sssd-ipa-1.16.5-10.el7_9.7> H HtxHF`w ?*}}WzYC$2S;tL"lL0|=y{1c16ded18b21da491b0ff87d40d0cfab3f799362ez9?ul|yaF`w ?*}}zZ,^Yr}թW}|HnȦ2{pyLT~ >>%?%d   : 7=D   8  8XxTTmT@DI(X8`A9dA:`A=GH(IHXTY`\]^ b d!e!f!l!t!u!v!w$,x$Ly$lY%Csssd-ipa1.16.510.el7_9.7The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.``sl7.fnal.gov Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $Kq&-A큤A``````^p0````````149bfa1f39ae8e535c3b7ce3e93adb27b89725544091e18b4fe905376e2d9d1dceb1657ace250b31760539581212f9dac9865b4fadd328e59e0f9436456046b18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ac71af98df93f2caf49621db53b8b99f91a65e45b6e01ad3c5d8651d00a184d5de95c5b2d2a113a5674a5f7d5424ed7a188067c5536e8028835f7799fecec5ada10dd3e44313611109e26763bcb173feedd36fd04e73e65832587bb265d6bd0arootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.7.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.71.16.5-10.el7_9.73.0.4-14.6.0-14.0-14.10.16-9.el7_91.16.5-10.el7_9.71.16.5-10.el7_9.71.16.5-10.el7_9.75.2-1sssd1.10.0-8.beta24.11.3_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.71.16.5-10.el7_9.7libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3819ff80f7811e597b318ce6ec8c4430ff9de0df, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d29c9b3ff5b1ce536f22b15c514bdd3bb022558e, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER os-tY-pdA"޴>`L%󛋼0nI/.du~L$8Cmw1ao$o):3 Kv UEwO8m9YPbM׻Ğ.k иqUvlR1fʿFtI q nz[&=RȱvO_Yr,աP5$?Z媁WK֧w1|U/ޅ ^w 3pP1 >մBM{_ ]|%?cΓ\?^-VmPcbHȱ&$ 1'p L Hb OlmOڜ pzr1xT>-KGyF2:%*ɷUo*u+8M\W$5H#ltsyB"V a? l"Iƭ"U UR -9`j- q[{=Z^IUbzBʿ_ʴ9^ߧI[{:"Ovh3DE%Ӊ$cok"2̓f̋x%kwx,'"Q,Q^d{tݐ%A6N}bnB$]ZD mK\\NAy-5ȕL;Wue?1ܞx=xtF"T9Ĺn"/_ c]V+bڑ])4UvsmBIyW\mgNY9<QQia(@)TBqc:Qe/Y7Gdls|HeoH b-l7iξ%/4&ef3?V#dy8O1iu7#4q[>X&c0{Hn&Odn~#ebRo%Kֿ>o!wVDoyD WاeQą=lHMӑ@eq= z$3B]D&8Ή59 KŹ ť&3l~*-Z+SՅgp^Kt@ Ha!^tI}h}@GM*[GBGZ&CaǻE󚳄٦8*bWxuXj(6ɱf ,hL-x0 zUh0LJissndeM#XqR3%թY]LËf̻#ǂi14EԱ1Vi/֩Vuޔ~VF/42'ߘF+aXb[x07~q )|fwj$ %S~4Y'Z,WJ !y(ȝ!:D8w[4g+w0-2Zi֑*fH>g]EfN;f/q6rA{&na[ ǕWBJh:!QP!C@JLO:WIHƢ6tjFD"mDpd\] TZE$Dyrg -ϪlRA#Ol?1n 3=t(+BS (XbA}*EC-(Kw2rJs0՘CQ|mar̷]P W$ko<͉5M)m"f4k-ȽΠp@xɸox *Sة" eR+ 42gY_CSRx.4^hQM|ٔԗs6}7Ta4݃|cw$MEKu(4Xʳ5^PD&Zw++F+c+Y9ۻFւ7y  vT*@DIPUVrw G˔izny1KL[T5Z_롋c4 })MN$c ז#[*\(H݈o fB '+1Oڛ|_aF-NkLPb nk$B@R w|jQhnwЭҤ8蚎 R:7 E JUc Ic[Ck'DtÐsNX2fl|Wa.tApE-ESgX@sFM4TX6l/֬v/!#B A% ;Q{_/:pGu_x/sٍբ$&y>EyCI\rEEi@? +i=~|nL}_x)Z>nָO4 ^hkY+1n E+L辵ܤ6}eR:J֌# 8\9`m`U/(# $Xzh):< DB|Ho2ҵ+Bw+@DH7?MȣQP2rf+RO2KQiWH`²3ʡ9T5FAUWBE*LFz$Ui.4\R)XBpOScHЃ1vk[c4]=)jHCwUGB]{ݐPXmj D;}ߦ7/N]{魧p1_orzSoe#ʈ{Mh&J?MPŐ~!jTBCVoӞϘu&/E_d}b!6KL1R`^Pߒ]T.w%Ł!n,E,΄bu^N? r Lhx]PcDSS~kkS =T8V᝞ (!"Rz׹A)y}\Lv˕J)b%:x:ފ1A[n` D7Mi;ESGA+d0k$ǢGSzt4kg"4ݸ)9AXDD_>Ӥ]a8F\رQhFhn~߉Qojxu`QԽ6z^_ F {L[ {XIEQ{Wu?jpS<ll[qlKˆU&!QExu#H\ CFCɬY gd3>qܙ78'BG(,?5~ΔY`0W/ G=+0?JѴ3(`#h[3vOi*">ӿʢ=HC`M,UQIAaخM{lK,U駠x܈-&L%*Ό /a[)G+l+Yg9k t+Lg؆ܕIcVrU0"Yز}~n"ig]xtsDNNO|оx6f۳'->w6eK |+(J'\jq"8 K^ˢYICX1y^'DϯJ⺈>؜l%Y\<`2n{f-Bjw'nvL4APtR6^RےBXg.y.= QL_4j,]o1_+_% 50TᄠvChKENwwi<(=;rPJHxnhU"Y((]]eMJF@K7#xAE>9* uWX6zז#xDNR>4emcG=eɺqŵF7USj1R>$ o^fuhuM7 3߈/ɮ1};*f~#,4 :ًJ#nIv_%bqMT6Y EHVxfY[)fE8h0֢x`Ȃƿ6Kah. ~'o[+5 s9r`$rt硓>sa@HDULn2=a]ѢӲ%:~c8*a: yqvk`ȕ.4ԶRD7\,qR[.5V=aIoJI1@ڳ 7$YJ /zŖb.K ĽJN[ҏ$U)=_U5@s:Vm"v0ݕLiYREA`x=J oڱ?g!o(mrSaiT()QH'I+:g.ɨjlj0FW&|p؉:fݬb%V|,L*B{0X2=Lf X3ƯJk pN99 9~&ͥ #RV3jePz#BndjIx*񅴘TLBch #=X0}//a^Kh8ʑU_UlWl|^3V\IgFBz ܻ4Aqb+PQf&7n#`nsTlIh;Qo&l=f ]sMxXE0a1 ?QQ+o0dIgϜ MdM[=MSr! q<鐧}CHE,PN2^])dIix2xWl>M !q4=:t#M[e!"a<*V/@wHg3_Z2Xe0j0wugkr2?!UP/ 8_ִ,҆v68jˀ.P7eঢ:pUJ-Ain(ꈊCs1 ÑDj"RT}juX%K]s^-\ %1pվ&F2D%lשzlx6φZ [ɲl }s:@4G;,}`ۧ'{Qjz#+8'\*wq(/,lܥt.q̛;"4E1 )%I R\;S[>}o|{턔/x_H0 u%ޑw}@G,"]{еMT L0e#AbciY-b67oo1-g.Vg&L|C}*ǯ)/6IƂ#f#5f_ P*[hua+ۃb0uz_p$hoG"e}{׿p7[XV!cG1^yIhK7V졸v m+X*}IWh@@H(qH$cn2'[vgbgb|a[*&҆(FTGl` 2r/uMIrtlŊx#vv KNّFN&CWA,s1j R@?=q$D %Q1AwWC,U*\'ܪNӰ`8 ~D~t`JξmO@/+g86}URLd9v:36_ʼ;JXKY_пfU}ן2-@<6ԝ[-~Jj+LJB 6b&Up32HJ>Ol%0=LR˩Tf{TW(`G$įV7hxC5 wn5h! ~K,ݰE[ *sqx ,LeC2,<HQo;Q<}LŸ#̰ \{V_1=xvZev}S '狊y|iU\`'SInK_l?.yb ыl&1$Ғow⑗{yѫuY*862?-͖ %"w[=ix1E~?VIH9uGIAk_%+϶Xnڛ WeQqzkgZj<2*3򽫾: xtXf112a_@hN(ADBj @I 8Au=WK8H )Mj-5wL b7{uV#XT=_|*#LIH(}_; PkO5,_0b/NwFxP V@hKŌ㦚ԖvH6ŝHγi*> v0C7[.V)X9[:U5QZI[f­_`dr)|f?fB({U#~A!,=edoKA,VSi1mIp Uv((HVUbch qdj('ϦS>eoscmcqGk 6ʵu?g!6h8ӎsp -O)8(xKAsz,f|#5$IZelLQ)*n)'b״M&/F;$ + 3(Z5Ύ:Ge<w7LNNZt<-sž&AE:1$aa>br,X@ 6IWiqEԢ@ BM&>, 8~!ݰz1#K#:=[S,BHtpNR7Qj?5MUFӋ+K#a?-j^l~Al^w>$jPO"HFuD q'8>0<fc.Ub"sX%}ab>`()M#oV8!cq0Dh4fxq~z=cIu{,J6R"ZN;Oa6v4ri2=:jd +aBL ițgs ̸("8 )L  /|"=x{׋i[ݖ _bYq bN{Zˊ7;pBa?fOx 2mJͩŴ|xJتϋH$ҥD\ٶB(n1niVlWbɡhVщp!U\<;I[mxIl (ȍ G 뀕JU2dK9=ݹZH "rT]ٗHH'%]T7Ւ8.{' 4%(ZwmH3hK?Bx+}chYZs~\vbuM 4n 8yƏ_ؤӅ yKf3!{e5l[*ѓ0:LsV;b%X*pv7Szh9u6tFӁz.hҷM z4b)žydi 㪁‘FGEm1M3_XZ0~})v&/fdğa@|nL^}7ƾY(%۪_,8.<&x:_LRZqE2LKʦ/n1p._V~L"$Si@c%;1UsP|%Lj0_@{V֢$fe\%S&~d$o:WMW΄?9dӢْ\?%,jTCl^ #\zh9&Z..Ƨ³r"%X\+r[^? Z|4XIyigR*xt.e>gc-և%qoNd^I/XD)s⿰yU8u$C%2KvnrW W\lҨ!t뗒߁6Hc8>jw<.v~a"0On'V2{@GժU>F~QoQ2!{ĈKIZEC yE.ci ΃T[8e~E* v{:6]'5gP Y}d؝dp@N!$Wi4ͦ.کD3> Skf]Oe<B/n64f%ogו:RIn,Ec< f?;JlC]NChX ޚ~X$gU2)vw(ϳ;$_ȷ4bd{ euw x+vRuQ}Ӗ\B ] ;?KIutIM| ,m0S8q*7āԁjc3]PhZ㲇~}&a]Hı&qf9fAlѶ09}/H74 K=.5H=CU$vcRBbb8.c;EWM6Q kȻ b 6Nsg -aeiL9/z Uj\~V)Rc Oℵ#nXJ״!7C Oܤ9˜/[ZoB݌>xOoq_2R.X$j[frc;\H@{zC%0kFּn0ZGx kVMh*0`{{QmPa5:26CjᴹEv HX.r`-]U|m^F5!Q3"o)זΥzzIEw׈(6.gTBy0)U˲iPG Sy &lPcәbA)q'ðfm/L1nr[]DzɈAuzFJmk+4}4I seVUuqZP-g\+]uΘ^tlKpr#)[`xpZWMu@R(H"2#QѵPlfTGOk1U`XoB4KUs2Faq }m< nmx@wnB^KWtRpԝ6Ry;{{`Z$'p2#}Ih<9i>K:=Oh7.K8 Q'eqpA0;(]DλS<@_;|"cv@ O|PI)r>:PN j3r!˜=yB{YђiH/-n\왗me& * qe|-Ɠeҙ!QiR$h1YoW9Bi=;`99  2fi0}XdO&ozKF֢ {bi}rI?lw'i')Fw[F%Ƙ4#XgK%x2J?T9=H=h3 gƤxrњi٥횟Ik=fshOXɹWc!סGEk| ]~k*VYntI3]$:Hfٻ-وt)7[?7*5m.k/Ln@Rj M 5!aO?vܶ'H5X=';Q\dJdbJ"MDUJdڭc6KMtgT!I#uMiΚl*A@,wX_C1 ڈiN1JsϚŦ9X vHuDتfsoI&b!g[ p;Zh)H(m4nV’+YxqsI,=t {.tBT<27\%B,(' Bl IŝM xA?;hG;j2t_2J՞=H] Za(UqzM͍$lYl>C *OG"A8Lʵ\|7J /@.-C쑽vͭO,2 *OX,%y̫:gT[!9:K.^183sǵcS&ZOi^! WxrC U5R:izU fwPwP"+ϨBf;LcaٍZqVc+2-d:zG *.bjYIZ?ZP ZIguO[R8 Z3H"gAP2܋};]o rdm{e}lm~ ^;36`Rn 0=SORÓ'ZM'4aL|!΅(s>ռQnwHQ: +a5`)a#H{3%R9T(eCz ᘁ_&~⬨r :Uvab(Ցn̉z Hxn!9jX -pػ3pk[6-xu@.jM|&xD_ \2(,|<Ѫ5|,N)5SBZ>t065!][ڌ$Dk_>xU"']VmUl氽ƇJ_nbt]G f8vx`|h?c.-)MǰUIP;V՟w &a?q"MKj 7q9U0U@leҸ|6yeDHf54I\{ti:9~p9?hϟH ؂V)6z ~)0ZqiUzXFT1_Yٟ?w-XaX.WO= ^{*xJ?Т͸%4C s*'=\G(xG(K1(ZW0)a(vng W1;b.Ym3& z}W:'4BW<`pARmSx, lz^ J + e'A"s1ۧ:CXk*L*a}V&|Fh6n|bU$UɊ hl@ pH6-mT#T·;*,+\QI ,4%&v(738CA=7d ##T044<s^? ɮ;q BK,]čԹrQk㕒\} oBGSẻq(]eb!A;\ZwKOˆY u7R̶=AbZlgStG.hsP$TZjTb qA mwY8-D22[&Snc~Op+7:4(N*TJoXde^i{kBk{޼`lVf/ ",ܱ3,C|LMwN"䐬Y%BnOplڐ S5/O9&3qj H@R*9oNUdՎ[r#^"|!&Dn Q>G<.}Qr|;3xy@_={fd%#R - EU!mai|Rw??44>UdŽ;|ʞ0r3 T\4d1#Tؐ!y]!upmSAАbuz%8qZ/źQ3O.` )oy-t(]4GZi2aQ py%RTUw k^XGd1r [o(O=% yE(%hPVKvޞ1*Bl >WhCH öݔpM)FmmI !0RoϢRΞ5wxM} HHlY$/Lcom!b 37Τ9yfhi){պJM_ i?sDɇ7|ctEBFj82N䘇:~`p=&m̰/!.aE33:ƙҗ1wOL.+KR.*ks r THJIs/Ӗ68YotΉ8%>?oEǤG@2|ݍ2V',vW #o?gsÖCߥ%Xqvx~p<[}'לbcPn7',v?첆ǽ!&/o7PCJp*̑hsJ~a|8׏qVVheGzy0wB\w?} XeGύPL rP7Ff6F9~b[ teI zoq=&m tw5(߶0CN M}%v42! Wx"rڼ 4{nN ?AE6ܹ73CGiIuae?vg-Oa$U3S*N 솓O3`fӇwѨ1$ ڎ.9,UHgwq}~dugF1QrWRc@̭1.ZJ8g C/ Go ]fr1=EgJKi(5ZeRb?_8Wi5^vJ(/sn€>y@4f]A9zْ"ujufp؃KTͤN\i_L,TG''^LNJHŏj֔gUhu Gl'٤ Z ]Lt5'=?];-Tmp4+>}= ^IFa݁I60|es~Q-{%o<wpɰq@+|v!=[- ̳%?9 Y=TblJJ@?E'=}5(KP^rM`X+=(QEvSmf"c[C絒 ~nbf(V;OhFu[x# QR^"H_i$EPOGސ67"7oxF`ꭏwӭ`Ke k~6` $̢=}/C%ԀC@X*jgHۖP(Ĉ)؏8Ԝ0ZLDgQa$H,]~rC#RQx/5YI ,c5Y?rpqB*X I^pd ;VK Ll xDi ;Gv :K0U&kdvF<=(n%NEWA}yxceka-up+Q:n;d9 17;k{d5-!3RHfS)wVQ@d"iԗRNV O@تS1oqv9JQV8~K]nDHj;jdNHpH\!: A_s?t8U&M&$=xxXE"+{=f,lv<̴9N ص98F9z%G;KnOgf&Z57hljA%:;d`NVi[iLc2elr8cz4#3j^O/gR',Q37[=2zbx(& c uN5vNp2Ӎ!O#<@1Ӓ>J.`R:ƅT[}?F]p]0؄)ULRYZ͡&:E{=‰CJ_|&fXw=ߧ,$ϫ ?-ґ7,Hl6q3)k!\!)ܞ8&aޘNʙ~WIǚߛǨLHYo Re(ꘀ+n %tPduE!sLk9㴟O{+P{ж@OOb.d]8w 4( b4߁=q)jO=0Ewb3?mq Ji/=Dx[mˇ Yc!\j)wr/v`ZW]~QY.d h"O4cG nEcM/K Q˳l#{5>G|}ޯB\jq{mxϔ &䇡k)ܣ*&@v).PUd-u\e@n Ux="wX3GO\]E:4=k0@ [ lvd{Z B)14*|&}Q]œfB%ymu(ϴ@pPhju,8sY~J/{0 ګ̷S.l <\LoҔ8(&\X/ ]).tS;KT[i$οE'1ʲE;!+%{g ބu5;0>q@P&Kz5E?CZZ\5w"aI8~<!F.@ﮇzk{> GϘڈK; f!x3em8;zV;pɼK0\4_qz1=YѩoX% L?#p󿂸ĖƚX? !Hm:!M(~+LªM-<~7|6GQވkBV:}JF/ua@GW2U0q~'툥F*֟@<HH\k;M #?+I2+)2YI0N|r#2PT,5Tk -m2{qQƊ<\pFFr8nsY 4v*g##C#vy3|7gk"2F= AuqIJ?Q~ȲT4ίe?'w@&2ZvK!z98Y6;UjLDZX\׮֟9EHoV,-KIѣ=$( IpHqLT8݃seڌ?>#O8M2#G'w:̲5 rHF ζ)1PbV':n&h,1z/BJx(G IϥSR*YkgU!K.z~ߋ)0Œ‘ / "\+'ܢ pUvUpIEϪh\dǡnՔ'_$c3cz9^[z+!U\'~~;i>H?jԃXC6#Ηy,$ۜtp s[C&GNw/@n򞨞5|qծGR6=NMM̭xBR.7ŭ /za Hy1]JW_)X4V7b3jSph@DZl j5t#+IN;Q WYiG MQ^}U\U6!;h[#렰j;8Rbtd/o&h 3*T]XJ>timm8p5N^n>;bPԝٷG {:M:%!28Xi\c!WBc1s{!-|&th0 O-#mC=pwПܧ*j v6dEm A\ Oeͮ!yœrk,e~B460%|5wR: M*v᭬%9z9FXKn9t@ V0l-n"ڤ $,Hn4*<{0PńGݐEb07 0=`x*f>i{^h$1 H4-lʑ]4A; D4)ҽDf60%Hw<@cGMZ'p3/ae@ E7Zͫb &t3ekF}5@#WQ\@g>cSA!rmۜQhpoc) kwhH ]7dϾ~Z1_?慒Y:I/D~K:^F]% ;Y?3ߵpL!Nﶭ(j@H7)Xv([V+Th _:)HfKBKo gF6J8-%o h$(/Gll-+t*"~%mΕ<ҭ M}f<]^~nXV}MlQ]' =B)Sfszɸ x^@U^kvqu~Brwg캃iED|mSN|BȽ) $eNS:y;CghO>k.A?`뇊eX 9O:9fuڪ>fJşB./zL7#jh>1gw=0ԐDEںxi_-5.FD=N'@"zXvej|É*x=ICFws[TqslW!rSp]D|"ݼD]w7 ;Kk~n[dS@o:+7m]ta { \*HˌNLG (> NPi9꽼OF-h(Tޓ!57| 5ZЌ;/ĆT RPP`o[׳J$+qWȐ6<vu[V< W6 .JVY!hCiܔ GpLeaO뎫QNEfҡD$54]AH03]ra&HO|14~T Dru 87Jrrf"M1*!BN 0! , 蔾\C:/'ZQmR*Vwro_v 2ZѨ&{ > k+&ndDUgdYJ\e؀K|`ZrM?W^ NlǨqoΩ\<Ҧs(aVg\ȽR<߃ZS"uٿND:Um5pϻv?cm$ E2Dƪaa`FIL+T)ɌWr/}w%kV݋e<W+''fz#hϻskT$e:$d-/i&tS?e&fuƌڨEud- 4y]X#:soE /i@FbV3ƽE;T|N!CK5E_\whG ;aWEfhJͷbar̢Z/5`Zڝ QY3J[N8$hwLwf`@W!" ;%?q24&^1!ݓ*yc(ɂyd@ca"*ubtg}_GԔY簾7on@sn [䗘 SuPx>( ӖJ1tg }5eٲh 2~>.C+6hq3w!axUjlI{p#B&ml1]Fl]c;^&'kކgMivў(CKMuj,x>&: P麳F~= gߴY5gMSmk/bAmr|{>ٙݙ6 9zEڊD"@x*>{"^ln]ۆa{ɴaNs*y\nGvQb%4฿_(jmf|a.J"a@Gv 1(^_<Ǯ-̒[E쉃{V^Axh' !2 ~gt tom)0t9V䈓x㍯)` TդE5_OT`^R~|VqQRQ -+xrx+A Y`~=?OD0git9.8#q^/A:Rߥ](</9;IWKE Uܹ+eʞ}/gl.>SR4d\ & y(XX!ږu]3^-\$؂{kׅBZB=]m pq ,r8b/S>]#5D'C _FKtZ;ĢXu(HK9ѷjB1OtT5и(.:♡@KO[IKƳLT P3xiXGW5JhvV uN^.|,8QV]ޞ}ck-R*VOꙛP"JE@PixZ]K,yCz@QWBߴ()><>Տ%m9ZsD~q4MåS/B=g7e%dF rZ+ge`1.#u~]@Q(x-9 {yx (DbMNK)i~fGyHbюx{9D5h"ڋ 8HX]7{\̝aZpaJ R<=5qq#oK$#!e^f ]FGde'GvPC}XgKƫ>nn$:۝km\d 0%`{Z{{4x9o\Q8D@@o;}b6٤kr]W#Po n!iT z&#ih"[KPq!3d91QlCٖDt Qiot,dt& O?MƂǝm>5(`-u7A-2GRT%k/X+"W ȁ[jwj:I4PZ) : ˲8`,CF{1[_ar+hv8Ǔ2)ǀ1EU(^$!J>}ΩՍ!c/xh-=)gShh$=Sz Բ4gԾ(R ĩx23Grc ڤ3D]`5r`p}Ko( }Ӧ}P.޽40P3^IJ9WfHq# 'S@SL Q0߃7݇'+`-yüQ*Qaׯ83$&]qRHKdF쮏9 f1723LK٬P69_CXklm(scwE gsNhiOaM^%uIyS_w;xҨUטiXFfּAWI}Q}ix%sؤ )I '8`☞(ψo>Eptn s^Pӫa9 V陏za/n_ #X3 φ2Kj`)ыa=v]ŷw /y,dc7pFԟ|Dsiwz8 B/дb+k79c|8Ԯ?1zB~Rial~wlU;3wpm똸([MaU51WZ! at}yd8s*6(+k/ǿm Ft5'r),(*pS`b5 ҪA>VO J(_9̧9X>쩌ވT_ih/F1L75u_Fa~M+Ԧ ;tJEkHr/F,8< ~A;?Z~+ki * D]fdVnz}\-ֵ]P=#_嘆?+C4ʼnUv׀>n:KZ&:%^EOenBrbIEe2VKx1A,/H΂K!rĤM=t K}ZE MSܻi79l(/؜^5qɳ:#H<^s_*R|d@_?lLT=!Ra[ UFK =o2l&qSMR)i8X!~K5\} %(pYv])N-y`'sK<- =IO# @xvE ;DN~ #O??ô PT#= n~腞v'c4<W%;TI]`/cn[䎴fXV R m&sB wNRDy3Cg4d6{`I(z <8z|,KyTǣYlD'Dk@y5 d=NL:Fp|) ָ8JruR|5R~'dᝊ$CGB=dR'40- B`{|QYDo2hjq%҆wZ M-7[jKK PgOS6nCr%$Hn8nQNK$ =EK뀈9 ׎YMRσOWI+C5ryXϞa!e^\QE!m`{ z=à_l2 K]O^yvlWKs*iDY~_%'hS䡹=tPΥRg8y6cӘ|tngfk᫣֗ RQlkf6k? o]B$7+Vzx|,&J?|7 zARZK 9>FVT 2YFX<2 v@ω)8 ܹ:W961gT. B>:m'[Z倐7ɬZ0uiL= cw<`^sch돛 !̂m>SY=Yxy"s줽Ns3_NC+h ?bķ`'~{ZR V46QT՟j7~s-D#,}1RRK<%bm.>Eܯ}Mj!ƶxetrm,?t]xܑ|\\ݡ 82(u[hTG?Y ֊zG2~#탼C.ҽNQ]U -Y{~ d6NW}\a¿h-T8#J)hn0DK3#A9qS"`=B 8.i W%|F{G??jطko3Zs#70$%5-ZE֐)YLZdU:B5S%,$iG,0 3iػzqGQpq^Gej5eYMOJ F`e$Xn0CF!k)*"Vs6+czTKo7$C,#P@CZ\ťsX7",X|iBݏ{``p1#&-Uj /Yӊ!S#DJu_ Zإ= ox]-_70ahz'Z`Oc РxHQ&f"Dx^hGߤaUw~ |TdTVUR.nQWnĭjg{gGP#oWTQ-Ky)"Ũ8ppR5tP6 1=}N) S ϓALةْj i]82 (q 3{Zk8B $%m_QBJӃ.}lB_Q"@;K{f-k 03cmʓ\MiYZZ^b@Yr"~a= }OY!ǻ#hB>kCl.]͌$Oi~ϊ$МܔE!a׳!/Fmc%Zh[|g[f ֗` HuC0;,gFܵ MO+Gv`υƲ;9aÞbh4w9C@%gu_T:86>r0cW`rטD% &(Pzw˗|sznSi"n9]lQq -ǝ;V&tפ0P9\}w4x]~FVZ&fIEȄEEFmB1 KSxwGc9+j㉮歿@6Ch4]$9K?(E_,@肢Õ|=53Kw öVUR 4 (~+} C^0ݏ( w٢K{Br~&{li'C^ntQ9ȸN73#bx3E4xcjQP1Qo؝n-^\\PYÉV A\酺U5/1Y4Ti=˻oL?ȓ6-lzY^$qUsLֿ#Lr/x$"A%\vlu Ns%K nm?&`ϯձ,2 \[R6(¢@8=mFfCw آRNOʌ_q8P7ca/RdΦ~>O&w4QbUgqz?;:e80Q-6@ՙbHig*ҁadxÒ^ @ K\=άciXYTeDҗ>ԩL!#McFVYJAeBю{ ()_=|7"%)~1=IydPS Zb=x96Ȇ0 !%rh@d(4H] b&-iqKs|)fbu-lP'a.9Ie6+Miy\.sS*%'q3aQɮ{F56'&bN5&wrXDrPMK;5EE|ivۀ:&HA^lopsNl3uEe{aхHbc8J;Ekԧ o竨<[D-܁p2 1r lZNq{qd$L)bdm~gjM22<0ץQBqk| _Hz Nbw`t $iy!@G0=T㜐tHf!e]0OXߚc?fslna(!o`G*Ue+C rwрxF|ɍd7tۓ-Iڵ5im$݉ f> nۣ4A-x& oZ*?HE:\gD@'DG e? 0Q.1cKl.4 )TP%SQ&F?:Rk"S,I7̵:h v.ƇN2W&P};3c3V+$!D5Ph. do #g{v/95d 弧n"PFMmdfO?mҡ]1Qhx.Cv^@؋qRQ`KU\#iN嗩#QٔIH[R53H0$Jw 3qTN@i!B*B/>1U5,)BXhMw{SmJj" /f=g% Zlx`:r[=яck#`Ͳ6nK"r'oTL>#D_਒:Ƚ %W-*Pe6 qlOި7~&Qp?FI8~KH&}ӳ.O?Rs"Ege8d֍h5AF!6"\%Ő+B!XR0ˬ`jAeLesʽ˷=o!FU6 ɡ-ՎT~e~6?חqPAЦICBzwo6?cܡ:>0Z9b1vnKsECx;Hyq[ sl +aZ&)lnW@ه2ˬanVskn1xmx2QekqJܨ6=kUt~naj-Rʶ U[W<ԼP) (+ i_Op?eG@\xþ[.:#8Zq^ʑ1AݤQkW"]9V1 &síY֢4'K˂VtI:ؿ{Ѯp>WAQrG#[%!9t#! /#?u;+)I)^//3', 5L ;B/c܈t!@9pg|#zx&굫B!xSTM<::R1@JO}3R08@ScfF,J`U3EʥF5ZSB~"7=qZ'[>JwEi1wc; *8̶`_4hI-ˑo>`L`W] -Ҟ:T%@7|Ėa~V_[%vpF082Z8סPOߗ|V6P5d2TG[9&~Kv7&!ZYu9.= %il_OO =;]?4L%B/% PXt|>cQrpZfY::ܟ[$i@L{MRpH& :c(,\X %Bx P˘`>iØ;xݿqnD>M(C06)Tʌzb% %JGR;~ w(>ȇ2Wf S$;_Phv [ JĒd>\nc&, ڳgh};*miQuq"}<W$CCH$}k??1)7ȢYh_/圽GTATBmg,qP>-NC:/Ck2~*[7mw -Gncc`k=M PGwEf7rD.-ᜑ q\{aŠ%^ÃEM k֎h/BX=BW6-t B:g.7Bcnw|]ֆ%O(˥aXHKr9S6iꂦIc =;?+3^Uf5m`V|epΠ"{脝!JظȚn t7v] \p96B6t/`?>ix4q0v6rCV-jWd * 9hM4>Ea P҄WɊmRe- "IG q7t 4bFrIX ^6֦a5]׹4_=4t8;0U=s]y|[s0G9~% ?[h#DBc8@dԍ 'qYp_CxI\EױsҔnu*ÿ1MO=?oػ#jr"5R*@0*qGI2Yҕ'MljDMKVe<Tnsw#ʣŤ~ k.IūjJZ77BT-֯9%: 6)$c תղ#Ea,-#/om]\@~ ?Ijm|0|f_`RdKss:+Yw=ܻ-ڤw~Y%on.3XsXA,)S `glEޅ8@>pFdHq1hQ?Va gԟ#Uinߡ] 9*W|}[;Ћ]j!w(6PݍwBv7pROyoZFwS|ky^_N ?#3aoRmDdmV:; JPˠgԣ1VDR'H*/Tw>o &z =rZ@zF.A..0&S'wh^fN3/IF**U=o/rHLJ{wG>NZm<N8UFk9ˠph]g FWnE&9\p_,.H ngc +_SM-> fN9>y8+~'ː~歶*b ,VzRqX0G9kq޺DC%ft Z E:e`+x@YU|mZ1Hx4Le"ܓoB Chj@4w1);"nKc?d䖼ş3?I-O·QSr@З3b[+}DB]$r:MQrl;bdSbP|v5SRnK iJ *oM~* v}4pLJ _,d+GOZ'N{S ^,A!>/ђmU}E8p ޯn<јGOבH yA>c~7,A1 >'htlY;2[@.JJ9?ȭ*g~#K>)M9lû:*qQ̭i 27Vo.DcC]c)&}|G6ʼnW7G4JJ.(0ȐKuW^יYQ᷽ȿW d-)ݶ**.r1?Y.5_mQ5UCTĆ*-.cnuP@T;nبWBMZ6=/C0*[%rwME[Ҥ-|mHim{9,΁8O&&$ȁS l׀&rԱ z+x:ljf=b=& )J07s>Wɴbqn]-LmPӿu_( ,Q냍U-UjDu[y7m7{mIhB>mu*3vkM C:&R>GMrXr^Bה2WPVjHP3v]jH7%-J۫p3G{}+nU]zCiWw6y^UdChPFsےGȢ`{e݁ luѲ囉dү:zJ>7fhWrUpaP]'n.m[Icn+ٞd#jޖ7V+!J0'pTBjbֽْT[ ÑR;=ƋR$B[i SV ٸtڪ晑OX.g|E: Da9wU;*1oe{R2 A|EFkS/SUՄ恬(! 41EAdC壅:8~(@,g5,sBF&z-lA!qJdWYӂ RRa'9rJB@S|û֩N@ cEJ۸\Csnkt#%UFR/޿\p C I|)X&x໚MH$\0:0$wKܛRٯ&)̭%Kp=@ XqiAMH ܿg»x,}  ef՗ex)Ê\ۦOBUJsM4=E2-Q{{< /'B vEL~L^kmƦ'uE Y wF0@٫F0i!\ȷ؏vk%4Sn:SɭC +!PR2+ɓlX< !Yxfly^Mڼ-˄gS2fRvtG7/&0Fp|R.FH!%+N+O#`[O94jܑ*f"h<%S v|MlH^]fu y};*>u f$<ҽrPi}UQC^gEx=>vv`LbKQs{~+Dg=HzЃڀ;&FdڗvmFejT`(VZi+ (VqS_r78\늬8tnNP4َ?q0|͝r,~ 7K`g\_L@?[0\iFԺW>D/Jc4WhH_oAwEXHeMHyBG|ètĩ%ܳ>L bá7J*mpT ]7.\LwŌP?]?"\~t*V!-r33tbKh H L~Nݖ`E tA9-/;WB Xuo8l䙐]7Inct<6Ulm=I`wRsl϶m;AԸ)NԃXDV,FQ*;/d# <$H59 )yӸ!⤦}'iFxYǯd^ޠ@DŽ'L|",d>u.~,aa:\+ZupW{gE^aDJ[:)<ٗl-mY5q'. l`2?f5'ma/_֩u'|7Ű 8Z0/Xj0#{0{]` to?jE^cBd HCIj DtYa"u 4 /CҙNiBa 0O穣 vzY\b7z'Ifv̀a5:3M8ϪXScv{IJ'}ݘuwVy#'@P "迟22ؒ458/|HneP􅻴tز1ߋX ~(l@ $ Gȗ9DžK8{RP[U F0@ZF}D%+rZ&mh jڱoR,^A?̣_02=?[jX@-Uod6wv^>cJ+fb὾.S+Sjy]zytwA5)n{l8B>wOF@rfw;:jZivb7zmD*s\`4YJ[9&sߝYu*=rHwF T(k@vX ">i{j $+Bc"^v.[@7&c2zP:7FwgDLW Bp:O׊D)bSQ`y~}=öJBKşkT!@տEŢ>hԿ;-{>ٿHvzF¶puy$a˜ ?(F {bw`CS-qG~,|nG1'@"\/3s0DdO{d.FT~sUG ZwhnXϊ$}A}n8'(za%{hfb2c j;:M)gN÷lNQ0baEzAabå+_ ~v@Ɇb0xv+p&҈. i S Y}D9?]]jP0"(:>< K|rIH GYaMw =8$4fV0 Ƀ+_#rw 㘿'bӵ/E7kf?= _]t*KcZY\{4/ ˅XΟK7<>Tur>t [likadh[HN_KQgO9 !gwF/4ѐC:1^-Be5qmȞYMvwx|ShTµk~6gVcKMeQ?1@%YڦO*0֢iܨo!T=G^XLhx|s.&NmB_׀a IELGC)+ @X>W [VRgjPcWQt@: _ILBޣ!&.*ĮH+B=YmJ)GC~ 0lӝjL~k9aݲ>}b`&"K@ï\!"jD}i8jJ`~~·.+++m)ٷ@m`>,{I@B! @Z@R q5ӤəFlw3 #L {Lb?SYН1B\g3èt}:/W\50{!9C?cIBQGџV!A3Z.Y(A-`q+YH/,<8L?Z\#~'յ{BeeJݓsQ:jZJ1qR[畿᤯0DpZ+Ӫ>]/88O ]-WM ?-u{ ]]>ハ_R3`|9r [?oSRb_mB[8g{zlߒ@Z_RBzY9l.-VGjR qz3 f'ơXjHY]YL3B_v.K^xh6oz;2Ytg'o2sQ{Q7y_<'R6|(t/+|mxTfGB;s:2 @.{8+k+r慃&PG+䔢mQ5PJB)$sS4U%v B5r>2IKԋ,"j|uW?sQ㸗k鮏F*pZMׇnOq)?*B*-M3mu :;uwXCαWW%'Og$]y'(o~}eƤwI Y$*v5F{iI9d8O*1PȒ[S8ڔwQINnDA0 <>n yuG3uݷ y/6>w o6Ft θ +ZB_yAi\⌔u˶P6LjvP ǘ<cWCWKz͛ }S{Lz2G]$Q/;}/4 HR=?\_it)ٸwMۢ2f,Y.U G6@@2P~a06 j0!0j)V@F8D!|~Ʒ2 n7pCdGgdFz*e#>͏ _|ve&`R>@>m,ݶ|qK%} ԋ'\}y:$~5*K.@r#z,PzGrZoϙq!&ъDcBuK"w* WlꕞV}!h< NUM L+D]< *ءFF(ږo ?X!c٘k$>):-' ! .u=i0JJxln; ʘ6WN.0+za*Sm}wd!?XV=ΘN<1pC[4z,2*u3+Ѧf5zmJӠj"53k5٭I8zkGQTn#ScϕM֮2rz8^*=pEHqn6I7 L|A.$c6V#rA7,Mw\΍=|=Uhfp5%GufoId'eD|\('~@~ i"ఴ_ w/c]žմRx= h`D4ΒƝ(~XǜWZ{NI &>|:%H&:ÖW5<C7#;4UʞP@ dn;v!e?k1oUoH)`g}P D.o }gtIP1Riqntso %EsK"_Q-o̠ Czr'b)Z|>M,GӴU wו$>t\2C M%+#/9St,%Sfռ60GzˌxO3xQzWp!d&=tdvF"꼛@]x\#(AJz#\.M?h "ʳHu^~Fi:|VOwa_^yɺg<&=]"͊:G޴\}}ʳlw";LXKgv/ۨ C8\Y%z~%zbo &^x'&קil%]۶\,r}:UIY!FNswGNA QvπFv#,u|{:Njc X[LujW< "qc;`L$͔KS|YTMmL8&Fa#[)J_PԾ< $Ħ~V¥C~9X*yYəN)eЖX nP`>"En^U Xbȴ$9IZR lڦq~?"[VB|@|D=54ZLD9Z^W%Rٷ\ mBx Y>7_Hʠ r2n{ wM吒s1gb@PnsROK1 B/R'PfI#2ê#d^UĞ4)KuUҿYE< YyBOi T9_>vaX꣊`5T 3`AdGPEQrdl.\tlFlj=cxʢX-Q92) ym wRy,!<'fӘ 3 aHU4=Ĭ-{:a3>snY.4f&CB[a%/N?GA uoQEP+[F\Ͷan, ܉n/+oTJ7%b-W 9j)ZDa\8W4&B] x [ xs,⅕X݂,ldosX^N ru?. :8w S`a+?䎝VC7jb+am W9S_ Ly])PͰ::AO\ ' &zܺ!qM@KLs98Fo&/&ʍ~Sr|Q]8Ā?#i^H+f2IP&tHd"%1}Ѐ/IG y$#q, o쩌hxp]"-_mp\`Vi_ *2:Y%E>@0zp[S4X>r v4`CKdq&(ۆhZOf/otr{ap-ыeyLD%qB!j>|{0}sb߂^ , -/wߊV_vP:房I6>qb/bCOH~_\QPr߂,+KE1d#CA)7#:&Lm)\6ҕFp*5Lک EM#2 {3ԿŹ~y}&v,ER:l%كKgӹ#hsL຤U om&6ܦ?%͉K4 {ە|s蕱TnX-8' :)M駰3W%~9I%yr^\="&fUb/9ۘ5 4kѰf <߾?ӣN3 P["X < ֥z;5,yOQ K#S-i^d+ 7ZsC+v:( ņI[vcE!Kd(H>h`:ThQ!&Tܩu0{@Ū͵YbVc$yCCkzQT-" ;`y_6!S? bM"-h_ ? R0?|%(qZ@ 8ՙ#$Am *Pڪ(\c|NDc_AG _ x\a05IpQNKݚg60(,+Y02+Nb ).:G n C2@909.LB'c?ڇgqvQW;D!ڪ:Gq4"B\q+ӉnΙ O eƳ^OR$r=I";6ܴ&R?کizE/KDRN-۽ҕ9liMiio}Oal/uw*sӁH`dLF͚ꓽ,ǫ,]Xݴf)1  {3Shnm'fP(c*Eǥ7uI'y.@:`?QbG "CgKmSڽjܐyKL7ծǩFdebvW蓠m]|n2L'0nSI#5joO}nBГdumrKh6C)srzg.#Z?Y?'C.xO&!W5 xĞ7g4r-܅ L5uO[grfRDJ!If~RP\?|{5ux'tPk%Y[SӖ [0qB#VF+v5o<{~ܯqŗ#p= ?ū|dDXd7 Ś/9"c3v_ osͽ6ڢCi]}^7GzHĬ/#8"1(wedmhu2 ^$D$FﺫO F 7 dk]J CDpgFହފD4ڍו\KgpL~0ta{jCA\G${{-5boKݍ1ߴj}":9JT9xKsA#nJ9Rf ) E ~:f7<<Ѵmvy t7{E2i -kxQ '$pRw mevWS/d pZ[ʥmhkKvϜmacYDa:}`VR@m{vr7[m1E^᬴>E3˄qЖظຐ 3ZZK*\fRCҰ=[ l kG ҔSIrF H"x +o E!>hbPD2,iFD BUqr% { gs?۸sGX)W6Ԧoµzbrqs HflVb/"Z W9d`Ů;)*bjdnUHۀF4ZK!AceA6 ʛ{mNo9 ڳۺTn.+FZI|OAI9"l>*%B3Q_iAy֐iM;h.{Ax?^wP+?]PKb]"q0wkEC^:UR]%hdJaZkv4gɁԓEvJroVف'OgEӝTD@?nE&fo4yF$02aF2œԚ^A>6F#_Qb}~@ft .P6 NwopZU4s;? h?Jd8Xk;)5HxN _JgSӨ'=̝Ce)on+c!ja 4d~Tv瘰Ҏ8@X-_ŞjeV ,9yV$ǫow4;wU%)gǕ8H b"A&4I J革yė܆6*[h업悡q&B!/Cep_:k:6}uN7rʀapԱЗ40jw':P++<%2NQoU΅U-S(#y~kK_XzW윟CGqbw.ɠTkCZcE`{Bղ.A!r k>\=> E+xn+ݵ i|l;ˣر#_;6s}&I}6 7pjJV5D>B\eA/M6 7NP[aזNJy>cAe,pntZ#CwgΤU::R1N`Yb Cp# s'h/o1F1;`ܮ˯ Prr s#J!L7<"\ c2cT!SxO7;Q[*QK,ny "_ k7w@W' g | *vֽ"صKP|foq٨, ]w`) kߢM? 2WxC[=(p62żGG̐fw)g\seXP|'M'DiI#{x^͍y B6]bj:aas(+e5(BA )pn-rfAϷדlnYUY.fK:TyK m$`ؐkIa~p2η'r9Yr~>C}Å:̜}KG@-L|s61 U6eqv(fPY A 8>s|ic,{w4;5d @8M?c,kckNgOj{nwͼ72ˤ\PP;=r}~#'"Gx'u`fpJ~A挮;zv$R yY w VKK(m,cұL(@Q47Ɲ4M@@>k295^(ja̸ 53n/@ *OUX/|pj=<<}YO+dxvqS1A5kU.zƷ scʳ$`gΗʅ7V©'#@T`ա"߼xUӝW4Tkzw4Mx/Fm1U4-rb w)'j?YKptwT0yؚb?oK[C+OLٖk NR1rjN.P kgu=¹(}$.$9\qfEo|䟓*Sd@ `]fҕCm0k naևArYHA`=ЊEriº[MLS78(]A\ rӍ*k'}LG|LN$ .UE*AShw %Bzt׳3m_Ui绞ё f&|/vk~vrCwL7&-S`gy7m..范w-?ާ=br?c`AZe EeDl<&WV)9c3j,{Z3,-xrZJR^5rM{}Z 1T>[K)Vm7@r, d՘:ډeΏtQVUGԥ0pD9fO{Vfg\MO7A ؠYHRig[mmrɮlzAn˦RF&5.uD[Sz0 싽C * j?l֥]1>9#<&\YM]Ԧz"RbE!&uS~>jR=՛u-[9x=AcTpkEWOfBܖߚCA&=p1 (&Gvv*5b.<ڟ_[i5frGjqEl~[zN` +ZqހM>E2O -:&d-?nC0G| NPEJ#ZY&x a W28D>̷T7PِwsOIG!.*y-)Џ4go dbIWjxf)1{X[3*'H|[?ꫯ̗^y{NnblYZFGz2zz .fB2ם7_R'FGG@zZ+lx#IЖ=Ԧ|/HF֗tY$N$ `r]s(%`'=NF\mvc@5z7ڳY-)5D 8o}+MYqfxivglUn}>&0\?w#7i {G%Eg"q!C!TI"2n 8:vf++6&[c*9gS/w|Xhwņ5@exúP^I+\*$sqpfEí+[P=hU2\f>j{kgmUF0g;J*xltURsbKc)2}U$_vo\]% z149dXӫ{8(tqqoK᤭մKRc*UM$a $}]$hvs&A@[7Z̲'hpS5MPJK#(O)vBPSMR˖b=jnq϶B[Nt$gLLg=, }{,߽iA<p@v16V}Op-9?u$o׌(WP^nSX&(xMuA91xngbX %MHLZU.=7`V v*=kCҕ_bP;ATb\MyOE2Z@c&|0$㍁j{qPj'1\)O9QSPOo~WoI;{v*hDa[: R˂(~:?.0'/SW.lC2>:̽RX{\?Ū`q< X-bov#iJ3󑯳ko,+keO[v=Z¾⥐;֣Ncza-=¤yʹc{.R0/sP7M8(EƒlZ L4Vt |Eo!8 '~@a-HvDKI&HIH' pM_'嫮|W~@[DGk pfh7Sn1k5Hˆ:7gNw_l;mde]6&zW "8/_^>dc, Yo2z=EPkCޓ˔[pV8Zf븼zX-|5"BiZAsb{adͱee& {C'z/؇ξKZz.?7z8Zҥ&4ӧJfdhmQp"vWp){Xw=-&yE3#$~Q>| ! {n FlʞCeIHSe^k頟uyXVk M^, җCC 7 Fۖy-h5t!DŚIkoƥ%%_\O3Af%r3fBr ^yyn>9DaV#osy l7EAT8p&xڹg D}QIv5M3aZTz ]V'V$靁M~_M:\A A-4CGˆW- hێ^ŽǥPe;(hI%%-XբDL(sA7oVURse4*+EN7gǦ$d,Jx-;v˸sE,$$ /̳E1{S%t0Ȣ_>a=&O2"cdv1:+y"P?L`D^nq:g_g7ؿ:(Kpo䛯^%b*]+7I a74U3~*RS}bY])wu桷25S *c>n߀@K}mS%L&" t5 q'\ؤÚ b^kqpna,ECQ=D_C-|Cuu2SJ*#sV@jan!-K[KY{q_z"|j`%Q-heB\i8P6n@˓);G P[fUOd>ykixy޸8Bɨp]+ ~vghN$$B/2~{ u[ԉWL++/P=-[ oyn"J!߼嵇Si/p?Zm|q]jwdz:~ s>bx쵛iDAXK֐_ѡ++ _VSRUԈ .(,? o4y-S˨:3f- ūN"pi-4_fa@H0= NG=ẻPO+L0V_qn/Ód^V 3q2Bs̽N{z;kC35mu0TȏsPW =iLӰBCb~xR ѬtKb {V zGGRAr > -2zrp {"h8hhI"0Kb)XHظ|W:Χ2r_k >P9q Ak;\Ö / Qx{j[CQ&1p؎㜑j77XsWGdT*B_fQKJ':R~`.=Ϲ݀aNNʛPmr5[DI_e K3G/A,OYog~ӉuQ!dBfm.6HLu$ϼ*Pj;p!L|Pf.xxQ=rɈ'8Yb(<;?!\(SݞOE'R-G6C@D ̹S tg6(:VZKUL?\#vn?f4rٖ!$VuT߿0j/L4jqעU=&>1ˈCf٪; j@gS4YtpIhYMMwױR~˔[S|X&bj=ir'l5!CZHjzukqXĄ CVXHJRFN+ϫ /?AZI7$u͏D*у-t_̯m1}5=Xjiājw Ieskr ,5p.n\?1(Sq[Wua1"#Nb{TVmiH1+s2ئ,َG9{KVqhF۫\*߆k {[Ph+L0]1v3^xs. i!K/hdKr3vhLSb %]8*ԑ!Y6s~J@%J{¾p\Y\"Cێs@(aa?* a9e\A5 ]9KҔ߃IՉPf D_VvE;EtĚi-_#$3N=3*3mC}wqCX1]e ükT~sMQst;WyPEw3ߤ?_ӏ%я3eaB?3AgPk =S9qrFDݠOP4++I~A/M>CZ\E6=["blXTr]kUjOE㛥nGY{9Q_'C?g| @DH3 dkqsRxg T,D 4bE#K@^k.^2&$/ !O=¹?zȁSdƃ< ߃u"p#ոo||L8\qJ|jd$ͳ4? #s3=[{*9~]b0R?Ih3@Ìp')(;[E#DZUnCovz :#I$ *ΰ# YdsKѭlO$p-V~!wS跞.cpɬ̰qҮܨ3yŋˣ0!E(`TR{d;Z~= dju~>Vd.4U :M&m,-e9Rv, yVS@>UX(u7cm: ğq[IVr֟[ȆZCÏ#E' nK2$+j̐,Hn<:*/6zX1W1Wwx-8Yd,bXMS٢aXT(%9Җ HS)!+wN$Odˑɿ> i$1E被qDZgoV-X\"<x4rY5ʹAEBCfEo^$9Of Vlڞ*Ed\X½Sg鸜e_|Z甎}EЎUuK]jUui "^|1[ # wA:"%sOTj4*aOE*]809n1+9JVa:6^:O,~@5MRK[% a֯ m*f6] Fʣiw>NuuLR?t%gnBĦ s6^Ь>wdŶ^ْ"sTXi*7g00Pw/q̃m51&\?3o_(gnXTz ,W0acE ^kY&-^*-U8床*l<+GGɒr=G`uKQEa.Iț)Zb)GvtZa/]&!g*ǵߡNw!D]X`H* +p,|fp ?`NM$7Wra=[kuE̷x061`g- Ϫ-x_!&l{Q&y2ГdN 01삼[,TZ؛/qN0טl rPy'2#>qš?q>݇B1zPx( I{l(v6#˽pZH]4ϓ,H-#n<%}sLqIt4jvт EZL^Yk# iG1@7TI6){ԄrÃG?tdYa=/djɣU#bdp~@b23{q R~Q;whլ$7uvBH(~#U}x Oz5P ډ!=Dxip{v@xN]&ꈑ'k;޹?n W$4ⱖ=>M"z_] t *b,(]M~,kWD0ǗgȺpm1NawC;#%XD9k2Dۑt4)pY ](Q>J= $HعC>di/34Oe >tB qA}oq 4bM/s0XĕniEX`D/Tn默EYѲaTeİxCH=!fna g@P z,Ս׉ijl:w:IiT%wZb z\ja?֬'Z>O QVbRy:TjtGwg* ):=e \Z;q|q^\hq. VxTqTp=7ƒJOTJ4gmWq=Y}_,wٮ,ќBh $,<uOZsPӉC: %F䃒09oۚFpf)!HO,}DcY*V_.PViUt,s}x] (}*ىY$!y+ۇnhF=hnˆ3|G`TI.c1l|@8Oފ&':-|#¡ym4䅰 mv4SU܁ Pcz7{C|5G8޶+›oc|p 9U9e3v=ڋv3M}_9q)Ew^|\`QFSUaXFJ89L?9n~Fc|ډԎdeLdurAsΆ[rf+~:V{?wMAđACfq0..I\@rn FJƈv_YHJEnKS\%Sv2ɭgDCIZ*m‡ 8M&mq_fsƋ;->e_8 G-T./mэ&`*28|k u^@}S"DsİMDFA1F.SoʗЭʨEH@P,_au66"%.4UbLO$!Wb8,ꍗLi%ʧTzqO/LJq1OH+ pT`M4.?,[GKxxǽ\B6I<7A0Ok奶*\D¦&^^/M TUM`m#igZJ.+5ª 7X" Pzrtȴ H՞d0m{4ۼk%qYEV̫3[C0Ik?p-@{\7r(Ur*tj@vt V[#6Ws.KlZ㕚+LhN8o Xtk/ItV[]PB`e+R!7ڻӄݘ>]{X6Ƀ >\6.Ⱦ{ňdr Hкg&ll9UpU" `2Ke`hW+8EBFÓw z`xOUo]މbn49է?U(Ii(ƼO$A qgғ+#њuU"s QY!A7]C7zS^IŠ{v_gv^&9TAO`*LjG\޹o{LTIBJ =,϶L ~3a^C6r@{qun(8HEo52eO|1g[ɗHoFw: t2?jUe(o ·Đy|/"_:bFCǫ;&l8Zוb CDLV V#af]g%i,bY4h"&A'Ѣ4.;fp~!B|?.Ψ%c ;l۲;PpL{jx.⾱`&;HT ơrK#s.šXhn{xӢ;eAhb3 )ITX,) PG͗eό AX]7@NU{)z~:2(2CG%jJSL.)іsDS5 'ҪbA-OHL;nYFF4؀&q$it7_r+pnMORFZ#ZZ+x ti~Uĺϐ%o-QU o)y(-엕 ,&lHY]7T(#,K}W"f7&m001QNOshvƄy^[{oYܪ8ֺ/w3~E&;Ԩ亿[R^XeQ0OI4jU^k{{c׈ֶ5)iП}2߲tsJIHk(s״/zGHQ氿0JOB%U@0ދ6g,+ c[tHg'D}H ݁˯2#q:׮wzi:.qZ ro;,VsIZ{#8@S4EUi#]di(HsE!NSjM$nK G$d&B583.b ` _֎ڒ<gݛegj[=k Hɋ6na$: s?CF8qghd,yQ}a1-^f/ ͵Kg<kx;Li(W]X.E^< P=*O㒡n  LCnԃźZR9.spg'z#K `&FXf^|o8̏64!yKsWs(zyI;$`Aኩ!P!ӛO5zETH@TRW1/q>$hCBE,lJn\MX )% 1Ua.+_c ZͶLU]z)fh tt'bǍ="=[|K"JGN! ANѲAS'򗈤@/ 5ʥ J7s`~v(tDK7K=Wt SӎA WJef+"U-frdxe"vawtn]ڑŒv+ ƆN4`>rJAՑ?sz]w`PXӌ?W避x<2*k.ڰ{ec0h 5Eٌ)IAp74`Q {֕ھ*veȥeE֛U+A-F˔pHn||A`lop厕v̜8h;o.J.[%t<8~"#_i0>Ƀ1K&!0.P.|U}pW|!~=CsCIHB|C<"l *Aj!Mxi[} [Оlҵ7 BiNJ& i>z d zLY,04;`CP }EFgſ ̥KGgZy[>Ujc sd'Kobeެ>bo:lY`g6Erf߽Z]7Зэ2ο-pGݻ֠4mqxw ?Bh9+2Z[(*'_ԏ}MtidA0 {o=H@ZosOd<Qx/ KgM*lS%+.eWV:C{*o6!;v;ߙPVh+N=̅sDf0ρQt9_KWPԁ:-}3}EL Ip4>fzTZY_+G 7|`fo= 4^.@,@P"oTde燐ĜlOQbѐ|+iHͦ{c uߗGE1>e\](cvT[p^RƑq$Vi=Ph+l ֓`o͑G3Շ'1L;G+CΧ8r I,7 ҙ2MಝӮHsbFhA^ UbA@Û $snm6A£%*HfxM1kҤK."P9^[*':ץ+TFwَR8=14E-kE>\2VwhM!¹s#ΪxpT[LLrekzm3E:.> p@ mI9Sefe;IqTQUօW2>&aol: 9i)N5 x{@mU9.v jV5 y7j*gqY rmJn>EY:<{2Adz7HR*+}"zkV60jE(BP;DRU$-Kv]vMܴʨ}ŧ賒 Bhi8?m|WR"^o^B]eGqY,Ћ Gobd-/L#.TG*vmߍ-52?3GnPn+&%XuwͫjDhg:Dl"}Q|{3/PAIhijMHIe$v'\ TOɪbT4vE*ԒKͪpd^lM_ yub6O1 2XjHzYTVn?wǥΑ˱I1nEkWQU2\1uG MakI|`^qᰡZS$-+I 9'-1zdOQ,z!҇3rRZ $q^yHޜY9bWE<:޾+pkInJF+ϦgYH7'W@*%X *zg 4ogZv0F*{|Գ-S)Fg*0h4-l;r#.-f#+eёCy03@d8*4JTD\%{"' W>$H%L\},LZΧq ®qeP\>cTo׌KuR2ThXX{- ?ςf,6 $flV|p Z|p1{x=:\M<0_|=gˆXk`pϙB@꾖'`}\^-m"#Ifթs!1 Ў_G4"cOz^63@Z"_vNU%_ /{ >v'[FFyrwIQhP{~cHM|Mvrg$p+ZZ U٪#6 `|λLY`@4 4yPIS4@}Ik? VkI}m51 _O*ŢѰMQo3'SrZA8߽*柈?Y/)S-7ֹ|DORn<#=Z܄\W"]Z, M|ZE =ZaWߠcNGV?^?5ճc!rĪHMa'X5f ne ҺY#jl^,^]aĉlK⥙^0^(V_m\nLAR5e7욡VNtQ{L{? @fn-N GɱrU9)J7 pYxh[]E6^CIYxς55r Nl>r5+y8܇X:ä&\Pi@eߝsdf*iOYٗ<5Q9+RvTPmRVS#KK`:fo! ~KA sa#Ⱥ1Z{SPPWN:L>lg.u \|"P^B=k&匴290zDg&ЀBH|AcԺyʒZO= C=)4z+q#1,5A oD㙃u{< /ˁŤ509\^$_ڌ*eN_{ :SNOS[͌weWoGhl)E)yp0B.JWLצh^0*x![zOK$bsk(iFS>x(DG~.0_Lo*ppz>7|8RniÜ <%Mv27)}ࠣ '#rl?"IDMA{dXp/u/xD`:H n V;6>ބ`GO~!\$uګ֣,imc8m"ŞI`C+5+'uCw" ś?`ڹS1Ml([pn>?Ԯ/r*aNA'++ojY+$v^ZXhgԥH9n2 މe*#$GSX 9o6)`ZM]G^0xc!Y,PL8WI zXw޶r$]VB+ݗcyF{x 7Fͷwz8!]FoțߣO EA{~_7eT8q,ցUTZCVZ1%&r1Ǟ{8w kH+֧=f zMQë$(K'GskE0WcSU#*dfrE㣱_ hݽ%:R >rI*ՂtzmX1 8~ؤ,d0< }Féa3*UsZ/(jvQ2ATt`:NJTJkfզs3{@+i1/6\u"0;X>Sܟ>G;–D"-ԘS- //4ֈ ޣ#q1 U#0?#$~kt3ݔfOVL)^),~| Pk Sc>>(}AU{"[WxiD0JdZ2Cd,ݿWaXHߎyL~< <j;a: 7e^wMY/fUV;'1Z*MQb:p߮YjL hTcl/n밨ijr"A<>-n gV&"@M/Xϧ3>$wW-"w߫VY6-e=p c$atDw@řLNRG.MeE,`'_άb`V-Zop*¥N ]R9MmNj јy3.q-@/0R|'Eg[DeT%4Dt5z q4l[Ma0t(I}_2^~JyVm\WwxilaۥBi#`]9yOwJ2|eHf8Obx{߿6toC B\%zZsÆ\ !5; 58Y+ouV ټ*~ 7`WRۑpJRh- -Fr,-V !a4q䮝}۝Kk[XCwf|9j b?X1v|6vc6ep̦@_3@w=F9-"G<3Up;G.>xGqxv%v- Ўv~d%kPhz~)B6NUAI>W^-f:bPOYU)I ~@C$rr$4YjIu@E!ّHݐ+f;F !e`ؒDŽi&UbqD^Ĩ.M^^ѕhߝ.h`}TV' WD⚺+k.JɭJrdoF;^ƼE'Uwvo1-!鳬R|ev5EO>'Evl8%$tZnM/J;ܳ,?)C]mF2^݅G*pqC].KV*T<=Ue30hGͳQlR_9u!UFݬ!`kMx/A>0UVб(,;h& *܏$F'Bs2ieCb J>8@de.{6Ȼ~V*;W/TJ76:uIfϢs`tC4))W&5ݱyd,I`x6D>^tBTBp$P\>YTLʏp|:V,tԚ?"*/{Y^3Vm7aٻ(3·kA,*Pcu#`2σ] D3ތ6 ~_`_Q,|1|ڨ0H߳Yq)ϧ=ߎKݗA#S f9_𴔇yYzv XkU>V %iӠ!noғ00.LRjM8Kpp/gٳ pHyyʦ~4fΉÄ9#l쪠0QC#`_st54+=cᱛ>qyZ)SE&kO[6f "U7;xs  1MALˉZ,aNP롹>٘7E SWoM?=]q^ $Y]@Fd&%6()&0MpKKY~U.ms7 W TFw>r \QsYpOkaݘc}HݨUhIaBY,\ GV1@nfd 3uy80u҃%1ЕX^4H7P'#90M&]Sx%UP%QS-0>H {C`@NYdFĔ5mB;[lfn8IIu>cQC2F@ԅU{ײЈw΍6V|UN^f˽__93_>>o&> ՃL`rbf{de{4>) g3U"Ԑ:2 d> 듈G9G/W#tgǥ13OpnI7uX2:c͚F2nVB)t ڷIop/R-eڡGƫV+. 23V'i`` Q.Hwpu"=ftpT9Pi648y4F&P e1 -jc`7_IMz7% C$LŌ zsCplܧ,dF 2jeC$ \:#ڒh\Nąi-N،]2 5OdܴH<.ΐ={,[H )dga@tlpeoɹ kNMHF(EĀ8I;·Y,Qh^ɸV_nnë{ h 1Xʠ/:]1P.2C:M,vhU%07(.bV"?1\Ur!01A#hN7IB On2-,tS#pf=@޼]vX6i/. "}N}*cht=Y ЊX4H\ÜSPzځhA*uJHC`3m ٦3al:^D3MBy_H7(3h{ˠOJŊFzbI:m W V@NaF7;Hա%7YBhIĶQP-9|=&Qe@zT?*iu[˵+_cj Q[h@ԂzFmтk:8^LQGЈI5Ɠ&NPW`D>Bą<&.y@Z>|] 43gp/ߛd;lq`Ճ%gRjN _ f$@{/zAnC={? z:P=2^ [*!b+AXdOpWlq+VfX%1QLKpn[XSv RW]+oȸr ِ$Aj46}sbre=X0Ơ004 nocع}N7S窫+yuU/}N:]1h*_:(G̋3q8[໔=[6c@Bj ޕ!ڰ18Vo3A1% OoHN='i WBF-anPUZ\1Y3jq,+YT$ME|P.q0ji,Nn2#2:]+.60y+ּݣ2N2~ jZթL0?#裯onj }"J3sXCkeA\\|,27"Thdx~5z#̘Oʷbi(L}ŃM1][AR7ԗZ(LBn~5?#fo9K0'THכ0ou?*Y^(+d>-u ?[YtniN/x v!Um\cб3 G$F`=0%% ƻCxjkma44T(ǹ4& I`zS 'ئ)F{-GUHqܷ2{""tyhZpǻ@LL|=Z sd|!FuPw k-1ͽ)P`:$Rpu s[ud A/6 g=IVDzH˲nԞG$Jݳ}(w!$m!%qbg $nĄS_Xy:KW}}(Ph7͖[>g;1o"-Ï򋒤b;DO' [HQ5B ɸ"OK0k-N/48_oL&]N_uX܌ngYP~Eoж(aXz9QHT[M #iq) .DaYE6u{[Xtzp ўOp[^NE*2z1ҍs:`u!F䑍s|IW`E+emj GpY~Z*ff;$~6&bJ RV=գD0O/q v4-DMyRi\^ٟ s^VLASbaWWm5$0L=rRy@GD2N?O=ETGTs2 y;V]!QIk.$RPЙ+c6ֻxFXTr<Bn$$`$;"zMQ9eP^ Ϟk#?i:H+%؟HXK+5=$ 'o[S” M=6I{@yc`;rGXk~(,24Ao)޻Dž`?od`Ry\i>e0F\jI+J`2 #ǧٕ)[׭L!栍x}-L&9#4=oJ>7}]85G3le-h \gÂР/9 CH~76RuX`|O7x6~lѷ6sK vh$֛T6818)ڂFI-w,b cN%GE4Xtͥ;00T5=ߌk,T囟0߯g'8 HGsՏEL$ h\s*C/JQWeZ7 3"z~EN..3>QE} (h؁=a"vK\ =8%8l-P4 %Nw+5 R p+(!ZۓZg%Ƃy+c l5NX^̕Jjt|/f2-cP4c-Q7PeB~jcpvr,uFsZ\K-'#)u{?r]G}' ~#1}={s~*ՖWI ;hW!_T36\7QyKel"Ƥp6zF]j{yʓFw\#^Z48s;sK0 x=IyގBHiZwo .t?l:A.r&"<|EX l2u ojUL~W|ƻm\cg <EDHxԉ$%4MEi~'_´C8#PgEH„[;b>`/ǹ+vHMp/̲$dq!2Eixq RZن,m1f`s+2X Gأ_5 w2߈1]%Tj.Azš'F¢g`F苐5`~,6dA Ԋ^<ʻ-JW.wx v}92NM݃i=#~9W4ǡTlO ruV/]Enn(U+ڿD &q [cir';H$cx聃+S.F{A=;n=xdٲʸeI62 /6ہ 8H_5]~L˗Ea7C$3e 2@'˺BK+k0 OQ$4\ 6z>]ي$Kچ}W `үA׾Ot ';TpNUMѕ:7ToQfϏh\$'l+jzٛ.ggMʄ QϧG`N?Þ5~^WYl@bqWi$dΦM^ýmOA:DzYh\>O "N&c>:*fb[l7v+\A鬃/NfQh=JP#wkCۦ~ՌAMLP%Xo\1 ilq7upu%3xϦ]z,8Rc7]in̋ne߬>=lB,h8kRPB!R([g}w0mlNISP5^^Ԉ l}B!gmg)ƴrHC{-w_{MwA'{!z'z}B=ͅ#Bs=RCk"d%7N _e,N9ik3MG%^Tل q٫$ч͎e؝NiXZ.#p2BnYpiSAy?4/,Qdίtz *WMyk*:bj̊'Y<\{0|j.7znkwDč0<ܐ[or{#~oFCoaeY6®hЮ( - uo3ϗDC=idc%vGD3q J9M}ybCexx=H'ہGw?|G$h $6EMr*RNg,ZfBq'~ I9ͼxeJGZF D5](x# ( 2u 4f[ٽ#\9iE7Ax+xՄI/w `B|  5I4*iN<^AsA ~rȖXXHY ~FbecPаU?v(Z׀+~HD& !ʭ0pA3h&:>&/ &gpͳ4l0j"sڂ;ԂQ@O]a )~BWW[8f|d406bJ߳;2HA4 LL><~xI@D=.P3AJo"*, )xnTJnnA>WYYzD5!5ҍ7'gn6 j|_~kSu:Tfsś@,QF aeiMopL?PI(:.ES@,b:Tg6W+06BOq_OD$K,/oO,MB&JMd0bM7!Ie1 F荎:Ɔ-,[A4 9x牆 $ y=jFOyb܀Ogd2^Kg6[U^}egЈc +')Y4[|.lZ?'8P)BBt5_k!gnFfFG-bROўiA'_.;(SߝE}}c|,3ۤd7yc<xȝ.D%g A&+Ɉif# ' udYXovI|Qف{آŗ06b|8阀ɃN ,!uEt,C_Vm;N$;y0C#T ڎ6̲eA9ؖ%k"J+\RoR.d k# ZT"C!E$H3:qEò񕻔- O ]ąƫLdc'/?`~TN%k# +J+bY)i6!S^I:*!Z9g?E[+?p^[2k7.rr+t3o2?%TbaA M"3 7H9t$v>Oa?q&Ld6^14;=T6!3cE6).>F&XD{r#7oΝa[2#Ohnѽqe]ǜ5y9Or*n Eʵaz{Um(?s4Ɨb^!nHv͎ĸIj`JP-[bSqQd9 D?KhӁ]_`.1=`;R y.~SWD6~ &q c<j@ ^DQ*?>%{[t?}7ʻ2uu^.Hfܠdx}4 ;>Նɬp^bUi0A5$B4s /dVufm=Fw[Lz~4U(GɃ?G8W>qAMmg 68{kB59cˡs11-U2.%.cБaU;%D;XVX ݠ |:nR!</Dk!:fŗ鐚HI@bpжݷkVIlba 2\KB[TsəSZc}oa|63)H,QHG^w"@^o "3V$b.)R.碾9CQw77L[e(le)p_"Ph@*YvFW QC։mpP( sDzI?+̲88os{_D(U 5EDFQ,Mc.D{ohAEl(NWv#7l^j_yC?|5NhD # Cc iMWuk~uLRtI91gEҘ@ӕ)\7htX府*楢y:E4&g-)1 !`">k@,%(+ug=5avJp dJԵK)r4/ ڰ P\+q+ ^oC?qI)G$aY`VQ~TiJ~huEwDk*dɴE*.oP38r\P~.; @[ {O:!VeTw4 Td-& {&H8_xvwK6oc0H,ӽ%1djYGWܪa!AAaApbYRAȭC>46vk{t"^$'`tRH#d twF@, \uCsTp~M&1+Uw$`eey>&-"+d=vĵ#P('0SFW/S8p+#$,Џd_:p(!S R nh ߫9 ?+<,kS Gu`x sםS/nNq-P~p.KgkV׉#se%-\] D3=Ź!*uc񹣋/*Xa'JOVo((y6G!½Q +iƲa-zoisڛ;pq5;WfKx1zYPG2_@,k#1>K_E\D.a-WL=y%nF+%Ŋojm8P|Dp~^zH\jh[pl٩on#Xڷe3V ߙ}vY@? [^[قT Vy;xr龜b^ycR?!rhg$CK QA5gPOhտ@FK2oW3g{CģE5veW{ۥL3i\~;ΆVauiY U|t60V;?qO#g=߲Fcm34o#>Rb>Q|®#qޝ6)ͿpOِCYzT[A 7sXzS2j9БV j'Ga!I9eO7Rr2ƛL adY4'Z6 bhZT5,c(P7_NĆfm.dD>ޕZJs9 ?^){Ul]z$H~An珞B!`P.ŠjIo2lJUF $&DpMec,hATcK oCc!o l|$`Y]|5DI|VoWe"d;|bapgG.>6p9 󗞤 'azV덑~]P ̛Mu=:mᾚ5rL&͙zPNYSVK&Q7\ Nߕ'DLZ8!.xq ~,Pr64xq9Tl!*~Op1O(hG됫2ThXJ*s:P IM3:&*~#;%-b/'$~%P/.sp}'<)<5[Z[ :1#Р.ϿCƪݠ?XE?!75# f am͖~:t0!I 4ҐћA8&8q zNJo}o;kN7 ;O^XEeNjzPԤW坋ӷdͻ).lS52*2gD/*꯵ĕ׾uяbD%,?]7HR.!i֝x_Ej5@6S@mvL2Zp27?\`5w,ѧ|C`iCDIC֘]Ichߧu;C$C#OgȓF$Nd~3 3Uez7% @Y̫Z)0r V42uR^X! Zis<79XGT6斦$ tȢ# 錀ukcg=]N5u ݳl)FZ'hb &U2LO$Krm $m7J-sA+ f@+bPPED~PPw$+ܜZi`҈.oJTq`{ [󈡯tJ}P~7gMKgr7$Z !~VsPVtc/a#ݬUS']: ˏS`BhvhZS] ev?JrzU8ZϜn%;ϠEMmkѡX9NO;6[s$ŸÒvx̋Yb}\lì+X$y˷VAqHeФ=hSliC1ˍc 0vP)dP(ްZ㱿p87KlI\`dKF->oWuH$ӗqTDށq{yGp ËfF'Fx 7ckCa᚛v3Z2􄪤`b?P)?Ss4:hE{|{AP#Іli ȏbߐ*u/6 '.Xp^BIAԒL3^0q^klV>p蠞\ ֦}y"A퀭pUK;Cc?ID+y~[9gT5/Јڸc۫xp r?c*t_+}ko:-y+7ÈQo芋AX+! iZ=JJqS\/KO*H͋UjM~IH'V y3.!3Vf]<ꏲ?_7ß;wX݌<7*Dp,\Nixbmc%4:_4-| 'q.e>uC/~2H:[X'J>YN1D/ ;qs[/OuXXyG/,µ} q՚y 15]ddϋUbW0BږØClpRT`.F;V,diI%ӌmHW'ۣfQJ-/$A\bD{nağ"S|JxMܱ+l[kъXLOɚIWo)썪<$Hll>Jip޼2\nIs~ Nu0%'eFaFjB:lf5O&Scx$EPjO^9,n=rWXۜ@P(W+[x,dz<ȡO8;)ɐo'T̃AMRA_ΨA* LC@Faݶ情A:FyH<@'S#yY#_2٪$>o=AaLFZ+`5lk5KD_\2-~&bmVM^MM83f\|iCJz`5D OaI]+To @$H*( U]RVv,hr8:hqNY8Tr~囸R }<@E/RI#b0gQo܋R iJ/:lT,- #_=YrqV?] Ѵ;6{oA7`?N*z4yzjsȾc;U+eDžކ A~ԒH34HzZʿtɺvؙ%Ab}Gj }@)YU5Wo~ZFK>xeznMɝpѿdɯ]ҳ{Q7s*"[i$OVP4?_{ l4yؐB]6xL 0z3-:ex "t|Q qoYUM||>8#Eq*"B[EłQu `0;|M XK 2:Nmx"~]#4%W*1>vhQO P ZufA5;! *PKT~gV&g|JX0[M3[LH~2,LzƱI=±\sG 5 /&'-i 9.AW^t P =h #N׎k]i{'תȆD֧~*Hs˥ z)yܑɰl'rN)kIucXgJ'*9!}p cwU!Tn>y^3}|Mȯ,l#>X .r̜U9J4sh:=yRn׳DLbQPs!f sGav+cs>WI4)e8'0=W&-xsm8dP lӣ8H0dpPxL"DJ'(1\PQ.ƣyV`XIȘtvf~MR't mwa©65fZ&d"Ĭry~,Ÿw2I8D$E| { GZ=Cg",C>^Ѩp0izz\B]ƐGIM4 H)8OJu`Di PX «UK}'z&&u\@^ ዶv, nPc/)y[9AI헁[.=95V\=YT|W NHEU8s]#P5b?%vFkpIfXd@O7|)̍U-Y4,g_iw6 Q^$5)e"ţ2iA/rz )UTd GnHYV~˿b6]"?Gd^W0fF6H! ơOGn ``12} Gezmh^sme cE”J?UL<ЙXO0djM,dF@t?]sR5æؕ$QIl1o 1bpY}Qع|tz<·Mx Stf]9n#zvbjwbTɦpL&y{BYv j7#jWhqYu?d}*1MjcpL 3D滹4#3GJ!lÐF`E .pOVJ>yVj!㨣0g}T;[ɔFy3Xϥw?f[(LQh~r7`2=s1cVfXsxߥhxؾe-, F :yK搯U[tgcUGbћQYs^(@?LPPOcY+@hyH͹ L гM6LXM@m mhS[xDRqGWlG'~8 b4E>[emY9Dk*C\:?Cl}SIm0o/#gxP)a\#‰иɁ^\?U8QnH'KR-b# z<ϚVƹHٱlF+]3aqWͧp;,m-! tYԄXAX87jkFuąoF&wXﵳ;|T6io{vq L* Љ)q⨜{R1?.3a6PK*Dx~_ؽ̽M` 2B k#lDۏʝ_@v?ȋ\V, vp YMv煇o`QgF*^[tɱʽh͒>诚Vt&.K"ܜ2'샳d+DRgM\eIRJ6kfvF4.xI\cW3tWxߊhoZ4S|7k1oא=O\ߚ˘b8BKV׶C +i1:/{mf<: ]&n9@B#{´.RfJADOxNآ}|1 5vV)0D@Yq3R7:B%Է]vvƃ l[]W޺STbR8 [͊lO8U2z#yAy@su8<\r@Ci[J䊮jb 7c`=H~5x|R~]A:bNwbņh[Z(R|,zR̩g"ջ\’k?9mAu:7߻x ٍi3> R5=*sbv٘GD`r]>Z!% em"sw #Oxd{5}Z>+GFc5fo;kaEKlvTW !fm~mY3dWwh +Ubkl!!j7Jpl}"dd8W)߰ĶN1X`ՁUNF9iC:cR&RWh6W!Ғ_+WjbKb}Q^s ^9j ]\dz/Os҉Qghrto2, B %𹼩%c_].nsN^A&o.>$j,KQ\{1Hf]X`%#uog3a5hMz1BV  &W;IρֽP5'Uwo3P_%%Y_˧8p{Xsx˥|uO579,\.yQ+ $]:z,<6v[j:ՎFAA0䝒=JWK΍\ia!M̾ۜy롓7 2Q[&gv›b-ts#&X̼[r־./o~w7_-FD"dOQɇ?7 G?X(1xYa.0FS-8]qN)x@7`-Mo=ڌdDK2ݐyYɷPTў=`s SФq6z;MQvԄC~@|%8'{<2}Zd0?\}M=a9D\IǍ&L8<6t>ҥThڶٍffCluTbx@3kUEloVd#ɚ^~1и|#(bP1 ߥRbkN 5b3Yn`˜׍iTWS#06u5[ShTf}#țD6L%^7~|O#D™g}f0WмڴhΧ}#5.}I`*' :|h#/A)M&)*> x6p&M*h$Z5QW6(]5]\%O[+{,FuaдiXi:b ݍUQ] 4/ e4-Q}ϝCܯ_=MCuC1H>ˆJw .X3N3Q(BBCCHЯ5br.^-VcSDVmn•<[ЀALm7lqG#q<"?6|S(6ajF9O=ˌ.&A3q+9-L@k`|/ lj*lXJv*A=4<(o՟a.Kɋݠffџ kSh&TG'CSH#!t~hUV/ "($u4'\؃fpYsCRˊI.~(L']ηemj&$,֣Oy#uU,UFU~e(7WNHx7㽦I$ J@GgUҴJ0pUZqw^?; JP!ݚ7b7(Aqh!\ ʇ_LnR? tW$IvJi&PAu8a[LV*!uόddZ7`(&]`rL}U7d<z|c00XNk4E`- [F3 %&&Y9; B_Ů#ak LcO0legLw lʒeǟx@\`K7p~ml!"l5N=GEa5?#B!JShzCTBvV1Kpv&TWih< }p   >Ûj8izz# (ŗHsGsQ@70Jȁp;8k~=cnd%/VouPJwnY,- j]7vʀs7%@ǫiyW] DIX@9B(`Ȱr0nLTMM4r.!L%m>*,{ܖ(̶0r&SgJu?J8) &o<ӂLٍO8v7E<j(L ( Yvj(q!zff ix6yK԰@2pԊgX(>ncPwvjh i]stg2, \Z#VŴm#VLM[J&tl~T 1!yAťm0) MOLL%un3j8:@tet[ԀKh! "EU Ѹ\QDǡ;䝙;*^BNxߦjθֶi)Sr7 kn`AO")%K $4`)l$3ow_M(VgKdx^ILSߡwU: X$6n1ٕPV/Lj)% =P<WCsZoi@(P(}&L"La\֒@S$FI碚hIx(T$&A E_-HP,4Qg^vt|$H %o_Ct.ɈT6[`n)[)L +#4MG&J*ՁϽB[fwi9 yhyc;??;q4),m3]zp`N'9ħ@+X\ҋq9Nݝp\: ݽw(Bwqc$KzMRAv`Kx5`q{[15\uxՌ1Y#}r.!蹄 ¹\'Áɍ3rWB[]zӗtOG2WA;9EdBu\:N7G%8Y]ܫlp_fd;df!|X15;> N8 6>D] =G@:0GK1Uv@uNKc]1(ssccj@R 9Z|!j’NA @0x(f۝l"%'t-'d;R О{n,Ԅ+ڧk{;UsÂ{|o!xc.?M7huh˺:-\Hb75Iۭ8OPaThVtEZ;7w_f5b (|1Ǫ\oƬR[{h*cvwOgL VVm!$< T2/YygRiV);[CXM~`$Wup}\؉,6"l|U&*l`z\$~}GI{ ,V!-[w\cz+4kZ3V*x016SOu '㕇YѪt#p߸2`DK e4Hâj`:YBPi%*bV,qǃ܎\36gM1|7G^DϪAZpaϚx1uD8d g:cR^߀HK@6}sB2*"R&'$'JjCr O;4`XWho"W^vw\_ԩ[a*(Ms2EARq ݷs,q!,D\0zb_CGFT 5m(Ym dע wPt;P,pIH.:v0q&0SA8)yywD($E Pz_.+#~4g>\){!9e5R鬎s!cZ9+Xkf ORc5@):*AB CC ␚cMH{%WY뱜 q>y d"hLXNY*NGa23Y2|ELR,=rAnIZT!Nr458@U\P{Dj8H!{{ib:~ \mQEtEk+,pCZ'MX)B. a씆q!cdEX3o["?{{6͸/Yk'g_1GyeITMnaӎƥPJq"'ίǡw> 8D˛8\NN'{NCa| 4Σpal#uIV =|(i|]*_O 'c0=R. Ԭ<@p7c._ٛx;3%Z0[)R ]ٽ][)k?, |En@2 paY}d [/kmPdxӋ7G֯lhDa41u7-?q%zN2#7Gqmzny^KoZG\4%WD %WH3"bg,Y PSyN2ўktmd@UI1LvWق,ڮޒAlz2Piݏ l{|(4@+BYBAQ4IZ]Ry4EAۯlB#!xGA&sfծ3U*8*u4 OLKK 74}'3+ImŠzJoS1ԂpdMJvS0e2Wo$-ѷVު{}t"S2^]d@? Ys=B_+g'Eq\m)SıfAgW@H0hv]i&N=Ir8)Kz(#: &X:,a[N6Cs=9I;xl %ĂRß&.W!@N 8XFSqX }9Ÿݕd4ӱ(~+nZOqU7.dpLV K`T*Kbs}ʿq0~ūE$ y2 o9g(U De `ʤπqLt`42;(E `9fƈȠ L%e"bKއ^] 𢮿hnF{7;l_L4oQiFLv mpMn6(^#r{եWtGI-V]ad zy;G{ 8?l7fܛwWx;PrP[:.8] 0c?9ҮʃC3)L`I7SDs&k ʣ~캫rԲ>hYpz Hsx[u0u…LOϸ \J2M'Tn̺Eyri]OWxMξejv2`w0.hXMt.uCWNIJJ%.j$#Aukh-~{m ˔G*P NoTW$CތWKVE,@ U&/mup8kOq*rbk^UfrZLƉ!ux~<(;n|M.M,;wGfP.K ḳ#eY 9EGZ<#ܚXh>責VVG]U T 6%XF]h㙖(5l/ {}yR/?_O=WWrw&)\r UQ05v=@k_wfι{ A$5(`\6l[.W܇B؛/_ Cm̽l)yQ C #~zLÉE2wj\2W,y hKb Rz>]Tbp/7!(iʢi;}hVavS)~a*2pA|"+V96 Zĸtj_tZQHeZ9_ٴ2!랏e|֯%H<}S&N\+LL$%7”L8-'N>l(lv@Fu?G+o32_@B4I$%酫B20`u]=0*+~k%a/i KV/2EqhjⰐu_{˦{߈YcV&Q<(wH? \'@ٗ'_9Zwa@gdY~36w5xnO@] ωuh/T/ ?3l9'"<.oSh8Fl|UryCk[\{%_h{BԠF[2D#LO!̉,BF0bD︘R )uK#:AJ@I&올.yc{z`^19@( +0-Iej4hLu!J-1Iojt/%:ՕE|R Ŵ40^b.ذ̣ V6 PԠf4 7kJAsnwI ;^|vo筑ay1 3x8l *2ϕ7>=Rxc*bw{}8̆ BGiu>Pȭ?b2:^,|fFo{V*̮ HK <`\|` t 'WVڬ\^A^dr$@e:+y טּ,c>&ek"OI`hO1yNFž`䱬@%A!C{$*I#UXCb(J0i~yn"atJt0; Q;f~~/-X%LP7i+^عOۑ?Wɫ@^Q p%I%e_z7:vG]K.Ib#bi*}a یȜL& v摮tDJtET`לSQrb%4ׄf?kW׸ X}-%ʨ˕36[>v? D/Ďs<" ml3QJ[Ԉg>͞j_Uܺ%hGYku|+iE$g}Yuc l>lF8t]t>wN%{w}C̄):H`;Y3uJv6t°cyt'!QY,`kW)EIp+bW ^ڬ!hx) &7\~~4?7w93UoK~Kqi$mHJo ޮx@_юxm[rE\$ (}"j }D+ yU?ݜ"`!Z};G&H-MWG!rF$ Z]H{ĺstBn6n2Q? {LSc 1# /3Or?!tar(LX7 JO/&?e%l27Ŀ`! DA^"jiсfOnq2]X:%_Ѫp@քQ+$o vVkr#Ș6gZUUΜ(ؤȧluDD(֫ Tu@#p%bJo3ZFuLKl},=mӏ(驥ZK|f;Eare:}s$DK9?3=P"pO;1o;87b鈒R Hkp'#[I'oZTۿW<>fvin7*ɑ5ۘѲjY&|Pъk$0v@'}0hYUmz`bed+R8YXifS*]'4fwH+ri3wh6"k6jQHHvڜ!?sT^he~2ۖ)tϠNR\sim3jԥE>c)rVғ0 A&b@q Ǘt\b7YЩ,uM E±NPmROv&8e|YŚCS튒Z<)^<&Np7v?dױbf\=?^n]adӑ߫֗:tx^[!eG(VGQM=Ĺ=29 'G<t@Wcĸ<f9y]V="Il`0qJM)<X ՟ek%zF>y?$G LГ^ ;DHR팲rrр|d:{U+K'w\"ڻ-.uMH(QpYyg?dSwϯ)d߭Ӆ`mic҃g)B{>l<ͼrdx*K-d> 9G~1G_n7sF}cp R3[ z~W5M!Վ2CCS 3NV:l7RuԜ}I\2ܙf0[./2j>Cv M unp/E08h|IZ,$Eѧ2ջ:tM9[%#R"?;/H3=5  fp__~vѳ<)r8jXbjڂkX<쏁 @9vIp38S0)ͯ< V^)~ jމB:GvQO{.?vx]I%aW* Q|7k6H 7D  9VE>}ؤʾRA8l!jK,h+}?l;~1[Mx!XnlseVXvu8aeaLB- rJ hy wq ~̩*dF]~Ǭ4dj9(P 7 ȷ@DQC'=#D8oLT"RN_CN8ejcHq,ĕl,<6"1CT ,1(EWj":5pb׸V)^~!{uNUyim=Nnrm05\7Ѱ:{!=3z:״?$>0!&*bBt0?mZDP̨\׹CLX,Q7QlBMyXV9@GcamxZ9'U,JH #FBڅDKgLp_3!}>]Ĉo>[Q}pD܆0(Iu K =4IWxRqd.*Bis}AIFL~6[{%hu6-О%dNKFnPl?S)::/WR~B b8w^A 6 s4V.T]~E0)7 $v9]3 מz8\ OD H0|`yނ]XҐ2FI腿ls NzeD#AC p*i~3&?U'-w=wLWۋkG('aՁLIsR2B[~B;3Oq̤+>-dܟr"TgrYEJE2fpfxs~8i[R\⻖ 2@&HԵf¿t%u=s[#܍YgUvLئtoPwZl% rx C h:|E;B☘ `,- gSDC. 4mnErKGKRjtL=K➐`^y` MwLu@! /0hty6Bj\rG?Q ;p%Mxg' |t;moSe:BV/-e -rOK;!j?.J[K7LGOSV#mer&15oPЉ>z\Q7bb>nW=%R\i<bX쎿YT;^'Nȶ;-]IQ"'֥+ޏ |EMX{0xG'ag/n z^y=R' +!eT>gY qK6si)٫Uג1;~Gܗ5\۸TWE! Oƽ-1bح6r\i7_֡guz$b}#ǁk5KHO%Ĥ'!ҡjft{xPs!'zg4Ax0x@mC5$f5u*9s:5J 0q :sc_9FwIA+l&?HsոN^PfJ~%VWG0W|.Bq g: hWXp|3h.LXχsPVN+ w 1IKSۏ+#kl{LqL]fzw1G(ah++a2Җc_{C_$m8FK'?;C}bǾȪy~>7L*Ry>?G2yl 6;SF]oM8W3q#+&Pi7,sU$tm*O5';β0W½gV1-}Wx$r{=#h\ d R1(] Y)w{u]KUPkZMUs0"uG8L$2 />9Zd*H\R1ᦩ̀G?C㓘~עJ0?-d(RgCfe̘|ZoF_F1YŃ"MִփÀ!;8"9zNȾ 2A'"K[Fwx%̂x_)-[Ϡ k\Hxby%bX)˦ *ͿsK+.{@$Lbkſ'n+Yso+\taK)2(\Ph1ϊh~}vr8-^9V\ vdV=Ƞ6> WdYc zb~oD>(=YpIG,AUy'A8I6pl 9^ nI$.q(2B%{qX{s yB &~eq-QRl"6AUPdX\rFԽҜu4Z4U ek @zxf:ɩ;CӇ'q"=@i-7捣s GJ5zr؂4`jf}ap0t(9 h7OH "5jkrƤfl 28-!H( `#Ǝm(KQՄݲ OaLwt1 "ݏz*ѷ M^ ўTz,m xҎt>JpHL),5bSVs)a6qi)i /DD.XH@u0OB evyh1b?iJТ9/UaԣL-.eBvaiU& w>H6aYҊ/o c#?9ڮb!`~Z{ J܃:C"S)=})r}$֋+;2EKWV Vyrn[d /~Qx̿ɩk&yOJ.S|%vwizY4- 69إ\*ItJ0Bl,.۲l{:=m~/2&bpbuĒYa9lH`'\ܷ3lCUvQYUiG_~RT~ T]W X9 kz\DZ@dSeźz#x ܙUmVH- rFo1Lϧ V{d*2xj"M[f(Z4{9kGr0ѷ@58Qn\iԄ\\y$2Hs M0,^yRY$)ZްDE"m:|Urz~,[VUQC$ԨGK^ dgؕ>]t{M*X I¨,ߏg:$LAnb\ѽv.mC`'*ÇƝ W$@ ꡂZ`Z jhR~kew֣.)w(Y!GDb}U΂*60#!!2efV`&~P N>d@akiE/ȷhn5Yvw]͍؆\bXβ<r8t_fWy\=h7A1_@q&Kce: w^ӡAO'Ȝ)̨ӌSS bҜ.)VC33exa٥T&y.M+ib^/>,e:k ([ k7(~=?>(ZJ%1!Q{;`Al\' q5WR2߳Je?{鮬oG u݌2Bv{I 0;LZ_wm%j(O~dL .S{SHW{?E Q>$VxN 2*Ϫk 5r^ZB؋(ZDո޼0?M_| 8ij3=:rl-ܕtn@cՆr G[1Yhy|{-liyT#o \$=8^w'ɋjWxЈR ]UovX &"ĚF,BitzRr33Po jvfV'1.0|iC0/+Lg^-ʐj.{๢Z/8lLi#5sH~& آ}j)nZP8<8c*DM=[q1ś4p{KB;L{L] [z^> ̞9[ ΋2/`Z#}H=UrR(Fh˾ k_m8۠ aÞy]%tm"(yʼn$[s^?jSpQOԀ9ȕr@~K) Mg[;4ؤ7:zydyCL$@JT:ކ*qPa$FFjcZ`ZM\PL8'U ]=ӊ>?7j$&4-iH%z o AɗNbZ;I!7!biqIq6PbC;3t}:*;iEl8~?udQyf9ޔy>EXWkG[3THJ k;`c/еE8#= -=`3N-/ MٝXhr'7|7(};ORͳz8NY0 '8W;QGF_ mi*l,+, V`ʕa$͘Պ|1 hw%SK əVJ0πAɔeKRa6')jT?j;-~'洨ؽ')9[jUq#&:AO$ l3`䭩 OBдOA]w#/gژ.`aC ĴlVyiR[O5Yx>;wĭ>7A `DIL!R?204SfD/[p3R%iÌҡC^bbOZcO7 9uUUM,X5ی$y ~kǟ@)uԼ#3;g+FۛCywYEftL/&FҨض#JPrR«L.8TYh摒3Lʗ6}H9[5݀5}AH&R,{]$1O܌FM{}!b `2hX7^ݭ-BSr%9PD[ QKep)/cpSsfz{zB,vc6*Jޔ2wRH ?ThУou{߭iիC:!ݹ~@VTomzM(eb[|_HFEg I3c"D# V̕DT(3ugW#H)&K/x\=ݾvev/d"@~uG$DOM-6KZ`@&—eE?85R~ANe%rIN\@lʧ˶O (F&$R)M$V?1YRʾhv!u= 4?1Z`ېR*"esIy2wUdC eB\dr F¿!Ԣ 8|xeԛ Y)P) 6!TRzx›5X"B-8/3TEr~s4ŋ% [s8ک8ȮyR:Ϯ&ٶaZʳ0֫FmXuFq& .5&mZ[fnd" DZgCǦӠ Gص7QîYhK"[坑K ț! qb==F]dt>kx㙈: qv yvGpnsA)hCS0lh@̧*sA sG* m xHȒjLM9j;->}*B9O(cstAw60ñ_*Y>"k;j0 DjYʎnS]]$2jZF^͋x+T^Fa$au  1cxucFd$x7ڑ -) =}ѫ:_D'qDž1y g|G gIۻgyp͊i o+iF`;SLK&B Bݘ>hDi=g} ) o9:b(bcgs+EEb,7;Y /yNWZ䛉yT7!@ (x& hP:|sSWr;94Ȍ [#R{ga"JZ3mf ʚĵ_6P '*MwWۊ_1|s1?s?;jXbvN5j=',Ba_M˲ /ȻM9A=j#OޗI.Y> 3'LiLnY/\3ob* 1& SEQwէ0,kùSL8I1,s}%d'C*5"0S . VyljBt1fdҲ({!DХ< Vnb~!#VPp7Ol/{ B0SDzBs[]p3 YHj*$w栒YKdr-}lCtuP76 $j}^͎2mlZEi$%F.7j&Z}NLHH&Դ餭7%1ßŔt(&e:Ap 0~%iÅYB"DU4|z9#tP%&5 V9aSr$R%z:a @X33=K R7V$.&`\a)Xl2zK`MK`*Vkٛe#voD+>3eџ=2c|CTR>8/AWpGe"x|m`M W¸ѧm>lbuWR}4$7]w<)|ΝlU都p8$S.Msಓ9&8[T3>"`$5 G2J\8o̬SiTimġ'9<&bۧn!]fI);KRZ&ZfmՃˀ-u{4Z7#YpЁ1}UYm2!Jr63OG.c4_m[>6d&X Na/B{]YZ+]lB`z[W6Q@\!70Kh]NvFeI뿒MDPasA(]( K$7䆞}!0D0.3Xa CA[=_@+"n#kJ?NN!{5A3ac}ɏNt9ĝ$yrWYv pN"”Uʭ|2>r@*UQc;IH ]'P|6YK{}.c!TuƲh4\D ??L&6r~Fۃ%2vwȺ4644T(.q,*9Kqb&:ĐuM$:(-Aino<}|S_L^ Dã;8 =N:C#7E *)ܰ&6Py},귴>#@Ǜ?@k۩o=G+E7d$Jƒ'ZCܦf3Ъ1S4뀞u(9M뾆?eGDOAº.S,$s L|3haEjtieœ6&c ~6Jdٍ!&v"s $3 _YR,>Irz,CXf93,lETl䖰Km9Wk1mhL3\_ܗڨ.O텕i+% ¢zK>hiO%o7#oUka=m|lq3V9Bhp|ع]c:3pדuXj"*U&m,c³\F\:V '{6s%"̆&?7}{f{WHU[:cv,צ|G[>ZF7AWjZnrQFHC50Y@KҰt-{(. (t$,Z]z yXon2YRB9.J*wrpZNk[YPB.1%q}^2peJ!wPl,uf`nF1A'j6 %RwZi+OtcY~o3/Jxk>tǔ+&n虀 ×Oۗz#'\q#D!jl;]t/]$ H=Vp4 w f ^:%^׼UEZ5JG$¦oZ#5^HՏj2Ri<7]d%2-yΝTh(רU[ܯ~9zY nU|YE)`݌NHtG>"F IH^-8c^ݼ<ԙ@'և6|Rc9uWl [ .64 N\96uLwy8A(G@:S&(-vT[{O:` m$>U^ %ēle@v ~U<3=tڛJ94zOO)\?O¨CM@z36_N{KQ!3_LgAS*>]fqe!khs,._-?J"8)De[r$dވ,"ѡ ;H+b2)ZeD3'LЋAWC^.KG9 H" *_EM+'?6=JB33wu90=w ֓E5X/.8U\qX9mѱY4pm,/4 NB8iI%*FbܾrD=_{PVɋħVy\ٸ 4-I@.\8 QrtowoaKǔY"EZ%xQDj,5 IQv.*Ut@VdղJw)'r4GoO izxٜLZ'4zߣQw6z'Fɽ-f-{p`idC~Q7 ݶJ|gԐ"5L Fd]n)ZF]G5%hkPI RQ8!. u:TLT&Q_I?\ uh)n4;C5WQʌҗlu%9 yлD7xt`?6RpM knĂ~ +X]uK1xIZ2Pyi(GiV(JQ(+"1@PX!V3|VU*: 6v2c(Ͱz[pp"|ēL<ܧ^p; ! `ôQQO|:,66gV3(<_;?ZP8S@afjфҪUP.PT Ua9öV35%,TFv ;V@<?}9xAܽ9 sC7Ω[G>T.E=_)t Yk?xh6ϔQ53f*| 磾?Ͽ&z7 YN.l:;X#V g 8%' \&f ;k}/OŽ.u$VoJ~k*>Q)iOC7k"[ڐX(up(ƒ/W[etPscօmaXGrޖfG|?ץoiݸ!!&c:pt_'QDkajq)̆Ufjw,vA /n]Isv dqr|LH|_nod6 j#34TԓsRjR4Re ZQ&l >G7G MX35nou>Iզa/A & QF f+7Ybl& TuSә؂׬ٗQD稰%,sLxAA|!@ ^/mLef7Z0QopR։VXynx"#ٓf|>rq]۬:$:Nmb@R dԴpk91ECQ 9\M\A! :l%_Q&\e;Nz*G9ڨbG5g E` ƌ6Mߑ'y1~״oE3EC8`uL;*+MI1( xT:8!7ߥ0K]ۙk6`B&Atۇ'41BIOj[ٸК S1[My%hib#U Mih(>ݓ:D\u):WsjQ @گYmerјry +Bg Ӝ8}fΓuAZ.S Kڼ*$mlD{=~:$T_:Ll!.[C7io~ \ (P6C?J|(.T1G߭?xr9:pI*gp[` k%-YO28+tDBĩ>!-V-ZtPɯ~Ym}\Yb"%E#FE\ -OjhӬ8E Ţ\SM#ZlMMGGelj\t|OU2c(^5}æ!(3zOČQGEXʃ+$nmljkXZZ:ρOpr@L':C3~} @D!pϪZT5(_\(dE%KGES|'V.~/:㸔Xw d%+`zV`GfR﯈"[wRlyɕei9/)Zr&O]$8<9.^y`@>i{{"]7a~!1yL(:._ v-E ͏lM).T(/Nf8180=d; IQ0RS咳AT,Sn%ԊNNpz.F`1cH] BZ\o8!],V2S ldqè\y nGݙ<MbRlzKT9?&QRワXtI1 d-6x p:3|+$za(zxbJt%#9aQ?8dk[̱፮CJ@}E ί7@EI;$٣ 3ik YM(o\irn)kˡX:Ѕ)( v fIY MVt`,hZX [z1?JdszUF6RYU&H<;ۋ[5!1o#~Q dB:]fj ,δecS uL>ֽ) mGbu#i(ʭe #`l*gwLBJ)-fΨ v_vzܸ?>(vM`|ёٱkr˷'`{}Wc Uz&cZ,v#uM`׍In?ljU_/o_p>\%= 4*eppTĜT2E_7gRuz>w O^ƒWjA.@s_fp_.  ʯ⇵x軠OJ3RV4F:6,r Tb=x~`?V9 x֣N2SixF,_- Pצt-;ս$Rѕ T݅Gcqr 5Tv]nֱ9Ob voF*,Wp!jkH@a T0JpF|9[HBE RMJ ifԉPNFIA. #Y3q k:;?PlFJTSY_v*[4*Z*a_w/ ɐug.m5(g濐ml9i*W 4I0D^/{qԣkQ(COױ$)8C&1: :ĺ^E(tƩ[_|Ѕ HfٸdrP)JV D37ywP8 2hm1#~!:L\1Ixe#YQc>.-G!ʅkyjAM3߀<]м͒|{~2tOJC!k2Zr FAy*oB:ly"1 V5miO\TP nWba%dܭǜ)I;Ol˷ [#>^&QYXj?iB1L=o9 |XSƌߧHXO4{kt;.uGуpfTZ)iTXVX!1j6+CyhC+ 4{>lkn8LYKm[?cGa'Hfqa |! ߄ݰQo l7r'14zʮ}~3?uSj?c1 $؇ v֚GOX_h:Z)8%_LJYZdEuE#yk)a\L@nؗ(q2Uêi=%V h/:%` t{Fxx-3|hG.W\BV-E/>7n S!|L,uT5mFN:,6w1g9:my>uнIŗ`j]&/NVKzs <a0rk\ݐ6uwfD&ne:ҥ{)YͶ*uvF&7+ǗbQ}=Iǂea &PH} +N,Z`bAkϟf䱰]V260QcDuz{CMղ7;ȡ-98wHB'NZe?^dpWB; #r{P*DY' LP]Z>TV5"ŢaKHCbBL?[VY04~~M ǽ>\˞]ુ$L06[<%*P<6GL_m wq0D7}aw^ a<1&ʅp= Akµx3z(ʷ4 FEҩOENǣi+9t.F=MMX8{CξvPN,|L7Gs(ެW"c?D@0|]kt^BSt@UԎ=:(vΏ;/̾f=~Wax, q4Tu /mC1,{$ع5czWq' /iΔPa+W nPSdZ.goeh1*=7$Sbrcv,zD }hW0W|d uc"/5wV4i®΁v FNѣQ4̉?#I";#kiwCگթ4~3 -GC%fX.W0/j.k&21PY؟vT72ϡ0@%4ۺa n~ KތL*]gc#t'Y)m:?UKаHNݤO eD"<^baziNc4d>^Q$McfK7ǔě8;2 "Ɍp=!+ռBYks ;U EQ_\G[l,@1Tyd1I9w__1ڑg9teߓƩrK1@B.ya+mYȭq^{Gqs?_,d!Bw?2X|hZWMl6wu7&Hc؁)vZd%Qoc~\aRɥ )b(.\yNOOsHEm!HrqgldrP*I[wT! %Ɯp^Şߢ<3nz{ǔagxfxF&Yş1*Eor@\x"QxQUA|X/d# !CJQռؾUG_a~rc1 Kv%UGv0Dv)uC9zAM-9P  ?vӔrͩSN8d }pׂ`xR>W1ТYSEU )_w;:BMYcnTˋ# s2i,(_vρmFR0]EfkyH1thpQprg$̇Zנh<`}o^I3i(By53I&7ċkxZG!829,z bmݦ}'ji@Zͅ& mUSyal鼉ㆂmFZ#@z#Fҟۼ| (JDƃN'l`^2QQWr 5zH||(.,>%z[7E`awj?D^\ 3rL:l%d/( lPe!܈HJ2#U~ƦoW")U -:YIi^=4 dlV V.O,wCG2D7\Z--?7R<8{+|xm=l3kP4SB:Ξ% uK?c&ZCt@ kd7ixMJ]s ZS<&!e~ir/qϛk{K죂tTZE!7.3_@xW3t?l.6~*.{>.), p&&(PDXeED}[P+w՘|QJ (_yuw33c څ ZQ*p;.R@|Wv"PHC;V*,#!"o&?]&M,eS|O\fF%tU6OtN(gC!٬15kZJX y"J? {j f|J&%VGc0DfMjڟ0Q~ZJ%>'!"RV;b?H(Z/K xFyy44QRB|hZ奻otB2 ,$rXQ[?FOڳ2%v\W3ˎ 0IRҜAH1(1^/ cK9:KLDd3-|TПk4CCW[G(lqF7T +<.wqkB*Z"1x/PE>I)lqߓBתu0#;*e?608.GiE`kj:}G$(3|O%C_Z*3T ֍xZ\pf1LXߧK~CI8aH6]-kA!m/^&oV>)t]6xMXn)~!r) Y4R)u`ugs/?;5ٷ9߅2'4UEEdV!;v5Q;yjw847t (eT(t p@/0 iQnk{5Rs#3a&7Y(kXa;zR?k>ڽ2fH]% ǙBv0}bT%o'I!:B>BJ2x^"RkM$b!Hª$ ]!Q|5*DÉr_$gzS,wYSr8jNoыm*NHfL] >w=*;|\HU]& 邐BwmqKm%s Rz( UF]ݬ!Qq{btBF}"gcbW .Ԭ[IΪ9xG+v! VSRKkz8H&c++1JX$iHWdy3xax`=qvYv[ha %01gc e_ě̕$o@  _׏/ bpc/"t%MLđ1J=L2E߳n.O,ߍVޔ: =mW3kmEп2pFjX]9BxIH|aLa"?ϰ7.H]eQAU~T?Ƿ &<׍mNΤU|ݞ^O6~h|ӑmBZݡB2fr)n'n$FDSogf-7&}^c\ϐMAF)?ZD$}"M SItGJL̼aa6tprF/Pc[e;xـk۲˦4Z xcL-.H 3Pic̳*"Uv(>Ba#a3'WBo]at#C!kL vg2J=S)u _ED oe»L@5z9rXoZ 78X|ڱ}&MP9W[ <:ϣkq"ŐE Za9EDMՈQ\jPLi]7Q3r$sZ^5NYϴQo GFQKHwz.IsaY(ւS,,N;dr[-C20b%K Yu1SA)`AwbS1QH]ڵ['eó7AsVr1U[O=jmbj~EG9XplA1@>zoW sI8gh6e I MeJG{\5ĩފf;*iL6 DR@ȆV^="tQ`O W a [@v⣼G3S]12dv6kξ&":-B7Xt$z76&:Y"霿Ж}jOJuJi6]nq̷Ms(.*rYn) ,e)JlO\?j |~թrY3?bR;F2V#%,9^(/f-y4Te%. 6lɟ'gʌ}pwM,u M=X%חUz*er䣣Skc4qds))iLgh*4t,!XmӔn:*iA,$KFg3Yk8'Ve󮩟,<_Y99(R M'3ib Y6˿{V@ I 0d(U0xJ}Ii<:[{ ډX=ǝFvtu@@ByfN(*ψo[4OA5 y Xv's3b{-I4[QrO-s~-%uHCXW0DosHb\ LE#Ӣ- AJ|*=[HFV_TFV#XlI_-=5G_/XJQ9V. GiT1.[c:!믢_/vİ \k#K Y*_UP$ tnHO9O3^Ki\"K9.WSJ}c0 )DsTwuNź蹘hů|}K$._mtc1/z-E`J 0ϰ6T>(L:uɑv-g! |ZnTqi3Aynf`ͩe) O'\⦼Yc`8k‗nvﲞ^Wiޒv:G@ܙC(0UbZR!H)**q!f{RYBd^*f0هPv*X:.CYy+d~:H"wFz:%7:Tu7L./N7Pm 俖>~{C&ΌI}fڐm%{BcTvhpBR ҐuΑE%+hiaez|FuF-6 wrЙ _=аuFl3;RC%L[XÖ~؁~`K;A@\=XAZ9O%b$9/V 8SʝN{K?՛jƨk87'>BlC)'yQE5}ΐ%>r%S{}ٳkGB_w'"^En:emj6'_ ӱA#5KE.!3,nv[~ jC2>FɣB8K9ڬZq@P$/u,^= !#=;ͧnGǖ Q~od* uSSR<+b .LJ+o_UQS0-}ER, EX VgrdA"M$]X({ VP%`Q8|~^\|ǘ,3}BcmJJ5"R]0*5I}v r_pcq✂pcΧCibk^(-X])x͕w0*db8wi~u./>3%g)-rVuocA*K$L3F-ܣ;뼍Ios9֮tCXj͕&*0rPNoyA_lx" \"򹾋>*憭6X N|xέ)6mIReT /l+t65g^UXr7+A5߯}91Yn_tGƽmٌ{S_J<6X2@G ֤aG?%QB u r =kZ>C)wЈ-_űt6i` s)ۤSozQi8<[Pԛ cՙwAOذJ .P++^t1IrV_0n̶JL7ƹl#Xζ\E[cݥ%;6d ʬq[GKr"thfJʷ}~2^[O>H$n`@YpI-`Xߡf狢}d]~S>bfzu'%u@2Q؇6ܱs:%c?+,#,T!fi 8;*.ʪJnIpܥ"e~yL{H*ob"wEp<<(47r ʴ ^$tuqIFUPEB9":TS^FJHQM:ñH }!₴Jӵ !+?w0WEe7ɚť $9__nqTP9k>ʱ&Ohk,^evuS!(LE$%a 8B0}J+|fq zpsM,,e#'^{zeSD6,W1d kc^pTC؂ yܥI8 ((ErAٲuRLJa( P!+5t dFlfr=^=;lp“$L$Ruyfe}vn->ż4eޒh D璡^բoV˲\ F$ #<'?)O3][oJD=PW Y4% $fR:${{;*j o%!aҤٱҙHVR\ bZn詚HDCs*Yp%{\r /O3oI5=jƉ1Ͱϡb= #&=L}&|UJ?ɶ d W+&W c-ro=zTįMwWtN^y t/) [|{ PtFN!6njJnxT9fZ.>NǺ;,o wTq^`m^g.ISo9,=ҥT"ƚ( LD}F̺fJKDN4?[I]?cfRx0ۨ9 .$ -S.jp;vߠg${rIP٨-`fi;2;LC*wQlE,Ϋ)I 41uYG+CܦX8 !^97Vd!ʥkÌ٢;ӼM B0>'IBc k6bAԴ ".psV\x U%G{$W눅S\p\rˎvf%%v>4e͟10w4?wTG k;+WD.;1UXv].PRձa=pE,Fz6iؘ|>R: o 3*?ؓ?ǂ-y!f[L9?BtRAu yҐM5TmS+aWlxFL)eCa(gTKĀ#z@rDn&|E,mwe4GxsX/TuS'"6 -qEE -sx] .1NXsT&؆t;v!-ԝI/p}4qHAΕs <%о4|ojI2EY߬L~zQVo:({ (^HneqnwvR~fhHyJAPqWױݻ?mۮ(r)_ `yGcYBD;JO'K ]^m00lMX-1 -AD+&U{T~Nb]b6 q4WϮife)̤t)P+]5 x~qGҵ2ټ%ѕ_a{ZHAX <{rJtjsJ 㼆sgw}/urqQscдCmVԩ"KÁhNr =4M~&eg"^s r ́R6^ۺRVw My:JsV^̇jLk%g fqC@]Q5@PEب 1(*}~KX-܀~LGX:Us $k8F)톦xe'yMy?_(C0e&4r@`p*7Ci17&E }}0^tB8HB2/PIۭ}(`]lc(2}*X EWy|ˆ_}-JBa$DY? mC<:_CA6r^p v-l]/ k)07>kr3>ܾuu/Jh +q D$&"C/ŊHU_m:)\c|EC}e_ F "nXZX#| ^w2t1U9(n&gwr3ɋ:8O'nqZ4Kߨyy-+@2Z%#?߂niʑ}M$jǯ=dQ[H #3M)&)QhToI93R/;L]DYM8ƆCM0'\ZCP"AJtICżMS858'8p+@y\UoM7!9ٳn[ZsSD^aOm!:ljڔAtv\$BmDs2C?ң ef6YSy!P!6 99 A3tu{܌WN͙Zd ֔_!Er&WNӸFѕuob: Á]4KI߰'ԳBvtu5_#cO\)K\1 Rz* 6 }tE'DE*%BtA8Jb1[!F* <ϱhl{FjH:F@6q۔sh_ntoƅO-؏轾 Xzrg%.L aMSIu%!/?  Q,ZJ@ɥtGS9ŞZ HtǛဦ@+S^⯾©S 6TO2ښP]Îl1X5?Xm"i`]zFu[U"(赿{@\4')BhU/SHg㉙KW.md J÷ ;tRXll'^d T<|j,9uqͶ8iGB7"Wۚob(JvfU jc{eYM~˻PJ;g_"vvS#(BpaT(ҙXg"1ifme*H[:K8k`5tֵӥ7~ߊHҲA|ZǫJYiۀ[eS3\s65?g;vs10#an3p s&r]Vf<-!^"g[_|~wl$.jgrhwV,h-¬ͯ^Gދw4Ϟ-3&0iyVտR"@%D%A^cٱZSIK  TQ5Ǜ|3㐘zyB\\,],F.l+yu`JAOg:{bS[׌,cQP5C4-Rwos(clIjz0량kƳ/S# kxAwlNfB&N<'<^JcZMTm.^]tL~oEG%dT}]5wki)ՊQPr >~$3]([I1a, UΆVQ׷%p[ &ALZ!3Gѭ!wݹ!C4d4s_mڻp/jl<}\#R*%pŨnsơhRu3~QgQkW5%(͉\>7'Ȯ{`9S[T$"V>g;PS]R(qgTy!RBT!jEEr]Eu|%7PwrzA; :rx%H*)JU7۾LSo@3}ؾ/MA#d 9cjcM)ř5,ҡ|utx:$37%}ni ':# Rdzɟv2%<<ߟ("vye~Qm^ؚm)W8&E6Fic5վ;n6bzھoG+Pew_+rL歘[6x9Ȯ_ FT!~Q%Lc)[ }e<3y:6btlvm˲f&x*I &ǏVfrZ}Zl_1/'?AV:uY̠x2@م2Pc_v˃X(q9nfIB2dؓ,ftҥ#3˕.RPh-A"AgL+6oY e!OԊr#Lf5qW,]5VfQ}roʋ[<0k4䲕";t.TMc4U()W~4MDÞyh08z!=hIO KH (S[$PKK CbM1C !iWNy,^ 8j jc5Nq0YC1=FS80@Ġ*9ٌO؆^!ʸf;㨖}-WqzӸz84EFcMtDco=>&NBB|tjHĶuB2#\<;-?U֪K9}ʖ$K}QR4n^^88>bQŻ.;$"] "=$Q\ffB?@iAx9[&j"_ʃϢ9ks.˦A",(P';Q8N R9Ȼ(\+Dz2Ѥt40|Ŧ85E*4\?);q%ΰe?Zplz)cP']Ro5TΔRѤyʋ:)R.5)ymĀEft&um) =51DfkYޚ\}Ù'Q>7-28:}w66Vr?wYoehz)~JyQtFq~Fb}?rd: :t=M5bx¹.:B!0wq'׏Ρ,Gٛ'g $"ܸ8K@ Cɹb/ fḫWт%1.8ESC@_duO,aX@wިl:p|"$yTF٬Q/XYGC^1~$w̒SWDΙp#ZUw5RGPnz'UP$%#bߏ٨uHو6}m]+#mMu#ᨤYt57Ɠ {-(̾ [4-j+X:DXu-ܹ 6_'R[cm{#4pe݃̂;z}]kD)1 Jhb6=e:I}ɐP+ ,838d2Sn`³G!k=$})Lۇ}iENE#;t/$6*~@A5a1C<\ns߱9e^IM!(ÞЯ+.C1Zտ1"IkF,bgtvitRf; ZR+JH_];u?QfDfgjp*XrZ 94\D|AC*/9o*yDyl^2=Ұgn:fCҸjezkyL``Sp,׆L7SmY|e[\;+0m^"_s Btk2!6E! C͓qv&i@wCȥ ؉b>!su H; NQOȁo֕7eZ( Q̶zQ!»z*Muu$0 hCjx?WH~/V*6̃xݦ:DR܉96_Ơ VEAWi}pr3a935kZK2Q^٨\)KYqW϶w֧st]vey;7=(}n.I).,Пf:[ >GT% INUVҿunLEK.3#vSGuxERe~q{FOS] g@;ȵک g!h+k5:7Te":|֦2c4v׫(_sN\{oWlk-V 񎀲Sxi L(ɩqϚ{k/O xFڻ-gHkvPՠ,a_*`|8s&cH@ OJVBlj7;aY \Ԉݖ| `d]H Żc8gGW'- 0XJaƐKbq2dB@XʢqeJ^$vVk)>B!Z$sS{ÄT (P~e[ʛX3#fPZiW7-D X 8⋳`ÆpXzURYہ$][Yֈ%i;hhlM5@ołz1RV)h 3%7QٱXNB:%'JŽ {! lu!{=zmdKtvoP!e #s z1H#g:ѶiE@d>IJD,RJ" UtnI 1rOCq^[!0sp(f0%:E f9A.t s a#j8֮Q0UVfrlw?捪9H7bJ=5O9nH:P(Lyw+1IuȁO>[#zC3s](_J:V%sN0#"j9l $D_t;8%TK\}bb+81]9M ^`1cG7ʍ6 }~@D -~,7(F~¿PW&* gFٺ̛Ui tznggW%z:va{4Gr/ GzlDƅ:6 &+➇EJ*C@(x /5͏wu1xR+dBẄwSl,dq"Z|%8l u3JǏ -PҶ~pZTVǨoןuQ ;lFABf|^ՠ| JG$`y+ mnt؝J]|+K.|63N,_h\1n6c q-l+Zza]"x㰚9V /laD3{v+.x)Lw@?ygEXl:WJ^R)h3nmwb\a۹ieΦ_WG\:4Qؚ۞s 2ҳ ȁ4RV4$ؐv\{~-G#K s/f6f`n@o% fhE\JJL1#s⧍zCb8:{&iBkaJ'`!A c& ĚIt&w {>P6rU$0~A=C7 e}iiH7̭#2'ۉWE!_ዕ&f<#ݎ)㌒S^0VeYy{eٕrEԛ9s$$-k {^P=́ :aIU> שsFY C!ibhCJQzqfaKvCA%pͰ-/zO8{;xE9[a ehw,S Vmm:dq P/AVLĴC*v騜3׋ԽEJ"=+JmWRh0uĴPKSedаGj}`y<@\ft}*+b_pf0 f,QIu +~"m58b㚩 {` {rͬ4=+qU$c8)|)N/W>?:$ALS@r?rFEPuvӱp UR"U،ݾf p팷LLcHsc\Q̟[XUՅT )lRӖ ?lY,y2qc}-6-u^f?YXiT(̱谷E$2'uOGsBؤ|sFGxOS'%(EH> 卵(Dx} -Zx0Z$L43 8KA 1rKª4U_fzRjE(MOZ`2!9#!P4ѴCФPm"=1`V{mD\z J.3F ZIL@sab~U^8?V!O[XgʩFjvP>`%u 2_Y_9ߧ(ᨂ5WOWBK%%U$c N!L}HU7BMd  .C(TW56[+84CAh^j:G5O5fO'+88/ ʹ7/Vu?5j<.0 s}R37M$Eޞe?2,dz3X^M% +W/.PNH !۵(QyS qS~ wڸ ~ LޱypDNBIXPޠ_0s)Z<{(|xo2rjN [IB@`\A2!]}eXT^y2:{`ҧЅ~eֆ\<+E3 ;2h8cUe=m2oE-?^Ş]*?ocm_At>ѓPy_*%׽`'FtYC!)XgBWQ]ѩFx\>#ie¯q.fDA8 &飩 FJ{JhZa5l+ 8lot[4$:ͫh^ Fd"}Y z:7& ЖwUENY!M݃ϥa0H/qo< M^#`&q'@TNgvV|x:(lj̧Lb:^&6VWފRI}X+Yr0E5dQ;e%ڦ 撸[5zPT-H 4 rܪ3JH$Գ8"NX3=MO役E*3GQԐ~sM-+mGB$p7H&B>'YPjJ,֯NO֋2"/E, tNDnI)Q$n|MPK 'U%b!/>ꦹVAs;)^E2k ķ|bɑh=3jd̯Ë 'BΗQcVT6wc8g_%՘N}-6A3cA(t ;w9%iɩ5?N#מJĹb\؀;ck*;|Z+R7P&Ԗ^0rӲwɷXM+:OjSU.*11XeSX#^<[ q@@S…HϔBO9av))^rag3 ]([($ ok>B?A#ָ;P9%_g!QPӑ mT"*`W!֚xt7u^\i7)~oo&"yp!qF Yw74z uQy+ț )iv{8:Xáb/[06q;џnX(U>v1ax8Dr/2`~Y $p+]:ԄU٣0FZ< 3P@gi̽us• ApGa~Vh:cEH _ˣHL,&+F5\/m8mSL+;q2G4JlJO PةD`4a&kHנ\ˑTWerbX>#6{q⏵o#=릐)RT Țs%5z(bG{=_Pp=l6>؈M.|0w{O ɖˆB]?ψ:# IAvs]vWaW?hy)NK^ 'R}2cJp<7U,JÃ<A*p)Jo!ѰZ)4 -CiFEsc3L3 cn0+3h-?&ߓ9pe)L{aFY53gf}{ă:8(To&-cu42 S-q%NꅛB9r="+![W6\k;*.5rmE4j7964bHoi Jhw4|.(#enjG]-'vI(!jԛ*^5Yhly;f2p l 21=X&J3oSW.5Wp0߯T-D񒞾5Nڌ2y020 KjI'秛V;d,뮓Z}'{GYlNZpeHgY+k  }cli"koI__hCh8xPG"0g>Z=)ԢYpPҫ५ŪJf=ne\+qWOOGH=.T>lɸzI0.;\Zt,%HǃATCLhBjjE# Q^d 6fE=y=@f (Z4hzJyLHہy2Pu#" D? fʎ%_/Y2s-!{^׷|p[[=@ͯ.&mZ$d"E\riv#vْvw;LP[v}}t&E x?gʩjbx :Lw&Dł,f)hG5IpYkο )JT!/Tnx9 :>HѻF3sy.;koq" pYZNr11Fä6?%E4,3M~">p{7X&)|H Q 8G9J%)0F/ yECe7k̯/_qtܽ9gFmU:x.uaFHҀI,ވ_%mGDݒChA&*%T[pSh:Wç #.t>Znup_ 8H.N\9 —e&Ѷ̮Y>UDH 5:d=QiH.:;Xw7ByjruR K+B&NKAfi ZϵYK#"mb L{EDS~*nn0Pe,Ǡɼ"{BX4_8fQu^lf~8A6 }1Vlbvئ?lD>fh|dzɷ?},eKhiwa(WGM-݄=\AR,v0We8#uUnL+IV)96t8ž Sz_4HD?rqVsjdfl{j&ufRpamIG|{̑7!giBa{tax``a7mΌZx.&:9bɛYqZrZ`y.Z%7G$BeӕpdMnv/lZ3dI;z5!g:9-`؉B$bclngPJv^Lp)@ ;,`*#SSI:A@6Zϴ&4} dܦĜ %iyM&M~o:LfnPU&=_TH,z+?$yLs"S4R+V¶<{J&HMu4tV)To;lycU7(Cv2A0j_kMo$`*DNty*9_T'bnP}tUgVX`0CDVQ]O1w7Z)0-T٘N~ ::a"y\ }k/:/븤^cn(E 1P*4ns&8tR+D'EctICV/Ī/jxR[O =vN@rQB@8mk1s$%W=jAeص֔Hv%i?SzaSۊZ{z`{\,nq#84<_WW'*I펳z arPe52 eT^Y0*7lzry)G,;OrA#'4YBy݈EG"艱OO<{0 nz5qBƁZ4]pW"DL?Zp#/ 蹜FßQ+|G G9I]tFq /No^˷`C[X *"*njL =qS,x]hC}% nԦ>Dp/,RlF֩ ׊_J7} s =.].mLy2fY#tO/.*O@ӑ9 ;!*Vikh0_J"腩 Ŋ̸s {[HnښG)aC>0`Rރ (&D8]xe,ԊUO 6-r]yd%)OA(s**Z%+`̚}J*V;kd-A%i,\`|irn5TYەgSc~)]u*~k0ֵpT]XrBgy\$yi LEm:!㓷zUD,CE\i'z~F FR3"9p:BR#:ᡁDCC{$o@2z`a(z/.8q%b1-n7HR{/}T-8skTS 0(bmĴſFd[R`/ƞhR, TM6:-|; 6b95,o V 6c8IǓ5[=js7vwDYZ{vD]7fBpQ׈nwUUq &)I: My\-mYh:'Qs$ bÉ60P_5|qxc2,u{^z{4X~]nÒirHĽY,PxߊqEXzަ/3 ,4~m?8@@n\6㮶^µ ,-mIj<θ{4<=fMĐu|# %HcM$kr@o9tt"J2~55b-E9$/XxpD Kץ: )L~SG}V0fMb)SR\g ̪Yk†/u))_ }#cߵ&hEX(,AyEF,aӍÜW2X GQ:ͻ4j.!؏fS mi.ga'컟|*.eϝ|ۂ^Mi #+#YEX n=,z;_Y`ƐS襗L͖O6A>d^?2h]r ak6@0`/x)?O^?e2z%)H#rwiuu{ᐑEjJK.q!O|FSV"{¸}}b' ?vf^bq;r5z6{bD/]hsbſl(&Pǣ01(Y=2e"/t$w!$5L]ՓЙ#ޑU>e[d2| CHJ9ɬEwQ78ZntȬ_:E0ZQ]?Q^Qq3s/0Lx Ŵ0 f/q bqI"#ȹdDa7yoo!> ^^\ݾWAMW1avK#_G@rl!JN=ho_NNZ[`M6rpą =]dqPyqPD~!kB"+ޙch7g1 /@ĸ$B3mi;R @Z?3IBR8tZnc{:.׳)cPI^y/\VƭIǔ3}1^BLnySPyo69^ix9[ POwJok/yz+5$irbdՙQtGJ E\@}{MSw  H]+|Uf҆-q{~>d;cYO$_9q͑Tp=fԅ_tt҇ Rkߝ+[W6n+ nצXbMPC}꫋RR.D(rWGbrzzElNMq!RdkNJNE9f{G!=]+Z݈6Pvet뿋7t A$i}zC!OРnf0QGZQ /Y' !]%Diͮ'zA/)WݑFf’Ⱦ_O۠ygIwf4odEg,Iyfe&t.ϕ![=N 3~Z],Ǭo)j bɃ8(GnqKN!ϨiKI L՜RtDNAeO Zg3{ojnws_8W;M-qP?pп,Acj{<-30 *V<hkYr#S#!B<s 传aMʸDzk:<\f 3xhR~8k6z-hIRzDE,S ?J"2ߡ=*?|73x:9i.Ǧ;q1o9Ux?̵`*V/6=0d݄uDyͲ#4;DYNޗmz& D|* ?r#%LQnQa~Q{/n̓wMRTq):;lͪ ,T6.gw8>i3v3-] aF`{=왽g)0,YUK=7{G}}} r]m&b.ŬIK F[F6Sd qS+a/|'ѭamRojFNjrs'8j)Ի7`!GVLƟ+@A8X'[p2U`y̴tdH%]nFc)WT7kSg&S`+Z eEHK:( vg$+=ώgַVޫpZǗLy;dE <4u m( Vf lgoI.._5%/ǚϸM0v> zЄ8,`[8Bhl)ViJ UqͼIC76LWu8y1:F$saǦO$O6W8=kR'U9HM6!?YG]CA5q#\kJkM|"=DcEBHd'v 9 ot67 iŎ|>0*` (KLBɇ;'Ql:m=R6:|+JM$:J*vxy2n>Hk^}x2@DM3_T?k?0hW#< &`v%_X q>RZiN.Y &:䏅flKp؁qW3^{E܋l7ز69 ]@+];lj#Єԥ`pڇ;;0>.GLr' #|$s]wA!)2H414M'w&=E`5ZD?.gh2SbC-!q[%gEʔN|W(@ucXeR~${[u,!JR,0_[0&#Ryԃ02aj</>$5oYc4V2r%v kE{w-\ޠM9 ˺ч:WUfSD&nGvv{ vF)S-gB5k$+T vH.8vp;kZa`']t{Xzy1߇THhNӶq$,f"uLեc(f SnmtCynBe>>ʚt=D/8ǾS IgQ:wZ]8Hwd1lҀ6Nymbi{G9,KX()-ޭ_Q8: lՠ\r*2ue[~_mdCy;HQd "z~ v 5(hfRM;a>b,~_I-c1N ~8rRPIw%<̓38=ksHj [x{Su_Wq!*F"OMGB0Jcvs2 5ȸRg VШ;*P}h[L&fKh!0:N$ ǽZXKP ř-owI * [MU`xp|p[Iv:S+ c+ܑmu2 q `H:eeco"3[~XE&4rgmf"!SĶtuBsdӼsiN3҃ޕX`@˂뻂و̳2K!6.*/}Օ@ߓnS B)yK^yoh lZŵגS 31_t`EDƔkGsPkḿ(PL4ό1 uBj3;`? kV 7of pQc\Wl\%6crAO;ۀ)I1kCUh D퓈F h9F4 {+@*f$Iq:ëyƼϳTaN~泸^rt ͖m:0-U'm&n٪JS-2u` V< 滷ś: zhZ̻%ݼx2~'VfNR9n$۴at؛8XR g< 0*{px<uJ omLÄ-J 3,5wRVyy?ڞS H26= 2ߞZP?:"t96F^Õ5-JM1 ^Czc;HJ \@&%xG=7"J'j7f75ӊgΩ b6?ZqxJA9e"? /?gis[$0E+KUD:=ZYapSBMi)9<-@p " ˁe; '7Û[GIe@f4n~-nY QpӀ/no'¥ǙNs> `_p[Nb05%!yyQ6Ԗ0̤pT@+\j ?'~#HG_#wWtb6Y>пK+I w*@]ߒ>| t}'䘆Cn8,G!ū VIf'h G|>ߔ~ zAkqTvma[F[`<ǟneHyO}ւZϱu:%x(jUt}.7 rV8mOP&`~AlZjzO{~TlkQezu PNad{i߂ .L>జ7=Z,*ȹ^bF.J}urJc@LHDZqI^zS@a 1D/j}RZp׸+#biɢnϷDWgj E"sgX*GlOiݹģSh 20X&pNG 1A6'ɼQk60˒_tۼS(jOs.03k2ہ-;oQ3(TIIBQa¼p<1qЁQ]^x{"P>?tKY OB}sRSSb nz 7 YM:&gZ& #MѮq,R&/y؉t7y<ƿH6r{ȅnf[aG9pIwjan*x&gMz;D zW8a3lSXX&f! +Ճxp.v#".>Nut|U`.`;KAd#՘(bPQB2дp>JFM)oѶMGkǪEǾ[fN9?!= $O@%+ӟTzTa݊BٵsHraJ2uL tHm*1HvLUH< lC䐾l|sNo=Y(h71_Oh:~nMI+*2;Sr "W$^T~ٝEq %8BZQhY:[)av 0saf RZjqshV1%2ӭ=4RX&,.Yd͡` ppdHBGoΪF հ chZa<򴨠l-l tj7F&miz䔇 8gŶsFvM0GPz ^{<]TG鄒79m> 0⼟XWQ̖h?ʭ}O-BШ(+kzZu 84e+ed]]c?s2ڜPfs9c#aeaPю~v'Nqz5>a~]^d/:0xll >JOR jW!|fQ6:Sa8PmP.G4i$~Fvot~(C^7v2o92j9XdkAary[YU+>HKm q3fsɘW ` .fwnΡe=M!~µ@~>i"!'$[9"e QNڻ 0z厜qX~^2?:H d8%3k).~ iI ZFH:}s$(@ Y‰- lru|,(dc0q jbZ6uf 5^"WMO fqLBI5ǀy~n ;7|J[07X0ǕO$O{w9I7TsbN&/BKoz6p*„ީ'I$]DHX0Á [ݴ(V i%j@8uK`^{s*tKeK2w@Tc3@K&'t;KH,'Cuǩ<`"5R #WF|g4mip“fWv * Y$yTcHx]їk #_^3e(#xs#)c:~PٸZ q25q`$Zm>h/BlWO+<h:"J>ȎU*%ߘK$OO\bs'-c~gJm}4bf44aXnp؋Uls,鈁2Ѵ1\H(O?fLYR;ۇQj9A~WZbBкb2a$RE6Q ] :r;B#e;'%h\%EwG'%q`n:ѽ٪O~} W;.!xstӴ}y1M"Ǵу*Y]lv=;Rl\ޱ6߶_S@-|x#gm4)`w;}!(lAbtm #~<'QJ>f}@B* M=fDOͼ6IR*u.p)lW^dBSn}u5tdK?d]fP ~ۮ0|$|4LmRmSܳq@rMKT{/ ,(IJ<8. \|b`,x% {] v!s*@31ۘ4O'1_ZܛAP/F"Ձ2K .:%|R:bKOsl`]f(fū `F=;țMfin^m aƍvqQyR"n4|=u`ĊQr!I4ad>S@+w{8Xn*Ps3~+i3z"xjPӪad_`ćʌ}*Ilh>Kn"|;)  Q[gP`@BR;LqۂkZ7|]d;Sw*oF|s}~@uU,X%x5uIJnyn9y+8LJG,~~.!~YcA%虵}RwXg/UJ(YQhyefm$"#M؀~Ij F;iEM}ƄLb#AD;ҖclUbE9 % [vV 9ȆLrƥθr2(R+BlN􂡒)vQ~Q{5&k Zgw,nat;KHu_)mgb4+ ʽ8pR~7z$Jas&){yy5`sAF "!x.q#-L"1|N"H8Ai9dϲf=Ud+lq_PDOScȎA [nkˬnv3 $4?uIc'*Iq~k t>ٱ;A@ `1g{6mhıŤgT=61S6J2e*T[KհTI|Ev~m}tW3CF.kZՑ MBqjgǬƋzZ@sVglrvZ[ϙ 5ƣ RrW ӗNcqB vRpٕثOPHFrN6hJ@yBp:ңUghK;V,Fɸ׵9D'puS'b]tm!BQ:(‌ØL ^/#Om3HWfzP><3**QsĨ/<-? ǹ_ ^B#~A55sBްG97G9-ؚ-!&sgzmmېo<6gHA2l@TxtP"*0yzΰF˿ /c|!'^ :m|UDM~Ykz%_Ձjihi^E*buY?!g?6O 18 :·}{ٌ#S|GߓXsNK֛r,r()tpPddsJb_܉Kd?,t4ᮛiA`V1;An^o*ûoPM68*(ϟو[ۨDb}\{h{4 (ZQ n#c&B`I#^@!qӅiℵS)Lm^?IN H} %wQh*{ ެ4 2AXR4቎8(czmjx'P[ɿ #`Ȼp0j;F$WP;|XΠ]= 6 NAQ*E,Y,.iZ{hu4%i3&D)ݏռ&J)K7N @aFcJm.[!/Cg%LYZ] 2 ^} _K{jy6ႏ#R2,9]^zD PK teL}UBJ)0"/}Y 6/&o;)4Zei@O`MT}1gNːx ZѸR3 m'O׾I=!{Grw@8-"ȩME)Xa)[>j\\n1%\o(2'lBthQ g'ٻҲ.$r;gf'%ՍgP?ݯ!-}1r ,XDM0>”fv͔FDt&$rp!*]F@+0iuJwxhL~:qۅ#»qQ(faцwD;Y\l 򿲵-ߍKmO4'&4 mHY[R9槍`&MRi^ ѝ\Yh=phz_S ߥ?t:=G""W9 &=YjfS;vK9oG=OVHI$%NҵY M(,r=Dlkz1[ܮ$% uxLckDwd;{U  ܣxfRSU+G4N)׺c K@q f( 0w2Лfl/\qbNNF)r:7]xVj9挂ɿHwM3wD@\.x ىIREmMnJEF%6i+J?qq\4 wlq8?t6N:G7CD0Mߊ3Zda12YEidZ|C6כ!^1¦,@e0%8T@E YO՘48x=o,7PS*t޸Eָ|synhbGqF#1[Q\~E߻Fڋ$b #.\P3i{fxZC|$:\?_"(o|c_CnX o݊uP :q2z'2|ިC8A `{3$6F] AX( 0lD1DFB'_闵^aYH Ct,lH^k,mrXӝuyU.^A/!c`<)nh Nn)\W(@S9I;Vs$<hcr?j]TQ{B}y Ei;!/'mn6 LVNb+c` \|Q4i'{xQDYJYs>P20Sznkn ʄsI /dw3•8M  `gb<h`"4w{[B՛n #)p\'. >#uiNZ\ΓfW !L4If9!ߟ[>s G ԗv`4H~k + o" *Yqx#WS:مNlAO/A>%:x#BsJIWˇX(i}[T袡 ycj$ {, ԷnO`Kp;gd:s˥]Uᣴ4e#l'U-Bc w0 bđJ4^z%| 2gjSۧ3jvyَVY˵ bepbS*4kD<1혗U,f:lޒ=/̤l-l|LHR*'ˍ뿀.J6[bQ;}3 íhZ؇`0y H^~{[Z15Gwz;HA‚^$U |9/uq{_(8~a.ҿK>f:y"J-j.GD8 =~oGH`66`y5 EOGoS)/;\~MZ~vqt$#}&av)F(QlULun668Igdi}jrL" D-% p۱uA@U:tkE}ɪާq+ f!ҙ]c jdAҭfP\`ZŕƎ!ڷT5C"}kkNJ1/yK =='`UQZS25 7E@J\= `C1R{W2"JGM`j]%)" iI #,nQl-EjnX^y*?uw?;ҋ5US6 ִxSȓc@D20ݴ!:;E#޻.,5\Ky @'L*$DJ+wo-O@(YϿ`BM蠩J踻 :戃 Ԗډ"Ӟ`9u: uO|vHl]Zԫ~8X3P|)ފ,3 u0wV@U==KoA4]v2xYC=NW-Ěc8I A68oZ0P˘Ig2Ȫ+o?MFHEE@߭GQm3:˒o$X~f -3ʼc#!_m8X$,ijb=|)pd$W1m߅ Ӑ2^GjԪ̈́RAy ,^Ah_EX)`;:ƽ2FOQ' UٜC65c3;=JݦKk:N>},Gy܏!v0\ )8Lo T䵌ቓZuMGҐğ4zgI_2KS\)HA9Ŭ/"a~g8ɨpDE0?ő,IHy?P!Y'.Ų IspI<qbv;qy7e#cHJMnNPH^ H|e|+$@Hg\ܫw]*,+>ۑPNR%*)xۀl%BD0JCRh\~b{L5~bznҜ7ƺ qQL^ $ҿ6]IE%g~ctG+EON 1m# b6 s$  vTHZ;e΂5cu$zɅ `b7<\V>SpzyM}3@8% 5ԥX{OB$B/t>qyȠG)!9Y!Iw>pպȜ$XZ J]7m@؂Ъ^9WQ4ӎX!ut~4109+,N2{ii "?.K@-kESZ%j䇔jȢW _PkG<,:Wq3ܕ,,Fh=l-~0lEAm* {=ԙ+h|Y绎V΂&N&- -jEC7Dg `/NxSzaF@hcrd<%Dpv{_4EpɕV 4n ÿ c4vt~ORN _@m6(KV)z;OGMi b,L|ƍƻ "Va{%{.bpzy "aJczcXMln&en.qߋ"sNrY E?8G{Z;NW; *l'RԱYH4r퓽2Դ,Drk\zY;6QtD*iؓXJιH)y-YsÏ.[>Z ȰB{NRn8GFC*/^͌ BZxM 3 @D?&\T;q$V%F,EXd.ͼvL𙽲&$<#_ ?ƇJI.LFO5UYWr=b#;L74׿=MR̦CfLf(ϗK2<8{@@;-:BETla$6|xwh7Ӹ7A)Z Zyt׋6x-;nyr(e[WM辴+*\C%}5N( ^wLK [ XD/b%KwNEßp3)L5Zdg:L J  )@R"*˪j!٠}?mf ʃgLǒєac˨13-`:[\*Y)"+C~.K!̸]C֑>8n!Jbf%'nDt$eG{ev)Kd=йRl~Wfy %yTD>O۶KwBb44,8W/cdL{TB>Grj x6uчQG+WKLmX6GKenuwJq[Frl v+c|dL4{ĖM¦>v԰Cs.ᥦtN 8nlcUFMYcc .7 :BqO@.JMCJjWQ{ vA#wrȑ Q$F]6Bèu[+*h6AZr@dcYQ`xv : 4Qnhnda&? _e5#@:hҟ#Jm;%- O /(DB ZcDI8'F]9}>xXg%34`;Fas$1<{ItjD)Dэ=B]3K}%[(j }Rye& Qs.$&06`#Y*M"ix>q(sqOR$gMeT!WҏW| '"PƎaEݍbTGƀ;BRKTl\ݴOۙh1y$U҄p. {l$9 ˏQۤ'7waMt[LHeRP/x h$8nޒ@>oP -$ .vǔvy8*N;\SСC~ ٮrRqLDq߱]d[-ݗp'MjL ?{kKfaH_m֝Vkf*pЧ̽_KSlSG6ӏ2&:@3nOvuZ#WjO= eUO#~t4ɐSV)9%;C5&S .dȲw4ǏRlfr^ T 8 ZbX!wh.%^P^CLk#pX"KLVyJb08GORKe݄|z0U0G;k? {_ Ѿ+vw"!](yqE/_V'ĬKK,_&  " mBdWԵ.N3볠r=/[!-+v6y _sKU,~p{"*o-?)ɾo ^'0 3dJho=ň]W?OxPF)jThFaJqOVj6ib|c!vHXCVUbN9!{]b#hiDx/Wyڒ`l]ǩ^J[8;?j?D7\9ϽL_R B @O*FG쌟9:Tڻv_8l>; eK|g&˲'O[0 wy(WېA5ge>MP=?$HmJNݹЇѿLM>؜7!xO͸GkܹWN>zVyQ#?:(E"&,suഎps%M 4 Џ,* cj g{8:Fk?`E]l\:$9!G͚A\?i5<Թl[PX,_qbO!ª X ;*`ݑRh$Ow3_Gy|ef !o.8%njWyZ[泤X@O4=\zG%ؔReϜӵ@j; oj>&_Ft \wΙJ0Z(F& H(ψN Axܓ ъ>`QՓe] Nl`kKiD#!qæOOhUrI>ىڙBCpcNFa'DpwX4R9#8ǃ,1 n/|Si(ZneǢHˈ(I{Ɵ;"6 c@3'@UJY3H@oPxݽE^x-IBm[~`[0rpsp&}H)3äx"1검5C4Z cU 1lC|q3P=] <;t;%o=k '{-rǑݭxcRGcj&,S`-XN^؇J4Q/! `FfSS5dV 2"ٰs +keo̓j9O>5"N 3^,䦭0īl/<S{AK@+ܯ2 S 3MCL@W^e ]&D |MO04];S23ֺ^ ߳&^D\NtLbBK:lƅ#X %`YV$.: X`UC2Wt i˛zf%  fU*62%g:1wtwf N tjN9p3x9^.Gxg<m[_ydq㵘ItBES]p( <ǧ@9pٳ:ުt `|[[>8^p@G/:`=X[ Ce(FԟR"Ol'kpoH~WD1l66 ?_1<:'ic~]?svQrSqO^a7KszagiJ+**P|H64ݩۨ뵃 iE-*9kN(Dr! {K6ҟQF#)kT}BLxџXL}73yrQѩFQ $LJSfT:[ެC[DP8n0,v]剜E~tyb:tV<&Uq!V&XKS4.MmMRVp%a wگ}I[Nֻ%2^*"JC42e*Qzγ=tIbwOB{1*rK#r.f$*ީ dS6rtFb/a &>1 >Sa0E1IɕX7;"W?!VKAOD#c+m36I`(V#W=W|Jy0[Dte>4`s.,imRj%\MπslFoCʥ2~* $>,-8VMj}o/Q.'Om7_^UP3Wͻ"u'kϡ棣VuH8KV@Db3܋gA^A0Ip D쉺'oFbq]/Q@:7ƀ){ $D(+Jͼ:v.F(b-X\pUÔ3_b m9/L"ѡ,IN7[jPjޘ?3 )q9HaJa%~IQ~VݥmZ-t%Uvn=H!U!Cs]Vm<2,L/ShP 0xHR&59X^ 2wgTJ.M]&QoQx5x\??zHHp~h \]/s{}OkJ[i%g1# ҫK܎>ksA7g:MJ&Fpdu3{F>cgՓ2W}:`̖}z~l9УkټOd̪͈B(#*u'r8wQvzh@mp@&~Kv',Gwt[?;r;0;o{l /a_1%amg6gM gʛ'Y3̌+LA#s}:)-nf@Vzg,,Zd^DBc@AM$g -qMř-h:_W_DӡmR U8H)]b:+a27FRDr4GFyjk73Ũ,UjMgC̎><%~ yOP Rq)i;+n%Ȳ&, `.c(tȾqWL}Bݕ:?#UϜP*:(؎:$\{EHsu hN\#t!f,mO9II?~C!»|NE5ݯ +q8$0sk.S{g BML)^sOoR=LADٺC-dȮycΐ#xKpcQYuba^ 9|J?SP? Z>%dE;;S¿`S|9xG5:KAIV izR,j{Va\q.iGIP``# /( {5̄Nέ"O˻vJk&[FEyߔ W-pJ0Rh`dyjn-[zL+AfG*u5IQARQXvu#b+*!?4qQvϤy!^.Rx #W //'*ɲ4=Livȭʑ\MU  0sp*.@MN,_#?p#٪Xz%LBY,\({DZm.|7v :K1OOe'D[d=t1 ugP2tZ=8UC[ {}(וg&oCrI _IFΠ9逋:e 0kI<xEm-f _i΀![} qJf$~m{dj3HV&PӅ uy{>3Do{ɬ*xrʏ.%\x<+4iU`5*7YSHU*;h!v lݽ۪QDw 4DI0>'JxW(H>pXt%=SfHzt5iwRwb4^F9yC-N}qIЇF`mIXdnV GC.b4OBi{v> ?eA 9L=S2O\n]koYˣZ,5 ࿏,@3\DŽz+#̄\D7`xs 5kHmZĪ`Ei:Hx -SAcyV!Z;k|HHFǸmJ !񥭮_Tι.5}'}sӸţnh@˜#%njZ  9\PERB $\c|@+ ^X2sV' Ȭ}B7S/8m (v\7[]$ON^w#V5Z?S怭tmoKQΖ(Giȅ5~#yQ=eP !B%B ÆQqh{'qJ"lP% ngܧ"ΰlpT.$_NTa%űucS/PGGAӅ@/xQnn)}Mkλ(K9#l(k$Uou]R{)d ,S\kUaJ"u ֨b?,?v-\%D,ݺE>d~;ت/Z _^4c)_D͐E9P40>jp/p=W1%'h? S!T3)n&ß.'c<"o,nkkrryP,5Aζo$ g BG )xv!G#e2 Ŋ;͝6M|.9$isr\c;h^dM26 ojR$5cmxPEM T•&jW6o8f<9fqxG|m>2WP_ͽA3 wI .I\@P9봵w&l0vF|DXK}5,#v2z[Mz:l޽zĈ=tbikAy0f=hyV׬bx -`riTu#Px aΑMNl9|߿ifWH]b(ˮj$ipW4jU㧇cm4͠-qiieIp>_E<3@ipq8խԽ2+nO-ʫK(fDBt2`ς8m}T1kouZojQҺf$1$V h֛RR x1$XlG3Jd]3w-'_,>rIW!_D aܾFLj/qEsPԶ@bwX*]KT!,izNuXn,r|z`ɬl@? mFEԜ>FoMN$ts:$>Eh538QT7@2Ov8N/Htް鯔3#DlyyJ؀BKShh[”k,~Y~ pF@ RNW\C'h]3#Z,&Ko+"J;iԘjNZu_ŃH`kv{0.&FfB{Bm±&t|bXz_QdwTBSER{ۊ]s(GЃbFs(YĀ*sdO2:u~rb?;i* \Hilߒ.*$f[f\0JT U :guUJH>Pfs!(X2{K;vv yU+ҭ[!3kMT`X vu~5kO+N1"7htӡ)6$}0[ޝidd9cУM=ޭHD> ]NuZ^^R8>mM9b{}}OtkK\ߩll#Uboؘqz0zFQs8LZ|*G۹]r*){=i 4&w&B3yz+4UC>R~,PI8~BDo&~,i2r"w]$؛񍄉e[øT\97D-P$ȩ"Z)D:sە6}Ht64!. ꅞo7j,5׌wY\I235}EacQi'%L{ [YJkA;H%;+Po}q5S3D|wZ~`)9Me| 8|ZEl#\@@IkOnQ1<F739~KBqުxaFۡtph$} ^ʀ;>!Ss.SQjP*~Y |)/<+z8%bPi+kX[i <0ȟ:ɼ4;_/3p=0u a۠&Ԇ^K|l:d8v-Q*6 0.ҎHucߗ&pQu!$61_[u%\gӆb Z}%|I~1/}f4:J{PiNz@VaBJN'!ÞF6mc.%nbTNETk4AB cmA[ 6ϚX'oUZ?ް]jŐB9{~?E s$U.g3܇}ȷ:j~Y}b4R=p5g-V >d HIQC 5PxW?' h5Kb͋#h@s*\MM#piw){Ѫzƛ)D) b>WliبOMNeeJf#=ox%O`j$ޡ yoGQX4=SDܮi UNtP܏ӰFͯi&(ԞЃ- 7FoS@&$Va51` s[ZO$!K= s7ӷ%9=W"δ.43cˌibG :a3{vE@_g]S)Pbihz 7`h嚞YaJiwXŹ촔Њoɪc<*sy4$0[+S$Kfjٙ?%XpԣGBS胫 BhnA*ӭ0_[C%2S?f2ʋc21)A=*ej@這E '9> HȜE;dP[ 6K2#G/5 E|h0큐l⪪[䡤 9~J_vg+3|sbc@ % a. F5^Rb+'l[ڡ}e,_8r6I0DHj VXXA-WE5)d-)=R6͝<ސAAK"6lPHٴ.=9T>:#xZ^>!rJS2ɶr" `t™ GjcJ1q;DHp2^0z'ȯ`)ܬj?"68I-?<{9ܨ'7vYpYi5N;C t2$T5I^QY\|")"E=g:0:ȕP[!g<:VkLx4YtV8/)ɻȽ93ڲr:iwTc՛+F7AR? M/Gy@g=`/heZFAIQATȿ ;RL{;{-7v/QN @w/RrxuYP|o`6q1PJfp{0cP`R$2{ĉE9- N̫hf_ڷ+*"fTOe;v$"]ۚEF;X] +YzC,"Bsk^겆ɹ33;Y\,t̖,ʻĠ$'K-;(|',vov?tYو K wJƁOy !8ZZޏSAb_=csMtNbd0 +E~V ^4f`nJy8OjX BMsӏwڝIJ%( A*X_.v"+  W,esn`mTR2!j5Aw/eiX"I.ifi}5&?Cb|vGީI@_s{}Ⱥ QDJg` 1 rP3@y/x}o Yŏ̎ ~ng^@FA'iZ0rEHMoG rV ͝J7:2z^gaV(K?5fwIOۘ7ueo6m qN lR~z  Fςqd# n[i/ w_{]1iUWnfW8hSP)$qm D LlIfUYe#~5O+tCQ}Z rQU9.r^fZRp-JsMy @*D~eD9DI yavNcZnsJIRY@S)KzR콚갪 'cVu-"P?v{jiN]&r\Sx<4T+͎X3SraOIaI_U'I/@d/OW^?xXM\ad`! )v$څZP޹zn7*W&nQB~śkeW"@]\ <<#XmCI;T=0ȝ~~WMF9cZ'F⹳-z] кHi7gUu<+'us 5d9Ng}1N`îQ2ٲ@lt~-3q1rSx\vIX5u?ZU|9)H%]_' $zpto 7J#X L?RqϛgR{@,>fvvq+1 ?[V1構@]\-2R7Y2F48+'( };HvdgX]I՝OE{[{6uc}华VY !ҎWnbu˔νa2呬Yq;"8*IS1 Unr,GMGLY J1qm2wjg&tHo sjVWxYjllGsil`F˞)W;InNQKD,EW|IqOءRI*~9-IIHMD5[ymMZՙ /{4,xC$SVLa$*NdD͌p1\O^aǙx)MYVH&C.P XLC@V<[T,^PQySMJRstV=>n5IwÉ"2=N5˙=>@J_6ꗜhwO`^9iiY{nU_W2b(cT3%qGV.[ ͛kP*I+O.+tAN<$;NnI {o_o5# tN{g-r~`Bh-A /r;kb_j^ߖ g%!(6C+Wf[(:) mZT p~PibBpk=sqPJQ/F5@oe` .ᓥ^yx^~U+#a̩Oޙ?͎wDdvl:bz U9܆`%+~f88M-A:5fWu%J~g|Ϥd`]C˽e05%a,#aP%1:<4茢y:Ⱦ|rRh1#(ZΧފ͋xVqM a-X<8"eA /HPzpLʝ;p~:\9H6UvKUNV*5O#pT*+ݼ jItM5fB 40sxǺǖ:8!eҍ Ղ$lu0|9n]KCH萖$UwGG~0Iz/)4>]HQGMzRh;tyuWǃBޛςՊl(O\j<d@SnY;ًb^'1rlnWoAՁ' +a }4?ИM<|>ąes~]<(K.KAchЎ0'f^h(]9`^:D=V:[zX25.E]n#ɬI(.վw`2ݦ%Edr-Ni<3>Et 'oDpVy2+,Lr0 JݼK&%4A&;Ԩ/q>z{B T Ǖ6~)w6Nhu*jöVI1f#&VRMwP ;bK J"8kMfz$FxLx Na@tq$AD2UeQ+yXa\%6U vd+Z5+SF[kפdl>&DUʉ)W;N dcHcyTBtf4gĒq&yR:0ݒ2 W-Z3Wp݃/5!+f|@PS5UHeȹcj_ݛ$$KCչO["yP6*NK5=1g$ RSMw'Fa=ۨ1,v4 (쏧Q9 i6MzBp+CrwfH5u2wK9(o!a[v KuzakL(9h`G=tY%``PG}!sɪ (?: N &z%Xɕ^1#2Ͻ.ťlH2;g܀M?[^FCmqPςQE_(wq=Zu.+ו73uKnR埿0DoNyƎn/=zK 2|}q*H2ID~,wS#>qd/t%ɯ<$n"JءtɭZ%r;k62Q ggL{A`ĂؾS$B˅f-mWmw0~_3EM3&iDekOڊZ$n^ ݘTXݝ>;754)2,r,^-73y~SOFpI:tW\S]E8P"?m癳2X#aoU$=Py ,ZݼLBY|S=PCFPHZ}?14H%s$}68Q&coo,x*fsf/!w6_QJ*r~^ %[ðC;:[`f핗S܂9̠So{˟q¨j@s# vu/Ѥ..T[r{%R ʶ}1zqy)($ -6#A-of=ȍ#GBQvguzMpzD}Ut&@6T" cO&L0]S8q0[*尉:Sovx(v~ }>*ϑkV^Z9cԫb {AD!\ %*-IP nvz$/,},BuiUCQa cR+C^6A* q~YidoR+Ж;esR +>SKn7f;Hs6$~CVԭ4fBPǮ"̡%t2riƎ@fGYB+T s 2GOYVcE|ՎCmW|Rh9ׅlJi ph>)41s!p0˼?Qi$.Mp,7T*}5t"kYħwld{O;N*}IE_*ռp 263׆J):&;6'>:"cZ:l* s^Y&}"6!ڀ@(X9*IemF/*vnAN=^+: -'ჇOTYނ>KT& y@Uى|TO-&Fq+*:1㾺bnW %h=Eކ)ܠk&c,8$j"b r!k#4I=mj$[@Qy/ؔcpÁp2c8Lf Pa+k!xsk[[e ʶ4?@IoO؋9׬w$+SL] -NχBV0~R[RϏ>|v5$y3դ աPT/f^]<s5vhImեd#X̝%^w}2=Q3. [ wz2MNQ鳭GgVSy. 13qsgkkІ?7 QOz.'S6I BiFNKUG&{% !YpQ+SRfH&Lx%PVJnT5|]X [v`{ShZ·bww&N۔(@0f\^ _X[پyv=Kb҂fw-K2,:c#A'ymD4ۍz,i?]J%`>M8@֗ʸ7Y"TBK{r!D yQ}UÒa.1naqr̺tr 2N9r*{]98i5>mͧ#V&.r~3y_ZcGS&Zg| \S> w/-oVui6[br A&\TJ HlQ*_ė8 ֨S~'-~f;3Q]u27Il;K>!@ֻnܧg-+߭^y]f|ô(m8B~WZqA.Uff>jmZFru0ep?`Z u\jPE(i^\mk١APW]?"NQ3ȣQ펹-19BοH0p.fz[CMC-g,&қtOY4ZoދӏҒUkR%}&bk쒹QUH"Rb% N }Hr]aB?K#U Fpq<3hyfQwn2w!O\ئ':Āa\>XTa?fX;Pͩ]#bVUb*h9j7w:_xsA\ 'p;_P,r(s]`P}=rx;{m\ܻⲺ(o0/±)nl}_ڀEyM%何&xwjik 4D*Uŵ[MuHNoOӘ?'g&# |Os-; &{dIWȎ_`on?v6nKۜ t۶@`%w oͼ׈œhAx`%|3^ oR0.;r;kKPGWc"Dv}^_g7{_N[vrWU5՞#b(5`I8"ә0ࡶÕtIdu0j|s=]͜$okaWp j% ŭ/S4WȊg%Gz.VM"?a%9NttaB>G>cEbęKdt>mzc?pk7+I-4> ܽ/OMVjG1D39w=T-g{/m ^ueS[O酵/L =xևӬ,Fv:z54ˁ W+U>H.4r3Shg) #IӱHj e{J]}v%[)2/"hk{0]~3^'\<ؕh(sAw9DDTJD`5Qr,@U  m)0Py4*iG fg%Kr yq|g)ih#;Kk_0n KJS<52 %@k[V7FcQ z^c?{}]X͸,^:e|З㕰 %+A7CM+YT\g ڸAō} FcDS_|c0c ûSh5wO&ꦱ#:YǨ"j ,FOUJwA,^k"Dr@f%x χG\8kiW.gVg I%[^lTN?2b?;jo%QTGq`SJX KF`Q/_[Kd ?G^?(2?ĘEѐޱgX,Bb~ fq"0E_D]. K 2$p, LZ|# Xg~}T]DQa0yBU`+]0ZWv#D^3&%r?2iD4GT-S3dZFXa1,t}M?eQX@9~ #]W`/Tx52UUuPV[ۤr@ςy2p]W)]Gً& =PPmW4F TCWn! 1`<58)/cWv:犏QVxAJס3u2J %*Z  q$V 7 9MHWnsJw6#qHc"ɎL.? <)5\raMYj+F$h!JmW'"^%r4?& !{7w=bɠ[Ew\Jt>q<Ͼ(7I|;'X/4(Jm4ebZxɍ@1A~EfDnvky@8j{:?N~b*Cᱵ[T"k&aBW.;%⹽bf(Il(r`֕o=0MfĄjeI5-%n3Jah;}%'}9d& <>Sq$;șL Q<6xA(4t^6˕ۍhTaJc^8BJN<5BX&rzV h+"&Dog1I62-맨@|}T}転)T.VYWEHaBtÉ2tV&cB< 1L&OkZu _ѩA\G}췑.4؜_uuRd4I\O7fA+e]&T顫pQ;tz{jcirqnn%e2oQ ϒiq,%f֌zծZ$\*cW QrCy.&F{]o oL:)im0M,s爎_{7F.&,^>|eOsOar%1ET=m)Ϡw핚Ά.ǂV'[3CI4Ď闉!Z/->_A]m%@St3b .٨PIY4CJp%BRMO zI즏d9y/ΈvL͝evE5}E3mG?4!BB I"XZq(IN ۼ !  H%.T1=2{+Pti7~o1xܪK" YRhYoxͰjrU f vM#|m}LP~V*^Bj-iKŃkB^pc{cDD?m7O#vq{k>xxqaq v7ԁHO1m(n֋"PU!;!tSyPKN|-:cZm 2٣\ K+$?9=dBH*q 3܍ "ʠطyB,۩Iլաb@ Q[k@)FʛFT-9+|2=@ШeN\! J_aYh 4;p3hUT0Hcp;];rӍ`e"xܝv`bu% >Ŕ A='q&#"ZOE1(Vց>J3:0bdݐ9aN'9343ez䨙~o <1,wz(p 8#rN!*Td[1qnrM4?UMߢcnbG7}K>||m,c(Z*or|bp)$,D>x+ӗ5qqf&1U $"Noy[%;QXqKl!!P$-f7obwI T#t=UW<:++vrd=@a}@˻DD$ g潸|mp>]SHqcDE(ޮ}R)mvXDҕ`)"oc>rd i `}\Rujv@m;.\ בZߜtU0Iգ]X7`#8ĬIÿݭ\qu%ӟm+r9؄eb>–3DRhr$:Sh%YUijd̜Mv6פ^ׂ ]Vީ;>ƚ4m^c덇F3Tl' Ir8870]ܛ?ZA F8 eot] f}kNȉ֫^KR#gG*>*ˀ &w{'Z|݂)B+aN*?Owx t?/ G0"{ *=HzAB{qˍ\x"V)E*[Fѽ74۩?ru)&;er*d@k^(^gf," ͧ#$Xo ˴v459-/ If DE=`FHQhSk{Ǯr;%/A~CfFFfE~r\R}`#TfFëHFOQi{N CWt~ 6bȔHi$m\8Rٸ}[kCU2]m$P+ğ ,_(ooe 2+] i"%Z(ô{OP[١}*c4UNR:-)4Т6v;yg+8[&g` ok^iD 3V~XȭfU_P|]W2uk{O磒[@p WH-O@#&aDg,$ACWDPS?{k|bhrx')a|^ {ćl^+w? ωH 0躅qkVkvI$o%a􃠶骢]_X;MѺVLU'\( (US0f$o-ӋpܬD$f:#,x 2}f0PD׵1cSRQ֢QdWyxQix—]MMXoq/|in<HwCqvRF)v|5Ws\yvsm0KBT-#DgÇC0w9ЇG⯘KgZ(NtSO4 @ȭ0yčLHZЭOs6Il|7״2te hfo#Q T:`mWO> j ]Tցa-jsy\?#?*=QJ9= q:4*T,W C$a-4tqVԑ'F<#QRگ,oI\'A ZN'N[YD3#6[EN7e|@?2'xΟmsw˜U uHYW $Y[/Z$qn=;a EH8& P>_,Fm`Y n>|~*K!lUw$%W:j7㗻~KQimّ!</fj_͖P4,Sտɩ|C;ӊEh ~7Jמ8h?nsv z=6(>ܭGIAU7Kz?G,1ROMeiZ0Ȋ`fᐄ(?_X.7gYo (LK) 6CJ hmT-LjS RtLn{Op(@ΤMu1n<7__Wd?B/[܄ZWl^~nA=[ZOdma "oH yg\83j!6:q.;礋GVAHoUNٺE^mST!~xxHPK~SZj9I03֘帯ߛ+JPLNM{\@xUmQBe(tA`0E1 z' _%Rvul66UE*f\|iգB"?%2jhlBxtwmPfHmajb p[Ue媧[Tv# *eˤ_D$}PʾؽS ۤɲar1o8Ĺ8; ?qEh Q5?q<$"ė:ӍfUb/mSBߘ&'f9'm,2l7>LkI_5}:'#*nw%VIgPPҌ_k6d`RD,~pPxdyh@-̏)rL5CYFOc!x 1? ~3s'K T &-ΎӽM>ĤbqΦrKO=~ pž;َd&G&ikttO*Z1XۊZAT7Јk4%ZF: lY ]ì!HQq΁Øo&~X̙Z\ZARrLP4,(3];_8ȁI wYjy#7"!k֖n.T +?GNqR\&+l>6hʢ^Ҋ%~ F_QxP’kFq [(&5q\E?#fC.ZN`Crc8cLjZ@ۢo{l$VϘ҄$u\w- ͽeIX>f2/ ҶwK0YT3Xbd: :,!K c6"YG%;rUJ^|P(3cdl{ZCxlm3j GBfI ɵ;uSAn؍yAsk¡@檅:WʾՎ8o.)|^nzɻk.[JsEx"5'ʕOkI%.m+̢4Jhܻ5kluǹ5,菖a8cV aa[@xwՠ!Qexw& poLܤ]KFCf v}&jYLF-O約k*=Dt ]afj ОRmWQXsQ|[߹Nz#2L%t1_c m?W^¨p|}0Bjv|5IYd+, nxTw8GX=j||cl_ԻQ(s=T ]%DQ_f7of* 7,3G0hu9QIF '2#Ղ' r-K}MhIwt?NW{"[3q1SZwEfhHK3$imnՇ/_Kj;SQ8)5P N|iޚ_i:EQHX3,FS 1W>*z 6$"K~*b 2Y Wv"u#5 ċ\mOM_2*9dU)\ {*5>h:{9FZ+}R˪&EW~IX^ ڵzfNǢjɝPV/݈7R):UG=ϕ( cb! ?uفY;6ݤN5\<,-,p!S35h!A4`ꇧ7Ў:~HeXE5Z+2P9IVڒSEQ52YoKƭNc5լ>aE;XQ*p?:!J;+d5)Le~,O謲i VprTݯlANM _R+ ^4:V W]*_2;Icы%Qmώm융6~ԪJwM,o*1NI^sP-lez ~,6xh\5B4җ\EoYélvL^IY$/q>g然٥0l8?6Pc-슒eߺFmin5 zcp£ 1&cIP6nNĢzDﰌυ>vզ{֣ZξcE4bLYJ!iP.*"}T[ijE]@ e/QvZYcJ)C[sT3tXZ0IWZO#7~iG4gK+b|sI9؎ kćɭ=6AZ3ާruW0E3*y՞Z٭o^c{L'+'y7=M3  e+u}͕ŤmD(܌YҐ! Shji7篏.c}3:ߜ9sF=saKfK7)a.]U:kNЈ}6կo^4pAO;1;B!N5VyYAiIDz4xࡰ"ߏx۱]q>oʭ0v޸[KFy4(wŔ,46J*<`f3e5uy7K,2~ gqMɶ cg` rW.DoJv&- gn('7\ޮ ]ʆYBgXq 8@MؕH_ !&nʽ6n\=(,_mTk6o+"b1'3E܄ >EzHZ}  +>#@YI+k'{yh=m{:2(Ap-r"F&4+ ##!CQJI=jq:3Malt`Op@`fVZɪe*< b5| M|j*> um|_5R/#R=);7uDeKD9Vs[9H ݡ|ѹsIpa܇~S];>;<-ݍuٮv㽕|o7`+z}%VlPV2zz_E{؁)5`,d -o)`$%[{@-"#T) m1K`gLL뙙Y\lj)$ 3kew'+*BUh#+WF  i(P9a7yI$"P)2$O2Rr l;*X N $^<)JG-組aJʺkcb!8+ng1셻QCY_~'78E6WJy/W`bj4DKCj ܨz *1(ژ1{a8\hI> etk;OUÚuK\+=(3/?9c ڢ&N4&.d/ȴ7 A@.k( LW:gPnVɯG2T Z#J~w3ܶ80Y$ΛNtu<|eBSp*$֌Q~7IqXQ7Z1azZZX.Rbh }a9gّ -JP|LtDb PVamsq_.hppG-鞭Q!"e1UN˱39 2C_{2iͦ"ÝdnMZPZO !Q{izm3d.I>WKi; 0`qk}S tWΘ}FY@w 1cq}LUgUj`ߥU#<45 bwBH y` c <Xg /uUjBiZ2J9lfGJ9B~<5߲ٺ&vWDiW+F~b!t0zV)H`|C $: e:݋yDd;eTލ(rz< d:G0[G^A˜&|Jήx>1ϭSׄC=Yئ"boa&T  G'0w%Aqwsb+0$7/[%ݫ6VlG_ncz$&$pÄ 0˝-3Ceb!!#OC1(~c(s@M,a!?vyAV"x,iq@Z}U'Poz79q+]Փp;sba%m1f𨫁=Tu\Е'"FrԀ^aH/β e3x/.sDBr}`v\ː؂4R5(KP4^y=uGHY`Q詌&ٺ3\ u&gvbnE#/*ߥ,_$ G 62Чg5HYF_EAfsV4ܼSUgU&*"#iix X uP:Ĉb`6[]ф2d^V0Լj8{2ӕ_,㫶;+45DoCe$zF_ѯגGgr_Gh~=j؊ʴ SKĒqK Al:3=/XKOً{xasEYd 0R-GDnbڨH1_e&r*x3M1>KQҜ[f5@ő'Lpء?t W4J_KUm08ԉʍsK8UЊ;\{t\%63VG˽٤a (Wip+Kab Q+\t-r@Ҝ,-Ut*znpEH Gqڏ{1Ti)ScehD|Ŵ2#^hRG7\#f8ɿpϑ.S=x&p+ӻ^FBnɦEgCc:¥psْC&&} E`v'$P ώKv~9?,^xVv`PCf(00'jc 0<)"~&ٞPBd0\H) gVv>|LٞWJUNұheƶĦ75l8Ƥ{ȂZ70)R:x]">%,6n%^(AG:Xu@P!{ LۇgB!dKc3Hlv\YF1(JɔǮ r|s% =\ liH.ORw& CE=d w%MC` %tK-2XJw/29Y兵*%fއԾ-03h;q[P]5+:г=IkByɔ.d tJ6&frxhk5:r`?}ڄ8B:/y[o<I{"$K5B[sJR4 |ӊ ~x ә;ϻuFԢ=8ܸ*Z…8XE ĵͣG$)gs;;SMgf#~1Jܻ5وYhP5?$!X{SgU`rF+9canIoi- 2eUPoXBʉJA]U' >Atl]9lpH s)\0IR?|lJȬ[qǽM+^ͅ:Ip+C@t+dp8h"{qu0.^&6(ĝ8>M{\#͙X=T M mS`424J*+ow@Z3!uTV # ;] AͽFO e:|Zl>b{7ܴOHˆ]D)Иk͟{͕ΑKU\4S\b WhW7+`ν׃W(}pb C]ŸVxG/Cu6tS(f UG>޽Xl"[5̗\fo_lxOi:ߞeߔ |G} ^>FOwH|օ-C$X3|ݦ#!"֙|Ii\& ML`q"Bz٨F?Q/і#_2}CZqv\+ gcbbu$ݘƓBd` '޶1p8 Hcx-yzύQLX.D+!z gl?4rwv+pa 8FNR;SWs0>hChk=N6TrV`۔!d ul,ExSC澂[W`3RRN<$WUq^ToKo/eh/ Ve!!,ڤ\hdq@St0[N0Je`ށ\cfuZo_ $̡(oLy?Y3k}]>%.OV%K?v+{iT-U0W˹ɞ-Fy?GKkD` *vz@jF0 2 Iyډ3:5܈9>Qc68x N~VC!(Ǭw7KF(U/?5lxOxmD)Uڄ,ygٴm-T "}*#M]|HOi;g:G;0FJΙ[J>Kf}zV'Owk.)3A4; TgCݻx@5%FQ#B4T Ѐ@5b팩݅]'&B~HaSɾ満 ~esd|Vq+R(WPdkmly2̬GQ@X(HY7T,[[bSjWb:,3Y5uzVlAM۾/@%^,ir=\R U\.gSFTqSwB_$-݂cc{ OXAj2H=b}Ӄs>6~7Lmjp 672*[H|?f|C)g'1<1 QZQ}˭{nſj!JjV߯≪K.)5wr+܁g#80BU"/FE2=|$ pE/wȍD6>6nH-΄j (dWzIxZH.G<+%U2npZeǂV4<71LKcPmP*vQvLAKcљDըLh-4YYH)@>ɖ; BM 7TME[IΩ@~=L*ږ^vm=p?!jo)M4{xWmvs)"Y-\οk\56  m̪. @ޚIMRBD޹`fz*@mYI5;U =` Pǰ{ V\fKxqܖ֚%` +{K5*zC|Ks*B641HFÒ# zZℽ]G8id/RclCg8uMs"O3]Z2J31ha 2m-V.yIq6K,rTWh4ef;eѩ!f92Oiq@F5߅-&̓rB5 |-^ʓی[~%t¯?(b`cJ8Apr5S;0s}*mw񜀡HƱH<, H_~]Ene!whmrzӚ?qM"P^a2^Tr߯WMڍJƛa|rG5)RѮ/j4*p.ß[kv8C:gdTC|<< KwTA0EW OT|S'4L,w(Ԃ _x/e&HsK08=ޠG@팥v_ AIӈ\h~ :# E^jf,g˹@_D| G-rn_P:ڈJ +-IЮ͵&:!QF$dYEAf 衹 vD?HĘ /#`!X'N1}bA/п4[u,oI*v95 ֶӆK+)4|nd9[ &hNqJu٢ƾ2",_p:J֌>(̴Ce\,z\`k%D-l%VXIBwzxfXdՁX sx;4tY'RU mZv.$c @y +) {*\a G,W$l;&^$S]Y)EkӫׁA,0X ^&*iTLImbȢ aY 1n]{p~ !~}btlE)_jAS#ww<$mx'B 'gtaVJ^\{Bw v"n f׾iL_vIɥ&AGFXxA 1^ܧc"/sP[`qDTX`=|^_!6kǙ8/jbr5ђF;FAN'ZU&C;|Ͱήf4 *;/ M)f鰫T}S z176Q708n+c FI R[ӆ> 69jH1Qy^ImFj],?tjϺ:72k R3)FR_F,Ld;="D#[||(4&\\ XAM٫6" #BsQ>á`&zןn_z ݭ.F%ċ mސ'eqDqDZ?4bDR=pjކX `Hs؋) 7II?PRu*`U_MNXK:c~iZnaD^Qs0\WGĎ[=&K3AZ=F#Y~|}."CY)k.h-֮dw8"=f`Bػ+WvUy?Ff Ǒn GIW1G :5hO`\h`(0.!>/Wz{}~\*Fo[Eڒ2V/ ӜUPu TMʸTgAlX!#X^F`9pf{yXl zD+Ѩ -Vo|߽(](@ jZ;X;`ynVAI+֦YE` ?-k= Pmkb -'yΩ+*MG&E_.CMA}αUzJ_"7K:Hw*ial.wk>%O6*;t{0:o̭kcGjy=fY}RH' +f= J{hTv޴һҸݣ(á~@ #+L~ri_#f8}Yxk?ZzY paO-o *@aITy^!#T"HIo~K?.7T 9e\HBˆZk^;UTӷ״CKsU07: ރYՖCALk;:>Ӥ5.] cX*x>L ΃_%xQ^p!,C^~;>@H;2R>! E-$ʡh?c~vh>^ζT%0Mf r{u+wgDD8e_ #7m 2Odo@䋅B5KmKE[)̊Á.ߧ=^FH cpFA0vq}a0H+\^aru&4SD͠*dT-[U&C^)ʂ x%6Nq"H6s(hfX |~(9{a-2]88snOEuwZӡ H}cb?[,yA{FHW㻮oņr|oXB.<;qՂ^+-E@Ha0k+fN挂J:#yt6j`LJ@XR J;O &[ȭ+H` YZ