sssd-ipa-1.16.5-10.el7_9.12> H HtxHFb' ?*}}mIjct@3p0ߏˆiBuXA7ea298509c11233e62ff8fed9ec61406bb10d34b8kEuk1fo"|Fb' ?*}}F( *sk@h7Sʊ~xPnBNܑ T>>-?-d   ; 7=D   8  8XxTTmTDHM(\8dF9|F:uF=&G&H&I&X'Y'\'8]'X^'b(od)4e)9f)<l)>t)Xu)xv)w+x+y,Y-Csssd-ipa1.16.510.el7_9.12The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.b sl7.fnal.gov >Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKq&-A큤Ab vb vb ^p0b Cb Cb Cb Ofa1bca0ce3e9031f2f44946af685ca0ad569d56a8c4e332741e9f5d87d3df6eacebd256b07b448bc1cef673d1b3a5185660d8c59e4eac9ca88701bb13c90d3908ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036ab26822fb75569a43df2b9bdc4e9f79fc633addc6b19e7c9d136b116e19400cab500ea4c5d98b49ef6374376223295dabc509d24fa880bf4eb68a11aa678ae9be3f341afc163d96dc1fc1a92ab07faed64d353129d09ee968d0adeaeb0c59d8rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.12.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.121.16.5-10.el7_9.123.0.4-14.6.0-14.0-14.10.16-18.el7_91.16.5-10.el7_9.121.16.5-10.el7_9.121.16.5-10.el7_9.125.2-1sssd1.10.0-8.beta24.11.3a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.121.16.5-10.el7_9.12libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=30d36eabe33c9a22ed2d5c2abcf5127585317f7e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e6eb76c037a33a556d990783c1c8f8f5fb18a8ec, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER$54/[Ĩޅ$s&xP^=J(z7*nm GY-ƞG'CG}[_+oIؗt/8o}SO AʔcR^v[meaL^8|/WDFHӶC @WL '+zXn+3MӌعbrbGӽQZO=Om;YЬ^FGJfL˳ТgImG~тiSsb-`A"<EѤWBم^u.(j CTl = µlnLi8{a6YI}ڒq̯;*w-Y"VZ@(9L9zP%2L-9wכqjfD ..$|Ȓ\>es{鲍Bf|d<{ێ' VрD+0UwHQA:*.%E'6j[/;Rz =-nWF=2.2Z=~P",^ub'i{zzhh5TK]{&v/yYh Ӎз$N@-Yպ1 Y_X/mDNzR'u`ǩ ڄ|oDbƑD&>l겁re̓3kG/+S)KWXcm΋DyQH0۝NOSGRC0EFnuVIM{ǚ"nR B5[_ <H*\-$$8v]T13&Li c̈́mLP^q,,l6o`¯sً01A8AƒÆ?tce"7ix}61!!$Odq@}:}v~uyٹJ8ʤZ7 (db½c'*+i76Ncީ- U gBF9B<31w iZ+(+~1~hN)xP4^;j7A+ {qhk h2ٰjtWv]7aI$߲CL,!ĴRN9yε m#U@&ndmiΑ] ۲{)EZ+IRM|*&:vح&}Ej 4sĉ< AMz@2 f[" ԛP-H+VnN2X:/j[%"F!t6nó_6Zu|gêN^C*'\v>\zkU2-R5A2ٻL$%ΡQ~H`v^8kll RQFD+ެŀU"\A(;uܥ xzySLEgZyi(6 {\L#m9ǹ PjaK= o.D|p/#|w4k`}5,DO%6<~jK1k>5T7:3x82U k5# >=E. ad A&H1-_uh*{C@Cd{sR _=L+\"hޫ#.l~F%:$l9<2-{xM-Na9ϐ9)|̇HOR,8-^.FO}${N=7 ~@-Xr_YvC f*#$̺zy.T![% 7!noE,H;zE'?ԝVn8Qfwc"$LPH$

s/ B*qCĀ/Όh_837QiFIofS`ݵ=m[B :묇D#[AbfVkثt-0`e\c̛iשpθ|JDgk3 k? ߇ 2 !q{!)w;vhǢw :\Ml fWbdoleSح}v\ez _*v0ohjrVf# {O$cwLgD RVStRDC9h1n<eGۗ X Ўv))|0F(>24pﰛ]<8+zXnr?N[ob CMS9 1րg`d''GȊQ~CZi{XZv4$ɐ tz|Z.d/~Lw"c_FHDR)±4ЉS,M̈ZKsH+x7j&,oOպG=01?>Q?=ԯ>NqXJACvqF4C|Ǽ"HyV})uiC :FQ[sI FkboݭOE\r4o[ ^VkpSh ?-끀$nCNxnռCBata3Ep{"˷~4[߳!3WC?3.Bh {qN@A:+ 4wӴY'(1?!jdJ|P5k06Y.Q$䐽4oID^v_IC$oe:]tٺIH`쩍'2逿^:CJcmM!!S%O꺕osHMo6t5j@ϫu J(43S'R}#%| ޻7c=sE PBppđv}.v*@2,}j;p;ES 0UJ`A`g eqN6ΛtJ{(,|mȅ}DF1f{l9&6نJK;!xQ1旻2N:Vmmז=ҕz_q! Y hMNUS_"L{_Gz w8YvYdcu{-z*W&~w ;&=%uT6jM]n A$U!6S]/j9n]2E].\.j`ڳǐϣ@֡K]ZթrW!Y3"zVc_ [,c\4QdDHAbApۯXO-›W)6:j*Nm;|v[iE` $"Hu͇S\V/(Q'hYIk@6YMw! `2z~F3/ $qNR&4?,pq 72-Hu^vz,֚[? DΗ3H`ًz,3Z_cMZ2?;)iRt u"k:!^u5t0`0l~;/ |l͚6 3( #(B Z1q嫺$R#CĔBw|7 &K,E*0; j7O(`thlG6)K[}q(!L0*tf2J1c𑤨IAd}U:KLĀ! ݳA k&xӥYGad3MSDԾDb_1#.n!+Wzg ̊84m4TG =;߱F' L t-mώ ,Ϟ@IW㹬œTL154j]n {f1=#QFA_bƛf^B,&qc;aV7hW{㭙Fݣn m]4L %6rQ_})}> 3yim g]h@$N { 2cFmf)/H#X]}WcĴ]CΫzHceQNzS\\( ?Gt:]ʬR.:leV9u'O*rVY3ԏoP1QA܉zM Ïgr:%fm]C-U(vIG$KG.@"joH|ď8W3;"ݽboN27lAqw@`_j7u]XV;V:d-/Sx-J.[H#1:vᡤP{v~2*"`_2A^gcogV}&flvuYp-E%N P҂\meC36'mzhoL}cf;PN'<F=}ϘZ}?x>|Ңú3W^o?۴C] Ƣ"8ہ)QA4}ؔ}vϴ34d{VTkt'!Bv8a|뮏}JVs.j;9mqqcqItZ#hϳ>sNjSbKvLʚ/y[h={u(vW7h':s}wcrb@ _dBp%ZAv@ԓ2\IH<vRd{ܑ>s)vBH->@}+6~ɞ)Ge ~rTݩ{7 .% ipDfhPM)dܦμʛW`;fu 5/s.$ b,PVcKhU:Vp)!ñyth=MK@ __> .1v6ö`iwF. *4٘/b]֧G_ H$CKGXe㋇[d/N)=s;f 3S~@ݠvLa#]hkhS Zc :y$\2т XD_vw )њԼr.eo>HP hi@uD35RU5/_ nbT܆S۹ߝI}=djx>$l (a]bӿC#wܡA&dhIn\ؓޝe@SRA.K6مφpH;8 Žh快e[Zo6?: ( <#Y{N_Z4 :kF X2M͚I[=bbˏ2a5Mg 7^>hf4iYC-T}}a/Z^vF'bASd9@$_mxӿ6[{)Īi wvvT|֦.9'12Lv00/~S[л"hUX ___R"|Ti_y„M 8_)/)MrZ0!O$Q$Æ%B{]u;/wD`:7<3A& ʛE-zTuQ|˸F]AZa NR:}X8í".4ٌ!my~אViB[X)N~T{_uKj(@9ǗI_BFtBvBӹ=Jlb eѹ͑#+ˡIq Q `:ofiP(&U% v{ 293^#SD)L0#ZA898H[ jQ)^J0CcF)0.=(%( :Ȟ"niVORT?xr KYIDU+4C!(Dеg)0\DaÎlV" S|ԳD&z '@*[kҚ[qM' +Z*+g;hy wahk>ѱ2hl90e!PFC7 Qo]!hMV^gP䊓\ R4&W^0Og_ DUrZ滱+Aկf&f䄝'a+N"ЂvA}6kT\GhL_(kd/b,r_%/iMӝŸ<X|Tl*V[&3;C[y7a**d7<$]LKA(UEaI?J+ fSŞDyδX10ubLTA cx4\I׋y9 oJ$^*Ǘ 򱞱Ȍd 9H-qhe 658U0;`: p{Ulx ؖ ([-: C,}l))4I{ pX*ZE*yAۤiL8x_ WpȴxM/-1KRc  |;4F__G<gB#?'|j#h6 ,ZAXq&[yzpɫۋܝ>3 N @')m_NU< &j:vf雔 x[%q-gVZg9W]  aYryi9c_V3W[Gwʼn9aWqe͕ Ep#|"c Ӣ9ɞKP vs}@m,wHëm{:s<]zؠ^fY`9H7QX5 [sR'M"<,j+T xwi$ 5@*L&g>Pr1t|F4 4VKsrl{BNsto'rԝTc?1CafQGƍnU[nЮp9̟0l G"BS\ ͜X-ݽ>HkAO2fʯU*0]ДB$Ub@d sG68ѕKr? nra"E#va X,x␚>[Vloޫ<9Ld/}}tze sv`6ϣMnmpbF.z(zE,Ww0׌=n7faôX1A3H4*N.j1{Ln oi>K{D@.&K ),WĨӺbV)H'уR7ghlK yc0RY$1EhL-hgA|r7eI[k~9o{hLe`I&t <]j Fd;ɴxhb ȄsK|߱'ꑄ / KJvO[Rl Q ԯɾB̆&%s1~[.~&#ԋ¡hQv2[#KxB+jko4mWtK2ƴPȧ7AehJ+)g*Iff!wC֡#OBo vO4'XUřvo-m',SPHjUm.w_*19o|P-*=8QsRt{22~@Эgo@_8|a J鐇AplB6ۨ0~آB2LmE/>jٶ W6_" U\ǯR6u-JmiGb? (5ߤs (XT{7Q$[\ `H\ O~nǵFxH/-w%^J1mUkS tqxҩ|Ԇ#Ʊ>gĉ§Mv$/Z}5M8DVdעr2ϲ~+'_4 5S踣v*Yobn4jwgI>aihrXqFA_;Xf5;}gQZY 5HǾ IP"~Dc=HTgox $j2"75*+X&#ύ98"q^ܼu6PS}{v GCMY(w#مt9zc(T-*i~*&1q uE܃wq;@מ_$dγlLE!J Ϲ4&O{\ȗ;\{UWw8J5WK]uz>]jڻ YQ5WPK(A$c(qپOȟb>Z fYח}AP]Lhg1 1 fya\ s(j =& YShKϑ"޽HMk 4oZ뭶95c)AHģf_ȑ_ x1 WZd#sb7k<ɎkWvIu.{,3c>Au>(ww) &Pt镕# ;Rm;rֵ]ԒLٴxLˡ0Kacgη`/ ^xH-ܐ<-Pn.+>cQͣ= 6aYyK0x;0NA^.4U%uxc/쇠AE' \pP Oq~/Q>5u{t[Y*k- O0|ϟ9~Qq+r 3qჴp'H_I/uEfJn8%fnpFE&#-|ۀ X+\d^w W{5p6f@mv̂v3A -6F9nTI._ÇA`ˢA~`(^`o`J'TQZEq1^ -/Zj TzLj^Fk .E'F#۩v/(/u3Ϊ"2nbޘUDxr1vk[*BovHAuoX'.71unN̪ɷhl̒&@S k \ɛ7z$R ;i??ڌni"Rfu Q`l\_ TzpX62@j26GɯpqZIxe5t'u>*M$ר/ŐMyHsT'DgϮn">y`q&d! `trrv;oF>@GO;䘩oQڼ:7Be<'/׀q@s7NFmrT'U>!srMdBC[(+\%i1$Q `d;?zX(Ogr뺟Lk|ڐ|%-˓RUj$6у3Dgv=!q>pٸhWձW!P1lȁ/^' 0e?3:e|Jg6HOۼUZq˫w1;.L 9&42f%ֱKA)7sP2G(jGyV{9p߈cѕ'con sBð9E_\ѴDIٗMَˎh*%dYD j܃#gyaZ-Q¶Q<} $q ,tdUR,.+4*WqlϷGqݥ5gH)AcFTю{'3%=*ˢ~Zg Sjڬzw(o'Fmm=\$Yl/mJT50OESSGx@mi3Wbl\9W)+i4?40{ R[kʜڰtՂZ.+k hQ9Nc0j=wvJ@5iq.H 1T(l4㸋 {-Y{>;Gqt}23%V*v ҕBnT_2~>-]$bu+TT6JsblJ< >yB"c-hdobҝbrOPs\6t/7X T"t& ҫm*^ӝi:Kdfo<~<Z'L4DcS!wBwPǖy1 HgbJ ܰn#-R")_Ä\~ul.`F˙pd>-v7Pi1~t3׆Sv.\i˝a/F4X2 /Xz|'>F^htLQJfɷNeE/@AHi;3o*ژ* tq2,I٦\Q K_+FnHκP|Qt_l"M%>]&nuFD:tԮydU|-X ]6#%M.+HdNv^O=TY!" D0a[dgzŤk klNfps$&ܡ|pPQVixM$}@|4h Bk+F$|FwEC΁yJC']HQh*Lאay'z-h35z%hcꪫKpGVeנҼ77ɣxL#wfR| L@ 6*0LS6;@/Ko0sbPb(̙>nI ˷צt<Ⓖ)0+uI:|^0bS/칙爉`Lw7z謉.H'gz~J8RMlg2waW\~o7zg=ϼAM;)P=R \1!o 33ptulK oVz!b 6mWgu,Ԟ)c;ʶPְCu6u(ͯN8I êO뒛┛C=V@aD"_rPo+(hc<^CI HSo]'#ND*P<6)@_,fl.X7&_ ޡ Os?FJq$Tǐ<`YI ZXc.,1o mexj3F>Q<&F[LkT(yawfTE+r͞ʆЮ&dةH?q*ĦB,f\֟>A^ZQԺ =6H׹bDW;šh~P7lr(my 2&ƹ^$3.~x6G yXBtfAa,Beľ\Zc"h&b\4\th #+_N4,+#FcBfhiT+MٻP7VP$r0k ZaA!=ՂEG̳PF4cތcQ/QLRNJ'˘BAin nzuHtMicլ^p^rh!z$aUm ={芥c{l`ػw5} f>\K5"2x<ԨIQJPu>TG$UPi0xxE^&D5,vW@QkJ.~ ֿ /q yPLs"uvK:Uil'Տa ~cbc6kQ/&va!1)b 1?^=g+K(8bZ!||J It x)bh`fMӰѓű V!ykLjHsaXbn6t7Fp6xcDt A LUf–Q氶% FƂEd> qp*@[䫜Ut`y#T,):=eIbn{CH$춁v7‘Aog'&WC'"Fe\t8ZA*tqG%{= қ'J'A^|X& j> b_+&!b1%ٯS$e8@~p+5tio/ ULY,Yi=q:We'KHj4uP?, ZR!lfԘ;c%+H'b=u0S\{ 9Bw~tE> DdHCYNYWJ)vW.[:Ls"l s.v4H"x 7 #@v-zy־6I|(ʣOʆܭ4XeVlN-e'ў{j,& 3$MFdgDچCqz=jiϬb; YѫFGyH}8à82 2}$PVȰ]9\{gs%gZž z@I&s:~xtB4Ɂ9Р@sPUX_xuĸzmLOclf`q?f/tKr>։ {ɧf~Br|VUyg_֎"~<7Jn{f\_Rh#,!0WE2a1jgj$g0iL #wE3 wpjUq IȻSVX?6aY-瀋Qκ+%dTs%zi.{͉k&N9dbDP\[x昻D_#k,F@k#P5Nr\,fAjE!U6T}A/NccG#X\5? Uv*E8]-F<.ajJUoB" Hޡ}v$ 'H3S|kPN6gɠ d:_Fx g'}W(/R E: g^l婛ř} z 9V2*t [0&xH4NFnħДԏyt-#\+y>j7E2e7-)q %$K۸>ڏbUp y1"䫫hgȷwS5uQC ȬA˕2c͘ބmW7o%ri:CwR0-L E6Ĭzud6 ;!fKS5%2Ý?ɢ]t3ކ;W+X2T)1Wa_BUiy~LtLɡeA~&NvzpiQd kcD?QsGy?Z#uE[rn \r:[2BťltYIPx!tFNhp!жG+QI&:v rc4Qԫ6HtLX"\n-&ܫߎ7pI㖢}s`N}f'hY_ Q}Z[,n#i^j'(ef? m$STx$N!i P}YW "Lٱ3`Ν֧3b7+lό{.l>E"t`yKc3H9_m;~U>؀KbŃj1:jEeW7E}ʮD(J Ҫ}A%8 ]uHj=>`񟔏?eɋ>9Df(݊IA2됔XhƐ&T@*UiZRPdSnV\g E|IXY>9QesbH ';EkN EJ NǞ79ؑ\ٹe>ضy{RfTK~5b,N#(>en %umҞG imrӖ:H}+1'0Ls^o7kkh@$ŪwFRtrhv@&*U&8e*n l׋i/'flq5$`:B0; ˌy13K/quLMq] Pe{~u4tGY>&2ەQƼM[Ѱdz1qdXna'X-g7 qV iJrTϗIpåk@ap?yS/;XTȯEjY)3Wqqn: In=u%c6El-'oY.u)䍽Q$_dC[z= $@0QSe|K);j!Xqӧ%B4z@2B-K{# Qy%۽EvT'”R|}8}.bz(:n$M*>sWX7۲X4;ծ \sd]ƍ`g4鹄Dm(8M@ "vN\0갲"˳W{F!Ok<+$ Xbh&x#i€ЋVM/yNVS-S*ș^Rr`O$%g@@֘? U%Z)b0]: L !.vVcL8iJij4v4Kw5|N4Mx # OtNJq'\3 I~|P D/S]l{#'){4j l+üMTR@Θ.[!um_֡ .L0]{;Ws 3\m*Mr3偅,2"+N{hN4sW/a1;_%Ͱ%j N{ZoSVI-e]Fvn1*?&%|*-sE<]fn2 z.j[^tm2}x*pWW2\Gps3}PkK}OU(Ab7/Fd^V2w%$&5 'SAKx, q8~av:Y6u(b&7cE`MPh(ETI{= Kc>6KNO$ }xÛ$2[rnYW}(mךvkٞbF.E[+*zN= t54s:Wh|OW Ww51½4J.QYzLhI:f~Xlt!(ʖUU=8d2>i9t.Eq$ܱ;JVxuCv'FId(̊3^ܗZjʸ٦C|CV5bzg^Ȑ_4jw 0u *PamUfC஄{{sϰ'A Y[}_0J@ ;'< 1~fɗ, Ot2a; 1H?^#2䝧SFjD<|kn*:dOYⷬtl [pi3zU[~npo~ ZjNtB~!c%%/~ KVSLзiRZ<}ڌ_6&!NDJHx]`z1HT Xـ^C1 w5C֌7^6b/"6@jE;=/C+Šǭ$Z u3X)&]5 "^e8t&*Z5*縟@Bfmj`Té &%SY?9yҫ4D*)RvCsAJ ?"mp1&VgelՠE0-NI1 UǶ<$Sy쫝x|Z';fb΢2L"m50VϠ);O:qChUĪPF]$1?#cx8 /Efj?tG" ҮʀM&Dwf2)n`06 S1=& Ww+ joLLYb/lrix8=QNA}}N5%/=6M1KXMUsb{8MqFin{\?K3հ$BQ*]vz@_ )$ѳvWIaF"q3bgq&z ̬M4#[0o2\߫_9=a:^N߭p^)^HmEkZH %8x%$r-bܟ~6t4c;>_U6L E[&{9D.I) 3!6{R\D:o+|˟jDR +AUM|SY-@ɣV r wz f8X!A+QJ}_媸LMp"ro 45mU$=6YRDFoQ:/ tEc`o}3_?^}dPiiMn. aXuO07!jUf[VOTr'|9x*!աv,IYL#G%Vw5UkLgQ:IISIFzbȘl(T/wZ5Ȫ你wdvyFҀ-1+z[ Y`(U4o6t[LƇѹ}ZrT%%T<nj8};$AGq큩oaF8n>lߊDPr7e,?P%C>`S~'s[E`(ME>dVw ư˳<90 YWlC4aQdo>AO/8FkK\ie{ %`J\a"e?@[Fds-N6 e1w@RTQq\8?4+Xր('Oʴif5۳ {SR}t^͡:,lҷ_k/@{U;sPcbe9>xE ;f3I Nc65GhXdg҉!q˹]ySin Usoko^.A2΀K(( jk|i8Ap.ljjɰqSފkBc]JF]? )UiZ})Q@+1) r\ OLbPSM(q+F qareHj4nl!ޝRm ?y'.ĩ!_d^/=_GPkԧGDGiq#$ SV0jt @g0OaݱrVf]b">3E]S>VNJ篇$ lc U_Q1L\FmHx>z)f,Mbl,  z ڍw镀&gj2ΪŲ<=}Wn!M(rd՗U3sdPoT"|VRw& Y4f="uNS,;R=q6! fN# S#.1Qv@ZQW-ه&b|tCy;u1_4b6qLcKIi5&D)] ߔ a:0dP+mW= JPؓ{H $TҁXn\O ̉ߠ:-a ޕ\3 h:4 B syDq_# M,RVtEt_ď{C &␅R(MQp 8<{X}VI)6ebWrM77 U=#dz9].7Љ\ܘsR 3P ,ПcFf7_?c ZmE#%&.» *~~_TfZzȡ-1~xRstPow}} OeRP ~"ʗN tol]#˩il!X_0H>MqZfZu)TBDӛӢm܁Po!-2,Nדϙd3s{MCr̀z?SvAuS=e'}cr;sv=ϷLWC,qҍn)Ƴϱs+wDeQق}t / /8|F}@)im`t):Tlkҏ7E1fѐz zzbưSǯ7N]#Wqj' w(кg,FN1L802 ߳@tۯst,4` k_qh-5=cP٠ƫfDd43BNtG+Ġk:G(i@OǷHzHG}FYIM6 QH ,zQo1x`.e34[No̿m ƬUc,]Y Ogt_W5_wP{ BIbYz8H ldOj|( -#O͕ߗ `4GKBfVϪٸ+-hpC~،"kr'Y=+Bxy|eoϊܒ+}oWT̑sFKbq2? IBΣUnQքy', :T$y8vj&zkEhLRkn(rdpJ(G޺&^ZG%xafÕh<4MVt?R)šFh wf c0pN5dyd?ˎ׉}\=KM9*$v;zz>y1V6akFTezVQSVy9CQW-Y>VPd@(.sW5Y*MyиW5)=Q%W݌-"I$/Ȯ7_  ."j2,G1+~+˨.Y׍J# -XܭrPVW6iS)oFz-н\ /޷}+(LhMnccآE5^E k/QϝZ0a7q&5LMRGױw?f[FPQdIV"\2^("?O%Sd`Xr#\=B+#z`P v&UBQ(pDQJ*K¬i^$'()jb[ #4~B>kmPB}^ }SP0zB]*sДwlG"JH^@]۬|LyusUi XX]5e' 60A_8O3dwg6Wc!f7'l=ߕ<"0+hi~D舮 $l!*5pjGgUH4(X,JIMCV: #O8H~縐F{*)K< iF;%aGlV.w|:#Ub5Mה⮾?͌vDNvߟV N iư3rfS\\kƿ9z|#Up"XP3X5e=:u"{9nW8wAױLТ0E- Zrq+O>;6Zz|z=Q9OR롞ɩ&lv`" X !J촒 f^7A-'G]y%,\%UB:"DWA^GKJus[wPb~9`*+Ms\ Ӳ70KH+gޚ ]JfۚE.0-oTU:X+l xH񕄖EdB*/X 84R[gui1=^w`1)Ai'qJ:2#Aڂdq"m_vu xh'B ̈́0eٚvp5@ q5ڽxu5AhlAI0q#=QQ!cHǶms;4,?%,8ui "6C?ÎaHY>i-^j|\ys`Kt3zfalHu"cnxC6nYe#~'/ZR iާا5胵pm\$´laR aD6Pb~%^?}2`HN$ۦoDbt%^c4Sq< p-hdނuv)[nbH(I9PKl- ^ν֘`06Qw7C&w7@Gpn]E2Yf!rg dV5-Xl1+ϹצI(,ϲV3OB,dmA7燀PUPբ} ,-̦"a˼j!9]ԀX¥ʗ9k~V pZp *iK":VBP+s"}jz>C{[5O@6䮮 cV܅K}+z\7Ͱp=>JSw^c!8C+/"Oni\<!"ab vHΨVs001xLT pw\tQ wNjluBqr[>gf3`@aԸrse4\v+BQov /qS]#>?17tr\=R|QD˯BQ5X4BuaP;r$cLJuo%6{Wpc—׽ǿͽf|Y1yh:Dah(`\rL x/ oY4*tL۬b#h(瀔WڨN{"ȇRN Zc3$ŷ"p(2Snș" 6R*MޛKsZd;ဃV.rqe&?5/`a$#"{=A1y ]!]s fK41S l:f.@%Glԕ<9)ekFPqT6+1)X^? =So*xv ޓ!׫D?S! ]<P66Uq](*5BSVJW$g>C/5E_vn(M:A s#LDd@6wVTh^fPJ,6/G 0"#Gy?o(džsUSZ^kן lvVGy|6{;-80;8%#^*-NxM5ljD\@G:j7k/tBP՝#tpԸt2%7;s޷Ru7ؾr +!fz-mcn q˪)VTGĎUf5v#VBv9L5XV;UmTQ -ԳXxi{l@\{B_Qh(U52ikds ^¡Px%[HqaX WL#e"\:lm8O$Q8I&^ fX)9Gt >czII-{~Q/VqYIh> P8(.$^;`x jVr¶E[qs(KRY[BS0)Y kUbpT\0'PuO'7?Q !g$Ah$"E  _ ੆CWzs>?\ }C&i/G6%D-H^Ma:M+'9_$XڧVJPUɴ,eAY2Wۻ櫩.ym&{1ӎ,?c,$_W<7p,ր*r Yi[$p?0x،WP hke_Z 4O|&\8r){,px@Ԥ[fDRm >mCpZߢ9ܦǷ<=2Jpb8Y bҎlUhb5A- p)]XZU Ȯ 5dK^8+ FLg2jzIm頕^\ϫLlivG[Gvy٬g?L8z<~EP [)<ˁAim/kND:EEp mP˫=UC^tؕq0\69l'%ɐ w8;k7gIFH}cE]rk QL<ߠPqQRxL5Bpذmc@I$K&0;ۓtgRr9/>dmؼT෠Ư '|Xkf&vsvlaL0f~Fn17SZ}hTQ~r,2ʯɧm%JCFO<3b)Y=s^TիKaW~H'bWSa~PTD N[1љ8 DQC*:gښwh?#e9yA㡒xI}`C%,W;RfY۬"a~dzQK A5űZ68?[!A0"Gm@R~J(-VvЖOz`y"Nt ÏaO9Z/C\8ANj,Ūf/ zDv7>%` Z$3QƋUjpO ks6XOrt /Tg=.7¤Lj;Pg2**仐ҟAt3,:k7t}r[Ik];5}Poղ2SG(QE3 gcB2|d"Ow ]:tS B'xpR&@0I PNWQm*eHC2S z*JzII B}`F.o؂ieϪؕ*ڕ4{SFúIRk!]OβA͡9ӸfD_]I\ щs'ovz^IǂR f3t4a[|*f߭?Dr7I:g/cx^JS>J_}6daj[<C%D.@j+p勜Ix4o'632kK[D]sqbݗ tFȩQF Mne=߉qV! p)[{g,D$iV&wYtAi/B&eΥ\IN=@DnԠMX -Hbs!}R>\X٦4بniaZz}[ul]ޘ(\# SMgJoK[lBafwbQg6ug])Ai_8u; 'B&4=pg@ӗw f3l >o5HvB ͝.QjbB׍qק%JZv|D[D0H@Z?D_HqR֩n::ǯ e?l\\3aw }[\ 4f EwȆB'sivyNWY%/U!%K0fɪ αP+c6Atg\L6śt܄f-*I&4mAD./4ǔcm2 PyO)] =֝2]&fDƕE;\jn3*q2BCxs~q%S`A`mAR4{&#'q5{#fbtgH9^b#R@g9ܱUa`7Y9(a}?dJgbIE0એ] 5~tqI (;7pMF8IsNpn(^$? "U6H)ʦd$ˎB һ?>eC9G4% |(Sm1 ,;%0ճ2GX&dZh-ѤkP9ՄNb h[!`_'?fD|!=u5LƒDx 7] wFfIx)*j$@|t̤T`*H>Pٵ~\1MPO`FDJvDwUa٪+q >执ZL{ʥo-8PH1MrEUzCmC`Gz/7VT5+NȣŅu0bKxkdU!%x.>,3RFOƜEDuىd㜵9 +Fփ`ء椙Oڝ-"W+&bt%wRKb k؉C6IWq]$ֿf@g 0Y{v:P&pX#"(ŦxnO\j9H۞Z*cX]RVE?z *C{|_2"O|Oʲ{}yxBLU^Գ4UܳIBewßB*oZu 6@ˆnp_Cxlw)WOxh 17+#]~B?f~$? QRަf/3en7b9Buɏ*U=kr>H$A%Sf\LP_l<),}6;BቸS:;>ŚL `|ROP1Zf@:mc;9*և||IJ@ SGcpoBn4Ns7= iT٫x:N^^1#:xKtgN Gr ,NshS[aM؈0n]5JU{,E]ǰ ծBj6OKʅDQjRMԋDLo \ǓCRTlAP >Ε\ wYZ-RKɤsF v>\ޱDf2g>MU,³XA,bqI9AXb[mam`^"|NHtu,ScIj',na-=?*y1J:dg 2bO6߸K@D㜁 uK`2K{S2СD8oפ9D1MG eW\*p =c ɹo% bdZ,= ˒[&;lGSX]uӜR,mg]ywfInrr+_3e4._ n + -{<(A> w.#O"%9t_3r$LK7uc}lLݷzKTYCQd#D5 5[3\N $ECj A;MQԳ*N{f>6{ G1{Sa$Vn>6"JAE 5RrZ6?TH?JhNM }PA1`ERԎa9dm-Nt_ (|B?EC$+^Q;ގfoFh0xv 32n>H(z&ŬUOs%!iuf#={13#5qZ $:!zP9+^;¿6ӝ| @s>aeI9KCb׶ ҘDr8˟NB<]r&*1J\y]SN%yPTBPy)ī~Vpig+wSԭ:ްIPRGk}UQ]^i=:`%n(n1m;`Z)/ɪ i9z)BFXDH*4.HSK4)u j8eU?7(E;\zӡ>B{X-o8/MnH0N=} 0e7MH9$nQHGnJ"m٘OUPjM>4X۫lR}K[W%d9b}X>v NoQf hNnMHx=s1'G'b&|8;_$dqÜ!: wH,zЄf ti/o z+1 K0ś;^LfC.f.#2pz_ #vu~k@'K}RYDezrR lm2i7U{g<.pC>xSJ }Mi8rBQDj⎬3f'/981J7B0, qUV-blm"Z*[)ڮ׃{q fVܥL`Ⱦ[{ *PsGTHۊUT#wUxT{@U( SJhٿ9ٔmQIx( T޾^ KZOumdop)11 ju*w2E~_W0?eIΉ@m= ekLyXW*&Go.FEx!a_ bdbuR|h!w#{- sRۣ424UNgJoR -!ՙJJ]Z΋s-٫O9$ѶWsV|w~ow2* Jro%Su)9grۈmVY0la2DGAF/qZPy{fn1>yimUU@]c_5$l (ƧFk:U$ .T܇OĄo>.S>uʤ ,6.W'j8 Ҁͼ99%rx=R+AP+X`dIEWOb9txt fj|57 |KJ>5 -VDc(kZ!rN J*}O_j1J|jԳVvYNp2wHwiD3d eWX|˽Xʨ'@ItJ #D'F7DwP!I;э]n$SnB[]z4!vל@4Ж "6V}C:ӭ١\[=͞-RvG݊1 ҨGS^H 5X`iaG,cb sW])X>24M{kդLjbM=^HVv6<&[g5uKd?L(O-)޷k}$a!h{~v(w?ߠJ$ H BT4rb_oBg?+˄*|7˥p#DmYF+\e~¸oZmtЧL3K3p)- /cpypΩf ZuU,A 9T% &㣾58Ŧ JI{YRB뚾9dE46\QXShyq rVmt9/gO1sTn] S @&v 邘g&꽸5dXqMp3XWè&])oZ 0eN׊>?j5[C*7[ܝtz#w%wD~Ftfpxgnv-9 pq\xl{v(?b5ݎxD"#ܧ\GAeK;@QYbhTkMMytػ$vj J@slݷn@3Qp }moq'5'ٚ5.83D؂w<Ѧ@J>*NW“,w-{8\4- G&k$OB7guvP!Nc uU6So%fÐoP#yZ\P!=B\N"` 7C SIc"1`猐 qfd .0q4qO lBbvzwai Av=XL9;-U[5.?ꌋE><8 4+Y_S$\oX+" nKa.DfyVkAeFiKtHt!2 9V/_5-P <:rC[CcJ=}ke|@ 1u?FPārvUn߭ 2k:fmﺉyVNvՅh(.x,Yo}7j@ Sљ )?~gBvkxL뇴C3 QO>zC]_ –# \4so^1=:l-0; wƆ7 :s\,Kv aRGqS 'cmZK:fŬct"mȧR;QK˪ s:Ad}|A `鱢w U^o,iV%>}+tULÆ.7+ :+DkKJ1:aw+mW'o>#F.X']@Fʪ̯mf`vC3@|dI٠1A=fjjLRCf0V2[pMC8:NkN*,tYjQPJbA!i(8MlҤQl<#d CIF:)Z=9]әߑoUGy8D4$9V=!B3=\J{Wx|OӃH@+AR*aÖn%L޴ _*>/H9 M+^a塟QywY{UB K5G(jR[bspr-ɑˇbdŵ}uϻ){0lj/M2 Eu}t{ :Y~%*?_ k㨬:kPTbƦZQiN{Fjuw*%צNKhEbe^ -`[r;ˡA [ f'5%dKxd.&_ vƸ+bJʰq‰M [5f"o6i]ZGy% դ8X-/őeX`q?)p8x!TEHJTT!~sw.+{/٨r|1+9&zꏠ^ poe{ҳh "X6ylԲb$@f)֔.cĘB,GPn56UgK>P{,VXR ?efp^Lf]jeQFI)bB%)_AUG/b6u.% \ĮQĨ) c7QҺ}di)޾T@q`]/*CR scXFbb˲f~D\ixZؑsf61bv Bㄷk!HvXWpq<-,F(DhqrU{i*Ǔ<=`.)W>,.wLP逰38SR]1얂4?Ts_u23PzqeR3Єl!N7$x Mlfp f"g6P7hcBD61s׺3INO[& ݡ_MuhE9;-q28\bst^K1fVޫf2}JϢyr_5hɩ{rbiY&Erh#LHqP\Zs\zNՋ8;/&Ȯ~!E!@nعzMP;˜7ǭ @p)t8މ%u!V5p?FQkvmܜn^I^b1߆qIKرhN sx Z:| i"NbIc9~.6G2yf#5\x <L>fIĴU_ CԶxYw^㍄ۤ )K~N@c㒕<¿ds=%e\|+Zyddo1,>m*zz&0yUR3/bK_uɸl.p:NF3^IUp`_suU.]aQ6AsS7_'Dœy҄2z0giR(LXAPnb~(EUGh̴__\ zѿ}l.Gu4+uR=.'?=,o}m>ǘӚ4rYY}2s>Ga;B&T9\ˮܖ׉2B5 ×0MOׄ6a6IEJQY 0j:} |o bA6ƒpMO:whsނz͍hr HVr. ,!W0&zgR AWF huB,uRܘo[Zz]EX8(´+?FQ@[aXZ=wd!FRԹkNK=nqU Bٛ}dlkvu6X`h:c(X -<ӏ) d>{l\H$tI:4oe'#  ywÛWU8+q7ԠAoH0?26@<ȕu+ekI`^SQD?ar%ū 7.D!/Ѧ&^-Ꞷ,a:ͦz_%JӮr=2ǍGx aP?Yя8&+H &DӏO osY֣i}p8?S ,ouT&uf (PDcuPg?&gj8Kɍ?lMT3mbZr|m+;B]U3MF.ѺrWb8ebz)iF?hȥ) oL{jV1sS.6QE>$=͵GjyQ]lXN(Xh7^4CI g#<kg,ٚ_xSi>:^9lBΖÒ\4M[kĐ FG+* 'h뜝fcZ'=+Y٭&_77Uo)8ovs;°hhjX@Z(Hv* j??oH81W S^f>Y+Jql6ths~5A}nLq-! x1ޅk]=82ID]?t7qkWtJTp fA)$o Es?Ti*\l)<|b@w(㞇*"ٻ'lZ*c N%PSpM>p ʧr;w./2xZBB x=";}\}5BOR*͘\?m-/eMU躬C(F$N5Hz5+:G ElT":2m_וbG?ta98Є~ĶUKq3Bd坟o5~Uc Bt:sb1 s!v?b:ŁlVUuVDc߻Q VhuH#txG#"Nqg6ߖ05x;ߊ qͨ^3QTu)hȱS8h2f{kB8;;R&OhRw͇;?,MRSUqqzF󛁚*/l6Q-"=EWVT v/o\97_\z`+8&$0AϮ RR2WƎecs|bWf{Puo0dĖȸ5 ȼS{G <¤xWmL+Szb -a6̳hs#޵GK}zѸ3\AsLl~h#8T%?wt9dޟQxA=p``1DЊb7(vVjY+S2!yEpn& 댯6C~D肁l,sF߸;JE><ݙUan4hU0zM?+^UFRY|7ŀg;Ri9RmWڥg%PjԄ) 6S"?.k R aAϣ4όgZmwT`K[Ϧ#RE:UiqB\4m~+sm@k6u(̓~ tp ď櫸tJk]sV L=˞EH)ۓ~tڡ@w)v8xk5X$CjRJp};e:$uHD-sfi ,ZUuS?s:&旊)* ݷ7lB[+5߯QKT,spu)o.9J4uxG u鍹چJj;`HU^ӽoa<&4{GIc?g$QPFgˮfG= YJp(-P~,Cd<0)OsBdaI,р9n u9̋!JJ]Ϋ7,bO8T)S΋XW7x?i|G]*CԆ-i!ӎWo>ƭOLR2 &m=S ݯ6`]} v R+5y: I;nLp[o &v)),-r5#Eg[rzw\p.5K S Cita`q ~uӄ1 2r{ɋڐ=ݱ@]+$ LLS͠ :Md1K@oh&CTHV\T&"Sg*Hߟ <֢_T_6*1śuvCSvfWbȚhy|BPc㎒+|,Nd;sKBgRrF.i+rΝu׊z^(d"թ3tJHξQ] <,{DՊ93;q WZ5A\q 0E=Dݔ `s^MZ[+9-zE0B[Yj;OeBШl?koث~'&gF)!r-dN͆b`,-CYt0u\NfXkς@ +}:6H_9>`]PPfqڿ2pS %Ȗ4tbIJwL~[KFz˦N qxBF,'QWg`2}P)RbKy+5xv4yQzA^/LXwPW[nYxzq<4}ծ+px {)(݂3MtI xhP~n]gOC5U~ ̭~} O=~Kl=1ڏ|Vb|iD[VR5xCZ]EI?Җ!&$@FƧ" 22,pH:h9%s_dW,$7 7Fǭ%lTbŪ nSS%0:H^?rE/uK,&m= ;|O3=㼍kLh-DX-_pdk-fG C!^q5|wxM6AW 3H2H6RpЗ@ޥ\i~B]+8MW9UB;ˆdg,BPJ\Joj'BFq"ъ,}C?ݍ(#$10mޙ s! ?E g46Nk>|~uC:á:gqHcw]S @Zgg,RP:2a-1(~ѝ0cFGUcg+O⫝̸\)滒6D-kY\hט:_V?f;L.rD}XV0p6 Sֲ. f+f"0d^i%lmR_;_ &hbLؓ DQnmTvSWŌ+LԒrX1zsb)' #q9U=Ce aOZ:@ r&]o8Hl?"רzל{>{: 5PP wWri{6twY%$"C1VӦ,[(H vE" #I%hh~aykUw7-թ6I\r~@aX`W=ё/Cl^Ա ͒o;g.v\`e!–Iy5 XS0GsTgub$!fלD(ByazJmILCbc~r*={*Nhy@}: ~Mh\dҫ)G}:N uLJ"Oă /@n<ܫ]e ,[WoXbA5//yvgWa7R$: 1mCZ| \4 "[\sV'8?4;{eg3<ƉTeasaP A>&CUydn*u,`48x?&e/q{dg)xig=s)Ҝ nU-k/m`?'24a;z;l2z38.Ճ8'uAPR#i>*_i7/Su 1:dFT[~FdƗ89xO:B"u{qsFؔcy n߆,;n[tfJGQ Bu%tIa8A"J:.عE5-gufc]wrwNjڽ7ɩg_};~ɏ (*LDoKaUHlȘצF97STxzDbY'..GO u:/.7 訝,N_+퍺v|IOO6\l`L~SGer./sMS BޝgU$䧳F_6-)&xk9`}msKp@Nk=W)PqKkU6jtݸ;D7{Չh%%,$@H1l9e EJ.-!j^:DT2 @W49`~=ο2$Aᄍ MuGno\:r{|7əTwtL\B򝓕>H6QobV ־p,)6ԝQwX$W ^l0˽xOSƳsW P. AfJ&3Ow".1g@:w$S$*u _>o<@zGA*l)75zkw«gp(:$h@|AǑGL{DfCp J}{;Eoʄѿ"-#n}ZxBR'@lT&,Y&\?S&,i')4끷CǛ)OARU?A})XGD{& j%eGEb4U).$A<͹(Pѷő^|""?g?͎@?8U勺 z[Y-mY+:o5ùFk7Ӂ1шݒ$Acㅅzq@r@zE`|tzBmGi=*RXU;~NሓcĖ8@ё+["Cc#Ż;ջW^#" FhunSաa>=I:H+H:Z<[np-b"R.Ca}6ZmHfE|W>>_9/Mt$sC%SH 6i-sSҥقuF{בz\21 ,n9o2|bB['us-\;L} uo Aܕ] ږE{%籑n2ptqٝrizY܅yg!2~ 2hȨoVMZvĹv֧ kYǗl *Y7{h0 l9C:XϜP aj`O{c[6Ł!S)T yUJUh:f&M'& ~DG !*K3NJ^u@B}XIҿ >.BN{My5\dџ[VJ,9 bE<"3|t!?B rb[DSʗ, q: -|Yܧ-Mx [PP>=rSL)O67c_ xɃlZ֠|IvfLut"$nzՄ UE7ó5%, If0b6 _F5M?,m~h|nſd(Ȟj7/:j# #HX׷p.CP Ա1qG*ճ(P ޖI  5{y,Q mwIhߏ.H%0`X6\~AӭF*_RL~ETd7WwK6|~.>Ad-!Ι$ Эt"шOtrf𞊃}VMVRlIꌐ-,07wy^m%]ΪAN%N$XbSQ޼2EhPAC@\٠>T_-2a(IMMʵt qޥz`U!;(kюݑj`awlGEI%`A}~,@[anVYYlBQ :}; "Ψ;v>"vVKYceItk" #a lZKm<ĹƮWƲԱ3`Ub' [[WT/- 3m?IHhŃ + (k$:RoJeDK{-&RJfȔyt4 13լ+A#j@%ci)lnD,z6&}U*x4K7tJ_[thc5z<1ZQc' +8j3@tQ>F@h3(DŽu%(}aD(dɼR{#="$N1D$c|SL .8=WQn8JmqzVƹk=nSno+gX<ocU@]_|{id>`601+&{h^AX@j'CY3+|عT! PQļ'ì% 7gv:|嚾~UILhVCO )[yʀ*mDzY׮UM)̺1lK1UDj!뎒3}P)0\kjy(sѧod.Q ;^ %ίWHyj2@"[r6v$)yY-Ci6TkCY{22Q2e9CJVERn=>O"^>;. ꌾ*uU_@a{ eO}3~N?hah |N~vzvS5 ߑOWΙQpBPH cĞ17c=꽆!Е"7$aaKd;N?hHkqs Zu&|KRpҖq%:ʘW1e#kazAz_r\6̡{/k3l==aĽ 3lX?~M7Za%+M㙓]Ninj4x-iZQPvȯ1FlIIL[l`i RU"+T0U2#m恎YZp%}nfk\|&5eٹb/5TN4#9-(q36EkMHjaćM `0\.^rH2YU3vV$Ttm6}_sB!XDyNCQ-L_9KAZf.N&A)^rEAO䗣.\:m  ,ZB]R',=E hH$AAb5ؤɝ0OvڰI=j#w7MRoR N%9payI5ƺȶvmH6cbl7p5,;<Ȅ)O'俾xN'.rX*6rʮ~Jޖ9>9OLWr-8stŃe> oK:L%֔ϯ†VvXJĔY(\5MEFM"RS50#1WjaץΓVS miEN\%#Iylk%\zN;%{M ۍ뷵@&,I8ouoZ:ߣ.6G񡿱"lf6C`t9;~M-4! )$+ɾ?#N/F[HcRh.$A5xƽ+Ycv1@ q=SGLEw<>Q[P1oϑim$NϧubV8`SQܣEW?N1WU,nֳrYīKE#o[AkORrYn^p:_RJz>FАxڵP]SAQ;K(x%TE͞kJL4bn'ʙumcI}D+o +Y{4."²x8tA` qnlxC̭@OИyb<`B&$%}?|dĭFCZ.6Z9ae&o.nmm>Ao7I'6 p f A>=(#u&|oW:J!( exu[7]a:\*QIIDŽ4aVIȡA=lYOc^aE"C0}C3{`0sw'\Y)ѿå> .~[2~l?Ty7e&v;e? E'ڧOAJ`_€}i9+"rINԘMv֌0߬ BEg6)J@%Ws^=q^ekZha Gk̼ɺ#~5(—̂ 0֭Bf[ SnFNfHXa4FO-ݘk]W5(󴦅P 90CO]R$JꜼ-!{A|2ݑ$l6S}Kɀs# s\± ;~<|凅x|uNqZ}O9:1-!EVNR9.gYGMb} izLĿ4$}#LN@șZq jZDym-okb|3y?w9~4HZ'bBTP?Zis4ϫۭu4(~s,Rc)Mam"*PB(qw_OGM#:lDUv 220vY[Oͭm`,|Í5&BG0!ad;(u`|RMI󋨌y} Vpbl!G!֏ldtD]Ry '-69[ 1 ʅUJp+lۘy-z(>H1)i݄yMjBAZ#޷bCND d;Eu@"n T"Dl&}ަT?^-KGs82K1uji:)s`Ck~@N 1%%V?}2qLP۰4fSr% `ϙ^ Sue.bà\x~6N.!Dɑo{%2`Ѿߺhd@d{,0AMPq&vix^ ws_$#"[7K\>f+n]יDKPf~S!}vBƒ5#ND._|EJpTTң +!mFaE?+xT .9>l6N]O*s6Rswy4tmP!!s3"IҀXՄ6 cxQ:D )yvD{$d HHu 2 9GsZ<<<~fk3O2GYkDAhhI}KXs& {즟2 :Ƙmw/`f$G#rvobc821`jf Ͽ鍪a#_SA>$N+#T6dj5, GbUA 2otRXL6*p0{QؓnѸs$ ŭż'Yڏg$;$2I ]$ЛwtF@)Tmn\48=Rs4Qc%84:|}s숄Y/P\B\AXC i˓09/V5<7EBܡL-F`(&a῎!qۍbRN3)$ERl>IHC]F_ "^^ŏH܅ϧ';q2t+i0]VJvjGn-R#U:R@h*Oܔ,Rd!ݚ0-ěX㒛8sOƄ7Ιtz.pOd!T k*r ]VO0YnU˨ .H;F]vCAejq5Bv+/@%; U0oߩ}8|E '"<_&yDgT)}rvHL:XD2oۙs}O^K f֦X/X_v_?Xu˂vQ0ZTD^-ώ KΌ ^;þ2M7E5pZO* i',cN!6(=A8x|t @I+fPQ\2O8Ip9\˴ {}Ŏ٪^ԯ#W>!{[Ԓ%R2X Aa̲\I9^&WQ=ў >#m,ZCrzw w Eg$ _-ح^G7u2\ JÍr@<}F x_r^7X& Û9|[hw=rs95d XHK0S4ą XqZ|K PI’@DkQ+o?_AkL{ӦzƀaIT\Z'M;{pXor\ZW$*ޑa+NCYnykٻb%9(+逇' {td{00#-UΜҟdeZf'52&ǚ2>3 B>GDF4dnP~nD-֢qy"U)wCd=Ү`4%z-n NPoֶ al+:%͉D5/!'?FH#!>SgE& c!l.D&5gk$- &f=XUM|pȊVbwNPޔGȲpzPGA&qUX:OK;H@ҳԩ*^gc^?ˆ(d/-|'iV{YUW2~N >pT|D_*^*r|- ]wm/C^C#=/y%s~5O 6G;O}2`(#v-`rX \S0|=D_W**0A5ZrL2dNwqy_Th+βz*2p~Z59 Ĺ+QhG5urp۰G( to~V@%"MYXJehv<6C*ftb9=%O^QڊW]f1h|9!A\4YR".~܎֊;#sn~P,RH [_Uc|  f%hf+ҐG,?0iscbQ@ᷟbޙj)5ܴmp+?6z^*9-PoY;g67ADWK !Cy+mPW51a׮uw.(BM 1 U!}CO]n}7X%34NwUo-^ЅlgA}(ݎ=ٺ[ 1|MƺkE$\#TP 3oׯ/#*dMD5@Ic;JPW!*"#z9 Go]Z}"8,i+$ 3e?R395j˴K uNw|Ӹ+ 7=\ۀ%4#mdqTH$>k!͙|꼪,'PV_%-& |OOs Rj3nV>JP]nz-j׆!=8 t/ެprnIbqyjkwl٣%iR[5T,6AEv!%> 4˜o$*v4 ,މQCZx۴}/ 7(]ѐpYfy^HV6:"M Xwڙt WRitkk-P=ŽA|AVa7YH"N "CI4@@p|Tx1_ 92/캉ʚ7@DIȔXfLGZ JRrBMՖuu3Q M`]8ő7Vf,Z$xzz](^8ݹ#.LZy@Cm*(ޅ_"rO, ͈CKtd-f'GS=qժ$rwO~(:zFGy*suR8h`T17y*j"uQV*XƏqwm1>y;?Ia(PVgi|)4j+~ڬU @ -&!1\@11\ X +E8U%}pEU鶰lxٗ`Vn J> E(2.? +C&˲ͥ6:J. % WNxUQ͗5T[GJ shl0AT}{?bbɦ8B`44"1/b%fYӂ+?#@.±zuwE˘拽ssbkd+ dqʅ?. bٝ.Jܾb\͍aWx25.aSVK]|t˹dXCծޭrRx$4KE\Y}F+H($uG?f:c: lx6eP*AĥZcQgЭ㐋,o ja`rqQqsS싁fU?+ :M~&(㜁6QE#ća<^p5@}eH8),c1qNjUGQAc?@İ[UI%OxzV%-lC$fAt#.J95)$W/*Mꕬ* ) mH4KC$2uRKUt6Ѕ]ϴ!?sc~Vضn`\aGwo13^ҼB`X٭r$F$ZI"/9j2T+ ĥan4-!Qg êO݈M>{)|i%I<6<gd;|7C,J,79t/tZ>tG+jwXѢm<'XFnG8_#1n{3Dhwܸu<}&,gf&rƻJx??3:P]Q&DcAxk C%| %cihbt,M┖ LhӔrD@P(Y sj^j45xugE㊪?GM tJa+20j`ƽG^k hWK5|?pײYP-4VX H:rl&{ܙDBIEt#krQ-89-d 4(A˷W5j OPLN1~6RAQ-Ywz;wہm[XUe!=|_e_J F"]"?wA?غS?~4 ۴1DMv}'vG#}z_ H1,}գo kL8Vnq 50§א8t>Ѻo>}^%\MMp'fJX¾fy`HTj#HNs6T)f7)cϸOz^pu߅G,kF! Ces'-=#' ܕ#؇@8Y)ןJG.ҋgPZqVMr {&*䅽!J`tf1 fÖ%[qJP `?Lo1J^[K2.p@'"FO:6eZJg엮& #)".EYɓs,C(7$Jk/Xt3i-愦`=DO 9d-,BLKiF(ųt;ͥF)yp'?޳cCg6 i^X@HC8_[9d~iӫGYMUb=if"/{|iE{`䨿+Suh7s!3 hJĺ7@b"zF{{>.nw.gCl>Q$ڧ,Έ-~oB, lQMQC}׵0ozW?7SǝK:.S,ӚIyyG4s_ӯܲk*פA+j1OhM)܂]:fPPlL^w@syu^r&h~RIB(9ڟ WA2;%&.!QX;;犩5;t Ȏ,,ϡ1fF V Ŏ) +*>zCn?xswv`CY{ȤTtZSE36 AE/g #J}DY^' M$Nt3,p*Y_puϹ]owf=f5+9dڻpp`AFEIbu@]<6I'E6ߒm~Y tN%2mңO~uГ3UG??P(َP^)w-D+Ynp6+l [XiLDzQ;y*bDf.1}ܤ d17UX"2]UjY e1+zX>'@veMzA|U22Y\UPxsO8UCrKBGA9'$ZlfM̥6#wƠ/]/ j8eT5 I2.=s<~N/54Hs)GԗMU,:˧..K2O@@s1x6i$l`p_`zJ ʽvT hJJ)^,́NWḠK %@#^$0[gWx)}e[&FVyrNA .eN;y&ṅˍ X- ks'a]\*4n`S0MU !($=  KY_ ,#s;Rw?ˬ DBز8U7^OV{shh=J+UȻys`pm\!o̎0-q  s5xxJ۴.).s b~2k9}8fTS[fz&cyRޘ%'˭Fe>z FPc `bͅ>ߒHꚢ}|.YyUA,z?:ԭߨ~eB u=y>o\b4 3VRT QR3!pғ3nEL @, ˰&Bk5Ou6ܡ&tSr@%#̑:ؼ o퇾80䄪KOE/Y^ ]\?{fM#Q p$cp̲mBALFPwV]86A w7FJhqhDkcxj]+{\#QV&aҺ*{(.wC"0p-PObPipthFM?I5v~jݾڌv~Zx^XYG]ul1,xh ~0s ubqʤqd`&ʀٌ>W1P `1EvxOX;u'>> |CD/BH7[ŴhX˶>9*?V5YC1]5sb 5+WSO ncOrJ|U3Y޶TLO!KށQ3Lj])>kK%.̽sMa8g '#MI6?҅%NJи91!ĸpc< 8j6o,_*Vw`䂼vWnOK3GЂ6txHɊCf>aZ,%nh*곒 QLBZ Hg'}cn! گqiJwXJzsXc # 16#u;P jg]:e+Cb@4Px^* "+J 6װO]3C(Vq8 ew8,hS;w.U Yp6A?8qT^HYݛ{z4:B,|ll"N]<%\_;d5m%PMoMy8Ca: تꟈ^? dLR]3A340g\W[*{U_138 "P1A 7=`Tݘd:Fh5D-k9ڳlzG@Dǫp*]J;zFݦpz= $B>˘5sG Aq)SX7w"CT2.L $*Dy;Jfא56y;K8쀬hnFfب埙2{1tUm]~\K$=#Bgv*g08X?jeWb j WN|C♦p{er$ԱFGȎ/. ?R0bˬ+G4{n!'ј57ͦ荚,S Sqbk|!r~?}6džoJه 78n3uǍ+|C >/ #'Rn- Ub2m0Zy AO;" y_̉{g8\'ŭ&6V6ǼV[ 2, ц?d +ƺ2wA-Cha)ĪWH&ڬ'3%3h W&I:N-ي.` >Oxwo_9}z㕻7Zs/B[BuLyV?cBc}C^Nf="8覿[d>D u? "қ^ffR{Vӵs5y2uowXuGCEh/v11A2W?dY0DI.2ϾcwVX vP55P܎W$scLRsӡIVP/pw qQtJpNN=.v-97,cJF6QyL;*ѝVueL(6` &u6El "ʈ`(wcr̶='Lh_}ֹwk/ @2&%v=/Z6i˫Jb ]ZbQ\(ś_uE&L)W?Ð"4_Ǡ|P Us G"\uOIryq|oML }GZ45J(\> |7-qOUn 6ؽ͙mZ)IRפॖW?QSvQNaV+Pᔤ PEsXÙ脦g?TMrA>,A8x#hl.0u}-!'SkcLg=lJ*7tWr&8S&Sf=u9FmW07UA֗\qdj.n)vy&wL;7RW`F eFUP o?}:@#I a:MU;Ҋ/TE \ʬc?@)( {-V["#jŽ3Uf/[}ҡPhNzvOpE}A:wTUZ!d;D?[1lЫ3c|s7iW(f0(DGc̴ v7[W5&֯y݋-MsFX4:,gǣ5*'iM2_Ch "ԢXfZiabTT0:VM8C$PTX/Ft'I6RZӐRIYwbtǻ5d-ljKU';%?aױΕ?,@XԱV $tY;QAO 4q|q)ue4'ÌhQaţfYAy1NELp8F?-7z1;.״ :8|a&TN/ ,> .Ղ;7gc:T'׶&@eW]-&/ZoUɚ- h$  H'Ifin9ΐѝ%Up0ak̓ű GµBve  `S<5V۞v^ͳ4r%N1Ky2j:, )ѡ:}l íwך{BRckh/-_Joh WNBS~M!IPE+椖'&~^fdgGX3ʕ׾^_m-zݼ_f~E|mLea_Yx+DSl_Rn!R1O!bYcej!M2j 2\YaOո j8 7"1ǑtJF!Y,Ilz%>Ga_-]#)bN5?y:[Uʽdd\6לW?`?:K1Q~ ┎ê-Ɇ 9VMqch1ukf<%ix)?y8VS L1rz f9Yx!X2n}> #eTr;1^۬\9 qFBb@%bx_$NU(DM)$]rM Wu5. +%ڙq/-*`> K¹͐iV \&TomN̔7c m5u?D,ٻoYX8Bid]"db-(ֻټӆ􀁆N]k0@( /)f3G]xAea4s =ۘ;BF[2L.AW>L̈́vsnմ @Jt߾'ƤXqD$>nw:(|O9Oc( RӒږ.>9"0}&r3^>bw ;t~hlW'/+Zc> lI)@JPûQd i0qerZ* "%a>]И}AIކWR] J)Ks$$( \gMTɟM`2<`rI+h^_izRZ^J rяqzpwoc^$7p2̼4i"K&izІKoCdCaގ^X0\D?]thWƺŽ\ E<.ңT ieFSNXv\|ޔ{G_JyHoRMD7ԚQf9N`8p^Ȗ)4^p vxv^zex5RXZRi~ޅGa'c^kMߝ&!O ,K{+%KDApSB2y J&a.%Wav@w5o,ܘ}"Xy-Cn c ǤVZkA6?QmF8d1[VB%TV"PDg ۘI×m~G+Bg1 ~4R/S2yr\Q~V hpsn?s6$7 W\Dݖy LELq%'z8*^GXW,O.X2ϱ!W1Xbxf4%dn<,ݸp]X٩Yy񥔗.Ǹdg//z%y *HNb|1q)hA7_ʄ\Y%Rᖋ\Y%߰hLB}eW2SYݚumG֓ 6Rnո e\F(Jr S4VzciՋo'EҌ-Fxn0Izu~qwv>Cu(%Z9R8@nTſ٠?# jb%j9t"L ~M$f>;:3uI[N1CҷbG)P)NP "/~J7_;_ ny;]*r;WdФI{lB,-FFm/rfdEHh:Lpʂ*N; D6c=T`TʪD)Em3W^s^&Mq9ZlȞ6* $7X;TE̔4ZD5_2jꐵ)ɡYѷ4I2@tlVRֺ| -R,!R9iSSa``+QЪdh?󙆥ۗː Dcm sP ~v{D&є"HWm x2@ 7{0({!&/l8H`yt@B^3=Q'7m8DL* zfk )弢H["??N&H,!g/;zBgn.vC)K^ެj{2^{Ӈjw$϶7]:ME?՛MOF5CADFGwyZTD,^ߕ59v^7\3]O޿Hզ-;m$%!&) 5-yKqWVS`VGZ$2 ]`aB]KcߎD9ykojӪӚ{>*ֻ͏  5?$RԒeDePJkq ^ߚ~&uk5;ȼ<|M ,Z8,L >1#ɽ_.0O 2뜓+BZ]uqf~@hGֵ`8E>C`>3B͸sR/'!ƼTW4 wi j#ܡ^NC`JBgoQ{Rzo݉ݕE>7fėBbQ)@ g69i)mzt10DJs["WE`NaNܑew y.܏C>~Zv/pnS(33[ӗܹ|B/B`E GkN*uEϵl1ap^~CWcߝx(kփ)SNhYnԐāJE*BhYmuA"\GGy;ԻL<گTu-,q7qcYq+#ZmZ"YvF|+5JgK._9-Pc7~V TqY ܭm8EXuRyZXمle9loZ5}R&:|Ro:Z~FJxCkQ;36=163b[Ty뻭Μ܂a1Ϣ ~!vu;AhCFeSGYB}:oÐ/ϙE =N,R :IFճpp2B$h7qbV(J 2&'DuN?u^a v_05/E{t\%_Pwه tVWb0;Uoy)#qUt=C4X35V3', > %[R(-rf E^wnJ [Jҗ~lkJ0MpՍRw2CoQ J)]i}BA ۱ld} C%#0qJ~%"ݓ4IБ3T w^'!"V)S/!46Q!8(e%Ry=x> LmYe!9Ōi^p9 ƾX_Nb̂bAL !H٦*p8_27t9$+nsK9ƅxo-&z61FG).s5Q_ՈgWsBY^Gi:_?Nyc@ Mn28YNe׼5$wd=/Hh3xǹ;Vv:owxR\V|==19nQ@N 3a.,¯V%< $/9Pt5?wGy(R y6[,z/\ 7*LA鵯6`ʘӧ#xi>(nj^9 BJ%%D-úSRARhӷh#%߷+k\fAXY^u1S2 %䞥ܾF&L𖧵>k|c1=5&֦~Onk䥗Sx3'Pi(;sg!d+!LQ*B"@˻ Kn,H;\泟}旈q ]mh+ \-@L6ezs Ap.ĺ9]R6e7Ys 1de]JMt[~xXVśXP\&6G$`ToյsVhE+ (\:tI@`5҈-dZOIygAdA5 B ˻ZQ@- Rk.1 t|ڠeZX."NzdOi^#+оAs"!g'R[H-/\KT/<'"#ڥgmu-w{_f͆]o|ש!f8Qшi#{X'.k6ƟNY Rѝ0[9*ru#GP&z.iN֪L #jkP4tWsX^E*xEui%~kvG~{>"Mk)Ǡ?~})~Jl>rhRFl1 E^=$g`ϒb >Me6dsƱpo|xuc s o;㽷!mX:R"5(ij`6+0yQ%^$2?XLBHy0 z]묯FT?+W-̺/IzՉ,}χ%VA伏KilEl9uQ dq+]\$}@رD_Q>-&;3?&Si mGPN1cwC 㻸e,Us헧zl5 8<7'I3fzߤd- vȹ9WTdU ǽA5n}"4fn{T.kN%Sam<8;tA9C%GX~R(廌va |Lw! FF<5 n [O9Y9y=Z1}D8RrI9QOJr]|[F+f}Ĝ$ ,Q$?ḵx$Hl Fa2a{\q`&@b-%Du֧ KZ>:dYʴ(. !mF:(~^z5?*b:yu P`|X߹Xab҇J_Phq̈)2o֊ȲeXJC#zmŗK&ӷV *Ɣe!`i1[cdR [+7/Aj49׶ dP}~ ;$"Z{(|z8—zKX^}_iBϛ聸A _:Z: U{>nִVitocY=t\YpTWiKy 0ֱFeyl3s/6( X_ B?Mp<H W&z ;xReZ5LVoOÝGmHwLB_GGE"ߦ#`a!LGjq4<8,B FʓkM-m;236֤#&!;Ƨ%8~f*/89_fT9_ nW?븐C-W;_b;Z .ػA`@nJ]OoW ǦQP@!? yZggܒq՞h\Ͼ0` T/T%u䕟]Mt@. o )p#HmpY>$925Hڃy+Q8&#Ѡ{a]!iK1}'u&(桝f&"]9C\Ѕ(]"\(`D{҈9+ 8R*ߞxnfrC07xżd}ڇU'#]-)C *0A0$r:>ֺH mjTɭC.|vQR!}2{jgd%,q)UԱR[yQ)WP)yeIWq³NK{dDMYsƞ^YPMՓ@7-ғܙ_ ;KmHorm;>PΣ[AZXAR3D؍i"R%8CMbKEM kJaR?뭟<(w`%S-ص1oB.@1ѹڎ .Ebźn _:mg &5w#̜'d"Jp O/ A/j.6!wH፡\rhY5dVBB3qf,W@yt+-eG}qU'w/xs~(F4^ټ2A){DʱhnX+/_Oa6b-=5;T tqO^R&`38 l׺7o =!~ck(Y3Vi:_+9WSy=놲@g^ /Q]8Մm>9PAJZ_yض-raD#NW)HmDz̟Ud xATio9EXyPr,p"LM>Ȳ=E3) DR9ZMAdQako Lwz:d @ xl̲jfBK3[= xɅ]°T,nH.5ٟa(_/9/.<,Be+ - ޗ8=3>3&&#J- b('g֋T?b( Ő}}|atYkTNP Λ}dfW(gHfqX"}nU/OM3BP0v_n]1AJ#u;nd`iw-9B\8pS$"E%X=M\)O-KBPVS[u&AbWNBu Ǐv6dȫ3h#ssNle=?H4?E)JWՍXDY5lu ͛v2}D*\.9D=%X5^߁p;T`cC9"HQ2$;,I2Tǀ#,k+5+JUjLzۚe0 ͝OLpA)q&؂6Xe&Y}әO-K2"eFmJr0ׂB^p8{UK7K+xڞ^a¹Vya42IK~@YO}RP<ϬD5GKg˨Ze'NJyqc.nxId@)@b&(0 \'@`FJ>K㚍qtG ҳn'-X*wK1 E4/+uh],I' c/J@O#di>ƋG.w 6r= TPzC@]-׎ NaǗ#wܪ1[Tf:ŖJc^+Z_cĜnl'\ lqGxOBd-F;҂WLXcZ˃.s6|݇'|m?+T;Mb:|˽iCn*Vث0rߙ#o֣-Tc1GuԸt(N,]$i'SZ*T]==f?z]zFN 'v)4JjXO.|# PIXYq><+2UR{v'D GA4ƙ~6cBkzs2;2S"FU4x <zv]PX\bZR]IOeFG.+dcȉ6D{Npm,XP c_lWixTmttz rBos={LPܑa-*W\N䗣W稡9% KW)=CdzYHZuW9AO7-/屫3CC~&ǎaad1zye˥ba,-0b޶j&LLgqȄn KvBAU/ݤE0ZAs& &A zQйq@tJ i =XRAF 9` yK::K uMf^ <_}Kv#S-N=˔%yUSp9q]N^'>-m;$P9ݕ6,C\1g_!R߬kAVMvCF/ySR^C& {14Ps "a0F u|ObFGS0ӶW *\l<~[:.Qda)QZ/xΨɒ%n8 R8FAV{.辜+v!{ 0~F\6'VF/`8Μ~?='hO9l8rp\Я.Yd7 ? M[Az O@cfU.5r5G=잧|SUA@W䡒) <`3DT᭐U7KJG?$*$R M_ @ S/X2JFtF eGB|Ed>Z#'0 d^[73I@{(oiM8df?ܤMek# Wm^(^GB8_Om%tH]kn(M7f5[ `qx3nFɊQCbr335%WƌOpIT3ͤк zkD'9A  F\;YS]"3n"ُN`6W4H j%)x7k(Ub[Ssd?{ d0`n]D&lM\3cg6j[p4[Fe<Au![x 30+3Gj9cr"c (:2JϡorΑ#lA{N3B׻s B^4?K>dKduwIDzv*eLXN%6 _90ИU 36uAxK4D*,W Cz_7*DceXnn{xITWl׊(?ZAI^Խ p0 -&/m&JeeQfCMlQ;' y Lq8,lWfVdb!^6I¥*(L Q]oG.3~qN7{جd2Þ>)b>pGNGmhbq(dRkHM\D?;mb< tG:n'OKSVIq@xw`bRV,ŕ^mk\7gv,ksRULK*z }J\? ]eYt4~#/h2ɼ@fǢ2~-<'TE8-,)KCfl\K$\ǫ_TT&D8J8"Ehݎg%wx{%t/)^4|b!MV91DbϿL_)zMpRG${Kg]tg Y"J$yjɓ@Etn+^K_D4iJұo.smރX:^.MbG|i rI ,TO9-u}P0 3?2`?p꜡!S;R7E ^E%=CX7Nz$\9~iEݺݾq}j(%Pܰ`'z"C~@ӝ]kyL*)- ::S%;m|Vr(F 4AؕABQhK۰{ F ,ݻ` r3]oϴҊ`#vp݄l_iO@,[lTR&u~<0Wܕ|ӻl..y>#2`G2+MR<҇t ƪ J!TGAUG/yPHwBy;hnKGzV1Ƚ)m.4.l wu:/!Q]nzcyͳNNh "@o dt+/lg2 Ems;Lf_V-ɠVIM!Fy)5Mmivi`ee@A3`Eɲm&w1Hˆ8_2IN}ݜ@@"'z9[H^ {E=7D_oЫlQfҴ hF.t8YfaC&&~GO7:ZEMixXP=/R[m;Hޤ_Οvl^0 ;w[+YU z{?a{>J4 u M[QfCH<1sW*,M p4TsY.MDDtŻRbcs >s$Ie1_FNiQƕMN*23`]? IVm mScAƯ%2+h_ƌ Acl kGgJ¸Lj&9 *{4ݮSF$/]-UImf.07 5z,l.h58aLsGw=aƌAFhвX)~˄蚛}$ÂKn T\GꑽS2"[}̀R4x+7|\!^e\48~[6*Vޏ0^Heېz_RXsẮđ;eypm? ܥC͊} wb=Gak.P:hcMv" t=)^ұzndC %Nidxxj7\wŪ?!643]$]d #SX*?&y}$wεq6bB{jݞIK167߬h)qX5 WUD5<7/\y15$fyN+2T'8"?2lʏxB*T%Φ7Q7O<<`;?č/ŦCvzu~ƦPL*`aC7e|gq:g ̃gRTc>u#c< S܎nE:oOoÈ0{ &MY8´b&^BF?z(%2Ϙdզ'Ҷ}(^\b8:| rl)EpXy90ZӢ! #s>_e̜ig?$ |]q ]]mw}]3](JR, Y㗾ǎ 0rJ)40rC%7sCRMrSkaˏ &Nb}(gi_1\K" Ͷ h D$:ZM+Jm.{uO1[ڒbO9xDSl-XM!XTA}(ґb.Y4xbű}a%򋠘xc=ؓ@meL[ 3J2KO,v3!9_eVI/[eO=E;N?/:zPhCP8D#I-Bs"bŞZ7˓x`U_ ҃\* X,Y#1T6 PdY'1l QlDu%Zx^S-P3?<0= d|@;D֍/KK J>Ŗy ]wDWyIdD%ذKg7#HH8~xЫ _ݱ)`ft[7'.؇_ IɃt%j_| 6P*tXa?umh륟.d՘[QXtEyR~q*AMA7#V *!Xh'dɼ:DGFu ,V:}M\g1׬qDr-Z$FKd}gAm$&.b7@(@DԈ1JH' xnz6Եv^>&Vɝetcr73ɏ{/hG]fI,*m(w$/f_R\"cɂ@:ȨlxO fN}3tQ"64!pPnZ:,y=va]!Wt5.g)'뮿lСÄ'CvZXʊdHZIJ-"C\x75`~IO4?d.]jˤgwْSTm[K_J؟^}oh @P:&l_0m4]zçuQK~3 L|Bx gi ';rMZYQ6oY1;U#Ыz#1K(%x2ILHR; 1BU,"Y%μFƌaT4$,~K,:!]:atsIĸ2증k@}ja ]zl}+d5]ү^MƄ|L!Hw ST7z\0dXt<5\] ٦ !y nM7c-9"Kp`b"?sƣ|%8h01SP|(a^XC-̄Z >44YNiØjaupxXqDMƆ@j,z]N1Wg9nݭ+2%nkI!gC5oXB ^H3t!ID\/1նr,hqݮ-(i?ki+Yr9v$[beƐ [ {!Gtډ/{7DR[H+I k 5bA˵ƽ϶¸X +vk,5{ɀb*^M5e@]Ag[Q[v0((HX%ZP0u>˗1pC9~g(eJۥ}HQZ]SbX @so%ت ik>R- 88xq%l C5:Б "1ϻFtե5kh|Xyzjj u?4C.<?.Vk-[ӥ.f'S(@S>&v-rȉPkDՅC \7XIU$qIu#HF\CsFgDBk/9ɍX ]o^grjjk6Q u-`G ?B-GVՐMo5=թQAg|"?9C9M^,NHfrBp/i0mvj 5鋈iA](>?Tasl=MBǭX:3;]:3%cnXMXhiɍ.G8)KTsO^=^ͧ!wZVc騍39-Aܩ 13@] ldCAlfל/#}eo Z"aD1ߦuvm,VZ8:!͓Xnd_^["#¯_eO+/%]Q9o>JI "\\>n/\S1l|5Drt=8clu4 lJ%<*=}mvںQР $D QPc`_oSUb}v<"Pq$ Ū "b|Wu]a"m1L)6ɥg$“C^%`IJ< $NmC#eQFȿ܀èW *bd˕\8,dInp]*P*墐A#?v. _6,O3XR',񄹳1o pBs%A5oCQ z͍[)3** UEg v}Y' 2dh}y";9T[ zTmފu$W5".s 7Ta.`_7|&G,Q㊘ $57pi-T/#y$^ (jv\A-c%t]-5~.l Wm:;fɢ}MZKfUIQ5-{{_ɗ~<Ρcn2g,EZ"vP:u#Gڭ~a[vȳmoТP $'ix#r 6$W"<<}[a⇪yZbj>pԱ W@F Ǐs%ltd~yk%|o3N蘸4| ϊoÊ\#Q;PZ!aZX1+w!9 Y ՀpL!h`6B D5#Z rƒBsy;ڻAqC(eiO7 I[9)fβ?)ÁY@|^;KQY=YJ |a) ):['yg/FG-Wf=1Mqaf&?&vo;ܱGnqW}BK`SWAթ!n͂ uodH &}_\&0X~:i׫ w ~AdMU;^$ŵ _#iv1ü'2!>o39 U3; 3u>b|mzB[[|5@jf2 $Q/ 8,ѫ#΂^ ǿcoIvp.<#8bɄF׳Klqpcu ka(P.qVgG @N(:ayK}f]&1T #tگDG>vڇvCk_OVr6^̀Kpy:( AX۫\=!6khTLWdj!as"Uƀ}хӋZޔשT,xxB#ꃌ\3חDmUwė28C*Y[N M,1/!ðBn61V}g1m.]YE-u?)Cm ,z"M''W/JƴPI?.v-hp,x{"{e­ N5|26,(vrln0!_'asPќ\5y&b%@>dC+F 7 @zAuf!KPwS٫lZ8E&IFdɻ')Jcz8gˣjNjkg |d1b{5iy G{}eSgEm`'ߋOO(yrۄ+b%B;[d\fI`mizRU숡'U¹jM *Tt&? zR J}vkJ&cokEユÏZU$ ; kɐv1֟>,uM(ڴFbZHt|ʱԝa`0]L`n˒h(qiZvkM1\P#SEӪIkTKpUa<^ >\F{ kW;UH2F(?j'wDa>`z'ZX=33dp5C e'5Lp+Qq ĝ` 悳Kď׿u_dwm\|  MiU5Rf,.UJGJl2Jݝ%" Hk Z7!c#?EPƭش|e_ rxJHK_1$̸E `DTcj9D#s(rh`Ӟ^ TtB0=F䁴i^zor~k&^K2c" aT95A2bd.et9FVfFIOGM"=8IaZ}ξtEQxt> 0unXF[!zT >R"IBBjȋԯIRb]x]Ӆz#yJam=[/R? `Zfx V$.Ed T,jE6Tro>*J8"3KNE34nlsͭ}U6$Xc'i ۨ#VMIOvWǴ3N\*:XyخDnM40@Vq] -.g%!.iSU4df^`&7SDnn[K'X׋ۉ^VIawܣOuی!_t5^l VͶkɉ-h,s>J%.+D{:^qpRt.)i% k8. +e_Aȷ &ul{$!BA, Ywe*9*}o22uZ>Щ Mha0 Q+rgV ha-5^+@La6}CEuE4*$Cqֆ&,~}@+c0(r$ʝ1=vRl$f:?ݺ-%VsŀF<2&k۔x c;?[,KVAԥugX|t` a1p"A Ǩ^{$ʈli؈^q>X(&6ݻ}+9A$edJ@HEy GA~[\t\g ]^t-6z4hF\Febk/heH'čv ZAK/H?ϻʠ1Ԇ_N;0wKDΔ4"45^ )$W K9xZ=Bl RF<"wGAAÒ*.uZA+ah2p-?lSضGÚ0IHR{ Μ)YʃEņh逡dLhw2%?(-lӴj{2+APs(?78h&FjXɩ\;U E. bxp]w؈ij;? =y- @r&LBѓz]*#){7!a}ָ$'Fn mprŏ< ߙ!GOaDajဦUN Z֓NcO0Z&m/ \p7eJ]#]|%ݖW tMٷGLpQ Xh|-8jmqIBz¶ ߨk>+yilt)ɷ1 }C(dcXRrXw5\ia3\t0G Lcʞ}ث\WF/PDg6Zc6_?ܳd`xs>as~rZ7 #ےV9Z*kgD*'vl,g W{OWڴk+Rc1#5=J#l¦v`$@ܓ| ~CPD$?%>lrobl{U{CzQ: LӷWe%sa׎roǙh=BԬ/*ڨU~.,6~F ?q<Ќ(қD^0W># E3wd񕰘i7F qE؄9Oe[ܷrڞ 3 *͛< ! 34+ H%VIk2~1Y \v-= T( vCIfWKTӉtmWZEs"҆BƄp'),\%%EdS=VZpa>m;qnr\EI}MC~+E͠<^"n![HZC'*M NW}۝q/^V =`);Nbtv^~{uzlCU),ah(WvX'H@a \)EKPSBT.> q8=D>aX~$5G~!ys0ra7 ^o;l['ڴ?v.YpUAHk䑡ey)~]3Bj m{,~9zH_ƚ6%SP;_?nIfgKz3fsD%sk 6I,(_wNzpď|݌Eg;0J[׿޺v <۠hP9 y*n&|69Yk&nA/$dOo' 34m%gٱW2fĚWsrU/kAfRoBarX\vQ?ODmMS2V 춱$vvebghF 7PPF\]k/by|%2p#"R(sQܽ& Ublv>^w0Աqy6LJYyjÊBNHF+ Yᜒdn41IeL} ͬzp =0Q+=0x*6i!41@x({(ɶ1 L}  O,Fř7 󨵖nꪀH>\fP\ZT:a?hRQs|Z'xF%+!8&C9q 6.PG#M]|fXiVMO~2YplbAMbOQ ^@GŃhlYҍG3f?W}.ۮMы8c"H+k2Ԃ0%glHͭt>W4DtP™WTm Di(2wflH RDJż*N]j壳uWu//YBH8#so7R"dFd2#ބҥם eL}!].c~b TL͞d~>˩;m,U9H*PIx@ np? z@GK8F)}P  Et, @ 48 W/B;:%|OUV*=HD͞so@@w2>:4`qiXp34jY=ҭ3yˇRo а~ojgMҫBO7Xuť=|5qdEԙ I 2`3``\hr5y/2j#ߐ]is"8x1ޑ]n042c2m?`g&Ҙ柳8}Vh+Xw .Q-6hfB!Xsa^Qk>+ݰLy e0,3BeQ^O;̫ i˅#O8<\˝9K߮z\_.<3V?cvJDFBn~F;c&#Et0}~0oJ{Z0ϼg#K;-J3hY%komT2g:U qG|AH~]neooG͚ j= 7YU"}$GHȳԽgg61g?eE+yJ1ڙ:8Tm>/Ƭƅ`\5 !Y+]SQJ{Tby=شSie{- JH ehr0,s6Gk= ^R}٨8h%7* {- A-:u=`椐q,Ӏ7c}{f tj}" xkc% Dڱ-IODwYZ8"՗`@ ߁Ƒ7cM:O4Hydž Y8x"Ke!BG>9oXee^뫍`+cl_kr&.6/ Q-`+>) l ka{Z׀AD`IAq5D-Y@`f7g+KQZ:fuqPAun 66֟3vq?Yv[Tgp$z* Q}V728 #wW߼HOsG .ROo|JvKD`@;6'W QcRAIRm ֦ܢVܪ,TʛVY 5wW3X/ i0|_KX"[׫t2,&}(p r ëQr$vK| I:~뾃EѴcM**򨞟`ڎ)v kt+Q$Q@)2[6j.9eݧL9r0}jq})IC2Q ˩>%zG`=CLK"wxK pFھj;,2IS;)^$|I2ADȦ!*Sw6U(f#m ~$րم?V@Cx,zi\"bSiRzҴ]|vjQ(p\Qc $'eB|\bBsb<(Z8GK\>TտKTۣ\v%r&9} R)`hER11Y{ +i4؂8B\&%e2 [c#N1,/~t{Kʹ %%Y] * ?.X&g\ 2A Tt/v@Fv~aߠ} :e#!ېxb2*'a輑Uoqz_G*$ZL  !'- $ ƤGANh/o3p7JqmZyp6|&\m>?L'۝GuGԱ BSksEWzBO$J{1!-흹\92 9ZŇiٓB5(S cwKlE oɍ><6!\6k2`](?'tmHS?i4.x&;PAȾ hBӨN4ټHpbM`QP`8;pW$ѻj r(m]d0:lZ'uBzVLZ\nE.>)_kie@^mj97 VnIA`r̢ˏ4ժHO#yH~Jhzy%cNoXњ@0B5۹lxlpH}ˡ [K\+.G+[:i =2h V|\"RRs _[e~>Fϟ$'-Z2mMS}/2WvYwthf*$/"n^x/]m]O6*R]]khucIEMkBPșrHwAh7B{hqܞ-㮤 %h*.3 jh6wSHpu ?XCbE _tH%ur(Z X'1:%kJEdD#OL &뺫5*)[M*W^~}!FA| +LEh8[ bS#,q d1Tc`Øg^XP/ F'U3E+ }Jo\xd+I%9읣{KCIK?5*@9G拵(x3)t4kST7ŋi+8:٤ž@  0ԝkS87)HCNTڻ\!LQj]e;*t#UZuk%/3@`|)[P90 tc L6Od?6@>&[o1vL ];&uC׸w@2ʴD$NGTn"2ru'٦,e}9y,ҔmD xY/GsP`zDF)Ռ/~IUju|Omy.T2O\(k1@dw-^/9=ОXd]筧3I. g;/\K` Qao:b=㊼tRpX=:謗!s )SڽjI\Oc]rE鰆ө!)kN;C.o ēT]\qPKgyHrX^EhK $=ğ2Iw1' sKy#2EAŔ(RF>9?sOz.>L* |)^j"5ͫ5A %@B'N<ʼC"j20& 8~6w*+V*+"KED}GuЪ qiON1YB#!6CuX{lYiDV?[:CV1 8>X_\͕hi;A >B~ X6Hoisb*g">e1&}(5زX:貟B &x, ʇF߾ Ί 1TFN> 屮@ε"1 wPojѵSL3:(Z=wVhmVǬ.^WwLh_!o} SjU%4HjT\;<#Бoд[Н㍂^hZxfPN7_A+[Oֶz"†7',,|(:s/\!!{zD\Gʪ= =ZA{P˳[\D/G*˚ZņF#zDU?̏ū]^~)0g%F9e\O:-03NjaϮ-^*%ReBNT+X& "~4b;ΰꋙ0}#}įpg=m֖ Mq2!!#FZqq hF{W$uHzBZ n`КD)" \M1 ~P<# tya,c@ kֱAxRTBsW*)(o+% &oupj* -JKH6ڃK,Uw+vB_ ȵDL% |ǃr6*vz::#7iseW?Zex]# vGuJ;a)//pVw+'/f`z9V7"婺8ilU~va]5پΧyz:]gPc:DcQ~Iޓ[rK^:Pf~dUfX{(m t|;Nⷸr@m.3u̘LɥGMh(EzzM=v=+Hmp@~s5 ]w̓%,7m4GSZƙ+cusi>OTT?b,N[A W`]ɱ &"mRHd$U5iuCi\JI&8W* lGP8]Gd9uLRn>xY "h]dlE"ÇҨӆs7S¯J).pȲ@BGzbT#jJI t@ j d9UdBSh>SaawU cҩ:Id3OCC!IS?"mNzAsU@…1+bT҅ a[ǔg9scD\|'Z喷&ZW;_R3:2ڲs᪈SVmnUˊLz:!N>4(#n>ʥG.!)\h|]aNC 7?ȏYu6$P4h$B4i۰I_c&Ѡ_79CqD9@TvL{8ABgU}oG)GVexSnIRHX#d NXbܵ!:N^m|ʱqbbOMޔz@r R j,!,P[%*vy޼Vg| ;q@Yd b1K j2Y/Iʪ Q}I8"}Vbk&9 se{ ?ռcSʠ )%Ե+_nx2A-LP?3 ?ğkjF GI YRǜ&>IE6xVƥ Łup^8rܝ1'QԊ.UcGNuK4 KY;S՜0SHy{a8GS2Tu'KvV[l1r-B3-qW;5{uݝ.fչ .K?F 8 AVOVOk R/h:NxCܲ& A ~*xc[nȥj1Elz֑FR27쵻ky[Qu'.;C0sA'٩*Q?{/[:PS6_GH a\S~4'(z0&Qp Y7Ηڀg Y´"[($fWmYWZ%C0|͒TER$Vy#je2LlQ=֧1D.S,膸 Nt n(7K"`2cZC~0HK.·yj:@,F$N:l F,Vl!StsٯLZt"NSD+.^P#RoVEѺ[j ]P5=H#(<h~Py [8=ptKjH:̞ %*px'sF}8n~1dc+ Y]vLn:-^LbruLWTC$=Za9!ffJ& ".2>[N+5nDGh-4>)3<J?YR'>h؏>X>5|Jt^` ݛzqF u |h%n(?CCSDR)jTvW4 `?&X+D8Uww+jf%.o~r5/0B_b`A!`t {ZrCWP`HzQNXebnT]/rAVRiF#E='5.3uW$ݦK\^!JP6NP$3(yO7+Y s:I3$ce-s:82.qqpItap%enޮ۫[H R2A}݃a.DY} vs!EӼKAuf-4zˁ@+{EيE?sۑbٷ)s]]쌙>9iQO>$J] dQ]<U q,7M-]1&B?Wme!b=u:FӺ3E:>wA<"Kh}cNݹ/|ks;Ue\DF}J(RjٳPkt̬\E}`1WpdSg X,]ƁY9$[-n3.$͐5t]<>~GCEXPBkCM+,!H(^JT O55,gF@hyu<ծ<%ARƨb2dH xw",|M@o;C )&)O/")srJ;bpޭP0 fZ[݂ .h@֏g^_C)y[3o0Q/.ZӼX'XN#-ajp6`#cq\ƔLC9[4W_Eb;3MNӱ)RmHoy-lpedq"-~]}55`1&t{!4bV.C2"8)4Qu.d}-MKӅj,K q)c!O!kpEYZjR'MJv֧P=ȷSAp߽1["]2UA f?C:rj#{RYҹ׃!JZ(|b{ȬdkF^K7vм,D%Ӵ]pS-gM`u}$Xe-v<23af_QdEO0MGCavX\Av*{;SJƩ`DO&Q) 9Z'3AT"^wGlS;KzkW)sU] HrHh,0Z !m|Yȭ]P%'fwD%-ޭNmu`GҞeW&vmT>!]@_I%{ "ʭL$U'{_xd@O8B>\S,Q d4^,tX{i?5J! .%RTs=EynϢxFI>tilM̷֘؜W!VqoP*Bun "]uSk?Y#ew4&tp {\#)Q`%;QREzei-\>opLbY|A %,ɇt -PPZvr9ˋim YNrO n h$]I%F,t_/+c}~O;ͅ{ie=_Gl4Zr#^hmskMe()KHh/k< veJ8^jKlם.3I]ә JYӗm'D8~bڋVpƟ3fU7D(:Xy~" qR-K!v_HŽQnY~ڂ@1cAIh(Qk.Bxj+gt27n'-eB&,,pȑ›${K PᘫGXDq>I*솉y^Я~9 мjo_뽻bi:ӄv&sG"ћ[wHLoPvm-S硐ဋ B(K{%8+/8=Hrcd;iUָÈ7']х߁CWo'}7쀚. 1,}k, gwmnRi r*!fؽkU[OiYKb ٖpvH"f` Uyb ${aAg>It=Syx64ʥ^ sCdylkC(dƷeRuPbdُ7:`'S"wPoGM6Ux[?W erH`n8R;|?xSCp:Shr(!ؠ&bxA3r*`cբ +Ȳqyi&EI&J -b$ r{>$dZېDqc]wj!3R>CaQE.tF R*<7A=#4'gZ@ڼ.ZӉ oo%zcT=I.M D!kqi%ocRw孞V*.J T x2)IvdX{Zv(O(g2%YQ a3p' ֣MF|fG H)f8 cw'%ؓgA#X{OLOҠ xuiԪ/眴=ޏ8 峿Fr_{h lӕUjv':kN$UK~%x'V{ ÙN1=CzdwXVix.tܖ +5Bu(`Q'!i,ə3?N+nU]i3ddEc^ԽR5b& 8!%Ԡ!jeN8?iZRm{n=`3}W_ʛ~y10 %?=ũEsLP=BpFe ,5.t"f~mIm]H)Ϝ [/+Axa^gaLbF"?8oF ѿk/B_&"gd>XGϨq)| ]B,d ~sN>>nhk9KRQDݍq0xg1<;CmZLU} 7wJpʏDIYS)V,+n}(%*`06^ F_@n8G>54릛@n49`?Xģ~*  PMؾ<vR"+TY-{MI=&06 [cYi#/onKOm%桫l+QLXy'[d XIN%QoM'~ o:=!v=40j)>)p W;C87(BJ5O5zPburY@U'DF$tD ^=^/To߁οS0{CEObgu^Q(u/UFe"5P9 xcXT'g ?aB\.+C#Kte= p^kj{4&O_oh)*`P0Ge r4M9CfgMWZ[nmebwЁXoY^#"UrBJSO+JVEnv H`8"jUEc:GUF냄X&"fkN5ݖ2H&hkuWy>ty?E)LBࣤ]r6D||F;X7[6ǡmJ`ks|~jKD*[-KPQZkis-ҢDڒ 32y@)?͗hZA~Ra"D3 tX0ۗՖ]&5^ #m5U#uS ÎOyTBztמ-,P 2~6OT-gR"OI")5iCc>]EOj@gӓ&bFNRk Խ_c0ŏ:tt WBg;Oksv0a}MCZ~ޘ_C9=0dII jq2`;B>>/FYⴚwH5޺ cSYy7cy$ԙqIkkڦF3d#KWxSLۮ}yɎ0Y2۸ 6#{?7ڇ x9«+ZK)Gb &J >n#i3hkE7 D-@&DXFY%rgqz> I .rL 3ήN&pɳWF?n pfWYIP wG"34ѧDZx\{xICS"_ׂdޒʡսeB$fbWD`>6ҟ!= 9V%L8@_ zU,Hc?8ݻ'T^ *:Ӕ$C|`}|hE[Uԛ2h1ʘ=ku6 bA-COsjf)3n<=ç,;' :y[ðH۴*'3*=ZGSS|FFk R=;4W^/*_ݽ\f6=zqW*9gB1זm{=>(`vYAx%P3 UGg{PzGguH=|Nv'" 2nI;:H 4K|yx \ܰ5dXpF^*~؈K`H<\˗@wYe?yB$n_go܈*h#2ySM*Rc{OGc+b@b\p-R0U2_27 Oɹ'eO]E=UH a[p] +8lP`q}<::ٖxxm)Ϡyt;}w^牢uxъtC{*%+؆;-|;3F- (D ]㷹 D]Go4;ÖQ{YYm)N{Rfu`oFm,1AoN.KztoZ2@5m}5 (U; MXuMBm1`G.!|W=n#Dc[tR`ȃIT Z?/ AI1,}|ֵ)76t`)inTZo+2\oTJvC2PWaf3* bt&$B"W*M#CM(b:jA^!P1!u7PԞkF9)C2J 3V+ ) oy[bqq2uS! ]].]TB㘅TԫT2@^ʗD{􁽾 _W\/E}=M!|x/~;otIlq2T)F{ZG:N&;fŀɆ#'BbswGuD^CvCo͛6!œ4ASBOċTĥ"\ll ,9J7-ƚTX(۠P.4Tv L!Q*J& s=p{17ec2>Qрs 9|IoHTCxxnpW.]~V}u"y=h(i<KUP8Nؖ~CdPt.sx(s+VkhUi6YŦS8🪆%dlxmh{m;$a6ﲑ"Yvi,9W$c!nX3:lj;^y#UYD]|': 9N }=2?|[x~L?+%f}Up]7zS2C:Pt򕣭(sC쾏 xx/n \sEu^vmm?<] C3L ^t d,YEt:G,Ck *AcX-Ҟ(Ǝ 8m2M =uPU%6H_W E0 ue5 T#eP ֔W偤fdU&tQ.hA!?p{ a2[>叛L)-i{qͧJVؠB =89^CM Ai: 1r+pfL]/ɢGe1WƖi~tq1Ֆs=(xsᣉLBة@xcbG7'D;k,gZwD ZKO{9gjq5ȜLa>YLYC]YY>4`$}h07{e(=i(@|rߏO:VʑG90\-u"E"C])g0O(Y<̥ ~8^t- wGi(.+Z<, ӰsPhgDگ43>#hl/W%%l]TT+ݧUU UI3&XTg%<7m FL7 I6ZW2b*UPߒp BM~TKH5BPܠoTi2fqBs?B!A:h*W\Kjɽ_VskY`-Tmc̥ m w{%Ai37z:up})X4 =6s y =3>nb/= mm>5.ZJE46(!=q}d9YAź-Aȸ9 "fHՉ/?0m_W{G1:(~sp{u,ʚ[YkɄ Qņ7dW yzAIPO6=lg]c}Kt2 g/~[4=$<#^pFg46:44՘ e(y͜ EHɅEtE4w"J\S{v pjFNi$#@"y* XZatQoveVo0S*vLi!u&MVp = a+܅ ܋ُh8INh 41i-5V]IK> )%NEHy\=E+R*󉯚o U.ָC7ʡY974ə<,ВZ>I.fX~7Aؤ:TFqR >zEkx&0lR_2$w;RC[w3rT&$Eڿ&N40j+WG=ī)tS{;k+8Nk4 #ZX>$8 v((0-W Gem%I~(R~腛/ %c+|B+Cruxob>L[eZ_~#jU,:Z/&46m J{MN.~4qY;.~3^^5gnr,f;b'*ч]7Ob@1`% TA߁ֳ̅޽<,ʎN`X0˺YMX7+ޯZ/{StAn0zvOLkԑ@SATy0[ D!*0[_X?0b{Ct0Ek[rp19 I`%+)=^&# gcP-,`#r࢑#۟>1>.??g7TRX.ocISfR .9QIU<ٲ//a6wn.m? æy TGm"aDLZ7y8N/o1[)kZF:Z'^N A"U-х21Z^#G(,3tUHw9.kLK,~>V'pW/~ MBb.)mM T[<?)[(|~l uAJIw%;IN>iLMVP+IF355DFb5 >Sl&ۋݝ}D2΁m=Z0}6%GF/B alJ` E9#s)cB%1 wS}|Tqy>>DV㳖!-gkδMysw].}Whסld,i1 B>휷F!^oIB*n|&W:P̹9yhMϰ Jj. s!QR5wq\"^y0 -."yQi4 @Tà5ph඿3:aNgE8'r)7 wzCQ!}'lf-1mF@4^A7f.<& &"0=*,y)Dv2N6<^QLOoVق&$\)fV\Z.oqXX)Ɖ" xs̥u ϱa)gPU|SL̽YJzD"ǹ3ˆ+LLZi\IJ]+nFk zU]O&ÖVn+դ&u(+_l>e?+@]s%܀ 4|X0&E2`^::J1iPN4AE9pCk-Zg+ͭO!VU3p*.PcRfNBPl,]? ]߻Aq0E2\*-@w>ϫk}IWVW[R*?iAKx^D4 _ky:4/EMWl@71Ѐ{KSIHU* zewΏעl/ }6c*>ȗ\p\I[HVj/'N,6${cIܸ/-~fwI*gO8/A[zzgL'|h q6IMp5AZhx.n[t]h> &Tכx,2.Yi.d E2cҝ(x^ܩRJW$M~nzC'2/\a 9cQ\ଖUy5)]V#$ߚr}$h2 0}Pq{ɉdӉ̕ ǧ|6jwT &O%v}> |p\HQZUPD%H_]vfY].@DޡQ.cAD^g)Zk0_OӘh1[]33vbY8"mZepHu-bފ/4ˍ-)<'k \G0qgˬp "P\B5 %8vdB#9Scը}yƮ^PsA;E ŏ2!=u--~=p*16p.$diK2U]bNwu< oq>R=E׼d/nCtgmRqx?O]B?Gּ8vR'>n^#,UǸ9!<$F):A~ lF6 *l,[\L'Z975 ڪYk Я;Ӥm/BiW,Ǎj6<3n E:I &#l {55bgٯ 15ʈENk$?"N3~Ϯ 69Ou~x7WUP6Γ˼<؀Ktve/!%S7Y[44Irhky(>fspdZ"AOS8!PהTǙ{vȏ|Pc4E!%bYf/ҲVL^ڦ.1\uS*E+,#^w5O t8V7+7aWYvʾJ"rP 2ca j,t|Jxxgۼ[8:+H5  &[s #Kh0/i^@~sgEE` Fme =TN=)b5h ٧{̟!t<7ߴvJaqesZ^X/'xQfY`s3{ ; 9Pm W1Y3 xDA#21s(w35 PgaU .&ݶR\? vbpPýD#Q_>Kvf?$MwA˱,zxr?W"os5Cn }B {weu-ݽe_rs1b o,⓼ZQ} 90)LR6%sJC=u'ϵ [5dE>2b{ EHbԡ zE<vj"Mvv[t1ZTs i_Kdf̞ jz--+wr)X(cE!0깓f^V8*cXeHEbp.BQ̌ΔP\Sxߖ[0sRϳ|kB0u>wa0) 4q\xbQa̜!٪Zpιl,tUt,91|,iT*9V;V݆q!AÚӅ)bNiQC| LpIE/;|gB &W^lE@%uԦ5(_bU*GۉphZ'JN~a,uγd;|(5c[=yJ?Wgw6lq.`f1T VLIksu}F24,nnKVƯxvFEn2a>m_*BDR!h.{(? W[m}oT~U6'd(B?>u :m6|Պ|ggTK.6W!t&o4gDJf+> IQ@~M[2'FVsudeJwTF6a>#@" A=(O\Yyhʫ&nG5#K'bIgYfpU|QxmHNۆ9īb_[ɘ} I st2mJF!̜ڤrB w)83[Xjv1Kf=/(#q$ kސӾnm[ںGۮ p]uzA M)~aE,{ML N8<ݢZi2Mw)r>0Fr-H%)r=@ЕX+<%JۇYpL 'RnH1Hxۉ Ur-1‚LhiX=[ȇIbWMmξg` !Ů|^S TkSw qۊz`x ~>&e`L{K 'Ӝ,"f Lu@m*0X) V\(bX-l$Jp]43ŨNg^kmX~Qf\g0*RNIyH1ƥ% \2޽TB54_@x&;4rΣ eF%r [<öB/^T_n P/ӍJЃ\|) .9fn^UHdzTuʅwG0/\B14^q5O3xhz=?7 Q"'VG&H}D0=x ܲg*cjS4Cm)?vw,GkN|aWғh" nF|r TdžaQJ%u΂Y?S_>%B?Tx"z  ~tfA<ޏB #oۛuN劊Ct6TO)ygǮx6>%,W4'׫7YF rp* #[C FdG9uIĐ/H"|ltVb@E5v#%>>xbؓnp[fDW+sKAc< D=`L/x5-Teu|>_\/tuWZ$(6lB -\>$ږAwo*iڰ7fT171cv?߯_2X73!KT )JD"jV]3fg6.bOHIu XbQYBڄO<)^ ձA:o!J&94%LYwC./)Q8/_ʛctGE47`DjzܣޤEU\;`LܣjVsyA9M()(%_/7ΠhܜMri:TJN3\È٠_gq6!|;r9u|򥈤z`d#(ɰ&|%5j?A)hNcWtOeڶH,komD;Òk~F Zڜ|6;Nt}'$+<2pYg hS~-|k{>OPtH(/$j`G 2~Cm$w x՝6 .cKtL.X[VJ~ OM yH'~!aAL?"eրMm˭%}h>qm Z͜OdO>PaO^M,%ͭ:%xj+`|6hW#ӵdCv RAo1P1T^̷)(#c%jqU- &߳i#& Fe7-+!;bdtŴY0au"--s¦mRREBu/LMPjomwUSaW1qDuA<iJSP٬ =;Nxﭻ/QZtKS&:n iHa`Nɼu5ڃ{XmeС.J6](âia6jʇnI|. Rwɘs 0K*jsNuRr&%܍/G䤕N2usdDn-So9[e(cq&'XhF@wlB9dG \VTz1,U{mƞD1b %j^SH{愝CYu7$३\&HD.+^CbrxsA0: tK'ZR]ٱBBhXGHa$"}<*ei5Cy5>;J83Tx(0 X5?HqhC9ǩ"CɻUEe#̈́ =E$vT=Wh嚝WI8\~]5 ؄k9ˏXphY]ӨQVԶ< mSŏ(#ݠ"YQ1aRP ڜtMb=z fH~j(Sv_Fm%KsYFq^QtΑdW-boFp%Q>@8:-5>1F+hFtco3* @T_* r%` pfA;+UOl8>pQ:_ćOUvChPi=ZXepYoOE}p6T+ 7U9NQ$%Q(i/`65%dk@'<b,57.r9ḽ5z|mlקNzsn1H7cȑL>&Niǫ%VƮ\UqӖs%NmoZ$:<[;>8AVQl n$0urIEH^Ci55hCd}v:\vc[}) NZbN.e`57ɎѢz/Q-@ S3wi I*34`3t i6LɆ:Kpa7< gv {t*DP#XΈE:;4x 7H2o mRK(.U9IfI}j}V$m{n r`iк9q/ ZBߢ-HbGщ8,2~ġ?QR,ynWo83@Oi#O#Q5r7kUwLP &#_sRB'_[֊& {F=ˆ:v х7VE!%Q&1\fNU&R%Yo}t;*-E5_Х8Kvy;L&ٹgl`}?3EfU8z?{]ߍ>XDFc D&BnS\F_b(0m{^~x`2]2`0ĪH7T]!5w$܅-^1צR,nꡌ2ٯ٪?~hN3 hm<O4GR8( !>0 ޽t՜mp4hB)9 #W6^8R<ѽ;~({b~ V[K:fL٬pOeqa뺛cjt GsucpϯN|OmaT'G%e׆]^u4ꡊ u\P޳܍sɛO9RY MS65C_L] FUY>_k4+atxRFFHL锒=\ KG2g/G<|!f/wD>Aki&[8<)!UDQc.`'_ɢkX2+Bg#p}5XVkӐ;SLZCvzP-{ըmd}Av586Q Q$+ݯuX(CI_LrIn~uҦ.=ތP6fKdДf[YĠ4P,K}Y>_RI0 jj(w"3`OrӄrX*>bv'vOD̎7Mq3Wrg^/hS|`1|]Ue5޵iH2>4{X(R.d^jK I@8mL^a_G-G pNFn E%~_S8^\~,&-UI[B䱢ٮYq*V[yu/r|iMW 2ut6M.XiC̢rFP79y5bBC^uSʼK~x{Ma6^Gl>چgҏ72 c& wdӟzKk&>8uǐf~7op͐_=Yhio92Yl ݅hZjݙކhmm1kCNHX}MB:atRaΫ{ bSa1AZ<1;0 5P\`7Ye`nXL%ߖ{QpTt~hbæ4Tkn1eHwN듪Drgjl'H:8ҽi{}Nr. ,E*9U_2kr[u\H_O4Rz0vgN jS h+v9=6CHv!( bO5/3=qCzwU>%W:%6Qwb&r[ռW& Nυ{^Q!5;Q3((]m ec I;Kx^?D'ٺoŃƚ H&d.saJ黱+GPSz}gX ,$%6j{w羁&6.ң~느)˫0fO!8bRPUpiIb$a fjF9J\61G!k]Px!9]6D-zj_u@d~H#~߸nv~31ʶaU_N]#d}U 7!D0SԜHUq(z5wq-o@cC￯.jYEe$"bR"P"ʸd=s89ut"9=VlWڮU,8Ew61pBؓ͜б`Mr+/uak4 oC9sx"$ _Bܲ@6#KÅ첦2t*xl&ߐοaJe\C6X~l,LBM@߳t_\ْД1iޡ˧]#Ke/+5\dS)ßQSL +3%ȼ|7'8( (5p VI]X3{Vzq0rWUS=Yc3V`߇j̭F. ab:v_hf+ą46հO_*uWw]젤px`v eW<3e9ɱF1?#7arU9Բ嘺c@6it~3,0⼇vV5ĉJaٵQ.DŽ󴍊JّHSi\Sua |%3(`Vbi쑶y (y!) M?jOTyItDe=hq3#xyhȦ \;:@pJg+Hσ*^+`pY:03%7Z|sUap 1Ql&>i?q%c5<L(|ϙ:vnc$ُ6.т:Y=&cMScL=YbUMG"~R.˼2E3߅osrwp?܌T>Od~;Kb>& n$7,.a͏7rB,tLajgy 5+0ާRq竱_+)B!͸Gre'B륓B]HߦT _+ 9 wsku#G__#C;nwp/pfV < żf~ҖMHnPJ]4C &CՑT̆S:'_J= B$uYLF5 8e|18߹ F*oU쥞D{0 auD&Ug_u˂JK⫔ŌAGޜң2iZADnSvN-7;>M+,}<7ʹ*qdiρジİx Է4lBQld6@ [Jnc7竱TOS(rzrº {&.v&7 ,Fzc!=c+8޺k .R07}I*[SҐ&|bECNSӓ3C=4"]704e#^ $h2hd *MllDY99 A fxГYBj<Sk*7aUҏ8"aщھK:9*]g*FtZG#Կ6t&J}%ܠ%Y='/a^[ b&-YvYaw`=t+-DhŻdɽ[ޠQ<1\Ws:(7;>٤djaAA7Jz~Uo=SwaKNf=XÄ9f W$ rԇ5TgYbg_ 9*\!A^nU5&˫v~dB;h#/\ j9zFR_RK+ Xb,4UDHnR'Rȶz[}6bڼ\[P4?*u,>" hx)Fɱ(F;R@$r ܅Ekm/!MOaMpZ %)9: hh4ĝj\ !tŗTKJr 1'=484ޱH%\δ WNl:zCǜghL(igh~SF}opG0gi;J\^6BuX3i(&˅?6an\ac;TyV6 ދYrSQyػ$ ,ύMהp9$$4Hg9eW,'WJ|-uՇLӹ#e ]g>ӛ0{&B BkjJ3B8$Pf3 7 ,w#U:12{5cGGgpF`w=Ɗ~͊<\D! I X-'sCDKz} Ȟoh0UZ=0{AwݡvpM[ֈYK:AʘdUZ*es\wa|+J*ު|g PFKy#dTH@vjヺ;[AA\NA9ة8:cS,v[HCw b)MW]Qf7;{^`sM:>:u_|=pķ݂D GE,N"bM/"$ZF1 u G>KrI^! ʅuuOX¤_v(Tvi"G;*&__7-įy; 'P֩ "  EPZs^AƽLBsL%Łˮ`q 'F>z  _]ys\ʞb; -O'zՇWaJY7Aɯwt7P= Q}89MO=1D*Gͭz#%9$6cH+(uxb5Td s*)P+_ 8׀CEԴ軒зi#*2#CpBLp_*" $:ߑ">97CMi=9ea`Dd*#$oLU"͢n"՜67G|PA#Ml*0׹G9e(2!wx|gF}`־ wvAJ >vjT`Ɂ rR`ar@{*)`.U'H84xů6Հ*wҮzz C5rAp!,/FmZ Scu<"3*|2'@H5 2pH~vN@5'njćѓMhcQWdjFnZEWY>l@y y0RmXPvpiͷڤ6=s*qj}l*?!"IV!ꌟndQ3 M[&#`h"铢9#ӏ2#ӨNSZ;EFAļ2_p^aRix$oK|9ޯ_nO%tx}K?^_Wry%Te dT|6~)f/V6=;ț/k)6q !U̝yǺ$dB9*-~ ֳ--'D5 YAWYM+Q)ot}x?J48ʙZtZЕS#%%=[(x6rK^ff٧Ҍ/,E Rs{hӎKۆxJ١UIo*hw._+9XD_ 7|v/eY[T9ج?Z*m8 $'~` ѾH1d6sBbOhk.WXtVO!$+Af '`Wl^$4⌴ȯI !,pGZ?C'0$'lM>ҵ+VdIru ؉Cq)ARM nvm*4Ju2r[Yo?';z)3l`7l ->,4J~I;,:"cʅov+3ׂЏ_ .:MllGHSgTSz-ΌqDaUN\1TE@ؐB+nc UE±PJ-K6QB5!cݧkpV7wW1CDЛ;_[q^еq [V LJ[e+\Sm.&ɘ` !Yi*<=BuvsUN2Z9|֊zƻn;:7 ܬ'nTUW8Qx%H5^cb["6Zd*CDYZN=<لE\?YS(O!f&}ТM8E>ب 7I/3 a})Xk]<~ܰߠKvBuR+}b>,䩐w'5lF =€SэSʽR+=UC&1ԑ"'i,Bs^2eu6O'TF,сWj͋+F|_AfhY"gቮy-8ݜ[;$!.K-Yڤ=K#7ĎU(~Q%M~1+. v̇v;])qjB Aۼ>%8S/ՅīSap'n34]YӒf,Wt}cX@]*9Ҳę2,;&(@;o qJDDɟq4"EJrwހ0]hE~eR댔MaPW@,gb DW47T+oO9Q76uzgy 0 \mxѲc.ixFK!ھ|a~:0ͺ$r"&u1@N q~Dp, I៳p \YNA\"ACrs]Qx)7A3lmȷPDPtlfa-q?؎Yk0b+#1o\8y~GQ痥l84/ZYAKDg'wMI J[{t^bIȼǑ-UuyRc#2hZz.2v%vH-nFZW&~V`wYr>)9u>7B&?BֹkI섁${1,Lg!74eޗPB aۉ؊[y 0F3up G د3Z;D:削UKf>\xp=vHpK8s} lWb:9ZoӮY.)(Næu,tr46{- uu,řL&*PjwQ]pOɅY<.w/X cS3n@S[vɛ;x4plFe$nuG Rۮ}Ώ@\Y@Ey˽Z@d35ETRP1Yo!R/.IO4Br a\vuC;#E+ol9N9דpkԛV%kCIntNR9/,7  cճ:M#qN_\sSV` '7dHYV6^jq[Ɗ߄F81rYfx#ɜ޿0o['VRז~ΐJopeAQV<#%G(&|=6lk{HDdGeXAsvTn!g<7}E$fl QimPxɈ]Iy|dp @yh,ڭn_,iyx_e 1zqēhM*!6^꣹j}vW$l^Ih:Q$} ptK26qzC8K.*jKlbcyҷ~E\ |F=)0 O˰o+QL%-'JVP4I%qxp1AFo$-sN8^!W0W%.3X9Р\#fMZ2yGx-Q$,HUڣsw>akO1tR.g:Ij_!(Qk1?$V'K65%ΡPlC3SoMlXW(DkZx7/"h+3-Zqdh&n, =j9ϜuגX G /d Y~m>׋xdi)Mz=G&#}V9ZK,6fkufN=; q"ټSV=Jw|%Q :̲l\eB?7KLLSi!,-m|<S,2.Np[J*0Eqdd\BF3V&3noOg]HȗI) 5hdX2sȷK ?_]#>r ;?塭zq@P[զ[ LC|EY*P])X# ~P}b=`1U?`ƫk-r60z瀩ϙ|Yl5k&[ɟbR*j+˼b- Lc_.Ԧ;iӊ t/BѼwFBZг_>ě-3^ VvT3AjgG P[{>PMOg!^QIs^etxߏ n,ސ1#o}/Ln͎lA@)j'|a A ̵Z/5B4I0ߑzS78* |Pd|t9GiJ4Qۢ 7zD6a$v96#mG?߼_QxXJP]UNH刢+vs|,AkRQym,9?$ Nm ^͚&|Gv ~̨#q+΂p76e+u1@Z'B'q=ZOk{15ma62& 2"[ie2!?~{|;g7Q> t7HXAu'MvR SG~X o$ ˑDd)HF"7):s6|-ݳS$]~Oo$O_:Kc8!qxQkkؚa#QSVp|2M${.WbnzHQ=~L 0rK2@P'ĽYg5 @1R ڐlQ b5 xsV)+seLm4ρwRw 6Y:*|1#@7ve#P\^ۑ>Ae"eqZCsD:_0U_xѩ2b3]MF@0:4>Qj$IGC#hs9CԺQg^b췄d9}Xqrv/7g x)2TRyiy m!bbUKbj97U$<;J1e~z.j=ς#JeЂ/mE*CGRDtԴ!BM<!Kִq/2/kplZ*\3\[p!0]ZaW z|?H!o_(NKYp<7il.dvIJ!3V[䰞1MzaŧFn<{!"!Y\Jf[N`m`l3 ?AҰ Csl4Lۡ1ItMً+zRjr*965^>)`9=y368G:awJ¼yCEe [dal Vån0PiaFi_{>1Bz6/?8Ӱ>Sy y!SYKJhwBò Pda_?RPn8fnE }MX}H?!{-*Q։H蚨l|jP{,ᲘЅ^xZ|QiaBDM]8] 4_?^vZ}=2IL ?}3x'H@E!sB[D# x3_d"+fBSmᮼʑs|ȿ-0~@4OM-RG@a_r+MPz˱=˘b(4ZB 鞤BF= cI]׋d아)ݍOLg+WMЊ[8/ٱJ\j۽?i{Iy-\d{Xz:%ۛQ‡gDe&^q*PQ5߶- M2ڠ yOPݰdʜ'3 Иԅ |Z,bq#+ 2 B ! NHvy &Evk66J&k+7/q"i=U?)/CveΤA6qpºI"TiV+5DO҄Fm cyrhuw.+u13|.{a>T0J`Hjjϣ9[F.謁%I1.9MF~@\;>xs܉DSʉ;6ODp̖Vrl³+jƬ#;c!X+\Gօ:.}>z _MUf}#dֺ1 :|[δz 6UtEb4†M]/O.՜e{E۠&F@f{3 ^_f+.af# F75 T+s;8X0mDo&9cb^l$m~c֓{-?,K/`W%)shkЧ:cXѽB̘C$X@uM6v2!Q Xf hU<\S!I{0`W\)`d4*N}ߖZ=L>kZkc!Wm9jː v~% =7@3~ljezް  %= >1zeҩO`weG;pmL5+3+KFPhBV'/d!:su V(ͥ6y\ٳ~ &cP#غuBWI5d _%iWF)i4%Rئ74ok_vkyijf !w 04-Ni]n&t/F7/LϱvI'TD¾lVF&hVMQ0ㄕ3f!T#_A黒aW-'.Peg4aW#8͐K%@c!@qjjyf!˹ DOxpG%2\XۭҦOyo~Hldϟa"q46ׯrՉPf?'dz' ߁snc4Bzwcˡ*Ɩ /kґSi$ [g8hL`HfU_Wưm5 j!l\]С$@/,֌Io^ƔBa Xr7@cp#. $ ҤJw {$ߔs`)d3uX_U3mŃ6e^',&s;鵇1Nuv9ݔO%+EW-<ˈ1.ܦs'eqGʲ8eW2(7J{^bb:q :֯I3AK9<)5ȡPIQς\H}يӊ{,UJ*׉]oPhsq|u(¥H]u&zd:M+XiΒwfB`\ txi-9Xhm<%-j^+/WW`2XÖ1CK[.'ʖPT~ɂ]F9cM3/7b xYw&/wHȑ!}5^ Dh&%'IdM-!]ʼ5mne3Ք\ܔOX ()$]i.}/F'<Щ彗U- PȤOA|t!T*0P%INU+n}v$iDlZye\@[01py!2F_k{C614h)3j.~  Jc qXv4M+*x ٘ g+H`|O1JU]/C:gjAir#>P_WZfuKDfūoZkWH'8o/d5@P=!՞zo6F7K1:ڂB#zg݁fyu17Zi!I;]nAGƵ"/-R\0P mG' $B.S'{.ys]+!L W/leѷSUe]y]h[ A 64"+7R=`XE L[h5a"?>Mԕy_+/jM°U2P*3fG=c'q׀'=GN)'KwbR`J-RޮL8o*GNDJcSC׊є&~~ FJ}U6p,@} QĂȖ}l>"f49i m]כ&~,nǭs>pl#M%M5r 2l,=b|:|Ӡ*6-anNK۲:T | X1@ }Z{u͈0 *4\цK\@E 冝VQ# _!DOR2~O:r;.$&!w/dԽ}%70V}y $&(2}!n#v* 6,s;Ew_1ʊ1ҕ. P Qbk[iwz6KͬM+)W<􍕻 ZtUj`ydCw_y(wצL- `pi7Z&F8;lxZL*򅾵caac4g¿  HQ:S[26^&UY>~e#HuH}߶]ݽ!H'|v;:Vŋ>*`QcT4ʅ|0I=ϐnm,[>4șXX\R9<ߒo>=;r;SrF xPtcdb "c%DӎVqDE|*v_ӞʧPpNЀ&ŻL10 9^yh z{\7Y+0#9.\r!QEݎS,!""n7yGw:^ތޕ Ǿ#tl u@6W>T4buBr0?8QQ ".A5tGIӡ,G h@< 9?b蓇 <=ܜ6"hh@`^9P ^QddVX(yp5y۠yƖ0%n[:sEB@&-hYh2Qr۸ ^K$44|2ת}ٴIyP9+{u[x nSQ66/JbJ]8 V۴1%9ǡd;ؘr"Aje=C1X$WjD0Jz}(kؔ.]p &V=G a1WтnV>gIt۶VT`qExR‡r€NB7Υ(csL[,Yx`w7!<.r(AeoZ~/..Fb J8FmxO='v->f"2˘90:-AU g1S i~'ݤώg'״3WQ'˧Y<Ϗgt>›:4` ìVRsRiִ-VM)E:DAbl;44k$#t\lmf<<dVHbckN[Ɩ`nrlY<`ur&*w. I%Lx h^E&HpxI%cvdOڣ?[;?%XLZLr7E~HtnA k]AcDs7nBT$iEO @蕝Jj ?4ٿJct`tڠ&VR1IB0[r?Se*z7jq4FxzFogLur2d(Te{w0% k̝ɧ<:!v}!͡YIA9Q'`a3n# k3[&'?oTeފj9ήx8^KzV;~n15dx?] v@)1^@L.56yE-Wq'* }N7ZKX vLz٩oW=D{~B1YK*!QNZfzթKW}*Eoe5Z#h{kŶb(JsTaLu>%IءhxzZ豺sȄŁ4,O{8j81A>`{$ >zT4?_I iߊK&WR/VF7Ay999I"Y#P.mMӪ0nU_NFzO49VJO5r>{QuE, XcE$3vb%޳~\W)md`֑St^i3làh\k=rJ&ת7̵R?-e2}zFH&DaKLz=6& Ԩqsbrx^)Y6)"X%5dI;I y4do.2 }qpY&U hUԺh"Vq0"YMxDvscJZޘDD іQnj>*@ IYm28Kk/ ӤpvwAxod2TB""F0(l G7-wd&Āx > [5U#MW76LjOoMimޜ*a9}8IP}p% T 9:pHI ( j+ߓyxsfeo\Kgߜ;HR0Ę5E8HV6%#h"&Bu#V9ckJ 55Z{]4vSyS:33b+a%'|qzG쇰0i Ybuzժn:({J a.lQ#aUh ;Z88JЙГinƸ8SD`Nhsi7ESd#PN#E~qiVqzhnBQ[.):). C}Vfzf-m[h=p1} È˄"!Th4xjyP߼'zPN &u%)%sS}$Y(}JlRL|L=~D4,?˘@MUa 6Jbɲs yys=˩耐.ȾBATR5JGa,f.OFV9ﯜυ}5v/> jWaׯh޳ҷ)[iS IPӯ^NG+(-Gl(B{2z$Ԟi*"th1u3?ܲB+uFV;^*VB0D|4~I6Ͳuo8."*mb̦/cefc~Sd8!+?ɹ^U\{gSPMIףτ׷ݸ ?3BI+ xok9^xHƂ+dʳ*aSkR8V58oԙ"ygAR-f7r+g;a&읦+=qx5X5xrDގ}ߩb(h|6d{?$7={YOP!'E4ɓ}K?%܊e7;T`{S@cfspp|Tt.>kX׮ړdNz3<ʱ q67p4R`AHIUOp%Pڔ[Mb~c[\ ʪC镽0)@ʛۇ"Ĥ3!eKSc*#/#v:LwC =%bD OAF913R[ L66ifgI\8bjE*1PO^Sl#'6#l^j#b{")}D8mwNdS1 EG'!N#/3T^c3@Bn+R$#"} X=gIy?Q@H1oӈZ|wyWg+rv"_25S/m[8q~kN3DFkz\.r>h}I&vlDz$}q-5b)vXj'?zrvÃ.:}f W"}DDN{;X%-2l>KH`ctG/ ƣ)oCͫ~y܆ẀՖtVҩG}ו߾ya)PCh*&S9u,j3Z(>ڠ0U!(ZbLmzAR0fPa6b?/kz(H#3ܻqLj^y#׳p=M*C:[T78Q7('loa)e'aׇ$ ʹQ ʹ4~7T (u k:b|`t&eK <-S>W3y.DQܽ.(/0,z 3}u:D]t`$@eArDXNԊIhXM6i.^[4|lTsz iD $UM\8XhPu | ZF"޻jھGY{lt\ aTv:lF#B$a-SG,E U-&wr$@)i54<lmmt~}iX%)%/C+9sMl;ý#>L sHEc{97F@GeZ-G{/9>qb"xvLbK֣zX8 ªDwH)fŁ$7WXU)ɩ^WϬ7m9 #خm Hi73gfJ$Gb>jVEZh9=:?"c|\2>KqߝX?JcVIs" _T0 D? 7w+? h|y(&eT0B޲瞹%v C1-ҴxE&CŴv=+=MT.R=RO- N .C`.b\&> Z0h#2NSmP[ˏ6..80Gs0~O&XWEk6Î[[eח ? -E|u k76Jqu2.NlA(·.Y;`G:\6M6|.A1z^;n#YRE4\(/7گ5ث6ЎE`o_rcm7D]^3o&A8L̕ kEÃc.pb0l_)${ pZN(Yn#F hx]U+,c4[e3D`pN uxơQӔsaH;faOsALaOJk3dMTV1VJ*ӋJf [Υ6i z);zIj99+C}'_3n72WRF~ڤ߰//9\q0s8\ wSwj;c|M`^?O$P _K8ً>[ZaΎLإ )e2F*)tƪK[(E6Yņp({p5&AGyn,@"M]@,w1ă O;sb-!tWP'Pm-ʈ$'/̍j 9 (*ΑwJYƨP$m(Wm fm6N=gUq~^t2|M3)8Yy6ڣ ˁ. lba*9m>b@u5vGyUs!Fg\u˓_d!̖ ) E2 p0;{3(2'Jx6\tKk✨g紀rJ|JDKR DBE8u,նN݄,Oidg$ݥT _]R9>uХ*T QL}|pvM]cAzzhΟ/)u Os Q9ԆQIa '_с"GTiݢr\~*0.G\#DbOweI_15]!ػI< ;@$R?jQW H}y|2#{f0,'B7qǙ8yfL2]s Mj.8D*NEQ.{{e|/PZSBaʁ̍7ǪM=fe)"`3)4\CKS؄߾ 'TLh/Ц ߛo{5D6 5:F &sb|(JA]ᠾ>ZT:Gnh#0.)/@O>6s+SSDSbv{?pW"j洕q&gzЄ9 P9{n{~m|I("y#gqwTm;aC;=6 ޽UIzH97,N;7(t,Ɓ,DWJ xN{zƵp/_:qe>^q|Ȗohs%R~aϠ3黀q<.\ | ^IJ7<ђDvS%g坭 qՀ\(-[Uc/{''O\lᤅnE=pIΛlY#cm:Wb%i(K2 L76eٚ ڐ8hՂfRr #IA F+[o,0K% cnoxU,,eaB}bG`1 gݐ("`.!d)3DyHHzjcԝ0 \WpI"Q2C #-ج~vʙJD~ б& JIy݄#N~SjFuGڻYB:=Hn>ʤ\/bS{3:wyU];!BddvLW`u+rüJ+oˍaMT{3o0; DefN3@<&!${=*$kc!_&=vjYԢra]jޮPOpY0.OZJgUGF>Tȹje$k*B98o-KQqw=9NmGpwi B-l.dܟ̞ Q`V?STλC6?t%5j)rszSK}ն][}Y6Mgi]BF43}0SOt9LhWlܒܩ&7V [×[8Xt;>_ߞ^=&g[Y3t8Jk˸JɾS?[Óō!?ckd 8` ć? ڠ7E,\ \j~m g@I\~eL^L}uY^#3m_dd:^̋ h_2Tð=N\'ψIa4GP/Ÿ?z(FŲeʋgw.$ ̏j>OlfMD\];Nܳih#}6V7Μ$6SP9 "3[X_[k:mi4{,2|}`Ý 6&`(Om+(I6~0g8c XR|/cq(.3M8 ѭ'?b^b|$W!=M X. W/'e I MWB Y?G; w$qu^Z.yV2t]I\1~"GcMJ[ aԼkl;pwEK=%壓Mqi!>gBfSpbq4޳ʦhJBZ1f%9:q>[!"s'53kH$לͯ2w`93Y < U٣18ߎmTny>+VMxub6O- |GEŀ`1>?E}Kk<3 <[븠٢ž &fCc}󹟇#~}_~Vo&TMS9czsxd L' S KFZM">eМӰ$&X%fM\X"g>Ä+Hg51z ͻJM,?Ϡe G<G/?ǚۄff %̙'/GڭjFÐ?sgœ@pƊ~<[j,gsJޠվ3I-~Ch^@;θź;1u~63-3pi=_3&g3N~zJc/@ۀw&śqPq1OgQ܈:|R/!R|1n{)8doSB  V!NbHG낂wngohf b馹' ϙK!l{o"h$!;ELʼne'I.9Akг3 t(^54f~*P3[4NGS /nK^Yz3y| @Vo/v Z]kמ˻&$oGx+Y<[WLf OIXht&2(U iM6QRo]84bۄoy)T=ʲ_BWÎ$l)>daek5 #0ھiS>x#ݨQ彧Ѕ@#jvsJ4*ܢ"n'6Z(Ȋ*9J C.e߳Y/3~/ڦGΤBqt:we1drRFSNab9.Z1̑ΖKߙHM8 UL0 ahUd*cQ#NQ ;XyO>8 CQ!x!N⡏?+Esr&;ȈS>SKS 5_VžqIcsLJA^ϖ~i%U:`ȶt*1d$!oϙV1beUy-_ `W009>- )P,,PZ}7 &XL)MQb48(W-kl-@e5o`BNwfu9?Bww]~?Ԑ`{`39爸p]pߓRd&22짗Zk2 nDG Z)t|r,!m=ќ4#7ڍ7IC`̹e&LZ<{+Sj&KW5:%3mEtwSo3; +;HGWPɯAX5P/ x= OX>V!˭l>1VuΦafĢ=?|QNrĴz_j`DZ@jcFLkpZп:6kNGyetS0&r)Gk˕Jn2EFWc7 ѿmZD{B-R!x@ IN ڿNi#4i֛[hTm"1hqcψC/63r10h-F޵ -7,j< % ZUwRSti œLIong+4& E*_)OT\FIT]z]Ϧ0be5o4nUcXlQp$ W``Hf0sOaͲ 5oFC(wtA%NިS5iO6PpN7PdM̝iYyylU,X?Q2PGӓ:`~܅c^&2m$ƽ5sYW/2Th2j(7އGq\}lObJ|zeoD ~a uKcdqקȫ` 8$!-تk]=Oc` VKT'/{GAu| ־ J*FaRAKs͸WE5#eퟭQjŅĈ>gԟKC*^J=upEKmu}fI^Nw=V@,E)5ږJa?+WlemBkkܒ,GSp(/Hbfz@ WTq 3=[i`Uf ZOS҃ MF1#֓"rU-X5&u_m?-l$^Si@-*MGL/DDFf&#]BzA'LQrZ'`?fk6Y %bM|ǘEx^$ z`c0P@ph^qٜku]$.vnZG=gdMK!nSnMhv.Z'uSKdW<*w>C(/oyh"Lv[z '{SK 3xBo_taZJKPdҼz9877`g ҟ*}䗟 K><:Ns_)8~`z]6I~+Nw+ xPjثJإ.[i4wzn/ e˖͌L\Xysعa>;1"s]2c-'R5)gL޲E  JJtNYn'|e*ɵAݜ#nb$E]R> T=8Vz. g7ٍu- z.`GL ?}(tJёJ蛨h, ,AZH֒F%sduG9׵Qr ?f /vPb h;c?>`6Z۶RKCQo7%eyi$~:Ŭ `+!cY9)r$; ;iQrHuj}ˠv?d]GQ exeꞲ6)P-~ dID d-VO%"OՕ/%2J/wʛڳtҹGw9Pqބ1R4q:0QLn|O{͢"he}4"n[*<N#6k2m$v͊%d) r>'t(ni{c@X2Q&[+;i[9ޣr4uR۽UGwHW|$B7vC+cDTtjR`jѷHxw7%GstĵU<آym'Jx݂^XO>,uXƖY ~^Vj\ȼzJ@`ZZ<Ћlnw"' <#&tCN2I#2eZzCO/_[+^ )QMmg3xQ 7JN Y0X>ڂ<{dv `KxTȄ<jɕ,TşZ3(H{}M]Ԛ N59$GAS,[GU;o.ľmsUq3#ZL5 i'iAž$lw9>zJ k!W?]_z-H\ըtCHo}5zV}dDv= ZCМD&zj$fJ' T o[0?䀹6_hS$8w2MQe 4ȅHOia?4qJu f%Y]aY,phV9+F20d.M"‡ =zjdqpypz9 9Q)7 X ,0 hv?wHފS/{bi`_h:q|-+B33BE]GSi&ׄcE-cƤ^S/֛B >,9ϧE+r'2;o@joɂE]!._?2dƖ~ sI [c;ݐ_Y\ɻhCl{|?:;M h]rgmĝ}p+8ƫT0+{76=3IC9X=:tjMhV_.L+^okHumQ]FbC``V_'".ltm $zISla/ 1jN0|gtV2D!9+ cZ `d.%|#N邽RRS}C6m&yo~*Utf)(Z`j7}4?֎!k/ a]"6.L9to)+Cd^|Q-lW`]%Ǚ;=Sp+rC+F˄~cz!t^D[{h,~  SJ?5Lxӊ";)#@@h~Uy襢BwY1I_<+fGEipa˕z9&K"_sʺ )P8wXhyPa>,ezSWʮ*^t0nZ ú+>-xRGl Ǻ˝ߥ!|oL4U~j:\gr+l^q䓼 }C}[cr/M< 2(d[^g]PT uR\qHdRD2 em*NI ariZ NŖKySnKNz8Ve: 8gոGm15Zy :"Qw§4T+0΄W.x#Rx78,oj r d!䒔I 7QfQѡJnA&~tEDHW Hw,U Sz< (_Zz%߀CO,cp%gEP9tK*\GBd@P)22ќMIxT*Ŋ{RmI.@AT>j(Gb"KQ,c8̃P4Ln z.33 Zv5CRH!E;>@@}17\_T'I #砪_ =$ukG@v_StkuC7~OH؄kgTΆ}@ )@QLijic|:IrXlp_pK"t1|?kw&Q#ꐅߺ&n3u]yel%~C3\h2[MZ++|a~ DtFV%QyOSFJ]l <6j $:˃B*)8CYg$x9V|f_;dF" J"Ud5̈iɬcr)Lp~I[~Ē @hM8+9ZXe<]S>p) }B5>2T.R^9Z?Fꡪ?y@(eki .ծt+.5ɴݴa6C~J)3UmC8,F?=ƖB0Tg:uD{7j`.t8s+צ(`4-{nZbUnV'O)\C")TO?66|M)3@om>*UCUZᦼ@[22La JFî{wd6P\; N_2Pg B=9j_;W)a/MPmґ@ CDKP#2br;6IOTJ)\2hAL0[%Sg)HcenL^h*RiW$w A6#ꟈɱ@%)uxY":zb Ӛ(S}[Rjɑ("fZPbheQCճZ)SH|8u蔣cGK7nubY'buC er9v#v3.'ZB&"9sDWt7jqP}_^031;ݢ-C@d'.tD {'z?e(8%ov5fX.PtwK5< @=.n@O&tjp3nz e5_hCtXuPN`1t1 ڧF?U3fY[GRHzʋbCBx}Gqx6tZ G|E l 01r@9eϐU5t*5-/uy/e2:-HQd_-X-(xL4F:_zpce\Oi~nEE:`\Ӂr:(H vw*ڭ>P3\O Uzkc48\k|M/zߤ Sz, 8ZRd1ik"{!_?N*E]0a4ΣOR}?-%j?aXi%?Jۍ[ֵ%i?an9ӵf0T$_Mb$H"(F+kMJ4;xnW7I pg|)GRF"0X\L&Z2ſ8G&[4.6_9K}6X?q@ogeJS{S0j39P> B<:S!ækr,>4"*%C\`K?OFV\~xQL6z%[K( LF28 dd.3١ 1 EhnT@NLu m78q U>߇HK'T*ɿGfZ#G#,Oj S~:xQ5\yTObW And1u70a3W~F}ѓE\݅-s2\Q!:.I:-$:u!̔ECBVJmYxzwD[(HE02 RUt'q4pe_y1W_z|GcG{t]vX8c}:fF=P'ƜGyg:O4RNRXi2_qYiշu_aZbHfRT6ڣq?B%Cݼ smz_J>{т JP%Rѫ6; u5ؘV7k>z-?)6 aѠ2KW*QBV 'm7VuDG>Z~@8Ͽ0wg)Z6`L"n؇,р<_ign$:bzq>9>Q@LZ:ky{jߨ[];.|E1G ޟ%So~0~sMkBvho 8˧:nFhPCl4@Ҵ(s#[C@y }h9 L6/=&J6Nb>S3Yw53+RpEͳجga\fDfQ1hU 7Yzs.1qGWg }UԔ$}i#F9o9bjĭVzrjW0żqnGUbZ>6N΄.LW Zxٝw7Wܚ:7v DPeԺw}ZzA ;`U>"ߊ|r 0ХCpęϳCftԂ8 Ct&HnmcYϝbD*Fk|(J38 3cNt\,V|>bҚM'5 r]x#-sE A6#&-Ջ1$kM3ф<q0z?u2u3Gf;ҹX-%[1̀E, ! p=~|t Ug4 xh:v]|I?žu)5ӧhNR(喖^m2<~0->rER4 uh1 o`fA< p1Fy3?Z#0URRI$;)C{MUFj#NPJʠfp%xnC_9{uV,fkrmhFJak餧 -s-{YAZ 'Z/MŹ8,;!~n [m0P'z:B HJJ[Å#EFmDL3[3Lc?:<%)Ľf9 ^02}^J" zY֎%v4$;0,M9&8 f˓x6qt*֍ /vhgQ F0XFn2`IHĤ~RM,Ս޽}Zm\ʌh ?DG2-@g]weؗ^ILvfY BGC fiLllgǼ%nwS:zq eKU"het<&pPyrbDʞRN 67.5ր'M4K-ְ@f]|(e!I5-Ix)K2.tnyt|bqT?JQT`GZ?G촚6ķ-?0GÏTa*1,V6"<@1%#`8 r92[-=ECCwj-y̹v R?[z>,$߉Eκ܎ 䍴jE1AYe"P%X -Z6#SRyͧ8HUuFmQ8~+˜U1=2iE1@gҶBw"9mòAp69onQYUU͉W(W[=INwmID9\CGV 2r#jpQ`eYhKq֮x*Rܴ{8~w:ږ0ܹݻS~εT/rfI;3JͷhMu pL={kҰ99̷׎Ǎ;ZJ{9k綉AS\ԅ3تP{&Z ot<d4}/&n) LF5Xs;؛B@mᚧ_I/W+K} O9MsiTtNl!d'" tGxKq@| '/pt_a4K&*/[v㹢D(dr8_bl 3Qr{yJXNYmFt׮`OS49P$`j! [,zꝑX'SON1hĻD;RbbTzj6 `umw'#<0@: &ܞg2J8} F 1ZV^|`];ꕀHe@m!UlBU~:v:rbgq3G`}ջ bg"Þ#i4 +UYurSlz1zQNs+Lo}'R>8SE>A@_#~&Xb e@TPcS#;%LΒjM|]ث\J\m9g˱̯8: L<6V5jt "i/~MZxI<1-\ Ev@K"qDx=l6Zya%JЛ{jpGD}ooc4;QkQU09Q\% iPUAci?h¸ oId#q9iH!aצ7wH-Ah/AIgQ1x`jS\ G0֭51 I^owbԽdSZ,ƴCF2,UPtOTVHI%^ҵ0g+>KJ4h(:`.ܮWe#|SH1paΣy7M\l`tK;}XG-cIU/%<9M*iU6|T-͔حç-Xó-ʨtkpdȓLٯC,v|9:5ߑ7PBo)*ka#~=X#>d Z ^<ٞIBQmU1;p6,^&z.wsQk"O}4#8~bx| 4]_4NGaԚA63VlQtǟМm'Fn/ԕz!cQ$hHeB~dݣ*ǘcɁ)9VAN^v`5" G'a Ȯ&[sfǽSR70|nvrKBMoR, e>o[ZХ9rJv̐JvLoXA #HRy/ 8x`M # ț5P7#wK*\F&DN2^1rje99/!O*4Aā g,%!!K#peVB_Ha$$ e/D-DgH(YMHBnI n:z ([X:AyӇ'FdN`T1$yE%{hJ'0~^$x=K>^'H|`E9[iX|Eϛok6-`Nc;J`J&]jqO;CbK27s/_*nTzʹzQ,'&̷~T! \JtA+E G~:Go\VxTGI<91*kZ6p`^tD)R}"7LfA/k(֟ÐLVۭW 2:)jsEKse5l-TRjUF0]eW:=ӿ+D jg*,u!_t'2ЁӴYܠiN" F\;IUSk䚩>BTnd м銹UyD[r !i1V-QEL֎9/a6da 8Q`]??(EVH ~~;|:UEIIHjH#5^YOxLbrٍZ\b= rdFWkZ*!{qRӲQ+iH^ ;BUU qT, xǢfszVޑ ŮȟR Цe(q'ãWU!_D8'UAa)q;z9widk*tv0Pʙ?B!,u%FZmA0聻hayJq&ヒ|Z  oe$Iwch=ӡiz2.k(g4k`U˧$ tؓ,\e&ԽgQb+2Y<+`,fžm2Ft@3/66rU95ZKHV,jdr8%a5]wyE'LqNm9թܝk; fw;c9bB@wӐW@nr@*?yP/_ Nv{61fDW[cIĨ`ϛ+vRfUa3Kl+w{imP'nէ+ `rL5kQL& *|HIt8qQkcE#ӝ|!{EΠbObúIQ#oMv5xݠtVM@_`EQuDI#Uӻ74S|hC 'T;C"K$@>^$A1z:a_K\JM¤^gB _olll8c(.q/ǖk~Բ'LG4:ۍļ]]|G? n诽OEX~K!(T 2r'J[^'tDuǒy NO%,4*BSY4p"9LY8 zL%Gψ*[[2}])M:}$kftg\S&r>2[Ivn>Px0x{,#L1`뇞_@ZZWx XNjxR^RVXT9P pkce=m='m1 uIxQ=Jh,^?U޼ť -I ^Carۯ| RZItZ׊l YEq`x5@2zp ғ*Y0`UɇQ4+!kRr' gioy .Af~=>cO<\N;ipW.ch{4xsYzT~jfIvz*&jE+Z*ou(A yKNbi +Ks *"too=3IcT To^Y'Op( d?%@d/iÚ~hb֎wCpZ;UDoA 4alBk \#'o@q;=#'Y0@5ʒ'T{bv> Ĕ辇>fMIYf)>>Nm:yDx };NYB.![MZF%YA2k8p$)@vՆcՖT}kl. m6Πav@Ԡ ٓΟ'4ЇQtؙϷ@[Nd~ykޏ.kRτu<+ó9,e=%2 fF{8At sZ"{ٷqx 8XwbGNnVq4΁^'X(T1 M@3J-.YD(<0nDM/!@] },wʁJ"J{e6<:7GH=Uƶga] 4I`́"H$zsBcqZ3?>x/h-=iUE\ Z{Z]YzFj[,<_R+&k+ټ>*ِӆzYE !]N4TPE`v8Eǻ]bVK$KzHx|c 6y>Q ZBXütmb8dGuII1GoUxgG:l$};Fyi~(CVy-]\ +)L<՗BlلiRTsDP˯yvZxU,?C]keFv-y-lj,q`+Ǡc|_gE&<'m7ǂ&:~)Yj~w5_/^ŞJD}mE8UB~m7U$)ruưڤ.mNz_7E׀MMNɰ6<==KhiӬ'wQ~$혭y&e!jLRczVd4\d k+qEoVZqXYrGu31wOJNU*míX:\f1: `'V\C?}#Ak8-V!Ԡ[6|L) ~o (pv-XFXcQ&{&lĤ۹Om^6WpdK?'VF۬d42ZP#JŴҕg׌рG? Y\Q)t5v_R|PB~xg/W^r!'X . [4@ܬL #ݸljƊj*yd|7bZt dn@b Ysvp@ ZU[}=vx#أmz:Dt_HWh &oW~4̅RgQs,%)ln9t5v,Q +6nc?K8_n iKz+3-R ㎩ S Rd0'E:ɫ/ Y\L1(5,"z55"%'zd"_}ןz#ϴ;'+[fmoQ#ϡT_!#M,j}0éh@O6v~PLMt6SH%'*ҁR67[w$#jly){ X9(q~k T3G_of~03>#`9xD-#ɲ6Es;OXn ܱu{ޜ#n(7>g53X)$#Oh_Jd]سú('s!ȏJGjel۴\RO.WG!9W5&?q $/nU4Cjɨv22t?]FYf` |y'o4ho=2Ǽ #HTjJsiʡ~Ԙ/SIE QQW?~0"Uam$q&eqZWv#L.'T)CT$t̢ .гu`;' ¹rf i2D,-ƫ=lU(xPRN>Oa!9wFGF&oˠ٪~]ZL0"&VĦkRj\M:$k~F+:no4, ZsI -oRq]տ~]pzN-27gH?PdB`eWc8t(Jc~;fb9R)Hw=cuX |U3< *lMSr{yoS+ (bys=*uE u,N>dT*Ϧ'ѽѡ OgY!X1".1HCSa{L=oŘț7^$}{{cztT~i sd*e!$ө'jǕt|B$E9!?l}5G2od3Lȓϗ&l$/ 9-ftdFD$lTcmVP%\s -<Y{XWwzj/Y/3p,YUbe&$t9yx@aòdqƮfnA {klo;Oq[j$2ʛv,u#? €j Q(`DFC|vt~~,A;91P*ԁyJTƉA^J<;h *ye#EdLaYorek3YY/kSMx{+WETlL;F-fU;$Euu}Eœΐv9)Fr7G%gr'\C+cNĈ̇9u- +vN>1NE{AF-H-XqFWJ+2FQ2(q=BR3P[A#Dw{X#cI08!ܰyoxW)ڿ^5A/*_lSkNye;!MP}%R\=hIU!K!i9Ǔa1ax ?"-K#gYEYyջz4 f}hsL;y]Ň(Ie8Mekǝ};͘aF-ƒx4Hz!)f<b=Iॢ';It"8P>E3Dvf"`94^늉j:=Q>lRU$+Z0x'(7SL|]fnDLmsId  '*?DrSє Fu<Ԍkêk|^:Yu[)ZYSxj06J2% j#w`0D"޲ll/PeVD0ӓث%1|5nlA NW28$v TYK!u_إr2NbzdoFş}RzSbsd|)O:t Op40.`ĽV>ď+e<ˑ6M0Ӵ +D-.ZfhV"rML?lhԑ0KR.?Ib٨}2)Pyh)B#dXW[Hؑ駠7lq2yxv.kj-묝_- ~r-̛p,"-Fox΋jZM#z}ſ 8&R "o.C)h>78nyj2\ .~>cLFyV}*Zw};WrQK$\_^F!Ź:-C嗐owx0`:bfM!mU RaabWWpj.tN?ˍ=NjeZKO"d_[f(L >f.-D:*l?]:S8?4o 5󥥛VU Ez! 8 ё3mtJ9{:00i^vúYhD1ojR˭v[v-tfgdjOdΚL?PfcxU#nsw2h볍0JHoKR?Ih-Rjџg,{̇]n+ 35]*feӗ ֡~ˑgV֧vTJt˷)Ѵlϔc'Hc '?B fY46_K33녪\mU/}w GdOKp~9!X F32 6Pbxixo3+X+a0icActtrK%3?2;:t,X!-Te;sL|X&f =]< #fo >+C"̚4+f%n%Ls4z{LiP1aQ0RJ.bb5׋*ލ,Dh.9arx_Jf@h*H@&W7}|Zab])l%9o33䊧F[^-ጮ[_UC&a+܂4aM')}J[7 R.ku,z)^}VjtP9($ׇ'8&~Q#=sLPP'YHib36"Ӝ0u2q/2lhD@h\]&Ƀ'/Q=r :^#Ù(TYВg"Y@vO;o8ϤȒ'1"dU7- 咄hfZ,[7<$2D B^_Y-:B_ vC/b>"i|rG&%nN6.h/wb`%W0%3ZB,)2%ځܠ%s2-Up&U,|s)jX8 Q#{U?!u4haj\`-~]`][l;qV]skXQ4IQ=%"Oq: ӄ^НvuovڴliC#AZ} yf=L* qړx| Y[&[υ(| &ٝI NQm!;{_w -ofOS&HYzv>eUV! u+L50 $'Ez*TXnPM.Ij-'[$SZN֦z<$z}#$#%BviIl w[ȢK90 @^[Š.F=j k?XI lb,^.$o޶Kw+"RT $\;zHG@δ Q%Ӈ~RDi'0U2bfLWN[[&(ϿK) H ԰us^1,C=$c$޷$ʿoIdw0Iۦl d7ǑR*T~}-aX@S\l/T%4[zk#{&#H]U\,nX| FO>r=l)4)gc9ݫVFP`1\R |}{-ZIܬ N36h2,V;~!,U|F#*׺{gQ*R-.W 7⽇X_d,9@t}2h%!0$YMtTHh`~.,{R5Dw[ LQ)"ܔ[Op*w&K;(slƙIiOmΩdwmlgP&:䊯_=w):W +y0%?Qg3RyӥU/۱Xezc0kn?a@Þ|lÞ7xSFV޷~cz^9B8_@$6I[*`eZJ2ɠ!b ͇)(iߚv߲l1(-<S#|ow& $wV~.N;ЭD׼Wb@:(cΈ|Ij%x t$|rLt;:^vg7HD,|hm;Y$ga^=1@^UOu \9 {JD*_8t-"S* ?T4h^?Oȥ<>}& ֿv~{tT XRBV=Cj ~u>Gulo D t =8pej@i ? :~%U7Vgd(bW(k>x3jȢ AΘ ͞M3aK_]myw3?Dn~[qU "V6`^zIUkA2[X6v/*$6$tXS1rx6U3Y.a)rv&oρ.5\txoLUyy|x&C2%z' WAFsmDtߍ5F0B.+xAr&cz W_MX|w_ GpLb?HOCD_Q[]j n*ykTiĩO{ ]vߋurxx.JeVn%ԲX7'X^޸ ZTcq_uε7ozT7|5\D2+kpjY~%+VT!*P&Jj|d2_vxEFrVИ5Fn菒ipO^:]~GweRaӫ24 &Jjnhű(\NdqT5V"ԍ(rQ}/ѴPvvkyUHzA6.cOѨg?m̕P>oSTIV݉Փjidfk( m WXC̙ u0h!2|c0"\#<)c!=~kp`E&sΈ$ [0#ݙ 7/Xy댤_֠%i|74]sdCVοx 3BIYW&fsվewLe#2 _iu@ i3-[w 9ѹoRW_UGa+2F~>+aK{kn*RG ER7(awyDt=ƝOi]dy CkFx~&* @e6s$lzD,ߨK\a~2wnܓQ;2VnGZl;0g}0T,t؛xӑj]_8*͘`Dj~!+:MiBl |-l JAmmޠɂŁe3b )aCe*Ԇb5[x%`{ #{B ϚQcI%rȷ=>!w#5<b4bc1TD`sEPM!i5iQf#5M(&T-%wxA>A%صUDr\n .ű1 4_b ٶԐ9m;/^ Xb\ZBEf=suAŎVLn70ڝvaSm}T܏g510-@Ve(4kiì: ۡ[TT"d*w ?!O`.X1#C)sTuиg-CU' R)]n< UUV'*d2\m`۰@>T X6+3xE ޅo/ 8![`uk$`)_2%\풬N*'Ed#\1z˚V}A7uͼ+R\+:JyV(?UB_TU(e.>Uj,ҽ5;9fk*plQ#ecCћ#xI گ7Px[ɹn ~1YB;JP'o#bǡ/.NMWΒɴܶT%}1O+S/9GkL dy[]B֭vtB~lY6:{X_Ӫ$2<c٤z^8 D]1?{'+ %SM<=d [oNW>x&~Z2 EΉ<> S^tEgxijO<}1RD*Ytaؚ֪d;9b̎jZC؏ТI}YhfKl*dKdIs)lIPOn9kmiAs:ގ)vH`̸+ƪp_ãVmxOj&[L^e^I~ Q1ᣆoZcU1)8`p3;_L`|Q+K /&ސ{VKL"8}姼m{trY[ ch//ۂ=yZwr΂YEW0 "qN[[#ﰣ(.Ҥ(%{@3XjūQ˯TlQEiE ql`Ժb@ ޢa'EqŖPJ{A -`yi‰#Q|pSъ97Љժ5\D:߆(H%$Xu ۈ)ClJpֶ̜ o=!"%BiDE§2%"͌}_n "~m[LN_I;T=_q =.DL QLǢBr Q@A2$3+2<.|2o9Ч-_67fƒlFWoRz+jijA؏gJJ'/*r𽑏S~6ȅ JX>s 褥䩮/}/99{[ځB?blP5k #} Q) S6MG:9] TY٨}-^2,`<ϡ zʸT#S:nTd"{kOb|ئ(YllOݩX,X}:2T!'tx.lluчpeZ-y&_re"=GɒIßio"B# CD~BS0OdzD@B(Jgaecj|60dY ^И0Ewk'[ۧ`> z g,j,OKD }X\ /3HIx 423濫Sg =edn搰7fـp?q?&˓NycXȔu*u^UZmysp$6Ъ|1hUJ?- zLXq+ƞs*i9*O<($&ޛJ/<RJ,&sS2&G;PGz I0dp \ F)ёdg1@9]X<}~io>G;_vx ZӻSۏ5'p˳ʍ果ɹ{/Lтgc2C}h3{YOAKۿƍB\l9d^<3m얦3[5qܵ:b|xӰC'6h(f|[(85[xd _Zj. (xFZyst. uPެ_f8~]Eyϰ!?q+=E*eNh_g#d #KPx'Q{Ii+r:y$ixzc!E'DA/0cg bFLaiv[sdnF\ (rȎ9WK˨eK_?Kϭw7Zv[:OOCL~e,pQ 7uAi"]꼃fqgn7  ;y<-2fj~ht0Oا$OO954Γms-^j"!B{Շ@{j*&SPm5ah Z̝UHH!UZŤm>#Ew55DSLMJp >ec!Fh%iJ2YM:;|+7uT.aҹO4Bݧ8հo\*{56AO1 _b;GԬ+*'" tl0MhME@ʬtS{@֙eRw$ |šzqY==' CG,5wn~>VZ_OIYVP4B~liβrŠJwmHVlx } رb_@<)/Y;>0a3OM`G%BDq] d GLaY[<&^3 ;%:pɯQ)rvii1er4zcwLNR'o@=Hg|L ,O@zޯ9wT%Ͽ;Qk~.%AlP|c;$>ё[ݗxBe@W%7Nh۴\̑Hq~;Ƃ8kln>A_CKei @_;k <ʴys =3r7}W |f~K}֍HU-c!d\{P*܄oZ!4"KZ1DR+RBfc~ |tU-maEʫY5P*p1'46Ͽo⬢fYV~ߩcM3{q.7 }Nk#pBc2 Q'CYխ[ IN/ Zm@ AB!hx644/^IC^tq:Gh"Xu@d;ؙnqY$3jYQV,ߡtz\N5+(CQd6rj3 ޠiTu jݛ3Y\4K@|O I-tO'-~}ss'(bLln(024rF{Dj?aK+8ՄfsCɪA̷mۊ"缄c&ɰR4N -W7& DCEL GM_Yְ S_ys4(ʕ ,+iE_G ŹXɎA۟2 [ $,>f%gz!R(6Rgtu@p>bJ\“E[H-Mv ،QCIC#Q/99gʐ!pG270"6*͑WA跛gD9|'pJy-q O08 h <&ȧZKUBbdM%\ |=`@ը2d;~`{7 m hHr.Cm*wAKi6 T*^󔶈U(@p..^ ;&|rOP.̗Gd9BUͯ= ߇!NΎ 2k Q,=w@W(I4k5B_ӧ=v$ykT!#pMpKXVdCtE˗2מߏ/A2ÂGC6y]?#~'RXc)حWD)*F% :pk!K^L'/0R\'{ 3&bYz r ƭ^y!~eUrF2'Q?ˉ/k"bkR I>mob)[r8qF),a$+lkQ+q2nAq^aKdʉ/|$[c@3MAWFmʤa|JV`ޞوץ {a }q*Z~JT;v5 3ne0 .tDt[ycYLړ+ i79h6 +K4sz dhKjD{!]sY1jl2Ó96"Y 6hfU{`Yk$'T-,3q>ZGAǏƸPU1j Y9fIlJz+t tޠ{Tt hhK]f{ |F$ Rw2B erI,וּwNحYWK܆fE[rфj_ RGy?ScfkuΝDhH6u6'~^?t 7 }`XyՖ@ŠOύ<6^anp/JogqlyeZ`H hYD?'e#AVhoTR:5'}<[|KԆ4rbT*RAC9}AS,>Y(㷓؄L}8Ҏ#1YrS Q._q$ӥd,s\9rֵ}m MgG!\ڱfwt|dRv~b`|<=uqc;Sm%}|Ƌ DX{:b0 \z4+ ㄚlGFB`y00rx#U& +E%'~TRO,rLǭ8k?>ndFGr ݾVQESpsS)6\T.: WZ~'JKެm/AqUo^cRǁ[=٫;TܐΙFjyeoq#Ү֭TdҘOh, Kх5OEnB|LwU7FE\X]&⭱"<[&'X;QԄØT4iٟV@BJyIYfsHn+cݡDGHmf@4(͗瓯P@/gЛ>L5 PBy9gGC:OrA`6&AGᾔR'&-c>VZ<ʫQ4K*A_ո4fsJ2c /ko"ȼJ%iQ8XO  FRܯ"p@dAF ߚx|CQc7مDE)0|єD%͒Ӡ,S>S5bߚcW'tfYOo7c NV )4IcQCS-C f|wW $ؼ$q~齊 h/u;K%=`M*rӕ%T ;=^3L`F1(# kf5]e;5~o?2.vγ'G3:[ O×% )4,T pQ"G&WRg0zqg )#nKA25 0˒('*ORFL3NCMUpH=6ټ/Xy`?<ZftNSٙڞQvO?͵P.^9(Y& QcCt% )T/e|svڃF+vHTvk  r Vcj91.ufxC( mO뭍Gkcʷ.n2 q>Mږ%aAYjꭍhg% '@n-"xSCa3Ib3*0#置؏3,\SEroU1n97m\2cv9k;Lv-FheWpEq6>۫YVAF)0f=o,`n#lޘda.n(iO&V5`q@ ׁ3薇TnDJ^U f9NO3YBSv'ƀd z[>y**E \mu\J%fuܪƒw:hı9Qu尢 YĉiH775I8fWs#*[|5}mׂOr.9'b<:d_ Hh hؤt C'ۺ@)g`$ύH1̕{&iHVI|c%g/5g9sO^C=Tv){Qٷ4*aɩō0'ҎABJ堕[,v^kx{e==hФ.-f 0c0U]65Y: O"|5M7;衡qϾ%5 S󠒢lȥ/喁jf5kfD0:9wLj7XKZ\7OBW3UfeȡU-O< SԿFF |[QՃAo_Mx1/h WA 9bũ]sjI: &@owE0OBȞzFpɦmJ*X#Hz5 j񖀗hAvkNj?4⇹wBXBA,9tW~YqVW2}.zn|50z9dY<"}pZ;*̚xb\Q?3$dP9{$\ UaYT¶w 0;);ifQ-8rSM.*l,ʵ+^ELo;rP$v 9f6XFnYov#Zɤ>L'ڣH'痿=7t4H Ǐ)aSO%a1C*:n!oHbFx٘-+?Y"ACgϙxm{72Hr6O_Q$ O,q5n 0b-.rdY+cU lɢQaS}Y OlKYK32Oe}&M !#7-:lJ"%?q>U>' VQ NZ І@"VN?{<%PPy1_.!ac)tg˫%첾ΙcKv ;S|>CxkBLa汱 ()֍GqB뉩~\a 4̱}ۊSM#Z&LsHC_}5UV y6 Pd{ #kY5P: p.!z$$zwG"ǸUGa&i7xNL`YFnJm1<}SB#&,e0D,Zf "SAJ l1UU8`PaG,mYsg}^TL&fN*#`'BLKh3]sg':.< qgb58FJ8ҥ\{$Ra* ^ Rˊ4Ko8!n̓q3i#jң*X6$]swʆZzVa+[ &q>O]!cS|w4 mTCc7ȰEn[+/Xvtg]^^Tt8i#157^tyT宅clң7IyJ-T+N~?ٜ6Z5BdG\S*yO`d,` {mc ̿bck"pb*)}- M qH=P:`M_9jAeHd,Ƽ!l(]|l^FP^,Yo̟B*xm_ D(+BMl^m 6hȭ+|UƯ}>6=4%R $xB_2v<07Kbs +bHZEwqx/<7qY8ۋgbGzo=Ici l9l:9etNy7gX2XI(`# K*uEgdž7!"a 9ɐQPct]"v=b(;V1& jCHׄ-h8f:H|PA~Z6SpW(%c!B:|_’'` v)=m Q7OV[GxEWbFkYx'ҝ?8T˯C\a&p)tqk!ϜZ 'HڡfckuC!J^uXiՋlQ[׈zg5zo`k#R(T +ؕ4ޓ8HT:vͧqnKRr9^\.`D憻׍e:?wSm 4D\9k w^<wtw/-fHAKY"`EXkߚ6#]r0rCȵMg<צqb9=r 3rL@y*is*}KD6.fjʊ2/ B:Rࢨt_5gWE5Sv!0(=> 1_O,cq}^.UN:C#vT=EkӐOW&Z 6BˏI/c.Vm&x6餏DW~ɰ!I嬯}jԂ` )i멀|W~q41;GZ(>uuz/)f-3}TG)Es-s'nӕcn )>RBsV=䧟af+ҒƟV-yi];(m18m9* 9QM=;_ؑD?u= 5'wyEP}kyRss{ :dY{l񭊟>ı0 =04_@B'Ŏk](FY=u녊zBb3?AO " FOhwR.' Q1l2ȳk#C&x jGj 3J1iO/ Y8zOQl1EgޢdLq~m0!_;:GA j^K>ܗQ\N`)kг \qE' NQ )TbP.ZǾqJw" ,!d΂֠ᑦ[͞`(=e6x|!*GcqF{6yf" îjJR}`ʃa0f۔~N/+>ch7w,a,  eGX=">S}vAt@ȷt2gO 42%K]H{ߣ pXErX(4 4 XAQ[W:5cxcj9E"d*0Bsr8C0':%_zk) LLvץҽzE.\qhjx85Βh2R\D<w?Ym&׆o4ϛ*R~pȳ(p]]*&:<{ >A1`*颏*Jd vK8?b4+ =6ٔtcg4%&%%d"QLD=]8|$]~V/5@dbn8PMG/g@_,`v.q_Yf7oOt=T%M KGWl 'n#TfH?64CG!az^x3b756ZJ^q;uȡ@Ņ^( eJhkG?]Ө_S5g ӄ*G>4O( qAVO AWEC aAA,qgf]R/DFhˤ }N2o~#P!* )>kj R/nrm<|0fM'MmdW΀]F#$SC<`=\%w# ;x  Q ?"ov,G˧Daux{UBIj8`ԦJ))hqN<:*eB >j xv3(*29O }걡N]D) w#mI s>Ud %Q S^ }*T-+ eN%Sp|m0_)M=Hl??)ߨJlU1X"3]6oQ]`+D޺^FOmaJOVڣ< DBqXqY>%cgzn~?*K9Y];>l.BD+.-?g?[Cb@ 6͇F- ƠC:HS=ӂzp` K*umW'֌#EbyLL0 [ߧtd ҥ2V>ؗ+B˞Hu6VT/V1sKK3VL/~\[lv F .0U_7L2 d ]l=B:y6&Cn-YYoTFnytƼ 6MO#N*ZA6}k8׹dt'Բ}TAǼd=+gxKo!R23j"}_}8pҜ! @{Zha ,N({EȊ_-O>4S0cڙiEYXz'U2 6mM OX)wT93|CR^њ0C ̸0s gh͹hw;l%Cj>Y|Z?_'}kzTM~j` 9ч hh>ڢm":LAPRraJx˶:rsxKЇ|q݅ޢ J[CWofdG KI%ч%] 4|Ne}c[fi2K?P,;>]~,$qθxλDv:;xWGO "t١$&K[jt-y}wwHNC>P ug936XJ+!  7Y/T/(;JWUDk!cg=,d`0ߋmG*قsPh@iGiۘB"΁kxy'a2E5S凧9] 0 0ٷyP|̿m Oa.d'^ow7 Czjجag5_žUTBIZzF~xCDp#B 6V[D58u똢l5$g@"V_]@ f=Jp8/⋎B{3>V#4+,wsqCE>dGK89 ;Esuo#6|F`lhI}\e&$4e Ѹvt|?YӖ[:KY )!dOh%Wgzt Q Zai" ʩm_ !) +*`M{.ꤳy9p$(W;UL{P)ERZ녞O#0oR ]6D,Rt6(*X5+c,h"q" lRlg-e[lQ k4>I#Y8$QZ}aqr3!>*~%+[j*Z&I9{uLl{qb)om.,]fW>v 3Tult1(.26d}| +M4vQdЊ Fu·zj*W𡬛YX ! (}^Mw eo5g t(lZQ8Fm,i5XR;ugyO1mNFO,@\V_ rsӵ"XQ $XC _]7TK)\9HAヽ>>[QWʵ8m}`C酂Z$H"c1PCHv,7'MMpWq9Nx''mVRJ;{uER u&Upxኰ>N>E۝(V ^*3f DuAbAeڔzϰ;}b,MaoBXR{|26ȴ`nh4y& ۘ{h=/Evb׮>2!/1d(L^UGmݤ{nozu׀o.cɺ(ՓJo  ɚ'6=1^食483G8A}ۯCL#D AB#/@22ez&_ ud{2'_SUS#<_P  QWccwvqjt=CEx /p&Նp/ѧ!<İVnjE ^N\{̱4Bءg%YAqToEL1hP=mǏ.n+-WGN_$/sL @S!*+Yd[E!,MR+T#W`@to:O>}t*)hZ^2n$fVФϮv?i V fSふrᗉEXcYҁ#V>aM Tߡ\( \;H;N2HIM=M"`M-%jo)">!RT>g]PMmxKfB[[O*qCA@E'Q;nE]Tlwhx:.!2o) N[q&r~] gan3S]נP^V١O0>:Cp'3P}J94, ᮌ<'1l4!lA)'CHF]urXe6(ƪŕxIem?Yt~N+A)<5 }W~Ž֝fI<3h8MG(/#84P)h7i ё4t%<^}YXcs'¾?m&4\ -)`2,Y[ EB`٣LF"7?xBT »lwS+.a}B˻+TW> ةlO \OeҽQ-]N pSPvK Nu-}0 aSfɈ,Cbm7R{Tt59@*xf4gg2g/&8| 1,xobEОGq_7hiSnzM L~\`,hxO-"rIf|aK-ҩYdhP (2!5*Na<0_@@}V: ;_qDWo'$%mV\>1zwIy$H?3 kJ%ң|b{ҁ.qU+ Ȅ@2𰷬_'&ZM1wGh4Z+'nCI졨K)2עMm:FKh1xW?zXP;WM-ѡdYe~A9"SP#oURyՈހ%L"lq l3z| ne| RÅu1KgVC'RӍdYUcXǠm;wS/H|!ûuU"Hv D\72HL$+Xm؃a1.bO. 1te{銔jPSCOzD7ڮ1Eoߕr+0C֢aXK%UX& k('LǸ;؃:!t܀5uUOâ V@V2(nRE7Tնb7XAvQVKc'T'@(&OK1 ý8PTtSڃqR1oźȻH_V"Ef]ypBKe4ȿ a1VLA\;7ˊq3qpe55PϞ X 2[7A; VSR[Pg7n=SN 41SqUJ/*8Y?'fƄ"lb"oBH}/p~S_^5 Dt!^:A]U,zū=SjnlixYmm<3Y> %ͅTTL H iRkՉcʹ{ZkB$0m*+ d/yquD?& D'q}P(H?:uXj Vx1DLjW~r3c2lΰ2 37HL! ;*!8qX;:ejkMB+<ѝk\[t̽/0`3Xk ahC#lQGRFROd~aZeYz~ID *g|9i3SRfT)Ѡ uJkjK< g Z 0ϚK{i')L}BW̯s(8W|jP'X:Go֖qwdR=_2o=;kTC>+r4i-,j9ne`> 3#^7iy>MJCNUdݢ(qOڔa9{A zJ"DU7fY甿7VޑTORDOKdH blGH=A B>ySޔL'2P݃ TժMq8BEl%!]y5 ~ UvgZm9xP:6u,1 5l b2"K>EǴm? =03Gj$u=?;Z3{ڶ$d#3 ybL)Q?JX5 FSR~3fauՃ&5Q-ב5(nxڃrw.\`=4mR/ S^lO;o1Lԯ#K5[=\)xas onmt$<<@WuwIh++sPP,>MH宵RW']܌PTuW %DV6!\ i6:"L4JU. !yWKWFp4r1#h*f~&5%@#<(Oګ ȬӅ؀+R"5a1 G$EsM%['v* uz DJ}M?–{ up6oYuINb6nߪ64(3qz~ uܜ/6VUU >@_vZ4cjcuX uRrnhm *g;yJ.4+\к\Ox q+\Ui?.rZ{Gҁ^zmjIO&'di^]U] ƽސcN$x:+IXGnjZaclM]2Q%2A]&2< PTf}%Wy)aJg;{"t>ia*I&zk*~CvoO ǣVA<ϥ$a6A~IؗX0rj]Xb~50}Fp5wa:t=3}\Ra<)Og&qL9"V$ Λw')؟#wyw σ*Uk)Okp& &5Hk$fnmvIie`B#`;T4%č0WZْb HMHmoFr=ո@͚?pk ^Bxj))2[W}ٌ??*]2vL[7 hy+1R5}hb=RRm`3cm9Y{ĩuT˄pOJf2jvt~sӼ{X9EW 'CNw'qatHV\`q1pUҊ*^3V%,g.nb;KZJ*@XvLrs^_@"PQ Oe n3-|7&mЪI^ϸ}F3{abD K KNgŮal>X"jQ'X˕_[ҏ !kobAX,ړ@1/mƚٲ@K}ڌ*,qBc@#kڸu+ $f 쮇އ@T$$j—7CcI$p!uys)FI og60I{DUK\F#fijE~d\Or I)pѶqK`{x2X@](I-me.±3EƙU|?]缴 l΋B`n|E\ mDyЎFRiGCTsu OfA+Px^WnX=Ǚ&!(7+8uqʼn.BHCeQ ȫY(%TD-cllhMSld;}TwW|!f>E1VE''Dci`z msه5U,zHxy7r׋ Cf]jz#-30qbN:=U]VK BVe|/]ׄɧVP;n]f}jF: Xrb#FFld #Nܬ;gy68ON_8m"dQu<\h+`2aDeK@i+^];o)0TS[+8D^ꬬ¤Y^8&`34"b^гr;쏂u/`vD8ĀMy+j : a& Jk(ScEl0z# /mopxDȦd6fPQsiE 6uY2Թ^pP./hMs(&|ڠE$L:CLpF{ yi$3*n f}W?^9ŌM,9^Ey͛3!j(TAԦ9s D~;8Prd\Wd$H]nzI£A[ɟz&)=:ߙgU- OƄ6VuM*~Q߫e\}n3&>]/lwU{rr$}~9ˉ^{_{J-̵e'ɜj0/7""IQ"R(j{qXmt[ DCV$ `-aB|nb{Y:4s[*s f*M%^`(hK~JXM wdcp‰dVBƹ/p'ɑV9O:5&G~Fmѓx S; -67!єĮ2%_=Y5 \B>R%EA^i#<Eΐԗ f''vXR[ ; [.@ӗ`3P)dxS̯ܜ9iC =[Ts5 ƴinKBELΠ/p.D:gn뫋}Łt ?^&zMpG%0.\խ8k䋱c[jh?qf+n4i\ t0 y`B;Jd_cF=Mm1t{Õ$s4ȚREG/0wU'Q꯴U𳦼XIj+(-6BkD?1 ;{8{+V@](}=.xH#[P I[epx|WGcWXZ)( v))f:%#p,6반Ǘ N {B;CG>?m*_տa?Zy7Y+e,gA'Іfk;F&=Tݡqݺ6,s $RjIױLz q47Ӛ1]Y35J:' >*tNv|c!8)^ s uBf'd0ۊ%WlOXZItOP]X 䅙mtxa$˷-D)PAfMp#IGgA&YAм-M>D/5ɪ6jF?\#Vd^mJx  @ipB)Ѵzb{1_F\{$m Lq(>Zx u:(^7|*9Pk'o3z9V[/VN4&>"&5BTU R)KT|.*fb>hsTe[쫽)1HMMl@(owqS&TͿ.6K?J/bO'P?P%B `zbSU~xx_ұJb2^yFQ~d?LߌQ/|`NB $ϡև!'y> ȓ@E=hC4򜓿HPG ґB pyqB?& H_X|A m@F&`[K;); 0A/F9ׄ^z̺-i|IdPƎH2M#/i(xH5Fht,Z6D"Y{(W0o2G{" OaB^ k:njRoE}<ĪUSQI7T)`T TI*/ 6#='͸v?c!y9w}jpn[ABE ~  W,IoD]dej2E];^+cPBY`*DjgxJqur983(픴_^YO q-47j=M%cs iȾº C|}9I}Ds{[~9DG.z \2q$./ؼ=1]l ⓯>ZFm$ $bq?{=2ggv l.\WP Y^U˯קZlY>nu|;Z";"*,}їre'xG 2`rl dF?ꤊw dh?$-:*Ay ¹|#{tn1uɾ_/1Љh& ;+'>[[PJ6 ̑Ya9次i2GLH֩BrkS&b 6[6sˬB_r$xv?⵾VR um:A߉̏`O@l?i}A4╤LHD5m4u1RznNblgP-NQ@xt>?&Ƣ NC ? Y ƑFp (V0yy^npFypx>ym'z-+|ӛ7XŝH'fsMāՉ#S#1 !L} nS诧=آ!7[ӵjZG/?@Fip#mE xg9"D`[8WhɕzmeZ/(ǧ]NАߟՇQPwM]i}{uN;-(~Ήv'zMFG.L!x|aɑTRw Zzb$Ga(7Q04ky//%,̳Jxw=X.!ai,O-ح7~HT{'ZR_CLVu鍙"1 #1^DŃ aLU$CAӄ% Q#Sls×3~*G 8h} _1kQش/߾3Gyq~0 L[Jx24K|Z_fV6T^r`5T!˒+Ckgʕ'U>xxE˂8!oĽ$ ,&t>/poQR"h bZf7|| Ýɒ [O^CΩ]eDy2EE HLBJ1ە."iIHpW51|453PFW;w&8w-͢|3EզQ#C90#.΂_>rfCUwC蹠%ƮZԳ&6\ESoѨ,˂]oƍvkZYOɌ%p粭<"P2 Sb7"9[9YK$fsEp 1U0ʨEӏ7K"H5_*rRa!L+Bh_ TWE?*2AUE~&6 }f0^ Bpc!7^_.Ns-h5`a;rϦ7Q|is$}ދUv*/%%V ON]`YlWVID#~}1٢VW#ǔ#=)!@X7E@8*M*#XW_Nk:.Hf)VB@MeݴDpST9  USd Op5n^;ĘV)ϾXޞNKZkVNAmkN08Ir [0W9"/ \z=|LJv?ЀZǘʚ/4;]֊.:xg#z&4؋TBj6h]>}iU Khv*%FOR'9ClsJLDR+nKi2+#:O*GL C[x3v|ɞZZy1E< h2GSZcjQT+eѕGtX& H {A@D#h=趢%]gEsU:bmMvE;n'v8{{xk;cωP["岲^7S%]iKO]U+ ZDuC^#i/גjVyQJ D_,#KU c~]*3w.Y1rxAS G{(pi"dd,t_$(R;w:R^Y%Bյ Q5sR$~ F~O{4.?9O}wA "~[/I-D*f"1Tl o'exɥP/ʌCρrj7jt3 *kC6fen*bgt?үl7D~b n;lx×@6Rܭԧ3ArUXzL@ U\QI/ :h+A!ϱl7P#(J[-M t?{k @8959N(Ϗ}[Wmb*G^9Ki0:~ ɔvObQm޺MkftTajNO.N^WbkR3B'.COfU4^g-ͫ"8rOz^ $E2kin $> Szdk`Y]-][R4.5W_{RCmq;AM7&>@6%}>6<&;y!M\GH(Pqz=v si:VHl161R٨5"BrrG!pYVY*w]3QLܦЗZ1xq/ >j#hE$/!M{۪F@ !!,_G*|` Qo:렖YdĒ9m`/+,驟{"f_SDtUuNc>uF6H{6Ғp8). g{ ޵`2h"8VݺJOh-!ϗ͡=',#0qM^GCK1+E}lŬv`nH.瘩]ujN/.(anG2'x?׹0`Sy&lKCVb6qN%Ph VҦjsфmo`sC EI^wĄI^70(%[o|t~ ~rIuj0 %ko;uMWt,b娵91;5KWYLx-|iȓ}\4Y!(dgEHe - Ol\Z-NjE"pn# CJ <s$2c?]mFF:rTNy,x$Z9P4OK{$!SD"n_u },*هp`{4Mg]Fߧ 51h8N;]+HX:sFBtru :/Jkr/`OkNPvc},P NV;DL :&/4Kc,.A;5!̛E>Ї Qt0JAV%q&Ibźg /ԤұMPVUqC2#cq;fLL^+C7M4azBl"  - I$ʔ>x{y_,?/PX4Vӆ7hbv v*0ˊ,c B96xIMOH%CʧA6{/l\J>4ŐܾjHe;#|9$5k7<1cj㥡_c-!4){'3?P mWI8=(߅v hWaK;ohnLa h@i{zJ՗ ) ;e(QɞcߞƬ,m/̮(Dfҩ鉳WlosXddP5 0uF=*о ]XL:GېF]87[NkO(xzoѽb<9ٸ@ۃYVRç qiyF@sp|mj{r%Y 5NݸXR'"cK>+,]*pwIfZA384b׻98Ȟe5AqD-q"R,oQ8|&ӽp8u&f L |YPsgMvmi},}_My.!gY}j0e#"hg诬73C&+Xutsigyg搛fuŃKBK6?9%B[9as1Q>uc R6kzv[K`IUBkM5tGHŵQqc(,11}hBPbt2(u%:mcZ0~bަmyqN;Z" +*Mk^Q4.pu?uJS9 4)+*X̬n_z"@`y8K3WߓuE a@\]gQjXi5Qlw} Ymst<h 8-ޯhОpUBŔZanl% 4f dӁZvo/jXQ&^n>8.PW,k\ r0U&flLMTϝSnTI͎Eqm Զ7]y<.zZBiQ!4/P#bmiNQ]M 9QQԂZISrɅH`K^e~!|(C/f_:EQG|T` RnTlM5[b%k;L6kYl%?Ej9P҅!-C={^N)w+`pJ5I!Җ5"/J8RVXa ksuTQ|W-"]sKCBn1'fA:`?!l]/ژ2GlCHG`R 'ޟp%)&'6J5msm &QU֪]UݵǫܧOt[MmO6l'QqK7x`5(ʬL{MgcHowڅImqۛTW\}y9c٭2%e9O0܃T+go(V"=mr BP!NlZtﱣ!1N~ {CQG hJ9Y\eSJ߬_W٦s}V^- qrJSWA }{E#0;=2A GMVNփEvO[Bw)E)SWIR).MMlPrfX:H/Zr}On>j .*2xpڅj\.=\"ZU$d7G#oI<-$EYlڤz; %ʤLG?ќE}_N,FܒT$TFgiS;+2 r^׾QRC{(.:sDdˡ}IyM8<>^{qQc~MطQW!%$lSJ5*zv3^=>!\sSQ/ G𒩿˧ѬWqDÅû[T׌d8n7',~=/U S*zIc G+ /\c,=w_0xM-Y/+S&{{Ln (rSYYuUa{t*˅y%3-·d6dU t&QgSfF)Q){`ׅ1[u[uѽb/ x.>]=3}Xh4'.60l Zڻ{ŜJ:?3o6C-S7\畐c |g88U^JḛjBsXcTb%6hy]|g<sL\WS|zUH/ƲdÕ@3޽ 21./j{yY=mc4 !|;>c$$2 wj?ErIJk$LeZz9E>ys潂S+gBhbؙ![>oC"4~<_^BN]4ɉd}ը+Kcul3i`{MW^׿ΕJq֩eMd?-nRnf8[dH&X,3#AgJKDT} &JDx꽴XGbɎue<_1Z䭁&8 şU:4·)lbg/UjНtV>krɂE^ o.}$ǶhMRZ=]jTڗ]΁8r"|iI2q&TܶAZ_5U|S08A{"1XPƈH}gahQyfO*#s°:C>;D;"}[[%dvJZpDmlLl18QZnzՂ5Of#^.i0E9ʔ D~ 鏓M=̕bZ*J,衏3 QX3wA=!;hxQr 4/ɧGPup{x(2ЃUUrO[¡WA q# bɓ7s]P<|`NRP2"z!.+z7%6Z(;}nzra?4pA"#\ һC zYC˜7VW4|6?a7D[|l-*Ʒ74,7m[PqS?6l_OdICLIڋ˕H2tPrz{Y.\^tDAG H}qQoI17OaB(YfGK";.6"qQWO6E1ү~0(l)M2+5HV&eV{i=pl)utc ?Tyۖ8KbŒK}lzz\r&9):^kΌxn- + ^2|xy+>PІ\bG.matΣ Ŧi`<:ծo2}ʟ#Tq5:i>Ct;4E$] :[I`Z45>^Y)VP%ae K{q|g֛b#~?L/t9VrBbǃԍ1fGLxC-ݜCV `Bf,KKw$7iG.KGȫoP ($L=' P``+R"Bhk4)'mz6"u"_X t(extLw7Ln `y߷ʀh*j[o.!c[ muTC[͖(hvyT6gLH]3}%#e!C$C9c_p28k_,zE,ţ2pP+ WpU:h=@[^}54?{&Qt1ATlẄPРp~hPP_!ceS֜J}7|ZsYXGLFv)ʝj;YYHbaz_Q+—7%_rki#W+!\x`WFxN3P_2A}cxH4ϩϦ,QqvƦ&qph['2J&10Z1ZOx'=a}Ja'yAKee=3&q9a^΅z< }u^-!WX {OnFPF@{EF/S;\-&W'̚ sY7AˌӚ(a3VTȄ|uS2?zͳB"Kb% wS7]|YݫH3c @h8o<~D<[EI,<<$Ôz`4UiO&X/~ f}\ ~ T*q˱RcT/\ᡡWmHaBW´Z:!Q-|_sm͏SQ胹.y"&+ Ag"DTW~޻/%FFWyK_jOxKo4j: xg?̓$]aZdFp)f$wui-kG(5E⥥Dy6_eyyppϘIŢ{.u+M[ eFtuHlG+ȳ*دWw;֦T^#x_  dŎʌ'BEs4ӛ }<'8c\%~n.uě>MY4:n"F{mO.Ab\A :2٩j)SSHt6(}%e:]JWTj̎гO]:>#j•!*6e}Yt"a@\va0F uG3-1.N)Vxpw`nGg#Y;dC9A0aq/N1wLx3IF=ppJ3B 4ÃU;{zӵp>`hY=8x1/HUo4M7rׯa.Cq87`{#aÎX @G|78|m|i UIKEZI"c-c 66n/Tdz'|].> :9;"hz 3yI 0Ysf޶Mi'7i-&'L- AKt΋MEh[#GS90EQJ@ -xz#'yX!j=U@2Q%'IUc" q`tR2bGT= ˧&3پ9"Cj4 5rGvb[ac@e_E/ƍOk . I _|D1"0oq)'UL+ޢ.wdE, 0 `mJDwR/'0E̼7'~0\O8:D폭scG>.ꭲ\eX-ٝLy}e)|k_*Nګroō2oh٫Oh+RWx?vZDQ%[1y+iy 8^P[Me%b د՞\D^W$; >v+A?4Td>S.]YۣX)σ&Q.z@q ^AO[槩t;G ZzP>ȓv6Vg.b@UȻX~P\r/.$$nGXŽʫ/ҼsWWa`vJsHf}RҲ:Yz g!1 ƤLQa(Og_wgqjT+4K39U  ͌VB:P̹b^{ GuGV-C):]EJRE<2N\`!2;j7~adXoOq~a48 JplU03(?F:Y'9+^ _tWC܄o9ڀWonl= 5|*sYC9WS̎`9hyG]='c!VB&`2eo![8c2 .ò!5_dk*U˰7%k<#릶 `|xlDϷXCƱašpCb#z9v寔@Vq@Gǧ;eWJ2kv冷F]Nmg:[5rsf +]N߲D\)YtWdSn&cZωo$ ڡh 5-ʆF鮹(ȲkNͺɘW6`t疺;f7Xq96_AMs]"ïܢ7(\'1=.g0.}=Z+$ q(EdFNe!^<ל6.Xךi'Ol~WpHLlVCKmP#)$,W;٢2Jvow詟.\`EJԊqRmTDytĪЀ2_zqyx1K]1 \Wʉ T&G|%M9:ګ/uKCLd&s9q!%R:''i%5OJ5M7oOd2m7(D,#T);EHO;AI qB';OMG> 9X #iO?[.sm"8)S7r z \Q^2p8/-ViLQuPBNJJ )^~6,'e3`vEWtX|dR0Q v T9Ǡ/ v=?;GJs! [=zz1 {'MO-ot27\cL&3fv;HmQ.uJ5S؍|.maI]vL{C$x)aЗ^7tTPVe:ۯ 1Ef@ ʧFEet^8X$ ::u S=GՔ 4%5L>TE 564%߳f 2![lun lu"tEy@/pۭZ6)i~(5~UGӟ[nANggR\Dշo_[=N0]6b٦rl- Ț>pNҗy:*'MJRYi~ӤDz '5sM?>doHW>43Owwy[^.b'W}Yܺn/Czf"em\ 37]NSlkRnI5/ۼr0<󒦍 $!rYDN}hg};*C Y'ˈ_߻>몞opRmj`;bԮ"EPo{3;9\\[q}ReۇA *^aMχE7ڐ޻V [[q dWn`{d] qj(?N'5:Qjͤ H._ѻ2l'ᵇ)RAºbk ʴQ<m3IO<ą0Wya1Q"1.PD"k;fӚ0>! ߫z]aT'hۜZ`%R{ɢe)Ɂ٩;=/!߾ZCgri\\KjX|@?gc j6wO*Dy*38?*0@_i.q#[|/r/+vFA؏}I.dSB%oZM]JEDx%AЎ^;ZYlʽa"Uh=x/ouUXX2OS g.WZ9+,0b)(d8XVq`=V);l2Xog;:S[>uѲ.&i1u ΢iYXO5BwF̼fFQT]7v> Re5$9\X󆴂ZG}.nC.d*uQ&=P+ iR䚤ՍWYqk."0m2zbO a©9Y5N܀(f~eS~}Kb|zLhyYqy' T5QV._#j]X\}|-Y:їo1C><yf7( ^)}b'S:Vz|KGc{!? VH[ Et Xr`Đ2 1#LpoR;LXB4 :Q&5g =F7mE=3Fl/ҭ ږ3PwM%гuL5'J,OQʃdkv c!VVD)ܑs vxH22bX͉U=cD&/fO<҈Iګ_ rMi vqv>c!- ?)x-I Q8ҁb.)jhC{ sה͗buJnlb:gn=gH&!qcj-I-4VFLXpJ3/hSN>^om!#6.XB >Q3&sq7. 5gS: p˕\-ׯ >΂ɅpD]P5`'7|*4®Ӫ8/$+Kxݖy/qţ2MŅrY^5˭28Qپb5#SB{X<% \3PH$4jgΞXx!4Q\Ob plb.f45"_D\K&$g`Z6SZ_t@beĻWkf_X_4kϐǷ/U6o]Gb'u5d>-gUL<;k+!\[eÑcwy]`VAV0vaߵG|8i X2]Z㤯YӰ#Ϋ,IM= {C2~C%^v6~ݧhr:}X )KQ:TRGRYe'PYg#Kn7㯦h0N\0%> +uz)';)F\*Kݧm ;RDd[OxZ1)tu0S=fDq^B Kre7E]ˬj'G?`D~w'1<ԡ98yYj@␇9|w ^=P k3,$TxakldۛY=o҆$#0qIdW+Ұ ~FA wFIQT$6)Yǡ ' Dy+ pJr$tt=Jԍ UclHZ;M67F:̶v3k'J7mI#=kǍQ_\?jdfC†iz>S=6B?#!ujbΠ$2]Pq/wpa빡 0)mkDSVxݒWjP;α} ۈ,h~^4,=8,