sssd-ipa-1.16.5-10.el7>t  DH`p_$ƨ(zc|ԲX}Ef&YjҋƵJ V:HoU S;S-O"E(-5B<̐Ov*h[ʜ4nA 6aUVUw[ @W2a-{Jo,h N%gN$y4۳;Wepz(>ĞMꈜN;?ԙ l=8˴S/=( -*\-.C'2L!,˗ߨJmRl2oSdLh 8xBÌxr,7zY^a[qb5ObHp.ivJPьj.'wȕcmso mk+úA4_Ά43a0pk=Ծz2*=w^}Euaޣr|?%Ѵ>8 U{<mok ^*~]Fn)n4dae4734fcb74ee9bf49aa912950cc753f24d1ce`_$ƨezN(PHC h̔B]FTg͝n&]řKeTɦ4R?/d\*;:B_r&;nC5=uIx,:WW6^LG w'$W9]jS ߈tO_j©mJIĤ ˎ̠L~]4i:ONfp6~ d>=,?d   6  ;AH    <  <XxTTmT(,1(@8H:90:::=PGXHxIXY\]^Vbdefltuv0wtxyYCsssd-ipa1.16.510.el7The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._%x86-02.bsys.centos.org TCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $PK^t&/A큤A___$^p0____ 004d2787889719bcad7fda2aa278d20b0a84fb231435a44e8ed4476bc388afb1758ac06d742db51f892c2a1a8740852505107b98069a540a9e20aa404e679da98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f8a33530a2f3cb8a2084f5d78927f73945c9c8b0c8c96dd14923c1ac271e76bdaf02318b2504edf8dbb7412732242a8f6d44a2e3481b4866cf10f641803e10b4c962748704ef5acd7b5f3f09b0afa73df24db4756cd2e718a567610d23d3b6f0rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el71.16.5-10.el73.0.4-14.6.0-14.0-14.10.16-5.el71.16.5-10.el71.16.5-10.el71.16.5-10.el75.2-1sssd1.10.0-8.beta24.11.3^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el71.16.5-10.el7libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cc11e4f0c122eff7d8e6df0c4e1b31c42979e17c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=f4861d4047147a2c6f17a5937e3278486fbaf116, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRERmH—*yQ%-!5x72d!1gӂ5GeD[,XOKI%wMZ@~<[7L1ւm1 +:SfO_?$=ve\MkGH"gQV% UhnHNø0|&6)|]!mSf"`j[9},픯d86#2,oZۼ`ƠK+@Zk-BL]Gpn=l%2lomѣߍӒk)tٯcXbjF#oa/B9&X;VQ2PVXu_sHqGikH" 7'`CܬnSh~t6Q;-bi1N_j+<)Jˣ'ۤ$-z %~^o+e-xh)?sTo[7 a Qm5Wݠq yR}rAE€3$鹘Krx\8aEoU XUeǒ4适#(:5RwV%Ffވm?_ɰJS>jQB$1 #+Y d+>b!L>в2OZf%jR}IPq/f-ZZ{;:ٸمZZ^f8{?QiQAp`*YC@D~߃J aR=Ȯkbl;LAIY 1߹ j`Z_LK\(#$js;nХi"Gk1O)7cMH/¥`lzR.hHO`%Q&% .CO*c VNV{'sGT+@x+TaGᄏhPEkv:L枷[# |_l&#?L / neKpީ"VС-vt*F%,]?D(5:,@I {6S6LC}2w=]T+:WR]g}G)WEgZw fgw,e?җ~< "K논¢ohpgVnlmE_ãR-JtWc5Tt 07S#;9,IĝKbrs1~19Pzi;rNRɂvV^3Py8ԜlF }њ$O]|8R?:$N'*Ei؂߯_s 7i҉c?K;8sǩ90"GoePTj׳- faU{sa.à,IjZVt)Nkʗg6:6rmZ)6d")(нQsJ q%S-=llFAL( Xzm75 nd: qS?9ҘP:bq;Ϛۯ1% /_kTEt:hR8CR)1c}[+fIGx=>uډj5Op`ؗXC ߇`N^:mS/N3s1*z40E+s7NT Op^*Zn(]?h@W aאE ])Z@@AQ]=EDsi"L4^_#mA:TvxtS1Xk JcC<CPԀ'CZD1!:c-˗ .|6uJf}-C.y>iI" xe@yE4L<#.m v,d]KC]%LwI#EiTEw:|U;y&k"ӏs, VICJ!*h>8IO'MToe9)­b0 8j M%b7l9%`s1°z-xG9;"m;0 :W\3UYF`RCM,!tH̋JӐXx1V][Gu+X6jlPṨdac,IJxDpoq䙄Ze,T@=|kp+#W,KתiGeVNJU\ w֚7pY4cWⰽlh0EЈKuDq❺[ќ%j ~r3 4zb٥w35}NF^ֆKԲeKud}ϖ-_gcm*)?^w D Ϭ10K(~0?gIٍ@V8&x~Y!gne/ -dZ68+ףU[Y.~-2QǑ+nw(.[W}&gb9Ȍ @~?DP2;#&?3)&]OUD4selN~. dHŐOou'~Bkc']FB-uTk8\E_jp^)/7 _-aٱ}R`S2 :dХ-b5>3,> S##Oh-RZ/ys1bmbJvd(~dd]-<:q JCDFnv=1:Rz5[^95W>JY`ɜ' 0Jï H L z_(!8 " ˲ԩiߌMMJD{̇|ͭ '!ZJtwUmf_R }j6',/a2XnYx?oS%D 9\8 "K7W z${IXNxJ8*MQU s$6m/NQA? ~ {P.ʬ݄`)ggUx+%eRcӦYb#ݔ'+QM95rʎWeو+Cbx6wUX;_|xn`%Y i-Cd.}Q6H>+(t!V!f7 6a6{mMf5$,^d){~9]a^n /jX&p7ku.`xH ȄFТnuh0iiQGT>¼ hQuq"Z6U,25bEif{a;uP? 4b<I{GCb8-xbX Ig݇_uF .Zk8|U: L&( {O <5pkH `\%f"5lI 6)Ѻn"e8RJ.*0.kai'2RW>Ǻ\;7 1SιMu-tY 5_+=fs3R|ɀ8id6[Dg{aF ׍82\4uBqvSNL;mIyqĸܓ:NJ+QӠ֜CÝ5glj^o:TqК!sIt r-JYUp|ymb_!Fތ3Rlԟj:î>\><^h'Y3v,.Ŝِo 5d ~6@ *,Sl+B G@V=oc}6mg=.}^M8!7wN2 &gdO>zVj\N5K&p'dwJD)IHAL?9jt(okO@SD tuՐ?] M;8A>#-0Ͱ FNf1!8-` A0Sq8 Q3!2H}B}]>o]j!Dv 2ԞؐtolVó n hM#J{u̜c B'F}L!-47MOpWiI.LJ.iyrץ ; qΑvbW~sp], kN! 3uFͦ=[W+ev78L|殖\ c$q=U{nޘI?(2E*$*֨ AE6kƄoY缒D|56 [LbVAUM9 =Rr5:aJ:{!z̿  [~n(D`iUmwJ"Z'J'Gm::.xQЎe/VAjDdP-÷c^"`G]tOia k]y2]eo(#ē9\m쎱҃q1:aRg^CT*'[suN /A2 ~5=ena#Q=xOOK0,[u{+'sBzͫ+ɝGKf(ڙY,BBIi̡H~A۠u,4^P8jHt#}P:{uuo<-_ ؠCG fZG& {̸3٥e [=xlLι P KB YZT+py%] qV݁]ڇ1ȯ)Jy6:OLzP"f -eB2wyoi3>w(k}a҈ʃPS }Xi8?Ș)%p"DZQSE0P MqQ6y%k> 9GB ]qt|H,qx=α,FþV%TCvZmg1Tj+!G2ӏ(MJx; qO qq~VhIDS?U]:A;͙:Ͼrq|`xq}ETZ#/Z<M~D1fZ>P2Oң`1Q" iEC2vz1H? ;ՁӲ¹ëiqqOb wR¤=zM9nLeN4+z2`Pj ,dj5G&-#W}e)̲vLKcfzKXW]HSīP^\O{vF-ܟdC[U*6xFVRGwqx4@)9|u}6UobجglwݩփȢkb/ 9i62[s*->^, ST9;3phj!F+@s0s(m۠(oediF f QV)eG^yqt׻Ξ)#^% Դ\#pXTvs.2JK]rIwB%>tJ:fF6.}T 0PkŒ1PXx^|vbb 媒#VQe^);'.ҟ_)8>痖 (XQ;,?c0D1Q'zчԨ^n5OwCS%Q#2y4İ QŤ@ fB98>(m<"3d*Qdx[}jOZtY fw2q) 2ث*ͨbM/My7WaJcG 5DƍkycB8*r'+o S2<M~lCU<{oedawV8VZ4B]ZkŒ`U3ġrZ?eX\?`5ej5y/(O\݂ZtTQc b9ݿ\̚2Тa<uϟjm6/)ƌgʰc0^x+:ZU9Goï;4U#8ҤKHTE"A uuE}c ̵j}ǵə.xjU)]hq;ӗ$BXl Ul feW/@?c-)-݀{(9S-(MM`gXPʶnZItXR<1tR>^kKe5 z xDIflފyI5CLdxNi"$=;_q?d %o/g^Ac|@@>ߧq-7GXz9ClF?h;R{>@8ϗ/+3 y:w#/AbmYA 3NBIcPIryXZ] ^4qeW۔) g  3yR^"^6ؐ;ˑ,Jd!eaDE @5cd5"~{s'tcN*gIAZHju Y?(4-528q)kg@Rbu?a[(K O%r`]?n_d 3 #8k#eqbɹ5zgޞ;^Ko*'-WGa)r.g6bi#`$CSk=4Yh374U }-"CP1=Mf$Z\KjzɃe'4%$ƻ8r+Hv]:r ɜ;$y?p=J[ll+:@!춐rt?u2=8Re aIY``8EaI^gX?hcRj1=MgW:&"oϽn9d^=3>X١fn r?BA䖲hӈ|-?Bϵɡ!MyT$&t<魒osHir\_$&rx)0^5@_Cv'Bjhjo҅q>ߊ=47=PGf{[;MWvBLHԸ>Iq'UdYW  ;(:Wgw,HLca..\3@"b>yLNnH e58h4{JStSn,4xWla>leo*/nDSx!k3s*R@ɾD=a'I=)}#:Ud06)%WZB+aϞPős;I30k{\ORV^!%Z@5\FF1(8MReݞ?hٸپJ(gJr)5DL4Ž{TԌk?fι-u =%uњ;O1Rh\:B>d#Y `.DT>r|y`RA+OQ6ʭ. ߻YMoxY彫4R9k|Ƞ3iyLڷ]͗nUuYC >E@~{CKed=_䕴E|W~fRrXk (_*-v*O$"Y?CqyyL&0MwFÅƂF=aYA(?M*㗄5?| wtXu[ ^a aU3+KkW#k:/rhH[Wg(8c]6ur7r ؉Qn 2+b*o^MG"g7E-aZKؐ%Q܁L=QoV(K`Le@h]pͼo$%>Gj\Sm))%(sun{F~̢)y H#>pwn{%稖'MMoC 3;f,=Qw/t{`Ю3{(Fo}hZP.޾)Wpe()[8B}yvBDx\xO4Pm[$sj c!CMk* (ZJyIyF)AV@hk((d)wPOZ0lu;LxgzpaǠ܂i%ֽm3[wmfk9]Y"Rw[(?_/II[%= @M3@yTL#" sJ9 p/Yį_Ģu ˅PZO:Z=~f>jeVXdΐᴀcE]֨GVc4i+.s|vgk|W:T[5s\\x:3l "^c|7}^[TV`fŠrEkluJohxt:v'͸gi o2eP긨[YޓJ9ZnCWNdC3>|َ`ˣ\Ońǽ ׬ iWE׃TLg)2(VQiY$]p~_jqXΐ*.˻Ӧ v 2Eg ^ E X6nj]%X&_PNuN,e>1V,AbF'7O['2oɈIЖ@FE )zH15kZaC 2# LQԮ!Nl3[gy#%3=.8tUY{G7'/a׌$b|)uRI:#h;H= jlVgE)ބ;k YH$$dfzb<ސ:A/)532YҪ a{T=  dcl.m؝ŘB鿓Tq8F>v֐h?:fA 5Cpup/;7I<={M{ '+;c(wZk;hB$VP,XP¯1y-ٓqw_E)V?#8LW0Qe-ʢvHz1]QxY(uY[.zoG,;J!%1PAJȂ$18tR!~H|ӊ1xyVbt-|%o[ZsQ6Ť 1q[X]}'`b@!ru %pچv!'㮡|bT|ۻ[JNS|+yY?+=_dYgXeOC.@<4YjZFYg}O[K8$:GVV$6EdpfkZ~f`|:P#-蜓R{X=쬺}kN~{MYX#,Ҹkb)bԥՖ-[bx`_|ƺWd6]p~?H8@/+.0R D\~+DHIc]1%bKTLA\AVFw].EOފZrR6pV1E)6lNsӔ 53=VBL-mwC>x.5vks6z+G=hH'(46݀櫍aHV<nޔb]D\1BR)jMoReY{o,r3tHB­(Y4/I@DOH鴕z(+CHEȎ!v2W)ykH{~ &yw ytZ m܍tJxf|S;%碂wQR9)G\|,Gof7_G%EL @$W%fTFOex\ZN*,Ǻ@rWi&ikP 8peȑp VOA GPjdTkC;?n,?D&wӇyaW:pȻjo&iQx["f*o5{ .QrP^@z/tNj"6=.quw'ϸJYVYdoU>C&Q~ rrj(ޞR\@%fuhYiTNHV\OL:Ca~AͤY?ߎLPm 4bÊ4dוgq@ %2c!>*BSV| I;(+ؑugV#%h(I ,ܙm`sǝES$|:B`Zi2 )?\L_Xb09#-١Qe_b8Uݑ'ՙmDZ$ij1!S~9Zu}!%E'UC7H(CABA!EZڒRJ!KqdޚbJJ*t[b {S=~m*k#a}g]aSEgQA{IJ"d 5N5<9J;[K^ɼ6:Nf޼):0Cpfvi@Ua[ɐ~Y_0D/BOilFZfҚDy3C9 #%q`q:uq+$CC!dײV$p3Qɇ藸,,H|?$S@ !Qfo LUvo5D+v✾}Wj . UE;_C@!#E. Rw2=]ұxtWҷƉ򊙯q)t\~0vԚU&iJ4LiNW9u-KuKbƬӌrXtE< BP*ej{ ys\ I"j4Nu_fb1h1r-{ܗ9  s*St u`]Bj4*zaP Ո[RxF,^< Q'c݃4WH9$)!gشCOs~>ѯEo4U]6SKF]23>%߱-]\Z+Ǵ!465 Ңycp"5I *(82j{ZU Cw>F^d'ˆ~hySrLlyB3DAk z_ ݑT͵pf$m.m״-3 Es2glAhq^Lyء@;g&E pOvܴR p`̠QA5yU^Od{J2*?LR`o}]%vhk B9d6y'#\{&N>tc|DqV]7CQTG^SHh33/ 2[ %yn#Ɯ5psAg\O8&L+ݏU J}e|#撶 j Q1ʆ-M Vdo33vò JՈ.4URomM$ PMя'71T2*BoQu 3Ln25@ol{셽!/g7S+,>"C"w&|]$Ko [FĽۦMBiӰ pȹ ,DKYպp `gFu];Æ{MWoC㴓Ho>H&}NhSj1DWe EॴPI0OSpBc-iݒ?UBԮ.y݉ko\%*L&Fb9ppTYujKB: bM%j^XxwmSc ܭԼ6N݅Θq$:F|ArzRRAEb _δ]G{Ru@Q\}MKKm[$Eܚ~ >@'Ĥb~2R#x&]6Ib7.-pY'HZ /z<+ö1w6->~T/Hw`3a Mj4[`). 1Шi#AJ|~z"nwm9Q?u{k:)zs8!qt>bZ]t;d/;pi?r) EHl/|1"+Hߜ֕l|FCobуYVTVyy8r_W~-r0]kq-QR,auUg#{n*~m4 Jb `;_+W8p0g;Sefz sN~{<].gLU~=Gs|Ĭ9{eHb~QRz?1)z캎uu:@qZT";-v$U.첖(IT6/s<؋Kx CW(aHHHP&u弅8 A) 9LS7HhNڜf/nLs?jW_f̳@dɡ$y\$C9Es5~ r _[T&їmtAɲ UZϿnqCζКg+1]?/$"CB:8Wzpe~dmqBxūkgOfIu;v ; u, vwm9s񕨱 XkZLpXd"jBpv\AOM̲11u[,P'ã5^Fys7ܠʯ~ IT"6؁uܡ:!W:=žwi $IB&E˫PR =#.wоoھPF5UJ+ޚ "p u[j[_VPHG盲QMj!vgu+5ݟED:x=D J㼧|ڇʤ,G7h{_SoWnͺ;RbAwCߦ]RJdQ|`{IuZ,`zCT $N[hESt6}U@z^@RP10sg%="?xD/݈r(VfަtVυw 4<{StQՉ 6y,o" GyLJݹ|Niaf_:\hu_HSt l".Jҗ b?I}+$ZOM:)HO_iܪ+TKuZ Uq?v?[IX! > a^Uk'X uQC+܋ xA?qZ-2 )eVW.6E̪Cb'jtVTT!a|ۜ6oec|b7"NmrCzSwޚ x|XXOeeX]J&aezMU`w/$Psm8qJԋ+c9$ZMǏղȑU~$ ^;j5#[x:&<=ZRl~0t w@rQzjJ^ɘVkY}S7X*fPYxuO~30(XkdEUQc\#a F[.>Sù R'BӻN?Ĥ)Ʀ!܀NlXƁ1,E/g+] Z&SN`'iPx=3)ܕx^T:U}.`ݟ[s:k~C[V@pBIi/q} nԙ*ie&`F$՞X WQ<"L4r/3Jpw*Xae^y5 <5>~ N1U s8G%sVWI:7ڠ+,?<x7](CT5!SO0;*-宼՚zDkua巖YMP$mhP"VrEߊ6wmrScJVl {THtb Cb[ro5!_AFvu؉w^A]|a 8&+0BV, )u[YDP¼q#X?K?쪵Ѿ HT ӮWm%T=^̰Dw! 3O3YK[8ri:*_m?+;1ڈ7h-hDX7󴉘A^2'ֶ)nDSU/XLѿ,^ Xh9e@-U9YmfkI/tiTCu) ?6cN)Fr^d0\Lo@ >mR]TH@x(㞎iClC鍛n] =O5yF)p0Ok4u 6d=p ,8If ?'{ΩtPl˪GRx9/'OYǴ^;]5BM؆(CG&Ȼ$ 6cϘ;V! KՎ&Qj91$Z|# {Gyi7PSRwVjJ|R:.$k$h*6Ԏ{RG0f##1.0^$[<ȳCG31 ͷ.%Ϛ餂!(ߣA6m+]KpX ul<@_^k{H9‡E{C Afdz iQū 0GuR֡i%âkBkN2x$ʂ#|L, Os| &ʝ5K0LQaIgL~^oV0'V Wiyjxs]9,SZ*OCU !޳q0ު0t2wlfd/LH#;F'y`3Pnu/ͮPR=Li3Hu,m+Bᵌ/4rBmSH d8\H" FDR˕ V練FRKU"PcJY}0 )R' W<ƨ@%eNM6XZbAެy'agO{}PC@5"gP2A{ՍKCܟM2c}Y MM?-pYRE/JMP6KAt=Cfvv ] GOhƦhCmmuHH+#Z EB W_]VWvqs?p''t!̋}k0RI<πsQRm;fVɝB!-d3"#𨍄t 3Bǜo^@bn&)]b i^i=y3ĆHC{pV#Qbww%&B?E~ŨImV7!FaV2:`?;,@2Q(bjY0OT^|I2Gø`'2\6IM.~lc$^ A fRZttwQۑ-'3H0%֜qEߑo[a0Y]c|oD᳁8XD\̾ &fjb6n}^$RXa;}ρd^vܑn|!BFDW#Ŵ@$fp3M=96fY0'ᴫGd%9KIƚ6;U%dur#^>q_'E(/ʴaZzWv4fR$sY<!a{eO'ٸ[Ѣi$+wW,GDQKȜK+ఒpu5 bezͶ=oq7Mt7_g࿪9,FtWA-7/R]A .!XЂUy* Gs oo1MoC .9o% = o|2_4gfʿnr#Th S͇.%\5rgIuiu.WAWVn$˘XlĠ\xX=\]b|F]/~ܣ^u/\Lru=tղ#>!X庂2%!ˣ?|^|*LtiMnB۰G:yh8YNKU -XS?m PoV3p3n/0t lj`Her ץ|7jM+:a=ve 4( +o{"J vW/sL|Wu裢%%<.X QQsԳD/jfJS=Sz/vdŧ(kUAfUȦQtץ6f[{`lgGOv#0 dbDk&;iw? `q yYF K\N|*2H@ cևIB5X7z;f" i6iX:/U~H \͚r먕zd<;` 6W9R#Ԓ tc,HkbJI50ӆu;6}@X~}n`b! Y]p@5]3Pӡ>Pv\D0NE15(jd ^vN;JQ;ld\c{mAF5Mj?^1G7ڦ<)ueYR)TVjn>! cI#vNzJ6s-5 >F;d1BCXHRD?JˏנdXS yƉղ =9*NJþMݦ"rRҢ_d!7|fIO}#)/}3M{9~$R5Z7w:2h:7'R6 hCDNL(.5ǚTФ71a"7pIFKRF jZ!,L: RRѨ ]\{oT(՚*Qm.<wb gp΋ɒԑ p:# Ū?vќWx| 'eY3o#t +xpes_S)='rH3,`?8+jLsn^J`P~tQi/OuzE{I8F; sl\4rځ䑨09>رE{Es s}ϗ,W&/9r}+*PPGL{yБc_~ "J(yrDc'n` B%=ܤ$.9ۃIKNOf:X /ڮn9'P!!g ]Կ /~p*EFSLVe.'dڧ p7ߤ§VLĈX"EZt7)'4/)c>}*cAuZpλdתH6lZ_CT &C/1,L ʪ>oe]餟ro^EHFn.s4F̓mJfƽ}BMmL` .CI %cOm|4攈|"`0 ?ҽ^ 2]iP +*/PIPv*HCSHa'{zYI8#!~LzʺetTê58DCݍ_ܟt Lb JЩڇsP$\(wEVKTY#)Ш&PY,_Q{.4T SUKmlӎȵ6{<,FH)0q0L; b KiY"{CҭGu6'e97 ʳ>M.6r 04: ^Eb3K(zOs\D IeY9onP >](z,. 'u哤ʓ*1|*/n;y|&^XQR ,_}$C8mAZ\C?"\?*$a2ȁgl ZT7&iQC WH$!>c񘠽))(!>Vz(^TעӇoz^&K n  /59he>+ld79@] w Tî.-i X6rK콭M Z< V35ytx8\DP K֏F5R %[At<]%s.&R{Fߤ٭sHynRMАʿuW+Ѕ9H:S3X+@xqÈ!xrveUv18 M54/|UI]u@DH,T}Ã*?b<ΣB szz|yCf32Հ[D`Eo/k"[Wagt|h5vevN?[j|j=NK*]wzCus8lWMdnLHMj4"/>ΐ@\[+S"v>׾vz>Y"s 4(x֩x/4~I$*IFǹ:5{Y-7O¢3O]@!l"@N=UN?za`v#[\b9^l^&B,  ~LК^L ]cB¦.|GIFbRG'&pDVW<=3"-K {NCbTPhH}oZ4k#&#$ZЮe4. TT+E]S#8NpaY'j7ft'aUE-Λ~s´Xj[I0׌WģҾmR"\8u"5} ҰCt,F `HV!ņ"*\-R mԉlt)5ĭĩnֈrŦYޒ~l1b=XJ?R6r6dSa[[CFI70D' i[7._{RKn"{>*O G4"W0Nm4?*Մ]%tcHgQ|Mr٠"x`!/'Z让 \oZOGgFotbiW;ZKiH59bO|d\(#̟[W8.u8mUvup%(WLWL}6 X<+H<ҧƒt'dh~@Jg zJ8;(CBX}yձʏet9w6Ns90Rw_7Kx}qHB:O ;}.^3+7pC؊UvCbIE@!!G: q^W.̪iMSS7yOp&8W2/wQpfQQ(+ ={ p]u!љ}բ$)٦/` Ʊy^=&O[)SJ!9UW"1 F STYX#=PS =&%D2Uxq.swLiWEIo^"*VSY\U(9`o`9p'\zxO,/7J6ҭ`@464]sY|} "sgKsoE]8@En匱_b.CvS ;$xZ_c``Wx1qDPoJ% 춁 I ` `0}zQ:;ɗV7ٹ-墝+cEZգd b}:QkkW96 e1C5k޾eOhZq? =SOoډ8ʹۉ="Jߊ@WJNJVӻS@dv ZdL'Q#&P$֤Ւzj&ʹ(78l"&.iCs^(ťfKw"W4PH װS9]]P8JzC|PuJ˦ʢ1^ mmes"Ӯ}27b79?oRU|nG n -V5=b(I0X[w%3}ߩ۾e#f$wz%"96ܲ3%1z7 < YMˇ{@_UD2f̗Y; | >{/R$Ch;*;]xLx PWzjr) DVqzS씴-P,,!h!dOеh_dPp-%@}B?i(zo^rD b(A͟ZFPHdov}=eǮچJ~bߡԉ& LSsb?y[MHzB#7q8@pKOr kxc&qryVA9!c񖦼PY`XciOzPՑa͏M- lN4#d&4\f ɢE[(/@%ncO z$7{pzZ94a¼Z^T}+7Y=|uq<2 y]i31 G% w zYL~xA^gØA!_2|lUInjOV>i8gS?8qDH|`# F$H h'ǸKk/!|_PA;޺cGymEAdڣ_Oy%\ƨzmd(` QTmgIxLD8b-6cfj%t5@;5:mA`7nЅx5qc;*q[zxVlf<kVM{JjvXc^t"κj'?_o}*/c]bExXu"{˨VYA !q-)\Fd](De3rŞq~lKElqۺ _";,S'vBo.qhjx׿_K~G}KvK(>^q{=Gπ|5&ZBCqgɅ?-pI揜z{|߽2,9ܺ>'t*T߲=EWN#hIFCGfFXSu񾜂Qէ1(|t&ߨAPd>qґ)'X~Y a_'u.If؁&\V(P^G4&9BA8V5#/ե@ǗJsm@cCub'J] 8nr-JT %4,zyZ+̤W%sIDRFQ i B=+2=}ǒ>~#`s(NsoX\(W~z߻ä"*cDAQ9I?ڝr\pU,}NoQW 8<ʃ`yƴÍK'4; VTWFxJ (Qx|Z4-Su L.$1Yo/^ Ll*_]ggM@rDלcus,$~FrdM?0;.b+F5֠t-$5ݤaexRnG}77 `b5Q[Tٕ/5T1WcFϖ=0sk[N&wLR$Ds*v$aI*FKNLL×CkmҔ{a49[L5$=q@b[UjkCJ#^-"xϗIv,s#9 %Bu$ z,sc]VMN%﹖J@NMK Hᕼʞl?Qg9o,Pė֥ZW Ve+ZdѓG'-D^dxGmZ$sK %MRbažSleOK5f*ٖZ[ep>3| ^9:^gxb=ROg7}/_+x Bi26h;ĵṋrV=suWBZjzPNWDy$ﺁry?ʏ@LGN$bwNXKyUiZPfG#w@n !}# }ؼS[AT_)'ɲJP9 AT2~< 6rdÈP!0_\RQX7ӷ_ZMv,q*hs)p0H*5Thj7!kcӦ>hv68b-xųs,T|BC,~z|[}o3 ߟ;w 7$JpT;U_ӑ-N,haЇzv?@DJAjza@gQ|#FJ9fӴ6NkNW_4/캸7ڇia5Aj-cߍX۶eXE72^1Vs~(. ("rxaŭFZ˅O0NϔEʏAx!&UwtUڄ9 oؚiiKnG}5۔ ub,hw!䭠YWʏWZpl}o8}ÕTUw n/gMľ<ڭF oKYn퀭sJ䈲ժ}jWzP<hx]ΰa F6. n,Ja0nl"ku<%!g[BSwNy'𗔏W/Ha1SKcV?z9((8$ O(&BeF99{` dUk5>/A uFf$z&WDX4ֈxXd(FVfm!H4*qDpuiHa=hh,< BgyJ61ءNX"{O,3;`;k)Rd'@ZpðNk!$*ŵ|(>>BLUqr~0!pefUwSPM N Z"y[ʏ'AYT-.t/VFsk | xO<;z1nsh֏Ew-v {8@,j;?NW4:43VCŠQ^L)pYtE`d rU駱ѫF{XeH)EaJ"W9LڥUIphR ֏J̛.9/|靣(6~l1#'O0KW9-ʉ8ѽǠ]'(N- fD{Dj1~SYas0uvܓ# P7:'~p s5SE^28qعzR 1g(ļԖWEΙhY՗Zƨĕrnbl<ű|a/ 7 P!ߟi?"|sJsSd&M0b`;ck}cmk_ OT;i!lIQQ E\/J:1)gX;eh2Gr*[jOJuI]^L7^(<|[;V~L вXC :J%r8}pB>qpO$/vGbS aze!R`ssZM0fP~& #(B;)xЭ8Z "fhN|$l2uE&P~9/'wŋVe[(\x)907 W[c/4pUE<A;$ [>&9=m{%5=ɹh{\_諣}cI( DcWm)<K MY=7%cE]M5گGN(M1g~Uk! 1(ڋ o95j^y r|mw&foNJPڻPQ)sY+@8J1hq C- u>f@Dm#qټr "9`&(Ν⡻ع5<@ǝh$^tIH5K@r\M7^"?bF?U)D D Spf 1 :TX6j΢ DвP M6G@]k#V_"81ۧr5s&<ӯA%7)ufn;tǫAܰ6.]u!;Z{'K:*|\k:T΀VLnvy 89-Mᴟj{eY֦\McPfk63X@e?K?LZ_)Y`זlP< _ܯA;;BڝF?;V$K tǟG15ϕ*&D)nbH!пD6h7r=-_Gԯh" I>r.5roSCnmN~Ĉ88U˴$XWkefp#c,[|F/fc"^7ȹ |gPn~݀Om=#~.v[nq܌nX*-9caliṽ-Ep>F֕1ޘFϸ>W_-1ГE|gN{%.|j|dX\Mt1 )>o>&QøLBɻ哰ymqÓʗOVĵYAϜ175_EsQsߝpF8u(}EשUjl,(?p f_/S7u\u,Vh r4U: Qu]TNb(CSږ|x!h?}oVb*@ ~MFJaLwRfoM𓜪qZk2ʺF *Չ?N76kISR~ ꄥiՑ %uW6W8915#x`~a4l.ҎR?z[eA1m?֊ļ74ӆ"2  ў$QSE اtɪ ` h.i=3f I梅 bvJZ*x5f8sώ+IAcⱫp݄w<AwƁnmrocO?䟰[6^ә>0jB纯JN [3{JFq.%Nț=4&W| '4%ȖqmžF*K'Ns@D{$H/qKcW4ziJՍkFzȁy_iPz+vK.H"$k^r𸺿>8y1C8D[!TK~oD m|rAz':xp%rс*Us`OF53^[SUy%J̨1$3ܜ"pO_b7wfaW?&0^+$NX cƶjEb 5<3pZJ 1 oQ#Ψ<+@Qbܵ-"%0NPRbbXy"C?TC&4F`.xvT'O{59J7= *@sa 68 `&DAVǤ\n :ѻ_pfowV6?7J8Qt9Qv…\HHư_:֫ |pG(ROWP 'Rk5h X{`qH;i VsMɖ#xCgۓ3+i"K}MdLqX#Fhsۆ4t-I!@Fgj3VF v=&xbl>q}Rf5{2md38{s{>l{i}Y*Qg<%[3uw)/=ZDn0@zm^O~ekjΉG k^V(wG9ؕHLٟ"vbN \nd7 $U [`l(E8#//:)^K ,IʩL`_CkMI ]K&$*(D|ݷ}E['pO^|SZy"C{ []>&2N}v#C٢ tzf-=jMEzQ轮$LFfR*˭ks=E|x(xR;w)j27e/'$WMҡe;ˠ{ZB] w$#nY,S1[{RJviU'5ekC73 `|bT[}Dk!~Dj &0:6L_&>!h/4d7w4n!o`Uպf4"j8˚8pNAF{r5NR0U/# Y|n|jCBJW_?6n(;J q¯}'ߖ#gIm]M?좉EMbuFLƃlET#f*9jXZ;0ޱ^C{$,ft`jNJApN7V4E6Z+Ҝ[XÃ` eCmx9Q>"S>G1ήM⡽OS+6 8jGŐ P;&V^ 00%5 6ۀL WsTD*rv]Y疫>dB#M~VʚɷU=q9=ϟz85_fc@ ɯm?4 ]- {`'f]f`OJ$VJr HJ V F&p LYE LOꄪAө :lL\[PonXdj'Gi &C7dC>یNwrhvQz^/mYEoWaZ!R;2D=*WGh WBu5|{c`lA|X3f5$ gw'9"^(V^=폍2B,mY)(_)=HG1H?VML%ur [;{ުCG'Yp][|-.OZs'<~>vIM"on&&hdpVU 41vnLH*ͅO4E0ϛ7B1GYT u%5A/^EҩwT|7^*a ?!EUCgB 4mjA B^jlo,!.SlR- g8̾ r!wSpT|k^=._hg.㥖a(F$ﭗ.Q?L`3J'ybз-uېla6&VT8Z{x*=VnuGG$g@XgTAz*ML C 'Eq̥ 9-iD]> /QY.gVNi_&cGW>71E^T̐O(r\lThdO _{PM@;Dh;RBqgZ{F_Cu{pkdۃv`X1Bhj!=F٢߀`~YP^?2u^TPu㜤`02tlHjJ(O/\(}9 j@ PΤ[*&.ڻ};&ZǸ")]S0H& jn{ 9ѕ5I" nR7PMVH;n[B땥{K,P-͢9NŲh5T=:l ԓb}՚2(PD5HaY]^Wo-4:ѕ^ \U>%ƚݗ`k*uWf>I+[&χy,>#H(>:|;RiMB5 Zʗ#m(qFNЃH/ݵ3Z C,fG %b cNf߲F2heNl;߯#R\~mˊ{ruGm y _BoG$SŰۍi ӓ}4P T%8)w\l 'u*AP| ˤx+xg{cΤXiJ~'t Z4ٓIIx>s7.0U.K꿶@>DO=CX6Oi8䕲Tc>QTn!Z6xZm@o;; W3 yj$l-_:TV^ҔQW?ٮhGżʁgM4 =f!SV!۾ 31I$57x`Zy@B}ZkƆDžBT :5t3eg^@,1fMdk|e8I .冗 2Ġڣ@tT`xVX 0ؐ,GK0w4/F%w TH''9m5ͱkvc%.'[9П0<,UW&;P?b*nlH h`;q&grdҷ1?ڽ#?r eh'kuYPD]_9dAOhV[-6h;iB5:f̫X4)i ɞP_ru~.9WL֑\&]U&}ZbsFPyVI6t ~iț F}~CRE_I4;Vvn+ު߁YZ`4O]9~lEjD!b[xtD V ]1dEsxz>35 =qнj˪uT"gTsM#Y t*Mo[Zv_on4%YQhN(T~1F2 Xa”vcuH:5uA1*Uw[mM]\ٗc;Gr]CqB]jǰG=NUJf=>@Be)0;/Q2TKVȪPXLv*T"Tm'Qsjhu*'lGx&Q:&&N4:1437⸴\_,iRg,ei14>z[UaÛq50 4yƤ  ~ 9t|h+}pMϢs$\|5Q!m2QI~:08c⼖jĎuPwu6J+ 7gI4)ظTN L-4A1 ;cfemڋ릊HUz!`$Yg`DK魝`lyz,h:#ee}L0h~ Ưܣ R F\I9Ao5U)n? ~x>.!߂)o}SEԡ"sp>+ڝz!yy!dFMW ;dbq|-t:BT7vY+0ٳI׿YGKy5l4.S}/i BB'\ yb`5#m^G$^gDqZӥ"Q(6q,ktavFJɵ16!ư}H:m#F=%w&Z\-z%>}~>xG ehB0Cj: \ંP>]pQj..Iݟhw YR_2B6Ͼ@ jnk C\(b1Iܖgiqq~dqӇog0vOieH%0Epr61< "UF^obt{gǹ{54K 4+n.STʞZ)|+C*;:AK15ɮĎg*'bJCl/Lshaf"7BQrʙxǮG'ơ.`χiiQc5k` |4b{a,zn!rkE-^Kc|si;_kAQDDR)3"!Y*j96{Oa^|Iզr [RL 7 * D1D>|N (y7h&g+(8E_`yړ:s%A7֦z$IroD$dI)I7/rVJA|[J1ՉC *NR;FhheS8FQ5#oϬ#,aV=o" ceØy cf3vV 80WavS*DdsvDga2OWE_S29ΛZb+Y`> kj MA ϟ'4_`;.78WR~;6XVCԇ//OCgt㡃muFo`f&4d}HFEҀ [z# pB^#/k+# D3kGHPOcncâe?z'm R=?)Ӽܯӑ጗x~ ;!-[ (샐R;\~^7*0 $g}Dȭgn8z9Xpe>6Ԉy=.:,61qWpjYdDf9B_zɍxRErr8^XNCuRIDgRI{fH8ܫ_?H) GuZC-D3c8'^Ԉ2U^d 5G4, ǮO~.󎤒%$9{B_hE|:B@!UEU7D `]ǚ*?[>ēF>< 4SHr r[Cҹ?n<|KS*~aw#5khZ"L;}_/be7%x$h(}OWpir HiJ9LfSƹxl 1%@E`mvDN&e _L)s%Y%gt|«Dm7@ctynιD?X A?b6l=%s|dZ'7 B16Zo2eZqGwcaTŹ_l yB>X_UOQvO&%NP`m(.29F+Jn=,rpd:tN}7vA Z);Agdx(o<~P`XQAc3&Pǻs:.oOx.[4'zcYnZ/C9u6M-~06#߆F'l >dx*~qe?j /Z8(ɉ"?w,3 fߌ;`Q%[+cN[{TEnbŨ$^Klϓ#?Wp58K̪Q NQtEM ꝷNi`.nQ!X(`E ͊X!Eo*`|bVEд:@1'JPZ_8^N9?hO3'wʗǨbw斗ř/MZ:Ṭ4 [݄UT]daKXd8ħwL^-f]ׂEE Pk% uEúBC9έMao2ő{W!B$E˨;nh9B}&3E6c;.U7# 'ȦWTd!<# L#od[SBKo|'yUlzRSUѸ ^SNNj ZS? eP|O}δB_wok&?j|JVj0D=Na>]hGyozB͉Fg(?QbXy%Sev8gzi*H`~5 \0ɩSfzP5ϥ.gs+] }MReU:&x{PHVG)rAg~bv+hƽzcur]1Xh>M I6#Jixڀ< 'Vx1д͙(J-ZU"L0X#f!^Ox}zP ksfxfLR]d3qA_7q ) ()y{nx_^ʃbZىi:b)K + Sl@ƦN*SfO?qnl_6F>QrYmn&i @Oz{Ѱ8"DEZ+ҝ7oB]Wx^2wUq&OՁ܌ 1W'wnm[f>E O-Ϩ^9OqBRsDP3FFS|) $R1x@t9v'YQ#?=zaQ6&n{;7&%/Df_%ZKٳθIx`&w0ikD$nj,tj?BFBOCYL}*;ڲRT0PX{G(ֶUrU EVZYK})VUYAOjQo:E{A$( _l&Ҟ޵H|R:27|b4h5];0{=aAY(rUww,E A&!Tc)qY5>_ezEǦ1lvQmጥeY#ʅ=-m2( Xز )i ݗF#`>޺>Mƨ]FsGE%K8̒xi+.9$11&; bne)\(~W˳#3d>9d~4NW?kI~8.W3MÂ6F+TywM|6ۊ (%}Yx$)hF++DVJs#ЖDKOuGQ`+s<uׁY'7I".>2 uu=2eWn4f f]q_/ȻGy9#%ճӹ o%ww 3"b ;3*i;qɪ @*՘ ^;@XsT-ϳ1(Os[ Ć#\o0:_±8n3!Rݙ} ~F]jBF#>sUZ{ h] LS>/jؗɱq0K;]SNS?$gX7:՝>Lμxn^Ѣ$$IuR:`|ƌڽ|bGDBǃ)>oeU:vU[e:(Q2{ C 6؟`N=Yxn;°kfOW(u3t:qPץ|i- {2a&S)س?gduKeS OJ_o55vE-G1 \ܛ"R:7sμeS(T& X U^Qy `Zd `N{ ʯ!{!&;|>Uk_D'H;R I2I { E(T-%ڭ|f,`4PIT+~':rfgpXDksof|.uɥ&Ħ^ FF{gE_#Y9 ^f0bQPr+XSBd7>/ %Y9YQؒ6ztt_\쭁 mfZi9m) eD?;8b+iZ1z);wS|ӀvLi33u?e*\r`ZU網yb(AK \rY/ ViZH-<L,HG$o޿7yK,zԜ}sxf;+3Y_hYByI}6c'e~=:OꬩdO[}囩Y3N*d@@2w1D\*ƾlIWz~[+o ђ& uҤڴtܖvi|b=f^r$:a1ut@baV(R`?qV4/61ɒH M*Βݢ#1 ؐ, 0Eʓ=͏aL'V0Ku 0`񚻏jd:n8Em<:]M6^ j!~٬X4y#`9(89x?v!;QqtI9SGusS .l.-B낖;@H$Y{[G# 4AT(C^{D$5W)AŘ&j>T\S Q4# t@H˷ wO7o>J)=ʊ"n~UiFmoa*m?z10A&T`e*Gzfc~}S.#sTЉJ̀Iŧhrse㿈̛~xÜ*%׍i:G[rm&qے*JXOU,o4W@Nb7CL:n-uR_Cn /C gK+( ?߆LMTTɉCm52?g>ܟRfI*hy`iچM҄pDr4`O#ED "FtNu͓몖h AU]}ROE'KaqC̺wBu$zjZ'" gA7$;Ȑ ('@65&#.!eLp)gF"6ܑU:qVN\>+,>| {H#y`Cp3n;^J(:zS]{}MT2Lז.Ps 3_$ Ѧ!0.spS+ ٱ Im<:\G Fޙ+iC':7 [Ǜ $V72Օ.4S%o1Yce2\Y"CFf G8"e8M>,cWɽ (qI%K_:kirqb </e[Cz_Nt֛/cp(c jʒ~29s ΀h9$sx9?1uC⼾7yP|=#« )ꉟ~D޳*K[Էki χpSfQpĉQtpPmS\{d{qd3yTH:MJ(j-ٯFÎ_t"q 2W;" SRiӔ *^ƹ7q3v#(?N R/Vti 托oۀof; ̲?-Ń`tgdTH=ŌjVaQ0mWsGJHmdĎXw8`Fm*Y Б#O{#N1V +uBcٻ.CtpMAS$+YmK*vueX'iat+6z:!B6ǡJnX TaH JGT>Fu?h`F od:'Sm[ krV'pE`0^M=w^2 Pe4 pжy^&=aU۪jB*-јq%P{}AgLcK +}n{UEw 8t5}љD||2(-1}pRoE v!b8 d'z7?"> iox(Jz(:Dٴlk]z˶dܗ&,Kݳ0 | L Mc`8Z-/;F7Xzu3D)ߑ8t6јƲKT|ӝUaUzSJ͙!*&sN2:H{p . |]#Q~$ԻW!j M=Iw:|=eK 8°m~oYqO*MXԕ3zupg1=OrrV 9oեtN]7~chChS5k<092]B`zS ;Z}hjk~dXOR鋟]97^B 4ct) /fg(.L\2 q:)}٘a=8b-{x*5b7b8Wq_v0\8" J 7&Mn1cU8U;HoY\zIVA&`9Q?ۏ@1 V|0%coyZR$Qg _V:rD"EJ \YSA$M@3¬8;(:@*ug 2[ILҬ<:V F ӏ0@{im&UhyjųuB`8lqOUMyi~!o4z=wl9(}[ ^iBv> Sr'Š=O4LX3mBې+W F;aR~lNv +zN[J ^,Unb@c(M9ߏ1{s\KԸUOF+MR>Iqȑd.8pV+st遦dCZ M XLag66|e S3w:Jt!/1mάKwΆrڪYNwwnEs\V @ Z>; |rogz7_Z;(;,X\*V#$-ДXNǣó{cqK$dv&ELTiM_;DAp6YhgM xYjK@S;?oJ6% 5mL3c-)x uO\LU.uZ  uaBI1&HWssi?{7X 6!p;5_DjJԣmOg5~PLpܬdӑ=f7Q}2WxXXt0U&wdv QL-) Mc@m]Lfg9#jE֨_u gg/lv2g`i!n2=F9OphӀz`{ bBj(UlD qgU("V3ـ1gC\Tahݍun.0 JDqYÒR^;\Ȏ(ZB^l`,().)1x&˦x5[ٚXJOaKo~x5 6M5\wa13=Ts(Z,8 &hZNY`ԩՍ5{kK,AYx2&]Hz<[Pp2/*tۗ34MNk!*(#Qz=]:?£8@| Ir.nt١Y%C ±?{d!gAPElN4U>L<l% o$FtѶ'n\-#fg>bt!uTv!@Zgg WȠ$V!gSG/4.hekhA6ifkp/dV"Aw%!S/rzisሼ0fbig;Gi6) @P2^R$ ibZ"bU*M?0BEaN'@12 SM*e+I :p-~ٹu㠺37jlrzЫ뺪*BA%t=Vkg^A@(`{uʐ+jmfיpɼc; abYl6>Mf"cqu"iV,|Q]^,sZSghGDaYi{& YP#RF3 p&&3K_h<%RA*x1x* DKiI-IY G ([#gaUmxEc䦐{w./SAR3:ӡ?|3$Ʋ8}i^{3 4%r]]hYNLH yXS{J%pKͅF()d0,G}icV: 'IG(VJ1fjPb3lJߧ:U떺+Kx 3{ ʪ~|zA&GHd=qČE%僋U%\T|f_&3#Jp/u<"T ۊP6 v6"V@?JemJQan9 ,:_&ijtH!Ю+Aݹ0@ntVBb[M7ӕ?a Chľ׿&& bmj,OSyG%cL4{m-k7S̼z _:ۿ HJ42cml/wCk@LX0h;l)לlobu}?鼿۷j1'M6QPm5T%#T lp&c#bWWոnUo0I%Q~/ܜ8xǼ~jo)[p7Wc+,ɰ2<k(VT;ϔԢkx -6Q|՘4u DU v4Ց#;C,0lŐ^wٕ,1QSIy1b}ѩ#7Y ʻɫ$%G\2)vX\CāGCC^?T(4i 6gcN8挓GOԻa ?ӷN/O Sl"; zfgy[1ݫ\} [E@:*,lbm mȲl-T3\jو!e>JbeGZ$LWVvE gaF*N rU6>󇨺_QRTJ}/4a8Mj 1\|TxƄw%/ 1P#~NJ%WspiOq^y]A2sőerWsՐaX28[|fw,Ū44\2KUZ-cQsp9FZ?}ّ܂t q gpҫ=yz ,ޝ}k8vO+,"Q.*ݞs5%)e>0HU4itY 7uQKCUK젱5KÒ݇$=VTûi)=&LOʹ7N-ҡzz_zvRr'(t5%4cxnG1 ̨cX\Dpf?&8aPC&h'%vOk@ŪSҸഭ;>zvy˯BEB6*nu _4hLV,Ow:_T9߄buU)`hD,JAN i"3g+hJǓT=s8쥉v [Hִm} B;-W{ȶ=)\P,%v;~3P+0X[-6o{/59=󻒱܄PV}鴿.QpwEG9,8U;y?d4`[Ҟzwz95h, =IW>=qipoʻҊP/@Zz}vc-=gDIE2*xDW "=dP;e=hw~ l R;şc; ^h+ç4;q11jrY.CC]n(; {~ AR7 V+qk[vO:I)nh^&2m]l # P : Om62$υlÉZz'*pbgAK5kuBթT 5sLC;&=ǂNfO~$"_,;qr p r TYjZ v0: zLΥR =D}=*^1_y> m"1AsGWel[OՊ[5., ]icݡ2=f:ج-"+${̜t1m f u c#(AڬKQwE?uZS@I#,?%Ɵ -|Pm+?}yהr)92|9S&1t ®z8*3'1U 5`J6͂52d6QjKS5$_lHW`ux ?TB CVrɕ)7gYH䟟FCԕ2"_z.t/ni*Iqf;;Fs_ %bZn+" |@nfHA.j=IIsZ<@ 7Koagx<qȌv嘅]4SD` aހjgkv)v6A"6'&OUSd/8"5/}@[ 3,ޜn#o9\JI~)#n|uvM8<~h^N~W ?Xو Gy5U`]8دFz>@vV1Wzڋ(I"LQuf!#-;?Ѡ&cfsxPGҹ\RCfhUϡ '-`7_7!`hg .gk%!Nة&VDr1px8qЍT2VChxvZr]ذG<ݩ:0,!JZՖO%}TRdgY+=eex?lvPZ)#NJ`[ɀh{4vgTʻO,}jS6o6]pv_dwr ^П4Mǂ2ҩ mt3n2 i_H\hةwBm+؞,{ݞ"(RmګnR([ap^v yw8fۺ=|0ÛO1O # oܶmOal5$䲮جUC/&0?0*cfGSv̧XrIcpxPƸߣ{j`3c"s(.Q7E:@1o(_kYnױz)w /ϗh ䷵"LsR:დNTG?0 Ҋ|ڎhwu?r'uL5~Er2x]afoTV~ӽr%긍ݯ(1ud 3n^w*Z's0JeNb'>$ʿ}[ܙU3dA|@nQ ~؞U-C7PX|ad,xǔ )Vwĭp?4` -C4򏈾'~Opy/ozoVV pU׭;_AK)s.DkEK ơjFs1^Ô ˜VW,8&E.^\$#uĈk LYLOUu-ծx!doq;*6`a) Ÿ"Wc^5ĭݶGFz`D/,@1QS6@SH""˱(̽">x\RpAR&~41.&c5)X,77 c;IYQ97zH<܄*9–{=&їy: &*K h -J==bH^q@AuhaO]\ VOFQ~^}.dr/.B9}TBX,Z?ճt t㩊ocڡ>"=$mqX7s9/1 $XV_ d983 5Uh& #xSu`]<.{ +CcAil>0!CnqI]rFuGK@:V/ ™t]Y(+fdse@w84<wa yph&F4*bb;9̈́cd 1z@)^[fE&\|{j9`` ,yj?-l0;Yv0\‹_`d?[μ.J .Bsv潚Zh2#W=v0I"|klثiʆ^<~Pr+bVt:s1sHV9O^EVևG*d7ݞ;@sjš4UY@/UG0,m"w<-֐>`?рWofD0zM,R,ax߲d^UR,Fs .<ʃ>H-.)**a`&&W ζrqQ+~ф(, C$ix&0ջߵ]](M ZBW\Sδ 2!\>>>y~"?  +^ u!y">2*`!_sD 6g?V,?,mOO> aSPAFʾ[ x-RmO8[Oa&\!-9P*da@q[|efPڥK&(Wrߣ~JRd~ᖱpwĩJ/`z2!?Ͱuпl+uj  Ŏy+vYCN*MX2e*!ÙTfѶ#ա] Cj25f$Z~A`(uءK1ww Zjɭv3sn2!AbgH4EM] pJў<.>e_ϵCb=J'CQ1jڑ1}sx!u-&vL-_Q(A[s&{ˮ؈w dy'.Nk-IؘCЃ&Z $W"4;ъYJ]ΚM 9>L PC@U¿Ӿk⊉~tC9TCIXe4бv]0aWldP;zyͥN>uR`iq1`m\E{n i'+sL-74XH\c}~:$ ЇP&r(`*p{{EԈ'nΞz2MhCH?$RZy}r&e\@vDI|aTY#k>> ז8${DUJst4ߖrwNł} QjJׯ5'/%T=?Pػ WvА pDG~:LN??_0EM^bw-Pwꀏʙ"|)pl-lM Dpp59- x0sv~"~NLMK˳HLr0bUkN)LMJ0eQj96ʹH])A6L>@=~vOX!* ?vCTYaxk,V u7Oͯl]" G~$z9J:APȟ0++3OTJp-i2|T.*4[n)KʵU5gNjyU6߅ej& VwXg",('I߰D!ɼZݨh%!G/@%B×͑OcmYAY\*Sm`-[Li;VRX t1\$U7]z*5*7.x3ND0ҟCQ" ^Z8-&Nol m\ǡND?"+i`f$1xAQŤSJ? LTGBam=i?(2B%H61i[pL'hLߏ,=kquQz03>. 7zh;irx8(xwR]1%1V*y'M4&{2 Fe5ͪ] QJʆy(8lb~2tW{w%ӌ8a 4k:Y2 QyD-WpwnHw|ZA"pq'6/YJ׫ʐ)ma} aCA_~bIw$razփLiڀ-UjU.6p1XZawP0Ȩ+ =w4~p-Q/Hn,B+ P$Cl f ,!X ]~(v 7ija8O4MξG%yD?u)@mqM' aVwbh-ro7CQ/ }U$8Nh:Ϣ3gOi,d+6f?kjź|L3cB^2=OHҷ1]G̀rmBөW:j9| ^k40E )d(Fv)3;љRvP$UA(0Yu=q9-X|Av +qﯲfJ,Siw?))ʠoE9CO^H A$0xC#Klcے'7V mb{}I VrĦh'[Lwh%:M*Ø(,SH}cO_)ʦٛ>{MѦ>{*ݷŢ~LX6JEPa"'h@~ _L"]X{osof bN&\Ч"A@dб/pKqەfdرd%dbg2!. lE,A\F秧phTeǗ)ڴw4u*GÁsED0jΩon;aU]dREz}1XE I\@ 5[>;Hz0=7r3Z*R.szTYWzԴu  p"'YA-0(JX$ܡ s*1(9)7 ҽmMOU؛ T0unW=iktdڲ!pi% J0A%I*\YEJS,X䥖v1b%q*b7Ȁf#Ddqᛇe&=&NitPt9yP}>\D'`p-~E}Zye^҄,{so/O ɐg$ Z`N?.9YOƧs5wXSݕawKCFKC;З/]G` U;,`Ȥ~D'Lf" bɝ{sWGEk  ? ]^a>٧/0'_ȥ,ć'=a'ILjf"n{ q3*H6X*:&mdI=HEi2rށlc<"[+Ϸ2ߥϳ ۉvCޓ瘙 Ɨ,ę#$+msA&&̅j9jf*^!4ǑwM}s0Ϭ5p.LѾ 5Pe΂6Dp[3h+jA{iT `<7hPjDֳؔΦc>aGϡso|Xns@嵡azb鱼ܻ#XvLEZ7t\ٮ|1!c"p~J_fWf5KI}Aq*E6&G^; by FCP*񃃵^>ө~.- ܃5 *R^7JN+fA/3hn/~rwzv('QK( RT/ڡiȑǶ=oؙHuJ"pUzBRtߤ} >۵үGp)s]ԛ9d mPԙ %YҘ(]Lx6۟)dNHEVdVp/l(9u#vcrfHB]{z8#ypۭŁ$ioQjEk1]烣B6p\R$psG}eN?VFFQD]Tan2<^gvotg#%=Az?&'èJƈi>4 #>˚QzRR0UqbfX5XI)#KbN @j$ Rqnk.?bk.DR!ک5Np/!0ܳмIfB!xSMO(,F f+zhj¥Q(&L0YO @Nк]]R#ĽeƇG)b T盟LTA"!%1]f_!E=:bKHA_$gd\7 n:$K1hTɎ?xByu)A} ˑݺKw+I;IK2Pio1wdE5̱@Rνԟb5EduzXU`⃇sLB:7c*ӊ\ ֐Wi,kSl+r"BW. !c%(92ran|A.MDP: vjl|`4P2V uėhk"e#,\3$ nƳuil[/~FT&+b1Kf݂fЦLZJ ;4o%Gr2UFSپyUc wiu``-'gEzA>Ͽ;:Aq}p] t jn$cFUI|hDz!_:t[Cizc4nRSC)"ev)ƝDcfq ^w:TD:t5zn="GW-󟪲D{_hKHGQ4~  ضyeږvMQ'ݮr\|0(ʜLYp%79;c"Mh-l-lok] ?iB?j<Eh fpg݌6~: )ܜy_2|$1 Oc|iLBK-?0X.R9ݘY?~(7ɜHEP& {؞fm4u,?M^M!Q–F6rUu>N@ldV@W@[>bPT @QTCf0z۹;gkkʽZ92C#(戓1$OÌ6-~xUgv/ByYȨ2I{<شWOwj;g)hb") _b*N1Wj}{1–Q/mXEN-E~zo !]:[ҚC!vZ,HwKb=qr=w伫AyF|1MֿL~^йHM `Gd$ 3 R=]qV>mM`;PԆ ן 昕K?9PvKIe}=p1 9H|CJ 3&p?o4&;ggJQ$ \6 Nzu/#Oؑ4$8hz9Kc?L?|YІHIU3 RmC/"iȡ. +<=˽]%eB>2nm@YyO-etxk\?qR+ɅxU8Ț>0'.>yl0!m hgBF? 3ϼV@O.*hW^3<TJkdǖHx}oư8^䣺1!w{(Ze ~穒Vq =?c>z:ZsGYfepi H$7rh1yznvW ;[Vw; `Rj[nHj~jev0gYZlԙH/6htD>jlEeG5PY gG" XG_Bb[T\02+$ ' w`R:R HҝZ휓W/"S$iǬ[Vh<S;LZ zO[;Jl<6['&߾6(~Xb gYYq5-cAϊ D5:%$Сܭ'!lga%+_';71VQe"?u4h<.]^)Rݙ.s|DaVFԺ:e\B0d4)Im|dMZT/m  e7̜.DjuQl QƅTJ7؏N',J81D]鎥257TXY)/R*$Xȯ{WyMU5ّD%YkD%Ҙ{Tc_|`I Ц/iPQWWq:=勺)wJUp)P]o L&6Lo{N@YhBsRkp@Q<=e\@oԌDp%.k:qpJGtM&ƽ&2)_,*d k0wUT`zk+'"vd{1M5wd*̭N!̽2VO*McP'!+hʣ"@_O"-+vp.3!_hN-NBqQi%"j!' A؄/$s{Ƶr , (_0(,۔?|mW;6ic@* J+,ݳ>jefJpDktou> ) GS4'T…ɊW{==5s |ziZۖګ6R}f@zy)GXȨp VƨE/&R'WBĚ[YRKg AUƐ-2(?MC77&%;&&|΂xi~7`:E LAhyGBQMp9+:R15Ի$Rrg!s[v|rB zhӮk ClTHV^" • 0@҅y܊2nb{HoE9ߖV˱9L_bA[p}n\#FS^?TXߛ%!?ȉ]} sÃseRU÷F(LN 8y S/Myͦ29 bgs Sm;4-vCӲiՑE \H搚@H#9 Z0ts[ Bǁ8c"PE&$q9 .(ʄ8?{DuBƑ"cc7eEM@vinK&Y8W)+u# ڝiki"XM<5WX Vl@x:iSQU&G.m`BCpj-ӛ|wR @p^H#(3.|ݏ%jeWDd:)P$#ӡP]M # Fg=ܑ{bo}GqΙE$tTE(TrfZ&8}W߶LK3_:&ASup)9VO8I4 d~X^u$8WYf&X|d[JAhdNZP"ˮGt.z 'e$ء!B{Fxa\WG#C;@wIfBDNHLZ0UAS1(*:"Mnk:Ȝ[\O=eL =9: qpT{F?r}em(ZRd1"mnf¿v[-Oyz5@BWƖ +XզuZ$}Taԁ3fb7n-kHjk~fsIn:/_F-5ûs>6[ыOҤp43j; zY<KນW&nLLYK7@fѦ󻲞q5fMTpu6?jdjPa<i xy%aF5&p+ƼJggL[9q;L>j 7PZP܇Z]SJՏ9̵W\%0VuC0V B/31&{ql7&=0@WLLR|0'qEg?=0C4+fGM Gg g5{4_Wmr kVFuoWLxjWΪ>S1z5= u\@eCoǵ!i&eW*NfҭM|uc82hLbo+&m١ǁ~giy+2*|?)FZ)f7:_ˣ.X+\ tHD1׊H1A:5.EdV7<Ɉx)HCLd ik( Hd:Sa`859ibcB00m{ QWǏnE C4:TK׻4Ve HB4=_O*S&?泰"G-P/=?b iCpM3ߖq)%kKVg\iF]Ǭ/nj1r]vtBxQ)':( Aa?]5`9؉ 9LBs<ߵk^Xa` q*+ 8 smA] ϣ$0e"6?w]ɵκ-&L;QXvsq_"4<|Hf)@*/9ĥw*_WM!啔\πIY"%dțAՓ/U CwϻZ;<, @p7אECrߧFq+uw&pZG{\Or'?Ϻ,yh>c,)j1A wFj`l O˩L)&k;?4 7'Uk7[k)iQ'B}a_l(i|Ux/1.͵ҢpGeoMc!+}Ც)U˿c>ڇ= Ҿt"@<5z>U@]<WYhS&[Woa1Ńim!ir:1%lvT$5W#:O'(_ȱNGԮjvknZ7|&uVFC¦ k o Lk@~ze;v-L%I Ḁ@5gQBBi=GXrM]aQ/F?|vOKxgwUBWC[ա96GC&rěfz?(Wg nihP⭣: 4"J`c~T" %p L3+TpHlz4YױxCŪ͢0K`œ^ ? e!> 8Vٱ%%E9o`L(eQYFDN]Gtn1yfKļ3f ]6a×6S$Y_eH5UaaGr(~1Ǯ_{ԉ\F ֏Ү CWR7;XMyZ~ qi7o" 7IvXr,+;0hg__ '/p`&Pjx7P֩4<۶ɌH+J1CW(hi+go4qu3O5P9S?NYy՟Aw&ʢoe v oYټQQY{Mv 5-njX GAZQ,'Z}'w2n7G )C&sBySYYSb) CS~6XqfcԂK6^ F\8%R{&d z5t= jj[-cL"˖ҿꜲ#r=HV:Ѿ\uXG /s*~0(vNXkk)CQDUo-y#@ 9^{{㰴z]hʆU1op(\`/iaEqzole V'A2 'nJ m ;&ElP?E_|MZIZiQBmwxUã`RhY${ZO}ވ0XuX~~0j}ڄ}^ ߹. v~ZU[moqו\ϠJkw4,3*`~DcpXRr>х5t b9E_7@ݞwڒ[6)&Zʥ8:fhZ?Sn$P͋GbqЈ)ir  eH ܋̯ C. S ޾U7kFobwtEg5O1d=)m .%0VU=,j~˸ZFǏt=]&1Ւ`:b#΁C1>dֈ{l"Oqʚnߡe=)؍(9rxdoЍ5-Ѫ |`c#m*vީwN۰Kan^zwfrs$ XUYa4IzsT DXf-u k u5j2O5o;bŵDaWymM, ?:DOa GWptQ/[B! BCBɞܗ }mik:mU̟=]+5aW+M2 w+lS;lP *23Q9NL!Ki yoᇅ";ducMj @`wSN^߂0Ou 1V?W1s]u^ eNښG㕯[әDIz=倝vH/KG LZ 'Pyu-`Ol!<4&t2\F*\x]Lk G77,u/*A|Z)>-a!u,>H42i:^Uʸn5x\AW4(<\6.A ]֫ȑ$vS]j6eNyS>STӶ!dxr,f{0p(b(!"MщNIsj閿&;:[IS4thȺjbꢩוH/{|D%P#; <(GИoŖX;Vb NQˆr>A,I1R@ i)IKBG)ZEgbm7ٽ#$HCvNvXQemE{6$A-m7_-^ΰsE.X`Xwc>p8|oxolSӑQ;a|suWUt!,ozҗdþqߍCslІg]x7 xKʏ/cE L#sSA;Pjc)H0 ^F _sfvg^SײƊtZLVLۙ GuZZŊ[H \7U_Ϲַi^DzSWeX5઩pL]ے]'TpMCm{#ɪEyɱM|lu'Bvs)pD eadP`'܄o еv/O5.E'>\h`C"cϋ 'C4(N @3ɴOP|8yBS>=E0.<@L/+/p%XQRE[Q#[ rƅ I kP ƄH к{yQ/ ֤҄hV<~?|z2M>aeb*g?XcB+bby JN^z JfBzw"6v؞o-¨fQ/pI=<梤63NpE/ihR!%h2.cڰO["J5ʦ@xx=|Bh͙$4ꖇpo5 f*-)aQP?J*Ba /0AK-nQ#dժE;{Yv/,Z%OgD&2AqL^6Qe ^\pJsn![_i,OHۛ_29k0`Uq'61#2 t =,7/;l08X>}j@I;=E.!}ogCaIl7ͲmgI; VHןlK3M]}-ysDĝ![ @HyS`)UN/翉|xgch6j#L.QxY==!^9?D&R%sa#zj[*uoȚH"gUa+a ~紞Bk}^iX3"K͂nVR4 Y4`ʪ[u?J]Ш,5"E:s!n>H'xȓr[PH=I3G;JNN Jnf]GIIBd]A3jWc-Ktf6GQbq~Qf%ǢUakߧ ) 15^.vZ 9;\`rLN"o~OG Z k| <vԱ7/SvT]ʈe)ȧ>{۲[Uzx8=8I4)[w E6텙>n4ب$Q8`(rBC\7YPg“2 KB{qFyb[rHl褥4iP6B[( # C1lUvE[ΡV!D,{&)/1u(o€1gPYvfiL"mǿ0IcI050MV1}ĝ7HXPcĴ0oX28!7P# 2OrZ,V2! #]ӱc?>@3-y4[Acl| PQ@*>rKT?,a))H:^o>xLW0MSꮶ^W yMS3 LwG5B(ͨMeT*c?!nd > 㿅UkV˻AWЊ.SӨV3Z|7LJ|^׵tJp0Kgm Rvx9@0q > "`nY:]Nj<6~#Ѧ=?%/0ΩdMML#M-nO"_5VZK5w S<K'@M|1;tF-nt6_`3Vϫ×?J[H~csɺR#DrR+ Qi|FhHGW[<{VX2_-q5:lWƢ5($񚋆g?/_f!9ƄLeE^ I'r5p!VC"0,q#)-<]Vg͌v}:$_H]i5?FCWz$>ek&ծtG&I0!7n'AJY;$B ى #>lFm~n@C,*ES5Pjgsΰ|JR֒-ke`l=Y&'vYKM%(oSCφY#x4⷗ɤ=-3y&Q1OiA[+êG < _!Q8ɧ[N0g$iq>zɵSJD3^wpځ0O'>{S`ny657{\mr19ڹ0vYZq3d$Ʀ߬#trkqfWk`WxɃXwJ yV T`V GECm=,} č=2Ng0kQ'm;H/&fl)Q6:tbCF&sz=vpnWxEb!靮MVb}~5GߩMpdnڵ1Sn5Z7b!$cRKn"暸"YiQË@z_ʕJ#Tw_D*nIȽ3k2,if]|2@7ci)X4W$%jq6E+73ٹK8]u_r aAuu'l߫D;rf! ~-OdM$AUSj } *ezWڐuߥ$#fNQ(5(!(CX}8qK{HY2qy7{!#P#=Y-NMZ.X/%\ /^zNy EDdP)C:KNSr(+LÊD5ojѻK =u>!}d!ɵ@׫'"!,sh.I_,m_"w(iTa15pf5hPT.ӆX +m $ZJuŊߥG:'\Y}>c8g*$L 9?ВmKf^Q3FNV4ṋAλeh*Xdbnmy$X@8Ri%˪+_2By֠~xcqz\ Ԭj9MM:?jAǺ)wU[E܆r[D3x_CLJ)jbMԣ\ I[&l_"΢4BMuGBClf}%e emQA7HQ֞Z]f0IؕvmK@ɑ4ٔ6Th E9޸ߩM/`&2z.fL!U!k m<MBJ3e˒t!J1'OL-&Qk-9 dH~;Z[*%9/~Êqi\$4XTA=VLt0/k "+605*"mJ /Ѓbh{^1f`.y#Ɖ}ɣ*Q86ZP^/RV\0YI6^ؽ@,x_ n^c@ }g%>x65̲iS.9XODM'BI`#n ȓqOlSjCI2ؐXI~]W \)%)r)&ŊjvHu|# ,6ކd5 dT06[QVkx7 Zaݛ rV}Ⲁ́g0PTJM<JEϞ-dA=fd2<KAƖ_ S 5YAkg9)QǼ)&sZ_"d@۳9O8Cӑz >⛻{ ]Qߦ?жH{^U8 k5OGʡzSCrU%YPŎk [Ph-K bm%9)g O= e?L s}Jm)8QV@w/YfzMf&aY$QhX?IȪ'G({CeSkFxctF;| |hĂ#Ux*C7kٽv)%0_z6PN\1] o'kd' $! h6mox-:bG:=PzltaO=Cgm꜀3P+\Uɸ䂃)#R;` Y@MTv\0xiaUĦrև|Zbȥ7LF:Нuɪ*Uy1[~ԇ7އe7R_|WyRҦ¯o~3aی5=q55iԼl/s&{Ұo<)}1Ϥi 1u"!ǚGnj3ƾWӇyJ]0_Eֈ(,#nӪCnt:26}fgo۞]}: VlQ'3 !nq+H;&?UyHz8"QGϼ%œ1^0X>õ|@kA2DLa=3&r&ZV;29 )Gcf\G(RۓCMuxd`cHQ@-|%NsfqT</4FjY:hUHK+*`sJMDrzU i)t) L;Zt _d:e߼id #*)‹2MZdN^]P,?(&oI +1Sʇ˺;6ΧqeIhjb'،ZHRofk\nnD{k~!vlA) BWҢz án,6XaNG\+6,,om\a$G tіfy>$E F@ta0idFRfAv?iIsݫ 5W[Ap2hII} @@8 WF:\8ژ 2"XGA%/>i] @I!ֈٱXŗp}wY:)PB^ۑ4%1X[KU m#+e!QLة{Qjw9iE2y]m{eEO5Ac~̘Ӳ=ir"D덹+\Qcw,E,;r1Mџj?-:CWQCvy42ԯ~N9)KcM7(vU.GQ\2w^Mq8 w&}ѱ`=^\`$?)ٌ+NZ*΍6Q5*nMxi.D g#͝tZ!XiuG½ɷöiٹj]\dz"]|(2u9lGF&O_'!^߱u+lj_ҜbеR; 3|n&3f~6OWR)(K]wtsYZr'K,>Mǒ*!ʵF iиc$ %+n<+<sΖ MrTWogK* <8Dэpj1#馠2e} m \yLk㰤R+&yN%qU90`Tl-0C$9חYNկH{ZkXJ8՞YUFѦ*bRe J˚`ECYxSxk1S-VD6o8JēT?SMQDY eՐՖnsps ZNkbWW\oL5-_-=zX]kmeHCkI:"jIvL|.a壂WaIo܊oH 6즰:3_q>l9t DoH؈/gvm6klnm3ԭP@櫕mz:LMo?I^Qz&aA4a㲘(nU4H*Uk+=M.5F%TjU/]E|؀]DP!ͮ=d.؈h=Q}Nd|zd)*TF#&wYySo"嫻1R̒%`(0 kl"%Ne0 -*0ۂO& YHT#~~g'¦!3\3{2X3$K] w\WLHMv?t[z F\ፌqM䲝g#{Q_j%J#!"qBrs8P7[M2b*ѓʝ:.S̝iDdc} ,n KXWp(N\KmF`b~A&?-0.=8p`Hrdf7@ 7E]Q&x~M49d̵;onA#=+$caNud /20D({yo֡d}Ѭ7a\4,.DrL?Rq-' J$`KwrO+"}lFS ;6=4WF(Y%qLW@dTִ ROxjo!ns pj: Y(ָNB9VqSh_-# vu˧M.:ԡ _ ݤ/ڀ`)BgC#w7B^;v֤5D4|}8y(љh{ZYSzL75M}o0`հv -dCܳct68f QZK8ƽpG_˜qXhsȖGDW3$L86.|S]YM0>u3V}tm 8@i2 u ^ T)~˒ DrG GjtE:}.~1!8X( YI.uHk73#J) ֎vݮ/5zfV 2L@_>tBq>:C4l,&sQ& ?ZPs&kOSZ oGix!5raCn:R,N=UCw:tJ})N0k)0A!BtA{qҦ]OutɫR\7n>4Dh~$c/\V /St$/}p ] Όi)>\U%?R3'v7yК#/p LS))Q(חI+X+趙Br[Z[tS"A3^! cӁQ8r7)r~C@6b=o=kY:k#f>Oן.n^9arP$9X_ɛQڃrR\-y̲屔lbB#Lc8loZQY%Br{Aݕ3$LJ^eq^cϹ3\кRRaDLgPAl't mI XOU8J4d]u7qv@f7,Z~@Ǐ{ X%8a%H/UB^^D%irz&)E/1Q87 #ݡ,\:6 .C]aq3fqF)g(Vo7σZbZK&-/*G%?b})F%.Bu!(t8!q(UuO!_)6Zӱd,@Gx}*cpէ#{L<[U 2 0HkbX9pa:>t+2<y~tވH5!vu`xkz. }LuĐv*Ь)[D%Oȅq!lKSguܡ :4;n#R*L4XIZ㥖&F<2uM t+YH7e ,ˆ~VUW~MV?q돽zv #I7tذA_Ђ_M$C+zrpZ/oiDt^Le [Q%uPa{= vDQfם8<_8Unx+ x5^-OA| 1լ)K/ ԞDzu8mwF@t BH5HtVaζ0js$-nvs`A瓤3:UN4^ֳNa.϶EX@^ff ']g- F@"\ "w||/%ۄA?ki#7ܠNP3=݌?#$鵉,/pn&6ٰOGL >xw'글u״̄V M/{r uP/ZV4h~]C3 瓞r1LNR(彇E}XeEu` 8ɼ,Ѧwb>v aO%;;Yd#QE{[/^AEb'zv!A+q0=p :I`&t>+sN4QJS>%%S!Y2U) e~PW$vlYF^ Z;bg)d&d mg}*bHcƌUf,U aR > H? ֭$h>kL^O^,p,)2!h`\)$BzmH(FzGS͛"ĚXT&.TA/`Gܝbgq_QNtHI}W+k9rњrcv}Tw B_oDzè]M^T@LyMQpz=B@xR9R@c|P Fatd;~B@V9a ]/}b´9fq#e͸BȽ@y_)`5 IL$Š Q|[._w󢇼X/d(B8|+؏\Nax,pص3C̛pbb:lu6l=po=r8eQ JvD/}=aB d}E|TfDN.O"0 "VRSb$rTh5K8<[W&gq=Gs nQ#wuX"b7%;8TFVC?&_t zvy,C@pb`ž`h,,usHį Xy`siюq)X'Nt *.@sv~}2 L @}`p,oBQZCQ16Wy8jrړ!V! iȦ%|% wNEw )e`>S?G*pVP縬8pKN`aBx*Ut߯⯩ɠfݐ(30}):s j6y+0޸pb} `MM>VWZB|1=۬*aruW.ىR_F$£AHg6=#;6ML?D j~HBW- HgON%58~٭_64Jo෎H ܶCsZ9qO9Qʶ:+䜘Ch4[3_C+8&1\ǯ[NQ%JDzY12`=4J 3|Q3ʔ*q @iOzI6Zj/WBQp-H1k#Am,E?@˺zѫ xD2p@_zv Ϛ=| _k; ¢#lC؝#eo8zqZ._{2]g"ZX^Gպe /syZYu;*\"Aͺ_X% mu_C+b%!y@Y!N}-(K,MKe'J~?wF3U~n!-%P ]T$ɫK(uɮik9V8S "ێPN8P>XQ3!O[Zs2> mi ՚O6mP-IȍKʢw5 \k}?|4x ڨxˌm{Va;q "u]B!|3*29|Ϝ1ZaV [" HY} [ɉ۟}M4 3 ׂ{_W- վUS:|"8e逄ʹ^-cO?%l[l}(t..4 ߔOT ,9R|DA(,7:Z~Md]ia*3a9I}.P vsՃ fţՌO2ü6醡sCT Bߏ@&Amwɒ! kIy<"A@06 ۴ŋ&SG^ 4c.7VC L@BSciQ`kYG)ڝLCэ+Nse7yE msv1ė9|ZWX1&DEDbEJ1uӁ1 x[LU ũO>AC)]V+t*aHIJWAG77rQ̩Ai¼K˵Bٱ 0MK (-re# }5[~JD9 aE_Se38=WvÜZB?zF7`(擒YWAnXh&L|@SB+S=+yoꤏhX LY6N2QvjS5h@J}P_01݀e"?j,{0Uy9o>Ӆ8`FJëyMx+?8?. FO3_Ή+~a93QRo:;ȓ>h׮Ҙn/UP/DMM2_Gb~v"3y7'bV]WMve)Em][GGb1^?uV2ZYz& ePb(D Σu/¨ZcE6{ݱ"j.=!Pg+9-E0n^ vH㴸n"=Hh@H4Efxmnn5YAwMZc)XAhG =6˰A<ܙho*{>fow\A]d5e,W5\gi^b3sztRkPEm.QSLO evKnE6{Cj= =U,2! &@^LJB8&˃T,C?nMmJXF (-qZ1dnGGFؘ,C[}t{ٕ]a_|;ٛע",򴸨Ǝ`a_Ц}k՘/ֹdFfwhb$ۛnT~%PRah) I~_˴JoO,9MqeΖG@ ("d'뒤BB1m6W ɚ*tnd +%wF:db8)AQT:S+0AXQ*6b. _ 75/)zHF/$eHZ@_*UAlPtwj+k$_HH mjsghBE{&Z_q;[WA @JEtְ'j.$4Z" 4$,Rä!wG=;cw9vMWۊjZs%g#7HSBŒ7aJi32]]bX~Q/=`E@KTx/NIt Mq1r:kdlG3SЭpPF`2)ŦKe.8gEɟ l:?p=k hꎑ7+ug\sIvLb!]&<X}mъ ATbv4QaIlnx>CFEU(/tۗ`Zn,dǤk0uT)^z[Yi B*8~3t6U|mqE \oQf&aA ˤ\ Y,NmB~O=IW+406ZT'@R"hS3MLsIr^AC&L~8AMTը |P?]P_ȷsL\j 9j& %j -mYB5v)vUA,NdMž9N+}o) cթ밙P[$$,}C';?C47A$P&CBX$50dx=G3QP4tm3 E{l>eE_E$mif"3 g$h$x NbὼV+Eg 13eaC¤FY6<3V55\3%hLpJ邦(zM[)37PS;K'Wy ͶHe Of}k]Y>΀UF2$")7TM5\9?XtF/q8''_N yFIu"{eX4:iXcpBP|]xOkc-~+r{ 3ZC}ɑ1̇ggwbuj`NYp׸WOm]h_ng3Fb!'CK6]<ޅzmK*Eˉt1dSl" =%x,i6JLTT͙J13Xյ䏁j~ڡ3~"$^5G|'C 5Qһ8H\su%t1i2CYrO0~\m|>oFYFrĄ7s0+9S94M Tb*9D%\6.MT9#MU6(=]c_ſDVrA~k"eA.ֈvsbxLϢŜ]Y ?cg_=D9OC!2/iE569z/G~s.;ǯ`Sp׻Dr<\zt',4'KcY umJkvUuQ ہJ+~$#nWcXad:54r;.4z:5`-0{ )KכH`*+ҳOB*V AˏHBiW)5b*Pc[$jL#`5.=x^:419IH. $˥W, /0w{/J{q?V(7>|7o+Wr[{ ?ߢΌ @ez y9't>sH9:{jVߨ^8'Xm@lߗwA,~,75&91pw"=uoH&P61 8,qţaӃ ަ'~5FcF?c\HvW_0Ow]AP?F,kNmhic P4_B澪 |hǂ,;uFἺ8HIbe?,.1L?(L Hx#WNm?i cӻˍCtεsUxZ_r#vy󥃿 co\Ð/7!B/3`/?;ɬ! DQ|ItYBbRVo"l|X{m=rY>0T 4C|ӉҏaLfhQS6Mk8[ 蝾>dױ P=DfqèEVS< l[.TK JDOXz`y`bŔWIK>[q6WYhX4QtPM+&N>=U~}eZT9ֿ1Jphk Ap5۔m8~Uyf~;x5j¢\C! A e2 (d=٪t@ s[ՙsśЪ\->H @\[A[9Y)q #% GEW<"G?ux#jn#ѵ'@`ϗoE޻H5K\wۡO[fRlr>6K#`NkOJY=O_oq_MhDmnAbDܴ-\7є[k=JOzs}^-0WWt=653&NE@NUdYNjÒd}EMrm=6As5o<1N;z gV ` Q@ye>FA7$ d,9irٝ:@{Y-wOӴkvK5%%3i^+6$쬃i5㕂k-_.2kآԘBîo93@y5(ϙZQ^j?<ͽ"Kuł~RDh*'qX—wGwٍc2ţn-ʚ<sF .;t^:kc3u3s=nnlQ`1?r$u1. :gڡ.5q _24 R&!Wa% B8Ykm{ Ȑd{<:C;@PekmMG^VCQX}ma P!bhkF@N o5P}`5i'C؁2c.B|YY>34}3γZ '8a1Ws6k ϊ+X%TŬ<5[i՛ fS}-ryT>|_~:Xy&Z9$߼I ~*7x5i?-Ɛ 6 5AqUza%+T)ʀD1_WiܑHj2gޢDs,+6JӋ[$fz6GtLv1#~.44U+l80OShsgVqPnBNlj>(Trs3\z+plPC%''g6i}ff 5΀jɣ)tEV}:E_7y[YtCHr*.= [b}/knmD"Oz)Zj}&4?xYH:S9as޺B>kK!)Ռj cW4rm1 2V/$Ϲ+E/sm$`7=Gf()s7z,W:5Q 4H^ʴit@#y3&VNdX$Y6#oz%g(z&\5dfI> vGgtW;J*P]FV~ųZm?}}Z~ 0d\>OpIbMWg 4bsXG5ĄA=Ew=}'M' ad[c/P<|uY73sG3#޼di7{T b(?3%=iF@BY)Հ@aW O=o莣pD.e$+[!Y>odZ//bGSޝ䆐4bH?q|0`9g טv5U3K˟%\x– >I>rR[!=ԡ !Q|h R1,(?Q @Y/I~B#<+7 C8]r(ȵR`AK| E/h=A!Vasg5MnYATϐ,B㵢,'̲;24+-TWnUX\lɉO2RfB+S?b.7L5ŋ(ǍrU6{6z-|pI3QɕoF]&yLRCVSɣnihYE*9!_#%C}C#|^gwG7S;GZ+6ӏpnߴ~Wړ싀Q-%bh.؎m\Gr};rꤺ:ie)IكʘNFp+kQ+iEiP=K*X|ŏRu9Mϼ{]cYȵI?t؝nڕ6Oᐿ/J>P&Ft0W:5yItJ6BVI? QSIOvU8؉x{ Ph@c1>e(a}QJ4om[RCKFzrnwv=ܓ"5}6|x7nCX|Q`w%l;& Ђ(5{3df+Gj|t9h3];M!0%?]<=c3^j{Kʑ".mTgn$\S} d%qu+x!|): tZI0:"Vr\x(kw@ /ѫFT뇃]Hw9\ k EaX," a4,j㬈\tf ϤE 7挼3I;ΥDŽ߂M_؜w=T8':Ʌ:92~1ޤ+%v</1vV#oq,}D[*o|pκtMyL/j 6FU@7oe硊Z<l):H9ZH[px{@I{҄8!ɥ٠A5^e$UUSӫI ٟ(Ү#ܦjt$w*r[y"~8f>438:#o/o#A%g=i9Gd}==Oy@$EZOO6kX.& #Gm|Y# U@#$`Qܾݒwrec^¶^-Exӻ6癨kDA6PRt{ĆIJB.{c{?n ^M! 0/sƗYSM  /`Ab4t`pdJ1_fv8: N<@\S0a~Ěm|^U_HEE7Gyf{H405N^ڡ H 'qߵS*OIi[$"l5v?몙s:x1ך/*NO{eb K:q!HL^z_h5N[}$q4>) k#o@͜&3$J8nG1cG.^kOW\FGiW܈EQQpIF]s(k0#n &]? .:i]ɢ)dhHtQҜ\@X ˍF'שνe+Y,К$'B֛,,}%pC oXt[Љ.{'|А;&\q+4bazmte5ڱWY2{lv$˙jI|$H2[7DBksD95uӨ$xA a:=*;58xn`Q&i50zUbEApl!'HrO\M=+ϔ-]?j3Y]4%hL/u#-Yи9rky"gU"( f7HFFzR/%Z`?XT*{I$7iR!/`s*Vˆ02k)teljb Ԛ\V-Ak5ǂ"5l@ܨ!u,󁑖&nɔ10{Aeز57u S`p B! p,:1eɔ!Y%х!hxHF'LxG1dD䲽yjݔ#2Vv @#p if` [-h}!=(VT%CmEE}_Md 6];!d3l7y} 4>z73]0.q]G?rqkLIrv2Hs|/zfMU =H9",nycDu)%pT IX[:bKki ,H\pPҠmSd{`y"ܶ* Ϗ#>`eeZ 8gDضh=&oV! n(o?f|e-f&*Jv mȔ$4+E 4zro`Wea;k>#_NoP䛞{;N:m f1I~ o8EUŧ -&,YXӐG83д y#7p bK\}v|C03"Z. IF=sVqo4y Qu_&ec=&:Wj5k-’5? c@(&/զx7k)cOQ&-Xr0 -NkA Cf)\lG}AЏ]fcu_I@Z*$[4 B9iX1q?lz{]8zmgݲs՚8o!4r~PSJbo'EsXY u㞊l}'WAQg: qu tGyF2${ r 4r*a_,#錗Ucbl (  oWy}2:6!]n d^@[ؓ=]Kt5"" )c 輧& M3 #>Wy^q6"Y2/ siRԌ| l?fӛ}pdz9UӖ1rd/;F^ΗJL0jdoܳͭc3 ڣ ؽZdCAȿy,%?C;'0*r_XB)1sSp+ۚE p6VbV1n Vdılc=PE=B C(*246R |+4dz6)ϻF5.3s L᳕ D_-^lpga=1er)b<`K2d9. Z8’sKe2l 15Ŭߌd{mĦ~>xz3*hmF+L$?#&o(m-iROBO!Q&%%׼aS ''C GJ[}:>l O=uoLkFgTx!ߒuUvMnLJb'A& L ~6JeqF +<(Y; =F <$? 1JyVsd9ŀܓQKIz{r/%*NݴƙTE9hpBj@0@9j&fal4SSb JL.o$.:`{0T$.`)t41_S\稺Aj!p% Wr]d 0qtק܎#:?"#\JIlI{+9v[b#uY}/RM 6Y8fVquo3ѓDǟi&cqG< 2׿}x_gRKH h"]e GŲ!Ű]d͋ޒ<<hqޣ XTr z]$I /DSY8}Ml1AjgMa ywJO[=ؘ*QP,:Q_"[ET,%&Sc|;ߐ"g |1`$ r]e,B &`~_<*n#"^b}+GhƅKӄBP7UOi(zOֵcN^c\ UaW 2f3.8*VEqF+xw{a[ R!ܷRf+F@;J.VlQub'Ed X/{IiqBK!axmlq[ۭ.O5ps3t&3P<0$'nϧB8n0@pu>]/*H9$)6oEr3cjw- ٕnXS1%ǫX<˿"֘4\!EY4Lr46QySM#,MSuOA tB¿#Sa m].sD VMyx!S^v8άAd H{ɸQ_.)\0qg`D6gU9܋ZwzZ;|[~^N-En6p(,NW@l"Н^E}Zyvm<a( {s ,faN*ž+\'K?s|D$'"UNm@lcT(:BaF/l5*FfV8;RuSH+{_`W=z~*#A?!:Ԟf6Ӱ;ś}̡0" a#梤oM]y5*ז!=pZK۳^jNs ?yT3l+hI3 7 S +E}$o\$Pt3GE0ȑS|eeŗŪE A2*gf CvԖXL<Ӽ|4˹^'OP o|VL at{c]㭏T&9Df0Q'wCgmQɀ ֽrb2ȹ[wp4 Y%`uZh_[1IDu䞾󈮆ov55ͺPf-Е A R|<U,ueO_ jg FC "sY@jDȄufYr%;tRCxM|[3ES$s2͢)3n"2[i0m;qcR\/(w[١g,1h|l#(Vfi6-5--ۥT>-~駕2z\_ŸzB6_ uV3]RSO"@U.86GM{Q)CC I]VkYD:`>Օ`0µv^j%@۴̱@9Weh09zW kRǎM(پC6N{ucl`[)+ՆKb@ަWJJbOQw4AF/f663'P\z4 I8n4˾_oϷ_F^(K#m^-j7m;_T>Wh/+he^lDfrA!c(il4d&uDvi*}/NDxm{j(qC^LBkiC+JH;>`H=9ӽo.R,G Hc[sQJGC05."8t͍S`H+uSU=Wo{DG~]RՉzUcGdd uvr<Oua?xu)̒3 #CS4VSL鷍 yx>%`#FaAj/hc'4 ϯOatk[nFUXgvPKDA<$d wiS!b6A6a͝s*F0Tr` !n=,J?w< ۘO@?ԫ*r.xtL#w`tr2i[8Cޏ‡ѐ̾wZh;z+&k/aH OIB8soQ0E{,3r#sUn&d ev]u#bd Fӎ&F,:M>DoG&գc{?BqxcSB֎;)Dڃ1nxE\Ϙ9Qٖ_&wkO a;@gxw ;$ML"N#t=<1hm7 ")[]ٗ^(t|_!HiL˭͊h_vk `2:i͂bDjU5 Eaʸ#3}KUе梭9ۢT#&7LdX8/b{4+(x,xV .[8n0 q KI,Q 5ZWi_n"J?DkK#f|i{NuȈbqǶū'Y{Q /¨̌I/g-b5%9)m$Tp1̩sm5M|js`3: A/HX`Oz-]R=eA!Xc_D0}5?.6TŜVA$J >+1ue=zݕ ecf 䚨X9^Py^,s7}Քs:ٔXo4G|=Rݠ%d6G:ԷmX 7Z d[Y d ;?gɅ q.ukTX=1JU@aQP+]"Z"ˁ \pN;F61j)&ZYQ5+b7fwͥ0cku (5Poǝa3ם~[~ʌ RoYw\B'Othw,o~P?".C -4H0xOoYo:50BA]qMKh7N(f[.nȝ}gEIK$rز+;# ]O3?5 ,l;8KZ'I)$emKp+ D6z1.I.;HGŭfH{L \˦ia(sEWjeyYi]+?'̪SS2QI W+v *u@, OrX2,arB݈"QL}jWV͇@AV$wZ&lGH{L%P]L H'䡚os4x8`kFDAx5{-ՊŤֺ$4mb Bz!ujV]FtLˤ!itA˽=yۦJ^74ݟuI1Jd%oiD݃NWo̥ aKFcR_c^-RJOӇPR|:ARjyxД]W:d(K=MGAx(ە4LLw6)_n%gM~<,[3B[){6@ɜfV'e|!]˜j>u/ɦvjz? 7}Z#}CYXj<%%yOW&p^nlmFyh Yav(RCS?d4<Vv̎@b;(\Ɍy߸.JYHA]M?{`ѰXm{Ʉƭ^4;K tJM&x.B3vZUd!E9kߙX<3?3ޡWυ`W"Ix{^ Ŷw><S FLk4׾vuC?j#z3AkK:=Ёn;PA/ xٷg#iv[J *Z;bZbm !T~G$ǖzI|*xvз:6QtHY7hI^xhƉmƯ}gry+g%bϒ"5_GSU^;FDjݠOk`m\@,C}/q2tc\.5̔cimtScN6;f-at+~q3J"r<߫r?R,L<YKhrIu}mQYD X+fI{S‡qqJ*:=|S+$.3?&5NYWztޓؽDOPY07 NKTn$xBl ׸:\*r?5/X!ZwkKҟЉ fqz:=sl6XZ(O5<`iK]+xR)Y=0niw ;ӥ@˹螠L;u 0,o5]3}y>7¼L:DN^KgNA.uPϰP;Ms{x=j^x:4P)Y(4緣3hiJG>Ś$<_ =HkLSUx5$f~x$SccQC7{];| :!1di튶jiUӀ/w]pAki5y1SGa-ٿL yڋ=rg; T`qaR-Xb;@|Kυj]q\>|BpE\j14u2)L[IN%Cϖ{68hKo.cn9mH#\M]'lwCh(e; Ep7%/!#{BH2ja2a2Ccƴ65x#I؂M ] *s`Ks ~|QKQR0DC,C**5fbKh|tGL8AQ<]Ae&xC}̬ߞ VB""mw:;R-~aLr|njpĎ2$moqۮfXu]vS)܎޻fyq=,a2m#+T«4iۼAѦ.H }S@aׄfX7Gl^͟9ebo|7--NdؑEi gFvztR+ۈį`:ÙrF{QgN3I-6XUXpb4F-#3LݤSAW9WyCH6Bw{y-x =<|oqdH]u:L:-vmo-w F|Ô~hX6 = _%;LC7+3N ;pa|J[a`3%<m+q]C&SR]Ɇ|5wθѿY5ҭ|03p6F VVsi{c*]UʽKgo5.{ȴSfuArgOκ#bkL<`ӳt/DW |ń"& t`lS _(:ܺޛvs;z#݃\v]B.>t J線^""K񺠦nylR:Syljm+DRFJ}:! 'jh*~I۠p9v_Zh˿5INIL?[Q̭^m<؁jXG~ᥝh;vR6kf],K?Qbw{JL VlA.Uy-b[rڄy&THd%"28&ᑢtDL-Z}ruGo)"o_kD}*2a<]G͂A|.~zYm8e~8@h u,x̝(eK[zGȭ|XrW:]O'g6m- cqxM [& z[o,x&LSX| yJBӾu0yĶ2 d 2b5bkawGjqA*ɐI\ i3)"?ih+tڭ;C`XP}]+mP\3?$d7^4N 9P.'#Î><+ Bтg: LŲvRv &Q ?zz6BŤPGDx$rdR6jC9tD?@;NcG)ʱlPGnɞ͜\KC}[.w`xӛӍH ,En|vﻄ&,UdE7|x4jX Ԟ^ř(Sw,{-q3k:*$y{8A1g NTTܗڅ~n d+)4E' 8433؊RƱ/H-3OEvU` ;  ]莶H$\<TmF`w&MYA6L>KT|縒I^ڨ.?^vYue+?L˝!5E@H&oˉ؅Az%;9GT֞oÑϲb8J`lG$I.boJPAq߇#ܐ`1pǓ.y_IՈWp3 L<·cH:0-fr@!) YOlQu)X+ 2-ȾתǍ쵹6FU0VŊ @.lŞzg<ݚbh+G=fkM+iE.6~,WRj$`M]5L]/~=#h忞4y,GG{>!l 6bP zU![|-1;a&7߸?</ Gb*:Be a 'vy sVH+gK]pv4\t4Hxs#")5l6L26iffg+tTx'7AgT-䳮!ɍ'z޸-=kw>pv3]E?)' FŐ~"W__`h0i˹:H2?3g<|$Vc6hP7\|9+eOTM2quI<<́UkzcF#TB)!NSxέB*}o] !-zzAp07Ɗ;: {q֙iy6d8A=EŘKJX}TeVMF؇&1'm@ -av%n), fѾGPt[VHx@?NWA% ͘ Ӣ4HYF㴚g#nho0H^(RMn-VW% " C@5l~r]p:jmt9^##4j!N 㣗Q̾FӠ:ҦzZb *tL9<ʄ *5Ͷ_1֠^v)yp(4Cu-eXCE»ї杝'r>9pCJ;I-r83To49yD괄6ڊIv$mAp,J%:hH ӴoR2ein#63 52dXekZ#q mpsՔ92 GOs][} )eh7Jr 4*: }L6j"v]!TczVa)t_Jᙿ{ɨ~,/# sKS|?HeQ])l! hcnX(<:͓^)h||AnZ3MqOeG/n>moNr,3R3m6C\XԳNhNj'@\Ic/(dl˿` svV2>"7z'RpiqJ*F@X;'jevrT#퍨Ϫ(axE3n2 x{j$r)[ OLu IQa:noqJ"wC Lia BG<›7TEza~B~0'j}i!02uήQBFҴ;M8i3 "LMCNh.a=Cit|/+ 9BɦN'Jy~D}6eBsS흦ʔLkQ]i=tF/H^! ,h}6Wb$tI@iʅjHGf0*?iՋ9H:~Q/>mX4ny1bTƩC?docg)rI(q`I_!*ݖi$a3Og8l mڏo{!|^mOokd|z* =3[Yx"Aw!›󓍢`ā"TJO4eb4YcCQ5Pj ITO Bh-/g+>?9ym4?Gg dfOk-O韺l%#HEV`xN qIɠ9~˰8Fre;ڬAJw!P+o  7΍A<&1]'>뿅̎+Փ :63 I{"%tcӐ28 vJ18 ģEw+8&Jxq\=.?ીx~_gڀ#D0?r@렦@;&H^tB6n5E\<ִstWOe'jd8Qorl{lbMjnEdn*/a'_CEMEqhF$iQH;F߳!&ZV " RMMq: xS:mĖeQ{vHM tvoCnp]%Yums{БOH)MwC6֠snh'8nk HSw5fr'zrp lf3ϮTf2{4 b83h1 –_`}'gPs}]%r!D14uA>8 JYDž/E)b_C3Ӑ YIC1Gloq=/et67ckemE voq^#(HqDT)R&$#*~1T(յP5z38NGUTjF#jUmۃߥFp)B&PAo ־lrM$b5I;8=7FBBܖf~M# T۝ Mp㎗R {'/f ԰svM,I|iENFa걖YR_^_Fتi"167 HuW}F%m~پ3vN)#ȟ nYحM,) )()0<P5^z]he=X_[PduC\;pÙ."6I4p3 Q֑Һ@O؀e9{eS:: /}>ȋ0;E!;h+fikc@Znd%5."`.E{`'G냫!$jޙZ=P! @>8#xre ^26y*x p+ߎMsŵ<)5@8RN_<^[F7tN*ySd_ʴ^<1`w+G2\Puɦ՜`#l:ޭt Z~j!]b" ^95~!;}֟kN:m`O;>OPp?M0<&Qy:w 19 VuO†BA§WL`z+K [ԜJ5LOiLQ2lPy(<}//VS |1bIQJ.l 4yrQvgᯛ/$uzu@'j+Oeh֣{ȩ$06n#VgYwhbX6f)]I+LR8`\%~8wքFqk`qiֶu@X7A!Py-5*2;)O r8:((6n*&z*ӕVr2NJߗY تśFnN^ m~ } 8z% }9;~BuN, ^'C]F %Xo2>WqWӏ9w菎 yY8칔 13f`yR=N_i =~>'>84T[D0xHf9oAc$ЭJ4y֑EGBNQ;!P( l8nkbQX>iqZ*,Uk*WNO_S2;t!;-aIXef`lv ~Di+>mfzΩ$vI&ކKRSh0h:ձ'EYϖ6臶]|=ҋvw9F[É kZ(5ꅨ4t:{V8&nd̆Zĸű؃6菋Rai.2Rq~!,@[V>fȊCؐc_.|k\IufQztgp;y+P'ƙt0\IQ"h$5@9rh#U>0DQ6K6B+z8v̴=eppyAbW;ѻBP>ޜ[rroWcVOfG1b Oܟ;~j !9J 5ޜRV! lgPw^xrS*0\9R)ɗq:$I擓fQ~bu OLxaZ %/gn[`wXf}#;WQ[Kkz=*VU Hub83x[# B lJ@>x< ƿKQew/"E^&dA٩ڦ7#;je)Hmܽo{;Y8)$R;Q bY!KuZU ,CaWvP  K, <(›[`qFV1 n"6}c{qf[p_k S!O yYY2Ik˷PE6w6(YJn0}=$W;ɾ~g,+K"֘l:tuj*p 3~нƲ\  kGl}?Ix7u_6iyz{Efcc>Rba"-_ N<@;l3䷛.-OE'pnt[6;' ö $a˙M+?q˪ >ب*BdSl͓ SYAmX)@O)6Esˋ ѡ5Lп"]ALάOdholU Ek8[Pvy̜zDH.EM6v X?S@~% }k2WSWO. T/w5'*S&N-gwuv!w,d,y=5U,v>\B[,5) dPr~}qKMPQsJƋ:̵ɻ1T&6ޯF'Ijj1&λ}-]S܀F|+j.jxW xA-XBf%NQ,̝^te(LLk;h/T+1v9߱D`~jW/FK%i4(섮l;$r3q۳pOyZ%9J{2ROeAɠEg~|b#/{ףqKnϓOJ<5CXّ;eW|OP1mth)HōM}feζpQ̻r@Ai6Im&_F6 6VoĄqa $.U~ /M)P# F'V K2W_]م;æB)cD&}zbM1/YPO[H5[|BBᇄhgR~z4 (w|r6]L $fw=ڼV2v@4s>CM Is.HCBdIz! s6U|CwzHrAɗk?=v>ǓFXX#[f1wָڕ̊]PަF\p # `BZ,dQRT{nTG§ŇO'/?dp.ra)flW1?rP#0|.&p (5B!ZscsFAhU,vZ&uX 8f.pE1(!G wKi#Ngj/zXݻle ܑM ']U/69#ĆV̠&ZD&{ T}6A0rz<Yҧ'.& 9\Z͇vU JuiGƳN=:KL[ X+{3bRavY՞K U $iw{0n3af~mX~.5H࠲F׎IU{G*3ڐ5Qw |tPM^o侫!k\J\iA `DD#,wlL1XkohkJ&܅?}X0 b+>@]+ច)ep;)B*s-8gF=vA:Sc@Y l9L9=ܸvuxrW=@D7/1r*A "pX/L^FU-S jx)uoǕB W8$hDԣ SD~ ٘{ &L߫Ó0[)oŘg=/5a I$BfugJ%~N `ȋA ^\X1k$ ?㴶P9sύRijS []ڃ*i[6cᴌ9>^"Nr"ڙ|'I!Ra lE9P }=]"oytCe.eS1c ttx"'6 W>#fBϸ1Vr[ƨpVd3OYJx?N)=`(` {ZS`D*Wvf(]㼤Kn,ZZ!Z \̤&;#65K-g`!ӭG1?O~pcrATQQS氐MjٸO0r6m8Pt]KEOuL#!::9W.pnTPȲcŏ-Zf}3bۖRFbGٜ"dz@r*@T?3LJ<6Cg7/lVp&4t-R?TZ9Vޣ ፳ .i @;uBpFk!T_@%X4UK[5i:ơ\RUأ8ǝ,SЊū~x'h ĻYYJj EFz 'MaJ@ibH7{]cF 9Pa|Ndˆ+,S{wb{Gs'Zt b=wSƯL݃H4x-x S=  "jvQp:#dygvSb"$(Y f|:#̼^푣3ܘ >R€?Ao 6~s?+ ACdmz-;Bd$Q(F6a &Cޅ`8ycͩD|+2TrCM-3³=n &x1n#1 I0㴠%m}93NK(z?bPһ_Mq!d?3cuTڝ6\~&F}=K}FO?؍Zv; r.@a0!V;sz=+$2 ?8lWuYvҹt(A"3[kҖV.CUd0޿Ԋ۰΋{:4tY.5/=hp˼d*8 z5-2U[/X+ ;k"Kܹbv PUGiӀt2CKnƺTR؟L ݯd.\Sɫ(s1s|&gѴKi72|ߧUG7h)M%݅y] E 4z uP!Ҩ,>^]u?Txi:MA\ԛZ%rȴ僜{jYZЬMvnݨy_Be'DsYH;xEض"8S^p6Ҷibo7D|*Ƕ FrힼhkՌf,Bf'G*z8᭫(8y愢Q2Rb=w &`nӮs|}ZM3Eǯ=&%L}}6jWՆ;X"= :gYo{"/TRyI dF]L3K)c`2Q#π6}Mf-0h:S R\hę1zdl_T|kw:лwT¦hnRwkǞx^mKD_g媀"1z).s#P+:ÒHΗ\ XbHQYg-|{|=V m`Ǚ)T+DjkZY1aCqfW7`Oޠn{% A8@Ʉ##) 5;\\ 9 @~c ~U %l}-niS [(Uu|0<9%?[s- 3Ql55aKf-V(\*67*?"1q rS!~آ-a(C? ?\~ wvȈap)5 ~RF4 3c$3]koRXn,qi>xwxpMVy[C?pR=:J8h5W GJ )R0$ӿXSo f} >?C:;/F4PJX&r3y6U5nlҋ[dA \59žcĈEslĨY++Z7i*kE)z);:HfAJn. ޞa⅜ƽIwy2:Cve ߇u$M+%?#`:7N,DD)0EÃ32qǑ,rWej~zb #f~g mw.;swLU)ϱL N_5k@:lQ; V`u—\ z\n;ۮj ar2φMwSz3БtX#`2G3u{`pqi=1\3bE7޾;!s;Y䙰`9 O7w7ߘV<3VF2q4>:Jؒڵ!QjL: O6ڣԒY 6PlercN._-`泼9. r4"NxHSE<_pd給ZNyx9UDh\ Aq0'V%A0v~2?y"Q[Rd |F1X07:2 ܋猯ybDp,ICZ{o,X9@L+ɠt] k4Æ~QL̋ߞyNp&XfboV6&I}# 睅tMY![s3>nmtR:*1Zko6eΌ&bVn*;L40UAhR $,0sbWI%o*+ã!<Śv2״LoTl 42Ha댘0mH}b}1J?{*!"5)sw0tXFQG")1GXZh~'I}ZH2.hPJ3cɂ{m,.LޘՕT}s l-fL,Ÿ_#ْ.$ō/KЮ<θ`9$- Af|i;%9ΒLPRR/$ (W֥Zۓ hUiy%7Մl碼~Y2/]U vJ`SUܜVCV+c/~G*hi0g 1ɶ Y _W#41l;1×k}qdm6?]|#ؒ6rmD3?5h MRBFs Bal='0K`@Ɏ nh%S9;2IT/yUJ&КH-X~~5gez%K`V&bZ2٠ud朐tp .J׵&q~j ɗ샮 Ŭ8[ћ ؘpC'~E330M_ֲ#]ݾeӲ]w5L :Gd9x90Ǜr9d-XCjX} \:9[FsAPKn&Z&q\r%85 >Ai]Z"Mq ō!7lL=}ߖ3(~0jr_Z&?&.#DUI *. R*7f },!Xa =!z[(]Ɛ8a#-&wpzY=z WH KʱQf KPQQmv#ap6EGo;dߗ H4YX v QHOgЫR^$PmtIΡ%$sM%=mԏՀHU7!V,;Y(хDP?# ^]qg:-^#rkF c&6oヽl\܎jfUzȊiO$?u3}?')H&u]8]um=/್P$vİ#zOlu8h0Y)X*.-c+ckD9'[u `)8Y>X'0N 0nm"JVqClMD*[35mD79ueaQdFE2GL!\ӢGk/TUZQ(#wX3h+ӘBpجlSAKb5qC|q5IL|bG02z26'c vNMh-Ҹg) ^50үv':Ѣ@(A^^ݞېuTrGI1aRrXն0fԍ9Ǝ<(o;I~ m.65h$HͳM(k7J]ٟF.:vNE#4A3} )%!\ :_EK赻 HhL5p:Jt2sEIEL{2?6L%jGA +?fX_\(%Tb42Iqy > j8! (+xvsY^&IH&Q{J\^!y aŒ9ߍ'%a⥉ñy/'WVuk!F>?&e7PY;~2~GQGʋun$'',*T[-[ãU$7m}hxhM]Zja#8֘c6+ kVqӖ9Vo(h8͑!G0=Η6|9AFe}7H#qI9=Z,t<bBD.Jt2J~ ZPV S `~1 KL ,Rm&z0 va힃XJ9/'یKoy<,ݻ*6Iɻ[̙UfC۟}+3 ~98F鰫J &JFfmC\U-*%R龛MNൿ`xZi"O*wX=1%JgßUINZ 0a-Yc#LN>_ƅdaR/(/~fZ(1^{vV'vQB/CHDA{Dƞ,cIooG#ߘ䫨T"z#oT7EAi8la%v:vE8MQJW*$C3|n(].7JyE||s @7|l;!EA.X(YBJw/μЖrd-&+p.D 0UqRFn4Dvӳuf|59|8Ii2G_~6thm::e2G`R 4U0X\ PzeB odrN*xstӌ޶$M#  6(|;ݳ{$,O?f22T>qlz e=^>OIGݼJ޽Y$j+f 7dl^.(j! 4ZmvLNY=>X\$,UeF8u<&Lg᫫E*i-e/s.:{` ג-ȍ8G'# fdQ*=Wc&#oՊ4FHzfeí8"9v<+" I^w1PClwI4@ l ȯrUɸv9xO/OUXU|)yV!@ i$T5/O#Y[}{ٖzj!>"p.85P%"nݸ3%}Vɨi\m9ffBd7WD@3tss :[?= ollXv@\nwdLe3WGҷ|NjϳwTւq3i;a[=>bQrؿxg6kjuH8{H,e<%$ޚN?!éP$MDw\%Mm=4(Δrc}}[- .(ٔZf6+Io_#I kFr:*&Ekr2 IY0)éK8س*2c/N 6mrb*Q5!OZoAZCb~O`t sWD! }Qy{uo>4eH{p٢LF|kCdJ s~<8|:{!NS: wn}l̬#g81NܰJIkzx^E% 9v(?"?:+_BVJ"&C r7ZV\(- Ӱ&⻈]ыsmQiOq/10fP+ EfϮuք '鋔Ri/xb3WIiXVc NKAOZ_q.e(E;4س״$\& VehXMXyG]b +׻Pi Rд,aӠb$;z z>me~ogJѺHIJ@Fi@CW/#ImW[P=l}QtO-wHs4 yEף9{C[#{[lod-6r6լJƓW ݙ$b6^s%GF"nS׮BFMݗ}{a//`w]yAUb!B>FoBD[i/v̪Q7J-#{!1*]+<=;Gq>NL1_r QDӓKcK\y|꼫!X #&v9ۯ)[KD&oNѷ*O ] Ёߡ[ؒ`:\4tDzQqAi~BD 5?K4 '۩+/yr0=Thc.%8)'"|9YY2 mp:fBaj'=`/>Nx1ǣBׇ9|eZ+Hɥ7tC/EhL30:bQ I{,39x>ϗZӁ}oP 5z(ŷS,6z[l3l +AeVF3ԢmD*#8<"'AFxmM\"r1H"6W>pntK xYܴ׃"Xg琹єNè ew gF'}27}T({& *bz?>L&P+= )C7d=H!Ur\2+.?Ojyn7 hh}+,2?W۹.W[bq<q| 2S) eO' DzcD;Wq󊪼e@C+y1p_#'}U9ؤ>)UDԇ!E0o: +i p~D}K>!H!ARk0FNçwg rv(#'#Ų67n ԫ7czWgq Ȼ= kj䘞nni= zk(R?.vB]0vh>W@%% Xo"kGIDyŸ'FrôD"a fLkFT̻šf4f:pԂ|=8[d$V63߸A:X툜 r ,8Q=yA4MfGͽXdk}ܻ=s7ws—K#>u#MUy+?J51tVt,21 3=!"ZG~"zgqc2-*hko'[\p;Pl=YӽyT?x* Oh/AX+N9 '\B|'A 2AFdC!0n_Lh|b= = b휿 ›}_?!k/pA I]fPSi+^"RԵYe[ כ^TVN a֢4&"ɜRjua{".ńN\Sk녉]#״Xݟ b2 =S}n]A_kD]֡B + pTuƒ CBʘc%Sn|'uW>p:dW>]m33^H w?( ]y`:(EJ2':VQ̒K˫nWSC 7}A.|rh4%*Xt;؛Qā;C#^cn'."/Z3?o ,J#CwrT౾0$B_MIDҼwV08D߽A҉a9ux$ Rwad?RV2.d[{n6‰[1W ^_8dtOO&=͸ɇysI瑌τ>`gU"B^Hc UL Ӧ \ 2ui4w]4{*t>.L+< Cq0y-k~g Hv>t 4w|ġmh _XK@/:6}Pc% 2 P5Xب *K1hvsmmO87JM)d͙3ߚ($2`z,{XT\3L9 &WmߣB"A]%2`^_C>(4Y'˱~ >)/!G@\tpuREu< yrYpo!ʑu4m3Sl \"еbP b/=Bm~3A^7E;NGoq,5QcN>zvM; ._ĂPܒp9xu55)‡x|qPb? DWËn &J,bq]Yf! + 2Y 1b{I2I߾=`+GRD6@x(M[.6t0K-}UK,!3 ]ߙmphe=Ow*GmdގP>iT&&H9ʖK/ҔӅSMAU%%u7">d,t9C'"BLGZ\a^wrː%/<]cBq66 |-1J&k-@qD/\c ZՄbDuW;T& Ꟗ#s{a\˵ iqhWa 2#k59|#(JPg.w\ٮc,xuZe\ObH(}zmD>wlV(\)EV -G%9aV~ $rX-S-_x6:@mbȺZB֧4Đ3-HՖތvWRU_%VHjg[hM tCnc}%0v਎5:LUN |/ 6N llX?cUu~CO!zQĔ]t8g$JsF>:q?Ҕa)/iSFH\@7>WM|hc-Y[P|Np´83AW\E/B2o ֡!LahPkCfr&7&NX>mJxOm<6}PKÒmM #pZ6V﮹gV?i1FU<󇣊uU`tоoڬm2~jJ|fx>^Q#{"Qq@?l C3Frk;yƋɷioy9FS|q$;ݮt0(lo>OH<]ٽ*pɟkp;g8O>I4Ks4p&؄ӷ5<1&b3mƤxD[xS]gy=g߆kAո@'?-WuJ85dʘǵrDAx %8aﴵBywU 'hQyQkƛW|N+J4a_IۙB&Qp2j"8>dμ{v1/\N p6 rP."5/C8~ʈ-^D5a4gCp|dRrïCiH tʏHJJ[7+R9S\ nhDq/ "Y`f`. R~ۏġq'P70p$YVnA[b7뵬2zivb_hȰ㡝 2N\W+I5^TP4;`PZ LFpNC .F9e~B&xk!aŕW3ےNGyr9+O +y[o[9&,Q)uH2b*~j%߂hHY&RUmFV 0j UPfnTGՙ;p4CNu,qpLdu쉬 ֬xֆaK>mE>_9qѽxG' ;@':pV,@}C9 #;ja\5j2^mmz6,!97^}JI/\^žχE]ݞ*ƚj≐}mΓή g /(QƕGGqѠ%Y8l}]-Zm3d"}u(I a8\|8 ]6Ί ;LږqHtXbsg^tF:*x$Xܬ] ܟDۋR=PށߢEßn&؊ا_?q*yyB=דL+ޠNtӍ dsP$GMsPy]m8sU&vGQ6ܲJ"iWk $U Q6G43t?T{!CaV^ܫc4= Y}WHML7T'VrFEמ*Q>k%e?]_U:pw]~,46Bꊘ>ƶH4=At 7vi $&eBd{qYc RK|7e*3\ }"c2O~(E|x YhNt,)1ʹ!pΉyFCB񴁋%év1=AYx(?1?T0jG= Mr ҰAǏ,\(rD!&0 O) 8Ѡ=qJ!tN\SܛHX7 Md-3gk9%r-YkZH8!İr^8WH3ɠ E7RǝG') .:l&p_2~@i&L+!axY)$ꜿbWMͰ5qX lc|GJTtF)\|w׀NEŃ' &V8dt ˝1bW`\ UXP GZrzl3 ZmR)ޓ64@ 5D# #7l#snVx{9HRV&Cƪ -RmzbW^oOaPT|H|FזB7 *" MDAkA X߾YWO]X8tGո~\oupD):}zFF24`xv^Tɻ~rf]Z=e$o {ٍ)u_>?P}) S,In@!Bw,QP8kps޹8"|:Ŧ:R(t;TxF bx-IA۱ @?~4sUVS.}fOڅ7U.[dRB@r)1x^@ԀJ4|r&gDQj!#^fg*&|d@^V߃ύۖ*1s;.$/òV%Q'/:aGUA|r!Gm)ndANW̛iI"WnxguY+Ph8 `H ՃjDA%Er:2ft- $ik=NU$x YA[C|/f QuwG'fdWٮt ` 7ti;qn,:\orf$O"nGĕͳ7e1EO&ם6Dߒ#Z+ cEpp󽟡'@9< 7s>ϛh`㓊wя _Ӑ8\;CcQq94Pg#06g d78E/G `gxXYj40N!x~`L# "p4YozTJF8+/(6ވfD^3!B4vZKH͸9AVz{?AZ]CVL6ڿ]J]*_ZzyyEugb'Dqz}!=k%d&~hS=h{[83D* }J^ڪVzLFHOݎ`Ok鳸ttr_KCd,:pxg }t0a[qbYzLBuTHZ+ԸzSFM%r`ڄluk7oɬă;v^e n؏`U,)j;ނDg}K5 G~Fb,[}/ }zavՁK|LujUsA{?haګ>;0QЦ/-(66c2Wym+ЎG@GnM*Au"aہ 9}֠q,m \kW f`b+)LfOz:UwD_1pq,wiyAa9b0]38;X#%gA8UE I>M Z! 6oiYl09|>ã*g 32+t:&}G6Dg 57~kOPg2!/OgHK<VDDy@{!DR}V,?ӻ~3u9[xTѭy6sкrJ {/_,oT21_u @9Ro%7JaLM =W;`^]ܮ=_ݵk\avp,,.qlvUqR;e(/Gakڽ|`Ie*4wTB/N!_l#*Fg L̝Q3!~ǢPeظ v/r:s9`5=oպFp L7[5f{T{3Th$c&4`AXu6-nҊv˜$JBsuimA~rwǾ?#1oB^U-"Mz#K, t%,fm^!LQqy/X@@$2yA]% ZL72Wg_8}Htp`FEB1U{b@HVð5D͟+Zi/ pbad<.S}p]QԄ+lK'bMh)q܅k ɜoá .x8^뿶q(QC1o[HR `N 9^\zcJ/WPA.RyJ=9#+.LA h̕(_FhvgSSZC۵}8&,E`x2(*twW 9 JD k] [ga{h [GiAdBXW;+X*DnB6 ܬ|d\J\5ؖQ+HD\.jNղZk2~ss(ކr_A5.!N&2-JSr'~٠~z'/{fcVp++p|+<_@8]ҾcJ _@.kZ'?Us@,ؚT6XC!,}oB8!a oU4iS&Ӈtg3lo0Z^RAJQ퀢Hj.өdco,9x5X^`5CM-孚.8Fs䐰wg1^"C1[­4cSSNQJ J5Omu2qف| O+C1(.ǥ`G1xw'Vej1QV'=zVkB"r=pۈL&w$A{0'"Œ./8`ڢ7 ui6f3Mj{'n6 5uFY\BYQ1yƞ?hbԒu(b;P2b f3O ϧp" AwZYp2(uNgPQ\>@{XRl8WK2g.oLD|cŸx,E 1Df*wؙeOjl25e_j;n=q. IJGa LV ^>BD O#~ y4B@rY=*l=e'6uNg>حpٵ³كØ?O@#u2t}j1p?请Z =Ͳn: 0&:hs(0P%{T\$W n30s̞xx6=ⓎqY,콸@%GφyH/uѶ%(39T1SpV:É8Ү x@d4싵frPoCǿʻف)_ɘ=t8G^wV5WHu7ȱj s g^7\ ׶U[R 8l"B-å; g`ƛlF&H6Bi᭢ "^jn]6N:hTh &@_=sg \+ؕ9Oj1T%$˼K_48RB^_2\1"/WNMŢ>y+t-KH ?w]VٷDhkST**(w]㴣mX_>ZlcK:?MHmMsro4y籶h/Zm㕉LF58WQӋc_6Ʀ5w.X T1g1af#~fm@h09q&{dt^15RC6k%ӂ%ljP?g8c4}ʽ]r"KDK\ bYd[s|&~POznäk,slx6m!ۙ*vgtnSvʿg?_E>?#g$U’EZ_P 3j$b0 n$gȂ?MNx`1 =t)iٞI7,}䞜Ah-yNB|p/,B4c^*[ m:W$ŴئeF5 I^>Nt )ݭ:K{{UC<3Vi)G@e m=gvui=yЧ؟SB^4nm0+{pE@_ۍLu`V2?bJњ N؄17sm汻oB2y Bܹ2 .UnIgVo+qn suk*m%lZ"LZڝ͉Br+Ry̹^ fHr'8zC)%N(V&QSI$)y-K(y&&!k Vwxܧԧ#6l\L̊̄C1ZfLZL4L$~KyQJ2([: ~vnoߍ8ٰChj$W+Ii*')3cL#xj4E y!X??!"Ί=`o&PB6j~#N5p%Kw r]z03,SƾZmp%z6/@DaԒf+N1WcyL=~S^Czpͱil*b 8Ķ@Xd{Dp86>ML u*0p!qx08~Dzv'mPC?Vv|7d֟ݡ{7 Hvз.ĸza>Rj0 \kM1d28g 0wXM+.x-ΞEGe:7j2 JI 좿;nقW6g?&6 K_dtow%*^w?VOWd9*nؘqa=Jajaol$~oNX+?prc<%c 5(O@Z{J`\MU3 JuL[ɨKLʈB&8Fj~?ܛf8К1:N{7$g5d(v|sxKFrhP] ;x&}Оe2@x^#^kU`5["g! >iLxR׹pUf錿ɡ{&^r\Y|-1|©ө:QJ!{eM(UC@r@?p-WHh`| Ғ4g<բlDfH8;}hQxd~4~  n( ,@ 69$y 71=[[M YH"ύ">;NK4LԱ5gvM }etvA h/_k{TWcwW"m>bҎA^\fw܈$ӂUS`hqx؇VFܩj*2FkN>gFpЌh14F\P>;.wVQO;yLb6n/i/yh6j1 A~Wg*4̲- 5pl SX>3YQIw)-@0Q3c6A8s"pf3Kn9E^9a/f+dY :PĹ?=AmT&ӽ!(Om ->l{T׵#r-ȨY-N [zi"i_dqM΋Zؽp=qs/ c5.}ihs#tG2!ec^`O0UƲHA9d0 25%D8읯e]S{eX#z2@YQoIxFoi0:y/fCQ9A'%qfw5ܻ'KP>W\ r8hEsJ /6:G)్x7'T;=gh)Kl mԁBE"Cf -ҫ%qX\T $, `iA&њ Qzto6&Db?XhYW>GlzXW`2k)1wbva>6:fr?F_|Wi*GGkr~ϋ^mN9һCyʴI+l1]ި[ y m gꏕμd1E;4{@%cnm1D4Zy;nj=5pѴn%EIfq39/26mqY2!iӼh!E\@t19 -@G1(#[:OOSNJ i_0Ps C{No;q(lfN[[ꌾ]dJ4҉:l'_G*#19!bcʇ4@]=z+CBY;1p?i.ĿM3/zۦDNvoԖUKf+W,s®[Yt-kLKCs(Ts ?#H֤76,}@rg^L]g"q $ylV &j3W*G b\ &*G_Xwڈu1 ^j#yDH>Q'j"%^BVRxkT-1mOu$`0+VƑ3[Jݬ^X)*NHؙNM:G,i;?哾 #w~fO$x/x,7 ,uQ :@bE<׺5Vä B"i|%(,iN=JV5*9i{)d+%#MLnyއ:~4ID\/{x[rGd=--OpI0bjNAb K#@T]x Y)I<0&9iBxky!OcYb8/QIeLIgQ ]y$6Tǘ|O,ch( %{?8k2Fb/s͞\R]{ 򅒫| X%ȫ*!ƺqfhJSt,QQz q.[Et"B(s^M|Ƙ /xY{l\dg}Ԫ9v9j>Z[Z9 4 ^m9JUđ[C >25_oO8xkXt8O4ֈY46M$)U_o{5TtĤVć̴ZZqS#d+ږV|QmIZW7iMgjH%*:N[N4oEqlO0~r_U5&~\8nFG~L.ԍ(U`BR`@^Ŕ16Z& r>\˒=F܂*yfhA ,1zxQrlX,ѭy~YFKK .I1љNj:uI_`219]6BⰓQu-OTdY<ʄ5s#{:RnJDT:+#IjZʙL5)\C^EVga+I+njx]āUv31,j 52}WchT_w v.Y;Dm{F_7yl0X5ݳ#|)rw4>n;"W`n#_[C] w}Z d5@,Ѳ9Թ a1h=عC3ahAqsU^BR\BkSp"g켹u@L+"vqkՎ)6 M2*ht G^oǏdUa@ b{'aؓ׹(^y3GXO]6mF1ߥ_KE׎I"sSM+v ْw ?& @CB7Q%GO5fRwm׆yHHn'ӯRSk -)8cgxB`"/q NKZաl<}v89,$oav?T0|ZɄ«LWG>t_MyRbRWG^Yd N(ˋ2inJr ф^smayẫND 8dCR{S/H ȰMM"s&gFyjb'7Y"]Cm9' u qCebR]]LLdIόPJƟp` 55QW{yʽ+"M NX2WcJWExHv12-{Xg\vk#ikM}^r_7dIt&_c>21hu{(*cz(6+`KVԤ9VOEj;1Br珧SϕBwsa:֨DuNN9Pm${$X f <"ɗoG`5*ŌA@~/ԉ>j)r3v3q2q Ly_=gFS$5$ޮ܋َfgO@avvҤ4c@Ɉm?[& Em,FfØlUGŢP{v:]]AhATM*(Eۿ<~ {~{&w2$Es{@ABUdFq F˜d-kUO`A a DK⟭ZJ(JSJӨa $fFvxfr@!]۝k8 ^:S'a U댏h%phϣ?rB?^9y+ߩ`U m9=qBfԓʛ>|r˾3%)ĐN zo £=~ZW|/r,BU*9Iie^ĥBKA)N5&n s\ʻ~-w뻌ڛ m󀒚 @$`Rp7M ) 2' ,=VL+z  .[9ZG1;?[y*GtW^͹5blW2*䵍x1QuGj anV MP 2ȒЍӚ"]Ƈckg;OES,#"AAz;Ri;,2NZ|-x M̟ 4j9Ǒ棶7[*\nf?4UD~5W"()na ƭP2lib,P~V:5 Y\ce7g_2p'+Kt8.A9vX'>ɽ,VYQ A7R"(e۸p71El[`W#aǭlq1ax%}d+P:p%*zs+HrZTƌ B+Od*U4DAY_* l5bo O&oyWI@]2b=TZ>iXT z/5M|e;'QG5 rKDA]0=V :^@=ןK7eJ*9c @$%+S 6ɼ4k :[U+zBvFvY udB[R܃z}\?3)ZA-W&?\ _}(U]\W- ^q $F34[/QLjM+wvE@rX/Vk]\G%qJ0I%}GunbUň@B 18:tWߚ~n0+ ƺbU".`Cg[ubȏФ1-C{ߜ5|Կ7t/z9Hf:؏?h6?b됞0m 9E0Zpm-2whyIYmLߧL5ISܺ`"e00kF5K5ծ45׎pqӀ JfpPkV_ ^> @ H;+}ۯ6kzziA G{|L%~$G00eC%.܊ R9$8NRȩQ^3!"F(Mb Э>D{+ 7H*д>a$S4Sn{Q[O79PAmP?maT|uJ)Q"߮&Ȳ%/O5 &3rG98FhpV $d~PFwiB*tEHu,Ьů]*}B\C"Tc=Z8)mzum}O xه8-: krǘc:='k ~rH q"wjsB_Ì`Į.+$!f(9i)GVPaR8m߷{;@27{M||Ad@Q32E(Q V2@\5͊=pOCV \9kfd5Ј9  )ZZCD;RvžU8YW{gA9,-+LXzD{Y3a am F#u]5WI#)-=-crAȻ׿(&Q>asĽ#,\Xb]m {Ƞyc2rP'ċ}?(I>uAΰ|H&ᏇM6Rz۪iލ '8l{E Z:%.́Y37gP¨ZB՝Q'lXkd "ޫ,δ^zͪY.[˫ ϣ K J64]ѸISƘW N`q^rq@AlFOftGՙ\ j5WSv,b}s}À"36H<]>!g4>VQdLXLbSO_iS1kM:Kp0#巿lFBFi\tTy"IK=ݫRp:*?"dmʦܢY`H~YݙPbzCkK6*䲡P'j9?}s.yf^mBT=TiT4z&HY ڦD(Euؚ-*<輝R+;L.&Od\ڣs-ʢ&\"!Gر+T,[|+l{ X-8ɭO77.@ VP*?+(kK5 ,x5(h[κ'펧b]`QV =&k`&m{peH,S~˿ 挻ىJ7x0Qफ़/a|Ԭ"&wt/>KW`_*]C@'RK1AJ6 9V&KVqc#9'H\8< 3ۃ lx|`rRTehn.ʰ![T-U4jZk3_tpϩJ` Xg78CXFnɫ`y- ͡RV$".س| 5g!p_cUcgJbgm eI^m UHas"[CQE򀙔W, >Nj)˨yhUb'gref  2J@JFT'ҚUQrEՈ? Q 1giq>4 A (M/ T fd?fRV"gP)Zv~iy].:^IrI\!ԙ:.?R%৅5Qͦhźt^5 ,F4vcU]sn⍜)>(nfS{_)zCA%V&SlGl/"8<|[ T]t#P.ܳ<i$'0Eԋѽ=FyRu@e$!r\QWCCbx4j}|h/>_<>ÓUXƙUV& xӊ+t"pkQ79 Y3*XBqX)C9 b+H$:x ̯q-PTV'N>q"e\U)2+^xRY&tj qY:g }n_X؎ߚ+1)̈́Q,x.}x^[Oq X~~qy#Jऺ___u;Y #x}2mJ¬t38~Ii$Y5Y6C%'Asv*@H>ѯ 2|Vh&ab-|{(E)4;KS }iO3qz_ƑpTqv؂v2k+2pu]ހ@G1y,"Ԅ d s ߷EUZ 5}[7ozRA5ۭ.OM=(Famu8]H|_2g+Gad6=;&pAd)Ol?귺?/zʓbY4S" <􊽏Xa٢^Vd92Ph` m:ҁ3 aþj D9"gA3 \UȬ,d؉lju&$Nث MÙ,&hU3]cݖ*V-C%ֳn޻3Jt5*1v(oI$a 'e|ӡ6.Jj8p-$Q9Ab;x u&;c;\Y-pXÙ2ѢTL)/b0S:W: 1ߨ)ݗlOIr]ײK2"mYkLNZ0^@v[x HA~$f"Hp*d(>N.a+W[If nFb=tS/v+OLp%Js!_׷G`a@e?,{\) 3Ց1i]Č_dm5ogk>ahW{lªlKkEYR4C󤍎NE3| v"OL~Tu1:Ai{I'h=T4ju+Zܩ>VZW>tl0zx)UB'_Ǘt)u͜[xLyѪ5(G7>h*p"ugZh=q/zsQQx8˔j*[:*ϼ[xQwH{"t@.?Ra/>.º^er,VܿZX1D kB,R=KK߬{8.zb}x؄rjw&As7;;=r.ђ1 Ledr2 .u-7k9BF1S`.1DԿ]굚VG@1*_l6S5qrig @{g d~F%n$!"(鼩4}WRFSmyn Rw;.NCh֬k'aR:c+MAYa%xc1d0({ PuWj4^MX6#TbkucR{@z3z 'gۿX؄#:.{mi <و`\QV^%rA|ǓFm ~5;qJq?2Ԁ/NWR}IWB;^CO`Vo}~r."ɲm&I:B[YTYķsowU@;̉oOeK(sr%7T`LI N4uM;~t5T0Fby <'SOJ* 1{r]k0-i(XXeG=~&xzqC}P䃫$ JzoGgN2֐Y k t/LJе.E+0ρ]j>lV9Z~=4qXўQO9'^wڃ+/R1-;|,aM%!pЭMX#&:!nvZK@t4D=v' 34uHM[v W[@o2;EK ITg196q3|vW%م]AcHt<+Jn9%4R] >~=Gml1m1yţ>9st&9pFBӡ5mU5ws{xbӠpKNhyb{N4no 2H?yos2my Uu*UASE|#Mu᝭ ⋫9"87:hW`Uunf%V[fW~h 8- GxX|oJ"wiLI0ְpT~4ɼGpتWx[t $Cq^^aZLW?d֛IM& #؃ז2|Ǚ_P. Y^,D,u&D~1=vmTk7n r>:=_R}R<` >Y}6ilo*#6n߭A9Hp9䠬!zfSHZkmYM$.ۇsDb.G?`94rg6 I.z2?GH㘟~_W6 8vӃPzvs\Dz> MӜL ja s ^a[*Kq&|<&HݮŷG.V:΀!& C.vPj4+i E%Mlߛ (ITo?:<{No)C(~~n ҫ?XZk &Քw $Iu_8)ԵG\&~E.VmƟ=! c:@-H|!J42PzPu qE\#;Jo/ ?K!(x $Ǣ@HH˗JDa޶ >9X_ }2a6J[B;γI,BO +]HD_ųV5LXm޳v>[Kb~pΞJ;i}n[^x^lmPU-N1։p;-!y:.c"qšr6&yn^oPQ4*\]LVO.F>jQ~vT9jn%3*~9^ԐX&/y5#7n:K@Wߞ%"V!n? e`dL]M[痓GDYv]$`61Sgִv/7-6>R9W\\Zk I1.V#]V.]=B Ahmŏ;##?+Aߵ (%tӖx kǒ̼P'-f=È 9QR0ך+nf'-EQb:.zSD A\#7i>l^15C{ꬍô P ]fUKb]>?}(p,SujB( y&kP櫝״ qZ2J ?Uon?-ħr(921}Y_,&FͥEheBw hɼ^Ɯl3M'2RĄ22ϼh^mudl[sZ&F(M ͰQP LJ /+/DIIk{R$8@InWV#oK "F8DDJ 4YmYHInLB(Gs޵@I{}DxlD@81 FinNkݭKDWjecnFu`V81)@v)mgA>, .rq8ذ5ȷ+kmVhw,Q[`:?ŵ)[qm̺'"+%^\ 7#pW3iLiU riHo>>UEFGD׹Q%K F4qV58ĵ!莝(*ҳ 2a:w|0֝ -0T|/}?W2@^wk4RIs$ q/<p=0䩐\7YQWK"O|#ܩ웍qV:QZiB18Glt)fw[.*+P҅GǢekqP!| #҄hw'DVnNzP1W }RKsmqyҷf'Ĵ^js,wqSwKIcJ|t8L6T@^O?.̆R~H+X +#q+`bnAމ ;^ˌOsukc m`* a,Zl QGh2!ḚK*_0bO./Y\B *RW9piQK֤~5O^vA?I&x@JĎO$CJpT*[OM0W+Hs77ג+my[L2XQYFo9iyVh>#}٧ۿHYs98fj5f:OxCsɊK a%Pw0lXk5ؘaP>a[0 y7U`p$fXx\o<פzfR2?FE5)!(fVHO9 3RI8nu +"E$uN:!8HeFZCVa]\̵A+{h.k"gfiKtQz@a :Tc$g?F0eZ=7 Oq"A7u)gw@d@f/ޘ@Ƴܝ*G0n+&*NclN`ѹʥ$B% aUٟ`ib)ʧVHPڛD~h;x?O!$S<FÈ RPs0Ei#uy<#yU_HB1V5 ŵ{dKh  t cK0$ȸIG/SL@VB EKhDM+prR^kxeh:wi\B@".ֿ ᎘%queQ@@tp CӅĽ-<PoؾH9 |e&,# [-`_^ڒG5_otYdp`Q&S < 坘xS&)>5$`f@"K%ظ9,Mdmc%;=:#uuk @>1A H)IRtlo\9y,B:irl~f|阐&A.bV{"@LelZ0Xڋ"}?8YxL:ypdpG ,pܲw5jۘKx`t RySs,_'6NRmndxS9Wc7g0f`Să' 9U|i3̩|cXk2GqJ!]uSP>[:;C`K,,<62g !LFI4vB_Lb:B]ΙNպA^sbCǢ')8 T,Dr$#7f3 g}z8C[vh!&&kx :)̊Hj"ъP{roooiBIUߑWQ,*=:􇌑#DP%rB݅%Jo44JM,^'Ϭ ?:yڣI4&]Z\>kuˬǷd'y+K=C*gމW<@-˄eǙ-ދ}-6bpr}Z3c|nA5j}\O/[>jdawNnqPHW0ʱ; Ruxrl>*ba!\El+ G^̾%_61F|5Moj7b75:b᪴oqz&:܊тGv 4P!VRtK_"S[tƘpϫ^][ ,ֻAfzdFpƻoLj$ƑKU']‹fsPϴWLTtgߩڷNrLhV;(w ,|EjIVOzJZ\m&UǴ&BT. W9\AUeAՋ  )?zW"cppO44@}c|3uֺ{JSev&BaH-ֿ8yv%'p\y);hWJrÁ WWQfW/śRSt?}4  #ύGl]n sW`@9sW3DI4[]} .'흛e״oY;bGCJjɗhk\59q|*cE޲[#H[3[%ZUh޸R7"7"duoTby*[ʞ M%f$n̆M`h|}2A~Ւ]Ѿtd?o|5<}87 x!d\VqM+*sKk.}:v=Jh* One-Y@'w^Ӹ P)/_k.=Y#4;aP?Ge021PEP߬9 [?lIuJzW|KJzm=I "/(GĠ}Ix4[tz^х|-Ho}ɦW \= 4,`m9+q 3J I1⯩O7(O/<YX#QEHEs.^Eखx9+ .~*I)1`0%{o.LNk88]v~GY o֖*:#TqY>\n;0c@9ÞWZ,F~0d]ZewJ"2D!f}US+9xl[:j@N3n!yCWΰplYcD ?HD"qa~.=Fy-每ٝ ]\ygTU6gM }杣βAiPyO"^9P),O4[rkMbkK}"9N;%,.+]vdD&nunLp] i x*1֟ecT)IY5xhmHG눮{>3Onv(n)l%'T*j#NlX7\zߌ_Jόcl !QN&1uxG#s6[Lަ@V faYvԘ!tc[Y Q`Nk?Pگn֤iի:(F2&>[o6?GnNףP(t-u 6# 9LX,O nۍ`pInZPq} (to`rrY?SxN?f~7\c$|r|+OoCƟ5lZ,jԉvǗT1i+,nN!8/|N-"!۷3.Dh!2} Ϡυn2pĐ$lghDٵ~!%ЇG1e':h$v }Td74?O$șͬR31+;ؐCi{B}Q_3HRRE[j;2Q[[ fMB x,DFOx@D^bU\r&*\3Ws?m5yӃ06'a-soVo?Yմq0 eo}2iLIv4vOWѨ T\<-jl+F̬X/FUS`6^fg_Kd<>k>}% 0Z`(T*IVAΡYUQy}K5nXDOA!1m6pd׏znJTۄCqF7^\bpw,oT}Z,d;Ws w IQf 4SkU6i1Tg9%4<Ӳ?YD55dԥd5Hu2[ڛP{ü o{:-v o3nh29~U^I4~c,oD?4  'l!*ޫ:!fÀ*mL k¢ fܶ+_FZ9jWq >:BDp >py$V5,_NQimџ&66%8Qd c=jIɞ:iT I:j)[)ȊZHs@H&iRKuht\h?2|-տ^n{t.o@8 i*/'Rv*E@y#598T[mKdXym9m iuD8E 3xKGFR8S"M&D4M#C5qC)>;_cўNzs`hg0jUYRBuɁQ*ϣ}6iUyР^6];Jޚ$0{F[KȭGH/6 %_`$)}zsxth{<6DE,l otV%`8lƞMT^\|d[:-43DIWpW; c/ZUa\RS΂̡Htֱ)Ǹ]E0.ԥ짱m>1c,F wu Zӿv {L$z=,9B)cpR;t~cd" Pd̃ΠƥϔZ{]@yӅlȾy,4}ّ! eM^ʅG`CkqVW3l`Fn7gt^q|J\}̘dPTQ-ؐW8oU8^lN1(?y13Eva{Gå'ĉ[Tpܕњ9`yBX[8٬oe@w."xvs`k[WjķwE}H|CYHy9A-oՈgK#@%:uF km>lXS:tn!vgvI*1Xɖ Ո^//_=Sa~̫گL=8!ջ }dJe`L=[Ҥx1w0](-J}^ns6*}?UvYV#< KӯYp$6XO4c7~8w w>$ypSؖ6V4ϖ=}=Np| ?{b=g?++!5.yM'(MK0QE]U2TK~$(?8m~zA*mo ys}ݔQ`V R`jJEUopizC_LQ.]mn[붛rDvZPFtuQ>}?[[9VbnϬm7a"9yo$,ω>/Cr>)5}»$s71ud'FNඇu>:NTBM0zD@6mU'󱀝9;~TX۽iPwBPlYT}yMDjF#dRDrCՋf vAR!dL7fW8{G6{j Ą8?yȐCYWU\gswŋZ"ğ} qw7!3W$̓NjԧuUMC`HR+){GF|>ڳu8X2Ҵ2:VW _՞c ?=toRbi<BNB':(^~t>Ӻ0ړyMut,1,>ԃ< p*^o?Ҋ~@kpO HEFSu:epg/Xqz G.V։/jaKnܢ0WnI[4 j|f>Tibet{MƢ0I]kɫ*V m P('2[hU©3MR\w$>JI.ؕI8ZC4Wxd;љRչ!gf%s#HQ 6V8mX [\gtP#Zh80=錦c6cpTk U $HB2Lx%+e_,O7TP1$YW8P> 5zxWmpX(/a=Ge}VZkhڕ6wkE ;GBoϰ Vv\B,~NVScGHpj\ a [(ZF7 ӳBIHP0Fo2̔8wȨh cjB09nGEvle/x SzfNtr82ͽ` =fۅGF ?i)7{} o6#i`aoBo~h6)W n( 4s+D\<ZێVsxR6 @c|+=]->.k!6]RٲGuňq,i&=[@!zw~V BUY{$x,N%|D5 v@X.8{AJR.9!fdc^Li0udNԇc?6DQŽ 472K:a۟[wD;` |TsZ]ja*\?UȜ{_zNᗆ>&?P!n:OSo1T LUNy=J'w n.dg.9 K g\r+ mjJ xx |G6i9du7Halպ5bKxt7.#ksA"5$@k=?m\ ̅\+D7|Y_IYU7J}lך`zJm'j!€j)zI-m+0.lwcOs$]Qծ3T+X͊'#&*u{}9fez6~?Tr N/)ƷS|v/`TUq#Q2,JjtZ7tQEP+a4~;#oy +!E+ȱ*5tDTsׁ&|A*YTr1jBK[61m$ >e|ٴk;07)Ƀc{C*AZW{3Dn',易._6 bdcK{6=%%_XyLh?,:0SĈ B_lg APLκG?w?(Ȼ{$aEA<&!c>`u!U>Uy%q/I5y#!B}3…}L PpZ~R2\wU;W"0:oYxsMzY"΁I6nH^#$OY!9B0[JCG jnN_ * eP\08tȢ0h̾M˔kɈ ]M9TιYIi؝#baLO3tΕ eBlwTCDp^q7SW@;J;鮂`xf \(xm'#7֐O֓1;T4uoǿWVZq~,Š H9v̿7< Se^k,JϾryԴ`wʯ}s_iŌdl-`AuT]BxN݂Hr`/`@5ZAQr⍱/kkڝH¢CmwfҞvA[BsbHP75Ӭn,n,ho`sL.WPS=ԍڐ{ΟUD̳yǗaK7 #K14 kSWNRfܵحp`SZ3r*j6| v10-*7.MuV6| g>Yq?lJqKYV2S[.O-1O*kUL֟sj[&(>g4GͰWt+OV/#(:Y6n>I9[uu/D @o;.5grݸ| [4#Et947W$DYeГ  ׋~]% XJu{6qCm pGIH/k$ "Gv01JFX[&F7"+an[7C*^`^s>b\\_SYٌIq/d5@28{σzċ94DZ).G'֮_Yg]vF CKE93%D1pfyx>;4 W]*"xTCGXDOv%|aҪ<IJ a9a2xnC#k6H40mFF\Gey<܋nrl/g T5޿L>_ Q4dфQ7ӟ`[lg>mF]|!UXB);ɇ 0z0OuY3v[e^"&,, NeG#ymG*W$# ź"DOfܮ +S2/!E |X?E:aU{wl#FXNO-eca͔8WUV(a7$KA, 5qFVMQms &ET+iyA~;vDsj(:AyСe#V*A =-+ˋ%W̉Gr w׍ǀ9H@V&<r٫<4UeLX1 YS>`+<ӹf70PLbvm4 >N Yo:`*"QO$WqgZ=K<~xcaGB PGK87 [`)ǭY@VOk<*OoֺwaBF.;) cplJl<'*g^n.,M20g"һr v)@; li~N]MSLlχ@Gv0𠺌h ÝlRhiHLN4:ʉ(ʷQ g[;b84,vG^j!ʕ锧j5*וkBV0L>}]5I$8q[ZLse/FGCƋ$ə$L?ή8M^v@5"69#\- tUhTKjeI}V@ w3ᡋ2%N:2>N)cȳbc^E=7 KN@W~7m a<;cH΀_aǃN=2GOc=/5 ;ryU.74=Ka+1P?nt']Q'3h܏ˠ5ĒTj(z\X`5A*]X3tʾNy7KǙ՝5Ŋ:r!X܃>$2$"ϔ ORyr޲C~PGE?U>.@|8ܼiꎨB9a({N6Vj dFDAKfN*^1hqËXf͕s~a/Tu3rp23Vn3$DT*.fG?LʄR%oToIQX>`Y3 oT>h L4rWFB9`ٜZR3<.A}OLp0_@. ` %~D;"dئd y]#=G)q[c^èS/1 {]qzk&GH;n¨G){F 19.;'HďIM JO A,e,>,5aB50M".q ߀bEL tm1~r8XHr+Tyc#G sZZ's3!#JUG:hIհ)fGH0_#zAbaQ)XD$nK gS$9Maj{ϸZ M iOR=ғA5:)+hZI~ٯ0E=i&?}2 @~MOߛ8ervsHn֓?t+LTW1y}5H ga'{TTinf\U}԰jX F 篶s5W EDoVa#~iz@R`Ϫ6%a?͉.9rhpccrcB15c$Ý#;O8〷jŁo~cW>e6FҥR&;䜣 Psa<&氡( ?zdY-7!T;FKJOy iQҕr6[N35,p&mZPfDo7Pݔ-::(&-+ʈ"}!FˋKNǐ$Rj''.BcG0WżJ~ T~ӯs*[m]gtW2LOsѲC.$%#cJW :(ziOpgF>-#F \ǣL* Bh o."YGTǰԩXԍ]i+ݸEqF$,A7 <|_8M#7[cgpfxĘP69h(#cUI21gjJnꖊBpê/uO;G̾TqդBŘbk>B3{ D[̠[ Q3j6 M7GR)6[ ֥F@kG!FiD 2[^W˺5ey.d:p"x~G">rw)(B/!Y@]NuV$gR5˘ofY85Wc MyQp Cy:_ƼH.J^QH=n^B'ɠÖ׺ h-}k5Gšhd?|QQT{Lz=>}5^]tQ(}Z P4̶;O`8 stX`Car_zbc*^')±y}(p]퓻,iddH(svûCo|zREӑ;Tb1C<!& ;!815즠 [ܜ.YbqPߵPyf(fW!m91J4.FʹD69݈z?#Y]oݖٕ,cUi"r< Ūn-P-W`1ɺFںv[;@\H ̰rXp1Yߦ}"GVث]VNR  $SW V@5WhVE}sIQ`"DFXݸմ`Zڮ%eЉnsbnP <`Ab ^[g-9SO; V)2Anj$qP)Q2Cɓct获a[UUc+gtQc%&f`ïN~:jpXtF&J}~syU+mC=| aYuu6(B`/~3K̕eSl2B)&(*tG{ZȎ!8&9h̵$&h<ܹi#>Z.}m9J4R$IqbA{>ZËY.Wɹǯ-4,pZV/Zj?0  .z9qi 8vS%=kPɌ/OzjNV 3[lz Tm}o)s^ +iOi~mg<,656K|'X0=Rgtĉ#Vh%'ʆS"MIkX ;jԼcV&AXG)%j1d#ّ'R-]NNAξrR#ɳ)K" e,A:?d}%4G_%0NiammDT&?c#~;D蠖R/R='_Fz|fR 3ԯf(hG-/pgA`$ @,2%8 pZP,fHZ~5}GTCjabZ݈(wƣ#癲J }:iHb2֓L)dfo Mo9㜮 }}|IA+组`eqAl6[ ΫU;gsRp^~8]!8%ҹc7~T2TFG0$yu^bjnlh=)?T]rmϾmk N-A0&/$ݛ@K⡓y>LL3Ub65֞w!CDӭ;+E*!n~}[%0!E3KrvnAڧ>$h.yԾJ-x uۭg-_-f2 De^JWwHۘuPˋ.EfB~RhEW$KZb}RϔĠ8@I{b,L+|TV_c!۾?M:q͓s2EdN,ͧIHoy6GQvB|KNA\UYOFڀm> B#v iƭyq<ɧuױ̞^-1d>ڑJq=p'FO߾l e}]Uae~ cj?g)AEl-|qewV+M)DpUz肕sSǢ+`m!S "IYGnJZ&c9kfvj`mI Y~qlJٿҧwOH!yl- 4"%0".\.V{iT\us$)Et[H%*k-JeXAmG9L`_w: <#2{J Z7J4OeiKgGxZG\>~)C1j I]pi~=VcK.P)'ISQZ.Gv޲L_^'H^QCriJ(Y퉎-[Hv;>woF%eX}Y/ [aCBYB4HRvoq0WOtߵa#4"NHeyۯV1?-椶ԗqC܏tDgN=l*t١E#0e >qKB޶)+LjL#\l%ܜZM %\ٙIY?)&@Sm:^0D:S3M;(fˮD_Z…;Ul^rΞqG=/RRuw;CQG)OedK2R ޱ^:?x-s^p C3g/J8M)nK[@"QOXihq /TP]18߹09ʹ d!Cqr2Z*D*eڵQ>]`dK:ͤGQ]m]SX#./EU eTo"֩7>i*3K al/qif0uʐ)$%9)УWhwAIO4u'BO})Pt]-O[ 1$+yhÉI1'-͚Y)rB3PCMy6VZ>]$+ovO7Bư&b:bD31hrRā{}`ׇFkLCߤm⛌dW2& eDb4N 6u vsC(2ϴS⸙Q=+ E}[Pbhq9H' Ϊ:iJڸ^ު 3,U7ġ[_8X@P闰%5?`KQz[ȣ+pF9N YJ|hddGMBϲ n(_';Bxc5!-yF\V jz=^#Q?vc:Hh\; h2_J/hJ>_y=[ڌv KP^ې BQFP } mO SK?r/=n7GefI%`9zrTLo{5i$(!uJ}S%˧؋LRHmH9TuL( OUV#"K=l5_ ;2<<峳-ɼHwZGW{ci:EwD4jXгvN M[q+rv1ԋH~gf2S'+K 4zYSq^^lSx閦y A#VJ?F]V?K i B Id8-Ĩ"k*V\4gVM+ڙWq`C2qZ`y$@|]U)>jƫ$^1OY( {¾TRq*`F[A Ied0t]2?F8Dʳ]$0BȌ>gCVm&[e 2su\+!|k5vx`F4O灏PGK JXbS_N gD,BoIS.HvP߰c?!2.҅[7,=9 AO)x0pJ& 9 ~7\T|B<,Ii35 OU[ms$vؠr<ҡd^֦l, rקidH39_o8Ub"b3Rt{#Ⱥ[}/ ZxK<*~ꤪ\~`yNXc64T5\i#v-/8J: F#]\='.NnF7_o9e,@A{jݳi2!v X~&-J`+hi7w~CɌC0(*& ,L @'(j^ ψ1?Hv eFBb:\dMS(rҝ+Xxɯk[ӫ&?` xKM[Aȝl?0BɩARe H߷L'&_4A2w Qx(dӳdFSKxDߢjq\9uX#Řޕf&\JHx^ +KMjhv##ɀip< Ceve{3nA­ph;jqJt/n%<{,FۏA+PGqB CO/Lg)XD".tu]venq%eゞJfB| Y N) Ȅo.֘f])fi[Q2gk"1f*B X3w[jv.8!V4XHyZmXCPEa#~M^Yu>ǝvOʜ~H~:GW((|"q&#_+Zt n[\?oV Ψ"hZ[;aW7 >71KC;ZZvPO¼ UװuX^{6NyEݾ/$ <2l]E7+aU.oV.Zh޻s?U&D%8kw'_;ӶcyqCuhGRꤍTqcocb) {v\ShI(3b['Ȧ1(5]sB8 `g7ܒ_oe-9V͇U  ,"|3Oq CHx ftG!7w˛y|ϒ^%C.Ʋ"ݼc\VN{rkČʂ"F-_ЏE~X:d" C:J@ Euͤo/ D_>Ⱥ~ó }8fyc55RZ9L4HMo7ى #|K%"!( ;cK\ g. *ID\TFB RB)`q9J$VXժ^+uz䚣=_Fv`2iKBvSI9,AP4(̈́&퀶. mLĨ 1$@ ςiu{?x9> 㶱Ux<2ms99tr2=V`(ס̟na |i_, ?wiY?gP?xR½y#Std:|`ƵڛAtA4 6 w?Rh ÜT\/rĝr'cAp#*PY]~]xƢ!#_E3؀D>i73,@ۃGXR&tB[5r!R Bo&DzL"^b&Lݝv@ ;v{Չ_b 6 Kp -/ /nw&jߦ)ጃzd$$D26 3D.E猁Z <$VP܆ũickQvzeA_'_Q@5 +kŵW M&@=F]{Xr$۫ -C3d> J_}qзGz84RdG*qDV"eg5DW'\ e蝅smөB4z Oy8{BF 2_w怉r0\NBqm^|9Xo:; 6o.sWyx`@*T'o1 9e.u=>lX6"G~DFULMB'IrID m6,eIT (q!$Y9jH)D>e]u Cն+߄r>CDN;U-&6+v]5d-RMv8I+vY x$yo8"P!Ws]%.n2VH9TE|Ea!J~,^5rCOKu{>?:7⦸DAGI@2F:V?GBbVk<ӵ/uYvD cRV@ir,wA :2?-#Q%?-5 52o:"_fLk󁄀zxnUj7dliƁD mL5<‰~󢔝6i€8e4Ps3L=36>g+V{ϱjtdNH!|OH'-Gr$4m=F1-}k4oxTXɺ)K~rks>@'#DˋߣM[=J#|G ,3JoE_w+#+fk$9R;t~[܀0B2sB^ pݷ8\(nB_%jй8OGW6BZ< ʌK>]Ч,d;KegqU!aw"1^8}ّlbpC!{ ']AeJj}3,a$|=}O3`S/̔] s0ʌ)C_͔h"J(L&3Ųbb( 0" G{Gj5ceye'ucW{^@*$Գ_lw-n_M͊AO8GD|)>$c\, ֣rRj&~30ҽem6U$ʛ(2;g|82vtKt g=iKmɦ:UMKT-cn~F[fOLAV{Η=Î,:[Ml*pV`aS\ShB zb7/6gw1hEދS/{yj.01)^D)%Od\V*'VSY}7H|ۢԺ4RhRY-TEịn.5&9^[%NӅ1<ȯnM<,k2{U MՁ =VKb:be<),K>J t6,Jwt(#Dq=mv>i&9q*܊T4<sH?!&"BZ}2\@A ۾ח4J= )cYvC~Nƥt4Nv4< lA"O`w<5Ri;.>XHcFҢifytRuT,q58v:^yrT(T5ր*3i9M+7Vĝ_?K1^u u0h}{p$[ 7>[ c=^(*:qY#H9y>N񳟒u~%X18f ,g"4/0b9>-D"tJx_yOEhgXg#㥶DssxĻr;$ZO7Jᆕ#53LVMxjqʩL@9K3@n H p&̯Lj01L2r9s> rT3)h-h[jt,khwA,Mj|])2b^gO͂1yQqzeɸ>{ Ϊt~PWLJ Di8~ͨ`~S%/LRm)}neǦ%RC&.\t"3*8ĥ񯎛tG[rEi2SnE{♭ksJ(B "/a4j\cOwaļZ*b7t&eG5(X0P>-r*Z҉${ ~Cz޴'Q4MکIRp"1)o#zK>f%W~2Е#=8dL3mqȔ[[bot@YJ{dK*:[PX R<(LE PbV{yNl}]rw8˸i|ϰ{L ZGU[;MX?Κ-;V+q&ao!_vd|ɻij]@_Tx<9=a"| UbUW8نe}| EVP ry +Xlz쎼|PBkn׊SR%ԩ xC`Pi`nw&|mY~Үe,Ť|z-,~L/l;(M% A@g;"'Z;&}Xtm{jpQ xzƹ㷈8IN7]=05Ј>zvO .hŠ57EJ0]t1bh{Gmz!`_ 7iQi^R3[ƅQXf.{fc,WlTܾf nR}a0x%97[Gϊѥ ߷ KoLRFb$ ISr#2%룠O. =jf4shL}#@%rSdxtMLlMБ9z@~SYsߞit3 !3r1Dd8cSm^؜g5)>Hc~Ps$zK3kN>8T^4}`;?>ph} 83nio .Lmɓ{xLVv#a|T 7U[9 =MTω>1O!/.ib1H儨+;KPQ^E ] vM(’F|SkN ;Gz$26!\2cnRc+m6̓Jg,/R^iǢ\O*_P:m8w)8Dh+Vwľ罌l':7FwJۊFi%ve7S?ei(Orgw2- ]`k+2//H> kRV&J^)Z"S(gEl hv؍ij*kYE,Bxl*rbqHzfa"}ƚv8~0~ђ؞湂O(I-B'9Ǟ~V478/1YƃxonHpځ:m2OFt;^gaaoZ% Xș[: e4\a!!DU$ue"iSGҮO I5l;g{mmQU^[f9__Pet͙fI6s0E0vjd(聚:i pݻj'`M>O`mxeR2F'昦;[5>kPԴ́9*ո:@an˖kϐj]wn1F<'uۓ[NXi[wX'6(5\ΫԜs:cJ'@m) \$sp̲4 >E|k ? y4H]/G?ux.-z]4]_#gW;򳏃lݡ%7€M9cNo x?J/QY}󖳳 x'nC`r"'VWU//6Rg Yq?rK}y_)zM^̢u0.v̾M4f^6}P4;Yf!4[#$ @8g(kQ]ʴ"rǢ8d[1xC`oˑA :RlL%-E)Ȏx5!_Dk2š ǽ}_E̮אkj,[KΥ~^]& sLNq`@h `}5Yq+aS-"jiL/ 0=svt|]CORG};Ssѭ6~Wż534p'Vokpi{$`ιW`~X JV,~BB@!خ[q0 coVos#co, 7>Vaf4{l}oyH`&M=\S 5Oe9;@tDO(qS(%ZqE%vo-=00rfa^VD%Pdq$}kNzX&Ij;0Goe^*['vRʗڥzRwOsAc-学KlHÃ* Xf>Gp}TY8k\-R$B9 6Ekzg֞6@+|/tÊ\#br#.F. ہ8 W`i1Psk?&~hzNBza bY0!6~}+0U'%qsg/ [/EoiY"2{@!c{ Ø*6B\ԷP3Q IP ^ }"eWCMջ h\ H~^mb%iv~'+3Pձ SZAFߑ9ʈ[_=~`ED ~,%CAJjJ!:<ckJlo$8g x'mtGmt5!εZ.`g;*8YYG6Ydڔ?%oIFfKZ)Yl92E׼!EXq:U3=VCҧIYIpzo>SIѧn48M1~wL]Ӿ{~=+ʼn1axW~kD7JivުVEy3=Vh|v^ryP:ܐxq_O34%L{'08c.Ý[Y_x TY"Q#s2,7Ÿт37V2ϓ&̑tHqagtJ䣙HT\=nyl8dF&.f*mdSpo`?XY7ue#@90kF` .z?8e5'jDAkUic< Þ ϔ.9?׵6< `Ϝ kjbI$P^]Gֽ3Ӵ'˹ϑQ,ľӖ@6˴n!KIRDTz?>Ő۝yGUCI:7%}6 lՖłlú 0f:m W,́a?"sxrXaxrmJlb Wh:.0w.׷W)b3g }p[/:i I)$ n\' jkk?=N+/sGǀڹVTB*jTM8~w6㾜 GB*<4tY ‘9&]+EV R#Zn3bj핟EN̔6'-ZG TZ c<É0!\ԣ*)׀\eoէd4Y.X.`]#qL+c7BK,|PPXzzwo@?OTǏҹ['Q4ל!Z}c'/Q.5i|ڼE^˖oj[G>~'Ly $ }oNcN|T@\ԐTxQm8,a]@L8xǕʻmH(s zœ5DrRΫ?PO4p4ŲHxt6[=0d7dD>XhQqs(\1l 1[dXBoCJ%Ѿ+ڤ_y>B0dTFUbg s~'h J?`gdH/]:<|esdgMiWdJT|Kk HmѴJdp'ļ<_ kΒ?ޓKW҉~)@I{ui%IE5N]SAC]qդs@!h^3n158ZCޗ{"SDrϔxlG m[#ͤH#F߭`8RcMPGo^pB(R0\5{~^i!^ʖƢl RU9$K'F^ݗ./ dT{Il+OtҋԠ XSΕ{U]E&rط#tB!⮒ \$1m >6!y \p7:Jɲӂ+*S~, ÞC-¬fYX)>Uzw)dLD+Y1073}29Ws *F(]ޫdnVA:ZmSIBR.!(ay3_P0A$s7O[(G|S7um:G*)6yؓxBbnn<ΑY\upRp%0>#>?8M]Jf4j y :tǿ1YxJ<<կX,0h (W_|#J/x^rd/w\J`iÑB`G= WahpdzFÑ?cV<^& z*vƳ'?O}u.Hrk-<) 1KG:|ha-'a㞓IcHV`Tn1~n#X3Er`a`A36̍wϵj 9=4׺,.L4N*I|dfſfpfiept U Xޡy{O||%\kH"PxdmXw)M3 j{R ڽl!OmLGST2|r Oi^ sc- YbƑ9Q& ?6z =;M[?X\s/y*r߰Һ܉5~SVYChƓբbw)~?KϹ~uѧgj]RfGen^cȊWOo`>y9K<6== ]-p:gGap\0}/`3q,{gAΣuOO>|E ZqkG ,7]0)C(B%QaVDvtVDԺ!Yc$z$nu:&\Ό)2f$p =[u1NKȱ<_8+˙7 FTGm@Ǐh (qLBi4^(脌Rvjl ]ƈȯ[QeeHSN۱RZT̆$vLM/ Q!Nm!j `S?HUMU8C#61* Lgd5)07l0%=lE80!֗;}~< 1mϪCl|{[5 /bʟ֔G Y=O!Q *ٹR%?p=X0_ԥω`ZsJuu*,kWV,KD' 0sf-5*kEATT#I؜[H)ؤµ5= Q S>MKp640 Gƍ\2]k&[ɸ؃iWB<sv& ڣ^/Zc$p9|u7 '/sr^ VᏙ4o*8{ِ,{ v#y\"t=]4kځOjW?)"wV#1 ГS {Zmbt.Gj%"tVl'l3]T.YY+*ZtOmj,w);-w ٶsZIVkpOՈ]]=kK/-59xla> լyF+ *@F`~;?y&!ԝYv5%K$*S;օ,cdD 0Hڮ:gcIHZ洃49nQ_2rCϫ&pNjG-*۰bRqaAyx$aYycUX< K<ك`*i6k#4(_ yg1nrUy]Sp m[!Gp/iK7"^|Iiꂤn@$t5VPML\vޠV}B:8{jHyA+Q}Ų~y*# m W8gzx7]% .}K>,H'G,>E9P%Ǝ!{3R]0B%vI*b⅍W?4-'UŻ?(r{AQ4_,^̑ya._\׼ֆ{G|S qDPߧToׂ]`H"ǿGtdAt.\1S"IYyVGJ-|$Ӎ-9aa,-b$;/nS2&ԂBv ޒn247/ h܉ W%$5MĆ&1>w[haT8ōE*_*?Rb/!YNlP@=$1jۣ׉?8 zٹP T5%s0NkȈ.8I Q',D84 4S!Ztp`۪[gZFsyXtH[yվa$UrM#+-*lSz|Iıw q.FN"6vcPuØ c^`$;Y<@Ao&-yqOB<d %yW/wktGWȠG=j+F{.?I=9G2؇znݜgv =k>Y2S%<-z'OKnfmSգs3() 07J'ķ@ܑA*l+q4{BP#iczqLPH{c6 Pp\恌KnXF"rOv"Rey6t&Q9-N#~jm#<^|7~ #au>$<D*̐Q"AdGR'V]GIǹE(`s@%lS:S{ԨT@t9 ͎ٓڄY2i^ݫgjHZHU)2E?ޞ%29@L|„?џAx`"boGMpk$X%n$vٛq&D! MWc0v3aj܀%#nɻ˶$w>DgCF\գnP*ECm5mQNג4^%'5*kuR8UKJvTJ i]1ad侳1PQ/ mP1_2\C| ]Qdd%ڂ}RCKku־ђ^¹ƬøLyJɶ﷥ğ$*%U1C|OM2d ,;]xΙ8;g(|Sr&w}ۦ##5K]\Smaʪ$ESI\0|U:B?UU~v j1'׺Y/Pk,`'iZeeޟ}e.Ca$Fo{vב#<1Em }^{<#DsɵKcq j1%V @GPto$ܦAW}8$|a{3޸EBE$5D` 8r\l`˴}MݤBgZk{f%u yt{׊de ӷ "NB3(c:DAFQԡzlYf,yqPδpʫ$xD2jj6tiq`eKa`:oL=Gt#(u1|SwP~y~r-c d-C$XQG11Y]k?U?0<ЬH)LW*#\xmՐ<*JvbԓN@EPr|:TEDK}y(:~`f^ߏAN҄VC'Д+-EJ~讯 E+Xb]hHKFlҹI: Vi*RM2[eM4 ' ~25ⅿCZL-CpRb8fl-{ʐy 3!>q㯴Ѫ=! kMy۰2#t.2]2#Z4Uؠ/ӝ@AԘ$GLrGf:ıY_~޴r\[;Ea,Ji9O5N®kBD!/UW3(N:K+>Rhx2lFYERԷ/`ä-`\Ѕ|S53G @*?i x&cp$䜭(?"F쪇QF$3˃B vMP9Nk7byvA*5v,H+I[۬2uKx3Og; YL,4KiZnaQsKDN!_HLiw= D1k6iV>pN003@"mFGS=avwߨj$Mm~YvnLfJ]0̲Q5pȶ5$[h髑;.Ҭ_ t,>s(4b3mκ|}r{ԑJX[]"QLxo; ? \lU~Oylci$򶠶'HGICkTfIȤ|b$'ˎM kw 3-#A͟&LKQVLFt)v엩$0NAWۣK?-a:_tUpu  Z,zT#Tթ0Y`I$zIP~Ao%?'!7qgiro]X$ UḂ8 NPT7&Ҿ 8#I1|w!g~*V*vݗ&W`A0:99I[pj3xjq]_qO2>rו+k>Z|ↈp8o9j>9G .q9_(g4x ͟^pWiCW+  13>G|91.|A3`i?:;/mߛk~ ksFLHyLemU5rMmPH}a sMEt6OlյKͣETKx z:aQh ٕ$ Аdp_u3b =)v"(C7h6Qڻ3zkP+pr)3jU;\`lV EێT+ctWЏQ]f/]W:VPAEHwk|K]~kJT£^̧6*F|] &r[Um|`:X/_;UhPN@kzGEfH7R3(>FJb=3.> S9Z*b8tN~# CD& ,?7 PA=]HfH_y.cVW̕yC7C(nٴTD |~nʭ)okUIm/ueC_XHт:r;gL-Vx|KADx ܱ3vAPlCW+؛ Eȉ}]gqp-!DGddVyBEmU5~KR[)R:u|Ц ;a/xۘ@O9r@º?щ`;R?IG+s-*?< -V*DCw/Hsػ2,X/3%TcL.S\mxNXlR8r7č>O\p֎@NMPfN cؠS%Ȓyȼxw٥Qx}(r0Y >yaQNfdfw(k^aƽ Ʌ6O.&7`(Z <%Q.ux}GڛR{l?q=dfMwLzwKK:tJ"I Hy2x|#hcrJM.^ [)Ь_(Ceh16OXFz<]?2MBYSϹ[=GD.aw7v0E_+$`2CmU:,pcoFiWۮ ź*(W 4tg47r74Ŋa +On|^ߖIDq;Ѷ !RpTƟ1ăb 6yXكYb?iL Jd{y2,*Ik.dÇadïQzq6񁒏%'K/ jB$<˨>o>39NۑMtd ybA]jo g$轇-cDŤ5=AH" Xn[fCgW6S1zg@KUuN-bpsl"rKDK"\3kH+yڝP_N6%*ECbxfk؞wLԲ|2'G 'NMDz]A6'Nd=ͧgK]P͑KۗQcTȂsK+e !7?3$)KԂ_ 0SbG42vA!6N/܇`/ Gm5Vlޠ\P& ?'HRfW5W`zb[i0 nY>q:C.12)zUcktYVfu>-)5iRד4\V9*ST#6gRFi UY:h$=u=ʵ'!WۧBa{?Z,bIo7NjJĩ/`.ݴ$ws;qiCiՆ;T&u8$ܮ*7necX0y >G]:H rCKrby lOGh4Dp㣕&@olzw8eFk.+CsNt ~*Syu._)jfn~"6 ^ Q]e  @Ap z`=\:{;8V =kXg'm@M7z,Hi1҇IlT R> ׃uZӿ\E[Jvk788B3.};}CwGEĬyi,c!?"8UUW<N;f=M ceuPbX^6* p 4s){9wá)hP8pq_kqW+2d:e<DC?(UW0[]K:5W^-Y۫SPس\nxP?f!0/>v k&- m<L`;yr\=mfdOkL(7 [lmt pVa-U,CQ_Ox/psga?uqXG϶UQLtJrԀk^鿥}ӡ RD U;'ev  ŻLD̄/]Oѣ.W#(sYzUd-+w_'sNjpn׃wn˻SG|г!+"{MT:(- Ϋ Q~2֐JVB|^( HAZa4ySZ=Lld3jy6խ7^8zC) .}2emXRUvQtn)Fw58ޒqK@JhͤW -u:h#p|9鐽*b_WMnzQS|k_ԢGA#w(jBVڝ' 0?>'Qom^aLu0k`zȜzdM!z:.^)18b/ 58w8׹\B?N7!)/+,VgǣI_ۺ2Fŋ晟qE x";ܮ>L:ϹKQ˜ AnNtD{Wa"Yh@m %aDL9Țqֺ ǠW12$"p P/=șS ,KfKqmNfc5WGÔpb6^)*˙(gc-ή%Au#Z4aɛ#xdN PYrR*)LVu[u2^4NBT|jru&>tzCBVK qƐc|t<g0sgwP A >1*+UKg3$WBgc6(8zbf㫥|Ԑ)6:Ya(/d2qxlOsq8KZD<:F7GVirX.-4"#Rb|((]Qc؀iN:Z9+nߑAV `4p$XE6 3:U51sZ:Wouk^J5VȮBiߴsJ+:pлy_m ȫŸp{3êo)>G9"o`0"?B-e4i~.ggЊR57Ԛ dD\fGN iAA<`6%2RW j6qoѴꚎKMFI!*dk2m'"u@[h"ѿBĔ-bD?*D9ר@WPA_٧Yrg[WA.ZRv)blfo2T Gi}I"gSDnvM,WP=Fuݬ]tUvVņ_/R=Q~Vb7)+:?Cq=˳>6nȱ̱Tؔԫw7~V;#jD;}Љ([or2kU#m,Ib+bL^$ 9YATt~Ce"­O|~C1х({!?QEńSF!xҴݐ 9g="_.p|ףF'_Ȉ?'#Y6dh .hȆJ@aރ 1Kn^$Yj3雾QSKW +뫼o9Fh8)t~k}b%|fI!ȞnK_:rD#ӏ|s0R,>vYwK0UnA s;>ZXna.I8ܲkNJ^ڒNg>Шr˚.RNcJIIM340`{:$AxKrq3e}+6y08 ]rT ìJSšܜrر/6J48,{Ϣ`5^m9dw@/ {ꩵ YN;M[8IHqR &HOgmJѩCqUl_, ؜.}DGOԔ<"/8X)|Ve܋vrm6 4a;ᗂ*Ubܗ#Mϰy FA)`̞n" Phse*E.{u4Y3~h bBG-"Rc,FoOY=c;l"@6SpbY87Lwx#I϶Q1}J>뷥`X ƍzRX^}l>v]ZcURoGsp O?OCi3u6{qv7՛VQU}yl^ F;"Yãe<[F~u1>c (g"B=#N~lU\ÑYabۍv.ņ+:cbJ7ÜQmqXxuH_ͳ1f+\H}q7<EI{Ru`3%$Y2e|1ܠe=:ia`FiZE<xc\F2:~Y打ɸv0;b3I%9sk|xuOhZC+rX{YC6Ppфe:᪅j_ 7wtc W EyRH^IaGby '.rl]˻#]{jeRKD)=v5Hpcg8Pho `Z~-'xu/d1><619'DRGIE>,ŽHrƔA=lD&m:Q~6ZO.:_[kkR{b\(vQ!vhzn^|iI| /_ fudJ_As5)PaAGHyIuJیZO#%H(mĿQ嫛Q* cݤStk:S2k\I@&^O*h9 :)aѶI`h=[=RI_pPDsD7 SL^a!0U[ PP~5tR>}'lbߩL@4HpI +WY^'}7̷k0.+]Jfv(&7ݚzщxd?4F ?%+ B,C$9dY\Mk@[3mSp_M@.V'ᙁ\gc^{:2kr$_!%/rǗ{y *$@m}ieZ**踮\]v(EvDX`JG,Z)^jnYhNgESPיU6 | I~LfV:E# Ĵ|x4 䃻ڴcFi N]|ܒ,hY2Dq>Ӗ|]1q՟ڗ5x(ِj+M d(>/CHU㱎8L& pWWz`ֺ&ЎW"dpù 爎Y=0 of37̾$x1 zarn:r|1jEM.&曆mQW (oVGeB撣>W\ĵ#`2rj0a=-j1 ddv9sUҨ:gkw[]sv>`d0z/1F򤆘͐L9:`$H1O;+ɚNb؜RXjEJ8#\ub;r|\vFA Sfԋ@(pkVkTBO~Kˌa}\F+*l$c^V [=k20}'Kd<ل"^Bk#ָ u:9>7J%: 1OdJMG h@=VuI,rìLs՞h`0ꭁ><:m(NPy;uPŢn2DOdfl zmԤd O+unp7|#*fs|[9g8npy|[ F.!ve҉#dBz^ғ4MSΌm`y6OU3Ys\EBOb=vrcJl].5һw$tٯXq/m2b֍aVq {t<" MqC|h^=TB(-W,:\-s BlSZ7~@Ϗ)t7e#(eq9݁]:&٭f-8 x$gO@Fc`e[G`7m"h] ;pW _WOܮ܎4xY>ZJt4T܍)P~I^9:V%eYU0HG|qlT@Lvטb-0ѣ%|CV"c̣.l SiKJ4꾳j$Dnq(]uN&w4v@Air҃Dbscn"!6hOFku&U@ѯ[IqV㇀TVRyLT.rYˇ^ӰNKGh 6 Uk%eͲۓ9-}`;E~:...אV1 *g@$ @Z?b8mE(6ePbhHBYO% *lN*0TDӘ~!46h.ҢS&`n,-#o[xB_x1M5tnד\֦4&]G嗱> ۳֡I p .^%9:dA_[ ղ /O$>@WS6u~`=H*iC\N *uэPKg8K͑iCז8J6grdg}+!tr *3~}Js,3^lX˷)Pvj\֊8{$1h$%Cf+Wx7M z65dz{@bvI^+Z6ԱVN0ḄX;ҶXP 8\R=B7UsJ0_̗@W!(  դElUxmګbȲs>ݤ'*YnZCEi֨˷Y-ou-r_%ik&ȋ6q f@wT/m4{\;eFr?tml0F-lMjN&_YDQB]mJ<}9)0Zk5fpF4KAYBS_jЄW!I?z []UM(7avxi`anGsVQ1 6dAt&@Y I22Bپ*6P2nJ h a=y U9^TK@תdD.hRTL k߅Frc`/l&9^t`hLzRWodM ?xV>5C&f}J'{(x֐'1:H~ai~S0#,v׺!AC:q}Yd;%g6\#r(\AzlX/ILڶo88F 8Yg1X RX.#εS<;[Y/h2d7Q3)ٷZ7eԠeŵ!hFDV2tJAnIC?_4/Ѓ \^SͿ=&d OdӐ.=ZANĨ%3Fp30eVxlt5Ģ+0OXa9_LBeGfp"mBU P/oy,/WKfz  Pڢ2/L\EsfV{QZ9ql2ٕd o6I5APsۼ!%_#[7޾E>T$m6\2yD3Z 1 G3>X طpV9MQ琨E +֦]+J&w|"[CVtB Q ѕ纪pUD\DKR ^8oe0S)zoB7і(I!,+j٫ox,|# UTHXpmc6.Eȉ] *? OMx ,hWNwOu$':4 BS}j4US[.'xC{FL/䏜3!1H_.EU }n˿ﹿ.a{ex?{ 2h-rǬȯ!,r]j~q~gX8+ +wYfWue,EqhpS*OeLU et6ÄfjDQ"g|hIɨni'@c<˼衳صV7ڽk[|4-JcGekm L!a+z#}砷Yn6sHZƐxHc[P)-z_*o=Y`P 9&:&%,gMޔ!wK:6&t3 ~kc"qè G2-#X"ʇ-t#MG>)l%٭{~ud ec]Av])p ]5p։$FP+zZqи+p+ƭSBĻ&Pf + JKNӛoXy"|.'l= 8&G-x.6מk$|92 MT! @?l6Wkp$k緤3?o>%'KWc|E{ZAmSnVn8jB" -y^sHv(B0AQ\ۈD& lH8(sֵ3>e5S!f ڰ6g$7 L+|^ K:ٙ;eDŽ`7:S _І/<Di\]:$-*؝G:XXW`Vd3M^?Өu3Yxa6: R[vx42f>yCڛ&c `"s$Dt甫ڶGz#dz'rJ͚6{Yڍofd #_ӑtJ[.!H\](ynZl):rak=jiauWn MURdA4h!`)Иt,ѷ zw2zra 4l6oSbC'Apx0^+7dwb͠b&s@k;V8sӍo| WRSH!  CNwCM:?0#0\F~d1GoTlt7~9SlKJ_"6$eK=GGk):JNWa:pqZ7&c^Pr''[_WX˕ih ;Jd)/ rM2x^)HD%2O-ZXi𻪟_l0\E ^+,A2[%Jl&0,g`}4ay"I^yb]YJX<=;[9_~N@ PD)N h}V$t5ps+;*y-ZJ*w?)aԪj22Y\Y)K:o$ ɤ1mteNmĦvL낍|wAœRY BZ9f|^pf|v:ΠST1uwfh(d{j#F+nË9HU=!:*귔+Co}f*[{JFzja.޽%LV3=^H(+NySj 0Sh=v&I{- )@irMht4 rn*SxwNSɁAqL9j* u5u?x=fZ݃$%{:/KAY)@hm̉I/6F{Whc3nDC0dHJJV֩h*Ɉت&3-ju*ܟuB:ׂٝWfŽ]@^c %Xge't3TK_wEEOqcVi3:38  X:2]<-XclaF%"oD*{eVe>p\0ύ;*ωPw{]'=Q5{`G󇡗,7/p8~b-̟uSpS ?B~+zčOʣ,NiI,id>YVߨzyUYI|+xUgq(/-cl1Z7oy{Y("ժD}3 TWˌM ثo';F6ri'Kݓ_Xg ]%- b\:J4یDHp6T. rI!yljreDhS_OJqVý4$KEsq ꛑCd7͘]:B3-| z/F0xC[eAJwDkcl:Iȅ9פ f/A,* Eq ]p_A-:kmH+7K-I~9:Zwjˁa܅ /xfG)@И2sF B~$r=RTp֚H|;7 ;? f dIF% fbl1rQ g Cրl=bF0MiZ\4QG,7j-KvCV$˟E_e-ͳq;ASk 1'ZE)"I^- e_5ug=/k/T=:oΫw< DEHk[#R 璎@xsw2SnH`@3a,?H NV- \h>ܵRO['7ځ^M{.xuwR8;u,UAOD?{iyVο,H^&f\F17ۢ{6f9 ܰƛ*L]RQ"5?ެSK`+kvf^ t].n϶f~{rCN[e.QI?ӄ`)IQ5Cm5yhbFHlpU!2Or猩+nu`ْA$U72iG:K< ͺ, -: $ F#Wz(<IM'8t@|6D{iC12WlROnV?Šjw .Tʋч1Um!`j-' 2ř}"Wnj*=P&6o4{zOt!:#7GV\9u(0fb Ps!\?XK؎;.Qm%)k3}@pA`F#Y8skdTMz|֚^;:a-s{҆ DQРLd/L u>_/xq&Hpfo߸.H;YGi>ت0TKaHHW!hIt>YBixnywW_;F3g(<%%^a]E4̮!:%.7ᘼDd|5Z 8PI^6V3vUO5Fb8Je~!]MIy 緪ѻ"tHmroPZRLew97ZeeS986<_w"Y$46?_H^7צ kkk0s cV6#ͱ0'=#)-hl{҂dEtP& ]έWN2 eS<Q[>B*j":T7hZ /ƙ"hxNA>mY=m{\$ѻpj:hUF-aDN(R59%8 $ ⒷS<޲xX<#ϏHC+SyR8b.y?v۠rE!Gqè@lDG`DЂV?R૊xvb6E숴lq;ͦH4ʁB!GMzFLJz4I%q=4ƣݲ}FѢcǃX \#,6]{;*{^X ~yi+{t Q9jQOs$5t*߲'ۡvY#UEGg];Α6B8CĔd-54r=ZסI4(ޣy5qYZ[Qd;$=*l?wnʯGlTgh1uuIF[)1⬯+jLe^"P JV!~qX{U^EODY亄dP&,_gь =>0 =HgQEb//akni}(JXP>A Q3KZ AB` FV^ۀ%%s#Ă]B Vg<'ё|;J3ضG4ƈ:Hz,rS78i(Yn]bCF"|s8'2gu-1i(틵,{H½eLj ̎DA~|(Hd}ܑ3="%AnV_Vǂ55^ mv\K`|a9 b{]" v $Ǫ؊@Ó MOaT?_V[\QisUtqUij&:C&|@jzZP p)|̫RE7G{z.sD@#T0j]>VKȠn^>s$i᪈V:NixT7k>W{22KK$Ln)&9*Oh,;m H`jLD=R^{QAo5k5 @Zӌxإ[[TƄln^}U"$m*(JHl~瑫A4[~5U(:~mg>qP,3SԼh;گܓݵw{%d!>CA{!={鮾ǯNV^K}!4(rynBY?YQ18 81ayq'khp5X|v:H=|@BB?5ME>_겸t+"\'ǧ]r6nc ^{8Q/@!! ;aQ뭟)Ge##{eJ7yV"Q Ih6׫;gG kܻ3/V[^lHb?0le<4o&X9*':+L MMjFPsd|1[7ij³TQM:3_vX !nlw>Gj'^0n~G)7} Т;J^U<O_du]~1-$`'$KSRF9z@ ;qnGك/>]U5YN iVlԪ`FgxO4MQwC"ei zɸFH87  YWB1v/n $/)A3Ȩ/In}<##cPJ=!+cn ||l\7u¯ibeJҷᠳZ6qZ֨T8(6O.Bs OD9JD?dt>cxh31D T!|QHyY4 [o_Ws"+4Л .A;c Ό<4c- ZYp[̶:<"US9Fv0\y䓍X@)Sf8Pc~ @L~k;'ܮg3٪lTˊ8pDSle[0!%k5pܫ^[w ;qA^X]|:"!3],3SzLe$@2+WwHVΙR WI37^@=&_ƈW륯d>BbJQաl.NVQ|#ǚ^C!RtoGAaʄj*mLO1Uhꇶ ?N&{'ˠIȂw]aFސqW/;aHl MF|GG?1% 1TD`TI6*LmĪ'LGOXu2Ӧ+:~}U"G + )>iF%jmǡs%~7* X= JM3%Uwja*>%w5깂ls{hVy~۔4k57opm8bTTec'~_c>m7v(W~$1ݹEX =u}`U &?z%揚U`2Vqzk}E`nX |A0xhZ6lKrJ2I쏶,ŌPOc n0C EOP ЌRsvmL]TADA+:+.돪7a,eΉy_CElCc9vxTEVHs'HWS O\?Ȗd%r&tM\3܆g5\b*DLLS}w;l 1^ܷG o{0gz&8h31#6H PR:HyީzNV"075]ۂ*=s$T^x CS}p<[gkXߥQ{Yb[QK<`hv|dwARaZWm.0q(sMn(_J9jYwYvؓ$7EWU~(CM5e@/a`"a=XEڮ7)1d=t翺 "0Á [Z$p`3$6z &AgS w$ z7Y1=aV|>W49p,@fDv(Ƣ|xy9*6m% c'wv/|ȩ =3>- ;BO@(l;#FQbCsRLBDv 0`783q˷ׂ㰔[)31= SM UtS " $@?_m2,/a, ,㔅=K򱡾+U+ṀQ>58Qz 3C߳y@}T^-9a Ov,[+Uq̤U#>ѤZ-q6½Zxʰn</L__b5c,oT  h8*aޑ  mF\ℊ,>=`Ex~ET0V 8ϋ~L:ɣ+''w}1Zvq(?`nb?#+]f]9L~Lᕩce9AvnT[v[ S6Ȏa""<1i1g,eʙr,a\A+1Q) -wM9㢼 %r*ĥrZ UǪNl7*ӱ5jxΨww4!`@>߃'m>f"NXyX)X7ۡ?5_"!.C@ ^P"6zŸ3\ZnAlEs?}RR-oHrZq6e?8_t&}^Z0/Ihת,ճfd;>93-*Qq1ys_qs kNH`8򌬄P15i]iM>'ؒOTYB,`I8UJqLj 0 Kd,:b >dE*29C%voS%'ٗfNByd*my>R@ccC 4HilkyB "ʺA3Ur@ ػzUv@.QQaD'%#-BO(7i1hra%ѩ<3`5Էڏ sF";jи? 9⟡"A^"-A; ,`y%\p]^4!ǧΛ"Tpو TxxLGr%UOFQ濚<%i4i]c}:5A:44XJa_fULK8f*NYsI#{p syU!Jص*u9 >W-#R\wxD"#p-Q{ßI|XVS&eBE`h)|[#ù)u 꾫ݨ&'ĒA 0h@kѝqGtwZtW偔gQai8Y@+*~| `zG`:d{I@K4k{q T~ m{:l\u?AwVB)ʃ-i;vLַÇ9C>x<:3]^O@op _DQlx/߫-0}8^ WvB:IY^T":h|\5Ed}de ksॾO)F9g]io0cнjj'%+zc{uP0>q޺V-5*O/.h!TCMADk?OyTaNEK Rd<~Mjn֛ՁA YUyC_b/umSb4Bʷĥe9pk要\'DE0ʪDZkIA.Ynf7I/[Iot E`*t0Ghay6rE:<%t[}K67Voyr+J'՞ G;-Rծsk' _ѷNW(2s KXraĦzQs"Oex,@h-l#xܳ]啌;}:$:ވ`6ŏ5`T92rq>\^mw;xTtAYånɑ~F#E38qO93caⳓ=>;MѺg>-g0+J?6cy9l FUzhN}OG1s30Q&:3cr`uӑ]ʂCQjΟ{ W mt^a̸+׵nWdoxz|Qq،Bu^'Ŀ1_ -RPi MJ(2$'L!Gzl Mw\_ujiuSxM$/4W"O2|h d1G޼\A V.N\lKG!@rSc .ϱe ¼ޫ.;.!\ðAADZĽQIOQ}`.hY"Q%yźkC͒I:uàE64Z/vw}A eQҘ|AhiWb޼ٍ-u's'xp?,lkd­W@SߨN#AWGn{ͮڧnSL C~ oܱzusvE\J轨&\y=uB}LK%қ 3V*a1K ڊn8}U8aT5H\b9X ~k83-/o0izp7e=a?Mk•!q8~t\XE些-SJKfU88װۅ$2x+*UˀJ0bSa [uY+ ~hD+</#A.zH/%(960}*_ a#m\F τ_R}bR]|..HQZ)6 kGvLy-ܧgx UF7Bh-GAF}F]7w~ f#l#(ZyPyTuU<7r4qf-ztO( ُDUa`e$]V8Nk /^OOTQ! 1XME@0T:@>M5jYD) 6nz!VJTۈQr1pdȤ iY4HRPDBi}E] r/~\ >CgAbS%;ǂû3#*ti78 eVZ q­4\e9 md / N It8 HЋ=5=Vn j6-Ɖ STsR*em[ ]{`E Dݗ]bdB֪uvlTɹcvݪHK-'k+r92Ѹ@PBJf?E~l0-~O$:? W-XQ=,bW5-0OĤJR~bQ: VG!]@/Yneu %n`287BBig΂Njv}璖 Zxê$ ɍ/;[LuwPPxu<\}~4q7FQeFj~l}`<Lö9JH4X~O^d|B~b\B{[.aq\ \EPj:S  x OՅҞHw=%&oa-JNwh/a;$_{-e/aK+ >;VP`Ak=t]EwWžlF$g{A*._:Enh̡{?zlr &6;8& %Ρ/Z٦K: n=)*>3˯P>KV]p/|OL`[ZriSݪ'e;Aj{y{-eh=A8d&NEvF),zQ)B[maA=vW*B\͓FdjSώ˄BmNB& Ń&bc'p6H~h6IG|75G3M^4(sGd7OX 0h\h^4(ߗ_egsQ1` 闇s"]ҳL‵d&|N֫\\՞bo%l_dRbջ&vYv 8|lO ƭr*LAߩƎY d{{=! ~d"'{a)59]ЕZ""=?\΁2>/'`[r\6IbBѰFi^. P,AhS#1*Um{}F(<Oftn[jr~\$?3ڈ(j1=/t}gź +o^ɓI4~FdT,*M`~@Kf#G\VHw7u~M([>4s8Or9%;ȫ%1 "8Cg5`OJѱh,-cZn54`/A? +7ө5D^-2`nq"Q46- [LBЌ25ne0IGP擩:rAAx45FXG|InYosg5i'%G]y1nZ>Afy 9JPv[:J~W2$*m?H2+QVދrM1;8CqGAЮ̙HxmMUwkXq X:]-ջAؠ*΍q|5!''#+y @Hx{_.~ߪSMS}7y ]T +NpKcKC't6kG/H(+pHCz>upߘ,<j4sX3c=CդbJ0#n,9 05ɫ 8k[f=]?? .6PS4C|8Z&0u幉?XOSSy3"z2- |lOSnj8LUuÂb2xD3s_rv.~|h]^@zU JrT26`:Y4Sa&XwG_*э^eV|2~ltD#Y=G @r6AL/ yhŸU,wMǬ]P)sK֊Wf!,y+Da Zm,.: Br\V#ba@sˁn9;!,gN@BHC2&ӫpKGN8cz!(>6[:7lՈ@:É<bc(ĹFvuqs72J_?> JG'N ]0x'[B׻ݮz ySM0|l?flkq=J-7uhSxSLVh]_42뱾JYavV k,8%Y14J6 !  KTE](qHaLa`ަz{'@jwT$? 'b|"t7^.6O X6\q=ͮCKU19WMrב@Goо`A֏-#Ҳ\xc:\meñy+H9{2YsцnfiDj~\lR'M8cʫ;}بN|)ʊNH*c1]O{QA vTߤ+LӴ̉8UqΆ^C_qhD뙛U K_B`MjE,3ڳ|Eb{Fhj{,*wG9XFH/2 i^ ѿR!5Wv0E"X<ڜ=)yGQF}F녷AFĐ_S敠v):/x_ b` XS6Gv7 [ tQ {3gifU1 7v?"./0_^К{kW!?!aaeX9RDo;!n@y4f @p@, tFֶjY:lt릦^KzeDAaj;ZZ?h=|#Ƴ:(&Oh+P~Q}6G~Ch /6U]{1)44/8o핮ՀnsC2i֡نJrg4R!T}X{#{$A2\! 5a=Dy 總aZ7?:J]/J5}x$Z**k#WmЍz7.MP@ 'fśܪneݐ\1M?"isxϡj'k냢 n 8s2M d9 >^FvL2 ~d:] 4"8E dt/Y;홧2+ kHCH&]pP'FB`uC(ޟ]b+oY]}bǨknOr\~yiY_wQ*#N}mF=Lig lZ]5ڤ9kc7k! -B^~>A$~usT;}NXZ~k7[5**VvISuș]%,%y`@[C`|\сٚ1jL9Rw\q9V%UZ]f"[(ʠ1U/&^(ޔ`-Xdn!߄FW\=`h,u=y9_s24.Ǐ"l/7RI;#k"SĵVĚݠXR}ӷxCѰ_"hhW?؈-XUA :Ե*@Bn&'([16odə0ʶl[7aܞ3;aI*j+w#j( nVDWlĜfkI?`]2TTd=^]1G{8-_r4g \я*uCZ*0]XQéc_TpTA|(B.jpgg`k4wʋKz_0u(=|x-I@Yz6+DLt_j.ǡb2jrJW]:3Cn:ϼy./ 9:z,_a^_݆q#}B>IRsU