sssd-ipa-1.16.2-13.el7_6.5> H HtxGF\P ?*}}9MyS5g"3ߺ]9?CyU=~o"892dc36307b27d75fc6aa37a36924789afa68a95cSH 8AXet0,E\P ?*}}\G'~#$5NvYwr* o >>?d   : &CIP   8   (\QQ Q(8 9 :w =gGpHIXY\]^\bdefltuvwXxtyXCsssd-ipa1.16.213.el7_6.5The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.\Pbsl7-kojislave01.fnal.gov jScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdxK#A큤A\P \P \PV[\P\P\Pe2ea9ffaaefc4c9eabb0e5d262b23b68a3617939ddf07f5d30087dbe00e8ae09dba6de2e05382226d6e82402f63473ac042de1a87ccffddcc1c421913925a0bc8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90306bba43f7faffc469015f3fdfcd338d1212befc958932980d8832b445948a5d954da544f9c9d920ef362c651541ad9448b158d391dcedc5a118d26a471640707rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.2-13.el7_6.5.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.2-13.el7_6.53.0.4-14.6.0-14.0-11.16.2-13.el7_6.51.16.2-13.el7_6.51.16.2-13.el7_6.55.2-1sssd1.10.0-8.beta24.11.3\@\@\@[@[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.3-5Michal Židek - 1.16.3-4Michal Židek - 1.16.3-3Michal Židek - 1.16.3-2Michal Židek - 1.16.3-1Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1659507 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI [rhel-7.6.z]- Resolves: rhbz#1659083 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust [rhel-7.6.z]- Resolves: rhbz#1656833 - sssd_nss memory leak [rhel-7.6.z]- Resolves: Bug 1649784 - SSSD not fetching all sudo rules from AD [rhel-7.6.z]- Resolves: rhbz#1645047 - sssd only sets the SELinux login context if it differs from the default [rhel-7.6.z]- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.2-13.el7_6.51.16.2-13.el7_6.5libsss_ipa.soselinux_childsssd-ipa-1.16.2COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.2//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5dc3af1e1c89ab9a44fc64121f06add9e036acd3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=348dc2cfb8d268dbb14d69248fe47d71b85f61e8, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R RRGRRDR.R RRRRRR=R RR"R#R1R?RRR>RRRR RAR0R+RR R2RER(RRR/R R7R8R:R6R5R&R'R*R)R%R-R9RFRRRRvOIsDR G{=;-YF9 !X_ɍ8=ܛ.+_A<{H^m1jl.tQܥZ5ӖRP9gk}~13R#(!Z3Wqu+ExD+aa'p=έh eٺ} 7P;o \ޯ^hE45zc,4 yǑk#q4ǶtS>xawGN aD;܌eK)(JPRM.0,uy{}rBĔ#,An[bͫySe0VyByGv-cD^ockvNqf-ZG|}iLA ,aֲMC$.^$AZrDHOԝ])DS4e8l+Eh8;z>Pl*>+;bXP.u@/[#'fW` 3uF&O:g2k:mgDꋴ?e2ީ-U7PXN؛P&WjC'Sa>Vlu6q9 Ӷ,j澝OU2W0a+5 ykvE=s a¹4kX9U6] /xbGTdR?p2uzQ ܒ>w4r[^Cwzn{e-.y!=|^m+)+徻1wt_sC?WYrN@dK{­}i9W€3n~/V6" ~G ?XCI#Z^ٺ l4[MNŐybtqFb_4V*nhhQ>k 4$>v)e' 쁐"QГti 2"m_?!Y+fӰo=7d_7:ηl]{5X9XMW h`н$W]26uPz!}B;,tP!N/@5j#Dw1F԰W> *6 5?HCSH5N]}^{9liF~]VTыHV;ȆET;}oDeuCǪ%PiίMolž&%zM HA}E,0]xvf}t l>v>G(ݬ^Y)oØa6ƾ-eWA O()'~1Bo!E9A+儤 A>-y%A2D-Os3CB<C6ل#j4_)0aŷ &Sg:,UQlp80e>&7Mky TX%uOy37'<<Xˡ1>sP e+Bvtq!lhWMCE.~:27}`+Ugz&YB|r#>1kx͂IuG%_긍%M*<m\D:ƚi`iANxjHk.Z ߆2bs먭JM aa( jոf}w6Oyg<=;r.Mԏ`96@Kr`AA|,T;t軆xN'_[Y2YƩؗ\Y`Lӣ )p.Ѕ lڗ9gN'=W%G*yͬk q:xCo7$a|^(*-ed0,(Hx f7Q"^nV'9YߗnwlVoMF!FQ9I.锛QIg2@f,Y!X;hR߫Dw,VF>RǵpMvj]ԦK0}>bAj41rI6| VK\ {ئ. l>/49f,f5K)rȁVCu=+8Pܫ=u;+1'nLhjżNSc_6Vn{ZR,sQE (uхƋy [@ūcPekY@y~Hj>Gڙf+_2#%B*Q?nqx%?wUoRRą`V@ )a_D>i[ f^WY P݋- >E٠&p9TrsIV([lKe[=N!k+ .a [_JfqcFM ϓ&#ˡ 6؞䡹ϠtuDIC/X4+b_O?t`Fx6%+!2]:q>QڢmvPYbܺ.P_ hדfF=ö@sAk;r1۞˵7n_RFrcf9dIrq ͍@Vv4{(1t~f6u  ~s<[ wݴq4uy!R=e.>U{YteN8= )21Sxk^Y{AKQRЅ=W, EJq%:4$1.2ܱL"qY?G"˛c UN>BṆa}xhWDضWyT{o(= 3>0 VZP֝aϋ^W,N3hfEx7q/[*~DnFGsLCsZg]9>@@x&,b%p+y(.51$Bs Lҗ=lq`'߾u7?_g;)md=LQ7TL&5&/ò5u*}Olo7ԓ?f:. ˿E@٤AD`jOQw3Lyhۖ3nlӗ&\z+VQ՟ѣ,~y%8}ʸ>⟍o.о;jܟu}/R|Wܞ/mg$Dw)[3c~L{,;K[u區 OK0NB閦hHSn;q4kN+)?'8o:4}Xuxu:},Y+8.f*3eyO#fé4 w@Q*>em=@hWӲ]*+Bxߑh;TwCM;3c&$6ږ < `6K(a9.tNJ~jwg#\Σr2ҡ79Pwk4!e~m Vqrv~ DhD{K6Hy;֭˔{C=@Pw"H䵧HiT+"zi,WkAȣq׌4}½\`S VfjGƝYtjf@];<[.uD~?/Qc,r-7&/J뭢߰H|;#յմ,O"ԉcW?S`9uưq^ڃ:NWu9IFyzf'$ە,u0G#vt8rFH]c݋ h9uqdbf;p2ƾҨM?7DZf<n%2&{1E} eԲ7};X i+7Tas\32#v8ıhq$=V9fST2ג-8=<5LVmӖp8rk RN -,E_fcK|-a aH#JLIߋsWIgW<#7_bA/2=GqZj >zT& 'UxH¦j4HHpUdDqI9%Jk%YR7yGзHsdOQ$s8xY^C^fWy \_^kBؾ I:bo8t2D2{=-vjƋw/^G}mFgPe(+63R`A/Nc )" w>v#YZqCOdu5xQ>&7ޕcEd܁VW/ $:+@wK<%Bıyyqn;*d`.@C z 8=;A~ ( ՌO $|\*(²,<e0JM% Q=nùƁB5 < ipgN_l4($48"[0,d҄w}CY sL| 0h|$3%q*i7E H5mt*sL?,gF'MKed2?C _`Hb ?j#؈Zodj.`N@B{{w:n?W&۲Js O]~9{E0ƌ6%mc_Run L_vl?dء; .ӳB[J0GG|nB6`P Ogx&z>}&Z%Id56i d3,Joy  R@^n^~s]0vv*DBMN7\#ṃ5"}ZlI3PlU :BssӜ&i*43̶dh*Xeڷ WzD7QnY[Ӭ>kTdYz0:NCߕs^1* !J1/rbjsDh>1拧x:ve e-bgTBMT:~O}yB5. ;0R?8gYVK *4n nQ]مbӠ1@X7_VՆQx M-辻;T^~6sMLb>\[rZTQpC,X0:lNjow_O%G!F3SIrJiO@LMpSRvcbvބ.?c8#[x>tY:00 ,[V멫n'yvveHoc1 s% % Airr[vGk+I*j0XrP3.gaķ=%a\/IdZ'`,PlܩG?Ȱ38j g̭R;cڪSfml *3xH:juU,~wYɆOxϮnĹ+\g?lOz˶MM):d{4kYoZ^ F˭ _.1I+U%*40% l~FD]p GZDyE9U]—paƝmVR*pcch/K#xwNr5UPKb?ctPP%" bfхb[8( @_~F(soDSo!դKB ,)SopV1.NC̲F^%U(VL\]Q 1!$QE*+*.@,J}삆ˇFo,=LzڰSrʝs;J4zb'cvu=N+¡&/m3?]HjKSڰzt#7P,|R-n}v##aNn`[~یUko"-"Lu;T'nVH2:@(wk S"8LUjB)ԓ([XbAZ9 EmfL>t24 hQ HaQln7Dx5V/vU|M66uL@f-zHQR=b]TfjoJIzfVbx=gkgwC3(`W>g{̭<3U̦NJ*hZ~/j@vwtlWXe7)U(bm?hw<P2H^ L t>4Nz#Ch9xEM)bqY9(V5'C`hRM@hu_դ ^SB?UEE;;l "Esf?-:u+h%Ռږo;9Ѹ-!p0w({].SRc x. ڋO P0\9JPS.[FB^|5#%֓}GBj5Cd[09q 2Xg5 &}$CT6D #n s߿@a>m>ɜZE/F0 C]y"/HCVvDT%I>H^hu>iu˺ !1=C:4cC:_yc=JvX*"44(@ns?e~5 1 ϣpjn7sH kruXA=id?|ONڧ>'6~*īzjC"tNvCU7p*e# <^^@@s;hz QϢX?+B,>/S$_ 櫝I ?eԆ*OpgS볫йb>)P,ޖZVM 6kke!os3B}>93gR`_H{^w&M}Ai&ZUBGTﯕK@ N4}ĬO*}Q K"~.|셪(H?\$=ps}--_jCG%CU\NGD F9`Ce< iԘ:ht:kQ.Э7?_ݒ -鈇<9:ʴX}=kGm_0#7(}7j%el 6lzJa)ͺzK9&-~- ;BO/帩ګz(Rp~P Mt5ИĜ+%9Ѕ~>E2_\+|Ӣ5#1;fh/GKR˴SMI'wws-H`mfnK;pAL42y]jS_[۬7/?`z32<=^^L)~KPŻNNK[ZW{?0e+8zi-Q%AhyqՎϨx2(-٭J)U[Y& E + )j;"bb,MVJ ^FmV29z{*=䎝۩LrD^y\-]Mu< u~0Mx]]fF'^U:w/6<GGϤ*#1O -⎩{e<-I:Uþ1zrJ9 d2#ނ𧯛n>LW vrmw`cu/ I98alS1G׌pZ-h9u-VD!>qkr8nʷe@eC## D6^;@O`D%g2vX6:gC|-$pL7Bu.*"jR!vICNd;gH_n^XQYj|O +M] QY Q h Apb}&މm~Ə<sA$$Dpڦ)uQhfHG U ިbW_f nDdi d.w6%%HVzQ;[c /%A،CMJ+PMAOꚖdH?T"*hr6cs\y%^7Y GtO %gl$qf ;#dICGi>\*&b*rx9;*I#[-`a}{G(M֠τS@28U^tƯƠ4bb,419(r.W,5H^ J՝hζ+ߟj |/-s;ph$SrGE~;&nɎ N,8f#Rl7R[Mq`C^$\ff\qKn):zǶe%5{k'g$ub}eu1ɝ'+׮T°>ڜf cSae;7vA=]Vu"& ( ^[( tC'?,z4.iro~#Ѳ#b_DF<쳙 +RMi)ڻaf.8+KgʭUfRNѧOW"=>9ڥ}7tu3^\AB#恴-Cgyz*9N&} ;>iq9>g(4h3uwb|(T - |[Nd3jy;zwQ9v3p4%GJ:&-Wt^2նÔu!jm-<29<gr[:^ɉ䵶{;JxdT檻,)@89bF>rͬI{qH. #"EAKBvVrgnǰlK:C>}W}uE^ *HfWБ!߽pc`20#{ezx0ڋΑ/i󆫸kq%򑰟sm)8*wn.1NP Sm:>)07??¦a u&"Gl1Cx"dF$MRy4čėb֢̥bFE>{+񖒯!ҙbڌAgbmȀYF@8߄ؐzp8\8==y|G?NйY߄D~~Mf52'r;z![:kM&f2qj0cVX~ 2 RL}n=I̮ɽuN~ ;X}h1X4l2i q1oҞC8*d]ҵIjFN)/!!ytmb !3ePT״5`h;w-P]]Vv;qwV)"'T.=uK9!xpҦ?~6J륝*lS-F{ ߅ dD縃E{rhVu:#(zI@Qrd1|4)|Gz8B۬\}Ao7+#ړ k騩|KREAe'@2a;[!ĔMcE4N:ęeo9[rY3R~tt~85V_%=njNJz/~~ u Oե0)LlJO8H>- 6*̓dˌL%f2!J H+sG0S<3Yt,IE3IgJ6smvx/ʄ^AGH_(kG䫗b̽Hi0{1͜qgw2z6EOx/Vtb{AgeG62;1vf&3ZQdm?}(6ٜVzEoLUѵ.&ǰ[QAr}9 4#L"|=Jߒ<|ze;F]G^Lq I"icw \Y7 G aWŕt( d-lEfK聞%液hzmFPa yDYBT++A :xs_RaU)&"5Cw+#Ijҁ2o='vawmNTbk,l.p<&O`SpDM~ }Jhj1S@֓8qr"c<^D}ϼd®]nw6x>kAfΧT`V.'@Ѐda^?T&UurrC*=x̿:@ y'AQD%SA% HXc[ _ A7xɽqm7GxB5-RO~{VTuH^#3);cqf_J8 y|3-q;2,ΓYFv7vf#NŠBUzc :gR.;y\U+#͑vZyBXWO#ppqZ6-TcBxWćzW_fEqgrOģF9ca ɶE޼^#N'/bCz4hUnAu6YX U9oKd a!Aӯ funk+ 16vln9I1L  0d2}!ش&Ի$`g.kWex0P?MHv0eO2X Pk !"mDńO! } a?dq]#/CESaI,IC!~d/BwHE എUu-cE5'ץC5l)Wi7cq[N0 7Z(_>O$GLBDFn(Ǥi+CMsqha@ے>7.LNI@|)G h"V|`zgOWg1b;CT hnSr#A%;N,3CvԷ28v1S*jar `"5o41eM{b-L B>ܡAZxUri9 °ұ/ە>v5(v_p`<3Ђ=ur2 ky:k 7ozPK_AĤs2I L#\^Y95x4NS(D".ڿV˥MO1L@2c5!2N9:\Pfƒ-r}H@%C!{7&'C2-fovn(u4]x5&1 9|UB~ra&,U^Q=Gk7Gg^`rgl, g:fUXy0wN"KҊRR(pmr I=יA)-7y6-,:CO& `1oXTƫ; b6RE3)c~Ũl0sP_SlrŖܥlw܅\^~Ipy]: W &ǐMi@>6 a86RkgZgޱfݡԑǷ/@$5EQ`~qN#rQ.S8Yn7D."@.1ȭSzMBؿLU|P<7ip.9qU X\\ϔ __VY|W.xZ^션׍3$BXJ}׶a ӋRjc!)|>^yd*$&~!%aYU԰x ]kR>>lπKd<aml.Ŭ0Xݫүw }6V]<:{|(@}b G^|Uϡbp dײʻ\16&9M" 0e)M0 qS!<2GjL oY7zs.;u/{)FL/XOdQL~X k6072Ik"˵Mzd̚էXm9. (c0xg[įr\Y9ZaI:H0@1Z, `;rbHIh9_ 2N&S@q,VV> i~8C^R[5B`Tȑ 1 aK>7A4w̕/,j7k@.QNWGt_BG+_|7|SuW7HTMOjڜg3bw璖J<:Ȉ4,~mW4)Xr9\c uı>B-,ES_t}c*<7,MşM⥋^ b{&ЎBܟ*}Fukft#-imIkåX`^u+0>I( ZSRa-l=#So #f4/ODRztY8P&TK~q^wk[=?E}/Q&G'+W&ҵܨ@ _q'D+XQfL H9AP=q;'^XgU)ҙpEr~"˶H&:EC~% ?:vs=ud\c5~pP+ ?`ƭ\Hc$2-OA'Ո]1Txɞ8!M+2>IW/Ҹjzb4Pkw5S0۔y{- f&BޥAi)#v*ڇ}]~ @|IAR.fw襶:)GnUq"T&Є!1$7䦵oF;1Yn ?+CLsg]B3?S}#] ^N,NR5 7֑^H&PXV_oXbaFhWq6,ATp@<ɘڴ6Xv2=v& LB1}֖?A }јm$HxT^Rf6ɤk1  jg|b=hjEE7 ,!г.g4Y.4lbj$ҷpj lmrqDP7U\/Mi_I*$jȀ hw s1P.P|F@#=.QSӯ ǿ>y(nFw=KЌ:VYʱ?FJ?Uϖ(7V=h~&Z* }DU)ZA57LI <g4}Z<"7U%7b]iEAr̐BJ :a=ա@ܳE]qi3Cz{M Ɓwa޼txD:$n#Q5ل@sa3\"iꆖDM9p]2o:q.ҢWǰXZJVBUZê 'LWR-l I]?]9A>8J~@U&A ]Ӻy`2  @gʨ(pR_#:Gbk1az' P`]rd/s) ǦF 6ԶQ U1z3*ޥfMr8N仴Sv8-]HI9ZENtr4dD[xzpk煟57 }!* RX|k{H/# ck9`^ ០8kz6 IZ!((8E T7$Ȫ)+=zbqnVC=1s%c8)5mmEf"(}LG5?d"5_XVz]8֢qaFy '022(O8Zǩא{Z*eE(^}]xOZ)*YŮ XJ]ht|j}?:\B&0Υ0殕+c޹ub34m+! wT>%6$%wI.aʒ rT372 QW"A'bp78b܈)!X*:W")cگ[!ӠtǨsG `0nd(Á Zojk|Y>P@V{+xsM^`Y,4kyqֽʢiy'P wb1ݻ]pG- X]yMm}rH&7cP:˿a 7 ERL̫epꭈ)?.s< Z{' $%Nqe6yd}=Dڬ[qd TL&@6m^WdlHeӊr}z+̭m9UhVqf-.L#u!V&Nf%krSQh]/c±3QhE e*33[ku[֞|_Qɾ/ eH#t_fϹbՙTAq\TQ`'lnk"w0 `]2Xq8,;e~]I{|E-ǟ#7}tB}oi'f䘂X.>-"h)i+ҾQb12~5.^kyQiPݏsd8ʡ!ĝ<núKlt]1t]gH!!CÍCnM @#M7׬QP=Zț ƝtQ/x {<8U? X prϔ3-.CÃCѵKQ~7m^Khi`|VS`:e7ShIpWw:4QXo=}κV*&",i&T IͧO:#Kx5 =])d,Gc>s=G|b *on1aFRc~tjgS>wC>jGh/BlfϢfΆh[{#Gf{,_m Hfy>QmY5:1R[x LT;}#裹RZvKfK@BYߔۄb_ \*̏&m{ (Ơj&SliE{ 5X$hsHOme'̚&;=YPBʖjp/ zYQ2yw8\EmK|gFS 8g'Js߫u MMaY!`Q.kW9CH4Oz`sOUѐsdMd?[c_TŀJbesUQeȯ Ci}) u_y-T>q,N _?JK7Ж4>16Q[E10 'ђ*J8bUp9hIqe>ϙ = w靯P0# } Rdlv\@i|7 [~ k(5E\,ұ,{:p[ ֚@")CMB5T>|5ո-6]>4dޒ6p qF#6a+x)лv4 bEmI)MRIYj,z(v(Q> F uɹ7Ñ>s `L ػros)U&_YR$\A >52vᑎUr^U6xqr"O53 bb~2v5 C\]ΪWҝx mu([ocq^#ͯ_!;81Lf$xN0?<֖E1ր_rU[Sq" EQ§j=(!i F=Vx;L:*nc%n %;L^Z M˩&dN35cAEC1 B4k1~ -@~smo.җl֮LJ5OG^B }j/\ '{F2&UioԚ`hK̙z?#& ,*pcG̷ecRk8w5 )qJVoV*&mեܛár}f=d[",WVT Bzp@4BjJ`yJJ<ȩD?ch2҉.G7Shw$}%vvH'.,KbJrj,N! ϸUPx==078vgHsBOzײs~ a„Z_Pff mZXy-ƫȜ d&%Y29~>ӯghkӀ@Ż5w*6V@׸[`]!*0/bɉz:7̌AB\" v端XS7COR>.E;k"GXvc2o%);ڙ/ˬ%qiBqd|bI|Fc$rT?)tuBQG/#CQIcq&HpTZҷՀgUΔjo>pʇ\+:Pa5oDI 5%ӳ%g hQA)zH}e¯A5xB!K3IZ$zà駧 oNHp)d@ 9nc׽b]ۨ4ipd=u%=RptUH4S|wKS\?$T% }/*8=@*toCa߮et7N`Vc>EBtd j|o(ieCfUT2O.F26#p2zZZEz+{H:q+t N ]?wUz=qߣe$u~5F*< %2ΓCY8Iľ$H–y̱y 6 mLx|#{c[Y ">Q 9 Otu) d-@vj85"%?&"{^%3f5$/)4h8 U o';NlL8Ͱr%dGB< 6:/E$wXΌ@e,]FagX dMSD-,^}϶TN/_ €jSȲգ> )ZRvPNƍ 5zƯè5G>׌*`yfa8ҤϗE _\ &1h98,:1cGyƐ yDxDZ/zCM4y)MuDsdx҄;q]\ޗ op%U҅DdXw+^ S o\3`,3έlb ]kYqe>鴪ULf.ELjҰ92&ڊ'][5nuʔpՅc5{ːa":5J$>=8s݁+ =}eZ`.ьP=eJgS1'-M%$ɝӕŏWMo%Į_L99Q\F3}d)_gH88]KقEyhGӻvY˟ٍcwBFǚ)cl6ߦpv[u'ҙ>`HڅgbT_%sl.=S˄Qnb\CD[Um@kV5CTGq眚@!=m,JJW~S4ˁ1M/ {"fvX ffM[DeqB0Q>Dm!}$5DCT34.c&DC|Ug:\br",dDBfTW= b!OPq }t~6g~f[@ʇuDqt1m+k?;KcN5nN؂}p3}ht^ OÏJ^ݎor}8}rn=Pp_Ipc^hRܗAõ)ՇӼcc'HgT{iJ->Zȋĩ30sr98n&[en)-80 7ɇ eYEWΨ)9ftnr0,U !M:|ovn 0U-Clr܄Wy2UT:u`*". y`Kc(S$y')nA{M#YUIhxzI8R82%nH Bd[A33\Za*PƑl+O5GAbPe"X}T.*#;2<#x^AumE,Uc4K%)d46:.5BHt~:2\uX-6S-s# y6//$X<\I䭷g'znyOݜ3ݷuԙ}OUّJ ӇTQe1;c5{<@Qad79Mc;7[,x_\4;AspFXLJў(oLMv>±Y?gozߐ't]&fy :?K&m[#6Ɖ{sɨV"3 $Cϣi AV{&DZ-͑ p|/X[M.QM,GMzKP*F#ni g{j;`zgh)e"ǙG xy𰹷6PR'w+Nn؃9541; D2k#~T:f(R,* %M {¬&%"O.w >xv脿7E']Źjt o:+j.MJEHbTw"(<Ϻ|7 ܝhJFVW{l<`24TbPaqJRQ]0/D>kgN@a\<bJLh,:)ek5zCbS}i{Z bQ|NmNx pl-] tXh޿xbBM3s;,U*^}v3JŘ 2Z);OI&G-;Z#p5lbwU=y+CKqV>W[ܺs6kP̥MIفB9!dɌwN:t4tqhQm0&"v"YFHrt9;FҜ"zOz8W~uP˧/'邾\!T% љw7'SP'Fu,r!֢=xrgl&g&B 8 fR8 =2w>}["{*##ϫ_?4=vT,T<1'Euq~Iz;&j&f׳jR4U5E+oX]B=iµBR*ƅ.cy@.]8XL<$>t.rLJ[%VcRfQ@JERV Α'61J8g%bE8޲Ke~D4ʎ xe& LF~z`@Å@<>jV,tݼ^'tJ $A\jOcR9Ci(v>ΰ`NsX"E޷۶:me1 ̑*"y{kle Q{0bm@|rC26Y@b{Lʝ?\x e.Ruj)se`ӧi>#\ C 7n;4H`tO#`Vڥĩ[($"(GO OuDFx^n7[gSws_;~OU<{ň'sC%5W=_+[31$욚2iH!,- gHtiM9omi@/Hб룭>Kڕ!9j&y[%kG*czܦ WpQ>λ_԰Ø,xE\8*ʶXWB+ V`T̎h ]_Ӳ]|TxC%8cʩ_?U<}  L% SiEEOtr6#bF@_h[ fGB{芌#첺˞F8XţUe'^s%38iG%){˩OE/ ϝ\ ȔϠ ~aYtK;ǐlce8hgN~0 [WKȿp{X26ݺ}ГoC`x#+0 0;HP&ݒjYy Yj@M?իᱤI;`j c %YD)%ejPb) c;)VH,S^J}NX1]hl_&zu~.BiBNi;Z~W2>j%..k˷ 4^@9&[lb~('icˆB*nE] Ӱuم*}cDhZ \Z}T;ly"h}^ņZ 7ed l|8dmVe!+ԇa==X}jN\Al)~Բ"[q"JqLj [Mc?OAv|/kC"ɡ^~^amT_Jό H`jwax$e`4}r[-垜CSl2Յ9X,2&(Pw杛4GQփ* 0VHEM&Mť%p"VhݢtBr;](/\LNF2Ph`ܾ &R;dK2FVak`k]1a+!hWT|`@3snNPՁr4VQ5~;_mg?2Xm]pyL.gW-u+*YQkki/gن| EGxxH VvŘ75' ߌuB_;htX7ⱽRI(f_s..m인 iVGSsjeOLg<< Y~ۭ.V*{k|@^ꓦQ CK-~l;Z ܂PSm {(l 3ᵇcd )xL 8tkFsEK' (` c[aM0HB5x ps`gjcTRuv7+`=Z{Ŕ 9Re.J1'XBMvcsOA94XiK˹3T-t Oxe-x:7,`ժk;9)eAph zvKSBH~͍q%{g}O:v!%Abr&~=e"$^dzfu:tEMNj= x ˕ .{rVkh" 73n &rQ` i=?I_-6}'R6 pM=b}> nooZ#[(jg:bSK˽_ CVKVJ^U50ׇI4ॉ;LagnOQ}-:ύ/޺l Xhl7uG,`f-ؿ0_iҏj}@dU8E T m3xMjT5uznZ,tϕʧ<MӦ^aFwE a\.$"A ݞ4!( կtĊ=i! ^Eϥ[C}Z4A*j?:37rm}&AQH󴨷mFTDc~(c}PMy|cÖoG4j/btQX}*-r%ݟ? s.Ob%˵G}^CkȲlo' :Wl,SEV>oQ֊^$T Xj!.{7e\\8F`)~@JOmzײY7䳋Vl{cD;!m15- ٶK䜜>ؠ@rEu[l,x1%'gXFαɽt mׅZ*/V?9._jN"~/ ]{)TohLFɆt{Lm%ٔ=*2ֵ7POv7+[>3)~u䵇jur?YV'SB%-5T(Cm!tFia}^u^09~<(ԓ,4=-Tӈܭ 0K[[4 gF@8@ `+ [c'VJvyiRS욺5PUvѶu#U#zZ2 #)}pc-R3)DeNu`D7}lvev) ÁQ|MGZgmn@I_;)C}`8R hk~Վ6|Ap@r|=ANjF Tp/tDY,c;z#&TK:PY%XNfyYbnLኧ- ; )V/rfIP]Z*,֓:KPF[$ L5mkPu!ǹ[_"0X )3Mb"pؘʷc/0f TGHs9Nf֖E\ܕ2 ksPnk&"p(@5fNzBM`h_o"i%LR'i\\:oYf5~]a֓e1Fܦ7G{]~K`v/G{}Xlh&20&wZ\eg0I0 R[Tg ]톞6c3Rb[Urp(* V|]fkiI6]@b^k$nV((mbCC~ȲWÛXZxNl/5Z4õb* ;SXע(^\U!"Y//-"S&ǖO-fAJ/짉Q%rQxޏ o {pLln 5(3%U!=mwdpnJI[k0@3S?tZ>Uod>N`9! ok|δݛ$9gdψf؊gtԓ7` NEBy(_7 /2f  B[s`מř3Sn b,JAmM}Z 0б׀([9q zSZ T8g%i]2 g^B (6}9ՁO%) Ű|^*ө9%_[CTmsO?*b rFk:{˳r#XKOSŖ*sӓ_&לF*3 g ~nm 损oC0AKCI&,3m~~wT?T&*;_R +M:dp!!%)ؗ[?54/fn!7bzHlp9s1@^B8+۔3^AAa kD47=nuk^pP .1'X]rfo[g,KSTsC~AIwP/A4%CA4od΄׼Å$D'$~6Et%+COPIʇd@;70BLv 2L`>z >B(3*[lV@JHՇ0S0T{3P8Qicٳ2B~ 58 o`і&&B8Mӂ96NʅJR&ƣ%x8L%rh~Z [\}σT?YxU42OdLGN/[%Yqn}^-`{Op+7ݸ &/@3{0BQ0J0Bp^_Pa5[μőѾNNn$Lj1ݙR^>a1cd< s(Xi_HjbZqn27 q׃GΥqw܋ݛ[˟wQBYvCzYˊ#V[ꄛCxyE4 >A&SSc2Vr:u kb]+pXؤ[0u¸`lƜ+0Ey~bp?=4+^> (Phicy`7y'%Ĝ3x/C+Qbx5:4Z_㷽|nHxаd- 72j'@G-+Vlt+5ë:ܾ^b|Mϖ\Z> #W(=P`lufyV>R!v)Occ>¼UVؚ-ӲE[cz_@ q EO52{I&:YN_I N$=b` ^owT+vdwoR#$? U̱_),ϏƠ[頯gWM,N9sALV`V ߶!" }3B%ɁL \C.{S0,awk{dcЯD^]7[}RV[@7ŗ}l5hb@dǵ+nC3qhy]:?E1gxuQj-6YǬ `Kpwjn9LR;gZ: |k;Qr;Z u|53xt}kduuS&y K3loپ\ ?}&7C6W^443"vrJK?&SQ*.Iğ6zvK_IOoU=6umx}D9-\ F1> [SB8A%X-1I<'ݪ vor6\9`}ް}m|}6ڢ/FJ c@}~b@-n ZFka()pd4,w᥏C?` qዞː[ .v'vUeԉ *Ԯt3\l@L2!Hm27GA@3ś(F,%e!AЃwZcGJ稅9x=xx]G9( ĒK?&\48DP]ߦ>lǞzB7!}MwEfʮmPvx(4k4?_rL7:)tARNgMizyBMKKܵM Sw.ѣa*ؿ!7i\>%i5DKT5J-]kayaf@w E3'Q, ELֿG_9H瑚 'Cצ XX4HmԢZ~uC8`%U?7hbYڣK!M)XFu}C6~+f0 9O^8lQT\K^tW +Ƴb1? T (4!d4a"F)C=+o#^Kd ߰Y˃8c B٠NH}hJЅaI&)sN,Ÿh`^ҎD;"eN52 U J/B(3>̡/$K!)H/[8Y+ On\#QTL]Y2B.8 XmeN̮gī.C<(yނH=씑{cԠ{m8afK$cT+}$ [ Ϫ0lɛ/@kxgIfb*Hg0Hمq[ɫkW 96"/!Rpi2GZzuNJK<-,4QE?o1|Ȏ(Dl 9 >FX(q\NٌG"6A fo%zvxF3uOŐ.GُEg.Y&n{w&6pH> )Mg'@rV mclii~w;eMtĦA(gu9g t3ƬB$j#Q/~X+5-=bV2p:[ڟ -ɾ1L׀W1>eF3rBِ \~h%xV>qۅKǶEqe%l}bZn{ANmbs% Kx*:T޷9 k9,KLث4ݤF,G]4{ף,i1L3yw9]r)L Ӧjm=&@^+'ݓ>%oCCHE5;YO:=7եwh!RYlv+ΨT2XKEV5\ j},-aiZVǟtE}$qLx?*6uku s)!A0 rg>gٱ!E%n$Iy.t4 3XqH a ̱M*_KחCMGN+DzsQܦA'p42#P%(4L03uW)$ߛ@Bw0\\AǪ0m"#(=C{Ƞ ޜ٢t7o\)[ᨨhfs2~q[ٶ][QPS9^l7؃ BK(2~r+AV[WgX7jM1F:(ʤ~Yn2GbrErMc5-&Ԁwh#]){y%կ g5ZjER&Eƽ?=RdÒԉb}R]'=dMWDcpds|y':d*#H,%&|:߭y>'?|ă~6L&IDCeme#Q!;my=,h949* QyYu/jȽwV&^ zLTGrP:%ͷTw o0~@ހ&h|sCHv'UE94/hGj ۱sỢ;O I}=I57|oڢ koGQ%~rҩ3?%lF j5qLEXZt˞6,.ήTJϯ@҉*DrK d ;MU#zM@ cm#X)5=#.uծTIa{OE2Nu9ਝa ڒCsM X[A;N !u-toe[Cc)NAA5L@!>8K.e)YZy[Ź !\Dl?| ^$X5[aъY\dDy=PٚTJO9h y– .yeg0,!Rdm,;9h5 HtUn)6Jo8A& &z <7Ȏ΃^o_˳"(Ff??uE4(ϭ萂K Ved7?Ь#őǰmi&Q߰W|xRudd %8| Wo7޽t}կ? TKb3H~V !F<@Ťú||ϵIj^Fg)b`G 'l4b{ssbp,߲6K0Z(d)cH' Bn:E=s Vg9,H8H(vޞz+ϥ${%^Nm T{"Uyhs`nZě\` ]Whb5Ry2HDGx>7KxBA;{Vds$F?qo,,ht] 6;A+3\;ZM/Xi؏"tM2g/ݥR^ |>զIUPôNqpX[7EAQWތV)zDz$0^}OS0̧&ŭGjdE2ŝ%ˡ/RBϞ_n`뗩JtIwKӛ5tơrnWJbpmD7VZ"lZ83d}}bٷ+:8݈Am!>uN7L̅%ƠԒrR˅Q `ga̵c`IYvdު_ot^}YrjnY.;Z%j#ߥi7؉[8pS/Iz1G<k#4JHGvn,CFZ6O' 'pa)0)/Zpڟij<Ɛ8-3'1%`2}A^䲶%HPW&tfY>k( SL o^T5H꼥n'D^O?jr]yÍôB7=*]!v6ݍ kؽaJDߑ{H~щB@i#n0hY^o;E * aIfWhUAnC!Js}Ȩ"|U//(jM΢C~EcWgYts M6i%BꁝZElM,%q*]mv>L x m<do{z\>槻)̫8~*&-MWMSؘ3 ݭފO~$zxMxy 야@؉U5l#T L{ KIwͼGa~e`KNkFꁝRqz1GO}mK{R9GJ]k?^-ɚ=`OhKĒB$4{u8E&ui#a?T@M]*ȣ 6\'rV2"b~Dv'o(b$b]gV—JMźT!>, ZpzeYrqW0If[\X G .ĩփpiS@d*zqGY̺yma.Lm׿X>0^pH>k +*{>-Yؕ3'5V$&-LNj!8r8SzZԍ~W1.(H][g9vǹv&^(ӛoMJ ;eObCfw"t`=-&?5Hu'6{$_*$[%L||u$ \](C[E[ ~=:epoftQ;F̨^P$|| LNSwu5WYdD~`gnЏ)SXpc|WV'j QOR7ݥ@NbV\S&-?Dĝ Ǡ;i"Iۉ8SF{9&d)) K+,ћ;sܒFjRkucuQ0dȫ*9サZ.$I|#m7(㗲8+]jWuD km ruyt#1R.+zzi% 7@ޠr)L8YPh^WX6D^j;8wĺTaɗ&$Rsj\g,sVH\u(XDQq֧χ0>FGw#ّ'!"Ú@":I7s>AҢ~ɟO* K͠)xһ@n|"/ áh91;[q`|y:HW3&5[]D;@ʸaM""}LD\؇> \[o+سGͥdl4`#9!9@{t/)4$ТP8uPˍq -Ul@;o,1'Q!`2z0h}ȓ#dM`Q928}WhoͅUiA4%YazwԌe{⧾q9b[F<V!+agOE$W;/DJّ=G"fk!gO]3MVݫtQ}MP縆Gcܕ?w~`j fK md: dnK1Q/CM*GWIк`M I3'E6@ )}@ke K8 e<~ K%U<~aè줚}Vl&{IVvHUZŦy|o/Ω"\Wɘ}sZò4r"9=2AP5,,_M}#Q2*$(Z`HWp_/k4ͅywsDǖZ9ݺ hs}C~b$+B0G;:z'Q +𑙑=n }/QIϱl]!zR>)l?ݱ,yZH`[A~#'q8ڿgUՄ=rA[A׮3~$(`u $UF*74:6PC\\вDS/_z—Tmg:VUA7ˬ4ykÂ~ r"B빐0d jt)f:vܗ@E(HEs ACInmZv]~XWNV+rM=j_X+md>CPl`M @u:`<Y4oVv-NwuSzd%}yq  :@Dc,R-]]ud-D_ϱlA02h<[,ϖADnR1c7O-ͣ%AcrE|l}eT.Ycgm)zk21 1Mս bK3n8L30IeP=^`1^'&WX3E9Ém-"Ǖr &9s7=/gF<ߓw{ 9$qvQʼnd\A2+  )s{}J.O6Cu Jlj|N1ILl@* gH!W[ת5CZ8N,X2\/@?x;x.!+@wٞV8$kNv3pY6a}r XarF$fXp>c_שT#jQ1"ڹLFӰ;IR')d~jeҐ*-8#~FT'h#Zk "-LES,8Y kOZon07 ;]knA^#rtƶopSQC9^J'wJ 6X| w ^o qrzpS0et<x޾ Z+&bK|?Ghh%kƦ%%^RZqd_æ]:ǰ Ճ&[Tm9[\y~ǹ9j*w\ؤwoI = J/' 6`1 -Vd6`3RWjM%cg5c*6lnPYv, #S5tH/f.!ęO*ZYZ#nm<'^r@޹c )~Ln-Eǫuzץp{C9:CE7b6iULL9.+Y`w!]wBke aJwnG/4 >Ȝ|3I ɸFn*E1b;Y0Qr =xq}l[bkύc8rh]Nebz֮_UqW0;&oE~oDqv%8d{ 6DOS=#F]8YWЩRLHMiVyHh9x7/c~f:XCdoO4ϒ\b-\Zug},ԕ#."L"+Qs&N2.!MJ !p(.r:9cHOU#+Bhԟ(VW2=qޠROPʻ9! )լo`^"a${;TVPA@??k 1Ku&)Ti]D %&|Yt#l@k.XN^Hן{ȟIP!`ol۶㔚ܿY. JCJ`@#kԠh-F;I |vأ2+W1 4!g|PD ؽ(a7 w)L !*C;"/xJ75.NR )XpT$\X;ͯHS1ɕL O{&.cnV=(M/]BNYI, YPi MnxCɳ^gBe_`Ӗ0D2`zg;!R8Zbq HNM#]^NJou@g:܃xajy_EM+wՍ/nTdPZYe}kɝ|H 7aakGyT6|t G =74zX3'MddX=k81`Q{!V# W>O3#K /0o "ZW$|8a LmK|΋~M_ʄǙgeՎcn.({dC\zix? V-2f~DZ|LJ'%ƥJ7!5e?5 Q2E;˪T ?O(tn͡F`bY\c?Ÿ;1bnQ/Kl(T^6?9G8(Bԧ+Nɔ(ۘY5n|űD&G'ӄ=:9uj?hg3ťgǽ?R3 %29PMVx<}QN6fcM@ܯIa۸mwB5H{3F Ty*NR+F&^4-J.#D$6ŋ> ( \lnR9m{$6iw2m\ dM`iӕ4u>.1cfuƋm=F̓F2,tS)&?xCVp߃Wš]T|m W nh cL$xӭ R&]p,8"Y4;N<Ʃ'. p~mAHFR?%BmyqY"D!%,6%/ɧLol_Õ>OrfρlI;10*+rr{ҫe(iOP" 븫Jrh.+%hUǽ%qnqˣqGQ^`묷BM2X,?7 v4+sC.4mj찭䫸Ը>όnr@YZ}1J[H+9Kl`weGQlPIsfmtC9Q&SOZ o/&dMՅV@ښuތy;JM\߇EjC^&AO`(Ьi4?bCB]j˙ T֫w*?ggd"j8O`YNFC摊??,#om*XwGrb#"WO i%9 L݅lЙg慪ˣۓm"/D_$"XD=̠4,-~`ln/&45a<׳ZD/bQLLf*CM<_^zf>MN d5O9Â>E}@yoSU6>۰@Z` +xe&j8} ;& 8'۫d4H,982u *륳Z0ajyifd8&iOF.i24Oz.x&{;Z,DJS\*ҪhabgJTV{2@)ALƝ?puu+ y^3'},i@ite'hYnmHKj3چ9Uqy;\$Ͱy(GG`D`d?{\5Ә(2qɨb;=&7 iUwkg`9eƪ%r:iarCZ1Tժ=xZe]| ۼSDo`pS׾x;Lr)ȇ^8j&3 XQcwk=Vv§Pkw*oj(P+Of `E,t&wӘVcmL>OCJϙ9xlrX[NmI˸)gj^CBh,uEQU䆣LNҠo_:pU,ۇ,ޯȦe"4[fl' sl ʼ0^̈́Ŷf͐WYZuoXP-*C|{~r~Vr*`/juJb) '4@YBwOu_5na{fH`;*f+M]mG ^&!1QF 1FɈ*?k4gC(^E.^e1!hiv۠|[{@ :.% x`d7.*ȫI97OL5.-= DSLz,bSήAٳZr%=LAߎr XU[(`ou|:D٩^}ѣPk {{bh ~ yǀ#x@ZiuΥE4kJ:nhOs7p#n(Q2b+WGÄ`l1%K3OuIWGF}5H#OZѼNѴIsrPոՂiF7]hbQ%P)Yr?0`j⯧<,s@5zN%|D1  @t<.vt[Ύul뽦^5" GZ>[gl;2[p꽌Uh5i|[^yZ+?s@hqRjJ4m|gObIKxbMs#C_K'IOCf+4vѷ9fbC?uۼ`xcI^ى74+tzkK _"tipsp{^zhakڒwF1 TDH"tF&}1cdNO'1IJUBS7AAY*OW&$,zg԰FGC%JY`vesVտ]:ш]PK=Ykt;0ަnp.C!`&$烥j4t6tg}Frae!t(8v],ሥB9xX&K'p"L hWRRU6O!rQ|[LRB)>`=H7-ocO9Y>:FyG@rrv0yhFR>Vi @=ah>ZU}&M9J k{UA의(_@1nj,s\F㟉jl\N;o`6r]h7Ak+l 0P;"0{Ƹ_ o5m"YYo"0DͿψ ߘͷ% *c*)(ơ 0@# yEK%bûIur&(k~7rTQ]a>MhA ^`qN`.IXOU~U2D;oIK;2J i&T{vywKWepo]uےT#Bt,o1kZF`"C҂I,+{|2~P]b[Nsڢe,X%}?i

~5$Ag%̆\AQD1e/Ny|PΑ|vgV]>L|&Xާ扌`fUso2zWG1+znCS- &׶1-^ilC^ȨoZQJD+ i=#' lt& E`KP\Q"OjK0xa1J~0qxk`Sղ2?͓w*) AH=LƘ\',g.ϧ#_a+V}V(trSGC N %yAwR!YTЕP 4= Y)9# AočsU_GOѸ?>}ӏ*4]4_"Fi6N~CW|DKӅ͎o͞~"t߈_@58l!d}hƞN kW{xWP@5<?QZ3WZ`&Q]y$L-M?~]=F8E!,BL:+PP,ps"b<.!?ZPβ+Gue_#ԽH{IJ%vB͢KguUΈG6V1~4 `|^R>NU mR1K+̰`טh2'3##K<. C˩!F,:H 5aB/i|^ŬZܿ'jHȒiʅ3y\OoK߅n­%hq"].[|.t{ YW0V|_`^UkwE)cUKO\y#Q%H090D Lv dc>T{\dtn|prJ2OJA4LnCazu2vY^'۞VR *Fe<cc/A0T/NWw^6Du k,/+!43d9_;ADJI~| S~96 1(-&4g~]QJƍHx\? ͂#_Vk%qo$(LHI|eg# e ?xGQ6Ͻ%M Y1mߍZRȐ#nQpS\Y;',16JZY>Hh&rcu'v5`4Q*gBW$T)&y*kxZZQʡ(鏴:4 ^Eu,E[}mneeM@BgS"?$9dwխ.Gp 8'˭ŵ=kF"%[Gϴk{A[ Mk @Bwj>B3 3֑}gœ"_ю"T55#>$aIEJU)|ctb x4hS^;?G Lۏ:;RI#ҟ֢Iz{"%;`g"xosWAXvhi5=$$1z!JW;MLk΁YaYJ'=OKyr@QuCyYq9>a' BՂαn( Ҟ4lV`volRA{qu͑2 c-me%z7!H_F©O++GݮN4-<;8,u, ;?lz9*߷L#1S1w`[)Yt۞7k+nZq`OǠ!1ȫPY9ǵX.uaInOcJj͂n3T.;u1G%&V_ _Uc Beu |E* 51Rg+\̗Ax=E^=0C:;:7 c+pYxN$밆 =jcȜTRLr'7Ur/OeEɒkE?BD!xivW(2<[MClhiiQbRBHNn\~@"qFe{\ԾoQ_:d' m̯TG/}ۢӺ;i|7jvy-}-pO߮9B+#zEF^~St}ȺY={}9Vh֑\MzW-UKJ 0l]-0FסقAsG7XX* Mdu@#Xs %)Z=3&OxX,{BM|E4FyZ䔞cK(K\-H3&aUWhm RH })U&vcc};Y[<Kfm)I4bX<롲v)L;b]_gIQLz,C ̊5:,lQ8(EsH^ a ٢$/NaYV_0|'m?W VFbɦ V&ܺUU6I}'[ `+׈Y/͟El5,*C$9+hgiH1"zێGa0[ұ] Qrj!^exn6l⡝@UCUذGku^Mώ(5<}w5uqDFi6f$7RIR[;!|%h]/#wANF%K )N7t)^-֬FiK$p}t6NhPX|KAD#` glcKyDc#j4oHO^w1!xx ǻ aC0#lր1;oorq2yf~Tr$hR lpT);ަ| fC6Ca&F$9soʺt=]V8P-*'s7 |wN!E9͙QKK=Uf|ݭ,Hu v7%%>yEwmYmpO4 NMS߶>,]?ҨF>K}wYuעȎvn<!&# 眛Y2,aeACBR+zl޸#D*~W07xtv um #L 9f \^SpHvmxQESM5T۠}S tB~nT6v }2 ֚oIkn5#<[Pج"Y TgrOAQFj=Z\V)13> HR$^hn!3J d\ܿ^`?ahS!lywड़Ȫ73VLm\p5*xN`CDˏfO%1+v1vST%<1,xK6EZ-M MZkpx8"1Q( "#[ XһJ?10נFωճJf AϪEEδi@d%rb-{%hᦨThbDm6>ɣa$g{]|LI >k,%CM{H4[{YIb,TvpJ>^HLQTP;פl* @ϣPp1DͲ? /';O>]qU^B|n?[2 Dٌi;ݓzl? y6-kJӟ@^U  ]<"Xr ƶr%naڶY8O%Y/JY\`>OcrW6>y2&SaS4C.⨔RH1Q)=n/Z#{WvK-ib0e N4}yU+~xh="aR\f=(nq}ROAe[{]">6DG2ƜZ 5nR-EwY,u7}3fd n PcN%$čOLF ٔI96©stPQP'8 `$ :lʒ8qM@/K >eH?2Q8Ŗ۽77-rĞDQsGu0֝%]7aJsk)T]L i2!vDzD(}ծ8t%VQ'KZPCa#] ~am *avw\E8}tuEo|.G,7Ob"Ou;ɄBjC Tô['XղrŬ85g' GFfߝ) (gQ͌ &"s3^iZşTW-Auptc`+*Fw6 ڬb90f-lY`1Bˮ `U*(ⰺJ'/#>1 "*iSG4lmƍdeXe` )8aX[,S(co'ci2ʯK,FӦzf'9OjPpLhq23Xs(Su3NRCS.=3֤ |Quf> ԰re%듂l Q+֙h׺i,ėEw|&Ƌ5c/i$SB\CG@LSIp&1W-b'1| SwSAkb I`dՖQ @H7:[p+Vف͘I r 9PO>:`CAhG$%2l$0HD=Cj8"w_f٘N&:*ut_4__n zzN6Jp[FYJ2jD>q#Rm1{mbPYkj ~0Ir*CdѦxy)%-[;Yۋ^'jCuմe9ӄ?H s)Df$?R7sG=*(JނcFr( sLm\L⢺nsYWpf:g؝:(4z%2CY+n W/l׎@nH|pB|bkTܑH$09lC9K"jU1)/ӿYJ<hz) r6;1єjn R%&Z3. ¶|M4tB%Wm1vLQٵWs"O|QsXe|8$Pƣq߱Ep+H!0طS9gl,K!(~B<,GXrzGVzW1)eԔskz]om9,Z{VVXcOn6L(`m+E߷Db5̪83I{{e>Wc◀ bR5#Sy'e\{.;Ք"3厃_W=f=6EٯШ /j\_i`v6"O |(7vH*5c" YԢ7n^#1rw<#B)Atiy{anao+9@ ;tt.MĪʟT-ZbRp{dz"x1_y6Vʹs(JSQ aOc&vهt8֛gОcIO\jȈG,9Hj9qcy ٧m+59`14V(Fy\bɌR0)j͆iձaZ7^nwDg= U6) fFY?}u:F#$;(HS(&Xq`H g>`_ϫEgtxnD,K+ .R}goloVdzÅGcI8NC!Sz)8/ klUto`ݔ7HÝ 6}tKSV tTr|XNJ⩓/{X56G*Qcdfߺ?)YH6(R E,|\ "&ݬ<,2Ѯ^ܕT YֵhO)GveIi2F;؅Ldz9ɟS 5BY7ㅌ ke&ıe/|s'8 WuN sqnޭ?9Wbޯxծաv_iF0 К @z\{tCg校^Q/A[iVZzK,صʌ*r^$9E ~6p Dp;Ey@m 14qZ7m.ٴ#"+ykdr:DbsV| %Fl#Gq,<#AxfX6TYZ+7c^4*W٪}oY>kQm!HhZU󄺮wpjHW p.5lQX۠(v俞P3ɁbY\3M$Ҧg)@zSM?^wlvt:V~ԑY5+$<+fkxiI 5H z YŁw˃vnuřg =h4/cu5Ozt+&(!qi\ R3}dB\9_֮ C!QG2oiLp̶l>TԢTp*X*Y猒 yUqU0d0pG-R{I 7.@7ȻU}lO83v)o Ycܗ9VGXAJq'JNWOX׏/W)|.g^bb(Wsjc[u-IȒ3d#\H}{79FK;^#FO&JdGl% FYHsTtxʒQcNmY^rdC:l(ᪧoj=e(|vf n448ZHSz[(>aQd΋W'>@EySWa!' ل^;`sݝ Bu~\w/rlC=$O/.RTJZ](b9"(LŠa^ۚA Ay;[*p6ϓJ]?t6p+55Zf)vD4!n`ϒt#=ۃI">DSj.:o F -2et{HOê,mF4c;@*\fZ+:H2/MvhA6wqҠ~73rO&ETamF EcCIWզug̼ZGB; Woe_/]>==Ļ]Ex"3>#7sg;z(vQHhHkq69Q3] EWjZgQ,fp.*/i%mv?ox7r28$g\]3ܗHF^P2[0n$ $B'7i /:`CF6>7'ױ7eވmIk2KYXbnPnM Dj7("|3m)`=N.dw'2w!e*Ģ+`NsGc52़U3gP:,g4rAM,p\Q'iW_|¼> [G[?hm]+x\7cҭl0VM:W]a}< ?[HGVNkÊsB*j^]Ix UЯ}r2Z`)/U8%OP))˃VWذ|MnpqP {kB`:=-_cN]o-T a`efjķTP%y$6cxG/qM+91fxH9G|xJ@2tX}P _)5GH|IL9N1b |@cZq+"SDBoNk r@֣-mj=%ߡOY%#jBc8#$EDrdյmLr V#sj姐I8hơ3z[oW2Ue7 WKӥ"%z%.Ra%1 C'9K__ Ȓ%̩(-ORu\J᪖ٱuPQ\>k.tnѷo8 Ԃ( t9!ph AjK5OL'KYx4dZ1z_>D{YҫZMH1%{O.S:Z9H.#҆;(|\JԨ"#~|#zTSE>+q`;{ fe8j#ˊ{Z0oԞ䳢 V:qlS@AѫmI}Q"IsC=p0_~(j*}#cs- ԔH%)4{@ <^mE'<$JUzpx%S 8cuCQxܬӄng3/&~eЋH9B; /4?ul*MΏ&"C/r1h}D Yt$Di?봊mV3|P_#vwVt¹r!WX3(hyJS(>RF#&mq1F:v?GPblP/ۂJqTލ"f$יKG1[ztׄ% QMqЭ_髱G@r]t8#]Ej*WA vC)w_1P:ppbtsLaӫz`>4qgh] GI&DϬ?ۃH)(7}IMQl A=C,U)SіC͢ LIΊ6w8]o.[ufOXHO79 NH3S{ CHfq.ǀrՉ'Kȗ<-JÚ"Mۖii n$Pn?'2ih)#zc E,^&@͒-Sdz|~k9 }uNLވQXur%5d,2&3hWvUdO&4};uďMjP"*juz ܥbۢW• ϐfA1>co/^dՔP^8޿LٖՓG-mf]#rƆlaL+͸>YO4Sc0%>T$h֦ƢG!UO 8 b!TCѱ3s65B9JB _-N&{ܒ7tuqM~`9mZ *sT!bI|0=|l?c+|A]mul TTSF0|>.C32'w^t 2]zU2? dʜq)}Y[x7a7UٳԜ8TM:|q"OsTF^#ߛjQF_d ת,8d/gInI<;`hv0-uRVjUaH4^1 C3 ֆ#QZÑ020jFX@|R#c,6PrY! D3U2X~]K`]Ofpv#ŦhqݳJ N~2D Z )}bT<H“`zCq;uY2 m*:MFo .g&# {"W"Ԝ1wϷ(HeKIH`BcI+ӍIo}1m^Fx>^bPbͥ [c9 }|\qȇD+ _XIء}%szTՠ +1%(haS )bb9ioV[.1`ЌU)PEL>Q*CZ6;1%6z5Sg_#}ݛe94S[~klᳲ\ C},֜/8˼W)9J-DVh\$b.rJkͳj$J6UJfe“!8ѷͰP!Ci)J2-iByH3g.4sT |HiI9.CWj0R[nbq4xWwڒHd@鰀_)A$U ]wy)"gYirE쁗KJl:WXQp:Z;rnDJ{EeмeOkX0IC8Y.)jO :qGu^+e7 p5Ӽ0)uS ,.k\h]Ϛl6O3ɀyArL{PicLp8(GP'O770Zi թrlC@Q^D]:1)2̷7d^{tf89+ty> +NO(f^HP7*[V;Fǣʆny,rea@+~#oO!k/6>h,܌K [սb ##fM^]P:Q&PvxUyAQov >itᔬQrs1>Z?|{kAlCAU! K<^MP8dg/)6\# ]Abgrj—Y0O\:Ό ȴ.DT䅈/(q!k3]-Y3޿?~@ \ z%Y!G6h~+W45FY\ ~ B ޮЂEP6c4`74Or"<7jh4JH&WHO› l &8HzO ,g&i86Xw4]Et15⛸CĘ܌ 0m [),E)bJ!A!t\AG} ׉I΂g}%tp P$298cd l8YO"gk;itjڨ$i`xu7 /G<>l#N媿,`7eDPjK=uJi_ "w<\6˝ 8#q׌w@RZͥқE #P;";-m <$z"#ΰ0K6# H U1v.8\9'VCC 2QLD,5>< -mP8"ô݇j:}{E;W--}𹐢>7L3'D-A!R k4ߐPaF3t b4Nܢm:'ΕEa@M.r^ 7 +㴉z`6Z"K8L$z 1qp_.q1j!MÖ,h*,5oPp=ESI7(e?tM  >@^b6\wcD1y\0Bp(w(?5l;$ 6ؼxrf!Fy폀~ 3Q`{R>_=!Tåԉei U0p;/҇KSW0:^7^p8 B;_Trح[}u@6:企L 8+[`^Gmo'zŴd |68>Ġjs~U|RPw@tYͷ{Ljń$yI֯t ^GAEVb›I=!YkQ耀R=O"B50Uc.#hv׹k.IMWnDsD;m# U~Ʉځfo[ Nw`v NxhHA5>T5vTohx4.~ri)|&nߘZt0j T8`u\7Kg1*C"=W*o= +$.3\講K ۩sOZF`8qC.QeٟS5>OA9Fh+p*+ZFQldGrFX[[;vٗ~g2rt6YbL0'i12jQ`oMҘ@lc5,lJ5vY&gT(oVwUoڲ?r5@ KyOI$׎4*}N{Y) /Ax4!OSIs4 * x.|>|סFF_þQk/]%-\ hah M XUQDRTbМ(o ЂU˽i[0, R@$9 ǜE{ xÈ:8xfϿّb۲܃) UȬb%Yu0) =KsU2Y~  ` :2}Jqtc 56Nl)Ѯ9Yo{b_J-X/Y80͝|J.}G̙?i%$hvm g -nPKld74Oïac]Um4K YU:9_%L~:UcqR2_OTpuypS5cr#hNr-W`V/d*?J¯?w=m 49oby G^Μ"VSvO@_]6wy$,Ky5>YΥ>,}8W+Uz0GVL<J s ibB*n9Jٳc\%y.q I'J𠹂Hl )M; Ð$+x x߽LɘbStm}I Gwb40CKTWS BӋ'Y(R=宰3v.ma~<0Bi}j\0nlxa~q A_oWk%rz^$a0! mL(Ї,:__BK,< pz·~LhO%eiP`)Y Dq[&֩}880zp*eP LݥzOrN1'2*>yinȣ%F{P?),ecv iQ7e l1a1|F9OXmO M%*v=5 CUח1XJ$`Vv^[h"r"CLahk6fC+G1+RT:1T\bօ̢VRc@^Ϛ'hEl\@ [V6; ^TA.ޚm q-N~$&4!n\r?vZ`ɍ#mMo&1S%FOY޲eKISCb oxvJIdȆ3Q~!’ו]C,8( uwthiL|n6tܶ}i:@w{[ خ{^\s/g 8A}Vl 6ߩ11򇷨Z&| 0(qܒu 1N]z*CxXxPއ*O~;0?5:~ `b:$MP) -BQk;"wQGFl* {\eQ(^G҄ GoP~EnIJ"oDz< T)4Nwփ\FH Yu+=[|;&'yjG.uS⑲+Ȳ5ʞ Dlry83Vs@5&"ʳTUM:f6kr^SDT B%kVѭi#ŸiФ@%٘hmm+`\5Mӳs:Gcߏ oI$XzfC nud%ӻm^"-y,NQ@'4G/k+'(h6D`W  tSKQ5. GW\eErCÊqѣ=ZcY5|ܩ4ڣ /x@Z"5:Íx,oO`ĭqZ8nEd7SdtPR(ϳ vGti% 3A ܻ,ަ#BVGL%5RǶ{~{N7 +T91c.NZ{ ҽs͜/T"Hb8| <PyON@{JjyDbwu#Hx?bs\D~(h$ QLT .'^$zӡ cZF+=a: ht աMr Jߵ< W5KócD7[͢Ϲ/ܧu"kQ$PbTX̳X_PZz:`a+OVw՛#?a5Xs-{ D WmPZRj\Ү[~ Ŀ̝Ǽ;2]# Uא2h1nR{K|ΣyjfP)Ŗz FgMO*"!T!l";ߪ(+ 'O2<.LMw U1UvX+-}HߏVG$GWf8P,1KOGy\}?!80|qh~,q*lߑO'Z0WËRG`9زQe|9VyB;"UuJ H.yuԧIJ|V`5( rC ,7X#MnzL6}7uַYgP$~NUJ$Q(+dO$'C*UV!a?z0u&|T{=PRN]n}Nm$a9J egJ蟶]s]?翼)Ƴ57#<˾m=8g}t"&DMo(;ʳ׹FSS?IxP)`?)V*Y^݅w#3/i+An4iܓO7_[f^M"!:Wz{Qln⣪@M 0zȹmA\K;w@E%'ubh Dݒ^ ZRYct:7.|&9HY$"w`}EiQ&Eaَ4eb_U' e, }TPg) "Z]mwa? =ř!\0(c\ WWv:Yb@Uӆ^Kuߵ aiN9gѻ}z>brD֔/B0d A@}rj uŌb.)КD1{n7pr`yuhoB n qYA/çp6+I21ʴ@M"FE)VR;W+XGV/G#-8 NM$L9ϸ١zg'4 AXWryGUfix\K!Te1=8r\d~Z@ >Wd44y c=r* V7 9~ 5w2d=SGR8cF(&S)zWb/iujUƏ֔U-3h*- ‚Ј  ߓ*>4v;,6$Mή o0LР$QAHz{\:ee\ƾ-vU+U8O"Dō~SؿWYLF9U%>W Wru6GmOEg58̝Ys#9fdOVrvƜfH%/?oq(+U(Q|!\W:XSd¬'3 a Ż<O3nE Fhc0IsSC@wY:.# |k(6**oDi)OtLC`,3ʐ9gnjdS+K!xzo{F2; BvOfYC^Z~k9[x4bzdzUGâGN*! FV="m [TruH7d,Я,Su#AF y:L(?:N6`ZhN#P?Ov'z,&Ȫn5GGv|ܞ[ux_Wԋ-^#<^\N=θqRei%1|,[Wqz|PZx7EXX蝁|ԯzѳ".$x2Ȣy~Xʼn:(`i:daDK0A τ kS2XIn$k9H<`f`1~zGvS-Jh=a'ܨmer8AEEAj>$r^Ӹ#!_&.~s&mbQ uKaָdi'3j%L޺"4L M~ZoZȜ;/Olr=]0bcBִR(| %S lQA`:EϘw%abeĕ@%+stuXIiSE"RUhX}ׅ]pƂ=@m)<% -ǥ7p OinאIgJ}sX'[[-V99P7`mE޼/=miuw'fZ$&pG߯"}&T ꪓV2|"x޽o:t5N x& `Tn€x[\b:ē$uVW:g/i#V'fjZڸa@s*pQ'm>6H 50O hP[6TSB;O֯% =6DV |谦~TO b4kU[ U#]פacmȞwW {~nD篌-@O/Җ +BADȈ= 'Aէ"#+[hǥoCgȜhjoQ4%(dY_F{WuR5/WvyW-J8T&z.cz 1 }>KNf찭A GdҖ=ty˭QgXI;)c̃y XP^Uy,H1&c:Fp➿a33FHyL\rUAiřo깭#Kkl1OJSqB*'fgqu>AO-rv;DAܑu.zK^p! hR~};8-F68&Uz\۵&]QO *3< 0BU4DDVl ÁGqe%dau P!5$az_j;D{UFd-nɖ9!#tkG71!%h}YRzХd>I-Ვ9NGzPd&xz17J7=YGHjnYjN]GpJ[4i5<4 C}r;|ajpzG]7GtFJHT+?w`C:Jʀz7G+࿾Wa;4L+꒰[/+!{8etֈ0;͊r&v$[]p%Y^U޼P=lܳDO,?Xn/'y <×^‘]#Ts%{" pfC>pQr.Q'ʃX$S^ eV|T6Z^aլCIZH٢ytX|6De-.n2`%Ccb 4jFh:*lYshL5_ {5/̄JEs|ME\Y-TEKzǏ_SS1^)b;i+if|e4i:)`C? )sig8 g(S3i~ p&ẖ>21?cZ緫I C߁) lMW%5Ub8^K]Y1e;+H))`SϮ}$9[D;P ,rw*9%Fn^[9"9eeIg'F$4g 5Nq`f}^g`߱2u`LBBȠqFT;7 v,IKESf-k;@*)NT|dUxmi3=?d% O dsRæp ǿk*ES>y+(9r0eߛ0Z/jP[Л7ԣ| #Tbq+:_<˶p {m%ـqŲ^Z?"ƣ21LAXV !`7A1Xg:XGYNÑ&0HHǧTZZD΁׆B&\ү925ܖ׼]yTS(i;o,ңR}nIaTU i9S9瞋dָcĥw`7o3Mq:JptNeaۖ2׹ՃR㻺/!˵JϬ+NQyf芆>ϯ\y?k4+\5VҺ%tVV v@ g/7%8K(ϭ|YC}H[J7tONNicMMm*WaD)7C=~3HxX-&v4F*L{*}k3<%[sd;p# :1Ѿأ/-^Ys9Ʒol*_97p&\@[όč5idܫSdS7VR]n%yOT(SbH[ǝtI٧M rh4]lGuX<h5o^7&^BexJ3F]}] 3 'rL,:dD \GL۬sR%lԔQBL ):u?o74fX=шw6PGl\F0sYnr(x1> u-5X\˥$L#XdDYy&N(JtM_44ijRIs̺ vsa, Vp"xums n$N}u׏ ~uDؓwj@Lk촨ujA r~"1'ΣRi)" , (R(:>S38פA_sk md~゛}u@N9~y/iX;{j/^ ڙU\S4cx]fE4T΢i WD!NY)1L!nU!xu~SC梚ÖL2>4gh 8Ц]!·RK JgCgM>-%XE&nnB]GT_6|hҁu^\ }[6`&/=DVHmȃؤ$lmeTV1g4-R~(GPX8̋K3Ki )[z,gMx-"REXF[01nQ?bgQshU(~vnKKEKG5HNޜS%(RlT"HFa{PdR %sCit؝!nPKg@*#->#%/xЋ4gxlZ.~@wˣ*Դ6W>S4sr`Yؖ6? ۲3Oqz+6YbF証|YMY͝g%+m!a-8?Lz&*'槖x@Vy+ṉVCMhKRYn~s'P/j]#QNj B15#!VÝ4wac)Wl, U:NSܜf'Ղy=PlW4YuDѸX"CE}qۥ c~DE"PjJW<ԛcFh꺸M* C w`q'$J];M̑;$,ԋ wǾs ?FgJ~*zuYn!Ow7K:\@; ߵ BUDW-F|^txH&N1!M~5N@blNbvl~Z:OTƛxak8.sg n. ZUk*_y\̌0V;:޳j-i麦;!I [/['٪_ցhQX1^]!G {Xa6)xQg^&=!aPU|qJPﴪvXվ*>5,jyfAYӟ Cs^8SAQ A岼 e5-4r˚櫑%;i]y3IiYDЂ̮CfUM=H/"[MD5/78Pf]Hra jjfA pT?xll TM(ES)PCv'rD~??dF!fpɯve LU7[[Zf? ءnLScWDx]҃<22JZfgZx&zS >r+P. ,N2knASQ 3׏rjX91)Yͱc"DC8Ɣ$(7]"GK .^q9$.. NIUd}su.@#)["֫;JDz66BRg(1):8S/WagqB/ACsUao+&կAϭ(%//R8^*i(;:??WFd=};o")EcXrST{ɑȉ.q5N OV7N˘+ p@d,X:?"0.qS|"%T&cTa/GX<=: Z@o7SgKw'^Do:R~;0^nzˢD#/2\C`ӿ>-T R)~8^ak)uFdg795=3]Pћ6p#I)vt09*0|HGiWAwXzHo,ߋĽsXCe\ru׵eĤ>E~ʌgWAuvR > wy`tM_][iy . bnм5k\0Cl>u&)~P:M*X6-֝MƲ&8\#uv< ` b)<2)D,W#*9 m&V!.v΅89 XAo kaDeJTh7t~Ӹ?'9tw,1$M%I'bJd+m>6F ykͪק5oͤvǦurTN=l gҡ\7K_,+z& iYHAUK$s,}G |aq+oGGGrij7 _ Genrs 2@ VGTܿ@-"=L(EXYi>QLD64{8Iq18 .@> ;T\1Ul[W͋Lsbg%ܦex咴 ej󃤽?v)^ݏ2ǛDKWT;_ԥ; 8O2_N'QM a=Y[Pu<ʳmcIF/A!Hq9L g%.Jۄ/St? mS 8iKQcX}?H͈혷uc}jy~* =\L̒& BmWd5NOkxWDŽiMu)~=؋4FX-Rў6:\ K4 u %]Uʉj 9c(F\Y)vޢ{Q ~ljEs90)C{jS5KK@+J {' 11AnHͻTQFHމoPDHbΟ% jKTwXnO셛RO{Ҫ3PPx1):?lj,x:L*$\NiZÕkl_I~{aq.LNN.6:4AS8Y_n|%#Oj{-0hvm&v¤b. !XϪ[狧% ""0")p_hx{47pSkyOhĀOJC:-0/' Ѝ*^ B3DR|Th\W,=Øi#?J$[N3\v(B|^q:Rԝ8~+≨ҌByޡn,vc|jN|P"hIcy$<E87}4-?>wCԥ&*wO')|Tb 8\f er9A=q/](ХI ^aV=vDYcهhf9{w*vF?Mwwk6=^~B*ݗq/es'I Aр6giEP&6cGx*JNTO;YݳL)O*|zאtsQ\ 3,y"wD>u}*ǛVPʹ4q_VM ’fZ!"^?љcXը{sLW~UкގQBuwwyDc=[EP~ ٦L t"" 9v=O^ Xx(te0`1A}'Hz(KyϏHOUlQ]\V}XhzԎ8=&J{jvo- J Ίb4JچxznY=>(( _r-FqC<$g01~+x4"r9ه}D3 2*xĸvT%-"+hpɩц]jw$II~2a4@*q몝[T&0B' E4x8j^bNKc}11UiLٛo J]s@; Ԡ*ּ./L{z +|ކFeݱ-[S]w. zMY/~|b~K 7|+T0ݩ@b:8c o->.A*~^K.uCU@9wc蜹hkçϢɅ1`Qy95މ79( hA3in>ұ+eDr[Oo/:!xNaҸz=$yTOmG_߿WP>XJdkn2?.dL`co MVvXUԇ~1{/㜫 әsERn$!) AەG˪"=-IDiT & V?7spt2"yʐQ=EU"2>L94*=s-4`RX`QjkifQX2!;8,[gR \()h;vSGln'CoC[1<+9K ǐΣ - #5qgcHԤ }-\r-kbКRm;ؔh7?.o`HJzY=J qD}KJT/!)n{)_T'&"=o FebJ$_plv1 b9G%(.YN8+zĻ4pϿV7&;8,t rO%OfCUHMd](<Z"+ع2<֗Knxչ /ʈHy& s@.SG%cL5#.iʩ$u'3 uW qt(bѿJh,I̗W5%U-;!SYXw kē֌)乴q5c)0ttF¼qYȚ+N#Ӷ0j;,P,D`TnԮ7]hٌN'ha=ATSL])"5_QY8e#[MIO65BU{Ƃ2J)@ a\.FX1胤vrb{j Ӫ̰āNJrjLI5Q * b.{ݏ췮so*}ۇřN{+I– jv'Xj^8Em2 Ʊ;@E2!XM+#8>{^@DW]B$Aj kHҔX faRdb/N3ګI-Ti9IaVPS!XN$ŕnoygfeYyObQ1% ruJQ6Gݬ461dLZuU jHݍw'bmfx3/ATuKSåRɜGUJ7݊Z0} [K\%x]p(t*H-O"=eGV6j5Q+EBq\ӨGo-\s1 I<$Onw2dk/mREPsHj&˽g+@8[=}%h%-qSrBNpY3p& Smh;-j*x4{lV&^Swr.`m,%˚Ǐ_Țbjmyp{ZDW 7n ͹N$'!{<0K@}^ksڣ<La{md2X`U2/;ߩ_t/M--B շY8Uopsuzo@[7韟v6S.)="c3\ <.p=ȕH`+`gfxkꄋR1ㅲ~)Y/RֽJ  Fw6*5W]%$y!t,%L=cIX1TǾѐ6,8Mjx2UsjU]H|P7=Tof%J~zybc^#t΁"g挡j)$;WY4.xvc?+`9*qT#X}GA.cC~Y\ serjB[Ҍ?'UӤ?;[H<Eja*G0ſ5i`+$L).&s>I9=%tp,A "FvwEZyˌ%Ec z+ 8NXϭ.8tpt<ML&i@ ͼi@#P ~s6{M F&m9Z9LiQ:\ゞTV(ygmzwP>cyhP v41A-o"|+)2ia5HwIĢg(('V$DnA{@BQWT0 h\fS_p⁡۪nO?ŧ|LYWkt.4Kn@嘄[.3-Un0 :ƙ:tAƍ' jȄbg;rul6{au' TGlMɬ:b]ʅ+-bb;p,9/3WP3+Լl0vE}aMw{HOHV{ܐ?D1_- q jGʂ8q>wI=!)!kϠm/^} ٶ,Ҵgo hwKEV$Rñ^"ۜ 1PrzKホNӿmTϰHH{K#S_yWX_℁$#*/IwGL.ý\Bh"8nS2ߨҟp1l_ *Q4Mniÿϼ Ó ҡ]sB1 *ט^3ff0 H@d5 SE r 42UuRiUujUj.xk&ֽmÐ5M> ֫&s~Uu zɋAz̘z*:}x&y~퇾a.ld8[:8T8'8Hϛ7FP؊gANzpJp-Fy9a"&J;Qb#[oeJbak4Ҝ_x8`p@$seLR6TFef`sRe~ .cr(vK(M~7_ %vs]ZQ}fN^0o |Gb]m9#etw- Y{[7 N4wU@ ڑȶh= D}C/^!Ej {tRʳDrjLi=K[Q1RK#Erz$ݕET/_o_m?pᯁHDUlWaHS  #y#nmYJNbDܿaQ&P'N ã "UӢyH%n($J "be&qx㉃]*2qOt@>G˯wbҜ)8lY>ZA Cq"5PƸK . q$E |֪.,_⨸b}b,{7հƧԘt#]e_ 7~8/6=-'rZgS3%Mơo%6np塶SxNzVi֖o' Z@ a\HYs4jT hPbN-@쏟ǟ&ygtuZ_Bl&C]d}@+U^ɍFgGy+ݿwo]PEPZIH!gqfAMP5!!):}\CObPz[\=hu,3%zF&ЧY*ykygR::l-W<'wnDʣ, S+*^4#_krc'4:0Jhދл+ KfH#UP +"p&H#/M:'}Ćʘӟ1mI!-E>B1ƒ1$nzW ,8ht'.%EHu"y hke3g.TsZ|dj=z{Z8)L%OyQvJI}uNjl]#ghz͗,1 IM^;HjK&z9"dAdr>6 ֒OLnZ9`İgjKtL`Kjid爀_9HERɃn^RC>5ėmo uyksraK4(Rm(U,TlV*Rua_]ʙz( j1 Hb5Eˉj Wʱ]a f+}J6@(8 [w`NN7[/W"0z8P14[*n W\ 󀤏VF1NesfPL7|P >np?<d:*͖_fwn\v]ɃwpRqypHMSBmH=~ݜX#Kw{!jbApoF3DI}#JT"c@&̤?CcΆ& E  rI B_~oj$v c(*XDGAr;-#'*_[Z<$!%L݉6z5J0fenvsh.9ЍMV*`m ʃ8c /߰Jr:B 7V(]8FBDߵm 9䪽 Wh7`7 /+b MrV$%k:]!R`c؟s:SJF\FfޣWIpE" tLNm7uP_tȎa(xrU۱琦o+.t2ީ屷e 6< v@iHC ɈRESI=~1n;xC!rdDU7N\zk"HbLг{@%~1ß-? *Xmܟ'O2{Q] mPScO"@vh+:#5dFz-3K摾m`Zhj}Y}'{rf9]x J=Ԛ/Jlc6hrRkB- (0ᣥkĖwJ2:yF`H .T@ԴR6"*Zvɰ$+Ri_4 $O Pv[==l3[Uy48%i% C*n>e~p)rQ%y;$75 o 56r dk /憒Mew3nfi v!0 0N=KA7!g7*鞫nifLRAuj>%_5u͝_y+M^EWyKy=> M&<cPJRԸ_hw$,p1XPpUICkgUǚ 1Z:⿼TK%bϙ HvC#CߨU>R$2!aJm)'|^0 HK3,^+kɐ})e5 s$|Gcso?֓f#\UPr1mКqt/nrg(Ijeb1hPE:MH`'`ُaĭvb "|á< 5Q ūz B{s*m 6nN6Bqa@TtHk[diMk+˶@O{ڦhHkӡ )Q mT I|lҽWp͑\u7敾Z Ah2qhZ>Qof껞{|H M\# SIͩ*>n}XA$Vi4.\x (_D8Uuq2$pj.Fg~O8E냼b^i1~B$.xAΝƉQ{wTi}5ӷ)HAcC;٭@$Ir?t 5m9ïW*JxuG=&f{ FV8Frڑs Q.1}\ִ`P<_<#!4wހ5+QY qG*BQ4A^ٰM? Rt oqew qfwXAfe%&'l.N< rPѵ=s 0|xFxDW`Q߾!=Kw3~kX ~{D8*+faծ>f&^uey%Šĺ<%ܜˈݴME\枛WEꪦ>.b'mzE:k p%-\rgj :aL'/6ļet-p#M+"QmYb|:٪6e Ig>; M1$d0 B͖emAb}fAˤĿ7՞*91'ݝ@D՝> Vv;#37S3z9`OQZ|eh)Ϯ-/{~e! 遳c%9ZpAьۖH8M6K &,EF;sΠ_ժlWqu+ӪTWX7MoL0{yz:_۵ӎp8ߙ)iMdJ9"޵zr?# La,:!/Mbw޾Z|-zyky|==%B"UvQ!*_A۠vrLOS.ဒzZ^ >h]*uptA @ {g|ò26qmR6(G6'moCv 8S qeîb8T,nS/1l|/p>Oǚ mDCiYN[(xv>ذFW' ^F #Eh6Ɉb…"Y*5kͫ!~5JҋŀҀU$d$6̇^:qPSQ jlo2ib8y6n$/Nw4grfL+\{6CaǍ?Fj jJ^[;Ǩ|6j2Yڌ#d[LOc{{\}|ޓe{&Ht  uhS2? 5j'Pƺ"zŒ:} T) UG\~}\d2ԏE%0V?(.$P,%?8Lq98U[L, tze*e ob,fڭ]aK(6t]`8kۇjY/ %c/ŗbb ә6k}gU[HǨEٟHi!5"=-@ WI@MTlxy2ݏ(S\}`ʲIW3}ǥ}2#6ë䥴gxz:c['2SZ5.1F*4,[ݘ%t$)07h)εGLH:}]#5 J@IžȜf6tbmkۢ٧$6,*#S_:V3m8؏@x^e'j;3k+(94;_98ovGۃ]mBm:̮ pOցI6'K&|:ҷ3* 8v1RSb^1.Jh&$%5ftl/?8S|H@BsC1u.Մm\~)T,QU^xKL4HW[mRׄDuY *S~DY}bt+Bn^kΈw݋kh/AL1u|xi>;kqbܘ%tq?6ÙWe |[6Hlz% !bc305ns\CYWi`4v ly92n% "lxi2uF(dHJ݁F`#[R̜?bw+y%qp#_nZ5XՃ:dHyT3f2 wxOY2l:Ij.sϖ% BcP *Mt+0m7&P_%/L8[ѬF\n"fe'Kav0N2n1 O5Ćad"yKeDOoKA FpE=NͿ:IjZZXT)fO# k 55g=C,Nֽ3'XvUtQuSn^[ɦ|PoΜ_v[#Y&)]gaD=FQ NV.vhn7E:Q+ժYY0(,z~cj^Y2cpI"UXHOΖnh'5H**)xƧ}+5q>aRQ`lBh[,$YBI҂uGn]Ln!T<Ù2 ;4fIJJjS?' d k]8 0 ɷwW`Iss+ Fm]N~kR ء6ҒS5..΢C{yoQnSWS~!' "q\ *d :GgC,Ӕ⑲s޾¾;֓T+sL9=*Y!+my!Ĩ% 0%Sr4qU C$~W5aq :qrm^4&q6]ʍ` z3tK.8hp&.6A9̀0"60vmHm9&[P&g/.7R`ۺ:QRU&5b4:ZݓDIQ0\(MƊ-oYGpE{:'sp `8H3jDisI0sF qMڞ^SZ?(XfԲu#%9jnP"^?n44!=+%ϞLHuH H 5 :% nTxJ)2K3)t%3bg#M_,h҄PMn__s]SA5$-L0R\h7uNka,%D-}i5 6* T;Jvƕ}#|jPLF/7>~7 3unWaQL?UHpn6/ru HB#okq#>yA ['o>d !`$J'+Y*a8Cecf85C,Q,G@rJHNBǎ$!4 |uYX Y Oد8Y(}ZV^>zwSdFIM7Af0ͅN?|\=8J 9Lvg bƿf jj,)S> ?}WKR;Xt?1ZF# QL$\ ɟT)J t>o/!bf5HLu&!v|^$Pu/Ҝ7R!vVO[z {|kbkCɼk& jx]o &î_Gs|8֬0SD5-NyYH~ c.%|x 8z)fntݰDIs[Jz@/ LtLͲ x^>~3vDV"so䮆`Kwlf{GyJn3P!\ml^,ʯ i̓cViJ?8Cd7 F_9ïhB *|-"\~SƾCffBN{I+uQSlb/?k UJh<k t]B,}F4o 2axTfn KQA6pHxn.iXV:=dRcWȗyJ'C?'4c F'ARl<R]7R7f a'OpfU8}'>G)[JSB"CeK >gZ'OE ^SOzeRlVU6! R\=Gd@`Thȿ u{ȏgXXj(<׭#y`7i)@AҒp]s`ޭ<-ǁ ZkjR"0xZD ҄w Fd1< 8pU SߧM٫vnqb!hZ(3` F/vRWK.ҏ!Lo(zߺZm)Q,6~hU'=Og|4OةGVtXd*Jv@~k-nZDZȡ=%ŕSpach;=^[ȵ@M`FN ;셫NAU`k/cp;|' BmLÞ޻L#1GǎPr!>G'$[ B < pR}Hr/maM?77H&&K ƌFlX7%YG͇Cd-*QaP@"1~f=u+gLtS ؚl v,}*w0go%?GD.LlYފ r_2NIQ'KGƓj4gH-qJB֌xpF7  i7&EO$IѺb䐸g:qgE~UC2xZD:M>Z4#31A&L[xױIz8սvn&LRtM}'^SljT|wE %¹C6L{62򑅑R8+B؇쬏^v 3}QnաykH-ma,E$\Nz J`r!YF8EXxgSM&C4g N. Po17̒(m6=; FNۺh}W#єuD@8u~7ҟWE֙ſ٘C,=e?xCzmV|yD|+púC0~#v'o{"bNZчO %\K]Q,W&eG-MsAc ZȬ w z%&B+zq-.|06Ѣ^&7dڽd8 =dz=\' Lvb+;s R×PȒEQ'DsF=ʼa1\܌ѿNۗ dͣHw[xdV쑷U.AeovQ'`dy )^@8I~:m,K)|o)wwtNOi=#߾N)e3ȞE 2 _FQoëGYS|iB"ʜW[G\BXo&UûBzKŘ;%ALyL$0|2ׇcI62 #RT3,MO Jp6S%%-= RGGOCT΂){: v+D⼡xΌQ=QvyL0Wұj`?\y$i_7skB_֙6cdYjB!a0(,} doMpg6Uy׼ECdIƬ~Wy3CI&űяfP]7҃U".L(FHѲ>f GB2bi)iH^os|H_:ĂdꗈFv0^fVE@=e,b 4WҶZ3J)vT2|)0yƾ,J"Dab;}t`xGuΛJc6D4OavaL د^e=cD+oDmW\U8D*wT-7nrIHPUBȢK>)fdU}+- Uͯ\沗ԛqS@ e.t̠\qw+Pgz)#,Jh$CbS֣B%EA[e奔󯤨^=(~tvMrl`_B? oY#9B/ A1Y$ -_hu-E>sbQ/˽T7ʕ>"ڲG{/ء] #|.=[2zhS]%.}uK"7V%]w[_c6b%f*fHv3l<#m0A1e!к?݈Śd6%TĀŔRnx֜utAc]%f厓̫1(  **wXfȉ3Ӎ +W|>27^O٦Np.&n |.?wK y!q _82f 65=r dk;]Q4Vs&{H'PmgNu JLQ%̗5"GJb kFqCa^`tC-_~8損kS!@ KsqJs6> GSH*@,țɜ^Z&")x #{M;3`d3f/l㬯O k9toݕ5Gl;N< L=6&Gێågn}_+<[vYZά-.6 ARuGZSt&o" PrŢW=/[3ivckW_Q9G,C`:"8/M6JTϣn |G>_@_`84 RDeh*;JAn);idd] +T5 ZdSEn4rnqTDbpƸd?{`UIX 포O$ma˒ huXjO=TRWxfn8Kp< S`=Dx}Nś R7z&[WʿƒɵEW O [Gr?*<ݺx᭗S(| ?Gl{ȵY^KoGx ro][:3:$$&'(9D$wDm(EAT$G!zhS Vm0MDuͪ28޳F?b'|k|MO;U6pFiѮUӞ^]i9&oN YLHkpl<^Ƃ2Pq?~^kQ5% ><3<ey˅>jN %@$NJv>Ԃ]sK1S]5gBM#bCz*e{H`) \KwX(gZʫ7B zVbxX5}P8@^3d0evqT p3KSig9{5F&Fj)rq﹗/?:$[ Cxw=sjd#*TQ^'g?z\O؏}ik99Mb v xy∹Gx!$Ιb*1'nֈ֢N8zs]\'w;8ݤl+Z0pW7u;f{<G%~鈁h2sq/ 䝓Fv1Tz5\ WSҀ.ܒ)c>_vN)Z{Pe1-6Gﺙ +B[h'dʴڒ{@*2:17(9Z\_bӂXwMdF&4DNlE=#0)]`M7q]|$@ᵁwz{s*̒5٫W] WRC?)ZZ +^-ӓ,~% e=fe-!P d@1\ B` 8|#a$9WħsUbaæJ)Ivô(J؅A^*j;QxY'z"Tx6,5-RnI>˽I@l)DbAp6:A[uo@+Uc5k'`=ׁx⭆}){ m2c/嬄N HQWfLNB0_yװCWKֲf|v`2v@]X/rlv<-0B-K m2Ԑj\O͑ZIU֕&LbM@>U%ɛؑԃv@_ J 1-8B8ơVN~V<&i 2DC!q3,YZ>kOb./]e? P2 U_ُ Fiz_TR !S^&x)u,6/,4%ʹJUQx ya@_>+3ĩG c}wD"~tmN9&Xx;S|]ֽVS,Wd4/Xe}{PKa^oŪqǃ4p/Q@&}Ur޺͉T4O HQC-f^v`w^O,-7W$E=^69_->!lc-eBox(r֥<;jчӒJ~D7+^5g\b0y]) oi2S(_GFֻzl'7ͤ0O!5bapf52/ϖ Ďw&~ޠLS]2uSKC9vnpE{̓dj7Y9mDJS\^ ˈAnჀÆ+?{}{{d^S+|_}7V:ݏcعJd|U^k)di^Qsƒ䍚1Ȅ ܭ\XҖ7`+Y6,F=`]-)y`aq fBK\!R—Q_,^ Yv4wʶivDnqfml KLA8n κ,+a|6U?1H^U ![/|TʲVruP*܏&cHw\9b-~P-; Og s8g!T!臘D %FyʜG1s_,a~MUyt7*D`5I&o3ENW^ c^A;wE&- n&MoC_?Sqg Z[5 s zVԉOrs doqNj6 vCh B?F0ũ@c { aL-F?@#0g\T}ׇܖ|3iCX+10XyI42=9%;I 3&])l(+]-+?f93fMnRA6"ԓ)lx]彄&JPUe9Q.6sb#>^RѠe!f, .6]TFw"G8{Iv.Cp7-UZ! ~ʶͲ~MWוQ9NGKx}fӗ#~ 6upf >o BP~#.Y_|%~BȰ (W//"̊MEPW[>]Czuzc=`1~hngq9sUpD!}OߖhJbCo,=1uyu.k`]_,Yo1/ߤyr@S~s0\%,gȢ>@03s:Z.a[e(S *ޣg_]y5!f^:ơm;^өB6fK* 0HN>6-CwxkH<0ݶ8[?Vq=#/:!V8iOmR6 ~Eķ[0Rz"`T BM8Zn;_נyR2q\4] AbnjGwdkU'/jƈ7ݺaרX<6 N|c$\&R &I`ruREo8u*|lG>摐C? hkcEZl/*$/Zt_! !݁oU~k^^NDUk@KQ𠘊y{[Sku"pdKi]E|$ t ƹ-&`,UQ!p{_y-6P#A:qAFg<4dMz RfL IIV?#iuJ뻛ɢM;}2U0֙B8m#1J~9J\DZk'Jhʼn+5C@#e!K$1j`5WCGsz*X*M >%,@\w@]X3^a?2 Ŏꑛ=&R\{L#>KV:UB-ª#A0.S8u'>~1I,חLwBn۪r J>~ikg]I? 1i5%F^M]NG߽nj_V6O# FؠpH~~-,81/&p\tڱy/GGr*g&fx5D8]yX"(s|ǁ^ݑN)ppGCկ=OSY(P8bM(s—ȸwEWqb3;Uo먯v(IU4cؚ7x~f:Td( jni@ggiBvѡ@<RB%ڃ{Fg&yZH+Js_|t"zyHk qln-):ҞZI.kigCeOq &^hn^xv6~ luf*~UXntn܀S67lLԷ4pf,+orSU1?+qybz( 0`pԱ5;}^} FÂ\|euNƉG|2ShJ5QZ`X4U譯2tlKo:1ᡥiu3֬x3ؗu_>xK%5{ HdIHiT/ 4nC0]U?/5BI\F2<)7LKsްD[bfvu Ћҡu;Z$}RS gњ94M|W-휋Ȑ@KXJ3fm }%&++5ƼS=ܞawDo{n%<}}V)K`F7Q4/]LSjlAL]J6)_"r[A|~ 4]^5EP-EnR==|#82rVѡ/кzWi}!eƬ[Mӆ]޷ %yeƕ ε\ǀz!X<u>+J܈w7 6RM.4w3i'žha[ayNڥ2!A%eRUl=>n%pnD+u 4yx*t`Bvn<©" <_1Ejf!30 n#LKP 1^_G '_G\d 6z,ˁA93"]"&x%oO- V!"Uw[IFD9 -`=+}@qz Il.Z=@bZ=Kr šxr&xRIiTL8{ueƬv^ tDi,_Pŵ;Y7x#/0 8: W`d_TY.W/n:Ҹ/ J%:ǣ -C7RƄwˠ05W,鴣$lMtPi@ soaX`!6v/a2Ӟ-j{-],M~Q ~Ql82dړD;oT/P4 r? /"L.>M EUo ڴzmg Ocݛ% +G(qsc7٥۬}*V<KBjMJr'T:K&c˘CW{z mV èC A7eqŚ lPrC-w+wxJ ɝHL:X]YO뻺S bH:LݴS1*~0Ӯ~E)c) T':(ꎓc6cdz, -c[ NZ]/-JA- X(=fi5ئOșo-)QwtWPG K.kz˧[+l^J~$36ZäBC(s@}AY( n.Xg0eՀ~9@G/kyRRȎپSz>nQz-"(GN~'(K2MUp@|@]ⷍ =Liyڧ^ ?hžVCmLML:iWe}x0ZfS~$~3@&D^8 0nzP{0ie2!]dLCO7hR_ ^O SPQsL =Zg[0[OSt5Mf g?Bў{) *@M&RDG. Eɕ$ y,ˬ6ςC)8y~H=}`8@%=5@idb p!n$ )Ac%P!BVY,ZC~ܻn2ۑt5w'QW̲zzݳׁ35{ȹ4c2CHVjEC\KW>5sTe%]c4f;Uw4K~'qe$OA3$(ۈjRNM#%2}G;DCBj1n>Z#Ă6nԹMw>ؠ;+'q似 L6 62CeoBigA+bDs6pm1QxFonűαdyzCؖ @~ěJl <̨l%pYPyp<#Ɇ.LBdrjv\ s=qb! <6m1xTMneI`ȿoW)|@ vµ;Eq [#SX3 4Jtů#vG-:?K v:WiO?~`Now )Qm>߼@ŹT:'EQcBkiՎʴ>XOԦLg#r>;~tZx= >VĐ7Wdmor_yv(}QXaO/=}j{-ճ嘢j! wVr_^kc3ɋh(/W2j#0tGw 3@'ډp<yR:2XX|oHZӋ]|yH׏G1Y\,?J q<*3# ӂne e׊}i1l[Ul)/|uMvn1 &QygShc m"< "=!|ú/t|Ia&1>@,o秋E)^А7}kˀ#!Ǘ1Һ1oCkTةS1$_Ē70ܩtI6@V3{UQmo\%bu y[@_V>H֧"Ï@|2ETPV7izɧzhqBX߻=0evPDԺؑCxygu5{ר0+YR*\ Fclvnt<#.]dB//HO ^֣)t6/{.nz^~ZOO|sTC"R@}k4[51 ֗H}>n.D~wL+}aw\ϭQ;b8eoeld3 afA[}O.+덕RRK?lbߒC߃PcH@b Vj hfG24wPŸ9c+YxP#5y/8Y-ip+syooʨM2VvY0*䑪Mcy啸߃]߻;" dǃno4[>b$\BD(/F {~ B)Ց6vZ ͅry^*V}m-G%W,JvaSHۭX_Ϟ( -V٥ %꒤X ETk Ȱ f)`/2ͪePDj*zCRhg 5Vo=n@£)Pt܂j ur1KYZAE:*-tLozqȊjmsee6h.w"\G$o&k(FF ;ՊpQ^ɳ32;bkUIy+9ną \EC>\y~7~k&*҄ I$C•u=FoSY!8 k*+4<U{2MdɃv_=4N_9UCly]%c> d rJZ{{Q#`o_$tt)ջfd%Y ą Ԓ$['BY>m M# \P6D$'q<EO<.ӗe73G&YWtڴ71ւs3]嗥[54mXs SOUY0rA*D:K%0i h|>ekaE6jo *MQi ',}6"-2,ugB1 uWo"GB@kFF!!:NaD5rϤ}$Ł*tqxFshɎŽﻮjQW/vK׈pfc-* ӟ`\.DhSSzcfϡEziT\kKn#޾T(Wv'u(ET 0;ޝO=ѿC:d. 8[ 3 K,w i[)F́b᫾lEs83))"(`#!  ds:#1&FN˗R곜MQ1T"v|n@3QP +M_\p3/&CGq+%~(l1Ko2ē$3cr*C.t-{ taoy)`nmZim 45`"R~ h,CC-jf$d>X+'ٹx]RAd9+=[RdM M,sM7/m4N!q[(~! L~e$&tTX#nY0Hbuf4t`B)}Q*4c.tmtL.DHVKZSb!ӨL457⑕\e",RLȆZ~#BHM#M.AGb2⚪W~R(",[K P NkUOB?Mɟ&V姁*5WfUd9tuKRy@VH',aףйp8 L޹3H-6lTR݇0Z6?vCK)d4~i] }B6o<<%uj%"AfI6i66A\]>ݭE.h O:=]h p1c#п >84IL(?c_pOVYE$NJp<}Ì ysj\Pf|4kQ9VmdRZeyY  ÄVjMa]=ƄPz"?`<yg)rCܾ Hrc8#WWXF@b≨^/}1&˼`૔+ ԸJt;Y$squ'I4[KPYG||^.!64qy)~ S@V= cyK7B:Lh} |-%+yJCo`tQ,nAQB|y(AMfobҧT27zdKN1bEb_p肘ү4ͷB%.e %H5'TQ<[Xv6SNo~ ۜg!#䒬fb' }/U ׹6`*3᪇6NX :_&>oq)ͦnDA5n] ٝ?mAmﵑKX#,OzOz##+72Ump7&xJ\p䦚z{5M||'”·{vs8DBYԊ?9=l,@dz 6zjj /|Y ^wL"G { MxH}sΔ} yBj~-%$ CPL>BO~ߊmug ]q|4c%bW4qѺU>ݝ7^X<$*.S@:4B^X~#M#ڿn#-DA4yʶ'ڹ`,tw8jI:Z) W=y !ago@7s ~y?u)h ."x,m 4х*SZvry+8 GygKfTZ2i'5xͨ@[76snŦk|*:G&݃eܰ8I5B{;e2+$ҽ [*A|g;łj܀.&xeuD87YbTmIjULVvܔe=@WƇJJ.4ZƉ`@QCC_5dAS¯b+ݺ-'jLto2'0eOȀMs+KxL"hp٠(959W_BFf#Ŗ1[O?ѭ7մY=]xd[]/h׫^Uvxg]-Gf`BW?"ǤNSTbGS1l~o<³` ت[)̙FνC~+L+9 \:!-m"ސpy}a1tJqR94)M,h17=~_9PTL+8]-VRQrsGW% :"ġK0ѭ`I8Nu̎@Y7emʹFZ$ D8:WKBGrJ 5D gq-k`*\Cj^oEii08S9q6HgdȒ#Iqkַf?+ A &'XK1!Yΰ-S]LޠxUU?z9g!:b{1y?2 55`Yݑӯ@{җS8Ȫq=_p}BZ*_L=!aqi-ʅ1I5&.( oqLZ#,5_HI[yv-NAX;>.6_(*y3mT6a2{vI[}uf7gZT^d\]kO4꼾jSy4="Y,+Lp!}dC06{W6[!tOƪҾY*} g.0",8|-X^_~5陳Ӈ k-,5D` /J+4Q$bחuqto,yb,-n#ju yQ`2 P pZ&'^f ,Y4QSN-"@JDew3M pT 93ZcO.؉z yjw7(@%n3x`u`(KQL_(1ogoO3t0 W(w^M+RşJg ܡA c @Z/rz7Q^yw 3eϴA`өfǓCmcNE&gLK9crߴ ( 1h;ܣ}I{f'A}O0_=qR?G=I#Yr#:{j fm .1vyy[rR2)L)ӑHXJB٫^"yf6>$ UOrRYP0X +ٔsk\'c6`10&( B y,to?ӋGd3}1z5+ByЦWx9cO0ض#yvϟ`;1]Lj^vQ CLpH"'•8va][nyy(\ȊyaRqL,M;5=$ cFQ瓿p Cc1f2 #VR-Qf$:j›[ aatTpWqx:E:-FV2Ps#qf7Xp:ϰ$.9Ŀ߸L%7~fMjg$GJU9n:O ;$:jz# MN$hrrJz58%cVi`TQp51dDl݊h5ߐ|GPU} tzB&=ޤx*`S'߲kB:ڻ IwqNYTq0o]_>&I Hx}\ /Jk֜;¤`)_v݆`A1BEp, %N`{@xc xJL9VeDM[E;.;qO/o,E`oBks83PĜ prňa8}mgT!&Oj\>8k^`BHĒ[BprriQG^mfI/=}Uc7D!^Ŭ|>P#H\O]L0$W'̼U}fϻI`% ;~?<=|4\F`(lGO0ݗ^]69 lFI|ao׫Uƭ8%tVaj>PoKdPլt{+YJ2X"K#|yp_9HNt:WFB{ATzR_2!&zYz *DKpJ#*Ok9E+/qb,Aʵ Pc*R.yV'~5atJsny-6Ђ/>YOBfj3PZHLA<8&֐>d``ͳh'802%Ca%Qr 9<44 ({y{qgI҉=8Km^U] Iry[#Whnhn5nͶNMѪ̰TՌWpvs생KL{q%+ 4Kk!ZA G m/|`Uɲ[d6 aoPpW2`$`)4KrEԡ D-қ$sDK;_dz\FzpF *\G~8$M5{^})cd{ s+Ef/W7r@ ]зcګe^\q˞m4eK]D[O0p%E7e,:. XlR>yoiZܛ%].Sںsd'*4"U4Il1$Řy UfHjIv Q4 +7Q[L,"I'GW\}BuSs]IioKv(6qNŵ7`>/-t׬6 iUAeqp[-]K!S+ՄKMW7Tpw6|6A Ŋ_XhqW]*W9?C^и *JQ 2Mںyt~b!?AcG a/sv k7^}דšQ‰rgJk>W,Q5m.s H'J5KqImK+4ʎf5E7)m1|^aVZb)9 D"1W~?o:\;Ǿc4( 'a!LULp$Sv$Tʼ%)4'RO^`f:^ݽ)D5߳гץn̈~qzÿzlꕟ^Wukj1g&2hKn\ 䖣h}_zrby5w_WuqEYyP$"A _aqܧDt Ӱ)Xy`nGE':ga݊ oWpR9Ɲ_gjUL}5'K}kNx9<&rLdDi@斌e#0=%!嶪-&^EALg'˄w սM6Qʒ^aYr!bh>=U9ByV,)^-j=sަ%NCN5V"'t|ofg惧jS봳Ѵ߇ BA\yv"4]v6;o~/jJM]ʏsR-)7Hgy0cQ7fV -ih%ӿCH1:<0'WY,jNN,GF%;ܗu[ٜP (i(ND di@^܂8AC>򳁡&w(WNERg̬^5qd~5mSsxDEAFNSzJL={f#v>umN@k J>5&W U9>/wk#cXP,(z=Xe! ,MCQc0Js6Imigkyލr" a bʀPT-g MʁwM+*}$buGHq =|a鷕W7歋'ټֹ7*WEaPl^貖!)tf$P-_@Y1N?3V7<u{5^W+y}ǢØm)Snj}LƑ àDCЇOp.\^-<$yjyh͸Q} #]،.v$9,<)<;V9?H!{> >ydim_U{WV4>2f}gVd0a# μ`Ғxx]?0 PȖM0qu߫j2䨇M?r-ӺcP|`rZ4\@$.]*Il+EJcw$gلブ[0X / YvjT3|?UC$;Oz}W#M;5?ܭ$m"U@ 3\K'@vd6 Ǫg|}#]}UGg!5hw+ZA*)@cL)[wEkLKTeiˠ>AThMv?>* t0Z UCKî>bZmw Z[A{GaT܍:lN8dgg&/ z7L\kyt:J9I$f7g Dfc_3y8;%yL1{v.D1P } {g4(}QƚꦱMld]'VvZguxȢq|>} ff`u3ANEaYK25P NU?ef$U#Q*[tz AQɜ>t@"P@_1Zi7.W;Mycwv l}qj κ9D\,%4 EyFFi-7xsy֘4Ф, )!sZGi4/!crB@rJيm]?r\t ?r6 gAi{#6 |7 o)h"f/à<;}dm0l!]ӂ3EGχnX_Sst4޻=PXG8Db~uSD,9ΣSemh1WSi4>_x3Ϥ +u2=F#5 h c[NZ7U1)26Qa5b/# ,}'M=&:a*R]z UA-d8:`³ɡ/78tmc!-"6/#ځi;!&:7a:k-)U.t\T!G̨W޲G_\i#2b "`V4 9hz> Uh^#hY}yCw+Fo8qD[ye؃/% `lUfRWf缺eA)0RSK7}0E =/h.CFXgu 'ϳo}Ѣ k\2}ec:\:d/?s9 <19єf_6SXnTрV)X@ov3"!ǒo< u?W!vd$};mGP v}C 9cGԪ-y߯gמ)ay%!`-㝞aѓ #Iu ^ueOSc}䜔a:g] \sn>58M\7cihǍ8\0o.6sLXDerQPК 0{M8[nkKڤ}CZ%Y&/@ؙРٵ?sPthK3RGJ"q w~3x:[[?$Yma]`/ǫ1q]\V0D`x U_{әya3fjJA2##eH忆>ZW jO>y (4}Z)MsN{#ǩTˆ,Ap;?ö,!xwDܚp^P __R]{qw$gl^/i: d&"FK5,qr`\COf=%313v_)@v}`Ȫo'C D35ey4Y7sor@,%틾I t+fí.fOP;W'Y|OĮc2`Q2f+pvLLq^;*x"=Ve]آOc"lP%O[6 ܉36+boܞF!/% 54 l>\4,Rˍ9xfdPfsw= HL2 Nd.Jq " PeFDQ^.&pGmvZy;rcfS`~%N}Х,Ż^mQdH Wlw5hmGDi5&Ur&C'kcħ K!K5?N0/C")#wy?/Ԡd#6op+nla/8DYN!$:/qX_F-[Gڱk-˥"lv,˼@(+.6 \m&[MB߸c *ӛwM$ 4J/8W KZ_F +L׍KlVmKJG/JƟ7=crU$J=!A02 hp6W $V8s5gRHi~j >?w6?*|6̇$ ,OWog`a[ Ɣ;+cn=sƅby7_ʀS/"1^SA/>!)WS\i똝 ԵR='iu`װrC p":-ZlF r)<%d p_;HXtqH1nbk-xe%W'%ﻻ`p^R? wk?oq\paZ If@ 킹H^""`۞SH7Mdu'0uH1%SM:}QCo5ۨ$^hLXʿIwq7t6%@T{pU1?I/{n0n'~ h8 e¸ʨ]V}ۭ _+OYA}Gb?͏"A/Ó4\*T! 87ITPlᥰ]h9oC}' ư]ڰځNBH䦴&Y_ޔunQPhH)Ip9XX+zn B{1#5h e=~ũTDŰGGuу$+(ҤƅFdTJU%‰kRa@_֎"62kE}`cn\tF~A{`tKB;>ne*]v♕&1BE=% 5Laom^i\{$2p"2]#^QP%"Aۉ>kh0k(E+ 뺄7ޖ3g8E jZVtz㉊:lQ<|⍣%l Lr쯥ԑepcY[b) ج ~l'f@ "|_wXIi1@,ՄQ<('(d8\u^>])8-9eŒ dcB]i/~>n 0'0%JnJH .nŋ2DI^2 ^<C%O]`qhFf[[iqhqlЛHTjzQ8!S81I6`75/(c]MUz+ aB]Ùb, h1\S&}j̙^PױOO+gm K| HGì/I{鐅{ާ|3&Cj`qubG+"\r=5]8/=\TS@J`U.KۋYUkt0)c8XͩJ9iqK Z}e,88/nCe8i>MuK:%5 _ Z,--.S!4dP)?z9]3[=U.o,"ѕhR 87=/P-"B*qx?{I!\Q `#H޾fR:n<}!f̛8 z_@`FP !H,rS~ʭ8JFER1(k@>`A?/֥x2FT95j. DFIźc/F*C{"(ȪY7L}8Tb|bo𐳤zTp_rxqt]E_lEܵ} Z[] b~Ta<{Igv}LKsWֺSڹn&4@G ?ܔQĆ;z[Έ8EZ;co+53R<HK'p4`kO+ڑҿoxqq+N]LY\) 7fz\HMrzXD TۘR5l \Ո 26 w$o-'_V=BtMbB)w!%mF\<@n0[V0]y}HoIs9%qsߕI F$ gD8)V&%^x2An7cbfNt7 RlpTr;[4i:dkT2dPR-)rE@ق]AbU%,jPP ݞmT;:~F5'Qih*%C @I}/ij,Fx]dR֊6];Ք 8Li:so֝ VP&=k=3aDvuXAWS^AWkdE{ؓ8Z\\X,&7T " :D8~XV}*¿W؞ @ wGJ>A RmT:bOߤumR AÆN3m(+OŸK%5g3V+nĹ)>|$ap7 O@-oY2Ӊuگslu,=oԆQ}hQUM0=bw )S"ۧF(iQ+aEN5A ?dސ찤! It\c .@Dz%$M01m49SWF][/̴_.;Wz'pT!J.FAEG= M#K7h'UAUӜ-E4n/?OS`iqiZOd$%滲aye;T^Fึ0XN:U2L%cIBEjf)&;XRdsܵp'b!J|~f9e`P3uɉVfhwz>޼\Zq[#SEGrw (sk5h<?[]X}:;_YfVcNZE` KGI%X n3- TJ*ދt y}vMQ9Gi&N ګUldD&g~Ν_ԙ[G툄%]-]yT̓"q GCމŹݕyO0#`ޗqc_C4_l1?yD==﫡UNpau][L#@k6qJeP kn:5E~ҹtվ?5OUv qrAHy]ٷ[p){yB5ohRGvFk+2 >Hf}9.$X KM4>XH~X.t)@rլʹnX+w<`n9I_DQ;QʡH.~G?ڜj;xKw$>!8)/ا tScmF;xTKEIk= |aQA4}E拒Tà!b?6=9<̿I_ m>+X  TI,os[L3K6JCE.|VW+*B6BWҾYlm,q4L FU)Ĉ #3ӌȄ;x5oDGo.Q I,ޗ-'*t#66j-o [G|~|6CIXu@ЏY}q.wJRDnqU0kQG½Go^'djW6P2C@ptE>3B:|)y9:v<^fϼQ|Ϟ>pHđ5yNh , nwu8r[XF5 xdIB?nbD}4Ki) &I>GT#Z 6&çͯݰO)~C!"zÍ̃SD'|gH=[ZGe"y98eKx.Iaسu4+݅tU+3{ 'dJ6дNiCz1H7cPK$؎0+Y-Onq Q>Kz3Qݱ;ߏR0As!~쌆 J%:<]#K6(U\ˮB5 M///kƵ  xuz-bh;5JSKx^E_ݧosSst: _kK7Ve;2J <: M+0/wߒIOdTA[#C2Pd~ax"#bԎc!fN!YNsukBgP *] r5UuCH_c h7scs|LٴhZYV<7z t7Wv6 :vIuS_K?"IyR{5.Õ7R上Au9 Fչs-8t™7 %J=+ ӼHBzg?}ZXnZi+E < A1ME fy06V)jg*vq:3:\cr)Q7>*?kY!XZAz8@慄Q'̾$OUe?5Jcgy]cŠͩ :8O׷;T YbUjAh1 pMЍy2W1.rSX)ӹz&qHKTnc@M/L\ޑyY1*_3"sȭz%?3C*mx-SLj&pzzⅣ%3a/PAclJ̴M>:&Vd.Mh9%<7߯<Mp*D,B-Ckby6y|N*t'$3ؐ:=xRyuB |RVF@;(_( X3Bhx)|;a&7׎!&`.( iz%|/;/N֙.G3IW)4E~J+†6p_!m )!h<`改h[ 2oޘ$^,(xo}R6 #"5b'ʺ/-jt#bC3;pl smGi0Q=xA*Q(ؘ"\7MQ{VZ]9xpDiRqxgh |+_>9 }Gj d']΀Rp}'n0ki@[LpN&?!f^#^Snkks"P;SAZʫUs@!bXnA`o ,Ly{}5980'c+qwI5&⒛jŊH,=(+R}8qL„59߬pK׏m#=miL FBXG4Z(y V!A4ȽRueI\NAcu)?_g^٦ulWHj~02Nax2}˶V훨P?3Y_: .ZP4P,hpNҹ 黒IRgg{>B_BN1II[6W, &)jё*U* %/tU'!$SrFU[yFpRK gfdq1hOp8 ׳wYk¶fՋD%Ԛ%ˇ˖ F205$Yv3k5֡CCZ,L.d/ޏUu82fFfi'eAN, &1cmB`aNRUڳIxqD/bBύvQwĄ[ t.&Bև7xwdN Ȫ\A<:\(kGf%4Z?p *}ok.\Njiu^+<0d6ypN b3⌾fQ*JrV0rR.2o`wU46sw)dZN0JA2zAnpq=$_0/O QA{fEG}^NslʹJu=?L#?lC,Ɛf@U&-KG <^WHoTTН055Gb3[{LOqlЃz Jkucφ o@dBʹ@:W9$yneX?Gtbx}b *ov6{#T13xe|?e* jb!֛͘!_9%6vdoͳG d Z-){rU}TPmA$陰nuÿ^bÓ*ʣC `_zjll7uKSU =SՆ {o?UYP5zdžn<uXcܾ~~M r\5kO+K@X3ches |Ŀ? hi+HkMYadq2)2wOW,c,{ @BxCLJ4[B$.hR@BB\,j]er߶tA5a*,}o NpC_un .TMUaT3VWus?ELWuHA Z76VǸ,mܾ_c9pY]g[ϵ+6DnyX&P_]a5u}%) ?al+AL؎,vzQr CQ8I^/yZ lRԂ%] l!.$fm[`<">on m%! d=B>lLh5>eJ0uY%hglDfIlEQQ :LȾ˴džm.Xq?8XZ<. ;cdԫ,`܉ե?x%]puMB}ڴ]jՀ i;T`RiIc%pFEe38AJ9bf)_SRmA$8P^u#dVmEGRבnq. 0( fF_ J s ??EwYV? F֢ciB2XE\]KQPϵG1;Ȏ ?q].2|d⤬ϥHv>cpX`oN]Dj1!P}Q8 %&x $hiZJ"mwQHR=+>mB=$ޫ!U/8l0F-Yx}݋ ;FSmrM]p mE6#QL1TMd g/?^fjq0\f D+.^1zG:+)`#JPw f}E Z~t ɖH(5(X i~ [pMZvrN߂6L{2Ƽ͈G<¬阠A8fvxUFN'0jEX*|ŠO̔y9,^g}pR)@N~Fgug$YAWJH4ĹZ=?:>)1G|Tw.j4,8AG;H7p#5OЪ'0iyw"xmɔ4J bkƂv%b8˝ c;sS/R %Wџ ^RgW wCA2SU`EiX"_Rx4LXnĭq@hdIbՖ-_ k|{;WpnѣQozA#dL9f++]|4 uIY]=/W|iV~.My̛ˣܗuբc~ OZjIJM\>a(s[D=@YУhDA좿٤o[TG+&pC(|CsW0L]>'Wnj% |sg6ۧLRuUj v?pvPX%_8OՋm]er$Lq:ոk$Po*vManETuHJ3PTضڇ\OTD?d!hF~'-O>$l4a7 ŪXt?Ɉ5M8Y5E]ɲ}SV>p#Kє] ÔRʊTB%(D*QMq+$咣T3mA,epv8کblFg@mm2i>RiHQ)YhT?gzP{%Q r+*xp_eƣvGw0a+iQ7HC%Y2= AFXZuAi]p: xYom@U'(Q![l0u J]ûT^C[,[塄2A9yAۚFA>ȱsW0wan"􎱑O%D#Vx^之xt37rc+ce\ObtY6l Ql" w{dF.᥮D\B?5ߟn}zԠQ 29f΍ݐ+p,[كYަɲR{j3Tq^J!$vKzkD,y PO]{N0H8ŷ t>k} sm%]s'`)w`19T`[_B[|]!߄V04yh^Չr,RmJ޳A׉0h<.>,Xc>:7p7U(ޥ6Y"* f_tOIhI7j>r=KFt(6F޴b$ .D2,_aG5 nzӛѥDsQrPw+-dGW \SMN~.}jC+kBAVe\r.Ҷ . ; 1s?cYIߊWvG0<0B TŌVfIbPnq[V`x9)+<@ʯu.:b[:7s<訐_- !q:"bKP4_nHev>&^G8iݾF0Sǎ*7DJn@_8`L1wpJ>5J-iZ!^olD- {wITKE(>U% cUה2ayaq~$iUc&׺X{0+FuJwR":ZJ㌧?4WlCNI-!9(o1! ֞7a]G۰:E0XFL'(Y]+lË㗼=C;E3?X:X@ t9l6qO,{\&۷n._3@QIiJ9bOipaFp=;D9Ljmd7\d3/#f(%Nch:w'gYdZM|&`]n(JcٗP]I`TfVbќ %a~fZfO>8JA^ 2Khw4O0`ӝ+&  9sOγ;QJur+owSI _¨ecH4EKЭG #OR4ɗ?ԹL_I-2 Lqa w"HlN ?=Q$* >~3v/(Os29ƌB;"N{c[,q 'C h[5EuiEGl)1l1wc~'jpNs :{P\KFqh  ||I O6uGo̦~!mV_sIbxU'UO1YS8JM%?|aM-S7?­4iJ 7aZؤ7}vp̽ӓgmTF'˺[pFTjXaS()^bCDYYmF ޯx|eWI/j1&x$Ë?ztXV'f?1-#uQ ȶ9:V !hįl/`sj}$ F(Ę1$Qe`ʎH E Ikٺ *ov:|%\ԺKV =Am9zmf` *$I>_h#>p 3o;U=oHa| FpG'YT-?~,0vȂ@kmi6iƟayX|TzT%!RqB!`t8w,vWzKWFףsUHRD19k_MДgga&.u!Spl 9khDF:,R;?߻(lꪳߑd)NW)`wZYE-{AO$1 T zfpћO y}*q >)#xJ=gQT^ #S`"wX^P0?KB?M`؀)LFO{,uvK yʐ+5z2Hh\9vkU;T}~TEЫ$ebxYR\G?UK'[ Ӏ(2- ,(%ee2cWZOȷ ZL_Πӽ#Z<<$T(>oaQUؑ\6~&W4Rf7'}H|["bB<93?~mN_1{87z K+l9~¶{c?Qlu4 MR~&wh8L;5Y+:SrB`ߛ!!!TbՁ>* @4Ń -̪et0ch٦P(jؑ,'oov>nw1ۗB?.BNPr}JPa DXw 2H#&_M\Cr)oN\z` 3#zTdrWG9Vv:2Z<=aQ!UwxoӀ?`R31ѡ"L7ܗ|vN0 %WT'k,N,,%ǐ$OR_#Vdž6ߵ9QA+k9ڔ&R{K9867Y=yio2ŌoEPt=³$*Λ*P>O|(ޡ^.n5Dڈ[)r}PTd6% IJ%mu+`>nٲtuuwo7aF/$n'Q4a,P97="U:<(g~(_=pW`lZsTLP! 0;dIl\,R#,^&x>3ޗ}HE͈8`Z}D|xt{~iDaw.yg. \H^KGNJM5ߦp NI$ XR|qԅl6iOWh6H~al dr!/F\bm8ZX66Ja(>fBߎ)tB$vZ`,]. b߭/cN]+>0MRަtz:,%>tW-.Z_aI6O[qm? ¦=j *,j/~)e_4YAB+Rx) bjtv|AO+#FWUƳuצov(Y^+2 de5` (-X:*4 XD$OG$<0L)D/hdr|{I"kPe8Vh} 32>=YO'>j9o: _<LXK9VIz/ظ@AB+f= G'0=Q6J1,t!3 3!NA6e_d:EI+naY> ,`SZd+NH}% e]䏅av=N-𘏐INDG(#뗗Ԭ5Kjc qf'6q=u-x&t$F"YՓF۴gKxgфqX$˕0!|3"jSp}!u!-[ipwn!QDB("]l^ $Mx ;^v * Y^mؿ!dWMEry$jO,rry},1_P+ ig[?8bK,G%Id<(x0dKW_,*i ?c 4ՃLj z-#59O /˩fٷ2p L7y3C*s{e8;ai<,E3W.d !?fk;εft7엷DUc(: ǿZ򎱀6um3IP~q;Og?4\~{7)_5|ꆱtY_9wk4'9^M Cff"g9];2C9GE+<ɴO=D$t( 7NP.)ҡ(ی|#q7٧Mb+FSoݘyװ$(!iG Ip`aλ]0#S+~$knP6Ư6͠_OR9eox8Yu,K [$VżPYexZ=OR2r>~/}vⱞ`>~hR>3gͦꤋ 삱L.rd.`g3dS[;XPݦG k-k6'Qc@WX({N2["(0삨EWVp)wQ X_]hz*ז[{dQDs5 aTCOhu)e-6C}U ;qM ~^E%w%NU}xY^cg80m6[}s}i4z~|IȲKzGn7H}2"Β +f>=RG ɘ(~'A*[*7tm\MKPN P03Xn[9Yfiï͎y9eLyŌC^A^RN)%'|AHWp`4oCNfzo%zG17|FŞ0;Htf\бdR7%; ce2fB\y 5Su9qje(cџE Lpee `{c}ki2I';{DL>ӞSh̎= |WK* )|;V;H}vҞGC1Wg$8.;MԴ4rkQ[3\OH t?gu:\btcO)h({J  ҆1G׮I3 ]DӠ$=(h.D">%dU{ֽB9O5~#i&PG?$u,= P 9Tt0aX)~~Ս/:_4 ϬK*QsF?3*^rKoɋ]-erR-]xWO,J`x*ENGß2,y񂻻*:LagK5%>*hĪ}1RM"m{G+[Z6F!G>D]fW7LVNg~h%S[&Οui6mj8 ڭ'KZEqM942WЧlE@2 msZ ^`DyKaɊSjaD6^kLG!)%7#\o"{8/Ejwv\'JUS፤;n% ҄_Zf u ENBw߰fjT&/RcR%lcšÝ?MQJa7(<RG7/cG `m,e3la3x:;T1&DD88u`luir^vco.ּN["UGc>Á׋Aiwk56 FόʣPƗ&^[ PLQ."p`zb3O?x<3!|mB_py|퓌~jj[ t0>fƽ)Za0}œm:W :b;h#54^}PWOt8Z}}5@oIurgpث$K|;0 ̰yeAWER7E$%lO`U,O 1i_hzone69=k!&G7ݏyrLrwMixg݀L-|Xh4Cq1b+nI _ t a0nVs8yTX)N`7*pvuŠp1hqcx"/U" {M/Y!B^&wq K{=2i"4Wx%'k ~ 1.GT{+*H+,"Xf 4gl}"6 ,T'Jwߙf20܈Ѩ`˩ܳ>exƤW)ɾ0G }mQ@@=ГO;0 A|{߳& ʲ -,DARćDo f7?s3r7ih:> ,saCw+ۼ~Pж@>Pձd mƐ5G-!ȵY:~n!ߍ*VBX N,n?Ev9e9ȇxr)?Gm% ԢS/7-.P'g6sֵ\;EG|R4GXz\:Z>ҁNn|?:C}+E|VXuzwڎ76^g`SGv:=nI͉\ Qm/ViG?3Fe!)?L㷎D5Xz~jd`D/Ɛsh϶;CV+ ʀ uoG@;1H"fz ~Xū^h I8sJq^U 9f !\Ĝw|1~g/?yJCG&v{WHgIRa)l]!VCuO9(oMGZ7}vXo2o62(ir_Ox4 I]4協hnݱ'n eP7n.- 40PmF \*Kǭo1(? ]%=.Xܨ=gWiPf46(=>]t˿eD_*$F(hhdb b'd`0#rf!v29s$+N+0T H}fUs<0.b1uX= r!MiYF~19W?9.]͜irfk+KR7FF wû4೎ sIz.Dt𝉢ɹWjBP8fe:Id:Ԍ]R s> _c10𢡄7j}ͼdxw3@tW[0d(OAS{(6h+ơI@)(-44/*>⭶S"?)i}XEK ۝Hۭl J%[}^[4}Lql"|EKa >2l!μV6L)ӢcZ hTrB:!9}fS̀tnP(^_l78o\+tC^NJC5T IZ5rG{Ba> pt#‚6aIF j3xN_l7)1ԄJUo9G_;n8sBǡA;D␇,s }٬ 3OE/v+g;V#9FGjfZ`)HL^̈́n [n n,(tw u醒s}e$,H,sxS}U#Sz:r] vUp5,9VyΣq4q%}AEIn7΋^5]6ЗcgP[A0ޣHAQ)xy N&3<%(p3a=Ry $(F5ojn$Q`O]Cȟ+jfʴCf,bMj耈pɪUZ֋d&$F%[VnouoJmɞ4Y wF=&9Ё;]$%>o(N tU6}\Ix7:8t"&xLӾQ1^vP(n>/P9~,;urj@eܡf NJGW8YYl#΢zzmw~Z^A "n32e׊ɌIQ _9b(M DpI{QI~T?aYr<Mc|ޒ8\Ja79/ŞԹ<@Yow(=wMpަQܬ/Ż@̜oFFx6KDHX5Grf@Xܹ>cy}嵝Ex`ʃɄ|k{cY1%7U* Y':y9 7kld!HHV99[Cz^b 2pXZǪ`@k-Y н;4"x8cV,VY(|IoM%q}NxPy7mݍj ]l5]zԃQB ņ@y,{ x'plS7,9k>V B=^H=d^®*R7*9Nt C>ᓟ'deF̌-\LRy8o&63)&$ӝ쳢Mn4wŠkkVo{ߏe\j7NQ0ڞ%`IJ27bv1ZVBŘWy[fy$.$}fP%ӵ:x+2˴Xfo2@v45fq\gfO8CB>-]K#|ʲT#xL\Z.C=wX'6ӻĎ tfz7+4f PL>W_[ HlКl9?C`h 5QWu_(DP$=Au%fI5.>Ҵ p>M ?@:x.2)u siB> J)uFu*_KFHz*.D w+:yPR#I@hEV hš^~9~1GKA]/;gXp7kmݼ•'h?-&2O,hd[7ߡ_w%fIN8$8ѺDOX6S+/6J |`tsXB + پ8A #u_샚rEm eGE61R+I CeiU10nLl-Җ'R?&ʹ|S,KjK0w?S:(# =QA?/b0HF3qGbLQ,[A; G_TFM&VX ނVg,Kg蔼U41a]gNYJV  >b*d^4+mԬ't/dSژW\ï=nZhtYKt-8ZE&]GnhƼO[lSsbUUThy= C4X}DIyӵ@ݚ='ƈ0MKF~B=+%F*/B\ g_&PWhZ`}i37Ca9]#h*:s[G< ŴAcg:%㋐hl(L#1NU|5P`!65̭׈Hw@Ğ$uUʘA9#Uo-$.go16z[ڃ)Q҄fScth"Ϙ/q3vw: l r!n}?<@Ael=!FX#!`j΢"Tٙ$g${?,Jbm,rO Z K3H"+8]X3#gug P'c>`}5v?Š6a4"iybn/6i˵ʙ|C|IkJ N Hh fHܴ9R'Sq%LD4s rk`k e)2#F" A! S1+wt2wWqf$p[~-mrB/^mkVfO=?"~q緓XQn׏N "x.XXwU x~*ӁԻ8 , bU׿yV',U0N}_VUЙ}$s_\K.܋X S\z"mVL)r @8ӥĆ#Xx"pV/te.6\<\rN[A14vd!3uzlBAʪC3G\vohY^?VÆo/fA] lv{\NQLyVT, up+j L`RKe^ œѕd!D\Mw&֍UIkSq9gV!;pw=pwt ڹPni w䀽8(;6*OQ{qϣAݳ%d}c((50-0:>oVA i7 Y}flgZB,]^;?uL$V\DY/"2]yn/)iLHX,:j x]g/Ʈy}-I;0NA-^İĉfV䮴VB%wevJ^ȑV1l8q!LύjXr ӹIj`YMǩ4v)!}3>\^ZT!aפU ;潇Qr}3ڌu\TQ7doRX rup,49SI (В_-N,!Oio_&4dz1ulǸ"pxiCۈֈ˞χ)#_"DW]qe` 8S ufxKxU߰Z JK,i6ߙ;D[ y>? C٩Nx 0pR:0"\ jLxLNw0L_'W}+Ʈ𹬸~].!=-Ϝ~!wE 9T~zZ*+`>~&mSܖeg5:~kA <8f&l⨥Ŭ%܉N\},},piVs[ Y;F^nÏ6ꌍeC>b0(U;LlDO@{n x5NBWʤ4jg.bUO6>HxIr#.X#!gOqON9s;5>$:3;М!կ 1u,D7+[ d4|wʍJqz[%>$ %+a{aS$uHҫ[HN-3-F GkQ4+ ^A[V^JNj&_/RbaYrc5 2jMҐ^{K!\3 b&s2.=}ƜF;UIbt Qu.f|:_~d]B?v]~}jmeXsfM,=WQޟ ȒL7LS}a3ns98)`>Ft3掐._\&w.,A*5N#uVՄy2 4p {( %kFrvm90)R^ã ̧ʩ`IY/Lc@,ksqVNu^# h ^ |PY7@gFΦVL wBtYޜ1'F5q)B+`;`"L.4upƅg{5^x|UQPBwe=R)3kkaJt ̃S.Ja KqKl@ # HzXCv(VO>{*~WyQKxr_G>sX>e_ꥃ[R|*".]\tB}MW$"C*f1{RB3zY4a\m_#_%B]ທLhEs ˬFF>G.#IQp]V"4j灾]+(j]Rp0FSЫш= !k~Hֽަk}*ߚ@ϧmU%h5◇S!H4C\mLdʉ 3YO`pZūd/q]%J LN@Jh֪g=KSj`$Ps"8$B-ˠU;pUVdžp^8P{䄚wkS਺:2%UL2:\p" mKo©]Kh31]5Xʑ7I:Et%ϪJOWv0'Fh (Q%Z4<@q&0Z> t&Tݪ9޼d𚌝YO ?OR$3r҇ ? F8J"=W7#V@fO8$3Yb3+;|*6F "sJz%GI\NG-K/!f/fϟU ǡ0Y2H|zG*#\GV*WIOu]E@1xCe/z^s;8 />.YRQGiW+RRkiIT$oɿlځ]RY<30ICE8nSv$8#M͹lu@;:`dÕ>^aĠFhsmT or{n4,Jq\% YJ:Y^{ L,oEؤl:@Ht+AoUB[.Z#cw%"w;vS75<]0Hyf6\)1G^irfi;?P3,~ꃶUK-W ƠWSSl|ċG41 ev_ڧG@$ E$1|8Gp'6P*w6:-QhÊ46٭ AH9T ܐ #(h#n9Ƹr0V7$W*@uwZUM?iYؑ=g0DN`DRb G{v_3#nEZxU)Gur׃){iT T'VWf$&ʦ]}+ vv5faF"382[5MZc5lPf.ڋTdM#K]4)of!a,=M[?.r5Lm~&*1o24c¹ĸ4)̜% okjv:#A\G-HC0tR:Z{I*5 Y~Hiϣ:3gTmGJ'<${ i4E¶^sO_􃢌Gio>9SpPGZFųiˎyTRs PuZ}Uިfx?s '4V>=[%Ref *ǫŏ%ؘxBXY$;7eG#̴I+l i(δDz5J3!L* S) "㒍b_xVSe jl-`qUFs9,vghwmCL992]b#Fg}݌AuGsfmG\4`2/!5F߇oeZhqjMۘYۖJeiPP[9-pnw&b6lX^I In3*pjtr7lRXPԌ.6ǐ6Д0{']5`V7NQpFGQ,?e? MFZr񱦅z!cJ3E@K13n0$@aYyҎ"͉1[PAO B"26V+ēI<[!=z0Nʒ ~E }R"14dt`C#8HU@u?|6C3*?~SG 4fvY4n<|DZbDao~^G2V68@:v%elV( {`/*<\7N k `,E!B`rN߾K!r>ʈbAY`Q"}ᣫO ĠEzP@w'".)nAίD1 ֎%>@v9`)'L,Rec BP]_RPEߡs-%D`u]FZwt b!v툙 <;bqk<|G`,j9 \[;䪩eMzTugp pFs' 0Mj>7` B~LT^gvfmFi^Oz~4Mi sU=Ѷ9.1Gwl&Dm~ |X򻣐Lq{򾕩~>\ ~.79w(9-Fk^1@7S"w 8pN,k{m):ߜB]'gK(tǣy(ځ|_)|dTiJ7H.L(aztUM~ #r1I/ ')Mgu|lCQ1CY>4eCkVOkJ ,>K0a˗BStK )n ^{ƨ\(,=!GZlpIyGz\phFAljP}z7Rhj\d&rwmD.?DEaE+}&)Щ| $^S.2b]:3/Ps1P{/vl7'?8z6qDhc0*s`,W%0i T=0.89"ͽ~f7ݰHJPe zѼ(hꀂF;yhI6֝?+I' f/&߬0 mKBbY:dӴx'_]r'Ȁ>ˏo&,uџ(u|1=.E:[IYKV5GLɷ7pjh#<ʫ2Z VHrbik%|mF^3 [g<},+r~ODBl<8 ԃsmy?0shR]Lmh(LYq""."hRf*+0s$چw 2]k.jxѦ ̩;&xM#(Z/PӼ+@F-?°nycqoΖ~ⰼ(GlO6oq}:hK&2˟ sK*2&ݻfdL~xǝ^$)0=>{ I6d~TB&GLTJs,.z3y'۱cȜ7o4h CO7X)f;;LN_۝"x<3V0T8_5kdP꿃 )+>TZq"9*{\U.r"Ŷ̊˓8_-ѽ߹%r΂t5Z(G0/dK2!m|qjjxˠD2zO{ ͚?߉\[Stnz&°%St1j/mDJTK27ym*(d-R|Bӹθy/EV)Mlm$Km"v yJ;-Z^KL53@U(?7 F`XaŮEl=|th3J7BhƵb-Q!򾛨 cw;*=fV oOn$z&eަyo 1Ez '@ ^%#7$/,MUD;^a|E^ULvāA+&|r.t+I(P_|hb UC>Vul%37GdgaIF}JP^7g/C 4fW+]g1\HBbƬ'łnƥXf:ŮQsBJb禌paA?3FWǩ`"Qwf'M K l;)&Kdm,R1.l sܼD- &ZVW\EVj%`BP*LCjH fzO긎)gݠX լOhiHۑ06<}"<]+YkD?"Y5C|vqewwn'1B 3N/iƵoh 9&FV6&\b<:$Nlem Δpt2!a :es-Z%` >2>r);g#{b,#R dn2 ոp3ӈh=M+Y+; }OdnL%78s9Q{ Y&g=&JkTF &ԇ #QioA|{>SWg%Qvd,v]Z1D0k4"&{n BOǵxgӦMa6y8]=m =eƴ_8Ċh!^"K9_ ]r\&l@4PGGZ ck6m؀A}{Wt{{d2M> W\@pd?e bgjTNZqF(.i%ZaBJ]<*0h9YHXɱ7lf Cm_?p%/A1ܘ:!r ͽtm{b@Y^*2Y:K5@l=x !U?V$!/Z 4,z{J{~8bGГ8}xp $f7q't)jQ\j"ع&×f]υ/ |8i9X؟g ʓYTi7|~dҏT ў8LقXAYal*2".@^ڴ& f?HlGUk*rsMSFxI<!rQq:ԤqV?FEkJ-=UdIIoN0II@"/`Ei$Ю+c#:#z/pqu3=х/ L񺛃8 xE6Md1Kpc%\EHEv Ua. 汧Y dA. ÅQT 3o3ovaN7}@6RmzkyJ;<͗IF4ץGM%g%<2",TA~8Fd0'cG* {2aD&F'G'C`#9P|q" Hnc`jЁٔDhSj?DKz-.EĩW'D:],r⋺<vJiY 71S{UF$`:H ]@/\ڛ0ڬ3ڨX{%K2A@[4մoS~]BOɭ4jNAWGz2`ZMΞ=k1Cw +å 9.X 5v<9B3wNYZW2 ZIg&O7@xe~O@db.oH7ܜvVpWʑRFo>VebWiOf&$6,WGϖ.v:,p1(q[,è+sdsTjK m5ʦ"d+:Ԕ|=@[j㯈 ʴR#?C""o([~xy+RHuT,oM&~ V4^  zT.O WNI#ga p?D>N\YkuYAuůlf]T$k? L2}>DZkVҏ!uQ#I7-3C%,rȆ+θ YùnAc.-f <+E[u\M q0$4.]L/Ps= CDx1 ɾ7CYmOK@@mPԏ:g"M:`V)-n`fp^g cyax~gćyD+aQu?c$6:IgZ6>!z'}cbe!YV9)t@VPUoו 2^F`Q|yS d ]t1=^{dx@ bzDZB%k$r~:ґ^tg\6+k dŌ, "w*UwsSnM̖yeGՕl /Vy"w;cBŸI&2eLAms xbє hם笕%RV  k 0>G/{f"@oLdgmW<,ZQ]W'1CTNk o빝:Oi3X˂USH,',Ḋ(xa>m qK (C$. +  BSuD}}OokX{8H\jg7mgWtr4*Njx lGPM'쫐+Â`u8N K'9DR-Gl W0D&saٌ3[i+O"xtsÃGpZKX{l)lr62I-@OA/f~te j]g T KKeS~|W$)Lpש&/ҳJz}ݿ< ү A$0ῐ_ E ޕ߽e&@]/1Bˑ5aj%<)Ƴ>ZG**W].2ù"Z3U xqUQЩQp 0 w lvFJFTb{npwLL>e1w+$ bL<]XSӈ p1E|fwd)BU^m .W [8##{йʊ`y=lຖ/־,ymUS*]=‰v1 v3@ i#F0mB׼OҌ!ɩgCS 踍DMU{m<)oi׍C&KT>>ΎUdAe7/;9 +"3`|[d!PÏ 2hU/LOC>5h i=w\LG^#մFB8|%\-GrJƽX_h2R2Q%* gŲ1 B>i4? uO,eF1@-fu7 yuv H,@')'j3TGT 'EP$r*SC0r~*I{KsFnԥZ,VD[=G &N5;yJ}EhxhEPמ&?gK BSJCFȗ$_3^-;nZGPԇ;##K_(</-om PYLͮEl'gLg?[顽>1Bh;T?󚸮>$l]=:gyk涕4&zxʿIPȚM8zmL ;'m֚2 X' ۇaz#ҷNTf 33iyKbS kft9^9#aj݀}R` V|h{ &"Ͻ5qJiveͧBOp7Nm9ɮv)kOH"5qIC??H/ 4#IQlĖ ŷ^Ob U$Lӭ+@r|ka7(ȈHl+Me\&,)SF7ڔI1&F'zh'L{FsH Įs3Mr_Շz"ӒXBQ "JW/ ,|9l͛!*XJf.qm1MS&'xAd3C[Z6dagqDG5ֺp>B3P޸[*8|}ypd&kBԯp+HrAA}šc1;̊hh26,e[˜ʄ,2/`{!XͧO 唇@]bP,*r?,}\r) ^B3v33b\Sa/aDZӴY,A#zcTDN^bZ Nvv"0jῊɀiڬmFCYBR‰$enۙ7'Ğ5]Be1 (q@}lme:FxYm ~vC4ƭ6/!)4ӯwDSKea]%˷6+ZS"HMNc02ee@5?.\Iwh3Jb_kY{0+揥+#z-*b} ki{7?8sI?zKR8b[!e~*vXB;"Jlhu@?*40"k>W.)SEs7 bL^p>E1oe޶^D6TdSUFNX=^ǘ9;i8܅6!;aN^?U qCRAVv?9FBjd#0- xrCY0ZѮ[\j'72E+:E{%?ڊ4߬|H0c"HbcR"ƆRB+!0fD j#( (ۊ5pµ[W5{Ģ%EŰٌ[62Fc^6Y'.JS6#+|͹ZRxݘU0Ӗ$Z RJcb+n8TmtMIfa>R۵bҤ Bi#cٕ$Ci솂/@G["9:K2Lca9[=2y+èVYM.០%LwP@eԿ]ú<(-3s'N/)JPC1CmuySSUMm"c.}LQ$JT(R/R:{ĺAE8UrC|Vig╻WGo {Ժ I`I'1}?`d 4b8ޖ(H a0K|\K,ŜyhIWƾ>6K:V20A[}FJY]V)fM|OIt[5΢WpMFWJs[y9*A3 PđEÊT1 -҈_HM?[)-(mI'.7T3>c?W]XWlJp!u9,A4YG($Y2(Y3ɖϟq,x~M67/MZ[QRhG mx? Tu V3MYٛcrY;9 } &Df*d/OzϞ8*hʮ5q \6hX4,hysN.Dz%j̑T'sR 3@GS;e; s5ijMpCBؠ܀4ݿm +25{t j{@ N'xzl?cS$>370:wA9j^O&|ԥ'vU\o$}[8'TWy 5@m=?&d(D@UO:$k6>n;3d5o%2L/SԂ#-b4>j[#:h$x@sK9Һ($` ew%kOBH15A|%!]\i6 S:.1.g:u$$G WMVuH ! G1ߘ̝"w@ZEib~Gy^ Zb@]1\| m'h:: &%)0?̀ImB~?K|ygbx/y_G9|ֿaTf^;O9T,t j`{U{O5Ծz>0],jnED<#;B b8[9pe87ě`"*!C=(ן9yp@Πj&wU:R_^?q6"mf 5Rұ76>̓`udɵDQdD7@| I{4?"~"few84 g\aw "v`Uy: m: BK zs^0wia`5Z9D+z* +TJ\J^Ƞuƿh ]W)(b/2‚fdЕV|&yONJXp ޴Yjmղ%Yܙ&]m8Y7.cH)R0IV~3Xڣ$fDIq"mXJFR]?SƬc2> &q)KVOaC#ݵ,V 3Qgh9sykIBvZgybG04ePT ċT =+mnBƯiFYj[=/eT>q?vȩCNVt>۰3#"x[iG&5,q/}Z`)x|U1ۧ3d'-f׊lJN6{I")Tn^apHV;e o+ -+Tq蚣<^4$I=J i%BlVx|1m6+!2 /9P3KB.nE8|T hLGA H q?{{4Vxу,|PS= E8xLg`@wjP j'u0ns:|X5(4Z=*D$ͻ;3R--~e#;D>E,V$ Q뺐5i=,6> )}̳Ha$D P858"ohd}z2s|Sv ]z8}`s~dzpOnJ 6!ˆsJ#ZhR2I`c =ġī&.^1`wwŏXoFlQp7ԟM$͒`ug@&e "<cSF̆%*.0sG7RsS&3F?buaX_zZ2%u1j |m0, Mǥ>{-EWG_űۇGꞾ1.IVvTWCt4W{@-1N;?77+NAV [O q#ޗTbtBk"|B}vyE RK?bwDd`I*bgcZme]DPsOu7_YIfyq 7G ºV]I0G~<3{v"akDTBJL*c_ S,3HKz x4n-R9H }[V##lFX%0! | ؔ-y-A25tXlt4͹e 9PBqzs߀`!!lvuo::9XL;dNƩUyj:zDx<Xu=/l+f<m缱D`ԓ֪ܤw'f6$M^Fh-4iqqr7;mCߥ{Mh~jt>_FPBĵzNiIP2?|"J|x*!Ih@ u {Ћ%3`eNct'9XF2ɵtPm?Hi>2'Ƨ_ktXAA}C1l#''mLrM~ #)c ?lּk3\81!Wp~_"P6 FV9>2UjB={?NI-]݉Ε!tƁYH+=$9L"ajrHqSҘ9J'1 F S.O7WΟ|q-.U5ua5"!nl;F/PL"dDov󒚽0t32)ҩۭs%FnWfT󟚽)ju<%a`Fhsny?oiDžQţť>5- \ 0g+62᷏E58ȁRWKb'ΓK\9F()\@ ֤F2A1ư $N/b8Vf! b NΨ;*8|%/Cb žP):l4$"?y&;5IÁnJnڅVkyj3,#8*/n/ -9mμE2A+3uKHƙp}Jge Dje# .Yܾ43树oX'D Q_bϔWKf~[iaYC h~P&d(oY-bʋQ9|Q&p0 deZO |s)P beq(4`&'nA:̕x{1;P{:P=m&~ʹy*0Br8Qupoq77(5w 8ߊ^L܋4 q4KcWoUMNAT>yT#f3|@<`nqłL'a9+tmR0)5Po106wf gl$ec+ZYeE9r(ea^^`_կ<ĄRo=+݋;4)ď٪pofK)i )LݘHBHC0%3 ADAԠx`Ύmw^BћJ a%(X{Bc`7 paOaNx [8'Jx$G`Zbՠ6ڻ'Nj $>\2Ut_!~L)<_/~93ſ*;""[(H 9i&mӑ~f]Nf ^O X(PyWU`^ucŷ}sV'BAj9I3 @ MNh7]n]Vjϱ;u]m')|zQnsTkިU@ H$tQBB=a.+ "3C-ى0Ҋr29@p rqSuvng:vTL)> kΘtg8o-0\4ۆPh!%D̹9>8>fUgf|0y24t8B.# ]4^[KBJ}{3{Q,1.e-E/w/oL=0F;R%;z2["R2՚1O ʱ|Gcu_W͵6f!On~lA޵&L筁Smc$iȅ3?X:W  Y) "P+FFۏ:߆"NL[VwXs 4$՛yّRgt5` n~mup9 OŪ/hb%ԓh=B}7x&hXq1t%"sL&RR(ƼrjmsLk8Bi7IY`<-N/H%6 (as{%s sb֍ Y{1&TmۍRw9B][B(utXFh}&~j/tW9zH%Ge'%g!jP kgv ֽZu?O*h۶*AD38{clã;k;Zޤ/@F7QYuu;Vaxm#`xzDy>_[gmCeLg'XKq>=G:BgUՓHWU8E}gvzPOY\g0'_[J50"3y%T-147+L<aR~KM"Vy] mm f6^įBP͖hmNI|=>$Mvl((h B0{Kn {N6nopxZ 5X.(@9(I~جPEI+T6]vVpmVZ%Շqd1myc a̷%zZS{kjFt#c*XS&I-,^&U_n7I9F%i@{';{*F[ :KÙoh3Kot_61f8ʮ<\`8j=k▆f%}וM"{PVceB'k)M>BkY <,lG\ XvK Pt&B₢2n_~CPo1rcN:y~TӴ[Cr3jBcB@LDy'NnMc my[aH\"/פC̘&z:AJF.@l[d>|[04QIL FbFV?-?!4s+_/Op j-~`GE :0q} "ui_Tzb{*򉣳bDŽp, ࠅ{C.:aS#P 'UW9>WXr.Ln83*@^L^t )` "S#3gIEyzzqXk Xb5>BqKu+@YX}m+ySw˅7tn ǶVF,VAtciYtedlkaeu8 KGaid(׭j>6 lb7D<||LϣcջQj=L>\]RM,@cIzQ֕(@4'RC} Hp/xY۷/lv`P*jG(~ee-FޏIѻ̅AX#٫2:gU}TR ƕL?/kŤ-m4XǑ5l ,;Df{j+tAMO&In >^OzA`M촼P{~k.c OGOx.j۳:;n1>a6 ,Wg&X҇XgsxBvh"&)"Vt {F=`%yʭCנA]B0*_U^!hQFŌ2GkIzc ťJk+xSGG36gwG@B0uYNKU;F2K'ay=P3y|埞!}N~jbGs[Y]&]PIݲC@[p҃Ոmiv{#1;4:5O{.h F67;8N߰:^M 27 )NuxeXCkWD\pSà4Qw,EnT6@M 5V1+/Gh-{;TUV!2ʒj9`m/o g> _^ EFV<&ҽF*KB!R''M[7iIߎo.FcoECNnjp|+< V ӒF|N8Ѩʍ}%n&( wo(W*|^C'E`/50U'( /1QQ8~>^t`Q ҡ jA"<+?B5DqcS YnAհ#+ch@׷fׯ (ۦ 8Z#lQ Zk\M1kPe\ (t2kS@fqnjF&_6:V#xȽY-zOxtU`9jS>vs"JcI$ gȊ8?9JI zibd$#^hg=˷r? su*E#vMטvk2nR5{_?'KUIamCZ:Ře>Ͽk%/ djc"e<=hl|JiXHLch{d Xyn.D:k>*fPI`Q$9)XbeѨ݄{UU^ڇ'3lCy4Mf$1Sijmx~\ 1MW JPt96R;-~}  ^08cնs\I3WƤI;e5К )Jn?+wbjMU k) A.[OPQ YGE0:|kj@>~ ߎGw:5:瑋z1nGi4\GR#%؜cֆ}T`L @7Us]YB xL[j 9s#0 j|2QOU6-m_`ɷӦ*h*Pl¡~+BͤbXzzd,})@NP8+.pHZp3s7(*؎E('í6HG* Jq">ʅzzͺB{ 5pWHB̂ʓ]C%ŊOHV_PG`SSSvw5'oug>6mrQnE S*>Z+/zRx$CAY]IҾA_:P-pvxa%2_Med'C \WSU5*V]B܏J C%<@7FͲ 7z83W*(&Uv<К-lp *?Ӕ&ˀ.gݱ\tVχXR M6%z ` 0y}^䨁r| =v 4I*ܴ7Fhzt?034\XdOl8+Y;Fz"(+|W%\4c֭l(&rjlpѥ4˨#!F18*%kc ŧ͊ LVDݺ<8fxKB}BЏhCJ 1XE$>8[?NLبs*>s%5 -'.Z,䒾E*NC]5B\(nE' lkV*}$e)Yh$1/)JGwpHx% ..]٧K +AaR M%p h`)o*+eB)VX{gv{Sc⚅e{@|*imF姼!~bg]۹؊]{\S!M8g4 M l^E8ʠBiD7DÃ}H(ɐB~Uu͝adT|u'-u{TiU/Klma>eD~tx>۞/bʕJx1G^|M:;FpWD"az?$)4͝d[gN/7zI~<] ݃ k&{ pNInGYY6lfjU-K} q(  Kq*GJ~xGRM[&8'TQ9Q4NnNc_=ύ @A+ʖ¥婌 yoRը(qat/(DלּQd;}/޲gk۲'fYi_gdifdW6l޲JD:-ٰ䡛)1++HB@5 7`r ξ=آX.UTUywF}v1c~ ǎ`p0.} 4yyJ|?kN+ǖʁP%lHYE?:`?s| ^9%X5N m0[~O / R.L_ DK[+ٹSo"Z#+RB2L4,TGx~JYJfÕBPhHGaӾm[+ gG(doT@VU툽b9US O%ߣc'Vw6kHo~#N[f;PY1#;! y 瀹7VĒTMɶ:B^ \HP#&}ImtVA?=])(逶6q߈NjlO {u'>n\Kns5@m /J8sUNfZ?d6o6u%CMh^wm`|(+w&Y"q# dҬGC&(1ewwm5Z'󵉝xԕ&-> 0\Toȴ2Qxa+°PQ<*Mf[4ext ?v*MݿDim!E]QM":Ft~S_·S2eg7zL: r?|n€!e%|*k ٕ.&keY $AZ6MQJ$cxWɄ[J{ 4n=jShN8:J GMo0mup.El9p>cJgdP$"%  >k0=}@PR0]yopО@uh)Wa llo}:2'.V#V{20+ɶ p&V؃%hIǷ\l6S\jϓJ2*/Jў4АX!tVfpv/.vyd] >MlZMDόeqFWrɽ_ؘC@K7~/eC :&4!ip`NN"zqsO .%?o8![3 _*K}ќLʿ0X|A]a Wo M^ͮNk+(LIǸqjnc/RÑyO)ԓAofؕ,'ܤdE,tF/i 2I]MSYqo~*FPIC}%݌żu  *By$ڭ>fm`Np.*T7$]z}tҚO h[Zer~5vjqmWvʌ+ngoc*_bVIPIy"{Z~A7 ' 6reN/&ZҒC0d B!^[3kIk)Mk^xq^, qW,?qט9R_: 7 #Pm$ I9AjBf5JAЁ(O`1`,=])*0: a8[,~Ę l$ `,ƶ7P7[@saQ̶yJFUסeKf>^eߓ=VN2`bݔFpg4˸IrXhfkאp"rź{e3/# ALUc_264澑$ٱ *, L ҁK|5C!*#.jx^|a! 1~. f2t~f#5s1)=&~hP]PY{(zge)={}86xO+읢OF;ޗhs~GsCAbcI!͢Ja!h̏S3Nqco'˃{ߘTtM"?Y92U+y%gE0 j 3 Dm{c"awÍ^@ O+qQo0 >^zyVI0w(-Й;z Vr-h DeBv3I |ap_TnUp>X:{,NQ.ӳ%B +Tؕ5@X-.캧AsAmgKܭP]9vZq-~q`Lj ^tk0Le*CZҁyR74k{ Z9W#Qs"6qfsf~Zg#Ĺ eBo׬u0A:'r7y PŞuJigRq""~Lt{Q l 7iNn ᪖DZ h-Bɑ@fE J erCj-%~d QƐtCZ we3&t -7e&>a,ik4ҏ}Ii{ m?HrdDZ-^Ov*h}2?;OH(Zk HmYP>U%Bx.n_59䒋;}RPi֍=EmZAHEKl$7ng~N vMiOFUI5EFMl(y#J@k\9Jq3!mi9\b iĄ(7ezѸݞL K`XSWםy"+6ʶtF'lָ:Oc\&6 z3Flg^`H]M #́~?* =Q_ߠ|Fb& ȗ11c$+ LYN \Wr]̠er=ꊒV}|P9,nԡ3F|̳ɇ|NPC /e %1+Xo il4Ӹ>{#WrRYGbH@3wsʹ֍RSL}E_ڰ*j!]#GTئ͜J?~c3`BZP6،Edz_.?aR*x Ch:˔iTOH{6Ax 3.WNˤ&w5Bil)6^1&bN'OZ:ǴWP+C. ؉4P|X\oP]( SwA!FFf^gFxeF[~rP溠(D8v7}Kx1Fv~ih+G]טVrX>SxH r$tc^pi??%MG?>>1Oat}:17}9!aVh$Mi(Ne|x|wh$*Y씮+y9VkA} 7;:'(pp!n')VUX;">=P-ۢ(sfY-6G qLp[?@ [\\Hܐ$B4Xسs]֒Qi0_?WTɦGV1.PylD(1?(6y^k_ƵxBZfg=tX1aV~Z~4U\b2،"J _Z52"dRÓX[SSЇ`" =+yuO5]si̘[|qqO61ˀ=X'UN㩠:'"0tVM3"}32DBi'vw0[hؤJ?3Q|, >=J'9/t@)¨\YGwu7~IlA~OTo _4ד%Hܪj.~^,S Gz2γ07 LAFk8v"t^Z /ͼGo.'e fK>L98 1M9MVdP'q ! 94B~D73.6%aPOZgip{M|`dtՍ ȬfqϚP90;ݹWkRaӲ@΢&CW0=ߤA&;N $]a,_nJ_Х} ʋAZ*Z<lBCzMj\t1' t*L(|)o5xyE{M9-W#}¡@W#ӿh sur۾<V)E͝ӯϻ!% 8#v#K2~&Wc-}!.2ap٦TTx+V JcuORBŏRם(ͬp >+-5TAS(LJ ǥ.F{jdt:VL:&ùJ )׺0ߟٚ8`llխGfM cϔQxs!`ٟeNa|$pUcg5<*EY=vY<sws羖S0L*;ox WoC@>nmm 0l0^Jշzf<Ωg}A!Vl2 kkJnYp&_5h\~R2TOsNurXd]#֠<@bOq~U飪rh,@lE6yv&\] }Azi>?ve>CVt IKȰK;5ELw7{^|Q׳|IVaAڻY_d:7|VMp Ԟm|Dl;i Pdtr -yz!`]}Y ό a[$]] Ku?;e= <1zPq_3c9 br j u b4%8.s1bP&xnJNJw/p\ {HfJL7jn^C||yIGį;}}"pk:u'YoDF'0qM,jogGi$T"JvQ:)z7YAVjmx@-Ã\DT_h@.L"K5.<uE;0ű3Oc,>8:-CZd7C =ǜL7[U%KIKGQX@>pC609P ۄx1)MH'/kCܛaMz)TLcҞ]qjӋ}1}~ [X: {s1\ah;)b;vx}v8hxMz~n(kX-F Z#\Tj w[wS8 Y9-43qPc~ܵ?v,RmVʫ4N*-ɆL\%0Q͗e{\ª_ڻi*:}q Df>vvq27PWB:Ħk`pxJ:©,Cz.Zn aD:]Nh+»CCZ5+Ѽ%d+k+{ H`r3.B-xk."6x盼 Oy>#` }ScC?yf9RĚ$cxVzIWh"cmhD6% Lr" P WiRnȡS@:1/DT?F~JF#?F5Kؾk><.L_KB-wHJwkʉܬ b&;(mL%y|s֛ ApU{=1|ua9kl܃ѓ 8I)yZ+ĝw,"gh*=ABP:lCI'k~sƋY H tiֺޮz]3pV1y=!CҞ7遧ğ:0,(Ss .HiE%!}h8tffIå b)I1fL Hއu QvšV칾ILӋ8:v׵(Or>\6/"AX* 3 R'> rdÄ/Ni )f-HXCO|P+6/>['B-4L1F *HmBntM5UEW_<~Gu]I#ۘJvCX|Bpw/&k,7cJԘdE** &+iΕJS{r-Ǜ~Hv@CYLMQt)urr2.^|@zZfNb{`Y;Yj9!E>Ok)}虴-1@]=EBN[zs%?q([# ~/V5f ejVMHۖى#F*}No/kigDotի yiU2X.v@r89 VW>Ob@ &W6n2 Ȃ|4btVK~L~O6ʔg$1O>БrWP4ؿ7VOPNTX*6U5v .2Pd%2֬b1ۛqZ ̫p%/.ۥI :ZM9zӰ6ПVVm ɖhXH/tv^>T"4|5BdȨ1f_E@77RŭA&&zUހ`/Jkц||{h6d>%@ЌO37'R.LUTe~ˡl10^k ƴ?5$]:9C2Ey@*&l]nhU)|!AVo;6ŚZVaž+~NKسrO L-&*j dzA޺7en <\T z}1r0.s2!MZ89eTLw*i3I1,-dKM+M>*aђ8r#sT;c9Ӓax>&3?9钆fɎKIJg_qaS17bV^N,6\-Gߧ-&0͎=})DѢ<#\h =O%iQ<ƾj;RfN6~2mU'ʿcY4pYx)]0+{ <_+ \%|9+/?GD2 }SY8n~8r!R(A`Mw^`ׅ~wD2;ˌǨzݝm ΈJ>TQ%|\bҭ+Ih+LQVo\eDV ln̅c_K>% 0_G] ZY<,挦lڗf}62_8ڦ)04=~u?έP\,Ԯ#8gU敎+sF\fBvXI|GhWv$+.*.{TKڛ.tdA9Ȩ QH[H5(^hrPVTs)gω}uhGްmwgL}JG;=\DOӏr(LiEN[>BN&;(L$ܿ!*.4 U~?GZ LˍeS*O0I3{~3ςx? ʦɔ˶.ALimm9eHϮx2\Z.UPؘޝn%4+_![t 18k9gNAbZ.R!$*-EΣ*6sp ZcO b\Y1TۜqfjЌ=A}g )%9+Ad>c֜뢤>.iLl{[xQ:H=y8 Oޑ,̊i L#%Qs/ZNhB4q;UBk=MXt&dh+t/ &:'r&]3l 0|^}$I-]GK{ls7Rƥ4pXgaNM l6Ef!D}n!0x̳Mgv{D.d]b*c/R?19GSH"Gڥ"C)Vjz`6gT69U O- }daz]sHA%* 7I 3M"35<)z)8#"2bE*=`l_2-gyqjQRIZnwj}4@]oQr`>.#zr+TxZF!rAsm1HhAuH@K5tlʸ⯼~#&̃ w"%kiDy,bҞ=T} h0Xn[?X`l >'*{6,/+[Nv_$X~,2nuů/<-WA"RgŌ.\mR6Aq(S3ͤw-a}9SHNRNard2Y}>~7uhC@v-9?LY@tz),M;u58"4S0|_.%ݮ;i&(?:!b3A/%`?:gss.egRT%@M~M_e'u jLlCxWC2*q=7u.kDDf8ݤ<,uTn<,`eE{J ?,X>Ki?KCƅ^],Ic^1湽R #ЦX1+p_Gfa*r] A@}e#4 ,洜DB`%*8΁%q1({e(jXY 2taÇ@ ǽ4ܢ~ hr0kFvTah{`I' Iw=A+)7M4u@B8cP3ǹNs&i;LĮsl]Z:;? @ۮ-;=>`P7xF _c2; 6˧R7O > 2Ő;_^Hr?VWjy=5-֭ z*J7uy'cov<0@ {ۇt4YO!eF3/axp:?RUond}*g=w~tkZ8 Iim:chUrГc9=3W (%8W=84وUe`өL:&)H'XKjt[TTQpp . fmqpLY(5*}Gu*v3M"3HVZKSM}5\FGlI{(3ua l+}xy/AL&c3X7̞0 s +‘ bzrn|"neB+ڭFfIKK@TUnA&чkIaWeӱ#EY踉BeO{G ;PC.64aeL] 0WF t_Zu! א 3gI.ƚVh餁\^5y/_i=-190ԫn ߙ%8v.eWn7sfWsP,"#>3S$bY˽3ջ4X: cAY gJ<'w[hV6ԤW: DRkh*P#jɰ\ ߬sxvb"\F}j Sn}FU!4+MN9 w}G &kzN<)XL{تvXm4E}+Afw8!cƵhDB3yȽe2\xU찪7v^sfOPJ+oQ!fL#O{*M^ zvu-+,θЄrtC ENA({ֹXN6Y_K9z/^𜻴Y!qZmlml+}_2(C^?fWu6;DAKIYkvO½ 3lp& \K4I'PS.sНs!'޴Lav)܄v>FW%7D|F[RhjAu OIyІ} jAZ^_O?CN^G44á"t՜pFeKzJ|k| NWqYVn_[A%~g~1/ {b.d= &e#*4 J=8?NsTYmx(5FEb |ۏƙc f_ra*2]s.@;WNVbl 3|֓!X:et _=ES!ZKX'ƊlNb[cYn_Q1J+R[!0Z=?s$U Ƅ ]g U@vVNYہz %\CWZNn( vE/pD_~SK Q_PD_|Ib@/ mؘ>f"P"tNrp6(lY9"= 6Fiq\WzcTi֓Jjz eSI:GWQ赟O">o#HÃTRMKAmStTyRXvķ+)#c5O1ix9շ c]v2QN7\?fꀄj~iUG%YQTq3iJl('ȍR6NYJjOet܎~=4י%eJtD_铒sTU@YlEF``DtߦN5[J#zU2Rࠛ @OTc-͍8[_y=o80RZ9OQҘt✎B8%YxiR&6ͳ9@OV$TwDaMڏv^;.Pq%Yr! 'e/@1EImWHtdIQg{%ijC䴅)j5.+PT^&MΚ;}~AysQeUobκ|lld"{Pa"Anz`dՐ50L F6Hg5$I|TFi,Cmúgj8)C@64l94<'K^Ey]xVcF.qd vTX@}In4JxVIB5=,r 8]7b0UȾVr)q~:P9_N!: 'ֈS(*,2Cy5]ʣ)GGj1l1{߉d$9%(XWVY JK5/LON`2$n)>`1g62u+UΫ|]hZҁ(lE-J=}N+k: ?MhʸZ0&O܈(*c# Aܩ @-gN{.{oue$H~gbB1:y^j[U){?E@".^#yZ:-O-z;*}HeGs"}%|GGLt_ SNȭW[b;2Imq/C@U*wk='ȁ _xѶ&xgsb#TTc܄wq!{'a}n`DYanIߥxFx,5d<vжO[V^=DCvn &E)n}ЃGWP0/G 21Y/PoJ9_.Q&u3[2p>[+iCsP .@8 MZbgZ~taFWVPB%CQ9.W<rgVncP0A(:yi)d8\X/53prE) =RPaƣ)ørb?ܒl1C_Fs\,9q["Գ"#[J ^L~3Gl\#XJFR3{kG"'p냞DNa@0>C`Pˎ즤\%W8GbNct8WFZK@~X@Xg"Qَ_oh7@Jc>{Jiĭ0JA@_oH?jhA9\^ Vͷz-4})LKⰷ]kqgp8*S]w^ b#`05`AyT2=,V*psw{E ᤃpiŃmR4xNjE*CJhħKHvz46D;J`:gK`ff"itkעbSpVIɡ߿8&kv鴺? T0ZeC+*@@~OeYkї>IxJ-tF+8rpJ%HDԗ`J;ϳcqSvb2G@g\a ۭ" K3%T%9u}j:LR.rC!cuKzS VDgs ~%[nk 1dʭȖ>]N#wFࡠcP!>yx_*5+,^Gc'6 @B8 ،3O+d #.5"BA _mo׿Rb7]Knw 줘dA$uU_|$r g%[zHDAc{>K){ \+/*#j4Xa+T[N@>,Y,P&EQ)3.EkD( 6| x* poMT>ɓTi[*Ls]N7́Q*g™P}z6%7NCն\*EzO3`z$QCW8{r2T~H  >l `dXt*^[&H|{[1s+`ȴ$%( ubn&sŶH*# { j.*!EѴ c&z 뙶i mFXm0)EYZ D?6HTPR&1TZlj ư"ZELC!hJ1jc󺽍q)/ZbpvKPـ?H|{sѐkd\gtki=ҍj"1g iwÚ&kgtӤ=N/&HKM;"c/}!X25mLA %onÃ~ LI8T8RV֩4Yg1by,CDIbɯӟzض0C9fd\~2Ȣ< j욜W! TIv1/yy7?®DCp`S+B/`xq7{IYfrSئEx2*]i No)(!pmWJN#p e$ `dFRh$]AJ0´Nh+qc|).՘ ..$'[}yeE%Rhck(6 loٜ6u·{@ ],ǞB}nv~WzrSM DP3VHɆ}x&5qy0Q?g$R 4VHG?޸g0+ ɢ苴=TapD,a ~.Eħ a]$_";Zm.w sh=Ũx)e,;8* F}(`Ɖf(tb|1j Q׭B?av& Q#M%֎0Nc^MQ@glFd۳!ymmS$hu^Tݡx%}U 8MQT_J6܅4j%XD7o}4Vymg]t J@>uv"gCsշN,b UΏpg{e\7x_jy]iqS&en',<0K `ԷsdE$M֫\-qta}n>U=_ 9j]BԲPqrH]NC)RKXP⢔8~2E= D%p'ԋݒRAx8g=AΊ \fi1w>~ȀS #:j,-E?@WFAr|uN <mא  Kl©oH_%#Q0He0\'5Ҽ~UB3UE=O iOhz4n1|΄s\Ivt+ݿqqNzV1bxѶSjJUӐzzݚ&>yo&IGDseW =˸{`m!$M6Ocyٖ|MD\{E|]EJUnC-PcDd -]T!?;y5 8Ǿp1嵡RLe(v!Dz(X6^`i1->\ %dDs ߰㰶6%}|~? 7m1 &r[\i/_qAm{ ^鵐XS1TTΑctIpwꤤC&9DU"{Ө4 p2~B`0H@Yd$WWko.P@! JɘkFӧZ~/@@D3m4+)!>x MEoYIbkOwBK@kZe 3dO_$Y}O! o28UΗԧ(ЁI (>71ǸآG?ƅ( 0g{TM)҆ujfKKd%>@:k?w;Mthhw(uV2,;XO#|<.bs.%_QM_7z.Phy|ZS+ +tyb嗙  #S>, zr{6  a5$D%;N=~9[GR