sssd-ipa-1.16.5-10.el7_9.16>  HLk|eN $ƨRU8RԏhJՊbGhSܝLc<*bK+a =`%: +rj$j?w;qE2Ў}}c݆"H# ۩S+ź.[B<w>—/\}Fz^x8v&_@[~F#Ծ"$yI61qنrfvS f5_ nfJK"aa&?Gkqmϩ[mhw,ǰ(Y(EBL]cʖaEC#_hV`↸iz `{05*)s69!V= },ӏ61c9e8b6e7726b16820aee25d349c3a9997d03e1eM $ƨ0*ohYD x{Zq>4 ծ$> npgk2X`Hp_4ΪVUG`SDZ)?i= w{@gd&:;0/  =!}vN9RA|Q"TwfSkrqmxc  :m=B'qln@.^ݖ'9z9 _Z]CjeE=/ph$p(s:*(y#Q, 1^Ky T8SOr*RLnHngտ6E_a#68rnl!&/eMԫ=3x?l<~$pxxq_/HmSnE xz@p57Wz|o̟/=1+P1ʮń-$Pgڙ1ݪ0AYsg8VbՑ^Ӓ 鍟FFѾ3 :&4{fjkd+, '-wv x>=1?1d   ; "?EL    @  @`TTuTLPU(d8lJ9J:_J=*G*H*I+X+Y+\+D]+d^+b,{d-@e-Ef-Hl-Jt-du-v-w/x0y0(Y1Csssd-ipa1.16.510.el7_9.16The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.ex86-02.bsys.centos.org fCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKs&/A큤Aeee^p0eeeec40f4e0bff454b8d2f26cfe8e291a1d9259405b30b64b9c12075274fe966f9e13cb3060c6f43b63bb686fc3615db32e5d0a5d9363978f54c5c93a617043cfefa8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ede600722d56c382c7820b67236ac20c76822a1c6c77ddfc0e888655823ed13388bc569b320e11d9f2dad64b32f79a0aa5a6975f42418bccf874aec86d2fe93875523f0234424fce5f6a6c95013703ab1772246e9a5191648f7e4c6c31aeeba7rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.16.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.161.16.5-10.el7_9.163.0.4-14.6.0-14.0-14.10.16-25.el7_91.16.5-10.el7_9.161.16.5-10.el7_9.161.16.5-10.el7_9.165.2-1sssd1.10.0-8.beta24.11.3eV@c @cs@b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.16Alexey Tikhonov 1.16.5-10.15Alexey Tikhonov 1.16.5-10.14Alexey Tikhonov 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-16003 - sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy [rhel-7.9.z]- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z] - Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z] - Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z] - Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.161.16.5-10.el7_9.16libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=881fe0e107a00858131322f99256b4a364d3bb88, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=cb6b90cc96d70f73111769bb57355f66f6383d13, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER2MN5ǂdhoqEOm] anPnw-qAI.:Lzx8e[ƗfϿd'b/w\X6s="J}es+vd!XEWޱ71pxư:;o7(9_Svݘk!'WU9{ME/9Dn͖CqNGۿ/j\չCJ҉LH0x hk%[Ko]a,_ٞF?!Ulmg *N{iV!8 xa^qy-\vĐ*)׫C"=ij]:5FvٴPÖг㗺noMNv8>X ف#( |~_<:Q H0~'Y|FLa]oq9Ӹ&o+eGڡ&vߋS}@6"6k-%YznfIhabWk8LL430-?V|M,LC ;Q. /-y{̩5?0MN8 ws[D6 B^1\0pT&צHZAk:)GHb5:bz|m*ݸ(n4:(q(l0vpd*TsЉ<~CY-Ŧd5<Yw C(qD+=ږt"{T05:5}>ڇzQ|>v8}7WǡWN&ٕ 6Zk5ʋYS+ta_ݤaSC'VzyFx,)5*yc4%7U>tFXu{8#G؝!8E (s.g8bZ9m6"ɓ6ה撯֛;a[ݧ¦>?px(ږ_[ˀٵ\v%#tuzW]5@]j")^N-j@V;㪐҆'zkK=zhd07UymPS(/n LY"@^-NMbK|Q 5 g,Wy~{4!'ޏv+ s*ȨŮ@|}}iZ9qRr?F UVAv!F#.쥄c 륂׏/ 'c38O 8Fb{+tI yV9/HE]`ڌLpCJs_K̦a E ;9ͳ7Mh`̮IԎA1N˅+~K֊%t 'wʩy|R8a&m܀4vf1wMw]@1?!*ĭ*.ʊ :{F&7B8ouk'٥vB偸;GbʀNW8tIK$PCjkx0ԓ+s"e㧮^U֤?Pw%̉BX~@d!i*+NU W(ja j$p;+<5`u-FjM#~ǝ;ozӴn7\\cCuCzuc0־}C >U~K LNۛe`uJ]ifȏD&_Xu^tt1/tNA"UiWwG S{T" CiUU+xd6$[}j/_,xAs T_rN06*`0Dޤ)=Hང]т8S( E<ݘ*"aeI @R*5`هDv` M];3Ցwf\_\$xSaP:$+" {e W2pC{|+r^{1ݠeA՛aģ#ňW2U\o"Bmu}x8$I\$4>=.RgES_dܜĸ_+jeh YtC ]??%< xfك`i$pv4Jgš(z+ͦYV`O%W dzn0:+!O.BLc5`^#a8rszk`Y,}m[ʺj&cZbU"xu::{^wzkl-pfzo6#X!u;L|e5m=}'r=ߎw1 Z["=ma=st^wC-84)vo 1\Jz֡J|.脌 Q0p[a..)r"S8E~~'á猆9섶EKp{t3  TW1)cC9zip%Zެ!Fsn?'1 kuS/׺\ <$\'gF8\F|1φGm:3:B[؛sWv϶ J8cHD+zvyFZ[UD̫U6Ŭ6j) PgUVH+ʿўA^̙$e@r-W֗m%Ta.l4 *Ȧh9, 劁9zPD{-iH`r& ^θ@)ޓ0i$zvG1./[؊RӪ5 É:t5xl4F;~mU]="b{٬œѪ S1 G.sy+Q<#O_Ӊ[Pf~}?Y!ZI5Cl;Gb6ZztX Z b+ٺnWVKjƞxVB;ށ>? L<׷eDtT(t7l'|'ˍZqt= c w!$s(d>uڅ\>X!n8,Wxnw!Iݠq"<{ɒf#v{}0fycOzN:u!ȓ1z/poǚN6/=IkpI.}ݲ$?PrrƀD DNޔHyAf~q5@Hhl|ɽUb K,/ѝƦ-B])wJL.To#̏F09(O} ~Dvn8e-:Hҧ^M <ʹi 3i_?0Bp+sR6vz.-q#;Oj⢓+ݸc=e^Shڼq,RBi,^zCUlF,awp{Y!OǨ&Zed D92{Û]*dHdwI? F*Em1:.?~ GNYکlud`ӳ1c! &i -:3~o~#ۗ,,2ğe`cIU@ň%-f7?S'iR W&DQa4x~tJߜ` ƞjg5_{ >F03Y,bH#46ߨ[T:~> D}MPřAU/~wP?M[F`!RPA,k{NCyi[n2'BŘvH^՘}VpϾso>F=5zh~[ uo!7N7muWrɔϬPPAvh~hqfGx [6?pAEL.F}:N-pX|z8STktYZhPI0U;C{n>1w'ORSgDt]28OeL|XBOz9"Q/`nnT~?g**"R &' 5ŲgK2pOĝ?FrD|YRT$1" e&@x786%6 Qֈ 3s<}n+JҴ[H<5UDMUkq+ӝ\f|m'+yR8}5*w?{r!Y5WWaLss y >^s`;7Xz8cmc0U%TX&⿐v5a &_J6TcG ֎eض1b3 @o/os߉L:!owiY)㵯oxM^5Ր9*8!XR|re ߶;1|kiF!lT4AG OuEbk5s?%_,Dh< SFH^]EC\dF8=!X\U&Ho^BD()f:63 Kwjj~KW=b{EGyD^ {&7JEL=Sde1- IRg.ERꎿ!qFd᠀bap`޽ !ƪzsPKR=3ϝy!gɯwJ!OE'M5ns!O7EMAq5):`H`ۈ%䄂BnO/@N"[3EƝfVMTP ;;*@v=Sq.s4N6WLL 9< ( Ir 'ٔH+_YU@<1 Q:+Fsg6>|n99v,MyE_afYԝU~Dkǚ/FVt33=n6uټy4RA/F$OCj.D-MC&=+D1-r&[Az3.%r/0J|`` m R4Έ|NfòT}\OGJ ~Z_y=ۈ >9Y"꧓/9>}pRˤBWr[6Ȗ .Łm-RDDOpELyKŕNh|O[G0T)b(c0o$Uf5 .gGi9sHVu[7`Ar=p?}ۀ%pehb] P|-!eg A+erθ{/>/LF *Kܪ`f*XJ眾y< >S^o8R*v9(/]?(,@M1.T_mUz*UŽvv rcM4D&F2vLa$sXf2R4@;+5e%&}=7B~㚵~PI*3XxPkֵ"~Itc[Y#]p^bK:l1(vg*X5!m]AQA M4yWr:=>qѫFejX:DC(<֯WĽ&^Af&t > Yq~BԙmSp)Vk?`Ea) ):D-+ڴ]9Qө^DΟŎb%#;iQ'K+bh^:hq➰*-^)Hidpbdo;ͿnJk]66a*p 7p8kE'_,PQڬϖ;8|;aת`IGmM.^녎AwWs C,:6B TD&RBKEwS$QZUsP0[O3}/ :ce`(p=)g vVņJ)8駫WqY'e)~{ڐ 麸yA*nN1PH D@0EDݠm $ȨnD(A107>Hlk2˗g(+xoY'8dt.ϮYss/9J%h#Pghx]A>`0p\kN bB\ȅR_@a5(rIbw#z'Q1uX"+kmv @Y8=\Oe{g ` X8~bH[,-iw< bJ&S-yX ,=KU+}=߀>`.=-KJLJnq)z?1Ty 6,YWm6lӭ.si3>נ0cn_]^k'~I`ǂl[N'mKܗ"\kkX:q|g0N[RK}5oǗPx>|'[lLG\\:ϗ3AلI2KڇiJe{gk(΀liN_2֛Q2aH-Qƭwڣ꟡*7Ƈ%Z̓K國u>ΐ:m? {$PXPb}IQ3z rЪN|޽ozŃɒLGB?N ^:.#q}4B#j:/~iSH3 b8T:o v:x"k'ix>ptERWcg٩GҸ3q^'u, Pl8s9X`;Gk`ۼJ&{Np)|@ :: ;8»wH2pֽɜz>NeOL4$2k81eBŃZm0F .6/&\#zC3uRoĄi\Xxa.ǫu&A4W\>)юڠVI贠k|,nNHa {y˾ɈNҴOB]礒\;Hq|-7B|.WEEPK& N*+03m#maK&FT%vHůV$-l@= y!xWl\+xJ| ${՛[&-u @<w$LmǃA {O6BQUNJ1 bG^GX n~=Ip㉸yħ`em[Urߴƣ_{J&9((Yn+Dmw/%l F)gYi$V/D"Z Ҟg4 \-Z

hLmLAT?{3j~γ(k8^&Dz䁐?3-TKJy$)e&6AB˱by%vѯeAUſQdbPrSw`|}>^^jD'܅?pǘG\>UO|E-Cw#֡hX&^יOV>V?K3UP8*Xݐ\rvUs'39YJ>t_C3]!8IOKڊR}J8Di&j+a<*YRP'QPWi#CMʰO_C VLޫ`e`Mc}L+>A)0NA$>Q:W1"g!TYϙ{@eT%sgow@K/'8 =h;K?|!FIݙ}\Z(:g5~py˗!e{>okĚ}B.뺂~9Ȕp"Ët/S⸡;.!FsB)=RnECcX[b$S/zSh/W ;~JjA%$`zGXVQjlg'z ٵi-!Kw k* ە\&k[p?rК~yWVB&P/O0O qQW<9SХMB#n{Mvk=dՃ00P eg\6J_aK!p g*z"z װbU#< <@n8+GnGs%&5\76QT%}-a)?&-&qu`JT߳,P•;Aʻ`_ MLԁC; t8¢# Ǵ70sEr!:WJ\\A")K3jOW#a^q|U ``{l7]1%ou:^ӹ;O2r>SRPupDY^ߐ1̹˝L&\yY;d*‹XwA!%6xy΁Z|d@d EXz0GK- ՜$p~lWx2.֝(fRi Bm\n4]Q7;~E_6KDnuV삘=_4}T#9 v ueJ Phs/IlnH _]Vm \|r TXL w֍4xLkk62V#ɞڄFHݻ%cuiD,"uO[0bSf0S"aTޤe$hm Zb\4XOR(&6k5N!"T.?(t_&X?V*%?`zL WZĠjqV< b0Jv~DzUaD|[qg9mͦ33udBc'9o~lt@-C Sz𡘽ií(>WZfx (hl%SLM!Í<~㡒8MRt/ yxh8ʀJ#ŷ)*šUj9tAw˽'^cêF_鄊:K}bl !>iR1c9"\_]RFWeSM p|Z2yfbȤ/]=`=s^d4K9 lM)N,լ!1Hͪ7 4|^H"l\Kw?)ӟ:_= '*^Ӽ˺3{Q]p݋*P {B=&~FkcX\k" z$qMr !皤(ElYd։(:6%fU'ͻ/]1l;U(\ ͒ɢ/+/BEkSaO(Wa$oj[@f>pс3)oSz~X5gQ:8tE+4!c%iRQ!^B[jÚN߸d\]BjK(yš)ܪVG2Z^[T7J_`j-* 4sQn6J-v/=MSRȼ,aJC*vABaaj>RnXSt5NEf pZҾ珁JǪz|Hjݑݓ0\o9+!b>"tU4[U*4Mgz/X*ՂH/b}hJA QީI/HQ+_YkUk sd~՜z͆T΅>Pv"㢀]KMngL_)cf }s2n:b4^j\ ]pɻ>NyIBus(i̼Qs,6uy;SI5*zM6M~e/`XZm97'%4C~BAnں!+HM1\,1q޿ a44T ^Q?7ʙdxTgz2-b\VPvs{/lkE9Ji,Ac M mJ=v>A`(7Eb?ְN(֡?^csTSۤN"B\HAH_g=U6 o+Ѣ_4lVf:_f5p.@YI$6g)ѵ#7vkBC`ب2 $/0\ b\ kFPk6& Al0,;#Shrv XBVC.!/, ( 07Fnjyc'FWJKvi?7wIڅ"=HwC{3-GZԚa쀖7G]Rj9y!h?sջ`/#`ĕGA( R]fyȗ ,Rs&W?a6!?f{%O}R׬ypGUڻc[&1,5i I"ldS׸,ѐ\ƒ܆Cf[XM֚ϯVlY[ؐHs2':4Wi RI{of&79&-KXe]- $'O[koW+M'c2:ܘѵG[OuZ >j! q(Azф6_u3ց}3b1玑c Re> ?-+|-2"aFB# qr4Z>*\>!:hhAM` F8e]!::9IVScKrvߢ?TP7L) *F9fS|Y}~MseO52l3:!VR޹7 4hM{CqWz"9LnB#2\ :K=}8x5Tx3@zhR02}|`D~WRRzhφzx5%PPΧWZa t OtzAV%[OL_ҒCžWG9etIV ~[eCP[M@T4y:¼0~>  1p`}., wox껞 x|{@V~_i+{ժbo4߸4žJ;hvi}|T/E2!xէ$kxzt 'ɥ!a[J;F8E>9$֖+I'#|K'U!}'Y,{zMCn]0h HEVikj_Lstlq%5(`݊~^,Un!mx؍!gڽcz3w[Լރl|N޸ gƕs1`lBԑݮ9kʹSLsg=x3F<>#2ތ'^p`Y4=@9>iYedwLöf1H)hmF%tym>g-=mҧAwF%zid>[,䢤ݜNN"e=!/GiԦ> iHu^Рh73o<&㭦,Fz>,="qDOfr=̅d~K٩LV$Vilǡ;r;:7W|K@F&▭͛2l';% 3Z1OMXE3A2"̢8#LgZA$y;o߲~̊brNhdAHVď+g;ܘ70e rfC*"Q8dzYW%H%bEfc.2l ڍfw=y;ק_ ?={*&!vt" G>~ueԡ:t;ծ6ύ]cjHb5RPN)1#!ͺ@Mi0At!ᢕyFۡ41,>(`T`i&x宇d#nt(b>ScǙ͹k!<'(ia--;6;eH4Ykk°O*q3Li6R+ko,_I<^ަ%w;hT ʒ i,F-Rѭ$,~<UWVaڦ"k;*;B"(-=l-}EƪxX9`QaMȦiG1"qHrn&2iLlaWs3}K[[y¹lmN:@'Ф%:'RH5xW~G~(=yuI#aNτ/ԓwRwGaJ\Z+$h+h+5=x%{-sلJbOu]1DI'HL SsuqazPqG>0:p͙fmUqÓ欥0NoAA +&|VBNN`V0MB'8}<Öo\e:|5!VXR]*Zm__yY,t@ހpK8373n̊B/P"I6G:*:9^„R9OmUDl^@IuG#`:4]*&B *߆l(:@>c<%l5\ȸ'+Rb58%4N:0n_td{c!Tq5*! ɭZsZ-n=DA$gϴ?Rx ΧP?'*ǜ ")'@k*$Bwy5 8%\a3e.7 = BbI?(ang {L[Y6Y 7gnYҪV:uJ3[ Bl.Y#g%bK~{BP+wz4}"nAḋЕ(Lda*l+N\Uz=r)=L̦\ڴCLJWQ# !Vە2G*K߾y|O^ 锢&'+{̎ lFVuD}}rCyɫ g8*^*Sw 7.~z<^C%>^ %O7!jD!vd&4U}I_"6N>tأgW_'v~HtkhXX.q S~/@. w&;ʙ}S̲~\bhl<*s";}/zh{(-<Qԗκc(w3kЌ3N [@/ljɶݯjTuM_~Gx$z#;L<$WR؀UQf7 0 #`I5G'ʕPwy%idh4^o DF e3K4۳BU=|dxi p;/GJqWb ~ i, .N8g\ 'IշzŁAAhb#OhBuԦ;*h{ bo3l+=ILyLڳTQ!βcC1Š~dR2!\20gWæ?GS!Qȩ5y^;(pVWˁT{ب|ErjKTf`yE-d6}P׳{D%)\)< .PmԢǤ6LېiCV*eO|01oL3;S/g^`$cyA4zp\kͲԙYh H¼m~!\=\qo҉40R!? m?.)󴸪 ѧY}lnc[KDB/"lQmռ! x\l㱉a704 Bg8ڍ}+5#G pGw;2 lHo 7d 1|cKC 5Rٟ@Ѕkuw5 G;5eufV =!V:AѨcAG(˂yVj<|y'铏WNOl^Ot;i (C躶6+1?R^|řZt[L7Ys@F#x^WN3%O|Nf]cd4 ms [a8|NQ RGqo*v Z 1JB<]|}ڭkE^3'R_]H^xn<R!qu8ˢ@Ku~i:b3SM.f鍸VQ(iHl0ŝP~>zukSGXȝ;肱RBJ9[XvSZI _=Գ2WY!чmrU%-^^f97[ӂ?%#rԥ'jeăܨ\ﻃ6JJ&u^<ǖȜ1my݀r49~T4. f׺P!*)<+7孿Љ#WP d G ,ԋ?l\W=wr67i@I8-|6D4<'@\d3_)=\-X&)Nj^ o`*eW*͖\"~vSHHB;t 4<ܿ3ԑwAڙ6󹫫&T^x$quxQ{֯79 N&"\luDFU^ gH ;ouc7vm!=WB]+oEy nb5߮½B~|aEX37-C_,3 &u:\5dXw}ɬG}C*=SJ)f^@ Q[ >8KZ c_CY tlT$-,v6ۊ6; p~UW1 խmKrIԍ?&ixߐ`F4ʴa6=eZ+qu 0:83쿘,Golb`2@'>/*r<rc#VQg# [aҦ†?6#5Ni?"I RbtgX/c{ZS vt5–QP Q!NrJ1g;8ŷLn_@Mކ#!"&[vʁl_lqG MɢG^m|]c(i*\AzAZ,vɺkP\Ta|N ⚼s9F2?[`I< R!N^|QMP~]_NxeBnmS^h??׫7faUgX2p&DὲO9˃DXN9@l; _#K}P ShjTxܾ^qP+%Wcdp0ygM7XZ]σaf`H22_޿_̋@J~jbspZBCYo |ctERdê }= YW!UA5 Rs;!*F?R 1';TU_$b%,D2gmkIJeiߥNGFZ\3$.WWJQEy,_ٟvs(P/BI9Ei`5yfi>` T P+ {bhܛ!p)Q k(ʛ76bA;}VÝX:k+X 6|ך  .j+I e*19n,y.i; 3ݙs3^n+Qy }@E Ըj_ؚ Ѧl42-U^L}d8ZJkCk5$i9Afw]^Ev^ߙ3,L溬ڑeU%(0uQG:\V"N{ !9 qڷ2QXfsȨ=Z{̆@Da?QuBq.ƱEd%4OdՊhg~֘1<^ &6cPmdz]jhK.BƖjx3RL8 ߭% vRNexA--QX M 10,:C `@}{u'Ehc}eroCZvSm߄`%Pb$ f̱̱0%b>ƿ [fx|F 9$Fs%sۥe=$|Qds:i0eVMaqpa c&l앳vЧ/Mp{2; e]y*頯jͼ`G4rġ %LvGJ&u\vg;>ʰ|un9%H@|m>n?GؽmZaSc3yf6Uuss"ŜDt$MyU#7>h#(DzqAkLa[3%xy_ځ-1dɇ4$Xlb e2y>|j^s~OUJ.mȕ7" ޖ%#"f&w֩<f('ݲ`4 rڜJM{si+qZҺU?ݎNp.% ';J&"FNۋ>{K.(gسyh-cTx + S#V/0~NW9xۯ-Z)̒sӗp!`IOo5m! Sb#?"ޞcbNu xyvLKCzu-O X5PW6 N# "˶m'!mg 4pҁĩ1k~k_MG_pji;P:Ws^:]~t & @Ĕ^\y+^|~XKn9U >y?ЊmBhKWr|/'"#7Ipfc \# *5~%'{8? \YZe*Bu^4 *bwνldV!ofT)5O-j^j"ezVG3(~Aᯀ;鴫e(T<Ghӆ?ڵG?:#V-Εu "yc^i'8G3x¹ޞ3[?ЁE 0w+G@nBۥZjлeƞ#eE~ @G9ը fBguG`cy;M? Y31"Dm| ,}c~$^|eJB`*E/HgD&lSrLr{e ><%2mA|M CO-4m kq ;0`AGY2jHUQZ LNl%PbKI%d2nn7: n,֎*1g8y&1|0l3ϝ$ '8 XߎxKeGNJPQkFpU<Ld9j>n-b f"c߅Uoj1qR~I8cOIXd,w$bpYt[Rs L_Pvd,+K |$k"SXcRaÆ%JeWvZQ)`45_aV:feg y>5<]vG.[tZydWlZ _Ne!wH_kjq,[1c5izS%*yG[j?HN=疾(Ke?ݎ" n?8JAl[-GXoiYi30:$f"UrAN[mv/(]UV#= ȚK6TmOZ"\N#5Ź2'5(EHHEs|rʻ0L%SlۧI^^w(as!;xm4t@CŒj#J,߾HWT8fX< ~in~p]Qe=KBJ&2z@e^.#y8B#xZ_> ʯQj:GLl|YDzD~.ɹB[ULo r2͠.KQ? ^Hе/"'Nݓ^LK4<)uc&8r3Wβ?S˾u)mۅrfm^ ~$E]QoË/L^bCD$x|pӱY~ΊWz!?ɽ~l)OM'C NC]t^Tۉ0ċ!q4ٿ|anR> R"1wɤWN!W;j;<%ZVSZW Jk J& BU Mg1̈@r]1Eh8 ؗY \/rq%:o,DžRZ(g^Z'ʤ!uwI|r:qjByO҅W$ҩɱ2cح|crnSg)]ͺ`^ֳeQʄrQqBTE t!ot1>w:7oyqALtrU-{pmpDWW?&agP]h*ih- |Hxz{'}Zvb?^*qP[ &"#R80mfT a'ѕ4wD@y6"* '3ۀMϟ~9^ Ҕ< N e?l1S-cC{63Za\ϲ u%NA@ȯ7Lde4 M֠ȼ &bG?qz)C? .9:B?R5]H&efbw7wR/ EˤpaT痛 b~ui"?r HmJI^{!ws_MzQL; >qq"NʖI8RJDc@ΩKԐBk J*(09xf&B_b7{O-!1)~s]3VSdT݂^t@<6ʫ͇B{z5BC18N7(Ypxz8Qxc&zq+0 YO%F!Te*;.<+جm յ}i{wnl-f`,?ANҴ +3ktȦdf3H/$WRf|'TӐ#Ht($LFb\>gԒ> <;)^ nxpg8^hVwWu&ac4suTy2Npo`1EŽ8bږs@ԟA'_7*cDPqWNVOl ƧҔXhVUdN-/ȋ 2}:Ƣ#j(tJ7/ XCbljcc=&2ۂ~Y~)X٠WɻB*t!&)3_-T/>{dU,]oB)ihpO;U!*jүq#"pG6IgvN= Q.͚ ?/x ې:xw)\m5m;h%*J U%j!4Ӯ5aIx8TIgج2F]2S&н⿺fN.щ۠gqD;Rji|J~*z:t,yK8vD2eb?U|d;[=5ٍ VְDk.o)df!L5`%=_Nb{|4Mcmrm P_h kuLzsw},yKhcn {ۺ%cB1pںU{%}n6DMq޻usTW2MihKE U&&XvoW#S.4VBFy!=1'#"v7p&hQN#{T: 2:бx"("hK稴Q Rn |Vx|ǀq-YN W-湛٘x1ڛCz!kBv{%*u2oNIaԘ"X@ 41}h@ O" M9%u$+}-QRz"BIlyir*BfIR,f\|MP \m-TW6Bk;f>hClGT. |{yX3)(vn8_''uNgVS9nV ZZ_y,S:16RdT|u'j-<`aKC(ږ5w (amxH띴6݄W I@(^\ML0###&:84w3_amܠtٷ/ɿ7! 7MEC ݼ5VRldC/|#*ڴ-PXdҠ]Qh؉]LUO`խ NFfCe# y!Nz2}2<|LΫF+:YuTٔ %@85>9W&EcRH ``jX}N15E8qUX't;u%FXvƑa 09։ h-uJ^ <0K 8T`D,L=Fzoh3'Y0TZz<'o4PdD#ںio|!牯=ЯGl.2|}ꀾp:8u 8Ƃ7FŝW,`"+f#b9@l=2dKF:M\+{y$r:eꟻ,QCXt;jut9n1#f;S烊UN1̀hi.bd)| Jk|f R?}ϔ'nU.e`\ ,?[$+ETΨMa[hRaiuV+d..CSkf (r*2ءwqK=s?n[k ^{Ej$Q c)4g@󗺺jLJ@=4Y߸֦T.ėNl]<-sZ[GTWwPH1E]QQO8&IyF0FkojLk=픬YĸZL]HBq3|K\cH5Xe>0/@%5=Rvx()\|Vz#B,jX'}bCGX-Fk80! $K2YSe{zivqbsO\45_r:"/WW*Di"8˟-d^U:hFv!:BP 5J=}]o6yD E^&3WjAC(5%L1=83$sM@g~GFmjQYK-Pzۖ7ZIK?1:6p Y}v%.^I ds`;jYf-~ҽU>ޒGޢFlRN^iQöٳa6bvjP1^|YLu׌7}ΌE@-l<ŀ\~E!cttiwwjj~WgعSXL83>#98iN Ն-u%F/TF(a;$^3Z| JfCrdQ('Bgz؝Zx@rX?H☮{kު:8N]Rh!`gW(^݇J${ Z u|YKM~:&c]2@of8JЈnBƔ !OxT WH m]>UV$&1DK!3Xf6(7G*.|/z矒n%}8T*Y*[:~PbӺ-}fY聘6h|>R S|4L,qʨDQAOpN:~F)"{Y$/xF$oE$;>4Q<"@o7o',g;o5+zd|du+ġ.NsܖM:eVsĻz%/ANЀ 9 +[ɪoU7eSqt\R]R[w]JPIm+uABl(E\6~LQP*c!j,JvnP/1_lvz`5m9z.k"k-8?ݾK^?!BLЕ&TU#PEkKnvfjɨl0j0o;{‰d^e\9d}ucPy"E)&>G{ָIĜǯJBA~''!G4mRs~Hq[のv ; ;öW6*XPAnYmA^=qao猴gmU`$hۍ\^@{oힾXw Qd`yB\C-M4';|>4{,^mI/3{ )[*iv4ܦ+~k^zA1xbIC8XIi8+,h\f|v'*ƫSxtN:7NpbYt*-Ȭ)ߡǯ^+Xֻ''bt;?eV][~_snx|6s;RSW;CALEG'Μ U:SEy?- 3!+YfN lw5d%7l*NȄ nqwCMGV8©R˙l䌯$V,7 }@d`debeQu>z@b|Hw c7n#n WLcl酰HҀ~xZqt+ʠqK q1=>o^G$,z&hkC.1%ҷa[x.:֩EWbl,z c~DPEQN|/sj0JLU4rۙo$FX!Is ')vYY&z%5#pvѽsvp!J  <여 oyWn܏kOUVCajAC=HhP\O(9x;D|LOpfJbi?j :{H*"eN}L:._v}dNeqF$D.cvEBKZ8ι;J}b*-9*Ќeopo1,Pqݟ" s>F+ ["<iwU~醸ؼ /5IsRafc,nŏ$M&$> }JLWI}qS-eW>b03`9a g:wNQsq爛IzN ARzJZrȹ`Jp'uEh ;^y( AutI!2ٍPMS JdzdȐO5<ëLDkF?/՚:z-Z桇DUNsT_3lo%vFH+2_u]2RezJvxbI0]?c+_O`x @Y dRo!MrX50MYxGVvcei9x'rBjrkx]dQynr6es2y?u|]h% q.ˊٮd!Z'h}qkOX ?xASʉ$j&2a@V9If9?x.juU$ 4zByAǃ􌖁QH1MGиL)SE?w?<&Utb&xH5cX cnssfbFA5T0 m}OB*%[r/mRrx}2~"_kLװޑ|9d4c RR[̢Wsqf?$cXӣ Rx۷-kSYW"\(ЂҨε D1aȪZ0ZՆb[֩4 hzPjoEȪl};5SA]W;>E^ae%bkM*e^[\ B.64R UyQ0"s}5s[8_m"LK,_@I)B+nL@fďL 4KNx $AFt;` Hqq_2jf^(p?E_ ~u 5 ,&7avE@[rI xUE,rrtkq8dqVAU ~lG lh.AN XպeN:\xflO Qవ$orìNf$4haU/('7od:y@˄f;w7&06Jxs`z8\tC= )Za͵=nmBEbk5 ը捍^8RW2/E$DX};ajGՀ[y<=s,H]XdϦVg䙠eXyNmɇmV~+O僋dcWx'ds}܉)t+-\ - $x[9ҧD?W'Qu*5ڴL#Fb9 AN3?u|@% PxX,aE30Yj5.\&cP~5Vta 1ewf{y!g Ic\1}&yM~h!A7S/hoS}_| Fߗu o$c#sj Ju_€YT ߘ{EL`Kno"{,܌+F[Sǫr_aeY?cN揝i>;j ZӗkL]%iX 2VA.am=gZOAd/aL@ %LR @6m*F0 n=*-0S]WH~F0qH ?>rIVnh`pg:* f !wOYZDfpe"'mB h.?$EE!lٗG<` kzG {T,vx4,D2FXkp>2 Ϸբ*+ 4D'->_1LTsY3 .9AtOĿΐ<F{̧z S"-DPj[/Έ8OZda L;JIW0DfT(6 5lmZe{j^/vu""o#悍Qaxvqv5s:#W`r'Q:qqs/g먱p DLCϐ#b9\3h2(iwYUXycOeJ*Õ-9`,CN!RR ')%NWb `:7‘ېٔ 5 hztsf^V™0x254{1t,}Y0G|ƠQut(3GY [%hfAtaN!"YNEiyEpdHOENf ,=Cl񰬄-gH3Δ:왌}lEf}9tR,κGblz|7&+p6!z/A?*iq`gE]qybBglN&i<ӍD"( Ia[{]jښVsxAAEV]?8DȖg䨁p *6C-QhS,,7ޙ soV)_ &H' 4qq)BD)k9)VG!<"K`딪4M`Rf5C@pGX$)>Rp\"q\t_1V$T'uL7 @X}Fh ́ԡc8P]k|ooA5L]ny})'4iGY5(Fڨ,fꅲz O>2p}v cboڢ>u)/:xU7.Ӓ/8dqsɻrU,6GF-bQcPбTëH|8E+C K򃥧rteXDK4}a6TÉj=g!Fo::ӕGqCDZ)ڒ<9^mm]_ˆP۴a\-D>kZwk,jq`hRRȆG^I׷qQ}r~AacHKY/RFZ&X2Du1y+q/RؚΦCb[ L%DZ[h=]TȪ2vd][ 6!ߟ)=KOEvp?I`Q ?/r]3IҠWULbBmtVhS=7[%!kz[~(*x..hvZ{hF~ %T+: B ?%tvT&d%H4%/G˿mFг$M1ɱm/ SL%AFgse只Z}?ߛ*qu΍%j'l *h#@ [#T)U()@*pע;ո,tC@j=yOc<2<[ѳBbd<??2&:+ WˈK6( \-i>V#;&!LsWŭUwScBgo+iN_# \3̀@&ڵ3uk*Dր[mTƩh7 C72}V/ 0TNr𢻵 th Gv"5'*-v [lI0##*/.fKOT&x/KFbatLIaj؁zU.$ uod;Xt)x SbQ)cϨ$ 1_Ux/"!"kI(˶!O 1AbC#EFj|pC ( %nnkrc ]@L;{A@ibψ{dw7!we[Ŝ=9Ɖ'Iݼ6O`Zy6(Mi&Sli@-j0Vo8zV?{H֦+9Rο#s22 H)hiž c=])AR0$ˎgPf}Lp^C%D?Ѐ5Ts$9J==諼ʚb~!qmEMjwU.LZflS1ѷ\B?t췴C (y$gjH׊7EA.4j9[zŁxP#NuBǰe=4{M{Ń a! T.?u omߞ&#A0`iU 2Yu+]\ %{_+aK6QCAv8AS=f:kxBN6\+u6&>Fb_ -|Vh[u}?IαpkvJHCcf[w3qUNРvɏQjfXWW91jl=m^lkФàٓ<Kdx))Wi9O `] mm, ɐ;fӖl-7˾)mAܪeh0?@$7LW;,[\,O6ÈC0)J6#ۘ Ri{;֐n}¨B kSnO;uHCw 1yoT'Pâ Dbb@wmbIr-Mm϶Ig!olk魯)6}a~9pY7/Aqvx.Pœ\p0P)RیvHbYɘ\Nڗc?N5Vr==/TCDFCrnU8 @më0)yՠע5?@)W1>++fH>6R$nT] )?aZcZ`Vա( ~ Vp4G-+ 4H_!DKsURa(Bs@ joDB-%踐ZpnQ]4ˑ#Ug29u_.`v;t<ڝBmy ~C"I,#{|ʱ<~+hG:1ЊC!¦63(^%bY kK2zW] n@l7zt"*md{hopAY؉+JN{u30J60`@=W0%^7w| N5GMH\oJ߼$dN2ȵ-gQ ٰ[@'^vɐ)rFJPw7-8VB&OLd-JTDl]Qҥ%$iRmv(lB4Et0JŊ^0u'JZ!י/e MJѵb+3#Vغ3@bO"؈G2ڇH=w1Vq8y$\mH6["`gv@?0"rh@ET% aA7`Ep> hyst ؼWV;k6 W!.xveL Z0s&0#9Ǧ-ȗ x=wLY~8djeյ{ú{ħ<*Emb۵Ԋ9b7 rԿW׳^bNkMG+A9`{|8v:M{xr\<4⦆ڙt S_Lv9&$"\ b;\On3xZܣCM\"ZPϜEsnyj@ ؕ?5z ~k.:dX[wVwYqT *R]kf]{̑+zX* Ƚ4ZRIՂ^|qVkH.Ԩ|&|i3zg!6"NG96X3ցU|ghZV~YW=3s.%i<8lȦV;B7mw-k%L%3ȑ^Ua2m}]&/vA+rO.uu{ {,B \6 e">>XIvHZ/ΚOOK+%ᇢN1z9*&-=牏1/vg^ NxeLBrM6 K#F9E2pOK:JbRK~2 ]n[1$cK&mHlc dw Mޗ7! Yӏ7Ad{13ޤgVc~sdtEVVَ}u#ws W'OOh LqMF$JSbhF*%'S&?ݘle`w ⽏mA)5 Tt#s-8F ䷾8F +hؚY 2ͤ( ?5QOŚGqUxA$('##DvwZnU!R1sZA1Ml{(ElVz5[l+JJL#WjnE!rK"x9U+7;~bs^>s`)n Ͱѧ M3Aޭ ={Z*6LDV&GdSgN!4dᯗA;ScV0}Ѭ`) We]K8_6{:4zw$l簡|g ] 0VNNJ-Ezp 6R[z&he웻ރ#]dKe>Og_!Fy4B=uak;tZ 37뚀O ]cMQUx̦C *$~eB@&,Ӽzƃ-I'ƚmH cCg^lpob_DO"z:̾c zOEɈܡ9DpHW.C/niTj[$^hKF_ChqfXUU*Ar!eE oCV*e1>uAdŦ[Q^jB23d\44)Y2-}H8I4-)-q_9˿XAe!o_9RxZ%`ΩtI}9Q=Y; \${{p Qp^jhFB gqGFOϔ=LVvDh14IAHM:ӧûrCnl;Ъvtd YSkkA@xA \BZuMI5BthE&&!o~ikh ΆW}t^tdAZsjlS8*8:~QUfP ]]Xc(oZN>}|Z \1k.b 7xߘ2u@SyO[nrNURNYEIby^ܨ}9bbODyO\yC }mY[Oi[o[ MԂL.|0!܋]JKHwg!t#׊XlPg$D@o 2}90u <7w(Ő+aDui桋Fƒ#Yg5 -dhep5seIa2ikGbߞo]8pBaA'`eZ_SIZ;w̵=%-(+f]Jih4O%tnG^:+lDkALDDp] Q~"hqIL-jXHbE/ct "(Fŧ6Ua{r:CM 1$L_Yk0cHU-.~*$+߉eo^Պ=P᠌/{ԮZmۭZ@ҲW|wJ8 M7uP+Ayyuf38tЬwBOطTr3pIY6s'RƆ}(=Caem((% aV~Xﴱ1Luь,W%&h$WZ气~L)q?]E8R2 16 TZibt^6N/F.Vr[aɷtUXB綥592%dZӂ*wt d4hrI7ĄZDutKמSk {vksMZǷ!{?s:-H*ʺ$0ǮG=5 [*gF?Z +",* *$9daլdG75|Aar1d!)J ]m\8sv;hҲ&ԿZ+7樞) WgyG~_VEOCЀWڕ?IƁf\W 84*J DAg~Qxa"Vqv˗ x[@Zc>BS!0m%5ޜQJp׉ X;[ޏmퟍbRﷹ|&u=dbS@8=9gܮۏãy[MP;`FwT"Yp4ޣ "cxjN +sKa/9rS 8{C|0Wp$x$.ۤޜbOO<*GqAX}U<1N-K:0Ӻzxwײ|C훆}9m+iɶXF@`: Ɓ\ZYOz$._;mFOo 1G/8,ƾKݱeqȉe,D޽OIL%*|Ϯj[2 GTӐGR> '(0ە1hДJejm94M7HÌ_ecozWٯRBEjw9Y+d$6Zaz9e"kb\ZӧBZ`=FSdbs>Հ$q96 # qQgr(v9-qLMp ]J v+~ܥry"t8|WyԖ? Y^Y%x\^~nᷱO>/#*d Q|׏Q=1Ȝlb(us\9[dcF+M݊u-hFeٓN,bFp9>gN JB a I ` Efbm!ދle'w0.'9~cRn|w E΢t>녾[}/Py}/ӟ 赁F8Y]:~I j+'P܁;rOrj3o "6z=aQ쿲58Q).!Aqu7|Hz@zW|֪Եm8;S<#.= RLұjPB ޏdd$ TQgDҲ3Zҗm;?Z.Vj?Hb#Xft: wdvp⼞Ih/y6`)z(@-cRd`?ÿE2Lë8ْ;-] \ᥫ-xB 3k/ P$K~m1WɤcdU`#rEK<&o$*hP [t 'fDnLd Cv{zpWBB]0 Ew6jA8߻x1T4.r(ڙ6G{+~ Kz o$3zU o \c~W. CE\޿^{t`F} +d 3KhbJ/SV foMaQ=]XmŸ^+LoVڂ gAl})s<44t/]' 2;E~h+>ssw/ ^#sx.jQM9 R'xU;Yן-Uk&,(KC><<->rK"ץ8n16$#)#@$}1D!ZK/;#j:rIA*GПG`?x%WC|`){kSjc '%15#=eJ^'y9,,~UL썧d!twޤӚ)FVgYFtҫXcZŊ,H(rFz,Pul,R]ci`]y-}3}/(P[=\=U5TZ  -FS%$*7Ar f1l&'hGT/@u`$e͘>X- [<7VEbTXJ11ȝ.A!z ޚ jD\~uǵz2q2҄Iu&3q y N=I#}5xi3CU\w pn؏a7*]kǎҏ[N* 9BT5*!s,SuU£l LW$OEܔTʈ.%X[=hpk,qt 1wX,!eq^d 57К#&XҦkDc-&Q{IuLD'^G9mo%(h!֨|1\3"|}Sa׳;IG Zsnyk>r#2sLH\ta@yrn sc Gcj~pɺ*›Hw73S<qp5jī!^ǂeI+Ͻ?.=ϡQ}Oo(N_i,bk[[;`pcl LZsju5C)p cd,{Q.e B9/ዿΌ;pxKJ="\ N~aՒ**{ t"غhIvYǽ/j;q0fTs1o=1 DQ] 2;&j m)r`wM 󇕳"cyGX9!0*!{C#Nw$3znHҘڈ<4ݬ|=Hcr4fKְNt|иhv$AvGjMGTǼ{di㮈޳Z"o1Dvbdgf'QVN|Ḏ6C/Hj~ ܍=Ƀ gqʀez4|OY8EU6푬_/r )}]; B&s~g; <",e6kH%|U:hC*0a8fw^$B7ok%_D"+wea4afroC[L^|֍ h-.{`#nZ,EǬ 4x 'ԯq2`]B?8PQhT)ߨB]M[L6| ϲ%{Mm%*Q:}$^J"vlD5P1o˅c;?x9M^?`-22/.hsb4KkRonrDtY/5 zd[gzlH*k\G2"/7l}[ɯo;,A/[Ƥ&׌RĀ#ٍFNg=5僨i~ JstJɰ"LFSPDďhWt=w~rȌ4$xF=ꬸn<,KD}B O#dUk}gQZ9񅡩'7ץC[8y9ѝ|H򫴎"\2=R vP;Ae|=1/Yi^˹i~p[^Ay-Fݴ?jXa5a{ $Vz28"FDZ"d퍐,pRe#7װ>&w1g-?ћ؈S7 );XZ3.>Y5E2;*0 !?WuA+"AiRm/i`-N}KfvhӢlf}Ug\["V?1NvpyC7A\-Ab {Wy,l7-ROn^D0M={nxzπƂeRO=yׯu^tpmp%"RK'Wwٖj (uhcM&Do_Ss+wsj,H5/,5(B1pNҗzMZ}lãP<ƫ @.ӂFZyŁyR?qLA*W#m G BI^Ds/+,/܇gܹw^x+;a LYv[2~ aOhnSF;2=YH=ecAuj9'"$/ `.vyBJX$q-a@ eX$ |\ng  B.PVŹs䭵BD; y:y@(_ˎ '6;2YڱG;P"Feq6l'.^;dϞ{f~B#<eĨ!{~W;Y@-\dIx'y)W1w[M3ynPsշY>(HA:ΞkaMvA6nn _nV"8Bt){i,Ҙ#4, P'Y _ r#TQQ:?'U"yƦ3;AEgY$CʀK[Nվ}4qF >ξBiH,gZ\=u"HM)5,aą~C nRK׶BOc}QS4x,Ks+"]@񎾆55?,%,+t*h7e1E񦡌v57v>D`-CGC9i*$)({nk oA ˲x9p9ϣDd`b)]QuE2ָ5YagI0aa{)"vDSZ9ONY4E#_B*x dȁ}S,=׀!IfjFԖ]IP< Ig?4_5OATLF{4cX.G|>S$R޻ .Ƶ0Vt|Um(; :j|/? (ŃV1 F\bf,=5f= HV?OCgsiplkvR&[E$>L輒9=5Q)Ftm߂$bv43] 6rlFDTk -ܷU?h"G=U\~(EFt/Қbl}~rO:6I\9:Hw񛵀nWL:Wrg=K7􎺚/R ymlЎ\nVeMe;˺`c2m;$3]ROm p @ũCcy'Q#ԭ$,S=TYok(I[,q/lN,;Ԣ R`༠(Vu=.,Ğ%=7#`96n[> K X(>'C觀m+fW࿩3,!ŵ1q?SK s}Ԋ;1ԏ yE`Δ8=`IYTMdcl㟉ޔ)kSFWM2}+qP'CMSӪ@mmMa TI|qVNmeQlVո4Ke촱~FU4CB3d#6l?$4J9TjLv%4Us2=vTxX!1Yec"j[nK 'S^Va00|a@U rŷ?ytcx] f>c$l#p;ݮU?-m-Q"N$kjw͕Y#Cw_ñE;*"~:JWF-ȚnEX;s>NT${F @}wRs|]:J,:ѬהMgm NLlil#/yso;ֱ'I\sgI⼅$=S1?Z#X4/VE CJ΋gZ0ldLV6pRMR$MIW߃,m[dloUA]-.SoƱ@IFL}ZON*=C@͌mTVhKq-4/ jLq*P쬌Ap M!籛Y[NK^)qVXfwەॸw7؝^EКq agFwS6"@y PU ygT,]%=79%&6ǒ"?/KH8 T? M)\1`N2OBG(e a]}=0ѤE͗t* >4:msuw_hJ0~:]ޚTuI0gC$T|YE{\ gfz֔]r{4\#/^e20u'͊V(u #oe`ѢD+ЙJ֋ O fb?WhPYc `F]\M |P^;~Xo>kIz]M|qK㘠5y3` ?dLjVhN)$s'5JU9Dy{چߍ8,W5(b{B,Av2: BX[DV?VYUE*]fY qsxkvϪ^\KM'sטҵAEz4;@زFM>SpzЋQRA}(A Sc@`8'~ul Q)A)O>ƿ@Y MrW;) n(4Oҧg~{y]'%^Ԙ hX?Q*TV~Rzf1PE$1I3%A|PYß$g!5fu"$"j?UWs  dsADIꇷDjK7X51y!^8 d~\|UJG wl++l:O@C防Mhif͋ T.(ʋDÿ[#O| pVXjOjBNB%e ߀v)\p2ĭC ˌCݳ[7F97-w,W*+0 ;Dn&Es i'߈HWI̳dF]Jͷn?Lp9赦r*_r0TdċlP:k񷃽^ lͣngd7b5P3>,:C68מ9?> u/)!apV)lT%%E76mm}E=s%9 ̃j/E:n ,Ľ ZibbDMKL2c{QVJDasaԦs1stJs.EyN@3ug3:KyWnjENJR!MP*Ka*RPH"x(nҬ,nyx`4bSSWS~d_LEPI o67scRd[FUHyFzyZb}#ėED_XżO!c=6hhn3-IGep*[r@ܼzn8GT5΀Vh6&oB/mb6s4,Gvb@^%0 FP ^eE|^hʈ:S'NE4݁jf$=3 ǵ.lC|Y3Jζs+ q`㇏J~$Bc i<ˍk[.RI fČ5j`.&te=1*{6%0U,+.I+<^*SU"N~?6'Pi*Gj~#Q6`8ٝ768lvHgu3_ļPsL;';"8-mp[I% 2l EmK"D ,LCl9³>غ73!CGNV=!~%r'}K1>EciGoLGhi@fI#6FF kLr1"ٙ%S1trT !ĂZ*)BjPVG0"`"gG8"rIO{sx_ov-O&c@GF2$yدQd¨~RT]j5!($(MԸhM|L~`Ix"l^YtP6A휥7VH$%+sI]}D!1իkf|v*x ;FvLtޜ2({sKiL`gWV`U\6fR5\~/ShUɆ^smL}jt{if3R[6(&"@Q֧Vc= N ' yM`o 0#j{B9zFYa9c]Bsؖ 6y!BPNtbNRcq}GMԎt`-ۛsy} _e&DAc #fg}ɑU'%+v~=zn>hBpCC"_uTX7$WU;Rka;ePÊ|mlFHGX[^Hpf i˒Y:ɶƕ$݊$@sX^32jH'(6XD/eА~䵍ЮX?~CH%^G\'8N>;m/ݹ 2B0+ZxBrH"x-gB%u<;C8#Ul: ,= ~Qdfٛ!"!9r(;~I=H4#~3}iLβ OqǕ|) (]106 $ʪb7ÑTA1+G`oL^+6.PS5^B !6XUp0,M7yۂiYhDΔpZM`(G?/y%K۶+ !AЮF^/LWI,I^9sKC@0 SsPgfz*bf5y~5VzRQ^N+`ipw]%ZL|,O ~($Y KujO b)nq{!ھaS{=L8i뚻=46$ނZ0/.c8w=)t,gs4>աpvg^#9ZAn/mTt S/b8gH4!ZA/ BRBzvN3yٯ(*:05I9ɇT;_2?qo|pJ֋ԍĪtyP҆w)z{14MPjճw3WI-n b ,OЯ@yUqF"v-0Y36f?n xRcHT2Y<;)-m> $ -"BQXWL'H| ت!hfA橏Ȳ@ljO[wP$+"RTPտ\f |ۯ;=xdueaOds ނ\)~jWM@gGH =wofp"?\Xq)ՂTJwM׼zfy|1*7yh(lithIѵ0f_̙4 $Z":y/`6Y}Z~M,ڼᖶKnUi3$k%d\_U(kJ.Gg`suIq5/۱dwlFy`rU5Wv81a!uBKwΠ0P"u3Uhth UGW,n W'Q?:c-œ+T +]<%djz3T(haʫ <ι~tf*9URUɨvuЂ#߽Rjae?fk9V %B%39RYCs?g^tpyZf)Y5?]h| 1r0ҷL= W=I3/9|BI&YH[^L|~T97S,^́㳝P$r)J]ddNIXʱWtG"ϣ,Y_2#Ci:~^ShpYI^67`c_Om))`mj +]M *wM ܐpNet r}wAh'wTs)rj]Eϲ xʳPB>8-1}p X4?Y~Ͱ& 3A!y4mY(0an!\b$VjBmQ in=+ދdo3HI5Zk2E@rO$ we} 4lOcS%lŽby>s|0ԫ 1W1 vԦ>D aEp6$-GGGߡ00K{]XgԾ\nmb3H@*\@ُcVӿ5DRuw㧇 jc6v93G*@A97?&%5m5ō7Fg -2H0~T*3쳋Gqxe'Ӹ2ߟq0q F[rv|j Yb+tct~qfZ9.AV"Haz/ =we]G-]\w"OEJ=xgs[: 2,{OnurfLJ`M'ƣv&@B2 \SFhh]kQ\aAt}z2"UzynTTTk¼ӿY=C*wIǚ5hVav$j&Dn[1x;hCxR$@$YUvL|n*`a-a33\V (YlTASB>j_J"Ċ@7ݓUAqM"^Rۺ;ŏ}R{u+$jx!f<Љ?j(問'Q.ZG-@J~t O^.p[ݬoחnqҙ~O~|EܿM)Cz?+;%J}QmcA|hJ84wqmrOE#`׍R|X)j]O9N \e>h2F$k{leBk.﷎z'unN*HXC&З@B*Sv. s0ArՐ )1ݞe\ʮǢ3C&l)^1N41A=l\R-![%`O.ӲT~/Pոop*j1_>A ocAԥ^iShOSG4U@µS|)©CߢB$8~2& -:~%U0Nr^ SQ#()UGʹZ|B(Bn[8H;觶e uz'cnM ?⬁B$/8M 8i*lK\mZIa^ᨥ'DOW4}s+䔣\dJ*6v{1:6*_*6Q(>i*P0BUC>iSUm\%85u|PVޱR:Y8Ԉ;O} Jpn ˖{Ȳp*e'/qs Ar%:Z]jEpkAؤ@gV {v*| i)u,)(,#޸,>F' ubJC!鋊;Au8#SðRH g~NX3V=hPMU6xKa΅a=.,4=ՀoL'H ]Э(@my au;Elĵen3H#1pHRԩ?W%_G*H“nTYo2FO0ңw'B)7sS!nV"_ 7r=pgCňRmA\ 0xcr;SD6<[z 0֐0҅D8qq""$fe+"'AZ*Q1fꢷJ e|Is:w 񍺉!gGb_YC6 x5忰4>PfRg^?m%jo1eCd#em^*%DQ4O4H%̪4B@q}ÄĠe͟Y1xaY|ڔbҀYYo%Qf/>y4(F4~LmSpCCMb׼"D| ǫzzRȄ$fܾ)gc"->5ڤb|((@Gti #onjf5;3qQ&4? л*Evr'c&K1E!_Hw|9ȿ>~P9bX~ u}fuyyM65/NZMDM+Œ[.rwoKDBN ϫm45z@?)U֖6y2-}!W0>zxN!=m&ix_dҍ)n v+'ajM 2mN5.cg~D̺3Y#EIjjCjd[Hn=hh,CWs% {W&3 8P-ǫ7Ai7>h뷋`;ЪYc}0[Qt]M;oV3Qk[z ]VV0M6\XFk' MB}NEKxbq;53)|pnߣX VEŠDTu't`]C3劋ޱNYԤkCa'py|jK'{uU2PK E MܨM}a) ̒')}i} , .8|0phgeB)#$|n:&M/8b 8:|X S?m[xQGA;J{iGtp}]҂m0w+uf\0uһe>1a< T}֛H-eg-va՘Z6CX^L.?x;7UQgVOXsFM ;;sIw3*#҅}'E7ȝHK@yM蛸5]٠nW#1N([(-y]H%a]:.iw"T~)|\ai`UbLxc&#Ȉ//K=jeQ{F9c\%vSR'Gު>qbH+]s]+Ƭdz\}*mϴ5VcNjoƴѣVw8r uܩFLD0%ڎ| uv0ƣJ** CTFS-ƃXo3!“cfvpiz~]F1DDe_OL`'Azت&U2 D*x&ʟg}|Qq3Bav;+#uANGQЈuc-˒~5e*x_9ynMaiTz,~[PY-b` "Y;`=ǶAV>)7mW97Do{،GH\4.$GiUWU\ (D2)R%)@u4plvM,[oK'|{[QK U Γ"$KqM?#;8{M(z auWedüxQ2&릟ʛjVo׺ý$0 EsSBXap |쾑h!fa@~/&9/%JtHNä@TGV2W`?Tܝcv+vY"q+"xV_~c @PTu Vv!︶]>"lofZr^#[v.m:RXy[xA^@YC i!żdxٚ4:> wO/0υ'^xO F||Uv7XA.ȱ|(w,-gZ´ Cv j+ yVJJ{zQH .7gޡv4QL_$`/ѕ6ltH#!9|f\Ap:-*-l;fy>1kō bWw/K Esz#9pMUÅ-LJ?KYxRIzC-6-z rwfΪRL#SMwggNm+ݤm!\8I=]6 ~dH^FQ#*VvT8E%h1&DZY1OyHZhez<#8UjbLH7rOPY"BS'ăK=(^&joC2f^G{F,1{ E7 zV궂2~EѣQZtUvl eFG|;riy:f&@8镕u-=Kj⯐=RIp"v^ؘCJ5Z;0<V:vSV6j5R-!➀.1/X]d êFw43m@ W(qs7-%` UrÍjr**V6t7@TG20`4!G5UB^A$N~ 4)uK_2uD#sF 0`?!/kn4 m\Ms[eUn*t}l̓ DR㛮-aOX6h]^yU8—Uu8_zV:Y,_觸Xѓ52O+zB)#J_gkH/81/p擎uGy^Jk+^M M{I-bٸ1G!>YA>Krʭ߉LXX\oFȥp٘/4q(hO-']Г,-߶.z0:L-O_>"q*B+0dO5%Kx U1ӆ%`g% hzrZj@!f2別N9Iŗ-^H ܫ"Й=y#ڳ#'g_5w6>B+0HmljDZ!ɡӫ:;_.?K.cSzP:$'~O} vNK@7|ـuR-LZBg|egL9pN\XnMi 9Y0 v5lNOuHt3LzNI V<ө`6wxpOrҚJuYt '4@ 7]s&@z9N Cn{>c=_=_* csw@?=P Ϸ"☂eG$< zI24)NHDψ yRdmmhx4-dT`6X7 FWCSqc~oIw3D:gSifya[k.fxUL&:׹)3hrȾv>L'9脠^z_tCt$~;=Pt揆"@[k.,NJ' 6% wYdN#V+g}:e\* M91]&ܛD4;G#;>{s@FTߴ7b~5X(܋_,ގ+aSx}+ATBF9 S&j,8~Gx&LIŋ*OTkXPYg)+Ɂe k[2w<@zIaK AMlo 9F`?j>KZؖd3@Я‚bP'jMלQyDSQhKvwV\A >ٝ(j2&ZnPD[+*G߰0Flna;* 3NQ˕>H^Qs2CQ!%wK6zE2r4N| =n:J4vzrtM~R%!!lnc>"% 6t2"Պ!-ᱻ@~QKs9eg OS\!‘H\-.Ds6"n\y[[}r d ©aώ{[a20sH =Ӧ9ՉJ`&wc sNwJ m%ӊ9X;r&h_i3jt^ 99*ˠ,:1@ܞ $X<IPTZP|,;r6Q3S8nj/s*LvQw ,yhq*"fԹ;gj:lGEҡ4+!uRKms}HGQǃ=?~!GT&~q4难(+IcB Ꜽtr%58JkT>/,HdrِC$:VQN:.yڧ?+-J 4SLIwpFreIւS.#H,Y)iKG _Nj,FDt|e6*!8z<5sQx&HX<bLfpO0 \&#ȗGR6mm qW(LS;RbTaw#h"6JSc5tu[Xn gWSs)"/q+~t-2GM%"]J95 L,eq/ f̜|6SM^դoY~Z8@\v!в U㟸U"L'w%\pbP@{ȲČ),.KRDhͅ6Aex1)=ip]m4ޘ6ln`6hD )z:JY‡AGWpe=;*۰Pg]SG';q_dC vFs 9Un[}E"= dYskYxUi6W-;]q 3avM;ty6gwR&PONȀUr6nTX6(';%f駖똢v_b0tv%4Y0LӲ>#v #"NGK%aDВK_X'BB*狰<ވKpd!? xmɁJfKx?o !":Vʚ@EH֗|Ĩx$-@p.JUyw8CGYknKZQX%k$+6 ,-} Is>Zfel~Ж񈊴8Eqs}U\\gZt$Q= ~BD;(Dx{`GIT0*D)R?]H2P؞ƩI` O??s$\Ig㒶?w:]ݯ ])$ ;IhZn=Š'9*QpE{~5Ekr}1tYczm^:yw="$iqj6QoDɘ:PTƫiQ{hϱ,zԢmZOT8x0`FiבTۑ,Ug5j F_0ˌaZ=]",T[ $ M\d bOEX)Uw@+u@{(0EKIpOT#H*BM|PvN8jҶka4R:=R-а0D*] _ %l\C7oz0HU@1{ۤh?&'%x,Ra.q%ڦ_~%־O+bXFI/ _'uJ 4|^Rn7 ̇_vn6F-kvIW"?]B r $=r;T-Xuu­nE.Cմ;_z ؂P _:"&I1:(/:GOL"F{^j1gھi| $ ͟t#U!a M B:8&DG]ǩqLkFrE6gAYY,ڋ564^~W#&eHea%ERba\) qD%Q_s8!(3N+"-*c\]]c7joNb ;^nxrT'fi)yh^k/OGLJ^NHv nqΤD [ǀXXwod Z""<@ðTDlLzi'\C^/OM%SF ͵/w!ВG@O*˭zWі  Z0F%Zk1Hd]P {5(up>j!3c8t;QU?9f{e⚜|NE>_hu.7(t@/ւIB:'ɪ /nI3_dP KfdjFL:bG T,EI]L=WEL姙IVnTvd{7˺3ԔՔ2+Wp3AC⸕V%?_ϵҙ9N,%+aW3[Y81_YQahOT/zPdrtk;17ӳjعւR}gԫ ;@QS|77PqyQ+ulrW\+^ 4e]q< <Ü7 ڦm0M@-^7SbVvCw#c/kfכb3=b3Qؑ ڗH%ņWWajg& 5=k֝xblnHKޝcZo^+ŒLb<r7P?Çv#=֭$9bd\\!bQ"Jxy=!]E&Ϧ9?eDk5 Y7Pgt6 >k=_6Ð̪bn<9DDrK2|?eznir"<] *Ꝡ95]WkܛyXJÓ< J}Hui{{,@LI!shJMk\ c#k$t''] 4Q_]07-䮓kUSQw H4Ƅ6ͣR{ɰ}pVCNx358y!x=lfIM$_cF#ӏegT$)㶲G Y,R&כIbÓIA~T}N1aYDvsvP@E0('i+ftkX.cD v獵47LhnJ ǔjf~YT]9RR_xA[s]`yc}tuV@ąM[ RN #`6(E/ַ>A s|}O΀O[paO_z_ȍP\E D MS*7SbW)vZ{|Ϭ"gW,y8)&sU >A+ؚ31u>&M17EKsc:0`ױj6<ҀN}t)aqRj*sO3[7$dw#ÝmH*te`"ַBmX^ cPS!#">b<LY7:B%k`u>H佋ivRdO8Q˨aW]Lw\~M[` EXK +j|ɤK&Gl"Y50 _Tʼ(Y>tEǸĥܩ1D^&qB0 Iɠ EÎ,DDtWzV;lz7tX*v}0VS-Cݽ)^T~dȦ'T꿣^z[Z'S {+7Jghq#P x2w͡%ixVS`Ih{J[&Y5X@nO\6{Bzr  ґH[zoHUZM4orPRG[V]N 70I [Vň[6߼8b)%UTy&aXQgPs~YϢe!aX2?J!ugpN#n{=)ÁDi#q 5+$j\J͌ZhB:y[N*&32Lw$ B1ȽkQ$N D?ev [WvĢ;$[\s|{l)w">N$ɣRK~V[a;n㻶ma!,¶P\p+yV̡!:G.x9R!7%<x{$ ʑ\!ꪡtmҒ]"Hu ۓS0⺼KK1 \U[:Kyvl4Ol |B;Ӻh0:ZU ǻjob o98폷/~pfz&Ĉ)evb{Hnǃ txoϾS]J4fO3f!K~st_Cg~n&d\ 7LBD:@ϔre1B. +MƐ ^1u;tX+zR`!FLp$s9Yi??P<3KW*Z93^[>w9יnx!A-(>%.~&º1?R£.O4?TNΏXibʵ+ynuI NQӽs{Ge`ü)9Sʠ?. Wg' <<%Vؓ#^2I!DB֪-vdGgp7jPI =2~ ԈuU fH/sO)2*8-&caSX@bIwXVq&NI*l٨`34e8۷SV %(fy8b Tx>JcĪ; !%\܇vR4}ba՞9"PE,kW=R2&rcD`mGw{&&(ek;N}>U0P,¸.?H\edL{e'}4YZ'}%>}z Ma}0rG ~Y{g+ߴ-sl4Ө7H(Kࠠm!SR&B~~˹4xYMmE+{3tIsA(>mmw5\+zha#W` so|`e:g:&$m%7 Hhyb$׸_DyDmŻ?8)].&Nm(dlRC!bm+uUԎf[ȒԒzf'1r ƴ>%6(lI![j-P̑+Y"0؆vBPkN &(fUyN"v 8x}i%Q:rlzg'VI-UE}u 5<ץ#}:W3OTNr(;ٟ͍@1쫺 9N&9a~ L*0/G*`ԗA\|G|!De$;jƽN-ł7el,Zׯܗ3a=LeA}n`䟅crZ1zLƿ;jj ጄ$-/lӗp3)ŏ'p:a4֍EK*$T02cu_S񄬼R18oc1~fF€$􍹜|{+iWQȺ9; Q|SG"%u恔N88kMlG @ 5bdoG'l,dVv )0ٕ@k8 $aҲ&ufKID]I45 W qWմn1mZ%6Ʒ(WU}w/s__J=PMw4D'p|ı! !r{ncxT ;CcWp9ƪKr&-L_y#?-Bj5a4BEl{LwwL] `^W (:Yk,ќ(2)ː`8k8>aU~' aWv7O1U :r b>vVP}ifnZS; 6FؖazJT~d3'c׍6Wh+'l8V8&R'-#v bM˩E y+NgE1Vpިh'1ŭ1;O*_Sm pr`߾`%vsp] bunlШH8zQZf+eg;6vEʘC2`x.0%s:xӋf>CöDMkn/ ,.zE50R1;}V>ϼC>ǘ,%DzݝOp)@`Dx"tLa42Kat AsfqC\}b?#HԷdq ag5:VW9Ey RDkjBRHrsWiּxR O#],  4 #@pP95ҋ p~7!XTGi]9\ܻ8/MA,=*Fz3֐vlZEP.W*7*م]h۬ӝU٪j3YSlsRve@ pŲVu3[1+o)1‵'tSڨ>i"`tMheME>K8R ^ Y!8{\OrSV;BZ:1EjO[3R:BGԘ=]qIiPkF\JV=xNU, <0B%+ %YJ|wqYd$wȡo ^h:APCEfUh᧕4H#rk噏>w8)r5#QjjB~ {FsYZ7$QG!f84K}a r s| P? wZscx?ŕL[B;] JR+X1\\oAd8Fl:B^,m K)@i0@`$4iNwU}n7h~g#??)Nj^,̴N_C~anͭayrTe_;l-w B`=n9''b{M=OWOA*PShhqYOq+kP{ Pw CΡ~v^5]k7|哩grLA\Tjk:CM@U4*茇36ei%2mA>GK ғ_J_F<IX2q& :U>t\'t>gv[jSƃc^6񵑉*ȵ7Hf^hwmj`[[)4\vVJ8{nH?$B[G@zvcp9,#z8IuDIspG"GD'X19iqXo#/ >{SiG=ݟ@q }\e~V»佮W哩 D]ԱC{Pw"oS&n?4?sM |;Y|^<7>h$W#Ka@nvO\lc|4 QOZkPM@0$)u6\L8wCQRHMphqrj34H.5Q)ׂ{e(!?7 MW/PkaB<-{AZJ/fnu^؝2dOÿVΥJIR]hiV w&NX6`RƦW7O#hBR{VoaZ甊~޽oW]j/׺5Jmp/C,ဩQ%a'\plS@zwxg`Ѯ^θjۊ: CtNZ\.Ps.ׁC44-l1cȫ@l.E^˄+yS:FYp-$O[}P,ލLr*\w^Pƺ'Ȯ-$45'"m{r0_]Ś'*I@n t̼AV!(dump[f{Vr,OQ…U 9$/EnakY[ڧM,.!*Q-TWO8G_lHsm۶aÛzf_U @-Om"Uo& wKȣtc鏙K}bvYj$f@+ $ bs0sYpR_}mH 3< o_0+F7cMN޽Q/7W(5B&\lo5W p3֩g~uڸmLԻ cʈu.d6'Wm>S\wD0٭|{+h9)x\Js+EnL !8^Et`@!Z8Օ2֠( d`r8w_(gMı*[/?%M"} $Ң9}8/Jb V'v jF.yjaz$W"BobPDFJQv4+j~Z748!\7$e7/nY3. GX*ugiv#v{>V@5C@mD/3ͣ`dOf >˻-W dpgf.qU*dO#d/ho Ă <̿ S=ivM9Fof~`d$az X\3c+⌻z\bqrݛ -6,En~{|1V:0Ey^!}wگcf:)an uv͌گLLexK"U|lSwN]Hҍخ tl:)`2 ~쉻֬ JCqZamhA ȺҔ_ TQhu5q8% $fVz4vTZ+ bMuJ[L!C ; .C8$UeB_؜*MFUJ0KsR 72uD Wnȍ)j)oռ:n+:.=LƦS][DbYݳHpȟs~mwF\~<72ʴ8]>X$"{2H~i o ~s~_c}kU{g-XP,=pEWeKUg" P@-TLm3池%>'ek.9 bŎp f._Ɛ#T}9dڳ3'|P\Kr+ cHYn \(޺ɺDf sCcA*g[ nzy׀O!A:5w*Rq\P賮0I冥 S%ah'RTӝ% D RsmAV:%瘬a#)3Ϩ\ 7ûGP"uj"ޗƀdꞠMkHm'N7 hZy#<3<:)Hпy ex$tVfKdb.Df< AP2P!cyОn_9܆G+ 7HOp‐/ O!:8f՘'nLGB$ɼ +7Ua!Q!r}zn! k;A)Ԙa苁RF]?5nd/ C '#D Z)mvY-]}d"o0Ÿ$\w>)3+ĔLQׯ =Tf_ԡ^Z@<E`:TY_ރ烫OFe 7ߺin#*jR= qL_NI6!T %GҮA`,I!,l&h 1nHQ m%[k ]Y䁂mϝo\9ٹx Ԇvt=3o3_%؝͊ ],R Չ1_$;5\6_+^[%Xյ!4 :1<~BO-4ʟq{dcGP"qyR [a3Ǧ_x/6;'ˢ}2"wrGg],<9<_i>mB#uT2?QE"|cZ{ȈY;#^x"H0EcvKhvMMs2|qd]HɑnÁJEwnlhʄO:<-!tLatB ҡ)l39Ðaj@ѰftguD/ ~ỒLeeIy9- :D &`SGU`MJ&08HG&pEJ-ZR9=SdKZEIK62fR&eA<Ǯt-1d]) @觡6mZ,5n$J T (o2O{4<=PAr^z#ywYKZIs[HʋN[7'VJ2c볂8BIJEt2qsﱊ+K#L7vy"2)v~9(!K|QCuJ"Mpž-X^׀Mt>l~$&yȲr8!kGQ2_@EM{ƣZS̖3=k$ONv)=QF+{?U:}o]bthyV˂ UCnzFTp8gd|t"wh;p8,xhJG]ash̗vx6 n;1ё?#2C"fEk^;}ԦXa=S` *b)`:pž&~X`?ZL}*q<$d܅#ǧ1Ap䫕[1lH55}k**W-sE\3qb0{S4B!m:ܫk75L^sQNguDdڪO2 98|HO$؟b\ ) ^c\*âIs:J`sF,Ĺ'Xu&_ݣOzRQ{Y٨A*=}5_~a8 &ǐp){ɽLsȌs^K͛N6zK~ɉ:JP縜+-7w 4;sPB%ҤQ'zL qT$P )h$8  Nf6.QoUo Fm9|X/}%Rp;ق7U8Ҋqgm{&yg=9BkJ$pr"zw}qVH-MdXmC q襅pGQl Iܭ\!WYÔ2"itҞJchdj] :ZT[>m˞]LUBumjLD@+Q$R94B$`ǂ1֒ЁL͖S։$ w0IKxU;TӰk] `?m4c/&춬y}vw(Ϟt+k8xR<āiLRr0H zRy?,|s7H)C-ip/'-_ tqm[,ϫG4}Suz{lL|eKyz^h }ЏI.< l݊#=$Z~{ƲpaV!4&>P-UʸWAs0p^Ny9)輆Yl|Aw $tR| 12B$iycD0DϏk79PmD-;l.OGŤgf߄}iiki> 01 cd(&׮_ŇZֶe5[lė 9-n|)Cq3[(`Ҽj0^ⳑ]/o:ZB!0SK,To¢Q|4 CǏAVauZ;cVM?~ C,}o^u%~q1bc${"+^츏{nI $!WM2i*"Gk"ۥ{Xfiva>[S5+-9H)W~*S[Kwc+4- PF>V{[w܊{6u_ūBAq\AHm2N?i;Gt9D*oӲ^I#NSH$2ɓiCO"/ޔ)C^ _.Xfkǵ/_ݶ=/~j-huFթ>QG[C§ I[CJ&a-;na&XֱLVD5aȸoY؁iYUhU1#!dYW-c;/~!}beD0W{8 tWhnƖ)̶se:o)(˶ K䑛~Z&M܅ [D/-7a,ҵ9g9y!PC-7TB 8eZ[AHł_K'_An`2eNYwfA~L4?7#6U^nQqD m ^hKiGk|y\Qٍۚ!"^,>mCSTM:)k1 41:7 wudH1oK?WFHY>@O+"b^HRrO[r0Bn,H$|OaCQdnq3Ix3( (J5Z`݃o3gƓS LQW&kNkMϠ /m3eU Ԛ4,呻wf7u"#Y %vscmFd-R_ulҴ٥5K>^r-o:z驾S B iq|igqXzcp୛ߎVuVʟi[fYyd?(oa{B a0Jy$"lL#k8jXJxB !<]ϼ#*o;8Xra}AP]8&i, PWG8Fq8)]B)W`$BUa"ťU 矜y>= Ь:R9UN^!I轔U`sj!Lg!!)Vk]" :22W;f͹#3+rV[, i?j݀Wr2k҈eGJVa ^_\ʡJnV 痙9q*j9٘r KV/Fׅy|A]<5:Kp7CAx8BebzD$~ҴZ^SzIoJxfǖFbdBcXmAe—>4yS3=خXj5`wJ+.Z:f C9ϮjoAIoH*o?rХyE*YJP5uED+ߦ:PB;(=+t)#dmsK%uUud(NW1p`/34YDԋvhQJ{zk8? h{Iѥ6V}ΑSFSQ`0DeOz"AL j}B~=+Am}|Y70Ƭ\`&J0NE/!1`T19[ZaRݽG(FAdsKC\*kM4ڵC\޻ۯI>Wu iT2ƌ-*]~sv}$U*lI.kfd>Ϲ0}HfuGcɧ"y7ƌ%ճk*{Ąyr*熼^<h6=O 7reٯ1[9Ab"b V[_k(^0~)OeIvE{H*xji;_H t.DZbOf3(j]ZšUY޲B%2FƂkIP_k]#5OPhˠNXJW:h3erq,5<Ԅ]_`OC50VoLQti&y }1iܑ w.|(D3o*Yb*y i&ȼ"&!BSSЀ?TW$5\;LQq(X]E.mӎ;sydҚy{`xM&ueZ$Sz.S6-gnR\g9ab@zb[y)n9 s|m=AY+4THG<29Pٌwn'=RՐ~QBX.lД-Att:O蛵P ~Rڥ[~V//}I0ur{{ i{.QcGA2džmf2ހ?YWo k{|?JөG, &VZ W[駎e^mҽaIIbd"x- mم ʵ8B, "|9nZg{o2akB_C%9 ˂V*9[Qi fG]E˯X.\Df^g'>-o?+qP k^"K@ШMa,Ņdto8: AEpa ,zdѲ}L͛S5urfh@nh!1F5m7>N NW x/5rZ(>$с c=nFvo=Bwi_AC¾ᕻhXJB6\5NLLSw=[94K8e6ݢ7wJȩeLa ;POQ|7Dڱa #>Kf2,;?V kD>N7arg5[X#:s 39R{mB@>+.W@b~N/kOZZ}/&b)lxt~M^q]+DVs48{ m[Έn눥Ϟ OěaM;ɮH|ȳH%KQ'ʾV]YT^6q.ZcMAjhv_NI6g*o9lYڑ5{2oEtO. RYYxڡh_yc0g𛱲2EpEf[`"\AqXOgJ`1& ",|PfyԌ0o &пoXq`e~ۭ8>PX2 V''8, 7CrfgCCHG\ 7j-R:v-/Ru܌-5l 0,d)q YIZj5׌ZCc'G[P|!矪4Wk}kvH-. cijE`WIl/^ӯOѲHZU-[|U'к7MgTEDĘWA}aMm6iTA уL,UO&$eR+<0釅+҅2͂FFąМH钴L!Wchf,Ư@&uZṭ@5W 1_,̷Byžyσ~óЀ&ڋ7~Ϻ9%ޜ<~ZcК a"s=S訧z8t8aD|{*i흎^ȫ# 8lUB0xg:O^rXCby_bB)/H*epCxDCsphh'.:b; )8C~c;R+WWPcL2'`Zd3mRS/' \a7箴g=7x?}6d:M.a5?dƃ|1k}jE KMZ͆/k f1H 97KEd}Fڍ;|+Hc $kyRHx 6_sdJ’ NC쭂c^K\- /bGRZ& y^Sd`OdV6}[ ?'e${m'LQ=猁!!T9RK>䜚Fvś˰2<.ůRQZ(RO)"MұrS^ɘDDŽIg4Ogd&C_1PYoXN !mX* #ALΆ,zlLw@?߼{7I ۫heGUFKAKgX M;wh-cJq@0]!"M㍐G׳'wOV A9Y0drZll~1hOx؆s6wbZC%Z1?O.U/Ҽ f8ߙDl]1Jj)TVr8f;'&Y/,g:ҵ$o9 $ɯ\zR5M1UrC{&Z OMz+\՛Bv)X;«6[%$#̵Bk@diօɣmeqY> C@[RW x"CF/|Um2 l,f>5a~e\KG"@{O XJWl-x[=[u񦰊T /ƒK(~^}MažmkۑFתB%8DzQ$"^*5ssjNQ"VleRNL"lGDQ=2zw2,IW~N wcUfu΃TWh @\.YQ4lЬmnts09g6Zd<ln/( ˵Z!3Ϊb24'OiH<d߀dBB24;5nGɚ5G,j̪?%p? E oQ<3Oe,|k'wđI+v-)DaSU@SؗcŲtbp71jBV5Z?Nh$ 4]=׺L-m=-l%*uK֦;_[k#3a'%N} x;ELQ|$M{li>uw4Ұ׸yK<1wv"X2N@p],O- {}? eM5)5 ̇m}&|~(Qqj8 \J8P͖{۲55[~X4:D;~_X^&^Q ]p S> f.(@X4Xdܳ{Kpo.XȮ$] dY)|чLvs· fxQSvL "E;P<-lت8t# ||dSD3R1`wHBzYMT]|Dӿ20caQk_K]`gy'!BylYa*\7 or责œbtCڶJJKx̌m] 1}08S[WAI-` #O1ׁET1=A'|reh}"'B8 ~ї[u@jD~\dT[n;R`Z.I3Ӱ2>\;3Y ]DtqӢ aA25KEcW8Ww֝W"`A튧9%Vy FjSKAZ}֯:ug[$P#%YK(#MOevoaw3."A,_7 ÷2ZXq%3:'G'Ds^*P W@VB1\w3mɂ,GstžZehP+v s\f0Nc[0.5Ȓ22 i]VUEUyhQ2(]d@kDF*?^!'rRIw@/-!Xfoc^t%.%3Tx=׵ 唼[O>j!_%hhZȑۯ&a䣅 c^ mJpl`9R $ڐo{ uITCB% ybyʵ$pUv0}% aWs<8%Zlb A( qd{\r'F"C(z=N]LLB!TfSM鬲5dZFL]3K+hRYa.Q.GI@,[@]n㍰=+궘rɇK}gi}_B.wTdYuz J EQΆ @+!l“Ś`әvr266'ɔyt?#3Ǯ#Y;wOd>(a(5$䂴b͋4E<ØCGRO$fZ=Pb OrqEVl<}m!%͚1=˲A7d(LJCOQZYo%-z-xs+)TCu&TDQ}py^ΙyՖPɪ2I@ʪr6 uLg%fjm;pΠ2ps=[Dl1N/͔y_!KTaמ=|6xUJz9և*mz.L`ݪ /IJKo":>X,]"n/Ascl #WuwʶGb+ie8)Qgj-V5ga**A޴  x`=b6jgiCX۝IguLϛ#W)^FRt& 4-ћeƘlQSoLxƖ`MF4ֿ|6zUбeߍsB]LJPZoR`]tG)X(#G_j U8V[`/}y]:F5Lx"lHv-5t#T,VS[bZZ"t'ΉE iK7![Klh(ev8G@y>a^pT`z Nv=H@JeDjjaguMtsh2 $D4rR@hCQQ-  Qi:#g 0~$D2Kqq`P5i,~fͭ]Љ&%!'.ԶUcu47a0pcyZzˮT@XCU?}3ulk5Э]i+2u)PjPp۞=%twR% ノk?E" V{ 1dm-5x/VMBJ ̊&XGh,ΰXM su.rA]@ ~ojO{ #^[}S)9U5H) ѺQO_ʇ_}f#$dP.60H;z| Sv/hH$-&i*Q]vZgBMF |4zrt)1Rf+9TQLaV}o>h 6*QLgi߲D[*KNGruxK! `xy`bcyeك֛? ̦)BOwAAMNkwϬڥ!)Wf xf8:(@ۢ! ]V wTmy%QKc.SԛU!FiSl- Qzzck&d _t&48{Fpixd2տ?/*J.P lh7Z6ݝ@asCЬ]<%&=aT14O1rAw.pъVOUßzbe}FT^'Z|-$1sVx]MqL5BnqLy;(D` Yw &tx&4@4֬h0P +4OdLjܬA#'~zG6i)=.(Y5LܰÛ>8G>,u3DDJ>$=;k/hX4CAG,V/UdWȹyp杪l ý+' lՑݼ{Tְ*W ¶]#&]K9+9=G*9+[w2uЗ4_+fN"^^~xc u'dllକfP+`8Q:זONv,r~$␝{OuArN8',P`ZÊM9hC&D2uL S L(ֻWxZ vq|FDɯ8ɱ,Y%0NoZQs#`$C%7 S|Y5шjp[zG܌W5L1h"6(--V>3vHJ5|S&LQUFΣJzz!c`{d:rYOf#w̐t)e"$p ,#VNZ`h!@t?Uxў [:q"ڔB ?+7%a\ U{=b5fq"CSp].'ͼ =폓oc*2<>J01ESݬOEk ItO πRDkBg}qm}Hj*w1HkI6Mqï +5(#Mн^DOø`5t߼=J^#ѕӶljE]߆:t~ .9|< gyM.)Qu1:|<j=uHZ IpcTVAܗ^P&g1+Wcs ܇fGY,_ m].rOn(R 4Wz+Nts{-I7+v1A~sq#]%k;[2lY+B"mJa;xG6j$/*WQ|RwBI4~8Qde͝ZrkS )1ֻ'H j݂wWM֒MR?fk~ q!UB4:z䷫k%q9}uOnEUyơ*]dz e :; 7F!kp|.4LF]ŵ,ESGqƁIUI$OxيX[R1lm(;p\ MRmdL72(~ !?ʽFh9܄51O N1a{ 8j0[70Q0r'ݎNxctQq>+Z@2l-r'`98.^^~ yל C[Rvώ8CRrc_W!O*{vɈ䓳_US=}.G]m m&}18F#9ބ\/&C"BJ?"QAgU2!Q{ 8/٤ql({xjYF-r ݑ!(uG)6"o%twĉ%ӆ%^m~ծ{.=v=[! γXbv7 ,|Y,~-}IB{sXXNE)W MJ7xa|jnwpjjGBv' (Ćk髭4#@P&KF$L-Tu߮]y(L+-b #o UK Li&ÙSi>Jy"DZF.CwQ;a:0_:us!>Cg [S|g΍pUqx >_mZ)=/M^UsNKvGqNOjQ:~(EewhH*];ZY^8 {n8H#G~tjy N&BZSX7)mE.W`$aavf ]ι.ej\G[s$GhgrM7NgLߴzO i=/X[q|]~P(,sw|da|F(*~P(t0CI3u+,S8o/|O82Kӏ/ äu Y}F=uFc4 5/eM<0_Vs=Na;2dmK)yTߤo@OI:4_F|;7Bޜ5jgfӐ snǂ=M{`}ZПp{)hu\ {M605*q93҇pJ( ?{$0{b3ʨ _m1Z}xTntډRw+Zwyp/v,o6M"2dv&^GfQ `T7.Y'ݮsPߑF:L*(ifJ  ũɊH2>t+CLc(X>^JbYdM$}H,3bPz T9ꇽg%=Dȴ֝̏"xmВKw"gC..#}Wl.PT!Qhu7=En3u]NXZF/I} (L"5,B` qmu[Vu|,5+wS{>(:0~`.P Hjko8]t{!Aa]?w$C+4} "]A6JȻ6ոE7sq?i fd]ƾbyT揶\Dy鴩0EubcC)i!%f5ك*9zHXQ5 .#ِ[.x6: K sv1s!`Ol~uHmKalbpcQ[[3C@U=@"Ve )ҖݠzL԰߰D#oJxB AkqӤu53z UϧmLN B=>allGo"Etgר,0jNnX|7_rf>ȰvU1WBayAK9tFn/H F63SH/h˫*.p߆FLQJ5`QoH< ͼuз|t K̻5GyqYyvYҒ-q1s;cόy[]쮏mIC_3o>Ռ@&ؗ3Vxb #o)HN !T/`p+q?s"MtS[$7'K_51UJ\l-Ss?tʝbY54Y 6b?VL&_z6eKE]rk51<4=EJVf2I wj5Bݣ sa꽺ZWJ5t-+53C[/ervFӧn:m ڌD?pU>.I֋XQrq*߇.k؜Ԃ%N iảo.O@X8w?[kIel\:֑AQqH@Sj'Ha{8 bPI+!)8 2y 5GYqY[뽔fh2x&B Q&3b>^RmwuGǝõ3@5Bb#kHo !)S%u!g39-]vX;aP[Pf46#d2|dW.-EE#:="}g/g`9ՇrJLT *Nv؜ ^]Be82xsc+@,REY{҇'M\km8WmqX#hqo_0]QCbnf]ynrC\cf3s wV\BjȽ_V"~?aC+%UYU 1Jvx|R=}\b|`\qC5Y:? |G Na~P$~~Q'+WAc!Vfgo !tp$+*;؊c"B{ eS'f~Д4hGub{iTAGçlM4i-ΉblQ0>~v.ĸK}^l1qR1SRZo=Z8 (&HS."EljD 'O^!ԟ6PgIk)h8j :TNx_/BF)fNzpS) !&1*J&B>V:W^Bl`;ܞ6VF~y.I1.H{C..58k Ҏ .b15b0 `n#?J뽋xMaybxc2F]ZWJ?1,Pbhfw1.{}xDvfCY4eٳyX {S@HUѴ'ٲHš) J@rĆ<rOdWY*2%ۭ(B:#H +WT>2E $g0L};e@X, hxSȆ>,-re:"~ԛ/NA韝iz&)Oa\G"LPGC~Oa X.نF(Kmpp)컨wܾ09p 37/OkJE& +#-Jd^3(';[`l=PA: u5d_kZ,{q_>z : Ajq#/bGV?C[8QBXw?Ld`SjԎs(3[9,Gdy V~1=Щ)Kշ$: 11.,?Uk2@-X`ё;P7/dr!b= ܒiR?ѐ)2t" 1a{Z!$d#~Ho7 OK_uJV*( DY0Wpaffs`x=Q ,}Twȇډt(&Kzƀd m)o3`pT2)=.I4P]ت-QsLVZfxow4䓷ȖP W8^*ZžtZrd jqH&d4G(dbJp؄W ٰl{f|ZڀV$C*QĊrEk8:ǁp^gՌdãw$I0ws @RD~)`cqBUs]#賦swao<@w%5ICߗJ./BeqqT/^2Jokڃh?۰0rCgR5o[Rss1dX faxB%+'4YXsQy$7WC'j̋7TrMdܬA~qψYR- :d]nK`(*JLlLu{=.\Џ ڥyscf9y;p.h6I{:RXLw cR&6c%R 5ڦRE[p0ξqBJv!0YCGtUf;seQ-2^(% }b{J  p $BxUb;Nlq2:T1=0(dW#vܮVq k~Bjе,_Dʼn".%.p'K&r._SN,- Mu*|"%X)$h=]X}B ЙGyQq!vJY`[m&sbj &J&?'.$ 劜m bsOc]rVpޔGz5 D2aXA F(ɵ 7eqDD#).ϒOfv)/Nshw.bLI@|IP6P_Ă$MH{TŻI<cxيZ|61ݣbp1"=ؤ !)[@6kZ.r&.[_s[Suj` I˲w|0|(d{ݼKL|V.b%ڬEJ,i$iD//T.4`AYA+CiՅGd].⿈`ۂ>c$xm'<U[?:-AxNwP,6]a)dҞ D=gOlHSkwvt4Hxj`a&`0]( ԸN <{HMl/%̸mv)t^$w͸#FY`-2G%J#({tt֔,9Pry0}lfI?x̥X#;Gɹ|4_~W=”E&4$?f@3_ɨ*c&9K ]}t1oS~oydXVO.Zk,I.`IU_;B4Š:z8NO63nT 1f'Ոwk|KzK8Ljh(&Ul9Vx# w.X}ťڮFD3of@1~rUsX'LdŽD0{ĆfџѱXQ&AYy?9 uœ<r-6|An9=km>\? jT1H?RPCD \T%࢜ՌV " jaQ6X3(}6U@VrfGr4sQ )%]dcmN}߯PuwjNʮĥV|i^t c_xsI &]SprߣA ԎF`T ^R/2'ޟI8o |`<ׄKUY1$FO"2I|˾+'ZBӫG7h~QڊOyQ3-=WՖ<R BǶQ{YWOl7[+R/09W =*{-e%ʩ&kROkJv07c~O޳|g8Y`OJ6<3.%ւ'9A-kUC;rSUG,8'i:nK$jΔZBhr!lU?BRJT-,]]Y iXN_`G-]H,n";WnO`\H8E(ɋiAM=p7!֧&ŀz#e`h6 ~۔r@ʅ.aԷN"r9aʾM؃ك6t/RjY`z*`=eE9*w֠چK.wG[1.6UӠQ!UkR&@|0N] 8 ‡ș]x1u9Z?UZ^YzW7;#$1e+zZ ׺fxq|5/ 9Xܝ!>NXEd)r&KӇիyκ$>"{\_P.52H'ژ -TN%=X1NWC+,ez= a z* l~2W3u3yXLM8{p8*y1z[~fZnX[8}*5+biѼ5Qݯq!=P]}]Qawȴ}t< %X[Yp>HkT-iҭ""z@5ddy,sQ8l[{N}|}B`uJDol0ȺD8=]1 hUL80Fi:&\ +Iᨹ2BFRg ;D~9p ~mHۑ` W넌<lh;lEbwFbo?ݶa,b*;56c֫RV B{!Lg$?㼑NZi'B݂HpfJ:.cZoxH)SdL Z?/G(4v ,{!RnyjM. W ƷmVJz&L <=Mj<(U,cZz3{>3zhFp7PN|ob≐ᾊܩ͡qzMu_ ?W-H}J"'2]n뚽Ky~8o^(ѷ#PK#g^[9;ˎŤħ9 ػ_&%=nD$hϙWv;YPhKZo|*GDfB%cZNL<;DKB8? uKw!p `GPGVCGgAQdRhw1RMo _8\DJg o Fmy~m昕3+vDZ{/g*q#($XA}O .]&lPo #Q{3t^;l2qMR}pZEߋ&Qk5o;TZށ^<*^wr 6v1-4]*?nr}@Ni r<ރQXi,P8oq":\`@J[s`j,Ed)<A7̲{4 $cIfjkV6kD #.UtxU=@hJ4桰(dM=\MwJTl1(3f0gqZ]Bfqۊ[ꅆyR5;w^e>iDA޴6.FHkV .#`~E0$ٰ T4׌r \WT9;2\Op ]Z鰰8 ۧxRqo x-w}GI)f)yZ$M]UMii*|*Ji˳*.[@#ºu qb 'dBm/f!7ЃnOV!z^>_\dsl=>Ρr)5D)`-)ܙ6.󦥚!T-ԅVIɱ8UJf `s:?$-FKa%χy@\{T܅v •cYРet*ۊp?߼J@jIYu`|}W_cPHd ^ӝ%]^2<|P[{]#:{ #tݝS]Xf]Hׇ=3?Tؑj΀61Kyy%D6R[dH[ɟU&T?ͦNXb dWs[}5Ϋ1ṁZtg2̖UѢdJ 6!Z nʱ ںBSY|a7p8c¥%bN'_p0F1,ߥˤ$9ulId#cHRJWso=T:рlGM6/9{67ˤ<*#ʶwWѫ}=/g=vQv3)05G=ʅ3Q]A2Oqg)%R'CTP^'LЍIj ![ 1~/g97WND]4$7VK/Ħ5fwH8O/ ~Z2Z )px}W"mWY4c$T1N(QE<5 `,E]י; x-QߞB˕Ni0I>PLV!ͳK(=7_LAl!Mkbt $H>rG,Y0|lCD/Z} [#˫Mчq ?ٌ"Ht9ʑ$-h)sBֵVBO+I2[$N眼%c+湃ix'o49;&z_ɑ.bT79J藗`(x|%\gމD{ˠV-SD<yGFq#}̙ o1g~?"g$2T5W<U  ZGB'SE0@|IPkm^\- Ln7g%V-KqX%u.ZBD|!ƿJ d^`9 9SV#VmS/cJhxsCQg-(N1M0[|^qG}wOsBSE'QEhK >:`e=:k&ܙ pA(i#H#&p@t`GbZ̃a⸅OŸA#G1*]u(?nі9h g<ꐯ 獘aV_8{z E/uoQWh;@k2-HYTk ND}>{C=nf?j1'x ^kϨWM My߸L!|84-`VU.~I sGw?F+) 1`h&2 qşvm!.M0Ie,D!xV%5@Ha`Wu -32}'ǯֆHGm>mc9[ t>R_z~t@~ =շOO0Vndaw* N^U,SzN)XgЊf$x9JczնA}.,|?:z Deeg!Po~1{,xE@zQFa/sV*!ZPBM|F_>4v%ggcGn9(VPcю/)_ j}HOr@,, EE{+m~EB5c~HD+^e廊V:j:!t p.t9Tӈ e{etI be/t2Zo0؟bbŪ޴Rx``E#X Vh͇89?'BOJrnCxCÂK]_a,nވ 8_8K)ûđսbo^I5:Ϡo$ ra Si`Iˤc}$#>W2SZtLPY}H8 g4h%[ ,IzaJ2zMw*/ EEfuDDm8#Hgaq3alfbxʒK.hOh.*u?ꈴzR/CA5`u&Z|_b#u͛dOkđ\qKh%Ɇ̔>7ڜg[VtԕfqځL]y+Lm#Q O8=ӥap4e[(Ce[D^*B]=,)[H{'YR5'&7I_x5+G-,ĕ X0PgBϚXAdG\*@qPױ:ۄ(Ql}=kYoEI1 e*?|uUd͋7Sc4G RkncRu .Z`Mݶ,rLRXLw2Ғ ׂ1 ]o*KqXu\TK6֤CdH"wԚqٟWܴ='-$)1&z-d AXu4M:!ᰯ][A:psy6RɎ 1Ҩ5q/ϼSY~*FI3)XO#2 /0IҷH hfk KfKѐ,Du lnQ{XGR)-+"Zct<9YRS@j=byU-SS WO#̺AY0rc4ubM,d캼R+ޯ" jTݚX^A!gH*n_V]3Ră;H @.m,-:,vn.wSݾS"*c@51@(z ^N^@[`[aUa#zv54S+dQ|{`>~oO[1`[(Ʌ\n8 VieqԠ/m{ynD Э,$Ǵǩ{W'HL%( _bܖ|w+t^!;U&2]g@Y  NnصׄK#9]sev|h7Oc:ˏor$lÀTq֥,?/YyY[D N]!$t,02IOzK9 aL"? Hhusj[fNV=7QsF $Sxr:q✶xKWhLiu¯QT]pFxicmte(5CjUp~tڐ c\) XW)AJpa< 2"HNd XWЋ#Mta{ +sLKabG5 e1s| >nǞxF-5p5g6KwlgH5G}s) 3}1蛁Rm$@fS1+n jJ|/iuF=^;3)8gp>]LN>$Ŵ5ijz_ g 8vߎo̢{JD;i`A&`&,&ĭH{\[%*"Z>A:i[/"߲5L$m +0'};.DWא 9jٞ]KC'V6J.A\ZsE x%=ZW8yʧM(`Yn"{:<`CO2n$%3yMV̀3%\KM.Pdp1@n؅p/01'  ^[ß&%On a[VEMw{ B7 =Fsxt.Yy+ kl\CgY,[~ISiE-{HKtB Ɲמ9'nNH=PEiC2Z2T V!bdg}d`qɿʕLh:KA*ojƀ# N=؊QN)ӁsBgKZR~)kk{k 46%T8`x4ъq.YT9/*(FOy2"< TΪ1`'+8 Iw/žX4JjFJqbDǙfJTf֏ MN˺SsEb3/1c-}2vsRun2yŽ&EԌp zP"泗*d\Xp:hel"חx6eOom}lUn+#斚w TK!YH:@RgNgVγ6 HYM_۝ "پLP'EIA8o; ܜ$1,n'm=V7|TIC{xKmf@R#NX@x䝭NMtx_xѝ;"Mt ~`~C ~Ή;]f7^QIxۀLkWsco طh ؟G6?0w$6\ $1$S ಔ3VXxKa)`i,LйLVhW.F "=릇mмxYS4/ș+'3O 0 L++IXfH E*:.HKwU\?Ϟ%ӌ ŞUmg}".~Crfyhs+ozw K~Xa2i '8տpY PGGNܚFb7Jf1c"q?N oGh{N,KR {h{.JW3LNF2<ߜLGoD 1Oh5%sj;"9ͺNqkPIH (3Hu`YMTpE LE][TĕO kcs^Y7}'ďiP*1z~9xG0y\:&ΐe37?K VV^E]8CHZ5Rt%$>|`1кv!C:n$[ sB uvAe6Pc*yV7dhӞs9CqߞA9O 9r~Fg[59Pup?k~A :|pɷЄzJd.aܢ8FEC#PFxKJ {*iX.:NuZ/4.FMW/=|E>Z6Lo1j8jۛV\0Դ8m$>nƚ4h|iOrXOy@?Th 'b)Tؼ1!ˉO >#7f#d "Em}&ePS Qx( 1n%S4ҹ@㝻 P@qy/ewUjKHfjҎdC Fwz\eC&pgRpHCF']yeL6MyPuNz/GrI~ =pccDڟB 'A, 9txœY YD&&hp7hi.[k-h{mvE:GΣ?SCr_zha@Tq&5 K|;R(ͺ'SY"-4_I+[5CDODUw:^U*2Ơ85XQEnfLm+cb%= Ifmak`HZqWy /WvS0A0 [[# " [&('OǩԕOЦ qN`Jrè.Z!k2dJtTN /K4iRFEGbYdfmY[$Qj\Umvg^ЃCİ6{p#rmOu{JV^㮕my'-$32/2>'pM-+@r~ǰQ8 ԺxS۸S9j8 R8ō3v־Z׎̒!yIȅkZ VAګiNJmvZt+wuH胅 M$OGB;YaURȢO lW6BآHo<0pFv k=pVE}9{k]ŝs.Ccx}z'D=u7K5FKf3gU;5J!cTp>vӎğ`An󳔌 M@;dQvʹEGj{O|\85xL}g0 ѸÎ",(Fr)6Ւ"r{!ڿ~:oeQjL|WgcjIҙai|JQ~v΃h xy=xʾp$PJNI.Ctu0n<TNMᰬcCǸ %CN_ԁ0NV\j\!f iTēurxQePvz?/Xj^g'(_%v#2z OƉ2f6:|s&+i5MT9_[=V4'~߉>ÒBld9V6 ^5]+/1g&n@&T}V< ([麁ʮI57'!^Hy>oa<ںEZi%dܶB-V0Ab,ke6Z~PZ ,CuoR}*_="W&5ڊ/b\/"H3rjٴ B$-'to{'\5n\0S@ϗI>wUdIj[2a0'@4@Zj3`գkt4^\0LTᵤcTB1c"5?<B]5[9G@ `Kk_,\G,ꄱW~b<:串~уåz$MIc@,ȟ$1%G#1\GoB?zԔbu1s?NAi{š$4;֧vMt/忹aAUS'cDO5yec᪒^[av1wkrz '{jz zDA۾z|os>Z(zW؜L]󈃀hUHL&<:CB-*'d+r"j )l:p|{W)KXH&^MUX>3FTEdfwn\>QsQ+XGnhbAP/ҹLp1b1qZl09CJ-(czal-%[oJE_?VFɗ8x]rCWlBI.lx𑭸FtVsy&>nұJ2HTojjlCvCyZeeib ДxiC5\vN ;Yʰ^iDf^4i*=;)ɞQm<pK(qULA< /BupQ$FwӛNg`FsVg VkT,|8ـ-F8 _V~l~Nji;5HZ£*/0BI8pSÅ3/,ԛ0 Ib|гx*d-->sW+#ΪYL =D1nTWT}|:p$a]a=?/,9v+#ˡcp R`NὊͅk4=F8#-t**՞>7fT*^65יpLrYS؛9Z?7֢vp,v3R泲?l{TV ;OU1swu88p`n/G̃]e9 })SBi9dW2ȝ V"ܺ|V԰ƽcpS6|-fƃ/+׺34a AMe;!W}bZ*[޽Vϟ+kPslHom)D@eW!UvԶOLڝ֓P$ ,ʜHso 6c"Dv)ݢ9l2 뿯@b܋;5"H;W׶Ź8.r`f.&i ,J$ bzrHT<7Bh! EPatl!EG[c/gBmWƊa\ZhKYya5@֎] P62`a_i\duxBBmgGGE3 u{4gDzBwNVc8 V>[3B873*\ǦgvtICuSlnDVu~?ρU yǩ\*ރ8j8C|] oR)WGʴAqjvN&6 #kNiF3kcun\yBdR: Lu+}ظK!\.fm}*k:y;y[iM;*gaAO}+-*s9dY._Z~ޥPl6Q!Ɖ`>nWH\]G\U=8JKB"6Vy˕ˤbe }]Kfx%Zllbڪ}#SwbCm:$̠Wkp;ӮB_X-ދ . #SԻ?#(b~?wlN2~j~qj^2I}m0hɅG;Uk/yϥ=!nTLvLϮb̑a h0i2M>I#שӼMvL1 2#650FtO 9dW*w{3ոNIf̨{;| Ô'[$Iǝ{"^w_+#u9Qz)>|F͢[aI}Gm5ې4ZH+|]Tf'J`?Wa>m&~or@y`.6'wZyIl+T]䘦p禫ꭊJ57Q!+ѬBrUvf愿OJ*o~v_{V̹,@V0OAN\UmʠD bQ“]x0a0s d KB2rS>L鐅.#PGѫ8nz*@zJ'y=ɭO_Qef(AVxRQn_7p%0<ˁ2Y S[]Ska\NAI3Uy'h4闸BYgtؠ*dV-9(H3LΗj6a 5EQ(s]B'Aѥ|$PŶ+"Hz{,Gv>@|#.xdjA|ozkK,$яcӵNa=%єikfxO#vhbʄ*|FtH n܋*cU' w퀘@sD=21F\ٽ.Uőe?RĈMbuVzĠ#V9͜.e,.U/{+xh >zʘ)V%{3j(G?fɟ} `!/3Zd"v1LpM|~:YE:-[d72HO:R8!? ,)ge_s']0d&}Ra9́YNrhP4K&fFKLD^.6#3&kXhvms@n5݌#!gS[Md̑nxF佐a:ֻ0:` h $'( x\awdQbnU+$ U1ih?BYRgQJk<LMIKׯ}ST;df^4giAS[g Z;RI+UƼ}h`Bzltp҄ u+Y݆pT4oxWˀ ,IAA6 .Ʌwܽ @l]_k}W@$YNĻRPȬ'BU<)3o(爄Qq/la91XB9~dCyl^D>gs,GMB!u,`mz7ʡAMjfvWN 2Lz sE ".?~ +KO4y*wnuAYa@@2,ဪ!|;!=ў' 5K +:PUȟ[Ix*IG]YF086# :D/ކ,8l|PiWW:~58.W ~|7:ST/Rs%e*!h\*X|*Ǧ< ο1? `ƽQ_r J"0f}i{GPL;5[N AZSy.3v\4(U^XӐ V) rFEfux[Kcu3]+ǽzMb J`Nuve?lhQMr:֤f@s[EIe6a޾| ^Q'S-dT _ ^zV&4-a'읦GG*_V+d#͋pex/-f2?MZ3f- '~J}P~;ޭ jup ap4ƈh^$;߻4҂L#^aaV{|~;8!ljV>#* $AC-`'V>twХ=> .f]TP+r?K_OjWY5 V@Db;2Ź|Ʊ}ϗ!dʦQ0=Mp) U jYA/. @b$F}D6:Z ޸0s%U-+H\T *vY HK[)3Z͎{WTTPYˑsJ%8$-QSfRF˜"a_FSl7~0^ #H#cez`lT Ƿ \ ''R%ݷ$XF"%΁Jt5%jmа>7S/ݽ{?,aEg LRONn TX:aFX?Ո5My5{]k٧YzTAPI\:"<f+׳*x>r, j܄7gZ.!vaVͤعOyL?A|׽i/LsY\yq4ih|!2slEl7-!"fN$4G G(m>Mԟ\q&(.4#IYD^L~me9))%׊~C٨ː\z4JøuґҼ.p۷RI&²pN{^E"33 M$9-D8mrD Z~OIA$;OQK[&y~f "TIѱJt)҂"Zի\A9ό T-u|mIeã,W7]I݆+}]F]$KEfɎ^M(b| cZg,}-v<, =-D)r4ТD_H$,vqQiH-<`\!v0|n- } 1M_6uGhn&j#[x8\5'2\wL| ;/1[Ӻ7@BeL:NߴBf<ɂ%mns7G h zx8jG$7Z?qvPcK}-N =˥Zj߷ xp;Ě{ m-ܦ A |eܰYFJɏb~Vfyr.cj;lTOooL2#&dQHLH+0qڹg|*'u%."/RήaԖ=UI] DBoKo$"iMhvd&GI߮0mcO5ݳ4}T<==Ip}f=-lRo2[{uY{=|HISA]|Zc%03R䔿GVslj`Tuܒy|!@\XKک \=],&hhN.QXC@ga2ՉVq@Jo 9 {m#. َaB\t,]KQeťBfZv~ْ$Jc4w.Cke!z L#nR1F  u vh 6Bv7[ Rhyzë yh^ךzax5hB'02mՕ2U]z>eyyߘewmv3AwUKL '@c]ۚTGw}2Bakgr2T7`?/F'mq 6SG$B cf2,efjni/sn'ujӀL9N&@Uaa&we[K^zH*bfڝ(m|N\B;'xӒw44R{J4% {6"l--ѭC[Rv|a1Pp>08+H&…`  a_s."݂^M{$ףpVKɛvX|yxyâp7bjn^moQ_ɃqY%Cg+xtTu9Ó[Em2N/ BJF_Nmpݵ /ːNVGDPMCG-Nb!*D=} S qwHYכX UHE,B_3ק8ֱhx w0|m!bn `q ܤJ7VX2 JܚqF`YΌ  sbԿ%gLw "1ׁثlˠ )ooa.w [ˆkie¼z)]G֮ӂquG9p XEN;OVL|TC…!DNCFM{EukhyCNۻi_ Ea$jwcDAC""9R&@L<XY;Pf; _pم d1yD]OY҉oǫ߹kV۝VA:\%vH;GYR K6*s*dk"WL+r*Cy%_07 r׀ k a=73Ӗkoa+iz-',(LG.E-|XW94uӸGcn *˜֒"x:[GCC8ʦPW&U*m" BbjR;惷>mygn&7,Tl`Bg[ 4~ KY8US{_6t%/Ńj43n]eiă3ri1F4?B])1bБ!|+={Sdo:EFagg׬}ž9 1AuMJ4J{*{mRRRǼdi7,<l' O4$Iqb\ʍ@'%ehLJpƜ3 \B_VkFG4O;jB>۔?T QjMSk4٤DmpxY+r@K's`::B(t:J Ai(rK\V蕾iΐl>Hx~z-qkH_+4=/xq)ȱbPej5{]C݇oL!Γ^0%LxXI;͑P˲E T,E=J,i]?>G PAd)h]MsU/[~bZlH_}R`SS,|w#P}He>`$m=/!9hyY7JyNXwks0,H;h)c6z`s%zW^/Ճ-,E) BᦄxhV;`gC 9*|bE/)6sd\][M}Z#~mS9y>|$63'y> T:]6 2{ĉ73HvZ U1w?Q"m5Wp_پGa!-喢P h1_>Yrw/kDP ^*^=DJ:ڿѧ8-u\p[U%Ȼ_-]U!^hK]Zufxg^ndN8Pn5O^qIbp_0\D^֧f4{,E)Tx>/'0Aw5(c0gk9e$&,d5α9Rf64H{&ߜRrz ـ6 =S~[؁ӆN##plX7{Z򰟗 2֥DVoacZHsw1Fxҡ-Xdh xJ3S%/]ZϾ@rh#i(*h-dMR/P1+olΌwbN&5'~Yi sa͙?Wu`TK2)#^gƢ YoWgRYt+C'6{m?r7'htw[-@}6ĤaQ\&1|. wD-ÖTw _cv. KCkD}MO>~^;zG/,%8k]xPjbҴY 䣗"e2.\:rwɔH].Kv ^`jۆ,S}oC.eȁ'ݳ9WA"d9 X"!dSwQS Ab=nGMR-1k+:e6IdnHp&FKR`IG#uK4= OvO |i~1^|v3bz-|h6gDd0E JKCbT g!h" dhƜ(> 5J ,_wv&_T&69v* L5^yξ@PRJE)[e1Ost6j ՎR`wwV(;d*!=1 {qx| lHt,i e24X.0p7b _6.Fr1(3 8Wl]%Wo? c85²dq:JrhR /x6dY5Еܿ(wkD[PxՊD7!Yi~Fl]IuiK:EMOW?Pj<g60.N%"u/,ؼC՗xBI4!F'' lqwMvAxX@dfr\y}'ŅtxdhaFMG/ǵ%7瞧YdUA] {,KIql $k&Tdbd2x!^ݔyR!12^Z))izW NAqfD[W;]sc7l3ݮ« KI ]!S_ϛӁ\h]̵U"|.s-%7~S=wT>[5<6I")<>Ihc;z(Ea_lSRNf~&*Q=f)k2+f+i+އW RX-P,ΐUjdHLY2嗹T}+41\5G:P Jzɜb0eFzoB_@i,qbUT̬1Xp77c[w:m='p6腵YSTuT?<]̑J^#+tbq ?NaXdWYbYO$N‡1PMH!(vN[O UQߝFN=cҴ|e3Fm l2:Gt%`l{4'tBOȰy1߇kYrP͆-4KB/!‚$ ( p6?LQif6nTI2OkW xH$` 20Ȃyz$ϫ0֜. ~kv0*v,pKqSI^,p~wE2E[\/5nY'U0ȱ0Xmo}x#J'sЊ -Ľu.>|MEvPf!QteK)L:MzU}?tXFQu{ rn%9fY9."0&Ytq[%yr~i%+?mqu 4؞c[]&\DwzqeuVɥ#S\d0#w%)ϕd薐}rcf#R\ T DHaj^c _TNnٴsj iG"tɰm T bߝ2묿<ÐwG^}X@)sefPcʓѧYV;j 8$WnO1`Sb7K5A)H+9,cl/P5gæ"|] @P̀iJmXQi*c¡`^a./Pi =Yջ:J3 `n^8SݜlK7P@\ `x:1N|[1)8Lgprn/KMNb)|؏(GPޱvEA+.M*NzI54K1<@0*H; 4\W +mKWC(SlBon9ݝ7V&~y:Gn[ Z)ie/rwKHuc}.-"͓C,ɜ?ڎ%m3āy, ֵd(dvEl+ KJg'X\;{)W+DIn,|~y+_v61(R c[K91F֐)݈2|^Qluz <\Ɛ5G X}a>/>I:at|?ANN$aO[;ͫMdW_s1TUлA`j@2"ޕYC"XHjlu8cZMu[s]L^qR un25 B6 X̘<=F-[Y4柾?U|9+>!zqeu?iku!%YK 7[)jRigOTEʺs&3ҵ lX!J7g; ,]:s_=("Uܱ 6UEauMN[/R5ģWR'e M2;Uz7b:wyw*RU{GgS t(IɕkDt& Rx(_j J!hjDb]IOd { Վa&݇p26m&,믜IVW]楦]"$_@l'U>uxK%6sp`'&u&M/{xܞGA* M?34Gۦj?Oʓl#^mNC9{7$bqMd|}mHs2]dMn#^gC?Pfn~zWa +iGk˝yͭig_ݙ˘6W@<4h=쯷M6\wG,r8mfQ`&'%?zXXZOҳp!QiVc͠[JҥR@6IM{!Q~m{)nhy,q +LѺ^;JK(; tm7Ldtgse'O<(4,4}?[[I;G K? mO5Qp;;s> ה`]o:t.PftxRdo~WX7BMg O#ͦ{VkbvIt!H$}ـ)h\社GfN>K澼p/B#?K.؉ѺS'y_d!alO%͘/ק%]7w`2eɑ޺H{1 @W`F}Tut7  H##*:BODc0l[:خb'VjcuD X&r%+1.q ht+a>ɊمW*Os* K)&Xx8nA_7H[ODjrgUB2 Hh)8mFcY~;.>x[(6s(;k, 4,.Zn$#Wsn{3bP|>kOxB%LӼ@wqi{힇_feu'"bgKQ`D5Iгg).|DosvΚ5@22LBBL<#\1EY2iKOI |9(cc-,V8J-d.c ɡP$q{I-i+Y~]´uUn!l~yy^0;`MأS4ෆaBHBch*Ǘh5zſ((Il6ľx= ҊbP'zi0wch.LξAmc Lԗhum>OSO%H\js}BC,4<}L'EiIfK BuaJJ71s ]؛d|!cݓpX*E WW[}\ln8=%g'4#`z68WE6٭nmnnbcs { Ca*&1o.q'YAiOш/H4cdҾ )_ $d]K楮^}]K}s_b鿒E|KYBb*ahǸO"Y wyl9G.AmzdTF=bKN-z,jPNl9O*{m>-dg)oj3҄[; ұ-';H%wbvQ*cǙ KcG4?cU1mXEU3<gQ*ΜCYZ"y<}NCbg< 7SX䙤Fܤb: ?.dεDftִhs>~9'M&y7Pb$06Yky8&tl~iCK {\CHDƬ<~xCŸ՘ν"MtEy8pqPxONaKgˏAq%Q|1UDA@D޷]7ٗzjd&1:GOm;MϦă4^揸Sd@sf8f&1aX]O;,"x{ 4}nٕaXMkhu졗x z3RJy"~!PECL:gہbGuW1d bE'r#MkXjr^mP(1T[]0bRW6bmx76ZゔI>) |ު"'` /bW.8"{LE ">_M0yk5s\zQ[W̎jx÷-"4µxe`* wpX,Pw3hpk6ݽ$ 5YQKSO1..Y >Z!t&DNܗNVͅqKΝjz.`F(GO+5;\Qe%>j$(C r#$иx:Y.QNz/{ ڴ47>u jR.|髈<= ,0zZ"X}]u1sY\[Mnٸ_v(Z^ i ʰ+v|1Jľٷjg1 qz_-9Lj<;ˠ@.ۂy!ҧМ*us010Pm".}rLsH?6ֺ͗-<=^m(ʚ e `hg%:s^gշ#Xb]kzXԼ0 4#YJ/; 5'h--y>A㐨}hgpiugؘG|- L׬-]Yryͅfb28U LKw8B* k=|6BzQsN<\lN'$/7K*XYji;LkxN+`M.!tyʍ>y0\&(@ϱQ=f_v/ K(4\Ltk5.3$?;lfy0j~ _Ɣ&4y6t;.10ZOFpHfḧ́,҉C ٺ_*U3_P y$3/itX5o6p !X,9A$j䲏|ݪ \!zKǨUYш=y=-̘v m`J wU%V~%eVhjpą9.V&a:gYG$e_vMRT|-dwMëŅp߫'Ek$(BY_2ŗ ~b H .LZy&>ݡLn9REE"qlg5s1m7x[qtg{#9 ?Va6:"#BSB7\yw,<&ɔ(fսI~VڠgtUzz 8xr׊h]f&89[ԉqX6$?.\f+G2K7M&8!4R;/;n(:X( Fv5s5'Q\m8I[P.6SG؁:P <$wu`H-/_$%h.fI.fceBׅj߇=⮤1F"<2&Z-G,G:Rr41&EŠ a3^+ pq7MUɳY˖;G~Ʈ<$P9jUH+۰[hS ~۰ǒޝգZ+C>`M?@vC ܧQVfmsumJ|^{QZ:7ɹ8[AS 8N;oÀ*zc>֋ܞ`ԯqE7 }!݁_&nzBoXgTQq/4CK^Eр[7L)j)reF\6[a!00%|вVna]@yF@:Ur|[vtY(^FY*g=uԇǚ^i3E*%҉C$5 sM lG[Tzx_+6ڊBdOX d=NB{>Sx]& ̌p`JL*-2Z y@9Uҷ%7K*g +=P,OP^3Rʀ2DŽȧs#~tn6ſ{7u|R l@BH䀘CC6"r)"Χ HYi-SQv4~rN LH@Q={f`D/&x~#hCB:d%:'FFyZWl(9|'4n'ٞÿRRwᤋ:Ϧ QsffJs1zQ](SP<݃ԉ@BIZX0[z|zϼ6̲ 4BKkݫlnESQ1Δ4glejfw}ad0R6şmؠ5RH3||ݰY;KrANtU8+Zg?c%zI AsI١6n+pj#ҧ dR<-V,)YA"ߠ(Do3̽ԕ߭_t>Y+)PTbu$K6 7>,Qxl;tМK8UCx VGG=ohǃ1/-TOtn@'=j82viZ5 &cA1xԏ59;هJx, xp*ℳ @#۝.B=M "?q#Х{Tjpƛ Т/-Ş&7, Be-~XJL sYX!MPT=1j3ZVk •>"lRyxk`c~. +_Z4H~Zka*2LKvxo"ICk\X՞:5ʗ ge`?mNZyT3SaB:vVOK I}@_р^ b>W?7ep7xynv"xL8k"l4Ke{)~_*+.-8j,wR(Yg5v*#AҝRtzC6oDd M#/![/1NxIL|ke\E3CO7I>K hR3bãjzV,E0`M)A+E900uե*jw?؋ě|if$'8;8~F>ƣ`nn9-n 'Ff]Z,/ .aLFbZnP"9hVHvVn`Sd59F?O ʒxD6:m4u2]";tt$PkjX5DzK_گd ,Wv~9Fe^)yj+U: G,<7l4(V#,'Km:G[br Os+з`]'ؾncxKVpJ_8eRܝӃL 1`3k,i=JKQÛfvHB? d<=SyzK ^&`&k6_V !ySmF~!Ygh^Y]j6TV. [)ĝ 򢁴׹¥(_6VVoqB"Q_4qQ\wj1, 6hCa5cbS`KRDaVt0i0*UPYp34H%L[t[(Vf?oYmJr}$!k)*qFZ`Tr OXiP4rKk^!.|YIEDe`ѴmJLT敋 ulJSuL vS['~D'd^D3 X1m^@<)0EtR%^T@ @L.*$F!Dߏ)l! pmPS@c^?ȕo(?CQ/*|2 Q_}+6(S'DtSA9x4 S6Gw\w e6|&z𚯻 wvx<^z{z%q&49HB"B1%9y|kUX,^Hy)-ʍGb,|[ $}O@SKIVnQMp$57Y]^,^ԭ̤;":SMw䪵EqB\2\+7b Ud`@qG4Lk-LJl#-:*mHyy` :BkGS#mGMքa&)|!. ru3ykިITTA2.'ꛇ)H)b"lV= t()#OoGA&U]B Rn#I }|iX$Wsx-\L]q{jj<,2w9tS!I'=[6jé&jZ9L^C LbKt`d_υ9 {KJ 2 ^.BL NyLU lFNlk9 Z흲!$t*>Gn@A G3K c$DTI,Igd EVj@/"lعe==CLW4}kzy( 6V I"K^rQ>ܲEfq_l1֚+Π,CR欄OZc 4cww"<OlI>tnZ8 Xƿނߟ$]M DޖGUn 0RI1lfT<7p^2uJFZ:j\]psa5ZB|QsI-l(w HB+'orXqHn߂S;0^AR $spuzRrN̥P,,Sr^~Xyyv|bYC L`؊BZZm]fEy[ʶ։?ҙ>bt!/zǤH.0ƱWf,H HmL܁ Bqa1.ReNF z.Exn`}[ljc_gl<;3]tUaCӟ2Ujr_rVlU>+y= HѤ#,ԐRC Ft{4̣A`ai9|2 &0AjFi,2L TJgKUF es R ΤanId;%e +!\.&1˩ Kނ'Gog>R*Ќ,0rA\JTh@O4}NcxX 9,ɸ`Y}FY  E{nT\89~l^}1 ]Mg4UǽZ-_?<{%X!:0 q倍C r:MN AcbL^X?4\^K^ٞC"v&߿45[ rH%$ Q4[+񹫍˛*Yrץz <>ZTY;qB+X 5i[@CԀrlfgs$Q%6nx-;VtWe @nge"݊*7]%P# &d%g߈("dOX$ҁgmkjd}/YqUE6l=FUIm\^g=\y@@yű/:⁇vũ8\QdNj\^&T>pƺoD~1PW_NόHBՍ-ѩ̛ZH|4뤎Ϲ`KB?Ȳgnƚiϊ=aN8Ad}#m>G#߲h FwA;yRAά~kV&[C׏gJvuYBʉk\OT _&|bv,Q$@rvC=T`a {5c6]mG=_RJ) }^qT 0ٖN'4Z8֩s&H')& ikvY8cJ>oE B.=%J*`L9?cf^ܟӍh vXh+R./;7wHg5 c>#n\q^m駼X/C}\^ OUiRX-#J+ǟX˟'%3̒0-QjlA؁(#@r0k *-wmho9nYtny]E]Zno9|)J˰qDRZ]zldT,h1/vlՒ3e;A d6 `c;~)U~E3Ή ZohGC}UbODZG қZh }{$Z}F5Y@r 29]%rYy!@ϔz WciZ43a:Nւ;R?hٮ%HqU\"iCc19\o:LO@1Mj+lFy@-սd[joKH&i\c:]f&"Ƿ+v֞6FQDKYzQ&80{2 :t5N,*.K?ꊰpRN[hC}+(SJ_2lWQ3=_=Sb/+_<9Aɩ}1x4ott(G o_wQIfC͞ 5%l5b1, P~4=P|  D"Ȫ5jzXāC0Xý5 V0}RZS=Q{4 VTޘC,&zYYThYX"h<N3R^+P6pMPun蝚}ew8 ~p2l4X$ ȥ?Lq\yzqD}{JE̴862{BSx_ۃ56 \b=BfV+HV:y^;8/DWaF{AQ'LkgcTZɰtjb@v$f-Zw*쫦`35hJVXJ+s9wn<+;V<'ԶIsfK:ޒVd3Ntg2 h3KG$Y&[ӯG]zFSsk/. #[,UEt@uKAifN4hSH.Vjjۃ4«2[ӯJD!;tDDblu^ƙ2Rs^A 528CCR©pk {Q*9Vy҇ mζwʤ='-[EzG)ArjUQ>q\HaBy|}<**K0@O[4xXب'5bsÅaF4Elָٖ݋! W 4j6 諾NhHCJܩѝATDߧyN6"FەSJޠiEÝ#LM2>,` 2`~\;.N_ 6]5 Y5٘y0Ď_<"\1Fe=Ñ)b-NEwBZ',<~ǔ!E x*qȦZ*N' e we8PBrjGWXx$}5L  D\O"-,ԓ2DzGL&{">]V^BP*I. a & X)&ߑ-ҁ(5`''n̦jݶ9AiUs߼F| \?ywZl 3]:H#\/j/z|Nq&PoA32#~WE=76W6uBu[{hLb!9~L+Rgd'5<hI8dwD^s& 0[! ¡3,Z3D 9 ˕]$x8CO-=HCRql%U,#̰eā1z $糧N71#AlZ`Ð(T'rM#SS2w}Cѯ3ǦIӂonK8~S?p'<*_Q|1/񣸈2[b >X{[SJ ։h V?ӥw"ݖ0i|ITnڿr36{LDpG ' zWۦ)#Y˾^b8L=5*"ƒ^}̎$=ABѴHzQm/ !vT) E뭑6UȂ:۫?~i49z5 A_!?dߦnJf70F+G=".c0j0O#f$ ֦*\t.ICB X%2J46+&q. -̩7lj8RN@(5Ke\&*T2;P@I0L a$'g#ðFhzg)jUpps4;A1 #f~voDVB߇vZbK¢\RaŞ8mً5Yg:K1YyNVm\LHugVޚ ϯ=鼒zɻYJdې]SA P!(Cх9 cĬҌöw ȻbQ_o9%Mq#|^y_tdl l܄p̓"K49V.MHէȺP$I&=ulGP`Hg8aQB[/'mD=dW|I>,MFe?Otj}/iw,=@.UG}rk9B?@!m p|Z걄6+P"Dpر&C2(,.NR$vQ5읾דּUEVIeYGyzCp^#9yoW@}4rWF̦)mJ ˬ'{G®p#WDO7!efR<4hXLl@ϒBY'L% 9TIos0[զ{\31{xO*qcz[rKInUf,KT UvU`ڪC=}Ux-s5B鏹Ab1@<ĴkNZ&Y CᕺH31)mtV% XTmq;6G_{(h6l ?ԓ<qS~=\i^N\5Q|ډ%5/`BIMo+-Y$m,v#pN>io#s3t}ơgx'vu21XF}p\qÕ"Sjo/ayu2D0,gMdp^VAG v+y80 @@S?3UDNypM.SW&W\iowa:cx0h/W #{ ?buqsZX͋5|gAt׿H5!e%z@ 6Pt^pC? Āݒ]`? 򏉘+n8mRUjV P[a4ت{ 3>7KoCm1h'hlҎ{QA2-=^)5KЬHtd mod嚸]zz̋ʪARv%kQhS'HNNd'35σ^N25x10c]ćDj$uC<);dyىtO9;xc*S۶$@MQlQ~JO&%U`Rt;`'@P. JlģCMeTGRWae5bi(Gm%aN/ )r~Q9`Ҽ-o u/Yu_ „|?>mBWv}SII< 6: ]5[E:f%+u&2ZfMEuyh~B9{!.mv4!yd[RE9 n{3PB8ReSQbi\`=X6٧;]'jҖFHA 7H h(ן9] Frd "(kIRl,xEBeHͣ'hC <1',Cvɝ0p&yΓG44-׃3` (-0-x-]|^]*q-τ/.d[uZ Ƒ53v|r9' g;G#klB<6N!w3Sw|5_"#&:&^ZM3Ad7ck/l}vv|2>2Bd7b2-dhjd铫 %̗5q{qGKŹL sѥaM,/zz 8W)qa;6Eo8. EU1Zлd׮ I /ì7]LbNPAGT=0A/.!w!^rۅ?WV@PVHb^L?ZP5adAY&(7)Sݎ^:[wf/6V[TXAg /+N9$]px#HXL47ۏ\ye*c{Qsl;T p[HisPݶ֋_Usӿ8Q<_e۠:f>M\=7QU>͑cl5è" Z*eCw I:nf2,s;b9 #zJD8<"E]x[/0np;Gc1;=x$u\x'3z#4WS Nj(/ ?hˇڌ; VV}.IjŚ擇-֮m=:ޞ[)['wr׿Z߫ ]Fr6sL!#nNH|pq++$;y5qmԈrs%*+e ]YeD ]݇;e$FuUx-)zO\T]0P3pZlic[n4& mY17nSwf=j~/⹂m3-&`0KD[Fi0A,dAYRK#H YU@&e!=q_ t <)[LMW"<BJ«j*F|kl|9jh90 %:!"C9Z_9۟I. &"촽^Ƽ|ccW%(Q*Tne8UR#ޖ48cPN6XUʼn$Tϖ T8r{M5lb_]oo@>Ȭ]EЁ` 9A2c^ lYNb@q:R^a QW|8i掍%M])b9r=g1fUoRJj}QN6,PR2X^ x]",k!<yo]dWɚW^[>RH8!nelTbK+*i{сQ@FfLDp+o-oɣ6ݕN~d81cP{rr*\Mo 7no+3/WohClZF3%L465 8G^*S*>zH1DN:;/gR j;Rr[yZμF /eXg M+G֡1~+J%[+HI'=T/U5ͳZkκ*!v| K5k&_{0)\l"NM9DvCQ$G'y ^R"vKEH~&jNvLl'b¼#S4)̕ffqf귍 ?AA-asDrANC&2c4=;P$k~nrı+}E+Ikt3T0=2{3ۥ÷x|VdN{C}G%|:Ҝ?;ʒBi  0"/Hj=CN:i/&3`%͖a_[SL}38Vu$WPϿw,ݤ3}&ȸ3r7ǘA:ÓM;pxNtMbzz3hMH*kWޑ`$4.x{Y 0HVU$%/:ddxcFW$xs%GJ9 KFB Fn|&9bZ?]Ve^QNyg`@Aͺ#b%9v)86O\Xv1 7m䧕U7`Ra,濰Q)%NoUaV3+XfOW7wү# Vyu\1/+^""58EcrGŒc<Ʌ@vqrv@\cB8 ^;x_֠q*IҌYQY~AV%l}`g.w$5.Bri"8mTJ"F CZ#9Ԃd0d0@ kNu&nymnUq0R72fu|H2SPJ_gL MkNNR31<l^9WB1vS|.^h2{QHZdzZ&>(ҭ_\Tsu6$Mc#"PWvyC4Nֈ}U^VulQ"f~ͺOt >޺ 3Cs$8?ep~iob@Tzr~HѬ=at;0l=}͍Z!nn`%3I!;P?s\%iQ(F=(TMW,[D KR-}ǣTlb7`<)3ǰ8l#0'/C8 TzV SdJ/{y(Vl.AIuhCoMzyRܾO\vĝc+Գ)W\Z%D6?l6!j':Z(c? .3TOx/&eK)HUw$x)ke}D)Gkh;W!ݪ ,Ac`YL=Y\*lh.DzǼ^ZmZ,(֢הF5m#d"Q[J/f%y,bmVO?6˽QEu3>§Υ3e׵9^1.גcϪSϓ?/WNv .lJҟl6O i)ah UTe~w'- +%,e#]0mu"̫_M4°IxFk3\~mZ엁a!7(g /w*ꙗŊl3>sG2za A|]6}sɬv戶8m|9E~%сzK2V(b o"Do_,9߄Nk̒#9 g4'[f96ULnyñ(>_C3Hj8¢'^m_`R8z!A8vp;&TIJ)_ОL,VR7MXIdJpi90woPe^t،Z_I:piboe#C5R(Q{y,ZVⱻ8 ]JPCrd R.s2W'~%97VNB-Gv/p3-Z̛̾**>]Okլ)P7y| s7 U(k i6a.Go ^MĴ( 3|P⡧S9Vqe@nU)Un|#xgŌ9lfyjJbZ6CYd\#b^1Mt >>5r4ׂLCW5~h)Hq$=ڃYt9X̖ N/gjA޼ww.<8 }WjZ8G^\ 4)Xrr'7e^X s]11E>ءwʯMZz70c _2zh}QSė8 UFj,JX ~r:C鵐,ixVaԏ?F0ѓG,tX! 4Gi r%Zu۵ZYJLJ(HFщca@K~ɷ\_-N_C-5鿟"uI. *e"h媀ׁU1->A 5*21=U{n W-̯ˍDKju ~$İ!뼄8cKV#bhۏE eyi#sOvp ~tЄ"S18 3Ϭ: q]|HO]7m$i\:}U{RsܭL_Ϝ,x˪:ӹXZ^Rc.HRR$GFF* (೎(+5@!xJAXbrn#Ѭ3'"NͿ`a?nfI`;])!/ AOK p13I=&T yB*wZIՖЃMcNKt!n1AME33BR}K[pVj,9УwвtsI,:ǽGҎ]EE sOfB(cE\aIdIJֶZDZ7]畲&U b65Ck0 Fܳ42G3S/ٟ@m4WaKhw\+]|WT#@A3CkPPW|l7P! LK{aAK9ON$M̀ K'ed@5!S,osbi3)|7N#^;^̢sC" PF%rբ2ā}K7QӒB'l֍*p*^=#MK})k>9)]2HeaaXRB>k'drAvm@& #J=sww߆Z_[{ck3ּ xJ9ZB^Gamo<ȇ6`a>0F&rlŴSܫ떺a=w.2GoLRru4i0(Nnj>Jq43EF~v c51QY}:ee6 Kb;&ch9f3MU-@(Fi`!ۦ4s@Yox>BVz8U5ed+QvcښU1$:A2XkiHp"-čJ,*ԽJ ?Eڣ{Ց9zs{Vc-{MAc%{7o tʟLe#^Zؒ]L]zg[HnÍ:vݴ4m.JB[iw \Uˉi#m糭BXNu- OMG1"NmB՝š|F:RP?zΘܭ~rq~"^aD7&E9Νԏ\ *[߱-Ϳum J mxꪻ^ݝvl.CYq}R|LsGi&R7P'T+255GU*02\1F)& +ڟC3~ v3 |̫=/4MlUhG$MQ0UQԒAy%s$«(KŎ.Ig!5RȞEWh˱T4h3za܏!IU;b~2Y B+8Z?ի~'CG@U`rP j̾W.2G~DŒ3 J`Sf[W&JBY uj𺗿sS谿ɽƷFظJJ CSMU/~+ x;1G>;*A9% aĢ'c2*\;:6@⑋Hg/8K(`h?,39)`>|Oι+yzpHVfN_c!ŔfZP0;}܋.{99tܜӼc-qjGB[^zwAEWYI/K|ȏC1%IT2T9CUG%a^O8}e=`wԕ0^?V23)›S #K;jyN|P1MeiAU ZHn~E,B=ZA_udz/n)2S©M21lع՞"y Xͯ;byvW2a:6ÄIW5iIП$̼K?ˈŦ\IGRf)0d Qu)x#C`ӝ Kd: [S"JV yEGS&AO2Ÿݷn-4琂@09.\\\zx6"2_g0:,> Q:HB֦ JI uاLÙFd^-J_΅jK@e+{. }ĥ4֔ڷ˧ԣ#X}\' _&?%6*$ :Jy\a,KV䁨hh0&'f$g~"RgLF^O!f@$) ;$`/%!ÝYnz2 N>0ݍ1ͳ[oL-7CȁX]pH# @N4 v`KEN3>2xo2kojnI,cOɱ 5ǩkkrqhg~*"i%}o,6fUV !;ጏfe7~ŌD a `8A<#Té^>V+6 .ji\o &\d U/hRcuGᜏ0\`l^f^6&Q-ag~<}^\ѳ٬tAznzMHTV!3Cp0'<.A9դPY%MLh< gg/Gy*{p8Rae*m&hDayjYUMDV} B܉M܂60vh]։Sϐ4ZT&">.9h.RMpd {ԭ."= zΚu5QLi W؁YeBtziKEmC`أize|Ի6))|;Fk0_\\(dٌ%:"yGN>MiD-XKJs XؔDF~h~M7ߜoj$m >gphأhaa>1~5F}fs36lFX[u t`] #yp1Uoy\"-FOa٨"d껠ˢ_IgN<6<˄:IWcz}2mNξ]ck]!C GO8'vrա<[::* 5Mgco\"~֌ְ&.QGuIZ"/j'_l-]b=34:c\s?ee-P5[a9B w: ӝ-H,mWjLJ`(%!çpתx˺by'{6-z\+iҦG;܍]xHq%y;a"TAM$xE8f t=XXfbPAgQS>3Z_ҡ9#@g[eS89 jz}sr0ɴY֤InHHZoyȌ #N,1LǔJrN6f02XWwvU!.Ld9]7=7U#ksPüzR밣L *P'5)[&:\CR*R?;z ,bircsZAE#iϖ_' {`p(絋Ik; ӻUt!ӿLR4+*W-XLޞ\Q%|cx_[ sI젥IѦoش&aZVYioc똬RKi'RȤHY2&*˓qW"ʮRq]z*=-5ӸNKm12,+zjpH;nrl)TH8޼N=Fc[hj:اlY> ECJ[!KYg#Z!ߔQY٘"4;S)}&&o'pY;b NZ{ʂ֜Ÿ[̍(QF/{\;vϽX찲 $2zg><290i >ZPqK Q6X"_}|J|!莱;"7z,vPg $O/R@yuO[:!S.;Ex֕k.59SDq\VϵWEuؕ%l)d' . Q.ꝱvrP:댿UR:Zء5opdNGt_->? &Ҷx>g?8Ȁ }7R@r:rN)LCEZ jߺUêa1>V촮cN(HSwo824QQi! Y.?WE_:U>R yV.}c*x/Jm*WABk.=aw;P ֩@v_ S,IķO4yUXLo+>y > H̱uO,념lƲ];Q܈k J [l/Hǻ. Ƒk%fz'j}Ӌl5͠lAb \L%j|>YC"4AʞY̶NwT'"93iEU3M=yKTpHy:ms~K;2WWt+ REƌ5a uaC=5ʟНaԊ#&m Dπaס+LlLʟ&xlo'WfgEݹ:2dEL)d)/E]  ܨG,_g}y㻡K 炣F&{VtzcanCUKaϲ4sࠏhG$貢W{%jѺ>(m?zlBAL؏FZ:] !Hhh0f(ΘFPb ŠC+䓰Fg^A$V;:MRNVjɳr* -7PɾY: fB>K#,K 2; 5Jj.{EM= % URW X،r!O.WCN_!$!d< ]+ zBj?LÐ Nb*0-sZ+5-+rfo6j|B=RbbL\#rpogQ~F;q~/*/sDZEǽ? Cx@ڻ,Y"N30;UG9I&Bl\+qMg[)v\v$rU70'r=7n< qq=W}ERDgj,TyfJ33O}oc,ޭ{]rGQ=9I?3+,}!;C1SaF9V Ev F8؈p!:.f~gHEoE} {վ֕vs+m ,*mH}ȩ .O^/iԾ@QN؋`zu2Ùb2wxFfgkJDdKy.rϓ)16ϗeCW1̀_8hy g u4#8sɘk`wLfkKp0Eb-]7om fjw_n)ﶁ.ATJIfG\PyR[ܾ+8a,/$P'B7*t}.=Y'\CP Te0eC[ şw;tWʝ2 Mȑhzy55 / lḣ\=OhOW~V2M gsص2[5_/b5*006y s*y-HkE-2z )&-S㯴Kxvb;ꂎn D24'CM~ *qы+*Ήc,N!l熴&*&b#İpy/s>/b*$ jXV/6*1 @ eV]s{9=-t>w4OkopIK?}Y̔eE]YS̉BR 25/X;mcRFHޅ' .a8uάjI!H-Zȓ6GZS+Bgl<]fvuxzV1jqYHNyoȿ?j\\xȑ&WA.lqhx #_ڜQDI˶k 00pKyCpͼ~@T8?ØI%"Us)k^`bb;1U;ַ'bsJP 2'Xu[kwrUPVR ~RN (L[{ne=uc^4s6|ܹN' z0$VgQJ .jI2hdvuj73_9h*k52d=cEEar-$T0 Pk3uyLnͶ.ВG {nNmPU\~M(GG2934@GuJ;Qd /\FcNr} T7Xsk0ROFAfl h/oD- .RI=,4zy*.&(XDpAb iz 9!nc̀~sbJ{/΃ DoN!K SqtMBv#RZ611?uނ5웕)6*sf g<=qF,9ݑE|%"+u`q~gcr3zzWlh]х]<ŦU]ht o_BC+T?Begt@U~\Beo큝9cKQK+*,Sh5 S3oGyfBÔ.s C{@Z_4b5`,0?n aKwrH2uq}K$;Kb?"XZ@.sW ,5Ozѯ#٢W_66h\ Pow/a ۾eD_uK,r0wN?E4^ #k*|+9t` 3r jpQڡѯhgJw Q9xìxTU[? L2%^Pxn`6RP[VRۻ$/ gGf@)#^pI-$Xd@;zϗ-nVb Z%`ޯ6_W-iX&:%Xa\M*,\-*؛҂_(2NM^US:2 $Nt4U(z9UװU2cY?D4%B[#&~O ΍niBLw\N*z+ ^alN(an} g%&;,&Pc4%d"19w!87c&ג^b̞Fz&8ac>ܐYv }y԰~N+B"_v f725M cOtԿY\A?}-F]1ښUX4ظNe8|$4jKOBBzCyϳ&#,G Co۰6|%?P+gQ8>j24 17{憸tLB[=-HaTO')&>S%{ :?F 3#b,?粊2sWyE"z;GhO$o Nj[eܪS|ih2g#A$9ieSWuO3kCHԆnqtzŽ|٫aze!/ÑO$Apo;sèTkW s0ZLO#ŗ,m Mϑ՗8$?|P.VTtqYm]}wU%Y⼊-܋™cqMaYv8ʻ E(H ?><{9ҋ?5U vfdmN[vwz)Kl9}4vyo)"$<أ-;MC{wq# R: eX3v27wMzyd455k޷wӠ-G~ S'\χpνGֵ!W|N烧پy*s( M(V=&ZK3NK- ㏘pdQBf%f@`=}~$ZIOՅUso톣4E+Sې/laf4BP(rT4k|ubx[{O g;ﯬ{}ٯ(F^V"]S&Rz wWѮ#I РƸv@n~Ɇxe:v_+sn gݞ7F:/Z„Wj!PsiFyHmws=9*K-쇸Ԇ1xdF"Ŏ@n.Idq 19(6u aw[ƜV>*)/i ;C\H6єhJT?6k١PPZrI}1#NwYAmq EOoT=g{L"`XL0x!ER>ݏs3"kE [g8G@l> 9{\\DJR?8xj]%R{EW^p`A&mcܭC%vw{Б5@PX# ݦPZ`' )G~ 4R\N-lUAfN)W% UxC'm,\mK_|/ +O†?1n[U~?MdMէs[]s_fiQn-b=$qb{R-!0Dzvm 僌5TׇS#g a[ڭ W [{r=~,,=̞&2[فͶ%o߃)2Pڧ2EC#@XpO ZkTeS7%g zJ@H}8PQu_wA9GpAKr;OaΆY̼s>En^@ kPH1S?hPEZ;˻ə{ o@ۦ7]B _.N32>rKBฝR=4"7p%'ìZ,TTHzW")mBFy عY'rHZ(a=H 'ͥG_{]~WDkh@9tyg5^C}0p*XΝZ -.31]؊ۡt΂V_:U\hczsg>mIo׾O"idfo58jְ^.m;A6d쀫&|\?|+ؗ3Y yOghwZ@60nUC0nvV|^1mqsњ J+P6!'7)V0N=>A ,^M굓O[[ɂ9en`L(8l-]+,pg0 oqr$+T9m?r/ 纱GblЊ)j2E͆UC΃-ZoJcjUK)0+UƸ?Gr2]Hkʤofͯ$:E4&OiŤ^" -4jCt̤I (WQsڗ؀kV`^"jhA-5WU>-|,ͼ R֏3P$X&Boӑ ;Ĩx薭kCo^{WhS޵Ko|EqAv%C^AV e\m+hUЦӗvsF'i9鯆YJ7솚3݁$w9wB-`Œ'\ZH[\ì ALX- dCbl,R)2-nUБ սr;Dx&BtW2/Ӌ$aM&^1 2R3[ ׎fe7+ȿWTA/f(D!~zׅ5RN"Fq$P+6K;>D_ [1(y{7*pЦŠ]'}U=uU*+nBKlZ8/Qb+dFی}7p5yUotVXu؁o׮it5?@j&*E^ۃk+gm6/j#^Z[)zgYusaŹ*XuʑwA8fJ:Tp慳y7drY\;,,gu(yĪBЋC9?@XxiؤD 6vQ?V\s IF- VQ;.!P}vfYtZfYVȖjqsU+A@GL7Đk;5m-Z+F}RC3HES@qn" amhZJ`ørk|jP3r5c_PXITK@2^o=4OC|/Dp2K^ U!Tnxu>lerХHDƳ(YgEֲi- 1U of+ H zT$y|)DD*bЯ7, ;3cl!%ztCOBa֔&,Tқ,nҹ-*x( TI6$ V]h}qPb!:FٯdLnPa@;ji[FFDg30vq&О mgl1Mg#qC'h[:$,h_Ⱦ(PYʼ~UIF=_SH0aZȍIx2ud^?g[eCqh}۫eg8P?Z=i!2Y5n?Jya7 H=WWݒnl2Z.<18co*3X؂~FCP}5 跩Y D\xZrXI`!UAk3靸TLPa5I fOH߉cCQ--5SÍmwƦx $勩3pXjv2 3}btw#e}25/W6=F毷xrD?7Jn^\\ók(De9``$YsNi;_65B #1﮾ˬ^Ii 4YU^p&q3&mഎy.ۣȉcKZzQNlfLm%o-hŸuuvq=H>)m9k{o4^FH[Ϟ|g)o()>J jS!ABX @6Uj%zo%pӛ%r XSh6(AޅyQrMG3̱!?_rok5=뚴ce~)P$7ښk  TP,7=p ^$@Q[0SG Zv?ޮTz̿ڂGg//O-hy/NSXDQZd4KJ$ĢrtФ0*6hM[Ixy|S\Ǯuބм&7.i7:M-V8cp..JXV-R1JFM l Pt2p|n[RqX~=:CѥؓZV]%b,؋#Y1W Jmd*Ɛ?9N ) :2o1B%qv0"y3.: @'<.HHpQ+ySk<` voPf·!/B*3jPcG^5E W:Cy/ $3Z} WJ1O_5⃳4Õe]OjfN~?5.o˛.ч/Nv:}/D#{?#G9&Gsk":7L6\DUO=\Z\Ye{@rؿ{,f6&uZ $FXH3w G $ۉrn?I3&ox;Ԉ)yVM`~ɶKs.dI:~Y^]̳]%SP+mth*;svv¹fc1Asa J N ;X[bB6gbpM,&arko ֬ Π6?1pB^7G ,uyÊ؝$3pShOJ1+m༌p[U-BW׻:w 8Q濶8\Ͼ %<֤26Gq i;b~L_lXh=@;a&3leQUx7Q>o:*MmMyq t=tHJ/y7kVsI,-%1/VdaʵDdPũ֮VN +:hҸ Ua$"vmW\O]~ B}Yar>xpngw[hIJFJA:f2{֗L%nt\W|cc4n ad qޏ.T;Hn )*XaW'EfI}_0;Y5PncW#ℭBP4#1!\;.q\ 8΢ %kC5 aShvyf%"? Pa3)K4ݷ&6fi3"ȏOa#{r-eˬf=ˑGQ, 6r#&#jRB'snm2owrʹghYnҏ= .nu*1;3YGfvP@Y D (8q=Ƚ$ŗ.X5?sXSF3@2/U*%w %.K멽姭<XU>y+WIZ/Wm"[dc1N<eMZH`3E~O?I^eG<6j! %vUdJ!Ú9Dr3Y TqHFp e!fpAmQnd IFGVQ3>/Z0<U;uMx"a3\0Vlu ^=nk(s -q:Vny}ͿҫV#P(ܹ5X^'H'̬߰ʵ1wwQ桦)դCހ`68 >f٣%-]JDH 9^E<b٫/c+  E'3ä%Q$96 MI#ҽX"; ]R@z]Q,wNi}H6YvY+O<4ȃqrܜ[jgG ywg3IYjz 9{5N%^b͇]L11be΀_5I:G{W$W .1u̹u&dw-`̥=- ⿸) ³nWzWFkMG0N&QPh[v ]W6D#Mx֧4e%ᓞ+S-@Wץ7h{[|w50QrhR.*'L1A-{X!lBszl/@j6ݐs b=A~Rܳf!@w6xJNDɚmuNUCGrRʅbq[gG;:T(=pblNҢOHMb jQ S:t3^Hve³*hߓx~_0HSУ^|:ajTbSQ"yqаq*3E'ThBM kb,\0m)pC΋S\+w&#p@[oH?,NQ{@(GxwqDJ1SLܱ7ҵtJNs+HewBeC$[YJp [PRd;Q*pj+Z5)ȳ7I&k.#chm4Ύ,/ L[Z#H)u> HU&c +7h`'L3c] ;ʐѶ<Ljz)ü>=w-B8nvޙs)Ϩ_"r%Z\ UvM8x!E̚KOpuٝA.q$?3)ɕd[k'njT%V4Ir кR=wՇLʅ~O!<,j| [aGa/1Ċh|:4Mm1V "T81?vڅqnX/M}58{]^BC=I)PMfOj'XlKvIa4n=^T*u# L]ssQ~E&u]ۂ.~+nīr^@;)xs3|@fg1Ȳkɤ Yq7 Bc@z9'uٓڝߙE*gokU7z=]lc?vFq:wc|XMt}d^KaMA v#~<~袍`! I Ĕp*Q%^Y%$ɛ^^`Q7zjvNTo1Bp.FǤ&2\aڙv2=~+{b\M)gf!f,ZF7ܧt5"MJd_ UڠoPz(ns0-{MDC-'@ko(MΦyY]DWUur:B"?xVč[ո*M5t#ѲxPa#"沆_b ]Ǡbͨ}'{*7?rD&bVH4$lm :F+)cÄkESBGkΩlK]|à;2u hN(xÌ[bQc5=6Ua,\hn%}NP'i|ҷ!kC;:np[.Rb&EU~kC4 hmĹoID >@4h$=~mZ#~yԧlGPҕQH11Q=S礵|@{_Ytzo4L#rې985,w 薁73QCC_S+VG:"X?%F&)19%5< XW>T>=ȉgSbz$TB2-=|„, ^["}Q(oH`?I1ʐZoxqھ&q/aGG,h)UL_vʛD0քٗV^p׹A(}\.gJfv[$fI?OP Ϫ0ɭv]KZ\t4l㚤]s H+,r(@[x(SόLcS aq1h&H=wnKp`QeHkq'tY y5/=.a9xVPcА ]vc,_[mT9Uj 4g<җ52d)OMBGR?"iյVW #t3&T%/8CL ,3˛XF}Y}QWD/-k7q[0}>0[,MN(*|k >.OO($\_A?2v:P?FƗٱg=s\PXSJqf2fv%51}O8B)ZeYf桜:js]n(R8!hP\6cy:9_ $r Kk-.*\w GFIHm^0Usyzw8OU@~-^QeZCiaZ2 @y4{ѳ%oʼ^W = ^ž(ܴ}b4)a W=,(lĻD%d̄\]. ߾NXXqr Vć~eT9zm*J$#>_Al.rC8$WFiu]hfŢ'}pdUeqp;^؛ nZ.^OX{?1PIYlfI@pKg^TQCjQ0MD]iT}PjBXXVOٗN7Ban>$,j,\j&yx<=]1̞t@OLf9JIO^^ Vߘ/C"i:.4:e>ÄEN`)̎pTn6_hZ&rLֶMfk##82<^?WOBĨČn*#NDcNag9LIyBNTq{t 8<^Måۛ*Z뺒ƫ 'uIZ F/8L=DoVw2_EKTV su_zsELW[Iv+:hKml{?@}ګ{1XY߮X.WPIh ޭ52Xz8sVe$]tdPff`Ҥo:OB{be HSh[D3f.˿(~SׯuavjPZ>B;oehc`ڼT#")[THf,OG܁ǟ)x,{m/=qvS[#e'ϸSi~>q =i O(-7CwDъm oIB,P'n9TKk΁v̞ۤLc>'4+; h±RsH2 ]'hs"ajG1ZBOsk! *9fd06_!<+@$9F]/F |q'kB@M6LâƮJz$ȈX>R! zpYy8շڢ!xc-77$@l6r kI )<)c:ͱ g6=׍\pu22{+/{i$"qguª.=[j&ugeƛ+<:=UUUJ UT|гVdqRMrM|@ 7?M7" sl="C|G ࣂ[}0i=qaVY\X*N3ԗ oxj%0]G"$0E!vo%|;V 65軌>"ƯDS衏ܰ\DA7hߛ ,\DH.UIŬ9m mvk٨K:yZuȠ@Y?4.3R*7oIYOn0X$<aRӶd`l:94I1UYZ XX#96lC/ZC.e(g≎H0na/(UZcCk,_0A^`Cch:CEKb?P<>ZG%\>W=HoẒ^#vRwN5A3.S} KefG IP.Zoӎ`9j@r7uƦ6̹9!@.CLmb <=], PXp@y!fY @Fv6dJy9ekcl߲kd'>?;PE!_y\<3$,L9Qպ (!|Y)/W7}jxrǿ8" ;yP!&[lx6!<?DQgMbŠ%p*X &u\7T4Rc3V] y;6)Չ `b5HZ\t< GJ,.ysY×c,[MĄE{ۈ"%Bz4xunlx<%OP #fUY7]~=_.Rk a_yG|` A;4[`p1Y.>B@1*L)OΔĚY!Be]s.C!? hje(GrAԟxA"HMN[{k3,"NU_u g_f*So4ܤ2 St`"$ۿhC䔩8Nh;yb GIr]$ot~'D{}u"XTҺ)??yo}8*F[)e=ܕ pMt>EʠcFY*?#k~hF3G]̎ې침=|vp.'"(aM&a?j 5'Ku΁nݛF3%>*)b6~ҞfvLFV5⏀C|Foٲ̴J9r!w\@WpöQ#,4UL&qN~ X|'atͽ`(=EZ,:GgLlUv wr6g q8셒_һh߹0wڮF p*)mцNeY1R l#m8R!5dl둬aӢ!9OhSnSQGJ VL]Cpm9E7\ E@M|۵6x+֞xȺ<|L0tAaE*0ӢY^Z\$XP6OooiTfTR+#{7n<5Zys7edpw<ΰO0@*%gzړdӝ7_1K8 cbYx]@`:}D|bPE _. Bh3iWK`dљdݩ_*hFGtAn t>Vxud}%*OǍDOu+y([Z1a1x/?#Vd-$k> 68dFL7r5~B%UW8=Mw ;t `2oM$A0JŅ-mj*=!i_;߈չcoNAdN}ib5?詵n^Q0DWS- iV76ǙËK o֌Du>1amNC]ƭf?ԭ.1-|F ~͉HlQTq"`%o^?&te(Ԓ2 oBrO;.KOx*3BfݡF s_!vz> ;>ghEa@=f0@#d )8) r#K`8 jo0(.,P ;ʶ.XX*!`+ա\hWݹO.͢'kfLbH,'Zz3>&c}M4\2GR^e)Zw-ě~ 9/l,"ox8ė:͜YHHZc*ʫbKii66tFDX(% Y &g+ɋ rsd-n)0KtqȉUz!iik&7vraĦ˓*ml3e`(n/۫18ӭv)ߺf?bVPYLu,hyə#D^n*Yw X_ßa2~q8dyoK/pp '']ޤʲDpץ9V{4ɧ?4oNEIfQ[C4YO(;&<ۯ+q[4lg/J@EQ\ɰ 3wk aMzHcpmІt?_[{;ݔR<~| 1zr^\QGrk:,5,x%CEO*훊8ݚk ht[~ҋ|m*S/qû(`ט4y*4VRs;IF8mVc'@jF-]r]d'ĺ33\H`P ɟ y8ڊ: wW97ѪrՎXPbY(wcGY^5/I}{u4wMwf)VZB.O v+X˿+Iٙ8}7793aӂEgme[ wѻb9SSka$EU ݋/1!)Sv}PӍrPYY}f!垏[eu#I&XaW"k=5 N]ژla$u29d)IxTĝdxXKSIBM Hc2y1Skp) 狹˟$p"G킵ntZ!#{P:Σ㓲זs8"U.3>#|whC+SөAfӕY]RƐ𑅯3AH_dAPىMfߗ5xj~ Hg>^~ՁC J6imWe$'ݑϷ>A-\DZ`Y13 3T@07&ܴpo}]@`9_ n7nCn 0q?*,NkMk 4 Ve0FMiF"0Nz u_&ڈTaaA*/*rClx[yZĚJʈz-'}z'fr|GxWϨK}7SjsKR2>#$HGz!4-JX) ]ބr=QluЙ aVP((iG}Q+'.; ˾"MR~gC  #̌73 t҉~@CJ &/{89: x_J })&;c(yFWL\A1|9=@i%0  v٫;yW1">JP5 _ (zꜦW\s\#W-On{GTDοgE)E[U#48Kz/~ 7]E(X$NWCLQ~_tT1&+ms@FXRR$(Uf'wC#!.}h]uJT 5h'8`ؗvtiD>h ˠ:}.`e[yA,DٸɚY +4 Q 0CNʓ8zgdh`MZB\==, Z 퇠*fb[476&3d78``́|2M&h{EL9{$p8:y]# 멉Plw U!,wb+8UQƺ ʍm׭byU>UBJTf#˥D3%Db#l8uS0ϟ4Jb^Z*wҘ059^h,Uhuo·J< o!*r&Ai]YؚkaZ``tuϫY$PeNei[S $ȟXV};pPreqz؟̾M1@c>I*F4Ҟ̊lM\)$Au*爈f) u4v6Sedv^AP@vetZθa {JG<{zhn J )Bnxg3pFj~4:CAWstsӯ Vwp{$=@9lwΈ=>=¦St9a`QYʾnJMŶSˌC"R! o* aOUo­)/# plJwN]&;?v-01y#V'ɍ!@|]V*{/GE۔o1JFCD9$IE!^[u+fI̕jU_H xuM 0>Qzpgam/.bwݐ^R3lb:gxXC0ZH\#3s9%2q{4T8F5E {.}eela343g̡nӀy-E#ىMqw|&v~=>H!˫u%L*Hr\}ؤ2ۅPwޕ&=o +XZJBǹ$'V(Јrv4*|?8a}`AGGJdDr)7w䶚|$8b{[Ң7Es |qyvB_>ycUwn)>ˠucg7jFӌ0|mLvBUQh>T%6>=ʧ@p 9u)'æi2ڱw 2> Yx>p"nWL[\\m8揜SL&#Ɣe!Ec/эK+8@e{Jdu $nGXSroS[ǯyT!zi\P.Pbo(_/0k LAr+7+~ncuyq_" E< t|72:rsWMxO:AFULyP], %aƁ /g._2{Tw_aQg_ c= IgFW kOd÷1 j A?AG^lͳ;}Y d'Mͺ? hmb*GꯐR]c&>^!mX?4_t+A1Rm:nm hQ }Jst[y/eNf2c$!bǸ͡zOF8K۽Tdu+l!#9G I^w3h;Pze$4V.~0_~&~n~VeNbMJ:j)$Ɵ6 '&G쑎D2FӲnJN ۾7 F0$ĬI8?;7,[t_Fb:M}T4y] ̪쩝}EsC5 TwRZ2_zR6 #jG VELK!FsqZef({'ЎMOz5dci0 ǐ?#M !eۿ.k?J{bҜN8-]p*6ތI"b|;ޝgF.+fEc և]*E  eeځT+PL4|I [Y[#.DQi9!#UUQ߶f1*7y⎤z+wv}7 0GZC9?hev zWOqv:X쏛)ײ<7iJGڈE# ut^ 'Hfe d셙!,xbMݹ*s O @H+ie3W;<(y躂#_!-BShdi~}#j‹rj02їnl[`'[V'Jt^2( 6.:F9x$VC6]3geIΒD=3]qP&Nlpukduʄ>bOJ(J6#PԉK .f3yTy&̐Pb1MĴ.rCn*Eֽdqݑ}fS0?@D#7Hw j gQ$Xlj`J): q&,!`LFiЇ> p|QR80'<yP-фMԓЂmtA}`J+?>UHNe;1k+m"Chi"E`XYIZR`U g}_ԩ jF Ƿ%F/& c Vr`EOuQ<`x}OG66 X7)UFlYY Q֖6_>[`"=8[B0hBw"zxM3 #[~-䓛(6/ioCu$>z:æk e6ɲNӣm`՚[>/Ek@f~ \bZuE*5Y!`94 Jޞ`"<̣_Hʛ*L;Rk@Ρ.)Pfh gh uS=sgU'%i I *ӎi,uF٨NG8ܵK|:4¤H䶎7= Q}kVOau*{*H46cY}yVЩ:E=GH^ކE .f JަdnUnRf#v%ZDOn = (;?;/㟯T*%lے߽yT&S%I˅ќ ELGΌnd[ty_m+3$2g؝l\o JjOpN0|xWmMnޝNE,-BWaYݑaJA%|Uk+FuY+oO42 ƦGS3G1;sje#H}“x%>SLG1w\ܘEB[]WHHZ ,u6NLb!4`TjSAِZ6W&f6X??du2D?-aqݠ?[>:ϩ.ܒGa+V2,@y5#}|fOdvܨ1{-x=J~4nG&B+Xw^x ,E0IT3d֌S?K'uT j3 eq$`]bN/#Px@szgi~9yEd J&x  YQCt:6Zo]Q&nuŨqPHHĠ7%ߜ=vVd`cQ^ [~Ċwb [$t홾(ubwC] ?QV7{rk@@i nTFqKN8"F]8%Gnٿ%:bx6]06b+\˚ѹoSq:^VJWuCX$*{ t"~SBZY{JZ̎ƖYxK-NUiԷ͜b )/X.^rR*h* ͈cɲZD=X RYL'VY 6JIRSIG/CRt͡ƲG~0Cz﹑Kl߃RۈA9޻=N,<*h5cDGk;}ț8 %?nYFY,.R&NҋRtN~"w:s !Ox G;c0[vgp 䎽1$fNN ~ȅ9>L>&!s)9G2&2M'P[f ]{Z*8.HCu6ZdU,r$aKث09ޜ[Tw\lpmɀI; ,ؖ/Gwze%Megp놉5sG4Qrgret!Ain^"ȤTdBqAEʚhʿD],El`oHvB O5(tc L tU6=>wRB6fVNfxO{cwYmz5>\+d \50{BKPFlhBe@TbAqtBas{c r?e6L{i4o,F"C٠&3CPi0uJybFD'K~'iE;+P,eXY?|̯FH/i~Z./YqZSgA ;=]8. 2ejȓKWWכmN㙜SFQYTiZ-wUBA-i!˛5Ă1]y&?Vtڞr:Rm {x I`<4hKa pQduw8ؒՓM5 =-2$r,otsةX]udlbF;O4%jMaA1*zhh'Nni2RV{$y$(Y~;IlEw䇤bAA,AI'k> k-:\0\9u5,U2, X(AX;q}J1ڰ^ŏԍRf,zb,s=a~?ܑ5X~4avYPGBjb< ޺M;7ϊQBp\!6\0.kt 9uJSq^?sဤ$Ki +Pvzth#~=0~<lAqN6h'oEhOS,MPЖx%{ڭ:N:9vVUt++]z|pn%ږ4^rU)$9eU5[[آ4% AK37Vg"s$kOuမ)"4J}0uo \۟1A/>%(G)C`리Ţhja7vd*(XSwFǘ?~1k/䱲4lJX%$bR鸶唌VKK˘M7MX wW4wK;摚# k 8F챭SO`1w&{z?0ߘT٦v3;Z9. D񃘰9$D9_IxW1Y\(hZH/9콘CB]i|>WM~L:JHu(jb5ڛ1v,zP6ua=g/z%e;)*hr4| ctJU=sr@ŚZT>IimX\^ʙFKU!d5>W]t&Gy>/} %C-jZbCy&)f VО\˛o[g xL2cz%cKsӑW c.Q̻`i<:g  J$;NuM!mdS{BEh0 [*' #v]5KcǴzh9cOW^:BG<`x᫖Z'eq=ЍAX6®q%)H1#]E';EOc-Op -R obYr`hų>^X>@8eRyFGpƸogq"u2j rM4wq뎤zvPo6)-_sVOg%,5LF &P{9^eg͊{e  Ř;7s9 fq cj 6cQ4bsE)jBi-i^p);*&b;;%Xuyqp9w㺲gxܼLs/qXBwE382/84&bkF6}34Af;b烓{C@<.eq*{.H4m+Rjpdb٪Õm3ϤA+|~8S )e>uU nx>wLȫeqMK_l2_Бۢݘv"{cP=P35\{D֠"yC{Xb;# 5gf_. zy-ײ%\1u?>hC(6*SS<&2k6gd9|ԦkPW,eTA7ƅ$*lx`.7X{}=FM33pnݽ_4<;}Iq>dM2XVAmb!K1!rYWD?&*̋A9eB-,Ps:O =!yB i3hjimDeUR ZmWL3SE_xE}kƨ8 FfG,pwٛ_uV;Ѵ{zo}+Z sEK>j[yAKIppŖ+gۑw7xpCBUP?ojWUyjq|RK#`?+,VlnIVJ1c5OM3Oǡm3" 걣&*~(mt3~VF |trQsFJ'BMT.Ld_&+]YԸ4bi:闣J$+ c$N,w ,~ ?{ѵX_P:-75N@(Nշ\E!6b§0}5  ^jM}D _ÛWvg t"6 9ognυ*&-75&rr5)ZF}>0H~-A)2328r0ݕFh[9pW" '6I. /=JІZ"W~kS=-D:bAZ0gʥ~{,َ6mMN@P˝vd %#$ZF}~nŦ!7Ae"dU,sy4BЃhb'Pv5O;"IQ[ے\Yu͏Q5{Kؿ>\Puh<X5 &=7sk@1, *oqKlP7ݞel` g[Pi?"A22zTfC*7wq(;h@ybv@@ҺL P~bˈ;0NB~ZlWt ޒgI'HH[=7)dP49UI.z[z%[GQ}4(.Щ~*hUzyoQA8iߟ<6Ǫ(]W 3.Ȣ| ;*EL<~yiZaBd/v =1/z(>QG{ěŎ luq„=Ѥ=x+gV@"ϼ \KJz"Hop-?-Y|)6%o,M`Aɫ2i=MN cPJ٘m-O+%s awKeXl;)tYc:)~m){/h ޶..V{9> WS2N4g?0⽻. LņS V_|B8:`&}=H-8Dz]UY2KxCvhb<nZvY.$`jH~b$97dITf7{cu/l]3P ha{m%>+%!'-xLSm"DdNQL5.Gn+Az\C9IF*c@%TIadkm!Ћ9a*yp% $ 8I|Z߹&c g3j1|I&[:3̅ϵYq7}FVV=lSPbn|a8^%5ej7ͭԣl߉vKq!whRu>tb)+ `V.5 ,Q6=FVw[# jgH[v1zH(sr'M7PeXtŶKwʼnA q9hNrZ-dQ_`|^{F"qncߟJF@@v_\HPJ>LHϑ% x酠N~5o6hYntP| "qU.cYϺT׹E?Z't3Q⾲1!el2s#֖ģkj-tp X)[ \ϡ#Q /ڨ34<CJm'5HJ-ǰ)Ż0V5V.*^~m$y6/^u`VUM2nrܳ T [@nHy^ 5k)03)gh%]Gz6q4xo˶1A/kIvpQjalbE45Әtf\ GϹO.HOXd"l^uR۾↾c4pJk?gkS>Bqյf5C(VLP&qh␺Nj²)oH+<\ް˹2 nN?^+5xC[lΑ]1R=:)t\S51:+(T#r#\E>b0O8lrdq"F1t6ݞ[Alfda,\`NH@ ꈐ!Ng -)C!'&تבs  cg3h՞Xd$?a8RԄ^rjrv}+\ZE;e6g}2u_{Mc׊|veJP,<ύZ#'-i<٥reo:W:F9 ˩8nt{|EIHcUJV@JKva,_Jyؔ~Kv$#Z)ܑxzf^apVX*vn{0 Yv( *hK_t68VԔ;DcEb1pB!X=T@1HdJBI,uG/>8j@"p$zDf`w1tshQI[.E:#QjNைҞs¬b[W;-2؉Qj&бU>!-wz/ena/y5zu~J|'odtFSV q6~8Ί)9)7)\݊`+U! :Ef76ՐPaWӚ́[".\UCDa/uyKHj3q1jl<tWK$DOԣ8by\4HAA2TOw+y`.`{<4~bcD*O86!:OרA>PBەVDclcOePCDl1@N Ȼy=ZJwZ< Iݞ9n&. wr VrԽ)rmK 4spdMG](k=U+Rsq {,ckh6EgߨJ.Jr$ay÷V&Ƃ_c/̳qH4V%|ÎՓϡwvS 9Gml;r޸GzYATr<5j[aUt4':܀o  Y\*c0x?LiTZ$Nԅcowi[Jov!r!겧KGz ]y;Է@?VY}!6Kv PCpK~(F%,pcplgIXH3~Oj).(Y ֬*[>pWC>3%%]N dzK ߄FL* [aUn<|gs`_@MS" vglPQ<͢ ʹE\r!e(|"^>m|.u8oq#ᆅP!,נILn4)8|vءXbzbf*maW~~u5gWvi ^"L*Y$@Ptɣv'y\3;-rV4 kEH%qmTn=nhXf]D"f1ߔ\:2QҜo rj ]݆ta 䮘NԬ\;W̼C ߎ;{<(0*Y=POH]PVsW Ш9@ tG*<Sg8zȳn+g9}s#¸4tӊ nÓ2,%8KD0k!>0 M)8dn{d'ټpoP6vi,B^xt.w^~z}a[!bSēОbSsl|Pbů.@!(6mtyݓ+xy>M߽& FxiXXެ1$CDtϲT T~ɩk[{ }vUDfZhig kGL^R׶t 'rv"LdNRxU)̔,-vkkȖK> hy`p3¨,^W=CcK" q_75eOnNS{м& L2b\Q塳0hF}<>ul/Gۿ` ݰiOY~uvF^x̰y14(Hu;3|p$Ю̖ͭU\O$< 6%kÏZް3gJF!᳾'x&c08:V\\m8enig 5Dvէ!(bRXng].P۽':#Z,y՞q סZ ϼ^z2jjy(}T ?GX&u AB)O >% ՔP4^ !oS̓P&JYm ې$Q= fݮwHC@t{k;5܂F#b.XhN}5^D2+6c1w]󊩃(fҢ- t9.Ω-yOG%i0M \v +ԴB†T|Nk/Ǡ%k*X|dV=QfqT&P-n}>N{m+;Uf|}z/AK 1o_~6"Y -[,}/625|]1POmQሾS9! Ї"êQ X|# ?ț0FKXJĊ퍵v-TUOW]up;=s`osz:ox95#NN` Hܬe}j)LH_0$>-?Ū2 IϋT[R9e<$A/Q`*I;pPWKfG$f0|צ1O,‘?h̫ryцXp51( YGf`ȸEXE}xWPS ^4.gP;/ֆ4Kr{-x8֐S#0Vu^Y0v;]&\ăɋ& )!}s1#y!g@Nb@tc׶̟7LO==6% w"@#&ѬFBZ:Hm yϸOc$DbTz %2J¾%tT]7PwZ_Yl[LzH(^'GHだ;C85% pSe88ػ1mGwPqKCLwQ0<~Q~UQwW^Fyy!8z:UXqGDBq'gguRN/"J~Y7]q -X`hC9H`\9Pq!ɥ42EuNB3Dq(:id%PTFL #Defqh^-$s ch|]UCt=bؑ'¶|LP]LT^r?|]3`ȧ= _wX?86x5)s3ˡl^Uߴ(_-ߢ:W}\ ?\[ms*\oJt *F.?hV8|c-QcDYGV.8kR_1s5'h[3 >=A^ND Crs  nwl438X~2>( ƧэK@ z[Mc?ߴ: UZu v&ZF1`xeN̸lQ69~ӭQSGirO_͆4HņflqQh&?IaM|Dž)&f@ƕNwT?K&@&lX%_|N*|sj& %U?P|hvs]bh3qdW7Dxa˃,#<Ȅ,'X_n|@5pU?vyz.B C2|K9v}>F̧?_*O{FߴF&JJuNىN," u7V 9!0a%nZɑhi{18Tqk73k_FC> z5za):}z 8A$#)9:e/e5J]ؑes<]SWj)n詨ኌw|e} \DLNc ߻ ?z ~*⇲Z&oz_$G'2}҇1 AOs@9risBms[EչGG0*fat=E%Ib vfʭ<%,wAPE!oi4f r4vo0|ϨXݫ\=nS+_TWZ1be&BsEDY3CXhEWh3b.Tb'&?9.t0`7 QSjdn,Yq1'AcNB%@vl 7 9  ݰVPxþ䴶pRcBȟ3Ӕ}gO o6;ۤdRlwd0 yHBYjd[n&JJw";nmtFO ]_mb-r@$%YaNݡޙ,=YS04!71ƕP&%35H!y#_$=~zIElr1̓ 4|~嘽"^CKOӱqtkj>P ^bZ=]-tJR0ў7?hw`уfk"X:\? 񿺥_`gݴn=u4&my l}]#gt'SvR U/? m 1`z,kOfwg؀y`P8P Ϝ~@ ޞ^b7yl>{.`f~Z"+ܬeβSd\-t`ۙ=FI)C˗["7 (0SC"#4)8#:#m٦@Y&.+`!3̍>yJQBo7-k)d_nᎼZV %uW6.jQ@W ^-u>{PnP(ןWqiL~[_8hl| ]9 c#3;$\EK@9! 4q~z> Q̽|;t\l%A

!{C?/Ag?кg D.NV:@*ː}^ްH@Ayfm #>y~[Q6݂Tn_*[wy7leF&Z% YoUa-/C̾ A#*Ҙre,G?$\M&'6G`;KGb˥Rձ*Uc<0–k52t_*>{&í[z?VP.õ. \&Rk]8Z3H$C#}MgU%,V'k q)&I$FFu@Ao5.BndEiOavbwaZGơÛMlX͔. ҭa?L6zQ1p2-2l{m6nPͤa&(Q.ZvZ.˛ x\S|4ݑP/Q`*ؾ~{z7R,cyB[wBV{nl72? > r xhĬO0lkvD>n5Sw`y-0Psc@agҊW\Jص>M`8<9r;(IHkb[S.)5],[-Lq\+9nxo5u3}wXwY%K'_d9ďLDJ:@DHXs:h~q!iGƍN]|wyF(eJ ֲho\Icz١Yb#9b7}jjYb3gÕ 9y"KO 0cOQt' DbtSTUˢ nFazۼ9 oKNļ߿~^V޴%e:!X7U3 'H#iu" 8 >7Xi-<:Ѽ˸N]9&[UZձܥD4: + u3.Fsq(>?MoVy E#k27ބ,F}<F*<˯Gx͢қ?y}p}YhuD'b:,9+;.$g쟫 xwI6t܀4 IrxUu]Hv2+]it,`¼eۺ%Q>wσlA"W;U tX-t;ʋ}%in@ƫA= ![7zrߍĭX4}A;uc5eߠ'|) Tӥ@mQ+w=g/3BI/А\xlyN}!B˃u!N!v GQu? 8K>X8A9`4\ Gy&{ RHQW=!E!ʍ7wDcou.?p/1ՠa cj\<4AC1of`RϴԎ*U'),$\I#&-;v$\=hN|7.j8 )mWSZr /wI$(,FlviK-Kiiw=gp# 0_Bpq0+`]a8J$F?MeaRƢ7*+$0pu^2Ϛ%P&{8t5N &sӪĘך^Ge뻚v'qGҙtrh eX\w`%jh*AGFZ~gfA.{Kz92-#3k/u2 ) [,XA8&>Do+I!ߏ$ gkʏiXzYPPC֦qX(o<_Ʃ`T,g^ü܏v'k#ѼGO<1D9jbFqBI:\CNIatGs >WRJ?.iY-r䯫;Q$KˊZ,p2$6M7thA4!S tz5 cE`ue+ p%!؂|>5IÎB“a p)(ges?@U)2HDKԴkJ{<&#n}g】3b-w卐zox@} coXDhmƨ07f8wD/[h B6[Z*/qU""U3`N@,k\+p{~Oa3sa; Z#,?1=~_.~*=fMIξ8n؊))a)-Rod*-UJS,iٹ~-nW:%)ņb<;yM-:mG"ԓF15ܯ{1 =@\q)+Lm_$Kg Y DZ)}OnY5GTI[laʋ EL 8'z5lGe"rq_% ÆoL_5EK- Ϩɦ2)XR[#mg,`%vf MUWޥJ2.շYѾm;!Cl>ҩun@K;[]&p x(R鸉9)Uk Rݯ^ƞ3eMڹ5[kkM}࿔! oeٮOvsp|ٷ=iPUycD+!tBOX-RRthp1 @af0;AL`\yY, {ZC4".|-5hdڸ0Ac|mNoپVT[#Pdq]iWU9DŽ#[W, wfE쬡U#!5m1s`,^R&>խGCI~ji"MgH#'VOVu0ɘ 7;"r-R61Jlڞ_*ԝQ@NRN`jU4$)$:0,g6((>JѸ軗%HU`.]J]|+7g1{T?. ErgI#YoMLz&v ଙk3(;8DB>}'ӟFYXExJV ZaGFItd{7p H_n=rdS+(Bg :j]U=ψA !rԲlH* "?hh C:( +K @?3! h%iNgFD3"H(0VF9,$-I'h9oWx'C\N$}>3JYrB[qo:Rij;4V`}#8q%E~%.e3#ɛj^V|o6lN` גkW 'c_W5׃x7-΋ iEAaDdHJ,6a<34g҉UzZDx*~'NȉO /W"rpkgE` 8ӶYdBgg*~ J3gv՞P.-W*ayPh-|8\lGkW~m 5P1îChwKO1l_F8b?$oX7 ;7#Q)99U}L4xΝ,W_`Kꌃ)XI($ir*01-mi2j_R<h?s~#uceF{{H9{Mh M^H 6+Ps=?aaE49ϥDa8xc^8 ܣboήX&ې6j#3*pZY?VcG#lb"x O|O8/܊1pu;(ܚNJ_/#y0[ H((Py|@KQF\ã@S)WnhU_HƘIQ-?AnI+'΀sPS*6oHubKȋ;-T[ֈJH 7 KrPݮ@Qnp}lU@BC*%:kKw5HvXUOstqs[[߽ ?:.-T#%~=?=չ&?,F)ѧ6WR\dbFN3 cmNq0~:'Ԫ._Gt#'vvxCO]IӽcqZ&|ޗ zL'+Ez 3hj@eGvZR=Oۮ"M;W4WiFXhiVf\oHXE<7{M ү$me1:'{c(fJZQN9Zٰi!z!T !.B2J9mz) X"eԇJ#?1@KAmSI8ᝏ5SaDçN/AKZ 3^Q zP=39Lj ű"\e1^ NpXEQځoKyrϹ^C+i+v;tRp,5h`BxI@kPlԯRw [+89d}@G>S}h>=b˄& 7#G(q򁺕r: 'ӋwC$A&>@Eme9C.~ot@-n`bvJij%-lmXz$ؚFf*e೐_.$ A5iv!*83V9'KY O$6ZqkR\30+ri^? J i6`撋vVGA Q3: 8@W`Eo5ЇuP7hCy޵&m?auD"yU%KfLh:@q5H;*P'mC:P ~)`qw#'u7ߨ䞁3ZWL"h+e !,JWƳpt+FFdiFIc`zb^hQ  (#p~/ل1j`UMy-y|_p@!C  BR,.j{D)JVxxlRlMPY-.U YbqW,t#VGjEu0*؏i{@zy?3Muލ,xuiK@6Ru.$=_!jp][녎DѺpaJI4CX =ʒ>O0zz *5!) @kN&@,H0`-6#69a4R&]6{p%^ӝj4x0RF/x?I3ۊ%7r8cwjfFH Mv԰b敂Wh#gIo㹠z^,3y9Hu#/pEYVTlHIC >ʆ øqXkT $l3m֧Br a:V4Me[ۤNg۩OosNFp\‚e` `rG`jh`ck^lOBtu??'Oi5PMo4 "Nf3{xM{R*?-wCA3}; 뵄_>qjNv'+?{\i׋`:U[Q_OXZ'ׄ%4ћF'p <1n`GеEt32ah.e$U, %Ț._ 4?x'܌ߊq) 6BJd /;Т˧g;J5F/l?yT%40j›FiEG1鏉1 ;+48J2^d,rġSnjԑR6HJ5;R[U y%Ň"K5=Kt_]%VHux;LY>&C&B"߉7çnLliS/=h M$ ((nfJI^̃$f7)(N-kq| ]#AK>̖?ȥ!Q:~ɿ~x|,M8||ײ'95hh1Df2[+g4TV|Ҥj<فؾ3/V봖j>Z73BE6`ypFS nn@SF eӆ1hNh]X^K5%\ICdZ)t NX@d,>K6Q9?顩߮ ?l+M!=^4DL(T?B|X7ߔ3!-a8XR }X+" / jMB&B;}d_5 U rWe͉sqѷf]$DEM &א#%Q$g~xꚹ= GUy9 "p\L[*)jȥKwN^[7ymyB@;׾# Xr}6ᮓXP=Ifj^8xܰO&6BCP_xIuA%CaP].bm8w)5ޑH7+(7TIMG1r5Kkn]GI.ye|+VՏ'Xۼ(zc4!Q+'0jy)C,})cJR73SPwg wSA[#ݘo_-Ԇ$y!ühSg*Na,^<#eцqmyEj%@)Nј\ }t7>* Omάhxy:$S'`oHL ptT4,1nv-$OJЁ Y k2I} bqb~9ci)AtC_V1?Zh7N$]NOxd)լΓF#!,56^|KÐj 6}MLYy|k~-AF~XZ~z^ŧT6e]ݯ*7f:V8׬IWΝΟ"b$ՎGjPVr$ @dl(&#A=%+y[<줏4/d:X1!.b^w`qYm`<2C=YCb):Ck`c󵡰;M&3$z0 mW#ϢU]=E? CZb7OB~_ݮ#pf*CW/&m12Yv@@M}7]a<],@̺۩l:ӎ:YSJ}X1,YOJX<ܳr6 Q0%bx4@J.Ti fBKFLq3(P]uNG/gP Q&Pf ]dYQ}'PzI Weu N"'Rv N&3H(A60{΅, L|XQ[ o׀]FCs Ic!7E& e0R&/x̓ck&R(BL~mSqR< \JJ%Rf{xK"`! x?+]Z7$j}I>ÜAW-4tbrYD}fm(1ѯ勣S X&T X:?[`s& ⚖Ӗ~sכfc@/ĸTr\}q gr [JVͩl<˄kFZjc a DQO:Phd!]g :̖cH շa&!@=)ӹ9p\6 ~Ueypo{~By= !8[7㒊|ZhUȢa> [{V4L OqeǽJHS *dRGxϳv -w/y[`ި#T4M.ȍ_U2H=Cr _y1VR9o+t 2aNҎIλF)r/%3R^0O08.@|pڈщVk//. &8 3ZZ&qJZ- MjLF!*-&-`5C$gcA?tN'| ~@^ʳ~wzG觤"/tR!m1)!?2E!f~ɾ-P*F5g60=klk T_VM/ݑ) ݀Jz_gW K9B1%B;AL-bj?啍Kϼ!a(@@SMTo0:8r),s 2ZyRw"Iؚ_UAc^!bdJ@H}V<:5Nm-U(zTPg@q*M=A4a Nɫ Qoϝ|1\ Er2 3(UK2g C4Qg@]5yWD &|Pm]%SZv"uHg*;&0h2Vנf;wBh) ʛ)Ϝ`@gݑ6`vPIP:F 3czٓ̈c=mm3{4$PJG ~M<&>3>}fxِĎ#6lE(P} `M߭DkKGj4vX.06}Q)!gĹ_r8AR. @yZ^QFqtX=Ja;"ٮuesO$ ;-C0t$/ K`Fa\2mb3<,(Q϶kDK` ho e֧zt !=oR;*[7l)^UƐ,"ƴ#abd]L;d{}0?6)?)ֽ8䈠?!iRV_sw%/M@oJAgmkM<}tq6:Hx7Cfwt;k革u!8ҳّ]rcv&c9pf{E MR3ȪHKT {iLt3A5AEHc`6%MM3?(I9Ph:κf|1DG>UM\eQ"?GfyMҏ[~CT$./k)dA9]qRb,S9P g p%^eȯ6 8Ϙ3q9ָP| LFI)c^{'1yc-g"~B N FxcR> B͒ Q>d%yxZe\`ja#4]AQ( Bb }'Jp4OƞvveY1E5~-DO6P@릧7:߾V@%0XY[t\蜆p1SfalN8~E5Z@=cuinԤ3heuxE{ueyʄ tLW۩fپAq|2GBlbҩKyFshi߰Ox% e!Р0v J[jF+ANeҮV;TrhDdO:k'a|&B7MP"h#yW,U.PxX1%Rz&zDජ@yp|2>@u,ňO{Ga4æOk?$+2/*]{SK TT xxYILE쉢+L_[" a> ue?t@T$a=92D4 T2¦L ~2{bЮK,$]DoxhR+* x* *DKvpmlfВS x0Okm k3&Ъw\$3;8i[/^@p7^Fd.sGnapgb`-9f~v4bp_Crbѳ>mC-"hVѕ|+1T*8[H$7"Ŗ}AcE+$JQ4Jƥd |RzF@/:s\dt<3$<oLrP\%SoA=A#?1sg H *^.dڻpԹl}t8DŽބ6]-noU6^HDRF,<=b+^, |rnFgNlfMv= 6)Z nEfsݮ}$& !ΩceQr=);4";urν рGhX2,wZ- ϥ] Q_c6}W]"Xcm B__\ݢ4:Bz8}4k'q~rLu.,JOfÏafkfQ/uYK } 偩MKk@gjzN:*{Ϧni(ÔI(.xc)NAQg24i໥wy 6Dhn8T(Čud/ Ls_ÆH89SkEgVH/8i%7w,V .JT>py vJW6Qa=|$kS&u\O >3EhN,ɫ7?}L+֌;/<+q,G˩6:;nt@{B# b9ӇyўbHXF Ic$GG#Q.m?4*D%~DKR]~p% }{ w+0aӈjI1>#l2EKXcB_N@p [F^]ҜtrHͻAS@L2\̿vHqv~$Kvnfˬ#~dXA31L\k%? 3*vqan]8'5v"xXxaJ'yK`9-S/qqkh)L.PcIOwY]dX˷2+ <M2]t2< c&}qq2́=YW )3d/n,m{x'](fOwz$~E,S8Y !‡#8̪p4&}91̀Ϟ.W~rt)JE duj+8X)P!l$Wm_u/ 'uї`g!O|:wr]5w;]goDTX$ƱCe:u7H T؜gW4pqU$?׺Qak-:٢7Q'.[ˆv lt=U_6;zUŻKJY |S/e7pQxwefCv"}W ,x,|ȄCzx*#F|Zt F<؛|Us0v3~V"ɱ/̍HA<$Ztw L4I`*dzT`AWNJ>Z:3?=eq>e6kcA9 L:Nn~-[|e J@ < Bil=7l}e}NE Jne 䪆H> 91M/dً{'{uݎ=]a z7n/ĝ( 5F W9/_0+X[HFOp=8^,j-9$ӹ'Ne= 3C!DG-c/^Lc6/'!? Qi4|?=~ʄA(/vrFzV"PMg09VjR8Dlq xT! x(9fl~j%2ѧft6jC44L|.$ַPoCZEmCӊ,q9ޜ% 6<-2v6x3-9EWE~iI}nelbv}X^oH,wAyc;H6lgRgUtډ r^ُnCjlDo#ۊZs@UuSfW]tH z6G5zP3kYgd8n5FSF=*5t??]ȟJ!3dg:a"}e9ވ;n%@?)\[rR.1ka'jp-MT^ kGDc@ꤢke^\tVeM2RE8T-ù:fJf`+GXg mn[S.4j 3Rkxt:w{!"YW,y3/y}geX?JjoͭM]{{ j,~"zQ~'Zw|{UGբ=l~V9)Ukզ-CF}jR_h v~PclC~ѷ751Vy5-5G ?je^4&5kU7ʼn_kgBӚc9~k퇗Y)Ɣ*h QMp {4RO15"6LuKME}>rA}ܶ]Ȣ}SF"e>I,x\={hG.T^JCwǢt5ߍ\a/ʡ3h gfS59Iz7H'*IZK[)w٠g{ZFԜߕ‰pDzֻFmn]]5$. ƚS;6t7%k=[^.L+f<N\O(U *J#ɹ`gq?@}܈20<}`rC/h[#c# Z` ꍡ@F3L$]I:,2oۼ (Zݴm@Q DQS>xIvފEf7Gó>mKIAn.ڇ&:b73fv0꩙ghLG Z\EJ!ʼŝ@(HW&!$S,6L1/ #㌎0{,#yz* @dZ^E}nQ7$pP\rUV:-EJѾ$"d"5%\9߬eRǚjZ*ɸѫ1qU }'MjDle !fU'}/Fd!˺PJ'ڍ&A7IW C*^&<؏yߴkpޓ%u 1GCDf)0 B?fu_3.Ԁd0I*UEӻe:{8Q@UžM% Iv9EB$@?O 0u`{ uAi,n+#3a"@Db7/-sŰUA>⛎=j~UR@cc%#3Ҝx+t|E`m4Q,SJN/ԋ78Qi'F7 T| # L1X[TAEjoϪq9Mojr~ "MJb,о_Xh)i-b"R| o*-I ! =Ei %YgL]Ni|~gNﮍE#J V6HWؘq /Nk;j6/΃yj]QLd:2K dgX)I$M?ʻX`-oo]|հ Y޾ed8y}CD7F}}|*t9n\bg{(ZqĊj*{ Le佈'9[Zo#&2@ Zr;}α, WWVVĥ'uL(U|N%,ϘT}vi"V|Zޔe{ٖ4o7afqKH9o^rY\Nn#j"Ky]r?~ !֑ OhBPu-{n-\k$  jcߞ/uCs_, a9A1Ÿmb4$ yτF~l]6QD)+s!K< 븪n7e=:Lˈ*M._]Xm1IJYRl{5+~ Ib?$G6SWҤ ۈ=B ɩc(" S<-s\Uif"q N|Me(9<_ PT-ʁ )C;Y~~s)љ4^2`[ x9 w;c.,ėsԮj[P:N^O ?,teUpvš]El/?Ȩ$=20xF*Ҡa(03 c6d= .@XOUwy"bxQNw(`W Tye!G !9a$Zwg^D9ǏvJե ĦVx eBTkWs?6/ޜR8k.JyЛh)3"2w- JV፝:]j)#98NS0oV;'):q#Dh Z _'I?S'CR9tsb?Yx%\!:,d$!M^ȵ0g ɑrm҅/cᥡqHhTGp*~0I\}*YgRI04:j4CNƖ{p2Dj*)wA띏Oҽy6$iՓ6|18rd _6^ҤFiwvp/ɷh9gm;LDߧ3% f/8@]]K ٹ:åS4D7UTa W"o6"h{|) G\Y"A`S]1XoU#gah@fek=e{ dYnayU@/+B꠼ ߀Q\qwPZLW&|!h HyZ @LZMJ I-x`hk8߯epy +ktGK9 l*[T% lz b܄3 k8%?r~M4rzh ܒ}oٴ Wӎ<)psq`UlJq\*0eX{U2W@1) PA EٌR!&@|0Gw(.! &P!ո9}%i\X efհۜbKp#ۑC``\L|7EhU{$MlfeR˶9 HT#.G]~I~aV >3?BzVVˉr9^j##W!鱋 QƲ"v_oV .حXk^:BԪ@߀,gHSB. 'A!K͝6(>rdZOS}SmuٜO4?2a &#Tpo$HjM螳'rixƄkІN0"t+B-!MV {, j ڴs@-V yn8-Q!MV6Lx7 ]5 ͛ʫȞ82h6:շZ N)Qo,7skR@S#>'vAnOٰ1=o0@u&*_;\*99GKvs(o2Go;?$ܳ K9г+*Gz`Le>F.)mCCwK3B"LX^b'a?ŽcYG'"`3i wU$`XmsU4 K#}@aTac e3iqԐVqNgZTGh8,ǿڣjr7ZiE߲vM]^WXr/'hS8&KM6hܡ7 ¢xYJ۰Q`=nVXM 7!~| *'HY,D*`Fr'Ѻ-  8E2bQa[w=s8.mqs['cU^Ԑod0o Mօ/M\jQXn8o{ qb/Ow36MxCx(T"nsY~`/|W:JVvc"^Qr t<i(vGW/9?ڠII}ܾ4,Y8KcWhg68n s-*}4l$>76>ӭY9ܸv+uUq\+v2nx]W!|b6z$ZuzK sT+u!$ MWV!9R*+jim*T?u=ο꜐357n,QH_,8^x+j#;~2;ԏ/*PD@Iԏ4@Tָ8p|0)NED@ ;ӈ8^6o+E;#9]wES30>x72R?CZQwi!E26y"G\4wgO`Z sGt!!ɑ[Zu!*S%Y7vs| }x$*ߒ%7~'/&ҙK"$gڲ 4K[CFǾFHsW:}|0F*:";TFRU#9" >WKQ#Մ0K Bh,@L$aNG !5n ~KxW /x$=ô#ͅ !.^(9rjKHlJTBHwzWa8;} o28_,S>ċ6/C2})=;Ύ{jfu{S Q}L"2x TQZaR3 V|vm ;>'`<8-- 3m?X,M!pX +y 8fiqI2dtN/Sr33G>pt+>+zM^<=DOt9Z.DY%+Pć(WYאep };eB!!`]0ΜĜtA]U@/^#MG$!vp;F?8G՟5;t\i?DZRRZ v#-'!,FBSub 7 kŽokExe~^~6=Ak(V=i~hI1E $AK8}3ٟC0[UuL z8DM8#~ M0Ee|[^ & %R AbzμU^?TqحMSlsWsi¢-;V4JyGutoe5YBU,G٧szbs'FBrxD/|&#ތK~! G++D&KiQ)G۹%!KV%q|8}T:Qj *rK\Mvo:2+AO*DT[)[ebn<;1G]>K \ht{iEJh~LgsE ut;^~׺jE2s$Ad}JdwS~{\.~>1%RMǵ$BVyoc{~#uBR&/V^-]O9 ҷ9 A^Vcϛ2Ш៵+OB9g/F 9l-E~xQԁf+7CUw๎N!m+O#p6aO^ ~,zPilaxFۓ?ĵaENa@dP"gjVD ~a]woQՆ=(fF=eG6\#ћ{H\U{4vշÏ6f˺SCPj$T4AZEvg.X :=󏙤۟*9%*2" [>d^b`lARȁ[-Y+ K>LNl?ZM:[ן-asa9P.h>U؛ j{&Z$|HPh(Ivc R6(Y^$l_+̆K Y\*!#"4t"tŝRPE-]7J̢`Ǎ}6.-; Bĭlx!\Q U/cwpshD a;]g9!\/HVn{Q dmx݉G" sKP+c$Njk@3HBr-,mBl恞yad=AWKq A{iR @Vla:|#7bhtob6#bO tUfJ%"31р vZkL|ɼ_X91DOV +K\=~К Xavվ@frHr@4ąBk%] X\b?)aPÏwbXj5zw_^e%R@S(pmg.,8mLtw׳ѽ,_@aOIdײg H%s9D 5ǸG:"EI>Ugn3ܜhhN!lrU=ƪȡ%wڈPskx7A<$D)Z8T Yջ7J۵E['r%Nu} lҘ+ )wKd?:bϫi'7v4imn2^ M4G0ZsZ,1=Qڍpkg_|g_B 736/P&rxz~0Ԓ@]|O`ӄ&G?P%1p;02ELiRBR~ (G6Q|Il < G7:^OV\7cי0|> o1j />hÀw<S#wzYāEJNQI*l^nP7fӈg\t;k.!*lK@'IaG%B>ֱ #7\RەQal7R^hhD_)TLΥ kM!1bI%]yG6[ṱ xSM,(.&£u o. ycx,S[--7\!|reH&78|̤cY i{d F맂L'aZzb|eaxF^!#G+ |Ls? YI3;r4 8:]1tWZQTU \ɠ]# qkd22J"YxhiP#QfŒ\2oM4pr6%!HoZp.(?A)3*onnĿx~(6% DlД>s"6O(5jXK23hjz0 d! (. zEKU,h\KFQA178rFwqa u`v⑞?ʀ(hrQ%ҴΣ\>o6O4+y>mk"^n]6> }G`*ia2#e{z ǝe~WU TG 5"Vaʿ2IC\Z$ߪ\z_WӉ8BNú8qǽV7VU@l68[a.,p;XλccPTzS&M:5l[!L,5K7CxhTPpd=8|C|b ~dT<,ϝզSN *FDV[<UD|Z@hzRE әvsʆbh Dp2%;;\O"'tk姾LW,ba9o%>T?! lqq[=${!Q0#=b dmj'hzd6Z޽V:b/}WNVc!MV|ar qVZCИ]5,ek龹T̐ڽyr`ttWK{uBXمwJX mYP87AoǏr+ˮ0  IE݀ƌ kIٿAu! zj.Ϗ]NuGN1Q*X)o j_0;pP&GnHZ_TwbETJ1Y چ>P(8^q`>6ϼʮй/:a TG$7[t[0k1ns\CQB,]V~B(&&S6Oz hEgy/i481M4RrY ~5`IwawG~8 sd~R^0l5`nnVUk-ܽj0bB|xùت' M1ǴwŐTmoKFl~䀽Oјޘy[m'0,>MGO?g,E/*zhkP.@M?{$r<Ҝcʣ\m 4zD䜙h|owIsOPЌxͲժF\yc{7 쀮z։T <\xz ކ0,Nq.q=j珗Mp3]s Cڄi>R^W$ZȏeF*۰q"CWvf cժ5RBd)UXY[sO ~6[> 9&k3αt&$x۞izm~u|w}m jl @.b~9YH\]ԯVAR&mF푈&)H$˶M;föa/naj?c.8ѡ>mA櫆ͩc+0}Jֵ u*^j$t\H51kHG ,WHLd@P#)`(*sVH#8!ȦUIV: ѯ"(s1|)Dϫ"3)z=&3W9؊ og^l;Rc*]D׹_XH~veD pT->l W8i"Z R&r\{ HN7|\j|{~nbƀqo=lrqVYtJv17UTbYJ *խ́ǁ#n˪.\Jsǜ1VQ B{`ϳ=/>ɒ/U]mzNE]P:I `^ M픠κTNbGHS|P Z߄o1), e'F5bǸQƐR ]VOMwt`mC I- pKUA+FZ:u,0|{I%+=vQ 3sL\xU!z67Ihl ^ 5 zt]ZQ&a̟3RSurt!XhG?M&Z>uÏ"zӰ#nLO@ {3l+ H!"{)2PH( %?e:P` r5 T6'vy/d x?M:E+lK0NX]((m%à[e>MҶjWzh>4`׌;!bΓZͦ&'fۍۮmUX{"Ce)j)F7CtNEEwϑKGLް $[!-=z#av?{P ̮a4-;bf.q6v#!a`^bKU9jUxFY>0Qܗ)Me{Y([]5+X6-o C@mg2iIy2mbZTAlTD^Jqi`d2篞%6:Ҵ4)6`:k_EfyPFX KŀAuIܷ6#b,L uHQ`jٍzBdmdݸU n;q)7&?(I fl[PR@墨(3 ?HDmT1Ԡ.F1f9h0G a?lD`Nc`fn<:;XѴ !%ҨRQ!꧵zazFӬtt$8M`k{l23ʚm[;/hJ*51PR r!EHp'(y]*CJ #g-7Un(Q0jнX5ypye3y"9r 4860y+s{q=&w]˩us8;7'jTe(a*D@ R9Bp̗F/ r}33ʺcpbCOtFm(IU% [8j:"$M2tNDip5A"svV`qC`bi[~_HBS-zy4BWt BGg;A-~1fa J}cD(`q(Ȍ)i3GgJ%G}+ǷQJ*7λk&OV Djit2ȼ_ދ4 A[J=t}Dܿb8/dP;:t eIԪsQ~&ϦU]i`wvg5~±`JEJJWɜ0wћSv8{w/‮[|į( džJ.ݔʾX"IaZn ؠ6CSh@YL;*rX'ɑZ /Iy`Ԝ pD^OtZG7_؄=72 f t׆/frb-"+l|]Lc75&Yrboa&ΩkPf!ڡ*ՠnuXbMԽL' ,:M' {7MMX`ށR5s{6;P}ntEhfrt;I'"8xޱHS'!Ljt7H2dkS(Г&p7%6,^-]qMP/l j6ihѥKl{=kJBWpr;(&ӢS0`Ww^}3} D.d ᝨc}$\qXDYq6KOV݌/SE?{h‰T.ڌBvdr;X wԣ%IGY0NqDEgZtC2 J0,8`w{霎q2$햊xP|^ٯQpO'?w!椓 t[lJML?NLO{6tw,O.z>MnR8B5~GsE~QRȃGʕj~