sssd-ipa-1.16.2-13.el7_6.8> H HtxHF\d ?*}}{vuaxjBp1ᴡbYw1a202309312323d25f0ecc1f23a13c4ea525cfdd2Ws0ƕ0ȈF\d ?*}}2YZs bp^wG<Ϧ\,SX+~t[ o >>?d   : 7=D   , s |PQQ Q|(89:x=PGXHtIXY\]^Dbdefltuvw@x\yxXCsssd-ipa1.16.213.el7_6.8The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.\fsl7.fnal.gov jScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdxK#A큤A\"\"\_[\\\371bf8b9ce46b685242b4ac25cca6cafefbc51934ee93b7c8c296c72a4a54601042c855ad35508bf92bc79b8eb3355faf76c94a8dfab7f36d1b9209aa2d2716e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903df88aa8f1357dcb06f9b25d82da35c112beb813a94d864e852cf62aaff7f4a663a6cd8d21afcc2b4f408160a0aeaf17733b4fb60b865f448713feec2e6fc9323rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.2-13.el7_6.8.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.2-13.el7_6.83.0.4-14.6.0-14.0-11.16.2-13.el7_6.81.16.2-13.el7_6.81.16.2-13.el7_6.85.2-1sssd1.10.0-8.beta24.11.3\@\@\@\@\@\@[@[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.2-13.8Michal Židek - 1.16.2-13.7Michal Židek - 1.16.2-13.6Michal Židek - 1.16.2-13.5Michal Židek - 1.16.2-13.4Michal Židek - 1.16.2-13.3Michal Židek - 1.16.2-13.2Michal Židek - 1.16.2-13.1Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1690759 - RHEL STIG pointing sssd Packaging issue [rhel-7.6.z] - Part 2.- Resolves: rhbz#1690759 - RHEL STIG pointing sssd Packaging issue [rhel-7.6.z]- Resolves: rhbz#1683578 - sssd_krb5_locator_plugin introduces delay in cifs.upcall krb5 calls [rhel-7.6.z]- Resolves: rhbz#1659507 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI [rhel-7.6.z]- Resolves: rhbz#1659083 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust [rhel-7.6.z]- Resolves: rhbz#1656833 - sssd_nss memory leak [rhel-7.6.z]- Resolves: Bug 1649784 - SSSD not fetching all sudo rules from AD [rhel-7.6.z]- Resolves: rhbz#1645047 - sssd only sets the SELinux login context if it differs from the default [rhel-7.6.z]- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.2-13.el7_6.81.16.2-13.el7_6.8libsss_ipa.soselinux_childsssd-ipa-1.16.2COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.2//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5dc3af1e1c89ab9a44fc64121f06add9e036acd3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=348dc2cfb8d268dbb14d69248fe47d71b85f61e8, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R RRGRRDR.R RRRRRR=R RR"R#R1R?RRR>RRRR RAR0R+RR R2RER(RRR/R R7R8R:R6R5R&R'R*R)R%R-R9RFRRRRq2Iv|æVR~EVvЄ*jN^UEl~PDsҺkzyB6={l7EF=֒djɔżW·xC "JOBLm.?KV(YBs*}S4HDGrzy w[7UuiD~i={f_,cUs Gu y7QZlZVR + 455a%ݐڗ{xs7~8L;N!q(s2ptNWgGe PX 2@9 R2BsZMt ;Qn% tEUg4L5/b׹N-$ 9t@vi/T/r{7BᎶv-ͣI+t0pN\Lȭ2SFp:ȀE3 ˖1{OOºᨵ14A 4 8iKs2ddrE9Cg\3TEb YuUG؍sp )2 EOTĜOeC7(:3\Ɣh~+SlU fƠE'w^bnKX?Ivz/6LrUz_go}ן&n!Q+PfR&MRMh`ʄMD,ޜ&R*20Ϟ^_SܿBy?^S1zHLvGGn6@>Fanե2#b]ֈ˧N,(zǟ%*ܤ QtW.|ʰn9di HCRu;_0F&d-r,ݳm7 o)c$vt4@ ^l̨PnSuyo} $џ]H]$&+ăG0L3E.e>ЀY &^p٤Z2Vݲ2{튘%\ܚQVɑh|m,a?5̣e`f&zzf K+t#Ig^Kn1]#5VH6N%Vܿ; KAC rDvյReWό+l{Rqg4XM!m:ZzZM5]x  Rȓi"ֶ|(Uޣ\N0}|f?'2n!|lGOT}Jto.pq.} -?!YA^@.eTn">f+gFB40oYZٝ8.06$Sŗ~{-M,=>e)n @ D^ _RcܫdQ?aJOs[_PW%3XUC\Ŋ3 2Ōa4вm/^^e~7~Qrj4 &d a Q+LЧa5?x{ [/t\ O#ESX kJՄ R g+mFQEeEZ1\[.yi:HvGT]lq#0\CJ_, z䤖=*N2x>k!FU3 drPJ#lf,K5A pg5YC:;eӲ/`HRIȣE%ټ8j_Cyl~Z5уw8rkf6Ps%Ih} 3>֓wu}YJW`d?2_;iFjiMR t w+ABtj덂T L_Quzb®E 8<( m=V;k8PD}k?ݧSa}քWwu= ms]-^pr>'A]V[So8,rJ̔q Y5<q2 b#iN;uns[#g+V(_+3k2=84.QK̒DtF| <応@@ڃa mj) =i] \~ux|6iM*iX,ks"=NJDsYXHTK1Nn/ģƱf VLٱ 6hjPk ي'j[[h`aK!opW`|΄}n!Xwȼ01Jb׃ne2OchB.hDD@90%C` r%,*hJ6-o7vO$9l q#NCs^GlѾS[s]|;J/2mg16V?ٸ63y{.7ZO B?):nUxFnPUʐWZUĨR^(@ ۾ɔ ("ED03M.}2&irpr;yb(@@N#]*JުF*y /@-m @46`$P4S~Q:n;D0QЉ ˮaf@J P|r)z"!a+}8Ʋm}_٦r"c*lN-x mꡭKn?`piYF~u H׵Vp?^9B'fExA6}yTݜxMbAØcTT>DY;bu;SB[SUKO.Dڕ+P"ҼTD[eL"2I9&U=U7)^'b%Aq+|ʳ%C;)7kL|Y E6^}%| ͇7e= +Pg`Ӥ$.HS-'쨾%tS16E>@ X%;p$)1!ptK<,p}0GY)" pd-X }F{-|XJ-R;5өΧxf0`8e`mxdАb-Vժ§Qc˖ΰ>$t;>779v|յ$+N벾#GzS-GB߂Ѝ(`_?بQhq}6˺ؗ5lGG"#@S-3#xkA'I6M!MqqYA"gUߌob!yn/A |Ih_y6cc^3Z&pZ[]st.ǧn3OZaՋMY畋޽IǑ2-Sh ޯ! cۣ,b ݪByqNP?[&i"/&j^'_}!R0 Zp]4hk-L-+y˾#AIIM5r?-8;iΟ^蔤fHM֫L A#U&k wrY8ܱ #"D/Z@MmM: xKy~3~b0L3;,]W/W?gvDw񰲖7x.l Xdڀ8#>D`tX|zӫ;} y2r:vt^"5Kꖹx;XI!oYʝ"-e[rXm:.:\:a7s;V$m脚> {(ZrD~m (w#%vW2JV-7PJ B gn#E%쫫|9<Qr=1ݾx"Y}3 Gv(ΟŚ .[_`\Bnx}Pb[~]UA?ke[I5DƘԴSm2ayOcHc5E'5fËq/6Ť_xm϶<IghIL>J`cQذDwNt5'\ m-ڑ_JPlue칧\-si>pkNr5<lG֟?~-ɾ-q\MQ@iZTsԡ #XJpe(yoLo%v\~uh@g>앋v-ʥm"4AnY0({ozL 舡RPA,' @eIoyqiGI~96 2w dNj_nauLJIJ nX.|̪ĦFrL?A aJDZh5f;3MrFswf k v׭4iîyfKl3NyܧV"7s1P֢=dVoo].եU *խLy"'E+R8P`CԃB+Ff嵻@Fli<ObAмHkU9ܑpr|,a "saͿu*E|~-9c%*OYR2g9bJy?~n޳3VG2K_]+hR` 3f'犟t.# +ш!axïЗ8Cĝv]~O]il;z"4ϕq Q,T~Sj5_^Ij9̬{I XBRy`AD̪1A Eh|zOY:_WԺBdS+-&{G=R6P!Zm>[^Wmp ~X)Y+3eT})sݤհD6T@'/e\dK6?%#P,,Y~whujK6\@[YE0_˭ֺi cZ`qr?U*DdFmt?[@)-Ё^\^[:z G?#Z\F=c_/tWv8fc0b ?H38AjwѬ tmF q-Dxb*{=HߣqFrvto-ELvHþ^$G)Ro;r.mIS(u4<]d&tobih)RI>YRtjjÜC]tayvӭ#1"aoS-##{=L8E4DȘ(Y~Q V\:idf1$'MvGFb|;ߏ A6(+JQAHcȼC<%IqCfX!(-~od]n@i:%v])GO<F}O Q84@ } U!,侩?0L8E⌏{/G[ 'ku: o@c<[v6S9H<' '^HB]Vg~G)z+@;k} Zuj9FYEǾD:Qfn҂$Dስaͮv%; X%mKw[K-z_y$DYRYiUjMRw0!#a;"X#C쎿ϐsaOklХ8P Ҹk 810V܉P t<*ʼnkqOp BeDMu4x?Xhmdv^JcNᱸؙ7XWfwf{Zim BG:#pԙ"{/hцʭ~*ѮEhot撤A);`k8.CL ~kl+ѹ_8Îfcy67o)%vB U'0%ש,jjkBQU&ֵViq8H/ܽ͞ޯe䘫T ^_ 6; #g{ Jrf|%1,K*u/C-;ߋwG. Uf O9m]릒L!m!e^3"&F)2&َDM';%oɪqMs1TRtݱiQ1R̓Iza7TNLq[n7[Dτ8OWe;0rO`0 BRE|ʅ:TxځyZʷ]םJUkWxeߒ6 @'2U^S8G׈Z8a H+T]rܪ#Y 2DP: m2cd̑a//L$|͢-sBjg'2čUInP>& *Y9?zX mGb ygSOS>/jLHɦz@&W358{9}7qyw%Z"RSfqj5)߱֘AaR۳[}W8I$5XcGɍGKmю~@.!*MRTuڕ^g/5 ?dzzZm:'Ba:!92}ת gfp3 B F> \D͉\3o@D1 FuoQ׃nxK\\?[ IE3]I!QYW <$ S4".t_\}NP/AxbtZ!Yy[v4x9ԀSb3 duO@^7F Gs Fͬaya|my @\˱DĩgĔ9dIN+5K $tW𝹘yiE1f?>pDg?{-qke3vV Co-Z| ((*ۦ\v )R}*vH kD\M!m̥_[RčP$ a eoyx0skHB`D䔈6wR&^cb"++4)E~e%lzt>yU΍ z1J71+mW'ìw5v "qn9,KbhXɏߖ<},kX=g;oO.PXO\2ދ t.B<҉I #=?Sh'tN&\!2s굿D)~/vQ݃>!4,l%ܢH1YN0 ъ,oNz|yn 0کq(kwPo%c[$:}+@,uX 6! fuNLTr~~6$_}Ct _-u/B>B![0gY崻km ilaJ*'Ϧ]GSDJt^% xIЄ!@#eW _cȽi3N)o^Rr0Z8xv;Fҙϳi|xs=uޭ 61DzܲC^]-`u~RjRi eFý嬠`˫h/@Ӈ=2W,>S%KP$(z[(ui-D{G};ăF愬R5 6nrNjVaX@B/¯7 %kC`OWDpύ=@oV  H,bjWE:^KKi5߸X >mQi” M$ϩ{pEp- .Ka3_d6Y9֋(IW|2=d-)ֻ7x<e0hY'{S$-G<K?b: Ҿm)1WU| ,g'nB5Uڕ/X4Q'*kiQًڕg0Z-+*= qkYqJU[P9W]ڀ#ñh"soDƪPuv9UAr/9eغg#NުEQ5>G,|mcO;A5G&2kk CSKB?].-.BaFlnZ  Qf7F1kZڑ'Ⱥz,:%FF]Ӱx-˫oW#v  `xP+B6Yl:D_Gj\旌)(橸y=cl1fPG>cKKyd=ZOFYA5!8XD:%|>j=mD{u0w){,ݑm$= 2+^{2۷ؿ㹂 HaY6kaˍ_K@ga9*dmh\[k< Npv&YÖۊ_(I grba􁫒Ia >ʿ]^0c8ň0 ~1>s̒4"~iJUQ -g+9 . c>^Ff80 z/xk}w,Q(_PJpS'?ITn]G&L*1Ͷi Z({xNeB+ؖBy"-?q 3- FVS1h 5n{d i=4SKOP([ڦ[l(UՕADp?KTK^#eۧP%IB-HZ2bFʻ^N*{OHz J e@ y-XqsA`_np/-!~DeD_ʽ[Im.~M_},facOc.fӰy_# {hvT@U&lKF'}M-0Ckk2ÙlA*|%XgVrCщT5c*)10W+B˛e̮g ɷ`nźSrWuPz4騿މRwʞS8t[5I`VRƩ./H*D%ϧFiSOqUxȯ{?r9m"{iaGZoHu0䏳B/ORnNYeDL4S 0W1tcwo¨}ge;ڴ/nJ>O^1[m|J)>-ahbDK\e.F1GIry(X3TEi.}UdTLX[U9Ə$Ӫ{Jac"ea%l`5dK@֟hj_BN͞Ss4\%޸ֹe2wg\0FV1.+*4ɗ)S"iDgH <[ؿBgGbqQY[! J 7pJMy3W:X-kh^W` ΒAs3Q0 /#( 61g5+4ߔ.Zd"G['\H[q4C+E`?ñ:ONW }aœ0 5HVcOUJ?!17ݠ 4̺F1&[px;o7^W5!gBe3ā0'YҒ:3d)r|O4>Y]3F_7Z6+1e\^m@E'e3M I-0C|@L|?Ew2_)B-VM9Z3`ѷ6/=2cs|@U^YgwJGuׄ' OÖ0뼪>U!M~ Yf~$rc t=ם]g RiPK+#NA+]Ղ`VtMQ>!r꣸wA)mJc&*ސ5ZH=[W440u^יF (YnԃO>̕H]SR@[v*Pe ȧ4m5I3jsiӔ_#F_O+ڢ~tÊQf&E?ʍj}:̨2cZL&uB &%9@1gɹ+w}GIw`_o p-H"U*9Dб*åJ> sQ^Np!8YnouW(]܇04=GL.l YJAĖ4UVi4+wI粣 @rg{GC2d_+CGl䵁v)]=ࢺdk븭-ח*Tث5w!Ι l{5 #6_Ce&R-pԯbR_R/>v` ŶBڎ| Њ^}b 42錣+חX-l\ vޣX;I-#UA\E]JiK,}Emw7@Gfpnyq@b{_pNs?^ %]D(.;}lw#FfS$Ft&Ɂp;Z]eMS>{8$  aNbŨw8h{^ a9l\ky-_wH Q|}FTǴ T/[3I ><˵S -)'(zwQ3~d9g}Փ HrЛ[BpgfeP(ſ,.KW qG7?פFƐ2Fo\m=Xd0QҪ/=F`1X]~9ņ La&db NVSO1:hJ_-FxxeOg̝HJ-!v7|.ū!k⳩.wga8r}WSݬ <ZGnž4 (wIk,(t'~uZ^$-p}];a~6E\5,GN(M*;4p\!P nvp"4oVY՟T&ɺ46_q9cBDu8۞AX=9td4hP΅S1^P<1~уMKN is8 EQs|6ݹ L;;LܽMHTkS:Er=<<,xj9s1++ڌGax._x2HHnE;;Sj&bH Vxy:2vްae@!)t/lٙsYysDI~6zܕ e]+r@}wt}{钠bG|B Ԏ),ڑYBN Hl?rГ4Sn+0LΐՈFhq$>CͰMFoKT3vLS!N`Qi>] ]=)߽BJN/*I\r.fʀPcQ^#Wk Q2íp!ܚ1@dجXRHhY۲l9#$c~1THQ*Wu >FgC5noYr?~/߅|eg."Ʉ׋;e~5-.7'pe.y eBF!kΈI,b"bFZ,/!ANK>#n; C攝|z!6Q8pY:7O`߸11`ge w8f -l࿚JSN@Mk RL{1yd.as& J -U7+*]P;Td+nU13V%"bk1~ȡ]NopxO!k+ӣC=M#S-4NR2a%}gEu>rOg ;P%rlzH 0tvـSwͳ z3G>"P]e,!H&9ҏ"8ϦnmuH>'1|1M@Q4rtc *cMPۜt2-L4|g|^˽ fJ/US +ݗj3I+_ISz"3|Ei:2֫&%ѫoTxiS=+i)`e}6Eup\b.#wz/Y(@'YP[khL]KheJ]`A . +ySe&5ߠ1"ߞ§j&0x4*B1Q| X%mpUvaǪ1Ԉ!ئ͖A0=X ud1 d֔\vٴOŭ#+ o p4srLpܛ(-yn}b ̸ pYe`ADzv_6e({K`MVkLAX1l(WWgk3&nk{B ?D((*-_T0^&XUH9 rW;Ty@ RbN$m^lDCƷ鄺cehO iyD WZ*%aSJoSɻPX5q-IpӿٽP&Ir'rMm Ӓi29:a9)v.$g{j_;q>[jp@SC)Js O#GPX V4䶒;b 6VN_^v9a 8!ht Tb+(!({%9覄$sM"` l|Q{X<<65y''f1es)@lp/b_ܢc.L@t!A_nȒ䥥8LO9)ԭ л?Ҽ'L@Ty95O&%aQJ.PYs>x7ƌ<CUӘEck_MM{'4"ց.$WWN Ji+11 ֤ |~<8^ZBrh" ?DkqbgG"%K!vr>mY6H#>qeCΎA w3 Xs([d+EMƤ02F+1(7^B N^;7 MG#3(]u &''c+xn|۴:Zu<FmLaYU[uG_(z$ui"Df  KK ;uNG-zOSR2_ItEnIDl_iRa觌2Us+ޓ͎xl5-@d&,^f#klFh h #%- B+)2I+v؎ýIZ~Ma/U⌻SeW]Im=@$eR·\=L*+YĨ$;Ky91GXG㧠#t>G)U/L!kGFQ_Y nB8n >[0:X] 6V8PɢL۞)tU 4 G4RIBbsiMU'W)u!8_iNyқr9{uCz4eBTZ{ͳ=߽Ѻvt70׸nO4V Q5Q""0Fd%tE6s(UKU"!mqm9˞_jЦ dy-_Tih?8[< whاB|f )rвR,E3Q~-vCNHZ $* wiЫ΍RY4ᄈz0Ug ߘG/e0spI?%0xq!:]Z0p ]CܨϮdclt |N2!|@s;}˿%<2<]er /R) ;N1{oENJxZ-}D,olSA^>Bd=Ľ*#`çmoꡮ$,+]:jm >AhNBWVQS*arQg_\u+1ո e%l~Oė:jčxhp6eoC5 =}2'}SavsNŒeY+Β1+#hIM'V݋!'+)N #{!{uxѪR,Kn<Y*F-c iHSh~{@Hze'YӌF<^T+WzbO| V'φPwg(Q%}Sf|閁)& rJIPZAa yܛ?lneS+ @LOJR*O'盛zsOai:AIF yL7c{S{v-.^|+f=G>,"+0CЦ2%^.uFP+(I;>Hi-Eh: aI8rՂgR-w9~tt][e\g,{!PYc;Sb!^Qn L4GRrm:D*I.KM&H+LEXK?)'o:nXutA=yQ|#!QU 4 :jyzeP=s@C7?o2[r!JN0NꄏқU_rQ.BoFgҭg ڝ)K(U;VXح\}sdeq6&&_:~ 6Śp6\/bQF `+l3G 6D$zFd~j7=ʍUYIY#輸NGnI"~ fu=4mEN,st =v_)lgYWbK_YfMK n0;e-[n)qXAL6#tْS[ hCY=ǫ/fDOaQ3_m3},poab#BZ1Jb/T]{f\ko*H}@zӜ<% u69???ҸTӄ ƛ$У4 @zuTM,Aðh{MSetT| (Ü[f`I _z} ⦶ȶprCwrƊ6G̭_IԜ2AOsK&.$"ANIc=9 F?Z%.Qw6=11F]hQxn,sm-`p1FS tіy7Zt}y΂8eig:%]|!.z,Ә[?ţix"U5BdI?" kDZ4WIlKS0$؉U*\!ݪ퐟|Ŋ}Ra+POM׵/j& ka flTN# ${}ʢT4V:!HeE73S)s^Ѷ+XϚ۩߯H EJ" x$9 ^603nR4v/sS\qב'bKD`(,᫼Gۋv,/LeQ"mYYZjzkA[vm50MZ.PZ4^9z@$|hLzÂ(9TϠhqc~DONK ꦤIINejF2ꊷSP~Uq](e(` 8D/K|\:heuX0?~ooqY:Ai[&'y. :[ymkLHVQڼⳇvd1?uܚ;-[8'3@3AHt{=?fr 3fz+YxSzMIOcB OYAO @(7aKO=(qqI7t)6lPK=iG%L %"\y9OxA#tmB"jq@۱:9d>~RP:r?BvGt8nS:߯&0}RC (ej8sΜEDJ}U(5 C-5pؒ6kx*J.48%2 ?^! yB-*RW^l]%@ Tp'Gv!Gr\#v]'pZni璲,YSkS7٪ۏ|TN&_U\hؙPS {'QDSo U,-õ9 o"gȥEEtf(u[thD}o>'<V2lUc9n(*IŦk'dհq_>~dRF+͕ƀpFB7x;Z>yOEw1z+9e؏$v8ႼYl|ZLUAê~3K ц ߞVhsdJ,C1A>x4685>;:9'NR){"YӬ"eWݐCOg I~Sژ|A%e“AՃ`Mg$]jb t`T ̛ JD@H:S",RJ/|nG'(NXm-q+b [Nʞm`7)*Sz>K;LfxW tJ;p,aaM X Mb nґp~Բ&p93+wb㔁v %3Y#HCGVj}j`#\ `sH Y2rrBb屸c#zO P~wo/` 1E4q,x+9a|Ri}L4׸ީ,˪Sᐄ.=4@!O^$b6XɯR"k@E9kl_вNΆShۤ$D*9"< b"?WcydhL05 u K\$?ok" r>5{;cpTIBXc@wpb0^KgZA#^9uoL+ʋfe;6XlAZШBB`9h٘|RN98q?`xQȑmT{X-LAĝ%Z)\9}QìKI3Ma+K)9ގNX^U}f)sZ$fAv2l]ȇ %C713Yi/|խި3P&_G=-jg<`2Viy%tEK VcN5:JBg mJmO1 8xLOTr'BeJN|b=#*{c Tw-ڧ./s-aշ"McXe&2ޗ%`f:[0$!\{%|r-3XU_xѪ 9,Jit%쬷]F'.}fOA4%9')HD ч3ae֡ͩ=j#>YVPRC4&mhZ~l3>VeJ'ʋ@ޡQK,KzG&Uw@zɜtW 9Q "`?WX֌QNc{}CC .@} e:8nH LI9 jcUށ rN% ?c;-M;C7ȝo/]#Ƞjǀ)ҽV&zXIv8 iBzL3Hd«;{bLxw11AWG]l !4 r )L眎ln"ua26R^q5 0.sB*jܪJ8ySa?Fki RE02q(N hwMh۷c\_]Qnz_'JЭi IIFؒeTVBDa@zdh!)Y{ lXQ_ I7HFe劏NطU+5EDF+AjLSUP ^T؎s'GT$/1/ }6?#eR,(8|6moU2+MȂ10>8SLY;N G dTeB&BcާD.0WJ{L/z2El&,Rzn9S?3A=d͙VHP~P폰Et8sq&?LΤQз8٥ Sj֕ 噖"SG9WD\!gTŐ 8Z\qlq$Ʉhy?R+F2)Q5CT_pbaT}3jb~&{iنX~*ye O? X/ u|t+x^9ogDbI,4d+Gyr N4* -HNO\YeBʢ&B(7! WܷkQ"z-r`w$@֚'3Gc u"B7qd_y5|b>RK_uo p݇:d/Ft>țBKT/~n6+y#˧C0S!l_b57[]YFS5ɫ ÿ͍C>{#6]vET۲E17ò:CϰUN{*Q0$4wY sn+G,9'%;Zr|Zր{@ *0ǸU%&R`bͺA-zS-FD a _cd)HHNƳѥa8óxSv Gdd_ ?pwT;TV?gHd||"sG,a[nt^EzR.U2nMWNԸ'*x%U\۸E0aiu h\o~_Ph[ 6$=49~O<&>Fxq4Ys]{ۻAκ%E 1[_IsؒA&m ygxV,gB%387xh¥+@[K,jU2{KPK, - "?*… (TVzB;ԏ}ryAB !zT]wQJސwXmgCNŧYxٝӪF=)aBcMuŶ{Cge??/q:PcN .ee۠O|*]s]Th Sv-NPb'BLsRT#;ΰHB qP̻-/ZE܋9&Ј}[05Z <0lXb hNԚIf$U~r>)1V.U)*̺՛[w #!\nأYi(gԚ~&A Rmn3o-x ;DU+bn P x B|\ªplB%W_h%eod%bnE/Ÿm݌=DnK‹ATh.k?l=b%QG*- ?e ƚ)Z"ƘPJ9ÍvidƥjfJ5jW ش+ة{a{gmQsrKE;aMLU.An=#,<;v̯-9䖺/1b[&o$w"ӧd2t6's)rl++ƋOefH:GQ0o/ĬGUCKPdy;Y6rtӻf7AB-]fY )\-PXp3 W)(];kI %'qd{rGX/ڥ=vZkaD)(Q\5$ȋ%?tviCOi$h`>Ϥ@:C(DvWb|nk~_}b<Йwje%V,w^u7|z6sp>$) LY@c*AUknpSJ. `~Tk.HZ:?Ͽϐ%~[_71iT@o6T֣b.5KU!XpVc]Vڔwh xz'‡iP$ʙ>$qG普Bk^ +ȹlf6-%v&VFrpy\kmM5XpRiu^ZHux8= D䒌AN1b\3:VEբ0S:cĐh\ge}(!uyKRAMd_ e! +p5=Kt9x]LjY29WQ&DiuB7X$jJLv4YV. Y@Sh<?9g-1c^+HX' ߃7fmNwIԚRh..:L<(anLC=2>&Ss>/Ʊ-BйTdgZOѕr_coIqrN<:OAjqf!l| .Gۧc. [ qذ ;;[W_ c>` Zi?lHZrwѴ\ҝê¼>?͜)ON5/#gCJN Fuv =MZ{em [UCޮƫ"JA4%D-йtRs[f9#gpme{`s/*8f=dqu !F +)H@ IGDU~kY8.r8vwv[l,܅ڽ&4+pۋmq੨'\| 25Qg7@`IoKWw]):P n(Zw8';Y4z^;}te 8.E,x^}7ptϱ><1K"@_. T/W4u]7H #[ 1M_f3$m򮡤J5l̬%8M' iB͵XE-&9b}CGO``KP(, j8PU6%^z1nU R0 ]^1QtHZkˆr 1CoH!C&5긚ǁXeUU'dT!V'||CH3eh[_WwXD 1 sKWX#Hw&3+99NCWnHDf]9Or i#No/gJ@_P!功 K:ľ:M~ײnGj`Rj]QUuCZϦ % t\{ǺPw\vC)6 Ʋ`d)VF%8ojO\j1 szMS1ȿA3ze,ŤȬtEA33w ߨ+.g hhphgXdBh],]8}CrY;uعʡϔz ːOn$.FFƣG\fUWxwF8lmT Wճb/$c|VѠt+(2n5hk]i.KZou[HJV!2ڠIu6>6P.a,lݣ#2`]yWHpJlm/27|'P%ɜ v15(wx2G~!+// +tn?!K iE@\i.m~_gBjge#trr`AV )I5{9S Ɩ{ +,Qk_ZIm#tVF,چĸ4T*q ׺GA({A-ڶ:JXϝxC4H'Gj E<2D>gۻĆ\K^{.w_U"4a7[oh+Guԙ N(aF5F#n&0e/k{)1Q'-<cy6*Sdov3ʰ۔,oe4&/ނ;ɷuDrO\]频O U vi LB]f҉ց$0yrrpsȦ$tѕnX@$Qx,3k풶Oj43-Ɛ0 e7* 18t|xI𻿐?l= s7@a:LML=ٙCGGIJ,et fg-}Q@pI> hSc0A &5JjYzx AA.}5/ RZ^TþiPfZ"dC]mG^ Xp6D$?fw0寀5PXQꇶtsQFx(̉.` [Bo9yň<]C5REy ~!8]Bp\r3Q6ns#2SPj(oE?6z8$dư .k8Bۆr}twPبEHSW tn面bpҔttƕ.gHgJ:PB-<\?f[1u:n%iƮ%4Hӄ6cu >x0~kejA[=,7Rlj L;<9_'s~(ARV!v0NY` ݭ1Y [>|*@2[O Yoܦ+w㠩J "39u* qT?Z0aY=Da% p>25k77Zˌ3afV-.\mXxߓdE7SԆeasbL'ϭ̋tJuǖSSbjs>ca_/T2BGW{ș{dmVVN2Ǥ198kZ5;m%ΑƐQbf=sD7 F\ϵUB;ڊ)_ň |ug'[HAQ<&KFWA T.lўؖ ` }Ѻ3~қ0[jH[CykLB#)(="QyeVmH#K'D+@l]}\AП V%+~cz[#o? ;9ʢ0)0 E E_q=a7Xv m|)iϑg%ŤJo^'Q/ofв Y;B[eSWw Y[{|CU?'/Fl x7]WtMX(z7x=:9܅#X#\xQGm5S "NJde̘a z Bb2Aa WWyspq\a:H:+VË%m.?٧Km+DdEr`.݇ƒ;]SioMiP87rx1_گ77᷅ yQ-LF-AnJoQKX~{Hc!SZ<3,S o39È }@mg9X|blCH&Ve*9\dzPvkE2 wzkTo eqb f_W転ئ/7{E,5\6$"Afe핦҄F~0^8 $J@5/cq\~-4O37Ђpe58y?_Y)I;馳Wm?lm9˯왴jR<yĵZ\χ?St mdoFFqpy0HN{L2yl yꞄMo3~4Ϋr`n6ey6OXJڶUUb9z+r)bhVm'$(ӣ~F^/↪z uԇqO3{KůF$E^RJ4;zѺ*03ðN(ӄU.C*CR/2't9*^FL? qF nL xKE&7R|s>ፏl)I_ FU:OԞG"|TM=ߝ^2-@ev.04"$ftd1r; HV# 2d#j"x"^>vGѬ˔||XCCpU[Bha#'Y7Vg #J5pL4L30 ZH߷CK-A6n<((F d@eIPp8zLV,¥C2-tx8n_&{Vw~#E[y<"@eVHE E|vӅWX0YĮu[B;ES T6k^炛wqyfH[[vkPS/tu75p:^Xm!D%YFwt,%6yd + Ne:m^\-`Tkߥ @ "s׾KvP_xx:a0GM' g<WonMR4FN]= )&[#\جեL}[0]z*ym kz<:Djaqwq]zVbS"q{=b3>v..w3!5`&3EʾQp C=4ބ6+Dgr,5TД4FBVݢ-nX 1q|Zyr8Gro``u/R+s N[*yͫLoa^8Iy@HޘhRoMKZHZW h-"R>&a!)1ȯ/JXC4a@y^ 2Yˣ>$Ջ~U6z0g_%rlM8*;@k:gv?L+6g0jNs m %Ɲ\(S@߰d%i@]>zBB&YckKݫ|rFPmK{[ ؙ@+ Rx:u`>c&J/C1bc;JF5KFV"HV^k@y׀29^fF W<+Q᪫ aY gwϴ{t7_Al9-lpu{}WT|I5?5#!ڜ"c_ X4uJUPU;hǻ/X>jPX <--P@cuGrIe|lnE:oGP UC݈V.8DHAV| BS07'*w+ 8v~dIjH%~(*;4y, Ĭ>=vNa1V` EuȗAR~L:_g)Ĩ+VOƳVG֧ LEpآ Bt?5I #S/[rúM1bN"Z=ek+QkxWLݷ8{, NJBzYfm8>: z&Bv.Mû_Vʢj;ŒQS;,j8 U{VU TNP /ފ5[x:@9>e}Gjѓ=$1 =i Z@By8)^fsi\[љDT &#H+DrEja`)돦r2fvpsf;L`  Sp O5T!Ʌ-EQf7r})'8"&@U "yk§.ehtY#dlbyYR 8z"I.dGvdIH#x&j2ɮsakM\WI!% ;%$jtm QHHx 70j7*sŅD "f BLyȍ. iOk7ru9 ē#f7ͦL0weF]B} u_17ˏ{=1!ˉ@(.xU2{6}aP*q9ڏĜG>* )w!\vXh|\wĄ}#Zfǻ0YmiY4\Luq9d0!ZpבLYRiJoEK"θ : ZR,h ;iܳgp1mSr<@چ1Jrٓ"_nt%Zr*H/ .y𚢼d3S^8yzNIL.Vs`|INTxom)kE+9YKWn}8EསDpG")C4 g|U>o3ܾ"0 M~OGi0Z*tnoޥ;W(Sl{.+[_d$@ʾ,¬\?rSw BAgyF`{ٛy9Ą0*V\M8idQc4P)G^Kop2F _p_j>t#kn YGBDI<Tz>GyiՓ5;Y@\~x0d.MAG\Ony40l^ADAMנMtߡSgM\ )]F|GPmŸ:*I;CXc<)}Hb(ϫch);yg`8mu_I:Y" umwA*)L乴nz(eš:h!{6WxןU="9UZȴIAd)qfa?4 L -arD O^ 2y 3zX(r_P>F9y0 ~OP;rصiG%,4.܇:MPΠhnGƖ0aGTow uԟ`ѻqEbgt׻|~JSvtG-j3MIUXit6mSr]t![ V'I%my!pאvB }f :X`,d~436TJ9 z]Y J|Z݁^Jct/{V61T]boȼRCǥÀwfw +#bfQD)? F.s#h^\jB_zZЅJUf/{<zzۃ V%Ѡ!"9i.ά)ty^iGJ]||mN>*o ܚ)0\lc En n ' KbFi) I#]H~т*%1Q)pb2"QDl]nu/mj'I}'kVhōVb~2O{'k פ>B:$(lffGRWՓ!:R śC p(u_Dҗ;Xo6;4ΌI_bX>`jI ~cX-  a ofz?PHF0$&GUQ*(ҤK״2hADَ52NЦB2c%A2۹,=J/[N7QD2qVhQ1Ju=>}?:f'pHo 3JƸ("ǃaKg⥫ٙؒ;RTm(}r/nqAwd': 6Oǚ4)nɆnҐ"AōNr(yO9EӼ[.Hou 6tS~J\$Zq(&ԖҭnٽWs*xIE 8 \$m;B$K[<8w7MOMOJ#\Y[ 9iWFr >ӌ)r(, R[29\A; ޟT嵚km@ N`td==}PiF?Df3ʲ:^Sqڷ(p IXUG`Yzbs_s]1j|QPo2FJo(q8|KbZ#!f\3xL=!4l%,ȳ@];vv\@F Ū ֽGKIE~dv 04q[5'cw .bkQt9Iul'dHQ@Yتmy$c, ?Z&O+W 6/o9Gyro ~!wr:]vd=NgnqyZ?,D|ylB.A8IwbS*`<,'*t~Gׇ{و8t"S o2!&0KbT (PWɘwILF4Cjb|:2,J:`_Jf"RޑX">d0P>0Ҙ/=`';rE:bB21۩Gp蘝?rJO3dwF|f_Y!)]j^SJiD|0b?CJ/j h8Hͱ+7Xo@z里fT91vT'_n Dv&I=R,U hFd))5ZT cKp0DD4XA #[jB}:o`*(ȩ/:,Jtbސ5wkԮjTcZjOjlF%8)\-=n" 4 \>RMMARHڥ**/!Ùs)h\,Qھ\<Qӷ7E@k:z=#J7cֶ\j) }K %ַ8\EPZJ9 ̟GD<Ӽlkobk};%d&a/ǜ@gvʤQ/MEO{u6 NBCLˠBc)NBAZjOמ&(h1IB`7XHV]\ڦH([Y #)şOHBdFd@[j)KfXK,rL~Q[WCJ<gIlU̿z u,k훴x`\Gulm Ȍk5^Qj2|ӒjBqJ s0(^H)GȫSψF(C$ 9p&M],*2[шۙD7 svd2l lno$gpr]*>N$s7;>bw `Э;E$o䮭\NcxF=g1L;L461x,v &Vv qd ),Oa# dP, $BW(y/379hƩIpdӫĞE1$9_"TUJ,MUdMWgdR ]qR3 u^~zC7i[grALn|>utڮfKcæ)F3 AoJ˻zow)0eTN읹Sq>)aʼ$t3_|u)GoSX@Ā֒*rZѐ)vlSm69},:J֦1FgR05h敌2G">?T2 p :աazi~ "N߇t'hdv~=wZ$f%hoM⮏RH0o=<"hָOM8Uɀ3{A ^_,(ݍVDA1Y3SM(A>/5eYI,:<8h`Ug[H2;hOti:&ğǬY #NFeXRux~oª1`"Ro6&-H: Qx5'a Z_J% 5?rnsˢh1"xW\Ia} US#qgNK~=yb>NõJ]~),R_2Po0e!'@"}ڴwHK6 J-x+߄X@7طS@j~ueH31nHp}iJ;_#FY|BCNTm,QϿ&%PmH)(ɒyJa!w::GC<ݯK2Y1~4,)8G_Z߲S:NR(e" -6-p[I3F!stx#$2J)L~hIkx/3 sҿ~ɻQDjjSV%7[ <_1NSA3 &a9[q.'HszAo]:E=>"Pjf-Zؗ`.lư"IFUڊ Ȉ4A,0w~ FLf'COoy\IAGy } JuwfQ D0 HQ9,{/{]?i.p 4K!!fK;yBf}rlhMk+oDk[CCQ(33Zf^bJ0@*ֈMS6@ͫ,: $xx%>}WnJW)@дѐfl.n;#<T5cg% %(+^^:7_ W' NdzW Y\z50,WqӹG/ZD{#FҾ8$GD;{O-d I>@TNvO[m\nH f0X xt#O{{%c3{vL#(#;Хu9h4B1Ud=ѝzjVkҦ 䯢0nhH-d '㹎r|!`b!l xBtRfiќMbNQUMw{l "-+x*R><:wTs^Ǡ;77ԗ3jȹom>4 6J.8xcP|x`W2-rF6>5yت%$5avsu`sݓ \Où@OH $;x4AkQڥۼxFt崖d`zlPPS^15!89xAX7Mv<]v(2672oW)$p_\-.DQUp&vx*a"Q@yT<>{>>O(*9-b4وBwMwUy%po:# $_ϭS$&w 6zE|{޼9~[CqN[\g %#&|sB!ܓtDuJ?2#(q# wAWt%,en8^W{QUIB9@=ybN;t0`q:JNf9e kh27PNhKQf 2ڶxsG;ɚs1o?łߋp؍L\%W, oOMZ wVcd 6 $F eC Wpa+fjZч{:#拵תJ:ʋlx9i`BUݫE蓴G\_X8ʩe{A#(_b|32Ld<(56g'kIp]nٮ0<=kx[_|i~֚U8se￉Um'WȾvc'':U:G )j,6[|\YNsd-x*5Mf֣t+ G.Eq^ap̢D 8`~xdNOo^V my2E3mՔeFt^}֒a^"xL>LoD{!xV:'ZRwYò]@SUu>2 KȒw:/*F]<%_og/3"Qa?w⁹l(l.-]X:PkU;@qB!PMQ}vcNDed̥2c.[2+_ZP֠N4`Cz*TDx葩<:kⅣc펃S~1t!tl-^PuQٔ>^-55;Jo]R _޺}v~JrۀzV/lѯ.&5afWEtƳ@2A_{OiV"IEKFH2M=j}ŝ1΅qCG"XQ)|' 8eb실{sfA`؏Ǡ/ڟ  G;ys^-RK''9g?j^l36upԪ# e3,q7Y#3M."2#[sv9/` beT5i&bO/aFۏ M*އQ /e!}N_?Wel>3%Zl81!}3GI Oj⬮aScmZI`)h"{SĄFYL;?gs7ERdJ43:>a߸Gcޚ\v/Ŝ2Ս o"Y'ɑږ=ٜԍ7*+z@t{@*`'V= z+4c"׈:hҕh=@MS dm?Z/${rJ< ¨L&|dmb3F8O]KQΙ4m>~ ~',sv{%y \2#foWɯ$JIwB@1U! 0<^Q\BzҐ\08BC I{-&9R8øg?) \UVmķV Ԅ>&70 5^&>rma1h. %aL5'^a&RT?6@'ؙQ8gNr\?1Sh1*+(ARN ec9DKp3ruW* 8ȑLۛ,X2I5'%&HIT]fKuf_ nPa[^Ŧq||Ď/;=#e֝] P[qx(16:x+sMէMT7*+D8z/R:XbجMtVȤ. ؃B^3sYrK8[\Z5o9~L8|. X((ZTl&MSGKuU-M1G.Xㄻ 5`ε A4O/+)Qo{4̀KP'w R]@u1?0DD`cS;G M̝VMn0殣XC]FF|icLIFcDzͰmx˸|of8yf9lP70c-!cA,g*[2nnbtMȱ0#!$Ye1-Jͥ51lm_#dq6D:z5-NB}nj|j:Q=#*3uhl0q^v ;6+6〓m?UFNv}IN3 `n>I>>ֈ(g<Л `~ZE;"IŶK;CLqOȼK _SP@[xےg{XH@9ߩm5h#rzi T 9fX)LphķvKqnH="~g L"k&OAaYNm$T4TEphXh?V1D>XxkvА"șs',f(̓@M!}D4zzoÒU($! +PwJz{RT-hDH>AgA(0J@QxBxGbC* 5\rz㱆BRSQYtPH 8>/g%t5niѱDq6hEUmPNykA;ƂlίYS6@F S_ÖKq-D\Nf΀oc2D;Љ/ro ̄@ 8BUaz^ZcijXf͙0kGO/-H C?jX@(Pќ5PLa0dp%ǻgaIHmEe:eH;V{#*$!.US^Y{c'Y'IҩzBp3xd~J@Lr@e9~BJйccee~S; Ԉx]rXmłN': nȜOa <,s}?Ԩپ ΢3i5Oi{.9zl?8.NpK;܈*)2깁|^< ۃ,lXw4<8x_'Dc]0փg/$?U=e:4rPGˆ~fŶ-TSX:2t|@I#R"(o׆pۚIt 6 & GxpEF,@Q:r/Drҏp68|Ea9xo`E I.Y[ _ EXƵ-U1bNB~ u=kM0%p*M;Tbڢy37 A^PKʴo˱JPƔ%#2#m):\RΙ)ۜZy+?'eTv g&> PGARXԝmaĔ(3>J*axO@.VAۺC>C6!`"'~isOKekS婔5#ky ~M-|C@1؄ D1F,@Tpt)v)Vm.'𵳘a%m-K8t/bχr=|; 7$y T%kRkF 0.fWm/@cb \裻7%]1f32Դ㤛lj5~^i\Em DA0~nP,Ѿ0~-&b`"(ݝ+q.y)l(/H"J{'RcbB5䟊ϙ7L6|b:ك&;kl4N5N.GI@3*G1cFaӃ,' ʁNOȧ!&$Np9sXN];yE/D4_Eu;/'^_=|A*tMW:_>:&Zekjҹ~IZ0-&-xb lդ( Kpz˟L}<Emb@ O ;oJn5)Btf4, k9s;`#C^vCj\˩es+CVhVˤֈeo_X6yz^ cRpfkw8CsS-yǵ_-vu="S@яW?UJ2WIxk\M1܏$zЭ Cy2bm ceoJS v-[94Niw~jOWB}X9< n iBJ3<5L"z|@1\̒v;yc]HԌANϘpZ1"MmզFS(pFpEf &Ǝg?O{H>.wj,{oO=aWDY,( RqD%U2hWY> p.ZiAhE?ȹVl*2^('># j"]=2F/FFXīlV7Ӭ3GfCGI}le HYŠi .bm6E /A"@q1?cTRX㓆1pbЕd[3Wwf X{5$/+?x3WJH!t y5tF$N N*]ЛmZߚ1W3!{ۜD s+ _29憆lN:M}v\/i6?tΠ=autQ].uw(hf(N3FɽbVޟ75BvJvZnQV@| C{ȺJ2?t&cǐ8'NHjZ bzjIE+| #U>Uk.xx' j㸗տ&&4Ϡg*QXD]qd~] .mL_̷YēU^}ӬU(;6P1b<@iݭpiaRMdӾa]F/8exlmЊZ1(f*d+6ymC汇@ KDƠyKd61W!e5쑀o;+ֆ{T g;))%~VYOlx`} ܞ`<s>F^EsB9 })7fo#c}d& 34o#bN]䱬n1tqQ*i G ~ldw4Z2qsh}ljEImZ|O_,~NZZa<6 y\N\ S.&U!ņnbyXɰR5 ^ Q7/߷-sUg AËkz.a3wo4S0lTU8"/]jmymV7%TXa쌫De'(:~_8G}tsL737>2 fQPhuƒ"t94N~EKn8> <Pr3;ℇowTw쓡g@jhH i;2I6)n1O7c*w5ꫵȂ(Ր^:Ɏ6 sqg0O Y..ʵ)7j[5Lp&;~V<"͎hwB}b ql9_!0HK$3ϣ V{8z^Vz+)%7ABJf*!=RDcuڪV_ 3+=K"iMfqA+@}@kGމկ创m+ǹS! a~gѽD "E~fؖƩ@ҭlΛ;KC2zyW-\UU=P`6Asw"a-{[,XsN'P礬D}ZDtVʒ%vD3zA5"Kl1k() e9A\璕!@ZBLRq9K$UB?%e@d72unJ.JjM-ʝʣ Rل@t72V8{pWZф>K|!P]bAǵ#xv3z~lhT`Dp~5$ܘxvs^[5exOz}fY Cyr&`8SyF(wm` LUT4ev"):K @޷[UU YlĻ{jx&Iwo;a棈i _2Z \5=揪*kOnLo"`NF]rM;`~ *4kb[j+げvпXb 1x㨴l{H 79@F37?j,̶$)7rF;Zi׬~j].sUS𲴙OHxFC&TbZPSnEjvsQK5z32ʙV2itԝ"YX^w/o%x ._Z_,B,e<;/t*'ֹͦ\@_[qUj]FdUp|1ahߡvO.'e`Ed ~^!M~A6Ջ]-VEthFŝM&B?j U xBUz x4;'ss D|P|[Nb$+NDw Q(3꺒o>c'jVB,Mrd%>>)뙑lD}/t%OZ/$-cqN7d a whk#ykgFir*~eyVxS>Ɉ&(;ơQ"}ulusӳ#aGknt}2-`ƫj tGE}7EZ~}I;ׇ;tdDp,Vh{[ʎ~.sfXE,zZ=وƜ>dLL@j {mwNM#ђ |S뾽^$tZWqE9vLӐWNZFT 9@פ>jN_vcwF#0`kguQ쪃}A_zƷ+<31Cߡ|q2%ӻhMwGe^,|sU% bN[PwU*x{?Hqu"m56X5yɘgjjasvFĊA}k>*X4 ˼َVo&Y8w-b0CD)T˦Uhe%]~&2=BG2 Rjlnz9HAzG:҆+Dյ90:DQ$(5l#HFu!L K:3CIBe $Gwy~نu]V(gkԨ>^o:95l곷ݑeѱ$S[4!A1 ,pn~%v8HNs/5)TtT(UmP"iymqo3N%M湚W Xx΂ pUnh#y3 ʖ{ iPQBhQ_L+[0]T>IT]oU ѷr``(]L~K~F*O⷏i NZ8!jSjh1GRa)Z`L7ŝ0}3k5 .\_$^~Cb9 ",MA!HIUI oh< i;*Hi 2|P;r^7 ZeMlk(6w`}g2=5ușoz*#i<Ī]ga%T1^"z!@S=b0BDžTAX{6*Ÿvه \f}{Kr-۳r't(~TJb퉑>e9tΨ0CB0yk{-sjE%T^֟#{TL,i7_KЕuT%ZQ\oX4U+)*aNkgl%RŻy,HMd/,KAGR)2>-hSV3zyQ}dl#AB4uK;ĻQ^0i(:5G6Ry[qZJ[XkaWN8,y-gkbwje-~L#Rݪ2u3!$gck w|v9├ױ sWNN(Z}>'}E@[25 Wd!ؒ,x\c9dޮ-(ku\omk)v_G,I-FQGKr,w;qF⺤^TuuXh qͻ_ފDJUUC'Aaw,#,jl&ڮYs\'2#@QB30Ts~e1v=fP;*SlYԑ5]bapAyVc4D⭄_iSK>^]#nQ__Rl>JB%PxrAEd8#`/II{%ONNZv.`&%C'gBҁ&Х߲ %[*! aPe@%kr#%㾜Z=)SS$$\k>ei;d$GBaN~7B 2ހ$Dg>馥FNn*>_A+ׄ$p<ё)(3u?Uf~8xJ=ukQ68SJR€LtDD8H"_zP$}IvVcdj4[ȩ+0Qt>"D ,&K|!A],_g >~?3Ãk\dФ=ŒBMl֍EUuK%It[`SD*ѷJ1@)kJnb5Ce͞-VoޭO ljζk&0f(@Y8QT}Hswm96ّB*B/EKmm|h P+,>q#z%ܺ%Nsґ6^US|񐻶l |_ݏi c9]}܃*28@g:½:rb׃rAo &V B;+I!} IjˮDW2 P:jw@kZBNj~c) ɦQvBO7Q0HbjI#82xp:g95K(DDYݲ ^ vZzb9D'LvM{>/7.x%A3eyÒ/rZ37>KVkG7!ܐKsQ:Zj@mO;.qUTc9Sg$/GCM- ͸)e]8 cC\G87E}l!l\rՃhSQc9SIpWJꛟ yAf%r5H۰MĊHBexM uag P=N0Ha[ĚCT2U92ZjC?ExbLѸ(>` fQkޑMT_ؒW=zlU!_*GH,╾fsZMBm6}\@\>q.4ɴf"i7@oSBM)&tB0S*0P|qD1H ?H('pfϩN#u L7 #݌#sϕ썽R [{Ĉ!N~jTRG [^9"Mkp srj q }77:H@uU'c!?E\D@N'+} )kc%{8w.JwNGĥqsm8M&#pbA}z ǂ[ A 5CRx/lG+.`uLM/s)cp(i0LjzDײ[[8N6S { q5&cu;.4T}ئۜ-!j S<|ytT#R@?y߷cdk7~V41V?VGlHDŽY^Arv1\0)"$]FP72t?OzYF@y%jTƌfTSK9÷(lgq h⧸.u-yvOkT%Z/^g {ALO׉OhlmdIUv}ec wǁLZY(MEn)Ŧp"hoygb]>3l)sB$Ƴ]70aL MrHl^5[(nEjY)ͦEf?I뭷^;G:T8z! Aڀ2p|;:+:9 1BP4!>yzaT)-JqT,6/I&`v{?V "p}S;iƞ\n S2~ r[V|P)l, )>*2ofE!WBV]F_OFg'%DwF!ꯢnJt2ԣ#uiӄ|DBT&}"dN2`2M4x[H57vNJiM?K^@KR>1 ;N5$]fQ-)FEM㗖:#M +xeJ,F4(~7עژP]n Q]?:%&b Q*3lvQ\DF||= };5Ee:L ދGS|Mc8YlsPxwT)-=nX}m͝}(~~@On8.d΄SNggFRww/#3.DR̕;$||'+nƐԯrZU 4hJ B[B7+l9j(LA 7/=ۖ}^m #{zB$2X nKX& uHH*FuB"SI eT.IGkmvp/5"1r 7h_mfRϚmmUSj |,S:m^a- uޠIqݤD@:vh>Py|X5\zPJ'm=m^=>.b3Rҙu]׽HUaE[ vK:wAVI/[Sp8ߟ-w]?ϨB[3ؙ0 =r ltʂM۪d #pEѩ]؅C0>c`yώvs{w>rC]wjVw/z3|,Tqh3A⾻·YCz]Ih,R=;b9ߢ9P'MofKV?;B,LK hy=Y~幗cV;m]Y/ Ns+WiHF7;۱qf..FuZKf< G,HMJVɷdsio|/;a_1b\f+v(`6q~5XjmBMJp'm}ГTp5R]?ۘ%HfS|A]XIU*Nb3w~ÀQ=R( t+y |ˆTeVG>Azxr\~B5$Y:PhV(R q\YpI@yj|ׯJ'=$~ 4%`4&nR 6ZT?NSYީ9jo9#`'R>I΀Z9T1)CrLdoޮ8^uW1Z&{XV%kw(po6kvH$Y aC ++]E0i Sf#NmwO91 ۴HgcLo!df&ŚTՊ T~ޱ0/S魼"K`}EuV RpJ)<;̺UfgSH! we~%O T>p|yMJrjM 5CB9f1*mIg+b (\X\:oQg )jnfdV+hY:\q:n2[3VS6p`c$(nz)B_}d IBĦbD38h]apCjĵ<'['+2eWa[:-TvoV61W.MZ#bʳx{ s֪fV" (2\YFð ɨ٭ofm:[ujPs3M0DvmLya˅nq #:htoV*g# kf5EVİTZV4iLa/v7e%Of$bÀ354Ķ9"PDZ`Y#jݧ*Ra+zS|c)Z nG0r / ;MMg|i a}vO簁fgaB PqC]CVp]yW3`8?9}5k t=ʍjJ&uJjo>`d<1A)Ua3bhcexm? 챱~(&UW0WT  k|W0N 㛳 D~x % Q;EK+ cڤ{q~m`E$AodgK bPiN+ ( u'Y:*tsPiDHmn0+gPFa%RZv앐C/@o_*~h*.PЏqIO̰\14K?vHP9.3K%̌~:l ux2InQa&O6bRh*2a@ը0hN%g"b)m: B#| 4,o0;-ecY}qa[; q,'̒C]Am /h̭T>#G/k7GXoևYe2TqhQwlTcof#跟XwabO8! m89h\6M3pO 'LdNؚ>: nP꺔ƊIe|z<|zbtg^iɩ. [ Ѐervo.:"8%k#2H0J}~,Ìt!Yk@t?OU66z4oHn6*B.wDz1hm G9 yPFIVQ>vW3c|ʸ8]z(xڸIL40ٸBt'q'Ss6=>=y6eH ƶF-koh]go8`sf,*>gkG7{|ؾxj<5!5JgE5@HN»jo<>"Y9ɝIZ;Gv*Tn8-MwMB(^E8L N'}ܯ5># pOj9l*H:9ޝ}&^"B@\EWH 4EԙqI kjZcSbn~wteek $~`;#v&[ʈL19uk-^q [dxǪ]o՝[pt -\ =f*pGd-sRcYW*WR$[*j]pSVrp'>v!}I-&K'QsN<<׌xI;57E|tTZ?_Vtkmu]`#qPt4n2>>mshO^պD:JLxs@V_1e1qC|wu %&3W>{#&){惺 p{x@KeP?-';2  7t>YTC"q謖yH[ߣpod4%>s/ "!"#R>9eT&Wb-hŐĨ1&Y,[#6x1ȋQPm0z8F((B w!`.Jg#6'ϲck6%I ncY)Uӹ[HGJk[M_j RBv_u2;xFʀzb.9/x.hL};- #cՏQ:<5Zװ#f =$>-X؞B@@Fo_A :9iQ[SFٖ s z sF{3.l&_\XzդZ*lL)w!}"c?Gb5#d[gR&bfw&}հ24%{63tެ%EY7=Ͻs$ƙlnr<ی1k1 w>h=U_ø4nU'[7Жe;Aל1IP鏗Ux{譀FcScEk'׭<E<~5 "αԝst }Si2Cd 4x%#(K%61sQCvǬƗ˧3Sd#{& G@E:B<ޭO'S:& ״Nf@|ACFK9/m,g*zb7̧VqYrȇweɄ"Ѽ \&nLkDi'- YFVmN aQ|Q?Y Z 9mG΅CLzUA IULBRaŔWXqS$;0,6[ҟ)勵gDòUmO(wAi Hѵ_[ {$7)Te77o`N:ȦP40{Cc~fOŞ<+uA ڢ0hFgAB,yfI" r%'g|(sbDCJ_kvLP;I9w"=) '}a*}yU.^6w&nrn929e QV`b֛/4_'oxfE::zD]t#0j I M$Wƀ0,ƛJ?@C  n4_zɍi ߕ(wP <˄UbcGBětp\ 7*j2X3nD2예"|fAmдҳRa[+uk{Ta7aǡgy8fWWL??%M8ޱȺK C\JP>:}i:."hrʨHPmƎJM/q*DMSCOx+dy<]Ni iJ8LO+'Q2CD0MYQ&z$&pX-T"wa wbkZxֿ- 1FS/Ik~ԫ}҄&&W >I .j&ZI:K8Xg}p*e6!-1xt1 ~)o8PZ_ƎhG` :˪ Zā[3u?h良lffT]!v6L7NT9'l5r+BB ;1 AϜ[x8 ‘^Aə~VW =!Bܥ;@q~k2dUHKŒSq pY銀,/['!Ȩ3H@Pψ."-/--#-Ir't4>nYyd${5'֭#05Oֺ$+BXfaԲ9%ǜωrr,Gwb2Mc?K~B,8X#nL+ \ *a1׿)yRŽvdD1E H_GQ#v ˳ըts2{`Od5}~:[5I.X\[V3#B2JM }>[.8py IVAy[.roH9R'4<<1T&)-1Y =.Y}MVd )Z-\C>+ . PI%Ez fK;sxdcCgֱЗ ,x5ݜxa2p\f1!)LÉ]f ʤ:z'֙Ma''O7cmsqEQX,q $(jWunF> \{Lc:ȰPHe3Pnu05l{~$*sP "1NQ9w xZGrw›G ;y8Y%xbv]0Wܱ]rq>a <(j7c 2(Jb4D7|94 tv56y@ \(,P#Fl4X;I%o1Olo(Y&kwnK{:AGE 1It*6VK׸R´"ae= tCCDV ҅Vp>)2h?j,M\$,`rtKHa砡F"He[n#TH(yԢHvj#X_ެG QXe1żC/>;+Iw*:.LVGfwc\W).kX)[[gw F5pd­{FOx2l(=L4%<L#͛<٭|JL3 ڇ,"[wOSb@`\r)lNVeWcY' H#;|˺9ΐߞPa@q}7(^.@ح!7 piGWZq,JGte+i~J~+/ UK?yTDMwB}V}"xDCDAJMV78`˺P_xj׆f 7ӯ[Q$KŬIax ζ*DžJR`Z!5aa@ZL#Qꙥ+0Ǐ%Y /an,: LԐ` .,/ֵCй%ĘAvs1v'J.VXl / 3sH+05?<$!Aaԗm]f)q@L+ܮI?t`12WME+54Y8uV5o\8}+XpŴb$<9j-zCpBp&с0r4pdKn{{ Ki7@_eЕmzGyh`O *H"SC{u_@],̹ |#_ QwMl9ӄU˅_ofتtYz2GR=|~#|^A#OM6GW2D*"bc=G8V EPmyT|8K;ہ( f8m>7P'2 K^o-<ssj<\?'޵@pR-qOJJӻG{ 1l׸mEc/C%9R:ڻ:fIqsP (CפHz=)V,"Ll bof?PU5h_׫.pByP.%42f:8:ёpWl,1vizH~.Ek1vi^Y&ʀ{!)-Bu6v g0& /Ɗ=!_] c q;)vaztzvd (40wL4Va%H]Ѭ8[zi)M-gW: M̒C/G2{m DFb=Z,o^=Qc 1 >׷I3/ Rf \x խB*7a6ssuؔLi#ESɧ~U-zM9~Pkbo) hS[F6hxu ?Q=\ ZH5Lb]=ɭ3RZ:L fB*3/ܲӃX\:pa*㣠.Y%|͜^p}Zr )/~hl`2~jàrȞҩAHU@!cY& f!dOA:#k؄%.f0P*ɶFhUQ/}o|2*$i/pHZf.Y~ *tjrlI׍/e>{9CB``MZ([($74m]#(}yߒ s6g+=: O "Ep; % *-3$]ӕVX)x +靣/͏4RuQ<_Ij{R0u}kg]oj^b^RdȤ( Z!`Jf, 7|3~i Z᾽~ "1r"Ȯ8sѹHΖQh㩽& Z˯Z]v. F]nXMAJ)-2E9 |Ch5Ф=Ndti8^0wtVK0't2y_]ک1EdbM6W'o-P4HYst'u̔oBz-~1s2QsG _%-}bn.pW pF-UA׈Sx>1EC E,t_g~2+귅VƒugqF͎2j Tm-פp%O>р J!|ָk?+Pڮi4t!/[#SbC{a%`5u6=$'WrPxA}9 ׮E О>޾s-3yޤ#N"5|!k-OHTēP&# /^"IB] ;fO.hylst|%.ێ" |B?^-Ǥ*1a؈0tMl G^HJ饞?34!{.L`)? $Xd>+|+͘%us^0<}8q{Z*V}{9<ЦҢp__O$O3(@ڇ o*X࿇7gQll?)&Tq:)c֜ΙX=ОvڑS0״pӏ?0J5"9'ޛ?_zxPhQC٤ȟs'@:-Zpjv8Pi ^ x"STkh,aZۘ8+.5`'5&ZcKϧH1Ǖ͓fHjVqF8֋ߴ-IIVS)"t3ۣ= /B@CóW):onfm.\r#I/l{Y H,PϏQ(`G3Ne)?])$.DuA.\wIseׄ6Ӹޟ WE|)KD1ʺRU(;G5?xBEC^HMsŐ-d /=R1Bzg.~#69MI‹d( ̤ "+VIWT<CלJDzљBFrp \Ѹ 1/J+V%=\q hJvWQ(h))"< n9x ut+{o_B{=pz25zz K0H^dF1/9:ʆBi_LWJft,ڸldUfh)j>v"- qcz&D kV5 ZvPLs 6DIߝ/ˮ#] |>CJ`p#Jv6 ߄ThD}+Vs7o-ԻZR/eIBbx 22e 2ʣT􌦆|uXÛlO;}<Q'|(0mVĒ7,sٜ[wddY8+cGgT>jBxt262D5пµ m}(J.G˗λ AA6YNTPmVL< u|z}b9Aε"1Ui?<;u\DƻW;OJ˱rѓ%)Ԉyb͍.͉rG5 6<Ҫ]:nusjtUg 'ҏy!\͉#z)S<{al%D_i}p@:gaZId0=`Ws@$Ks& K9ַY]U},Ry"NܰkLe6ء`t*х qigẅ́$P2d F>fB1A&j\+:Ã>n M$ݺmRVS@(е_LѕLᚷ ywXRbӗA$h8gƩ[ ڀl ۶(>q(/f cDvs^ Ϋ3?75&t\ r,D1NSՏ<wCb7y-ތkJA@eKe,'3*H^3D6LD6k V"h(Ls~H /IJQt񪚼cYʚǎ@9fL~jUv}h]DOgh,X DOB+\K~TCePn B_;45%,0Gx`LvG{#Lv&0^31w*ˀQD:Q %q #qvFr_A~0Ș"զ-%OKFYb77J>-6}{'s}y]30N-QȂISA֬[M+l1"{56jV&@qCDeS.Џ_ʯVL$CQVt'8<{iC=pj77Q6`1 f $~, rh!A9@в,GLg7!aox'QVtzJNƆy>%dk5 GM|I{ 0 &?zҹ%v>n8r(6xcFEtquALIXY"*{ dCUir?y.H"J) jU0)V[udc%8-Yϗ]T>7.{Y[T_ _ƻ^RVЭի4<^f>al;dUIZCR_y[Q lI3H.u-Dx%8@tI)0O8#"r& $*:(eLv>KY]{ylOu5мcߡ^ 8u~";> ?pa~s0ԧXT!`4 y`(ceKVǣ4PCw>޺]eE<7o8K򠳚ѴyG-qHTJu)4E H:#QjlDPYb2 s[1X`/0@KMsvEzg`}G@dv(CuFAZAqnbū5 fwl8ı'w 绍"J!{bu,S4QC{WmFp^`u3M]Ȉqu_N)ގ >1vAMi,t'P,S#c~-:se-\"+P!7XB;(Th;k_Ã4fUUg|'PE <dz}忦NΦ{RO K<͔YF*cW8i7vvS4?O `!n0'&_-;hHqVmtȭI|ǁ(`AZv]x5y҃=H\*#Ѻ C8KOV$'aq7]IX2?ņaxq^iL@PV b<PzXUl Qbr,鬰%]⠝ X NZ|hO]Ңg ƶ,V& RbA(þ&80{2)]"CB 8ygV Mm=Y>pۄ 6B6p#Bv-=y"iro{ُ'K) 9՛x8X}ˤד<oe4{r^ÅF88 eDgI?Hc~2&ڕԞu&fmU[P *&G +VφЌ'QV3)ga6euұGl>'q\2h.QD+n~݁p4Y0@t B=M0~ķ{Jd܋ tΡ#/ +~s %ųs0|w;uom;N"\1pu+%U\Xbd41dH%?v> APuyNC^g$S- bniz)0|f(!M/1L6b@'~an"Dq&wd j<FBo&KE kN+t˝g p;p[(_EN1&X_=ھD^98BG3e,jenJH3邀 blAQe6=]?dSZ PԤVv2#0!.ZIGwqt 6h.n|̫e37[?R) [_dUͷ<]ݾK#J"]j(pD&,Cq}~}{mQȺEV=(p,^r+ogEЀ:Xն*L9lX<9t}9Ǥ9Oxa Wjp)lU*+%˼#Դ,GI[Lx>Ýa_rPo+roG:epX1#<7bqOoS~E=_rsCh |K缏bPK腚pcSX[#hF=xW;'2B.9? NF Y+DAB2u9#UnұVA@gֶde:#6OѮf|{JRwwp3 D>{1.*p8  1D:KR ~"LRi2`&0̫%5UNEDIk@1 \Yrvl`nY#|I^{l`S #g`2 %$G2+k#}T;UO)l8[ҫ]桚Mr/o`O9i[|cUl TΧY#-^Pls!ΨoͲ^>r B6v]zzHZJ4(۬$_%Y c2L 1i{P&_M1F֊vŘ+M)'޿Tќ⦙'y&%e$4ŏJmڣt˞>3~cvKKby\!b{5ҀPB5n|\Wn&5@ #B!-L"B6gwᦵ_67AY}qF?AQXό, ޵(/C{b~u.NFأPS~1iK(j\=dFn 9#1q1w q"X*j08BG{[d5}P)K'Vr^VFk9*JKZa"0(h=i\{'( YE+WK{MO}+.b=Ia@Tzw~X3u0u 5=91OJV?'5˙*,yŷG:Z0u$ 1Ϡ>nHo(e墪5(_niA0+ÞmdeYR%\Ű6;1vbn5WA*xW&B 9E!5o;_ [pЬ`{1k'&(?4>sl鐂45 ߷+="8d̵,PO) 9Ju"ZH L#k"=i\4~O \E牝NwܐNR̃u ,Stu|&Ѭ!'U}[V"24WU0E@`jq+X >SU@SEL Z+`ʣY _O['/H> (NǘVCL]Iޫ!SyƖTЗ״I|d9@F"~Ŝl s[c%m5}{ر^\&[&ƪ~W[̟_%q-Rn_bS\:zC 6`TƁ"K wLit>BCa`0m+y u~[9H,kr0ե_?:IWĆKJID.;u;5ql:eޱ@9k)*tbPWRO&'q+tr[`Q%n#)i:&$.{pe#qRoO ;})yrlf_p)YxEuhTrti5xɶR 6[WDl1&]{+H*B 7>bfBJS C:ՖPOE/h|o4{L='ti#n+ع4gk/5 B-2s, NEc3m^\惚rJ?:tTG2L\sb}0/rWouR1lWacxW&2d AL=kLZiNK5;^f;4:{ u<.IY6rs~AJ#Ur˟yKyFFRfZ=C}Y?X8 Qɣ.H ue(5)=Cg=|x`?^H'՗5ExgH r߭X+Q܂hLobF3QZ3 YB;3b6[vI%*o^G^D0IW>L w^fеI;wV,ț$K/㻫;I 5ѾOą\ܖM,0жuWZoїlUM 2o*$~eAޛgjuN&KtD )9Z$-A){~Q}7 = {H )pKs M cyw[HL.2ats8keH~],D|>~ڲD~Nq]XVb^2fwU8#ʈi[/(Z4"z)cDBakŢaOJʳ=*er;-AH΢3it\_T#I?.vibd/L@@(:&T6͂;t"}kmi\·9 CE.e {UT cN9S6Σ P: g'l 14:88u(HA"/MZRr8v= g ]㷢16V$LK6 Ui#c* _{o 枴-)1כJs2Tr*rg jw4y#[x-]1KW:D_EGMy604lK@L|7v􍨱t7{Q d5X3`:%JGj"~ r( 2\ F$iB 3$;J'O֣WU{{q;UW'r'ĕ,Y=S/" ;+}Mt _a83c8o-s=,E Q:ga5҃>%+Gϔ oִ+sa3"rR'8%l RXr Vwy9ښ6c3_7(TP)A-zGy?#S0=縞iM< | L CRj򘖕X=9!*J4NE~KHNqO7 Pj]0ĈQG){Z=_Ot pUW7_D٪UxAn:67-g-{J!ʂtbud+㑲SX|c ,al$ĵa Ff _C#TnOd0e Xh2tF̉Q`+18Tժ$T9zk7Z /m8٩ւ_^8ddž +q:ջ 6a^WJ.xqhil,N~zAu8S@54r7{ eX&m~XW!@,U޺8b@K|czyٱ$t:cL[B Y<޼ڢnUc(xSC.Kf>Gzk 3$C~ aDSr:Znԟn30 kV}ӊE VKk:=#t9VJ3Z e:+ &ӏk(VGQxܪWjϲ0HIOk*Ɋr29"2fo 68S놞FZ}18%Z`EL$! ^T[nf~8)X Zj>l42޻׷Q D}=^[orTa(K0VMKC ,S|y7%w#O5n<^Tx$}6,G и]<* :ԀnE 2iPx[J.L La SD4LMWw+&%/Y `ͼǕi·yUY&eؑ('>߾v_G,u!Pz*B#0Kh-x'YW]U$+F6kR"І[LjwCΏHW>"ns”VB;K(MFIK/ShDm5<Ŷk NM>o%LP*~^9>Wǖ5 t{.:AbTW?>Hn|brMt Wʼ kJe Q&8\t*`yE&&xA>0w2}G1Ei+/[}OtB)3hqB4qNz;RLSقNHGwMz*d`?GZhsŽlсIK;o-TD^_p~Odg{7T^ 5I>w2uN^t^bU[ƙ"׶7&%B"G)<:)5 qT``7;%㔢EHL%A"G W/gct串 @NQd}UL[[lL-MQAHrS>f6e؁aDh3YΔ4{5jMhIb߇Fӽpy! ɀUa*U MZ_(Gn"fKHnт*W'žbRޠbP%j_[pm4M퍟-ܗꖮiͧj1\wő;O1qڮ'SKjp-C9E2`A \Oo뽼‘n袗l ._ {,f}3\"wDiLi™Qw4,$vП97#F6~lg|Y shhs8ځEOhւ|| ("~nTE>VtGϒBYKV(QK $yW(Jw~vi_;ҙpX`A\L?ѵp+ZE'GՐo*U U +?lkZT]zR_`qXԧ#E214z"Ͷ+lVaEƫJlG|X }Jϕ%VugVU¦/]Jr]H@ʬdےzR6>SϹG=i}I/IcUOZ5NMPtaj˟W/,-/8;֯IO{||~Z*_V0tNgS7]YplW&35'/&-IFJk\#ʞXWPQ ꟃwpTg٘ +ڠ(\bݛt{BL[|[JPPCL= rIVO𻃣K-68tV^m E\o-w0{LB "l֣^ ?JG0b$mtD$ь._;CE D8z8w$u?qnv@|p? I!mMh&9JAGY78^ vQH+~ /6yR㗚ĕGڰE6P%A _%sҋafـqW,eJ)WLabbW@P :[ tlhnTR 2)8Vuf* 1]0 UA硺kAhsʞ/hp<(N句Ѐ#JչE`߷*Rm^Dm?<{4hb k[;pd=tڶ}6*.?}K뵶 ?Gz5$Mv#/>iv526o2:S@iҮ % 5}ܞ"` ߨoȅk, ZB($#OC\OX_1C~'z;XƧ_iֻ\jBU/|oAe:KE{H fG}1N&[oAԺ( \n>4yD1@ 7ϮHHp5Fь0tEݠF/پ}`h5Rަ-!qɐxeR:k )a">+_k&##jfNqk5-!2DGǁ_z鬽Q Z8Nvנ&b UĎvX~La3qܲKZYwv2 Ҹ̆m`#l%X\sξ?0}d`Gf%߾j>Ko 9WGBՒᮎёv72}3n7c}?'qYnѨ䛥pC}gfJzXiDQՉ0cEO,BtA bci^%_ZN?eXylx+hHAz*/ TP`1>Sxnl.뾞ɿ?;.%}2yXBEֿXC>!";fu+Y^KťX@"e26QZ! JæhyQQUp;935V@TXt$2gz #S~Zj-$j<@տˢyPoԽAM>mLY/x/Yc"K)_ՍNQH5 yixޜ5CyQn` YHPNW8wf[^ΓK޷AX'"5!lh0 ?N5y)1Cl0SXado30t7Y`;%cW4=lR@w!7ߋv9AׇNcmW@@GYh#)݇9(Jz&k $>F0Mv| l`t^)U5TEױA+nbǒFZ:`LYs|խth /?Ҋ;b'u]2R?% ;B^@ ޹Qi`S3s/t94#! F]%> DMi@{ɦ6~ˍ3,Iq8Su9I85ay7)|ha^3:׋̽8 ]9Shs1;߾9A7Y?*hGl92JP: w$3u{gĺf"yFns|r */A_KA>ZnH{[dQvT!O| 2w웠sJ/J&ȹư?I$FB;9\^ʣ~6x! zڷ,qT[;Ucq~ippm36Lbĥ Sz7Ls(Mwhw/$Z Kˣ$gx!qdƸ3zm6VtzSݝ(bK;y=uCELjå^K_EiZ0SpL1] 4}EˢX؛v*3G QJ#K2rWryB{ȀNMZñXz8j}i}{` U3@eʚqvr/7~8ؚB]>l7OK ۗ!+trֲGi:.=tљbd0Gy|7\UkQ$쾻$ O1,j=;-TͽJ [yr:[YcRo+UIs#^+j"{LhzEշ?IrqۊM<1m>7)JcJ, h -=nL~r. # x3e}6Y} ¬٬Y%?FA㨻5O?ԓn|Ke]Bos-: 2|/ :"I~Ho5WlEI@۳QDj/#? | ?FanQ~䖙PCS^lQpQ7; )fHFzdoߐ0|1wՅ"m{c;%b͑ަK@ 3o{oxrNsh(hRS#zf``; ! \) }/얋0-0ے"-bxJWo@Mr)G8ӞVW+60K.hq< ΉxFզq6- %BGX/Wesa Dr;ὦW>0/hc`&?K鬀\MrgrGX突NYh}wBxi@ b^BEyΝ[uF!1ʥž,CbeׄK&G@PF<=&:.0m69v*uYTAHu檊2&uwTfC.:ĨƊS wƒ>NQԨ8ifGN PĖTČ7g^H}򛑄]8%fki'\v0d T5*; qe* G m!>±χc{K6KOG׏B)6b'֙:Цa#W$Gs,-.L<@Ea3cC.1Ɯs VNMGݎI?R'BMa'btTj[5ϭ^t;+ ~:$!Qe&rM=U7pMT H%9֥V=O4oyf-_<$_9WW R9B+#yŋzhq4GfTrTƯ+0{,2I7YOXgI )o3~7n5d\PL3sVP>rc-( 6/0+邗?)Te޺D; `4|=dB WNdt8VgpgzY7MT2eM ]K]O/'D5o#]rL"k8BFIۤ*'%.?;%\eaxvmρ'֥A+(8RISUH<q7Y|38\h$JLh\<{ps9 pybmֈvA~`k:]7|R]V@CHhS#pE NU9QŻK06&u#JZ'탲9uShh:3S^KcW+WXZ\ Hhy]E֜ƕϼ~^59=/{he&3n6:Q:Vb+|fhv/͐o|A9Ù>/Ю/6QV@oB6 |űVu[Tg/p9> ( _w&R sR7˅P[ve#4 #W>zF 8hM|H*#. ZEcIOO{ɨbVo~UyHœ$G`8;x1mэUgo F}d89:9c*aTV$Fg1( TA4qtV~IhuuBtg?GU ])ƥCbB (|A85bBe^ }C"\/U)=sOHrsMf:}Z0=mWּKս>Z+B:6l^]K >"v[v6>zK` (t˝Rj^C&vP[89"i+F;; xI42q1_ː,ǻdB%/EdVt0Hϼy6pm{m-AZ޳,sK$E7I̔0e|_4b8| я!B'LUF7:P2܊|H.aBZ?#B*vE;ЅM',37m+MFM:#Ջ͖PͷR"IE(/Gp_"eg s~ed!%@L}u1Qx~] [8F]Qº6#=}@ӕaØ9cf%^G%H;3N{JF[ }4Tα#7s%- XL(ޱrv9tᆚoB  䧤jIƒ\k^c4FesVtMUT,$Ϡyww/W(XsfqPZ#(2PB7=_':yD"td5:_O.,T"3FWgi:'0k^,q`6zrsWĜSn^Heв/ngO:7Wnj74,~(wx"öp^DKŸ0v9#KK [W%佶.x9F#8nrشx &۳*g3)PSM#q~C"bt]c}]|uOC7@5xJRaު;Ûcw:s#}P9HUHU)h(:[p_CP-F9 9!] QTbWv+@b'g?]Z%i9AA'3n:ڞ?Mf凝~HG>^͸<+s[خ=aÞIv"G2ð7qi7;MtQI^,Cd' i}'@ٹǢtGC k5kSqSƊȉ\#:X}Ɣx!`f@1>4y'JafpXtD[ͭ@2S3Cv,+x*`Bie{3-&X~t+]Ǭ+UU&eUa׾,|)QmKÄ'E\'$Š;˼!Wp7A]rqQYuʹ&lQ/z] a)o5^MB3:m,:y!)¶k- 5HK\6 >0G&y7&`XWF՗J;10R7epw5<;x|'5S'!،jGj;z;pI?$bɴ.} *&Kqa6"A.p8 ۦLQ4B:l0`~͌#w8߱hRvNG-?ZDlos6'VEyrzZņ[JMC@!3 1ڙ7QMxQULP5&lK͚GVd\Md1+NP ڐ$Àv=ׅ{EMj+h\2NE@:j,}]W{gRy/I ^V-g9 <(%bN0W ݡOi&Hu< D RT*u 215Hݫjq܏r,.K@o7f;XCtA>[8BfIz~>|/csW\<Ol4}_Q^bYrĬ|kv0&)I;9; /'c%/ kJk%`Pzȼcj%u!5f^8MA o! ą2=l&2>ЈJZCX*+t.}5eҕ&1B!y$x%خġ:h.Bh( Ƶe~6#J>" ,U Ealb6ea+f}mWP_"Kt;>1)@j[ "`6o5Ju LQ,JU0=fX4cpVb,$}S-D'¿ܴx!]bLoW*UHS@yF]~YOG™q8iqYln&"'a:%:)Weym3ci0nY#3PypϤ-"bX9 ?i/9}[A@8!K%^3>VX%Qγa6J46'pL|Z =ht J yZHs3Va5#Ǐ_KgF }q_aS0{`4\Oc{^ІLΦ5l˒BY`T=h{2\ ͛qBomC搴&pJҭk#f 9BE?@%)uu|QԗeWܶo',oƯVOZ[klbNP)q*O1z9YM.GK|v.HQAI/h6v@Q*{te-9|!^@{5~)sYDj4k'gK6Nʜ V}?f͍,;4:ҡ73K}MP H*nkT?a ;px{;&)gVlOB 9[7N}4PZ;$Z= C*|r!p2z700 V7*LZ{J_??f֑&:ծпFBC"+C+ft3eq0a)ᗞAQfeb^Dӟc>yt:BzeD`q_t~w.ɔe@u>Y{ @t`%S@HWOÏ4I(IۙU]h%( RTZ+QS-&w!N)QӤݑZmh$~,h]oXz=`-\dml%W\,obkaI $ ڄ/I1-?xIڴףb+Js{̊i>| !1qBs sd?@2ŖZe~oslj<,16/YxdƦ݆q6e&̠4Vȕw+k/,P;9P߯Fɹ!6cJ]LSsh

EݧuBI}}:^d%,J >9D=_nkM@Oj/׆U]\)K5l[zًPXsL!{hpFδB]oB@bC9H,`U?\WA蜨biŸxV雊qY73w려,xAS~;\c siqՋeb['h1gI[Jz3wP<Z0ZIŀP2W3-ea2|5-v+M7&N"u y캯E!**FHDt;%J!~}NuLiZKB \'!!di4hoǰ^o0s\wۘsۢ;E(SÔpvdžlh*oh)J`/N4mudҦHEl ~Oq r1>* NBC6鹞zZficNDcPmO CՒJlWe?p 3Ic9ct:co~2Bֲ~ xLv;iWαjC)&QAC7Ӫ'Z~IRzRQL6%d*LS oJŖ.z?uUǽ -5bHvH:Ks?fm[jYBG ܤN;7stE;nu̝x[Vm NNHlI,X#uIsO\]0oZu[Kfᢺ(1شBZrf$*k=rjf+,JҳOk)?"*$+%!< ؗנWn^f= ZaGv)Oi4VIM?ۑPf͢.zv/$5MNatg:(Eޅ!)uv9'+R̠ + fwApgOH,4Qx0H3D ǻޜ!z8|-a6rS0n(D -ù޶򺰘xˍ\q#^TᮈB5.Ϧdڙ].Ym 1DbXB~f9V1"G8-x@W0^\D[x~Z8XG{e^9JCbp:okgF1&7qWp'o4M`D}+8z MDu"쿪s\)y_m=7Wa.3Di m]ւ($ ܘL }Β߿[y; ^5k9H; ! `L \5m.Jc0Nq.l \e=;-+6À~oB H$t0^jwY( %\9ޱ_ +sp8k u}Z@''9t9S w_#h;Ɉۼ'Tou'vf$u@ي'Pva1]R hfY= X5$gF%x$z2q%}ӣ%RBaEI>+9LXWr%;ʅGvMιR\er8`]CDU>fqt"2lǧb{=r:H"j,B [? x pI%`Wyġ>^+T{9pY$)a0)n}mv]h9:ȩ5w(с & F%Qtgˇ4m?Gyy n) N'JA+ҭN,ON+;g@ܫ[aǭbpcE57?;XQhwbzW5ˮGJS8D7Xu,NG0XzZ~ $!7BNZv<s >'s:XW9OGȟiַu]r/m(;=.|8IA2S]z8)ۻa7e*DQʝ̆*XOޯk| M\ Pݬ]?!&/QP[\x+ L$J F+ e.'_?XkUG_}&/wgolDJ{XWgp 3XEU.bXX-wpbNu6 * g ж=%>'_yKSM6Z!W+ޢj OmU5dnՃ&zImg>5n%+Oy zmEwb(T+a d *4lo ^xE2=&Ωa ]z=P[N-:9տG&D @\vzZ=f?0@Dؔrr˖HTUMj)' VVe?й Ht:GjĚ%,Hp|p}ߝ 13ogud:n&a \<Љ[( !;_x[:lL%͸ƇS/UpZKbN6cS'Ȣ}Y0G5^v&z33+2b.+bUWO(-珬L˂o$J^L/;dxz8VN{x-̩oM02+\C ZA1Ʋ@E2s#_uNcFfʢʤaVnXg/!4s}0!?!}38܆gkgr3Q 4-A2g]v6IVM3/_}zDKd*./ by`K7sƨhkqU19LO:s~%_ыp@- w٧].^@qHdw5Zo/nwLU+# [{j;z<SNߧ|MA8㫷{JEAo^<)ba*Kk-|ó)Vq42롦^g?䇙TkKbl IWm?)\6..Mv 6|DA[^!!бxu?AW;ԉ0 Ae QoccDoXyJ< qT⨉ݣ.>QΊy`Z'jj5rvIT^`71c_; pja[lj3n.k5ub|Ҁ QeYId-Pmu]^8b>uʼn7_R竒YIWAvj08=o[c9(_N W1~t&? VϙhAx ʽTnw* ܴp *=W n&n8̟`n=DrXXrQdu8͚%R[SS?uj'Lԓ/ᲐWNϭ/]r3v W,g⤃r*5tPfS׻gpdIO,'7MBmVwp ݽ5?Q.H9R(n+Y+றԙ8Zͨ JPm5KPV^Ú`0;gۙV TBT3hq(~PK Xpy1V\]QJ˽|s'! fC'0LKR1M(Nj90;Rg&~ OCG<}c.I9CQIUP;[dfB`FVs4$VH-Zߐ> _d'pMTՈAcOvq{z`2ׄj&$&EgZdA/ALoXѹE)S#ʖR<`xWI˒8ddx*!٫|v΍?ѼE5aj6+9'I-Q0)M)./=~1Lt^j,g,h@i ;9E/;V-hȺ8W. M0s)H\^ssͤ^m;tkޠ[xL~U!Vz~fkH_?*j"C,ʑz TKEcCJz!ޕ80%?A?duRRocsv) };˂* PU <;//;Aø3~!C^LWE暺AYgBe B{YTsK^^-$Bmiuǿs O|@S`]S=jXo* GV'odL@Mvq%&|(Ixm&&Ei2ȓh IOr œ[():tOUtAO^ڮrwrrMe%ɨģ2rц@.!d4%i"#z0i@C4+Z$Ɗ/P?rॗh)E3PE.szqj޽o% HoPZ2*/ËmԠF9E)$eق7=o[-!;|Z:"[c _{b+Ep޸({Y6+fu/K,!'=3㤓b-HvT!&g6=nZ/+s pu \-!4o܈uV{#)Œ`rX10^u ioU^u( >M)] Bj ,>j!/qEyڄݧGVsQzgۢm<Z Nhw+P0-8={WZa,߲)9[_Z=w=hSԸp 2T@?xS0gʚ@>@<^ج T~.p* Aj@o8=h{74i R1w ^%t.A0 4Lū(lmX|Z!FVRU tHa)F[,{֡I וCFqPfyPUHux%n6H_zJKJ@LoGĈ=ǧsHVnWSM5}x4XxD KxBV?:c#I/ ID˝ xnJV3aS@%~dZ !b9 Ӷ H+?{fC\gE"8l<>`ȑW9Z |[Ʊh %1) Ǿ/CT~|T.8*ݐk[:RAh-eٲf̛ή!+2X鶎cw>}]3ٖb>dO.餟T$,bhE/M|r4i߄$sfVo3Xn Sp=g(uǷ \NRm%.W(WPx~JY>u7|5m 9iZXx2 ),i!(~w|o[D c Ũ $rWEg'a~O֡r]T#$ tۯE x;17-YcUtێUH^`E"S5] BԉS&!(-ao%yNf۠c/cLѮs $(RόŹ[efGYr(R_>ʶI5DEZm/JԌIFʦZ )ghXBޱ~P _|Gy ͝ޚvW[9:ru-0n Ugf2壡 c@pL*~2aXI\;~_1.تȅ;gInNf1MLк9)߉BnHN_ z>JAۻ8lc- $FZWɡ<KqaŒL1/#L˿̐Sz8_JOxRN (ڤ A&8)ڐiz+Q_K:Bڥ7AM!c~:"*x!Dq=  -+EL CBB;s{4}]ȓ8g/ATcP);#L댍dbmc^6,m?aߪc3 -T\|_Ko[nOZ]>Bfӥ@ӛFNlxcM6eqqx;е^}2؂9}.Plۄ#Ȉ+|ߨnP|$gyۯE,N P4 bfS ʽbb%hJK^I!=/Rm_ b h&)z7ND:9<)f4AACh/fZ$ ?gb6Q_j5 :!i?s܇F(`Ku!'idiaT6Y(\8|NzLnr605HMyE9℅5!ItC BpޑX L$nf:r5iTSW/L?PiUe;AL]<[+pIֳ؂{d}2P(56_bw}(2ty:!UqynDg|/&ܘh0cd! .&<%vȁF`DcH yٚD"/mMIpǔxmHb:HCꒈ>׋2h$ Z?' /4yD} ɱ[<꘥Q8m\xPuB#ui*m3' iEFmQh<0CdlN!1v֤m`s?cFRl PU5鲾4SL.D{K˸EYTQeBGuC)?.PBi d~vD,9C:&;1/?A_;d8^kαe*xXj?G)|ټZE3Of`W_0tlNDc>fS|)ҳ8 Wy'5qMC͢yM)!-6t d>Wi0+H_xbAS-?[eAЄFHPDƯne3vb8S;#㑵vKimI ֳvg^_AP'įe-0`ePMb Wd]Dލ/1d*37~;X^?h493[պXRPXsPc?b;+wy;>+زGW٦p ۽эc*v·~r`.,ϔ\K;OqoFÓnw詌)8hHN,xzwqgG3zhj)%_T$v{&],|jE,=CAИ)OBS2ZK $Yx4s.NfZez_Ai_C={`oV=T{mp~fZnnhun7ieDzѫ<)]t`vniX4׃Zz~P-W N (; $~~Q}tK~g(>bYY T%Z2Ϧ$V"dFjqm/AI KT4ipD6_-gLszvs֋qkx8GT!]wP^Dbo)w)ɥ k3"j ®hÞ 丆 -/tD\0Zlq0ʓ=/a{7Td^ 1T!mA|1(q{v b!/# } a'wO@)DK ~ .@wCX%Rl׿M~SS5]4q;@=B(nBOH8YIC(""c0ޒ/QkZ 5}f9E2⊾%E%9o;*<1Lu?!?ƾ2MS{4?C-FO NHTeW۞ٗdL ԛUڥׅc{[A<}4b|"trAN pVWNz ~Onϔ` &uP#M}IW>h: )NYq71k$[Nd+dTCTDcN[,CUPv[O]^pmuܰYP'qd_Ǩ>^͊NCUԍ4Ҳ8>)r΁_}'󲞁TuۜtmyR>OU댺 ]LDNIq opNQPE~KsYS(Q-黟 ]KE䌣tԉld4ivcWij"M>|w.Hӈ7I23g \A:q Sf6\ac`{+8h:1S}FIoFxMN_礗#'DWQ>7!uvL7%B@ed%woZR4˷6⡇64skj0􇾶 ;jOkEhIj(t᝟ǍKxi1iףW@n8" oгAz$0`j?f[Zl\/ Xbzz 7llEĜBe؂Fۅ, /:L%\Q cLaX F]#2 }3]5(Xd ~X|ro? smhťD'U2}@Njr–!A9i@a>c _ƓR~5HU]~fZ+JHuh^^oDvZFMaRD MoHiqx D͔=?삢6N,bøkf|3}+<ƨ[ =Zb5 y *jч!#:Gj厀Ej#C$dFK{/x#h*0HT]w`56t gmFH$!,:+м*'j&N o,¿v`ʇU 恵f>jkxo[8.=FC :{ W1A|f~\҇_O뜙P?m]FÍc,eBWfPDFrciu[^q5p/>?b}~bXEk<61,U,:ͧ1y gI#y<+ƕΞAXҫh l$2ZD}0(Z8it:_W@R[XU_A\8e`Pv-R{cO^]/y!Qd䎂:Z(t7Uj:aUH&~샼Hl/°8Є.uޭEeGos˰MXn('*׃q";צ ?9]枋P)ÒL*<͡m 蝿ۿ(b|0]SR m-v03b$ezpZRa!,Ȇ$'8u WC2}#d MT4C<"=/aڔޟq5ʲ UpJzsv-7yp!`et3)QӤ4.FҌ3X~" (Ԡ*j7KJbK>]>Kd9dRנs ~pB~Io[-J8G?i fHdza(l6|4n;) Ap fv'̤# 7o z2^\u‹4\` 7H$3` 9hbRIE)J)gsGYAea:ʢ-8Z]Ԝ͆"nfuܯ{^ Od:p]Z/9/&^o & ÞqQ9ڣa"zUPcEj<8/T֬,g)Po/m.^`$袦oPo|l 6Ai t~4zΦάU:Cp F%gCH2G֓"o7%aNBJcb7/y-/@@36 p\> k1 oTRk4^JM?\O_UMf 3ȡs+~ 9oR(K= Z_MXNM)+IKgw;F#>}GUND: gc[3lܛPS &7wqhlgs=V82B>u)g-JuArwf?-vs҆g?0g =J[C&3Wz4q=p~>P"}\a|B*$k*]_([Sg^8MjO{blx:;=#H⪿Q[$R]9=t?VY$h ȚܚjPk3#RiЪtzCm\2:4Heuin4Y%(T9D\ְA^qgqxܶO%fobB {@N*MQLiyF @%~K$N;Hw{`u|D׷ڍ#^,/_L+8 z._}k-GnH'ǩ*+5D@IK1":p4r! "#x9| eK44q4պs:6"Q'=?b4ЛA.S~G°EJw-`N]iH3(!Ds,]9"N1׼%2/nsg &8n+^۔D (*Y?l3{u}-z zor#s۞ &/<WUb[%wSJॉ!L41HjJfa @UDxY2*e]iD.ޚafʼ EڵBz9@S_%kPp:lӳq3jg!Csʰ!+{b2Z/^3{I*simL}ƀ_ܠ\WNثowp9=T]by^I[^nG6)ŧﻘ#E4+\<X3xN[%Ι@٬1v{8yRR O.7ںN5/]_ Ճ`u Tv'9\H普^g@ljy@?xE"Oiӡ;M`&gKkϷ{f/|9UĺzՠW6Ϻ[5Xex0)|n/Vm|{k?DoScWAAo[VyZjɃrf_pAaP>ͷ4c:7Cc{BIKHG]oپ]WJ(KٔpO R{kG UY18j_ΝeϚi82*diyK*u4.ql0H &,/ ՉaY0!!j h9-cz83 yϳ4Lw-(n:,9#x/;Lax8xeăh+dpNg=re8[4yk )@M/ ٜ/(%ŁBB11Co`%N_.ۭ̆jyZkřW-R+i>t>D'߈ctt>IT SI]na%]+*vkm1޹؄W <|F oq^}aY-"clxq`p'E鑨RV}9E~AC |CJ ,;L-Zzݘh8O~dh~^ F 7"mzwy/06A_B8<ªPӨ3ӏPj*I9CZ6CyT؀1Ok;z۞]/C*rnV" O臚[9K"mV1nP;//g_\d2ue )~,0)NC>MpOXt&#M lBz}y\6v,Z?چFV"" sS(G7"$QTS¬Әfgcئb %k/CHQKN-~šhEa<.5&`F8; MvrӃdYse~LoP3AP* %Sׇytl8"ד!ť pvNGx:2NcA$LO 'x{j9iKtXRoib^ռ#@ys-E"};1Yr5Lhp6&TN"Aҳ`|"vGr~w_߄QmҲgT( R0 ͨT@Gzq8=ZHiYLV615y XJYdNjr*qMgO0j'{AZC[rJaC[Ge?E{i6EN2o82nEnU/2nV4S)4Q<{wT&y#Zʻ o|2ԢN'ZGTB\wj,8\5?+ KQm5$. qkp݆+QP:P Kc[A힉kVUK?{& ~G 9e ( i r5QT` ,{TqXMoLH281@n cTxAu(|w/H,`e8(Kn%31 OSc3C49FO]4l,,DR披b[x- neoޔ@6yLV#/!"By{VxyI, JM;{X~D!$xΩ ~p;":D7Hჶ2TA.ZT.O]O] ?9Ǧ撆<9"hwGqYpA*e>ɠ[w[s /p$ /.J'hit*7/͖l.`Ȑ B-] MZ_pq 1898W1ž$t!dil|Ax%CoCs9{Imw5g>33b$JveCbF<>Q~V>a@'эw=S>ăߌ1փ4/8p8À LR?+fn.CRh1kl[0%-}ПK~:xoA_Iv.:ݒ`do > y)SU7#RҢs|w+Gƙ5m#K!wc\Kz `+Ô W~s?Oavq -o+Z͒Gf/'Wc()E>6fLZ7!9WNE:A`_3䛅AiPlM/>~B~LY]HZ!xZQ6H\LDcaӹ w/~~11<%M`{ꖧK^ ZGI boÚ͟d D[V&Fa72pԈ9!i-u}e(2"Ӹ{W iAJ3wsy#K!Vvx+K34;#*0-̒PvGS;"i&ct7gtkCz(ħ^>/5E/f_9+T+v [_pf2V`r:s&$J@ZLS3BUr`S:WfW˛ޓM>WYH- 290L"pY_1/.#j eQ_Q/^GU/0pʀk: \ըe~ގNOTB(8,ȃ[\"9x[K1j +g;)}I`'ԧ7~4Ka"^-['H8H/T) b2[NCtgwI~7{i )F^ok5*FE j0o1Sɢŷk1I6lU+g}WIyPPI`XN+>cM$:$p43$XU;x yϘ<%Qz?,TL/g k)U"|Sì-{3Be0Us<`wDpZdckpÆ=?C3X&/6%nRoZ>qO AVIn<J Z4d5n܍'T1R\|P"N0/Uv7U^\86u&L\YZpR"&\G0=[ DX+0OxMps%_ebtJ,3 ~dru'Pwߠ%h3wߔ>af}L Z[NrM5ЕpΦ!9PjhuCU$~*yuy kGk3XDT 6X1!7G5K]\PAT߰< pK +W^s|`mOb*οn=y`HOIa$Nqh}vޜUěa ##h4jO+M}XTV|N-YϒrL0Y.jAE#v_5;iAE1Y xZT3Urh"K.VHP8Ue`T$vbE,pb~ة%"lݬh戸GҡP-#SZ֮ 5hb!h@F]zE/.Oһr3!X~BF݊Qm4o@ l5>Qr pSM:/3=ﱞ]^%OӰ,@0Ms27Y,N?MO׊1$+!5.Z! (hF.6K9WOh ȣ[" VwYiTRdQQ !k|m?Ֆ'@ˎ;ŎC秇˩mTgu'ZO$h >]|$N v#?q[w{ rAfsGrOtYW8KήscaWD6Fn Yg,&M-{?91A k(Dgjœ 1nҚg˨#%'ڹ/ Qt_Qn>/oaz_"1UNTyߗLif(oAwvyZ.YdTUDWEhq }SUY7d9ڬ|I{HwalΎw5ÜUYb]YaF34$7L_%cÛz}_ S!S RBɄX aw(f/]j[q|X-C;@@X֩κL zJ=b8݂k6]N&EZ-֕=1 jOLr|ާ|N3sK3@jNV#; >kpsFIv%Đsh}"wď5&s WȀ&Ph:t¤Yu߁' %}{p2F`'qtbxt]bw:rPT 7Y@OյޘZޚ}~j)iAgQFz q.cۑ !/KchwT1,<hd+QR/EIlF'r#,tM%d(ެuy4/nүXFkR5F@MhtYp*T{{{-߬6(<3k`=͟iD{+5'ɮZzu oO *|)*!ۉ>+W afy[ӊ8u֨ۑ A6D hH~9 6 SE.^#('7']Vh岡ZV 0ez*#YKO*Bg)1?K ԒdڰC?s3\HpbXCԷG֣͆AWb:鋙hsij2+1PLrqeYhקV-x>XStv zKPVAzE՘^O˵B"zkntԨc&iGĉˏxb0C䅻8K@_͒ո}y7? HQSY͜-$C(^SR0s|0UdU) W!͒9O@4:_Ӟuf^"K~7ˣ Я oܾ p]qqQDZ-ɭْ"U$XLL*;^xCG#~Gt5WO՘<.\쑠I|]' g]D݅CW:>'P(S5G*'4ۨ5P@w\%t6]L8(/ً[ͻW޽d 5KIÿKMlkiYY>Xu=`v6I*pFC2 3+>kRoisu'u` +lK*L\h6E\jCk8V~U&ڀສM0h4RvNgO5ѡlSX! CHa+h e]ԂImgFL׆Eu*MBվӘB0@rfڱs]l.y:ּxᔮe2Bk7'46mJ%R2?H0.}Ĉp)0ߒzt\ N )ʙ_mk4>#.B5\hHN9`&RM%m]wc;0ܣSfAl[FzABs?|lykS6kBҫrnzԆGk/A[L>V(=LMGf"dcEӵYCGHDi]((: JR.ml}ٛRarJT ׹}tz*xdθr2oqB1? xh~sn(E@$V"LV4PMjە '~ڽs!hDy A1 ͑K#,c)%!@WO=.b050,]] ce;ՂJI?B)ڹ/iYs،|?xڙ.*XX14(R= 9^S:"DfܷV<1Tnպ/Ai!jv`Ah)[>ә=)e{w`2lm w4)ѳ2b܈nYL=s c|O/WU Jp~Z% m&Hֳ\E ARe63 SČm=#&bay·[qbtB˂nDϡvK?7'G/ok8IS iU(';K6-ኂ7M߅ S S]f>/'(!.u2r5h+=A ڄUTp h0GL? k$n6]뤒`\nsp=ɾ 6C;."'M qs-ŝ ArQ#wnW1ꪌ82$H[UterrZ%)9ү7QBlZq3TA,$ʢz뚸,#- M?)C6(v @P>Fʝ_JBޔ(Żk>U\pOLnU){SeVE~d])@١Rc{Lw6M, pۚcXِ2fۏ>X c LC!{HP祱5RXGkNE3e|>:8h]d':9k3!l (/U zR%jw@"Dk93+9*#~"Mָ"VM)LHfyP[H<s NC9Tb GgtEG諝7|Ƚ6ӺVt?*k/xrkO$D^1nU[Ђ񆺨-),b%Tl#3!46C - @Ƕe!A-}Nz$l4N__B %_SF0\7HՇ|*!Tڣ_vB$kV~e O,LvӃM~K"qZKuzQ/MCάq qc˳4_e 6v/HFQ+ .{7h_|Oʅ!x1 Ao[~!zEJ۔ٞOWT 46 هݔ`q0z:dg<,Qܛ`[ Kʦ=շXvv 2x٣ߑD_YZ.> 1%J.}vqxv؞lJ'ܷX?{ Ī- υ]ƳRZH!lKꗴ`xqKW"0)Gkru$o4Y,U wǘl%[ U`SCvta)dU&2r i5|aT/CI=ib&}{!4nkfn4tb%\k3ܫm},mEI,q^MI,*둿cbao=H_6;mZsԵ9rzw99{㛠@kHζ3/ Z-܅|wio5CG9\LTSS@NԦms.gvL&? !dugUW է;³un)q>g$p4)U;)O2eVIgŹ#yMji0|*@Y-f~. qCUxD%NCNq]'FEDb^<\RI(PT.U@? )wؙ,Bs?2h֭gpG\KlI)^ppogBJ~h/iYtvjޢ h M[] %дL"MOٺܛyb`MP{h'<6XK M}Ḱ5>3̲x/cjplJmDd,x.1Fʗ~jNNiӼQry.(EY!@4{ l~\od.H(nHB~OVu7 5qh^|q.T>I4H^E`xm@تW+߭;8&PLl/.($p{fVK}4t =HPMEoeNw.[̲Ѿ"yaۂ8\l/3Kn"ҾYº̈{rNm V CE1$iuH{z'r=EF%jۨ7/E{L  [5;2*͈gƑLpm{ 4.F҄z #ߴzԐ^e[|>td2wvsBr\mW>hpcTvxx#nIh FVA9Sȩ+"=-I %S RR>jjkL~|j%Xf=V | ) n 5GF}!FpC?g YEeMrC;W#90S>z9j%u\v]VFY6^62*g7O.5$SG-CV{8<'l2{$,:dڍnwέ`& 2@H(.4[jY 0i[-ǿ!{>qPE=>+e)$ׇ( QQ-syLX$yyPPX|uz ^Xhٽm8;8̹MoZzG O ,(;a$~1RЋ ʡ/IH}xin}~?X*3[#؊tLbZ79\5#ȃ,_8MصRjqG:{b ݒ]UpVauiM s#I9evū{WgfZmZEZtE'=^\`sa0#cSFiNU\ǰ+&_z+pv]:1GoNċ,$a Ü^@詳%̍ ,[ywxR(އ]%(݅fdKO+<^$u͝X\w!s/,DpG ^{H_GZo pmш폵z_rQBH)|/ټ ۖԖܖ!7ͨRGOY6 1;>׼5ʄC?Тh$׹j. w1[1I["Vhe: E'/&Y4".cl'`x8Emڏ;fͣ\KP)(x({7p0mNphdr'Co{a#vVOSҧί!]JfG{8'fuio`ls[[\ʚi"^ Kj*U-"rsY J|cX,tpjKLc[_Q[@VHg9>#`L< .nInϒm[r/@B|5/6T x5;NK\_)X͂߃IW;zɈ4ď bԸ>RbZˈ.bSI^x_/@*؁z`Ȏ+[,ZAZb 8_?@ZՇsokǾ[<HϜWTuM|}v^QVp98q8?ڥW(Hvb_evؼ0'ӵV0O_/-ݳ_$)3Sc1|3yt@{V/@SjX9ւL֢I?VB뜽w_Pd^OqFt/dB젠!T \ (m,bVd,'ĭG0AOBotDǟ0/X@XLiQUCĎ?)ybvWTu.Sաw~Jo?NAiZsՠJ6g]D<o&)[|Z7J <0 2we;hfz]/e+ y&:HS|Zyc\RGJ?LNzǤv>+s)|.A9|$%O>'pcM:3+!7 lȔ :I/()z>Z a=KUc}4F⧤ /aZεnC=o_\PȉX/ha c40ng]\CJcG],?'!{ |jץ}GFƛc$No0JNˌ: IidyCb4ROY<( :;V齖Avwd֎YOރ RjD%@+1!Ng qG7-v ^DωZU 9C)X h35k]tt;>Xe z4GǥY!FR3U =;t jMz'8LZ X؈cL6l7q/Poe>tfh=)YC^t$Zjoa eb1[O䁣uـLtI*02"; .9 ʕ\C{v$k^,Q|@x⎶د | q=%> OaypTb*, .AKG]?]_EmPrz(Q'KW~ce|dNh8v_1 xGeR'ъ2GWzЂ!~ X<*0. I?H59udTJ[~4*)Hp+i+I"5w @E`__,k|'M(GCVPlW_r[Χ:  P, AmKhH1,tGSkHӥ^ZTC> Pw>ΠD=RT½&g5u|aܒb~fw3\~|Ķer~s6M1Bj@۲^O$?D*ܥ]0 i,.$?@ܮŭ-:JǡA4v Itz78[w$z] s1x#8kmc[p?F,q%r2 !yBC; 2^+"/#5tū׹4ŶNBSZQ*=թLr ć/cO0q/9}kN0`oZԋ GAAk5 Tv8r`CPaEd[$)X5dVPnJj\4Iq?$_l+cj;Wzqd#jc'RZm}v aQ*[$*{cqn[aXv2 w[c/ A7T?"> {%[@ZlhPS,]+fy3T2t:V~zǯMBYɗZ$Ɏ!``#7/h>Mf$IIT}YrM7b\a曌o ~U$ @.|^Qώ ;5Zm!ـx^g-HLư:tۢ-fH՘Odwtm{p4]X*oh)jye{`ln|Ӟ [ѱ vm~cnnt3J]ΞQVRkm!1/2Hp'E}>n!\ZֻY\>2b!enI(]SAs_+&Fwć$']&uje?El4(cpcCFvsQ»,W+,DHG_@ȸ#lFh->0ˑ/ۻdgsp+PHa".'GMψBeiXˏ@"ue,֮S~5 z\gxAI6ل53~M"-rqSH:G?#PE^0#P'9Z`97sf+xrD ؏gy/||ܗcƎ5Xd)| IO5)ּ EUK%ZN(Ө;4;wo \ nd67pպ M=eD~h IY/xzD$,@伪}]c 78)JC"xXUB42ESr {HfΏna3#:zmß#޿^7gw&Vnߙ#:XAk| φWrHA ڤo<Ցi1Ȟ0 ⽶xIYL`ٱa1V5ReJ+:zcSy/d%gcX$;,5hG asqoɃG[Mp@[ {XO {'ྌ'Db6ԛW12@-z`DŽ-=2J9HxT9M=oO_]NݴЈ%~][4%Am xs)!_>)62p(ZǾǸˢq|ʰ3-nϦ8#'2iV3wAUl9AV_ӧ*?ĤuU 1R#lk$XMII=$QS?`kx;ѰC̪EQ•t? eP_:uV BXcb. |JP8s~>~z5n,PI`ihJ$J?fsJRB.fs¥d]b$Fa񈕈P<:E5]ZR+-"3{AۀF]$%-EՍ/)T]6¨j+ƛ3d3$p'{i \_a?ϕ&GIU\[I-([L΋.%6+p8 .vn43y'lyղp%&6Z?"Y c+Lf"$S#.j[8W'z㼐yQVώ.yq~&EKUyPhM"qQ 4xTL|Ȟ)PěkXМsхt Kj2їY|Ŵǽ }ᱮ)NiBF+Mz%c{S"cޮL{ u!dԞRN])MۋZY3Őt ծ1/ Ŭ1rR^M0hd pdž@ݪnm9%9P&PcflЈB }"f1cg _H{=s{Л$Ci.~Hcgt8KH3fNi#D O^ibZ"L<7`9ySRAKꩤ,O˼kFC@?FP StogK ҎOc)>d|-+"{8s%aGHSflHdz93I'"R_ sa117* o E}~p -_G;oCWa\Ls6Q=SXp܈{f.q3׫+l$;<~&Lf\g Ez*plOt.q8;qȊ"n~h/50mtڈ&g^}F23e 2p:T:kr;8*;j/AR*հsUx_b bP.1}SenL->QAWCl~ƽlڈ$mb"]/0zSLۦs_!\5yg0P'?`c*ik&)dӹmlyڛ^l˪iJ ˴gߐ_I7Ex 0N+ːTu}ɪ#]PQviy&Gzˮǖ׍,\f3^@ZT#VC#Ў5<>~2!ST(iQr:oO󋞡Ӊ?MT\Mb V=vT%يݳHw#I%1-o?wWSKeGmܲw;JTM6'kv5I70JsXzXc C~9߃^#kfx (e uXg%_;;՟P@OpF=#5sk|2t*?'#8#X~`#pO14hl؍%vָܜ=Ď Lcu +>x\6و-P80Fz!$.u5[iTDú޲8hONŹ@ȨXǯ_)5BCP˅rtŎKfr˖!|$xTo-_:vr# ogcWl@Mnp4[c0R|~+lw_Hצ5LwQVG͐G>xM0xlBR+ByډqY,.yB|BJP>[AM%aBȈMNo+0ifWJxp FG^Pzc#i-}Ts "QvR` {T'mT[DṭOE{Xh"Rc@`1!]pW7K+KO/O-QwȰ8cҔm 6(ٕ !2n(d1pf۾=I/GmYjC_/ߡ#alK~jYeDI,O@NB5WHw3oyU=ِ+YՋX{8D6#=:Xu-˿IC҆W~c=NF8Ч)kA aqKF0\ɠ[nbC t~B^H ʌgH:VYT,~nFSM7T;WSNB!GK/F#*`Ko!\P!w}Ag5 D?0d>Dxk'xb"P*9 oOuH_Ӭ/ôDm{WZc66pٕ1єoT"e$7.Rܐ (igj4:D7'L$ QiGT k1FxswCn Ԍ}H6GTt%ǒSYdޘIu?WX,jB +*Q/riJ+Nt7iɮh?i ɦŮݡOq~MX9[EaN +NS7fvB~7񝯩qU)1n^{ 6]zEd)޻ Fӂ名dLxh#Fr@vVD)T` ]rz4HD>Bَk u_GS>3pTsdPC 3avt,f2%=! smK(UuLjYthE!-NW/zJ%eOYELգߗ.ϯA)Wfx2[CI ciUoAo|Yr lmAgJ/+oVZucE +C]Ĺ)!BE¡ۢ1tXi|/Q6k IÂʈH=WJ6'F2UVīʛ[krwX/X RaaGq/L?Ff~5arkQ٬s(暸*'KTs=XVYB#- &qhnyH?5A}UGۢI@1ɩbXN8W?x~Û\Yr $~˷jK ?![(pԹP紱iT8U~N*C|ϝKi˨oLf*=(a !L-U0&؆&J 4H6)w6ܰ*FYvRޫƺ .+ ͤL acg=lKK"X wۛ3uu=\d<"rMc9lD( N9P!ДK!1e{NS`]i;c'}z/ؒCc/T7U=Z?7l͉uQ8`׊&TжYMs,. ^}_Rī-}R1۱3zgH7jйkS-sdDC!OtF!X߂z=>k2- 4M2Lj5XqyLiiVOps"bf j}A,-;c^`7Lq²NtGEœʖ~4q#sߌ:W = >{ A>0]NJ`@ԄC;;-zղ~F)Pw(@:ړny>, JdskV<1Ϫ Ϡ$+Vyi]%C;ǽ?FwWTJ@2>}[CV@î` x^uK?T5 r~ E[xF\)] KS3vdy{S 3ɖ޳JhH;+yłZk2nRԧYE}o=B>8:Iz&,Ob۲u}:V `nJ@iVJ1`wE"P+<`~Nׁ+p~&Z#[W)X3_!ߙ8 ~W{y*r}B#nNg%SA}wq9{ٔ9d)޹x;W\D(lEC4 Iѓ{¹#-`ӓ?I4I5Lr$bZ 1]U&|5:Tz%s!K󍙕*ѢN'|Xun'~RB/QzD'Zm!^8L9'v(E|m*8g(4@^C!p$jNr`Yߞ(^ Z|DS)n!D--A7\fP\)?Sp푫F&|bx[Y^5GZub+ t`J\˺"$12V %M6C'.ur)a)Jz/ߍrX:k/E_1  ))͚|@&B4$7b[ ֯|bhWzxMfƋgV)AeH b(r礂(pɠ|$虡Rb\'Uƕ1)=4vv$~rG~rti/ z;1AyW՚ۻ#dxNGDȈT䨡tr5/ϥKi9U 2!7:eJXd/u'lB.&~{7.kYH&x j](fo]vHfGRX>Y`>E=wҼ5]!ATES~2W:>`!P.㣅oj!@'/~Q]$gĘ cn\%"="P!8J2Qu?auɌjƍ? 6V!FCDdۈair :UB~24~oNC-|r5Nc%"3^-C+!/>3ub3zY _W|B}3dK+w#k~Ծ7*~́#f;ʦWlYHք@Q6yn~6ozCQXO<&[ܯADXw\|ޚIWST!K}`n޵A@M&YQZ컦#ĎB o?^g[c *$vkaՍB[Fa/xg>Y;kOn]-CL5(+ĔAak/ȩ_,i<!lST2>z'q-zNB2aТ`1E$\ImJ \0_i -pɈyQ\%=xPԮH)1uh@͋Vmx`ӨҌ|Ϸjd‡`5u.EwCrO`ŀCWER/l\5Qbv,zYeK 0kg~Ҥ<I9vA!rQ hGyZ`kж89"v C If}}:Yؾ0lgdu m&6sA<8$:sPG՘SX wuгPd35\jzy H?N2Uil7~3C@Q`B VqsU$($IB3 D,5dW"e"mEG9Xp;h `S:M~JB芎>1y i7r1`H q#r+ϔyS.x==h)WQ3$[U!d3fsԩ4L[5VL$5/UNQ`wIä=hd#5J!qhpց>%B>;5@D+ (Z"){uJ RR+g%8U`x__yZ!=Qs"bqL&P+ljQwzwx.X%=wZ^ %K@&EsafTwptbń'kv⨁TtX Ce1J9S-"xﶏ)$#5 :(Ƭri'3NkURkk1ʲ{FՒIÃw={?we_),?0: _P׊>zԱ O%JGKKQ])JNoG`ՇZm.\ ޵,,$wV^_Jik); |b0Y ͹]@fc'G_;TO[Q7S [Ue+HӅ5ē \3Bvd dЀ!r%I 8Z;/b"̏OlV~}gϮ@dPK*Yn##bPqjIpyo$K袍 ReϢ)h,zRS *ZGp Lfmwz̳yTcdž[qT{dcf$*n*{辦Z OgU(fO:iAaI2'O_8w*^]p&(?OBϤ@mveWA!w4l x#,;!G\a]¹ʺ\=;#T?=Fs# (̡\TTѧ>]\['Oad#F.H)Kp堤n̙`I?Zce3yf7PB Qר 6%)xp=Zn{W/ZYzҲz s4=ʄ@+˻Uhb689 FQ bV(H5DͅG2x:SksYkŁDr!Qaxgk%&O FhhzٿEC_) lA,1UWKEl5K: "Y%;XgD JKӇ!1'l4\<(sbE }$1ݯ-- z@ I PWīR/%!sweXc9x,~XX;#13 0?\^N♀8{9Lg۸8xL>>@.|4ϓ6Iַ[댭p[('WĪ|f~^'O&-WC aJkgaIdTnxctﯧ Rxu})4އ4nR7T1V>"%8ķ4I8$? ?zW *nB)Y*|H}їNl'Nk`b7Qg2xބٯXs(׼ten c2$5o` ϡjmY'4V֞x`bЕ4m/*U|i RbD|R8.ܴ9%ߒb|ƕ{A 9C8H7^_IoNvPi3\q]،&jTyomk}s+>1/v1 \y TiH9A龾ϺWn쵐_Mig4{7k=T7=B $.%OQWzJySzAwrqui@xgI_,H@1*m?Z|r{69ח SntY#5Poj,qBGU;$!fCN{/|rm?c_FzŜV[x_18؉+>8t|oJP%>КLFdt\*]hNPtÑ5%cPM>~v&[#?UA iU"9 >W*_~e#J¨!!#*kJn&j&o@Igwu]wH:0=灘`+ȧ}xrMJR~X=9G_}ntfz|uu0o*_{hf)5x׿JG}DaN\B{[@w2-+,$!A"N`ęj&&Ly _독Fb3narm@:x(KHS'Ψ GVRRo'1nj)I6hd=jm=niNBub;=рu*% ӋoO; ]~aɐB_gQ?2"|G(Cߚ{,s\H@~('t~XvJWN⢼&̯>QFE$۠x)a%aѫbfH#ix'XseX }zW͔ۼTt!Qܐ] xNY3jGDUAɝ~,(5,Z]H Uˁ쏎5N@>.pqd龕<jҔ|Ф]HD yu,Gw/[R =mZCc9W\z33py8ԙ۫/5k [) $֙aΣv{?7}}9=NGt}L`$S紜͐ͅQ .RٙnpRru\>*49ЈeTmbg/^r/,j*@m(=ޅ B__ghu,yG+D۳\;r̾0uhJZR^6m@j`SU:1$ 1+/_zrrR8Qi1?k0 D+f#IىZ`n2 k/UDž!>7x6Rz[mt}qg>аC:,Rv^_.+_ gZPBS˨?%cEy"@03p 6~s5E)$Mt]XR t2ua_ 2pPW9 VM=?Ĺ3nﶶ};YǙQeuPVh҉+CpzB^ٳ$W%<ǑҸu*[ q:j>r R,C_ @JO--xy VHKscJ[m?x*g) *kB5_&Mv!:(ՀTj ıqQ޺}ejf`; H,$ h#⩴E1kiv'XH^Z~jy*ʑvo׺KnOQg‚Y^{?#JضEWatlrO;*ǴqL1v+PWz*$O%$+YT%E$YD[T޳l'g݃KQ9Dԟ9 iFc:̸D1[U6xB1sQv/dUM2- AҲO!o{4 ȥf C>*x]b0չ}t8B&+ UF!-Pokjٖ/<+;ðm nh!o$fx^Pb\N!b5w7LufMqԜV8aa!5}!y5_{ɡ_YQh 6bi e(o.[1/3itQW߂T4YȀmFRgù) P={T6ÒXZ2,gw6VJjw.IKK-<9)qG[~+LKW<ؗGfP 즓S}E*=kC'nKQ!܍+ڢ7~M$p d %ޗ{%J` O5,gȸƠ5Rl+4^Un9IR~=0 r]k$TAhzIu ĉxiPIYAMVyxЬX3҆+z$aMp\)zw uUnZ}# +<ϯ|Z/ g "bޤ2@!#qRMI{y9SSA̭rm)4nI{Q QțA2p?fri658gޤ+VTkf餱k <E^jscWe[>]jL:#(mJ:xsw$( -c]+D.5,ڡ8~n.,_/rmA;Ȗہ %GݓmL_,CWp$fW@QKʳWcD~ g€$g *+ɗH=-yFkol &sۃcA蟜!䟾% )0j|M16Aa?§uh `{1k,"GtCE@EX"~Ŋ0]].'u}r'hG+ mhpxϭ-da8} ,YF ֯=$!#39?Zfvi~Oͱ5&JغtBN%"/@ƷD?PYqɱ>_rdx§] 64) X[Khu ys~|Bԫ{ѡ\Z?y$wRRxM\M@F.V4JS-2lk.(zFH\5pGZ9 dB,^؆\QF73*Np6n0R|å>9p~yz@ ?}&\4-Kpy˯3(;WX/zA@+Z:Αx{ I1ܸLj }cJŎ.;+ӰYDTHat 귳*=)uT+w,mn.ewԶ^4bx=VM%eU*i(3s =hcERJjg:7lHfހV4^U`3Qj]͗XL^w2䬉xpH?M"ufX <tp9J|:u%ͨȩ95ԫBh̒RV`0y\i\(VM6ˎI/; EdS'}\cՀP1MWt0A^M{?=-9K[@0hpj #Xb HwGd'iKsE}MEϮ(j}~Ýىf f׮W2(nJ*rC5L /5`S:j n >CZHnD T=)y-v7ߟB )S g}i 5vjʠ#X3GIo`:m^S%>#(cZ %110.twrdKQ)B@n }|}S0/u)r!f> q^F̩d׭ae&wOx55 ?X5{)Rk,* E8cv+B,-Ҵpj%)=i_: )wlŠv9Dm zD&e!A鰴JA9??~N?%ycN1+-t! O lihא6`JѶG0P!Ai@"aiXpHtO1^ UxӬi fډ<A~2A|>E#͸ d/AkokOG÷*٤|+ۚ~c'5|*;ZL1 mNO%fPaev r0׌ )`̢a)0RO.lǜg. >6LdxbElEjJl&SF8@l%g|XO*!&`@!h}/`iRL 0>wU*ceofzz22pZ;VN$Il0 w̳Šw_Yeq.kGm #L?j3IL]FI8Cz:S\jfWưߎ}s.Dt(^HX>Ke{Rj2E'G ]pW$#! jޞsj@|s}Y\ P]c;D8Hdn`e>\~mr#@塒䶩kwrc>ߍ_;&ѯ"tl~ N0/L0(͜ !xtԖK[LjY`I=Ҟkgpk|O3i}Ԣk^(χ쓪%#DnG*, ={J?Vdפ-..e 7x !UȆܣC7jp4tQ#&)cߏ"P&@_GG}1fJ}7M* 6LBȕwg*5ڀrЛh',<M9580qWp=ٸݙ,Zg O]?InlTKgX%0svpZ!x۰iddzTj8F޸HIɵc4+kn.6Pʩ a VX0L6^f0/U۟vEͻXH5]{+%.A6,vh^A}t|m |nv:zT:bc]IS5aƠƼ\^]]VUԸ<)[(4}I([5Ț!/pҸ7g7м%ө5:pDCUPTD|r<7<M Gq]4PO0'mdW:AafHg唶k=ZS{ qeset,cZ!-XՓ3Ɛ@t~ތ,y+HT\>oMl?"raf-ڝߡ.f dۃU#x[_13n{`"u'Ŵɸe755wj2DH[_Mf4;yQ8P R<5/g .\bØLe`?5s1R6鈿 tPkÏ<Ή]*E!z9+J;` fBAGf58|Y535S6gjכ7v!6Rl``̹ 8ݶe!P. +fak},WrX@sd^J-oTL}Tѯ G\m|$jԣ"(f &co ̗HC_p9w f:K_ɓg'{W%>ȃ_\$tv+*3!{HtcΗP,D_|鶗Ce ) 3wީȨuWwzUɯ^dll& Q^C c4 O'/)Wj2+*r4DwinJ0$PDWW^k kcmIZ^U0)Ǯ o"~qln\fq\?T% )HQ"qX'] MӥfRѸ pJ t\&:/?*AKބz㶊|L:V ˈtyᡳ -{=ݡ^}5դQ\uW?cޫR6B=X@+VB*G?+e, D,_=ŋl V;< Hf7m]e y-^v E:X31zIK=zUܢuσކLUV`("D['XxAp^MsHr\ j7^^Uvs .!hOC9$uĠYq/2˶.,gj<'\BDm FĸJS 49r\|f!I${xrP:VaݣiAqvT6G vL|?!EH{M#cuP\下A'a'<hmH>R u_@-XaDmgֺh'ptkGcXD#t1im)7hG 2Ք![eL5Y&ٰxEce{k 0d4=ߪ*|j۽}pc7x&9TH( rjl eJx{ׇA?Îvجn u-bAZjtK݄m1#O~PdavKis{(*<X9å}(%E?/m Uh]k>(90&$zDgX9ԨMh65HKxQ;==y"NzW ]kBgd"0ɛ?usfn48 $~1y5Lۊ:WN$Yn qV<1^o06`-\̾#LVT(1Վ5y0%a,kۨߛ(͊*&fL]"+0Ѿ >Ϩ` L|\jp{ГTBR*GB©'2H*9AXs[ҿgiP@ū]EmqqCRQQw*.c]C>E&x bN--^F>ekr&#HKFblw`6 fbMUn+%]2ߡ'`P=p#t[?|r8`eN,F{&=җxuG>Lh ;}bRzm\5,r w x\h[6"T):w~UR0g;nzMEh:lRs +^f_PԆ( `Z(9)GzgF1T`RF'M~L$X DUQHvSoIÙem[huhM4Y PaQϊ*nb\lѐX /ub2+o>AAoi?D }[hWQr90g2a;V˛ﲰ .ߋ4zL箐3 4-3CЀ{Vx3BLV$+:)=><8m`ʇb0,m{`rE2^(Hm9}z[JJH́aL0;sSIK; ZEմbyH__(0| nm7II]NʶI$ӛamHPi a~cce+]Rћ \v`ík[KMdl|`NɎ}MV+mE Ct_ᢣ`l7ؗdfm]DXwkL3\;e[n+pqox9&lE=hCk;:@o#SW's&J3s*Ou'ԔDYl謲o@tb/sFbk6 C8t):Z  CK j!3^Xt-bU2~R%j'b[8487@wŭӏ}U7 fkPy?Ɉ.8xQ cM Ӂ7s,;-$s.+~&|S\} `+[XfUV7 _e\X`05jˤ:׌*% $H~^ Dq RUI*el,56_:md/Ko2Vdn *ߚ ԔAjuqBl|gbp.3ֆehlrDZ4ds Xs|֕YsV]FWYaN"?;Nl%}`6 (W{9m̧8}+hz$(0ŷG|џO^Rp 3 f%/'Sv:_|`skM-OAI݇0̯EC ްZ`#YD8ܜW 1T,1FB fPP~^6Q3qcvbj$^kȚ8Lėݚ|T aQ?5hHQwsN.\bu=mG ^8.Z|yٴ%e/xZi+:8HTљg'Ez9l9J'c%!urfeՇN̠p6tS*aߛ.Lrݲr 5eڡ?6 .HEzݕV/J.×B%(+o4:7i`! r.b/7CiI72њ2}̵$S;D?; Ap} 16Z㲦;}J1zE! ^_C헽p0Sg|2+ }P5GǓ[6IHW e6x@[J6qr_3֩r N7Sd yD0ʄZYGL\N 'ykr4L|Gw@C9v!7Sa^Z+r3(nX#( OC0Z5́FQB*{/ FT^;~+n c57f'")hs"\ ڳ o sqpv! Ѱ8L Q"#*L9Xo%B-de O)a|a"L@kcչ~`*$rq=,;#֛Ǡ3ِ' 9.vێinb|r m1g8֒;{#Z/+4Vq[X̥kAm+n5WigJ.B?vޡmT8]!z#-q^Afh 3~:['Nba./jYCSiWb-W jZ+%{\O}!{ڼG|sh<"OLZX'x%w@3VˇU@\7|7"S1(g*@`{}|=C:|rDbGQ.nװV*ȑPߚxx?KwCc 7˲,o@ (M3L[$w2n<7n %IIx}  E'Kn9=2E.  Բc/|t \LYǜ~ICn(zjo~1:*.gz. W@LO}? 08^| *~x,فDf4~潱ReZkaBg>YI2(!@TXɵfcU["̯{a% HtǤ F@} (x?쾖z&Ύ)CDۘq)&p  }K \emT,[[Mj'&oˆ+iIS!:P*\5XvHjB&I ٷ t0|q6 ۍocn90(oce+@c(!>*N??gz^*|PGvoW}t-0#SJPM3/iZG^Ut-„gH M6su|h< ,VDfzY'i??BO60J@SI1tu$*dzvҚߏeNA`Gc}:xGc}NH"5|O qv!l.QŽ!>G'b/5+4_V7bonV}=;PC[u!"}6kG ϜU7Dl] !Ȟa%|^\L2lK4zqFk4c  nɹ߾&g"ޔF g'(\rh0m MTE2sc|;7 N}9vټ%OeL B⚁~~WUPIF#&>NyE6irn/s_7ϛ4E=mPoge؍$j%1Ux@rcIrUNO(o2Kw^y΅)B9Q{وbB6ob]ˠ&o( d[lD4V|-A,wpz~$YڍFK)X^'.):e>=ZRԌ0(est4#=S B/[eIV6*;1( hh+r/>[88 M%xn|k5DŚ?uˏĆ*)riƩaxv̴+tHl!}$cM4(w{ϡ;[q%ӹŸuH+$+Y5[TM*6j^ǚBT/17*`tW"4V%Gd8 B))vq7e%NI[*.i4vW::-J[)H(7TB&>dG$s :$kA3z Um #U;Ԭ)%^7'NAk#v1?dh^9jTG Ґ#]LFAa7T]⸆5~+jZ&nDmq[USPɤn~؈Oò,Uh)`fUHwwdZG<}hVB"~l MHp.|j ŬM;Dxq#f3=>cz-m4 ȇsYHߐ2]$ĈV U/~Y;}%/Ch~hw{$0DnMGˢE.79IZ6hTe;sφOVd(Ĝ^Q2cd9+`7@:rJcgHem]bߖ3BVixyhAzLZ6Tw^*5>jjZb3l։fL/YagVP?>Q"wIL1nJTks*u3#ۊw!ٴ}v"[}Ӡ>1>fqc.BD`\"]ana p'xO[%9BɾQXgg$BP#ZČjb t4*7ǒNG}6b5/!tUm&o>@.. z&wjB u혮uwjwflk/=5d*AB*}"b"[\ 0mK{҆.E$VI!(I*1i%E. V+plo}n147&-UaàSSWXOsMvCfo_߭ |_V-TbHf}xdˠkª 8޿\ u;\3DpOm 3ѶHf4斅\ˇH78 99'y\)y6K55ќIjL lS7U|<*] !7j 2oKN /LYZh_ G¦|iF/ c\aw(4*HMdIk ugPVd(ȡ|u4O :@pJ bF4c6ѐhMH4|Plwu,0`j,?p$jak==4Ԇoç.E0ŕmJcaˆhxC';nH$'~_P.4JYͮ|~$Ϫ+rml|ֈaoDef ␈ś:C@*&D=Gt: {Ȧd\KcOYVC_eaػ8}ۇR*᎖վpbi 6'H6m{zwZ zMq1=e5הjH?Эw߯kVgPNI>V&C=́N`>X؆"m0 ry)ˢ̟~/k%xBöB72l\ԗ,U*?ۨ 9χ;]8'"nƙu{GPBwO"9Mv"iSw:H(?>O{I170T *JءޣǚYy{nY%UA1 Hsdu1ClZJt 19o+TX#I 6ܗW"7SBt1UI|)yQ̝-p3?_[,JtkW|2t/n}R9z{e rXnDEm'oϥ#a{{~aFs.n_8侘h}w,gV1mj(./yJzK0ڼێ vT$]*X#t4-%2vGIX"+5QLSNGX}?4B 88鵏)6đhV9AO-6h4LՑ4c.L9G?=>IZz:C絋"#4D"qd4Cӝha)6WMfKo59aGN'w|$ħF(!Yˏ}r,lo!`yU)ʊ)9X &'jKұ>x d-'(\(|?|`vtn:LIygulZWՓ_ ӮGk-,FA~SCĎ5ޚވ 궷i6(yAPaLlѴaVMS L}lF4Gs-e[QJJp1H:XZd)>cv1ױ/iE :Љwwd$ssE25Wp5OI?ɛĄjXĖ\sVF${'BğNL1GxP"lӄs >;=6{\ucM֙"Msh]U[gfx]DJa`I{ހ׵&/v3[Wc#E)q6[3dW3g <}Sv :,H*sgGx o˟vc`1n!wnL.r e} 9Kz*iܱgǼfMln;Ǽ0 8._9v$CNјL0@a= H3a c`:&MUwS"6\vFg{8Lee.T搴"9̴Yų & Op5ⶰ9Q[F@'$I;`8752Cϝ+c%<̆ Hu=STY,Z8+yHx#ctDenb"6`ڽԸZ1潒o_up#=SAZDv;miCVpaҏ0H75; 0)X`?Ufl!08+`R86Fˇa8~|#s~pه+ r_zU ?q-]0^Hzo~w(O>g&͠:}Cg89kG(UR7<]Z` @R.HD]WF~xcAل".Ȓl@]eq=A] Dt#iVgdEfI6q~.@m`KPJVp2IǨs:dʧU*6>ì=q/@xAQZPB-E^i.G1@qC 40WOi\ רVjtpm{s˻#>+) _P;7&3$Cl_ _^cP/^ln8 PE 0e\_٢<'O`=vH#JvJ{obRX&twT@o-mmAZ1-xҳzJ')/.ЇxTXfׄ%y[`pt} Zd&)ŏѺHZνb #׌^~Vuƭ)T|jA;ZϮ2D= 2Bw~Aú7k_,h aCnnoh3ͣ>gPȺ)hP`sDWضznmʹ}AL,6k ( ԕQ0BnkzN$OJ>[?@I<`LKD?DkB OШ &*I f ohUn`5K>l TNCGKxq0}-sx>зY|.E#u_T4Я;*AB-߄-u$'qfEjYD&gʾ+.iR'Cn,]eU`&Twr)kCڧm5`V41cV -"1x'Jk}}l`šRߙuQ<ZTeh\5߶AiѨz9BŞɃ”Ŋ?S K-?/6I^lAV&P Yazu0I%%?>'k4gF~ri e1}y}d7_# m- z8k:J v73uޚPVLT?Zষ-78OP_S–k7YՉ5<Dz>M'w|O<LqҶ1")ű`kQFv -UU*m)lz%/GUy|ѱJ > X3]A_34X z!E{ҾNm$4uV}}[}52IB89ם{B 8mp2J8ޟ^*z/CJH X]du#Uꨭ5[u (=ՏTw>RR`k`A:"I\0Iiߑ:`8\-r7̍ttS/3`ttJ{**5h#8u2 nUcJLȊo1Ӧ]v_BLRuLM$[ARa;!Avz,nˀB-&LFtI9U%̹'TAS/![m0o,nqhEi&A(TN4􉼮dA).?󲭵I }3 ;*1tULȷjpD&[J7R`6O 2זE-Bj.Hj'9WΨ|ׁ(xb&7D$ vX[ROun{8ZNHɞ-v͛2ۺ\ -o~ 0od +'u^*B̻z-px$A{g@BYxu;#cP>"s.( גx;8Mߐ* I 3g A-+uG&sΧ*Qppeuĕ@:-Z8v;JD] [ljp$$ݣ?ݫ*XT?R4ۡ>-::s˯Ę`?J)!MjfmLU5A#{G<˫HD&:ZٜSn(8>[1[0)AhǿdFeWc[-7cIpWׇ[mbgUuE}xs]Mʝ(\fM c|8ӀFuIEJne7du$Ð̕l` oTe CR/+IPhRQ?a_5 $x}XѭKwKxI]+'kEKvÉ>9J!$G"aq'>̈́0hQoM_96>dlk~؜Ʒˑvow|oeݏc?slgL_Og +ۀ5u< ]ھmӇ9)3Jf_I`qQt~Y\E sz~LQl{bV^&6 ,Pǖb`7F:nd UNE?RF^CS>ݜ[wϢxnE%h}xWQ݉uԅ9}20eeТs;]Sxm!k0b:R<|-٦_|@'cʞUK^e@eZ+?ГBv_l4oljJL̃~~­i~"w >L(-{/'m*?43AB~K I9CğvqerqR~9_Gm#LGXosIҷv) W! g(4LAOg0.J7M xϾLQH Tm<ݦ5dhL"EV$0, ];bz-w^y|8Sǧr,Q+!-{HP$I**,;Uw}W˃fb %&bw@)D+ H`{b^';kiќ'sRr)K,O{Uľn=vb| $,eddj^WXZ.o.5<ӝ GRZk] V=jzZ^FX!kD=!}5n M̚;Jۻ6Kgp瓱QsK,ɭqVvSB!_~)Fw7<'Adի둽J Zv?}4%.:BSFo^&qc@]$y?Ѕj^b d;q\i Uw۾嵛0yb]mm .;5=Rgї&s`&P u+^Hs>}W d<))A2rڕ6 WŇW褱g"(gWGNĭPCC %)\-R;"ـz-꒩f,V0 WҔ5z0<ʞ*҇t[&V>tfSƊBWFrmONC_Tej8g|~45'إi!ϛW| ߍWv9f*ni@kYxۭKymMJQ5kN"Ӟt?"22>s:*P]l<K @vd GX7ZwޚFvw)\D'!WEJYɮ>,$`7ֱ oq8Ec8rm9>-O_e3Ϯ&x BfL'9Xv+TRWErHf"U{{D6IC&N:нbNQ`aέj;4'l3pGi+5auT[ TܙQVq1j.HUA`Rt_ogua'BB4 1mwys覽8>w N?%61#2.cp[^YB/byU-AEȧD#9gƏ$Uk?BogCXnPQlb;R HxHV8D_@[T)*}!N,c-8%&͇_RPnO-tEv@Hˈ dſ04lA"5dhZp.aGY"])&I&uD!|֭hĽFR R 0# H_ax~sBeiE{Y{_IK,UBFC(_S4/!GW[Kŕ՚h~5J 6z<ްI[w$Z'.ɮ3%df\7>+J-ysI֕Xx ͼI\Q05v{ z [T-*,Y81ԾFFOw "qi"N!ϟia̯C˹rRTF<ëfd0Ei%OmBOo.'"P(>ifZ!slTrAK 3}'t @'ھ5 I1k=4>2$q=0rW9Q"z x'\G7T`<6%P}} pRv 't^VE+≏uUw U (>݀g_'H~G&_N5pƌKy x5(NA?c&StNց+z9.:&x({amj2g?n|SaV+IϧBӅйPbKI>hRM6qr29 q63o}M()FrDw$8oAe1ɏ'"/Po:l6>8xG4Iv|_t|O/b畛FG*zڨh]. n#>͑tsB5bz'z7{\d԰zhLe,<684{k~NQn1 m3uqҼ+@2 .VS:DAکnlT ܑ|u [s B']&CLe[Cbt8Z&7 ^osE7AsSJOWȢǽȇ8zF?? ;BcBJSl2V?1E[|'y2!ݷ. FS݉\@KezሃCy}jm_T.VV;A Ǝr(wr+nu\ƅ%2AW:xC{;j/!iёlOؾfа(6zg^&ȱvE>,# SgSLaϔےG)b)[Re^`K9O#aݧyþ`D*BOQw`I~]u^tqf+&ܕydJqT[}@3hQd9i@dWMr^rgormիmd}$qgÁFn|u;oh2x8YF.#}C4K8(#uK-#Y,o%1#R \B4q6ͻwqɰ+2uKD C2/Xsr@@M|ǐIu!]B:pt.{˙1|)r0%$v .,}:mp[Sx6 &X9lrzUbna4;K qWr#^9rIM{7ЇK oxw= B&zĶ_{x$J!جy,iۏԅt+_29DDWcl! w=B鞮:fTM5^/+Uƶ.`;)][ƹeU@pExg| w~[ /]Jdu=#.iTC 6nq=IX[ bj /-9aXg\D <DVt)`FNc$‰*ڶ U@$c I_FLa>pPpPpkGpabFYЄ lYvMlguRT_V9YhPE|t=an`LL%*!OJ'ey?8d5: ?`-%YFuuo_=w/O.mP-n'uR|e0Y @P,PPTB"` ةn}@0[+^Ӣ2<Q9Ģ(&JKt?_Iq.Q_E|Oh~mJxr^*AՏ x[<_A킛M(r|0x:ZF`L~^.Ÿ _r}w`D;ljC}޶aEҘt\ \DLU`J)IDқ C_¯F 0#S%ZgrUѡ&g礁\xRXX"~ǣ|Ecmk].U^(K< qE%-Z'ލX%< XE/;ѻ eZ4(" jAڝR#%` >" ޞ;sV[K$ ^B3`ߤRhtyRͼj(iQ#A4b2rUF1XPZ[¡U DwpwAD}_Q rNܑU]dCnJڜ~qOC_NI0˂xe>Q~)8,a ^Wc2mK7~i^\v.vy|̛n ת™]^tE>EH6>i_Qk^U%BάDS\%y$P;cgP*Ͽ1H2y#|(5_ LH9EYf}p9Ө>(hF:Q0/2/գ|-׌*Vv8z#r!H:JĀCm𫏽 1xcep02Cq.<-MO1n[QkadeY? 쵒TU[#J1e5 S7'ӰJJ5D +Gǻu VtM݋ !//_7xhH?SI=4X߈?JP<].A`<`Pw@4b>mnY/iZV[ ST+bW9;h- WG8FήS#vTħs]o ;7-{-LTA>nWym+O$U#FY֒s)a )lo80Aϕ/ռhgYI!vhpgK- b<,  /bX s*RLW,S`MY"pY(ޑ&I5>6v<C!A"ֶUJF՗>j3oBm l% B܈zI5CѣJ9~f١ӧVI? ^bVУ0rdVhD _ ZJo=BO]c{?qlܶ>hXd Dh ^=;(^T$DͨՀe}kM]~N].ȸ6ٖf2n uQd.5Эu)4vNfg1/{Vtu l-> ]N3]JD]*|גz~hװ,ɍ\#ĮpG'K+o ՃWT B)r(Yp6m ۍЖ6WKr2N44&!i<f Qr}JېBQ3Zò z GBCSs< sB&G@)N y <^#o wu>m'℃y dL(Eə ̐@tVu0dw dIVl%OI e x&٤9eB)EXP]vcٛUs祊J~~&WfYrlI99[>Y4kCT!; 9Gmm(z>/J=i4+7bQӆg]i 1k{7"*q0A]y:!8~?྆1_zz(>#XCo^9&(X3 6I.~MS6r5;)Ojc&U&i7ӑT/߲Fx7CCGXMUZ/.v d2i`w`D`{W2F2QUxdsl Zs\xNX=S[w5CUAtfuΩG>U^W<*:i%2}/O;+a/U|&_&N΀Fh@lu_'V.Q"KINl~Q˻QYbٱf5R+'"o&|b%F0 4=%ls)NRL8" $\z~XuV"ZGZms ·MaϊY U\*ѴtrfI}o;j_cg,aA&Tsʞl ިxcxxBSNG_xdyR"hƌ&B@v^UDM68 0}>M`ǀiC5R#(\R|4GSl.@bD;fwJ5þ6LHF9;-kMq wqYG5f xg4;v/rekZvcZ&(XZb˸((2cQkPP_"XQ<[n3:DUpxJ*ץ.KX{ 1s]>!Vu1wOQE`snDi9P4t&F1^hS)%ogdn\QyJ H&gǹ _նi)-v4e+: V]}Pk;ŗ"j0r8Ow˜2_12O4Оxb*ʃ>z(R$R0l>4рQy@uG_ t[M>=OS|O_갡/fuC띖{Y/,N*@VM+̓w%^| G#ͺp+$^ZT1'kڧD<;,΃eacu8<4a Il0$6Bѵt#~?$x6d4!8e'@ wu+ D,~Z,ػqta[Ӝbe P`@=ɰr % 9Ԩķ+kphY ɿZ2aݜObZSb(0xN%ȌTܟrtr«ɵ642eOm50 :>*cF ?Xau.ġ_fe(zkQW%֬:0nE0rx]i'7 W#qc?+NV[~9O_s膆m ʔ ֥mJh_hy6Vxgl1x(W.Ѻc.xcHeAh'68 |Pѕ-OTBtw 'QS|ˎĀ!|J&}cAN\aCЭ^!aP J,A<&C(SrS i91(p~5)O!Qn r嚼L~F{@װy!P9q?DM /..ke,2o7k֡ƌN4 P-M(1!zRg ͑t3-M# y_da4IoB#7Հ8yy+`=+qdpٹ{I ~qquO}x Gς Rl/=`^, &x($~ABw Sfz%NռV|a*-o[б#&"0EI#J[ܣ0{ZecE~ԏ:w)B*kNE!)7Ͻp8F~Y\)ۡ*F [rM'-5#%tˣ@rbȉBHI T6#Tx&Hڲ\,o? G{tVyu'Oinʵ=?= b {;qDfE|`r= jv|"0F֚IxusH__v ?Ӑ^̉O_(ww ]Ҡ`r0?e6ϛz@\18gx|-f)5+M_y8B gy XTf@p,ihފUCa&(;϶ՉF;,Hws$a('rZ[B;O>sVjCZ^|`6~29me圯MSTQq2Z1t YN2Q43(\*κ.jZ+ >q٭z!~NnQW_ ˋW{oϔQ|c@togɶƯ afr۲ 4~Z,0LK%.E ">M [ǒc#3N7mD0v苜5$2,5e}g&C5lj`Jp)oC%{36=3vNw.F[TPT՚`ݢ,\VVN{6/"7!9h ͤ܉.-KVpkH =cҟY,fn#.PgV+_ =<CNQ`CD_}M*54/?EHF2MѾ?}dzkXS j#1v08;K4D)k!ppC_hMd➊K0dHxv%*T'](8OƇn[pJrHO;-(u Mnxj t,|U+P7`Kp-Z߳ӑCɫFA9oL]\-Ljӡ?Zfj\ ҀY7;nW(V ^X$0x~;xR t(d}n4V n)n${$cǐ31TZ%$FҾDY}Ҥd#OU`t#l^`#mD*#/Rd 6qviQ%Ld˖Ȟ2(qʛ/<̗SdFWdۛkFfȐm=l>SN(Udڰp`JIl"`avZTjGG ">, i'X ʁS@K,z,pP*xZUp2Ξ)8PU<0vN;J[W/ȇ/:5O~<%'5yV2$꣠HYL[aWUS`)cA?x S&v*T*%\d'gXix0NR mb3F] ^ģx&DHsn,!<+\IWAN[XsL\H,:FOnUaCB @O Lc6#2rAedz6uFYzp^܍p/(=z6 >ɟE}&*n1&׋npC(0̵xt`VIB.qFb$9 +Dd",j Eżz.I|ʈ/EhzX:Iy@+wX^/~->e+YR ̷/e>~악RS'8- ;k4w}m8,#g:8sy0rtZg؀@A=ZpCaG=K՟GV'2LAhn)wZ 2:3::rCNcfB4ccVv( ndM-vޝ #\;ƻ_&1̳fJ3Qn{\lxڂ'n;:,[\~V`iG4%$Ȏ FttL^֠S$`Z {lߖ)Q;O\\p{G񦚮1#RikGdh҆)*+?pqekf3p| ȯ4M=՝rgRs 2 i/I bL5C՗XB >-Q ga_,Y.Y4b岑p ͝Z]hL\/a+0h*Vo:nAjt'QdbϬBz{?v%vdBnuw|- 9E*׾hq4(>>bA> )O=(9)ľ Ăȕf}66Lq1YkJwtHr>ΐr+:pl Y L61 ̔xtuC~: 0A6Ey3 # ̭* w9V^ڰt ~8wPpI$Mbk=h }= $'&={WDB3['Ѧ;4p"yS6 tw<[k$kgv*tC:{# @`Y(g -RjِBNvН8"sCt1PXcR赧{oE!f'uT{QN&:DG3~^ Ǽ,mB>z҇_կ JkH L*ZOp_Zy5h9OZñ[/}x%M oj@6#\h(e+DK3Q/6 oMYM\n<]TZHnBh6vS93|z1} VjKqb7sƿh;q`׳u29tH V&){tu’է{J;Z>bsw l4[{SWnolNzJƙYl>qE'2*z/BL!ozIQt1bSiNq],_v'YT,Sԙ5IcW:3[D=OL'b|R}/Ip砄#:ʧրn 59==)[t/aTTW(8W*pc8}=a)7=Ȣ`y [Ķi~SnANkLǙyJ"HnE,=)KeD9g4,(ZsĠ4gO븹!w沼睰ĸ! dY_qEiUy [3^em\2f{)* ,h6o] rES}%}?,o/:wC3ZR6J*k ~{ gXʴ2oɱt0_\u*˿#}˚dA@) L7[c偶SD&-wWt_F. 3]u;?9# E@J;UGl.XyT .5s.kQ[a Ȝ+r(LQ6-`f6Wjj)@#%{g 1T/tïA!ޟòͱ,fn1;T.},])&=O- Bwn/kRnۜ@ca4pqDtS*hmCx# ~vN<\A}.\Y>֑W,4 eW̋9hhx؎StT/aw#;60}|%B yC5V> c] zFChR%AOq$I!w w"T?]5 c 땰 jlϤS;*k'`,c f]FwHC>H6}%g[YaϹb(FOis̗I.Ϊ5LIeVkˉ]Ü0aޚ*F.C _Yؽkೳ% ֳ4gtc4C,Bk/BҨpWt3mB3uaX:5L\GS4%Pd$i^#i炨˾6- C{NOjCֵ߀AM%lSLY4VS?Hi}8(r&P`{TjTlY|Oq[ibFwUIZKB9 (_]+pvoTYG͎Vx}jqLI(]wmQ VSAËp6,>&.T/oݲefbL.f ¾]pl.j5\ Ny~V-{_ACQ>0MeZ4 Wk"ieib ӏ't3)a n|gST,/gYhژ5.|8bz꼳׻wP#GJ/0vBN%`pȃHsYHL/(@SßcNvwsqWkjqȔ6;Ltۑb:3 ڝJ !Dt}~gח uX,twd:\QAH}t&=rrŗ`%Lr:Kd0fnpCPڐ!s䱟 mp-ŽAfQ:u׽R|&g NIaNUN܎J t5tZbVH oz^6NG,w pzL)l>=bhzx~.#2,1N4[DXv<n@%D#+y'w^j&|fOW^7M5R 9X&7ވ#y޴,Pyc+.Ԩˀq_2ʟR/ԒfH+-mTxmXs,~dtسި3#&4sKEVϼnKKl pջCN 5^*Wk؋^t|ZS*쇧)8?I9 gi6ؘ#7>eFXQ3JNDܢbgyfS $>ffھܯI(/%mf#ڈKljm8GM*d1g-mˣ nMEoX oHf4XoDǕ/OHGTDAwmoh}PAPKu"| vZY}0ެ~P.wnE$m.*ˌYzOYEStg)F\Ss07ZȠ:¡iy% v;=qg&?g#tZ_"^H& ܿpg(F?wznw;5^|—q5Ք?bI܄,XEg@,u 4)%۝fǭA]aA x'~&__O.m׀S$y +"L(Ϳ3op699щtIyY#f9ˎs 3"#pɉ XF8 y"Ev O6jhT,KPEIoBZ@{kLBNYTwb "H s9RJ.gm%j/ZnhV<;$r}Ani/LK14(9cP`ߑ_b=E0~[utP5J 2lV ,cӠ5{;4ϱ"Nù4Vl@יOEoeUwkf«AM= *CS(Xqϻzj[9] *>gӕy9,WN)<4.ZQ3CىyfVQdQl MR :F-dޱ\KICxYwQE :?Yf+ΈTr~TVu>;%:Ի3ͅ3&~ Zty#rdq#꯹!1_`* jGj%ðs|wRƇv?Xd,"K;bƵӁ_\A{CZZ5΁v㉾, S:x:No#%^)S{_gN(P"2@-joH>T0ʞqƲbgCL-/F)"3vrLʢ ʹa$G3ȝF$  Ey<%MDZ 0(r[CO2YI$gi87^%VUS%YU#^P!ÙWɄXW;D@O9\V=40JgߙhEFGdnkOTʇ֢x1@Bf?)5toLp<Cq%/BSn) #GI9{wL`2\ۮBun- ZA >=,0VʦA=;Cfܿ"G,iF݅6TyD[7xNf >lBO'P耸`hؔF)3eqUbF!~du 傛 \e }Nxj Eu1 ur OAm]eP_TeD,o"jК$n3R!y$E7H_cy)SIy5܌= PxO}]q6 T|cy!=8Y9l(r*,u˝>!D_i2ǖU !D{W D8ʍ ~]malup\wE+w8)L2H攪$Y@.0T2_}v cZ/aD_=,wF2^ /UX̝S`4[LZg_ȼUWT$&D{0)\s 4:j42˧${N)|-? y^~!Gzpȫ56Ͼ E#+rif&f`'"3vZ)IBR,siUَU; nd& 6x1]MK;U^`&U<cUXOF:eVfFDڀX}SJM<=*]? *>6a}-M_n:`6psbQTCtG"_6!&H/eE_i.TfD*#KeOބ!# tFځ/B'DH+_"UPqѡ g5U \!qy{p7"@xwo˶v9% EEMR=ҡ׎@u~~663@Ha锜K+S >";vKco虭M 2?|Sh[,=/gRGd NMȟϳ** xHoÓ-TCư 2˒ԹOQp,xǹю] YUbIW8$4控I` gŰ@͕]"9@%] U=ԥ1.!Ce/"cj-P=N{y藅d&4k\]҉5|\4.RtᰁOwoN/cV;) ];̔e}`/g u* V=W6SJ% obL"BF 띿hgvzItC ZeyŌ׀ZȺzZeA菄"D/݄r$FH3&ͩR%'; ܑǤ@0L{^4*{3j,:f),O;(o|yV DIzSclڲ ɭܛYkV`}+9F`vmehAt)"max=O")):'D3P~\敽߾-\)PɱQSBH:=ܿ|AŚF;訋U%v]`GYa|g=>أI9Dk9Z))'Q`C E5kU1L_ MX/(RŗF/-zT﷾\4%T*=Y@d;PVQtv%J8~j& V%I6&/Z9Oj)BČK)K" `w xJ-_ dto+\̿P'>sQDK3?|wn{CU" #? [CD<4 ۏvOu>WRbjQTz!&1_ʘ)kfYOxŪ=-a o;RK!aQH6oTgdЫbWL@r~SԹ*v}ZV *#td[멫+y^a}&qY20Ufn~( GH˭ʹ oBv9KD^0$ eun)(FDbi&9l޿P@oOxo"F*:MlKS*2P \%VzqX}!䰐VD_fIBd6b5\Ѣ}HPw!I|g4 % 3I9ޅݽZU/eE$v|b"%k$whWH;\sm"я#D_Hw~ē}Z"b=VnwvۧA { YsW2Q,岀]@_I;c>i% C9р _Im+ &+Q 4y&ٷD#tv?rԣI!?3M\6d?O}a< @ynn(Q(٧^dSs$8iYEZ voKN垈#\ ӰY[n joVVp/Ơ%^ir9%ٸβc>&Ft]rB};q?K18r^"]͔~S k<,Lg+џSCxٻFceq0_Ӈ= 2\!8403=??WD"ޑtAŕx&2l1ݵV)jK+nA4KE y=_"cV*0JwRY.tuɠ4%j fdžƯ#L M̐;6U,%tͳTS|aqiqSzC-.Q40"v`&GXM1سuLڵ'<ҬIs*< Xk/ Y5@z")zȸ[ dGy+8?V1 !eM 403mrHlv/M &Af‹j mBQ'(@YV )T{Bϯy-`õ>GoiM3Fpďx(l^~JmBB{چîmyT ^ ÍA钧Xhp|nFrrkMV= o!;R(5z@'¡$a|8GPk>SJ<PJ mµuPF-*F h \>3`":}ty++ m;GPk,Y90%o=vZ؟r+&s_2SPhНu=֙"oU%Iw8jՔ V[Mu8B\P $Fmhqd%b =#ww >qUmrPV0yGgd*o59=ڳ)5 Wюv/Gڝ0W orAo6=g ((j5tV*AɊ^'k]a>!{@>h> Qy/Ehg'cʇ+UaĐ-Fφ|*dXàkRβ@ߤm_$ ,b"oN+}XC++)H UY>5 41[ 3zP`L-s*ݴDN㧹%T3j8X`)T}@6I%B@w8ry!NCX/n0r(x\AZ|s )]TKkpjA-5{-a|t*y̾Ml,e8\Z<9LǎG*SV>2OPfM\<>D&~ܱ0tK$Ci&eb+kw9R*;")PV^&1/jXxA3"XF&-_WWzЌk;y^?xp;pYTi.hTœC\ jTeO PRIms[ܿ=V1tn=濦.+{}i8'-_$n9u\NkDwj9\0hW+eDVw~A$zӺO [tO֮9&/cY(*H|D6 P^Z(밥`MPgb,kͼJ)DeДrg#Qw^uj"P` 5h_)y`"M8|+. yNy[W^&V'4szcUv(c̢;0@T40Tڷ&wgS+?u734,Cs0шا[y],`WirS.hLU( *Y4IcFs t zcw1;8_/Q0%9HDjvpe׽4lD9\fZσh9t"=A}\VڮzFʸ%gג,fV02x3jniw=C|x*{3rt t(PvhOm8SI$E :}שc>}'*k3L~M[2d7e] ށJORZ3wdb7Fm<۟1fU2;)Q=-:gk}ZC %{"@Wj8c.$*㚻WR8Eśm4aw6ABEbI%%x\4@@oGNb[;M'f%W*- C^q?;]A;qt44"i^c=3hƎi꟬d|^#Gtr>՛0?pE`oɎ?#o.{ǵUnp2i,yzϒmTJ 308E=5gRs'c0oP!SO#dwrKk [*C l[ SW?xS+ZM;-bQ.DٯR2ooZp6yQJQ"8I'Zd[6r4 E{+@͵?f -![BU)~BU Kv{-w}pC)ޤXĮ`3VZkV)'Gri#~_|d贌Ӏsfn'̈́ |bg LN`zm5RPҫ\ e+sTsyo}u̜@Zցv烿HoFgL-)z+(.V#X,{yl6r,~ǩMB )4]Ymvms5cG#SfYu1MhإtZ<ܥgchQ8LXb%ˊA&ò >iƂJU:Z%պxrT lUwsjГG{!T*an(ɟPjdܹʊ:|<}:ͻ]$}YM|MS{M:BU6dߐ⿱c`F7)֐ Mr ݖ(ISӢ,֎9oEVBy#@xJId>St]3 0fHbyDF(>Uj %E37Th>DjRF~)R-S3Dt&v9JQ G&VӘs󯗣*o]Ҳf31-0@J%zk9tDG@\1C%;\eRZ6 2w^a_%H%|}"_HH)g>&D즎L0s!C` o="gf;A +9X؇UlKNlE)"[aa0;§&FH!u}} Pkpҗ{Z^PҴ+d6-Z2v]a0 [R#4ht۲N Ǿ75+{ձ'H3(DD{CQ3WC4lRV=&&doC$uɡ8|rw4TT1U `d\5]s1ô׊dxF}`|%*j}#ġpt ܡlu;|[DK_gWghfhɎjqb0mv*:zaLca)_un:fOio-f(Wʨ~gY;M?bYYwg<0%J1WU"c*^sבֿ¹K> ]-׍'cFs{# %'@; d9H,/!gK XrO:j 5Da4J euMfH{ 8jk#]&wV&Jh.Zq.149ϫ i\KQ 1EMuǾF7[ə(F6ML%noWòU. ]ΉR}pU9,haoW{ٰ5)Ҹ~m R(Tn#bXj9QcAa3{x M'jFYO6T(x0d42h&N t N:$*u#Z@JJ*8B:ަ:MC Z*99 RO%^ H: sL| >*q G䘌 u7D_!!ZOIrVdsi5'O!ϊg;6wʉ/ v0ا]| 6(MW4Z%-'/JLwKky~V>{RJ1dVCU3+0(hx NCpQK1Fw[>;9N ۃ'&_, G^2sa{SQT%`EȜ1΄NWzIhMJ$_]Đ3t"<jr%3V8dwIXf6Cs*z&#ԏ7h'^ZUOԅ%Qa'\\\{ 5vq ghtv9`ֆBq:7|Ȱ`HOH$6ʟN)3sl-GX[&=CEϒX3> yVh&"_Pi?̀<+a?7k6 7 +Ɛgaq@\5>`quӾItt q#о<$v+D2VPhjJj" EDm*:@nO}zH/Q\o0zYLzn!Fa`a֪Ad!l]H?ZtjIix`WfCcʻov[HDPZ#!n=J ]9RF/qq _({ q'Ǟn(|t*M;U,6_ UxkaNePpJ;cbCv<>},/prlGhzp{i*b|ShfT{%]x]\نrw,/KXky@N6L0cyJY9ਣQ@!Nsib}bA0QֵMe"OMVlVHOloPkk -3&ONy!NKh :\řڸk ue@uqRU@nj֪҅z-YS?Xs%Cz&K5|<4SxYa;>wcA,츉DU,?`NICR~\Fz fTyjrx kMyPne//Z}-TT%d bƝH+Ae{bz )xT a^)m5 ̡Wn+MfvMdәݘTnjKs=RYQA@Ѥ}M%zYT]wzY!$=-MEViz٬$G% ;BND i2a삤2jXU/XLzw s&oGl~XF]vL&pG4u7[h/{"Mb5k!U(^E39K&dl\/KMlDHE=$p2j$XWT޽KK&B:Ěb̶Sq)W@᫥@5?~DZ]; +y0LW6axȈѭK`EBx" LwX>mw5)<\<"}12q(d-?Ռ :TվCKF"KF7"{kPX|~gho8֛=&!G'މno5~R~'$z#wcI|*Sgv] NhqwR }Be.kq"S]cw%DB7bcxմ0lEsV?=DZ즷8͇?,= {슔1BGDFoȬjKZ:hwҋB+z! n I;8X8E_E_`$)8s*Fxȝg.KS5lg;uV]u S'etkSDMоf cad#iFxoQͻUM4VEK oz~d8@ϯxwQ޷~*봟$7wd1?đle 5}85Z Xƌ%Ys/%TxE[[I!q&+6UCRANg"pc_3:@$.2e1HFe#|Y9I}z53XKd^JD ԸL%-hiT3_jGpǗ_[h+n/.bn0<'UG`tjNCQgUv/,A-׊m~_Tu;>6GjL?T=iR(UEj~+WkmW.iY=<"/R$0Y2UuL --9uGQcf[;Iۅ+RG7UCB͒!.Uq8 p6/wEkVy7pt@ĿP hTWt.*K$WPgic7;" }Dp qpBp[g1H@ Cӄ.!bf:C֐`Ljm 9^[r/w`!9cONc<8|; s^/6ymfG-LӇS!Ovp4'4_#$?W_7>^/m0aF{bf W=Qm\1g.( Mq<*7Ƹt UDyu|04PCPlgtpd#FVo؋٩:<0&~_+4p i Q. :w_Vy}<`354@9C Gg~@OMrJܵli;+bumw?W mh9Pv;ZSnY., kOyIkR9ySK.(E &9);+mo7u(ʉDD&XmǼ2;ҙuO7bVl!鿔l*cٖ\cJY:z*+ 56&=k@JX!6xpͺ%q"rw?D&" enujFhhrq34|.(V@ܧV_ֻTF}4^clxq|4_?c ߓʒn\dS/Ů롎O"Oc;5a©m`W9sʻ$3ϭGA6NCv\_Єi]pƵo~oxD8$%o[ijDX+Hw`~.us)#I! 'S;,Y;\;2ͤ [F<4u8\(iP6 P)%6yx.?[U2L!UB,-q 7nU|B|vJt`!sDLХӖ1oYύ2\I-ɴ P:Ic  Eq; 6IsP^DTLHAү2/P‹C9푡DKfL8V(ynFr:+V CTZdi]Z4ղuIu3o;{$8@*ٵ,&t)<8agmiT54o|n#IW:ҳ0@˦$v3ʹ-FZFZW.I]nrMuw vFHN9AIO1EEɗܞ|e`^.wB,6՚f9f: E'zZWE !`W͒!\UCPV ݋~(S4~1" 1J5-Hz6I`Z>Mrh.E%qdI~<ݬDqmC^P@Mvoˑ8g fOɴc:ƽ{%cqKQ+4B|?YY!h 2R*fs L`;r׭`99eUY*iO$c\cbf-Grbɘc?.jooEbǀ@%1[Pó RpBYV@GIy]Xf;/ȑ6F5TN0-UЯWm2GA Q BFX!2b=Za%kfv q8&@.{(h?aO?_#˥sxGPc6k{ز[!ZȐ vn[[eBW2CbIZ% &TS4e4VԊc9k١EF`1y:dR#~:V1xzg|Og{}ڬm]z0ozP2mDu]`H*d'S;ɿ3)G{;=WҤ5py/@pQ:+7$DžhӫFTkL^.;c?a7_ɽ.wH ҈qqT6~ֳϚ7?QkүM_66u(frU*]Z K7 $I9x|5q6M5Vt!9${Վ V+Ds[Q2Au;V%SQD8[᝻SkJ.sS {9Em%@׶,' m]I4|?(c6i/PaϷHń ar#%om:P;#fVM =F9{//Tm"%2YGg93]BeGx )IdN:: 8 Y#GiˊIR9ƍXSu VBtxy5{ddI@ t_PPm'3II5 zt`f(Rzr{% rħ%u%Yd/rZ$-Q ]Ε?E0tr)OlW@F[iz;Gj~ roQߙ^p ݻy4x8S¥΅VH+ _ciSbPjL$nu& &>{^ h[,hX &gHo h`=(P_~RDޡF\jmkH[:xCږ٘H{ڷew=%O%fn|jfnl**` ׉)A=F6)<JW2TlK؎HF׉]-=TB\R? "/],ۣA7:-Cb&S_ 2ʹxo/F&ψXc(9R*5gs~U!5hz!DöԁC&d"/lѮG%2Vc@zow9[s$#sQwDe>Bi-l7 fC^\?N(Qumz!u,#Y,]`R],K*'$q^^4 maXcCP}y.ߌ23_c㝊H o_J\-oMh -9?-%#瑝Mq*eE\@IҘ)j\!\@<))*` n]Շ&M7oP֗: qlxaq]<ЗpTΣÌ6 1V3re=FIUkk.7W­ԡY*@"/#T 6]GۢQwa8n|faדӋU|HZokv-^;%Tsi+2a^1x].jZ5S5/[=qlZ;X -kƕJ_.Ad^oy7+仆 Mz.b6'r,BuI!&)}S'o'M:p%gΣii__)I \7x ^H6%Oג)Ƀ#@+XRQ  +ͼgh‰Hy4CwwK\ҹzW5pÓ|ʀw;߈:F[%@Akzc9>œƟfX+W^2pNЌA^]bQ)ZZ2Edd!?; X5!t|M# ̺RgޯR{Q(_xXᯁZQ?\: PD`%P0$|Ȓ&n`^I3J2ot2G2*O Mzc"foKNtGHaKB7/(mڨkmDj(.W:'gt@ekqe>`5НTc֙zb-"Evfc8ȓ"0 [CQw|zL ˄0^*)q2y 5&73^ۓ3]Ǯ=Eok8: ~õx0B_{y ;|\cN~|uF5h&"%%|vK[oZr6AkzkDKg-"I KEU+Z).b)D{^؈@90"ب1:&8 օ7D,^b$6%PHej"ٟ!4zK-H3EH$[={Fpǂ&jWԞהFa!a)nYxu/F٢s,|uۜC j "_M{s.@C[?ju9~No #wbv(@J[K`mHEY Vw$O U+0@{@]GL4p kޯ 5Y;b1oUUYZ%4i؃]Zde9Ey~xTZn);U(SˌD 'DDgj)'$]m":[\lsvT8-}Hs5i)Vz9ʤv@@`1y]!nhW+?pXBFV=JcQl`-SY5Ȏ?wK4_ UU ȧMҦ|Q,1YQ_uAbYײU闶oU,e|K]Z mbuup+ˤNf~P4ۍ:|i$Fd(@%Ԁґ:/'KI}p<0q ?՝po*rsF͙_E|YA+:퇔:TSfS)Tv)1mk55s)y>O{\gv.OZ!j6M5q򟓶 tc=MMBdTe ).UxjmS(EIy0*Zi7j+i/_Y1}3-%g#KLCۘES#{C-12^a &Uh_6ׯ!FEQ0x&*C ZSӆUeV?zPbrH[|}>up5=o!y%[k zZTbpjhUrxuƷ%@C%n WɥEdVlcڇݰI§"#؈HӵkHa̺J ^-€f_Pt)T  $4M fΪTR.|n밨}'[-¶GHv 7T˧бZo2;@T8q]GkJhxi^a?l\&k-ܘYx}:q:3ɱF- 3FY\F@BtEu5 Gzj)$խ)_RB] c&_H[aDc{&T)]\EÊZˋ{nE&l4*Bm`f0Te2^@hR"-~9&zJ(En] E 7؀Na?`(0ո ѲFpJlʹsP+GTP q呏?Kl2s԰I༻a.@9p@U 0o*t$ "dl˩Z: }, ࿮FU2TRC~~-n8ټ'JYdzÄDG['6JZ)#wXTINýy0D~t5k];ʨfQ0і"&ĪLsw5yePLt[C5+ ~dubzk< Q m ?Ijڝ18tKmvJ$[֢6[b]sJJ?s=ˤ>i}2h D9FKLr!nkezOvMXp~?J4FSϥ xZ1Ei:s_qr׽prr"vEa%60'PC |%U "M~X|M %͇J )K5mK ʼ6FCHRplXVC$RMHب;GօGXe  >(yy} ]([W|DFd dL 052'*ɭYݺ|3P!5nR3s]ڄ89s;B l&%9U͛|)Ԃ P\y3o!a,9R q\8Ug7x|TbV`>Q0GuݠAG;&^_`8Mj>ALwo}]-kQL`i~# !f)_Sߴ4 I0lS` Kd7щrӡ lGg_*f1Ш:4 z'h'c[Ds,oZHǮZ{ ZT<m"SR;[c){nqheMF?*|.oǢ cw2Xi/պ emL002c HV TGwZ} Vck_΄@_үYzkԺo/!Qq][E7 㠻n.Y c١3S,p:I MIlO8QՂ}`(Z5׳'qm]rG)q"1pE?- ;T.ZڒJ(:ۨ0{4S3'0c1We/Z+F*2Km2JY_8ha3Ï! ;?9qx *^0P;YV.t{S ^sKrJ?ŐF: S{USCg)|5XrF*% hM"=4**9~hbUOE#fFS|1~7JBx7K_t*lIP1Q@__ndBP̊) @G頫AQ>3^F,GsjFkUȫ *:@"2,ѥ_LQ~(@#2"qՕ)"HE_0xK-o+FYV`#(*qۀɚ~UbD/$@Zj$"|[cn gyx#''z;. Lc`IڵcraA8\}ARA+>9b[Voɼmnw~΍G#Mœx7#e'DV $H! D햼on/Se,BMt~ 4 "ocʒ(&41?$mg]ݏf0Wk\ln'Sa-W Fd^H"m$k8Žx]Q7zJI ! wa w1HX%i@YD9|Q9(z̿Gpiǐ1#w>:[H[$-Q  Ey yG5q"50?E!;kER?0y\]Βp&9ώ~5%F 7K+of/ -L1f0yZN$.,tmGoƋַԯ5x YS!!>T:10I} 5r93 #f* ;`@\W"=ȟ!~;wJ&u(^#pWٚQpU=iئw@:E?xTd\wD]lu-jp .5խJ_'4.y+jҐW3W Q5Tص-+OeARU4t}IB|fSrmVxЕjKQ/;D0+`9e^:(7{Oܯ(=_Mڃ7ũmTLYX"X52!W|bU`-9JL8Ȣ nt1ҏ)!I%$W\F8u/Q=,[(C@g- !V1 ^-/Kԗ8R}sB=4^#4E]1tuq&Y8<9*Sgqqrmd|{gVuxomsTWX J șWR)Z&njY )ؖX&bND~bF>4 ߬V>u$/I?N˦Bd3hT, $xo^@mb.㼶Fu2A\5-5 4iૠ!&ZGBfz ӳ&QnYJ-b|l ?qA[uO@!igt hE#t4IXQ,eI-]ka6K`W0ɊmN{춻ye E\Q@Q’T,@%ֿr!]' }HK$|:C㐜Ɣq?/fT`k"<#har6!,HM` Kat_8 Ekb>#c.&4#t.c⊷F,&2TK$~Y($ /N5 4:@!)uezE}d Nlp4bt`G4ۅN3ZƝHCDWX*H@o*Y&Z 56(1:GoEc3p1˹sJUuscWF)&Kc;)%!7HۊCtԼ?\;Aq3!$_ )%E~7@ Gݢ>7@ahFfcGz2"wsÆ<^&;`ٺl2ӅM Q6 itL,J5Y˒QK1 `2v<JE;ݺ1GՃA~N*.H8|9aX} zOcb8ɇս0>4fDv",n,5ƲN|G :`8SV,-1 uji6L(t.P%=`ljf*N#XzgDaNEmk$)Ikl]${Mi2-x k]'y p(pXv*nG-tsסu}+>: Z糰y6lϻ;`XE*VmtT'9qVE9sqA+s~w@v12ὠ͒m/Ƅtfh"?ΞY2ѠU,,e0Pҭ&ucb%pnj9Ln!zȍM_Qh_}ȫn7BLKW#;T-[Td  ">i1hm5nQ qF>\L^7Z#CF% 4)[?݆DdˡcypiO<)5',-iO tru t"a (gEyWgSU@ysʓbu3)JKl$fo,fk0"!l@TOݗ*;(Ͱ(/J[U$`Lpݹ]O5qRTfqcSK@ ̕ Y݂ŌJGGmڟX*"{'ʀCaϞW.s[2x&Ez 3\n&^˽Ǐ,eRdGy dO,f~-G`*X2Ḷ =!We Q48vdB/5T^1N6*&_i+Ia ֙^—%sF<aqUV]S> l*QHpz7w#;Y b(i7r^]cN* ( 1Mѯ /ꖘx)LUj8qRYxAruinVrY[\?54M㌳F OH1&HsBDI85 ԜrtA3SafөO^1z5 &|TO{ֲ C|xQB\R(7,KEs{! ,&~Oyr?@m1>'i p6szɾTI;=H}1s|@mADx[?Gr->`]'`:PB!,Ff593c A6ٓLpi⪣+Ԭ_~.5.:Z6PFoĕW[(_3}ʭTOOw ;%1+K4MJ$6HEh~]^m" E^?4 wc 4_5RP'’.6'J¾rܫۣyŬgr! E \?bt7~#㠡yƄj/_}q%gnԺtQRe#${uPij 5%-K#a1CmJ>XJ2Hw޾.fy'`'-27WϟG5): "a،pfġ>uYi}O[nL5FhExVDW Fi8Y"Z~Żq%Uߝ+m <.U_I#g !0aoB1B|s3ii\F_Fq^^RhAL6ìmo'c@]0~2ҚjnSgbVe ^A%rsW鋌AE*EPJUK##ńi8[4h< ]{748R s-]fԱR=l :'ۉɣmW ~kasboٔGQ3~HH`"ѿ̨`lBQr SJ}3䞥T1593*zaryX*Z^h@Ό+[%7px4헞nz#VIK-؛X{S Ag9_1 'GVRRkYY!tw*t(^GI`qh`[ ծ &XwWn4(Jθ& mwK< G9hp oz*f *it?MO 4mGY}y^iiE&4turάS>-o` @Yh ɱTMb3[;85gz)3TO|`\7*bW/ohucAږoLq✦娘|]0`7<[UQ^ V"ŲbT,+ow卛XΡpF] ŭt] ӆJq|i޹Rh٩P72:1eg$]&9PvQcfvO#c1NAXr@VZK 5R3}#=8l0 e_GG\i?Kt%5M>Dj/&G@D{ɜ79#٪fDtnڊ7 )jϞך)V4 ~zw]G.1#M;FjIwƇhD#c{^ ĥx5uƿ jrjrU,@D$`)v5}}1=1('1 snHNgrىeFfi`/Kk8ۏ앣Pu=M]FUf߸KW)!\6;C>5Uܺ֨+>6!Szp>X?ձP~zD=WZa\ fb?˂K~zOde-q(ϑ1Ǜ=zv`ԳǠ kE~͐U('T7v0>9P>WȱS=|T\9N\kn볱':eG%P 9W$N&=ki{da2fQg\j@Y [UM rSv=%2DZ.2-Mmb{>,6bw$V$R.%AR]:L"RҺ\ވאQf#1 gXe7On^EIIM4C!iV6abȢXr~W@.i^o"f~b%CF9L SzτÏ\85G]2=D)T@ǧ5ģ[*&ζJCj#4o' 2xdhdZ]Yki}}Fb$*jiгxi7s(Pe~NMkD?Z%,]ʣ܎DW]qxqA?:x.]`wձUfbn} S!/&0sZ@2W?\g ʐgHGcOkQO|g3WNwмwA1Z}.>e%Qiu\zquX9m)aJ_&41 k2/{ҁ $sv i9E]d"nM0vXNQ`? V(;1!,A ) Ďlܧ= sn(Mm# Q(D\e@>BdC eyr(FӇgsU ~LKھ=":=5*!BZi~X 񾆓Opj6%Rǃ"4Q*FZ3 Y ^nƌTi Ns{AI9If@c'twV;l0+,Nf &6p346"sSfwez1'cNJD}h |WPRe+>cUcQ9='|M+objcny=4!bSqO+c2L%^"l1UOj߅<'R{YHuY;K խo'Kj~<7Gh,8JOGT<^o< \V 犚:@OF΅_-J/3%CmGf>qr0v Ny{mS  )<Ҟ YZ