sssd-ipa-1.16.5-10.el7_9.13> H HtxHFb ?*}}EJ*5!;SGNbb82c087bc77a68b04362779772c3437b628369aҬ 1壅uVƙFb ?*}}ci9ԕ TEx=/+#5$#$PNeaj x>>.?.xd   ; 7=D   8  8XxTTmTDHM(\8dG9G:G='G'H'I'X'Y(\(,](L^(b)cd*(e*-f*0l*2t*Lu*lv*w,x,y-Y.tCsssd-ipa1.16.510.el7_9.13The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.bsl7.fnal.gov fScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKs&/A큤Abbb^p0bbbb39e2f9967da62c7dd2747a48c38f8876f2c82ce83b8587666dd4fd5842e7d088547d0fbf6f64dbd044f7c4fb9ba5a1813e7e4b18aa07f1f4f73443bfd2749c2a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db640627e6f816395046e3a171e913fa87c4a5e7d54dde45f8f2c383ce321b8e7c709df34868730d2c8c8fb7e44aa78bb35c3737fdfcbda12ade8725737a67081ac819d3ad722d7d829ae0635dce667e719e8091cbe7e7cdc281971d6f48ed82rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.13.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.131.16.5-10.el7_9.133.0.4-14.6.0-14.0-14.10.16-18.el7_91.16.5-10.el7_9.131.16.5-10.el7_9.131.16.5-10.el7_9.135.2-1sssd1.10.0-8.beta24.11.3b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.131.16.5-10.el7_9.13libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e86221462f88a8c09db5df0c5322a377c16612b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e6eb76c037a33a556d990783c1c8f8f5fb18a8ec, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER5CBRnKst?$)+ˍ?v.h\wN]]ՎeCb9A!z!H?;}2 C!->>Eer]ޜ0wzwR/fMJu ekB3{ךtѡ2}oU*BD#e.{+|> u/ _SZ!2'ә:۴]fd>$rVYO.N.{B i!xT/3(%k4iJY͑I3fKW2 ͖T2?F9 *ב67'e*vtu0cMp}{'=y>2ꇑ z&IJA:q,ƾbw GvB1XZ Kd`ӒTt?鉞bftB(l)$sݪ[^0`ȩ}ΥuAop\}6?5\0_ty Vި 4btQ%ŇPul^奉B&eTHB/+  ~*G@qְ%-}]j\;Ex?qD㰑ƖDF=A]P( ɖLjØS$tiq' X q'2l0Dk,E6,d _q6s S"`D P쏿;"ըX9K#M)i+=uhd~%n(˹bzR ɅL> {DQnX"ӷk$,7mbǿ` Rdiej5mߩS%z1<9{~7#&M ^M R'fwpP{m.o233MERBn_(Ű˭vQ&T׳3)uO@@.4xY t\y>gx4tlJ!1홈G +z{3%EyU"\ÄH_ ը^zO}Kv;~j"#|P~ncXNUŝJIb91L>GnZfjK~\1s#Y A%SnWhͿMfR%a:[aֿu[ &jc;H=6Hj(-[mVK|Ozś[I6Qo-j|7v 俘5@-,`$9Xl0K_|ҞU v$t+lњQGu&kE؃L5#4݃<#]?9G%/7V̴IQSAC{&Zq /d"bxe:)3#5htҌ:JM[39gPp,ׅ}].v:țwj 5w`7WA-4p*Xv!B$ڒF҂'pvmu+a}q$f:m ʴ%V'yJ47*/18!]Z\cw>^p;ӿ,esp'Ao(edR4E 3ǿҸr+qW( 1vث>_.yaPP Vh>Ww_s &H zkU$At3N"Bd\CUOs^&~93Du68<)W-wLAOط;(4v@NWx/z )ImԚC&t_(9iL|B^J^ +ud6|pn{F e@5;aRwaCN8';yŠE38EtL&-)Z enK1xJw#->*qN'+ն$@9MRpTi'Z"Z=b]%.a%"Ñ--iVlOV+yrN_:uY4dPwvCY~'ȡJ\Kػ[./Fdիof63%™]~g'W&ʊtFIs{w.)"Mu$ͬkAmA'}P,X_ 9Kf(> qoA^l~nHkyuEzK5\1;&%U yΰ5ߣ ʃn$x0XrfV]ěԛgkJ":ɪ{dt0A·z$AߝٜD#rQ&p1}-t 9ƞD R _LcFAS9;Fae/WHzNFTG~gye)_F[]j2~ x8JdSYc['M$RH4ުxߥ4q@跺#dzQLp',jad1xpczm(ĴC-hbsiv þ6 lCT9yEgQ->3'QL^|vjN"0%6v9Z{݅0)ۘ1Roh#b@c VW(]UxWf?-EW=k)"`Ȃq%H-xhxE6&y&=Fx&@ib_#}}O¦*[2-iKh/:|5deGOFpZ/{se]n3)r\{7z(b2 1,A,Mefax|)mX@6Vm a)}+;31I @}KJ䲴=\_1AŭtrW /mEbppR_i3qM %!:3`Y͟diqSN}𫫐4AG9">P6$:jKQw>/OpMzZ“ ޫk*ss;YG{YwURQ X]C/_#pwlniZAM o΁g㺬?Fd{L85"iiY\A5ۻ~Sn?CԘ8*nŝuje;!}=ImM|Ѓ7oR(K9eTY8B\ylj|XP2B c_}2ex!J>O;6H^g sI7mkEή;yY<e1B_ŜNJO-{,,])ێÑQO%뀌rAn:*t ]gX8xW'I%mﵐ K0N ј[l 0|l⠅66|6o#Jљ%geNgyQvc13=`)2 R`r>2+QjbQ͏8șXV?$j6ѮV^5ָCKٗųQj5mOҙ/Sx* ~g$S}*׏:E ((bSZ/2|36/kKƙ}&P«AU*Out_j!(jԢml Nho#=k *"2+\v\̖4ݛu9BS6B)n: |Yɍ//Iҙ۵,$/vUTЕGA B`2r;پ׆"Y&AJ}ma?u#ҫ}ϣSgtSF)V-2Mc> ϻI gsCiT`.z}}#DFGL(`*TBFQX[߱'C0TѨ?1uk O>L 9 U!,[6,}vT4;; SڗG %u!=MtTE2cW-} vi2W,+xAFpBs`HCʽ"uD֑e05U ](.J`H DӓፍժjU+OZOiX[Jݹ1gq~]w avfVX >=V̮2^/oRP77_Zh2g]RѮYL9DvotPtį;}GVqgM3Ń-W=x.ge+t$ %7VJ`08Dsi/Ÿpf*ud0]HJ{<@/%:{pW ':A@Y}j|Em3,tHЗupgZ(Kj /}*Df:2 Y`&m@ 'm|`mQJDɱ2z6NY7b s)kDşG~oRc[3H[:qv0)v!)Iv6{9|(\5lGNľŵ|dy^ZV+]Bvk-bj?V!9f9 Mog"˦45\Ɛyw4l|{S!ɥm*$x_|O12CADhb(] 6ɓ%;GsCkP,ޡp bIQcof8s@F!81| [K}A.@j.pnzP$M54ζ d .j1Da+[卤ŋ&)oO_GU-jEwl& A `e."qY< N+''mBaV m-qK=dv-’ D&&8/B1;FD;cpzȶ&Z`BpvMԺ?y5Wp#uՠ췊WEZCr-oj;Pp",>. [1öxy͑RݮA~ ИAͤ}!C37'gXFO KI;=#\A* DbF 7j?nzB7%9s ڗؿR/'زKѐ$:^{݄K/^[zC /{2o.lwgig[ RHU%İp-q-i?Sr|s)[+wl6w./ZJF503w%{E+ϼ6AD`*SA-"oLX='m:U;ynl @atW|~)A q1úB04Xr^KʩQ/6zIT5|{. Z/*Sv0l^HґTt峰&B ~]ٯ헃 S_̤rGDޗ5"ry uOJ}(t050DZNe,OvV H ?}#Y2zCD}B/'U+4Gj)?\.1$ o7X%B i fyN@=e#u6\S 0ፂJL[GE\+]fT49ƀ`|({=$ŠٹfJRV D _5$qE'jWhzV)jUһ$I/iqw?$RUbE,iQ4mmg ^b`|Bn,3 !sa \k P%4oқIVubwa ?1օ@H.; e㌨@R7c[,<,@禀oK{Sƒ¶<՟^T8ZħC:Tw)SO$wڅҋY~(P:7&æ2q/^r3y(o&;O3 pS6p& %a[?̀\6!{K ϊ"~½eʤ0f4+37mS0ZF&%VRK+O!axy_w3BC^ـ$e17|rʧ&g!7t,*Slz6<z& 4Uʆ&R3ޓr[rM08B@ԞPecX.AMFNp`N皢1Gk>tMR t|s4Gl7HN!x^t'{Fr#@Q x __=2Hf?_N *l:rrvzZw3v'F t))/Ӫ9Ag:c݁Y<dNrXScmZIx): s# /?0>WUG Ԋ9sE>O׍gWVa`Rdm ` }"0?* GidIش=G40ڇi l/S-Pul]C]3#Ja`O_|3xHԉK\k6O*0"z@0.aiYSnQɈvMJՕ|Qt>0͜I#2$`=S\("U'U5 Zt귣k͌sB( A/0_[?U#?T@5Y$#r6< xMDYԊ!= \G=|>{:)"IJ*βk"(8,m| uK.(( g~!s+$Nj)i/t G7"ІGicˎ ot]op]9xRGYm0 i.SA`CoL5z5bŢcWg̫}L| Z nG\[?]őp)ڌ<"`.uŔ+_x͍)HAqf=F#|7{M,r.ċ3@ԪiUFT ]J}Xnj mDFO/Ie(`UMZB wqt}J%_訑( o䤹\ ֚"xD^ {cv Y}ME3v0-OF AYZXgY} j1\}*cF,_H~P|N_Fܑ~M$<(A^_t|XguPꈵGT=ڛWrQRo>o V*(UWQs/T#ժ\AC܏2\tK2D׫PbP=4TRZn@ҳ=mljlȂ] OY![D~6ܳ.I*bMǺō϶bрuIY-Lwx+ť팓+g2/(b n@F斒PcnfV$1> &:FF:1kU ]4iϑ5I` (͙Pqx1>%_X~]T#+)v@C+ttI?Ԗ$}(~5~|\MDC4 6j Yg  ͂ϟwf}!,CA»Ƅ5>(WE,JJMJl|L&D:쨧/QƨZ>vK # %_Sٝl1 z̲Kb"oFE\V$[pU# uy1f!IeDTM#Il&;~E rXjha㢶@j}W ^ xjv7dG `lש ?.a Vlrfq&!PA+oOء2> 5gJz:Y8J7>۸JtF_'v~}K&sE?W~^; OXUNTaPq3- ̿["k9gP T{t1^ilAK/JW|yކauD m=&7GbHjxLd+\&-XP=c==ds䚼bE9dGG18rJ,߾=&bzFUglqe?_F~$)XѼ' `BI}bSx@St6e_s@ee&tLNi^ay8ak2.:n':݉-LTn L- _I +H_AkA z>t)LA#3YsLf#st$ * 72`7+;{2!6\Z i"x(vfŏ+rxJ%Q:z>`G֙*+Z_߉6$f\X>naetZVG1LV t!)Ղޕ/Wg-;8ER8dcR7S4tHĽS> Vڮ4%g.gdRhƳAԳ~sȶ$wr? G]sQPfd|3|jEu FfI-@Ɇ0ULC* %;)q{ȲD|P@AV$\? ~o5(܉mub3 1m iւ*oԴCƱ1BzsM.t$ol!MH3&֥-sc Aʯ;2zATdS'Ϲo)p8ca\q,ô$n Xvyȧ*qT- n L ̻V>\"͵ NA TD2 j;FY_H.%r߻_ErA[ Ƶ'" G"z鶯PePj2a댬%*4C#&|T “.Z2pŒ% >*%|mπ *yc mPu]RC}5ጺ#A׋'GXgˬ|꩒pgkRȴU}H ؤFReB.[Mm> Bn51C8]n/Ru?,@)A_ kKDNadJLwR/0MH'޲np4b9Pw'=ٽxCrפ-=P;Z1b4b r3o,T_ZF,>TAhx֯{pE'6,&@kB.:o[֎mF|J6׳ ~74DbK~ .X[tHa8pq,MX0kJxtKxNDKe{ + <.mݍlmLBi ѯ~`O陾cǀСMpef-x4`o0Nrzgo>R fvȓC%SK{ v1Snqݎ(ݞ'vh!)6.((WXYCRY.J rjBb%=x-ld?S/Ou58ؿh vG-3/A;~5N-J |4W͖$;,cʽYv}f2KT>`'/v*uW VD+w49xg{#t|(Lxe-Et: ly\NӁvqƁ1BavY^ Q Zp73h;bЕGAt0j+SʵͦUz+heJj0~+RIK+u>^^2m!EGVD"Y8\lSŘW|B*Afl;Az}; i/h(qEeq\":] IoۛB} qMQh(0yFH8WxEv%*%}͠^#ؚRIE+Řa3RWxcz21? ۻtۅم[!>6J27:` ml~XyhFڲD^[Ț0fZʪ79|֊7."hwX-aҡ|AJ'?L%ҒOR@ %蔒3SdQm8QQS#_{_<.FM2>4{f)Xt hu_ ;E MK%w URZx?0of+?DLsOr4|ogϽjI4+Pؾ:ʎvOCi[s~yj AsAaXc6P]=r`u)ޘFK _SPUį1 ++vDE{FE"%BRy+BCh^~$+c.<[ִduS ʄwk'Sꂑ*&.8vu+h?yzz'hBX~ObFsׇg%ȵp?u{}g Ko(D !0d8̞A\):u)AS^(>Ћ5Fp9Zo(§\욌#e SHId y)ImRm7<2gh~@ @L$vfj c{NR<>3wTļ7ch!2tXErJg'U@kg!  kÍ (v7SK=<"w`$sAטr;2d.Lb/{#ElPm,Oh+&o]vʅ 7þ!+`nUεh#rD0%eA &.Ti֯Tg7,f$9n%=h9)Q&BVlUcJd67@ щ\Ϝ\\䢳!.1:.c0ѓ|اQ}zG?][P (rG1,$t6\WEhhdl/z\"V:~ÆC3-/ҹrjbLhN8"i@쬗٥OK£PTnB7UXz@BGH9 2&]QijRLC7R>";j7?'])5Fic-&e%޲tz@+Y ޠ+H$;^0fV_SJr$ugx,e<+XKݽ1@b:$,{{S2q Ru9zKl>. +d =AW&,xl-.:3 r}a,δ, 8 a9z~{k*9hiO/iW)f2%? 4`VyH3y gtM?iX#Mg>lRKwԦisXlSt&`v `ֵe}u2Fۿ0-he!]rRI4!b1ͬd;c i+60cЕ7fF(`H^0eƷwfcrLYL;OZ5/;Z8dMZi2Bb&~gLJbhX(m΃}S0gI˪LQq/ U75rvu dY݌bIj;㲉Lo̸{JzjAEPK᪽PT;h7Mh{s:ABꖔD^YښQPc~9HU9sDeƧVLt"~,e4h V0u‚X>-m U y/rPkk ĺ UUXB^ZF>a%qb,{ x&?:ɏr%ޮ5 hf2Wo&qfy9Rucȗ@F|Խx9Pj-`pnAQ vk5w87B%[ ʦ"Wց2R0"φ}Ux؝#usFrD?nO9CF|DRYE>xgR(A n{;4>|n+j4=p:8Lq& iRxuo_5ZČmL䛅`'=ݠUvoV<+v5[ؿ8BtdVnf*FI&<< g+m̌L/W!7^y?\L* Ҕ~u._Q WU}g/!"t[Hؚ<' p:x߱^^^6hKqpl񤒣2[+ڝUأh&aXv8T$GB .Ib.Xծh/3"br%HEv?,x_'G<`ظ@"-Dm$9$ 42@Zk`!Ʈq8[ 3G2Ka.9N!nG}-p|H|&(wbTgԤQ$E,+:m26p](I;"?{MIC>QP +vhTnHT7 x~r>(N&&=eWgl^Kff & IOnq 5 ok70{hV"?Թ]ţ3TI_G>^f}7dH\4`vZǾwKF)m-A)@EVqfR@Fp?.&v\ӥ38iw(Y-/"!4FF23nU6Q@lE͌^n`e Stt, lvw:ؘc{ngѾIxp(o4maV6 )c0.4ǜhs 5Ln-ppt1K03.CL[x3q|>b4\I՘a$Eo6:+NQcxGw#Nٿ'nCѦ {a6EzxcDI+ y.AT-KbbSL]D腄 jͧMf_i L\x#}~.2䝌7 Cl^@tk'6B:\ԮB}nu꾗Cҿ\8X۳ .~*οhWNJKY~d)vRF|Lv1!]2{FYw6iS8#mmXX@T[eJVD;Ak? $ 5SWtnN_SC_OC|y͏<.RTCS݃_d~UHy8=g9wc!.kؤKM}(ҔWb(/2-cbp*҅߿)1V24rz5&2*TX?Qk@Oc~:=Qט !qGwHT&z4{L"- VgˆtPIf+qh<EB JvgtoF/k D/%䄽px%W3mU)C)hvO&2L?FOVWam4tހ'=v4Q/"`ev]϶I%r,r(LMt?@h˂hWam7+ǜ9 [6XsB ~it-*^gG,͝mSݴG AhP $uR+R dE(hk/᧿ѧ$=m\I]\X5nx[NrB\;lZF{KŏV̳q5VrIv$qx$ NcL]A-پ޷itۛ-!aTGFQ-Yڌ*< 9rA9\TZz j ,rG븊9hvPEY¢b` Rz"MKV ~-U=yz#ºgj+ AHX]^ިQJ`#dǮӳQPp+ TgQWt=DKV{64MS̰,L| p,}Cͻb6Xwn`PZW6N 6g}a5эhe~^۴z2і-hൔ)|vuu;.&I@Խ9,Q(tDr^iHLԶ ,2S9WB jyj2^>ۂb厉T„Պ)f)YV{:+$|҄T\9dY'h`XY"H|M`A/iCɈ-p1- 8a* Cl(UGIZ+/kˠעp W+yCT] P[c]IUn+hunlO5KguuG8)lh"ĩ` ~ZfN5:w>֓5337ai8엓D0" Ə3&d(+7X(r(e`j\8DRcԲ zkyKy"› O.rޙ87f(:G֧>z40_p&!%C8}F˜Y| w/((|ޮ?0o UCw]^Lt|DY}`vkvl.Futh7'yF yr e4AN]ˇjP4{=Jp>EU˰ch,}m!($% )A^n0kc%{{X,ަ*; UUC2Ny?!Zg, +bfnS3?Q ͊/Z?M,uR>~^<)?+kĕ|V}g: pNj*\~Bxv0Tq-( d̘PSf 2uMƃ8;ꝿ~&b D gho}# 3Ri닱]L +_`#@D+]@Ҏ:Q[P0ij3RiŖk Vޣ?Ά ; 8k`%vL2ERhdR-ȟ.wavg]A ԽFΘ! K i~?^ I:زm6*=YI >[˕P| M$9:q!H.k@_৉`2vF&"g<ʏx ؆!Kg>Z51t*//7i+cWlU¨խVdd"2̀ݩ^9fB8XQH:5`L }AjMW >$5?oTHSg\5G:PqI#FmmҿoET/PKrXX+rI;Lzx쒣NCP2顿d;I0^_'v&cQiV#vG9՝ هqO3H$ ̼ǍxLƅ~.~ʄ~I0uHJo_m(\1{(zQe\:E†"DDάQee6$h {ZISTGk Ɓ6$`t<C?{ͳO|IzƔ keƂq_TlgDx?tsA,]QqHhv♶aƵDj1u]Ӥ$a{Ң ~PR;&o ] 9 Doi"Ox6e{(Rw}szFޚ*C ^o l"| v `ځ;yb˞CD ~5vm5^$# itTAis* /,37ErFw^7g{M$;Q>},z UT1W*p0Dp߈$Z~o8bgWEaXjyʀƸ,W\F='^׳ wEU -2 #F#zH s4\Kv?=%xjh\ uD;…Bg S"..xRH&#$bt,ĂI]+-@*-L+p =ܧoU Grÿ2*J4S\-D3،_USD6zSAG&s&;%yI0$n\_:'[Q=J&3a6eښ]^7YpG>j=}˰CpF@H!/@ع6X"O=BLXЯޙ72>7.,pv][&Q1:';EC ,70r 5Le6CytF~je!7k6T E*$S.ne&Y=LȉVʕb$PϝvFTdJQd˝1GI*n3A钲70SS;iuL% % Qk-h5 Oxd6.Mv^8 Hk='sN/H!q悈4Ά>uqq$9!FĴ X :JƄ ՜N@/Swd7Q'#0DbuZCL/]M:m/'6}2].m<0mQT(NRLd9Qfݢr@sԔb ;4Ls(VgV#:@d0U V.a.vY]Ăֆ W~,*0+i>A *}Պ̣W" |Z5TYU2tΛ/<Ɗ!Pq-PNbfU[x:.:^v hA \AzW,X U_-\;`1_ C"bc!FʲF_:ey-G>YGsª]֧[`n@4uh ? 3'EE6&W, j[C(O(jx?5lCUiK-AF/n?6`vC lڼގ!69xv'EC7@3[<=Ae>NA#-w>A\55kԢcHR`PNj= Ђ41!^W^D]ҩ:BP:?-A-T(68oys_XAA\ Ug+w)4v`B>ggd 맄SHr38RIpWGf"uK5|i+a+G%O\Q6A)>XJR!Z*+Yd((ZjqӃIl#\CڻqqEb)tt C+7/dBŲOqw{>`3%Ђ %Q>+ZƂg,Eux秜jXTҠ\P]Xn֐'sA!M$z?xrG X5%Ca tص'&EeqL;.e,J^) g†x;qba@T'BC! 4G57S/0/zh-^/s>%OSy蝮at ggt1A]TeHyq%5i]>d M [7A5j6$,dJ(9KE?:*O&/gYLRJC24UL RٿLpp/Ý>qa^EcBy$mo־4ʲ;ހ/A)%D.v4S琢)O4W ҵjyujSHHU?(6҃OsJYuld4_Be8|ŀ GŬ.݈t*媻ThJ2|hlLnpi5Rm qX:Dr{8$Jo8 UП\(Jո 0cpPqm:Ty. |C`) :BY9 UGfxGV_ #S=zg#OM%@ڟϨv}`ۗI Hw߆OT,$i_/fXҮkC|"c^׏%PEAZ$YKP8Gomak`H0VO ׉ :dۃPbY894EkR8F涉 x"* p]!% hJH^TddhΗWB-\ܺw0e8aZFԧ!&`@@d!ړ%`" 4BJW%y,]מ}x_)eKDgq*`];OMg.FzjM'r萾ZD~t=Q!@n/E 3~kBE$di k,i)TWMI<$#Ʊ=CO`A+UDAS(ZݤMkJ:.K= k8_b`l}6rc2B( W(rѥը4@3 cqT\d2bQ~بll( &5 hxd>Jw3}7#sjJ1ѭ(U(!oqImicZDdWP?g5+oĐm`ly&+y|GqAFWu[ZޒQ?nC}LCd*3<t|̺,3oqzX1"4 &ĔI2 ӿrs<ݮzOe+k'1r}ta 9?!̈~l BiנMMw}x;B-bm^ 䁽R(Up$ |ۖ wyU:Qw8@D<8C'WjRr{Tw#4m_qo#DY6<'%iz/ %3Cn%5y =vjIp:h=prULEYc%&npR.b n]3R""VrKaPą'P4Eu?jR rw޵:[u8q$kb-j,oiWNT^%kcMc~]u9Mz 7M&7o`c]HFslڢP O%)~-zmRIZF5[*FR/>]nՕ=ҼG|>;gg[U tĆԐ+/c4QRAr>L1N$&K#B͐3 UWN''*%爠:`,j04J?wK71U8to 7s/]+ k,‹PͅB E$jg-/u[NJ0bfMӖ:4[>wGnxCl80z p5ct-mOmLZK4P@x{;ʼݎ'):mف8P@kʺVR pf~/1% eL|OaO aIAC"H}F3{34R7eW6k݇;?{@m, FζAoJ' ^qi?R 63!KjLzGqy,:֮%4[jcqWF< ̃eCrp̲rJjӵ1!֥ ^N |1E]㊳NW77F I&S:nGšGzۑ6{޻3wƦ59?9~{AX_Vn,BrkK:"^swS<%㵿j2=\ZHty{-~jePWʡ& V-$0X9Uvw7x ̸OUK('i͟97~Z>:(s2Ǫr$Q{X6 s0qXoAr&`dj:şi /v+6L1:Έ+1537v3Vo2al-%ֆp2@\u*c=+|?^!ޛlF" wsFKkN'*eT8>![ kiIVN[9ZPoօN^p@x;b h8@d_4I$v4y.vHC_|"Suf --DY}BT #<>W?BIc0>2]{[p_UAs?-]<dƜ,"򀺟KRZNh\A/F~)KJWG?p m{Gf ]#VHy|HvjqjHgFb^ +󗱙;BkwӇeea.uh&O^n7Jt5ws; uv_zvdUqa;EȦ WmˌgG/cN!R^@7kMVrԝ\mĿD#X$I]2 QX_&5:W^[w$ H(p~Ht2-xkE$_O}xTH>cyx26tco8'&:Ytmt_{)݈Gx ,EUsvQWkk-:@k5t,30fcŜz{FjUv/݅uS#BM{~kɫ+=AZ@T7tBN\oҬfxabkr:!V$,^b")5 Q55oBM5aWЧgt;0v2,D_7{"¤g#tmk;MŤ-8aK1gs5 XS쎚i98o*ʽ]:`X =s_*aU)D9+R12?jSh~a%jv%% _9ꀧRv(#pEtK< u?nн)MP„M'],)@)΂$?-?uP7s&ˆ>7l_3Վcݳ|PE+;aYpl̲7VHNw8͹Z%3'ςrpnٰ( ɞo3tnjɭy(V&V*wAɠi@478ޙTxȭ,§3q (깦eٜS 9';!BgBTdp0 ܧC!:Dz?jvO$SĆC"4¤i}"+K6=my6؜ 2FG%LffouPPBL:2[&^\.-l3 S΄%L1e0,#p&کtfK֮pswD{̨F>y$'Q..y3\\! b=G$r~IaGE¥sͲ'~͞#3®;n|!atS$)l ڨU\JچV y]Be&#hHd%dGxEZ'^?9xDv)ƪEl?yI1gGp!Ee_ A83\룁RP3LU G[e,Dy+ϲP(ҚU3Db-]&L`~QXo'f$nuRtb)Lx)w~z/EzCe M9_[%N18o兑κVi"z'I$UVWΝU2&R=9/ tֽ95E?Fz !6f Ǜtrti,<ٚ?elfOg8(3RW&t끣!Ks_bn{Q3b0BP~i`2[AINb8ܲ)U։ܐ'RA&1NͽZp/]0pT\ZU&7gC\'ck]Tm y~>  ``v’ ghwokH|vQ(Fnc78T\x!%#8joңTS?n'x* *'P1p{:Y(*o/v A"xe5 tqш8BCyЕe ͛=FR"[!oyn|-уaݠSU*l{ДV1 SmdxKߗ,t8'W/7IZ?S a{"11,MZ|߷C3.; reBV!͉`8jA9S}=b(%y[Vl|̕ S> ;?MѪ)5ǽc;ﭨ}>&0|ޑ}sUj65OPSQhu5&iODo]"6@t$yIZc^hA.MaYahLM!FYEwϠ/}0A^Q؛5Ϩ5Tpt6kz&D |R 3k _28gC uǨ;5.9EEb.M#S!P rhc x"tIiQ٧󷈿YX'Id#+2 #ᴗ%QS+{Cn΢zK+ \I*k)\9=A]N HiXx4HL`d,K% UAO.=Ee" @E`IO$%zt.|_4HkY8EfQ'NxtEJTLƟG l`0MLy YH=iZtiuQ=0+Zh.6eavX=x,fJ_èDaO\[d_=&r@Va'2;8;$b^GWP~P PC¼^ڹ^1'v#_|Ȑ.[6K> F6U ,f>s6kՌzp.(KQ.6 Vc #Jx_t Oܫ G܄̾B'a*nRCs{,j" `3퐻Q"md=MVB7/NZ}*wN}68K ~! ~^c˸M]BA|d'ߒ6ؚuV,p0x'_>qcRwI{Fd@BNrGiNܼIiK轑B&icu8cPT_7ΧzH4fFS2u *AW>`a:N[7AyZͤ5-eyp/9%ֲ3J!1>ׄ ogpF4<פ cx5bl* ïuvOM؄ɽ҄& \rR1۵=;:Υr8k?@oh)K>,IW.P\ 7]Qmkƥx:Lum=<6"iEnjBzo 1Mۤt.%0^:?i_}b4irGnzRVB,*Uk8g]LJfkDO:W^2v=V;(LQ9i8yB1yasĞDqGvLufqFG![ݚvO멒w7̥kAݮDj|PwϪ@\_!{evb< Jj֎"ty);jٜ6[c5x?t֑RȖ҉,(MLOckǚOd5oq==.yg' }?_~>"*v["j9rYQzBIu`wԥdD*vȒUmi[nX #FD% 7%:!rH۴ RjrapAC%Ngk|y0,65ޗl dv msT cnrxr u|Ͳ3XP(b$W,KC )<>ɩZIG4 |vAn;^ܔk٠r&Պʄ<1u^lWz;;KUFr.n "u/6"T6 J-zQ{w=PRa {h\oiݲ~gg=bvzSwU>7{!TQ.*b ? $n LWTKĕ˗ ?۱dDVE^pO=6i5:[mew MExo&$OlE8Eϐ]Sar]$gR89~!GWoNQ-1+&U{CV%A”8SӅHu#WH3B~L XJ™u7ܾqʪ˗Nh_Я3ygA`ѧ:7 Fuimx@)%F] .xM.ER B8]B iEE @c+zQm]*:RtMoLZ"E}MB@ד&0zg?@)VgyBnFyHB.Lñ \Ax ʫXaV"˸{iFZ]PQic7Z9Ucҙmez#+`!?eȿ1&Ꭰ'Y<]!ۗ4ĻP/*|"k! t&n>UWtp`NC 4BjrrhO'ӝ-{|a8JA9s(sW@LO/qK\}y>a"|M9[p3\_kf&e{0_glޅ< p^34 rHY0hW3v_i_16v1A~*6]fJFMqYi~D(WI߅|U9/^dv$>Y& ~CO`;k̕WVȥ8?X}Aʷ.#r̨dyIUky,/_Y#ף=\ &~w gt"|(+uw{B}7 e 5D\[\f(7&yƉg?kR v0: 2$o~i[ 'k~%˼zl{  둔}6J:D#NK_p' n%e@0D}R8(e yZWl^̤Gb&CFiz:4eؐʸЦ-g+6? XQ}uKoFP8g&pHC`KU*.;qRkeObބJ|̎Xv>d7BvAqS1o71/`g`O>ޕƭS⵱Hl7Ģ 6OI~Xaٸg (y "#M1L S@J\#.1tQ/% -  dzz{r8p<ԉWp V;%MXA" cDկ bĽ RMi9.WgA 3+)OKx̢ C#g$Y4k ؄ TՑ/\ Mf:3?$r'_[ h2m¼/ $aF|,D|AW˛;& kԩ3xYe3͹M?a˷Rw$a hbyÚgSGR[I64*&'1ALE8d玪 }48 nY 1 1xF{0J = 5; Q,PkUGY[_s`Z\g)MۅD\0IO7p&/=W³&,PMxN%!* UP}gw!RkuMM,3tHjK5ܣ5qӫnÝ֝3cQ3S |tNz{b]S"*ϡM٧qŤ6mW gO20ԻJn82on]@/{-?bJ}qcX#Q\.3VHYD1N:Dpw^\YcO_( R^9_=)2t~eӭNAH|zwGׂ=P6F'8]0zլV=xbܗ/L@Ռ"<5]2SoCG!@IF(IB;u|:=լ72 *K]gYwJ +܎չ*6Te1gUͽ T50%7Ӆl}&buZ-/8:mUj{DƝ?z5CE.m0ڒp .d?@Xe0WIɤt*.V)vtjszL?q2Mg,S ҅x7hP и!8M`B̀s@O7@3Oӫe,;j̸kM^+ *ʇuhAjY4#-uz&Pg1Sn`OXR,! ϶9f"!u hW =-7#ŷgG:)"t[sI}wJ (su?< ;z6ٳՋBeoPFVdG uU 3&1gU *7Wj`EQ#s i9>5jHZj5ǵ+r-굅i{@ bIwxk.eX\&M❻M$_y65 zpRRv1^!>>LMnRU˲l]y!|9YF#7H2bɍe3euIY'V;1Wsɘs/͝)ԍb uEAHx|]ѧ5f,'F%"$mPSæs$Ft:@O~k/L)bO>ϡv{$cS\l:Oş +L"wەfܫK*ƌ^؂U56mSɗ擀T,Kץ %MᅬvT-7~0$u53%O5M8{ȁV^s1^2$W7h᙮+bh6&W"=DDuAa(G;>v0@iuw/d6|9ew1ˇ )P+h:}̠FS!!VD`m9*uΟNs ;lBRhRSIU+M'wVѝ;6:__S@Q;Mo[?W G2oགྷzLet7)tt0_32bdzڐh"a90ݬ!XG4kcH-JV9<־խcHKM#Ԇcm.VoAnfF-"9(`~]8nTt´+2M~SP︖>m0cN`&{7 Z2QKI.k]७GKL؊>aFbo!I[f V&*9%u!a`?[fL˄mk ϠјJRu+c#'bWn{"AE nhŹdo`\InKz2;ж.[Ü 3 A;jC'&on*nɴqߖZg)׾r-J^FG# -z[tb^sv3jq}RgkG<&r H-&&|f>ufy^1l&}dlfTGCrQIM!:xF19¼VfBx^_o Ie .;"5)?iֹ~b٠]J#j,sFP'֜Ve(SYD$^m+tKpt.3H'psF+ M RmrҖ$Һ~m@Xo4rYVe.^| K ZUDK~W_3P +B,qTr+D ;}3JTL_ W0gq̭~ ySDg="lE_2&#$P5ou~9Y,xi`T2-'7z;W, ( {-9T˜ItC?XtPi%O@l7jMljl@2WT._[܇3Guq\kL?*"_NF~KrgU?;w5WA399!f;ZKsnE8~^X#Iůctw1{Unk3Fkڱy$bڎ/aw5 ;>,uX,5,)q4/q'B6Zm̥M|Y\j2y8U)F&KNp3LRdQN$Ds.ۗh좊aLZWXFF!2vdQԃ|~GgMfCuEDXڮwjL.bE8"spie}]<_I4r@?z0$! -A!E4\t T'J9+ mqլ6YIvdFȠ>(.&D@u= HGeb_4d:{m:&4Uæ(:R/8%Q_ !L9Cpm 2l5xdϨ5G( Y}=%R_>1ɞ (>"8Pj>JuOP 19uQ1mEN䁻x5rgJA㸪zI<KfKZLzd.ᇂ[YM8>M >#WMx5@K[ꦕH{nKں:Ve82f'1VP2|LFI~{Ǧ!"K2qg lfN,co0dF6E6E*|5ׯ.6T|8iMKdފOXTMNpݾ2Jg|B_AL\Hirt!5:~߸iOe1̨:la(|%msmVNʃirj>66IAt$fl)e;0Z9V:yoB|1TWd3nhew>wO+ :}l듹CrHښHL}u7P CXUK Od/+&A$ߩO]8JMQUyJ}jH;ök"h9o>¦Q\K?WZI3‰>\CM9uIhn2N`dCGJi[I D(#jAA`Gl†}zHchm N}2Ygm?Ⱦ{wwB23p3-_I$ SfvvsPz`qd ^D JS5/6Ā*dg .n0ȱx(~xff.#J* Q=s0IBKH u=hE9\6Ip4O `/`JdGyК ,g_ٷAR YS=ܑ/D*~)¿ ۄ )BjZGT_^<6 4xWH}|LEc`YM`5jBΗ`lV1h;nG+)T1"6dy/$"72 K-oΑ C/X^OrIS~-wc[N iqhT&va7amvt g_8YYR7EJ#HV$As24xl.orOig7/ l?A vjv\b}nCkNϬHƂ+Cde1O/|/QѪ;Y`H ㎩f8KijoC"FhsIg΄Q c6F_GbK/ )5"s@U[L ht-|({B=>A4 $2V+sa~o¡ZxkHX@ rHyGJtí RN5UFqwР|\D\JT3QHy). =IvҼ.(n(PhrR*z@JnI :G[~o$9x+Q>kL뿭5Szƣe%qX%O[4C2_仴{A46 i F$3LfDC ȵEŃOB./‘Y,d&b &K2-#!{U?l\봆,*1V4\ߌ%P[n'[؏ܪUjʱ*5! z(|83s뤒OmMYT!zYmM" _B_6Y#R ?x<<{I-@j ^!J'OF*a3L! (r6w zlXޖtpJgk*qK3j yG 9Qb{cL~0BjmHn P\@H )A;jۓ{qf"7_,uVTқ&d9!J}^1T.yAÝtk; T!_Zx>\;.Tm̻V7 5$p80aU"",GB!~^XdDJIZ a:{YOSڅ2BPLO@Kԧ\IL1 1lPC6ȏ0˅xRėqQd1!7˥ RS&B_ڛ$wl2ͳȨ4( \a1aerMHn>%Fq$#zt8Wn`7 > >@'t!MU#g$'uQĦ~ ¢5qoWHYi$ixWC;j~T7y&6e$|ebak8b ?O㽘'x\ cV>4ElqҴpboߕ/L!@K[(RL`gcHBZeDxg݆q8-}W[\8Rpa\%Mq=auݐcrXq6#nlo,KuU^WEdV?F5P -&W\L]F3* %۩'iűPʫr|V<+OUq݋{j)bwNIlFw#dΌx;+oK.0m,R,JH+%NS65P@q^\tAnvMFJLlL,QDh~\*M*NѫN`u@C|n_7oѱX6imU;TC*K0'm %PTRFgnÐ>OFIjq5AhuLQPtW?ys&֗# ,;bzP8d~G(҈M;xkԅHO= 舼 ѯz[C ؎yx\ BHh҂#-*WwJYǀN]s̾ɈFEG[ xh[ =,|n!5( ڋ?.]l.(칡mNjA';eeInhV|5zv&8٨(<ثs^cqЌp[5@2~-וT4g {Aq4ŕ\VbW6s&45V L*3Nέk;vHOQrzk>q8X(@"O5.9 ="7]:2+B;&*:JM]1 7kRÅ6wnk+TFt zA!&%<=}Uʴ4agLT8(d8k> 9v<@g-[`hI>yS[xmw<{u6:P~G??fs0׫Hr/\,l[$N{izi_%şJhs`2T0^OO"^Nu@pM}Po*4ZK!!nK<+90")z‹(ˊІgS w9#}E;w;pRp Dq$iqW{?%ʽ%daFЀ+ eWHIXYXזO%`LDd7@C}ѳ\iLdڮQLJI8*tI;N:\K7i`w{A&`37|B~ޜ=yIO}u 0!oVgJ}8 !V'b5p`#00^=V0#!\XG|vM6!͆)@7:'B,F42Oyɍ~L)%{/&ۿ#֬px YS7G!vvR(틏~xvB +Qla39hFb$X&nָbzviL*eSZك&R?&:xE.뽌&N]oA6!#gWAZNW$ 3чy u. a.;*;2n %Tw,P'7xYP&Tk|~D97YgSJ~G@TKW`\A}_W[XċxO%܆PX4Ѯp,=D˝q5+o ~ Ձ ].kw>`oa3U`3K8q͛gcMњ6Z ?Tmb] 3K=[Cap|Wq}:YDbku!H(ᵓȏ0C`_S}7D$u~G gݻdqGf |1N553ٞKOhOv 4=-ADAc{󉧛b{o00Uy ?Ljv0N\6Q+Wkqt 4P)1l\HT ղMZ9ң8 מgƽ+ ,]Tv?2#@mF:`._C]"בV4p>Ź&-wQ  7btO;`)څFF'(X-7`44E+54Phr;mFxaDYflK 6%$Sz7}6>wZ43@[-ow7 (YR&>-K2}ySvE[_h1Jp 8 fȢ[{À_gugmҫ(QA1%Rwh_ 3ߘF\ . >h-ڞy|O|"{\DƣH]In_olt_,KD~`OJa\@޹>}֐kchS GzuA$d1du=sk5^W״v(GD\W?Ҹ&Iq18c^[^8踿k N,v|rtjLlXsW{!X& \ 2$U aph}GO`TXs4Ö<;1 )}s`˃.~^eqj~v<5a?½ݿ#?On!MrK! 5c4#DUe_h"/ߞ>ѝÄ %Vg-!:" $kIlp,ƓES5* 6>`/h?5FTrcb ie#TTc`)Ψ_ /n'Ū3/T56 /~Sd7jC( OQ#ǎ˷[Ȫ}DCibM["/#7 x\@1 }1e!2$8L.FA̖ph$HK ݿ K;rzp>Cɖ۳ۻ$oIA',M(9 +>ʌ/Nk|.֙& 5C{e|ت8Rb4q0ȥ7\&*i<;LLQ0RFe_d My_G- / P-B(Z kˤ|,ip'kf,XtW,쯓dzcsbInfZvK N6DϘiPU㲃j+l!A5-}ނߑN>hDq (~D1,NR%3RwW_=>i,^!I%MQ>|\z)$`MY5`etNy=YHT WM04M]w5ETB٩#7o)LЄF랣Z*bJ1%pNMOkc Yr8ce\&IԔAݡCK^XT|'֓+rȯKLTeёuR57!#}zjD:&ő`kfvC{ȴ,8M~|3 ,ɼp\U% 43Gq]tONJq1dШ^^Ɛz21y! l盙&&a$z2$WuzStl^~3`{MbPۆN@ 3B5]2K Hz .ԪMy v3u8o]CRqcj7:2(<)v'duL)*<^bO60Puݦ H]?ԿJPCBF9[\MOU:B/B=C'm/[շ862f!}m7hM9|.$M}f3xSv1tMeT1JAtUp72'&o/'HBEc%=gD#-3zt5 O@X߻B͗u l6Nr3a|`)U"{6YlT]b?]9F]*_^$5V:CҺ˚Tn?ӝC5)J `I'Pt|B-fV4Z73yV>nNżWi%/S0ԪRBtƮ&' ]W_2~&pxJ$/ U'm^|e^}$0Bq^:KAQQY-ϩGAFÁxKb^e +ȋ%1{C㩋la27Q 0 xYx#}MIXV'{TH^%*0}&>{8B߷+~8a  - 4Nuv8%Z?h v\JNG ^㚷F$f9hcgL&tjovݑHψ,-5`ӑ'L4\ QbMͥ BOk$y&WBC[ SNBOryhLNJ-ZLoA`a#t0S^}=~L{ihb|^H8$ز ÅW Bcr%DzN]{Ңi7yhŸ*ߙ٢ALSʺ/3ʋf -dWfu>{H˫&YK㫽OHjP5#E7qFUGKl 3߳Li1$vv׾Ȟ(Ł9ӥ# ւ<Q_°8O@:LJoVL> 1)2G{mř{_;SŵO)\1Wl)݈@KQRiU7[*X}*<-vp{kH5VhUl ^LSMXy|I\pI )FgmyђWE y55Ȼ iι7}%^A۳R or$ЬPǩmC6Dz 6ޅIsCT5hZ', 79d(E;Ih1KN(cuwuniM满Ҷlnl/iNMP Ş 8E4.V&v`!8|ߌ\?B\{Z ,zòIi0Vz3NjK $A E&=9LD_:-C u %BT8Ps=12JeiFBXjyH4.>yFBze4r/11R Dת2tA,z3~Ku#s/Z/+m17t.'x|]w&p ^c_ZޱX׍cMʡىn{ugPk kܝXVeWXr/~~0*^UBKM `'/K0:>j6Wi\B/qhvo"=(v{H]/ L*;%lBC#KOe,ڞbZb:|Yĉo=ׇ|'Xߺs>c>:A!Ώӌ-Yf1]HcP(nWdGCP d]y}7[ @tceP䂹iQk" 2`Ur22PDzf;?1b/zC;(7scڢukp$rL ^]~_W@W=h$>W]dfT*E%Z*;{У̱} 炗0Y"ӕ؃LOYCZTAPM/*3M"]lEH`C|*kUӆb57,;.3Se$ctwZR2xtGmY5\8USи,!M% B E,",jSk0LjC> VăxO+b{zv/:ܸ@]=վ d l@d6PF#8zJ.jy?ߑd:ؿQvʫsQZu8CAHxxX2f..|`pP*pv]31yێqV$z&rZ$]]t1V :ZL@g*|BP<:fYօΓ ^tux[L-GtfYC9U2Ӎ e-uZze") ~I/`]9#zz}7ѵTOh[@i>fRouOϨeUSh/1G|$Bjϱ+|haQD\ x'%BR&!{ەpd-;([k6ߵ?CoQv/.5H"D{>UN;*p2fKj 56ek8|aaLc[jZQH6|LwF+eZzhxcv|x` ~~N0ձЩSD੓B{3rZJ@,W]g\i|%C$_,_EtyWrD*K`ۮ-:'9x.|,5jеb:Tp7?q#ۡPrbM芙`B}i(XUfyF# Џz+d7,h'b"Œ ]{G\}/XZAU@UC:{Ffmba)rz"}'2h00FoNΤF+;Wѝ ޾{E#VpScӑ{C:H44G ~Zdg)QC |'io M9 xx{YmAF\!kvڱ!/ RZ05߻>)ҫ}*̏5F.o ޳{1+bݟe /e?%%.f CVIث*o'GNP<==z~B|sc3M( \[[jn@q 0.&eRoٮR?ura׿ 8ȼ*= +Qo}EqLsM(=ς4.+p(Z [*;^ fI93 b ?¶`z7&L·NdnxwFS/nŞ޹Fj)&[('DUcBk o_rU_Gw#E퉮KzJ--Z;ŷWc|$ԟaKwc- AV "[瑶/SwM3Έ'Lm1$ͪ^1F;4c˒lS- _gڲĂ7t]kmXsp&}'~wT鈙dT7krf>krz)\C+"WIVX h!P Rmt9Z|(g> xנdm*h=/*\c'vm|s)@+@WU IrN7Kax@Ɏ%iaGLCj\qRLA@ Hr0úZ޹&#)-0t4XaI%GAT }M[dd\yG]%yI4BUwxۀ#D]x]$n v+59_=ڏ#yZcZ i^2[KJ36ΨJ%u:ѢEtpl#_ j]G@oLÈ?X )d[!Kb<1$i+Ih-k6*(,{ځ/RsVAb- {:[|/-,&MHIzgzqiwrӌU?Oյ{O;R5G}B# K& :dn1{ 5NPl"0E0s%?`"Xnx\E8qnM]`/[:^3i+ k0.`E}2H=Zo7Rf~k6mH{Y q/Iƌrҝ0 ֑D(Gd;mWqمAlEk},dۋoj/TmGUDBn` ~}>X̶,ΨLUъH:),57aT?f^[Q_tᲸ%P +PS\0I}DW *ty&fdmB8-{Ġ8zU'|%[ڟ,s1UpdcH*a}\ eU x4I,Ukc͋7@ܚX˜u.f I]؅<+2!x 0&,`4\JKT4- uIV>YEVhy࣡Mr>U=+GFP69S|?t$^Kб+Rz]!y2#Y7Լgʿ[L:O_Ȳwl&$a°P,3S c2IB"E2(Nv[`Gn)Ymg:MTK )$OTwdhw-3%YSy* /:Xv 6R=_9mi'SC/pAIҦ2ʈ97G؀pD(mZ@&#\??yVzX-5H\f2Kʔu rƙJ]):k˯ѧ)pt4f]`n(`^l(gG[xYeuuFϭ>>kIoh5Ov?~GdMz3j{ֿګ \o(-4.jVj|r{J9%;U/]Ds6i3U0߰$s  bJyʽ1_ E{sf0xv  Vyzn^ΌXnr$ 8V-"fmuMb#MloN(HZZtF=~JuM5D=h8àD^ɶ&x&w)I\C;*A<ڐoē6f$7 #;b}}t"V Эls<>L=_L&ASKfZ@qł d3DUf65e87s{xQa呜Wʦ ղ)0>jy(`Sa5fW?#W:yr[TDbQeぺ.ݝ'eeO-:>rAy-EHpH?8* 8u?V \4[VKEr Q_u;2n9!9#Vx>Gȭ~SŅ HFcbrJI,$F")^B$iڗKPZm>izv/e:ک}\ʘ=YoɈ8l==fu1r-DnuO & RLۇ5^7EG,)BE7C/X$TpZJ7?ABS$-xTĴgӬ9Z 3Ol4./` ݧ>y hJ0ɀhK [83_Ib]A<^g\h8k ;ncZ<\EBk'1`і*hQAaNV,K} m@ L!$+ CMMDqpReD!LJ}4ۑb|*l !NJb~ .w Xcm#v)kN[kDc(~ D 0WSyǿb4p70Uk@OfͰ 1yEIdval 3EN#b "yHtq;˨c@=f6)5z͇}Uc/vF*XTs}T[%^ۭ܍;D[L{^6.Fk3ISK/ !b+ya%[oGN)>y u؎HʵKSLF;AK=W#0XA\mK{񅲓NJ]YZFaz+W W`/C(鿺wCۿ UFuYat$񙃔.O|?\Iϖ@76~㾛~wW83s!<ohE:y$DcoF# !|mNbJƆz׹NfA(uC9z˃jbY~*glamJt:6J| pg2 CUN~uX]ZJŵ̷ >o@kŃ7p1р踉c'ʩV,@ƻa/gŃΠ$/xvIB M.׌ /'ѱqљU49 `halhJ+o$%dQq6TO &E }. .a˃InM[u.m8OٞeFu&6tBώ#tPyJvj-y/̻GjWqA[K+iFC89>j5d"":sKhMl2r@RlQQ(ê\9>5 -ZCMUy1Oim32 j*d.8VEb$@W$ Hu7[_vC.˱C<%UI GsbǥtׁT/&q *G#"i,*iӬqJlO-]+I@΅x2ޯf0tlVdeb"^)&ڧ:QQ@Znc4"fv͵=C G}s;}3&wM7t7uf2!@ Z<| cDhflFOM-ο | -%B?v,c%M"h 5p2w:E^&ÆIdv_oj 5)PYE \.>S& 6m ~8d J.ReVQ(WqS"?л*D%\V22kݧ'Ȟn \R5OO}׻D6"!t:X;O(ύࠜa~ EOW,h2ƇS"Z5ਫ਼PJ0rJ2ڙX,q#j+R `9=YgJ˿!:X͑ژ@48L,X 3"@8$#9򲵹fwk2՞ڀ](r_id?]oϻ&q-Z(I9q.I;S5=>{.֮{i/dHiզqRS)wrqȶ?C UJr7Fq$fNds!K ~ |x*Hef]sq?mglUvm%f#iqeqR+e–HZD!fբ;hhS _![gQNN(K^׾ub׻Zz;-go^Gc5|i&~LX]]e kp]Z:#ay|"ol|Kآ |BK\N kgf/~a|lF~6ȯCqݳ- 0W[*T?Rfԥ1?]zmԽ_O`"v/3y=p$;q&kpX"OG5'W[5BfSC& (kGO*. >{35 *!0T;u"U@q@7k.7挘m{@;5ﴷ(dfat*ߛC-Jy¡[{tqtl?Bذ19 V8}iLr;Xp<-gb@Q1 Q^GDW/bVkY62c6(ӧi}v/ hӜ&.OYd>,=LR~$BDwO"ƌr ms+PuѲ`~! vj_X]*ϩ-DEɟ$:u j~*Zʉa͑I-“2tąI?ǝV7&j9Ɓ6}[~9&o|?W[q2D1Z4b%{ihR4>c]q8+4x'4WQƞ*d#VLJ,S:DᒇR:J 6*pyG UI0sv<+e\`oP?gw!^ 'oExS9w,Sf*= M18l-xueLABI9D@ UjhZsV&P⹏@m{]vD׉h?|w2x698JlqEP3wFD\c'lǵ_=tC ‚ }Mu#yׯ\ɇƹ-b63uIb".EELNW3-"EI<ӂj,]([P2P8PH^asV+$5 8` 0MS;gI|lh p/4k/n"5W|Ώ:a,8g }3Nr$w $YZ<3NL>K#;d9k #E԰S9;U2S`s1`' uִ-I9fdxm%2ʾEMOPwN2JMpB!TkQjY!4<]6\Ų8M  m8jxJS#vt[:] so>]SDccPAP4kHr04i苗0lnB[;mQ;RbcZbL?~j{ې5J~'N;BO;n|Av|@{T6а&>bΨ+$i>6=Ly|O䏳@:BꇖDb.u|V(f"0g -cUYNtRR-+w8 OM)s X.v,<'Yl8^]KqyK!ƴ8IUKks1uۼlIBV>p[7Ofx/4 @wNxe_p)h &ݹ X;<ٱO/@#!x32rڹ f_n=$/Ƃ^YE P CƊ}GD1Φ\EQY/"نx._aIC vG |:L1s>MT0#3:P#| {B Dt g洆&/z Np bTehWy XaonJ7AZCS9LBU-J~WyZ!&PƪSHWp+-ul3%==]@L@ hIz `nA|7㌾;iQTJENu<͇VCUx0 ȸu73c-;smʈjTi4P8Jf9H Qrmb4{Lf3ts}b!g[c:\ȑg*qIV%q|_ m$p5,Lg$HP.\0yrv%vk@_?^ `9N!ƧvlK__; >"/|s@,oz?`EUx {tIe!t vXN$punTW=޳0Fv:yqMӠaG?b? \4M~a,^ֵr^@n8\N %aT՗功ߕbѰxgb" _L%=9. K[ i"/gT'֏$ma]q$|dEh%:J:d{82Y1iUC8׃i@9+ ۼ+]f.d3>uRԠJ6[dB1v/Z\ݹtHV{.=MvwfԪߘ-s!F'jŽ0 PR+nrƎCQ8zdQ#>gF+Y; V.NAidHd0bjKvb?sv_sWJ[ {rkO6ᵊ5#g&QFXڃO/%>̾7X&78qw !,"݌tIoA?92{O/U.n^f^:OK,}Oe_wB;ٵPa2vdZ-[c&h)h}zG=ΫBE~Q=>Q9Mz1ǸʎYZEZ^`W~\Vfmn@mu 4&6Gpwluׄ&sñS\AIYY?Dt_5?qpii=.=o}|%qo ՒV5m*nVC[1f?H '++1Z֎$14OvI}m\nr *YM;z||$LI-7"]/y|"l@dI, M4N<~vœkJ<MEMNPY`E.+0Iq߀aIxEj`n5 }& nDO_gIؕ!:֖2t;_U$5&Cfc+ 5  vIJEEfC.%"錎H7MvݧV.bЄOM˪E nca~*Bmsl^{2ww!*mzZg͠x4J MГgxi1(ӈ˫b6) ΍34|M$DV(GVw] C/ ,),i{VB%4n2cWi^eAru#E!'x*K/XZlZ(_3څ"ƕ# bcX<?oe,BҤ< 5k!0u4=-D!xۧEe[k݉$de4;A6L3r.;Xlc( ^>"t6 0xfC d5nB$0z2G`u]4F5czX<#M(dsHGU-Κ$ˎ4dUA =bV>w'91Ma'v~ 3E-1࡯舤`YiܡuCД-n''&3'-(= \Ƭ8Ŭ̠GL@YWHod{tPFR ;(@7"TR;q=|\oOa3+2Z1P?h1J`J$귿a1;)W}.d7y؜ Y$ѴoҨ5- s7:/Gor ,~FpfSڍ 4)>MwX|SoS06yq_ 2 y4Mٞ\ 4أf͈b>O)0sB{1Β3=vMCB^N)K}@W_by`dB' v+K|} Kg$WOd,R', ç0X?+d߫dO,SO,e}c6rBFcJ_E s$ߊJ wdD(nw#E&eǠS&ڱG]b 3o>VSn|1zp^6&6A!wFI5N=r}Idb"y%λbɀ5?ӂkČ\ BC`|G̿7 h[$ %6{V2пEmX$G'zWJ;Uyʯ#tEs9Bj%_\8;ֈke8 P_h-U]Kf:GZޞɒ={K> @ pU~x?6M8)%xQzM+jӟe߷t+ 2uva%=m'Xapy9 T~c !vs~=}|XJȰ.&:VVM͗j]gcy= +AiwiỴ.-Ǣ2~VcL2x';X<÷&Ϝ-05 !&0` E1-TT,Uô]X*X#k*>r'HLK(ɧh' >-ț)9xr%:0PY!;Kw# Ϻq-}$4Y'Ze0t8 'իa 5IZ<#Q'!-c6c' ׍bad`Бji\֋C9{Né|C STPg5|z=8RCH&8y- ZQQ&p`^k>Yym/#48{"R.93. B%þW`+VK$&ޚ ]gz)o^]VSL6d[t|'H t{T.Œh&E*2]$gOnvw  [B7@YuQT>:;Z>!π)>yD9lSpD9$Ȣr*sTejW$TXO#=v ++yf GLn `< c"p8n/2)ԣCsŽTU˪=k62dd2 1FV#c{z|kqjȪx:kݣP2yezo{3TyoQ~:uЪ'5S?>gd*ܙ$t/vɽn psus g0kA67pν/;UBΡqS{N3*?Y"|궭acŅ$VB#|EE٤q}k^U[0h8̳Q3cK?U ϢZM|qeB Zލ`׸d1)vUIO!(RVVSs~sC<*PΊ}t2ٯLMX(5'fǾ<`6VEQt@ڑC/mo%D)[?fׁ>v!|ƽf>Sx8ylR?Ć?iV'ޖƗ 0RyM睈 3=0N&!^ThӺS8s zٲ*i ߖa@$^)NBRX2{%[>*󇼩܁ЮoKfiZzwH=w,:z$:)#bi.%jõDDM8JM$\9ߤ^.m=MGVu[:ad[^Vs냚i԰DS?rT|_KvL%¡>N?=:vvߧ$Np{O"tpQ1~sT6Ħ7s4p@q0:}OŬV4e4=%-JԕzZfI6kc/N^|p/e.x-i:ͼӷW+(-oegh%&K؇_+<%% 줰wXCQ g$j0uB`j@6ū,'5to}+8zW  [[3yyZ& $׀O)!M>'>tA&Z1$uCu!gP~jR!#E1 çWq7eqFOG?Jr]/('z0OS ubS'jYaG }w2O똁=䴪oeCV>yI;," R Y&aC\;j pSEߘ7c #FC*oi^CmΥI\w~PW'їז*fzq,'DwOfIB^| XME"F}QuSB4Х/إШ*[~55¾QPwV5N!0;jf"Gt܅ vMjxԯbnyҴ( p[p0{"c}!=_'#eGp?6F@`.q\Vs䙦V@w=,r~1zL5(e89.v`J/iDC7~-$s6$cm Q(r;&UCU-]O HVB}@kݼGPֿP#ߜLlD-0d3iÜdΕ3]S%+H3@p$bGݚ ܺ+k+"葼ẑ^j|!h9kp-`=7dv|Zp4e:7YYXgUЏ`KvzRx<T0i6Qe2C[(j~ׁp&ɯrDYJnɤ^Ԡ${;GSalݖv .Dg#:Hwc fx|oy0 kib RM .O)7`5J<7BnK:5[wcKݐS\eGă:?wH梬v EY +Wg9ViTikmqEhTZO) 8CvD}D.F@G|(ȱ.vXX*;fܝ$nyҁ{rt arIM:+֟row&+-#UɫP/`YB:N$3(4 #*rsN8;o7փ8+cQ"FI6XgӀQŝNEךN\i0O2xsuN9QwW[*}oGBu7b3G"&N Ǡ&ZC"D=-.=/&jצl-Ba)&4OtG/1n1[4gvaѲ˃>$äfÊKɣ/xxVo H. "wxPcNYo0F3Z&]FljyqJNTmC VG/GxtIPû~jdGT"SYm2~}lB|}25i!m9pd1!dQN3AȗQЎ#r*RQ#.ĩ!d2NuzI8 !Ɗ:C`ZI>3o U;v6G'IwB,HsFu"[=!FA"?Kڝ nEV9@tb.+ b 3jߒCzl@Ἇ2υ$ D8cUVlRtq nί3aJBrb@rj]Sme],UTVRC26pK}.C[q{Q$_W9R`;>; ,` ]_&&>l8EŒwس!QeL P@A-LԹ8 Ilhɤ*7Bz|ϮMYU{fr ?rg^`I/rDYb7N6_ 6H MhCL9!kMSzݪ!?KjTY'>& hwýCPtGsQkCH*ՙ;IhtSoDcsJ'ɔ%Z @ ˝%B-003WNutI֫:Rʋt.B]k5Ayo- o?g*d'uwb`mM &ã|(ͥYx8h.l5de őݘiT'6d)3G"=$S$`TTbh|&IΚBp{J$vjB@S  p 0A_r_S^< m)3͉ bZ(y`ݘCB c]I2o 6<ڋ) 9]R]+^IH]^d%Z=p݃]b:,$~42NonqwǿwH^aJ e+ U.RanfV6>,2@g#L>g6Ê3f{h.eݦvVnyg.Ga5\DnHoBr[3r0W脆gԇ:!O=%-BY&rui *hGo#zFԋ)rVЪt;ŀKSmF_۴st)e G66M  |(]Lp4r_B=)ǝRţ烋FZí0$ƨA5BRg9h$ B(o}a>CTϦ___ #aR㒳}$oz6;un Qh0uwKcFʞ݈^zw\\.8+^ܷ8_/ʂV Phb?yFm+3Y$4;EFm keSŲ0-j_{hpPm $f M@2 }gZYE`o̐0N*uvP8C,wxYi(Rڷ|{orvi;ST7C}Lf`)בgev8\K`bco;X>%a݂S oP $w!nK99`D]y>w~DIy?^guG7͂ih iNH'B+[~IG0+i˹~wV#* c fѸ#o>e)e; "I r0 uPqڒ.M&=!+k=$SˢQ2R6HpǴH0y[q?dǔaٍpW}³r,PcRDb*8E84)+~$~x#z/Q6^˱] LWB.n}cdѸZg|S%]0#{Q؇6V@7(ryCnl*ju$ovTгNS 0SYvx˔ z*ADwHKQ{?y" ‚|;گ B9y٦8V2m10L"x)^nSG_a:[9l>HZv_ᴳxBlo`&OOLY`xCέi =ݜL$tɀ;6T-M)+0*ga! ODKV(l ydc߈2p|vI@m`Ql<tO ć <.Ik5\l@Lb>bx&ŽBR"ud5f8oCKm^AgѴ>"qJ!LM(Ӷy6lߨpG촞J!7:HWQ.­* HVr;2 [a%dE Z?wK]j)I3F` >w~F]xҁ 0Z<Ь8IRMtde9i'=RrS[l ~{{W>Wú#n1UI3dv^f|}ItF@ P=A$lSKO}\,' FTOU(;;ՇGGLq/_ +{dMJe*~NBJvEy- .^vpV #c\Du\uv<='P:$b )acs8@|l106@fnxG55,|L70H;8?!6qHZAYuC/"ebɽ"C#6{dyNtw|F+XS, n/kefqr7tz7 +c> &?R0Olt~j'M/4NPj[{{dEb`aȕES*^ (4$9UFڙ%z9KW)4a {|3X&9(2Df>EF T %Ǭv(u=a.R܆D HnjhࢌIUDV/n.zS~@տ6ZI̊Ka /AXz! v69{<,Q]0sۣXR N/8prptCt` 툄=.+=meL[/!חzl@^e(YQEF1x(V~<ͺɂCo> d_zMQwT8!k儷6a{}Bd{O?cz^HڈRQQNV l'rx 65:5Ju*v[9ZnzX8;fEF-cSl IVvx$V*~ymG6EGZu4E3\28q| 0Gy=W |aWrAGUh9wg iOiFx:f"vdTq*76]{9[w% )] YHTa*R71d!*ZgIЈ71zi۹f~*;6:fbb(G4oL=ٵXklKf@-*vΨ`iǀQ<5Q!cES4T嫞UOi!KFKjd%uY5c1U,䌦dG&mΐHT_iWtlX;J 9. |ʵ5>lF\Y :x;6+$pFߴa9Xsj SQӌAaq݊9W;wlK0?l\ /\v!L>WfxAАēCIO0UM*m:l"?֤m Yt.z3&('4d: ;pqՀ+Ըp<,ŧ"KJ~pgB'!+Z^*زṤf9)S:~Zg\KE7$1 "34Ą`{Ts2%p)>c| @K x-oHE4C ,<MT׋z0mYBz~C] q@"\pq٥@RG)u4N%B,ۺ*@GYns7UnłWl G\$vI@cv)& ][1D_xks]GYmg37X/nĜHzҤy+3:T .Ѧ7'ju{)_\"rqyQV>GV TLh~&:X<)•SI%!yIorS.4Tp%uHdzU ޞA5mzj'z c1I`aOl 1MH'y9U|viaӟO?1؝Au#qHj݇|,/eS%/FW_Z^sZWs,l—ߤ)ņDT°A A7+F")!ϓ|Qr;}M݉k{rDAԒ9t w{] 'L0 ^7#a7Q&؝q a{%GN|j,x9~4 9Lt2gPUE}p;=[`Ҽ)b*Z)ZܦNfiY8Œ]s_6JXWsGRCX CZzU_r"?0ɋqw:ɒDbQ@cg}pǤv dJmFFcGSg)JXlj> JB5S(pUyx}aeaD ӄQ71p>wx kge2L2`P`|Mm?W`J҅zD>:K !s|rDI (qVnXɻ4JUeWEᡌ^UT}qVIR"(!"ZG%̜fL">j3d.d~r/Eq"+f'9.3~?,VFYLvGwط\=$T̜\h,6|7=W*D>s }rs7U=h J6Gΰ`F>Zm.MirPI'%ؿE7sn\%iҕO_.$:XCIN*vd21}D A4XeiUˁl׹%z"0FTf$S]⊥Me}ׅW|bP`{Jz Qsb<;dYW [K/+jпgaxnV=J39{yӯ!g[tS 1Atdc=Pfgqx\Bx=0nMJJY9tc,T'viĥ?dZA( 9s<Ŵ\<ұP+?g `*n=`cI4`hކ&CVP^deXxM~\̻?EWuiYE@#t'CM%<ŝ2"65aENDo]2:H x~ *kwkeE? i:U)釢%ğ,p \RvCZ[BNՌok }FJ_zWf7r`#L<\싨 l>:̆^'Xa~X)Ɓ!E4-  D'O$jpg;"ALz!MɧBrhv[Ԕ8nWD=?:ɸAxb}7U@CtVGCKKdZ©bh$c('WމuWG8uoSNrEBbΏekJ/jנۧ-¯*^ׅdlHuP"ݱ IE~'kxO;c^u\ѻ:ÝA2%`TM=8/Mf"#JOvToPY^=`/B瘆(8'qרJs%nXyMHmChjZ%{pd}닡豾mxAyMH@riHt͎"c>f :l>s/Ő BA7]l(+/NH 'M>j7b&P]:_ĊdP>/Ƈ{aN:EI%4V^ %nGc[##;`9cMiIӋHٮ|uWvZY "W 49p{b&C.sNݼ~I[Oo]}ڇM{c!7rޑ>cu\ wC*Ҋc@ي\\th爐lDX]q^Ҳ>a,%vX50{7C%_w`HAbnjcIi&a^oܫ/ żIr?F>{6Xa65rvkKsrwXir«ƿ?O%d89(+5^˕)R OZk@/O{_w~c GP]@Q,,kkcAb$E(֯1}N3bzD-)|oYz&^pɚv Lxl^TC4p pY/IROT60+*p]p-"ϕۯYBLm hZ}"MɋuTdp^)<r/ #Q=sTl͆,J'r^yU?w2q󞦼UT]n+KaaJrk}̙RѨq8gBtX, /ԬN"ЖFOf;:×M~ w`ryyK=^7^*JS#aA>I^F$n{(,kwZq|x"Z|8]۷Tx ~1kWKPe*X i;᪆f'}̠NC1TmJu9aw2{(_±7ZV&$u,it9GY5 T1Ϗ~=mBDniG?­A?w{Zq̷8ƏI. 2/LȹZXmq&_3'*?]+mҐXr$wu~=t^֦@e)6͵?pJ5cMj5H/VIA{ZҝTPђ`nW>q1wyKNrJ\\Tko8OmDyc+@fh6]h'.1r[ G; 䵵-c{ e>J2y~wY rCx߅^\O2//1n9(L?X2xS8[:m=%BD\]nܑS>]AmWWa_?YLFSd&It}(H:y1ɻ'!_v34b(zĭMCl&_,>.溮 Wo`9$9ԡ<tN|+ȉy o;޻;K7`5V#jȬ=iOr[:._DQbeFK `5zʜ? Wϩ ZL:T#r3&$\.~G],A/J0u.YQ[9& CIޜmu6 U^~۠pŵinh#X? :֑ RH\V>}o sjw-{vI緈 3X331ҟ܎RϳzV$Abt(v(~Qم',1) МGg0  A d13OG +!C%Q[wP&VBQ/O`=nOe l-.Q:&f\9N);Wׯzkzɠ{8J olA`Ea`[A.i1h/DLKea{Q]W]*RR,jxl'߃Fqwɻɢ7ӱ:sQbs9~u1AP<ã%ʔg{^~* qNyךD x=Y-8v~/~-maG:rhskS"`%֙6L=*;uwd;:YeV:g=cRbA%ñB24~.tRFwMq8o6S.JY n"Js$mAL.t7h[.9ڱFoר\Uݎ8Eg HA;"6ՕRgVC ?40- B> +sD=8qAV! _jM,R^_eږQ𜎢WԶzQ)*>AV8b#IQl ){q7 O]jQK$ ^tRfJTףl)kQ/uxI ޵P,$N{MrZ?ݟ)N;Ӥw_Mu :uƫ ֶ > 'F|w r3i`^եޡL)!W.I w#Uh*L4+$/]N4t(gZŕÍ/5؛#/d_n>O8Q_ס7ӹ  #7@ȸyݺIcVy\i[7s"1ũWC*eAc{XDqV w~fTlف@2rn.2{fÌRb&A6 $q# ܣpMϛ.@ݵ"  ⊘XStp8z =.QKo-Ksv8 Jh, ko3A/~"+|ݐs--=/z.IVL5V)b۽9e#ZO&U։8nNG+0eUy(d}C  .Q! 5`Mjʵ% m€Bc`"ǟ L^:jqEfPբ=+qTmWJkl˥|S3'{lPB+#z'1^}traA֑M! :#`,fslP?g=*Ktx`c:_ oťr+ a]BhU-0d〈ϥ.}Z٧J V$YFg$qW|jڅQ/'-9&!ٸȅ HΓb務OPn'g$lj/1L"o̰"L+NH(D}B TDJ(+ʡ`)_rM~lب<n\~;Nt(+HYpZ17eB:Ѯ]ru eJjU~#,1x$Wo@-mer)i(j[zƲDx j8ژfmFn?ۤxp! Cy҈?D;[1LnVLGE7{|@ (]F F[1}E=$#k7AmРqsgzH>OQ x0*)黴-T+FhG*k,A[TN Y▙Ih}L)qN/ײQ̝qKJ2dU΅!pu5pXd#1Э^݈t*G tEZG}2$Pf.MTwww]h?Vw @hhN?.'32}XwҴcaGe; 6[M*3pgX&@>#a#\ľ{tf )SI$I8@`MM }{qyƐё[)Sשּ+0T [X*dn4F^"ڃT?N=L>v<*RߌL?w̦FMRy- ,ٺs, Ry8`G@  ̻!E$^ èeL[BC"d7 E[ |Hv"rDZ^e WqkU n;.Ҵko}}%!U"#/)X{.xںQdT;LT):Y\Wj Ĵe0r㻌Io}1~ SоiŎLT( s$*kg7/gqÔx$ 0jV3ww=#1Jɘ~CYJ儍â &_5)cbAT6@ A_A ͡K~Yd501k4gSg/6e~ s•< " PֺUN[Gd]*BoVL>"ƯCnT2*2Q2QkbV p?6-w<;Oe4l[/ۇjxTSea޲`hVkFbt''_4=@KYР'&!aɊy8dD5c2l)/KR*sxMDb=S3\*Sΰ(ߍq7£6G+Ul=46^/eކ&@0n‚On;BE?(w32 s(&$lTvHQ;<U`6}-.N`qkTg9X]>mL=J zl-R/1Op0bꄙ=nw}D[@='0 n|BCGejWAqY2۩T7O]lU e{$0JT"Q nDYn!8'zr{9我3A]ϲ2KKJRϥВi:2^{/ 5*M2 > -/:dظ[r=&)?; mi{ uiJW̮ AY?UpQ Y8Ōfc;Yb#8L8CC @AOxJm/,.ʠ9\lَvw@W2LxdJ_[-f3JAߒJF;Yǃ94'{y )ΌD-Wp$)5ϫ:OъP-H.2gu& \ F ڷ96gnpV;u5mketF?RjY@kpЕh-BZ>op/r~'p eRp?K!NRh à `JaHV"¦c*m=VJ{y9,{ƨqȻhfZpx[On!oc:(hUD| ^&"lf~ؿT5<β WKj銨"*v`IAixNB HL}c4U{]rNEnd4͵VD!>>zGҧ\6V0ʑ@qr?y7^'wM-!6{e-՟$^)/e;'9N/&QLdlL87häB/`"N- ]} e.9yxAz=9rA*$NKY8texQx& 0;0ϧ Qҏ6/]{ߠ|tbD&<#"V=b^b O)u:n*O(/!e.[քn+Dz8bW eFP z5 /9ooDUJ,ŗ%RxzBhӅF)tZ S&dIB=o;_GdI|۔GH $LUSu05(;K= ɜusv(A࣎@ENqDj ΃]kҕeoxZsO?Ɠѫ[+k(sRѓp0٘!(o& ӳijix'fcv![T,>mxl'wtԵ]Fl$>{sp@ .YV?$œg2bҥ]GYm<h)eJz ߮@c2CwxƌHwjtj U &jˢ0^xk N @~Ii vZ>.;?3{//W3n^HP41yI0Z2 G7]ڭd{J4ШNp_qD[MfN j-QpRڡ;KXJNB[J;q$2"C?|H }*N^=_AR&?egZx#HsIŵvB tƙw}>]kY}t&mIOuLN/1!Pn2ssYZ"}m]q/kP9 %XYȦH2$􆝚=#z'+twHiFPyɽ5cI+՟N[2e`,caodTe5n ,DR?Z532\#ODøջi%bL2Z'2Ź a]fC`8'Xz*jkdp''+wWgT#D'K>xֱ"%&.=ݦM$\!@Ǯ@df1)ZS_FR! ͛^F$Com01ynJO(3k=YZ"V|w?մSI+ZlQZvlQ&:sǷ˕'-N!-iS {3&fIIqN/Rڽ $fh^W$_HFG)qxΜh1a<((0 $+42 dׅ1y<8˷F`YgOD-zB׌hFR>ep ꌾl!LA uBL"%F) }fVg ,qtGI$xRZPXHe*bŽhգ^1x:Os;ҧ|8Al5"FHH_K%0)poX@ #Y3mrr=|v#(dW*byCQ]jYPaQ)SLkoްy,:}PcАqt=~ׯM^rSw2'ހ$R?V>Q0)NKhYPlK0r١]KZŝkmׯM\LtC VB3X)>A*-^YغJRKo{kf/'}E; H qj WFal&^)%rM`(CZu]3y|8~7h'صVo"^S >'juX ˮRr(t#G83Œuk"ÄBԤ+ )KjI5kX) x5OWjRscqo*Tctm349FPȽS|Ѥ6ЕʝG g; [xg:3̰z,m W"2u.!ȝb[kjH@ݿG"Ps,yb=I.a U~9zo._fAupP,p Z#syi3EN{+y&H:C4=Y{a wP/!Yz5mP!e<ޢ|b2*]En;18>얍E<,aL L؊=0M=Z$X{n,ڈB  #]6%Nv'gsWOe9wPXd#spd,Ij!zV'ٗI&W&a0nݖ)14s+2k"sFm;E4!xlAE]@sáؚUa̲!OcTd^\' ةDlň;0h=+/^0*?#:/,YB.# 6e `[O)iOabH`!.R<ƍ΀]]p%RJb}#k(Chf] kBG>*]"y  #ޙp=r4L|yl')1F?{`c 8'Be r#* CcXVGG|c^a qܣ6,"ܖ5=qI<<k2ߵ/0 m^?eLQY=Lqw|''`sQ`%i r"lʴICHN:j$+wMy,vOɵgLI+Λ']5f)z8_5$ʷmeK8Fd`(x%vS$xx(dqY{4)?zDl\O_%4r ୏*rn/1Q|}j4+mvP/gsJ3:IVa7E5 ~C{[4$~BN`/2YZcBE]*[ueE/}WײZ<0 Hm7Z~Ny$mIJ rk)MÆuQ a|擲Ű^F,*U֨\8 5U+=¡o3~hUgΝ+Pڵ1kBIɠJ$.cToUN[ >i'sS  g;״ГZRSf0һB"e9_{eU 3;[G+$l'ca6, jt Q zv/m"H]/i]}8*(sv Zi"$yoY[)RX2@ۛ2އ!G"R鎧prx [}lquFTclpml4fA:|^̦]^&]O1vZ Ub#3"5d/% /z{mG7vxFo q_Ã#Y>*VЮѷfèbNknXEm 3C-L6wVɫ>0ZL5rCk`m -WyqB݈ Iwh ?>)< eD AFq>t̏VYQ&ykh;I&7=0ϒ @=ZqM6$gP >`5eGH-^|oH؄N tW''to~=R\XI?f2@UZ"dys>-.ZήEQy*`P%m(ŊgF DZsk M,wՋv&e9p]X]սSMTyC8:%JWQW`?g ?DI=/2S#wx踸[ΤRn?uHJ%j8)vIw|8 bVtăX"G/#e֦Mr/7UF׺uݩ2ּKՇ ,*Mg 5႐ߎӐl]iL"#m@EUs[4o m RXY"7sD* ?*JMiT;P@TvSSHzs0s:5`B60]RIYf35}g1Qn5~ƹBEKcFdѯ`ma3|`ӡ_q22%z9jfNT*֪#^䯃)pmWzjp=`,s®Ƞ:Hk}و#Ol6ry`R8]ZUu=NG$u/4]S7--oCpӱi@tT"UPaF=IUO|M ]&{!:dQT[$ ,#TZ|i{i)#s''@]GQ$Qo2Pʁ^m"iꠁ˗Dmn?u Z]j9\(C, ~b571h*3 g!wJh.4OUeI>m A4AeweibR`f 5=WAbP۞3VŲYAyL'umE_=IA?F:k>~s @d~2#ew&i.yol˹JG9SsQ 4 6`~) |Ӽw-]4Y7[ǵhj=֋IcINdSc-Y96+ls]{MDBgDv.?Cyk`j6jUf rPis&Q n8%j]gYD1sN\w5jYTlNLgƘ:86V@D!@V˧a )\)Bu H|nipbw[DYk?4"CZS|)K`elخ.yrW LBrmY\pcosHy fԇ 5]ro$Oq5˯T6HCJ؆v5;;z,QH3toIJEzŷǼ=WN/3@FrP h=V#uF8PP ZB9B*6>YiY /)q`RbGZQZ7 cN蕘BéqgfOʓN^1%\ e%qks0b1=xh&zNHoQn(t|4 BvX?:#ÊMO/d= ]ܺfw)]gINzFBi*Z" 6K.> ?czNcLM7⎄hfYcM{L &j㤴 k.n[ݗWG(J czn׀M)TcN&[۰3qh޴Ve)xrlndb^j*r4v DMY ItHhm/]/!-HEF4,&%K=> {lIZft˹oet5 uxD9rd7aAΰ6ڐJe T Y;'AF/8 i3ȇtX|M=“oURMvh4ѹ N.Y+J$}]+33Le tP0U9)K$ ;nbX( ZmSg&~Đ%iJ1ѵ# `B0|Nj;E8O-wF6u s3($<'06I6x Ӯ ؟%EAJx )s w r CA:_ߐvR-r_JMs4]L]9|rT3HNC@ jEH 3**(K-Մ\4aAHaܺ7+TwAv8 <}${h~^8s8#qNy*eHB%]V9>F:lp %M,VFcH騎IOUرρwdz趿&d2!Fˤ^ n8~OZ:8T7zV+!q!y=`hI>8)D TGW{dʯ_(+&E$9L[t]GH_vK)o/j{u[Ibk?[*VSoʚ4r"qKkjxS=`IE)E8jt1XLD"8%'~Ka(ZH+׮Z*X#j;1͎xE XqD75?L_|)mr"Qa'ƒ9|k饣: Ax.}d d"~/=췯ۚ%.R5gThaLx`"R>rFF"wn0 kTbh]';uh;pϿh}ӵdZ;u$L\9̮j%n޸E2Mrg#FPM'F%Y%F;/|+P#J~{EL̡CmF3 3 .jNv瘇Ub%$t-җ ݞ 1=| >(m5P=h!^P6|,F}Ol<"D 'I^Ğ#RF#Zy]Fr eh#5تbA X!$\)8EpdT^FvʟOÝd #3 _n fK`o^o:T%9QN-'JqEX}+ G `Y;RxhEsg0,z ao<\ pn$y~qVz-sI V:t ]}9g TTK"]3c${~U& , ǰ3 osg5xpS'ֈqJ( _ azU[!R F3`+fF38u(cYݺ"2c0 қ驓ȧQ[ufil>#|P i+mh e > 18>RK5fb㯻R p ?ycKΘ|28#kj-I%̎ rhpSv֖vL̀p @Bo#`G §vTq;:o) jVsM] ?A;s,<[/>9 $7 BdSoIA2 { 3ӸQmA ʆXx>Wi2`sxqgy!7!"8LȀ r |fL_H%@KOJ˪P?9=*@ZNE S>"'YgcRcaӀJ4X6ő%H jMlFbJpkWvX{L(a/EI%ئީ[mr>*tA2F]yn?SܔSEd}KHWx*G1բ;31\gP΀Hꔠy*}@ύW@iLS?-=%~L}i_Ԃs (촛Ղλ`"aLUzߺ=)y]䭁GJm#ϱ; -qLv܍h3կRf b &5]Je 7[R"/ [܋@Ԃ'mL&uTt 4'G25,b/GG:};:l*sw <"28je[^ύÃfOZۅt)ۣݕpIb>nOT1$Ur9̍9\9+ax}0d*3m@4!gt.bI'BC@apm^oߏHe'>7Pg#Jr޼+Լ2(\[mIUu ?0w*?? Rx K L[WdA[uVy9,T:a:LǮY(/5{(Î.Z7"U;@c(@UQGc̹!WRŐz蘴HZC) -Vѵup>Ay[FAm[lOND p t#cUBI$ .cGWP/q)Oqx#,Ͳ<¶RH~4մz*%c3f!7p9[r3vn"Ӡ_GA8i6R,g={(Ҷ"4_ Tɐ!o-m}GE?:biKw{CcsSu0cL0hCݤվ!y2HK61i}U^Hd :_tKSvf 8 S%4GhLS:gr}Wp {[6+&_&?ٳEa;.Q>[f[in壌/u'-ˊKnH|h1wعܲ4iR>N{0AKk3@E=R2o,Z'#* &N޺EC%\\ ioFtG4JwЯ-ue$o-VO6 89\x P2u)@u{{܄>MO;xDDXꦑ82qAuΪ̚Gn5:ǽBcQ`%a\85 Fjvqr10 KrԲ]yA/_ QESH'+i6N#p'TL1b"Sj4eVآypϼxMډVt⥷\x f__IU=sZo &@* 2Q$`L8 v]%#]g5+?1,TKŲG0#=́~;dA1DGd8j fv!m N\Lfwun ^vf7C.EΜN/q,WHb5yJ[gMYR#PD\<u=0̃~[U?rz;yg$CP:s"t*Bvۜ _@,.gm['c7ó&V)X.Y3B6"Վ2,眴F?!J .*a+fsK8 X.%* &c+=-yߍ)EĴ%|YZM%O!/褳CqZk,-`9ф$$=fjQVNUu蹗/Ӟɕ7#fHm `3thܖM5T gjpvy6z2Pim!$J^nj 6 0\qz7|>j;;^w\Yڒ5^l)bj|jYZNDuC @B33X@JcDT߇ 5~ v\w(K*'7x!W [*p&@zB9f&bg&4ގapsffTx Wo֓OD$?F̚J'O=;)L(ncα7`QEj 9{̝ x|FJ5.ȑ/vo&,SAP=6purBT*܃`՝}6VkC8֞Lw kyxx>_(q@u$' c[S2B"v(ac>|w (ďQ.x46QkexJnF:¨w4Z;8h08Ta\ʋwI58P y5y2oli_ǓlL]l}&(39&ԭ9xAZ/'/1m'մC/G61ҟJ?(^Sb4:)wkc!y% ~"Gqu%cx\HpW0@iIɭ;>vstv)4u0gǖ#?0t9b޲ L>jے.H3j?dG9-Z"mTXxj6CN+pzWQmf (0՝͏or8L]9]{Kb.HP- Y%_]&_~8}HV36ؒ (pyP J~&L޸7 ^сQc.@ۡs$玲:bxXPh@9݁0C03DQKWCux0"9dI+2̝X8fRrBL@Y4LEf?zQ℟DdNbqeo{JZl@5xs l"$I#"]KU;]kA41` L:?Ok8rOSYmuhgYR{ v&mUę<$W _zXj {ldu~`_k3<|cbp&vޓ;MSn>h!8# h ,j"%( LMM 9[@quy0p# (pexeuWoA:(.#DNJ=oMB-bQtC^]aO2^ )A%>?p=ZhV!MNJj9:tthctP]Ҷ !Q4@&?/&&\#$w hj=v2P$8KxՖ~jn)iɡ62vBg+F _kv%!SU?0".NqzkCh>ƃ:gnҡ5漹!Eb%>O#XxN.d[X#YfPV,{w8'z/XsX0:pH }Md ğ_x,Eۖdϝ{Apw,IڵM?`X }7?xckEӤD;\]L.{2R L|h "/7\ٰ̀Q5TNKT}R@F !X!zsE'}T5 MvL"x'H #tLݐI!A=j#ԃ  30*cG/3Vg}xcB6%ꍑke!N#m_Αt-efnN曺djZ) ,=Eoiw,ZV3P06xa>xW\;Y:$9?F .}ptɢT;S2z'6&Vo0J~7pr4 "-YtCRbm% D>7T~ z ɇ;r~ybv#p  Ja< 6qf,>8( = "kEt+"B}iũ1a{j D,_䘦xt<}~\sy,?|UmѺaCchr|*0$r 5$NZ sA Ɉ@8Vma•+'AMJ!MZZ][N7(Wj%&GkSdNlB} cZzIM&"RZK`v{PJ;_ՆvJz軡3oa -T6W덾L thy iޥ}\"d|kf>"ȥ.ڤ R!Peaw$U3>FG߱ Nѥ PGOlμ#qRvѪpWn|홚Ӗe+730y֕k+mjjL!D#ˇԖx%IHdiK4cʁO?CY)Ǣ_a]ǛSao*̎Yy0ְ_)GSn,cCU(2Ά$!.\)+kX &6s >c;Yޙsa!ԎŤ?Ws3o_$ey)IFaZkiyk/[ߖԹ^y!5cl(hH A_`uXSyxѦ&|{rfue4M%H'e1nXYa){IO_T5@#1q5s TqkbyWS)d -a!7%EJll63|_7 hƁw9 r]:8ehzQƀGE >Ș1MejPRC)ll!D\ -0Avun5qZCȺ|zUy&*8(lXU`Tоʋ*uOmNGc)&ųo=Y Cyi`6 S^6nP\\Wev\e_dh */s|Xvܢf8~\&K! NY`N0e|8cDeZV2M“3DًrA](D[}iNy<wjdCi|~{Qz, eEׄJNf_}y؜>j,;827J,֘9?.+͌P38\MF5 q{z#<MÃbJa*׳;F*z t{"y=9@}EZ|b4X+SڥmC-|Xs0_í}Εi/N( yToHj2} vzqQI=QJ H4bV1UkxW]ʮLJ >TϻX"rଉX@m3ރ&q]ˁWs.NotgY`k!X?﷩zu!/Y&%7:0w8DY]7^F;B<`*;Rsjj l~æCdR=N7m+]/>DmGlPIA-NSS$ _ű8VB'N4P&u!HkC֋rä^,שy^: uxN @?{*Ո:Yq$o/V.!x+>v=x٥JMBjV,}XI=bHu.{oZʫխ$7*6/.%o=i4iN[i=ǩTW e׍Vx17 _ /-r|85+TOjrYTU;=,~p7[̴Y5ġ>AyUQcڙs א &[ kyt_28>n#Z# |ǡn+Kt"AZ~RJv!1Yr):J8 %)(*A 2 *֍Hl__[*;ڮC Tm;kkQcVRv㲤cqeXkk#iqK SJ:sC7 =QuN$ lqw7z r$ 3 Q27'I]MB*rggI*zPR-1D hz:igo<4tTu/ZVևI?\jo`@SdKxH=[L6-+po bhSC" db𖕔L$ܰvQ,tPi bo(RA-`:MV-R-#أð{a8v^|-s_Akw]Xαa l4^m`Z9L\;0<,l䓱Y=yJtr!+MPtdC*ggW$BOj ouIo #o#zK㐟__!8LY(&giƲ<:ty-U.=Y xD?ma2Y`ױ/usf b+aHq68]9ZZd=\Mk wx^80-lؚa0bplGj*S3&!iB&Ai F{[8"V%} 4V!Ѧ~`M*UyP#Oz (Z͗=GȿWG!`*lյ]S8'8"0j \ZZ$4J{#Pqyohsݴ*}2:]-}RΟeJ|c\&[![JEe"W DX)oʸ+B*vr$Pӊ l@qHM󆤚b[}9=RζI\Kәg~`qA %8A"/iPJQ5dU%^`}nnEi\a#ڏ{W+|܃eQ1> Es#0-5M]176Ve\%&a'?+4d5Zz%}-:S$9=O8n9ͅC`p椴RPF g?^衅UQkx=0ga-F!Bu0Îͧك"F.ò/*?N^ܚ$)17܁7@˥"?}'o{'j'W =ˊ]UT[JʡحÂZw$;k$Avv:-ΈmJa\Z>ZY5IJw䰇״Ӎar払:oJH%l:!@+*>1[cu>Tso.޾X?UT<\^Wgk yiis}iDR}y{(,I­U~t4(!m׌~3Ac5U^[GBK%JZ8;bMo{vCKۈvȦŻ|I(!'5g%BS # +Kby?4vy鮘X_̖afR90׹; d#rG f*݋$M ]m|̠ppcƕkDbrh IUlvqG?2iU=>&UWaII6MVI;k>Sm dmM4$.R*8nDBc6C (鞾"@gpz,Mщǽx"P_8)_M4'u= rGJ *HΆ*RPq>) ]P]y^lg~B0$X$G'cpOv)GcXjv{b p(|FN\}Uݧ)<SYV*o+S^(Ng&c G?|CJP>upv^mg kq1d=Rח *Ċ4 Ř߶cO<=>^i +94b~#7>*9=۟q_㿲5\FqVrh>I+^yֹz+1yf;@2UĬd<- C/g4nӶ6Os||m]Ė' 6;<eX|VR `Ϩ¥A~eW$$A&_>TUKƅ)%h/Q[>u:(ѩU'= 9B:`m6#㗽qPXESR,7cx% hc<=c]6DgAՌxa/uBV]VΉDk`&\ @Ī->O,,.A&-òR?N+M\sd.!~&u0k4YuVT: ,v"ma% 29*?uR-5srk_0cNT%[f]G胱6h'y@JԅgHpS cԳa=?㤡5JӘ:>ؗ#$N7ꬨ{ -ZU8 QɢUYKmhcokGF> MYݗړt/r<\*n˷gw%.M?yO_ kcZPngQ'%VeMOM_83_y;-[ sh c2fFKZ+R*uյC%ߓy_4ULEN~6HC3K&7`ԠQ j4t &g66g`Cn\y9'Y"B)sSrJ%qao=׀s ں㎕տjS ŵC3i^o䫺nIAlVj׬h3Xx~ӈIMw1vQi|l5D715.l-B)-q"$6I?]kzz -7t */6pFiBcr|h^c^]HMK2Q~I)B=rn'/we*/뗳:=MSH.]bFxDA+&Ťo? P29[]0dgp:l`#;U8n1g Thہ[.EqpW0,ۑ9ť9eA>Q,#21W)ESTˊj MOOm| 1/?.kدJA2M a5H:Π.TR1m:/n_+Dbb+%jqӈ>'<&ce\?кط:@HI E[8g+?|e&~ U"y}pl^o7pD ֙rl mD$QClD]iO}+Y;"ď8Ɓ Ѯ8:ȐbV^d٪+ޛ\Zߌ5|J"qf~C7lq T1S J>h.)g3:#{@3yk0L^ 7>CSAܗ;dc`BZR' =|(ԅg3%K H( cs"h (}]ªiY3Vw.P5F*rz}6,#%P5o?˷>$]WHo*M93̔; x$NVҼL2壱c4ծ/Vj Kd׬% v-N c!%G\,ѫ +,sE%Bz'Vʼ. yY2L?&#[kUfU o”\]A:<=QbC5 d3Cu8[g|P]*V8[ !f+Qg4FN Wa<}&bX͜Mnqk&Cڦv -&MFc >sy`HRxObpzf'>25G43C٢8yxم8w HVȐ+ၢWnL2;WHG >w0^Xq !\EIj0˷[MP޹JGFB]O'.ͨ"l樓^qD4z!~+m9)Az`F۩1"'I^Rip6qVjJ|F'+ܩ[-9|k Ab-Mx %Dk%U(jZӳWܟC׵#N$"QkKe wgA 7oÉC@.-| "`E4w;h9 F4hЏ î_|)P~'B6ak k]ŠZ qډ_27pvĔwx^Lp"x'nZѝ4:-'̅]iɑ+GɝJ|kO!*l%$A&?'N_)bޮ"[ھf`B(ػu20S CGpA3k®?vCDy ݰ*2E,a_|Y@UL"ZO=pBn,* 3 Do#Cw5Q#վQ`$@Wp|!ƶd+[#OHcs)'?gogXr kj%x9din 0Ѓ8Wjќ T? ѓgC*&vG(wq4ƞ3L#ҸWͷ55࿪`gU (G -֗l"QfVv<,WJ?.8$&⒖ 2ZIz+`5PάBV5h}9 aX7Ҝ$N>Tljx̕,]BS+0WA~w܇ i+>L 'ۈk#fCOp \ĹN3!Oqs[ĉ2]SieYgц{Cy\tBY CǠ2wN W@Rg>k;J -0&m( %ރg"ȿ3ud6vVxC 2 4,;@)iL/:|h}iFjDԕVrcU1 h5޹k]| $ ҾOsk&8s\6] \>?uyB"7> XįP \.ۖD:v_j2t,]qĭkpP?-55*Vz^AV{`q;解,EdL3>G-YQCO )3-I]lཔE<(xJ[jߌSV߮pMUF[bDwW)A96Az2'zu՛bi nҔ@o`yڗ*e \/7D]VşT\Q(mT2ٽ].#v|%7 ;.lRǴM%Gt'Kꂒ:e#"$wzTӤk}`OrC/_- _cZ0cۺ;ݺt^Fd%ڂׁ|ܗ؜y6TVzhvZp?qцUٍ&NqAZUe6,W#9U[ZuFze7#O: njAZP 9OY)jAO\s~ZDM4K5Ԝ;+8ʼnzz8DKGD~4=/ ȵjfS'Ǔ20w{\70-S)\t񮥵Ub ƶ6t7˞#qQ+,[B(R6<,G84R C}x""B -հ%q켟9ZPlUŨESvD=*L|wߥ79AJ6cLDqGLu?WA: ľE-7ѣd3WE%NդWoyNE*dq㖘icʗfࣴ(i8 ?ܳ0&&74y sgÈ*߮VPB @ƔjǍcs_Zhƥti  s|9zwIsLJ:B*ύ'oUlt,$~wofVYoҐ_W0c>p%FTTtrAKpk0DŚ-1I(lL}Ꚋ`CbO-;[+K9Li-= ?n&*(IiS6FsGS*.:p* 30qI:w)[k۴ !E OIg^R #vs}\6=w})aW?p={TPc ]}KwB?Fz۵"O801#ў %$+:dCJ PVGu3=Jt,v \T]B*?EaET), hƝ)h< m 966gs$f&y{G"#$/);g*u^HEg`;êscѨ\9tb+?8߈邧,ۯs2K8]OZ%Í JijS-` #Qˆa)ɑ]}bE7fS_qNCo bP#%^#rfེWwu[}kS8bg>zc"[Z!_z!r /rkpxl%FGd!9{oי6tcU\ʖF3!L*MI y3 #$2fJ4*[-Tj>0Eb: ^Bv\ (' lD~)ȶd>ݚesܹJUZ@v\Pp^=_ۣ_[#QʽtߣSJ"ܽ%1F4VbaqZ8A bW ]p fP zP/Ϊ[f"Xxo/͑Ř,ƞu}GMzi0vH/ldqʈqhYB2RuaZQ*^|ĶDargOʌmP~Qq3ZFe Lg`dfώp`>0XG|Vx^\*w1Rb U1U^LIla!X)=b̋Rlr, =jS$I&+S*⤳ܕK/u SmBwp^hgfQW߂hrXLGጊZyS'.Rk &dN=Lq^'R@ԗVHk5i2 7" a}.N*u&eUBk،Єb&%zWނ ,{bR]XoX:v$E3]LSi|<^J9 vܮ~$],,ݕtIm#yϛ{v_n84gkﳋ;{M:->қMx ;8E]f%/Ս/S{?H9 t \!4' fN{5$qtqHh]Q_ȃ ̂4`<ベ;Y8Cqa6⻰ϥ=6iN T  .bheJ|)H$$`gzyG}GX\",aB(0x1W7I_X9Q + 4?h•'hOsP 1!4݋SV.zIVl=K4v֚I3niIr6">Kyw/,?ACKoĝV_siҊ`̮!g>H/.|I)( :osEZV mݪ~mYT\ ib ^oN&k4n`LydWx89y5B=RؔX4 p]Lx~5){"$)V劐J+:RI xv +[LA xYA+3FMV=`e|Z|#(e@vEtY;6j 9TߎyZHߺX~ϥBcڌGF66t(<,Wjm{ʨU6MM=C˧Ǥ'X>:oi|dBnS Jh4!e>bGlʫ Z&`RV+siZ`ԜP2QB6bP%v]wB따ZbI |dt6QVCF:)E,td, 0?hR< &5PH|Ig\Xյ@Q,o^캫&5 icՅeyxEUa\0KO&9^혶.AZ}7e [p)Uqhq?/Sz,`B^msI0yyHU nm~ D-ܻ2PkPp;~mЮԠKKUržFQڄ`UQ"ziYU6 a# FnZ|;ZFq'L/P2kW ;]`d)k L#CRn|l0|",6o>.w0̑Լ!RZaoww/eP\ULiXϻN]7pNo*.x10a\n+:؃ha@y=uG )IJ% 6f34%dĽҲ}pXF$r쀬$!o4ә12ŝBr,e~4֏o*qZTHCM7"r,T-ec!Ur-NS}&:_w%[`Z< 8L"ŰnAíX3V5i, QVI-|TLcf'0IohH+S}y.iƒ;jrUv9 KJw&.!;LiՔLO:CPO}bV#-{7w %grO s)lB|i0ZJEZ]q%g!l)!\Iv3.q"\Z,x'0[H ) B/& 9P?$:ڴ~R^;ztx &C(k=ʆpߠaPۅtgBy)AkHp/|wH \K>1*)NB.JS$Mx|O䈯R#($Y0qZiws BAU㵁 gNgpm6p}]UNw uxU-XFz]آ24uq<]Sp|MRgnܒ-a ?s !uӱEvVǑImB;:⸷@V4({`;Fސ.sWOaGQkK"k)d?pd>A߹U {9?.=eT*17U0\Yn0SIۺ%aJt1z# Ho y GMvRhE~i%#U0V qN{q,MTc~}B ޠg .Y|V8`p'Hc=T>L*!~a6~)kа񔨆ŲTzH{Ucݻvsn\45HUrK9l0T/ mM/X$=LHXD2ѳy|u.o^H+rhALZ8"!ZTf+)(s}UCɎLAn&֌P"@Qz׮,\ >?cM#̣e0 a7}$tưi\ HNKU:Ul!W؜-,j)\ԘS[-H<~-jX s%p*%p< )-|.'q7 0jz4O>MmquAR`uLؠ@X٥ΩDOSTn2WTSv`1M;ZT/R!qU{ IT.j:]`pmWzDU*$=3LfW YC8yn9k))UH\f\d^~;88uW(jNhlVnblkL dSÚpѴin"$\{!W`ɬHʟ5e+-A{YeYy襓_:KEwN5VkfA)}:n(p;13pr 4^~^u>~7SmSIۢ_]U<NGL>5.MS2FhZ.i售,ܵPj&{G57n 8 2^7:/ēV0̼ a/-/hS!ؓ?m}dł^a;O ռ5%+&{BGz% w4wA[xBU}QED4_)`l.[7Í.ou7~3\Hzwg~J = &- U%t`iƐOfvP1lp}Xdʤz2Ԥ_] p`))+o'cedc X*JM6{*6P#cuӜ̝Vz=N3Y{PJL$F+!+V9yәjhݝʄ9) Z-}&Z{LBZtgN^>O-Q`EӞ)z I%1+ iM%F-k-vcj\k֙k6ВީP!T~._/#EsR[sED,7G.ݞɮ5(0Z gg|ve ^OQd *}6y|3,a=BJ[-LK/M`w/|Ǭ6G(dR5IhПr|}/.T{M w)nV5T/]DfSmh;o)zT /XqR$Ozz-~]׆Az\E}VAPaMaGY䢸N0%GD2Uq_>$ .}2b2h~)PGQ`(Pb Jc"*hzyO])@c儝R;D RT2ARthH `Pv}Ci( ȋ@[f2Gg)&vھ>8A| P>7YV[?Ԧ8W(wΛ]=!h"t.c> L"ζ=),sSp@cn&_$rRSq]TXR^7{|]jtȌNfO+%F# m߆l 3?)ZZW 7 -]S<ȱ.5a斾h@j%Bm4<M%UmJɦބL&|3tרs%h>iғ,/\y0%]|I0k3P,_)`uJ=6ͼ q>lEVe#tfnV,DPt-HΫ8\x3i9@)Tl@3؛pՆX' xi|J!DM&ӽ+Bz*G pc'q/WLxU杕fyRRTi6B:5ן*/ʦ

CN}i.(?%̗4@|PMq-H%m˽75 5/gk ' y)G`c^op1BEU) f+󃛸Q8tF_CxC ,+l(|i}h?Z$U`7CJK $ANDhk4 a֎. Ή>o 9@OM{OZc)P[ş(mOdz;ρi<^ C1vZ@i|'f w15t*YEOQ4F}ynۥP#Wl>[A|?!߸#;ᗡ^&W1~9 %ܿ'-o|i2{AfآBi΀+[=z cE )$GY5ќՉRj$"+$Q53dPlא>d^#q#Dg->nf{CBZK+PEW+^>CgM3ܵEEpR|?8ȜU)OKEn]췝zњG5n:wM:HcM+.d6how,2KX]yzJ.Eđ]\O1v)X228DM75~)BgQ\?_mKj !:s5[pfjUMN_=7g08Wpr.} mNMhxKu# 'P~cUY-g"`DؿUcW{¬5K5l)*z][olKB}jT/9WI?<ԣfD21&f4YW96 wO%g_oOZ-c_'۳9{zX&Jf:{O w1t(]@ NEe 6,PmݖįTiSneڠEtN );ti߾~ UWuk{'8?3R;XS̋<5#+RϸU:wǪ|$E:3r, Ui.ޔ_Я<|a5KYL,wjWԛ?Gj+p9(T_Dd$z="/A0i:ܬXrT7lC<Ά}%nEm(M1i]hQT5[JCʯoWWd&KtUpo<A f LWtwԂ$5_N-Y\ǃUn mh)[,ll8oO]%gLa%"fAuM-Mg~Ō`*xz͍.1L$ W֯QLﰇU*Iz9ʖ/v.B7|fOf~ୈGx`cѤf3` +[P%c9aa>uA#l}^B$9chۉo/%iB@hA_JҚ 0*0Z#Q(q!rxC+4Dވ3~aָ<e0'(z1 'PzDsψ|{/o#OS z^e|aJdm[gu{rfi Xs @WV(i !kěw`2rtiu[v&sߌ^e`~YۨŖl$1w!nͣzדE̫hؗ IvAQit =!E!!B^&xY6lxCG3mG90$Tn.kekWn#L.I w3wI2P\4di:*Vh`ϒVBmj 7Hc9TLcC--JlWkeA'2`3"ٜ~KNYGV(֜.}xSEC+1pಡ ~z`\&HPѺ5`+qtZK0}gЫw?!/muj7 qnx"~!Z!=kXxsK{dݞF_Z\TtML=3BO@M[5 6 nVVuQ4ժ;{mc.ce!*'7u0"ufŘR-] ߁]=@kf~fʾ!Ӝe P2t/vW.R3å|X:cpFseT-_Gqwh_6sT+ȿ 4^~TC+LS. R{p8^5 YȒ&e2|ђ@H[h k<,0p\A>l>Qc" gxNՔ6!i(0Ae]Ds,{mj>S]L=[׽q 2`{wTC9+MinzOȘd5Md3e;`ʎƩ|kyNP/!4~+ ;Bsb.a1"|4s8jT۟9/R I "/) Ѱh1:.3Wu-mDmm,&3 J_XHD͒vuN6\{37}M'_EJ#/@{[vϯwCaXnN`ˋqX^R+Y>\:2:d!}iDz=\.;^qp9bh2٨#aŔm9 D0=1'Rn:p{we'l}l`c!/+nvp\>!ad/)}MtDX&J#gOmҝ RMsSucNPg47Zo rܣL_q˯2(<1KbmY;B= ;۷ɿQ@`\SRkObnzqIH0ζV_g 4) td'JAAHc>Q:(Xu/7W]E#e;$:.pv/}Ksw^\p?Fva>jh[ H@^Q\0oҷ5V(kJaQ#2%gek$3@?x>꡺䡫i ]-$?H3stUV&/23q rI@-`9-b3<,w'Kq=!P:`H9c@:&ŅiWꌳ~^mz:Sш Nv$\g)OO[mWP֟ʑ"om{KR5TEN:χh-Y=`BatYpXE޽LvCsZApkWO (JQ(Gl7~I mjsP8ym4 djLAfAx X/2ꤷR9)N4x֋Q=%U307_;#X63`/+gŻ䢶Ziʗ8M_q[KײO,'Xƒb0G!egKm?\x8<#u+tF v"@5bG KiSh$$0igjec6EMqwr5ëM#q ⽽leڴtqMFԷL"sku$ :OPs]-+h >גB׉DJQaɤ7L{bqU Y7MtLq^!,ֆ{= p398d%2Fԟ qk&s2Q-إ')N#GQ7fZnE׸,KבWF~ƹ^?ajKW[ )&6≊Mt!O+8; 2C[[`Y?4_Ѯ<V Jz`0XYoxcӂҕ}"9Ʃ":(sogD009+=U %ϒ-gwt!Q9N=Ĵc,d~EʟWmo6$`Z-tT i2Bjf zч:W:nvASJgx;ruf3pPlr!JT*3ikDpVNu5{zbbI!g zɍ8N7AI\Q#̨ @+9%Vm}iiWWt|cy=k9Qr8ffn5 %MY(WM[G3hB,(S@lԡtڹgW!s ̊V'%qM3,5$MG"5kS9I,ăWk)Yo}v}"]u]QI+/S]kW@TB =Oe5@b lBS0h@M9/vyM.]eQ  +ݸ~ɻa INPz,G@Ʒ`Wwt$EOGfA7$m:@q,& ƭG2覅.[[7l {M/f}ɧ$0"aƍM>@ܤ~vf aQ=MЮ8֙U:@!ХkD_1 02iiqy̶fAv\; !R#gk{yss u'K˜dt> 1)DeHN=@8ޱ{rBX2NށX*S)?YU%$~VX}*hLw/鵇M&D\T= QhXZk> XSh[˹sۗVXV\sC3h2g+>_,5!WO5Ʒ6%<΢ij jt2K!ose ؼ<&TKR%9e6wآ7jZc j}"&ONz)g@% 4T@|(KB8%»~RmVq(q28svu`@~&-12j;Iuظ痳hg1V)EHŷ8Ab/NAXL߇] Y:^)Y3Li-jkPA2sS؞ EV(m~0l6 7yJYolĕ:PHD-jk 1 zD'Q|=< !8g]o*L0],0}I8V3`p%qK=#vOѦdJ&#}]51?7G1Q\@~Z2?5wA3Cqٴ? D퓅 ;1L}qaQd 2b4^ O.nI\L 9a$BWܝ%ԋ+0B܍P2ϯהVkIu0HQBd6j=T2OޑSH!*2iPluIKa" 1N 1b:\y$P%0U~DƵew8P83 RjKwv xՎtƏGDg כB,Go[!fq)F +m_<2[M|=qPfW&?.aJ [Zs /N*^K_ ؜Q2qxAX_2Ya7TXQ}Nn VkS:ݭ) 7A.Hk5Y!2շG#(vȂgMn?P֗}j-as7R=RB;iQrIL3¨Sy::Dpbofᣩ|Vp?npt 48q2 v€#Au}gpGRth`fAK2VKwM.t.^٥p/#I/2,%mˏ9#wA5w͜N2hHE(8| hdN>ES3z4Ve-iݑnկhcmnÓnpˏ5 ^WjUs``g;Ɔj308A[# !G\{C*Phuy}Fű ;;xKgȠ\Ќ/N)tƫ懫?ɲ0[lD\0&VGM$-$?K1 ۻ.(jcL$Z:m,ڱ[#e?y=n @Sc^v2OathxmskTF_WTM%sώ!QdX WR[Ih-FM] Hw1:jW)H^iy&.[K?D-̇xч)  {TҌψʊ$BP=󏒧uL8j"ߠBSӟ]_i4H-ĔEi1a3" ˕Rrܖ-m6@s;P]eNd&yY6w|Ώ(Q<v0P%JV$qqǩצX!{1͗B$ t\DŽieXf#6}7%_<e ҰVV;fh$g,uućGYĔ둨6N۽^ShVj4oNEGX)+1Mx.;:TK^U2HkZ\TB8ܴ zkUcFV#:$Ti&gpayLO^M'ަL>^A #*(CYs-sݑǘCj:H%Zvoi[_Q 7-s3㎖/O7Y`IṘ>̾?>wzAq,`ݥvY1OIK$+jث=q˿nfki9!o!"wXс ߠƞC!"` |1_Fi~@VJI"@TDՄI[SF U:EgZhES!toE]y#ZͨՕ6I+ Je98M^RCfn{q* `QE~߼٨`_U\>8w&m)V kn~jˀ`ӣ?_z5e݁sVE1Q>{Ϗx)7Qa ÌZɫ8^`2ѸEޣl3ܜlx?{8&g_FL]FðdBC-F5;; -+ēŸ`vtT/znHbkؠ(  E Qe @>!/N$L\L܏(SNhSyraSDrdMü,̻h[ 4.6ĬH%_Qr·a%Gh::6ZN!zC~-[]:~Wtl3\'̍x K-LOD h!x;Wk^qd6`ѯ:UWφa;~e=aAvRSm)w`w+E(+N zdI7LB`hz?`#| HF,\JL*tO_V錇JR |cXr3s#CXMbtgAbckz ؾHrb|{CGwZO?-^gAivC0Btvj 9YC|x>/Qa'J'c0]]P/I ?Uj׻[qg^%= Us6bl8犫)]><>gGạ̊X\9PC? @ۥ: 59n~kXgx}h8iS8Ʋ7m0:gֻصff"zyٌ?ֆib^nGVh,&AW m 4{yJxxGK^Rl=Ws71 ^Nw.!R|@BaB81mV*la#@`Qa3OSJX4ImnuR\ubfnkr)0 =G:QHW'9k`e喙d+MRQfn r.i"I=c4 y\RBJM.[71#^M#P)qpLNSyNYY9:9-l )eaݳ\!?y0\K VSjf,V[Cgʕb!6!isvٌ=Ѽډyykw |E#.Fn>E=7 OM[_LrT9%H ! mR#"Pj[anۊs3UEO>6;?ilحjI  KfkXw:wу$8)3}7K8)c@EQ.Rش [q2ҷcu,̩lZv $3 uFͶLQL/Ka7L|eK, E6L3@/@&~Cv ~naNU,$=- u WHp#b]^Qy,)qX&9j 䈜PE+ﱮ{ b 6ߚv"XFEzWդ] 9.< %9ǽcFiTz遢.xm ? jt#G5|3w-mpPc$ YW|+p3Jux:qԮ` (M]_8#8Zm*dXKDY䡐4r[ 5!N!7>N֓TEL%&vrcSǁֶpI~"^qC^!qB֥'2Tk|ñiqRNafP{'-[b$_?h;lAXd[Ix|+·a]v*^;y,$9V_+Д35uZ\q` .9u%C2Aw| VXa+l^_2[Lm2wsa?~"&|WuGKR?V=7rpdb XY:7Q? H-D^>Rܹ5윷 &VZ"`౔:ޤeҞ@qkոֈwlzt:OlG3k*\3 q&&QǷi(\(Dn%8zȊ "2&9EQML44 j> (ئp9\0zp7kd2B.O_,cԭ%i  )mOM-ew c풛jcyf:s0>m1 ̵co)ap,; eyp Ee*vc9a7H" !;/FSsfDzs;[^F?" Bb!sO=u*u9.%C-[QT8YK R}le˨YI'68ys}Օ@߉d*YkF6ִFv [5ԑ;=quci{G'S\%WyMrځƚLe+/ᩲ/ȸ+R~Qx7wo~z!CS0PfL&/oDnYO+; H-w]< {{UX$Y?6|Mn}rS΂h;Z8n1^1x"o՜Dk-fpM%F q8R5\@ "vPoJ|pJ%xbo1A1hVB%6&Sblj[9BZP_T!2I}"q6m.0ns좂󾥒+ǀ䑘;]Rt-V)–B$֊6=%nӊ7}Ķ4@nPc*:YӾRaOHb`JzM3`>2k#=1?TjsVVV q|dpw  OjsanÑOaE\Myj7 > o3-r.qkk^3q82)6շUn\?}s8>+x ny @n)0BV*70Z%j5p+(:el$ 0̾V`νbX8YX[@_ ^ͯG,ZM?$G$;ƾ 0Q|O6Xr<_$B'*DUK Zc#4BFͪr^C(;l,W*τp`4fjwFk!x *DJ}UzBcFx8Ej 2#gvLe ww^u07rިr&f*}[er| iuסG0 xBљÇ G:}°VHl9_4 #{`A[~V:*Ә4h-G6aCÝ B*n T?l'3 dB࠴Zrح2\npjhϷ`~| Mtv ^sk;j u$2 "~IXYsNn\2*=]| uB+|ҰJrğ<$ "nCFtF]^…YZ!tyC;z}UDJD_=;M{L{|@i幨1|?;w-}HˑbPH5_B+j xo?BsۖVAjJg_ͲۀTU[^U]U^~?K:'aF0eRR'HB9j~'?P/D硫b/"Lss"oDРK 1^VGIO)u[-Xpd"Yrc+ ΘԋoL쩧ʸ@޿-.~-$&KRT",_ǫXo7na26njdeyoEП (_:tk? ie%sTakDܿaJQЏ$z!Kv O} ]ߠ@4ya5UXoJ U23X&;CCg. t@ҝwLNlÅJTM5q!y{'$>XdĠ@Kpp! C|yJ.?Xp+1Ćp>oD!n8;b 5ځ{#Z_Ba{V{sKNxcjweDgD>pvE'u.%;k #;k*x 吶Nط9jY$(\w/5bԚ?LN/u<_#, aV=5򵳩AO2P%FzIL력ր͗- }5@x5x_TSpL+T&L#Q'P Uxf]d5ƈ )UO5b;t?S~*_)&@r 34&N*8Vffy.OJg<ж./SE!QUgsF+dRFr;IND-{шLWƧe5͎}L0ȏSZ݄aFQ5ek*T/?#C^ǭכQ.P5*iW֣HCSSD">q"^o{Fĸ{zXۜuPvK& ^Zoq bݷmC0hg΍g_Qn-"K 5KiU. Q̼J%*TTիXzA&nOxѿV5{\7I{c#l}o{ LɊؕ\hSG`c+WoyVfdshv6zIVX Ҝ7@'0;v՘x%u/'>(wHhdkj 2BN|fh4RxaKB^T<2H\[GuxAÛc%Utھ_sy /6\gpw+%rc0)Ooƴހ|B![lz^ZN~qy߰y,K*[4֕e_Wglu?mPh{fSr'%lY`YZl?2-}K}mXA&Ix׳J^apQ#eYƕآbFM9KCKr8[,mP6pFmT oQ+/3Z7!j|r?fnd1Dyl1u 3mbee[ ˭.:lA51l\x5LԔaJzG= u>sdJN`2'X{oHmIЧWbܾŢ| G\<2V )aq L[l iegpxtuJ(SJUwLGjq\رx3 br j45AE6[YpcԻƞlԃ! 4L ܏uiK?gis#N4f}Gb>2Ⱥ+* T Ad+Q&_quX>7,NRɟ|ߗ%*deDݢ~z[٫)5uYgBm:f]evQͨ%DN҇|wrew=k^5iTQ!Q<+jsy_߉^¼~]\ xcgȎ_Zn007r }܁Rn'U\blJw6Y#xu>,U;u8hͲ7")CdnG18N=uk<9M;¸,lCaxi-V,byƃ+]Z7p9K_6Zl' &l_F <5y <[E&|Sz11;[8nXY3`W.[8af"#M|{>@n&ULI;0'@P(U. YJ; `'(?"Y~ a&J+OB<8dS1[X2Ǯ 8?ْm,u.=ӆ5d1`~T(#?k҅S zrIn|mvW% >9J.08U'bos ۘ<Lc>]P`AJ x[F)eJӁUK/alWeͰpf},c2밲s* ŃF"|5ġ @9Rn4EZfW+PXuҴh] D)o*"ԻyGQ&Ģs:Y--X$fꆦ4>9θ|FsԳ o5:DTSt54y?)$Duξ8_'km`CƝiN\Inw5#Fm#IHS.f0q ad: P&~~u&<ƪ d)@50'Oe h 4θF:'j]R`GO"Kx-z.M\"!vss\cMe l=ıҿ` El5P. );d6y&"y ~ci$[ 1IFܰqD'rX>p} Y'+tÍH:- FoNx[[;hPxX{7IuuEZڊwrAYSEEP*B$T'xTgvZ*3:G1\Jw?4)!2¬4B q6O`gEQȽ澆%OhbJշp9{@΃L6YC>`٤>Tq3M<#cT ٦Ryr nW(z1=ʄd†F8_гm~? S5hIk*gw.FnDSHXfce5'-]悡BOt\H>i ƒ-qVО3r2$@rWQetrS \0Qo1h*"6||p?#2]9T4\MW!X {NFD{_vPC`sU&$SZѳ|=afFT0&%`a $5AfS1bk̔|^8I h cDdre>BARʹ⥥_JaCYS{FWtn"LNA'\Iq&`FKTu m`۶v{҆#B~S_ӕ_~i[s4fT" v٢*mfU ro bJWI:qESϟ̵gCϏ+Oe:st%WL^LMWp!+=x9@1Ե0vMWpw@GEk$Ix~< z:YKf]3S>3?\YU˻N{-朧O:Ey%%ۼM'_H#v{;ЖA3fLU^F{&-Oݴ]ё _knKΠ@':g@{mp h\C1Y+p)>{o_尬 a$p#Vj5͓"dqrT ­ul.20Mʱyzh;4gmƫ޲u,MOC> au`'<38C_lZԶj(a}'Iğ *%jOe/(4ʠC |1> MT+\;!{(pTw uX],#G,`arö뀿:BwV)>2ȎDElFS5f9^Tj:uTbm֪ jlKis{^_5gW Z߭NcoS^I|rubgaR/9\p5(kع}hAf6& >al_^5Ln QLAr}ʳ\~y~$*6Q@5d A&{LSQOgYmٓ'zl o| FɻRAbBy#mL-+#'RΤ]͆"߂CNXaT"+D zpӐwм'{*)Q;Em:uB)_{ z)B lNXtF mHaCar.%:̸Zȯ)(JkMXu oióI+iQJs=uUwވYTgh@  LM T媀Btp%o|fܜ/qPҖB=#OZW O3ѡֹ%d RtNk LPUɼ&B>U+Qɉ=/h7ļ֮+hyWVT<ܕ<2FՁ)bS:dܸhHFN4Ui2%jQg:WrQuE^kO=0qsT-$5Mľŋq/ڳ9܊-oX0 MM46=OsD]|cɨzRS5d>10GZ<ɹ4A\˾'0TF󅦉^?"m J1yF,20\vtF0S-\KϰDHI.'4|̺rf=ܛy|}k^ģEogq@b|zǡVɩS͍a>B:?al861Ցwsl6ͷ*N׻QG4=0Ӹ0ϣO){ڿr'Yc!#/2lP D9X#E?>U\A_ir>{ (AUp|rMrnRI6Y3վA1xNNՏVH kKʳYuU*O.X6?^qĵU^p hBicK{5'u6pB~^~Éxd%cCKxbwW6X۲zpöu%9>,mzG_x+Txk;a |ëlr^Eum[e+IaZ4,MG[$uRhUuza8 'Ug- Bk!Z6]>s*2MrpysQJe͵kHO-2HDx- R(zMRۼKr'bDNDE\kq iTv bQ2B\Z,t̯ xnA"S}Ş;Kgt/Lgi&m3WE_ );QAs Wlni0x+,گc>;N ;|2EZQHnI(mGց|'8R=\7 ;dҘuH_FL3ov&}l|tWϝ$UQ ͓&(+s#%E_B=ZWBnpoUYi/N| <'Nd[trL&v({2x2цҲhO&~=Ӡ9DFס; n07Es; pv&>w+i;[%G f.K'=ZS.&٠T8jeJHNn 6Ys0i_^@I/fd /nuܓ4ZyM'`x wjňjo9ԓ j$K5i6AiCҴ4zrD}mlA#2sNG8H1QyQuM\V -w( sr_K[Hc*#yAR Ѫ% vJQv&ZřaG3Ҋ=>|YZ tL3]K oBj8o8@WA y5>OG[4Hm!#a.suQoOsom I|pr(rF䌆.]̠Ѹi B0@,\upPNpKcCf$2(Hcx7*}v4y*~&>+xoBF#wA(5:BSi+Ŋk[';j[w9}}m4tt/ Ό^EbA6nzg^ԁU,s BR`&z&]JmPtif@sH HǪh(1L8% L?ơϖyrvcWNPC ڋbn^_HI:^=ŁbUp.>)Aqx, 0gݔ̭_>8Wiy us;zn@V_&Z^ww. W#", (ćp0 kaA{x>}Vᑛg0q dgtrKw@#MRς{4ZFpb]&0ΠؿLIܝ %. 67XHau|]с3.9`M_f]Vd^ z(3WmfO c/c{Jٓ)>AeV,`(YҍN\>v>Yh.W#tZs1ZnƙBXަy7 ʎqTn'Nv 4[n%2{ͤ_L LsARLMlI\ ,.4iM(zˣFdS9]v /`9SqK5vn붐qxiAj/q;g_#Z O_dfbM\&Jrw68Q|@ X9girʚaq+p,ґI)1Cg)*ғұWF{sJ/ұ ]Dތ#G&މ< gW!)_zIE#P!6@==2LBDN;gt/!J<ƫy'ikc].~[|deRW[Wx%"hɮ1HH qK"ϣE˓?p>m0w.V$2)(E.SK,7mb8> ϢưǼ_`EE\N*5 ɾ/#TYd%iH_K@ +KkiToB!mnQuaX+J#8 J "|9 Ip=܊1)Jvau#5׎ b!_,*a)eQ߰q81=zNXՈUrLv-;сEiB8/a_H$)V*F4XǃV)xߖ!#udFHI9Ji$3K@L=N<ӫ{ Ŝ w|o\h$\IRdݲ@ڙ|o Ӷ2mw3s 遴m~,k%i""yeH\S&0*$vUBu*t N"[ ŃߨY6I88N=9Ltxw%jm E2'HhbC !D5;t)PiNqmvir ŪCbNci^c( CxA#M`A",#K\0]]! Zopi C{PS pFYʒF.嗮06wp yFi p~oŤm gJd˭MbC+Twǚ`o$؍G~GFZغ4@ru[xEoj$KbLx^$Aࣘ( [)oB @TA[ ʀ`&<=N[j&(S& 6LqLƋZ_<ѼmEgb=rXuC~ڙ@ENMEM4kH]B?`Ůc%GISs1[YMr}nEtCBkǪF-Χe"u)r k rh\LiHŖҽw D[aΣLB4Y]t7Μ<S[ٱYG8"`A4`: %'r)Egh%qQ*['ןzw6B 떆 AoST8XQZ%Nӳ5::w"C]0wƐnؿ <_:r.pbńt#lZzeL[Mzv7^`! Iutf3.HD_ 9=TnWWɬǚtulE~?˳W6N*O 97C^ud%-߫!.yg*F2C݌_`zl1}ݦGvAbE ?33Dee1) i SsɻKd,{0oOR ķ%й$]G'"_Xq ^ {<3`EDǷp.E",`AG<@ӏ-6BYණUv=jR-&A' Q/+c4Lw98sO>XГ>Π~s1si#,+`ppv|DzX4D~re&lI=K#"C}sHP5S_* 8V({lȤ B1Sr ub%=+.'V-H$t"C7N?o'p{}'+ !v>]jG+0;-\DP"|UYQx="\ymk!"ϊj9}ZHdVkn<9@}׵sWg1?6PI/j AZ.mPNsEh{RC (,h2"BQ[Ȏ~DrEę/Oc@ϙ~w:OuDc]W֦G/FIw^cbor[ *qF61hn9ɣh3\`KƪeUgACdH38exwym:LJ 8hXݕ2[)7}O<ɬΙcTpv,> ?SoNm4uya[\̳ўdCVgCjK^!]%ӫe^#]`wBc#G([6Yբ^ڊl=8Kz&O ߋK>~u+o]AMT=8eĢ *L J\B0Pќ[JyzzW O~q4%9Jt.7켙Qu$b)~p5h7#yaȃ2 5t?!ljV^|dw_4pŀqr:-e엗N!c$&MgЛX~qwTⲏ}gHs&8量Db.\hC`lx6hj֦flx>xP: `j~6CnĿE-azfGzf/2"l|4p3՗1&V*wPƯG{d~h!ͪ2A ŋfc+1}*;.9Gl(4nщC;~85LDtil+VR)yf莯/Ydgb2{(6Mnчbeȇ}G  7ؓN$Y@Yϒ‡Vq(ʪ ۰r)iDZzњEpo-2ZUBtR4{_%E'e-$ _avKb*GVPȖ]ѼXV0SKֺ`Cde3cpcAi1NY]L\睩L(C%0Uܦ65vRF3@R~V!*}ػn̫ p_8b_ic.Z#8Lt6""L>J]fRk=ZoD0a:eܮ 9Hk_ \Y5{*-_rui LMzدΦ4?#R&[ _S.|;F)Ѿ<'Aܼ&r/tHis͓#839@@"쐃aT􅅲iKJkcݽ!Urn ʪ]jQgo] +VN Ęaj$ڦrQ2/Y?È~PeXr#XzXz H$AO1EУ=˩b`?z HDGQ > zo8v{ x0UuDk}}o]jK7>]JB]ܪ} ny/r}%.w+دRsZj}w<ҍ f= f#:+ Z/ *ԕ:Ԙr n#DQuLuHR@Ʃuw &oPƪf@N;洟c4EVUlyseT('Bn3ϩI(Ad 8btrPkSL0+~n5sYx[o ᜤJgY<R am؈5,o`(^DӰEJ5d.3.b۠d->Au2+PgЄ8'xI`(#gr^JjL"|w ʡWnЏC b 'zY#da4.. m?NQj0\dcʼnG' xF*5~۽;d?:\Xͬx753 x";{Z;^QȇPvkU8Щ}7bxOY^,B+j/{jc35+\m~zt1'(uމok#: f4H3Kw 츲{!#?w4'mUuS:y4ȃz߲|ȇB-HL6\tW>ѕ Y7cTyA8×\_0on\PySChEIOyV\6#nƌ =Pwi6 ?4Pr";j8ȮA[ ɘjm l/e> 0~ $f64MؽZWA8wEX*2'ImoR)Lx&ӋW3gBrG "sI2+?ͧaj;]zۇQeׂXzn/=(<6^Bi `Odw>G2 h4pgBj]tG13u?2.7Fhc+P-/*=%Pjdn_B y&y՗(i#+EGlNb9qk}[!< WH2?^6`o;ZqU5Bғ)2CgYuZ.@k ̃+3!3> tnFl퐏y%.=:(61P:m^9,!x54y4&M)  [Q-o2g3oRF}3-UbmߐavsGr<$}}Õׇ'a3&.zzs6ױ31vRP6TKwq¦a̸27KM|ž'?sxƨʸfT#j>4/W1@bi#?8?n+a]r5eg /C#HC0)taβ Z>LLM36gc7l@qҙQHK8g4P= zdsWFETj\ilةr]l"*s;g#m2.b 1&"P9yoF FxhUvDVqRR2#*^-9JVd Dk}K\"9c0OIu5ˁ?p`Ğ,49Z^V Gxu$887 M`YVN GxsO5D'^xLf gZc|D6 [9G;JJ (tyFɦkفG"ԉuJ-ٙ=-%ފA=s9׾*}=.Bf~ i׸. Esi_j޻fNltm2L@<Ի3岑l̮ܾs7Sz~^`^Bڒ'kcolOJ`k*,)wjوLBqݺN[}HrL=/q3E,݂8 !E1s &9o5oD|F@N] It7e h{q*w28rZ n uO)3(i4"6ʂZ&cTu lgf0p 8v8.bXbpdu` L@9M{:zXɍHw U_Uݣ̎vBn/#Wz)1Fl\Dާ,գ!ՁP*DĘD9QBD4H-7\Ir}qYy\3<&<{νxM?-BȲba `p2BЫŲ O'?-wq;cWy(A$x g<o[p2 k!,3 Q-LG g ?LHNHqoqCdѷK&F?W1y ;w[5Uj2Jf%.vmqodH, 'u tO,@*oqNjr8M0-4fe44 1~'quŠB1i=*)Rtn"k94ξ%Y%p&J?EdXAhq2F>)N2 5F2 FɄg3p[PoQD_D@p!O%nXVrpAqskK gg}^&` ?SJkVQ"ZO ]a8+$Rb+:'gI+E+H2>QBZl[gLL p1r*[YqoHiXGn㈱y KZx]$f2l5-޷+͵̬u@Oho,qy-V\b>y8:pPC7m9vaj=+$ LX`؛PUN[U*LNC ӽ1RGJ~Dl+k@GWdԺ] s+m/ HO 8sv6I?ɈLzYt@HUcWn;䰿' sS iEҿ}Z+bpW>LM+LaA̰\^Zur_hRRc`}Qr´*%J܋΀JmjoN;*T8LA{zY^YxvˆZv9stY "p,^:hV)[GhTM*Đ!A˙aZAggtD"ؑmhoIMɠwE O2:,O$'B0-@#Fϑ]dU#k̏E-R92/)&Tw\e `#I36j.\$ 2S #J{پ,Rb扅P9,(lb-f%bQ6%d8S5S=xmTE[Z8_ KBƊcGʖʦWBVg ;3rRD25S$/s>!2" |Ώ,jbbJj ~O5y]r<rp8.>88=lzW:"޲ݟpPִ|E=jT?^"caV|lthk 3"Y6 #NW6'J)Xלa>;+phXM\;c7>ȑ+íFjW&~IE{;Wab,W IʥIg.o CՂG##Nm ޱ_se3y6ͲR $RVEVԐVTM4$βؙ~eʗ0]%@VXcB3vA@֖9j=*kfv4tzTχ) 6v n*8{d$)TH|hO܄0;1Dv5zwe𖅖qh˻8Ȓ*2;/ɡܵu RBN$(%mz.XXBD'!p>_ `šк}\PAaB:4DO;܎Qdt/Z(y~ZEvfZĀK4y‚,&$ -gFۿ"mAKMqw|JǑ}kR2a8\}f9saoHƓ[}rأ⏝߷{jF*g|m\ ˋ7%<=vB *`m_gZ~v_ A2.d]Me=}XZGRX$JHI6FHozg%ڠ#^Ix*/QhI*gl7 I&kZ(Jlq !$v&D:>=Tc^x-1+Ͱ!U_v_J!9 06aXIG/s((0hZ ˷1k2q_9^@H)AawW0$kƉ;/jA<ܩUNohRZ, ֺ;HrMMJz[`d/\_Q⺂|ACi,Dae78gx#R]8}F"VZv @=z[&uP[̌w{'&AZPa|t|5y9pM@7,mF.^e\"^W+TNσ`{'Lӆu0 /9w5C<~ m =j4k4~Fl!t .{=CnI?)A;a=K|D0 &,Ko cvAur`OEV'8oߔFŝM66kC#٤icĎfx} ȦMb:?RIw4 ͦ{G^\^S/@e#yE/34Y<6! wwKyhUs|xaktĉ?xYB4+&X5D63#_ԘH$ÕG:? F%iOp5Y 1)3i9Q͜Yj)vI8]Rt|5{RA$DE5հ͜qߏ⃦oNjx&Nvy5?pYDju|{3Cr*^sWryw&su7rpd}kHw@JD]{2Omlxex?Lbz=#\RuܿmSDc ChboHV{*}jvU9 ʘAT'OWjNkEs{h%8ɳ|fsm~V,qbwj!QH澕=,YVa^Z-]L_䝂']_"< {Ӯ̇p&1RqH5,Շ8arbEA/&{OpJ$R iv†:7Wg^s$;l?ߣ2_1 q@_{pӶ yFȭx蛂3yB0ܓyks(J=!_q!\,{B4Q_=D_x ]Qy#4VɨFVc$ U j/ixoz`XioN|WO_9Qy7U8#QcIf UOGB7dbYO3^ wٍv R6 bjԻ!E8ؖpsC{l&AGAbX0طl҇Ƽ hgR|;HkA[ɡULsyJ2@pX_zӢ.Dqz70^PRGn~.9B5lױ3 .4;{ҕHK58O7qͽI-Pfqz o;A):uVXǹ3-iwlf/71N5[l92>;9fL^4Q~iVcc\s蓿ԕw2%& f;ZŶF"2RD}z’C JQ'%] 7+T=s6dʠTvٶH-}0`?OowLծcVR`<xA,Oz^MK"FlU({΀l[#5ө$1Dv~¢&6PxdtpDD[bIpVU1OD1`$گ~i*{X]m ]5m5_!![G}au[>-|IMh7WA U#ʨrQAD tx[\~O^PF7M[Jׂ~g(~>8byh/Z-n(Ornw\&% *ՀŌ9R[TlJgh+#9hÕb2 GsoFFM\#ƿA-pN{63HZ}ݬ d@8],W(a,Q]|D^(SBęf<~jw- 4]はMrUAdxh]\ 2y`  7J2-YZbG@JYU<6^4p•jIoO&D EQӧCi `OzXrU\ ]Z?v,%LPlL6asE!n)jP`kÔ-EjayhX{<2b&m%nonuE:4O4T7T~{Gmn碻7CW5{A9t1fԄ1̑He@#&*bvۤ}iwQ똗lctOrR;͍t^䏱FۀKRG8Ǘt3823֩|V If薠,ڣH92b.:{Q"E$weocI C 5@ N0מc[Ga]"J`.bcJs#+/7pFЭce:\J ,K L6 *=-|J6/ܻL y!8%˸P]+#U\_;ꊛI|mtKor @U!Li,C|oDs7&Z( :rqFufPlK>G؆ԂDF1}jޛaڌjS%[.}:MOVE|`!ٰԷ" &R*ʕ>ԩqZ JԳ;ImN.8X^m-CI \SfNuzʊPN*=8]R* <.&[<-B\O4LEOWЙ^L ttEkY'O=#[.I]6|ߠT&x Q6ʼnօʓP9˻€۱<<9Y=zf FK"7"3#wFFtɄp_3tF#x]>[ӱӋe( ؽ)aTuG*GāqJ5:hmF. $zZhn/`aeSTdnX; qRUc<SuM,d6j^*/g8^sK݌K*u̬ ! i"3u˖mD=tK|W},JX} nKr0[ 5c#ƺS?*-0C C\j-:#;!ة =j=^>˔mH+ŒQN"`M[6[?e5a'"2&fM"?nIo?zۻ5+=?EU2! ))8sqwIlףUTK=|C.0h> &ģ;+h^"w?N{M?Mt:a#o?B|JilU0VhG'ىr~`lX*=q$i|Vn 0Lo-;$@S$i"1G$~UߵOb)(v,ASy&^o]-X :z3Sn( eK\֗'J9us)dhAxà؁!Rh*M-|!ر$'XDb c钘 R@$"$=mLCCy$v"-c*>$`!ղA'- C)^鋂f{1#5#Yj[?[dL|.-H\uY|ԞުNs$]jM, ~"MSdO)-EK H`&JU)Y5"%/ #H1HjQ'n|U6Τ.V4ZiGz-R )|p3 ܱLU0.79fct_;WvfI<-C̀#89*E3kτ$yrDby!>NwKH.|V(YQ3`~p4t4-ADr1_?:÷V Ee8p7ybE5 GR&:[\"'>9g)u*4}b_f BO(&VθhFy'iS()8`K0ob2[(n:c !ww}[] RHGu@j3\(5ae G.o6-?UC#4Ҳs6@;0p cR0XDA{;MDyύαxQ ?BDNY^:p[aQ;"urkH+3.&?yVk,`f>*!֞ձ?a%jPCģF}WTi`}Ͱqڰ>-c)dun#Le:ef Ha-V]^D `+xt]e8a[ؓ[F="yOoGJm4:Ր)[]9[.D!7+#@+藅VL7}Yq#DM <,%\3` ;+򁢵]'L˖{~U2̰pݚGWu tqNZkCSj M\xM}G[x.g5p$<ŗ ÄypwVNI1>xi]tt[n& TrS$[KtݥD%{LY^tzIEA4 \W#PQ;_BG ؒW˼*h_`yLF]OU1Jbx@ጄH92v;UZ#/ t˨P Z4YZTg]c^ #8A }Gf()bF9e8p<D% uA*mPPKA@LkA07Rltdٞ :X(1=SxJZ1+A(Y,BA|`#Zw-d?HW#AY.aR^?6hك-Qh?✧/H._ws  3 ;c@Ƴ8ʶF!ZDAJx2oҍ41M[gyqfk{,0w.*"0lUR&54P/l}T[njLS?798ިt\el}A6e9kv#;/7BB1MA h4łn/M.;\@>;t a{:Ē]e[Klsݡ"=z(xמ,)~R#ش+Z( @DڡJFNכ8  ЫO%s!$t+p5KelroƜsDkj%QQFJ'=nn@z7T'_n㑜!Kcywn*K_ fswI".2 ؼ, }\))^oסSGT˝xx ^4> "ҕ:oIYR=`X8L] 4M )r}ҋs)YH~Hl8_6wpR<:[W\K[E$ `XT2JQҕ[0-_ s gmO< B,turz5W KF Rr fgj!ƶ췟eÏT`:'_TP|j#ZR F|*j_b"/EMlȕt<,G羁!EZ;d \e0h;6cgYƹb~e&Ҹ;g)'#yA Ee_b?OFM-Xsk\3`εxg$M `/$c]]B!g*=ntRv{:ojRÚ 'a&@O"R<ϙg|??ʉ8#{ike3 Ns&<C.%ԺvHWfhXUJ t}v0jN/ǘ_<3aqzY~7vnq\I~]O3JD#{=BU0Ya2똊wUm>Qﰽr#L3gboPL,5@\H9:,(_y)G.{YrzLhɑ\7#*\2f3[=f aVmhZ<||LBe=PznS.L%' )xD]W_&,B$.@kM\M}m&E?-fxfU&gڱ0طʼż>ArŤ}"6} AO>,Ƞֶ@!jJwwϦ-3sLIuPr_WԀ;h5~ |}ғؒ#J WP4-zz5N`"~hc&p =9T&6:`:YZ6o#ݟZB>uJХ]5`HЛvUVY 8g stOI%Oė: 3)Y"WVIϹG[_bx"箫kw)[djH`;#gi\UMh:10V@;~vFF&[0=y|Ϟ2>Rx5+=5]tnyYVHgUa| ' mUkt0 RwΟB{QV]%%~|[+̻Uc*[tX*'ݝ$6EK"VHzRZϬзhڝ8yAL}g}S~ R8u,PMA F/zI/B8ؓXȵ zgqh!`Z&8)Xߝam$]XW#gW7&pǰxcN3JXďgx5=Vz.M x՜ְ ] \6dS0s($23LENKʺcx>NbٕGʏaF! :(T x#-)pQˢ#x:Nc]"i9^`>1MUOC'B7-_XsV7^k4h[35oFsr ߊTqfNâóC&dONߜ 'GG(>xq,4>`- +&Ȃz,<3 ,RUYj_|+`#D L 56 ĭM+DP=ʶp6MaNlAS^P̻W[JH`3$"j>L~`=Qƫ^N.ɿpc|* `#RdҭJ:̤1¥<ڗʷ&I ^#EztNEv\v\%}>|x~ T.)1M hx&P]ܢ$ 5( ʷF"-K]L/-Y/Kg)[kLn-KRh ׁBvo ?HY}+WYGj33|{5j%`t%knu;I ـO+ML=EY7f"<%5hP? t2CZe)+O>\+1fL%S[-t8g8 vATV0l5jyagd[4!}^>g^c7w$y=ooگl ;6f4CFdNc"ە4s۾(Q :?U>kC[GxcwaCwhϾ| Q@֧ *0*MTrC*³ֆ@ٻwJ# "c p;Efv cF Û>Rex7$ #W"SYUȥ< $K8^.r)\>s}l@G;8/BTdMhmSB^ʱ"v*UyqK|_LUߺ5_У3afj>=hh9hb .5#c wgYXӌ7r TIjTç+,pQ(WN>AI gb`n;}W:ն?l1ITuůY?N.-9ԝykeUDRtv@oWQ@!}D6^j8]e'RF򖘌:g9çWEveuwy[e=6{-<߻E-տy܃%$@>!HC摙1dz-T`X-;JHl+aPѲ7-"$(́|t8}s*&]☋~yƱc[YA&S5O:IMli%58"afc T=Pz'"ƻ'3zreoA ~jˁ=5uu JӚ?N8,s4cgrTL@ڳL!#|4`[n|hx bY+qYcamod=a0O@sُD<ƳsU^c==CHfmkzC.ݴGdZ';.BP3KGGlv/hVk6=J)`juV; mO66.ɸ*nӓr9}?`61bCHy A+V6DCAX{9*l7Ձcɭ2NAV)~B"L5Cٕ9`䈊iY&k\e<F7$MܷP<Imo 7O&3!+\#PdG? K{Zq(:$KA eYU[7/ 4u$5d72%k */z5CS@[C0Dj;36[ly>CTʵ=D=-g/DlpQ[ cyxh#.39_5,E[`_JnQtr[' v< ~WNDt\%wq-8X ;-^v=O4T_/eFnjŦY|QCLK`-tWfp>czQ\k~OؓĘ.'p˺ KSgT~@l aY`e 긅j|'3du: ے&u4P%YҘ3:=M"3&/]wɒ=6:X>_ysIBB3X jZBD5~!Vq<6vi*N $t *9Vbݝ hUc̻@s ?/xv:ޕgX 8I[|Pp%^JDdWiV)Ə*#T85k!M>v;/h5'5ӎ?pse r.m-CBA ,@~){@Id_ʌ3 O~!I$Lhdf/'~ȴW{E̊k*.<ȅr3d-6|=c!ÞJ*PlT4TU!~=6SrGq6,^W`v`? o8d!}h p(w"7V7RGf3Bzby`eV!nON'h~ XlȞ//GZ.6(ҚRtgqUYB)O=@@mqjAPQ?3! ةb3~(A3p7G=e㉍@N)oU*d'WqreſH2]?SI0qN{lgvh~<5s[9 I`بrv7fsJJ5#Ȃ<+/ߎ܃<>%lXk2 6$ 0,X o jjVm~+Vvya}zH27MTFjnAv,<8De&ATޱ:0pݪȻiN}E5?δ!}@1=ѼfW9О61DA4gqty`}=-wy{yΧsyTVX-n%fRr롎&z@߹JQPZ ~;'Eq֢ӁBBw~=3GƺDoL?Yqk#L#Q e]o.Me/ cM&Gʍ= ث=ۀ^Y a Ʈ4D`n%` AGʔǩB'`c]>Kx/0sڶ4<u{A'yTG8PJD-}0C0Vhȑƛ2tkcJ4"n^_ K?|Z6p?X>\RR멯hUn 6/JvhQ9J$v&OXtAi7Jׂ0%w,?'@P&qu,p@~Êb@~M9 CA6lPC .Jyt25e~As#5ol= u (zaMt32RQVe( lς:FHėr%hIb>CJR(9AR݆4H42嶕s-r%@$炖1E%17J0lXs+j(hKsV{R\1uX&%4!X儢k}ZM7gUW>X}1wAIi@dxf}bif7(abojԟax%>\CH<|4mVX&4A}b6.iL?fb;aўqka{Z=i=6&i},;BT|Y9Aܗ9|(!(Or ?Q4vû117T0!C +kCQ''>Jf@F?K(?2Fc4*TQ f:yXx&%Ko&:dp[ kvǼVôɀnLke`\3H+;Wu vL0┲}TQ6#wK'w1_yc˗2͟A_f3d y[%h+ ҂wz<b RFK,̖ %Qu=,KOcp2M={X5_pUٹ R3#]c~G|Aԯu9D[Qڝ40lh66d&רvԯL,/-ڪ*٩{8ØCtTN{o,^MM_T׾$^A 9|> *ր%I9/!qq"m~ƺ-CBfwͅ9 ޡD%QjzczIf&%Y`[j=WKŗ3B6S@sueJMqZ- n罔N{x0qm]hpX5iQT*PӷmOsKKR7>5|u1mT/&H|nwOtԻ$F%3Hۘꢰ큼4@ ,)L p.L42e/=L"E|zŇquz*XK}0A 3:0>ݳMT'm thDC# 2>ZMFTzvK-+'kL4kx .@G \w>#j#zPEv/19(_s\IG`y(MZ_t,Snc,qB̐"Wq:Cs%TK2/;fŇc߾V/c <]my$o* R{z=6 䭚`Q+У߬|N[^'PEI;z1!KVS?1lz?@0L^xE'P%DqT&SMe5loK,rpR!c &!jn1s[RP`A`͝qs 8(a"ZsБ ϋ$|3{BLpTS,"#>ayK$|jX5X!] .0Q&:omJ$C <-Xl_׫"X*>5.ؾ9 % eGִ/Jz1)4[VM8d`p%hwuTqaZj֓WF+>ldďXtP`>E_YOU "3幦=" Z<m, #'U}- Oi:Pisl#`g#wOݩNR{_SB&bsD8..$Q%۫ǚ=rcS|x=XЉ~d k+.<)4ND5Xw.jn5guU'{NbMBErEeah%d6@}+RlJK*I$3ug!?t-M/:y%UFs!D1UrĘ7ߍG8ywoQJ:;+λZu!;͵$285)tnKtQ+3ϴ& TgpbZRYE>%&t nKm^fݳ^7bՖ_Y!*j$rFuȭƨˆﺊh/TzI=a $%&?Nm~I(=?" u^Jz[MBXe'#7CeJG6 WI(%{J&=n*LU:S퇪󈗵JGqN==@- e^GزY#\7!,>eR_Bhe d#Iڼq6ukNwDkA\ De#\Ip8xfK[1ct tVۿݨ#P~2xdQ1:T+T$h>ڎеI*?-*7tz2W TғAx@C@=_қݼ(07 @خ-aiC:wx>fshF?WȑX寍Wٖ|l3gsN#gF'-}yR 0~2\g|Cc5| onl|@ آ GU|*gޒ 6O#e-a~:@8ַb( l%9a\["2i^U)!b1ؐpGY"0='Cph )Sj|M=T]j-oduDWj 1g d臸#D TVY5. +*%5_~קKOUtC0DNJNVh0jͿCb7|+x=bZ1&ҵӞ{mM~DɆLf|MXsa=z ^_G\| yjFКMu^nVhu%U/ǵ<(>l^J`u֎ q!REM*BŸo/bF(L#J.5g?VKo+VU֬݇^OX5& *_':K%)̉r=ӵB5"}nf}:خf˔wB,j h^uDE ˓-9 ы+]:b]\9a/< ?{8m뀝l~4#ptAFbPlN1G+,L)3@u4>~upG`Ii汈jjۼ5#'>ǟ~O%kuŪp-x=&[o]S}ttoZQk =ć3&N{=v3LReq7pB:2NMwvB K(/bq*ƥAG0KުƎfFjD*e"B7%+n S#k֬+${A7n̵h.ZbͰGhgۃkd>Xd9(|Qhrsh*~2BV \ %"?v&=G|8BV)Y)[tvm~f%Q!jtA[P?b,L%zWp,:ݨ6%v{0&N ȕYrH;3'bFW /!`:AblN(BbYYk?|lsᨃZ/͓)k-1c00] "3aDIJ;*Gù~ϸuՇߒ3X1jw7 ՚OF+E? \pX*dH?fNțJ7s$ѦΑnT CiGYEP>OVx|K}[6 dx'gШLM[gE%GR ZT h;J%^%hKN.&BQgݣi7z)Il%d[xǶxzy#zۍ@tlluk_c+[lyXtP7yq!Z ĕ)OEuX2|pzljF&:q6 {6f:Z8dE"]\<4y !i)r|X4Ϛǂ:KՈwJMpO|W+"DUۡ4Fq;EvRQ YTs털1hZTE=OhزN=ٕ'; nFm]@7n3OSt|ȫs݉՗z0Pv9 5ªmJɮK QkYfhzB[2er-*ĥNJVyxxut5Bk>[z@I.cn2 ~As(k_A\JExl׵'^4rdR56 ` v"YPSk(8JX'ZJsHə޷uȑ6o0yw,# ɚ +~,;7JPJhBHMtU* XN!Qk9q+S{zq/@mjJBcdkFa6)9ʛZJUV^г bEѪXumh9p,u?ΔlW{ߴ@b;$.?WE׻hU-$P\8m<*p:_l22$0g# ؔ@6υˀY EƵ94.~V,]neFD3I\Ӛ5JN5*B0/!9e(%4(t.y:#r`)o+ɱ:hA6"t %~SfZfW oJ/ZhB- H-`P4'7E%iMEU5K)Pء e5o]ShKƊ۷0qTB}pvW K\wCl:To=m&ǃ\=_:RK-rJ97+"PRjHn܏}5^4F_3J`I\QCoȎ1vJ"uUnLY43Kƚb\kY{1mz/S Ѧ"W w\X]!h-l*OC.Z(?m!s|,Y+AȣPW2^]f;&)>< vΙW[ZDW*`G-zҎn!&5 VeckkiM.p_A/X?.<;zy=J|(l[%R(VI{")p Š?$ (I}ʇ r2oD;`K6Mͯ4s|-[_ď? Rr`3ux;+Ӌ 2ͷ[O:kjU+_y"=c%^>) e`\9+LFޠQ֗K;9ͺGnŪd> x龍+F:>` s|dl*FV8W^ܫ.ʱ'4[ny9O,0 ۾J0MډRDt"COvև??(FkG>fA1t=#Q<+h}{4JKlMH)Cr;\+LC<&J=ùs58&`Ma‡+j߱SUtaΣ i36/*'ֿTW%N ߨѳEX}`m{ٸE3'~7VVJA?(. +L>m JȌF Ҫa)04oƮZؙOGm֯} ?gb32g՚*_,?ǃ3 ?w*uVzkD> t SJs3Yd.epTl`hz4LV`aIVBFLu։G{U_,0=lq5ʙkc @|bEv1eͩ<6eo>Wjq"\M|g!AVbnvu[lٱڱtNagK( *_ wڶ:Res CJ[ @acJ9}`b <5vG!Ѭf{;R1w=\ +֑ܝ,M%2X2)ji2}zTqshk18Я͹83xv5vob[nh-Dr+.A|蒊@ӃmVƿ" 0耝,q伉X\`\[Ni$R銹9PGєkiɔW"f~Bd+rm2=S| 00ɠik~E1kus 2)|~EXdK_vfҽW!!S3{TǗKYrtkF2:'f_D*8B55CvbH8">9ͷqbÓxfm2憎Y31]q ~͍ab ӦKcjp=/nh&ߝ_e~DNDx>7qRԐú^*2z C( bW X-EV1"KB9݅K9W^*2.l6z=aS>|7XI˝ ݟqB%'j14!i(+;ıM]OB+\4;u7bEC $S%|CVW,/W3+0> OKAO_lPEf{$#(N07g1B >)Qdljʉ" JyRZT#5uj!k/ E0$^/Rĩx3d"b0R/ b:xqq")$Rb 8p,o6~rZt Eƣ$QԠLLǭ*ͥXU7Z/4ǣ9Opup;AΫzaM9zIy,6V]cq6'n"7/sM0 /irp[W rޱsp Dr%¡!1!v9mDk*iԕU(D)I@ԍGXC*Oԝt:] Et4[do?Bž'z4@l" ]\ݦR#`!SGOSZ@jw+M*k7X)R "ܶO(GDPO1Y})KpY1F4x&k"ɼ[ d>SiQ$sa׬ ['bݚ0p5X ܠ ҋ<2q 7GY}IWX8zk oJkUؐ-e^Y|cU)6>wށOFfbiߏ.;Z+_ap8s'+rbꇧТ)֒i뻙~M1:=^CZuJh]"F&PB$aW nӕuM wJ-ߢ_u4XjP #a3Õ'1| o݆RDG܅+DS}>0lLopwvx2ʰ*>jbދ(!$~u;נ"l|L)q2|t½Jŝs&1GCUތbvu]9|b9hW xZnA;}E牕vjz:Ci *>N:j*1\s|?VB3] #qվUR0v;!ÍF|#*-.,aC/qӣv`^pG\$s9u=M+vgi\`~d&$>ʳǶ;JU>*mZG;܀)؟pBkδ\qj[SM^C"L]iW'4:ţȌODd:v޷ Ϫ:)k \H4U޼1oHi)i,JidXTJd 3Uu06d DťFY1z$\ ?pZu03A?@6PK:忐`Tύ*D:gKM+Ph}h)$1܉ACeQ`xUlnII'g2CX{)Q_]gm^hlMJY௫Psϋ id Gȍh]wK$k؎ J-RkU7[z[UAeOʁpIJArz`,X>:94dD;y` A%Ӟ>aÏJD΄ضugii>4pEVEH0=RLHS6CRsYoD֛r[dQ 0K.7<{p '>#Lږ݈6iFBV/sRX@pnzuB}q̺ Q+OMùQ3jmKa )( L699BĽ="PN5e#6gf4DNEY7$1'>жr]/a@?ŗ3RMң*x5dA!j(Ut͚g_/n!JIѹOr x\RJi7>XXݻLiuY[M\DL']o>P59^gl/I=# ʑd諉kp:ю{K&?]T#%z3)eBm]]_*x]@VZ'Id]e.x*mX GjfJW'B Hƕ!әHJ{U0d[\&T=b5ϨJANaIu+Sd~?wĴ,l3GT4Iixn1 ,XǬYZ@"(NbC$=Xw%i2~Ƨvw4Hn,psk3 d1OJumk!vHxT:Kc[€*aw̍}>Me6o89=*SyV:-BrHnvXrV27'CAiQteL>s8/ 17WN&Ju[ B#*w*+侨{͙bZ8 T$4tYܬWu "6u m/9-qau@c,^ 3,V+d໤$ Or 6{&߹b̙Ld㶝Ӗt;5&k%$%agʼaks <8:>Jק#~d\" \p]&: .NϺ~eZdsӴ=$LHȤ_V7"oI8\;xJ[O;. eLeus<~sj]nmL 8UpV|ͫVCUI*𠙭~/k5}lәZX*<"f} ҶVx-(* 2Fj" h:e#`}}04Ve`jIWG^L6vaP'&"jD+Ѧ\QKЦ^C7cҤd a$!j':Axelf4as"uXnLFVw~G]B9zWL7Q_T쒶XLJ)~JŤION@;=H+BA|=D x \h FǺB 'jk|y: 4f(}m^xEΏ:D tJ'>W!)jP?/KUOAS#xXhq=`PӎbWSGBn5ve hg (5}w2&IŸ뗘copNޑwnvJa[Lt YxR< M_V1~Ps]ᕃLn~O~YL2a*%JlxRv&'rͭb]WZP#je>ϪN" ~5&=1J pwsugvuD*M \$(VqȹMhu2h![Xǻol}2=V_0>nU'mߺྒQG 2"ԥz)Rx#3J1OTpS:MIɖY>hoKkxO^#sA~3ps-q [5r!ƱİF@m%=O2f,SS:‹4dt:j?ji:`:,s!A3 p]C 3nzE7RCx?AB/?"_%[g>N{tN 큍B dVpU@2"4Q_Xfb.l( 6I] zܢAR4&Mú@x-=Ba-+p1h,h-C^?3cjW_ `ѯ-, 8'bMo['H3$їK@k~z?fL*?`bЍ_,d'м*ޚ1U ~#D}/x1>j}V{V5DE;> u7Ybj!Έj/A7.BݍrV` q!/ b8Q#eSՐQ/q_Δ |%#=cf1 }=#&t1HpΉRj![Rl fDG2H/2"՜aՒz3܊x$h0=ʵ;ůhήM=-J1U^]mA'eY>CHy[cރ~i=_jr]myyBCBt[Wg!^DL#tX'f*n_C= fD|z?oticbeYcgyЌϦډTŇ#YـZd;xH}^|Ų,]֋ vUf%7,9ؖ}i@hx/Cz"@)㈵T+>,Z~F./" Գދ'xZF΍߻#28x "@P(="zR#&/-" ^eOΤ5Lp'; \k$TM[ֈ>{$IW٠8S6*Q%k@)b2{zdˀ3mY a % GN餭)?um$@iDy HxN0$lPECG`<N܍A kcK\&ÍYgxOl/z?0s^^m0EJR6JAdcCxx3r0ׇ-Ԓa_0,R,YۺF(7eoW*<Gd\Ӥ2vI#^@"*T~nn[\؎VV4ک5nXl +A#l04¯##bv/ۙʢ8o4,e1?[&-i){m2!X-I}xbxNS 樲õFu ao"L _`""!4|@IrMXģTl,jYr`͵5ha<, @W|64\bl+׻š  6Σ7*\թ9*A{[/FoRF=~峏 l}J0x6N8+;j] W3Pm`e>!tl*pʧ[nQn:!cuiPb)cō/0WP\!֋e~Ǖjb~I:3UP:*AKPB(UW|{NݠMWC\!~S-[vJP`jH51ՠ9O=]F|< Q׾ӎ<&xt&nCeAy7ٕ=Gtg0"24`Y3jm6p-w @0p?zo̜D 0ySM?"K4uQ;KahjBP a+U;08)fKCcz&{iz[0P2tgbq^B+WWQ3O2X MǼ_, Gb (BDI"ZMuTO '-r@l#s͗ZA< E D.%1VSG~ye2+p>آ,>f2է6YM{My^R|-Ui-w(}&O4{kh"T8[;Dtsa@^;zWEJwn?%1 ~Fmha%o9ong(=u/eGncmȵ̴(nZcD*ɲh4O!aCcDR>{-N ~<]L\6r9o);_wꔢ,$&sB%B]%R#2}W- Q~IWT`6cw.CjD%l1kPPmC0[ ff0r"G>~2"o>;*!Zt|")x-'x7#ĥpzc4 X Wd  /D1Q 4fQm|;_ ;0GtJXM`~ qa 8'JҠfUK XhmeΫa!~Fذ /?YCj)gآTxte\r jkR>fB>M!ܧO}ь) eDC Z*du섆3dUFy^q fZ$3c[V,MΡi:4s8B-dzK}OP$[RC}DPLC)[k_eqED!;Wh@B-E3Ps(2k<r ,%H}ϋ\);;~Mt%ۥ)bl=!FYi b.K_4XVz0s]u5?IDr7.Xgk^ [,Vh[,Jx5&\+A c_)A 3Jfʕ}>H' PNJ}7l$sQLt1&l!w;Y J#fCu=Zhm]s]8 oA3$GNK@bclj-A$ 9/Z}euGa*bY  qS%@,рrw`F*|h"b0,'u "cÔȢ4H*L, /Ƴ%@b2.q>.pj^SaI'0]׿vn_ *`S(^s,ʜkD~#G Ʋ2ǢLX`*' %i/1ڏFݤ#'E.Qɾ{Rlɶ@㌧d $({6.N3[MRˠIԦH9MݜB/@'#H|Ǔ0jcB[SZ\+G6e.u:!S-C']M$k*tÈ5,(ܜJR)0yd)aJCs݌!+_i+2np;mз+a/aΘPP0rɺrn$BG A䀪P0j| 8h7쵒.69}M41/&@"Pr0L tAb l$d̦u聪X3" iS#f.߆lO*8Ts8Vr3.yM\.nBvZ/[l!# x@Q?XOze1Y~5V~@i[2d`AɇC>F̈w岓4#!!ZPw}X iM|?6™\\?#J~K ;^EW~69ߟ Y`a"2M]OɛX4g z?7%[6i:Ŷ9X`TB39n!=TV& V ܁O^nGPL;Ck`ÎLF : .O OPW{/f~=03ȫU?-"[ W w\! "u0a1yPє?bF@[ZT .ׇ:""%l aǙc6tz6AWq!6zxg-Wr<^a0d@, aVHm  bPhN+S@/JBT#ņAzv t}6`H9>ַH$;dKL <^ aC7YnoPR&yl _DQwj; t<,BP%tL%#4d7QK>mG2voXk:w4 U}?wb}~`2᭼ %xЬjݓ(eGZ'xYT h½&m.@X_WC~J0,kF3D ]@,\W/9 )nw @!? Qm۽k 3Ϯ.c)"HԴQٴ2?EP{`oUB^53Jmp{1y-ڳX~fx&g+Jǯl&$d@Q.q ;rfCU}'NK&jnA?56X͖hN$;bLq'F|`D*,@'n^B|<>XFD) &5dT+c1]؅J֘L XbmMG> yEjB[WY)aGjFBoi/UFÈZ5?j*ML$* ;^h'! Gapb=6ےöۯN2@jjnχlcB/trdVU!\E[ 8<0pX.f.cTvuLejcި_g87*xyЧWX"v-DK̂0Y6ă%(y™\Hb91O;~ 1cUt1Ӗu^w[SSeh+ⳠǞrz\TuWisx+3٤o"VjyFԸp-+Di9! ʺ3(s4[W.ū3s yht$,~ZԼѡz\5̞uF`Jh'w q8K">d'k$vq(z'_˜` &Iu|%cq?κPM-+4vSLķpb2g:fyOx.,BkpE ; p$4ǔ[KySFKS _h39W6.,}gZkɅ?| c#f MJ#tSp=;B:I:rg|&e&tSE%s$ +?e[KT @*ӓ!D$AtC XQ&QKc]8фdgvvTZX5Γ[2e $a̫ ЎL k~wfNJټ$ mjULm:9&y2)Yv 8Ź&ho_00Ssr{Фk~rZ8 {:+܆]>n;5Y,=DNf].Ž*F9!墘?ʡGEQO'g@%v82"if#ח tPry⩪+419VОw ӧt1j#KaHԉ`iBɉH~zT2s@J*aVxn~E13ZAx<4Z)yRN2@۟LT y)T[Ro_2̞Z) ְKHԺx^Ҽ(P?:oy9RS'TMe$'&|=ΐ ״s"vkUyj', _7IO h-f()0R\J@d`70D"+_\ L3OL R#osr3vEa-duS ,7}`#Q;0!Am#Wr: 䶇0(ݹ\Elzm8qɆgU`2ዾQƝ$7 TA@뙦H46ǖ%xSwnFj;ls+ ğI#-bw1lsLm]v*Z2/Ï`as*|e4edۉ'@:GM>Z' []-ey9CZE' gQzdr)\$Velz-7T>6!òɸwX] iV%2:2 ,TKz[pڣ1Xj),9+zћ^q4,w%X٤a: vce+A{t߮-j !9)łid%0/ >GO~`*8Aӟj},FBb^1c vf\K%bwЩ8}5Ok|9i}9nCa]Otm9v^,Ippld{?FAfz@QNzOҚB͆r+g\y >$76BA5o[>B17!ǀ'q|rgzȓYj!;#2F\Ϝ'[tWkoNà| r(pDڙWJLh. z#eཞP!;T|Kө pξ7Qk;9f;Y,aˑ\+N ӎ [olF'# -;߃7rִkAB3UxVjz#}Em(YkIl K&F>[2W}|M2WQSP*F8ߍ PD &|Q'Jڼ-_&W0OzKYxTRrZml(?n 3JO-!&Ę1pE =uB)7Qw(">(X|߁Gy9$* ZYF~ [0{(hP[Ui'pF4c~\+D)32T&Ho=C FM'*ճQk#D5T#^Uس!0&^dA 3OI,p_=X{D9+ЙGے?!_a{{L%}] v6UB9V[dAab0/qM.PWazTtp<MEJtoush@A;Ȕ\QB0g.*k|m]r7v8zj` uN׬M~-uSPysgL2G޵Vr,%7vy`i$\R5O;W/\;!;U6in7 H#(*f񷲕xz[ApsX: j"#7B j.7ԲR=̝Jh-^'i99/ u.xN5f#WŇ8n,3^@Jd^[U3 ++`nnXlt Ϳ5M>`|J:r&i|7-8g<@:ě\hIWwmA0Q#,D<┉v7TCvCWҴ{v:`h- XjA-`!n`=3Hh|h@ROzg^MH纠^h_y>b -d2CE-ƐQ3-V: ;G8tRdB)-mc6ے#UX89F@+rCG&p6iDj7T0h̨tiꅓo;A?Mf} nUh~EHfuZ+эDPZtKEԡ7[6s?}foYkY|d㓿ֵࣖQfSygeOMn鰁n/V'j l{fy˜=HAu} ~pTIvlwɍ;mbJ J·eoWiD.{8"SӠG4/۳>lx3xW ew~6KP^դ`.ap%ܰi~R؏V3֋fICRe2 MލV 4ICi:h-,aFfxjS` f46~etdŁPAe c ܻR 58 d$W.QD)d9wZ8? |v%'f#tHc |0i(FS] s4rܷQֶR$]hfJ\ a_k},AkNlO/qUbkX\vhDht9-L^d/`ROyx$~#~ x㏋1W߱mq]$=%Dnnk1ԘSؚ),ѩx>|l-YdN9>֩nMY)UXw[$WndžT|ゖΡ/e% 5uT@x_c 4Cc\V1יQJ$df` sG<*|>1^Q%kK]#Jhdƍu778'y94юΔh辘 E/;%9gm@dҲ(γKfF 4IceU W %/)nf?l<w[).ċvfE (ȹ `1}TN-68|ybq 9*Y O oaMK6 yJlJ/ȱ [* Q s]wFW ?de"p:MX_S{etZUF@-:⟿I־Sp؋ Q}+8/`^ٚb &Bn$*/x1\v.A͇L,D_8xg}L6n> [fO{ew-ƫz8׆؋%uZͳFY.^oP6LT4/(i,Ps~Aą_u؄i?Mc x( -wiެK5PA$_[C =?EkI B(̾kE0JNÕaynFĂ?aat{=o:p;e2M;%ӄz@%3w Vf9i>VB%ý=P3 E𹝯C;fHتSM  h,Cΐ8Dyy~Ƀ,{"sXOLke2^ܦrJ vt>QR'nCxD^#wMT0srY/\ 䌴FFC 8?) [WϨ$V=S~06Y~{g1Z֒0̲ rÙ)c0!cu.=A5X Up 4O!>lݵ⭦S `h*\0qܫVl- m$(cYgm1~A{X t$|+.0P"FFi-w sշrx-؅ K) Ċyxߒz̈λ-,iq)Z1]+p<{/&*T!cUX%6@^'+ӨvٝBY"=QIҖ6dR_\,WzMn9;bC\V~Qewӝ AnhҸ9'DP S>GҵvCqn/?ĽSA;KJ/P H/4˼qE~ h" s1P $ifgoEC\.G,, a mN@E/C7ZJL_m+S(T͋?e)wO'P 9z: p%пZirZP/і*\sޕ^ˀ< ܄bv'^nܿ'* F\ů 3G4}5ϯ-u+)}74| o6 pMҚ7ȐAw8;7"чoBڛŴV V GU=gE%=)[wƀGZ,GN */zt%{幘aé(:?o,ǠqHAx%N=-&UC_T;74^_soʔ-DvvM1p |徫s.ANJd3jD雐g$I`.z8Q "!R2.W>*B5z-K @2WGNrX-!} BqFp1C{ bi2+ⵒweS)kTѕ@ȇgݜ>flxaHyg/s"NX'<>OH]W촆VP?ʹԃ%:*hKd}}Kl,7G/VhbrȍL7 )1fxӕQ5hDh51I2SLg S\D2H7c\o毇2 75_'iH7eF2 *d6b}_ >+;d%+'z /eΣ$- f> Zl eh}x.%Tiu+mљQ?dfjHwK^'~{Vu,A(AEe]1cL}ͧ%jmCh|}g|A`4h#?v?e3XM8T1_*)c<Ђ>.b6C&YI8?H:o ^0 YE$%ri}BE8Ď"'['g~#oHUxM g[.hŽ䤵ER%*zX)jS3@5P!s,bRWGy573]U17) ĠGE]Хu611|!axZ{ӣQ['K7.SΦNtCcyu!Snq>IGءOn1%+a@l#hY'j~=b' [8MڪyB!҉%Ц&HrlsƵAzPI0) s%sbI=8fޒ:\)[~"|ͦO ?Nʢ w.9ΓE%돟uh)JE.]bëG8ƃ iPmQ<|r^v\@{Cڨ/ VӇ3D2{q\=k6lno?\4D{ύK*S=Jr^~clD%wۯXssCWΈnjrT~7ZRQYlE>Ы4az IMy>stU Ql[RT~k&_@վ<H1 )X lR)4;'g´ $>ƙ{*;?[׿m>NtŵF,L;]jD{mZz,,GJ eS'8TA>it\zfgç..S`n>v 4Qۛ'"(08mz qEa~3.Z Gg)#.I`Addc0LP:|{ 1){A $R~.̑#ޅɀ{:ɣFr{hܡ]#:FWUMx ;`'#lb%ߣGtԜvAKe$ +lVStkӡfvnG 8mH؝k\ \t_hd+dJ qN$*Jc#_^|/fgq6YWܙxRx0_z@rL>Iczzfæd@R@ RW,[eQP _nԻ5;<R/;+zi´{6(#> :鵅Y{y 7n4CVRC<}xt$e+k@YJ &hpG'\ BqP.i}d]Sls 0' ̅9Nm1!^e }eqŸ3T3#>_ ];LCwuI?pmt/c7BѐcIl_'r+ve,tvC ݨs0.GrEx$>ͅuLϧ˸ZkG+|@zP(Eu` Ֆp1~̇$+oECz6516Ҳ/%w*Db0> OIy|nny-C_"f0p4Y i =4)*%I5"CH7hb HJ&GR t1xYӭ[BHmӲ*|SY5"` ਲ਼PjIiu:s@z;~B FA?s<㛯AdUY_>î7c)Ywzm- 5Z=Uaj!Au ++B!|`=Jz@m̴`jҠd!ݨ_k|,+%ػ.ţA^Y-YeDQ|~`# :@WNOh^jQEK7U׺tụ:ԶtT!^ ~}0ƤVsMwa * -|)I.ya/wxe =tH(]=TD ".ӯ47$NjPC '$,:ZO EWcN Q]934i̧KN=`3I[7qWu}+``-dN>&k|C>]yp{vGxw7Y,}9g2O,6WqXNr a6W3KV6tJZjX=~OF1P39c K|d%v8#C2ds:$`KC"~%+:ч(~3?Pa*w k]EMYi[6P|1 Uª@׆rX[6ZRLDEŽ&hR,cJД]ueU&Dҗ&~?Uou?"LޅlORcMI~"tu/ԿbV9 i 2> EQ8/ReA xr0,tH";vcAB"4zgETeFuT0D eM%*i&lR%baAL/ě4bhv5 bS $iMNl`QYҏ*KxZܢ).ˆ dBlJV 3VoA~ء(DW3ToQy0bhN;Ãb>v" wLر*o`[fӟ^l/~'whͥ) 4UK\~ru(w ~v_8-`׷gfEħD%6`UF<ֻZjhhn7ݤWhĻu= X@ڐ9F[GP K*t`%xJZؿ6uWBW^meax55gݨ9m2rsNyÜ:s{oLZ| v|Eؓ($U!Oj<ꇚA+-l;$[+9Irxu$﷐j+*PRAwE*֩tl8WT/5C} T)jax a\ ?#[\jo{WD FɖLs)_-2 ,tZ̚.XA:IJ?&< s;qw7Ii #b ay@dF' 0{y̴:``oۃ-,jպ;5ϞNP2BQ$s__Eξ2eAJ&I$>J#>q3@/{7feN9 w1~]izo鵯U%e]Țq&e{rh@$Gc~,P,/۷sN`{AMg/I&S{ 5K=./d)٫foR\:]ՑH.d8h;//C}D`h (b3I`cPZǭ5ONTjP%}\;M%Xfz[ (;C۪q!].~uvS2sB:I [YV^Kcg&8a>Cԛ4kϏ:Ml J.[Z^siR@aݶYvoWC4 b5 qF*#s2+FՇ}dgTups@WA2EK&Ƙ:>Sd* ˎm)U;p_K&*C v{ay aWuuwˁÍmY 4JAI}7gE4g}q|/W6 +pm1hEa0;j%GiCR #a LLFB 1 ǭ5/v:C@*HA+>&$ \J0~:Sr7/)K?&x(P`C4*US"9M?Mjcє+kxKj+tڦ$@\ڢnf>;L5COB8VC>/W $G|s w~vsO|p2se ǣ#UF;hah~V :sH sjwѭx;=B mp'(b9N''hyG'^3B:ZӴ=Q~<KJ2>ž2o O|_b) q|!|Q51N(K2 |z*^B\:sjw$9O%}pc=05,ka zrn%\ }qꙸg0{ ¾x##邲}~bⵢFwY3|8 G RRgtO]/+_V|SqB?R2Tr? .M" G1ZuL[Dg_ޥ9|uW9- # /r2ruU#gz0׮ .3`zLXoWgRȐUnႍ_dìpw6[ӍǼxk#-_ 4uAᄧ[Ha1| @pIe{Ϩ4ϓ} #]lsқ!((ԙmVwjaةChYt?btPjeP]sƇ_F'WmW@@V"Ofh׀*M~_86e4KL-KSpLq Ex72-6EC%+ //-L> *n2IǵNv`imVuN]z Brb P5q@֌b0UuޔzuQy%غ joI^db5yKB;.&) R?>άz#<7SSAD~% ԝs0u)Go(LV "7#I5v)EExƗ:Mq[-{s;N62Fc$[`MseSv*[CE 3y׿KP֪_E =.M &%(}qB:TpwStKB2QH-PЇțddwx3:6b%wnUu'W k>)$kiE,Dc/ӆEESVY4' |6y); -*#."+Yt/hiY Pk!GIuە{_ZHYx+] $kU o\gePDhm-w6bI F~L3Swo<塣ψQ; 8#35ȾV:tƎp48OO/MY.^ B|\4Rh Ȅ=Uhx6C%1Ov?1ЫA٣wBцP弢{BzfoQs%fKaℷ]-i_H{C>k|zksᓳ)hGS_v5ןʚ't{JvfVBIX͔; @OGѿy^J+͏?|%kt$.}ްKbo-X4|jM&rxy9E o0Z<١Wd*2[{1ƐA܋}/Fr؉nxId)f+c*\ +|-hΐ;?`[W ĘP##Nj{9 iADy<ӭc.njڼY=JŵgRM0w<] gm5(;NjӮ,CR:g]0 &ױMa据@Agiu`iUѕ;}rkj6w]mQRD6N|D[ڞj+`~ɩ, /}utFnūlJ:Bh쫢u{I&VҴat6<GK&?= 7}fRT Lfǁ灛kmBzoȨtZ*AF8^>"PQE3&)+}I;B6FO cZ-ױn1²n |2\n=rD*E6|҄s}"~AR8#,-tؽ`U{| .Py+_q~d:? >z؜+7 w퀗xw*+d}9׆FS\3gK&a Z >ʻr3Sr/=З~RE Gb-RlhvEi7.OV+QۛJA07tD墿CUBopm0+DdiC)9J3 &%#HKeL߮%pAd 4l ,ǐ"cTbOѵe#-]eW:ldSCό RUFjἺ3SLv &\Q ;(H%7$/uzJq(.3[PuV˄ 1 ͷo)'Ŝ0O̸.<_\3_ m[#IpZƑe|A[V9є9n)Xc Sӵ3Tw ޝƖV(rr5e[j]Zt}kVmk +S93q:^[-ɫfLvWcϽt,{`aX` I<.tK`X@fΆhY]M g≪q#VL+ݤ: xsMPF7ĈJ@1=WC Tc>v n(l?"uNϖ|uHƁy#L%Y0|/#7D%Cr铣*!H\͢a3]VL?Ƣ[6n|@\IEHvKe\wR{AF G"[Ha {;U , kX=>Bw9WҮ/ ,[ς!@RS\|&,U^Q jaFuy6,xS]" ?Ex%u.%v^o=5r6tS'3G uޭVs'y>6{ {͆jP1OL"a L+)َ7롢Yߗ22`gd!Տ0>Ve62 {P[_?C,xIԮ-lMs)p~nEFs7P Q R]q{hPwiQxZi1gQR5VUxVɷ UJ;J tSڮwlw~/W1)sB̖E4fJX3>,D AdBNǫ9}4k6M0p-pJu_ZsRXWɈE g9ox]&.S‡rW^C዇^6LY#ㄓ MT$^B g"AP ⠇g\i ݸ3L4^'0OŊC {#"+K牤+.n,: aϡ0o%d'^7Z\VlU]CX# /[Hn n,8?y\U)W;f̧"Ŷ&EZ3# \άAvjP{,ƈࣜ@` qK-nZh¶ok|ؔ`_*|. -fDg\ŧ̚.g<*d? БH'APwP1+f4 ے10RxNxA>3¼Ry5a2`S$cg'N?;͇vPN<<4j[1{ n ќCv%ݚDfJ ATcR]=〖N^(c2s}J2ʁSFh-u/n{= ~>B;( b]BX>0@µV*^W y!X,99$&UE'-W-p` e9Ѯ%4h!I6J#CW#ZĽ2u@>=Ы Ip@$CW'B~ii2j< g8_ p X*}s,62 o'0`P,| _$쿱;(Ti+'n1L;"k-CkhACiG`>zF'g!*NP}vɭJJ@[~8D]xhj,JͽxR'dW7(íËE!U&҆U= W+Vq Qj"ȒgF`bBڨY}-`,s>j/ fp._PU0x)Y D?#1fFۂCAS$'Vz3p("�L` 0,<,iB',F@|lo+`vz{fA3cFP(sEڈ'4j.{49h81}ˡ #J{4TU`C w#r 3Xo%PjՍ=Ə m^rgNZ'Gʍ# E}$»m!\Neeʥd\. =oֱ SL"˲<ԧDzJg̍7z:%xզN'({ &Wxs.(w3WVI!pg [y@LAzz%&bU[db0j8*.oq$>_!3'H*<9Ӌ"3lӇBgFtG`Y#?we1@0/+2vƲVuQ׋lJ\QR Y'`5I0&x@zmb$o $XbKN cV1W+_KWSQ%$[ttqn_"`9vjq.z@YDQ:q7`2%N=-n8eڦK&XrW#X&\|lZj :dR/ 3e*#KKDm4>^dZFpg<͔zCq?FWl>d124w]>PeE7o'l:z*OU1'{}CCޮԭXGY3HR\.oAQݐ"s1I`uȬdKF())#F34We}O pFG> ]uY `IٯXZp wC<Э~ϵbU2{]K$j.kRS¤m>3 [01!~dB a?), OԸCu #M:O /֗NRk &kNj&Q$QMFQ ͨ栯f{-@yP+CdbV:{L)2fc2`"x3 FChcLQs">[6YIKsס8 /9s/)պ40?،?4sE3aB Ҹ;+= @%ۋeSv)pepkŗj4.o5u6H[ZCCk ԝho_"tݍPKSqF=*e݉|0"=HhX(+PC>f@Y+Sbp~}+k$WU+vr 'nMs_oOVX*~ʰAw-y&Aڊ?z>Z؎M eii"WsQG~E8z,獲~)ֆ7)TrfX .ou8^=MFVQ1*ط Ba<*ې鳟+A;H=bY ^fCb$ɵ:Ϲh˵%T* TvT(Sx{6R6_uWM UU-'I-fb/,Vvnbxyχs]z(35ೊ/|V 2Eo79UrBUW a AlG8e'S`o Dh>Բ#lu \HjƸ|]*QС!nx2bժ/Shڏgt,[gr#'/>sk6եZ. [I?IH J-ضSG͛]-L:ԭI-A s 1@*wa\;'LPX\KuVXAZEp5T(z?'S$ d|SHeJ {^Gz&#[X| }IPw)t֠^ ^ƧAI:,A(xmu;ʬ"I7VkpPp{n@EY~pJ$Jǎc˘yH4]ۃL%*w2_+"R75E9*QM W$n;$BzexK/Ln=h?(=Y-=>1uZ-J:F m\:l&X#qœ3M泆C%ȗgq-.FGv0jȪBj2,+0ֽ G%.0 YG~dBRl(=L< \~ʉ&_\ ~|X"+hQ\iHW?eoDLz}dk1 zQĿTuȱH ZBpFXD,r03s8jW4Ehb?TJ]&)iYB^ iDEju% -@pt-(X(~oxt'4'^=A̅%"#Pi9 dScZzӺA)WA9xM]P$*%;䩵\c,$t~aFx>:WYͪaNTNx1`H0ً > xGsHq=(EHeqňƇG3{ďZ s^C~9,SM ISIGUi EĬl^Ӕ6+_-#&edUE}fẵvrn%6%dT'FtڳĆNNziPoN?[*dJ&5Q^?H+ }M.u?<IЖMStSȭ\݊K6hўmZ:Z)Rq\ x}\ގZ0^$(M2MshzJGFHNև!3-l}Xj~f. "q4&K5cǂp Rt d')^ܗX|%t]fv/mIԕͦǻg[Lti7X`ŋbciM>ɸ4_0I/^,]VfZ>5dp=}\m ֊D@+fp 㸵RԂYn7-E4 34TlTѾ.;nAboS6'!Vאָ߸ӗH j"ٚ{ 8Uskn͌%5*:?#t]XK ~cD#) gOnXhmubuIB$/ +FQQk+rȕ6to{1;n.잹oFAÙw|]%eO,PJ(̀,?ЧP:Q|^W/ML+(q|8 4L)$K[v&X' qecǧqf,^)z W%*Df6D(eqDPq[Cm45(-g$tLF$PiE1%TS1")ŨN?$]s"QuN g[.%`XafD L X" X=65և+abPYǿ4Q92HxhAWg֋9r(3Oc5jѝ[@Gj>xqTOmrh7ф;ϻ?FȤ- BL=ڴWxgG7,|JׇЕtG5o{ڲ}?35iƥo)gu2%-,Tg #|< %slzY}NƩ)[cPu{Js\s684I@ XƟav8~iF%SG J( I 5n kҖ[_aBn{]hTJE`Rv[Y.;JC׹|P]%h܋iFݝsÎĹ4QxT|h Vaz:R#-SU޷)EZq#j1-H?lT6"2/ +=F=J`(C- ?we%Эk \ 32סgF=E)aX VfQ$9fdFFeH|/HUEp$ik^}=5!0Yo'K1wV,dzAq)aKZ!D2Tr'Cn @>"J/wN؏9]l[Ki/I&!|i0gS}Nr"dr %qWѤk_[jXAMPK+ɚa| zG"^0uc!6WClx|قCƱŮuom28,@ U?@'6(1 |庱V?3N1 .|(9W'窨>F̬YwlG wr}[ш"o5MX%xV-çrg_fkWyc%/9/ˀAtuϯiೣn={P+332 w?_w;e<3CJ9Lif<>m3 +s# e6>zY+ЁÍ Pp+rJ``pk 6bx$Z`ګ&2iB֞x1wW _{Q$'05a!WntVw (yS֎,&u1MBЭi{W_kmI :{Jve"$cF1\br7 :6CRY n?NyBEM|횰J7+5O.GCHY}MZx%z'!ԫ;_Tvyvev<*لaKh1/rt·] ѿ($s5<F2qESxu~Ll6YIW4j W{5DovИl<,@,4+/]%~̤et%VN6kqqsм)e=,lEKx'!QB|k7iXJ·͂t \ni9ulXC;zWE Ytf5 1 x8>L쑌$@b*&x=K","/OSlwh-+[d9q^hh;: %Ek G\j{ e99x߂ # /,'k?w~ÛY>LBKΒ(jBy1c%$ ojme`&EX@2$=\nOVIuUy%J8b!55,S7wɉ$z&$m8i)JL?fS<27NQ@oC(nA89mXծnfv /:ɉWCx5񼌥XеƵvM.2>Bk!X/rvJ[O@ u!MHةq",2qd*_r[ v4L 02&lBU9cOY< !Es(/OuXD7 L(D[!]اjJ+( p?Z$9/\?INP)邧R9 {x mZ+q1{/) uma5cW;7xdPz7n0[UWïR"]/$88;͠f\c.á ,P]Jݎ|,i!@~/`>lM4~nCARȵO-\=kʉ40ZzMh)aZՏgzgr~d+.K)4ȥNJgz(!* ϼ3U">=z-u@:o=ʞ/a"YKb@,aGK*‚R` &a䂖FX'zhn)\} !\Ϲ6i4*{w }:ݵ,yדfBEXڈ* Jn| yUg xx4a~y(wiV/J%A!~i~\zBAoX|,Y&|jrqF;u6STYnB",QEzA58Ӏ@ bV^ bXA$}JR>cS+*LM5?Ԏ6L^߻h-29s8~ $-