj({Sy!;sV~4xH;V9Tuo2T38vhCH zYrOoODNs}FD7pS@i$Hr{|0CXuerKjUZU!7&lRR-WY>B6L0kfEQ18KS$-qXZf=S!V~ z54^tWj0*8w6P2|NK?t}i-NDj?gtg8@CkWm>sS0@j&Cu`nxl&9x9 z8(udeNsjvL+?_MgtLk*XmsdI%)PcBxwyRX8zisnK$i@+3uNN7;M+4nf#3g<- z5Is_!H>eobV-FalIwbhr{L1XuL9ugWq-bB08)*dZ!AwMwzY`z zvJ9F-&ptux<6m^fC5)P?KfbYmo%F;J{WPnv$)x1g`U!snhy~eW81ybVm(ww~R>DUM znJX`gXC7}cF>W_9HIe#P`d<~7@r#$Wet?Bsd341no^Z9mf;9&6qBXWLQ&C7wXPJR! zFneH$u}U+&)8a+7=hv)iXxhDo7UbS{D6b`A2`7jR$0XW!KB{~_&|9TkiO0zwi9Q7* z5hE19@l1#89^d<$tdFBQr@P97Q#(KDC`t10c>|N%Fe{V=gh)GxEdpxOc&c(_ktpcg zYuu)y5s?t?_{>m&7Gwm4eRx%i*b;FO<7zcqTt;4fP`eC9$F-Gm-@6}lEb}SW*S-H~{nN1?Pdu0opOi}LF2I_T# z)wnQTRpQ2GmvKc{Vle&d)W`AWvJiQ}aw0Dhn<%Bmn&mUL&?R4B$!BYXY z=vpvKsutO61`E2BmWmCEL!Z)}zdYk~5Nr-sWWY@5u#_omNfej8P9FIjD~s`;Q;aQJ z$M!4b1Sz07DQ)+YMiKAlxnk04t>vX$sx4zU!`D4SqHg?3nosoA#{zVM#HG0U>YqXq zuMB`Gz`S!cvo%EBOrn$eSb<7qQU;e?#YIueH5UYztJR~! z_9|Q!xT`s`(rq#-i(IFNZ800Eup&yZUNvRz4)(!@01t-K3jnk*37;R`zEEc|mMeB^ zl8DoUeh`*b|9~fU*xgS?`|HB#Q;zspoLDA@^;!BQ@13Y2`2AJf zJt)FaU^0%-9;St^cK1t5=73>`HRZnv{9M+41HLl!!}e^EV=OgLmAUj9n)MLcAg^aW z3C(PH=_o8QmmGX3`%UNxE<62Tqr;IO@F=}|i8XMaFBbQsxbXUUOnwIfmLh+iX#usN z$P=7JtEHXg_B;#G|HEoR((yPY5P)6^Z>-?_s6^f+$A|A{n9pWfl zsC*akUCqWTIEedk2g0q>ex1^n$#Nmk)}Atu53|?CDMi`u3i-i*5Xc;R-d8{GTw_&@ zB96euuk(tmQB(KE$1U9E5_hzYOOEW%C4@q^;?j`nZb@V!cvZq?sYWXCP19ARXgq+B zVk7^;%RTY&S42#nm7pVm+K!BjZ$6CW=H#hs@A)IhO{<`I;~kq=JQXch*i|IpZUo_N zvL%$;>uN)IFhs@G6p$MV$3RJ82Z^oOxi2CZkEjVRT^mj%xuR+}Inf)b#pC|4to#F( z;31E;!z49qQLn=z=Zcy^+{;^XPeV`@Oou95PRE`Ng1@~pUcgT1@(@&+(uDg_AjC?q z^&Ln~kcx}kVNgWFeiOC8`DINuWr{qup_r(I)0gFH5*iwiTUTF{c-okxY}O;oK!p9} z8a0!mamY_pPTmiisIV_CIHeYO0_oQAa!n2dijk58l!cz9$tqKU)m{dRG9peJ$O<+L zzQd8e8nY_~T}-PR=ke2OAj(|8dj}FevO6j^g0^0JM+d&J2juQb4yVCfhpx8F2zvg^ zwvhHS-h=(G{lYE{+GA+NGeMHAyZn%}vyWM@gJkDL+aEoT@hu4Xl>2PVohG<)cf>V_ zVQ1cr54Q8PX@r|DPKKS(8!nk73PCH+eN+&U6x;Z{am{FX2fVJbd1x#LLiGpa!{dxQd{Y*Sgmy|0T^he_{Oj?Fm>ji;8pT+DNE>84x4Pp^~ z{)f3Msv;xU7hL`-k0tv|gs=v=srU;hP&JPU>vVb`-#=`e8wNtAB6)g(%?Dg31hN*{ zqasR`<$b5EJ^qOA`K|H3WEewqBBnj~#^EkFKzXa25(PfL2ani%ZZiO*R@J2Y55GxS7bvTSx>iQ>Oa`G$$XH&ENTAFipK!JBYV8Bk5@HNbkzDA z#JNmT;$MFq>EWxvRwOb+nP*d)kX^*l089|YxO;S1%uSC{@@5MSz}sfhr0Ub`d*|op z;ZU+vjMO>P71Q|x1Z_Yi9i|oIb#HJG!zzdyF!`O8=N9KHV$^`cV^<<$oJs;VPW;V; zciSj^_d27Z2vb5X9;-9}tw%cWk^5&423HK*-;$A(O)>fVL=w=Zi z)EM_yeG``h@spF0MW}5g%W4jV_x96%3{!(#yBlReyI||Vn`lUY(SGw(FStAaB$fK) zFG`e>j`9V9eXf56N?#0vlbmWT*IXz(%< zmS~Hf{Z7_#J>=2nrhR;VLf7X65D#qE?Rre^sElhKS%Dt_dqLiR1vYqQS}z3plENkW z(Hk0^MN;}Wfv-INi~>NKwn5=7Q{<#xvi2;ECB->RUg^&z5leG=8dWh`d){w@?$ zm5PDN%#NPq1EK0tNHWjw8pX&E@rjE?8~8on)Y@xBxjyd>B>qY#8;8bxf#(KggavX0 zMz22x)>w-GarxqmG$|m`FH}y7U>14qs3AZqhG3_CGgqy_0GYnF*k-RPpsi7;(19S2 z3G*wI{kCV6+3T>=F%K*u$jCVs&Orj6r!7iuz3EcjV(uH{$k81a9Qm*^O zBq>zwaT%tP*-H@?DaBE-@GpJI>XxC8ZLrBHxZqbcaeGuu$@&x-faO(1PnN35QCh4A zQ?p?DlGCKE<^1WcpF-WrAd~kkFd1C*r%ok;k}J&NiqIw|RB}=vC(M)4tjBQ^3~PIs z;HJ=b;WP=xUMb7erKh^jY?V2B&cm65>u;|42mM-ddjF!-!}rGdcgx@zCN14|TmCtu zo*(lug7payF%kYg{rU!<1K4J}S_Ce&o7B6rC=unEys52J=38s=I-Od_P{n>~?_`K? zj_S-N+2Vwn>{_%GjQ%o&pP7#X{GoN6NvOJH_yOZmW!a^SeB|XSX(k0zcrYQazcx)z zEOwLWk)^z>*xV4A^e}K9i#aq*# zQ?}(aA<*y{uGNzg2cf30q@L(HOa3N}woMHejrOt2#V~CsBM(lgYuA5EqF=kBMjGGL z69c#G*SKJB>e##eLg>HU;*}vi+8$y`ohz28MujA*(Q5tCx{!+~`BjQO`Dy+CX_QYS z6P~@HJ&kR}y$un<1wsSK2)=5{ZVA4sIH_Qr9V!VisLlV7=VX_$j&|S=X9e(dW)5f; zC(NEaTCs+m-YawZe4(PGb`s4dcOyG|go5v+OytN8onGcWsKb2EdVXl;+mf2cX( zRkgC}Aqy9PCBFn|e*%u=Ps!d12fCPkiEafR%{75j{jt!OG7p#9^aMExbK}vnTH!X> zcU?y17BWFG{eW)I}^`Rf^OE}LN*w=fBYgfvNm^TJkeQwDWP18byJG?Go*S$3ktJbx2mQnaCS+7@ zd^^};q|GXaCDXQOPktf#g@tWjAryz-0Mimasiu=V|5vfau3s1x^hW4yM^_-iSAk~4 z`&)Ce+*)rg+@-$q98vannU|MIqya=6)$N`IRP{$WCI<{{Xy3fotEUx?t`Pw#hM@CL z;EI*#NNwU+9ACI$$7EK}lL%Ei(`#yN%3Bx|Ry18k&RC$zD5E}EU>w6(CO-d_)t84j zE_vo)E7f=udib&gn*y=!?eq?Pdm+$T+K)G%9F-nX6_t|y(@d)8AGRb%5kEz!)Io%8 zSUBpxNWpHo8oS#GQe66jA2w1br#{>%p5>bnAKLL*!%QH*fF()^=Kmx*C3vW~oA8$4 zbwDdCz1;}2#RiPb)i%KV^{1oQi=UNRqtnnpHb5EaTPQ$&VX&W7P*<$k5R|y`;%HqO zK1nN?*ISBi00ly`vvy;@fhq=H5>|pasyFxBE)s}B6Qhi*h)sws`AV+|QT7_OkXS|| zC9sRd_m|@hdj&r|G)qP7OH6gVt56sg-KGBlbS?pzO->*i z1crvv0nZ{L5&=23-8%r3EhGSxv4mh=fO+c)kB^ZvkWjXo=eS_>NHp&?w$tPU<1efuwR}NTWjYF$slU)6twU$Jm99 zNk8T9ByaIsX?u6u`EWx?lcn4wIMce`o0Khu5=3@_z0~?XOg^^V&IO4w=rA~^HOV%j zcb09}Q_j^yr9^QEeMksB&|0F}Qh66@vlS`dI4gYvF_qK3Y}yh$uZ6=6fqllCytysh zjOce|4FZetar6;8l1GVhRuIO9n*hj4;Hit@u{{~X*}M3^y@sNpx~Q85Y?BY&lkj4@ z2ibk}!~uxb7vqkXDv~;_Rz~9cU#kWS%!akdk?0Gg{iLV*Qwc!T+Srn_=UR7)%G-4p z^&vx=idjtYUARP2%J6*4tNXG{jLBvqcBRZJU+G?blF|D<{!oVkC0Ff{%IAHN=JdxE z5I+eo#i_IW!@;sBeTUr3gUX!Yc^KJAnY*F>&pyD>N{A2pD7*69*4-$|3%WDo6CCcx zyK_b$LP)TZJDlN(#KIRHFPiu&Z;kRm7$Nno0(MxGwGRO*%^m zx5#29IVCom)V{@!E9ly^Ed8NSNNU3Uc_9)(@TgBGEx$z+cMDHW^8YQ%3zqy#*cN`W zJ4ESnK)cCq%h$0)u$>h9L#W}Fy%mWKtz7e#?ESQ8>?q_v9YtGt3wj+PNxUq^+ z60>?g%fH9d3k(^^FrACHL7@3XP$^#0dgwwQ(8KTclixV0QdFe-qOwx6&<)p;EsGi? za(fQWWc(gSs$P>2#8UNYObALo;GEWrH9C8CPcc)@q}+m%b!$Zxsp)0PVhqiP0fLsQ zYUQh2XYQh$aABK2M=hZs;Z9vg@wfYZh8D$l{Wy$+sfF<|;J3!fHz~(;)GaSIci@ig zH%#f#(zhh-lM6a8acl4=>YmOQAh$wslaFpG&ElYBfTq!Lj(cA2<8kW> zn7UsmcMX!05&XzNwwU_$&{;;ekb&RkraVJ7{6)X4RPZazCRJR8ER$R7ky{>w-iV(D zZOHYBug_I0A5RR9s}uvmS;%R{>?PtV%iO^3=MhU>R$S&Cq0+U}H}$f1ZNV=l&u^gc zVifFO$Y8AgjssmIQ0Wu^H+g0^^hUZpEC#%YjE`*VvH~DQvS^Wc7YpY}L&gG(5_mXO zoXW@>yZuHQ}DI}$coo(n3PlhznZofZ}|ho3DJe^7mO zuoJI_&FdMr2;@*CR%C%Wt%Io%(U|vrssO8)x#L5bS^!^kf)5Mo4w=nT&_qc;`TZhS zmpkO8ahpRCT@VwQqp%HPjfld}FR*Zz zk1I(Ka*RS{I9nc6ZVF#bcGnsLBmC&pC|5ELpg@8e>fRI@$V^EU7n9J?KQZ&}mqAfJ zFx4r#6^;X;3K^o_lHHoJ=8j$2b4&Q5a3AC_# zO&MrvL9ARqjg=eL_U0*xEnZ<(Ph3i8%(b*@=jlc+g=VYno}_9&XriG;M;`nmepEPYYy6x1f{;;TuhaWaZ(`P?(HXL9 z4V(>iq^R>yOq#T6BP$0BKFNYCh$=_AbLs1jQOJA-QA-u-p=llLPg~S~v8G2K$l4Di zW(o1!n!SA1jp<6!d<nJv>5JJ=8VZJ{@yh#*KzGr+TbfCrb-=eE)!?-LoGrIy%#L$qU45C``1;6kGtJ4q=X8%OvXtGg7r zy+rdt%4wBG+tfz_6rxRGL=I6-gR0r9DWEnvM@O%zx({l1YIx=JkFd^ENs6ovED`Tk zMgIzrs1E`$<*(t}4z}(W^i3=}@+@xLKN$#|g)+;l6I2nVjdYM)2D7F9MEuq^&j|@0 zj@W?uws7CdM^}5J18_cQexIUHbijOmR0YZobPCG-GC+op)NDoB>l6=HsFQ>!C591c zJD7|hmuc5ajZ7?K0v*;D*g0pt-%jT5Cknv7b1k%9eKhpj$1A#LK`w_oHcuI5eP@Hw zbtmjeoE*fB@nPY;)OX_N^rZa|PWQK>|u-6nRL~mvJ z5{AjRabZJH<>=x6buNzo=!m*t18$DKR_~Smzm`f}i1-F>&L1w(PYIF&(LY+ekADiM^?)yo}K+vkM4!bxx*A}PJ_{=@J_DR-A4r4;8NPDYTlmzN5ad8_{GYr*V0_Vt|P?fWy| zCX~3&x?^R;)w}E57ySY}+tUC&AoGGEgl^;H)7X>)b)wi&Pcp*qt@_{($7fC1f#*zL z{A4vSQo$H3aeY$6?^lj#NiuuJUGex^;H@&?@B4$I+{&Q#yK;}z#-i?NyZg7qK$WOs zn_Qf{mhcf`P!k0s?EQ*$RqBA*G&amQ@2!5nS|+Ba3^&mVXdKxyCz z77m?;*XzQzzuZZP*!SCT^+CYC)>x;cL^J<*38u|LH!gvQ@T{=112i)vx9@C+;dtj;5oRi;Ij`zj}Asz zz2r3j`UNcs4OWJ;dQQotThs=Cch9OYwioZH2G!qYvVDz<-Z`wwIU%KPSJ?T6m>PbeArRa(X1YHL=$GY{ zx#B(0fBk{glEiEG;Ne$xK3KLnQ{6}JuUlSFZ+t|AB8bT*lW9}f@~D7N3@?PWDPwOq zXoN&~3mB?idrfeXcgjT-xyvrR7$W{KjE%nLbW#@B9~#{C49Bxzn4ZJi1zlH>&NiN9 zZoDF~g4sC#%MlaMCy6ctS8DdF3Uh03TyOL~KrC0#oxr&k_^WPkd}_YFDBEBd4Jc#^ z0DNKSA8kN3t%#yP^9fPqHc}-I41*oDEWr~343bSN%jL|!J`*MLPK{3JTr;&&W9?KZ zxt5$mx7(Vi zum`RU>%}P*hc~hx6K|MdKzGIbsP)S(JqiBgW)Uoq93E^GG9^I+NA$ODJx_I(U#&O4`ZQfCE&Y`@Jisccj4y_gfUqZ#L2R>+4GAWR^3-wOBza zqg6q6RTI0A_Oya1<6(DH@Pl;G@ny45?mZsv^hF&4mZc#_4;WhgU3m-Y%xx;$7pwi( z8~#=K4{RRDLtP@)CeKCj67@~YPwtVuPW@s6j+@aoTl^xCP z76i;G57tRk;N;usEhLGIVY$p!P%PI(|5$!~(La6*RN_8RWbAJkdPpAHo*l#jmU?z? z!gNh0;m{sSwG{^QU$^D`pB)SH-lrbfsq(9w)ej~SakurJ#snr^a+VO}M)uKuPU6bV zSF!UU_k>>`zuBc6Un?OU2Ic#6&7~#rt~*O3qV?H8bbcd#4h=|h4JX0wrh;IWDS1YK z(3Yun3S*opDtp&vjFrlCYlp<;Dfdh;o|#B}C|c_9@v$`H$XVaBSDdb{zYt{^eZog< zJT46)Mj9`k1qX27Ghc5QxA#Zm_4Fp#F<}7rs|y7*cSo5KFmw95?kcyXA(LTQ?Xa>Y zq{N)5z$j1RX-geY3O-`#RhW)ScgO%~$H(exlZ@3#(yfB(x8BWi>g#KF(o05t@vHD2gfL|SedmV{Vc#ofE7 z;oR0)K|eye!v9Q-#7WvUqVBNlZ^QItOdDyOkaEE^Xr|2lt|>FdSBz?6Iry9s;{R2}15rRbb= z?RVPJs(^pPm=G#Isfzlw0we?=ts}z1`Cj9f29_a{kH(X4L7VT@V0^1`cGw!mHi(0# zj2%MF`M#N8e>-xE2*dG)WX1+fE;RUP)3m{$yC?D9XS&03Wl_}M&OiD_y%z#mJ&|qh zsJ#-pc%-mOR1f({A74d(Nm)H_f-zZq?5uAQ&bmZ)L_neY{bH-9e=B6txW0iYeeCI_ zfFp|fzw1R&G^&u!RZB+nZmVccI?RsUDVW;Z<#*}5C`)o^~U8b6RY|W{- zpfQEMdYt%Mt{h%%aNQuVbaOfPH`36_`Oc~)x|Z|YnXUfk7o1p@bNRgThcAO;CA6)d zxXsH7o-&&*;aqbG&kvrox?q0uUVQipNMO-mN{(ETRWM>Y*1T-nSzK{lxUjJ^_ z=cs`90BaOn(}F*I82n5qy5tN|#%CLuX9ZIzcct+%h!Wm9M~o+tek%BBR z!)8V}$+u&1?(+50VK6l$#0C7`xU}fu4+6;?NmE%;nr8YaeTK!w{jdklE`U|^eq##d z@+Yh-fHrqwJ1Z5x1f!r#gHDvWTd1XMRW9$)4FEuzV$WDjS(1{lp-Q1NA?Y zDtCHU!ADd-rn@Ofos)PLhu?IuF)gw&bgBc#e1K^!#Id8G631|9VY^V5XIx0eI*ZU7 z3`j^tv-?UrH~9h$p&%NSz3qWs)qRFq*HSGX#HahXR#J@wkpocb(`3qODF!k z#ljTmnlprEy1bBW0uP3~Q#w!|V>Mc(b)foiNQi_Sk^q5J1DFi@XY8`|&_Gs|MUb;} zOC<%V>t$m_&!9#{U7fM;9>!F7zMD>XJW8G~0mIkx@6Iwi5NRL$P@@-9=c z_BNW(Gt0iyRdkIv4cdua-H%}Q<9s!kA)anSStIia_L$+16LE{NRQnn}VRzhorl;P_ z!!?k$q11JrM!ln=oh#fkauWT&oi-WOJ*A^DTS-b#&!2FG3yL7#AE< zOw5#Jj5(VKa>Y8>K|zZd?l1#jWhpr9HHOqRq@M^y!}XjkSPa&CYPM zZMH|`%iZrrorj%Uiw?7psYyt!9swa$(X3YLfd4UN0#Yl*8D6VO7HI{JQ$V=X$d4UL zv;xmws8Msa=Uz`lF8&YsB#f(jOz^9Y0yHKGNyL+6bz|ConYeOt_Chuv6Y2qO0wjO` zC9}b0j@w)dGe=XNS>&C#Ic43)uQ%*BALo)V^B4;dlu&ocz|fZ*2LU?Vxh2J`Y`D~! zmn`2O30LOR7RB2uog^LQ*)+mcXJ=Qu23DcsEPpl~!LC*PP)vEs&4x)uS- z7-kC)^u`q2_7q0Vs{1`=elEp#k>7{iA(qj5K44&V43H9ZhNEApB3hGRo+#YdI&!}P zCVJdtdKx6s)qsscG7TOW@9k*u{1FQ$`mH92$FB0RoZVhBV>zHJBT#V3q`jvC^^Wic zi8%$oaIP4PGs-iTDUtGlTm`224xEjBxRvh=ldatX1fLeTgX3sp@swnH;PvU_OaIhU z2yS_Rh6|YQ7#A*Qjs^8YxzCv=w8c_Q;o_0`617}LwoEgpIYGtPT8t<@r=LsDM;KqU z`<*<#WRwwo&A`{m1TmfP7KG-BgbIuA`f}yF5ll_t4r~8&SK2z*B%%zRR?*#n!Z&aW zcLi4L%NLmk`lWE0YhX@R~^lKPCz|tA&K%mRl9gb zC?KY^h1D2ng(Z;Yt^1~|ogWU)X6d`nU*0#%APC#DbAg;Dtz)q5AZ4b7pr8vj-5Bt% z7K>Hm!(Z|SBrwbQ&!T(q%4uM+j_|v6j3RpZQQ&SDA1xSv0fraGfYKqj-+_A5-EZsx z2MtdYP_`yLdXRsX{MPk;@~G;ygPkJCn_!UEGoSwb^?SXi*J3$Cd+s{Jcq&Urq?+(; zQHG!A{~nZogX5*hV)zcrFyQMFkt=@DXY#s-!PhBBcAzLL{k&gOAGM&@a<^8x4&+vuwuvIXa`0{6G;+O!l~D}=&~MW zEnj{#%suD)kpo0v|C(|Lh=0YKNvK{qXYJAP)S(9cu~rMkd-p)Vc$Hdvj3C62Us@Z~ zf%mZ-rjXGjd#&5JgI=GDVCG7`D>gD^$no}{cAUQzY^$C@y4)h4zjtS>8&^!ZN_AFc z93m+>JTCv-!n-s@+h|~-seS4heCPMJxG3erbJTAFkN+UM;#(&e?%)_Rao-7iiEN13 zG6vw0Cd?kHgTH}V97?PajjE(${zcrNu6YK%3cD?pJh?qW-<~9nbf=fm& zN`~qzSS2Z8?PX%uD;S2+d_>P$`|t=$1!8!JAt;b?!o(k>oBleWTVTk+2pt=o7~^3Y zS)w<;R3;W7DvRHIfICfWC76rNI1%Gx!qdPGe9N?eUz!)XkFw$guBr6QoOk| z!fDEWG?8?0N)of+x_3JYwLj26N>R~p(7bG3fT;)~wTIVXgBxtnqa~D2iL<=LorV$W z_5y6i-NiMl!|dViS>OAh4ujEe0o<^;Ff#;J)nq6COxBdO4aDRp+0&O(`!t<43c%m% z)xfX#{FELheD?UgLF~{tnwsJ+bY4l_TjMpxH%@wUY5JlD53nw`{!4Jtg+?MMV@{;L z98%&2yeYZK13Gw+oka_^##t=E@W>|7Z#vEV8*PztzQu}dU!1jgg}u!CnDG2F9zcTZ zHlD#^cg!#5OqzNvNOpCA;*PPc4cB-v>1X5X2E}enub`Xt}h*@Q9|G-DH3P{+X1gN$EiyHaHjEk>>= zgmdE)-tS);YK)4v!^-+p&PN9Rp8k{vaUfetxLd9yD5c_2Yw5@Ze{(6(BgT)OBN(SW zj_>@32p;oLKm8IWFiXA^M6#toG*(j|NPx#e9?868k$e~;b>_m6V!%pg* zjz{EN2*B5yM!v+;)F=obAku@V3RA&l1%`nkkeRU;R8Gx-PZ#q@3&8&DWcE*ISh6@1 zl6UW{RpbsuW4xX!U97Z%3jfqisxAzL6Ts1hs_V9YMrk+lCGz@qz<Q6XWKss67!ScF5TfuNhN*ZuAb6cL%V+CKrC4S(d(LKgdi$_1 zxmOeQDt=)fjM3H4#J?Fx;3(uds5&Z@V&xeX2?d>8`};crbGz5S&GIF4ay#v6i&{Nf zpds2zFq^XUP15~II~CZR*0*0We4;cyJ$tpOc;tvletZHRtsIzXX8?Wf9rHtB2IU}w z?piYX5S;k7A%h49jcECVgq)b?c-`3pzfn`8->Hf*9;t+*O(41rux=~C5Ql5u*frCv zuc3P>HxuU5y}?8kwHKWA?0bb|tqBLF6p05-F>J}~GU(HohF&>41U3RLqDB9Xn4F3* zXTe-L8JZsp(fmgrg~aO$T*}VFognc#xj2xc2U6ho^Dctx!_2GY)D8^$AOVD8(TE=L zl}_Ntbfo@v>WMR(Kw?CI2GRonh6dUJeSVC$fP8+^tx;-Y050yn-fz=m8~%8V0cvV+1yjVziP<0*9U#(ERmC`qAa9JP2YL2R>_vY+7kNWUc)J z+5k-r{d9&I-%Yv4KP*Y@a0tCsw^iEnX6`5n`dEd&dZ~Ljt0Uw%XYlsrfzT94lkp%vCdzm3MZ$)(ma*Vz(Wg$ugz51niQx%4PsWi8GJfr;=n%w^eFH!6cBBftNyEb@<94 zv)zt~kRA)%$w^weTbR}-{BSeWjd2}o!xsAR)%B*_;LeDf*%ZwyDd(Xndb{=<`wzrc zi+p>aMX&bC^EUs8WCKYXnbo0PE{w%DNmXO657A}y-y2z{qudq8s_qa79Kt1e63(;q z$`AVyva5z29ZD%!)q4D;+~IGCBPvuRttt@!;B+$=Bps5M@GJlT0Nq}4*3=E#?v?c{ zASEha5Mo9VCr;y*ja&rTHyeD*2{eMcU70pR;`qY{e@ae$XDNEVP*vFkQ}dlvTPyxD ze1LDQ)}oav)7V}rTgKF<#~;5RdR>3IIc%2tc1TkV;)qS$WnhWZ>O;Epru#Cax!40t zP8+^JvaI|-qF4TENpQ$!@V0_UxX;$~F7IO=eR3Cv9KC%I^r&$vKlaxr1)iqgo$RD!4QiegL5>_S zDX5=*+!G+DHH_zL3*|lE^jRWD-41~kEgtKG82f5>&p?x@gzTDvmPK@Tdn3Srn7!z` z6c3*zMDP3WU*2cD;r6zUUX2JrkEe|$jBA>hHWzzU>$$Fd^N(4|(mx4Q@69Aj+sOrZ zEb;g(@b*FhwLe*qn+FBzZ5!Sm9arAKm>^EazL`Ay>CH8AOibDze9Tp!*Wsbz=h zzt`u3A@1gz8^Hl)cQtGI{=RfQ_hC-EDmQuhKHYm@WN$ zP2cMo3D%FuM5jZ$?P&|Rm!&gl+}r5Vd{m572Rqog`0dCot(*F# zafFIoQ$x3wW9!|phK^9meXtrm`+yT@y}U`3yiPAIc6$suA0reX*+vnVG-Op$gMI1l z%x~_Q>0zA<_eGn&uN@hd2?f}^tJ4_sOWqZ2eYJrtOC0w2PhozHp$IXYy+YW!O6$}PH>K$OP1N?RKj{97pa{X4MT3a&dmKt1ukTX7QL-5pmN+(J7}?h5tTqlvs%<=MGagCDgsi!39UYw zOOt&-*1g6vHg-kbaliyVOZBO@zYy8Bo#d{~SCl9wbS@nt2hZOP45k#qL!Gh~^GnF>U zT|1*FS^tyZOIRugeueQ+q}2Qha=4X%7D!@IoWi41W{(5WysTNLS1x|^{Gyk4r&wGOU zJ-L44inv=iUMThzHlWB03ZrZ?TYRu$p)&1&+GFTawz02A&F z@?aQIF#^Z>tyA8rt=&zC^<)xb#DH8#pkp=Y*PV93>l8E4|BQNh#;87R)(U$z1RYwb zjw`Ji4foHvI7U#h&;PNX%h(%EV*xb4))VO@?(V+xYUn_%qY6YWgM2>+0mZ`eOu_U? z?-F17cK-dWTm&CPnFhwzxcRU2K`MPP96oLdPn1YzxN7D=M^b$pQfQKzq7wo>2I}$i zPe-kqOX4UfMUTDBFyU*er7w3V^ zw|QtrAoI8AfphH@hhs%h^1~5a!poo)6zzt#NN72>gYq;FNKO1wPh^wLhi{nUD0nK- ztEdwFXn_s_O-&z2Z!-kAr6qz3dDy_!bwl#Fv^Bblw2isO<5~9g6nM}~t|IWtQ7hHf zl{tQ%aiFloF!6>vACtPQPK$hj4yhQ2EX6u_Ix{Q-<|>V1mhP!f0p#+(F6cA9v*4*R z`J$K`Zus*HlB)m@*u;pJCm8J0Hhbxlv$+wHmxI)C;9Ovywr0pkh>}Hli;qDT#6J%~ zhqD)!NXsCBMav47)DHt3Y!Dmc;Uu6|JL;r1t1aSRX~!CN;aQ!{aKu_46uANAV(Xhq zG;uu)FAScYsQ-5)EcWyQ5jn5W36OvByF?H1nWPd-xQ2;^gD7t0BVh6h(%LbQ7(JGo1F=IO7;lx?h zQfQWd$MXjz(%3E`k@HKhkJTRs+09vsgl5m&+&bnjj`5Luex;M3PPb53qBJX=ZfynCbi5I1)mvZiZ58lI>oY`vk#_Swex2;9T ztMz`RmC@M3`#QmGIO*#*4s;zgsQyBC)DURv#rh(vU5p^%BHK1Vf-w$6#W0N5oS@|$ z6!I15i@9iY1Txux5vD$tZWzrTd*!43xUvU;vVJ^L@SBennt|hmbKUHZ<4$BFE(y&o zb~v&}IdYhv&DCz;y>BkZq;K*Ef@9^~r+;*EvPF&nJy)(F(dulPEX%Ap9hW2A%^{7b z5=Re~FyzQ0Xzd3VNbq9OqHua8zbGX<(YhXq0(BlFDa?FML6by|pljiRXi z)OYKN8b-oo-B{)rmlL-2t}s=(dV1r~K(nyYP|7ly83G0>PlYBrqtf|kT;j4y5<`15 zM^umJxViD8hO3c-20fOTO@z@nFi;keQgiUa>X$Lg$_I5ns&|DJrISi2); zzaAJehI+HiX8nrs-*&Sgb%`=1_5m%5njw-%v1+nmaWg?O=es-89G4kPoXWnliLYrl zgycY_&>wnpqL93YYr!<$ zt{1^7b8eQFa@3T1W3QlzKu@d&E4LoD!(~>q>z1nv;0pcaR1{h@#9KflfW@<>@Z{R$ z>Ij6RZ$ys4zMwJKkdGvj*Yak8&sF08+HI^xB3by80y&{US#r2Nen&pZzJoDRT zN%)aU=JK#~sk8i>@1#_?0bkL%iw!YCXfPSUvAJw2_~Om6v6CIMw2hwb-8D?)Yb_vxT4iWY zc%(tmPJw|7ZLc z2rV0@0#OmDHn;Xw}eDCT<~Q8_RuUX{kD;83ISC16#^-)^R@p41^ql zp#ay?{avU#teBJDJ;BCA8f02Qtx*@O!{}srnq${HLtFs+y@(pgs*NqUf#^)t1!q}l z;Q+VPawn6Hb7B?i&K7|m*)Pl-3X~u$>hFVcXxs2634a&)LW*OkYX2qbA;oRh2PH&O zg8Sog(*eNtYpsEv8E*p7zxksRgbe)nLT(QuUDbX!7X+AW+XcSH)aVpyy$V| z4jBBDfb;7F!5u(%d!ad#-bSh3<(T#FUA^6tIwO@5P1&Sx?w=lnA> znI})qchci@xdgPfqFY_cu}(j749jm2JcJubF!uHS98U~a^y2b*HP&81`Upoz`rct?>xaFk|K=qAXHp1E7Q@F)5_MC2+g-rG7qDj0&lm^XYkEAWTwx08p zLe%xR1{I2yxVtHT6k`pt-Emc4R)OL7FSJ?zn2Wa({+ufE{+?X%o~z{bgo^DU!a|;O zBYG^x*JvVxaiJuiBQBNUp!yf~Ee#k1&!=Mid+YZ!S;MKu^Ev7Asa@^{F^L*2`wuz# z^pz05ab^8^b{Bxs(*b#q5Q z!p{CgPHw3UTu+g|cq(wr0#Bj2lmy>K56cxh{@&_(Y=u9KOV4R08EG@RM$}lL94+td(GUF3s&gFJ714xRl8RiZ88^fZ2d3hK z1RGc&ia0@8VtJfjaWUSF21eJYGY#L$k>4iBo3es0;#4MWor%e*e#;1_Q1jd+#~<22 zbgF8u>F`IGyAbbeFQDC<3NasF?( zEd#X@Hp)73^IY$vWjo2+!fxT<-f}jqGArJKXYm&dXZcFc4tV{feJt>Rb$a; z$}9~NY3q(Wc4n5x0uABb#m1qId~0^YVb<)8)9-*0Dycn%kyRRcwDPAiau;ZkKbAm- zQP0OTvQ-l1u6{!&3*tzl9MvS5yc)s@_w}4Uqc*-kvvoTu{**rPe8(e=kZhJA^p(08 zhmg$3&hKO1?F<+XnwgCgX@R))+8nW`yMj4F~d z7=>cr3qQnJyDd=9r}Wk*CQ-Hs@&6`}!{SgYsgD=c!ghCZ>k08{(J8&S)L zq|n^Lq8{Lyo;GeY`_PABn^b%A0(<@TFutwLVh=gfu8p>-O0IW-w-B+rw%eQ3cz(`Lx|!N&eP! zBmk3$=Pz-TAQSx}=~NRfxjDlO8;;y2|s$KTRM#RLeVMmETQ=B>3gUE1dt_E@p zB+MU@p~{n^c)#eix+UH%4;A-};$QPcl<8(A7}1`%-ss*x1aqLg4}saOZ{3F-G>&r5 zw;{Mx^I3!*F65$Kw1IuAwrVkwa6Ce5Qyp+_q~vRtX0ud@OFPjV6chuKbzV&exiG9y zDqmFQ2HPp61E2n)U)rU1CK0Oc44G=y_665Hg&}_F7T7hGR(7CQV_789;B_w{tk%^6TKi4%j zihWWNG%7HPZiqBCW3~x(?JxR$IrgkzD%@P4r5*_kxIOZ*Pz0GgPLZK1ArH{g7SqXZ zR95QCo|->-JZXGVc}upW^5QdszJ&y9Hg+&W`$yk2SZ1Rv*THDsi!ysvZI}eXuHSCr zHmS4d7TnQ5H*gR)$gn{SDJzuE3cr|UR{eNJ@gp(2gqY03AGCMHcb%)c+?O>SJmr0t zx?Sv$$TIV#Y2n>*VSmp&pJ6?4K3l5)O}%;E_I01hDn0$qTUROV5g^l>xt0d5cBX2I z43Io(Bb3%yRE?cuWW#IF;>gT6eF5=AQNGtXslErZ%z~%#8_nbcaMHkp&uR}_%+r;M zgCO8SNe_AH(*KodZlO^BSh1rm2TA%uhAsATMpuxNqZ{r)k9enVYL!FNdsMZ$>imGI z+DQJ2JAEER?%r*N8sa9_UX&j`jP=lHUb}QX&bit{tYAVWd|~Lm&pNj-B6w-TU+&(i zq|{n&zZkeFFGumI^1&|p;kfi?r!y%g^GZqB7|C*tr;)^Vo`#sf1eyk+9MQr&p3m5%%XY%of^nlPS zLtw6|+4TNB?lp?f>2)4@{r)QM94#zQgTmcB#P1ecBrdN4UwYEIQA#4>P*np%b<+WV zR7w69Mvb~jMSHjE5Dhwc^t}`1vbIoR zkO}eO)z4iobDgvLB}S49y;^`RJG#By+a@g9&)bN(C?46&xv+{U4gPfoqmQ1rB9#cD zCJ-+_vTRGFdzs|!P10NrNB~&<%*Ig~j>jdqi0Sw;htTVoC1^HOb zhJ@qs0u^5?aSk_+!&7vm-*0dIHi$&Ynq@QljVUT;)4cW#5=P_wt!mA~GY6E@q{QU= ztn~qk&mGghofczhLw5+1bhR%^jQdF>(I0%^z;+V!{9U&As+axHQeV3FSvA?+?h#T) z(aO$q=#bFa(aw#-iIzTsXLxW*+OopIRxnA!7JFzFO`VS5GgoZaO)=gs6WOtO_W{QQ=4c;Pd^f&tU}vjSXH|Xh zk}Pg@l?V^(8!U0W9dQiah5I!Z&`?po(7Rl#($nJN95R90S)+{1zv8$CX=HcTnO|FN z)HoEzTM`Jj>LitE67w*kUp*YV42WTFCx{`xLG6E}=_nJl?jBBMk}B(oDR(Z363@rp z7dGJukP)dROU4+jYmaRo?bD?7857S7tgAl+>|&lLl-h-%l;PkLEHz!L088IJ=Dcs# zzP0-_IH=fyNT(N2!_!Dmh<`A(a2`T$BDGw8F|6m|TMPa4jg? zpYxZ|uw)@mnTB4$dEs4`N=+TRSTP|WoEY*TS%;)3KI8Z6!!xnZeJMi)j}-OdXLda4 zvd_XH6yrXk_!f$qZZ zT*-`|AEM2F9$(dWW6JXyuOt zH>ioKe)y$##^A#PS%hr{T`KK+AQQyW;hj*FAV&bkO;pX5VCfBzyUWfM!&4U#bb&2K zsv|m(mXT8q3A?_vupV2Fn?`02meWOP;uc;VqSB383hIkHG*m{PQuAD50nDh_tRyql zjYnplUkF6CM1M1nUQlGk47{h@XdBR(#T_I3_AJ?wbMBmj2Ud4BO@$HJRK(W0iCX>= z)W$SRs@^la9808|Qr3+=S}=IOYGFN*JG+m{9NT`t%Eng*g9P@w4W>(c}~bC&!HmQtAuTxDf8jAAJP z^y>)}vPrikPJkDsQ~jj3#X>LI0uRRG1}Rq+>EN}jDY*oE^p!y=l9YS0XM2Ms z?t%`#lvO~LedYp=6=|uaW6rpXJlI6#b;*9|ATW`5R@O!rOU#@G|M*M-I|N zbD$_lYV#mP{=;Zu?Q$5+GG-(xuoC+6{aW~vOpMLVv2Y*`|HBN|=XIK-KV{^X5qx-dx_ z-&0|62%}^T_-{LZnxC+Q7veUzkD z2di?UMC?TUUe54%y=UURV1Rnz8jAIRKeH#QcDw*GI289)_o89oVfmXZ<+)ORuDTSw zd`|eAwGGnc1Xdm3Yk*^fR-l{CEM))t31sC(F2)}?+rMJvAlTl0@iDl5|ru0 z`mo(y+l$?lZ~JPS*&|+pjB0PMpa3gk5BKNJ*)pPuN8DLTMhaH+VkC`OtyFS16XkK7 zMymRgsoDC=ulCj^NfkW&v}7>ECT*v)oeZmYi{2}K)l7yiwq$U;K_zF0+yj7 zS!$~#6yGi3xJm3BExh^@mJa{~iUYmTKB%xFGN54}z}09_xBv)04%Ec~=$upl zau=D`h5$hR*Ko`Y0FnW38+;I)h%k?P_X$lz-2foD9MAr);+uE&=&U9tO@b=#N$_)0 zARWLW9Hr;?!Qz-Lr?~+q0O0jAF$NlpAD2s_c7+?^mby&bmI-LO7d=;v5oT%yS?ru} zeLIC{yt10vq-IJ>)9LBlG?}IIkXM8kz~dh9lgD~|lRHkUteqU`7LGlL4zqT{GgY<| zfEm84Nw@@kFX(;L-(k>a`Ez+3L0#9rb`?Z`O>Aa{$z?U)Q(XUJ7w5x@b=&ZQhr*Or zhDFfbta-`YY50Ek-%~EkakN$$0(#lLeM`K~y7ihP$RMw$aqI&c& z*5fey))k|YuThjlXpZBz1}OX5Z&7fM$2ZhRnZZ~#{UaH#;|Rf@6hE!(3bl8?HLyWW z{M!CYXbRmmrwQ<1=p2H+sRRWYyfJ!2T8m~(pZe{D47~)(M0v)MkgdPg%yXgVLz^7i z_uCxYtF1#4g;$w}~{&q*OmzdlQp@mcC@p>yeyq z_P{+7+iwS`96>@z5`Q8;3o588JDB-QPu%zhzh3)%4-1gJnB@jC0021aQ(%c)(aAuL zNXO{6Teo>H?dOEi!}<-|gxUd?1C-~R;WqT7pToNyx{*sb4d0dp$9#Pq6=oV9g=d## zgXD>Te5w^u|I$utjmVYxeEBB#<8S?_op`zrtnR&^;u00zO&I#ZX6zpl)Z<1$B#e`^c?5+aze+4!eVnMTq?oIORGPjaWeU+vd@8oskq@0 zGVU)^IG61f^qp4ULF~sQcPt@z5Q7D3bEf0hcHv0(u`l0~<6Y>h+(oJ7E5h(OnNd+s zMdYg@+$z&1dNNtR``$O%Zk&IePfQuCsBj{-)7J9flVT|_Hz@bQR=xy)RloZz1OeDK zf&xRq8jloJaN!3TJq6iC_}*7gUK|?A4A~$_CFsW zoWTe{03O`JwIl$xkx2jgd&Bvk_Qw+eaDezft8QxROV literal 41202 zcmZ^JV|-*?)^BXvNyk>lwr#6pJ0070$F^-d>Dabyr*1zp^SpOv?t4Gfhh4uqyVhCj zuYIbNB*nzea)E%{=7qUkpl#z01uJ{OzjBv2EvCA z7bqC;!wSfNBRl1KkS;yywCcIzGih@5JO2ZJ0aNCwqA$N$U31_I;S--`ckpZKSWm?* z{B!IF!%FsNxAIp>rf;V&(@V$g{Bg@$&7pHLJnsBLS)0YbX zdmFgGe$`S6SnhcTY<}+cOnnUkreAD6M?N6WDS8>6VlVh#y_0)7051S}0RLg?8^aUe zi{OBN9#G(W_f!PXe8&Zt9j3ltzsWDfzT_b5-|~Ncoq7TJ?mhwmrk84VdKUR(e9(OM z0KRW&H#xIC2>{1W*00U4`49bOK+uQh-Sh=v#rA5?F(CGN^b7Va^s;8)OCNyz(ekwY z0_f8p?2h@Ef5ki}yhr@XIp}))s`;pSLVWc-e~trO0VaEp`GokteZhXrzbv0K+}C{d zoPCD-rhK8kqksIEMJV^3_zJy%J-_bv%>rNm6hGfzF~4f=d(gK8KQUj~&-w3i-hC;& z8Nb>-QXid8AYVpqVvlxTh?eLcP~|MXY>&KJ;g@x|_={^9!$xZhrtKkoqmKzx$`kY6Jo>`!j5 zc7W^W9wXliK!EQYVE3b=i{#<^N6U@fqwnjVPXPc=#DsV7Ap&xraD~_cbzW-r$DzjJ zTxMVI3^=FKPQ}NvQyE$8T(-^|r)~59Sh{5pJMJ}_HVbmo=EuK|6DLiBP2nqUF=fHV zC|3ik!VJarBGVElmiH59WPe{+`ze2apC)WKtj9W+^8ar3*WNZj{%2|)`v_i6=X8|1 zyOv?Lw=jb`Dq^2c|KDpkO~c+X#l|_G&k~occK8!kSGtd9L8hkL{6Ou}8sDPn@pxwA#&X28>iVuFX zr@BUOP6~#1e1<*t!R{4MMEBp*K&6$A{)y4r1EdK@Rw_#La8fmGL16XB`Axa+ktR!G z)l3-lSPt=tL7VAy`(Q(~%lIm(h08Ybs!sVZh!UQKqB`=QQ~kTTws~jz*XwVrHG*hb zs%A2PZS&;bF!T@wfEZ)7hL2G&mrIR160h@1&C`@+fJ^f*o1!IO4>hJ%$)w=N2&R_5 zv6T2nOy8hE--;ustv`}34d1R;ZPGy}KbslNpdAVVOR_@@xz6F zZSMhMPrGIaEMF2FHRtb3PmD$ z0Y&dm;Y+aHZ>EU(O}LtyRhBpJyiZ1J<|{>vmYGFEih{erfQkbFC}6(AA1LTCKTs%i zL^OX7xS_q3k1;-SuH7i%lu8YNTm2ALKI;_Wr30jk( z_JT^ zh?m%mv~Hf;we90aP&|nc{oHxenK!8R4Yj(deVq-kT;9F^Fx~tP@SzgpLo7P+4in@( zxU{y4Qp1&j2;bmTKaUCSY7UOso@wcsCBn;G7qI#-n7waw!l~X`#;NB!3C7;I zakbU$pqSET#P~^(n@pS|U2@ zo&23y^g5#+sAZ?pVsMu(8gUmXdzNy35xU`-w(pQ70^rEQlo0%;3Z8MUv2do;X3ifb zbD-4ZHusNtR{zDm|It!6eFFvVIkl5R1f(Wp@%w4W&l^7*J@- zM+9ctbQ#QIGLJazR{@>(Hm_kNb8=|TWcurBnc$tQY+zyivz@swpQ zn86JY*6)7s5D(!+|Ec_TMsGgkMFX6<#}g$mu>kU8*_qONy-Vc|r8kaxfZECJOBq)) z23OBEl;1ge%-e{!a=Jyct#(FOJw(6T%8Qfk*VTJ+dUX4<21}=WQNHY~jXlX01V@_- zN=aMCCcwBE5sG-S#D$~pxrF<8M}MVX$QY3_%_Q6Mp+q_Ck#Yr9-S<9zvH3g4(G5T8 zrxL<*Jzn{zTzgpV8efQlp7@gkq_VJ%-%^vCs70v3994ucvD@K4by`vj<7f?iGCCvR zAj2nzJM`^d0MD04LeH-L_AelK5NSh(?*2jVFfCr?Wcr{iR1I%C@%3X$!@q_I!m&Ps zwA31-9?|m;E(FQK57jdqY~gMi=8ACs7h&4wbyrwUQw`(o z&Ip5V2??owS6!QZ1jO$LR-Au6iTr$JD%bNvD>?2j2KJQTtFR_LxCVi|YtR^uU4Ut2cKy%;hDGZl?a!lliz%rfLyAPM%Zx7kB zgB3>Cs{g{y*CmR%-v8J@u>Rp_=sgxJt)>?y5G#Ek+}b>>5N!B=ro&b(yUNc0+xDkK zt-I~Mp~yde@$V^4Ao?ROU*qp;r}~Rarv!~2!sjjqb@CsfJNY$7lnN;JaOu%B!nwqk zmy8Q$yoUmIpv@e0bkn=Pf>aB}DSs|j@sm$w=8@#uuz@OrdZyVzqfP~0PyD*F zL{cAc!RSj%)=)Ogb8#H*N!p3$h_H2Q-Ar9*M*XtuL@btN59DH-M*AR)$-XbW&HYu3 zv$+%N*Wa=%FS(>(6W4$@Gwi_11q#AQh0feKKcJV!9Gr}xqdP-TV8;EJw$AUOsB&N3 z_{hj~Ex?e!9oz_&frzqjuoSg+0}_)2C-75=w3W=@cS4?N2)4?}Z1@esHUijJm{sF4 zd-?@zXe>{(O9ed$wtmCsAdD7=nHV0l+IU;pJRVh#im-It&5su7e}u^Sclsin84%o} zhkrHAFfZ(PXRv0Y`DPmo+M(a>v~j)>iYK@Lo*jKv3zro|U4GB0gL(3x2*r<_NYtut z^xF0H2~*cV$IVqee-rSZ4&-d^SiMNO|2NZ|75_uu|7E*vYmF<)7JpmTtM30G?cai^ zv+077lV9SZm37(QnBbeU`p+->=Skw)Yvr#b@(+t@r~D5u{CmIkE_|0fmHw>1PYc{! zDgWECfwZy%NZsZiEci=#wrQ&V4hsLSJOZ(NK18zrs`(`UKjPEhKHOwcTl^0Y{8i#z z`{KV}|1U`FT6EXn$g2Gne*S)o;cv$&a+34NV-l@E8J<2DPO4t5r%PO24}f9KQR znEhK7H&$KU)oo|s;7c~{)SoMEW8H%TRpS_;ILqBK-Y<{P^oG!tDpDYKznt z?Qf9MLv`B;C6I$~q*{LT%sJ(meVbeTeXEy`PnUUj4?Rb#o}~3BYw10qPE^m_I@eg^nZ{n9~%&`172DE=N)W z7!8VpupMb+mJl$MCI^gp@8LpcP@gPGND}R0)g$@ab|8kR7L_iGGoeVOlAVpwBo5@) zuMA(A+Y{hlrV7mBC}~gfwNP0l)4q7R2G=m(hQ#(CYxc}R&E~K2{I@DT{qZ~LZ4a@Q zIWpfRX#hIa5*6@!p>vbD#O5E=P{6PZEz-1#tjwk|j&LqQyQ$ltw@kxZOhYtS&8xt% zAYyTe9_RX!H#SZb;=?wJjOPK!T~$<|9gS3@s!#kc2yla#Khy2j_bhV-Aawot3Ld}1 zt|=n72L=YbvC-EUPr!$;?tsLqp)lw9Wv|on%YVv67jVai!++ue&PolWPoLKwtm{u! ziC#5l-QJw6{h2J3PdpfYzj6L}kd5B6f-hT(ZMh2a=Fvc)w;ymI7kQ2g!WY+7l07~j zF}GtDvyV_qOZ}BR{|3tsrw`&Q$I=su-GL0Ku6qy06s~<$R+x8I|(DwMm(a*Aq}w!wC5PS;ua{3o2<2k#LAjM z#}#paA~XjxEAYgOCZ~kKKoaA7tKVbmU*wY5ms}e*;Rg@sO4H1Wkr(gj#zZWxj3$0bcUjbL z6Z*%*-9CKefP89!NK$IAtF%^FT*oqFw8((18Bd=7ZY%cz z7LO5USqs*gTsro^FeKd@lX?B9Cq>xe93&;qsGr&sApYU>6JPlp zJw$dNpJ+(pRxYK6Z~<8AtYVPhy&CagIa0J1DjgGxcX$l?~i}o_hBkO@<-6 zj`}-N*+R9JCZKA{Uaa;upz{Y|13Nkc)y9IWkO{*~Bh}C?)S};?S{Y8?cBUesB8m?U zVn>D=soZ1je^mCB$4bC#ij#Swe%RVzlg*+NV!t&fgM6``qSO3>WyD#UfG^6Qromjk zRK_#7J4qoIlbzJYzr!|P2vz>!eOk$=t1p3}9oH8H?VXWLE3{+b!^+6Z0YU6q=7n-H z`C#^aX*e)C1wM&Ynn-p*l1>%1!>d0uXq(x7e>-@`uvu{Vo_qYlio);#=^x-zs0PwI-Lttx36w#|T{03_ z-Dh4!<(9|obVBzAV^H&i>_{95p7Tf@7Ho-v2?~KhN4_l7FX`W3P4_>gW?Myz%+tE7EFj2sK`FQ>c~<~`V@r}Q}8S^ zrRG7y*3cs;efa=%w-Lg%;8aiR0n8bn(1_nMn^jp<4`O%dqK_{ux_WyvuFZvkZEue7 zu+PCZe?=313RqP_MRN+oCXp{zBSlz#|M&)E66WaWq^hk>!Oh-w{gZEb4JIeFpu4UQ z$hz|FASa*j7mAbc6wS?yz4llBFmV9EGo z)Cl%2Z*Yl!32T^C^InXMxoR=ZfB7>C*^e5C z&%W{ZEmMn;Qhz|RGSFsoye0yL9|rY`96HGUpS{3g8AI0=L7_#-URS#xWSvAfKA?-M!9Rj8EeuXpzRNVvd) z@A4V8sMfiN76K$&NoF@kX4&_boO73aTY=_r>(!_FjC@XqkA&T4Vt=*qn||j+^(gf0 z`R*Zr)`FPmdsjkzd7wSGEWR)m!qTjfvBLDC%#w2Wj&OXlK&X~ zD#tSvpTaThb9P6XmcMj49;5CYOne?Na-92>a`HmDT2})f3F&oO)=CMxJhU;Nh{+Y0 zjanpqKO_u-(;QR&ZS2&xHQ_2@x9E6n9-k%^JB_u}^gYX@LZy}b2Dg$F>M5UqR2Avq zMn}dtD+Ov@GthTm6_HQuA2d((M#Ef(ZN9mry}~XM&JA!4NPGlRVL#K`kUKnmvRpC*6!$w$?OiXPH1qF} zia8)4P!6%}t`*0j-$UWSOgKc<;$#y!;A3=+=ze4EXBkqp(steEHS&J)Jo1U;9r$@s zM2I^$ba^_<zqwb&kq1GO=cy6&AGfsJdWZ@|BkrdE4(XHxu#Ln%VJYvw!3hNXBhfwX--E(%G9~47pt^z}Z#-ddArWEi_1q(4a3A|Gd(>uq3^O+)@o*m9N)W3aE8U zdQ_jv9<1)ONueOTL-n+q9A^yJL~KwAbcIn=@l;K;QCj$v2;OD0#@Mocl6$(+4E;Uh zKw8Bf7~v@YF(DuAZoA4vA^A)Cr#rNbhVwP6k45kes!M^2Ow`UrqJ$D1P(4iAb=QKj z^jx!9tM|ePXAe4@yP4*b(!}-Z-Yj?xFJ#WQgAmaA@p2kB7%=@d8KZb@ZBJlvbr}AE zkKIab%zgpiLiu1$UezEY7b?E7cc#b1-2=(_g>akta=o};u7^B~G;a3^)38;tO|)Gp zMwmxZbOFM0!H5}SMeq87HYvRYk5dBOy3xfxJ&ni}W}Aox(59G~+Z^(R!jFOWWVf=| zOSgI)^ZDwszxx<6Q|vv$qvu6J54x`X#aV2}uo!PzceIFsBo2rZ)d#p1kn6`J}EjQdL6R3S5 zE=z{25B#gjpk9&!6YN?zX<{~t*XudP?qXaoR@5kuDrys#r!Y&Z{%5W_3{Dsu6pDa$+;uOR2rsj$pL|P-T4ug(7H3FmCkr<7BAd=Sk}~NhYSU zWMhLfQ*sa4cL$r0S_?Ht>O)MC^$=2q5?K;Tr&z>6XP`DTBvr`~SZf5(LPdQaP&_(k zzQMH?aeD%3>u|X|W>w~NgUlcTL;X;YQq4oQegVNqUq>rVv*dNuD{DR1+?QbXeC*Vm zz6^L&6UZI_L4Y8L&6`yMYrtDxqg{bR6ziS>+V5U2pryn!94tBcwj}{zEuB>Hi&_7G znv`<@M9UimfjNDoIa;-4@mgWRj#Iteu8yc)f+OvTU3cpV;if+O_O3zhZ=?TO#7e?& z%49p%8tL<)>U%hKg0S6 zg?~$%%a@VBc29yH%hVl~$P=W3Uks?x;PGEIN%y8m}atfOdj-1&@bj}tY zAxo$P?YY$V;h8;s1`+jxN>ZL*rZnYg$R-S=D;;#aW|^DyPkTir3lz`Fn;$2T7t9=G z)Uh&FZ$5$?Wr(6+5}WB#Cs~r3XE1zW*Pbs4PXJ4NK*cX!waq>R4bv^XBu(zHf-l@B z4>6|KAikZX7U^_Tr`9Jsc$VB74J7fnVkz%P&fA)?Uv2=KG04Tx{0WUIRCj)MA;5r? zf)v#ybh^9eJ-hGaRkX6HdFA*T)DsmEgQiQ-PKR|3R2=@-m+Dzqw<7<%YrcKFZ14_kK=>1}PSVw)8Hlz0ir zc=kZeoSzcVDko25Dcuz>XwM$O0%yQC>dm6obr^_Ocx7Rqybz(kR9}Qsc|taR#~K9f zq3j&wPS3JN#)iFlevY__zff~_gUb_jDXR1lW;PTH9N|Rz_-JmS3f(&oAo(iZ477tT zQI2;kaDAu0BmT|dK0=BBml9q;RDYgkBMhG(V?Pazz9ZOvPo+-Ic~u{LiO88TA8FKX z%3ck-9$!lxkuR}Mv8|qsD}|Q!jhZ~a<>Ii?eR+AL{HK60Ty(q;z7;+Pv529oN}x#j z(q*mK$J$TNDwVe`8*-fVDqc}D8u6QDc;lkcKjvCm>P8)R>q8O zK~KM-=M6H;#DdRkmO-AAi1Cqgg8R1TC)!}AStKcFr5scuSw`_yG%vTj{8aofp9Q}0 z8)MT2W+D}UwA7+s($z`EWmEfQKT+1@HT5B1Ft)iHRE!d#J#zn)7Dfk<71sy z(8U&EF95&xqVTkKpcP<8L%M4%H%#WF6?=0Dv3)bBX=SBzF9XClU-M}+vQJt11LiKo z4)ti7f?@TNJev~Zak`xG+49nHb@!iBdX22-Lgz_@ppW`_3oU` z6@tobrS6zu6ez#ea~IHu9b{}bYVVG6IOTiUy4f@Ts}jk6yYuF7nsttxehc?$tOpOg z-rotuaao2c9@LGWLa-TpU1KinkIDwoQ`6yA-1pCt&1kj=Cxe-^P{FPz2y40zMOTB6?XB(#Z~EoAj+X=#+upRuZz{Z0ka1>g7UrJX!2iDbP=b=O2*C+ zNaAgwt68o0V+cX5E35>#?sjaCo4GnEbb%mt#(PU`uVsdRbs~C>=6+D9FeM$^$XYThIfg0%C9eBWEtspE zq4B{8Y)wD1sVu5?j3ldj=pUpmG;%lK_x466T%fYMe1Bsb3PVnzaT?DG*~Hv6RBRlE zaJ6iupj&m^s|j;Bu3~ynpB=GDs@_q;q{fsusNNg4Pr4^5+k`7i=IV62nrEw-L<2kr zi%XH)f$z;g!p@ysZnqbik;jk{OfQ;ML_DqWly~bt7))^}$Bn%s0fW9!qgipH8c}^lW)XprLZr;WW^WDt&1e?s< zo+#$kZM+8ZY-nhigbsLCB10{0DNh^F$};XI246&QC=v&@>L}!_c9i8zj~P0HeDU-8 zuNRbOlACPo>{^`5)7MvGe8y%(`;nCbEyNyRnmD)urCa4c-DF6?aL<+%xfE+R0~URv zCa9fp)-xxKZAPyx73I4mC2V*f{jW_EO_l9E)=qTWkg~5i18l@hNJnkDZ^rqicHg!* z@=6S%^;?J~aA-D4WcZ%SyYW-zl(Y^d#jRN@>+J3Y{7E9!P`?XkyAOFEZFr08Ab~b* zRKReyg?wyVOkRqUv>a>6e+0cXvEo1Im8U$5C{y7|4zv2)A<7beNvN?Y0!R3a<7ba- zM};2EV_3S{vdUg$mbTUwYXoys)wDb$fce-&<#Hrc?n$W~Z%!`>o|HBejYpl~KvVjU z5>Y%RZ*~i|Q3Y(fCNmBSh=Dhh4+`oyagN^W9kYG0&#qWQp2sBF*3WcSCj_4Te!}B9 zVc=qxNp$*^t87mcNF@0S#A<60C!dna;8g?>Z3GeSNp}uZ0b=-T2-t?vQGF6PN34+v zOO*|81nG=wt27?8Y6f?Zd9`%mTif@a!$!Ga-lX&(uX=4_2MWL33ztX~BbadM>*ig? zde-4RWPxR$fMuqMxwbe$^n9zTMg*GEXildSD} za-W$9aS1CGJkjtXi0$4+54*QeOb^9cplRdIhje<5nYOtF5mnty{)oc5Iv0xW!ZQN( z#ZgEYezuHoR*y*-hE@2{!K)2|o z@@A2zCH!rYWG-$Nc5KZWfPN_L$6)F4G5^g{hun`6o*nZK+5eI!g9JLZ#V(eMP3=_QkreZks8-K?@Tbxek-V{h3)|c-(^F-;}0#Us!2!=bz4o*hj>4E?&%16rE>=t?RIac#0*CAGiT z##Nu6ZAPwQ=kF$*nIZ!yZqp+d&RP_B!otF^0m`f2M5pkNqRmS%+*Oc^^pS_1sYGf} z#5PMWjeXjQ&jjdJ*7O-jXlAP?a8~n8DFyg~R;xADaaUuq)R@+DefW`d0+~{hPqT!j z%^p%Z;$|^-G~SwH14|PWEv1?tIr9u4=h9_( zoJ(-2(d~N9M;Py>CIsu5PZSJ!IIDRO&x9YUu9bU>Qau`W|u{9zp6R;S^f#R<3s@RTks) z{!6-XEGe9`J%T9sVi zA^M(zM_`&5bw{p>^TpFb{LQ_)Ym=%f^u07vqZ`s~zBRVX`I!(#N7+iosn#GWUK3%Sg4?1ci`x zrP02)Puz4_FvWM21zFP*n$#~Ols`jR6T3q`o2i_T10ha>=2$~4TSee z%l4YHYC^=vKEF)5kFrz)NCMr0g8l5>IU!C}40S%4 z=V%KLWSbOm;$)i4c*Se5Vh;1GwV5k@Aq5yg2fUg&%0N4>NOa)==g`)6eh2K=1sV55aRN^Cre^}_B zXp6&EMRGjHsB$8BuF9L8G9j-L7Nvy2?OZ*L%C6h*p`zg- zi54InT|8u6KTbB1K@6So#`r&8P);C9wy~#$g}Sh*$uoIATXJHB2hQYkT~B$Xq^r(ho~t~?)hvLYwDAkJ~p@W?jO`@&?_iBdfkf8biZRpJacmq`-mbm zOJvR@u^HwWQ?wR!Ga&qG%g^2UMlOLa|DzevklmuLtEa83OJ7yXT3!aLZ6<5QncCah zLutH+pF>B^pODMloB7P`qo$}FMkhHkG+Ue$pYX5H%{kTe#vr1nTauR^Yzw%VNHXO- zoNoC|NJACU>G}!&7N_8+eX(6fB zR-;HFHT~JEyp}<08^<^+jd(YkxI)7(!ln?l^R*`D=o2n2NycguP%?Z?E#zt-*X8jT`qyMc(NS zgIu!1=7@ZuBGzSJvqlFt4}Ifz3knl-%}hx*)y{S};F=~ch4aAse9#1-bhA8s$IznU zt`~8<;=L!*8#A^l!uzKD1h-IH7VwV&s|JlHPAbGaUREX;`X(`cNI?DM1uPJKE^NDv zT(e|<1Hl(y!o}TSC+7JFc_z57yfBTs)97z3FzY#F>q15QfZ0C=QO=U4c5K&59fFbk z&5XdlIjgx=k?uDw`Xn%JFQ_4vBjgu#E{M4RKIBL=+Bg$?MOpEYb@zGolW6*J{T^WT&AqBo0?qD>hr>3ww}AL=-K zca(yP;AYqR9&lwQ%vX_&21n-t&Hb>^-(aAl!;{2dIcyoppigQ~Yk$D}vI%8>A185) zB9?$lakXCTofH;s=!#S7Ks|zCKa=!B2}W zqh=ehQStaC%I})SQPg729=m(6-BC=i7r6b7_Lc$S1Fxq=vF5k@*(J~=+hba#4d$dF zbC4;p<-$jlVGbpQdwaE$>bMghV*f8W2=2AL`u9NGG^@a)Z1{7yx zg+y|~*T&oRm}o?IhC`cVl;83cBFd8W5Vtn!1TA1y$6b^6z0TqPmt&%C2fkuwf zpVbrF%#6xCZ+udPw(428K%Ha!GipZvU`Jq1{VIeu!bKJmbCVj)cGzLR%_jr3(XY2ds(t27tg>Qc|kS-uQWWFA?*5Is>!cae!F2My6>$6 zy`wwd?CEW-uj=M3ybp4|U)Jk@MHca#5*7R2O^vF|-H@ECc9#31A3THCQ~r3Ryje=1 zrvIJC_?eSwU;(y2n7#B+4$al$c-B!>Fxx~)$&9WO!F1Qqo3&LJG$gOQoTmkS(|%n& zhbkw10iM#GOx)&sclx7JJ+?>G0J+uUh^62Y4&KB&x}Gy27#UoWKcTEZmRyAw5G~wJ ztAWdI&O`jdWLN_8G{jRKv8w|hdu~zX;4vc5ri&}ie~uaOvZl;i5Zvv#Pd$j2{Xw0e zxV|z=Nz4WTI)-fr=VM?{LRPds7KNV(tvuFSD{y@K^F@P3*`X2yqaF~n?s@8`LxC7o zxty@5(o3kVa`wfjOL4s(K}9ZQtqTZ1|8@=g*@2HF1@6aHM=#5j(?82^;at3QxM@=a z`NeD>#ES=~MF3qB=+d2NKAr&!vkeON=g;)QyFkvLB*6jqMg-KTGP|DZB$JA%I0eRt zD=(fe)O)ZM1y+_pnTBiS(ttgKl<>GOS7!xpHha0lnZE7^A_j}&obaDWhSmhToH4k_ zqH&JXn8%g(kOd>neE83QPCzs(N?caMGA79o1E}x~)FlK`w<+!N1!<9uC)@auOF^{T)JIw=y2TGOp zta?;zBP2#&Q-jh-ERvB^o`AWY7c#$I3U`RYmP#wOjAe&fCZd%xE3xbgxm|e1y}F2_ z6n3m=<%f0R#t`%U{B2)o7}>hxk;QJ>+f=IdQ@7uW#jHD~t5XCHqlZoXONV=zkW#<` z%Rg87UwwQ<>9os{>}{8@2&%U@>txvwSg9`1f5ygw-O0~g@OGl)m*EUk@3nO6mfg&p z9oyog`z5QsG;rbl*t~(vZb{D+SuT0oN5$cSc2w{2e3vy?tMRScqE+p0wa8`6HL3_5t%I{~^W{U-_o}-O z7q5aND-GRRrs*!I(Ks)ivHsf?f2@{D;{jL9Z^VIJ2;0}TPxfsfT}?g>!W)UQc3w$M zqBc{D;T%Wq0Qd?=QObgtiS z2`#yo&$_bjD*hr5cBdkkMcVOP)b}~@!6PN@tH;-?U67xog%VDwOIB}NtaN9cF~QeP zoBWpy&ndRQjpRs4`;K7-(y&y0C8w*YCYW+b`o$Tos(=>~Wq`9Pq9Q|E{L#y~cB^bE z_Qbu*E`*ZrdTdmJ(p_poOX%0}PyA9)g*4s*v4`}FsS1|`6}Rc*eO%r;=N|ExsMk%e z7!*%7%NU^L;sOS+wYVu&XkqMELNcpA&uVh^r43&EpK_oEi;MtzwXTNuArZoIE ztk0My#ZyGq<5PgxdO4_eR%lQj9(+?Wx`g?4zWE>8!00F_)e??r;(n0B7 z6}BmB|6qpkF4jYX>>j4iq%ym2%!_T&aH$nSbBqn@j?Nw9e8zN7bAB(`?n3oN+#G|~ znQz~!k!gIQNGlwQcrwY=h~YmVAj;R~txt|A-nkJ+jgI$PTd}%*(H)Yv z;btKN5-#*%XM30#yZQjvc^9GnN&e;ASd3gdx0#9!+9<3F)7#F)Oo(9qb8w1j>045= zxMl_cx!vr}epaIjOt|~FsY9X$F(wHf$q9036n5ME;Z8m!E;d=iBrS+EPwgB~%)xpK zs}j@?rvL&oyK)}hDQu{ADxUh1OEb7=oKL62zyu^-oS`L9d$vlfL&C1l!{w^9NCD*^ z{=IZhYz4_-U_EU;n^hh9Zn0TM1a@laAhfG{n5ha)vP9sXjL+4a3gi&=(-VUk zQL+zijdQCoLOT)KVGGKNxyjN_K@CwZDNyj1a0C@&?M{NoCmVR|IkL$47FHOKP?B+J zJ{wNn&IP?NK9rMhqOoBE4c2DF3%uYl>l_?#KWy2PTk>(ph~qh;Rh*x4dNEyTy9JH|A@YTcf`B!&Ga z0nSZ&^0HA#-d3Vk5a2{H8e735iASSgVZXzreOtJGv0e1#@tsg2yN+{;sPaZ#RMlF! zrNWwlAcw`B)I9;wMnRg>MwyJ9YQE~_I~dM4S7K@BFD@s~_h6k-Y?MnU9&<+WGQ-MXg5 zB64fKTpZ;3_}#v8NrKdMY$Tbr9ozYeeS^_RYYxln)-9(Zdq~phY`4^(N2)EPW5K{y zeHFEB;b@$$F^?RtUmJS3Etm846)Y3lAzV`G%<$ntDV(mkk*^k(l`r&%eQn)R&BU{J@Z;;GwNMWq8kKpACIzYbZ^^|DFtCO$mK-d!c8<(KtK z?9_xNF+KctnT3=5@_63UOUSNsQ8gEbc>EE*ax|SKk~5q+_D!3_if}ItNWe!)(u0r- z2MV#tJTlmpm(o9*2<^Fnewi)zcG8@;egd^Vg8FMh~|S3B{|N)*8yqlGSfRj+PNyc_h3?%6r=tb<|bT zd2KG1?M7kbkF}pwhVnck*m;l-3XJY*v@iXT4fXQI-JXo5xef--%WYq61G_ebzVGS7 zJA5-lWJ3onAgdQ=%9F?jjAgy+Un2N@Y;W+?QKp04_3_k2O3C@}`R>9tEW@=QDQqbi z5|g8kIrheIK_2m-`UlR%#xs`zB_)+J->R@_J^Mi)yG$?gKZ1`4fl(K+0=t}7YHha) z5=lT7AQAi8`+s08>`Pi|77`H%4Harc&zP2CiigwTrsWZttfvbSKMjaajy#tynd|L7 z@nv!2rLUz*#4njsDimhs-5tPmZ9>u<)9USNb3rC(z8C$Hac996!9}xLOqaCwd_UaE zvX+LzVrub&s=xm{{ke)RZimc4t?kKQXFQ#Gk#nPp^IATHNp$BXZz6pW@iul4OqGrh zo3zJ|b4jFUy!8DED^zPo7JBqq>sZ3Xh!dG7&6_Jq*4KCtRIRi^Pext}jwyaFc|z_n zRFlPUEk#+gO$ggYkrK<#r$iYj>>85h#?dILh8 z4h;yHl;F5m7a-0p)4}7TwgiA!rod%etF<=}H;~K%@?xP1k}b4;8zq9YE>*Y*cF@Ia z9)@&@!8YRW4^Fv?-7)&#?9r+I>DN29TfU$m@-j#Pk)-ESi01kfchJZFD=U^}6=>PIH$~)W zI4OIMF~n&lasR$xBv-{fwey+=JWTX~Bz}h-^SZSjB;wtV05Dt~$L6+goL9z;827ZK z;BM)tk{t?RePhh>_621!g~C58C>E#yMRf;D-!~+lRs!z^S$KhOR|HR<1z6;wn4gpU z_*ue(8E{k)joKS-!yN)zh53jg$67(j?`Z;+N%e#=sAw|6tJHp5#8LmjO6}a%R&C2V zyX70==|xJ{!PP>DsmCyz0Sh(%)pps*BIR68Oy{oNRR9AoN`>}YDuGShgYU;InvqkF zjO0Z7jj55TuIJbH!jWhZ_c~mlq%#A<*0?kh>E;p zT?&pMT%<-L3Isn_XzOa~)+auY%jPL#5~rhE71NDFOkGSHeT@xalLx4umMo5+3A#SG zXmb6eOK8GUIQGd^y=&EY`lH#va%cPTL6~Xa46GcP0fUU4D(H;W>UZEuhrts3@TjQe zEwK4m4`>42%;OdgMFw#Z5{eWv%ge{A=C7;HQ%&ohva%QooLg2+*jrPcP8A(#CSci3 zK(Zvcx8XtGqf}oqnZmFFQOgXZe<6M>13E>}uf^fmF|G&ZzVFO_hb|an5%h#;tRJ1^ z`L0ne`B>Ey>}4KFi-^{9rFahR6OSG|%anw9A+exuSvRS(*bIpKKLBSyn7<15AFYCz zVx;`~=|hWoHL28(j7$Gk*@2ovl+kHH-;sGb*nMQF7VwU_di0Dz7_#wRq!`QUfnZ0P zKNbDvX4xxiuLVT<$g+2e>Ij=>cAL1sG^NNBAgi((2U(orhggL`^#e9ef&G#4cB*(( z^JFLW`N8%M+DD)Ig$bZtZE&+BHLy`?7Ya3K_qYO&AAqMWXYp0L>)x?0c+d-1GbdpQ z-T+>>c*<*S;1pJw7KY6&fws3P@p$lcUiSHEp^ikl%)GHSlO+(r{)0LL z3|;tvB2`Qh4&nTCd;!v7L4k<_4l3N9F*N0OW;$)il>$nAfBb4Y=|8jTeg8sN)cS>~ z1D1kn*4M;MzGuquNC1Zf%4qa0?HpkoIj+?`G}WZ_N;hJ6cW=lMvmYkZJ~R6s58dP3K}hSC>n&lBzN^6d1{B z*!z%s4y8B_@o_w&;bBpTMd}Hl;1b4r8(ofc&yMlLx$5Z|`oI7H4)SnQw%ez3Z#AFk zMOW|(^VLe=VNyhYY@A`cp}9%I4}!_r5=tsQXjfZN6m1>_JUVPn1>-F?X;ccAYrmu% z?9~8XpxgB}P19J+f~Us`r$pLd7)KV!wW^8gAb{Mwg`863DSOdfyD_k+DUs#wl;X4C zng9h4LxN!O8|PvB@TJh2B~)BJQ#l%p*E%X2vPxlgFEv*7`Oa#iu1>U?xjxb7)LA$W zq-ME~g!Z+J)ham+#xW`g7SIWqB%L{Zf!r5*-$94&>iABu)TB2<_R$9kb=N1jNdHUe z^+_tpsR!kWz3vMHQXppKWYrr*`iu_}ItcOu8Hii5Bbn+0=MIikC(`kMiiuJQYu4YT z#U`98O8~$9KU^pV(42U!FH3i>4B+gO>GN(+cm=8D2I!FpH7{5OqgnLxrp&G~nL&EH zGPLIs=CO8TeYdN9O#J(covfYs*Ztv*zTlv*Y%V9 z?G+lzA+loNLuL$s6F;nL_4Om&s5kq`lk94MXWJP;8Zb*I8<6&iX>IAKF+FP(=RpN( zjRJvYo%Vvjee#`hTXO(LX7QBJr~#uFre&*_i0pf_Z@ z3kGqr70o1JIK`mUx%t5Efu7u=%u<_%mG3D?~(u zZ{2FLf_wI0gDY<9wFB6u83YbPUi*I_sVzsk$dX8!wFHWtTg{I!hniJLjLEYJ8)+QtNx3ol$!TUpt< z$gIE`ED808qJGRJn}lyZaL#XOx`5P*E$a)}QY#f3=^~BiuZM>t$V^MgBt=2(RXBQY zhp4@p%u-!DjL*LjZ?uUO!;6TZ+P513cyF!t*r8qo*3Ils%jFsFa7{Y zzw;{emlc;xmft|z@PQOVoof&JHef`7NXJ9hAt;=AtK}#63cgt( z+Vyo<_ofAar>z(7Qt30X*~`$OH2*nGc7aAHJmHLmj;p*dB~fM)pMq7s&U#Ylrzt#r zvB8TXjjQ8PjCideNLJ7b<20xqTIfkKX8n>GqX4$^U`KUUWSQcK@=wl2rAcu4onUW< z{k2m{01Job4#IUk5>vgZ3Z)>)Cx$z;#e+&#sbb?GlcC|IXx85G2*DCHH*O&_72@h! z7gH}x;tOp_RLP<$2D0PjBO9qYY;1ag-t(50w?w~N9qHkK%a$Y~Rf!xvR)Q!#x!;Jj zo+PtSYo4ta5@g*=^K4(!&X z+Z@kS!h_~?FYW}!hfKH(_9usv2po|QX<|)ILICqdv>j7*DTG3UVlb@)IaKW zu?^>dMVJu`ea#i8Gzm9;5jQQK@h4i1#howxc*i(~lS5UP@6rORnm#tDJ7q4uXC3VV)VB;%M2Sg`Nu=djss|~ z<69a`L#_m`q2n9Fy!>1Q{Ku+{WHMY#ba=qVx5>GkFv~qpA`h^!XQGV z)ZX)+;$mwUojb>BlKy7Obnf+&k!T!#eyQC>8vpdQOn@3adVZdrwLu3{S%Du;9Mpu7 z-?MYAnNUT6P(63QX$69t@k>z`mTjX6A9}?Bn$Jn&2qRGONc4NO%!Ht%8iGGHb`57TTMr)V^{e@=L(~}|2 zCFrX--D{7C`xMQpx4?rPdvLZEpjgc>^~~`!p5d?f`Cb+S77^^e{P^l)sr-MAE zohiK)V)|XigU%@MoaBc(Gr`=+F&W3OlD%=4mjQCVYt&enB$+<^j^NndEfWwlCF7X_ z9lyq^?JPi{9%9i4(;r7qz)5#Vs*g8V>UPiyI1>4hMH>b!ylgfMSYvWtBV*f|q3~|H zNVjkHe9MjzH|lV5ZHybI%5rl(GxmsmMW|p4O8s@i@~o-lXlf@oE>pw(thA4n7gAWy zGK)i+AOzLrmsxwM1sQP-Gt(Wg^Ir!zE;2(FGa5ziJCyIj?*@BqyrLTu|HK_Zh^4p0 z@&=`*b;Qwh**Qg#A`MS_R=J9J{t?;dz+o{0(He-aX=eoLktwp@MDnv+Lz6Q zL=Hi`m68lc@BZy<4BMbvOA|XQK4?a>T&4Wyn%1Pbov}(k_s{b#`9X{h%*Tl>L0}LEx{@-X8(yvYTvRacEV3H#9%)U@WXimFL~n2Lo*K*tmtQ z&?_;&6H`3G)Oz05h4#n$FTL=*tQ7iN={e+Q3n4SD3N)H&EAw@$%blI-4y4r(|ED1( z3LAt9n*YIzy(c1lDmsImAR1o*-LmMu%iia)H$?gPt?A089!pRI9weI6sGv_OuW)rF z{7cb8&J*LZG6c(BE?DxU)GQ*=0i4vDo2wO0K&LCx0aJ6(t$NP*(2PY*Cu%fLeNfb| z+x{GN7#G?^e5S7ufRGfk%DjgOAtj;p49_dO*aKINMkRSagsx9UdgNH<48`M0aLuRgcaBCIVk3lzlXZ{>x0 zBC?R!-I>DA*pgP($UqwnP9>l;p5O_Y`Csk(;JuX15ECv$000E5n64Obj;Cmm#UlYT zVF(1RKKD5|GJN+Ik;SH1){rFMu+it{~auUiEM9B)$8k@-Ux>xRKSt4~z26y#y-+ngFP`NjgICm1-f7M6~W zLG`obqPp}$v(R9u{Ye~%o()e_)Kf6cl>Pm1DCFVYTH@A3zFZUZ=v6!cx!xupc`8W2 zPr&g`T?avzp1Kz)YEUD0{Mkc{Y~hQh`6{`La8^vZ#Ku*PRDGj!yxaQX`lta#?Zk{9 zk;`OLD-P7VObrZcdfO_qAf{U`oCGhLd(7*m`4hMTYAR*u6wZ(4sYXkT;SLd6GC3>( ziI=Dog~%qB^a(Uid%yF<=mYM6oqxfG(~Sl+nWRjOo%>VF^cg5^(FRJnk(!^@h3LIs zb#2iT^P}Y}4gUEqgUK1}NqvH44$^@16}gVo*Bt6NF8S3w& z01~TFh24X&O(zp0(P0B1sd~%APG%f0wZ?i0Dm=gQ$r%5eNZo?-+|mt1OD_K`KiPWR z3Cv&yC#R=3%?!rK3k9YgXGWLbjw4g?rt!`MeBpb@F+$9S%-C`QUCa-&2$`>@C1wYd zA-WAF)fgfSEM^^P;Fm%VpuHXi?5|Z|)%kw|YZfH3i2QME3* zawbZL{iXOcV!E|QsQn@XTP8dih*m9t>$qEXudXD$Ac#*bM?z_wIi7!M**I44N)P%o zymtT&c72g}O-G6ot#18xjoyAc4a{G!kg2mY@cA&YCg@+)7juL6gu%0wew9+yo`T(Q zx?26lu$$WZ)k=&-UMG=tY)PJx1xI@6owwSnUt_$rwL_d6_g&J2IV-C2THS#pyB}%4lc>T}@+Z*oObYtj3C%#f$YmHWh?r6Gw*BdD@ zxEG9^P~;0(f3T0z`L(Wu-V8V#Z$*c&^6sx|?XT?R&W#*jqI2tFg^;B^X zL9E2p`N-C&7RmSZZ&v@hWIuk-pzkm;Bv5$2$Rfa|_Z(#QXYjF(@`=5Td6)sxnCax1 zR~cxi**{s6mW?Q-Ln_0BJ_r%-d;_mg^kaA?x)Cem7y(@lsI;*1GrNr79w6ys7 z)*n*T1~q zvUkD*c0k8X9Z&5EDSlQflF|DFy`v&7Av*Y`>e%Ggv;{sgpreMX?+cFoa0NFIzvsc%pO|eFITIU6g@pH2H^rID>|9gpPz*wv_e@I-7#V3;?#TbA}9yQ zAaA)X65@TkJ4elo@an0_KyPR+T=+oq)|Ozzwt2)6KR9)ZidU#JJNwBHeveD`V6nZ= zTE_6Gv~JsUaR^gwgnrP0fdBw;tcPTx-YU(+9gZ}nofuEfYB)+% zbYLG4RjMu}$N|yuRZasCvhGwC=S2fvd=KZKGn*}FsCsEbNAx`9+D`jLMLLNstm40t z8rtzyJi&GZ-YANdsjQzQE*zqh%V;WBV7^?!d8<|8CQsOOm0KV>Q4{xq_E8D@itYqW zJ|?Nozgv8j?JIc{T0mCZ1|u8Gqwz`@p-l|jq_=8oPKZsaT$DSytY%S#$T|FL`0ZIa z+>5qq4-yyZoWO5?fz60|d2MP|0Io*eM%jvq^2#IV2J%*Qm@ao>`3p z)K-)>$FH}*Lc@HYqPTvU=Utg^3WSGqML_u|23h{i;8R{dfyZ#e+bIig9WTT0WZ{<)NR z2@;uf{V~D63@{U3=X?R`k;7yUrz=}INl}Tg^HVS>WAt6KFkxN80KE>gwd-;cJJY9+ zg^2Zs1p$)0I1+TyeJ&0y$2yp9-yl!OGBnhGe=V{nt;|`&^6Y0Ite6HVWE!oll}|kL z%X5t%3873@U2PqOle5g!6PIU#NK&0Z!hEHH!XK0 zNuXfjNy-R8C@cF1#Wq8M%*_)bEW?B^bI|T|;U+5Cb3I~t%wB8SrU_ZFXcu7+c8&12)*k<*=(Z~&Y!#}7DMc$JmMLWgB- z)^SG#SPPXZ0NBD|*be#MhCl{=<`g4iR}(|gV8d(rDnK6Bi6#TNFFvUE*3xMa5siK< z$Gq*0lXZpN{U6LN{3OdM;jAx3f%}mTuD{4KXX^E*x5%K#%rCPW62#bv21uUTKT7|1 z^&;Ovra8vuJr8Sl6LE*9aKCVcS6emIyT7j^6oS_^d~CqQ^9S}g8C*H4_tFh25gl{M zM(&p}=!HHT3k@aks?mPko_-$|fsp{jzYzn{s+>A7xX`oQAeI0^tD zyYd0t`5qKy?R0_DsSy=159LS;)v*uuDz445Zk++e^$71bsza!viH~6xumHZQGpg*F zg$8RQPMuYoO;=xltejd39GI4|+*g9RP?IABd|#FC8kD7X0lCa4d<0`s$QyV!&C^97 zhHV7J^7k6`6}?%LSm6{qjMrB5J4xX-jIYp^O7R7sCfXtt;A+V`dkGt`25IQ6Zi2^w z(=;$B)I=F&KD``BQQEi7HCQB24-MdrA*{N16fq5$99UquWZk=2dBOOipqkRemySD* zQr#PPYVArUXoI5%<7?C)L7QgBtqu$iAiHqdRKbjept?)&>_cMttx3}|S0dyCZ%B7r z5jeE@LzE4$_!eAz73G~vMM(b*G`XznI+e6m!O=KbXcrJKrMMoDa7KiVgvdnk+qScm53nKY zKI}jM9kMm0AIGzp=5JH75NihN51TzZ;o3vlP^7g53#MNk>beuF`sDgaJY4-Fj)HQ- zW^&4R=B#VoAv-KIJhZ?uyo$~yjQWQZt1#sE~Q6ed0X|h9LD9H`N&ka=@JdQOCW5lY_Fej$XP1(<# z|MjGf*}c(DQL`}lVXO|SIvjZH;zhdJ{eA6-PewN&KrkJNcIBj-SlFF!Pg6ky4^-?P zM?txRYnfshruN@H++yX^HG=j(M;)d!kM@rg4>0||3}$nYm&rD?f4Q|ADi;}kyyWXm z13L<^^zEN%4oF+dk(uVWFwh9X)!yp6&huZHz^ldRNRZ{c7tr=;_``W+MhzxV2>hLM z{pmt7}y;!4k6pqqy3M z$r*F3?P1$KkVsFQ49;#rGfXNsvXN>Y38rvv)uu(<2&60Hwo0hMy>fAb^Kf~P3_7@J zf7E)6Y%CrhKejDE2w6x$XY)lQ`tR(?O?r69tRq6=rH#U~P#@2_QzMOaBxP1ZSa=EA zi+4Ib8NscF&O%>)uGYy>t8E#hVd}i2pgWd$Bh$UFkEGfhiPZ;W51_Qs%QCkz?oxGb z(y^-vUT78rJVpVW^G4;I!g|RqYU1d|LJ1PrpGuqu{ph#U@lx2T%Yr?P47T!AjqXWi z`D%h2`?k)dp*vGk!2TpE=pTLWm}uYU0auxE^%c^uNkcyG;C7>&w!zl!D$8#4>1J5-JfG-o_BuPvpI?D~{nTeWE3 z>3Cu{NT^NX0-cBm%hm*f+&Qt5YIpA@Mrm!Zrzg&l`n8p}qPFAA+omdEE=c7y1VVC6 zytVwFI99(Sd}AHSFd!(QgNGlYRJK z`oi1z>Ps9ZNEt>ENi*Vf6OhU$e(K7Ouag5|Fn?f0s+xj7b7=U)!p_ccr!*t~H|lsePQYkf5Ro50xE&uqKe zw`vzz@VJfck)ATSXa{qkp$cN89y7OhMLZ!;pO3SX`2Ts%brTmbmCbZv9*e>XVpHQ6gsqBwM+dHA}$)UH1+s>MMwXdWEws?2xY zW)0Q6jqsMU*b$ZhD}HHkoG8`$FtjsG3%1l~IK>QW^(AFc7#Q_kr$`Arv8_P3wP%(7 zw38q1P7Hty$n<6w~7QdjYrE2f>{xIeaw0VK#IOm97D_F+%kQgx_TGRET9Nn*g@# z7ZL$JlnUVro!7z<5>bb^Xy9czR>J?IzZ&DLn7_ELPR^E!#eWM+@cZ@En3EMg)dt6L zHR@cAfMecgj3qschr`R|8SK2Mfa|dPYL8z)w7Pm%zylC7pYLb@?APV~^fp&M7ZbNs z3YUSpE@KNiG|bW!1JAE==sEwVd_^r~YaJjZ2$`qIW`e;kL=dR$zEP)-f2@egNOIWV zs$pHF7LOs_5{}A2_x~Z4HqMb#2S@f$co=ZL7GErtaK+GcR{79b2WwDwc``TbC&ok$ zm}jS6cOU>Z$OHZJ!&37RnLtGp$xI=?!ITGZpCDt$r|mw7av#pZH$c*lXO_{T2Gv0NadgoWTvLCN8DzKy^%gZ`|7a!xp2slv&*nEuuN zZzahjMkK&5HhpUq#;=C8O}?P;FLw9SkjV_1vZrzcy%rJxY;$Q@a0QXS_-)r|!Om_m z39KF>G z;|a7TpU_1Leu+-wmP+m^0IiXQltONsepL^@JY4lq%En5Iqa`X9g3o(1*X?OQ5O`Tm z6Xm3?D!5tWG!<+KWk&5g2kZ$#twxELeQ8LQH%U)bkVe64S_E=PO?|ckTEa=fUCyL9{I8g!zCCmN=f z>>n15(Fp4a6PuTM;IX?uacT8m`q{-c)vO#3sISdROmhgDQQe8hQQKPuk=so#&0HyF zOfD7dWuUK!)G)Nc*yTEMKmmYAJHl<~BRpq0ZV(m_ZCobL_-?&-4oU~mXFp-~e4l4= za;R-v_qbPLZ#8Y5SJ=W}xJT}Ey8!8w02L|-c%?0wAF9A@LUK;}fT7n#NYYF>vktv_ z!%!E&%kkIE6b=Rv6iqi@#%xky;eB{WcFMG(nf=PZiXx>T$zG~-9j^CuU0{;_t*#W_EldRST6ooM9w%GtW1fE4%+MBap+r&4ggou_1 z;%)aY8>5`2(l>QR!43;{;~X%i#(JNyH)W(F*y1*aQP)*rX=4hqS^fUCxB^-Vj(OGT z_w#&EF9+@i9qS;2o3ZCbjOaEJKPmqFpU)Ev_Ze(_tl9KgD<5w(cSqdsWc&DKAL%Sq z2|QLt0*Ok>LP|?C+~6GW-?dnK2?=)MpP%!{Z8l#L(#zZ@=Qm%Iq{7o`B)h}7@;P7f z<69T-n+t5GI3LysIk)2KBh@ye3@qgbzr4;b8)}TkN*?b{vM5A%URlt(OgIzj`ln_i z?vXhK+w!mKbtwLB+LOUTC!Gt#q7qJWh)@bt=$_e-!?rAt520la=LPEK%W##BXNyrA z+FY=+iH%{fHj4-XkCcy;5@i{n4$--Abl$jpKr3Jwx*6zPxi06Rt@%wl9uzz)dl+y# zUf;6x7J?fwLM(*FkINazdQhZ~|9DE&Uv{_I{;BrhRC2D%&Z`?+911yX1_zh3;X4Z) zoznw^f$_uwCwG7Axpx$RYbFm1ILZM0fizitz>m_2#2Vsw;Oq|W05gKrq5m)@)5qnv z&U&w9F&5+{08}DD%W9$iF;R;UUhR>)^B)$u0LW74q-U(h>@olV037G~@yzWNf%vi3 zB9oTVp(X0WFm^5)2t=KjgvD7wOp03%7ylYi9FisU^P;N9v$V~QMQr1@S;B1bAw1{6 z6K&|*q_lbrk*0zKMaQT*+iRtp{!M(`?#%JQJ(}kaMu1H7I)BDeuAiFJKRkj^T)@r+ z&3x~Oy`S%enn05G5dTBz|FSx`F-EDUZ&!6&9)*$Cea{aHhRC?uf=N?oM&0pUlJ1PM6`sL1RRt|W35scDer%x2 zp?RxxJkCYEzkVk(p zBB2Ep(+APcus@4*Y4wpR(9CHbivfV>E*&00l1f=x|BukVaViv&G%Q+y#@YTJtP?|G=dOm%&Gw^B!z~I8;j#Y3%s&_|6uziS8E<-Ejg2-5}EXwVZmk>f;=3Y zje53YtY4Mn2@3V=Z$q);?FywTtrekozc8tSnOLG`?~<9JHJ+QO^Ko165Mqi$v)^bGfD+% z8$tzrk^H=1V1qsb3uSGpXb6ylED~S81pD|0G~8m18M?GDd_B<2BTIP_TS~C{8tsJF zg473)15c#KRKxe&Sy^_+Y9~YwO@y#XJqSrP#`D5=O};wQ(loMI#C6FdBukxEAm~Sg z0s}dCw(aHvc}1^!mIx}?-ewKMw3xR*T!7{A7k(U7*iJCD0IfSxx>7)Mm|K9%n~G1( zw&u5BlVXUawTEMM%H7%3N7@HpYWKAmP`z-D>^SGK1u&d3(r#s+=}=*#Z_#+Pf7G@L zX229O)JJj_|I4i{Q01SV{>C7!Iby-m}fY?_j>Q?icd*BR$3;z8+>KCA7KCI{_tW=E>DoZF> z`MaY;+iS`^7wXC~MJC_`S`%WFZ#(1aZf=`gt=A)?k=LYL6`^QcPEG|9yg`rHmrbLf zz3E-qvbgBk-GE^)M5NA9ymx@ujF#Gv_`XAF!_h!gsmioaKqT z?#nVmKSIfj1q0F*@SN@n1oh+iiHR>*3~vfSL~TgcHs#`mhveloHG;b8zNC=(FF%PQJ{`whU zumHpAzO}d!D{+d`>IcuI59Bo50pL9Q`=J%unvW-;^j`|!wTE8J*ea(3wC5m-6~NZ3ygsX&Md_uA08i`*z^#?MD75_-wv z0ndWoHC>s@blnqDOF*5@^jV9hCfixgbg7oWxC%KD=ZnU_>ZLbN>?KGY)u4Ltq${`Dmt8{-y0y~ zzTpj^q3@DfsoHzW=MRoH_bswN5^Dgc2l8N5S1u?du`jAS%P&jVJZJga`G|qelHFic zfm$<8X62MZxr+ip-J0r0oyERgH^U+%SmLBbuLdvxGQCV5UcTH7dZ5uCRcGBy3w!nG zDujE5+9Rys%a{NFWeL=5O@YwtIOY_E4PPL)p$F1*ngI3y03pm_M5X+200+ObiPUUP zS%xf=(fBV^_%+aURCEEwx0EChCBsxA%fQ)a??l^w*n0q{INpV}ue7;#?$cO-zm;Z;WPRHV zN2%Zq_2e39s(2u;t^@+P!xHmiivcQhXA4?!%B(qm4aKdTaa~sDZ@4Ok7MNvkgp-x8 z(#92J3>Rj>!GY_Rl0ikb_EA{ zO&(ZJzIF`v8fHB4D0E)z;WL|4iR{XSZ+_u6%=WJJbZsRNouVEU`dI+=FaVaOL_W#6 z>oQi~^bi;QID^q5f<35{Nr(+^;pf}+3?{}(T7C#qlkVRyT#I6tl%JkEzjO>iqn1z` zov_G))A0y70i;bktnzCaUDZHDkbIUzhv};e1Ksp(>Zu>d{2o4@bPlHxk;pVa-^EU6 zO4HOU>(WkqVQ-GxXzHY1wJc>o=)B7ep{@A{Nl24Zbc@n=1aAJDkRnIR#=X3-spgSU zM@)KtWc3E4*-Lr-eSg7hY76V_YCmWE*xIyK$ z-{D+;uyJXQo2)2Xp?%}Jvni>BO*3wzus1Vv-pq3>w&_&MS~8LygCt~9NAOVtLQP}QCLj)}quB}ZMi9cX2qc{TNJh?`yorn3di7BVV2N*ZG|0%MH;?~1 zb)(=n0y=_K+zZ^#hTk6OhPZrzS0V1^0lXOd%4kDgL#Q^kjnN5 zN49ASZ3@v%poEXUQAXTlk@MZ1F8AwRH&ywUc%4#+`k(YouTVr-)Jn9M9ABKX30>7W zzdI<`oPdQF^16CZ#2Ge_zJ$cw-W==skYv=xMeoO@@90l!eVt&ZCtI8AUf26F`9V_! zrp*}|9;^jJ$(?A=Y5tJgL<2a-b7=T}-!doQzu=h$7- z^7J0qkLe*t3pc6zadb3hUF1cWaPy8;k3a9DtR16A-q>O|)SZKO^f|+x>P#2MhjTBu zCc!GghZpd4XY88Re@(4E!IXBn)aM1|@=d-p>*3fMd$asm9X1B zsah*pmk6&lII6$?+`z9r13DMeC}=AA!p@shsf{Mpvf$ums!CmY?SNcYw#F{#?LOE< zPPpowpsGxu%<5&Zb&iV1hrSE< zshH&ojLVS-dQq+so+bfeHn+SUWa&OV=&fC{MLd#P;yPIFwVGyDFH7e1DIZAsC?t93YIP) zAUP;(uhYu4A$k<%dbWdiY^0VQQX3sG9>KN`@=U>zF_biQsSm~?9JlW7{S zqdKbj*yS&N->KDCJu#!e@jEj*@AS3ixqxH|!?Bz`7{a*91Cn?f$Llh@6IC3Nw{j-) zaBlnb7VztKrUH3Th;0+UqG0YY+O1(JO{3UHvCxn+gY{1JH|(u(OJp*ERW~qlu;bh( zAoLB@oE%iLPE9l(A5;qy_vx$_;_&6ZpyD;7^vwj9W-_)&nLt+6oUM*UQ%b_p*KKTI|-YXsUFTDKulh8oeSQpD-;6Ly$Mf+_Dx+nA*i2jRB{kkqD1dK5w`O?@jjLNp~5yx z#dr1S6~73ow%Deox1?*9k%g?M9nBFt@QJy9`XyN7J^hXj835It9)6Ia`YnbIO&#BW zy)}$r`!dCeHGQWOroWRzgw|SV|_7gw10cq0m0Nul=buc%XAe=Jq@46 zyNnaOR{hYDoV`6*(ezh%0z7^V&D{d`Ai(8OGa4i9rWhpY-{+9;k>|CRK=?_7u%(1e z*s;U*1#{pg9^5jvHE}i|^Wnl_oMqd8l(SPdjI=Y6O>9E4_d69JI@VVAXX>OW|6Dt^*?aaiSHAvx_3tvaI%{avI{DuDeJ}cW#{k=cm zmYUqw|NSBLl;*M`3E|ijBE*Ri2AA=Kjc(qV$Dz_2^i0mv=!jmC7Gk|9274^OxvIW& ztQ~FwtD@OLc&+(LUe7s2x#8Mx4_@g_y^MdPIwh>`#_eFGI#l9M zkpIJ$2!(w$Ryt$1&`|Srej`NI^*75A`_d2=)p&vini|!$Z%Q>j)6bsAWrh%8Yjko9 znq+0-6LZ`%hoiOHB)tU0dJ&JTpsO;ZOtlZ3bwN_S0YzXbV^U8S*b0nL=Z>vKEXmZa z;2MH`n*H#xU0LcPe9tm7oN3-L+O1(G$`e6vMINM2KZ)uneB16h2PYddCsn2EmgUbu zI?OGR*E);)mUzm$$IfD&*mITemV$f>GRU42pjUR|BfTJ58hxBh=W9ybY6ZgX`*8_L zL2FZlr%2~xNxKTT@Pvda5H$E`wUIh&^=9_g6$3uH_l9QAzHcm$A`nm- zvHTvPRtwIUu~3hPOZ5SNa`Qf;mqayuX^%SM?|SLG4fs&ADzP2~6(u?M9U?9SGkDOm zUV89t5*m8|z>iaYZ&CcG>hU`5wT`V?T=+hSM%s={?mV)n@JtBL^`d!M6oo>)Z)sFU z1CF7%6feEUHy5!dgE^Vv<>0pPf=v%r0-@docX=cM*1xCU=gLCXfzdL4mx^y#p}x7V0Q{)7f`M~@VhR8j>`(JSysS(AIe&-5Z33HWp}86 zYr0CpbX?@?^ByG+c;N8Bq%CLQ<{iPI+=U$}+<25PB0;eK#iwt4XEfXbowP3aQeIkS z{vWXi!n-5s$cFYS?Ky~sCeGs~>8Fwl@hz|?{~rrr>`7?3OxN#U$oY1p1pe1gwMG$O z{m4ng{DYyHGmAQEv`e`2(BvkALWcYz(|)iMMMg9DqJT&yBq1yonI0Vg8%-2PN$+4?%|?It|up0`lvb`#zfOX((g-r0yGF#Op8@16)d0oU0F z^k@RbIi|DtRp%O=7XzLaqIN1-t`RQ2@1~uM_v1rGlvk%&J|G}k_?7YB zJXy=75|?Ubd`S7TMVfpABq;47K>!=v?jDCkUNy}tCw`lQ*87>!k1|QV(Fuovf(yg5 z2(OHvjZq6=e}tZp?UU}OB+9i%R2yJ>yeO&14Q#0Yj+RjzM6MZU{mD?0mz^5J(#ap20W`(17kt_mTkT0>WgcCIUWO+dJbo!Z&&#GmbW^ z%!ru#Cym%Uezg#EvUxY3HEd<)PqVP332;w<0n^BDmJCTt9@UNq=ynFcH@w6}lC|HNkBe&bNYXm9I(S*0@h7y7x<)$n zYU*K~K`hSTm*e554Ugss`lI9`G5L1*{$U>qGc6PFEuB!ql_vHpK>!vy}(W6HA1s3=f#@tx4@VFZ= z-|cvAI%N6UE|A&8Ni>3@W<=3!ys8A`UvR`T&IHO}CFhI_YbAnDbWS^1O#ABL5>Z2@ z^^SBgmc!};s;+g0M^XB`@^fQ!-X_tQ+Ib%;BRS{Oy|WV#B|TYvkQkLpp}c=ivi$X( zyZCNUM_FUe`w=;3cpQ~lQmvR?NKX9fK_qZK7)eP8-kECV^c&G+E%hJ(nL^V_czbEf z{?%Nov%0Jqu}a| z$d~NxY`?JtHgq*T<{ko#r?@#5om#x<9tn1quCJ~at?l1Cu-_oFgj>zqpA{MQoh|Y9 zE4H|4pUjeG9`pte5ps+$M$^38r#VRyTfJ_oTEXa(V4FUwExwodvNzYmc*z4j+6EZ< zcB*1nHP?-kcD3UH zPF-N3a_jszoF(y~?qO?)V&-=N*7&n;A>#ZStRN9@qE9IGHs>WILEot2NEF`#I^4<5=ovN;W zYWkV(e_f}}^mHHmvUN-7`!(1t*^XkiEp^eI<=}vA>}_fP_COT6^G5RJdWpcjTShM& zSTpilhL(`~c&rD2*O;Npi89(>-VFfE?5Qvt4Kxw(%&b0LQM!!4a?TtPiuXb3dU9*I zF4$tJW&k9JB+es{A@He$*C7iXA^)PTm7HS}X%VdjnEP@oNl$m1 zxo>5xqkX=ElAi>`lIhqXG59$&Tw&LGkjS^Y3;ym6D-~W?LJNqVN{X>&-G6zFK9WTh z7&o6q{UiFGMPSWwbV`*HV^^E5lKlBc=*tAl1c&XuWUPDO+u@sw`)!gifV+b5e31uc zgJV+YA8x<1rRH72GY{QX@ZH(mA+!=&0P>Qq?!E@s#;Hik$G4v*8A)!}Z4D7yUF(84!A2Erqhs4Mne(p6GSswvGcsishx?)K3JB4voWgfWWV_w~!g z`wbqb7lBlXcbWtb3G+1GPC$lk)wRbCHD?=mN>I>x={7y#p=5Zs%MhSf$~t=}l|kqfPC`4# zsD1q}mxFSAE;!&ck@y&eD<65QzxZC(UMZx{~_pUbWI!YG)4l11;?M4sZ$QpY!+ z$ax9gAo2udT9Z~aK*LYaYOjP?t}Ph|ZHN}IG%ACBx~b4Z+!S}qq}Drr9oQnBT?jzM z2To-|FMhnM!?BKSvZ~nC+MHXG<#NPg1^jm1F3|sWuQytuzSJQhzxv(T3`T4$b&~@A zDorh}XLpflI~49Ufb30)qLlTTm<-gCu^$ZcW~{7lTe?1Cp=%ch=DlNd4qdM?9i+U< z=aJDODgTT~L%C(Z+GvBeq<&JLBH|kz88lDYhhsIUu_TJV1pGWYTJ3)b3GOMT)Z_Qu zN}tlu_QXRDFRzwyg(Wp^*b%$IKN(QJkN*Iq7ANi*=%;i)izROY8c9O`Fh6c$%@mAF zGj2-Baj2u^=z91dp<@pm5PfBV{!rwuIf=68LhXopl8&vt{U+yRN~7#Y!J(bPmK8KJ zE9^Ku6B`Fw{!Mf4DQn?^%ws{;GggD<)AI46cCMEpYRL0}(tNZ#VO4>;71igSNHF5> zmOSn0q_T<6Y)53Nt7Rj;^BuczeeZhL1tSf{`|)T^k_P&6!B2aaZ}YklNE6^nV2;%C zS_Kk}TT-0;p|plW7^0F>li4mc&@UaL-W#GM{awkhKMRNb)UD80h>Kby`e#+7GI@-J zl>jRBMqQ0L-yZ5s7WwP1w`nj?C?fi0;<%my58=m9#121JE)d6jk#mRqIqlteRvAuL zl|%2Bz~VfS<|KhgtRR=Ji^FlK0Rl5ksKkb71Q3HK1wfJ<#jS!(K`FQG0=2C82_Z<6XCr7Q;A^>-5Ol-DvgdwyjbjO|-~lCjA2`QG!kk>)A$^&Pu3$ zvO4Sn=#ej^ScP5Q0nRS&o^gvAw>}@OIQTb1oS268jbMNHN_ZnwFX~12VAA(mY&OD5ze8Iq z(aTOejT6*#2gUUFY|yLM{U&Zfl)^+7e!s4G#ethjlU^rm_vk`(>3=)CZ&Qp(Oa<0) zrIds-#(}v;9AANMYVURfzH9xpbc=Ro;nk2x7~UkrHqt0oU=DN)5$d>wbtFj=p4pmE zQF}b1TEDvbqgZTjSbH{K^_!R<)^%5AW9@wry*FK;?@Oml=kSJ_Uo3;d+G^rYY95JU zYyM^%0|}SJZPbo-A9U1(Cqgghy|g4h4J0Y+V>(MvzeW1Rsc<ROYdzHAd$KQwf z3osR{IQeB?ri&QGq%Mn~S(Aao{O_Y`Xyq~oaWFf6XDa^cn1rmCLRxM~ke+#mJyrDy z$3qcea^TB#H0p9KF2;lQ9G^h`UaL=t`Wo`5D@(UuCb{Jz@R-Irx#z2C$6oYop2Z*| z@bA2#?sp(U;~0&P&K0BMK#8p$JZbORys65V=_ncIpl26}8?p_Obv}Qhclr3NEq=p^ zXAxR-i-z_JW((Ow_H)xqDN^*-<2iZidt9zl^J@!UesfRtEUV^0_>$bC^=SFH<}h=b zfZj$GpX*V;S-6=&TIN~M>^KU)03LeR`RwIJzoE@19Ml&4JctlB@An0XqzO@dF2v5M z7~z0VGR~36Q~XsMH`%7B*OlhU-UcMAzpd90$Ts4+S0)7Yl;VS&#f)8h87F~7Q#WOB ziGB$OlE`b0b_Rt@C-ACGN%B5)=8$on-a@C_+^4Mj=EVm6zHu~C{J zW4J)&B%aQBtiN5_RwPyu2m)V2b)R;>Kz2=|L+H>Aeg<}^A4z&bct4y#f`KJ%KfX(X zdhBZZ8XlU~KURS;KrN6Z#1)n{i;MVvA8o*IrJgOT&xhOHdu}1C4p$@>!8K(c?6~m9 z4h-*z3e_&P19Rwpxm|I--u3H}Ag@-#b{4X+6q`*vk9@a{hPAWda?8lReXkoP?jx2r zo}?9Dh1EJpZl95v7x^*Xv}{0!%^JMU&!nhBY8oiXoe$5LVbLV^RiwC5sJSKG;bY21 zM%&RHZ|BWy(Xgr>AG$kWa1PK7@GGia9S|2Rq0eg{8N?E|C|43z4vDxeW!ip(u+zQ~ zB9XyPf=d*BC5t|KHtH__Y`yku&r`n_qxi}AL3n)I{9>qR3WdokJ!K)wG2azI67+Ft=&3My!d14YYGE}? z#v%49jjH=2cj?JC;j%E^(M8M>oeAz$VQIEZH^f(Kodqm4tuC3^mm!x&c_%#y>oLiP z8H4DzaW>Ab`J66WKF!Sa^ zFM)J@aPB^dks@AX`vhTz``tu=KVOhzRkv(c#pJ&?cT zUN*^`d)k>c32pikZ5f$hXDgsnm{?K8p5J4dc0o$ejL@IqI#$)f^9Js|;?^J^_^hqT zB~{sgVuPV}0dg#!4OK7#ROl{_q^)#NIE;54WdqX{rH{jV0`I6ixi>IjJC9!TYO>q z0;E6xszq{mK&vK}Y~P+kkD`Lq(Jbi50#pS57J~zk+FsWpPu~aej${e1+wv(;TE=(q zeL=&Xn9?MkLLVa$d{QwDVHDDcl4qg&4htfs_?OOC7M$X zbqOX2#P@KoC<_y@mX#VVP(#w{o}^3a@El?#MSVTdoD3I-%BWBJY*u`L(#_n(x0 zeu>!8R{Ai)MK5GpaVhW`wGdfC>tYy{0?U${oh7z7TXd)pU4H8a_5Lt&b}pmLg`QPO zY@1F9w>OQf_KgUanv~ZK0p^oH-GH8tMU-00p4l2(F1Rd3^IgK)Ixv3{@#bR)ah>Ge z-ZMGK{M_m3Q+DezobxX|7iK+AdYrcm_04{FV=T(g)a;LCwY~D7zTF~Ae0bAk=9-h! z>eQS?AY9CVA4@)ha?Qht&2*=X#IPSpLOgcBP6jY`U4uNyJGIUS^5w200b--g>ueS4 zKE-_y(ZQ+e_**ZoG!RZj!6~Hl8<@#I{k0y9>15H5oA~9uxtIWX%I)DC%ueTk-QQ%= z1d_Eh*Y@)}SYvnZAPR3B4{G~8O*mLTHVs|Q4Jo_Izsp`jByc_8YZ{xAqslHCcLCB@ zGqnLzAK9@^*YF6MqaO2Zvyo^)&Hdmm${A1cj} zGU@uTMM?;Bzxj;pWGAP?mJ|W4$!y|mAS%KH&rJ@Vw;{ZBrs3Y<6Ieo-Q0dDz<{-z! zVVnLfG0q{JXF9+5gs}5)Yb^}lz#+SrUZ}BLrzAK%4>fcuNXCAOIu2V=78*U0@^pE| z%b(ypCUFb&b_W91>&2zl(;L>GyvcG&N3R_hm^VZ2KQ$(bHN(;B=z|P^YKc5r;zmW{ z;7G$inQNNc+yR#jI257M%EO1_B=!qeg~qpu{hd7)EiYrQ9sfFo2*~I~cv8 z0qQE31?DvK9!V=!t)EqYcmDWmUsv3pW#KIads*WBoRf$@AEt?0m3dHEK(cj2bx9nW zQ@v4IT&s&(bc_|*p`yCKd#40mn(@rqwBJ}XjM)nsWi?w`DXL@Aa?b5rIcjc%Bvr7l zmkC)u>#kO!8@G-DI&#aLgY9z0TqCnOv8g0pL8&gb>B{v<{pE?uS3KSx?hNEeCiPS( zAHr}+w7xN)SFC9*Ryp&jEq74NldmbRQKfGXumKwdMw@!4bk)$fs1&{;+qz^#pK%6mx zhHJ&D@AHL&{ZkN(NiDel^6|3A*=k$xO~ZrH79aIfWDJV#ImN!*a2jCxeiy=$0K7st z#^#t2L*!L*lovPVQ2t#-S= zsnoStSYLPamEaeo*tJvh?TqMDJH3Buwf*9r3SeznhmraVyz?~!Z6yNMziIuLZKRt^ zZ63{MaAeLm@P%>)}T_693O~XGPOn7gLTosqP-Pt&?Z1tNCRoZ)LP|W;!dg#iEHEG@%@;*JV?b`y z{0Sw5vGacnGeR$6Ltb#KpI&iAV|EO^fC*e2PZs1Wj681AbgSZ@PY6@7)O-nMRxaxD z(O5N#%Da4DlSvc&55129NPYj>`q>OvHsU329ZNprFnD5XEty|&zY$SBJOUF9s+0k4 zxA+g@GgKq=<;M)dwWJs?C%ridZ4@*x5N=A;uQX?~1<@>RZdfZvJ(-?)cH#vV=NU%oqm3OlA!S`aoDAsEN zITEq`bAyGgJmy{7{+mHB?M6DADl>Z9ohfqeA!NjF z^_;$pN-VDWd|QkIhtJO%H|HTBhV=%RQau4G>H^r0Vj@0-fw{WAYy=$O6A}*dG-th! zXOfUaRVX_`x;lBAIXxsPx-l$AQps>?$_WgIq~-)&W0#ZVebqIT7503;cr(*}Nw!ju zT%Sfi2Q*!fC3-%d+&85qouDQE9OsaEZ{4yNz#wTscA0oKGlcm;>{n#K`hW~%t0Ly4 z(k9Mt0@wFLN11H-P!ln?)PW6p9wQt@h`o_RuXK)M@p_Ymo;Ntbd`9C9H3dsVvM#mI zC9_@Gpf7gfLhU8sfp-fGg7};u=E^vv`loaCD#H<9z1N7@0|! z%0$K##+Sj~56eXU&pgvx0D$?r60k` zmf5K;nx|a{J);`(kQWXP4nd0`d-V^Opb(_7B5S<;QB#|v0yPdYk>LWSv2RR0f5R6JfZ!!Dxw(A|i;AdahLlE4vKtcOS$xvp)!Zy1XqjG*Q~&q_iT+XA7u9?%9wqLt)WXx0#+B9d}b$bs~)xo@P*Y}5^|`h=qB+kwu8ZIma}u^Z40 z^E4<1k_VYRN`~LEC0rF}0|jOiJIvl#zMeR@r8&W(CXll7PB$3OZPVvi(hp|RfR2%R z9{Z5*PC{7R$IyThVnJy#`#h`+oAkCW!vC#u@2wU$K-<`%hVys(vrf5jK55qLVz4+$ z{`s${Ws0K9HLw{=i7@NJMoXGF**_1|i0n@c8kUPV>cU3j6O-Oth|$ zNN8r8K3HglpYv`f+98NJxmYy@Rt*yWL9%{r0rFW&YUnf0U7mnBfBX&0_~6(F3`QIK zZ25DE$8J+~K^&pw^!HGy1?j4!1UB&i zl9iU<+jQ24*fUw_xG@#Hw&I1si_;7ymr`XvcuaqO2=~Zz!Fl?m-Rnd~ZvuJJ%=R^YuxKCaOZE5)QCs@sLl`b zHCEzTFr@`1I zO@&|4IPK^_Hg3cdhhADuU}`<%`>E=_;--N~_zszY=Rh*`qi3*iZG%){Pua*59Rq{9<@My{sRRAd z=rbZkhb;fk7+jdc`mb6(cedTTn5n|-J!u3ep5Ln=H$T#~RKvSXmK}YAK?c`OIq#pv zV*Xn0xVPYC>vY(HcprQ38@@lRd{^G<@vmqc%-{zJF|1nzfh&1p=;_Dx0D!!avck(; z8Gy1fJK$f2M1A=hMgkzbpnpPvfbu_W@PaA-!|z`(>wg@?7tDu%2q1XTb}!->iTppl z&kO#yEMDZFpZ}+|EFGOaxHaVU=!CfWxcT^AQVIZ&ga$x<;qdYc@FGC|e{4j^|Mlhe nVnq56-@ODx`44}8IrDEJzC=L$p9dW=(HHceH$Gn8f7bs42V5{w From 59731018ae3b5f8eef36089d97995894c511104b Mon Sep 17 00:00:00 2001 From: Kunle Lawani Date: Tue, 18 Aug 2026 13:08:31 +0100 Subject: [PATCH 8/8] fix(auditor/10.9): correct Azure Files permission display and exclusion scope docs Clarifies that only users/groups migrated to Entra ID from a local domain and added directly to RBAC/NTFS permissions appear by default (not cloud-only Entra ID accounts), and documents resource group exclusion and the User Activity omit list type for Azure Files monitoring plans. Generated with AI Co-Authored-By: Claude Code --- docs/auditor/10.9/admin/monitoringplans/azurefiles.md | 4 ++-- docs/auditor/10.9/configuration/azurefiles/stateintime.md | 7 ++++--- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/auditor/10.9/admin/monitoringplans/azurefiles.md b/docs/auditor/10.9/admin/monitoringplans/azurefiles.md index 08a5b50db9..b11285685b 100644 --- a/docs/auditor/10.9/admin/monitoringplans/azurefiles.md +++ b/docs/auditor/10.9/admin/monitoringplans/azurefiles.md @@ -67,8 +67,8 @@ Create monitoring plans for Azure Files to track file and folder changes across What you can exclude depends on the monitored item type: -- **Azure Subscription items** – On the item's **Scope** tab, exclude specific **storage accounts** by name so Netwrix Auditor skips them entirely for this subscription. -- **Azure Storage Account items** – On the item's **Scope** tab, use the **Omit List** to exclude specific shares, folders, or files (Universal Naming Convention (UNC) paths). Choose **All** to exclude an object from all data collection, or **SiT** to exclude it from State-in-Time snapshots only. See [Configuring the monitoring scope (omit lists)](/docs/auditor/10.9/configuration/azurefiles/stateintime.md#configuring-the-monitoring-scope-omit-lists) for details. +- **Azure Subscription items** – On the item's **Scope** tab, exclude specific **storage accounts** or **resource groups** by name so Netwrix Auditor skips them entirely for this subscription. +- **Azure Storage Account items** – On the item's **Scope** tab, use the **Omit List** to exclude specific shares, folders, or files (Universal Naming Convention (UNC) paths). Choose **All** to exclude an object from all data collection, **SiT** to exclude it from State-in-Time snapshots only, or **User Activity** to exclude it from activity data collection only. See [Configuring the monitoring scope (omit lists)](/docs/auditor/10.9/configuration/azurefiles/stateintime.md#configuring-the-monitoring-scope-omit-lists) for details. ## Next Steps diff --git a/docs/auditor/10.9/configuration/azurefiles/stateintime.md b/docs/auditor/10.9/configuration/azurefiles/stateintime.md index 989906b523..0795a3f245 100644 --- a/docs/auditor/10.9/configuration/azurefiles/stateintime.md +++ b/docs/auditor/10.9/configuration/azurefiles/stateintime.md @@ -2,7 +2,7 @@ This topic describes how to enable State-in-Time data collection for an Azure Files monitoring plan in Netwrix Auditor, configure the monitoring scope using omit lists, and set up optional Azure diagnostic settings for activity-based reports. -> **Note:** By default, Azure Files permission reports show display names only for Entra ID accounts, and Netwrix Auditor doesn't expand on-premises AD groups that aren't synced to Microsoft Entra ID. To show display names for on-premises accounts and list individual members of AD groups, see [Configuring Active Directory integration (optional)](#configuring-active-directory-integration-optional). +> **Note:** By default, Azure Files permission reports display only users and groups that you migrated to Entra ID from a local Windows domain and added directly to role-based access control (RBAC) or New Technology File System (NTFS) permissions. The reports don't display users who gain access through built-in (well-known) domain or Azure groups. To see all accounts that receive access rights through any groups, enable Active Directory integration. See [Configuring Active Directory integration (optional)](#configuring-active-directory-integration-optional). ## Prerequisites @@ -28,7 +28,7 @@ After you save the monitoring plan, Netwrix Auditor will begin collecting State- ## Configuring Active Directory integration (optional) -By default, only Entra ID accounts appear with display names in Azure Files reports. If your environment uses on-premises Active Directory (AD DS), you can provide read-only AD credentials so that Netwrix Auditor can: +By default, Azure Files permission reports display only users and groups that you migrated to Entra ID from a local Windows domain and added directly to RBAC or NTFS permissions. The reports don't display users who gain access through built-in (well-known) domain or Azure groups. If your environment uses on-premises Active Directory (AD DS), you can provide read-only AD credentials so that Netwrix Auditor can: - Resolve display names for on-premises accounts not synced to Microsoft Entra ID. - List individual members of on-premises AD groups (including members of nested groups, resolved transitively) as separate rows in permission reports. @@ -52,12 +52,13 @@ If you don't provide credentials, report output remains identical to earlier ver Use omit lists to exclude specific folders or files from State-in-Time data collection, reducing collection time and storage requirements. -Netwrix Auditor for Azure Files supports two types of omit lists: +Netwrix Auditor for Azure Files supports three types of omit lists: | Omit list type | Scope | |----------------|-------| | **All** | Excludes objects from all data collection (activity and State-in-Time) | | **SiT** | Excludes objects from State-in-Time data collection only | +| **User Activity** | Excludes objects from activity data collection only | ### Configuring omit lists in the Netwrix Auditor UI