MZ@ !L!This program cannot be run in DOS mode. $yJyś'nRichPEL.Q @`CNl2d .text `.rdata3@@@.data3P0P@c̡PDC CC(PDC ,PD C0PDC4PDC @PD CDPDCHPDC LPD CPPDC`PDC dPD CPD @ PD0@$PD@@8PD@>tuN Qh*Bh$B EVU RẼ|WZF EPEEjVh|6C׃ hhCVE8}@iE)jjjWLuMQ4#VVjWyVVVWR$V9?uW REWVEu/ DhP6CQEVPVMQ3UERoPc EEjVhL6C׃ EEE EuVCEEtD6C3uvDS<6C3uDž<206C 3uDžt(6C3uDžL 6C3u E$C3uDž\C 3u E6C3u Eu 6C 3u0EHECMPQ36C3u3EHEsChPQU5C 3uDžx5C3uDžl5C3u E5C 3u Ep5C3uUV5C3uEHECE&5C3uDž|5C3u=EHEECPCdDžd5C 3u0EHECPR pt@PEtE^5C 3uEHECE/5C 3eEHEkCEEHE}3PMUQXRDPQRhh5C! Dh<5CQDh 5CR h4CDP\DPHD]uܡvDt;Dt PMQVUREPSοpQXtEt PlPtEt PRE̅t P7Et Pi_^[]ËDRh#CPz MDQh4CRbDh4CPR Dh4CQADhX4CR0Dh<4CP  Dh4CQDh3CRDh3CP DDh3CQھDh3CRɾDh`3CP蹾 Dh03CQ訾Dh2CR藾Dh2CP臾 Dh2CQvDh\2CReD@h82CPR Dh 2CQADj;j;h1CR,Dh1CP Dh|1CQ Dh@1CRDh0CP D@h0CQֽDhX0CRŽDh,0CP赽 Dh/CQ褽Dh/CR蓽Dh/CP能 Dhd/CQrDh /CRaD@h.CPN Dh.CQ=DhH.CR,Dh-CP Dh-CQ Dhh-CRDh-CP Dh,CQټD@h,CRżDhh,CP赼T;t^EE;t DWhH,CQ艼 V舽UvDRWPruuE DWPh,,CQSD;ƣvDu)DDRh,CP&E ;3 9ut DDQhH,CR vD;t[PDP{ vDh+CjQ轼 uy#hhCP>tVżVvDDRPEu4 vDh+Ch+CQR uPtEuvDh+Ch+CR uƺEu$vDh+Ch+CP Eu蛺Eu% vDh+Ch+CQ趻 EuovDh+Ch+CR葻 unKjjjj jP vD QRۼ vDj VPQ迼06DVh+CR& V莼uDVhd+CP }t= vDh\+Ch+CQպ u葹X+C3uEumvDhH+Ch+CP莺 uHA訹P蜹u蘹P茹E܅HDjQRM t`Uh<+CPEPDjRQPE vDh0+Ch+CQ u裸DjRV- E%}vDh0+Ch+CP螹؃ uX DjQS-E t P.MԅvDURh +Ch+CP辺upMjjjj jQ謺vD RP蓺vDj VQRw0sDVh*CP߷ ~Mԁ}?Etu5 Dh*CQ讷UԡDRhh*CP蕷4Eu*C*Ct*CPQ Dhp*CQ\边EEDDžDžXA|otYtLhWTt:MԍPWQV5t!UVjR tW WQVCu7EPȸ*M̋UQjtR E=u8EP膸MUQhR聸 EDPS,u vDh`*Ch+CQ uus覵Dh<*CRѵC]܃ PVjjSvDh,*Ch+CR蟶 u^[vDh *Ch+CP~ u=:K DVh)CQb]VjjlSxVC)C3uUEtEEMU3PVVVQRS2uD %m蠴EMUPEjjjQRPFt Dh)CQ訴]uȋ}؅Eu(CRVjjW蠴Eău.jW苶5VjjlW}VCu"jjjWN؅ۉ]uh)C Dh)CQE}uDh|)CR]?tuE?u۵EC ŵEWM3ɋ vDht)Ch+C]QE2脴 u@)C3uvDh`)Ch+CPM uu Dh`)Ch@)CQ/ vDVREuDVh$)CP  vDh)Ch+CQݳ uuu蔲u}jWeEP3ۋQU&}SWSp֊ tW:tH,tC.t>JBu>vDVRWExDVh$)CP4 JBt3ɀ:+UIQHEjjQRVPWCz;TMQγuDh(CRımEtKE3P7~9]Ћ}MVQbP@jRSPWqt,MFQ;|͋UERPFtEE3;lj}~(uQR±uHQ蘱z9} h(CEtC|MRQP  tVWòVu 谲|裲TBEȡvDux Dhx(CQ蟰DhX(CR莰Dh(CP~ Dh'CQmDh'CR\Dhh'CPL Dh)CQ;8UR蹰E u EFPu 藰;vUQR°`'C3VIكIu;"`'C+3ttuX'C3IكI;&X'C+3tKuL'C3IكI;&L'C+ 3tuD'C3IكI;&D'C+3tuʊt <:t<,t<.t AAu AAtр:+u EBERkElFPh8'CjdQ@d}vDRWPL Eu E4'CNQh('CjdR vDPWQ ؃uŭVRh 'CjdP踯vDMQRWPC u 苭ENQh'CjdRwvDE썍PQWR u IEEMvEMvD}uDWVh 'CRPDjjj P`hSQhh'CRˮDShCP$< ?hWP脮hh'CQh]vDƅu) CQhRC sƅ ƅv<.u '3I EIƄ ~;}DPh&CR E|;~PDh&CPܫ eMċEQMjjRUPQRpRDhx&CP蔫:MQuuDh(CRkEEt:Pի~-vDu$DhH&CP+ Dh&CQE u }Fu W肫;VW貫wV诬 EtVh8'CjdR苬dMvDPQR薫 Eu OE4'CVh('CjdP>UvDQRPV؃uVh 'CjdQMURvDPQR荬 u թEVh'CjdPīEM썕Q vDRPQK u 蓩EUEOuUȉEĉMvDuUDVRh 'CP蕩 Djjj Q褩hShrD-hh'ChrDDShCR?$rD< M9hVhrDɪhh'ChrD诪ZvDrDu&CPhhrDC evrD rDx<.u =rD ~rD3IrD EIƁrD~;}СDRh&CPL Eȅ| ;~DQh&CR% jEЋMUjhrDPQR軩 Dh&CQDRק G DPh%CQ fVDRh%CP褧 J Dh%CQ苧1}]EuEEtMjQptUPRҨEP辨Pj MMBPQ蓨UjHRpzdM@PBHQ>HUUHQR+EPMVQV;ujjjV VRĨvD PQ謨}$t5vDV WRP舨u DWh+CQ UERPVWojjSj jQNvD RP5 t5vDS VQR uDVh+CP MQWSڦ ]uEtDh%CR}t.Dh%CP$MQ DBPhx%CQ)|ERPV tVSŦVu(貦 DhX%CQĤDžDY芦Bt EPDQRhH%CPLE}3uMQޥEUWR补؅tWEu!Dh8%CP DQ Dh,%CR\t/lu%tuxuTu3c@uaCu܃ PWjjV譣TEP Dh%CQQDR? ut8NJ:utP^:uu3uWj WjujlV_WC}WV1W豥 lt9EthM]PQSVhEMRPQVܣ]xt1EtURS MEPBPh%CVhtEtS* MQ襣uCh$C RCCC h$CPӋuO QRVCh$C PӃW蜤 Ch'C QӋ] \Eu^`u URV轢%u8CR蠎E_^[]VjjlS謎 VC&uu1C PWjjV耎Eu2jShBhB3WjjlVVWCjjjS辑Eu h>CJMt PV薑E܋5CtiMEPQseEt h>CփEt hl>CփEt hD>CփEt h$>CփEu h>CփE؅q}GP:OQ‹#hh=CS}膐؃uh=CC]USBP襐Wh=CE ֋E 3ɅM~< u h=C֋M3Ҋ Rh=C֋ME A;ȉM|Nj}h=C֋ESH Q;Wh=CE ֋E 3ɅM~< u h=C֋M3Ҋ Rh=C֋ME A;ȉM|Nj}h=CWhx=Chl=Ch@=CWWh=CWWhCQ輆Dj;j;h1CR视D@hBCP蔆 DhACQ胆Dh?CRrE_^[]ÅuDjPjEEEXAL EuuDhACPtP/ DPhACQE踉UءDRhPACPą tMUMQjjjjRSSt'lS}u~DPw DQ^E_^[]UDVRhACP}8 Dh@CQ'tTEURVPW݈t> DQj$PEr DQ΄NDR躄ZPڄuuDP蓄u9 CQSjjV衄EЃt?t:DhPCDR聃DPp ű]u]C RVjjSuEȅt WSEċ5CEPWʆu5 DQ VjjlS VChEt h>CփEt hl>CփEt hD>CփEt h$>CփEu h>CփEWRcEGPKMhh@CQ讅E uh=CCh@CShx=C֋U GRP轅Sh\@CE֋E3ɅM~? u hX@C֋ME 3ҊRh=C֋MEA;ȉM|ċ}hP@C֋M W QRPSh,@CE֋E3ɅM~? u hX@C֋MU 3 Ph=C֋MEA;ȉM|ċ}hP@Chl=Ch@=CSSh=CSShBBuۉUEt PsPEut@DQhECPw *B BUtDh`ECRwuhehPECh{NVUUUhfʸ*hPECЉ} Jt RVzEwPwu|wPpw؅]YQEąt2hxBV^zhxBSSzDRV@zDPS4z ]uuEt CSjSQCCRjjjVvEEtcDMjQjPRu9Dh7CPvSjjlVvSCEE] EuDECu8ECPSHzPhbC VTUVRSSVhbCSSVhbCSR0]3DWhH,CPQV RPPwDQWPRPW;DhbCRP K$MEIM] DRh#CP] PxPD xPD$ DPhbCQ|PF u#PDhXbCPYP#;tSR PwDDQR #E DVPQ蟗EXwD ;uDPwDhLbChHbCRP ;ƣXwDu"DhLbChHbCh$bCPO5#PwD;tnh+CVPP ;u_O*hhCP$P;uDOWPWO PwDDQR謇u DP"PwDh0+ChHbCP1P ;uN DVQW3XwDPwDh+CRPO;u3N}teXwDPwDh\+CRPO u.N@W0Quŋ DWhd+CQN "X+C3uEXwD PwDhbCPQZO tSPNkNP_NXNPLNDGNP;N}7NP+NZ!DL!D!guE]CuuxXwDPwDh]CRP? uuUx>E̅u%XwD PwDURh\CPQAuE̅uHE̅uADh\CRl>VjCu Dh\CQD>EjPW Eu Dhp\CQ>MtMHuDhT\CR=0PCODVh8\CP=VS@]Ѓ PwDSQ?EuDSh\CR= >E8hXt PwDỦ<EQVjEEE,B؃ ۉ\u,TuDPl<WEQ4<EMPQ=؃sΊt <:t<,t<.t AAu AAt{V=[C3CjP@u Dh[CQ;DR; Tt P7>\S@EЃt P@EDh'CPuL;MVQL@U܋ERP; Dh<$CQ;Mċ4jjjWQPR<CR_^[]VjjlWEujW}jjjWEu!DhPmCP DQ ruuFC RVjjSEMGPt`'GH M UVjjlSVCW}t Wt SZE_^[]ËGP U ptdV3~RWVMPESt-~?Eu EPSLh'CSBVG ;|}E tUP3v~FM VQWS&Eu WSGh'CSU FR3 ;|}EEuE܃u WS u2WSuɡDh0mCPX  DQF  Dh|$CR3 DhmCP  DQ l_^[]ÐUL3DSV3;WuuuEuu. P ;ƣDt C@QjjjP ] EHuu}}܉U 334$C3u$HECP`:E36C 3u$HEUCP*:E30$C3uH"KM3oC3u Eo3($C3uHKMH3oC 3HEEu ECMPQ EH}ui ^ PR ؉]N PB E6.EjCRVjjS DRh#CP  M DQh4CR Dh#CP  Dh4CQ DhX4CRz Dh<4CPj  Dh4CQY DhXoCRH Dh(oCP8  DDhnCQ$ _^[]VjjlS.  VC/u jShu:jjjSLEu=DhnCP  DQ  DhnCR 3E;;j)MjAqNjARu ;hMF ;t QP } ;ljEAFu;/V} y E PV MQV3E3CPEtVjjlP~mUSSSR ؃uDVh0CPWSt8StMPQGVSuȉ}DVhLCR Et Pmt SfE|au EFPu d;u]V5uuW CU QVjjRZ DVhnCQ DhlnCRxDPg] EVjjlPx VC|E܃uMUQR} u>EMPQc u!Dh0mCRDP .E% Dh|$CQDRt S'Et PEt P Et P E_^[]ÐUV3uuuuEuuuuu܉uuuЉu؉uĉuԉuu9 E衔D;u3@P4;ƣDt C@QjjjPDSWVPNdwDu.PdwDtC RjjjP] ẺEȋEHE E4$C3u'EHECP_3Eq6C 3u'EHECP&3E80$C3uEHEnCE($C3uEHE>CEC3u%EHECEEC3u%EHECEEj(6C3u EL5C3u E.|sC3uE @E E  6C 3u0EHECCMPQ>G(tsC3uE @E EhsC 3uE @E E\sC 3u E @E Ek$C3u E @E EMLsC 3u E @E E/@sC 3u E @E E@PstDEEHEA3Pu`DP DPh#CQn @QD@QDDPhbCRGF u}u( CQWjjVBẼu+jV2WjjlVWCOu6jjjVO؅u5DhnCRDP  DhnCQV]AEMuPVvUjjRjVSuPjPjV@2PEP4MjjQjVuPjPjVUjjRP0u h sCrURHQjRgDhrCPJMQUR6uDhrCPVSVD  u Dh8%CQ Dh,%CR0E EuE;u EPdwDQRhrCPF9uuhjjjXS dwDhrCQtdwDVRUVG dwDhrCP dwDh'CQu9uu BP  dwDPhrCQ\9uu6dwDhrCRCdwDH QRdwDh'CP!9uuS dwDhrCQBtPdwDPr dwDhrCQdwDh'CR9uuEdPQVS>V'PdwDPh|rCRM3~Ed+5d+3Ɋ0 RdwDQhtrCR9MF;|ȋEM @;E GP;uu$ DQDh;CP}u3C RWjjVE3;t SV9}t#}cWjjlVWCEEȃu SV uSV;uDh\rCP h|$C DQGURdwDPMdwDQu _[tRVE^]ÐUL3 DSV3;WEuuuuĉuuuuủuЉuuuԉuu3P;ƣDt C@QjjjPDVPJE] E3H}܉}ȉu؉uU EQ4$C3u'EHECP!*E6C 3u'EHEbCP)E0$C3uEHE)CE($C3uEHECEd6C3uEHECE46C 3uEHECEC3uEHEiCEhwC3u E`wC3u EXwC3u E}$C3u Eb5C3u EG06C 3u E,?C3u E@P;EtpEHE}܋uUԡDjRPZAM؋EЍUQMRDPQR. Dhh5CP DPh#CQu U DRh4CP^ Dh#CQMDh$wCR<DhvCP, DhvCQDhvCR DhpvCP DhPvCQDDhvCRDhuCP DhuCQDhuCRDhPuCP Dh(uCQDhuCRqDhtCPa D@htCQMDhttCR<DhLtCP,htC DQ ~Et Et DhsCQWP EEt,u EtU𡔃DhsCSRjVWPJ6+u EtMDh<+CSQjVWR-4tVd}}VCuDPCu]ȋuuE C QSjjVEEątIjWV u9SCDR:SjjlVSCEt#h$CVGPVh'CVEW}uhsCVdu[tWȁuGЁu7ȁAt*PPhsCV/Jut :tDRHEt E5DhsCPEu&EuEu WVWV}u{M}QjjW\hhhsCSE uDh<$CRcuEPM jQWUSVRV}u Etu[Eu!EuEMPjjjQWV WVDhsCRDP  Dh|$CQt Vt URE_^[t PEt P E]ÐU<DS] VW}3O;ƉuuuЉủu؉uEEEEEEEuuȉuuԉuE}uCV@PDVP<_EE 0$C3uEHECEc($C3uEHECE3@{C3uEHERCE6C3uEHE"CE6C 3u'EHECP EC3uEHECEj`wC3u EO8{C3u E4,{C 3u E {C 3u E{C3u E {C3u E {C3u E {C3u E ;C3uE z;C3uE^(6C3uEJzC3uE2zC 3uEzC 3uIEEEHEXE]}S DhzCQo DhzCQDh|zCRDh\zCP Dh@zCQDh zCRDhyCPt DhyCQcDhxyCRRD@hXyCP? Dh$yCQ.DhyCRDhxCP  DhxCQDhxCRDhXxCP Dh4xCQD@h8CRDhxCP5UءDjRP7UԍMj𡔃DQjRP$ u Dh7CQ\DjRjddE HtbHt?HEMDhxCVjPQR$(t[WWDEMDhsCVjjPQRz-E܋MUh<+CVPDjQRPi+u _^[]VV}{u" DhwCQ{DRiEЅtht7CPEuhwCnCjRlEE̅th CPEu!hwC4Cj R/EEPhhwC<6W/hhwCV]MWSQE(DhwCRj0CEt*3ə+‹~TAE DE J;|EHww$ AM U}QRWSVFNE M}%PQWSV&4U E}RPWSVM U}QRWSVhpwCDP DQQMEt&UjjPWRTu0DP MPWt MQs UR& EPMQUR,Eȃ t PEt PE܅t PE_^[]ÐAAA5AUDCDV3E;Ɖuuủuĉuuuԉu؉uuuu3P;ƣDt C@QjjjPDSWVPc4] EHu܉uuЉ}}U E4$C3u'EHEbCP9E6C 3u'EHE)CPE0$C3uEHECEX($C3uEHECE(6C3uEHECE6C 3uEHE`CEC3uEHE0CE$C3u E}5C3u Eb06C 3u EG`wC3u E,XwC3u E@PEtsEHEu}eM܋DjQR0U؉EEMPEQ DRPQN IDhh5CRo DPh#CQ U DRh4CP Dh#CQDh |CRDh{CP} DhvCQlDhpvCR[DhPvCPK DhvCQ:DDhtCR&DhuCP DhuCQDhuCRDhPuCP Dh(uCQDhuCRDh{CP@?P؃uDPu Dh{CQoE DUEthsCRPjWVQ%h<+CRPjWVQ#t VjEVuu$Dh{CRDP g}ЅuE C QWjjSE̅tIjVS u9WCDRWjjlSWCEȅt4C=C h|{CP׋NQSCh'C R׃EąDhh{CP)Eu EuEu VSA=VS24u`Eu!EuMUQjjjRVS VSu!DhH{CP DQ EDh|$CRt SYt V3E_;[t PE;^t PE]ÐUHsDSVW3;lj}}Љ}ȉ}̉u}E}ĉ}}u3P ;ǣDt C@QjjjPDWP-] EԉEE33Hu}U E4$C3u'EHE<CPiE6C 3u'EHECP0E\0$C3uEHECE,($C3uEHECEC3uEHEjCE5C3u E?C3u EC3u EĉEq6C3uEHECE=$C3u E)MQhCCPC UUEEHEu}]PEPE EaE V CQVujjV\' DPh#CQ U DRhpCP Dh#CQDh0nCRDhnCP DhH#CQDh?CRDhPCP Dh?CQDDh?CR|Dh,CPl Dh~CQ[Dh>CRJDh~CP:E(_^[]ËUVjjlRC VCuCM PWjjQE܋ DjPQg(} t7D3҅RPjU tSV DPhACQE؅DEUEXAuh%h~Ch~CC 1}u=Dhp~CP:CU WjjlRH0WCMDQhPACRDhT~CPUMQjjjjRW0uQDh0~CPEԃujVh*BhBS{jjjV}u% Dh@CQeDRS bEЅt E WPE̅}O Q‹W Rhih~CVES؃uh=CCESH QuU5CRh ~CE֋E3~0ǹ u h=Cփ3ҊRh=C֋EG;|h=C֋ESHQ}EWh}C֋EE~:E u h=CփE3ҊRh=C֋EM@;E|h=C֋MSQRWh}CE֋EE~:E u h=CփE3ҊRh=C֋EM@;E|h=CWh}Ch}Chl}CWWh8}CWWh}CWWh|Ch|Chl|Cփ@hX|C֋}EȅuoEuM WQh$B u5U WRnu=Dh8|CP  DQ Dh|$CREąEuhh~Ch~CC EPh*Bh$B VEuM VQuAU jjjjjVRVEt DQjRE9Dh|$CP$DhP }uC RWjjSE DjPQE jj9h_hdC} Rsu WVu$V WjjlSWC 3vHE|PuDCu4'CPh8CSWhCSE F;rMQE7 E,C 3uFDhCPGP7uurUࡔDRh؈CP ̈C 3uDhCP릋uVu DVh|CQ MQVURVu3EujVhBjE jjjVJuu$DhPCPX DQF Et URVEt EPVEt jjV EtjVS EtU Dh(CQjVu!Dh CRDP  DhCQEV3LEEEEEEpE`UR3=NUEMWRPQV0VEUWRVqPEPV]MWQVA UWRV% uVOEEPCtMQ';vUR ;vEP;vV;vMQ;vhhdCW uh=CCuVhChCS{UBuhCScEWP3HE ~8ƹ uh=CS+3Ҋ>Rh=CSE F;|ȋƹ uh=CS3Ҋ>RhCSu h=CSVh؇ChCSEHuhCSMWQ53HE ~8ƹ uh=CSm3Ҋ>Rh=CSYE F;|ȋƹ uh=CS53Ҋ>RhCS!u h=CSVhЇChCSEHuhCSMWQw3HE ~8ƹ uh=CS3Ҋ>Rh=CSE F;|ȋƹ uh=CSw3Ҋ>RhCScu h=CSRVhȇChCSAEHuhCS)MWQ3HE ~8ƹ uh=CS3Ҋ>Rh=CSE F;|ȋƹ uh=CS3Ҋ>RhCSu h=CSVhChCSEHuhCSkMWQ3HE ~8ƹ uh=CS33Ҋ>Rh=CSE F;|ȋƹ uh=CS3Ҋ>RhCSu h=CSVhChCSEHuhCSMWQ=3HE ~8ƹ uh=CSu3Ҋ>Rh=CSaE F;|ȋƹ uh=CS=3Ҋ>RhCS)u h=CShCS VhCSh|CSh`CShDCShCSVVhCSLVVhhCSVVhCShCShCSVVhPCS@hCSzhCSoVVhCSbVVh8CSUhCSJhCS?@h܃CS1hCS&hCSh|CShTCShHCSh@CSh$CS@hCShCShCSh=CC}̋Et PEt PEt PEt PEt PEt Pt WEt Pt SEt PE_^[]Ë}̋EuoEȃuEPShBx u5MQS0u=DhȂCRDP Dh|$CQE؅t:uD3҅RPj5 tV6 DPhACQLEE؅uhhdCh~CC URVTV)uV9Eȃu VS?uAjjjjjVSV}E؅t DQjU6EDh|$CPvV@ DhP_^[]ÐUsV3EuuuuuЉuuuxuuuXuu|u艵\<Dphl,0u`u8 4uĉuuudETuHPE졔D;Ɖuủ$uu܉( uPuȉ5hwDuCV@PDVP Cj QELtE؉@ͽEuЋES] HWBQAEE \ 4$C3u*EHE CPNL 6C 3u*EHE CP6C 3u*EHEa CPt C3uhwDEoC3u'EHE CPvE6C 3u*EHECP=@5C3uAEHECPCEEhCPĻ[6C3u!EHE9Ct 9 d 9LuhPV۪P̪]QhԚCShRV舲P虪PhCSߩjVAh@hCP!,MEEQVbPWhCS蝩]3]~:EM3ҊRh=CQwփ uEh'CP\F;|ƁyNFuth'CV7hCV)UMQHQuWh`CV 3]~:EM3ҊRh=CQփ uEh'CP˨F;|ƁyNFuth'CV覨hCV蘨UMQRWh8CV}3]~9MU3Ph=CRZƃ <uMh'CQ@F;|ǁyNFtUh'CREhCP S蘪}] 9\uPUEQRWP59pu,h,CSQPS2h'CSۭ9huh CSQB9HEMtQRPW路MQۭPiPh|rCS9M3?t+‰EU荄5t+3Ɋ0 RQhtrCSMF;|9`DhCR軦u>EMthCPXQ DVRPQ<ES}]>tu肨E>ulEE܅uhhCh~CC W4URV螫jVrVW¦PW襧$hjHR腧NE@QPBPY"MQW2 Et"W~jWѭWѭ utFjWjjjWWRVPЧMWQRV踧8EMPQW蝦 ~)9EDhCREt4MUhԙCQ@RDjQPR|EЅ}]Ѓ;tuĦE;u讦EE܅uhhCh~CC ]3SEEkEPVթVAMjWQR蠤 uDh sCP/EtE.|3ۃEu}3у |3IyhGhCW. u DhșCQ躣|Wu@URVe t<.tAAuWhCV<WhCV+PV(8 jPV.؃ t5jSGu DhCQ%URSjVCV螥SGEEr}]uWPh@QhwDuR(EPSu Dh`CQ脢S$PW URWjHRңE@QPBP覣Et"WH~jW3W3 tBjW~jjjWSQHVR5EWPQV8tUERPW tEQuuDRVEu EP}]I; DhCQXUMhCRtQjRPDP Dh`CQɠtuТE>u躢EU}RVW腥Vs(EuuSV٥SV覡]Eo90ugEWP{XWjW\ȉE3Q讠~'UVRߠPhCSEFP臠;|ًMQEȋM @;Eo-Dh$CPǟ DQ赟 h%CDR袟DP葟 d Dh;CQKDh@CR:(3;t[V4C MEBQHQY }Uh$CR(EEhCPu9utuuMWQwu$EW;tURߦ\EPNusDž4aCDž 薦ERPh:B ;_ DhCQODR= h|$CDP.E_[t DQjޞUREP؞MQϞUR辝EPMQ覝UR蝝EP謠MQ裠ROEP@xh6BQ_Uh6BRQE<^t P Eԋ]ÐUVW} WtlEtDhHCP13_^]WjPŝ DPjQ%V衝PW賥DPVhCRߜ_^]ÐUDVW3}EuЉuEuԉu܉uu؉uu;ƉEȉuDE;ƉEEĠXAu3菜P胜;ƣDt C@QjjjP]DSVP ,IP=;}uDhCR] EHE($C3uEHECEC3u ElC3OC39;C3u E"C3uEHEFCE6C3uEHECEC3u 趣EC3u 軝EC3u rEhC3u PELC3u .E06C 3u0EHE|XKMEEHE2u}} URhCCPC t E DhlCQƙDh(CR赙DhПCP襙 DhuCQ蔙DhPuCR胙DhCPs DhvCQbDhpCRQD@hHCP> DhtCQ-Dj;j;h1CRDhCP DhОCQ0 E܋ DURjPjQ"uDh7CR躘E؋ DjPQ0]ԃ uOC RSjjW觘DjPj  uDuD7uV DhACQL@SjjlW`SC2tVLDPhACR E DPhCQ NEEЅtD1URVMUEPVQRzVߙ1EuPVߙUEMQVRP輙to DQju3NQ~ JuDPPhCR&EUM̉E̋EQh"BjjRVP]ȝ,tE3MQ/E;[t PE;t P覗}E;t PI;tDR蜖_^]ÐUӦE*MuE.uE+uM uE VuEjNPQVjjj RU^]ÐU,cDV3E;Ɖuuԉuuu؉uuuuuu3 P;ƣDt C@QjjjPەDSWVP%] EH;ƉE($C3uEHECEL6C 3uEHEgCEC3uEHE7CE6C3uEHECE`C3C3u 腝EC3u 芗EkC3u DEOC3u "E3C3u E8-KM@EEHEp} E܋ DjPQiE؋ DURjPjQ uDh7CR詓,ϓPÓWjjlVu譓udWC3DPeE;t PǓE_;[t P'E;t PǕE;^t P輕E]jjjVEuDh 6C3u EHE C|wD 6C 3u*EHEr CP諻|HC3uEHE6 CEC 3uEHE CEpC 3uEHECE@C 3u'EHECPߺEC3u EHEmCwDC 3u'EHE;CPtExC3uEHECElpC3u EHECwD:hC3u EC3uEHECE\C 3u EPC 3u E E@C3u E E4C 3u M@rC3u MTC3u EHECtwD"C3uEHECE C3uwDC 3uwDwDHC3uwDC 3uwDi4cC3uwDHC3uwDRD"дC3u4EwDHE~CPCRDĴC 3u]EwDHE8ChRDhRDhRDhRDPCDhCP"C3uwDLC3uwD+C3u E C3uwD,LC3uwDC3u E|C 3u EtC3u EqhC 3u ES`C3uwD2XC3uwDPC3uwDDC 3u M8C 3u M,C 3u M C 3uE@EvC3u &EWC3u E8C3u ܄EC3u跄EEC 3uwDC3u*EHE8CP(ClwDC3uwDuسC 3u EHECwDCC3u EHECwD6C3uEHEwCE̳C 3u!EHEGCpC3uDžxC3uEHECRD^C3EHECwD+EHESMQRHEHE63#萂wDDjRP MEUQMRDPQR謹 Dh7CPA DQh#CR( DhCP Dh'CQDhQhXCRDh,CPރ DhCQ̓DhCR較Dh|CP謃 DhآChXCQ薃DHhȱCR肃DhCPr DhCQaDhCRPDhآChTCP; DhCQ*DhܯCRDhCP  DDhPCQDhCRDhCPԂ Dh|CQÂDh0CR貂DhCP袂 Dh8CQ葂DhCR耂D@hЬCPm DhCQ\DhtCRKDhHCP; Dh CQ*DhCRDhīCP  DhCQD@hHCRDhCPԁ DhCQÁDhCR貁DhCP袁 DhtCQ葁DhPCR老Dh,CPp D@hCQ\DhCRKDhCP; DhCQ*DhdCRDhCl C3uwDC 3EHECC3u E8C3u EC3u EC3u EC3REC3uEHE$CEC3uEHECX\6C3uEHECE/̳C 3EHECEЋEHE<3wMMUDjRPX ;PX;ljT Dh`CQ$O DQh#CRO DhHCPN Dh'CQNDh CRNDhCPN DhCh|ChCQNDh|CRNDh=u'jjjJW>~DhtCR?Eą PW>P>OM̋U܋]SRW=VW=*$AU+։]U}3;E EE EwDhdCPz wDhTCQ>3EEEwDhDCR>|E ]~vE ]`EtZEMԋuЋCV QRCPC RM+ȉuЅMEEPW =PM+Cp Ct{]hSQCPC 33~ < uA@;|F|&M    Mu IF Hy݋}t9hKhhChCCEh PQCPC]̋ wDuJVE_t P=u̅th V>V= uth V=Ve= uth V=VJ= wD^tP;wDE]áDP~: IJ DPhĽCQe:U SRJEPJ DPhCQ8: wDhCR:IPDhCP: t DQcwDh`CR9UDh`CP9@I DPhCQ9 $wDhCR9DP9W8jW8P.IWx8PIE Dh;CQB9%A4A;A+AcAA|AAAвAAAhAAUVuWjV7V:8 t4jjjV7utM_^A3]ËM3_^A]ËDhCR83_^]ÐUHESVuW3;lj}&E }P7؃hCVEB8S8 hQWS8P8 P8RWhCV7hPWS8Pn@ P8QhCV7wDtWS~8PV8SG+8;ehCV7U R5 }hCVg7wDtEu WV8hPW7P7Qh4CV7hRW?P7Ph(CV6hCV6M Q;6}WE7~vhCV6W3+7 ~j}SWZ7hRP$73IQPV7jh'CV 7MCQ60;|hXCV36] hRSq4 h(CV63ۄ]th<:uOù RD+PQV6E @E3ۙICu'CjPVa6 jWVS6 CGGujh'CV:6] S4PR9PS4PH9PhCVO5}] Cl$CuCPV,5Sv3Sh3PS4PhCV5t#W7W>PhCV4W7} jjjLW34'CuCPhCV4W 4W3E t S3rCPhCV{4E t P3rCPhCVU4W2PV43hCV=4E t P3jjj VB4_^[]ÐUMSVEWPjjFQ2u hCV:EuhCV :_^[]ÍUSRjW= u"hhCV9EjSPV0=3_^[]h% DhCQ-%Dh'CR%DhCP % DhpCQ$Dh'CR$D@hCP$ DhCQ$DhCR$DhCP$ Dh'CQ$DhCR$DhxCPs$ Dh8CQb$D@hCRN$DhCP>$ DhCQ-$DhCR$DhXCP $ Dh$CQ#DhCR#DhCP# D@hCQ#DhCR#DhCP# DhdCQ#Dh'CR#Dh'CPs# DhCQb#Dh8CRQ#D@hCP># DhxCQ-#DhDCR#C DVhCQ# C&txjjhhdD+jjAhdDF+jj@hdDF+jjheDF +jj@h eDF+N<ɉFtNtN t Ntu3uK&jjh`eDO+jhhxeDF;+jhheDF'+jjhxfDF +jhhfDF+N<ɉFtNtN t Ntu3u%jjhgD*jhh(gDF*jhh(hDF*jjh(iDF *jhh@iDFm*N<ɉFtNtN t Ntu3uRhjD+PhjD+QhjD+RhhC+PhhC+QhhC+hCjRv+HhhCjPU+hCTjQ<+hCjR#+3\hC󫡔DP` ]0 hWVvu]^ Dh|CQE~DtPDPhhCR!DP u W6_^3[]Ë_^[]ÐUUSVW< t< t< u FFu>C;|I xhhCPQKE;lj{}@DK;|UBUt<'t'<"t#t< t< t< t FFuN1>u)N)ȋF|DG8t;tFFuFFME_^[]_^3[]US] VWjjSKP<uh%CVWVW jjSP hCVWVh'CVxW(3_^[]ÐhC*h`!BP~D~Dh!BP ~Dh"BQ~Dhp"BR$3ÐUEPPЃ]ÐUVu WV}tGWt:V~-(Wt8tPVWy _^]VWZPZЃ_^]ÐUVu WVP}t CWjWQCCRWjjS EuEWSEwVjjlSԋEVuPhCVFV:D3N;ljE)U(QR-}h(GPS t}hCCGMVQjE> EtRHtKRQh4aCC u5}MUVRAEP EtqHM@bUhCRHOuWh"BWSE5uMUEWPWWWQSR~ EMPhdCQ EuuhHCVV Et P?t S(E_^[t PE]ÐUE VW3WPuMUQh CQWjjV腾}EuEP贾EWjjlVLËUWRhCSSEPh"BjV肾3Wr~6SW覾tMPQCWC?;|͋uthBWft VE_^[]ËURhdCSs hCSeSY UE Eu]VP E Vu袽~oSWE PVѽx<-u2<+uGhChCtQW,CtCF uEu EFPu 8;u|_[h BVaE^]ËMVҋ9#9Vۋt Љ#Љ멐UE Eu]VPE Vu貼~oSWE PVx<-u2<+uGPCPCtQW,CtCF uEu EFPu H;u|_[h BVqE^]ËMVҋ9#9Vۋt Љ#Љ멐UVu W=,Ch0CV׃uE_^]h(CV׃uM_^]h CV׃uU_^]_3^]ÐU 3VW}3;uE ;9uSPPE u4EM PQ^PEjSWrt3}t@VWUVWEURܿjSW? uӋEjPW t"uM FQu診;tuU hBRŹ[_^]_^]ÐUE SVuW23t PVEȁuu-UPPRAWVƿh'CV軿W _^[]Äth'CV螿EPEWPV\h'CV聿_^[]ÐUVWr?PW2tvu jtjVjPuEVhCPGjjjPPWt-ujt3jVjPȸu0MVhpCQ覸 Ws3_^]jjjP蔸D_^]ÐUS] V3W*C3uMhCQ=__^3[]SulhCt:jShCV"tjjhCV u V_3uuShxCV÷V跷3_^[]ËE}tjWjjV~DjjRjhdCVhV u!hLCWdWXV3_^[]VTPh8CW<V_^[]ÐUVu u 5Dt2<jjV, uhCVV۶ 3^]ø^]ÐSVW&؃3IhhC VVSWcVhbCWQVhbCWE0_^[ÐUE MSVpA:u tP^:uu^3[]^[]ÐUcVW3螻S*PEuDPٵ~]MSjjlQE u SCOt!jjj@WtVW<uDh8CRnt Et03E[t P躵t V۷_^]ËMhPVQ\uDShCR jVuDhCP뀐UU S33V;W]u uI}I3ILu|Dh|CPnE_^[]ÅuhVQ RVhtChRVPJuDPxQjjlVURCQEjP苸؃u DhHCQ軳'SVQh'CVڹEEt3ۅt Vct SE_^[]ÐU$SVuW3}IكIك} IуI;~B|Dh|CP3_^[]ËM QVhtChR衴EPVhtChQ膴URVCHC0=DC׃8t׃8uoV@Ct׃8uVQӃDVRhCPFhCCV@Ct׃8u VQӃ_^3[]ÍP@C=DCt׃8uQVӃRDRVhCP±hCC3_^[]_^[]ÐUSVW}3ۅtֳu_^3[]jjj@V衽tE tPVtu Vz_^[]ÐUcSW3:P.؃ۉ]EuDP_[]VuVjjlS.VC DVhCQ謰S聱^_[]jSݼ؃ VhChR9jlEPQVS 2E~ RPDhCP+V 3hhCja u Ch8C@QCUE _3ۅttShbCjV跰 t%ЃIw3Ɋ?B$?B3t Vut S]SJ^_[]Ö?B?B?BUVuh0ABhABFjjP6u(vNVFQ DRPh0CQ軮3^]Ã>tHVhABhABh@BjRu'vFNVPDQRhCPn3^]ø^]ÐUE39V]ÐUE@ 80u H@0tPm]ÐUE@ 80u H@0tM SVq >0u NF0t:u tP^:uu^3[]^[]UEHQ]ÐUE MSVpA:u tP^:uu^3[]^[]ÐUsSVWKP?EuDP3_^[]Ëu3] IуID =| Dh|CQ躬3_^[]VhChReSVh|ChPMSVhtChQ5}RjjlWwH$VCDVhCP43_^[]Ë]KQWa~SWz9P-RjjlV1PCDQhCRī_^3[]Ã;X+Cu)CPhdCV蝫V_^[]ÐU$ûSVuW3]IуIу} UIуEI;~Ѓ|Dh|CP3_^[]VhChQ軬} WVh|ChR蠬WVhtChP般SVhtChQpLSVh|ChRUCEPVӃ=DC׃8t ׃8V@Ct׃8uVRHC DVPhCQhCCV@Ct ׃8VRHC3_^[]ÍQ@C=DCt׃8uRVHCA DPVhCQhCC3_^[]ÍE܍PQӃ׃8t ׃8HCR@Ct׃8uPQӃ. DRPhCQhCCR@Ct׃8uPQӃR@Ct׃8u PVӃV@Ct׃8u VQӃ_^3[]ÍR@Ct׃8u#HCPQӃHC DRPhCQhCCR@C:_^[]ÐUVutFt PV3^]ÐUME t# ЃIw3ҊGB$GB3]ø]ËGBGBGBUCS]VW3hIhCFV(FhhCVEhhCVEhhCV}M30;ΉUuu9u;;;/tDhdCPDC28UZU+׉U 2t5\u P@uDh@CP=t(PA@uˋMDQhCR˥ \@A8tىt;\u P@t/t+u}uPA@u@UABUtU9"EEEu]΋++QuDRhCP ? 79uDQhCR 3RUjjQM QPR脦tWEM@;E|}W;EP2MQ)UR E_^[]áDhjCPo}MQ8t WEt PզEt PŦEt P赦_^3[]ÐUS3SEEEEVWcCM3ҋYuPuEEjS©EuMShCQ蝣U E~$C 3ukuEETSί})MhCQAUEPP萫EEC3u EC3u EPC 3u E@C3u E C3u EnC3u ESC 3u E 8C3u EC3E@}u?tt P͡PuOu9Et PQ+Et PREt PPEM 00ƅt}++Љ_^[]_^3[]U裱SVu3;W]uCS@PkE} W趭WE觭CuCPh`CVMQ{hTChDCVߠ;t8h'CVWQ ~.SW腡jPV4WC3;|h8CV˦URh0ChDCVwt:h'CV蛦S3 ~.WSjPVʬSGɠ;|h8CVaEt V臠_^[]ÐUSSVu WV軨V蹨VE 褨 hPS}PnDQWhCR譟]uD] S<PDShCP舟~D;|~D 3~DF\ 3ɊPB$PBF`hRP躧P˟DQhCRhDh,CPN`BDQRiDh'CP4 Dh CQɞV`HDQRP4 Dh'CQ衞DShCR茞 _^[]OB"PBVPBPBUSVW} ]jWS˝ 'DWh8CP+ DQ3_^[]ËuujVS腝 'DVhCRDPٝ3_^[]SKu DhCQ距3_^[]_^[]ÐUE VtsuPVh|CURV$h`CDP\ DQJ 3^]V辜uDhCR*3^]ø^]ÐUS]VWS蝩uE_^[]ËE }=uEMWWPQShC=u$EMWWPQShCV贜UWRV襣(_^[]ÐUM V%t`C TCuHCt"EP DPVh@CQF^]@t@W8Cu0CuV›PV貛DPWhCR_^]tIEu"EP茛 DPVhCQӛ^]}URhPDVhCP谛^]ÐUESV4'CWuECuECE }=2t$ȃtu(ECEC#EC=t,ECaCv[]3Ɋ wO$WBEC^|CtCr-E 3ɊK3CE L9w $WB`C}EMVu RUWRPQhDCV蚚 vUh@CV舚3ۅv3uvh8CVkE3ҊRh0CVT C;rh'CVAjjj VV_^[]þCdCZCPCIC?C5C+C!pCXC @C=t=t}=t =MtHtHu!E4CVE,CEC/CM3Ht Hu CC3tCAdj3ɊDXB$WBCQCGC=C3C)CtC`C DC,CCCCCCCCCClC\CLC8CulC_M3O3ɊXB$XB(C6C,C"CCCCCCxClC=TB&UB0UB:UBDUBNUBXUBbUBlUBqTBUBUBUBUBUBVB(VB2VBhC7XC0HC)8C"$CCtdCCM ɹCuCVuW}WRPQhCV蜕EWPV荜jjj V評4_^]ËYB YB'YB.YB5YBt$V. jV%MȅۉMtE_^=[~ D]ÐU胙DuODtFEu8hPÕtP•t ]ËM h4CQވ3]ÐUDSVW33;lj}}}}}u.ψPÈ;ǣDt C@QjjjP蝈Muٸ;ȉEU HC3u C3u EC3u EwC3u E\HC3u EAl;C3u E&HC3uQ]]]]]EM@;E35C;tS3=Wu1 PhCփ 4DhCP=_^[]PhtCh`Cփ9}tjӐPhCփ 9}tj輐PhCփ 9}tRhTC蚐PhC臐PhCtPhCaPhCHPhCh'Cփ09}tjNPhCփ 9}tj7PhCփ _^3[]ÐU(蓖DSVW33;E}u}؉}}}܉}u.BP6;ǣDt C@QjjjP] EEEH} Em4$C3u'EHECP赳E6C 3u'EHEZCP|E0$C3uEHE!CE($C3uEHECE5C3u E @E EccC3u E @E EE$C3u E @E E'ȵC 3uaEHE|kKMEHEu3艄3|PpujDR+E_^[]ËDRh#CP mDmD DPhbCQF uE_^[]Åu1CPVjjWEu5jWhXBhB]fWdsEV]hlDRS EMPQVasu_^[]VSsuV8s3_^[]ËVh\DRSVsE DPjjjQWSgWh0_^[]Ê]tDh4DReDFhPrtt_^[]N}hlDQW*VPk=V_ru_^3[]VWTVW/fVd_^[]Et Dh DQdV]hlDRSv3V=e~wEMUPEQRPWVaePS+nVGe;|_^[]Ë DhDQWdDRPj Dh'CQ8d_^[]ÍIBBBȊBȊBFBUW} uEMPhDQc _]WlduUERhDPc _]ËMVuQhCVcWE(dTS} URWOdP[ihDVlcuQVihD SugPhCVCcWRcGjPcʃtxItAtRhDVc @PQRLpWhCVbWjev@3@ۉE~U3Ɋ QhDVb G;|h'C9@3@ۉE~U3Ɋ QhDVxb G;|h'ChDV^b}E GP}b;[^_]ÐUxsrDSVW33;lj}ĉ}}ȉ}̉}}E}E}}ԉ}}}}uCW@PeDWP蠪~ EEahM Y8- D3uJCt-CPeE؅u QhDDRDa EEt0D3u'CtыCPbEu‹ QhD뢿4$C3uCtCPE닿6C 3u"CgCP輎EWD3u E9PD3u ED 3u ED3u ED3u ED3u E6C3uCCEx6C 3uCCEMC3uCtsCE&0$C3uCCE($C3CCEE1 DhDQ^Dh#CR^Dh|zCP^ DhxDQ^DhHDR^DhDP^ Dh\zCQ^DhDRu^D@hDPb^ DhDQQ^DhPDR@^DhDP0^ DhDQ^DhDR^Dh|DP] DhHDQ]D@htCR]_^[]ËEЋ DjPQHM̉E UERUPDQRP u Dhh5CQ]_^[]Ã}uE؅uE uąt5ht7CV]؃u3DVhCR2] _^[]áCjPL`؋EttUDh|DRXHt)HtHthdD! Dh<DQDhDR hDDPxXVeE܃uMUQjjjjWR|ZuNEWPeW[MQYSXE t PZEt PZ_^3[]ËDh DRW_^[]áDh DPW_^[]ÐULgDSVW3333;MEMMMMM}ԉMMЉME[CE\ CMȉMM]܉u؉MuCQ@PqZD3QP U EH M E0$C3uEHJM($C3uEHJMf6C3uEHbJM96C3uEH5JM  D 3uEHJMPcC3uEHJM D 3uEHJMC3uEHJM[$C3u E=6C3u E"(6C3u EEEHE.EM DQh DRUDh#CPU Dh<4CQTDh4CRTDh DPT Dh DQTDhp DRTDhH DPT DDh$ DQTDh3CRyTDh DPiT Dh DQXT]܋u؃ ]܋u؋}rTEЋ DUjRjPQtuDh7CR TpE̋ DjPQ肛M `C3t҃} DhCPEPj#jRQYqaUȋ؅t3IQRBPIa VS9aVPVS&aSaEth7CPSE Cj QaVEu$h DDRSDPR iWh DPRWUHt hhCWjS CjQUEuh| DjSMjQW}W`u h` DnMUQRWxS u)E DPh@ DQ`RDRNRjPZW؃u h( DEth7CPR}Cj R=UEu h DEu SW_SVEt"VSV~pDh DRQEt VWSEUR{RSVEPQMQQRVUTE_^[t PSE]h DDP@Q DQ.Q 뛐U츘caSEEЋE V3E D3;Ɖ]EhCE7Cuuuu|uȉuԉuuủuuuĉuu܉uuu؉uE@uuuhplutuDžxuuEu3PP}P;ƣDt C@QjjjPWPDVPMW; U 8-zC 3uEU zC 3uEU ;C3uEU e(6C3uEU ApD3uEU C3u>RU EU C3uWU EU hD3u\U EU \D 3u\U EU }TD3u\U EU UC3uLWU EU -C3uWU EU C3uVU EU 5C3uE EU HD 3uE EU 4LC 3uE EU n<D 3uE EU ID 3uE EU $4D3uEEU (D 3uE$EU D 3uEEU p;C3uE EU D3uE EU iD 3uEEU CD 3uEEU 6C3u@Bt EU tU EEU C3u/BtU MU EU 6C3u BtՃU lU XD3uBtU MU )D3u!BpU EU 5C 3u!B=U MU D3u!B U EU D3u!BU MU ]@{C3u!BU EȉU *6C 3u0JBnE QExU xU oC 3u$B/U |U C3u$BU hU |C3u$BU pU F0$C3u!BU MU 4$C3u-JBWE R.wU EU 6C 3u-JBE PvU EЉU ($C3uBU MU eD 3uBU MԉU 5DURMPQU jR2uU EU U M]:EuDhDPGMEwDhDPG Dh#CQGDhlDRGDh@DPG Dh DQGDhDRzGDhDPjG DhDQYGD@hDREGDhTDP5G Dh0DQ$GDhDRGDhlCPG DhDQFDhDRFDhhDPF D@h4DQFDhDRFDhDPF DhDQFDhlDRzFDhDDPjF DhDQYFDhDRHFD@hDP5F DhDQ$FDhHDRFDh DPF DhDQEDhDREDhpDPE DhTDQED@h4DREDhDPE DhDQEDhDRzEDhDPjE Dh@DQYEDh DRHEDh DP8E D@h| DQ$EDj;j;htCREDh8 DPD DhACQDDh DRD0~u6EEȅ Dh DQDEu:Dh DR~EE DjPQ DUljRjPQy u h7CEt>t D3PQj$ tW'DPhACRCEtE$EMt7CtyE}uE CyE C}uEu]EuQEDE }t; Dh DVjjPQi|PWCE E uŋEt*u%Dht DVjjPR"|E|t4hCVjjPDP$E܅u DQBo}t9uDDh DVjjWR{EuDPB/u Eȅuu;EȅuEt-Mxh` DVQjRPDP~EąEt2MQVB}u/DVhCRB CjP&E}Et2MQVkB؃ۉ]u2DVhCRA XCj PD؃]}uAphDQRP8 E̅ABEt PQqAEEu3MUEQRWP3Ou Dh< DQu+E@t }uEM܋UPEWQRPN벋Eu MQWN'ujjjWG@jW Guu h D'Eԅ[EP@Mht7CQA E؅6UԡDRh DPI@ EEu(UEMRSPQVNh DEM؋UPESQRPVM Dh DQ?UERPVMEtJh7CV=@؃tIW3 @~VWT@PS@WF@;|S?W?E DVh DQC? Eh DuVSfEEEtPh DS> EtQht DS> EtRhd DS> EЃuEPWVSLERuVSDE:uVSDE" Dh@ DQ h DDRZ>E_tDPjEt DQ&>UhBR=EhBP=E^[t P=MQ=j=UR=EP=MQ@URDEP'>MQ>UR>E$t P-@E]ÐUVu WVjjWjV>y~8h@hDP5 EXjQWjV>?EuhxDS8EhDS?2MȉM}uhxD3EI;~3} 3UIʃN~h'CS1hxDS8EU RhbCS1M ȉMCEuDPE PhDS1hxDhxD3hDSu1Eu hDMthDS\1EthDSG1Et/thDS)1EhDS1Et/thDS0EhDS0Et!thDS0WhDS0 EthDS0h'CS0uăEM Q 3E3;lj} t P2}UWWRj Vm<;ljE E~h'CS/0EEhпBP/E t P2Et P2Et9Vk9 DQ/uUFuRP0;dEDP/MhпBQe/UhпBRW/EhпBPI/E_^[t PJ0Eԋ]ÐÐUS]Vu>u"EjkhDP2 u^[]W>3} Iу_I;rMjwhDPR9u^[]À8t QhDP0 E RPQr0 ^[]ÐU >E SVWP/E}MhDQo._^[]3ɅMU QR/h;CS8CEu@PPESPN:uwuShDV.V.MEA;ȉM|_^[]Ë+ӁRʋȋEjMƄAQRP9tMShDQ- 덋UhDR-_^[]U츨=SVL $@ED3;WuuEbCu܉P|WjjvV3WWjeV~ ; DhDQBDR0 V WER ]uuE؅}ЅuhDjjjPDPUEu DhDQ UDh$aCjjjRPUEEt) DhdDjjjPQ], DhLDjjjjWRYE NDh$DP/33WWjeV<V%XhQVuPu jXhDRC u.X< t5< t1XhPV U DhDQ?jVhBBh~B*uDhDRVDPE މ]Sj9*DX󥤋u؅]jS;$XPQVSuIpu&|uEuEԅux DhlDR Eԅt jjS) phuhDht DjjjPRhS؃ۉ8t,hXDjjjPDPd[DK D DhDDjjjjVQV0 `RWPEVSP(w|X}ttMjWQ( t-h CSNWVhBVxtSM>M3M(Mu6jPhuQVj@uU3R3] 3'EWj'\EPjP"}'jj9EEt)(+QjE M3ɉEUPR2'P&'VW'lVRPPP&3P󫋅lP uh@DhNh0D& Gu h@hCyWȉE܉ W ERjHQU܋R7uE MPQjjjVSE&V}3I~|1\u +닍MUQRMPQ7tNUEMRPQ |RtU DPh0DQ Djjj R Dh/DPxEEE3;t P D;tP45DE;t PE;t P jo:vk`VTI DQ7D ;tPC5DUR0C^US]3Ƀ Vu t t1Dl't Dt1DDD^[]tDu0D";t0Dt0DDt"EUPCRVSQ@h0DPC^[]ùp0DӐU CS] VW8}+uEEPVFtWSP_^[]Ëjh\2DQC u\CP R؋MQVEuRPhCST S)_^[]ËT2D3 P2D3H2D3D2D3,2D3+ 2D31D3PDh1DP Dh1DQTnD3;Ɖu PnDƻ3FuDh'CREU ;tM؅ɉ] uDh'CPu Dhp1DQuDh01DRG DPh(1DQG ZDhCR_^3[]ÿ,2D3u 2D3Ã Cj QTnDt%TnD9^uRhCW< F uW3_^[]_^[]ÐUUVu ;t+^]ËvBS:u tP^:uu[3^][^]ÐUE UjHBQPC ]ÐUEHQ]Ð%,C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%(C%$C% C%C%C%C%C% C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%|C%xC%tC%pC%C%C% C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C% C%$C%(C%,C%0C%4C%8C%<C%@C%DC%HC%LC%PC%TC%XC%\C%`C%dC%hC%lC%pC%tC%xC%|C%C%C%C%C%C%C%C%C%C%C%C% C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%C%|C%xC%tC%pC%lC%hC%dC%`C%\C%XC%TC%PC%LC%HC%DC%@C%<C%8C%4C%0C%,C%(C%$C% C%C%C%C%C% C%C%C%C%tC%pC%lC%hC%dC%`C%\C%XC%TC%PC%LC%HC%DC%@C%<C%8C%4C%0C%,C%(C%$C% C%C%C%C%C%|C%xC%tC%pC%lC%hC%dC%`C%\C%XC%TC%PC%LC%HC%DC%@C%<C%8C%4CDQ=L$r-=s+ȋą@PUjh`2DhCdPd% SVWeejCY D ăDC DC DCȃD=rDu hCCYh PDhPDDE؍EP5DEPEPEP|ChPDhPDLxCMuuu0EP0CE MPQYYËeupC%tC%Chh YY3%C%CM f i X OV : w   z 3 2 ~ Q   & \ S W  EObk_gaf^^j_kiltq |{zu * ,  P TSr 9{V.+q,\4N]u o$ B%vzRk I{ mucC; YW9mh Eb`C Yz nA^]@x_Z9 f  ?X< = ^ P OC0M k+S?6<CL !" !>xOg c ;Ji% ; x % F ~  / uk   `lt]mw8  | [S=C5;Dj?H l76B  t 0 X0NQn_W G/Lsf VM7 @ ` | H s  {{ 3    !mw 4z e Pd ~ebY"\ev S o + v`V rkT l z ) e 5:Up z - R< R. d ` N (c UF ] B. c[  f D H d ) L a 6   M Q   h y P T D } V ] Dm H5 > t  ! | O p % & Q@@@@@@@@@@@@@@A AA"A*A4A>AFAPAZAdAnAzAAAAAAAAAAAAAABBB$B.B6B>BHBRBZBpBxBBBBBBBBBCC(C0C:CDCNCz4 b&(+<8$nqt I v%wZV;`y7!1K-*SR? MO}^Hl:#x=AN0#"psJ47 3qts o.QNError loading untrusted file %s %-10s %s recognized usages: cert1 cert2 ... [-engine e]usage: verify [-verbose] [-CApath path] [-CAfile file] [-purpose purpose] [-crl_check]Error loading directory %s Error loading file %s -verbose-help-engine-trusted-untrusted-CAfile-CApathOK %s: stdincertificate fileno certificates in file, %s error reading the file, %s error opening the file, %s rmemory allocation failure error %d at %d depth lookup:%s %s Error writing output Can't parse %s type OBJECTNULLError parsing structure Error: offset too large '%s' is an invalid number Can't find 'asn1' in '%s' defaultasn1Error loading config file '%s' Error on line %ld of config file '%s' problems opening %s wb -genconf file file to generate ASN1 structure from -genstr str string to generate ASN1 structure from ASN1 blob wrappings a series of these can be used to 'dig' into multiple -strparse offset -oid file file of extra oid definitions -dlimit arg dump the first arg bytes of unknown data in hex form -dump dump unknown data in hex form -i indent entries -length arg length of section in file -offset arg offset into file -noout arg don't produce any output -out arg output file (output format is always DER -in arg input file -inform arg input format - one of DER PEM where options are %s [options] outfile unable to load EC parameters from file Certificate does not contain DSA parameters unable to load DSA parameters from file Error getting passwords -reqexts-extensions-set_serial-days-multivalue-rdn-subj-no-asn1-kludge-asn1-kludge-x509-text-subject-reqopt-nameopt-utf8-nodes-verify-modulus-newhdr-batchdh:Certificate does not contain EC parameters ec:dsa:rsa:-newkey-rand-passout-passin-keyout-keyform-config-new-pubkey-key-outform%s%s(%s)= HMAC-(stdin)Error setting digest %s Error reading signature file %s Error opening signature file %s rbkey fileError opening output file %s (stdout)wError getting password ripemd160mdc2sha512sha384sha256sha224shasha1md2-%-14s to use the %s message digest algorithm md4-%-14s to use the %s message digest algorithm (default) md5-engine e use engine e, possibly a hardware device. -hmac key create hashed MAC with key -signature file signature to verify -keyform arg key file format (PEM or ENGINE) -prverify file verify a signature using private key in file -verify file verify a signature using public key in file -sign file sign digest using private key in file -binary output in binary form -hex output as hex dump -d to output debug info -c to output the digest with separating colons options are unknown option '%s' Invalid PSS salt length %d No signature to verify: use the -signature option -hmacetaonrishdlcupfm-fips-fingerprint-non-fips-allow-d-binary-hex-signature-pss_saltlen-x931-prverify-sign-cout of memory .\apps\dgst.c%02x:Error Signing Data Error Verifying Data Verification Failure Verified OK Read Error in %s bad input format specified unable to write DH parameters return(dh); } return(NULL); if ((dh->p == NULL) || (dh->g == NULL)) dh->g=BN_bin2bn(dh%d_g,sizeof(dh%d_g),NULL); dh->p=BN_bin2bn(dh%d_p,sizeof(dh%d_p),NULL); if ((dh=DH_new()) == NULL) return(NULL); DH *dh; DH *get_dh%d() { }; static unsigned char dh%d_g[]={ }; 0x%02X, static unsigned char dh%d_p[]={OPENSSL_malloc.\apps\dh.cDH parameters appear to be ok. the g value is not a generator unable to check the generator value p value is not a safe prime p value is not prime unable to load DH parameters -engine e use engine e, possibly a hardware device. -noout no output -C Output C code -text print a text form of the DH parameters -check check the DH parameters -out arg output file -outform arg output format - one of DER PEM -C-check dh->length = %ld; { DH_free(dh); return(NULL); } static unsigned char dh%d_g[]={ }; static unsigned char dh%d_p[]={#ifndef HEADER_DH_H #include #endif .\apps\dhparam.cunable to load DSA parameters This is going to take a long time Generating DH parameters, %d bit long safe prime, generator %d Generating DSA parameters, %d bit long prime %ld semi-random bytes loaded warning, not much extra random data, consider using the -rand option the random number generator - load the file (or the files in the directory) into numbits number of bits in to generate (default 512) -5 generate parameters using 5 as the generator value -2 generate parameters using 2 as the generator value -dsaparam read or generate DSA parameters, convert to DH %s [options] [numbits] generator may not be chosen for DSA parameters %d-5-2-dsaparamSalted__OPENSSL_malloc failure %ld bytes written:%8ld bytes read :%8ld bad decrypt iv =key=%02Xsalt=Error setting cipher %s invalid hex key value iv undefined error reading input file invalid hex iv value bad magic number error writing output file invalid hex salt value bad password read enter %s %s password:decryptionencryption.\apps\enc.cinvalid 'bufsize' specified. bufsize=%d Cipher Types %-14s use engine e, possibly a hardware device. -engine e%-14s buffer size -bufsize %-14s print the iv/key (then exit if -P) -[pP]%-14s key/iv in hex is the next argument -K/-iv%-14s from a passphrase. One of md2, md5, sha or sha1 %-14s the next argument is the md to use to create a key %-14s passphrase is the first line of the file argument %-14s passphrase is the next argument %-14s base64 encode/decode, depending on encryption flag -a/-base64%-14s decrypt %-14s encrypt %-14s pass phrase source -pass %-14s output file -out %-14s input file -in zero length password unable to read key from '%s' %s is an unsupported message digest type -none-md-iv-S-K-kfile-k-bufsize-base64-a-A-P-debug-nosalt-salt-nopad-v-p-pass-e%s is an unknown cipher encbase64 -%-25snon-hex digit hex string is too long ./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzpasswd != NULL*passwds != NULLPassword: in_stdinin_stdin == 0.\apps\passwd.c-reverse switch table columns -table format output as table -quiet no warnings -noverify never verify when reading password from terminal -stdin read passwords from stdin -in file read passwords from file -salt string use provided salt -apr1 MD5-based password algorithm, Apache variant -1 MD5-based password algorithm -crypt standard Unix password algorithm (default) Usage: passwd [options] [passwords] -reverse-table-quiet-noverify-stdin-apr1-1-crypt%s %s hash != NULLstrlen(out_buf) < sizeof(out_buf)i == 15output == out_buf + strlen(out_buf)1salt_len <= 8strlen(out_buf) <= 6 + 8$strlen(magic) <= 4apr1strlen(passwd) <= pw_maxlenWarning: truncating password to %u characters *salt_p != NULLsalt_malloc_p != NULLsalt_p != NULL the random number generator - load the file (or the files in the directory) into -engine e - use engine e, possibly a hardware device. -5 - use 5 as the generator value -2 - use 2 as the generator value -out file - output the key to 'file usage: gendh [args] [numbits] usage: errstr [-stats] ... %s: bad error code %lx-statsCAkeyTimekeyTimeholdInstructionremoveFromCRLcertificateHoldcessationOfOperationsupersededaffiliationChangedCACompromisekeyCompromiseunspecified -updatedb - Updates db for expired certificates -status serial - Shows certificate status given the serial number -engine e - use engine e, possibly a hardware device. -crlexts .. - CRL extension section (override value in config file) -extfile file - Configuration file with X509v3 extentions to add -extensions .. - Extension section (override value in config file) -multivalue-rdn - enable support for multivalued RDNs -utf8 - input characters are UTF8 (default ASCII) -subj arg - Use arg instead of request's subject -revoke file - Revoke a certificate (given in file) -msie_hack - msie modifications to handle all those universal strings -batch - Don't ask questions -noemailDN - Don't add the EMAIL field into certificate' subject -preserveDN - Don't re-order the DN -ss_cert file - File contains a self signed cert to sign -spkac file - File contains DN and signed public key and challenge -infiles .... - The last argument, requests to process -outdir dir - Where to put output certificates -out file - Where to put the output file(s) -in file - The input PEM encoded certificate request(s) -selfsign - sign a certificate with the key associated with it -cert file - The CA certificate -key arg - key to decode the private key if it is encrypted -keyform arg - private key file format (PEM or ENGINE) -keyfile arg - private key file -policy arg - The CA 'policy' to support -md arg - md to use, one of md2, md5, sha or sha1 -days arg - number of days to certify the certificate for -enddate YYMMDDHHMMSSZ - certificate validity notAfter (overrides -days) -startdate YYMMDDHHMMSSZ - certificate validity notBefore -crlhours hours - Hours is when the next CRL is due -crldays days - Days is when the next CRL is due -gencrl - Generate a new CRL -name arg - The particular CA definition to use -config file - A config file -verbose - Talk alot while doing things usage: ca args no input files signing CRL making CRL cannot lookup how long until the next CRL is issued default_crl_hoursdefault_crl_dayserror while loading CRL number crlnumberError Loading CRL extension section %s certificate file name too long crl_extensionsData Base Updated writing %s writing new certificates Write out database with %d new entries CERTIFICATION CANCELED CERTIFICATION CANCELED: I/O error %d out of %d certificate requests certified, commit? [y/n]Signature did not match the certificate Signature verification problems.... error unpacking public key Check that the request matches the signature Signature ok signature verification failed on SPKAC public key error unpacking SPKAC public key Check that the SPKAC request matches the signature Netscape SPKAC structure not found in %s unable to load Netscape SPKAC structure SPKACno name/value pairs found in %s unable to find 'section' for %s next serial number is %s next serial number is 00 error while loading serial number end date is invalid, it should be YYMMDDHHMMSSZ cannot lookup how many days to certify for default_daysdefault_enddatetodaystart date is invalid, it should be YYMMDDHHMMSSZ default_startdateserialpolicy is %s policymessage digest is %s email_in_dnextensionsSuccessfully loaded extensions file %s ERROR: on line %ld of config file '%s' ERROR: loading the config file '%s' Done. %d entries marked as expired oldnewNo entries found to mark expired %s=Expired 49entry %d: bad serial number length (%d) entry %d: bad serial number characters, char pos %ld, char is '%c' entry %d: invalid expiry date in entry %d entry %d: not revoked yet, but has a revocation date Updating %s ... generating index %d entries loaded from the database unable to stat(%s) I am unable to access the %s directory there needs to be defined a directory for new certificate to be placed in new_certs_dirInvalid extension copy option: "%s" copy_extensionsInvalid certificate options: "%s" cert_optInvalid name options: "%s" name_optmsie_hackpreserveCA certificate and CA private key do not match CA certificatecertificateCA private keyprivate_keyError verifying serial %s! %s=Unknown (%c). %s=Suspended (%c) %s=Expired (%c) %s=Revoked (%c) %s=Valid (%c) Serial %s not present in db. Malloc failure databaseunique_subjectvariable lookup failed for %s::%s cadefault_caerror on line %ld of config file '%s' %serror loading the config file '%s' openssl.cnf/.\apps\ca.cSSLEAY_CONFOPENSSL_CONF-crl_CA_compromise-crl_compromise-crl_hold-crl_reason-crlexts-updatedb-status-extfile-revoke-spkac-ss_cert-infiles-crlhours-crldays-msie_hack-gencrl-noemailDN-preserveDN-notext-outdir-selfsign-cert-keyfile-policy-enddate-startdate-create_serial-nameSignature did not match the certificate request Certificate request and CA private key do not match Error reading certificate request in %s TXT_DB error number %ld failed to update database unknownCERTIFICATE WILL NOT BE CERTIFIED CERTIFICATE WILL NOT BE CERTIFIED: I/O error Sign the certificate? [y/n]: (%ld days)Certificate is to be certified until Certificate Details: ERROR: adding extensions from request Successfully added extensions from config Successfully added extensions from file. ERROR: adding extensions in section %s Extra configuration file found Everything appears to be ok, creating and signing the certificate Subject Name :%s File name :%s Serial Number :%s Expires on :%s Was revoked on:%s undefType :%s invalid type, Data base error ValidRevokedExpiredThe matching entry has the following details check the database/serial_file for corruption ERROR:Serial number %s has already been issued, ERROR:There is already a certificate for %s 00The subject name appears to be ok, checking data base for clashes %s:invalid type in 'policy' configuration The %s field needed to be the same in the CA certificate (%s) and the request (%s) The %s field does not exist in the CA certificate, the 'policy' is misconfigured The mandatory %s field was missing %s:unknown object type in 'policy' configuration matchThe %s field needed to be supplied and was missing suppliedoptional emailAddress type needs to be of type IA5STRING The string contains characters that are illegal for the ASN.1 type The Subject's Distinguished Name is as follows malloc error Error in revocation arguments Revoking Certificate %s. ERROR:Already revoked, serial number %s ERROR:name does not match %s Adding Entry with serial number %s to DB for %s ,Invalid time format %s. Need YYYYMMDDHHMMSSZ Invalid object identifier %s Unknown CRL reason %s ' ^%c^?\0x%02X%cASN.1 %2d:'UNIVERSALSTRING:'IA5STRING:'T61STRING:'PRINTABLE:'invalid compromised time %s missing compromised time invalid object identifier %s missing hold instruction invalid reason code %s invalid revocation date %s bad input format specified for pkcs7 object unable to write pkcs7 object unable to load PKCS7 object -noout don't output encoded data -text print full details of certificates -print_certs print any certs or crl in the input -outform arg output format - DER or PEM -inform arg input format - DER or PEM -print_certserror loading certificates unable to load the file, %s bad input format specified for input crl unable to load CRL -nocrl no crl to load, just certs from '-certfile' (can be used more than once) -certfile arg certificates file of chain to a trusted CA -certfile-nocrl -CApath dir - verify CRL using certificates in "dir" -CAfile name - verify CRL using certificates in file "name" -noout - no CRL output -crlnumber - print CRL number -nextupdate - nextUpdate field -lastupdate - lastUpdate field -issuer - print issuer DN -fingerprint - print the crl fingerprint -hash - print hash value -out arg - output file - default stdout -in arg - input file - default stdin -text - print out a text format version -outform arg - output format - default PEM -inform arg - input format - default PEM (DER or PEM) usage: crl args unable to write CRL %02X%c%s Fingerprint=NONEnextUpdate=lastUpdate=%08lx crlNumber=issuer=Error getting CRL issuer public key Error getting CRL issuer certificate Error initialising X509 store -crlnumber-fingerprint-nextupdate-lastupdate-issuer-hashunable to write key .\apps\rsa.cwriting RSA key RSA key error: %s RSA key ok Public KeyOnly private keys can be checked -engine e use engine e, possibly a hardware device. -pubout output a public key -pubin expect a public key in input file -check verify key consistency -modulus print the RSA key modulus -noout don't print key out -text print the key in text encrypt PEM output with cbc aes -aes128, -aes192, -aes256 -des3 encrypt PEM output with ede cbc des using 168 bit key -des encrypt PEM output with cbc des -passout arg output file pass phrase source -out arg output file -passin arg input file pass phrase source -sgckey Use IIS SGC key format -in arg input file -outform arg output format - one of DER NET PEM -inform arg input format - one of DER NET PEM -pubout-pubin-sgckeyRSA operation error Error reading input Data .\apps\rsautl.cError Reading Output File Error Reading Input File Error getting RSA key Certificate-passin arg pass phrase source -hexdump hex dump output -decrypt decrypt with private key -encrypt encrypt with public key -verify verify with public key -sign sign with private key -oaep use PKCS#1 OAEP -pkcs use PKCS#1 v1.5 padding (default) -raw use no padding -ssl use SSL v2 padding -certin input is a certificate carrying an RSA public key -pubin input is an RSA public -keyform arg private key format - default PEM -inkey file input key -out file output file -in file input file Usage: rsautl [options] A private key is needed for this operation -decrypt-encrypt-rev-pkcs-ssl-oaep-raw-hexdump-asn1parse-certin-inkeyunable to write private key writing DSA key Public Key=unable to load Key read DSA key -modulus print the DSA public value -outform arg output format - DER or PEM -inform arg input format - DER or PEM unable to write DSA parameters return(dsa); } { DSA_free(dsa); return(NULL); } if ((dsa->p == NULL) || (dsa->q == NULL) || (dsa->g == NULL)) dsa->g=BN_bin2bn(dsa%d_g,sizeof(dsa%d_g),NULL); dsa->q=BN_bin2bn(dsa%d_q,sizeof(dsa%d_q),NULL); dsa->p=BN_bin2bn(dsa%d_p,sizeof(dsa%d_p),NULL); if ((dsa=DSA_new()) == NULL) return(NULL); DSA *dsa; DSA *get_dsa%d() { static unsigned char dsa%d_g[]={static unsigned char dsa%d_q[]={static unsigned char dsa%d_p[]={Error, DSA key generation failed This could take some time Error allocating DSA object need_rand.\apps\dsaparam.c number number of bits to use for generating private key -rand files to use for random number input -genkey generate a DSA key -text print as text %s [options] [bits] outfile -genkeybad input format specified for key writing EC key read EC key explicit possible values: named_curve (default) in the asn1 der encoding -param_enc arg specifies the way the ec parameters are encoded hybrid uncompressed (default) possible values: compressed -conv_form arg specifies the point conversion form -param_out print the elliptic curve parameters -text print the key -des encrypt PEM output, instead of 'des' every other cipher supported by OpenSSL can be used -param_outexplicitnamed_curve-param_enchybriduncompressedcompressed-conv_formunable to write elliptic curve parameters return(group); } } group = NULL; EC_GROUP_free(group); { if (!ok) if (point) EC_POINT_free(point); if (tmp_3) BN_free(tmp_3); if (tmp_2) BN_free(tmp_2); if (tmp_1) BN_free(tmp_1); err: ok=1; if (!EC_GROUP_set_generator(group, point, tmp_2, tmp_3)) goto err; if ((tmp_3 = BN_bin2bn(ec_cofactor_%d, sizeof(ec_cofactor_%d), tmp_3)) == NULL) goto err; if ((tmp_2 = BN_bin2bn(ec_order_%d, sizeof(ec_order_%d), tmp_2)) == NULL) goto err; if (point == NULL) goto err; point = EC_POINT_bn2point(group, tmp_1, NULL, NULL); if ((tmp_1 = BN_bin2bn(ec_gen_%d, sizeof(ec_gen_%d), tmp_1)) == NULL) goto err; /* build generator */ if ((group = EC_GROUP_new_curve_GFp(tmp_1, tmp_2, tmp_3, NULL)) == NULL) goto err; if ((tmp_3 = BN_bin2bn(ec_b_%d, sizeof(ec_b_%d), NULL)) == NULL) goto err; if ((tmp_2 = BN_bin2bn(ec_a_%d, sizeof(ec_a_%d), NULL)) == NULL) goto err; if ((tmp_1 = BN_bin2bn(ec_p_%d, sizeof(ec_p_%d), NULL)) == NULL) goto err; BIGNUM *tmp_1 = NULL, *tmp_2 = NULL, *tmp_3 = NULL; EC_POINT *point = NULL; EC_GROUP *group = NULL; int ok=0; EC_GROUP *get_ec_group_%d(void) { ec_cofactorec_orderec_genec_bec_a0x%02X 0x00static unsigned char %s_%d[] = {ec_pok failed checking elliptic curve parameters: unable to load elliptic curve parameters unknown curve name (%s) using curve name prime256v1 instead of secp256r1 secp256r1unable to create curve (%s) using curve name prime192v1 instead of secp192r1 secp192r1 %-10s: CURVE DESCRIPTION NOT AVAILABLE.\apps\ecparam.c -engine e use engine e, possibly a hardware device -rand file files to use for random number input -genkey generate ec key -no_seed if 'explicit' parameters are choosen do not use the seed explicit possible values: named_curve (default) in the asn1 der encoding -param_enc arg specifies the way the ec parameters are encoded hybrid uncompressed (default) possible values: compressed -conv_form arg specifies the point conversion form -list_curves prints a list of all currently available curve 'short names' -name arg use the ec parameters with 'short name' name -C print a 'C' function creating the parameters -check validate the ec parameters -text print the ec parameters in text form -noout do not print the ec parameter -out arg output file - default stdout -in arg input file - default stdin -outform arg output format - default PEM -inform arg input format - default PEM (DER or PEM) -no_seed-list_curves -certopt arg - various certificate text options -clrext - delete extensions before signing and input certificate -extensions - section from config file with X509V3 extensions to add -extfile - configuration file with X509V3 extensions to add -md2/-md5/-sha1/-mdc2 - digest to use -C - print out C code forms -text - print the certificate in text form -set_serial - serial number to use -CAserial arg - serial file -CAcreateserial - create serial number file if it does not exist missing, it is assumed to be in the CA file. -CAkey arg - set the CA key, must be PEM format -CA arg - set the CA certificate, must be PEM format. -req - input is a certificate request, sign and output. -x509toreq - output a certification request object -signkey arg - self sign cert with arg exit 1 if so, 0 if not -checkend arg - check whether the cert expires in the next arg seconds -days arg - How long till expiry of a signed certificate - def 30 days -setalias arg - set certificate alias -addreject arg - reject certificate for a given purpose -addtrust arg - trust certificate for a given purpose -clrreject - clear all rejected purposes -clrtrust - clear all trusted purposes -trustout - output a "trusted" certificate -ocsp_uri - print OCSP Responder URL(s) -ocspid - print OCSP hash values for the subject name and public key -noout - no certificate output -alias - output certificate alias -fingerprint - print the certificate fingerprint -pubkey - output the public key -modulus - print the RSA key modulus -dates - both Before and After dates -purpose - print out certificate purposes -enddate - notAfter field -startdate - notBefore field -email - print email address(es) -subject - print subject DN -hash - synonym for -subject_hash -issuer_hash - print issuer hash value -subject_hash - print subject hash value -serial - print serial number value -passin arg - private key password source -CAkeyform arg - CA key format - default PEM -CAform arg - CA format - default PEM -keyform arg - private key format - default PEM -outform arg - output format - default PEM (one of DER, NET or PEM) -inform arg - input format - default PEM (one of DER, NET or PEM) usage: x509 args unable to write certificate Certificate will not expire Certificate will expire no request key file specified Generating certificate request request keyGetting request Private Key add_word failure .srlout of mem CA Private KeyGetting CA Private Key Private keyGetting Private key notAfter=notBefore=unsigned char XXX_certificate[%d]={ unsigned char XXX_public_key[%d]={ }; unsigned char XXX_subject_name[%d]={ .\apps\x509.c/* issuer :%s */ /* subject:%s */ Yes (WARNING code=%d) No Yes %s%s : CACertificate purposes: serial=subject= issuer= 2.99999.3SET.ex3SET x509v3 extension 3CA CertificateIt does not contain a public key The certificate request appears to corrupted Signature verification error We need a private key to sign with need to specify a CAkey if using the CA command Invalid reject object value %s Invalid trust object value %s -ocspiduse -clrext instead of -crlext -crlext-clrext-CAcreateserial-alias-clrreject-clrtrust-trustout-checkend-purpose-dates-issuer_hash-subject_hash-x509toreq-next_serial-serial-ocsp_uri-email-certopt-setalias-addreject-addtrust-CAserial-CAkey-CA-signkeybad number of days -CAkeyform-CAform-reqerror with certificate - error %d at depth %d %s error with certificate to be certified - should be self signed e is %ld (0x%lX) Generating RSA private key, %d bit long modulus the random number generator load the file (or the files in the directory) into -3 use 3 for the E value -f4 use F4 (0x10001) for the E value -out file output the key to 'file -des3 encrypt the generated key with DES in ede cbc mode (168 bit key) -des encrypt the generated key with DES in cbc mode usage: genrsa [args] [numbits] -aes256-aes192-aes128-des3-des-f4-F4-3unable to create BIO for output - a DSA parameter file as generated by the dsaparam command dsaparam-file -des3 - encrypt the generated key with DES in ede cbc mode (168 bit key) -des - encrypt the generated key with DES in cbc mode -out file - output the key to 'file' usage: gendsa [args] dsaparam-file Generating DSA key, %d bits unable to load DSA parameter file -HTTP/1.0 200 ok Content-type: text/plain Lets print some clear text server2.pemserver.pemACCEPT unable to create curve (sect163r2) Using default temp ECDH parameters error setting cipher list Setting temp ECDH parameters Using default temp DH parameters Setting temp DH parameters Setting secondary ctx parameters id_prefix '%s' set. error setting 'id_prefix' warning: id_prefix is too long if you use SSLv2 warning: id_prefix is too long, only one new session will be possible second certificate private key filesecond server certificate filesecond server certificate private key fileserver certificate fileserver certificate private key file -legacy_renegotiation - enable use of legacy renegotiation (dangerous) -no_ticket - disable use of RFC4507bis session tickets -tlsextdebug - hex dump of all TLS extensions received -key2 arg - Private Key file to use for servername, in cert file if -cert2 arg - certificate file to use for servername -servername_fatal - on mismatch send fatal alert (default warning alert) -servername host - servername for HostName TLS extension -id_prefix arg - Generate SSL/TLS session IDs prefixed by 'arg' -engine id - Initialise and use the specified engine with the assumption it contains a complete HTTP response. -HTTP - Respond to a 'GET / HTTP/1.0' with file ./ -WWW - Respond to a 'GET / HTTP/1.0' with file ./ -www - Respond to a 'GET /' with a status page -bugs - Turn on SSL bug compatibility -no_ecdhe - Disable ephemeral ECDH -no_dhe - Disable ephemeral DH -no_tls1 - Just disable TLSv1 -no_ssl3 - Just disable SSLv3 -no_ssl2 - Just disable SSLv2 -chain - Read a certificate chain -mtu - Set link layer MTU -timeout - Enable timeouts -dtls1 - Just talk DTLSv1 -tls1 - Just talk TLSv1 -ssl3 - Just talk SSLv3 -ssl2 - Just talk SSLv2 -no_tmp_rsa - Do not generate a tmp RSA key -quiet - No server output -serverpref - Use server's cipher preferences -cipher arg - play with 'openssl ciphers' to see what goes here -nocert - Don't use any certificates (Anon-DH) -CAfile arg - PEM format file of CA's -CApath arg - PEM format directory of CA's -state - Print the SSL states -msg - Show protocol messages -debug - Print more output -crlf - convert LF from terminal into CRLF -nbio_test - test with the non-blocking test bio -nbio - Run with non-blocking IO -named_curve arg - Elliptic curve name to use for ephemeral ECDH keys. Use "openssl ecparam -list_curves" for all names (default is sect163r2). or a default set of parameters is used -dhparam arg - DH parameter file to use, in cert file if not specified -dpass arg - second private key file pass phrase source -dkeyform arg - second key format (PEM, DER or ENGINE) PEM default -dkey arg - second private key file to use (usually for DSA) -dcertform x - second certificate format (PEM or DER) PEM default -dcert arg - second certificate file to use (usually for DSA) -pass arg - private key file pass phrase source -keyform arg - key format (PEM, DER or ENGINE) PEM default not specified (default is %s) -key arg - Private Key file to use, in cert file if -certform arg - certificate format (PEM or DER) PEM default -crl_check_all - check the peer certificate has not been revoked by its CA or any other CRL in the CA chain. CRL(s) are appened to the the certificate file. -crl_check - check the peer certificate has not been revoked by its CA. The CRL(s) are appended to the certificate file (default is %s) -cert arg - certificate file to use -Verify arg - turn on peer certificate verification, must have a cert. -verify arg - turn on peer certificate verification -context arg - set session ID context -accept arg - port to accept on (default is %d) usage: s_server [args ...] -key2-cert2-servername_fatal-servername-id_prefix-chain-mtu-timeout-dtls1-tls1-ssl3-ssl2-no_ticket-no_tls1-no_ssl3-no_ssl2-HTTP-WWW-www-no_ecdhe-no_dhe-no_tmp_rsa-bugs-crlf-state-hack-msgError parsing URL -status_url-status_timeout-status_verbose-tlsextdebug-nbio_test-nbio-cipher-legacy_renegotiation-serverpref-crl_check_all-crl_check-no_cache-nocert-dkey-dpass-dkeyform-dcert-dcertform-named_curve-dhparam-certform-contextverify depth is %d, must return a certificate -Verifyverify depth is %d -accept-portSwiching server context. Hostname in TLS extension: "%s" %4ld cache full overflows (%ld allowed) %4ld callback cache hits %4ld session cache timeouts %4ld session cache misses %4ld session cache hits %4ld server accepts that finished %4ld server renegotiates (SSL_accept()) %4ld server accepts (SSL_accept()) %4ld client connects that finished %4ld client renegotiates (SSL_connect()) %4ld client connects (SSL_connect()) %4ld items in the session cache CONNECTION CLOSED shutting down SSL shutdown accept socket DONE verify error:%s ERROR Read BLOCK Secure Renegotiation IS%s supported NOTPeer has incorrect TLSv1 block padding Reused session-id CIPHER is %s (NONE)Shared ciphers:%s issuer=%s subject=%s Client certificate SSL SESSION PARAMETERSDELAY Write BLOCK SSL_do_handshake -> %d lf_num == 0turning on non blocking io .\apps\s_server.ccert_status: ocsp response sent: cert_status: error querying responder cert_status: Can't retrieve issuer certificate. cert_status: no AIA and no default responder URL cert_status: AIA URL: %s cert_status: can't parse AIA URL cert_status: callback called rwrite W BLOCK .htm.php.htmlFILE:%s Error opening '%s' '%s' is a directory Error accessing '%s' '%s' is an invalid path '%s' contains '..' reference '%s' is an invalid file name no client certificate available --- %s, Cipher is %s --- New, --- Reused, --- Ciphers common between both SSL end points: %-11s:%-25sCiphers supported in s_server binary

HTTP/1.0 200 ok
Content-type: text/html

GET /GET /stats GET read R BLOCK
Generating temp (%d bit) RSA key...Allocation error in generating RSA key
                closed
read:errno=%d
write:errno=%d
shutdown
bad select %d
getsockname:errno=%d
connect:errno=%d
drop connection and then reconnect
read X BLOCK
read W BLOCK
RENEGOTIATING
write X BLOCK
write R BLOCK
write W BLOCK
TIMEOUT occured
Error writing session file %s
/stream:features>AUTH TLS
. STARTTLS
didn't found STARTTLS in server response, try anyway...
. CAPABILITY
STLS
STARTTLS
didn't found starttls in server response, try anyway...
STARTTLSEHLO openssl.client.net
CONNECTED(%08X)
Unable to set TLS servername extension.
Can't open session file %s
Error setting client auth engine
client certificate fileclient certificate private key file -no_ticket        - disable use of RFC4507bis session tickets
 -status           - request certificate status from server
 -tlsextdebug      - hex dump of all TLS extensions received
 -servername host  - Set TLS extension servername in ClientHello
 -sess_in arg  - file to read SSL session from
 -sess_out arg - file to write SSL session to
                 are supported.
                 only "smtp", "pop3", "imap", "ftp" and "xmpp"
                 'prot' defines which one to assume.  Currently,
                 for those protocols that support it, where
 -starttls prot - use the STARTTLS command before starting TLS
                 command to see what is available
 -cipher       - preferred cipher to use, use the 'openssl ciphers'
 -serverpref   - Use server's cipher preferences (only SSLv2)
 -bugs         - Switch on all SSL implementation bug workarounds
 -no_tls1/-no_ssl3/-no_ssl2 - turn off that protocol
 -mtu          - set the link layer MTU
 -dtls1        - just use DTLSv1
 -tls1         - just use TLSv1
 -ssl3         - just use SSLv3
 -ssl2         - just use SSLv2
 -no_ign_eof   - don't ignore input eof
 -ign_eof      - ignore input eof (default when -quiet)
 -quiet        - no s_client output
 -state        - print the 'ssl' states
 -nbio_test    - more ssl protocol testing
 -debug        - extra output
 -showcerts    - show all certificates in the chain
 -pause        - sleep(1) after each read(2) and write(2) system call
 -reconnect    - Drop and re-make the connection with the same Session-ID
 -keyform arg  - key format (PEM or DER) PEM default
                 not specified but cert file is.
 -key arg      - Private key file to use, in cert file if
 -cert arg     - certificate file to use, PEM format assumed
 -verify depth - turn on peer certificate verification
 -connect host:port - who to connect to (default is %s:%s)
4433 -port port     - use -connect instead
 -host host     - use -connect instead
usage: s_client args
Error getting client auth engine
-ssl_client_enginexmppftpimappop3smtp-starttls-no_legacy_server_connect-legacy_server_connect-reconnect-showcerts-pause-no_ign_eof-ign_eof-prexit-sess_in-sess_out-connect-host.\apps\s_client.clocalhostCan't use SSL_get_servername
Expansion: %s
Compression: %s
Server public key is %d bit
---
SSL handshake has read %ld bytes and written %ld bytes
---
Ciphers common between both SSL endpoints:
---
No client certificate CA names sent
---
Acceptable client certificate CA names
no peer certificate available
Server certificate
   i:%s
%2d s:%s
---
Certificate chain
======================================

======================================
response parse error
no response sent
OCSP response: nistb571nistb409nistb283nistb233nistb163nistk571nistk409nistk283nistk233nistk163nistp521nistp384nistp256nistp224nistp192secp160r1string to make the random number generator think it has entropy4Vx4Vx4Vx4VxVx44Vx4VxVx4x4Vaes-256 igeaes-192 igeaes-128 igeevpcamellia-256 cbccamellia-192 cbccamellia-128 cbcaes-256 cbcaes-192 cbcaes-128 cbccast cbcblowfish cbcrc5-32/12 cbcrc2 cbcseed cbcidea cbcdes ede3des cbcrc4rmd160hmac(md5)%4u bit ecdh (%s) %8.4fs %8.1f
+F5:%u:%u:%f:%f
%30sop      op/s
%4u bit ecdsa (%s) %8.4fs %8.4fs %8.1f %8.1f
+F4:%u:%u:%f:%f
%30ssign    verify    sign/s verify/s
dsa %4u bits %8.6fs %8.6fs %8.1f %8.1f
+F3:%u:%u:%f:%f
rsa %4u bits %8.6fs %8.6fs %8.1f %8.1f
?+F2:%u:%u:%f:%f
%18ssign    verify    sign/s verify/s
 %11.2f :%.2f %11.2fk@%-13s+F:%d:%s%7d bytes:%dtype        The 'numbers' are in 1000s of bytes per second processed.
ECDH failure.
ECDH key generation failure.
+Htiming function used: %s%s%s%s%s%s%s
ftimetimesgettimeofdaygetrusageHZ=%gTIMEB available timing options: 
%s
%s options:%ld %d-bit ECDH ops in %.2fs
+R7:%ld:%d:%.2f
ECDH computations don't match.
%ld %d bit ECDSA verify in %.2fs
+R6:%ld:%d:%.2f
ECDSA verify failure
ECDSA verify failure.  No ECDSA verify will be done.
%ld %d bit ECDSA signs in %.2fs 
+R5:%ld:%d:%.2f
ECDSA sign failure
ECDSA sign failure.  No ECDSA sign will be done.
ECDSA failure.
%ld %d bit DSA verify in %.2fs
+R4:%ld:%d:%.2f
DSA verify failure
verifyDSA verify failure.  No DSA verify will be done.
%ld %d bit DSA signs in %.2fs
+R3:%ld:%d:%.2f
DSA sign failure
signDSA sign failure.  No DSA sign will be done.
%ld %d bit public RSA's in %.2fs
+R2:%ld:%d:%.2f
RSA verify failure
publicRSA verify failure.  No RSA verify will be done.
%ld %d bit private RSA's in %.2fs
+R1:%ld:%d:%.2f
RSA sign failure
privateDoing %ld %d bit %s %s's: +DNP:%ld:%d:%s:%s
RSA sign failure.  No RSA sign will be done.
This is a key...%d %s's in %.2fs
+R:%d:%s:%f
Doing %s %ld times on %d size blocks: +DN:%s:%ld:%d
@MbP?First we calculate the approximate speed ...
internal error loading RSA key number %d
-mr             produce machine readable output.
-decrypt        time decryption instead of encryption (only EVP).
-evp e          use EVP e.
Available options:
rsa      aes      des      rc2      ecdh
ecdhb163  ecdhb233  ecdhb283  ecdhb409  ecdhb571
ecdhk163  ecdhk233  ecdhk283  ecdhk409  ecdhk571
ecdhp160  ecdhp192  ecdhp224  ecdhp256  ecdhp384  ecdhp521
ecdsa
ecdsab163 ecdsab233 ecdsab283 ecdsab409 ecdsab571
ecdsak163 ecdsak233 ecdsak283 ecdsak409 ecdsak571
ecdsap160 ecdsap192 ecdsap224 ecdsap256 ecdsap384 ecdsap521
dsa512   dsa1024  dsa2048
rsa512   rsa1024  rsa2048  rsa4096
aes-128-ige aes-192-ige aes-256-ige aes-128-cbc aes-192-cbc aes-256-cbc des-cbc  des-ede3 rc2-cbc  sha512   sha256   sha1     hmac     md5      md4      mdc2     md2      Available values:
Error: bad option or value
no engine given
%s is an unknown cipher or digest
no EVP given
program when this computer is idle.
To get the most accurate results, try to run this
You have chosen to measure elapsed time instead of user CPU time.
ecdhecdhb571ecdhb409ecdhb283ecdhb233ecdhb163ecdhk571ecdhk409ecdhk283ecdhk233ecdhk163ecdhp521ecdhp384ecdhp256ecdhp224ecdhp192ecdhp160ecdsaecdsab571ecdsab409ecdsab283ecdsab233ecdsab163ecdsak571ecdsak409ecdsak283ecdsak233ecdsak163ecdsap521ecdsap384ecdsap256ecdsap224ecdsap192ecdsap160dsarsaaesdescast5castcast-cbcbfblowfishbf-cbcrc2rc2-cbcrsa4096rsa2048rsa1024rsa512dsa2048dsa1024dsa512opensslaes-256-igeaes-192-igeaes-128-igeaes-256-cbcaes-192-cbcaes-128-cbcdes-ede3des-cbcripemdhmac-mr-evp-elapsed.\apps\speed.clocalhost:4433starting
Unable to get connection


Now timing with session id reuse.
%d connections in %ld real seconds, %ld bytes read per connection


%d connections in %.2fs; %.2f connections/user sec, bytes read %ld
ư>GET %s HTTP/1.0

Collecting connection statistics for %d seconds
No CIPHER specified
SSL_CIPHER-www page     - Retrieve 'page' from the site
-reuse        - Just time connection reuse
-new          - Just time new connections
-bugs         - Turn on SSL bug compatibility
-ssl3         - Just use SSLv3
-ssl2         - Just use SSLv2
-nbio         - Run with non-blocking IO
-connect host:port - host:port to connect to (default is %s)
usage: s_time 

-time-www option too long
-reuseCCxClC`CTCHC 
%s Policies:AuthorityRequire explicit Policy: %s
FalseTrueverify return:%d
issuer= %s
verify error:num=%d:%s
depth=%d %s
Private key does not match the certificate public key
unable to get private key from '%s'
unable to get certificate from '%s'
error setting private key
error setting certificate
write to %p [%p] (%d bytes => %ld (0x%lX))
read from %p [%p] (%d bytes => %ld (0x%lX))
%s:error in %s
%s:failed in %s
SSL3 alert %s:%s:%s
writeread%s:%s
undefinedSSL_acceptSSL_connect, Finished, ClientKeyExchange, HelloVerifyRequest, CertificateVerify, ServerHelloDone, CertificateRequest, ServerKeyExchange, Certificate, ServerHello, ClientHello, HelloRequest no_renegotiation user_canceled internal_error insufficient_security protocol_version export_restriction decrypt_error decode_error access_denied unknown_ca illegal_parameter certificate_unknown certificate_expired certificate_revoked unsupported_certificate bad_certificate handshake_failure decompression_failure record_overflow decryption_failed bad_record_mac unexpected_message close_notify, warning, fatal, ???ChangeCipherSpecAlertHandshake, CLIENT-CERTIFICATE, REQUEST-CERTIFICATE, SERVER-FINISHED, SERVER-VERIFY, SERVER-HELLO, CLIENT-FINISHED, CLIENT-MASTER-KEY, CLIENT-HELLO UNSUPPORTED-CERTIFICATE-TYPE-ERROR BAD-CERTIFICATE-ERROR NO-CERTIFICATE-ERROR %02x
      %s %s%s [length %04lx]%s%s
 NO-CIPHER-ERROR ???, ERROR:TLS 1.0 ???DTLS 1.0 SSL 3.0 SSL 2.0DTLS 1.0 (bad) <<<>>>TLS %s extension "%s" (id=%d), len=%d
clientserverrenegotiateserver ticketEC point formatselliptic curvesstatus requesttruncated HMACtrusted CA keysclient certificate URLmax fragment lengthserver name.\apps\s_cb.cerror setting random cookie secret
connectkeepalivesocketunable to start WINSOCK, error code=%d
gethostbyname addr is not AF_INET
gethostbyname failure
accept error %d
.\apps\s_socket.cbad gethostbyaddr
getservbyname failure for %s
tcpno port defined
invalid IP address
%u.%u.%u.%u'random' data can be kept in (the file will be overwritten).
Consider setting the RANDFILE environment variable to point at a file that
with much random data.
This means that the random number generator has not been seeded
unable to load 'random state'
 done
Loading 'screen' into random state -unable to write 'random state'
options:  %s (Library: %s)
OpenSSL 0.9.8y 5 Feb 2013usage:version -[avbofpd]
-o-f-b -context arg    - set the session ID context
 -cert           - output certificate 
 -text           - print ssl session id details
usage: sess_id args
unable to write X509
unable to write SSL_SESSION
No certificate present
Context too long
unable to load SSL_SESSION
 -tls1       - TLS1 mode
 -ssl3       - SSL3 mode
 -ssl2       - SSL2 mode
 -v          - verbose mode, a textual listing of the ciphers in SSLeay
usage: ciphers args
Error in cipher list
-?-hError reading sequence file %s
Error reading certs file %s
Can't open output file %s
Can't open input file %s
-toseq    output NS Sequence file
-out file output file
-in file  input file
Usage nseq [options]
Netscape certificate sequence utility
-toseqMac verify error: invalid password?
Error outputting keys and certificates
MAC verified OK
MAC Iteration %ld
Enter Import Password:Error %s getting chain.
Enter Export Password:Memory allocation error
certificates from certfileNo certificate matches private key
certificatesprivate keyNothing to do!
Can't read Password
Enter MAC Password:Error opening input file %s
-password-caname-CSP-LMK-LMK          Add local machine keyset attribute to private key
-CSP name     Microsoft CSP name
              the random number generator
              load the file (or the files in the directory) into
-rand file%cfile%c...
-engine e     use engine e, possibly a hardware device.
-passout p    output file pass phrase source
-passin p     input file pass phrase source
-password p   set import/export password source
-keysig       set MS key signature type
-keyex        set MS key exchange type
-keypbe alg   specify private key PBE algorithm (default 3DES)
-certpbe alg  specify certificate PBE algorithm (default RC2-40)
-descert      encrypt PKCS#12 certificates with triple DES (default RC2-40)
-twopass      separate MAC, encryption passwords
-maciter      use MAC iteration
-noiter       don't use encryption iteration
-nodes        don't encrypt private keys
              encrypt PEM output with cbc aes
-aes128, -aes192, -aes256
-des3         encrypt private keys with triple DES (default)
-des          encrypt private keys with DES
-info         give info about PKCS#12 structure.
-nokeys       don't output private keys.
-cacerts      only output CA certificates.
-clcerts      only output client certificates.
-nocerts      don't output certificates.
-nomacver     don't verify MAC.
-noout        don't output anything, just verify.
-out outfile  output filename
-in  infile   input filename
-caname "nm"  use nm as CA friendly name (can be used more than once).
-name "name"  use name as friendly name
-CAfile arg   - PEM format file of CA's
-CApath arg   - PEM format directory of CA's
-certfile f   add all certs in f
-inkey file   private key if not infile
-chain        add certificate chain
-export       output PKCS12 file
Usage: pkcs12 [options]
Unknown PBE algorithm %s
-keypbe-certpbe-nomac-nomaciter-maciter-noiter-export-descert-nomacver-twopass-info-cacerts-clcerts-nocerts-keysig-keyex-nokeys%s, Iteration %ld
PKCS7 Encrypted data: PKCS7 Data
Warning unsupported bag type: Safe Contents bag
Certificate bag
Shrouded Keybag: Key AttributesBag AttributesKey bag

%02X 
:     %s: 
%s: 
No Octet String in PrivateKey
DSA parameters included in PrivateKey
DSA public key include in PrivateKey
Unknown broken type
Warning: broken key encoding: Error decrypting key
Enter Password:Error reading key
Enter Encryption Password:Error encrypting key
Bad format specified for key
Error converting key
key-v1 obj         use PKCS#5 v1.5 and cipher "alg"
-v2 alg         use PKCS#5 v2.0 and cipher "alg"
-nocrypt        use or expect unencrypted private key
-noiter         use 1 as iteration count
-nsdb           use (nonstandard) DSA Netscape DB format
-embed          use (nonstandard) embedded DSA parameters format
-nooct          use (nonstandard) no octet format
-topk8          output PKCS8 file
-passout arg    output file pass phrase source
-outform X      output format (DER or PEM)
-passin arg     input file pass phrase source
-inform X       input format (DER or PEM)
Usage pkcs8 [options]
-embed-nsdb-nooct-nocrypt-topk8-v1Unknown cipher %s
-v2Signature Failure
Signature OK
Error loading SPKAC
Can't find SPKAC called "%s"
Error parsing config file
Error opening input file
SPKAC=%s
Error opening output file
 -engine e      use engine e, possibly a hardware device.
 -verify        verify SPKAC signature
 -noout         don't print SPKAC
 -spkac arg     alternative SPKAC name
 -challenge arg challenge string
 -passin arg    input file pass phrase source
 -key arg       create SPKAC using private key
%s [options]
-spksect-challengeBad input format for PKCS#7 file
Bad output format for PKCS#7 file
Subject: %s
From: %s
To: %s
Verification failure
Error writing signers to %s
Verification successful
Error decrypting PKCS#7 structure
Can't read content file %s
Error reading S/MIME message
Error creating PKCS#7 structure
signing key filesigner certificaterecipient certificate fileNo recipient(s) certificate(s) specified
No recipient certificate or key specified
cert.pem       recipient certificate(s) for encryption
               load the file (or the files in the directory) into
-passin arg    input file pass phrase source
-engine e      use engine e, possibly a hardware device.
-crl_check_all check revocation status of signer's certificate chain using CRLs
-crl_check     check revocation status of signer's certificate using CRLs
-CAfile file   trusted certificates file
-CApath dir    trusted certificates directory
-text          include or delete text MIME headers
-subject s     subject
-from ad       from address
-to addr       to address
-content file  supply or override content for detached signature
-outform arg   output format SMIME (default), PEM or DER
-out file      output file
-keyform arg   input private key format (PEM or ENGINE)
-inkey file    input private key (if not signer or recipient)
-inform arg    input format SMIME (default), PEM or DER
-in file       input file
-recip  file   recipient certificate file for decryption
-signer file   signer certificate file
-certfile file other certificates file
-binary        don't translate message to text
-noattr        don't include any signed attributes
-nodetach      use opaque signing
-nocerts       don't include signers certificate when signing
-noverify      don't verify signers certificate
-nosigs        don't verify message signature
-nointern      don't search certificates in message for signer
               encrypt PEM output with cbc aes
-rc2-128       encrypt with RC2-128
-rc2-64        encrypt with RC2-64
-rc2-40        encrypt with RC2-40 (default)
-des           encrypt with DES
-des3          encrypt with triple DES
-pk7out        output PKCS#7 structure
-verify        verify signed message
-sign          sign message
-decrypt       decrypt encrypted message
-encrypt       encrypt message
Usage smime [options] cert.pem ...
No signer certificate specified
-content-recip-signer-from-to-crlfeol-nooldmime-nosigs-nosmimecap-nodetach-noattr-nochain-nointern-rc2-64-rc2-128-rc2-40-pk7out-hex                  - hex encode output
-base64               - base64 encode output
-rand file%cfile%c... - seed PRNG from files
-engine e             - use engine e, possibly a hardware device.
-out file             - write to file
Usage: rand [options] num
N argument "/lib/libdriver.so".
 Eg. '-pre "SO_PATH:/lib/libdriver.so"' calls command "SO_PATH" with
 line, or all supported ENGINEs if none are specified.
 NB: -pre and -post will be applied to all ENGINEs supplied on the command
               (only used if -t is also provided)
 -post  - runs command 'cmd' against the ENGINE after loading it
               to load it (if -t is used)
 -pre   - runs command 'cmd' against the ENGINE before any attempts
               -tt will display error trace for unavailable engines
 -t[t]       - for each engine, check that they are really available
 -c          - for each engine, also list the capabilities
               -vvvv will also show internal input flags
               -vvv will also add the input flags for each command
               -vv will additionally display each command's description
 -v[v[v[v]]] - verbose mode, for each engine, list its 'control commands'
usage: engine opts [engine ...]
  <0x%04X>NO_INPUTSTRING|NUMERIC[Internal] 
%s%s(input flags): %s: %s
, .\apps\engine.c[ unavailable ]
[ available ]
 [%s]
RANDDHLoaded: (%s) %s
     (%s) %s
-post-pret-tv[Error]: command name too long
[Success]: %s
[Failure]: %s
[Error]: internal stack error
	Revocation Time: 	Reason: %s
	Next Update: 	This Update: WARNING: Status times invalid.
ERROR: No Status found.
Response verify OK
Nonce Verify error
Response Verify Failure
WARNING: no nonce in response
Error parsing response
validator certificateError reading OCSP response
Error Opening OCSP response file
Need a responder certificate, key and CA for this operation!
Error opening file %s
Error signing OCSP request
Error loading signer certificate
Error accepting connection
Responder Error: %s (%d)
.\apps\ocsp.cbnsigner private keysigner certificatesNeed an OCSP request for this operation!
HTTP/1.0 200 OK
Content-type: application/ocsp-response
Content-Length: %d

Error parsing OCSP request
Invalid request
POSTWaiting for OCSP client connections...
responder private keyresponder other certificatesError loading responder certificate
responder certificateError setting up accept BIO
Error reading OCSP request
Error Opening OCSP request file
-nrequest n        number of requests to accept (default unlimited)
-resp_key_id       identify reponse by signing certificate key ID
-ndays n	 	 number of days before next update
-nmin n	 	 number of minutes before next update
-resp_no_certs     don't include any certificates in response
-rother file	 other certificates to include in response
-rkey file	 responder key to sign responses with
-rsigner file	 responder certificate to sign responses with
-CA file		 CA certificate
-index file	 certificate status index file
-port num		 port to run responder on
-no_cert_checks    don't do additional checks on signing certificate
-no_chain          don't chain verify response
-no_cert_verify    don't check signing certificate
-no_signature_verify don't check signature on response
-no_intern         don't search certificates contained in response for signer
-trust_other       don't verify additional certificates
-verify_other file additional certificates to search for signer
-noverify          don't verify response at all
-status_age n      maximum status age in seconds
-validity_period n maximum validity discrepancy in seconds
-VAfile file       validator certificates file
-CAfile file       trusted certificates file
-CApath dir        trusted certificates directory
-path              path to use in OCSP request
-host host:n       send OCSP request to host on port n
-url URL           OCSP responder URL
-no_nonce          don't add OCSP nonce to request
-nonce             add OCSP nonce to request
-respin file       read DER encoded OCSP reponse from "file"
-reqin file        read DER encoded OCSP request from "file"
-respout file      write DER encoded OCSP reponse to "file"
-reqout file       write DER encoded OCSP request to "file"
-text              print text form of request and response
-resp_text         print text form of response
-req_text          print text form of request
-no_certs          don't include any certificates in signed request
-sign_other file   additional certificates to include in signed request
-signkey file      private key to sign OCSP request with
-signer file       certificate to sign OCSP request with
-serial n          serial number to check
-cert file         certificate to check
-issuer file       issuer certificate
-out file          output filename
Usage ocsp [options]
OCSP utility
Error converting serial number %s
No issuer certificate specified
-rother-rkey-rsigner-ndaysIllegal accept count %s
-nrequestIllegal update period %s
-nmin-indexError Creating OCSP request
issuer certificate-path-respout-reqoutIllegal validity age %s
-status_ageIllegal validity period %s
-validity_period-verify_other-sign_other-VAfile-respin-reqin-resp_text-req_text-no_intern-trust_other-no_explicit-no_cert_checks-no_chain-no_cert_verify-no_signature_verify-no_certs-resp_key_id-resp_no_certs-no_nonce-nonce-ignore_err-urlIllegal timeout value %s
Error querying OCSP responsder
Unexpected retry condition
Select error
Timeout on request
Timeout on connect
Can't get connection fd
Error connecting BIO
Error creating SSL context.
Error creating connect BIO
 is %sprime
not Unknown option '%s'
%-14s number of checks
-checks %-14s hex
No prime specified
-checkscast5-ofbcast5-cfbcast5-ecbcast5-cbcbf-ofbbf-cfbbf-ecbrc2-40-cbcrc2-64-cbcrc2-ofbrc2-cfbrc2-ecbdes-ede3-ofbdes-ede-ofbdes-ofbdes-ede3-cfbdes-ede-cfbdes-cfbdes-ede3-cbcdes-ede-cbcdes-ededes-ecbrc4-40desxdes3aes-256-ecbaes-192-ecbaes-128-ecbprimeocspenginerandsmimespkacpkcs8nseqcipherssess_idcrl2pkcs7pkcs7versions_timespeeds_clients_servergendsagenrsax509ecparamecdsaparamrsautlcrlerrstrgendhpasswddhparamdhdgstasn1parsebad exit
error in %s
OpenSSL> >offOPENSSL_DEBUG_MEMORYFIPS mode not supported.
OPENSSL_FIPStype out of boundsopenssl (lock_dbg_cb): %s (mode=%d, type=%d) at %s:%d
CRYPTO_w_unlock on read lockCRYPTO_r_unlock on write locknot lockedalready lockedinvalid mode%-15s
Cipher commands (see the `enc' command for more details)

Message Digest commands (see the `dgst' command for more details)

Standard commandsopenssl:Error: '%s' is an invalid command.
list-cipher-commandslist-message-digest-commandslist-standard-commandsbyeexitqquitno-CC>\@2j@@x@4x=dBM
f
iX
OV:w
z32~
Q
&
\S
W
										EObk_gaf^^j_kiltq
|{zu*,

P	TSr
9{V.+q,\4N]u	o$
B%vzRk	I{	mucC;
YW9mh	Eb`C
YznA^]@x_Z9
f

?X<

=
^
P
OC0Mk+S?6<CL
!"

!>xOgc;Ji%
;x
%F
~/
	uk

`lt]mw8
|
[S=C5;Dj?H
l76B	t0
X0NQn_W	G/Lsf	VM7@
`

|

H
s


{{

3






!mw
4z	e	Pd	
	~ebY"\evSo+
v`VrkT
l
z

)e
5:Up		z	-R<
R.
d
`

N(cUF	]B.c[	fDHd

)La6

MQ			h	y P			T	D
}V
]
Dm
H5

>
t	
! |
O
p
%
&
Q@@@@@@@@@@@@@@A
AA"A*A4A>AFAPAZAdAnAzAAAAAAAAAAAAAABBB$B.B6B>BHBRBZBpBxBBBBBBBBBCC(C0C:CDCNCz4 b&(+<8$nqtIv%wZV;`y7!1K-*SR?MO}^Hl:#x=AN0#"psJ47
3qts	oSSLEAY32.dllLIBEAY32.dllWSOCK32.dll_closeD_lseek_write_read_openOfflushdftellbfseekWfopenLfcloseffwrite]freadRfgetsXfprintf_iobBclearerr_setmode4abortprintfperror=atoistrncmpsscanfsetvbuf_pctype_isctypea__mb_cur_maxstrchr_assertstrncattoupperjgetenv>atol_stricmpIexittimestrstrYfputcremove_errnorenamesignalsisdigitstrspnZfputsqsortmallocrealloc^free_fmodeMSVCRT.dll_exitH_XcptFilterd__p___initenvX__getmainargs_initterm__setusermatherr_adjust_fdivj__p__commodeo__p__fmode__set_app_type_except_handler3_controlfp_stat_access_fileno9_kbhit_ftime.QCCCCCopenssl.exeOPENSSL_ApplinkXXC'C$XCXCWCWChWC0WCVCVCXVCVCUCUCUC@UCUCTCTCPTCTCSCSCLSC SCRCRC`RC$RCQCQCpQC(QCPCPCPPCPCOCOCOCOCOCOClOC\OCLOC|Gt3@آC̢CCCdClC0:A3O<}UO[g[h4ޥ.3n4^qإerwW_UWIAWj`Rrf};
B#(%%/p߁ImT.&ުY1!G;ZFŹ+	xz3pBkh$!
hwn|ڼ>S"絮nUe LsjI)aF
X׈^{BXEA 1W=[/_OGV? )[Iz*!,IOQmKKR,0\ܘC=C[Щ>˃uk4A)jUMp쮇8
 EwnW`W"ˏ3:7o림Sp!v>/E$Y2.;#x=gO7NGL-OA.-",SU+?X:0ڰ-O&8=pQQy2{-'ŜyR|I ˊf$3;@VP澄%Ӝlb]+}=zlTQ	[GdUZ7%}!ioɊ@zp
NFz۳˃#ĽԪ]1FΞugSGD%s~ЎYѲZ/9ͣ¹ǹHƘMʄl)Y5dY!3kQ^޸_ƹ"eFD#33kYtj>6P!Бl/&0ej0VboVqIZM4Xy0UlZL,YV蝯
xQUC;l-A(Пj~Ы|}5'IQcd>amS9'Ogw:o s>z(a#+΄W~%Te̕
0YakNCy% Hh	f+vFNY	LeHxC,$}ZpEl)@?[GD9rzڪ*	T#7[a
~$sm@r	HlF9OxFj1d	8<*+16`-t2蜓n{q%8*7Dΐ?RR"8v	iXj}|,2O

7C]$'FTSbq+qAu:a)F:ck0N%Uj̙r}m䐵pNH`*z=$)ڽפ`-"ek(/y|CBjEO.4T}my.QMyVD7ZHH?,QFAƑrUs,tP:/mwmEi'e^4Ӂ=0C#Bv1sFa
9@zۀ,
4ԒlnOϯLwvrGќJ3nuv1w)R.R0u͉lW'=/\v)K	xraao9N>Ǐ68%zJԠ>!9r=P]_?mU
![&+wOv,"j办VxD^`ey1#.t॔KXU346Wy.;N!\HJ`)S--oB.q1mo+#ߴ@,
}}Kߑk
iif[F}pm~uNwMA?bq^8K,0oI.ɚ]	U:%#Вã/MUZ1u,A_uc,h˓QsI`&FP_YT͘At_	`{< 뤓ʚ'e[yn&(;smSX`\vCX$;$ET7c}t!HĔD"-->Z1ܕAX@_ڬ?*kX_Hx $< %kBl61z&vjb
|I
wgG!?C!F0bQrHg͞!0A4w>9g*{/@pO?vJ5NG+]tC3{I@fbz˓SԀH'KAa߿=q%qJWl!}5EjC\T_$.@ޒ#YҡLe[·Uq<
$ka3B+wtyyϭW5	tqXk2]vH9#wJp>lR$AZz^15uĖt۴Ȍ;fPGeb4X5j,Zhxdk>Nz¶vœjiV4J
n5`#0d9`vQJ<:, `iJ!IT X!QG>TFٶdT/ϥ(9v[-C$oio}_x@	(eƞVpRҔJ%L.y\ՎTU%vcP"/XXykAg&lWa:}1-8b6BB$ge|oDɫLE{80X+]
TIM"@P.x(x$V—,Cfr_S챱^@ H{?j!5GŊO^c`q[JO`ƺJ$ .:΍'!
QU0c׍ąN'|.墣Lc9wfʠqP=5.`haCʚ#JEraww*-Va^jFJ?PֺוeSánCӁFFHNy@4q^J^Op-=:ը

9_!1trkd5a
9!f
|ʡZqT(pCl{hMEFC,FN&.۰U*PD!e8`$ԜLz"
h__;kܾz:'IC=~,^{nln8]V}S>$
ki&+pSFbP3Kʼns;lIǟ
D0پ[_׉t),TQޠ/$kwޢhR }!ڻbG6g茪8a(1gPޛ~,Pa孽6N@}
K?nAj)}G0	j3=S.Ys>u1GzR٦{8h~KS[Yqenfk6(ץ,9&Kښp7V#^9OCeòp[PI1lՅePfeoMLoPF%ho0i](Hޙ?_s$
 ]*?'b{tbSa'z	MTXItU~#Za~qM4)h^ 	lAsj~22g蠋kEvϑGjZ 7dy=a!t]LQG\LzrSxH:џ}G{tPVW+AV8F
NDC!]n&1
!Ľ$PH,.I_W'6 +٘4PXTctvR{(JN؜y؛f/ϬyEx~"Qg&#8pMO@~rR33Π%]oO4~o0o٠]\A2¢~h\(!XcLNKMX\Ug}nTo@gL[<zgi
@v&CV(_;i6,Qw/W{b;@{h
8!]F#rQFyٽ,W~={k&'jw,B҈ӒQd\lG	%??!
]Te}ðhϛ3MӔ>btơu,xY4cO/<8?~%r9캐[:Xl0B71jj	)F˅0^9""4ah7=.J[HcӖd4ѠѮl/HC!0_ޣpx.}nBܷF6MF=`-	XCLC@C4C(CCCCCCCCCCCC	;;XC-time arg     - max number of seconds to collect data, default %d
-verify arg   - turn on peer certificate verification, arg == depth
-cert arg     - certificate file to use, PEM format assumed
-key arg      - RSA file to use, PEM format assumed, key is in cert file
                file if not specified by this option
-CApath arg   - PEM format directory of CA's
-CAfile arg   - PEM format file of CA's
-cipher       - preferred cipher to use, play with 'openssl ciphers'

DC'CrCqCxqCDqCCC,pCC|C0CCCClD DDDLDDDD0DDDD8DDDDpC@/D0@+C$@/D`N@/D ]@/D0d@ICn@/D@/D@/D@HbC@/D@8C@@/D@4C0A/D
A/DA/D`A/D0A/D`RA/DYA|/D@^Ap/D Ah/DA`/DBX/D`fBP/D@D/D@@