sssd-ipa-1.16.5-10.el7_9.6> H HtxHF_ ?*}}  >bd!o}6P4~3~e 5ć 1901210f0748e39b5353813d42c084bddd8a77fepPJ_*8ĈF_ ?*}}rld@%4!_RˣĆ$|/` >>$(?$d   : 7=D   8  8XxTTmT<@E(T8\@9\@:&@=AGLHlIXY\]^Rbdefltu v ,w"px"y"Y$Csssd-ipa1.16.510.el7_9.6The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._؞sl7.fnal.gov Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $Ks&/A큤A_؞_؞_؞^p0_؞k_؞k_؞k_؞o9575b32e0646fe4288e8714d911255bd13e9d98d85b9b5971bcc9c202d0e463e0deb5e5eb9c853c768d375be7860d3b03f048a38512e8e602df7dedeb133a7098ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9031cfd77e619bde9c4623921c1fb14b57ed137f043df7dd0b3f639a566403feb992bedea46c0d2dca2ce913178e0a6cae6dda1e423498782511a26508e941c5a358a714fbcd3632f9e54b1d9ae111f45903be25a1a8090c561f7e63c758362d8d4rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.6.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.61.16.5-10.el7_9.63.0.4-14.6.0-14.0-14.10.16-5.el71.16.5-10.el7_9.61.16.5-10.el7_9.61.16.5-10.el7_9.65.2-1sssd1.10.0-8.beta24.11.3_G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.61.16.5-10.el7_9.6libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c8ab6adfae24502e6fc5ed2280fe91b1e550fde8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=5cfc57a2af18a333d5f41a67a36accbd90e503f4, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER=W~=2!N=Jx@g,%+R N)dCUQ}oQ*Yľf.yVOLÇ966 KgQ]ğ//^@$Tx 2JT1cL.#UZb J9e#eߙVR;$A|2jJ=f)5Wˡ ׯd3 kv[yx7pّ&x#IVjhcKּ!Iq~j[%r^d>fOLdT̗$~`=htlq1cDmmǪ̏97H]ڳzz sڣgVڙ!nO: չD.gmhQ;@ !FjR'`Ž'erIESL:ڐ2?jL16Z?B=% *3'N4Mn dC)$Һ>R3QIt5QJ M.YSml=r{v+o Q$V%* Zd-8Rg%je<(5,TWڭWڰpBYv&9Gn)jTHj)@UIX]${:,+t)3C1A{^AHXUKyL_:MWO{WRMёRǛF5.YT(oN"ʟ8ΝP"Y^":) ; +-AHIkmW~6dŁZ7싣+褉I4v+ۂ51sD{Ҧ֋,q(zQ7>˞͉jlN5`PrpΡd2R,J>iR.xq =Cۺ-qYNeuO hq,#=;'8'qJTf4b} aRo#4wU/j5 8BᔲOvnWcj B4(N3.V3 B}Ml]*l&Sz5Egپ$n@:0{ q7=5ۑg6F8B~Ρo C3*39Dͤ;ylN!hXRscH֚i0k}bϺ)w:Sb29”5,k( K[y s;8ط̾9I=riT(-Y蝤Atalc'0-aϐu;wC^j@^Ns owQ1@Uò{:>Rhr0Wρ&\*ŒzU7wk|O.9? J^n.M޶,؍ z7 n$HD2(C4;βGρ+wkW]Q|]I,&?'! ɦiiH}PnUd} ztwQ^VėZ;\Ƞݗ,6q_`\z#p^NJC،AnyOv‹w|NbԉpVys[ElC<[BbdY\:<ϰ>|2tNׅrF,K;h/ҁ5_6@;K4$'^8 ,{nӫ9b~-Kr?~Haǀm A*D3㰿Ie2,0 5@j9Yy$&uL6Ut%9_^S`[!ϴUj2 ;XeG5ۼⵌ·9S!I񆕻S&Y7mI\  .uda|qc:YC&4qg&:ͼ[|QEU*[ꄣgӷ0)&$Vޠ ̼ƂQ #_FLi0*@ $l.v拾'#.@4ӵ8_S 8bL)IDy:JQQKms 8IXkGLCxo2\ѷn/t.u\J&DsR W39s_)σn@)C)#/Mw;:lڝX HzdX/&* U{LCR c=+pc 3CAOv $瞵2/ mMFɣ>.*C{`lA֫;^}\"bsOvJ hRL|ҶSό^^lئJcKlP(ʟgN5Q̿\iVT~ PyaܣF18^M{KsYdbȳ`c uGO9勬,Ƒ\KYXY%nrı D2dQ~3Wڌ 8Pz- `0"(=z cdrlCNo+d {9NjYW,c"X;Ky`Uۻ}xŨ tU$H#rCI$3y>JܣXt_L8puiӍ}hGz:ۭu>q{g ɐ>fPd)?JutC?v&+l¼\LLT um r#IV펯08vֹxO;=/@yv #bKUa Ƙ;XSpoАvEfQnM+j_ w2ҥlN>P{'iͿV\ʙ֗MH\_F>绽KhT΀ؒB6\lc" 2Pn> Qŵ_Dcy=g:_; j r 9xTѦB@Q"kB{öu) m؊P7X! ih$ w$J_P@VcWn\8l2_>WTr1ߩ$ʄw,:\e_Hj1 oo)QBF5^S%7:HS]-̒9#YuEլ8H{z.Ir7K>c*B~ٽ3*Nu'5Xa*jMr"V*\J^z]t?^Z~↾=EYd[*B; I1e`P `Ck@d!(] jzPF,3Nհ ;vc:Ah31z4RY@gٍjeW XRgTgbnNxG/ZOK4FbY}s9Yʏ;kAlާ-4^aWG= %l ||zB'ZR:֓ È0!į;.@1aߢ0xwM m|"~K#vedpi[db$~ٙ?** 爂!dwxÙt{cf4~yh yTapF: b?Oq=VAkG:}4Hpn bkD+\r_8Zk봪gIּFZG8vm ߁ppAk,/,v 'eNb0:QN wrz@$G =42X_徔֚OǧK`Eࡊ8f6?+ln9DG.m"i-D9/H(;9Zoc(@@,GaPfl~E_8UOE)9[١ d$ Y}5j=zYv`Wez ?5gE Ѭy,D4-_U|V`@|/Fեe2svWF-p'0%(|)Z7]F*ǬjQ'=DR ff ⫺5.!'`DWf45$cFR|ؐR% aٴŌ=-wexu(%ڛ5߲ 2?deU?җμ9+Dz F.C$^4q 5my{ 9}wLb\ &b*;=4nJZX>r,GOsMу>/&^" jK}EQ)\vۋUaA2֨?AZ`-qv,%'ySm\.gxr.uυtǨx#kv/}Fk`8FX!t؃4*,K"^6a,48(/]{`J6[UU#V/S`PR5Xf./tDfT6<>f:rJ ٯ QQ5ȿdϷkήᖯ: @dFw:3_X S\]nч.Ih \c f& C@K"ߛ%,pNql6ʙr1nf饢RtIoჹ/=c{w_yw#L2-H?'L;}\Tn\\^bIH6W6D?q)Q[jobQ +}3{~Y K$gwD(DW,#mj^e~PR|/?xd+!ոb^̿ƒ {0JJ e'?*Q}=pNpndt<.Jw1)%~ؕr[8Nptx`pZ4*_}EW!Fޡ˔Δ[)]2 iMUЮ}p8n} f%+ Й앧%$On` nfPy&js(a@Wu0#:d)kJIXzԙ0ǟwFBtד;>}>KZ3HiWɚ8(Jj:?Q߿sgSim TypxVt@ky^yATtU4 ʈS[6;49^2q^ABR>J7A-^jcP{4#QVg^oGtP5lu'  SW*r|]yy5)9hTb̅b*,P߰"5{N'"p6*a'oOJJjL2H暤LE`zW ޅ 7ćcxo?/d-+AMVI 4\XtQusb)̽0FV{?i oElhI آ0o3Sfc?Ɍ`⡴7h5m-xo39sYߔ}GnK7XE 4 J4veR4@¹Qm_='fT-rӜP.ۼD0;Úehee{gE}2CMffYA=㬱Z ? }? Rg ݘ7 ` G4"E~mQ;&5X v Xj\6+u6\\ dj"d߰xeOtTٲǖ4;l- >: Ăʢ/^)&g}./_wOc!8;Z#*B )9>E!uU.}qI􂴫13?iX4A dH=b|5"쫌c}Tb,uW\x;KMxGWa Xb@Q&)몤JN`8s40}Ջ7:خV|:U 7ERu4T k?k w6s!7Y,DJ #_|Pwh ## *|6s0ʇHxzvQKwm ~$/I-LtҤNy8`U=)]Wbߛwz3!v?,&G]KhZaJUEp% N_DΡnm(ݪ|P^^`Tti5o/RIWZhT[J﨔dM_ǀ˵+zj;'`i]`x8§?7%ZZ[$ޫ>͈Q6B`'g`6þ(t%ڸ:wy  Nb`6aѧ[lq@$pV֋+p R0Yp HC4 d kԝǼ.)@b[SN`sfM.DW0rS'R_!ԟUd7LH%[BB; žW)@ZI["F?Ɵ @h6pV?786/lIe[Dki2ԯ'J/7m]N fLF$Cf\bNyȁnK:3 Ҭ:!NP^M{:|eb0WxB &JVCYW ,apyn';htВ+'p;>B9&Zdb,8r"Ub^IɈR4B`k[<}. >nj3†Z]K/Z{nW=r8Bb 3Rh h)bg(Lp4L1~X7ġ* ~7nAn/! vɔ)wh {_ %ؚ_gjbyFybH]&_`L)b~z}ASMpptƴ:kTH̱\3 5 .X$W+K!cΜ, z *-R۱m,T=o$N#cWpGqr0 D6%?%a|$x)GAg "l'$B!19 I4hy8Miךn G2xhfSTFK(QYAg5O0-U' 1rc)-8|'Wç*?^ &GruXD7z*;db7ލ\ GR0Gy3vHQl]&žLɽU"Ֆ6Xips7 Id·-`A&+8Q_) #mHo)DGc+bW), br ^~ޏWq;o/1Di˅b R =# {4-P>l4PdFhvGjc;$N"*J/3땲-ײunH^c!.} b'^jȷzo8{ֽl wy 뾼ŷ^ <#g;,tiҁNp]ײtPMfsޚVЭ)j`@<F1--Ks13$nxcE)7A0 NtasW_whLˈM6#`-{w,!c)p=A儡U)IzB;Pê߯Ez+x7xGlvrxCc3 b$pI&M|1IP?jN]i mw".531 pAwMMF!rZZK+q0ŕa"%tI@5nB sP&W [ d*&@R:$䞕,@۩ p:TA¶F&JXn[q ̘zހl$ &R͊|GQo=AUß Փv6qљˈC`K4k,CCfDt#sAm.tu}HGDN xiHzbu*^32:zE6WSLKShjsҷEgoub Fp_q>CP #?5 [z޹ty &;K*{X1xLsmbsèK *IG;/޿7&\a-~6%30A3\/+?HNd:elAj ;L"GK{^Jޞt ]Z^X7L&hKE0N+qCa+<%_J^lfєBZ)gX)evQwR%Nj8Lw`!ʼ|ԡaTnц2ښoa1WY{>fc6:`99Dg0Y;g=ӋJ$p!h i%Ziŭv2$Od$~2DjC^"$C t"Z j=E%GڃRGƞ^e w&\׫ą,>Rm`Bð-8WͭY"v {$Ev7G}'#3IIdLVq /=7֠h 4^+u5㶇rni 8 2b9-u%ǮBI 7Z-a4 \vG9&\REqL=[_aKWO}wBQz˙kj)\xoSj$Dڅ:KT|n']lQJC0C€tԮ7ނFLw0իn] v0`" Er7Ju8*n7+g+)`-]߶ԣԢOx4<L(8tEs Sn=~sˑRdj2}ql>/u:YZk.=htQDhSMR^ 1^ch_†rI,?ʗ[[,?`m%AN'!)&fohJ O{rt'&p2Hh̩Ƞbc>+jM=<|F 8ƽ%ennlq&b)$hw]1cp6t.Bd@UIzƢS5hD2~D:8[}SWu唨ʷjPt|Hl*|%h4BA.È~i}\k̰9HBG??˜pgYJ+=>,՗3,Sp䨹ADB<3 4m?61/q!GTlwӋݣw.̂(O U-FO]2t892r3`qِ#~,27ӂa[=lXH2 ~ QD74δZJW64x_"dvD| = )1;g-J3of,GD\%)hi}W#ږA5JOhdE$UKcAPЖ=rҬ;\9%_bxO X(daaU SI ANfB,>u@~_}럍YQAd0`\@ER.;V<=9IQ /< *3 (Hhg)tΗ;]҉'I{=m{lђ . `G/uVxgHо>am* ikKl4p 3ч,vr[9Ft(q-3RB #aL+xEX:$ӸN%a%d$UT9o"V 2JԨim^=}G9c+!s1N\i#4]#R71w38;M9UJ,RC3A+v#Zo?G:U| :q0+OGPJ QޖP'awtpVt`c5A ŜmAEBr-PҀQگJk'ͭئnA1T H3rVfq|Io5HHU'*4 C$jE?WE.ݎA)?!f>K.Ԓ{vJ[k+s+,tя.ۢ}# Jl!MuI"qmCZɬ,(ɵRhC\Y&pT^V33WNG%Ѡ^SN>cz@GsRs)yQA7ZU1Ԫg(ᮕfFWC_b=TDVG8{kmi9hI$"HrT5dh^¬Nek aC3]lc/B)M!y{ C?P`ɷ/z3c*PI:ӧiel(ovN u91c&sq;NEOUs+%%%HACs}Hwi&ԡ7w>Fɛao[r:#>fDPOg Vsժ)B~K*&.I/z01[Etk $NeQuDMۖ R~;4 ""$Ycn/ ,d.Ѕ<Ȧq6uoYʧ6p 23& І>2VM#f^>C M~h|5^8WU2co[#>FM<ڪe|6H;|J ܕwF}zQ xl,xaM!vםZ j!l4LC!P/l q8Ot9P )I-a /O/ 9d}lx%`V8 (R`|LKX+x yXE*k&Mmbt]5c8<$01Hd#(Izmx>6zb e1l H̟ %g80UNYi;W}jr~c؄hHՑ:s ):v. 3t*]+i/~6s!6 u޺ZZdϤ*lt:!B[eDA#?~)j@]Ы:MhMdro^l;7S3*O'[&ހ/Xa%ΈMwĮ*qFA _\|q&]pa) =sx8שn`% IL@8͉ rc`Bx@Q¨PFR _C~V<W6@˨ŴN |)&Nek_>:e(v'LӎlxO'S|[o$O}R)A`8(]l.6R_.!>O[vKXBq2KqՃps" Qn4^."W:Il!͌s?O@nj7ܱrTnXxLAuxM^ 2@$WRàKqX~H *"0C9dzD$]rt#`qtux悱¨8j-K#C͌n@K31R|m*ws)ْuvGLES-(J lx G5$( ӑr@Q;U ps SJŎ{vԢh^%Ӓ >g HoxK(Yt__(D!/פ8X}3iK,19)~o!œHA!~M~ѶVxb?x(NnƕI̋p4A:6[z%!Kga 36XPtC ]/AGgƦе!/x9бu4 ŠxN ZI/]"lSId~c˒/CnsESǕf'XMCEl1W}'r eBBl |~(~@?/;dZ\-Wy}!鈺kyI/@lD=VMՙ\ Ȃ0w@Kg %Mʖ+yw1Mf7ஆ-E&reo9%TXOfsff-v.{aBe;W(C.-kbRj½t%Vw'0:l;qWt%7 ЪeQ㶢NX?yp[$dfQOE1iL~fMFyz+ N5gd*2-$`N =y\5% J+"e{ J.TWFh\q Wp{  !_bY3J}5VSp5h|ɫ"2kta  nRT|𙐍VA\]+Q)cS*$j]O<7ˑ"PZgw}VSi%-O{l`%*"R3 ymOUI:Zbϩ!'(5_e;_ FڻX Wׄm?6+l+zI>D#8s _nKiNs;TUL7r-KݥQ0</YK}HZ0r= };2[j)ӯB9dPن[Λԕ>7ǹ)o U/Bfm#◞0}2٠on(ez\/GHd,d*sQ$ْ !!T|Lz-zw[j/ekt"|.8X<FuGyH  ݋{HYKkQc&AY.$$~hle(I::`-`?c#jwM4$Xnti'nb:.qZcDwy~rc)~ }>uc$Idj`4;x&cGPQ[WAvtT~Ge^BV9wY{0I+et;Zh)E^zJ9ޞdhmt rM[J%uFdth&*ۂzVF2z,wSCD`}ݦXȗ'a'}Sg Yx0'$Oݍd*e.W@i2iծ `R6p?hI.FbBnO842dYڨ@ꍧ}kyǓ!GLQS P'&2ljt^oT!H,53' LBۍ:MD%<Q2}xKSցp $7k<|6wmfaMb,yΠMK.ʢ~R [ %هI&{TW6L,.7єJ UB X&N#%!" i|]+soiXSP:Y)b&H6 |jI1LǾ\%DX&&`2 l ݾ+>1*Hoyu[b&S꒓RЈ+\RȳG%XclSI8(I LD12`Ba0Db!"}b)1͗.;}6v^=[P6{ Í!c$d"(G@oA4NPrMA󉎗Z}"+[QsA>zwFD9C*u2Y}B4koFg6fMK[^;E,x&Q2<ڄkwh%8Q+ďXOɩfj !m(wG9&h aAѼS.*Rz{ (r[Ͽ/W%1~ (K&ygHE"W.2Y% [mYag :JNGӛC*NFYʖZ>Z{ mi9 5iM7|29V1"3Up\D)I7$Qj.nmDeѮ &,>o/OUz T撄?p{[1oע_ 6-(tyq, CRjZVpq =|Q.0*ϣ:Dl0&[q"PY11Ȁ^Kka,g7Ν,a摙g)Bi=8p{a~~7ՁPxgf2ւFfhIx0ؘgb bvu1G4+6*.4\ڤrx÷{B3lu 7m#5GOٴ:haGb+TR<- ][r68o]7vوcI3E~0q\q/Xު10[ '򁎳ͨL==#RxQ8dAba3H*,NPC٫@Y5 lhcf`¯l.=HZ7~ǩ_467 BWVG>lP/R11>XzZiӒ8܏kF5Xg`\%WD]|/^0Tf)x. ;.ާ1$q(1f_}fL[o?$QE`J^ݡ;Ka2dV_[2c"_o&t-fmÿՠS A4uY&JD4#CG 6\/: e+9'?F]J{>YHot]W&3o=]6bς =*'*> @b. yԨmtycƯpaztL0H`zD\ƒWe%Ĭ KɎMo)Ѡ盖|a  꿮_ZĻD;eEsbϣy!#2q]1{ΪzFSOG]}86Lv_bΰJ=Dj5 a}w:#:Gr;[1s橌2b|xuqN%dGh&]EV[vpF )\2BRq0G?Q?ReK7NdDYx~.;3eb 9FJ=,^M/Nyt6{^,dG${4U~ubҷf` ?y W.{V][lm,nJJ8A Ѣj:KcX R7u%:P}اG·KV'jWg6urjއ35sP<;3j4jJ*T$X}CwwF\^Vr4Mөp<R C:Vc9ڇ;[K-t 3ĀG,RØ v;a/E1 gn"[;!'X6\m(iS >k.n~ DR.CdEsDH%A l0Px m@^e0▥y(:{rW+ף=D#Jfi~"b-n3xI#m'H#9/SQm薯4&VuY29n|ǤּG[=3d YB zIPe1yPS4,I“pu0=WxƩQ߱y)8[X(=aٲKBoU[c%ђ+U8+MXNL=89t֖(}-}\(&l`8PvH ߖJmcvXbK%1PL;Wr ±dwPIF7hK],Fydb rj["&z 5|?CC)wu8}K(6߿ U7̜Ջ``̲C"b5v71Q2Y%n^:I'Dp7[F]ZʜMջ5AFF2'n2-HEչ0wr+#ht0YtRN@xk[{ 07`KJ)CS\g[rQN!hFkexnW bO7tU"~nŝ99f q4ྡྷx֐`Dl]?00YLY~.$ۇc(>@U2[3]}4u7ljU[ 6S~h}\4cg]|]槪Tȓ"g96 E$Yq 6+uyܩSnC m9! *g,P$?Ksؽ]Zꕐ19[1?7Ar~u(IWӂЮBBE'zOt riwl{_Uuz=0 iqFi@o,cAv y1ϸғ!3 '[#):7JE~ ڼO&t1<+Ltm#=Rlo!Pf֪.tq9bT ۵qg~p~cIo'M3 yC[x>E II]sj nLYD@$jm̙= y8k1 |Q ŨYon1h,#pñQX3^ I_g|OȆٝTB9ZN5tYKҕԻ#龏30230w!*E ,?uogyā%wdq'Ab,rH#8~xRtҼbK" J7*‘8QB嫛\k_^tD>[~->V+Y ))`fc ؛ `ZTAm* Dr{^}wejϿ&x}/.L㎦hKw Mv7+ cㆵ5:>׎Vgٸ;DL9†Ȟâ=LO/?V2TT*H;*`㭃9!c>=Pz8}q+~@\fЊ+ rl;֚rDp$#`ȝu,*A >eϗ:Q \ptXӉAuY3z8z>'tCV&*EnJMaXǻ \Lyց{l3D:G„߽Aݣ(JyP7kJ8\4ڽ-R˘9=e`,C$u:mi1w@Mzן5lS (.n9AJSؕgtn7?mN֔ؽ˸k ڑ߾:Ջ+8Y7>hMwq'={pȆf0~X=nڄ >HK*^z$i"JN>O$ `0WĎ?yK" #6P% c@,dT: &ϧT)ľMrEUQ\ym>+5@V2?ٰ\&E+ލ)ڜjH :v1q e7"m})z*dwI$Qe°~NSZiml@RS[@;jϹsP]H/C}0qznuw((geǀRBhjRRr*3S˧K3o1]Pt!@qCբ/\e|*Di3뼐f!T5$‚wk4Hd=|m hd~_KYwk2DEߓG3fmҮi^Hq  uWճ,E5ż'*gѲv(arI{] @@^ xA@%x=vC;Wp|gz4/ZQw2' n+mHAmGtQ冢 ѧl;a+Jxf7((Z^/R]hOkۢs@˒:tyetwrδɬ8Aڻ tO eVBԙ ,Ib2idbjM*3jn3duGl`!X`#&RY*>ᴾ̚ oBڜ:ƴ:@k լtOV4Csc%'A4ȋVAr҈د c%Rb`C6]%LNpmէ!KACRԻ#vsux[=:qh8#'H/#>:`I3P YE;%ZKhx;_[l"IcB! wr*U̮;DÿN{Af4l/ߐ>N&vr'IISG7>m{t?CK`vJi3ʸ!dagGԏMvz~0[OҀ^1 )NGk$ݭ?pQ8Tpt&T)T?H*t MY U;C],6WwSWq#-1䰭8eeмV&3wsf.//4 ,")/[qj~$_HrQF fQt-/Fy9ʮ^#|7ϑ!ٓɉ^Mb4>$ǚ3 RT:3d~"9t{q0W(($4,lz= * m'>0,]Syq*L`^}L(5Nڂc;&-ȯ`m^M(^/.wLyƘq/ &3 Ngr"*FxnE~,jNCC!dg%uX(4lr;ۯiYQJsBc<C]jS)و"A, l^e&^МhxZ`aΰh'(LBbܵ+ l`S* -"ΊFLf|xS^,88?Y\|ְHkokءHTYvn=1xN07ON+t:DZpJ="M.LEGH/ە,IeDjƒ칹]|5^Xuy_lԶ^R6?{wn&9VO77kSct_GP8$q0mAF潻KOei/]ok\Yp`Xa^Ay uWls=@W|s!~ T `!yA7G7 84-g L,s3I;E朂 #F>p!hI~~$ӧloB{K~L#]g_}B,1_hܚ'($'i=S}JS>k՞Xy >Zy"Za3ɰs%00iM {Z-K?1qE ^2]u~?&v?nH))Q_ W00Rɴ;s3HɗjpkBeoa"{{ҁiNP5;fq&+LXվuz!etw#k/½luB$W\Ge! ž$3Z\mkNTprJ؋R~^#M*"Rp$ *j+5eL@âQ\fK V-9Beena銭nhn fZUkXY $ɮ5Nиi%n(~3uuvЪzYͅahz-`}ytۚʫ}_/\6|c+-\fR.2;C1_WU`»XLLF:c`\X o Qa ϴ\‚r }饗R! 8L,8G"

ʚ\Ҫ4Kdd)K?-|фj[E&6mvl$MRE" {rD)!B7&:΀v?wU=N$Μ#TS vs1[Vs8ﮩӵpƳH %If!e޴0/~ڙ=vė!S8~][5rCk/__BE>dbac'U&{+.-qh 3`Au{/ 6|.tr+n9_Ib 73hw9ۤH#9H\k~W{>/;6֙68"Dt٦{2X=6spTB[ȿ" RfL sP" _lZ\U4]D4}Y(m7X,4Y&9TaַKq}r;+$ u8nΚ, ~ };a} V3Mb_[<`@Zrp2[tiʚK +ƴZe;[6w>ߩ&6`*@?s=L>m#][v䢢kS>_0G$v_|v1Hb+VTY]ڷ }z8s>܅qPREWF/"ŸX2]FIO1r5+.I(<(1YGB@Fӹ<̷f;\q_8}5pC̏< TfQMouWq. T}~pI{^"?./kxk5D[p(݊ynDӕNh$X8[?h\Dar"(@pyAA]mEK: ǀ\ W) & q yk(׿wzv뜯m%*W_@bdѮ  G7ڢ3,M27:⹰ߗ.tѶ3B+r_AbQsdMV'dΡUk86 ƃ_&"E {9.qD!f~㶊O=:IF)_|9 y΂plK?p Z,|ikY#;?(cq~riF:&}kF=pc#*A/ רП,+֐<`ŎyWAG "Ñm[%roz@NܥuNhΊN&ۿڊuIݢ+g9Ε=Kw.JoIΆL,i>.C} RYuӖI=T^o6G f;^Ww {hg {ƮϮuueST J#@h0->b:R>Ƥ4!<2oFaa%;7ZHL/K2Pɍ;f'%-P 5z# yώx*\=.{5[/uUJ cf6"-k@it'n{8ӿ ۿ1=r{rh@ a@hI^=ڪIc8OWy[Y^(d:YFn?#Wކ.\iq L%-_&|5Mn}E~DH'ڥAz^ŧ1-qɧW^R5w 1,Q *EN\Ad+|%C\hm B莸:O.d65Yh^{baRBHf Z㰧2՜Q>kSq4beBwF :Wvtr,ca-PMk;¤qmek[t4jpx!ɖ$P>j*HzgАnž߯E ظ,``h;o%XċNi"ST~0segl,ccl`e ]hNޟI xT礞K7U ,MEO j{`}~k jFI)= gK/,KDdV P'n3R'fP+FRvK ӽcXV3"+Q =N}х96gIic4幻QHTP T~]Xrۢ&6`r3j=gGLe%#HȭG(mxG][OWN"0#)Ux׶ڭJR7QUF{3?N=mE$If%Þ 䦋V-AuՖZul9k|sG8%#CSLf2.P*lkvFwkwB$&t~$-Dy~(K\k_R/ Uy;mQn_(䪌*9B _%;M:}"y/:v|qb7dZF]`|<{M^ն+wA,}X2v$<6%@'{6ai)áъ&a+gyel'_M_\*$ET :SrB>CF%,X5uXW˭qΏH vj:u3x,uŧ I7z0t}vڨW~ȽB_Or;oVP[b^#| GV@͇*}8^DOPТHB쿒SoI O1&IZ^p{Ra(rlυn;>'"T?!U/>`Eaَu@˪ei"RYp> Uj۝s(Sp;nVdTФeJF& ;gcIo5هoLp"Fz ͣb]Q~9T9RiMz]G1ks I,-23"lb"sCbAD.f7 9$2+^)gzA ЍN A4c~P &0 @( :t2N ]si8I9Hm6[vA3J00J;#pčFG쨘 VjfޝZ OΑiE'c, G3t*~[5Ğ1n(/7;_ʇtar~J|L'% FhQ*ykHWOk߻|(2ć͵B,$\R|Z'>W$2Ԣz/ҍ35Є/n II.E`< ~[{|W\U9/=2mc_#+P8]za+Gm[ OL6¼]AY^ ̀$AycmQD`e캚\\Ya^ܸV8'%a\C>%B¬D[k8?:D+hs O՝E+(fL%Rdyeœ Xf$ {3! 4M$}c> 86Dnr?~d)]`^ü"*3ftB㐇;zu iLrSY&l$)s2SuYUǞfE`?cL 1(wQ5d#NZnO`-(IGa$=8C=m7Twejiӂ Z"]Ƞuzd줧y`w9D1wk©\'g6eVHОIeӘ2CӒiQ.R "1\1EځK[6I"#SYN:'􍗥XJwIl9gXΐTUfq"=sc;H|ߥ&mG WLR/\hvR=kxj^ K $(FJ5j@;k l\ Dլk-mu ^g~rh.}\$hISI梫΋&( ebq:d[U*A/ehrL>{0 AQћh[7X`X墇~pRܨ~b Qn4k`=+Y|~d6(`(14*zX?} މv(cq8ltM Z,u} YGToȅ' uRJ @7OM+c*魆kƻ ~;RNЯLP꫏`!vinAgN_&t;4K@ۉkH )G8'W vUα& }`%m!>Lj(jy)xH#`ƞD0ѕH#~ Bz H20yT73lT l2Sǻz'o/`66=辰uyX`^m>JTjW%g ASNxdE׽c'vۘZoGDĢL\"\j7Ax#9viELh<1VS1d6_f7au&tALT!>SShk2ʻF`g$%\fj5xh7͌#n}?ޟ"$t JFsJb aug>dfNҋ-YaQqd{̿TAT:KswT=@H {LkZbnzZtagMJG\ 9Sit(G繿Z<t,\d ZwxMX9 $xF$D,HD&_XOh.`hmZO Z=o_vP&W풡Uy5``* %ȿ;Ӣ[[G!OᮄArs^ xQثn 8"F߱ԭ t ;v _dqoߵJ RLɎ܊cOKV%8?^U^ȿ82^"~Z.<~e%ud27eS#f,;\0w+ P$:7lJlSc}".8l*}) E5}H$(/e9 \uS:ΤAg|±9ʹ^!$%n>;`JH!ZLp%T?8:fco#8(\Pqw W`^`4g`"V0a] l~ ΙWoyPǁJ&&j%@dd"_ RS/Ϊ>}y rc7Lksz v J(&a%}o"`6Һh(<^ЧZStGhUSN'@fGU ?X7={*Q;[_e(O>%?nnQTiTiDm&6k,7O o.ˡ[\-}#ʤ'W9BF3hy'<-:.+d-[blS;I.΅gllS{bHmMB®܅5Sa7Sq˸T;,BFBhȡ>0JSl@PU6vs >Tқ7]Eȷu\F>uk7NmSrB|‚p /,7"U>HfوIm\!C,DUfUcPleg6u9X\T@u+k=C`<#%aUUX׳7tAhqoDbSنr\߉*>z=@3 $5JG v ׽,ie1z½L}=jDr+,"*dޯIBEZyDA3'q):)K1, ^i_=-ԁ"aRW?َo:O tMY=>;Li #7|d€~AB?Z8DS*!Bl*\Bq~x}>yW@̅8>Vri" CLlzNhңLu_3+\{fVK))?)jY%M_f u ׏~ز|1.:$g`.!Dqi9[dŗQ-j4)Dʯ,@~֯.hY Sy V5wO+O`_rd gOBΓ.pկjΤut*ae~ؚ!pA넯A (.QBP/l`& 1*GogR|M*=ko-Xu *#IVkzH[L˾Bv ǜ_Cl=t eDӼ@/ϻzH* :u?X9G?L%Ad-Ҡ޷skW`R4}J Xs3!S4mCHtˉ326l %[1p49J~D?j ׭kf& m.nc/\UDl@n?H-P秴U4zÝDO_)I>zXxBzv*15 Z"ʙHyX1ח(P7Ѩ_աee8T c+ њgN1?6U(NEye]EkFW4KK8)gϼr?7yc/K +櫎0/'9w̛#{$2|4;5 ca%-ВɜYOmd _IZcזCq|GH9LwheMkzV7FxǖL2 _d)ҹNUarrK0G ~D).eMG:PS8Q`Rcgi-V!c(GRMjŕ3*N4U4ПoV16@yPA-!S R{pr١c}p`!F`6O#lB r8d&A Zivd5 Uj`; oXn )َ18UKN4Ψ>H/ /9*`̕ހR&Ey1lw#H J:"Obީ 7Nx@yؐ[ p»KH)@> pjIZAaݢ55 w]Etlsgh ɭmn=͏j2Lս1}ϡ.&{6\On%AFF9TqMigc|;2^l5xAuD<(W!l.dapL6[ݫshɎ ʠe1 /MH Us% Bgb~]ᾮٸt9[pŞ:{ mk o%a!lIo OiE $Sq10ILP3ɚ* Qwo {,69 Ht!^s}PKŋ#iCe<;wOKa6 fyC.3!!k-/aъFc쐒ڰ{CʪC<29MM~Tayp( 4YpG[UTpD?$r`r9X;VEAV؂ jl . >ƷkF{_62~4p^hSQcv+/@[E~ptB=#B$뙀}!buػΦdBm$nT8pfvoa3|-f.?Q!V8ץoh % 1wS257K^#Gsj!>KYx<.0wxAX>PB[*dj(=em) x;:=z v{:4ʉA85dڞP&Z6C۲=.c.3[IA^1'L}II,AtJӡSI- 0@ t8z];K,~$/[ {"iMǬHQlǵOs8""ud#g۴uC W&CQ+EV)N2r6!l[rޯBTH|g3ɗڙh9'݆*@wz ` a2,xA̋*")em'CK_FSUpF尝z* 1P)8|׵%j,[ @z%#ژ5. ùt?V<q཮&fז~"9 0VuL/ABDj҄ЪS}VɎߜra[q d%Ȕ=͛(H::L A +d-Nkutk r}l,'UnϊY5o(LF"h;"^D\KS.-'¢ xV6Nfho[2] $+Y*8.6Mn8y0CbSlCZ A; B륻#SOg _Avr4I5!`x.Hē1#+DB7q`gyb՗v(=+9.+/>:߭=К"ܡ2z;= ۺ"]Gd0%I^O-Uu$a3:,")=kk6ĝzEY=Zr yj-P "@H-n|FK~3xč@*2Qx;9ΥN#zϥW"Ǔ׋")2U)_U@1!%?Y#Q\$ݡ{aL#8oE4qˉ]~^F 戡lZM\=!,A~ ~hv+]-c3N= ;W}P;` VsST_sUOTR^LSg!C/ &9}}+v򕛽t+y FN՚O_Y MHcPuqɦgǬ[D420B2tGQ4%X#.d/_^Y2+ g5-Mj~-IR0 JƚZNe)5!q~$`͈ :!`hQ: 29Ԍ- dUXɶHazaR p,L-^.P%HĶ30Z5F(0*xt_ERl(K ^2? rTN%,ȼ 7s4i~/ 8p/: /2tCU+`Gu H9[Q09>B傟8%cf؇mK>.\$r; p]@@UK%lK=νFA3;?Z1򂩏2_oMAF:QDW,z0/M-R Tr 'ْ_CK&!bS$cAet= {?y{y6jRH$C#٢=Rې g.-e?IVw*&)i.;*x!ƈXG/u(ס<`FMq(cl6H#s)\B#_ !`Q&)g0އgW: fŹ|[Eˏ?$_ o;qe~bV;A7ﬥM1O>;ILˮC(aRWB>1lBYO_֥䫥7P3_`~@0pJ YY5=.r-n/eMf4p8:v *Vꇍfdpecaw%#kW 3YaKYeO8O x)#= Ҍ'g o/:WT K] +0]p>apjh2r$|C~Eno∲"%a Aot[$~ijf+: һ,0 6ixzdޑmwmHkE uR%,~=Ozp2ę'/ʎr/r(Cp v@Z?a.^ U#]Oс e7㳳ʰm7e-ZOkT0Yoiݨ>/ {7afb#Cˮw1}`˖rV.͂fPAb1}gCsNtItajXn8 NF'VVo~-wgrJTvM @$=jb{-r輋XSPօ6&gwA$E%p|+1uV y( ts^e/v1M[$9;Yw%1X}F3~(dOC6LƇɥ'mG;xdX_ļz5-Ryo3l8sA FoZ,NE ~6(IedN Jgf07l0`fdob*!wfCWEu@bM5,AdMO@C_q'kGdDZ PoJұ?C݆SxyLqZ[3w>/K9v"B83Z=vC$`)L >]/d80'}n2?7gRQ,;kh4 #qL*7)C]OO{O jG?G @.>e6ͷbp^bg@>ǡFdKdfZ~i-ib}M}Y\̜cZk"P S!\,vΦ`;kM$t,֬F)O܂\~t&:c G&+k iÖ!&Sd3A2^׳b`cD1"戚H0gXwǦ*ˆ]$%75c}Pݑlʞj3#3HW: $dF[rj`*"qnA!e@\K2K( _gcc-$s G%/Vr8oݓ\vMUSlK(ql9BcV %M!n8@q7!c6@DœxpgZuB]M}Kx,d|.,\F9{3n A?.W1KHּ+:0:GmlJ~])Nx8w;SYDV" CH\1$Zw`UКqaӕO^#FEL/o55mWȝ28/m7 L ݼw~.6V oO^jxYVpi؍\zU+O8p =BJ@*$ uS~Cb(YB~Tg~YARx\4w\;HF)<A"QJ`F/Y7 Dxy'6SPr]N"x%fY8(`P(ed,ڰƦ:6^1$P=qY}+/YSiIb_r81$W*膿v,|\.c b=XꕿSA9]ѵ/b0٬n,]K|q=RWD}~(?Ŏ ̱=lgՄtj2d* .V1%h(@cQYXX/(HzoA9y:,sk9g/#iՈѻMtj뛶ZE+U,"=#ĭ=`=Y\}љ{g#,X_'rvTq[Yɭ(?HGݶ֓6"rhCC8K=km,Kakb.N,Ϧތ!_N^Qff귻.ִ}B34G1RJEtŢu#K-mgԘhG^6t`l u [1 qVjkQ"P5 Gm6&&)6?^|(SU~ajP?ۉ{hdVTu3u풲O+^!(^\ ZL!F@$J(wa)wp\6(ƜO{5/nR Vʃ[H,J4ʳp5=43QՍOb-p“A*f0:`6"CG6&b:jK*:.WY zF\=q۹6f ԣ9[HAz]A'݇quG+bT7PL0gozI"E/ lȊ,ufRc./ӎ 2>- >a@N TAf{ *{[]wS ֓:.c֌:+S"=ֿלf`d\QC zF i0Ƃ_aԲw"$c5;#GFb1waVb 0~ __Tc4=mh^"x1Mُ8*\z[=AYBK!wJ-]0(+2bX 98._&qZNbJe> U[7(!q3,f("qePQJ=1EFDhR;[BlPrdM>L[L, 8 ՘u'1&9 /:El#\1LFΘHI30GW5*"*T$J0m1<eco @*ՋP @bD ֌;C?ܑf-+c])y$/ccNuzzl_M M}12!";GVS:`r<#&F]x =_vfA 'x`ղ̒d)XlYl;}} Kq0E]dK$$GqɅ8'Gh>"fdilŢ.2I\aހ˭sFl3yts]=`/b+ A5>cjKC bTvz.q*|~+~Tq OU7gӤMs0|Wozryjt,-ond+f3k@ˑɋ'+^Hל{jhciBӨuޔl_r NǡRshqj⧋Vw痵|٥diCvM S>92-KP4e}D|f gUà%7;usIǞFY lD2t[) ]^A%Z=daRoDtV}PhÓ@Fe` 's3)`lЁ3G6b?dbВ-7gq's|DT:pYcwz2T{ [peAنs+u &˭:h7v{!2^#6bPګݐ|EOI ~Tw2sk?|wg-ӜX (I{vQÞ?,q~˫Co':r֥VLh^κ%oxT,mMe4<4'ZV8I[ZC+]0Gyyr&Wdp*T0VSfB;~Me~>H4:N.2+A7 n"V)Y, SȢbm ri Ր%K?L }M2L+/sŏET)9k^h=S=*g4y] a}؁;*hN{<b!3]iRu\OBldHnԦMI2x9LR#k%yޣt|w#i^׽Q<X DLl$x?\s->H$Aȋ1qJHJg+^~sS5,N> Q_ LLӳ+CK6wMj.V 1!*[7`l g}&Hlvyb7%hbH?*dGƷآH|.UHpȮ'pS=ryV7JG7>,,Qxb+!$Y@n#.JaIS $$̷rUx'@ ǁhX;jlʵ0Ϧiy=5KߝXTevenvP`u[?x*=t{ȥpXWs${wfge1;*-x!2V FS=CSK(m˝8m{M bhxH%ə R uփsXkKE-L0(Dbb-Gw`>ruSӠvz>#1:1bLbJ8C)A[Il,h~JhB^z_9(8v_F,tѰia#5z;@U;FBWjPΐ9q_k"1:K`Ęh,E$},T Lvk;31TХ(t={{dђdBu:F4Kq}ؕ#qk D΀2'ixF\僤+$U9eXc9ۅנePc78 _Ba&yٗ|b{ݵޱb4AjGR[;r%Z1+G){| -1/L0 93 2C>k_ub'LqϐhId-I?NR[7`qTm Ϥ(8soSE댽f?̈́W HiSB(U_α$+GԎо[6mx1N,0:^% Iyyy77M-jƱa_N ij|d ׺^}^E\BU /iH@qV~Ɲ@«➛%VJRDRj4f3key2z;q]?2ÐEo7e-hC* (I== zo;/4,[m ݏm횫Q,wnuE=SxuӖGP98"cs]֟~=aei&NuTN0Hޕm_h<]!eV?u *Ǔ`ldi y[8!=m~~]@հ{^UG5]F_] 5Ct'uK$*Sh)H-hdD BV.{NW%QNgL@)fKC' ^p1}NVf&W,kts#Z0$4`t? U5#N[tI Ojk5n&#bbs_AP$r88Bw_fN=23oF!N<&&b &giql tN [ < Gq<C#5ULy{r!1Bz.7GnZR0hX7/aOOo5Wy1֯|U&Y~pm8ܩ]Nƽ|߳{CDg{DQ*yhU_; y=ʆI"%k3_3ᷤ>.= A:Q`'uwxB3fHc|KB4`ƞNRޕLz>/П͒&0?|A9΂U#)/U ŤB4Ϧ}DκD-;*us _}D0ʔg0-h/M>0`7Ўiw9mp)_sOW{7~+H~@^R%gr/u,d>Ƒ HSJ<gd˭W3=mw}^㱻<+Rۄ G[JWy* i 7+s&CBysN>ۑc{ ,=e@XcYM{d\w~8F|僓0=ψ*,b10 3K~U$f C3pڳ48DEO J3Kg" xt٘O wD ư׹Kߢ;.Pz,e]33|#U@g[E`r=R-g\0z6BZTWp{s;Q$_!tB']ql %)*Y{GLh9&͚q_gxɾܾJTu8*;lf 4k =&:=q4d+NLʌ஭Z]t[Hn ytVp:"fZkj|jO>.J nk溺"{ 8 zDAbܧrWKL=Mz z1֌ۜZ,EX5_U7GUcx"VcODo*ҁ +Ӱ;e'6EMvUAVWA݆vWgJcKaao/%Q4Sx) Q瑢UK@daqP oq;+p&X[+p!xJ[,ōzF34r+^6x3KY{1b+<7^S<"9_֧3ſNVY ոrN4p*Q`3 8XC-Ma_QɿI}Ib '%+èKi Wl2W.]kc^ae@x RQiBhպ.? .C5K%HzW=?q}TewnLSEՓ]Gdx*y C'msIpߚq*ػkh2ùAɥQr+:(xyݵN>79Ih5ZdBO,deϬGƎ~bTGs_øݡ[N&F(e @*/܊@ S Uy>蕦U?[E ŵfNu) H2?%LKEH<4-xDO?¥"̥S\pOHbܽBPEE-4q,jS( Wv >$-PI@QyGҞq 0Ffp YI(röwj]mDf*FBf+t󻽖BQ![t8=u#buJ++'4@)l6Ez䙡V?0'P_)_vi \;uNFa1𝸥%-g{焊TqD#+@j]{/'`)eH6?߯Nv43gm.}D >Z" {r \ͣ)?r+|A= 'X9=.26*.yqed?:FLf"N/դU?lWɘ]W[`^-w<-̍%QRcnztwɥ'M l{M.aq؂l7ɣ&oU0#n Gs9,袠=Kd]^P:ub͗ 3|NV cmtYR7;OTc6Dy{u|Ewzlu&E H 9^^T{tЛuBinGB?::WjzU{:(tFv]O]l.q}l]pZoG1>qCđgA_@mifϵ %Kr/y4B$g:1,)^\0(|2,KӐeFdYy ^U?|wu߳pqB-mnwAoI0Z/wL[D+u odjs|/I<2kkIHtWfq.K>=\q5l1sG~Z?  fW7t,`KǗ-D5G2% :("vfƙEČc~vꗫ@9AsTK6OڡV\ $9(jxH_ֺ Ze϶K9+ea޸8Rbֱl*|"9[)oJo GH*% f m68P8 W Ώah0q< tI\_'ʉ+.eO+@vW ,VgE+oCMS:|eR5XH8o١ o0D'&$Ӱ=%O7m0*PbC/lh Ko~;n"3&̞V>.EAᯰv@bk@3u|HЌf=;;p~1df s)8(QvY/QA:}$c 3qWO[ÊšGq3OUu܌$F-4NbcwUwMPU?3 8[*mLVhykAjדC#*⬚i /u'Gd$WFa  P>P (X"k\HV&._]|ȟ:c4oe6'[x,QNݦ`(2ՙ$oR N%sF>QћNoV 6M5/kpyeU}&\S qj6kL,J}VQC& yKSJ 29\ql2[!wKo2hEiX3U ),ߑjVF߯ o+a>Ty;k7{2JʂWOX.y\ QXtf"⊠Z? PqaV3*)Ր8M*AQ̱SbKeئ:>@åc1{"[۔=9 w0:07X7?-+X ܸ<յFbA;يLM `WOQ@>? 2Q%湊l;_L[_f x~jvOAu^%} B$u`3n}9"A۝K揫̟\ʯp9==*JEC;_k60&;Hf Oi ePm6OC*sewѮrƍU6ki-aZ-uz1zH!RxBv*$I}2ROҞQC>;)bkf?4XkCjˁ̢7y?[U_;O]5X"r:c Ա$99a>nX{<&îfaqzO-/$|/cG(?v|]$a4b*/v_νa?jKG"U5(ۅ[#" x99\xuLJ_m[g/ݯrѓk>)"`IߓZFnOni~?3lSx㠞t=\b ܣW^T(`ܰ5k4V vܓ’[ZM֊B ->6WL̳_K#vj#2'?ScvQz/[L;Q<4S,|LJm mŰ;4Φ1yCeKyn~ 社n1.] PW1Ǝ{]49]9<%%kKKkM\Fq$ RlD{eހOD¯'x9Qk{915(1dcn137qwҵ_m-ΖEK78^À!cxŎ˜ثLE%h/paa<.^f >h9B.++s N yN& )BaVOVЬOVnh}xؑ%9JOs @ICůUd @1Hq6OEDmz=j.Cb zSrLNFКs4(8 l/Tʠ"R >:n?;q,Ji1Vo \i⋃m 9lAkF3c(Amrrpo 8baAc v 8vyu8`2pYEG Cb|ۺXP2lSJc9̠gt0t)>kdϥ>yll{dAi@oH%-#dM5޴' 9J 9ĶoqşuT>sr]$? G^. '(n˦,T>N l%ca<az?ϓ*l0pTZCm+OǙ% nL7Lg}D!ɎqQxfqrsgz~y B}s淪'l4ssjes|߯۬Z,ۙEw,)-ct/A%-`@tr{ٱ 2&AEN'Uői PN+v\/B]zjAf? `[؊xḩ֤hf9RChkfVw 驰5^<XL~'Pf{ŗ< 8=۪8p+. H,0sQPן?$#jd8*%!9{oP#0tCS-0Zq9a?,r@&9zDe~ s3ώ WX\KƔ8b X%޿W b/FY.ؠHؘ HԒcgQPo{8g9/lM6?}ev_s_?-!a [`%z\K4R'xȴY8{0SU mU1dN@gsٯ.~:xRVuõW;ĺ?6dx: !&9flPu@36ˉ-ƛ/}g7-ۂz3.6e^p=l\ܲ{*\}bK1;Y>l$gp,0jFc$kUgqE}zz/LyV7kTWQL&'45!Z*J! H{(hvng>PQ{,h%ǍU|i>rynŝbt ϟYv`;>UAAҽ=~PEohpFƞ(e@1Cu'U}~R!*PKƾֹuV4!TB?\S7Q3 =;,Q4x6taA;9\aU-.o 6ڟ"h]ARO(tHjB]M 1 n3ZґuEJxd -KjLݖ0|e#9rQ0Ƿca1q!=3: mLjVH"'}C*YZի2-:~ȇ`;{wԁBŐA0 lģQJdt&ORCkWPUygjΨxߴJIiPsY:&9$.a)WKBҮ砚- C9.z+ :C+[jN=e jpGq&C0u4.u\lm@i-FClNV7R ,zP]ꗙ=g$Eb{~:,ɨ@!vvYrHzTyt:yIT {x.¿āHt:28)*Ls")jhf瘈Up,vozY [ͦRAA5/DscЩ$.sG2#,-Ҹ]5rtEĞm!; ,0YK6Es>nTT!He:0=n["_I0a ۽jh/.Msv KWLbp}3w15yYd.n /mz3n{H7䅽EF9-M03.0 w-Li*$DQ[Gseݴ,߲z}T.}܄#O7I]f$ e܎ǎ7\w#I*@fnDZfCy)86`Yѡ?iAQ73]CTkCypK~Yt˕I]FHdE 'zYE*EQ p]XSi~"u3!ʼ{8Kwm"&-_/Hb/qWxiWc19󺄓< TT,qchVjܿ+zØQ4퍮; ـk0dit<]e]ཅ?Cp9~̺*g*yWXpystnD6:ə2ڤt͒ٞmP?a=K &O.tVwU.y]kf~s$Pz9>K-#OANx/xPыRUQ!VU}@ɤ܂Yi ,NL"0`!jq ylm&N\0"P6 TSA \Bvk]Y̍#B쯫w`LZfZP 'ʖP]"X38\h5vdk(W}9FS L9,|~)H~7n2ChMI*m zٻ 3t3dEe[5ce=H18ňNt=M.\D)v3!3s}b&.1ZA~ a|k(׬c\hL>nZ m8%*dV*аk#2SVcF\dX@Fe̎2 je,Q#D+HpP ԥ&@0q9QK4Vvf>KDMl,5oZpt?,Jtt&u "8}>etYF?J== ~l/=VBOwVwlZ5µ F*՝;37U 7%]z`f4қP8B >,KS%j;^. +&*oXruM/ۍ='sP h, M.֦hF#ĺ1ˆGECvۧ,_zQ8aΗG|!;mB |ݫ:os,w%؛򎄏q{3S9mY珆܂"J5t4:I=1.a14|:VQ;*UPk\ƭ5Baup~XN_Ξhܤ5?>Q|; tS9:hC Tkh`u>XH"-*4ag !ӷ,h݋w-#DR%n\JI!\qAXqCrn Nae=TOB9^C|KVtu v@Ԙ=f[1oڵbk_k÷aoӓS?1=mQ:FQ `;\nhA[s♾ͬ6aYz"H=ݯ{Qq$+'EzM8!WHyt8O 7?8g➗!%(-+DE%#: 9 }M,|~.r[ICîGA<cSHGu-8c%_.<2}H1jܳu?3 oEid_}=fTS)څ޻)tGo - opXAjvUEut4N="i }"Vu_h%VQgi1)嶼"Š#3#twŏmx+$\.fWڄ*i=oIʡ`Vv@fEp4!+m$ojt(/\+SKm yNJK Yu-e.q7nK&Tu6H4L7;{3-)-OE'1I_TcG-ʺ^.6f]A7vLA>=JeG^6u̟,mwH>!4Xm'8,x!O7T{Hd:y:fP9Zٴ=&Lʇ4Li]aÂNW~S!f1ISGLʁ9yDDɵv ͊E/?y*Tf.n&% "98t=ʵ2j( q]D^VJ %'RpїV,*<~w^b]v DDgV9S3; tئ""NkItubʕ 88>?𩳹b,d.,-!M '{ 2cHm[:+!ye&uHgp\`"\VK^TX&e9:W|YC \H G[yƏ*WQ^ZMPvYGBc< TcHytk4q_(113N'DkBLi *Ao)@F۶ȷ̼ct9>=Kom&,_y.sqԳ%m pm+5,m#8oJW|aͱ~uBx04 W<α! ~=e&O5;M_߭//E BPsWkw[\-mO6U o@-[Ɗ1J8%6jh`mŋspt%x@zQGxʵ&kxjQ\5-gmZMJ|u^OIKo+\ZQi첏v~jt<>}lBP 'noz{h{vZ%FKZCJO8\?MiDn#,Gç"s9R͜Ue9p…o1,57XFAR5sC"KmK-Yug V]\ \(N 6NS@ Lz RCƝ+ /(|?n{Vm~tt{HQ+o?ͅpAM|x^*\רƾgА|y_)6X;h P>[8 7>*uK4Pdj L{(z'X\ >^Zc=.՜'P*=qK+Qcf(T4) ;m>{a2JC/s~NOVTPN%+.C { v,heOr[`<-!7piW.MH!*0=J(css(L*jnRyt- O*KZ*QK%vؘ;h[Ij(j; I8T|/y̚9fZfTwHjH1#Q0p0ؽbdGg& " U =/Nu'p=. )@MϥJZG0AG(YE1!}m_Y̎؜%:p[1RuG"H3Ƽ~_qJ/U<J~5qR 1J?V3.Yi|B%jJ8O[1) \&5[Y;4A*:/t%& m|pUT`y y[Aϭ:Xֆc_{M=w1B f\_"T(mHUHGPo.w;̧:M/Rn@ ]d/UYEtgX8)XGv %eb#ba=̐@U5CшVS~׋#IM8rL^<ڿ}H< 6[k P,8FN[pMv'Zqo}uuJWٲ~7 Öa)PTZH1=BUʕyb\(bosc4 NeLB3y13*CpRdt g?ܿu\*#ىHs+Oosv.t M /}hmAr@'|4R֤Bg~Z?û\ŗ¡f[7dM`xx;\l}9֯~9PF`u%YTU"ց;kj;_K%7~qtW&J9"ݪbԆ]05E@g_9ebJ^C+!^ʭN:'^kC=b0D'"/3sT˴̓}eS]pCyQ'9$P.NNp5{-@g >@xcNt|Mv?ǯQx<{227cJ k2Xأֿl n; SVn83 $4{y&/(x$ D=)H_7}RhǼFUowDzXl)O|m.ħ 3f',dZwI=LzI{%J~] D볣UEB[ФIʉJ=.eVY4RqY`iHG&TwϜLf9AJ('迻ܧ> #BLWǸluSK+qۗV6ixVDGsՈ9nL6͟N<mjhrP|V})ItG`F=QBP܉be 7$|yj'wd, ѿN'z?OCNnWq!P5|z f8[^wq-) gM#^ #5QCzݟ4"gGxƤes3=kE։w*;2o$ P;:LTvSmVǫ΁jȨ[M@!;Ú6Bݩ"]w +v%NoQy]wx~ |"s.JgaSa⫱nTVa*BKXpљ|$2A9J7BYЎͲT'C4-Pk[fʹ4@~fUýLsrɌF O^JiHxWE;ic͙vy8x-BhDǑ/%Ns5BTzN볛ZV3ˊfڭEĻAtIRf߭0D&r^@u0"sE4ݑ>Ц4u*Ș64kgAU*U{4!L{]8YžM=chJ^0dٽ0RhvoG4hROBs%Nxe[RpR;KY212t>\ȅ|odt[qt;{ &7$?'ܳu{$L&LOM 3a}66|/+`amC0 oLLSP{j.xm88WO4`P5&]en s5)_ĞN8ݠI(i^B|c 5I8_IL AK6i\*@6H.6/:Iz׵GL0N3poq]['TJơꒉZ<>Wa'~Vk~'MvZv^q+U4teSe9MT̒jS8}92YUq 8zK>Anj`6NR}C"$LӃ4bC ҥkt+62{|V{N*-*v%h)?NUf%A1vE -{ J'. Ѱ0P\Js%AQѿ7K;%s!\N-vH`xq42Hׄ ѱ0:N扣펢L4i+qoI Ekі0 N+~U r'- H福c޽8!s@ɛYPwXZ#G33:3_>0HT˺ ip(zomoirĞPlAb37|zzV80o;+`v>>1Tr^uHrt.6vP wkDǗe)V,`c3ZtT;hpf t5ETwoORendUW6 gŞ8s?%DB'ُN9X2 %bHNMhC1@O[NkDk%/4Y#3hR~#4{šyES+p(Ԃ_P>Ȫru-?~vaXkо1D;N*0̼jU $WUA>)Foł}ѰKhy8^ɖi"V:zlafNP&y2G8Ki0xLX rR _"ܼZw(s1<዆)Pt"U ;UU:Amӣ%Gd,%9dr+7h録ẻx ^v#wJEI${#Hm}Wۅ*bˁljb8bqzbqQB<˒^JBJxӽI](j-.2eDj3UX1lڒ/<ѡ-׊ @AUzdLWJRK( ~ɫh\Tfo\-RYSyEhK܂x,(.H=?6Ek"=z{oLXn.~ '?RQ  SL=Tc[%n C9FPA!Ov<|[Rk:( OA9g8ZEi ޣ:8…/q~F(uKt{5BoM16SpH#F~\HpIxk֩+pkX(bѿNijCrf$Rm$J0&kvzȴX_jKGBM]ρ!LC4T.[l)VٔohkR5sֻ{bDX Ga`/w+BYXp"e:;nK)#7Icac𥴤ԑq26kci )e2ϏsuR#όqP7*`q={$ԏVYvN`q(;BM}#wjpȓk1_ލnKhV6T j\/rE-THUjT;ѭX]X*=/ .MXi"bœx@˄ʗc#0-ZAEZzIV>=!͠ {XMu*p> ]ٳK~\d9iTA=j?"MYQ‰ XqH>ͧV-{+ni 9OV.#P|DCᓐT5cy)q:1DYVMdhdG>1X["/YF=saԽU,7F8j4nKSؔSƽoѪw GAZ$[54Ca )ʟG/*=+0ir) GPح Vp0+4kJE9#}7:Z%2K]0]0> H}2jd /CM$ {vڻ0ob[H0,S:Ė LraK} C;,JaP) 5dzkzDm)&I;GVn wmJ9 e/_CjXS'dy%xl<{_pCɃDE4W=0oH*^ Go5S1C5^U&6^$u!VpO 'Sf0Ak R.P_?ڲ#%3"i;A<3B{_( ѯjzhr#S)琓NʂEQ>1#H_T!y}VA`)6cwE7 ivҨ8T=wkov͉- ^FG݂[ JnJݜ$Q(d`LM+'$>"厶&6`PȏG&G#g$U[ %sMOѥba㉍. /*-ȦBX}OP:MMz͘<\E50F4ݬesGgrS3˟)kar?ǷTBa[ ^Y{O rOM#=B5,IZXp4YxCod6˙1Iu -S53\b4 2Mq`I|2 gc8dhz4kFaҔ2`=%Oc±^SϫJkKӅvyLSA:y)^zNh"H'oɭ2tURPPHnDў?.L4[/tH%vWx3z?* c~$GfQqtq|[`sFrs+9r㼢|ȇX`ًɍ2Xfo|ʽ} _5,_)\)"بJ15jIFcBBwb槃,"WA0lOmbzY؇QJ\&C_u8a+&56^ς<'AFDY&.zy NE-5[q7r`H)nX;)^̊q .Vxi5㰵ep^4p|0f>Y\2&gk`"}-LޜF <ॉ7ZlZL2*i2#D1K:Ap\fl4ayy)Ǹ~XbCIvW3癝A)m.h{DZ>~P(M3Q7nݜԳCqb{pnY孰[DʠzMԂ"2oʭ=~XLTe{o͵h(lDDA贀+X=JѺ>I2My {2B8jbdsQփSv׺XtWa4GI22"EAt.V}Cev;(0ȤGgAи;1yٺblPH U!0aguy7D"x'z0kDѱak!Lwmݶ !޿|9D-#& !n-qt8TF:ʛN{ljeCƨC^)lrx k@^;^?Yeޝ:'?!بu$ T3 wt0̔PLZ$_-TN1 w幡n>[cD&g j eX_=V.dh[GsJ[!} 3$-V ՘A4gBCV @5nB Օ=kX3(%-lĘz K25? P8/ ?pݺus~/izt"}>bTl L-  2.IJt,_.1Y{ ~2CDX0쏔!q1էn LpdۈS |"d''y߅/:~t`3Ev|d~yz%EӑeP҄K:c"8{Xluɇ`&33TPivXs0 v6ۭΣӃPHЈ/~Ny4C!qVG4&\yp1M[ɟEv} B[!,Qc^ 9u_Bר#GQOg㻽BGɞ#m𕎟ԫ@ej6kk޻0$e`-_2\3S ϳj<5]&RĿM$;$Tgԥ Bq1$T8k: O}TWis5λE' 7}SѳU+E8MxB=ܻr]C6ő~m5/F9zobg0s:3@MǙRU?U@K2kxV>!Sag* c} sRQ={ x^>Q~'6rUM4ȨART Y8.BGkdSD(?t : D9fF"v"9$9h:즹z&EI"70F'Bok|ckp3z1?$4h u$ު]n:HA7sV;@c-*Չ rƄtˀu}35[En~!s3q`T3uڵ__N@B̮ Tl S_wJ`@ Dv{R#69$`fAs()N_2gW*{ǩCҩӒEhX.f;F~e͘X^*VGDvq85ִ8~4^XuهKf7T>(>ť¤60cYPĤ !RnyMn@P_I&c{`NT{7La{z}qT%3р $nkIe]BYGDtV0@O][5A\[1 5 8(!%$cw$ 5%l$G%CȆkA&M8ILBc##=aF wͭ ܏ :5 hm=>:X`7;axQ&'GOΈWxp{7>99y/ +WLb_>8"X/gNm!eogkwjWV9LK7ج1Hz72:_qz B%"|/6Bq 0aNם 7յlD+.hE3ث]9nwsA&sA^(A`]hl#L!2ˬq#Kqen3tJr-C=XeAZlou:~r[ Z=i9dCZYEEOp[?H7 q5UL{Kǁ1 E+YF 9yf|%gE %rVGFG:E*P#~^ Cx^Fi38/6fإlN}vީ]*L')H`k%\: Emy$(f'r&CO#}+zeBp*_JN}`T/@Q7)0iC36}WϤ87nLvH(.oLu2BYuڐ2HQtE"rn*.J#\V*tL10Fx;4 #b+B\B#SHlLYxM(}|AIt+ :uORX6C<}e|Li#?4Y3)*4r ĐR#Jk0j]V+%O/N0JˑgQ'/ /vIa_CH&oLr8i*#ukwM8!b#I*rWj8Z$*Ɛ7:UF0iKlMظYꂑZp驳Q֋ߋGLZdimd4?ܦ7DQU{_\zHhɺ>\<mj4!y~0A*^y෦Mif \?Qfh0$:x=oIB[#3I Tq;o0ڇyH=&n{f(T8Z gY9ldCn!˞% k/ʲ-w pmG IY۞Zs܍ lp4U/6 #XzkXDbݷUXD# Yrx5RSҮ)&ԓf&L>jR^kWY[jD)ݞzm /a/:z0wVD &VAp1HDз;K6ۊZŔkq\0mUËUKX[_z\Wߗg%DLvm*._ F$e; *k-@5q@ҙežwg0eH9➱"܍Qi8̛ӻ Y_G\ZYr; ]_nF$jJuQνsqBA8f5A˛\DQKm̒r "3i&{EKq |2ɭyi]r2$P׎Dq^hZ♦y>1t8Kwv-Q74<dFx\U)-mHܷ;ײja2S/ź%peK+s=MPw\ )XyfZ[7Y;GcNsNLE_`S^UIb ?lXc5j7Xy(we&.  ~% IEHאtmn0ri 3|#|Z1ȥo`hQƟABXmv6$aP*j ƀY]e [,07ԁC^^TsI`6]cgpŕ ǽ-iMHFѲ} 0H'atrl'J8X2\ح6ҊGY1ŏ|۹ KJanjɭ百!1fR D7.&MY:ǰwKOu5_\#4ˍ;4|礶KbIRMPg'!CѦLKk=E}+0)ae|s01Tۄp\vb }3!ĩ0#LRrG +H 2=w4ڲĉͭm+PCN;&bBְŚ"F\d9vsd~\O$TVuZn J%Iϐ͚>yR[!+3 ;=lܲEnXm"h>"A6)4#r1`5yOP'1A:~ovCof= W +P%b s wrU1ͨ"x'z070s Aާ S$ķe윎 [<4J lagXf0 C/mAs#e<& oH85zk*xQ2@ 2 I7Ep&G~--X0[@Ϫ]=kb3gLס'H@9XVV ww2kØғ<4$)r~݈_KT=n]Xޢ6jq􈸹@6\P 9"? |OkĪ@ie!T X }EȀxĽވʕ+GihkusLڡ~:R86gtk +Ɩ6«@ HO B د:K hF&>hWXY4fIfȱ^}N~}sՃ0PwwrGA {![ԩiElj@e>d{H;a9~Lm| “/9Nz>,$2gudBP+3k"t;CI~Lmښ{"DNNⵘKCD/~y):2N[V W ;_dk:._VPgl-_0/B٪a ENN6M_q7 DP+W []E]C#Kp?gM#c%U-VO_gtjXV3d/I}=\[LQ^%l;:9Q rqv_RF6cDn=G`ƎF9'@I"?2X!A]…sX>{rm)9M=M柶 ~Jv1,wPW{3-g eZ %}$GՇ%lH~3ËPt [E$j ZI4mҳ} (HzVB9KlZ"%{ǡ|!HvA?n3Fg$)ug)B 疑U9v)- 7*nrxUGߙ!+꫘~ ?"hM 5-}OēI p{Pg⧓@hDJY@UOfq37_I 3)'uHZ8U#ۜ.3"vZ@Lm~\@$V.@G|XœoJj Y*+肢qkZ_mcj5&c_2iY&aR7oS{ɩ\xqHlyM'Jlkpӹd叛7QW!U4"af~ vD؃٨6l/O}Yʬ z —X~ʉ3U(Ԡ8I6~-'g:zq0I#.}VΘg){WM@ ;;" `:󀂐 a.E*Ы,WX g*M%'>_}+3R/xJ:sT}5~UA&ý+FTQg7d< G'Q JBncCF+r 7Pt͜ĒE<)dK@Q5[] =Mسޜ?MCOa.'+ 9oGf8{h-"-Xe_@h.bɽ2JRyQxIezW (Xzoj:WA Բ90w&3k0`.ݐqTKXٞ~ҺTĿ@[ €E+1 m㨧Fs`jEJjziiUJ6#n?G ՗Z1{F͍'h,.3y[B$qaêB~ ۻ!i3jyxȸDg#+̅ĭX]/gVX}_TBjHz#^%QMP]߆XjSwOWZL`u~Մ?є:˪\4ЙDٻU,H_R[ͶP2],RpyNL,EAR6'HW .\ 3"sgۤ@t6}(`= I"BA򰆐J"~7\aoLкN-D&gP/]"${]i wY+{QǤf7OI-)yn&lO>A+ا\H;וG0xb=AU?bD;7ݚ@E L# \^*U"^f wvTr^&*`, =gjJ`53ڕոe ޭkNt7mbawvd_txT{>iP02"$ ߰Um>K19Pz!B Q,=Io9Fe+ "I83n91WcRj/e[)=VjG{jS ٯvPR$<3`Ԛ9*BjCj@:-rR Od){ ]`MC7VkJyT177a}*!9E5a9ZG>ܩNb%gCY}W |B k;}M7:oրEѷZ/`7~M4+\"t.z*ZQ=EhFB8N62畀~4u*.DŽHM@{X tCEbi<ܤ@{d|Kߛ{]oWHЋQ%Z`FO8'&]ERYcUkx[CSq%3 YA(onS|ģmfՐi^CF59'F?_e=1L1YQ 'zߨ' 0ՔsVT0vSVesw}U%OwgDJL%5ӰALnR$Vb?;PH&5͐mn-HʞK-m+#H6OJTf@KOt3Moghwn ^^~=Y9gTMல3GSWtumkdpx;t" /-K `/wdilij0^ q䓩ܗcĸf&̵}P8~OOk%=;HLo/GHR&NO00ck߷ZPko6LǰE@?X gEX@f,J2|ZpXw;7ć|tXgڟ˲ @Lf}]r},As$B>u %A Q۪/;y3:._/[SF*N=b=Lf#Yn-bF~\xoXxҩĂBv #`NsP \گYP9Vbn1J2L3 _Rɠ.~DO7?& k-r }|t(<2X+AjRgf'co ĭ .L9ϵ Ӣ gd p.%L(`ώ'G,K$-ewW4:a>n) $~sx'U䟂C aYs*wJ@36퇉,z v?L'T\MzTbFCY>kPl',Hrw7H`IH{%w(\({ܽ3v58-rwP"ޕ^ 2^Z 1jy4zlѷҙG<[&: #dr|y!|]OQ?ɏr_* N&}^(YOrn4",mqv8'nZُGqudmJ!4lFt'[Z5 ͔:2"v`Y]9-Q Tq!?DI\8)y$m6A"֩Sjqã v0,cW=b6`G[0>l&>E6CkNŨ޷YY)o^!ӨicVcdCkZVR+5\>-j`0>8F: >MvV}+G̐1u@64]iF<9Srd+!͇ЌR-uP+  hO9ZkL^d=ީW*dco&/&z^7_fDf2,)(ӄN 0$fquJ  TkA/54u3BAX40> w)bfVc7hk'T夻'ȪZ[VV_f!DD4G,+P2NiW@~L켑E%Uyet&gh7_pg"&(] [rC ˝Mth6c:߉^f5o e\H fuE}ɟrY])УwAMnjT{b#fKb߭bݨ8bDz0ܦ8<=,?1q]fHbH3 +&!h(kܟ8#g u7#.Fu|̄Sf54g{7SZWibZW-q3- HF3+Z1'L dG[S]]+oT.;' x_|LGcK4&Xxt6rX8 sve`bǂ r]yE؟REclv{:3m/P"g@y3~rJNU:r(ʫ+*3n [8́ 8T- <%e2ƭ 'ikpˡ^ 8ˤC"L@^q/ D#"qo )_5UÅҵΜYTJ嶿?L&kNP9-"C̍ك='.ybZxoyCRq] 嬦F,;f(_,4Q[/Yݩjdqvg-1ѫ ODء?i;=lVΚkdt2ѬݰߙS걌3f I4:V* GHX18|,{_\VM5>tyEOܗHS yNkv8N:A+gJǜ:ȋJ-X1Hm.Y¹O DRi'p#)UN<*ƫp! >׮wXJ #yxOqR ' {<_[m9ʲ]Bf|oA¶OWe'i(k֦4}2n>s%Wφ-[tl-f fR|Nk5tVkIP-wGKOwM%D_zX:i& ,8P)cV*&j)hC JIm (ĚR-MNI0n}۵tua×n5Pc6O4l8VIr5tCx.KX5b8ff{ȿTV7Б:"ShECXҪ"$0]u?s0'I^ZAV NG]4T^iOW5@sڶek?d4˱cV}!kMcQM=Tr/1tYd9[g@q=\f7ߙH%r0O…u{yp~vqt|Y!8z!tW3pz(G{Q GvEj-֘ƮX,8Fڟ_ޔ.?X9'6UXFF.yg|WLb&{-hybٌzƺ8@j n;Z0pP(!$;?-P0CnN[FG]D Z=*O1?9ei4Hsmhǥ1N?{b|&տ,{!Y0OvH}$O^euɾC Llɧ){g*ė.6P2rOc_lt]c,$I#^RDmVdu :l1܌ <^ ؎ܰHKxzDfLGG⺛&oP.$ϓYKVu,TGnz@fM~ƋW L܆'lªdfLsDZofˑ .m'7j MM!B+ĕ_0HK3=|4uGрܯuѠ7B_iͶX.֟ՙu3C%o!&eY&{Y$]LbԃE0!Z5.Q@\k?YH nЧpF?,;GK>qm#ウw sa@A,K"ᜧ DI 2_Hbȿ-ӕ 6|MgO?5o#`sbIHho>1ܜ.L[PC%&"ԽVvv?Omv5K?ړċt5 Pn&É!G=fs܂ RڸFF:A[0b8lSWNw;{[0ʦ]Ր9nhB| %qv3tD_2~DO2}q\L=*עKroW}C)- Ss*ד1vd{u2ҖM?|a%pbt4qǴ,j*a4*l=@:D sb˨%]N;,uYHB2`|駽\Ιo" ,a98eCNԫe *Ԏ%aa6 A|q *~y.^a}w̨ 'Tug{oaXJ|TyQC8jm{:I`Ćݎu'c˶7XJXK+dz&{O>=gx)p).(=Й~~hCZD+nrg-mC^P'U|Nԅt[J!A0>'J n6Qximz+w!3ڜ1^t9 J P'uv7_5}yhqC;k ݨO[aU֪UJ~ es)Uoj*LitKVI'rj^Y?fv8ޔC&}ZgBМ@nn< vLU5=QJn\qN'j_= 2KqFyݲZ[&rTynQnj 9 2'eA +jnC6MVasS'1u\@2ߴB|@6UkmiX~oo燕(pAP&6/.XnW8Fv?fDH4G* qA#IKPA;[ėDEw0jf*za[jc]I: ^p'eUkZ ?0$[!{JoQTd64B.d t u Z2%I"zT==Ium_',J T;%ܩd 7hc$㯆Juy9dM~;l(lOEr¢fЭ>Øu2Bna\#?c-Yn[O5Rف@MqE h.UrӃ~IZ~cǞ?4(g!dmvK !XKF@?*QgW#Tc;7wg^ 5)y `0p2 {Zm~uc 2x 9$;6Uzes }>:=|i|C(@9FCp'BBI d(đÀOJji6]~%8NįBDC3\#Ahc D N?< V6*|M+WU#8S,TkibҠGDK@`G.lUFAѰ3Xw⡀z,ehc~$ ӂYjޖex>w8Xʋ%ԯm|qBMxY@Cs-^Gq%BR?Cځu\(bj4uD 7,Ƽk%S7͘ `2aktwF*`&LIݗedn?*Fo+IAt i[R&W1CCofLr0?<jA+_Ք1<g".-Lz5( qz`)N}D_S<хQC(NJXp@f+>4;АƘJq ֏j`\ &0z@TP;2G /1צ~0?Qbm:׻ś8ό-s8|Ƙ))N]FAE1]1۾T'XEm6y8{MP>ӛggxW/n`彴&I%jjHSoVg" ԇ@T>шtf;gXΥ b6mS J'1^o&&BjbWU SW^+b_|QĨKG' r"x(J{3g桏B< V=<\m#O-cFpk72B>i[zmp-%W. ֩b?!XWv٦<ʄ\("' $"UJDZ}d-ZHU iͲ)- i b]fj5qԋ1t043I %_4^ %Y} \fh(8FA\EяsQh39Ysz)õ~%Ku~vĬ5h( X[(j A;kc\B d$O6Q\ qs .nA}el9"<Ħ"8byvf#ĨG|]ht4n;ܤ`lLW\ZBNf3Zn|)7EKNu=9}WY /@Hڦ,x]}7w>X-9-i:P獤rm)bq()O~7[^at6^H0{ EK/AY?.B89cϐ_JXeQ'Y|8 $f-PrrKÒ/>J=r6Fua-5{_f!qx R:dDz_cJjRǸ1ƥK[ >\DXjRJ[ KAu:u={њx:59£3+Fj D'aX9kK!N{XV^o[kt*^굉H*ʕ=бi:$w= zb$v]uGu9CޢBG۬ K["јWH^rHK:kXUbtr*sI;݈f;]v+>8*~o:0@n~܎x{#m 9A$fY4D~SXID!L娑'x0<~'oʍZurN  J%UWܹY !'@T(}:2&JK;GБ~ǑޭLHIt/A`(.hʾLI\sT&¤dUk&pLmM@c [ECeh,滗A F,dCWgf>gU , jmN>(kvjAM0:ն>{1g|o-潻(b-a fd wT!a=i.2 }L9M6dc"٢LQ^5:'jyRAs>n".->s4{Ɛfe~͢DUפӨl$P`^Z?L38!}%ⱚ0sWZ o `e"~ dMkLG18amH?O(x|;,Z|&U ܕ)LҞ .Kq?Y |b4bzKPC‰L^E9SI]{}v.JWݿ]Ög2h q̘F"Yfh:tv*߽abU)m>Ms&5?T XޒFy[ l:Wt3%Ꮠ ɢ=005̮p;k!p3(ob^1\8#0;5ǒBi^ەk;r(,BN9{PYQ?/qz^k8PPz)h22#J^/`[F%}DJ>)BbtDf7ǾD*4­X+3qu\?JSrq՝d> ׻fg>FyG 3 Ih ^^wخBk]2#jet֏UQ[U]icdH6$ 4/WUb%ڃ188]7x;cbɵv|w8nd?ҕI5@II mjv䷹K=܌ ιy{Z_'hK =6JC,W5rxx`lj=)BP =jSw 5UO†&uw~1ߥU̦r(C)RVE&h!]YR.UX&d!scC4@LWȘmm-`yKVꪠƻP+GK_,+{mh?C3bHG;J "R^TH i-vm[:I-1?Sl%rT?Hkv֠͏t'9M=8[$n$@g:j̜#ռw Qn٠տ"s%o5JxTl*cREP73Y|YaZ1w6UI"Xh-.(84a1SB`~`B*iGq= Z, 9CΓ%W+JMux=䯥A+eaM> w\~mpf%\cGٖ,TwW5[INGf5Fso_j;V;M޿,u⣨v *bJhq,D0~eȂjWR;0zB 4w}y.i2G/&b0ZbuvB}a< K5*ևb( 9i&&WHmfK<Iv{⿆UnWJUдHD_Ɲ2qQ0v\8btXrͲIdɌ&xsj$r-\#ČA zS͉ x_zh6mP1>xIWv Oix/^7Pt$ q;*K* d|eyXudAƫe:LtbK\-BGUW-[ń$bq FQ>ܴ220R_f=}pK 顜] @ExsNLr%)x)S3>υ+.&o@;>2Y<Ey=AsPdD;X&-QH7d,)x] aW(Z[2lDžU#)D'[td7>>ucµF]wgg6~wxq]F$ sňWwoY?ykVI=wͧq)7F&~4D:v&瓫]Bs L5|O1su+o` eXիibB^% AޫDwI3ԭRHv&pu@-!v$>)acm0HDQ[{w1R"p1V[oD?Juf߽L "Xb_=0Rn`YbrJu 6Rِ10}g/:o9Lr6BDt]K.(}Dn!kt t:C떑}K"l7oHBODJE- <2U\Oef|؀v> fj Ok ى57N9:97@ը5cQ9҃w@#bG%4Rt (ְN1sO^ js mt+Tܼ: mz5k׋{ !W$p{X꺒/c>AR'=H= ۀ>~wʍ+}9 [;i$#oAb۠@kw =2{#Ji&QkĄ3NeO>5x鄮Jxޛ ~K0Y9 q .͢2 Fh}YL%.'o@110f 霶?Ý#Nw[eU؊z"g{UX3e[ŖbU,1*|Ա::w)4bʿau؇<} pd mH6aAW<#LA7RqݝE.I* %3.P vMVQM( }#%@BiͅW5l:zCv -kCJ爀Ms6 e5^ݑQ? ̥E5^a[HȭveW|,25\D { Z?/3N.(*0630bwx|M{rV!{{-3Z@@ʽ# DL+曶g(G޻I3GL-v˽#NXC4@= A:ޥsޕ=9!Ֆ3!g!9|u%)/LMfI%@:$ǍE M"JG'N/5v,$-p!UI#1y߻=}  ~ d)ND \h'PX_3'.[U5 y3_) Yֿ2vn y+nk)9C$ ^btP%je\<(Uo`d>$؝bG/Լf $$3봲%ev!7vMQ puc6Pz?s*&By9RJ5ٶ> "&yiSba3ܡ틆sH"7 L? bo7eg Zu Ոڨ!}{xpHqӇ* t)f 0IQhNHuBLۜP|w[(օС@FW6Jlπo@cY쨳r#pg2Y"Wa)$K+Ť^ef 8?.[ϸ\3$ /e[1֝[m8lsaoQ@0wL)obr[+&~R)yaEPc-emr\VldW~0 :\-PfRAfҪ/FfCXtm{ljHc)DB;| SBU%_O…U0$:y5@lАÏ>vb43.RD~ N_GlAP-|Kh;sBFv7EUA&D#mpz5S8(&%T,_(pp*>ۏBťq_#Z~+L3ٞp+GlS},JR R(O0InTgw*=]hI}%/藽T]oqջ. JҏDd8 >aŕ^Ȁt2}YF%S0^DJ%EJ`a)-4(SJ*c3DaWkQd ls=  }T$Om*W}Gs{E,ҡ ԇQ# -,|uJ4e_>jx|ŨB&j݃LnNS8x-S(/-auALTCAl:ݴ)feG'(G#2jj^4_)Ae]g؆%f1KD(Q`&z8SW#8ݸS fZB@@B#}(]$k]> }FZ( .ۨ&T#,މة(snrΚJ4?VV}6f~^2MQ8Fլu|[ ։KVC(rlW%o^ {jUapZ]rQuypN|1dDaEB4 ۍc(hpz;ܞSx+mh5NwKj(ԮIz"ó?pէ Rl)~AЍR;H!vZ,s]Hj;1`v=w^ó ͣ=R53/zdӿH+80ā׊)(2}QE|YԼY1&f S8%Ž"6[ h)Kzja:^ lÊ{UO尝zΈ9 L$ʗX0LGvX03 qJJ}Mʢu1)D䰆o9 [cϣ dC{.G)pU">e K2>u/۽ӯrgO&TtVηE kl7ZUt[g@ u .Bנ2nRf9zeW Eӧ8h\_ ]O .W7yճߒ4ƃWM 8vXptIhE2Jpf}'9^t|L{ZFHv|Ch vQ&ZrqAǜgmUZV@>Lrs! x4ڡ| זmQucl g5?r;Eஐ?oT-[Dv-XO ( tȯ7VVvcH&3^}571QcO2.5уP!:)1yI VT0unI?]Z3(Tƭ=ecy|d]=D1Q ÀcK^XwzcZ$Z-BK.fߖ[_,B\Юƴy[o8SO+ic ҃^[(a!2BqAm6Uތ˶Zo?X$}l bL3U)E ?^amЎS*6)I\;4C1 ^z?<$RSVm;nL:3 I.$7j"=[MPC>B)^, FҺij)5ا$m{*Pt{SF'D݋\l0&UUv"qbm,m4JEB-ߦ3z`vaMLQK!PSwXLN |^c^Vq-2ThᙪhxCYk86Vd]_pMǀO^A1gDXHz6%(EZc :oeR GTOq& Is"/h'0x_5QuUKIVVCڱGp\sv7'M`ҷHgМ/w-YĘo3܄MSR`#nH*Zl]t u fsr; Ouϒ8uI'$FdjH_]@X\ NL/i &@L Uz$u^mjޥ8{61φ6+p0Aɿ|\'#QB " 8WonsjDkrJ>'uci$UC\ɀjAsϭƃPj?/X#2`o:;OY~Mmb/w9q_iL U7)CnoQ x,S/6(p qbs%t]zBe\sReiJu=90][LӎoG]tir/SG#Z[>ka.LT:! I7W0l^Hӌ9~I{JT7 L<\.QD#ͳ A%jL{70fJ^?*ε̰@$)9kkWwꑃ8&zƈ~ߞhېEezTcPxI@䚾%#[|7zZ'T:a8FJxHŽ(W8~tV_]y\s&Ng-)KQmULZdm+DBOʯlP!RP6u2;hNmdtqHuSTYۏ\&)~~g) uxwžSIѲoC8):do#&Vʒި `NwV)ݎ>}L͔zv qgbl.|ZEm&k!g s; L٥f P"p;7T9 ky5|-:D4w9$;UvD)41E?ҀV0ʙQsw!!j dip[$~b,QiڵsϥE;ХcK5#X%A֞)V^Hp3,K82Tԉhn!n at_Y~]'S /8Hj$X<[~~s7h.L&POwb)\LgWS%lUngVGg.[!ïHUբ^Jd^@ϵ' qIնYָ>kÈ 8͝(`ͺ6Za;ȡ~!k|D]ѤNFytZAQ=?عAliz`[=;7^{#l"NWP=wOiȶ63K -CP v\EN|D%2 n(хw"|Ue%V})% P\<-w{j{v[eH:":ݺM l+ MT\aerx_KEE-MWGn^V,}.V5`kK$YzHC1:)&nɝ+(ۥl!d)baOs%mzR\U=VѴm*::츫y%ozcI'${D װGw%}-q"82dO2Xօ_Ȑ8ժd1 &:鉴jY+Z@gK{AtEnN|sJ`k6[9RTxBg)|_Lk#@53?>( QMD.Cɏ-IOXƕ%-Pp~v K{/'C9`NT 11(93v=~@C 5 fGϟ0pƄlno@2V 76=ϤB\U_κ*gKBK:O߯Wxc)%$r 8(Eg@)'>c;Zm9Wk 턤("[>0 .{ldދm"f🤵YJή6RS1LKtD62j"* 8do`vVC*2TSx1c-<[NԯaWAR!achM)*[CeG`^[LmMT1OJx^됏&ҋRpNןi͎5$iI]f|ΤRB\<ʸW%@ðzA'b=)m " \ f7OE/,\|6BftM(cfaP^NpYC4†eBXN+pRKaI؂ ,# ^ا!vL7{/n.q^M^ܠNM}kp1SMJVb,n@C4#{c8SnjͳguK('#Ck*8@Y=%ڠo'[9P^")d((H9H@R!wgUZQi &՜bV6lݠI!b愎7f(H:5Q$كeW2 կo$X/儘A |0Q(I۴~:+Yr#P" ]t+pt^Z93^9g9Gr# F9w _N) ւ0%\׏OmKܠ"*D/$Fvy 2zRG KB6DO]9<;/7iiO c`[lHνm2IIuDrG4@4."[qN;<\"(& j![O(\Tqvdrφ,3?:>g?MD3=O)M!~$8=[Y;|}UqXU8\}ԟ:ܶ6q4٩3 '_Q1|$XUk=. t 3Ū3!\8U_{%qJC A<X1 bĸ2}{†7=vp+c7-&3OQU*XʮUͩy(xH?XhkƈY6")E!FQJ@@ $6fݓD 1([}9@Rszu1F7>o-Kݘ[)l4TBǶ5}|xoHN~13GH tVk曞V}Q%4g4AϸqfQwđ2l؆[o]4c /릯+zD%ZTzmcB3;ꧣkJpphXT;6ra+_ }c[85c,I"H=GHG) 6̫6ǿW.Nc1,0>JK~ݗw' b|6g+^-Ը0/N-sғU fR%<48ԎA :e 09_ 1þ"+y䮵TubwH-jB@qkt(\3}h!s`0Q T.<\Րe@IRE8dM (tlxi8:O5YADM>aWԊNu!(/hn Y=ܚj'vq$:AږuxUV/MON \+{ꅪ.VhD^@¥-NfY)}Ku8bUE쒢L+gqX{ ٚ*-ӥ ;=WN/8k1B/̀)dqc;0a9z hb1c`}#ګx?|R^(W`?d"JZ7+♅*BT8*f@j=$?|<㚋iYԒOivO^1'J Own"IP#7lBl{P1?T]|I0ZM郫6R!g9V:FJЃniY0/qg= n?J*Ebp_,퐟Ը6؍eїO\͋Y';{r=|WAv Qi/jB{i=Z2h!EU~xL>Uh^^1Slhrҏ$47Xj{vA/xy&5l.fDFJyHAgkUB_oA?9|-1TU # 9#D0'](o)07%@K5yʂFOUkL'*\C&"FkY*3">'6FGn.]B@Mr )vb= 94eZҍ0ǻLG<&+#J+sQ=¬yYoJtAD [RSs~OpeckhEȱYsfp\[ȟ]zv`f>u6úX>lݾՍ CW`qv'A#g}"w sM9ŸL֪"TPFiج{UJmT53(Eр$3P2~y`MXTumPa*ěhΖѪcQvX}h[R/2>dU47\=MٕvOH5hh씴j̛og]꣛sG OX'qHO ]nm#?i@$(:V]W-TAggB<̫&F4>XZx\S}57z#p;aAl_ʸm?6Qs""#J D#l;LfxZZ$"b. DC>ΠIяy|.'oc˿%y4pbCZCvKkOrqy,Z~'j%G! s*OQDըP[2379xeӴOn"Al Lnlk]Sn 70&I[N[7Nn=O#DN㻶LC&O vf,wX)e H@Ak$Ծ_{FU$JZtY`ȘڳBLc,|a:ٛlu '8Έ4Y3&5dmD`!ah2G 9o2n=D+YdTCDN5׶ZՄŸd9ѭN;Wytt>?U3'Sb]ˌ|rߨ66{(UخsffLxFoЧ>Ap{xdQ'aA0Yt!={Y^j {JTyK< V0`~d)w ~lM8JdH2 G !1uUv~ ="~d)lRq$+0B ~ƒTLrϳ'(H#`6 ??f'nW@Sbk^*g@zY.kwfsld#XG(]Ɨ%VB0~b3m8$9/b;BuA(ܙc~r)o۷_\JQLP V&tv`Z}Isߍ˿SHU˝A2 BJ+$Ip{֞󇉪K~'/x Š`TSnAxk;&9D̽˗oBX!..fA2swtLe|w:-.NCPJ]~^1n !܁,Ŧ~)b,w} '7#$"f@O滌}7!,|AcNP= QcR6zճpR&E ]^;YREz V\A%Nʋ lZ+s Z!$DZPiL)5_03;ZYhr:kOF)QE8:F~8LxT7U`gWWt#$[#|y58/~N$ᡨ* SlR$QA}=e xPgVv:EƪŐK EPĜ?شK%}tԠQ:S͎h+чeAvzqAh2Ӎ.PkXr`X G@DSy@ڧICO cW8;zV:Qt߰?)9pͨ}~ %X$fK\bl}©mR-Lh!w\mSp<£ʹjS~Iu妓۳w7#)΃D)}V&,Pp6OVwDrdMYKX*)(ݎkAgªz=Lpu}]m,QR#G@Qb$O 6-VetqO^FSzJ+e/$?py٣Bm[7Ǘgɚ4f6x0^ Eor ##N0S^[0wBO4TrS%އFeM6@"xk3pl)pV( s~iH%SJ^osW ~+ٕl52#|ȯR Q͝o2C 0CpR=_ME\u?HKM,@qo~;Qω_CLN33 u0 y}(As˒I&uJĢ{ǂRW*%LW8vDѬn]oF My+t F^7%MVKw.p0NفrIvsp$T,[9ܼF`fΎwO2r9@u;UߴƠ[̲BC6=56B-woQ$nݪsCX;{ AT($ɍFlOSwr Z+v#v erˋA~"S06r.lXXl/;S/#jߐw q" !0# x'Ԇ>";.*iѬ^MfG!mKZY|j Ȏ]ed6AAp&Sf1pA5mF`3pmt!݆s EVۦڀ \_=d/ӯ՞bh b>`:&sۍ?%aLvnCCdolTɔ ]6;]MJTNہ+ }moIн$;QoEM\D=[۴t2颤W{ǃ'غ)UՅ]XlV2 H+8DEl]^um=V](g=WG7j]Ih̴/!xڙ"f$M)TIb27ڻVgj -ʷ/I0Y(rm|GxøH9Z{~Z# LA4~>1(4|$Ke|;A*#[欼)Q>8kߠD a^C2z_h2%$9h g y| IgB[5<(>њaN$Ә:=="/³ז.ZYyKx駉E>%arQ1bH&`ȶw/~@aʨ4Ոw#|Oc6u[$EfNvDl1u 5]%X K$S>s,\e?/hˬs]zx틵1Ijd?p\;x!fJM|F7.iszS8WoPDa\c>`6v-"|j;Qb٘"M ΘD`>+ɫ+E(g.2! dkvg'pk ^ a ^4I˓k-Oh]5 mmDҤǍP+@i%fUm=uJvM #C3*cvYܯÅeeC}4:GZ?CesM-z^Gfɞ 8Rs*Cv5@ a|6wV2ֵS2rbo\+i:i+~6k*u!Xcb<;ek˓߃`1T9ۙ -t2)AR̖TUFn )&<%~E}bQ7=ÿ>NENEn%]:d(Qtd^[JVQV <ob1jFX Gt"ia zhĭƢ>ÁQ$fe٥FUMګ%?PO+m4rHzdv,&5 _Z: :h7:fkx}?~&Z;+? k̑*V9yM,}5ǘrNY$ߦtHi]$ȡɴ+c Y дaٛO\2g}yK:uCA>r0H2N:Qb{sMZ*ԑ<n1c4=aP:g~ch /8+@.ko= ¯![}N@Yc 3Pc"M7K?DbFJϠ]7𾋍ema42n\LvdB˭~UjbKlD"h A*0FG#̻%_O^`@p)3oX$by[6cܰEPеLNDyV<ԥ# y|ps |Fp핤X[blfHe /v>?B:Z٭Nm )N{9ּO%ңjZO i4]on L3 8ֳCn,R-u5X*sM5x A7y&7aiRzѪ+co cH嶡G`Q]p7ŗ) *t"T:q$'$fbk=:<^殂ށ'6mٿ^ֲh8h$G1WW6hdopSD[9UgF:^.LRܹbuꁡhb3!}C#\. %ΰ Щ_sVC7̲[F֛b{֚6JRx~aƸ?L3u.O<7TT[^)!#_HP+J$' F3$ KJ8ߗ+?VF@Տ2ZAuqI ^h:5c>-! VfHBÖ]* [1 Wk{JsG)n)3(,..-;q8S|[ٝzMrtN S' 6Rv# # =nA|]>HK<T/p 68#; 7ҏ ]Z^񛋐Џ5ɿ21: 4a?U|l]%o}_MF@LYAIp] j v jRDF9#6粘gMy5Pxn9QVT L0E'@#`jS[C4ʐP ΢ 29zڑ+wpJVhb!9}C[8]Yﵗ $UItCk_f,[35#U a!sK&{⻁ v7B?*\tS{8Q˔2luIhzK k]:&O巩k Xk`4< wnCYټ؂ O}cF{#pk_z0'ފtCj)~?r>@MGrFڢ}03Bn7#(S5b~Ҧ6L~\m<6Mp++|PZ*-vO=6ӣ.u\6r&Ra*vrW baު/.Z%΂r&_2`Zs_\A< c293a`8o /ٹX D}tWbGp޼h3$=Fi{/cw1uK֪Oc\aHW _ ?7T.t]{ʒЩ0-Q)@ D&77Vm_u.dرkI)tbP> ${t߰^u -H S5I Ac7C,l* Th"FR2t\頻 B;j֒mt&qs |~丵z9~ t"m?5=A䪭$SeRjt\-=ո^;"ځF{Dbl?xS_dL6Kqy2Xss])Df|r>yPSL5Sw<'Gu MIs眎wfjآuSo `5qr_Ӡsq$58_Jݷ8LnvPJ`s̪*& ̡IǕYmPBU XX]'Ұ%G^(c@%þ%&*dk2WJ;/"H㸒mRв ZfQ' ⤣ELC =-W;h<$^R٪# < ٛn0{(] vz r;֦P'ЧN .Tnky.y1L%Ud:/x@ 2A[;I+hwg-6$:Ô)i]c2S- GIhfCn|0cb5)}wD)>R={i߁b^5.HIj,=lTh-)盲s-8}=E#gϒ!CQ7 o<ŧE! >Yuwƕq%Y\on@ݼspX;fD|.fi ę.w p1JC rM;t~-fs5 ` ĉ錼$j'] 05h1.HO>gM Ԙ4}]bd!;*pչ %6s͗Mv . ތrq io]&td*&HЗpQ&{4(R)7*濹:fj!v \{8Pwfj}ݩ3aX|$YtTSq=6mBb𴽟5 \,TJ,iEC?h]Im6[;ON2A:㐎֛4d?67{`z؜F2>n77 '%4zꂣl*$gܯ؀ ']I\|׮y8uXn^@Ʀ?&._x~&%ao?i z;Ϧٶ3-@ӊ  $cBC\% Lr~篸q L$qo{i-g M5ub9dh6A;8}jpw28.* X.lCoX,Cjs5AGEBybFצŐN_PLv$ř UZsؤ$DNj) +NRx?F~tҾ]p]@  Qvs&٬^#6t`ۦQ'ߨ .!hs O^O찊%%$oo\z˂g7e~ t9wNTH^P](+P,)e Z_"3PzBRYWZ¤ֱ兌*YG866A$L1X #1%|J`z ;.ްao[{ }va)p;64~i~Ep(qPDnK=c[tXz$e ɥ+UϜn7kTߵB 9D@GfŒ_& o Dqu|_ ZgY3ܜ6t=o+DBc9ZG% ص3aIkR矲\ti6 JGo(9.`&dv,/=Np ZID 3ԫ3w8[  ~Њq#r$(b{H>P$hV'K8sk:Y34bOrizRӐH;Vþ|${MȻYR7N4CleECCc X7~[I0h|6֔Ա 4)7D/ Ɍ4D5~S-[ُ-$; . `RV\M&54on[36a;D>3@}B1c'ϢzPs+"n\ޣ~I(NiRXp~7Pl-^BL!:֤4]SȠ*` (Έr\(l#fmn"iA/ܾ_^"/vV1˘~HG Ww8ZA%)۝bm4 wJmH>5^T'%&VЇ^tj\{}{F0yn'yK*yHhy*,"BO[e(iQ^2,=lxGC wH"zd7XlOwYD59|Km.&ϹvXgOaem_P_ tuY 3[N7=)t5KbmokC pP.~LS5*e2lGkD`&0 G.k)\VaaJpmK쪽Oi0{K a烧TN?k4ڌ1p Z@=J\B.^byP!+tB}r^)+m}[߁ţ)_R+ ŕv(0T?)J>Bʭʳ1|$h5c Ž5;m_/)GX]kV2Ag+ vm~cu4 t,C e3*pN=OaJ=S:7<\nC>! $+  t]u6[BT?k k$ O蔯$)8V"WLTQ?Nj)x](S7P:ZYr ^ L pm}$n7YOMrp`D$QV_g)|Sf2T -k'u7ͲJMG_d=K6 C:h*#(' ̪1FAkc$J@h#ȯC[8![VVeIWH\' ΚjoTfY'ï*ihЌYI„(W{Kb03g0r_n;ZN4bez&ݿ~Z\r'B `4FԮdո3:pW -r)֯ɽHHӆӃ_ k#^OL%bIM w =,?Ny wo]p:V&g$P%xtXj7O VvEy?rJ{VrQ-sƞψ`m)ft-)3Ny\;3(.FzZGu*'A3aRlYwkL=1ֱ$9wjf*?oΦʫblգ_}:>c#nz[k2|FG8#n&1{K9G!/+:l:a>=]O-"UZwBU~Q]ֶۊ$|XW<>_Cpz!{ϗ3T `JK9Vk=o'eťJ\L%xog;.#,N"LI5i-wl.$ ¾Q7[τJȂ)©Qe䁂0|Ã~Bpu0Zy~d[UԌl@1ȒRjP0 X~u`f:܄! ,W#25i\bO%y{pyQfd7ʡeBQZ_kl%aHLw՞1s|4tK1+@ϷEVcSe'C^yn %cYu9Q}K3R^2C,uO'Ӛg{P]p7'i;c-z| Zۣ\B`vFWVGK -i%!o*XiKx>QZJ 8 e'? #Liajf#EnnL.sYH ,LcOmOa']z^o=?Ca2N\,7y-:cz~3!:t˦m 9Ld#oϛ۳p$ ]oİ-HUa^[f lzȰC쓪\3"ͺU+hԃEMt> {-LQ/c$b; c KFG6 kS nhq&nGwW/L:lUM xY7=oEI#~H f06ߑV e-y׺g?ޞm3WhV:pJ{ T51/xY㽬&7-3-8'-p֍֐6ilND tٶ w0[o?;uȆ w!=S5GW{٥+.NrRa1?i> *{`H+EKqj#q6 ~Œ ,*zh7YF:H``= f8Q]ߎhq0~عtS)ȧ9jhPy!:x'Z(SwW7d gzqQA7Z;;j60z.myW O݆@rs3A:|.EN5ih5'TLW[~$~B!^)װ͖yHK%!L8f=WN slA! =k+PJ 0ICJRPOeG-<( Xv^?iލNkp!i0[|_wJglmrIBј{_3}E Aпo"N9gS&]$8rJHI Ԥeͣqb6Z'(2WiyX~9_Bu' 2\_n832Am)"ԑc#Cv(WDTH76\YU_j:=&2oO]@/:c.̼hVPTVQg{V߾sM;#4a%3,WLж=Õ7'˛)vN+ej;GbmY`%@Lv>_u0 GZ0Ѧ^Y譑Æ/a2,8PV YDzezP*+&Yˉl>o+'f FhH+]+D;ӝ|L[Z9@ t&mܱ ]E֎Nsv)KN*1˒߭袮IE6ͧhUb <6dj)5i1ZU>ccBVM9!upz{k{<۔##W1I6w]Y6@dY-Y`.! s~8E bo#SLy#;Gޫ<lհᷗu8'ɷS^a$(+ U| *^4n [y(* JVh~Z _WdS_(E~r.>uwlHVy,l˾z֎$=8s12&l[kQ7$Nuuf`LM ~ 넽x'6[Sۇ 6/V c{ˢVˈCC3^D` ,!wnN_cS{~2x[+n8.1Ox!25w(frYHW=|kdY1F`Ɩ-nX<@mד\/NWl)SvNOm AJ1!aɠr<"c!bR4?MԶ\sfLƳ59, .μA+*[oD|zz2 ǿO0WԙpDŪ LOZT_FA"{RhkCDdapb#*4Zn&ccROº)2M2)<RV"_y٬!ڋ=K} o U.lyװJ!ѣ3 #dcV]n| V0xj]tD͡;?U$au]؊xT.fJ::r$]_  *fpb0O~Oj꾍%alp/{pcG`ɧLpƳCᴢ>܁XZ\;\k0xdfl * S&Re Ŝ)oltQQ2Ku2珅4GYP9wAEY9)Xg>IJ (| R`993Z:k]rPj{UO]vDgVn%Uɳ{=@pCeAo {Qt"Ӭ8"7ZQ2^Rh@F͙|AWNe>ې_ (.ʎ||Q[l;E?W W.)䣦Odl`bCtP%=he]Sx +` YX77HSU5y0Mr&G3mgCD!4\  tB+O^"Ϊץ6?^i6љRq$dK. vsx_W"59uaŀ,Dny{Տ'v<ɣ+mۻ&:.SiIy`3 J)f@NU4EK88TK),,ro5F G?Ϥ&IΰiQrSz,Nɋu0Ai!=D0A1=N=LHQO0Ҩ0h=M/YUyt Z$%qI@JXf_sA,oOElx#"Kk3`%V2[Ƃ%՘RZg9/3;GG \o{ Dlt,kScE!ժ6/jhS@:?luVtt+ rAvz +IP(.H7s5fG(>K> \u=TRဃRJL/N$" GKHԪ<tۚ_C%¦)B9Jl4v .=7f&4R~D[mMrY˱npIj ML@)a'zMNGj|v5 @!%>&&uji^v:,W!7+[lh-БlbRFT߂]E<ǬؐxJVSY.|昭ng;cbnD5JHYH%ܯx^iG =/4.jFqߚ{RHbR=2K cNqcĦb{9T*le Q͜}}x@=*BцfNg͵4= ȪeF964Oǎ2>-I,rdgߘ0%O5mqtO5H*d/}K-Wqo-_+?vG_moiŶƄ05]qs5gl9$n1SRjjda/x{PNW?A 2Bi6XVxlԄx,em=2$Q%;3sb_cxvL3I/54]ȀKy3R\Cxv=\W fw?1}2x_^CuP4ZB,jjn mղyp%Wjo )I~kڋPITI_nWHz(,a'*7b! <vTȟl`S\ybIXAK ,T?^V[17G/N_O[;=5K&$rԫx>{pj0I)TQ4TzmAȇZx.;;~kw,f0ޜg |!.3<T;$[PNT.%\8p|]4J NѣAm aw~߬$͂'쒬Ɔ?%WCծP8QOX^?(ЅZ0pGKZ^ϡa*fhQew)(18i }m)="}Mg^ sv#TRQ6p]K3_X>nXbJD` KӮKk/|p7v՛ OH)X!_gY/zM4F*¢jzt)w6JdL&ub@KL,~\&+K27 urt7E wn=U`,LZ9FƆ'b0D>l#6p_xD5%88Tu=)\W]ơpG0Xfi {$7XAȇAl 幁c~ Fɷ(= FtFlg՛A-iXh!%bs,xgmSRDuo/V,=|4߫e| `.+:vu;Yȹr& > ƾ"%Y4++ռXIeͣQqn9/ kU7ЁJuG%YH]`hx+G"▒݂bYߗȻo #q8"xIg, ]H؅tW:]Lz6Kw7' n"}R1֩S5 5EOEs̕0%>^/B z(N cYr9k/l~e㒎;ؠmy=DX 歔ێgc[9IwF rrZe0n$qɅz]2kj!iFF 6=YB{ܮ:AǠ t~CW K ;NPs=m'-Jlߋy==_Ha!v`.H`WR9S#Hs1~s4CЇMwZ_ bQ I'\ ;(6er^Y;W ^>j,G+ RBxvxJcM+adlpl穳{gW]m{OG#U 15a} `̋(HQb/g`r+k5FXd_kN/':JK5%.OJk8/c:a/<O`+輌z.s T9KTk֟;U-X/:yDh]˄ƌT\mn* OY:~5]6_:ˢCr]I?&ZTXdĐ~.uiRr:G 뻵қ=8\҈'llP[cZZ3XC=B hOnۏ+ 5ܣ ww&G}fv\,u?Le'0Eo(Jtl]#|Q݅B~E P%籲kHjvhvs;;lMd"(p3nuє] s̕0v̜ 2lUHUK[ jw~0`<g>{TU'->Տt0PFݒy˦IO/-%ԑdp5X&V7 R ٚ0F+8B_- /!AD\e@:}Ig?x \ U}Dh&gb :GTO]+z>Ȯ iѧ7^V͌J3|jY[AɃw;3Nʩ:AfX1O^Zxxu=ߕIdhNݳߍVShe/;vÝ]p? ^oRjuH4Zq+Ϸŕ_yf-!.[VOX :CE 3\.RޙWԚNz޺=m Xu< CmzxO9O_:/`!hwn CJK QߺIy+-P)Һ%(WaJɬT)b!10w(=M5dyj1C$ KUNf{2/Z>.ot)[k<>| |n@HY6ވ`HP6+~7HthƟ*ĮS'G~%~*k3ju.ik{k](W|$1NHϲI7ȅؘ Wdρ'dz1-,CieyyQhjNadUO5>d#,ӿs9zx\hSD9FdۅdSDDО>*~ ۟BnèlJpaQeA46Pl :ElP yB0c$@'X8[u8`*r㚬[# os4\G 4\#Sr8'^&p 1*巃_P,gWQwY/yԝ \^X(hC7S3y&[pt[rG;I~xζB@+K&35qf?5U%"VuEdG'|Zo |.ygqq/%<\ @>BGZQ$:o kmy&$ fv4mF!yz%: L1c}{Mh9zQF]Q6WI1Vm'o=aihNZΰ@2eo=}`eKTzITF'-'x"vZۂ>Wˬ2%#{ ?b)ӏIX_IJIf:`hҴg'ŏ&E4 GF)Iӕ K(z2M 4Q;xW)Ţu-r#ftZPz9ܷjQkEsQ4?yW oEf=DdaOƢla+Oˆ+IUG|ĜXLR8|1'?sz9z]Y#=_hڥҊ>3x>@uPM>Y)Ў"TO_'Lfo\)'^`P5|!_v=F%Jq +zdՈ P)z i&87fiک$d;Ə֯p'Ja\ s{?I|UH;tj˶ 㳢HAP;|i4;`iXqE>fT9UU4.'§z&(c>{IIDSp$zir$Կ[I^8'-UȝhZ}[W1̐=4-sGѥQ|cM ;/ޗz[[K *4 qйDݮBqM5MZ'WMMlY}cs(-ufH9O#Xj|2&nlrb!}FL+6rϼ u=d4gWi)'vt z-K41%4$wh-]>I|Bsl@Y0%R`ye!zGs[C18C Vyo>5;q?v4>my"8f#B|^Ɛa"\L`:CmǼ|gWf;8K]~)`@DsHRMh*YP a0lǣۇadzGCѯxqAKzSԑ1mr`fyT=ݼL{duqlvrϋ[~Rj nM%~|ɹlALtx0Zdz3MFhhbFF$ƁoO]?+`S!9ۄ/-lZ#=pGr⍂ΘD5 tFwXóAdG6Qt R.Wn+J@77KBQ {h'H^4nZXB WP^nM' ,$)q>ڑkA%^pWŮ7_ρȝJm鑃PKZqW_-xkmv"'MvݜYJy|S%`䟜=J&t0pNBZ8.AjEcw8SKx8~Žr=i}y-1tA}a8p ~m5lY)MDI4Ul\@(4PםkTƜ^*4K-] /gleMڑ:DX; FBڞkcY1]A>̩|%Dtώ)y_*]J91v{jv䷭Zk#<2;eN}峰8uׁ0GqIkq%'5| ~to.MbSpߟ U`Eg&r&OJG@#qMef.ܳW $-8 jF!'h`[,, %3g)-<cw98NrC%۾f bS&jHs-X6 wvIیl*VUMb{<8+zkph=)w*/w+B*1 w ɉm.%> 6Il 2)px#ޘx8C !=,g ڨ_UeT9 1 y|͖NƄy)M5G% Y'G7A(zu+a1p|TRmૃ$~f%LY4͉L"lі sm)Zh6ן]"bRh2ORVX8xCߨu"ĽXD)s2Zg ) vA6d,䶖H¸Z }G+,A0=&g9&R 7t+s^urfuLTF}bB~-|[|?y%m Ch##:Ni0ȯgT"\ \AĦD) Oٻu_R+ZkÛ}?X,|2<+ ¦DqZ3xb0֊xNRN1nz*0?@^)+DWрțj\-2a0hz@8šޛfKsK>=5,48&埔EѸlLA]eUn}tTۓXvE}cVY H;7jNM4y_7_b_0oM*C'=upDR^Q6;s`^<3Ter$<â9o8x-mkd4>S_6UKn v4"7 ؔ\=Exybd' 4)L;;CJx#tqzܭXJGmלF땒@̀/U>JwVR%wIi;iql}2Ir ^I}*2ғ 8Ξ ^TOɧ|o'zJ;cwz{ K?)c<[FLUM&d*:…lm\NX7_y=kz"+Ю9|`X≠zƯ7e/̮ԇA-`C]A5"sx.GL*}T>rk%*3La̘,kMtrA9hNMc"ZJ$/HXng |3Q~W`ӣ]HRҽbdpt .yyb}@KewE4dA"z~&l)N ɋ;6r*|:2v$E@;S9kͭoX`aaoJn~EH&MfCH 2 MےK@Ñ:w-LU573mw.$|{XRGLj>x ZJȉ]TBEAdӘv>j0(f1 _$/E5}}ts`A(i*`w? ֍;u!nlo FY~5Fb$e+:,@""#/nw#LUPf,"EĻﲶ׏^oq wؽX2iJa #w$}Y.{d =T>FBPUyOz0QSi;G=52vxv>Gu M%-B4ꥏ-C2G#2=|j3 z9 .`II(}be-:n$|{`RjhM%ǹB#y`[Ә$ʁi þtz|C/f&,Qw >eƶ2nry-\Zd{I!c\ڕ)T2%.5@NZTP:sDk5GBݠ=|1| jvgK \<8Ed5Z{tB[ĦBH#yUjXW> Hm}j'H@Qŵէ㠋Kq`S@ɏ!L?!S O32~ V[N(akPas?Ye&wSDTCX@WT3*}[gPi kiN{|Zqi5T,ۉ6' ^F'e iDG59#Hjk֜.r'"F=_e8%4i=/FTapйUzDI㪙Oeӑ;ë#?qD9WqBy!z_TyR c,u.8yq6f2*n+, :G<“2qu?_dSy&a~mN|Y$P/bgGvk!ᘡiw`';Q9>8HfBܘ!Ná@Kbʀo-"jw4m AӉqFV QayÐ,ˆ&s_I";V*~8MAfzH/Ow! HEaI:-fJWFP"!w;0xIctdNI5z-rTcc2>.Քi;O'Z3rfI J ?wь`DwID`6TZݗWe$=>lr:&?^f8FyLkHK؞Ƅb:SFmbMl.-nWxtaqd E%':lMH8l)~N.g UBj?A>83dz};P[-{ tqSԤ}i5)ؔ,[,_: )G<<|Ϻ]#/&UR >d@!O.tF }5s4ʼn;;@G7F1x7uNw&zKOW4קMUm˰h3ʱJ?"r`|F^ʲU)rNH/#UQf%='t %/V nn!x Ë S?~ϋj7hcO?/#l?z18şƐPحnQOlmZevƗH-5#]~WOQ4A-؊$I MC  4d(ϵ'Z[8V"7ezgY;)tL#z+H, aЫ]0a&pTIZe}I&F>&-ApAʬx1$'Feֈ6V*PRZpXWg}Dd}M[i "1C g0;gfD:\?3Lg0ͨN5g (I&۹dvc+E2ź tp3Eԓfp|'˫i{!Qyd!KNf5@J5K3 >LQGT-Tz@xz|H=GPk[1ɈFo"B yzfxG#"O8sJ 琏;''RQ<qM7..~wNrWinYt5TK14tS wPq$axGeߩM476ɄDȘP;~)+h #`zic'(2j3SE`!uߤk` JE(]bh$Dž:?Ηl쨽 -ooFyVҜyǐ4NP|bWyM_#sl' RE9u56 *o-OTf5dd~e |c LJ2VֽpWr*3Gkw|mv#h!ϥ|I$Aq&P KO4vӅnLm⯄Xz'0)A=ofUWg!12gCvB&<풾\OV-CD.q^ woikțV_2R o'OVk&74%X?;ÏAKZ iO;ԯ}o,r4dEh4Y@G]CwI o/ Qh6T1G,#BL^Ѿ4p|:lкX!ҕ)cvL;pTĥ9_P5J \^yܤBK= Z+RzRtB- vYiڇ9~Xk/_QPE M+^[Wb&޺n943Yo!kʰ0X6ڞ=.>;ާc\9~/y6zԒ7\| qUPյ BƽX[G^&  F2p): c؟fs NxgirK[VO(FeYyBbK '5u/g_ewA|fvrᦶɸc_;'wq[ec@_ՌzB1S7b6JHESBihjS?4:aޕ5}f˵ؠQcYBcF4vE٧] EhYNxmCkM_:Wa#ʰ^C]~p?3w1F^7bW`1#l{sn"1M>%aJu \abkJN.xw6a;j'*m+q] l5?mDv _K|ɳDTEɶU>.\0U,Αqmpl۩lO:rD008w]1m#):sx8wFQWi sT y;ɨp5nGWE|2"$͐JBd5_[qK"g/ƺNǦټ8c]y༶p+Lu 0^2_*j5D?6wȎG̓cs>C:*v이WY2h: u,"U驅)Mt2cCq )B LMF<#ޯ>n})ֽ@{(ֵN}˃zxM6ٺ}Uӡ=gD<|^WP~I 7y'QHg +dI B{*HCґM'/uTPc׿a$w 17lmʑƗ)+h9>_@iQCX1,Ʃgt׿777mvc'%u33^wmӧ>.̲_WYO8Puei }'y0Qg(Hv9!Fn~[BZ5\YB |I2~G(kH@q*OY٫*9=ouQz9/Ĉh ʻ'~Z?5#đC3ͤgi-UT2>ȋ.$li9xW]A~`$>{z8xA95}!5ʑu9va}/`ɩVB^7J`&G `&In((k֚\utX~S܃]S@~'4g+-BIʥ*oP.1>W oƚk<.Nym:h9Gkr lE&dwSzsvQk = 5oP~Y+;DyG!xgC%j8oe/ԇt4hMlݩ]}fN~؋H%!`v!p\]]$ =IJ6N UP_wpW SӲ>ĚEl/M5! aPQs&YF5Ci= c|g|}F!kBu7KtFz/A9I^>گ`pJu7|ed- $c-ڼ*@jлڻ+>"ܝ@kIX'Smc0=%Q4~Qu` O|o"N^N6V;i u_3*Ðf$i&(RSM?B,87[|o=*9Geh#Yy8/{a#ꈃem4)\HTԻbp&V]GJkRQ' o( "f Ԣ|pob=p >@"\3T6Pqٷh[F9(P74'sYj 4uN" J89 Ɩ@tSٰ>k&DڙMo*MҪC͇Rxx*3'! R䡐X$X8ϋf-Y;ŚB2_cH w k ~=1 V-L8l( XQ^@*Z_uDY]1JL݄I|$:9},ܥ܋U$F`}t\$Bh<vT9gN 9[ ȦB*ߧK AV.iN x-h%,CITخvMܲ;i ؜O/ta}~)T,݄k"&:]H̹h̗ȳםK ʎ(z{vt`w (ZJ^IƿMװ5&.d^_vCS vQ-H !l6؜9Of.[ݜ꒰$Ѯz20ܣ龏q`u<}!8I0= sm.5vu]Fbo/q^t(#y4ހ !Ԏ7P֋m'嗀TxhôC뇁_<)($gީ-j]i d+퐉,W]vʶw '1liȷa/9"&p_CNTF`уuXE!,iY#wr=*t W?}oWvJmoPUP"70oJKd oCuL|ũ7uT, i -qNO"cke4JQe gaYt1p 2}ʋWkbROO0cs7bB=-;N{:'/.ׇ N"4Lˢ%-x8Gt]Czc4zSAަgy)H6~ӟ86հY܇9nFwdGK APɊo/K-R1% #Npyu4[0`$ ;wϐlD`an=eT::0(Kf}.տkD A)h8U@r^'l3LAki2xR N@ч]+QTnm"qh*nOvL,=7x0'#)CgLZGo 'rF($$hatf>,|eܦOVoub~~Q#.%GJ~d ۛТ 4~>*iwҴ*#p\l#J%q\jY<=l;ᚺY˔{0jzپ3ZZV -$Pwz\Yt4Pg(QcXkfg4mh:no>z4YWȥ0 Y|gQlW_Q129ry<;\'E'r6_gJy+k|P(3k?0jU ^*E]"l.L H}!ޢ_1"*uy 7}ao´3 w=`W&5uҗK]H J@zSfRpc(Anh݃~X)mya\JT 1]wH<|_PmˀOǨ_/J'Ż?\˻X0ɮB]XY?3Gl?*a,-ɘ*7\$U`$WorC&_f Q|\@P+Yf%Aw ̘0YsD|?BNCM'k5T#ئG%t T+o]GsQ4WU,qf񶊣V; 1pi mp"@wzsQcߌ>8,wWTy\K(Wa o)X*\\3J͑^ \8D7d4v  aw#Zl;]i^ZΔG J:N"B/oHf an(eѴX Tð?i]&3L]@8n ^b 9r,`3x^iLcVEZ=^!5@{G_0y '?H6T0U-42m0\-8Gy1 (1 {Kg0r5s;>U'uѾ͋}Bc9ͩΫ$)DZ04G.EHFؗbSԘ @9|[q0uĂ[f&.ex&I ؃L݇ǐ;o7/\w2nG*"CI(t (W @p}"LǭViX;اA*Hjx#`܌dߪ^kTQ%ۛ{Ew0@:!e:Z!<})ОW3q ٣L{{_X@:Slph rA+J hSH(կ N3μk΋ճMi3+s07ÃI .7рP<' =a_GsӆtWu Hf3OeF4^9~Ӆzs;7GcG@AVҙrPt0-z]Hpv3Vze_fAxpa[s W ҧY郢`pVn߫Rװ4@8;QpYw@cpΪM/&~"&#kDS!vHJW6|!ѠÝ$E'6Uny+6|NB!Ibsl5MX`_(>L$a\BdL~UyHVQkf;YÑtklT1% RNOת;SqUڮgigӮ0U2)P Kmj0ER4Dm;)xzzr C.\{~(ZYHB[N 0݋RdEQ%-T%r=ab"O|inj72SKV\}۲iutCf^g=Bo;/ }ԁjl*iYNt[z~ӔHX9|eö 5tBuh)Wonr-u RyA~$%K\Vz)Pp㪃4lCf#PF i9 zql>)?lqD>ǁId4? exx&,gg!]]<)ŷw 9ͺ"gGR('쑎G%[+B܁e6J GdW7Ǝ`67shP)WGBb-t㻪y}zSک=RldBV+N'M@F&4Wp*m>FUQsFDʚ+ 啵`= kb17gXr$w])}Z) {֤#jD]RǢ]@(~*dzM;JqqX7D=jGH{O#b@fF9H`%2:Lܸ ( ^4*j~3;7t| :K"/^rwӨz&G\q-[bb¼jZ MeHI L>|t$ペVm]',OS+0fxa0dQR60 ~05v?z|HE5 [{ے82sH.iwQH̔'b0h\wONө:=Kub3.k[aDp5^˻X+kJOl7C~u,c9X9al ܷ݃g,} slQf9(3>kGTsWpR %bL6u_# _ BW{o1 tk..SinlÖQ/*J0X%@G#_wboR߶}QǷmdK?z0)H-řOa1c,Vs,֘Y.,=Jx/\ruA]N38]d7^bY‹1 ^~Zh/1q7RӠ.f]/Mds߽巬9 2u&*ޡor9zX4t kԂLwK.? QCy@?oUI\C:ȳFj;x1k? 674>X.jҵةLwP|w$u4>z k۞{9w$3\'hZnv6`̴9z0u"?ъ6VUVVǺ4{ oB כH`xx1뺧;loMu5%B`qEI KX>9 @{[8DIPPrf^SՏcKnB-M)v4n5+upD:cAViA#miIL_+N y50 NcpH؁L%:16l 8r3&l=ȶZ{+k j4$,rto,sĊ ; ;\˟G6t=?yWQ8if{Yvlz8?$#Cc$uygetzf5*7 Eu 4//g>KGx))ׄBPfYHVj%\J{99S"J^$j>rVIUhmr#B_<_PwF óE/wk 8y{aG̋?`N0є>$ڮg8="d *=T7突 (h&i=$R kǩ FfVM(_O-SY7(2w!A1L_jY̙{Y[">5;خB /iZIĤl-pf-$q@ *2c)Qyշ>RϦdC[׌!#~3E|^ V80":2V| U63DZfjͺPɍď&yϋ-ىSF2 .d6XA@Wy}~WCO{|(!~ʅ]&tw6%~PVV_T ƨkpe㽻bᳩڽ1)4ӍjY89-\u@hʫ0*=lG?݁6$4_oط4 CzhF@ix799xmRۥ %il[Ɖ+0cЌz:U?Ǹxcoi["w!kѠm>=$Z2)BeG10IxS!nu] V6UJcNKÿ(#Df*eVZO k&sµkt7Q1Y 'h2̱%OdU_J} |Q" Ñ%pn>1f_8UnWNˎd"X8 ib17ʅ=SNVNh 1)=%TtWv&3L%TADR s@KM$iTics͘0M Yma+kهFK8gsW4'p;`P>l1ްF95qR@XC7~.R>֥jV`Z(Թͫu(&_Mw5w A{ǀ_rwcJQky~Wɇ')T_tc2#=i2<[o.4@עɢCb(SAԚvb JTH*ϩ!r<007憺ᄤB*'=pPr֡2Ͳ[E\.Ѝ+Wrj¼Q-seE-rrPc6 ,;g1ehe襁2UZ%`u)ǂRV߼& ZTCR&cI@YJ7/-i r.&ׅêjD77vٰg&-I(HOHs -WX ~,M2PgH;p0KpcyK4ZS PgJ d%ddVlR(exYp }@ٞpAL7+sxfS=~KOZvgs gugD}% Ga1-lkA cC3=#tDa J&UF6d rjdEL LO5.ۻs|&u*6J1k$Br7U $lo15ÑM`rð3UnsiB_7}_,J F=Y=l v%6+dA9Vt#)O 'U}d6Y52,aͼc^*Tč&Ε&WOͶj?'yoh}=<'=9Jңm&錛Rpgȷ}i3Sݩk^M L~?6QPuV([t"e q5|v9>&$*ZϷ7W `Sh&s-L k೴KrfǢ"fVtsF 4d1R.@knT,SҡI7aQDFO. BJjUP8 \N>!5Q:\_EU39-Wg}Mrԥ&^zT@L(4u> ~|W sܪ% 2ǃc,ѻ!s?Q/q8$OB30Ե\p*y&n: oz^hBp }=9R1I-D/jƭ܇T{'CUz)/ V^+Pg:зZb4\Eh}MoףP5 34!F N8^I"U8-C}&?жZeLTf ;U춤vGێ(\+7jՑEi:2I?cop뀸7}BhSWe3G"BnO<,4Bgp O_~Y8VF ݆ykXyWCc7>u>2"SQWva/ryA2HQ.Cuf]\>պfZ;X-^:W˛c'[nDbq;hEºHU~yJ#w\0xnoo|;!&Q2Xt8st3ϵZϼfBD/UX\o;1lC[.ɭhڗ–ľW&AՍ$Q1mp|7v2YΒ< QJJwAn +\g6},4?uٝ־Оl<6UF'I$PpqJE9 < RI/,t/E;#}*{]F*Ƕch{ ;y}KBekU1xvw6ه;K.e?CΠGG%ʧmkRQHwo+Ih%tQv<ؘg *0lQreA7'e 6s}X(X>_6ղ_$^ oAgg Z_L $w)M}׸]um SP+NBD%nk=m*4ֽ1KI|AC h 7e`/ڀ[qקI0smȰ,!k;#z%2KyQL6Qr,ZC;*Uk3ڿ]zŠM ZMPcE GD.ܷ4O?yRnCY)eo@uJ;,o\TV} ToIɷ3RMgmKnĕ* h%qsa;dBc>XC)O+Dy\!x'}$Vٻ ۀ1=CaNᴻ&X _*:|t^Aq6zf\#M[#߼,pT;(&?ZDXifHuQhJy͔clnq S˴ b̍?N:Dt CYCgG?f. LOA)/O\rU2Lj<EF{XNպ<4+Bf K^|+f"1.+T?a|ljpB[+݃-dR,ci݄=T[π< 3 ԓX˟c>C|M{O8RSIZj#zRlEAQTڤxkT'ot82#ehm^TF®d1`Ӊ;U?FHi0UtM׫ꏃ2"4g 9P/:t8ًBwp,!8g#dZ('t~]bHO? 5՞$Ҏan˪gbMp͔LвInNd:5/|jL X4/ls*2O"Y3YFBL ϟa!:O]ªe'Fl C4`pߺ(d|rm7+ w\1KgHG‰E> Ddk#LZ)q=KĄ,/8Jr`}~ ^"ǚu^i?6sDË8A2 Ft]o7Y˯τڻwFR\>96 N#$x;tHvK^;V&]BƮ03pNDXPrV΂p+]տQ DmS e#,Wu@,JzC#5R%ʈ}''.$VcT'_0QD -ZP@]K:s1XОCa(Db˪S "+:^ 8ݎB#xޮP572Xhsz0?6y8R ςt=q{MԈWD& A%ȺKljAXb3E&bмy .fW0VrV A6G,. [ F h2FFqNO?-zq[xcLDMh U}s4oMJ]P>j( }zC74A*JyF,mM:1Gdg u}(&N[,LOٷDQYRrrS{sO,40v5gix7?A+xU.)z۵ >.?OϤRFW8DNmbC&̝Pg^Y O8r/,mZ !5kqE9MEA?#tj30Mr5̚r*5rI}U no%dϴ+[7Xԟ{,In[p]הx?_/Ac)SĎh| /6{Z!Da^J Hi'agj1ƢkDxj4y.߯fv/)i$MEiF=Z))+cK^*|-屩fI댚C %{T<TK$FR$ bԤgפ|˜&\_uZTԉ'hPlڝ}&bT)`: J>ī/Ri:#rڜluꝆVT~MOީvZ{D31d2:\Fxh;'>oW%nR(j=MȓHq*  :%rnol]I2}s`_@P~OKwgDR_0ݼ sp1[1THG^7}37Y7 ;7~ gWzbKyP\ߦk[(*rQu0Bz,nCi6Ұ!Ah*\B_\B"oRѣ0Q\hMccD Sa4'I(&uzrEbL\jH.F5Bō)qk aT*cTԺqLizuUC]Y  ͦ RI"@yEsvj=/=#;WPq}" (E1m`Р1ޣ46_κP'tՅ; %g۠Xj)x(7OD˂'2ÏW"MoFE=qwj#h| E$30}f'G# .s|qԘ@w5 {j1=9Wf$SF][ C`Yľj#[eb] 6c1 XG|XMxL0'wй2֢1-3>{F;ի1?`B^7ԡY~f7Wy󜞥e8*~f/_1oaH݉V$(h;%(+mc7^!iCGۄƲ:pzv,E<'> 9w HsXQE`I.|%E 5\`q OYM,A6| < ʦ#fm [.Bk@0WczjِecN$\Ed( %2BjŜN/G=o7oҍ[iX QY%_@](ƕd ]X$zE˲֢(ep׶Նz!|C Jɯ$hCbML!|ut*B/;kMi*Xs_R w1v Ԩ4nPc)8`ML!>Y"׍G\&ڵ?OY.(Vig4#mLJ_1jkJzUANW,4 ]Qcj  $Bs!OEugC|FBa{o^d$dq?= \!~eRVKe/J8N>T`L1tߪ M0ξKQ؏9V3)˯GCv[0t&4IrLdr@rNn,aFWU/_wZ!Mvݵ}ZM!ႄt'6_U"̅Gڳ3 Ӵ[Û+rjTΣ4)vɁBQːt 6jh8|> 0P{BelْLrDNJkL5>;w jF:}x웊zFZRD;,$C9!Qt{Vã-^8wwJ'5Zyi{_jk}Y;ư;xf4?Fv0-~dٸ].){@5<}WU(L h!r7XX\v*`]CZ_\ :U*1ӑw䕟XeSo\* 2Yah&sc)eli[d 6!k<6*km ~o/o>I faEVLk}Pk5ZNDr[b0xw &ȕ [YkY>‚azVhB& 4Ӑ! ͸l>g, SNPT>'Kd}$¹R,2B\vshzUc//9'Ζw,Wp.5xȂ=Sq톶*`d;Rww0g6o=+{dʛG6)[^蜋7mEi>&/7|;9G|!@QD{`M(w'/uWor۬/"jjKȹX0ep{{ ×k6\zXvV~ % %AB(rx]%`t=t ,EeONṃ]&ps?Yȭۙr24C`yonӤ(5e#DI_\zEҁ?OG2ZTeK݈5Ӭ9iʳ"1WĵEeZM /N0XfHSؽ`^6񵪐w9(o2sy'Ayp^ʇZ_=b]OnP̉:S>NL ɭnsqZyQ4Fݟsͬ GoFd>"V<#}g*O7ixXq{gTIJTwz#ےBkC ѧfAMO`ah듯},;7yv^BHC@a ']7eO;z j[Z%W9;/<n,M͐¹^_*!v(NjDp e<5'a|6ʫ jCMJP!TN _HnJ5! ֿBT&TA&C3Way!EF1'ٖϹ_^-A3ƅ&E=kDɑ?8}8`ԝZF#k-F\{ǮcO}ONgv6IQjA:L@9פBc8srЏ-OlRV\bMǷG62ۇy&Dd{l +$IdVر71X^sGd޻{ЅI#<)g 9Ya/[||[C:Z#|5Wfp\i.XKaj _Xֈw/ b882|U,Q\Ŷ=ze5^1EzF?sF`饷>ca6nk, F. L%g< 9NHP}0t_Ź IRŮH%xv,.z;cDTJA-/#]i|f_?j 0ܿu~;Vu{Ec4ѴRIkӁǀvN ~ E']H*#=QqN2yW[&_?G1o]ΰ|1P`^W3.$ HDu\sr9 Fڻ (kLj1`Wgb4ŗuU]3!X"&Nnw}#T=}8NRdZS&G8Xz7̳HDW(2~W1~K %I%Wwf _c,qMRjA5?e28 B,bhHN[m}|LX#1ha%.kkB {{x( G &ENZAX@KUuct5p'A2H$t+W?c\9#pbX|;Q]t @@)8gJN9v/O"N |\90BBrtD8 ͳ[G Sf<6RjrNdF"S:i;pl5EШҎcz4aA׳YZ^Kr;rCt~CO6f;=8ҧ ޿7p>Z=9wJ( K~@Ze!x94_ 2!s7z&ݖE]\BG}z"F.TէǘA6K; | ~aqڞʧQNd?](ٴɠ,#h%"zZ&Ub4By\" 4E_Q9U^{zjuXz93ɧłQ#,3Is67E>5Q0I-U>Բ!%`7L Lފ `81 Q! Y$rЫV&nqIcP>迴>F6#{BF0} X( ?ZCʀ>#SB?/D.惓HϴwG73w*!A[Hā]ܸÈqt,t" r֊yT| '=vemOBu*+aٙ, (I{u792 !=O_3S@k| zo8#>3>nܵ&.^TEn_:gM&В-spS͜}4?e}#P'$=-dk9dp Ibf GSœVʎ:|\_C=Y2}uT#B MZ[^Y7^pf#d0(<TDZ6Kf嘃OD Q¤{7Og*FVS\?W,r?@ӱ*2jT׭o0߻/ޡ=g!}B&5?ч.X ,J#-1oO}Y=YÂJr%#Dj@]GlW>+WdbOV^WHt4]J86T9r>'fCK.!bTzYP*z=Sb~D)%Vb[Q]7c#}_H]ry8s}˖GnU2'ew߀9*<,vn8G 5?@_B$m4BW{l2g6h3qv*^=nُnKWp֌aquS͞o9_<Zx)]s{7IP5y"kUSR7 edZ{Qė6V:1nӃa}xxCNSsσ0/ܱvI_K,[esiCsS`츀S.嬙1Ϻt e .ilw*ÇbE@k]5> _+vOJq+3Yo^ _ŋa,iHfT;:בېk@$m.z#L\5D 'lq/Kt::1Y,9 ,@)| jRx"3,}Sc`]w}Ua;~:H9fߣ.v)K,N#qVLtuHKXDekXUcҺ`mR Ȅ` 9>yrAPp)*Z9K91y`]tҎ1~K,r6 Ж`pFAE*Ssku@ns+cU9ݧAw^Wg"pȨ並v̡ iv]c@/XXA5^-1hv8پ:&ϚuY_,Llr>pKq -^%Q+2eg2d0>_uAW#u]ؽT%]q,$jϰ14"p-1se4_XǙ9/ ntAtrK/[noX$4[vadH_ Ǚl|1͙c&iQZׅ!^"qYφ匰JOVM}'Գװ1W7~A[qs_MhPŕ!~0Jp :mXygӖڄaCI<ϹZKKyD,vfkim\Tj(Snm؇/)=ĝ0D̳`[ Ё +k =!+4Uql +dyGzQ'U7}du_ӱa\&E?S5ls d:BK88. ܇6Aя?[sd޻nwř9r_Fx_u \֎z=+a4O@ сZFz0xk~-/H5O!Qfvv !amoUX u&IO.P }.ecy{V}`n~]oRf"evwZBg8R}|GE/VQse G< k&5!0]5neS8l"bSab@z{/az"WSag>MQKb* YW%Y e1؏GQ&pv&i1p. Q3 u}t(O"EcZPW1lj<7(EC;/b6s,P3E.e rvٜKmȰ [JtT]Xdz6f qE1 ],uuzgە/}rk{M;QJq @!Z-,|He' 7 &8!">ažpΙv2 D,Lɗ7a16UzͰY<|?A2>tF kNp رm0+5N%j|)s&Xag0t7cCd-rj+aҬ)Ei Mȿe=5 Un_&~T:zQIт0ZahZb(IRmA5/\+Q۝w͠5#aJ{âJܺ0T8GtMZD.qyĬ 1?l xW{D.d* \RG|]oU-cZt SBS{&DRt/'AJbGCv:#Θ 6BZPfNȦlHp5nBn`D\7R3&V:ENy>LΫx&>nCj= wȝ"{(,{~y9ٷ@ζLM"mnǫb!g8J޳G˜S/ uBsb!A'56FMq6H4:*Ȼ?Yyix;L %Z4زCgfjk^_ 3<6G[z嵠̮[wZNzQҨ.J8qk\|e"yPq?Iq"ïF-U1_@/5Ax(cr#L~DcACV"p}""C }F>s%1ԶYhVc~]tGA6)Kr5-Е~ IJ[]k`@l`_SfFA2]}S29 r Z&xʁ3S$X;iTHw߽~yy'wQ6!ZI>,x $S{j(1xgP~#2R zE+tr7k>4'/ T?Ų6&OTZg#F ȲxutG2}Yn9"]S1ҢCݵP<| ^JtVKC鑌 |\rIK<ȑ+AxE5WZ6ІF18e#`+`$]۟^"3΅tAͻL*c(=OPPq3 Fw`Fd<E+\SӇ&fT1(a)Vhph/AVMo%zf-yl9,a6.+XtީwqD؃¤z1MS#Wsrr2| $WE]~1*p?*R=~Mle$}ݽ(0 ƫL6 juh~ԳcUM."Wrׂ4/}ոХPM]re IJFDr =V}+9N?ڤ I=xSfD u>$Α-bFӒ'.U}:6}*sР:a S0Y(~ky>fiJ~)a9EO-}W/p:ģ̲>N _Jd'DOR b[ă@Z.bZ⛐hya;YT >ҧ_ fˏH3$q: * &g_ة||J ]2er}4skW<^07ڮ7?_4Xj&1L %kBk& Tg!CÇՆ!̌-wd ]3 !ЖE9oU!HaWgӖFgF1,&akא}BY1`c_W'eH+[C[8T BNg' :Oe"H6EHo{ [LǿAi1cL *^īuH nf)g6njϦtҲI+]"C4+l!]:uB?:^Pʞ}#d! LBG0PߙOyoTLG,K~7A7 'N_Y:ykLͦkrҕ)G|(H\Hk' ?R&#p7/?Cejo{*8鋏e,Ղ\n+",{u$ceV{|N^%\k]c4bΘa.{dq%Oo/)[DֽXq) ~=a WͳȑXq1̓5s(' Y#z6Gt찃tVBh}x |Z_5B4{usfYO姌) b>Ft "TϏ3vD + 8a!U2a&DҨ\t7/5 tcP> gSfm/$L't e-t9$"Q_jؙ!z^WdwwaV{9 $\jJ_N#;%oNI(6>vh}Jb11$[*Ew4=ʻll:YLl(dFww nL3X +5V‹HUԾ`+ BYP qb)+0Rm˅ IG ~4:z$$сLd:R6$N^_$ާ|>]lڊshQ@u)s z,LIy vR]HM ڎy!rtUYfR5晉 }ky4ڨtLD↭q- sey?k`\ >sf$oCٍvUPspvxݺ&"mrUB SxS։(숗f3+FN2or1ޟЎ,Dp:u܏VG0\hMFP?/s* *wD :],CF`3^ķgZ-ř{Mɨ==ͱ+ߥVZ,QT8 bj͖מ#V* ˕6^wd_{"^uv*"S-Ǩ@Z}w˜u/"wTv<=M7 nM:td(56?cPԴa)dBlV;\rYm:IN 3/S[: C+n"Rkբ}3WJ n𔄺үYib5|) ',HBh!Ǧ !YNlHÞR$\_o0:ꏁf'dw(t ,TD('4]&݀$_Vc9tXb{]KBdG B$|\߷׆zJm?\zbؔAΰn$dѣVQhFP[eGS0яI ִ Bay Ԝ@L(4E8o))(24/͟j9ͩ|\ɋ[OvxNIPK轪2޷5*L^+In+x:j4 /&ivPPOª X88LGZۨ?7t/`K`A<.O?N(o{rQ2NզVM{v/ՎT~jld։( \fV{Nr#Xk?UsQ?r߷`DԹ%A-F,R,Q9gd̼gv0%u}iӘ|ojXٸTμ\$vs< &pGs 1xuq,>73aLQZ'WEz?j]2BƮ{왾!g: en,4NqȢf{ [hRM~Aͼka}a"$ C%s FgI7Q /Ɉxc4ud`=q\[K Zm:w_,^3 xb 09""sü?ӻFNzNRZM+;ܐr8uXZr 9Q{Y)8&u FRL\03`qf--+yqu!5`#({3҃vykUVZhD8 굝1|BGH [yFx霾/a Ei*hBy3R~~!쯣6)N</zPw'$ERDHY^fՇ(#nT:[)2A5b%DTr-,.^9'X.~RS.DpAN}/"6Xog'_i`cٷvX<g?\u~S>3\ahE#^NSߗJ*ѓrT۱9N:koߎ="syw +88b?ѥTϹ3 /[kϫɪec`?^jd e*Dhc@?ex1stTҁո|,ᒮa܇eQ3 :CDf1^$ _E4Pmj0!*>#ZfU eW xC(X(x`l)㷏eac B[oI&Xhdܷxy}\q-{/may7NRrVl("gzd}bMIYƶAJbCZq£Pv4;{z;`@A̭u=8-e?g+ʰ5R] yeهWwwsaYKCo_N"BB(xcĸD#㈪8[g>Q̜~ĘnD h W7N[$p#j 9nlr%eKx[##>Asp  0rW*N),ܥ0 V4{U{q,+cZh(xD1Ė)?0GL8d-:^m&zZc *)sac3ѹ#TU^-A{#_׵k/×jG7cjMwAT~[C-UfB F9Hs[sWuEf,ێ#_S/8dS cM Z7zbγ⍘ g6De #ZTB#NֵbOݔ|VᨈMHK#H(j$N$}q,qsSrΣ'Gx@YÆ=GG\9RqR@֨ ]b_Fq%yCha~`VCP, 2Oce+~r<Ϭ,˯: ZGY-X ViLV;@ yĔ4 L}i6̦ tdb gREi 2Anax\|kL e%A)-I|d ODc؇4g^&=#?ħ K 1}0]25LoX0}B'-QgyS5*E+< 'NA#) 2?_z(YbR͗-"'Y%++690 M,w`+q h[V9O1߇/TZmR\]=᳹h9{şi|_"Ogk~ m5Sb;=luSAdmYDTƜMíI>1-7A|nV߽]eNC5zV{1m2݈nB`'!evΐ!$2TjSyӲ]P%mD/-_9lmh%''h5l zH mTH␛xm8AEVF9$̛t߿آAu\`EBp*( T@{afo0 @ OQg#(D>,>,BA]PXCt/T,2+e} Z{iDk>U[h[=]7y'jhLr袌mwR يFxmWfs?kYEF* 8HպfXAH3Q|PR-D>"b#Q<ɛSNLK(A_˖titoHsos_J\xn&צ݇PMPOP33$Nȕy8KEWH[o_Œ1$.VLls]̣2ml:n@M L%ؗT :HnlIO[`m'"|SyթU4RZV-, f4c;+Os;`R롂FG^CņE t9*j%4pǸ*IٱA>!<L}m]4 #7_2ft >-?ŧ}9Eq>GŷȺaEH6c*W-!g}Y~Wn6"8LegIPD#lK1W"M' ĦbZ,ſ&z12j+YK-^2kj|: @G* $W)rfCD/L]ng% P\su"S-rP{}ԴdA5yM NoLz"NiKCUɑ~3d˜j1Yehu~BzlNBw␤~Œ:B)9S ֋fE)8];KKz謡>7:MsMY$?] m NּmeR7Q%>kGuK3%^OG 5uU[pGǞ_?d[$pr7C%бF^W$޳j)cV?_՗_Ux)4!v_;آ5H_NN 9+h9}:ܱr‘o Q#zSsp| tZIi44:zߏJJ\6Z8Fc'0dQz/hi^:l]kM=Y޶D)H HKGS 3C9/&#hC Za(PY~koPDgD;\=V€GlCs9,6B9G*Ch|ީ:}SWrEli<)t+P&~g b#EfN GFE¡;Tyiy?LV v۩Dti@ oTNCC{.0y\X6/'f'N$ B3.z<ذW6~_^ k IDW$Eݸ6g%FҰ_gfp軘0#y"!rY7乽`Pe $=)[ˀ{0#T2ɺO|9y4 MS9iǰ,z.M݃ 6wKHJG4Rp%s\/o'C1R#7m޴8o {5$`hk;P)=zmTC'/nF#xGGﺨ*[N&@a͇N6O [UuʔaxmVP0ҁŶѽx$3Q&#< (ܵ/"dcMT,z x0IL≤ L]'PQ 8|TnJېN6_%ѿ!J._<5OڷzH@doDC/iǟDDChHH7R1!JZQ1 dzs}#Td)j ~w[{ĭJ}^YSkDڂ6jWAuk5=ZpjYyBPpƘȦ^IF{|v6 1LY_-eyDI򏧋fق$m}8wf["*]ngT4IRz΍w`6>fekkD2ھmRh1 !yP*eG߇H%m?Ɂs@dJXыB>S5*3^Ye\KY| h~(fڳS7L@bv6HCj;ʭ%eR2&hAU\9',@T\`W=VAWLY-'"Ѡred Y@4i߂< .s TW7-Tm 6$@:+Fb./|R,Pl#ٮ/.7#9jC;iX;F&0*g"qMT"l^k fp !I0+3ojlΐ-lcfS|x!\ ->UdxL_>oZP1"Cj(T:o5XM>n,),7@"ܹb(ld-(yo[i뽷LdͯP: MR!|ЊѸn4_cp,AF0N޽ngAv[l] P脎0" tы )3AɅѻ4M(%sYj_li}>ˊ?4M+K)ޏyG(DrytL}VP4uVT+МQ rwD 8(8l. ̿ ;WB%]|< 7u^8Ss*xIO+x4JlVAC=qmՈ6a50`-y5RF%P>HNgDHzBDDqrUöL+4eZԄNm}p_1/qr O$h4+/^#dpb"gۺ"n1+Q.5ÿ'H>L{rx[%"P%?_ `_H37wy] T1;iRJD A|&i&A1ȣxPkB>#+/8-VYmᯝȟ2e&zOVzn$5$3LnMFxq U00F{ޅ]>$lHn$PJ7;`eHCi]""%'9aGgF3P%U`rq4V]4Ii~2uښȢy#oyEkcӾ–t|BSgG;O~|H'2~!~ +Py 0"U¸hpajwghk,18IU{KW vel9 ܥa( k5,5 #u޵ؔMQ^e<h5,xGTr2]; 7i;TDؾmHxvsnXvb=bE1M1 1Tps_H q:G?؍埶5Z }]̂ioΫ<.!>+we[I#ϳsnN@b0pg=HPl= HĠe(ס_t"}"D5h!c3 ~wq{r -o 8+yKrgf"9P-^UM7|, u4Ou.y;J2ࠉ9rd̙G4:'}0{KAV[Pۑrҭv@&F%c"3\;2nh(;$6k_Nڟֹ߃qzN3Z[a͓װIe3:7u1(ٴsh쀚$|[1NZՑ7X'cպkzOG1*7!nS@ڏ0y!ݹ1 +9&1j'#;V= B=r0{_f5nۛr+P1 k܅f-j<^ϻ)17${0Ld NnpijRKu^v)++> Hm6h>Q)[yJ|=Ve18ZٔD׊$i?92#y(wOVI<6Wb_)(*=JJ :@L{,N1[P捇.=YQ=?<9%w 6Qn-``KA7.ÇqZ/! 3muHB>*4-;Uɭ4ŏzBC |mtOdɬ|2ļBb.yC1sj ^s&T;’VVn^plHkZc@K@7NkM4 :Dz rVԎ(Boa13(Kʶ[>讝-Qh7IW~J7-?ȓfTHBsQ s&LD}EIVh|x_fUoYeIr&3 2@7)5UT +K%@1vy9 #o*~}N\wS?>$ U$X0R6[>SoڹjGTt`.?s18ÌGJ\kz"6+|6X f,//(NO#~e[JDOyTP gCdeiUf\ t2@qNņ6L& qir䷣q(.gI&yA& y5Gه"$OݪLѱ_AyGw*7L 4^k_J^e;q}ry]W UOGKxRG -O]>^HXdeXC#i*soN }F{#;j銹ſxJc[FIfd:'qoKqPB+Ӊ'{.H(w= Ka*JR)|  bi+;5{:([CpVoDRީ&h7.LaK))q\CᮀE1MsɩMWhׄ81`LYF:M_KJ1׊`ɵK=eӑZ|R $ZkðyouG, ʏ]%kYW頺yx-JG"ffĽɱl,d)jwޓ@2~|n?in yIG@k @`8> < њ5As-[BymoH_o|'eеrG:/vWWbmXN#Cϕx~MB9Rc&o3ƱlkOLfh '%BV DOMΩy.{4x~aHMWߛx1 dkb&vXv([5/kŽx"yzN5-f&s 85Atf3՞Qh"pStH*׻qRgΤ @{`!nv#g I68HKs^Ss9>o>=1Թx^wϭsbt*Qh"/GNkݙx>O=|ѯ̗i~"Φ!˯S-k Ckgy^΃jli%OžXٿE?'ew6Q0%yPzy|Kh8jbLb]A|< vW L1"jbDr|!x%uI;Hn|Vb.ԩWbO?sJ)+/cvFv \񰀙A)#kUDzf BmP86:Ul7cG&W^vqtQP Ĝdu=a.d/|bT&:qS7Fnmb6Л6 Y!)% u$=VOp1g'v!GU`)^?/La+_4 մوB;UhHfI96W<~l1J4|ȘV1 ;Hxj}7;D-Z{.3lPS1y!&]OGZ)L\rB<>b" "LӖIik*8Dhb"kc$]8/:ˇatݓeT2aߤ"_">lˑ,]c-@ݢX|7w1{疋`9^<Oَxb  'DLzWpCBiC|58j V9+f8]zp UDcĚ&9S%;&R R_7%308]#0o!+g)$?b!=䩪fbq;Ȥ;'*x?:3DDPd 7ܗe;U1Pwm&d 2\x'x ?RL@XZtRǍ Z^eE &7#V 8C70Ơ#i$ \sm:~'si tOPl;dEbO,JmE<~a4԰!%\HOnN{_̭R |օyﭦqVfB5G Yj69*Ze> z,D 0%cEҐ O) Lw`) ɀ,%Fn-t/lwa1,TiKe͔aO~eG86ŏ Ɩd(P+`=DgDl[@^^Z4l+v#3Գ$4jٿ! r`DCFe^Oz$?d/#<~B,SuU 0{}!ݜy}|ӛP| z% gfxvm0>,L{ܜǃUܾRGp3B1w|8z1<Gw Ah #wA}%oMUx .+{+L~#V}i+!d\*3}F|QdИV !~7+x cƷwVj* ' G9l)* < *I_P7a~G_N0<5Q'R(_7&oT v-6|a[{Jt,Ќ_aK28 j9y K)U\m&>q֑?Fj rw\p]{ "lփqQ5E+eD4rMOt(xPB?Eg2pH+ȐK @WrDVYn'/[FeG 3 5C75I)qgۆ)_ᔐǕ*n!0P?m-AA#TN0\3 a%7d䝡3  ]k| 3@76] +յj,懠i5b{' DY1!(ifW88ji<M&zs/[Fvp%yd5;mq-}<+،RB츛0qD_GLIghEfͰjpĆWG`SXD,^ ˈRML{dž(! R /jGuΌހcdEG֨y: ӧerfl!tO? Eߠ9$v=7%#}'wX~~b䖰n2R<Vb/ 3l{ِ NK`5rp`\5֎!;TR7\;^8jDQSB${Q]kp4\ZR",5ֈM5T2z#D߅o$0+֧nrIԗ}"0=v0#X^mR*}P?8)!]rn~SSl,v-_Pw1Sd큖=]ZL2;a24·Qݨ_%^]KVxs9PlJG+?$>Y)# moE唩yY=ܙ| 6,ΪA9zGI.5:xChY;t& 8g7NXL=aA 7FksC) Y:QhS`%u,1n4[A$[³nib>GĸrUa}йFT>:·bQDp(6;4*.r8Aɫs/:9Aue&TXdq=T+x Ts:j10j_hr$mN[ǁ,yd'i0m3PdC8NqV]=A'F{JX5Xx+Fz'8 9|2a]J_Hg9R7(hzًyA;4jK5ūöKo)]}@?->~PCiG- yYr0ZBY-Aʥz=xwjeVcMTSF]AVlL?yV(:ku@pVbd %"53a'>/} 릙Ϲ"#!Bh[a-Lt{.srG ٢19d8Ɣ{ 3 5Fw>?.:J'\8E d=b\=+XJbTUλ2P’٢ h8䦜 e Sl˙X[5!})lINݕ*I?Mr$$$5D 2!_U7:"^%@N.١$E,= |M)?YxEwvG0  <|5yS9Ѣ S EU&U 9߫OD!VE5j ؤbNm˽lKpC;BVK4OJwSĹw`CfeCAg=[Vq?FK6` F4TrJSAB֛8?R0:/6OR6iVfJu E ` qĉo(v[aƈLg|O =h͊f<_2;}J-#gμ6}ҟ!f\ܫaj2 0wiU[мx⭻pd?Vv7i<_:ӌF  DHeWL_gC'˚I'SdYEL(r?O ЯKY)Kz>!rQRN~c,QE`)Rz^'H'Dt,s;YIf4uh,$C!9Y`<&t1면Vډ'cwܸF9/cMc\}9FTiDhakklP}H+kSd*FA?WI"z?K+&p71Io48k3S8CKnq87XpvT%[YUV "bbSWWⷁkX9F܆PwVÛ}s: /=F,_B`5E3N ;vQ!GP2nA3- M4Z2^tƞ} מ:y\Ҙ)_/6ӺܖugSLYœ˅{_S)1 #X5Չ<ܲH"YOh؂+C)/>!`On8xqjgKBF_K)UJF5rn:\9z|pT85O*; 㗈+%*Wp1!-d1qyl7b݀~Nl8?ܞ#8F h y[nt_"̗Wc{p8HFԁDs3h@_}`){ћfX&Z*pG2Òx1Y.B#G./8=HB-Ѝ+E1<%J농t(l[2hXIX;`:&> -GȘcEo+E}N{56oҸfB䆛MGzS ضm5Ld*ɺs,\*e3#rgjk)ڥJE0kd"ȭKk&\b;@!bTd2Uz1)GGǓ 8H&f׏afz[PDM1[TZ^ѿۡfFKލ ^nlHwI D-춟46kO |9lždzDG'#sӢ[%: 3T&)g ";3]62|\Ķ?I^l+v uV 8N!ˬO6o\=vJjywMT&]W &v\ӘKBXze=9L}[u?ي.<>γ7ٻg %"7nk>y`Gv[˜HŒ5Vޮ=꽬Y= OE3>e#4$xg(ڈdfrη. * av-HxJe S"{hHF;h(m>Yr},CK>O%9dWe,&̳w{Y%~ ~+Fq–4-"Jݜ\#'1?Ll0j`d艇FHn֍,= =oh Cͺ\ˁ>N>jYB,<;oMر{+K],{+LD r:oq7 SO'XcC7vZ\{vY^d:5tH/Kk-53qgD4؄ ̖t)S):bv،'8@`jF -d@WH;lاGK2-lzf 5vOZUI̕o {_ eFHd_=iX'jTT^;h2:ྨףSfTܿ/x՝oy]m8KݳSi=`,miDm6jƤ8Evk7>(\tGÀ<) 9LYHjiŇĎY0 dc (CScD#ᛋɥ^њl5@A1J>JN,:/s HjLa;BNc/T/xGZwCܑڈ#d.]LPUmA=u, jwvM|oH,+ Ż3׎qҐ/my=[4@BF(~NHil-NAµ4aSi%= cB"r0*R~weݘY(  [=՟W͝ W~g"C)1RYElbNw<}zH$9qJ-D{Gk۹MތYALܪ֮3U,峡S :ˮ.hDԇXmS2 V4{ BW͵Z*s]-`MBvJ_Ӟ:lP*Pm24 e,I7cNn#z#y1TҴDGFS!mЈU"WżIuiXgddZ}DQuN3BbJv0@FtZAv֥Dn"Q#݆V-{2!#2:݊_S.ͤMt$R]^G&|&z_,LRݭmcO+nUG'S3OMk ]u۷zP`CtFL̎ U<*ha0)T&ÌW~} Л8ItsY@ϋ̛1p JkS1t'1<1f0~3ǹga+Zx⦕h2Zf_RWF˃)2A#v{>$i*<\uhj0.-JQN%;W򹅇 F(dzb-"^-ꫣeBѐ0.0{~6v_]zюuAsF,6u%0ՅwtBK/VPZ moJZ`5rRMVI*bSD(9o"{҆ gzJtےp{[eȔ +Gmm٭G">S6[&AM(X?l%p,i>qLz(185ѦRˍ}R> 77 :&vgEM) do\z,SUv֡AYld|ŮmsfyhHx@ӸiS'1& Jåpl޿ oh8 I+!V!|x*!JiUCвt=ϻBCzN}zH[g>\jeH)G_[1 ǀnLUi\AqԶq!/W0IuUDޠlg  c9>=|gSVV:YT|r+qw<6d1}]JZӕGQcoum#0[F2p&MZmHY^u>K.3fz ~Ա,Ux-u6:.znXi̴V~QJ->F#tϫ(~KT'Fd(1 gZO~Oʏ; ʈDecܸ(we'gY5v(\AkujZhˈeF{^:~\Q<`2PGe ! 3{}l?1c+g ZKչ]8U'}jcٷYuo?1XH}*ݛֶO.v|d}?XIu/f@7W#^ܷ\yoElT(#G|ojkw7G ~&5OեE'TR[S~È! P{U\p:V:mƲQϬ 7"յu&DY>65>+Cd%[<ͯR;auM!Ӄl0M_8Ŀf_hXI}+IBS{ :F%й2L7<%V0 RFH^Ɋ$dW,K%Re6mp`/7mI"2j$h$m{.檴% olκ'n<`ty=טȣ2@u' .&R.KF-/m@bEb 6q1Im6g$ 0 UFa*\\OkYf)u-+eZ pi esyGNA$xefA4P5uR⶜ߊYpjjs.;o=5,u4::$,Mj1sR){^xiвV!Je9`BƬQ1ZB"-d:w]Dyp (-xjDj&|P45A2JiW 6*Q0XK4 ⲅgy+"Ѱ=BT[%Qq/^dJ069 DǣKQo8FS 69zfď"wh;|ZrZ}T-]K$?[~!yٌП襉z{J.\29/0ϔ/gjӜ>aa%-bZ{;Sp2')P?ipGq=xe0y=\Y>`]3t<=P[sU)|UA`]GS==|2gw襚ͧj2{  hl |Ee+ٳda/*9qW#S2 6j$kg`9u%!P/qS+~LӒـ}֋zzC'+C<;]Bo cHG> Zٟ9!9 ɊCq2M T~BB{6Թ!8]'S4 fk.`OOca0˄I5!hP=z=K&eKo\ ]`2*ПC贺$`a^؇U`fD,ô![}:mҽ6٦'0ۡ-)wje$^l5{ѩ.Lq[$ *ѻMsVDͲiC zb")uf 'RGALN#:̇1:3i^o{z̥8^͔޳r8WІ[IngCGEںnhNeF4il㵎o2uA C;zitUzT+ wDjٲwI_/^,V95/,j33f(nFUr~V&dRACSi'hadM7JgNz!Amo rCgeIr5> uE0msds!1ȸq8jovNgIw60h& ,~/lcCZ_E-s-)2V8P17.~DžTW) opZ>Sԍ7 һ1HOإ&@\FoPoj~"f'&X@`)mrCD SҧN}㬌r~N V bAO޼'+$ǿZFY=~t;I y ug\*c2\Q$FW.Ml0A أ;®aٛQA$Q zXV==|iD$σ+s~Y-P`.v9Uvb`^EC;*qRtw&NuqE)D$q[~3g k/Ϻ{ns5PFGpM _ f =&Z䦺kSٖ.c{OU+ϷltAu"t,i}a,]_ɗX1[XO\ZWzbШ?Ģ͡\ erH8qs*+\'%ޒ:&V8 V_۴ %Xʔy72qFNñS#)nu Va09Fu&O7H%E`1~^wV"GItXD?53g #87XwtX;.߇C063!>#%#*FMZ0:"K =e+Ip]aO]7]VRti@X]PxRY*v}S{ Z)~+7P4JNƐUl^{.=1pÜ^ o["v<_˺N]JWLp.|W+CGv!Ҁv w`ئ- n~3X6K~ȁ1\=ǡE|u RoOQ9mTv&7J_bzsɌp8s[ydL ڵ`WY^r/οk4q Bf^դ>d?+/[?~S *soxjxՄؑj_f+\n~"$= vydqc*HLK`wX_]kU:^"EudÓO$ꢪļ-]q-_ s> ݗ=Pg L>lat۬K p$|ׇR@A4R|rҽ(f߸>ETf/I08Hqp;M7.l/uLĂA8|ÑFSIuKׯ; Mڐ/#r!_ppgQX*nQ;q3V'>AF}mEY+"c?(cVi8hcБaRM\PgÛո[.}d`!Oݏ y(XV7vM]U(]tȠ#pUip]\]+'s΅SzYN@OᴫHZq0H#q-rQv C]_^91߉1LyVA4*vƔ@BO#Vš)*y ro'lW'5/aP?Ÿi~,ScroSd>{n&"yq0p2ϖ3)'lY%zÍʜ]mjnÖ˼#=Yg}(o]-,6 Zalef='Pk{n$3<қ5V EHk5[vɛk37U_S(Om"Y\` ! 1m-"RsgD|ۢ}LNrxJX8Q:#iJab-!xJ..mWzŎQuk\jw#b]6tDа5F)lqB|V^< ۛ,:7kWjg]W4ydѤ|<U &c|mgrm%r<`J* &t"g t|$oق$o*9D$ٹBQN9d}O5[rN+K<'usƫ%ufٚIOϸ!4qvxG~ 5i!KN@0L2zdo\-VgPY1dNS$^ԣ&˕9 @=F%DA܏Μi9v#=mY  嫢T$]'=">ۙr婂v"];Ӳ@ej/$qU,Gȡ}TiQ}bK\" Eg5Mb…( ůkB/D$6G)ø̓Q7(l.Ԃa23. S ˡ# a,cGȟʐ wwz '4[0K3Pu R6fX+Y_7ֽ)~ !xZ..Ywf;'{0G˨OGrh__YHIQmap6%N@O{~cXwydܞ?엾IxY$roMBu_}… JY0@/+A F iĜ5QTPH )ݼO2Smڸ4FJ˽p&[?۳WRzU7v01`+iW΃5Ȉ%o.FMA:;pb4 ]]_gTڿI15RPcrrnKR"FZ`/2F7nyC3s# yU@>*+h;B?J^|>]s(t'#0rwrq>SLY/uWj,_^#2CIU;ld3Ȩ}c-jz7/TS0T3d4`7c _&p6!#}&&Y (L>g\iX,"1ب6jquk1Lw5D]5Td?ţMkeBԶf;g9K<%`LH)H{9Z_ &ru4Fr[OJӱ*+A1痘f//yO~|N3Iݻ8atц%\4oMz"2UqGm*jI>K?'DNKAP'/K?;|u{&]/O!dWV/d߫{GdH@<0Ja92\+UwsIKm'6ĔttgI$tΓ!.C 3+TPkwuOkkz+_Tv랓?AWBհiʹxI'ČHQWwgW̾XTUi7mL)BL t8sMX|2E|d]!q;iV^Ǧ3%^0t{}+/2 SV*Y .Uc=] _)2)b<2x Z].%Le‰'r=N@Fe>] 3"1q~M/UW.-TU`,9*,^(ƑvTIN%PiR5KN8(^pN kew~3'o}gdj_ ڽu14W*LO.X\U@1&lR)n qG4"K(zK-'37z!f"n;rwuI]{P[#7Ca+MS>C[  O+ (w[+FX)K ڵ :4ܭx|cA '(B\aD^+=Ɋ?`xu#3Ehza$oH֚Q0d@6duUIJ .""8ɗwWKr[ƶclmOÐߏ;_Kx-H$|$tt689+q7zؐ7T.HP% |4ozf(öMfW ,(9M>[{vF~oL|ۼ<,윁/)4go*Ne6ؘ\xzkػ^K* ܪ95QI+kSԈVwƏY~6[yc5`He?7)9^ V'KT ΡsmR> F1'f#_sUIg"XPZSIܾM3ۅh{5/" +*")!CMa_HKZ?U3Hϔc|DImP~n iS+]>QTZL2@IkpO3*A{Mpؑ'пdr:/{&p>hNҮnnU^cr3iMrn :lBR@__sDT*bV:Qb@ՊM)$\GCz aGiB[8GGB@w C^{Hl;K$w#A/K BG+R#$56kVTi HLpI9w{qRHAnħg쾄Fu_AÀXRc JYN3}U6 nB'bf@zğ jҸWCP#\ j(`UDJCIٸ>uYV'06@غ>80,a"2t"\{ /~4踲g7DMH6QPn(}ؙ{83n@lvE<­R.k/~&΂!cO5 ߋCj1(Jiw׫J {,,}Wh'~H}[pC0 R,?_AG?1mJ]0  pKdvSƴ1uVe8f9qI/F@'.xH~%qTD'RC0O[||9$oJ;͘Jѫ@JXbM˨*28 cܼ͂^n'EwQ9J&6n$R68$u6b$)FzQ.J[9^- ^Oa=A٥PkT|@m4R\mt2#v.OS7{h9uWCB@4!\lN`%|< t)7v{II` I-awt[OU(}NylB?l$em.ADqMr쇀ڙēpGo}%`i9\ثq5r% f oY]eDP2@^Du=/(g'?4wx$Lֿk<FͲ| F*d4iIJq׉ &2pk ۿ'd](`!-8oWb1 |jz`2͖ʵQFi2X,|Q؜Q5=}0 U(ZqU9zMfpϻTfR Kyt]Gx $ : !Z[,[GF5#F+mYG8!YMJOګ?s'94-3{SW/['N8O9l,a쒞 W@Ђ iGGـJO%}I`b4@۠\Kǝ1{7{+IPCLwznfM2!_Jfy]쇌q| nM%ӷ``viXo@\<'Q&䓩'jYc;GQR ftzQ2;Zee szjTh̷>v#}K821/h@L2?)je&* UM* 0Gv{ǟ\]N`\W󏪑2v@x-k9@ҡDDGG[tQ p V9&^ /,BAazKLMcCw<$Mb'n\|^jKI-ޜxƉ Z&,\)\)G.P1% =d@/lۗw|!_K@ȬTgX^&# "_ ʸ,9̓dd3M_[`h1^c`MJ*x?7 rzQV 'KCOrtv((4?⌚XKQr)Tр4CKӜw2652mQ1wȹRG[ t8XK4~*'aP|gŧ=JYk<ԘM4\`h| Kkn&o,TCN&ųN飾}4?œNէwÿb'awؿM $mwe[P.C#{O:n" $=$DL+.N}Mut}'M词YdhS +JhsC%#4b %5'RԜ݋/.!EAE9 ޭ!c a`F>A5@lBI"BBOQ<^?AST[9kN .FjcCMW]d VH-M!9>$űDTih42K.Dӛ~|<иĽhpn"tuw͸dR?pvJI7dV,nNH;>nz8/<)' ckb3T_lPT8]ahQ@"kcm#F:'gcm핤ClzyA].AnT-joŇFhtכ!|сE5_5M BIaZX:XrKԻL^JOn hil@2]g3=Gn7fWI%, /}Go&+iZWiWeh:LD1[:.׽liazk5io M$0+e5;Cי6}Nj`Mtb{t^?ϰ_Y dI@-^dR6OHx*%=I7Gް$y2wu)P<8 5Ua ɢvKlxW {xκWpy2AXllPPx_:=h8r;ԴC ).FΐM"ETEoK]c' > uȺM G -8i\e"p)T_G0bd5s.}OwY!._r$StLQ8Q76v]^B XZXL4 O;jLl/hO&_&Lq NC3aQG~@x5yu9'ųs+|]M-kmA٬h֢V3N÷題6]H$Sp=̛VsqL!'(N$2amF;0FdٰŌ=&(3Y0,XXÉ6'`b(D/)ei)@aFV#B[@#S=:_ yWӷI!YU۪5Bï}Ϫ8 b;%‹_O"`mb {9c$}bV\r@6W}n@MhG9sߖqbS{|PUfdR%yCVf!bwU]2Y4t𸔢'3oxb D:%5CLe 0ӷI?mR% rh+Pq,vHo[F57h ++Lびçdz@h6O5N(ࠐCݒLS%,Ag tc \MڏH=K%+])@ݙ(6Wݳ6y;&g;fNe>M[:6$ixyF,}5wg}{lWw=G'mZ>h/6[XlP& رtԝDiZyʴx-W4e{{4Уyڊ*1f̬/`l՞ {a^@C6Y*_ }JC)GA|mG7YuzVS.P"Y^xS ղz9KԠ6Y;ߪC^۹d #Ƽ=akqҌoS(<<6N`4UVQTa52xً!Ȇ˶Nd48L>hp ֔cPeI,(| KhQ-cON4QiD~l)պ 2-]< -®@6|z&FC3m4@EûD}wZ/k{_/7c\I2Dn$7(Y]= 7~cO(c );.N {@4Q=7j=N:&28a;}*g'mIFIq 2j$8cەXoAm8a|/b;Ab;a]v%jԝWvk%6չ/ P~E)FܟOT>k]6JW6׏X>R|ZMq\HcPuYOdW~A"+3k$'"aƄ m~ƚ 1->%#ZExT֤Ψ43ސA0b |IĚqOq AJW#Kڕ)ڊid% ȯ^-@57Q_sX̜VLi9B鄰@'J}ݠsꔋ+KRHWM8 `)9隠-z*a:4P ?KK/ :'i#q1~YhҰ^BLMH1[7Ԫ0^'[Z5J5s&zc ˁOkpbhÓr΋홥Ywu!E8[su?iz4vKǖgD$}^HMtun/;'K>p';ergL[_< dag< STwc9DmEh?O0ov! ֣MӊhE-'ݰ {F[.iվ?5쭅= )]W@9 b I:$4HӐ!܃FD 墯tRgf:$$!Gq )9MY!9sd+vW*Os?>'={^=*b@k3QqN#$yQq޳ELJA߮]ࡼ͆(RzWnihcrl+z&LLN_Q\騨TTb!y4R)K٣iÖ́%Ȝ[NYOSjl>NBcx@U܊D(aDǐXrw$ %ݥz?UbE,ͩ*?N-AsY:EM /~nc sk(+7v5)&! @dFz>1jncڳz`%]zZ!qԹ_=Y[>fbqOL .Pr7U8J2簑]f6B/ y̭-jzV{(puQd KN h W˷ZpLڲkS+yLfl rN!ȕ$VjQˬ峅IXN pLk`McPBw9>e.C!b=] >Ѧx UpJP?t MlMx!'*~ufc뜇hx]~qVo%XF)dFf*!sھ2k]7Mk2eQ,vR{)r yJH "u (֡G&vaOZߏ[Jh,QsF(3(suzMZN?^p rPNnw)T7 pxC=}T.\A_^YC3_Z89!8rKOepݗO,֚2B,lJ%hdzQot"d6YMS]E2bi\ NO{)h=-Y̔#4y$Ȥ| o^4:^]~QP/>XiWA1;`|$)ɰ< =)@%UӜݤ};(qneU\K|8VNbCb~3{]& A ZZ r*V߱U%F`ىI 0uuiz26Y`& %DRߏUKfr h:*4ֈ|l%~p0d.\\\ S?JF &,voU㐜J3D=/*a*iL=D25%t}zRm3l-$a*.Bl`lYx]z9`mT8Aord{2x4 m∍M zq+X!pmZ!S(z2THMWV@Hh'M s.0Mxj7|(Ouu ^=ӓ9*8 iۍDc7-=4[È'0nNZP"zNtx? pұqBJ;nT,C oti 4{CI U^ +7VЇ^򴵕qOܶ%s00OaYkYh}rH6(s"{B}>EF)7mlCľp 7k9,U΃ LsE;&8j0$ɮkC[QnQ11_H z?zєE_/Q[*P|D-e7&=t0D@|;1&d %7bb$}&حFoMLջgޤ_@c3h"| 9IɎïw;enXm_zgiBAb7)urσIc$y$ril4%d%%, ]B>z~;_iPQu*͎y?*}zM݁e;\|'"v@qr;m p..3(l4"Uݽ먉;bUar7.Ɯvz {д]v;;I{S^h^]LR`AB*rt&[؀.epjMk_QEsY&R+V-Yy9MfM u5Kcz܊Mh6Ӫ[ ~fLI˛sgDZ`}rmGܥ|/[hku[&&Er"\yV Rm2>rR 5lK.Z${9ӎ~-O+[0:zʩ?3s[;θǬ•"sSkB",$gk8qo$PjKl)w7_C>(ϡ x71>\MZ1GfNLlsbOAϐ4[3ޜ~$`V1ź4$l_yU֋mK"EO)3t9[ӕMhVf ;YEQ6qwkfTlȠ o) xaR 8WKԀ5a p~z)Sż@t-7^*N4iif,ZIOpIxXm`e[5!5GȇGӪ>i/&R}'栙,o̍3pd͐V<,&:[8^.m6Ӯeʡ;sR T!PlLɠڙYZRH>tULUTZ-jGb}!T,µ})Dr赈h"N3 \%RqU#%&$= qXo !~DQOϡhõq)ZlL3;9fYPg\]y@P7ǫEy 4MAl2^JILj oFWuhF/SuFlś)BD7@TAM^K> DmMJ0_GfQcInag&t.e }nN.,76)9֥@JxXZ__H-dFG<26Z;/=XJ9GNJt˼sWtSzvs :X?C9y ui'E<7 nxW}6p+}Ǯƫ )b~jԅ[a=)BV]*~`~I))yXÓBiΓOoo#*,hOp͹nA~^8*5ew奋:J!"e?942RL- oT Aޱ{@["+NzɩFױ#ayj[͑_`yvƞj0@t'Wi(VUn[mxw@F_dwmc_ybO-;+Ӭ ɯ2[F ֔ZE;7f -qȽKS =AM6/: 5q 2≯|=G:f"¾["uyo5r{ORE{90Շˍwu2_3l=θ ˡ~9 Y5ՙZh7]?˝?yD~ף*$J84:0n9Ȕ!xOcӨ[lO}|XFf їT19/N EKMaA&4LͅS @ȻtreN2*:k[;|Bp1maѷj{Cxt?T.,t'؆Fw/gFB"D)  ޗOnJ6 p2P %84 KX?[4ΕKտ|W}f3˓P !vF9|xFxiO`ehm:+>'yCؽK%֌μ~@| {jCe,2_X}0~īZr=1y3H_X/Q8DCdvEf^SPmD{۫; A; y»(@4 w [ Z`*yU{rS~bHh>#cر#QxP|G}0#W)!]U-]Y+^:Ƚ]#ɤ<զ%Kr{RԷRgY}Q&-6 8ģ U }-3H-WJ ob<=&֏uf%z QVsxQgynj n/u akƋVd"il%\MxD?x9oėF\ |i'ʣ}c.46}v.IDxA%$a86_.GRVt8Ψ1P dT>^CekM5x{} xҘ,qL߽^.A\@b.*dЖ_[75p!.U'T\ f"pC5^NЈ2!=$N1q@M5ll(" 2F]Asa bG^1 v!uN r`K߁%S#%=WR%0";/R'HYE4^ͩE IʒeY~-g^/@Ain1uo1DaOU&B4 "yrէ݀c2O.pY!jVVŒ";nS9ʳ>( dqAG"hJZT罘u[CJ»U&CSA3n_D ~H4HčTq8Ć@!ke.t賹LA=*pͳ39z `W M,! a|ՃLDuI,I*kq ȕY^ lUhs)yS%6Z@nPIExmO)!'ѳȲƏ(GooT>o@exX=੩{Ν XνmƟ΢d<a'~t)8v^ euPɦK ًZ@TwPe+2afnB۔6s4ߩ$w&|j9,z ?jP0SZ( m>˔$1ou*i5a/@f RvV@=vB:&02j~ ~r7lg-oAV"a $;^/;]"ApJlj =?F52_@H(zث%Ć&ܯh<unxx6$sgя5PI}[ʅ#qp նZЬ5o]{aY}.Jo٥)J9WI&xӇEY+t /'~՛N zXۦ^z2d>_s0n yRm Yq|&od#c}ѮeEOcE~Ԙ @/EOomW}eWSy \|\H?k $&os1z~z 0Bt8JO&} Z7;VJ}{.h%by*&^5˙[D{0(&h ZqFA%eOt}ƒ4ֹe%# 5[GoKFd7 #j1J^q63 2o7؍4_O3KtQ*T +*#'b!BJvMmvb]bNaܵs*9SeȧM;i!=nVݵAl|ZA-RidnMWo}g$|-@̓Dt~pM8&=߷)c}2׬9'$M=wBpejšAdXT6~{n9To}4!|!tp-) C Sbh$HD$-">ҽYS燐ci:`5 FNp&D7-bIEFy/Q6ն^)Cg ^nAtu"ĂhB% G6J_JSs X31剛 CۤTI;sfTE)Uj{+j#ܧg~9dk6 6FjzxXeK4n*\c9ZOb I<O&,q;q2QF p*d' xNs;,4\Տa)=u{(kpOc *c8\`K= DmASj|<F~ϓrVeX-r/;z2_Fvf:]p/Djϼ`[}γIyougnjݟmB_IQd'y髜%T o&>"1XS*7x2o\mC1,tJbKAn*7սNJHգB$,2 @evsXj>7^f'b_E` <09#&Wծ:5S]?*$ܯtDx$4I<.$i,C1:y t(3St XV r,9^1 :eL:W6E+Ԗ摇yZ\v9K}ޅR@I|g\=7[Q2wdpoĦLxt+{@$PO0̤c{20$(Lol.rmIM)}rs+~( BW{6~c`a-?g, nniT2gxo lQA3S{F0Sm *̽=ɞ,",YuLg(&]kɪ;7 Co\'[,c@ v^ȑ qiLã Th6H?'ezScs٥ elso%g5BX,n_f'g o>J,* y" ا àfbh!t)]`Fڵ|~ 8H9>yX53!¸!vv:m5%,|3ʙ0 d{Uh9Z4c5۱( bV3NE؂`fHe TK{P}ѳuyޜ̓XD5E)6vi*N<8[AӍv#.^]3}#iӜt {.p/=+Cws:hHq"H]BER3pVՐ4Pq7=HBp`2'1 ݄lmW}Q%?%]t֧">:eB/9ŕ?Jh"{ o:(VP>ysfJ$B&on ? 0nDp )znKG?*Jtw0p5Vu2nXVKtڤQ߾&ƶj$(;zpa꿋K#pݻ۷ˀH`4꾎9O[sо;p&y ߨ!q0{1j!󒾡aPPLq蚔`%d=Z,1߀l(A( MY~y1fO[ b#~#RCٶ?ݨr8^#8tO鑄er*g/ZQ${ܘ9*mAl g8m /PJf:&F@ _+-1 }1VJA+2jmR?Y!蠽qV- .f8I+ʈ2#iؓziܜ 8"=k0*{Xmm(i ߓȏOؿtd\2ntIv?aʘ1Vb&DjHAOތF y_:Vʨh5/}\LCutTeʦ~5Cc<`a`0<{=Eir| T٣}8[63JCKTyiBֽqCz"TwvX j|bp#?$x˖w9Z8a <d6NA*ȳlMJL]6 :؛'x.pf$lF!}mG-D[QS xN\#^$B!TbCSL~K9lNdNm9o S-%~#H˛BEr_ $AQVTwx`St{;*[&aogؼܷm)Ry`ƒs~A ^3i^~3tz6p) T~e|p{fvb3c敂͙L =0uZQES:vl="CO4kd8 KJvNYH01 H()9*ZT с@ܦ*~2siLy43&X{ؕo?J$Kfi9DP)P[5gPj3dN@YFVɦwiLuibR)qWb.xlPqA]óW i9"j?%APo*//Fvjn5`Q4~D櫞 G1ix/5)Ybi@Z@8\a7a|8çtB z{ mfbN\ۄu>Ͷ5Ee5l#69cX, SPBٮEl=gV7Blr<~{Gީ SxU4*!VnEZ7l̕ڰCb }PTu`-chX\G{a U->D c xuđ58S٤Zi}_~349t D,6j=q1WMU藫cWI e! Q2I TR!ɗҽ7CW[XH"!'ޱ欰Ta,7E mp64v+ҍ`dKZW.jjsmCVLMU_EnuS;UH>z2mbO?Z#@>WN 4 95o{G9ґX-t2 A '-z^Dl3UDx+-[kp(f)'U8('$7tXuj*TrH'ZWѱً_2>bcH ~g# jKȦ25 j^͐ϠWnQoB$}6*6JtR9OUƓJ!*I@"1tzߔ K vۀS[#;9cI}f4el L8?Ztf?ErKƙwyzezqf*,F8+ j{8n<&aWgi))B"9!J/$Xhס彿cj԰!'f _YAo}T}!H\"Ds r̆"pb8U:`("+=K8oO{_v.l <vH eRg(`aJqYYSxٵj/VnM?DTWi7ϬӭgR.. j9M+k Lg&_&Wp upPE| nN/Q`PW_L+GTO g}?"ؗr2t˵=R+#8%ՓFе]'>˺`f`uti <^ͳ9ῈWs3v+\"ҤCuz} hm_z]27KП=)IG2W~--i2(I2&S, 5up% Vc=b'{ Kƚ|ou#@ sFdN׼+dvGsM 紮Ļat̍Rϐ5^^f5U]K{dJr=|/1tӬB.E? _Op"uҝ@*񷙦/>G?%/7RU.;p 3"AHC Qo{3?Sɔ:Y A$c*O࿝?ǘM O!hsqCakBt.?9&:Fb8[9T x+,fo& ~DNM-g'| ^ŕcEB_"Ɋc$$amۜahYS%}O(]S^a.5QiyGj k)!wX7@5̨7ϣ2Blӆy|L jG jnPݟˑVJr\t *"õk/8ˮu-V pɆ@>xAwW6@|R|/C űYGd]"ŞFh+fr̫#0ljVQ^i"q `e"ܯdlvww&/.O[yhb#kEJԠ㟒@"!\┇Vю F^c S>x igi}d|QRK}ys[Xc~ tXX0X_X's^YdC#Zd/[u^25ɼĉ{\GHzd>V2$ X:€#Z}<w6ۓ+o<]ǯ1>Uja5iG7Gxh۲o/ is!ŶßKHTd Qd#nxdhqw0e|A`2!PI?4P{7*cT9? 3?ѿ=j$ (G ޟcCDoA<93m3d"YF٨xOC @初gl>!).=DsLOPK&hD8b#0⚲fSDLjNcEN}rL@J$TƗ=Wt xO{W7 z:iT|IS~S,<%N=NGi*[Nn&&(7PO PC| Vq3!k~ ai1+9?u*h~<}-.,&$ uH I3)v=?yGpe@#kڔEzC,dOseg |'xۈAS?9)1m(4ZTi~) {Zж^#\A"a(몠V(" e6s[)th N&*c'$^%zY I8ET^yHVI V+/T'Sl^|ūK;'r=9gP6yvz5w_g I1ؚ7WQ&H":go 4$딇[bnުVt NBTgq rDEA̹+r)/#pBk%Fǖ 7Sԣ|L6}%+mU>cP!-d7[\_UD4_' A_<\z"\lhөF"?!P󓧾rZk)?k҉f ?Q{)0lm"|S) rʭ4,>#sNrUFՔVAXY (>iҴIS GPiOi™kkj! &BM Kw% a$](E"] @6lnJ h_'Q1b+hw "C%-5Mq`TTwd4+oY ?Ϟ~Oѵre\3*|I$eh fis*om&.)VbOuIh͠.շ i uv%jʠb~\P{/#p }_;\+U΂XZO{?xiȒE-6_J!^tS&wMl[_ےpn2f*TpR-'ga"&6DǍ q╰=cu[p_.{exz)3@H.[cH@͟Y S>ms >A n&> UE{ enb e7N[6;tk! LE>)?R0HTVErz |Z{eHVFq\5ApM=Gz0V6ŏ꼦b#{o*xd 1 TXz7G :}|1-ޢ坥ȥ*{Dy1_n 1Z8mʸE1,&i)ͪ^ _!<q 9~C,ͺ&&6NID5{Mm>k5Տ&,S^a'>b[0 J޹EIICq&z!-zN[.4bv@+KV* r*qZOua0DQ *3i ztz޻C9+  ]j"3ʇ?N3Oˍhȕt=6>1m#V1^2t-=luU+Uo*zBG_7ˑK7ǒEޓ5蓥_ZVܻjʻ&!jtjA&F)l>H V 0h}cj/"9O,UʕS'DL@]gHi ޮij دxcwr^L?;Qo& [Tz˷+8JR"}r z2=9Hs][boG 3$`c^S .eNHrNIaߜbMŝm^RH2շ3B+oNfpFR~r#Ob@ϒUe ia6nLھKvCX')$#S췄lPOW%œs7tMR6TgH>cWzlyC\FyalN6[(p 46hHLplGQ}|P1U>Urq3dz> Ͱ =r5BqtνJADK!ȀS';ONtڱN6yDyJprJͨZٗQ3ϼ|zz>`HjN\FX;@69VPf͊1Q`4 jA1 W5ϛBcvCŲ!+8 [Ŕ"Pێv/yHgɓ2JsP'ssK(ԍ:ԭMA;~t ^Z$)_oڢO{U, BZtp7.c 7ÔPTC<3d7rmmG|.0:Ε&gߦsk]YMi6 ΨLY[򅳙SK&+myn nҴ޾DY `UrBʒl,jA3/du>Me[b~} 5ejSN"USgӒڿuB NY{?( ~R4< S Jx2LmP2JQY|+U *ՀД mcr9 y "2i=H`GM[ Vc26 UGdN.= 5)3$Xo*AG"W[vP tD\9?p ~*>B(~IҩȈж~>)%eԲXyoSExz3]s{E5[E>>v!tu=LneaeQ"_ ~-U͒x81rsP.qŵndeX;[!U)׋FJ%!sdK u .a^:t]jaN8AR+~Yha|R+ YZ