sssd-ipa-1.16.5-10.el7_9.15>t  DH`pck$ƨ'k{ݩR ޷2.PY GmB&lpg |Vb+!]Ӷrv`p[ƀ@v&@/0݌ey:Yׅח+(@=H~IP k> QxK; Galk_V8:"=R2WPu/HwJY 31Zk`NNC !JW R5ؕVldݥzUlڬB~Wȗ;ྠGAYf$ۼ<"aPK3|~C?dv}dO {C}lk4xٗpmHx#>/Vphv(;!2yPσ3EY~ 'Uɼϒ"lkz{C<[~X[xE39ዺj-wA;$^³P =_<~oÌLW@@5iq7f?) C*{g1ߑBcacd11e347a33e62808c80998059989d8eb3ba71Hcj$ƨ gdsT'1Yo27QJ"hۘ$U%dcoF#$u?Kla D/p`FO]l ţB։^5<_ȥw#jl(/&tl]>L!*k`_WlRh, ~؉,3M_h"M%T?fAYX2׭͠&vO͋X",jQ;$Mn:5{"m^t!bEf D=fgܝQ!>f8PNypÊDDYOx3~c?KMְx<' :!wT(Qd ݮ< Z)y̩pw7)I=5񹨚sgtTo*Ȕ,8a?u]fnWw2ĹMƴ9+'⨂Qa񹞸/HlBT<QifRۏNzhg<0~8mӆAs Os$ x>=0?0d   ; "?EL    @  @`TTuTLPU(d8lI9I:"I=)G*H*$I*DX*PY*\\*]*^+ b+d,e,f,l,t,u,v,w/(x/Hy/hY0Csssd-ipa1.16.510.el7_9.15The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.cZx86-02.bsys.centos.org gCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKt&/A큤AcZcZcZ^p0cZcZcZcZa27f0543b7ba646138ec4d26e80985cbf8a811ec79a4335a115f07fc2f5406f4385800a4f01fb0e4ac9c8730dfe9761473ca49bd527c3071ab217046de2bb62f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9035335c40111accbbb78ee88438b8a2ac95fb2032fa0c1a8892b3dbec7933af48a40e16a24d00d776a540d0bb92fc6733598497d582b8285714d731a96473beb966b7207215c1936e333742138279829255dad98d13b6347ac459470b462a51a6frootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.15.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.151.16.5-10.el7_9.153.0.4-14.6.0-14.0-14.10.16-20.el7_91.16.5-10.el7_9.151.16.5-10.el7_9.151.16.5-10.el7_9.155.2-1sssd1.10.0-8.beta24.11.3c @cs@b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.15Alexey Tikhonov 1.16.5-10.14Alexey Tikhonov 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z] - Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z] - Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z] - Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.151.16.5-10.el7_9.15libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=881fe0e107a00858131322f99256b4a364d3bb88, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=cb6b90cc96d70f73111769bb57355f66f6383d13, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER&QHw3So;6)r~N\UjH$,=mn#2ѢrH=TRLmP{3NϩSM%\rA]Ǥmt}nl>X^5Gi`mwOƁTTI:ݧq6䱢N4 UNݻQA-_ ~ka;]cFӜ3+~+abS`l])S<ՌKְ%7DDf?IRA2TgPuN4`2n74ľC\ݝ,n ev7mI\9`•u)6oc{:`dPL z_9JzDdא{WD`->Mhp1CU SlyzT⧫!tOHmڰ4x9٬[0u%>q@nK2>/9s,BDrD| l7^L9P嫵z`b. ;/q#䬶e[~љ.ie\U*bG])wM@?ƕtKYPx;qw"/ZI҅sʵx m`{ B8bL=Y͐W>Dž?@ )(澠oCb*1xf~v^JķKI&d?A#we=f~+&OxIF ^` =߾`8q'RW$?!v*Z=Q&9.}QL>HaϹuNv ;ݰJm)Qj>U}&I_SYbqݱ}p¡d{MOkhλ1^=lL5H@PôH5kASj|(zOY+PKnPP5nV J\g*$5Wߊ5a)sLVAvZl݌AG`c*. ]k6rY7Ơo3TwޭLlzOS/(`Vyn%uUM G 3h((ױr w (YfUa'4Izu r4QLq', L,oڮΏ0_EfA2UE}J 0ӌVѳ#4H?젒xۻ[Ӄ JXB7?8c#k; UdKjOqK`zbቌ<7YjItNɥe js{Л\}٪"i`,jU i>@Δl,/4V\m͔HͰ4v]wxF<>}eCa(E׮X\ ^j;|b SһߕF~1Ml^(Kh1'=Uy\puˌ6w "BBT\古%^/KJ[k ,CQM0+%Lr;gDϼ7"_E vZ@$ezAU=ԸҘuEkTZӣG[25+UW[Yu@ 7Tv/ie,X_„*"TxXќs2Pş.^?F#Z{#^Td4ntNHnLbǜeb\i͈8Qruע%+\⾴, Z%qݪPV:?eky,[C?ڤ`[T1_ΧyJ>IV6A>';ѿ5X[=z޸LNhbtoiIX9`B=qcO%@hl g<8 X:(9tbߏ!,*GŴx@mH qJ*Š],]> i[cGz&!Mg|.f]Y)^ k:7XVȂ}0)xfou#Lpnئ @+gXa&KzpvJ%_*|5\LU)g[ ;DQPwIWZȞv=0+EȖ]RЗmǟca*Bƴrl!VZwVdPxtѨ%l)dvX6Mhw"woG7} =A"8er[ڭR  `N L@}#/mbm9;B##3F]a#8Uh`,{7N'r>Ig-foU,a#G^lEp5CbnڇeLEsn>K:WSdRT/yR2%72hu(1Jƾ; /fd&)/.$|zluv< cHDyU/MyBku &O( P$}(;RkVm _B.Pm7Rю#~h#f ؙm mI'!]|.#0ÛM^FJrҒq 2M?rRF?S{xʺXu#cb*6 4jg'9 r|vK[?a8%2VPYg U=•vy##nMR(Te-c)6+)` CjƴDA\3&sg ဳ/Ǡ4+_6H><`%+~F4,O-CwYNЙe~5E,FCPjr?]B"3$ wU+0XKfHNij9c9ArI  h53GC\N7RCI=`:H܉RtOp| |D`dAq2o~yQ,ns~`4z'8\JOA_`ahh+m*ʒZ"c"gSu##ߡEX?aq$=J,7] K ^=;꜎MܷI (4P߯ZjfίӊfS k!" 5MH׸;qT}W0=-RQU87&Xze5Z͂`$ )h% 4i76aW6jI!va&0ȡb膟ZI`?" 1jTM:s|t.=[%Ih3s;v5O~y^il0= u6٦QDz IY%/㦯=2^Ps"7XXr.61^[fD*)g8i!sGbTa4.O(I5hd9aᆵd5qjPuL8].^CVznOCsԘlY]=BM+?bJ. ZCa^-?y0)YKy1DJ>ZNi$ck<3!82PBM{q4j&V >ӓ:KHmưP|]Ԃ=1.f{'^'ȣT\%NW9DJt);y.w{ ^璢r47rmuJ, ':ʧ;-e^C!@l<^僕 qGe;y\q@(.ܴ_'mȒW vhjA5h[iG 4NSTڙ^r5)qCiF;/ڧzdhԽgrtֳ $yj65(b}V-hebګ}EȟJU´"r!6餸-/oWjL%4 @;FI-q8{ .LUJը2W=!11=/3V6%WVqO_n?lWHτ01b(wi!TT$f+!M$Aڬd7R Ў9bA`Hh&22LPi-w-oTh엓򤖖 $}/6d#@5Z$F0r5ٱ Z0o[}*v?RrûXE.#P%ZhLG| |yE SOmˍ?n^UBˆqgYFO43ny_(Ӿ* E,Y+JTYlwwiY8j}Ĭ_+$ TVso^V_wOzF-JϨ:-<}mQ L%µAů2s2ac c#uꄏzQ[ʕJ&W"Ŧz?7䦣axajHc]k"O[Hr4Ӷވ6`4]Cf5gd*äs<=+&xta k8c3vW{fJ E՘O q" 9h6Ϧ-'<ͅI3.Al@kvȵ#tz熍ߓ JQ.#r[{n p|k91`X4Ǜyf+''~H=zs+7a7q :qC4fͿy(fZgج#.\+#.+SuHY#1P$2p4YbS'Q#"B׋z?)/yhQ͞;rTJ\VD7Jj+Qr@ "w;CQ%pҎFne0pZD GXO3\͙c| +gI?:qmH.h;Rw`o4hBi_cH1z0]Y}TqވzSi)xXn0_p<'kuua#KG'(=e,5zqw'.SC J'~N՘T4=^Ag&aboQR\xK`( )"lՁ:WkVfv_hO|KJ ]G,mį<&e !NNpCtuLQhJey.b e(& v)WlXZ78`o`ߑ%pjzyõI\+/3x RtfqeKe~2 %Mnd+ (?>8ь?VRV'B=L)2R(3~zؘ@3ْK2z< ;sVMf_rhmD7cc9BlMstŜPMA䱻qs:i0Iy4K{1>2}ٹɍ0w<ҳ$O/\8dq3LI|D] v-*=cDaX"Ȟy|RtQ˜)<ܲ1c:  M&PEً3{sfiwrb"&Y 3pU]OFG2PۆmYoeVTryKk_ɂ,E|o=~toYͩ)$ͦdp[$I J}%ި;Z&8?ӡQ߮`x]@9\ } r`GyR~s R]2LF׽٘gL$i`Lqb쯂՚2]` }bzKE)'ȳmK*`-h+({Xu ћi9~V ,a~dCw5ɹlAJTFR>2*29be.z|eyg0 "qvC@+#:6OAI.xRl]CuoN񩚛NPn@`a) D|^|E#;(68 v2X(~P|0c-<-2[YD[M=-Fd[֠X O|aB(˺.K┺2,P`Z}3Om;s@Ga #.IL.鑌؆%;V=Opw<ʙ^NP폟O8 10iD`;&JEv"c0n"eDƩKSa"1Z'Kj_ZxPe5Kfc1MvNϰqV/@j5wwږ#HKP+|ƣ,1}#fciEZ%$gpGMOӥn{fCψ\,u\\R뭉Ca}Q }VKbu5,&'*GImjc0njݦj8][ wlUp2|/)]8X= x :#/"wfR:gpb%C.؁`pL %~B$$W3yxw({iGcY; 4yNؗ}_Y`?ɪ-֠!0t<5\,9#밬Dɠ=a~"ѼT -2P3xnӰ˷r;vɫ*|J?E8K#Ѓ8 @ }ck>΢˪| :_b7{ I*kWկGɊ%ԕ%C}V-iQB#XfgAb(NNt6@d]9&"rF}eMև^imydBu?퓸Zl%bWleQm.; kCAf=aLR_yUnS(YɅzX pǃ ;__5JEμ٦gf~rðL.c"M [h9#kP9WF}zjz-u).!mbR8 fWio!ձ/bG0\󾽨J_-kbiHȑcaQRl:S'c xvpTNC y6ߣuH2_uŸrQ<;UM\ڣ_c(!Y HG̗Ieʖ6}-g#y3S% am9[s AE6n:;H m {r%C@)D}e&uFHX_ԷvTFLEanyaLECD CKJDxϭ槠߁dۘ";#eBo427AAV*Oh\}t5O n3&ȍa԰4Du-/2b'ֆ~隟ev-; SRXp!O6pj?¿L^H{"q¥ OQ믱~'=䪩 C9Uǹ)cժ@jU~=4,x[ =Ԇr]ƚ۞QQ\V-El 9\*;Ϣؕnݧzz: }|0#̣ŭie|xtr^oDYɾ3> 9 NNE1.5R s!XCx o4(}ube>P6f[s)iόLԓԪ+d ޓ#VdrݧqX2xa .G%=U.i o.68xqX3jm8uw!DnUwQv>3}kC6"rWԟf VrYk>t'ܟܓpV\bZ I%M$39i,t2]yXO#Q!Tl2%bBBe5z>@M`QQuK;X^ԨD%[?s\c&G)ߖHȳ6<e0V^=o3[4}VL4Y RNd Ro[ǀ`i(5ԎLȪdȪBbLr Zֶ]T,$#[gU5,.^J]A<*0lORP,DCJXlAdRH~b;ڔ&7#%^S_!)=~]5M6WM_~_QS aʨ7zv*fsUbIQE,iȅR#qߘn DrG,g6FW)lvJa7Ee[39a%ԯpc@&q5D~f"A`H DpU^o/Z[yqt}$1()-VU:by \@bg:Ǒ)%mf`_{WVV VKZo_B1A)>Vx&\ )G@ˇM'! N &K+?CLV_?='0(+ %[aJk]1uƭHUA R'+=*n{+Ms6ɥ+QU&? Zu'%M̰Ƃ&@"~:􎇲IdSS/ nthuMaQ᨝xto.69Y=+L%[ʓo017v"T{Hڇ /7QSh mZ4ٌ:iaL|HN{%'@IV޲CuO"u.?{e#ˇ񻯐<(S~!P\@@˩D7zm}86: T]Ypx1bUwd=;{:53cl!3?[[HMfz{ Qa;2FuHDO0-M -6c/ӡRRF^FúQ|o]qbg*י*\8k_P%mۃSˇ"4x%GťtA0Z,Rr٭Y_6GN`%U`Ej}eEU+ y|J7oI WI7Q|&sٻ 넄x%4-<)AsF+?;\7R/3PT%]0[[`B)gU[-tbw>3¿&Wm$&s;)bEdϴU"6/aɾwxʑq@a/>3  ? ā=W8zLD"::Iܒ@OF^c=) cyOεs{O=ā +}>sʳ Νs%aPŨLl14)Z?J hL ֌l|MN2K;?2U8FnU=~ݤٴ ZYq?(:',Zz?[;ꗐ:9 Ő2KsG %uZ?6x0Z|x>gX ΢y*Ddp]z'mGZ5ɫrgεXT̖Pa}4(},,ct,\ qUPon6fP]S"no9rʝih[D:(\ eTGxjq] ۮ_DpË>ҥ(h * =0/.k& 6 2_Q'Y@| _wgHmgl sYJ1Ѓ%ETlQ]aD\ǖTZGJ;/L.j2 }G?Ac@ٴޫ$Eud84Юaj*]-ڽ`ntTez ^ ۃVpp#  ٬"0(I.6sQ X8C=i*p5zE]BTw<`Pwt$|ɈLLUC\}aâ?R&\%y8݈ 9ӛ)#;[=ɰqPH'ϩ^ˮ^F%a ce&͛t^8rGX$sPS {eT:{DkVY%_ȲA SŇBg^ݚ] (~\IZV? I !6@2ꨦeipQHlV ij7*0C'nG%FoL|!id{\3;P U;=1x>l6mINCwLK_WA^`-@?oHv`vLbGC[?{BST9AG<$gl!/Ƃ"bd_Sl͘V1C _b~Rϻ&x!u)3E㢥=>A *3C5YJWL:mradv֋ 9ڒ;Um5ȄJ$%LYE,SBAsa96 y\#B!i8Dz pR!$nhl+}r#Ib'UEܠ*o P4{qzL _}{DYL"cncϗx9E{C^*>?\3:!S\nd( ^0nv5ъz28B#S*;ՁJH>bLOj9ƦUqT}SUǬ8 $dL$0׾x~5&V\4@!K &C/Px;FSx:P/َTԿ^;o:r^ZaIy |nAfZ(=4ӻ= ~ބ>i؁ߐ3Šk=~xdu4m1UN'uG|E@䯹8.:YHVˮ> u/PٺY4s9(G8xg45]Qi-67pG^FBPLby5Jvʣe9G}ru%_BwbsODCLŭ2k?/+突͕L Dv)b\#mdk2 n;]4euxQ+ 9T^&;#wLMT#䬟ԭ}zJn '2h{A umRW+vixny4 iy\_F?dq;RC:;EMR|DzVjаtFVm;ۄy!2㛄WH(tz1e:ԅ2cU\; !)OM^:NDw&n|߳J*aI}Ww)6ut$|c.[XO5$/!4x>R_QL-6nǬoΠ !K Ģd/vq 5|K+&tL5G\7B =p]V<.:^1N 7ن NV?sOF6X"+A:L ̃e KN2K 9Eh8.Lѷw-.N2Օ>l O03Gu︤Ms \ő1PE@wl#6 t:ZrjޠkD77yלL7%kW/_r5t@@e{~=( (xrIsn`eY%zx:п ewp} >]ynNQ rU 趂0Q;+c,ZFyPLH[mc[{E}S-,cGloV6-9rٜX 'd Y.UtpTNHpKPxR7l#{9J.6"-pOEJ#+,968)X4d1E:kYR|G l~ EbOPCo>!w0g5ֻEs[z)nr&X<T}"~;Ȧ6XSXӊV2b6Ƌ:%k\Ś:Y $,pzXX584XoyBDG`gv,R' ,G"~wC]ޖ19@+|R^$霨t!Ƞ04jz9^ukG@>@U5pYfn-襸c9;(+3POoOH1r:;І7t[)R/x7nAɣ I/6w`ST3Hn%Ծd<CaƏ sk];; n&^PC1H:\UJ>7_ tnOxfZz`~W0(Pԯ!0(ql+_\ hdYג(Um(2@>\~pnvh g 5@HQ0  jA9EG?3%q D$@ =)i. L!½dyX mFɭjsii lJH=VD @ToDfXYE]}$"v(*`lZP7y;V)z]h$\˱d*5/t?=c\2O:NC|3#O_=g{DK#PO@ܪ_liD?G_@ᢛi){_B9R ď &LrnWb9-|LyO9ņ8C禩,kDڠ{"F꠽ژW9*fF!e",,Mc<2qƅo]+ل î{ډWmq%u O2,tJ))2\(KU 䐽<{Z'MWG {mH̿>$$Z,]'=CҚ/H?  x'P]:[9nhj0Vt)Qo嬜)a vx?5td1y*9v#I=v"Lo*h9m )2(Mjc/"XPsR!:\mXXss-i ;n.'5Ƞx#4DFLD718_A'=G^NUd lL1+ #6 G#A9A qL8ZPqϨ5Hr=DXD w!Cvnu>]3bHjfJ" /2s8"Y⨌٢V" 1&HGevS^w i= CqG;>,&*9g^<xSlS^hfZFv2l)o%6ÄL V/h`1C$muJްo ÀQ͚k7.܍ ɛ%AE]a._]Uj0X_zd'a}.]WSwng[^4ψܦCp#f7 ePYamUW(겸2?!|?! MQwwD,S{ fѥ Rf"T C nD؏ s'ZUjd*Cr¦T8dk]<+cO ѯ>(ނG'|2õ+| TtLK5jMiuf\п!6YB8 ! #ֹBBл``MVD\'0j59t05l.XYY:G2X!1ImPYYt9/֒G{AZC/V ,!\@Yl ( ʦ:uҲU#%5Шg5?ME}5X=s'Y*Dȇ:caxX 5e2'wHS-9 D1@#nT Y[I@&gϏ>Ox}[ ~B#`H_ 2d˜kʋZBY /sR>rPU+↉|{j܆BceSK'PT֏J@+@.גIIgRrXL1 /r؂b dJN#^TxQVj5=_c蔽rOwE | 9I'r5@eԔ>G5e@;|>0@&* M>.O)qmGMAU%UoH`  Z~ES P5HC[$u~*o 2铀=txQxtkBuWXS-zaexT.W]S%*mf v,5:TnsS Sn>P3*_ֵrzwwΧ6Jù-+*CHxoVb(d[o3)2tL̸nճI4u.REh1^8 4\RSrc2'a?cĄ}E$n'P%3@Bq$ؘ jzBEJm/yY~ :"s)R$t-{NLצ+'iϘ{4hU2CL|{/ Qſ_ S3&3BHܹ"($w;kIOfD!D)+w_}?I]hU7}Z)΃J+z ީӀ G3rR GMTb,ѱNͅ8`{tIEn/;xW8pAkNav5qsƛ'i o\4ၞ_Fu޿c*H b|n#9V[֭%vG,ή5S[^ NHLK?m5})m_M l( Zvr/OwvA ]N07vᝂ exw$uCrʝ p'|H^| {Z@*?ACHqOt*3*F<ƽIn$)iXfw<ύUCppZ}ƘYuϊ&~hѨn 3Q2wBlXӆC1_TT**Q#3PB_:?,egHymە)q4q`2>6JߣTQ% Ƥ!y)yzڲ'-5Gew#ZXQфoHq[ѕX[ ]8#[-u^ d~ЩoY!U"D"6wܔMS\~aT>ר+;yj s[*K;S%Ko/K]K`PG uQf*{0f܌B=NAؒJ~.L.*ylGd?k3sCx$*C9X`E%m9^X16~xW8@nPs~dd .T3Zig-?̨]`|r)}ubձ{[˅(+G_QVЎƓ(Qvrpm>&tѨ"*`+up@]~ zF4#wJ+p8`٬Tݱ+h%^h ߄fS, N(|U+;hL`ctEX#d ~rl޴KȬ'C">S(̄ 4 N"܎.,?p)4J ' _#S۫ 7_7hT\!V)vi>S[Q!<+n%ܐŜDI:[z:f3~qqѻK[1.._8ײ]751$ :>?Ad !_5cE19ď%i* E32t'w|(!̙/#RQ2*sXؿIg3S[* 6ac7 $mS=2ȳy|%(ωy$?*]B'YVt=Hr:Aql w=rT88ht_-y!e7;q?FyL:7ipiQr}²zav@qu7ESgڸeŝ-:wdRѻi1Ab\ YCq{HDƟD+RYo#0Uד&g~)"Wc2;Jr:ϳ' М3[ )(k' ϑ̒9OQ+ǰ߷Ta<ۮVRNEG>'i,qcx,%V[Fk'(iB-barU( ǰN[1n T9R  ˕WPQld;^VH[GP+K|Ǥ鈄 VmVrG]aUUo "*I>.L;CoYD 3 ԾФP% KM劒A>a(5 ۺ*U#F uLe>})@֐T~ wĦWP _VG!BJ} z=et'$ Ι`GW׸K{>^ ,9Z=m=i9 |AGZy?FNZ4AiZ.&P{i}U`n$} 'ôS~ND*Ls1-ڦ.*dKwGK˒s!~Dnq8G`NWuhK^ ~D5E$@$&J xk:̺G!o8%uey76 SM"|De^_Jh])_*hS*)Eiq^滐iD=E]4D8lx!}ӭۯM:( !, }Fn"u)%GBݩZ?R 4B{#JKf~'!iݦƩ>T8Y8y@FlUlk!fHD" #xK9۳V+KMH,]臬zzn"%h Lk_Eߩ襚۸i:y||YM.Y\U6`l #Z5e,IL\ۘg/mO4Gu;[ArYHzKR)<*}EY\%  7pm.;䘀 \SȎq1iXms V\í9!/qه!FB? i^)ibJ.5g\]+m&I2޺ʒP_b޽9 /kyfeZW[2H C\ea2 |1? T踙RtK-t [1(S"滟FeKAE\bPc6i4rk-c.6@ ! |Rӄm7e/<~خ؛l5s,*<>dzSTsS}I $DeoM}lVڱ_ ; O򌭹HpaCAQ#O@8@tUs#*&mȅYCǜ0dhuMHPX &aiuz$ TKQǁkhEx\ͣܜQ)e'G ߬`TL>ў:.C}6 6=uhHYZEv:%WWY>rlSB~>;Írdw| W7p+Ã=ߐQk+:Mz:ˡ/OrK8n1%+E F YgXf3DM/~nʰ6UYR0b&TO6%9)&+. )BS}$C+ͨNKE8K,[@߇c=ࡴ-ShH(7"Z*:j<ӺLTl 6O滜ь%Zb5rh7? .AW$RScJP40sdM2kyrG8au5z4zzrvFr}m tS S984$s ,P2޽eNsI[˃3uzp ]&Zi[^PtЍ}VIQ)i&?I"H46,5N{(o94S3u+Z+Ԙ NY⚶RbmEd,qtpKStBgDw:J|m1B +[~p w 'XR ŜBw63Kd?)XϏei#at@B4; [Ve<\ecUXu8zKսtsv:1**WWpU8א:xh)?iO|Uj^6Ao:#eEǣmZ - I drUiwoG("2P+cpS\,u[~hIhXg;^1>+$ 4-<jXhң E- waͫYk5!1u`\R(`p&B*kr6dAb;%X~j. $LqXZnAE;Ny*L94BM!\ RfZn6MncykʣI #0>E05+VN 2ͲL *[^T* ci~Bg|'3¥.kyOQ=R(ev%__WTPUu=yۇ:<έ7 _{m6I d,!yÊ r{&XcZd#:%} -sv Z=@̌]~껼Q~F ;1r#0Z˜xJnh`??,=<)0)jΏRE TSΨ/S ϱhr5xZ)m782NlNkuK(f ؐB>ݞїҐN/-H³9ci,>$jyk. +Xj}b Ʌ~9ð;B-"U֨-6]5RQ h =+$9)~g!?KXSX#sd4n_92"ܓab(`y!}3;xȫ⥈䥛?[?->6{7.-kb(!)@BtЙ3"ڀ o}F˦9>Tc BeQUpGZB<562"G嘉zbuJMoFlpA,ݗ efe4;w9;OYG[ ~}0*y<=TP!Gcݲ#%)yyFO7&wr)6oE25Ap'qQ1LX3(-B#r<  ^A@CH%N̔ǬB Bh). lQ=LLtC=]h HQBiʿn1r! 1-"k}Xz?/lYLyTFz34˒^Aې0Tc>XW$]zK9&TR?hh*EX=-˒Ca!:. XGmJ=ỉk]%4XꌿI)*t@A_7&Lu(>I%KAA O̺8)JSxGӟ?ʀ{-?pgϽ1AWʈ d )5ܨDuƨ|{X[~h9@uMY**g뀞]MÙސ){C7`]fu+rJ;,D\r&J=Y܆qO 1GY,)(;ipXטdغ,cR¶,fhUUݎG0jiiZ=.y]o{kHVm?Q+LŸE_Ke9z*5_Gso*X(\hz Uc%RC:NnK`_Zds899GW rPZ0?: rBc&(@\6LvK]9!iwr3]Ҋ|Rl(i|%9J,þ: HA$ees;Vpnn-9˼dY _C]Kfgn֯3nQ96@ZV4Whk]D-ҬG'`9KzX@"S4-G2Cy"+خameD L=c3w=l鮮4$3))*v zo]Vٺ̟)(8gmUr"Wڀɼ#n_!.q?.BGKSgqw3y`|Z[f/F$ץb@\3@#Q߂mEdT~\,0NB2[+U܊n/;4A5/8  Ql8>xd Mtek6"S0zN`v-mF;a''wKJB݂4"C:pKmB)7-u:۳5 ko7+P.g~bbBcM9,vw~8*H?b~Н)#RbDe DK8Tl2mgNxB/R%~bsprpkc^ aET<8˞uS짒W"eghI(\; +M<3Q$㊫+71uY70r~4@1.!= ZMIyFd׮YX A傝+b_MPdcC c?{ W`LWƸU VlSQP'-%0eH*S]8 :ɸAX*Ir.m< F Fzxik>CY.&l~7DFT()Ŀ-)N ~A.M jUdH…z5 ɭx?Cx%}4y%*<+}q*CnTۉ3kn.CEd?YxF:[ J+ޜQQMUdҏ,OC ۵t;X{<ڟ[V4&x O]=W{"5G4/6z ̍]L#Mm;}T*,Ӟe3H6F ͙T%gRb$Lo-TWRw_PL2V?~%fᥧ>bplERd؊6_ RQ0Q3`r9u۾蚡(>oUQe&y@wEN +F)K3ꢁ-ާYu2yz]Fp6>uJ+OC?Ff zz[ΝtcXvEkһ]t2"/pX ;uǭVE`x)LTjj TցTo={DNF=rIOƖǨ'Lf^uI|GAIpgAL*L3F&:psIUeCbidUx+gH?cGc*D]gYU@||9,15JzPmJJ)nAMڡ럔| :%-~ea;gkƄmHZaMaeQ@t+u693"}E`m񗡿,-!_')͘u$+ %Չb+s "{Q#@k T QDƲYeqbK m`#<#_R {Mk9X ]5>M!42sOWRvNiHj%)`xj>^2̄x>%$0h<\p؜|Wֶa=2P$ys @eMq]lۧ|*L6go"m4LXvՔ8nϪoB)3Mo: ɤ/]:Ísh6N`O +l@b%-/sK&&$y}+}=rv+v쳚JDd|E"SV aq>8LK> NsRps+:_DFj;FnBlu?Ob\R(l8}drYbHd*NtcĂжXA%1p^!LPӷ5tǮ!]F˭I)%qUJNz2=\qos&8&}v,!Wu*R^)d HӸ:ŐCYPD{lKjrCQh=\OE[ QoR}MQ$2$Ǻ)mP~Gz_gYJ 8f}:YDOVLB]D+l-{{VkiwCҜ dnaL a?1uO.sc)Z^S (_:蛼6wVl>V6Vk(yy`zg׊LjV <۴Y\1JNBDM\u#rʤ / 3slБzEP)lmVЍ5^w쫸J+AovNũʑU퐞 $T_-+.U H H>hVZ}-6x)HM9*v1Ԡ5jK~=*Oۛ:͠D٪„忒f/AOЭ z." B4O"1bR%Xb*jkK5|.)`Byid7dp>tPu<-f{Vݜ*Ce+Y5|x{'c [%/GO<Wwj:n:@Y;}9Ĝ[5c5i5 18CJxmE':U?PFg12Mj5|Zpeo`Γ55"X|qG?i5>YXh c}@byV<F>| koVj k*br'#hp=Ycp 򝜽A$Cgb b3Ti-ԬcbEwA'%;$h+2^cP5PK#mc$ЎqփM0wAL}֮ن- TEjhLkAAx/Uoaъy˟.:00c}]ľ_/`3m@d\MBrHko"P@ݧ?#(՗'N閥¬{kҝ, Cش /7\p~g%AH\Ϩ Cm3_aRmr2F\umx~ ljI!vњI ȗVcgZ= fnMh ̆C#,{nP. h^%PST-63M梵协59Sv"k;r #BK !״z2Fs\tJf g-ߔYҋb! U \mJP3 .K+g+.ߕxmZQʦ@-TѩE3;o "08Iy6xՇ]<kṔyu+S%}$Y5, Ν +R=;|%9RP&/Cqux+3{~"TƘr| \);BxԖHJf+bQ@/3v:ޫfXϰ=V&JxPM+ALQ@%5*q}c.:Aher/Ʀou*+i0OKC\| ,*q>gv_Yʅ7!PVWf /\lZ} ${ۭ=wL8$+ӇTu)'ecQ6 y|G9*zk, if;/+LV?Rb/sp,u >[ Z:H?m؛hkYJqJtS<Z;Oky]"r[~pXDމ@o)ųj; bvWYw/Aj3! `p%4&-E8(f5?9qo!IW]UJCǜ뼓iFZ 3 bQr ftRTZ¿rZ";2ױTiFν6kA&r3+L.mĢzwÃMeڞ<-J+5Ir2o|?Eȉ`:%6Q|3dkSQIQ*..Q>Ȟ\"|c,U vO78傹pa4e}Ќ/qWP n !t8;KYL9uɧԓ8eZ&<$XEl|* !}ǻ_O+([BtA4& P{㍭Rio *3-?&[A_Hm zsnf[TW!U3T F"uX_^ȴ)ia%hVL3 F:ݠմMًԉr+&wEC+=8zˊ.'ObVu/NzsR/`$ E` kkYJ(Ѷ5*%K'L>AZGB75 :7D ODe$`<[bX@Ân7uIe x3#YN7iMP;F[DN=Pm@W*z<5@Hҭ"0teh^v֨۩3Y["&H mBJP@ *C>-+Mte!B`co؊:Yh<=.ɼzky@~Y7}ﶞ†NrX%DDz,4oV X^鍡wN!_xuS0|m!8iY^ƒgIC$dz}W^\ڒRk TfGob VTUYP"ObI e &ΗB~|QT8m7cf4G24, TY8iP"J#@ĕM{;WS?T{xrR>|esS8 8$wqO93IKY'yp[B%֜S7ԽsF $K)9`[hb 9dt#]$kUޞą/? +TJDڻL ۂds;d#s #W94CVmĐDop(6 sbJrQLrQ; Q{TKit܌b: )7niPL"MG' UR2ءr||s*,\_Nl}t0rCP4Vz9J(?QY4,CDjm[uRC~ßU> F4?_!/fR=LUn9 kotMxsOG<8>A僰^.m`=Y;wfqІ"reV'T]ӽ8qӔ? w%=!&%B`S~Z/**Y¡ 81DDQա&H* &,| XnCjcGM2D}἗Q bMsR7xܖX g!gdPPP 2DkN[~m=G ;g!kg,HqSJ^hEelrR޽EgZ8TLj`=+t}ر1EB=U3k)kx Yxm"Gb'R4l([L6Cj41Ҋv2+_c]a}) ^TvENߚ+xPQğȋ>o;< Ċ[nODjlIʰDŽ ėw1#5~G0yK@ݧ5u#RHSEZja~n08+{ T0:$fnyA a+%G1}-㻶[3Ǽz>7xkb~d[<5ۡ?ٴnC;=F//+ ~cOƛ| X| ADknd~iU[ϙT(ȣ-Laϕ_59&0pݓD80=`74_|I !A]E*2fbARc7%,)E9H*zs3.B02KKz Nىf8::NPndaGXj!@PǬp(YO̢?L'!%&gRLPfHlg_IPbϔ&%{)'I nd.(}Jx3,L1;d%NvAAP =~'ղ#{AtC$RWtj6Zn!v ^~gB~xz)&,H R"O 3Gv;lTs*Dh@R㋍z\:r簛d"6NDbhIҙL}wfZ\XOka>AmW_,8v,?: F(v;+o}k!Ih 0\3ʱT{cKŦ\oA ~.B <͜+Z{\FC })xbϏmkR5J`PTRY)ԕ$@Ix+?'¨$ir>aS`kո{V B$\{YHJ2ݐ_&!&o"sƀp};BNWqr:ç\ȇ9cTToܥk$;?ŷ>fF\2t6\i(sɖyq\^֘y7Rݾ:<2%̺%M`F՜UL֢ S[)]`]y 1@m"e3SU[Y!dnBp0_yRͣ1BZ4A2rD꠻DT4h2GWo `-x1 ݢΫ3r yNWRr0%hd#˗~BY Wu䧳yB/dWHzKRfK,^֫Y&Rd9[d.M1h5孈+)n{s+ W{t]|Ԏkn\//<݇d3 s~41_7h1AB4&ZɴޓrYWWdwwq1k֛{BQ,6h fNkS/>ȬTU΃7#87f&^!(D.<3L+;Y G*#k0])]iVB'%F&0|9ϝ^^C<dۆoS#i&cBD="OLf?@礳1[ ˬeK=Ft^3=c3ZvoJm\lI%H2F+u!U}tMqn!ogyc$SӏlԭWEjh%ؗϏڀto+YaH>q3^_wV~X}0빉LUnle#3iQ}9`yPɚ,ߊ~U})Վ\W cY-Pc~4l/B\Egz 43W6 0n}h6[VNɬ5eE}W*5oezγL|sX)Ƀ$f&hpkGaTlKo\ Ȩcc1J?ィǸq!YW\~"p*Vf]QԂGPl`d},lnOIߥOuk_MݱR0b ޵~gz5`u<H= Mc@ ^K4W9aɱW83ȷ ֲOZ01SƜ<9\Mh`C\Kp XPsDr~ޗ2-[)|.C ^pB! "; 7@ k~^Y7Osg9=Vk\?4PB\2Cf ޤ('xX)ʞH~k~-~fUt-IY7Ԕ/ #ڔ-"8@35Ԩ=?ϩbQ8ʖ۶-d,wM FqˢAS =gZZP-/+qêPnf%Ŕ%)# J|ݤ8hnfhzJm{9x'2"a@ݵ<YʹdSb:Mra[~٣(o+no{!{!(TY( StyQu@y_DV]$+̼T\jr爧T8 ~S77b:\~&i]Wŗ'LC!Y!֓I"j`ȁ=HF1W=E>Dy3x!47!m:\0B7J3uy f1=8ڑA xL~Frs={Oi%z&-c\qx)tS)pw ϫPX| i(.Or0{Ш3߂2/r%'IҀi.+$/1\lX_7˅yk9T srGG(_>(muwԂ ;W7hu9$b?'_яLZ|>6 W y6|X^q~ u0BfR(ł٢³s/$@L> Gk)/z; ti~W~$}`g6q;B$m@'~mU0v:5S?\X*h9^<(V姴_\<;J1r qCʠlo&>lIJdP+*f=_`|猃n1MʏTX1BӶO&ve TC>!-MuD}JdQխ N?dCc. T$ 5fJRWON\~;  MZV+ID@_i0Y;\*nC#>lpz#wSDX'ef 3ogm!D+,)=yq}%B"w^&IV&bT(!I^bm󲑶# IV/~߲ʂt)i["̩ytA sG 6 ],EQ1?:%&TԜs[ε*ޱnZʞC+.q@bFH 7O%tIxWGg#t+L6$q ;?}} ;M!Ջ%rY0hqυpj&ʝ5`h Vnm'8zХl)Xڗ!AxQ+Q$AQ5F%D ^e6Ŏ:{yb#Qqn0 pOْ;n Pch(Ĺ2Fa}a A='oBWL0>0 Dg@{/*2r( ؂]IyM6ctN~<ԴVNvs)>_~!OaSC. Qox暢" VWS@nCtA& GὟeb]UjMMqS*( mW<96]JD/5!{x,ih3Oh$A;oR}3)$vVgZRMXi+./ P ,dgo;G ~(Q4\N}S8O a5Pk-]n.M> XРwʐ:v :zo;Kt [ON'Ev5S귥q#dwG©z,ZaN<qK'S(+Tz9->g}sfj.ЋҶ%7z0mK~A9>,ގ@i*{s_~۝:]-C5|җ2O G҃+q25{뎞̝ټ'YM gHðLJ!ofȐzcΫg~'Or>]P-Zk=MNh3eu?n̬%Ruh~M}zIK TwS֨V)4֓ÕHц[Ǥԥۆ9dl5MboJd NUz Lp% Wi#mƕNKJ1Pg}޸u%HJaUK~ :vjM=.;eB{V'[iiD  h:$K[IàIQ0BrN,C =SbCa.f}_ mse:$cdK).j84+َj<뎌t8Q/P *DD F&^-khʁH 5>V!`48̈́ B4N^Mhpk[[By~Eb6˔7^~2 f+fƕSii xn<<&)hx"΅.wE}018Y+3Q5f ڥa);A*-@A*ny8-~? Uk.M}EygHs %?m{t!ZշzKox$6L:?yKr^%3Y_mEn#Ay$ d8Fa'd#Ug%o4PG!+y^}VBz}Qrǧ6Yu;z.AV}{d@j~AuZs^kx6\VBN֪枊1{a0 nħʕ꧋s, vVYy=y{=en5OFzθ `}cSKS T[OXw{y'l:,Ϗ.+8ӗ3`:c+-"tlکῲ _Ѓڐ5߾E ghTjc.lNpԂ:JպWIҹN@tvI& py3 Iߓ;K3初8fDO[b#r}3_G/Ԙ|#9 |L/V(7$~4tLCSe quq93do6ofQ!鋯2TAh(wib@zk\^QgCEۺ)Jg?#7z6pNoutxiLg,QK{Ήc,M6Q687p$ AN}Pm|%fv?#aL)tG_?Pˈ[c"$s*_Ҁ @].O(+Vq{ō02i0j'!ݎ,oVЍG,\Uv +Dh$yu}5qr'.`1Lǯ3s}Fy$jBk̯+ a,wi4בsDy?Ơǰm'_mi!9DUH{O3$ڪf6U}_\A7T7y–灹C25[ZBh(zsͪ=)&Z4d,YR,>*f*ʖ-l,0@Hew}ϴ{( M`3^ČSp ziMՉpQG0u몔mHQLf(n"c;sˬ<%\./_Zb ]<8i5zn($'wފL9.X2iV׸FЧ[Œ4>" AmGŒTQY+晴 IDt*R629q"K k鿟"AAAb+K؇ˌha+F|c`+W2|29lmcp7yk~bi7rطg}Cn(H8R4,r5GPCZk~Q{3h~Aji!򈆶~cN׮gnWDzᴖ:<;Y%0!eI}`=T7H{25Uanz= `pNpK\)[^uUXDsⷚC!6Iȃ%64:YБ&YMdx׋yi%b10Mv~f@vE'6 `ڷO8Hi3b,4ܯ ̵NϛR+)YDQA!N 2L$xMГ8;/eqq5 ,D$'Sڶ?՝DM鿍e *LZ"&%xc7L/jJ :[jC~E?5NF鏱[<u=3-9ۋN՘Zs/^-KӘ-^2j](SVȅq RR3CAT;Q ԀcOC>5- rnjrEY |{.}X )|! {M*b_?g#OcZkքyGtp AvglX%rP_2WxG> %TZtܬN?]D4N/ 6\+?k3}z[G>h{Xw#@*0B7#J_mQ :)i]#/U[`i>d N<>j\1ZaCO o_ءwƚ”M&%iK[a]A/ Yu%ZPW拑.q'|?A$. C6sFԴwcB/_񑍓g3 1@2ˮ(E5m16sEf&|rp w}.IIzIh&H\,>>16ou ( p̖;~IGbw t2mKG!?e[}s3:HϚ~.L3XeZD `ʏi[E5alH:N0a 2wߒ _PtU`BM%aIj'cķ=:<i$Fb}-oD4'7 JnLƋ&]>}񋦞rhHKAA'Jxt7~q0rö(;4ãN8u J(wm엞:uWs UAm_øw QhbgI(iwعuGnڏ}Œ*!_t!> 1ڐƄqT;@NZ~ՄѶΚ-h96pxu΃l5(7XAxI/W! 1J#TBG_L8su\OVkSK70g.!;qr"jwqFpJ7ܸɋ=a "%:#OF4$PcѦv/ǚX((jρ+@G20G ŧD9f+ڭz*s_V.G>QeFA$!ܫxq7@qjgMK_H7e*0b?/a 2Vь(] z2k mC{fKlc/ _!KDZ|2DGC&`?jw Ŗez0&b췓:R0栍/~Żev$u^6m~Z%|8]nu?BgFU_Z$Gߪ8-FzY"Q Le1ɨ6@/:6U?kY(qiKH&V̲TM2Z)nXI |L!X%/*>Խxjγ?n˪vhgO2O4Bɾ2o$^26%ɘM֯70K:bˁyý}#0:c9Bm4~-g΅6Q *o0G&luzI -D3ŇĘF#|-Bwt]P5!I5ہݘRۅ=YWXQޣHLTwMubϰ >O1CI҈_ICq;wu@8Ҕܐ`1ukS$LbaUn 1g;N1b:[T}=҄q)CӑϘPԋŵGQBkJ*zdF_&=RB* `X]MΥUmR޵Gg\/BK&R#nNqɡ3P WRE|1O wH=(|̹5KĎmUh 3!JzQbvñ s:4 \3EϺEek;C9~vJS&PڳswdOf}̓i1~ѳ؇ bHACC+Ga~|LhFY﬜8WjkE1sROmN$BVµbs9ro!H| r4Jw ||'[a[P}m^ⷫM&&ű-&BK,/|L#,a};*)5( }_炵7XZ0i?w&ޗ( ?n+J1ysK`ƶq2M#.eߐ1\FW4SW-n7K?ױM*,D,ioYKڪAʧuJ@| % <~!'ά-@RxɆ,YyiV 1JmB˥ׄT<[Pbb&j!zAoF#BkrW.˟ :ڜZF !WCwb_0.?C7,1Uڐl]@ ? /)[h=8Ԝ_ ZLCx+vђ)5Z],JĚCulHz|<(6BրSdw$q\L|{z:YnIpJrاòBgV IufK7x Q#ȖW!񀫃Yao5oSS?ouJ0 oiB 3gpz ?4*Йu9^[eIP:wD"ex!ZeیQ8 w?uWo]U$F?I|o D lA~kT&Y^>35ŦOD_D\>3R9һBߕg䓃UrrWy6~rdqFZ 8tі^uLd S|;]Ĭ}\PgWG)mG2h~g&u%~F`gfzTT|Քnz-iM[nN <jq69l]Ў0S)F;8IecwQ2W)b ܎ԨL>5Lc~`|[FHKq-ހ.XL2zXVA2Sz}CĺJFx*|nRVAZ"e (.ҥ&qGJ?@T$m@a0rX!/o$<'^cV]q@d&$sz|)\0G*Gg^L jnr(zk/ 'g<k&:Jtp걆xh74m/ێR.pC*Y22j6w׽QJb!['uNtf u'H@ca(5ȏS`^Y_3aitM *+' /VҚ%ȌEbS~"aŤg>kK~Y~M>981V LGݥky4 KK n>hk^;.57ۃLh'C 6;%Bj[?^-oU;&r77^x忏HU0:WHi4 „v|;:H}9zBaOgq`Tg=ڇБYeOm$PcE.3x$eIKH n# @0[Ժ{l^toj;ԑǑ# T,in/mD%h D[۱Rpȁ"*ȭ*&a 7 .@Q7,sv:ƹdv>RCK Ōpp%BA*UFx)zΤ3=ھHh=j{ZW 1Y_Ak%Ӑ@{F0!u4u +ݶeְBfCN+˾q'6I gF۟2ܴ0Wu~b>ߒCGQ]yu)ܥ1%ivAAw+Q- z&4psۯF_X4ؗ6YC0 6HWRj(垃 # Z/1Tx)Y[]0*`u mDuiē%X|OJOa]Xѽ~J;`fݖCHQ;rt"k;Hs(nÄ-Oв{YnK1|#Q' LPs7P=f?vx~#Yr4#8Sy\aPkx@e-n3(24N-^ A*Hk0T \dxXC2?fG*ZJl ް)1QF-aR5I[ͣ9c&z'ӊ{[-Q@:p!a.^x =`\M%mVAMb0+m2 vk$)>jTCPZCKTW"3ýQSe w#QTsh~FM`aY7Ə)yshjoG+,%HmX8ZzwQx5*%U:|8xABK t" =g[75֛ƽQbM4ZLn~4uS+$($K&=%=+ L.k\;8 ~ RLqO#yׁ, Jl 4b@ z!aTXl "m( -$a~X]mREnq$/WI|̀ATWrL∸Iڍ !lGq pGS$&ܡeY㳿"Б2%aV`MzL'H(`AIA!Pu'8ۙV-_H:CkⅷkGbw ) (K`2 u]bJ0@zdYЖ$6G0$$`Wd̈́`:Xxi{R-&oo#?`nje“ KΟPW !(E6sCi6/+c8 At=Sh*э]  2GoޱQtςMaό첾FůC0ᛧBא9B% g(aY s솿fzjQ)$v(<Η ø2Xza*伯VL; it{zTjš7iuIۇÜaYX65(50lhz ,9ϐ]tT0oa+Bs(O5Z(X+E:itSC5nì3x:=KȎvO.~'FQ)#G }Jh?XcSs ME|4| ~\zE"s+cbOhy"޵Mb&9"x@%3*"xӗ)3ܫ+ワKAQn1$I#4ՐN6G]޽S :8WFBxH\Lc"9N)؇w[S ݎ%P#5狩GbmBPi׀ۡ|ɮ =:+uR&X(9OAޒu4}Olވ**#Zk5X.È֣@ZlۻimA!S-Uy15}cZS:F ARD)0Vz hhhE5F4 /ĹDCWUudy.؋}p%8ETug%˴xd];5z>YS4C͕ J,vٗ{߃'{k.(:귫\as2^jbљ \»6ɵ27G|y!_.kEQ>.ݘlxС/tnM` m!#腒vۆ05XG=)䍴osP*8fՃu#u3cP;GMD I@vzj *&@M6(1ķ}䏮mU0ůvj+ nkH|KI]@5O^W>i.b`-϶ۢX)x8:IGyw& ~kRn9dOdΥMYm,.E +s3. uޏirn.y2{4SQtQ%xĻ‹K.OʠVPn p%JnE^xlY{cXKɎ{pQ /z&_b5o0Be$EpukyNCh&xSj]øİXfM X mͳlP:l4u5(9(fW]~g l <2F0hQ*0 eXjN|8 z۝f7MU%[ 3&H(Q9=z#?yO ovPy:W/ ~dq56 uV s<(ɴmȇqz$)kqDy}wA}Wð%9eJi^W6  șh}wCC76虓 , _{|,`Pu! \}Q@X-Mr wsXqSQӼk_aP[R$u5ff<hߒ6cF=$HwJlC6Q t 8qzˌCVS_ BЦ8<)&VXhV+D>*t)Z@\|ptTE-T`o=<2ٷaT~bQw\6P0['1Nm|ݸ8 Ad(iE'ckAMuKilKױG~~K;a -wR/tvoj@B=F}V_^ыFe.cüS h$+{Θ<}W/F,$Eʗ[x*E6p0H`%n+Sp~ RIU >\.)tH0oH[9)SJzk\n{)lUE/PD^%Ò5#tDujK$D Rg)eg9 TqP1&NyPB}v%f#qeZ~xj\`ci c|~mYroN <XLXĺ%Ϡf
}jˠ̡/IӼQJ7|ԯǛ~yfzw.n]eR$,r *߷ unfK4S_h~f3D20o8er 9~Tj1W>gA3W{p_ڿ&rM.T;_RNC{HX(]T1Q->^ҏA9?<{?`y43SkW*u8"G8d2eξ'GГkeC,K@ji5"Ox>#f_|[i\Q`2N剭r/3Ψ 1p!"(Zw ^c"X1]nF2|e?HM`r qQLr- J //^/p%FX~l+ZcJ;M(9<ԺG<ʴ'AG|Hg3?f;@0*I,8^Op ~d 9,w~E#2dG4!;A7[hK` |iD&%TdRU{ 82QĻ-D)}Cq?l*wRT@Aj xȩɃppNY7%MvR&@L2/kk Ec]$KZ~]#;+*@cmT%f dh :cJ!b<Ο@Oy{8.G]KyxNJL xpj۞nܒYbΒY+E]4QLZeWn6 t A qTf+RJoEg1,BU'VM=0t%_k^r hqlˀe y0+L[ Щe U6֯vĺv)JxN@`%Nx'1ǑL!X/( 9ocP'DB\#@OԳgz"2+1m|I1xw2*d'=KQBkPt%|Zp؂CLU(p4O=<h -ھ}{ E[p'*ּQ1.K6LhH)>-=32Ę#ڗ-.iRFZX) $wP:e>4:@$3cuYfl6h~]jE 6NNrA=d${xƂKkc,VV3Q#Vv%F (WU;Rka;ePÊ|mlFH?paˊ~A^Q IfMdqp-_{ mw ʱz <-t6O (Iä6 DRފt! *r7fe& l-wEPACmol]=D0S*v*Tx"Cw[AUpHc^˷rt*1v /mDё^UPG^Pڕ3">wnX:&\Iu%ԙ:~j4w gS_6;^$,(riW<ٌ%m:XoZK]RnP2dŶQ 5_[I4U-k/[Ŝ&)DرHsAڔwBǽR%l`:bslsTd/_X-|j8} (k _`yZ% kɉrZ'0)mL@8F ԉ?CV7S$&Ve&CN 6O ^ xëg)$J:㙌cʈ]_,nMs!j=ڒGiGz*51*qRR׼C#x`_k ‰'ZC;Nz .cؾ<=Qp𛤛4Dj @aNy@1nPqCza07,}@g,W=oΥ퀧-ǵ٣˲ Ԩ;߆vGj.!}D+C wgȘNkr?h?saT^Uƞ Š28|aŢLbH蝌 m_:{#&x3I^:#9ʃ<2_`s2!.Q68yfMF;dM#̵s q X=SabLS։IՁ)iz*bgcKݱgsǯF<=Iio>CZ8CJh=x`rz[=m#Ҹ߼/DLe_%Kw™9`xIKo NuJupRFM[.\RT;U@EEq,iR֘МEؼ2MO('XMV1Lp rJ#'0YqN@_s*l!f3 ʣO԰5[|Qti?+gs~)C!Fo UQuTߒM$#K/!lYl*d; gm[?=|sOc㰺c Fi&e,IOXʻCg96 !㓐`)էP3F0`@vFs/h{6N2).zǠ3 æܧ\I7îJ(k^!ʨrt%JwSnjLLVp99E(4m/-%#jG+lu7y,wI;3umι5h dLrN=FAW@|0UJdۚX!Ѥc<ut ȈG^?2)-k~Ґa ސ|Ul4|df3ԭB@Yx *p0:TEQъTm Md L ~!\]EdU!}#$ Nv5C%<qU9'x'n(;KO` #u4djrM觾zs%f;}v#nZL,}"-cNy+s3p 0=urdɥ>_"0+g ZtM ݛ Goa[V#GM<^ESnV6"WfF@/-R@?3 T5L|j{MQ~ܛMha _\2_M|0uE+bW\2" yI]0vnVGWxB 1m~Z"c6TC25mp?KMG)w߰ ȉ?y/uŗ;`Tp aYn6קZPsiP$0Q*nNlϋʃFd\lLjIp[?A)ɳ4+lbt3?ܒT 2\\5M1k|=2 _|ng694p%Ƶ݂ԝ>m!Oغ`Bv*f"Κi{I2q*s7uFPRJDdܹp9!.䊥;ͯIE %O.pIjhzu-8L8KxNU 0}QИR *ԿgW=^yktfd@thu; +H1k|jJ5OZpJ敥/OWT'a.#6ryj/D1oNƚ=@ 1Eۗ:pۤp_ |O#=uIU`X38sR?1aHѫ7ϣ̻Vy\z#Lj@ffҤ؛߃Nv5LGV! #ÕNq!b&,I"aO$*6:O`IZ/M^+ o&5B7x6X] W|e#!*9Xڙr';X"`2c]SN_;|̹'HNVEȦ,=:0'qs(*$o͔Gh/RHv0aL;uvۖMoXFH'#3im}0XmYjqc"/8؜؃^CP3*݋ F j6+|m^>i"vwGMռu/˴IaMfE&-"3T<.NLhh4?5ʂk8ܸӬ; Njn'%-xB u8K:JP򿴇' j3Q {Yyӻ' td𚐪'oj[4:EnN;:(|9~#k2ZeH֎t C"8a[߭n""1o5u|Z0j\ȇ\Z^:搝_bm :9<= gwA٪y41V tk #1&ZPy\NVE}RinqV㣞uʸ +9OY /(k@;J۠ʓ1T|pZO8A%,j=CuPYdk/(UzxJ^:S@zܔ)n wR1+ իl7'H'<}(Td(//#W>0>Hݳ|;r8bpoӂyJbMtb_< 91yL0h'qϝV9VQ|D/zĥO.ž+uD [ϣd0 |2T$#YPN0_,tXj7pTK 9a+FSS]Κ 7{@پGPЕ_(t%vK5jb͠ي͇z]*u}[a#_c"&6ɃJ[ʲSTKbi `0\7@ڎ V}/1Ğ<ګ8R.mOm6yn-f~ Ȥ:9cK.o (,Y-LaA@( ]b!$-Iʄ%G]pF9f JV4 R U6{$/%&qbּ"3y CsG%BPl q&#f1%Б⎼IwXJ Y$Idżzb=zPz[`qh5{r)B`r-w S:i [%pRψ A,+::3B7}SHi0N?!,R6w|? $|٫@,ia&]@]갃lUހ{͘cfW)e 2~G$XwyKXc?_lZҾY2Ca^)?h47 *'}9or5DV\2a\ d4dIz:iJXIZ'6FEn誖T+9WN!{-F(PY|;Ϝi_IwQ FUb B䍕icPGoPX$ kg"\ |xj͎Yz>DCFjxTåhbYeN8ߔ̰_}r,}}g!64.xrY(Q3x OE0)xd)perzr8 c=x"D𛣙ŗC%}0gMg#Zc>$*#B5M}Qam ;g=ذoaU$q1<}b .Ń6߉^:G9ֳP\8OǺ7>"?,yU7~^2·иr&:';{OqJ F~6Wm αz[qoeW㍡1(5ɤ#6Љn֜9ؑVk*Ob͝Ļ:ȭSxەSaN-T@ `TmAӊm&1U6>H nT‚@{e:c[V~ay!yDTaT\2ui:[_joȹ{sLQI fjRf2GإiAq:Rդ+ GŹewZfa7?L%Z]5o}Hsרw.K`d,B16K1ΓEN`W&sEsq վqʻ5 9%?JR/};\Rj)iz;abT @)B|! 7y{7 Z#* K9ɀNO8(: #i}F)gHk/ڞJ7>7г򐓜vw0u~$eZltHHdK;VW-y^=˰AT<8$FM4N/]z u5oѬB'G{B׵"RUd@R `Hlb0Ow~9~º'LN]J]n0"X8Qؙhgy!l?jTxmx7KW QvpCsV W%.#tdP%C&X585G{$6#Aȟ2U65咝Y qR1F4.~`ޟsLLz÷>vF#~hi.0kH uOJ&T+S 2Hf_.b0cvA-  ÆSvs\3vW@ 7C9bH E@g$j]Օf'4i=žbJ2ӆNcʲR!*?C)|U$Z zCV.N㲇34䝿*V+.r\"V<UcٳE,iGPYp M9isK rp DZFK;Hpt)Y goI,"]\pEl4&Z9*8iF6lkӒFi@k>|6[-l*bK^# 1>q{ԕ'eNxjHYT9~>@@ez\/)3ܧ0 z!C>iu>3't]X9#*ݮ;\_ufS ˏB,H-!!=e1]tnvE~VJq+E ~!~sA#|D+P5seՉdߏ^ɝ,XIˉ& 7zݱU5xɵ[(Wt*A|76T3+ !ןL-:rt !s|]T=y͟pJ쇘)ƪHf.{I4 ǦYVifJG 8[ X9pG^MeO-)|\)ё0ϱ8QN8VqTIZ+{]ޭn.$Z q7gգuQDF6hy#s7lېL/ڏE3'oŨ ?G{Jh#'Lʻ]⋇)f}Xiap!3񌣦JMpzH{]+@Z r^fDz~ 3fPb-iэYUٮ)8ۗuc[Vx, <޼3!uޤ?'R 1# ATh1aD=Q=:&g (VHH e6 oۏghqv*j k" ע ]kRs7"=\ c,^:MEM6C5mAs;_v!~zQXtˮ _G>F6h0W+?`~MP.b ʿX>nA <7Fdb,y֘йJz` BETW2o)ot.SM% _ ?K DbsŃϚWKC.낝ޣ(" .(jp'O{"{(+_`CYu;wd4۸~fȭ:UWםMkރpo`4=QIfq0 z^ݮ(4#“r OA)tguxF ^obB06>C+[ 彪ʼn\/.o2? Yw9Ogo"kK.^'6w 0S@YgQ}bjV;p61y\i蝦@H/]&<8Y_̾6A0[}_ ҽzXv:orz|%"{~N!&4cÕvY)Qlƒ71G|X{Xud²Fk/U_|iJX%578pqj;[ua”>:n։X`;[3|kڢ煰#:!$4xB97{Bq>]\UY`b|x#Jؖ lD6VUZTHҞ~×q)\c7؉nNp @qj舎y5^œS%I vҿb  Rk墰>`8@@Qä%Y><~sdOk^և: 3FzA ^'NΟ0=A[Jx8 h1^&?cgg$'Y%Db|Zz[ߤ^=/Tm}}7})TUy>FYYXFc}yS<]SB|i(d+#}0ϱzN֩7nF"0_Q8@AZ]=p (A7S݆s`~s3/)CҼPuic`Uo1y*؟yGT&ϲw0l g|l) D4_ƕM K,܀jJ/!x[cL![ =$l1bH_'zM4Y[D(}x5QYz'DdGCmbHI#;c ֍ G]vE⩈PnF q kG'=#Uw.vdv77DWw9%4\R:-ׁ23R%p ~22{!oE0#g)8[# cSpGUO4vO!tj-<ov̐3W-!#Ho )h""M&$B紿#oF1lah8pW7)1do[n볼Giɢ5a]lim\w›Jws>zl 2ñ Z@&%QRr$F%g*8NHF#-BYOa/Kuwa糎 Kd&]lA龨~` `bU\LPs5sT(bTbaD`"_6m̹ӚWH,wXe{|j;w5@`_l>H3!d;7,n]o g|6g0aHy,2:r#m*Cl1:+RJF(&[FhkQ{Hm7M.u%5^ *>~y1;2ے֗1Y}%kxB~1Zh␌lcо'(-Tvg2^3ܹ8͖oG? rþlۼ5Q4xPqȽ8²ؚ!P 32sYQ|r=~psdeuv⍓f.CW>yͭtQE[X##&\(s[YXHUuC9 !AP\SVQ%ޟ$r}qXh6o +R*jXlB kS"+A/t!}F11cwyO=J^c8 Z{}<m~ZMi|ap0Rӄ{.̖Ķ)[!bVPIkSڹs`g2.uP+ߡ<r\-ƌS{/冑+S3R?^.y %=M; m̾9~(nGƆ'W\ϒ 7bM8kGqT8MaFq޿߭PkGY\ >l'' ZΩcoV˚Իo{ +)7]7R9@\KQL{V=/yqGQ0i:2IYˎ,p|uRBbam@{dgXk+zw='+ iHn 2˫q1 0sjxS1a5JQ10"Ĵ1eD-Bxu :Me'< r|RgC4*Qjt쉹av7kN "_!(!áis5FIG7i:|T1~ ۇ~}Ɵ<}QAcIKs0ydM5TcVꃳh_ewqLoBUHN 1W£`NlZW6P'Ol{P,+YJrW$޿^Bwa[A޹7HK 3%C .ztd/اViIJ@%6mZiײyCΈ5 h1%.`~\lk @{j ЛG^ƍgx-.aJ+ yE$Lg:F61ѕ wT5>{Q<u5l#\ !BnD>|u5Cw 7d."%f"X˻0s4 rѠ aw0qk3[2aq3ѣ C Ev)\۵ִ幺&@aZf#5Wr-6wx!a1c^=/E|v~F\vK4w?ݔ/׉1t<Mao<7+ I_x.%HkiRf5pkim#!UN)Bu .60m+fj8Ey 1cz\69 T}(Ap|R`:yݹF1Pc?P؍;WUSse ȵ`QCZWZ.j H!F='B隍W0\~>8ի2dnh#NKI⸓8%}Xf) >PGHىFD{>Tڙ"^!?/5QG<|^'~SC/ttي`kQf(]79˼|dl,H}֥V&6Q[6{F/׻Q=Aسˮl$RD+lJc/\OYQϼ||9vϵcJù0%@⏞xLlbĺvqؒfj<7N5?|Z~cTB.UKm[t;ST.n pn9s9'XJh{s{z 7N j3C[51 ﮿ r/=9s=4_?h eGlt Z/Jɨd]L*OCsw,ldͼ3l^?]e%\LAK-@ٛ&"~7b#4qH`ϲ8:͏f3Ð4"jӻ#iM訜"1;,ԅp4 2Y NGC,$o T 4BmXIi'*/uv~.9@jYt\n:!Ô==S%Mhxˤa?9BJǰd/|YFX)&0g'~D+dѾaܱRaDS6JUmHFΙt@BW1_ɁP _v<'W'IY0be%,ֶ1\F@lҾ_C\^_৸%7R1HEٰ;u8&(PT0Ms5JJ"",XO3ނFTrfSXzB:|ݎ+7瀩pvt]"{/E8kwm!ǮXON/Ϻ\AS{#-[@ K^\ u![T)9mD>g-]>IJvaG)b obYK;a NQO3?4 E`Jrj7.# jz5' 6!~Mbgiu>zc$E^;<1Y]i=|^']71F21@(T+^8C/e@,PfɎ!":&M&;  v;93^bO7a71leɉ;$ϚXG'&^r] ů!ޞ#0ːvu؎tvo%$L{c%KU;pQO6o8H HlhF=,g-M4 XLFn޷c~ nK.Bx3nl1 V$\5#%|`_U>R/@$ESVC?j72売̹Kr!단㙤us>^;']QutUjxFOeiW7 9Bv ӂ?Y@?~OILX&Z@lxڳIx)ڎPx/|+xhYMYlI㷡EʽnG]bܴ YR ;^?\ZrMS<'K3X{/G,gqz9ok3asi3U){2&<6<*^^dz|8X8J뿭K4"gih_Cnt?P+\fd2TC Y$x4NPiE1&9T`N31qg^[y<&24hbpe ʂ>7Fx+a^>1ϭڸqgn(x׷PoqrȴI bkRAr!;S0ӓ;"Ik gfXV&5t! WbKؓbPnZpu0bL/ot`>D^[&gϝXw2lhnA b W`5mM PG~r wmWOwJCQ֙ZdDGA\ U_48Trdc PH^'6ql=-Wr'$to gvОH(2"Y09;$x**M3 i3coG9 qħ`U"#%yRb2"M5rZ1:[3:M Z8 }C }%g$]myo6bQ:{z%;;ojt޲l+-ח %$*7W59#]e!)CZZr{0a'?ޯHC[$k`:PF'ߐn;e$_ˇޯ6x쎷a~0nj[8@vġI}9OONH{:%lGH^*>~Tm,pK2҈ޱH^YD Z;cg(.\BY"Xʐ⌿R Q /O|q>499r0l4uڨ K/|53Ă\E/~P %$ 8E2J깈)Ư`նC' !mbA[<Ù]DjԽƒ!А?CGMbv)ШUs12 +3$짩 &9LYFJ8_dЄ ߽>̌?"!{-nm*ljn }qn;ْ ] `X.v^8: JSf2gY3j|Q`1 ܔ[)}tL}L] u>rG#sƚ\_n獞@5T|?[ӫ, bG+nr(sֈ.b#` AE!V'N @3=3/CXVFqcBF-25ើh\%ygtFݪcrM }, Y`2Ui1^P~[yZτkx@5rFaXug &d[Z]]K POFNA:.v\ؽP eá͔r~T9!J(4ZAEbe ~7;DQ7x[J6Z+[% M hciHT&W+od(Э<@nʷ)1,BSC]";RhfSoKnaLw$Þ>JȬhƑY`SːC '҄G{Ar-7+tʐNӇuTKߩMC ])=P;>n󌢿q\KmII>s FrǸ!e?\ǓXi&.+A4hٗH'Pq2!dN?G搹Ƨ'%NzkéS5FwӷVZ ZQJs8Kb#ЂVЗek܌I:K25Uxo>H O[=u%X};R۵<"YW=LT*k'kjMy;y/`$Lh8BDPe 0LG3u2>iX fU'nQ^eTjOݮB3ܧlӊ";je{if_>BW'u9% +ߴDe@ʖÞDGkõ DwpZwz4,cDz_=>Yp-$O[}P,ލLr*\w^Pƺ'Ȯ-$45'"m{r0_]Ś'*I@nA@ȞI}'mͨfJ\ֶ [vK՞ӞkdB$DmwV_I6f딑*82Ž)㲶Ҏ_Ⱥ!25VIKRTf ]\%Xva_vqDC 8ҁTޭd*bG?`.e1K7<,;(U)X/>V3 ,LP䱭I[}.&\чujTfLiD5p-Z^5/42y#SF:ǁ鱎 Fξ9~A|M^f+HqO`Q35+ц̱oPqA7''R˟|Q (HCr0dꬕi%R?v6 αY%%n]& s0E42(fP][Ԡ4.{Z7gcMqxWU$#k {ZD6 ڸR&ܧ'e}@ V oHL)Zyy٩xon:J՗̅yhlFrAL];CVzFyd`[s9,kPa$% $'c& ?1i3" H:psS,Ph4-mWtDuy&r. b qՇjQf[g=C.=̉V@f W<ڲyS_0I|oHQ5_+]x(w\H:R/;3 iË0.ߺKi0UAbAj.5$ {2X/nA9nd1U\rq'*L[ua$a hg/٩jWھH*d;]/vbeZ2jTh^*Vlm֔Eɞjc`@Z @Y H T8j(9v&K~<%hZ"0^xص~=Q]D_S*X^9uk@oG,ܝw[2ߋ^́Oyga&Dư:2^odG3d Naxfݛ B'AbTEwDOlbP,TӄKn,u>ڵD6nRP:!7plE{$Pcz%8fC5[|~BDfPgcvVOx@X3Pu(`hi$7xY%cj`L)-SE.Ҙ@+xg->`T=r9(iJguDL6~?/~ u+ɬ'4Z9Uh Xb# tVzʚVdG$<#r#'ٱa޷r B. ?ذ iJ`Bqk 9-"1EkF'e3wV|`!s-' {'JR4/f]jEѱ;:˗3-%C&/”XcלQJ25t-w&Q3=|kSb P5r )'w@Ѕg"ޱ;wlBsR{y2j?^.Ӊ|qDTũ^@7Ѕ8ҕB^]'`|,a\R8z6.2WiZ+/(ʤA0 $T5$Om3 !}zJuźMA-#%ݣ\Fdƭ鵤JFw֭>Fa)W01)L 7uZrJ.W#a"?PoydIagV:lNbhp ֊">1˸GOPGd ų P Ug?eNR}d<53=ɕTpkdR%n5IFnCK+ Ԛ\yS g j?dCHAA&Z=ʙzA.UmD-~}^PÐgCyAGM71ByP{+T\2" `%'P= ؖ+օTkI59وC~+_PҿT׀pUNӨb7)M\ Hr7g=Il}Δ\E W/$*#4M9` m2OGIR6\r-J6RbG9 6ϟXR>b hOqy#DٲzQe ͧ()i:amZBb"oTb*mMGppU:xBQ ϩ :-V.R8> #?2ۗ6l!;/†|K+#b|= X͔dmet>FmwZ {l Aм@wX_q@D^j<\n.ճ|jC?#VǩT"BXd޺\`7X3hzYw +?e%CQz q-Bˌai]bqfb @2,MsmQD9LF؀_R _t ;ٗh vXOmfCaX{>dKhRsZpEEG*%תgI"CµkaaDXEUED~'}"2MH~y45o%@e32%1 |:Q#CuK#?%:D{IMfdaO:,6b.@xOPV/]Ay/m]o]2GU?*Jp/:6{c]Ik$M &\@3yCYR*JUfL(  ojQ1cE*;jI;5e|ބֳsYbc S&&s V^j H;g"m]6b ~IRw<.KO~`){(?&D^AXR=blt[I{l2b6Օ4HAAf<҆@ۍq_aY0=TL#˶Q pH4,c.'$*u4ٓ9S $sU34&2m+NI7 ^_} m* ewj8ƃضMMNʳ׉c!'[1FNG=+X&QЌD3WnD+ Ah" z,Ӄ 3XNO:`c!J nC:OE PoԾg<Z@ <2"kŽ޸&4paȜK ANk0\ٰ\%Ż㠕X:G#C z"nۙ.?#QSϵV39wy<1_ڧ1v"n<.R7^sk ,#Ҁ:ҌUX ^ޞ&}CbeQpf6gf\A1vdh#)ȍWI]c)QLFa|'qzɅHB?9q#IZ387q&h/f-R"WX~_3!@ebŗS[;BdKuakAp =>h>5yh3p$^:w+e[ewQj8sQWW$wO O6GB֞qL<:YyR7W`S^SQtsh՘{$)RJ%G ]no)_yflfvdwZ*)CQe<PsZ7/:;@ ,a[[d܃24Qi> KDbKdpϕ0ŔL^y צ$d_s&֯VzޤeyΜX‹Vԋ;d~D @` mlPGvGb\n ^9:KVW oqNJoX?f(0i:&Ypd F R!p:YTiY4*C`( @mwyb$qoƉ̺|wÑnGz׳~" C(f+l`v908 mYW;XzwBXfƹqĊ?lwyH%$~dvхT'M\wG.@Ua#jP/n!F{Q*>8a: 3WFo`*59!gk^%^VٻN~16^5D9.N$hF')7n%EDhi(D߶Goiɺ;  8Q'k壇q|t &fVPS oVPkԽH( P.;ecߥrKD`pr{}~?&Jpnu.< zmUE%IKt:}N;U M YOsrf30D$^ cgFK)'BI=" m%$"nO:%. (|Lvi[AۿKK(Om/ͷU`7އͼԟ|abu'e!_'_#> dex,$9>h;%ӂ6BGӸwn2M5Oό\ ͣxjډϴ³y.ՙ6\N @0`ĉ> R[L} P9Iar>E9\#D]) ^ r+dhqTG?kZh?bô1͸R#w/ ظ:@Oo9xBM;m"tq] Foo8z,շq.NQŸuie$WKt l.[tB52$^l?wFz \ȊDN (e(q xisQK1/ZU+SXEqO=_Mdۮ@]S=(Rv6qgfu jm500D͔71I1sh~΢kw}7aI Le 䶝Z[FEH」<߳AV9%'l 3R?1y/= tU3_Ru $cLOzln5 C2ɗҧ@1D-f&z`Aq ̞rɰ~twZNc'gXo6Z/EWlP3PiKƭP̾)?_/ &lg0Gc-i'F 2c&L9?Se+1O&JHw`B` @eB&I²s>[G9z߾9½%PomTr [ Ix.8PD r{PO*KLS1D2u@msk"yQ< \;9.hHiGz~4@ҍв=E)F%dH Ie3}ptF\^IaEW];}?{z+؊SYUqXXO.iX z2&J|&֖ $8fA+ #-̙C- Pїz^>#~r1uR@zM-YQq05c#kގII 1O:NӢ,bM@u^ķ$PX_ CPz /|1RWyroF*5R a•sFt3Zo+L0O698.+_:P)O>Y{)acPbьd[p@`zؗQ>]x x%ٟ혍D+k}5tQiӭһ*iE .MHyqŁDt< M{ҭ}PԼ.gMѯD<@QAPS>8 ⒍첦`nlݣᕄـ+yqp1LhxVB$x#3"q^0*Np- `ݐҙ43ZX|7D_,_gəˑGoyn}[6$Vgn&H$,Kh$yW.!81K+Y^f ,N"QXJYӘ@0 (r$D5w-k;> W[è ,xYh"FIx7- .wYQ>Ibu.rDhqƙd{]c8η{Pȭ^1+hUe '&z=嘕da ~ |9 >TƀI2 ObalYet{^hSaQ>9 N1 Jj90K@bz}`ce34)wX@]4E/6KУ6PSp&-t+xY֞\i63qgʞ7| %tU_~ZL]N`hRwl~aD"@Zݼ5 {AXu+PﮙGbƲs˲C7^x6qy3"$:ꅄ~r_c2|&Z{7ff]j6s6p~g`K0 XݡQ˒kzPˁ";?Yz]~+pRH'@=v]wٚOkV}Q(@[y#nLwwZ'$ f9^&c%YTuz<1ؼTK-~Ģp"ʠIL C`jt5#hN"RG+H7Ǩג~A{>[5ڭ7'AH܆ `^{>'mL=4 a/60<40KDޑ?f]h7gˋDZ 0h3$;?B߷MI򄶲#K '3||tK)yh<0Aҽ r)G dhэT[ @x0E9AЬso*~O"'2 /d.xw-M}o$| ;/])ڐ#_DyaL7&|"ո$mx ݸn%15_,z~LZO6 1z*Vq+-N ,|`j&!R,B2iDHwOLF wN:}A4]垸  HmwX1NYa՝OfTPq)Ar!r}-Ljֽ]0] i|jOѲPew?'FQB;5T^7?/2m$ј_e|4Ü=C'!Ŷ١e%lzy&[{rQB^2]9<ԏɇI$ 'Ӡ&V~pYs/BCr@(Xyi]:n=i$ W|9p|ώ$LRt(bt]ͩ\}*? g7˱븇S^ bGbU]mzM&5.j9}&j==P2s;&%Z + a9< m3'uG{^86}M4X@PeM5C˿GdOiBUɸ2X![o:}MO77{2[O {ݰx i C;qmYV&ZWLwwe`??B,ZPg4in0Y/0~w*=Jíh&_׊1SAΑo(JPŐ3@֍+HˊܪcC,6wZm` f ]{τ3 i!Z}Ȧ+7t[~)3 K~~Pm@C!ȿ|siH??9@qZ: Wgjlŧ LdKfp!/4  g>B8]4R@ +;>NC5iмNI3B35 w. "#U%y{aRgfnPB87~njviu h]X?!sŲ2DȡRK|f$ĽKq,6 $\ 0ɖ=}m1ZClk2Sy%p̴}PiTDX 9 z~6U,|5*FIm;J0@xz|MZ~ûCUP>F=}**K)aoYDf.OX%z/:j|&a3#],QnjQKB,jc/ _c5!bZ.gW'F2(<==~±g @kW  ̝lhN꛵(ˬu';< IXߖQ3ÕǢ |Z?r} `Ģ oOV`M1jT9c\8u9l}o.XfHPN7+Q\W8dSm[EncJށ] iRR;|tE?g e?Jz#d}k"4dD,r*;O*59N,CVms|W<pqCH b2QllHߌne|ݎ Oa6! ,_OC /MW;9$%ev͵HiX4 H ,c\eaY6p`_|M}p6u){V<ߝ"(sd3 BezUB*_(cye= d׊Y +oZ-6Մg?:dyJBoso‰|XCP`F"Ixf9y 3ŷ~P Y{wxFB@(ͮ_i7} B 9m<{dtXZ!? O:yS45K&5bc%{0gQD2/O9@./y)8=D-ǷVucC߽ma:Y7y!qvuG8n8|+J4bU}'S(U}[tb^ N4*+ |rG!![ڴ]^Iq n%>ډ=p+zZ+T2$|&(s5 õ DO\ʼ(!Um=z0/@^07r"Al6Q jr\: QWH 2^JwE¨ܵO$qpھqX"ql[M~h&@g}洶zvyG:39CΤ\DjTy1Z\HIg8 C_¬=8dDb0/A}Y&)&yI/0eV Ȇd|Fa2|z0grw81hxX]zq7r3wEe~A xMx\vPv.̛G,5' f kg9 p4{.Uë(aXKw$+x  :yO,E 8ApP!CwvRp7WetbK YY=j9՟w=3k ' u\57IR/%R77X\WrJMk%sS˺P.Ã\MSHC%lNuBf˙(,UBh ,8 M/iwwp:?YOHB f2 Bħ.ѓEp{Q'Q7ʏ-g=\e$wBYy9#*Q3h $Q)Ei~bL>qA40pMl.eWO1x%(>>A쑿GblX7Gi.עMv(lo Y|l3-Ɇ@H1 mXgmYoL0Sㆉe4L_2ec"OJsFC])D_eU4*{840_n| ]j9KF;%&|K0U%vvXܮBm[՗ތ `!cy_u=AlSZ{y}sS|xA 4<˞/9PP2Vg- EaiGvX>YT3f1*0Nv8A/cN%u&̗b~ 0*GJ'7 ABlqL^TKVS}p\bb2 \WU-QT_`zw8 )'|g`\2B-)#G;S 1:oKj l+g盾ctnA,F0`[Z6LOC{(io Y>%X8OȈN^i- わS5Y4lm#br CT) t"bԿ9s3 -p@Lzq 5:$ m-w9_9qu5c^?Eү8k+L-ٸ Rcęm( 5JtY!&vAA`ѯ$X纂ŸwN}eDըfl8k{y}G%|+s=W+3CH(f֐?V(<+>o`.%swI\'a wStνw(ӯIѵ^0h_޾Sh;gaBen Ja'kR':yf;> Y BPUתhm"$&]~?8 gQdaU[}Yr}?FzT<?1aU]*e%RheSij9GDv?֘GtS r h~ |^OE("pXn%(<:ZE;}I P0/Jr):͜sZL؇%685!qZ,A;m+DD*9!T?X !KOҠG&)w?Wqp} glIV%?xmGKCf> lHȖ:ʢ]Z.1i@[6R_9twip'o57<7GFNU5JvFY8ɓs/6FZ'7DT#h}g>C^LjћKJf yxZK;چ/ج]'*)W> P.5)sS9`֘ې؝ڊBUr!9Jz',iDܞbu^ J˩B{0OoInaQZa}b "S@Xkwǥמy^\"b")a<ҝ.6gYX_(YdYTۨW bu+`4QNFJ&[: Bv_hעѐDiM3;Ro.h& >M"(M[降Q"e\k2]s7SLIC5:  /cp{ T|Le2$2Tiݩub*9Z8nc7K2/4N|% XMf Q[A#xX0jH?2}͈jC@ 6MGOhM[|}\eM[hp.njj[}X<Aܹm_"%W("L)9VIaxD3T} ß|s\12*`;T $+e]Ըδҫ}K~"TE|q)*ttr˸ ?Mbu8ILyWS0Q-&'Hm-Gvqԉ)BH+i I!e[&49oÆUwṆK@U2Z2}H L*sR#l+Go e- Z+p˜yP㛮R[RP(k(頲 Js{kVn( BSD`՜aǫ ӡ*!sqnHl~ml$K[ܫ$ !kQ$=֥,LPx'\X;}ޝMPUz t$ ;jf?_fUW6'-LV N<2%M4Y=׮Hf_YqlU>4xg7+MXM6NjMzsCQtVB[W,}w HT,kޛb+1yS =-dώQrn  ՖHOlc4f-~]'$n"'OGw8?gQRX spi\=ӦXHV; ׊oPjџvU^"k$9@M5=ԞcRlIJ˫_ǧ-ꚪ=a^W'?Cu0YtT( ď_ al~^E*c(v)ECk)LY4ǓK=XpF##tF.1wkLpð(mf5'#6Vv{;kZ󣰏*ve ˀ(Yɤv V;m BblV#9#g|doLgrXZN@xp 4^VCP'(M9O&~joG3Wd$f: Trt8\'g]i ClHUY\6 u|3YsF\m<16̱/aH5`'ilEY^eՇ H]/1~ɖH_l {,qDUa d=?{zuzl:}$E()Zʚ 4i.ܸOS&Iu[仅 [ `.EI[CS$|ϯ6h^@9;Ewԟ1Zp.aBfL{}7qsGИ/`B◁ 1ڷ5@[n FB>l;?9+ 2 MM=wYPq3-ߌˬvv+j"$Lq+]s渚nRl=xi?QD3ᡔq D?ݞהzE"Zfc\mq ϥ֭Avm%:`=T *1~y`iuEfJمu6hu]VV&A06>WmjχQ{/Qag|\o`ex B#yk{kR̷o\,xb`ǎ'7LO{pz' =4GOT Ʌ!7%Ŵ{2<ׯDBD-m}ce~*3%0sP@yťqmЮ#<4PpP6} Z?v̲hl"-}u:O:?lIj' 1(Fi0ԣ=:>/UG V7A|h7{B$(i e'{ڶWw^-OҁDFg*cST|+b 0@ߙW"[9x]e %NבW\*lu*+H = #ѽAvr($q,>q]6!.x"ӂqvitoje^y7\6b_鉺(䷳o #lNDg C1!C)fӳooa~l߉ԁ|tw?Hu,B1d/:w}QB?JXԉZ=%Mj|'1Gdw\6ڻ;`<S4W_mos4;(pZt:WMAdR |ϝ6>2(bdςvc z ;eem} YX[4qW0zvF+OFxika_n]m+ yw}_ jT ???[1f( 3'j!]L:j=fЅJR84N"USC򻫄%@9?evբ*RZ> C60[=\S̛Fmg&^fj1yE\*#GH먞""tm#Gͬ\Jl>A.H$Uv߄97lv !nA,z , νj_3?~{q㳁6qT(YL\^_K;.ʎrd%,EF 7aHlD(F`GCğ̞9_Z8]Jf D;o>LdB>v'6:I[#"-٭.`@6)s 3>-2&$0(JOJD)Rڱu< 2wԛ_҅Q#ͩ]PWuS1ˇC !õ6䋷{bH;L]gWAv.gX0NZFGwɤ҈9GSCu-68y1gs캛 aPP9''DECCGko+_dP~0m* 𺌌r[:զk&O K=ЭRN2%ىT^h&ٮ,< =kÕ̂z>7P#dWPAD%kiq>9PҵpbNYm؂q$}HHt"p;.&˼ю^t"W5f2 -[i CF0#9Dlnw+z=3scp+.O \ T&4_řys}GGk2Iڊ=yl4x#7TXxӂॿODK([QJۜ0urd`(yA@ 1l?f7>}r'Q<㗤d%5V1nԇ:k59,E _ rVtu(bBnmɄŒ^ajVlmw'չ9MYy=Iֺy $uJx*T\GH!GMsD19,J;U(cQDayC1u1c{x&ԭ5 L8TW;(`sqQV^Uɜzp,+؄}ooV*>z+QBbZ1/R{\>cb+[ID-NVt( M"Mc}zm`΄-Ey)CSmv6j}K7?aQei=L)B\C^.A.lز%bl_4AO5ZtkQF JoR)^~=uh&+WvnHs T[>CJ :H#zj7"G}Qv"=cF/Gw` /ѿNx! w&*wk*7#hd={ (Y9$ S93  `G BU\Yű/N?oY%Y[@CAo=5!q,"k^dzKn sI& bqruUT7|Uv}"*ȯxnw';RyG^,h'c%X7g *0Q.Vef_p ӭ"l0.K-;˂3Z}eu*… <ٓ@*-S&$no3nݟ.'% >;e5?ח9ofTQ[A3*lzw/K2#hMpZ)|LR^nH&ig# :j*k^>1`9aG5.Y'jQ1f榩8F]kB*,ajU@ q)rJ%`'S.e:,ku .8l%+mK!chouj;$ ώĜjRT@V0J|ՁF6v#; q^_bVIhȮvR@>b*7vF^>4=ӮY 2BԎ{e:pK`"i!: ȑaRUΣ#yyRM͛UR20W.y<֥}], zm2ZڦC6E 1Z $k!=>kad7UyPFϤer1|z5odu^SSc&a{Ϝ58ͭ7\5̵TұhUIBfϑ}vd-[[X>V#|ZXX|.㏄ecRë?e:B5di R%L1:`Ζ6pC4 GD ^&4KH8EWuHhV.nVWI*=鄷z="5M P #%4]  -3!wN@'hV5ں( 4mG,\#oCpVS<te?3qF\YJpXAjHO0u*8IĈſђy)lrb@]:!JCJnm)㮗^mnWc"i;1nNDO#>$1~Uo$X-J `8DNb?V{0i-)O}uuO o䀥?Ƀ*b|B+iqBw(DL<ܨF}vwxIȰr3CMbD`ˆgM.!ҊI!oML#1l# x]t" l ŰĐit9z/c#c&4,F0' Ƙ}Ӂgy eޤ9z% S~UY%kx.vW}",F6zc狺5&Tݮ,U!c(,0$i !VU1C3%U:!ҒրJօ)bi49d (% Kɖ~|Sn?R|ؾs ZeS(∮ع@u=>v/E b#PE i^ч +3e[U폊wUp0P% MW6TAwzoPq2?3`>eջh Ka R1AkƨD'vh؈M˼4$fCj 9y*`z3?lNPz$?cah`"߭)G>k#ME[èrX4>!o~~3UxZ4ˎIR˹yw #랡Aq}p}2] G@PMS(CaE]~:$<֟kK]f9`~SDΓ2a'M5 urOQ}ͷ Y%хE_)^nGU+$߰GdUo>ոoYy@A:9 >| H [ZX5p *mܝK =^RRfiVWkq*qk-[|s0qBQ^\a/18K!IKKh=8蠉= \S&7dx#솆)B`Խ46@Bdv e|u&|zbއ@]ڲ ?Od2CB @05{*jh"7#~'2}%+HS9p1eGp?փ)p|v- 4^s~0IV_(ڸ%$3$7,, Um3袁?)_<%(/7Oj$ԼCJAr9L,epώzcIyaO$R;3*{i,ۤ!]W&{ēY(ÊMTf-ۦ/fq'vϘtZR(`A|V)RtuXfT$5‰ŕ AbUurI)QdL,6@:sFBefhHhڊRM1A;OOx'UxU?q%d#=vڕ4n.{]QL#TKP/w AHʟ)Hb]_YӜjlvj~4!Kh)pӡ͇LRDX~G~ p5 " _7&Yd'A/4='Z&)k"k:?9CəWXW4 ԽJ ڏP㧫?Yf"S$u(o`*25<[]4&YZwWM|nDNbQt#G02{{n +RUxF) O'49W@3x A|wG ?R[OO*!`5l0-:*2Xl2Ui.1Ф lm뤖{|h=Q9,L+N. ƻ^kŵ\?sT~[Ax=-H=О$ėu]}Ӱ g)}@z= 2=7#?й.* nʼ{OO%%؎*P!"VI/Ȳ}Aff$<9z$r Y\V3s%Xq\cWLM6>4N{eFa2 q^_rb'Sȡ]^2B6AI&YX#/VG޹43@d 9#PՖjhgsITҥ> eG@ZY5>W$~a%~'a~ae4xD׏v'X>$]:Dr=Ҩ+>}j+m p)*#Ұ}ZK}5o R ^Px鐘1VrzڱѪVWu`TᨬPwG 2ڥ4ǝ!+8'qȓ p?M^R%Trxm1̗IJ;qT`l8VEOK [3`XzUDeI pXpߜCM͇jur!nc*{#~MEb$KhƬxV*a^EBq_~"8͌6[P1=qS+"or9=̜ei!l5ꒌK1Wڭ7ԃr}]~?~YTKyG#՜$fYЖlV N`%:L̨]MPkDư>Ek"~7)pw XV @YU4r9W-{XbXg%Wv"EPzd(@Mcm"zniOuV<*A7";t㠰ve e~%,N7+z[rJaC&* Wpha{ 8wGI2M и$+N04h~X2VEdj, =i|a}9j(1(4ži~>7tKJ[>j6@Pcf^PݷCIɉRI^ < D.FGs{ݞ"+ z1>d4$:s >Q _ ހ#THO8RxKKMeJ}X  &o{ݴ͐g 8O2`S峙Sz;ϯXS IM!cҺW?4 .OPܔxR/̌htkd^Jz4E)fzuEEA5qGJW2aXכv,eZRto7 $PjWn&5*'*N?P-q;'E3F\}P;XkEe~S%aJWGe?Zsm+x~_e%+-LZ4HD"ʒ,PUtH;%S9uۄlБMm7!3upBa?ID_赮TE"@xUa5t6}^lԘek)`Pjq8|8zR}h0<)\V-|y?:0kaN2m UJdz ZPjrB.IHbtzC}r0C?+ cb#Z\}F" N#|hOH锺VLXa"1ˠJL9sv,j)D;8DR[j$]wd}=dP?ܗ20T^ۅOW$rMQi3Ƭsרح[e`jV3zp87!߂]K9<GL#enu*|3w|`3 Wft(myPPČ UA[ 7+\A/D&k^[+*j[6+X"Zqr$i;N}$/{ox{ &ܺ(y%=aeʟX;[EXkOlzAvLcgӬĎGS |v*r&B5..+`iGvL庎Uך,'\? ed&4 ~$Y pR)Z N~_QK>0sg+m(E)e $fuAZ|Ela.Qfm:;"SѢLIMxV0isu3kv|LPM-Dmf݉Ь<ϮqbI>c9@M-lbA  !O4ǘ8 fwUw #XsTj50b(OhQD;{:Ύ>53ˀ|r`FIծLĮ` 'p:*Kyg|pcwX7Y}Wi٢I+p0ys(x>?:S_uX9`Km r ΤBI߀sYZ¤=Ba ͗ZXF#^l%o!Z%!b1f[H_2c&r ߺQjpRpßxy&],xnEFN%Y&}Rt5r8o+~b3bSm y!y4jg_pwHR cӈM$5VQw8y8깼 LJXa~ X($FLarq2<(bp)b:d'tk|O`d\ˍcqS CP=nu%W7]g9w87Z{\דK$c䘞 Rs"g%l QtðӬp(4 <ҽ2u+L"ZnҬ!V;tB-Vz3!` !NX/7FЏ;<6dx7%AQ9xd"pZ_ ͗y21)"NƮcQ6%@Vbo(DB~_LQ:>wd&_[Mϻ$0-ڰ" vG1Mt;B ˜AӨ%k,-6peUeLp''ypyN6gU 1M rvIŁ$l #f]mL<ܬI7Uq3eVK")c7;8q”=U^M$NP>ټ~9jGۃ {+Mc̎/ۼ z* ag*C-s|IMͭUګa 8`6{FqR2'`*|w@*6}@0}3$%7 w(-h:f/y j)ẓ̌H4_P6`MJn'*bѣ/MXMz#07V{V6n\yidD""5-Q!TNUj AzCOb*fЎ( }ېwUai"{ M|B f`PB@pKԫ>AQ0'(*՜WhcUo$A5la`_*3nq@yAyEoNZJza,21AQu3Ur^hM m>'^*Ws}=*g;RO)9`5e)]cKle|j "t6ƾ cg;dL0JӉ @H` kT&U w/XSyv\98]ĬP3p’ 'A^#1ɟ c1d~+e$ ȧٞlh!Z>q-3U+'O/ye QTkRJHq+xR$^!%"j-I0Մqq3B b:\u7൛)wSz+s 2Bi =η"WPXc} 'G 'bZ0ueR[b< x{)A|?Cysu1 u7 ooz;?Ƕ/Hͣm̽^4xOW]AK#^I\d)SU7[ Y;vA wkyox0 ws;# 6[v`wȫSXԵ5vАP9 մLm4"0}x߿sz2'.BUBkJfYN4$5!WN4֕9Ҳ|: ν$鱐ޣhou]idgP.]{/Ut5{i" 8.o'߈>N͖2h2 N0rEo:jҢ!t|Xɽ=.wu|IF9ZcPCO.ʘW`W?X#?j|A6q}` ٙoM9y8=mEk?w ''qaz=<*W[jI"jsOZ)ЎbX:\P `㞿= dyﲡGcWP eb2Y~̾ 'C.TIT\Uc1o$9,NaLvss%TD74#MNYٷّgNLE JPbFU&AA?>MڙB0=5DHzQh# ź#-Εȍ xR~x\ydYtd\umW1u𵺦㦬}^Z vwE"Ξ䦪AXKx@ć}Ow͔5&yhi,(J#NM(\ǞJbBi񿑷::?PgAH?5l{jET+O™õdvz(-їd'vr [IZlP OGOqv` _ >.xyekws_[?R }HpN޽:X)'D i2w s4V0%M=I4?I*ݨ]8/e4\y:N.\]`yjaoQjr}*@% J`(WP8uɌ jS׃:{ti9g{dl+3B(lٯu_b䰼AiP; y!U\,cm}`>c;ȱf9 o5Q%fB˴#Y=F -qO/qӮy,9; .| =2Ͻ3q456E,d'wǐpZuSXNZEq#ytS4]@O(68 @l7whN3ۚ-TF1n+ٚ=bb #9ݬl)D$6GePWgmj-`FymMq rB+fDcw +G::x5=ӯגFtdsޭ [?ep e[Gzh˯fSLÛEd+Q OhQ6݃x{}JUHa2Bhc.FNe0FnqʝE#Չ)>PYy}p޸褢>u noa8=}d8Uͩ1pqy0ֽp#h 8ѰG0@w2Y`a#`Sh@|t#ÌRW|A{v@ëc3{߄Mr $+ Rr X銤Z#E)3pW?40f/L|-ȜfrBEȯ @{;E}qpVK`nAy#rCQqcRh{[^#OUvb-Hӎ`ky(UOJ P%J5Jsb@QT p\zQ}G)1 h` ?M(54s bbB t.3? ̏}=D-v+S˶ yb Ԁ"IZ{A9"q t KrLZ]saȝRI@`麐Þ.;Y`ztq;&c0vu婭mLOanX!Bg}xa_P )ߢ,D8ʆ9WQc=GgP' ր7RY29Cꫣqn {lJX }H3 ;TsܮAӞ/Xi+ Y㶆L9NRMu$^D@r7v[bثsmvNb,Od .DmOuXγ{t(DV[?vObFR$=6|kixC={+2XkCp^aWLjqǕr $¸Nel1bPO,|-PΝ^Q8fk>Gݘypu!0D2׬ Ȕ y}g%`l_zSbڂK$2^+0OA&R_K6ؗkVqb neQW$hJ*NPP..;/n̫)MmA٫,# =#PC\:N:\k&JXڑĥgbkʠH/>aH`r:SյQԵmzJˑ{*_G_VoqY%l8L7z}A@bvvJ@i__hm+=l 2 @XZ|Ex ~C"dlTKY#S9wjt)AԞJI/'NǥmMYwe;Ɋjo8'ZzvCf>T.  |a yQo CtRW ckMR2[v h:N|af±MHm,jvpBr# |V!+z#*%:JM?YƟT Iz`4\$t9%kr׳e?ae6Q&eGHļQ[\k~U'tNg˾>*>ZlV5kEe4fRqpK_ۤ!u:ċkH({^ЮƮLo1wk#N}J~HіQ_@zXc,R&kEftC^N_)FZ#|k1|rMAIET:Jr]0ya77NN ;EXZju7G mg$87/As:Zʮ:nYM j܏+ɜs+2SP2E %!K780G|v [)X4u@J ԷKWVjPS[M5[b)i 5#bH7Ǭp'%3okpViDyoV'X#qTn$U9%;hĂ| ͢gV/ͫNe=b/KS#Zҏ,5ùăxOQ0VAdwxo@o]QNؿWNP3'ͮkPcXe` UU3 vJ:':9FA8 Ma84,ʓ䧏nPe0h(3 JtZ.ݝĻca+Hcxm8e6WE{<bwKSuY>{Vb<E7!.@DŽjXd>3/z;Ij#CF[q j(J.Ra 0YO|=O C4wa,Jxy x0}⬒wo SwƙbSXV ko$g[ >fb$*Mxpy W%Lfis5 c|f>u=X?vCz L=㘀?YbG.D;0#G![\rojI9T]gW(T[sZ}mT)avֲV\R-C!+$E/{|w`i.NOHk<$ȇ 4mX^M,1X(kHlVyu.yl^'Eglc: GYdEVP29H:VrwiԒՅ}Lb-ie"]RaC÷(Q^T)'P;HD+Ac7_PZW'ۧN8wHw F81P쮬]U3Oe2*< o01b.7} b O,-@aotSa:_vr3h(g1؄M[ؘO"I1Y67#deXcȜoC[C@tY%.Zٺ4j} .}J#HOp5)E۳aTY@sޒL戩? "Ԉi@E9Ա6_ +։ޙR?:x2F#J^Q_=;Ggd0.j0ʐƕJ++͊z ;q@\&a7wS-WYI>hb2+%||KP.ЊH;vƆX2f%Q) > 7^NUaWo;j_Tgy&VOt4K\x~gYxܡX@?#]5Ђ]$0U-eTj>u@[݅ju3>G')HˎrEs]*'!uM)=gf H$J(P;T5:`Dݱ+wuaZch/{#\q89 wzOMJX[ŤH qљ7T{Bcfkw{(lI Do] GNsusLԖȶ!*t+Bj)&QhZ<9#PKMُ&m^s[poagNM ~TE^:GyX4.EϏ~pI@6Cq-R|i are\CTPDqHhMoQΏc*g]j+zPB"2 M$OGB;YaURȢO lW6BآHo<0pFv k=pVS` 3&qu# ;[r,h#g'cD؝^1d'FM5˭̳> Eem[g-mr=(~.-Es5DӸ1|WfG7k7^zxBHiQ;LZS/[5VJ)Ii ]t'{8©[?IU{ (0.}mr{WiFFcGOƍs(b5įηB]TAVהzo@NFTP-M[#,C GL5Q0ŔdʤP \$lޮըTZ]f>8|+M.yzVmx%[脐j܃}c ?+8ѥ^3_Ղ66+vPQ8k S}lAGpo1ގKo¬R5yL>ܳ]S0(NœB7DwH֎+襣M&[UjɱJΞC9WLEz8l l֒*MJ.v[gqZKwo}A KWb X Fׂ =l螀jXd":&՛e[z Nw2 1 DC=<"&ڮ56oދ\%7?$16`Jarb)\x5!˃6˙Jw٠wC;=q#폀9.2G׵z[u !ZutĦޥ:)v2հaVd_'ǝ@$>6 *0$iyw\pGŎ t$~-xM ^9™" t+!D|ņU>쫅+‚1KC+Gc?$^y/6b,vp|#c (jH [TA7ZAewrmWv),tBm|J;x:X}DuѣMs!N|"}8Xtdv4؅iUe֨Q :Jj=Lr gyt&G )t|`o㭿حcÔz -CY)|iʀLf:ڣËԏyߴr%&6߇?dpn hɪ9?1&V,ӏ(hlUt&KF&Y33 } AeLj%_'U'瓗-V_gW֮5A((!x9m)Fc 3V&1nxmT跍JiJRLc]=nlpֺO-Pa[5lHhlʏFNTͣh`pW_J KLL2Rse>؆Vv=l+ qb)wC@8v[AKH"x4lT⥭M=.s^2aR>¾b^:x~[l;e0r9K8娪~o h+d|I7g tOe1vlOφpϠ* xY: Wcg1B %i4d@uvLv:7uҀ38?Ijtm1bbfDX +!YȖh [b9.ZBp1PI]YX*Q G؈q;Fyg -zt϶mcz1ezkxb_ͽ±71H^[9V㗕F[w=?Adߝ0S:}w_CR0(^o3O:uvc^[HR S>*qA ҷ3$"} WR&B!iQˤV5gwžv C1}F0)+܂/hAOMv|ȹ 頻VyPGnDI"4Ny;Id#Tz~ ,}/|jVq{546ˌ(<ΞW}{W+kB>b%+F~h@*/&EA"<ɹ$`-Ʉ,^mBa:KBU24W2ݑu؝7UÖńK옞nWH\]G\U=8JKB"6Vy˕ˤbe }]Kfx%Zllbڪ}#SwbCm:$̠Wkp;ӮB_X-ދ . #SԻ?#(b~?wlN2~j~qj^2I}m0hɅG;Uk/yϥ=!nTLvLϮb̑a h0i2M>I#שӼMvL1 2#650FtO 9dW*w{3ոNIf̨{;| Ô8E zI޾r^P@,5 2g.Z=މJt@k>qzl&0s)T0S?Hw7(+ɔ*FN*Me Ҹ|{SߕqV N:׌6"## Ք󽃈%{aj9(w#&3(|ʫ[tDSz }vg`HK]R/sۋ?GenMv*7ר洿;1x$Ijw]x-1-Eb{ބHS PmR4%\ ?)r(jCHQjyXb,xZkiR(BVT ?UPHZN;N_n8aN ;wɖD8*.[Ќd1QBʳ9g -gvǢ9X۔tqf)*dS]/31%M HRO3ɰo.Ö`ݕ`f֫p+\1OAB](;N>yB+in9JsLIKfna=a0Xϒ׹cs_re VPZIo쓜jN[{!O+E=<(s2'O7H'5%RrΝUrUh`~؂CO_" H<Ȟ `?H4(eO|;|9X5o-R"Xؼ_9+7~DʶLeMyg1ug*F^h5k@ݛcª2Ha]^@(I_e_Cݺ~θG6[CѪ"g"OOY+x[ \@O>  @7l> 6MK3k)3ߗ[ d2NMd"*&amYo(OÉw*hFCȑ_]d{q7 il#=б 'e@~An@5X l_eD t?0otkPOH|e[aqͪ/j: d4ejlt6GbT=nf_6,Q1C}m'eKɏ8C,W 4k<[W$~L3E:`|mɜX6[x'*Uqp2c4˜FZ6k)q| O"sX$w>y aQ\؈*> γPbmIҬb>ty(펎qD )uV!?_yQ\-~$T^9`V'5^L݋/l{Ɇݪ1+;rVttq&)\T_/Vf;mL[$ckqyGR vԊiwsz0e3'#Q  ܒobGtekH7i+IyY X_˂. ZWj kG~~ݕ[q@y$J KTHxÀ+yHlwlF7?q/68g#lTLp`$|An?m~Va%p/-ct=l߁-rwvo"2MrC Mi,"'o_09c2n4VrV*-?L,{" mJDET`g\/I C9Cǁ/NsT5&!\m(:;GP3O s$;0=zr,rBs|ĕ]Jc@r4ϝs2+{Y{33EI/"c#ufTJ;Ig OCJ'|8h!ofUGsTzyZ]]Kq3D[ ޞqj9WvJG)]0/R |>O5!!S:|NuNlj\Qr?`^UN\PLFT4 M9W<֡2nP9Q.1 ) Y_;Uwĝڅt)^J $(FXu%>%iAŭA/;.*gU(l+kq$0fCV% G#/D+ vE*JQj)YzPfoU;"_;; NKh mITIA)fq 0%Z 5T2`ە$| >\b@ͧ =L; jZEy"O?OW+wmd.H+h4Mu"ܾ~&5;==hn01uuՑ{D}K lBr3,~ےwpF&ԑDlw9;_-}wByɪ #'pDj~"Ot-fg[_PuV^{kpŲr7nCy!a8P1x!{B4 lG -#[ YWW`M G@c^Icm\P .6Y0xWuOA9$i]%Reph8Miz ~eGv UBŭ5mkF59۪4jNNHK2to},/bi!+gB rŬX0l,+6ՕS`;Me7HFaNKyZ #D:!nenc;{9% ;ގ FWVݼNX `eB@"p]Z(:K~IUjcZg# 8g><`_f #:kWxL[1esI58hY,S_/B)I3: .bVv&1naUn7O.SZ21m$ $s ;j CdmdKa{8yjn9:3:)|8C &0=0˔pY]b9-p b0n(:Ԇt6!`E4>DGuVcI=X@ɿFo3\uy kfdf=0Ɗ]f)8߽DKrޡ:~U!~uZM0U-C?\ "냹́wd|v ap9ccCHs*j%>@ŧ=ũP#@5u)1!r5hBA#IywZpOjӍB!==' uSҐr5 XO:.?6c 52ӺJ^\yAHVOgGFb!cE EtV3&fՖl4tQƇ&iZUA(.TӰ9Rp=ڿq2J^/v% mcFbW{F1^Gڣa!;n18 /ԄL9)$ S&aW`]u +qEx=92H];` _dE۪jHc`@E8A;qcܯFw?sro1U3X7H:$e #Tێ?Ep'mK2]tF6_e S(// _~Ui29'cZJߵ;m4er HuV$#49tSFȗo`96?8ź٨8gao^=֏2JW?9_W5ػ1?=PGl+vA-+(0Hĵu= DQOYw5RkL,y SqoN}]P{9uKɼ.Cͧcg3r!\CA}jRBf}T 7=6rQ.lyRFKq: BO\ھZFkm#='bV'C_Pca|Unh/ {x_V).K5pT0(QWt2=2&]qLqNJg`O=x1?,tJ6&-O ow0-n*Py0yЉk?{ͮL9GNz#oBQجOUg6#^9ݮf!R}S-˩qebyi3!}'PA.{\j{UQmB$ky4>oSmSNP*[xVVo +4oYu6>p"l˜rr EHQ2|I@n B)- P.ݔjS["sC)%_ª2et= InCjZFsz@hZe;Q3{M%,oQa=bԪjH: ݯ346`@L]^"^kN*Ջ|ai3<͑(is{lyTU  `QSq3j@L\V "kuD8r&zX2E:(^}-Sz"(Y>z4»Wdhvu}slY=ˇ,kEFٸc/YWbjg1(kti4mY&p=C(f,=݇?.]4z뉦f2 =d!ߗ===ڿ+e)e(u5$' Ο<:;Lާ8=hpOe47:C, (Hڵ=_J>$ET;M׉SVaL0SCy6~~41-SWDݺ[^:bܖ":3t51>vS'%m_ bJݗcFA5&NKoe  a}G_ :sQh/#66R }T? Z%U̟$.0g2Rt $!VN4쾰 3,oeH/xE_`0]yYϜk/gjF6i}4}NO;kDVTGEAcڴ,c>@;Ǡ#zsCd)6;\Ff5WME Խ%Tc$U\b7 zPCJ'"Muؓ|2C͟|pnq!395 c_r䖷^m>f~U=h}|Ϙ!$26EELѶYn1p1-~7rGe҆{} wtnypᇠ7T¤k-6/ L4߁4GeZ~1MEe-,ellp?ŻvWŋE؋[" #s}5GGr~gq>[ 1F3rҤqmMFh(*`cwe> љ +&8>%ĄbVBa3R+Gb!#%\?r/(k\@E680U0Zx+@ PPg]eO5ƒͪ?JϫK5m&8ŠYI%$0r@Nu;:G>`A9RYBK).'<ɸ[{7gd\}͛rRmPij^H~L AeܦI}Ѐ/Wxv2I,KהQ(a7bc殯xh8 &QĜd4GZmTqR#k]AAoR>{>t'QEBh1sV&$E ֗WAhċHNPB >VJTmIhL_5iYhhn8vu2W<$%B=b`&}!7dr2] Yv_j@u F5lʧd1Tf` ]"m%vNY1_Y_b8y˴e @FP|Ts .JϾFּ!ρ.\D]bWYMDÎ2dL5ϒDDz!ͼWKp? r7Ҕ.b|TXl*u`t?sTkT|-6y$^bf$Jz&P؟2`(1LjtO>`AS~2Ջ) s=RL%œ4֎kF}4Bb>$UIY+_ =U$[w俧iHev#8kZQԦn)a huݮ\\ Ǯ /fcw& ^!vR%Dc D~LW!2cpRi-N[`P mz6NEɸPɱV٨'^5}Zi.ϑ{ .vfjFWxqFc,Ye+.)'1]a$%>$l{e9|nt~%|x P@^'{E;8%pG͆Ն*HT.3dFW8kj V<~RR/!> ʎQn\!Տ f;}w\7("ZPOCt/֋muqM=Ofe=?H&  Ydkyh채&\탤cJ*{~ 5X| "=j2cmJKxP1r&D n}ѝ5"\@`Ȗ 9i Pri eN,<5p. *|Jw4M RCcoᴇ*ɽa{9lcX+4#noYGpokA..K\GB19m%Agp+ѭ eGwakTu5 8q(E(ވAN&j/K[{2C ç+XPyjЍ2κ&x~gyHz@=?g9Ѹ٭%`iBy f}};3|Jfst/wk˝~uBJu]=J FRf;d,7*ᐛrrA xYQp>H]@x.̻NUr*jan@T8 !pqau=5' =*sHT8mc=>L*9RSa@FgDcJ FXhueá&cEqU@XeXDMhNA)Cv̦} 0#':gE~<}~bX.R4?AM#[Jx")u`v,bW^oRZ'K {Bծ0N;{wܝh}M\Ѹ#ޕB, iD {TMC?y5*lՊ<^z:t ΀i"aQ"R[39=# 1CْrEk]8sx R3Aքߙ]Z\\WL)pdyrhX-"Ia9}/PE5kέJAeTg&5'$o9U+0κs"7 \h'㻭3.Q1 4sd_͞9-i"TկZѶ| .ϱ!j<Ai#AwJg$P"}Pb]kNw @<Y7 T&`I_$?LyÎJsЕJJU bD+Џ-K-x2vi 9p#'qk@)kUK^*@8?*Y6_`!˒eDZ)L )F<'Mea2H)~ĺ<"zq1 |VL(pFU]8RK!i_ \RAJG֠hXv@=Mw k7[GX#ӝ&D (!_}G5+JjE ¬^'Lk zbRB#^~ws)MAFmjj9KQr16['KoՔf 7Wyc[aEy~qunyw"힖 U)D랥Hj^.&l3 ^7P+=#qGɳRb&]IhDr##~Y `ʀxkRQNFeoʆTV#a+M Oz/Ps<M"r:>o.HkUA{n*(ىe)hGp5=]|RktYLC7N 2U~ֶ$^6-Re^dY}` Վ{Mʛ7t:M;p vz yqI̥luC@#7 edW66OdG$.J6}sϪ4hګĘ̹|*EKedjt0 N(&i]yprIgvttbvX$6r4V4;1Q<' &+֝u~3X&",ZH&:y$9kKڋʉiIk0˨"txXgԌ.-e}Ks: ?  +Bܘ3QLG)A=oߧ/Nw깠/FfUgt>8HAAmXp| ޢIqۦPGx2%/2 WiPCmg%RTD_lvd*3 , &&gyKW{r7p'Cթ\$覼ɇ< <  ,{zAgO9$h ̞Ѷ7@6E~%ts֛w;z'υY zBQ'1cMLsj f,^F)lMõQ(!v>XS۞ׅUϐ{5=31! (R5 VsS>_*Asx pd6SyH(D.m~l{ɾe@-q`:xWNd :m5,圕$gE3-0lL?^v+DG7 AW@HZl7 C<ȹW>D\0A55Q탊έ3 ~ }ϴIfZ pij6k< 7Hz3dn)?',LmP}ZA؊(ށ:wG畓'M0>rrTSakכ,Ր60nA̮=ĀAnpTT vXEw>]|LV\?5Dj&kI eSE':\Ƴ2)ӬH=<p&a>:,BC#$dT=K@QĎ!=Vu-~Dnd-oDb-ṡ쌜%P /۾h?ۧJPLe{“%*Q.et龨>-ۓ{=7_EHbO&;?4S崩g^ w +05mXh'KMMN*/AaOw`/JN3@z>*X t7SGrl2'aWp4JѝBumLi%L pg+LN Tgre`4L 4O]k`n~Y> D!b@B`LTmq},h翆btY 5c'/29جD5UfPڷY%S"m2r8S$X(e$C(W0i NѦʛL Cj(3n /qX*+JYm8)A[tb<4a.kqi 0˙9~9 3W4RuPz:!%ɠAcMp/TdiѢ{i㎔$,i&qH$?L'J u*Z x"t L!S  {W#u8 10c*q刞 ol:nۋ9%hw6u(בU;g*njXZwLxf Gz0|)-̨y P>%'YNm*9'*5iUL!Vtpzx7x[C$7H`aX8 Ol0YutT?T ɂF߻N?9G_RV)n>E[>DAlB :'~|Yi/'huǠl QLs(nޗ$ur 蝆-K I.9= } Ef(׆$9#uk<#s63'CŦiS曰̿[Vz0;4#ٺWE7[$ 3ZSo0 ̗{p^% 3 XdRJ+5+- ѽ-頞B5cu܇ޢKH|Q`F m,d^|2<lBuճĶ@02&*sG5fȐs T}utK^Z/wB,“\6\2}%@xx!kQVfmsumJ|^{QZ:7ɹ8[AS 8N;oÀ*zc>֋ܞ`ԯqE7 }!݁_&nzBoXgTQq/4CK^Eр[7L)j)reF\6[a!00%|вVna]@yF@:Ur|[vtY(^FY*g=uԇǚ^i3E*%҉C$5 sM lG[Tzx_+6ڊBdOX d=NB{>Sx]& ̌p`JL*-2Z y@9Uҷ%7K*g +=P,OP^3Rʀ2DŽȧs#~tn6ſ{=݀5/Sϯ~qKr8^& v9h;߭rU62͗T*oRutќeԕ]"bf.ǔ7UUBQe`x}uYt]C=X{ y舻M .NmL6;&ƣĺ9Y% xUܖaB )]YMyBup_zmoP,kw%Z\7J9(]@/lVh[5T9cd݇dؖٛ^eFB-ҧ,)1CPÍV~Om֙n&Rr^4`ۚp0ԇTϡY5*W+2jTbE=x,vxSr`;$b%Xl%>iI=Rq s! jH= EAdU +}t1>t?%~!j ج/u|sb38g4X"[9}RڂDF_uwJiIKX[W٦6_^oVH!,EHTOW1.RRX =D5"J (ȁj߾3ir*hwρ7Dnw$6nSJĈڒ",u#/4+!PÁ?iyô46柔boRzW`# }"a #ebfzGv#f֢$8ؐ) ^zde\{1[J,*=Xz;s4yTU=$4IY:tϘUbS'/̟\~k{.H9۪WWoM/XROܽm4i}US0soG 1t_/˛9\McӦ`-|v.{VxXf~jX@5I(>e|qm""U5rCN{'ߣ7JO}dRuBdoLxQ}ytM}-BhM&Έ8Bi*\?/ܚ|K.cx'B%S"u5Yr+PML کѯߏՓE-=sGCg:ŦBP 忁>Pc˜ ֘Ni>hasDfZ-a^vE=/D:Aek1FENM)t=Jb9 _ u&\lq5~<*tlV #7mש׏j1(ګ'yhq*(1 3חX`[\ R!CgUr9xvb+ 0: Rvx[ޜ\eFX+SOO? ]-'^(uz2 Zc@(g^BSNcnmY6 (G߽Z$?0?#ؕIC+]&f[:B%6? t^3*;яr8?-gl;j kRQ"?| 1b52s-W3nU.mB/+w<ԕK% 3y=<&ܞrYgҬ'tOI;t=J&0əi3 ~^.;cUMoyMfLrWЫ 7~.`fyXQq*0K H.hwLAm:`; ]ns'Cp>\niܕh\1^e_ 鮡䢱b,4!ų5NI01.kIonyX&Sp?\hLQ?"+W _wzxj@`^2amnK ?J0:r*@jI0HY~ekis:_eFs ŠeTw{%;9SACֿ{A&uu;uAPH 8@nu-=sUpi6`2h,zViIR\y̻g2]_  <ԔxsE=zo KZ(Qm v-iv|E#Mm ɍ-l]tG ln Aƾ](ې~fi U/j$%S1T"$槿1$n1VkԹg":3E .@ߏ}ȆR-)EDdZP)CQ `sN9Emzen(ƺU&-.H>C1O ^>yуbByU9#oEw 1[2[ Z7FT<2)<>"!E}ɴYX%PQ6_#ޖˀt'wf1]Nt(8Oigye37.gc t1<7zNHIY?`blI/ʓߌҏ0 Mq0=ӍGޤ1B8u[] ޜكyf/Eխ`ewZs60Z$ 6C~R09Ɔ `圂7D2 .' q)AK/vN~.$邇H# i*  , i?Rh]>uQbdՓ|; }}2⾞]6Kg4`ǻx1qGaƉ{ 1U:lNߪUGv*kAw+om\'P3T~8x{Sf'݁%\gkF.`qqwHcQ ||Ono^I jqJCs օѤؿ i/Lrg2ҵɗMytY7EMLtt9Sn_e3>#TpU"jO6V 5l%p&I"d)da2m3y9\G'ǫ̋4:n@^՟cG DN |3"+YZlCze)^sn2x&` ] AGuC P,rM7` ?+ֈcY 0!4vs72#aJuN-pQ顗f5-T5 2G6,6K@Cz\XtUA(? [P8^r1 =YLϋ U\tь^y9]0'Γ8FSr>SypiR\[l/\*BIL aBފ*l޸bqS\&Zy_۫(팉PE:ϸz'}$)ٛQsU Q%9 }6Lj PHD1,1QQU]<3N(3 E"ozQ6Kq97Q Z-g4<1%^!`8uP࿟-9wozbf%^ANj{J&N!RJ( R"[,S"- ݋d~~cRNug._ΊyNmۡ=XM2)f5x]j7nIp^΀Y9U' -q7,Qt)ms 4p٢C{rI){y{___VXm:3Xgx4{D5 JN* sWqqYiL*23wf83a'UEf[eشl1sk2%`˻mP⒑-xaFɃSv\d=@U1Ur}CF ׆Z| %Nͳgc<v?koCLzV! r=7~&W |dLpxWU]ΔÃKOа ;§Jn R q8=3uO=lbE<)'ik, Zuk)VnKZѪ\KsȶT0!b 3SchŒ[H3!+|PJjF,,1|IHlpR:$/vU=vX%# d*:ɑJ rErDF֤G{Py+ca1"&/6.6kً-%6ʌ dy &OKW+ڸWXr6[9&1MҬ $ m0*t,EG~!&)Qe{>in%L=tMy6QoP{b=L).LnsyV [:&4ҝ2|D +ιbF 9 J$/Z lqt)T~u6xD*PȢQpvZ}1Yw*#mɑE`[UWG/A5FPI#`?%dͼOd|:x6#Ip$ ^@c:Hn,}M 8~R?F XYrpi A4rVL>ʋ8Yt W~Vӭ_vP6H;0XG)q70 wY)Y\h.W[/7& s9V p@ʆrݣA-k陋%afji9+yԳ:NXE.Q?8EluT Ycjעm:m>6Z?pЗGqm3 P )]Xc>;ퟑ;be _V:%›RzYF SA0?Eԉw)z$T+ƁoҖA 4l^գ ܟa"`|7'^q't?L9 'Zd+]'t~aK'Ͽ'3XS&lzظVJ 'nP~CMB;y=3ͻ{b4 *EAI3&`&VT+XQx{2T11D?*] ?%#9P*Xxv[ć+s㺹 {֘:LBY a㨞[ @BY_!IڎhM4]X3#QZ6Ю UM|V!VAuar-+_2T8N+PMHLRlڒf䄹4aX  @:îzGe"BM~ޭǚaR8i+3dsa[iI`wW([QoFdJF$^VX%SšrrҴ Mn|eV8Y3 lHpfqV<7aP1o5s}9H 3ŁNPmR` hxcS3߉ _jM4f%_I8}l%W@cK*U)bn|aвJ3*jZWy05~.Vs j&ؓ/jN @5ߨ२sHk-*/Rq'e-z?*,sWYkw*¾}7쎱i[W"Ңe-Ɏw5\HF։IUܡ6iGzir;O ?3m6oېlK ˸Pރ|ar(to0 Tٰ Fp휝u2" b#J!;|;~W\ eWRuWXO.eɝ4`xu <7y'uǵJB#DUA_luAr.cjlL \,HBa1dzʄϛژLAZg0742:(^^OP^Caڵ4Pl=-vy^YMI SsӁT&5olIoxM̙^Z *=G7j>H\Ɔ\G :偢71]lRs^Hؒ?M2D`ǽ%*_z7&oAmZ#C>z9؀QCL:vBHԵ$yKiqn}[l2DK>f<.dޒ_b%7؇Oed\x0E~d/O Ʊ4L!ςt<`LX%c-T $6?VO\40 IPÙ-(3<cJ.*vǧHN19ߌӊ~Τ ьp zcsq(:hMeb!"Y k r\DW( ;`Z-xS| (` KxN{OMA.κo7bA+e4+),R9k6L4ѴqMވK| t,Uvg^ Gisj :7v/)eO¡ h(q 2pA%8}D2|J!1e EVcko^< Y5q ?>3F1oި8]Rso)Фd)!gZ疿o37i1eQًTȿ>rm\htv>QК`hp$]9$V.<D?y^%t|Gޠ+f~`sݰ75ӊ ag4X؈!ѼQ14@x-Qnd%r&|CV79$/!ufvֵby~R^=Z)Nj֋?d9 $9-i(=ڲ4Fk+@zS䥞ac48{bUI8nx/8YSAa,J9TjxNzaҎq6f#e껙qjbaHJL8*~|% KCX(h8؞ZcCTY{;1[c?p"*o Dcl ۚ%QuEwcIaԈ5jh"2 >qqpv:+( QU? KԟI?@iM$ƨxrPßyXZďsW * J+(vI۵Fׅdb4~ ńw}_ sQ2wu҇]iI裐XDrlia^A?qshcD[k7(Dqs<_X򆽄 kCj8o|36[xq{iQ#<sk,t FFiI|@cKuSiFe^%(lRݺrAHni XȶHBQ]|~6ҐfcjCe{ᵭ߼YLőev Rx|fCp;_=s sX$}s7 A|ïG \Ѝm1X@hlЧ =FCRQ1W3 x^.z:6[Pʅr, g+lMX\gQ- V Z6bѰ|0Y`αf>:`Y~ 3;9Kꁧ.g)EIYN3]!&iIiZs[i-ln#dNjU$?"˞OPC+c@a)xBW9'#yZE: e$3g,O7~lv=DR=gz,@@3*jFj/P-))땋G<&@mrBB $Q;Z heղվ°wՕ`tb<,Dv7_-D;"7z<M1]jfA5SLʈ yV;^7ϱ\p!> 9/gCAV#Ʈ9 uI> "iyHY 1 d x-b.WVL#N'h#ӿTWւވ1P sm/XuN̏/Z9e.d&3C8c$-{{R;NU(>9/YoWXA:@|¬)]5 e@9&[?~=1c[<W*z`7s~(w t'7qaׂ!!̩kx&hÝp-^Xzll% ܉NvDYyqcK.\hk+_#:J" s!š~+K~wgw hIDCFq5擔: 5zb>FigrRDG1ĜWS}$;'\6J:>EӍ0Iۉ"j>!ޕo ѵq}P~|71}lo"y|9wNB d<(PԪI/ي&`>Fmg.pvey_I{%c ӏ&)vn ʂ5i+EpۨѠwe5gA. 80K>H"gttM{A&p}/ɣB4I"jN 01K(,#&5D_/ӼpFYS+ _ ሀGӲU,2;76BlH1+Mg3djǵTL ?vYȷ_hw),̺oG8<4uC>,mă3d|H\2F(_jX.tՕh 56 ƞb2ktib^As;̍AǐHg[l宄62$R^ͦ{aRg7;ь,{Rb堯!N__jwIX73qH۪,m_j3B5E 0 iǛֺYn hOYv12I‡!c 0.7O1 yt" kys?8냮vs 6jB |ZGɔͲ><GpHe`!F8=ܣ)J$IkEɨ,:.~)us]mJ?dj AM%59UOk_ >"͹to5+"3"r$7o vl)P75wt~c,zX^.^hGhZoq5jw*u/n;c:.!/ΓMܞJOr\F8NQ5 L١l!r MmGqc R%1 ,l \6z_K9)4 {Mu$hr&1gŻGHf~;$Y0Ӟ/%OE$ܱ9ڈFSx߇&8Q!_&َj?vx3`$Z`FC5v`4>ksԽFB;z'ˈ̞ n !8Ő U3^_]r$]fQz Z7讶PfBlFO|qe=̬d/ц 3&LݝĤb<:ٿL =H2&׼NmDDPʗ<;;HdksHF@~HL9Ҷ4k ԎÙ#% s$Q|ٻ*\#[43F6qo7"a!z1XI <c[|ģ}o*NEJ}O8\FT&9u!co(m|@\SlCd,3G˲T-& teIGxUB&+A"t3]&\)]9-Ω;'_MSmҜP鋙LO|sCF`ÿt KU<@՞s / %w. iu*b:ëR*)~m{ܭadM{$nlԽ,<Ґ9 A3>$- A-'2@|]RY4ˣbYa1T 6xBkw´'[־(UhtZ--©W ^ J)LzS?w6sAt/"\I.XOm/7_+sl&NC.'  Fax;A9 ?rvL1LLKոl4xP(3%x \yV P8T¿X Ƞ+$4}ܘ(}!׷OXe2Tq{pKtLUΐE&PtaXOD~%ԏF؝]j# ȑЋn |eE 7C =gzEԑۀ%/jVʅ9٪('$8~ibZ'{I|Wsz׮KH|0bX ]CQ_TwBKfGK}ͽ$K\7y)BUKe\q .͝aNaǠwG`yg#aka{̩/Pi^J0@4v b, X]Ah?姷2/cn!^iQ\| _[|c%Oj[0Q%,Y}w?Cv2!J~[WOd㱲~P"!#zkP>KAeLj9ugѐ4/00/As7#`wf ,fmt p Ccpo{,-Z#lY&?WSm ]QȜc3RRs}e81yx`O)$Q9i*~LDmDw@aZ$%U觚_PGm:wzHszFS4r6Jmc!) Fy(9KVľXF20k_37)KyMXF2>CIibݪuk$R%EͣZA[, t܅$P"TfuVdwWWlCN `ƞq:!vHсhC˘5U{Kă[fC^ΥMeC s^H`<C LX1л HC b]|1#ʝd&kJ:_T)t{/nBLT?ň0qsfRH5Ecc Wx &wl''Mi$F3!ލNF?0-biҴl@KcK JXiɩe:/ ͏~v2j[FJ,>wg,IG\XcY:9h87C_>1.x!UVH 5\C0E1w Wr ZMm20)!S_BNUqj Xn .И;I i/՘hw4; ~C ;]gj2<$:hs+1bS XN$z5v2Q}$.ɩSJs9+iO)&!bcBH$d ?E%tiZ\<'.?+ɾ"ou kb*E 3zn: )0G{-Irh+m[UҢPKpKS_v=Vj47fB"J*g%[Bl6Uۊ +&ڶv|-S6.ZfIY<G>7IS;/w5kFo/ʗRtwj:uzS5s+xSOg7\엘+OFEu&Э|t?ӲKE[zZBiUwdӆsvYѬ=Jž$r4Lz-6qܧ wv@AZ20Ƙ?(v4,[b -&TϢ+Abd>$+֝dʓ?Y|;8/d,, ,-م9i Ȭ |{Qw G`ˇԣyYaDYq™K++3ppY.lv ƬȀ&M).? ¸whGoJ >V3ϭNpR޶ K5>>P451c/ʧx1gqND(쉷U^;~NmV_LD*n>:0"tM>sv=I<`od-aYC%BbڨC'іWMN d]uϔ /2o)k‚!TjGQ/= ~Bw*d ٗ貐k5!d ":Ul$?ݶ'aEqW/'nG g X a&'x2jlAo'7 W 1<6iS(44~vknɒ~ܩҩ D};PB }pA 7sYIE$q;m53+䀪U)rGpNZ{|YYgJ?}2휔r^SadTNQ1j5#}XKnj-3#W@WQ\13Ľ( h]V1.]"BT3+5."^`P /g"R;$(RQriq4&U3hUiʝoO8m+@M+5XX\2W_gHcY?5ݮ@O"AmO л|#gPbsxq)e0XP零.^)psnY# yZuz5ţV$mi'^[4SY%8[ CSւ)πkvTX%x~J-#{lӈcNa6wKE3$Σzt3U4Z#]ʑiӶi~!t ^1.1ŭ;½2@-88r)/YY\ΰ%{fk@b527.xfR~d ?4MWM\0&4ed#LcFa蒠DoO lXϰ8% c"ɶbmɥbyDv.}1]\aD0pZ; ؠ.i-R L-J(]4U.%Jj%QotދxՃoa? +ޅDe:<AujK1 QO9р?WH J15u}Į:g5ݻ.nXb0V͌e_h>Xt`??;h>N' ~?,Ib#8Q++s|P2Y8LZ˪DXf@gRisC5R:##@Ƹͨ)Еs.q4Nۑ0gvW$ٝ' I7?JeB?B"p68Ț;g-9NN=Y!'ض 63QA3*L$/^zo9hƿ*j(g7y89)p7gcG(7UHY rJQ͈DerU#^'혶7$M`YZ2SJ 鎂vB6v0bR>;5 QK*yUh6rňFg޺[nP*JS4m>Rp)~ރ]VV{=Ii5|{Mԋ =f0ݪ9 "am7i<~$2d;5$>-h3leYռ>ڍɅb'MM\Xp6syjJ1Rt^sF!=u:FFZ\EbP\גH޾iD2)ՔzeaX/?<;)VVN?wLɀ}0<ð+G~ex MCK,Et!( OyNE' nG*t3hNVXwmanYsRTd`uA&ؚ!@O%Q{0K3G HK,a똑T# $tB߲`7ӁNը` z SIHU-)6gZ25\F,N!zNar6!$= ̰؁vbNXk"\ @_ wCCQc ~2(Ov)12J}]/k & nöܺ3|BABoJ3 Lj~ZoQ«$Æ,T1(sy-':4ZH,o+1A f~Zi>FAg))P Ew426T.~6"FR1RhÙZ1==l3CyPs :3}vQ"r7| 4aNT;Jbb`H9|eETȭ o/mCbM6\Wi ߍ&zӓ^ kWM8z!dKgrx c%2Tv0*i_[U7I+14?x 4Umt) \a bөW_a~}fi j2ۛ hb={A#9G2gfk.閄,Wt cA~ yN·0+ 7Sګ`2n#U[Na:%D3o]`xNÂ[7 w;{l$Ϛ qw*uTvOc"OՀ6"M/eI֬$k^s^ ~U<+ȭ$ڐ>T "x[$bm^ڶx{cHK:+0D >lB)fb`3SgIyQCISdRNLԺzTnN툛@`<UPƇY!o+H{MwM˞\6Fë^ERowQ^]XWcxn{8ڟh_-kxнcӯElhŧb{@`$*A/5 nGbdmyތIzAX"_u,M;b7!9eݽ >3hG{7oq$~gW8Oj.DFj3 %$*ZlwF?7&`H>6$\%r&:[g~ y,8g2*6.vgT8f iIJm% >R+ya^"0,zg>QӺNf_+8$ݮf5bEi!9XU8xW@& Fd1DO%C2Y#>UURh/-f[K:G",v 澱{]=NZ@*,.WM/-峙@bwidFF i"h5XbgѢR:Yw<3EE4!|ѫY`ؠ!IpWuҲ&yjn3wKD> QFZ$@Z:3MTMChϒɝBa2/L]R?v0ҩI y\ȭ>׏MpFN"Dn8󼀄V"C{/+t>?c"ŕ{ C֡הIn`Go ~BHXj/Zr"Tc갃:SRT~r4{ϕ({UKo(BIrFOrᷱi|?tze ޠ]*DBG~kXPc(MB<'G]dl}V㕪XAv ӑ|I82huR;Ƒ&7Q"2UcW)£hU5ʈD׏j?x$-3܃N]&129ɤ$C[&g2u3:)VD8cȍT^mwXh0'}6QЋC9yRzš5ka0ӟMaoO=X:OOB(x{k+ `B>QrM2Pڿ8'0jN'b Lk"[EO`oZ!9MBCvfpz+ KF;ySjR@eu_'r)7i2 ~\:P tΐ5Q;ѺC<o $rHeY)ؠWq[)@K ;ij6y"dxAbIta TOJ\|TVyԔk}t֭NaN*q{Ώҗ6E/(lP? TΧ2OvCERULsǏCo805iE=w79Spۚl\innKgN ҕo?Fuc0 Y/VD 7]Skؕ:DչiH D5"4*`ytn@%kF#f`4e)y27g,`YNhڢ]x (I$sP tzˣZko73w?Y x#z iF۾aȳ<$Z|zb/tg?v+֑E &wDFj}ug5ی 2ԹZÙv1y为p!B܍Qe o,*t xv4W8ؒsQꙩ1t$l.J6*Iql,9T`!_%=s{g քLahƸShEf(#dhdB*Ӊ-*sSiǧ ^9mQG6T!PZJ0|˶Xܹ}X^byhe45=i`oTJ:?T=< 5h`6/?m;FâՑL.8(G!U9b"2p_z״dhS.%}a7 MۧlMZsEeP8"? 'q4Ё(: O'|` z ۤP(X~*x_$(Qc]U) #sKvag aҬ̆q)-N16츅}*@4y KQwLС!ޅ'6=B6jo ݘm2qfh nLrmٜ@ d!q+űB_9t4?gQ4Tp0 <}y_ק8pL}#~\R16BD.5-zC]x `1&-uKsbSgC&슣(cnB]:V: hЭ2j%>'$  [ `{L*>0>+&-R rlHm~/Z`1BVC̐#pzw-Tu. SR!<7%QHudh4}DJ5BHę@K cHtW9¢o aMx)T&ٓQtr&.oU[@[!:ɽ`(T<Juth6Hsĵ*öTׇ>$fw&5c wTD”UQ]wL!æSV?:G7VK6Kj,Ѻ5i KޜJ1|QNPۏD.6Uo ܌(п˫^.<!]W&9^ۙPjl̈́(r^ĴF \}iea=HH] " "gIv2\"hSua c*Ou?X}1X'u@HĜ+슎^~ʐS>7N.|T`^ avZݟB ̈́ag\KX4}]3k6"d}@h2pn gVnGO1qȹw۠-=&Ve%b0ke'6o.O X=gG$FNJ]3y-\$f!p8k(4պof%  kT *ѧ?1kJ!:$-4ͱu Ϝ]/SXW*>(>52q`[ 'D0܅^N|M$Vg F3$#Y{QM4vMAS YOL V%x:\D U]t|m{&}։<IЦ <\ԫAa3KSeK –#1I{bD+n(A/U6b"Zթ8/ ~mٮ hܑ $:yZr5Ғ %2$BlpC-}A73mqS>\~%xo-DoXßin↼c@K .eZK0vo%`6e1R'O{eўNfJO oڋ7u|C{,C*B+Vk@pLH)Zw8o)ˌXAC}4#DžNN;3wSXhIB{yJRRfGXH\pr@O/O;7 7/8~Wl8)(xW*aqHL28UX}M c?-Ad2Iָ^EHQpWC?ǦC D2&~EY0;E L(4 NC@2k%ꎯ2| o63 n/ޤFa;sW\Stc "fZ -Nl ^ƴ;X"uZ'dR4OOnbNtufކg:/NL}߹Ʈ[a' Az}؁thB0Oq9U\u8+T0mvzb@Vm`b_<Vds~<`{ lguUwwImt.4Nxzy_7WSU4m^;Y۲ʒ3DEC^HjoԿOu[%2ZWļ~ }[ !a[7SǢ6&9)lgtyNG.b-|{שWF&dmrp5 x sN{:Sߘ/63kg>n* {~- hG?՘(O)Oon-ڈv7RU[XoS!Κ\vO%IUJ^:)"})v2n|\KvEŒ 1#/N}$_hvkA ?8/\@R$̂ȟ<-scI̶g13Ic/轑؂:`|0<ϫ+d @C5?/k佣bLu儔?}&j-lZ[i e` .tB;_a94aY~x Jsb֊1:O`:5d{0@#IыhS"I5\^GwBL&78ِ$y-]Ͱ7LVey( v֨ ٶ OOuf۩_dkf$ ʵ]f`꒐EӇeQBcSv}M3XV qF.X!_+G:6 3`p%7 A˹RE3 3jN#G#'$0a`k\I=ŰZCAw7Ç{8x% 2#9a`ppZ NNivN]:ϰ2r =Xc RUB-沕1bx2bj[Kv:^&6WtP$yQ,@ f 5Ӵ.dBiUR[+]7+h-؞`Րn!"%cJwq3@Fc@-wrN֔:2gHą[QHy0n/x3x8h*Bx ;Ta'! 2.5*Wil ,!mf'1S"TZj@*x3VbԨDuW7WLώ`nj"SdBp T!~;R.l)6VZ@ DY)yb AT"33!$dֲ 8`@AT>I qc7/hjFFA5E_S-fc*c:]ksXuJuvkgCDq 'حbâvW;MΤ(; d\{rݚ?r˷pC\>R{` S3@!V˝ԒgӸLz=5rUg>L/#XIԜ'!zJU1}- TS'Dk^(8x^C͟s5Neb()t}ď{ lVchbC𘖄LO7_U"o59$Ų)L@+n$ٙz@=k!}: $vr$t>о"lU,;y>~ r&Eo¶ٰ K4N^6]Vo Z˒d 6/el [('ɳa/U!@PF#)Ne/ k_c$DD 6xGbX2#qŹ@Ǔf GzcCeG'[Oj9BRR*#vakޚDF5m n zcFB~R/5J&µ2" K4$[zW.s|ͯm5<଀6jOSyXѤ^ŶXf  &3@W =o3zVU;;?QRk)Pc .nlGZ]-6U*}} zqnA/k߳P6`4Cxр8!lF(w c~$Ь T(Mk5GLV+JOXa^tJJ<(}ջ+带=0Lp"HݟAůEj!Dō/<^?8o5_#t_m! Ke®=?L:!ܺ (8;W" A:`3jg6ᣀSyS>h9v [۲b?52jd65U"lN_`#[A#H#N؝8>-qCrjS)"$|swyOE932Zd'A xxHjLlIxZ_8-h٦:(Y$R͎',w%N{ >ZHPpY:_ ІxaPiDW>t%D g ԀO Ih R^rG|:cT6y\Tk\*'\Yjē9/-kю~ %þ#,e"d3`Ϥȇt T=N00;g̛'@%x%6N6{¡5m` S!8p4FT҅Z2fڡl8Ssj ߟrOFEXCY`2}H`Q氶~yWq,t}hЮqsDoi5!+^d{6/E|ujJc3ȯ~ҸFٕoM?חbcC· GcGnBXX! F̧4u$qKo(hL3NhMsC>cl+:fmi8mLd[DWD$WBS&k}k4bt=Sv)<"g?j)bH|,VǗVtjKQw3<4IwQYl$ͧ 1 a Jk 7T{i"4Mӷb,$*|g O˟Y'*-J/ %"ǽ /H?vD lXޛw8^Qq>7SbnMP >!eVL՟ΰ΄ 4x`*'T]m:^nu8MVM~qt׋iG@g 64%(QAmM;@r"ھì,gXa)[{6/I8I!Ejn"Cg)+YX9q;2i=xw툓,47N Lizl4+u^65;0ԻXfsoy>pi#h; P끝$% lak0"x[ 7t6LVUPOMY>hV_E0d^pPځ;^2:g#ﲣagP>tq+1l"Un/}V]:si;δ1#6!6EK@R.t m&aeHv(p &)r$eEmPܕ ${~{7恙 iZ(ۡAGNݴ {=Bv3|CZ%az&HK2yVy?*'ZG8H3 bqMtH,yW;5_T;kj&z'-+T"~* &Pd$C+9PkfS MU6HTjcDeuK O,WWF)[~u@쥳){mjWzg^󍘦l 72@E.yykă?<<}䗋K'[{Cvp 18RixCw P9?/Qq6^΢h5Z\R㿺Cʧw42WE|k5q° 9xq32223LpRD0-)H_2ɖ4gi_Ri'5 C ]gN$Jh6F@vMl|gd ,y]p^I%6A7-4u e-9 "tѠ8&++&Ε gTQ!jߐ%5WG!wm(O/P싻zq9lw+V."opKu#~#}Hj<$ؽwfq! &Q(\5&Ƅ< >Z1/!,s6<]/%fC 9>qHF='%\羐jkrی{ NZmr 7oj h.[2yMa7F%ho1l끇ܨ/^D:!{Kl+Hۄ6#T=T-Xp Y5dI4E >yvSL,F9 ,0{y YqQK;1/ JLߪpI 5`lػ \,_-)n& LA W'?_76c:!Veaj/q3L?=9 çN=e!w C8*sJZ`@Kw1(k|*p\fS)@\Ir8Y c*AiZbo9ȭs^lV?`*b~&{"37RA>Y2Oz59_a%aIIضPxpˤ3MJK#}6I Z扮LU)bum'gvP$o?;P%L$%9KS3Y+d.m+x y3-׎̭H,LB٭c]& nůU=XAA|U0,@D'S@ &si*4'oW#9T '@ruط O#'saysZ"ӓ 6W(~zŷp9.˹<B WxLonlZi/@xK4wזּusx,3B'^==tdM]lV6<ѪG'nZqaj H#sjN O[<%Hxy{.@4kx{)M{5>ёbB6eEfF<"a`?:"{={vLäW"}+e+|kQ`;m:K4h *Ƈ 'ȋa5%CL4r̥=  5N&ȸ%XEH밻gy UDЦiY;\TShB\pq7) - &9gq3Q 'Nc'zog^5Tg%_DXc}ڞG4t84Ɇ3G,ͥx\#BL! ZAuRݠM}&H>Qg6(? wGK?)8|f5RŻX\TDɮh-7ѢŜ+pԏ!a!m\e`vgnKz8dv\\&1uCi!񅸩Dr@F/׵u8$b-. WiP p^E ,Twp3QU^\{Ep$K=~S+_+:e 0Z^Dд|.L[2W܌w=ň1b'fB^Yփg4`y)\~Q./ImI_vhZe9Gp#dT4nAhjvM'a.?8Z( u;A&)2*`((7>hRuA Au}0;>njM/ B* roHḊi )xxo#s:Pbߒp05^nfP-|rb$Z&CfbiCU~2@₩(g7;Zw3 ^qPRHMR~&Q3dkE|绱80ҳ_x6uH3׸gWD؊<0S齶3k X W1H-LRSUOz߄LP?3sJ d'A0E̳Fb C]@Nsfa̵A}zV;Ka3̌}o*Exiɂ0>veŽ^Qfs$4#Ի8RQ\ `M*S@X_2x{FV7  ofyPcL=miY V2\+E/  GȬd;\K-u'Z/chF9FԴ D"zE%ƥG{Ĺ8ʞE}cOVLKm1 >ymԦv,-][s[M#@ZX&翋mG+S!yj]KO_BIb*HAa@I*^٥8vV L,d{m;^cxW<$cs:84Tj\b+x97g -T-q sGn>9jozWON !ᲯI?fy\5`X #觪wX*)\>g䊫w9k=+؜ ]C2QBQOge L8%,CIfbq$ ?3boT-js)n~"x3ܡښ't[cI @#]&/2~TqLv=QKD#XhY=+J*VۓK5$rڮ(z,< dy/J*|`h" ٳHYU4&~+Txtq!&lɮ$j3L?d4lѡ4 bBUŧ-r0BqwQ.t_Q{(6=}/.U}o2DNo VsN}T.: ַ>0CD^s?:h1˸~S3/. .@?N 4wm,v{yNއk^9R!p,ŁKp[ )=TDZ2'5mKalq.V|f'zF o{A_VH;˻ ᅵ?,?ӇMXaJؓ{ :օPrm"f[7ngQ@/!qCբewA# #D U[8vĭ0Ɔ֐{K{˶IOH7CO.ɰD% I2 ۻ&pa(obh~ ԟC 412\ImU"*>JkO,S^pwr8(w;JY̼d9!o$)5l]޸ +F:vSG@ )ܥm8Yxai6w @]B#}e/aiA?ޑI c](|2-;>^AF[ ?xll8+G\.ɷR,tTK?")p jS5 = 5l> 8v8fw :$.ꏷ:rw+E`D:ΙWPWmpQz*|՜ri8aTJO~-QLG:*F1 ^'\;2ዪ)LNp{U=%GWym%؏B/ib[n$}t[ H:p(WX-c[hwUppѭ< w)~}c-Un63ŴAci!.M-h^2B;]JoGzqbMMq wHv1NbQKJRªң|GI^9m B~{YFIЁ*)(CAmJAzmg׳?;P :8» AWwP ~~ۘq #aݐ\ -i4fg|+wAÃ~dǔ}%Lbtyp+Osḑ.wͩHC {TIP4%SQ+&Vח[|ښz# m5ڑ#-Ϥ0cvܛꗓ#ěT/f:|!I mL%F.{z1s@< վ+Ha|Lk~Th,'sb 2o,z(Mx'Ǟ,l-1Nձ]|3!n0Ϟ/)j;`ux:kǹIÕYz(x>"6Oܫ@Vz%CN-d F|*jb,~_ߚOyn4k:!/e D S.}.t'##πY #ފFMcK92Pjj\~;wo0mrh% lsL~C$ *ڔ2O1nql{OP.z$2o ,W0Z\r*.*rH4`>ɀl|pˎFV"qA ?ܩhʵCq<mrLh mSX-tF*ZLՔNjM3^9s/P5-ncF&i)B0ǓӍZqQzFIfyGvq /X~t}߯W%Ȱ#pbY(وQD+4ӫJ6&ee\0"p@.b.jӵx\`f13?T;ZAR޲.ۤ_,Y]cOL#?*KCD< WeȱLc=8!J8{ $^d8є@? Q&w8z*#ho Z|BɋF iigCݣ]i$/8l35Y*b8R8}xKM\HdOC|&4+oN2| Z M;). Vz(%_)퟇N'T&5r(2<QtoG { xrĉIA`ɚ;,fe]'޶v<$j*uV30Gt`"l%u \lԠI/]&b.72c qM ,-g tT*Mn?ՁcG$U)]ʺ'|F jT9٪, P ,qH dNT@\!@?#g_P e y",8rVG3Z^ATȾug皌A`i4JS 7/E(!(%PI!rGAKNR Z6גs1,Ke)F$;dzOj4pWl]a׍-ߞOJ[hhJj; ;o>j i5"h e/`=7Fʚ'`JccAX7ob)# 岌|Vw4bџ/{td@+) _Xbx'졓%KɄD±ב zFQF~% +MM wze7}z~,fȒmګT{`hzMe {#p6]MN v֙J㢀BDbNn. BIBpRW 5S܈ L!蒭"U:!$[}6)Qt+eK+=;Xߌ'!@W,SE[]|'eƹ @ _cB邀ؖ|J%a@rRpBWS#yZs3`H%sfQQ-^?f3BE~k-1uٱ*=rP=)0,"2[Wwb.{3\ Q h,ظnN F2L*EYHbw 5л${>ǷBxx5vˍ9 71wpW8D">ƚ}[s\`>$itR%{,[ea6}oN1ֻ{ߺ FmGw8?we?zR ~R%#%=Ee9RU\OBgpSLr?ʀKNq{~z (KϿ;px:oԜf)fnj7e*,m.BO#2 yuZG:d` uL$bΐU<) JӝaZW2?С([vкGv[ +HZgљ}Xݘ"?J.q ebhH!" |`C}MxHZ=^2WeWمuٞO\;@¹氋Nf~ bN)t63y_A}١FX_b :VRVt0Ry!'Z*vSDdыhE7RwK9+U ԥctuP}]I"= q!UO׸tduIբty5e.\$ $޳ 5?0mЧL1'[ב+YHTēR±A&Y>w> Y`9ԛ*pt[qiبJ{Ҋ;`y϶59G,"J@4v"lP}CF0D!S5V(+m EȶeR(2Bso\]RW#پ$uOd>&4IU[-9Ȫ鱾>-_ҦςоbUaF9pxgSƶ3.GEpNJ 9]i!cz0.T ^rD0ְ@6c wYq a =KiXS$> o)pZQeHkq'tY y5/=.a9xVPcА ]vc,_[mT9Uj 4g<җ52d)OMBGR?"iյVW #t3&T%/8CL ,3˛XF}Y}QWD/-k7q[0}>0[,MN(*|k >.OO($\_A?2v:P?FƗٱg=s\PXSJ'‚7mtTd\2:l|9R5js]n(R8!hP\6cy:9_ $r Kk-.*\w GFIHm^0Usyzw8OU@~-^QeZCiaZ2 @y4{ѳ%oʼ^W = ^ž(ܴ}b4)a W=,(lĻD%d̄\]. ߾NX"/KjUϿ Qorߧ~P ݌ D6Ŵ= 4zPQiijXJRGcPGh{gl+mB㌨JS ɠON}4ѕc9PrFc8K$5JcT`÷H$Z[NČ'1jb[vN)G K{b]^4zz}<9;a:G }&nၥLpGX3κ[)FظCW~P䷎NqJ##XVr˴NMX<ڔy˰86]"Udβ  TXUQgsE%oE ~!R$!0DL hBZ_ڃd%)KpĸM7R ؄,ǖ~e>Z(I*j>`V8GWX3'=|$ 7cƚ % . iuZ-I_wH<$3n̲aHยuW=}j [WX,=/ur[?C4 (Z9 !ЪJt|ia/,ڭ-Ђ~[($sޘ!W~( P$# pikc\iI L찢{4 z|mI!f- #"!lO7L+F[I VJRVi`z?{7X 1..}{R7mRnqJ}vMA2\Vbj,'p ~LgbX0AY ip?׊~.jze7``@0!wD4^9Kk|Aqppq8*6yA' .y`|5e ӕejl-t 0:ȿRMލTТX`Fd!HIn㦌<TK{5C1)/@RiZq.-19釱C |j?l8EуHknRQ gQ@6^nUMR;lq#h\/Z#ep.eUbQ.4pv4PXk{=mBԏLxݗF>7V]AI-Z ;in慄fύ3wv-=*&NC_ƿBs=Ӆhd&Vs/u4he d!zx2DWB1H Y\/7R|yv~gL#FpxƉ}>۪bpRbbԾ|Uڶ/ @Å%KxyW\o]k?hnӜEo;d^(ce!'$C{Mz5|Kы S;@=P~ Ggpi'7/`vTC]Drְ&L}:+nw#bvޱzkg,q8>q\%m_ַEwK^X C} Sy-!J:&-ELWKW_̍b cO>BG`"L/ĤemВiR}]Aǟ+;PG8#?|d'VY]1w/aE dnxaM.7B6_sMR~癆, cr]wB_uEiVFf 9(>۩NN~puW #_8~WeFcų`U&rN1r?Owo.ΝU{/R ].RYrXk 90E!u>*Bq&An7mvW1#FՌjj "gDroag :42gah,n`b@ =y!Y?sk%`k'w>&7-Ŭ BE|jJt@ĸ{잡C0MN*o)Qg+w{#TYCⰮ) T1Gx|L$VŅF~v=F.۷3Te ,G9#5M,~ x@r%L;PtACeLىE_9"p0]ЮӞɋ=iezq6KCq{Xi׵ ~2DoDQ*˰0 g1H#DzK{3۠fi(EdI 'I"I/4&{%k8nq6{U?&$!c* ?Ol0g i$ڧ͔& pT8ŮR^hx5췎C/9qG>W-sݭ?6/i!vL.Yݼf@b)Tt'̄7$+N" \-:4I]NSעDj| _97uQ]俱 9C ]@hpH0 Ek+IR:DN}Y?V>t(p>U#g"('S1> tS̈́zAa~w1VLC/D6fNv8TuIQ5}Xc25hYk]XT35ŏ) `iF%} DqL2& `Pލu\2XKur=7/ο8.:V*ښP bT732EZzeԅ@`fIMƜ܃At:x:+5OUB7b̳ ^>{E9+tb *-tr lT?p(|iܐ/f[eRF& usYe=J؞zo 0c?O!,D8Y8n_VRƫ sɰ䔥We^CId2eJ9Q'Vp`v޸8Zq ̽ddMnUŸ$V< 9K<iltl3 ]lV`K`mΝ \YA c~%a^{r rMزfBPQ:\+D)㌹ww C,ӷYbfvA;NX]*:8HۋJщq#>G0:E߳Rp9rΣeOc+B _X'lw u )!3o97IYJl0"K\i a1=a+7pܓvʰxokÛ\Ս&Q,fa//h^o֛d.,|!YgWg47 Nt!ñ%2k8b4NmU\d.ۡ<W-P[=NÄ,\_4[{ӣFK()8Ca 8GO担&V*=$9j#=A5l k GY:AzC;ڶ:!76?]ut8E$w[%2!^#OB6"eK,L,s)7ooܻ}a]AR#,4aI!bEJX<շ㫂C\8wno/1x2 MRop("'45m3&]Ŭ.&&j[>f0=n=y[EcK|Emur}[Ro-*U9˨I>(%o=n} e@y!Vw5*[R%C<e2#,L,F 5(ǏOz7Y:s}9v +/Y/5ƗaW_jh L۴Q}u?ʕ8l-TĜ a"ǿ|نߖ0bD]zRll@ô(E<%͇:%~Tt ֻ%`K0hdz㞌ҩ+lX7A~a_lIڛ/_ 4,PG6Nm]$pel6#-:ʿݖbB?V3䔘Lɝ\Ʋ](ZSLe&$nTnSjKS{xa_;ThvL h9#{׃sZ ! 5"+[\NGi'caD f"⏯F0tmg"o8BXrb0RG,nxG$ߐ05ʽd\Dt~ M~ƷmDr/ ʨp(.o<\HK6x}2tO<%si:%{Sh_r\b}+;XۅT}$Z> U R#Q7Z$M+wdv-QY,گsE^M%0 zm͟#zfԃםwLu|RZmG'Y:HެIBS&P'(&=CEXa},Za&HK/4Ϟԇ~ļ<'FćdL&#q IH-0bJaT =:/CT8QDMPxvA .$mwrO.C鰶`#Zk=` H7=Z]SȐ6G9/Toٌ߰bYCB|bOP^[$ (ȸշI^t8BDՋJK.cDbX$ }vXVUƫ O%?=*c>m}_id oIg3OPEF*:?-WՊ078?#4{raa>=ֱB^+[ތ9y [w\Nd7#jyBEհ/@Fz&ax9ݧu;ڶpM$ #%ײsp %7\%! N4M '=,Mq۠B$5J?jTMf- } e'x#MSi=$ҏr.2kgKItuq@Sgq< .\o*~7^?4ڧa98:3H*B<-V谆p* ޻./׷_S &`}m-tn)8`#>hoo0``'L q 3b=Z` (qGR|*P1הu_:%' %mgƯS!cMս5+(%]>P߳xxEuDǐ~N6tWeꑚ]qť^m`O+Iʜ^Ȣ@TrۤX$Pb[YUR7wQ T3,q`ǓAԄ$k|/h|}zX$4CHN/uBPNCژo8K2>POYnJ?eFqg臰̘:ۃW)#FtJ&ݸvm.*掓 e"+Ϗ:y=0\ Ÿe7wXn_ia{GS$mӸmf.gMbyt|xh~DS9w9QkUTĽ|Ԝd5Jل.ؾ1rG~Ķh3@Kz ffڇVg D-9Xl^R]ͫ-ql;M$}fjA`Od'wcw;3!NҼֱ;orHj-%jĠC` @'=ᅮV;51J1nn/eo)ۀ0].Ykxhk:a x~* aK+̢ y(cwJmhe,#ZsEG{?J* {c\ws4d4HW~V-hiYLysrXxP9kGh! $`'-4OjPy4n<_sI3 q'ŧM^pm_6|ЬǜvY;ݕ]|#XAq^VaNM?Q~%rYa ۜIej4+i1&"fI,oBQ{SG u4qh< BY mdcIR{1]7/|Pàg^>֏y`ZXӦhdfmh_wR?uGMW;T>\pJƒ#x.J5$t!RXylA @\Q뚳#X0u;TQ`sj씲.HO{#6ھF@۷܆QuU3C'j5`@{v4:G=Zӓ{#[(cvN#8ϽƜCPD`IA1Gĉ;*%6~Wu44410O[k\sۥS<"Rr.YUy+OnA7hs3[3YN̉+8_y_ޯ=^h.=R6rF>/vbc0gi'"jKP%xa@t<>x^`^,XEi-dj@<2M%.`9Wj;A"^ߗBWTBIJ&9^Bqz$D`[Y< 2}e-)ׇu *yowxfOi%!J7ͯeyXKDfdHjڮ]_紬 ;ʯYq{3m,;yQO3P2]E Z[4Hv %ݙ  8Ѻi^V_; ~*U52I;€9`f1oS0LgY' $QCz M/.6s}Y ©e5uL;)A҅ wØNm"=iŵC0 2}ҎbBpĖXt~~z²ko5~W[mmlFXL̪ݓIg8#t?]VFÊ%9=Lr 2RU`0cBsRӼݖ7aJ#s7$>nT]",W'Fr(5ņިzry\+TdZi(v:0WAyQPVS* ]:Aײ/1X[V@lWvɴ}C-QWe;!,xœ?'[xi.\(Ў*vofM~C,7ɫ?~ ҴpNul|o,߿: ?bn%JQ1v`[(sY,yE|,Q;RO\'A%qA .qGٹh&ֱiReg5N6}vw">upkJvߒA˰MkbH@/Rfʄ=+P>׼uMEzfO8VO{{`>䴩ZZ/49ƕRN׵zR1EZJj{/HGQgT+Ƭ:JVv-_t}++|s>w;S-W2m:3\fճƾǜ$0ju94.HjV#KVgEAVZ1ʚ]/拗:kNeվ 5l,`yWV/CjgFgBߟM o%vOCV r=Z32oES|=;`8qMгG_}Zon{&<ZD}c͛Y7p`;3\z7=3淀b#J`73wIu"DXڗ !f9 <ǂ¢p-]`M<*ŀ f<.0QczT^nסB))l~J9dƕL%'#m@hL,j͠>g¸' kIZv>ɬsnkgIn`Z 'ld ݋ؔ5{)S4\,ʓ?Ş6?%;>e/cVО8[)&VY2pD":8U{PW0˃kxtK{/+1n|'`巣u__=R#'/`Wnʴ= &.oUE07W#dJqAZ9]3{#YK '1n;~q/֋?O>QYV#\ToWp$˼2KC -44<_%K/O.׊p`kL2&5sA4ds1'|N8 *O¼,삅vq˽jA<`2uk*7@8s((!Ta^59TOP[ъfT߯$,UYW%I=nDo돢4>Bb~Wf>+FX. Kz-dp5HI?-.zNh1]݁*Cȹ~y:/TLLI/[y%3~ͧxCqDRw0V?"B% -D5Ӛd#2.48-yf-xum)!PN{"+%2\)pG, ghV9 wf7R.:f 2*tpX1wio*ʪ  66P2ADJ.zfAOhفI:~[JYT>ng<ǘ|?A}У5]x齨,9Y%e4vO $67 -ח\TvlX D2xûvk%[#8qytEl~NixCD~s!u[Ca! POw9*G*9a0 ]c#w ?u F7 XmBHT3<4D%2+ J^fPlB;҄IW옗tm@2ǸW~5K79 Yn.fl;*]QDRFNGK\jfükwoAXڌ NC; :/x<us<D$+/t 9Bi>aJD[w-Mr>!H!'  OKֹz yLsX$w~Vk:6a"1}G i^yXP+(lalwAm/QdvD%ix=HIts[.px@ୃk'S#d$\ qT1D)Ç0,g<;.0f*ƣav6o,)2=X'jJo"t'M nn29B[p}LN0|ihQOzz|a&mN)"po{> 0Oɶ˩ǕՕ푛04[Xc=j!`+0ho}g 8,[obBz"1쩿? T9^c;ߴc ܜ<׬Y\F#QR3LQ+R3f4m>|Fml^5km'4ņݭ}YuAddfi׻K1zt~䠈gj9U&FYmP<\ ndp!$yɈBb!UMF jKS[iMSO*3_]Gܦ[vjZnIԠ$0vmw(^0 pkϡǪ=Eׅ=*KvhI-1CFJZF %E+C;NjkOT+y֊Q/8Hș%pv!^q}'?-&5Pϗux Z=&\sb@S~Hp?v}r? w7dK/a7:":^TCDï-"!KX!zz3a$~Z#X;,lp~F쬐>=V6dtVޢj`I5KĉGiTKؗEz1p|_NSHӥeb ogA#o&.߹jPFŬ@^'ܻ1SO׮F`Ra26\GU;DdӜ2v|nqϽa.WOkMGJyyX.- Em˪#V;r[8i 'ssשZ?N@mC\t*`'c'EZCQX`[I&3Ӆ.X|0˄|{G”Wh\r0{q moIs͝>D+Cа,f#\D'Y^ʊOΩ0e0ji˞$xAӒklKѓVm{1Q̋18o^)۹6^HDC:5g± sLE+w[TĖܾA𷐀aںcŠ<>N,{9n]ć;Z*vSH; h!/W"sx򞼠s !p'v! ˔m,FNRi˘P6MiP5}%{n:qz@c ɪ3;s8"tOl V]Lpmݫ`ܼk5,oB^͒,W34dnK(:L!1cF]P[V c,woߍCЩj~ܖ z?V$޹9B%jSBm3*Aة 0LqE4 *J^{PCs ElVqhgZ```1]f5w O}) 0 ;; U6o( sE( gJ _K*y_|9OB@o vlKWޔNdJؽC$s,V.8ԍn(! 4hm$f"kfD["V 0f2D_#"[m=PN#؏tjs!蠦k^ˤNdSw.DH{y6-w1W*Gxt1Ueh/h|`o\Bq~**֒P 3G\؆o90qhsڡ:;Ql!}-Y8sB00W)2n7U+l1z(4$MJK!q܊qr7鯠.bexFGf;)ذ ڣ'΢Z[*o<Ȫm@'w 2rR̫YExj}ZBJS=%.{MQcIh n\Zh f?N "/}!5cr^sQNǠ[Z.)k>a~2f0#!9[<mlN\@j{;˨RtXhpBl8go+ $瑨h'#ԯ_x6,`qgۀ J'\)C}ZZa6-<ٷG҃?пU:J&?V{OLm:p~A~%JN= s=|2sX?` j`!ڋN!{S`hƔ}~,u9uU$ aL=8J⢬q̀zr4Gf\K+N--£t' 5>p|^5Cq)WVpHq`&FA+|ޓh)Ě^2lNhoy{R|2Z_!>6Ms*FU${Qj|sЊ+Sa׾ۇF 8H;iD߰mhxS 65 za nIHb[5#G,KM_ P'2)Tn4~˱kI4VX"Gy+ʧٶBW!+T]rfʷВ/V>IcyRZqqq,CxItdp ѪK O g v/0s~ྨ='؜0V mKgzBiE±m:%X]}wb(2țcۊuto0q'HQ??)/_n=Fe=}_O$( NuyuvQ,[S)jFm)v?”)=SBJ}(tKrf[,XqH嵆9Cz9tvk'^[h$Wd+݁a_ fֻ\u\J6WG5&s|-98zF@Z͓1<7r~m/;_d]nQ'3(Qȏ~8"uO$DmG+<<~6xbqG,YN[B6\=OPHS [q r/r91hf=,cz,cxR!}fG_B0Bmp:G#S%6b7op n|lSYRYo\?y)Ɋ1G;恛Pl6].oaCY yD#%r'PUqwo/}ضr{1OP j֙s`>}&Tvܲ'ќ[L_yS]} =^f>vXYb?ؘk~G:Vm%iF]@ A(Քw1]>e:D5}((G4^(@\ WC˔# }0}E{WN"A Ixv%N#H+sf w49fvƢ k[Bg_a9NC*NAЗvr'(A Y2ڙE``u2F6j #)s>NXTyBkˉm0Esk>&5?߈ۙX+ע_A'yD . L6{oyUU4Ԩ z9 k22?ՈǹtۜWR*ԇq%{+=6Jkm33+y 1*XVz/UUPo=o.34 \iaB2OW^=b՘n-ڔ#Gr=IJ9́K\K+HRDʜM+8N`_tp,|6|*^[q`3^P"( xS SS9O$ 'y5Az0V-'o~^ !H2>a#üw|Ջ~wkW֓zf-(sn.`M{uÑW \p>O%ʠ67Mӣv(Hl8X"':4Hj=#"pA(ybn{k>Q'cfS]Vh0@tݑI` '.doտ}2GBj3 W]3ĝW=~ٲy`gs _i*F*Emwqޠ!nD4ߑ{?~Y'ߟo4G6vVuE%F; Te(bt^}_bCxpx`ꗟBRExq`?ب{OVys&$( 1`%nnD5;[O;n)ejWNѮFT ?q d< ̬5'tC}Uu]jMF]E*pv "aPZVWxl@[(`Bv)k`>)߅Ё`Y@P='Fgh/_=PM!7e YjCi1/K&.URcC;s[|QMw5 Õ$$mu̿,VPXMHCgp+%fRI)O #x{-TÝFWt_?vԽI1VۦV{НG.LZ6̌9g W79{PN1}na /R'S!y.+z~>RW^bm /*3x' ^E{ Qn5ҋ8#9B5($݄D<V4../z6'~+O= &tώ9mЮ rK\0QC WN5kwEQQPS3'5k4܂l2(/RMD4`J9X'<δg$[ywJ~nU:(ܒ\ .Q5atHePּ }M &Cp9:wϚglNڗBNg}e2pq-wR|71w5W;f G'p;*9-6K!( QI 03.MX.DA%w3Ð.Ky)c#[ξbb@U$fA dD#q|:_v}m!PM \"QyA[gKn,(H EZŭB~m22oߺiԺD֖3lF2/=Rm2F.UJN ԙs߂KE[( %", Y|J-:ZZmkj`%"O=c 9\$ZsZ7ծ)2w(! "gIqj5 f-|;FCG,E5TؾU8Au< ""蘑܉Yp L 酏IxHp=SoMff"E$=,ּ⊋lϞ$jQ8[Zg>K5rnAoKLY8(5%?kRYmΆ8c8q7>YPb")5bKC O}JfeO[ Hw7/$UȴEO^TE.qG}YSU .\Gy.'/ԉh_gPXRpwB+E"F@{1JkBraTԸ2!GUz/HyͼAR*1-"ojiSdr 3WԌ*:- 6ё4ާ[K)85qk0n5f IF_GCH*b=x>ة ><]+Gie@Tvqcׇ~ 6u50s>%%M22_0:z6~Q)@aͼczt9F;^ˋ=`}W9[łIH=5#Pʬ҃CD!S .uc) j; DNi-Km ydC]_Xϣ-,DeG _b# [\ d.$hF" K6I;OUdSSOKKzDkISqD骵V,*ݕlt ̮tl @eX.ʕҩ NGxW3kȦ; {zCۤ} fK؎X_ Z-14v}ӭɱ닊`QP*6pU8P}|YN=Wy"r"0R$pedO`"zLO&iôF ތɓ'oԙѸ?L= D= mPyf^LōQHCk7vdޛ#gM3#u#r~kr-ަsFϝ\]+ cvhA͒\OSeݯFR3OCPQHI.~{clX{Ù>tZ |R3[1Lw}eGsȕ5L9fb3I7Z=Hns3eKKlWwD(VTW`u )BoX Og(7Q;OFyI/ĥw+ gi2CC5t{ŕ-1!ikiL*?Ҕ2OcrP(*|-,n.MRfa]ZPB *K7hǿ~z#,,"G)6dj%}Iq([+)u] ghbmdу,'EA3UCN JX>b K,Le89Bk ,Js8RZ6:zGr]:G/R^iuPJ8B8Qv'e'\7+gU$Aߟc+nS]}$]킘^MR}fqc3ԅK"L ZK}HP q.]-r(# pf7S SetE8k8[Q>ҹDKZԜ t׋IMs@\7lDqiEs#z[Y*h V>R#}${7izm:#w|& =|rtHInd2Rjۄ(ũcD#_YJq6y@DvO b+a;HlTI70W`Sq>Øʄuhr5̞A )Nwkre߬dF Y VQZ3I(O4_I@yI&qIо%4'Scɲ«3u$ 7v C=2 (w0] R_6L=8F I.D^NSL )(E/ovAz0yIXpSi?嫸{ҩMF"IET[KE]$M =QpcМ53 ysb{ b vXUhq j$e3&zjKzhh_+qF^q}ok`nNoDcӻV铩펽*Rr~+5vnw!q]J;d@?Ucepݞ;?1Aalڢyjb,qyb*A&QR~,LZZ5 86ww g,Wl: ;r-3i*/68;)KSI܎,{+;gU\@Rp)w})8rfdPT2:W+t d %..G50W4IkJW54= Tۑ~WM5޴+"<-("#v[j!وw%mD/m1g[lh9s잋Cg_rOh5x/މEYJ1[:3&#Q^n.Y, ˈ94$=-;mQ(b3ZxڧUAY wz~ա; xj~%_G2]Ac3pZ:̍jߐd~KbbI wga5n`#8m6:iHRf\<Pd1OOAQ3S یsAشy;Mr<,-{J"(ybzw*;"Q4~!qnPC4ASVS Oԥ 5%Qr(bdu˩ɾ*%G~4T@L9R0}x,b^)NqE;Z,ѭ; 8.HxRKwU]M4sWa5t,lƠQM⬠]keqMˆH QtJnM\~ N>_L3AY Į6)F.ks(/'칐OLŬVY/U8@T.w~5z$b q*U{:\ gWcqoD{$_ׯ/jNhF?"~ ߫DcGwi@gx-ޮ2"֤Ծ@ΧWZg'WT=-' v宁ϛ ;B<JTKtPGjģ`foy\i=AM d~WNwV`CO}݄Yg#/ . SΣSq/3aM>@\ 5Iq R/6a6X6'˜| 3얭tI3ĕQ󡕠u {y{Bmq!?(|w%ז[b24~afc {xH`"g-9gЃUG@`0@)*-P v%a<#]V^.Qp?>C޴ŽDyΥz 0$Yl @klrEuȮ񪒚X9C.PFːs@ݝ~:, 4Cp"Y]OdZìLcF"ǘC\?.I>hrVEV$،IF>{8{+oܔ;yR"^!yt'諾xJ i_XE8wMv$IU0ê~heN1~,>[2y}Q!;Yn&iX7%A~ޙeo02@&e#s sY 4=XDb\`R/EG[5vyWG%L}0DDE]CAW,Wus?8N"nCj'#JvAd^0bFoxESFe ?D*^Ӎe)O-IL}Kiz]ņNI)/}m26T]rBGu#lj?_dpWhMIhܕ1CfV:17iM8qe^!].$!w]6} rWF{y?qb0߷ (jkg0ŋ .`6 u{c6y8ppGΜa0F4if2qڋ0 .-vr6jC$ ;QF~cut{J5ͱLLhB<[O /#^Iκ9$5 =Lu$.)Y>W\ Z#XIήT%d p{}Z!RbaBb߸h4js݌!g&a} c 0LphkKS29o#ڄ2S^`|ZZnC^7$ յ¥Dže&j?6:gM"$R}l@c>3 ӋZ{yL2Is^4Kᙢ^W}jypX@)zU7a3[,X= R!>kxϾM53f#L}[y$*hө<6~qHVyzRq$H<֭ [VCTd@ p%R:a} !ٹQv!: 1G y}(:B#R]VA(Gl1䡗&:j"s 8ޏԨPuFWϑZ\ugh^a3/Q;RqqaWS{mrbݛ.-L!iշ b?) g 1[IR\; /̮-/@éL>d־r'ڒI+#[8/FygPv1iK>k%wNSNEKZV 77?][IaGW W,ݜfu,(-[o7в(fwj:)8 Eo}8F% );x"NYKggRzWEAOT>l/kXm>bzCeW%f 's>i'9XO)i(zO<u/`b,\WQn\RSgJ$/P!4 IGu A]6d84@R]V\]i1g굞g! xX 1DmN>FM| vj_Bݢ50sp$'x7^DT>?81U7ʊ=)p8*:Sڴ;PBQ:@vC[C>ZIm#PzzU}(y&?u\i$o`5N^e ˭ &H:zWXZ"r/?Dp1G? SZe+h6@Y?%%Ye*CI6FIьΟWni VKGm8BaIQgEbde;p 8\Mϗ*U< :p|KW.σt*-l !85vBܨ.%dpY1s~:JC$ dIΆ\ q]6^%+#Bc \/pe˕}hXv}~ɏ -?^!kµE|ٌ*\nՐiy,1bx1x0ֶcv63Z,W}4lO`  =, EKwhj:y4sG"o6&W@:QOF0D!Q!zcˤim c >,v9=MҪG$tiLAȗ@ϕ„:6OZSx@36W_l j5Z(Ƨ= (Aw !U@b=L>8р0{5hu "?a4$ NY)|*hJGLA@cƁGAfX1#/gz'v* vpk5 "\볜qgo {ŕ:{W^8zmy:a[{s xiG>vEKEv8DS6wl]0t@fkRK7^nMQYDGwOhʋp\~+ U{yJDbtB/i"y ٟD!YC3%G 2=k0#/$x5 CÂu$xpZǣhLy uU FLjLRb:8:b`y1ϴ)QG'\V=8?L-ji&R-us xv#XULw yѕlm',Yh6.`hS~lwm8GXWXȐIǞ1b)pSMT3ɅsfJY;$U]YA#ykNc#S{yP@#R)e̿Z,)IN$EC [gq1lW56H>R 3g\R2sG"(9R>?G3uiEr.~f$Лw֋ +CY=[ YA%'J΁)nXW~7a%fm9B,(B[ 3l7Mrm5Sҁ(#$م(`=Lo\+hl',mlGOc@F/Pdm̌.V(铦aeb~k=Ndq)BA8(cjYKj[:ooc˼h29w*^6J űO _A'TOW%m 'H(Hyl<у8~z8v6hָA(J9u]cEOm*;},Q~cqdd' "o‚>VC|M +6nAYf [eEF[ ZDQ3,+-aB*z+q!|l NdqG<}Bw_Ɏss<M;z3ב{Nl jmILI>>N,3vBd;RZp%T8Z*R65)ė%EmsQ.M{ 9¢R/;'fkL':_7'Bˋ+OA9Jpډ*x7aDi&׾LP+XBrhj¸FѓJ]=t*Uj٭rdO EGLo`21Hqɨ~t*8CĜ.Fs86E(w@~tMrsPG"-`-~tY7l:vkcUCN{1ձxI 4fM‡xoRGZc0YLCA*'d`'1!;Jo bzvK+5CN&V3#$ 媨 LkyO=C=5_v|G;.L{Bo*5ah"#V&SpDrrcK6K>̈́=BbR`,Ⱦ9z^Gttz)C<۫LݵO\@ǵ׫1^HNsīSu%{KaTJ]ƵSut4>5i,g_WR"U*FUl&7E.)ڤuśY"`:0w FOWh`f(-xx>=qKiwޝ"%8!'j?#ƺ:Dz]r7f3M֠0zHRUBۇM4 Y,&.pf=-v>?]|DWf%[/;ړ0ٟpZٳL(&B= xA%8ua ]6e>b/mu&r<,#7c^X09~SBwAjM醨-Fޓݒ ڦF'yAO{6#Wl~+XYdUF!/րN٫I+x#C`f|\[=l 3uPs@JNC oDY<i 7%ZgCt/î`hsȉJ~a r{ ֭<=i6%J$6k/#% Aެa=<;R}D [c0H; wSpS[ji'?@;hGh]yr=}BoUE׍EF:.]%#fq,*+f8P_ɏ]W ^>H r=H0+⶞s8\49@j` vxCo!Hj =22.2dWPиPAF!:-vN~$5)4j$-w?C&Q< =)rm< b F 5p)wAW`?F cT3'Jͧ]ٍpJEtaf_=K/ c&7YdrëNbaXshd\Ru`ľ>~/76$ŤԨjk\Y>H8& &I_u;iS}Xm]ޛm59P)g_,ўHD17n9Z"R+7 Ҟ<8х{Wh|]bL g)z|k' L'Ȋ(ilX>D AtR9@c^Fs2zagL6^c}K&{%R7-d|v]K%)Olf9%ZۗÖv%UOZ]:9cr^ u23T,x{XMG+Ew(VS>6O,$7l̾$]/d;贒\-agߏU$'YEzZmxOvfMf/PMJx菈fV;xx&F ,2.jhn Uq;oI>/PYO{^DFQ͈Qϲؙd(iPk F*4u0w[yV53f‹$>M7[nq8w-L܈ц( Pik]01eO$S@|ߑh1N,mSjSy\f~̇%d),p;`Gdz@D,pKBID!9`f U-UE6_ %H }ݶx7cv g/2w*^T7ց#%>$/bxw0UOpsabhdLTS0[j?fP6eIQ.^'!zkl8Q0͋qP{ɋ=þnVtHo{qJ[s; œ#1g~h˶vR? Su7u5yrme UL/d ׀%/}=PڋpG bi{ O*Y/\b ܧpXQ8-@'Z]s+]lD4)OV=}W-&8Q}sWK 7b=oNzt ؁֏ ̍P[[زRC_dM iT{<4E6LϾn&Fs y2SИ"Zam*[m/ArKdofu:Blfs$i}=.;c o:[BAg֝PbVaƛeb=\Dzw ʝRmIJJV[H%Ivpޗ3l%eZfզ.f9=s@!SC,鞇̈́ R-9fσk@»ٻ  Jf`o8@a&N`iy:`FFa}^"ZkMu gگ|Iݖ1?$wIM`{He3ֵ*_ג$s&:SujAa9zl+HFNCF#ӎAT;j5}SM@`,E7hZUK\a]5(ܙُXţ/;ĺ4Aڶ}㻺d >)jN:X=Pн*{F;5GFnjMAAFq:X.JASgSx'u+D)$#:`me&#HDQ"V;(~Jm$HߠK]\(9rMp5nX1UBq[{h.burjύV F*;j']JvcԱnJK^z ˥*M s&{M|xrX7úG? p?.a%x1M* }{L(⢑,xRV\Ge2ZgcR\IA/Lʸގ @>2ѐVU,Ro3(Hzwj Uyf?0AH߀ ֭goK2 r]D{mGQʩqQ lIbڰ)zJe$[ƗHTqn{qƊ xym7a H-PSSj:JnI q曡^UgohCN p\:Pۛ1Ȱ7oJtۙ_+Y|g҃ $S Z5qTLiG(h,bsÈ ۉHE#Cp@DW> 8_?,vBɼ sO9 `sWӉXZ>-[Iw]{;d6n5 N?=p`fB0̻cπIegaDpzGp aŎaRmB SI*yc{ys׋D)P)FwZ7^*s>S?fՐj9b1))Xnؚa,E􈈴YNDq\S[CQ~]{=_/AGR M넣fU+J-[TJ!)fP̜2,HuM3^_}]wrR4Rac­9Պh?E}#SD7 #'{'bjQT^( };.EƞOP,fl՗?mSc|HqĩП&a4rтfߏ{OɊ),m-$wC[Z3Y 0 "\F׍&s9pQwu 04:VK2T+8# LQעs\B< \sӳ/()X|c9y=SJѱCwu69#g߅E2%At4?ռm6ZN&ducDlm;0lGK MsxY݋%56*o^}K 1 Q"*lvpŬxh{V!Jٛ ЏoR|ź%?+MEr<BGY\_A ;9 3Y| "b-`pHmiwf|,G`&<*rE-* B|Lh@ob_θU`WWqEUh[= ,;b=♩qͼ\lw:I3;CL#_RVѭ}#I:bċ!.Fl!"J&fn.4O*eg9휶'an |ezA"2*0ݎ|c ,n9l*g?'S'%LOcA2y:@|3CV f_87X@œmoqojVC)2 e i524/ZQX F@>pG 0 "ŖE۝ j"Uc&+0ƒ0)M#z P"0>}5>%CШ5\ 524btyw iW-zE]4J,0/N(ykqn jFF5G2IEr. 0!qxp4@vGhm+Pihŕ_+|+\\Tٳ6^D3DvɆTF!fl!Ѿpl;odݏ7`~hmU,9* +]Yގ(U\><=RtXU9zuV[^ͣb~3Hػ('դr`?kOANji$5ajWƮ}D3 aa8ʰTIX# k(K"8OߪaS#!xZl:|F OSzƃDB)E?">z Ŭ|Wy=8W?9pw>8Y*#fPVP&лp2h :oSxY{ f'OVDyx0.ଢM+V%'~1i; DEXZiVN rǞ$\")([(yME[2C(튉>@,0':gDK[¨0{d]x=9h7 eU2bsO¸(-n.nXe<6q޻nJTQ9=KT(v䏎Ea :3"Uo"l(c-c/,gSQ(ZadW$gDYbtsU#ll RUɝޫ6cy7,[vyN< m>9qvRKf_E @l}ARY >EW-p?:[mȑX> aajU80ꎳo*qh'14%ȠVس"L~9Rvx[GdHDݻddk2Hش㮋PVf_e3ծ0ۀ'pZ 0g2?/tC2MK; B" FX7n5T&D ܨj0:gl{iWTؼpyZZv fJ"_:}$0X;hV2JP.rzP`JIJ {`ƙTͮP~FJV|e|ݻFKy@ }#>CsF0 ^Ցky*&?۬XgmeaG lN⛼1٬O]Z#VļO}{c!J:,.8^:Rb̽yZТ `ڌFwݼEm"cEdϸ+N2?W6`*?렮05ȹzKosݺukkO{摴B]Aa27D[1$cNҲmғ..C9˩5<{6$Jr6Ϻ3ۗƒa{vv8m٦n5=,E#ֱד2g@g][[i&HKA=iya7&:hnVy4 ]0bkEOxCMƪrS?pgX7"$+S ְ\V@xG)$ҪU 4>@ @zSƹy4)QX`F.ky蚅 rXmOax?zY"/{L;~JSCٟI)3ڂv//*Ebó,,0FP% ŋS\miFIx?7?9[e=I`c. ["L`dSBɓ09GEo?z;dZ wEGn3 1&ʘS)^y:dg=>и+3r3%QƧTɟl{L2ʴ6œTFIar/ʨWxe'GkIfVzGnq}SZ⃪d,t(^5L۟]K]POU&x Mw%A8YD2djܰzyޏvwT?M]BC&Iw%%-VJ@%ܿŦp!xʏZ Ӟ䃽u6Vf%VDQ!A ‚Uw<.͎C i#J(Jy8)} C9TXep+{0[J "Zqi`q! PPD"92]ƤOE*9nۊ֢qIwW~ʩfĒ`_TK}9 ?48;u'N8œd\nv4H ^8](X'INwφ]-Mf o.;{`pӬ屹Я7k4;ut?6l?S.#}tHmQlV!Dt!^.ͥ̉ەay)C%"@d螔uD , #r>-t;B<!h.kH QDzX3{D^R}:->o,s 'm,JݎSك֢fH] BCSQh^:t1gx`!GYO^Qͱn;ц,#okYmU̙HdB"ddZ?ZD}ws)(8&[{i\HʇSlm-ӸdM_70WK/j6tacYJqe&Xf/1>Ή~E0d(ʇlϾ=E[X"78ۼ,qa_T~^͡"`IcҸD+Q`״iUH»f4F`!Euݿ7nϹOey֠4Kz2h(C¢M^;c~sn:Iy?]a-.F(rL_|!Y U|G~ ͳ`'Clgc~<h>~b{oE-,ɟP+=Boc~";oWL}'aEь"l+9E^Ix7=FN$Ŀq6py+vCF{0nepzE)YY @JFZ+1WFBNkj/{PR$hV~!Zh'C*0Y ɨn3odcIo؄t"k͚3~fZ.=DEA(P@7M=8 EuLb/qdFmR-Ԝ:k/;1gzGE[3h5Gd{Xm::Fx"?E"왘h܃ h`Hm4khj i c#R-ЯIQwO;@*uLfuޅɺ8 #6q+#Ĩmu6%FD|+MPwqTc\Z&v.>}]st0H*^ `+ezV+bUD>ʇ :?rV=1ehĮB2s`/lgJknEq]GBF@ڤF q3c^`CR)3ţL‹JJH2@'ogS"F,'tP|du^>x[iR`ZUЙ3(2<+*apzD.ņ I8㬎짽F<$ F8;Ҝf́ȶmVFܷTHg'pr%#l0XP\"M73s(v+]2[$ Z#*[=M I3Q$.j%X\O, iFqhg{lАz"RZ Y\^tу<ד[5  {)r{qN: 1u̘il0-- 3ܐTy'n¥h%V옯"m:Y $7,$&DI\U,iR1.y򫱷 [__pJ >Op]G9@T@6-x1^bĠl 9f rRŴ> YMʮ?zY._ĮFLUdک@gq 0'WΈEդp$*brc(lZXJko#$,=94d@+sXJ]A(*Mh$2bՓ;z-qz/g-<9KG9q>ac/'|t뎇JC jVM?!]_)*+5D/ <{B@Adl nZg2G_C[ X!w Baz#QMݤrV5+Ȳ=Sy!թ Lr^sк<5%KH{g,"45}5ֺMH ==KJ&9_\Z#< UIbpw8]0+䈮_'_'HLd2G%S( DY7-JH+s9'EKΩ-jѼ;OeY,+~PpFDM,Ej8ݺ"T+}A#kLs^-R+"W+kڃA$P2SbZσXQVS^pdE*mWP_Q}ZԺut2h;:אm/'ߒ, vy[mz5 gMu( WĥCS@=dL8h! 4oW&f%Z[ǍlbW,1T< \YP19Z%0]wiO”/IoC} ggMdn=oAwY#M`=YbziTijLTm% l1ov /evN`˵1>]4vRĂ gOazݎZ yriy¦5܋y3/`kHژNtX}>Hu"8sN,gđC"KRE>`v5\߲-MMLŮWB &2&g=Y]ttW[D8_9 dQC)yR-HθÁHeU+] m@,_˯bC w|j 樴++OZ)pK\hŸJ)g4r*t5򨯅FkVLON<>^h[5TxHN\: Hy1{ԬtuPx)1p#|Y#lpr`]IHB H'4U JUwBm[W"[Qd4/]iBy0~*斍:ʚP Q\+d>-N!̖KtLUa4Jm'-_E(v7>z ypGa2ڑ|sgƒ)&lP'!65*-0oq.)@NKDEldhTC1Q eIL 4j EnT.㔉 "X5߱`Y, }:w0+Bna/mk> d̺9YpOEc6{\ۨM&֑E{3AVluiJ91n/n;1LLNzz߸$xUMEkmy#]J$C&_oAtZ  's]cP@ =}QC*Md"@JҸ Q̏egϤr' qxm Zə+ CG{mYαJ ˪߸\7ށۮ`#5=μ!grz N @"/2ur˞=W _;{O W B3EWCuZ_IƪZ$h0iUX]-˱NR :0<3:$? 2yR#c$ON]SuXe\#u#KɔR8xGsDZ$G}~>\tFM&pmN TT|~ wB&Qd 60eo.Å|Y_F L b@ 8Z\x}(:JNVzl gPn- hv҅!{oDwOj֣ǟ(#JCJ`"7ְU!޳kbDRsY]ɮ%pz6e%`uZ,#`L5ϩwѶ3TX1 k1ӧW&HY^A'|Iϖ Vl}-9Pʐ=>;bc<0:KAQ7-t~EJ7„!BK5SϱdS|7׆`bᯈNj%U ^{ ^BEZńGݳky]|idYR覞輾TG"OTwA[U9X@C{Qƌ2B+ϰk:ez*r<$2qFgitCR(sG\J2|ReD_ӫpw({8|ۧcN< SэJKC(1%L#ł0U2aʾb@Ɛ0UqhM CkQ3_ЮT1;W[L\"/`DQӅ=[#ؙYP1h}eNWQeTf)@cqJ< {Yj˨*_!Ch+k^/gz x^xW͌~Ôm=AϮuzCG&}E-a-Q&f6QIyF$JTߠQ_`cR0Wf0B#] 7SdRRQPHξFhOp%:WIJG[CSծzl'Ok>֓L8 E N1J$iu0?79?8YCłf-~K:횁Bf3E7Q| ez #%[ LAr3* ?vCMǓ7tL EYEI&nc. Lmr9F0vXP5ftA~F= E;l= 2 B"KXC= Keٕ"1fN G3* |tyEU򌕻?酥i!0i=e~C67K%V [׽&À4ӊP&nR`z~`JψU+c$#j>m|sqrXL9IV+@ bK{⯃nyӁ6\]T}-tKR$\ <6`J;^FIJR?"O|1fgvN.Ggʪa{y䃈Tْaf/nãcK1tѦx <Tv 1/m9GvA0$hd·I4⧤m`X@jٓR:A#LbeY\$ ' @['-5SlŧO6$O%˝IlZݍ,E9qCр~M~g } <=+,4/v%wOZ8Ly sW7/wvҒ3ky'Duffoql֎Tpa~7+XQ&ᱺ']~54pO i=4kbǵa4ކ/=4 'N PJ>TG*Foؿ9'\THA%xJ@SiڋH{ ImQ痽K9`x N\Ak:705=_kAw D|sS{{ ?5E?K{8!V׊!C2RYj n_7;{[̎Qh.&p7cakvg\X)=^Q+}J6` Nqh]gE=lq~_mzf^z=-eߩӠi͌aK;E֗_O>@F`懋/IFRp2wV^3j5"inE )E( /"㈌0z2W:pt:.t ?c+dž9];NM=^ڐP4Zg Ȯڨ=&AJ-@CۭZU%X}bd{c6OsWɂ]=Bzח ?넴'%mWmL >}.W^nT'[ʝnIxIK4,߃? L9,A?c{ GFLA:at@5YyuhﱛJ;e8lxTBֈK32sŠ'~ RV  pJ2T-Qc=99O_Vr(6mG/kq->!;уN F\h6Sۦ,Nl@v_(zDēMBd )v|< Sc6vdBp>5AC 'ch#sY%]iЮDD)2N+L4C ~ bkW oQi b:]> ׈"ݲ2xbu`ЏJ8d@n1Y*wd5d?HAȕ*dȡ݌8पkd< ||QCrdr}O[QdmMZxc0J4Intt ItKQ nb `2"rH8oҹ^dpah؜2wAƻ_$YȲFd]GŁ})Fu|Nx(/{$>"v-4/}%'=U5槭VmA̰K$W ‹;FY[q8;Jg{ȶyC[N`VmYnUo~An9¼//Iџy)1 !QŇĩlH=8y+(c\IL.{1ʚS 1LSx۫ɱ'^o|D>skIsdz#,?! EeƳJ 3MmU|wWn%#[7le9nrDٔcר,gЧT {~$~H} Jȷs RV213k|qnq];-_$z,g?= AK꾌]`p4`tL 0,#0'$=F"A"O/t m **)gl#Qn bW iRx0/+=c$kNcUOIY[B^Х1fk*.,E"^cZ;:+X JײV1lБk'U"G3D0#q A`r Z鹋L8I[ "^;AV̘<4*- AC&Zraql32nxR--zHUZ9{li2tZnuo{|H-찔PptBa믧;=[cu'zS4-*_h?")qߔ@c&G'HsM-,2I<~Icrm!KMt kבbY4v,}Z=jxHepT}2Wi9~$flG` ×*=ni(]Kr͊|/ٱ^TUX8!wzaY|}Xm3g}R(zNZT}T[],aϙЇ3VC"\L2r"C*›i.D}Z"1N LG\Unro88lhi*Ͱ'A[W>^'$J9Ed\*)'`UӒuR;lENyʛzK%X\ݰqm(J@>@L.Fg> 9MfVi]6 . QInE8Jۄ'P[jo٪WmYC>I~©Si(j7nJn͉gʊ/BeEhSHr s J JOP/*moO* ?Wags ; nHn@(k( ,ʲI&]R#a1Cf=0^&6  4D/u);t|lBl*F1d "TK]@HKl篞I`S+r"tF64?}cdgj8Qр *yXf;lOXCxsF=t(+tj8&8CX\+}Ijds}v?Mg* KE7k~! mTSx'V;\rPOitNt{w!vuq"m~he=xnwj$yDA[G}Ƹ\gKNY&9l+[J.̑,sf S ZrcŁ+tUlj Xaڥ. y%HzIKrsy{1|9y9߂~kn7A(4DVv!1BTѪU;IZٶ35W@=AS'V7GW/Cz؄HqLj(󫟢VTiܯqAdWV\IF{>#?OiBbp {´3 npO:S,ldd~T"`%m>])t"amGN@PLڢCk4ŝ|ؕ˷ڱ\%YQk*!vu^4uģS6˝i)枝_gd{IRgxSZ i)^iFxT>j)GJyq >Q"B"X bg@i5} g ]Q[B*!{<  \UgA*u셥;R $<_ŏ)>ȬYQvoQyM#jKF+^ɯ@O(We[ C[FHȸ+Cw ,&CTڟaP{"f]m{o'򻭊@,ٲ&ZA7E .n6[@qYzZPy, ?AVt=L,(H.uE܋-ٻqJZU*y39c}0}㧭tְmg܈+U8aq(s࠘QJ خQ 9Y@r$Qη<"6cR7*}>'Cm3"bmXu\f麯BlbQtLu[0> vI:*w3R}&STIP28Oinh{e|\a xn@/b0sZCw9"l":p0`;1 1lNN„@ގgfN7['0Rg1aۿUeOar lӨ~7Ie:ݫ07+ ܘzo*<s~}@D=$Uq Y_?cN?(}֤xc:%>f*Ä}{y_^nkyԴ4T%DϿH.]LxyW]تˋ(cɛCY+t8ֿ4(a,`n NBzui%ٞa2ȺK0i^x%\["$.Ln@$tHod]_hDhM 6|P+MjD~NLzsA8ٚ^_Sp7eP,1;U 5\jGcA:Z"|) ڤ2X +:\P) s1,2p3 ZY{ɗ!22GgZ UX(k#j@jx8->rr_Xȵ*ޘgz%D$m1&K}0[lu^SJu,#G1ɈȁyZa)&2p'n'JBMvb f$c&LEIriA璐 ~]d͢hwb.>WNI54\'=ѓ ʭP󝄃ND#*AX\EQ-P~ dp/&KN)λ[8̮D6߾O>~[i D);ۮz2dQvۿD' %WM -{8zAgy=5!)(+=lߒ[fxV9 ^'!2a?2Kʗ OʅB{=4Pph 5tKfF[)Su]ҍlb䥑٥l~ d?scrc}0L?r(#x!`3A Q_&u kCI2[;̏ s-pwZ#)h" ^_~y\@k`.WEKf&: xDG P@ MHo2<@➷{&hXLx<\C{Vvo>q1|r}aE?? d񩗫ssZȍ$8RU#LET13q10? 'Y<[]\zr1G1.ksɕ)ncXR=g/OQlS6Oqy$>OKN6+kq<$3 f٢A y|F^6->(dX6[Wej u>6hܳygH- Z@̜²@pc}c4sB]> 45÷^Vny @ ߡ% ma,5^5%S ׳K /տDbޓ3&@ٌO8bj.!͔l70Q÷'2%7s=7h@ yd4 ۡx/R~8FI%!q"q'a<%ЫM0mҖ.xD i~ƥ"rݦ#ʄ<1qLmbV9tK[*@!M3#*ik(=e{flu eiSڠID0- j@7/ ;_,\2I-ݫZJƋpZW&Z9FmZ3M*ϴqڙ7:ӑT:'G4=~-WG;KT 3#$0t:=qr(N#&*lr}}_bHcqDθKgG/J؀+㝪/}o.CؐbUOto DAߤ8ksUȣ?5͵hla*; wS,n* !@;(f$Xu}ƖmGbޱA7X "6ƋИYdyN)x٢ ygKk䨼5_JbTy6W~`E3uFIWnIA-N/ j9Q^njr=Kp%j(sgU}/?a2"n U'Z #9lK $BR$[ɫHGq֌zDқ?DVw4s'k1VG 'Pn蛼ͷ Ul͖ѣ4t{OUª) *; rlH=z;1u_lMF`uE=";]74i)#?pA\&Tw1oPᣏMy ;,u (h a4c>0Ĝ{y;Z|1 h ̀r9a{-f[Zh %X hGl050 i< MPqTE$ ArS&nkqƨeA^0yTj:t&5jD(Vk`-:B1ZQ ªD?i lƹ*̒W,UG ku^=3eVu* Ldouc=;#-O~ ʠ8rHgZzbw!˃U<șP/.vh.H. i ~j'\w}%;@ϖoJTX`dOq:wJmD70>c5RdSRM19K\&n, :M#;K!N ׹]R qE7N0IN]QեlF^_ߘgCCDIA%#x xVA־{>3qBF4) 5IC\ȥt 1$;)xE3S#("^Et&€Zl Ġj%[zۀCUsSKHK:y@./M њ^ηNkeEm[u#5d,+Ӗrr;/L6@&l)4]>dqvלZ."w \L89~ZQ.^4x}ҩnR]o`K[V-_j1)eTp^jC)*\_*{~`Zbr - 1jX^[z6 'f`#=#5]nm2l2 @O^'V󊀇@/L[ qAuU)^Mx~@C5[vޘEBBw?ID/D9>+K ݋M>$6rvR>w%7鈊'̨N, QES? <"lH52\i)(d@W]݂҄Ŷ'?b%b _ka;=@jvّԦ 2X"/MUP[|?)|ƹA~25X<&R׬l!_}cyow6!?7};HD@RDF(ӧfJ€lb(xL ֢QfUb0׊՗qնu_F&7D"A8'nq96'bNM ' ?^eA!а5jG$/7y(P 7Fے$xhC? r:znR[MT*'I>gWiv+Rp&hPky붘RTNBWOBE Kw{mqtSfrxmxt^%h|diCYgHCMqAwlp~0~w ~ 0AP|v*Pk+H}|ZYhf<嬨W$L3dB>);]Q2 R%RG(2 &[_(cq8^ cPŹ^7vm TY_;ڑdjINΌWLfyp@2NgTs>CT)?gh펣2ȁb$-KrA}UΤ5u-=HX>種LjuBwoMv='3Q8W9ߌc#M$/?d.M򣝴ySl&p8_+JlyPđDĵ#pt+v(ݶ0~\pS®O͂"AfOB(}:$_;5I͹rP +ei1<?'@OR*%C%$LolWt|MHUu\+@JDC{HYzîӫ 1Dz*wƭ,,0"rGӡQ]a0ڶt04ZKG&׊wӫcĮ/Э"wC.j&1=]Wt@#tVIEЫ04wum.Qޅ 3űy;&&X@2綤3;>.)#$Rsol 皲W_ڬ+#"aXW,qu` :lhRiD ,enll>D0XV[< Qډ.G&0 rcvc՜a&h<5f+C[|]nT|q-ۦh$5F48Dch0/C-qۏI8vXBv 0d)_XrQ1ppKo~ 7p<dZ@0El3f[ rbVJUCU\x^] 7~ԗϮ 9[.Ws[ڔvhh54TgJNn`4PIbu:YE0w#+!v~J.TM-lp+gc#" %~?÷8ɔԮxsv݉o?$A䴄w/\Z|tWo`5 G}vrnZ>, {[2"|C1 + I)8>+CM"B^첩V-fgfu#{yQ/ݰH3]'au}/'Uv/}vw _f8\=S>pZ϶mAőxE"3EAFqVp%K%Ѐ *T3VBaEaNl÷ g.L2»d/rFÜox6ir:1-|GpwO?ıԇ3 ]DO IN@yB 7:@hfQ( }q&Ky,~D8#=d}s/ӂrsɥUҩ.bDF 36͍$q)D '/"lCc]`1*,{.Pp" iVohVÚ$]-~bܶۄTd e "AQ56 cϝ@ŝgv/iimV%ɃO:O0*[C^QA5&ښ& JAnd!8D%vvm9_Vr3lY4,?|BXt$X*s% 8FLdZlI7i>G385rt3C ]'tO\',*o70_1ei$߀tQzL$U9"-7;N ;;K̅L+Y^UQZԉ6.#Lrs vJfB$Aױt!S>TOmIgoxg|kZ3dnV}AS=Mu"^侘'^0?TkF<]2!cd0Fa(]UKđoUPʚ+26 ƭ4ˣtb__KJIgؠ d+ Q(YOR5?L:Ʉ\m_˹#YBGb1"zZb<$5ӛM1Y'VC_ [MAa(Ÿ3\!ڻ&O%iV NۙuoT=n M߇>Mjs+X>IIҪڷl`>tK4bƷ/^Qt/dz EyZw{Azz,0Eg~JS`Ot}",eHPqhuПe1fO=Tk}2_Ӹ^TE]G4"Wend ޳&bzh&Ԡ+qGE*ڕ[9a[s;qSj /]9ZCtZ#ZELȾXEq=˱]'qN3ߪTߴ%`!}@&h@ߛpӅk)`f1 &I;dnY;T잁:Ո3[D;7kaʝ( CT{lϑˆX2Eobxfw3hڵD ap~+onU,f6ʢA7UaD, mږ/o ":R2wt3|ĹR;d'GAI}a/}4T3N&f N3=5c'7kr(gSvTֆ]]az)biH8Wa129W,I8GluQZ/n~mC ,)̘KkcfY_rm,sIh? -X_=5tcR\/ J"a1S/[IL_, 0( YZ