sssd-ipa-1.16.5-10.el7_9.10>t  DH`pa.}N$ƨ(TQ;:)J#\?+h4p}:r(^T̵W_ ZP7-h17=Xt—z} sM g89]kp djK3u4R~j[B_nhu*[d[$y29"9cw$pSAcBsXE`Ho ա!Z ګ#sHݵ(, y1It$qk"[_tmymۑD+{-XAbN]Sd91f4cd46805731b74ca18168461d64c6b6c6190a.}N$ƨC69C| >؝<*g] n$45hfV8ta`}z9Q uS337zS./cH!7q-;QTE9պm#Ba@q{AkY[a-j_XmᡢP3,5q @$>(r,~V!ShΜ6whennSA_ .OH OYnsGbmP: MVAL.* N}l5~˷.^1 hUU ٦8z*56 I_TMV̏w-:~ EN4FIGし})OdqYGx|P'+r|_(y[ۏ~EMuKGvz [4|*G ?41%"Q CiOKR{vz4"JG2kŎ (b4!ӭ_V;b Z P1udjvۃ? t>=*?*d   ; "?EL    @  @`TTuTLPU(d8lD9|D:D=#G#H#I$X$Y$(\$P]$p^$b%d&Le&Qf&Tl&Vt&pu&v&w(x)y)4Y*Csssd-ipa1.16.510.el7_9.10The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.a.Ax86-01.bsys.centos.org fCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKt&/A큤Aa.Aa.Aa.A^p0a.Ana.Ana.Ana.Ar8c7a06796e8c7b2e716029b9d3af22991b54a428654b75669de4d4791e2abac57d4fa621204aed43ac8bd47b0f9cae5114165173d462616f0631d6814f221e4f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c5a645b31fabc758ad40385a5ce992de8972d2ab6c1873a032f97b7de8785bf3a05f7da421b62de276aa0f0cdd5e392311e0ce6fdc5d06cb3d47e9dbf6eb943181866fe0e3a144012dab71d4cff8f16ee133c6c92d93f2f55e66dc3224c8cb89rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.10.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.101.16.5-10.el7_9.103.0.4-14.6.0-14.0-14.10.16-15.el7_91.16.5-10.el7_9.101.16.5-10.el7_9.101.16.5-10.el7_9.105.2-1sssd1.10.0-8.beta24.11.3aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.101.16.5-10.el7_9.10libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=015d5450dd89bfcce6cf75622d25529216a9e59a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e6eb76c037a33a556d990783c1c8f8f5fb18a8ec, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER=/y5lG 4>E0=\dhM@| #A }Džt]1tN(t;q95yI]^È` TK%]2fk+kvFЃ#pNaY-(#Gf@(׎)MiB>M: Obg vo+ZsAr'_N`<,N|ʔvѴ3Y(Z#41bY %wOyc2Z .qKXw֕(L)8k-}s=v@= B j홊ꗵ%I] ͼX_D=D`5]?!R YweuR>!,݈pOs 땗!G,;A<8@ o4*~X)%ymǪ˓vtcdlۇaL цK< G.9DP)zG"oaә*;V g YVb෿T36.#S˿x橔W  g1w`|rLd{UeP7RaRt0s`>Emѓ:y FĨd]hf;@%iwsN|q0r@D(r%9*IڿіUrtxɨ̃2:':ep z `LF܂!5m)q5 m)VZgֹfeą.c'n.nevhk-fǩqm}K)T28Ak+#FԱ)hņ 쌒l l24jr^w饿1Ou?#EblzIfyUk+9 n9~br`+Exo%237@55Fe5Q2rSC[2bLe9aopP4F 0 ,;s9``h]8# a26nU6W=nQ.ClGw#C`BTAbǠLy3L/-s!znˆW1Wy,ga _%75 H7wKoCPirN+q@—-RNN)/TsM7;ZڟV!a.G3Yt #cfULs{ r[Cp bX)V WD\,U~b%Q޽~[HNy)2y ] /] AQL0H?7K a(wz2X 6,Uzf04tZ*)Ri߻R}ӗ]+hB" wmCo{oe4 ziI](|-ƍ6LjK6@٢+r;Xk:bt8'FtJA{oihrv4gi`ja"2y{PNF}x?l>_MڊK G˾z#,1FU_.zT;W0Ѩ7ݠUPW ߋ,&MH_:9,5EUeLB(;Xn{ZJJȡTtbÓ,p4ǖN,aYiXQ%H鰳-'^mQwRjv䱘Xt3ejl]Iҽ"~rS8_L:!q,!uF* x7IpES˧QsYwwIC"[ϛ,&[h#LzƷ/ُ<f%0o8b:*䬮jYZO W&VzJbh6ޯvD|G}6.BP5 m>vWl4 0C1Dom.IӭRَlED+ Fj!F牞ϵUY/:4!iJɲFa / -*٥$TOذ"Ag`xQz9t~6ۇ_49KiY;O [D %rE"胀 xm1- |(%<7O!q8q:'&. N :ORp 0l]*/[ʹZT4\þnQ(e'o5nUlXzN 40fzBS>5E)kHm ~*XMb%n(t$0- 2Ox p9tԽn {ц`X KqD2\O+[3\KPs;Hajj-!ߓvAM|˙ $2vHШRH,R&%Sİⵦ0 l: m 36'ieb3̇ޭVUfYO9wuZ|#{sWQ/9OḄdVCX<*_ӤqrrlHcTh6ydcgOZG_ݡeLx4C q>šo[HwNn(-k˳U?}Ӹiعl)+ڹdYܨ>SV{{F5UH2$ՓTZv؇cjЯ%kG-[;:%Sg,,~&NQ<͇gj{  ګIR,3npsQ~@OVL۔QRcOzxX/95IwjL"vO?}<,|IӋWۃ.0ٗlwczvm4W=~fFT?OO+6z4׮T2A ȡd/e!b!0Sv'EW4^4#CG9)!3nט Lt 9gFnMyLﵤ93!gEvi QSW֙r%Rc^޿c4)n$_O\W2,ymr_a/jpZs'Qp|2YEZ⒛Ͱ2aӃdșMQа$hnĥf2*UVۃmIeT7jCnEQ I?OS"`ؿDprYBL =X|4愊|T`_=jROUm2{E읶 T+`'E\8CpsDfe~! o2>蜁OqHQ 2>9 BGvRG0|a}w۞'-u(/*Ac_}VԖ]++; }8QCf7њxE^k(BkoF`Bq Hm%"M~"< 1BDxZ G]i6XfR%:Au-!1~1~g\D7Г yP36i/i)a4@VJw%q`L^zm:Oj uEh)Dxxy`y4B NvOs5/x[' S]b3T9.ER?gTW|R3zwQfqq|bҖN⒐KmsSH8AFJIqZyW%^g0IDS_sE<+ ,;X~%w2FEپ0oӔzx_ IpJ%~K~e1si*}o-7>#5# Ju3g#&z)?A{(qqBų@lF[p[֊c䦎"+zE'O |DДTJAaղUjҎ?xw2Z}<5v$tbhe G@O͡@Jw,LSA+HP v #65=۰Tj^)= 聰"z@^ +:1|Rap2D8]{JU9amܯ,u.ܑ*ْdqωV?lCWlЎ l E1-òHX!+h¬ك3F7{0`2`M!ygAYú4̖5e~Eu pd dwPG۟RXկ Z\8Ȝp-3aw!k6!f߰ L3m~_@)qg~+qȹF˷+Giy{xM9>1m*;y\65:{,aok~2YӚ)6n lp]/K{8b]z8g{A_S G3E Llm|LTDM$u+w+9EysnV?h`J+ox^zz(تzYĘa{0:CsqѸic,"EOq R X!O⣔jAF[KQ1gſú7kl*\\| XRٞY4JA>H`lJ[p~CeKBG),gpҫUhs+%D-}p%i+'JZ8/UuՎSI>R1*rUrz]%'λd9J6ክcd-l _ywz%LDD:w1KM!U9&}T-Qq u0lu**}LwWq{l"לwE p20KػSݩ !3eZ@  b 1c!xjZn&h1'DaK*Wl\! P#Ar: p0^Z p;nD0D?H8AkCr~ %मfB"ӽkg2Tp1L 90F; L2jMJs< zɌrI6#9e-,|<8J웽4 Nkg?7osVY<$+bYPQ(4Yj uF>y'snVnԊ_2#NF1;ǂW Do#ET$.1Pf`QgX|6ˆ<6`w :3CD& bcU"vF6$ NCR/XDȽDF? ps{%oڂuW? mTnaF}M.|_NSl$ 5r 6 ̎As~3e֒(TPmkҧzɼv1DxLbz~NL\d뼂!˟X7FQ(8^ & Ճ8DˑW}GGetp4+nDa4fkcqt~qq8^,-}Ճ1c^}p_JG 3^|:A,>{=_<B:>M L-5oIjFT39'IJ |. [ĺdg댟[wv iWA!ǥޯG)#HBb1`62ls"^ϩźWH FnҥqsP 53*0%P?2siiOQn*_ړf7nrB9r,]볛ݻ8#Ɗ?ϩ&<W~pƋZ7]_(I:HfZU6OB'a5bkM\(uC4 dža\U^oB8!i[7 nހdɼ'^<3N0D/Nti&PqЗ ҌKbY.,W,GHA+vxWCf>N[gۇm pʏV6aݔUI ?hl K-[7hdy*)]men.X~VyM)N=,yU<غfш&BA@V+%O'O'7{q{[uIVfvrf|зU7FylLCCubԔuORގG~bv)1a)V|;0th q\s0A#{eS+ntcS=UdqZI1Wc;2:9M3 醣P;~ =)O S6ýt0{#SbN lw-Җ'G-KI󯌫D|?Ђ 7jdZz9*DXC-XkusQTwas91fNxxvf0/a mo}a@ +j}b`$T̷HvJסVzL} %;Ǜll(* \c  z*}lڙmys'PP8Q x'~Q0LqG%ow57:Za/`-[0we=`r Lw$߱&tXnp9݌[WRE{Ze,: kY 9 \ H@`~~!E"k8)G]&S#8WXOͣVeL6QNԞSھbZ==2z` CF?HH05J;ih!p[k#;={8"oH3;WP.xY.oyaRumgI?ڽz ΫrfV 6򠤯D61UPRvކWt:4jݣn܎R"` ,УȤ1m%@ Ϯ0WΚ1M۹Ycc(<֫σlB^zk"N t]޶[l|:f0,`j+'te<%7± ̇ttdl(RB:=ݰ:J=] NHls| A3UKN$yA[+ S@%I+ ,l&{`ab҄faC"|.N}IFD?ZG4;_n!5 \|d7#P 0uG6pATug8y@>>0vw^>|;w 0QfP-W:[$M?vF,-U˜$yk*R)itcO[9o8HĢ79P0G@I`ތ 2XB%% h«x[;%'USΫgC)/ !L|@/q zBHt``% ;~R_Fjn7 RVG^L`~')h}H5빉1N֡L.>q6=d{0X'nƝ(j(M[ ,pl"apzsQpC`YEs#~9^Nug~899.+-7=[У1*z]=^jIuB]@[~`R Rه행dԨonMdlWI:j=&]r/?%1e$:RSMw^0ryK Iy_L` v9Ѭ|m` rvm250t"N],e[}KeP+t<@ *ڸ&?:]㨓J?A,҇cy1ba;8(nr 2 ۭy&  lpIKܞwʯ^B]- 1FS/1ow8Vi>QłOk{ϙv~\ܝ(Ejd6?pH Mx rܒպE/!A;L`+iXۦGu7Fq@ҡ Q*Ć( }~h^d4AF(*; _[xo<'dpv+ 놘h$+za:t 5*aJlz# GޥK[JQw4]h{V,xHdB:,3625'V.DH^E{ݔ`i˄"_7HG=ߺ<=l5t&. i-fL,f aF;`I TTUSc$5U +rmna/!n(`5K)}B] j" ^~Yu Ge;hH,(Dkr-IH*OzԚUv!ގ2Hto]Ex3=7]2fyB+#nP{^Y۔BRz6}iL mue~}Ƀ{'ѶШ10&Z$C Hof#Cy={yB|-JWYmi5YS$צv-fxSX{0 >̣Gym:y·^ҋ z ,/S`-{@Jv |ԸeNH%[6RPِZx6l2tGa{_3xsYU1|=f:N ÛRd!Jaf`:)L3u$=Y-5t{{>^4=} g1gt顸|Iv_br(b)m N6n^m0"aAICƷ'v{NUaS6 1깸# ԀOtyByT!a`l`3n~))1hoJ$'?JAħdt;V*?a}őF5W]`/YU[9cȱlyGJ2x19U#$y+iY2^ٳVD4! 9NS, yKmsڗGM/uMuOfrx=6q܏u dk{`S7P(Rąy4N9(Z6/&dj3]̪<1s|ĉx!Xbw, ʩ28bjsZ66`a5w7|Jt!J _G] 'Ή]"G ]%/쁄u/3d,}!:D7M\Z6>?a6޼6VCW2< W͉ۊEޯѼ=2V'ft+!&g]c:}߭,vdP*QW-:5 Q!=9&.9 ٨N(TszjkT𵯟:ZD"]:|"LWEPGc~_I$d5җj1[՚63hkg}ݖŎ~" _%S ,Gz&ZByg-𥱄@nq_Z=cS&ѺEeR|cKQ͌˸s8kJݒY]XMWSj0Ky'^sqfrB<t:ݭte=!A EɁ\K޹ q*Bl'Ogo@qsN'P¼5Jl"ꌓѝ|1hl9;߱e&"ӭ Y$)BN=-һT QG$$omc CK_Kޅ`_/\,LV4rA3b$v`|z&C|RLS 4V7ח2+[*bNkS7C=gZfd.Q!PVX^ O2ju%^7x'@_nUjPpVB^졦x1d(6(&˭ܑ;K^gs MU- uۇF%{fЫ8ڰLk2qc3x-gA->$Ku2h0d8ӧcB<;%zeUmSgDص|{/4U4Oh[gDžg*4(7KynQ3-IU:WrL3;M(=.Zwk聓lo$_No.TMUJUp+]?H;c#&R C8ϔ}qkB?ggHcTO)68rjxH̭na?hf%Np=dЊjMN9_M͡Ea;WC0yʝ#W(.J3";?bN h!< `IVpqKz3@aiS^YK~ &$b-RN[4kW?40ɂIde=FɑDa*6ܻ5QgHUIM:gԋ7>oRIi1׀/xY$&" trpUDz XM3D4Va =:MOez|g\-Ad6L͍#j2fF}JRMzKw= x%/!H⍶ |yG39ߞL<w?YMН{2A-!}?j`Uҁ NԼv;ngl7!0[6ƭQmWi5{KZMeGb:wV}nzͫSZ6-!W,sDs)A. 35D8#R(ceZћ;Xk1qwho?&Rq~W8,4v4a rrv L,."U,~iwW@.+ZY- 5~LC9?Dl'Kr_i㳸GwA:0,jo2C&Q^g, ¥*ubǰ:a NeBɜoʍ O #iDb[z*PYӕ]iteHP+seo6SMTiߠ[e]̶6lL#/h8.f(JtAot84VԒPrC΍tE:|c+Mj|F* k-y?sgN8yX(cF4s=џ/1 @ꃨH#%È'78hR4y) =dt eՈT͚"y *Q;Q)xW<ϬYN:cFWh%^7ݹ륊oY?GgLv^MO%u`6 dꅍ^݀FA;!{}w䴣\#/v_WF) ËB|EZ=!%($s',ML ݑ& ѥknwpqMc͵¯ꎛȎCn6S=!9{(/ 5ىBNk,G4BIAL2_A.Aګi\a>ޚXejl-^Fy+Z$}nl-jvⳛ2w.5k#%se9(>v0VwcTQŇfiM<=k[lްnYMP1'E7fS;x|% ʎ@^Q>ƫtXk .0=mWۃC,8$CIV)17?V+d[\5vGg]7aBOoiaH;PgVy-dQ.ɔmav p2~v 'Dm~yͮVsMpbfu#"2A EHumF%<#IZR:gko4=VuV5M<0o:WcKCiY "&(74׮KrjX#S;B41P"rfbݎP&bS+.sC m_"D;cof_[, FN3[Mhp!ai}DX8År_T5xXkW%M}GbF&Q7g'=C|\Ok'e)NҤr|s MW5pPɑbm z{fY%FxUܿ?KRCn*ㄹi}6gJ{9yE ʯH %3!8Je&Zd.Е0{/ sD}+'/O3ם!Fȿ܆ޏZuQ[!,;Q+B. J@~)d5+5J@9vW+hG$lXAZ(DDT:#{Yetl -("9tG`8uG_3WĐKI&Қ0o3N`&Ni ӯ#btkqifû(#ݱsRVH؃iWIa&ąT'J{9ywP_V+0zоVbxLJM{iFȾxiۓn@&u/˗P QZy]J(ZCu-`l[X >G\ .NJԌ{JoVF}I, c w P@kB(uK/Su hǑAQUZMۙ ȬI#4.}/nTu>I?ax?WCY8OHI,Lޅ{Rp,;G,=[v4yyZeHƥ`L [Nkέ .-{Hu |(]5)O2ߵuW7dJ`W"S& TlA8^^ti-?髹J7ޅZ>@ |Ƶ'ױI??O}׌*fT%o\\i.mPIg>'M)UIJ#w&<1DV .! E "MudO =_dru*㼊Dct}lc-GNTKF000NwQR+p7yWVVf98]lt#PLW/xQ2{Ok%E;3D;׉V7 ȗȿǥ}0kfh"_sv9VN![qt~KxIՅΆ -B}~3'ѵѦp!>~KPg&QF&N !Tia$/,@V|Lc-dGwfD7zNB'TyP-X[N8 c-J^lK ٬TWbY*)kA *Ud$N2 xjZJh_)iz338=2YWbt)!*#KiYU{gLxjk䛴FG M,'@G4]ͫ-ƞ=X J6L֞pbϪ*ޣ:BhƀXEeOۖ`.10FnM.k~|=z^d-vF/3;θ! A?k&4eyդb{sH0P܍jK v<;`*s]]Re^!FeTc{ܞء>sZ(1zjVL2B 8g,}|q_#>,mp"mMnN/ C\a3f]W'7ޞUʝ4^^r3Zݟ.YVlUD-aӋ sA'k^GN*p/`[.Ad>g hB%a7m=Yw 4>=俈ڰfViᣛCEc" 7gM #&fuΛ[CE3reٶfZ'!H7 irbqP*p.@^QY{Mu|iowT؊bc0m3|R-%TC>Tc~yad`KvrVWKTȻ'8l=>! :nR nF29QCF6<>֩;n0"O0ev&ed7zNВA]|+]} s7ȟn?`H׏}0̶W7ZXdk>id`^y{f% ߢХ9 ̦4)`RDx%rh~3ibM4,Lgpfn&FцC<@1߷mf-p#ղ~; C 2>"|-{3:F- L͉(fOpB=?oBӪE'miR(,Bq60 )$$ w|bXfLokm Ȟ#BDe2ReO$E[sNu SH1k,^%\t.ۚ(}jўJeL`T鷏usۊ )9Ez`bS/جE%{c}irF|.V$ IQ+F?D.z ԾVW}z=]resH My} WH̓œI($=:)8_~4u4uo%UnջPv#Ě`tl\K!lV ~샱mbꖳӆ^7|Vq ° r}o' eu>@mOB^W7irbВK:42 n7Gr[dT&O(?$Ztdn.v ԹůÝ%g(xPeŮ+ojEHX"DUhYZ(:׻~n.g_N{*A_Q }Y 4桐r1km:) _}>,Oux: E~c\0~@u%S8!*yX!B:M8PAw)[GT^b W{z3#͎˄,vs|GA|WilC#$NRn7 /zn:Ď>zbvj@CǩEo* u . /9V4n,iN||wa`IARuT-qT~;\t7]iS3̘$`6sb@$=W1YɎu΂23ūMyi Gps4JFUpo i}̇`c}p, 铆>ھ2Otͤ:/=M ΡLY g}N ڮ95x b5 k8lPpB?l7y):\픠.*TO^U O3Ndk"OW5=NWV<|m"-|)W:d(9f%)."PD$rz+[ $ ~v8#,-W1CYiH [ZMo'U .E9Y~oѧrlDeh_ _I BV:d@ydž+Nn_BqoKx: {D_PIS&1bgΐuW'ȰjjLvBL]]\?kԂAs˂q sڳ(o~%hwۆI2Y+cYw2T.~h `bVffd຋9 (fO$o"~+x!6͏G訩),NDc?ia~s\T[s4B wggl%Y*r ӴnmD]JVs}c-GZn:W߯eh~D鍸:'N 8r+RP :>È$~|Q.Nr'=(Ko/Iyz49I+Wy, Aa˲-k;f v- Ԓ07em(OͧAbdɰvv #t@13DtwV5smt!] ,/9PPޠ,nN/PJ=nDO}nN#bn^T n"NxՓ{uQk!5=*Fd74Jזr#H 7]\.ϯ$uU^'#X̮sd"t wGN;n•\-j%l_bh7ckE*;{jD&;iUמW\Tsx9C\]Јg% ^b :lkY8gzq<ŤODFI 5U~[Kq 7Rc(GenVKt#%Z)-9ZfV+f)vc4vB֮Fig m"Խc цmW=ڷo\40 Ck›r`~;'),&pHajnU(dxs#4dl8ȓzcvarc07Xg^{;I:VEvz3g5> +\姦ZG[3;"Mt|f殱0SyP$Po F0oI%bxȭcy!@#WV F|D  c}ʁGFR'PV9}2Uٞ-+CD3  !v}j6iD03JWOc`/@۲VMv[N pyĘz!5zX00.]kDnA`m7.)"z"aPǃ2phk>:pChb'̭l07L*8"h?#R@w2HγJb^UXGqlY񓃂diMy̧T6G7n\ ٨g$-M]8jn+\LhN|nʒ FsׅJ:qoZ˰(QŖ5'//.AuppMMvi{lɑ9jZo?HMR>~-2Fg?}TL+Ie{/w%քWddZ!ӿgH `gF lsj7/?XKk:g.h8g$XcR|a66~{3^AG<+/A&ӧgK@z5!MAEաKFS۱\֯)b,NnE ײ螻~9HV LjgbJ:i(Kɛxs =E5ߓLtfDY]>>+E~_ѥ}JEϩ+/!Ң |eL:]#v[13Og Y؋9GBL,j& Qp!`5^EpUs-Z0Lf a*r"Dsp=LDьQg'%&8X-F (Sp粓"FݬgJ tR"3w]aRM[6oKtlxtQ[Kt\]nߣӮHPV^ALm"쒳[z?rN`"3Lgtٮ00Lz|~Nd޺HsO( zNRSmѼ;5|MDM aqE%).F;K /;%>ZIf\@ňV@]a=v[yW*o|bXqd1qLΨO w50ld@|5>^ kmdC*}!<6 &H|w}p^8A5mqi>-3gޥ\ Ub2ȆƾHFp\U\4l F HO^e\l trN0\FGigGtud[qgF5w9}+<8 +Y{}B*j&Pf2VÞO#Xw&+,S:qK\^or-/GIVqT$&p~OOHfg ,P}KDX<!ukB h340ff_KSY/e ]cҶeNC: 4_ԝ S0og_7N6?(P:9F29g9,65ћ۟q0 1UYL s.ܧ#[׫PD3+SfirNktߐZԒm࿢:|ov#9PfkI9_Ο:];޻ԩ"[A> G2^sdZ529fank D))W‚Wk\#~`}..!B94FAAxv EZg=^u"I.dMPs9ƨ\ؽ,ÕB칃o)ɽKt{啮Ӵfy޳I9wa:I PjygysIn]=TmUD5J~6(EO1Kl]b՟2"W) .?oZ!Qԣ,,GkZ2j9t@Qy<' D^=Dڴxw&?X~Uϗ(2,&8[͜ s䛞0In φv%AU.A@r0*<[m'4Ʊ-?`#QWE rVv7O}(͝ 8tɅt6D<٭pX(M#>6KOʏJAlHsafZrmJK}䷛vӛe+Y9͵>&@rAQ?-e? %FPЛi0o,a|T~ցqT1jn4:RaVUt).THp4J3so<؏?a'ȥ)/tt+eEDrܘb`o啳ueHGFn(m.s.0~'(Yaٖ).0#S1R,JYh͗Eo_}\2kȋ4ꆭ\J_3F=-.,ZėI\$nnNzX诎@l9 (Š<_kQKġZ©qNNDt8PRy5 ̟hoEw~/!I+5O:R%X-BlȌ! 6č󹞤kEj [) -Et9#VJurmYHݵ o~.P2s_?yR<.;Ÿx_Q:(jķ,nHMۓ]4tlkm["דKanȸs9?c!wTnpƙ؞4 TY!cyg}؞ = l E'Igsd=1[y|oHr*\`pvqB9QyDeb0P)gYo|3s'‹xzaWB gw-5aB`0)xy(P SD+'iGnLIi}QRWVi$&HHlu{?E}r-ʊ ńEq1}(5zmP%^n A;Ξd]y, LZ;nja۶++M^4~4gO/ fi0SrC6_e8*TЭկ-$k瘝 cUjT'<|فWɉ\yNL14 ,w.tL/ɻ,5ۋ{m4J;ΆkX_;= |c{WΙi*3Y宅i]O#j^ΰ6(;Jx-q{黍w Q&V?kl*ŵTb5D X3g4BAMQH, OOkhecaS т*ITs_z(ג)S $$I%9=5La`CiZ>^T$ d1Z|ǧ Qa;b *ȥaĀhRj:8q7X(M/fθ9k>߮8=߃Xި5}M Ʌ/*y mE]@nl"p5 w~2 RX!ȊeQ4f/gU]W Ay_VImNߑ P4 I5%[rpl/#B0<2fZ dd`5 W馅5\+Z:Z㔶-q&~KV`[`Q-T_gmFYחg}F׷ F'Q5~ѳӐfuz_lRM7c2p8è%I6I*yYBVQZu,v_PS7I7]RNmo pvFA_86ϱ>r[0f"}tMW.)E|ht!BFiux|}6 )!b`.s5K^NwUj䘡yj]^BCJ?M^?gy5ׄo ^j˼6z1`@Iۢgi#|h>6с1 /1ӍgqY1CwդKP̭r]$? %jJTL_µdX i8#@BU\rZ0n͸v_85p%5 z0'ej1=_􇵢T-`Ow| T8k 0;vF.ܞc24 qPF,'lck&r.f 4;w$ CE~t ;X4"Ozm*d ͷ&S^I;vU[&||5>sW^ψǚL~[oY9i)s5UQrٵuLJo*EL5h8 b@1Zʙe@R径꟪Yq@cWV:? (^#J5~LKs?8p7+(ghS΍&+g1;hI) ym.p/{*5rØzэ9nQOR:֚~U=H D)tjBju߰Q )$;”M.NN rMX`S ނV{$hhpn3;@h0+{4dI,7r^8>gDzC_>*pl{dĦ4n^&ȃ$x)Xʍ =e. Yw5Nr#?5$ H}܇<#􀏎gVRaD~_n{ySCzoтlZ/7nah"aXq і(_HAB;wهNb?|^0xwn<ۊqiЕg7]ҩ%1C̵Hc^(?g}x @ȕN`:Tn[bM #TZ.>'GuF>>S?aNhcfz|;83>7-ړ,T 5v ^J,/NZ8ZЧpjzcM+Ԟ_ AXZ  ;xTr$aڧBnUZV?kNBYF3`{= P%́_"CJCEusQYJfI4n e;^0,q{bk) *+8ȻxE%!" =zC[ Jqi|:Yyv.A]wQE팏GE~µId$-^N⶷&gBp z?Pa yK'ΰ@BRl/90;˃&K;̗S52,-vd(F;=Ǵs]NݞfXa smB7c#^Ln{%>\rnGp.AUt(~)ס<<]l@ J.~Yy$YO^Mi[E~bA1@ 8, @V/NVF 6'/Şq!]DxEy(c~rZ[}^f7L˜1Zc?:_?w V s9Vp։TG<a93O:آ{ Iڑ+; !V`I+3Wdc%1Xt,`Ʉ,h>`'z/%]-[>Eb{v."-ڰ"(ړM`Z}c6xVi"T/ء+EMa 6i-]`ב:U4CXvU%,Lj~ub{~Ѡ !%Uje_';@s)K`pJ Z_XMRQ1…^ڮpS@nKEQ40Cy_y=ĆKWw8w"#H0 [{;+EhQ|/c!m~0̜`C1&O-w<ڨ*޵l'(/\{͛iF*}kCۋ+bn(P"X)-ZƄR]g!ڟ 6{=6į+.-y'+eWflJ6 /^'S:NFALCβQzr%ԍ\IOꪽ A^9!Jx˪FZ`zajC+ۻόT@ xc&J 5Mw8qrsu]iWHv**einFB>Py|Z~\Gi{ۊW)l38"b,_O*/V;LyRqgǠ)\<*/ yr5K)h'v uC½3OmyЅ;f/GJ/ 1_-[O.;NGɑ궻Bqy?B!,gnv! vEHHZsjIXYnF0w;ҐH>0(d\ΣplVs*վtQճʧp*vmEEb*m ]d@19 0IGjvgn(3y]_vw&7_RJh0@w졾!Vͦ+/ Z4n kxV8{G쿚g|*GO/.ѱvF!n%J|/bwjp^y&x)oKw]f/F1ng-* G p$lJ!;:;B!mnA\ Qi8SGgͯ6gaoz&oM 3]JҠG`<q:^S-('V'IܛP7s5 򓇄駒NPxP#jD3ldXEpR? TkzzLz ҇Ku^VVB=&~+8P_>YG~$c8qw<&XNANN-ۀ4l2WO/XǐI> +Èmպqv^ IOv^+؏ FTjS/\n[|6BtKݙ"%lV@bh"Pj ~6oO.X9H@3zE4MefW f ^ѼAbz?2Vc'jKxmfϔGm?7EkkVBPўadçRCa.AYymΤIewnB:ޜ?A$g}-:NFwus3I'B+f-nUB$r ,-sa+0&^L~2bZMJH㙊 {~PWmӎivifRͥOCNrU*ok:l?a'}px m,e_ZiA=+X_cKf+@,΋J,E/ҍ9G|O^;RFG6 _h'gQt4!ʳ\t1T`\Ndoyά`M Ly5_k4!11=ݨ'vr)rt[ʯ먬#{3tM4i'+{b O'_רiN.G({}t)&_pr5h9=1xIm ON'!D֞2T]qfp иiNс$$ͫzX-6A^!ʔxA6]=6s9{jW7mHXQ1߽!S KHEWgIω?mQ5T\2N]p+ &ՁFZ5i]*C 7旉Hw$8rÍ xփZ:옌 @y6!pUkz$INX'3H /O >O- |wT'y1I"3o-YΰP Vu[ϨG=a8Plx:%XWYԻv[9ʋ5XN #*=uV i=dTqJzޜ%F.TY8q{#ߏv7pWJnu#+W`FlOL: DUA./x4ORx6>bSo9h~^6'|\CkW.R һ~ @`-TK'(J5 GMf`8g|6R8YɇJ;0@}PI,simE8g]fV#xiC $ im?Z7.2l;<)lۨPBH區٩@ޔ'T b"3@;T z +ӎXFRRAlNDTaPږN XԦgg,76Vo'2%ж(S'FuoT6oV3Fq+rFԺq D<&cN| zH53:)P^<03ȆJ FG*F+軕) z5HcwQw4odBRCk0;[с9dgo>-4!2>\H\]tdڱ?; B!0ؚj(5%[H0&Ȁ' hB&ͦ'?Õ<K_LŎLu  n.ur"b9M&~$rk@)( 5y^m2ă[ =%β1-hI@bPz3w蹹6|א}{դz =>QlQV!ߌ%\ Q7hE<|`L۱C UʌaJ5)fۚ DxJer-y]f?)|70M!$^=w /s#GU0tI&g쫓)z>7LoP?#>fj;e{qOA-Q~O̦_D0_{N$<{rK lH|! G(bzFL OW[|S/3 xw$>Uټ4*nVHKjNҙGGuAL )$oiFԾpzA `D1%h-e rOmKا#ʬjRF~EzKe︱0(vjS;Ӛ쬣eV ~ ɾk@-?TzƋC@B/+.aQ&#H+Ŀ;Ej[pnnMBj8`qW\:C5puM[82ffSt87!wJs?=Rn9gS=g|:LMƭF858aPT!iM94JsSve=N"e9j/=,op4Ɗ D dfh֡iL.Em \~nSZ;$h:/..FֿbV 1*UooUAa^h(IN'daI2 4]\gښ%="40҆BBȉvV;&Pn ׫"^ =g}ɗWDpAos3`Ŝ'1D )~[Ɔ U2D e⫠5U2SV$ءm F: X_WNT1D|JLD ^hoh6\X]xtzEjD/KFWmQ2F i讂X+*J^}!'#il0wً/@ZWO A> z%k8gEwrO{To9m٣1:K8[ۺ9)Pj+,5\`.f'HplzvߪiN~Іf燌{՝tt'ŵ'FL&]Ps4(Ǹ*sYy[|LiB@IƬm!:)]"<+G3DS_FJk?j×g̢t"#P*{_l`=reqfsg} M}Īu/] =¯?cDE{~=<-vWa+A2laHwyj̣\g>n9wW_j s|Ɗ |q",ol㡉}n[2GJ&njSH QmeQ8βk($s^ Y ٗ*9sX(ջ&_sIQ#L?-H?[GY i23ʂMK:qL#op{2+wS=D }gr*2Wx\bY< O΋~-DHD'댛 JpS7̂3{;;d#ӉS | ޶wonTш7:8mvZ~f$a-i!/ R.a3b.oWGp̈́hAL8$=OMA2 srޗ|8+ݙ.Н«_J JTLҾ.ddFŗDc 5$]͆np;Q $Y{5pBva5p3eU 7Һ ڄӶCO4v4L7/b;94L.]QmL1q}5ъʲdhͥ*Z3qeqsХ0`hdGqȳU1>4.b^mtˡq(0ZE= -Z#Qf'ݭsuM%(hpXr-]*aD׻_B"`Gv#KNwM舵:axd3`" /|k <&Q)3FFtzXQ7@+@-8"{t81ClL!ؕ% h[U@n}+4~O@i`u49^s5_zU#lb mIߍ#Wg4w!ov2Lux!~ţYZ E͹BPXPx 2aEws>y-u.Jf0]zqMe>3 hĥmGQU2;ld3%]t)󼩊xߡM> +)q8;(0BGFWtgP8 [c4 `W(.Q4^#NBѧI'R oaNA1Nz*41[5B*\oLo4{6`..2tw?-˝'/J<-l4:H~ǒ_1`GJVx:$$&||3&^HP0hh Htmh uzSÍ W]cN:>@—zFFQоU j`pUxAAV3@}y)0jo`jC:Ġ@ݥBl؏@>-)R^{d6Œj|#QM9/%ߍr}7씒$*U*b_&Aqwif, &l*C)F!d!e;Q "j?ar3pݱ7{ľ8̗0g }L恡)۳Jܙok,A*GX1VR[k _dJ vF*]|K[g P2XAIa$3o‘SS&WO`E1۶ue"4ou`f84aU>{-F$hjmT! ):}$RFCe$P> 9ɤv";FF9^҅^χua#TQ$aPil!1 #)X$T*p͠uбr&~s]z|+YZ2Q]'jț5.q#bԡQOU7#A|z:DɟԊ;"eq/n6lbjQ"9;L'0$t!ysj>HXB,KYdWa?k6YN`mu}'j4ظbw{H2D&|7xhF3]8YQQY^ ;pVS-ڲMB@Uݝ6&>ꠌⳎ>=aj&azG m[#1U7ˆ]\&:'S$~H)W}Z.iJ.ЀH#Tt0k[ $#9Lr9Wu٭r|՝9s츥UmkOK6[6LsQIl1{Eo-y%A3C1 {sdfHS0IZJS̎WFج}Lэ&v+<_#Ah (QBg+S_=M)-y+eY=i74njl~֋(0}q^WrKN9^+'Co1.Er%HM/Z$kƳ{tK!iVYKXmSAOpJ"fM=-yO o$UU=_$@; Ʊu8':|?6DW2`Yi-g) a'vu>=?-@F}K,>1[j_yˣG8v$1'z,K몠+#;FhzRe"VM}U 0R]eUcW?)?Ui;n*P~9M @=']yUMRmx˦q\` 6=ۛSˎ8CW`PHi!>jpZi]QL,\* C#",ɀ(ϩNf흈y!f-`a6u\[k !ҫX!TkG"N;GY 7W˔.7PGykI4j>ڔCzNh9Yt;bRl|c.P1v[jr )|.Hmū}q1MS@"VU$ 1+2F>}c Lkmݬiwb0{K k@ j=[a @"-u&}0ՒԚVbp )2ɕz20^ွXoCl:Arf [+Dm2"#gT L,9y1_l"AG#۵~e~0&.d{uqlDp`JU>p޶hgMDGO#SwLA٨7:&V' y틜.Kui;,q4a ÜގG :ԝD+hoYR)T}D;k|O\_swՑs'zܙ?6.Z%v SA2+62WOXx|DS 3 &4P!ѳꯆ՛ Z}:Fqq+'h ;;sTn +63ӧ{j̔`r&q-BySQv\b}d7O.][36& LGhLk+kOi ,iׯ~;M\hpF񈭕Q2eF'aW3i*|3qOߜ 2Se\Ȩ&sT_&Vd>Z^]?p,#9X=wwΊeD36qD2ԃfd l|BNq375\$K6vݚ%75 e~k֏CHMMg]d)ߟn dٱ?t F) *5,#˗7Kv*+LGEC%_nП剠*Jb ^V›;sS2涡I> D<*TB0,'M +)$OtԾDx75p SR^pѨNa_E͉/ vig>&z}~2MD&*kTh6*̙C5dThŀO^g+<'5Djק)um{#!|I(/ ,{;¹V:{~P t \\_cf~jK$*$ET4?⮖_"N[n0'fn ]]i4kDz\y* 2BB6|l~NqN$뿆g$u+]s?S%s0:=?{v ~$M$= HXRe)W=m#.UK6կSwXor'HHI@ )U.g'Q}Öc|g~d)FO./^-洼n@NdE襧3 l纂v{C©C_((NС|EL-uK#t996|LnKݴl_d1BQRg"+#Y:l 'Q@'7LHx9 .x[-EK.<]P5M i ‰1;XGvհ+bnc'Qh?J?LOj0=LV!D#`hFya /jK𿴇tsxVuT?7x.-yOj~{BO (s,=]nv \: YR 2XDrES*mu*t ᖳ}o 9"_ݺ]uC~;-.ΤUB{LyGWL(dN" =Q0ÀmsLZL;.k3 ^ !o͉Nh u.5L'4nb =ntKQ6#LƝϙ$TJX2r'Ekl¸jb$~o֟M0Nv+2MwC 5^踍[YԷzh?[\T?(.-ճrtDB-O?S$ B4zKz{^a]x6^-Ka/;FrgGPs*,0%$K> j{}nHz!/MͥQL[雒&TKC"y֏?]znSJXȳΈ\ ڣzrϔ )>߱*TjEAm -YrʘNft Ső]J t0n8T%ȎpJf|/M^ F(Q(acn + $s;=_^isl*?E@7+wZi%պR7? 獱\ڙYW(,O0PDaDI+EװirpWIn.ߌ'#dddj-l0>TOdVCW_>)]1 )(ѻXxS D,IpZk##@yW52ųpwb؇QsJYգE4~]6Ŝ'CUw:,y-w0w^6J]c{1u57W$2y Uɥ vKeij\Fst>5x!^]'PzLi +f|l+fŊ~`䰡i/|m#CaX^0h,{ue +߃xQd8ڼg 9ҮJm ܵ2>(ϻB jqp$H9pW<`nL QV4VRtjabΙNye+٠ĩڈւ VnG4.ZIoi, '!{LUNRTb+WTX;Rȇ܁`k{Ex}i#B! ,K @ Vv>2nֱ+͚C9I *\=\`93vYmX^-í >)ꂨ{Dg׵RAE= . HWiYnj[!K.QS$TmG] l{N~B1 e3OV5's5RO` "bV1r^i7KӠ!;ʛl+(9ueh &'{`H&\k $qeQy]ɊF ,L*%8zݤ~N/@dhוZ7tr fř܈dy]"u]v"Ï_3fhXZ,z1qGM?RI34_A PFK121jPx6!}5+ߺZg 5?SjE5:=hp{Vac+1y9>=GH"8WXs#Y!_4)lyRk 3zUFJLk6ViLF`r#5 .L\~[{Y&:Vdl$dON.@T|qE)aȼ"4+:pW zϺ'1 Ի"^ksݓ_kޘ[rX~G\), ICtmC70<~#K(/' KM۪Rl$7eJă®%ۊJا@2}xq9hn\k~wx6"mc;aAMF"5@}DE4liT뱪5BtxpOEPeh]YQ"Nra 3(-d^H:gokF! ~”Q}@ <˳3_'EUAQtwΆҵ<__=eÀqQ/Dur 'ƤWP?ݷP}d⿾~rLg57>8Ձ/wG|XJ(~et7$XÂr.ء]W8>;V!ߌ>ߦMݺ +sfP/Ӕ)sR+I eOnjzzhCH 4 1{~B*R… ؟t^xwD.Ԋ/Քy]nx}𽼩yT+[Qv ow\G)<<\:4KQ2_eZ9-A8v5($LMEI#fO=Q2$޾)>EVI.#98/?y @n{ Jw!}2!E03@e6d{y h|➙-К}Rby:2j-\ozoG}2eanڠqFfVȈE|be!?(][4Nh).THD. j6⪚̆U@6-H; eItwiD5Un1$QgRq5hІ-6؟{+Gp_SI4M|^t$FNsHaN[턨m8mT<(prBw<(EKYVٟ[`{kywa) ,:k*SxnVʔk%"j wSN"覣>FxeVp\w؁ݣ>1d2rX::lEc1ώ)$s{ <ڃ8qWaNCVjPQpa0WjY Ťul͞/LXʖ{tkdY!"/}h.w30{~A{K[3x #FEPvy[C)DYǹͼס!)qAfv0[kъGm鏽%`m[7IԪ,j^"ȹt4 avDn|,?G \Ȉ= "RRwf[͋Iچ$Q ߓj/\eĞ3 8Z q{H\"QTtQ1RDt))Rbsdk3Xo ĨOV+s j (6+Uw]%Ԏ&L1ӯ_. h/#w쿌;V>^P"~B|*Tyw7kM&$aX#w#?z^b[ǿ[VNfTZ bB);GZ">61t}N*00}ruۺR޺bㄊ'pLT n2{5z.T6_Q;$EG,JZwSy),DJ,?šUIȿ5]'aRZ0aJ^rtXRWv#B%7Ho85fh]%pX.f[ۡKLsK=C*'($e p \c1zOVN&r;WDZZ(k@9Y/wi&Jsj.<~W,sTDW KΫ99^2M}&D_~hO^_tSo 'H[2 (P+\&˾aWS. mp6|.U._1z{JhhIّKWFLn\3]aRapAI$+=r:]>P̀H߉p/RU;CpU`?_ͤpΨovBiE(NHd7DU,gerL2i5<V`677Tpڣ:|{> QˤRGOWr=y]m*n,Zզr3{!:^fY}@f/}4`*hs f~e7v+9TuoJ*P{}g(^LHێ9a?;<28beSV ]CH,ŝ F2 H@J%5T$,e[[E4b1CMI ; ~~ P!Wn洴yer$}w7K)1-aȪnȷ2\7l1뮚k9ָOWg\Nt=orgIvD+U+1lHJkxUI`j>1CqŬi;K}BƆJG,kATQyWP,48.!ɷ=Tš'=Qr#\{$Q듔UÇ/\I3%q~bzg?mA&e3у&8O7$N<}@i$ !lfU-(o"i,d$m]ރd"! ]p,6<<7e3V_q\& BjGS)Ԗu CbC1%vbep0l{7+~!]нRsi@u"E"4锞~/HbN7S}U7pj ޾j*nj_-%tw)͏(=GK/󐰊Ng|’{ .k4@ɠqkG V3"AdD?y (0MX[QyP0'ga3%rlJ`C* }]|*됃8.ndsǫ8T,Py p(%ffs rB.&̖O༔P.ޅM=/0C,["G$ɞA >%Mx1u h<rV+0,.I).xǎɸ6k2׿xrcir]JK`} %-Iu?D2Jƣ hTkH, >"/6ɹ4#ֲl1'ACIyh.#;wYn.媭%SHGHXIU/g.-7D.]Mrw[DWx~dsBl 赾Tit"a Zy̾#+LA:ㄉ{^6_!_nW(YV@ R%\ D|D=GM0"zš`VU W^ԃKʋ*jki \Ut#~o*oCP袋Ϊ@ ѫKXxwEl`yScFǝ>2#8S/=PJD|#ґ8k+F~52Ǝ2X+Cˈ+xuhu[:|"S^Osͼ>6_1 .p-o2):ZpM, Uޱ (|E1Eۈ1 &IB8*Tߍ-K@uй4eQ0gaUvFI Vt+Z9#~IznG)h4.(9?}z]Z; 3r ʙ]/Ե}VUva 06O~&1Fjr_{8"ϑ4%I.@VU oƏL?m J``fϹm/3z^oNmiOo8 jఅ=P"\[( lSѭSO?aeS16~XSP!Wg"X)@1E,ubTV"n+E-R,oƾ]pӀ̿[b;CS/pC_!u!Mn1Z%D z9)6 Qu[j ;#`/]\=fLӄ2.-ĪJ}<X`ސ[ BWG3n 9zeJQEHï+ȍdHbvN wciE# i}YpPQ<42yx/Dc"Ntz@E'HPO~{pW׵1&X pz|EHha;.یI!E3l<ȹ -*Ǖphg@֦g8\[n9 Ck tS1 u1LRn6sP}0,*Y?G8/NylxŵNE.*d}[*.u8j=sjJ#8H*pE4]Ǚ rXj,3#8K6X/}B>"{*?kҕ7![C|͓#&| 3Z$&`J<Т;$/y"m4Q/ -m2;š\Sm{Us!alBxS6/ 4kZH&%]Ǹrna2UE:ִd4҅CU /D }Zea=ItpLL4șErxf!ǖzW$KP^;WK}#c` O35aD5oۣȀM=Y6 & d}Kҽ$Y$W,O`&3(V.|-9Bs SGjYzeT6TZ(keB 3HM LT5O>8k>ᩢL{'g׽_(j.oT̕8{6t0h_IJ(7aAFߌ%_ٮMl͕Nrq6Xl /bSmGd_.]DL5{xΤX&?lqnX e3&ߎjRoM ɉ 6vF,Ĥ)|^ׁ lA0F ^ގe#}Ŏ63fz^1є}&ppH`C% amO8f73t},le{楇Вh^03ǼTW8Ο doe93Fu9twqP#WO?#%Er*PCZD@"%9Mt% 2i)7z_d"^BVy?^ŇF **d4G ;7~0#V\`.D2J' s./ )6vz·B*a#Nj 0]4h+X&yyY40PD3U1ѩ Wq3]2).a#r@Exev:KTx/$)hmh0p]+W 3jP/Fͧ"%)׆b]f)0B/8S0)yw"P fI\; +GVV'qeZz s̳?QlDq:Y1e;s|C7:`$%BnƵ&szۗSǻ87PZZ.W>,]hzTq9} iE_ djg : w_ #HN!rPܫ0ص 8!-csp0 >,:igLkٓrk!O츄>N}2eC ?l{2XP5h"HAA7x |@UV<,+8$z_GgcHH&hn~?vvOEx´+H}t `7ЏوAtP?ʩx_>d|QYਖ T&e!h򞓃R?rt1 hQ0]s"=V(8־Q._st7;h oHѳ60,OSdP/]nW=]uX9̵4|e_%/7$[OSW6oV~0:-W7䱨 :\,_f=#וLzy+ԣ\zdDw7lq é|/ʣib[Pc!gp$3"q2:zg fR 3A&T nHiyЭPW*6nNJf9gTZ7=A0ӹP#N\.$4'Pˆ}f"[-i4LTS#WurE>nL/(TP#CE6$-&>iE`X'HJz{:붎b\G<'lSƕWqM.by^F~\ f y*2*mB܍mgLٖիFS,ٷ!"A41H6!Z|Iz8FjkG20H4nX4ٰI38B&˶ڥ0+!.3\SZ"JFː D0-wjcXp A !DT/=ZvR o1 mdݢ.9Ezu;Ƅİ, )FS8$vk Wv\+$OK}g ի\KtQ+PWuRN;>.bWm]ʓ1KB;\BTH,63nֆMj_0JO vU4)SyllL͒,5廜hVɘV׵ڗN EJCɖdRF@ p/Yⵄ5s}Vi8#|alOx P:AJlQ_K EC( KAFC-9B I6nOH&ErJ6ţdG뼰n0 ܉eiuŷG/:@tؒ)zQ4|9)Ќ JQ%1DhSp:ޤ)(â _rLtj+^])c< Qa:.n])4|)$[ΨSz!&g=} x8Fx9]z1ϡv}nʓ'݀+ “ <0]kToDwJq 0m&ύЍ佨}N?fϥfۂ\ #6.R}= Ɇ#2A`u{⤝e<|]C7Ftx E2?kG,f[>3o✲;{tB9vδ^~ f)"aD7N@]ĻػeiW]!]Žٽ|\+]9N _)gwDr<`J"fz2uI `DP )d㛆(;dr'|[ᒋ$3l~WZÒHqqb0͗ Bٗ |cz1~550]R|BCq'XK ހrS!XAM B;+łA 3}ɐPə1i߫SGb+,,ohA9T~ l}&G :94GHt`5ٌEJr !+O vo `p%L[GB eJ9X1":qsճ.@G"~z7I Ǎhep{4ʜgƽm9 r3~H2wX%xzĐFmP7yTslǥLJj]XA+woj潱lyZ lV[ O{rNhK+6A.~lki˫jBJ˻F^8- &?l2uIh]0Aܰ8l H#_(OE`Y>|j~aKCn|6މg M296V+yvTL܉r>,աi#ՙ*y\kC,KDǗhGXc*b9"4arF eъ %7ߵ+!j*>o3maۋ.vfG#$6=j8V+UOfCm@&#%U! @m/SOiwg.w~댣S߆NȨ; G.7`,n?$f\lY\ъ Kw=wtC7^Ju52l;f׺eJ_e.4Eiw;M1~~/bk53Z.3 ӰZ뼼 *u)rfnrl+Xc54XKk/_Dܖ=?{eޅwD?d.b5Iͱ\5L&d<6:%ed脬SBYtt" I!9NFjVSEcӱrDŬ\8ZǷ#-wqr]9/{j?]-*yienN>|*qMPtinS @Z%QJhz JQO{K\3 ct<~qvuiiʆedv~{b֒pDWAB q?X2zլ|yIϓƈ` ƲKښQ:N)6'W~5͍.OnG^gFpv(CfΠ+`׆ۏ#Tg%c%3~19bb#-9eyj_"sX]47\^uZCۚk/M/u&sH"JeTW[*u'4?ōpemvrNIgRɥާxc6[蚣ɦ6* (%1:Jb딯㇨O@ ^>ԷAa]%QiV}N׌Wܸc[e8uD7y(cV.;+wV~.O,(d0e>Z:Nшs0V~EYv$ E '{`R[}a[\T;ݫȯsÞ? <0zMO !vR4t2TNa9ӝva3/s@Y/]6z Te0s7V>퀰XiC]#((I*-^H+{/ NX0L9GSGF @΅o˷^Nr,~fxK>+J<Qy_>h7P(eszYӭ'BM!=^1B:df " .E\`<3'5RV32dxBCU!w@TfUNP8}OFģ Y0 .VG+R-?k髶b\45ܦ#9tQ-w;p) '! y9HʜuwEv!+d>bkQ]qSZ:ge'}]7X6?.kQ"c3lDzhvn!-UؠLP,uw WP[-Zk l6hVż:B~2s Vt#or"D+43%cXCbmIIŃȺ~P _3 JJ K+CJ9Ep ʑ6ѩl>$ю r."mRO ;쪉˻NT [qcι [f9rdɢyQڶF:3q7ҷT,0ё4hv (gg|: x}+h@ֶ`̀QЩsm:kjPC} bi&ɱj bLtn 3^{̂oG2 "FrF'$}r[I]wvZ`wp+-cV:(pxZB'\h`;E҆Bi`wޘ6o@X.Grln%LqB7QjơU@1dMYg@KGn\!8d|e>OsdڹZ4$&<1"$UkmCk]{ߔ CB=8d7sn$zk>+s;p\rI}"1GD+ uFq!J8Zc`qm!9%t;wPm@qeǟ?JAWV`lNEo~ x$1lI\pe߇F GېelZNδR<2*;Ąj#t3zZ2ȵM)pTZnʪR_lYǩ T=IW\k~l Liw54c!xqgk7ΚA=EsDQWu{r|} &u: Jm EWy/pmf>܅n5x' _]cK7bԯg6nwt]|(݇76zn׷PlGfyHX>S7Ic^m,ϧL xV@Vgjwv9s[,5"?GЎ/x|[h΋",K/Yݢ'VKuo~by3yH߄>R.uFIP%Sd|-OR{)E&Cӏa|;֯f#D@1[иLu߶wyZ[N0O|r66;?WjײK6C҅۱cud{c`b㘥{"(z ^/CiTwRe|j0[S˕wBM_P3ܺD#P^rG}ֺI}ff 4x^no:o~'@d CMAN0UǕWaRt^m/ 7(d>VH讞FPIL dQEk|b4r1.&D~qHIm@f^P6޹awVⷧjX#!v c1U=3-;\M,%@#H $rH17FQ8%9r qTqdFJG8[u#MJ$C>*p*ѥS/TCԲ8ިen ی4)?e~7 =W{M[]dAh۸$-[Dp/-3q8Jc-Nz+)!_7L" Լ4b:~J$؊uG~CڂdAؗ|mi,i*4εµ$:{{@xXͼ&m}4vZ+w#]򤦺DMųm"ۻ9q\y@KPk)U߱3J܉ r;w@BnKbwXKҌg>_ݖ΀ub_ ]̹Oɝ2q| 7f+BQhn_%9vũ:zl"6D@}oxvv5Qc<$\cy=?nBk4|ϒ%qC=Ŷr/}~`,K@W*`Rst,hk%p{6Z-I(A&}+qpPGVћ%[+ZyxL`90oSIq4DÈٳCLܨ:1e GZPW(Obk8 l(6I-2dxL"+{Jb`NWtx{7JCJEER7'b}11j=ỉOt^{g O]~Ljֿ/7zP"tThGFEʲD}uV# Mrh㍿e >;*GnDzn+$#9X[8_h7rg_H2BQ^kMg; mTx J)*VlIto'AKWO$-2.; KUThu)HJ*`w}Px`l*_= #BFDekX|;ge}.1TLneʹo=&J J], #|GUܬ@53)t Б4dnC] =.[NE;hY|[m~>l#.1l|ح> Oc"-zT1zF~A;J8uf$}\KE2=}mR.fZoCh':L.Qͯ 2&v#\̻Ǚ L-96S0$<=e\ A/{ 3/ؘLk'\ATsEdNah](| F?y,lY 7`v&h[l\Iy#QmsMB(A:AݯG+N=ç!#BR޻)ܖq6*q41qٔʺ+aT ,,_z^TETa`3 Kz.U2` O\YwRgAx4aJ׾ <&) U!xι5|a>&ֈmYReJy!̓BVGq K3WP + aK<_x&{Cvm9l6yqUԥ\~z",WظeyJocCHƨwu oBj:Hi韆4xql-;giAMꂌ_yJ0H~R`Ғ[', U3ū%PAU:J07D0&Ecñ$w/HbZq ͒{^z%V lQL`!g/\X@V־KBySViAx-_ [')'z^ʄqɑ Gnp\`w=Z Q? NoG&'Mf᮱WKWt7눥ɰK&,KbC.tmuЦlelT D+vИM2T}V8xqJ9x:cNI,a+:=9UϦ)4;\r()pcngfg.~ی%{BDǦ7ӵ8Mpnu*WxeQP1]e1_ q&ُXGO]NrѸEkȤÖ. Fk[/Y˴mZnȞ)n *s}އʽk+Ul|byA]8oRL 8oh8JӽA!0zR"H~7Aƥd'UI7K= a}nP~9;gs)cIΣ1? ZBnp҉5,L|hhmZ #hJ ˘`Y#֩%a}66vth`$0kG Q25ؑNGH_jtcW/GnZtICv +]-^90cU} 偄JzBdH ?d ! nx ׋Z8H+t郿ij9eqt&RQ)ҿ_靼Sˬ*1۬D?5D a+t9V ]n`IJ\s@zgH"͆^[2ms?>^}Xz S;NbYt|(#?!l!^0󸄏k,Օ^gO@eM:oC~ūSQ-nTb l~"[̔ VS 6ɉ7rN6%~Y4]]@jr%ayOcH,y%oϜ"W~Dv.o?i#XANJcCp8e,gX? ?m:HH0W-~ [/?!3w( fdeu^9H:->+j $ǿ:ʾǭBT;0zx/ofWӨ;RdDDT,HpMݕ^uι੪_`7O/8ڀʨC*5-/vZ_[_,d`\-(~?ϩ&_ClAR۱elƹ|_Ds(𪟺D5䎦MVp@dO(%/?CjV=]6'D Vd8 u3eJ]4hEo9ihAd?Lo p0*Y~MQDu ۲2Jr\l[/i;=/zZ;EO܅&Ya0FTvhLi8ʇx!JO2Qv~]t `Aw:h'SD 5L TkqDLSb&zWfiaP=Ho톬 7x^^VHǗ%amQLҙ DT'1QM'K[lRE$JTJXz1I-n?hP=|躮=yQ}@)RYV UlJۮ츅R/oئ4qY€1?m+-Z%EaFjtN'g!{ ;yG3zV=BTwϛ~[uTJBh6`_}Hx|3a[I@֤xJɶjbGJQB⫈Zߙ܊^sؼ|QPxR6k-E?5kyjِ۲z}_KIQ' ^G rXB&C'unص͜I)L!սԌ@şJBߙ{yfeFe-uD2+$+'TD άTeeF!2UPr:&`ų#0W{Q=Hvy}(H˸X.#밶Mu!fvR7ZXz w 7!9a0*~m[#Bb@&쀟"iyLtD+CIl9K%us؟vҵMBRDJ,mi@z~̲mm2|PUu_-dѾc~&H.-d4m>de|؟i+dQft7zq轔U%5t۝b<{S|p!aj=jj934@ư8ȐZj|DjHپ 1O? m4+v:rBx’~i|z|{+JTDMN @gqA$qpqǗðūT1p6RQۦUh?I=QQN9| avcwu9Œ,K"G/uYƫٹe哙8ðL1?ڿ/TTSϼ ۆCpI,ôb]J,ߴ` [貎5w[ǚʋS9jH ^4H,wGrwi2>`kb9]H '_(~}5P!dʨqgʮð/y$9vV \aC`̒+P35RKl_d -ZHОOyM9S+ESѳC_zIWc*zX uzʄLTn9i 6( Nw]뚂jĞYoҟO߫PԄ+#V2=Oǂ&SU΅zuM̗cp_nHd[1M,\:2u ݓ:\03@JlF>F7?$ކ"skV9_KW vSJy2GڃWdF_ټt`JmI_ X~ʼ+!v%);O9]Do0Ԭ2t5KDn<GHḋP8y |'D,%391܆! ) 1(vWCiu*.AJMb6ހj -38 jZmb"'+U= .~=ؠ )ӝȨT+gڶs:t (Aֲ^o4AZH[ FE83jo% 8XodSAisa*er={ (寖#^a&"\wp?*qM}Joȷ 9ׄU\_ i0<ꇦ@0%Ch'W&!cJVZ.+g=:um,I,m m_̎8&VAhof&lۺ8[/U\B(޽'>6`%= s>^⻛:OdY]x;K 7."z8<FGvt{.9x(G#dpॺVZX>.`rqS^@&jH3~ѥWj0inl JR$[ PYxӥh^3`\.386C{FٺBLdBAw̌lҮ}(˕wQCl2CP%ʚS^eS+qZo)@&ࡪ0"nRUb0hthG?$%9Uç [WKm7e;&}zAsU` Dž 45_zIY|?ߔԽ 6Pk$X*p5p:?^v4"&WS@P[Mf䗾 aRUM}$W [1ꎢc|jw;/lb8u ~bgk86sI1LÔx~-B5u`n@lm,jLVl^;ow*Dz5EL}=߇ ᠾ $T[yf+IzIRmK?XUb.EC[v)ZcuoH@҄T }otU*cJW>|00PXB ܻ@|`5xv'HAHBKypj鑹k^fU+MpVZ."]2>uB4,~Cay'y/pϾRN^-|wY +88&WR>8dԧf䇲Dګf)Z`Z `D1N[wus[4%[@ 70ox gc5󂶸S¶1}$>kݫ}þd;jhFb΍kI@sH"ZH&vj >efGZ|Hl{1jC]s)4L ! 6@TB˝ޱ${k f|~l* tѵ.n4#Hig|;K W  "q>IInx=:Q@懀.8ՄΘ~J\$^>*U# ;7b2BZ+KN \n`x»Ca|7(̻DZ`G2ݦn^%3X:)ֆ=>WU!x=2gpfU0!H̑eFJw)?붐 `-.!u_͗ߵcЀh 0Cq)G=(:G);$JW8|rW]x j4CxvrG`2~U,?-t0)38kȎ7ܐ ̫ k8xB!4S ]uz,cc/m5l T(FCF'wZ-az>vj pnh\@r7;G\pzHgqvGZ%c>@呝jB(@~9nLƉp.7@\ފɇI&@C`h\3-lJY>]YΊ!$l@!p'*$sfGLx ,B#p#cEr2ueVcrYUg[a(?Pᕁ7w)3HgǴ})f{ц%_} [y9̓7|$5{id;yI:UyŚ\Of2'`*=~H\ba,("~53w/ٻW 㲯wMFju 0ODY?n.^-ȷ'ƕ "Hn4)<d&_ Hݛ}Dl/~j{+<Xk.ziLU5:*'7Tmy(BPqh26@mlpY/l-pieHt`÷-c=g/ҝc,j}Di7@T腄.GȤF:TRɤhGijn,EzGW_d(4;->=MB]gZ} jAN!Az.]fR Q0 mi=!Xptgb]ΨztPe϶+䬔↹a ʼfZegGwȚ^v" zrfrXqY"ۘz1elJo"6:0n{Fb4%G;4&B,h5k1 O cN/XV0k*{Sfy7}y`hRߴqIIxUwҁ%T´W5ܔw7Z@NPU5ëZ싯}:=>io6alא{+ʥiC%ueoXe9Z_jW],nLnaJ'BTCcr &ލ f*[L@pFt*/CZGj*.Yh͡#-l$ v2:- ĪF&"Q%Wwbd i([ƾFLh.Ztu豾zBɌ@<τAjgRQU=m$Oh$/C]YҢh >RsOT̔)!/j.MB"@*0Io=q(z|vua|ߋT4J[O@NSJVӂ enKP7Uc(e;' -qi[Q/>j߻8Fɣ[1ǘ\~ !]U\3RVU%SBh@ GnԣXҺKHP `cT'KkߙX%\m TG,s3 # R4_?LU}<ꁳSN_[(baj\/UjhgT]X)i>pEKnT@ Tf|cs ;S򓪬O0h#B"3ZhzHǮn!u%d|JCp=u>mU1V}񙂜C)Q! U;2±cBifݖŠ>MLZ6ZT}fd#4˛)b5V?} & Vi麑uF-0?Bl!L|_cƎ@`(s?oe5/onNȓ^ϳiYLڛw{Ӊ J8eZN wt MBb+dO(ܛ$: 2$3j0c}a%+yqo%+q@"\W|#ۇ<kj{g+RwsIWͽ3p:C>,}޶VLHלsLo- <\N߮$U\!U#(fTLnuJ)|a(d䷉]dD2ՎNlǁ]xs{Y$֡AQ"Zjbk]gHlFD0#ez𕿲,.]x7PE t걁>}!GHHcξ>&ީyI;`lZh {V}_&ܾ_֢$hMBf3j_noŭH}B=!=7Uǒ8+`Rtahyn# Gٌ I;c4V{{9Q^Sh gwy 7$ry{10 wdz~ƪNs߈@69(D [)c`xMnt`"uӦ 15 𮷭L'i_eZTljt`?„kV@t_gs˯G@ȔF"Jio|VTu*ӌ+bڙ+?0AhcbA3)<$tRe+mx(XfdP[u -!ڻT|i!νrN?S;!dfrR,l4f:VxO x<bW6?yLQ!R&L!f 槷u(08E3N d` G dtn(] lbX *s9qSA+)$z<`$ Vj 5» Uڶ`Pt&5FT+Ò.0he2Q%5ZcUyKsq{NO?8+|WsD@9Je*~ rբǣΩjX}lݰu"OXБKPK~@{ PȘ(6)jD' xލ ;M465v*T-d%Pg{aZXc7r 3qnBDܰ^҂ZuI*ҸG,"JC%F.m+m7u FѾtGbժmVZ{dWg}-kKq͎O;Hj+L9w|3Βl-##)x%R͖It!;~cgLLN8_c_< tdinD=ZK= 6t"ߊ23FWi, Ġw|,=11o2ܚ;CFkƵj zp(hۡL;}|s0ֲq-DߌHwfB+<`iDUrX"-au -f! QH+#=mTW4#v&z%r]z.+m̼"#t3j3Tz_Q?+\i-P)^VܣP+! Re4Je~Ov$H: [vo}H Tc: k_zWh[wVN]II=fS| M^r{xcZJٚR.n&bσvzv*z9{FmޥJ0 g^4siѣ (BG zU4,0vWV ^,^<|Թ-~QT)B{L߄De8 vb|taնU!QPK"|zemqn/+ڒڵUޜAа$j$UxR39k+ uT鯪}r^ZMEwF\4];!/oj[)>{osSΤQtP5l[+f"EEn[S2:1faĞqNq\Ӳ,|:'e* @Qd6g.ԭcljRRVXM+kO_M|Xq<˜EGyT+b7UJ(ݶvOlL7|zMY b-{+ D//mE{KIZ @H+C o|7T.yLLK`i=QvqܯwRz@'sqVpFhKo`d~R2嵬^o_CǮ\,q+ZLJ0@98B%~䑳 juk|Ɩ_3}OYFDZ&?uIBGU-> ;7x1!b==5[v=\&/D_T=_UjX&?ܰ|ƃ$CpBS^YCpH Pis6:(B=O5'_(t +z)G5ڭް3 NBQ`?`k~ٯ=AT!153DC[h]cx+f?3o:HQ֩t EiUV)CYto6Lx -0^qci_4%yߤIӛuqhؙ]1.+9`!O$Ţ,Wc߶lLds@Vkܕ8MlH2Xd:vM${֦d».T |VRf 6ߪx"^dHRC" /$j?ju au4`3xXb /@xy*y9-_fP֠GwXM3GwE\ش`LMr)Um4z"Յiv]*ZK7|{k8VsbTw̐ơ㦱X5F6!Okb|٦--Oq)s.7.Zt"7M|Fnin|:DY =D }q Mxa3rָL^YvҒPde˖.^in 4qpK pqq0/. BN( 7k6 vMݕԎ'C]-3,ɌҌ߈c'x+d@rˀpRE\+Wj (G,( G#{rOt-4uqٔ1!~a)zI PGX̹]zB]"~,P 耚eA5VV7UTf_٩6Ӕ h@Ʊ/=sI,x0GȺ2 iUm3_+=XKE߷Zow ]^FִVzylۇ-un Pmv(W2d84-Hn4βwcH!<^8uF'UܛUto73}Q<ՒjUv ٦b4ueS--|4ͫ[MEs]t9r. ) (jgp!a?G}5Ux IL3 TU_ 1vgVa6Cަext|5Fմ&V%|$$Q˼БYcU]ngwa$R@]|kDL8!0z}> 3u„sXe*LoK^)xv9mb:.!7xhcSA^:&ĥPmb:*QlkW>a\I4R?up=K=j/},ν1Bhm|ցa "``ԮN@("`/-S 73>-])10OFT@:@`L+o6lg9^8 u |?8H%*` zTO$@VfXj*̑|F=͟@`B/k|g%?`lDbYJ!>SPlٶp o6i;Ae>,HfGH(,ΚK:Z73MP@uxОZi v\ "*諈58; -|5\m󫯤HdqjTfLiUU#>D)n<&oa쫀KE:o?*jb͹ d 1b"Ν3Nq aI2Τf,p8AChm+Z/P$6b4\cueSENDA3K%q+P̃)f) UXQ cqvh^8GCrj>ї$JӉg(eMт&Q;,C>/j+0& sBVմB[b1qy,"(܁ʵ~ n>6W }n'h_;h- $9^<B51kƠ1cS xFf#^tViv"DrOA 5)O$u>sA QTw|:$s7ITRf*{7ffQ:n{TZ4Yn2Z+=Ǭ8Fm}@{\.KI Xb<- I;Ծ>!|S=_*(a).JHԜEv;1q͑mQ_6,@h4m>۶S(gI;z B ~ӓ͎CzN烱(8ɝdiHa__G枂Zw(&(h~ڲ|1#>Pej jink' {9bѼx6 U2kVJК%-0lV3$(q#ޕ q7*y#fifR w `ƁTUyg!a8J `-ۇ&GP U|"ЄkRLs3 X7!u3 A7 W>`:}ˢ"#R!ð:7*Y~X!ǩ 7Xh;üĚJ4τ w&c)ڡ:e)w e\w$ů${oqBJUÉGThU `~ϫhKSgl iilgGg-{&Rlc⎨|cijEڇu&OC"2:}za *(}wpX 9iȑN:i2wSiIVoxw)t5O=Ad&|v.[DeT%[5}׿7&Ɨ@-"ucj XT}lI5n|Ѭɹ5Bp1` a״Y|\=/@TtNff@ٽUù)eXq$, Ny?Ɗ`\\JtM/DS̕9AKyUk|D(Ww|4tk-g9/#.\]~0*ޓER-ZS?> ~ɇ0EblGډ6:˿~4wagp^6UfEKo_ Q^$/> t(#NnU=k <ކiO:Fkf(pr\`wxXDbFa%CP6~OwW)@p mT88'X8+vށ^˅do/X"~!ǺЀAgDS_ LsfDOmוJ;Տ61wz%\!:yr+_6+26:azZ@֏ʝPl)73z= Tn~c>=*$/]7MKWxbŮMUSJ& ̕yHT$~dk6[b J8=>Jd7- cbep#fqR/)( P^AT>>U ~ujSH #XmV$ln}nl+ ䷓zA/'%t1WT?du2"[}Z'®TfUQտƍUwja3Bʷ=ؗ.폗@'7t@ *(X* 5!$=8C.q* âId e;Dz~=8oV"!;q[g d*ls2YS[h9Ф, }ߩp+ٔhoFD; 3cEPD$u((!OYfQyU0_ed:\3/1ċ|m:!zvs68amǷ`Gc#c3?`~ uM?# xZư]VA/.:nFu0~Qܼ0fx.zD{&Vc9T̯73:\H@ʵ'PǶSJ>%,OX2C_qgkGYGNK `&rW$~!"QJ˪ހ?;›K$Y֠ݞJ!}iA]v_IR@M Lgd4sXtX[{YQ<5JX`r{'ue9tf)UY-673( ƺmv̶\w a++:Y.GA N_B4&uQzmKnd`6JQbHuGLF5gȊ +4D0e}$B1?Z\ 6f=UCk}`j?*|~1GaVЎí?JחzU:ƧcܼiZ6|#?iKdjQneMwَ"U oVq @Jep5YSdsϮ,rسZ+}5}xx,oU)ovEbcf*O{#g}eCuDn@(4* Y>h;v߃irѝŏ(0Tnar~nd%D ӁV24b'-< KSC؈zǏ2?%ɝ=/玭Qig@&QΑ|wT\vqV4dC!&Qr"kF-[u 6p n Sq~@u.Q4SªHs(uFޏl[PIӡU>ll&_b +} g*Oig11$ɜs,Uq òP$Cb!lm9DPgzm(|t@SdP{W16)`>`?!RA6CPM-]PpS<99nY#Y6wKkJQBښmS 3EYzpEhFe_a@/~v_ ?Xe-Y'!!M{ƭ'0&MCx`T8tx}ͻlq:2RZLX0G PZWgW*i\&3I<0nWql"Vcx.]4rH$ǔK[\/qG`mZlSD(S 1Do1JAb(8x0R6e 9]CMYE誤O/,+biC`,$ }F)V}W#)Is&h`u#ۃv6HJDgI+/!cCîy݉g _MS#(5Bz9aӾHiB]`I6%9U1׸F.b<ic5t!%-.e6ke\M}.)iim-j;pQ]:Þ;z`7a6KLzƋFNS_Iu  p*;J-Rm}V]I뵜k['eG:,iJO1+85z]^m-DbO:޳ʹعi>K][dgޒbf ]OcB߂AXReZ$]}݀VJkg0A1.m#=ov9f6z<?T1Y(w:wa-YrtD[Q=LovE=Y.\Tq,)#oD}1,Nm5HY8(?F1˚AHUjRXC.k7TrZAHtD=>E+?2Rs^QL9}OVB,5lVT%Ӽ %6 \{@0]׵3!uD%Py|b}x3oCen6\=3s;r-nĄB7{6 z>AeH';x^̥>uzqŞEZ脥pJIA/`vqvkx~?e&)kxRS 9h7wј҆8T\P'\U&r[9EZD(\@}aPPg[p24r5c #9>^0eaڣHȆcO|C8M`88^:O#׀34m<㫭"sm[q̥F"=cSQP؆-X;O9gWG̢X*^>w x& ewHƅ/4v۳V^h8&zl' BS:s Bs@E!(e"'`FT,# P:ངi>nMRUu.C!]l"q5d'Za }G MP Y ymP ESWVV?bN/M$7ZZڗ) Q?t}bA\nR/ΣGD[lܓ2 Q$W>k*F4YMAJq[ K!a, =#0ZRE^ &R+}W A>2/|%`~pKRWg<arG@ˈs8tQr=}5?j+K f!`:5hi\n3,+l1Hy .f~exq)L\~_$nqֹ7k{2t Vo DJꙪL6mŵ%e+O>N1GQmxA4 EFWR۶fsUJ2N#mtQ3˵6E Vްu1Q;j 60?.ԫ#!k6RrMW>>{1,ָbeX޶{ 6kVz*OEsz66Ç=hfE+ih!f[լFqa7F/} jl!\fUA` Qݥ\0{(Hg2SA?~6G-lD8MEb @F(A&|Ddͽ+<:X`$M^`]r:cupE -}H12_NFmxtgT X>Vt1XArLW JhT 2]ㅻ?q|9BvhFar3+GxOl@sET[^[h?Ɍiy%Q' ZN ֐W Woϻ֓\q9LBXbwI5;Ы/NfXEw_)U`!}HZRPQA vV'(. ip|-='?Jyn~BG`h uY_su;2j?JM0,#o3Qk#Ja\i՟bѢxJ>N#-t B9V3 A F4%lMC[!0}xrS7?" nL"ԸdaW~JJX$S2r7E_n&īN7_9*E@iɱ:GgUjva _XwNQe)^ry)˷W]7F΄gSTbԣ΄6*i*ڲȼ4' u.^LłI(bql&W"ll=<̥N˵HW̹-@H]`5fcDif 8dĘ?@2q0;]͔Mu7S֜e̩ʧ?huWhc_C>o NFuH|uOK앧8$Ky+dWo̙c"_ l t.J 1f"}*a\w|l}{Q:5D$* "U: $ItOmG9$a$՚?"kxȚL`OU<Z?a3YNIZcrf+AJN$\f@vgOo2eT# e` A?'¦BL$?PԮ4]`o7P"-F$F͵=R䇳XbCbf+:h[К4Ͱso`2/39@vOzoN ŘUUXxnDhky(=靹3 ,TW|a~K@S #ӝPU|H=c&+(;* @f8:M>P&fF?Z?'dr%zpҙWk7ORʹQ򀱿}[!҈*IB>~h( _D;Xģ=~3LW^6kz cLh` ۠(A/Pl߃'Vn.߭!jƌu6C4 a;KG!: fP +Owy%xz躄uh Ox'ܮPR񅁧SXÎa²2wA|5 W6O1v_#c3&݀WA\H1 򼽡~כeWsZ W{b gW-|#Ϻ0n&&e#΂h/,V( jM-uEH69(ZOȒj4#aOox5Q &v!19LܝDdY,]d :mÙ\V~OӋ_ eQu+T Z߭5XY1h^̧nd`d˳T>2+:;Ӣh1p`ųa׹PLd(אI(! U^!NoqQe? o+O-j%;՜KYCsZUDӮmQ0~>Yh| ] `-|M=‰ST̜ 0A3i#tZ8zeP^G*bJhj-)HfTuf\x,À vَYήaDBTW͝|^w{~Æ NlHWj:"q#"*nJDIUC,>2'1r XЎ oKfli;!PSX[Ιr?-ׂn0Ʋ2[=E WKVys}P1*:/.bݹHm'Ikt]l@7"UoU&Or,Unj%ri{3՛Chm"8{a^;L]~5EdEE{]u^k SQk,P|Ws<.15\h :Z>P`Q~H th@Q@FLp"qȏge>XH4-,YOcC4GߊCY'1H];fcsn\Aٮ8fMcR6w!_3ⓠ_V -G۷Ug>J6A% 1 i_Ӈ]sKjHb&/kB\Q{*Slԯ`h ñ=4)M5.)%m>ɭm5ɭKgDr .3W-d~>z<&"C۬]Y%/3>P|G4 2p0B>/ aB2 c6ᤫ :wC\ʊ\g5&Vxv R.ɩ@9? ̕>I$[B2llR+$L|G:\dnc^*X~*hV mII\ d'kN_b>*)UX] O>=m˂2TNG{S\]s)%oSǰ c=4tCr@"IId;Sj-^$mZg6|Q&B}H$=;Qv]Tf ^,ċp=':H~l_lS-aNR<=,jcz.\.ۚqSw.?:n\f# 9A+pQ tD 〰Wė0fMߐnQ5k7xf9[ݠB͸FoƚVrM|iHÔR<XP|ںHh DSw羦"O١aI5Oއ>5^RyASpwŖaK– F`?kԫFikT!S·֒m8d%<f}&k<(k+p*1/n .C7=oܡfz)b™n~J$6|A1;tD<܈CdvKxs1Z;՟K?#N˾x\.{^aj:Udd5r,_Gl=/91fGgH~Fy)M8IPr H;ɝ*o7hMPiq3 22)Փ1;^2hxs`HNgĈN,{9 MCcaZ/ʺ-YDedMf>|xҕ!LҥK}Ki漖}8q{(i6\NJT1a(n>Jhi:`e:63Daoq7Wdȑ(];,- (~4-"#qI s~ Q降=one{6F563ͻU]RZjIyiR=pM`i~3oɱY7x҃@䐤q/4B'{/xT]`(is[7bϦ @̮=3'(EZC)4u>`Jh`;w7"菆6\mb+ 7lm筒~5?fE:+^hj .T2͝Gw uodɇ S1Ǹ&3"s~,g|^Z\N܂>wJHY7D@"͔xuDE~DChLMfʾ<ڂ{z8Kyr:UV$26L}]--X:1_^贻;AUxDgRjG f PEJiZGu*'e/ϋE C7f횫rQ0VńHmhip1JwQi^eMz %u!PtsAt/xkB囵m@Qv0⪭x%Ji\_]U!,71J>aWnqe₌K,w '[hsi v2aoc-(YHG6\Ɨ``b k2(enY!eFg.Wo1/i1vD8 XI4(A)A@0eɶaoUzRI4``$ͼM$l BAƄVJ. F8wAqa=5=km%뒡0cTO^k)!ǿD%XE 3~Uix$,4.* DǂU=٦ѐW”8*Ac55 :$?Pǒ=qNfvg>mߨN PG3ZC!It\ V@UnT{7*{K+>qX݇ռ7%1.*EVj@݅|G,bڳK0ւP%cM%@HYĻYoCu_0j1ghMo/GpadxT&g<c |ɣ0Vʆɫ2%;"Z$|"`@OJӠΆR *djcq9гR'_*dyf=Vy!^[,bA$J .v %wm9V?SV8'UElѻ|[ V[7W\B N]4{cNmiF IZ%'1GFdW8ҸLE60# |E/9Pd7^ o< $}3~n3q T\ eovM v9 4mՀ:TM40 d JfߧD_gnC\~Y;H֝*+h'aFUXڤؒkU"Q)%B!c:ΕW^Jk?+` bb%q>,ўdg[9N)н+P59k:Mz4Tޫά_cvY6ϯ;e', hj~^_Zpz!]OI.%k@=ۡn&vؖaM3mh#^-Q8ɬ@#˺2Jmm >d 3<6lX'C0VВWɷ#'tt۳w5~uw?u|< v\{U\cW{[Qnai޺gqP: VJ[O{!ٱFpK&4wc{x4oy?B~HҌȕ3(83SW[Oj?4=pYsaZ=<顰+bdSkXף%6kZ/ 3 Jd IMkï 6RbokRRK|yk"ዃٍ4_ Z$f=CF4 ~l^ 8Yd͆&3۔H+|kg3CU)H)"% &_*э23F}J7\ov.;PH-g,񛈍*kw-E.eHU,ͤnFvE%I .ag}kSwnc%eCŠM|0[ 䋏_rS8nW(a>Kt$TB7d :_kwM) ``z].Q/U/ԋO`(e6 `}M=;W/IScR$Aomcq`ʿ M4;aSU2 {UCs—6د&GZO?]r]v0fo"@`YXdavzs(Qz ''w\dhAQ\F1g ߃:*Ҁࢆ3}q_Hx? (Į:M&b"^ τ*ĚAJ6QctS;N=@Di;fyWTU9PT Q1f,Fǩ%qA[=Ras+?ƃiirM:k}-;;g) X*g!xtDYڄ#͕eCHԢ̤%R$¯/T\9PJ]h?zO:uP śr\3BjZuٸ2T/Zff_A°NEz]Di;V-E6ArCp1͊NWOF((  -pAU1Lg{$ՐTo`Ҳ4efZ2b "\^(#B3:ѻ]Pbݱ>GZ*ptŹz^ d!i XmXY5 %b-&Pǩ~vjm斶W8,bz1{z3Բ60/bq̟gS}po VDX OgmHpcmB5wh1%OHπ9eԒz@J\Q;31H= y4.~'j PyW6֍_X@<<9_Fh{oT:Cg|oh $O1*f3=*sOӀHVĿ州uE3` AkCFؤ7M?4@lwzsx:h] {&45o6Wߚ\o/gIGkt8pr$?zRn`Y"H|8tQ"#+b+#F8!(ANҔ &6niBŮU9cF&쬸LSYhͥѝZjʤ^9m~[X MSo.|h,d:yo_aQ@B"͛%a| Ճ[?ecx3cӲ:/Zaruk<8eE"7;|f!Kq*"_+)f1u/EؠKyc3OҞlw3j:Ϙ?CWnԼ|K+B'Ve+;Zh\ 9L~**VH=`izWbP2GpvSJg?ԖaFh%3_X,9 -= db#n|o4==KH?#mr1%Nj}UR,t==S MÊ@e4y1",Ő7 (ۚ;gļ*0n}*ڐj q9m;2#4 G5g i84ipcB.I0*o`E4iiH!@̡̈́Lm?|tr>iZc&X!F~f.Ѡa{/BazM7K(}zn3)$Λ *Y8\J/lӐ{v斩GzMS\dM5JZYrf^`bV ωş8b$2AQWw\ ΂[;q|FX~P'9#M'F^3UE;+1:6-U!m<#A6ɣ9Չ"+T}\m^͆|פu;$NI׀unڿWՎ쿈]5@Puиgո,@Nޛrݳ]F>J#p-39PZH@-KD*Q6}jJ~@D2Bl(d @jdt̅zm4^ۓF7t#H*}Mg g_QBf9\t!Z%qSaV;< b!b>q)\mdf1ȫ,E+ta}pӎUXEWҖr6|;q-c)Ùo)J/l#޻{Tv9kJ _Ojەْ\ayby/LI2_ ~kχ_Zl͎L%| !<xCq#_qgS+ƈ\K8<8{ s\2tu@\?;MM8ޘV*^ʶ X[; :>SN拐^άӖ[k3ܙa:#ۮk'9mJ=1ǎ4-MA7RhO!A8@X'f$cUq->#;wE\(`% `Nljn}Oa1B/mPԛ,o"A4ר99nk\Խ45x%McNS PQ"UO#$brM l?v*ܮ_2m\0s\nFtimSL2#$GeY KJPwyR'P9ۜ[Ex~d69UȖ˒cgBp2{ P xF׉g3rPX|v_ &s%"|9lgI5:u6d,,Qz!n{\J bQl14/؂V 6#s ~8j@3r݌~4ɗLji!h0audpsD]Ӥ~ywa\KZ~[ =h(B2h u@@ K˷.}pn}0/@co9j?H):Azd#Hm7!Y*H/h qm0um@ӎ_ۭ޼JGDžvWöij 1Gk#@YeO}RvUwaNZK)9Vq MJvP{%|t'Ϋ:.po$8>xƦ?.W. T*M" -6ï|4 MF B+e8Z8/Yfb|) SHF*PaFO3^i+BXHkkDL4{C T=CAL~DM1]HE4+($B&b'd·eHZxyMhQgER'QsW51; Pǻb]Hh~꾍ǐhYV)#fζ.½KKug8]L D B2=ΓQy c<7f@QX"mf-链v&e*ӆHʽoMOPT JB a&ybi!U&PvFA꽊mRU.abdW@3xKܙ(QWGQ^1&Y2$X_ N.Ғsa5v|;%N.82%Jd&I~-UJ[+V$:ou9-c^lt2֢oú,ˋ|Ǖwؙ$\ZHR:B5ѪeH jbo9jG,(]V\m|$& F#p.*#2eÁS[n4:̭ح#c،~zMrQಡM r{M 9zϛsQ(  }K]\;73rEKlyz3Wt*zȑh%AoU 32%.C_^ TfgyRמYWxL/۽)Fy6lUe~+h72TVM;\0w+­@ڭk ;D^<僧%GAdzƛ?#r5g>!n^s\0@BUul6S(W FwWn8k˯V?F䒙9̞{i ߼`ZEg4>;G8=xL%Sn }6|5H,ߓ"Gqmld=V!e-c>L pw&>aZ+fkv% ;EVPiه0qp,Kݙufx́n̎q{-R vJKY]$3T.}֞ZU,v ZuT2,I0-Vϩ2C$5[QKgRߙC wƩ Hx((Yrݥ cҧ|opRKAwSUSʔ2"j_pT| pN6jJcrZIsS=d:YSt*")L}\!YAY. ?g06VޯEF!"%l4"A~;q_i!ʃ~ekSWβ{=(u N?4' v鸀Ӊ򜃳?)\O(i"VI{t6JV=QƆΟ!zirP^&r͍rg}6l-nJR8R;^50D_o@JB9I}{ގgIXbhп~l)>}wYo)&Ů.FPihl:RxIU߆P+M$΀D mUF<}M߾X$keEu$5}?{UR/lۧ&oQ1iɏB_@ g'M(_]ϩF:4揞dZbxBQlSы&X5H|?4Cw_b?`-/ _WlSn;Dv*N9|pFX?(?? p O~.tcaNRKTSC0B u$5jbZb>eI!/ѓ Mi;Z'#҈GaUJ=&6$KzF3,#ZxE2S >W"?Vd_<W լJXHk@["Z-]p|sm<4,4Xb:w%"+ ϼ>znԨ2^;wuaul<"x ̷ /%I8f9§Ҡv6(?ϼ'>FJ;x`:R+o{gEء~ wC['?\1wjmdzu3F0Gnp3;W.wYI3~NnYHBo}/O4wܾ$2,;EQ7 (3/v8f島 0^w-9M& f LJJkxؕmBt?&v9ˊd^쒧D4Ni7Mt,ஹZ2q5I\tvl7^~@TOrǥ' /V$׏vXe[&0e^'˞od4yn}v#|䊞βoCröCUB >1kLWgt5!6DYs֕\>!l% =>hG8Zp,TKBhYh~M+m>K? 8km 6!d$.iL g8l+~1&I^{SUڔr``C J/vG4@ BKT!HCф+V( 0Li%ɐohln8#9Qqp"ݧA5X)!too@CF?YYO/8&ْ4N*h Gs&͐7g׶( =FTC. #lq8k^rrH Ȣ/뢰-k!~l:Ռ]^h[.FC|:v`.eUy;1,NAU ayvFa{ >1V0pӻn'W:* xMX=0Modyޜ3>Te&8̥TZ*#je6%@ӽ*E\hEo+W[ =j(tqZ%,XVBSɈh?Q 3lvWmO^7G_``fnW6%+\fs%"<P{=b) H{8곢1X QVGv q'$mdAq]Yn*X =LYV' Mg`9BZjA*  mw(ĕ#^ʀԏ+?O`!皱R 09^AP_E7B]gS6 M}lt(CVXۚrM 36q澗`=z@/`ٸco2I>jaJ,ރ~./H7DkT}_͹B 2 sf 8 I!%+[&u궙]ý$Y ^d5׽wޢ:L G4@NlK>dKﱝ-:" Y\=~I@ywT(뾺2wS_7YKF |QbNiJ.\ [ b @i_z3הгz%/ %.h9Qg1?|)`L@/qy&Wm uv+߇osgLɃpܙs)Џ<+cPZ0AJ_IjMiLwAKV%=Xf,{ܪ1yo|@&crO'3,ڱ,߫![kdj<эR *ޙR, 8C$wv(K11X &0ZH(wf/y7>.BzJDǡnwwK󻾜l<) 52@H#3[Iltˇ(8VjI55qVw)Ӻr{aXC (̧ϲQEpHpSQ6? 8YjW4- O?bk_`6&VCJڥs B,Yj;,z'I3>CJcE.'iWŠ>e ]y\t4cef4r[\6熈]:;3Wpщٵƍ{B$TD_76x"}[L0yũ;ɤG纄f2Ҏ =|֛C4,4=v0z񩤖lQ;Ql>HsntjBHH۾IrN7IfA=ԭGZ F;)C_sm.Qx Hi&g}2d0¶Ǥh{BssWl̝NTZ=Dw2yF߯Su Wiߩ֗,rW.Ucl"7ZfMdoҲ>GbIq;g H5gag~|p^c?5>&{ןCW` Y2$2^:0IC}يP%즖#7OgB(p4BBJ'л7!l5 0EnV~Z~QxVV^[Oz/]7| .囙YvpFlͅ_4j@x^6&G#A*7Oj ᐲ. ,J~$N߻A-i9ƃ,}%3PE6lɞ!u6`p+agzg|8Fy6k.5 VL[ir^u0i@B 1jQyG!R«9I9_aERgVDrl[/N7HnX'7r99LgIyhzp+@h@\AUl^)KwY͊=vdÁ"R,êيQ$R޷:WHϒ0aBȅH?ɚnR(9YD>J/ |\([}K=xs%H;[oO45i6ۚޱ̺%L8NiJX d0PQݙ˕Rh)xʽdP|DFH*ϙ&K=c7{|SGbԜo~nlhkA >>mBcoC D |aGbBEҌ7O?) 8vd<\S?!f320J*=hiVY c=ae|~aNU,Y֊F˕乚F}g`J2rݏmB qeYqJ3k1AC*Oj)ѝLQA )_/*jE.@7d],I.Zw&V9zQ1챈aJ&#Y|J}gI3Z`y~ɮU l:BЦB*X$8Ґ>Wx%׫y{bH_+? \?lنt* ~6 .%!rĂ>͵koDXHY9YMzK.|DN܅<6l ?>}c|Vx y,0qhMvgI\Ͷu C~ AwYк$n=/nx.} K擰T ߃}h̬(߆說rdZ7N{}԰̫9ЎT O"ś Dĭ3}w^9ն@͜ % Z{-F&锉!o9]-j9~Q/+ 0F?taSծ <2s:)*~kMlЄw,*1IlEө‚랡6M;Sx("`,xJ{oEQ0)inIu+,t?0v3NۿkqQ͑hkQH!>x)O:i @ZOPFi2Gm]j?'h0+<)kZ[q;諢֋P* s"9 3殮rTl8i`~$wqŖ c֠ `0ˣl7xp_~qo0.'W)w3kE_m'(X[!E΃\й ʱ x21M1E9|"G:F޳.܅[n(xҸKGgC@rHrЊN ;C!4H!3gj(BT5ܸKXM0·Z9yRt1-O[]It/ݝܠ}+$!Y#-6-8ILB=\A_~W0g|Dn4@^Sĸ)r{ַ6MU's!1{gQ"zx"Sc_ ]k=.+e Ki\F|G'jk/c!E N)¯海7GH_7D+t 4Z.X*5gKPRbd+,xi[&z=>I4@qI聝@dN5} 1fC UM8L=GK_$Pv<8jR#&bqiD`%Só*Ty/2n<~<+V%ILKn{)vE >\L-=bZZF^eI~uKSp½kI &|,ЙnkKf:-/Z[SUŝHqD9RttAW |: u%8t([ py ֖_ʻxC>kǍu [hEc % 43LJ=FU"ێl?/Ȧ=~vđJR EZ:a K@N>>޳=z~4*o֕F;/=hJnB:_ OϹeFD4ڱ#0yd~׋؍27dʊҦZA'Mbg-=m,UҤG[K,wBx12݂^F4h2[dU6g2; QL{؅JwiHM]H$G'1`s.vzuUdBD.P"<'"J|LX*ZͮGa;/|~Y?y kr:E -ed E&L`5AdY: Yܲ4eNM S/coɊȞh,iZcHޓj%6@4S^  ؟ÕB5M 5j5"X&j2o *TiOX(J?kL1FQЀȜ)*2BEY%Κ#!Y N6IGB賞VK5s̽}u=Ppb6^-6RehDs'wܡKėnq<7?A"ט`s.pCoHiX+}pLJIoE0 k&abM?lvSe i?J fuu JF68):hM&q:G_n?a\) wri?ӯMFhP@B;Iw9 Cunݙ%<bZqHb  s}- *[~:me16WS `~ ]u19 tu II?eV+?+io/&SBoXJx3\ H7;}PG7Az9`*V-ڏGWG6x*V"*'Fw.e-qlzm'ј}I„>ĉj LK]"z{H=m,`>5fN9~MҞV弌CZCR,3aAS xz"?JVӊLA$5iC$x7a^Fїtǡ`5b6x |@G#-^bZ;%FތoG*ɘ n>(;S ̑p)j~Nq#\@c_bᰍĴ44s"McՎLZ fW023G5LO=smWuzOplnm<5lW)X| 8Ç6E+'wǍn/ӛ;2.$m6Ⱦ PntwJY  [><#C>"<58QjVX(Rx~L~{M(3-hBk2bccVzP 7CNk63G_.A=1c`mnVTK'yZ?/R\f(Ұ) 9#VJwY @@Xęzz$;ѵQsIm'M$h4-^>jCsQ1g?|㭉N9D {i&9gN_!kH~̆bkr^3.N.4>ILVmsLɚ9jr]^VVdkd_8m\lmV'M掼im-{+y^7{ci$vt1tnx+:@@]2ҞrarUnxZKSjk OԢL-yu4sD?S2v6 GumJIxcVM/N* 6"o/J9qMw2@kv 9#bB,,<bfw kkB[^)']}6vSӚRAD(rY8 ڡcD['I" %ҦWFq>kLC/77HrrW'/S,0qTN&]>:YPRcY5l\lκ; 0vz}`2}asy/oSRqo5pe`fot=Lͭ}rBـдt0`D]]czBF:}ʒd ٶo6.a:v|!o2N) \uS?e8d}FVn@ yp1|ovriLe&rg&Vycx#*Nhnt3e0Aqrdj?p>R$2x}f@,nt32zI5] >Ŕ˯@a-'O-~W*9-i0w#91yY* Vkn-VM]+Y҈xK U ůAR:q3SJgD摨l7,ɯe֞Rc+1Z9E7cF\KKRܞJF@LL*uM[KMg6|eQ\F_lTӰ]&b)1(S? $Q&ِJ}xևQ8݄K -b2N䷡vҌ '}7ڗOev*K^"z`.,:QG2~I!9-^8BF Q5f,쯉wн,ީ_MW\l1oiNpM(2:XO8R.jvЬ?Ua쥛/P,1ci, 0~&p%ݬfuw]sYIc/NUчfֲ,,oҾAkԁh';:]BSoЭy /ԏz:i OA$(.F3^=k+b(hUY\Q"jRA8,}~(V68P33O[D'1Nl5XNϑoR .&?6ZH~kdGk-s3u4#_uj"* n\n%cc5fќ7 Ј(Yؖ%ej5NbkAz?tQ:MBUPw0If< >h&wS#GCJrs mDn D udaط#fpvKZ$[|VѮ (F}fBt^*U1l_ǂ7MKҌqQ}EE(t y/@ynRʦ6Y#Tj##Q@+~#=bIXǶQN)++/7f|v08fnRwn>)#?ctY_IiK9p>i^<9USR#Yӧ؏/vtr} GwѪ/gulM#ԇ⎁ WOMɸu>ce1k+lâr8 04vD[WtuJwƣ^W(O f+<0H5Teގ { ?p2Hv`p8t <Hәh#z-tg`tD_6 c&4<Ԏ0=,.!"%vJq0w9ݕƊNiBӓd4Hcy0Uv40A:V)z*0̅BlKc|l#` a{s^߃4}qj\Tk RqfPc3,hvpc˩ϡC]Ԗ@k$*^F(Y;aץA.FQ܄x.dĕ@|GO/ofTuνb#[Jw]-j`vbhhZY4[nos>#ڶR 1vƵPiuko3RIڞ:]L'@2'CO"џ curPW`8X"b⪪` P"B"'ΊA ~C,a;폷b{\)}76RfGRcz #pff80kaWCFnIh\+_]J?21$|(װI)Rs^eSh b'ЂYfhKj lfjOBgs[ S_o/4H؄Q]hDxdr^6׎6+m"^aHM,5?e4ކkGY1s&1irh6HYZ *˨PKhRrXo.~P\ƚsNAZV3  Z36;jsԘ-A5WfF'yهXG(m&r8bSG\G3}8 SN CrT\'rh@ۨیݱsQK$p[q} YW&>?nma] qC݋ˏ -G|=DZ9RE5 hNڹ욉QybvD-ꠜ7{N O5sFl\i7g&ƍ*:D܇ʲ;t.Bb376 pùZI2L砖w`y0Ip9.5yN1ݪLHbjbTb{J<Ŗ%f,MTҥbUbڣ*F,S)(np/NOTddxYơ*_;йR,W'5'GF N3cJNyN`v!&Ù 2=\tvQ &n#/cBL_C"P%݊S5 ]7m[Z_0yz)tBP)qpws9.^tuZ]Lyü7~q؜ z_@% n:-5r J2&Pn1@Z Ëw>ZEng^üsݛ&٨) ęwN ʄ|s6$_z#R;Y""3vgAJZhB9,Jϲ Z.q{&$[@nLB |WO_D梥ʠǽru+-fk"s Im,ةGPsB¡.7= !i|RhtAV@rcKZIw5zl*ߙ#1Bg{Y"3B -T1D75R=~ geiƵ"7 b"njm1t:)ﲅH2{b)ؚRh5gEߎ9x(p*ȬpDXr`7o!5%^G*D͍7y5<]W$q!'! ߽gǥ~ wn>/?ui={+ݖ+.jC~cI#91> aB+PG7ˇljB={e`[ys' m8tYM*C%ZF?:yAVjŠiȃyh`Kdx 6wl2 o˜V d],Fi]ɩfDh V? )].I-a&G9$H?bqP}S/IJ:AZO I5N^wrҜ %-Tp/EAX! ~wovk{!E^6vBztY]JG>˛R'SYP& G7'g!Jd`hH"ˣ2vGH-/ЯXd1s'pc.*J: b 4TDYC&`afB{ ںݷ#;g<:!ԑWOm)X9bɔ2*J1\V'~gʆ8iGˆD(5wyaYVyp;nטʇΠ5\M"; r(E-F<WSŴF~xa=P\,-&}6WBB^*qӴ:ϭVoiƂ,G{'s|xq1kᰳLRe!xԲM^Y[?;8{ᴯl+4=^HmDuxȣe5*'ԺF?vi܆+p0݂z6Y#$c w=o&SX:rV]2*y2azsX&F|v [=Flvmt|h:)BT}2qO*W\ߖ\ "ttb[N=8|Sq20ߖރ Z8}].tfͽhgyh,7?,BIV)k]Q;C20" -!i_) zEح}󝍐+t#\ɒRDBsjO8[szfj{ *w׮mb{q|rMfķ2ι8jl =+hGYbȜQ)Zta6__<#N.Ѣ~_eqjka^K$@l4\QqцEjR;(O 4PWVprH-'llÁ1C{) ƅ#wqA?{?@dM݋нsf4a*qOk..Ap{B~F,S:fe%ȆArq)JDQKL(1Cn6w@üttkj-3ZE%i)a3\o79)[ddf/JP.@VdH&dMŹ7я0E}ʫ9zֽ|?GęΗJ:^ub+T쀙4[c$6-g4j!M|*4zC}Uq5@oBpE1B=v!y/u{`i)8t7Ѧ">.2@Ӟ<:ٍjpj|>hՂw?Q^e@h/Yҗ+@- lWpt#Sy/m_ni@Y6+ܙÂ*ibk.EQloߜ?al_6̖^ۅv &2=B̠i hvr#6:zIdl ;tFĂi[5_HBbN0@bå1宨~ Ki<Sf ,DD׌'Ǹ>qY&Mƿ%FFC3^>Z2t_\-d,80n<~Јp!d*0NУ:\/=6 ~D#h5&sC-S#f-R"g[oV7gm CjFU9$INLW4S#ia8{zkBS|85*^#VƓm4mElzk*/&崤0R}9X(G&G@V!>. .%[:*oI-cHfT,*8rYS͙-^Xh؏j2 {in? @ۅOe9duE ߲3!t M,rZ8quŹ2LV3_Íw:ؘ<(qZԘTJ&-DFMWA1!R\FV׷HSu`m|83_q>7>:XbU((\m'@,K&\Knԫ Y {ߦzbmǍKjc0|M;S_qǦ 䃾@"wXжu52Ns{{9o C /: ^5{mieI9g)?`a`O8V <s hMwh> Hl#-+7,Ș,c%˳94M 4GAd{1*3P%ԁ0ĿOsxSKp9 \ʀ'@JKu{A:B(zV-?*OBGG8Ҹ~uYAg.P:[;'Pq_ߡ[DSVރq*%.]( @FH;ϩ?pӬ&ڐ^],v& -JMzAJ~4e@\8Q ӊL<5fJǹ\ %5sMϒGPD-ʪwa|힋9<;RxmN:jr3}{~ab֋O:L |p 5*xiUe77/&WQJ\BYXh}-o"|z]ncF_@P ~^.xS.grנ'|oM_0ovfs۽!3L,WGƀl^6i [=saf6GZ ;Lu,8ⱪU^H}QcsU-~SİQR0z8qV O,Z#>Ovs\bV#.Yahؒ_FJow`y#ؽqJV0YqS3¦_([*iAQ婗鱭vT%+xµrچ!B\U**W7ڐX?w2c š*ty5`D!2ԝjM $理K4Jq4dw2S\!OO,Fi{PO2ے">Bzr& cޑ&s`0ULTR-]Hg'g߀ڽ:f.lqað]HkflAk@ MJbO$84з8̐5_ypK>];t[JY)!PF6#-PljK5#lH%ioK i/lk= fDA1>!^\ `Бc/ =T0w@.]Qg-,z2L>hGsoauw=%n/@E{kɩZNpx lzlxqZBIz|,8jAs wEm LyoNd꺒C]ă}:kk*]Ur"oo6J{(z'Ȯ¼K`5զ]<>8xqh‰4=NJJf34iFkTf-v(GKx*ix,z^b_L䔨cONw8l񨝇sMpG#L6 YdKK Z4یيҦf'ٓ́tt(d < 8,6t` bVt83#| uc >NI@h #SS%aQe)܅d%Qjo™e ,iRQbfLP@U&w'4qS!NgiR\@k_Jʴ dWD [QX== Zr*~E;i1δ.0VR-q)8 hsqT}۾/@}\90r~a1f5Cp;K,*øլ\D 5b3xy|4PP&#~տM. 1 j0'r ۄaQl<~RUahAT`πRn$j-ߩkN/M/QI>W7snq{tI"u.t-O:aM~4FY "*o3O<HJ y0q˭»{Ud̰)ؓ}Ѩ\GC!&ifb/℃UFE8N@k8/dJUHKۚ\܍+Tc^=M`" a0n\I-G.zׯs"J O,I\%y4E -/FNB,WI)XM@.T◚2Neq1#Ɏo} !fK`[Η<$O_\wjtw"^o5|i^IʉN|{jEw$r(E "2C?U6 Ѻ)Mk 7eQ6D>z;|Wv9 õUŝ a5Tp|i^GF; [^a<+j`MF<5P`[jr41i/HtM1eZjW(A\;C )jp 7xG^yQ^ qaᕹ}1sCTo"R%IfcL4tCtfx |Zڣl]"gɹԟ[c-h:@DXzVRƳb/-bt R _OnyGy@Q];9G|@̦g*'AJ7?}Т"dF<j *"EU[HS\ :V"ӻp2c[ot6 s-q'fgWߓk-Sqo)Ge1L$2c'$taZ1&bgBi8d|S2Lo?0ZZee.`J- Ly vT{sqrtL}B ~.'KobSŜ6 =ї+Nip"3!uAP8 sqDbq㔡=x6*<.(=J I-oT'0w`}C7q4N|jarj͑wy N ;D;b=F@uB:쀥כW dcI<>%燉pڑFmyRAJo>|n' -r9`D扴L%>Be@w`pAx ^\.ATHd"K;8F_Md E=:+6c-LEZ윌![ K)+L_!ngBe@#b+i,-65fzUu}ʍRMWum׋)pv+  m4.WG'3JHvE*6 |X,Ȏ zP":~սNIpZjlA4KH fؽ/efVmqYTi2RN4%JQoW;ׂU/N+>媞QұHv6j V60u+z^$t–MOzd/_ʳMH?gYdQ :u{t{oSJ< %.EXQWt &WenwR֍ճ4hHUx{;is,,=$h}Y<`tԑ*cqx}ζznnՐH0>Sp-%6f~7xov`vl_կבGʹEDɈ 3}M Tg@׸Ս[=5`81W~<|َ$]15F"OدN\RRIY:)A}cK]cTUC[GCɗF3W%=68(.׶<\L~6z1O3OX~%u G`+X$GEyٰo羅TsE"{Ljk@cBp[Z7|]|$b/vJy?n>^=KyxĦF{fIXND-B`yKJ梒R]\ +R&)(1dEZ)-rj|J9xy@Y0|$Bzxb6 iLmzF n'cx0@ c73Q.=`2QZFoO w{0^^])`UI{1B*W-0\uwgE\j8 25l{P\܅,.cUf/HmTM.?/#F+ 9΄e7uA#I?R[۹CO%2CArՓS/C,ua{ZŌ"Q/ G%%ȗD5#} TfԻR(|ߥ}삑UsADMeśtwB;ʷQnt<7ݐ1+Nas~%r&"KgD(u݋o5')BV#}_.)9Y3ڍhLAʄ9ɚ@%y[ѯ0TpTUyqe"wH*߯t 0NPi6i}~m"phkcn LyHJ_J&vqP8ð`598iuD͎'BM`z`KL˷l<[BF~buYcqPeˡ݇vT"26-r;#w̖}®Q &錿_Hħ4ҡkDkʮvh[ϊQtH:h~kI٘w~+I(b >7 t zӉj瀂89aH>/a?ƽ3V=ѪC= ,נ-돘 Yǟ (ɋwl > G8p )Ẹʚ…du!q7mZKMK*~I8Hv H? ӝ?6 *k-$K^k0 eP_ӺOnZnVcjFM&\|B J'IiJt;G`&-(XdNwn 'P,`֘I۰'C#V jMNLY{PbEx4ɥj)Jz% @ef 9β:gpF٧Z*D!)SINx__c:D~E*N ԣ (?@Ë_OHlF14fd3\+g„^@"7>[fbFYL.=zoz迳be帲П\Dp]bF-Rn xe0a$v0`p2;'fq\c2wtް٥ l<9RI#b~s6dyj @FSt~k~PzGRopK17gEe|[D)vFAYe0 PNh?S_9!2 ܹQ oh/yǐ\QJ.;`^^dNXxanp<:肻ܑx?S# rZ0!I*2G'ʌG11F0לf0 L`;w~֛|8 ܟrYέg7OU sٙ`{"!KzCDK {!޺vHa֦ʼnGyq 5<Elʒ2'NZ⋿Vv_'0#e )Dό>$8=PCnAw|a·Cxh|]m^mnͪ0_+}}.&h^$KE/(d^Q8`O/ %CY݂0NIMXYBϚ.C/ ;!*`.,ZHZQ#9SaO3|h Y]Lx3nuS'-T8d%-Uf7griTi#r5Kay`Sf2&-/Pa-;/s#V ?gxn3&}v};{h_tc2f^ 87 &M> hjة mi.Id}j%&?1Gq|$gNJ 9 _pДc"O]񲠮91`ű.Uj".,n`}GO^ZyO/4"$y39eiywԹ[h+6x%ȏ.v9 %Mj݄}F CXB9lcư]nyn (Жjə~U.ERԏA_ix&m\)G:j8 ȥ.h;F+UbX1uȶu?/ n'~\ 9{]VLl@?8;khEPe[u`\bTRUŧ5ґ|Ej4S6ۛ@&!;V^%·Uݒݮ`ȑ%z"Px\o)U&eEvvV qL <a/xE@闲DJ!j/:thQ.fg.M獬ЬX:V{jE=y=҇[W%YCrn|‰ 8ټd< E1T&%T* FZq!E ġ_*4JݞCwXɷC7f+#:rXظݞC ѭxQA?'fXDX=ÑT0sCk})W- ER'{<@>rٝs^/]00< Vt;2 HTT26`j_Z'ʲlw sقK;nCJi3YdOQ3P+?% B)Ov͙ M~-EP\tjCG@lP݀6xZլٰӨVOpƵ6vL]Zd8:5uU^6j4D;+5'/8wl"_ B0R')dE6:ϥ|SُPFE40RI(ϫ-W;AՃА?}Y0 #Ϣ1= hMx)0菾O6%}7863Pv/RZď#8J4ΖnĦ=}֟P;S63(Mh:z9㏹SUf18GkެwZAH)ͧY鋑`!^g~RB1ΖՒ!PE{PP2sr1,#և OZ|?s8p)|$c>g0w(5|YM~](@*76_ZOLZh_,͖p'gUѣlCEL"_3eu' w˜~ AI`v܍ƳU?BW[; &]^X~XI.-I+$T<`%3K ! @8{pW,dbDIfՐ)<) NsB扃,3:38Ve—¾ʭ;S@QlR2oF 0~05sdjҚaM)<*$uZL/,OYMB_0Hk;PqFr]Ka.@ڛ#/)Mn$iECBr5Ex8M  Q5z&xFoOD?ق$&Km Y Z瞒9yZ^bXDqw(ewvZ Tru[ƕcgarLW:k+`[_C ȞAhMA\":HS[]ТS Zt`eL.Boʯp _ !2H\K{Պ4Gb%ۮV XSiGTVmC<{_YGP̜b= N>5RɅâǺ|kZ L$UTpj$h^ڐlK!("kxrۊ`lRƒ`jf, UoY=fh"qV>y󓓊\sshvC54=.w[;*i v/I;m|]ra_@d(\Uۓ]eER5 a__3otlUAU-i!5p`SșTm!eZ~YYzZ'Ҕᎌ­h P חjV^3+`0vѿ93%ö㜧wg~|{Fw9zD_ >3CC gMqdW'},*5_7 3c9fLFVi*QJ0W-m[y ]vZk C2ƅ)wQaF3W%"9cfH~߉ZQ/ ZYw3&3oƪ|%3 ب,r^ot/9l]l87ADՒ1ra OnՁhxG< =tQ/{0zM_ _qy*3/E@OPW0Y,v4bkfc َe&i XrݛnjAt]H{Z|K\D)N#Bb1 |~uǚ~)H!rp_g`X aF 7  W{5n˵8um Ɩ6Dqȟ,@(Q>.S!_~WBnl:],4 _^r&'A)`Umzق[ Y%7Hcu7M>ct#>\Yΐ ^/8SPWZO__ٵ(}:% o>Y]/^1PMFX)T/=~KAsWZ\uLq=<-{?K^ M`vRS^NqtyGV]f4?c{h`sP0?JmDvCvHn23|R,Iѧ+-M dbg@ 9y'25}VT:zܑAՂ[$!/%xQ~dH7Ixpu,,sJꜥ8 ǡ.fC%x ;qY*BC *T!ؗpP!t\d rXriJNF#72Bˋj%۞c& N5d;rK !ctBÆlpspEy--)*\e vv]9dه19R?Ꙗ@*JV΃B @kOțrePZ8 z G au>H Uς {fn)jw2^Ŋrr^g/Cl,x2q~5m_HA5J% ሧPdͶ=ۛtJ\lҴ~ِ-{KZ00 cJTT3^hۿ'`#H|(t;ZZKJNkM_bwdIBB`^qUyl˸Q AkGc #H)f\e,inY⛟.7%7dc¢WWG{]."`Lo+ h8uuJn`|S K܏rmw2R$=sݙ٭ BU5V"^* ד%z-2g9S%J09iwV}Ŕг*8 O\7ծDEs".*^L LJxT&]>/ne,RW蛶bLQ/H } )H0˸JwBƊ6*y.V]e 15o8rYU/δHj2̮l\+B*<'-@2Vip^r,/Wqg>`10%|vlc0~ۍxpPSs1n {}IнVp/":7[??,RH[">dgLآZAVtu jν]WYE4A {㥒r(/8o>)lX1_jY'dgvnھ){QN-S0 HXcfWz*W#`]O* 2hE!A<Kv,$? pP3Ÿ !}Ş_d"E}w>JLYRQ_Pt,bn>3T -T5UIRo{c ܭmƍeƫmU]NgSyb?j:}0ZI]9Zu^W%+Mܻ.3~B )+`M,Qz (˩a#+i ¥{gA{KuUH@!Ywx'OEbқ," cc)p'+ӪF]MLw3тѤ 7ƫ1L_,l{rYnc{]`42l!뵫p#4kU˙P ;RDz#xUӓ= bXW"j(->-w09m ,徕.;( %\C#S:h`@HS%͂-^n(^ `i..UOZ,& 2fGd^bv'*Z^ỿ@0\:=&[B!Fdߍe횦\n R=lqՒNɁ-1|V%g:0%0|>j9*c[Dyo|p;(dt=-Img^e {jqWNí{¹Fea:or }S1iQ>#(x~N]4^^l\t#ױWuk!Zg  nX:`-3Yx0yү:5*7S&J>4HʚnAZ0٣֐{8D擊89}获tNNdK ␎̩%A TY4q5Kb\ń5|)tۮ/i+zJY"yߓ Y#69d\C-'Y4d _zqgnAH\2䧂/;4_b4z8v`1{z,L+出{A =*KUevAP/A1Aؙz,7NA[dS}.V73pL*qя̥4+ .\>L.5oSuk5Is(Ϸ X`_#fJ/!8Va: mQ\b#/̨1/ap2P_Wް.m/Jy,(/i;w6J+]P^7w*ϱ Gm]fh;7::mC3`4*uTt"bFZ_vmS9 ]}Ǯ,qBgD$|4{!fZ~@& ;p fY0>s#/Wڏp^U*2@VsOUoњ-?@_'f G8,Z)P1Qѫ^_Z*Bَ==:mBrCj)s~ϳo*nk` U&,l'EnF6iR" GGVD1o}LV˖]oR^LԐ8#L?Tb({9i6qjPOLUWxy>md4PW}e*OSȻw?FEO m ]#( PJcd, P+ΉjƮ^{aSMhXy N@1wM{_)?72ONiO^i,gꦻLXA_='"mpfGOxO1gB^y",w9&Y_;UKYrH'@ΰ^`|eƭ?/uYxpxkPW)K0f+K߱@#h$3Z$Vphy `yXm4ݛRC p> 8t*z汛 ݂El{  màP<մ:->$&Ru7ZDHM<3io2D5 iD8q6ŘțZy{Y"4 !: 4NaΕ#B1]R> ;}Ff.vpKW48Wf usܐ3"Xۇy2)< *.d)97g)ߚ V$zu0$"=k`ʝ{1M(]85+F8wQ#K$/چŏdxwH`\ i :/J6pūDžy82s&k3z[ϛY+$ey~),\ggx =ԜȬ,\Wg%T辪σ9QZgyvZC8ʹz&%TA&]G~'|Q/t*v 1YLnU k{&a{<&pŽ ܥ6cKxBU6Z8r1]ppaN MnBjIkӃUYɝCz\=mR0.f09UwI Pu8`2u[vcJwm4,pbr \ $MȌI hy 9p)nXug1$m+vb%|j-f`h$_[ѥ0;a z`O +$ ݠQw͋}:+hIGt0F^cͶaTV"ƻhԨ`@Zl$!v"~iYq*?;;YXMULh)z^doVц_wZwhAC prœ낭O 93kLI4  mYBe gp[pM P< O_f5xcS#\s4̄4ϛRL9 c;_ &(1YX'@ߥ.z+}ќP5j*zm|H_L #P[ar~;+vrSt0vS>AcObNQozj<P=̶j]sI'XA- ;%9-/7a\DUKRWf+"Ws2tap2縐Cj`q y*-m#qӬ<VuC{JYRhJ~iqODo7A}8f݌`G80ıĒ1-?\V1$#=,prMݒ,T͔Gt`iO,^zF5&譥P%^XA\c܆=4\v ;Ζ33"8Zgۜ/ a-'<%:#eIu6jUYX 9iRRV  BNUwCqu!2en~f催AK*aPk5ّ\R!:9IӃ'H{U P/ϛ13r"6o ճUרfx%ARfE KYJ`]~{/tciK{pm &rr- OG?>#6&8_:N%|EXS}t&J"@R"M(0Qt[;ig%mGk.&eQϽe!g E0\QhWB/+x%BXXJo^QAWq< kjZAqORUG$ QSGg^(enGE  k/ċHި`ieoDΩCi *`҈GZ:5n[ 5yZK BRxFQJ%Eŝ/\H68~"Ѣߺ(8IM%aMQo &/ОDWn$y#!CTFcw`R |H̰Ą̔ע5ԉLo(gWXr0b~aTwD.sc & TyBh*՞J~+-& ZW;Q^5h @"?Num.ZÎgzofq6l"c#'6c?j^P h:jJoD-pa#VpM k rNYF\2(hOdGM`"KLJQ kyU}7:v%.5g'o}{mC E͂ rԞ۲W'ן-tUPe);]:Ly&/"vJV]6Uvx ۿX6AroҺ\69T~Q5{; | gXS.XkØս4Lzb3?C-eeҔ'jqGylc@D>冢hb[ZHd!nsFtoJWmPYwY|G&( LʿJuQӀ;,7g=PAu5ӯ9e봴pCA!9,s|>­YE8 &fC~Z<]$T-GU Ęg|  ȌngB:pJ1ZV0fLW)Dfఒ>kk:X|Zsj cmK& MoSp1ӗ?]H;7^+(+̒,!_ 3!7 Jbaئ3A@JTʱ/SBL( mm%wXWCn`s<@ΛhNw]IH٬'3mkCw.ZNQbsunmM4* 77);{ORI~bc*GCV0%6Xk ):}AMտ*ʊ&Ŷ*coC;R nBF7 I =ټ&r⌰ hHLڌ;rZ4KmbޯwT8m.XeNR8g\o^I  D`D\T9wM l 7t+nlVs=V$w ;!_,_Ei){bzF$+`F`g0hU!RFՂ5MR46j8EY*Da6⽜XEutT>-VK]vWf4;3LvX^M:]OuzT%g:陹4C߫[Ȓ sND``$B#{`{'iվ|]le\P!ZﺎB/#tʶex?86ZB*<{iv#m 3 |`~#J ^+d(VMEUa飸Mt,BfnrS@[%{aa!s5uu fT$x1#OMS`p\%HՓK<+Z~]3i]jXg~v4];B ֞A&@ej_D.҈HClEӉuwߺ hM(#> ǁ 4 )-5w1d}ou|;a~.b`E|:o <nx=#QȪ5{-:< ٝP3&e0޺䉿J !} )!C\BfI'49;hғoOfgi;O fcp[_,uziǼ\|EޔMHiI%RH7v]cIβ7jrqϼ4`<+DuKH%^, 9+ǏZ?b G.,TICtߥ~* qU!Tܸ!eݼ` Zm@(@u&Pb5 cwT b\3j[έ6|I++DmciuD'1i&u yaq%Ո+R16k B̬f,~iCE/TVp z懮!͍֔}GHJXMM͹H~CB{=e`F'{MAkqKCm3aPYНB2/햆а8~;f&ZHnY(asW,׬t j9Ntw2:7M"1%F taEVe[{KMOd[p1ʯ)ޚދagW]M}s^ţ'<ݕ ]2"b4$v=oLWl5 "aŁ-8|@B6^"wg)rzc1&msmQU:r㑝yx7hN= {028fT;ٛ0^ϸ>q-԰U?>.zKX= ".hx0x U.teEkdAJ&P82bz3OF$i+Ud|6qq]'r!S iC6ypnȢZݭnCAhyQRy+UyVfPm R3]@:rߒ=F.$*g\)R0fF7"ցYF@&0#&۝R,ҊG# yKJٳxI؊QP96Jw+7:(x oπ/:<-i~ob"`J׬ K|dzraB+)6|347| >CԚ͙fspuQ_US6?#F?oUUsOkFSK\ώulp,j8Cv0Ғk$| B޺\>SlrWe#Հ~seE ±Y< +a@dx/m([D&5n+G@DO S&aZBfp"##naOϠ V|Ӧ*Bk YfqpF @j&iFh0;f|؞H ƿ\t WqɤT%V]P}r>8 v[E0ݑHe[>`lZNzR_bg9Q%,5aS5b0 g .RU#+ȝ=l( tK ͘L-~ 6~B͂q9C>ؙEMoeanH?;jQ+*(9&JCycuqAt޵4)7|,"!r\}@Ԕ1JV9́TDbחJxjV-]أP΢j!(cf}D7Z 3"*뙔PL hZ7$&Ey$B_*I~p=4};q$< 5Ilt;`v>A!#`ܨכTș`cCSչ3u#C:GvM&hAFbA:Hx[,1c} t4i[l-¬j<]ki{2@R_- "}"mK4@쬾 ySfLT Ma5`4L&N}v:l#:y6nIA! tbR5V,Fhk)y+ksat1axBYH:"3w6+ Sa=3DM֦bws=VнHR"+x3,:RyGPe'ϝl:6H{XOk ⭧&lĩ\BJd3/ u}Ciޏ(ShuitK9Dq{ E}R0ś,wb?tb\*W;oV8[%<;dS?t7#)dF* &Sn HׄTM:y Ŭga-qya-O$?Fh&O&|4oUjcE7&(ǩV%9Rᚏ]]q;.MuRg.-qd8,CLf!3 S{tcދP~z7jQz? %5~ m쭲o&B12w¾5W>GŬ.vMxTq$`-Y&ϊv_H2NEۂ4FKA;vUC^{Y姰 .tp2G9p+RJ] 022jhnXjE[ʎkA ;%{w6.\?#g vM>E;;h5N~_>. Ԭ8()˱1:G&\*XT-CРt΍f66 q3j?4ˍw 1]_b̆}a+_$K3>H*Q'+gotiq|TwJT ?iJ,ZnM3&5xqh9 1yf6^^> lOrxd@"foE4}tY4jI:t)v> hMaLvk'0WO@"pjT/0[3_ `UTS#C/&+>e.7=d--ڗ[<It["6MO <ŞIJ@3=gpƴ2u.[r Z$kl'ZȒ/~Y@.@t!3.< xqcɅK@yE5m=Y3{ߦ43%G@#L?vtRA{;j;`ΕAV(&2R$81@CmSb6Zn\mV!.1 =|؟vNJ < xXAΌ}$3n)-, KIX[9[t}ºg-`M9&tܩh8I' j?WUfhz<|0wޅ]d ]'eNذqLѧ+)1?^R*r8  'j:RP/e1BADz[QݞD[⋶&عTh}o~ 4."nԂf=ʙVbD ~*#L"E4] Wn yݏvDdj,++ڧP*Ghnf̆¹A,-Cds냦\rBЏ}6Y:!`O떦ȐRVU`!"5>QΫ5ۏaC'uwɞu"LsbWNJ['^!,Ɔ;Vy))dV efj)}z l`=:$۰ \5AJhW^Q"6 akRX[GOa!j3EѰO`0j6Nte_pDah퀐# whZ#*4]cEdz@kxv[MNt~ yya3c܀0gbsEUB{ @%rm_׫Q>푪eIT۟;o4@(]ZU lF1پ$} Ͳ΢ņr40I=2 ]$xtuk5 {AK c(c0WWbMGU1M1i#GԣJ$})R?6$=9# oJlm/NZ/<9=]tF0NDXJ9ǡ]Eb7QǷL Z)aOxփcq!kٮrșKo~o{}A*k(FqŌâ[$}ǂ l6`R^؝J3f=p3qPrNSSɆ 0n:x}K->xewNJCjPzsMX"@"K~H[ngHf Kx;R[g]a:>$pFB8^7<6V,41hh6Ɏ LyU ځSrp<0_)>HKd(ZX~#5kbY+߯qT(JoO4$U%#5{EM"&,AjLbǡP2pJH^H̘s)\<=Rbsmf-s#v_|sЈC)]"H' }Igc4#WSs\`=m3f@?߰0}jL^6ϔ[s} m>fN`o!.ZȪeKם=]1U$5-gN9%'n<7gd#RSI!ľ ;MG*mrJ0C.&ouNqt6LۏSosOH b 񑈼ٲ4T<3k]tෘI);֞_7jztއ8[CHKؖ0&>"$xM44*Ddh5jP:ڦ$g\&hYRmZUj7{2dfy;oM |I#D4g6Ys^@Ȼr䑟2ypn+u1*t){5٤-od)P /=Nl 2~)1a[ "I:H{vbݠH} ExCn 0VaVZ̆eM&&o,|?BxK.SD=( dlVz^Kxb.5~nn&c6Ha)B.hˈ޶݂m2e6! l g% 5o@g(Syoa?Gr YIľoUօH%D۠V7%oMVGr@zԊO E GY $ XrF.d}^# V dc7bbbAg*@ky!q`ˮiY+ExgVHÍ:=Giz('~x/7U '#ŗ<ӈS57xL jrX>sI\<$~p|Т MpvtJut|Ԋi:hLLw8:{,t n [Nm\(U1G? ꐵi~6{b~]ׁh3+&[xsR颸[ {٫@M7k?ya2;fF\8YȻv=ЪaS3*?+i^8KB,,qzt!*sNc~uZ=-yRaj e" ^au*>-͈άz$3W`N^ +ܡ9[^%d n4{J˴ G3_^1Ϧ;R8M.EN?{HL@@\x` t # Hɰb)LQL|,+aA9Rf!tp%F a'1cEZ0 pAT$Q^19{ȱC06:'!nC5SsATF>5Q$ 1?h{Q ?<ӁgzjXPVly6 `xe*5Dz0vwcm fT^-<tKҐ8 9>øV]-J#y5T-ux6WzX#CnW@Ah/A6U0#|=!MC6.]WCo4IY9&ft[wi'>%DUT&^" I1mSfO7" 4i殎[$C !|P++GHjLVWq+|E͉`пV<(#X?o" T.m ɴbZGEr)pF+ _XTגu%TSЖb])aV{vc6썄LLA'/ף@C-u3"M?QUO-]uAYfwA8Lirytd:% -C x= 46;CJC%\Iu:7`P\JACl>O $f  "֝@ݵmkM;~4^BF2P 5-kA3\-l"pI.[z@q%A7{ Z+Fw9 =OgN]LKD,@Gmr?R^*PO OoO iuTy(ٗ`3O>ĹEn!|*8ÔIio(QygO3nd'Bk_bD1Z=˟^7[JA$h~N,t~}vƎCeDZ> j-ѫ9FM{F&{B~4hwkO_r":=CX\b3@PT-R_)ca8,oE8ON6#V_+⍒7x{/4Df)syda&z#b0&,";K%U]pM;A5[UJ "rؚp(6#VUy u&[(ݙ2Sy2EA)ǍA4Eɏmr?釒X: j_BQqʼn$^?3g !nm3b|ϓx@[nGeS#<SQ υ$*I@LU7k`6>¿"};T~V^ @O3;;JayH˧j^qYUoZAS*,=o7\wj}TYm8{}=~(6 "^` B^x5Yic0Xׯ.x5o%VkS~2VeuyN:R"d4S0F4"zUç9㖶LEV ↟ǻw?Qmh䋅1)νa8PXJH‹9Q~0ef,2[OFR8%q9%#pu@ғ67V*h Cm[#׊m*/,# ޢCi#+UH 0XD7Npҩ eZ3&PꚌ!<]׳CP [ ;tOnUH,i; V]Zclh֐ZCruvVz *}mnA UB{\>1"ErR{汾SMy'$+'(UB]jADQ8Ct2sHi|$#ySHܐVgc8 HX/F akPx^`s&D|L?(0sD>vliɲ~k ω;4WN)Eۏ9:7C^e;دL̞ >eS6Z[M)'8g>E@+[=~k7\NCL.[l^4H_ (8TK[7)!1ڣX|(f)9(L$I0Bb-5s+tF2ز Cf2R ({/ۼS?a85yejެ*ns'I-߈SWu)aV}* Lb]#{]g!gM5z}bx$t2<=~Oy !0kUK C>oP60T&:55€yѫXJ pK.;}[S:9ׇx5]^ctCPbO:Y1CKѸyJ{Xk' *B͚osx3,*;]@WFbD0hp!TwӣdS6pׅ -gv im :_o"itc&aQ[ VwGyGӭlQ?c"%4heScP c`gHfjh諕@>)ȇ_]r+@L ? ~V;}xg,0Z%h*؈IpD ZO:C 8;5V?jFƓڊm $^bjfx؇UyE@eg)CVm-/e#DEQoX?!O\jY"_& '6~@'5ua6&#kvzGT:óx8 pg7J)Uv Aa.Cw >uE5*rh+8@ /Qӂss[6ZMN?\iVe6 yM*G?ezmКRj)sĔ_*s =R'iQ8s aSBvFluBz#4.wb}WD!Ik;5iwTZ[`i\GE?PxDSA>-b/NIvÝJ{7|,IWW"1?6(R{踖?oi,=^?wXY;Puϒ;=˘eВ2 osmgz, X%|BKA,~5NffGXD *C|$dN'taBdo٪ z(]N3na`#BC]w*!73 V 5'⵳~4B8>F㞑䏴~]WǸzHY3-[0k{g֖9LXC`VLH*͢CBKeY_"Cgrrdl/9V;Sv $  θmZghwP' Ɣ7"oPQ 3*MUWkH+B6]lp1ߞԖ (JX,y2c &v%qZFݣn1!' Igw!vk퍡ƹ=־\аN< М6Ͱ1)]BT_ԉA] 5"~ful/+M}hf%;g}u6|6k,YCك͎۽CNr4<3ͫJ3 t}{IGXvw;C1/#G]i^-UA+(\5(@d.V,:2/?es?տ,71QYRQ$c}tf "1 MPc4(KL<߷akYHE쪝gғN#pNA`K^TOr5BH!]BMeVO1MTf,VR<ZXٶeY}Wy?/ ~b\CUw=ϹP=ez;TzӋQ`Y+3yB?VVez;73;hBtODD/Kѯ<ͷސM#$vAMΕE3 L[i'eYv܃!' 陘IP 0TԳ2s<}4LH;νj?cEzۢ-KXU\Gwni6T3q+DqyOoY$; >CÊõ5 v8Q髞޺̀ƊKaK:o|: *sG3iЌ)Ov9C2-q:=޸Sqp4Vb2[IyK-Ou$SD Uj¶Mk Ҽ%NǗI1+6|Rڊb%T|=O+cIu)Z{QEp8q33#{A:}-6ǎMx+J¨َp@[E8GM--؈jTld)%,^`U@C gS,DrW M stw4X"1IBLUC jkb0c#`J2Q~j1.lj/lϻ7MaA>QܝC q]fb[Ke #eA=cL3oGw"oJ\1v߬e/ђ˽0A}H{[ηRHZQq՞ ; /%^D!IEKMPQb ^SPDGcؙeq(п :UiԾ{LrLjDWUFbв/P bZ顥U6<P Gm<#\Yv7M4"\ W烐tL6*䔛;sZHBl+Bswh2vbeo;`Ȋ3i@+%H٥16Xn 4;j6^M"m7`hRws&|W  ik<`Q!A|lt)ɗk !7?Ս e=%._Y k (|C' ǃCjoeMo{dYV_Z M#fBpl@gڷXu$%W)ufMfh#c*5DkDM?ꨴYtД>t:P6ʅ:_K"K!|+?QӆwrDn{DB(Gs+bd c A##!-˥ jJ>k $ Ѱ\Y>XUz 2 eV5tXs\haP< f5I[NM#PhF+0Ɓ9*+Ŭ.nKu|gYrz>8fɷ?,Ζ zͩ]; r *+m?(Yձ L*֯hP,DA_<"᎓glcd%od?V׿/'>ueRՕ2i3D ZB.z]fѬY[E1:29R=aVy/$-梪PpURGѭD#*C |mM{gҪ:`wOwߝM?p7zp"d\g3ox*lJN'I[d ;˙\]Gi**O29v G@r;Ӡ *LN'xoEJi?Q0-rgBpU!tmxDcNAfI3v~ڢL\*X@c)Ŷvx# l쎓P,v9W.^SGZw>Uz)m/Ib*>QDcR(J9 &]^C`*p 򁊼PM̨@z]t6ʒ@t7)[TPeXh@7Carz篁_FhY/Z `OmqXlJ;TR5;PzFig'626ɱxK,hyBksJ5Gh_B><"(;+}A^B8Cva no6<Z*Ujx<br\F @ <2sI!/&4b:Dk{K8ygNՊrq&q+"Kr!aUYzf)y;W4B̳)Dm:xLBJ<]:JGik `I%o>ɋYhSN͌yyB{| v]`3;] کeŎDjPdrr*RD x۾Hl( =uU)cD 8,ڄ>}pc.F%[0}7U`okھ# K絹MZ :2aVaV,Q溲yuH20˧)x)H>+kXq<.qcn)*Z‹1t Ɗ—[d5z!Cjqʪ>5wS<9/bsFq S(a Npj #0&:)h+&tJ&[K=J7I L" *uζ#z)8RƿT4.27}t}ƾ o(Oh *ejȪ ó=oVP篙 R]W[4B,kh_:ǚ`3yJ rvx^!W^NQLw5y vsbnF[6&nu')zEתq8т@YSlīt D%^Wy-n,7(b!N#VU|jI(vgKAe̓^ir).ȳJ^7ŀi,(DعRc,/M|@z%qd5yDEYT; ,Uahg6Uw:noe;BbjZ,=W:b+WGz(0[nH{xWY/|Ys.^g}j@^t|Q}:l^3I[J2 [ 7#!+9p)n4L]B-@ƅ y{ JX0U ̋S初̃]8?zm8jsPRXʹ5 "{WR_x&-5?Kf?7VAqXydV˺>GT5@a!ZKik׻.agO o||XIcr {l 2{"Ah3MZ6XaƱjd0_Юo-%e\lcm0\P\I ycnGQKo.O$_٩%0'L?,9d\ShhȪe)x  D9lŇBls@ ng{UѹԺkV#hh3 N7 {n Q=gLGU\&H3ȁ1B" cyL;\LANM {+[ͱM+R޼ZO QygvFK Ŵf%_Εy?g( ?Bs"E-wrh9’ھ*ڌvwن{%K\?n|u lQӜa"2isѠڴXAėYŇCO?>iڻJS(H!.2vI B[*|[0 >djiW{eh(@R{Ȯ*d͗y{'q:SddPi'a:w{W:5^,~-jB׺.ȅŎKHLb0Rכ͕"hO~1 ^{]nPO9\loq87Cr],jdž{kEV7{AԚHyb2t 50 }UCs!/6:Ƚ=&?j$C]k:6'ޱr(_Dt\S xVAع*^3dȮ-15WչϱV\6jeL.݉f9~wIZ+fLgq0v٦ ޅrK!`Bф02JGk(XOӄ'(h0U-gS(M"4(/=(_*zظ0liMmS[ߣ-Z4"TdsZܤ_6bw:4{FfqNmcSc$!@]aMQ,K 5Q}hаzdx@Ġg[8my"tgka %pAQ4`}7o^\>wiDQM.RJbwi:BSr˸=$8f&jķ6jebWvkFڹʇԫ':ħ_(ŧuSKlgF9#!FXmK[][*G؞3+=Q<͘AqbMLDXD9Lr|%svlNg[O'TNֻ2 BygMRsO>858Sr@w"@̀wN1AϠIC C׮PRr 9*JྺOFE /ƪayObRwXSR #FO$sSu+ÈNƛ$FÐBd} X :돿EEcQvͲ3Ӭ4A t't; qUݜf!sv-BMBO8C[OQ0X? E-t}ϴQ^-d{[vT 6.yv#^ ϋMd$;!'%YGM"IolNXCAcE:bJ_S MΝt+/̕b/9HWZ@kw,$4'A`D-?/A|$t(Z7ڀDpΖ;\^40}K=Qg;w"Q۔P4=}vxJ6-MWw$klSI<[yK҆.4=mfnZz6۔&RְQXY"Q 0> M zM6WZzݥauD*}M,P %\B^ҵQHg-ci(YRZ(~v|dP=Z< CSˏT]0#c&1MX' ˎZgGd4A>>'GRYsȈeA eg =,/L½w.R)›uqUEP_[.YpbjN0a2:_Kń37c /0w12EaB щ\iF5c{4A1bV^*J PD:1ۉT(s ɞS_hX!f;d\b+M*6+4t5;o7FYd@"":\f9(*͒5ْMKe@#j?4Iۃ|J>a !>N'Hf":ٛP1N# \ [ `w H ECy 1N[7)˯ -~b*Fbr* 8tyȵ٘73RHEj.$hWC-"<ӱoEYLvU~ T/殢iIf#\C]'_Oi:@k$<<`tU0WQF„'So*]U%PU{k&7Fm] ΋3",jצyj\]r/+{"F܂.km{y,"NPʨS/PFI Pmyv;LܟBY?'6ֆ+xM QO74cRG|޵"!' 8ءT2™)Ƨ;Tt9АL $;iKit2%)ݴxnqoPנ 4&Mh|նJ 4~(9J)SPl%-Ǥ؏tTd̈́] [Y*?Wk1;:~ѹX@y⡽ f3&Xd.+ƽjTZjt5rb>yPp gZB'O,@4C?S'+KEHSZݹ(pphg K*G/pLLg}ಯ3o9maXTVμIf"$Am)8?߬V[]:Cn4]D11oH? &yⰶ(nRӞ #vk4MS`S:d2'r+ N 2t4ᯛc"c[i+ ̐aZfzj"2R %?̥20\:o@#}/3@c1܋_MPܯAdXvR!62 օYKNYf/J| zY,W6ʎ-Hܟ5y D'4)Q垃5w5ڲB5;|_t?Y-sWɭ zfRYe˰9E>1&rjHɠN;7@B퀒 -=M2RO?`97tn﬙ե%"3x\y k8wYFh-lw_FHdC> Y@eaGz4̨y}{rDڃ&}%y lyX+o]nSn]~VZхzb"$*?0_>Xe3V@ja (Qm:̓Pnȇl>? 5%DX_fWnS3vNr βSf ѤmJ FB| 2}]gmP6;:+K^hmZ0Gmrf!p&ց?i:cvYȣ/0pB@_Hv6gd9b6Xӫ^4WZbBayj6< Z;,hG6乁QkЂR1E0\ӎ1g"} Xn;`XB:1'Ndϡc#E7b1:L13pJ콵vڎ\B AZ%H@^vS~Nlg(sُ_f}oəyD'fBYnM-Aŋ4~ٯrO.I2ARdU?JzA}AAĭ> o'iZˉ"qD?eS_裫.$3*PjY.#@Yc{+yXOC9EONF*4&^ f5r?SvS'| ]b73iٯ3g3ΨUg?J#:G|Eg忲owbVI_j shRHߏ;|0']''ͳ}am45OCN;,(<%wO<?#7R,HScN?ճK/b7ZiI {k,D㟦= ;~uPB=JmMTϐ-~hWJ(W_AԱo9~D^Q/^2[]$l鸣B\Pt]Ar:Bf"ßϿ<MU @"AK}LX(]\YueuƃR S>n,[Cg[K)GPt_؁Ad)%y`@zE;Fa{ sJTw> AƇi~\7K<);\t 2_ E#T@z})(%;v`d>n!WZkIo%+jvtIʽPޮ1 +QiT yWICZ U9O4`g-{+p`!2Ǣ.,sSmՍ4N1frrTv/V0G41f(>g*Ց/6rZqz"]r7nWШNT4eY-.~p ƢVxĢKAD#AG#jpLR22O{ӇW2_'=*C }~6.+D5JV⯒v pjm?S0B8LCuPHp` !5SBPnFd4_Hݏ8V)vƽi%AEֱSm(/,f4Bn h= 70W^b$BgX$4einU~u\ (iuw "ͻBB;*J,%Z`D6'W՗yB"B[a| 緜ӛЏss8@/+#EOpMGgU4(Y]0@@D+"WRֳ.tZޞ2n{;}&H%b)8Utu,\-1=p768'aRwmhäKRc Q AK3Մ*Ek̿Iy**do|Z,OHsbTqO,*EpJ UN+#6mXses:;ܹqm-Z"77c,_{Iݫ`zr>rKoRlߥBvrN.JHl%Y"y!oz|~œ أ*37)ӟk xO!{@箎p&C;3܀5'V2vP\%~(.>a;q($ GtoP?0ӀtrgVB;H5gsQ7kNpуNTxpP^gGcN ('n.QnvB2b|.0vrk$cb}aG;TsPCi *#^NQFR|$BR2_~~欉$[͌uG*D&$* v.ÝE.M\L97}oSNA|`=Sb# ;>3l^Ձ^"^!yYtmvl}V:5,.tIZ6Tk] hmFZ|ޮcIF*&So@[r?и(0wNglt?f)ѭd}3}Lƨf ] O%|GppUNqW˦ɉw۝XDGδgѭlM3 C'!ȰpAe!oS&Z]NCcsBg-f30]w_p1PxE õv^+8=q>'Va:?vőH_-l+53@QƼ0|{J9zHBƛveX7>"!wxP1lTƵI:q]鱻?O &f%~›֎ϝ.-Sp`*am@˲*\t؅=; J@%d@Z ]ο;&O<'[tp 嵟XO7/GuO(sB^yy Tȃ `MA)Ee8 `{5?2=ra-΃mϊȇ՛ U -3]O &.봺SAj㈐,\$ ̩RE43MXrC n]ĤRa#FV9l"7XssPaVV.D8qN(ټjD| I8߻㊉jWb0=sf]_\Awp/Ri1Tnw ',dApVƼ#[vIn.)",B.־E#«^Kz gѬ1\kYd8Qe9i-Xpq?{PxTvP0$CGb" K}E|rVXЊ:-:h2%8m*Y8ZHZ*u?3m:5a{TLfRk%6%}J_f 9-,4TJB`< 14'iC[2n@yi&NxU4jv ٟmn+jRn|o!iG0p=ga4#(8'!Ŀn!E݌DP&i',8yxuedg.sGɥO8|}>ɛ͹jd0 wkww5!zL 5JuUwO[. |)iM|IY5ߢKErVk+:jviI}zv$T'vEV0G=lS>x?i# ܗb9/_%; *wTX?iTT^U3m+QZi7r?^+sgmߒ@9FJ}/p56FvX>*FIdd9k-tWT3Atx[5dPCSeWBVA/;fDC%]>ǃ@TD%]ěWݴȘ 4̦D}0V1/4APZFL%jFw$r{A#0&{\ $rVnw@.Cm>ŎrްxtI65|Kx2*=8]6YdYI8aҒRCPNq7+bQ>.ZHs_Z7FoQ?%SYzI"3ϙQL &6~ʶfB, +} ;]&e/f^Jx\Sa #  ra*S7e_JQѝ6MZyYf!\0L`ʫͺ!]) _}/:+./X\ 0RgIV.Ct̤Kvsi@z]R6*2QWGxf -bB/W';J_%#Ћ]<5p7#yjc+~Uxc- [ 86Wiz\uS()9Lh5|Frld؍RHfXg֓U{$e W \B O|'t? 0E:A6xˡc\% Uo7'Eұ*r3jbNveM`/b]wCdyf?Ou( 0iX~qNfbI` 3^x$e6p4v%QofлQ~)<c5[w(Rt䀹H` ^Då{| 5#̊=%/BK3ؐT"l;#ẃB3E:#d;_qot|!or'ըZ džRBY%cU]'N||t !'f(%>9nE8 QCR5Ϲ-:~~z%Q5;FОW[֣h YCY0kq@kh4.zNTgo]&LfBA6.nli:+0gcWl۶oZ ڬ́ko2&=[Y~!zP$ %d6[g5j`pluS)~wn_ 8]sVa/߮yH MC@XҚ%9Xh`'7a$c%C>M~ȤO7Ǯܰy-вeשHhneܚP$vztU\c)z 5;FAM>]"Ymz^6k0 Ж^*aR۫\4ɜlfʤ>Ցe.?:`/{).8T.p/n"0r.nൎc+z )1\!\q tɉ:6@D_V!-JG(,[ź@3/U6Oʺ!U !- P~xJj1Xx}P%(4:L 5W5 ncs$*A=]\1e/MC";,.}Ly{O[XD*β0B cB H9A.v5#Lр:M' A]Z&5k.i"CIT~C&:컛=tw`hSͪ¢'Vbꇛ*Sߖi Q{-܈@P|T+uIu,ﺈSZ ;"jX:9Rbo^+%36Dy)ޘGaA̋@y2$~G=vܛ!`_TF}Qjv<%ζ_Z2һ;fg_ iɏJ4M7y.5I߿L|iwU}P8TMo!kltuEK6ǭo3S-Z8L5`<䀨i]ڸC.0aXE fioH&fovnPhFvٜx?W<œL>$:!w"vtv7.4#PTs5.ubډA4Ƌ4!޻ƅ 7Pp%XkG@K3^̆e[ϥ@ufk)o1cC2ohYp{M`Cެ&J?7uY7­|ƗGCZQǮSG^L;R [n2SewdN&l{-5%1*!SףLqwm^ӴS}j 9G0Pm&_Gr ¡'>n*jkb"G\E h\؅V"h8@ۇ (@RѵP +c.^}BD"#iJy Rݤ$ڜ2佛T7  iKdqBQJ\IKH"؈bхÐ56ݏ^.֭{,# 7fR\O ǯōd:01tYH8&SYG_,>a@g .tdSR4a ?\{hf =[D̈ U}UÞgQ/:Xl*hnJ ۇʑI;@aGJBQTZ=IĀ(+\8K'&b^.zD[\v#iJEv^?q#EyNlt!HK$dY-Hƒv%fuib h QLWz9p^z|nUq 萠u0P5:w[ - !KKөģ Wh=}nQͻ2: ]_=J /em8Zl6."\sU 7z6*Bnr4go\aó*jeƽULrNc5 'C;m7)]p)ꃔEȥ͎ Xq]B]«%9p0٬dЪ'0=P ȃO]Bc|$CwoŤ_m C\Lt+;GX,'f|n.Z@aVyȱ"Ғ{njFitFBSmv`d  bmVN$PFNi9+T(gEAD"Kۏi*ќ;GLW '+|ί@O:0o `~4p|׀[ BfQwG ]z$cKX-ZH.O"!ߞҐ]6!%;V `}rCGWIf7$j:MN*'>vPA΍^Ew7jͼSqld&Թhͻ 4-'(*NT5c%TD>=G2q[ƞ7dq8 NM?/?нxIi5lM ao-4\nw\~">ka$nHYanȾ 03V S@onB|m'A?e'H\nF`z)#>'h4k6/.2V!0;&2k+_SӫDqMBg'&5$ K迭T\n!\+ήThcIhY\t˲`$.1xg,-+2Fm]-t&eNI'h^Rv<i]bA .k4o[frp AFD#_qcgS?𭡜s,ܭij4ffaK:[2m<6˘EtqBC5ag-ZJWb}C}~}f,,WKm|UaJºEihb %R69+ |i#Eɲ&AvZ!&f,C!W>_Y`/B$h-N`S1^F"ǭ|g]te-y!iB4h)sI=Vk4]S@p͑5ّ$i0ٍLf\#xZ\O6T01B"Y i?mހ-^5E0Y0I'6pY8ǠWw{dOBfbI^$v|(eVc%TDum{Lɒr%:35F:٢v卹w(oGz]30V]ˎIzLC?̜t5Zƀ-{JBPNcpUJI# W3,-S\MI\dh Uj K[sPf]0Oş&սBB74|zUSmCAN5^KV8UECk f)k$ D~$mKnl -T4ǬFo5Lu36x%!4|Iy~}#H3LB&aīe .{_јV=\{o_fj _HȪTs}]E dS+m|Q1B << bpD| L˒@lE  E3c-wWR+j~z r2 6-v !"O?T=OA'&|hF֫a6m[pZA*zi6U/ Av.EʼnhHn0l5n瘁xhAp6i[Iiu ()GZU&8ہP0l\5iZ)I]ZJG,iX-VQ~7\)ܲX,RJD!uK=_tBIc'1tLCm/k6d]YQ$T+|{RSπu/ifpa 4/cW^ߢ R)5=!dqȔt:oa`|*ݒ0:;5hB^zn1?enE<)GW=Hq07Qn!3_ka{20ƓKW_3":|Ck d" E~;9WQų">r[0$/C>L  ke6X;V eB7 Q$"I1 $q0 Z+MDz4#vIvu$1-8?ȉA1 2bHJ1 8eoPmQb򟲹*#)kf'0egu$* 4"ǵΗfW`n?;:V>Sq+X>$3eGNM"}@3FjW,m?fhDh ,C2m,NFHfg< Jυ5Db94myʦ{wxT Č5geBp=KGDcL7˗̽8m+6 Rw K% IeVS P+R"X>K1HocZtuMJdY|C[TPX5= CN{- J A-So#$]Y.Vfm Ǐ"\~P\مRRseD{IA+َKrvs[_Ĺ5Mqߐʃ[Q6Zn9)=wE˝jGA- {GvKmeEj`5o"^[;}!F]QלӶrY,.Çׂ^r,v4&?6෗E̚R^&e$e;i8ú+tǬk*=μ}9:'e)?x*E.ߴV#" ݭF$ {l8;R}+#3T(#tS ;7rA{[& [Lda2}cTr xZRtg@bcd ^~hε;2nٖ 9_F*'7\~-5-i`wnvP6Ÿj\Kzov>oRL[ƩT0ȈlDvфSavtdҳd 4˝eGlOJ~]wǰk'[D9”YvY˞Wpfsqs gC@pBxD] <P1Ӷm (c m+Q{7v4Og'> !;Z= Vq HA͉i3mC' TuzB-U³1׀A32ЅX`ow0bZbw~3 ,ŠNo%>視QJʝQAb\L;Yr[6Ux볔՜=(ْKz PS3$M!WPgx㨛4\&ً^:}污ϥܗcAE):Jd{bok! #OOb%[Q"!>Wjl$aYJDQyf҈o {b^br: 1-;r)6 4'pVO6&qIMǕ:06J\-JhU.f83jBFd΄}ܜZW1Qih i8y눝*9Lo3/$T0_8f),$P2iƺʛwORd ^T,4 wfJ@RjCQ}l2~۞I'wШE+gOƲai{e4!Cus1a6ֆ#r9 i=o7^:q瘿RYlN"ɱ*dO,K曟b9c.ëEd,!0CiY XY[3 SVpy.0ܺf W?hS9Ol5mWf`]w9_dOc+9,9濼O?ɵ>1k1??ܞ:.4GV0?2ۊd1jJP ``YWhï[ gh\MJAg&> +;6:==ˆj&pThIb tMANwwA糑݂,EvHS$7B\Y1/vYm1-ɟ5_[␏N6ڜWXeȡ"4O|r0!)ܡLGQD !x>Bg10S'e33#=Phv~jp BdMt%r{A?s@]E䞕>N7A\MC qOsGNe˳e1#uu1J.ԡ8JKi:7r_RYH)ڒ FaZL]zB:A[9|,?Ư V*զVɌ,)zRbV'U6RbĪd|kwyASfd]b'B]z"`=A`]Opdkh+9._zj=C/\`cWMe= cz?I؅ڔ9^2p>͉ͦm=W `7fP{?W$i7Q%vC-DZ4?| ;.WFIi :'I@1oU "U@ s*$b8)p%t; KJmmUllDv!- s.CU;Of ]%q/\ky {^1BƩ3_xDfϑr5 B"iŃIrAA4%0x>}ɇVd5k7ϕ „缟{*$Cª#aEj_+*K%7'OPP856lB K(icՑӭ Yf>_kH5)-*Y$TSI "smnry_wwE9qϕ 5_Ϭwa_ry 2,x]Gq usfnHnߏ38*S]PZpk2r&EGAXdX;qtDnhu6J*ʩoBI$mdb(IQK ߢŅ\ྨRKx!ioB0hvMpR)VGL@aS j/4Ķs"p/PÎ%H5̚u|V@wՂM߽Yq8>!OP[[1tغ.y ;*'/0]//%]9_R!qا[C^75e ;g<eOҙ~;+ؕ>eu__oI8jⁿ3I'n@ iëZu&o/t?H-5)bjw~! @h$A%N9'(GHr;(WuVw3^&4`hFַWf$^izG:Ă JZW6LЃ E/Ѧןyirjc{֚kٓXmFb>LedW /= u~ϨwЯv4N]i[/#YSx_5M'iSa{m~mT=;Q;~ڼ׀MN,2Té'RʕbQ $_}kuy ._Z: T2ry$1G&"d$@5YhFfpG;6% "O&ICFMXAT ۷*$fWk279`dK*v&Dug^< E@%#Y7Et{A¸ЄҔsW$Dxۈ78-Ą%\ ?wCʘ΅ɤG_'`:"tk>QGMQ:QFC%P9%ΖkhNń-_&6A&>QL{B%4*U_e.YcKˡ6#O<恡EkXCUn!N4j$b|glG!9dKje6d. P*!Me %\]?rKpJ,cVqj]j^*&xb?xaq%R\k98JƘo߾| 3PS~Y"Ս7 RK"]S,|7) 6#^*pc8H۷C5)0r=Y@ƼZLѾ]0sU`9v, ͦub*%tKyn;:wq?K> [.:HfLLrҥKKĪ3XGQ|3HƍkWߠbzWyKVSGUo ~'_o Kd\`1Eu2HAť(+V&Pgj #[l޷)auB Vm?vX. MG." Eh6QniBzNwǕɎ5 AcLdH?jfgפ#ilpgf5H՚M\RwvG[~Rי(wb~U7U? os~e'@?/ fMTTN=$ tYQOʳЇ095,*BR ;#l<(R؟J:" GPTSwp [hvoC7:+{0+I A2E\ϟ3״lЧ=88Hn圬G$ `!NW~p⣹wfS֖yѝd Lg!{ǀioEglTq>)5ExMٮ==OY@CO)ڍB0T0=Z~XIYGU-;S$V+",oC`*Gz_c ZO" "6$>'m|s&fNL"r*<,&ږycr}*oS?aQ5q@_+$-KⰂA}ոߟ#Sh:۝&\?97LoTTe> "Y҄J°,8C(,GNį dt=;Dj?7R@}3D&I:Ĥ_3<0_ 5j!Y,F=}1ٮfl4U[G/ؕaP6I_ɥ08:Տq|"˃)@EUX#AuVV`nBb6ŖhrךI`7v^^Fx1s=Rm6$72ݞȏ#+t X5_7BqxJ7ߜ8!ٳ VOZ/d` A$ F=6 t8ż/N=aJ=z*Ej97?:dt`66՝軬lƻl<(%'_d}21Q3KK'f$y0R(Ne yѺ6C;5U0 l\P&Fd{VOFߧp0Uo^xZ?*E+4]u{_GtA>ƙC (.kŢCj( Iv ]3==F0 yfKnZ6¡Yd?˙QUva6_aWB"41κeA26<OL&-:1B?-΢=GX*&b`߳ƯB۳z:QۺYD6OP}ߝmztxWg'L"MWُDž뼑]/.eio-P7/钳Tz_T\Ьet<&r/Ɉ2"[:̋lO(2$Y.`$UdN[ih.(W Ovi \{g6*,4*wTa3,!qj8 4/PvoRы~9.ZUH7qJ!t":p?>`Rnxז PrK<7 vt9gepECKY2M'Ƭ sj7 r癳X2Z-U(M{wNno5m>?B@`/U晒&Zpr 893kF/ K2 ~qUp?:E*#v{D4!ՊrXyN&XD*uC "+zD1T֮XIl94Ә}Fٻ+s[N5fᡩpuɅJ[ B!"X`+-|b,4h8(З%eb 1VB,{0wO ʖjcXhW!}v%+5S0,B=GWk{eXo ]<ڡw{mj" CCجV0]nJS\~<;Ir~Wע=g'M;ӼA\T:?ɫn{|(^ݤuH1LPB5ccR1  [ʦ1RjBEo)iy8S0Pf\8̗P\eR8"i#M!>\/ W`@`fAW%`)| ՛$ۘ W1eJ iαm[R!Er3@w" V{6 {8& b6c=pg 3Wy4 `&6{Gpf.۝N& 1g؊9ZOe*qDK`ab . e&bL^_6DhrtB H9c-y΋#`ܳ)Kp߳_l5ʨT _[kȸXFIT-WfΪc5mOa,¢SᖍLՕ'UbK$S  -<1RWoL; `\lbRZ9J!O&4iuQHH&N$#GXpLY#4bթB]a5 N#]hQ 7 1NQ 14t8d<| 䤫=zҿ{%;>t:OM9 PlXZd:mK8{2f*V m'WX14=R QMFmwŽt[$Vס8wS!@(q;1׺Q'T`nLB;H#0["EG J.{Wew9 HCOn+`*v~z79ElZ+#n$lvjb]/!"fyB(p$/ChMfN^$moL>+f7ۑSbm9ŕ<Hoʍd 5g7F,- qp=܍ەLA˝q1EW{sfѵeQ#@CPq',SI6rJfbC{ѥZimySIw9nS٥6`ΠQ#%7w{I7U>s0;{p0P6miWpsA_V0=VOV6nl[3]T 6{A)WfeƸ%Gr6Ba=ڻ?t#aƂy-?n] o;Fe) jʫ3R;)o>)˛u81/g"`}'\JqN6}OujVPmulOxn[WސrDKƷNC%%jNNo^@jE'h1^\ׇ:9mYy}Tz#*BؠТKr"jJ*Y*_l#Lw7ԩCU[`l}% o[Y1ݏ.Upr]h~uU59YH3a EҷsޗNf{1E{}$eKoǀ5$:OeQ\"dR5n \7"Jܼ;?OC顭=Bq)wjw`N̳qT/QOtFv0T#y kp)W$HGyT nZT+ kTAjv)~̕/:7}bh X߻73>9 Ŵjw1w4,Z^.Ѐ#!Bb+Pz5xZw&h9FiYջ_04 R퐷[d^Sɡ}Oc\Fķx8ӆYdTp%'A+x&u CjF{ʥ4+hx`r5 \3Lx/E/pu{D 卿^ %ʏt"VȂdsArᙿ%H2&q`B%J7UB9 +a 3fۭm3i,r"1ݺAw9v 0SC/މ ѣFdP"f&Szڣ@(ԘHk ٝi*/UBr$*MkmN36CEHi(V2]x'Ф\C>f p[? W04={-2އuw\X!qEWeOmc DK7 ShRw꓆2G-~*;U)C{B#)$S/{q̒QAaDFG%c;5dzNpfMe{Jk )oz92[?@,55 (fjEmsn]BVjo{SBfF.ʻaS5W.;k`CDܠ :p\^Qg< E艢d}BJaFj0Cb5uH?ⲕyk㚩Xr{mlպիJ=H s h܌߬P''~QۯCc\ ,~Bwbq`Hڔ-L)G[ [ cZg}f,}AY=V"D`4 f-;OC3r>D_Օ7,d6k 7ow4OXʀFJ>u|ޑegŧ}$^݅%ܔwe?ꂅv+GGQgL zG_:,+[r&hi4JIj3kd/S[ |EoYP&'?)E}p_jtnQ?pE ]9Ӛc9 P, LVJR[ÿ SšPÓ@5H]`ʪX߶;z(!uyR_P2t*w<6^KH\X=tKHˌ `3/ݦ;PWđFL9/4-sLm FFo [Es|KB#gXO 4"鑚_J&]okLug󥣆))6ӶK(TLAIAB]>P 9޸8lp ˔(AF1^'Q'~ -T.K0ҽXEEh-}Cܟ#{4=hc[*@d>Yz}O\IWLoSRnQV ͌CDM0б׻wiT\kCSGC8TKr9GF"nz5|J I/ $s^نѝ>Շ#NcI%|Wka+m%.&}\ J"~qh8*a]^jS)4Z*?1tuќBSVFU`^|4~`[-c@l1"FENg˔Vh314|bV94iib>Wx C:mڔͿo\LV}?|)(Cw{։njXpۋ9%R]vyCȵ|*"/DY[ul}X4Q#8l;}r$]uCI#'{Puɂ+ۇ "5ecj *ק$9Ӳ%ܟ}Lu37rFM7k\Mܦ^ٗ׍~6Q/xBe20!i'"[w>JHo"IWR;ch{ɱ8O&UŚ*D{t"ˣ(*g?Ouďܿgi ~k!P*r|G륗+˿8X"v:TRk62H܂HC?-+/l7g,yħ=zf{O Y 1~`N]F i-c^+' "DM& 3];pk&Y.{9&|rxM;wfja$ÑK{J+fG\3O{~P+6mu0M>k7 8|dߚoB5y[Rs⠂b,P֔dj3yw&fnzgd+u'{Νc7к_3{sfld'=/Nb8!#fZ{9'6AB3hP3aj=W6oE%x̵˂7x"(YB6"$+ܷp$mq&чjPxJamǂ]35+(?bϢ|QvdT#c&' mvbЌӀ7p͉%j;_\? &3!#V;`,{U&s LbHy#Z\T7"YhH~SܢWn mKII)8j9 𽜰 rzOnj˰ Awq@P߽Oy۬^WsE"eƕRׁt*KNDC A?v`D3NvT;PQD^]^1߱\BEWU荃"peu~% "f7ɧf@1z_JVaVy`nUoӈBm:V'IAҀ+^" b_ 9hg*7ZT&2?@KKlЮTL5Z/Sm o3|M羪D;R\Da㪜8!O)WrOJӼar1+F{B2D59]io;4d(8r՟CΚT`VJZϦ$uYQnBgz2xu)kqЙ<! FULuN"'T:Ӱ5CBm*5RM.=r+5g4Ђ^-2c&pHT>H[_h f=b*ڷ"͌DK,y= nMչ*FrpoWhĺ][<ȝuzY0N75ÑB8ctX=M.%W87gH4jmcO$eݏmbC/D2AD9>rToh**$y +;6IpX{B2N Rѯ-OG `Ϊ[\>ٱ@{zhYqaPGꚚh )2l> F,rAYqtQp{ҩ3}Mߘys4E-'D3IYng9ûC" v $eF)%|_WxӝF7=4?.$,;v''tac5v_IB;+lnXŤ ~r8KCްKR@_^'ky":1?OpifH3պS1_Չ O.pÁc,279HMns@,kv!gk:$>)5tbv4.%7zSi>b*nD78ǭ^u2Atc_zҰb(56%So.Z=jZ c4r /`E13Q2N`J}.@f4k#_ Ƌ '$;Rm]z8}pA1,|%= E.TIZ#4n% QʧB[I".-,˘!rJZբξMN#¼q:mTbtmyK'>d֝rgIж#cq*E@Wϲ/M{[1]ţ;?Uw)5!An9\g. @BΠ~oб_d Éks_$Ƹ "ot]EyNFfːvw%3b7PuߛKUv[)I#AVRb ³W_g[#)0#t(SpjˆJR*7XlR}  r\79CJ.1*9lrУ m挊?L28 ]#5t UKב ^u`HiCH[y!q&Hypb_:ʥcob'ڥ;ޕJG '!(ub)]ka: N4\ţeB<ۄET N*2=,E$7xØa;=-cs)kB glnj#|:LzFDhf02-d Pr|wg~+8O4I5?Kþq [՛8Fʿ0TNIJ9"`aX o9#l*p^g>|@׃hTDZWK:i׹6P}++BڜORW--m^]0Dkkj&Pl-V^';!٘s'Ð: -o:f>^w}C aA?@MD!? X4LI2Uq֓*)7\Ƕ_nDŸcCQ~JhzEe`j?N<]IJ/I#Z|0^Ҟfl0k*Ȑm$/mYE ʼ`M WS3%E ,"*~J Qvk&TdF8}a]e2Jzk9vLa25t ST 7qhebX\ 9ǂ% [׺?мcf79e&t)xUJJBM*D𤽷ȶ6%KҎMpp#n4Y7C=- |b"Khbv H&t\Iqces?qf`3~_nN+H,y5\F%r;AE/Q/u׳ RJ E6c,,@9v eXhWմ7=|. ^/)ꌔhp\;u̘FЍXnHtASDk!M"6CZ,mH~}3˸(_`,ϣ)UɼI'|VA%f%thvV^"dוv_$#, ̦ K(QpW}{yOHJv)3bGčjc7_4i^ NWґi*h?̽`׶D.o\A9l=H9x¤B}Fe$;QlD&m mlX4sk_mTxmTTXspDUbқĠ V|><I*(HmX͢ȶ@\Ia^|s4,}jhp'sFG),,oDG귁 8 eV%$BL{Z w]?{EGgٱVF~f0Ó'eZv*jg[eUmͫk:%2Qݚ/!2É!=%anywoIy1&yF66(}jG 'H$%"UJSoZ 7/o4*{qH=Gxϣqju؏Pw 1^2N AU*-/>wQlXMY ޠ8MC1'W플}1(tΊ]rm$Q>V`w(/^v8_0)dT j46Pdh$ d؞Y Ɩ)E 4ˠҴ'rͼ4vtN2͗yKbkQD 1 UּItIo<'P F`^SXV1?-' d`n???D'kKo`L>3>9ܨƆbYdlZ<]HmB浯Mtϴ*EN^M+X]O;':Mx <ayEd8rPUT<\*&.WԪd2'HܛA27%ʨd$ ʡON@ AkvY~LEQ:Ks؍ǟ2ZDRmB*K+X"TaݰI+AGTny@3pyyXfJmO*.⟪Q&,fYnlkG#lCO@'l\X!t2K m[0}w\^,8Pa`SEI5GUD."7bKp9ïѪ6b7CQ?ofZb5B4[۵u |q1c y{l/*/*Ƴ9qUI7qbhy|W,l*+sr?j-A7=l1H@Tz:FM.-;ZHֳ&?@s_,ç Lc* fy>KzYLQ/^@4^!CpjZ7[ԃEfUI#޲tYWtiElRIXdz6qͲ\yǀw]h0SE݆D C`=Xԭ@Y5x:M,JB/3s,In &U.>#uϑ.\C#Kcb **UF%nj0X)xCpB]]PʄF YR!Ʒnqt8r'l  }|%ANIQpP<ٓCrdF }MVޛq^ =RasT/@UM =8]w.@6FlȤeԹCCOX/gjɰ`> +&1;K:@il!j+Tr/hc7鄏>^#f1x'dWN} m ߷z"QˬOTk%.\'܃C?N+X0''Vf) 0R~۳3T`py&[ݻbX6aVݷ9R4B[K9Om gk#uVH"`1ś|4S:{ Kw3IAI`&_DDɈj*Q6 ,Z%xcT7ڙ"[^y(ZW勪1nI:^>V'.9}:%]q큷,~3|9WҿOybwr1!/vNP A#zFi212u违EPRTVfLqHHS)?Md3y3 ^'v} BaN8_TqˣFϭ}ے 7g`bPN@ jLXTOq(gh97پ}o0Qs3'v dڳj d.LϮNU8v}D TjLo7Geү_-/5xDwl\vJTlqs PRng(talQ 97Emq=H$sE=nlYBǺM0an)2B뗅O`‚7I4SQz)8wM^["PXDƳ7ޏil͇* _u]p--%""p),2'HAdcPT,D~0ؿj].> "BqZJ]i#oHM XNŚ4yjbqߐ?p1?UZ~Uů`^3ʙ?!j)$^$UZs~-`J r zIdI%Kdt"^i25Y{eyvC:p1Ie1t;ʣuA!u]f(tn1֖NTxTN]X\a8Eȏ qzF)f9tPR:0T _in{ guXyzΩ.S`Qc¯[ۥ^v{.HPFV w+$|%Dt>a&+,SC-g",V:N0l%etDF.⋿iAyXli:~ ]T\EhMuyߦy'uo d<xD xK|ˈ*Aἄ~! i@x$ԃ>VjY10}>v>!3 ߷`c(1&2 dSD[Bdoxxy!i0X:~nFs s hGCPG+2llzE?4^u+gdCL]k|  3h!KU:(Po R(Nd DF[ 6bCVtig #`31 ,&Z贃|x&12O.y1HiwiQ!rpg80gz h#ӂQ@#Zx';:QF6r[^APq&d^.Q)DI+hIebĚj?fz-)y"GHG)",pO!'KH`B<`pncfۊm,,V:1kJMI[xH<К& z(Ō1~ђĎL>C#q5!X)OB겑,]FI,S"#6JX4Obhi:qgAn>cQ6n+Mμ4_Y5581 ۬"*ci n-\xb؅m=дM$SGY#?r1=^s\BOÉ)uE&^><_逜}vi>%nƨnrkNmjfzKNlS78F0>i}] z vyrRe{D ;$[dԸ>1^VSCn~ɗ% BTM"0rU9Ϸˣzp Ohl@oY_ 3 /zd)GJHO* Oxaܫi۬uO!R"`AH5Jji5l\ ? ka$ tߺ&o\̍7..{zB!KrV5-@knԚ53&ػ( aW')rDM։{JzȹK#a#ҺesPE8}WpjDb!^lN?B!>$MEk-pI:jXBPaǣg=oGMaxrs= R3F΍C9/9"|L^c -V^GLgD9H?wϿ,p2n^|): zkqҘ0e,B[דRUST3#z? >H}? 4ſъ%Qza$G+L%?p~P7I0s:I3y3.1D Gnȳ~5bJdX4]̱l% 8~-vl1=W8Ag賕/ RՏ+9ylUhPMÙ,*]X %z*WޜcOy3>mƹ{T<t^Su ء?!˅d86/=b~+|lk&Р靑UҁrFFd֏1䬹V@ >1ZR8Yw~[|MC{cdJpDYUNY- wwL&۵7P5iJ_De lTҕ%9pkæ% )Q_^>R=t[thi~o7!lPin,sfړbA=Ip6miABmcDXWąĺI kMl;xHX"6o[\6Ʒ+"[G*өTVC|+Ӳ@2NZX&%MP.Xyų=B(oO#׀ߝE?aqp4&Ԃ'[P`Xp}-/)5_ΜrztK(K2)-y3a7_)[{bpN3s i]ܔ L0pJWR'{1eL C_Rߧ\w=0Z' dR̎Jb_4b7"!qά]H<|֐fǬf > cz5A;D`ȫJQdhKQ𓭝/Ohm-,!eV;ZB _HotL@b07UKqسf?&\'tw15?jLR>_Ԛ LEOܱ!| 1=4BJeҒ619P2MՠocZmt- ;4D]>Fp7*Ruplntb=*8۲ܻ!笻S%]_㜦"Mt#0ӕn\#jޒD<&M]n$;6]QxfABɍ>ė<Ծ`%vDY]N_ؑzMgzXrڝ&WHy\uߕmF"4_t2Q;&X(RؽI 3!Rr%7 (0Թ[ȯ%!H \dVqx]-\[ȯ*W(]~5$7#Zc]2x% |E1;hHy#JA!,h%EǝM8'qɛR6Ι)FY]*RHb $FšMW#t~G2tGVt ;ڼCu%RxsPO ~|h Iݜej'ּ|Ot+5O;fڊv"$65);5L9_:hDjUӍyw2fjD1<]9<tTQ}-!Eo0H^\)'F9P{El$to^V=N+NHb_˔h8x-KfwBsas(3v5loJ)č1WcC.߼״B`Y؂T=T|I6O[Nt YH ㋏EEq;$FB>Aٺ`(ӨsJLZ1aRJ;,ܔ 2?DsQzb(Gt-DwnzS}P +{9= 3G1c jq,zsG7bv6a9}H~Awہ3skW 84AAx;?'?O ' h #9S \ޅnc*Ԕr]~u:̇qH6ۗ|ޡ>;Vz'6*I #q 6O+}dsGAX-*0#u@lf VQ+3w e|Pt!(%[N2@Vx[1|:7w# 51}BvG)5}6TϗVw}|J |*FQ#8#n闾)[l*4]$!v֐r"h~(ѩOl.D$`U1 pE/˺V΀oZ])?gD` ||Kv F\ d|{HRЇcmjd83T&Uwb*"&'ܜkXI,s#0`<J&@T5#T*M2],m![(wQ}g^ 1moGwDoKaWsey?b_THdGxL$/~j:RKe0y5%gQ2}Uqn)܋5 t_EPVyKVpLk𞹷{ld[L_= vA/KIKgT/=5%#CQn*,~T~-l+[{R0Ynpbx=ܙ*:(E2Y7 |d҇)W7rmo;ɡE J:k{ž ?U 6CGQL7W 3Woq pCXKm?aKnC˸❬j~Q @7D&o~ȁm(nƘY]p"TqX#R? VRҾ' 5O^v%EK~Gֲ ϧ2#JptuhinZ "+愨"ݫ$;Wub29qq!zS6F $ 8¼EG??o#>\,ߍB'I{1( 2˛^Mrv(aQOXpBST #kCoܡaȓ4CgEAVP_Y< X ϯCrG)COKPmW+@b^4Qw3`ePteL^\}N t/"CsJՔc R _n]C^ʟBllKR D5鱺k*@(bEou;ͮ^xʶk/j6RVkkk<"k؉bX66>䚜FL1E=[8]*RnHA6D]{)kc|fGceϘ6yOР&=yD;9wX`sC숳sCRo1v,xe8 e6oY|ka$#o.H'%Y)N-SN\VZqM7=*mкWMk3Cca;;.!dy`ܰn_n ̐G!jNY`lg@ FK>Ho2 n`磟goxN=X`%, 03NQQ̟9:u{ާprTwoM{7)$*G;Y3=Am؞|%{A$q<cYhV4-cjcPZ s3C8i:GyBGgfjEAY3͌4"{O13C:#C;r!^%]@]\mO"s0q^,HCQBmX?43oUc+hI;t_kyU y_t@@|b# LJO[xі!Yͅf{ vG~=IRPϓkfEU=Ϣv#c?ך?>vi?(-`*\[`AӠ1{l]y^hO.6hkqv0[cE_9cL͙P F))/ xܑBw,݀PA>)FrSP&-_g7r}yG4R/hYz@Iܔt29|;!H@oi1_Gw{R\SaHɵǺ*+tR4t#[mܟeH7&~D'|K-AuL<^ \5/jzCۜH:KNgΊ)иJLTހA٢)0HYެui GKyu yl2/t/3 POᶹ;bގb$`-sD{qlnp7}UC,`tS,Kr&7`JM1oؚk#&+6 Kh]-NUY$ƅoNDXb{؛WGӯ(R~;iH]i ^q`>1~y[2e}R4J#1OC2׀u{rC:CCd3bJz$}s!l:G"6ejܡ{kc~᠄&VȬwf[pə@zg.;B+ɱh(@A|V5gۺCf=[~ұMݍ3V%n%GRYDV#4)Ϥ;8_!xX>Pe) k"eTryc?vJl|(D$xvb[ >tKM!%8h= )SoVSnM ~U.ɸ/[AgYElICR:.Q'Sx.728OpUv77u[ㄆA>y2H ڭf68qx?;~W-8A:(:v63`;<_^a,|A8~dWeeݒHyi s?FB]=,ۡ@(W/Sdmmoo+ (*PR}IJCF>eSn+1i. j7z(NEقz_}}͛ &DMZe s=?Nn"HIqS/D` Ԁ%Qr}v.&]K Ýg*F%df4W]neRp%*5|Lea!CZyQvqʹe%3Y}qʜpzadSD[weҺ R&2<#]ܽޫl}TV g[2#Z@E⾳̓^LkAt?eS 9)]o^F 3Dd,6aS-7_z)1X ޑ#礯  #+K>@{ $H$Tk? v ?T7D9l ,P*5}=*HGLv ڡԡ#l>ʺ`-9@sz 7ڹYl' ۖe2C<΁6hk3Y)Ƕ;>%^ Nyo[Һ8O"fS(Fk}n1UhtF1Ø+FlL>= t #K-c=rLe!gO]2W ~1t Y8;DHAt6nahtB0 0>٘c9PX,\>Kɯr0(#|ȕ'8}ckpBw2<6J!r4~2zs97]I+Hh.z7$2%O~„LtxL[aȎ'WLl!4ՄQ`x ȝ-D^E8?/Z s`!2] 3j6[8q<.XTQO2Ӌ!_wr&*5V|Tז<5dR N 3}WV|c@I2?>hبc!7n~ #铞{.# ջ—3{KGP;B 1H]cr7nWȬT=f<ܻøkOwDNN1V*c6=1:}Y'?s/S{R}-n~)nB QE?1jO^~|/F!zG&TF1Cj;T8 I&AnߎM[oXlEYWcoBTi|qݮ%HB|m-k 0fy int1Zڷ|K*do"L~j(>^r+zyMY5nQܤRc~ΎI%W1>`͉F2R& q8jX̹7p2ᲬT.Scfq%qDz'DA]'jDjaUiHV~\AEXn }A6[#\+h᮶. (JD?+eѽ>(;꽳}7 V1㓧9$ghxG/H mX a0j&G2:~#]Z6B|jÀ +NZ,)$#' N;W5ڈekŕ>F)(bUN :}Bsd# Ou "hGf3-gEe8R fy!_}9r~6WKke^l7TJg?IQ:8;{rp9!RwI0/B(jwXl!?5 &,q|źlE;D)0ypz~QO0% _G$M/>)c# 1$G)mRl}\4excSl30V~Kɢvc ^JHdW @>}M |Ƈ|?R9y>x2{^ !k8"BT 6ϏZEq`P_# NoIs;龙6Rl?WɜMaQOż3L]|Lc#z/N~e_}oELb^Pge[3 9@v= n՘Ya#*OQ3__ ϭ,9 }B2[HMcpb[ AYhNݓj *苴[QOMu+mpS^'ܷ^&@θdO4c*?DXhCMK<!0YBbS BP(KaIT[!_]s 3HI?Y#>1!24 aÞZ@a7P4P&^;|AؙZȼB 82L(Z쀮t-۝07Eww+Rϴx.-뱀͙b=2U_MX]!4LŧX ɚT"6f_!l?Am,6XTk<ӆe$RoߖM_:6hr9y+U1rb* jGޅ=2M&)=Uu/3Imx 30yǛLM[\1 2WSѣ{ 7%3j&AKr&w1[ O]*XfrJ>hgnT(iH`'8:ѓcu.c1h{IG>q|ë5[o &@Fp~8{UPdPhE{0LuقQ-uIJ$ W߲i403tfR^ P 2?ۏfNaޏۂ,k2@h [38B*¿aO^JI6Ӽ=(>M"8Q4Um.f>+H4?aJK<tnte ʌ~gXRm41ٵ1X|5j=zVlңJZ RݝIB3uBF)WY}|ڶiq!r)j?1X#r-!_r>ج_~\*w R=BDHsNH<Dԉ`K~ʁN'zQU=}ҹ;`͸vy{F)",.LVscs8^;!@cQdb!k[n@(8s}%X_K_cnPF3㈲c5P`^;rݸY-﹡ 8};4~٤išl0`=X(Տh>F~/(; '&.y]x69 R4vE⃷_M3&W8nwkG~ 3=5 4R_+i8nɍVxqyæ&g$j) ^0hJS$}~;am/yz5@w!980PgEM7 V_{klr1\? F Z`c*M+n iFŪ+;W}ô&C82Ov9.?n;zET)|W K0엙,k̤祝羽"W{f纗)n3UD3=4{{ CId#elKF\ HH˭Hx:M%<7p+Q7%W!&"iO,&hsH;ϿG`07 >v4JEUIJFꔨUMByI^t't`9 V:dUiJg/fTف@`* |@_Zb:U7USJ^ n#KPA BR_)3L @Ľ ߇1Lhf/DqkO+BĥM]Kǃxj%J|MheD<^nY류&tWQR9coLFƅ7r!eG[!Nܬt_$m6C' ]ZFlz[S,29zJ]P$a6?)ͮ~YE}0d6 Cn_pQ; Xێ vsEvÒӖĔ|vNT!A4Tt&fR>'ɕL~1, )P[TQl\:M6,m1r1 u;TqIx:h]ޮ9Uf:q^+WF"NH͢t<2XPnq oxcڢ,>Kp*]q:K"CxV\"Ǜe޳i5T^}]*R'>u4qP1 QMC|"9$dx{ hYtr [sTEg., JMc@]M%U?txلU}.2vȥFnp7e|zSmeJ$B7.,l# v*T~qe҇?T%H궄cA'Sx̞G@ҸlC)StXUGdqwX`q3ر`SWxlS~aE,eNxDN[=&*j0Tbc t@˅.G~0V"-)]du:IxQ$;i-7v-Lz|3ܓ#|ZvF;axjcEWk:Rw?]z'Iˀ{'t=k-i?Q׏njj?UFBF,61a!Mzv?nV:+ZWi?fPY^ i:1WL iHR<ئ;!ىq`UQgE}P(qo tGjo*\zr sa2ZFt[=U;(D%29>8rb7?5%,pԩ Q-/H:ȞK$YyC̐ۆm[ TtIYʠb-Yml;,pQ*ګE4X0/h1|zpRGE~`{N~0FKO.Yc jvkxJg\r6H 134̑HsB~Y!0I ǘځ-pu5ϥ0S{1ËlB@ ?QL,McwA% %ʦAuS-NY;Wr۩^8W iNf~}˄g8Qs')IqݔIUy1 8>XCnwpXSe6Tҭ#}/A`NSy>10lB0h cꗈF ,_q3:?㫕D۬(8`wz"Oy t^weg[Z^5Zmh_8쨥8M&lr9_ "b%᝴, j[BRLa~x6sɇv6vkD:`d")q9^1j t IBFHP4w, 71Y1ֵ=Mp ;}\WDS:-$c~imzo3F~/.wy9UbT@_H`eQN,F]}=9\Οy8Jq(Yh I53juK8H(ȯOJ?fk'taI (7XKE Gڏ]P}%=]EwHv|g\M9 Q{:M]kỗ#:%:c{ jSrw5c̯y@$wP7IˡO%m{W*VIm}S;Qܘte 8X瀐2^5_P֙i`z(a:F}TbzO8"Y-Y$|=x|+ Ēpm( v4!л(ˋfH.[pl\o9%뮚c H]%%Dgդu"z{xfTꑍ 6$Wk||oyUZgJ;X r4V D i`r_ϡ98 Ъ'D;BfkT<w#h(QDj{\4*-H\%1ZJG%%STϵ_Μe)UoBWGޜ/gTGb M=|O^ko -ˮK;Ls5_ V,vvk gB'sDR)&1C}ye7h3ɠ_5M&S.'a¼ Y%:r9a^0OWbye~9~4qP/ -Upk @\g$^Za8di<>#z!vv.urVukpdlcu'mcÈ14lgZ ڼ`w`ۇYl0mތ˱3^pSVwNM*oS"gwEgϰa* Je:tț YVSbqt K5 M ST4~_ PjaL6OY3U*M`[}̭ M8g93?~5b]Cb/G2+yc z&Y"18GH⏗e9vw.uU=}뷭ů> IE0czw-8^њ5f4+TWuC. f" a؇"oŸլLN#iy?QMNJSbKSAoϱWd?P7vhEQy`ܿh4DWۊ[$X”A˴pvgA({^ę-nkZ+ "aW>ANRG(]ԾUThJq/yHj1 s9לGS?bwL2 T#*>iўu#UWmIc]v!T'mE Wb޽"s=,S {5)c Ņ'ܘBR1GW,i.i-y(^o>3_S;UJ9[//{I]z`E;m3*L]V9^tbMK}|-#>b-.]xa/my{[ G8MF#BY[_y:Qef}4tc ~}7'-䞗ܙm*j3*̳5H&郬@ʤ2fBhO-fB8phUJ)s}T75zM}*1 Y';ehX.-4wշtaq8g23t8`HllZ*TL>ҍqhL5 iels bӑB+:+rQIs`)!;&_4*M\9|l13F=]hBd>WIb;5I#Uu,i< qc 8}=W$( J);b0E-j9/1Hy&5_˵9Ͱ;(+MigwXܜ$]-27#qSM*.gyd,J_?oEeI`wm0aCyɓ@rjytsNAˁ+@N?cƉ!;S#ik]o=9yEaB.~|([Wxu-9s.|y\J獚Kߑ^pso@ I|?Ԋ6J- BNrz% !+1䋗`3VUEfVMQ->VRjmߊuj"EfcB=ZTMeK ې n(%iM9 USk|۲G9uN(A9ꮲጮ!e;qXPs6yF@qBN5,9*K6[S<4%4 "AލrV[(J#pe[Ep|T)6|4}QӍ+2AtvK'>u[ s(̹OL5[WeßrYD >„]+Feyq P+}A x|TNbÏbn&A=e޿I, F mLtH9? x5k9<&ͭH;e[ݔ:dǚ_`?c?*,F[x1T=¿wKF3$ƼEZRY4Yfz+,3y kJ^mߞOT>1TAg- <1R+*ifNk /ZElCΖD-֑@I .o֎&*ݙ"ƧK: a*@yKJY~rw{_ Qv݌9`QL!Yyǐ_V=!6hɽ<§pDsj˴nvS]})Kxj9W?<)%Au9/˘z dX:ý()e~y+@xL޵Hh1~+!ڇ_7šSp׈{UjD(Dr+AEfI;`ڲ#FMtOfUZibe)wriv%2+Q`7_wr:PSwq^:?UCn)h7#%4%<(A9ޘ ,-5 *D5*U=kE6%˿Z*JAs٭C(LSօ5=`Xmx_>sk4w* #]je"憿:PZ$u'@ zf(ʢG\xJ 6{_)@22p;-NAPtacErU ѯLԽً'T$d+l(P$K|Jgp 啜m8OzGAnκ%(x(:$z"s$#R`\LBvscc,Q.NJz,U`׫&dqtEYF3%Of-JβvI0 N,Mk9<`=Ңamy#zoG1J~qA+}H>9Wh΀is氄$EtmҬ5%8kf3 ]]:XCOc"K HkRì: Wu dsR8E>C}EhnܒA{s!l̨LoNgq(Otn_\(+N;!Z=F퇜1[{ix-l~Kp3?$wb*8ͮ@xR%/W_fKNO%ݏ 56B6FZ%WS!䶦/@gG4}ɝMg@B@f4 ̍$[T3 QJ@G;VXՊLjK %.JiAϴGw Ϥw~;ŴOY+#zA]P0Ϸ #|tZ9w.(Z<%hZu"˘V&s< .E YLgX,;_{"7gK2Gɢ'讱0:r:Mk93UTf 2wb:Oo6:Y׵5er;Ӧ.Wj#}2s Ӻay}Qs _XjVr@4yͦ(-6F1-q1H'Ji%:olҶO*GIbK:ūi!qx`Lr$Ϸ6V.[*{Br"4D*67;^1+./ݩжQ7 ЀL;]ޅm^] 6J9&TxU8'J}hKjoksU[nJEx ~]gt|4 bL? + WkM"vZP9m"`x~8+Q[)^Y:`h9'F,&b)V1tБ>0=6mzw#:!SXtXaWn BhuɬEnnяLO:߄F za!r{5 "Q{*lPkPmS1%$g{SR)X >ZxΣC&.a۾v`k1O|iU=7՞9ӲU2ah$v|Ս#"[)6ܔ9%cM޵Ds7jbt/X߁E+ #7+DLwp^R3!K&Vn Q/`,lPA͉"t1^Rü7~uFi!oV3  {R'mfR{į۔EGPS'(" oGwEц[EAA aL*NHW/poAl_|B_~iRq:I>ԟ}~F!yyf*VLR;Bt=nZٖ*jH-D@ ^x1𗎠뿨u].ϟȦlyxtr:pf+dE?Fa?4LHdO>F_T=4q~ Yn1?lI)ԪtUcaUh!G& J΁Pp'|ax~<-Z+[rtK:JFm2bK3m:J ܽ(e}<*p #@pB@?gB9^e3R94BiJfWcd_fzXFjG׊ø . 8,xİuh&Uqs"҃Z_h"֌cаv3&qW=}vE\^ʴ?O4NʨEs?VWl:" ,nL񓱄D3eLr4 /@XPvC0?3 [i9qĹ\id,9{@j tKYJWp%Jt?scmQ? oܭ\c-˫orgzeݳJϪ $s.V6ѷJP5]ZX!DLCD3Oѿe_6GR^lETO'ODI'?0'Xʂ1v.GllNmsJσ>~ _vPp7!pi b9vD:y^31{P\6aٟھ u'75wuo1ϹLVX״jVI;}3IB,u[KΡ&Z\nO!WB8KL#:C:]_=Cڠ"T+M[c;jpH@j{3A eRPyJ`/FÙj*՘C7XdZΆ&;;PfdzwP>rx~5U=4BfwvoċP-tOJ(4@|f9vgZo#^q{ܔx |qDA8SE29qJr P" %=ZlE0~i{` VZoߛ.%rU.ݓ+SJ?է2aQØ" J?XwfQ/@oi]L>E6dx]A\&+dԦy*/WO6D4YrGdI;<~Udbh'a͟79! ֟]%vzE)|{iՍUpMqg+hM?I[7îFnILGX.MZm1 s{\ >n04n(H4+ ,~P< 1hؗ}S;p=A3 {\ͬM4 $v\uEX'G-$"ZMi!D#)wX>:@lR\_ ۇ"-6y]~``/ܮiSjq8:?VIp|h/v)#)R=˕'mauCjk$ 'vL/-QQFH]\oGW#Yq<'G4oRx~Ж'ecE)*Ϩ`h,4=}}4Nqْ⛦o- Kͣ,e2B Ɔ IܪljYw9c[EU;EV*7^ <,PD#Fc<U D5+Rs!y~@{r#3- QL48ܗ E㡝ܗ;EpiYX#8H[9:+\Fqz'J4xMNjM8_TtR?Z`1zed?}O31U[i[{dT )0=;ӧFB??dB T -k!&4x?Z׌"Jkta7Qm&J |bCTleFb@QdsBN(r/Q Am݌iqSD=Ydt.(ʴž-n}kLmI@}X(e[\gOȚ\xٺOoK}^Rg6wTo)oF vИ3]p̈́W쀔aEh҈ŠDŽ M]y0^y[ ;v$s8'K8-IV/5Be/4CȰlxͱ; 67NrK:A͙rlj(W@8]-o;=^q neh'& "@:$4L0KRIsi R5ز|C_ocH#>l[Ut ? 'BW%^kLqYima~O&z}4N1=Hb?a9.-xz ڬjݖXJXg-f|zOH4ds&QOZdݯA"RL )9/U ~btԗr$3 HOXKEk%̂,J'`_U8UbΎԁex4ENcQRnsSh9rLrM$A0gϬZX|oďI7D퇍H:x{9T3t ̠'h#Pd{G}̼|c)m) M{[)9Gy]k4{-: 1WTd"˃SXٻn1%&)Dp%ZXTvkj}N[p09ʄPuj_Ro0"FuYt|GLNdosjӟGRrͰ atB=\qA1)Gv-c+/1&- P7@<@QTs<_TzC7y>zjn%˃Z{ptO&`'lHjs:JacKܿ@1s{,Ҽ&0hׂRʫLn[ε;Sq2hW-`݂lA&wxchb=C;VX^MA RO$Luy9|E'C9N9h%8?`9 v~I• 3b!-g OV.) Tv;8y< r nff=Xia툲?S;j 13 -H|a/Hnn/~8=, >yVR Ge,yhIT0 O_l޼RCW3$1Icr /⌠k:ur=m׼TQGQUike]>g\,}N9T-[pvR݋/j avt/j`!):vJ_,69XvپZm<@t~)^'YgK X&EhH4ĭ=Y;\aCEs$h$TJINK &ԯ१ 1#NYN* ^k$.~{ VAt*jUx.Qڱ8:S ^Y^ 0ĥƝGU ]T)Yh9ŤgS3ݷ>w1/Tp;Z~ktWjA*3O6}I6.Tǩ/Iw@!MvA'NEb[ީ)xHBOxx(i_ [%` l)ʓӏWhgGk,Y8*;Zu;Rc\1놊IsC@r@n+cHk7ý:ߋakk9g'P(C(WgvGD"vK jS-r ;b!:hMNRoV ƹ~m!{S0axK,둆K"-#\c?D&]5E}mZf02 /փK{a"D:. /="gfMb ics t!J2h<zZI:aѷ쇛VQ,}(潇cO,[nśJ7:q;Xw%ڛ0[(YY-3uյD d`Zu`A3lMM/udhE}>Uyƌ[ 9KkwݿJS1 & q1l&QubЈ,K.z` S_r d%\-/ S{U0zf)m؞I>!8e<09c4tM,?.N)B{UQ\,I*sMax{ru=#ln ᤎq`uQW س<0ytoYČh-fчLh_%I-f(@Hc]XIT~ki2L+>q^P$^kߌjVyCܩIΑADxH3GTD("$ZDR"E{l(„p|1S틚9${8|l7~SA2EhH t%bX$ |fzKc5+TD O tW/ EsИ~ynwW)䳮<)|ut{CFQ(I,%p`^2cڷ]KXInnOf;,Z)]Fγ'jŊE Va@إa.,aϳw=aW| ;|O]mǝIF\P줟-Ok!}^;fo,Yh4վe&sbuou  ܞ\&apj+`Z/I(2ͪ5|_xnDD NZ<4η:${ \9y;q%I2ďlhtAfF}NAH(GNlH'#xZE_{| E~)+0}_^YH%;V9S&X P>YvN巺Óon,juy*a5o]sp4/=HBe?6)VCMiV(*s'qS@]^ҽ̑4 ;.l{yz۔iada$TZo#hA.0(&؏):R^dA 1/2޸G9rmBurrԢ&1 >R|SjX׽r/BV{[힊洵*hv^׌OAANiWbȾ ÌAdlFwA + w{E<=l.&(qhUܔQܽpv+XmfsOíPN FX1( ZJQ#k_)+mKۦ 7x9"Gs]S('b"O ١S :"Wrdg;MAJ K u-gb3]8+)$o /b }3vdȨJZhzd0"5|6i6:Dzd@<4U^[Ͼ|w!%%BYJE3U0>Mu>py׊PO lR}1*FѿWwz#!P? .2he2.R`j'zr,>v"kw=8ӎ2t:53 &\V{OK̇nJ B>x%rS*3ݩafw4CcR0 _$w}r^{zs5?fP: zx沰lK!4e$hqEX0cWwh=-q4?{U,|n:8q$Hpf'OEBN*̵yҋr <51 gf+U' v47|kv s&qX֘q,Td[KS\C> EsM0Qt hbpU\;LsS#ݘHD1]FB{}< rCCJ^l}i#2%.`8)|Brv:^DLaa$:=259z FԢ&EƣdW)׵ծS*Z7p]ׂ9_wGa.)'=B}ЩESyh2_R}#P "%O}XQ&}ՆiyEΣdp:'2S8MܘWխ1\4Rc|kv j䘶)t<]@(DzR`vj {=)JGmO(T iAl[4ѲN3(gXK 2؟hv5K".ݦa$o¿Iux8tAKkn] /\Q+ngbM?s'V3]0׵rCґTی7 3+95>#K J%A; h/uz\~!N6u S6_};]vM̕yxvQB/ l=#B\/#-(/aZf Y`gBP*]gJ,APLj#iQT eR{Ji` ijG &xrd>Ԫ x݈D 2z%f8\œvoGr{o $3ғa^r-_*KF"$(`z(—";cR>|UH H2zp8D%F[a{ `hn7 |H TF<{A`:$1[xY:Up!>];kyĖԉB!Ԓ D܌ Uۿ*hsDe_H{~ * L t;fTR*f9c01-VJ'G&ՓTa,Dh0j_cJVs+%`9pOvJIטEoO{{:S%<+%Q/ۣN\Or~ l\ڝrұx^{-*TQ.r ٶ( Ǧjt*NG>ӧ 6O3Qz{MTd*N8 >S6q-9'.i2ulEb{pгqpp2ْ;1XokiL'iঞ܈}2 @q]YѠeb1û9x[btYhA(xDx>?v"SYAu^cX31|pzl4 zx=O,EsRʧt"[~ ߶ 3i< ߁KMK,e[+LޚU{q1IӳjkܓLjnenA;R(-Ğ ctc*kQ>텘Ŕ-V{b結s<11dۤY;".er5O#Kuaj1 c@Icx60qdnP LjN8+1q[/eTy8~ߓDޜ|_dMx+?xݟ0 Kqr#J~o}Ax,JW>Uz- S˩ *L={<\Oe8+L',:CQ ܇|&B^`f_ߗy닧$Se}sn62hғ &D˧4ҡ; 0IMevy:2m8]*%g0úS|>*c7߄f!~zSY$HB8p j ̛@` g;gB @ojb!!M{b([0MUU >#P#怿ir Ca^nzH7nL`Z'Ҕ"-i%DlW쓔\6ȹGGjxP:65I6j t?\Ia5r[PIҳi4%G8Zlw5nRQhIPeqmk 5ЌD Ψ:4#8j'r wQ̈QE݊--*R=^GI^O(]G)u513KM%c&/G4 yb[e4Ͼ!n*%-ū]S7\/z'yN/RBfו# NKSC6ԆӺb$QU bm+U^S[mNͣ4-a?lbjs~C'{#"TV7@-҇4֜7a @Lv8OB#ƂcXz`WX;h}zR}-QìZ1a*úب2[ezj~ ]ϹlG'Y<*/FS G`!AL7Rbt%oLjr5SA= 9>.O Rg3 LQA `+6"|;b wb1U.7 =QyIXM*$L'ˏ,ncuN3LM\Z`\캿s.]!k:!fP#PDa9{ZůZM)O6e8=Ƶ߹(`i68ϖRH#.03#z1<`/Xan|/Nh. >gR@5Z.*#ڊ~tldyՉ;bƦl՟݅q܇4f[=C= '38S4~ʐt< Bʷp`](ѡil= -QG/_v;O/uC/Bz"7x# ?kF* rG -%1RXq&]MlS"~=`Zie7K3OzoxuĔs|[9 k_` ;Iؘ-dP}_}(w! oJYppЕx~:Diș]8,o(_w aÑ$O{{YC!^z;;Bb[P4xƪr8<1ע?ulmł37%Y %/2s9׆*P1Ş| rӀ$ 0{V _p$]B-)$C6@q_BAT5vI$HT4Dё& ʴ~XNx}RF*Kί̎{JUk1nV+t)^)Id =~J\K'M XttI}71u~ iYCɬ F|̏K#w3{JԀRKYC%H2MW=F:%݋ I'oEL-5by4Ty7>=Z){ J/Ie/@8=m,'}w7!ytT@jM^dl>L\`ɆKG[56~|NtnP8}'Ȧ=:>R6.|k$7sې5!HR8•l4ų3!`;RR' ɴ~] xӞ=U6ΎlY0a|O:Pc B7Qo-M3©K6-@Yk:\Oy\H,Wbtw]b[PO>3pq~@#5&2K@ǬP8< =T{R (p$VUAca^r-e(.GꢺI SM~T^Zp;щ\ן \aI|#f:!UVQNKj 'ުZ brO9W5q.vNHN}NsHY)77Vuɑ3_u\ l[\%i(C ,Eꝛ)T-S]B^!ʏ.q6@V!_7 t^[\ǃ*tTiShSSWs&BGF)ݱսRCI~,Q@(N WB]xǻ5Ejɖ;%8aa&oWց>%#8A/W㮓2i^l[dC;U8Afnz;`oQG\j(s6&qS9/rߴjh%{ 0dm!}$Wם<5Ok$$XYLya3CtOɡhQm}ODGS5* Le$lfۀ?b˖qt/ך}Tr=R/To|As7Q,# 󃠚Gu 9ɿZ '287Mq[82H\W7=#rF@q};hq]\ghi,?zD1$vP8t]T! x8DZΞ4G`U5t/ޟUPNc(eOulOi'~>FK8J# B'Q U迁ٌqH fn/rlA8"Z2q8?^Z^l~n6jta/ 0U84A AcєA.b8\!q^G0^nLoJߑ n\'D27]'C؉C vW,BPMx80/P?4%1 hҮv!0;w@#wM P`f=ۄ&vc;:w Q%G+8^@YG8漗IŅon[B~~XI,( 3#JW^/-`̬2"b}*'^GLe2p(m%~du{Ac. rMxdl#YQd-C@241pqpc^Oﺋn.ﭓB~e|1ɯئ*p4,ИW-I(WyF5V`qh$?Uylzs"pSnY知7"V!L4Xc&$[Ksvzfygu4='ʓ( P۸ {鴻lN"̷EIRp.Ae]b粻 <)8إ&r@bO.6{x*u8Otnv (l6ѮSYFC;4[87yҶF"t)F -鯨W=*s*+:C&Sf5 |d[uuX3,^XASdx6 2rGmѹ59I^,_MIUqDn]XB [&)aq  pe!_3"tZɍ]7,n7oxbn¬, &NH"1 $Y' ĝU=&v01fqyrr3 v} 8gN%9|*=տ &dR$pڼhfU䉖7RC.o M{ YZ