ELF(444 (444 Qtdpa""/system/bin/linker65f &30ZEG.'"/10 Y#)!sh+la|/~2-!) 1-<(5V4S Imu ]\e $C%&%7,xK 9#?@H A:$2`'Bo3M8kR6}zynr_N>XFgj;[Jp+Q.=t,L(w ^WbOiD *c 4v "qPT{Ud*` ,CHNU]dls} '4;GU ` l t y -5>CJU[ls{#+<HXfy .;Tkw#,4=T]go/?Od)5Xe2Jd{ # ; S v          $ , @ V j          $ ) 5 B K R Y f o w ~           " 3 D f v          " + 5 @ I U _ c o           3IZk!(/9@FLPU_eqw  *09BP__dso_handle__INIT_ARRAY____FINI_ARRAY____aeabi_unwind_cpp_pr0openclosewritev__errnostrcmpstrncmpstrlenvsnprintf__stack_chk_fail__stack_chk_guard__aeabi_unwind_cpp_pr1free__aeabi_idivstrcpymallocstrcatwritefprintf__sFmemcpyfputsstrerrorlseek__exidx_start__exidx_end__data_start_edata__bss_start__bss_start___bss_end____bss_end____end___end_stackmemsetmemmove__aeabi_uidivreadsocketsetsockoptbindlistenconnectsocket_local_clientunlinkgethostbyname_ctype_fopenstrchrfgetsfclosesendrecv__aeabi_idivmodstrncpyshutdownpollacceptgetsockoptfcntl__aeabi_uidivmodselectsendmsgrecvmsgioctlgetpidsocketpairdlopendlerrordlsymdlclosesk_valuesk_findsk_numsk_freeRAND_pseudo_bytesEVP_CIPHER_key_lengthERR_clear_errormemcmpsk_new_nullsk_pushEVP_DigestUpdateCRYPTO_freeX509_get_pubkeyEVP_PKEY_freeEVP_MD_CTX_cleanupX509_freetimeBIO_ctrlEVP_CIPHER_iv_lengthRAND_bytesEVP_md5EVP_MD_sizeEVP_CIPHER_CTX_key_lengthEVP_CIPHER_CTX_initBIO_writeEVP_CIPHER_CTX_block_sizeBIO_readHMAC_CTX_initHMAC_Init_exEVP_CIPHER_CTX_iv_lengthEVP_CIPHER_CTX_cleanupHMAC_UpdateHMAC_FinalHMAC_CTX_cleanupsk_pop_freeDH_freeBN_num_bitsEVP_MD_typeDH_sizeEVP_sha1OBJ_nid2snEVP_get_digestbynameEVP_DigestInitsk_newX509_NAME_freeX509_NAME_cmpRSA_freeRSA_newBIO_pushSSL_get_current_cipherBIO_freeBIO_s_memBIO_newEVP_CIPHER_block_sizeTLSv1_methodTLSv1_server_methodTLSv1_client_methodSSL_CTX_set_default_passwd_cbSSL_CTX_set_verifySSL_get_versionSSL_CTX_get_cert_storeSSL_CTX_set_tmp_rsa_callbackSSL_get_ex_dataSSL_set_ex_dataSSL_get_ex_new_indexSSL_CTX_load_verify_locationsSSL_get_peer_certificateSSL_set_connect_stateSSL_set_accept_stateSSL_get_cipher_listERR_peek_errorBIO_test_flagsOBJ_obj2nidSSL_CTX_freeSSL_CTX_set_cipher_listSSL_CTX_newSSL_get_ex_data_X509_STORE_CTX_idxSSL_CTX_ctrlSSL_CTX_check_private_keySSL_set_bioBIO_free_allSSL_freeSSL_newX509_NAME_dupSSL_load_error_stringsBIO_s_filePEM_read_bio_X509X509_get_subject_nameSSL_CTX_add_client_CASSL_CTX_set_client_CA_listSSL_load_client_CA_fileSSL_CTX_set_info_callbackSSL_CIPHER_get_versionSSL_CIPHER_get_nameEVP_get_cipherbynameSSL_state_string_longSSL_alert_type_string_longSSL_alert_desc_string_longSSL_CTX_use_PrivateKeySSL_CTX_use_PrivateKey_filePEM_read_bio_PrivateKeySSL_CTX_use_certificateSSL_CTX_use_certificate_chain_fileSSL_CTX_use_certificate_fileX509_verify_cert_error_stringSSL_library_initBIO_f_sslstrcasecmpASN1_BIT_STRING_get_bitASN1_INTEGER_cmpASN1_OBJECT_freeOBJ_obj2txtBN_newBN_freeASN1_STRING_to_UTF8X509_NAME_entry_countX509_NAME_get_entryX509_NAME_ENTRY_get_objectX509_NAME_ENTRY_get_dataBIO_f_base64strrchri2a_ASN1_INTEGERX509_NAME_onelineX509_get_serialNumberX509_get_issuer_nameASN1_BIT_STRING_freeX509_CRL_freeatoigetsocknamegettimeofdayrecvfromsendtofflushBIO_new_filecloselogopenlogsyslogBIO_new_mem_bufBN_set_bitgetenvexitDES_is_weak_keyDES_set_odd_parityDES_ecb_encryptDES_set_key_uncheckedDES_check_key_parityERR_free_stringsERR_get_errorERR_error_stringEVP_CipherUpdateOPENSSL_add_all_algorithms_noconfEVP_DigestFinalEVP_CIPHER_CTX_set_key_lengthEVP_CipherFinalEVP_CIPHER_CTX_flagsEVP_CipherInitEVP_CIPHER_flagsEVP_CIPHER_nidEVP_CIPHER_CTX_nidEVP_MD_block_sizeMD4_FinalMD4_UpdateMD4_InitMD5_FinalMD5_UpdateMD5_InitEVP_cleanupHMAC_InitMD5OBJ_txt2nidPEM_read_bio_DHparamsPEM_read_bio_X509_CRLPEM_write_X509PKCS12_freePKCS12_parsed2i_PKCS12_fpd2i_PKCS12_biostatRSA_generate_key_exbsd_signalfputcX509_LOOKUP_hash_dirX509_STORE_add_certX509_STORE_add_lookupX509_LOOKUP_ctrlX509_get_ext_d2iX509_STORE_set_flagsX509_STORE_CTX_get_current_certX509_STORE_CTX_get_ex_dataX509_NAME_get_index_by_NIDsscanf__lzo_init_v2lzo1x_decompress_safelzo1x_1_15_compress__libc_initexecvesetgidsetgroupschrootreadvflockdupdup2ftruncatechdirgetpeernameumaskepoll_createepoll_ctlepoll_waitdaemonforknicewaitpidsetuidsleepsystemfgetcprintfputcharputslrand48putenvsrand48strtol_toupper_tab_inet_ntoainet_ntopinet_ptonctimegetgrnamgetpwnam__get_h_errnores_initliblog.solibcutils.solibdl.solibssl.solibcrypto.soliblzo.solibc.solibstdc++.solibm.so,0 458<@D'HLSPT4X6\7`;d h:lptx| avVZ_qtu(&'Q * \ Rjmcbe igh^ $k(l,048P<@DHLPTX\`dh=lBptx|@(   .89#1)A*+$!F  2"3 ,$D(,04`8<@D,H0LP1TX\.`KdJhIlHpGtCx|+E)?/>-/524d]f0< [~ $Y(w,T048M<x@UDnHOLyPTX\`dhlptWx%|LNro|  $(,0s48 <@DHLPTX\`dhl}ptx|Xp{z3x --ZƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ|ƏUʌtƏUʌlƏUʌdƏUʌ\ƏUʌTƏUʌLƏUʌDƏUʌ<ƏUʌ4ƏUʌ,ƏUʌ$ƏUʌƏUʌƏUʌ ƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌƏUʌ  0-AF*($N#MFF~D}D\=/3೹1FEI1O1@2*+ؿ@`O0`Q^Q-ANF FF~D(F? ++   5)x1=)0F(Q-AF F!F08B"IFF"yD 3\?EGD?EGD2H8?]Bȿ='bEpԿx='p3B"p0`~P#) #S hCFh+h` h` ` " + #0x+pGF0#3P# *FpGHxDpGuK{D F8"Q@ڀJ S h_Lr@̀  S hRx@@񻀊 xS hRxJՠ0 *@  PS h@ 4S hRx񎀊 S hRxJ S 0hSxDu  ("" (B*i (##3b (O O Q3Y\(""3R_(##3K-(O O CB.(""QC;,(##C4:(O O C+/(""S$'(##QS"(O O S`(""S @(##c=(  Q` pGKpFF 8 F)F8 ph8 pGh pG"h`hFF#F+pF FF)H@51xD#BT3\*pC-OFFFF(H@ 1xDF'&7Pu(FYFRF(FFEFF[%p0F-AFFFh H@!xD1F:F4$(](0h FhoOppGpF FX- ۣhB`hB]b` ` pFhFhchpF(ؿO4(F!x(F Fp+-GF FFFHO"qxDROF F(̿##9 (O BC+ E   1x  FmF&6BhF(O60FppF(  FF Fw8(ppF F8xB"phH`ppF FAh- chBXh`` F]`Y ppF F+ KBآhch hJB FChm`@ p?B𵅰FFFFhF!"'0F)F0F)FkF˄ FFh F!"pFhhXi hh%`C`e`pphF F(H@ AxDl F(Fp)pFh F&i F4F,l`,``pF F0mFF!"hF F0hF*h!p#`c`>pF TF F!"X` Fp-AFFFb0@F0<p;`4F& F!*F6 Fp FFF !F*F. ppFF F^F(FR1FF Fp-GhF F-NOGF(F<-i? O BO  Ѹ2 `FQF" F8F`t'` 1F F7i0F  0F>F3#E#+@%a @pKhF F+hBhx!c``(FF(F1FF Fp p-AFhFmFhIh$hFF0FF0F9FF@F FF@T(F F!jpF FF B*F!F0F!F2FF\(Fp-A FFFF@)F:F3FF FpFFF(F۫hB (Fo1F"F88 ppF F8(FF F; p-AFF& F(E8Fa]fUIyD-AFFF1F(F+"FF8FB Op&0IOp2FyDF (I "FyDpF FF)H@F!xDw1F(FMF(F KEB(F-`ؿ+F%`ȿk F"`b`p?B? KpBF FFF(F!2F7 !p` %```` Fp?B"F F-CFFF)9hhB4 ZFF! F"^hhhK`+hH+HOmqxDjha+H@1xD,`FhF1FF9F2F>`l`O@FmYpFFQF1FFB(F`p-AFIyD,FFر8FFF F(F!F F9F2F( F0F(FKpAE * I yD Fp-AFF@shhXB3hB+8FD0F 0hqhB"pB 2h9Fh"F](F,  7F FFI,(F#<>@pGhF+2F FF F8chhYB h--о)F0Fh"F h 0F,Lh`oOpB  @pG-O FFFOqhFFON$MFD  ~D}DY$hF9FhF)FhF1FZF4hFi-O FFF8FZ@FIFF` FQOhFN%FhD~D#- #K(FIF(!hF9FBFU hF1F5NBIhFyD[\FXh0bh#hB̿  Flx Fbhh hJB hH`" F-"n F(F FEhxC-8 FhC` FpG#\  3+FpG"|8 !"fFFFL#|D,L8|DFFT @&h2F!*F;F0F#hB<p " F!F --]#e`#`3!`H!``` #%`e``H@iQxDpu( HxD HxD(HxD HxDH@NQxD wsg_;pMChF}DF+@U h`` hC#`3`{* H@3xD"U 0h"`a`2``hp`p<-OF$H FxDh(: L |DDDF(!8F MEFF!hhah8FJD8Fah HEXF@a68F0FRFtVD-0F @@@!+[BL|D`hB#c`#``<@h FhoOppGFhch*pFFFۃhBhF`hCPc``)0F*F pFhpF Fh- chBXh`` F]` ppF F`KB آhch!hEB̿  p?BpF F0 Fh`pp FFF !F*F pp xF F@+FHx@(H@QxDh(F!F"a(F"x"x(F1FH@bx(F8 phHxD HxDhc@  I@ yDZI"yD`>|>F"/L F!FX0F "|D)0F ""б 0F9F@ 0FX +xBѝixB +`T 0h HkIHyD @Th H[ I*xyDkxHO0 !8:=FhF FBF 0P0h*FI#FyD 7K"{D x\ 2B JXhCH IHyD !87F(HOqxDk(F4FXO`0IO`*FyD F@( X FI@"yD*FF s F>p+MF F}D)0F0F&K{D`(CФ0(#H@axD!!N~D`0h|hU h)HX0hI#FyDFH0 F6IyDH`D!FD@0u I yDpFH7<5h<$<<HxDH-AxDM$Bv}D FFX F|F8FNAF(F4B @hHI(  p FF8$-%FDE  I yDpd H-OxD@ON$MD~DBx}D F(JF F"PF<J+ FFPF1xDT h)0HM`1x"(/I:FyDF)HTh+$H5hqx"D$I:FyDFHxT h)Hh1x"zIBFyDFHHTh+ Hhqx"a IBFyDFHF4G%-OALFAJ|DFFXF#h0FB:H@AxD<!:FXFz1F!(F,?F Op0-IOp*FyDM' $ D@FQF@"F? Op(OpIF*F0QF2F@F(F/  x0I *F#yDYF(F(F T hBjz3kmKpBF FFF( &`````p?B-OMF! Or}Dlmn PFQFD FBFAOa0F(PF t?F Op0IOpRFyD Ff(F  (I RFyDE  0I RFyDv FNH"%xD,FKFJ.FH{D xD0L/FF   '^>Fv,$-  * t$.sDEl7%/$$f, ".b(@\E@7#/@𨀤,T  Xh CxD*-WH@[AxDS5-;QIyD(NHOaxD  K$$ % 9ȱ X h ZF# 68  ?dO(0`-H@{AxD"hr P&I"yD RFKF, PI#yD RFKF hPF>c$$&2\\\h\{4q KpBF FFF#&`"`BԿ&c``+pp?B "@hHxD7F(HOqxD(FF O`c0IO`*FyD F@( SX FI@"yD*FF  F>-G FF! "FF$ +#. &&(F`` p 0?(`htI+ ;+  I *FyD G@  I@ yD!( !9@F``p G@  I@ yDpF@h`M}DFI"yDZ ph& I F"yDN$$ IhXh+ H( I"FHyDI FpF\-FLFhF xF|D='mF#( hF8T h@ Hn IHyD7B!,4-A+L F|DkhFT h!+5Ѐ"1F(FjF0F)FxTh+ *x@F1FH$)x@F"kF)x"kFoFF0F{IBFyDF HhF !T 0hB"Fh,-AF.LFhF xF|DmF'FC( hFgFmT h)0H`IyD (Fn``ThHرIyD(FdxN ~DF FO@ @:H':JFH}D8K7FzD{D(F!"dfh&#xEFhfxNENF(FQFH 1FD8   YFxXh*HPQF"(FCF_FHXh+HP1F"CFKF HT(F!F(F!FMFaFP*@V-OVLWJ F|D#X2FhOa/ !2F(F@A!Or?F Op0EIOp*FyD8BI (BJ@FyDzDF ' <DD.F!@F!)#!"@FYF7F*F(F!F(F@F!"B'J 'IzDyD(2m$I5F:FyD@Ff@F)FJF)FJFHFNFXOp/0IOp*FyD f /8FT hB$1B)4NXT80SFh0 h##``h0`h ``F-OO F8FSMFF< FIFZF[F}DP`(HIO`yD[1x FP`(AIO`yDK! F:F FfP`(8IO`yD76IhXh+-H FZF FZ.IKFyD%HBF FN`E'H@xDUh+H_`1x"8FIBFyDFHXU h) HGp F$F F&IBF+FyDHFT'r-GF FFFO 9L0 @zx+F0F2I|D`Xh+,H0h F(F*.*IOJFyD#H0hzxB#HOqxDRxT h+Hhyx"@.IJFyDFHgHT h) Hp(FF(F IJF#FyDHM4F%-AFF (`Fh`FShxy 0(`(h2Fah#Fhzcxk h`hh2Fh#FH-C[M˰F}DFFH*Cx+ x  H #!F"@F)$U 0h*W .(RDI yD %(IAI yDC@F!FJF(U h-3  x5I yD(@FIFOrD@# FI@E+H@1xDfOU 0hJ@F("I@FyD"F9FDiI FyD*FFDK0FG{D"F#.EJ#zD"F"(F!Or0F!"dK~$ 5&4-AF F'/'':"+ &&hhzFFFhhvjxhS0`-O+MF0J}Dh/Xh!B@ (w F F6 hRhBFU h(𣂙H/(𝂛IJyDzD8 F F F PF"  " EЎH!xD FJFF븱Uh.i|H(cIJyDzDrvHX Fch ۣhKEah` b`uHOqxDH(ǁ:ihziFh iai+B. ,-_H@xD!"8FVh5բhJEM&M%:PLKxKHK08F 4 RF FMF Fo[FFRF됹U `0h(!H(IJyDzD -8F-$ @FRFKxXh.H(IJyDzDX- h-)قHy8FF8FP"F@FIyDFxH xK+rh*Àh +!(qU0h.hHG(oIpJyDzDP(0hlHOqxDrh*iH@IxD8FJF 9F"!(=XU `1h)NH(YIZJyDzDYHOqxD}k+sh+ch9F !cU h*]:H(XHIIJyDzDhYGphU 0hhB0!ph 9F0!5qh9F!ph+*h'Xhrh(#h `i`h#U hHȱ!8F!)IDyD rFH?+˄! ,&`0FtU0hB!OpG!F!JTJVII9bIIHr-O!OFO JDh%X[E@h@5h-(h(F(h:K+& D "HFYFhHFQFph(Mh 4 IFhHF#!F!-(;sHj!xD5;+/hoHr!xDdqh!lHs!xD] phF" D  $ !RFXFHFYFRF$IF#F"!@\Hx!xD[H|!xD7  S l !B$""#LH!xDh$Wh(H"KxD{D``pG>@JKzD{D``pG(*0F FhF!,,mFIhFyD(IhFyD!IhFyDbIhFyD# IhFyD +* 0K?3'pL|D#iCj%%azbpp LFS|D"H#Xh$(F: K{D\j\B ji FtKp{D FZjhi HxD! L!|D"b a pHS(KJ{DHXxD1 -GFOAFO`G:FAF:FFFO`OaF F @ ##E #9FHF zJ#FOazD4F0F(VFo&tOOD!X#FOa:F0F0F&FFP('F fJ0F#FOazD4F>F( aJ0FOa#FzD!F4FFB0O 2@O O  TDRODQODFQK{Dhù@DMJOaCF0FzD0)F2FGjQDK{Di`hQhBAIPFBF;FyD@(F gnH&Kp{DZh*DBiB [iBHxDhP@(I@yDhD0Z B̿  M}Dni.HxDh`@8I@2FkhyDa J zDPaa p$Z-AFFF0LKD{DhhBEJzD`i!(|FBI@F3FyD/r 'Fti+FݡnB"fa -ZS̀3KD{Dh EAR(=,L|D`i!(BF(F 'I2F#FyD@F#"O#IDyD h8hE*?hL|D`i!(F(F I2F#FyD8FHxDh 0m/ 7TZx pF(HxDh+K@A%@AB)F)F FOrF(F Op(5IOp"FyDh-!(? Op(IOpyDV!(F? Op( IOpyDD-(F!D pTpF F0I *F#FyD p߻CiF+H@u!xD bݻCi+HOqxD-A܀F7IDFFFXh+ /HH81I*F,H;FyDbi#jڱiP2BiO C"`H"HBB22BajBڠi @3pO!jiB!`D B0C0"jP b,X  hCH IHyDF! p "#K$J{D-AFX Fh+ H(I*FHyDqai)H@!xD;!j#!iR3Bi3 67ɌiX2HQ5!j9B!bFB۽F -OF,I&FDFF4FD5a#Z!0[!B ##B ""R+`C*`Q$ Xj`h) HVH+hIFhh"F3F H564B̿""B"*0FFs-AMN FMI~DFFFpXh+FH`i 1!EIyD+F>H:F -` B\1BQC%biYj!T# CD# Oj!&T#CD#PAj92!T"C2!T" D"0Oe&2!T"C&2!T" D"04V 0hZH8 I*FHyD 1=F! ǹp'NCiF~D F+%H@E1xD#JXh( Hs(I*FHyD- 1B!k&3CT!D!T#@D#  A%,V hCHC IHyDpF! pMCiF}D+H@61xDJXh(H IHyD!""!#F@# 3BO31pFI}z6K7J{DpFX Fh+ 0H01I+F-HyD"hw( |F!("0F)I*JyD1`)IzD)HyD)K1axD{Dr```#sa"2b h("H@1xD !h" qbnNaqj" ic!F FLqj" Y:aqj" iN!F F80FpFiU5K6J{DpFX Fh+ /HY00I+F,HyD"hOpF^!Or0F'I(HyD(JxD1``&KzD&I{Dr`yD`1a$K pa{D3aO1"h*H@1xD#hOa" oOc#`  " A!F F0FpF$}mmGpF FFX0F)FuF(H@AxDK Fp-O\F FhDjJhrHhOzqp`Ozr.2F"@F9F+jBFFH@!xDyBK&FBH7FBJDBIxDzDyD  X ڈ?!!`""`_LqB!hA!` iR'Y ``h($HeȱkiZ!h+ F:FHCF 4 YhYH;( YF H76(j B##E#+@F F! RGϵŲFii FF F-AFɐFMF}DIhXh+ HHIyDH!01F#*FB( F1F*FCF3Fʹ-AFİɐFBFM""h"bI}DhXh+ HHICyDH!B3aB*Fp"1F#( F1F*FCFDFR0K1J{D-AFX Fh+ *H^0+I+F'HyD"h h(F >$ F\!$"0FIHyDJxD1``KzDI{Dr`yD`1a#sa h(H@Q!xD!h" a0b0i" 4j!F F0FaF1SpF FF@ I@ yD0F)FF(H@AxDT FpD-OܐFhiDFBFF KhkHhOzqpZOzs+#AFPF*F(BF$H@!xD8!I%j$'FFY5xDFU,#3QUFF(F#9F#FF@FCi ;+)'H@^1xDxO0L1F F ! 5 h %h+)ݩ'nFhiFnF!б%AB5hF( b+ hFF( &-CF 7]M+}D@g! F:F5'BzgFDw U ,8U 0h) FH@8FHIyDFAH#8FF8F1FF@F1(F nIq8I"0F5yD.K8FB/IjXh*HLp58F*IBFyDF"H`x !vxfB#l6 xxU  ht&XUh{HX%I5yD H'!x|hh)fU hȱt5ZiQ))i"|"5K `{D|`Y|4"/H`U xD|`h+F$H(A(IyD&$JXhHH("IBFHyDN =)| !K`{D|X` hHȱIyD HBF4I#t%@FyDt5 *[i8F1F)!Zm 2+7,8F`Wtw p<af 0k`(ab(ab*nca if0F|5 t5p(h %[j%1F*t'BnB `51F(Fded'+ p#Fp''MB}DlgGq`p)xr U TlU h+ HH`FIyDFHJp) F!b F!6"''''QF#08 4Fa` 1O2a F;MF}D(i1+epF(^ F'9!F*(> F F!O@R;F%I FyD} 0F!F#6!I FyDr 0F!F#K+I FyDg 0F!F# JXhH F~IyDF HzJCFdzD2|#p5h(@ѱt5# #4W`5h- Fda 1#2FiG)I"yDFF-#p5FX23@hh@pB@p #p5p5T|$W h`I;HyDhcjqhhhBN`ah@Wh(XG1ihh qiCb iBܠj!#bab&HOqxD)F(!H@?xD!Or iA#)Fa2F a F`2H@CxD{!(F F F HXI JyDzDHcih!`! ݐYA9l+pF FFېhBԿ##Ssch!hBhuhSh2FxhBȿ` p-OF  FhF+D@ɀF($ X h) \H0^IYHyDh&0+YL|D >VL|D *h $ <YF$X h)FBHThFI?HyDhKF@L|DV8hyhB%"|`:`Q`0ihhpiiai >iBi!{aa,H!xD*F 0Fh8&L|D O9O h XJ`?h`3;`L|D8X hR H0I#FHyD~!`F! ʏď9fdh+h*@h pGK+pF FHT!xDH=xD FpBpFFHe!xD11r B$$BԿ&FD&Hg!xD(FpF!FV8 EK-A{DCLA&h|DaH`8!Y`T h`*F:OY:ODhhB>}h:]DiQj#F 1IyD 0<#F,J{`Xh+!HD&JzD&JzD&I+FHyDJXDhPDxDplpJXh+ HHIHyDIyDHh Ft^Njh[h+BhhYB̿  pGpF Fh FhY`* p-G8MAF}D)f6K{Dm(]2N 2O~Dh(U! ! F(6 "'+ F p* Fh FFhA   FAF hY`  1 `Yh(H) H1FJF (ѽF&h+h*@h pGF FhF!lF IhF2FyD+FhFpVF !hF IhFlFyD hF41F+(q) O0@(4IO0@yDj!1BO0@H,IO0@!yD1T$(QO0@(#IO0@yDCh[!14(!$1,+$Y14HZ(!"F$xDtO0BF F!H"FxDgO0BF F!H@xD𵅰F FhF!Fk&HD!xDoF!"F0F%,!"FF(F%& I2FyDFhFU )F"F0F%IyDFhFIhF𽦌0 FF!hF"F1k+ O0 @!"F%I+FlFyDFhFhF0E0 FF!hF"F % H3!xD]!"F(FlF%IyDFhFhF0 FFFF!"F(Fa%!"FF8F%#)FF0F"0 FF!hF(FIlFyDFhFhF0-A$BFFF!O0@@F!F*F%r!F*FF8F%l!F*FF0F%fI JCFyDzDO0@U-CfVF~D<2 rYh+0r_O0@H0O0@yDT2 O0@80O0@yDXO0@)0O0@yDLu !O8F$r%L" #8F$^%P_)@!xDcL"|'(FrO3$:%~PR F0qO0BRyD!/pF0(DoYO0@0O0@yDL\2XXO0@0O0@yD:`YO0@0O0@yD+T2x"ZO0@z0dO0@yD( O0@k0HO0@yD 48"vX0@W0$O0@yD) O0@H0 O0@yD+O0@9P IyDFO0@-@*O0@#P IyDFO0@Ox )O O @E@4!"F@D$4"!"F$T2842CxC|"O0@r8"F4!48/F4"P"Fs2/742!"FX$!"F8$T8"42CxC|"O0@184H!FFO0B F HOqxD8F!FL-Q+O0@xP YIyDFO0@4O"F !$L!"F8$DT"8"42CxCB|"O0@84H!F@FO0B F T{HOqxD/''-=FG-4"!82"2\2XCD3SO0@(eIO0@yDT x"RO0@(]IO0@yD`PO0@(WIO0@yD- O0@(RIO0@yDs\2`hd"(hld" `ld"\#`3hO0@l"x2|"1d"`!F" XT2[ FFO0B F 8) O0@y(%IO0@yD"H##V hBl~9K`݊"d|΋(Ȋj.?EF!hFDIJhFyDlFzD@hF cT2Fh(! FBO0BF F H@ !xDk F"\$ ,04W4p  ,04W42\p3*# 0-OTLFTI|DFF`X;<h9(F-88FR9FIODF(F9F"(FHFDIFF(F@I0FyDDH9F"(F(F ")8F)F8F5O(FD "(Fz9F"(FvPFQFF(Fn(F9F"h3x3XFYFF(F^9F"(FZ@FAFF(FR9F"(FL0F1FF(FD(F9F"@ "%(F8)F0F.0FD-T hB8/`׈-O>LF>I|DFF`XF*h(F)0F1F4N~DF(F1F"(FPFQFF(F1F"(FHFIF d F(FHF)F+!IXFyDz((FIF"(F1F"(F@F`AFF(F1F"(F8FR9FF(FHF)FT  hBN-AF(FF LF8#.C|DO5*HI#XyD(Fh3F )F K(F9F{D@"Fx-!` pFe`N(F |h +(Fp45FK00 04<I80&m"8%<%h -O# F5DF+%* ,iAFFGjj|4h )Y!h|h+m+0*mT 0whBk8 -OPF-g'F4Dh0kh+ KFnh*hqi`Bۨh7C/`  QFVjh8#nh1`U!h(&s0[ZhJhi3@m<2BT0XOYF Fm| hFTYFOX"4dH3[4!Bck3x!(4bkS+ ! F1FFi*$P*pMClF}Dk@BB lB @ /(I@ 2FyD$X(A@  {I@ yD\1+`!d<A@ rI@ yDH1C@ mI@ yDd!r\`A@ eI@ yDH3s Zl@@ ]I@ yDzX\2 C@ VI@ yDkh*,XA@ NI@ yDY3["B@ HI@ yDJA@ AI@ yD;3C@ +4&%GH]:F7(J8F1FzD4B/F %ChchQx$ Fos J65BF(7&!wF(H43h FP` F 0@ FpaMFd}DHl53hG dlp48"+B"++@ F<7`Od@`!`d F|4ph *H8`)!!p F F!{U h0b" c pY|4h *  F|$h ) ,5K(0+ (, j!|4h * @HD1 @DH'2#77|h )  F`ppF FF(H@QxD|4+HO]axD-|4`|4h *ѰXhq!`2 F  Fpi~iFp F!p"0F)ihhih *hlFhFG8P )ihihh*hhFG$` )ihihh*hhFG)ihihh*hhFG )ihihh*hhFG )ihihh*hhFG0)ihhih*hEhF@A0FF!&MF}D#K Xh j I JyDzD XhY ^8IJyDzD<2 0  `XU 0hбevjD$JzDJzD!3F>(Uh1F3r?rr0F FhFOq1lF@!%IyDFhF(+* 0=rF@i(> IyDlsXA`#*3PH(IHyDu\r`1 i,%i9!"  rqpMFk}DI`yD1 \ ` JXFh( H8 I2FHyD`3) pqqjF3@j0j!jmbj j j' 0F+upFLF|D HI#! H#Xh+#+##7p!FZpLF|DF!(FI`Xh+وH IHyD1!(F T 0h*}H I{HyD2&hk8T 0h*rH uIoHyD 8 mKXh)iH mIfHyDps<T h)^H cI\HyD[`Gp`T h+RH XIPHyDC(F4T h)HH OIEHyD.t!"rT h+;Ht CI8HyDt#X 4KXh)0H^ 9I-HyDT h('HL 1I$HyDq #H#Xh*H< *IHyDrlT h)H* "IHyD3 I`Xh+H I HyD(T 0h*H IHyDp"ppp"q)qqqqq"q1q4qCq`qL(K|DX h5 `zg( F p@ܱO1a`0&F% !hB3iT 2aD 056!hBpF` F F>0 F3F+H@QxD! F% F F! F!Fa`1[!``, F ap!L!IF|Dm`Xh80pT P*hb 9@` IT yDhFmF1F@lBhFhF&hFld0F T hB mp`/9sF FF,<(@ I@ yD F 1 (F!F |[oKFI{DFðJ\XOq KzD h{DA(F"+F8F1FA#hBCthooF1F k *@(FF:F e0F!"0F!F@@ I@ yD)1ñ0F I J FyDzD I0F!yD0F!F0F oooo-CF FFF,(0;+0#̑@FqFA!JF!F;F(F 0F)F -OFM01 }D SJzD,7##7)@ FE F!R 9t%" F7Q=$! F' 5+1e'iCpeUrB5Qi7+U!5e pq Xj2F!2FFj!!GJHKzD{D"QF[F8Fp' FT 5$%5m)`"0 %D@LU hY b8U )IiyDQ-6U!5epq Xj2F!+%!Fj2F!#7I%yD*FQF[FHxD8F (F pn._zmBlX^l-CFptF|4 `F`|D`|$P`p4 Fp$*l F |4h)@ Fek-pT--%%l$* ~ 4( Fi F!cp4#X  `p4+ Fb FIFp$* F!"p( Fd # #6p4+(5s O2+.",%(p @Q8D@?p$/''_*CFHO0p4 F+ F! FBp(O O (cFL F[ !rp4+AFH1`0p4+! !y F| h/Ȁ p(CFH`c F F{p4 8O +aFLI`0"d'` Qp$*CFH FL)`"0ep4+OO+qFN F)F|!ZH@p) Fr F p$*CFH F(p F F+p) F!" Fp(O O (cFLCa|$1t#^p4+BFH F!p( F!"l1p$* F F|hc|$hK{D` FO12Fh-A F@!Fkk+##p4>H@]QxD~f!6 2Ft g_|`bclʃ)F@lB F Fp4(tK0't F "|hGp4%+% `2F`9Ftt |FtUƕ|5b`|G`YpFFF F1F*F} |h# F p-AHM7F}D+@9!7* !F:|1H(> F*.'H5sg8F|Xf60Fu 8F1FzU h@ * &I yD! F  FA`fˆX#U !uh7WhA7!q'h Fi#7fK0L{DYhh FDhh[+*F `#F ) hB `#K`0rpF FF!"f&`e`p-GF FFFhOhEji0FyhGH h  h`'`Fh/8FWKFFQ | >  \ ' D\|[\ d,| C\c|R\ "L gW4+=#S5|_4;/CS+=#2 0 .> Q .)&#  ,ahzA !ycyChy#/y dxDhx$/x_PQ0: 'W1X{0BR"0y7iF+HOqxD@!i" J``agd-AFhF FBFFBԿ##SsH!xD" a%`>`` a`aaf`+d"h-AhFCiӱ&8hAhih`=`6 P0FhF(F(`a#`#aphFձah`(F F!hbhiS"P`%aeaS"` ah`ahiKc`B p-GF FFFhOhEbi0FyhGxh 0+`8FahH`` Fh/8FpF% iS%h0F(5 hB۠i Fp-AF FFFF)h`h C`p c`-CFFFiFhFGi2FFh F +FIF!(8F  FIF2F+F (-AF FFFH+!xD! TF4!"8FX F">a`CF8` `Z:a#FiA# 38hB8F)bhhJ`h3#( F`pGpiF F+HOqxDapapiF F+H@ xDI (FS0+yD*I (FS0+yD* I (FS0+yD*I (FyDS0+*paaaaah FhoOppGFhchpF F`KB آhch!hEB̿  p?B-C F8hbM}Di#`H!xDUh)@8ihhxil  B"RH!xD6 Fx F@h+ah;`H``HH!xD f/h  CH!xD FF FwF 8Fy3hAFFHFDFUh*N*Hy(I0IBF'HyDB8Fd ,H!xDU  h- H\0$IHyDhh 4BAs# BAs #/IhXhJH4(I:FHyD#`CpG!F`k`?`'`N`_4`_-A/MFh/H}D+XhchNB/۠hz h!E"<7"`7g`U h+ H0IHyDhh!``B"7`g``"`#hBHU h( HX"hJzD JzD IHyD]#h8 FF؉_i_f_d_F`i#Hq!xD hF `a^p@"FF!<M"O0#``B0a!F}D2@ j I yD `h `,U hA T I yD#ap^^F Xch+ݠhYa`C F` -C zNF ~Di#uH!xDh+@׀c+@ǀi*@Y(8ihhxin  B ]H!xD_8hh 1!(F TH!xDK:hhhB@V h)3FH(.KICHyDb( FF FF 8F+hAFFHFnFV hJ1H(7IBF.HyD8 `P8F 1H!xDV p>h. "Hy0)I HyDhh As #giGqRՠh)i hi*aia (Ff#p Fo hBCpG!F !]\\]][z]0 F"Ba+h#`0K!J{D0Xh F"++=*# #]x _*%% +FEs#Rx1B\*+  0CoZ Bm:! "  pG@p FFjO0 IO0"F+FyD] O00IO0"FyDPp\\FO00 IO0"yDIhF*iyD7jh";IhFyD0a !:Fh6IyDFhF#b !:Fh0IyDFhF#-JXh(H`hFJF&I HyD #IhFyDhF6(z^^^^^^k^p^r^q^p^u^y^~^^^^^^^^_^E^^pF F KBآhch hJB Fhah@h` p?BFp FFF !F*F ppFF FFhkh(FFh F1FppF~(F!F Fup*FFFۋhB lF`hF`B iFB8F] -GMFF}DF$ @0U hBx + 0F9F"00F)4DE۽w !F/(F !F F F/hchFR F FjF lF\F "!(F`hF1FhF1F(Fp -O0N0~DF FF+@ "*<*HGFFO .FFdBhG"0FdF,#X h#`#hX  h#`"hr/X0hB'F,''`'O78F d#iGF,-/Fvp0F+=@R-9rFF|!0@(IO0yD FX @RO0(IO0yDD2XD( @ (I@ "yD"<"pnZiZ[ZpF F)@(I(FyD6`ao0Acg(>!IyD I(FyD$xco0#bg`IyDO0K%I(FyDH!0aeIyDO0IyDO0@`o IO0yD$psZXZmZUZcZSZcZkZh ?7MF}Dd2??Z(kF(<2?BU 0h)+#H:8#I#JyDzDH2?/B,hU0h)HPIJyDHzD 8U  h*H( I JHyDzD0F p(tY Zj?Z> "+Li(2F? L'## 2pF Fp!cacck#c cpP2F++Q)k%\"TX"iG\R@O0(9IyD2O0IyD*O0HIyD"Cl˱iT\"G#\28O0oIyDO0gh IyDO0_( IyDO0p!YYYYYYpFF F(F< (2 &&&.## .C0FTO0h!0FIyDFO0O0IO0myDO0 IyDO0X IyDO0"Fm(pYYY-GʰDFFY 0"hI`j+j*@FcNfDB F:!#'4`0F`) "Fw` $0F:!BF#()Z  D SF!F:F 0F+C@FdO|BFbE.j1Fi"FGBFO0(j9F0Fh=I*FyDFO0[O0l(U9F0FS4I#FyDFO0&O0Z(C.IO0BFyD'O0N(7)IyDj!FiG(F O0>@#IO0"F+FyDO00бIyDO0"FO0#hIyDO0(IyDO0 IY 0hBJ?BqXXX YY)Y1Y3Y$O0(IO0yD Y F IyD\( O00IO0yDo YYF"FC-FkiG8O0 IyDO0hIyDO0(IyDO0<XXYFs TXFF8!pP! F IyD( O0j0IO0yD XX𵇰FF&FFtX F0ḵ 3FiG8O0: IyDO02h IyDO0*(IyDO0XXXpFFF#qT2FX20q(FP!pP8 FHps F:L|Dh . HP0F I*FyDFHo |I"`Xh+(mXk F iG F@7F"Q $2O08M?(}Dcco|b.JzD$ )*JxzD$$!\POp(!IOpyD $$coKXh( HfIyDsIyDFXh* HTPx$ IyDFH>($mXXWWWW-AF(F>M?}D#]'O2H(" rL,p9FK2IhXh+-H .I+HyD.Nco#`o*& &&."" .BlU h+H IHyDyI0FyDboVTpFHh FF@O0K`0IO0"hyDX(F0F!`"qpT-C3Lǰ|DT hEl+JЀi hGF(D,F'HB(Fo 'O! `D%NPP~D(F-(F^XO0kO01F*F T h+H[ H9F@F !*FOsg($ET 0hBRG?B(gSfS-AFShFFF'PDLDO0@IO0BF#hyD(F)(F!Fe0F!`"`h@c`KSKS` F)F"#(S Fih4N`I8FyD*` F)F"#(@ Fihhh WI8FyDF( F F F.RI8FyD F F)F"3F|hh`JL|DF O0(O0!F2F'6B O0y(?IyDO0vaEOOOO|OvOBkOQOUOHO3OOONNNNNNNNNN|NNNNQN NNMMxMsM1M$M!MLLLLLLLrLNL5LLKKKKK-A%FD"F)F)FO2(F')F5N~DFp0+K@(G F9F4,IyD6耹V h) $H&I"HyD]$I8FyD 耱|Vh+ H(I:FHyDE- FAF+F!D"L@F' K"1{D8F" SF(ѿFYwIJ HJmJ-OIMJIF}DŰOrhXh(COC<(F1F Fkbݶ>H@axDH2F/LM{O D%\AF8FF@ FpXFXPF9F F9F<"bHO H)F(<2+ F!& 8@!I FyDo F I FyD F! 0FCU  hBEX;9KIII 2+  PkH@!xD$:p0Fc H F(F FO5(Fp-A+MF0}DFFF+A (= )@U 0h*Hq IHyD`Uh(H^ IHyD F1F:F2h 2+X@) H@!xD(V\HmH9-ACo)MFZ}DJ@m(G *C )?A-fi@bae F2#yOO0De0IO0myDO AF F"J!Yh`m("#fa "e VG-O|F# PDFFF-@ (bi!!{ eaeXF)FOrb3LJ5LKzD{DJJ%JKzD{D qHJ%HKzD{DGJ%GKzD{DGI  HFyDSF(BIHFyD F"#).eO0c04IO0myDR0M| F1F"(X h)2+%%&$Hb|bxDeCv@ba0FF0F"Myh8FOr!qXF!Or% (F TUTGZGYG`GYG`GMGDZGUG-CM0F}DF+, "JCaOIhXh2F F9F#A¹< F9F2F"+U h9.0FSp0F F x F ) F)F" *h 2+pF + Fci+ FA=F FF'(F(co /Mhr}Dlrprtr@rDr0; "" F$g0Fp `hl m  2; F 0-CMl}DFFFcO IF"hF^Ll 'nFU hiFpH!hFF F.O-G!MFm}DFFF+6Bo.ؿ@`O QF"hFLFU  mhiF@h2S@AhFF FN6K-A{D5OhFD FF.]"1F`hF2-IxXhfa?`hiF0+9@2+5F#hF!lR]hF!bF F%%OqhFSF8 F% F!8DHb= F8?SNS-C F7IF FFyD#F(,X!0(P,IyDH+I FyDP0(?%IyD7%I FyD FR(%|hD<8F!F*HAF2FO1F(F;<,O0bIO0yD O0V0 IyDO02FC2C@12N@t@-@!FAaAe4" FF Fhi hh18`YhHX`Qh  Yh) pGFAh" hh8 i@h2B FPiC#a+ F F-ONFF~D(0O$FlD&)hhbC QhQE[3V K1h+HH9FW4khB۽6K8@s(MFF}D &HY!xDbhhB FiFc H]!xDtU h(H| IHyDbhhBHb!xDahh#hB"i ahhKc`B`1h iPa|9K????pF% "hh#iH5@S2>chB i FpF FmFhF1F8 C aca FppF F!" F(Fw"F` a Fp x/(  pG#`C```pG#``C``pGFP/!x 0 Fx pX!.!F#p x$ FpF%hS%5b`hBӠh\hZ!!`a```ppFhsDh hfhH FD4F,(F>ppMF$}Dd(F@qqB Fp=pF F(H@!xD- H@!xD!b\k\=*"=+#S 1B p==-AF FFF(HO)qxD8#.C+H@!xD9F(F~! `1`=+3h<0`0<+ h0h8 ]=?=-AFFF(H@!xD|/H@!xDuLFF|DFF(0FCFJFtA(FF F1' F)F"(F"FFpN!(F~D62F(F!F2F#F Op0IOp*FyDTo.>0#$HsFFF"FF-2FH"FF(F0FB|pF F)HOsqxD(F!F"p-𵅰#D=Eh (h9F2F#F  mh- F-ALFI|DFF`X@"h(FzI(FBFyDX@(F2FF8F@ ' I@ yDT hB&V8 //LFI|DFFdX J@! hzD(F *F8F1FS#hB7"LFI|DFFdX J@! hzD(F*F8F1F-#hB7.sFFF"FF-2Fv"FF(F0Fp|C0+N FI~DFJvX@!zD0h 8F:F(F!F3hB7$𵅰ȱ#D=Eh (h9F2F#F% mh- F)0 FFOqhFy(FtIlFyDFhFshF0s-ODLFDJ|DDO&  XD5FBFhOqDXFM h!C`0!("+FQFFXF9XFBFF{FP (;(I yD5!Orp?v*:h) `0 hIJFyDF O 6. (I 2FyDqFHFT  hBL6;C-,,,!hFJ X@-ALF|D FFFI`Xh+ H0IBFH;FyD+H)F8F8T 0h*F Hr( I:FHyD(F8FF5,e,-AF 8+aОh7h/]5HxDh(Կ  2HxDh(Կ  (1D @F!F\(F8F1FBFZ V9iF"FXBO3/,ho(H@!xD!IyD iJzDh*@ I@ yDD D@ I@ yD49$99(z98+R9R,sFF#m?F$C" ($ @ p0F I,$@$*FyDF FJ$d F|-IyDFر FiFHOp IOpyD  @ {(I@ yD"F++-OF`F#hD FF +@O II0FyD 8O @ @ I(I@ *FyDJX1.I0FyD '%t0!պнJXF)FzD*F;FX h!FG(@EX0(+L+S+:+O+C+@+=+?+c+pF H!"xD?F!<!(F(F!-(Fp*p M$}D Fl`Bh` OpO0IOp"FyD pV3*pLF |D%HOp2 IOpyD e I`XhC $ I yDp<.{**fChF˱h IyDF h` hXOp0IOpbhyDc*C*pMF}Dx,#` F:("hOph I"FyDFOpn(U hH (I "FyD]p-**7MhF}D+4ChhXOp0IOp"hyD;JXhH (I "hyD-`hh A=XOpz0IOp"hyD>-)))pF# F `K` Fh`XpV0IOp"FyD ,`p})pMhF}DCh뱘hXOp80 IOp"hyD JXhH )(I "hyDpP,a)Y)pF# F `K` Fh`Xp0IOp"FyD ,`p#)pMF}DrXOp0IOp"FyDN~D0F_XOp0IOp2FyDz IhXh[ 8 I K"FyD{Djp+)))((pChFBH@qxD (FF Fp/ pF F`hhCB Pc`p-A&F FFoFhF!6FEӭ&oF h!S&6FhFhhBh!F F𵉰oFFF"hF!0F!8`0F?(F9F"8F˄ F -OL|DFU `F#0h- Fe! FqJKI{DyDDD %@0Fn蘹/-h M}D(F!HF FT)F F"o=F0FVF(>(-hMI (K(F{DAF"FP X'!7F F'_EYF(FF F F)F" zH)FxDF FwI F*FyD)0FIFF0 8F@!JF 0FQFF 8F@!RF+h]FAF8FF F F9FBF 0FyD(4/h+YODYJ t@!zDh@Ft8FF@F F9FXFLLIXFyDLAFXFH FYF FYF"CCI0FyD(6(hD''}%&"Sq @pG"Sc @pG-OFDѰFFZ `h!_ O\]^a`"^I FyD\I F*FyDZI FZyDXI F[yDzVI FBFyDTODSN~D SM}DHFYF(8 ("   IH!xD[ (FIpFBFyDZHFYF#bFi@  9I yD Z(? ( ! .H!xDt,I F ( yDRZ[HF(ICFyDE IF!J!KOqzD(F{DHF!F"+FHFOZ hBQ&$$$$OICO,$ $###0FxF D$y$,""#1B@F Ђx)y 0*h+h*@h pGh Fh ppGpFF FF(F0FBxxA#(i$T" Fsp5  p iF F+ H@xD$#hX `*i$T#HD#*i$T!( FMppKhF F+(ۀ+H@xD#hZ"`ih$T#BD# ih$T 0+HOqxDjh$T! FpUpKhF F+ۀ+ HOqxD#hZ"`ih$T#BD# ih$T 0+ Fp!"pFO%pF F!O%re` Fp-ADh$x+xZ*#O2 $D`2+*x"xaF@0O5 +p;x#7@p28+Կ&&/&.SH@AxDHOqxDK)*pFFFۃhBMhF`hCPc``)0F*Fv p" F< `F ##`$ F-CaMFaI}DFFhX@!h FZHxD "8FIFB6 ++o+@QI" yD!MIyDFu4 7 F+: Н6_`@I FyDo@2F8F2;IyDF Fb607 Q) O0 @!2F.IyDF,I FyDA6_Nr. 2"F82@d#IyD7#IyDF F6_ s I7 yD FI FyD rU0hBFw)Q˺|v F!p F- 1b"#p2pp Ff *Fp"pp FZ p-G0F FPFFF# (%\PFF] pC(F"p+8鄱 F%jppAF"+,%%;#EC+,КnF3*F# *!1 @ L$do@tE 8FIFjF$8FIFjFE(FxxBѐxE x xB018 F Fx01h+h*@h pGh Fh ppG-OFFD(=HK!xDZ FF{Oc FE^3JDQ;x+Q+FG~x8!FEȿA)B+:.8 |d\E1Z@#h+HP@dHaF[F9\Fd@i|*|B ]#C#C;)t jtܽFpO-AF Ff(C8FWCzF+:xx@$d8FRB/yyB$d(8FCB 8F>(ݗnF*ۢBhF  lF _sթhF( ((  !$HxDHxDHxDHxDHxDHxDHxD HxD HxD HxD HxD HxDpG 06=BG)hhG%F* nhihG ` Dh Fh ppG-AF FFFRF1)h`h C`p c`-O!FFh>M}DF(A82ih8FGi:FFh 0F SFYFFرhU 0h)+H` -I(HyD"@Ff1Flp@0FYF:FSF!fU h( lU h+H38FpIyDFHH$ I HyD4!j! H!xD F&F8>DP7s "Bp%-AFFDF x2I^h+ -HH(F,I3FyDF'Hkk"''+   F! & F! ! F  FOq  0I *FyD8 /pK#;`p%@ =-F$D\%P(FFDF F!fihmTh ""Xf-G)MFF}DF x `(ԿOO `(ȿHии$$ >t5#0 $ F1F$JXh( Hh8FF FI*FyDFH FFfFPhhG`h F-A('NF F~D%H!xDS%#H!xDM F`"! F7 F!@ h" ` h``HIh*hpXBF+#+`h+ H0 IHyD*hhB F&mDp@ Fp L5|De#H!xDh H!xD5l*H!xD8" h F 8T hPHK0 IHyD(F p! pFFXjK$"hFF0FG bpp!F L|DF`(FXIT 0`Xh*`hk`0FpF .i F3hph~0`3h#kf hF(HOqxDZ t,; r*+"F +#`b`#kf c` `pFFCm+h*hF"F#G ##` e p-AFF FWtoN:F!h~DH3Xh(!h" he bhhiGF%q(F`p LnF|D- H@xD IhmdX `0F)F "c##`p K J{DpXFHmF `q(F1F "H##`ppsNF F~D)H@xDmiF$$IpXh+H! IHyDBHOqxDfˆ!F(FF F|F8qR.LnF|D FV@i(JCh+GF(B-m+@Xh(=e(F$(4(FxIT cXh)Fpm`H IHyDdiFm(F% "XX8FX1FX$T ` 8F1FEFFUN FFB~DSIfpXh+ NH~H8FbMI#FyDFHH{ +}cWfNkIRx}h(w(F !r,>HOqxD%*;H@xDbmV `2`!1`h+Q(F!F "h+G(CBiQ)?<(F !7(F3(F !p.,HOqxD(F!F"(F!(F!,HOqxDt(F!F(F!F "  ( I :FyD#fF{N&-OFhF(F!Đ clF xhF9Fi@FFhV "o0BhF g hF$h)hF@hFQF "SFhF!hF<hFhF(F* t V  hBF_ m8 hhi`hapG!C!2POp(IOpyDs)#! "XOp0IOpyD-OcMFcJ}DFX"FD.FhOq^ODx Op!"F.DD#0 " FO1v!OR %$Ou$ .Be 0FF +vF %ahih * 0FIF"h #d  B,^FF50I 5FyD3+he+#G+Z+ +#o+ QFq+n+#IyD#I hyDuhIyDIyD AFIyD  9F`x5F |!+)  U hB2       IyDFp0I FyDh0 I FyD`h 8I "FyDO0Z L B + -A4L FF F@FOq|D#.-I@F2FyD+I0FyD)I:h0FyD'Izh0FyD%Ih0FyD#Ih0FyD!I:i0FyDIzi0FyDi2i#I0FyDIyD`T hB (F}(I(FyDb , $         -A)!NF FF~DH[!xDX*F ihRahBڡh#i!hdBܚBۊBF Fc`8V h*HPch*F IHyD;FFbm & pFFc!H;!xDt#ihX#`!H@1xDg%`!ihKB"hc(@ X"ihPB I#hyD@ d#|J F!zD#hhc``p    hSh+BhhB̿  pG-A FF ihF`iFh"hFAhFA ihh`iibi(hBh!k`` H,!xD#hhbi`(F H.!xD  n (:)@ Op(z8+ @CiYhO p OppG K-AF J{DFHmFX `U(F1F:F,##`6p FnF9@iHCh;F F*Fp-ALnF|DF- H@xDx IhmdX `>0F)F:F##`"-AUhxF#N/''~DIpXh#H!xDGlV h F9F#) F9F x`4h F:F4 k xh F9FS| -AF FFF:F)h`h C`p c`-OVMWJF}DjX"#`hQF 8FF(w2i8FhGhi:F FKF0F YFFh5<(bQFJX F@FF8YF0FKF fU 0hq+HP\,IyDF&H$Uh*%##/ &!N~D /'N~DN~DHP.I3FyDFHF4#j#Hg!xDP$ F U 0hB ! F p!FP L|DF`(FIT 0`Xh*`hk`0Fp$F .i F3hph0`3h#kf hF(HOqxD t,; r*+"F +#`b`#kf c` `-GMMNJF}Dm'Xhptt F" Fx|4h*n;FhF!F i:F!FhFhF F!9OnF  xIFhFhFh8Fs  @@F4$hU0o0BhF 1g% *hF!hF4h(hFS(hFY!hF>hF hFh F$tU hB^ mnYhpGh hB  pG@mpGhF+ H@!xDck+ F FH@!xDBLFH|D&X3h+,!4"(F&XJ#HT zDxDIKJyD{DzDHIxDyDKJ {D )F0hzD # KkpFi FFhGiFh F*Fphp0mj pF##( %-0!FF F F(FpH7dh Fh ppGpFh F8!+AA!hh@@b!BȿIIBI VhahqNNB1FNB1FXBB̿O O B̿! I(F!F#+`pF#<@By0 ixxBѐxE x xB0148 FO1x" pFFx F&#76e(-pp8F FFC"3Fx "3F8 p8  h y7!LiF|D(8xjmeT `˅Hib !!! I`Xh+H IHyD~!T0`>F7-"F- >F@jCcb+ FZFijKb FN&-AF FFF8F)h/``h:`C~``c`pF M }DFI"f`"`hXh F`pp FIpyDIpyDIpyD8C5FF h^hI#pyD(- -%%.& IyDE IyDp#(ps# FFphH!IyDF0F^p (F!F!+F Fj IyDFpCIpyDj(F|aZ7Km{DehlBiF@i# JXh+H IHyD\>9j-OFFFF?L|D(v0F>Np~DFDDDh8JNhBK0j(HZF2cXh*;%Hm(6jm )JzDsm (K{D(IHyD(9FJF4ع Xh(HLh! 8FsmAF+SFF H "1F`0F(0FF1G cf pFF FF'( F#1FFCa"F(F( Fp-O-`DF|D FFCh+ FO!K,@8(F \ DFyD !!AFBF@F fDyDF(F!(FyD!phIF2 H!FH(9FF 8 b a"F!F;FF,@0@AFRFcF(F!W8FnHF(тFHF7I(FyD \ !BI(FWFyD!;hIFDK # 0qj hBћ@pj$0Bh XhB F'XF(XFI(FyD!si+I(FhyD IyD*, $,$(FI̒R 0yD"F \ BF!̢Q pAF | D8hI"FyDF8h7F(F I(F"FyD#F phYFJ.FC|h+j+:AFHSIFF8@!JFhncAFBFljKFV "FQF @cF j0F qHFXF/(рFXFQ{I5F"FyD(F#F>FF | UhYFiOġ D/F|h iqj(j hB љdpjkjBh XhBZ@FA(=F siCh"FWI#FyD8F UIyDTIyD(F (F !mpPFp_~!FDOCg!FH@!F 8Y! F#FF$@bFAF(F AF(FiDC" 5!FH@eAF 8'! FCFFhjx"F@cF8FijQF k#5{+&k}tgTs FFFmsFh + $"#F!F F 7*mF(F1F}0F  F `|pF FiFhGiFh F*Fpp5F Fh+XC!Fpjh,\C!FpjSdi,pc IyDF#cIyD#xvpM Fp}D  jIU yDhpp=FF hFOq H!nFaF IhFyD)F8 IyDFhFK*HxD pKJ{DsX%Fh+ Hh)F0FCI"FyDFHI|*D-CM FI}DFhXh` #(6!mB"iO2"ed#&hh(Ci+̀3+Ȁx(@À U h)0FU(𵀂I0FyDi+!m)#"H!i( e5FF h^hU0h !  !JF  !FaIBFyDF /( /''.#C ch~j W.5[j.8h#8U hq@HP1F FBIyDF:Hm0  l f6%0ˆ,#8 -KXh@(H -I&HyDCBix_s fd~ˆ `U sx'xh8Fvx";I8yDF8F J U  hBf ! 8Up!FELI|DcXhe`p:-GpL FpI|DFF`XFh+ iH@jIgHyD"2!S!ObF0F7`cx^KXT @:F#FFPFAp`R#F:FFPF6`I#F:FF -PJPK!zD{D`#e0a$ M0bpaA4ex":'p?'F%tN|"8F3fFa@< dpb" 2"(bF( oO` !"b,65+H@_xD"#Dj.0/ ,$4c(dH(qa"dqd&A]_iF[@ i-AF FFhh+h*ahY!p8@F J K $i,0F)Fq0F)F!7h[h+BhhYB̿  pGF`h+h*`h h@K` F#xp -GbEOFD.~%,$6&0(A@hF1F,&$(S0&`B'H@xDV$mEEEFW0h/ Ht0I2FH+FyDOOF  DIFhF 8F@E%oF" FiFF5B+R p!F L|DF`(F lIT 0`Xh*`hk`0Fp$p0F(F F(H@qxD#kDHckI C#p RB"cccݣt,2q"cacD80i+H8K[!F*Fp?B'-O(FFF,0%M}DFF41FH:FCFFXOoCox#!JXh( HH@FIZFyDF H=oCAFHF!Fv# #PF0F&TLFI|DFðFdX JOq hzDA(Fs"+F8F1FA#hBfCp+M8}D FoJ+H!F"!p"!Fx@@ * I@ yD<0F;IJyDpzDsI0F<#yDnJ0FpzD0FL0U h(ap(pZYZ-ALN jF~D FF+JHOqxDQHJ##bXh(AH CI?HyDoim !ke*nhnB)fB"jf/En[8hhC(4H@!xD oX8h5(.H@ !xDaoYam'((H@!xD(i!F"i!m 2(F!F$#0i!Fhi!Fo!(Fg!Fn(!" F8# FceV `F`D(pF M Fx H}Dcm I-XyDJ+`v"0F*`!F:p&.l-G*MF*J}D FFX"h!8FO<0$DFd>@ 9F F">F hAF'QFO h#js8PFa@!F70F@Ff(@F 8FU 0hB-CFFhiF%nFOh!jH!`IF@58F!F5]hF((hFK(F -G'LF|DF)CH!F(; iF&oFE 0H!p)FFHpQFHF6rhFhF(hF v JXh( HF(I*FHyD&-GFF# FFpX%F@F!'28F0HFP4IRFyDF8FgT!H{/IyDF8FM@F!#>' @ F(%I@ 'yD+0(2 @FIJ(FyDzD1HF0cI2FSFyD@F%T!H9IyDF@F J F)FzD<(' F8F%˂ѹG-O'Fh`Xh+ 1H{02I2F.HCFyD 2FQFCFhF+J,O , DD4hijihj1jhB љ&hjsjBh`XhBT h) H?@YF0F|AFFH!:F3F(F0FHFWHF(HF  FQWBpjh M"h h}DB""`!hchh"h`hU 0!`h`pKI{DFjXXhhB F@( F"m F! FhF W##`B+@@h(=hiFnF)h F"ghF8F(hFZO1*F F`hh|hymv ie``iCi j j2`ji%` -OFF FhPFıiDhGhhiRFFFFFhϱ ipj9jhB њ tqj{j[ JhhBO8 E@FPF(,PFF(@( Fz"QF(F a[ ah3hb)bBrjh*bjﱚB0F!F256J0F!F+FzD(,РjcjA8FZbbb;PPB0F!F(J0F!F+FzDxbjjPO`bb*Fh,F''p[ h+HȱN~DN~D  (FQF!RFF FI2FKFyDH;(FFv@F &t?-OpMFpI}DFFhX,h8F &9F5Fرi2j¹i$ jhBј@x$cjU Bh hB򟀹G$O  SK;"9FXF XFL4{@YFF豆i2jҹi$j hBѐ$bjAhXhB@F1F:F#  `E&U0+7 08FO H AF%Fֱ)$#HBFQF0FAFF F!I:FKFyDHm * H(I:FHyD^>0j(HOaxD$00F U hB  U h`b F^^h-C,MF,J}DFFX "Fh! @F,O0$"AF(H@$AxD/p1F0HF"FC0#PU Fh#/ #+a"F8F U hB< -A+L|DFFT` "# 5h 0HpF !#2F@F9FyPT Fh#- #+a2F\ (FT hBApG-O\N#F%~D F*h*@T:T DXCDDO`h( V 0h)9HH(4!:F h}bh!:FF(FQFFޱFxF pxC^JpCpCNp C qC CJq CqCFq FhF`! I JhFyDlFzD+* uh2-CLFI|DFFeXF(h5R"IFF FR9F2F FjFAF F FZ5+hB7>-OLm|DdFT0F@"hdx2`Ah `0!.40#H!xD "H!xD4\!8F i l   FH@F9F"2``A".(&@FO "HF9F2F  `!5 Fn\1Zpp3.O e c 5y*F a.uXF9Fh(0Fl b6..OO e a(1T 0xhi6 p/ bxF `(Fr+ f)F0TP)hA I yDbګ" g;8FYp3\2-Fک b c 23 f6A8F g)F"8N b!5u 1tqtC `  6B c (WНg aw `.`& `2F$ e a5p' c,p 3  `(F c3FG c ` 8F1F y0FIF a jJF#(F1F QFIFPFJF i#(F  IF HF9F:F(F#GFfOr=!(F4I(FyD"d*r g 9 a 1"+Ff: b58Fdd9F+FF$ + `8FX9F+FF 1h#(F<0_=008 dT hB mq;vh FhoOppGpFh+ Fhah@x FPh+ahZ`H``O5(FppF F KBآhch hJB Fhah@h` p?Bp&M|5F}D t5[h+?pU hA  I yDK&{DPS20+65Jh4U h@ I yD#6666p*#ӵFKB& *{D!lɱ`S h+HpnIcHgyDg#]#66&!"HXh6ܽ3rp FFF> !F*FP p Fd"!M-A`wFhM}De%sua ԃBt("l7p'H!xDf0Fu(SKBMpl'hGDBA0F"Dq H!xD6+&#Pl  " 0Fv(`U h)@H(IyD|6+"0F-V(|v8F9FB0FI(Uh(@xH(|IyD"0F-"-(ɀU h+@΀jH(ȀoIyD"0F-"(0F(0F(tU0h)@TH(ZIyD " 0F(0F(y0U  h*CHk(zKIyDf#0F"=9F(_&BԿ 9F"0F 8Uh+G'H3(Bu0F%Vp)I#*FyDH3& " 0Fs\U h)HIyD H O36H!xDg F!?BFy:V phF F+@Fh`h bhh```)(F"r p 8@dsMfF0F}Dhp7+ l;p7l'HOqxD0F( G- U 0h)Hi I}HyD #Uh*vHW yItHyD#6U 0h)lHC pIjHyD0F(Ā#Uh*_H) dI]HyD!6 &0F tl@p'p0F t'l7p' U h)?H EI=HyD0F20F-1+B)>( I0FyD###a I KyD!b{Da$ F-AN0F~DF;Op!"F]P(h?(HV 0hB8F I8F@"yD !"F =)hJX`*` ȳ=p@F, h!F#i15h=-?(!X 1FX"Fl!hmc@)eke hCD"P#`3BHxD?poF[!"F$ ! g`"oHxDa oo-GFFF!:F F%+FQF*FN~DF O3c` `!IF*F +Ft"F hq8V hB@FJ` I@FRFKFyD2`B8h Ch -OͰLI|D`XWX^h #EKDDO .FFFWFRFeF  0\+ 0*O @9 +`Yh_ p "+ F"C'+!)# ""7* )3˱`YhAx+*"+!Q"*'+"*F ! B'JF`OQ'07 O KFJF! г\ "+ ?aYh_ q ԟ(Ft(YIyD^ F* T5FT hBm0F'+qX(eV LIOs0FyDBFWO  0  B    <+2*5FF9KXhB7(F%(2V4IyD*/H "XhE$(F-IyDV(FBF±T hB(FPBFV!I3FyD(F'P8FKT 0hB;+""#+B*?#B J5FXhBVM al0 FF!hF+*$ F)F"#hFp70𵅰F$@MFFF FF@HXijKJzDKJzDKI8HyD>8H#Xh* 4H(EI1HyDj/T h) +H(=I)HyDjk(I`Xh+ $Hp(7I!HyD*kkM|T 0h* H[@*l ,JzD,IHyDJXh( HI(&IHyDjl4T h+H8XlJzDJzDIHyDp20A |rmfMM5-G%L&IF|D`Xh+ H !IHyD4NGF%`~DT 0h*H H1F*Fg8i57B(T h)H IHyDN2-A $FF@FOqFFI@FyDIyDF@FI:h@FyDh:hI@FyD1F`kS!bIyDF@F01#I@FyD| ' 0 0dFȱ'hHy (F1FiF0x#gI yDJ(F!aI yD=  ^I yD5h1FF YI yD)`33#*\%s(5/5-KH@a!xD^t |s"x3Q(Fl#p(F F=IyDF8F(F:IyDF8F(F 6IyDF8F`3#3I8FyD3#0I yD!-I yD#T4#'I yD8$*#I yD3N IyDqIyDIyD#"IyD WFC@6,d]TLD?*"!!pH3F!"F XQTE`%T `Th$a@!FTc `T3`pFPP1# 1 L11+Y *030( 03Y-OF~ F F FP-o0+k+h+C *?NX"Oh(8h0@F@n* FO0AFh9) (F7'(FF @q XFX"(6J &'KD4{D)hB+ khhdZh*"dh+ccH@{xDر%* F5S"m0hB0 F @ F4 FU F{-ArLsIF|D&`Xh+lH#X1F4 jIyDFfHT `2h*aH X!8`IyDFZHlTh+UHxv"SIyDFMH4T h+ HH0LIEHyDP"xTh.?HX!`AIyDF8Ha9H#Xh*4HX!d7IyDF.HLT h.)HX!h-IyDF"H5T0h*HX!ll"IyDFHpbOTDphhT h)Hg H9Fh6h.(T h++HT8x JzD2"kS3* BJzDBI@HyDT0h*:H!X!|9IyDF4HT h(/H X!/IyDF(HT0h*#HX!$IyDFHxT h( HH" JzDIHyDwPT0h* H0I HyD"e,T h(&H"¹ JzD2پzmZEɽ4<νJzDIHyD7Th+ـHx%|"J}IyDFxHTh+ sHl0vIpHyD" T h) jHZ0nIgHyD"Th+ aHH0fI^HyD"xT h) XH60^IUHyD"TTh+ OH$0VILHyD"0T h) FHH" LJzDLIAHyDTh+ ;HH" DJzDDI6HyDT h) 1HH" ;JzD;I,HyDTh+ &HH" 3JzD3I!HyDnT h)H`2*JzD*JzD*IHyDVXTh( HH," !JzD!I HyDA0T 0h*BH(=JzD225 z]eJzDIHyDDT h)يHGX!.IyDFHT h+H0X!IyDFxHT h)sH`2vJzDuJzDuImHyDT h(gH=~#iI3yDF^H|T h(YHxB~#\IyDFPHyHT h(KH`#SJzDRJzDRIEHyDaTh+?H`JJzDIJzDII9HyDIT 0h* 3H0BI1HyD #7Th( *H0:I(HyD$#%T 0h* !Hu02IHyD(#|Th( Hc0*IHyD,#XT 0h* HQH0# !JzD!I HyD,Th(AH<(<4#JzD12%xƹɹZN8"ڸEJzDEICHyDT h+ =H0?I;HyD8#T h) 4HH<# 6JzD6I/HyD|T h+ *H0/I'HyD@#jT h)!H`D3%JzD%JzD%IHyDRlT h(H`H#JzDJzDIHyD:% -A}M~IF}DhXh+xHM yIvHyDvOY2h* qH?@h rJzDrImHyDUh+ gH+(kIeHyDhU h)_HXficJzDbJzDbIYHyDdU0h/ SH([IQHyDi@Uh(KHX"jSJzDRJzDRIEHyDU p>h.?HXcjJJzDJJzDJI9HyDtUh(4HXjBJzDAJzDAI.HyD]Up>h.(HX#k9JzD9JzD9I"HyDFU h( H@i 1JzD1IHyD2`U`2h*HXj)JzD(JzD(I HyD4 F~Uh+MHh(H)=JzD<2rJMkQ7õ?jm0wJzDwIuHyDU `2h* oHH pJzDpIjHyDU0h/ eHH gJzDgI`HyDUh( ZHH _JzD_IUHyDXU `2h* PHH VJzDVIKHyDo0U0h/ EHH NJzDNI@HyDZUh( ;H0GI8HyD HU `2h*2H`0q=JzD=JzD=I+HyD0Uh+ &HH 4JzD4I!HyDU h) HkH ,JzD,IHyD\U p>h.HV`0#JzD#JzD#I HyD,Uh(EH>(@ JzD52T7? ' zk޲JzDIHyD4Up>h. نHH JzDIHyDU h+ |H0IyHyD zU h) sHH vJzDvInHyDeUp>h. hH0oIfHyD SU h+ _H0gI]HyD AtU h)VH``^JzD]JzD]IPHyD)DU0h/ JHy0VIHHyD  U h(AHg` MJzDLJzDLI;HyDUp>h. 5HO0EI3HyD ̀Uh+,H=`h. kH}0oIiHyD!Uh+ bHk0gI`HyD$! U h) YHY0_IWHyD(!\U p>h. PHG0WINHyD4!8Uh+GH5`,NJzDMJzDMIAHyDU`2h* ;H0FI9HyD!U 0h/ 2H 0>I0HyD8!Uh()H`h.H`@1,JzD+JzD+IHyDy`U h(H`D!#JzD"JzD"I HyDa0Up>h.DH(?H1JzD42ٯ~k]RH=1ήѮVY&)׾ĭJzDIHyDUh( ٚHe0IHyDL!`U `2h* ّHS0IHyDT!h.3H`1FJzDFJzDFI,HyD.Uh('H~`|!=JzD=JzD=I HyDUp>h.Hf`14JzD4JzD4IHyDTU h( HN0-I HyD!0U`2h*WH<(Rq/G"JzDF2a@3 i?ݽǽ~ëcC`c%03تJzDI~HyDUh+xH`yJzDxJzDxIrHyDuU `2h* lH0qIjHyD!cU0h/ cH0iIaHyD!QUh( ZH0aIXHyD!?`U `2h* QH0YIOHyD!-Hh0II;HyD!U `2h* 5HV0AI2HyD!U0h/,HD`7JzD7JzD7I%HyDU h) H,00IHyD!tU p>h. H0(IHyD!PUh+ H0 I HyD!,U h)=H(8avJzD-2Q>!ѻ t^HNJzDI}HyDaU 0h/ wH0yIuHyD!OUh( nHH! pJzDpIiHyD:U`2h* dHH! gJzDgI_HyD%U 0h/ YHu0`IWHyD!\Uh(PHc`!WJzDVJzDVIJHyD,Up>h. DHK0OIBHyD!U h+ ;H90GI9HyD!U h)2H'`a>JzD=JzD=I,HyDU0h/&H`5JzD4JzD4I HyDU h)H`a,JzD+JzD+IHyDTU0h/ H0$I HyD!}0Uh(FH(A!JzD62˺O%*-j^M3RUJzDIHyD/IMDU p>h. يHyH" JzDIHyDUh+ ـHd0I}HyD"U h) wHRH" zJzDzIrHyDU p>h. lH=0sIjHyD "Uh+ cH+0kIaHyD"U h) ZHH" bJzDbIUHyDXU p>h. PHH" YJzDYIKHyD0Uh+ EHH " QJzDQI@HyDU h) ;H0JI8HyD$"x(4I (U p>h. /HH`# =JzD=I*HyD]Uh+ $H06I"HyDh#KU h)H`lc-JzD,JzD,IHyD3XU 0h/ HHp# $JzD$I HyD,Uh(GHn(Bt#»JzD72rSL533C('ٸɸ>JzDIHyD`Up>h. ّHHx# JzDIHyD4U h+ هH H# JzDIHyD U h) |H0IzHyD#Up>h. sH0zIqHyD|#U h+jH`qJzDpJzDpIdHyDiU`2h*^H`shJzDgJzDgIXHyDQdUh+RH`_JzD^JzD^ILHyD94U `2h* FH0WIDHyD#'U0h/ =Hw0OI;HyD#Uh( 4HeH# FJzDFI/HyDU `2h**HP`s=JzD=JzD=I#HyDUh+H8`4JzD4JzD4IHyD`U`2h*H `s+JzD+JzD+I HyD0U h+UH(P)E!JzDD2բ?O-% ܷ֡١۠jRԠנ0pJzDIHyD[U`2h* ٛH0IHyD8$IdU0h/ ْHH# JzDIHyD48U h( وHH# JzDIHyDU`2h* }HoH# JzDIxHyD U0h/ sHZH# zJzDzInHyDU h( hHEH# rJzDrIcHyDU`2h* ^H0H# iJzDiIYHyDhU0h/ SHH# aJzDaINHyDHH# PJzDPI9HyDU0h/ 4HH# GJzDGI/HyDwU h( )HH# ?JzD?I$HyDbU`2h* H08IHyD#PO&U3OD0+ H0H9F#;6@.@U h( HH4$ #JzD#IHyD#U0h>2k]CA(Şߵq̵Gɝ{eWW!&* cH30bIaHyD<$U h( ZH!0[IXHyD@$\U0h* QH0SIOHyDD$8U h( HH0KIFHyDH$U0h* ?H0CI=HyDL$U h( 6H0;I4HyDP$wU0h*-H`\2JzD1JzD1I'HyD_U h)!H``4)JzD(JzD(IHyDGlUh(H`d$ JzDJzDIHyD/7"x"ZO0@0O0@yDN2[O0@0hO0@yD? B2B O0@08O0@yD$YO0@w0O0@yD"ZO0@h0O0@yDXO0@Y0O0@yD2YO0@G0O0@yD#ZO0@80O0@yDXO0@)0O0@yD 3$YO0@0tO0@yD8# O0@0XO0@yD8 O0@0<O0@yD83[ O0@0 O0@yD8 O0@0O0@yDu8# O0@0O0@yDeT O0@0O0@yDU03[O0@0O0@yDF<@#ZO0@0yDO0@4(hȱ ;#BB O0@z0`O0@yD#ʹ ;B#B O0@]0(O0@yD3`#*1) O0@E0O0@yD1yDA#"3+hYO0@!0O0@yD#ZO0@0O0@yD3+sO0@(lyD<pYO0@0hO0@yD,3#;#*3{P(@CO0@(<(yD +5O0@(.yDO0@_%yDyD ek"(FyD` #B O0@8$O0@)FzD0 #B O0@}@$O0@ azD #B O0@f@t$O0@ azD #B O0@O@H$O0@ azD #B O0@8@ $O0@ azD #B O0@!8JO0@ azD #B O0@ 8JO0@ azD #B O0@8JO0@ azD #B O0@8JO0@ azD| #B O0@8JO0@ azDf<@$B O0@8JO0@ azDS@D4B O0@8JO0@ azD@DH$B O0@8JO0@ azD-HL4B O0@}8JO0@ azDLP$B O0@j8JO0@ azDPT4B O0@W8JO0@ azDTX$B O0@D8JO0@ azD\`4B O0@18JO0@ azD`d$B O0@8JO0@ azDdh4B O0@ 8JO0@ azD #B O0@8vJO0@ azD8<$B O0@8nJO0@ azDB O0@8fJO0@ azDmB O0@8^JO0@ azD[484B O0@8UJO0@ azDH O0@8NJO0@ azD8PiH#RO0@(FIO0@yD' NV  hB m<]SXakrƳ׳ (P+Poܴ)ѴiI)ѳjV>'в|ap0Fs%* F5S"Z0hB4PpF FLFF|DFFB I`XhB(F{/2h HxD HxD I HyDxD(FO hg JCz0F" FC-)F 8#, # ""`0p FF*F!0"\,+ #T2+p-O FFxDX*&   9F(F1F:FFOpF;3x+89F0F1FF(F(XHFQF('(OX 0hBF F!(A9FHF9FF(F9FF0FIyDBF F',!2FOs(KXhE F HF1F1FF(F IyD:F F[F f-GFFF#@DOp!F 8F1F*FCFB F,!*FOs(l-OOFFFF,+2 ,  FOqJF(FOqJFOZF FD9F9F2F(FNOPF!"F+F~DDPFAF*F#F % pF FF@ )F"FppF F)FB FpM#F}DFFұ<"IhXh+H" I HyD H!F2F;Fz$ F1F~8$ F34dHpF F)FB Fp-G FF FOqF  :F% :FHFOq#Oh$"I F2DyDhCh4N#~DXi#HF1F@HF9FX #@5 -dNFJ!FFPF@ I@ yDA d sRphF F* FZhOqX%* !"FOs@hF F ( I FyDhH@A%xD(Fp u-G%LF%I|DFư$M`X BqF}Dh@FE 8F9FF0FP@F)F2FYHF1F(0FQFzF0Ff0F!Or E(FT  hBFrb_-C hF FF-:Nh.7+x<+4(F8)\>)-.T9FhF<9F `HxD5`` h|hF I"h(FyD(Fn:FF@Fo``(F --O߰VLFFkUI|DFl2`X * hi]jNI0FyD 0TpJI0FyDfF(IO  , l .!@"@F  :AF"3FMر@F!RFXFAFpaj 2FPFKFAF^Oq:F*(T 0B&8F&""IbXhE(F<IyDl ThE (F,8IyD(FJFCF!Or!@" ]T 0hB_,a9Z-OFDm FY H% h" 0FOq|O(h:FCF6(yF܉i$'FD~Dhh/PFAFd@PF1FU/7\@/ќY 0ẖ + I|DI|D "FyDF |Yh,4 F FJ(@ ("L@ yD@XFyDZ(Kjh*HЩh)EXF!:FCF(h8FyDB0$"Bs$28FO|AaEY hB F(ۅ FyDSӽihh+ʅ2ƽXFyDꀹhhpXF!:FCFp(kh2xXFyD逹jhrXF!:FCFX(ih LXFyD鈹XF!:FCFB($2C$} XFyD鈹XF!:FCF)(l$A$"dXFyD鈹XF!:FCF(S$2C$KXFyD鈹XF!:FCF(:$A$"2XFyDr頹XF!:FCF(!$"B $2hh`XFyDV鈹XF!:FCF($@@$4XFyD>鈹XF!:FCF($"B$2XFyD$`ihQXF!:FCF(фhhv(ȿ Ȅ Y0hE F( FyD0XFyD(9jh *4XFOq:FCFU((!0F((QF2F(D Y0hE} FR(w8 FjhyDn(XFyD(;jh*8XF!:FCF(Yoh8FyD`N8FyD!`C| Y0hE9 F(3 FjhyD*XFyDj耹jhrXF!:FCF(ihXFyDR耹hhpXF!:FCF(kh0XXFyD:耹jhrXF!:FCF(ih,XFyD"hhhXXF!:FCF(σhh, kh0ƻ Y hE F( FjhyD-XFyDhhXF!:FCFW(hh!FXFyDpXF!:FCF>(#01|pXFyDjhXF!:FCF&(iPihY `aDXFyD(KY hE F`(`I FjhyD}!0dqdcwZIXFyD(@hh(XF"I:FCF(ahhرBO|bE HY hEO F$(IDI FjhyDA"ccrd;СMP$nK**(IM=؞:;W:ÝxgV&FA ٜuj?›rz>ܚ+IXFyD(0kh+-XFI:FCFg(hhPO|AaEُKY hE Fn(𓁉I FjhyD !0dqdIXFyDhXF|I:FCF3(v perzIXFyDFhXFqI:FCF(aX]qIXFyDpXF!:FCF (M"!HgIXFyDйkhñXF!:FCF(6hhh(- 'XIXFyDh(2ih)/XFJI:FCF(hh (pc  Y hE F(mh <@I*FyDF Fm=IXFyD.xihiXF!:FCF(ۀhh ( Y hÈ F(ƀ*I FjhyD>#0$IXFyD(E P !:FCFJ (h](1FXFZ )@ j(I@ yD1ߘkw֗ė{IXFyD(@ P !:FCFL (h(RPF1FF(MtY hpAH(hiIyDFAHY  h[A0IAjhyD$Y hpAHhBIyDFAY  h[A0IAhyD{ R Y  hE F(I F*hyDb ߿IXFyD (shh(pXFI:FCF(ˇhpY hB F(𹇛I FyD2XO|F8`E0Y hB Fu(𚇌I FhyD0FnhG`F`hI0FyD aI0FyD""au}IyDaaha+i+lcaixHxD`advIXFyD뀹XFdI:FCF(T0F"`MlIXFyD먹khXFWI:FCF(;0F|Fhh`1_IXFyDr(?ih)XFI:FCFV(#0?˖J^ Yוyg5XXFyDȹihhXF!:FCF (OhhhCXFyDꐹjhXF!:FCF(0hh$)PXFyDj꨹khXF!:FCF(hh!4( XFyDL꨹hhXF!:FCF(hh"4!(XFyD0pXF!:FCF(ޅ#,1ٽXFyD긹XFO!:FCF(Džhh(c8!8XFyDxXFOq:FCFe( <XXFyDxXFOq:FCFN("H!,XFyDxXFOq:FCF7(z#@1uXFyDxXFOq:FCF (c!D^XFyD(@hh(~XF!:FCF(H0F *chh ehh  Y hE. F((t FjhyDhر TY 0hB F( < FhyDh #عh Y hB F(I FhyD^޼+iihhh ӼIXFyDF(]ih)ZXF!:FCF{(0FK (A c@! : hhSFx Y0hE Fv(I FjhyD𓼨hб /<Y hB FY(~I FhyDvihhh mIXFyD`khSXF!:FCF([hhIBBQY hEG F(AI FyD:IXFyD|(@kh+=XFO:FCF(%ohI8FyDf !8F <hh jh! 4Y 0hE F(I FjhyDrIXFyD4萹ihXF!:FCF(hh}ٻIXFyDXFO:FCF(ȃ"!hhhah(YXFDQFhhرXF!:FCFZ( F)F"(QF:kh1]IXFyDpXF!:FCF8({!vSIXFyDpXF!:FCF#(f"!aJIXFyDpXF!:FCF(Q L@IXFyD8>IXFyD(@XF!:FCF(40F5I(hyDr(1hA `0KFO /O/HD/JDxD zD 8FQFV(R1hAx4lJ( p7; ǐwk{~ 8FyD(1hB@8F(1h@8F(1hA 8F h1hB  `! Y hEy FN(s F*hyD0hp/P1hB`[XFyDXF!:FCF(JABXFyD(fkh+cXF!:FCF(-ohh8FyDl8@!P8FyD^,Y 0hE F($ FyD~8FyD>8h(X8FyD0Hh8yD("2ahih)zD ӹXFyDhhXF !:FCF}(hih)zDCXFyD(Sih)PXF!:FCF](hhFt9Y`0`hh0FyD0`Y `T0FyD8D Y `yYhBo FD(i FhyD`Y `YXFyDXF!:FCF(Hhh(L@"P!;XFyD|FhXF!:FCF()%XFyDf(skh+pЩh)m P !:FCFJ (h(YFhhAYFFh(hh&( ,wlIXFyD鈹XF!:FCF$(g8#B83_aIXFyD鈹XF!:FCF (O8A8GVIXFyD鈹XF!:FCF(78#B83/KIXFyDp鈹XF!:FCF(8A8@IXFyDX({XF!:FCF(8#B83?' q`K@>)  _Ԋ4(Fk~ZC+XFyD(ghh(dXF!:FCF<( F)F"~(whg8FyD4:8FyD!4/t Y hEV F+(PX FyDHDY 0hB> F(8, FyD0 0yDjh0#$ XFDQFdhhرXF!:FCF( F)F"(QFihĩXFDQF>kh۱XF!:FCF( F)F"(QFjh"ػ|XFDQFhhرXF!:FCF(ă F)F"(QFaih4XFyDkhsXF!:FCF\(jh,"XFyDhhpXF!:FCFD(ihXFyDpXF!:FCF.(q#2lXFyD@jh2XF!:FCF(Yhh(F\Y hE F(l FyDR<\XFyD|@kh3XF!:FCF()hh(FYhB F( FyDR XFyDL(5kh+2ЪhXF!:FCF(hOqCBih@<A Y hE܂ F(ւ FyDNκXFyDpXF!:FCFz(!hXFyDpXF!:FCFd(#3@XFyDhhXFO1:FCFK(0Fihh#F XFyDjhXFO1:FCF/(r0Fih"FkXFyDF(Kih)HЫh+EXFO1:FCF(QRFihSF 9RFhSFF 0:"( "B!r. Y0hE$ F(D FyD8XFyDVF(Jjh*GЩh)DXF!:FCF(RFihSF SFhRFF ;#( #C"r"ڹh YhEЁ F(ʁ FyDB¹XFyDF(@kh+XFO1:FCFf( a :hh 1SFu Y0hE Fi(4 FyDh aF 1RFSFQ(:Y 0hBo FD(i FyDa8 aF 1-`4YhEL F!(F FyD> `$ B P =t˄ a\ , #Bvˆ!hXFyDbxXFO1:FCF(! <XFyDJ툹XF!:FCF(T2CT"XFyD2pXF!:FCF( D۸IXFyDpXF!:FCF(ˀ!HƸIXFyD혹jhXFO:FCFp(hhXLIXFyD쐹khXF!:FCFW(hh7XIXFyD쨹XF!:FCF@(khP3}HxDPwIXFyD숹ihyXF!:FCF"(e FihY_IXFyD쀹jhrXF!:FCF (Mkh\1HIXFyD쀹hhpXF!:FCF(6ih`1IXFyDr쐹jhXF!:FCF(0F)FIXFyDZXkhKXFO:FCFIXFyDH(KXFOa:FCF(oh/8АI8FyD2  濋I8FyD( !ۿI8FyD "!пTY hEƇ F(zI FjhyD8!uIXFyD됹XFOa:FCF_(1#!iIXFyDhXF!:FCFG( 0b`IXFyDhXF!:FCF3(v!qbrWIXFyDhXF!:FCF(b"b^NIXFyDPihA F(hMGIXFyD(@kh+XF!:FCF(7=IhhyDx(uѫh+rd3yЇć.8k56ȆN`$8ׅ ЅuNԃfD&͂|V?$$Áāsh9 F(hhh`XFyDhXF!:FCFW(!1cXFyDꀻjhXFOQ:FCF?(#t3hhxyD(@ttxnXFOQ:FCF (c t^PXFyDꀻihXFOQ:FCF(J"l#hh$pyD(@~M~s~Z~2~~}p}X}X}7}}|||f8|{μ{d{c8{{{zzzz=z!zzdvyy[yfyc:yu6yy?yyxxxeIXFyD쐹khXFOQ:FCFb(hhBPZIXFyDhhXF!:FCFJ(RIhhyD hX4h1 F(zhihTtGIXFyD(,jhRXF!:FCF(bhhCF+8X YhEO F%(J4I# FyD*F;@0IXFyDFhXF!:FCF(0"ra+&IXFyDnXXF!:FCF paah Y0 hE X+hIHyDxD ~D Y hBE mpw{vvvvivv-O=MF=J}DF㰚FXmhna F 63KBFz l F UF` |`F& @` 0!@" F64HF!F"Iر F !F:F@F]l# 3F"!F8FZ F!@" !XFJFOs`F(OrHF aUFZ 0hBDc?B FFF *FH1FxD#Fn-u-O'LF'I|DFݰ&N`X% l  f~Dh [!!@"8F5HF9F"3Fx" 2F9F@F+FXF,!JFOs( 0[T hB] u! -O)LLFF|D F)GH$ 8 FIFJDyD zD wCIPh2FyD0(!@" FJ=K({Dzh)*"!FF W!@"PF2 "W$YF@F8먱 XhE(F_ (F OO   E "0FH K`  <(")LD*QFF ,B6'Tt''#-AO FIDFFxXFh+ H(I"F HyD " !F(F#F2" WsK{DhYhB C L B݊B@R`K{DX` Bڊ`Q@p LFh|DfhchB jhhBihDpBh   Kh{DR[hB"``hY`hB̿  pG8QpF F H!xD "F#5`t`0F``prp FF@!F| 1F 0F@=IyDF(Fd(F !4" I(FyDX+* pUrF FQhh"0F FhF@!2 IchhFyD"h/mF+* 0q#O2`B`a`Ca`pG#) #;Bh*ۃh`h apGFFOqhF2FIhFlFyDkh+IhFhyDhe!3F F(FZ I*FyDFhFIhFyDpPTq?qJh+h*@h pG𵅰FFhFOqFIhF"hmFyDwdhd!3F F F I"FyDFhFIhFlFyDhFpp0Ch0M+F}DUۃh+RiBhaiBKТh!h`h F"(*"`h!K(ѠhhX abah(*H;0 F%hUI*FyDFHX hH'IyD 8U hJ H( IyDH"ht0F! ApApPpF:M chF}D+cFOrB!b?``U h)R,H(M-I2F(HyDF!XOp0'IOp2FyDo"&``h>(xU"a`aa`h+#H F%hI*FyDFHJ?4U hKH( IH"hyD6! F  p!ppppF@hM(}Dh IhXhK Hi( IHyD"h#O2#`b`#a`ca`p! oB##p SsF RBBԿ  BԿF@!H^!xDBd,d FpK{DFJXh+ H IHyD j F!$"Ffo&K-AF%J{DF FXh+ H0 I*FH3FyD$H:!xDa F!$"?H?!xDSH@!xDK/8F| b\! j:F#j`!j`eaa aF%oOo3o#ophF F+bha`Fh`3(FF"X p#FF`FC`Fh$,`?0FiF $l` B##sSsF FF hPI"FH+FyDxD  F|Zn9n4K5J{D-AXF Fhi+VXhXIhfhB*hhB+hB'ih h`a`*hB`i#`iS`hO10h0`ih@&ihYhHBԿX`Z`hq`Oh+hiBqh/Կ##B,#u"5hihF(FD!pJhB`h`p%K&J{D-GFX#ih+=&O5F4"(F\ FPFzY!0+%І+ ("iB&i(FQh"8ihFHFXF#FF5iYhB'`;MF;I}DFhXh+4HPsh6I1HyD2hbhh%`i 1H!xD0h(Lhrhch)7КB1ѦhBD)O6D:hB>`U h+ HZ(!IHyD:hiYhB&"0FhihF(FT"8 ി  BѦhn6B  (    F$lmlb lh[h+BhhB̿  pGhch+ Bh*:B``M pF Fh FAh`)F" p F !F" s FhF$Dh$S"FiF(F FP (FiF8 |-G7LF<F|DFF83K4Xh+W-H(R//+K{D+K{D*K{D)HxD(HxD @&JzD%JzD%I+FyD2FH &Xh)"H[//K{DK{DK{DJzDJzDI+FyDH2FH-k,k kk k kkjjIjjj-O6N#~DF F(\3JXhB F .I FyDVhB FX)h&JzD&JzD&I FyDJ  DmhDD$pXhB Fб!ZFh!ZFFhAFFhh( F JFRFbFW-h-_jiiTjOjiip FF,*FA Fp-OdMF}D F(`IhXhB Ft ]I FyDdU 0hB FdX8hUJzDTJzDTI FyDh( @AF<4DDDU hhB F6HZh FhAF+ KFSF(U hB F 8I FyD.HFFАРgF4KD4JD{DzD@h!Fg FXFFر*XhB Fر0 F+  FQFx hXhB F FIFhi?h/ ihh:ihhHiihh;h2h-ANF F~DHIpXhB F I FyD/IyD7H:FCF(Fa0F<(T0h*S,H>(N0I:F(HCFyDEl,%O0 ,F$@B,F$@ ICFyD:F@ O5 FE0F!"t`$` `0`` -de ed-ONFI~DFϰpX h MvF (F!"x, 0 , JK{D$FIFHFKyD*FxD{DEFFh  +h.jh! Or0Fj0F#31$3x8 #+@(@++!!-+A)=rxY0h(@򘀄H\(𒀉IyDH-+## p9FZF (|Vy p9FZF (mkiuH!xDc[+O0F  FW0F O MhI0FyD#0dI0FyD O 8`I0FyD(\ 1\I0FyD(vYh. IH@UI FH:FyD[F4O Yh) =H0;H:F[Fm4-i-,4NFEFY  h+'0H=I:F-HyDTV h(''H5I:F$HyDBNFEF< 9FX4|V  h+ H0(I:FH#FyD$(F @FNF EF"!"#`$MV0hBhO-jVddxddcc~c{ctchcGcdK^G=^/M^!Fhh+h*`h h@`(I"yD p`7Fl,M}D%e%^a ԃBt(!l7pHP!xD%f50F0 HQ!xD0F HR!xD! F<"p'U h(H IHyDpF\]c]Q];] (+  !$'HxD"HxDHxDHxDHxDHxDHxDHxD HxD HxDHxDHxD HxDpG ]]]]']3]J]D]T]g]v]]] Kp{D%h`V4Fj lG5@40hBplr#h;h@2!B 3B FX@hhh FpF$ Xhh0F(4(hB!)`p-G&F FF`F_hxhIF?h/Ѡ6G`)hE-AFhF$kkV$") " (lG4@5B0F!@"KhF{DIXXh+ H(I HyDbhkbjG iH@ (I@ bhyD##`'Y\D\ Kp{D%F`0 50!hB Ftp8F`l8!Fcl l F`h -OKN l%~DFFH],FDXhBHFpy"hAFQF"F[FHF458hB[-C FFOqhFNyM#$FoF~D}D  hF)Fl F_1FFhFd#4 ,+(X sd[-AFH F F!H"+l#d+ H@xD&l%7h0l 3kGD%5@6B FZs FFFF `h0HI*F3FyD |ZF%h@s%a```)FF`h axpPehUI*FyDFOpeRJ i%zDchNJ izDchJJ izDchGJ  izDchCJ$# izDch?J( izDch@ch I*FyD#kG`!`N@ )(I@ bhyD""`sZZZZZZZZ[[)[7[\[y[[pF@@F F!@B& 016&`+hBJ FzD`pNpFH Fa!H" F(F#cd d FpphF- k`FF`hc` pF! -GMT$}DFF&FHDU h+ H89YJFH3FAF(648Y(ѽF [ KF F I{DXXh+ HFxDH!FxDZZ-AMNFh~DFFF+JH@xD (`k+@h B| V h+;H. >I8HyDxhAFyhBF+FGci3yhBFGc0HOqxDV h)!$Hxh1F"X1FFh%+h K{D K{D IBFyDH;Fho5o0@uB  8I bhyDhqkJ (I bhyDeF'fNWIZVYsYY Z-CF%FFB]F)F0DF%`%01"F2CF)53hB%`-AF'l&l 0lH-3iB3kGD'7@6GE۽-GENF@F~DFD" k(n"h9Bh!FbhV h+ 0H$@(F:0IyDF+HAF'jO)FCFkGi7k)FCFGF"HOqxDstV0h*HP(FIbhyDFH/@ X(FI;FyDF`h@ y#'8FF'XYTXX-OFFF ##`/V:l*S h# h@20BM3BE'I(F&yDF(F!" ahjr!F0F\PU h( Hh! h#iIyDchFH.q F#2S>SSRS-GO5'FF.F#P R-O^LF|DF-(h# #+ O:F0FOq,BF! 0F:F!DBF! D 8:F!DODJD F+n (k!(h1F([ +*#OO;sFN+Xh 2` +(Z" IF0F,!#6(0F,!ZF#.(" YF% +`Xh:  AFPFkhPF) 8FOqb QQP( h+6Ћh+3+1#(-h+*Њh*'!*%LhD{{B$do#h*h(Hh \ ( Zh*ۚBHhH` ` F HxD ` -Phsh+ JBBhYhB̿  pG?BpF F`h+h*`h h`p7LF|D h8#) FC81! J F+ #A#zD)j",8!!FOr>VOp FFF !F*F ppFF F)FOCL|DF0FF(FB I`XhCH IHyD p!JOFF FnFhF+(F)FFhF H!xDYIhF"yD H!xDM+*Y! FFhF Fp/OvO-O FFF!@F"}Lf?|DɈ 'uOOf 1D pHFpK -  02-/Ā!/.!"4X<B"HF1p2Xh @;`@h/@(сFLT 0h(JHJ(MIyD/ڹF{ T h*t?H5(oDIyD"0F OC(йF^T 0h(W1H(R6IyD-HN-0¿0 ;=" YhKxԺT  hTH0I yDH ? /ѝ (НpC-" O O HF5HFM!19!N N NMM-AF F)&h#(hF(<7F!h9` !F$"0F$@CJzD+hnh+x]u h@ p 9I yDghOxyAE4H@xDOpFF'F!Or0F Ϭ;h"0r`eiE#I(FyD!I(FyD#I(FyD#s`I(FyD# (I biyDsh+  +@+0F!!1`@F 4Fi M)L+LLLF#B=(H!xDW!F-F F+Kp FFj*FF Fp-A4F8F FZF0FT"FDhF40# H!xD I3FhF:FyD+* !FJ!$ U4].&=- & ?,?1? p!x=)2fxe".50$& ") ) ),)\) d4 XB$'F$'5>F)xw. p `-G!LF!J|DFҰXmFAhQ(h9F2FkF@F9F 0FQFo+hx,)3+`T hZ*`+hx*Ј_ rQT hB R:-OPLQMͰ|D@FaY&8D8D DhKKLJKzD  B)FOr 8`Fd(F{)x)^.(FAF"P( QFHF"FXh. +H(1I*F(HyDD F!&8`HFYF"*Yh( H($I*FHyD' G!&8`HF" (Xh+ Hj(I*F HyD %&=`$0FKT hBbMVJcJ}JJIII-OMt­m}DFFU p F049h4!`@hC+ F`h( 4!B \ @O aj8FJKFzDOq U h+ yH(}I:FvHyD0F9F(wJOq8FKFzD0F9F(𛄣jkpJOq8FzD0F9F(gh/qvp.. FdJOqzDFpU h*SH [IQHyDGPU0h)ALH(F(::hU h) CH!([IAHyD:hi/##.#HU h*@̀5H(ǀMIyD2f`h44a' U p;h+'H AI$HyDh@7KXh)@H(5IyDH(i"3H!xD4rO !4@hcE?ڬ!JXh/mH(h"IHyDDb!'BEEEEAE{_E5E-׸EBBdBDD,qDBszxBBDD D7D"D'!0F:F9Fci9F:F#0F(8qhp7!i) "" h'(8F$U  hB+o( mp FAjF?jBhF#F*FG%bph FhoOppGpFFhkh(F౨h( !xbx *ٔ8  #x;     pF,  hC`h# h#`hA`  (I "FyDL GBpFh$ hFh FJ f`.`0F(p-A?EMFF}DFF}BJ , zD?IhXh+:HjpO3, FcFh7I2F2HyDhF!"#| FJhbh FBh$  $ ( #?```#``"!  `8FiFOB?A0 I@ yD ? ?FbbAYAF F h !"F]pKhF{D F@j?@S  h+ H( IHyDbjlh(FajG`j>O0`bpFAFxh(  "-"r h"O3#`pMF}D(6h(0 !"O3 IhXh+H IHyD'`h(! F8U 0h* Hp IHyD hO0 ` FpF@@\! !  F! ! !pFb$B F4e,p-AFF&#h F9Fh< a&b&`5(h hB,FpF FF!"O+$l`4Fdlp-OVNWLF~D0YXh F\ FFy!F"#Fh@ HI@ yDy8FP tDMrYh+>H AI;HyDfXFO ;8F8( dF&!("(Fh( XF!(" F\l` `O  @Q$  PF`b`x V # agbPh) Hl0IZFH;FyD (F!M F!H V hB^ F??=?-O FF0F@QFFTLl!"G G 0F|D#  8PB F'p  &O7&tOB )#  0`(F`s``x?FO3h+Nph(Kѱh)HPT 0h* %H(&I*F"HyDs/ݝG PFYFBF? ( F!"p(F2ѝG (JX h, H I HyDC(F$$H p FF<>=-A GjF0FyFi#i0FqF8 iciBBhB"r8F)FOCJ(h ) `a  -Ch F0FF$CDFi i-0F8Fbi)FHFOC (Fph )> =8hC;`biB|X h) H8IJFHyDci0F ciB!iH] aeai'ga'a{0F0F@Q +a  FJ=#FE= Bw0F`i FF(0F8ai) F)Fl(B FhFjF3j FjF0FiFX F*F0F*F{  F)F] -O}#WMF"=}D@(yщMHm NIKHyD !"F$O ( /FDhFGEJNF #RF63%i FG0F-!5FF  ( "FH=F)h!Z"Fn5E Xh-!HHYFIEe 0F!vh.ьX#h FGXU h( HI HyD 4&OqUp(;AF(6 *30 )IF"F 2O1hEZh2"( ">" B#h+#c`kXh( H` HQFh$h,FkF"999-A!MFFFO"!}DFIhXhB.8F(PI8F2FyD#"F !#`FC`p"t2R+HOqxDt`+ HOqxDxpRtR6s88j8ppBFth)F7"#F(F$h,pF"pFFFFF1F"*"FF(FpIyDJ"7-OFOa8F # 8FpRXwN~DF8GB wȁ@?VhN (nI :FyD-lIlJ0FyDzD(z& DfKDD{DljO  $ *  FWIZFyDF0Fn0FB@ B(OIyD2hh(8Шh@FBQF@FN@F8JF FB(b@FYF&<&@FB @ (M6IyD@ G@FIFh$-h-( )F:F)F:FF%IBFyDF&"IyD(F ( ؎I(FJyDzD(FJF F   "7U=7UF797766mTFF"\qI FJyD"npF F"\#[ ! F o(Oa0F I0FyD, I0F"FyD}JF(Fqfp"BRFFFɋII(FyD! (,8+6 F` v'*o+m Fd8 i/f5I(FyD(_(F,(Tѕ<H F`Z!<7 F2F(Hh I]HyDhiF԰0-OJM$OF}DFFD&  &CFYijXEkXh* H H9FZF$ 6$3B4 B۽F0"Kp{D FFh! B1B+P JP `X h+HI*FHyD#h`JX h+ HH I*FHyD#hO p*FF00*pFFFۃhBOhF`hCPc``)0F*F> pF"FMK}DF$X<`h+HbI HyD:hhXh) HRH IHyDh F FF//p FFF !F*F p-AF FhFOqM@IhFhyD-K7F{D"!Fh$1Q\  2B JXh+ HrH FCIyDFH f >Fڪ,pF$$&P4(0/+hBp-OFFF!OrFk+H@xD&hF%`%F aD "$#hFgYF[7 ۨjEik!",*cHF@6$5#hBa*K*-O1MF /I}DFhXOqhXF +IXFyD0F #"J(.%OO  D0FQF"<$"FXF9F#0Eۓ 0F!F"&XJIF F7IyDFI FyD Fj U hB v*+0-OFxFB ?0Fȿ?0?0BO+ ""/D (l F ?") 6H!xD5I ԀА&DD#TF$" @F!Xh( H4@?0IFHRF+h6?0BCNXF"Y H!xD YF" H!xD?#,hF23hw`VB*` F((*'((-G=MF=I}DFFhX" 'h0F<(SF0FiF"3(J0+F$ 7Z@ 0B+10F!F"(. F"Uh( FIF"bбIhXh+HHF!F!FF I2FyDF H&~ y U  hBzFv)hch+ Bh*:B``  F !F" -AF%NFF)h~D'$"5(4B.Ѭhc b`$AM(HO*qxD$"X WAV xa$akhah( Hx IHyD:j7B H@!xDmF6-&(%B #O4( B Y`` ; -AFFhChFFB  ( I bhyDXh "L `PphH`.(-AFFhChFFB  ( I bhyD2hCN``p hH`_(h+h*@h pGKs FI{DFXXhB(F]"h JzDch K{Dh N~Dh HxD I(FyD|k(c([(S(O(phKF F{DI^X3hB (F$8 I(F"hyD@&)F 06hBp((h i-OjOkJٰD%XhgIWyDgH`xDF(cHcIbKyDO;{D F.FF d] L `cF``.`F(F h$ h$ @$ Xh)%>H1F"F 1F"FF 1F"FF  BF+h.HcF* P H0[E<4([FFOqRFB(PFMFBFUo`O hW h)HMh!(F5I yDF H3$WPFW hB>YF£{@'''&-OMI7}}D$ hX!Fh@(MF`@ (I@ 4FyD "FF(F @ (ހI@ yDO rH ( @ (рvI@ yDtચ̡̱"rKprLD{D|DD|vti$1F" FU !h+ XH(aI"FUHyD> -x8FHBF( U h,LLH(GIH& + U h(8BHr(3?H8FHBF|(U h,#7H]5HYFBFಜ$ U 0h* +HD0)HQF 6B8"8FH'BF>('I@ yD@ б#I@ BFyD " $< FU0hB $8F~@ ( 7}FQ&K&2&&z&^&;&%%%-CMT}D$FFMLDU h+ `2FHh!AF"FF U4:hBd%pO5 "  +s;{#@s:F""`7hO4   d44 FAF*F[Fb FAF*F[F73kB 0`&0IyD"8 -A2MFF}DFF#0.I0FyD ,Pah #hU h(? (:$IyD4$I0FyD,5hh;`00lUh pIyDI0FyD ̱bi#i;`4U hA U IyD "  ;IfDlF! FF-AF FFa`F#A;@&(h(O@FZ AF(0Fر&I0FjhyD;jC  0F8I0FyD! b ch0F*0F( c@ xI@ *hyDhxhh"c#b @ (I@ *hyDe `h}-CFF#b``FFHF(u0FIF;FF@;F% )h`(_oh8FX"9F$ `)OO2`@F0FAF;FF0;F% hy a+1ph7h'a @ T8I@ yD!!aaah8F8F(a@ B&`a` bhB ?B@B K J{DFXhK 1(I "hyD<^#C`S`pG(#(# (# (# ( HxD#1J !zD#XhI yDpG ɹ((1 (! (! (IyD!K "{D1hFpGZK"{D`Z`pGPK"{D``Z`pG@|4h *!`pGQK-A{DFF(BhML|DLL|DhKODF(D*h* GH*c1 */*^CIZXhBs0F(n+h+#+# +3 +# +4JzD# D 0IyD(XhBH0FV(C+h+#+# +3 +# +"JzD#!H !xD  IyD0F#FXhB0F%I*hyD JXhE0F I0FyD&8|tΆzpMIF}DhXhC I yD"&' F'g|4``^`U h7ppFM`a 0 1O2}DX78!*H@/xDH87U hB|4 !`|JzD`"&p2V3FF F'F} )I FyD ;3F9F:F8F%IyDF F /#Ic FyD# &Ic FyD# Ic FyD# Ic FyD# Ic FyD# <7#`!F I FyD F emgs$#FF"!F F F(F1F0F F|4``\`||4h*h) 81kGT Fh *  K L{D|D`!F!F !F !F !F !D;K"I{DyD`Z`K pM{D$}D`)F)F !F F!F !F !Fp܋K{Dh++KJ{DXh,-hJ*)\D\")"ۂhڹh++2 +" +" + JzD" K {D> # FD (-A L&F5F|D8FYh `Y5 6-O0L9)؂h`pGipG(HxD )K{D@hIyDQ0pG:.*FpG0 F !F"!?0 (` "` 0F8*ћx0 Fl"O$ F#k0n"hsn"F FF!D-T0F)F"F|pF F0I *F#FyD*ph -AF FF)Fn"F0F cM}D++ M}D5@F I:F3FyD Fzmm "FD(F Op/(IOpyD F F@h?O3#`(pF FH@xD5,4,$ Fph FhoOppGFhchpFF FF(Fh!"0iri#!  Fi ppF F`KB آhch!hEB̿  p?BpF F0 Fh`pKJ{DpFX Fh+ HHilO2*l IHyD$kl+ H@BqxD85pFKJ{DpFX Fh+ HYHikO2*k IHyDkk+ H@9qxD(5pFgKJ{DpFXh+ H* I HyD(%ebO1cc%deddpF0n( F8 M}D kj"klc(I jhX#dh+Hpk ll"jIyD Hj#k!l) HOaxDL(!l(H@1qxD@Fk K J{DXh+H IHyDOF80F! \h$ F$C9B""\`oOp;* (˅(F0@pGh \j$$$ F\i,p FFF !F*F ppFF F\F(FNFh F1Fp*FFFۋhB lF`hF2`B iFB8F] piF F$F FFh0F)FOCpFFF FF !'#"iz(`8F )h% 4BUYhAh)*h2aisa-AFF F #F{`FF(H@xD1)o(F!F2F;F FiCF2FF(F`(!hM-ADOFNhFOq$mFDD~DhF1FW4 hFAF4,hF|F{FFhF@!mF~ cjJzDJzDIhFyDr`j JzD JzD IhFyDc IhFyD]hFBpA>:h+pMF$}D0FU4 4,O4 Fpz0F F@!*  ԫ$ FIyDF0FFFHxD-hF@!Fld3 hhJzDFIhFyDkh{ d/ IhF:FyD IhF"FyDhF W uY^r-C%LF%I|DFF`XFh !HxD.!0F:FIFBF;F(FIyDF0Fji !"@F:kiIF"@F;FIyDF0Fz T 0hBr {r  FIyD";> KJ{DFX!hk ?H FIyDF \z#  FIyD"1=-AKFJ{DFF!XhñH(F9F3h9F-F IBF+FyDH `u!y 𵅰F"# F$h  F1F1FF8FmI*F#FyD mD -C MF I}DFFðhX hAJzDJzDOq;F`h1FF@FcsJ0FOq;FzDdd@F1FAU hBC>y # K h{DF 2# -CMFI}DFFhXFh  !8F"$@FIF:F3FU hBHx0mFLI|D`X@!hBIhF"yD iF*F ?#V I*FyD/T hB 0x0-CFFFɅF&M'"bFhF`}D Fd'e IhXh+ H(IHyD"j_Ftw- -AFhFFF ! F;F! "F h 0FI+F0FyDhI0F*FyDm)Kp{DF(IiQ? #IXXh+Hi IHyD iPOp[(IOpyDO2a j?POpF(IOpyDO3#btD Fpv   pF FHiB*"F(F#`t)F"ocip-OF F4NFF F)F"~D (W<hs(ROdO *(K   %`&!"PFX )F&KH,RF+F'@GX h;`:h (9n  M!()"! F)( (+)h+uMFF}D#F JXhh H8FYIyDF # F!PPOpt( IOpyD Ft*20F "Fb(F OpM IOpyD   !C F2 F0 K9B"!"H@ !(I@ yD>BK9B"!"X@ @I@ yD  >B-A7MFF}D)e ! F" )'# F!"(( Oqh F1h FxU h)0H(+"  F!  )%# F!" +#IBF+FyDH*+s FPi?FBf FA`?z !"r(F Op](IOpyD!" FC"( OpF(IOpyD FCiFSo0a b X(aH@!xDOpF F!OrO3 Fa#b*pF FFH@xDnK F"{D1iipk' -A0MFFF#FD=!"}D"F0F9F?4F$JXhHp!IHyDb"F0F9FF?`U 0hHI2FHyDH(8U hI H( IHyD4 F O4 F!!zqpF ( ! F0a (  -@A-2*:+F1c\+ pFh8( FI"8 0LIF|D`Xhu(F.( )F(  T  hB"00pp F!)`FIyD0F()(+ * @dDB$$ ,` 0FI"(O0 p@fFl("F 0 (3+.) #2\) F(  pF F (F FUp-OLFOF|D#F`'  `@F FnHGG# `0 ### 0 @F \(FM(HO HF!F!  DD?B ThE 8F3(]IyDpT `0h@ !F TO TIvFTJ~DTHfFTKxD F{DyDV@FZ" Xh 0ɱ (@߀  T hEHFHF!(3-IT .ԿFF hBHFȱ$hX(  ,K{D+K{DHFYFBFU>.@ @hF*h)PT 0hE8F(zIyD8FBF1sih h *e3iZh*a'!nXfS 7S')/4H!xDThS-HK0.IBF*H;FyD0ihh "F 4iXh$d3 2@B  + (`*!``0$ @$ F I FyD |kX  $ F!O$?-OqNȡ F~DF V OOe?h1<qF" Fr9F(F=#"2\H\KD[JOFDzD  ( !"HFRX*B"H IFhF*+sXh  `,j( Xh(G9Hl(B6H =<(F!F>y?3F@KF"hF(B#`FahE@ @@, FYFF@ HOp. OpQFOF >r(FPOp(IOpyD F,$(F1V hB3!|k))-OdLFFcI|D"`X hk H (F[IyDF rdO``T DWH , PKD  h(" !F63F8h)F#Xh3`1h)z*e`Xh8`ZFr+#* #+@@0`F#"Z(ihB#h``~Xhh 1H (F IyDF !i -OFpFnD FF+@+h_i/nO*hWa)k)b(o@;j@\FSlHJBѸDlD  lD >H@eAxD=;H@jAxD6' F)k:FY h+,HpO33h,ICFyD%H"F>1haN 33`&(hlkdD+h $ZjtY0hq |P(h 0 IyDF " !f!"(h ˄ʚ;FgeW0#FhZhOkhF!# FH``(hkdD*lr0+iiJ(jzDJizD)h00TR-OsMF}DDHLPHlH@AxDncbc"dadd #ebe!ee"#1"faf gca'cfcܠ"a!```HѻOH@AxD3ci+KH@AxD*al)HH@AxD" aci+BHOaxDal)?H@ QxD  "c 0! ai O ) # +2HOaxDbl*/H@QxD  c0ccqa'cfcci+Ѧl.;#dflޱci+ H@6QxDxU h?H@7QxDIkXha F`i@ F F!2F3FeQ?/{_@ (I@ "yD *-ON#~DFFF (H@QQxDc5(h !)`O 8F!Fl #k cl `i("h  i+""  a )H@qQxD2+h+@l+F F! +h+@a`i(3Ѣl**2#h  i ai!h hF i?a"*`6!h 0H@QxD(C F $ j !h "m`mm o@F"lk+h+@Xi!1 F 8i!1/Hia(?);j FP    "mbmm"o"l'+h+@Ài!jX*h*@#h!c`c FfZb+F!hJa!(h(@*h*@ lV h@ WI yD}#hZjZa oiLi+ j?%miialFKٱXh*E (@bi*AJzDD  >I yDD-XhP 0bi*܀D؀D"l2OD2OD2I*"" hyD.IBF;FyD V0h fбbi*$N~D$N~D ` h"!I 0yDI2FyDF )! !*h cO S_Z_$^=$wXi?g  FXch+ݠha` F`  F !F"  LFF|D FFhI`Xh+ H8I yDHkhh @BH@4xD.@d(F!M( H@6xD0F)F:FF_zG'phF F+bha`Fh`3(FF"@ pscN FcI~DFpXh+ \Hm(^I"FYHyD ,*k,cl+F(k(C)m)(^DV 0hBLHJ NIIHyD (eC&$,e( (FH@uqxD@dd)jB@ %0=I@ lyD+j(F#dTl+<*kB9+i+Oi(L!aial+kB ((+H@qxDoV h*/HX(F,kFiI"FHyD~LV0h) H0I HyD*klk(F  |H@qxD0F!^=K-A0F F iFthFnFFhFF9F@FOCh(F ܩ`! "tHt4)F F F.hF`Fp.M0F}D+>(:(&H@KqxD)7 *3#00!tlU h(H%p JzDJzDI HyD00t8 p H@LqxDyFv\a-GFFFFhiC+ (F@. H@!xDO$1hB p@Fi"FKFG4`lb FKFI{DFðJ\XOq KzD h{DA(F"+F8F1FA#hBCD[8/G-C FF hF!  D(F!F#@Fc`Oq/8I@F:FyD h  02IyDF@FY 0hb W@@F_+IyDF )I(F:FyDh!0F\ 1F"Fh!2F#{@@ - I@ yDlh0F<IJ(FyDzDu 1F"Fc0F)FK0FR Z +o`bY.ӪAi CapGh FhoOppG*pFFFۃhBFh`h bhhP``Z`)0F*F ppFh+ Fhah@x FPh+ahZ`H``O5(FpsFFh +(F "@d(Fx(F( 1"(F(F" `|pF F KBآhch hJB Fwhah@h` p?Bp FFF !F*F  pF# FF "+H@!xD 1F"(FOp1F"(Fp"1F(F !"(F(F" -OLFI|DF`Xh3."Or`5r% Oi {I%  * -FF/F&F !"ZL B"J*F+8X#h  `h,@(|F4FV h(UH(XIyDTF4FV0h)KH(}OIyDGH3y"HFOCn(F4FV h(e`dPFj(F؈78Fb( (րyI yD_wJ OqKFzD@F@FDAFOCF(F|F@F8BT0h(^H(cIFZHyD, i^I9jF F %F !"8F"W @ BG!0RFSF9F X#h  `h,^(F,FU h*T4H:(O;IyD(F,FU0h)B+H((=3IyD"@FOC(F,FU hJH((IyDHx 6.љF,FЙ dU hPH0I HyD,FOO(@FT hB s}!!UAR -O FyIFFyD"(FOCtL|D(sI`Xh+ԀlH(΀nIiHyD'Oe iK&F i+ - !"'0Y+BIIyD"(FOC(Th*T-H(O3IyD)H0 U6.ѝTh*8 H(3&IHyD.0FS+ћpgdT 0hHбIyDXF)FRF'8ThBH IyDHr'8F/!!FS^ -AMF"FF}DFI "0FOCyD1t ( JXhHI HyD. !"8F<0F9F"Fq@!h1( ###`!Q-O8LF8J|DFFX. h*F1F#(F' @F p O  F)y' :FAFp$O),7QF:FOC~0FBdT h{HXIHyD0FYF*F@*h2Kh+  (` #T 0hB%!P-GFFFF+ hF,AF*F8 T  hB| }nE{7-CFO $FhF*Lh|D+A8F|(FAF"mT haH;@ 0FIyDF(FhùPT hiHH 0FIyDF H J  !(F A !jD-A#F FhFDMB}DؿFr@F x.U h(h9H(c Fz7I3FyDF2HU h+O,H(J Fa,I2FyDF&HV>yjBU h+2H(- FPB|jI*FyDFH57(FAF"FA1F(FF(FV$$  $ F FCKJ{DX"8 xB#) #pF F$0Y)Y8")"b#) #"p4@, 8&)  ppFH$(Y4@,(FpL|D#2H(p F F+F F!F(F#`pFFFiF FJ9FzD2FF(Fh!FF(FFFFhF FyJ9FzD2FF(FL!FF(Fjp FFF p F!p"X.(F!F0"0(F "HP(F "8 pFX@,#0pF F h `+hhp}?;7{((L F% F!"ppFh F!p!`mm- F!Orp "p FvFXO`0IO`*FyD Fpx FF!" F3hhV`P`(IO`yDnJhzD2FFJ|IyD`JzIyD aBwIyD`a1hih>h@h'!ibi@m!"hh@k!ebc!`lb`lC% d0!"2Op"!Or"Opv!Or$ h$"!(FOa(FOaz 3hp 0G(F`3hP IP mlQ EReh #[i#3h 0@Yl# @32hkH`L3h 1h1hP `4FKd{DpS 0hFhVkpv!0F4!F"0Fd(F!Fruĕp>=-ONFJ~D FF0X'FBh@PF  O@ i;Fq9hBhyh Bd(`)\hhykBXѵ2ERp cj L 0#0  0!CPF 0<(HAR!xD4#!$R2C4#@VAs2#h/٨HP(FI yDFH'13 +V 0h*vH(p(FI yDFH}c;HVh(MH(G(FhICFyDFH]=٨//ظ""B #ic  @!iV h/kH( (F,oIyDFVh+bHtp@F4F(FeI:FyDFZH !8FoF8F" FDV h)ʃHHB(ă(FNIyDFl'KH V xD  8h+B8H!(= FOpq` F  F(F p ~|  CF:F HO~ rs(N/8 K4Xh/M H(G BIyDFH^ =F!F<KB%VXh(٬H I:FyDFH+ 7 /s T8 //O $#٨ #j+ػ8O+ԿwFN/(pFhHD(Ƃ@FIyDFjڱH1ñV h)zH*((FzIyDFsHܱV p8h("!FV0h*iH(F9F9FFhIZFyDF`HF|O '$)sؠjVOYh*\OH(V(FwRIyDFHHmJ#j+ػ 8O +ԿaFL)\VzqPF*FI()5H("@F^9IyDF/H"j9V h( *HH(F-/IyDF$H#/Fa O Ϭ#_F 'pV h(H_((FF@FI*F;FyD HOshhC$B@"jE@'F!,H((FIyDFG2Os"iqE$qPFa*F(|s4V h(2|H(-fzIyDF!! Or*Fp!PFs(SV  h+jHPCjIyDFdH:F^OrN(dHAn1xD#O| A1?]HAo1xDOsp" F7(UHAp1xDOpCr~ͬFuFŜHMHQ!O|jh C$B@"kE@3HY(݀(F7IyDF-H mO{ Cuhh(!i`O| E{0BVh/H%( FPI*F yDH ! K8QFXF%X0V 0h*H( IHyDz!F~UA_AxqYFBD(# FIF*FB6 F9FF(/ FAF:F+F('ѝ *# F1F+F(Fq F+F(ѝP&A% #  F(6BO5 FTO5(F+#L#M=|DF 0bY0Fh " `IyDNF00FO1F 8F>B2FF8F](F .F1F:F$ 2(FT 0 hhB =R!>pFFF!n+oJF@(F1FJF0FLFF FJ(FpFF%Fб" F1FF&%s8F6P80( % F(FpFF]F!n+oF@(F1FF0F FF F(Fp-C+HF$xD)ODF0F3F(B-B "0FAFF0$F(1ﰱF(FIF(HFIF(F FIFK FX$(F0F X F-$ hhs'KF{DF F $JXh+> H(9M}DM}DM}D FI*FyDFH$"J LS 0h) HqkM}DM}D0FF0F I*F#FyDH|F E-OFFFF/N%~DFQ8F)FF(IF(D FF(>XF(9ZF(4 !F(,XF@FF2FKF F !O@R_# F_#!O@Rz@F!FG Ff5UEHxDKF"{DڹLS  h+ H(I"F HyDf" FFO JzDK{DX$n$$pFر@ IyDhF1(40( $$0Fd@$ Fpù-OKMF}DFQh1;FIhXhB  UD@JFDh >NF~Dh1a"i1h aEJ0+E0FFhXh*RoQHO +  @0@.QD## 0`U hB '8F #0HF@>Qv E 8 /@(  p FF)D`FhOp(:IOp.FyDh3I2F FyDsIyDFFhOpI2FOp&FyDM)F8(Op( IOpyD< Fr Fn&0Fp-OF"FFS!:N~DF9IpXh+_4Hk(Z5I1HyD CFT$O %F@F!F  C4,- V 0h, HC "IHyDH$F#FD9Y3Xh* H*(HQF*F;Y9YB##  48"E"*#F@F-OTLUJF|DmX" h~! 4FNKFxX(h(eHH(`II5FDHyDzZX h+@H CI=HyDl>JODD9AF0Fb#OaF(FZF`?<X h+ +H()HIF*F;FA8F)F蠱'cXh( H(HQF*F;F,8F)F8%0F4E%X(F $T  hB#(FOaZF?%D0FTb m-W K{DF !Jp2JzD#2FHxD0+J3zD=pFF M F}D2Fi(F! Fp-ONJF~DɰXhG3+FPO`(IO`yDzI(FyDsI8FyD6O1FO`бIO`yDYI8FyDxF`O`8IO`#yDD!8F F FhF8F O`8IO`#yD*(F!"CFTP`y(IO`yDV 0h/ ٨Hh@@F@IyDH@F>@FPO`P(IO`yD",!F(F !O#(FI(FyD&s/ I yD8F(=)9FHFFHF8"(BF*H@axD|IF8F8F!FPO`(~IO`yD8FHF+xI8FyDF`O`8sIO`#yDz8F!F8F O`8hIO`#yDbeI  @FyDZF  F(=!8FJFKF9F@FZFFPPV@#h[oOI:F hyD@FV h). x((DIyD  ,@F (FDP`^(:IO`yD(F9hVP`M(2IO`yD(F^P`:(*IO`yDs/@  ((||DDgbQ( G.#O9F FXFH` O`IFn9FpF(FH` O`AFZ7hBۂsoI8FyD혹(F!FO`бIO`yD6(F9F"x`PIO`#yD"''JРI@FyD0(F;(FAF"F\Vp8hXjoђIBF8hyDO`I(IO`#yD(FT``18IO`yD'#j{I@FyD0(F(FAF#Bp`HoIO`#yD33+7(FF8.F@F0#!3#F,F0!HF#$ @ 0YI@ #yDv@F ! O`(QIO`yDf"MI@FyD$0(F@FF`O`8BIO`#yDB(FAF藱(F``87IO`#yD*8 @ }0I@ yD !.HD.JxDzD(F+I(FyD(F``Y8#IO`#yD(F%l(FGV hBJI|x>? I FyDFK{D(H!xDh}ptx F! !F" -C FFFF0Rck+O()F,(&HO3axD'@(F(!H@11xD(F!eF(H@21xDchC hQh 6$(F7(F1F"F( H@81xD H@.1xDgO7ݰ-O'FFF}FFD9F2FF FIF"FF[F$ "`F[F]U7B!0F"F@X  h+ H`!F"(F I"FyDFH; Fd-GFF FFF  8PPF Fz!FFPF0()H@AxDI1F "$($H@AxD=IF "(H@AxD1 AF" (H@"AxD"_9F"(H@$AxD FF FS*FF0F/ F Fg{]C-O[MpF}DհF xU O0 ^F@FhJF|S!Or!8FMI FyDKIpyDII  yD F HP@IyDOp@F6#:J8F;`1F9KzDx{D F1F F1FFU @#h+0%H `-I-CF#F+hcN!~DT8z(_I_JyDzD+h)HZIyD-F(.!" FO2L$DAFF/HFAF)HF(5$V 0h.~@HL(yDI"FI@"1HyDO ##FC)s * (g(FAF(_"X! `!#`1 h FAFhV 0h*RH'(M`JzDJzD#hK{DK{DICFyDH3!  1˽4(,ͳ!"xV hBH IHyD}HF!Or nHV h+ H(IyD!X`m I FyDIX1{TaT'@FV hZyH8|ICFvHyDT!8 FT# 80X1#\ m,V  hJbHl(fI_HyDbm 80XQu#hPTAFF UI@FyD(F( XV hjDH1Hbm IM}DII+F?HyD#hji!ع%hi"h1V hA1H 9I/HyD#X18FAX!%h ! rp!h"F  !4#X1!h i1@!\xXVhHIyDHl )F"z !"n8F ! ѼsFBh FFhrBiPjh(Hj؂BBѵHE"izHihbi:*jh؂BB ѵHE !F*F3F|F FFO4#+pF9F"F0F!Fڱ?0FȱF((F@"(F?($$(F$ F-ON FI~DFŰpXhC8F FF(H@1xDJ(FzDF(H@1xDuP-H@1xDl'`pn 9F:FFV h+𼃤H(𶃬IHyD"nzn`AFDFXF8FI!b-!_"8F-n#O!nTV0h*H(|I@ ;FyDH ) I@F!3nHFP!nV 0h*YsHz(S`n%n:|I*FyDFkHE#n+Vh(;dH\(5pI#`HyD"n`HFAFP0 "n@F@! zO BP P0cJ#nzDHAF:F^JJ@FzD@!#n9ZKZF{Dn!#P0AFFsPFN YFFd"FX@ (:GI@ "nyD3nF@F(Fc"@F(ۂE@ (9I@ "nyD !d"5J @!#nzDPFQF &@FHFrm+| n(yѢnj URkBRdV h+kH(fm@+Ѐ+JzDJzDJzDIHyD=S!!v׺ ijeV h)@6qHW(0m@+Ѐ+nK{DmK{DmK{DmI:FgHyDO+n+ n`n"aKhXh)]H/aI[HyD Xh+@VH (ZIyD$)"nnNKhXh)JH PIHHyDXh(@فCH(ӁIIyD?HT:И)6#n+3@F9FP@@Fz#F@Fp鈹V h(,Hб4I:F)HyDlV0h)@#H(+I:FHyDkm !((Q%I @F"nyD;F#!BF KX h*8 H(3I;F HyD"n++Xh+@[H|(UIyDҹչ¹K8@ l*eХIJyDzD)mFD# FB=)mjF0IBFyDI  PF#nyDlJQFHzD-JPFzD\F(m@@FS RKX h*ـH бI;F}HyD"nXh+@ـxH(Ӏ~IyDtH;F"nm*bFxOp(rIOpUFFyD|l!"mz( Op(|hIOpmyDgt!PF F FFpOp(b^IOpmEFyDP_hnFXFF`@ (JRI@ m;FyD7BPhiDF% YFPi.hnJF(FdFV h+ 1Hm=I:F.HyD   EVP)h) &HW@3I:F#HyD%%%FPF2@F0ձ H3Xh* H70$I;FHyD"n$8F`@n F8Fd `CV 0hB EF]vY@0#-CCOFCIDFFxXh+-IF4HyDO!*60+!hi(.+,"hiK hj+ !F+ !F(0)HAxD>U 0h)H #IHyD^O" (S0+#hi1K+I hi*E!h j+ !F+! 9F"FFF!=xD>0رHAxDU h+ٞHf IHyDO )08F ?FTU h+8HC(2IyDH+(U h( مH00IFHyDO0+B4F(;}J 8FzD2F?U h+kH(pIyD(41F"U h(aH(?fI]HyD^FO *N<h+Ix XCn  $B0!,!(1JHA*xD" BF F|耜U0h*2H :I/HyD*O0+41hB0`0h("2`0s1hUhB0`3h+#3`0!hlzU hX1hB0`2h* 0`L2hU*ܿO h+ H8(IHyD2hj8F!F9߰UV˯LO1U0h@ H I HyDO0@FHAxDb!}ݍ-O PF' Du FH}j&F F =FY FH xD q/ h  [jC~h(1ىHh!OqAFsFAFFp qF`AF&*F cFqHq/N$"*JO|! rS  F (O cF FǞ `?PBP!- j; F!*FO ? O ! F5v-\OFFD ! FfF0F!0FY h)6H 8I3HyD#i`pE!" FY h)(HP*JzD*JzD*I"HyDt1h( !h) $1h(L!QL hB LAPLAP  E-O XFr/?_gFt#ح̭Gƭh FhoOppGpFh+ Fhah@x FPh+ahZ`H``O5(FppF F KB HB ܡhhah#hBB̿  p?B8I8MF}}DhXh,R#hOOq3`0F#1Z"ch(!k U hE("IhyDh(!kI8FyD8F(Fݠh9F2FB##c"iZ kH0F"ihhQh2FG U 0hB }@pGÄpFFkh8%((%u`hV#j| FN(Fp0h(! F`FXh((#h%!"RFhp@ wPh IyDF@  jXai)"aaH!xDDG $0O2y@$0iFO2#m-O O F*KFIFFFF{4 FF F!4"O0'```Q///(F@A!(F!Orz`(FB!)Hk!xDsh)!(FF"h``-nFhFOq$ @ #h+++K{DK{DK{DK{DI@ *FyDm##c `"h@Կ!1!*p#abbbXFONNKF hah#hBB FhchhQ`  F#xp -OFF(sЃh+phm j(;HOqxDh*8H@ xDؐ%Ԁ DDF%0F?8ai)J j(Gh0FF!ji 0FF8iiPBaiP rYF(F0FYF i a@FOq ( (Ѝ8F%8F%(FHF@o[K31hapGCic#"@m8@mRCiO0 ` M\O #"@m8@m|h C7O##% F:*@ ȱ)F F} I KyD{DF@ - S@ 0I@ JyDzD >~-OOFFF$*)`" #B##%BC#@ J $ AFJF F0AFJFF0F)AFJFF(F#4I4K:FyD{D@ E!!EA)I@ (D $ F!BF!BFF0F!BFF(FIKyD{D$)( E"@ $ FAFJFAFJFF0FAFJFF(F I KyD{D@ :F#Fx ! b~q~}h++@h8  I yDR <F!`"\O3ceF@m(iH F-GȠFD(Zh+Qi(N'0F F(KFZ*F`j9FU9F*FFjOIyDZ IF`j*FAIF*FFj;IyDRFCF0F )FkK!(F{D Fh(F{ F F¨-A|LF|DFT hh+wHxDF vOD!8Fv(pe Op(ƀoIOp:FyDP " !riOW4p402hC^*40C*C40  ([I *FyDmYI(FyD0hWI(FyD*8 )F" 3 pmFI:F( Op(sJIOp*FyDDkT hI (CI :FyD3i+M "F(F9! "8F $4"AF8FZi!:FHC(F~(T0h*H^)IHyDi OpT0%IOpBFyD(F OpD0IOp yDpmpm !a$T hB6T@+rmPƳ<§-OFlNFh~D F +ȀhM rYhQ 0cI biyDh F!*FF`j!*Fjci˱h0 O @ O O !jYFV h("!cj =H =IV(FyD;F  )F6K(FAF{D"(F1I;FyD  )F+K{D;F'IyDJF(F )F!K{D(FAF"X mIV 0yD(Fh )FgK(FAF{D"d! !au|9Ȧ˦ʦئۦŦŦFFhF@!mF$ գmJzDJzDIhFyDՠmJzDJzDIhFyD  IhFyD+*X pxmcE=-AFFhFF FOqFhF#.&.A#h++7ah)bj!j@:F!:FFjI*FyDFhFe!:F`j{!:FFjuF )F:F`jn)F:FFjhF IhF*F3FyD IhFyD+(X ;}l#O H IE""EFB@@ = I@ yD-CF F#F(4BB&@ 8F!"F!"FF!"FF0F!"FF(FIBF;FyD@ 6 OpF FF" HI!xDL F%(F1F<0Ff1FF F\8 pvJpzDF F  J(F!FzD J(F!FzD8 p-OF` FFF <IOpJF+FyD78FiFD`pW5IOp:FyD`m,Ih\( OpB8,IOp:F+FyD60FiF`p/#IOp2FyD`mIh4( Op8IOp2F+FyD FTX h `JzDJzDI yDT@T@T@FP-OF` FFF<#@xFW FXF9Ff` ` * (~ F&2F3FIFF 2F3F`bB  Fb.- hbh(  jVH!hxDcjjRHcjxD!h #h++bh*KJ`jzDjJJO1`jzD:!2F`jN!2FFjHF& j2FajCC9Fb;F:I(FZFyD'7I(FJFyD 6I(FJFyD4I(F2FyD `" "*? 0AF( 0@QF(  0!I BFSFyD0@''e'@ FF]I(FBFyDKI(F2FyDE!`4 F  UG! ((( HxDHxDHxDHxD8ʝpGHxDpG-GFFFFF 8O (I F' (FIF먱   1F*F F (F(F F$ FmT-----BEGIN OpenVPN Static key V1----------END OpenVPN Static key V1-----Non-Hex character ('%c') found at line %d in key file '%s' (%d/%d/%d bytes found/min/max)Non-Hex, unprintable character (0x%02x) found at line %d in key file '%s' (%d/%d/%d bytes found/min/max)Authenticate/Decrypt packet error d d <x< X< d2d2will be delayed because of --client, --pull, or --up-delayInitialization Sequence CompletedMANAGEMENT: unix domain socket client connection rejected --[[BLANK]] NTLMSSP      pppppp888888jjjjjj(4kz-VӯEOpenVPN 2.2.1 i686-pc-linux-gnu [SSL] [LZO2] [EPOLL] [eurephia] [IPv6 payload 20110522-1 (2.2.0)] built on Aug 26 2011%s General Options: --config file : Read configuration options from file. --help : Show options. --version : Show copyright and version information. Tunnel Options: --local host : Local host name or ip address. Implies --bind. --remote host [port] : Remote host name or ip address. --remote-random : If multiple --remote options specified, choose one randomly. --remote-random-hostname : Add a random string to remote DNS name. --mode m : Major mode, m = 'p2p' (default, point-to-point) or 'server'. --proto p : Use protocol p for communicating with peer. p = udp (default), tcp-server, or tcp-client --proto-force p : only consider protocol p in list of connection profiles. --connect-retry n : For --proto tcp-client, number of seconds to wait between connection retries (default=%d). --connect-timeout n : For --proto tcp-client, connection timeout (in seconds). --connect-retry-max n : Maximum connection attempt retries, default infinite. --auto-proxy : Try to sense proxy settings (or lack thereof) automatically. --show-proxy-settings : Show sensed proxy settings. --http-proxy s p [up] [auth] : Connect to remote host through an HTTP proxy at address s and port p. If proxy authentication is required, up is a file containing username/password on 2 lines, or 'stdin' to prompt from console. Add auth='ntlm' if the proxy requires NTLM authentication. --http-proxy s p 'auto[-nct]' : Like the above directive, but automatically determine auth method and query for username/password if needed. auto-nct disables weak proxy auth methods. --http-proxy-retry : Retry indefinitely on HTTP proxy errors. --http-proxy-timeout n : Proxy timeout in seconds, default=5. --http-proxy-option type [parm] : Set extended HTTP proxy options. Repeat to set multiple options. VERSION version (default=1.0) AGENT user-agent --socks-proxy s [p] [up] : Connect to remote host through a Socks5 proxy at address s and port p (default port = 1080). If proxy authentication is required, up is a file containing username/password on 2 lines, or 'stdin' to prompt for console. --socks-proxy-retry : Retry indefinitely on Socks proxy errors. --resolv-retry n: If hostname resolve fails for --remote, retry resolve for n seconds before failing (disabled by default). Set n="infinite" to retry indefinitely. --float : Allow remote to change its IP address/port, such as through DHCP (this is the default if --remote is not used). --ipchange cmd : Execute shell command cmd on remote ip address initial setting or change -- execute as: cmd ip-address port# --port port : TCP/UDP port # for both local and remote. --lport port : TCP/UDP port # for local (default=%d). Implies --bind. --rport port : TCP/UDP port # for remote (default=%d). --bind : Bind to local address and port. (This is the default unless --proto tcp-client or --http-proxy or --socks-proxy is used). --nobind : Do not bind to local address and port. --dev tunX|tapX : tun/tap device (X can be omitted for dynamic device. --dev-type dt : Which device type are we using? (dt = tun or tap) Use this option only if the tun/tap device used with --dev does not begin with "tun" or "tap". --dev-node node : Explicitly set the device node rather than using /dev/net/tun, /dev/tun, /dev/tap, etc. --lladdr hw : Set the link layer address of the tap device. --topology t : Set --dev tun topology: 'net30', 'p2p', or 'subnet'. --tun-ipv6 : Build tun link capable of forwarding IPv6 traffic. --iproute cmd : Use this command instead of default /system/xbin/ip. --ifconfig l rn : TUN: configure device to use IP address l as a local endpoint and rn as a remote endpoint. l & rn should be swapped on the other peer. l & rn must be private addresses outside of the subnets used by either peer. TAP: configure device to use IP address l as a local endpoint and rn as a subnet mask. --ifconfig-ipv6 l r : configure device to use IPv6 address l as local endpoint (as a /64) and r as remote endpoint --ifconfig-noexec : Don't actually execute ifconfig/netsh command, instead pass --ifconfig parms by environment to scripts. --ifconfig-nowarn : Don't warn if the --ifconfig option on this side of the connection doesn't match the remote side. --route network [netmask] [gateway] [metric] : Add route to routing table after connection is established. Multiple routes can be specified. netmask default: gateway default: taken from --route-gateway or --ifconfig Specify default by leaving blank or setting to "nil". --route-ipv6 network/bits [gateway] [metric] : Add IPv6 route to routing table after connection is established. Multiple routes can be specified. gateway default: taken from --route-ipv6-gateway or --ifconfig --max-routes n : Specify the maximum number of routes that may be defined or pulled from a server. --route-gateway gw|'dhcp' : Specify a default gateway for use with --route. --route-metric m : Specify a default metric for use with --route. --route-delay n [w] : Delay n seconds after connection initiation before adding routes (may be 0). If not specified, routes will be added immediately after tun/tap open. On Windows, wait up to w seconds for TUN/TAP adapter to come up. --route-up cmd : Execute shell cmd after routes are added. --route-noexec : Don't add routes automatically. Instead pass routes to --route-up script using environmental variables. --route-nopull : When used with --client or --pull, accept options pushed by server EXCEPT for routes. --allow-pull-fqdn : Allow client to pull DNS names from server for --ifconfig, --route, and --route-gateway. --redirect-gateway [flags]: Automatically execute routing commands to redirect all outgoing IP traffic through the VPN. Add 'local' flag if both OpenVPN servers are directly connected via a common subnet, such as with WiFi. Add 'def1' flag to set default route using using and rather than Add 'bypass-dhcp' flag to add a direct route to DHCP server, bypassing tunnel. Add 'bypass-dns' flag to similarly bypass tunnel for DNS. --redirect-private [flags]: Like --redirect-gateway, but omit actually changing the default gateway. Useful when pushing private subnets. --push-peer-info : (client only) push client info to server. --setenv name value : Set a custom environmental variable to pass to script. --setenv FORWARD_COMPATIBLE 1 : Relax config file syntax checking to allow directives for future OpenVPN versions to be ignored. --script-security level mode : mode='execve' (default) or 'system', level= 0 -- strictly no calling of external programs 1 -- (default) only call built-ins such as ifconfig 2 -- allow calling of built-ins and scripts 3 -- allow password to be passed to scripts via env --shaper n : Restrict output to peer to n bytes per second. --keepalive n m : Helper option for setting timeouts in server mode. Send ping once every n seconds, restart if ping not received for m seconds. --inactive n [bytes] : Exit after n seconds of activity on tun/tap device produces a combined in/out byte count < bytes. --ping-exit n : Exit if n seconds pass without reception of remote ping. --ping-restart n: Restart if n seconds pass without reception of remote ping. --ping-timer-rem: Run the --ping-exit/--ping-restart timer only if we have a remote address. --ping n : Ping remote once every n seconds over TCP/UDP port. --multihome : Configure a multi-homed UDP server. --fast-io : (experimental) Optimize TUN/TAP/UDP writes. --remap-usr1 s : On SIGUSR1 signals, remap signal (s='SIGHUP' or 'SIGTERM'). --persist-tun : Keep tun/tap device open across SIGUSR1 or --ping-restart. --persist-remote-ip : Keep remote IP address across SIGUSR1 or --ping-restart. --persist-local-ip : Keep local IP address across SIGUSR1 or --ping-restart. --persist-key : Don't re-read key files across SIGUSR1 or --ping-restart. --tun-mtu n : Take the tun/tap device MTU to be n and derive the TCP/UDP MTU from it (default=%d). --tun-mtu-extra n : Assume that tun/tap device might return as many as n bytes more than the tun-mtu size on read (default TUN=0 TAP=%d). --link-mtu n : Take the TCP/UDP device MTU to be n and derive the tun MTU from it. --mtu-disc type : Should we do Path MTU discovery on TCP/UDP channel? 'no' -- Never send DF (Don't Fragment) frames 'maybe' -- Use per-route hints 'yes' -- Always DF (Don't Fragment) --mtu-test : Empirically measure and report MTU. --fragment max : Enable internal datagram fragmentation so that no UDP datagrams are sent which are larger than max bytes. Adds 4 bytes of overhead per datagram. --mssfix [n] : Set upper bound on TCP MSS, default = tun-mtu size or --fragment max value, whichever is lower. --sndbuf size : Set the TCP/UDP send buffer size. --rcvbuf size : Set the TCP/UDP receive buffer size. --txqueuelen n : Set the tun/tap TX queue length to n (Linux only). --mlock : Disable Paging -- ensures key material and tunnel data will never be written to disk. --up cmd : Shell cmd to execute after successful tun device open. Execute as: cmd tun/tap-dev tun-mtu link-mtu \ ifconfig-local-ip ifconfig-remote-ip (pre --user or --group UID/GID change) --up-delay : Delay tun/tap open and possible --up script execution until after TCP/UDP connection establishment with peer. --down cmd : Shell cmd to run after tun device close. (post --user/--group UID/GID change and/or --chroot) (script parameters are same as --up option) --down-pre : Call --down cmd/script before TUN/TAP close. --up-restart : Run up/down scripts for all restarts including those caused by --ping-restart or SIGUSR1 --user user : Set UID to user after initialization. --group group : Set GID to group after initialization. --chroot dir : Chroot to this directory after initialization. --cd dir : Change to this directory before initialization. --daemon [name] : Become a daemon after initialization. The optional 'name' parameter will be passed as the program name to the system logger. --syslog [name] : Output to syslog, but do not become a daemon. See --daemon above for a description of the 'name' parm. --inetd [name] ['wait'|'nowait'] : Run as an inetd or xinetd server. See --daemon above for a description of the 'name' parm. --log file : Output log to file which is created/truncated on open. --log-append file : Append log to file, or create file if nonexistent. --suppress-timestamps : Don't log timestamps to stdout/stderr. --writepid file : Write main process ID to file. --nice n : Change process priority (>0 = lower, <0 = higher). --echo [parms ...] : Echo parameters to log output. --verb n : Set output verbosity to n (default=%d): (Level 3 is recommended if you want a good summary of what's happening without being swamped by output). : 0 -- no output except fatal errors : 1 -- startup info + connection initiated messages + non-fatal encryption & net errors : 2,3 -- show TLS negotiations & route info : 4 -- show parameters : 5 -- show 'RrWw' chars on console for each packet sent and received from TCP/UDP (caps) or tun/tap (lc) : 6 to 11 -- debug messages of increasing verbosity --mute n : Log at most n consecutive messages in the same category. --status file n : Write operational status to file every n seconds. --status-version [n] : Choose the status file format version number. Currently, n can be 1, 2, or 3 (default=1). --disable-occ : Disable options consistency check between peers. --gremlin mask : Special stress testing mode (for debugging only). --comp-lzo : Use fast LZO compression -- may add up to 1 byte per packet for uncompressible data. --comp-noadapt : Don't use adaptive compression when --comp-lzo is specified. --management ip port [pass] : Enable a TCP server on ip:port to handle management functions. pass is a password file or 'stdin' to prompt from console. To listen on a unix domain socket, specific the pathname in place of ip and use 'unix' as the port number. --management-client : Management interface will connect as a TCP client to ip/port rather than listen as a TCP server. --management-query-passwords : Query management channel for private key and auth-user-pass passwords. --management-hold : Start OpenVPN in a hibernating state, until a client of the management interface explicitly starts it. --management-signal : Issue SIGUSR1 when management disconnect event occurs. --management-forget-disconnect : Forget passwords when management disconnect event occurs. --management-log-cache n : Cache n lines of log file history for usage by the management channel. --management-client-user u : When management interface is a unix socket, only allow connections from user u. --management-client-group g : When management interface is a unix socket, only allow connections from group g. --management-client-auth : gives management interface client the responsibility to authenticate clients after their client certificate has been verified. --management-client-pf : management interface clients must specify a packet filter file for each connecting client. --plugin m [str]: Load plug-in module m passing str as an argument to its initialization function. Multi-Client Server options (when --mode server is used): --server network netmask : Helper option to easily configure server mode. --server-ipv6 network/bits : Configure IPv6 server mode. --server-bridge [IP netmask pool-start-IP pool-end-IP] : Helper option to easily configure ethernet bridging server mode. --push "option" : Push a config file option back to the peer for remote execution. Peer must specify --pull in its config file. --push-reset : Don't inherit global push list for specific client instance. --ifconfig-pool start-IP end-IP [netmask] : Set aside a pool of subnets to be dynamically allocated to connecting clients. --ifconfig-pool-linear : Use individual addresses rather than /30 subnets in tun mode. Not compatible with Windows clients. --ifconfig-pool-persist file [seconds] : Persist/unpersist ifconfig-pool data to file, at seconds intervals (default=600). If seconds=0, file will be treated as read-only. --ifconfig-ipv6-pool base-IP/bits : set aside an IPv6 network block to be dynamically allocated to connecting clients. --ifconfig-push local remote-netmask : Push an ifconfig option to remote, overrides --ifconfig-pool dynamic allocation. Only valid in a client-specific config file. --ifconfig-ipv6-push local/bits remote : Push an ifconfig-ipv6 option to remote, overrides --ifconfig-ipv6-pool allocation. Only valid in a client-specific config file. --iroute network [netmask] : Route subnet to client. --iroute-ipv6 network/bits : Route IPv6 subnet to client. Sets up internal routes only. Only valid in a client-specific config file. --disable : Client is disabled. Only valid in a client-specific config file. --client-cert-not-required : Don't require client certificate, client will authenticate using username/password. --username-as-common-name : For auth-user-pass authentication, use the authenticated username as the common name, rather than the common name from the client cert. --auth-user-pass-verify cmd method: Query client for username/password and run script cmd to verify. If method='via-env', pass user/pass via environment, if method='via-file', pass user/pass via temporary file. --opt-verify : Clients that connect with options that are incompatible with those of the server will be disconnected. --auth-user-pass-optional : Allow connections by clients that don't specify a username/password. --no-name-remapping : Allow Common Name and X509 Subject to include any printable character. --client-to-client : Internally route client-to-client traffic. --duplicate-cn : Allow multiple clients with the same common name to concurrently connect. --client-connect cmd : Run script cmd on client connection. --client-disconnect cmd : Run script cmd on client disconnection. --client-config-dir dir : Directory for custom client config files. --ccd-exclusive : Refuse connection unless custom client config is found. --tmp-dir dir : Temporary directory, used for --client-connect return file and plugin communication. --hash-size r v : Set the size of the real address hash table to r and the virtual address table to v. --bcast-buffers n : Allocate n broadcast buffers. --tcp-queue-limit n : Maximum number of queued TCP output packets. --tcp-nodelay : Macro that sets TCP_NODELAY socket flag on the server as well as pushes it to connecting clients. --learn-address cmd : Run script cmd to validate client virtual addresses. --connect-freq n s : Allow a maximum of n new connections per s seconds. --max-clients n : Allow a maximum of n simultaneously connected clients. --max-routes-per-client n : Allow a maximum of n internal routes per client. --port-share host port : When run in TCP mode, proxy incoming HTTPS sessions to a web server at host:port. Client options (when connecting to a multi-client server): --client : Helper option to easily configure client mode. --auth-user-pass [up] : Authenticate with server using username/password. up is a file containing username/password on 2 lines, or omit to prompt from console. --pull : Accept certain config file options from the peer as if they were part of the local config file. Must be specified when connecting to a '--mode server' remote host. --auth-retry t : How to handle auth failures. Set t to none (default), interact, or nointeract. --server-poll-timeout n : when polling possible remote servers to connect to in a round-robin fashion, spend no more than n seconds waiting for a response before trying the next server. --explicit-exit-notify [n] : On exit/restart, send exit signal to server/remote. n = # of retries, default=1. Data Channel Encryption Options (must be compatible between peers): (These options are meaningful for both Static Key & TLS-mode) --secret f [d] : Enable Static Key encryption mode (non-TLS). Use shared secret file f, generate with --genkey. The optional d parameter controls key directionality. If d is specified, use separate keys for each direction, set d=0 on one side of the connection, and d=1 on the other side. --auth alg : Authenticate packets with HMAC using message digest algorithm alg (default=%s). (usually adds 16 or 20 bytes per packet) Set alg=none to disable authentication. --cipher alg : Encrypt packets with cipher algorithm alg (default=%s). Set alg=none to disable encryption. --prng alg [nsl] : For PRNG, use digest algorithm alg, and nonce_secret_len=nsl. Set alg=none to disable PRNG. --keysize n : Size of cipher key in bits (optional). If unspecified, defaults to cipher-specific default. --engine [name] : Enable OpenSSL hardware crypto engine functionality. --no-replay : Disable replay protection. --mute-replay-warnings : Silence the output of replay warnings to log file. --replay-window n [t] : Use a replay protection sliding window of size n and a time window of t seconds. Default n=%d t=%d --no-iv : Disable cipher IV -- only allowed with CBC mode ciphers. --replay-persist file : Persist replay-protection state across sessions using file. --test-crypto : Run a self-test of crypto features enabled. For debugging only. TLS Key Negotiation Options: (These options are meaningful only for TLS-mode) --tls-server : Enable TLS and assume server role during TLS handshake. --tls-client : Enable TLS and assume client role during TLS handshake. --key-method m : Data channel key exchange method. m should be a method number, such as 1 (default), 2, etc. --ca file : Certificate authority file in .pem format containing root certificate. --capath dir : A directory of trusted certificates (CAs and CRLs). --dh file : File containing Diffie Hellman parameters in .pem format (for --tls-server only). Use "openssl dhparam -out dh1024.pem 1024" to generate. --cert file : Local certificate in .pem format -- must be signed by a Certificate Authority in --ca file. --key file : Local private key in .pem format. --pkcs12 file : PKCS#12 file containing local private key, local certificate and optionally the root CA certificate. --tls-cipher l : A list l of allowable TLS ciphers separated by : (optional). : Use --show-tls to see a list of supported TLS ciphers. --tls-timeout n : Packet retransmit timeout on TLS control channel if no ACK from remote within n seconds (default=%d). --reneg-bytes n : Renegotiate data chan. key after n bytes sent and recvd. --reneg-pkts n : Renegotiate data chan. key after n packets sent and recvd. --reneg-sec n : Renegotiate data chan. key after n seconds (default=%d). --hand-window n : Data channel key exchange must finalize within n seconds of handshake initiation by any peer (default=%d). --tran-window n : Transition window -- old key can live this many seconds after new key renegotiation begins (default=%d). --single-session: Allow only one session (reset state on restart). --tls-exit : Exit on TLS negotiation failure. --tls-auth f [d]: Add an additional layer of authentication on top of the TLS control channel to protect against DoS attacks. f (required) is a shared-secret passphrase file. The optional d parameter controls key directionality, see --secret option for more info. --askpass [file]: Get PEM password from controlling tty before we daemonize. --auth-nocache : Don't cache --askpass or --auth-user-pass passwords. --crl-verify crl: Check peer certificate against a CRL. --tls-verify cmd: Execute shell command cmd to verify the X509 name of a pending TLS connection that has otherwise passed all other tests of certification. cmd should return 0 to allow TLS handshake to proceed, or 1 to fail. (cmd is executed as 'cmd certificate_depth X509_NAME_oneline') --tls-export-cert [directory] : Get peer cert in PEM format and store it in an openvpn temporary file in [directory]. Peer cert is stored before tls-verify script execution and deleted after. --tls-remote x509name: Accept connections only from a host with X509 name x509name. The remote host must also pass all other tests of verification. --ns-cert-type t: Require that peer certificate was signed with an explicit nsCertType designation t = 'client' | 'server'. --remote-cert-ku v ... : Require that the peer certificate was signed with explicit key usage, you can specify more than one value. value should be given in hex format. --remote-cert-eku oid : Require that the peer certificate was signed with explicit extended key usage. Extended key usage can be encoded as an object identifier or OpenSSL string representation. --remote-cert-tls t: Require that peer certificate was signed with explicit key usage and extended key usage based on RFC3280 TLS rules. t = 'client' | 'server'. SSL Library information: --show-ciphers : Show cipher algorithms to use with --cipher option. --show-digests : Show message digest algorithms to use with --auth option. --show-engines : Show hardware crypto accelerator engines (if available). --show-tls : Show all TLS ciphers (TLS used only as a control channel). Generate a random key (only for non-TLS static key encryption mode): --genkey : Generate a random key to be used as a shared secret, for use with the --secret option. --secret file : Write key to file. Tun/tap config mode (available with linux 2.4+): --mktun : Create a persistent tunnel. --rmtun : Remove a persistent tunnel. --dev tunX|tapX : tun/tap device --dev-type dt : Device type. See tunnel options above for details. --user user : User to set privilege to. --group group : Group to set privilege to. *{d- HAUTH_FAILED((((silence this warning with --ifconfig-nowarn)[NULL]external/openvpn/buffer.c Write error on file '%s'fatal buffer size error, size=%lurattemped allocation of excessively large array [%s]%s%02x[more...]external/openvpn/crypto.c01external/openvpn/packet_id.h[null-digest]Note: OpenSSL hardware crypto engine functionality is not availableTLS Error: error reading key from remoteTLS Error: key length mismatch, local cipher/hmac %d/%d, remote cipher/hmac %d/%dKey file '%s' used in --%s contains insufficient key material [keys found=%d required=%d] -- try generating a new key file with 'openvpn --genkey --secret [file]', or use the existing key file in bidirectional mode by specifying --%s without a key direction parameterCRYPTO INFO: WARNING: zero key detectedMessage hash algorithm '%s' not foundMessage hash algorithm '%s' uses a default hash size (%d bytes) which is larger than OpenVPN's current maximum hash size (%d bytes)PRNG init md=%s size=%dERROR: Random number generator cannot obtain entropy for PRNGSorry, OpenSSL hardware crypto engine functionality is not available.The following message digests are available for use with OpenVPN. A message digest is used in conjunction with the HMAC function, to authenticate received packets. You can specify a message digest as parameter to the --auth option. %s %d bit digest size --no-replay or --no-iv cannot be used with a CFB or OFB mode cipherThe following ciphers and cipher modes are available for use with OpenVPN. Each cipher shown below may be used as a parameter to the --cipher option. The default key size is shown as well as whether or not it can be changed with the --keysize directive. Using a CBC mode is recommended. fixedvariable%s %d bit default key (%s) Unknown key direction '%s' -- must be '0' or '1'%s (cipher): %s%s (hmac): %sCannot open passphrase file: '%s'Read error on passphrase file: '%s'Passphrase file '%s' is too small (must have at least %d characters)[[INLINE]]Cannot open file key file '%s'Read error on key file ('%s')Key file ('%s') can be a maximum of %d bytes%xInsufficient key material or header text not found in file '%s' (%d/%d/%d bytes found/min/max)Footer text not found in file '%s' (%d/%d/%d bytes found/min/max)[null-cipher]Cipher algorithm '%s' not foundCipher algorithm '%s' uses a default key size (%d bytes) which is larger than OpenVPN's current maximum key size (%d bytes)Cipher '%s' uses a mode not supported by OpenVPN in your current configuration. CBC mode is always supported, while CFB and OFB modes are supported only when using SSL/TLS authentication and key exchange mode, and when OpenVPN has been built with ALLOW_NON_CBC_CIPHERS.******* WARNING *******: null cipher specified, no encryption will be used******* WARNING *******: null MAC specified, no authentication will be usedDES-DESX-CRYPTO INFO: n_DES_cblocks=%dCRYPTO INFO: fixup_key_DES: insufficient key materialCRYPTO INFO: fixup_key: before=%s after=%sCRYPTO INFO: check_key_DES: insufficient key materialCRYPTO INFO: check_key_DES: weak key detectedCRYPTO INFO: check_key_DES: bad parity detectedKey #%d in '%s' is bad. Try making a new key with --genkey.ERROR: Random number generator cannot obtain entropy for key generationCipher source entropy: %sHMAC source entropy: %sCannot open shared secret file '%s' for write%s # # %d bit OpenVPN static key # Close error on shared secret file %sEVP cipher init #1EVP set key sizeEVP cipher init #2%s: Cipher '%s' initialized with %d bit key%s: CIPHER KEY: %s%s: CIPHER block_size=%d iv_size=%d%s: Using %d bit message hash '%s' for HMAC authentication%s: HMAC KEY: %s%s: HMAC size=%d block_size=%dControl Channel Authentication: tls-auth using INLINE static key fileINLINE tls-auth file lacks the requisite 2 keysControl Channel Authentication: using '%s' as a OpenVPN static key fileControl Channel Authentication: using '%s' as a free-form passphrase filetls-authOutgoing Control Channel AuthenticationIncoming Control Channel Authentication%s: missing authentication info%s: packet HMAC authentication failed%s: missing IV infoDECRYPT IV: %s%s: missing payload%s: cipher init failed%s: buffer overflow%s: cipher update failed%s: cipher final failedDECRYPT TO: %s%s: error reading CBC packet-id%s: error reading CFB/OFB packet-id%s: error reading packet-id%s: bad packet ID (may be a replay): %s -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warningsENCRYPT IV: %sENCRYPT FROM: %sENCRYPT: buffer size error, bc=%d bo=%d bl=%d wc=%d wo=%d wl=%d cbs=%dENCRYPT TO: %sEntering OpenVPN crypto self-test mode.TESTING ENCRYPT/DECRYPT of packet length=%dSELF TEST FAILED, src.len=%d buf.len=%dSELF TEST FAILED, pos=%d in=%d out=%dOpenVPN crypto self-test mode SUCCEEDED.Extracted DHCP router address: %sIFNWDopenvpnOpenVPN: Out of Memory %s: %s (errno=%d)%s: %s%s (OpenSSL)Options error: %s%s%s%s%s%s%s%s%s %s%s%s%sExitingNOTE: --mute triggered...%d variation(s) on previous %d message(s) suppressed by --mute%s %s returned %d%s %s [%s]: %s (code=%d)%s %s: %s (code=%d)Warning: Error redirecting stdout/stderr to --log file: %s--log file redirection error on stdout--log file redirection error on stderrAssertion failed at %s:%dexternal/openvpn/event.cPO_CTL rwflags=0x%04x ev=%d arg=0x%08lxError: poll: too many I/O wait eventsPO_DEL ev=%dSE_WAIT[%d,%d] rwflags=0x%04x arg=0x%08lxSE_CTL rwflags=0x%04x ev=%d fast=%d cap=%d maxfd=%d arg=0x%08lxError: select: too many I/O wait events, fd=%d cap=%dSE_DEL ev=%dError: select/se_del: too many I/O wait eventsSE_RESETPO_INIT maxevents=%d flags=0x%08xSE_INIT maxevents=%d flags=0x%08x[scalable]PO_WAIT[%d,%d] fd=%d rev=0x%08x rwflags=0x%04x arg=0x%08lx %sError: poll: unknown revents=0x%04xSE_WAIT_FAST maxfd=%d tv=%d/%dSE_WAIT_SCALEABLE maxfd=%d tv=%d/%dEP_INIT maxevents=%d flags=0x%08xNote: sys_epoll API is unavailable, falling back to poll/select APIEP_WAIT[%d] rwflags=0x%04x ev=0x%08x arg=0x%08lxEP_DEL ev=%dEP_CTL fd=%d rwflags=0x%04x ev=0x%08x arg=0x%08lxEVENT: epoll_ctl EPOLL_CTL_ADD failedEVENT: epoll_ctl EPOLL_CTL_MOD failedSet FD_CLOEXEC flag on file descriptor failedSet socket to non-blocking mode failedtls-errordelayed-exitServer poll timeout, restartingserver_pollInactivity timeout (--inactive), exitinginactiveFatal TLS error (check_tls_errors_co), restartingRANDOM USEC=%dexternal/openvpn/socket.hTUN WRITE [%d]write to TUN/TAPTUN/TAP packet was destructively fragmented on write to %s (tried=%d,actual=%d)tun packet too large on write (tried=%d,max=%d)external/openvpn/forward.cread from TUN/TAPport-share-redirectconnection-reset-inetdConnection reset, inetd/xinetd exit [%d]Connection reset during exit notification period, ignoring [%d]connection-resetConnection reset, restarting [%d]readTUN READ [%d]Delayed exit in %d secondsSENT CONTROL [%s]: '%s' (status=%d)AUTH_FAILEDPUSH_RESTARTWARNING: Received unknown control message: %sWARNING: Receive control message failedauth-control-exitI/O WAIT %s|%s|%s|%s %sTIMER: coarse timer wakeup %d secondsexternal/openvpn/shaper.h%s WRITE [%d] to %s: %swriteTCP/UDP packet was truncated/expanded on write to %s (tried=%d,actual=%d)TCP/UDP packet too large on write to %s (tried=%d,max=%d)event_waitI/O WAIT status=0x%04x%s READ [%d] from %s: %sdecryption-errorFatal decryption error (process_incoming_link), restartingRECEIVED PING PACKETFRAG TTL expired i=%dexternal/openvpn/integer.hFRAG_OUT len=%d type=%d seq_id=%d frag_id=%d frag_size=%d flags=0x%08xexternal/openvpn/fragment.cFRAG: outgoing buffer is not empty, len=[%d,%d]FRAG_OUT error, len=%d frag_size=%d MAX_FRAGS=%d: %stoo many fragments would be required to send datagramFRAG_IN buf->len=%d type=FRAG_WHOLE flags=0x%08xspurrious FRAG_WHOLE flagsFRAG_TEST not implementedFRAG_IN len=%d type=%d seq_id=%d frag_id=%d size=%d flags=0x%08xbad fragment sizefragment buffer overflowflags not found in packetFRAG_IN error flags=0x%08x: %sexternal/openvpn/gremlin.cDOWNUPGREMLIN: CONNECTION GOING %s FOR %d SECONDSGREMLIN: Random packet dropGREMLIN: Packet Corruption, method=%d%s %droute-gateway dhcp--keepalive parameters must be > 0the second parameter to --keepalive (restart timeout=%d) must be at least twice the value of the first parameter (ping interval=%d). A ratio of 1:5 or 1:6 would be even better. Recommended setting is --keepalive 10 60.--keepalive conflicts with --ping, --ping-exit, or --ping-restart. If you use --keepalive, you don't need any of the other --ping directives.pingping-restartexternal/openvpn/helper.croute %s %sroute %s%s (/%d)route-gateway %stopology %s%s IP addresses %s and %s are not in the same %s subnet--server-bridge--server-ipv6 must be used together with --server--server-ipv6 is incompatible with 'nopool' option--server-ipv6 already defines an ifconfig-ipv6-pool, so you can't also specify --ifconfig-pool explicitlytun-ipv6--server and --client cannot be used together--server and --server-bridge cannot be used together--server and --secret cannot be used together (you must use SSL/TLS keys)--server already defines an ifconfig-pool, so you can't also specify --ifconfig-pool explicitly--server directive only makes sense with --dev tun or --dev tap--server directive network/netmask combination is invalid--server directive netmask is invalid--server directive netmask allows for too many host addresses (subnet must be %s or higher)--server directive when used with --dev tun must define a subnet of %s or lower--server directive when used with --dev tap must define a subnet of %s or lower--server-bridge and --client cannot be used together--server-bridge already defines an ifconfig-pool, so you can't also specify --ifconfig-pool explicitly--server-bridge and --secret cannot be used together (you must use SSL/TLS keys)--server-bridge directive only makes sense with --dev tap--client requires --key-method 2socket-flags TCP_NODELAY:auth-intmd5-sess%s link set addr %s dev %sERROR: Unable to set link layer address.TUN/TAP link layer address set to %sOpenVPN started by inetd/xinetd cannot restart... Exiting.NOTE: --fast-io is disabled since we are not using UDPNOTE: --fast-io is disabled since we are using --shaperERROR: Sorry, this command is currently only implemented on Windowsexternal/openvpn/init.c******* WARNING *******: all encryption and authentication features disabled -- all data will be tunnelled as cleartextsecretStatic EncryptStatic DecryptRe-using pre-shared static keyClosing TUN/TAP interfaceinitdownrestartNEED_LATERNEED_NOWNo usable connection profiles are presentIMPORTANT: OpenVPN's default port number is now %d, based on an official port number assignment by IANA. OpenVPN 2.0-beta16 and earlier used 5000 as the default port.WARNING: --ping should normally be used with --ping-restart or --ping-exitWARNING: you are using user/group/chroot/setcon without persist-tun -- this may cause restarts to failWARNING: you are using user/group/chroot/setcon without persist-key -- this may cause restarts to failWARNING: you are using chroot without specifying user and group -- this may cause the chroot jail to be insecureWARNING: using --pull/--client and --ifconfig together is probably not what you wantNOTE: when bridging your LAN adapter with the TAP adapter, note that the new bridge adapter will often take on its own IP address that is different from what the LAN adapter was previously set toWARNING: using --duplicate-cn and --client-config-dir together is probably not what you wantWARNING: --ifconfig-pool-persist will not work with --duplicate-cnWARNING: --keepalive option is missing from server configWARNING: You have disabled Replay Protection (--no-replay) which may make OpenVPN less secureWARNING: You have disabled Crypto IVs (--no-iv) which may make OpenVPN less secureWARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page).NOTE: the current --script-security setting may allow this configuration to call user-defined scriptsNOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executablesNOTE: --script-security method='system' is deprecated due to the fact that passed parameters will be subject to shell expansionError: private key password verification failedprivate-key-password-failureRe-using SSL/TLS contextWARNING: using --fragment and --mtu-test together may produce an inaccurate MTU test resultWARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu %d (currently it is %d)Data Channel MTU parmsFragmentation MTU parmsControl Channel MTU parmsTLS-Auth MTU parmsLocal Options String: '%s'Expected Remote Options String: '%s'Local Options hash (VER=%s): '%s'Expected Remote Options hash (VER=%s): '%s'daemon() failedRestart pause, %d second(s)NOTE: chroot %sNOTE: UID/GID downgrade %sFatal error: Port sharing failedSignal received from management interface, exitingconfig%s With ErrorsSUCCESSERROR[%s] TUN/TAP device (--dev)options --mktun or --rmtun should only be used together with --devshared secret output file (--secret)Randomly generated %d bit key written to %sOPTIONS IMPORT: --verb and/or --mute level changedOPTIONS IMPORT: timers and/or timeouts modifiedOPTIONS IMPORT: --explicit-exit-notify can only be used with --proto udpOPTIONS IMPORT: explicit notify parm(s) modifiedOPTIONS IMPORT: LZO parms modifiedOPTIONS IMPORT: traffic shaper enabledOPTIONS IMPORT: --sndbuf/--rcvbuf options modifiedOPTIONS IMPORT: --socket-flags option modifiedOPTIONS IMPORT: --persist options modifiedOPTIONS IMPORT: --ifconfig/up options modifiedOPTIONS IMPORT: route options modifiedOPTIONS IMPORT: route-related options modifiedOPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modifiedOPTIONS IMPORT: environment modifiedIPv6 routes on TAP devices are going to fail on some platforms (need gateway spec)WARNING: Failed running command (%s)--route-upWARNING: route-up plugin call failedscript_typeroute-up%sctunupPreserving previous TUN/TAP instance: %sinit_instanceNOTE: Pulled options changed on restart, will need to close and reopen TUN/TAP device.external/openvpn/list.cexternal/openvpn/lzo.cpre-compress bytes,%llupost-compress bytes,%llupre-decompress bytes,%llupost-decompress bytes,%lluLZO decompression error: %ddecompress %d -> %dBad LZO decompression header byte: %dlzo_adaptive_compress_test: comp=%d total=%dONOFFAdaptive compression state %sCannot initialize LZO compression libraryLZO compression initializedLZO compression buffer overflowLZO compression error: %dcompress %d -> %d>PROXY:%s,%s>PROXY:%s>INFO:OpenVPN Management Interface Version %d -- type 'help' for more infoManagement Interface for %sCommands:auth-retry t : Auth failure retry mode (none,interact,nointeract).bytecount n : Show bytes in/out, update every n secs (0=off).echo [on|off] [N|all] : Like log, but only show messages in echo buffer.exit|quit : Close management session.forget-passwords : Forget passwords entered so far.help : Print this message.hold [on|off|release] : Set/show hold flag to on/off state, or release current hold and start tunnel.kill cn : Kill the client instance(s) having common name cn.kill IP:port : Kill the client instance connecting from IP:port.load-stats : Show global server load stats.log [on|off] [N|all] : Turn on/off realtime log display + show last N lines or 'all' for entire history.mute [n] : Set log mute level to n, or show level if n is absent.needok type action : Enter confirmation for NEED-OK request of 'type', where action = 'ok' or 'cancel'.needstr type action : Enter confirmation for NEED-STR request of 'type', where action is reply string.net : (Windows only) Show network info and routing table.password type p : Enter password p for a queried OpenVPN password.pid : Show process ID of the current OpenVPN process.client-auth CID KID : Authenticate client-id/key-id CID/KID (MULTILINE)client-auth-nt CID KID : Authenticate client-id/key-id CID/KIDclient-deny CID KID R [CR] : Deny auth client-id/key-id CID/KID with log reason text R and optional client reason text CRclient-kill CID : Kill client instance CIDenv-filter [level] : Set env-var filter levelclient-pf CID : Define packet filter for client CID (MULTILINE)signal s : Send signal s to daemon, s = SIGHUP|SIGTERM|SIGUSR1|SIGUSR2.state [on|off] [N|all] : Like log, but show state history.status [n] : Show current daemon status info using format #n.test n : Produce n lines of output for testing/debugging.username type u : Enter username u for a queried OpenVPN username.verb [n] : Set log verbosity level to n, or show if n is absent.version : Show current version number.http-proxy-fallback [flags] : Enter dynamic HTTP proxy fallback info.http-proxy-fallback-disable : Disable HTTP proxy fallback.ENDSUCCESS: nclients=%dERROR: The nclients command is not supported by the current daemon modeSUCCESS: env_filter_level=%dSUCCESS: nclients=%d,bytesin=%llu,bytesout=%lluERROR: The 'status' command is not supported by the current daemon modeERROR: The 'net' command is not supported by the current daemon modeSUCCESS: bytecount interval changedSUCCESS: proxy-fallback command succeededERROR: proxy-fallback command failedERROR: The proxy-fallback command is not supported by the current daemon mode>PASSWORD:Verification Failed: '%s' ['%s']>PASSWORD:Verification Failed: '%s'external/openvpn/manage.cat least sERROR: the '%s' command requires %s%d parameter%s>FATAL:>LOG:>ECHO:>STATE:%u,%s,CONNECTINGINITIALWAITAUTHGET_CONFIGASSIGN_IPADD_ROUTESCONNECTEDRECONNECTINGEXITINGRESOLVETCP_CONNECT?%d,,%sMANAGEMENT: %sSUCCESS: password is correctERROR: bad passwordMAN: client connection rejected after %d failed password attemptsonSUCCESS: hold flag set to ONoffSUCCESS: hold flag set to OFFreleaseSUCCESS: hold release succeededERROR: bad hold command parameterSUCCESS: hold=%d%s UID of socket peer (%d) doesn't match required value (%d) as given by --management-client-user%s GID of socket peer (%d) doesn't match required value (%d) as given by --management-client-group%s cannot get UID/GID of socket peerSUCCESS: client-auth command succeededERROR: client-auth command failedERROR: The client-auth command is not supported by the current daemon modeSUCCESS: client-pf command succeededERROR: client-pf command failedERROR: The client-pf command is not supported by the current daemon modeSUCCESS: signal %s thrownERROR: signal '%s' is currently ignoredERROR: signal '%s' is not a known signal typeSUCCESS: %d client(s) at address %s:%d killedERROR: client at address %s:%d not foundERROR: port number is out of range: %sERROR: error parsing IP address: %sSUCCESS: common name '%s' found, %d client(s) killedERROR: common name '%s' not foundERROR: kill parseERROR: The 'kill' command is not supported by the current daemon modeSUCCESS: Passwords were forgotten%luERROR: cannot parse CIDSUCCESS: client-kill command succeededERROR: client-kill command failedERROR: The client-kill command is not supported by the current daemon mode%uERROR: cannot parse KIDSUCCESS: client-deny command succeededERROR: client-deny command failedERROR: The client-deny command is not supported by the current daemon modeMANAGEMENT: TCP %s error: %sMANAGEMENTMANAGEMENT: listen() failedNULLMANAGEMENT: unix domain socket listening on %sMANAGEMENT: TCP Socket listening on %sMANAGEMENT: Client disconnectedMANAGEMENT: Triggering management signalmanagement-disconnectMANAGEMENT: Triggering management exitmanagement-exitsendw%s %d MANAGEMENT: failed to write peer info to file %smanagement-connect-failed>CLIENT:ADDRESS,%lu,%s,%d>CLIENT:ENV,%s>CLIENT:ENV,END>CLIENT:DISCONNECT,%lun_clients>CLIENT:ESTABLISHED,%luvalidation failed on peer_info line received from clientCONNECTREAUTH>CLIENT:%s,%lu,%uManagementMANAGEMENT: client_uid=%dMANAGEMENT: client_gid=%dtunnel%llu>BYTECOUNT_CLI:%lu,%s,%s>BYTECOUNT:%s,%sSUCCESS: '%s' %s entered, but not yet verifiedERROR: %s of type '%s' entered, but we need one of type '%s'ERROR: no %s is currently needed at this timeexitquithelpversionOpenVPN Version: %sManagement Version: %dpidSUCCESS: pid=%dnclientsenv-filtersignalload-statsstatuskillverbSUCCESS: verb level changedERROR: verb level is out of rangeSUCCESS: verb=%dmuteSUCCESS: mute level changedERROR: mute level is out of rangeSUCCESS: mute=%dauth-retrySUCCESS: auth-retry parameter changedERROR: bad auth-retry parameterSUCCESS: auth-retry=%sstatelogechousernamepasswordforget-passwordsneedokneedok-confirmationneedstrneedstr-stringnetholdbytecountclient-killclient-denyclient-auth-ntclient-authclient-pfhttp-proxy-fallbackhttp-proxy-fallback-disabletest[%d] The purpose of this command is to generate large amounts of output.ERROR: unknown command, enter 'help' for more optionsMANAGEMENT: CMD 'password [...]'MANAGEMENT: CMD '%s'TCPENTER PASSWORD:recvNeed password(s) from management interface, waiting...Need hold release from management interface, waiting...>HOLD:Waiting for hold releaseNEED-OKconfirmationNEED-STRstringPASSWORDusername/password>%s:Need '%s' %s MSG:%sMANAGEMENT: %s %sClient connected fromMANAGEMENT: connect to unix socket %s failed: %sMANAGEMENT: connect to %s failed: %sConnected to management server atSUCCESS: real-time %s notification set to ONSUCCESS: real-time %s notification set to OFFallERROR: %s parameter must be 'on' or 'off' or some number n or 'all'username=password=X509_0_CN=tls_serial_0=untrusted_ip=ifconfig_local=ifconfig_netmask=daemon_start_time=daemon_pid=dev=ifconfig_pool_remote_ip=ifconfig_pool_netmask=time_duration=bytes_sent=bytes_received=MBUF: dereferenced queued packetexternal/openvpn/mbuf.cMBUF: mbuf packet droppedexternal/openvpn/misc.c"WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent thismake_arg_arrayENV [%d] '%s'CRV1...%s%s%s_%d%s=%sexternal program fork failedexternal program did not exit normallyexternal program exited normallycould not execute external programexternal program exited with error status: %dOpen error on pid file %sUNDEFTEST FILE '%s' [%d]/dev/tty%s-0x%s.%s%u.%u.%u.%uputenv('%s') failedOPENVPN_%ssetenv_str_safe: name overflow%dopenvpn_%s_%s.tmpFailed to create temporary filename and pathCould not create temporary file '%s': %sFailed to create temporary file after %i attemptsSYSTEM[%u] '%s'SYSTEM return=%uWARNING: External program may not be called unless '--script-security 2' or higher is enabled. Use '--script-security 3 system' for backward compatibility with 2.1_rc8 and earlier. See --help text or man page for detailed info.openvpn_execve: called with empty argvWARNING: cannot stat file '%s'WARNING: file '%s' is group or others accessiblestdinNote: previous '%s' credentials failedmanagementprevious auth credentials failedERROR: could not read %s username/password/ok/string from management interfaceNEED-OK|%s|%s:ERROR: could not read %s ok-confirmation from stdinokCHALLENGE: %sResponse:ERROR: could not read challenge response from stdinCRV1::%s::%sERROR: received malformed challenge request from serverEnter %s Username:Enter %s Password:ERROR: could not read %s username from stdinERROR: %s username is emptyERROR: could not not read %s password from stdinError opening '%s' auth file: %sError reading password from %s authfile: %sError reading username and password (must be on two consecutive lines) from %s authfile: %sERROR: username from %s authfile '%s' is empty/dev/nullINETD_SOCKET_DESCRIPTOR dup(%d) failedWARNING: mlockall call failedmlockall call succeeded%u Close error on pid file %sWARNING: nice %d failed: %snice %d succeededsetgid('%s') failedGID set to %ssetgroups('%s') failedfailed to find GID for group %ssetuid('%s') failedUID set to %sfailed to find UID for user %schroot to '%s' failed/cd to '%s' failedchroot to '%s' and cd to '%s' succeededSCRIPT-ARGV%s/%d%s%scscript_contexttun_mtulink_mtudev%s %d %d %s %s %sERROR: up/down plugin call failed%sc %s %d %d %s %s %s--up/--down/system/xbin/ipIP packet with unknown IP version=%d seenMROUTE CIDR netlen: /%dexternal/openvpn/mroute.cARP//%s/%d:%dUNKNOWNexternal/openvpn/mss.cMSS: %d -> %dTA_SOCKET_READTA_UNDEFTA_SOCKET_READ_RESIDUALTA_SOCKET_WRITETA_SOCKET_WRITE_READYTA_SOCKET_WRITE_DEFERREDTA_TUN_READTA_TUN_WRITETA_INITIALTA_TIMEOUTTA_TUN_WRITE_TIMEOUTMULTI TCP: new incoming client address matches existing client address -- new client takes precedenceMULTI TCP: instance added: %sMULTI TCP: new client instance failedexternal/openvpn/mtcp.cMULTI TCP: multi_tcp_wait_lite a=%s mi=0x%08lxMULTI TCP: multi_tcp_wait_lite, unhandled action=%dMULTI TCP: multi_tcp_post %s -> %sMULTI: TCP INIT maxclients=%d maxevents=%dMULTI TCP: TCP client address is undefinedexternal/openvpn/multi.hMULTI TCP: transmitting previously deferred packetMULTI TCP: queuing deferred packetMULTI TCP: multi_tcp_dispatch a=%s mi=0x%08lxMULTI TCP: multi_tcp_dispatch, unhandled action=%dMULTI TCP: multi_tcp_action a=%s p=%dMULTI TCP: I/O wait required blocking in multi_tcp_action, action=%dNote: enable extended error passing on TCP/UDP socket failed (IP_RECVERR)Error setting IP_MTU_DISCOVER type=%d on TCP/UDP socketCMSG=%d|NO-INFO|ETIMEDOUT|EMSGSIZE Path-MTU=%d|ECONNREFUSED|EPROTO|EHOSTUNREACH|ENETUNREACH|EACCES|UNKNOWN|yesmaybenoinvalid --mtu-disc type: '%s' -- valid types are 'yes', 'maybe', or 'no'%s [ L:%d D:%d EF:%d EB:%d ET:%d EL:%d AF:%u/%d ]external/openvpn/mtu.cMTU DYNAMIC mtu=%d, flags=%u, %d -> %dTUN MTU value (%d) must be at least %dMTU is too smallexternal/openvpn/mudp.cMULTI: Connection from %s would exceed new connection frequency limit as controlled by --connect-freq[succeeded][failed][created]GET INST BY REAL: %s %sexternal/openvpn/multi.cMULTI: C2C/MCAST/BCASTifconfig_pool_local_ipifconfig_pool_remote_ipifconfig_pool_netmaskcommon_nametime_asciitime_unixMULTI: packet dropped due to output saturation (multi_add_mbuf)bcast_c2cUNDEF_IPF: client[%s] -> client[%s] packet dropped by BCAST packet filterbcast_src_addrPF: addr[%s] -> client[%s] packet dropped by BCAST packet filterOpenVPN CLIENT LISTUpdated,%sCommon Name,Real Address,Bytes Received,Bytes Sent,Connected Since%s,%s,%llu,%llu,%sROUTING TABLEVirtual Address,Common Name,Real Address,Last Ref%s%s,%s,%s,%sGLOBAL STATSMax bcast/mcast queue length,%dTITLE%c%sTIME%c%s%c%uHEADER%cCLIENT_LIST%cCommon Name%cReal Address%cVirtual Address%cBytes Received%cBytes Sent%cConnected Since%cConnected Since (time_t)CLIENT_LIST%c%s%c%s%c%s%c%llu%c%llu%c%s%c%uHEADER%cROUTING_TABLE%cVirtual Address%cCommon Name%cReal Address%cLast Ref%cLast Ref (time_t)ROUTING_TABLE%c%s%s%c%s%c%s%c%s%c%uGLOBAL_STATS%cMax bcast/mcast queue length%c%dERROR: bad status format version numberbytes_receivedbytes_senttime_duration%s/MULTI ROUTE: route quota (%d) exceeded for %s (see --max-routes-per-client option)MULTI_sva: WARNING: if --ifconfig-push is used for IPv4, automatic IPv6 assignment from --ifconfig-ipv6-pool does not work. Use --ifconfig-ipv6-push for IPv6 then.MULTI_sva: pool returned IPv4=%s, IPv6=%sMULTI: no --ifconfig-pool netmask parameter is available to push to %sMULTI: no free --ifconfig-pool addresses are availableMULTI_sva: push_ifconfig_ipv6 %s/%dMULTI: multi_init called, r=%d v=%dGREMLIN_FLOOD_CLIENTS: flooding clients with %d packets of size %dMULTI: connection rejected: %s, CLI:%sWARNING: client-disconnect plugin call failedclient-disconnect--client-disconnectMULTI: multi_close_instance calledclient-instanceMULTI: new connection by client '%s' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.%s %sWARNING: learn-address plugin call failedlearn-address%sc %s %s--learn-addressMULTI: REAP range %d -> %dMULTI: REAP DEL %sdeleteupdateadd FAILEDMULTI: Learn%s: %s -> %sGET INST BY VIRT: %s -> %s via %sGET INST BY VIRT: %s [failed]MULTI: internal route %s/%d -> %sMULTI: internal route %s -> %sMULTI: problem deleting temporary file: %sDEFAULTccWARNING: client-connect plugin call failedWARNING: client-connect-v2 plugin call failedclient-connect%sc %s--client-connectMULTI: client has been rejected due to 'disable' directiveMULTI: no dynamic or static remote --ifconfig address is available for %sMULTI ERROR: primary virtual IP for %s (%s) violates tunnel network/netmask constraint (%s/%s)MULTI: primary virtual IP for %s: %sMULTI: primary virtual IPv6 for %s: %sMULTI: --iroute options rejected for %s -- iroute only works with tun-style tunnelsMULTI: Outgoing TUN queue full, dropped packet len=%dtun_tap_src_addrPF: addr[%s] -> client packet dropped by packet filterMULTI: packet dropped due to output saturation (multi_process_incoming_tun)MULTI: bad source address from client [%s], packet droppedtun_c2cPF: client -> client[%s] packet dropped by TUN packet filtertun_dest_addrPF: client -> addr[%s] packet dropped by TUN packet filtertap_c2cPF: client -> client[%s] packet dropped by TAP packet filtertap_dest_addrPF: client -> addr[%s] packet dropped by TAP packet filterMULTI: multi_create_instance calledMULTI: new incoming connection would exceed maximum number of clients (%d)MULTI: unable to add real address [%s] to iterator hash tableMULTI: signal occurred during client instance initializationTlRMTVNTUAABAAAAAgIAAA==external/openvpn/ntlm.cWarning: Username or domain too longNOTE: Beginning empirical MTU test -- results should be available in 3 to 4 minutes.NOTE: failed to empirically measure MTU (requires OpenVPN 1.5 or higher at other end of connection).NOTE: failed to obtain options consistency info from peer -- this could occur if the remote peer is running a version of OpenVPN before 1.5-beta8 or if there is a network connectivity problem, and will not necessarily prevent OpenVPN from running (%llu bytes received from peer, %llu bytes authenticated data channel traffic) -- you can disable the options consistency check with --disable-occ.external/openvpn/occ.cSENT OCC_REQUESTSENT OCC_REPLYSENT OCC_MTU_REQUESTSENT OCC_MTU_REPLYSENT OCC_MTU_LOAD_REQUESTSENT OCC_MTU_LOAD min_int(%d-%d-%d-%d,%d) size=%dSENT OCC_EXITRECEIVED OCC_REQUESTRECEIVED OCC_MTU_REQUESTRECEIVED OCC_MTU_LOAD_REQUESTRECEIVED OCC_REPLYRECEIVED OCC_MTU_REPLYNOTE: Empirical MTU test completed [Tried,Actual] local->remote=[%d,%d] remote->local=[%d,%d]NOTE: This connection is unable to accomodate a UDP packet size of %d. Consider using --fragment or --mssfix options as a workaround.RECEIVED OCC_EXITremote-exitexternal/openvpn/openvpn.cnet30undefp2psubnetunknownnointeractnoneinteract???--Multiple --%s scripts defined. The previously configured script is overridden.option '%s' cannot be used in this contextYou must define %s--auth-retry method must be 'interact', 'nointeract', or 'none'--topology must be net30, p2p, or subnetNote: option %s ignored because no TCP-based connection profiles are definedhttp-proxy-overrideBEGIN http_proxy[UNDEF] server = '%s' port = %d auth_method_string = '%s' auth_file = '%s'DISABLEDENABLED retry = %s timeout = %d http_version = '%s' user_agent = '%s'END http_proxyOriginally developed by James YonanCopyright (C) 2002-2010 OpenVPN Technologies, Inc. %s $ ./configure --enable-iproute2 --enable-password-save --disable-pkcs11 --with-ifconfig-path=/system/bin/ifconfig --with-iproute-path=/system/xbin/ip --with-route-path=/system/bin/routeCompile time defines: %s ENABLE_CLIENT_SERVER ENABLE_DEBUG ENABLE_EUREPHIA ENABLE_FRAGMENT ENABLE_HTTP_PROXY ENABLE_MANAGEMENT ENABLE_MULTIHOME ENABLE_PASSWORD_SAVE ENABLE_PORT_SHARE ENABLE_SOCKS USE_CRYPTO USE_LIBDL USE_LZO USE_SSLUse --help for more information.Maximum number of 'connection' options (%d) exceededBad http-proxy port number: %snct1.0OpenVPN-Autoproxy/1.0Maximum number of 'remote' options (%d) exceededin --iroute %s %s : Bad network/subnet specificationERROR: %sOptions warning: Bad backslash ('\') usage in %s:%d: remember that backslashes are treated as shell-escapes and if you need to pass backslash characters as part of a Windows filename, you should use double backslashes such as "c:\\openvpn\\static.key"%sOptions error: Parameter at %s:%d is too long (%d chars max): %s%sOptions error: No closing quotation (") in %s:%d%sOptions error: No closing single quotation (') in %s:%d%sOptions error: Residual parse state (%d) in %s:%d proto = %s local = '%s' local_port = %d remote = '%s' remote_port = %d remote_float = %s bind_defined = %s bind_local = %s connect_retry_seconds = %d connect_timeout = %d connect_retry_max = %d socks_proxy_server = '%s' socks_proxy_port = %d socks_proxy_retry = %sConnection profiles [default]:Connection profiles [%d]:Connection profiles ENDV4,dev-type %s,link-mtu %d,tun-mtu %d,proto %s,tun-ipv6,ifconfig %s,comp-lzo,mtu-dynamic,keydir %sexternal/openvpn/options.c,cipher %s,auth %s,keysize %d,secret,no-replay,no-iv,tls-auth,key-method %d,tls-server,tls-client server_network = %s server_netmask = %s server_network_ipv6 = %s server_netbits_ipv6 = %d server_bridge_ip = %s server_bridge_netmask = %s server_bridge_pool_start = %s server_bridge_pool_end = %s push_entry = '%s' ifconfig_pool_defined = %s ifconfig_pool_start = %s ifconfig_pool_end = %s ifconfig_pool_netmask = %s ifconfig_pool_persist_filename = '%s' ifconfig_pool_persist_refresh_freq = %d ifconfig_ipv6_pool_defined = %s ifconfig_ipv6_pool_base = %s ifconfig_ipv6_pool_netbits = %d n_bcast_buf = %d tcp_queue_limit = %d real_hash_size = %d virtual_hash_size = %d client_connect_script = '%s' learn_address_script = '%s' client_disconnect_script = '%s' client_config_dir = '%s' ccd_exclusive = %s tmp_dir = '%s' push_ifconfig_defined = %s push_ifconfig_local = %s push_ifconfig_remote_netmask = %s push_ifconfig_ipv6_defined = %s push_ifconfig_ipv6_local = %s/%d push_ifconfig_ipv6_remote = %s enable_c2c = %s duplicate_cn = %s cf_max = %d cf_per = %d max_clients = %d max_routes_per_client = %d auth_user_pass_verify_script = '%s' auth_user_pass_verify_script_via_file = %s ssl_flags = %d port_share_host = '%s' port_share_port = %d client = %s pull = %s auth_user_pass_file = '%s'Current Parameter Settings: config = '%s' mode = %d persist_config = %s persist_mode = %d show_ciphers = %s show_digests = %s show_engines = %s genkey = %s key_pass_file = '%s' show_tls_ciphers = %s remote_random = %s ipchange = '%s' dev = '%s' dev_type = '%s' dev_node = '%s' lladdr = '%s' topology = %d tun_ipv6 = %s ifconfig_local = '%s' ifconfig_remote_netmask = '%s' ifconfig_noexec = %s ifconfig_nowarn = %s ifconfig_ipv6_local = '%s' ifconfig_ipv6_netbits = %d ifconfig_ipv6_remote = '%s' shaper = %d tun_mtu = %d tun_mtu_defined = %s link_mtu = %d link_mtu_defined = %s tun_mtu_extra = %d tun_mtu_extra_defined = %s fragment = %d mtu_discover_type = %d mtu_test = %d mlock = %s keepalive_ping = %d keepalive_timeout = %d inactivity_timeout = %d ping_send_timeout = %d ping_rec_timeout = %d ping_rec_timeout_action = %d ping_timer_remote = %s remap_sigusr1 = %d explicit_exit_notification = %d persist_tun = %s persist_local_ip = %s persist_remote_ip = %s persist_key = %s mssfix = %d resolve_retry_seconds = %d username = '%s' groupname = '%s' chroot_dir = '%s' cd_dir = '%s' writepid = '%s' up_script = '%s' down_script = '%s' down_pre = %s up_restart = %s up_delay = %s daemon = %s inetd = %d log = %s suppress_timestamps = %s nice = %d verbosity = %d mute = %d gremlin = %d status_file = '%s' status_file_version = %d status_file_update_freq = %d occ = %s rcvbuf = %d sndbuf = %d sockflags = %d fast_io = %s lzo = %d route_script = '%s' route_default_gateway = '%s' route_default_metric = %d route_noexec = %s route_delay = %d route_delay_window = %d route_delay_defined = %s route_nopull = %s route_gateway_via_dhcp = %s max_routes = %d allow_pull_fqdn = %s management_addr = '%s' management_port = %d management_user_pass = '%s' management_log_history_cache = %d management_echo_buffer_size = %d management_write_peer_info_file = '%s' management_client_user = '%s' management_client_group = '%s' management_flags = %d shared_secret_file = '%s' key_direction = %d ciphername_defined = %s ciphername = '%s' authname_defined = %s authname = '%s' prng_hash = '%s' prng_nonce_secret_len = %d keysize = %d engine = %s replay = %s mute_replay_warnings = %s replay_window = %d replay_time = %d packet_id_file = '%s' use_iv = %s test_crypto = %s tls_server = %s tls_client = %s key_method = %d ca_file = '%s' ca_path = '%s' dh_file = '%s' cert_file = '%s' priv_key_file = '%s' pkcs12_file = '%s' cipher_list = '%s' tls_verify = '%s' tls_export_cert = '%s' tls_remote = '%s' crl_file = '%s' ns_cert_type = %d remote_cert_ku[i] = %d remote_cert_eku = '%s' tls_timeout = %d renegotiate_bytes = %d renegotiate_packets = %d renegotiate_seconds = %d handshake_window = %d transition_window = %d single_session = %s push_peer_info = %s tls_exit = %s tls_auth_file = '%s'IPv6 prefix '%s': invalid '/bits' specIPv6 prefix '%s': invalid IPv6 addressin --iroute-ipv6 %s: Bad IPv6 prefix specificationprotolocallocal_portremoteremote_porthttp_proxy_serverhttp_proxy_portsocks_proxy_serversocks_proxy_portdaemondaemon_log_redirectdaemon_start_timedaemon_pidBF-CBCSHA1TMPDIR/tmpkey file (--secret)--proto tcp is ambiguous in this context. Please specify --proto tcp-server or --proto tcp-clientonly one of --daemon or --inetd may be specified--local or --remote cannot be used with --inetd--proto tcp-client cannot be used with --inetd--inetd nowait can only be used with --proto tcp-server--inetd nowait can only be used in TLS mode--inetd nowait only makes sense in --dev tap mode--lladdr can only be used in --dev tap mode--connect-retry doesn't make sense unless also used with --proto tcp-client--connect-timeout doesn't make sense unless also used with --proto tcp-clientonly one of --tun-mtu or --link-mtu may be defined (note that --ifconfig implies --link-mtu %d)--mtu-test only makes sense with --proto udp--remote and --local addresses are the same--local and --remote addresses must be distinct from --ifconfig addresses--local addresses must be distinct from --ifconfig addresseslocal and remote/netmask --ifconfig addresses must be different--bind and --nobind can't be used together--local and --nobind don't make sense when used together--lport and --nobind don't make sense when used together--nobind doesn't make sense unless used with --remote--management is not specified, however one or more options which modify the behavior of --management were specified--management-client-(user|group) can only be used on unix domain sockets--fragment can only be used with --proto udp--explicit-exit-notify can only be used with --proto udp--remote MUST be used in TCP Client mode--http-proxy or --auto-proxy MUST be used in TCP Client mode (i.e. --proto tcp-client)--http-proxy can not be used together with --socks-proxy--socks-proxy can not be used in TCP Server modeTCP server mode allows at most one --remote address--mode server only works with --dev tun or --dev tap--pull cannot be used with --mode server--mode server currently only supports --proto udp or --proto tcp-server--port-share only works in TCP server mode (--proto tcp-server)--mode server requires --tls-server--remote cannot be used with --mode server--nobind cannot be used with --mode server--http-proxy cannot be used with --mode server--socks-proxy cannot be used with --mode server cannot be used with --mode server--shaper cannot be used with --mode server--inetd cannot be used with --mode server--ipchange cannot be used with --mode server (use --client-connect instead)--connect-freq only works with --mode server --proto udp. Try --max-clients instead.The third parameter to --ifconfig-pool (netmask) is only valid in --dev tap mode--explicit-exit-notify cannot be used with --mode server--redirect-gateway cannot be used with --mode server (however --push "redirect-gateway" is fine)--route-delay cannot be used with --mode server--up-delay cannot be used with --mode server--ifconfig-pool-persist must be used with --ifconfig-pool--ifconfig-ipv6-pool needs --ifconfig-ipv6Warning: --ifconfig-ipv6 without --tun-ipv6 will not do IPv6--auth-user-pass cannot be used with --mode server (it should be used on the client side only)--ccd-exclusive must be used with --client-config-dir--mode server requires --key-method 2--client-cert-not-required %smust be used with --management-client-auth, an --auth-user-pass-verify script, or plugin--username-as-common-name %s--auth-user-pass-optional %s--script-security method='system' cannot be combined with --no-name-remapping--ifconfig-pool/--ifconfig-pool-persist requires --mode server--ifconfig-ipv6-pool requires --mode server--hash-size requires --mode server--learn-address requires --mode server--client-connect requires --mode server--client-disconnect requires --mode server--client-config-dir/--ccd-exclusive requires --mode server--client-to-client requires --mode server--duplicate-cn requires --mode server--connect-freq requires --mode server--client-cert-not-required requires --mode server--username-as-common-name requires --mode server--auth-user-pass-optional requires --mode server--no-name-remapping requires --mode server--opt-verify requires --mode server--tcp-nodelay requires --mode server--auth-user-pass-verify requires --mode server--port-share requires TCP server mode (--mode server --proto tcp-server)--replay-window only makes sense with --proto udp--replay-window doesn't make sense when replay protection is disabled with --no-replayspecify only one of --tls-server, --tls-client, or --secretDH file (--dh)Parameter --capath cannot be used when --pkcs12 is also specified.Parameter --cert cannot be used when --pkcs12 is also specified.Parameter --key cannot be used when --pkcs12 is also specified.You must define CA file (--ca) or CA path (--capath)No client-side authentication method is specified. You must use either --cert/--key, --pkcs12, or --auth-user-passIf you use one of --cert or --key, you must use them bothcertificate file (--cert) or PKCS#12 file (--pkcs12)private key file (--key) or PKCS#12 file (--pkcs12)ca_fileca_pathdh_filecert_filepriv_key_filepkcs12_filecipher_listtls_verifytls_export_certtls_remotetls_timeoutrenegotiate_bytesrenegotiate_packetsrenegotiate_secondshandshake_windowtransition_windowtls_auth_filesingle_sessionpush_peer_infotls_exitcrl_filekey_methodns_cert_typeremote_cert_ku[0]remote_cert_eku--pull--auth-user-pass requires --pullParameter %s can only be specified in TLS-mode, i.e. where --tls-server or --tls-client is also specified.the --%s directive should have at most %d parameter%s.%s To pass a list of arguments as one of the parameters, try enclosing them in double quotes ("").WARNING: '%s' is used inconsistently, %s='%s', %s='%s'WARNING: '%s' is present in %s config but missing in %s config, %s='%s'version %sNOTE: Options consistency check may be skewed by version differencesforeign_option_%dforeign_option: name/value overflowIn %s:%d: Error opening configuration file: %sIn %s:%d: Maximum recursive include levels exceeded in include attempt of file %s -- probably you have a configuration file that tries to include itself.[CMD-LINE]parameterECHOECHO-PULL%s:%secho/parameter option overflowunixport number associated with --management directive is out of rangemanagement-client-usermanagement-client-groupmanagement-query-passwordsmanagement-holdmanagement-signalmanagement-forget-disconnectmanagement-clientmanagement-client-authmanagement-client-pfmanagement-log-cache--management-log-cache parameter is out of rangepluginplugin add failed: %smodeserverBad --mode parameter: %sdev-typedev-nodelladdrlladdr parm '%s' must be a MAC addresstopologyiprouteifconfigifconfig parms '%s' and '%s' must be valid addressesifconfig-ipv6ifconfig-ipv6: /netbits must be between 64 and 124, not '/%d'ifconfig-ipv6 parms '%s' and '%s' must be valid addressesifconfig-noexecifconfig-nowarnremote-randomconnection[CONNECTION-OPTIONS]Each 'connection' block must contain exactly one 'remote' directiveremote-ip-hintremote: port number associated with host %s is out of rangeremote: bad protocol associated with host %s: '%s'resolv-retryinfiniteconnect-retryconnect-timeoutconnect-retry-maxipchangefloatgremlinchrootcdwritepiddown-preup-delayup-restartsyslogWARNING: Multiple --daemon directives specified, ignoring --daemon %s. (Note that initscripts sometimes add their own --daemon directive.)inetdwaitwhen --inetd is used with two parameters, one of them must be 'wait' or 'nowait' and the other must be a daemon name to use for system loggingnowaitsuppress-timestampslog-appendmlockmultihomeerrors-to-stderrstatus-version--status-version must be 1 to 3remap-usr1SIGHUPSIGTERM--remap-usr1 parm must be 'SIGHUP' or 'SIGTERM'link-mtuudp-mtutun-mtutun-mtu-extramtu-dynamic--mtu-dynamic has been replaced by --fragmentfragmentmtu-discmtu-testnicercvbufsndbufsocket-flagsTCP_NODELAYunknown socket flag: %stxqueuelenshaperBad shaper value, must be between %d and %dportBad port number: %slportBad local port number: %srportBad remote port number: %sbindnobindfast-ioBad protocol: '%s'. Allowed protocols with --proto option: %sproto-forceBad --proto-force protocol: '%s'auto-proxyPROXY: %sshow-proxy-settingsHTTP Server: %sHTTP Port: %dSOCKS Server: %sSOCKS Port: %dProxy error: %shttp-proxyhttp-proxy port number not definedautoauto-nctbasichttp-proxy-retryhttp-proxy-timeouthttp-proxy-optionVERSIONAGENTBad http-proxy-option or missing parameter: '%s'socks-proxyBad socks-proxy port number: %ssocks-proxy-retrykeepaliveping-exitping-timer-remexplicit-exit-notifypersist-tunpersist-keypersist-local-ippersist-remote-iprouteroute parameter network/IP '%s' must be a valid addressroute parameter netmask '%s' must be an IP addressroute parameter gateway '%s' must be a valid addressroute-ipv6route-ipv6 parameter network/IP '%s' must be a valid addressroute-ipv6 parameter gateway '%s' must be a valid addressmax-routes--max-routes parameter is out of rangeroute-gatewaydhcproute-gateway parm '%s' must be a valid addressroute-metricroute-delayroute-noexecroute-nopullallow-pull-fqdnredirect-gatewayredirect-privateautolocaldef1bypass-dhcpbypass-dnsunknown --%s flag: %sremote-random-hostnamesetenvREMOTE_RANDOM_HOSTNAMEGENERIC_CONFIGthis is a generic configuration and cannot directly be usedSERVER_POLL_TIMEOUTFORWARD_COMPATIBLEsetenv-safescript-securityexecvesystemunknown --script-security method: %smssfixdisable-occerror parsing --server parametersnopoolerror parsing --server: %s is not a recognized flagserver-ipv6error parsing --server-ipv6 parameter--server-ipv6 settings: only /64 supported right now (not /%d)error parsing --server-ipv6: %s is not a recognized flagserver-bridgeerror parsing --server-bridge parametersnogwpushpush-resetifconfig-poolerror parsing --ifconfig-pool parametersifconfig-pool-persistifconfig-pool-linearifconfig-ipv6-poolerror parsing --ifconfig-ipv6-pool parameters--ifconfig-ipv6-pool settings: only /64 supported right now (not /%d)hash-size--hash-size sizes must be >= 1 (preferably a power of 2)connect-freq--connect-freq parms must be > 0max-clients--max-clients must be at least 1max-routes-per-clientclient-cert-not-requiredusername-as-common-nameauth-user-pass-optionalno-name-remappingopt-verifyauth-user-pass-verifyvia-envvia-filesecond parm to --auth-user-pass-verify must be 'via-env' or 'via-file'--auth-user-pass-verify requires a second parameter ('via-env' or 'via-file')tmp-dirclient-config-dirccd-exclusivebcast-buffers--bcast-buffers parameter must be > 0tcp-queue-limit--tcp-queue-limit parameter must be > 0port-shareport number associated with --port-share directive is out of rangeclient-to-clientduplicate-cnirouteiroute-ipv6ifconfig-pushcannot parse --ifconfig-push addressesifconfig-push-constraintcannot parse --ifconfig-push-constraint addressesifconfig-ipv6-pushcannot parse --ifconfig-ipv6-push addressessecond argument to --ifconfig-ipv6-push missing and no global --ifconfig-ipv6 address setdisabletcp-nodelayclientpullpush-continuationserver-poll-timeoutauth-user-passusergroupdhcp-optionroute-methodcomp-lzoadaptivebad comp-lzo option: %s -- must be 'yes', 'no', or 'adaptive'comp-noadaptshow-ciphersshow-digestsshow-engineskey-directiongenkeyauthcipherprngprng parameter nonce_secret_len must be between %d and %dno-replayreplay-windowreplay-window window size parameter (%d) must be between %d and %dreplay-window time window parameter (%d) must be between %d and %dreplay-window option is missing window size parametermute-replay-warningsno-ivreplay-persisttest-cryptoenginekeysizeBad keysize: %sshow-tlstls-servertls-clientcacapathdhcertkeypkcs12askpassauth-nocachesingle-sessionpush-peer-infotls-exittls-ciphercrl-verifytls-verifytls-export-certtls-remotens-cert-type--ns-cert-type must be 'client' or 'server'remote-cert-kuremote-cert-ekuremote-cert-tlsTLS Web Server AuthenticationTLS Web Client Authentication--remote-cert-tls must be 'client' or 'server'tls-timeoutreneg-bytesreneg-pktsreneg-sechand-windowtran-windowkey-methodkey_method parameter (%d) must be >= %d and <= %drmtunmktunUnrecognized option or missing parameter(s) in %s:%d: %s (%s)2.2.1[CONFIG-STRING][PUSH-OPTIONS]I'm trying to parse "%s" as an --option parameter but I don't see a leading '--'OPTIONS IMPORT: reading client specific options from: %sexternal/openvpn/otime.c us=%d[%d/%d] #%u / time = (%u) %s[ #%uPID Persist Write to %s: %sCannot write to --replay-persist file %sCannot seek to beginning of --replay-persist file %sCannot open --replay-persist file %s for read/writeCannot obtain exclusive lock on --replay-persist file %sPID Persist Read from %s: %sRead error on --replay-persist file %sClose error on --replay-persist file %sPID packet_id_freePID packet_id_init seq_backtrack=%d time_backtrack=%dexternal/openvpn/packet_id.cAssertion Failed: Array index=%d out of bounds for array size=%d in %s:%dPID TEST %lu:%u %lu:%uReplay-window backtrack occurred [%d]DESTSRCDROPACCEPTPF: %s/%s/%s %s %s rule=[%s %s]PF: %s/%s/%s %s %s ----- struct pf_subnet_set ----- default_allow=%s %s/%s %s ----- struct pf_cn_set ----- %s %s ---------- %s LOOKUP FAILED ----- struct pf_set ----- kill=%d----- %s : struct pf_context -----enabled=%dfilename='%s'file_last_mod=%un_check_reload=%ureload=[%d,%u,%u]--------------------pfpf_filepf_init_context#1WARNING: OPENVPN_PLUGIN_ENABLE_PF disabledpf_init_context#2PF: %s: duplicate common name in [clients] section: '%s'PF: %s/%d: bad '/n' subnet specifier: '%s'PF: %s/%d: bad '/n' subnet specifier: must be between 0 and 32: '%s'PF: %s/%d: bad network address: '%s'WARNING: PF: %s/%d: incorrect subnet %s/%d changed to %s/%d PF: %s/%d: no data after +/-: '%s'external/openvpn/pf.c[clients accept][clients drop][subnets accept][subnets drop][end][kill]PF: %s/%d unknown tag: '%s'PF: %s/%d line must begin with '+', '-', or '[' : '%s'PF: %s: missing [end]PF: %s: cannot openPF: %s rejected due to %d error(s)[SERVER-PF]pf-killpf_check_reloadPF_CN_MATCHPF_CN_DEFAULTPF_CN_FAULTPF: %s/%s %s %s %s rule=[%s/%s %s]PF: %s/%s %s %s %sPF_ADDR_MATCHPF_ADDR_DEFAULTPF_ADDR_FAULT%sInactivity timeout (--ping-exit), exiting%sInactivity timeout (--ping-restart), restartingexternal/openvpn/ping.cSENT PINGPLUGIN_DOWNPLUGIN_UPPLUGIN_ROUTE_UPPLUGIN_IPCHANGEPLUGIN_TLS_VERIFYPLUGIN_AUTH_USER_PASS_VERIFYPLUGIN_CLIENT_CONNECTPLUGIN_CLIENT_DISCONNECTPLUGIN_LEARN_ADDRESSPLUGIN_TLS_FINALOPENVPN_PLUGIN_ENABLE_PFPLUGIN_???PLUGIN_RETURN_PRINT %sPLUGIN #%d (%s)[%d] '%s' -> '%s' PLUGIN_CLOSE: %sPLUGIN_CLOSE: dlclose() failed on plugin: %s plugin[%d] %s '%s'|external/openvpn/plugin.cPLUGIN: could not find required symbol '%s' in plugin shared object %s: %sPLUGIN_INIT: could not load plugin shared object %s: %sopenvpn_plugin_open_v1openvpn_plugin_open_v2openvpn_plugin_func_v1openvpn_plugin_func_v2openvpn_plugin_close_v1openvpn_plugin_abort_v1openvpn_plugin_client_constructor_v1openvpn_plugin_client_destructor_v1openvpn_plugin_min_version_required_v1openvpn_plugin_select_initialization_point_v1PLUGIN: symbol openvpn_plugin_open_vX is undefined in plugin: %sPLUGIN: symbol openvpn_plugin_func_vX is undefined in plugin: %sPLUGIN_INIT: plugin needs interface version %d, but this version of OpenVPN only supports version %d: %sWARNING: plugin '%s' specified by a relative pathname -- using an absolute pathname would be more secure%s[%d] = '%s'ARGVENVPPLUGIN_INIT: PRE[RETLIST]PLUGIN_INIT: POST %s '%s' intercepted=%s %sPLUGIN_INIT: plugin %s expressed interest in unsupported plugin types: [want=0x%08x, have=0x%08x]PLUGIN_INIT: plugin initialization function failed: %sPLUGIN_CALL: PRE type=%sPLUGIN_CALL: POST %s/%s status=%dPLUGIN_CALL: plugin function %s failed with status %d: %sexternal/openvpn/pool.c%s,%s,%s%s,%s--ifconfig-pool start IP [%s] is greater than end IP [%s]--ifconfig-pool address range is too large [%s -> %s]. Current maximum is %d addresses, as defined by IFCONFIG_POOL_MAX variable.IFCONFIG POOL IPv6: (IPv4) size=%d, size_ipv6=%d, netbits=%d, base_ipv6=%sIFCONFIG POOL: base=%s size=%d, ipv6=%dIFCONFIG POOL LISTifconfig_pool_read(), in='%s', TODO: IPv6succeeded -> ifconfig_pool_set()PROXY: automatic detection not supported on this OSHTTP Proxysend_line: TCP port write failed on send()external/openvpn/proxy.crecv_line: TCP port read timeout expiredrecv_line: TCP port read failed on select()recv_line: TCP port read failed on recv()recv_line: Non-ASCII character (%d) read on recv()HTTP_PROXY: server not specifiedntlmntlm2ERROR: unknown HTTP authentication method: '%s'Proxy-Authenticate: Basic PROXY AUTH BASIC: '%s'Digest PROXY AUTH DIGEST: '%s'NTLMPROXY AUTH HTLM: '%s'CONNECT %s:%d HTTP/%sSend to HTTP proxy: '%s'Host: %sUser-Agent: %sProxy-Authorization: Basic %sAttempting Basic Proxy-AuthorizationProxy-Connection: Keep-AliveProxy-Authorization: NTLM %sAttempting NTLM Proxy-Authorization phase 1HTTP proxy returned: '%s'%*s %dProxy requires authentication%%*s NTLM %%%dsauth string: '%s'Received NTLM Proxy-Authorization phase 2 responseCONNECT %s:%d HTTP/%s HOST: %s:%dAttempting NTLM Proxy-Authorization phase 3NTLM Proxy-Authorization phase 3 failed: received corrupted data from proxy serverrealmnoncealgorithmopaque%s:%d, opaque="%s"00000001%s %s HTTP/%sProxy-Authorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", qop=%s, nc=%s, cnonce="%s", response="%s"%sHTTP proxy authenticate '%s'HTTP proxy: support for basic auth and other cleartext proxy auth methods is disabledHTTP proxy: do not recognize the authentication method required by proxyHTTP proxy: no support for proxy authentication methodHTTP proxy returned bad statusPORT SHARE PROXY: unexpected status=%dPORT SHARE: sendmsg sd=%d len=%dPORT SHARE: sendmsg failed (unable to communicate with background process)PORT SHARE PROXY: delete sd=%dPORT SHARE: waiting for background process to exitPORT SHARE: background process exitedPORT SHARE PROXY: connect to port-share server failedPORT SHARE PROXY: connect to port-share server succeededPORT SHARE PROXY: NEW CONNECTION [c=%d s=%d]PORT SHARE PROXY: RECEIVED sd=%dPORT SHARE PROXY: RECEIVED COMMAND_EXITPORT SHARE PROXY: partial write[%d], tried=%d got=%dPORT SHARE PROXY: proxy startingPORT SHARE PROXY: event_wait failedPORT SHARE PROXY: proxy exitingPORT SHARE: socketpair call failedConnection reset command was pushed by serverserver-pushed-connection-reset[PUSH_ROUTE_REMOVE] PUSH ROUTE: '%s'PUSH OPTION FAILED (illegal comma (',') in string): '%s'external/openvpn/push.cPUSH_REQUESTsend_push_reply(): safe_cap=%d,ifconfig-ipv6 %s %s--push ifconfig-ipv6 option is too long,push-continuation 2--push option is too long,ifconfig %s %s,push-continuation 1PUSH_REPLYPUSH: Received control message: '%s'WARNING: Received bad push/pull message: %sAUTH: Received AUTH_FAILED control messageauth-failureAUTH_FAILED,AuthAUTH_FAILED,CRV1:external/openvpn/reliable.cACK mark active incoming ID %uACK reliable_schedule_nowACK reliable_send ID %u (size=%d to=%d)ACK received for pid %u, deleting from send bufferACK acknowledge ID %u (ack->len=%d)ACK acknowledge ID %u FAILED (ack->len=%d)ACK read ID %u (buf->len=%d)ACK read ID FAILED (buf->len=%d)[%u] %uACK reliable_send_timeout %d %sACK reliable_can_send active=%d current=%d : %sACK output sequence broken: %sACK %u breaks sequentiality: %sACK RWBS rel->size=%d rel->packet_id=%08x id=%08x ret=%d ACK %u is a replay: %sACK no free receive buffer available: %s sid=%sACK write ID %u (ack->len=%d, n=%d)ACK read BAD SESSION-ID FROM REMOTE, local=%s, remote=%sACK mark active outgoing ID %uOpenVPN ROUTE: cannot add more than %d IPv6 routes -- please increase the max-routes option in the client configuration fileOpenVPN ROUTE: cannot add more than %d routes -- please increase the max-routes option in the client configuration filenil route %s/%s/%s/%s [redirect_default_gateway local=%d]/proc/net/route%*s %x %x %*s %*s %*s %d %xGDG: route[%d] %s/%s/%s m=%uGDG: best=%s[%d] lm=%uGDGMA: get_default_gateway failedGDGMA: socket() failedGDGMA: ioctl(SIOCGIFCONF) failedGDGMA: %sGDGMA: SIOCGIFFLAGS(%s) failedGDGMA: interface %s is down or loopbackGDGMA: SIOCGIFNETMASK(%s) failedGDGMA: gwip=0x%08x ina=0x%08x mask=0x%08xGDGMA: couldn't find gw interfaceGDGMA: SIOCGIFHWADDR(%s) failedROUTE: bypass_host_route[%d]=%sdelete_route_ipv6(): not deleting %s/%d, no IPv6 on if %sdelete_route_ipv6(%s/%d)%s -6 route del %s/%d dev %sERROR: Linux route -6/-A inet6 del command failedadd_route_ipv6(): not adding %s/%d, no IPv6 on if %sadd_route_ipv6(%s/%d -> %s metric %d) dev %s%s -6 route add %s/%d dev %s metric %dERROR: Linux route -6/-A inet6 add command failedOpenVPN ROUTE: omitted no-op route: %s/%s -> %s%s route add %s/%d via %smetric %dERROR: Linux route add command failed%s route del %s/%dERROR: Linux route delete command failed%s VPN gateway parameter (--route-gateway or --ifconfig) is missing%s Cannot read current default gateway from system%s Cannot obtain current remote host addressNOTE: unable to redirect default gateway --ROUTE network %s netmask %s gateway %sroute_ipv6_network_%droute_ipv6_gateway_%droute_%s_%droute_%svpn_gatewaynetworknetmaskgatewayroute_metric_%ddefaultOpenVPN ROUTE: vpn_gateway undefinednet_gatewayOpenVPN ROUTE: net_gateway undefined -- unable to get default gateway from systemremote_hostOpenVPN ROUTE: remote_host undefinedOpenVPNROUTE6: cannot parse gateway spec '%s'OpenVPN ROUTE6: OpenVPN needs a gateway parameter for a --route-ipv6 option and no default was specified by either --route-ipv6-gateway or --ifconfig-ipv6 optionsOpenVPN ROUTE: route metric for network %s (%s) must be >= 0OpenVPN ROUTE: failed to parse/resolve route for host/network: %sOpenVPN ROUTE: OpenVPN needs a gateway parameter for a --route option and no default was specified by either --route-gateway or --ifconfig optionsROUTE6: default_gateway=UNDEFOpenVPN ROUTE: failed to parse/resolve default gateway: %sOpenVPN ROUTE6: (init) number of route options (%d) is greater than route list capacity (%d)ROUTE default_gateway=%sROUTE: default_gateway=UNDEFOpenVPN ROUTE: routes dropped because number of expanded routes is greater than route list capacity (%d)OpenVPN ROUTE: (copy) number of route options in src (%d) is greater than route list capacity in dest (%d)SCHEDULE: %s wakeup=[%s] pri=%uSCHEDULE: %s NULLschedule_find_leastexternal/openvpn/schedule.cschedule_add_modifyOutput Traffic Shaping initialized at %d bytes per secondsofthardprocess%s[%s,%s] received, %s exiting%s[%s,%s] received, %s restartingUnknown signal %d [%s,%s] received by %sUnknown signal receivedSIGTERM received, sending exit notification to peerexternal/openvpn/sig.cexit-with-notificationOpenVPN STATISTICSTUN/TAP read bytes,%lluTUN/TAP write bytes,%lluTCP/UDP read bytes,%lluTCP/UDP write bytes,%lluAuth read bytes,%lluSIGINTsigintsigtermsighupSIGUSR1sigusr1SIGUSR2sigusr2[unknown protocol]ERROR: received strange incoming packet with an address length of %d -- we only accept address lengths of %d.%s: Socket bind[%d] failed on unix domain socket %s: %sCannot create unix domain socketexternal/openvpn/socket.cSTREAM: GET NEXT len=%dSTREAM: GET FINAL len=%dSTREAM: RESETSTREAM: SET NEXT, buf=[%d,%d] next=[%d,%d] len=%d maxlen=%dTCP/UDP: No outgoing address to send packetRS%sS?[undef] (via %s)TCP connection established with %sTCP/UDP: Incoming packet rejected from %s[%d], expected peer address: %s (allow this incoming source address/port by removing --remote or adding --float)%s: Socket bind failed on local address %s: %s%s_ip%s_porttrustedSTREAM: INIT maxlen=%dTCP/UDP: Closing socketTCP/UDP: Close Socket failedTCP/UDP: Close Socket (ctrl_sd) failedListening for incoming TCP connection on %sTCP: listen() failedUDP: Cannot create UDP socketNOTE: setsockopt SO_SNDBUF=%d failedNOTE: setsockopt SO_RCVBUF=%d failedSocket Buffers: R=[%d->%d] S=[%d->%d]Cannot create TCP socketTCP: Cannot setsockopt SO_REUSEADDR on TCP socketTCP: getpeername() failedTCP: accept(%d) failedTCP: Received strange incoming connection with unknown address length=%dRESOLVE: Cannot resolve host address: %s: %s (I would have retried this name query if you had specified the --resolv-retry option.)RESOLVE: Cannot resolve host address: %s: %sRESOLVE: Cannot parse IP address: %sRESOLVE: Ignored SIGUSR1 signal received during DNS resolution attempt[NO_DATA] The requested name is valid but does not have an IP address.[HOST_NOT_FOUND] The specified host is unknown.[NO_RECOVERY] A non-recoverable name server error occurred.[TRY_AGAIN] A temporary error occurred on an authoritative name server.[unknown h_errno value]RESOLVE: Sorry, but we only accept IPv4 DNS names: %sRESOLVE: NOTE: %s resolves to %d addressesRESOLVE: signal received during DNS resolution attemptTCP: select() failedTCP NOTE: Rejected connection attempt from %s due to --remote settingTCP: close socket failed (new_sd)TCP: close socket failed (sd)Attempting to establish TCP connection with %s [nonblock]TCP: connect to %s failed, will try again in %d seconds: %sTCP ClientRESOLVE_REMOTE flags=0x%04x phase=%d rrs=%d sig=%d status=%dTCP/UDP: Preserving recently used remote address: %sSOCKSTCP/UDPNOTE: setsockopt TCP_NODELAY=%d failed (No kernel support)TCP/UDP: Dynamic remote address changed during TCP connection establishment%s link local: [inetd] (bound)%s link local%s: %s%s link remote: %sSTREAM: WRITE %d offset=%dSTREAM: ADD length_added=%dNon-OpenVPN client protocol detectedWARNING: Bad encapsulated packet length from peer (%d), which must be > 0 and <= %d -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]STREAM: ADD returned TRUE, buf_len=%d, residual_len=%dSTREAM: ADD returned FALSE (have=%d need=%d)NOYESSTREAM: RESIDUAL FULLY FORMED [%s], len=%d--ipchangePeer Connection Initiated with %sWARNING: ipchange plugin call failedudpUDPv4tcp-serverTCPv4_SERVERtcp-clientTCPv4_CLIENTtcpTCPv4external/openvpn/socks.crecv_socks_reply: TCP port read timeout expiredrecv_socks_reply: TCP port read failed on select()recv_socks_reply: TCP port read failed on recv()recv_socks_reply: Socks proxy returned bad address typerecv_socks_reply: Socks proxy returned bad replySOCKS ProxySOCKS username and/or password exceeds 255 characters. Authentication not possible.%c%s%c%ssocks_username_password_auth: TCP port write failed on send()socks_username_password_auth: TCP port read timeout expiredsocks_username_password_auth: TCP port read failed on select()socks_username_password_auth: TCP port read failed on recv()socks_username_password_auth: server refused the authenticationsocks_handshake: TCP port write failed on send()socks_handshake: TCP port read timeout expiredsocks_handshake: TCP port read failed on select()socks_handshake: TCP port read failed on recv()socks_handshake: Socks proxy returned bad statussocks_handshake: server asked for username/login auth but we were not provided any credentialssocks_handshake: unknown SOCKS auth methodestablish_socks_proxy_passthru: TCP port write failed on send()S_INITIALS_UNDEFS_PRE_STARTS_STARTS_SENT_KEYS_GOT_KEYS_ACTIVES_NORMAL_OPS_ERRORS_???P_CONTROL_HARD_RESET_SERVER_V1P_CONTROL_HARD_RESET_CLIENT_V1P_CONTROL_HARD_RESET_CLIENT_V2P_CONTROL_HARD_RESET_SERVER_V2P_CONTROL_SOFT_RESET_V1P_CONTROL_V1P_ACK_V1P_DATA_V1P_???external/openvpn/ssl.c [key#%d state=%s id=%d sid=%s]DATA UNDEF len=%d%s kid=%d tls_hmac=%s pid=%s %s pid=%u DATA %s DATA len=%dTLS ERROR: BIO write %s errorTLS ERROR: BIO write %s incomplete %d/%dBIO write %s %d bytestls_write_plaintext_constTLS: tls_pre_encrypt: key_id=%dTLS Warning: no data channel send key available: %s%s pre_master: %s%s random1: %s%s random2: %sTLS Error: cannot locate HMAC in incoming packet from %sTLS Error: incoming packet authentication failed from %sTLS State Error: No TLS state for client %s, opcode=%dTLS State Error: Unknown key ID (%d) received from %s -- 0 was expectedTLS State Error: Large packet (size %d) received from %s -- a packet no larger than %d bytes was expectedtls_write_ciphertexttls_write_plaintextError creating %s BIOSSL_new failedssl_bioct_inct_outTLS: tls_pre_decrypt, key_id=%d, IP=%sTLS Error: local/remote TLS keys are out of sync: %s [%d]TLS Error: unknown opcode received from %s op=%dTLS Error: client->client or server->server connection attempted from %sTLS: control channel, op=%s, IP=%sTLS Error: session-id not found in packet from %sTLS: initial packet test, i=%d state=%s, mysid=%s, rec-sid=%s, rec-ip=%s, stored-sid=%s, stored-ip=%sTLS ERROR: received control packet with stale session-id=%sTLS: found match, session[%d], sid=%sTLS ERROR: initial packet local/remote key_method mismatch, local key_method=%d, op=%sTLS Error: Cannot accept new session request from %s due to session context expire or --single-session [1]TLS: Initial packet from %s, sid=%sTLS Error: Cannot accept new session request from %s due to session context expire or --single-session [2]TLS ERROR: new session local/remote key_method mismatch, local key_method=%d, op=%sTLS: new session incoming connection from %sTLS Error: Unroutable control packet received from %s (si=%d op=%s)TLS Error: Received control packet from unexpected IP addr: %sTLS: received P_CONTROL_SOFT_RESET_V1 s=%d sid=%sTLS: received control channel packet s#=%d sid=%sTLS Error: Existing session control channel packet from unknown IP address: %sTLS ERROR: local/remote key IDs out of sync (%d/%d) ID: %sTLS Error: reading acknowledgement record from packetTLS_ERROR: BIO read %s errorBIO read %s %d bytesTLS Error: Bad encrypting key generatedTLS Error: write_key failedData Channel EncryptTLS Error: KM1 write options failedERROR: Random number generator cannot obtain entropy for key generation [SSL]IV_VER=%s IV_PLAT=linux IV_HWADDR=%s UV_tls1_P_hash sec: %stls1_P_hash seed: %stls1_P_hash out: %sTLS Error: Certificate verification failed (key-method 1)TLS Error: Error reading data channel key from plaintext bufferTLS Error: Bad decrypting key received from peerTLS Error: Missing options stringData Channel DecryptuntrustedTLS Auth Error (verify_user_pass_management): peer provided a blank usernameacfauth_control_fileTLS Auth Error (verify_user_pass_plugin): peer provided a blank usernameTLS Auth Error: username attempted to change from '%s' to '%s' -- tunnel disabledTLS: tls_session_init: entryTLS: tls_session_init: new session object, sid=%sCannot create SSL_CTX objectCannot create SSL objectAvailable TLS Ciphers,listed in order of preference: keystore[[ANDROID]]connectundefinedacceptSSL state (%s): %sSSL alert (%s): %s: %sX509_%d_%sGenerating temp (%d bit) RSA keyUnable to get peer certificate from current contextpcfw+Failed to open temporary file : %sFailed to write peer certificate in PEM formatCertificate does not have key usage extensionValidating certificate key usage++ Certificate has key usage %04x, expects %04xCertificate does not have extended key usage extensionValidating certificate extended key usage++ Certificate has EKU (str) %s, expects %s++ Certificate has EKU (oid) %s, expects %sPrivate KeySSL_CTX_new TLSv1_server_methodCannot open memory BIO for inline DH parametersCannot open %s for DH parametersCannot load DH parameters from %sSSL_CTX_set_tmp_dhDiffie-Hellman initialized with %d bit keySSL_CTX_new TLSv1_client_methodError reading inline PKCS#12 filerbError opening file %sError reading PKCS#12 file %sOpenSSL ERROR code: %dCannot use certificateCannot use private keyPrivate key does not match the certificateCannot add certificate to certificate chain (X509_STORE_add_cert)Cannot add certificate to client CA list (SSL_CTX_add_client_CA)Cannot load inline certificate fileCannot load certificate file %sCannot load private key file %sCannot load CA certificate file %s path %s (SSL_CTX_load_verify_locations)WARNING: experimental option --capath %sCannot get certificate store (SSL_CTX_get_cert_store)Cannot load CA certificate file %s (SSL_load_client_CA_file)Cannot load certificate chain file %s (SSL_use_certificate_chain_file)WARNING: POTENTIALLY DANGEROUS OPTION --client-cert-not-required may accept clients which do not present a certificateCNProblem with cipher list: %sstruct session *tls1_PRF out[%d]: %sClientServerOpenVPN master secretOpenVPN key expansionMaster EncryptMaster DecryptTLS Error: Bad dynamic key generatedTLS Error: server generate_key_expansion failedTLS Error: Key Method #2 write faileduser-pass-verifyTLS Auth Error: could not write username/password to file: %sTLS Auth Error: could not create write username/password to temp file--auth-user-pass-verifyTLS Auth Error: peer provided a blank usernameTLS ERROR: Unknown key_method/flags=%d received from remote hostTLS Error: Error reading remote data channel key source entropy from plaintext bufferTLS Error: Failed to read required OCC options stringTLS Error: Auth Username/Password was not provided by peerTLS Auth Error: --username-as-common name specified and username is longer than the maximum permitted Common Name length of %d characterssucceededdeferred[CN SET]TLS: Username/Password authentication %s for username '%s' %sTLS Auth Error: Auth Username/Password verification failed for peerTLS Error: Certificate verification failed (key-method 2)TLS Auth Error: TLS object CN attempted to change from '%s' to '%s' -- tunnel disabledTLS Auth Error: TLS object CN=%s client-provided SSL certs unexpectedly changed during mid-session reauthTLS Auth Error: --client-config-dir authentication failed for common name '%s' file='%s'Option inconsistency warnings triggering disconnect due to --opt-verifyTLS Error: client generate_key_expansion failedVERIFY ERROR: depth=%d, could not extract X509 subject string from certificateVERIFY ERROR: could not extract %s from X509 subject string ('%s') -- note that the username length is limited to %d charactersVERIFY ERROR: depth=%d, error=%s: %sTLS Error: Convoluted certificate chain detected with depth [%d] greater than %dtls_id_%dtls_digest_%dCALLBACK: Cannot create BIO (for tls_serial_%d)CALLBACK: Error reading/writing BIO (for tls_serial_%d)tls_serial_%dCLIENTSERVERVERIFY OK: nsCertType=%sVERIFY nsCertType ERROR: %s, require nsCertType=%sVERIFY KU OKVERIFY KU ERRORVERIFY EKU OKVERIFY EKU ERRORVERIFY X509NAME OK: %sVERIFY X509NAME ERROR: %s, must be %s%d %sVERIFY PLUGIN OK: depth=%d, %sVERIFY PLUGIN ERROR: depth=%d, %speer_cert%sc %d %sTLS: executing verify command--tls-verify scriptVERIFY SCRIPT OK: depth=%d, %sVERIFY SCRIPT ERROR: depth=%d, %sCRL: BIO errCRL: cannot read: %sCRL: cannot read CRL from file %sCRL: CRL %s is from a different issuer than the issuer of certificate %sCRL CHECK FAILED: %s is REVOKEDCRL CHECK OK: %sVERIFY OK: depth=%d, %sTM_UNTRUSTEDTM_ACTIVETM_LAME_DUCKTM_???TLS: move_session: dest=%s src=%s reinit_src=%dTLS: move_session: exit%s %s, cipher %s %sControl Channel:, %d bit RSA, %d bit DSATLS: soft reset sec=%d bytes=%llu/%d pkts=%llu/%dTLS: tls_process: killed expiring keyTLS: tls_process: chg=%d ks=%s lame=%s to_link->len=%d wakeup=%dTLS: Initial Handshake, sid=%sTLS Error: TLS key negotiation failed to occur within %d seconds (check your network connectivity)STATE S_NORMAL_OPSTATE S_STARTSTATE S_ACTIVEReliable -> TCP/UDPTLS Error: Incoming Ciphertext -> TLS object write errorIncoming Ciphertext -> TLStls_read_plaintextTLS Error: TLS object -> incoming plaintext read errorTLS -> Incoming PlaintextSTATE S_SENT_KEYSTATE S_GOT_KEYTLS ERROR: Outgoing Plaintext -> TLS object write errorOutgoing Plaintext -> TLStls_read_ciphertextTLS Error: Ciphertext -> reliable TCP/UDP transport read errorOutgoing Ciphertext -> ReliableDedicated ACK -> TCP/UDPTLS: tls_process: timeout set to %dTLS Error: TLS handshake failedTLS: tls_multi_process: i=%d state=%s, mysid=%s, stored-sid=%s, stored-ip=%sTLS: tls_multi_process: killed expiring keysemi-TLS: tls_multi_process: untrusted session promoted to %strustedFailed to truncate status file: %sexternal/openvpn/status.cREADWRITEREAD/WRITENote: cannot open %s for %sWARNING: Since you are using --dev tun with a point-to-point topology, the second argument to --ifconfig must be an IP address. You are using something (%s) that looks more like a netmask. %sWARNING: Since you are using --dev tap, the second argument to --ifconfig must be a netmask, for example something like %sWARNING: --%s address [%s] conflicts with --ifconfig address pair [%s, %s]. %sWARNING: potential conflict between --%s address [%s] and --ifconfig address pair [%s, %s] -- this is a warning only that is triggered when local/remote addresses exist within the same /24 subnet as --ifconfig endpoints. %sWARNING: --%s address [%s] conflicts with --ifconfig subnet [%s, %s] -- local and remote addresses cannot be inside of the --ifconfig subnet. %sError: problem with tun vs. tap setting%s addr del dev %s local %s peer %s%s addr del dev %s %s/%dLinux ip addr del failednull/dev/tunNote: Cannot open TUN/TAP dev %sI don't recognize device %s as a tun or tap devicetapNote: Cannot ioctl TUNSETIFF %sTUN/TAP device %s openedTUN/TAP TX queue length set to %dNote: Cannot set tx queue length on %sNote: Cannot open control socket on %sdo_ifconfig, tt->ipv6=%d, tt->did_ifconfig_ipv6_setup=%d%s link set dev %s up mtu %dLinux ip link set failed%s addr add dev %s local %s peer %sLinux ip addr add failed%s addr add dev %s %s/%d broadcast %s%s -6 addr add %s/%d dev %sLinux ip -6 addr add failedT%sT?NOTE: your local LAN uses the extremely common subnet address 192.168.0.x or 192.168.1.x. Be aware that this might create routing conflicts if you connect to the VPN server from public locations such as internet cafes that use the same subnet.WARNING: potential %s subnet conflict between local LAN [%s/%s] and remote VPN [%s/%s]external/openvpn/tun.cCannot ioctl TUNSETPERSIST(%d) %sCannot get user entry for %sCannot ioctl TUNSETOWNER(%s) %sCannot get group entry for %sPersist state set to: %sTUN/TAP adapterifconfig_localifconfig_remoteifconfig_netmaskifconfig_broadcastinit_tun: problem converting IPv6 ifconfig addresses %s and %s to binaryifconfig_ipv6_localifconfig_ipv6_remote[unknown-dev-type] ޲ݲ" ƲIJ\$(tH $D\t(H0H@0D 4D| P @Plx8lt 8Th,p!l0h$  ?  `  $48t< 4l !""#h$$%h&'') <+`++?h,H---|../,080T0011p2P333T444,56779:t;<(<<===>>@@ AAtB8C`CC8DGH0H IDJ\NN 4@ @A0CCDI>>>>l??4B lCCCDD?