sssd-ipa-1.16.5-10.el7_9.5>t  DH`p_K $ƨ qyه[T28ۙsS=HL!Ğ?Yn.0!*ngmb +'B2@-s(`~^CA n;P=ߦh%V>{BV md՝DfpV*:>-ٖ.j9Ph<4s]_.Y_BI%Ñ;8P)!)%/j:SIɽHFUpƩWC唈}RډNj C=X|m\ΝM#b}`x/KVRǺg):n2*ۑAF݂YWJS#QԖ~wPadB4MrNΜa"xH.l-v(q!RY>5-0 #mH,|Sp.ܟ*=Օ [񗇒4IqVDŪbpEˋ[ϕ:vC|<7 H*91d1affeaaeff15ec593fc4188d8e4e271c7db54봉_K $ƨ|m\b9sUmYqI?tjS gýMHu΃u(?KAD,A nEe›/dxYt}JY\9ar%6ϺڈoX G"꽘@:LSe0L9(d:g,|.C D8u))~?Lcޟ1}?lܥY%\PLcZs&227GIrx_p>GFޔҐ8]_#Ǹ7Z*FBgmGV >= $? d   : "?EL    @  @`TTuTHLQ(`8h?9d?:?=>GHHhIXY\]^Nbdefltuv(wlxyY Csssd-ipa1.16.510.el7_9.5The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._tx86-02.bsys.centos.org }CentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $hK_t&/A큤A_t_t_t^p0_tå_tä_tä_téf92936e322214dec4c382024744cc1d62e87a9159e512cb45223a833ea4225d8fe1f5cef3282069434b8ac12d6c44488c862c976966d5db3422211b842238ea48ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9035abc9b0923eee64da922cdea5672ce8ea303519f119a8a7435a4b8c3b0154e815322f84449761809328f9e348d27d01c6f78365c4afd731a17950a2b3acdf3f203dc4af2abdb9088d7e5db59bcafa90824fab9a2f4e60cffaf3bcebd9680d3ddrootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.5.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.51.16.5-10.el7_9.53.0.4-14.6.0-14.0-14.10.16-7.el7_91.16.5-10.el7_9.51.16.5-10.el7_9.51.16.5-10.el7_9.55.2-1sssd1.10.0-8.beta24.11.3_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.51.16.5-10.el7_9.5libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7edb7e9f0f3d48151eee9ed67617139a588cc29b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=1db00a43d65f72d5c99a60f653fc409405e6546d, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER bmdYW=Pr?tʑ{`%Ϝ"::WYJC3O3rvXQ8--mbT- þNXIxG#z0*D$f ܋2W<N`9BnzJXMS1j=QD||^8Ykx4uJYⓦWJΆ]:9ڥ*0%ٚ!n SkS 8Zw&u; Oal8"i_;+:,|5uzJN!Ru?8焷{*)iݻoohs*I,՞ W5EZri JzWčuZ7> h(ruT8+b9t|~LcrC8"4rabGq?_ɀ) >XꝹ*1"rTe\QzV/ג3|c$>4Շ]k:]Is† R^Bw, ̿rژA9|S$`2v1-K×UBJF@z=wC$_llld|h vӤ:L4z>RkΥp=OREU;DenIlLd%PVkW|@h^9!l׆g L\НS92VgdAp͑=?3|Lq(w h:J[ر1~N%51fd> f }AޜRg`=̹'c%IX \2oZUK6JStEa"XF \VSwtKKjFsNJk|̆/\iHhB1v< !%V7-]JnBǜ]9gxo]AAު|$ZoɥUl=vy>i?C c(Wx&֤C0oBQ_QjCtlW*ʲ 7E ^վgGuƋN<(@PD} Hqؖ^LR#B0";gpb؄S-JiQ(J c5iw!\%cSD<2u2[^H_]I>.Dㆧ[BbNKPvk'sƣRħ[,(oi4oʏYǡ`y2hS!Ԡ_8('*t.%܀6ݐ|:;j[R'qt['DŜ7X֝a "Xu`m 낻@ ^@>i>^?ksƗ}D&[PW9+D?ZsȌtU@2 =?aemn~/F:E ʝ1dd6Gen nXG;ۃf@LR]&t>Wb} G6;~pw4oGP.M=)$ȩ qi_bRI25x&DANbqLTaU9K&mT2vc' #%qZp%.Vfkb"kyUB>xdY]΃ K[*;ɣb67@Lhğp3R&nՖE[c&9?sfu`h+kd :P,Jek48j^.+ԩJ2}Ѳ>K%#SygYc}Quk֦ sUhZ9Գ8 |Mx[C7LdϢh\Ӧ5y.{FfQK7~SҘB=9{W$~֪w ^MK{+Lgf e)dy󅞿',Q!Rj-PI5&XȾ\ybH?;vdbCz8/Ns \WBGE['XGKjEz,}ʃ^eK9|' H̀r֟kPj{oa H'k5V =kV(@ I]/dC? 05"#F tք c|(5m|>PҸuAF0e &nQZ@Jdq^zv,+N(KFVgʗ}A%s&Ԝ%pV,6:*\uG(e uZ~>Bu%fcNN$z3zӫu')R٩5|bE)yNv؇yH+#Mj>]'l]eIVix߹M8I(VÙ`76(ӳ ]w(`hbD0Sw+cQT T,[<;1XAjs.w)srjC4 &Ca~ʔ0i5UD0s+29#^u}P売!4+܏v|/J(U5b]Y// `E^Qr'ž;~vCXec`-A3=4\ϠASDGq[AG9m~a8iTx46hˉNvGPLQI-%Cci+ !u˙$K֎RW[tr;L )7NR{ckD@1^"c;ʝ{Ȭjr%]UsXԊ@.6!) GXo5DHo܏0) n2K7Jl6WV~'q@$S;&8ѫ"EC!z̊:!7޺$56d[@yY_`rdH 1 Ul㤝kn=6\6&6 gEtu8~+jHiA{y^.LСD]VHuϡ7uK`"D;;m.E\v.;E$yM;&zf )UႨ$p/#ǂLLvڌP ;<գ?l:$97$ d w ؒ d`a!+  4_-z;G"mʓ>W p 6j_G(!y(S#e n3AB ;C| NdޙF )6q,aK,YjΟK`-)oN8i]#d9v:xzܛhyc M:n؏ k Պ,e\-B>c;9[jH-  (6Uw>5̜[}Ŭb-`g(gTzs-9SzJ q×G32אyyOjR _PIUwze> x'n,&tChLn]}:-NJ~T;\=4 G'u尯%FӔq-74zӣ<|{)啔0>$Cj\918'+Pm`ALp0-'.פvJlt71?O9T"V aY^UQttrakQ^AA9xg:'{sa԰̘NQr+]<哨`=rUmmm- N/h~f?zR([;2C[r~{Pˉ2+!WKHwCYE{ f{b")OC 5=^D:^1z?"0տ*_рcقs/'0.qvHJ ,q^X XW@K+1g NXOBIx*~[iKjjI?7d:j\Z RfB i;',hEUc%#jC7 {x v6alYbʵU:S?:=K[4>&hku@ (Sӥs>;h&(99h22qLP-F_m` W'hPم,H4q޾M2O}gR!C74}>O  aLAl~izud*Ն*hV==v&-5][P~ ^%Mwv2OEBKkdU5]&a6X,$3(f]7T]%2q^m_qE>{9r@fbQ(<0\4?ĴzBdgٓDo@2~0,BI\ xP{f#Ř*xw,U3"I,9ÏzB *9sVy2z?͍Eu[QuS6fD\WmlБlz}rUhsi$&.TRclcQ*h[TE `+JbmjA*զRQ5ou9a;yC\N|зnszi\ÑHCdA^SN MuoB}9W =Ar38N)@VvұzYg&=%>iZIi0A 2hLOW#\67Isg_pebUZBmߛG-A[EA{hhV9f˿[F> $]YjTkW MtWiKZcYM6h-G 5 VCcsQ@ͺ;\4S,m°>@aac >Yhbԕq7Ϟ;(zBHɚSǭܘVG2Yܬ=FJޘC?P jkR %qx##CCH+&Ō %{v'ɞ݉!^E!*|zoY0>n;S } 0$:p"X2.M(OT#*=髯6kxX@ԺنjyzH c&%;rπv]έAܾlg t" Vydo 1jg`ז6˿mΪ%cNkuHA)j)ó}_;4 hzX.{L26~%g@ht* 6= H@T.[Di@aTW!|Ns.L-  )_ xzY1f.^9doG(6 c^U,0p@XW"U LfPiGs;nhq%Gu$)x@)%a{ xc3x:90iUX&;"r:/~ NR9Wo;GvY^x\o.NqT fto|ۻޢA/FV^|.cD4+Ϻ(c B6OɡEV^ňE vdQӟ2qq=]e` @$GykBI#E|Q'DO\i/a+EclETՑ.u⸬hg*{%M>8=%Se-]Fw6ͧrk•J؈DSЩu =@yJ2:؋VKq tO h 1ScfM>8@f<2QɓA=wfN4pSfWu" !$\#3<0@VýfS3") Aanc0O)/-!jzd0i6Qx3A5\H~% $;O\@Ϭ9 \p9AK5{ՆUQ@GPTҘ"Ώ|^dRJQơ×ÖQ$7 lȊ菩qcz-n&~HDl,q0, $z*F%Z܉.-@g rf6jMrΩ)ʣm$~E-,j6ކ+N;L~Gn ?,ߺ0w-gYؠ'̳gnDѢ1ISe yáOh}*iC>~@9[_`e ElYvO љ8tԐjj NgrYZv_N?åFY⭃_1Pdrj^ub=u= Ҙ 6}õw 99>[s]꺋 *+0l=T7<*o}e0+)Cl:+I@C* ڸJc75 Ğ":JĐ쟞b}ܳ/SAak(b[Z~X tdbrf_`CoT|FIH ׀2ߌI=3H0 ܕ(h>I/)W!3Odiیq%VV)]c0\&IU_XZ k;.y8o- i96"i!'S ]~@YM lnm0P@=Tҏ{h՗Ǜ}div,[ZÏIq)vfUQ<W؎M5fVPQ.j}"l~_!)wzӍ#] ]QnAc#-7[lpB&t?!&%ZVVd9{$g5vր>.N;a1f&D0On2q2fL*M]kf2mbOu::aNmAhǎn^zo|fY@uoª M?9<4o,8SC>zf}sJI㍣m& Tq 5i·ȠNLLbܗIDRP]QNc Pd7T2&>sďVU}i?[ݫHG|e"m%Od`e$m*swf9A< a%x#rQpIs;L* z0Mw`e@ý viF|2a).\=ϐ»k&5VY>>41)^hjV3-¡hkɨfչA/` }oZ_ v⡠2IZʕ?(DxRCbWmp?< K+xwVtā')&Or_4#oU|L/Ry`2fZ,9S̍ὼd9NI},!Y&{.vOxZJfty:؋9s8DF31OGs_KH9pRI$s%uI*_c}7-//S 殘$lw**[PjJ䜾h3M]g/k-f/4%7iW:OF,?Pڱx c- 8ߎ}z/./-T$zA~Gyڀ^*{ue,\6udY0vuXa|j1Uڶk0/K{/{ouk\U(吚[W({o@dІMƒtfZCZ G ;螹2 giѣ̊" h)t9vʗ2K;bn+KI0m$p6FK6f;妕`Qv|Mv3'OVQ:GyS+rN:B)@V6սWDj52T}.h%FpYY-W@VzJ9VHӘokޓ 0 t ʅ"֗}Hh|dh qE#%3)h|ut=pF IM_{ a&1rRktO~07vL%|  "}LMwLʾ;07{V;#YUgI|ԁ$'FƩȃOl$=ѢvRWqaw9:ky@úK 14"X&w$<8]DI aIQ.COWDΕ0_ʎ2#ޠ xA6$h Sq{B\6,(Mvaiv0G)7D|TƸj*$u6'L{߻ʧnax=Iu'RͭP3] E6y^k[t!۟]o^?ǸBd#k8KzVDs0>YG`>9\u,O/;ç\CC|R)Y]h(-FgkVʍZx*~)s4>HE!("jі3o(uC 6bE潲/(^a; 2N bWJ2sǂ#H$l,J'4Y<Qmyn[A_g&_t7DBU6[mtGzCP/FZjM⼽Gs-'{>]ktY;m9TW!!wB&lEBn!멯蟤0?7Hmۛĭb.B@H$wQ.i }=L.C !%3WL}a&w{{w:.sӂ/i;\t˶+}|?TPZTt)X|GVid - N )pN4]l <?> n8\? vGM%sp>"EtܒHJp ^97Cnvˌ;C Yca1^/\N$d 6Gd[/+[Y:"LK/zkn}e=N`9[ؖݤXuY PB~?>!όy!ENxѹJiۣQ*Nz .R)nVib*;pͫ)Rg*NbTk^Mluj3ue<%rxl5C:P/m`uKX 9o}iL&K_vp[@M$,_ #9[Ch8'(;`kNl1,z03Pr&3&"a / vI7ǧY)CS:lO6 g!Eb8 }To3:Z6|[gXѷm w\bvwbkUDÎ8̀4Za gxV+weNCe!ޓ" UUޔXkwWǃk&.S(R3?kŀ~` sǣm6ZU]ΠM),.rӊ3_L`M +چfQ iS 󢺨:\_qtQ2[]?q~a dбu`~4,A3- zk~|ɚp؉:n HhJLb,H%~,H~KE~dewj4 5C%@g#bc d8fL0[5,eIߚ .=:њk^8ggL[WY9Z"v`C?i~ۗ-1uQ\$`,h\d?\8ciq7 8f|qS Mω/;ZD<ר\8]# w ؅"T43 \!ٴ{jM`U: ~D7T6>Db2|BĝFsRKQk8'y^E&FFٳ=n΋| ɥR Ek3eÿJ);#[lG}Zg/I7hRm<7ѷۇ1i Z>QU/?4x[z 0J#ujtz~?',N<.طBgF"Ddqp!m?Oϻ¯đa ABܜ-jʷ;Ǧ8FW_[09BtxSTZSZC~L%Uh|MGd[X )m7CRJ9d)՘#"ufQ(Qޜv^HZ(I1<@nVv:3kh{.7`LN ` Ss)DN7Vpqr9[p _/i12x9;!<[ *HxܻP'W^ 7fJCWa?˩?0Hyz-1Y¤7tFfJuiH*E^]mbo[m@/6CGaĈ"t;`U|IMO$R HW}p;7Lpms?;2~A95U:NS֠zG;(Ll/cIWt"nz pV ;C3O .`$,.\[f0$uEEJfHU 92}, Q40#W.՝I#50؊텬g)RKҋ*IvQmhkk% ?ǧc>ݒ!>mVolTMi r]RFcȬTWT.ĖŢ 8-ȮpsN)a3S`Ր"zDK\ ݁$P@)h`(С7Cf!B(eK W&_"PxX2Oy4 :bfMX[<` gC.w/ LXԆEoXu-%J PY'|;3m] L%,źHfwv1`[ď2,6Jϔs.Tgg/NzjJ.:;4ѪU}՟%uNS =6dmJgČ#HK|NjoOruYѥȲ/1Il#ㆿWU0xc`3Hoǭ4i@(›`?S6Rij À1*Qj3!b Fs5EF6xM%;6tT@=U%%- l^rvGu3(BOn,Ƶr"kt4k+a4-o [Z./sB=JMcS s%5 \H% SC\Bb^ @kƽpsl "qQCVe?$rLj8pF aLQFF&4u+/)FƛT̮iGTM%$)Uok6RCm0W:NaCԅ f n:~'EjGJӛX`gJ ~;q D0o8 ,;xԝDZœ8~:]NAv7 `xrWΓ;[s6JPD ;W"R@ldHYayqn qƏP}C4c[T}r2A3WTy˓怤n9 ¯p@Vhix;׫ӌyY^qDgM|Pjf5: 3YUTC\@1AQߨV901FIaݰlѾ7%Y0ģ _ыͫ%op u@PM+@\ʼ@Z+Xo5q-u*4NT[yAOǯ-cz(zb Ș/Mt!kQ@jrfyFNƭ?V;G9Y˜s:"AX}Y_qz/\¿Gj%V*i-cJ?Y,Rnt~pҁkVx"t[hY!HHR/0xo37lid="BBcl:78qpv#A%p5Ql ?Wl PP i/c&-z&51/n57eKSl|qロqX[6\ty҉\ݳml+7]q [ X72d En$/k%r[ ĄcdrڸKDZ G ?h4~9(J8&U ۄQQ_1Ӵζ(O\T?Cw?8=.>ӱ SW;9@h& .h3rKkΐb y13V;Q(*-U)1cD2/mm5ی;#f:W_h̊Ì#!c#l?y@L0uޥ)NYʩ2/Dl]T7;TtSsiƒg&R:@7_w-|zi1Y0@Ppf !vH0f O>vk?\|-T)jLimDGS/b˸Z玼Ht>byPW:ۿ嬢(н:i3:6SbvQgq͑XfB@0B}ۼ,h٦AXi,g 3j3J1Qyv,8/ĚvS g ,pt.QGb#k ș)ulw7x2&6÷TlG8?y{׆j8T;LoGPXpO|xS4@( ؠxI27,^j3`ssu/~dw6)ˠ[͍1f橛P|, F&&eV61ʣ\ ~l ‘SLn m~ODkՉBh4~7F<yd.V+ٚsm4kZ.04rRj\+}3됁%/=0 tX|PwGt NIcNa) Lܑ;a־<hϫL;2Um* NP_("mJ.s} #STdϵ/9,0hl d.vKIXDq(lI/$ ݥ9} TBǭ' ӤA_ˉe4f7j3EPwf\ yz9T[\gATyBô=h\  1H>lX]7sHKR A76f?.5LlT ߆vKז?X 2`VĨ5.}~zR!|[co ,ט+AfL0~#(_:Ĕ˵wݴX>6j/*ZuuIa\w( 7)mF,zŗY2}~-#Y<*Ѐʐ;/w儹91ѯHe8vƼ Zߴ(OEpOON1[K†n:-$ng+}\ }9D; a@Ԗ5}~0Ez@zG}}QF{?:*LI:g>̓,NH;8AWPjv2 RR b-d.5F@W@[!_a[ugp o,Ӊ/ꑒN,mC?|xT gX[-3±Q;pd; J6\|~ fÇ٩{~U"MRqmbӧ](?*4x4,eS (W2"!GC yKھD:,`ؠ8nȱ0dQ<ޫ*ϲG#t ;` "JQ  p|6ԈOxBlj ܃H'Zojoڣı'Ax%3@Z+jϊBлKw(A\ s#nñ(4EtiuҤ3e6'eWjF+w~Zch[sFһ~rI[ :ߓ&j7zWҙ(&L.O}w A`$ŸA+Ȣ6* ]OYY%ywLRt'lw!O|!+ؠYPDbی>\;?_][UA{Poo@E(6Opp,zZXN87/Irn14[%f@^g6FFg}  sZ܋>ˌcY37dc( Z@y?HW+ʌԷHo%@?.PIXtmD.kib}=)foAA4G#JQb8P բlwmhcwT4[i ݠ-w=(SZ@#o ij@з8]F>j?d5, ӑ&A0UvYd#׀$ !,3-Oϓe^rc,׸TC!z֝"5B4 >shGpqnG09I&X_E\: ,f( w=ѽ^9; CO$uP^ec)vS~$9ꎒ0Zxyp@{:D N/+ *&Ԛ`{\F礂$.QҾ_ -.u~)׎SMjH< R{8,@͝-@_KO9sȓEc|sqRS 5vޓOɵeRht&00`WS 7c GQWH 6ݙ5iAG'x Bc) diѶ S_>0Sp5<|:eĉ3RQ;qtlTW'H ( ̘~QKg6_AE R}T__Ϊi}sKhFCF;x?׭yJ-MRhF9^\nL e ;Γ~ j~2YMhK(6{`:uŒOo.s`fؒΕM kGLyQhE]G0nx93%f`\jBk$͆xuzl8l]Q 7BqI#(mdV \%$y8Ubc@ mFbMMԇ=V+kՋ<oΤ Ng@i8yK,E},b9Mh o@oY}1#< D&zW1-,7*7PR4ݯQu6zXqc UC.2}1F I Tt2jAP/K\݊{'mԅ 1XL]##S~2fǍE^XH/ȢJpe,QD؊ zXZ"^\'LqN̋&S˸ [83SkEya^C䬃υH"VPqaI7(K4p eG|"o uP~wLLi|㟓̽.P_]YU,.,s1 dc;"hs,]ZGn-tMC-ެ~ /WtvvVe޺R JޛO2[DzlnܙwWX=I ?[言7N95Ihc<|/{e백~P|зW?nBaqWstWM(1Li|`)'%!Y\{YZKh]O1Yϝe&#F/UD%`/B?fl_ tzy][4.L_φ>D"}Q:] 9ehGA1]&ձ!Ai׏fKV{Mdď:'#rZ=*~d~9nT~Ѕ @j:-ȭCOEzKSW/͏i]WLjЁRa1Br+c9zW-[O2?# aG?%fo_OaREx=gVΆ'Fk\.ZTmg?.PqEhp'8/9ȁܕW?Vf {<^5D9;ע';ZZv*yy6 %6Che[J@Db6 1O !צ*HR),ݸ^hIk(3""S_;YmibmҦeZw}KcƟT7F;c{bP T!|1Dcgrnk%v1Ӓe_\~\Fh>rꖕQ5C}~#ؕ̊>T2[d&SksFS,/?ņM)eLIU d'` ;ɔRu7|xܨ>n7ю-h!}*QrXk ­[4KGUPbwl=M{UTkB7ܩ[9LL"ӎeg;86? hFMFuVamPM;._z&[?C}-Lf3@FoBi&z=5!WV_? %=eK }c0J Hׂ>sCVo|e \ cb4 Yme-hAI-0 m,''Ef,J0b m6. LhSR&&De'#>omڧ [6B?{Zl"c)")%' S &E` 6^|h. %ap>XNWc JCe]&B.OIj,ZD>@vDLn4mG ;&]#?ߚV0Ѝڑ'sܥ5>%RvURX( !e]TхV 5UKdUZ/-D_ba)qqDlv7GmS ܝet{[vO{NV3׽ }$wX;'8bBjh8 o.-*nn|MD#jnh=5ыYcrYh1+М0,?c~K> 5tZ;_ @ (sVe>&LDH" ??іIQܠ+ZUHz'E+FZ<.Wx@-`FSG!XxWG\B}i. ki[꼍;cp]-QTUFY Stc' d:4֙9O\,V5;'|dOaMnNJUSY }jsxy>^XQ{S̻`Z%s#|9c^AFgeKOwiNb)s1m1qn2HAON[#b&Ӆ# ENIaK@h--:l)~zfh].dIBFXdCυ0^D#-_iAUٞe09I<S&Uu]!5=V]\dX(cԪ[O%$]D_5BU4&@}"뺤Gl2"%w@!Y;.Q9˻XiR%QTӧ^tZH[p2 K#G" {WVoMnkS2+!>+ߝ/eÓl!.]!A9(V1h$KzĻu Dl=* o!g]rѾ9o&!I7TGRS`T s6GJw7FHjd^#-V׋s;;QΥ׭[\Az<Ba=W)N ah$lypo8iCDQB=+>"Y}l="3gG7.GLOɠF֠y82-WZu%ў\ZP1ϥQ$v@91NV?zR\bL~3ގ;_&e8KkmӢ]( 2pz3tT/h}B`lc>]td M<'5mEΎxi.6E76Q) e:ޅ] JNS3rv1qfDnC&9HV\l?p% 9{h9pc|wLv`j3*.r,RYl_͹m“U޺b0IƝ8CMdKN:EheC5#N$LI)Zi8s,q.mҙе)w^zW$Hq tɥ'ۨԍ_TKQ~p&EBzQZg6PkBΉXKmd*µ{#G)϶p cnjAѮΆ#ׄDX88X,ǖNؑb2u~խؾˆܵ \@1*-f1cB VY,]5`F+/TsRI/wѭDCY6FT> , a;@H,K[A7 ;N,i`m.c,n,Σ{ܱLKĴkp60#Cf(Xnc%moe.2` y# (mLS"B0)}?HdBn:ާ5ZZd$͝EF'=+sC;kzZZG#Uȍ,v6f1X3{F5\]AɄ0IّYcb~b/?~q<u9IoJ/A${2'UᤵQG^[gkSLyAQDDh^+C%6!Ѧh- L'ޫ,;s^Ravnr ⷇>\c2@tBeZLneͭӉD_|hj!+R5/q}x؈$͓mgچ+kT 癳_kPty ~,Do Ytkކm93S= QCm9N"ҝ"HoHXOM_Qw9*>g[c=[64ɩw욃vvmfQ\B/v2MtΘ DIZCgPz HU^^5|./ȍyZDUN=lR X!mt0&?Ts)+6SnhAVAHFtK*LX՝w+n㤘Z6.3DxK6؅l'4=o"/}YŠVf y,xf$tNc*ģA@LPi] g-[i ;u8}^|'܉•M9 ).Rl>!A.`v_1!L]-$X*ǩzylLg`p8OR=ʃ+G ,S\?h:U,*s - :+~aiG`te/[Mey AyaS>@ +!`Όq,Zo:L"~wF3,eeڹDP҃dd+(ҡ ~:(G@׫D<84gZjx\tiK46O"FO$CMoc$~E$age+*ם b ֋L$T u^xq>?sgm`Sl\r|ҪwCƒW^H뛯-=}QB>qq ooEhVvS pX-_=&D±2oqE B?XymKWH:=ݳ.m"P%peuߖ-hL p/Lax[W3w Ul1[WӝD.8"q6u 0ɾ|uǂE!'nSm֗mDflT{e!Ի?>sGHl ,ت|d $eqxGq;-h tJR3N*i aqjM g:;dPR؟W.6rL3JL39dn6P >MO7#64jdC=S^M^eo$jiuֆi]_d} wOD.Ew;WU3$vYDg!*0w6n7oIpzNrU 1*UeóY>f3ɷ,<^K0Ca\=KVܧf$O=,؍up#Tl=&n~2Z宯xmyHN{/":k<(MkPr?l$ÊzI%ޔݾOS%o J0=٦\;$ykRa#"n$b8]8\ɒ8{RoAag1~2 NJz ":LJYcͪ*޴h]‹B5tc-7"zh\\Y H m^_`>4v@a-b :@B`=MhYYf 틱&[,w1 Z ri)6AF[T`Ց/3_情v.EJc_5ɟPg{=LHTwWPjq+*J1IxjPiHiAut[ID5Le8Q_d4cP[Of~¦'dԼx&<BnFUyan!k3}ٲ|\q4ڞ_i(έm_J \N”] G 7|C Dk90pT`,ڼvc`}nAՖi{8chh%N#J{!-KJN[a ֓Vgm;FHNԸdM2ӣPqru!Uyx^d!ݪq.0Y_+LGgiaѮM8۔ Gs>oq+3x %VW~@vś A(}#eh.҉HPp7oT/sx).rE& DR{"ѽ)U aחJ#גՑDƭ Gq8|󉙮'󦽷SM"҅+/ƩbvmbT8  *W[Yzg҆hֻ 5$Jk&41J24^iƸ1.mX %|XV͗K %ճ5nHY!sSf) X5xti1|U)l5wV%`婐Ln4h !9y%{ 5IcuՌ,AiD#fxgF`Z_r66kSO돆X7ʈqGcꎮuPڵ4b#+Y^RVkh6xœ@6Aj񯧨}I@4_x"p\ BK'ASS J?Hȱ('yS b—VtC`f!T9P~dz/Pfie8B`vʹ߷69й9PנgN>ng$}GR~6jiY!J5g%%JW5Vk6FDsg;ˆ&Jx&ΠnBσghOK0q'vCyV-]N\3X[V,EI !.!?fWE5%Hĉ1ERk,z 0[,qaY_te iI+k$યK#.%X {?5lF?8*>T6< 92w+K%ܞ%U}֘IXQ'nrQU@(z?D`ng@~|u)Hlv*2'dV.q!T|5#˾| sKMͱC6|4ߖ^/xLSEIHo|^fa52T3y?6jz1!eT'p@2ЂA R Zah;Tcd[$!ո#Dr^܆Kp >QI^߄%(ْuA\F@+.f)@-\[VL1-ɟ.WTpUʍ| '9|ϫ8 j|b7&_vKxlkC$֌fzn=p]ҜʪEHV~Ds&黩1!5>֊P7"r4ĵB|'+S'ODm:wt*^1г(~f)ry5e"0Nd[g6ޤ'I41:0ɲx\MՄ7X:Sɕ4lW۳'&9B[,$eXJ0ީl^EY8ico5E. F1d?P񾛺=e|U{MFCf*%@@7kyN3\T^x|ꥧNn=ʖ"_G]?wRC}GtTm?} з&q.ٜ,qվq2쟫@&3 Qf t3W'O4> fQ&7kN=tlb=9X!^l.Ogv깋 Y:5b0c o I7?&ơS!T݉aevN,Anxqs։Qx4?Gܵދ>OEg]GB@pSn5>hByʇb*w']e?HmDsR,Rtn.U3 voUp%bĔ7o]NF($R mlk&=o\tEU-tҴ'5Ξ9s&RRѾqN}9JLJȤqª\@git%VR\ڹj) yyIMѡ(|PJ@ٝ;Mo5aMV~ W.4,qOܾ|Mz$2W.ҕe4gNw( 9ٚ-Lm28 YUBcIsIh㬌E=w]~E(.OObNJ95%Z.LN;(?~B[-H.ќ3gQٸm7scu0O!y,Y~lm,uDLʛ/=nY $Yī$$\{95]% O bv8uJ@n;Suϸ.yO^LZƭUx]I25?)ߒq*k,5" P{-pq-$[fF5X?HK<{']!)qa+ U@kQ2Jpbhu.b!N=Qs@W{Cw656ѵ:eWȗ2,v\X4$^IeS P$=}}jzi;,bn0)h lްYY@Sm?cp6]KCŔjlhPb(`5ލFՊC< U?'# 6ra@…˷XhjI-;.+Ezݕlwg׽ ۂM?g!d:ā rf+}oaNÿz-'5]7BWlUUwko⇿1 77t7~ hlAԳD K16Y]1 /u63#xF`Kж Ĥ=M/.LFVWQ_h7رVuֵn 7=5zg'oE)uIu Hj/D\͝gZ}thDRrS'2{EJdoKxN^Oo[ȠC|ްp@Shw}y)e$A,OLxʾ17df\O\(_Y$yOKʌ7,huIRyآI^ C):eH ɓ1ؤ4J6vx Bs((!Pi~>Fz79JԠf8v#clxH+M_\gϣxT2&U?}'I(P^4,UE`p4A*Zʹ,T_Գ3j$$-1v-\Ɂm4JJ5(8NjӢ-2:ܜb3!P0W0M=1 |'LkpGj+s#K}LV Ğ6fţt}1c?Üu y{r< j0t' L ox/rDRuC&WH*7ҤtzS'㨠7synp|p/4ܗY!#!%ør#r&v@֠Cjȩפ"ޚ.{XtA%(M{*weZƛHvEH&'i A?o<_vc !ˍĿz;~HE](4 ЌzQt2e")w/ 8ci Eg GheW˜F1 c': _; )6`*4|@$'2ܺTe$m IFpz%v}3@n#po- $w7 %=6D}|ӡ pnYJ8X`-B9M6Fb٨<&lXsکTyc[ːgga~a}= ͍-߄ZUFG^(Jk'j3=LU&krV!ula `T50?bKv,v)AUVW2` w`ke=jfn6ū)/D0V;L/m^_7:6.w,E,u`\(PeqW_W F.AЅn%,RPĆq.f0^($g1 VTPߎYJqP,h/>3G u%w]N!]ߏztY /DꆢF?Ku vO`xo6#:B5PɍQ!s#=3cXB#xm ”G@4%!g(;xT/^QmCTN- #ЋIӃP n/m"|eAx I hytFIgR>E$y*/}ow6w}ʬoxXNL[| g[['[]ڍxx/ZAaRHx y(\+͞m'(dAH&G[W҆ڡ {5D[NO3qTf''ׁY >3 (C?~QIOƴO޴8SS]S&(ޗ7:y=Qr"9\ Mk93\m* GN{@NtC#CVGn5VK@$ P MFt-MǙAo*dڸu1@׺0Օ.w0| `H*r[}aݓtWh( ŽGT/J}GGy?ד @eِY њNj;O( 68/Z) EU#YcDı%ϩsYh4y<;8z?fޠg ruBNlQvfxjW%~M46kaUe͕6#,  <Ԇ.ޡEу_`!^|lRKrV~ԳO$樞#?mZKPp˶\Kt,gp3HEoeC~+9>-$c\C6r뢔.6-(K}1Uk**i@gH-8m7Wxz#I?L%[0(Ba04{A~6lApp2[c^#TGmΏޟRfU 3id U/vBݙA:; ]4bjP#aA“G1j Շ-k1[(:o_oMrZr97rTv䑤 OX7dNO8W@[\a :xBұ pBa#I3l ~MYʘG{IGW/ugτ Gyq/rg>Q= l\U.]k8t!1괖E;p,?r}1ڌg=D!u'ݻLqkM͡yy1 ձ]@UzŒ" X&b0ݼ6D)WLWh{ܐ] yT*dR|ΈpϺS>[|eIƴxPX]Ѥ,xR4=16Jgk>ADgy͎UXy@bUe{d|{Q01_4{s.з>z;W`=8ӈJR ;нP}E!xO3hYNjnD;<6*Ψ!Fv-nh 2Fť_nl`]-kTGq(@]z,̉Z7ME1%l~ τlŢHx;jZnWX!\w!c*5-!DX E;GRxggW_(8ʑPVUݝeKY;!vI@ ,+ YkD R-eaJfҦ/i M@ ubDl8Qi?]Kt_"Q#y/pp h'`(*4(d :W$-T;+P+!Ew.8 H{QM3ivb-tf[Av"}o==;!_rE?R~x,o'm9岂o?C["NBN (|xQ Ҷ)a+38k*l0IMԯE,)Fp>sAX0 zulQ('o8*x ]F84[m'&>ߤﳇ>8Ҁ)u2 0!C(f~(~ç3w WI@{J}e.s(wiA%)9* 28}pYA2{_'5jaz]6H2KSջ8%*F=K u vRoeQP<㱫6o>`, lEu;8é,$# 1x~ӻS]8w|`S;he1aj4䱚0u!z𜘊[d 4|HVyy%7k*D0vagwvj@ ʕp՚xN X:w&Oy+(S hnیr3HW٬kf#~!C:L(e'a`%Df y7kp) S[fJH]Gdsqa@xf>qo ~Š"b1JWEo"%UPvMHZ'k~ɐ2AEr$f~툆mtD0V$P nO_G?!uLj_sKdה$u"0wF5vVXnjq$p}&ؔt˭ mB|hY0VnTm&=dII1mK[#z~2 )FL\O{)7,;v{%9xL8U\;%[IOtI?xgA7e )^{O`cvU~%f;0K%Kww1'eJtg| ʮ^ &mRyLP0%5/.joM 8NJW_;l[s,9VXH0KnpFCs(Gْ*efʈn꺆_r ^PiRGuz~HO{U Wj&~we:'jq.+Un؄*lp7}07ױpXc #\ot66vNԿCTRr[~dfZa ZK/S3RTX'ʚLYS-KE&{YTΗq:gq/H 8̾NO@e H-[{8n5?95ˆ!ALgD߄lyf᪆S%ȅϮj׽a0a|uǡ-j$' !R+ZAb!H%)4x, OEv"z&Af,mCSPjt֗]y=Ʀm@qCZ@ uTH&#6ZdpAx*|j# L<7qګ饱f ȃU`?5ȑ,E艩Vk"\[9"\Zک|aM[OUFTM|p!3OQK9 qRYO"ehۘw"`c+dUdJX*k$DyD6ť3ODx'%MXвk6)r]1;!9<!GM(cՑ-ZH=7OG3ΣR ULϳ35 ncneO ;Si;J0/%AK,7 |U[.鱖yXb7b_vPueZ'ʴm`־ !~}!5| QK r1(o-RA4L7*B0U;X)U"le{so c]mrVUW6DW?vBwS zolPU(;5ϝ6h@B3߀bmċ75FZ˧&3q[ s:PQpj,<{qv_{r-jϜfUaQ乾f}+[͢8A7?($|΂.%4#z^KL1h{;|^1.EtzlP`Y萄҅\.nkfy*=*FٽbM| `M-k:^?wXd4R-bQyLS@RO8o ˋ1Lay3 0-01A6GBvOb 2O81Z(n2qֽĠY۷`QeaQyK~|ajq-rQL_LyM32.ْХǑaߋ;c|N~C7NY{K,scQYMڕ9mh ֖6 N/ɛ~2Be Φy W22:睹Q IEX;{.+}8zΪ̀իkJz `ui x! ivRm=qX 43bx>]c }b\7s?"Td}1l9bUPK3&BڰZݫY[NA!]_mQVB; X;:g/t Y#)HW!`d}IȀ ^g%@`ڕwֳrIΚ `>Fk{扒lB6CS-D&Vu'%^4EBN,C? t9s̕,%侑 Ʊ+/@Es{e)&($ -%5}SRI`G3Hh)ANDUj'MjW r[t^~(U^sNAFcf!dʵ+(E7Qr8#܏>g"K(5~4=2,<85-퀑im6lrQ<@h,/i8VVFI/}+)؎)Ey/)0b,!d"rϨK8t7[mӭzɘG=uClkԊ@ed1$l'i+%eU=A5EU8E0%jQt'l/e1gq;7V Զ (b.dy&6cv؝7d]/,u jszpnؽc`bZ?![OoU=@w YH1҅Ǔ- K PFb(vީhu]0vARZnK^%3jT 6t9x+FG=Aq1ǘ⨳dUDXꉔV ڝcV1 13+~SoEz; To6^bV ZPYyfa:x^I35)8jO ڔ݌k 4IkWMeYlJi6]转zxG9d1u6]\_5"o=x=Gd*ѫ7Սdta7qx^s~PB3%<'!QHY4uA{V5_x NұLAmMsM)-C~i@ mhtBW^ѯeG 67,6ؘ̉Ba*?G ep(wAO ږ%/wP#0alECH`R+"]_l:b/3$̣ nṀ{oh+T/6i(u Lc:ך k~$fbV1ĥ10I|f<6Vq u+nWLi.ʳpQ涒36p)w}`N 8r'˪>"p V;lU|Ԑ9J0IVzP 7Asqorv?]C U=,Z=Q)^[п_Di`,Ȫ䮙w0S)Ƚ]<FCH )B-w`: -Y6}Rl uSYיF8&2sXò)6͍T?,B{ uj;E&L/K;/,]ѥVQZ\Z0yW1UA5 Ը#<_Œ=n8Vs[羉+E%*1P/ӥ55|"~>MiTHBG:?PE ,m$\SBh.4*B,jri*!3; |B̽y@ nhɌ,ki:e>.Sp/|Z|&z%3~&l)W Ui %stVBԫd<7L &vUd⽢wD_p,х(sA ]AZ$׵<Ěl._|Mq9ҦӨ_rԢ#!'ycw{jBkޡ,yP:r8Zؽx pOL+gS~g" MH~C(,æ" [lWd%seyr_CLlP;MyZn 9RwQ64 ?eoxE!8vwjhI WY Ιj_083M YأwQȋϬ %pYSUxo\"7XdCX%/$;A.'"D@7;y fdT!A$٧{/(ϰ5iLj!Q_2sZ|댄`|̾%g.Cqʷe=JuDs52\ӓQ՘}˯EfG (9/@Af jN{ o/ |7rxe`Q$ 5PB-Cfa`tԴCXfY6OQh4V}QINZ헮O> HŮ* oސY}2a!-o(d,heu~<+fBUйOD7&~3X [?*Qpf2tfuP05`4+|R/;B0țJmO5wTyw%jӷGTJܙ;<},:AmƱ18% Դ uF;')8 ՗`m[R lg`$E&{e~0}gi:->Е{}aC[.ʇጨQƯQ4HB,</QH0|{t:0#X4t^P /2_=C'ݤ3 ߉=CNFN}{<}W=(j+_eutXi0^TK4&!0ɳA_~٨ Ik\_-'Q{vzLpR [37  pX<:`{|)bYGG:Dx!D-]I׫D~ 8]XAdz'bB" 1Mҍ**J̆MRG(#Lutdۋ~VQ ce7QV&xi[mpS:(jeIj, ܑ#_@ ~GGS5{_'<ܝ9@?0qsFN.B@n]B+}[zU=\lp`b<@%/AK\.c  :@}PymWDzgeƷ+ Gt!gs˒hU\LFL}G u]ԭ>M׾p}Eg> U&3G:V#-uV9p )DmJ&q%> gO,N49!b6lZ@>iwO@}Zlk!8p|i^q_]\oS|#)FL&s jN9QƑ`ۙg| J, =*YSӦcst'_޼V< ǝLbehӮV>XgJ"EQq]S+ hEƭ x3jTS)P!̵)#Gq4D+yg0p켿═[tk֔ڔ ?'ޤnAߓCDtDfQky$[m1bq`st o8v&E&ˋZ+~75xLR"BNQ%Ű{oѽJwgk?z:+4&5y 㤻1 /N|DB8q{~ymȕ '2z !B(u,fG DЧNqwg3JK/ʍ\\ 'Iw4GnHt$:ޟEb|'QpY3WwEhCA},wh~aYEQDmFa U)j4vngG݆W\Q՛G)v8u7\N& 3Ț?PdOWA ͂ RAP,G/#_5#fĺTIEռ%X!z䰦qɣ#¿RUäL} 6jm8 4|ǎUx:w&[G|^(e<.*DIw@>$`L/2\HWbdMEJBSɳEKTrTWcBU82"ƸkYleYǕJ/)2|>"WڢXk-VH}ZT=,+-1=xS2d,awAZA0GE5)u^Jp-SLF,O;X^hcA?=?:[knM$ h9?[j=)S o#=kd-S2;]]|֭֒ƞc;X^:6a#VQ7_T{F]\ƌ'̦G,8lkP`Fk.)"T$nr@YuD^F5z{a_(6s3Sr}TL.jGlKщ:Q fWQv3o^l4 (Dӈ9]8xF-ׅeϥbʷlm;6@'[hc*ƢpX&/nO\DG^[so[>^Xx]_zޑ쒤sHbhm3~;l5Z'B* 򌂐 嘙ll&kj46J,EN>An6^iPϥd)uu)cͿ r8  Ư3q (9@|@&v'wڸ (m}u8*gPE I8hClUiM#ඛd¯#gʬ"<x".Z۫dI.L+"tk?TܥF$VʍV[Y]'!O ÄMgpFPfXHxfy"qO*k9aM}1' P JQݿyrFUdEᶛIm"oHFy53Q{ 0]$'s4:ۀE X8T Kq=DF%,9HUזn@I XcSU2_)mϺiX݊:d\&)_Kj=cMy.4;( I!η6)v'CXK$<H6{zMv9;V721 ^v"Pv)094vbH~s$T_b~:dEG9EAV_;*%H{zBME@%ћ[`OjNcH1i5EK?8|N)ztū}6Eq䵸^_C,p&cܜ6[﻽sCh#wsr{a@3'j=Z)26nH϶^U+-:bCvs^ظv:Ο35$;آArG%ֳ7>.bA AD":n%1 %,A[O#=+- Y"j`\p 7Rx{>aӿg-.Ha{{ NQZ4f×U!_BacŅdBh\4 6t~P At%P4nu)U&I~bee`XiAn_!Lnʁ7᭏_Pqu PP:OS ;dcū|4#coKTVUz(.QyD;Fh,d 6Ʌ+j= 9,hA2^҇46-'T/2ʡ5Q3d"W v),}t٩7sBWM"LTrp9]ma.UIl:QG>gr_g}JL%S >fr.#zt߂|&+7Me&fE 9 O- "o-FFfUgJqJnSUC:eh&0 VUt[`$lfta:ծ) xB]SoPF8s5NTwqeFJ"ml٫C{6B'_fASAUo[f!?\sf)='<> (q5B?x輽g⳿e-s:sd V~QMv8ajo7,vn|3g|oPB]c(e[D<_EY,)B-QImX:]]Wrpܘ`D1Iʝ +Yy׎;YqI,4F_",3b>QU'c}&rv`c&xbB 1&D-V? OdY{\] q* g+jc7sh>F~UewcW5("適uA+S9-HhUdِtsTLR=߱R 6Pgk~*>_v-O0;k=H Ͻe*vU^Ƒk T x#кH'Fc'fTU<1nEYp') j^1f䫪HGBv̯&q5cCѲ*ចyeg 'nGa0b<-jlN1BZh*BI^I.A0E.4}cւkS7o:)-'ˁwsr'UJffqM/ .(*-T^Sgr/~Q']QFRR]ʶ#jms{4Wbetr7fa +MǨׇe{a H+L߸8OU2h# R1Ti ԏ<4:׏ i{w/];}has+YŶjV <[J(d{o+FbT >jr,;f:nϹ.Li~.>av@sf^C5w4͘A!ӧ0 oOJło-8Ɍ@Nq&)@|`kؚ?wfU ,o Ydo\:t:+pyEKOű!v9?kBxL@C^_04 o@W(ɟ`F|:da]6fGgZh`+d'[!mfv9%az9 Ѧ~g+٪̔:)s ԞM@Is#&ʾ^c|/ݳ zulXYb17X*݋mZ);TB'ξXr%bvv yh9+G`Y%?׏C j Dq/`H(fU=W_E1`^6 A3F#x26 }6IC ] SUaH(!*oϊ?A S!2޺‡(ۣטX|R"˿wQ_P9v?a$c h/o@)w'p;CH +Oi/1PcO /ct U>橄F}1Ă4Ā1 }DeZ ` L"Eyג.#{N'!+W*=dtHI69qbh#ouLI53矮HO s&6l++_,lsǺjD"HĈC.y9W^HZ=ؾ DiGSeQ$l'I@; \[d' ))9A6C y۷k? EU[V@y26"~|Yx+CRk'}&l:$06n8>ԺOM?\9"y|I8jAbξ2&H䃧5ؒ1o;SbV5;1(L'CN>W&Ԋ$Ⅻ$v$ƃ%tmzI4m uD1V@l3d~r]e/> e-pD7N`c`85R(ݓKBx∷hq׾ӕp賸v;JGu*fɷjzL%}I՝|̘w7^yOu YFJ/qB1>\fSg R)qPN/=SF|@ Y d#{pēN+Nxsc@B3-x+T67ޓq7V /kJ |< `˪ST!I{cB_YAR )5'Ì`!ʳˋAXg .xAsOS,taL!ic˛Za?ĀGq / H\; ?P̥ ˁl'3G;ϊbNʬ`7СF# fS@8%:@a oмbo^&^u?{oМ[ֺۃ7[ $9EPWw cHkIoMgϪۭuEm>$CWy_6FZy^'!c3!*Tn8=:YSf7VJM::tA Vҷ/:…%osUnј ]8Sڞ7D8)4 z V=gg-w ٣{41nz/0 #^(n)&մ3?Cd/c%#43Jɯ:LKԈLQ96XXYHyI4?Z+ MAxgqNVVY5 MN1[ħoPh!nZ7nj t-+?ՠ{ hA,gYML(#iFOeXsKBBJSUY%[; Y/+u ژK6Z8K*|֗5bt 3F^02:.>3mC% {"4d7VUwC;݈ 2[ĕ:tP?w6^#@Cj1<|w&I_X?9zBN<6$識"kLM#o/k=N~+?Sb {ѺH2Dg+"yto$@$F^A[x4auPM\C/5a:azEL#jוXN?rF|h sl]b"~\`m+8w%/pMg>~n"ŐDsrjd(:0U}6Vx DUrC2ng*{B<2V}= Ij   XXo>z7CFhkv 5%6!)y}xҘǼK;svŒp dePЉG)QllxPW=h`1]Fw)zƝ' /Y!hEaX[@y۔(sjP޴6O]_Nm; glYD֮.o=aE{^:[$::&HbvM4Vs>>&>xNGeD%+~ԝ*T дGơ.hw@굛#1e/X'J?'I>P{Ks *w8 bV"[<+\ܭ uPמO">~!UelŢ+_%*ͧGƳܪE`]Rj-Y_qvL¶Mw%.Ǟ2}NaX!ǪiL7etBs)NiDlJ0SyddE%lDuDưkϫw2o*Smf=w=!EUX kg=// M˗YW3揱$XVXEb,f6?3 e&RaMpalIq"$.fSi.PwY/^+nG\ڰ6#c?ڛk~6Z[\+QA!>mz}fy2!f aV3ȿ۲QY>mR[ЛF4#Hj}lP>M{9sy(l$@_rc̿@K^tY?JgE몠vT{T37mD %0s!A[. MUy9ݫ|Y/`0baz+/y@'_r_^Dw*ܘI6HU1J'տYq>eg^ބ8v0y;V,-C'9@ 6dyt@F! Uw,ehk~;Qry2'omЛ;11ؑ.:Ƌõ&A@zN*NuꍞjBra=ݔe!S^-jpIytjrZ! +6>$VU\C :WY՟i:X]="%YY5CKڰ]tNRkL ;!Mu$a\;c dYL]*{ F4zc8K{{d(d`]8 I[L+&fx?dzߛ,h-3jŋ-3e_?K6T˒KF|>"6ҝ: (`ߣkF\ HB7vW$'o''WXՒlY)ٍ a"V,o˛ Ux#GBZcD=gŞfSUܳ!a U'S?+^aAZƍj6C}LMNd=Sd`NKdPaU )}oDS(˂6X<`k'b;,'\mpucux͆TQ0x<8|){{ɍ*m}tp~ڽgdA - ?Lpˍ"5a=Ir%~1ܸ:x&,c1F ^U @n});D<>Qۄ 6$^ץ"G(ЋF&4P-%=WnG(?Պ,;9&їv~_(rXj K;FA^b4X'Y|f.bRsէKe Q׀~)A&Uˠ!gʼnão{tNګlv`_i&9sΕSHIr eءkȺT7goo5jK@[qS_ &2qtaE-Vd%=ѯݧo#i#Q(mS5l3, mry~g + !{ !v$vCod RIx.jCXRj*49ʰF1tuO_DBeɬ~c 5ANSB~6b[m(>VXa1ԥH#_ވNnHTxu:2.f_`?6oeT8Tˇ1"WY+FD>Y i?uQe;mS[&{Ŗ:'>áMֺwA]ѕ,P$cN²?͈bU,c  5UV@$e=)<*T.eTE&ŵ@sZk}xOe Ogu ^e6s3f @UiuG\+!.Ǵ˜#m02՚$1Z[ 6'C$_[x_1AqM_IM%[>K_߰YM(]gVu!|H2Aw!l` |X@+;/n!XԎ5 247aS-&~ldzc>W嵃/JrWet`,+qSeY &J$Y `ї 'Z¸>5/A?SOXWgF upl ]rҼX{t\5v;GM7 0N8xx**g蜆¹Q4!S7 D2PE0E{gӅjpJoYTԌ!5yh1& P~Z퓦@Ah[MZ=uٷpxM_y{Z~oKvNEx^hS|jFH3i6ٛFuH>qX;_fOv.1`4$}[0N9~z6PM&JǹUؽFgS_UkN a #uEIH\,.ۊsBo" VTDO[ ^uГM̨^M~ѐyxo98,&uJ{ Z~3>F^ɿO'W+乥*⟮j5{8hhQ lARln`8;8 vʑF^Ga>I*HG*Bz4s6~cUT^Np 7YSQm&!o9\Ei19k:LosB_eE~{PkEFb\供Y/ Ca sVvE)U.] !ȴ v M>m><`{@Z9]C V0$6?05YǷŽԫɢb](&OЗgU.Gz3&LjDN5VVjC0g\S2 ҚA 2?]m$3;M AQ؋?f} #CuNJsEx L7_oyj1&tWI( ECH0tݬe`wBHGLvC@iӮ-9hQY:_' zB-Lw>tJ"u/ogV/0%\|͚RаMZ;%66]s,M rd!=jXZZ6:Gl׎w.d,8pժ\tm9klH3TڷW-AO0uq#"zLOM>J3wr&Ѱ/LZ8o܋sf_>jbi[iea݊0Q)= UG-lrlBHg((jҥf Aj]ł%vNEӰmA–&!DĐdZťp.itѹ̮R>[bgKL'mz&)zdv,3w]$FKӝeffZb(3) 5r3K_⸡+:iG9HP;O⺝[Fok`/%3cU]i lޛ2jb T8.0Rƙ8Dfgnf̉n]k%B|ngC FBꆌM/q`ۊS84̥Lg9IEV5bc/1cJ4}t^G;{r.l8k„ɣdpf t7$lU+e&{ǨS|xa Jᗒ_ ODIa:,뜥[ө-D9AK3ԞwkkËA &=$5S"{rW0C6&`}ɳ:k4৒jV^n92(-,#'}R5eA \E#9FZz ~glLUTq0oPJuz_+cY9>7wԣq~ڜh*kL3Vn4L5i7:|uЉ.GѝM .1k}SSfq)(P|@2ޚZU<cD_rwE/IN((i@ L-iX׊]bZ}X8^?l.JwƗ)x]v`XR"1+˔*C-CUdU<4,ˍ.gg>r"Bo ǃE95=uuOs z͈W> m埾!F(v@NwI͞q?$uA񊍘>Oh*>x^޺ZtީRrc˓' HMvѻ8 /⽔T-C9)Y|Y9X k^ 5k,X$ W3g5B^ق9|ҔVQ WJС՞V^P$OV08[;A.{ # u<42ֳDv\KZQQ`IסY8I8)TXGm2iN9w>o=H rOQHr(ot3 "kh&4nц ﱈ'r$R,)&/ ڟ_@qBu  Bv~wS$ ~Q yʼ/#=w}i`%ť?9lD-s/~z}z+g9BZ}ph څir+ImQAXPџvGaE* 2fC+7L-I",6Lm,1ՅA-z-cYOsվ)m\ ա/9}Y8FS^R37ǀ[YbѡKkUBB)@NU@q;C;uqy<iw ;E=F+}!J)7BRzy3J!ȅB}(KٽAەtY&6,P_6=nsSd#_:۳h "YX,lfP!-I,aհP[bu,Xtoqx p B]_e(^w gAu!{cr+VhvVSnD9-KS&\IȤ $lօ )mX =2Õ[| I;<'׌Y m2Oi 震o)j03W>d"}$6őؿ=i섮ް*b#8.78VOdn={d.OEV#F'UnN{¸= ߃C+*×4Xdߛd'oirpscLnU)S6?5'CkȮe@}?quv~}|guAh`sA.8FmtjL?czVNri'MX68|OeE셆$d`"W%DW1P;ruMf%ck ?h!WtdD,d )%#0.5Y 0'J? ?uވ?ՄW>PB{+&p`ɻxK ?(a=з=Is7mAlF7F$Fm']Y0_)XFF]RW\!H4R^Nklb,P}fC#,&|Vh4{U(1I54M-p4`p7 5)'di:N+{G8 JA:S뮚cl{a(pulkߥ!i(Ns[*g6ٍLJ盲р3Pp[%$dre؝6@Cgw` _149:DX]Uw%rBB~fqY,_ ZÉi%9W JB|Ĥ&'ᝀ^kqKz8ϲ:sIF-$1I1oj^Y 4]ygv;4aD [4zH)ƶI;y?"<ɹEĒKHrm5׉ JB2.oC, 5s+l%_W)۳H]^⏄Py<(RLr!0p(C\G&ӫ)U,3.wDOSoXShW&1tp֋ SR8r#'1QQeŸ ѳqQ`y7JdcM/k2f>u Ĝ|x<4C|@u809kL(}[>e+ E*ֆKic_\L-%ӀcR~s9Y;B|''MiMEdn&Y_$5[ n?$itAݎeW7^Vn]O^QPBQr8U˩Uݖ˔2kk/{K94re~U>PZA\d&%I#b5 򖣇-4My|ܖ;%2i4{D@x];YS 0_ڱ;,uT́3B8IC9dObwIDiTI 4 ߛrƽO)]P\U ,r ahRKc{@##hǔ,Ӌ?A4J<ҜA߹kͶiZ\aTO'">ǦYv" a>f!+pL\>t>!ǁsgX?ެjܹ*z9,e`ed:vM;kUl޻h')p|yAUoB%ȩJe mߌy}Z;9 d!ܕe/U7 R C_"yJC6弃kq L9Wcv88V:h)OK9Dݏ#a(8P[ uOJC)bRzg'w(*sJm9}[K5|݇E'(g OZ3!-3AP6LJCff.n k3Xlek CTI!J(ހAuhh*I\Bn:' RlYiq6yx.? BC^b:hƼyU]G e]1uyRfb8uåwQ^VZl/0aϭϮEbsRML7횰NtΗ S\9!tIEAL -vvw`(w.x̜j98# 5ZՃT+ņ}J}HE#65PyB[plhF_Rd5p&*_0<$5nV5ёkJ%b'&eg%Tp\r66jzD&4Aq{ ck& $2He,)m|Ch1 : yXM :iGtZJ2{N%eĈ_V~EW\54FnW_đ ]Foph,)aڙ5a*S,Maw!UsV侮_*1/`qMtz"j\bdI=_$솧ǝ! ,DXk11`v6|vӻԄNTe,H:)dW()ݴάUVɛkC^(wl6PԱU)Om8L4oDQS D0LcO,K)|"dl>T-D$_zmZ8\!gN)־A-p?VdXpEL9V酴}cuZ $]AZ}E\|.j*B:ȕ2bH4(6Ѵb 6v"Q &VsIc%zUU|/՜~!rEO,DX+gUdu@)yݧw؇[%\(N8e_vh}I_tuM{B*3[@ehRy_Χ <@W_b~M'oL0哻%!xM@`, _DY&)P"W>CC9G-+ i% ȿywghJ!@JBpK>#v v{ªrJR?.[uOKǣlFK1eIBdss~0.JEڏ#,+3%ͬAZukbw)t2fT0;VaM?Y]%j5 o[ŏ #0mp˸Pu2cLE;Wd{jU!{-sXVpO;AcBmQ ~]T`.) zȤͷ-S*4goƽЩ<}{x=ƈDdtn,Zlv 7)=k)g@uĶC=CzhNّxL)2.6):aA>U?oT^P+=|,܁ڷ{?+OLpaܩV뫈_.A7۵Pc/Wʭyw.@L BeX^#4BQ1JI%/N%- !_ü\-UQ jV #ãɶ Za!w#V| {کzDwBcf !7Q; @8VJ=d>(X"?G±D# XWmQK% At?ejUr\m[4!+Xy_\6nie{;aɞS :?d=Q4E-Cz%h5&LtGzdwkz=HlLn1@gBT p@hi+Hy5~SW˹w-;'G{k`qV2`_pF0=d+(rܗ!dCCI+~eH U%oDhϱ|,؉0fPZ4?g݂w*NS)۞>IlXYɥ8B'u"]B\nާ b}fLY+a/Y%,%q8޾^ ZL_O:; ]rt6Ӌ2=+5E9cD7uvb+ѩg/* ?6n+' vК4CjqZ/AwsƞCTaF&5'_ r55tP(f6Mh&×ޥ0rIŞ&$°A`T;uWi\^=CIП܏/ )Q4K*Vafw{G(sK"4c0p6PL#2~ǵt`{(.%{ez+0(`yOJinLOV6$DG81d҈=_4?Y.bbXgWcI'blQ>K >ϲU:k LQބVHYqUB/K#4k۶țj r]w\; g[ 3.+p?Xs[J꣤~ 0%S|Qn]+?BA-wROOb^ oYb Zؓ;V1(9NEYr5^9:&;&<$3fX Ai`'v-w)! Bц׼irf1sWL\?XZSLɣyAUG+Ӱn͌1r$D'=߲)J![pSXV [C`VԲDyQ6q_4+=\`d1%[ًw8rCst=aɨ6e9L5W*8Z~&6l(r{! wd6v4 U$X{y$um;ˊ,u)L*TQ289Y5OI17x A6NC{\4ӼX.6.|`l+Tpyr?)$a8N`!.ZdpiK9Zk%yF=Rzc~7]E -eċp)䋡,'_jc0ϓ>DFǕz<m&}6Jo"<ܐHdh>\&]v`ΫC(?93C_tj=):[a=x'/2CL+СU|*([p|P>TÒZ"?+]wO\A'xKai.Uj:"FP*Vo{14E:g`#'WzT^{p_`F/*xhq$+ULUΐwΘXs:^Vt2wr}V(DNm/O~ #7ٖeXd< dhؚ}[&I[oq37ɻ;wZ'8@~8 갭ϜDK= pe2Y,ᝲP& dNƬVt5-«d1;"h MJaOD4f "|r 5r+Is_CT5mӲy4KہEQ|R"vN;6]8uNn!3荛A22 [Y%flqCPyԪp9;jYWFlӗ"zW18,$e.vAo:^3FnK%zf=@k' WRӜ33k<&4 }$ |0Z]CYxv䣠49VʵW P7:PSYP>5NcމUP.Fag5_y̛rH8{WK!; 1GfHRuE+$%L-FY{"H3$U+͸' n)/L9}1H:2,~p*2WQWl[|yambKHNjnn^niAfKnՎrB 5u42@Xp{.:7D~ GjX#iKM-' ]Q>o}Xt~]ɔ1ێ,R#,WO1dP!0!6 ?Y[%jy4<(/cS8\keU8:ϬRwl_2ԟsA[_)BL 4P %[7gh֤)U->"xgG2^6MX#Y) I,,~jS|]5m)Ai x=h!!jV\ ^ݬg%PY6W+{B,zRNBC~D(I|@w[(uO^̨<f$esc!Fȇ1ďv,Db*r",Ql 7+N;QQ;IS,ORtw)X~9Lgw+yȣ)\OGT J}H3k`+cU+&j@ǣ~Be'fGId;b18e ة]EЀY!$!O& f5HQjm d\ # j$+ޔmaF~d`.}|* QEdLM]Iԝ VFtf?? x ss,BDCkO o|WB4e© 0flF={ /blWx. ,N %QA/k^D`mrؼ=HW4zbwD37x "Vݐu eޗ!'<>KӍd!U`=-4gSX{c5/myn,/qڡctCqnq,ؔ˦v ey,Voia.|QN-P.96s{CI'sud!@p؊9q$xiLnō/_ZF}9z*j-̴+_V'̨`iS|]3gY{6])&h틇b8/t<]R02 $y«謎^`O eA %1Ě%h#b qq>y\cqӓZmu|n8}jBݑrZ0# 0t#ԊΜe^7,$ yDz&u[~.UܤųmmhϢ66m> YZ/8ش3_aS^sa-;~WBcqey"CXUt`u~yLm D s)p??;75P]dSǘ;s@ a0 (z'f8"ٮ`ƒ mM;*a]uިP yv]v0i5fd>$)Gleʵ|mWe^LQ;3߱MٶG'OPs*,~(^zI?Qqk ]̡Bxlo+Z1>~MFtkK$I" z%Sډw2}7 z% xJߨ:lA}iB}3}ؖg#$1!J3kh 2~;K&oߡٲI !>q/qyWd.ı7c\K夎=BlDwY烐#mW}7?9%v+Y133{T->wD$d1B5ouU G==DֿcڝP^>H"1Z ^ SY3Xpm. G `.Xth r^UV1 uHMn-dеPS`12}&.*<\v*(60mβ^; Geif$Zw(:=llyrNF/uZ>{K7u] $aEAwJ_z;gV7;pSpE^PS(mLgNH!>KmDE4挾/ by G7>/*Y ×Pjc fQV` Pibviz9hR H}jKdD5^|.)T(wI:W;gҬ⍊8WqtF)xXp(eb;a.|AHCNvXC rf 6Tԍ0 #eyiiHs$WVU+bVK,^ބ6R"E:)Ĝ>"ʽ-wVRq.#NiCrNG)MbQHCJPF1e(Ǽ[fW(*@3: {DlnYD YppAC&,!yׄ /(Q6huKA+0z{[Qxdj.Ob4QofM 2Ri"jzJ#9ȾqٹUNJy6z"gi pYbTK2Y]/"45QZ Ex;oVV (=<7/bU[64Y0[TFPqɷen1IsuIx.*Oc| »:2P5c LP-枌&̋< {퇔TجY0 O !4s7 BYn;b,Wsyx6ueBir+VccjgrA$%|\qP:0woZ|X~nTqMϝh%gjS7z9,/T3dM=d6yEI/KOVWwLn<~\֋ٔO!Kel*>nRQ:ݨEn?:q\[+Ǎ< YasXLnSFU% @F ԖjytK{MSP'- #h]`j/kD$yy+ǭooIe-BNO@˷iT7+c_._eq{N{WeUbN)zU&HNA/TK+Yf갺Ʃk,MVJJ8s5i. W@h5JGO}F~e]tn|z:bKkYc(b{Qx/IB%8Tץ9Z޽u,o0|k]6_P,"!7K&`_xQNb;xxa /'ܶbޭ64"^V4 [ȇ{9wZH\IOP]:yVtc& W?4 7RbեL*S RϟDZ嶢1^-}cK n݋ᛆ/!KB4l4U1T;G||UV":<M/0؈@맢Fa |XE,J cAPINcR݃R ]kc;[՟+\4S_#5Mǡs!p 삫;IלMu'!g & S$x"y88KԷ8ґZ'NiBbY`6\(vb`7˜2.}k ZcUAg:"K:fcrY]j^Q!Zk $95$? #?mK cLNi>V9W倒2i5^O PҎ:Bu/%g5AeU!l~]Z9S 3_~~K$Cd1Ztx{.Qp\ږ E+uS CǡV/xE:y] TapUc[MdfI6֔Vc׭W~݆=#Ih)!Gm vƫkta $z 5˜$aK mVRL-5FI{ Ϻⱓ,'܄<6$pb=D3x+ٕ68cCgP6v^΢WM*7meH_WWX~F"H#I/3Ȼ4sbq>*fM՛աz!UC'm^mD&pXɼLsaMv53tG*{!j4)gQǀڔV7-zU5-ݭ]xԆy>`%<3F Pտ|wlm^Ǝ~v>p^gܡ"TA Atؼ{&S2wRz!_` !-继\ںWoÂ5vBLpn8L&/<[0oaJK"n zH qCiɶ(-E?frI=Uќf-Dis.*뭦Nҵ*(aVV5F5|Tr t-jV(Q $Z O_W83 .){h.;RN~&~& FB(~7`?uhf,?՘0vN͑3vpݩ䡧G'Yǖ ܥ @I,n&>/PHX9vnlFQb*MV $Edb X3%j*8'`4ŭ1.Y5;AUcSeڽahE伈OXZ^SJ׋xCN'ٮŝ_õkB^WYL?A>&%L`cc'B8US]zqy_uWmGsXXgװrOXpqkF+E' ',1ʝ}MQ vpB~ Z6ӄs@)YIϾX,pss({i E+ ƢU[Rqv8cO_] #l*eBB˨׈K-!݁)'iIp\sYz~˕݄͓\ƇQ;v[ EY_uI|$ɤ+)K[U@Ԝ^WF+# ]8K$OG^A rKk/eHjOxpadFb !7KsE}$~ZX7U,i^ַ%#/qb"^\GsTzYay;V}GX>T+>N-"{-pщjL|=|Wz YI2"*S;VDc70<#HBOD{͙ԏW~W~a 6]Hidz(H?q ױ>%䆣oEzҞG^"@5\P;cTY aeNyU1+ߒ\ !! .Sh^Ğrq($~ׁA0(/ıЯ9 6D."We1DȁJ{jPWXt}3{w4φ)ƴ3H~caSD"l4T:l̕Ec@F胷K9DhSy$5ѱ&aZ'y}ՙT j-BwmcO@aP\p$#~ C~EOV2?EoCJPݭpG lUx\9yg%waiEȓ3}(Pa؆z M sik-??[)9SX7)Q|y1x2d'MyLJs[9FX%I*Z`JdD?vEJX_e qR*dMVV!?62/wqвsGr*ٹM`{;.rr1t?P!|'gFwVɚe27_NiB*m0\D4#~ +cs;.RafVd > ԙ , C "3Xi$Pc6:!5 GiZm|J+:i`>+q cQGmIՓ%Cz*d3 O!6LQFw&^ 28V KHh8'/h'VnoS)Y)͞OdPV8b̾s!J2eg׻E!R0ӫ7d|DPZ'r%3 O'#osdg{ZTPZUN$ Lmi|əxɶгu*_z !g1\~іCù8)/dVR_!EqfX47! (pi7Q8^$2: 2'Z%u0O*"6͊/g)^8 %xeB 7OS˽zWQr)=ds_sܯIVl6܏j$2sbײ5>X*NȂM 3 nRWJ\wʣ͙ 3+mTuA?g!z'\0ҜANM7!Э6N83#C׎uNXʚ֏Ta EHvޱ.;}< 6o ލz؂iYXG)«iaW #WJr4k&䒍Q'h}Ê]h`Kʱf9=צ(aTqܜa;utů/&3%Zj5*3D3K^] @2}7mnx) KZk?ZNvoڡKnS5cXЩlo |?ov?eśf7qs'xaq\PH+ r|[OzlςaL)@2VeyV 1qkfJb. 1X"(G $FGEӢy*I(22ۤ7aMOx<.ssٚe,Fx!s'Qr>|#e> W%wu6m> o AXU 4ɷ| FuPnfdy wאT,4HO nE*k{Z^~r> u)(֡mNL'Q7)DFPBOZueVuY :T"">G,2l;Rec[r9։2nL<)@uQ1qB֎MPoMh60Q !Pۓ|K, 1g^cǦ)TC~oC$L,$\KK7c32B9?[I"ÇƎBn=]QrCؚ86o@+5YPJ)2%,QpRZQ NS8_]&''Ym6DldA;ӿ, H<7L^Ϳwֽ@|0sԞs2ݺdLrOAavRFa]iJ3IU)3&.%NM2D<>^[A _cyD?awG9 ߥFV2Hm)Aj t t!K)u D\՞I'r$IN`A_HHa9)zw+Dۘd9P=7¼]A+{X^Ċʠ!X"ktsiG ^ u#?Hbthgw4Z wSOؖ;y J0Kjq u]gɉ^FZqxQCNji[TEٿo|vJjS }IVO49wRA]l_dA*9x W&$a&WD ق Xw>'е[o*V{]YD֐́M|_DٰBz SK)4b'_r{\_nߟ{_l,IrOY\)LoW!Mg8Wgo͋Hf;eKYѲ5_xŅ]㾠~V#WعVj<dZ&¿L =bv(zJS4myYrXgqakR֝qQỵJk`Cj`. 0eGW0"Z_l_Jٰ*^,AX JHN8Bd1JV@RnZ6b).&;K<g"Z 2 Zx S!c; *`j =w 0#,rrӫIJZAErhBaע嵊v o}_?V۴SE> )Uv#" lpo134GZȑ*`e^Y{V{ ثbr\]dhy^3,P 9ǃf i& ޟmxg:k&>:g5'Z] dRnYoAZdL`%†,-KLu3-) F\鹐ÌZa>\Rv:8D?&̀HuHi)o++%nt{gQByN+u0ڮ𙮄|ICE7ncM ާ&`cZ @6(fW6BGZlQ3z~TU#w㕑y˅ t3:W7f=?_oc:S ԙ4'aikv4l>԰Cz3FiST=RŊvTfCg?D)W۞齝1(wׅ]YNI 6~=Ց2zOZ)+.9y܈M?qVlpLmyS ѯQ -&CHô jq/pc "CSJ/+#50~6?ـ yYzHb4 {.[>LoHXU8 3 >^c9b _ s|ߋL'N5qT"mN> 2N)Oe:A_5*6Co!CZOC'!/"Eoo7gISvW;OwWUhy6w({jt rzhf+sk \2LEr$:Z\ۇ\D;5Ǘu=4[x<K^s%]l}ApB(v.M,׭<‚R 1GT4r,8Hk4Z^~D)87R^N)V?95#[-/!_ ^L,{u/ψ<-D-Rx^`J7F_ If\,a =UW`9c1x=6S+ D."EUBŷWm,W/%8t| f Q;g䮅ZFͯcUh¢e+9@ڳ4TĻx, J7"](9Ϛ27!/iB腷^Uhh_{Lyl4yk _˾vw*ɡԊT!m鴠ǵYz-vu1[dEz9ާ쮕Uv7s `~voKK|~kV R5qFwoVbFM!eD]ܖ}?g^ӒEF-uѠ)Bvs!&C_D=Q:3t̋g{,ٻERj[DDL0}$Ҳ~)Ki!XK~岯T ,8=Il d v`_8iPTloiS\I#:cw9 {s-Ʉ_m-XҼL]67~.uvPN55狃'l?5#ae3r( *P,X?ލm; Xon Wr0u6h0qZ ZB074UMY D`# kD>ӥ$Zr{cq+YF pom~ ml9ڜiÃmD>KRKQD5Y]ZES-jO<.3u/uN0bCWO:iN2};s6Sǫ*>,%_Yqt;ATBHڈׄ0  YOۨ3lfܷBT ,?WZw? v& U0@ DDLe1鸜jle$5RFmSTBwdDA)m#S\fU*l K) =u5L'jwU2Bd=YFάqE@7t_FU@LA EARTӍ݂ mIj/2q9myjq`3~ԌASw-aTƃ HUV;IXKiZ/iO#W0R|^ +CMbnd:m)p -ׂ%mlid%uF^Ywv '|IUSUƜ T5=!VRhkw29OC<߮:|7` E=q8M1U֨nN%WXY7eYLkpeϦH}7c٪tQSXi@s6K2Wv|nyנ^u51%iBJfWM0ڻl=JJ2 )ئLE9þEЧXHD$hVD jdn7&>=Ivoy=3H' x&+^]k@?lT C @j^(, Nf7,^ ;_B71zR<RԾ;#D"hセt0Bu^mϨn71(yܛg%FV tl~ El. /ʱ&wbn#fg|ܗˏ#h? ("( h\i}tf݇coG&9P|v)ע=$ePu-*4!JE\|M&•NJN;R~)fSνEQrbUjjqV5ў-vF+rCNdT~f9IUktEP@Vʹ:uw%S5VLOz*f 16T՛?q-Dr8n+ߚXoR&O '=~1KJ02@F?-AVFg't NLmfp^ -27 M2%Zi3?l38VUOX' ^Ԡj0fP4_NIsj`;V@wI&סG0ꢤ;Sr]?^S}ZPl"S$y 'DQi!^䉪!i}HERx»9c7t @Rc.ɏwZ wn&+CrBbj+#I\y < 08\oݜn j(*:N!^Cp_RjpiuiwyAQ>lբi "2ˌO36rV:J5^L 8[7(3.&<,z}M*դUgåĹ.*B`>w'XEG}[}O[Nj5gūcJ E]eF_ֳ Gl }jMf |mQ\S9ɧm-sJ >.'>ܲM905v[ \Ė|oY h2+wC$S~2ٮ cZ@!0 Gg4|XP7|.̚{[_?Dz-xu*Tθ5i+ǝ*+t4gðwGGUgpf?A L@#ejX  [xqjKtϠ=Z]6>.>xx^}p;SRy7gsjW1:L QL_z..b|nK PsTtp芋kh s}3eU|V> R-BMLuxɓo:؟\Cx$׆+ Y2T̩0:+-"qO%ܤp9Wٯk$bg_^y&d.IPyO;dMl ѣX{Թbh|nj5x*e 2.<ZX{lfR]Lzl*a`tj3UjHČE?]@6vg{{Vԍ,)E4q"&4Z$x]^[l0:K|i~̛Hj%l[~_B%>nK i\/X |X@k9M{.mYŌ]4AdUKmsbꙻ,ۏƽdMlrr˻KuO T[}R:Z?S€hLXl&|"Q) @>떰Rb 5xB=s C#v(73 t}%(t`)_ ^Խ7빞a(*Xϙ?hs?#6l>R+W(kC`kٝ @)ײԚ`m9D'/"hj A<} K4!NAk.=lO2n\eR"efujj&&$KdꞁԪQFYhul^u-*^2U4.ENy&ۂ k@BnBଉ=21y\[pW*_Ϩ<#iE?.nxQ`~y\nI^y!ςhU) ̞'XTs4@`giMi)n]4-ۏ60焕# N ~h&뾧I6Vn[NJ7c/_f3Rp3[ 'K-Ao;ae{ʒN u#|Qk2HY7vH>;rH(Bȅ{PUS=8 k_R9,pj97"tָN23Va!\|LK3 C[{u/J#/<Ѿ#1z՟ۖ64A&كiE,k-̾A zO9]R݅5 @:FTΟktߡJL|;EsW'ao$ [gdnbQ(R/Hă(.0H-s=5} źr:]Yh0|{DUTT@x<\U1 . ]6:#x%ƂN gqenSqJ ;WP2jZC' Ƕ(e\hקCxNioDEL}DQhNVR3Wxn [&/ /Ƀ^Jh4-]IsVkѢ8ؕ]|Fɔ ,@ cώo"$?3+ĽIY=n2ئ54 \p߅>֔VLvbkЅ@\$ -UB'QL<[:=@.r~eɊW3vVBIuAeh=*x9*GU?4 c`D k֟d$64BEDkðLZ s]/ҽDfȱn9 mu ϽĹ`a2mqr5 X.jpqA|~A[gcX*ʾT̷3q8΁qж+eʻD;V*T\0 6GaK_x=IE Ks_:wa,QN5H}YzG- ҧ>AfM6ғu3ۜءjK!l (_h LTՓʢ5I^E/dYvKewXKV~R"s4(&Ne? +>P?p}7f~eUDyaD2Ox H6ܯ#Oɋ2o0~@o()˸;5ќ"0|w4@¦]lg&jL)qG}gEgYGC(k VE?j;FZ&IuPA&bߍ.`2l HeaާCkH&K$eb _Fs1R:K<vEN< ˚ld%L w@a1(l ٨rŌ6}+bb,@vj$O9&4NLz L hL3¿S4CR TD؝JVabs9OQk *3p㩷3a#p 5`2T~8/*awbjVvXJ &*hS yꞗ!N*ZDlВCk.ɍ2?ZGFVg"0Lp'̳7se-$!|{pKEڡԣm&vq6VFCPsf9K<>~ɞl4uWgyO{lE1!$ݦrH?sg䑦є,3lRobT;a4/uP csEYXlV~9݆ "A%6)*!@zDk*PWOm!"y)g8~[{w<[WoVCDy=M>ms%MSƚ"^u=,rZ'3E[HҢWjgA=XJ)7CJܴ|ZTdכ"ݷ-ț.d{߱K޽eףK]v q߹/V-P sbh)%_* A=QI:Ezƴqaj^<}x{e!ɶ@t"n0/|H^ږ©l@VXɥ7*SrϾd3LyfByL(Md0 NZEL+xC=)AR7H{0S3@HL_UW*d-͗|!5a))\wa`O/l^2=={q @(9Gl?9eL)RޢDdssN5)059&vw1zo | 5{]F+Iuۆse)_q Pőx=MoK#S/4LY٭f@QSQ߹i@?'(VH:l0~ủVuqAG ݖ1􇷯Q[oE5oq89*w*֊)o7zTfUdi lkU;!f?/Or%е.pB}Eo|Jy]NQ<;Zݞa4 \; 唎s=Ʀ?|\=n9pXsA ZF+ک>ӁɴvGB1T3N,ϚaC0F|%NDp=lįElnze`sսR%|lxTxy>xP4~zqwhHJ>/ ?=f#ʱQCw-j͎$Ci')?aL4'X$9KjmUm+`Ξ lFGcu D SFM&ٛ7ǿ7/ qL ޓ{3 gto55B&˄A^+EŖ$zq\)Zԋ<(qN0CI@ɳz,-W1LEVϞnV=m 5A?Bj ?NPbPtΫ@}7h#"defzR.A9$de_Yi274xݿ$q^%?R30:AD2Dt;wⴺ:2z)-hRIGI=%*Lע|ZO8ŲKaii]`r; ?GKhfe$@P(+W"̚1Xog]'V▅2JЉ aV S6Dv3F7myf6|.x8vܐ81}knsǯ%AEڠ;j䭶GƜ6PgP*R[eb;s8V\S'MiƛwgߧVtWlns̳U;|vZ@Sȣ?#p[I*E7N_JHY{I1 n,F(j5LL_V҈Y>X V6lRëB"Hkw}^}B0j1*=&'O-ȾJuH[%UW$S)OX&y-uͺjp3`Cq!z#:ebݎZ[;;cCU14@)B~?DyZM910dSBa}T.BږcBlq)ʮ-Y"hs3jؼbrup$gZ0h ?ӳ\1If*&LIZi2G0ss3(}@f< T*+OD nAmӴ`M5?trP+cP-z1> l1@ ^=G HhϽ4O_eK<\y&6;OKM#M?F TP&>Z\E\4cSt˦\*2;x̩nymX,jNbOܹ_t !GTlj1(Tt6r/{إVAH*՞tC5uN܋ZıQ(quΘ agLDw F; As !݅ݸ#J2s)-O]M:I$B ^;Z kIO]JMp6 fӀWd's@MW8wjts[೩d (Ӳ( /93RmD F?ɝm+:j&;,zyR` >hg&eQWBNGZُYmYz׌)h%i֩n@Bq$LNxb;pv dJn3:0ֹ^6L}qE2M v'?6>i+-S, W;'".Q[L_rI|1Z[ui73OehJ1*/MV ,*{"W uY<~Tc^gw!z\7l{|[ tڈBu@_+ >%2/;XRuqoϗl@5O۶5igf)!#p{M1 rY3`٪΄j9zLVAgul v\*z7R]c wFu4Y:<%Qˮ5 "# X ŋl#W:ٛ󶄌A8DX6u\e2`+rL{fa0+><2#G2y<D) bvBݵ#C:`DzHH%! oP+qhKvbπZ-0_(j `#z~y\9lZ|\ 9%p)B[!EuwJjMؽy͑r_'W"e6U0^UrJKE  Um6Y~btGQ/'XH '[!N:v "zK?F*"UoA& Vǽ$cwfrS*prPYx|i(2xB52+ U!~:ݐN`~+B%f|^^‰qAFT.6xM:kQt{+g!{iùRī y|p|J ҃c?HJ79V57l,9X;jV=xׁ}h壜Jfyb].P_G ant|C0|]XƯt٠F#<922T7V.UOZqH_+G1S7kxkC˚wYfMPzCG) 4+VDcƝpNڵ)\BWr{8=XcL2IvJ\l .<30q';0Zz 9ր3o"j(j Rjw3QO1\DFal@b;_M;owY+|2, f+a۰(+`8 mt"/RYJc Eh`YLEu68a 7,Qc S<+ׁk3 ?*<\j-NJFlX1VƓ D|?udTn1iA$ R&DK2 ׇI$FSfs5ӶM0_q8p=s<|")`#*Z5p-%o24C9ofj)"==.1QRIO ]{3NC=jǚ*v !.U, E55(" {*NKqQv&04}};!9q:3pu9 lMAHE<݂CWotKAG٘,;FOJpb*4z R1>Nӝ&7OCEMCF\>Bp")%L C֓nas; !$s5b|0E8k &ڌJMD.]mi'jr~9/V{_]p+beXԿwg]2S`r#b~HkL@MCF&Y #Ļ[I7?Zn,l@1TInIuoD"*MN_*/ Dܻp @(3iuJQ175Hs/6U,-w ?ʁ$)b0j8%dtPy끳.}KԝMC9ܭ?5u'x]KB <Ǭ.E/N#%tN{ ?,)EYoCNr"4s vH+;x&р:5@4^_ÿonC岹kᯎj'/wb.|!n{])VJ8GVoA}]2=&Pl<1eg\Q)9)}x'Sk̐{Rj-zDŌ Nf&( Uv='ƭ Mt[.NX/#s;<?O̵d6 .{4w| FMZf jJ.q4dRaui} B t(_ =QGg+g#YK$Di?0W[t[S#.Jkq\p1rdf%f#XzDi/3wĬ@7Ձޅ*0s)w$XQpfIxhl*?z%T W6)O?GىkpI׬y{ʢFUc?zJޘV*geW H3l=k2@Ggk^U} >UTZ҈ "ۭ4%iJ*_J!!s#Z-ʚgw !Ugc!jK ]LS{3gr%Ə?T'+YAݩևnUfws3Rpi{U7{yҨ5˩ʴ`mIR:TX(R~;^O6;|ϱnCe[eUyk1Mazr9s.%/ącQ ~qOS$2Ѥ ˊWwd^$H}Y0ÊMtCKdpBv>&ĵT2uՖV@`CNqtif@_XAti{(ĐkJ7(`D~'`8R z;5~lq78e4=fZٚOr OCoQG%c#4^isA4r_▛L|tuaצ߹x 9a%nL% x5 /5 "0gh 0`n)U-tzBbJC?-aOnz~qOi ?/ZbenUDR%5Lλ#a9QIEtR dx]#ɷbKh-\e'SA?Ol(-2Q=,YMȬ/@FX0 w8!HT>ZyW#K`nU]BUIy Zj|O' Մ}v1M]d/A)KFfv"Ax)(`Ye-ьHk(^UZ#޻6[1&P١x5"[́d MH'VNwcy@ %2#2p?tF;=Ϣ8ahۙvUjsnYI 7f}dA s E:έ%|VrBTc+m/yM#)_JqtN~0#\ )Z\oS7Jz`V,j9:4icg@bY=oțIL {7o{R\&Cgvl2[Vc V vR=ey+)KG1Oe*6cҜswl\vl w`v5uZ-ԜRiL+xԄx@6aZ;țHd`}3xį8(Qy9/z}龈8$o8 D*څ*n&8_@2wN/;M@MG-"[MS&`k`B %/A?Ԣ eW=a&dͺJp^35(ΒdF]HՊ|W 9[js6::kBG N! h %\4\PW,f=7xT 8(K`Ң۷bc{N~Wn2)kɥp]rSanA-.V6.R1Y[ j # b_f[sIQQ$QYԴ 9+P~DQ~!b(_+73\c9 =H4PUU:rk < O+P(J>eFT ~OH?[1rSS?*L\#B sn1XC:;J‰^+lx!Q6\d)ecV(p )~4&I&m=KBm),&™V-M+딧6^݄B ' dzHIi-2`!>rn mx{yowo͌HrOZ'"qH\zXμ­H8|(GFП t5s>!S(u:M蕃j0m*"yY H&1~t1<b`@zyX땰1v 5zOh&Vk'~eBEhH|dN !*ξ_ 3u2?2 P ވ\ckBP оUmivGp - >6LX~F3\H\ߧu'/l@. r%u7 4b Td" Lb^X3dJuhkmU@&_Lϲe?SQxb۞T^a)9F~LVxߥ;d~m49]ץo;]>uJ[0;3IN/Ƹ6{F)eQ[a7 3bUԗDtX%ƒ`n 5 u/N 'Es]niꅣ\دskn ^erplS^t-IOǖ"(3~|M̬[I$8ۧo|Kt js24l&C%<6~V(-ʢg-k"y_6 _QxVZ6ھںnvSCM`d{5w<oU PA?#N8Of x^X580{޵}1ɠc J M`C1F7tc/ iNi2e?:c'(SK6€>Jsn1 !}K-%Ɩ6V32Ǿ{C)=v]}n_ pԦO_!251 %*QFJMqCf^=alhlub-Jl/`p3 "DZTKW+- dKADgP)-G<e?6z).0>'wCz4cy1q6"ns%D(jY,G[,BãJ"T9MN}̹ !M~ԁaNmς-'B}HkA[:w9ʼnAPp^[WyT`b6ǃ pݸbcXw9A70]ЧҡY^w-1F' -YW3HNo]<Ѣ]@:S(KeY>\{Ivido[|xW' ҟE$gGG|ʤ,$ZI8 `+`i¿LUϢ臹Nq-^[ם)SAչYԎDzLs{?G)*w9q?x#oSv("RSح\J&IA%fWW+ڟ-[v0ϵ0>["+m}%'6,۞MKkOw&kT~ktr6 3 $n~,(l> b[ ퟦ'(p<:K?pUq ~'޲0~r5E{:-_)+B$0X##c&Зu3ZႻy-)b\ϫ@7`Y">[3a@`|UYw@ P p χ;^BtPhIUQc$(€ƹ=0<| YϘ_{NW]#ȮG {d"* _l3z)Lf0DrqNM֥d#ď{5`>4#kG~.Q;\ krtu_i@=[W M0(VbB,xܓ K ~c%0ۏbn=B˼/fyeϟ1^ C~v}$PIɤ/cG!r[ (R&D\RtrmS_ܤmYY^H8_{wH$P8"v>ޠNN^g(i nHaE>PwKF|0]Dv8k` 17(rT*rVp0iWv./uNY;e6ih1awiu&f wꡫEHzSNƄK*zVoQ cv%$yaZ$QN6[!Rz}I~.Dn]04u=+KI檾h~ڼɑv uoJ*دH2%=e`S[H~`gW9Z ]s|dѧ6\!VP7*:}{7ʃ ) g&e35s!3CH/ 3h;z5,Jn#4샩x cj*(w^~J@V6XNYƣUY]|k\=i֑eRWI ~D&"x{Rt̅.P\=cGkcTtd͚ḴhKVeX*w4"Ō_fP N {Y's90$( A;2152*.X{|7h9y܉yܔcV]n]pGԯ"~9W\~ HȦmnqՈK [ٯCj'<~!q Hu.6:-]61~2TC0rI>Ou60`%1[T8[z := }|KI0  q 7E' [JY(r9DlQ#Jך.jU1h*?p^ U$9VT?9NzI< 8ӂ]AiOvYQ̽fMZY*.odB6e֐#s4$9G^4r>\$8c,&\C~hRoXkEͩY iisIUAFP5H&LۊB]y䖠<ph0ɷ9!."e"*^ʜ5O%ʄ0-x$0`@Y ]8^;ܒ$_Y$ lngIs8uA]XQNpÍfhaXZ|8,Uhk[cw6NdF0ҍNRͦMz1?fV@}tۨfcvKQh>ͳozm~_mYtސE _־4D;Aɺwⴶ܏k5#V93X;hN:+m T ]5@DT8/p}qBH~<8:.t C[+#oMv}Lc2o~ƚ}Ms{O;s׎ mm`akUE+ySFpr!_v9ea cOYeōY iGIPm4H/ߠ6;;Ut(iBDBH$v'ۉƦJ,zޖG`ѳӆT "%ݽ)W(KeKH0 &u@dP-j?OgCܕ"YI1ɜiʛxxϢw#i4Zox}xGiyo$F 0qz jtX ,8;"H= ӫuͽ B7.BY1a]F7QCt@}v=z<{SJ\,ST.;?T6 幊 lӭGElI(Œ́|dRAa4R-e -V b;hxC"|bUBmE1^FgxK;cGlCsIZ;UQT[t{^ZhIU$zD54b H8ס`ɒ[nǍL2wK Lix|fzCW^i1 ߌRp4j#/{ٰ)x.7W `5W&;SIPܘ(&v)zMV`* `Jw+vQ_}D d; -HO7*5YaUf! q$/-3h7ѝJQk,L {zT}߉%wONzuCvfۜj{a~fZ)0|㫄(6 @}X ȏ3S>0' ~]r7O\R/gث g7mAĸ70{:dC?8%4PϽG4@9}SOHr(M_t5<.3$wv'%ËM^U\-%%ZaU5]0+~5ybF??QfI8y$iXy;;(` >>Ƹji 8ݫd&sNJ~V {j!DiϴT`F# ߳igb|Ek*neD(%8m>­l ---"=| 0:  IdAK`l9IMN4S秙]@5j%/cS/8SФaoqvY*# hVؽ3!9ő<["l1+J͆ވYVsXɆ:Vycݎ· ʖQH¿q';&A Zs: I0;Lv}'ﵸB{ݒL*|ui#zƕ 7W&(\H Mvq7$g Bۥ"ufXDe$ MN%3q*7oŲVSc1ozu# Ie< 'biR=Y f Yn<JpE;֙rϪ@Lp5@Խ_tU-/Qie~Vl|4$5ϏNmg=S]7]ѩރh]1+yOqH5Vn@&Z_ZItVI4R0չ:UUB>{Uheg(qV&FT=R1dr\s:QĀ3{z\?w}2R~'AAgnJOFIb⧧QwL$[&J &wYZ$ɟ~ 0\e'N჋|q0?I]k+FO@^PXlաm=(s,t_m &e!6U R9\oPKA4&ha'Tu1ŭ{L1)lbH2ay\Kp] utDh_vhcS.a y#.-4S-#Yj],"Tt[_F.b* X^ą#2vɘg`@V 㖌P 19鳁LQvgX!.nO2s9~#X9=t{!(#xaa y[P=&ZZ[}cvWLE*CNs>DNDΰU1E8KO+ҙl;5Xo ȶ/5ζ ʏ.Iqs00gRz71\Ypz8XQ-9`\E''[ߛܹkO-rio,>j 1(w.!n^x3Qz\ДB:ֵuƖ ENdž#,yP+lԥ[ɷbu-sI:̲AOI7V!~>\^ Ta9fV<ܼ~f*0vu4A=Bzy(#esat?]M{kS MqiWn5*bDFlh\&UC8q2?族U*?SMweΜ>"ElF[O#p[GFHRE;gIU{4z25ՙa_axw [Ǹi^ T NZ_r:ݳۥ &:7۱u#$oëY4oet,F -/ &v1V#ӁW %4Xv_tHD^F@`o;x2n,4k{hN b@N; #e{1O W af8PpfZB%wF)!傜0{?|>^L!UzY4n|2N< JiEpʽSU_XZ^Ui U2A=ogo*ٶ;=N؞bG [Ԅ.[v׫躜" 0.i`wRsc]{>MeiAͥe- <:QyxMs)Eͷ /M Fv={23IYMg2-7՛iv:gMS"7^z1PфӪt63׏xې0Qxw#?^ψ׀Ǭd_Hպu@RTU~=J`)h6=iݗVguKi`\N-Ǹ8]_m M˽Y=/T}~ ݄%ZP>"{ @qw3;cD|C=9{L$o$vM8]|c6 4uVӷAO]E!+?SنO\wο$q/:+2"ňosv+c>2jYX;=%Cc؅|+Q Wm U7:ckԉ^%Ư !WWǘN,C9iAT@VO1 N?ަLW6FUDUJ(wUl-IU&j2<]FïuWej HH8KW c7E[e$RP9!6&t4TslLmGJiWSXtt S :Rz ZvTsxS.pk%[['4]y /MzmRsKKC\>~fDeOђ$Tm}j_~YM=HowH:#HJpk\Ǜ<3ᒇ{/,$ H55ͤQs"2,dCN` 2VRqVUspsׇ/-JYX h}uqiZuqwo8 uf$.?b*OC|9kxw*^(Na_m&oI:O?{/ V Ϲm1Gbu >N o7ь- lҿNοCTYux t'v` g+EKA/n90IdBpr2Ip:! i2 >okns#Cuj»_ַ W@uC:P0wB\ȇWVcլJ;DZǽiPl@oytjf\;AsT@E8_!߂ʋAgsj!+U2 |8!9'd2hz\~D0 ~ t4AJ'Nes `i_z£WqXPf gR40rbtbC@y9icJgab7u>dh!H?wsNY^p ?? ~ O7 ,+1]^.J[5Vx0EUkK=)kߞ8~%,44FT)c*(v_*:ծP 䶮ZKu\P8 >'p @Pr%Q4^DN]iC0z[Cv0T:YNi8WHDLN }xrt4\-q)kYr31Pɴ%#C#s .3sgK yVE\bt$-s|hgK M[h:_Z_GԒ}ʸcySjΑ|ˣd貓 rû>\DAkugmf[Yy̍%f`ْMX>9 OF-P \OUMn o(:+(;CtJV*lA$HADInq}x sta~ .>%,ZuJic9҂l q/o (< ONŎ@4~**Z!soO[v̤ns89o$n7sl 0nN)8מ}J htlUD8J{z VlIykg=%Hq9ݓ#'T-3[eZtn )-ԧ4*{2R MǶJ|pWgk.ow^wY`&߃; oGut_>qY"2\HXEfws_T'KaԻ'~߮ߒK Y3۔aуQEܯ/ c9z‡x= H97GBxax],AY`ZZĮ{V+ɴ᧜+AqcJDRRC[;{Kc6h7h~Qb&Nk&=&uFY*6x{|Or-%tm\8ٳ2': v d؛nP|k 2׸Qx=jwͱ8-427}Qd hOFSLWO(2KC(hכxgz i-[$Rg9,HS#ʆ S:Tc{ѳG}}A%g.Ri$2ǦLe?f/?zz{Ą zK]TP_cGFL@Cnk rK̫}vؕdF*>~~À6TL?L VY+9X %e5C]!QDv4 L0@)(R`+ DtY@~]@+U: C,PgP + `br/!Et.I;&{:㻙'Wˮ#ՏRX-7l)45Hg\_ʎ ]ğ=h-"D{1dV~[ߟf =Vx`QY?rBpnjjP:5TK RJ%Cb'kB'$ F6jasnϥIe5'O WɉZV5Zpn @{A#HE~šz"),O*R-/{]c֯!dzQ1)?, 7{['"L}?$LtqA/d5_F(h5V Y( u964G~+)VYd`4ѡBc _{_o N*XD_#+Ҁfz5>CkyN/vܟSd(no6GV{iԠo(hFJW .(caH=3ڋ(CR z 9Nj0fCjuT끬/pO eGA68=$?o':It?* p-\ҿXN~?oh$*%߻* (q%2i9J/Fwoq FiSgxw])U^%Qa8>CyYayVmʄ$]}<} )j2R*L{G;7viL.c#eD(s-ZEJfLi7UQ2$)Ą9JN.]OJ a]oDC'ٿ%C_`uK%jD%O!+<'˳8iJNrmB'1`lghP:7xm3JʦT:=B@!ZfC"3H샧LuG}9׺[рJP}#dRs҅rՍ&AShPs ;ceόpuh&6˙-}gb9͟-CR~Y>ǯdciU}\ v*#=zkX!4-{-Q xj ^a&/1%!Rf eŊ֣\.5@S$й]bbh$$E"MW`QLlVpn!û:7vk.1 Ňx<, Wdlѳ6Uн]/ eǫ%N98~sao9o.yK NF7#;442cR67|̓ h8R-:!]E`O?Ã) QRiDV%'6VuJ?7(ɁOOV8^1m\?t+,!CW[<QEcJkNQӹD'<*e^lFIjxT>(Ze DrYj{*j'}sp! gj >9afڬk(+H~<ͤ*K澜]La!&U{5ƙsRb8f|Evwd⺽2E[,ޚlzI$"ϛvyruhH!?b6UHrkJWƪ]f,Jng$om|y kZ!zӿgZ]JdqNy:3NxEԏye,pnc7)Ym+Xg]LGלT#Y 8-ZX]0}a0lFB܇_{Bj^$:?%`!~x uߛaa P'\6*2XۥW*>l͉qpM'e(N:})AysF&85+px-sٶ 8}zcr6LULrcPTsHXQc\RaƑ@$O/cԷ{BH[x/H61ZbB˴ UVc*L;sM6);+ğX]g1JMi+IdSB/ Pg8զ E~ PãdhQҔQɽ}8pla88f Oţ߱bp"/I"8~$8zڗU_QM=e=v0C& \J lO`utd]d" orYŮ: i Ya' 3Sf!2\EpTu6B0!#A9i];ۼ@ N.`, 7"@JcG(»Țlt6 $XOSinȧ}< }c\,v,llmJ)y78yq[s{'Ѐk RC;|_&_![Fҵ WCʕ{z`Ժ8'5wvZ #tވ$x4mU(8]Kt'B:_z;!,.vh</+ccƕQ$k/@lϮ=4,& -}(@^AUݸ0uQ5 a-Ku|g{?J75)89kͰdfًT*+yՠ+svs?S@ep3y.T_i5Z9v ;#$ͲPڛ{jы4eqssV*O3#W6죾-E0:{8,Mә-jFA{Jog/:-ӱ˱SDEZ,b zU|@ / ?q_D0"rRn~z߇\" g!"3+1MwXcJ">8؛Fs ڽ0G,v~梋GttM5> z-9|1fO?Ϝ X&iEn:/g7pzݱA7dDQir%gԴ~Twh=|gFwQ%-sf[k$da ayիŵx:ʵu+!^[sFپ:Ξeu\jkg6;*AL`0GI^ƚ2pUC_#[ކ;`K tM!|fąD\6ZYU35{# Yq^"-p `\UҐp1Ę!ֻzj c[w xK%|>Ԙ6Rm8_ۏacCc%<{=I;6.+Dj9Z6K++@_1Y+#~; w%5XD);@>.whd-^|5C%VLpuoʁS݅k&+Ysh*eӞ0dQ [EY Sb:ທф*RM }% rH](Ynvtbs)̄loH'p1*x\ -[ڸ@6 Lu^O *NcnlOMEmhNj$nSm`KZm30 aLy@{DtIYcĨ ]1Y?JX6Vqm2C{|b{s]bRӾbc|)>NP%52J`]ὰb|PHE5`_z9Z$w2#/tHEX I5A$Y#^CHe6t1E-bH ҆3w 8Vw7BWpV\0&M2fuc. 9p @W1|b^BOmd}O>hd'N#oaRO2|nh\ ]eymF| VNK>Q*2OJber\<ّM~϶ݓZ,8d_Q%DXJ ]N1^=n+ySZiOe+q5ļ.yx7zYrB 1Mè|KTWan ] cґ0 -*isL&.[?OJmb6XhPj͖_tfU OR}8kg &ܨb銖k!w{i9PO9ކm@mP`FYc7< xmI.W%F@;V8@nZ=(d\Zd)?,&mȚ C`慖e/hlP^2hejlsP1[Ы^EnKQjODJ 7dpDzb(Fn1;MW|H@pQI&53{$(Aنc sl3Iz˴t1<@/[`!eʄL6rJ Ub&O6F>"Ocqr"FP AfE64$_ۘ!jlh%*6f!/vUIa8nwD045S>O;}y C W2[Fc1Y9HN׸U^&\Bo.4)x|EY8QV.2EW죎Ycg, Cq!3!|!*{L^ ЗEXbl?L{/~(T_ם0u1~j>= Uf c[K׏54CL.+z\jy0!T0Ns9IqW"h,0pMScL) khR3>p9ZEn&Oz5\O,bx &_h\r*Xlrjdig7MnϠEYW"F,JYv[}nPr;/,A1#ol|W2~kS-EC`[. ;d8sX>{q}DrԉB=@fذuG>ꉅfb^E2a_thU=(N:nvSG2?ʍ.dr5 |hV&YgP+|o9Ye*[ +bsQUŹOv&E }+8SCǍ!9 L@&ux9,lY(4u"]1`r* v{J佅\AA;( VxTJͥx>\kӰOdLJyBD$/[64HֶCP$Xec߇筤MXMdV3P8(Bā͞ߊ|"9eRʠz(;["ZK0}ٴ9'n>xrM:Ⱥ%c -x|߷ˆ*V4-pPnbGז6澩K_Q}>dhW.$AyͲC@.ȦG~tĪQ nj|IyVEg~ =t^)㏾ARưW#G{0pSr%aFƞG˽F;/Ӡ N̋ܖjHQT%PYXN7Ib#?fOL([ajTiaXaB?rFP8@uL-*m.8k/zH mrӤ+JfujOd|X #N3Yd&!H{6C)I^g_AOx y2>_w95O5 Nk]6})z y6|Amdԝtf듂WBjNbm5KhM=۔n{0 q"ŖM \Adͺi76qNJ# =$?XcBM`ۛDsozZ?)m~\4e[qDfjQq ' y ډ(‘-OgIIDy$:Oʹp8ehYP%lp_M?;AO<up5V4n b4dKLӜ:Ʀ80)CU@@. 6zWUy 匫 6a=Ӷ80Ŋ@9 V0y:cSݙ{$e |fj_CM#ʵ1NG\ܠԱTv$ 9_ɧd^e0s~ubEKWʖTﳙ5S @ X'Ĉ|o'v@+=$.;MI(P,O?8'y:w4nM:^'{T>p>%/u9rHwA{40L3rbH:[S#橓HP}̿Qv75l.M6Ow4"VBT ǧEӞܴdŦlhQ?*>G1?6D佭|0s?lZ\ D@b+Ed=g]I*"5jt}Gh9{=@z.,0eULiKYH q{H,tU?;P#jj̧ /e"MWsT#BekWMk)2 TDbycś5vS"o&p%Ҿ)0!$۟ &< Xj>Ya}KYTi~ZY6||L'C=R@"A8^@>_ ^mҩHX@šz:^-} /U|T )GMnFX4{rD٣vcΙEhf> 5vI?,SQeSؼA͜wުm?oP! Zg1e$.J1VM#+Q$-]W6# t)s{U&(o`q>nDo ˬsn|!, N 0glnޯtڥ@v^W J. 4zf/j>Sl8M'.ֈ9BRm¦q<+|%>A<7I,6-ٖ[B4 >+<iU?[֨f'f8|,j<=o{&тQce0|@TvÂ^ D%Owig'l!$ËYQE"5æ=.!(^b63\qFW6[HYUSZk?JR o<| M<}w.-O_`)W8H (~t$ԻR 4t@`_Ֆњ})O(弫)5G>'oj])L)۷rW,%M.iI8 bquLF~] 8+w.>޿Sxq=ܡSgA&JIMfk) MV?H3K "&I@Ft5/ (WjM79mSFFvCQ:hzpBAc1T `zGQ/ ,]]q0 }:u9 ڡ0>PW%"Y4Ȥt|"O"[wG~"D h:8TZ*ײǵ͚?6k y%˱,8z\jrB[5PO ]jі߫׷_V@?z+Fn˯;앷_t<*wPbFWl{RCE~[{%p:cg .z}s7?U\vqMr>~y ij _$ٴ Uk[Z[B8ʖ0h뛖+VM(R+9Bg?/Č_VEvI$u4-v#e3f cVq\tȄЈ˝1xVUj|^vfѵKcr c-KZX_N?˛TpQ+tX#3IdX=7WT‚ne*U&.v즩8"w[] $ 9b (9Kp`tNazYi<|ObTTqxf8gp,Hmm6LBn5_G^'\6{`ӮjNWmJ9t|Dmuwئ&f k'4߃"fT Tr;.qpc/[*}$3<6#hOi" h.l[V%B]Ƴ ~鶸FA!괸3A#:Fͭb 5MahF4(vig/[Y ~5gϘ> *ۚۥX  86oLU8ޠ^G0R: jN]ΧHQS&?imsp,q{4 V_q[n?Q"oAc|d?N~RE v9 pBɣ GXfׄ-j4aZ2A%]?v n{{ +^@-y"xb X͢/1.5LбH6]QVNA>*wXќ*&3]*dȸL㇅Lcn/hK5Am([(OZv%1Bwb'N+WpV8=c;8<=9F¬F]m؈DoD=R]DGHxZ3f쳒gsÎg{*s7M\pХZ o_b<7U[ $щ417J9VgdPco)c0XZ[ni*9| K5KzwfakǯGz69 ӢL2@q=9٘OP)A6`~ηp>ŖorKF_d۽>^oX[4,"7LvO-/>!Nͺi_cG@Cm)KbG'CҼ$s's(X˨ F X!)-S$}TIae 4+u{wĜZ*=@G<8Iu{EaZKb^a03h^FTa @D2E)9+M1=o3Lz7 3􋣥-J<1nF.`7g5*@,pP{4E$jz`aNazkub9o0FTɶM"waLVl35㳌(D_MD^/~D{rL9[XBbaF( )=Ľ:13^ >XP l{ 1l5Dd2RPDJD$YUz S ]KxAzw"{vSECYY7F~+{ֽv3V[m/c]EL?F W-..-OzJV >RšӊcdU!SO BHZ jV@Us Vdui?r@a hTVܨ?IZK4% 3IVݛ Cͱ}xkAv5~>Z<`1Q@'8#Ԭs kJsG9Чy'e+CORNuK^?}'iH\Z0ASgx]ak)xuIJ7KU=BkeE'n76 o%A-ͅ[\t(Jn3 ^Zm]zGyqaq\QV:EFg@/DU1h^PpGOK+UBZ\2-MqM? $<,rzsNMCw aTN>Y}wU=Y|__|THc{aQ:!͜'oK0DĸWn5LKGsbÂ)4#RaDO,;ihfmkgEeݣ.ksBO6XGX_qN!ɧRƧ^̉tCBT7v=8Uf{$JHQ&ῚAyH8r0<d҉ j0SZ/i$5Q m8!Yd)pdJwzH8HYaf~ >_q!駧0ؽ}Sꂛ/UvHʃ)-+4ъ@Z긁'XN]PZOV ?~ ke׻=zk鎺4 Nm=S\e # .eQ~I/R#/qBo8@̱ݖ!M"%\:Wp{L,gc+  ^ |᥸QV1 KrNѲsCWn FfM<2U:AMKi ^ɼu $f-fajUheI'8hɫQDw gױÊouxdyާDXsI;^+ҽ |M( f'tMz u)nGnNo] / u%{ϖ : p0řAyZtDT#@ee'.UqQPE9bK&kGX؝XPQvCuɆ;y|:| r5y 3#h*PaNQ Ƒ2X¤psߝ 32t f2癛V&4(!$H5r«қ%jЋҰVpbc&%IK֯Lư2E:qIyJ $]L&sl.&Wh4/?_rkh~*pɼ=A[Tfy".wPZkq^  z2 ) ɿhpӓ-W#&btp3, {ӅGJbqFCdqG,ݝRzY/H戯A15 M ,XEBiF TO9`,A~Z eۿǘ3QP8!u͏z ؒY`ael&r Ob9Z!:pfV-V)uuUI dXܕ} yMUαl"~WzA?,o2lqc,D:\s$njLpNM^|L}N S73r\Tռ֯8 ]>L\>_AY]N 5_x84K%%+c@_gkΏyzf! .~U?u!P4H h'_z d,T)SX^p -ǗUA~pʼn,nSfHi7&>qyienG@|' -/_1>(ì[ˇm#rWҹlW{:.SV=7uzf>5N5vqꓴ!~ j*}\ qz q 6)^ Iw/NO{x倃BzCT՛&gZa8?\=߈j378r~WQRl2FNl~7lZ>&>\{3hN@9L%ċ)8bz|?r811vG v}v^R/bÂ&3` L,B=8:V=âb<RAF>Y M%x@ES/:$G.T2%E^XCXJsv;5S̮!è@};T PPPhow&,&(U$#Zȷ>S&wZȍN~iY^1 3, LxD*rbqޞT dM EN޶ c$U ٻ8ܳrfa. ~GXEhqJ])"!&;[Ƹ⢄2{ˀqP;YA0 |{׸auHy}P3aG(]Вns %Q ^$yc߷K+,FĘcLs<{C^SpSsn (=|>Xi͎m+NzdC+2iqfէ.-!(RM{ (Ple *E2kBcRg]cwZ4qWbOԚD/O&)z"'C'\Y|Y4 I6S6qڽ3 T  ,G{ֻ✰ #WO6X+\b${JtցܮYkt^4)*F3|l"gS(1hG5m4Gee JJ> ]wPm{O$ʞ n,F<0U'Q/>td-mYXopfzv MO'ˮ 5`K iwJ뮕}m)ݘ!g ۍ*TOm+rS螮Vʭɥiʫ&Rg.N&gu+ &/,hMPݧtwN&R'& 1xTkOW6 k0ֽt\. QzMR/ 9U<,mi'/0Tma`@ 77!C*)C~G\"UVTKJDL1Pش1 Xj8;HA\Π{ayO4dKV}\}B-n🋭i%;W7ĘDD:ґ摢oSa7Sy^A.VH`V0,?sʧ7m ;c%mHmra+DٳOu"$A^ݎ7$}*.<QtE5T*@b+3Ekڹ璄 \]6(/T>n  T7&_$[;c R44clXw׿L H5y;g fС#||QfF\Bق$TouAc+hr#ep1)uDcw.(+,>>Z>[Dq72j5ad UM5z=!4)3,`r]<"$Ma'r,LtsjML"`\@}U+n8 T(?Bo!P˫_#lz`|fPtu/kס^kսrؓ>uQ [AYNʴ=3 2BHUrex ߌlw 1&/\GO)zJ(=!2?LV+fҫc{:R#?#lW]$$m:#;U]v:tUljK#`O"`.G>S]^O3dn׌kXC,hIؔ<^hULؔ os?dnHQlqaWUo2Z??枉y{A2URA!* zjgd`Biz\گL!2{W{gf b#PcA9`rVX/b,((K&!o!A}: @HkQ:(PF1P7@{}beȏOE}i F~C5S"Y)¥Ko 8!j} Ӧ1[6{Xv猺5V leO"g>F *Q(L~lLCZk,lGHv(|2Kj?4>5@cH~S?ڨ#Ucf=}k<]qWQ%.ޝD}>cʼnV:|{JqbB<t29qfy=ϐPBBST+9e?lFUt~}/ 힫Rk6ͫ6P#}1mG:Q>VPOr{j~ Rq$mAB)5zhٓou{=OqtN({mNG$˙hXK0m٤TH B?g>ƝYukBASq7N$wn",l/u|cY֨4D3A* ֦9L2ZXj\4 ѣ2ɐbM. {7UŮ)l6 gp|M xޘy$~UJM[ᇋ.~X-!H=~\n|n}{K i Ji3FSV@+*B%?s>>yڕT1 CWN`:-mk{:G-@썱k Jo}("e4zfgDŒ6gq̠˦:qp!셌4y*3k@_;YD܋S-ֹj3JS~crqẗ́V9aA/tGgM~(R@]s%\'أa` ~evuohR'H5%"NpPŇuNDdwA &GLU±'5OPHFt.V#}[m{7<1 Ci"-%}w&IQcBTU7dT <=|43`작-] -ʝUVJ \8<=!zA'\*Y>52N_mSi`gE >:#zx̜KjW; )/NOW8ʴƴn&k0EUkWNmfc$Mji^ e*%uW%mxn͘µ'Osrn3~SRMxc6^eh܅$f~I؂毌g&VЋrd+R @phomjeX6k1v)#PCodm@q~8>?8F5Ҳ7HVGXi;NAI)7_YSuWNLф Rʆ3w]kRz!InCtXqbm=W|E'帩 *S2Ŗjb¹1y?"3_?lMW${n8Zw0uw]A$UZ6*osdX;Y-ѐR)AN8tJr AS371i+&# :m'>!6$灎"NѩkYqC.KչMbl@D1^Te`-(Պ<c>;R A> < ׄ1xs"8CPwq^ eF;D^Y%ƒTIk]BdSXW=-97LYM7)+01l9q pG(e*Ⲻ- f>J a*Ҝ=ܑ56C4\ߺ~Q3wY#FۿC ?6`D'G-J3:E`P@V w-q$ /YяEA|Tʣ(7bx")20VIDlriV' yH6*RF#SŃ_ε[O UNn xҏJ RW}TC¹(Ytr k``^h qg0yHn1wM?3#D Ѱ0*uWewQKFi-S|%pœh7g]$`miCOI" څیy[h z3^Ef M$Y"V",XDI ex):Cy0YO#tJ=GӟHXnV2^}򧇟 #QZ^Yqr&5պ+Xe!Sutbc|v_q,fC0A һ$h^jV U1r0W[is6VOf>BVdji 3%D }ں+[lH2;Iо|}cPNȶiN\<»U9Ȍ"?'?jgFL)}jO) \YyͲ5vp4C5AOyi\as#V|D0qj߱~iƔpKbPcڿ#SR&x .ڕ<:"ߐKL Wx##M[Mr|yÔm@u͈ſQq>y`+Oħy+źDW}i&s7®^dKs[$//bBre$g0'C Qnp۬-V!Ҳ(✌$` pKHBɅHzy8JédB~mq(Q=+#n jX!6rҔ1!2'I9G㖰%!qa=}=srqy(io3'`@CYm!/u`4d~>X9O6ѷklMNU;z?ȝd~ouU7$»Ϯ;Գg/<·ۘϱ>PV"j@sNC+m4H?a^YdVQ̈GۣT?ho}"p B^rSX'(\gFdOma _8n:'N:d(w@J$e"&؉ x! u7΅nڋ= X|MwŹFJ@R\XﴑLFݼO2O08|PhxN[H7F\zUՊ?`i|$NxAޞ3}xX >z;&iC0$ڎ*TTXWmƶX~N )1LNXMWMSOeyEBbwl߃}F޴wܩ&L$ ק;̄h'\gBgX TX$Fdf^q;;v`~ace5tLCrYT2Ѝ ~E?釓3ݏ@}q?Io5媩K^?>a+RnB;lBȭ]mk7/)-jfkv.޶4 rΔ}D;^qU.5Mffi 0CQM 2xUD:"7|،(pqɆRP ϖI8?16jI׻6})$Wxᓊ¼Y|];=FC8xklHMgBFŅ} TDZpǦ_:rwzUʩC"9= "Dgor qa#1nWSr|UNޏϾWșsI^u#Xl$;5e cb^dWCo{{ՋfZ(3Sp'A76QV9xzX0D#% 3RQ ,x]H~ԋa.nTYV Yzi,Mt@j<kttC.qm![*8 VyibTR/Ip"R96D ph6\WPϖ)N$$o5c<낽ZІ=Bv㉤ G Τ4(9צ5?5J?sXٟo.bt|kZQL{qbxK'%C>;oBLyqFkhȜ,)=Dr5^Ll=.JQ1tfk<7,/ޏ|n@)nq [^2iwRꢰKexܛ\ qg.H׽Z_Ad?,9tG61H G? $5 !ƤIr)%8 scaG)9r#TxHFى,XYߙ׭Gp*UAرCBrx4p~`]72|$iUR<Jg8> ϲ% ڴˈq1́z9b鋳7J:#*:Q>TqFsw}wl9=9JؖB1AR' ?8v8LQtG3r2qy웦~-ߝ\8' TB`?j} ]bOJ 섫&jt{;؊BGT<qMI}1'#.6ǯF[_Mv=F!0dEGf#vch? .O3qh7&[Vf}L>I_bԂ9fuRu&Wj92ZA"J~`]\/ }#|Nf\T"Oy1r E`Exmk:&828m[<[@<а`b-'nGDeSl] 5MxiE\Ȓ>-1cl8)!ZӵA7}OEM;~hǨ=l댵xșn滍%,((<"&-Qnq պ*_mn>LԆ. g) wԦ!,jw0MJJ%y)WXӨLԍ^y+7̨CfԛWv 䁧Zh jT<'U@H$8_Y]d@2916qB_tX"'`ϊL3i~T[Y%,i!Ш' ed֊m5"7+qHl`CJs}W{a<-H~dsBDhd6 mˆyy$0h5D{] Ր^)<U =1y=i; oEKt#˵7ussz~nWFTz5x|HsLpv;Ŏ 4Fx5(!}ДgJ$b_!V0~tc{U!ZGPIk 1 jq(>Ut{{9 v-݈D܌3f]QruuTUG QE8Hl<&.Zv$ > _d$nz}-,StDo>ܐ2ˎˣ{0{2as$'J'гZm:YO [S y/׋ہ ugp[,}}/rɶZ9@.%Q)6J#5aÉFk!vl0tn imK8,ߊ;NV. Xs]xdM98TGyE֐r gx/X^Tz 55ٓR Q^# Ҧ5̀{|1! ʔX'Woa:v՟(; F#l#T [Dsm+h6 Ĭα;Do^I{wf'5݋5e8+/2)m|u\{2S!h#YV6jw*2ui^IL@rwL&7Ajk4H"1E*]_$2b;:{Va ȶţU Q.|GL;}pzO1H|U`R9=ӛ[h~2d +I׺_w2`{[x/ߏZҏŒMD68"p;lf1+?B>{BQz_p[h# :L~e`FmRv"OdX^a!8J~Yӟ D Cnh#ҫ@aaE2a,,bӣJY4|~|CV/ᅣt綩jF6lJ**⟣GTp;%ڒ7DNtmu5 o>Jbub7MM@A]6ܯ(bήXrַyBנRo(Hk^'Wa7uV dș󘵌i^1m B@qlg :| Fq͛/5 ͤ<6UV9p#6]쥳lob[Vo/X~C`>])l%`iSPIs1aaEP ,h.4 pj!܅Qo}e', ZުLXS{ӡ+2KW}<Kْmk<^np h8`lTEti}_hj 9C:t5z.@wWN:jGr(w3^D5x:4^Ѭ^IE?tmK|h]z{d:i 4<(;K :tCox0+sޥp(l){)UoS*i$QG 4xDjJ/5 ݷ -.Hz+wYi}X?ۺM{A\ ~`:g.,CqN[^&Y"۸z\2 YLfЈI)pHgsa T ̾Abћvd4*c]r 4 i(! - ="`l+,h#_3=ƚuɾȻCB@-X :lÕ ^办 k\džgX'KK=8OQѫonD 0J8/iʋ`?9a ^mrSVAg}Eλvb87.-gv=Sl.pL Qi$ژ^;>]w}Qu)*7)H0Mk`K{G-Cl+u0Ehy`hrg-fN}5=n~_V5|#y[` yl;ekkN?o)a44 mD"^vaߎkZݷ_K4os a@bV֊/ ­:(MFےl^En؞;!綿ʽPƯR KOKGe8sQqWFi0(OzbFQo$?@ظ򹵏2p!}cK }=" \ m‡@Et1gY[fҟ!v)E&zyV9)l8!)\2pЍ.~@E &ۆ tgTŜ5\v XCnOoWddBMC.+Y,z(V쀼2"n7PcT .nJN_! ~ PK-VxLnaEq[cXb U\6 QR7TAs2ΉJTn=Nܙ6c#kJ\(֐a>OLX( . i"15;% 7WibO1y9[b L\F`\;k B&6R>~qOlV\P7^`o)?%|r_U+|`6 ;>Ԗً 0ā{ ӧUgtW-køLܽ{^ldSM樻$?j~_h KYR]?P-T)Q%bWycA+.an{QyR>LJ *+SuQ4 |Ȋ9kT'%)Ɯ)P:vC#Lp: $4AJ9s@UȜ2~rh:nr"(0o@F{$L_`Iuz5]>{ͿXpmR/AΤmpZ _ub!%QAlT.()]G/LMy`lf=R!d-̜~@w] '5 *`& a<*aFvYq P=mphr'^軨aכ6m<ੌZB [6fV.EH$w@݇n/:IB܊~PO椅pC#@mn2@{9ٟY^}tFWjF|e[Fy:y~"ߏlb@!C=u]ƿ ܈&&zXUbt TA/d׬Ȓ}0ۄZj?XC:ݠФYF?Z 4CbQ4@O*x !'I"F2N^Ԩ5Yߑ5XegW6T6N/R%Up!i4+)t?nުA.mA6ܱܤټ KuY` +R3)p>oHe41 rL^Im?b]2ﱃ/Ky2 ak65*?^{*EhQܬ$0/Yt|Dh{B^+Ma~e'jE Dg]TQƄ#u9OE rĽO@1pVzCln,MKk>lLLY"~`4aYkf iƎUQz)H#v<)pfO4@jО #Pg-oѐ-3_0 R RKWԩ8g̗@&epp@|p(?$Fdϋ450XTo6Ed`5㣈.>y+U p@M0]:_p0^H9`6۷x ~ڥ3 $(7Xv #zԻcb2i'8cUGUVr:jƐ6lj! .>c`@-or%wj(tIlw[^!a^;۹_~Z3Kv[s&$`'G6~PwunK C6]ĈA{hg2$| =|hQ\.S&\6] [&=c+xhggZWJq!) ,OCL[h 㭤LQgRWls. a+1[$O̤mҿ:*)Y߮.@b>M4P ᬩLVunx6ʅL>֧ti6sk}-Ӫ>xcuJxN#Xs /fnAu%lmxVE7@Z&] U=)~|Xyjg)З >}'SI( ~SJeKbhW.:&0!kМd젤 en ]_Μk iϐ^X=+l&PC_RΕFw=S?v_E`·w/pFKMz:jw@,>WMǏYҔ5]x9d&ŀ(bXjD?O"Q?ɸܩb!{oxM.zE- W0GخIذJ洑ϥ^Go?#ōwED+A|#MOl3m.z5x_.m n)j /EPӎ1 Tݨ>aKg4eҺa`FFyǯPǙ5j}cgirrc17B[Q`Ź_U|]!3ȐF6,"dױ6):cI蟤7j|m DoڒYp+\e;Ê)L7Ň1Z~FHm<)j(ݨnmJ,tܥ c|p ak}^AV%F "!N=Yltw ~ xpɴlFj0l_atpT;W{ L%8}L ]eS[G+Nt$(iZ8zF,':gNƱZ:@ʂWP>! cdD&O e-R8w1$ks9pkP5hb;ho,Ve|k!ԑ2H^w`DǜH7?]  6OiC^6U|}+^&j#M2>BJfQ/#@4f^~[JaPy4+聬=jpbok">+}Ad6ySIcPi۴7aYTU3@LDMф[jV[ѨEAʫL6*R!lhI]YU›3–Nq XXݻR)="œB{`Bu6S";ɇ]d}/`FC"+dX-y~˥KiN~;$WԥD@iw(EDi94?zzHJr$B O#C.yP9ei|LNh Eh\^xWZ4pT`{ 51,wn[{u:Uʏaz)9l<'pyY\|PF t hQjdsR1홸PFj7Z~$8߀6ܛCk XWM948"h|2u'Y#vU W=A=wy$ } ))㵎!vh3 @ ͶtᒆPѬ\= )٣"൱e49#蚁n[ J6~T7+R ވZ9"̣U@GUQ!G <␏ൠ9ʦ L:;܋x% 꿋:̉J41CѬPIF^ū,r1FOуd! 3K)sJ嚆c?Fl벭aDկaaWwC:ZGwMϲ4(N/EHm[{)Ǿ(w{%23SI>s}!EA&7ﲥv" p/O((:IDAiU2QDyN"*e`4K/ôg^qgFXP{DZ鳗 j-#?^qVp{;}Y/tʇ TTU T4MQ:nsuyF)CA̢?WR>߸ćnBW<]u6nn!*XhXM ٸ0*6zVWzN #݌+<ѕB3(r*4k181pGB!IfM dٮ ޵4RvVm" b!"xE4H@/-*j%@jҏ:?Nk/~lgM<(\,-E/+'VtZINBQv(7Hzh U4Wxc:lb+QD| ?۳n1?PH8@Ca4YC-kE[XaGe@$rmݫ#Lw1$1,9%ܑPUԎ%u6Gr)Noup`In!Q"u yl#.ʯϼu Hs5 O}1]9Ky{wx^`$h.aQ&e{ N\u@pG#U>F,ԍg XR q -O8):lqsۆ~3sox\&KT4gaU}uήV_tQz OJR54Lri4gl."G:dswyYГ0ud@ q2境xQ4=T*yڧ]|ib!پ "nUb = /œz Z TͲi{.aFeZDi6RafWA[b/ Sd;Ƥ iQdDd6Q.W#Qut{nsҳ Ŝ B^7j{ʭ/:./-}92%axA/X|#aW܂ 9ƀ%ZGS7=Ҩ`UKi ,>g`rn]/ -x ok/2x)7JЍ*A;sT}’t'] {xN^ed!> UώC"AKg+ȳ/V|/`jL+CK;;UGlP7Y͖l}'G$"橒=t~f#FK\  [*ڭR]&PKv75@T[,K_GȾLT'ФʼOC.n{>-Hto0 laNf=jui)JU-1XQu=Yp(i5bJ,ċ= FE>j㰪W5AAV[/@bcowwy/͵f!. xI"gn,[+IlIDn%:OQ-3.`<d[x9$6֔O dD["~A2rZl0"eEJ$To%TBk옐5!džW. ❸-=DVx,\h!B&mZRx>r_>KNjャTQoY`G %5H$UkNO6,SLDkRZȔin7^I-ǒhbf3O ?x X^g.91icM53$lzO6lGOS͊3W𮨾~ Uw=zԻ_x|6co$ِhC*b.!ߪ9DۣS|65*&q/m2nDZH A$[F1,s(F,t;\є{):XD)#ő>]ílkiD/gZ޺`CZaWc GFNCt7)YFDޯ߷K5.5C9>0'װA6P(5Oi_@h~FlN[yۙǡY4c@yoqrh =T [!G4{=Ƭ蒑 T5dF4}MC{ZL&&Gp͸:["8'cpsn#S6)ҌHPa1JPCéOM4e @1$+4W~7%md@C o̹!=3Eϊc?Wf 4qR?m+Gwe6Dn1!fK-q Z \0[rlY-Pմ.wJ4+tӯ S nj[ ?|JI޴`y ^>~6kZRHiġ%<~ dvHG(#;@\g#cZPЭ3Yi_&NvJ :dl8ATSG1A5v7[1Fd2 NWY"7=þxy_GqQҰw_p>S_Fq' OC"^5W*^$bX1>>hG+$ǥ&ZLv_ojP˺~*T.E≠ wXeQސ2ƃ,wv[6H(pg?h&A{=:URMDC|AE'VI>e]tO}> cZP`w#+p҈t2sbDM[Ug$.}˯Q9?F9+ΏA-Ŀ[8?%ZfGy= Ԥ 7L7pon!mw|Q'Me+w˘.=z{iώ,ێiI{j` 2;AWp/OeOC^GpT pu/aqU&svUN:—{.]MF%JCPCϼi_0-_j)4v=i QzpjCm,~<͆wdʚUBxDEXϥ V;b]RH;[b0U_%n/5%&\ɤ與Q+gut ,źL))iF.j43GDxplۉQ Ny&`CLLƌ8\J>ovTqO (%T6 C* ƷOsn6Z#+h?FtoM$ma5>HRR B=t$mN;d)W+`k=i'>#=蟸Z½fc*kЏٍk=KRMgnHSbIe*D`h/4}{5DKcG2_ pfA ,@b256z"|?~~IRuRɰn##b'8yEsY=ޅs \TU}A^6_s1 Lb-ZH>]|_ݒ1AZkQyta+`v|6Xaӝ9F* B,m%$؛~v*$>H_?΍7 x}oۇ)1s=74oEFu  Zo iX)=_IWGUTu ªKwՃL:mp9GkI{VPopʍ2 ^:PBʚQ ul:$54&+b+]#%˭ NcrU3e ,YU3g d+P%vU\N|>~59T|Tk+`ʙ2jc̺Hŗ;eo%s-W8p}d6qZZ}}/e7YHpb}?}2.l`]oI(ft5G`c} nl/B'i6Mߟ,p/IJ~wB9 fnL/gϜ9U-Vfd^tvihhp(' 22hHG#%Ju;\MD4`:mmJZ2JJh9Z~qs#(K+8ƀkb2ͪGϏFNq6egL'9\_sFՎrˍvu*VOaq4{e Ɖ.7dqaWkE/5"<[9Y՚%8|)YAʩ~L[(!"Mp&n/l9<HHDń&:%a=Yag%A$,J:c;dȴ 7`UO3 wJk{JOP7]oztUw,: $V@LqWЦvb ՘ ge˞.*LQWe N "^{7ԛEp0NfkgOoǽK¤0}./RT,c /Xfτ=;s %tύƉnu[Rǫ!ئ_ d>b0KATk3ȰCY)Lצ:㐓 D/i/mjAR݈,Ҿ {cpTo9ym%$FD.\?}8-2t'|9:R+"c,ݺ.#Ʌ/oZpCRVKՆI55RЖGTnKMD]5no6}x.2m}%ygG=W?gZXeYxu3Uݟiǟu[M.95̽U3L=%Ffdže~]~?pXa^ݓ=EK#0DKi{{a`S$Q'Uq#Rin 1ŕv55.d^os;1 ;)s]$dB s)ZwOeo>EnɔLzT]B%0-*F49UֽpG7f~XVؖ\^jf7}?آraÎݩ4(| s=&NI_T;垁iYݜ7q{NޥP6ƄGB~h̶%߂zvlHV! g2f(6Y{{[ %'b-vq*5Qˠ# (!zFKD|Kq ɼΈ񢺺_F\Y-W+C1 f*kdj_yjFҏ5e;Lmbη6A)6Se ѡb˘Jy@yV)@qS*ܺ8*h1C Q%luBN,:do ?[+ })v1E(/}~L7}Sȓ#Y{Uࠒ>~/rhZ2R2H}Px QT< aMw{pow33(ʒ7sAbR[BKL>CIV9̃tDk٭NF&R%4{ޑHwF#d{x_)A'druQIj|多ds4}ŮHgp\zO CAPYU˫澛pπ \Jq'HYH8).M(*Wawn5I%5tJ*9TzomrOu).OI! ?A\Op>գ= 1ZӤ/$Ӧ^ f/Pnm=걨.LvEEYvJVT1. 8^FOXcn'Ls VS7ϔxj,I'a͇9zFapI XS_Wϲh vn(NF{V|AVqn|+G!}tM 8cidBnxtW' ,rF&Aok) cK WBq껀fg_isv^"kMEs.NzvlGgc.=4/Hsee <9stP-:lEB~2͓&`XH.̰fE\g?VӍ6+5B4DsuJ53>~U2r$Z p w8!ÓG~K+MMP8 HXX$:f~XET[TQNXTBped U>9ewk-ؾ.ش]r:y}Э ~A>8h}75lQ+06-Ȫz T x]'^#7a9}Lz"`]#Dd<&5:دRXg?amh2ޑ@o:Z]n8nėnDI dߢG+!Qxx?>҆S8Y6MQu=."26| sMr^h_uGBMA숖S?f C33RZ04"ڴcJ̰*#jh`ˍW4!|-8J=AD;t-;bjijӝM%(+w!XVVX"a6߬C\g_K~5o %P$F!~̉pI9޺z} ڷIZ⏚q0-_ t^dǗ=%=̍v0iF4qvKI?׾a*Vf;TbW >#&~@ PxNn]4(Rlz*ܚzlbndFWȫFu@rk)By2plQ(a=Irz;\_Ri wf l?U >E©$[K=#A-CR&sKXb~7xfmA49*Ujv~o_EN2mCU%,i;LQb_A_&*j ^< hm_)b4J%I1vw5_sY猑"zt o; r*$銘ErXfT$}Z~m.bxS$ P~:f !e3-g,/!0e,2 cѥ-\(MF# /Y(w\yV: ̤س)%+" 1 d ZW S,UZ|z(/T͢$-%Whugd48oĭ]:LFL !g G(D n8B;~܏.ā͗#>cZűgc̈́L?[ބO1N3!] 4!dzl&{ZrOz_"2F;Ϡ@*ֈKGJ_Kǜ[ }<9%"cڏY:^:,P,G#P!9\/=j[7c6\65O]yYCYITK;xL :,z^k2jD8ZF?&31qsjx_?sPwsECJgS {l܃aQJBCn,[㓤ߏ i9gtj[IlRޡ$pPRޒ^J*A3߭׼Mrlm;h[Onq̓ )]~*#ڎ˹+k{Ɣ#Me&'EV(h+œ4Pl_ABfؕN.vưFR( S2O)=xԳEIi 1K_uO}T傴4=f\BR"zۖ.  %Xl{,qVQP*`{10+%<mBhPx"A ^?8-v}Qa^S-9iF 3D]~*=е~;*նĢ++PpE(+L- KlZL J7{84[~,at ǻik0(koA;yq|ˌHȶ>ɲ79T 77ʊ}9R ⣍="^TV+8/AQ7D[(>[,P fš͟ˬKSNHÈ[H+Cl{)Hty=Gw\pZ0Xz$kC}ylL4,^ VAi?!q1 Gd᪏&.Y{vK+7-< دj]J-bsr**T9JYk?ͩG"i̴+յ&&{4xGV/`EHqq.ƨ1md@"ua(̦5{ɝer.\Hk: FJ=;C`p>_6Wy$T/mz*[A '5<%OB3 U"zT;N"|>h1j꤆ NND'5*U ¨>  Mש P w;ڇ @B)oа!ںܡG)g}mD@%TUn)׌f::>w=LBTec˸1 *PqIb^a DVD՟-#v>~hZ~Hܞ[R >;l]?m}J~hAn a|-bi SR?(aceњĿ v+:|.āg͈Ja-T峾6:@%%&Se~=`: yݘdfk\o1U>%9޴k@.veZs/EF-|Ŏ" 񇭒mis%ŋbWAC੧MZ2jkϫv #O&Gx ,![rjEgʗNv\wڴGɉV: fٵ7\lJP<!_{|YS,:7r8th[ 3C|iESun-i>-"R˙t`sp Sξ$#vjL; GG6 bKkM<6F"p󌷼%5%/7/Co\ -/%cFGS߄O `p_ );j"3cRjX[o:4އ;(GRe(OZG׬[dUր e:_!U2YW. cx J!?#.E$ #cՂ]|@`7-8Sb[@{jil? mBf3@X~*<1w.:Ml VY Yk?5H5Q :ihZ8&dyߢ C[sm~lD;JgqйU޻X7Se8/_Wv-)HDgֻ#7lKimE;z Umd $6 uV&Ca .>4=aubۨ%Vy!|oy>:c=y[Fo: ˯JQ- ialZsn8%B19s\+pYdwGk T=ebϿ_0r\thq〬FƀsA}׆Q~*{tmг\F검;俪\tZSٟ+((GD9f4w)NIWqBn!5k^2[&{zPbѐPOCJ,20^;Kcop(:j~"=r(IuZd7dBn %x"pbi.ycvz?c=pՅM.>9ǐY"X"zԊ.\m*cw<~IbfMWV@Wdq'M{ O)1:XE`EP4ԩ}~TQ:5$-k nE]-p]V{ xHhwcy`CaK#n/Ba"zѝM)SQR5Jڱ v ˙kqd͂!Ow &M? E jn\ne$a}+eO® ;+cZ'$ʬy̙&PD5kt1]6 ;ŽUyQ$i/FB@i%5RlloK>=^.|Ωs0@lrAGI$I''",H>R5N='OEtYj%}`3Kϟ3 .z wjӐx& uKD TuքG؏ߊxE+CA+2k2EH7N SѺ4hgz2ůGl.E˭}~|p~GiՂ!5TF+vDvkO6Ez*PZׁxKoţ-#3N~z̺OJفwJ5+QOᤄ%ڽB0Ny6:WB4%|L/C!C`HcT'n|g0#p0:rgiʏd*ǂ 2\,ƦQg")")~i"4\½2%'ټpMܵŋq:BnA~c"/xV/oS3BTBDN8<> Z0Z 4uDtMh(&DJ_1}OI54sU*W=6>,$@+6^>^ܽU͗|~O ø(ŸʿNQ-oXr~~R'ơc*4\9gnϦErx_˞MSg@Rʴ,<5^@@o(FrEInB}ߕDkNCZE/\8cČ'\7BFz HQAp{bA?e>Ya2X"#_nAZ]ٯ>gQx[4)@kk~ .9r:"ɶwk Nr1C"c6 KX\zI#{& ȅ+T-5gyֵem["P\ͱ38b\Z33Lg(%Sص⏞Àkcl:h>J 2j[ǁ% Q@O & M IZg-]̼z*)g'@99WTO:Bubg@۹S;\ SFb5j4p4nDu6>br']㩈GN=dGaD=KH,0?"/]~۟QPWS@q6X{4G)jɰ<1Ce5WeVcHJ<Td YF_Dw"t%𿁕%H}8~R(K*ؖ  7j[#Yl,5Ɍ>3;?R5i71{QAWlMgx } Lf[I ԾRCxDX/JnyJ!&;Aca˶G·@0w⍻CT<kjLG0RR[9*Z#"hi6K- roJ[skǴC?B(÷>À,4[.a~rz\Ȃ {,w]w4j_<#1|995};9DK;q~JvDdTȪgɟR-<(֝oQ3R:zv긃TazE{lS'IW,hg!ȡ1MQ7?Xf:,Jk(_v`5#;iKGJdwYӃxϦAV?w@M¶l:"D,Di og6U1`y23\ȐvK[L՗ ;\̒/\;9Ř/3 /*hDh Gm9Pr_t<#waf.Z[{j5Abo }qM>$]_(hh7~~AĹ]{hc:(Nm( u{jafL%nz4&*6Sm2%?3i8q-{W1dߺ|MگVrmvUb_&zǍ lmؒjwI `VaO`! E3|E,5}!y" r4GvW\,\ P[r xx~awp=^+<,AI *ɣtR޿g"ZRo1~\5ܥFqhnV`qviIXNAJjTRS~@m:T NTuJ~4mK1@,4KG#-hT?F=fjPk NAN=4=.-Fg6HM9z Y'$8aE"6Ym&R6xOiRwω> INC_ăQӂ&ގs 0~w4L-p`5ι̪S/gJ'M⦜:=wV-y!.o.&FO i(~?c)I7 z52|RH|[33j -H˗B>qA8 \Lj$HzCAR ٿ`O&gӞ6Ҷʬ1/#2+mI|xaaholbmaR~ ڗvI̋PS`C">FHKL>ƆdX('eA~A](܀W&Q=6*=#Br|o/n ܱ`)(r"$P():R+P]XO-(.Q݃ !-'*n`r̸Gt+ܩb4Q(.ĉhF2 (_4g2ç(Z爉±A0{BiA{֊x֎*Ÿ,:#)H󠘜 A)EW=#O!q.bvJ0drv8x? Y}uݯB;8=V[ǰfVkDF- z[s@;+>'l$iR-EDӴ3A b$鬘*r?-{,; OSn'mjvΉt.иYu,>?V8 p,T2O=c@$K##tY80j,M>T!R("ŜJ>u%4Nԣ٭dPo h=G04[Q4{[i^fcJqL&M׺H9f .( N( k'0(*gq:^B_dDncO*GHXDoJQױp }oF22*t"frϠ2clΧ-ld<6/0~N%a41>o>iޅƔ 5< W0bPdž%s|Vqk_t"Ǜ^)WWzl3gi@JՔͳst*$&mL1ą' sE0KJ*@܋rA&mpc .ri۱&=URk]1wZqMXoK> !}_/X뎌?~™r}"fVыIx>񑾽abwk>—t'>&Ǚ8"=.夷>\ &DtLN}(TgnMQ8* |z(3AƖLospj*M:ݗ#h z08+ 3NL f-k{R 6%\Q|rT@N41 oVammr!SsU_p[krNmTǯ vʛb~/{ +l='fwBwj+śAВ;_{o{=PKɛ}>r5Cvpwc\榹4~k=棘+~LZQNJp [-s,\ъ*4OKxXѪ!p]c/'St|5ޑǏىT\2!% z!#B3HPsʦj*7h.X8NCPC]x44šȐdD,%pT"*~谭V ꫳSE֯R B0MY=[̅dnl' A8'--V.Pb@;˖ĩ==gZaSHT iwTʫC|F8niXS.@_繹9bwBVjv{׋^'3 MM'ؖkRW /=_ -"[\tt1!.)(Ď= "(J_YRd{-:Z]Q[͌*W:KYAmpY< [!9ZjyߎHUz섒}ܼr5^b;d a ܽbj@# !S+x5#-~鸤Q-LVLQ,fy^]i`TxfFo>Z+6r<=;)B-p8rvqd<^?_g^C1.#澭)|gi *ۥ TwgĿV[Ir7u"yѷCb6fH7Js&OVT-$L)-z,\c($E7(4Znj[r䄀{IC9(C'k\.ĸj,=Oq;CAJ v432dzBg枋D^tt;cK.cb5@V$9Hc?R~hX~0d ~MCFTfv{ۡQ .,/0dVfy:Бy ҉jԟ0̓  ?N@Â;Q!PLZF~@U%]xߒFKztF7=hâLʯE꘽Z )ZL`ʂ2A2X~UZ}"DI1c;B-uȯuj F#+$)^ȄjeT8(D"#\P-Mb=9f)gtBqyf)&c%9m3jc)A}e-$$Թo3]W`vysM&ѵ_bǚI~cgPdv5/ˉ+N @k塋78淾F1]6#b2 arfAJ*l qK W*b8 4ʎ$Tݛi86^AY.5o`A6ĢvY*@4bZ+9۞0u-+l G?𢲟JՔta3*8.$6EAlԤhtpf0v 0i}U50V XȐ08ᅯ[` *Z&<&V:-%͕ýZf8P 4pa͛IVL{S"mfq]ļS8TpGzt. )hn҆nkC>86**؎>6>*KR i}Q Va*{^^b#RRiu|0͙,;*_TcmsgdeEL6/zHcEA'0Kp~=Z[;,ˡ#v,d "2;:@wd_+! in>tj(|8­F!=_lE 8& 7*6XWB A[{[5ץ %1y.Pm A26SAy>b$3<7sg?R>]Bo?Jf8fax8'k6]«v򓿄gXrXyYFp(]KU6ELZ2b+bꄧ"vM}S2hŽ!11Q^v77P`U0Sh&rV@xsr}pL\6d-4.EACdHG9P`K/i/w@a̰Dw/Mc]ɏ6QsKNm"̓RH,a@DsғpDv78ӟ|.Tİ'*~0^z .;KKAc>qR:>,rQ^1IˣtLZ| vuE+Ep31h'vw;'-.ݳf5Fч\Զ15@:[qTr'lB FSH XU]Z2i̢~XB&ەHЄ"S/ө&Ɍ ʙEdr(K9<?Z5@X'9;tt J@V3h|F*:[.mz>E [ԅ-y˖g`mmBIt,zpHƦq]q訷2y;l =%(,{[lJo;M}ʑFϽlԉ"e6=AqLg4RGQV2|o5zF(lYݱ-!īl /0bL8(rYrWCӌW?ΘjWx`ijԼW)xZ/ǟw>b{](dFǡb(= T '62.A8&giFTT^Օr5-Izrƀud ]<k;d(`J.ԿĢ_{ C Be|ei8v{lhS\m}&J̬RN72h7!Lk NV5{^袄7A2:xRs\  ۆ8T eT^У˞I%ϭ/00*VP%]H)QW1La v}g >;;@{Vb?3K숽=NN1ڌy@oO5K gSRgiNך %)Q<- 8{!پu/C&4&I,$B2[iBH}$܀ &Z{]PPO[2[_?!L++H--- 0xN]QeEPEw<"= jJxi\5mtoB"EryXn q7& ͠*7E!d ZwZGK865_cn擴T iȼI{^,RsXO$D'9Z%1rLwCd,skMS`HaU}1 -$[ ~kf휊8 ]ۯ(\ܟr,tP7}'g_6{L@%>ݹ8{vBW\ +J.IkǴ ¤cޱw!t}\Z[/qgd#8`?-'tAaȴI{T<I5%2 Q,H<0XxS_mꊗ[~L[&lM&=)4oKQ^^+j7R%~^Q9=:hqb HWn|':FiDLWWWzapi =6Q_^uUԹG Gf;bq\@ Mi9+ MQk!GB 4 '"Жڶ6"<;V9 ý5izxFc8.R.EjqOʑ0喆jqoF7RVMD@`ǯr}><`*0}I=ͶAcdd ]zTj>.RYe Pcz4L/Lu\fu SlCF63n lsFdHQ3b$>Ǎ̎nۢ%/ q1qWүapy#N{żHIS:ipÒDwn5ż(p,Jۨ jySecobgwFSRk]]e>ܨB >Z,̟gA>џL #rIe7GM4u!+l\ 7Of4^o;e: "c:l$j u@(Q'5~pRD{ `{(2CլR w~S7mtZ`)`T+<$&}EcuG)$wQ?{Kdh hbe$#t2ރ~0Ft0RMT4ӵ'ӐaE !mjF,\KV`\=_w}fS,0K~܂5|i/JUE,SN[ꈌGnϽٗ B3,.OS1 gF2 h}zmzo-9P~T~`ONs~Uo&;"8l sPS0rǖa27q- MBKUA vG܇0pBـ䥷<K.9z۳hE<|7jCC^>LbW|ljpD>KQ;!kM;)$$_N yx>o?UQ0b3uXuj}sktN{<_7KH\,a;(?JTVS df᫫OBَ)SuV%ԟRƘd5$ڻpbư5F_Zs _>FawO\g vf.g'`Ro9>A1:8k-&I7 2j% P~[oJ<+{_@'$܈F|&RSa5a8` w3/s9s.:$ۥ֣(̒|- $9UWd&0_%F?mpaΚD)xor6w|!@~uN?&`/5u{e㽬ߛZiuA< צrq&klSz wP#u eq /IJ+q2p1;.ugX# P$@+ᢖGv&:!w?}dD7%FvX%LfKp@N*톓L[>K&7c3ʨ{RW qAmeզҁF7RV-}_~,,~[C@@<^1y "CGeel|N?,L "WV 1y ^KE?}x}͡[?S*3p n\G yv6m QKt*@R_hk*k5?rMLN fnleZD+Yk=MNe4K|m*%$ET 9Z)}U; aJZӚҸ*(} oqҩK`9& w5Jjh>iنiy-I(R1Ɔ:bD?}^e^ijvSǠ^e>;P[(\-zd /6_CbV́ʗ&&9ƵPel;A`e1Y4hpe^Ƨ,@TS:,>߇{OIoslXxL9ۄZq<**GjX6@hetaA^q\amiÀ=WLUf wt{3`][_UxI_+Tª폨I0hۼi5'=;[='¯ mjDuНjq$^ lSJs{F29}I.5YXhE 8L M.RMe!19ʥ *%teۘjI¥R\ Br|_qQ'yyfR O:X*&v_GL'f`0~86]]2 [w>F0 /DLt qѕb)wSuktTfJDt Ns8xηDՙ9㠐sڱtJļ^_@~hp(DUbwWQl+c/ tx6vT;-c}FF{/pxAGh&oA笤Np{1K|-b|)+,hvuƐXД@;yU B,U]y)8W9#1t܃S=SgaԘ$UhMWDܛItp{q[.S{ZH.BJ%Źѹ2x|:JGQmohVxAa>W2׋'p~FS[Po™M@ IL:*> ?yu5Z'gXɩ-{J6UhP@ay[B.:F4lbiHj/Z{S'~/ϪD <2ϱFOV9HC{a5 #<~z=&,vr̀vԼY(Lӻ1F]"uZ\{mJ_ZPQ=^?cWZ@R+,fA)R`c\Q+&>eԌZQl-áFEUCe ߆WxLAբO}mHJc4y[E iI$\?H?H r9uly/) VrPcޭ.Qhs6@RLǻ%jH?rT1k% Lk3Z|/") lCL}=kB$ $p~xg팄{:#xyw8-l0. (5~8{6z5TMTO*,"`qVJu}it;-d5Z9u6ϥ$QPҢ^& {KyXraj,8 /,Yu"5~5>cOho1&rOA&A ѶA{. &TV(l`RQ!c֔x{ѱF7|HWatah4&m_xh2[}S*6q-7,~& m,wC;" vl, GYoNwb-1~A[QdV{=fyxOfH6XbL ۸a>e8`@C5~S=;Uz}%)ƻZ'g>zQ.ipB+j<4k)FSY㢤%P1e؄`vT5m՝vH/wfLՈ,wvXxoEE.PV1y)s㿦O19Мg3L% }@e%gIOOB=%L.O=J}ܙF+ϻ[$8*WGnWX{j6 7Ke1^Lt%tdy%Ķ Aڻy%ڑ1&vhOz~< b oOo/D)1墉 2OҭZghwɪ]OE$dKʓȠv̴x46W ѮcW1[9N "{jTe+-=w} OQPyt)?7?Ll'uM4~8E;M芔Dj5' :3Y6 dvڮJ6Adp VfZyE#Q86R}1{hݙֳNA3`JV'_UKUngEii(lؙ#Ғ7k]ExH(fv(I"3MU[vZc-o cIˌ"7nRw1 ^m*' tcqb)+׆9[A gL+'vi~ LCT ì` >=}3;s9Ž< utOmCxMeU᤬cpAg=iUh-wvSM͈@̧ZͨiVV^'?DǙX}V\T,[OU V*&$`eBIs~) u^{fQ.5;#3;ւ&ŏ&ozM8cTY8~>J]~^\h4J-\#:2x{H_^8.חwқB dH+3m= !\wɑxQ/  ٚOsBƔmP!J ݒV,И*zyvƳM'"\:?Y,MVvHZnyd ,T%SF _5Wt&-(1$TIzhAڕ,jcD-(w]&ʡ@nbSzT1eY("ܙ'+~'_Ի9x3q1eD#H*.S)iLfO[bOy2OQfVl>[h[i޵uXL QM CCV+O5L2EM? Zz};a|јD7D#Y/(bY[lOPq-.|5, Uۧ C)rs'Yo`[4 F&ej63" ͌^O5`K;>DrCDWs^BFHx7-k918ꙋ+B'a@1,gsR-7-Yhȅ4t@IrAd}1s|M f 9ȔR`9B"X1٤fHjZD# OyO$CFWpk|aդ)s.7'[/({-0-S_?/L $1Cz49C'VgX"xU̹k`fM68e '+r%!Fys ߯rj,LmF 衒C'evup &85aOABNFlkWG;WAȣتצvT7rjzjpBQʊ} CVL,3y|զOʮ-}?Wt١l06Hg!m,@%lks=̆=;7 [am4 vS&v|'A_; b\(ļ`0qp fOU6U#j x#|*n2Q'80 ,(4Id@vekS/%a*ON̫@eG2+6Rc:J}tTmf_e"jr)͚ ,=:RKn>Ou9CЇ"Ypn!}`x݁XԑdXֆԦ8i? `Xדz[3miR:19GuS5UR;WO\y*wKGx-=y,s 5 3g4ؘ^pVzl\Oj?S]ݿ!ܚ C^Sc̶J#@YC*!aBcħC?$Q*HyǙsf\ *!&7̸͠jZ6S (BbkW` Og^:\ӊ9dg0{X^MfoȃNCH@z&Ch@A ʏz7f\ir3_AU[P;*gSactke?gn9^-ED" O.l5́]j"&Pn,7^=aOw= $G{ZP?C@KXhÅ=݉\եCY$B#V&&K;^?:ei[-A',sfc7ULI ˮS*NtN71fۣfOacˣOZj^8l;'`D%Bq@MfRJLn&FHqɂ9:?I熢Go߰+5KEz]vF.KgVfU|Q<]Uj u`3&ЛQK$8h (,D")ZJón%vֺp2Q9V'r*-;*v, )Ie$w:#;0cտbaBz>SU,}tF+ "%bY( fa4& ?Օ}V@Gor θJ^c*(_{JA0 `G[quΥcmIFH[F8XRDOA%5^nxܬևpP ׳?/$c|!h) S_{}L֧ u9t8ФH>[;;*lp$q5F__T*JJ:ZsDz1@`JLqSpkMD>QHy=>@ +ڃR|Ϙ 5}:3v0hwqMP%|s>0m`YwX^J v:yP8m3kN$?^`p(Z>US*Nب*#tD`,@7؊fL`s(g#?d&~v-1*3.gޏ]E^X]X\trnkGoI/K\8dl"*௧oCE?,6),IiZ4K~botNpTӭ1-}&dؾhi-Pi TGˀ80,LN\kfߒ>b~ g GuȰ ..X rM&rqtX!+xzcU7܂B eҩC(XjA`}Z48E>*wnpPo7q_^LF4ރ!`R*N_d)Yj3WI4uŜ0P|HpuB,s^nt ;Նt|\u0M ȋZj?\WN:ڏmmAƅ5 ?(@RsTװ"sʘZ>5/y?WdY[J\"Gte'Y 6YsBb;,u6$woщ#)}KW@{,tA`Bj?^:"R4 3/:OK 4{G50ϻg *쳮NþV_07 e=b>^ ?lQVbt(7ng(vr:ÃZznV1]t ˶S=D W!,޷$?6_Hؚ|N@rA^T3i_xCA>,ژ\M۸43Od?$1'buNwؚoW]]v2jM;F)ύ(僗39A)?̢T#!U3,XR5#ه0݇w`VV>T-LvǴ8 ZV ᩹E&KLūDqQR5%1..=q@e! ˤDЏ1ho!{M {a-s d3ЃҿUN&gLV6/(}1@-E;WP('نҵұY:@1 208O[_t^J2g TD (@0Dӑ03|VWD,NYeBZףej~n|8$*%ON#rvSg^' if~C ʍx⴪f(h#H#'aV[vAXH Eh3Ig.6`Ci)GH@~~ѹgqC%= l<LW+}W SV3ُ0{ɷ Z= /M%5XfS]Xrư<8E@XiUz9b±مQq' R{? -y1VacZ,G,2|_XrbõXoxf:XܷPN%Uq,{vU"J"([b^^XT~W(hr.][z]P|yƆVȯ}_bx ƃsR ??%r8/i[Cm8KeL{}A@ڈ/=f9BЙS5Fp`QWaI6U^v6FT^-C'٥~ǿ^jD5J~+} ?tqu!*/¹RZ4f41 p1ۗ5vݧBaPJl\ٛӅt }CP<;mdY+S2E@g6ؒcUYݦAw3љ lVnR\!k[:o}h~Eǫ9E*#*i!٪Mwf;B_[I|O6oj^|)y/a"b- Hj_'2zd4E;܏m]ߟ81P-bĮ]r.:NOi@z6tBIF;8Hk}؜ y腬R((9^O}:E!/9tsGןx;1ܙ#K'Huי~ XCдd؏g' ztrOÆ.1#n%mteՇKGw =P6o ֕mb蜷RSL!PO+z?"E VI3[DUfk7ĒwkǾ {G4@A%djH^2[%x zn*{NC.߱P֫t0ET~^k &!*OP^_4:V+ZĶY4y7Č5ZXׅ'$R0'2H ˥0mlYI_9l;P˙<}-}XL4H }ZՓ0*a-d•F d9UYA"woR i7ȫ@vŝcTwHDrTkrFPhfOe׫IiQtȔ\Ggt=0 1= HE) :}/_`aS:[1m7 R yMvCVqMF5~?iܨIO=WXԮZ'*u!3C[Dxk{%Wx0A'LQh+( $06xw5VA>j~IK'X -zXF-vҬL\aη $xy#\9{p!a0|5vG3L*1ZLru#G"\&'[N$,ޭd{hsavQ;z^ tm\d fM/Ҿh\\YU%[ OFp{>gBaGc]`pܣ$\&1C _˵o_e>9@v_''r9RGѬHZߎFP%_:2X+-qTsvaHH魰ԋ{e%qo/Ac/gp@+ Ϸlt/ӕQdcykԌAݺB)L qeSG()?ʨWHT$0'~i>|og@G*Ԧ ^Վ_ Rφ8-SclTm ?r|]dP 0BEVz} h<P J NJ?J*ݛ I:eaג xdu~)6ՓZglf`{L> 5]d<--CBF)#‰%M*pRѤ+@Y$ PaEὐGû1i}tջ/_I|w9hYMGaH2XXF91 L'ȳF>d!)DEo vz}ԫϘZa'(87\l_~o o!IT.Jn ,XW 9<0|7 *<^zdbY!{~ƇyqtjY`wsj]JX}zww\Nj)-ibhz V5!B!0YenGu9&<UGKl%(jH |e.KKUyAf8:AZHa ́QlR|[^3h:>' -L%{-wV1Gn|AL|s%:4f񊔪.dR}fh77 ŁfđrT1$QmBr \O) Љڍ{:1Em4ZGgoG*U{mn q mtCR _ɔ|&s- Ciw&8NpTԱy S K0 o5(Uħs|c(6'2*,(U>f>p<C\Mf%O)i{>3YRBmObf S)lq.t4X{"Q4gI+[윊"&0;s &dYyMEDS wek`-mKPtb.t՗ nW md&N8\Jq>^]S|.S0mG] t;_H8?CUKKmԝ ){o"^s@d$tϗCD|Mg ҖRHNm+ 0e0YSY"&wϨP=&siٲH cdվyc1,Q3OPQ^~= ܮi_3_v$x" +\ ɴt*VXlH6U(v|X{ J}jM%V3@{ + j1ac_%/;꠭F 驭i_&{2Ux8,n *\a%?xj$sTR/)!վ+X8}*P;Z4h0A/Ot 浐};j0mW?^E[emwp6YK4ҝWQEXjb/ P *E{ϫ) 8dF:#W =kZݶC5aV / Ct@'E2|n:~8b}2S mviJPUHcg"@'.ץ:R<$ Ѯ&O"]v$tƢ ;JO3_Lȧ{(ALabGx]@%I+|сpKT([i(MFVy+ <=z"PG:XنxlC1tޣls]2k, PÖ,֮GCp27Ѕ&#"6g;Ϗyd2 ӛ>dfDȞ\GW7>2z|CyIM>E854^Upګ7n{ ˦8Z3ް|ܮAvF2E Kl1#[%/Ry..x5\|uK57( Ţ,GNfz]nK3jemӱ2ieۛoop]%~B-ji^]Y6㮞9R$:I{mSq.9gh&yJhSTtLX)xPxǕmlԐD)![mR;`^Ҕ1*yiBN,J[팬r gҾ:Rj`L M"ULǀ_O]1DJHh/\°}ӆ޶E|%]K3%A,x %E{_Ȇ"c кs6@0PsI5AQ)QllX8a9vl6bB>fH9z'cAK)1 Qy Yah#"Z ̳_mDg`iod}⮌Vmpxk8ꟸV$_J4kEP2 J7yt;Max fDETMefN\Yvn z!a.f;;,k]r|)KyT!c;`+ vξJrHAխv3 nR@]d3BX+ N:ii!rXF|^."激 Tf U]#YWvJ.Ԙ[fUbQY!QxA _Zv鲰̽}縦ᲤUxo&bW:ѸN k.D2trf[`S\e pm8uUWI@dwsO7 ")6̍M͊DPYK 9.jU8l@_R]/HS$W2 ;hzu}|bc :~9Kp'S2j;yBqw9BlAI"*kRFòd{A҇1@5T~ac7ȐrV'qh(A?鳐Ws2hh'c`Ho0ﵝ?OhHJb?O77z'z"2D1^@iK vhXF9aBe‹yz`W%8u+Io$J7ꚙR$up/:Љ.0XG~/€߿a:|m֢03s /8q/0NXPJ dFHi5. !*qQ#؈0l;i3@-qibcgO[f{i/pHt+ <ҧ!1#KjT (Ue@Ek} <ԿK1:rb&jCl!λc*+5g~'cXvpθ=vws<{Ke|Fd1vŘNG1C5m+?j i mWbčoqW̧F]/b X- 3*m"ovϚ-/9BJ#ĆY9Lq ыhov,?(.y'FDa 1\GQ$Otv[,ENNE4k~0+uAw}'~}KA7Kiw<83iPj F_z<5@".ԣɰDVL_ ~`0u?ރ_ỊXr7՝ݏ3\{ +'Xl3 VF6fG,׮ 27DĿ45i/G  xF*q+Lﶠ@҈ qǭ}K5xآg 6gUo:%F3ձ^屚BgD;f|/o"aN'xC1jaɍ1ݩQ'<6M^:a!%JWM@`x.1$Ix/<~_ (P3_AZBJBB_)!C_ԟI oq5 =y$})cݸP&F6:Y@6DzوN)WT Mb84ԐN [rn-E[౵; m<'4!E6rG[ք1 ̍%t$f"-Iڂ ojnX-n]{C] ˛CB߆Kʋ59\B[|552b7)R ڊY qldrϔ@Z|pom>ӌސTyZMړ^MY vQ @N[DC@k'O_˟s꫗($ZFyԤXТz"-5n3uUH!5?\@4p8n7ͳm$jZ:5M&2YF8xR.7 +N;B6Ķ@BPbD}<C.Wa-nHD Nۣhq\yx1Oo[`d9 V:]$[C%!lYmF et̩{xˠzNP̹@Xw.MD#Q#i_hqNF.WQ2!2K"C(L[JO ?yqXأY70\pY?z<Mh`,(vu6eյ pd<jpl!u=5^UcsSS/(xgw$}l% H?-G$:EܦvjDB&Ֆm fZonZ7m qe' aj R >5OK{`;3AXs)2%jaQ_a~5ST_F+ /AZkh3Umrtl3 WqyGj]'@iJӔ~Us>-Ad =Z< Rf (!H'YX`˄ rG! rU7".4,xv҉0Y;p#k @ )NYhimm ۴Rb0EOx= c"@ .Wz]M͎ɮwhTX,$xt9,NY-rY n,DG&+1PXOɥ\Gus4w5=ԁz U:(+:|>Zq zK]vxi]JMY!ӵ>˅4zeX@[̱{;.$[<."Ŀ6X~\ccѕ ":]a6P3?>:glٶ'#X&c@h0چ*ia*{j<_!&` LPLc EhTƣho+mJ ;Wf]>͡)jM$arҭ@9[VשHyB㘙a̍w Du=]mB>ӀHd%uk4$zȴ(`=4瓐ꕔ ֡xcLV~zgU&rSJ'Ujh;1`j\~7:Y9Pğ5++f+V{1b:4ͧcUE{Ű/= )2q׊J "E!,n d&ۮ#yF $\JEօ|hBp]Ц&]Epeژ^Ͳ`s$idoJsە q\d(Ɠl !v>ig` w 1Z=NFt9CjVaZFՆzLZ 5_ -&YƿbCcuV".^uT[p YfwY?PrH+`~p紑5²c[nEMfhX:">J̛~bgs !UyDH+asNpqm@|-b&50SC7)k[>/'g:eBМFt5|,Z@YJ šʐ-LA./f[\?0cuT| {*j *SxoWȚz__xìIYFւ!/ ,Ftԑ1:/<&\yTeYՎ|ICŠV/\ @r6lےΪ٢: S') jWG'8.70YB&a6ؘ)MӌîGIQ,!ajyYצn(o!| vTO(VyN ef(F dz=`64b63Pi얎%w= @Sw1V1YRX 25r ybh.'0p30,,!|k ()0fQrH`^K &9ck;tj&AJἥ 腬QՓ*C&Λ ?V?BBn"9^j8 }$C{0:+6-Ƅa↌p{q39%l>HymCKw-R Y#LtL֝4\f7wh0-ωnJ)ЁIGR]ΐx9({JxX],쎻#׉ON+#P~\!-oϤō wwf^m:mÀI!Kv*8]C^bNC/ж<1|`$_v"9 e'Z1A G1JJ%*>$ڛE"jl{J{ȚȬTJ}S;9O-]w69@ 71;~kWsmؿt}gcPkKdbFk,|AjGV%]? ӕ}m==s⟠W-2 R;^T}'`'aLn:O!aҬhH]TǞi=\8wj[1{Ե|h* C! -_ {,Xhw*)a@![`Y2j8!w<#]:f&xE^O|"qhiM)BWLIJN b{PѢ^ƜAR.Ci0ABriAf+z牬{]{wZ@Ϊgzj y;o##O r7 )|Llc\8s:ܤHx썤*MQ6aR,r"n]hF~JԚvA:xXpQCw/;0"؁ԲJڥ~^W]9L{^ܩ%k3{6١ M,P?ǃLy{-4L|<)%V|9Lt]ȕ |ЦGOqp}%xua0ʰ a"*+3|vxqW*?bN'-!#]t1>r8ꍻcpH0_gn#\f:W!֢/g#ƖZ}߱ hB`ϻ 7Y0eMc$1hQv+8M#LIwv  fcC0|l3sHKfV(֔|O״LQ[ H$;'*WmzT"zUYoW=&tV < q%QJ5´K.P\ %dWAI;o{^-'?[%z yK(fIo~D̳nNW$/,M s9gdzk * 7Wsez0kzuxy 7ˮFbG!57ԏdTHƖ[rԞ8:ڶ+}ͬf;`ӄ)cs =T%/7XDqRZn7t9q\\~Hg=F<7pV-v@6auW̢)t=iL6q:pHǸ ~&t 3+pbV7VMVmN_B{ c>fGpEZEHy.pVyXvD^g2dwG\` 0R'>Jz8ھYYwlߚ;u?.ZnOg鱍WHֶzq{gw 37|OVfUr74Qgd~'o  T!Bl nEL&#U"S-5P#払?W &'%|>/dCUs Rao2gP3rn9x$t6O &||c4uJ0ђ%V=JfV/fЈMӏ?o>/C"sԄ{mN&ZUOSL]~bˢW; Iqg[ ڠ|]%.)U-2솖M#kr3EENکk4^pbTFmRcy\d|kDr$r9s&H|Y ;/]DC-œcsBQ9g0@+8h[ xè utn>)R'^DE&?D Z3glȄWtdӃeQЬX1wq4[emӄrθ'cF([0^~RyL(]^ LP~W6I-HsnnbCٰHbB*L5V_kE `1֖ۜ4$Ga:q'tjq0﵌kP={Q}HO%װ S%fx}H3 @gL[# TiX* (C -N0bikspjVMM!$hC@F2Բe[0񌝕OjQG%L}|0(Ԫ>)D[VpT /שׂ@aR?@HF'o#; 6o-9hy)_b} u7LF 5ghLg57M8@z*o3޴jn*5!#d]Mk!) ExvvF/lPUτM]CONFyρޞO3+`*(Czǐ 6X3YԮzKhTu:B%!6z0_Y y PU3Ptd %>%g5&k@`׿VKh(@^8KH,LydfKӶUן*'#¥v۠QG#qcW%$F`yRufc  bR큖j"L:Yv%I}M[Q6eǀF88Yw*%CkXg4o-rWZJoYRBTt['By ^̦$<}Al]m"T`=iF-T FBܙm׶ٓ)6G)14Me,#i$B PwvfڎO~k5~HY.uR>eXU#Ɩs^܌ M'PN8QS)7_e>@ » _0Gv5dz|~Q˨7^+Cu @hS >\tNBx:*I)\.XlESJއ/ gj3L%r*NN\:[JNntR,IMj8%46olqTj ;b:^0Mjڸvyo=8R"pژ\%ڙ OzϘ5K"m(F_)C^kn~ RyyD4ONv7Y.:CiO1ĄNv,Պ}%UB,DIyXd̵Dݷدep#)Z>Bs],UPɼ$^9>I? f;:֎gJvfPSj.NxOn%̀5I*ՐɞX,s~rjg+R)tmd9{bPW 7,ڗc>nyƚ$#%T+ !D^PҊ,gF t?v3t䥍N V/!bxީrz)@u;FQK;86%ƞg9qz@<[;ݟk3c -9o{ߞsˏk> kUU\ny{ݛ˝җ"SiC$/ H*\ +$$_" Z'|KhVz4۲ӃKVbvuGϊYaNU&;G3M1 RiKSr cːLeD`bӅoy6(# ϔn'Q-8\c*M3]H-J:{C+T*,Ψ52eAS d=K3[%Gڣجq#ЦFh"rH?% Tn0踮M lMQi2s}V .*!!_&D ZhׁOh̻N[y{ARf%WCE i5?EǗ&:#|UgY⵷o0yfHrL; 3z҄Muq7ڴF#&$%`F˜٤>/7 \ĥY@DVk^yo4q+pg/HQs 3>e8CYhXD -O<>E (Έ`4T?m˚e}xϋwX+С@r`N+a>eS;> l;_OꁇL>RjΙ藉K"naӉw,@1@dwi-翃׶` rX{<L@Fl@"˔fvO1nL6vwʿtNMk~$f!9+exo! N(nESKB[kC Q1ߴZ(I6}t,v΅iq|_nO[Ty:Đzt GFc_"Z#iz =]5Z0b_61JG0i:,Kb 欀_jAȞZb~ /a(lF{.r 2Q^?xR:q-ϝ8T]؊"S++ZQc5e8s]j&㌧Ԧ턹x0$8Aug#L(P0{ 'h}TvdgA?w/OV21DLZ_KDi !;:wt>3#y=),{c|`23-+ 0GDq`SVZb6.}:4Rs\P*uܤIPζT@c|*ePn(Az"滴 pKP%I[䋌@NRڿ) ֆNsѥbAWi^2Ww#GOEqu2ts 6<骡\%' jU2 qp[Ls4 NUOas9+Z ZVbN>t܉ ~T%CLjOA;L:;r ;C16bBgELJ"8x00*"ez>ߪˌ`+s +sXl=xr [_7:4~OC۰P~:z=ZgM)WH>˒ˢtZdĚ,#\B3KF00 #N6 Y'() Ͻ\u#I1 ,Ys {2"%;dj sg>Dh+A>"wEDU;c1U* Q>E`s81LjjO|t)J1¬q+-q)O3f@܅^~j @Vc6Qe6+?̻}n.V+8^G& uF@#0.Yeͮ9Q$Nq`h|Iro9 ]x"m',Ktpa4rWY dyZ~u|4n2HQyXLE2k2š^e/3Te/[\)kkr<9N#ҿ̓QxTP_)e3ΰAa|:e]5L\wC^o1)va (Bxb=JåQeӬj3tIgrwxrU4V~yAm7?@@`.U &=ĎjM.Ts, af˃VGE=jo[SUzwz?gު;);]C s[rbWU:S~Պ`Z8/>Ln9c{S;ڥN"Eb[ƥj˴[vNI-UD;f;_ Pºq3hSy0YT.<K0aK j*ynߟ_.t`ۃ" ?gsKa;c7ag rz8;&Fcۑb,[ St(:1r,Fj8Ŵ ~R-Em c+毚U5&#-`ȱh "m1ÅnTTVg"<M-OkE%/u; (qWq?XĂR2& ׇmkzfzL&rT<'H%ꓭ^dN2@fs%g4E;J}RrRߖEcrpM^lTM>@%i#Y{z]6 Yy*+ÈXύ;k>aJy''U|jhpi4>XB(. /LCegqm~9Y*vTܨ)^#>EP#hvFreQR qt0u%T9fjž"gS#L4+YNJl2 np 9 @E=Ň('l;@ %`d6(C Qt`]=60@>0ɵ6w5F7X/ .d{8cIu^: ?)%v -^_/k@CMS/3{Z%MD0!E׍| 0B10c/mIJ~ٲk RhߟI]tZ"ԉ .Y.KEkuaNEzThॺm(;g|hnyI`,+Owea:ի`P1+8E-ђR "HZsNF q9~ň&e^#ͣK=?Pk~tSaڨ}%.v4`o3Ѩށ͂&#xK 9왏WԚmbJaǻ[ mTs&r.П Xu%ڡ﫾Ol91?%o>q8:/<+`gi3 $k( x|v @:# 3+Jl~̤#*DeV/C%"NXL-m!O:kry҂e*pw :C )uw>RJ@.Y5x tr)M6($%VOHwLAt#Ft5``zC0 e(cX"|N+Wх~kgj?ͺTSF5] "a:y3mD3N<{2nV>@9~,84̿ a L!tvf3awp:I-|4O.W Rt}9/y_*edo'|' _cE vU.dd~V}dw۰d\甯t/HUQ#iGWt1/Dt(Tį! hGE2CA}Fh/T ',~L}$EQo!0|8(qȓ>Ի1̟DѹS 64ɤ )VeZux[$&2Rƿ}K@%0gi^sc{AZT fa@A_E4/`>vы )˩:>^Iju' "ݕ| ws*BtS:#X*z*&$% bAocH%xEW(H-oۢ^w![!WvډVXG3>818I,zMk6מM}}n0`r_QQٛ`Fy4"z*Pz;V~Zp"r>9^o.Q0m<5:n=6 -%%NSԳnvfVewcwnK |.Vl>KǍ7WHM2)aݖzU6r,nU[cP]%ͨ|< -x*%Oš$輜݊VZK:M:\$M-#3 IzgoVj I$@½RW^椣7 鐘P.7w\jM7q2*((ޟĖ Sp7D5VHLpDH?gK{]n'd]S>FôF m΃AyuG<ؽF)=~b;0\&`yBGw<-w!U5~[Nd'y P[\>\}Ҩ\xߣ?2`@n A㮈{>5mXЏ-tV]Lj~@O? ; >{!i0'Ҕ[-vDZ벤d!v Z";6s=JBl/y9aAr'ZSs,/=&o*gCPG=;?ӜlȉeڊI^/†`Ӫ5sr]% Dz|1]QjkkTWI|Pa }VGGs"U7E&_5f[h!=VoрYo/}%{ҚWʌL#; dtj'@x.AJϳ0 ͺVLzq*tYD|>/ &C[/|T}Dh3DɝKY{}rXGo?2Prm+]Uk}\ CC3d8 <dk'*_h揦b!CAم1 '{;uxR8ޮ R q`! u^1Mx3tx͗Kaƪ(h*6'͡A#CN1P&ȈqJn8t$DNxb fND "[0hpt訤 nE~Ux E,w|n @eK2_S9'aUa B ˿-:1VL~R߱)[ٹ+P=`qxkם%8L~vFdR`F0MSgB饇-ux"- bSyrD!uK!S -Á7DʪX\ytC։x&{ML,}rTv,Q~9D-QqIwj]?Q{"9!2<9ǁ$ Wn/eU_Hx 0\ j4.QGu y̓ JESHńZN&OVOC࿻9u(*UWTHVv-Xtt='ݘ)}i| twCEuJ(ʔ!LH)CYx~,̘ ,#^"h@QrOBw/90Q 5ʼnVm5/ Fۦnwi2ԉhA!`s0۱1MCA#ҏo I'Qz)&_/E9^ Ùe:KaC‰zpR.`yn+3N><EE1z- 1/%iOE@ƏC'!1z82MK[n&1&m6_8h3@knQֳϖ^Ș fk^1bn:ڽɠ&=흿kʩv1{8Ω2$6\)3y$ķE%^B!D!AW8XB $,mvpgµA^wd9t݁uY3({BdRP\n fȚnwP~BS6OX^' Qt| X*j=T̕3, ޅk'Hqš\~N7I| g,߫,:EhHMa^me{`ƥ2[6R<>+ݬT@}"Jx=EoNY xu_8DDzC?K6A.IIj/TTS6UvֹOZ6}&MSr^qP/w[~涥k ldGy*)F92uv4:J%RM+UymeHZaIX9OC̘%ӵ*xI+2 r{:;}~x g ט̺эr#yr*=?K.Fg#u^sY HH_'# Y9B T2.2G7!Gr0?]i,o,KsXD) 0bpc.1kczChk4錢f~7.`V2a~ie~Pmm޸Zd%1QDKJVƣQ9鮓w͞C(=?Dmi X]p_?g>f*x7Y)AS5Cn@B× >*4na2U*w+4G“Ⱥ߱v$V4Z3Rk5A< IE]VIP ޸qH)(뿻 =~zOxS6##L, dSRa}-r{a[h`>rw>JZEu]TXބcl~+ad>H!~uwҕ([ZՋ^O3v!S SEzo꒻R*!Fw>;PZ,w;xQ'ˉ3yܽ]Zَ1};|T5~*fjZv٤:72vYUTNLlA[&1}V®^4z)]^؟_NNHEdbQ4ZӴq({[J6">]n`vWI;ߜdrrvԢnfiiblk5d\ˋ@f%,HI8"Xd{)x^#r/fe2xI2>Ż/q.!m 9fJ[W}d.oa+PFY u}VhpF󓢼}5^q%frIzSQ!>83,!_|]2 bmݼ+#"HAKh ZIAMGNWC]+_Y$x,]T9*?9F$Xڡoi6{zIБ9CKl; ՍlH__5dGln B4ᙬpblUDͩE'4n Vɵk AU^>VAžwnoUa2{L a]m,"slWYRL*TTi A@R? zKFbv(1upb6."i{1ER(Npn_ "7hXKZe8Cė1!UoipܫK?w`c ޛ# }Rc-zrLsuΏ*$%I' #edKj:S}Hh=d>w?cbGVp߰BO]BfSyM;G流ooBFvm۲ \ .캎c{j.{~O$mS!lNJ^k MUNܽ$ N?(N4 ڇWKj--{#V#Ah-SpYMkK&T+*er:s"#Oa҉Yi4P~p^h0riJOPpg^@ zQ~]dW=%oK&%*B"kఝO6Wt R'T!ESN7,OR >IIyx^t +Qgm'*rl҈؎] ;/T722 1*o]s?_Bۼ S!IIo1JBzuv C=)orM*q웵#B8sE+ej;T q? fR_4#!+]6F3l(X cX0~9Ȇi;onLWd3$S3#LM{+t ܏``S 2l(]a@Yx]7E?sSH벪UW55*`y y"Խ%pL 2"O}L8[H#R-l!kR ߥtbՊHt'wpza"4 e3W#%m!&vO8HC[ͷU6:ކ`3UJ7h'P%JcBh:mVbt壻< }3¯1&iOMjXgf^t\Ώ[75@GޚQγM=E߻GߜOo#=_l/#順h9n_fC/R3$$/*o\A'%Fpp.@[Y{ǥFke;.p{܊hKO5։=5H<@֒GWPaGPfI jE0o.Ta)]%i9 Vлd1>X ^JpR*I\`Ɗ7/)w y9R3zEw'B8me6J T&ԠrYā-C {XS{t!N4H"(c.¾3)"N+#+l E) %wq=m6lK+Q=ȇ9Aذuvi@Y6=34Gd;w[j[/޴/=2+ ޱ~7VA?KxEe<@ m̟*$;7HR_0{nEVά[}pwC?A_K@'S1zlmb\o&&Ztw|#}k=s;鈩"=bUdE<߷E\#mOPF$.<,RڦC亨q8/*ZC}`ui{f{=Aw#9 =, nyijaz Mf`cH^7r&;.YT.,<` GMLOT6PMyi\K(57Ku]s F)@w5/ꆉse} ]yNƠmjH5ce'3S,rA@"aRV@9 D1oӚn8n0Tϰu*akǥ̡^p =TGN^薏e=sa#"Z?u\uٮ/]Z9t\aK4=Ɏ#ƹ]DJQȒJ!\bTQ cmU&haz\rY l4x9>wt"W^XDz1^Ja) "Ȋ 4`| ~"4եYB9^Xh~Ng?4tqQҐ-"6&k3JG GQh\el/h+_vQD~؁)C Ca㜧*Nqn(@TR}%O;TW5EsK&z῔c73Q"~`f-T6xUȸ8ۿc_[b 5ͺ⽄]X7w, Ƴ€hU66a,a6^R-8gg_Rr<ϡA{Hl=Qު%w##>b33 tbЦ\OvyELiv~ zMp< #a+ AA|{ԟujR.AC%wp'GeXdX!W7!LILSm`;}VvF<{7U *z}6';kd_ou/@E­::g1Y00M[|ZO tX|smhaɆ&Q'/dJD U kXhClzLOcj]バXƆ0^gs*|[.P ֿ,P_}Cmy)9@tU+91xI̠//ظQ@E"hwƬ`RWz-㝉zb@!%KG2kD5y#˖qكTPp+C0&Rei8VvT3E7dUp6nQ؉vj/4+)e!ƃZ9{!^㓰Y7hut`N g>O9׀DWCSJsQwB>F6qt0|I HM[~{0b%84GLRM0 gȎS#Y.c);uLFǪHc@H V FyfXp$ҋLCFWf&ªV'j U~;Xz)N,1?|_,VȢ?4!K`w2%xYeN&f-AO`F+|?/t?М =!U;ߺUC>=+p/qFv۲f{Sʄs;vr?>G\JaBM2qKޞv,p/,%U4A|UtVˠRniy`?{uq}v4^|ffwp9* υUG 5s2N!e i1H`H鞉k{gHĜ{_`!>+l}R7m;,p9UFiѷ!g[-r튄>D]\{ʒxYt 6dCWeU'D;j-6*|G'Wx\fG֡q4`ʯ,fQ>S xӧ,y*EfIKG0xCjk} ;/׹ 4Z6^h5|+YPm^̴qPAwˆ}"{v(y+^}gޒzďN"LyO yImBfK y|hzaU{-fW>Ox,AVY:؛B5NN{mc$2ࡻvAiv/<зGb^牎dCF.5K%..]cO*J8˂4AyS1KEse?Yܭ#h7uwB ?3c|̘=ey?9Es ;|g 'l;kdj3]Un*rypM."̂0n)] ,[E:U9T$(pcd9R~+tIN6ksΦHS49r7-0F@"Ux꿖G8#zt\PL+n %?d~ƣmuW{MzQ^iC+m%ؖx5n3{&J`CFpu<3H%M]Nw&j4m3fZW&.(@w z55 6#aqG C;|7At|D[ًR{BfPRw4IoȫrR QZAݽo}^y Ey#ӗ uݢ^P4 OyJJp#!&p!\8i;v=w2֚O&°Ž Q5S)8Su-Mxȭ0U(O?Iu[MbfK Y_Haj, !d+MBl’Wqö<&7P`=gS8eG~Sc<1aB óx{iDQ5H?Hǖ0eXmvNE2\壩?瘤2q DkM6)Tx}9o/4]Q3ϖ2wMMՃɐ/\M[8oj#] K7IBzd H<ĐnyTB`=}m()Sad1݊㳅F#qw0fxq3"w1p6ڴ% #M5b|jr@C <Ն'>Ѐh{h?TlkZ$+S0 7RBz5Žnf8 y޸k6M< 3bo7(49`p`8p\KXc7YX+=y*XG$F4͐NcI^{ͱaf[^acgh"*mt{Ni@ZZC 4%@Vt7Zg2 PvW/pQyK(FDE7[Yqq"TtlvW6zru/Lng|r\A ,b38a`Q2Mo]"FX%O07+p X4ׄ5g2L_w%FEL^V?~6,q6osԍ.($(+{H֐,c=TS ޚ5-Z\OS}2Yԋ:s'||g;tuԡ*7dI/N0Sjdx谻)=_Vifyɞ-~4{/Y?zOTDrm>YiZp٣;ެSL$ S⿌+4hjICnpx_MFbZnj@.'NB1jckW]bϭngoI!܄etV;/5]yyk򀌑 )XпiW3J?҉[DKnd+bΌr@½z )n"t?%RKcAЇDm/ {Q^}c>fmO0yv5@Ef.yUȞ闁$/J7``d qCrRg QWPL4k\Wᧉq}4/AL,C0\0KwԨ f&Nj xȧ\Ln'Xfe=\3&nJKV/hqjQn#Dn TnL~|+l~~j⼓a|W(6e=.||@­`a)cQ+#C0ִY׶];Go[YbE;I1Du$AפMl*j^]5 6 f燴 - <s*mTeMSM; %^VuuM,oyu] eˡ>G:۸.r6?υ0| ~;* „D6w[,8WVFPFXbMмv򀝊i1o \H{Qt6VuA|G:|"vtYfid^n;f`IZ#zleWf;)7>v7r, tn@rOemG2I|aߡo!L@J1iK O/b"o>~9m˫??F!rشcɳ¨Wt4i'x`x/L^*he&XQ0ρ%TK۴=0PΞ§j<~Ӟq*+6ٙ&6W+Ɏ_C3C,H;sCҖS$\v*r̉oT:0mY/Nw.ǯI#BGJlME3pyee=ܺUr#h[f;@#!X-T@X/+OˁŠd1" ]p/i~3` hE0SİB!逐(OrmtIܢBx)L"S6bUl5gy2Eby5 ~Ve$3>`8؟)Ô&,CB,5EP-* R=s}c)g$jQ)~Ӟ=6Wԩs\D$wFOW~`!5XĵI[95D_B4ϷBsBn0>P&~3>_ۢc晨^@Z͎d;S5cf2⨺v*3҇Ϧ\Ǡt'jvRI{}?.6 &X' [;4klslb_p TOm2"v(QTth$DgQl6e ߔ]y-pG E( P:0`"]=5O*gJ')0k: H %hWs? %VmV7M.BbGC؃o'2cM1tqJhLZ`ֻ=qg~B.ܙ0H֡Ip!GrzC!e*?y:hnhS>m=tg;" ١1Bz܃5oI2dT pZ-X4%Q$alYkbȸpįt~lj-dTKcq )D{I&;P6=T&2P0<"^' ix.2 "׶f`ȖF^gQҌ1fm5bJ:;Xa^S,ΖWxCG'5 M-"̣An)5x)s{,*>F?^ʆm%aEv1=)ao;;[x.xawX `_.㊍0~k";^s5g]-:̂D%{ҲEixUkjUOӼ]ο0ت1j-W9n BSn" ρ{b@.}ǂ ]Q՝%@`^iN:?/Cu81ܺpo97AR BW'=v_8J`M ڶuUHD&nv^??Eի6iE%wX9vP7c Bުn)DW!)/"<>6Svm#ؙ@Ivw6ua9 |]2U4z fJ#N z٨gu/h]k*?9M֪X?(ܨ?J>xahS\[={( 1{Ϳ'a%ʲʧ_! نdy9&O=Μ0/DKrWϼ)oVkG!]ŕm|n.,}znN=!>^VW_#Va Q̥B}Ի 9rK#0óD-> BqpЙS\2b̋J(i ]S|ޙQ|p#}cEGz6tZܩ 'jZN`=k:Ij/n@tD囚ig*eq6yQ#]J(>@RD*{,MLG>qR"靖 29WcG2mC+pɧs.`\v}`2`F qgX+XjV&)>yiͪ2HzpAt®ו,U"c8>iS?/E <a O"Lq.HdP^*o FTZՍ\zG^FnQBrT5,F.Slv-w&$ ZKnʋB$hy"g0T:Gמ%A9x&+СR8>~Qtd6-sA߽lk25H.P# Yy)+V+T-8!\_U]0Y5νWL:V?<gFKtB6a,#O;y`Dڄ.EG(3i@F"C/m> o!a L?.hp+x;owUCMYy=r_>yQ\buwH<^0M>Qu p>#L',;[&fO b /&h_[5:4baGó Ne@z5F7E52f=Og`pSهXž"7QXZ\tɥ:eR8H tdQg r_YqX5(:9VO1C)"gAhƶ3Tվ2jɡVaTIdeϲj #q :qP.\+XrὩk1K ym j񿬾dba> iw[*!I4?E8\ ֮ky\`]@$7G2l#9U̮}۔|b]`顯%vv#"Za$y#:N="8.Uy?e0xQ+aTX0mƬ:F8=*J&rWFbLy~|g mdWh'>6R!%6\ץPUq@*}j@" p2eă`6x6\:3W|raH3 P!;J:_ڴ1c ݜHg"f'@H9Ì_HoTi47#ϱ @$}! V5^-ΐdfi]#62\i@"5@9[M_P?dsUf/ZPVu $,t鹖_>+GJn_Xqazc1$EVU%ھYyZc$Jؼ~ а*" sHP7j\8$rGwv6%!JI}T%* bSds%ڗTla|d̙-<-cȖrXâIPLщ1}̀] )moCe~ fY-j#P=X)`]c.5Zm.P&E>E\GYD83" (t}UsMQW:VfNv 2?-fRj^l;4ČۇD*$ e-o-Z J]wKaՅ̩iVPH]/Ү%ncTnE pR~3 v lY¶Tk#ɋTn@\3ůɃlRSW|mяcx@q9k>3uZmLAAdhǏ`{eM|hy/[EgVE*Hei BUc βA_;9މ\^=_"񖘽ٟ#:k:@EZ1y/NJq3κmuҪZ4Fj2'LsN2İbJ&ק߮%V ;W:4!9{hdz "Ga{3m٢)/*Y&m]QLAuCyKF{dY䮡yxjrv[cŜ]i{9cV\BPZM(62ݢѯ9UnA?=Y̺ R,8ϥ#Kʢ\ro:sM'hD0g }d@Xꝶc,/>,=~\hP_h^E~ MѸ X5[0]b%Ưa ž/*b J0PETVofE[q A6]tQ"MqGCO輚?~FLZrCvЃ S1SpI:S|k̭nx'aGO;&vexvy !mj#6>;@"6~ F*G?pNX%L[*g:H" h;1NxUKύdϰQڕGoՓ4Bo ~L w؝\6&X1'HAn))fM! vڧ/QIh) PM"vJK\?wDʦZq䬥9-)Th 5Y|WbPung V ZC?N+pJ )P7"=PvK3eK'hڴXl pbIF.ˆB Q%s`!]d쌱uPLUŖ\K+W `q r1cv{TtEQzA)F#& 0 >ymtDV#lT`SVN ͮi[ ߺ̳ ﳵ؁Ni|^t{b8_=3 q^Bf0p)jKǔI[kǯ:\ ǹL 72IHE=ͺ]u1cUc%5%Z%g\|]U|$ W.^Y͐|$b}ޜgiItu0VR'I[:u62?( D^EN#R@#+_ڋ \ 3JpTᤣyC$9ōw%iY9sERZj&Dfb&Ʌ:r5yiEWRGeC0s4;rcR/aweUK-)z{HMhirYԬhx0.ZB` 7 - uNޚmbξ= *1 kzkOLY!:c(3^m?s*m{ i޽gd!WY ]xTƂ:[UD*nBe; 9%e*X;~蛁Z(J͏/u٫D m; MR* SbI> G0c՜E49ı~h{6^悁^-T%-Yxv4`iFG f"~9τ Qjs5:=޸|9Sn,߭I҃tZHaT^2PCr j{{٠P)EWeނkAò 4f8(yZ3BfHv[VƉdEd<ŭ<, ^ihЌw-r~|z 0DmɓD˺ŪTgi.C6k(Z!p4PEnM '`0v',`ܼ+Ĩd[:y:F(Dv{3>Dn΂-A rkN134^,h#Z"9bQ}^`Ɉ6`};۲ D*,Ң;6!b<7nK< gUXeaq.{Jt9aH?V oa峉00O, iېŨg@\miqaM=#('/?+0)^r.vAn"XK*?RSe޴[# P!4F,;ӆ~&˭GȱV'=7gIcǬ!ލD?y&n~ eT`'[6{h9`R̬4}ָdWҾx]b %B?ONFG7{{A8Iaī.6{PQDH8^}qjLI#WZHyiz>{}{ >L'B&T/(x._%fƕQz%6$dFZ"I\8G %)Aa,:3 \ɇ 9kl{ [T [|:_$jDyCd pF>)$bo/nj]2,$&X.?lr}Ww%Jz7k/BS^E NlJ)~ ;`~ƹpKx5ת۸.٬#vGA#uQW4;8(4<Ck&OV6n+6SW  Lr(ʶN+lߡ)J{!Q/#uk~>Vs1| teޡof%\(z{K4OXNp?ɍNwT!d󍻢cD|dMJv^B|;nOlVZ3jB|Ú2Ysȳ/^z+/ s!*zo5؄#\g<$ 4] ow|i_mHȿq:́E\OȗìvNTx?9GhꇡQgۉś#z"o"hF 5o)I 7Amo I e䤍+G¿c0`)2T6&V{!&>8 9L&h7dr;)O.-GP6-7ml;3R#{HRhI1@K"}̴VḷF} ƫO_U䝄60%gAz]vʳ®   3ʷ679k*25zG.FJ/Ow \ub[Fl}cs|10[#~8A"^&3b"p/Y#X O.D;,qf;WԂ*FĘ3J aWLܤ9@ꕙy-f{$ũEp(5=L4YV.U҃_Vү<2AF9zFwfV+ӝ2ᇢ߽+\j/ǿ+hu+TdrŹz{: rE\d|R؁^}`ַG@Li} p5,:ͣ$ʊ̜AD}D}i":?3u%ߋ ?36I"{M'd/~-j:h\mQ"* 7yŏI,Mƅ4Rblh,'YRNhhR+hJg9PDKǣǿ, HEqUEPb$x?YMLq6z_5U`s(bA6(DU@iIue%ّN5v"'AeVХ̰Y L #|tPS>,ek"x:E{1k#n l /6a G%B{#~09ܕz<%lPDd:FOӺ OJ;3mJly[lC?t{ΣI,:HRuG'':y5w",Juȅ7WF쿋)A*>{/jϛD^GIF Y \l4|Z̧h!Hm11+C ɽGvRYY0@F Es"C_)fOV٠q ޏ$i77n :S] wv.zI*D͙ܱmҝ|3L> \iU).+ )X}ѥ(> x*qwAq ü-9b+ɤBӴ{VV()_bvv%e$X]Le˼<:OnǬڛ躍<]jK zb457v k);1J*[^OM 2ƴ2R 9[~ I,S }cL"Xb]ӕwC~;ZG\43SH3rsR<4'nݰF>@ʱda)ʎV3*uɈ_/7ဈ&ՒAOxs+n#G2#A6cքK쑲 !d[_RX%ì 9ұD7c [!"Ϊ=cOGÍ)WC a cRmA㖩 Gt9.Ju/@ ?tiOD#r5wI vgqq` yfzJjyrU䋅k~/'=0! zkB۝dBv}քL L֡gh$C=UF# Ft[6e){HL=jpw^ՇDEC\酸"p-^, E:-g =e:=SX4/рFLkz dh- 周ͽzY[ubݮLE}7Y ~l,yHË.Ğ],{;&kS0-D L-+Qms ;N\j aQ~M5i[EĈ*\WK04>w,ʸ(T*6+ s!nQ ,r[і敊(icD#E ^=.ekt}d࠯ˤ ySԐ(Ei X਍Pȕ8g,osX(Z!fK!g ,G9<]>iPT,; f3 <[hXt^C9NVQT062ٚ-lÌ$Ao͜p CȪW GT1أxlnPX3Kx棎:PRGLyUT]J1`e`q8-Dmƍ@'ɒ+f_?=۾ujZYhhr + ɰ*9l"g/ j'v$ڍ[q 䨹f[INWfi%larkHo(o[ (%Ή+4Z"]z{#62Rj& ]fΦ )Yx蜁"Lj=@-r%;{?]>c:% ÌBJo<^plu=$ gFBW8odOOLyΛ&xo`>V9V5=.Zi6Md)I5K.'SRʙ wvRERxi{) ]K9?}t1f "8x~>hϫ:{XّHfTdoH'P4Iw$F/*ьl%'LH>;LŲs;D}BP O-?Ϋ>dZKT?}5!ɰQYaP4nfvg$Q4ՏuRh&$Eyp*-:$-0i[^yf X7YT/R]YiZg"b;;Zf[zH$hMtz~La{ϐoջmN?.O*`k~SЧc 1CaJ.uO7.`KF3<}NВD/I0}N'Q4ϚNA{3ݳ|@NOq Ohpk+`ۡPuSU^2q%Rdj&fOP W| vdI(nF5Ӂ).Bc> 2UIgXUg^tO ck{Qs9|x0}|G׫)FnUעjЋZ'a?0iP xrO8Zl)) NDIy`4 dN:CeܬƗC۾C>rj>W3+I{43MlK2ݪEWs|-,lP"3n =4CU߮&h6daqz==p Y(ʄi2IA1_̞H2_DUeNӁ8&^/+¿xPPmC.Έ^aPтw|b}bSs_QbqĀBvA|gp\S0K㐌5r)*"q3u'q2ɲT+cjGh^l߀=;Ϣվo,쭈~H+Vr{4dTX(R}|)'YK/f[^c"g3,eQ!|] I2Lo 2h jԅ9=;Q 4*_!dti O ɻCh >a, 'ἕS0l"~Clo!v'BanHPxZ{%C(y#O&x9tGp34v$a܀rQr)YĶwڝXUv|%@'}oimiC|x̏@`] yI)'k *CVGw$27tdŐ|Ȅ-/vPY r;dF=(#XReeVdH"5ߌ:Tj^F8}n4jfk=h-J@l \`F@Um=0OsF>O|LKw1֚{)g)KDY w9Tji yMeװA&(aN쎘r尯FfԴf}֧נΚ&Aȍh:9Msz|kZ4i=zg!}@6U4?*Teo/EL`y (HJ44dS^҈th*ᕷwl+IFܒIv(r5wm%Ju&R|6"h.>^nPxA"vfx헢^x_x2;Jd6fٕlaUv᯼u3mE{9l?w(laȉQW)FN+Ms%ǹJp%9.?H 3-oפGr-*Z '[a:t4 qvf64<KBWBno قXN=fk^ؗWH`˫7D.^a;QFFZCcdNrG:L>Hrjg*mvcw-sW<3j^Y&Mq|xZ3U/NG۠?ts~X7ZwPy?MoAd=v:ZPX_&Q D)ce6FgR;y:\h=@;;d;a΢Ѭ{%=Ys3uϼAvft]`283]mL%s '%.m-'|tԾTk/e_a=슊>;kM>c4e)?Wi USj+l'M?ic͕(' {ӒZ/Jm+n1J|ĝV׊ˢ*:QY*ÝA!s3ʈd'о:L;jD>z,TmlrKPrW1Lj< W{&5S=!01A>Gpm!/#DqcgmUpG7bڗ6TGhduͯ;`rA05Kw)f%\W`0#)ބHRFhIV;T(h%4ʗr"Nٙ-fHڏ)Lo)i;$ӞB}&u`="m|xXt .SɲmZQtX~z8ʺ8B+b>14 h9k>Akʪem*y <Dw珴MGq^lN1M揘>[Vk Q\dAq^Z34pQy ຍm<^܀ 3b0)!E \oPlH,F ׸[ޗc`C2Q.dhn]̥žk1pq 6R).!U#iA NKR|8MBO R$R|Ǣ H]ؖWSI@T7{lbn!Ndzh,^Q;@Eg E]w}jT#`EoH3ҽ:ƪ!F4 =w*qVE^ KgV`b\>Mfy{hdY81NY{jxҬ@d#tI oEat"v/5B5XPuBf_ܯXޔ :uS{o!vJ5ye-3.n"iT$fA47=b ˇR# Wébp0xH/L hC'ҽK>(0 );Qא%nlGwJs(%i҅k|]. c"U%ݙRҡ6=jN9!"T2MU0`TO$ldaobAi+BS{|V(1 69Ewag\Cr0Ymm.'W6H3* ہyv`?2|y5-P^xϠ_QvgtrM\N(y8)@ʤ֍S^)EŨO `*AIӾi;k_ի6ej|93ګ1Q h~*&,]` z {ɨ9?[css9 HW/Ae %'e^Bj\:"p-mJdL{u7/!8]&8#eriÎ d29ެ@H 3*(fh9W/^)`0&uwA Mg}¯i$(0 _ E^^9ɋs L7>BxK+n 4݌.61\D4CT"C7zvv6A"6ƫtK}w+$6XX&R7)2a39Er1ƟTqrD="=?\['1lY B8*2 g"K6Bs# *yS$X-+#;'8yG܊{U*S`"Gau._ќ^RN u(_n{- W8?nB]4KY#aEρ0 x +W6{ YZ