sssd-ipa-1.16.5-10.el7_9.7>t  DH`p`$ƨ=Gwp}sվ\k1Ȟ99.ԄAu9'E]D(]dgS4f*Ŷ._, ɹ1M%<NQp9j*+j#U+̧uk@Oǥʓ6rb0R9l׌(ͫB0M 7,@r@H pi?NOxkPXH|b Ҡ_+ ښêՉ\B +YXjKctsE{w+V+bG9Ӈ { 6'C–1$LZNs|_1\-&IlLʑ>Ѕn23bebb9f73fe7dbbf2826a22d35185d37ce2081d2d`$ƨH_ot%^= &({RQ jjak!f{C+| dY$oCЉ*1߭DzrEP ,+ =~1b30j,{vqۻ+-sCt_JJQU)#FXǒ1q2R!XRwUҗl::EZF( aZE|X}Bx;Qo-D6=G=N|eA߆%Mi/I) }k{ri.ߐܞ݀»jr>7'V%0"Ji)vv`no 'HRDžO6e'/[-߾RmaX/UפZOMk5 C?^]nB0Z>c soCٵ  \ٟ"EMe#Ȉ{rft4mi "O# AIi.`5 >=%?%d   : "?EL    @  @`TTuTHLQ(`8hA9lA:hA=GH0IPX\Yh\]^ b d!e!f!l!t!u!v!w$4x$Ty$tY%Csssd-ipa1.16.510.el7_9.7The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.`~x86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $Kq&-A큤A`~`~`~^p0`~`~`~`~900b8b1d2daab9c567514aa1b70af8c185b5937a76638bbca7fcd3c13b354b7e8534f29f2ea20176272d7dccf33b574055244a6eff1553436b95698d4815d1b98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ac71af98df93f2caf49621db53b8b99f91a65e45b6e01ad3c5d8651d00a184d5de95c5b2d2a113a5674a5f7d5424ed7a188067c5536e8028835f7799fecec5ada10dd3e44313611109e26763bcb173feedd36fd04e73e65832587bb265d6bd0arootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.7.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.71.16.5-10.el7_9.73.0.4-14.6.0-14.0-14.10.16-9.el7_91.16.5-10.el7_9.71.16.5-10.el7_9.71.16.5-10.el7_9.75.2-1sssd1.10.0-8.beta24.11.3_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.71.16.5-10.el7_9.7libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3819ff80f7811e597b318ce6ec8c4430ff9de0df, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=993c0b3f8de075d64d1dc6fadb8bf9e023cf06e9, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRERMsQd] yR8{$ sZޓoEjG"TL| vႤNqbC*L 0'CpDŽDVhEƒI3$y_5(t3邇VJ"oL59nT5Ȝq8c@5((Y0NWPm9u!>kH^,fa&1yy+;10&XpH+U1ExK1itf|T+ڼrѪ讱Iژg!XD15[6=epic݌c"Ɔ*&g;R z|Lgֻ# PQj]s"*ڀ*tl$e_(ap&pd+0{FQRHεC]/eDybE FTN>6 !tcEYm pȄ \" 册]oai}s+ V$ r}A p؀lZP\`.Gp>Wî_9"48q2E$Ew*KAI =\1 |Wllj|iX!r0ʑ(&]jV^s,E"~x.?.'`.?5@8k :N1G ]vo#}7"a Z]|f!9hG;2rN|2[QIﵙ/ÝY=ns% ;E!+jh&+&tٟIn/#* Dhy7HdIfnEKĹ;B?xI0ie"vύF,n82l:p86 to%r*XT} EZ 77M8XWzQ = &^5YdipƔSZPG\JLх9 vWͻ B <&'@h873ԉxy$56~LI`kؤ LM_}XY5܉,eR9XқKX fko !m0N3y3W778<^IQ~m RZB+&%`j6fYzHģj-:ҧ؅Te$[,8!CgӞt=Ed,|KcۯvVC w[#dS}Ri3X ƾpc?8VN@+;#8Iq~mxa ]bZaEG=R ()‘E;{Eҹ-ggҵKxyȋȇxK)3D& &]kX$]1L_T))| ~xۼf&q|]Ne7ړ=a>P,Q΢oOzo,;Of4&BfbqauDqhB3<<.,>jW@T _H* 8=GwF.*A2YުO8 D .ą H]t'_X͇ka~79K] @쐹] zB^f(keL~ml)dҗKi_G5)\Pr֥!}W&QqZ15da &y P4 )SzBF=G@36 úabҟ4+/MV0#*@BQg J9ћ3 N.7K΅zYp]mRY9mn%@b3Pl[BԹ:,G0Zt7̜k2WOrJB"|b-՘qw:G $@[R  @@pDQ*㤏ě' Wh}b{ lOk2Tm)Dt/ܺsޡl48OkY1G!b3pa}LCUKd[Eԅ`어x .xPƒE؎;飨YvUVuq=]`X3D_-(Hp@]xJ3"rsqI: |:u+)AP#Ow:kRNGt@hNjb="hxIZqX@Py2ju=򧯱n/P?y1olCvwTʾ/i sYe0REڷ!K^ ύ!wd ,匚H|AMy|qC?R|vcaF vZ8! 1pD)cðyyi.>ۯw a.M|+*oVu-a>{jN kRRkiNbO*" '3Q0<@JG sW#E6J f?u.&& x]?bQtJ %}eQz_霊SP_p{E:lu_y2AXbVo&g~oO^-Kݬ)-OeH9 %{UD^jɺ8)!i 9l ޫU l`pn3 ɮ`0Mlzt+I1`/l߼_./EZaf+)V~R,*޴eҥF0uSCY{=R>p `w\h?lNYmR. $pvN@_qGy;"2& Z5>$.!*$">1|zvtl au)Ya'^/?`#| qT 'XQ1Mݢqe, - ÙH* {w,A|Ǧ_gt;e.Y5}{j]kɤ2$ݭW0Ml Fe _Qrޟ=&32pLR~c7$kbAOۨ0 c2j"%CjiR3矨LYh՜D eZsc1(d9Zhۈ < l ߘ*)kk kL3js!;.] y8eW9݈|V~[y"6KX;eD .ӟC]g\%A t9dsQPev#|(ƜFHM<d8LDd^xb=v7PjR3,ɝKLin ϧ5z R6[KBSEsp}l`ȱYifHr5xOلU;c|0F'!wxhRFoՍZl #n<~c2&ߵ9U1%]{3V<)SΠ{ jpo;\hESFb"#eӘ)dE_ǽܒ0[o2OoM.b@\}P:Ƙ$WM(FWsLpdP.2Ȣ,cFYlNɽ4~U|ꐱ 0VL.O4HK .uZA\+J;/Ϋȳ nuбo} ~eZY(p;{ =S+h8c_H>%l%ކkNHVJMqg%^S:|P`Pf T%SӞ?݉L4\e=nWE٘I3l n\$Whm8LXGr!F >Cw5b5r`(ό`rD-uc3:"a: !NM\zdtu0sEHm1U:);K(4.{h~'Oؕ3 YBK/ 152藬#+\#\ߴ#Q9!Sѵ=@]>ag~tӫ%d>I o"(?PTPamT,Ӧ_YYULĆʝ0ΖV Ш O 2!M!~0z&a8n2PxR`M7J^jt=oGUTf X7wT t><۱N]$p|160(Ii 0BD78zyi]-}vfP韕]0ϝ.?ܮC)_Eԑ;|J:$βtcx\1$ôIL(KY (p+8<:k ׉PvۥeƓgz?S٥w541 ] hE@ ǘVX9B߈m~kme2Z7@ EIT(9R80zɩp^@G9ioLlL1oX$>XcXBLB7=/X^}ddW֓ɷt)ɏ+ut1R+W;A^y !??!-> бz:{-L&;/ۉM(M :k &4`pk굂$}=yAnwVRS aځі5HӠ8Q@C`C)vv溚B=Qwt'A h^f$)[Ȧ$~A' Dޣ4.F|J:Yȋa~fYpPp_&0z_F:%R1c`;(qB.~ ii`ϝ/9<-xꑂW# ! Ⱦ8X'WE }g5,p˰>S3750 mƖ֭"p}?h8K!ɲHVS_wO"0d"hMLz-0{{ w%}V;ev]1uG}Ê %Wp]9 MA{U>G7ݝjr#Mƞ6Cѻ]]d~b u̜GvmWv" =VbW^. 4p4up)$$B% lC&/Rj>w;.^ ?rhZ%ZY_ĻLf׭rXu{&ĆkiBK!Yaq4l- ݤߠ48@Ω/`և/3O<#LmgzP@yXt#WRe>Wac scc߁~kBt!:A2!Ca]LE^@%N EwsM}ڴ и68GUF+[k9mC?okRe0 '~)z} $\-|?Q=[i)O>i#F–U1x1 ?1槚Ȁv^ɿK« ucFX=p#n ,&1[`{a\E4e@'a#=psz+Z4s,> ͹>CyGfcuWzKkq- VsW'B1[ZEkj^)j9ytJF5"~6=i_Ŭ=x摳gyhs?މCP5Q'ϙ"!(\,7H' eжcYX5{v]v:mqAaCQEw ޻a r.mBEFY0^6à@g9 ~i(iKzo@uvh`6:5F+ljtySVnCFq&k*"ef*47V_w|!XbCۗj?kxBeGЖt{퉋'N0߅u8\DylF2 U䆟g#ٷ~n6͡qk#QC׈o#GW'~e(xkVzW-k!geQ=m+ߙG:ӨMܵV`4$o}:'.Q*;_)B3ZMs |^/5D>Ȑ1CDnĺ)3fY`D;N!ŞpC?"oIiUΩсh+OSȧ԰TH2E\ 61lyѳfP#⦒!X˺SGƁT9;+j1,ZV@g'1esS+`&D<'cc<oruLcyl{s@V9F/O  JX:Yr  2ꀊ)#Yf d: *jƧ#])CPrwq7Z $BtֳtRh Aniyl[ 65тCpa*LAOГt(EXeybii b;c:"'֪r1vUr 2COX:}qjRA+Y&?/}=#OЉ[fR P7놑ݐENHp_bD 2"H5QD⮱_+߀5O4aLQy3182[(/"GFnHIFTWИ@d{4=t7i4JvV^5JL4q) d 1FUf997{|yW 5/3cxx؎kH/5[9A풂]j "S&؋ νeLN::f~0vK˺Gk@r^"ДaF*; n7bօA}ڹ>𾹎,rѧK˻R]I2LQ<돿\G:2Au*>B¢c_EWUϺk8ɐ1\/٪i9nT&Iv7B`b';b'AƺNsts45D o?٥!{ Wb~_A.Ͱ_(b&]v!r T&gNdm>EBi"a]o]&zH aN5m[m2 s״v_+gBfBp98Vxu-03U(M7%7<6 TlEYnL|fN H#7L\ض`Za=>XFmqg^UoeR#2@5 qbAIb?#s4* e3.Sb˹8JNF7;Y]6ACMC0#sJo ꁵ3UL.G⣌voǠ[$k'K~r1%e;Y>H3[bXڟ 턴 iWٺtr@TS|:jx+ M$gO>98;G;:ϜVe5 "L;U6!S[6S${h&jzg.SC2|ډya=HW6MVj$AH0U~W+#ZO7 (;лճA>6x]hrs,ї_@I<% ]ϓdPN @E iԆFMT#I- jMܵǡK5bctdʄԋN2_ {L!Y!Ilsb$:(p 5 Ynv\ A:4dPp =V2xCV>pj&nbRͪW{'AH[ PYᗍՓFwS4(*s坦vL RjFheg9 ,cg53 0~׫^7Ex؀tF9[Cթ%xxVQ"z.]YvERID=#$9> kU ֖ړ@١, ?]x--wd.4RUP+v F#9dA/lҖ9ZJ}~o m =[ H#MP= KBert9ml~/$n۵I=D=1/XOF#JRQPA fs.sc/]N-}>~4 2ߓ3Z}gb1ߛ@򦺙w*fzrU(в!9_QQ=gmпyrej:@%Y"݆StvݿgET1Y;r!c=tw?cm^QC4B 1pj @2vZ<:\B:kZoe( K*={B DJ^i)X@$pXSĉ[pqV#۶\7cniJze9Ǚ2lFA]`2DKX&Z(0֚xvMf\38gU< XFD yTHq$ P G5u@{ݡ߲nD,*>|أ#CBS )(1`!OU6)vu !]s Uo6$Pjg-* qQaUU /C G 턏Pw&b=I#ZEa\x(VE+v#oԈ:w.ƙ\`6hg⠌M+ 2Jyݑ8dey:_?n0rhS2RTj?'yd$61@12( g8F.>ex?-8F,Ή^CJw^"q9ĬގW风G` 7Fr~=)kv]Cro/_Q)ܩ;rIe=AĤ_y6 @KV}֠3֗XW>MZ eͼϚ<|\.pTO -/6i} Rmo`9+6+_&P^Ъ8t+CGOzM_lj4mL5س*aoMlLdn~׀&QqPc!UMieAp]',[>)8AV+4؜@;ƽ$V~0#r&/M7Xx ]]5PGg5dJjL/ YU_ڣ΄bdH[EuS~+Z)a*82 S- ccwfs}U`:@[XYq® .(7بp m L3StTVC tA׬tuY}+$_N! j PG:>:K|{Dd%i⏞ _QP(k]9){~8{3S$vLL:RMN]$k_u!d}|LC8ŊPZ jh|dkq"t4kҰj$5'9 QW;sߧ>/v/ +/llj|v1b$NG렖8.i!dH`n*Й>[͔mU 7t맅$q%D5lr{+h=ؕx Pz,RٔZW]t2\DVb0jqBUgG*03^ DqR; rk`?g :'{!'LrAԡ`~ʿKzY ȧ('"fDmqlݬ{FôbsVM]lw׊?~1e0kWpIţk5b'!VrV1 %g!#wڸ5AftI\u'\Z%qd9p ,J ='5i{> v!9*\l24u֯yI9^*$o~.]p:*u/!rZPҁK b:BcC&5=3kE< 7^v\jS*AN ghVp恳Otlw5Zb"V! P^d`Ug!#;(r=ؗgW)քrnmV0P0x/`u7F'O_'%/tdx8_ִt\ɀveDhYwAAT<f$jdDx$t)f2 >vX[! J%޼!o/ \ VBAz_ʨmb57&_}db>6r1 X\B(q<AK_՝c+J_owHRNѬz2pVһj}b>cZrV t VHQcq7T #S]/\ublD8Fl3՚+Û|N1tVКW YayӉǥG;՝֜OȡQ$'k2]שH}gHK }E 3p*C^Rs1]!'H'V79N^M>޴(P_{6E񀩶Ta&K/я_pӻ0@iC'Z!ĕ!G tf8\[R zx-N`WH| H+:b5Ty_uVh(UR-FNG2UּXnKJPfC4rg uc~!oI%iLfUYv{s}: X57ygO!V1ˁw ףvdǸ4PR8TU*i1{A=FUNv,ꞲQ!E]!þ㥗|B}T'#YFxxt QE5=scsw=Vؙ˝j?A D9gS>VLTUtruM-iA2E4C/ֵ+GsV >1fi;-7Ph*dfkq։ȹKllOE2$zX.SҺ4xRs`\QU/ρxN'1g;+ST'xn &I^N V*&%jGI x' "d޸K^3ZP0aK-ǷCq \DYd=uc~n[7DO%=oH(3=<~(u_$ʦ0|i.Q -IFA;vK3K4JBmmD q=k_bQ|3-a .D\6`ƫ +s,;Zځφ 9+Ch.Pf3PTߐJUzv'R0 ꝵ1؊EѶGGVuaVޗD$_JZlxPFI/m"˿b.tR̈>QD"re+Q~Q~)x6jͿS?318i}MYC@ SIciNge#x3* h$V4@w.~Oi2 Szfq ED=~W2@B64s<NB {ip~8JfCfy4ZmmpD߸& <\6rѩҏ}4bh߃VNRg9J'8GU][QNMRc9mZ'%jJP}I鮨x5dasT6)uq3U`s'݅_~kʪ?d8 ݩڶT4i( F&{ѻjTScgb?M9O{\C\?J^JcS*@梕׸q$a5ld6'1ٵfyQǘrNQ/!s@|哑6ot.pڻ-ɖ;I/jO Ul(N1 `H(x-vV <hvu?dT 1|1#=RPY<8U`1^.06m%' I|B8% KR!_ц00('U[s08 N3u/\"֫{ndo)89Dˊ6 KSډl:8{@esj;U>qM>`Wwz#cCVV쇄p MGoB;9LrKU R,\5[%d]@vީTS[Y] /}C˴<(ر01y"k}Xd{TK> lk4qX^:,#RlG4~}( 2Qjb]}Ҷl$ZXj+aVJ!#XB/m<7G1VK\&Rr d@8*3S}u#L4i=F.a|"vqGԅ]^ia~@QR+Ӄbh0Ԏdo=+7cl"Bb?mK2sQ sӻ-\ ""e5go Rj d;ҒU@x4j>IIԗ;g 0PwRY9@3rQ?Ăoлa?qnϰtdLOU"pO냰=h2t\ex‰w ;!|}+r2S$aI1AH9.O^0ch(4~?tkCB=}cwTS"^qE6dŘy.ONaȲXT >J<hQ}R7oEY:ޓ׋ڴ ̞PUYtqKTqw#74ޕ89K!~1Yufaa5 8'h#Ď影Ѝf3gǵO@v\Up1h+BJk*-6:Rtqk$d!'h)rVħaVޓ@9x~x^w&4Q͌ĢgۢM[}܅1iwi| c!P8yXD>3р(T0WP8mko](0{|FfMÍpe_! ;n~Rh3u3+[[4 +KJ.u!nf`XO.\L7KS%8Jz}KGtI?ZҒDR!q>F ( tvWwU+s 4kQ<a~}Y'sIu{J>ȦvεIZ /ZbRTW4N:/o!Ԓ_'K; 1CfPC;/Tm&ې5.'~zW0[I )"#-d og4#02K2pV=gm["\O5h1ץ<{V*fnxBy%2tSaݰiF Z*;_P)w ʎlw6(fL.Xå Srvi4=D Wȏ~qʹH́V-E ĩw%-ky-\*ӪnsLO=Wʃt#b]J^ބ5vEvֽ-0K, ENPsPAam\-.[ 9q^o.rM=j<0s >_ ^C|G1 @vGg݋Y'~=Rޡg$?89) :~n7auQtꬶ&$e(sutTӓV/eyy*uR %p/kζ;;:.+A=- P՛ x.*on(E$Fe]0NY#:Q{ p(ÇZF{Tt}2mU/3*C+13a1~">9qri&HtUo Ȫ%GE40l~>~'kqb:9S%Z8]xskKzL@"Eã0\m&9R(r(<= B}>_?fp&3#sv~{,bt?c-@XӔ[k3s?؁ Qsײz5hE WY-[I$R6$; Z$`s6,&Uފ=ӎ@;+SpK "MkgZYո t@m„V2G(8ևb#sh3 , S&B'BrN\x/#?$.ȗ4jsOK͝.e/н2& ۙcҍCe|s2kmeJI?vO.Ͻbگ&N^A[ .jX((0kvK @ N1_WhY-[sײ"VZ(QZ&Ww_z|(W (X"wWs3% BncHbôU>Fi0p=9/*8IA0XJZYi\m՗F)`nm*>fJNɄ<|Đ$EֵTDE,SiަΉV Jwj?J`JյR"XmSvt> ׾Y ;ƶ[8Z5岉X଎4EkztgtG (}*rljӁS65?i7N1:9mҞ%z;2oZwz! n1PJpGvJyÎP>@[X=mkfyBSG5=2!׉ZV39ht&oIgL~%$ #kUleg!M=]/r1v =7k-rdj.3M8jܺ`C#vh~aFO.7WqR B UQ܁r]U!GFM0.QSJ+=xD([R8]dT1T HONQ '72DGʧ6b*[9k)} C0䣧6T ON17<:eof f gF2:8`I3 Akpy=^R;DFnKߜ^]GIRNHzJ'^tѶf0pe1üfij' ftUg%LPg$uԇ 2Cث&Y_B5&Fn_5Ǣ5@Vn"qWܰha7y\I3C9"TnK \NK (d|&"b W1@v(\r~H9؏Ō'No܊;3wc-ToxSY 87e$`4mVFI- КaҸX& zi4uҳqe} Z %p\CgHoc VJQ!k[-$8ԯʪ'pSf3o`Kk̺Ap|2b`:VA+H]ɓo#R`J8S<ޞ .ŴusJx•x^DKɘ<2pH*ntܪi𔐰NJT/t y/Y$_e>;/IeQ>eņ:_]pLs/b%x/_xBٺɦ`qUh6gU+j>fC#_5C; uU*zjmuPk;Hlm1UÄ$#?ITQ?FʫL`a%)bR"'(T]#ME(JF1r{Oh}/>=C۲{ˡTDy#x"qNH沥6K,FD URNf*дFL >Ed[m\WH~ Q겆TPżMm~vAgAp-}8:yۘbh[vgY"L#WBL=VF\^z@B|I.}.QM rW !Um yMڼ!E?pqIoJB7ys%+{꣣Ms1)?[|zd݉OHkly~a%A{ fIWpy9Nl?ώ/ˀ "X (2C}R1) N YjkWNܳVo1uLfc,.WgѭHW&dJQ).xȇFUMĩsdP8#31QbkT4BM=zQ_kӁ* WoC:޾59{dF(AwcPW9#r`gPχARt柪00v ҆0=v+8멮ktbwBb$Bp(ؑϨ%m}{WYZ)J΢rw T!0*DvF&XН('CZTXjRZA Zt@BܥV,F9dPuz~$c#}L2{۷Bx'Ae*^NEz*/HV7Zp%;mIS ;:cCwr_ rw%&)$&RkW|Q3%BqTđ%+!scNYm6/a+_]p Wlˊ8x]py г4{.:\]ۄSloTZ6YL~vu."`[ w97]`|g >|@OvK ~e2^Vx|w66`kHXu"SrS͛1V>)xe;/F y!;3AY,pSH:ZljcZ8͠ r4a ;0!9(uT<*V i 5-@]&6QK8ϭդc}!֯6i}ZA{^Do-hMNއGJ|&}EܞѬRr37:Rٳ]1VL?0LQPse;}5 {-7U"˓x't} ؞k5*4pzm>Q !;Y@.q˩e*%@䖪rSeED-ϐ$6wbs$b0MB2ၔs !k20Ж_OɌņGX2rL:U΁9,I"bfxo[˖_k>:rM| 2vJ+Z0o&CPc7 |>`sK[:hE8Hܿ~O3H.M@Tz,jOF? ߪ(шlZ崙 [fH975.z3}dB+Z;c {>;{SNm6[2]E||:惘ݏw2 =p(VVYkRg>7V)Z㾥КkwmPS!@:dNbiTeU2 RMn ʊN0 {Iת) ܀xGn^wAL#,-ϲ=!P&Ϋb:˴6u ϦۭVQFI.7FVj(@f>ESEֽn_0XZCFs@hH}3^n \o"o!Y1q n6tCr+.ZMF ɸ}ۤ wj5kyXA9C@sl=e4Â?qS%9ܩT촉غ(erY5jjs`5Ƿ;DC㟀p~߭\xLkREv7 t/~#TbSȼveѺLxf""}1FB#| d>4p%>pѥ)C;3,N*o'uѩ<#9f)taO}$$ sh ڎyttS`ŒLTDJ[mQ )5ɱl¿)gij-SaJ#i 5Nqyk~ -"`" #  5;V+r|VWP5pEČ Iի9W)EϢPUXo~;Mxj7. 0gZ2]N+VL"ɿ.c8{8^JfݏPq3p VaN3?{8-cMu{ cNlώ=#MӧsJ?MH2PV(TxXHp[dBB]~TѰv06KCy ژ܄W`N'F i((Dz'P$_:D}Rz=v| LƗ)"dwNs/`ź='ڬT x(p/+2-էVݾr|'/ r3YZX906I,+ůwaw,W Hĕ<62͹qu=lJk6ȁ+%: =h2FW>]ȘJ7Ħ b\Q^@ܣ cf@jY;27_g,'oC v^M'}Iv >!{#!Q4&? 4z ^oĦ헝J]1yU X kB.~I. 6ME` I?ɩ l9j2pfYm8b`άxK `D(eT`!n-э\ϨX\ jWEcQ"x7U՝CIz[ӥ1𑄅t ;A?1uJKRLƳ7v3AZ9/v%!?Y!9z岚+ z#JU! . tXֽ۵'m: &&ugw x~3)w. \p  &+ zQ>:7k*+pHj/D5Y[8|B[ Mn)(E-r6V@H^0BYZ[mP5&@O'c}ztQXOj}A <33v &cj]ybG"T '޲H!MBxd.m-=t36Ҥ/&^|nߚ:!\pU1`[_2F4Me.IO?4K斂1hi"$h_ | X ֜-E62C&<05c =<62w3nZCGMu5qW kZ~l3: oQI8N.]li1.;{% 9*^2ci6Q)o[_ ]:3~ZMv7\ZCp\'uLJ={\ɌcFy@~nB-$^ʛ$Nj4iA''SJnYcX/G=fS;'\,}beR@7NugO-!z yH `-Ǩ3OU%pЏoH('rWtWX$°<.V !P->i ؾlc켶>;w)xX3tm Y\ma"v*NdUsh-MV.RH*زi/sȇz 2xח'P*D(+H@  $5PZ,$0 XYd,%.v jq8FHPm9d]U?Gom~qnF! / Jx[hm78<& kV\:fahq@>)8#>͔&Gwax\Yx-a Ёd5P'ߛ3Y &:0e0j>- i \+}g(Dҏz|)ʘ+6Ԟ srtvH$}?/$sxI@O.H`7˥ZP0[l!:n}wNp \UU]U`B50pmbUTcI]e4dYo1+-]S-ɇt\$͍R4Zk/9RYMbil1یn~-e'5(ROUb) ǣυ 'qwha5 4e>*.}{F xRqXjp+^%3֍`$}'Zxy;5t۸gR 㗤vi_Dr:LqHuW =eMyj5BՕcܛeBG7yc 2]Ph)pup#~LJ4;@p=9k gcMSu挛BK7Q5uAPCtنw(3j|+63M[e,u2!Df$J1!QfX[G^U<{N֕JlIk#ͣE]oCxo Qm A9 mI/ K_[a}1ZeeWGB`h ખeJ v'wƅ8jni "Jc9="sU1r-2"&xaVoK୉̑<ڎ$yU:^4{bכh!i}h}uDc Y; $)`>"׹l460n}#zʖ+yEiXɇӤfS ّ tnbA6/仫öA~Oη2;n S׎o#|eJ̾}RQžlnML@aR@C?+gGxT.X\XEbZwڜhD_lʌy*s_[Po_l'+mwSb4fYސ1ջ {|(#B\tւsՒ R1[LVGpr1 VKvh6/t=μTN.zTCwL/*!sUfͪ􈱾aVIފ6kGnܗyy`6}.7?|%R2v+ փl2rieյ~,d3alC&[x VeF2@AҾA#i>]T0^I>%/sh XUٺc轌> YH TWE#7 צ!g9-f_`nrt[tō P "@̭Neo^-MětȏrJx~:Lme 2GJyHL5#ʹ?l4I!``tAC#E8zGэɕ7͎8]|H¸jd^2aI U1+o |'Gժm`5 <@wACX0ۚRF|W`s{eV DY o^ nȏ |5l[P Vx*"$ Qho6xy@EYQExZ॰UxaREL6SH+yW5#z..Ư*&&3D[o ! G+Z 9&1q_4Oz %c_ bPC4ė~JwyO_VaFQs`i(p\9Xm U%%LCh.e#}rs$a̛p,KVxMOs(SaPl,ޅ&E +Y(.i]a}ɼ̽uj ݖk,%W[(25`zӈ'n@ >b\) c?}f&U-&N5C:}E٥,?g~栘R\5f{V=r~7vpםvkTKXms,UR#:  -5#XDLڥ}Xgߵ9-Q,}1)F?8W!r|7qPQ un !?R<|3CFF@'esNSU<*ZHDB_Ht}(HG]s֘irD!1OĄω~ypI1|ߞ &kĒtŰB>$: :*\=ᡷGA7kFL>BtDW,cq 4h)pN3 K([A`q3Em% a/~l u>ōα(A> C59]y;GDk5WRnI{% ˅t?xɀ ^2S9bwQf=]SYb(^lՁ:>0cjlNU k:@arWb7duζI.oi0& uGj3=']97@O2HH >) *IcoS͑v* SJQqFIT(4^ogY (͒^, +IÐцS5=nXI?eKs:nJ$F-@Gx/|S| e9 p{Ԧg,~RTʓO0]刴zXHRD#@>Uǐ8- 5Ű)p@q\◼JL8eYfz{SN(`ݥ': KB hR펗h*6I{l ͟Khy9z|:l|D 4ڑ PJg.TLpv1 Ԕ}tnUaHqv/DsHe&N^;CMNЮ.?#JC.۝)ipu9j:x! gBuJn=bߖsnm'u/Jg_}jhltő\ZlEN;Q*oToqYKeȋL6~]l/\УйX<@Ux r Z#&35SOOERFB8GWI'F{9L/2 PɓgAro#͵Äѻ.(v.c =Ya"sN})x]|F@u=ӵly zzѢi o":'qeDozh#^B_+jRdcr+PsGL jW`NM.qa]gӅ(y^k2lyf谽>Go7Y[ëAp:<[.@즧*}"Ubp"Ie%6^ DuwY%W55Oq韍,APT $+@tr-&673񉊤sp Ft٘khf# GقdT_avmr9=@ݶV\ aɕiY凄CU R# ᢼ803^&a5*V$Km}8Ht GQഉeɓXmSF|="H )kpxNS$-oHxC uB%Nd<#䄩@P%,[rBe'kտy^٬v(a^p;Zq3 w33tHnn%&{vz̨LW<K[=#8ɿVA%&9UDEjxhz~u^gEx4 n4pmhLt&xo@N E=V]uV?$+ Ws3jaEه!1>Z} VAaxtsSy2R#,7ձ?|1?$EP:Jze 5D.Eh~  ]" 3 v=; {hC iL:i.Lp@fkr%9+Md1zFUNe#FF-d%HuT{I#7/pjpld6F !.s5L?%|(uhyTujqQӲYS]vINk-ɡC QQٻ2Š%6{O{ )*7jXg(>JP_]kg p": 5-}1uҖ4BIwAف0C>#DGy7)Y30gWx 5jm݄!F8vqr̙fm`әPƾSs j\տ\ A-i4@eMe ⸃|T sW(5F _T,l ʔ.ׁS)IeDФ#uKmkEIB*nUn=ǐֵ\[&C 6VG1n" )92pn#7Vus ̄?LÁ F^u#=G ꕓԋLi= Zo'0rZw?Xh=4]pZ-5;7p[u)uqzgjN&1A&XQ}GFlsǍG`8O|`8.67~T(#]8n]'_վiT/ꉃKr!jvbKf":IJ ,^A+;@uKj\#^!ݔ÷r$u6fTS^3vڱ'9d`Z;RcR tW7Y@buC[ 8 cР4IդU9_jBO/I/_ogR̾%RoCJ#'iv bO:p'ݾ2zM\}JsBou~aS>jcvQO-'/W4K3Dt3 E#n5VF{Ky}RԙFn5ku 8&N` !t?Dǚɚ?nY|4v@? (3"_Tx.GCUlx頴#[ rI*2)hQlQ$Y8C kV}̰D?dIP4E* YXKʶy&C@ۑ5l)k)wB]A K9c.#..R/$iN%[N߁|x \n&OHݗ :$.z0C5ZOzE;]db L Tu]#ҿ8;g^hI. ;#a-,:7@CaeC@ˬ6 6χ_gRv GSu+ϕŨ|6lmrt<.7qjLp;㘒5r^P4³bOpj[!sC&oiQZe? a<IoeE;5S.mjXJW\1 nDk..],J._c*o̘{vOfuYjcH"\wo-_f~=<1`~WY1&z]e+,!A>4 Vܽ_k),+#ϕpt.Wü\\~v_X'@|Y-g8DogBv=cn ]?H{in'gǶV_Ԉgtta{r2(8t#DUy=T;CXgNño~YrNUEcq=9yQ!;B1͓fv("b<($Bw}Tv<ݗLܻuac M! UiHrBO=TG}KqM_zpgWzW7%ņ{'Ee8#h`kW<=fK;L#Pg%%f؉ps gST JEQm|.؂}\F@u!)o%:kKu6@#F0p]YM'mS2'3GN JXQU5+:W,/X2Fz*86IN zJ_?Bb+4h"zdW\`݆=0e,K&T ިq0{ϟACYqha&q|06B&V$bJ?d`GH8f«f*뫴1`dS6Hy**hvTrM=4Ɋ;gZ6VG;R>n& $JTM,,e,c|5ύv;Xb@:|ӰfrZL8ZA%nE[:MG)|f/5Qh9|=>YN鼖Qm+'X8;I+H8nJ {D,ͤNI<9߹$FA |O7ʧ/>d iٖ墫nղh]"J3c"LjPN|m`.F){.hZc76F=E[c7P><٬ raaye.*6<IJ fT-=q}k qhtw^1ѵnS`ng`dќmTWt3TEh.{A#W4/bSR"+x&=у_[| #m(/(7)Zb"Oi% 4q7֤X,1%KaC/_#l B0m }?r}sln+cS2@4A oy ku~| shy4=y@ @2;,|)gTy]o`P2򶌮}a^nO#:9<û yF=j$1\a#0ucVS_ʫ:㈆5F7P s\"5l էq_nFbDG76W඙6e{yE|7UeV'rn=·xC2XqTs U=܋-ܬu o Y@[h1\d1"7rLBG0ux5BLzjZh湱 qqиWax a?L>^dϛKsB^G9kLjK et] K5R[!+W_4[83f!dQa n⼺`PCFI=[ox$çhhpםGFJ\N ?;8x$RkZ(S%ȝ4y"&xLsS(2e EȂz$[`1#uifRw%2|fDYGhջAff҄oz 1dj%r6WzjǪ5QX*\`LizLZıx`[CaR1WuEވjvB3:MS^*džX!{- P/<-!w'}HٯܚتOTw,wePJ(}YHQ0>4%Z4\_p#1ֲCo7:`y1›27dE,sYX: #kڋ)םeKmhdS#q{qUoLU)Jh z@Zx+t7d)1dwbXG**2&rV6KEM[)gpL'X"]֦7i\!Ry1=CG'XQU:+;z!88T56vu \T\Ƹ`Ll'?YqI+~޻X ԹS\pLP DXu%Axo&4U*o(y%]pfOk.z7qֿ5/}]Ș5obpy t5aW4'ʂڍ;F IbrHbhIIԾ*Yߔ5*ԙyNbɕZ78^ܱܠZJV`d_(m4HL ɽׅ=Vxv]{‚OO_[^ˑQѱ)WnoBSfrH@`h0:n4xw< G4Е,w5K|ܘ~wƋ5sG`Z*pbօ? YQϤT돞@@qnfV>H\B:/^i5>H@k׵e"X6cF\2vjF p:ˇȝ`1-N:t`cEao~rݫ#/I[y"8 w8t:_kl8$Z[AݱӾ@lJ_rk@ʕ/FW!NaN'Tb^ƩA?"]K &YH)/Bm>I})d(#F6_ "'ᄍVܽ '0Ň5o7tyx:^B,5-HG]\$ -8 ϡ]gֆ#q(O -?-Y;3R r\VRD0 1ޡgˀ9of`1RHj:p$pCr:D!Ng[E98{(rKEW αOC b@V!' ?EÏ-Rn?rq·11E\gPϒQިds{\f'j9-d7sis Glyjtq˄2/hފEd@O'?rpoHzQ` !vSjc@z|~}"IֆE!!1"ďv(zʞlkkQSN&I;y5{1 Y{3zU(46:= /яD$mf0J!J985րh:іbq͏uܹ^ǂ'F%@;.xu-wɸI a i9͋hPt oy1J9l]֗X pgTա1dj9vSE."TMs Ҽc0K[\Tu~8ejJF~*i#G1ȓH;e;(~:[#y{|+ZB<2v<a?j|M"SɼƵ#Jtպ2=/ !,FkZ٘8Kvle'x~F16*KA38N5B+\q]Ae W{g ՐB8Y@[6@B [&kbo"+6G(oxC $sh1ܢ !:u4H.rP=ɑjT*TD|ДeY`'>A_D%YE"EdR0eDiLI .& #pޘb4f= G 4Q: ('$sQt +۱JK$pS! I9 )FX\9ֈDƫͦ`&Ck 1+9s0:WoI1ErhnX&<|;arIMqvx^`ޜ {(5nr0wOB[^DSˤ>0d,f`2@ZwGeiQE~_b:1B5ifU:Ѧ}$nr&˗^.ТdZ1uS'#EEd_IX߀+?F  .|#:plola3PǶ*zld <{  # oؓwNGۛ]Fg]HK}ϓ^xd4+e=]ZnʷWٺ~xڹ^kP? UaYAfӤTlϧe2ryʛh~xl h"ihKk:EO ?<3Tzi8VaґIXVQ)Y2dtX>ffuwHrƩr  ŦU_KPyM-/DTߦzW=+ yJ1_YR^ha}Zw90ټ& (jKX?-zw%&kob-Yjϻ*,xK<^V;qЏyjrG +W]>.1MN{9#Y"x)q{e,o˒آȲGc _xDYt]^Z̞ΊRIiR{9ݤC,^N΁ R]glⱭGR=t"R >aweUueCSK'}Woi دj}e\}vpVn jz qFONwμ8MI#Fg+"vm*ݶr yD$0:LQUR("My`3YuM>q01$mLVLTwbX l M#ӎ`-w+aW vNbhW)^u@ /Mz3ff^h&쵻 qf;0Ϝ&;x&4Xzx{g2!PH?0 BpL+<۶Q -k׾XhɩWp#uG$lXi.p!ħV4]v61>X$ ɉU9 aDk^Nnߠfid iQ2(Y!N5Uޚ9 wl\苊 e5ձ9 R}\u#Ot+xybMQ>+&=,-5fr sÏܹhB@~/TP'xTT1|Ӷ[]6ZA&[xsc}'bp6}GN (.<MI̵P& 9{TJ^KE5jwdz hX&JΉ(ҴV£q'CP^{Xl:ԑk17()c%R'\͸Y7Cb7L۟~UUω'UOZ$m=qe$,^6Aݔ:F?br#Jӝ5[ Pv_דFo\"`>H4cZߘ&r | So~`IDž3}OLȨEz =SFuZ!&wk6I/t6j:tnRX k+mrXx$iD} 4 ]KiLIJfܷ=uR UFDEV5.ѓA5-ӷjeh&GF@*'~ ӻ`K4ma QiX;MV#hg3=I$XKG~QcGv (c>~q_nNR%29IkvG op8?(uO = "st˄ HyI*9|tRTO+1"gL/%QM (u۷vJ"H/FFbq-4^v IM,Qٶ 觸VSAw&?cK$}ݿcK[w2sil hA9!Őlr6?Ā1%gdWhy3JTŽ~Dh1_UR"cN0 bm23H|#a!/uJu RFs'5"aP/O$G jzFen_ke';H$6Yx ׶PCmcHݨm^@xϯ<kcNKK٠E0j$}thuVMc7D~rT2bUT9 h"lB׸5+?KTfau `Dy@1Џx痴\Ǵ<,)^iv$ރ\ߘp0 m!w(_狦uj.bI]S1RKȥ~5 ㆄvVoOcn!NgcRϵXp{;(>Ȣ%t$PF[+I=(gNgၾvq Tѣed݈-Z+Py?+ HY:EQP)* Ќ zi$fIv;TkUFe7PTQukXa}ut͑^;CpZҴȠ&IƱ'xUF3Ui[x\/0CmDS-|'rE;M3W=iJK3OmKDS\,pŬ_n@3:j>oDƫ,A{[k'6fG=B/ wgEZ@N7 5dpn\S.|~(|Nzl)4; vBZY-gQ } &W{ ay[}3;^|s\̨ᇰBS]3'ul4ƹR;Z-*W)NMgƣ(8BP9=pטS0{C=_ic}ntKRfdbI:xRy{ٞyEG~9|ŏ i~H9RpVdlXg˥7|ʫ'zf|wte/$Ql.i3z<_U݁o.55 Ei ^w/at?wVZ*Ю4xfA#郉Ú-(SŅ{(~t8Ezf'{ 9䢨> 3DqUAPf^\1樬fA)7' Sb+U5zL[g0sk`@%˛4'4n9W;pBޚbOg" Ţ7jD.+ ?_WG.S ݃7LEHË*r[)x}󛶬ey5KO̧{qwу%H`xWE+ټgeSgO řA`'~at+qr]OnZb $l{:A~{}XԮ-$SUt݌%6KPn6+C/LW.R$h/qMi`2b]MXZڅQWZ|Xy(XG`jߕ̉Wܓ}E{I`ZtL*D(;!5IcԜW0D["zP=h}x3):U\?s$DE*NKp%M ۽uw =7wъR5RR4{&2 m m7 !%m|lO sV>%VY@g8c渄b<& %2Ou\NjY// @|@ ߋ-%]cqJ8;;mL[3UO'3rtL|]ߝlC; `Ơ_[9%SmXL-yd AD-SZqE~ n}k˰'qawXjHH βS`Էc"@Ƽ)wnj1z^ZQ!J jaku}IhKG1i٣[xFU+C@Uc< ""c;Ewim_ uKBAۛ盶 P 6p% N80qu (ث5 `/X,TȊFB%5.Y iOfֈ/`(6 H?7!B j9=}8;n/ԫcdV'L7[$,*E{ڦ"v@_p2Q1\bA/ژ;Z'L> mZ˸9!_HLe5Vh '/4јIbwgH-#:˝Qo5@)L7hG9SfW[3M2޾Nu鸊ѝ|[k9}~)k.FBrPγFꐻ[}Uӌ[o d b}LzƢ( /8nP0K~LPP$iQ!4k%9TnAÔ}~~}*2Ex4܏1G (Ï1 +cs oaa '}"R˼YD~YJ~2 o#;˧ay#7 (hҗ 5H֣/es6#>7j︿]` uJ}Wwq%|*եv|pWֳ.MF T^(6,7:5#%"PhBRf"IE׾ڴE4T=!Yy0FMJ6}ȈE".~4Ibe\~ A}mnZN̳|Pq-j4H]MH& uBU}lmltI4ROD~ Tt߫" EkGD H3Yj샲i"H6ڄ/)**!E4jlrB+SdG9w_  _{<3#Խȭ` RO5("ǟx_ :s SyQ cTCeX6ٝwF/ g>YP"jem칟N_kҘǜs;DX[õ;m RSˊb~L}-ty-07YPYU miՖT gad|Q1)Af>|Ǖ,ٽLkսpbl=$5Y *'刐51jxi+vQmqsgҟQ1VZ *wI#oHqSF{qgm%U._?HGzO[jډ/NiiU"cfq55DgF")v?-z2Asj@c X^ QZYXX/w/<Y2}ѡeQ(MEWXi'[\-.d5t:VZF/_&)6hI pu ϼx.<S1~MSo_紾f` N{eRxůPSAkүH~/l +b&/ qC Xa)&ۯJl,W}Vh +H&?m$#]嵋^n}^oWk7x 5e(@q gf+O!\&۳RU#Qv Z˿֓L|EUs)7 'G᠎.)ɻnKa^N%zZ_)w%I "ܱ;Yk-P\tz #`G&Z39* }D<)jb^$z>+wQ/?tC(OO~[c~IWmJ^͈C=1@ʁ^O%{,'5N=^'dcTNEU@1I:ޤ$4!,(, 2Cÿ%nS([jGJdO;%*Ma ǥ\ًP )IǦÃV/[|NS%ȼA>\!(fNB` L&(iF/]I@| S2qjNTEc u#jI%K5];gL!&Qxh}B/{ gq¦s^R|ӘYivjU׌HV IKTw=\Iց}Keu-._f b9\'ArfMW-p䒂Lҝ1C.(:|蹌$'pf\ M!8{у/v/>-ſvpŴLfWgA=e@a熧KrD%Gr,#Wq2J'p ]LC-CxtaK$ݕq8=ĴZa|H1®_Ӻf𢀷j=^ *r;pD ,lnPl%!Zصһ|V@(fB0,."nҟ&b!Xϝz1h0܅-{Zɯ;eEv =BS\[[eN.L%?՛p*S5RAoWee/pyBRprVH Z@p-NEnB%LNeZntk /Ҽdr[lnYOr{rTp)ZƪibZ=NojO.HѷfHD!fAi&m;*vV|.ޭ G-rL:y/A,}uצRK=Q)Y\ÞXR'jbBxB\݆%V2 'c>"d͠v,ݿ& bڲߦV{pr $)fw!uKx$HinU=aeh1"m Jqwsy+ X֨$!x)s7(S3lPWR;p ]&Ri {rŦWkn^΀̖ !yUE&ZfM?w1I'FY.UyJɁ8_I@ae>xcx`P). K[(13&1.֙yW$5:\.D5eۏ W]&KYE( <ҥK>IEY?܃OzݱR^9Z<e{sf'Oπ9b0$k-߷ܝ4p]q@ftwޢ+ûqa_L?iF;cZٔu 9؜= %F.G[)Qg(6?3Wal~ sʣ+h .UFy z0JG;]LMU :0lǖ๽ey;g?qV>ErBe@g x4 N+!<3G5֪X4Გz|nd44}K\isz<M%7}6PHz/ZO'(M ~6"8*)ᘕxiŊC5FJ hPԟnt;"A Uc 훗P!]\trC :Y2qNr.TA%H&ۗGy6)1FZDgE䯡GnTYQEs +#;qʰ0e'=,KIVl>g6{s`)!U94^|nJ _#;2U3f0Fw&)N- 4U&<W#Oh1O@ƥ;YyO!V+*5%<{QT.j=*vsʥV:m -@PT1rkjJeWKyI wҔd&3}Ļݍh]cq\k7I #ԣkfd=Db7Oec4|}цw$) gJ12pw;@oF&L$;*#<)Ei1K-$4 خlκT/v cGquREBf$:£tzU8*UȡvqQfCLJj4jmۚ~Ɯ m*"UMQ/2zJbplDK(9[BQ`ggn ejZi6Jj]4eSL-~ eMӄ7q.!((iYx".پ,C ` kr.5CD5SD*:ZF"Un{k\(0pÝK QY<{Z(KDlP?%DdAHY[͐Rt/X*aQ队p]x%]5z&gpRn>3L92. O[ |h`!q JM<'8!4wIq~% Hμe_cuT )'%`zTx01^ԋg{ρ$$}Z_#3`:SCQѿ4df)u֠ŮR4Dս)c !?G Hgh1-!$pghƬ  Nom'$ R׶cR~SwKQc}X.ʿ/i1fYK~9z2Tp, =0-Ng! 3,2g2FxwۘNcz2А8F݈nxiF 2 &!j2 \РN F!N'$0!4뗔ݕ},m?u#*?nhI {H.GyM@@P{8[Hgl =/e1&k+0 vZ-&&r,m &H{} P[oб54ށ~IyR@C&NӪiZc =I$k8P5/ 2 29NA܍:*MReh 4ShlۇP+swsy{iKBL;wyH2+J'\Ć4ȮBO&'۔vOFщ`c4,UD}9 w"$#> yt_3 YL;foNF"}sR aXpZ?謰o'NENJ7eS権lePx8dnrhvxqI ڈ](*֢p`1# oߒ.i.G1/i܁R=bj,f#r0ⓐ*}LŨ1O)ïA&d*!04'/SH>Ы&pB(;'8g^ELU!'=Y 9έ9Ɨ!v%sSGa "fg@ek-s.ʄwvBtc\t"xI9.-CVJQ\p%.VN1X ΒS2J ["6 ٖNBó.{/>J_Xϳxrg&L(XpKbyn$XuHS%DɢYߓPj0;'Bl SQ[gJ2c+$X>R­{bl54<[뜃wA\Pa۴Ń÷'?[aj$OE !)yC:լ`AHP+^{p A_~0l L޿ydž-(?rRt$?qPW+3 #vZ7{^p%JB Ӑ%2D`hڎWƔYeNxŪBBp7H"D\M6n_Yya7RUIKX83VE/nv 9?S~j\T+o"bA&MB6VAZf?:4mMwO*}h:e?4^(vjN~ǵ#=K3K=w("nQFWhf/ϮU t׭w% ٥0ZkR>!ܣ鑲l:YS yc8 &BTЧq L45[GO~?q,s'9dMA*`ٓsUO& =;D֭pJn`TI8$DX"3?@iJbd6z GH\4TT2۶";O u2ȸZe=/P7 ?Ć*]ATӜof]>BY-6)mn_?Mnf~MhA_GB)t8#flT"W*3iB&ON |Ӑ)͚lw3,>x"z$GʭC;KSdN@WGI^;i[z܎ M΄F*o)ְ$%]17m5# o4T]8|6`;e'% Ll'G 3_vl kWJJ@9v:*Iޖ?!.8|F6L=KYX;&7+BP₀4L,nhetGD.8]l#s:Znօ;faKASvG{{#M 8KC |9t>|\l=O 8nDT زIn>ݸtNw G1k:v0"72hZׅj:ɘB3ҮUf(ȧ^c\lxQ+:l;gUu'h>_S}$<1mu _jK~cPD7\zI$d/dpПH (n:uGXv@bk: YJ%3<=&14upnμ}#N3#AGS%)V| &r"&7aGj:7f_ @J7p& 4;㖝kyj(1sA^gGy"cHG]5.^ IP|%4 m(;*~n3LQVx5 mΙo-Jx{AC uE_Pت蚈{h"l$3=9f;#*͒8[SIMzn6`w'm:,b1|_yc,X b{{>ud\raÖeǹ8- ϣ^5Fvp/8 qZo(o;piԹycT.K%ĠPD)of P_nui&US}L㹱 sH}/d<3]N(H+:%'0wHaU8FR GcNN[|kH O/Ռ)/ 'Bn(?S"?%R@R 7: 3N$\1/ ҉*nMb)\?׏ ^:]%u\*g lL jPB̝@)D-(nAWб,4y/s]~ON/~RMwG2!QNRVZ< H/rޱ& MT U<ɻ4%$38^ gUa4|d;0J@617~io?S p&>*_}S/ט8/|'N0V ٷ*kSYB`(u~3Wefvcu!ঔuz}K7cFߩg^`T:?@n4cRq]h/a3(nd~v+>@PhWHxJbr 6} ފU;0yj|fv1c)4G1_ŪrR&㼧J=H) /3*ˉIMZU,TԷH\63 &+swGg0@z=ndG:=9WWVmP.3o *Fpuϸed&eVXqGBDplW:nӊEt9xGԫ BԙPEZMsm)bC^?a?o k(V]s2l6z6 `ꈕWńJ4 _DZpT*j^t,_0vj:J.EsIc"̪KqcVQGsz,䪔ۣE+v"ƴmgSn; DKX$M%(WR# ͠?fT()} (BHG/ElܙyYj|.?CA W[ZF4SwK.6`7ggKaBk"S ӅC6BÂ{s} a$;Fak n2[`㺿lJj hBJhtrsZA!YR}<'( }y3rZG&5쁈X|A8'mj>j!me?˞AL?wdb0]|Y>jrCK4-S8Ċ z+J'9 ~i €&x89Ŕ@RwhŊc^A#nzl*8~LHu1/qd?*$4 Hr2PF#KduE=ALshoUC9Dy|Cݩŗ6iO߈#.-q,K"+ w3Ca/,sBCNKhqgn0?`gJ>K!0֊2$ɴk+&8ĤnjGT:$"Z 45wi})Lh6 ͳMH9afv4%r7aUw6^@w3Qi!UX8;.&Oa0֥ 2ԣs> KZ dU;vߟS} T9W'Q0h7mg߷=xgI#XJapIOtFɼ+`IĞ[ E;8c+TWgS_ECQ Oo; ApKe on@W)z6r+Q)3VPaͱ82euB&v6k$4Jgf;Raњ N/+EށQyU<#磳<ʓn Z҆bU0V rFhş7B7b[B V]"R;]:>X#>y6ٓxʅMLQcRQľfh$L3bV }(|-Dqf/_#٬NyHH'O)ni% ;5Ȫʫ: \'}vDq^[:OW]Ux/;4Z@a/QQf+C|;y)ŗ=5:KT; ؕWK?DZE%?I`a#Ǐb!Vk^C6l9_u֔y5 Z opQ v:#.^?6{d]Xw~ "G[0ߏjR\genw[VJ>c«cE) $ϋ|jO aڙW`1bg褲Cx%K"Fpr~8ϯ~sn_Lqwv 1Nm05cͶEQ9KmTuەʞ"cejWH:e[?w.B7|ȈPNwb1.vB cGgg1K;x)yXt9 {v5u#j?TBzr_|:Mb*;u竰Pu46~ Znߪf|([؁-$DpaOߐ (y xvH‚ vbXEo\Cbp-]oKk/$S{kM_3*bT|D39ݨTjTu =&A{wT>('T73{ #:o-~ Zcҿ[=I M"j;BvLkPxW/uBu`KJTO!j-Ā4 H#"I(9=V̱ ģ=`Q+9[D&]YUb4Ёu/a7|J}6ci2 2,ЩM zo"q=s3tHǺrt謁CH)ctawKx8X2@zJBRdj*ۚC}v3W}K>,ġI$LQ)lLOa,u~/rvxXULe.]0[N31c{8 ۦXK-y)1 );IEf <Ԩ ܳ/VԼmS /d8ʹw jY=A-ÀC=cX3$rHi@ OhIl12'zj pޑVw)-VWs+bTyVvh]2t&Rcr[s>H›o WEOiE2Oltv ;f< X,--ahw# 7-rTEJ3tO .q{]},G`-*~VrS%hs s1rD=sJ-^?ۘ!^>+% -h |B!Ǚꔺ0tS-7[^ꭤ^l:zm^9K5 TY\ ZJޱ$q4%n6IAjJ94i}HzW)]p5"wl2213ZO-_C ?f3ʘd;"s[BXF,}q>E _0貤 ɁGQɬm+u(|a Te',Q8UUKC&(3V왘bu[e߸R88KHPd4J ៦N)p«Vf7i>3k]JMAx$л%aToBv}"cM>d|kh,Jd}U|ѢC [MHn{`_lstߐwծUP+$"Pn@ObxHԎB9~~ݐ~77]Ɗj2/IsՁ8:Tl@dIbOR%On?¬o(:=d %:lGCхnş647Md]8TF7ڔ$gu]dxd p$pOYSXs; CA s?_RPMu[-sS՚-:xHyFk-͂jټt!p$+@㯋NAO&eD3P 66.Fu%>دΘ6, K("MNRI@R[ybuD($̥RXtGb:d=nJQxJ܈IHSN+V"N<9V&]Ϗj¦-pu5 s'RB>i]KeL t|JDjtWc18h>炉"-%W^Rz?ӓlyz?0$R!t[f\~rAM=7ĠȂP8İoQ.~-Ju^K4O8calwYݰɎⷓC% QfK)]yf^-zY㯒O>?-0E(:`j5\{8pՊS<b:tywŀ\qB/1ބs}):nI{yB ̽tY :ِ>}",]94#! шMe]%kpsѡ溑Cwœ߃Budq`Ž} iM8,ļo$/dX/D2['y ĕYo#6sF7MzĚ%GFyO5R}P xjNJ0mlè\FO&dGӬ sbb\;-9SR}$pD J&עG(Qv<c[v.uc ik*gXl5Z* \'6+l*jﺡNQ܄Gpe0uiN\ j~0PL1uї}[p?[{vCqg|T4\C.x3wTޘF>0T9κpm  #y'|!(zM!@q,#c*Ҭ" DxXo 걲nQ 떖 |.̽b׎#Dx5%2 ~IHS^%|\扣*t!ķ`wFKƮܱa rJ (uΎX޴j"z)fA̜j-kD%8n~:RDcXQ^!@ÃHnG*ʾqt Rh# (d'7`kKѡoX/BVAOV}<lm? D[~N0);9aUB-n˚#&{Ujw7d>E8p؛f2#̲w 硫yrŘ#YFb,K!]' ;0AJ$+vk஗+8TchC\faG1.sqdQᆲXU+/rhАM`ORmpmd tֻ0Ѻ @Tc:#q-9#cUݯ@KA.=J!P#j)x_SFp!vyxE+!rެ^Y*Ѧ_@Gp7QVmOI)^pF & 2*mYp% `!s(F[\6EjCĜ6}KETZہc]TE/dj gR '^=BAQmGKP-%QiI{Z@*1s޹u!,뿒'WRt㊦vHݿG`9A1`o/U(&eL\Kurz%7y2{T*ߤYVVEWdBKVpG(ҦrVg,dtQ,qJ9Nkl`ΰğO6rC0Qƒ(%G?l8R_@lnlJ7${Gpݶh.;O T{UEVgBɝju.w9Ħ͊-e61M2SnO{^?O5_L$,&At;xrBCc`+A `Z=kiOml5B.ho0N7x>H޴[s>4]Fd=v%&l#s9%7/d|z1Ӏ뿋@L Ehsħ_?WV%>;*\w5[ <mr8cdK9;ο9-ېIn g8$g[n \J.^x&3Q_h({o*niGZM(`[;BiΚ9CE b9O\iy s _ml;A.cߪ!5-ݛRٓ8WB PTŴ8Ĩ='ن3F ]vj+R5d  $G ҋIFf䂋BB'a! j | GX ;{hWAY=еxfUCu8!B@+i0J5zzĨE UKgT_`XCB#Z_bKw6ir>`ap֟z2oVGX v۸~(VxaT72 {+P:˥2[XԆȚq<(PѻZ덮Ʈjs>8"XoOkͼ\- pVM6PVA3iؖVn`p?a<6z*)C 간cu;PნaLxc$_G+"a 5c;QG r?C{\l3Nia xr5[|؍| ^gk^AfFіj ϡ܂L< Dz[Ӷo )4jxraa 2P݅¢ ۥE_y5jӉй{+CߚFM5],~fbk lIMc"s)i1ƞ<*OV#jLxD6i}0LٸAq >67_X͜[ _tkPm{EP'GYCDEJR\Go@9̷U,d"j@)uWbCuR6ZquC-+& T' v@i%川bb"(%b-2 뻽,J_:h`7H'$ũȈak$liW\z۞hB %J/eu_h(y?g*B7FR ~п/̛p*a |O0h{$vta P ")դ]?B.8ҥq@6M!/F4FHpk۶@HX^Ù=ZZ3VwHL D :`v&%>tO|z|Q.:\ NEiBxhծaSR]XdZy]v!@,4oo}9mh({'ݴC|VR;[\xk f!h&ghs9KM(Һ_ҳn:9 |]ݲR_SUHgj!n82 ءz䑒;ưpR1l#Lʾa=hqj>^[+i- 蝒wMgjx䍼ծYYY S왩HmQ柈dl2J4De5wl=߭`ļ8@cMio-zU;{!w=rD] iU)bhy6➪#KIsSqXOv _2̫aݭL&vߑ4OLLǏD.OA.GӏߝާVveb8le{zOk9X x!/P9z SRֿC9eߡYY*>gktAOEvJ.q-bUEf-H.c㯋e&幧2&o:>ǀ=9 B䟐1=*WDTR7k񆁤ѤbL3 :OĺT?ԥ? J&bu><{8ӸZǎ˨ŁM)3uaٱi/:  i{GG$ܭWϫߕtg2" R?*O@ cM/$-nJh!*qG5q]3:hKrЂ]?qj _:*10F'AJ?&)P;&:[a[ I NG|9\9u+yKt[s@ T)Xwe_W;2t) Wܡ hak"R,c>eȄKfi+Q4<tc¡LwhnďfKpl.>W1Gƪ?4i*7Aи(\NQ=PW;k:F-(oPx_lvӔC"$:]Os`1meKBO"*SmP"]&8Yl^3u, &g75 9usv(ǤxqfX_e_w^֢Ʉ9bn @`p^IVP-^K*hx4aՈ쪳~9fTqu_/`cˑHLe̩KM/ݼ>ۨDPc#-`ݹN@ROGy͜bJvʤ'b>IW&L%E`QS*={-Vp-& X(lB) Y]ҫ]cNM7zS'B!ȒŞ> /5R»&AQiߣ; $4#?Dzj*8M"YeTށվҮZ4do)*}@"AV;%Ad eXePL\]E[nICT/RǩxTE Fzf{Ͽ/#QE X*ѡcɔ6:W.નt˜k efQ:Pqno5vǺ۽${ɛ<DRrWϠQ)m"B*'0x.ҏk68!#yKv&ホoI!p MS IgA c{D:-)egk=Z}_ U?i.}>K{J;M]ͮO v겈 E9>Ƹ}&n?l{E*2rLeZ%UfgVd,ϞɆg5Qa )!d]ۨd+cO@{sq%aA^vD<3djZ- ީf@\.`֓9/p -K6Lek oVFפ"ڑ*=Jƍ50_& &w){GN ;k51~Jְc7L @sQ2ˮQ'S8|ӗSIO,%!ޯ9fKfU> `N> \mDBDYj EĎnWS2^l /@U>FmkKq"ol!m8DbH!2)fw&I9"EJ07F֙%W3lC9Ӽ51 Gc0X {۝й̺LiR͉T瓥UGۋd"!Fi*-/ǕKCc caF>W`A2zO rPQC]z|W3}j[5[ X&6 =t/痖m}= >\_PU{(K%7/<&,^F8ǓxWdz{#iE8fE1sFrH)"L̘vhV;`Z\mMOE{ ]ڼ?=U00vqiA{sS떷u2tGrYhjzz[G,,q.c^I/ODp.0>J3G[Zt 5aTƐb_C @I b_؀?SEްDM$Bx-ה`VzxU/Ú/-+/qd_}{9tTLhSLq2MoPĽɄ};s4,)aiN?xF+3b)O,K:m9uloXHUB:CEfV4 O^lx1vdvuы[X!OQ䁾F?0vw28u˴3 wq挜QpT# uqyB9M?h,H '?C/jv.^.d=ԏxf[=T%_wmꄟuJɠ] Z޽~ /wQ5E)N < CRvha7[o,$c&hG&XL쁦Gf OHD1$J$zq{UÁRx·uxBN ̤'>Vc`U7ւܻOp;7%MkV{ zTʯ{- Cv'N_ڇ#FoR|rEXȗ8NmSЫQd:H /̷L=h%*(&hd5cChՠ 8oOJEŰbZ ds XuzLH܌E$e_0ugߗԵa@R skZNçkG<Ñ0Nί1v so3.D;1q #O#,9}_9M7c轷q\JVHFBB[ZAGhaEȑùDHsQߛy ;p"uH B'r3!UR)'8"* | 7U=F(WtLNG6Br3 ~`&Tatβ]j{]: _k=)e%^@M9U֞r+Ee}^ r ^o.53ʝHuX^\ ybׯH׷b?}s/=]NB/\'c"m i7òj W3-x"t:Ґ2YÒycN*IV[7gh|zW-ӿ'QȢ~/#E:`;:shΜL߼2ၥLLjPxWoh $ EmׅͿ*gg(Y141R_ M˗ިs5GQuUo39ߖpQPO?8}fM[=3K$IAuI9G?t][c.],2u@n&KK}TG˨qUD*/WjFA\DI8Uq{>XL.ỌMݓ, Ox/(,jB[I5 yt[rSCA]n:Z'b546L8l/í-㍮"Bm^&_wҐg~v|U>׊EDu5+$^Zl IDu$XLD [7+5u؆353њ$V XnS!y crYl ]WpvI&?d Bi ?t9aLbP%R1JgA7kV?hxze'{NJg[m+\$Pt39̡ BM_C,=}hQZj)²;7|W)BW4MCךgHÒ36ij (뢸[)=>4;}`m/ -U22&x;%28\^SMo}K J$qcDMqܝe~2?=/,0XGAGjn+- ދL}UtZ{hCHnI 0𰌻ʕFt 7vT'IaGRy_,-+64zA3{¿hޭ˗YWԩP]4Iu"pYMxl+΂`*}2uD<.~Q]KU*(1: &dBUa`Cz13(dg $0DzM`D5vC?β8痊R.nKb)lg|ng|0H#?s/Y#ٜ;jטq.R6C'IN_ * xzx >?gu@|uƑ_& }qIHnߕ5 ҜZO/L'],۾[r$JAI<ŢZnLF i&NU`!?-oz'1k}'C $Y-v@npgou9tQ)dڷ!C6CNniXa,;-CSS6MO< 1w|Eb.ܡ+/z;Xŧ}h.!>5|ả$5Gѵw84 !6#[sPc8Ϊ~ g9$Fejĩ:~w9IďZmFۈ](~zd3d>b7QA<>]kX7 ^]akjgYE.˥MLLӺ%<~ %}d]e)Wp Mu\g\þ qQ #;3{4mZaϠY_P$ 5;_p tD%(W؄ʜ#(G$HY2Y@.g lXA~,UM$0ӔzWKC@1^2 1:p^G梫ys+=tgI/60߶Ȑd%O 7FPwZaʬpxi9K6: Y_#ԛI@@.ד^@ܚJ$)[?Sgעɔ?4¢5){a )i̞g-FX9*+zw]UdlɆ|^cADd&<1O61x>EɯnLqVMe`&I]CRvA]V°*)G꫕[q.6z Z ߊfʶb8_rAKUYg-wb/'Gc+>w,h+y2,˹"PY@2;e@"j b{I׍R[ʂWutb5Xdt#poltiyWee|h_Kp&.97w05Rb&*0şՁ'-?()x$G\UԢ-ap S)S cDGvj"c*"qwb& )T!AK Aсՠ pYbHJi_ }D!B|ߩWs'?+%yEȗoa[0(@=5+b͵JE&F.S>/u"Qv/;QfG-"̑Qd7xC;ݼTY EW)*Z K8th]7BԎ 7J{ Lau=2D,ΐ Kn9}d;8JozBCLYdp,,DFS۲ _[;z%7ưW/db=u, [Yu\ +T!q礨IC[ ]Sf |m X:OVR267byY@kBzΝ_^D)Ļ"ZX<6Wq?qTaxSzF'n{#fV$o3SPylEO@ye3%' |Fd C\=P7}7IJ; A$׽&oP3,zCη1PQ`, Tz4U8h $0 }o). *鵍 {n[%*#׀G)XVƸ@g>4 gR!]*+g/t&L;N; 9ɭȱd˼\WYBVE./s˄'&BǭTdTA>>BT-UÂi'_ x@1àY ]杔Ͽ\ū]a%y ^( zlʙ|N#`WVFǀv(k  Q󵲩\yYNY6hX/Ù[R{˞V<7}?m2w0N0׹V(}gYP+r?]RuV_Ӱ"}(W+R-}Ah\ـ zКn3<93_K{PY]7t@M2WUt6/GYh HԌq[jE$HA07w8 $ݷ-=$5ނVbZ&&vHӂc3gLnrq|ڸᅐhbtoWQhX(@6#C;?4=[% zdH;]1 ?>, O^bGI"U,lMz;ب=jF`:ktІS/kݟsAk}܏\Xϙkx 1q(&d4A?[b AV@JD.μξ@mn~<ﹼKd$(ڌ]u0m+P4.' maLD38[i J~4]~ f NlK+G Z|:ѓY4D01^ڭayتr[떗ZƤ㹦:+C3G/X!eI%mn?| L*4o7ϙU($s;q szJu IFrld$iT聫pQkʴ"\a*mޒ[]*k 4PVl=e-kQp3 ~69^.t=NgF5nrV7Xn4+Y}W<%<\k%UP}}i2F1)OWȆ^ 猔E.G8O.V]7$_rȞXFFm;eHr譧.n 71ˆuH0kC]d>ɵ"Ymhm3vVi["{ߌU`U>tΩmʄ/6c_g ] NJgs/K+Uh2l]v,b3LM_d_S><3]*(blfVA 5SSbcش\ʹ~wѽʆ(ր|6~?L1MMH&<ЎCԸ=Unp( 5O_w]2hnR_P(*T2hss#tp oVaY9K]/?t璿 IYFbAb{ʐ!b_o(e0gޫ**p\G8l:Z1}Qu[P:3Q]AXzLO$Ja/ pƆ -5ѳMʸbouZqgצc,36NG!]T`Ux $yfikGd&Q7].p޴on\ZVjy@w`"0'K 9_?rnyڲeհ=9LCj4Ut84J`VĦ_ƥ=#Ty2AGgl"W>ӢOuMP׏2anZgW{}}аC(;4zȢVjm}A!:1'z _rYΠ<l _\~@5f,14 ^-]38 uxH kHFvH X$LWyګ2V 'ە .|s3 /aWvKW)ՁqG$_"!p-8@~qQ 1FC6jV(]DJ%&DoHսT!1)?U1 ER},:W_j`3X&@ 槊F"$Om ~CdG)?AI97T@?9B-rr[jѸT?I% ]-{;_}]S._;@P d8\OEp^9Jᘘ O'u@LrQyF¬˿ @6P֗yy94q:ԁHK}"w.VzeBK) n݌ݮ~x(DU0o}*ᣨQ*66k]o//E|fq4(h*.o+ fzruɗmUSIe ia1bQ#SN.'6.Hy967R>;8eoCh8HG]}oWLm JdORDiEUzA%̍}&D>"G g <х9M\ю2l5']ؗ)TD )ŌwиM!3v7Yb7T}VV9#409Z1. oVGh6Rߜ 7CyKuc*Ĥ2Y /.ZGO)S'Z..WzxMS6:6)/VvlȯO8{(CTx>p%U(}Fb`mQf#)"Q&iݎ]AH#N' dnc2x,~>@rxZ\_Z݅m3 dv<־yASrɏ7e(Oz7ngf27ښhU`QI+NC .Sl2:N6!_΅a'] 3mVXcqFef&. b=\h:%z0WwL ڑ  cIBQ"=1*9=}.E0'!{SHdɜ6_Q](3OיO^ڡʝH+Ցb)h KȪɃUR3t: ,5/ܗV~!u a8ÍZ76{il锫'?HtO̔6 L8ok`ڻU2P; w+T`} P}K A×x"_O8i m5b YqJ|4m_|5v]9/.z (2G֪{dBJ TևUgwn|l U7jRb?-;_ᧇ2VtܾvGDm"=UZ*J :G}K(ҡ4Anx4mBFuRoa$ǝ묹PlI&v;l'&ΈB`+1eWhKjGeZrQ 1KXx-.!w>7W>T[x܄^Ƿc~Sy9Tr|)uN$PlLGv]~!F9oֆdkVx`>fkkЃ.qIf;+mPC;4/Fi٫*B7EM.@tY^_Wo}_; cѦ0u;kNo l /,A:A)Vh]Vha x GöROEEƪ0XdP5X)WmYW1OqcJsf1+ Lu*kG^z9VO1>ωߔJ8?.&1& U.r6vA $Z󿂤Ai&ago`< *3~·4\WxaG*@{JMPT\sCSIߔ5J Xl7Qfׅ=R^됕 2wDp=֠D/Q@{!dc(eb.Mr֭Ɠ#k]tDk=y@x6p ZU*zU̗wţtCx)pB7q I>>;ѕW`j᳟RddՅ-J\Vc*<(JBBk#d Ttpˮ*Dg$nHO BQLjjhD+FiSM\KWyWӦo a(PTzQu3WO #uo $/,>HAT-UNP#PYk=?4.u/ _4) 4腱·J.F?hP y*ؙ$L:!S:K]] WB!fXv%yP,5!3jU|mRzŋ|ȇn|9|XX)7/ȋ< J;R荻hg$$ _mqX{R*Yԧ$D%#NOk15԰)-V7WӠx؃nG4l_tϯ?0 EB!D&V_k+YeR N4S'd[I6(WXap`Mp§* a㣾7?ybީq(${(8{9Q9$Hf+*Y+(xsmq*WuR<~u/MY*ʐ2͚R'1.?H6hԤeD$ێ`uFrPˈ+T+<`%n^a4Ƒ}_: fޖ:Ž\`eu&1P'Mȃ5vͦ@+{z?ҺZ:M1fTwdL2 v;^~ss˯؊zk\&nNav>s׾:.EFW<P>h7 \PZ7L;P"7 z }D Cd/W;HF7ۥ(Z 'n%XMϸFSD>f$)ԁZ|#w'Jtڍ7~\TG~&XQ3KǤītȢeUBAarϑȑhX:(ti5.# Jy19Oj5vwKqgb[VhQ/hIZg|=̔y f$\6(jϞyӕ3"X{=kjw 3\,ON@3_#4ڙPJH$iP5[im`  xXJ2 {6i >9Qf`E3^lL9K"~ IN`#Un>h Ֆ&ÈȪύLVz[|q/^Z`t/3UDIsN?a8:c+(gyDž_UZL5*^m٢  CwjjĮP9ўP$zFvjU Vf@?^@5Ry#'1Cie= \TAOϠlsH*@%A6KP>>TtedpXGP2#%J?L;s$mLgygҨIчX 6_l?@kdZ)qNuDjL)M<.:/]j)QâG30AO.:dzֵQ_9y 0wӤ8W#p`'s-6UDzyQtA 4Ѣ);E `t%5)Ze&G͕'1+w;kxCz4~\|X6Ea0LƝA}ͯ$eSܨkÔu 3GgƤ{zNl:QHh8Ǒz ǶG9So/OtrVd.hE>b~T[U/e&R^[>oT%xŜb4ȫ IQ^4 ZHtU^\E!c-·i{j~Wp#5 G$fCH3KMg~LkB8hֳ*)5tfkA]F/id(!{L`IY>H&a5cY*]ʬ*?<~/&q=<38E+s3zfQ5p(Ya@B@N] IMitNm]μ)T̾p<ϥ|5R Ęw@JZ)sÒ=R爩O5!J[ff@V&6(b$hϝӬb1mf c .4`'ͱ8[V.ub-^^[:6xZi#@u9MF)樲G{E{/[tHYui\7TD\Y2kZx?3X,*dHd7;v;Oa5_ ߹ b}mMOj=JvM é$a:(R:`BOEJ#`8$UHc YO3I$~Npډ1t" `beMس?-n Hٲ9@-Tk+W'sۖs'&l(YADy5dq?ɋ!ՃRQhc]} I3k㰏8XEPn`U^p PFSq$/UXV ~DĎl:Vm2(ճa0o#|yL9_8"|:wHHL\ʬ)׳R{g+V/SmtP;~&^5'E6珂 {2?h3)d%f =ȯ`9`@q\9rzbQÕ4BpB9WL愓)D"6qNH/}zp{@lLse·> (${^Z]ot :v=7'H%ڑ%mL\b{ݯ >P38BǢneZ~#3nhFtU3D A/&N] 8 r8bҢhq%  4?3V(4AI@@o4;x¤jsx 7"뫼U"Hؿ $eTEMM8p2%/&"IX 8f mBv Sl[+[̓q14Eֱ) &ve0Q>?S+ QkpͼBkTSzwMA{3У5GxIR0AU%3r~Џǁ<,-& hگpvm+aF?( i^Pbk}rA Ie ݛco `}I*%)?j[Jh(6/~0/ C Ö)IzJH{Bޏz/0exIAț-ť!2TɄ:p;P+TO;@r/78[3{N#w;*ޠ(e?gl3Y)/23L{duZVf=2$֪p>9|c%(Ra0fGRa HUjԊ!=dh1AMy_W=!!9*O:()AW\ $^ 'ͪs/X`}Kd]&rǶo&fS 8uV`ۿo$ C6WD"u*KD=مo$N9Uylp-Nn f0_,^.<7!6X9rU/tR:SQ o?FCп.R7quط4Ve BiEa!+{i7p%NiM1v{F`جVrI~FM.(ӌ&0ƛD2W˴ӟrcS_4hnoǩKCMF3|LB/h]uZX`0)Zx*4+tcJwU:=yD3maqی zk? wCU-Ipj?Z5o?Wgɛ  Uv2<&)XB@]&-7M8P-N(ݸPqxobIh$_k,Ɩ u(>6P%!CO(WK,µKZR* "s"~tE#1p)g3qdhN8Nt:zԳ?qgD)D[l e<&`?Pnq  /)qi NίD}F~]Z0|cR|4ElmiKzT&'@\{ճrQڠc-yUUGӡHQeZ/.Y}FJk}D0xLIe 6Ey=las(Lܱ3 z( sP2nsFέKqHS6Fho)V2}Iv{2=!}}&U' 6ɘIlJ 6lT1<@9)H$nk$4vQ(-LÆM3?ڨHiNot`ЙD=i)JWJMX][HD~* K1 Hwfz2J*dx.x᭶'cj3l{ճ|)7Jr+ G6@h8`S~'㺠7Y%tP{'/9r@r|y ֭ zG2$30䠅C)?xoĜ\J1~uI K w%(ykc<|X,ֈ2i^YrEj\(C7(TM`%"bN|dH7?c|ұ>0B#]aĨgznZ]3T<ݿQ(\?F'oA|fA!Wo(L0;Ȯb&4FfiTu1Q!ݨ3瘢+О[(-K_ s:lid0bR$ej3/syI}8qɢyKV3Y<:0dig0,s>ZW<)=RݴKI&@{U1wg'PXցE~{P%`JgmC D~c @qg؈izG5Wܤ "'?`ӣꖴpEۛL6AΦ_Gc*N7FzFY'PX.pop*yЀG(#A:tj91zL_8:%~2ӣmI1LCML3M}BlZoqz)I 0Y̓eDvv@H/1 y@/@b ⑑-TKv:snT$5ٴ@t&7wQ?}w6? 3ZJզjW-N!~jS91vț2w&v!Ͱmmw5k  4-X "= و/(okNv^3QhCCfov]+]^Nޅ*.?436EĶΫ"ΟdHvUXVc hgjs!bG:ɡ%_gŕ :_`G )Iz S ތv2 MĠ[0@1pN1%N-l@?st53Բ?\cc]hgu|ugTЭy_Af7 ^L*} *K;M -k/⋀RDuRl }~Sѡ$ܥf6-epozߕC[ v_xY \u1Sԭ{$t'V6E`LsD݃WM >Y@3^08'n bdʭw 0;q>r CBƺŴ̍Oɮ03 x$I]̣zy.BX.}v\A|h fBs:iȑ4 *:B*eGRyr:5 kh=KEsl&>l+pQ>P UL3 n sMR1b#49-S"hDQ_g'RboaEOZ%_lja&*4Iwȴ"<:#d̽j‡("tNqr gX$ QNv!}q@G<㇊la[4j4*vR O"n)l̸,77"(pIS an׺$TCy \w:] W"ܓw{R2=Ds|/sF{Em@j@q24H,XVs`Z5lhĔ0)t4QOv[a[g+0ъ>[FEB@yIV <¡C1|+ ]Xw^*9qûRs֔`VbxkιԌ,P] Js61ca ^W;ٕl^& 9d HF4 .!up#H -[5sD9@]Zm9&:ڬWs"(O$Cd({S#*gٯ84Ct33ӹ)"Ѯk›m=%B)D.S:ڔ!joC9o\^"-uFI >t)Qg"x=a5{nMKp92@@DY~JͤTSeҹ1;M00Fq.H-^ʁߌ v)Bc+Zwt=21;\ "7'[ }n"EʿoWw~(K %UI^7q/'ՈMkbU"QCN|AEƙl|3WA^ ݃"Xݭ. -<=*"}d9%ikLJ:|sQ>si=YOС||:պ ۬UX-尥j X  `Yh> RV߽#K0 HZ2>`鰝xZE1yWȨq jd1+qW)Ը`"='㛴VLRL,J rx`nn[_X$-ًQ 9 @OJe 1uxt[fީ.oqEM++DDkC q7?QY/(~fׁ2>VmH5Xɺ %q1pFqA2$ ru mCimYXe5I:dY?KfzL-JM,K i2 uBLIi V\M0 -*H<ɠ1FӡR|: -D;-@ͩl[? m…e7RvPc^ne1 BcM{X0R*@.ceGqx☹y%ZXÛ1]bfC?^jM;\j,6bf}CT7;+S-> hJ?xxڊx}g)P(Z?AU̾Ђuv7ʖ[gVȑF.g@(/Ttߚ(22MezJl/O^w3`-v`X4j7DT+Kmt@L|Ь*S-ԥ`؆Sn:PFWiFEid,"ƓPvJ4چsVM`+Wz.Ɯ/]g+);5{cH{vި`zTE/@  3I2, Bhi̥Bi& 8#]ݻр=JH'gn7HD\+t6ήvG)H[pڬK"KFЖ弭ɂÝ: J#1.$zNqbI$Pg 5[Cj7C-X"߾w vxAoWaUT)Ƈ6xST% _ޡSf(LG-ڏ.s'Fa PgOz =7T'Y 3% sUd&{ cwUM/.OX&t-;-(\5zmp&B3ڠ/IQU&RI)ǦEZaYNeYw.BCUxkNXRAc(:?=;ZWY+|y^u]೧B%qCh*GV54:YۿL9 OGd*cj3(p,TA)Hyb`+p5> ANMWB^sR /Kp|z8TE3.)Alo!^ݱ; 8ޑ_lJU%e(,R>4ȴP'@<=(BG[Hl~Ϟ hO]E~VQ'ythL*eed;!' {X*TR[i ]RFֵr򹸥7_|]"Ȟk[ѹ so"V7ד<(Jם?)&>h>Q 0xֹX>+8)SM˼)1i8hr ) mt_gU*066 ҉X*Rv)jq T3X5pgX㪃wBi 282wmXZ ;jv9b௞RT{ J\~lxT߅7 ;㲘^ѝ_L{!Cz`p \| ʘ>Pf޵ x c15z:|#>P9¸2{uW~ڽm{R\ƸN3dJ_qh*/(X8=ؗY~0Ӫ~MmqP6Qr+`xỲJ Z a3xOuО'2Y|2ȑ¤I6(sҀm[T|zH|(pawRj J=f JC cm-R#A~鵵eaE9s+aMY79I`X4 XtGϥ~ƌOWyȝc]c7^.Vgn[݅ LP8-%fvf%lh!؂W!vsk( OWdSbG—(i$^JxzGи츧n:@cT( fN# W@Sa|- C5K^aY c3&Qw~Yx_ryVKHN[sQTkƶLITكx qنa };ڻQI~k8?n8o8ݻPJ@| "-Rs;|hgA,]MASؾZbOSV1L KrVbsB-5q_GKN +91{y3*"- ]64U}&PV*,OYy?bJ'@m?Ō2DtF o->ﮍ|\D$,*~џ~NBㅙo+'Ynw‡w_ng}Ącu&|1,b;ZdQY3rM[=W3n;z-@, g,T@Y^YؐFNZ=QpC08(ugA.К'~0|&,B c0< ;<ρY׋NE,ە ?՚wfM)mL"7y_ShMwce[ =DȄNq#4֡Vn vA#2 ?:{M6^k7 مmچ[$HG[hq>HvUSR3w<+ښF]_PT9{LglL,X'ݶjMKdXf>e".4HN+iׂk&Hr( Lne@+8|T5SnUTY U YZ:Coα6k79 Fܿ3F7:T-`$F֭L*Sc

BO7}3%y%^1A#JP&^1 5>W85U:\ap"VwY֙>C٬b|w WORPC#a2U}a+F2tsEW՗i>J3 xC)s~Bqߤ b.=SI2"w>Xe2ϫ2:|k[?poC9 k]pU aQFֹ(o.IS{v^~F0:P~:EXAPh3beXYY(ElR1VƾjYUl 2(?+GEl2!LjQs$ X<%(C:%-p)@Y71m#,ŴE?!^ ̷ ~ qx 1!|Qĉh/8_J\?rjlB#]s\Bo%'!"Z'R@,Xܤ`{Z2;kzKV{^*hZ$÷aԣRwm| $_ũ}~P4K[+%slLbj,*rd$4- ,y5&r03^N,Lk, f%B)=TIFhۙ(˲8-+y ;`W;b e,|Wm\5ΏAفvյ])H_y%Z?b!W[cjtYԥ#k\d'^ÌR^48+4\TPnbWVM!q+-`)J>S'[aA;I/.byĒa%Zr쥻ݣ+Тf?PP,'ܷ79ӶCa3ZXˆ}[4\u!O۬U8 ݷj|P}?MF˦YqY)kM_YsDivu$`y<=xH'#9` O-n~z8%m}BaPQ tA^KJ?v 2/%2^Ylvtc@U>WEz6ϐ\A3P7P4gt=7jK]Own[ zص =8=zcQ Coۜl+A+VИŸ[w 0hB G/]{v7$scgeӄ, t'!%@ԉиN<[X{ |X]Ԡu:]2uִ=byS:f߆/:n (WC&Jvtyg]J?z~+wo%a _])Ap<t6mO؋/b$/[h2釀ZkH1İ6K/znB2sp|}]VbXsmUWZIKY'{A{{Ƞ\ $)צׁa"GXGŝ vi0R$ ұ aKo’K2\st{"&E%uzx$ϭUU *~[RRbqK#|1l }k8ܢ_/c8[>:Zud>kP9_d!ȷQs[ѴN:"0[T⨊%8LZ`Usp l?"ir}4Oū>XNec*GY9k;T*BRRff{TZnrh>!_O2 @t̿'* MtԨ0Mƿ:ᚤC ~;L!qp5b.eua{1"0=1?G=u=m2 .>$ (}n*򊱰>TоO1߯.xoY5z < &:rXp1 ;TVku56Edʾ} Hn5N.umlث单Ҍ/ 0/9VFz(8cܳrm4c!u}hbNh jx1S;^'ڭs`5S\.ޜwxۨ3Olu238->u@[0s*HӨ*훑juk0H:L_:/΅oX8 +w͌mrWہɣ<`MOm d'QoOYsK2 v6kVvmzGP Lq/ 4Uc CDV=(|+/=rhh] S}(F6)E6X9y`%=77,L!V\]pJgDC+mKa$LG33˷W.pوHާS7>7/fX9w 8CqN׮BD:d~U;7ܲ6nKOa"YҒX>@-I] Bx:Tk\ f|̰ywJ1i,0!v4.wd.5a}MC% [IΈvf C%-ȹ^/+^=X,whqVwH:&-.>>T}4)J].ar܋~FlXW$㐗Dr0Y >34X4.Ch,n6%16 #2.^Y/¢m_J.)9Vj,èi-Fza[#"Jޚ&oVs/[J 9x<Ƭ/ ާ4Vtd'0Ns-rDͺtq3\ iP#b/cnd۰Ƞi'3l:Qc)W-/؄>ɔ,O!6SdfGqHLaA RZmmO-r 9i(/Ӥ1@F[D]tJ\&ER뺗JYMLI\\ᓏ"!V(R`Irnt2aES~ EziY[zp* 8o-HB'xFcex#_t`7j1;C%=B#cBD}sەwd~95uGJ#F?A&N7a% M~=?Yb9wh%@B0bq梊:ϑo/ucUN]Bl͗< Jy;."e3 [B[dfgt:^kowvC܆`vHˣN±(N;wjǘܚ= 4->QvE>SƶPd0p5/RRmyS?:)āt3y: "GNؽ,JlKGs"v!zKn;ÅGzH>`]H(0wndx-.VX+*ygu`!x"XQÁ;Y%Y㒯C^qZS"Jڗ)Mn:s`8v28\ *?r.", $H #)O\_+p 3gDV_h#S:S#z2hA^9?* qܢ~;0EXO, "S2A3қ| 8,H:l\G7;X dV_)9vXCc7ٱEw8kkf١͈)ԉQBY: L%d'],Eô" 0u}Z0F&-i/Ȃ."K]ElfKn_ʹ*!LT<{LJ{l%ʭ!yK1F/{:,IpAp*: X.gT,km"qΫ\A!{sOl2)^O6b Z0}PEo˞8kiHN!0J]E6UӾR~LΧ!p!6;fiNLI rܪln $a"9N<(]&1@m3sv4M8sJ^sfSFZj&&Z>'܁c(pP\Wb!3/DEB(OO6-Xv줶[O?[дi6s.59wL7ihT%3((%$)y.gz!L3i7戶zpMxDc6Oi)*,k˅RCϴ]ʞe tA!l1>k42+]I`*@Ɉu.-`TM# %\H)u\N=mvMuA,(H$]IYUfƺM_h<F@=SxU?B=rko#ezy CĒͭc%v=fZ& Fuk - :M0)'{ซCέzuU`oeP hI񅐎UwQ-eDOC 吽XLhgo#Miۋ<V+] .Dx^ ߽vӋcZiI6uBz(m.ZA ך'ᛯ4kEEܛ1X7#&1P4´gc*x.mиc|!PAmbj}8{0آ-#g[s68 ?eToʏ7];,Cۅ4Imq5BQxDE;Ef Yu.x=Oo@Ȅ|f"[y:MZc»X"' 7TXG|R~siC614nc(?ecgv*2~sDbR `8{$q\Qk<6SOퟬOί&l? eBX }Q8WncuCGPG!}w\x 3q@x\h$"fΥ.a;eʏ5' ]\}q߃g!Hi ohN(SL`"r%, X;KќZR?P*䗜2Omֈ78^r;O9HXY5 #st8-<NaXz\kC/ 9ia{9; fudqhw*TR̎7Lِc+wkj񀴽3WjZn-'^${v m2CK H6ZUBܚ8rd5BYU5nQ<3)J/ /C}ߧl+DF~88f\U{N~>!6bX[y5!3 7YJu5ln=;_ydtB]pB+o2WS$y Um/:p+ zYjǶuИ:,Z?1BΛCRk%L~7/yG+[{~ ^rD=Z<\i\a ,OH2I3fڅnD)a7 &ta<@rF2,ŞWZK㳪'0U_kIOub~Be_kE0^oo-e s[PCy0-QȾ:x^h\;  f'tcNלl&Z7R&ledzܘ:B'*Դ8ô1Kl&،En|ܓ_|6 m"s)x:r؆^fIF'us'agT*&>wb; EJItqi/rzDך<3~J׷ӊžNᓫ#>lҩfRV*+m[o "/1Mqhˑ.O Lv#0ߐL.+;va-p58YVFNգF[q#MZt&Y4+B6 *u0Gg3jcLQq3>5wU\Ref vCa<ܸ/ה>H uP{ GT3[V!j.BzL5r=6E f,XBI*\.kGl'~'JmDG5$MIXHs­4WC8)_(^Ue-vc1.\p/8:ltW{aU:\vֈ8֤$v'Y T(.퍋zEL8Q[ӶYlZY*dVT3 rNdvAlע.y0w>4iVY)Wx7( u!yw{֖ 6HT-hƪU@PR(*lpZ_#-D@.NV9Ȗ>s5-o𣗵-E;d!quXN5KWFI|<)L0[-W9<"x`<E2l)39@TP 2J]C17i=SMqI ʟ}w+UQ+j $.Ui/{T|H1$zo-< 1E4~<b4]ʢJfFHl_"O8&kքUVQ.}f/Ow}RKG$QqzMIXTj}yj_G5֨*l] es~--t5+Uxnfew#|Ojo?Qǖ<|T>U <~Ny9`B&]P&j(60letD e60YTe'1!<+YLw驷e'T2[w]ǁM)ʗ|fR̈́(u63%9oW7I>XQK#ܘȷo{b>] 2#֨ >aG]as3hYm%~ ͱ}jXynWzVDR%bn9`ZZ3hwvbl gos* N|XbCfgC`}=4x;[V\<}dseD'7(0Q>Q حQ qʟNE)lj#.?S-j?"Q djDo r+ ,*/ 1I~_7C=p`-Hy r } ?>J}e_>)&Q|.tI=1RYu_hDQ\!$D'Dlɯ;j҉\ҪN 52yaĖOUh;@"si'= R]w%xq6A!U X9=ػ^-i]bp4hR;},dniRG=>C}5tRBlQ4ɾƑ.R"xvwh4Ƀ%ncJ.v6r0qogy7Խ0U,c*ƙpx5!R ܝr+4AlGΜ)%8d>lb0̗l6t%cp:BKC3n v:,m?<['.WS;DO!mvk\p- %SoHKUf2YU̴̮R!g譭%I7 iU;ƾ?]*h8O܊a>gicTb ˮc khy" J98UzX;Z4|`n x?inp^ (+CG8)>cZpA?w};WAbLGgN< Ne__z&{3u߈hذ O*_0$^I\g,*^ŦBrtYkgSГSF1S@z+ /HA THq3OmX/\FF.OJY&LkNJ 3jNX_tg)9~eώ bMU_G;5zJLĉFDuGw])%VfRE0|Qn# 6ѐ-N3f׿y}? !: }Y//V1 z-s*ZP=GOgY0RG@URw(( {r 3}eE% =BgdS9$QvO1gnbkgC1' < (qZ&9GwǛάke)7=jɠm TtM(x[`V#PݹB$ż. -m4]7( zN=;GQ-f`D8&2<+SUhFMfURB@ ,yԏ)[~m6vccZ/D=B|ZЍYVtٌ|)YO٨Tي]ܙo6u^B +h1ՙر!T;k!@^גxh5y:0&qw HjjBTvf DThW;ߓngkOxPz,ΨΗY{_qXMcD>)—{娖.^4)z<(];ȝvHمC.0j&Ts&;WVP@ iO]!T*D{FϏVf³X.+N,aOUDDAWd(d of?*Ēc<Gf~YQw,uX|12QV}s̗J^ @ʀ !@HŠ6#FשD$>i j|l0ul46N5r#Jido,o.QVYa&0a.< JAh 0&'Ke(9ѧ &.(~D"ԗƨRL }UnoG.;=@Cͪ\U%5ف}M."VL:8GQggԁ}[)K_wdKew6R4ѡ,($dr&&nʐq)|ȴ,!YLkىqu:>ѪIPzY8Qm\tamr9)ܺg%!bpQ3ϼjiN;0 -̐cz95GϹ5 r &[`A_] o^U)ڛP{BHrP@y@ (W |~zsHwGR\@Z8bAb=g9W ]^? VOh_+H{_#?Q0-s+Ȩ} v]\ e+Uf fn&cdU<> 9N <%RN~6:x"a]{?^e?7ٞ>I9;fF#:Gë 503؎Z֨?{ε`A/DQ4lő#cF|vR!sJXڂI3iYzFѻHx]XVgS:eDa }ĭk" 㖋WFVˢ6hb^cU ?3&;O FJ (D-R!"6fV#(%ΣAI>k,l֤ėax~Lz{EՖV.vjs)[~]c.J!uÍ'E.!&Yu!AFة)N 50-vnh[.2#Ĩ$+l_3ߊ&JD9-&gxdjD~i ּ'!|Tlqp8CYaϪ7Bnzv1AnGLPH& OdmR]7%~C¬s>r:mp5x ~7l,m YWE TdyO6OWmD*̠v]A{P\8p]xsd,BJĢ˯Kx%P]vw>ϕ-b>L(q$-VakXݓ@ONqD.B TP1mQFi؞3b>32Vd{~Of%ӻ2}:HT8@{`9j_5gݻ>Awvf!.{<8jua~yid@*3YcvQ{)V03Rv eM7bhKV4M T'tA|YKX/g1kP鱭 T|W8/l*`233ʻSS-w)b\86Fc0-Wz:lTs5D`d+ IXmU{ y|[|, V0ș>.L{=4`5e?#^?IźhZ4dPZB#oU8)xrW9&JB0 U iMUW]9`.U2% :5"4j+{BqfXbpiWʥiE{d l![Hξ˔;f }%GUqli=c8bayAuIySeZkQXa[tA3yև`X̡sv5"bJr9T9.m2t"5fy 3kѕkC%2s9&a{G-FQ 4B(`@%J~K`@[@zS:]7lj_維QrbZ\ 3@lU0OCNbo&f{|j!*x/-w̫{t>i5>|J>zF%)V7~Qrorf=<1$!^*A+A\UMےw-aj{AqdE҆)!qL%ܳv*I 1zeN<71)5eG[ w g3f]#ˉp\?\򑇖sUL>O?p*o!U+m;rR GZ L@;Uꅴ4iY5 hIwѲvCEG+,6a+/C8Ͽc{jنH|KJ(e0}-Q31o"%Ң`4WŷG)L#CTGd␎*҅W5(ŷL2~vy\ch tp6pصnd[3mgxɀ|D5oCLC bzpN3M:?!$fjDAi{xGu@ AT,CE᢯ 4v[v>evPT) H+jz9aFA~kfD-emgN0k y4;BVxfq/x< 02i6F"d&A'xScv"yWnAr%HwbE]ZJo3Z[˂INͥo~Lwjn ~pP$ @TxmTIM[u' OWQk-h`MI.t/FQ*g5K0 i j⽲y3<}s}qM OerbvJHqqY8}|JiJ<90&\.PU#w(`M(YŎ)؟*_)MD-3]KWyOt눥ݝqΚ*SeB~'E1B&gtYW;ߍf.Ťe9Z4[ּ=8dɃY.Qs=|4EgZ\ Bb;.91㨙; .,8SmÕwɻ;Z>oi=<}U RCCA1VY[ 1_ʥhSs8ThݿI]EEAKO(Ca aʊޱN.\Y aCxRdvJCl.I<78$PodPD.2i!}udhʎ$W ܝJۃH2"dN+d"%/v~aN 4a9;sX B7βo(8؜Ws 5{F[OlsM7鹥k#l *Uһ\l=oGk"Fxh_>zHo"/%i-v!|WF+#w<]a~c/Wg&8RݡH1@(w E;Le g҅⮠9XхYo{&4TVD^(_KQMQPgeih */bO;. т9'tiF1NR"6 %._|Kňv?Kk^$ȱkaVZV,j2dJd]M2O_OD'2U(+gJxf6+3{R40OdwZB8_@ž޶"aӚ Fvw7f*NK7ȠjT+喠 ͩu} t) ~dn4aLb</NΒ\FpLAY?b\8J[e%K4FiX- %n.i .{C.)B9ᒢPn0Nvbُ]gTaf>Ւ̤a2|aH4BIJښMk̳|~NDJE(ZbĈçs 72w}vdqpVz<tq-gѺ2/ |{-iWg0(.& Rs=Ch9jkE1{j~.lWWc bf(,l[c-mh[k~Jew2dG)PJ0<ry}!] lȘ@F /p=za?]tM/ Ӭdž1@S=9,kFK+"yVGX~ IB k:-Qlt/x#rħ C[MqTYcLJ!]AQLX>6sEjw}Yk*혺!|f<'(:d Hb芊[)I|c`3'Bw/,y/2,jDsU\s_$i𧥐I;عV}Dոi7Jcbi#A7E<]OtPI,p3be 2o A_ߌvWԇHXzI r$٤'Mfqz d/]gC{S\$+l>6| KUm.)|``ax40XlȥNx2i.Nh5EMl3 .3]vwM*V1rzM4kr4~8k;،}EIL?̠ܦsGkЃsUUb m"j lhOBtP;ikX|Q\gn7yR#e_dd8FޙnV$zUpO?.7vW _=䜊jJo5B_5:Ƶr ❈H5M'#ݟ+BeLςSq@\<`$#k)+ CW%yL#8%5hw? &G%_.9v:ApʣZ!(c`)G=G/NΝ ý't(D-nwv+d&(l#p>Z#5V\.W ܶ {߀]63@Z o&'7Sp;~ D|š(I!Σtc 2E41~UL 6۞n/I)FAz\nJ9-S ѠGk =UzڨlLDT+4.v[?E3ZQp԰/E aްN\cBof"#} aHskT%aq` ?ij{L"5eq\e8+e}ËŢٻq;H+ ,j2Sc)8, ?]G"6ܺ-P߄aXQdTkoQr㛎Ib}sS>\窴zҥ!IXG@IopE%sқ,_leS\BJ-*+7Zisyt8r;M +6CF6Sםg5 gfm嬜R {a8_b+i{$0Hwj.!}8ać)IG(7,;å=h#xO曘~WpfBT48S R^|saוY֔3Z\Pd(&Fs]lCUPW*Zry#+5R 9/8t'4^oxCRWA6&'2\0_.ްK }%ru'*?rEte+p\P}1;cqjPgric `(QJ~WWl$F38`\ݳGyH|vPu<Ufo}ux#8 '='ǣ>B)7 +̖Ve-}=#IU@zKzfi0}x(NY|G:CuaK^qPc[nBM5cb@lZiK| ҕ9w1ӥtdZ.5~mBoT(4Z&! v'<\܃%ۢ8@7FǚT"8Ԥ  {oDd-?|N8&:>IEXzׁ%.IГN\G2j(яP{>:/*iMԍ}ܖ[3H1rtpI!R vΞ/+6FN)@2h?؀c'l O'`[u!̥Ebo33YW=@{3S(/}ʖ~.ET?2ͅ 0uN02Ŵ~WH^|}.]Tr%I AP?9d#f5&*9c{% 8Yt`MH4DRߡIS$5˷pd]3ybp5rXY9ܑߺ8UB0;@gn VVؔzd dw*m=6 h2' '׊'VxՃcƽb#`XKjzUJ{Dd=a6O6ʴ/@JQ @CtEILnS?TWxd3oV̪׿=g$;#d׍{]iÿ}qoKGPָbƭZpYzzXO.ِ%i) YƁ>E:6*-8'0 znlQJy]8$X&J''iWV33܃S&+XK;UTBΘDv4_)2HnkcFWˡp޻W\-V~|E}2oQ៿JTLx?`&1gzx~Ǵ:0F(1D7z,ȳ*GМӣ6ٟ ɫz!5{9Q*ێmW(3M`ahA#<'e,[ص K*zO9D=@zF5 LPxHIt Ep(D訦"L_+ÊTѽ6>Q#04HfnަA咍e̘;Sftg_6jlݲIiqIcYQN艈<^DPO>8׮ڷF}篌NN@<lyķh v [cq ݰ(d7ug'G9| -%E{Z^[Aq4C]9\?40*k;7S߻ 2lM3c@SGҗ|bKariszO!DK][wn4?Kx5>S vr¢lVFlKj=\zQ9Nj5_Ui% 1y6L6xUnY7`3ѻ~>֪~G 1;pc+"3}La 42S!Q6Z1.O$^w1$f+d$y :w9֒'y{̓;u>O'_rj3=@<9RǺdUULBϥůmf4ީx洀Cf~<ÉTcnа5@[\hF_@;2Z_Q! U]ۋMم,M)DΘQFM}L޽W^S1*`KHѷeIyа\"%}  e!?{ ]9~aCCoةPFmCx{`j9K7)3Ie %N<׾{o) #?뇻 t;>`%)-.g\'05b`n2߽s"7ee=R7I):W-KƄÍ&YO&*jP'(imJ66Bmū(T^;Zi%Ц3~Rs]_Dcw8{cnSbg5@D5plC+BgaIFj#8HkZ7"ptձK:Awb',_*lK|#A$A}Y}s׬LWry9hAB6A DӯŒ}z]2k" CVP M@ 6R4Ót1^(P H Lޅ7e"p"_ ec,3_pIJ``bUA5uhvѿV1N5Hunb5w F Wuy씋ԜZDr԰f$|صsM0^>&&,IU)Ct%:vp` TX7( _RK~@N 1: }ʝݤ)i5 <=nKDV9K}vSk\XOSg#pQV]~PEV)OzAv{ 2.I^J^WsӖ0)!]HoU8kxZ;^/ļ؃g8lg8,gX0Ũ²s@d(T468XY}*"\MFR+ϴ<0Z WgEa;G74ubeDn6 kD8-zlj7h oX~FП3] r落-C6y|,xC]웪9g{ʵ$|ՠ)Zɦ[YsPZcQom^N7IiZ,z7u[8eܥm݃OVG.єg DD\6#_Np_>m=J5*qҥ4m*P-X+iQ슩*f5 tc^lw P0-d-S'KhIK" TaGn*j𵹎o )v10iJ,>`-(X'.B&5debzENn{,ik4oLpOEUkD &xpCiE{ ʧMqчfDKNsGl/Qf({}:]~:Vq&i K&N@Ve%ɱW7]w̋ GQe m*shfz#%?낎 S-Os"<^˪Ya]!8e;&#T|J1}ǭ{z~Sk籏ǫ%'ãJ']:mЦzBvˏUL1ٙbgGũ]7`: /BC|i,\HZgm`ʣ 3_6Aw40%q hx"I۔Go h9*zg3iyLњ(qӢ] 1M5,a36y{:eAe]YTu8q\Dj+u-Gm(_A!)ltmFA~}CTQdn?y~؈%@Mv r9jϋM9eT *KLoy|"຿3sf*^?jy H߉$sZ7CҨ¬-3dٕaޯ26kdhE'g"_6&5-bJ{-1^.kCp̲ko^O+^mjl IcSh_zfM(_ԋm5XN (a+C"۽ o- Kr)KڍvI1 Ru1y..dek%ހύ+Ƶ {2'O WU!0a0c#ގ_ޅ?^8pAګPf: 5FuD6l'O۶?s.}WTcN8Ik@i-],-YÏtn_]ǶdPRbHΩ&(q 4=R09եd?2U&SѳDbU4y.vy;"0S%)wD?PW+@|PYI|FDŽ:V+Y7S+p W\twj M]Jj_P,Tu$>?,%f2,6i 2hy;=ƶMD6~F:,]NB8>/?ZhD%i r#@+1-l†xZl' Kfr.K;tEo%^1°:N.ӱ~#zŇ|̏/YH<j(&us:59Aqљ(g10ˢ<;cov 𵖕Q>6^뽫.sj|RA2iǦ==[7\xBl4_EӅMô%v v}dIHՒh%jXLivok,kPF,M&^)pv6 $ Ƨڹ֪NA sލR򨮯 xgoiɈj\|{V|-dKѩMP OTbaο(h4+j52$Cc5m: 51#o~? AbyE-C9U8$gm!`_7Hі]iX$'Wqi+܁};ۻy|U1iuBz+NbL?<m!۾_H%/ܗ,́-)GY"tr@M,!*e.A,qTCtu}j\NqkY;(]4cE) ] R:wT/ͯ^z7RH(,ZrJk1rp8%7ppʆ:* hNAeiׯ/kI C4F o@=wͿ^#glkTϾcCZ6)c+z }^{L d>3p/`jGq>w~/} 3Xf;;U :dQςtN+Tȣ!"S]r c^B]`e={/K)mk0'Ӊ0 r{@Z0pW zzHz>x6dE7sWQ*tpł<;3|~޻Fa.ԡg,r`ӝL-wSt1`'k0 [F/Ȓ\iN~ ln:vӢe70꿅 PslYi;Ơ!_hNe>pЗ'c ?V~b&E镌S|{I䖔;@rldk'efx^@Ĉ_ySʹMy6Љ:?)i<ЅQR6t.GN.3f뵵B1AGa 5<^J[[a)W6?4]1pw'5KpW^vD%4U]S('!ɶ=5K "uQ[H7>T]z4K!MUwYAY ޡS=9g ջtE*~Ef{*+iHr @D%3DZrM+nDϼJki-*a@W\?Icʔҧuwxc&qTЄ1o`W"5ʷ2fXиR?U!þ*i=xy_ " @qۇEmɏHHlnվ4=ŞO9-r+Z ZdzwFՎ9 ~:C;o=wȐ)F-8~{^Hsg%ydni(iu&L߽ĝAJ$9]gZJ>sjƁUZjFJi 3/wެ~F٘DF[ymÊ}E+ybU+L6FKYȈg4@ZRn&dL$F"ӜT  &Jn>5J]U,8gFTƿAQ#nfmE Tˁ*)jn*ͣ~%г>*AւK|HI^NS!"z (/""=;"TgRvɂS@oar=8SNJ`,O6y&lW4rڡ%Tpn8"UA~H2e(`Ur1ho}8FK1_  Lg~]LNx'IT<-5lڝG[ڭ:oV7?19VmK*Hg9\:vt%#(7phLۧnR_0$tmscQz ),Sw>Rw\ ;YHָVk-(}^4 ve*

t4 {TYT^OS,$@෪z\q-Qd#` z{5-j%dlǕ%~ rWڧKm53A򰠻o#ؠ4Ǥ1\Ooč/oXW9ߨD>jỌNAi}lo6;9}@ŕhҧ, !*;|-+#=:M0t`ϰdFadeo/w1$jQH8u;T0#gX$J9Vgsc9~0;4@(ƒMS ݗKy %Bݲ^Y ȿpTAk)Q7Nn+)߽"{f,4IUV"-J)(Er^ kt3oO4X{$!4I,7O[JyGhp_EhDm(ϱ&tRШ=o+ǹǑR\t``>G4 m-dkDvl`輧 k {er`d d^ڋ}RpG%/gf#B^;FtWFk:?G;H!k~vP8;1fڙ7@9$Lt'<T)$mA܃뒾K ^w@^lSFxL@GRoYUV\_%m򑸚S7o~mJ&ENbNexcSu)M$Fb5~j ok~RgL]PWbھcp)-w ]84~'C-x;"`{/ =s c.2 V<zK~Yc?SdUt2^j: {3}x w6"jshW^V4RTک鞚t2%GPGĐG?Y4mVa.JwRclst#N4SXPX>|aNGy ufe\3ʦ>1okM%m(->r\)zj ` d5qZBnY]\^a!@{)=TJ#Y}AiUA>Pɇg3pYLoEq9E cIMWWWn#/Ct#c2 ̼YK=%=ٞ4{݌2+< Y [Voѷ~ S.){`n"4h*bdQPQPL^Dec*Е&nkメV5I>B.Kl$F+@hV >p\ª!/&,[ O欩{6Mv;zbq; ⫓m\?!96`$ T L = (V1W\vUTW#ƕq$i͚ $G|$,~^ S7Ӓc_o̚0* āx:cC\C)w4 tw_%aUKOas!qyPkzhR d|YE!m "S#kSȠFX~l,xwU}_ - *hΆNl@1 X,x 6|ТJ5߀iܐL$_hvˆOP𾫵1ÐX:_3LsKtx0}TK]a_ S<1pЈK a$)ؐmH t cL' vY.VNBVF`7RFqL4/JLml@$qF-i!4fp^$ {1pqhD8=}. ́3prbrpM[.f$< q-@;ʁ:7붢/( 7۵{1=ty MKJ1T&fW.#iB9hVA]v-I޽qit>Þe1)HP"VP{.z3J;brLEg0*Ő_H}'F" osQ ǨZ uͱYvTJ#e~78 G?ɻԃ}"?fT: VINZBՉ3k[~^wҗ\jgkP[d!S$ 3F'S!/@.R޺P]r*+lj~ng5'|,u`Psg(b9έ]lu peD 6woNơCk$8WJ^gMf3=v!>ŹʪoXFW=,iԳna\/)gR&ʯ\~ DG f143%%T}oT,邧t 6vRN#@Dbnj3G]@|T@5ngQ|7o3/ЈHX19jeEMQ9`lbQˌբ 㡢,$?<\x]*6~ Q"8N2 "x[,3 O!eAŨQuv"K!Ҝw[ Wee5a58h㖬91+;4)~,[0sG>HXO<.+v!ZNH^;+&{ p[0{>C+m`ꩲ')vq@ʲX~Awg 9$i= YaܴၖAad9ϹMJ7rBl'﵇ r:rnZvmQ]:Aū񬑦0.w9 Gp\<8NB9<\jCN)NMb&7hͱYe6MA֭dз)'e!Q>R PE #=PZ曛dA|ukk(h]GΌ;?tPoD6>.'HUܞ{&-v,[gl #t_- Ŀ ,V_MR.B,ŪTH1 TTb~|RJM(bWҹ E?:% ?rt|z uL墓<pG ۯp\'&E-uf_ BZ)c'p4u A.N./LA׏5vQyҫCƞ\Ƥkѻ6׹sxT/o]T.G.p~??D,$EZ4/֥*^|cuaޟ^JĹds='|D )~57\&z/Fw._Z>n ,&O-!@NOx]_~QlBE>)0ؐS1=d\(*j?^hKܚ#&cTKAqX;o;;JVʛ|.A[' gТr٤Yyf E*Wo:k= b(Ntľ4/=~$Vccq:("䟚sJZkٔUʼn_^ˈf+>Ywcjw%PU/5Ymz;?LEFuugvv?#yL @g;lzgF^ rK+ڭ(`K~7/z$QA݀FGE]wI_āAi Aaߕ'׺I֠vxǜ652䘇AS$ s˘wgd ϱ\+>]xc&%??k"ߛtxX|z˃Yڵig{߸ֱ/7bGqYhc ^NWſ^?)]nNA,f MOi>FcN0$WgH[b%"Oc#3D~<pEOT< A5f5<@"u l>]諹]TIu>!J̈7v5ģ $K}TxI7Cl).i(nHyu]xg˓p̟y f qeU3Ϫ^'Z?W+߱(7M\i}/,CPHPe= <`îo-|%ԿX|3fZ{"-N$_xxW#OS){s泿4zQTbYe c+n4+vzH"UjY6%\ s*L̻(" >a Pr#\X0ɧ팏nm bc I7`Q]HgSH%"=6;}bfѬSs=~j ;Ѭ8mf eIcNGbDGMt,_ypjH5b rAv3 B6_7b_0pΚCw HkLH_-$`L%-ƊpLō(Dӵgu!c 'MVnz>g_n96y|LQ0.df<2$w@X 2|n D$0fp`+XySx x9r$UrkF5k.;vwjqbK;nGkEM~!׏J0•u+10ng'3oR:PIV3uzr=͖ -4 )[)ߔD =pCbڷ h:܉|q@uB36ZN# A$ƟF|1"D"g: tJ3|a#Ϫ?J[}btˉL5T Lp}Qw>-/1PuN0½`XBJ66@)8$V W7."g=pcܔvgidcj#xgj,qI} kY!f (,VTn\{PN`(ߨ|wܔ.[3ޙ}Sp511_ Pr_ml6q4)Pٷ [mGL2H7jQFȖ|A5*Vep*+&VG9n<*˹G@7 F;UV-މ[zUid9p{Z0ΠJ efك\+$ &YP_|Gb- u. +qUO Zj\ɃK@۞o`/muTz[N;5<&R -}uAiOj4n4-nD֡#ĈW4䶋kw:S NWR_108DH}golZ2y2ȓC,WdkA}Mpt l@ 63S~F˫[Kq+z:a$Ւ$ f)O ,Օ@C'Zh%i'`g)C+arTl5PBxDqy?BhQU}` w=GfM͚ܬ0u r9qmkɫM%\eXVN54V`tkf#Ѡqkn9 ujfϮBa$ hHm$17vZ(X[\ !]['3ONvj?L>L_;)ضX]%H̆llgM{o)|_v6T?\ZZg֛K$K0m 1t Rpp:wt 8+jJ <8W9$LAÝ.y>fo[exQgDg/{n|,nuĈmh;*%@tW}Wz݆3E#P@XMNֶ6蒰*5I< "l ay1}G$˜͐›hgHnP`4%4k5|F<,.M⩤6a2+b:5g&p;nZ[PE~v)64%;yC[Qir59c:SWeQYmK}': z<{t&tO $OL¸W3\TKXmy|%g 8*qTX}6;e?I}oϙw"?d'9s3>ʜ޳5/2yq'[|dZGKfcP?_hGdT]WR߱ =%bq'{#6ghUY.r=dr|w2ʝqf%eﯵ#MHghFs׉UŨ8R~pZlˡcFp'̥s-37/IyH0ik2c剓WN1;/U0iPkپLB*a-tNQOp1mUH c#}\հH)׃^4k8C V4Z䑎r&[K&^aӳH4Q^G_#V B!;5:NokvGmA4(N?Yƥ8e쉒w#Xo_xtsޮ֭0 QCybטoy\tZqg{bUe;VKhŭ+SRpF| : !M!lS3*?d{ Iܙ_VU/)/!ؘ>(Bx"D~Rt{G‰wO>ͱc_BQ-g%~ZbO{#BFya !Xs Dw]ތU.T>3cNr# 5u`b7qېA1rIa8 TK!7Yg)r#2jXt;}[ U)^;x?>p JrP}jz8T?'FCC))`ZUBb!@]cֵ5uͶZ44GJ BF9'zf1wgKb_W0t=hG!V"+B(q$HE2np%RKcqg-L^z9꼓nnpHRg$Rp2~r;t&/9_tleu\mkP/'dʯ2VuiJUyLjӔ,iF88qj(…%L-}J7,?zd&aPh:+; Oʜ\qhGT*?5wOMĂ͝6~bd]+ꩵ0SM{恐G.BO'b_0RUZVC D1ut(a T4CAJ8b{8Iwg:281*b b BWpW*$֍aT>2s#=bȾ8 ovklpqw3QcF}=Pgs8yaxu7EO˂ Dܽ[n7xywٸk|Wve:ڜ(X-jui|7[bi;z;C@9{Ê"Khk}tE4B^po"M~]CJpfh`"^-c͐XK k\i_s̰7~aC\/#ԟ0L~ bSX=?5TXs.dz~!LC$wI }E!-0z6+/_UQ LwX8x&P0ɽ=2z&wq?vJH˴j) (ÞGÃ}EI~Q}6ae~a0w eB_AL(+~kgᐠ ︨+o&|mf:7EoW_Z%XC*|G-'`F9u^$*C'b9x_O3{X6Ň"So@^EȦQjS>[ɏE82tQm#PY-z~=.ƘJ~6FeiE&|C(mHF` F5܅jriTje5~fr bAlنtɃ=,.~lvlObOXè–8Xd %RȂ}JA247lƅq쩾6N!fNJ:){ce/ jfA|]ʭ֩9l4R3kzb/ˈ:UUr㉪w?y;:}& ܱyZK1;\nm@T(FE , A^mdC Ee$n{kwv]Vߔ٥GRd6c_)#s[֦=qشB3 Ic*ӯ%-i{!a{yJO_߻(ɂ|[_50wV ѡ` 1;8AMRa0%=Ơ|! W夛2iCu4~RqxĎb '4_'Ǣ8O'&+Ak'@a޺$gZK=ǒ3ޫ%]׸*if'rMwE]#C`y>MuD9+.Re-(r9捵Oxq!D}ؕԧ#| ج)u uRXsʻUuWcψ{(۬WR 8 u#S%#/c*5d,+H ϟnޖaUZgҩlM{‘$4Eƨm-9edQF~U2&*ydSA31QcE% ٯZ[q, T^urz((/b?gwKcGcԳ{t"|;l*]5 C/;,ԙ3mU\AWWҒ.li (wl:s;%Lxf-m&!͍vSa3*HMz#n wVSBi`Ow\N~$L]_EK:;3c0S|P6s 鑵U-Q2B(5 YJјYJb2/7aU$0# [95'\q ##큎@<]U7Y+mZa녉e6Wx,^$[ 2h%Wsvr+ T#@[IU g< ܘWh&"QUBv _< LX& !Q!?ǯJxeOs;Щç kՎ7_HǾLp1gT~'hHz g?u=h[co#j]2ǡMQwl,GA׻%oOJbwr _[f3o$}U-YZaH; Ճ+ͧ!!7"i39AL^zy-7Q0 o3l8*f;d䔷X8J\ ?>J}SM d2ΒsɄD˶?9ue%9CѦ0\O M塗f 2>T@3Fl>b z'¿2֮i9=V"F:gٝ"$MPoiB3C.j@-d v֗HY!TM0Im.'4[Ac.N*nguO[ FOr&JɸibTRG\Sce~cp7ޞn Iގ(qIt@LҀGghA_~TF㻉P?54ЩwDb\6wϽK-K)ª 2%gpnQ[0sf}t_y#`-6%nTDĴR^8r__ER:̘w7gch"ϐ_]zqQp93t ˱qncQ$iwrVsǵ.\ =P"fE)e~=ŕ]B(i^Ӝޑ'w=6&N+5EE"^ҊyaH|V4!}p$x}/|i^f_N{@l}/mA/Dg*_p0zdo?j:rX܀ks#j׳W VB2QҨ}<5$VkQs3j4XS䞾tb8 З]&7.w^eU)c^[Z1_ZWyBPğs;4t03&0ű'(0 HxN/na803 2Gb5pd(ap"&M:Xm`m?fp98)qorҞ˘Lg_-%34on>Y08~erc{ Y>q)f.;𖓽Xv 9lNy;U(Ma=! w-c,TEE@7Lx/(D>u4V?YAw&5dIEOY KN `hbgG7 euVY:tC?m*T?O2LtaLE<6_$b!ᔡe Ufm:ݛnS G#'8v?_42xfI#j4Tu)l`,8D6ϣ L`HqsqN滰]z Hon[nie_j0:uD4SP؇5*|\72Ihg/SW3SiZ#ƩY&/gp]cȌ_BP 鴥 yr=u$蛶R%i?kR!Veh7n:^~Zq֫VԅZCVs(´Vj67ZOy.fS/_Odz4 Ӊy8h0:|EE7M_1R_hR! o}0]{ mDX0Ofj{^CCj:,Qw V3#\W^s .FXJ @yꆌXھ@5IȟKLSg|4KѺ^(\jS2b]軭kJyNwk "krwFM-'3)eBtph -bȒ񥗽Ld+_B&4Ǹ/;&ݐV{-^G :tj>tE;3z> 2*kz}W DKbUs^̞SKz z u bѼE1T? zZ¢gUY3AAz5AJISr8}pHS@K]ARe<}s[Y6˼? Hfl'pfA S9G2 ^x ᭷{A6[J_zȎ\= Uu!)uUY_ K#LUC4F V0u[im49K©Xz;u|Qgz5\ 'C+:Vh|te^(v`!NAf?;u9SFhz1'yqi*)-[h 'ʈr >x$&‚^9)&͕MҬVvtL%G!E8j5T}`ȕH- Q]+|k?9&r%.oV~QP{r*Ef[GGl(}{Vq5-KIzhQu92tJ0tOn?MO(eʈ_ȝH9o6g *ᐽ<6Mm&&\CcwTG0Ē=8=]V>P+-R |ģzd, x ! ;)_QUuk/D bobI=չYȤH>PøKe }WepHg:.ye$PsBu9ٙoèto-j84}@폆*㞚T;:wP˴7g3iN0-1eK\x8:;'8:(Bt3Y6RH)" Q@7uo6Nži}ׇP gFT+xo+ 9fA&TsP?H? }F켖 ~ ~ 1bhVg*_KbC8u^ 1l{t,PG_8M> ^q")#wH : 9\;Y.Hf5IXXH?$Wr8QT[T|WbĚr(̞AIsE.]s|% 0Q |?`0-`XFMDᆞU{͠SSqXZ <[ӂ OydwW1tv)2,^>0?#)}:ћv32?E?5Iު K !*/K[n> ^ OjD`~NDmܱBqN8ɤ=K,M\|zXUCB57;eg9gQ9?"l>L:xN$r>jQ(};{YTwE=$f3W;)Ͳ$j&IJצg?&,oe &Ԯ8z lVYUѐI9h!!kla&@PcA'2oz5LAwxҒ`gHbɞwl{j3)a%з`1[h] ce=X3]2Z.M&V$ed H.$%2&kX"=F]ҁD Fr]J7?3wG f\)`r,A#2Uk-@Ua;{cs@Q΍Ve2Xm،{"bX nŘu objN]֗ýsRq~58K x bfYseǾ3?V nn0t4qxىT_,Gn|AcbTw}1g1>U2U~Vaid0*V PU>'Á45:TZu5+ip)@ee ~ls2lRt-W^-m\HGOuY>l:\o;ڊMB,fnhPCX$SN"/s[l |"HDq&Hٮ~ix1j:XS0 à{?`L*ʹ"3t %NTedj+:2KjR@=q,Pt0DX|7>̹@+ґbqR}ֽq>WY"(am" <g0-dE7mĂ]擥YزؓZll3&5,tP꘩+ 8:!Ó)2L˦DAr$["?DQхI2Ig;%Hڣ]ƐG2wJyzf(!Ov>@ Hѕ~sYG]eƺ`Հ-E("!dST 4N ꙾D-(@ܤQ^Q 械 ~z8f7].4W}sV|=u吻PF1Kj5q@Џ{s``m-C}aON@ g%eݮoHU%t_;;tݕ͜%&(~#]MfAPVurǛ}[ ?7[Կ,o JM=} Sg = "H_|jh'TJրK4PO5rXH;AHd; 6 8*p Dy~p=AٲO 1TTk5E;m#.X-;/l\r2|I:`4 ԾU( 22txٻ~} VSٛ $z nܔkѯ7`/&Bh2`|ѮDV0v͞Nq=Q2[t6 TnzJ"Bx@ޅkb9 "upSiAev'̂.|#ꢠHD:_[XgP1ӘwU 0M\ǃcvYh?. '­GƪզאaUj 8@;BMmכ"л|}3Ci {ו(}rVCӇp>hnٯʝ(Im;OɨOa1 ]}3kq)%G j!XDڻ"v`EWPFCQ grS2.uw%<{J߰4͠3.7a?&W񖝼M!uS`u @@Jxj`: Q9o8 >70&o$ ɣmTe&i*"bW)cUwMV$TZ;YX>xg?O-o{Y,{`9rl' wr)A(&z3D(!HPCvvWv쐞[.uc.#Kd]VaMtӬXTl5<Ҋ 7C@Oo]Xb׏@m-"*(JYN9sjp"GBt &E^kz7J691MYhCpEdoBUnɞ#0W=j|ϭ+#밖#魯Bp=/4ѝSk6 >iگ7K&,UfK=^O|d?:u :O) x\ *(Uٙΐ|XkC7}ތ6̨ek7FȀCu$\4d'gb!?I4TG~jƵۄ#%xtaòq9/S?!onC=E`GM7; V(\C~=qzV^Vۣ_.9RUv}JD00?æ7(1U:.`0 I ~<=exg϶`z G|`NC kt+Ei1â^W{$`7ReV upg*!iH?>Gu+b ovACfpxņYbvqP.Lpϖl'9IIf<.T[oDzP,D;qxJek3:& ȳ*D2i*FT=86(J\]9Lk+* ! #hRFྺ_i Lw]}8i aV&~6;iNm$+e;Jͅ tɂĤr󷓫v@yg>nF5Ef7O4XHmmR~R|q4ŻEӸ[YS,/pj~?@cuZzC21!VlL]PIvMiVܕqCgE «[(rN{\qV#n1$@A 2AZ'|=DeҮ{޿?q^Y8rPzTN5;qmƑ=7Lk_H{; f''>US7t%C\t;UߥL4u2Y8u׍$nKH϶&/GppJ4rY cv5u*P큣]ba5_(ݷR }ݹbaYPG9Vg24Mb_0G>ܒ hkn]0ks^s(<ֻ({}C'Nt(ViܲްN >mȭ܁KeNK[1o5ld=|3Riy i.S/3 D޽yy'ˤjN9`QDGa`'8n9JK|"ȡ=jLnw4}* t9M.|v!FgB_{0l' u̓#S]&^oiC3hlJ#bJhCbg¼HO }7Oxk%[͐r ~ϙ<Jr$*p {bQ^kks ES@Gl_,hƓwil6?.?]w:pԭFR{EG\GDu q%䆟& {NF ۧ+m@.t#Cc5yuF&iqFreL+@Ǘi膚'.;?m-1<1yOvJ*,۳éDºZS͌;h|Tݖ.G%Yygf*g,{N_B&y3k?m:yRVަ!ْT߳\ *|]z f{C6'k |#vrlkHeUhɔm7uqΣS P˾%KBu=GnlN[$F>6La#ƙ .yUЂ/4`m!Ьqk̑JLatE)"StWX0$Í~i.ޚ5pv]ū8.d cK0^K _)y!`dՓޜ~o&)TZw`/FPJQ>t-6/`3gF,tz%| _vF7eV؇ f`f:W^f;ƃ=V$t)L~ݙ*|}@C 9j9ݛκIz*ت8{+!#(2uDmPX:i2>?OO89 ޥIpFN6VsKE&*Ln(s-ШiiT;v2V[[񿃗]ukdYK ќ4H|wSI41 CS,wBe+mQ!J 1JA#okZkl LWrlf&g9SR)wRfF,]ӝ뷆my jszk_n/kM>’+B%-f'ΰOUΕN[ҥg){]g]oeSO4s"2[o@p3!Ӡt\iI9y;ř5r#4l nk%UiA%{#2[|3=eڈBV#]h?Z̅"iVW=fZP,ڗ}wfZk1 A 2GYb`T=+$[?2b׿cp)S0q>.wԵ"u9`nAY.2Ov6j%\d E(3x@x!61w*A#Q낺G>г*Gώ qAC ֵ`}K f2U/%3L8KX9ϪGLE_"1\8Bʠtx(brOeV9i]ps_B*61ys~\}:ߥkF:n`  VrF^|3ݡ z5yf/1vltI?4g6rMa0Pg<|ծߝLZ4*\YhsLZI_H~|SԕlKnrt4 '\eƜ?EXe.%H_Ov8yv$#vwD+ +ۧ#>5|?:f%q9 [/ 9;YA=ErzKoc_.%r׶ұRaS9]\ZҋC4X6Ύo?MOD5wKUN7-N,u+d\OШ_^s: [Ye{1UfRÂ"ru苜c^VFV{cLxY#ԯ]76P 3<~=>AFLϳHʬ,C|Ŵ0Z;A+;Y.V?ӛHЀtFgZDZR_ $ZS75FP#07 Ӝ'9JANtPh~@Nl>fpww n8hFNA{ K5{m[ܻkJV6@IW_8FTQXt^?zEk7)0H\pPP-"`M;)^EDdeۧmz[)}㷚uI#":~c[ȪI6mY& gr7粎vٴZ$JU)-c!W$OџKwxNdYr5[n閹Ep4&t_Rfg{AL!w姍XnbW>G>5Wz.$ ==S'qTm/7~{+N~m0ߋ Ȋ7#khҡNѨV>x} 8hkxhbZ<ȭI>x-" ?#?) j :3͘2cD Nim]|0zXnx3^nqы$=苺۝ u3.3f%)w#_[0ۙ_<:7r' 7]7;^Y֌ k#}XѾ&#Vl|2ZVl0 "n9͡g~fx<Sř?a5K[zw*mB .$y#TY,+hgUԟpXy۫ƿ'!K(vxn>aX lY!Q+0DQ2C>t=LRio ]N2U+o3]+`}q寘B r:dۉّOSvg*Arp=*i(m;ؙ̦ uSJ0>6ʫ./*ӳoHzQ}Usfp8Tj̼ @qAήr }y-o}W}Tb?yDLYg ~1_Jo>|B7 .Q);!1S&p&{籓cTsj@7|k¬LwL>kfSP8DΦnw* QD˼]7 :skvpioAqw7Fl. %]uW;h(_ HuRb ȠWCqn9uݮ&Y$SI鸂U]dqwP@M(}gƋB\DI3w}zi#or-ZV|,oLec1DƉ[s9D.CQ%~A/pd6/?;S-PDz.C~=7BօԚkĚ[^5Fr!s1tG&]H 0[%Q <3gC'LEMx빾.R H[#RAawvr#vU0iP4$FU}*JGL9#ySh,(J߃]6͈jXH`l Iäg ]-$b۔2PO\.έmw-+ZШ h n⑷ʂm`wEDO=>@C$pq Z8O()̀yi%),XYxN! wAU~E$q Xp 鯓U=.%] f #8t46BӮ sZM`h~Yee'JHUD/Fj8FZvD.Ȇu7yB}&=D,n1u@&V]:]bCRR ޙݣط!&!NL}Ud].S]|m'nULAڛLGb&bsA*ߌE8`srE0!5TIيȋGؓ^nQ4̀.m=$5'd&tq|Uu! nP)>웲4[yח+O8{<[R%`~$Plp pez^>Pg!GNɊ<G؏(vi**i6h֣o)vt@Wo<CFRM?kR-ó/LSCN] nn2jWou1 #P&7JQxr=mdxkGd #-06!uwDB[:3{bT6eC5 X{sOe?*ȍo>0L6!ܯc:"Pr_ \B |D 6 <_((rJ tC5u>3%3Yьl*oM.'ڌq^ 6 C]$xd%qTsV~tk}\V1љYr'\^ 돺<nfWYHEvN0-kMg`u82Xt|n 1[jmFig͝\!G;ĮR{͠PV;XK K>'eV'BBKT&gҗ8]fg@"Oq c>Uyf d/u`y?BNl`@XѶ >hg/{hAAH3T  HRpTe1OFP+͹F.WYBPߜT@V&i?k@myխIރhcG+::{mOLUNo"87q`4 M~^E}PHNxLX3nl["K,1d zG$w1U)LZ%&PT-9e,E=|9wU8b˕tDkCzp j,ldAÎWit|Xs"_PJdtDgoCi1s\ZXc孽HV1瘴a[mU,h <H\qFKyK#fs_$N۝ 0]r6ɎG!5wwaB3;ݞ]aCWZw<-*:Qڇʎ{ࢣp~zr*@BUӋ<30z"똊a<8zշh:MJ#7#8-1f [q JV3N{J3I"P@Lc>!S A6$ހP>1ye=XY]Fjmp!u;[`݂^,h6\D?/>ʋT`8dX,e /1Yjf>-fxavR“f s> ۳)ِ۾ȶ`hImW_#wY?,G^1c$U%4t8]wM!;>d90]\lz|X' =Wf6Vu Ee@)ҰD'C6eqpιъ7R$`)F}a;ߪG4?l bAHQs@\1]/#ms30$9x^QDhȅhZ|ӓ)(,ފMVb~zܺ!"#t\+ ї 4_I;"y%c45 0gUQzܯ (BLz2JhGh7=G9_Gu!cS'hMHU]}<^JaĂ}Z.פ,2JZLR/!ۋ mzTX3 ?7!ÈщӰAO5P% !zKafsCWkpO츷 ޹0,_T&-8!QۣKs~Jp=Y_I$uE\EBWXq'w# '< @Tm Xbnc$ɚ[!XKx~&]VG5e4XEMy{r]9yC4=u%NqwY#(wDF5Uk_x3Rm%6iz8Xxܴ5+^[Z p: 8)V#ԧD)X>ӚIŏv?:BO>4vKIo[Y+Ma`Bbr]DA9}j7L|? <7ms3/IYdC:;GIlg:t_rUdQ`.H}~:AU)<eL].-Dn' "CMQHpk?pqD@s0N/\l IEFT 7 >r~N>!$c;mQPC~N56;^"" $?ap9Jd԰DS(`f=*z8X u q%MKjXJD;!'n}{ <)wf;?o24W e(DD``Q"'9~Gj{a7 ~0(ӱL!E&۫GpN =A1D?yDƫ Y ,٠'qQɄŰLUvi]Jts,l\C'w0\a!5xmE6}p]P,@z;+p7uVhd|]䅜")Y^Jx}l; O΢%CD H7n,l2}#fpgG@C\BT'FttƐ5 Z'g<ݾo&-e \ Q9'j)v i%~H.9|mrd2^P4Dؾ0GA>bWʌK?y]=o;1/]܊W:I('-&sAɌ ;S_l 7B'Yw8u+16F *Rh oކWԝ Hq54,Ϥ>bPNcb4<;E݈ BA'!k2XgЋ̎oVthxufHg_C]x_`xVP=Sy ɉdR3 (&st=~ڑOk`LKݣ}^}9ަ/Y5,*][b!ۜO9UK\6tnvi$ܕUaA%xi,\W]n4[ jAU&mlvpNNj( g-Mfim 5H]yEdSJ"(W~qiqFus4F|NѓO2PD1otD奀C\98fۺyl- L@!2|Cjaf 4N%\h)L6惠{i-[6Z\,ќH~G~ hfjtZYuoqKmMQc&?4J,Y f9E~ o3eΕPp8FDJ*LXM|%'n" 1|# 7.+4pm<'VA@x]cջx'Ӕ"F{p[VcwKUیӍn_4V-LZ5?ce;f:"$BPhdGW-iD0W,jk))y:o3 ,p &"fj>N_|qjH62لA09-~AU~k֥Bѝiݴ ,8,a_a3q!H"}7(Qr+)`xEƋ*㽗Lo&b\eeoT Q9ߌzrU:: h&ƺ>*ggoE֮I=fOtS)EXx )~฀Asu'g>N-E1b#~Hppع*KDxգV_o}*q:^ֻEC.@4 L:aD-=KRH !n~=@wŗxGu(GUCpI Ч } to4"34^WI9*& Rm.)wLOc` =B/ g#~q';2Qoי\ U\?* ZkΆ:HE;os6|{A޷P@σI^ɽhGy|Dkn_uIR/)20!B^]߬?B}|@pI=$K*,3K [h|e?l{݀3.q sŕ*|00x#f- 5NwyN m!f #O 8|xaPbF˙-s**Y7'_ #*lܰyӧXEYN+2G niNw!{")R1H IE-$jٙ*.;C]1x4ͲA[}iٮ $˦ k$ohyԆ.9Pu > !BV&3=cOz$s;ѕ'j1gkTUb!"L^CXխ\q +9FT]缢z?xಥ죸r Xcmt2Ѯ Jfx_ G+NInS/T*`[l_Wk#KEt*!9p g/m`E%e;+qcJ`ևg,>_OK!0z5d_P>13;z^a?(`"SYCxNwRGQ [Q~3OՊLcw"\,o\=lm9E@SIM W>@Dp*7 AFy{.B(;ޠ'Au6J|>!#<^#˗ykeZ3vYݟUHڠH 138jDb Syq`` _q`#Fɥs[wp*dFz|\g0m{!H^."fHP; :Ǫ?+,,'qsLU\%!]NI7-e5pnMOՋXm>1W};UCE b >Vη@8\EIN2/6Ծ Azy0E3xw_"46RMHB!_J@KZeSYSVݩv5q@kID.FTɋ^哿$7\ {@%ua|d/=VNrZ$X2|BbYz_ E=kuhqanuNʂ1I9/)6 prlKw=;Dpx(*L 2K~XEIA_z!Q Z*\"\]'\F3wA ;s_vzVfۜS+ly\s4pk9߷C06vwn:_a+-6ר Yi{Qc-|WX_S[YwRȖUSpl! t(AM@\.;YU&X5 G5i|l/~\TNRqwYs.j(覃uvuǪQHn箓[w NP^X\cz- Y8?b,kYahr֧~UF  <&Vj߸Ⅸ OIVp\+R ޱRq*γy+ cF7reFJ#LK\.3 \RP$~!D >xzGݽ> 8uQB4RNՍtP%k/ڎ^V/bŹ` vr#Px(*cLx-tBu\ CJ?c3Lɹt#MhH2c9fo5UKA7uj!N̼»a\IG*5,H>e6M*A??ly; Z#F0hHq該ܙ0;&$ jߗtWWtnsKTD8(y7E4,srߌ n.K_P]EcÏȽs$*vB^68zTCD̤W!iߟE~?2 joSi%rN6L`5mFwK-.<94(4ڮzr\7wK?w~6gQ; ]v//] PMulL 8vݵ|Uv6A'ncyE'J LmUD11, bjwL:ʸmd;/(溝&(b%B|m))Q5XhQ8ƒJG5=Cypvzy9Cf K>0euX\ Y%~\mzj>}9vXg&4`f*6-ҧҵ` //6Q9g+%EpEFsRVy @i/pt%DKIbQs@L& HD2ku1k=9^Z!g8E.'(%lpsv'dC7~Q:6.?BOظEթ7reQ NT913m.~A9:h떂S/d?&?5WyDP-~Rc&wxSYBp{Of9$6)pub/^EwR09g<'#Q*\ԨB0ø35")TݨRnWJ?g~{7gۉq@T~?mCO?GgxSX,)UBOzj|^ުfWeIFͱm^Jdw*g_~%)?.(@ɶ#nW򋳗Vc8TIWʊ<8Lզ:5%2/'l42,~dH^7Pa8Хc{Θ8os@NwuiBGekx?9Β`+~3O;Ye!VwHD4vPu:Esbas8 0Q!BM}Ib-O|/͗Ju%;Rܭ*m,9r wY!$:˴y#%kO2 x&x>+Qu+Yr a^^HW 0;␣̿b)\o'u[t2TP3_H^K*ɘ] #6#//ȏ>Yf!*IsMFتB--q aƀv'G)A 9VD}VCk`-׬{[BkBoߕ\KDX5Ce=4c,j[!o"TȯRY~PH21%(581T+,JG^Vn}m~p.A<9{_2>T,׶Vݍ 75}@[Q|-u !$HxUtx={4 t4پJ*(($p7زaT-293! lXZ]o"n:vCQ goi$t ;`A'FD U9Ŧ7No%sY&g45P_<2$ޏYME߾sPfp84:嗔ao_L}3q-J!}l!Mk&_s*xт]vh`]oRS~/$앐 {١+$VHsl=@<{njk2x{}{|oZ+tdK8G[v ##*"D)2-T4=X>$^͠N)N3Y iERن.喇6򃇞I$›\N{uS*nA28EB  X&{3@)EքHr&}MefE MhYF0)3$hAX=6n쓝&7Ѷu GiOp<}FP`{_>[1 Kguq,<V>lݐR1Eu)Kf ϗyd4g 9dg 8d@qÿ۬'?pNe؋b>bAx9Ǽ~sSgz8~D.j,DߏWMWRb>/?V5[~/"Q0pXz/09b3v+ߖRIVl>6Dx'3W!1%@E~&: ҟg @ߖ4Isl^fޠt{yi^e*j >EHծ.ayѽc-K3cv1VPw,Z"pje/ ۣh[%eĮ)Kl>a!'S5'ϻּqjٶ (6m&,]x9bCnpC{ m0\3Q LD-#͓c6nwfW% U ֏13Ѝwd ioejXI& Li.Oޙ + j0=[͢E[Ce12H ۋws6x#AyŪNɧUXV@ :;P< *[1wzH_d0  IĂ7l7=][4U AAik,IvfԫVYĉUa)\XqP3JQۗHC[i?$֠ofK{LJ8g-ɑ=v"=*U,$uFqM$DG]c*/ DB Jmf9*@O3:-A!!]:@f|cT~*L.VW~D9·`IJh7jꋏD0H|ȰA߀.8W=bq1+ vf&ᲀX{ns]le^XJPc/ݪ޻dLf .vpDMp2\M"\X "oۊ{X]aFtG eFKtgn-.y8o9ϖ]}t=@ቷ[(;tzX{6<Iq6am@siRA kb-{y"ڵgpG3'[;uL 툝/YVbXf@6')_@Zs artp('u;kp/j)mP\]˅ω6\.ւj6_107_%ǏV$](eI9W%F/؉%eC 4y˗mM:ލ#F4WVN$ߧ#򍎡{v(NX\sh9]B/5Vdr NLA5wˏtd$Z FUX/Mͷײ&zj]a$밢fU>%BY6M킚e_Doz[wSj7w1y@q>v?AmC$ vx#NIou:)ƙbVDza@|6wWi,^h3?[յV}01F ,As <Vq`>NO@-(S@O? X\!둆6 Q$9F`PWe .n]E-|㡽y_+΍9]Q4mjC+5wK1j9%i)qB]=`#:0F.H 0wsM"`iwJb&zߙ %'O> ^7In7qnRa(2ʴcz+ǃ$JĈgNWEZJur:dmmyG*V6ʙ&Q{v-M/t7uS2M% ] V3$}w.[ɽgΔ{șU_I)u ƨ|wV2Z;cle#1<؈98\L*?7E$;3pFr5 J$jmyv&QDuxl^icyܦMy`Up0 I49BD%@:VHI+܂|/cu}v~i)"<̝S6ZhM_*NK[H˛8ƽzRQcG*A9psei,L Js"""[b`m2}FUm Sme0+Y{Ju B`b/ 6(Oz9݅~>xSm B*aZr?n2BW@j>t +}G4nŒ|MwBJͬjBCqChx4Gg!EM# Dl~t<ӺRKmk=(j"Bes[`FlE7nHa5]Vihb|էC#Tql/:zu3 ȁyv`AcPCsD^a<^Wi m0{͘$+8X8\P=p)I! mC=%g:CbD gNUM+Iѥ/'gWoQYv'LJR 4*Yjn2ز0qWB+l܈GVJXhk:1m~axLb-<~d<9X~O:>b%/%#|POҁ#aɪ~Q*/vx%wb-/HhX}ͫ\1[CuyC"W?f\ ahkS<5i*)3Z6jT)#'yLe*j/ l9 (&x?yg4e3yaRx`NO+9e--0(A9!5xFf-ݏܪ u%^Zj0|iQH.-K˾[wx ErM!ό]$gn)|hifqFŖh0qZV]Oj[oZ# 참x$(y i& [KO'OxF *I)S aNweٝ=TmRōCIea]wdo-{1K(Z37NMƅ^} fv>kF8af'+w|vf:QtqHH{恉 Gh7 >[_eh))*ʺi0˯)\s{_oqڧfBvɮ)FպEݲ,VbE߮uPMF!dQĸ#_(~ piQ׻WOXV֠Mٙ{ t *hH@)9;MnSo_-xYɩ2rk*rTOb>Y] ߲0h)mXrD U+eGa9aw1= /*G{E? sq ~!6 J/~t&4B@5$ŎB7T}"5_hOr:bz0hӭ%Zw3y\*aiy_@^& bc%2 FrMq0jnA !SC9w^rZLc0^è!2&e)Vs~JUI_w@m"SX_Ю+s_Kf}8qoHֹc Ob]Í4܉޸[r c%|RG1yb1n|R{HǰP[w6 p3|<+ dd'XBDYrM7o'I/ՑZSeB|2A7j?5@ (⸒<.Ű"5d5 Edñm׀G6_¹ ҏTnX0HťKU8њń#\PMarrTqg\ @y'GsNJFxd/;T~MlGhF5QzAWq fc=+)QR̗Xa&~ [Jś,_T4N htŝc ԨSR$g >? b<ߡ>T{K6ߋ"Ag[4b_(ޫbLг,8g&7aa7sƳM?8L$?tK8#7O:EDz*Wm|[bz5ZrhX glsKCm3n` `ٜ`g\/Z/]1tu*=ra՝8XxCgs*C(%4>?R3 bDo+^2~gI<ɱbG@u-wيf\PPϚ9gS9EE|> ګ5R텀'>mOwʼnԧ@O[$(^ChZH 9}Jj7(r9-J1RiOU.:zH(ld[d8bpI-n7=1^W)/S*m:xN#l)ҡ%ӍjI` <ҫڧ54|ܺ_7툵'|j3j)0> Ua: _`#ʋ';s|;_{ʐ>!#IG"G5M{k\&CM!=yh]Q =)@dHc-aash{rgs. r%cz:<^P Z9&coGB82尳r ̤ENi.x+ j8M&qtdх4u V⌞E8(.qYڏe*LTVl-bJ@jV ٙQ)Ϫ`.K?ɘHn1Q{^#U (_"x`%X,p{CNM\!G<)FY84d(2jrX`n6r$ݐm1w] EO 2~X˰pL n[:׶fNbp[Tv£/% '' zꊨ8&wȨ|9ݍK4qTs|iD!hI Ъ*MKj#pz~BtRW$?eK[~zS/mZ"- ]#^U1O6]Qw7H=]'3] Ȏ]^OjPbV D [/B?VNgо@X.&cMg%ȤL`NUdk3ޘ "vm0 <~@93j L8. öY:yZ)>5 x8 :Rt`bE}Tْ9a9Bm+}nGgm^tп~.]FIu A݄Nipnxqzm1̹W?a*;,b'%D 8%SIPwLRI)uvodK"1f:H`F5UK? L1f\b(xx$zxM9_%b[Ul<\6H@ގ%E- \"co9ql alzEXsO`ƦQ40YXpcaXRsk!IgisQ5C!:eP&@c Ы; 7#$ p[ !e6uAInri~ O6ۭR|yeSːwUgT!=];ēg\ѹ՛I#(9qso|הvGgvP28)_70LTVt(W5>5$耍 .d;L Nܟ`L\P:\t1UI){Ͽ*#Xg>7֔[aVSno5o"dx%B~ iʂDZ6LPEmwM/,^bI;Mp囚F-D p3@m3d++tU=tJdȟoIna?0I,j9PŌ|~3Mldeه-+>Я%8Z;} ODn ʬ‚"1E7><m2Wn@֬? 8Ѩ\"a P^P|Z.J+bw@5Жio&K *iG`XVpqS< w]ڣBcɦcHШW&u;I: Qv V2kѢԐrF, (m?Ef=C5OO({Vl~_U>=fEV"abʙ#]W$MO^r,hdͤa#`!'%A ݯM?.q@pO1 &K04&.u*̬FpHfsYBYi5 j>R|KٓUmDAeZªT^ valKHgXsFqNl(ۏf:WUzCr6,5-:pMe=I߭IGWmgO] eP08q4lA)Q -+,"Τ%&|^6mw>k&L8l=9iB~v&K⚄ec40y?Xzo#"n)]B.WU#3^̫)# COO=T5'V!5PwgY7` X߭}tRc @>EaaL Txl7k Q l[roC:b>.g U Y{Kq( geBYd? ٵa."&[zE98v'u$gs>xU^]b 7o}5W)ejPB3ݒ}2:$( |wi "`TN6N<Id}~5E|+盁V.ip$;HGы@39u Nu/Cԏ*"j+lbY d*~L\*7/m.u_Yl$GPƛ'"Ƹ7y'kߩtStʿJtMaB$ϓC^ C@`f,[S- 7a=btd)0֌1N¥uGqYhV;eVMwM4 ~)<5Xߔ| Ze k=Z Wl+(KZ`F9(7|y`gj]&&xK+t&LkZk!Wf>n?6rZ_̶ѯ&!e-гR$Ș5owo'K[\ͪ)0䔂ذ%E*dJEլǽTdBL)=}8x 9C'f[%U@ (Kou*/mCZS,c|tw2;VFZdV#N¢(zhai}?=r)M}Yj4 I70\ɏ-*5<^%γ`uRV' X^q%/ӟJj׺q5H7!hQ?úͧ@e<^IJ3BVڃҁj,yU$bYV Nu Bhb9/\'9vVݗ* x鈆Swm>ENNk+~Q-aAiA-CTb\;IYhcX݆=興T Ϻs$/7]dG2qW*joF*,ۦ蒾#IN|4J쿹(&NaW=Rc$H"BAB?Sמy[҂ bCإhG ݖ\ xTu1-gg:z`ȗH2ghw{bFw% +y8n1>DF?UeIRd_51i(,CQK =-1T˾+іz:D؈mLw*@2ي0q7ǡđ ;+gвOl1h7e BΙMgũIEwAm]aVXJFOi37 :QV6(kv}(f5(-OP,O<@9>z0PF`:*W];?N;s'mUE)ɊSDg5F7<|-\}bt(?Kɶs|y-0;}cvz& Dv,c,/GY8@+4vps"do-XE1fO)\@>eE +:MsR{EGפ'A՞MȌsL,uL[&/P<2֋W<1F>1hIyg\ؤx tYol-J> ߺ :Mh8Lw./mEch2NvQKG0/E}$bAb#DѤ#[O-*p+=4;I(׷͉XN%tT,x%n3d\'x?LAoc)껒bKm6j ſ*7o:+m2}]?fǃhi qZT32JE(rK-zb V%DɁ߮-^@ tro1Z{Rj؟RYLcva~3(oaO'/xc6ϼA꺅qy;}8cU4*XW'kfzsy\Ip]Gj^KBI)YM0D$s 9߷;WYe _=8$/zuX"P,3O>{ޕ'4`r@b?lbW bqj0-3@ohtL8>bKE4^ΐVĀN'L6oT[38ש[M9D0^-m_0}0]H{(n<4U%'w%M p*ib 5ZYH,`Ɣem7:yx1IDbqݍQ{V)@Y#e[|\?{xCcZ>]vet Tw_(GH~aϠ]뫃 1 o)w-/W*i-$ ǃ\婁Ԯ @Y2JK*UwN0WJFz2Y%7]Gμ*M";!@/7-( Xt(:d4;"*5I &iWZ[Qa]vmBۮcuC^FqK%$y 3ǏFeޗi7EǵFEwʌ@iA71 o,K*[PF~t~1ʼnV]#=: ,7Mh!!ḡqkJ`)wQ*ytPj?!M.eɯ},dB}!&$# (72 T.f!m;t!l-Щ 7  $HN- 4w0/<17"~1:h|3.{`=تQWOtK_gik_?J/ltꭓ;9=2f+E0# "m*3a1uHUy3Ѯ: KK@@{j:&2gʍ9XAczWV|  C|d_]`]N#b\~ yR|^noTw;(# գ Pq-I:jB 1 =OZh;(xu*# )Pz@$v; ,8i&,]8:&|WE`5%롰fy<%Q:^&D 2 l}Xpͅ3Uzlc4bNnΜ`}{.Od:`t{Q9&߂Qrٿdzc@cС ܝsDx4lMw$&^~Qe 8ף^}/CᘱiF铤I%ρU*.u=˾.[%Ç@&hym^7v; ;pSt1$j2]8@,,67+C]{fȝO!x vzdZ+(;Dм~ d= ]dd?1|=_~Y=1At~w!=QY7}S̯KJ`PC(mTb R.32,>"-7m Y=$^g̈́7Tc] Ǧ*Y r(7 x5w=)d5JѪb 3 "e!}Dt+ w'I4FR1I5+D\w|{/mZـ)5~q^O79 >qAM BGeR2Ju@˕EVJanQ P*_X8t3{: 5ےRoIh *ҝ&j '=ϼ Oo{ۮJR-)zhbJi`ҊYgAT[VȊ8O&j8ŋRѐpPc݁Mmc=kYN`{%呍 TߘrZCLl!YC#.}㪬n`_75y{}xȭHgiEeJS`O~ 2x.|+XikU&u)Wn/A"ZS~sY^Q3-nBDbͮnt_dMbf ȼjrS5GE21~J8&4kuP|UYn}Wc :d(sK165M_x=IL2G6-rn; <4"GSQK^(]?w0U GEsI  YR2V^yg K.0МQ:g,䭯;Kibw53vImc_,NqJV|4G]u@K0]Vtp]\٣bJЋnOp.usyi:xXe :'muu}gx_F*E=?gLnwR Ld3~ `E;ZdīتzT,w\ (_8T淧•v?v1`'qLˊ5/UdߢPdTtK^g(2mԟTb47/ل Y{c>n5 )&5?ِ'8KDŽT)p)C)Z-Հwנ ;3c`Jviq' 4؃V{Bҋ%Ɂ",aaX6JÂߣr3[ :p }*3 $5+y4ݚg,=A GHV.6p[sVƂ/(xFM Q(_&ZR%} [>L$0C\G ǵC l>>1G^w(}`d]dK09@''oi֒b5iq_~hĘ"@r4O?(;'+8D¹@ɫ*ƞ^Q0MEE2G)}5C}sπ.|sL۲exik=kK6-?T4Tl^$C1騋Ec< 6>0Elv"vȳ3̆#3`%/:aqHV,nӍm:xA ^H7N\~P"]&qO"A/0܈I[HF=h*_84=_RS0S'J8]k)'\PXڑԷ_>&n<"h.FO O:}41-%$'#//eTS35+e%*)P@X,r I =%aD=!fO #\ғ,̧u+ g">[}g|0~e bV"#]G%+f)_ ^|k[-sz$ ']4_Cx+| _D?_םm%S9eVq(eHw\ZEӐTpNۅ8RM,d9(Pf X8Pά n hG?'/>f  ؋NREgK\dvx$[ |.:/t[KYGv.ܸxKCFS1l^`lN0NOΊ ;\j5'GrNy4(;֊BMhi rZVfhuP>x\IvB]ڹҿrd|9cxzcT7P|X(XS6zj֚ 8בtyBzaG6hmc$N؀4_W>hY_X}~8>~sǖw%^EF/]ԝ PVOJ:IK\ѺRꬌc]'boKWwT#ϪxvT&_q[Tj20/6lDdl{];}a=y"y&.@.xgNړjCpvY( [w==IJc*UfW$fC/vHIcz__퐕 젌:1 :E~Qښm:,*UZ]۝ auG;u;ݮ儣ݯnRG Ő!9KyKyؘRsEJ#.Xul.W^м t :[~-kQ@. !-W-qB (\r$gֿ3h,,rS7~Ylm@$i\ )yN?";).pᖊɜ(B-㣡f n?3\x#F բs8\YO,a׼;OᎺ3vȏ@M֦^ZKH74dίShnW);#vf3S"E$LX.22BgL`_E4ݡ 8ݒY~Q2p=kdKaI1m<ަ}+N\πvT%/0>-Q< ! )dXwO nm8!Q vb .o a2«%KEm i&'pK DWL4ِ+27ԥZ1tSŏqmW(Ӆ2sMMƖ\ @lFghʏs@9;[f IPvMjհK*How^(XjD$X9Z-!㦦+4]-Rnńvcbt(tg궼7UXvIJ9q:ƟK~#-O _U ۶}CpoPy.R5&P}!q_x4B f&i vT=dGRMlo ~창zLI++k2J+ L2J?6`=$ʀL8vFHuII ai5:E? jɬzClVWO١ ﴭML/8lɾIi:.X)6F6I7] FXOgɶQ 򣢮w(|wfJ7*?8}저|vcڋ!)aMcs!Ĩsѧ\q'<&Iұ6mPҀ=mr|izw@c?F!qSQ D.e+z)!k]aH`5Nx JE>HWbN2,͗d< wgQZN{r5Bh"C8ft"BwpESWgy)ծ, ܄}9෇l?6|&ݞę {Esd ё1].(ODLtKAR = RAF]A>{\kf;J3$2TGp}4)x דIHMj*3"(߀x2T d[s̒c0-EFzɃaxgAL3 ԑnqS4q V_+]aYCc)gdf7 4tfE>yT}d &-y`EE/:Wb O$! )Pk2:u-)+/6W݇<=q:n*!$S{M02c^;Ukf+9۵B֡о* h=Tcb_q_xzG< `ltRځ_J!t%Rb6\F#-SjHyM&qm\4")چ/N~DC6mBIw|}qbk1]3=D91ͩqXB"3|7!NC@>?B @a/l myXo(J0Mf&D,`N&4 K~JEH4uW6}?sPh `Cx9"M嵈))KUg uC ;UbYtēg/B ةC#~HSr|jH7HH .8\AfE*\ ّGAȻ&E"WBl6T݌˜D7b2]5]6reqHPdz~N13s.MГĤsa&wA::|=_-v92RvҜ;߫J;#%M})\vU=a\04lxeOKl~- Oa"E@J(pkw/)ҒX./#wrA%pgՍEU<{$y&<إbp7ܹT[D-QH!\Z 0ȧyuB_U\6aZ\_\*)^v{xaf? ^Qw0uh\**. ;k DXMNq8ur!=VLԕ7whaIaؼ]˺-Eٸ)/^g2$-,Qy5zUju3&tRh_ '}&FB#}廘$*=+;s}w%ąJj} 7X̱rWs0i1 V67G7~_zwd,F5D`7̖mÜl%0OK#"-[,j]ƣjKhP4?U1WS.7=h< XXWaSAi$b;۫.E~KA D@/s/~'@YsU2Aծ5 ~3*s0C~R|^˛Z{fe<6ϒ$V/EfkhTD/ɍh(ܺJ%&~+Oi-I*:>79D% ~ud!PԖb Ģ*z]Բ.[K d(rԯ*k dӗO1uav ޥ# %/|YK=qqOl*&\sP~CiX>2^.~_ֹK_X3WCC}`-co [lpM=jtfV"Ա}oëy0meGFjDG: ɫH仟zgD;AGbC˴FA֒jn(b0,>5Y][7lYO$5.π9Rd^ R; hHr(XePWx4 h6LJ( Z8z?[C_ yr,y(lr nlx Uqvfa+qأ%=imdiA~&:]M,yئU[%'QPE|Is/,ſ_;h6.䳏SVa}8Gkaqp E ]2أ,4ܶViCf0DHչI:%#z4R@x9{T1F1$MfQ%KT_i6Ԝ_Jv\TgM0d)U(p9[z{w|*h ꒋXJ P! A11PiAK0?|=~bV|jMt:Z(4,MqӺӾEStE M9AsB$LI>T`|<*k-ejŪ"nSR}?TSբ"sA箭`r°4X]f?2:P̈́Zߠ$y"3k:>]af̩fʁ*@j7|V $o-׵Gx/iڟ0b!^y1T;-LZĐ9=_Y| Bb]\e"Xp' IkF6l<ý( FR߶eC@8NݭRu.!ߪݻ'4}[lgfs5ʒI 9F9TcCZZ[1qkKw rEFe,˲CL~&`m!=6"tdO@g۩e1Abn၊w&eEDl>KמjKÜz4N%+Ñ웁/={e >[RESYfd >Du~]5(nƘOBa>kOA%&qzMlRwJPۙHe]ZD@2P)w ld= r8rGjgX#nUwN>i2WO\+6XCRbQ?*ݸ<㲿YwX9@A/섣xO c炎V CSGn2?ǡ>/ Y1ac$+Tj.V+fA)||/ƕD/O%]@pszY:%/3hHge%ȳ8ГWK@ImzάPup]C'Cʭ#A#R}&yO]@qokz @!j iB&?Vx_2VYZMb@sRA-C%,4BW#n YFړWU%EN Xc5ZF^6c6@>p=x"gq˼L,@NYJB޼{3Dx2ٙف"@1 질{_G E],MY٣ؤ1r&Gyw{Og`_sČG4[¢QNaA3ḱiۊ=F2YBZJ*3XjΣ6)%dqι~>aťD'EӅ{2diY+lq0۾SLMNяEL'8G{oNխGPqS\Faؚ9Gpd?Z|A{?ݖEֽ,q?T?Hqك.K3<I$ͰI MjKQN~ǭK^l>oW7@;}P :^iX{tmȆ6_t!5o+8\GI `ƨk1*AF/K2`ڈHLW纤%> Xq/{? }%_X^$s@d]d+bm{) TCcES8p ^]C]Ztn5MB~*k =k&3@4=Y7T%iX<\/  j+$lmt Lce<3wO"u|q>>aT/J}i#W$CN}k| >fO|)}b<5Ӯ7+{a!d-@蝏)'*[%im_ 8 x-TV5JTkcA @n:lJ{ħAeMm*\Tq8e(_D€A;5 ]CjtU)'a:WVKKs|aY}s7_@HLL3@L=Al!ۤLzAYģU{'`A&'/0ñ{C5Dgs'[cŽC:p**A?^aN넥t犯^U_1/emAV*%PDlk#wkaz&z蠪8lKvVc~qqE޻s%y⋳L -#p'DZ hNQB%.K|OJ:OهddQȂ^3>c)2ML t*ܖlIa>b6() W#{iR'@nNrKli(#IC;'!+FwAZN#9VBa #vޅrV(AMtac6<\,jb?8i I|ӊC:o;8Ѫ&X3H7/4fFnğؒ{=nZOH>FƧ,118WFAgےΚ9 7ũMpfmEuGZ@6Dt.Hwq0yGVBq6}J j+d;ߔB*ۗ؏bo缔ZW)yED J)CA5da>o_(*id;Dsа(14ͱkqX0pzFS&rihcg++t5j~f_Yi >6z G4E/\b1$~C}Vkۆm%Hk@h2tw}A+O//zk+MlqTԘnZI]_z90̿V-Υ 83=yQ\kl"RoVfpQq: |4I|>wdu<ձx4%vGDnB 8GS /XExsF`ceS/,%㍾SY 0/ UP>Je8P [uWoҼ n?OmidT߬oBZujt4\R7SF-C Ih\5bvm_ =1y"}.8s?Ũoyĝ5jwN˦hyYќqwSGs)U3HQ KcQI(O̍m9|dK!O޾b kn3C- L?{@))K R|Cv*Ѿ9u /qd){brWS+0d@ϖĦGa$@ulUO ?vr~Ϗ< ಎPhȩ CnUa{pKw-ؓAT{8xPcB[.Ըwqy OLQ|LP7`89˙ӊdrGmAEl/=yyeSTf4ߗk<~^לTīh1w:006m_So(k(E7`C(f7@[/sX}LN`:I+A_h.iVxzʪ)/2^SHUBvI*B`uH̽v-`IDVzIQoe\k3n"cVAYȍ~Ā3a=gsa?a;&V^`jb[ BԈo?'yCR*rY+U$MwCS_nozkLu!b=¼6 X@]9@D{dj[]y6A@6gflZlF]s5诅ʣȚmwB[4)["{ig w`.]|$ë4==M=,;v򃊳Lmee=>2ǽQ"RU#@{QSEdNGVTb=? =Y?%Rl;~",1?>70Y҄}w7;H[2!|:F6\7?)ifl9n3F[o+, Vd$^m*[*:cDۘ.!E|K46klCŴi.2(hЖ}Ket ^W%f  n̬|.u^;N"g[85&}#oTq4F,2^GzHH[+u%y(,zV̗p GJ5?vlv\g1MSE%ǡwfb,ĐuAxꑵ;m<{L%cO SzwiM^|lkjM |?yPs"dM;5RbS뀗W)jv`HYCht&KyߘI,KǏL+ud i E2y(=Yf-uK{^8vVs%}"iNd~UusC/>u֋^=ʼnˆBhr]ܖ`c@RxAұT5+ Cr;{!{k>ϛEf…ʂ<1<Օ i8ןd2̔s3ic pj wyho^.HSwzhI7xBؗ,>_2a*i&8Ih@js;Py_좇ԞF_@y`R|ZzÚ0i_JɌ?G^ҥ$@t9]r(4 p25|? 6b/7FNlwgaCE~taU3UǜUiXy>c ?] #1_ux0};%f6:E=QbmgyJ!'r kf8Fo^!׀!6JF 5w7Q^ϴuy-^Fn^̛dY> mDGٿU$Y[! ٙˉݡ|G>Ѡڧb3&AO\!51װ-(yY꯳۱çKaIrpK<(u&RU%0#)뵀ABr$E<^=d  gwC uhq"KG-juKgx5e7 [)$RݐrW3)t71<3أJ:Qq()Ptɻе.( B@3S}(K"flM>;*7Nzj?j*'}zbug 4tQ((q|6v!{sCL&V&%flECwpͮ. ^5,Y3_۪35wP7w銯61Xx Tm@+N]\iSEEC#aZ3OS_~MzaU_Z.f@qsU+ǐج}K]!ɔXtm*}YSwS`?(Dk2AB%੣TU-}d#Ĉm).7ѕkQ hUaᘩTG-T):+RJ;L`nTބcP.{)(8T8^Us!H:š*v`$Ձ(s%n/X_Wp5!&%U?W\>Pג7cչ fsJGg{?"0Bj-OapZ)zKj+iҾpNemk/eȥOfH.͈2|%xT^Ŀx8oL˟`_flOH' $ 4boxDnВs=m HTGA] ]RMO3+ !Y֚D۵!fԂJفD=j UKgf3%jD!bvFjs]wo܍ ^Ўa 0{"/IJ&N7G>D̄J*z&@չڿr%M`Dԓ f ^PVtcXe&`Q:Dj&d#3WMk. $6VQK)ZNtXTOMD NRuMЃ&]|ϟ(88wG{Ja]&K) 4ՠC-wVn%^B9!leyvw"J =mס_!kg}DXr GypB8uYsiq9 K#k]'Z`7[QbWqC-p/ui-Gb>T| Zd;=燇5|`dqI{2/ 'fY-Vr(j ET+@}_mƗ$ok5JH(h5ӭeZ+N80ҷS=綩bߑoM\o#y(#[x=@Bܓݧ6Y%>۟I *렿w|;w kPī< хv֣&1/Ᏽ8nH@^hIK ZĠG\ۅ,v9Ƭ'j=1l]n}E**Ʀh0U7tw+0<ͮA#7XaG5,߮*NHks0ڃGt)k*:-Rw2}M޳0>t &Fpp]ps)VU>ֈȳi)oYC=r'u:k~sқpUz(}gCh;~iW"?.WzyP?0 РI6`;jg攙Kcw#Wg!xj#$aq;DBּKA}AyH~$X+#/~ lqĦRa+qTlw6U5(U0_JW[mPwE_(5R6gD!M-UGIA6V\[;i6׎1M+ ^erq=TFxP|p|Xlo֟W,[+|:0ŻU4iy~-刐6Aqw"ۀH-2OWA.s^]n+LHz %uQ&I F*IkL嶼k|SR uKD liWG2 oz ʼJvpoihOEmr0 ~{X8ۖGwb|)T/ډiT(s",py~apݑk_y5E-F $zy$ 4 N@̌@gʧ9cz:;*Y!h'l>P:F;%kCZnCHJeQF2ֶ'F^X81z& 7[1iCq#~&a+IHY[}RK1{0bVp5B*Ivcm:.ٌ&N`,̷*VP (%e1@mgI)x33Gݱ+sWZ2zu|kͲ:jvćH-i XNfCH$U]aV Җ+3i3U ys1濖7nym{#_SPoFfٙ=Yb [G/wo61̚[2GESOµFKP*D>@1v HΚ!eałM"o٪W0=35#<+? <ۨ?+N HdXJ&FX}r>67烈N5lN'/U-[?J/l,A{kEHP> H`4\-K*.hTt-h5Z-Qt#AC9u !RcÈQ^35gn#26IM #`'f:l؜ ܎boq}J#̹&H'U0t$8d;bbM8 ץE?%{XК/KZ{œ\=҆^0a2ƄϿ/2Q-unЍDFBr&*}架P]Odz9"ssP^Y8Hوʥ/83~42ӕ|=CxM7AHģ< uL|KMP}ˤT$i?7Sk#Q6l x="j|z0XYWޣ 6ANF:zmIU=|Qny88USV0l?DW_?~VҬ%!Hy鴤8OՂFpXsG)KFey! %s^  `jѡ5WNQckMRI{ȁ=WDGq_*P= JGmbM{Vp/6?Ȝ)8ƂWJBd%@T[EWI[Kh(MPgj)Gަ?5<-QqiÅeI,`ml+V`=t VHosPAE~E~B^%ЩvKmPIU~Ҿq_؈-PʋL&fM (nLlj; l}TDDå=~ydmtYg5TmotQ}KZٗ|E ޼(dFNDaK+' o]ο~1ڙȴL: 7VjvnKzOs!zIú}Xdz l7Jq B.EgIqZ*Ѯ8 JN_u>hʽC 4>i2[Mk}c B>c;|U0Lb8Ǭv:9HE=Hx tXxHخ=u`^Pl6B:\98ANm߸jVL@>. 7}&b䰗-BcۄE :c};1bpe",Ay,!$ϲccM8zobd/x`ޏe!)<:|-,&SK؞iyv|m0jjo~&/-QK_I V &0ܖX*}֍kӢݞ!6&mO0f(?ꦿO=$8WOhE oU\G/}Ұt!Y{~a.+ڣ׳MIku@(X4DYKzA#6= ҕ .K^{e(>6ЬtEk |U]q3\ay AGȅ`pt{_`|N1 KӬe>=ʲ &HѕBh(&Z\Ԫ.d*[\Oa-@y4-7x=u HOĊ,pdDpmdZ,F6z(r@_ndܒweÓrJZq 9(HLމxvrMLj̯Bp%2uJUv'OŻ. O8.Hp'ۘLG11uм.jj t=To6WRiKpfAey]Zڷ<GDYA[ѷBwUq< Fg, rp>eX'"?G dRU ^UPY۔qPx4c4nEXmӂߩ[WkȤH;ಛsL-Ӗ𒐟 )sB?y94SB~Kܠ0DJ F{D9zҔezÜ?R$ؕ&#tJ/UHA[)3xw)b@a.qGM2oLERdDQ31o-e.P3Wh%5{hhYC!QJcJ|j.'5ꞩ>60Ԃo4ԓ.`~vI\}6h[\S`a:n{L `;a":r/1f2~a2"a7Қ!}OZa~Te4!L* q%k 95STE1*p+D8ze KX@ͬl[ā{vr4EE>9g BfU2mQ]^țZuQPuNo XYTz'-94N톝H*ʱwCV(M!9Gyr|edAi@ I.C0{ w'"7D] ?\B jSqBY"r0 ]q]{Ee7TSnT(v{hf{H@xnŮ5ko-UEJz4|x V:U4)c1l'@=(n{ ,Yц/;{ 5?Qo-pU]濺} aPOTŭ9TP"3-Qu~̲'j1dϠ1j?#z뫎G8zz$ 1%ʗIA?yu&>l;fjVZjlNk79ބCbcV8"+9md_J.fK'b^x^LrC\QÏ"IQ!B[1QC ;p]'p] C \("hE{U !ofJ̮QLLɝɊfN5y>Vdz: Ms쨰:Il)VoX9r-y8-WlAA7QÓE'"K=/7-nR$Sٴ^i`x ]Dj)9Or` 8aƾA+j%fo4q,֦>HAWƠ>]*ulZ2ʄ(iۿ`߰&m5`v'EHo}u&ZDɈ9z-1P.R&"=~rhZt]o,P/=MHf,H/6cL\ Sʅށ'zoda9*#MGu.6,ut-wf1wrl 4`P>6ɂI^Wm3Jྭ|*g ":BPsZb՜+I$\LLJ``F ~g6Ep8 ׿F vgA/h}:h*UrXloL]L`]\ښL- X݀<\@HH(Р[LԤT¬TYM,&!{-.g;)tlJԽS+ 2>2ҿiU%߼ԁA-jWqjr J{5@gc #(;/D{DI@C Jxf{wk6w 0n=xᩣぬ6E̼Mn= ti5N}D6;^puQaY; ػ}7$k;!aBDLs=Ni$@NS94rQXѥ" Pܺ%>z^'Oq(Ø!Auye*K!O%+ك??`}MJ)YSWl+Hq&Q@l)]'2^R Mg0[L 󌎐ugxEdĮOD%bXwFfZMw5c_Y|,JL,hTEw-*m"6wcAva{] *W]y1vx0jTƢ&_^_OO,7<E=&'YD3)1am <[c;ȳ"nWx뒢4 E. Q }19&6P $vlYD0P)<|[Wʍ9;R3Z":U0wjg\Z.o .|}@Gؘ`k΁sHا_#y=տ!'KLHZR!G p~b0yfUB?(ơZ$8oL"ݧfTig:h%,'u09Z0ږD\0|IXכdH9ֺ?31#Q>m銪u3W-h pcPuBmM(agd]9z^?5ǬXyPolk,b:Nv׀5},y˸g*'P#} 1bw3]^9;9!%7$gAkJF}hwr邅7&":S?Ԟ <8LS1١L4hu7YV_"Y|fhhߺ3fVPcMh@PAgkI1#w xЗPdKmd1ѧ˯0[,iearqY7lC&,0,@A|5f| `;("_I*GՌN7ze% yNol"/zr!wp?8ؘ[j ~G0i ({aDRa zmb7JxU \-0Y,O٬>:K9Y15)ױ,z nJy7ܾ}|t9;%|or;l҈'>Q6*ayW \$74Im55f1v{7e]ŜSs_?wUmyf\"B  |!*R )w=Jko`6@iրÜ1Ce|Ūa.j^hq{QeB 9@Tei䈷T<EWxZOtm5a\^#JR Z*:ʊGss%f<*473M)UL33 ;"bGwc9̨"cp-}q3نڨXĂ, CP$-{ fz cwէjdeĿw'Zk7XRVOT0(íL IجryEw3G5t z atpI| uPO QI?N4'9eiDZm*lUA%H:oiEKg=Ve^JTp.1\%?8?qmej;CaH'o4KrI%iQŤ߀BqZ"{zug QE'2cטJ͟?äɇoVOm iķZܯ#.f_WUhWvl8r-Af-,Е46[Mћ+?'/XӤ#o?s._H}{bPwG4iР T+ ȇ]*VXD"(9p`29mg/s4 UU @Z0y!ͼc0_jd\uM6q?A*rJ' GJ Uԑ#6J[@ޛ-g@^vK%db4~(ҵt&e]+tw,(mS1=!e˨YX/E="µ>[_e` 2FtVbfw t<~,[fSۯjܖG[)zR,(~@w8H3h錽ֹ3^D@B,678W(kZ35`QgA|5o` ice;`b#% n/ =d!ϰ}dī3Kc"emUXŰpl<%Bڱ$+2л5AJxƯ|Os'k,|RJ.x֠{VQFedH:{V!zO_5!2f)㴧Uyz`h|Bؑ.$AyeKEMΎT^]WÂ~{:E0c^iFb(?8rN] 7̈^]а̭Rv?t+5x/ ?!.N?lc@ͣ?gְZWA]ڑH1XZ'MtRǴzlNR=u%MT`߿pP4*+J`[D5FWj_x0 Jx&vmՇ d狵ZV1WksR 0 z]?h/OO^615dJP Χ<~C|FObJ'MX@;|Y>6&#g LaFʼ?KaϦ۝}d39َĩT:Ƕs@Zݗxg[Uuާ*WV!Ư9[{Y¹a6L^Cߧ^6tg2ϒ^|TMQ?G; !ۈf$!^9+q?bDQF*l1;3첒Xu-l I}n)B:]L釋fM @;`ˉA0l|N?!.*ǥ\-_i2IDHkIUΞ UUXC9lB%9XrChC\:/ʃhC}$8Xn!3lu %jF4~c34"i~+イzk_|s#}|AsR}8c>)UMvH'ǙuRJ/U,_o$ |udK/mUqpOԤRI[U҄{X4`6'Z҈ WF;#t^Fi?ok-/04иSuԩ1:}rnq0 ?R"NP]w̮gqYhZ8@ipI9h7"Rjyh >ImOoE;8z"wʄ=MlIޏu`?۱&\ aSmul O 5շvh=B0?O{wJT%4( o[KޛG"]F7CreAq-j⠋i~X;݀6%r~* ߺ @pڼ`O/m-ʼ8Fo;"5?XZCPnctC6ݟH=[EĸU ZTCD*,gk+0:>$lJK=Au'l+hXs1VS˚Aq_fkzu] nhr|c>yuCS݄o)7z+ۢ byÓb f͹6piI,@Uljel*SsbPwa5㺋d_,]g΁M&"}@_a@#VuTwhmpգzn% _ĉqe%Hj^=[FlgV#kpv7}HhPq2배GڜUC cj>R.! Lo7l28ʃ޿WG/n(g< )B7pfߨ%uI}2S},׆mK;Jŝ2ڥ7e&fJb9]$D!l/i|rTqolȬltHȟp!H=ه^}}_6:qBSYJļwU2Q ߲:hv3#-mHxuvp8zbiNM`\i2D(%L?v}C`RrɋUD)'*!ooM|\Ha-G,Yy'OTTJ[M_9Kbhy[ځ>xjc!N䮉ֱjʍ2£aM-탟~wN*H]cfģr^/X0q 2ˌ{``[P-m¢~ Z!Kc = 93;@B۔J;{#sC':v)t)ܜv~i%(rUt;TT[sJ\6 mV|wɡA{QL6JyZݯu`yNA;i.qH=x{xWt_vTXfR΄e`q-jf:;x%=x>C6b Z;21ltV֘b( U(jb_thf~`,(f7%._\n~\>-_QXM!;=@#ENkNbX+ci:KRۦe|!'7Zjs}*fAȭ9oB+JxV13m2{5[$7.ݪ oܶ efv@"%x c2tՈ? h3M5O ZkRRCj$QG=_-C*JpZO Vܯ?}p,=;qn W&~^dXx]n$Sq&g:/Y.@YZ͜/luf<^5tW>=8XÚ,"0pO]5jkVo:ě %ȒV F\kTidJVr[/W=0`5|TF/{"zVt]IKIﻔeԃ]2sj,kk$w ڱ8pinx 8%1;IN̜G}}d`hSM9)[B\F.3H<3,qB=p`+I45 8+F=2>B%2jKVQXLQ"3Y{%4/ڍS(f1ͻIHno_dV* ęO' J(>2EdDTڗnH>b9b@ni{-H.FAg"% ; l;O鱯8E`O `n)cH? /&ӊ >CiRQ㝨'^(5D(S\bmJ¹?tz!TCk. O6]k%g)O@ Mu3tvBRP2n-cٛL=,#mnL`D+OQ Tr,.͆w .)T` 2*:TEͼTGT!q? p }[:_9=!nxߡ1޿ZQѝ~Pg:VHT5Q\HEabvhKQe^c1epY74%Z'*˔%Wk@\&N 23\$WLÖcpE0 ,6VDNd*JqVHx(N;.2v8t7A^~Y.Sϒлn j2wyhG"K9ȑc/]XjgÇ{3I {6:͛1(iRM֢{STa2u@a(<>X߭ ʴ,}}h6qnЕ -3,d0UaLb  Zq$>޳2@lHBKpo[thIWpHg)w;i~\=<6@x4=! .5oB(lb!]#+wUPJw(V D([9X3}鄰xRO:Ȁ2՚6HX͐7[wd^e_wśh(5$#41kv +Wń־4 M>vaT=0[uPcL3Jw#:P2BKC#Ot̐_Ӆ& cuH._=C.r΍_ ͔1;+DI%PUK  8]z k_1=[)# ;nB\gotw2LGo4u`<}c_6)9&AD|<~e!U ==O^hw>\4щo0g9A1G"k~j2fgCSf$e\ʯ8#b#/=k.M٠`>Z tkP{ zpE.}X{g](njmbM "PM%*\s4}xHe9#%L^V棂Ht`TcU;im#mjf(0$+OV|@ݠէXQ1EDAK=~?E1j1FX?A]-XL| ΂r٠HV,\T9D'Wy9.j&iI^psCG 9=]0/>Tpa d/`e>.$PS5?4aG}d@&ITPC _}o%ڴ3\nA&-3h.JbqtaS&T'ņz9W-ZB\gmIo>Lf8@@pؖ_[L"sGk@mfKx]*olqjDf4{9/&А8>ķ~uīH:1A1vvL򏚂+ 4>9`s5؝̠Ͳ%h w##s ذHݧWY/~q}P%V}N<}~  bM.DqhY 7DsOԄ$OgA9 Q]*p&"]j2찘*R{tU/oTGBR"3IÝW[ȱP)+$SӨVe΄/!4iITC !+RCsJ\ü6V%Ixmx ߶| ,K~lhl4?,\lЀMչkUE)cX( EJSdTK ]sӄI bH8-E% ]S0^-*7cp3y/h.=UɕS)6=HJ4Q= vtE?/47/t}roIi)f!LU"ݰu,妁T\#45|vظ,9˖3}u,lŀ_6Ч}[8Jv(V"ǧ"?Clv˥E]{YE)y̍Ugf{u=g ՘N. kGY: !X# Y[ɲͥ{ch||Zsz?BN}2#J+ Gڊ()bbݧz댠90R=4ʬN635eDPQq#9W Rv%Vuj`U0m =p|6 ıJ / L >H2?SN%xܨCVl~7&?_ bayl &l` A}^{%j*(9@z!ʸ`ԥJF4oxb @.K03+xH;|5q)Hމ- ihy_C,.i6ke v:60.O8T QWlm纜 9U[Ȅ /V̉x .< sj^Cwebvՙ?nf06Yi->k7JkPJ/ Qų >Sz׏ y0+dMσO2^.ڕY2B%ZX^Ѵ=X#e{=1Dt$'E$/ .7}f%כ,&ݖhx%wp!P9+pgu4;e9#aOA6t߈g= 4U*x"{nIxb~¯A9ܡʍ@}phF67SX~E:@]`RףߛA΄CWhтc ϹfJh ^Xm 2M쳥mMbޅgwcaDN'- ߤԦQg'Ϲ/>/C@giI\[\be44˝N5 $2X+[sh+W5Xg5B_#`Z%ډ*Bd"Q_>Kz}[}9KV4f!WRӕlciFu1yr/@,q/!JΩpa;bzZ_Kؼt?/{~U ֺVL37"y*IsbZp~.Ԫ0 tK`R}(ek~]Houoݗ5K f3Կ!'v;SKkztVF 5%FY_GV:C[n ˘͡2G%`ʇo5$mFư6Ƥtu_Cx !k|k&%Cz R 21w@;>Q_6%_VR|1 &shpEb&NTs1ŏ@ FE~ T읜f>Lj\=1UE a)/{N҉P}fxfҝ$TwUw| "hz4Tumi`0kƞ^qRW0ȠV%~ )73Ro2 |)Z}`k8c^ZU]Bᴕ(r"b7Qpm؆3RENKpv=IO`F<}*}hg9.y*ZMu{R1IQH6bW9۬)C3qԀ U;RsQB CCmȅ!&b7n >-dqf^aLvѻA]寬-1 *?;8Rz+3PEy7^p-٠.,nh)9ؤQ`p@Ec  ,3EQQ!kk̾#_r 믣]*" 08(]#Ȭc 0Tc e.#%y.Ɖr܇B0z 3p2Wm0jAҩ>>D&`٧\0OK˘9pܞ{PW΢Eҷ K9c3>QqW$t{ckeb )@pC~p!FϻB>Yzl| EmkbS+Y<ʡ ʈ5O#%[Qj'6dn{71ɸ3Arcꈼ%Jt\v%: C i9+CꆽrOIaY4U8X*թk4W(a$mn]X,UBoC^=Gb-o'd ]Ԥz%ԓo0:*t}/ K-A )0OәPAYSd c_W}R)m_mxcz^$ye^{ >9Ҟ%?\17oHjv(DO(3蚑j'q샊Zorcfg~!c9&oe2Hς]_%rێOX<{6"o;ݻ1QgD+^ηCD{<مXUd0j_:ƎDׯO_ȣ%A Wo$,{cB,={[FtX3wcn0UYC Kh!2zl'"fk|ZrH#N(FeІ$RdS)ftYGЁjuCyP+:!w`F@ygu1Z8*U!a[ Ac7#Ьit_)|}nŖa_27Uۛׄ7[~ᾮNGu4gs{/JI)Z`; J#oe@u~:KY~:H|fı2SA-N@mm6L4x-@݆NߌŻ6S?W ;g4:X?Xa/G^VFѫtYb]8mV/c~{%Y: >XFk̶y'y{èC&MVGp>%ln`@dD܂x^e s9}YnU9D=U[z $Zqվ6̻b=F ߀D#&Ĉ´$ʇwȵzC`O:T |˓RDV*MN0?<46:MDhA0E7ii ` {QJ##oWmZ`JGwFl9_ _p$T| y =`'_'T&1w.6_Ls÷NBNx0h$D@ϯD =tMKnVcX!1JDزanwmфnrZ;B f^0uח˖#g J qECMpDЋ ౫f&e{8QHx7|GAJXW!ԖnoK5gD>2m1d> Xm&${+¿8x +f}IC?P|MK7&6 Ϯ_]/ԋrz: X38 j/ݽ!8;R<1r](pFTH~Fp t[ D!&g j"8e=Zx:", itnњ~L2CQ/~듽GBhn5 T[ H{K^kpc$)dΛ$V;859J&++Ӫ~D>%{TK B6όpS&^ijH&_$@Hsd2=6ۼ>^ƪnScLsK] I"3'qgQ^e!C,oZRyV|1tvn@e0ޓ(Pᩗô~G[r18 Dd ~)ePsgG]3UMoۙS6u1ʞ:,| lX, ^ղ FL o[%ݙ% P$V#naD]Vc~mWqVzTPM4{,Q[[WB4ݓ!u9g =POU4UT酹ץKZ;P(2$4߮3klZM){?{0d,.+"V97Yn; Fs3ٮ%~)1 6ߓxʔK[YNc0 i_⏷NRS16hEF< dK 6eE 嚽F62xd"d%WƧ *iZ=KOG;EإEmБGۧ,s%Cy dY oB4"BGM18"w kVDy@VgS!ff7]rZ'*[MfۻSFJ6we격ekxl - ?=<I fcѝj^gt(`[<W}(%g^>4|咥$yQ۝3a#(SK41s*vA+s5@&_̓)z2^/%'׷W9kk5 m]=izeen%(Z}i[sX=fo)!y6⋸oXCZ~T~HN9+Yaґ 5yS&)FU3Q6('>B"G\* A;6{?[[df77J8 [%U{ڟdzɆf^L.P.W} Qnmeh7ԙ˝m0"9!pZIKN:̌'[ .G?!ўgDmļC#Nosbɿ}fK\*n"XBZ?K5l,UBi=1޹u1?FjF=@$6u~|`g!ZQYC9qG}K0P#yb xU9E Mç?I+ sp˔sxYm]`.ܹa)GYO^{أKH&ai4bף7d5϶=P mqz,}9=]oPy<#@R Aa?wx>S (M؜N=`L3V˦*?~Fzu߰ *Bf+;h<=qnk]xEQ|Lr=ʁ|c{_ 3^H|z=myӒUZ9 욤%:nats3 J@pVˑGAaw kKX/:tՋE@^kTΌ?A&*6;%P)u!nf@6CjlG  ]} C*!YJ 1U O+֔\VZM[\Yn|4GEѬm 55gIgJyC?"=Z˻%$TǷ&s/x屮~A.J!%0&}ݫbI. 'tA me=)ri /`749>kO޸fB_V Aséx[S U="tu!qk-&eZUQEF o"V5(O>'p.~ }zte 2OӶn ;NR;W͛Si޺R Y̋kx䆵' yo/mRrP۽"KK~~^h@f6 "Yy}/=RŮ Ɣ`OA@P$tӴ}8f|%v0dTYWXzHxg0ж^i- ֌H cq0Q?_xJ\-FGd=JL}^Xi46BކVcLt4,<QTxC^!jaZe5{o %lqTEdӨ$&:UL"PcmjrIO+V q'Xw 1$Y}؞Jv8A/࡝i zXbaY b#*{p&l{Ňû i (*ID'*&P@Ȏ^HV"L7E=G|2?)q; ~U`mzWBo43 W@GV (0{SC/YЕp*dº|qw':.aE|R(V#&5:;(`W'yݚI5ST̥'tfgעwۗ}4}ʻΕp[.( 1zpC)yhlKJr.ppfz̢ZT al@\`ʲ(0}c 2T \Lq\JW]6ۊ/Cs*] 6!'I^4 {j V|cdd)G4 d|Ƹ1K`0gfp_&jE< Lܻ34#X'<Hd:Hs@<`=y0dLF zs1.gaL"E9*AY1oFWXV˝" Pm^LSIaj39TE+AkM.coG{p-#C uUq0kȞe9E [m$"Ur#Ӳ}RLؘ%EjhstC'6-dծF_:2.qYF`u*g!#u][>0ZlLbAi%WRQS ⒓:J%m=c:,NۯS> oZǥSN*_^zUK1u߾h'D][J aT1˫E5;qx#R^s]\ylZ~:Pq;FYU y9FЫ{]~Q-2@0> Y4T"-HX(|J>vl ]\sRu0sא2gAVԓqqWZrG+(n RxOoݵnVeIҺM0d.0gmcH/BW,l18gyWlM}GJpt*g{x3pz6;f|n3T(N"@TylX)J9qI0[lhhQ6 刳)NE0DBpGrI\qx6 ,^u<p(dj5rZE HRʰ} MΒ'=UM?iqq FZQmZ]s+N |I"Ll@g,BF $c1KƕJ_o+Dעg-zׇEeA8@Yjfb ZdRds>.':d{`wiG0[TM;!Ē M& ;R5+THA4%E>"sSAگ;y#I ]ϕ·W*єOu]ӫ"Z}|<_@E/g@׽d6`d)Г̈́ #?8XO$su.yov+gvԢ8h#=ý:e瀽R̄rqygZ_cΛ=;lPJ6ʦ*$+wdCIjVurl`Qnल6}]*ơL>G(|3L\4SDp.B.3{`8MGil&>#SY/[U FZi DdNYdւ術g(d{ܵYPŸwM<3p;? _"BChDOR^/tLX>> 4nly W$ ~bH U<@L}ֱ+Tڞ#0ynV d 0lC]+Vcwht/EM )RS֤|e"9e?dʝ6ƾ }e 錩Z>8V-7SNYڟO8QJK39aL$Uy-2q 3)rl!Evj4?OQKmC!Ø-ۘ[Vd'"İIJOfkev{vp(뤖$g7P ˈ7(nv4 }f}b2'x%v+FÁXw[p8wF(`eL` 5ޙTi~$֥{lslݾhqɻ8z赈ܦL6޾BSOjְɪrI>8~jj#)Mbb?mJaSDY) Vّ?O/#qeS΅f@Be;I%Qҿf\,l kZw\EU.s ֖(&?2 uKK\W/CCS 6|b#r,1fwD CjGh`oRrc1J5%.%O=4>wޤ^3Xv 4tt &I7M\&pS_FLWU25p׭xzb6sXpNuj!M)hEU\ŝ'@⛷ .o]zEPof,&HPdWK`G-ߢwn].9ERgdcAX0R EL@7"-4д!w" :5R t<H`J<ˀZ[fgv}/Z1I{7BYߗ@җu58(Rk)<l2?6FS'{eVK l3`yѶe4\Oƪao– Ƕwg9jٻD+|Gy?{g̎nLnv>rt2etui+־ýPnσ8|\ؔ<Ƶvk@<] j߽d[D3N06lZ%N&4Gpkߎ<-4eWBФSQQ}BAxҦO_;6K{->lYq+k|VO0I Gei@DPVQudTiߞIxeߢʜ"܁د^3T:h])2ژ=񲼤Mߟ)#B(X~YͫE&y'nS"hrI M9N }+tӂZ/m blLg\uJk^Ry{ʟ;_^DlmXNq~Q2A9(~Dzݣxߠ 4!s6 $41ɮ>]Y4\Wh`\' eJÛ}";c[09ND/G2@3 o bu%GS}JjiamM׌~6V믴T *fa5d4}t/"ӳWMFDv0Vb+ k7TË́9!f@ Eڧxo)lQSDI4p.w/p/^;u8x۴*?v[% )'8e?'<hyDUF)2>Gd@,kzז%}U}擏<)ht~vYgQ~2K5pMZxwyLjzU,ǧf`7ĉ.cs~jop ݓWz0E^HZowj4t|ks !R{J_f~[+5.3 狘yqYA;--_&cAZ=Qb8xpn|`QDX5Y}|=wdy-Z;s;ˣ* I!83 nIa }m16-f%66+ႎfP;q|g4r5Kr6H\W;+((J1ˡݦ?W}\{}[6u bnߤshGD4CWho*\ rd`~NUbMnE~*9+tbҢ桪;-Pci .SnժJ_!uӰl8az ]}qf8'BֵMY9u$AGCKjF*xxWƻvCVFNa0(-cMm)`6 };Er2Ofn2/Oh]J߅7 =_=&k($@ Ig>Q9CXZ~kRBlȥo#}t.YFtd}O %ސ9wP'|y]OxB(jvH Zf1PK45#Rqϼ~B]^MVN=s۲-\UP~8;F8i,lx7Μcm!߿Y'l2QW+ Q/HTc'*+H՛ݍsѴY*C(HU<…bQ0&1VB)'>n^ ¦w"' 7 *%pѽdk5DaQWs-jژM ^,:~*ܑ-j(6zLDOZ#IMݓI( e# 4ESr麎w?_o0QTe[0gýMA0dx~7N5ϿH5?hQ0wA-BD-K(-HN#Wtl"zn8uQfz6 h P`IОfϚ0vHTpeb鲗@WظL ʐ(⡰L"ۻk#uяU%m^LRD+)n"#;fɚ毩3ɮJv'Ad͒OiogjI3^ӠoED)O[Z`Vr)Pfe/ jYi:?Ew@<=fA&]1-Fn` M7R#ں HΚ*v xGS/}}ySM!|`=v|LTl{~k_ Fx3}M3GЫeV| !{lj oEvfW'4̀38 C-R80ѳd³H=h,7B.qiWjm}Sa@TbwZ \o:RZ k{Ym!$AZpOMzO\y1jT!-Rέ ӔFNd-^<d zυ/u -7H/w|X L!hGx`5p_,ng2\Qߦ͓q;YaTt!M(~uGs)-يLhpBaXKwh0mhVB+~[|pbh6N-"a͠8spҁQ\|IMu.¢ͽg2H#xhĎ%ZlsU⮪#LcKQْ6o&|(=̂gic)r Dd = 591%L1m#x8"<$wdH} 4Y܎%"kY)&a1]u+Q%w>>(6/CQ/=A44@dc@/9 gn8rBut{dNHdCҰ 4\GF"L.C<жwqRE ܆Y?EO2Хy#1g \K+#FlʐK|s0|UEI5ShRI3(^Gx@# Wr6}5eM8 BNΰ,zL8KԵr+$U`gƘ2L}x0nyn8UdO dn{(m:q% OZK'ˆzQCMu.},S׊I=֙l[+\8+“"<ڽw]um}BB"(YOu|q~CdI;e J^7cqM< h<гp]6`\mQ+۪ OkE@תOkX ,TE{/;Cc2^0{/,7F!V)mt_]ʨJen0Q"tJ5j&IoVnd]iJXGES3us=mrɿm€H]$%" N`mE%z]8Ek ׃ѶL[#8%YaN0ċc ͸ xb*:2\Ѫ'.5[!..y|urŽui\h;@q,wTypOzZp#ϊP^ڕ!ZˬT NF><$;^z ӇI Ad-aJ jen ?"z5?͙Tz4͋,AG{u>-|Y/oܾtF$B'$_Lm3E9dTv:rW{I96昷⤡TXEl0WCi }F*awۍU´S"tv$>\儛Jx_% pim f әCQ}k-NtXI4O3Я؝>_LCYoɼ 2ݪ:Ƽ'l Bs@OE_Od?)˂V* Z[HsoC=(A6Vڱ"_+- YZ