sssd-ipa-1.16.5-10.el7_9.14> H HtxHFc1 ?*}}aYu$_^OSj6Q4 |"y8Ʃ}:(c1e0fd17c709d73a8c38b11b56498ee72db218bc1/q+:1Fc1 ?*}}hbkOC^*7lV"}5at'tpuL x9 x>>/?/d   ; 7=D   8  8XxTTmTDHM(\8dH9H:H=(G(H(I)X)Y) \)H])h^)b*d+De+If+Ll+Nt+hu+v+w-x. y.,Y/Csssd-ipa1.16.510.el7_9.14The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.cFsl7.fnal.gov eScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKr&/A큤Ac1c1cC^p0c c c c$99a79bc96415bc33e5d801de64ef4570a5da95f12a5dde2917984c7ca1a9108068a17d8cbc7fbeb27e8f9e9b22085a2e0c73175e2637634d92c02825edc8253f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903323e314b446a0848a35eeac232d3b3e251c9cfaad49e0b2abb0fb09d0b8dfca292503da38df78e7deceff4ccce4830a05473fc42be3f86d735763accfc2dabda8378d03825dc8f1fed05cdbc210d9af330235a6e43e35f33c2de738f32142ddfrootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.14.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.141.16.5-10.el7_9.143.0.4-14.6.0-14.0-14.10.16-20.el7_91.16.5-10.el7_9.141.16.5-10.el7_9.141.16.5-10.el7_9.145.2-1sssd1.10.0-8.beta24.11.3cs@b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.14Alexey Tikhonov 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z] - Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z] - Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.141.16.5-10.el7_9.14libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e86221462f88a8c09db5df0c5322a377c16612b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e6eb76c037a33a556d990783c1c8f8f5fb18a8ec, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER@)%<%+OAN z+9lCoDtn!h//@@iI>nF(+]i(B+;, a2s3zqӺe 72tr_Β+Lr.A*`>3̔a[*L.l! d B:xsϔx{~-_&XNR8rkz FyE Fťɩ- H"!I+ (a`-uEY'fa 'BMн_+*[keN(,ʉ5cR_#EYԗku)mȈ*,K$Eki9'dO: ;Rrpbn%B+5u;{h6;wX'! ")Kte^QKTÂZ0 (pܾL'TהnXVk"㖰< ˡ≲+soDl4a_Ij@Dju9HA!v`]&nWP>5-pE"n4F {"-|rZ-_'&1+*2W|' 4+蓢wxe&j=u]!Qx/QP@D)Z!f2 L: s*ČR$m=9'-ӸK2<+Tp _Xc𾹇Cߵbp. jc㏐Btqb vX^5U)7z* epjz>uBС 2е)DžIsyr7+YÓIRM.iIuKt[!=v^6"חˎˑ\S$EW`H Dw6KJ0 |G_*GrQ't(B՗5Bx秺Qh^6XQDnʰY;`Gx̹U8w IrPlqw?Hȳ8chՂpGd7o4ʻ6*_4xOATIh=Yהpo2pA-hlWaFN&(prXN|&m; `NQ\}peV8OLACFqK?`= 4 j@\.ۏ >(HIvr:HT Lbcψf ulġgs M_™p$ S7o ~\Avp?R{P/H Ku/z )D}n_̫aʑiGVtC?{-cBp|/=D)oZ$A k:Ƭx'^+aQ:S"ןAjtfԥCW*6?-"֥^e5YC5TߛFǡwnt ~Tv `^~gɭEХw)BAH|݆hSU6ݘ<yC֥eX4 Ť $Qhx絛 B,bgIs0 +"67p\(}8SLɸIA;*_,Y91ݱԛw5 hCȃ?Ov+o2a>[ʽK |-y5Ph9tWZ=5HitdJf$M'6dS/F)638rLQsMK3)6H(jM z!m:yˠQ-Ӭ zJPD}v Z؞L eJr tuu,$,jZ¡'?Xo l^ 0zXDV+5]%Ωj,va~0'0]ܓCϡDheBwE힧H>ƹ4rXo)ãۧo>BĖ8l E%rj 6<33ϸI0UsaGȋ !0DK )@1֧z߾…K'}[5R8ʫ9 Enn=G v2yоK<شUR$=WT#4!8vr)m|1A= wf^I3Wq0s$WJ.6D3:♂j\l'(zLZDgɧ5mDF3ap\eS!:7t٣8S^F--f.M*`|Ǧ]wCLuRȘǬD%& @ӶLt1MlPpi% đ=b죻t!qb%bk WZ!hoY)+tS[ h/5E‘@:2ꈭos&\?Y`ъ<*U c-ej'|M!'%g&eh/f=.-~"f `k$hIT.4$EoSGM-Mbi~c@lU<{;Jr.>.t .N`XQl&g0ZE-W[3b2b>Rze#g*V{`֍f^-)%u2 7vG$IQQ#geG 4&%@muQreZP[gB>qh߇UCd1tBk @ϒON=`N*գ?mSj.%L xqrQbY\Ǿl=|5{1}Njf!u s\$-x~.o΅/.<\YZ\4yy:cHy4|o@L|T8۷?JqF Vq B(_^#{d#kѱ9lԢ*K`B|S=}1r|Ku𫂞?YЏi0VXM^VtADF>:%ØX$ $R㘥zl!<%8^fd %"GslӌV "$fcm"gFqP`|6|eL0DNtQ HE5A-]7Ÿ2l{L^B'ɍrEmb,~Wdօ; b,@QGyv^)o-e gc6>6#:AT߾-֓&nbs+wpe<=Ib bkˈ>qAH3N7pd*t_&3@'>&QŶw ҡh#fLƤdwnkl};H¢9\H=y< t~]\աI/ XB!%q `ϽNpk_}IZ[,n Gu +x@ KM]aߕ?F'Tbp@ІL|j7zE*Ώ&c%_q-7K}nmQ ^.=7Jz% ]ʧMdQQ{dȋ14$92ٙmJ[ A-Bsd Y֔%금6шY5'ZYq/>W\'hEFf|ޤ֧ Z>SWdw]WD$T`O1UbG8$]sN"[2ô+&1O@B>TVC黢* +$c5˪:\cs7^Abߘ,?Y0el^ZVK]?:"jÞKH Oyۍpdz`(u:@fx4圁F1Ó3c(bQQuΗ.@Wd@fdu /pѢ .W' N2)}G2`-Fftlv.,!@X=V1KyQ=%Pd{JHFWagB; L8Ӓ\>u PR+2XBⅶ% `0pCG yle-5{|بGXH.')e(`(ӄFGXޕ_Po˯`0Ė⭧@,]=qɇ!7ȐQB0J ^Y;ɍAL'Ñ^:d$h{f#Йcce|}Al.Q3 )K?9*͛_^SQ ͳs}׶GtwgVVXw P\ruVU#An@~QQU\T2PCA("&q=Nf}.t* Ymc-ph LTn w{%(яգ5! }EGYz=7b2Sf3dzSl#X{HX➭b3-$dT]tAX)!ט(ݞK` "ԧ\p(|.a{}*BxX-cݜ+akLhChN89 Ot֑pz $`maX}?IEA 4د`;kN{QtҲ $ّQOلC&àvw9KVλO 9" ؗMnڂl.)c/O)Z;j/E5S}c)phPY\iWFBE6/5h qK$ z7ٔx YVc.GEnZg}~fܭ<. oh["wJ3Ļ*mQ@\q1&)y)i> ˄v?ݏڤa' 崟2kŘCeXz5Wr}t[e0\6 {1-!nTlupoM~>k=w@m!⦷n~g>oUp39\h/MqC\bVFAHc۬$Bgc kSM`ryGT4bks7OѮ=w&o]ۼoC铅^l+w_R$Ru]r0RĊ.tѱKܰT/H0DMI!KlRLa0,09Jѓşq_h$3I+m@mKi0g2>YpN$ҌTd3T(BQٌ le|I晌h%j8_źh68B.7vif뱌'[D[7C۞cdKMo:*k>-?$vӵ6=)u ,->=nO MaF-v.c:H#٩d ,ex#@*EkY>>/>RՑ+cN_XKFy*X-U8N$؆GEmT<(yEO}AFy(LaD`dw#֏"b-n59.0[ϑg4;y$`R qwYiF *، Qу ]r;&-'^CROF}ԗaL9B3rcxw."5l^Q^mp~ OxY%D i7ŝD[Knna܎f:tzS'J{I vYax ]ƭULY FZ0ѸƯiD%!8^y,[Sbm];ZYHΒ(n QL#5N٠$=k|kThZ8*ŗ3cu2)3$:=h!7G,qP5:ˆQ)6juf`Z@ƛ* #]=fIΨYE?\SsFܓJ:9 JM#Hs$LJ]55_un ';:; gc19syw Z~Y?(kWd=pyvȶE*(ޮW)!fSy40\yH$3?Ú%Tfiͽ cݜvj㰭k|43m4ה3"#v(vQ7ַ B}{!8AqX{gI(:)0Cy4E?9fHΊDiYkS Z+jab6:t_̎9s*=ki\q L1w܊Ɏ/x+kbyEILg&cƳ&z"O/VoHڛr3goS;cM%0r h`<2y2s%h\=S/kԵK1rp!+E2?@Z IDŽ=^q_ڼṪxZ+܇?CYg\PS !njc}v.dr=T̆$Y]Wv,jPǮņݢ^T3Dߖ\vtG+n< ~q\d v6&Pwc%mqhlIA`v ?,\޺I'Bbʡ3F4'oЍ9eh"PP]vl .e p?VNVL !)}8|03;@X'I ZwwyXyvz}jGn%4! 3aY7Gd:_Y k;E qZ,#'RFB.jL6!{ʛaKHfo.PGD=]s鋟( [ZD^yފ`#0N|QUE<3\VgfiEK?@< #'m$XKhHxN\ܼ?a3<"`C,uz=ld ڒoݒ% 7u[NkB 2b/g q~CJ2;Qa7Dg!< By06yT.WD6bLH ڢO4=ZȾ,M"r=|7lr~&W<f>$;:w;x73QC7WNIx4G qp8'SV:R"h0TH=,xU,9L*z,;a,]QsMH4)^FlXU'LԑOО, l%"$M'䧛8}E4~й*&w5D6^ݝ#:.ZLDږ[U5=tLQ]Scg:u6 &)E*5,")V顉l)ELm}Z2XQ=0So]ܡ]'5\-N,]Ai5a|ރux2-M7WRJ 6{9 EM@1y ILX6#ۃfOKPq؎i79XC{lҪQpp9$8f'oe۸&uxcd'WFk{[/[$mɲwɆqϝS,K9{ ?~>$T}ZP F܈L[؁1S<| K̺ɾ^%axhHYڏ2#/T&[[gBP+v4X3~4΁?!Y.i>g_vGPN1&)Kogtl#aMϘp4{bI1E-ƞvLz$ub Aۆ[˻"B"=+mV^-W=:ԟkXymNB=nx{v9!C åcVhWUo:/,lTzz qE^.= V9QGJǍ]N=cs%NݯugYqȟvU?X FN9[g~[VIxp(Z,{~cfDa2܃?KɎ{fڏ]Q̪º껣o۝F( Ѩ;Q#E,e1=𱉡xmr‚L.}9삟 ػyyHa[hg+0\Ġ`&Ky&YZeɑ# I?^0]Q=Gf`E$ىJ7*㝀=5 *F`yYEHRU"2mb&0_%~8$xTjo,R]! Fs 8-ImYlv+J6{`_ºsއ8mT&`7?Ɂ.g(Y?rq*7~u{M*E6(Y{l0D]-}/3dCTחx0Gޥ)GS1%/b==iyi؝>؇#ޣ}{ƕ2 ,-?Gs´t[# s =取TwG+vzGѻ8aÏ\J\l`;k1O#?8.CJf..^KIa{E 2 |@c_K? }vB% E)ź6ooJ(YZd];BP0c!r}h֘D\c679gcgi~JgSLZGy8.M3-ssBP!*U\zS o)Q7>'~-MZeossj'e,>00Zx^r1`o:h%`?uM+Cc?1ر2?HR!p1[8;Gg)RYBtD3 @/|wxhcWן{m'bMm7uXrP5VߔkBL0ZT0dj ٻzW82 JO84&Rw+#.##r]&̰ B="6Z\n[4AHξ39khmJ'_SLAViyӌltH橍N!@ȶ@gx!V =iQ|_t5`c-lY;qnGM Tx4lBPKBmg+hRE&T.(F:֥${'IW%h S2_{Ҙ%֫qe2vЖumbz6be_-E+ՙMmHZѵeDy kr>y5mӯ?vC~)ՏTz#>A\;+= E#zxeGplѽ c/e'](* /au*Ͽ[>$(QDni7U粗>/TGiǎ~rl?&ugV[n7{GW)Kye91 JE;9ZPkr>qXgKa.2|锗`2I‚˶Et$+;>ighFRo6D$uf5l[6 .5P?ECY@qxZGX0>? V<cn?ϡnys9c퓒NdS+w~#|čh ׿}qo9nS k cdL6ՔtkI;m3Ԣ^F.yoU:E>q=֯, ;qttC)LuQ'},+ <ݻMc_V;"* }26ꣃl_X)YgGfH ļQa66}S;>kt3ٹ[?9ـal<{S$ ֢FeSߌb߾!ú=V@[{";,\b>w9U;g.R]UgwyLGqWQLvR>J8fst t! ي@CxQc5KA.OO"ВE ?53fOy$彜 vP,Ι52&RMM cRŅy>T[l2I H$k|3QѨͪ#~qi dJ5qLX\b€%|S_~ ¡v@j7?1a}kyU-souLT+h*l!+lt`4hcpCT~F`HDIlbI\,:ev:U|[f`2UeC-u-a;A04 ;OW%dTl# YVp]A ʜ%\cX*pqQi+u(ڎ*E!s;m~Yjbq/uG)bg 6JW蔷BTAŖ͚Ǯ &~s CFFǍ`k"3Iݫ).3S 0[Q%k?p+> u"y3(yWpF{dZtxqDZޫ9{ķzNIX=ҝ#14>& _eW>MvʳK 6~tdE|Y-񈺵be,4ʏ DaLMҒ!Q竁vse<ܭUc%Ԣ&B*:ns27+c7Y O_1į@18E aa}F(!o5FjȥbI zW}N( ꐹ/tޒUMBA&*h2ddcX{_bNމ{Y+ZSZ큺 _[d1Gz x%! >9`.@3U[(psۀ):hSit\QN8b}n]d&W[HX|kCpU5EkH?yV%qUd ΋'`>_Ibz^ۀ~xZGs6=h N{`wWP>ۆ2O٦={2]%O<-f u'_m5/i)>_Ս^3en iܲ*Uv~/*'zfzC ;PN-k( ;hg&U+(񨉥EXX1XK?R{gZ*KEA`^E{3k S:btFYܽ06V؆bG@Wó /;˽ 7eJ"5M1)yUŷKusߺjgU]=kEP"O_o/@>RhKE,řB4U>Xjzx7wZ}gܶJR3yWX"Arܿ`8)b'h^޲d]d#3-ŋ0p[ #M #iMxw߽{-k:=>{OGN/D-NjX~ĸqmuG_oOmؒ1#$؊X%Rj6#mg;7E5)fo"N>xWeLߏǨz0#Z'{YngcW)]g KYb_dщtƒ"d ]nUOۘ}"q-N;],M 3?HMG|[wrhs[):֌Zy̧ti- ئ HҞyۉW1EՏ*^1/y ?)@F1]sQIs?e|}b!!yR;őO³<(g 8ќD5MﲝKWm؀Enw@8g=хip (re~DۮMD2x-f"*.uWR&.YW`˘][F-.q3s9[F0$J)$9prw#WWO$l+5܇ORI4SS,ZT Yy_ÈSgވd}0Hzh__#~[|q|#GĽ|5>;CykӴ\FL 5K~:"_/cЂm\)$ȕ߫Zk=n1Ma%{~`nRN@IEph: Tk#yy ݞls@ yM&Tym99q)*$=Ac|gm尬ox/|8 KOf ~j1 @mhr#\$1̴p2ZGK <@ jIO]v4=5sdFFp?p+> 4Bu=Qwt-IF&A6TsG5å }nS:z,jntvs8Zw^y *4Ƚ:ԜУn,Vrgv界Pδ'8? 6)nH$+ј5MǞxL!DbB+Ӊۭb'[$߂\V Tѧ0L[*%?| :]֧yt#8 07 N5L̒k\ ?!<>{%mmq:Y9ѡ޳ݟv(ӷu?}3m8Ru>tm=HLE15*>?̔lxBaEiaʙHDۑ[Xw|YX?Cް& wV'i@Fw?[}o"P()|BCV\ z%&)sZ$Vx+Y930?'RfgJ:D|t 4. V5ydSKl73y,d`Qh[5V+O ][Oh?-l!"9Tq<*~9G"-|P{#F $2 "JlIÐ`[|GwYDk fkiR. N=G?ДHK.J7nYOp3ҋ :wIgb>&~AI; (IF㐟qTx` ?RD1Vhtv2Y^1H©[D%ZF5cmIܼ>#RD- ]c+Dmh:ㆠF~*ګl$Y0EGEP :el;f>\'OXϒۭMEv¯;ˋUequYcC#.u@PŘ{ $`j! |/NJb[ZaN;fC ȈO<*"#i@m%{/O$O̊2 W% rQ0C}:~SN$4&+d[9HrSObD%G :dч$TfWdl~`]HiЭgDCg>b#`w:ƿ};z/۪&T?%l;8=zq-5HQ)r+I*Xl}pC+O0\* $]6TݘHN*aMas:M:ꦩNcwI$6mBZβ2d~RuTLVU=sxڔt`[5`0NޒmyVop >nVJ,šF/2:U%1_n9v \Ye:+Y&>\*S0LhT=N&^;,-u!`$KJVyӍ4Ԇvv!)҄Ȉfp_]tHHr˰P dņJ6}nE~6z5=bvmao<t #U29Jgm,+3B,| ڐLA- Mf%-w?? 1]=Ct,a:ÜWΧdԵk/P8u$;y i"|&ï|D!]S/B6&KĢ(-;o)\ Zo,%_~eo#ٯ#85*71&̒P@4%!FmY#ӬR?j;Nq|2fɲ =l#(I9Fk9&|>D9v7B-5{\yR&.j>Fʙѽ`;BG֮12͢ʐdҔ ]Tk)?- T|~ȋpJUxfm`i #w&sB}0k@KX ׼ D̖RVAoZ4^&o-J{(H|;n227EPgěB:8diCiTI*J~%8>S!ݝ]f`઺>[^Dk% AȚ>2yV0iw j\ȝfA9]һy]1XRQ^SHLU}GMgP+'u4:ߞբc<0'CwU-}>~1֪fCDrqY}ǿsضz)Wr ~-]\|l6-+$(my c/+c:HkU{(r<:p>t92}5"ƚɵt.l .Ԩ2_DqU.Y[T?Sn2=JZ\<*NpD0_$CWs)譔|Hpc g׎.oõ19u$w`Ukmћi}?D9@a|RAY@b1, !O"+*rVPyz(0\6g|bFÅŢ?ǴTϥ|TY؉oⲙ+y:'UNiV %Vum{kfÓ?E XhWre~?h&?;'/'uPEԭ5vTݔuZy"7O4qp3z 2i 1fO%M6;AQwPPzWgh=YILjj?ic{RZK*_11^Yvaw,#){Y1^eNcvٲзk~= &sEږ\cR#:edzcBPut= kʌ#}W/z3sHi Nz֗I{,S0 k1ĨNӃ]Όa,n\~hlIxAQw̓X! (Ͱ36;"دQh dN'Q, h=!PL0(&{6Y&OdwE X"o5|v,XQDF.w̐{sgU-i2\ P>3ꆥY,L($ߴ.mVT\ĈY?}z䨽?pKi CM[tĭ 3>҉%eh/JG"9ŔH:a?06b=jvJTLAF LŇ(i?>aE8\R|[ȐEkYKM#C/ӕ$ƟHq&l4prTaHm\:,3e):b?Lz~@!ycN/OITM JC%hTb뮼|#%C6= X*;. |1gxj:F "o h|41t h  A5ߐ$5Nw0T RŠ{ȫrΏɥ[ -)@ʍKwv~◻E=xw˻bɐUt5*zAo}g 0aa<]Qk/]yKʃ #R`S92BG^1!$ÇXxēDm2=B>ZP."p13upJp.tk~j6*y^cs`Vf ,(!ٓW {h5>hכּ_aioFFlZѤSgv [ǟ K$?jL UUjj*1lhBDp7= 53SWǡzKVJ5W<I(qf$ LyZ0ќ 4MXrBo⠣S1 0SW<el89[}Lə0]CA9J,y \$cTyozl;`0$A ~3p;I^܁Bx]5qe3pn>H/D \Im+q_dr77f0Gw.Fiç})tX`% Hpk?2~>J,5V[9"^Ƒozcpc!}ॽen(;9٦r;g&ャtCἱ UEWdQ]VQm.tz@C%P<̘>meBP~6>#Zwt1 &R|BAYkv"1d D=޴Dk4` lZ'#śW5+yCq9YU?S.ڶD6a`2PJQtĄN )Z[%FEM1mc 6-̅c8-IDͿ"9$yT 2uVƫ!0!$ ۉܵޡϢ@% e_[r8_;YXB}˗ nQj_+CHbSu8kK/P9J$F5\lkqa YblG0GGޝ5iu T,I$啔i^>ax+\A`=$sᰜ`ʹ~'lbF ԮB xS闇!21q_`d`'c|r/ \c+*{:CP)HXuJYB>JO@%sr|NGR11̉T"COs|Z ь?\j ^etQڹ%8h;.~T,PKRǩv4ScƸ ?M0C& Ido=UyuJ&?DA#n=,HXɑ5I&l@~1TvlcYҙ%.1W; ~DEs̬3 &B0m~jic b4WgM%eO'S a(ZGK K2e ImcCW'!Q =Cq]@ѯZ%nrx;6îR t<"[ pY?T)3|t5dœsDBvVQbZ~^N?W[j`no,.ݠ_Dm sS# kU*dLEb}, RʲI?=x(uF\wLq\v}at;E޹]T6ߜ3rF{&bRh=n(<<:a3o"NnxPBOVK*ہ)}G{h[y |&jiu[|Ƹ4 `}v)k<` .9b [KvgǨ򱯃.&kWCq.>9،"YHEQ{nFO}>7ϪDߋ4o7p R ; F6UKթLi] 'u FA)Qق{b4Gަs[ 6#zR$0+X02QV9M"ùP\n%*$Qq]e>[T2iu=/EVXu>{KqAX2S.sJlɺiC`vkDPqMb'ƌO-|*엀7AVًfK$ybG_jsTRY^>;ӹq@8_ 1G ^8Xz¸{DŽ 851}q 煟s۽ttՕ ցZi Ԗr\zb%P+X UXԬ%8>Aв=%+IJnc16+f2tX-sɡT~ņd*Szե娲/,х'%)Sxpm S$*ԗM۝1س- 3=Zp,{b뙅4Ic(ĬVFyȒOn*@ BT~]oZLRQ$E!#B֕aRMҙ71cl?֓֬wk $H&U\堾\U" PIYn UXQzlIe0B9"CJtjrKjGK ({ԴʘRۥr;WppA3[ovOٝXzM9;Ky#i!K-֛ԮIzt;bSvGd SZO}hJGSҋW\aL\YEEϿIfI\_\!R6Уdҕ:/Yvɛ4KK-8荢 Y7M's #h_ȝ|Bl/ jZygi|ŷy9.L1,If7^WTXv K=̼QZ1lQ0lc=Z1Pѣ$&QD _&^Whn5Js7VY1);] 19#Io%-*^lsl:϶ /[M/U>mV(г>if6#kS}J\3D@CK?vh+qO39.< j$uGp\EC\g}}ydYL[6M-ccL 4  ka{2)@'h[q('GָfS=jiAW Z\j4;C,t#sq7FZZ/v&Զ/&5+N `#(>9~.=}H{v\AE;69H#(#aqG<,<8sό#MlIxm)`ZCm-I27梾NyOZf1NSf4&oVfY ٛk "scm[\&O=_G<KO !y\8F` x7VEmxr~3i&WLJc؈Cs:?ht9. {y J/!PXN4UxҔ$o൙+Jyv A^a|s:Y粉rAz qd~Bj\ If`珴oSX#z zޙm %CFt5IlZQ17!TRA[w`TpOeܵޑh0Βֵ [U+8&#_ ˠ!q FqXgn5As%#36㰩vj1 CEh=OWu/E"ʿ e'E>/M¼+|R&bv&$?hO.SNHg%Tzs)ؚ{މv)2p#J18;8CH {LpYk:ag,ܬ&mV偻߰ΞHe8P?F C!5\p»x,7?#mϐPНLE@u@f/*]#ܨd.}B@9>-J}JU(Ry!c!%5 lO-ɧ~7V;y0PJ[Xup!lG[bpbhZT]uJ8]ֿ&ߝ)xx3eWpaM (4%xYhU Zs=o# zp(1$DZ|a=8%W:<M ?̸M1 :Bqd V0Zn1}Gj㡕iËE7x}>5HQppC-ɋUGBpi:=ᩣt;$;:B bj$8(ɂ_]O\M@n37L*)up5gxH0WMcar $ ֐x |5 X8@&-UՏV9H|ҫ?rTKSͽ7y:+D[IxU".~16u2m 7l_yS`~,9֒-2vJX (uOv/d΢tRS^fI1+hWZ+)7]|TMBkh-B` "qt)f%#ӬuX| b $CUqlQJDadH3sV_rKJEQC0Õs<uVʈ+^(54 a+J_4b]J}' lR;[1a¤7'uۑI5@6N#MJ4 ~R.crc9yVӈo0w1(㹿^!O7N KCB00xLJW!xvHY=<A7,D, Хfq Y& )ZՍ \] @GJ'-鑿bUY 7D'Y [S^bؼPcy<3uF(0咸NNV#m%^- uH-~=$Vx(_Wޮ:f^*.\̪u+LP9rfo'p oD@lBhg@}:N7R|b`YZ\bV 7}2zp'53_T %%ebm qWWa+Wn 6]VF& e|@vetfG G2t٣ٳawP;8 KrKNkh3萨mIӤa6&Cg =C%n7aڙ|@Jzj ^v_ [ݩG4秏jzr! ,}( uC>u*a(֩{%sicWkl9 7d}##ޛ6]vI+:WC9S(GWֵ QeXRr@eJŐ\L?@$yT N!Hx̦C8xui&\>t&&uӴOz!T9F˕>,(c2+L2II;<85_s/ެӧP#dcN|Qmg@έ+ESʦs)XR[wـt -POɄɫȠʺ$ ʳwC2ڀbfɼFCT PNS5zWZDɖw _<[yX0q[8oS)H B?q߼ѧ};R-CfC :?: ppsx< 1] ]o;ЛЛٷBGzWey !=z - VGj},8$v$iQ*qv==&(nlٛY ldF"NZ[FJ)\ n&fλ[Y(zd Sǟ{۳&cI54s,0]C%9AO K̀ܙ{I*:,?^1%[聃dZG%Ӏx\LU0uЋa9WJs EQ v@3KjCwJ}hi4D*HWNn4~HyI-(ؖ(*c@cjf0c"pڈOY>‡ (]NJ!n:W"eo8UџĶ{/ЧFɯx0i8 ƽXVAܸۄw]kɯ;0 J W8Y4x߿QNfxۨu ȕ5U6 h\ه|d-"2K&f*Y'x?-izp~ڛ&i+aVP%bCHdֽ7< 4WW~ 1@ǩqkj,sDYߍ4qt@W ۧCm )\" YMt` w+Ggxzjt=]O2U&K}\O^fmbxaɹQ6d| (28m%Qm, pRA-:w׉.97vMM9X7.\tCɫ3joH6aĀ"yE#]Q 伾g<;uslGyy^eMY`<~^O?D迍Ls~Is7egncO'*Xk۩q*X+DdXO :_~`熦\ϠSʏ+mS̟yš1蹚Qdu;#w3"Ge(h|%2keYOdDՑQ @`OYUsI?'9=c%i`l{Xv' k@3:*Q>(JP{)%B&DeyaZ.z[\-n`:i*R 9 |3%2gN@Dxժ5ZK,|lN5O.k5q(r `=esg j1IbZU_TRZxC,#qfbM! u8R5`fnoQ5o?|9bb6;cyU+$g mmcGؤSIh%,$b1l̐xn?0wp\]E5uUbVi,ɛ}iȅ RfMf$ !y6B7L?ll1Z=d5)l]ove_t (:ϗ0a>#5ZGܩ}(a ?փ+i!!wdn_&E7xѱ=٬_MH!.{Ո!<=?c=ډz5F◉lO[5%e6`΢=\ U[+֊Z ބS|.yKq(y2-fc}ܕkQvIьG+QWef|uoruJ pzaKLNx=cQ}AJ :TGCb2l:c~:#OXTɳ/e-STcӕ2+i쨺4-Iӈm3J܁;| Xn; &=58W:86(niG<i/c {F0!_-`M|ApD [2LOȟ.W eM-R5P>/'!KۢnR(l<+.lp(^5K&⦤:D8ݍ6{4 rZΏ PsdJY{򊜘*j5)IVAbE\ 9.ЊEb}g ʠ@cWU*pY TăYU,2/sO/dܛSC5)Yd_q=T=BNVMVVie'<)#kxi3fY8sǥ1}oLƾ|s_T{(!lUMxZq1ȆK*DJ mR_D}rƬeLyQYh D@}q\qC<45iVBz@x~+szzXpi8A-&'&o S=} nPsHwiD&%l.J(> J,P"q<]U{8p-tc[]c̷Oe3#jj{ Oi)ddNɜ8(Hjl*qo.O3b@6+nP)8G<^tc47'$ni9 Ps%1r ` >0jݛ<[V_FzUOlN )1xT5Zxrkfrq^;A=ZC? 6@K2ϟU ro!~>VvVM'PEÈ(Xm]k@ݛBW^!74QgMa2z ҝΐgFyf@ONt(u}]ݔ15{J>i_!ʯ:,fɳXgxThM60>xET1eߝ3ަLRZb*ȢΩjrA83 #tF%Kse\>[9UKDUG+6vO8mx*# *lT41 t!}z[pI/f@fȔ&+t&y ? >ͪ*1Γ iyZ֢NִkC-G," G(]E4.09asn Q#쵡@A(M4uA7"ATHd@ cHtͮL#Jgp*'l}JUOb5GԎJbB E솋j ߄*9skGsI0S㕋bL^]f)/<^v >DmG5m>Ekf7puW܏(PyrU? } /^{<ɭt(xTR{.$;~ҩo"!GT:`JÀ2h\ݲUbTmהmtdKT(4r*eQ Sw%rA aRTjeP׆7DP3qt\LS𶭳T^-Z eUBJHzӟ&F)+J&y9!GBQr/}+DAw\< >i5%ٓ&˃(\ S_5"HɚZ&(Vov`ivL*֐1n'QyUo2t זmvhIƊFR$dx=!ȏ_)@"PoJJyޡ]6j8b5bis{lLF;&f+/c(S_$²DXz>']+-#ٓT.K&ڪW;Ky0.!ʡ8Ky)<#W$TS,މٱfC[73+9"c69qOѡv'DQ w[uf򾘪)N ƿS^+'0T1*`0}U\+r` $㻻f6l"gftp?&1QDkP*}O|z((+˧_>ۮt*1<+v(\'d~Ŗ$ԞOv:M$g|mpNB}_-_JDhFJ"- au9h;~*xWbQ־>~,KY,,:.鈵{vkҜ\Z%@NZր=x <+]p_oȷ(.6EӸMQ%]1%J)ת>od|;;%~cQ9 :P,3% G=4VA9V&qe*1-Hq(x @ivQ /B}B$2Ü]"S ZeW&O$8 ^͚PNXr7ܑhW Ti%"qu ּ-Q#2dAA[6U$p2G-YUf-" oP}F׽s|&[λOԜ $ ^'Ě\)*N~78iE WprVr9\6}\$!|CueP0z`-0IJt̡6u!&o9\`%3]c jx PTL(@e^`sIÿDҫCs>c#g 0:C(iRGbߴlB]lUˀ~^|Z18zf7~ͷ`yk ǽ c0E̖o\gC|6D<On 5ZC;6SRl|`]wW]<0M̰_++57Z> g6%<t :⵭zB4{uuvB4ރw մ2吝inu_n5D ,6k#q_3 r 6hS@v<Q ,YcilzT4iCaef>2Ũ*C ?K97^?S1r:!RSn脙Ż"ZN*?<,VzM׸5䣮U|z:W"$c$pxͶn;9pkAPᕹh"E{XϾ2O},LrQĺF-usPS\#kAW6 /x)6r=kC]ʗb7|-a$nbھY ͐%wAoR"777-IN}SPsj. )\r:x]BLmڂ=Hmt|#s1sR!t9nZh{y\Vd\jvmb}ؗryQ0a Ĵ;"[J뽚79#בaS@b/:~D!RWy[5Lc'ǣISzѮȬ䇧]:HZcN΃yo{]49۠oxB䠖\m'|iB !PjUsB@L'j1x'|+Y<7{~aYC 25іY(r7j$a:nV0IU]s 8;zy0i$l #^ڟ ~0g\2_|(,[4"N"Gfܴ3_{בK.XQq>>X+k\imXz!͚RmZ^d Vu3h5?,(c2cЩR 7jydt7Noje&9T}m{ڪܙ|n~!+'PW;}v2^(+4~PBL2P T}ZĢP'B&khz!(~5o3nD-ӗor,@̈gOX}OGDR]~F$5?㌘NzJ- }ƐDw>j8 =1f.Q{^k}ɍ*oqͳǥv1R~bv{k0'*L(>noƓi%Fu|S(>/VJ#W SSKȰP%UdݭjQ`hii malE6{|v^~p׈5d3ل =8jE;,et> ;rj]O[Sh׀%HVN $?/0)bd/^m=*)ANA=l3 Jh3fp1n/nLikrJkF)yaD5k t+$[v4z)))<1(|ķI6DZYtbh m7d&I%ݎeL(ۛs0'siUᜩCyinpT-)G*e(LlFz-H{K.טzX8iY}pcBN<GُGrHv\#i ic⻷TZ "z$P*⌄xb@򪬼x|K:|դ&p{_k>_֐hTY#,:S 9tw55os~F1p˓S]bJk&)x Av/?ݞ_ QCcx6!5(2:q[œ P`% LK&f%$x\%FQ)BHD8*֜ $Gmo+9bM+ ȮSւDuabvIyX`<8Oʲwa;`⧣܎!8z-7-wTz~۫,/juOWɶ _w \+Y= S6UJ15*rV kt*KC9?nW[BZSM#}Sm P)ҭL]g&ΉBh׽+aNbmv|ZHt"FSBNgWpf]Nq%٨-6C;=0Ƒ(rWHit;(܀{c?>BE:@D&re! ]}]e23ΚJNrpkȝ&s}r_3߫B5+Ur<_@>]̋Cr\ @[F7E43o I"uٯY8WE=eaoDƫ)WYKGHPU7_7e`Ž]]N`%L\T(}a'!KqL?bܴʴ.figF t^8H *"(YiU*QQ 듑>Ř=(u[(9z4C`ʊ7[6X᲌N9ybGt^F ,g"O&VRtF{z fۥ?TO+KmBoyZ5InWLIPSjFTطtvJ_UD# 'r|䚀YՎ~CL"OÈ~LMis|\zp7%dzZM5pd`;ԡmE)W؏Ű\EV]!,ѷu%|R2c23 0wލːG>)`{w`[/LbR(XkQ>fG~5znz yӪ [Y VRX'4DlqL!f:G춆D xIbcI++S{wONRk&z͠)_5sP"n Zcf󸝭-/z@7X\q0?x$OkQ#irqIX \< 9,&X^SƔb5J<ɼ_.4k3w&pBUz#sK6HVʧ" F+Xde2T$8s']= X}1*`)te xJ MVu~6zV^k<9gC[>0"p}Zr =Sw*1ԠREik 4f,YyȓHRHL6j. Q\ ΍g}ܦvTpcO5?]{tO8o\AKa_2 o:ب<>a]W0ᘑH 6x7-5a#GF(BM.VUL?n6yE g ݁'糎Z2rPbShc㛚Z&_>Qӄ&4zyW Jr/`ѭC,Կ:Ih.[XDe X1mhGB;A_ʊ8 ϻc\u Ҟ[ brymŻtk:Vg=r6zAM$y2")@.vY@ҖKQ; ^xWg R ;+O"A<ZR5JbiY^r*HHkCL<2ENS>9L,~w/P:\7oa`ƺrBWE44a edo. [uY¤ku;qQ"S m6a-\]J21nMWًe0_9<6&AJ*\r[aqºb⧈JaG>f=QL_IeNMx1B5 OEACWmķv_OXXYӈ+pQzz} KjM:^BwU ds]J.=(|u b)kV 3e_^א/Z_7פ7x_m"i6P֏s3SZeOT|0-|GnjLMǝcAnRP''zmP O5^Ls"/\g  U }9V!Szr,jy`'r 5tL \USo6xϻ?/ʖ*!瀏ˮ{nAyԱ: +[$C(cɶ 's()(X7MJ*/5hԮZ]wL /F<`<{*ij&ɲEZM(I߶{ܫZg[EpD,0^ [#Pkb.@{s}#W_ף".)UxbڳLIQÕ{&k4u[${_ (ZfDF *7f˲cR 'W> jLC2H-A~u\C. Celk=1  j]U]D\(u@TR4TVa>}a] NASP;Y.ϓNIkGz C7k%BTk̩rQsldguQlc>d5K 54ӡ(Pݴݢ6Sq"3GCuqmY͕fѸPv@IMĽ`?ZWuEp`,י] 4"1֍w0%8n"mMt1m؈W" eAtW'c!/v1ȟ%`4O7 !^tBخW&jPbFԡ+%+'@[&}I$&B1Fy[pt=>M)PMFQ\e"p5hDdހ^n#[:Nzmc3Tw.%6u2O}jqlRRjV R`d _T(M=f1ᙤmb"v]M6s<ƕu CH*}s*a''ן 3Ny5h9@{G4@݈1Rș(Ry]Miәa񒘉U-5>; \kVpHBSk6-D#iNV٪Ƒ<HѬ&YE&.އ971|=?=s C|u|nۖ ǐ=gqg"LY~r8'm? Z䲬/qQ$| ?kV3{A3b 6ˋ5xW {z׺>)AϪKڟ^_NӌCRs?5#A]J;2Bys/nt.|Mݿka6>ZzXGF#l\yT0Uk@l̳Q0},N['BC]2@}jF,݅ADh7d+y_()9֘o=0?;6#_ɨ{-aogf 0Jګ[[}ͤ>Lj&FN"~ŪAxgU~qk~Odpr^P$zLmBi,wӆnKNӾjgn4&Y.Y@bTrntִ[8kߌ n֚1ϿFi2!7j+O`/os.ѥ?;AlgýZ-*ʆyOn])SNr%)E1.MyzͺV?q9Ɖ^XT1m(s,fF^#q[ _1d?b&ANy7+.K>H./Ͻj_tKd|ceddPxfPR"dVUF}5#Ɨv /ӆObgăCnCk!Τ2j3dZ,VFgFb*Y^SgN RfWV^̭w .6[ٳӇ9o.I{۫wNFIn/t Aܜcj+k\ =&: vZIh OuOM%0Çvb׊dYW ׻Ju:+?#iz #9iU5PGFԨ~(@@R[PL7t=lBQF[o)|hDvd ^j')5MSrZr7'+NzƱ_J-@2I1#B]c-Fh*vBV{{~o;KuEvo , =q+QF %y]Jخ)MAeP$ :F)i iL&<:c9*v;_5\oJq<Ƹ#_CJwt@o&MwCE8zrRg! 10߉r^KQ|4[&bK4qtn_v0#^",^5^"([r73qpW3I=qUcL!NegzWm°jW2ݶb ez뼲`P uכp&Ji,+!{9s;T.t•v3W:CPҏصm^uBB p1R[;*eCDxf w&Nz!$6?c OaLwi,*Uo83|^FW,@5SP/1m+ɧ?yTࣜppЈؠ:};>4394īeW@.Sy/_fS?hRf܍v"汧Vm&}z[).)~p1n%h,[/c8a94G ⱘEzC^ Xhu7bKF!KFj+gk!em7gVZl{lπ)@ȉ¹!]|ppi+%Yz(r@",ӱ4XcNB䫟`՜~PpKXԚV$nYoܒ_Yo,Ѻ+XaW\zTLވWL7{ˆJnm'b WMYw_”? !vY5Uuo5#-9c{.M;TCm6t)j_[˜}t@N=T\$Ԗ,Dhr*Q[B޽ Ǫ7| sPsiBE+~Wo1SAϭm iZp 1{N_ ޴&ЄB J[A#V1YݚN\>),F˧S!ZNR3THe(sii,:ޥ0mI!e(+-.-䐧'4BաLV9p9pvSU߯`ݒ)!ʻEw{d3ul)Vm"Uj*b9[.tF.Wf^C>.[J= ZI=NAL>NTpӄOG$=$kKcX" JrZ}o~;"<}*#hO0,JtDQU_B|&jYF@e۝DzXQ,6wHD8z~דkdE!MfGv#{a"c\$A)QӊղK8 *ep2d0e[?}c)9;q6Ҡ_/bs-klE qmjzP[*>좏5haZvEanS\ 6"*]jU)F/!y)B TR1N@9NrTӁ>m 5:r Y(ʭ,~"W)C?B!qoANQqvəH7bKr*p@o I"GTT,tpH7`W,¯tTykUKԓ/RZn4 W2~ v[> bxq6]2Ld쮬90Fa$8׾*mod:Tḍ`Flh=*M[;2^JkwV\#^Sɍ#!MͪB:#P%j^䷼ >*&Y$0a~o08_bxF\xnnPƛr/Qys;pOYv7uv6i|mD S-(5:88Z8 D}=w0s-׭~/R9os:ƒP\Dj* isK̻icQGܦ7zOkh;fkRX+oO9c/IIX)S<27SR ?o2O|8"51Y؃IHĿ!X>m5_JX#ʏ*Tҫslh{~"it530ȱLΔ oYjD?3iCV #L}kWJ+l15&-+) T4^B.\Q״)-D/_yNAy5U)KI)Xobې~B PqgW{/I`G} l#q;pu\;׭ - m׬C4gXc:yk'>8^g0tYtWi3v"O ľwD7"2wLX4AG#o* يׅ$.VR(o< Mt啨#Hu!e}Ȣ8V\&k- DSˁD"++ݓ9ש};~O+N(":C?(!%(bpوKr=f!oA?B7_wP$yW֚`qQ4S\Pi߅ sU۠ t]qYzT6K"+!~y:q#/\ ս8Fm4 _ GUç PT= ;lüAM~T:\PwrX5+PRT/[̓X |0rjl,^r UlIFfiLm.6^\ԦNtq0&/S 4Ь;ٸOsf~ôYW@nϲeZd "~q9B(jU2bYjGHK~R`fא`8ѱ&#EP~?}n43(QS4\3EfP7mHBŎ9\q߇ǠƠ K/ d9G}J%NP BH3P(Ao R]j7 -s(0Eq)[H҇G\I[po"D#M4{Q__њyxѬ4<*& B<@4gap9QR0F.ґ.g]Xu09hkbԎY;pv) Aq|@YrfF|vZ٥ȈYJVJkQo7 !qJҵpaT&I;&~m?wh߹JŌ4fNY*AÐvرkQ:o{ɒfIc_I R(&6vR(X^A?%,$:=4#xI)) kxv-7Lr2_x.u5G׀7ci,X!8 ^:1# 1^f-Y?dZhN|=:+o[IAtn^[+ЯH8&PY*ȖՇl86\"y6n he׍/*X8y0Ύ*[ 7QAiW- FA!mW,/y%z@VEDiO!/EzMhѥy^]֋oEI[}")tL0LqhM<5 G"!@|Y7q!@sRZ\8D>h'|I񆍘RP>2`pGzVu 3#@cBtCtт0f({smY*_TjN5=TGCS1ScvEۡ10bp\0Wy80t_k:!C?Jaǭ~P'Kbÿ%=ީ۩ Wg1H^x-'7`nrVf` v(PHcs0nd 5Iv Fն;PVw:KnK+\CyK/h1 ݲ/,(aBql`-5eԱq %)=V4D{U70h;z*lEDˮυ5C O@h-*O+=!WMuN"D\}m]\P_ x:gYb}vSb3+rqg'FU'&aJO膗itXxqAWh/eg5-. 6{W9*R?{z-1{LcbkĎ_K` 秱NR n9^V3dh9=Et*uY9!P *NBU1 Pf) @H ThpX"d^g y:`ٮFCW6e~6m9#= "=S䠰#}Li={X黪u5}i'):pu>XF+֌me6HQn߻h >+}-.03i]Ϝ :7o^;rWDSN;97Z"w=(a!] *>Ƃ' I(wZ֓l&&+ՂGri|ۙNr4[7q2]g{atHJݪgR+vޠ#dN ;⠁<NXao{hNqcDۊd*~7@ߞ+H0G{{fMg_h3w){!XYuׁˆBT?,ClwPt6(R D \3,_yj!Awhٸ#ȟe^ $>=őNYqs[[mKwJ=h%^>rBn VPmZױpĖ6l>SՄQ.P 0Id`KA;c{10*w=}ՁԄIsA̴=Yz0| GзkDFa"BZ5$5nO?ӟ̮Ǒ=LYTWH^WpaÓQX.,?7 & +fT& S!4qyk8yj?)PY [j//K(zB &!5WY`zdl/CK² oUidޜ>_v 'sEMڣ$.t^`R%~ "ɡ3~JmF2Eu eF֭ .hMǍji@9PրHgv0Q5o䫅S㺴ُ]Y6D(౬ϕ݇-GcmҮf"8M(fHL$e `߶uiXPwW!쾹#=#˲ O_w'j xr(HlE5]s*&h)5yɌ ^NY yx bd d !& un2Ce2]gsYsE+"XZdX_VݏfJڛ=$Y<V}J<J3vY.EBQ{*r06m7p/cͷ{X6ިھ$/H8Oԕ ъm߭`ۨ?@LB\ ޟ;'[+z=P!4ث&!T5Zl- -8\_0;mξAi*ztz^i,LMƦDal<&^iAW@)=f"5F*&?)m  )ěm*Y " xXxs*W< r=@ $gvRf#g^O MxթY}l>[-/J RA.LE1Nڪ^@DдZL6FM?Ym ܸvxs0}0K\2eHŦɂH80 XG/ U,GV0>"nKp˻``RTh}FT*Aʛ33v]=JF4mY}{8da+틡.2Ls5YvXrJ' i{Q0Mr>g|rp۲:]+AqS:a|8U7c׊)^MLMxE#o-Cϧ3fJuetZTn{w`vƶz.1%( %*F*ZWvMcd89Q ]%eݓ'9v1^=@.JhCΌ/SziXv ﭻ|j/#AفuOYY4|/2Agb?,jnB>%lm-GeRoǪi@|3(Wa@/C+yTh񣮩TzFm6ޘA_'e%^/+yJm52XWT֣ 6 N ZKQ'ձ`+^t\b99^͔'^Kr[PnPU` 䵈$ʳ3jAWK v{\*[jCEhqnx2ޣK+&,}ӇqŎasH(": i`x[mT (tŵhSAkhfQmkOny25hd(fLUrf 9"%_f{ =Z* z@X@k@g6D8ӽܹ=tVkiixG* 0ﱖvZyzectd #+\E elK"E 0J +[:̠*Ffo6z|mb|ʯ sOV b(>#7{dʵd۔WY8%/_\~O1tRR7"ɀA0T = g͗,PAf8@Qȃ49俢QY -ƶ[PYO꓂27x\}ThsCrG1JFF#l0ҙY(5޷NvX&qEm'J]TG\="}l^'KC'-4l*J8KB\rܲٳɃoF _φ.Ύu-^D! ::f{Cuiv{j~a/%~'dl\IS]=aM=U2=J#SXu-[Gcki!&mcp#'Hyu~ll= V* D Ůs^> 膄 .CmXU`rM5aR4m1%]UF-e{S ďlw±jPUgRG$V[ Y5Q5)s{a uϬ nw,efn ]Qe2Z {WɚY qӕH]SUɫ߇9NVR,]f+Rp3_4lvIO=`DdIB/eh?"h$]x:gv3\$͉ɡB ϦP.5jZ>~]za+UiӌV?ネӦ"@_3w9b9n4ߒ\}M60:: $L`},[~0g[=^8ZmI> d(#% bꎄB6dH254d8$˘S$F'dޟ{H4 s̋t<@hXD{9W3ngR#>#ac1Q6v1ا,ώܾvp6i墲A f m׎s?!4w(y x1t^\ LF( HTE5&@ϙTyGa ('EBCBW4̣(G`څ! w;(_`ʕMnbcy^> Lm }cyLjg7jS6twpD8׼RDw^) k mcbidϻT] n1$!,OĖ$G&f^F' Z2dTJo>c[ٰpt䓲Yb%P+#e`osiw4)qA=YW Aģ18#rxsu#\* ש遦 &@0@bKR77}K]gx[jm Y;AeMGx9y@kI GJQ8#_96e̟R?z*uTpE˨+K]>^w;|Mڇm\z1}}  |ŠM!(m!8Oim=]43歅A.4Yg42'"uO" OfXgqEw"\[ DPT7zCOlKhN%!࿖gIt:TdpL0zП4:8fMsw(Nze|95} 3p&Z豩t/"5c{сKǤ#!:X+"7(Oo̍;伻m<>]o;vssea˂a>Q^.t; 76ww߅;|eU-KKIvej) }TL J F`:smj|R][qLJIg/iR|_p]̀I7clUOf+S&x/Q'I2 R8WD`Ў%'}jWOة1vDA61tE+_sKq !Sqx@ (u=!77=.T,>zbeG-QQ' 4tpF >_"8H8D=y]o .{s* ~h' %$x e.R3o̳x۴gi^mx2RyàIf1W,6]vZ|, L7r⿕FԲq0EM1\j۾%JFXQ thYkOQ  _ ƩELkfY^ky+K,\(v*{,. 3Rk}s? (RW :蔴WЉU\KW}Ѽ~4c#f?U~& &cD=խts|h\q&iǭ8D2\d/0#ʂ1Ј 3[uy!6=y]H3O+8qr^@ ^YT.9.?92C)fdO~lK,1n|%1AW]S{)v %l=\&kphc }Äx%77F\O,ApF"*VN,s]vG1[Pi xiȼv_f .X`hFv$#pebVE )GxAnN “+WB= KHNĀ9*(VV. ,]OUj 7n.,:k(Lr+-r$U 8Vw{N]_dݬgqrD;ۿZDt|{fκ%Dʚ(iDQ!礦߶aySuӱ:ʠ-|n/]QͦgNE8PlCag8Z*Ji`^>֭fj#a)666x kP{uk&8gT8f7R' /L;?Jĩ^K(d #OF*=lprk]YڷbU_U;MAfݒD{foT cFFR¤UAm*~ pdbm̆#6yU;Ri!ptW^gxte|.=~g܀㐌@B3.>Q.dQT|dfxJDvpkC{l>_ UyIgDͤ Av8Oʣ^Z 3*j@䇿2ɘ_Ѭs* y˪I|ywј^<K./~03 Xqκ a =k1-T0+7K2Pk Wf#wIcNBSx1H5등7ж'V\ Ht5vZ)CDZxB -Zy$}Z 4hS?3u)hP\.VcVŻU4Nr'tPgwvlcqM|[T A*l\EW(j7 \k7q>i$Aompj., ۸# 2Z  Ar0MC1iԚ 9KOwhĤ)T9SQ˼p5 0@^[E7EN4g붛!LC[P͐qkߦrSwqb7 Gcc8c&俟 @pM1eZ\#L -KbӬ? 6ˏ=07Qu%&RZeM۫c7Ҭ<BPJ">DA؉7hZ mEPq7,6KˑsӘ+IϦP4_rm!FeTm!xvP-2 n'I %$݀`w zYJ =^~~WW6K~gL_9*}r&OXLZ"4 6#7 o5u\vE=6&Ͳ3*St*suXָud]BA{6dD^,;>#"M:TX`[ Y3 q+:A+eص/4M K _={]TKtAANAR'=eɶ"q|ϖ3,(W g #%͇Gzz\UaB]k=l$L*:<~Vu- ,sRn"Fmrހu?G#Q=>| ֺ"WmՀSR 4HbDC 른p UHqs4LP8@kׄ[Q}Fg^R8LJb ԋ ; 2Pxj%5HĘo.9dQ}|MO2!PI\eBC 9zi&"tpaO8̈ܕ{tSF.ZokBAՂۑpUdF<ύPL3BQr ; Q{oA H0y| ZTOo0X(0<اc0"΂<-҃k|\%=sFD2 Aow㍅O٦`a&P@Q*>!"s`?ҠXz$snuZ{:N?1)v~?/Uw¶3!Ip 2*K;g<$5qBE7_ȫMPJ\nЅ|jA$UY+'c>YrU(6)a\W@"'-PRLm.ui$oUr  bf23xРⶪMhWH>JxnW!=ݓ5KB48S0?Տ9LeC ȬC'CSx>LL"#0j®ya]0uFFC K8 BCZ;[$MxA1k3@IoĒ/q54L) g|G֊l0!CI".>\wplvcIf}HIaSwHGb_]Dz9fyIdO x.R/s%Q- h9/6( 47_}李wU!C1U=kM)ֻ٧V~m=HDAo.Sܳkl2ނ{ [O1!c^:k40P^"u 7{4Y E 8 K}6Y'٣#@u7!03y] )kwh0?_O,<$:X/k3&a|Pe@O]ܼ &ŀhɥmQcJ, l`FDc1gRY*wx#:F\o r b@q  WkIl2 ֕N01,9&3pt:hȒ, By[Ct[]v*}t?A9z?UX__ϧ?A jK! bE6Y c>8$dus]A8y[8EWOFzƝo-Sx4UPJƃlXjlF2|STZ;%&Wޓ6 qB4fr5U]3]9|ŗ,/^D@Rc8vچ 4ޭ73h缱QEp:o`Z4QߎǷڱt&:$?*8@Lr@O|Un~*jҕ5% N fiƂL&Z ;-d{׃)f|izəoQ&l88&gpWS:.*Y&)mS'P/ˋjwwQv|  Q[VOv$NI+.jw ^sGS1 =UI“2zy0|06ʈ7!_Z jE>L@xWg_(Ӎ! GEknsϿwi 8gu׿#tu`῜DB'PTîtk*5í39R|K''hKU˳UZOtK{Okˣ 3ncP (y!FHcYE}>!o$7fq#az|\0"@MB09ODgX7ai`M-5!^yA}idl+Wj`$xѢͼ3EWV͖ (I4USBJQ;!\3_FWF74R$o#۬0fD⦓- 뚦stQV5eu:IY;ǯrCD)n& h7F%ɞCw*MJZ> )-6(YDM1-,(06Okqeʽ1zLBfEBkuOTN} LoomgX&{0F;QUi^ fׂH"HUez~y҉C\nJe휺s25g_Y1N'I 6b?F5OxY4k Ye:}!M;K #B݂8A"NDV_ZoyjE7m2}T_<08_FE .3ϝBj%Q'00/"rzd)qF{[[:X"( ' q o | bJ]wk;)2;;,j[V8fV*1p~HeA[5#WI0J9coEhhߧθNV,ȸ4DA*a i%Ve l{ڛXAll>09;T2<Q{|| oo!mGK˱Aa?0jKvmcԥ$''٢ɮw'0{Rkh\n- X2v,YhH3OV;05LbWAǰ9kC+;ߔzm#p/I.aAiԇ{֟O^zl79С'O:([h2hN1vFi:Y(~(56 ,P"];e_ qQe- D8#vUzXe!7LY;a dTy*~YjGI)U~Dw( M(F_ x–Gۓ9umsH'B(M5[H H3hu5QmQ, L̅@E-K%w{l 2S:ϱgJ[) ƈd@4ϧcLD/P sq=K8Fm^ɉ,g뛀:p(鱼S=1%kgaˌePXu?2KThk>{f2JDILs1b(Ҩ.tO-7_6!9 [T]Q̷1yz\Ğ[\4sx4,NBѽH?i0CAj iקc[ޒ=qvt'4WbM{΅;VLt {I8FgO_J'0TVw"k\Up^.8Kp֩XhƐ22D"dX Q M2TYN +M&.I]{apsB$'G?:oWKg{lYOkIk >R H3pYB@ȴ!"E uBƚ%BPvWQ|:ةHAB%XpX4DYFŵ@{jn{ @1kDΦsO|OaIIֿ>uϯh i,j,ܞrs/] Ľ+%U|ָmu~UfYѱMwg0Ot&{͆i;˓|Nup֤fi ̲K"Q"9]Hçi8IX$T7\6l 9EKs`jqKIĽ4E`5''#tWAL@mVNO4YXft(Nl*gQv4JK-\Zgzl5՟o^ߑD62EJ/\5G.aK}@Nچ?ܺ4Ҹ6M 2m'>V-) "~(y;%Xl^%J})'3tIY3]v!GoA.[*d%Bi͒x2 )Kşpb` TԊ;zyy݊K6z/l YB܅S9V&@31VVLRVC02N>;$S<û]d\c짍Q<" 5T"Ҥ?ʚEDw1 fĵ (m Md. ]1%mE?㨁ģcZA XO;jδ2koBE]^lI4!!Γ%Y[Uh>jX7twt^73\#G6]cB"H_zYf;6l~ $`yg^xgӹqВEX~t1X R>,xOmyvM;H&`=̒L>mֲ0:n3x39bNÓ#$HJ`~\e ˧=NkdPxTh:_zz9'a+aAoh3H^Ln%<C_.uMQuBDtzPc1mpS5dAtHEèkfM]I F ͶH$ k1n^9!886":mt#53sKPb}šU+ %/Q=x0qiiZV -׫Nκ{k 瑏#6tSiշ4$F= -ƪ戭|2]G+mTTF-M5e$Lr-n+OF oDbɴcв1w;C}\>~iF{XW꘎˻9Q=3 R7FA(:TemC}PbYq`~F'͜I@,\Ni oRbEw6Y)*`7SKa2ΦL)1o3Q⹧E-cjH ) m ~^'RL:f@!j,P}Du/S"]r5Zf4CxșFTR@ pL<-\i.{HD`0^Tu1jFv(I_feAzg #n-qc;ADՀ#X$B|^ʛOC/dO'L{x6JQ2D3n@>17-t-| Evp)x6oxCDm >EՌ2!.X|dY .r鶳 v bKZ}!S#Bw͸aF"8~4OyI@)f+H0w')eȭm܎[6-ڻ_a6m$V#(-}XqOGܱ:G@k-2dsFcvJbUtM@R@/P 8T UU(Q@6Tv)N:ׂBa5h1 ].!_!{32mn vÊP|ce9Wnf u=[V5]pfLCiVr_W(dTZ@>s!RoJS'Tz_%5ƃU@w'B H@(=5l}mGی.ٳl~@pYѧceXg'84v`MS4jF:Atn&}B^|ퟄ`19_d;JpM7*Azۮp]_L5̭I\Qa܍͋[By9U!LJ)5&/g:D}ُ >?jy|ƴ;glč+̋._HyL-T3y5My>Re-ggH%\.JuTPrI)1kolऽSX3f 3>Nx_k }|DHǫAzT!@1$b;,kayرn <~ p|ݮ r [p@x!p{ 5yA#{,IYz߂THZ {BFuapWR"T(54ୗMSIpIԶ[.a+nQx>e.#z&<<ŁpoJRV텀QIwGx-6Խ-^۳Ne'0;{qGShl7q)T-󂥝2z[>zl_SeA$+ S eH߼u0BƆ@z_rsJE٬ M*nGlL8MHvJK9\Ol)eV6 [xVNs\A*g\%KkDPQ|iT,1]]JHQ j8tU޳9]Xjwl,Ea3!LGT,GՇch%tU =SHXMk^}-Of1+XqhUmk~"50`i++]b!glgE )YAln+6{(~%6@پ|>%1r]]mtOW!a$Z _Q9!gc ydм]<"b eljE76 t塃mugi9^X%qCDZC\Qϟ$r83:8+ ŞXz& "+c dzlZͤrJWct.ĉV& < \^__uǏS?liyO ğ'E?uNTn=l]R|lM,k6[/KeD-:3qQkv\ɡMzZE~*bKp\?/;+B[2 i݋v>,g:f SIp]A3IPN"JÂȉ{4 =..*Ι].UFsjkyศvhJ $oX#(0ϓ4^pQ;ۄVh(w7^^4xF¶ $҇ELY19LMz2K5&az1g>8 P ok9t{ukoc;m6Ն"j1F0+~v?5H ωC qڷ38$^%pD#RL<]hsRNQC:sP&6!ǃo es#⢡w#70;3OKȗwf?2+_)M >7wv =_I7Nr+M,mrK404}拿!s )c^TG6'<PʵU"fS۹Ruߋx| Gn vN#hcRrJ50D@9s0w Sӊqi&q | KGՎ$9]=[ފ k>省 }> \}ע^(l=DӪOJWĀ?]炬;ڮ?rEMWD0$l9Ky?3:>]֒CՅ>!68b m`PQ &݁o_iE~'˃ӸF/D}HYT|9z@ej܅Tyh?oҙYR!IP{I~kԑͭ>ᅲ:lN O}c;m:B9@/BȚPijWSWRG׷d@FZ(pݦLTpjϺQAn^.'.^h4&+O^%S\/k]Gb:k0''~XLI\& >J78$> ;l="@/Y6bWؿbDl,1U97ţeDq1\ T%u璬2>,]u6@Rsڧb0lw=&;[I FF؈a߿Rҳrm[VT^39b:5NRYYCu+I<w*qo z.]¤Yf`NϞf'NgBE\k[[$Z5JDɠ䀼[7^ +3:UϦU6QlqQ\GMf2CL4vKeI2wM(m%km[/(i0ڟ(`7+LOCXcg* }KB"JA]˘:QIмi=rp,90eAS_2UJ( jnަ{;Q**zD6V#F7,^a†j44fJcrΐcOgIp$l$,K8z^^WP݇MܚMPw1pogn(mĿ]*!Tv_+$7)EXDu;*z幬ގr#K~֍*ϦeG o,;.}Nkg"|ө, Hm6NvA1zꛋcKriA1>1SN#?G >8lE B'bݑ̰Kw֮㸦4.|"BȐrz^rxHI r˱vS&!pزA#NH;dF v"Xhp;FVli}L<>/_|&+౐oE0ɺ%(-#9P%MZ%s|JW0(~;}3ǛP.ȸ)o]φJ/J/m@) o8{nח QbNTzWMྼc1iR؏lp8Trx׊la `v4ӓC o?)Us0A Yo0t|QAǣ^Ƿ[o=2W8/^pm1=j6Q*8V ~2F sKUwSgbH@:a;RzZA}+KivX1Fs;;VAtR!ᦡVoNDaiZ?ׅ~Uo)V_0;c"{F+ۭU$'>|ОQyDZqr[su`U6Yl93S!/j>YN'#[[ADLN*AB99ltK3 ͙ c<FŚjeA(fff\oA56Yێh\GktO sܑ6ajm };T̃I.mxޠet0ˆ'XGbO BFy PqA:T՟ǧO[u0fM|1lސӠoŠS%RN a 1!DQ 4^wǽm:V\kSRm9Vܯ;qƠk;GZ6p}T;B1eOAqځ'yOjHRYקTьMKҚFsÄ˼&[->l5o:5LFy(Fct[;fHkkDF,ń6FXb% &l .5@Ԫ0%^$CR8DѮ]d&q^lVSb J`Gm/< )Lu1~ Zm+/u'>xj\xTJ\U|%N>Ld4zaU*禓W͍Bn(MIsC` p){g^ztUJ㡸C;GxLV(A paeQE'NLwz:Ũ=bwn#D8MZ=m?ʑ)sM cFQh 1a8x *!6C!.qS}z)~0g.w7AJjOV xF4s;n|F\dWSRs`$:L2][y{uO.6mg-ǂŢj/`(Gi*4QmPk1V|_UX5*Szz;-~Rijڦ Թ|U6( t}㙋+4%Q+?`͠9A [ť}[]Ŕt f݋ʨ0QeP(qt`^͐)LzqF}^"ð;QT|/C^㴖6V7_μvb,xbݳx~rޝhCĢZ),/ %4W_T_ِ.,f,=xf[k|q@^Y3-sOk 83 O]g:!R_M!2,. \6~}x"V[v Clq4ԅJlFO݇_y>)fnuGf;̿PQf>KWϏǒ!) If(?&PoHjb^Sі廬P$`ŭJbu(2bžOKBiCKh<:T ʖ ̄YڛX):0rnEFeoʕg!-_ƲU#}CZ*>_S8]EI,/nGx-u(sY\p@еi%;?ZxH9cBr3$%r (KJSpي*yg¼D19b좻x+Tn YM <( u- Ճ4ޓX\9^_8BYvw9# тJpCaU[o5x1cAP;3|M*Ɗy>$&S2Jɯ]'Ad]~%pvVsdaJmopb&_]28&㸒!m_Yݯ-$E<^Dl\z%wX4ro]9?ž,p86 d~**$HzJINJ.%ae7%JqAp􇓁2q>x͏CJ%k|3\B?zS3 B*1XaK9RBYSkB5h{6nv%M\o{4c@OsϜUa9WYxS=k#!uB:7U3RbTCLI{S70f&KާJ.d쑁U;C\^7Y&+]s WBbjxx'8 }Җ%H!_P.ju%@;HS zp5< #Ki?bkJk 2'rQ76J~+~K^Bߥ 3ۄ ۔cj1A 8'xcFߏٟD=G,g"F/*=~ͻvP⼨!>,r?N?$_) ퟲWbסGZlH h%SZVcLΏ3YҐh jo1Y0[ ncE2o8OVDpn :~o62gɉHwsV s#|}˗5PWG]*ȩCK5(/4D z];ƖXPiphh#Z@$YCJfxG 0%l*#f[}l'PR+ds3[W7q*aߣp& I| p؀;/qpU!ʝmc3wR)X&j#^G^BW_a6Bg>S̼?=:|2_Rr Q |(vuU+2Q I G1a:7?E0"o<#BQ@ IQXc2̎2W|H}yEDCp`^kTHSӡP`M]cf.uT6ph=t/alm<*$|OGc0T$ v'|?l[m?p@} YO*jQOCӾ5sU3nj(vx>*s{ċ889&`{Zl-[x<%I' 7WA|\'|(W3(xL/7Ky&A:D˵uy3JrdB$ԹQ^i.?Lb&^ :ؓ|nj/o1N{nk¾"+FˣѺo=lv*<졊o ^4 m<{"AL A yt,V롊qa+ΤGR\˂kPE|xs0}QƜ0EU5?(*֋xFL94[Ydnz@o{;Ϟ)d23"-XZ_bV5MbUwh.Mcޅ[f:5Ad:$} u}S\tY3q q;[&ηh(v%EFǹop{)cy('ͩR} '%m%5LEU$7XY+28s=֜$Ӎv MN("C:idRN%{ ҙ—s1\l q?He븨fR2V!R 8';|f$=^/҇Ag 5E'?: * 7Tk|UD!^Q)yi;?P -/$_\\XgQଙ4gwJO,wcT>Ab-B}HIDPe!ZP6o^pԚ]4VC B7~TA_ uQ1juA5^\HJMn_%Nœ,8R@#˟$S^DyʱD`C v NJieeѽa~`wZޠ|B чmso  oBWj1BDA~?ムꐮU_-$;Uk.GgތτtD,|9a(E `8EV5\ ڏgp+#?0LM Z_XK;?#&KzF^Qo>E{-YeYÄ16)N p 8BYP,ߡ>#:x+m~jX#OM8HXD) -9*BGqdBe)+ k3s,=s4:xޤEMdqC#y3ߙ?Y!r- z7Wq2m43¥ǥP#Rk ;&1 G:>x_¨@wZ@9.}܉FFC(43&C7'o(#ʾH5F!BeXs3Fs⭾")08S}Ď Sf n$%wGq9 u4qCA:r6aΓ=@Krp)f:V Pw.$3& mTvw N, M7%vzp2d,ϯ%zԦ#?>j?*?d b/جR,yL2-j D6~]t3lJR\^iwj׏Rus|PPf;Q?7 +ԁY'vs\ڃfU |Pɯx,<؎OXYIy^]_ ay͓(6f9w1dwZu/@ #zg%svwL<7|V j6NLyX=×!OޚW5`%>܉ɮ|wݪDL i2$GїU125aQWRm׃lqBmCk^v~{]᳉~$<N`յ ġy|x*DSB%koxP]r/1śj v'͹t6ŇHZc鴑B)SEqz/*dņHj7VYf\A,|KR&y|Qisʐn4U%>ҔY?"B0Op+e "E::pa.Z5!x[r}}7­yTM?Պ0",& aa9t/"G *$q~!'SC,%=0_͢=D,/*Fݸ5su_(s}zWVV)E? um|bg*_t_9d~e7h,DqNs- 8AIEj3gh%7QcDctz)>1C5njD,/$S=L1LǨ)e`Zܱ!܈Tr`^zW 3DlL;z&ozBw׷*O="{W|Pʙi KGHF.$%IEcڷDW[)ԏz^ާ}9弹W&ȫ {}"lQ Y5f^.sa+ʜJ^Lsso^~1^KÀ2hUq1gڴ #lsMU)֮:N|71C&bM'̶irMIP?Ij92{Nsx=2MLcH~[Ng~nUNU/*Jnm|wFR.Uf՝|l0׸ZzřuaKf#|}}TM]CښpXDΞO۱AwfZ*Fm8,eݎ‚y_hQ|z“&pi롄H!a-iHmsbj%5Np,GכdJACdգYfO'w֬.٪SgB V$+R%V.}B3ANI/6&߹ѷd'׆ 휸݋K?ü { _@pLHtܸ\EE3`»mFbQW5j&UFLpfW#/55^nl%Eβ^m4E1]dES6P4 @ +AY;xli.!M[(Z#raUY@@T-1M{dGUd ˂9fblMp =_:yVT;?6ys-"J_)qϖ5/bGdΥzy%R?΋˜ 4UDɼy&[ߒ'*tŅJcE=Eбuo%鞁YVg?t ta<4l%˩+s:B\w<3I|֫MOELc[r@\{rU*a?Z) @nTw %+Mb a)8xc NwY$pا(MeaK9"cg?PM`i(c)~*e_^* #w T"(EV[hgUhQl??Psvh24*6)Y>Jʚϐa=oo2b| Cn{!_u$XVǝuGuZ3V/>yiȧCŻswԣbv&6+m߀%=gO|N&)陀E/LlGUL%K뭮U,ξ'* ˮ nz2wֲ$L2O,rpm6zrЕ^^`]ߟ>NϬ\6KR?j0ORϗig,scɵ˼CdTw ww3lX9[^ cN*QfXc[*Ma̒yY]ETsߥ[ 4;e]K)B-' dӘDbZZVTn,_&%2`8?DTԨ=b_d]*BEW/{FIG=xpdm +kPW]e| p)%hLa2mWV#| ]ź-aؗ/G5OiM`>g7 ڳ `i XHf9z;pb]~\Wo +5oI/D XA ۞|_L/`1sB)R]pV r:dm-뱜]vK#Y[xCYS\ JNrxE'TOTv(P0ae~l\&nObX5C89{@/?ϭZ@"ZHEtŴe]) `#K^aj`?6q,Z&-zGWe$xd,3",{@~umz`Vm)~  gQ >OD@`L 6$ JШT^Qo!Qכ(`]2# >e@WO1÷UԛCY~OH hCmr!)wƜ°K !aer8D5m+@6Q8C\[ xZ57̂hGIHꌳ͗oTw@G*/-2hݺVݿ>yKXw'^RP&EȆ/yw3d[[R`ئ'5*+!CAȺR7KXA`'t4iw(AZ3-)qTcLdnC\hENW5ODyq :n YqJ3H;u3Yɶ Yvc:E^6P5:TxjST b=/붌B ᆙ{JS ,τxĸ L& O%ENnGr2Sjbţ⩸B|n2Bݜ.'4 Htɂq9X甂OGވ6R̻; ln6H~BPƅ_iْ51 w(d2M'ї ,cnT;lpsePWKF 0HKR~K)j6ܡ iqW eNI/efn.iU2rvl.igeN%12D7шiL4[tӰǀ8& LdOК:^|GpEZbrO4gPC?ںeyf $|B%GK-Y4d/?Wd7Jk[W[h6(䎉RE)&IXhojQ]&tk=Zx\I۝\%.O+rӂ]ˍfQYy+tON4|~;rQ;Pq7^^t>NnȵL5iiU0PD mi2's~6N#,x`½*1Sga? N*w> 1룢vmJ_C+ DY?qJ$uvYfnk.}`xJRqO8$p̢KUdW;ʥv)p4R/LxN \0V7;ED<ō_G%)U?D>LQ]tބcd?$a2,5^7M*m/n"z``HIcAul㈆ >xƻ&Ow:9ECB9g *2Q!E[|Pq=)=yInwhg+?W\)5۹i.RN8Mj:v%]p݄L4GkQx# k_l)A ׃ͱ\$zv?K=ߐG $eK8A<ݪ0Zu6_'̈[DR{2<""Uz>c0ڐ?LYܷ,>5j`[rvm1r^fo0!Cg j;{m̟a}#CEEv_T >4!K6":LeP"uGR;@:Ȍl5{:2:|'$6qgE{ʘ)k- D W)M!i3& wx L:^^|O(,+;mX8Ɏk-qT+7nS9h9GaUo=noNEΡ #%k9݈VH(9xq;b;1\Bt5G_jx9`PduOx&L.+K1z;Q-MtF8Zza'PB׈]6GֲƎH(`U]Ùgǀ 59&0KhմEP؟陏|MIhC[!"o"O~'JBO;5]kqJm+v &:6'eq1)-Y1H;Nx3|fѶvSE܇F8'Rb\4YcT4Z>+ÃS=ǥcGFZs:_YѸ> 3Av \D.d!ÆMU#ִJS>T(&0nonl<׻Qܢoj/j S]HVZ'AE丆Xag,R{>a<&@'<} >xFͿm22 \.!Z0Y`YjgT-ҳgEQJ7Eਬ7)!X8pViG=L١;*lJCƚF&MW"\9amh Ձ#浕ȻWMP!9:.=~FGC]i6 dNjdUa H?:Χ~dZ;%g'7t&3V8ᐕO[I Y(]);c+DZ1p"Q$ -lc@ւ 3d@6O+-(~TL ;|cg2X>E/5zUHŴV $)hȬϣ"8{g_ZINu+n, zYPbڍ0Y/8)'Pݖu 3˯@~WNgXүp ՙ;L~c&GbF{9=,c| kn"cgF:ks]MqB>ۙWr )\߹mEr.3PvA0XtY̒()к,jElsN-u'':9>JqZu$+ah WCUd4NFآ95;DW+N hU )7WWbpRtvmX)c2A;yaɷEx׏\@:IT"=U6Z!`nb ʢ Un  dz!2KAwscBkl* ;kӪH/-]hl3 D%zXn3SFC:VmEŘo% G>0 Īa8]T)BߩH6`M]*jKwj|VEO ۨ2僇m@_ Bo2}z&VY_>˭ zAnnSR/ϫɩ'ύ<%jȊ<TQM'G݈u8FPEKhwkNqބҲPMH %p6[RPB-0 @ aHUfD|sH,HܵGFIÒ(ݥCOwqf^?wp}j85,ĩ2'6(Yކu>^*`z. 4x 7==]}$:ooh_ #-9OګGT&S#%ҨZMFD:"Xo(׻#O.H|jޱ\/ }oCsPJSs&޷Ѐ A:MQ8iɠޙQ91FWOl&e[Bc D=tAnȮ8a3ͤ+W;,}T8 nFRt"w0G v =*cuSMGŴޕ`Z; 5 a[k_!G",O, 'd]_XETL0Ҏ&Sq wkf#F( 9wn<8kZx6ZY<ֽiteÅШmiC?߂UtPdX(<㝐]R:!H,dq: oa kS-& ;(~A>6Oy|Sڅ!jXÇ3 [d:ABjRmQ-8TMZOLO)[W>h1 SWzP!xzDB#k yoJ,Mz d+4aA8M}&~y;J\(NFPמ@ꃷ{)lmk;Ԁ0' 7qp]أA[fOc םF xKfD c6& +5`c8!9kyЧlU{dr6+4->9f0q,Z\t&RΕ3D _}66˰ې~=5BVԄ@Gퟅ V{LmXA( mi`\c]f=f^1-h͒(bkngU()*:ٴs#@$ ? 8q;c`15*[ ~U-Mu9kx~«Mz$VOyqbMoDYoUH4 y <͙ʟs *ou8~K"[`m0$&2|B1=%0jAv0mR.J6mcZZ0y nlLi A y씙qE%?::\THrvp"/1L40^pzq#Bk؄`hw&Xs%AqE$ u:WÒ&J W%ihH!pf\a+0# 'م N([>fKBq+f.ò5`2mXOsVڳ@cא="u"7H4Sp1.\Y"oW;7VT_$Wvη*@ uC4V2<'($Oc)IFH1™qnd s4dUwXU-3RS+6ݲqe,R XbF5aS-6[#u/T{u!پ{qӈnQ:zEDLnpklQR.;q', Ɵn]|5GR8oU cMMlk-$!xԡ;mӸ@⦂ؔ]y3>y!\,͠^L+w PMJvO^=;q XN"Pީ78'k@*(OӫVd/:R5x\َҏ .U|I%VZ][J%u2k%d#p}cSX3 C5wT}x@. KƳ4dHP&Um+ &ތhulG9M_ ` A`ޭ2oA5l}|icͽ.(-؛/g8a$DU[{0Vc\G]C&핣}T[Rb֦И1iq7rm(IQZ)u1W@H)%vl'qm:KL!V:Hi '֯I;4lL+z5 CB.3[&sPu3LX/?qq>u/9M @:W8ӊvU2ܼMNiפd!|-Cȡațf)/t|JN_ 7J?8_]1& U盧x\Zͽ`K>sZob~2V){LaV'x =s-Sҏbq4;M%RUˌ^0AHi?qޕ{k1Agx?^54WA:=9gdaTƅV^Wx#X+S5\&"?3Z{xl V FtmEʔ/ &Z ZM{In1Z ɐǺ2\!mp1`dM/HgnJt %-i댐v nBl|kQ),fq#jƇy;9e$;6rhդUDP ٵŚ0gY;ԙBP)W;м}߂KOBGSKꯅJt/4F&E|5 m,m لKu) (pEё p8pR@2=+WT@@yE0I.!Yʾ]?f]/x1pO*+kuPi(c}_XV 5˅!K9pBiS]}ʮ, : ?CX6JrK/`$>/aQ+ٺ:۷=Pو%26#<}@_MPUs92h72Q\ B"M>!}k|g'*bb2XT3v|/G$J$lgP0sqrX,nȗҚ})U$i%1A$Kk ׸f´E㍯C8 4\tH2@F;cRdĈ|?Pu~E6 XW+!FG^=?3rҮ5%ʼ^xp_lՋ|H+Yx'On Ư>reJm?\Z45H\dZ׮M)K촳 d-{t~]g_ǣ& Ub7uV9qI9|z FCY=G`pߝݽH\Y(TA}SR,SUMSalP1ūXife.1L!Ϭ/m3FwstcElrC&PIoj{MZ۵cerMP<[-G5Y2a0(v'*w1M gfA}33%_@kC,cP--[&0H7k`#*SfCY3k4DU"_D[_\y%ڎ DїO-Dр\hj0oOD{Dxx7M#r'!B:y;pw dOo]՗R'Jiq,ڮ ׶2ݰ9S$VJ [sUu!31;-Fo7GzXn 9Ẍ́tlwY*D?n*+wٳ|]˺FK\jv5bEQ^F.fsf/}鳸[88FfеOWKɁKzCyRuVf` c̊҆`7TXF|oW!@bǁU)>u|xXɦ36^{WKk<拾^Û'rt!\cB ?7z2b8&.cIOvHC9o{z#ǢyTh zQ09eyq0^Æ ojxE`slC MqNuG?yΖ#H#|ī_?*SCKP :z?:)|`iX/ٕ0f7gH{M6d]1m;4naUtLGS0эu^x nIvdq!MnO*dъkwQ9*Q棣򹑭35K L$Bh7f(/ 1Avؤ)^InGqwJe('AaL(}g=4 !-ynYZ`X *<ݑ- 1lrmc=mPl\nEǂu<~'wK^sMB0cD}%i,m XZHd99$Zndl-t]Qr:ټ ;8 Ÿ2XX;?M#+RsV!:hˬ :!uRֺ 8:ь8uwu\+ˈ4H ˔Q:]GW";Nrkv=~vO ">79y%>ޣ fFAqߗ,8]G B%=~m<r/-cO"ԸwlyP](N%+]]BsT 9ORp"=gms 72, gų3Mzӽ"]'^<>La0ɂeؾ]XnnRP2GN}4fe9jl1N]V3\[{h)FP/!zy:b1M ǾH :cL7o!U_k[KGyA{L֤* zp̗48'I=u)Qu o0CD(e24~+ wT`l(\i-hNU;薏y AwfpFO'Bb*X0 #;pxza)I*cXį冯LS6 nG2F%GwPo41EN D̉jح, O.<`诉~t[Wr-j V8Zm6H. ͉yQ9xVU ">Ueu#F*`}t˨/ X>={sGRȔP>Nv ; <8:{[jIܞ:N/ 'uq|2l~R%h~a\! :8_#R@V GoMum>jDv)YpfNgm"${N#|8=:zElW Ϥn+ ɢ. \>"VTy2Ӣ]5rs]XjHHX⋭6e гQWzO=Ek;"X1j0S eZš~>AFê0g8ލ8%Cd͈]rYyƆЂ%Y /hu5RA8Xh?wkWt遧 +?mc8vSVN}vNrlr/],zMs{3-I[ M.ݱu'C%HJkyjcӵQahuض J%Ãz |:sY|f9)2 pt@R dyLԾ ~-7}NS"CZcӨ@R9k]]֮_|QUj7kkj5:[U}t! )$"mf+v>(oܓ dNs"&鰼1D.tY\8vP-w&3[cOqAºq,rޡ%/ D~~++UAW]tP/t 9 tyUȹcq//~~Z(z3]]2%Rq"O\!/oRF<7l` H /w>x.whF〤0kb3 M[}l)tI5сd|MmM|1$S"(v,yQa;;]x  )bqa^D1Z3jpf|UP^Љ@4OK!>va1pگMĔpkC@9 J@ȓ*1Yl_15FOh[X4͚%%I('VMi4wWN> B!}޷.}rЦQ9J+\l$2֌mpG#^aw0A^= &{c 0m*J+Df.^$ڀhJOՙPJߑL^C@lXxp'C%cy/%V咒ѓ ǢQ9_-۶vCaYlKL,DB -i&_ϊ.ʁ(Q pRk/ҍieh/kÌ& P\U Cl|/Xj<̦y9Pb̃\-)dNQ3 (e1*URmv1x5A ;mʎh2;XSnk,q}hZ&or9e$Öy+ rf_X * BOXt1[^V?bYKM3hw͋!Inz֭i[ :jb{GQ)^&' ;Ӫ':GTu>}>,b?ҝk?AKi+l| Y,:aŭŖbBF 'Մۼw#kN>h vUqe\4\g V73,KUq򫵪_X#2HO,A0.+lv?Moln# y/j)b-tmI3{_bgJ:Fi<6+J9{],=s7Uu&: Gc&N*:?2$x^*'mw ZΤjEDCfJNLUԉuwC- cʬ%Y|#M8Or.u4kǬ ż/l~mȎ*wnd Xg B>?*4tG?惲(C']t!&USfn.(B^4BK.vl쎆<`06\GG/Jӕ3'5goɒ>rb6xVUNӛĉ1L9J# :q=oS-cFK˘ ǡ,[fP2R&rK`]6F+tw@۶h!gTʔB/u:e@uʈߡ+J !p{]j>{StlQ'ҢK `Wbv [,_ѷX ݇|``}Dl,xpyZRXUx2SnGbJB{e,7K+ Da-MO&PwK%SMrtfZ6/l|hٍ@Pe~=Ri=Cppd #2nұ+{^D-;%l.p+%ʼn`KG@>+BDW|w$gt; cb07*e*[c7x^{k|LiL)oI_e o I+(b*2i}}z[ჂRAz߃`|7<䪲95 r#aN%ԓN?`չ)%}کW!y J5O)5@lR"eC б ݑs>*x/ܪNd\n>gtrcd(㵟9b+׋odyy5|@k)rr!0+Z{0 3Y{g*uZ$ɏ em'!}Kx@v4>iazSF$rםJ 67vzń~ҶJX<(˩0\ǎC@geu;LXOzӂ//{JZe[Q]?%nrJ?"ZCi"e6YL! ܅IuOzZUG[wn C8nO;FBNhioPq"#h.w# 4|pn/ ZYf5a{g-SϾ ]ۜGENj'Ro|s{zz.!ύrT&):k]=T lG`kq۬  KG` &˔}teܲ"kߣ 6(f.H _Wt>+#"߫O|Pp kE:ee{J Ӛۅ46pYAcpV8P BcwTtgAm>ojqMf꼜e48} YBj|%avQ.|QeGgBlDa/Gw7uIYwJS馡S.M~7[VziWeP]Ak9{ ŕ5pvӲG˟> *^K <?,A{*h)17\Vg/"+6XH 77r􄎜 KԝNgGȏt1,a6$8QHh&BX+5<'{1VeRkoV2lɶBu!#W#Nvm 7휵5e0.  ]|yLlE: E&7WPjt(ƨb)G nP{4NmRiMk9@G\M'ϙ`DHFRr֡ >+H5xsULJ#s\GA`Hj>08:#a1^OM1Ŕx1pӶhGpa/K9\geE@l&oTq`ls?o^ yz.YX\(](C&Ԯ;"}÷J6y!+wZ 㠜Ҁ^i wECci+H"Qbf 6OÿT(wDA \bS xw^3<S KG./D $`ЬNкiJGc3m䧭\f/y8,6N:8gZa'-##3{) 'd"N!'0QUd^g=Z-V(qNx޺o`pzAX r4R, GDrܖ^Z(KQ_Ui GӆQT\Ґ$Ej+A[*;;w"lNW4Juocu \?r5G0D껹vq .l {S@B2s&vcSi+Ch"%io3|݁rkㅽQ*F%=MDK!['[Yw#=EM3V z\(4"S߃#=v~j%8eWy.P²!e˿'DH(uz}1 HŊaҳ%ld=电c'#v<w793W ?AU=aeEPRx5ZFk ~dM3=#c@D> T0IsFAK~6r+jFk*vmjQrPuGQp),vm`XsiFҗOr0L{2!TlO.)n(oDN(QqK?R7?J:a'SkY02)&&^!Ks/rv9Rh@z,00GU<<Oȓ_?SVbܙ-JhM%M] 0 8 ,Q'xi:6!M'0PI" 1 ʻҖ;쿣< " qFqx2szj1qlJSŁ g u!H-,ϙtd_1}s)'Lw~# ʅZTW^['.Sn6Zvu,K-f*HiW3mVݬ&Xm- hO4%sHgCh!!)跈#xA3K@EZs9Qy(B`M Ǐ׭`|M+Ā0Ӵ-0livRhiL 3y Z$==Ml>^st)e6Q9vnԺOk32*?UԁdtBgql_CCt%qBދvJM>Mӝjir* WyvU}#GaWzn*7Qb-L#wZ $diU,W't #Rs?mTb2sƀk:ԈEtس>#պePz ~_{ h,MU}_9ϨW ֭~k*]la $5c['pXHYu$g6t$ -Zhz=,rl`kR)"wQ}uœmN"5?3r S%3n@v5Nׅ.RY+yCXA< 4`qxKVwrtYgS2(/NӀx _)6|% c]̅87bnĢNjESŽ/C{{|5gg]T`f)-ßYBd0 <{͵ NfGo7 e Δ)In$ \'У6y,DpP[s\DV%- b am)>.S/\M9z? ]S uy\mvWӎ{Kv _Jo nGM6 0Mv D軋Д9{l6$}5>ý*lFQYrn뮖Nկ؃@;X4!WJ޶Yl={d!ͬK F4.r#Șz!TҩDݜ}A_-0?_d\t<[M)ڝGdֲKɢ8m0pp/gBV\Yel56KAMNP]nncWWU1y@%oEwL( |1{.Xi|)WeσڬzYeelW aFK!8n@$#x!厧SC=vX;=@ %vmLnm488JI P=螉0*U=_=*Pآ%]pDU ~ҸA$a[.UiiePŒwymTuIsmkέfJ8|ϋ6`Opn}.w 87 4*Hf\6Յv-\3lGChb@6p c U%wP Iw mc˿mSljMyjv/n{ xh-Hο .a X%Ta =' ܡ{W^OcYfOA9VwK5حܶSȃwb۷CcWDUr}a F0 9x庡eڗÆc)ފ|D-m:ޫ@ ,b%hlfI(#PaFh' ti/u< }_e"Jcw sFgXA7%BTƛo>ˡ-i!tP7_Y7AX# NQ"9NO]:E&3cS4*K~u{}298'󧉵/y*;Y٫‰kX"V nųSK :زƝ9c/S(N!$8]:z]J&/3{regeٗ1U~/jkcY_fgQi"!].#$W݆>K&jBvPw!7 8_oT|=Ab羝! MvCt}M kb.)*}A; Jɐ&-C+rYƨup-Fx߆Sޜ)7XQd nvɀy۟hlghT0U*\t^ j&%&i7֓±3Yz/Y@Wpس|f[pϖjBQc6iWQ䷍"S? >{Vr=h>[3@q7nWU^7ިA6rs3֎Jul$fN'Ô>=?Dmw\,\|ճYlr3呋`".5m{[{-oaLr (%Ļqh@u} ֲ@s=~~*dB 8[^ f9dն ݥuTФ!v ĨySvGUD *nop-[BH(Pn,4O?J/EI@Iۛ03%A6>vNۭ(O 2^!]_B feg:nv"f_3c& iRFa4Us=+IPƜb* ۢr/aqLf U)[a\cӅFT`et)rZY[٥$p0Uiid8J&!7IF!&u8gt?t6i$95]/屧 ~{,@ sU[gU<Ϧ%b-[H;m`B {;vf%4@3o#օZQfVi|C}<.^S=3-nſNXxw- CL۩(cy +k3..\@eF lc Hk+Ϣ"ƤNdc 8GW%UV&:ֱF/ZѦeOwb}W0-*T1lH\CZyR۝ 3:ż 1Lí[7)ͩ]3$_4q 0nE9i(2h-bxmm`&}61.f> N^JO vBԟz351t s0 ay)4W}=qp}JCL!TCœ Bʐx!R$8՚0on;Nj$mJ!{/nZrn&…PX͒~ӻzdh2jn6X\;ܞԻT&RU*/>Gvjԍ {U,1b՝>ȏ>rĹ˖ @SNMMHtt̶ۗs=:MVk/dg@ՠ TR t(Oo k%#b#iA.#oufê!jސҲn(\:F@+ztK] バӨ)2-O>]/rFVl"Q&2-m|1h뙩n aS9ֶ;pʒie~4 *z_V×]P,]{ 9xxwvE %ޯnff_F9y4E%(z< 4MoVCb9 ˇ:;}7[ #YMo$5g:nE&dC}CI6"֓./E[]Qh D"bd (b2C:ԺG-l :K$"QLڶXۗTKri-?dFЁNv!B N%)-C;!ƟH ʦz2$іp ?%7bZlu~̓z ZHݿmx~WQ*R "Y>MQ@pc Ucq",LP \ҴlPV M7 D#@qMRS 'ƏOIsw@vlJ2vg)cZLT5eJ2ѭiP3˭ qaw fcg.U9 2&@}RdqHL  :WW@J>Vj&Ү^ʉD[uD<`8app`䶻ypCGC'h;V1-EV'* wZ)Fۍ[lgNYSoY_RHA$AY i+&A;KR"Ӗxd*bR"eN\_댝6= YB\9E|7xLY .M?]p)6K- )_ldDUSC9էB19;^M6/QdU?Gݕ Pe~L~MX9( ːʪo_]XJ(l} eԶ}=a!Laeb6FZE a:i4ٜ4,f}g黃E[S4հޢRu CuEާ!pSJm.4|]ArªBM~680X_ R=='Mvi?kgt4=&u4 Hu;Tcv#M73OhID 0}0pSX}\2irWUr ya(f׆ªJM2C.,1eiYaTm{K,t E;C vBNPpD4 ~)s;3/CdX.3Ԭ0 h}JpvEq&X'po\ڋ+nSc,mW: b^oGѳl&4B ώ:ڷh]HodtZQͳi,C2ֽ_2q+d#o([m0a3LTBC"NjdO-u\'fM(ҷ֢Հ0Co{odfى( ̭2ucsq 3<9tDfvPkeR{IyǮ1w"4ΰV7X9hf*ΘZmD9(U#Kw4]IK*U`eS;MXL㒬cd2z4~qD8+Lf4'<  NDO`I\)w^H7-5^?@Gg%]![U3|\oB+JiPKF?,# 8_)ui{.mf,õRM(MVy󺱮$Gc/ eGJ jJ9;o|3PF}S0*3ǂ20άH E <h#/ dhrU}6-/%O7W4|IZYDA0zreBk | J_C?B7\=7ݔwGq;T)H#?kaC5*3GGn Gcm1bo052:Y\>쯋F湘5?6GZ$y{_9DruHޡv D{^ %">eӘ!J5yGKn'F,f.^fsD=w MrUPLl CؗVވӗhF4eq8dUi- '*`M 4gG`Ay47nԞj_ 7B G}[ޝ{Mnщ*#1^#ۃX\T;30lzyb6cC3 ݷ&bX?fjv{+x>0ONU:r˖%HL1%ݲZ ӟ=ȩDI6_~շޑF Ẻx^?vǩŀ_wK: g>^-:]sƸJ~Sn9%064i[)c)<șs]( ǐ;LvAdg#V94$,mۨքl0[Ye'x?3s@ xRPh-^^.`kT@p?gbp$皃?]qLۑs{ uLOV7o^j8*^WFZ[LfN>}Yfqd>IAJ%YKx#$yDFhʱ9-DXѨ:"I?%y]TԡL)<45tcZms MYx}y2iUrE8NR5yEK }u$1(;Z>s)>eZc$>FvPq!rjd݁:vYkE3=H4^ߴׁmZGٟ5e yQ@"d., N.njV #":іt<"`}F l0lHS HX=njfwCB n`G!r>{S4:f%t^Nhmmt0<+NToP+O~/w뒞+eU2MۺlXBؙmW<A1**BZBŝoXZ+M#G\4U&)t$(j(߀da @O vL%T/Yvp ){b)׽K`;82_EۚSTTAVkڴhеw ~&q ]8yЁT m,V0=#2&H8Al.3Ǯ73 Sʣ~)ZcDHs ;ٰ9? T{`+#ths}r}Vxwaa%q7ʅCWR !?*wh`V*S~n^ &mp1 {^&U>ɵleAb/WZ X N eP.)Qޚ)F4Hiw`.lPg#5/*%}*蘣)י(42CFFcck&9yׇbd}mbnU[#`"Ú_SNx EG4u(NpA y:J]| ʰ )oxw\59\!zZa {ruFuꇷ$d"@0zQڸ" {VDIv>)V{o%+m؂ǚKѨ x_U{U~!󶏻лЙլH.t4>?+p筲qLtK E:cx?.ၽi[6i_KiDX0p"5!:4<Lb~Gٞ|x2v&j᫏,B@G'1y3?wJT#V.})CK(G<hC߻Kaı~GxMJj]V7jy&YKut͔UuSz VeD4ʕ\Cr=5YtH>Hu0ko)ՏܘY@Hd1烓;+|H>XtY(+AXx1£y؀%U&?fzhigL*RC ԤwmX,3/lCjb+(q\X=͆wOvۂ5C)|BAnp@3'­A?%<-nSq6??J9G=-t}Qhq$k^(+U8'S]rHqz3^WMס#JXᆷ]j,%|+idf[X !_b8_*3nzb˼PRRɰCY{2Ak`3+ s1sL:,VCˣ:N+-i6M:d+٢a(NsujRGaz7PJmL}'eo}8kn@L]N#}u"r@ e Z^3ɑs:%7 ttߣ$pD:ܕC찭jӅ=Yx'CJ-[&8ɧqpŚiF%Øe&WTs$qFϏ簮b*AŐLY7 H4e 8d5a;6(o\GLt]E< - =G>1)І hnEH6-dYUnwAj)Q!'{\EMOnb^M_Z pL|fnׁ8ӕ=Ǵ9y|5–K 3)qǮ1d ZB cP&x/ ŝL70/}B4h$9zu *5;ҐP^S/_ fϥgY?#Mu7*l|M،PGgnfT,F -dں ?/2Q};Eٲ܊u( gq8<M@e-qGSQsXi"@'7N l'M0z$SA *)wVHTlbsgT :p]I4=>&Dj.l;2(oW;TRj hMNWi}")Z&9 xv/?zE腪tݵE6(A`m.zMXݛ2/OԞc잠ws` 3X۪=>X4t3{}vy|!wzA?no G=@x=@I$JBcۜx]c"'a0Jkmf2Lѐښ;{T KN;et.a/EwH1W;JC4lwysO+U>uW;dJ+(_xba~+obWۼ{~x )p~k`Qqni旀q r(T> qc}%ɩL]wAN槍,P4 VN4zL$V4v{M`?\~B?.~T63orhutF'oYvSV:lp7J˄|e//}cw#.fxvv8YQR`Wᩯb:3b asYY:W3 &@PofByK_s錯Rn,>R}c֎ڡkNvCD0vgv-b#%ZUӷ pQ+8M,%ǥ!G<(茩h̓M@HdUȺcIB&+%%={Z75"a3~謒2iRLQHP[X IX>iz'B8t*,kW[0j]*+-Q@R1D-R Uo6r*$'N*v @;_Bt/ NWN0ڇS歼Ygooεe{u竇:oW֡J]F7ybj'n`~WkJ@'r |J' 啕s>/㺥sW aN^P <4aGwxT Җc˹%"jXu =de{a8%](uXIj _狛aDxzyzC2DsPgcwBg&EiP?so%g wǁA.R[hx[O〈*e(CjRX+|w3@Ηp jpiL1r^xc_ma> wi2~|e9"c4E< "g 83p~.ڜ! ųVd2%j#;{fuI }-sTM qQSO `f#tk-77zLmvpB󚹯qBӢ#SV.7X[ uH3B\_a8^,j/pj9.Bi; Ob  F̰Xz('B6V"t$L8;@e4'STryvp.cj[M/!%ﰃ.h?"kPYYo+>x6L4 n[#}? IWGo"`?aj޽Uc:5V17cqך͹~9@WCvj 4z1&6-beLdZn5)3vl:H%T T!:m->f\`%iBõ榯~"9ŀ:TI-\k f?..`(Zu:nhBd>; _c/,/&W faOHH@zѸQǍ XhB<ԬagdӆpĒA3& Ru(!_"wyVӁ0T:jdVp}>PZOE;̓Ox1Ofpٱ,U%p[SX*z~ͨL by3X#VC`xl! @L݁\;D׾ ~z Uf}IDe4,Ku#EUBf t3nl u>^hv ĒՀ*MjN>R_&abD}X*+DovֻblWDav&hmF4;ڸٜacV!16o$T$ڶ-= ѝREm# ; vXI_R\ߎ# M)8+72=RPM$ZHHYdg#NLp{MLübJq*uh廦<$cɗUTJbOw-[R uoY gWB5=|o᝴ LDxk ߒdXǟP3&5GTD|'rHc-t-Uek6pb-Th tG"vѝM}f}.G]߼4Cr}ƺ:@b-c'NpT1ˊL Pur!)(Cu/%8H5Ҩ0) hJGD4;ܦŪ7f>#O۳co)T ^bּ̧uV:?wt/{y (%0ElKu+LTDRj 'jR _0iϮ}tK#iI[y,@z|Cǘ )ά; |ppi=Ql peM#mkDY"?,BR}_+QOXAZA\f(quǐ0X(X=f`3x`}VXbv2a21#iL$5! ( |Zg / b )5c> 5<,aܟY4u2HU+e+aS@) Č}? pªYTمc$])vp! X{H09N K7< 8w}@J sWoYmܟ_p[_ϫrW =+ka,n3/l C2q;Qwpk:PA 2or)wd"vfl-^<Sqt+3d.RDF^J\]'f EϕbrdZq'\@4z[WrNt!ŀDSփEhz?Nc_r09WE?ƒ79.Dve ];4Rvԑߚ ܒNH+n5k/2#E(e*tP|ҫcTH?\tj>S}3>I.3Ճ%Zh0!5ag,A*(ݔ9^TukS̖zN=縉f؝^! bqEϽ+1? ? 2,|aJi>P40)!,֠3֘A?m:3rsHoyT-cnG~CMwg۷;icUSo}eV3go"̞rhIߢ|w `BlCQBH@1Tt"Ky|Ĭͼ+($2)S0*3Pp+0, =ѣ [`+DPӶγ/E6c cL ꬂG7ސjN%1}ԬӢ|(,zLqt}A`TQNftJ`RfdH9jj*@GȔ1b(rv}@զdFFH{N+g=6:\aK]0T%bV_vnD0$:?v/ZFϑhEfY-\2 /C8E;Meԉ[c9sٞ:tZ_i m;F4NajNAtON[O[[V,{O-1p4l O Gѕz t C>4A_?z{2(`<@`i܆M$pE&OݺFzY{TL7ryU@5 ](FT:5nֆwvTb3CKnV)lK\4!i.PK$q!iltcwS ?k)3SEc8 F?;{|?&c){`f%_}\b _m*K VިQDF%Qo >eu³-4(7FN+p&B7ΛrSC d D>ѩ"(ʼ=(aCA_qu#xX)u|Dֽ6* K/k1Ѻ ~K,)cˢݏԌ*HփBR t[X%7 (Xd=T<^rCW ۿ2 bCj߸-R~]>]r)d݂1'*{}Yh(&VlMU0CDw~9 G0t<ژZON2;b bkd#/ }. A0tߪftKV2pMŵDNrmAيmKb)ez<]#FP$+JwJN,hFST#z 5-7Lh_Z G| %:Oz*_|q"v7+M:NonW'u(<G:< Ӱ̔, u[ʺF wc?ӬNU@I[Ⱦ!,;}DSz}\ gQH&|+!!'$yǎ**npsCrQ ~-V(HĖa $ %Q֌K}/K>z^ ,5)?tθCOX] s|G* 9'|^rӯ.O| ]:'8X>7[?"\)M`?wl<7fN۴>7슘GMQ,b.)+17?5LҚq^jPlWfJ;=qvGm>̧߈]GAnBQzk$+3a*[S.UVQ嚅KlD;Rk/W%r Uma͖ݼ@5~&w7Rܹ/,=|h*u v0J܋ HXVgv/<>]|[gy?O;`PiLԌȮ20|g2ԻXrO4ܬy ԋ (ᮚSر|^MicK^6tib7aǶ3{Hl{CSr)$3߆LFP؞hnf~O. 6p5q%c0DcڭAb%AS^?V6 vuuE= "Rīovm*\w37 YSQ"U&B U% *ߌ3*.yt]YwBꔗہYHJޞJn"-+kM1M7%VB٨WW,2-EB^m(-2-|{@.M=w&wuA8 sKLA;"Z%7ݏB.?|tf\z6"_ =!34,#FLZ*:HYH`G'a):I#^"4q˚;@2 ՛<6d#;'V_2% JM5+{r "$*ڠfY}#7| U}IRe"+ '_8i<}2ڀ` =ާ._GN7C]Y}1M՗5iHm #3 O fgVkHCFH//Fj\m(G'. mod/8V6 &-Vzr#j?@3^s?>CSFL$kn/|56o4;vۗÔl\9 DE];k8 jE7B1 (o.!~Vڄr{GQaɎAtUh@L. I V?=ϫ8]s0NrD}D6BGaƟc8ݐ$冕7hKNl<722Ἰ *K&'x+C''FguyC95P+JCr Vy` <,1q1Yg \w.Y얂ԞbvU-%0kdత-ܫh:Rh#773Ϻ/ћ_*`]y7&V̩8e eJ8>I)yF &1o6M7I'Ƚ%!!&pKG*l||اG/ NAzڔl; 7د#(ȿg7kg,r Ξ4 P=faN=5c/qYӂ>B 5  Rx)XS0 O3\oͷls ɂ~;$Bwٻ/ёXɾ( 4LoYTz eH/9T9x9 mv\Io"`ġsuH*%B"Hs;]r}GfTa s(MD14\J%/I)ܦ_ ݂tEmLJ\3ESO^~ԃxJ@4@l{Vb*bT6?3|Zg_RޛP㿿C0 РGK SB<z'Fd%/̏@")- rRWJyL#13k,=2D_7Y4(3p?Jux"ԕttPp,vIy$새GbfvCoTsͳ&B^n֞RbP@(=ɩϕ#a Ѿdyړ+?uv.w w '>i1M m_zBOX4ӗ`#FqSoV:tN^C5ڍ}HzdkKɹ;@N@>iV$~RS}~i(LtUn\6M4??( #V3"w6\sV"l^& ,|kDeKr].- :맮qzA)_%7(W˯+42]'@k) |o8onm86E+ CU8vJ敭fa57H𤔱8B(o9DPN};sd2 ZNhE-m;0p*Pv_Zb>m*,,%NYu's1ĭ`>h)]r  vBpHGmW` _k W1Y:da ySW+8hY1wۛ!ʉ{>id~r*ɱ<,2$xn~)ќt;s.Bw)Ͼݳ$(~SyӶ`Rۏ"}/[L08_?5Ks{ *vCezFe ׷&\NcN ݏv@1eh!civs225 z 8l48i8P!0Wx, KnFWz£]"\  L Fe> 8WXV5f.O!gz}UYN|j408ODzW '}~sW W\k21tylRvėo@rRY/ 7R@Fkv-/:rsR>F qd-<Uq//6}Yza-<;+#h%$*%Hi*6(ն1 kNe=CAނvAix {0ewVVjB;{H /pB c^GQuC{NeU'mLFH4,E&f|Y bھP3e7[[VÁ(. KܽEFMoɴ;s xޕj#7mX'ae3͂Ďbе E-ΐWf?EhEx`婱D</-|/PDjJd^TG@Q*b4 Tޛ5 Ik:^=}2;#S L,b峌UMER>]4N-V"OG@է9${#xUn_f^ [{#Ϲ|/'BJd 0c3Vg{H疯_Q|qSS,fۛN#ϲFY,4p(&2I!%{_A_|=R %@WM܉-k] Q^U|^4AIm&߁# 󾤝I#:[~-xƚ?f SR i+Ubt>x-ʱplYZkd=NЭ!f" "@lg{ {h@`%]SNiK{uQ‹Mup%rͭ6Bc425tahX67u hMSM09| ^< F=NƖ %\=04:˞rme@K}q?)8~ۉ]CZ4\{ثRsp" 8^/\ Y1;Bc$%J̿s$@/啜J~?|M@*$SF0&ю 0#7./ lGXuKq9EĢd*b7Hm!$_yIpe -֦*{/K{|4]"W^4(ZU<쇝9CrÑD-" b (qyƗlְzaF\ @كUȤ{E B s^fCIh:Kt/Fj97 oq[_8w5Zi5mF< fd4\vi,lpK(ŬޞJ(чc/I7QJÏ7O!wMc5sxUT(VRTݥIDcޤu4gPBލ _d(b@pWM٦otB7kÛh l]7z7Y65UygGd/)N2M9HB*лVsȬT~48 |˶68ǍAl֩b;-Q\pn%zhz.*sJ`c+„E! ݠ#hኢlZ詞I?&~ف\(3$_ã )AYdYC-΂!Y#D\W^r5!D爏  ?D%M<1{d0ɉ )V* wG LTj˘T kDnÛ{\n/t$J3;?<I|P_ӃL>4?c|8/j/U3Ln3vKVUCI^w0HwP2YZ7jA *z\izݭO<-/ҹ7^_fsQH\&og`z(]7^ew Brō]5~/*TG9:V a CT519풄ЏsXω *IXK *Sƞ<gߋ!@9kT S2NŀDs92[$(呜2jJn_2]CESV(B&<@zM?:mwlQLh2ǞJF MF3~~`7SPVǶ4!*@|Zb0wT캳}%6!}gb0FyGx!++ia?NFO OCJ4`ºHVdT ڗ\Cui)ˀ}q8-O)JBRö~،q/5Ϥn,~r~t0u!llxJM sW *۴فċ&(+=lZY%ߵE3bdĩwos+%n6qYJ!BExĐT_Hn{4'_|jAQE؝I`='45#B! C|֚>"RZSKeHFغ8N:ũ beHST{oS.AbIikoUrj׋$uL[^&+k4E_Lg.؎ Q*Рf28O;b=9P`y.3jcO:e''wΔF}My)Az>V,u<ޤ׎( k$ċD{Sno`zjM`v}j?Y\A{ƌq@V_9|,.(~Xm'صn} L2]őt);Td7rjF8WˎÞSF NyŖ:x˄l$=YM.T ,*hSt/id?Ѫ=!$ST}y/cV9(po8B=A^~QXj!>֢v iPD~i(=0Hl|;aj`>1rd虭9k⭴դ_2O\JApHF8B]'4jIُ--e3?I Z6"3I}:OF;DD/aB2msRѿSf>az<)'As%ߥ@zpdAn\(F"7%5gTZ X+rgv+6!\R4Cs c@#N} ~׍(ʖ͆k0#2Pk%H(>!*|A u.oK)\TOOP=3RX4ciV7bSI3]4ǯb(IWQlEkoB*m&M{[8(bˠnMO~ aN^ɍ'6" n& B\K}{T| EE_/;'lPkItVqidSg zJ|)V  Otcׄ5t^'zk]EZ!Mȗ. V94F-PȦ)싵0N|Sz.x;p|S`v+P *5#\W2'~r&/CH=fBQSSEӞuiKU:b){WȀkIM9;3@jcXħ-Цғ7a)$ /%,tȬ+)7kK֩\P۵љey1IH{ane:-! N[eu}RԵPlVZfMuWgl) 'sXQZͰ5@L`$A/SA=DWؕ5jd%eyy3,SIaTEόP%uzݷj'n`.(\ 'tVҡQ1O(4*JͱVWZ6wU{vN 5 XIb:CV5<^:QV%a -E? @ΣvAn>!ݷ?ז_/oq޾Mj ^M7Ƨ~Ϟ4B;|a S0' g.^#uO/)"p q ̭8xۧ-&@97&R% {pqYu&r!9Bnmiur>pI /֮W+>F-\^/[1@%JL; R)5f;`hjݪX}4MoXzN; mikσ fpuM3y?}YEj^|e15d@/!i~7*r=|Үh Px |OGw˜{1^<P-Tn|VO&aNb^Hx k^Qn>9ݾ_}m{O!*畒v=xHHͽ8ܶȫ !m#r¾Ps^/X,V L gL b>5[8f%eJ fb̢1V;sM:7AVvn^ 1w})?.G0PqGOƼOnLV+>8T]1 '&qEru`BtUC'1<6Gk._.Z/̣(L"Rn-$7ֈ n/sDKSb }R6m7|TµH_OӼD}rLCV <&5pV?R'/[a^4wDw%W|ʠk#h:O@|+]l M9GSt6\?r`Ǫk|򼷎0"8㔃0@)dk.C^Q'D6{= }:#[^ѱ{jtÜujɻFm%ohwup  e)x5#yAws4_R="^V#_Nm_NF}paQQ*9P!*3a)(0{;IF/{'hsqa\UC5o~8&8SP6\,~/FO~g>_37v`Rh=&Is%*br^h[)eJZ@$@p}~r['Q8ոw !]c,Q$=PZgU3k=,uJ5}QLGkqc'/F)GP'v=~C86%9C B{vq*dϡǗǍ>Es23=mFf.ӞHɢ%wlJ jDo7=[Y^E V콟1?O<65 8 }C9K|Ҕ7h Qa2'"2=f&`@֧'}e4xco`)۩|,{1Q8Tu̯,sqRSܵ-2KbfIDxq|W7aR($uzߴ;5`]C?*4Wbˠ9欕`xvR;?|H<'RՉ;P(WTw#$}$ $G1?%BgY_w" 2?Anvn\7EiCEU7R*]ǀsơJZsPMޞVJB>Sқ'giBr)0jo7rux+&pJROm;xI]1(8%zI^}K {H͚-!_EyfqF2PܩaN$tIҷ1 t7\sZ эiR#kƃƽj;'` Yh `CDr FC&h iG=qI4"S>3HJ? +*KsK}c;Q/YG)ߛJC0H7&뚆2H [rKqpsS(s #3Kf]'An֡̋y327g[ #(=U"pCckL@Me%kc8iƴ3lEֶnUdt=l $rR̔IO_i+99(\=_9Wi)@p*46Q>ލlfP"Z'u U\9ٰzh~/xd.ν9$Q֔vUh@[x[B`䎭66c|+ Y 9S% -.̷7~9$ӓTodt2dաXT_"Y vczd:I,9Rq+aK :=2T?] neS Jc(ΝA( lom)NaT6 $ޫ ^r\Cˠrw%lGv 1}z""e/~ Wgef\ܴ7+q޵Ɉ`^Mydlw=)9?ҼP}F2)SiYFsIӄ'$Ufl}M$ Eb'! kL%3tt&iߔXoOrEdvrE1Y|| v- ~LNoigCӋ #PBtK֟j146xW1DkVt\Ղ iܐI'гv?h޲s^Eqh|@uW2|l=iD]X 7%ȣ;"n{Y7>hәCw,~}ؿȻk%LɧZĊdRȷ'=]fw8&70泖b?ߑo/٠$OG (Ce,43akϫm;`h?)cS6}g FSZ&"zJ1Hc⎴@\⅟zÝ?R7e.'kWǹ/T^bkjZ-G'y=u^~8M0πzmsmhѸЂ㜅iVn2G䶠,CZ3!ʟft2[ԣ'f^t7`*2JF]}4 'd17 ewxlְtRwlNjܕ hq 6 #S /DL=YS5*y@W33LW%$8KS8a쇏8$̭% Gj}f]u<h !=RA%z)夊+WEɹI?66Ό ?UVMUF/ tfdt'9<;m"ym!uCDԑ%@ƪLb%dAFS֛ihoWVŦP3#;,аSS2T"sjH>Cx݉Ƽ Ӵ@ʅvݳWs'ɶ΃'-/07@Cuz*-CVb\a' Ӧߞ>+&Y̒jPҾȏIU6&L`a7c܋l>i1$L {!8 /xy2 a R#C7Bvݭk^Hu3/BI $Zt]xǦ 77t[s3==L _8nRcs^P|s>܅{a2`|{6[aFj1 i('B^8]e,M`.Z::깊O֗; e~)^=Zsyi 7r- Y_ƊvWVԁɑMO=vrcQ-ƈ\\gAgfDQXiMgm^'!<RJGU$ @n ,C%$Z ckIgL]`z)D)zR8t?8iarA MdzcO[v,XJ@?3bVԓAףLN+',z֋MVTE  1/O:*zv,RIX`~w}ސ'3lA *-CpyJp#印zaQ[^`ݎ:HwBE .{AtF%!P84:+tC&~'iuR)|\"#B!N T)4RX1',l]}iCP7{Wmc ͋R_{ۃl|zbЛ9%]I5$DckQ" _a5,x ]a7LE@r:*9oJ_ }mKɴNpG>ķVG {=h#7۫"eQJZ#g8nOas!C3|+zTҷI f6G4@<͍@`ι~4bӉH45Yl\t``\qFd@{0Y )xilR]!$'';ѳlf!QyCc%'We!>A/JbJQІ!9fEZcuu0G=#㦢rGngD p*1l!7Ч;e\xT>_YDe^ |kbnr>~ҟ/~t7H)ոp-)YTM< /~,VHi]_v NaM񺍜f(X4Hk }bv˔ LwQ KVg˷z`lH"FkjR| ݊) Yfl"8x 7TVRԽ˨Ua#+Bmy8O`54CK݂9Ls!H:볼닙t8 ji a";5AZ "ekEBD͉lg9U倱^`Wjwe-Bs`\,L,mMXŔI@{\ĭ*8Ts i*ŨzE_KސF['ۀA`&J{ɯ}zۭ:fF^볯uB2 &۸`Ukt %$ }a=L&ŗND&e aLi:4Ϗc4!S9ZlqDLFӤc-UίRΌ:2'G)а܆ag}ܣ e/I;u&o5WJR+*wˡ2j0%UXT.>;-aj cgONUpŋ<>HcL *q>edIݗͯ;%é0j*P>Hj|?][tq q?rr6cK n}Qu(IiW!낤zWfC\9W ӎgyLɰ7ovy:d̘:Qn(S33 L7]p∗Pj光tzmnd//;6c hjjv 鞋aB& (JtcVj̒`8wk;7j4%ҫh8al>kY63BP$79;Jfu| \M@}7WQм"[IxtYuXAHHi{T[\B aG, %@P+a#Ҿ SXu<pjh#c9v. 'vUNWhjI.9J#T,O6r.dKA:E:"fi!kSF~tA3+׍Ij e>Wq)GiV+ze n@pJuU&K͖֫Ē8ؐ}L$=m}dpɐB¸}\2v.2!T\͏QI`a+/TS&?S๋7S>?--SWSE9?R̤<:B}i<Ι]ٶ̯CL_{ea\r$~5^ɒV&^)dƪP+cLחhn^[Vۀ]Z+[|LiΪoVy:x5$؊=#/nHŗ8挩+۸{*\KDh~ nљr\{STԎeNNU⵽Ϻyi?Nt9c!!LcMXYBgI0Y:aѺdrl_j>~+ȬOaם/:;t'G8T x z]#5?;$9'Lbҫ%3,Zc`kY͛Hɥ98>DLd-bYQ/!̈́8-Mo }[OgtLv۴S*3V#tSVEngIa ,<Sl* LTP*1C.dbT 6R?jҲ±€ŋ'u =YS9k8$(M y5Zs6zcU-3[Q8zt0`_)#3s}zCR8 MzTt_۲Ly/urgF6Ѡ| "By"guqtLZSO'5^.6 ꝨߨZɆ+KW}q"¢ $= ]7ǶW)<}z¤(uu>j"aQYHQf+ w:$ϙA=op}M3)@|ӼQۭK4F)y欐Qx:=V5tW3ȚE~Vh wAZʶX-!Oڅ^^2BA bGMWqŬ+#Dž]Y׷8."d~J{:U ffzӆ!bJY$gbGoVBC*Lެ\HK|+2O&A:^z RᲕK jT\{alS" quT0g" @<P+p de/n}^ /k^`VxL Bchxf/͑T$hjێywvRSwkVnQr5rʲ:U-jJl`p9,L³ Nҽb&Lݏ" @"ܣmT-_#[A1ҷ# _@EvXB%mGZ+ {`jZq{1H/ˮ]i>D>Fv}㛑zX{$BFǍ XaJ].{"CMl;1C;T~[?5t 㲥akg1?p'X(ߠ q448W66R&s?D֡%)0Mlѷl}Jzz[zpĹn29: =y*_s'9 ]$a: ;c%eGMBE+:,wX3\#i:K}u==h ݃ $<਴Y%W@//~B^"F/_s[Bҳ[92;oL*B1zt3 fkNm핎zQ iUnKxA6bOd%rLETݾmܺ*K|/%B,9wK~RpQGX{uc݋c{#GѪ^ J5E|66J= r4*_Dg#?)SʫPт_X>څb9qYA2c ;7evDTRpI ^E13dE i=mԝSM@O-f5ʑxݨC4ܚ d%gLgft6wQQJ,BTG!d2,ٵ i8bM>ݔ3KA }F`Tf!ht' 0ޅ$YU VE:`P7y5Ѳ-.P;먙]`[j}T^(GFalpgib,0ӟ:;>v晵:8C0glP#ݣOmihƑ} : |H$[Ft6 <_ W7[W;Vq4]K3Wq-O.!?0/0L4`;Xw>f,8"܉-wQѥ1kk긘^'u҄_Dһ bIb)% ' Xג6,:Rh*"T$\ X~"3o XGQ7Sd43d,hB~^Z&IJC8D|EV,B'! ":vVTݩC^ mػב7ɇ iJ4r| L I_zNxpWˣ_&#N\8 `m*(=}b Afbs߸ijn$[o_Uq ]/KN?y>ij5) Y㧲II7ϑHv7PC}'nx"Z5 9{eS׍̖B.wVCʅPux͙6l@$ cGgXg{%55/' ގPs^$P$Ăk;CΉՐdUUepjf$Iˋ$fග@{4d7C}|p~d7 K@VQ֙9mߊdTZ>gj)bgv\ahP2䎜~-*Nv+U@%|s0'Xx.͘O`ܚɹ wV+C+b,ںVsL ;3J9C2@2[@2 ixe^tRyX\>'A$Aˡ$e佃Pqc(*rb@etрDfU ֭k@2r⫼ҷHkW4_'4y2egʉ7|ap5Cz|Q{9dv{nVu[K}"9@ ?6B@V2~eEhGa4N;MN<{/ڗ 67Qe+UJݐpJPs dLcOQEQOz{7w9`JQly#@v @1oH{u40[|98}H $-9‰_g"yuv&j䦊@4 㝭(A~ϿUce:>Hw(nI=ON 3 yGg= 'y$V*|aMf*7!j\44>uzQ\lwæLoH'^}[oV`]hI&ߴRjN%#䅀L(Q؝ífN\jR$V uPնm _ Ɂ?|0'=,r UƄDSTKntTWx rI'.omHapVjꪜ!M\<B"r]VdKƁ^S M@0{JTPqq]HVE573ّR:V}p[ 3u!̻BDNI Y9^Z8ɛTU@3HiC8q_٦tKFR *Ydj uV<.cBvĚ׶g\O5RyY0'(̔j4 "<~d[BĈT͘GHj}7 թԵ{_Aoǩ+a<(0= H>!="+7 IJhtUJzuhbE%1?Ꮷ:76cuF#LʳXW('p Kk.b奊Tx2ԣF[֋}`8ؓsz --i~qu*Ke r=UOip_ sd$=z绔cA>HKx#Ҭ;bYʂM"/{MOu.P/@+%Y݉Q  pJC;;^WU_6ȇeV 1V΅u"T/hbRЎ訊[\;<Ag|ˢ$)ΞʚQ Nr?2CFЪ#0HE 0촇i*=V{lsi&B V^GЋ}djl5C|>&Ä%`$"k,SXq?ؗ%j ME@DQ^8Nx%+yW>RΎ WSGvrΎdZwB?@9̕;&Ahb ̱ - =Zu8)=+QQ"rDIT:85[::r7;T ߼y 6rjH F0̖thybd7$bS֔/P=VkQ(h{o{uɒCm$X$כs7k<-rhS&eمxJQ hLnLʀ{®SS͟[\;Y5m'?qf‚WHF]DكbdgXQ`+m;H!7RțNUc#{ibL;enSPV٦ '5NɡC'7#N?gʱ¡?/F.B8n]{fKA/N& dsuyt؞9M5%awJXӋV9b,@J,]m6@^؋X7_!!miGt&6zTf&MTG-0l"NxA=B݀ZstR_T6kْET7ZMAb? 1 }cBYn0[GQ X^O) IW =L>bѷ0շ6Iӛ`n ö[gvwWJthOdVW.&յK94|Jɖn(YX#V#cZ:*-B(jt@>|]) !:2^2 :pÆK1|bM3;Q*y:=$bb++uP&p A4yS1TbfJ=G$uBl؞sv֜T55,=_:;ܓh K/&wjF'N!z?@Tڊ69d6ϐ.3ԁq>7Ʌ'$:gqlEƓ]`7 =1TcOxgHhS,&\b`mk_u v=1qKCzoEzBGy}=^^mX oh$px;Ů em;yuU Uf.|e\(gjJ 4nH)xds%\NX:i ]EHSE9p\|01>I |$/BmrkWKzʁ8mڻG-ny-7m\*>DOAo$)S(On1t:^]<^9)›=C_9$wO6'ҭ'? B_V Az/[&[zT@F =&mNeFI>'K]f 9C\)eQĂ큖,-{fEK^NjkgAaq4qQќ>8<. @HLԠ%uC]1ocb Hl+ϳ@ %́w'ŎY-\{PEqRpY1 p\^D̡kNI&ݭz+]^x2(s3ҘJA'UYBlV;)Z-H&;ӗg)vFU3WP4)DϾHd4э*ʗ?4Id]/y_5 丿+*@nS8mT> OuT.LVoYdEsQD9G1 ]I aodV.if#E=oED()Wj"lK`C?i}c?rs. 2)8&ƗM/@,Ou|o@!p=ONrAt0FN5tYIzkw#AIE a3˸&Z'XkBBp+WrBP=lړa绩,vQ^ׅLFWWt+ PDA>$k N聣f t}S9&Dkf w;xr5Xʴ kj4ʩmߧhyBTA!șH}^{=h5 $@E23lfH7Ak O>x`pY4$G6TBJ3_[EŷW7%.N[JXZ ֡"TX{mD}|0tro3Qsڪqb,a,,ݤ*YV(1AChjWM ׁ=\XɈ4"n& > .S8ۿA 00RSW&o%bKm klTYakxHER1f$3ݱ'q9o]vTꝊ x~X^=W%DSĈGxaږBz5E7yh\^(- IUBk)%D'#d !t+' AvKy9 yK&;6j3^:geC{a܀Tve&sMyT[LWG{j]*1U#ģז̈Hc͚|OclW'$dʯmNjo[Ί(3b1`!O;7<&$_jDSevTiRb8]GnV\)nL WU5cf:R^Kl(W ]48iCˋ?m*L߄^bG? \Mk  ܯz*Y[ECCa$X /a݊-4jnrhz NX3I;H~%;U!)O;8r|E}e&b +<^)U;D"hبH2qV} c&#F;.ͼGKgw [k8ހߕvX.DP5?YNzy >BGʳ+1c5.cSQ7&8BVΜtTZknna6#8f̌[x wZO$Mr1=TF鞅cR?w 2riD!/U>i.Ο۰qdW 87z?E (5,~DxSoT,p(m4v7E߶OZKͽgZvFj}:6>ׇxq|NM6.ds`%t Q">L[rX_bqXݢygimr-X*(%Q+/R?`,ײ"+ .#uaԩJڥ)"uI{k>3׈S`M1O4KzLJu58P&F5QpGaثƍIaoWsX3K.s3l*XpZ;3ըWO7PfZ'Yx&VH`>ƽٺ~|G~6y$h:WAn0΁̴j$0~ _ܡopG 1a GlG*3<$1\N$d23zs;sRg)vbe֝9׌AKRWK|y33!F@ZbUHI&bO Ϥ<?u |Dqw IOa(9 =ѵe6ߨ~ηlWxKCd(-u^@㳨qK)S581^lq,z $7 yVA/_f,\rsznޛi ;x`(#!F $?|U,Nk=H_:NlVz/  j!׍6:9 x#0 PԯS2N|ċed?x\1D,>'c*r9!rIDćvjwV:P6q(͍gН!ZY(w}gk$~,4Z JTbZnpZU0Xz˴*Ŏk19.E31:O k7FPI #4ǜp/6!ۢMmJ[2ө<(3V_AtL-=euxX]5Q;l0"ФB?m+iFYo>{NG*Αo7z< 'Y.lexIp<3.J}hnИa6mF7qt$>&_>#7'i{rd6+܁p>RS-60bOIwhu`rlo#wvҏe"tZ+l9tL!:^g >-ڤ+9ܧAda؈k m k w:Ya[vZ3131|106 DM.^/Ɣ)5W@~\`Q@ ,(*iGT80l@]0:m{HB&FeY`f`^FNxf4c{ !\a"Myɢ?]=21uD٨*IS^ݟ4 D/ߌl_feƱ≜ŰgM9"B)"* ;tToeJ5i}ݷ|h[yS11Q]qMU]L8/73 3/[}'YjnLmñN{\,mjh~*j v`RuuU6%.kxmOHjiEĴBQ?Y77!} 2ԤsŶуmPB@< W w"L;ve !R.c-Fz_5ɛٍeU<[sNjTM+uBW-1 2?%|aRś3+`:Oqm`D/ lbpm.Ux76^])=}#iL%I\ɜ ::t!anhD#ψv:à<M >$Ӹ;*3?`߉]o\ٛBiϘq5rEk:E~loyN)%a DxJ\ȧ!U:D|?7(16ܰ10$B5^6 D{©ig֐4ԀjUy~6fqE)W"@Ŷ9:p'"%$P;WJ9H$~E= ּTsM n.-8 esVI?yh1:SY9X-]ҭ혆8p4̈́4hC'7*~&rq:PiH`` #O?n9F# WHn7G5M}O1v]9)h`O h #B4.qV ;5=ٍ;>q߬C@Z6]a#sij_Vٿ  [xV;)Fb2~9R[ju0K_FaU>#s V&scutkJ%FֵQbiy5,EA4̆BM2/",aqz3ds7 Cqp {t>bw};M c,eaoyʗ<$>ob9V?tZDZzlzeS4j90{ۇqM-S:6-nÀEa(= 8H" _zXd-lIWֵ}:`!;.*+;fPngc%Ճ)ܔtt~1W|4ݍ'ī:ϱB)Se%/TW^؇<4jT1l'ܳE`OmstN('>8|dX%g  pց+NOAŲ26\EB598FH&=2iwj]`1Tj"8_ CKX4FLA  Dr@Z' %mًŪ^)XМɃ Obp_}[^?>8?fY+gdBdVUw{[dIL1BUDD͉1=9m)[ԝ_xZ&uqFiᘝؑ^(Q e\_*kx@ 4)FRwTK/U/Đڿ`c<3(Rk"6/' ξ*>]8r0Q8X3)wIT\?>kH/KwEy0rsúS3߼ BIaMsm.yf1AmSFq"k*SJ~#*roht=LzZUY,iP{zçHnS~~ϲ]( ҆BoB1C-3 a| Z!f(u3\gU7 擣[U9,6\Gh]h c>zC`(!;=h^b7_kt2 Ynք1f~}}WĕGW^U^ *;ZA%ohZT^Uf#VۣfkQJ[.N:E[>b5~_&?db. =/-hA_;>e+QM=R8vDydD?㿩KL ӫ }(<Jߺ?|agAnW(>]< $][61kҌP o6>0hi X >9^;rsQR)e}9|@dӮOKS++6<+<Ds~+-S([_R3eI4N{n\J~!3xl1Qʵ5KƏXo<-B~:z5YD@#|iQLW|ܺ!5u^!R-qQP(H8r9nړJEa5dꄆqZwd7!gШC0y{B ΞL#sA )o=f}0Vb]&{n7F]`a]ēI)2/+L7)3$&B9S/V?sL?]־Z ¬U5m)Td3?T"eMG%.D_a PH|OzC<ゐtN~BɕӮ~Ve9(t+hQp{T<^^頿 ]!/hP h旊{mDDs՚sO[az3;F؅ɹ,hkt4u qˑx'T뾫+SRh3?1eQAV,x!S ^zTۚ*p1X{qH3|bI}%3[֘_S K\Gci\(%w 86ȁOk׉O!( ލLgҙağZ_*m\[3')8sCGeӒG/+ 5 NuǪMP$.HEUiMlږUy?ltW+ϧk=աHɒ\3#⇤L/!~{rÔZ1op,>BB`- @7lՖiUJQay77*V$ū#L}U0\'JA&<#H묖$4"TY?5kD}z\Zȣ\F@@W Zp:lxZfvx^Fh"`OU 40w"cBT;ڏ"|R9wG&5!*k׃Eu3bN<ʣ5]-ȕ0|{ƗWjCn67 a>_8 YXU}= }Hv?\@YݴeD>o*fss#:iȏccI'FzP\<}zqH˸BLjIUx,֩q6M5 K$ !5<omGq^%aS޾B*L߆z2̤"'pLVP=vkA24YDK+ ?o?ș'o {EIZ1SADY3jn]?7@^@1RѶL1 4m**!)tlP+]y>"ot&(E0W3w/ģH5'~PH )]8R|tCEK*lj8y څ|,D#_f:5b<^'zF 0e$ZG#̢ DL#$cHv'#8C Ze T($xB)EIE8u:Q:!'?{3^ Ib,szpM{%j)?Yc`L&q1'ۗl=d^=b)O: bM0{a[sBN^Ֆ굙oPZ~g;&-U92V e+lde# I 1\~@kD[y=g$P{,ٵdSf$ó@ BaGB\)h蕇ĻC!;stv,\'ut:'CqWPxyeNUBzww7\1m\Fa$B*"Ú'7`5Ԉ!\Xv+@u` _*8HmObRuG"u%! G^l C#:7;6*+N8Tn,^tQ:1t9\ _y$$-H8n%>\ȯRT, e&)ޜ8l:|DcT[f O.wlz ,9MT%E 7 vI[:y+iFDcu2'mAt NWHZ *[DqX2~wҀ]m#NOS(biýlfQZm步!YE8 ¡b^ABI1 ;şkyyLD= r܀{`JKKG|@t"DH\5|Mc;$ 棼ıb,dt +kG>E Wݥ8as34\+|S}O ácЦc;Սg7r Җ@ w@g3R%޹ m6${E(!JօaV "΂wȘw1gсa@>@rO(u-?&aRS +ՎBah3@fT'd@1xMTO'Vb dzs(gP~"x~AO̐kh9)Kb"W3:YX#Y̰C7 d` iO+ jOR`3yd}-/:sғ+rGr,/il=(_>$?.lTcf>)zEX|`_."Fú[̀~WB%0ΩsNgތo$4~s)4_&L@ڨxq- %OEd h[]:zͲP9 n\ 9<={@_Hn=X ~ō =WB%dڢNU2ry?K>`wP Tvjp su/!lozwu–4ۢSp\ ٗhhߢQ`Krp^Z'@gL٣ܻ:NsfuC\6.5=e |Ts/ os0^#>twZ/q+ǖMar(/% p5ҋɋN#|Ͻ| U:H*b2v*QUޥ"L~O`2r0حF  릙h[NŝQ҅whb )~ NBH:%t+`qxy~1"sb$OG3u{pA$T4:?Z&UD$2t6L-"jȻ Ԍe(bUKm)Z0KuﻌtTxX2r's_TW;I-u-3!W:'7jYlW >.{pIRɔYVM?<,7*˰ؙf\QFܹf>s\ Ҩ, Lmp,+ '&5 }%G21-& smbf=AO>;]mV[:t79\K.17<s&xT&5B6-]M:LI;/I}1C#7^EDG:!Ni}Ԯ{P ]6މGZ3aƢy7o]۟ڨzv^ʹbFm"d}J3R41I bݶ+6C좟h\臠oc$Xw$ 0/17> o'[4waѕ/bb?GٔX5ntw0Hc95e>բ)+lҏ??+6 vvT@8 !XȤ< ցZ>~Sk/:25PŬE̓jyhuz[cQqYnlZOq7M~q}ע"T/Cjig:vpJXClp8U聈rHYY钱7 l;, fXVT/ sr & 79zF|L.$QX᱿=塚z=;cub T#=4$ 9?|:!Ʋǒ`YPNs(caݰ?ED6m_"@F! ~dO M[,Xի@g=Ӓ*9@ 챭4`}w H Z%hT 5kHzQ `\C݄c)5?~{u9 r A#4ߔr y+$=;g,<BADKlh_HoR fOA0`_]zo੷g:Re%]Gv5)B5Uv1NS Di(7~9d"'}peCyMi O4|ջDh>oJי`^`IhLOl< 5i4ŚFm`bmޙ@?S:J5ҋ " !WmVNY:q2+RhxI_ϟ$6ڪA,iqK  9vT.d^Щ‚#_H$_8GC<ƯJQr튣ƽZDse%ogQHg^Z4YU#kxxO og0ljQAaӓb.mga+^%E|+P.[Xٷ=4J)6)V'wLt@ '7|E0wp18MYKM~!"Еδj/K/M,L0ؖwz#t~`V Xf_!m?$.D?`qMif1`$$T<+]K:!F wSMHod]]ّ=v$ݍMi47 V٬vvm] \.b)%vnMLXB SD &3B/ _70c?}γ G `jYc3d[ d)WUH)ǘ,lQ5;/G[fO\DaRػЗ'q~yuB[?p,vB8'^S.ɯE G c!k<<%: +lv$ZeޅxHG"2*=V]$^81GIgȁβt4ɧk>ܤ׵T0:gaOUE4h VyiYzVd.],'Aq 菃<0ː~&C`"H߁%q< FW|`VE}RW)gp(["5;L:'!˜wqayE$] hM`^=COyEe>#XٙІ[jv왦?2/J싺:2O ( ;)8jG VfNn#*F ])/IL,|:is R66t j_Z6@}{Z2'n=Iq9m_b\$moJq~G(NČE#D1̤:1q8h %o\lnr_ыbݡ 2a%$y[4dFQ?Dy=ZA5N\e+:P"gp%uzW{%^ bNCG\LmAx2M3qj",mOo¼']qa.l(mGR.v|~ =e1=S\nӛGa'L!$ߘ<hB9Z0 kNb7d:#A%?*_ idGן%;ӦN^%z϶C*R @/\ɷ8>&1O~Wڄ]>F*79J)-ju3IkUTe;lm$b50GOڟ N=RkPWb̞ӆO I ?T\󖡦3Vj-M{=KZdv&81!?I;qP @aJjki#={$BU:)%+u嵰 98|TZUzX0.PѬ,m =͗dXk@YݺPx!¯M.cbIĜ9PWDsWqYSx\K,yctb| Yc"owFɨB/ ɾyI:}VJm O#`&_m%qobBDߢ[^52|k*C J0?2ZgZU<ٗA;^Ol򅼳QH aJqs&ASYIԪ?CV#֞)Ѝte/N`~oe|rs9'.b.u"؊!bx3z{<珔4.UfE2%yʊ CtmwT-fd|{76*TQlpvW =l0;ǮgJ ~?Ull6p591Ś77u"׫΄ 7.W/-Ys& 1Mcbt.8|?C"ӁqGtqI;#t0pkio|4L`-,~wmO%[h4mE!Vt&Na}7}b=CF$7qmMP>k@NA -QNF"\uFߕR)B2Fc{>0_nGV7c5~jx`Lf)pa$bڪ@ -=#e9,O:( q-vb0DCKUW'=Ig gA{cٵ>T-o*0m 1^LZ7GKs^R`iB5YUѶ3M[ }; +q'_Z>oF0L~/61rDDn[G<41[[^ֺ\TJU;$6ܭܔO[ j Dh{uS8tʐ ~dS=:C|%\|!^ ·oN] =0-Z3@FXjkR"T^Y"gAr\- 3חN̬}wylAru{[Uu>Im0g55uu?(;?v f|:}0;ÅOWDwkbg`L2mѽx_fJbj3tZP`k׃EםMlV>?Qfk33pQ)2bdwLfƭ˖`\E [90J"VЌU~`*0_\ҾJ5BeyQ#JBb'5& nlOܹ덄*X6@e NMQ./^9כncc9U~okȇp ǘF {-NxU 4dNIŒԓhnmOAȮ>QmQ+ ԏy)镔 F+[~$e@[Kcx+ `}gQ_`TFcwݰAv @]}$yԶ:U+O? zD~DL( [fI:<ۥ&[^/1 dVZջM0RMt ]J.na),~M=FH8|uF@׷|<7 ;i=^HFP**4N2F΅kx!zW%w3Q~U1W#G|("8sh5![*|ء!'E*Kj=/wMsk*ZpNn.zH@~-X1j'܀oLE~/U;cWCk1? -^i .=EAo'Gyץ<#lAV{G{,)L{㭑|ù~Z$h Mzx7I@28![k:iwZ&=ʕ`2i9UVP_~hBk_s Y #xH[Ui3܆b2Fo@nP--zsE 6Z}9ZŨCh:wao&v这hT8+iG[{ 7<: +p:vDK]N.?d nLLv\ol6H}MBvA2P2GqOUx F֊׵t)T91/%+.'=l_xd TR9+&tt8Cp-#%L m8['ݸHLGP}( ܆dyIXxBŰz+ʌs1UIg M-J(Lh |VI<26yB 7h}(m͜;ˍUuφ,Kc{꿵 OI/ Qիr}[]h4-O#/J;K3u9eipy2L!B`΍0o$C⎰1\xK5SYTh;_rYBJ-lXTHjܵkR/_+a1T:o6];?=W\G*ťlJCj2,F׫+Atl!"6?UY[7l9aCHuWtrȬ^wZd2ԀŶɨŅx%.J,0*,ka -[ ݟ佀\2'fp3fDa'uE:sD5._!(>0~wiOa\  LMƍF&ODf9z[ #,^^v6jA 'Vy47\<Ԛ%>CQ" QHr%J\o:D*dԀ!)NwKwLM[SG |o,G],79ws=,>cLع(0dalupAk Z+ FE@̔Xu$xkTqeТ<kÚ/9! R9yч="! 5&T{Y! ܌,/=aCBg+m[zAfڀ<[YzIJ oTS$x!t-fz`q?d#L[s^Crwm0o2^NEwR mYluʼ_*c lэN9!@* DKd^W\:놅mYTAF: ۈAAhUv>ayomxdR2TUr `ZGt9^Un۞Ƀ62e+,n U!sopc4*>@b!!frO|[cjPHas⇆D6{Oޝ%ɰYg:A;7ٿoqLmV3 R3c jETIMϣ^I;Iΐ$4)E 1V~Zd KܖuRD,01lc1`"bU$D N, Ƒ<^ow{&lј/(dCSňr]]VE,"iRTZ.SUOQ+Zm?|5{)g=!UMׯ>qfzՕ[:?W@5ꃢlC%('(D ġ&~gʁ5(ȥB8 he+-hYgŞQu?(%t ~V1XɮtR{ڴק nbB`yf$(f[VfH ԘFrp+N8^j\9 sh'ȅ*NT7C!t,`GHDĹh yz vLZ]y4{>R , h{<8c~G<++`ᘦ|d#[|K?r:.KIW+_ )(&:]9#a4"P;)DaYbkE'eNM!w|>:%`:DNu<XhSgߙH\ IH8be\SmB #F4vs.JFΝ,FvL]I >o%vD _^jeK0G1;`˩&(,Tv@SH}*A',1V$ œ:s}a(qDqWbİYb #]li>9U_ꛚ8! &is^Kcld~~+,󾼖`cbx(䆅0Rꗹ;}c,ir/˳?qjZV7%+䤪z׾D(kHy<*!_lzk32i"QMS9i]2g$_6M /`"m}soDۛaћ-T, pl3O\'tZ;`M&ha8":yu!;u]6aJuūXN=Gx1tZ#^XWʷGqa;`|pBCѐ&w|?(.NOA]!6XL*KJm~鞁ܺ0JV rJ2>(ckk9}^"g,,Ze6S f@dKAn6@+Κ:bͪ>˲)j6hZ nJG7=vp[p7N+x,6Z F<-.‘D "~Pgo50zL10`H#-P/5Ϩ-BD3Mz"윾@vQ'`!@w]EA3bVC-^"m? mލ*uɏ}jWE \3 woCܳ$8R鯊 W-{s? l- ՋT%HKX&A2\pGp;pB;SΥ:A>4Uߗ΋2p͇Ivg5b=[+. ?]O. g"\[ҍfDL;O ~eF-clzO*rv\;lםJ-C?F= To#{1S.`C͔K^hE7/ ;!L 5Dxw9!olŽv3OZM%(a![Ory.=[ós}[uԖ9#3U")qh\\$_`/{Ux|Hv୥TiyLӞrKPb`sQwXRO dIN]Q$- x`]& ƍ`o(ɸĵo^*3ŸH릦,U6Mvů|a7@rP;dWI5JM"6j-6j@hMSړov_r΋&(O̢$" %j'xqAP&1\ETWw5 rwi+]oLᷗA2Dkjlxp,F6Ze69͇Զ-fɸp>wE|SP? e>?Z0RAiăҶNGz*kRڻc`3>쉤 !,W"` VԼJ(^3P-bB,[YخP朏)d;?XBQ,3f&ԨRPbSݰ#7_<ܨzjct ښʔuL|f{.(YQ,䕠D6zQ@;[U'|e &$!~K<l1iYvZ74oT\I}Zi LSidfAS< ]{|Q̟IJI>ܣmJQЏEXhͻ9h?F> ;y rׁfFa^?! 84Ê[h%ӑPA}EFq_P88 ǁuT>mQefk1ڲ…vþ HgRAe,m04~Qm|j}1۶B] f@`9$gARW\OsUk0h(_hq; ޞkK@!:nzN&:!S HdWmŚC ErIqQ6@ mdzrQ:RYx_)%r*19m_k 3epL3skZTјc@-d4;ullUdh@> Gp;<:u;ȉ\sz0DfOilb'`NGbGSӟ zٙ) [HcV{"\>?Z-N Pfϴ͙ϹGO9BD KӾmu B'+}E@)wy&р?6<^̽l .m0 ۷鬘TZ0psS+2Y]*ȯ@S]e=1s;  Z -HP< 9g<1؋JFD% " *v C-8]1rJFÊz,{, (Nt9LMu'8_Z`J'4!g\)^s!lrðw ܸNg u\ǥf=1V] CyCSy5+&ϙ(ă = ﻨ Ml,^YLcEvu,we.H2`=a #ghHSgU&mXR8❧|^;Yp?V0Q!J2}NxΧ_vqo${|CO˖MRvb,qp(uֈaNC]5 ^&'^uq׌>&.FS̢WX#kj„n]fs/P/Wphh;I<]D-I?se),N!"J8ҾIZfNkZN[ ozVF@4vtjXMxe[xAL(0C\*a?[88wM?w\hVTӃكO,bfxIع]޻ Ǒg"JEbXCc$PI,^C:h"Xݠ"Ӄ¥U.܊xsXs&a˰ chobӁq3 :/6j džL>24:-œwQ" {3ܩ2/A.M:i2iPrM+Yۊ i@ș9oOޅIed8c!0rru6it$5֔Uِ9 +`E;|dCdv3 8bޅN(vX uAh.G0|rQ2ZႣW' pT+"β95!O|{XRǥlb[U='vLby  "veädR[Ԫ9jG45&JDvōkJ!p.f 77!_CA]f z#ۣ1ϤrJ.N%뽉<= Lů#?uX(>~ YsZw.1pT)y'"V?[zh5!ٮgR? p|:Ů_{w[LB$. h(.,g5qnLiP~ڙ/re|r:ZEomPj[pXHu:j.PcyEPdp:rrExK9]C"2|F^¡Z jj^{dqgOSKfO( vJpB&q|0{<-6+$h.ՀGOQg kN{ToJt!(&yVa|}"t|W}vA )A8˾ ҙx'۞7nHm#Z!FD2"շ3鵕 +ՍAu\pH%FtV 5G@g1桯FF"#zGa4۹`8jL/BHTO>U}ڹA6 r{45[>z+뗹p,[H֝ˋIN|Jl1DTbrô/<>!*>'494߅(xhR*^Վ,IoFM|c0&FJ Py` c_g"mw}Nㄌ֕)Dk^ebHj߹;7c*?Ρ/XP兤>u2}>\uUe@o_b:Ct%JUXЧɺ' V+!nW'oe3 ȭBzL,@ϬUPT@0V*S/@]46;akE>8H΄aPO[ٱ<9k&uOf~! =!)a66 5@,ʪlKS]jU~7(ϓþ Cxy gb+f>d=Gqh+l(L"a.evn(~ϪV?\:[sY"sEJRL3TnTV,=]a|a*ϳ~ۇRD$`L#2bR?SCFAdHיTţ3ձ ۘE}YݢFEEFf4 k5/{F.1Ǻ\ bp+3絥T7|w[|&H0O_`|ы=`P<+4ank9{REHf=1]h@Eʅ1ľg,9}2!#jmҖ2䡥fnXd` $*\h(YpYPؤ_[ |nԠ^ĩ*=т,_2,A,qK?O)BcWsKG8Lvwt#3J2|rMUkog:bS?҄!v;0->M6Tt@\JN-%<th4?ov?ڛ|t/Ul_vŏAN=+7j`gxR[C|8?TTeo 1#seCm#XlT>z\bZ^2!PпL^a^Dk~a50Ƙ9@O&Be7ֺ -Cm/UUcAW)ѪFӴF-4ذ1Џ8KsT[ $'鷸Amal8 +ܰ^C@dVHhȖgGb)M@G 6.1 *At+ܙD&}hqtw/$dr+x/-?%TLk`=|Y7 gI1R'̇zk!2,L`KT)ʋu*cv// OSPK E h7ߜ"Qo<]sisimFtGzO-ʹMwBu1|9jޟ(2Y^m7$̙9wz"T{ֳTĂcoV.>ҝ0-EFi\Ck7 s⛃09PB~>W㒹ٕ>}t=/8Q$!Y` Q5o\bGZ珹tuDcI!Le5/~~뉢)w s.鈘=;NX\[ 3Ei͐ +Ы_F77RiƔɖ*,\JֳZ'^b  Qޫ dpo i'-x7 20醘Y#hxx DGOb{[phm)9O:W [/>r)M 38u$}b  bŇǐk:| %aNZ6dĢ/{zdX0{iϙO`z5حmLsCɱڿiԵ ovCwѽk ӆ{vZ[[,1-fZ.ӝF sցC8ks{$fc1o4rՙ3Y whuG3&jdr4`Ōq}HyuHf<s(^g4"yy{NQ r bFWMjq+SwXFcVP}y3Ztd"QdR]-6*0<]h0rK(U{FE]:Ǘs/Gakqúy]h NafVbz٠;C=P){aPm݇\do$>B\c  t'"ÀD8Ko:\6L$ɻo=Fc毣F~[n7:zǝZi7Ւ$]=P*1x2/7Evդ'34乞Xܷo Mxb0a‡ fI:F΅Ai^y beFpr|AwZ]JC*v\KCQ?Ȓ0R:mgRwXw 7 tc*~Nz<.1=3ɟl,͝-B#<0&"o[XBo 7hx yGvg Ȕ9B0(6E! I&k>_8uqj&#VPPjz4`ۧ;^Q:D?3x&@vF/)-}ិ>=>C^[aBS-\чw$7,"YKcz']l.>`j?8+рrle kS~9˩<|-ޗ{^Aԛ[סiN xJ9ؾӌ/6ƈbX xei'"`rAD]9>j DDZ&,>masvRS$ǂ MM,gܗ> naҐ(z}-E`FӀ|OԨ+e揳-htdbFרL:`C֏N($cfP; 2`2W.s!Z=Xe}x##1$nC|JT@>m[S-d/M$3 B͢ЖO>oi-ucD 1k7!CQ ]us!E] ]F4 mL֤t ƊgvʭμϪ`$Xh*5п&IPL|0N1a&6D!8u50R|Z@Wg/POD_.=?YՓ*a@ Mq8A!ֱ]6;7,,ꃛawwbmL=kC[nuio{Lk_IZdcpQy)]bܼӺ}@*-o=fʽ(-!.-aGSɁ}2c;fϜh 1[s:ܼ%WMr :|NsCPոBzPkM$A˷.huu8Ƿ_$F?̩|%]9Oi |76{3'aUVuˀ8}s4kveU @8?ч &O~UTbrtdh!Y)UXƿ DKRs!̛ǵx, T䷸hd':^$Աe@4Rh 2u(c7Zj& Oob%)MabQ;'mgCG?=Bfbp2gn/W$i+~'qjTSs@="UVa.5?K/s8R+rC|.> '8i4 ,H /5Й!+u”6p߿P^2t(•>a;8܃Q-@R)&_(QaiW_̝%f,IZNkW$p}[]hz9B I@n;V1!(s}BIE88f\@k+>J.y})[?٪D_BʪLr5U"tii#k*QT3u@"hȼGc)-d/tY };0uHfD獢tXf,zhǓ~s18Rjw@LJ RkC!p=Q jc:$=9Icq>;g{7lÝ?4/bӑ7O=r; S5I]\-SfErM~rfm\IC j?{a/ fx\i4$ ˏ; 0Q-Fk2 "Ws Ly8,=0¶f1\OXR, bKiy-spH&+sA܁o$.2;a Vܜ7:)FB{nXNvȟ?S5w[ݕKT`(*g]%I9=PB)ivc.{$+L)H WE(A+a:5Nxp2R7#Lszi Af0;uio"Qڄ5QTՅGpU7Kp2bIN Gpdͺmo};ofJc5"..eBNfC@B%CsX9wp܇dQiOW'NN1g=40TNLQD鳀_Śz$7|_朄k=Wr5UQ]nvŋ|ldu;}0Q =Jܚ!y6ֱ5W,F͏B!qkDjbl43Y#dH"4o{Lqyglt'{3&ٮȻy1ȉ+ӧ39}va[9M:g*,boI!$ cnJVֺGH5ᚣt~V`(c_O"5v)9M4씀a0ɪ^f_%*O^p#: aMRz.EWbpR{)+Dwؘ9=D[&-Vkŏ8M[mX0jIE)4sZs~OOH+st?Fux/Z* 2&Y$XHO12~y<d@\>DM͔/lՏ<;{!|@*Z9n]#pKm1Sf5^ ZsK.ۘI1"G8f4nOs?5[4Ց7]f߿@0Ĥx @¾Kl:x\?>;X(%J[ I2}*cU17T"Locf(vF!I굜GJMbo2KP #]$Nl9WD9Nd agąM4 db`UzQF8\kd Vެb!7 EC X^"ˀY+t`Ok2K N\U~ԩUf)@_TafdvARam^E OxXhζ-ut 2 TeJ[x,Lk)_I\Zj:N0+$DWb Be#봂pQb1%`i`}?bqnn.dJj>ₛWWV}nYLѸcXtH?^*CI{W>B=P&OcGTFւh&N1煾 Kwօc}nɚZްoFҴƶ> s~WƯc^|=gSy϶yakȱ=C%^~FxN0F+SoΥBgXXrj:@9$Hq~@aXɯ]nQށ:D|+LE0Z!7 :I,1@`m nJ(h pPi ޴jܶZ.C Zs bD?=i@܋SsܓEK$-ѥc'sco۸Doi6!x'(DT%}eb7-}crҳ&"ɭ8A&ꘑ2^QMvb8R+o]>ޜ0̵Xd$2{QURNZu2k%>d6Iy\XD?ZSn*뜻F}M%qF9c'?_hK#ˈ⟛Y/(YN8 6¼Xh}.AZ#cf&D_d_-^C4Z͎U':R˾dwYWt>ՀqT9j]DKN鈰1UR짰EM'A^:YP_b5`,fgV0 zJmjiB%h%Oiv&d *NKל_ iӊp\yۣ <\Uvu~yGQj"Telڇ~@9E_qK$h$R16jy䦥mVOلT/T@Mb1XPՀ9]Tc݆WJOV\M_S5t:^ L|51$Q;"UwWHDḾy4t! -쾻  k۫bei}N4Ct4gBA,c`˄ ZxL䘭lBZzj`Nظsinݚ)tQVc݀+uue^X^' =BzD6lW=x0?f@%ZhSڟϩNƶ=gE7ɕAjDޞa@@Nne0X=6[IBc$O$ǡx~)%;?5n |cK vY712w?A561]z7tfD=?~%="yS!Q꡼M7Q_, 7٣Oz[?܋%SR0+{2(zWJn4z K< 7%|-ݼM˽!2l,{Z(iK .*1R)˖hCezOz8]'jnA9 @"LeW-o[8r A)3M=էof}P`V{S)0iPA "o?jk:k! 5VIg鷊vN>PS[Q&ғGhw^!qnYW)aۏ;mk'!lX^4Fz[L0#K"k-ov56$)s6=)F=4?l$9nuވmzӄm ݱM@Hh|M~'DlWݺF/]mk/̙RtnĔiA7nd0oat,RmtL~U@}i-z-Ӥ{Qq^ίo#:p8}DFCLdGzxdūLñ5NT>W胥IڭdEybBEofuZW],YJg%(<綐hAK<TI l2CL{ʵtoC 8G~yGN8pF*?j{1꒙5,= \/Z5`aCIۄto72oK!2F .'l$SR|'p@,ioT˪kp?rzQܖiȒ7Z '!.B pqَJF4kMԧ$2sP Z]Au"6.@UĊ=ܪѴX̽#(z0cu**yj-DY^4i|lT2b?}]M!/e31mQ60{ 19)S찰=V5Bl$(u|-  mj#{7^pc؊;?c~G1=w%U//$.p?'7CY7ܽyF;,6xt:pv9f8E Hj`XNImԐX@tbq]&cVPO "w ݺpdU^453 Jr֠bpnu'OM 7b7ԭs^S>y):e]J^?üQgہ2 ?g?E:]EuQG]ᔗ)e^qӛN$ C8ODvK< NЏQ 9 ,ug=}RUkwi fwaBp8O! ĤxD䯅=FG-*ZzD?hܥ@Q!kc+kǵHE9:eҿ/Fy3[k\t9ØK'? 9SPӒjz3e]{Y^Yz͚!9Uw 紒:΋=̠a;&@<+-).1ZV~>2\>/U-t ( ixp7זߪYK5CI?KՑõ#]֎kpyXQ ;S;,q.A 7;{~i"ng2r'Q{|-`V xrq8WÝr[A) `_l>?sFJDט"& |8VCIvqG"66 A~;K:OQ ~HA Q';}1rIywi^E8KDNaRqqTcF*@yS0Ŷ*L; (_e 50G3#3TQRLHNy%!2)ZE&˶2'M&)p"s[_ o!u)!VD/v߹'g#xؾ$w9e͊9ij!Y"-];&)׈ *A&ةuخ^ܓRI4?QBpzQoQf*)70t z>-3d }^3*59ӛł-كh}% bpf*[Pfw*PgcO+&IQrpT6σqLmxڡIYE|I^xSaΠLijwwb@$4x!Jr"?U\0 K(34$Ki8!UުwB(@ aAtQ@r N:"yfʑlu@*į+g Z#v9y^T LSXK+zUz;C3;2Nj sI(C)HsA8X>):as5s Ld 9xQ1: Ҳfn}c8l`6 *0w/2*`2g?MY"Ӣ7 lQbW}zm'}Ӿb:;r}n6 =.ThP*]V3~F`'N IӒ=Moro23+*džz3!Qtv֪ecy[Plp8vO逰^h"G&w<0`dj@eU0:'In@Ɔ5*GGbZ.^U7k70gH!} Ց8*N+(}Λ穄tCp0MU7+ L5PL8C4s(Scf-ibRLʕpz;<^'wՑlϫd'tAQ*tg,}pzDkvL$=IXXՁq',"A*M!>*mwY5zU w fܺM|u:V{q,OMYD_ X`t ׫> JT޹jS4< {4\YY"KA7}_-٣ևru'X^4QFfcTsq> 'cBjΏ;K5=ѝv[ $v„Ր>biiAԌА\߱d],wÑjSnC^?  Eq7JfSf[}KfxIVA2 [ |]<;c& .۠=hs4p ^wNh]C@)tYC);G@qi6TEpSn$nS:r\^y4?"gZ!E^:TuĿ֊NEcoau[64= =1@F 9%w#ʎ >Zn0M$"RcRF}cq;Q;2gk21zaM@S)ѫōF6J#|bWu2f Wr ]5 LAۃ3Z}jg;AK is%[i27W웶M_7B~B~ݨw0DS5H_Eґ}}P0vwTJ\JKFW[>Tj -BUЎ[\iOv :-_C8Q9CE^ŒM k&fkWE8e}˵:NSߓN_ѸnZ>M.}`Q/%ΈgMgG̭Muv꓁.D2@*see8suM(`䀜 019]:W˸7x$M+zDD(58br4_dl5#xD6G[_)(̘w &9)`l| \E]F 4lhMJDzuЩrkn@oTt1zrH *QqRxL[~NgQNB΄0DY~+EY56p׽NyyKݭwg\RaJ襞_!E,dD6FV A'>L)7r6kg/Mo>Ę$%ps^5H~M8<^M!9gU=i7N& Y[Cr 問$P6(%xRc** *V- LC\-q & "m$̛@oO|S:g~fI?E 5{,XG}zxpƾ?k0'뇖 Q˼=U_5*:OTkh"٨]'ɝ[Lg]U7Y(\z߉65 .C QDBb**RtS'b(.ݒޙ޷$L B O`_JbY-ڲvjxp5a鮝e9*·6,d)-F( ;W;:ƛ*g{3#\+ %جɓG`cT.;{O[Op[_*SبGV_݅o.o"H~&^f˧mBրH-5'4A?肃ͷ`fŗFʕ2aQ1! `#;7DaG⏞oLRN`wrӍz6955$ifSjs!@W_%+,wUy}1/wz]X{6&`(5_ E[~R,E=z>r*UXi&[v6"Nt}&/p^ (CE.ze^@1õ diMm}ne.:He?+VT0nÄ́I젚=/\EKB_zO;`>eprֱRi hR&U^9(RdYP6֠+ LUO;5WRA)E2j-=B`j0G$ j X8D`>|ᐩd v=G)pF>Eəf4= b_qQ5jA~20!l!7ڢUG^\ rQ+tI] ͭ~'Z@_Jۜ-мu e;l!"F-0鯿w\CSUL-+VW&{PEb0y4yUtz'a::̐-l'Hd~tX;]Ξ1<`4O)%';x ?jɛ4A,/v˞w$P%3r&ZAZ-14N b(9BژT;?C20𛍑^1o8gohؠh5N|ODxMc3kH,ѿ-,@2be*=I+ϩhsemy´b}_|Wsn-üν71{yJDA59pƇ),\wŽ9T ~˻b Wc XkݚN}4g@m;(9ʊXx[x=8l"WP42?Lk+ҏ3L⇅0\;sJbBK[9%(12W{-nS#V '="zP0H6&;mB É1|`pe ud1\$ڙEebyhx17B5'FGFDv}r$T\|dœy& dkXBat n`6:A nF(R$?Ұgd A%:2;~oۣoFFNf ЯV_#摠{NlQgVE4I֦`?D;t:l[p p^ڜYD)W8RFA*9N>i{|U!^+t]MA,_Š!SZfm-:&z/>(yeDW1 0WfΤ-EKp} :_C7wt6Wp|l.(֜) êhb9|{@<nŠ4яmܣV9yhG9M{%O9Vw`<&aN~gdрE.`!xĚ 9Wyw%A=;O'Z1 <wk/7_@=ʛ6`L3D&MQǫgo8j}}߆n 2"_fňf?}![d\|DqD[|fy }!9&].6ʼR>TH:f6Ei=41D5Pba:8P.ַ%7D$ Ym9}* m%n8I/w5-@iBWOzdQKvGMGg{sAjA`ZxqAГCV܆V@um-$6'Mw/8:-~ZPJ)eȧ;} 2k8d|6$D2ҏSU>Ρ.! .5l;*»Q^=E:I,؂R^}D, ]DV5j?i5qh,H-;,rD-0 do]hOcR##/g, o}&iN\=,y 4|mo@`e(#fL5otb6m{ y1cS`PBݹQUV"m x-6mR,2֔@둋 9}ZN*6=hNh g駽cIFp^7h` j,bJ{A@g0![;ā}Df7*V͉B~a(7 U[w]F(uD ) 5 4&=AQN{`x3 Yx C0 -e5-/JuE{EL'%JdPd#Kuu6 wВbh)+o#(SwہkpT|tء3AVCϖ@*f?P|KOOypVP,-X*gn q*BZ*c>Dx8UĸoYRVv/y]GNB\cb;?Uw9ʳAQ;Wʎ6(|*Y{tЪy =멓IF.QGu :#FDПJr L#CϺRRg^u(A>&7=mLE?Q`MZȍ[p{,vfh%b7flGRӹhs4it_bT4$$-fT-{ =|ӸT_`hR•2tfW`D6gES(W5/QPmM!q|kB4$8]-Ajmkބ5'F.%e o uE= X)Gt t߂q70C8zūn&_e[$GGs>zܑc ]QVxNvĒˉą+K 1]a,Ӳ`pM"ػKʖ2 (Tc;]mտo )ߝ蘳moY C?iʼw nGxdDX}=hvlr-uÈڻoә!kEz`h6͌]zAtJ[oŁGYbzXrZ'xFc/f҆alo"c!ױN^GvPج"DsuF׎fqbg*cC>xXIl,=19'j)/G+3 {j=c߃8ZaQ fAkē:]0<\ IR=}5aBSF)d{īrgsDh~b`P 2! )LFkO9D֝L<05tl IA|ȺOfmTe8w}YvMx7\BQx|hPz<8}:7gpuPx4ޖzk֐\g) 4)>ۍl^]3[=>WMh]/1U'%GޑvN/MeO]& |3,#zzt PƋ!4!oK|Ag 6Cֲ`UQrMI6'#t"X+J7&Kq4^Yc9-!3Hx>5r/'NtPߗ< dzrm$22E=OFxU8c^ ,C8=؏#3חX Bb7H}<)5rj)5@i$`2w˙;%0+ "JAUPDwpI|V^qu}^{#dxWf:N0m`gL8 W _BF}+t?- Ş_Ui'2+h(DL!-h<ډ~^G|n=-YO6ĝ)0l}ɺ2fYS:ͲJ 8W‡؃y0t~ZقH c.X"Q- A9259&0 W<.*%Ɯ׬?˳ut.Ά tz]NԧB̻1q]:fi1?wS]&`l Ns숏׽}Q#<ۃH5AJŽ{+M57-@ }FA%UV0%p[W+Nx^ ƇnMhE?PP}\ƅtE3@Czk$Z^{, ]<]E)m+)["s/ذe+cmd{*0`sêlIKߖ/x3aNo01 ztX}a0.?EE؜͍ɽY LRUV Fr8B\ `WN@PʥU]bV$\[CNh;F07ڴQ o-)bNOߣa^ 읐OYq plR9SK&cB HD ?_Ut$ BgзbS.FM.1pI0bw=I48@1ґ{W%7Ufk𪔳" *Ai5x/}/JN*Xk?>vkzz8q`DF4dPJ >fMESPOc+${0-i;[`B"cwE|̱fdkOm8\8qYI_nC59L\;Antgbd 3*X#*jj~X9< /[ǚTPso%! K%Bkxw=rLN?<  &6W}Ty\YLKHډz|ym~Kq,I4^r$?Z}{bIP3ـVHzSW.o: ]G#' .h9l$cSi| @l?.x?5o}py"aIqۤ1 |b6DJJ2d~F?_8eC$kwE8>e'/БU{if홥Jām:(&n/_͜_ZZI* fo6OМM(\Ժirs*8AQ^[1 EZGȴI11͑p;]}* J݋/~fF>of;ΚʆB_֔HScGԼhy07*gs F'"LMHco `KB"HHSoHkgd^* ;f2['xi gG;G0 AjrC gҊ|GĽ?M|e Ɛ*|X"cUh'8b>p_g)Op0  V XT'z3]ֺxb44BU'WQk~gQNZfx:J;40mc^%o>ːt9p;NVh no)  m !߅3 %}@nIqӊ+ K_^rqq9rQf$e y54\o#Qs?/F{v_yt>>A?r7@",6UjDXN5ǿ+ Ec(j,vfIi8,th%cRrܰs ԁ\ rЈW/Ch~4Amt6.qZRl߹kPw5_yQzэ{4{W?Ƈp\,EZ7!h (2%¼ ^$iqWm6t;!dn䕶)v_?aX`lܛO5H;(q<{`+/|,D#\3n=_>&BnfI|R_tX$D-@L.gg\z,TlOs)֗;_#PRN5Ap4#YZ {?9~VZCoJd OL "B{ JDvVIyS|lǎF0NHSIo +Bzf[yf Л8.943«TR2 "-K((i4z'bZ&(WnA?q2Ev2Gpn12 co"t}lS.H[;p.[@z+J:H0e>Y n9&рC јp<td Z"%Rsa" o?NB[H({P篭,덄s*:'Ki[tņO@4.ĶFm\݅9[wұ)nF4֣p+ZDߔ=V" H=' D chf0H/GIZZS5p L/TykY;aj1g4Ա/#|m}';cdcA@*3Lm'O*"@t ^z WضKY|#&qk#Zv~YC٨P|&ZUu-ˢ#o-yl `:'>z0,6Uo#/xFdOp?Qw/̟B>T.SZ 3eVt^ =6xO 0E꘡Rh ~*oDt '/kxJ;p1ϡ _ '!6ٍ^X&^?m1Pd_!L?fy4EItn"r߻#udvisz1ODT#!ePD*)~i3|#ZXZizzΛo_;ҕ: džZ:E5ŀRe\6sm 0*$f Fݦ`w0.=~3|R"%xgmOI+w@Fݏ |#)hN];/-=٘ _Bj+5#d"%h_p\'b&:ֶ8 0)iҊ}8?^ ܙv|DbqN ؽRw/#IxN%Z#8f *cdq zm8 ,ltL,ȻPQtb`A'5/(Ѓ5⡁[x'W>N7#Ql1$w6Kwj0 -[{:xSIyI)dzO ԊDeh`{: TL`<cm9k-)+bizweS fc}ºe>̛B1CPLsGZ)5֯BEVwf6:kBȿɵ. ;5̀U L_ФUg:zpS/ ~IXy\7c:Tu d#|cQ,o ڝ{sAX"̨r-;./ 國ȣeKU”m{Mu"p"ͪHC oa!;蛣`Of  *Vy]Y >|`#CYX2,0]yUVg ̀Bٝ0z΄)ilkT&^_"U{:wW*ugF\'Q2mbWaͷAW+zmɏWS}l-NB%;%h$!" /` A]sO7it&2X1-D9*~*ќ6u:mI 2wg#N`6*b_ًi2/MXM |iCb+lx?MWi.r-ho>9*Rb"/g1$hNiI>W"WcIWkMuҝfm 4_0;K-7s~y(iZaR6sK0JGA$ea"qNŕ<ԫ,nr}#իFzw@^its5^ [L9W ,ȇ{:]΄Z jw,o-oj 8=h% P+}Lt}zk$팖u4)az~C)NlStkAfx?0,+IlF"v/p%[4 G<]d!hD8Kx Kq]P%vz{:zY~,㜅!/R=|j ՀoT!{n%ڴl#"ݭRVp srPJ 76>tp w l R? 1jlø~cޭY&:L=ߥqVy3Kj%"zuņBRa?5gDjw&(KO<뭞rf\oZdv+ؽFstrHԳ M,OukLo=߅a$)Yf ޥW)8O7"kU ׷|\u^<e^V6 9fM~}a2FK0[9.^{mFpUIKi2 {Zx"x3w~|n[~I\t2WS!!C5bvISPy9KzbBZC!.5ҍ䰻|Ǎv/EgS&U :w6UAJ_X zlh(.aX{i 0 vkѸ&.qRAtqLW&aΰ 8;F1"h\9:3D%Vl>w4=xw;Ϸ wr-C}d)3ɍWJ":i[yӴ\Ab։l0YFrj4k!,Lvo3vOf(0]%I0NýO@=sHA_ ><޶=䞚IYT/toAb}.q<1:-+JAD6g0?.7~G3~r>~7UiM\^񨰈%kX jۋi+FٯB|useח&= ;J~xNa;N# Ja #cgq_쟤ÆKMx"X:gr{ŝ_ӹ2yzc(7Ħ*`̇ 4 WS}pT)b:M9ڟǔNRg^r%0OuT&vŪ11]mdwE#-Dz@np1++Ri+p\+:̙Pq yu!S(,I/]r_H8i"f:7#jȬ*k#S2K6=tחdwGg)UH)*1x!e/T++pK2%/[\ ΁kzsp-~  uIGG+v?t_*:\68M䞞WpLס5-Q:/h\ؐ 0/~_M"?߱JV%Jg*z(C jHXERXy(m})@rK\*ފsR@'BcOP?A2$e 9 -t/4ۯ2R<-Ϛ&B sq!v7?.TܪU348bxC H\Uʪ1S"٦#?WjrpΐbPe8"|g`̍!|hl҆@YrQ~˰] 2K@rIZԃ+jpW1#: m08)eOv,mV{s[IBϸ͔Lp;Fzv.vOzG1 v:TPy?T]CO1Ǜ!rG4a7']-K&\G"5q bnE3;C̕;l`Q30B0TQb^XJ~&n3)Vs+che[gͮ5|8Bx9)p:F_7@ àff!t%Lб,ک%h!Bu^PYyCiu il8=K_C1.wȘ$ݤWzU2 daBt0ah،q^39F Oǔܶ`ZLn NW8TΟ nSV);"IՐryHgg@izE"XX"X֩\T$+W:JM5Mi<n>Kk I^ ?]\' |pSdq.]!jz3u0ؚwC3 |-L&(,N'٢s- ͓8B|(uk^Ib`ow= 'Wphnib AuDE(9HxtN;55Ӳ~7Gu )Wb`WoHeN;?]zUP>}m쌛 K:\.(VfWيЦ ɑ,ҸMEzZx=.p+?QZPU iXuT\W;HCۜ"T2Ca:D77P_&ROFFXC+^&Q͎6m+9M]GpD鱢]AJ咽hy! @m eL;(YPr_Q6MdwLNg[gDp:Qz7xjaB[Qڴ GnUlb}!k&9eh܏=Gm.ж@-1Rh{}leGY 3*hXe ^'ud ZLiMI[NWCM\n-C?Wew`',Q"EE~@~qj?F~_" GAq.N x]Rm>]:bcZVLdTX鸈ϵ &AUr :u Ia0勩W/hy],.E/Pә˫ߊ-LeU2"FO¾7)T#| jAGBNF\sVLw $Ho%8دþ TU`6볱j\ͮ>Z lhݖxwWV-\s(a4'8w  $BT3I%nc@w1yqGnm=Lǘ㞻9]QyF9/K%bE32#^UJx2Bo /Ggl+xU;b6b@"uD0Fn}qeeӥ Υ8b\[m먈*S"Y,5E2G Bd".@XE'52Eec̍vK *5)?"ɷ Iqԍ1mϳgT:K[:vG_ ''W}SK~\`] 6:w(_,`׹<>K_Zд0V]7) n?>.8HqAxVF2;"Ds6)ji)eA43cx~? ]W2xKg)8aز7Dy)ndh/B3RhCF0!m1yO+G +e,&rSWY 0~LdӲتwxr{] q]+fIշ!V7x ā$"V2B:UbJXfrQS5Ѽᳺ=9h#KoA/9L+pW6s;$#[D&9P 5,):8$4+5焠BpzʥA@kz =_R(P 3Gb oơ4Xs$ |!z܁;|"-S$>⻡?R\e$ر]Cb;xTJI0>s%t=%J:חF(-2Bf 1e1.Zk@v0g} |$2΂K_1\f6E+а3Mn5NS[F^ǍWhA:7,ТG;,dŅfXrUX{RLsb0<~P$ ɤjPԂ34\#za^ʗr]7I, (Xl_1@ڍ*D?݊l ,jDDV]/j9+;Ԧ" g %Er<}D*|l)ſ.9;$10/, q,Ah(Qdh<Ō_dp1&HG~?e ;Y0jk6PR#E5J <0m`iqz@_~Q2 =~B8o#;9~hN~:akQ'Z}QZڽ<!g!хg;M^,j$\" V=%د.Z3bdb0_+E hAJ*HB'%G.5/ȭ c$}k$ Ixk~ғ3Kc6W{.gT8wrB6 | h*^WQJLفڴmGdss꾘BY.r 449B!fd8 HMysjZjx@65+UqZc'`-'aً+N񒿧-|}OۭJA>o+pOKp/SYGUO*@ykfQpD2<x"0u_7U(rH)Dc-A}ffb?mƫNj,cOv+%@Dᙄt6˩x@NyԒd+G#Wk/i`/6 L2bai(` _p_$uRHx簖^fda:r2v{ >wpCxLc!B7Li@J@Ԋ:-(R=?B_=4q_;4A9'z7-ZMK#{{5 ݏlAʅrՇy,kgP˔Ր mƝF0pIMCbP94Ej\,w񝻡3Z l@V)!ܠ9<:E%ѿͫ6W ;CeNR8M* /& 4/Շ %bC8PRZ,5V޴n+3y 6 (f-FG,I 26VN,ҪemD&FkI'8[H{eo\ x)* 3j&ogDH ^X7y|zxdV\?IpejB Z/x&޽*ySۡ+;hK(RܡXgE 1~0#|e  삙P[v۹*aEi0N1q ,1isdN@!aAZ5Vwܪke4%X&5ɟ ]7ޛA1}9pV3slW|%Kőxi4eQqf󴺩:<}^򒨤MioZ`d[>IMʎΏz)ybZVA:癦NeCt%WKhOcU.-L^>T}{2z>,}dhCMC`B;*"fOn+xQԓ-l3!"O4ӗ4n@9ӧ)$Oڢ!/P]ն}gE#ӑ$X8pQ>\{l+:ǢJGM+1eA\~ؑ1opɈ.a8IOdW'^]`ZdC$r<3oFT}Le*UAyp1MCR[򞮯c[Gx(mZ">\»i`T_39$Uv+\'J7 d3qK!küuG(tNXg2n] Af^i'1Ձe",m&GKbb4׃WHIBɸBdΠ/j6.%PW6.d\7SFZf<%74o|3=_2ӓL45{/bK)hLFϠ9IGBZVz_حݦyca 9GZ"b?M枧siͥ{$Nآ+6 䯵gTV :ci p?<^g*TLN%7Hh<.!q C=bWSPOvr %U7 FQhwBѫ=@PWL8Y#EömwERy8yκ C 4c|67"crĮՕLFdŝ1K&oKFl+w\>I%ΘHeR|9dȏ ʛArE5$.k025`Xe__*wx?o0̄o/Աd ` ʻfzAMS:#!{0s /{~bn+GiiđcSH/DA&ZS-SC64:fI9e ȇ 4$`QF`I]*56RPܛ]o]$~O[1,?vDq O[@TՍs4 sb]J8 o+ղkOe5zsbw#ωYZ(ղpART3+ e['_v߻~* I 9j:l8=~ޢ`ƈnqW l孝=N 4NW"(Sz, mI9H\"C@CǏK\H]E,̚^:] .{@&(JΊNnQƕ/{٣ y޿wZnG7;LLg%6ۦ DkI=WM΅5"*bX(y#Άv nk+: }s3#϶z JΑ+מiyg+#]GhZ j/Um|M9U,٩Vy/v>jy x](؀!k C0 -0M@ ,E7כ~*hta_3$ȁ=n)FIiv&;'QGK9\̄?'[6̓6TRҁ4ۭeIoWBY Qʶ7!d y v|SPZsBv ES,*Vs)V[5106A)"$cGu:t"p|Txq*PTʗPD>̦QOazbE!:z(QjP+I%`G1A}t7pL=pU(X&I oi  =ntqUIq@>C2yeDM\T10ՠMK.Iɟt|Gt5ڒh)N $lsSO3YLv>@Ǣv ǁՊFL^XP˟*Oe qY0(e9?;R%|^z*: $/v+ʺLߖi'軚!>x[W4V~+25$zi]Xꆵ0-//Q.GVKdM79~'Goh'1#?b7ᙄ՛@v6*nn6u !lpr*6^0N/Ll7QPÒ[<2›)Ĩ;1^$wmfEHU+*(Ulեp=p9xy9CPxKM-Hܨ%>% AC 4!WFaj:<[ aa9<ԏ~l.g͝F1'BJ^̀S ѝヨN'=NzHyYתG<#OL&5ErЇ5<'R$佟O.$um큗l?-r ˝6;hW95+(q=bh'WcK&9& l.Lj+bc e Gx,ܝp]ER CxV`W=@Vnܕ[{ -pgkQQ3(:>ReGĜ烧q6~UDhZi) K;:AL\*%ִ5qHI_ؼ1ۓ&鵡nзÁϾgA+<ۢo1%G_\ 0isoL1qd[%?{$ 9$-hrzއCuo"v0;) 1c|*k-],妍]v5)|nP/2:_;4y6!Z_sf&>yӀ WGE?4^d|S2"zչч͍nRU ljzf~l"~+ b蓔%Ut u^*YPqa3?ALskޣ*Ē5jg.c _bf ;J;)4OHy* Ezg@V*ǤoG s^UOSb]i<_en30%i|6ݍ.B;'rFWpL$tXvHw?SU sruNNn-)4x.Rrv 91LO* pGdʊ Eo96hp>Yb#m ͑xm 3]ȾӘ\*e=. T,*{zqFvAƹj|6#D2*1O|*C0ax9 <ܓ? ǃ{GskEPP0QÃm_G3lrِ$ +h)kL]_^"Z2Ng2Qz%E>_KYMu]9JAiqLBLUKDӭy:3_irz@=8ͅ@Y[9` 5u8H>5ƏFX=abx(Ke)ˁ]Z0,II'ߡ+#Ek#,q94O\lU!'6QM` :ӵs5 c99Gv3q8~5^'x.H+xg逥nEw&NBxOCB,B9hDu]nU0n/C|Y;)ףvO,s P TtzuUҍO E yytS+M|{(xu o"&gexnXKFdڹcldИ 3gUD+jk( V$'s3fkY1q=zj|g(9{!m iy=NknKo\̤^8S|$s{YA 7?ےiL4U3cw3vZ *4+6pʮQa56n؏תꢝ!vOAG`6)"CwpL:g}Nr3QEE^4=IW7>w9GkmsI2*ۓcRH&|`ۉH7pyDM 1)QH]AJ(}O Ҏq5j|[!AW> 4zAacECoeܑAD+s"7* ,Q/DDXc-6C@Gl|tZ>0zI -x)3 {-^2%ONcmKCB<213H>(4-~./Aq#\D6Vc{:\m@H*@,>( ^q⤐G=鰪`=uC75z8AS! 5L] 3E&OAuk`)Їf,f5:tO(S0JR+iMQAtd1B1p3H !N1';J2Rt-C\a]O˅"zP ̺7s^4]Wd7%IhD.)}ŹzI3 E6_vIeh~X:I&'c>$84=ʬw( +k}^@`KE+:QzDx)٧AL\#`wԔFoSpk].+y>$7IV'"$<ȁn$Iv97P[uz?9':k5zռ`o֕kM.bfjg~K3/gKZ 9/'ā9$.w=meI%Z9hg6Ibخh59%שJ HV;ʩ =yoTbF! fQ]8b|LI=vGB9ypi;%s ":t:'v OKey3d?)rW *fMݛ;*lt3 ڙ, /'.0)\n&7W`D:p^S/h(8ѓ-QՇ8XޑJG֪O z7b~&:@FL{21Zu/½ g#Cm"%/}F1KZ7.[?udi9ybTk7Zh0'yݾ%;a[`Ћlnal-JpmnYZZR)(ܵb$|5b@ :J6ƠH\h#6Ҝjz u$&p-ȮQo)N-+I5B(dENFG0Ҡa]# ۔5+n~#J̭t_EApP*5b$:4*(p1'Ma3ac-E%6wo2= ^%JqBnqC\i$L# +}lT8ϳ(ͧ"wD.2B{D<|Pn#(-2vΪ,QM6eˮȪ<D: &gVNJ(Ծfk\ I|Hҁ 6n}q*'YN=5'A2CV?r; %xb~˜;dP j=lpʘC'\i+M(vlH7Zˏ @!Yz08-A.k Qʜl Nq?ݳY<5 ZW[ Qa Im GTe,<@+0V:wV ^5'ݱd)@∵ly+e^=;_1x H:ARc ̌>0969TO|$P@v!AKiK݋'[흡jUqi {́ay73}Fڔj&h[NiIX#Oà7p8ȯ갇a돺UU \j&0O_F8\'͐vmhJ1 Tq:DwD#\Cm\Y8!N.' _ɘ[jgz-9akL~7r+_}dޢTγ;Ĕ/#8CۓG 3#ْ=Ȼ9Nפ)3 6XOׅISNFHKrp`-̀ һs,J)T~x"G.]+Cw[Vc5􅮒Q%H0t!__TZRW m`moT+0f/ֶ6?6p 0`ms3!7_=6#Qհ[he9]]1ppp]ŽfѪA7/-»Ç!oASl'ѭqP,}D6?@#\n e!ZqAua>Z״>T"?dFC v#2L]MR[+x %}Cev{<> 0Ӹ!tpgP`SVKOgO"-!"_"U%Ͱj5|fE'(EyIŗڦG&唡fೢ=GO;oʷ?F908YpE X?ć`N f~KJ)}缲MrWSَ !} 3 +PH@.l4WJ}QB{è-3bft c&>Ir.> ({4XZbs|K݅ a=c $ǚ7R'2W*w 17b3X6YWKvM2Gc.ϥe- j]r= q:j"{V9UjrA$y Y7jvlLuh}3ʑI߾2֖Nܟ1e-J+ fSIX' t,jUAkOhtP)ùm&]fٓ |ρ=ݘ\T0*²#i_mjo7X8mK!eezbP4nNTΐ*?zɲM.5-'6IP`6#nU>~4&KűAR*I<.d<7>&N3mU|iƚ'S@]U#$A8kA*Z4>J%7v[.$,s8L뉓Q`g*q߻Y]ӏ|.y>s]d8Hr+t4"=;ҽw,ooC+ l3N١ڃA R\;VX(cVu&]e]7"[ST_Ϝd 2µNZp\r}9L_3, qFA Q屳-b Ձ|@b: 3 4_*M4u*!A.[;F傴ܪHWpC]btP6?XQ W!JN!Eu$։Cm]>A MGLqOM{zaNc8GmG=wTD8EVAJnצǟu-%hڍ {.ٻa_@Bžg{u6 _uBϙ$5$)3!\-@ FQ *R/x;~$;|- isch|l_7͛[Gs^%<X*Kh9O6". @fKUr彍7 䍡 =q(eXY_1mb^h('n(â;9<-)YGϽ.yãmN՗1 y|cnQ/-~E WOlQv"ԃUa:m@XsD2H TGF+6t.lE"s =>ۺTHj\ehp\ߌ#u_ӫ^ 1Y`KV!_ iD@r"ˎ)24"Tu{/WSVx%!WKqmqCvG.%j/3$QMK'D (Z*dygh,__! ׏0$#rLx9̱Lϕ.f!]l hh LLٚ`‹!R~vU֬5ʏ21eDLOvl1ncΟb\\h[ϧQ_[e'qpW1RÔu}uyVSܚx*Jh V#+N{`8"®Up߹!cX1C^*ղ5+4GԖ%yDaw{WnUvuP,iFV2!6FkEQTTw _<4 uE;"S0“.K}y|'dǙV긧"v&XDh筺=)FY?\̠5jԪ\농HJ*Q ƜLm界?֒Kc6ª] $-&ʟ ~xlddiI>dX E8LE@QH 0wn(I£cA5vs8MIY5g6gqGeZr: hNNk}l=8΀_,CG iغ)F(1A`(Lj9oVPɂeKAFכXLOOz=s3Fcfh4W՘SHlv|{L}'RG֖驘 .0 ﵁|U`!x ov <嘥Z+x9Ka Typ1ֽ!5?r`-O&7k,* %c%MUO ²Iq; oqD44цE 'ǩӄih3;:EP$aaxV)h%qqw [(h-E;$8g+dZ+ﱭ?-hDl^]d.UYu ovVQK@|\3? Nqn;yGu\'ˋJjc cEbgܯkᯧO |S#AwM?HmO &#y #t craJe/Ȧd+)׮޴01< аkK1msLlNB2sKI_+RSGHrX!#[wU4Q60gCŭ :*?W $q d1_,ڸr>}]7R|HzTX,/G s=: :*JbJ߷"oV(?u/e2M?Մsʚػ!䙊#GL+ dJ96L5!R}ۼy$XP)=$2砕o]kJoBdx{.,rVIVs뎰>YF7e=")v4k<7yo+SA*Mu | K$[9 lh#:%šM)>B\#&vPWV~fR5k #G )+F7>Q0DM1- aU`ג"*a:͊Ǫ$,+d YZ