Use "dig -h" (or "dig -h | more") for complete list of options ;; XFR size: %u records (messages %u, bytes %lu) ;; WARNING -- Some TSIG could not be validated;; WARNING -- TSIG key was not used.;; Received %lu bytes from %s(%s) in %ld us
;; Received %lu bytes from %s(%s) in %ld ms
%s; <<>> DiG 9.11.36-RedHat-9.11.36-16.el8_10.2 <<>>Where: domain is in the Domain Name System q-class is one of (in,hs,ch,...) [default: in] q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a] (Use ixfr=version for type ixfr) q-opt is one of: -4 (use IPv4 query transport only) -6 (use IPv6 query transport only) -b address[#port] (bind to source address/port) -c class (specify query class) -f filename (batch mode) -i (use IP6.INT for IPv6 reverse lookups) -k keyfile (specify tsig key file) -m (enable memory usage debugging) -p port (specify port number) -q name (specify query name) -r (do not read ~/.digrc) -t type (specify query type) -u (display times in usec instead of msec) -x dot-notation (shortcut for reverse lookups) -y [hmac:]name:key (specify named base64 tsig key) d-opt is of the form +keyword[=value], where keyword is: +[no]aaflag (Set AA flag in query (+[no]aaflag)) +[no]aaonly (Set AA flag in query (+[no]aaflag)) +[no]additional (Control display of additional section) +[no]adflag (Set AD flag in query (default on)) +[no]all (Set or clear all display flags) +[no]answer (Control display of answer section) +[no]authority (Control display of authority section) +[no]badcookie (Retry BADCOOKIE responses) +[no]besteffort (Try to parse even illegal messages) +bufsize[=###] (Set EDNS0 Max UDP packet size) +[no]cdflag (Set checking disabled flag in query) +[no]class (Control display of class in records) +[no]cmd (Control display of command line - global option) +[no]comments (Control display of packet header and section name comments) +[no]cookie (Add a COOKIE option to the request) +[no]crypto (Control display of cryptographic fields in records) +[no]defname (Use search list (+[no]search)) +[no]dnssec (Request DNSSEC records) +domain=### (Set default domainname) +[no]dscp[=###] (Set the DSCP value to ### [0..63]) +[no]edns[=###] (Set EDNS version) [0] +ednsflags=### (Set EDNS flag bits) +[no]ednsnegotiation (Set EDNS version negotiation) +ednsopt=###[:value] (Send specified EDNS option) +noednsopt (Clear list of +ednsopt options) +[no]expire (Request time to expire) +[no]fail (Don't try next server on SERVFAIL) +[no]header-only (Send query without a question section) +[no]identify (ID responders in short answers) +[no]ignore (Don't revert to TCP for TC responses.) +[no]keepopen (Keep the TCP socket open between queries) +[no]mapped (Allow mapped IPv4 over IPv6) +[no]multiline (Print records in an expanded format) +ndots=### (Set search NDOTS value) +[no]nsid (Request Name Server ID) +[no]nssearch (Search all authoritative nameservers) +[no]onesoa (AXFR prints only one soa record) +[no]opcode=### (Set the opcode of the request) +[no]qr (Print question before sending) +[no]question (Control display of question section) +[no]rdflag (Recursive mode (+[no]recurse)) +[no]recurse (Recursive mode (+[no]rdflag)) +retry=### (Set number of UDP retries) [2] +[no]rrcomments (Control display of per-record comments) +[no]search (Set whether to use searchlist) +[no]short (Display nothing except short form of answers - global option) +[no]showsearch (Search with intermediate results) +[no]sigchase (Chase DNSSEC signatures) +[no]split=## (Split hex/base64 fields into chunks) +[no]stats (Control display of statistics) +subnet=addr (Set edns-client-subnet option) +[no]tcp (TCP mode (+[no]vc)) +timeout=### (Set query timeout) [5] +[no]topdown (Do +sigchase in top-down mode) +[no]trace (Trace delegation down from root [+dnssec]) +trusted-key=#### (Trusted Key to use with +sigchase) +tries=### (Set number of UDP attempts) [3] +[no]ttlid (Control display of ttls in records) +[no]ttlunits (Display TTLs in human-readable units) +[no]unknownformat (Print RDATA in RFC 3597 "unknown" format) +[no]vc (TCP mode (+[no]tcp)) +[no]zflag (Set Z flag in query) global d-opts and servers (before host name) affect all queries. local d-opts and servers (after host name) affect only that lookup. -h (print help and exit) -v (print version and exit) DiG 9.11.36-RedHat-9.11.36-16.el8_10.2 ;; Warning, extra class option ;; Warning, ignoring invalid class %s ;; Warning, extra type option ;; Warning, ignoring invalid type %s couldn't get address for '%s': %s: skipping lookup (lookup_list).tail == (lookup)(lookup_list).head == (lookup)(lookup_list).head != (lookup)(lookup_list).tail != (lookup)ednsopt no code point specified;; Warning, split must be a multiple of 4; adjusting to %u ;; Warning, ixfr requires a serial number couldn't open specified batch file;; WARNING: .local is reserved for Multicast DNS ;; You are currently testing what happens when an mDNS query is leaked to DNS;; ->>HEADER<<- opcode: %s, status: %s, id: %u ; QUERY: %u, ANSWER: %u, AUTHORITY: %u, ADDITIONAL: %u ;; WARNING: recursion requested but not available ;; WARNING: EDNS query returned status %s - retry with '%s+noedns' ;; WARNING: Message has %u extra byte%s at end dns_message_pseudosectiontotextisc_buffer_reserve(&_tmp, _length) == ISC_R_SUCCESSisc_buffer_availablelength(buf) >= _length;; Query time: %ld usec ;; Query time: %ld msec ;; SERVER: %s(%s) %a %b %d %H:%M:%S %Z %Y;; WHEN: %s ;; MSG SIZE rcvd: %u dns_master_stylecreate +cmd +short; (%d server%s found) ;; global options:%s%s can't find IPv4 networkingcan't find IPv6 networking46bcdfhikmnpqrtvyxdigrc (late)46dhimnruvCouldn't parse port numberinvalid address %slooking up %sixfr=Couldn't parse serial numberInvalid IP address %s Invalid option: -%s parse_args()making new lookupbatchfp == ((void *)0)../../../bin/dig/dig.cHOMEdigrc (open)%s/.digrcconfig line %s .digrc argv %d: %smain parsing %sno valid addresses for '%s' ;; Invalid option %s noaaonlyaaflagadditionaladflagallauthoritybadcookiebesteffortbufsizeCouldn't parse buffer sizecdflagclclassCOOKIE data too largecryptodefnamednssecdomaindscpDSCPCouldn't parse DSCP valueCouldn't parse ednsCouldn't parse ednsflagsednsnegotiationednsoptexpirefailheader-onlyidentifyidninidnoutignorekeepopenmappedmultilineCouldn't parse ndotsnsidnssearchonesoaCouldn't parse opcodequestionrdflagrecurseretryCouldn't parse retriesrrcommentsshowsearchsigchaseCouldn't parse splitstatssubnetCouldn't parse clienttcpCouldn't parse timeouttopdowntraceCouldn't parse triestrusted-keytrusted key too largettlttlidttlunitsunknownformatvczflagInvalid option: +%s batch line %sbatch argv %d: %sresult == 00123456789short_formlong_formnocomments+nodnssec isc_buffer_allocate; %s ;; Sending:;; Got answer:;; flags: qr aa tc rd ra ad cd; MBZ: 0x4dns_message_sectiontotextdns_rdata_totext in %lu us. in %lu ms.say_messageshort_answer%.*snoheadersprintmessage(%s %s %s)dig_setup()isc_app_startdigrc (early)only one of -4 and -6 alloweddig_query_setupdig_startup()isc_app_onrunIQUERYSTATUSRESERVED3NOTIFYUPDATERESERVED6RESERVED7RESERVED8RESERVED9RESERVED10RESERVED11RESERVED12RESERVED13RESERVED14RESERVED15������������������������������������������������������������������������������������������������������������t���d��������������������������$���4��������������������������������������������������������^���e�����������A��������������������������W���������F������������R�������������ε������������X�������Ʋ�������E������������ܶ��N������������������������������������������������������������������������������Q������\���\���[��`��\���\���\���\���\���\������\���\���\��������������������������������������������������������������������й��й��й��й��й��й��й�������й������й��й��ý��(search_list).tail == (search)(search_list).head == (search)(search_list).head != (search)(search_list).tail != (search)lookold->ednsopts[i].value != ((void *)0)memory allocation failure in %s:%d(lookup->connecting).tail == (query)(lookup->connecting).head == (query)(lookup->connecting).head != (query)(lookup->connecting).tail != (query)(query->recvlist).tail == (&query->recvbuf)(query->recvlist).head == (&query->recvbuf)(query->recvlist).head != (&query->recvbuf)(query->recvlist).tail != (&query->recvbuf)(query->lengthlist).tail == (&query->lengthbuf)(query->lengthlist).head == (&query->lengthbuf)(query->lengthlist).head != (&query->lengthbuf)(query->lengthlist).tail != (&query->lengthbuf)query->recvspace != ((void *)0)Bad ACE string '%s' (%s), use +noidnout'%s' is not a legal IDNA2008 name (%s), use +noidnoutCannot represent '%s' in the current locale nor ascii (%s), use +noidnout or a different locale;; Warning: cannot represent '%s' in the current localeencoded ASC string is too long'%s' is not a legal IDN name (%s), use +noidninmsg->cc_ok == 0 && msg->cc_bad == 0;; Warning: Client COOKIE mismatch;; Warning: COOKIE bad token (too short)isc_buffer_reserve(&_tmp, 1) == ISC_R_SUCCESSisc_buffer_availablelength(&hexbuf) >= 1Ucouldn't get address for '%s': %sbefore insertion, init@%p -> %p, new@%p -> %pafter insertion, init -> %p, new = %p, new -> %pisc_buffer_availablelength(namebuf) >= _length;; Couldn't create key %s: %s sap != ((void *)0) && *sap == ((void *)0)invalid prefix length in '%s': %s ;; Warning, ignoring invalid TSIG algorithm %s key must have algorithm and secret;; Couldn't create key %s: bad algorithm Couldn't read key from %s: %s unable to generate cookie secretcan't find either v4 or v6 networkingfreeing server %p belonging to %p(lookup->my_server_list).tail == ((dig_server_t *)ptr)(lookup->my_server_list).head == ((dig_server_t *)ptr)(lookup->my_server_list).head != ((dig_server_t *)ptr)(lookup->my_server_list).tail != ((dig_server_t *)ptr)convert textname to IDN encodingconvert origin to IDN encoding'%s' is not in legal name syntax (%s)dns_name_isabsolute(lookup->name)starting to render the messageisc_buffer_availablelength(&b) >= (unsigned int) (unsigned)addrli + lookup->ednsoptscnt <= (100U + 5)create query %p linked to lookup %pcouldn't get address for '%s': %s (lookup->my_server_list).tail == (srv)(lookup->my_server_list).head == (srv)(lookup->my_server_list).head != (srv)(lookup->my_server_list).tail != (srv)canceling pending query %p, belonging to %pcanceling connecting query %p, belonging to %pError in the queried type: %d
Launch a query to find a RRset of type (lookup_list).tail == (current_lookup)(lookup_list).head != (current_lookup)(lookup_list).tail != (current_lookup) ;; No trusted key, +sigchase option is disabled isn't a subdomain of any Trusted Keys: +sigchase option is disableignoring launch_next_query because !pendingisc_buffer_reserve(&_tmp, 2) == ISC_R_SUCCESSisc_buffer_availablelength(&query->slbuf) >= 2Usending a request in launch_next_queryisc_time_now((&query->time_sent)) == 0;; Skipping mapped address '%s' event->ev_type == (((2) << 16) + 4);; Connection to %s(%s) for %s failed: %s. event->ev_type == (((2) << 16) + 1)(sevent->bufferlist).tail == (b)(sevent->bufferlist).head == (b)(sevent->bufferlist).head != (b)(sevent->bufferlist).tail != (b);; communications error to %s: %s ((query->recvlist).head == ((void *)0))recving with lookup=%p, query=%presubmitted recv request with length %d, recvcount=%dworking on lookup %p, query %precving with lookup=%p, query=%p, sock=%pevent->ev_type == (((1) << 16) + 2)resending UDP request to first servermaking new TCP request, %d tries left;; connection timed out; no servers could be reachedevent->ev_type == (((2) << 16) + 2)((lookup_list).head) == ((void *)0)((pthread_mutex_destroy(((&lookup_lock))) == 0) ? 0 : 34) == 0Destroy the messages kept for sigchaserdata.type == ((dns_rdatatype_t)dns_rdatatype_dnskey);; Ok, find a Trusted Key in the DNSKEY RRset: %d keyrdata.type == ((dns_rdatatype_t)dns_rdatatype_dnskey)Oops: impossible to build new DS rdata;; OK a DS valids a DNSKEY in the RRset;; Now verify that this DNSKEY validates the DNSKEY RRset;; This DS is NOT the DS for the chasing KEY: FAILED Launch a query to find a RRset of type ;; NS RRset is missing to continue validation: FAILED chase_nsrdataset != ((void *)0) ;; No Answers: Validation FAILED
;; RRSIG is missing for continue validation: FAILED
;; RRSIG of the RRset to chase:chase_sigrdataset != ((void *)0) ;; DNSKEY is missing to continue validation: FAILED
;; DNSKEYset that signs the RRset to chase:chase_keyrdataset != ((void *)0) ;; RRSIG for DNSKEY is missing to continue validation : FAILED
;; RRSIG of the DNSKEYset that signs the RRset to chase:chase_sigkeyrdataset != ((void *)0) ;; WARNING There is no DS for the zone: ;; WARNING : NO RRSIG DS : RRSIG DS should come with DS ;; RRSIG of the DSset of the DNSKEYset;; nothing in authority section : impossible to validate the non-existence : FAILEDThere is a NSEC for this zone in the AUTHORITY section:;; no RRSIG NSEC in authority section: impossible to validate the non-existence: FAILEDOK the NSEC said that the type doesn't exist There isn't RRSIG NSEC for the zone We want to prove the non-existence of a type of rdata %d or of the zone: We have a NSEC for this zone :OKprove_nx: OK type does not existthere is no NSEC for this zone: validating that the zone doesn't existno answer or authority sectionno response but there is a delegation in authority section: no response and no delegation in authority section but a reference to: ;; RRSIG of DNSKEY is missing to continue validation: FAILED chase_dsrdataset != ((void *)0)chase_sigdsrdataset != ((void *)0) ;; chain of trust can't be validated: FAILED
;; RRset is missing to continue validation SHOULD NOT APPEND: FAILED
;; RRSIG is missing to continue validation SHOULD NOT APPEND: FAILED
;; We are in a Grand Father Problem: See 2.2.1 in RFC 3658;; and we try to continue chain of trust validation of the zone: ;;NSset is missing to continue validation: FAILED
;; DSset is missing to continue validation: FAILED
;; Impossible to verify the DSset: FAILED
;; Impossible to verify the non-existence, the NSEC RRset can't be validated: FAILED
;; Impossible to verify the NSEC RR to prove the non-existence : FAILED
;; Impossible to verify the non-existence: FAILED
;; OK the query doesn't have response but we have validate this fact : SUCCESS
;; RRsig of RRset is missing to continue validation SHOULD NOT APPEND: FAILED
;; Impossible to verify the RRset : FAILED
;; FINISH : we have validate the DNSSEC chain of trust: SUCCESS
;; Impossible to verify the Non-existence, the NSEC RRset can't be validated: FAILED
No Answers and impossible to prove the unsecurity : Validation FAILED ;; An NSEC prove the non-existence of a answers, Now we want validate this NSEC
;; WE HAVE MATERIAL, WE NOW DO VALIDATION;; No DNSKEY is valid to check the RRSIG of the RRset: FAILED;; OK We found DNSKEY (or more) to validate the RRset ;; Ok this DNSKEY is a Trusted Key, DNSSEC validation is ok: SUCCESS ;; Now, we are going to validate this DNSKEY by the DS;; the DNSKEY isn't trusted-key and there isn't DS to validate the DNSKEY: FAILED;; ERROR no DS validates a DNSKEY in the DNSKEY RRset: FAILED;; OK this DNSKEY (validated by the DS) validates the RRset of the DNSKEYs, thus the DNSKEY validates the RRset;; Now, we want to validate the DS : recursive callisc_time_now((&query->time_recv)) == 0(sevent->bufferlist).tail == (&query->recvbuf)(sevent->bufferlist).head == (&query->recvbuf)(sevent->bufferlist).head != (&query->recvbuf)(sevent->bufferlist).tail != (&query->recvbuf);; reply from unexpected source: %s, expected %s ;; %s: ID mismatch: expected ID %u, got %u ;; ERROR: short (< header size) message;; Warning: ID mismatch: expected ID %u, got %u ;; Warning: short (< header size) message received;; Warning: query response not set;; Warning: Message parser reports malformed message packet.;; Warning: Opcode mismatch: expected %s, got %s;; Question section mismatch: got %s/%s/%s ;; BADVERS, retrying with EDNS version %u. ;; Truncated, retrying in TCP mode.;; Got %s from %s, trying next server ;; Couldn't verify signature: %s ;; expected opt record in responseMemory allocation failure in %s:%d; Transfer failed. Didn't start with SOA answer.../../../bin/dig/dighost.cinvalid %s '%s': %s %s: out of memoryisc_time_now((&t)) == 0%u.%06u: query != ((void *)0)clear_query(%p)send_done not yet called(lookup->q).tail == (query)(lookup->q).head == (query)(lookup->q).head != (query)(lookup->q).tail != (query)sockcount=%demptyfullcheck_if_done()list %ssockcount == 0recvcount == 0shutting downcancel_lookup()force_timeout ()isc_event_allocate: %sfrom string is too longACE string is too long%s: %sisc_hex_decodestringisc_hex_totextbringup_timer()have local timeout of %disc_timer_createservname != ((void *)0)make_server(%s)copy_server_list()%%%uflush_server_list()(server_list).tail == (ps)(server_list).head == (ps)(server_list).head != (ps)(server_list).tail != (ps)memory allocation failureclone_server_list()make_empty_lookup()!free_nowIDN_DISABLEASCIICHARSETclone_lookup()looknew != ((void *)0)requeue_lookup()too many lookupsnext_origin()following up %ssetup_text_key()dns_name_initcouldn't parse digest bitsinvalid prefix '%s' .0invalid address '%s'hmac != ((void *)0)unknown key type '%.*s'hmac-md5hmac-md5-digest-bits [0..128]hmac-sha1hmac-sha1-digest-bits [0..160]hmac-sha224hmac-sha224-digest-bits [0..224]hmac-sha256hmac-sha256-digest-bits [0..256]hmac-sha384hmac-sha384-digest-bits [0..384]hmac-sha512hmac-sha512-digest-bits [0..512]setup_file_key()secretalgorithmsetup_system()lwres_context_create failed/etc/resolv.confparse of %s failedcreate_search_list()verbose is onndots is %d.tries is %d.timeout is %d.127.0.0.1add_nameserver failed::1dns_name_settotextfiltersetup_libs()isc_mem_createdigisc_log_createdefault_debugisc_log_usechannelisc_taskmgr_createisc_task_createisc_timermgr_createisc_socketmgr_createisc_entropy_createdst_lib_initisc_mempool_createCOMMPOOLisc_mutex_inittoo many ednsoptsbad edns code point: %sdestroyfreeing buffer %plookup != ((void *)0)try_clear_lookup(%p)query to %s still pendingquery to %s still connectingsetup_lookup(%p)dns_message_createresetting lookup counter.cloning server listdns_message_gettempnameidn_textname: %strying origin %strying idn origin %susing root origin'%s' is not a legal name (%s)recursive queryAA queryAD queryCD queryZ queryadd_question()dns_message_gettemprdataset()insert_soa()dns_message_gettemprdataisc_rdata_fromstructdns_message_gettemprdatalistdns_message_gettemprdatasetinitializing keysdns_message_settsigkeydns_compress_initdns_message_renderbeginplen == 0plen <= 32plen <= 128add_opt()dns_message_buildoptdns_message_setoptdns_message_rendersectiondns_message_renderenddone rendering;; QUERY SIZE: %u
count == 1found NS set;; BAD (HORIZONTAL) REFERRAL;; BAD REFERRALdns_rdata_tostructfound NS %sadding server %si > 0cancel_all()isc_mutex_locksuccessunlock_lookup %s:%disc_mutex_unlock(lookup_list).tail == (l)(lookup_list).head == (l)(lookup_list).head != (l)(lookup_list).tail != (l)print_typeempty rdatasetsigrdata tostruct siginfodns_name_totext for zone: %s /etc/trusted-key.key./trusted-key.key ;; ERROR : is not a subdomain of: FAILED empty RRSIG datasetstr != ((void *)0)nameFromStringstart_lookup()current_lookup == ((void *)0) ;; The queried zone: check_next_lookup(%p)still have a workerlaunch_next_query()sockcount >= 0isc_socket_recvvrecvcount=%disc_socket_sendvsendcount=%dsend_tcp_connect(%p);; No acceptable nameserversquery->sock == ((void *)0)isc_socket_createisc_socket_bindisc_socket_connectsending next, since searching(l->q).tail == (query)(l->q).head == (query)(l->q).head != (query)(l->q).tail != (query)connect_done()query->waiting_connectin cancel handlersockcount > 0unsuccessful connection: %stcp_length_done()recvcount >= 0b == &query->lengthbufsend_udp(%p)sending a requestquery->sock != ((void *)0)isc_socket_sendtovdo_lookup()connect_timeout()trying next server...send_done()sendcount >= 0destroy_libs()freeing taskfreeing taskmgrsendcount == 0freeing commctxfreeing socketmgrfreeing timermgrfreeing key %pdestroy DST libdetach from entropychase_msg->msg != ((void *)0)Removing log contextDestroy memorydns_name_dupempty DS dataset;; VERIFYING RRset for with DNSKEY:%d: %s dns_dnssec_keyfromrdataempty DNSKEY datasetempty DSset datasetdns_rdata_tostruct for DSempty KEY datasetns name: %s for zone: %s with nameservers:;; NO ANSWERS: %s ;; RRset to chase:chase_rdataset != ((void *)0) ;; DSset of the DNSKEYsetdns_rdataset_firstprove_nx: ERROR type existdns_rcode_totext failederror response code %.*s
;; DNSKEYset: ;; RRSIG of the DNSKEYset: ;; DSset: ;; RRSIGset of DSset;; cleanandgo ;; The Answer:No trusted keys presentERRORWARNING in TCP modeSERVFAIL replyrecursion not availablerecv_done()lookup=%p, query=%pb == &query->recvbufno longer pending. Got %sin recv cancel handler;; communications error: %s getting initial querysigdns_message_getquerytsigdns_message_setquerytsigbefore parse starts;; Got bad packet: %s %u bytes %02x dns_opcode_totext;; BADCOOKIE, retrying%s. sending query %p freeing querysig buffer %pafter parseisc_timer_resetin TRACE codein NSSEARCH codedns_message_create in %s:%disc_buffer_copyregionstill pending.check_for_more_data(); Transfer failed.got the second rr as nonsoagot an SOAthis is the first serial %ugot up to date responsedoing axfr, got second SOAdoing ixfr, got empty zonethis is the second serial %ugot a match for ixfrdone with ixfrmeaningless soa %uLLQNSIDDAUDHUN3UECSEXPIRECOOKIEKEEPALIVEPADDINGPADCHAINKEY-TAGEDECLIENT-TAGSERVER-TAGDEVICEID�� � � ����x�����;�r�8����I����Z���Z����[���[�� $\��8_��ta���c��LTm�������t���`t����t���(�t�����������d���,���xd��������$����D��� ĭ��\ ���� t���� ����� D���< Բ��h D���� ��� 4���� �������0d���T����T���������T��8$��p����������� 4��` ���� ���� ������4T��x��������4��D��(4��xD��d����<�X���T��d�d�X����d���� ��<��������t������D�����������(���T����t���� ���!��TD"���$#����#����#��4%��DT)����)����-����2��8�7��xt=����A��4B��@$E��|H����H���tN���N��D�P���$S����T��4X����X���d_��4`��Lte����f���Ti�� �j��l�k����v��8�z���{�����������DzRx�W��/D$45���FJw�?:*3$"\�E���t�W����W��DA�8��W���F�B�G �A(�O�T (A ABBGp��Z���F�B�B �A(�D0�DP�XM`HhBpSPU 0A(A BBBBQXM`PhBpIPS XH`HhBpE`P$\���B�U�J �M(�F0�G���F�H�F�l 0A(A BBBEj�M�H�D�L��]��G B�E�B �E(�D0�D8�N� . 8A0A(B BBBAx�g��X%B�B�B �B(�A0�A8�I���J�D�E�U��H�D�E�N�{ 8A0A(B BBBHD������F�B�B �A(�A0�G� C 0A(A BBBB(�����A�H�Kp� AAG�����F�B�E �E(�A0�A8�G���B�H�B�Q���L�P�A�G 8A0A(B BBBHf �B�H�B�E1 �B�H�B�EH�D���vF�B�B �I(�D0�N8�G@N 8A0A(B BBBLH�x����F�G�D �C(�M0| (A ABBEh (A ABBJ(ܠ��OHB@��� T���\HO$l�R��<E�D�F jAAH�0����B�E�D �I(�D0` (A ABBB\(F ABB(�����MA�A�D � AAG@�����B�E�H �D(�D0�D@C 0A(A BBBJP���d ���Hx,���|F�B�B �B(�A0�A8�G�B 8A0A(B BBBG$�`���4E�D�G aAAH�x���gF�E�B �J(�D0�G8�G�� 8A0A(B BBBA8����E�D�G�HX�����B�G�B �L(�A0�A8�GPw 8A0A(B BBBA(�����A�P�I G DAA�d���eH�D A0������F�A�A �J�� AABD$$ ���OA�� O� E LH����A�@ GJ E$p����A�M�D lAA �l����A�N � AAH�����F�B�B �B(�A0�A8�G�@ 8A0A(B BBBA0l���5B�I�A �G0� AABE<x���&J�HT�����B�E�B �B(�D0�A8�G�D 8A0A(B BBBK4�����B�F�A ��(F0_(H CAB,������F�A�A �� ABHH L����B�B�B �B(�K0�A8�D�� 8A0A(B BBBB,T ����]F�J�A �� ABG@� м��?F�B�B �A(�A0�G�� 0A(A BBBA(� ̽���F�C�D ��AB(� @����E�J�D T AAGL ����F�D�D �K(�D0. (D ABBD~ (D ABBA(p ����E�M�F � DAG@� x���B�B�B �A(�A0�G�~ 0A(A BBBKh� ���cF�I�B �B(�A0�A8�G�= 8A0A(B BBBED�F�O�J�E�B�L�L���`���]D E A|��L����F�B�B �B(�A0�A8�D� 8A0A(B BBBI(����E�A�D@� AAGT���F�I�B �A(�A0�DpM 0A(A BBBDGxG�J�E�Ip<d`��[F�D�E �A(�A0�P (A BBBH����ME�~ E0�����F�H�A �D0T AABEL� ���F�B�B �B(�A0�A8�D� 8A0A(B BBBA<D p��F�K�B �A(�K0�� (I IBBO8� @��B�A�A �} CBJy FBG`� �&F�B�B �B(�A0�A8�G� L�3� 8A0A(B BBBF��3B�3T�3H�30$����F�D�D �I@O AABFHXl���RF�G�E �B(�F0�G8�G�V 8A0A(B BBBHL�����B�B�B �B(�A0�A8�G�