sssd-ipa-1.16.5-10.el7_9.15> H HtxHFc= ?*}}G(RS-v"$vs]+L=@`<512ff40b99470aa2f2c7c524ee94246e392cd6bdA"c#%Fc= ?*}} @lI!w!cuCtz |>>0?0d   ; 7=D   8  8XxTTmTDHM(\8dI9I:I=)G)H*I*<X*HY*T\*|]*^+b+d,xe,}f,l,t,u,v,w/ x/@y/`Y0Csssd-ipa1.16.510.el7_9.15The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.cϼsl7.fnal.gov hScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKu&/A큤Acϼcϼcϼ^p0cϼcϼcϼcϼb91010ab30225e48f005e6ff6f07b461e5652b0c335cb9d5e9ffb933249526565917e221d041ea8ec5113eba2a89ae930a143ca4acb0abefb7b62d2d594cd81d8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903e0fd20e5f158912bd03986bb56e37a10bd6493e56811eabc8a2c2e59620560783d7466be73a05d70198be82cca76a5a244d54b88b05dc7f93fa246b2a3201bfea7217fc897f551fb91e3779bfc1f39442d9dc1937f0a1e4e77e020d70d639643rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.15.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.151.16.5-10.el7_9.153.0.4-14.6.0-14.0-14.10.16-20.el7_91.16.5-10.el7_9.151.16.5-10.el7_9.151.16.5-10.el7_9.155.2-1sssd1.10.0-8.beta24.11.3c @cs@b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.15Alexey Tikhonov 1.16.5-10.14Alexey Tikhonov 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z] - Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z] - Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z] - Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.151.16.5-10.el7_9.15libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=881fe0e107a00858131322f99256b4a364d3bb88, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=cb6b90cc96d70f73111769bb57355f66f6383d13, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRERΪdm5S8mhy3{7}.~MKڷ]lCȠdِ+Ffxië.? @v%!oG{ָ7so;e7(3$zzPdC뚪FA٤ӱ d&rE BX2Cj"Ws"qBmިk@"2hNb$+a֙$ZZa+b{oOF"M \d E=j8Z JV$uL::n{ W0 B _][l .źlwZ c_C@ϡ? 5"a18)Yi>+s*h4) \KENg^a[K&3J3*@^l@53ZucCrvhɏľ=Z$(up9|ŕƨ̷rךHkv\渝$vJ-_! ɳ_as^/4iW\ hﺓI~ln6KJ(Ar6 ֮|4s"4fYk{e,×[-I-ۏ{$$?75GX2ʫ .o\%l8,17f_Qa~r4E`:AA|ףXE?qS~O%_u~6 eًi)1媕Ձ89';=ٝD5Df%3&b쿹O~fP=nD8;*r+2d6Y%L 4RJJM; c-1@bCr*pلɱlHOUR^zj.Y;`L;Ug.}Z݁ *Q|L\Dbac'\n!#_rU.WFVp2+U<1ñWtg H#8{KTaǦϴr5~Z;%^v{5ޏL[@IdPw 2חK!&]&BkLrܮ7Wki) Ψj HP@M9^(=t|YJ$b>Br Tw3ָLi?cZuJÁݓ_1@URy>DEI1mi?ݽ $@XɴQp3t ]2[%oSV+rԂ ud??sK%{-Y閦jAږ *tIR@ZN"(Ɇ_+{IyیB2VEw͐dWdD6/(IvD917Wh5H x$;R_@QH /Tz|-ߏ[!~0C´T5`8mT-,GI[ }'X ubAIX,҂UEl2̻P/γh:Khm-~D5DïTD7_nGׂg%z۟R/468k ")m@ VDUVU5ALɁ45TGW%+ Tzfi;рQky7cR," or%rNJ E 璗UIrˍ||ҧhήLLπi 1ubO:/^lI>nL\$%U:^3`6,Nr#X4ڗ'aë;"`o6]"ЀM)Gǥ8_VEt7*w̙u_2 7y( qcs[peb斈 1:իb(@xGJ dtۀ[á`lA.ueRgkgzIvYHT>XvҤ,;(wEfЃw9Ti_!]O[eJ ?MWkke $( |?C;Mф/kV/-S"6b < тRE;s<uN߹d01AK_'7HɊQ#Muf;UɃEKL-f@FǾa_6ʑ(;w _`͒RHmtuSt x}wgSQ %teq9l^jЬ ThXUKv0EYlOz*QxVs"2e/"QOdOf-30rp WLjlI]8E1{n6])k,rF9uHH'eT%Ý ӐKD,4ƺ}ܜtqA(~H"ﲄ Bkj#fzۥS1D(&{>b\`Hދ6Mf4ʼn3/3ʟ*Klda9cf=f/dC?g$Y?'_k BGOy6LvY`J!W`(!2**+ϫEo6(i-7bOgbnct0dP1E? lA {*}_uq{nq3 J}nyF"D: oxrsψMG2.p=ݏ=>W;j @]Ǧ"5=a9qKCxMqtGbk,T%rhG{P*>tAQؿ 4`8A*Iɖ9Ixv6%e^KOс yDd:8raY߮gL+ceoM;#9~^HLq,8.T*ݰdJ+\=9\qx]>էfkIA6dnm _Qa2 (J=Wx +ply#-A5.|V@m3=ϙyv;9)֊P)$H^aIR'Xg͕=7~Bw{GgZ{DV*<,*əacHMJ{' <'0>50~ѻBO%Dk;i߁Η%(nG1. ) تx8"RNj.s ׮颢߂xLszV&V˞NF0RF#H:U!קx}[uAzfe l|aD|9[>!V>4x$Csv?뮌)"lkFOfS.2 ?ݩd,,<{67V0vL퀿S^3Yޡ"9ʛ!:<Rd3:` MǸ'E\,wxqleC_\RbpqjzqmsGΆ\d5a y ?@P1IVbE P40za틃!\@cIuVC&z>9O&ѥ;ͼ-yLT ą*!Vk>yi8T.-2sš#/  !&YMcz #j1EⒿu?Xߏdߛ/xem+޴XGWp -3fBZVxH S b ߾]39Ec=+ߊR2]zWwI-HDGg/{C0Qw;!cg܉"hx?ԟiz!M YFdeܸE79(P)AAN&좂/l%VG rmmO[Ý<)()Hg]E !n }BO\`BE * Ǡ(B]GW+RZIMNa!%%qRh-JAV1cԁy G&HT}NvomV"ʿ ICe|m/b cs5 yro-KI,K<TMRᖵu6ی/ ڋ cM,+3Xڼ*U-Tҫ9+,~?иp<0oN-y7h`x-j{&dz.#$=3 S6p.mKEꢞ+MkQN$bd6x5S-_mYf?Ģ_YI?CTlѻ.;8biye/ } {yeZL$cq_l$)'TGQLGW|z*jt4\>1r;~[CDn"[PSV F<>f⽽Z;ȵZf~I0,WOƳ"ﻅ(*2o1WZ:3hл E;ߓ&n{m )˥pw0 ͤ-N=6€W&5]sО3Fbn0+uP@q:bA,xG,dO9>cD[jm#;V 騜Q`; _jDqZĀRX}bWuBa,KiPz o !07/u7 SxUyb2>uM B>HA-Xa(1P;1qX=lRHK- W@_Ӵ"ez=z}ayhP=uYH^AgΥp9@+䍄ץ%9'1–aA0MUa 4mQu{lZ4v|$uH=4/ ~*(tsaqs"Ӈw"m"&dV.-?}wk!˒FOQ_,=G/ Q&pݫE~ڨlh-PV"h)^-K?"Py+ͧ:tR.( $nɆ츶{|K{L1DJ> =u翵:Yw#,Q;mfB;ytݐ%4wCb橩Ez>Y[VTZҢAC[lnsYpP:>s.!m>bFF&7pya~w?]}B%?;< VyHnB9Qg¿HD_tצlЂQS(Xc0,&OoEYm&T/~Ƥi*c {=W5ȸRq" 8ĉOd)5xlҟWn1_aR1(yŨà'R0} U/uہ peVwTf>7+H6p[e'!,ү A=er0\3\T7s*2 UUREFF?"ΔyĆ$qnA\i>~?am/ɯvY|]JTS 7417~D;A~67scL׎IW.Cyh֓& QN{7WWPZ <i>F  c*\}v9_ɏu64ycDB' -dS`uI0Bi42[P \I`E1*!f(JW1ȫQB;<[!ŰkJ5`zm>Tf:y2|L]m_XB?'g=z>J5P/d?+f6^ʿ>9'͛9pQΕV "݇EZWLIzOS_qRBYNVl!E5f^$%r;uJK{:c$( %p2R(b`~fFz|/[7x8uȘ̜<oNj( )M<h].^SLjZg7)"fe-,ncN>YYk=bd,rxwB{߸lR%)/42x_Hf]\!j"nU!IwTcԠ0 _Uzg'#3G^|6TLI{E+[?0\B38hjA安%g!Z @L`HWe_N~~s]XFe ` upy\yƨqITc{oihSDy (?dpjW  }9l]~@ch?r\tc)'mI$_-T[ꈂUmld6h} ^^Dh[7Ŭ] y*GtL*HQ|g?|?$pDcؘ`{}T HSd4./tvSCP(lMqmm f^Qz];oĂbKVC Z6MO_K䆩y#3\L=_} Ěpiн 9ʍA,Jhs4fEasViY~4FE^L[V0i.'`;jh*K'>iD V;E9)_ZּTJ*0F>,lyc󣻯ueЙ 4 ָW*ocח} rPA -+OY*btZ͵"Omn ׼s {5<Ա0\>dZ9w%rE]:̣6Lk4w+<9 -,0h7莣zp.j* lM-Z .Ys,Tt"ʿN/ԁ{az5۟_f.jܖѰw4s{Hh*?'vT,~b}'X<)oZ/sR]7^QcSҨ8 Z c櫛ms/uO#S섫,؛Bz1%Oɒlj"ɀ*i~WT7N+&``c5$v`cw#4eɫC%[#/'j*NGpd PJjxF+'s9<ڔLPὙg|dzit V[I Ssy7uv>7R5;-YwT|cIoEw 0? =0:W![x&X^5~Igj^rGA' K}go26Dks#3'LFze02#I=G:¼)x%c:3,rw*RxM{xI}"Xo*zFK ;><~68Dȃꁉ2U4clXye3fJċSl jCgm̩h^xldDBJeF^KOwkwYDDUJlcn2{:VP {!ޡenl(S"UH؜r IiVc.z%hہ0yIrҮ<3Ah.e@[/pevH T]EsѧiWQCvrҴx13/ڴ)eJR/ĥ5^tՉؿsbB}6A7>4d#At]jc( |5O᫪b,Iv_Vxw%`&܇J-'jzJwT+.#l);d ׆d[T2H?e]8 09mߠOeO\\۠k#";PyvmBW|ŀpQIAG2z#Rt r*=7mxZDO$t3ՋC6i:= PGf}wJ,^61 Inac){"TŦXg>E! (@$0k)IW,pc2H^r9*kn[̟JyVu:yhfP-wGe(QPFq謵-9!g[\-0>QM=ϟIl]+vR}mPt"b"Pr#{gpJNjEuRCbh ȓV.$)z\nG`\7`e:'"ȦrVS UӸ x@,7@P;4kB Y@y3AH$i a#2}<=Y$d5t:=#LKm: C|s %Tx[ܹqrf4C] C Ue8?wU us "a u 穽đ3 {8/v:V&p.  t^[,A0)†=AvFmc $ &=V HUv Xs%قX5rpItzb׆CcfIUVC< #ɑr<)޳47޽3}R!IDDx|5#$r K I*(n xOUI3Xg3 H!88k5CMI!Ki?҈˔]ʒNdIrsQbԾk9^ɭOKJPcy|U'-9\Y@ :co#*l2-LC]>RNOVBSf8k Wc^}%k=ǬAUKBHk4jLש0lP5O^V:]g]cq tGѰ7~ RӨ"G+ a{˜y+ |W`LeO} 5${)[{nT"ji>f3#x!2an(@:#ꞐYY1Zp  [*9Xe_RWW&2Jӱ=fi%ְЈ擉9 wf:XńI q Lt6RfKn$%!8\{YFϼMQ 8'%6ɴAeqWAɨZ^ 8AS &A>؂X*y}G#JF6^q6uFpfJƂ$LCo1N41cp?u)dB w7mmoTaՔ dOEDBX ,:Ƀ`xhx! 2a/5M_N53j`X һRY]&79@L`7,gFiB`媒oL@w.9]P $VRkwh b/S,!@69e3"EiӜK$M8 Ǔ]ڑSkN񋋷;Jaa6lg9)oU7Ԡ،8ne^]<~uro͌ۦ+wbbnULe>cD3ށQIzYh g7hcP /G~9(yWwuuSdnBt}6{@%~@74yOd_)'oDŽOOQc}?rՔ5~C;*1I`^f(> }ZMA^q@lY$ K'Uq<%iTz_^Q{}^ 3w/<0R>!ʙg*jH ˠ6o>g\hgӊ|z+( VWX[]y{^&?-~蜨jJ\Бq|ߗq-3mN;<]7p( &!k}@z|XFce?oޗKʂ& ] w5Z@94ofb(G&Z~vooqD1ľJ2jpjs !ԉiy޹r/Bl0ie'xחk)w]$,' ZhG.O$'DW&Əa*Pz'=r(m.:Å /`9dK5=ZcxH~=Vl g*9- TqAC0yFBjJ++zB@ ˜1̋ۚ, %Ҁ~4gu;9_NuʼnQIMDurPWr{rv}պ(y~KJvV& dt%ѓۨ&<QG|F[f)>3ELƝH&MgL焄M8%bIBE@:r̈UI]ȱJ4k- -d(ưPQAA$p~դ]V*j/p-dK+cpF5yHn ]{BQ'ǘ#aQdB¡QO]wl[$EN01ƆwP[#ls6Nׅ i/ckzG_"/sו mVY\!8 l +bWj)7?q@1nqyp#IV77#H:L R@KAy|Y҃)Z"L&Lblg.ܷ:=`ΛW"Gc+Ʊ m4︮)oT~LD^nammV]\N!CeR:*?tLyZ?Ӽ]~Q6 .{BX\߽6Z^Tuv%4^L;fkhќ % A˻aupXkUxB%YK=8X*҃^`0 3 rmQIǞL((eM?ѓ\jM+V)͗aǿzT7eQ$kG3@H;2h+%i8yQ ^n;>GIUU)=yU*B"=]`$5 BZ Pfʺƕ]tMΩAnj*C+ R_:2+NVKsV< PSm їҼ; ImTTKJ+H| @Cc9vӯ .$(Kgy㨧 u1snTy29L]j3<񸉿/c%Mu4ޡF z'$F9 |iZTRg QcF)躚jvy8~q=w~gᘹRuhHfji!d6`GgJr"%wZ`2D@zhqUc> 1d7;jjzV ,@78]0Yz6lĨN+ˆHX5 :N}v>v~rddV\9nlx_M 5,;].ڼ9ܶ@^NQDZkuG׾[6Ub )-W^ԾL9X`P<ՠ;V{Yۍ0Rn(\Y! %Ck0Ce1 ˆSEE{D2 <\2 ޕrEu6(P=Di%U^B4Qr{A3]"7 Įbȓ\]itV{^NkW8aCOG&α!ښ#W,>1 0-T'-#7ir" 0yMʸx% P)Hr NlMkGR޾os d5杓w1"!9HX3EK`B:C~tioY^)^H`FūOM_gp5KjZΡd^"dt q  k:WiEnÏ+fAnQI$O5H`LYtQ0 &٥0?kᴁ~ji{})Ts{@0xo(ڄ~XcrF߂ؤj4Ȫ)sm8J)"@~C(cLY\ϺIFThPN[Hp'{ Bs'ZLN>T6~/^wtf!/1|>Z,PӒ<Yg{ j|ۄ[KIWv۰.AkF&T3kzB¹RYWiR;}q-P"b [{^HdV9u^=JN0~QQ(fd)ܧ,~]b{b !7o2Y43uE?ȹHa/N y6>MIL 1wyqS3cXVgx=bJ_y!/jÌKB[|h5Eb4ϔ_+J@W5TaL%jT! fFH7#!ϖebx?бc0ӣEUs@33B<&8-]h<] *yUYC=p"jjij_@3=)e:Հ5JCG@՛g efˎ_-M1Q=M@5GDd6+11њ׬-sQCK]QEQ/9< _ 0Ŵ.2bs9S?TÄ*-̕g`#u_oH 8|,Q7o2}R]O3n[B/koObɷSpZ1CNхwa2$Jڤ$Ysۺ[-:=W)SؘaÈy벒&UJ}lMGEq;tS` ;H5uY׃'/p9y5ٞ;ġPpHkP[{R nYYĿ9t"FY6[ؗBzNyq5Lh%͘S\[)̴{媭*sJFW`%%ocHN\>/+zcqir&74%5ϭټ,s#?iX%c&nh5GKje5ń/'㢜D)3#SbK@U+8rw:3!gn0M\GNuܺ6ׂ?*Fom !3{x{M;sn:DG {2К5Qmp:Y8PJB;ŧ$iOg8մK;ʸ$կ+XC;ؑihQL[b?~r)-x+dUO4 ִ?qnm*Q(/zGc~AA NJoB" (4cVHp Ԭ'] &¬ ǜ{AwVO$IITC>H|n?X0\]EUbz3m ˂$V(//^u3>Gw(!Z:x@F iI.5hHvu`ؿA[]n~2j7+NZ<؎~2>y Ǝ#) ǒȑw (/jX [+OC`5 h0˧!ꇺ]zjs*e\=}r]Zb<ゟޛ(/"3[4 >F|*!Oؾ8`Us_)t z[ۦeu\DZah02hM W/I))$=;ЉA^\]sx똚ܹf2x @ܓj"Q[ ܼ//XBnYe# 4?Fj{UaugStP#עF g@ -%ڡTZ&_]vH 𬼜䢭L"|avaݗ -y8q˻;;Ch)aS" Hf6e^`,_za +d24'||Eo*\oF-UfAXu0" :6䀄c:{LB˘#F=C(_3't(nFK|2BRb<8f=2*n٢4E4xhD=ҡ=|%i 0ͿbsarDSo.Գ+'2*ҥvJ Ol4v/] ;l>VSRPnU;>ђKTBzai-'!uCQ֠K[2 H(A f6Ey<nk@vAk+<.1ELFya׏UxEVZ%!γûgw$}ά[P7UzpFON`[Ffm$gHdIi(cZPcT3(3`XPʴfX=r+,9LHl&'d9ZߚAj?_YD<:u AV-lѳOH*L f&0`X_FqQ_o?QZM$]<wy11 @S<6i4M|K6vdgC K<'wRyڟ01wYr;Va[n/S6uP}w$0$" /[pdq+ؾ6-+.8ex^$uX^WF[m#nQ_{#y;-I+G$ǩeV{[x4}m:hpŗP :X'E=ΠY.(JtIOx(o[MQ_Gz7]c^vF!÷yq-L݀޿vcI>gGPek h_c!/36:u=A$9 G ]AEc)Yfˑ>>Bl$PL H7^IjWڝ@P ;|:h7<$3|րP5Bnqo}d^JdV> D{<7~c:/8>Q`BT V:`#ESsh2G#~O/1 ObxLl˷A7d)&k2e9v\'|X9ʹ)v7< _GI&TR*H<qjF~rN}6dr7K$xOR~pB u:A̚Ol}}}jOwԤip F?NQyMFF { {ln?d*Sf J\S޺ҀG6mZGV0L 5G ?(#O s޹ 4p:2(sɟ:~>h՛m7H֕ėIK.fx:%B9ĩ}V"\4DڈёF0[?M]Άs7 7I(wo"!NRrRWZpz,UsZxeMzQƋ$cƸ+\?JzjzoA ){ ހN$l+JwꙗUFb9ú/vʘ$ )/(!le,.`7>=ˆ[ӎQ7>2zc;j-T,G3ܴ掘g?e? D 1iu8;b/{22 A-]:N9NyS<,uij#|Xư)XC+0KyŐd!}&}M&[)<̍!oEx1G㇘' Nò{%x*j. NA.XQ~f10"hqxUhl#om@1D58(ӛC?Q9@#)fAۉT{uSLi&:d8Y_s1jU$ec/Deoxs%.݌wӏEDb=Smr1L !f%ofY1=Jqpw0ƧD_E2l{ơkOzCm& a2o~:?Yep!@*d^u0?&^0h1 d՞He˲`39d;@~Y.l⬽}H $ 2;;=l@6@+쀯p&/~ Nh;Yᬰ#Fy 81ao>e*^Pc_< 2RDqAmt'|N,%g'?>dדvaMrnIH!P^$prDwǣ-5r^KlѤK1 ˒Q+A]U7;%]OLA/uBsu"[ E&$^*aUGs,n)fKJz=Q/!8V`-/4y%兇+u ތbZ:^hv3ᗷ}dub|ŴD :&aDpD-{+$=P8z^k0H'cB:^.n`)l8X7ZJv2wJ4%dS+H}݂n#绸-08a3i8p -OZUN`&^NSFT:Q/ Ks &Zt\NY\ufk 3N>6Xp gCO?GXJ⎽gKYaXߡ9['tJ.cۛ#r ,c'~$ofx#ď,f C%;a_a _G>99lrf6H::8v)AR'%rTF-߭"HVL2b OPܠH/{T zSY32ekI#MQ/;*Sm (^j Hmj*ClR9m| ZFřVTljGG+VcDeht.g4KCPbZ4 HהeĔ?Rpve7%.O1q/x u{;\Er>H]xe.Y^s Å u)xԄ O-zZ9qsGXOn|Q$8\b٭4Hߏ#d$:^LbN8]HN?v \&(3s7bK:j˚:B,o ֊>g8l2A@2@E&Ƕx$lsY'!xmg+DWn^?`W&M%\&J,8ܝ^8l,BX hVx>&4 17j뵆?˟${<-wD/159ƽa>$ B]1K¾T(HJ _A-h_Y`E\j$.Kc<1XJ߾f{я{mu;`g݀ATwUt~O}SU5=d 8l<1sbϼ [pѫP`\ DqAI6l8Zo Hgixa$OEGvG@Q7}ֺJ |ŋQLMFe~] vn@J""f@il$"0Ň0YOE Lp.19b1\49wF8 ]9l=q>N ._^` E 9?UwN5tn sY+n\L#yᯬd.cIw)f)3Pe9\˿jQ[9N 8 {'rf&(bpu9aR8v?!z+ QIGq!rAO^-f>dחo*QbeA@>G67E7o*d92Ѩ1~,,--QP8x1,R͏F~fQ@ @|+ %"dTc|̇q"USۖ |-3jsm͖3 0vn6S;Iej|Κ Cqs˘X3` ~"azz`uc}{S9Q3X1ـE9@%_r'<O;Dp!jS6A ?V^&믿sgb5_kidB\GB :AsQĜP_=Ve4‹ 98\-4 Ec`Qv|bGNX '/ioK?*5`#W u~Vow ̩Jg@nh j !BG҉E8bZЀmO1^ȗbl13̔VgEsը5xА/|#|i5PЋ|^8y1Sgd U3 e8zBOU͒S3kKc_w"~wf4ME6A6m.!3sb_/._FO΁i+aF< w1i/]@ /'KB48x SS8 5fkv>$nfG]VJ(T˭]OH/,Eb̽=ϟrױJ֟H{Y%#T90gUI ~ <EɨմeKc"o5ȚB 8 nigߏ(-|'Y }gz:-BVc @8"RFŖ$1͊y\D3hq(,D::Lwv c{\!!jߠi.H u|$hP,k f(|i}XyܱH(W iimЦD~:Ru+GGoPFkܵs^/Ld[NmGڧs еtfEgnu|w ߈5׃ 0h6gI+!'Wp6H ZYԵ9;7te?bn_pOM`,\gpҪ%&q~ltS:BK,üU壟vxqw\Z*C_LߧDLq0NY֟E|p&VݖF!"g)SR|, ygN>dS3=f"FTx~ޓ}t:N,Ck~EQ:YY+6EI:;)ixAь_ %, X/r.Ev2m׆x 0^#SmH &`I 6%l_᏿'$/)ZY&_,wlɿ/DeFA/x0łm[ZcUqʘp7f1L'`XeS&p?W5;& ZYk"shJ\ZkzUà:<ܤH_I : 3jҊ#7)ũ2+X -/Ǭ*O\آj^`oE"Qem7[W`^ÂXh_ZJ3uIi=,ُ *cCЯQ0e2)]+p9rҥ+l8:SQuK.'T#η2PlEVq`ثx[pǵЙ@-b`ӏaTNRlD1`ςe~)ysp$LqNU'Ə`u++;T^:EhBv=K'fewv\OM&i>4${b;Vt]Ŕ*_֑830@TnaqJ[ 9( ;/{ eV}%YŦu=9#6b|OV:Gx\۴d/./X?ԺNL/~D%v~>nTXpZq-C硾@k(!Do#yf@Ul٫u.`F#ddd&u6kTQǔB4/ Ao%$?zpCG}UO2+~S>M^Tȧ 7 5hGH옗CrޭJ.Iyډ+%!`N88YBe{ 'Rn"5]w?ͣmԣ2?*3|ɔN72Ӈ G}$I{CXr>eyk/Аe6,:c3X35cʙ$`QA-@Dmz޳LJJn$tQ1]WA[ɀ[bv&ڪ*m?N)K4'f&;N[!u LũP16H)!1#XBÆ(Ќ<׀xm'F.P7I ĸ 5Y-s.\{R=!Dw5yZvF02Km.!^N4qkr}kx,H"hڝO?<彴-{_ZHf31Ӽly6X%u5nKy,#h`l2- Ezuoul a Acy! JYbJ^ ƍ=DJ3ۜ1/w=TL#ܒLA(ӷܽ̋#?w0/$2W<'6,IYyk<v( |'t@@0ӵRr/NIr#%垝ZpvdOd2_@c~={}pd $mQݕ~ph]н#8p86ٰ XˁF)ͻ:*͘pldbϡ' n`z2i-/ñViXsҔ.%k^~K˜zrדهOGsʣyTX>|DoqSvyh&uxӞ|jK.(Y3F/vPwYL$N;lͦ/oPjĨIQ{np2d]̆Zd+ 8? Sx~r Ar2VAIW+f2o7M ;IĘB-,{ϭgySTEH|̒,cX5Б[1ýS\j{3]WdkUz/83rA=jdIW:QUP,!vOxYScayxFbsM}oϪ(`!m]c .Үz;EeR]FGa.(k+? ٶps>, Pqk8h] ~t> +[& xѼi(|EeNP0%>9I itd:N O@Y;^EX {Jyczu 6(+gY̹Bw2aћ:Q`{=a zzU*G 'rH[g^@GS1`,E\R@(gؐYm Vߐ]x+Il? T[vL%XZ&vLuC-@c;v1@K{ >C)MRQ L{!:dž$M5Lk̅<.!T F=k"l]j\]).!Q:de1F}\oY~,,Q*NB_xWA&!~J0_<(ٯTT _݂.`N'^Ҧ291x#e`p McIxb}fYw9]:Vt~ 󗃯{ѸBq(!Ѿ^u{ϭUFk 癳A)K7hEq| zDq_'ԱΟlU2p4[z[J:ݙr53K s"6EBbwe4]h_2 ab28KP1<{C +MZEKTƵMbN$v7 9λB\ޟ/z]X I;ZZ΃ Y뤹{Jl=Cm\ VA» Ѻ1Z$bJԳZޟ;Zioc\T-e05j(u?n5)2l'\@syQp:HLT~\tU|h""/}\LD iUP{n)(Xmŀtolu^D_/IoDfg|WtvK]WT [";k I KrP %EwvV뷙 ǁ(pZcsUd7n_O;:? \]'kZdK5e9;X65>`ˣ8DtoU3s0Sqv h9q#x)]\?|流uZS1S6s֫,{:( {/?}Uf-H`Q>1O!!"kjB7P"ֱ>A7o_?n/PJW_+M ƿ%{RF[V[XH^jˁeZfVGt PP{E>*gݙFT6 esBAG!3W9Y$ fH=}9?nJl k;$Ǖ+F^ϔ&J KrZAݙ7cI91%_Ti1={Z|v̼˅xˑ}݁x 9J&2V/ج6A{vq;ppGwχSC'Yv"_T`:!`_bkfXIu(͓,؄lca1o:?d@w$>{=t!T9/蕂ҏjTla s騎ZI4d-O{u7%:5"C `r>2V[ `(ehg}f5- cDxv_2|_ &N>U ,/W:ALwtU$1柘tE#6n!6x:n'Z#㉞BTFCW"G\IFf$)j)rniE~zkB34Hz$@}s~!zKi//PN ߢܑL,أTi$vY&1g48݆O{ҍ_js)3HM,4_獳#x_N@(03c(,#OF Nc?DŒB(6]6Gڱ%E5$\2P8)#ْɒlm T9vȧ-2>\ʠ_2 i,l|TPRc׶5U8 <0?SoZB̩1DHL)$Fu{.vдr7Vpu]Oguh+) 8\.L| W u6r~$Kvk/rG9Ocfaؚ&Ǿ<%ܯb圇\ DI_dӟެ +-0(W4;̹vw70y~;ː#H||ӻx" λxs զ|"W%-=Hw)"iz=̧,{) ~`UM.CQg8$T_'Ё0hxpfm6A${pC/_] +>Xe xꩈe]̹ "q޿ɪ:c~G-a""/1d"h\J)Cۉu%ɺ7.hǣTJ yٟM)!I p 7Onsr|ѳwWSIс=2.hVC1`rXxUn?ڎ`=8-=+n k8W/E1(W1p&~'tTݺ\jQFۉ,R"E LP͸Gdff ;b$7Y@)8KAŒUF,DA)*, I%39HZm6| 4{Cz6mp -؜W)"O6bPY343s\8.N>Ʌ>NVDZv|bwWy6FP8~A]`h~0pBQFY!HX'x0C_Bi$+6NdgkDDgczfJ=N[ 1ݮF g(1  šsU{oxHuFE80lGX~,uήf&vKb<-r prٻfHn]yc&We0"gO;0;B }_Kv2bIDḡ(V5,@Yc Ȁ<(2 )t;j=\^ɐf'S~Oف^ ꀴ? Sm ,!xƘoUwܩb+Ά:AFLxA3JJ[CXK!Ļ:BK  )3; };.!AgT8?%S= ,Y $}w/5?eձSn 0\XZin.2Qm\rS\Zh"$* wG-!t^ԙAŚ漷1c˾`h j-Pjr' ͇pB6*cV(Y-{]-Bִ(wi_,aIƛnC"p)G}8 Z^V9hЫAw QۗH>WaTS)jjez k,7L <^ W"6-֌Ap YB)phSjd;N6 $.FI]=͢k;OU^4 dM!8ъn.L+pWܜ1CBy >}f4ͪgRWSJWP&HwrȪA"ܙj~j9S}SUC512sٳ4}9iá+vhIFvNXtg[?sA5#?g4-F$Y\)~P8znnG˻8hl |&]%C$ z\>'ax(iYmEt7f(\(Liyl.nJvf0<Sg()(ķD.Ȯ ee!rBEudӕ VhJOOS!.1x06-P@͑>zЅ#/VLoib]՛ 9Mu ~ =ˢ \t3 v< 8K.CϾ+$'Z+nn0dD.ofOV!߽A@J׍I: s,,RPr.h f}J/WNp!PTY|0G$QYz-5' {qoeCuL4:bf ?Kq!mWHc!0**Æ[â#CTqZҫI+8 *N{hG]e-4M+= x& 30]9,.ίz9AKŦX˽C2}r7sIͶݷW^ʢSS}( Mok \rvkh;)lci|2ZRl&&X*˜( t>)E9_]UfϹZϦ!%pLQ6ec&)sc .ǥ<ِ~k]mEN_U 'ߑxOƺQ1ui+A%}p-44*&3|Hz7 j0>,:dxb hcZf" Z;0V1[).$ħQixU?YzE-X7!!YA_ij0:Ʋ!HרDAoeVGY6RR-v5$}Ħ0p@wFQZI>7_{Îp|'rG^?8adf> ܚG81(@v{33U>~~xo$R8DD.şmrAA뎫H `@unY)Z%% wU/]Ϥ_ nas*_giy ~2 I9" E\ww.x&nh-FfM6qDlfL: m:I!&TI-ڎKZ{S$V JQ Օ@5|mdWKhTtMe$sH|}:x#W;Q]]z7^<:dhD5q*57JY#dgi!{^Oo" ?'_n~ZC?0Bcsu=cz&Ѥ_ʚjO-V89LSN,m pYqqmGs܃ʹuҕ21h񠛪<ґRi^* Kx=~Fc-=IܷMjq% a,I:94îOؚEG՝n` wqo[)Xl +⨶b_CПw{*hn[{.6'#}q#]HO+uJ] u# X>qL%L=6vJS /& ؞EP`mƛ)t?%n"n=(~ȩ[ʿ ZARt" TYkX6Oz`ΌT`,raHqH*Ny3N6n4ps >fk=i1K9H&I(i~L8nIWApsRji?lf+7XJq^_Ax6H˪Ks2Յ;?H+9=<j~X` 9ҒǐݻZ1bh}tғ5&d)x/-%?{O(m 6m۳l_hD-6KUi5z8ӎs qo7PJݷ4 q@82יszȲl Zbԡz$1yis|#o@ 9\C4VLe G)1:N+ka.Eq~qנ6@$i1IɩWy AuEv 9,otAG pE0̀1d'8e/D$ |t rC Bb_Nxd$sF4)-Xjl ǟ,j ;H5qd.|sS-&8;@0Ed2PsfoH6 -ο$sj>cO<ȰT4oXSzb>|7)OBD{lY=Qbwݤ㩕*?}! %5f#V88sv]woh/ ,\O4}5^ƋD^M~:-<?AbՆ'cF ВURTN z<[ھc"M!H&G>@RS4C-CN݉+4Ӿ1`<5G昩r uXą$sub*Ԉ3e):gvH/Hr`=@wU(O#d.ڇUG>`yktm-(2lq~߾X.T)_RjmO ;$ί{-k@7:K<ՂsggR41uϡg vB WKbnvMWȎ)\02. u#]2#$P{)]iAeÚxUZC͊NS,UJӺ>WP"}ItJz}՝"+VzL_6&%ømZf o!yold3"nCQJ..oe2MV=ȒZ3%?tU'КB) j ܩN71/‚[[I;ιV7crI|M?2\:MsʕAg;@uaB24/%s+mj TK?.i^yp Ir'RQmhWߺT lJJQ @\旐gv-‣ǙQz Mʸ2k7@A}2'/ScZ(=q3=RTXB2 qf,O ~'PM}h*rL`2Ѵ,* M\RIZC3 $OI X'ZztmRqNb~; ]۽f=&TԝxG+KK\=8i2qxtT+@$v5Z4*R0cF/Dl5\z>W[ K;9j!O'i9vfu@YRsF!QsI]N~(;ePdBĀw!5+SnTvlr/ȉ0x_i: z䄼XW'W+3`FWT$ i m)GŜѸt~dﴍbk5Rȹ~n6ozOUX_SAgƦ:fX(LhE(M㌪[ CF(6Bd{n۲Ĵ@or`O;UYګcLśLxurL dulbadq oA%K7.B0@y0b?_Z tCzù{S?,V/MmMŤjVTntźK^ {gNnz= #Eohza}i[Ѳ'R)M~Ѹ :`z6zǯtL5} M{Q_"YHM$Xvvmή̪Ǵ.-1ϓ ӡ/\f25)dT ގ)NrVʈyY?r.;Ej)x~#zJB}.%#ҡ 7FMm;oit`"%ך[{[m[M1~d!3ch3>x F/z 3(UY7X/ޅh>dk <=Ⓨ$'9%5QD`ےR"%Sx_GHM C; EĪ&Cz I-dWWk9(v}Zl;1GlK@ c[T i@!^C_{8 &Zg?@u\UWJ%UQ Qn8{h'U\=6A6G8ɷ$<]j^h_*cqy|o?Q"հThBB#+R큂q߷Q f8󃹙sNkɀu Q]#PK/* A国J@(cпo`t'fM+mAH棐Ts4rz@}`{7DbfmPG 2i"I{:X[W̄ДU`~ퟞ6gⸯ\Z(`HGXqipe|.b}ngS]y9zw^O$7tV) ?z#!9/@vȲMbS95%Caѫ?_=^1&.brl .bEHT7 ƻJu(TS)ɝ1ρkGRfˡ2l.UηFO2h3ǛUlK ka]9*n`l\S//ROYc' ]҆ e& n->6W)vd6UfOCNS"ZpFl7psKO[_O`ҟ =!"n ~@i-JIMi<ړ<AU@>f#G@O}yf# ~>1揄3MY PVv&QFbx7J_uKZFێ""ϭsdCGsM:Ԙ+^w\|`EkY j s92ۿHfg:71rQΌ(p v^W &@z5:e$:(~Dn}#mZm{4\nޕ!ail8^HKNLM׸Gޞ77>(&wحѡmԹqh5m!$#ߢYZvLmI \L SGT5!-R*ˏ r#Fޯ b'⏓PUZ0 >}%z $1SS)-N+t"oXݸm@U pQHD+d.k%l%q<_@,qrjܲIw10M#XqƧƤ7 a%OQFq7!B/ګ5K7NWs  z=~Al;x&8WF[Zi l+7]S/O띰?'mRGNy!΀ @. Oy#ң-6hW C2W%H2q ripN Q*R/ol~]hyi^gcf @4B\dcKDSD& Es¯6!V&>4|fej1 {PEl x맕?=I' 2S6ނ3F}zփFTϳ.KP%2A@-+73Nj#I5 xJZCi!dV\=񧐖8.gW65k$`.y/]7چk_X$><=Ԕ"␒^ H)aCX>Y9`!uvEXv<fIf +AXA|T:Tu-B6a4w@@jKЊk{|&AaPqU\yxS[($_ɇ& 99~Q4@ܼ$%7B4QPDI ~G8Pן 4Ye: & O8Π8<4X9mԐ5Tx(wXow+u/!J8#~䶕(Bv٦Zu/t{7&U0Ҭv g`Gз7E;r GJaJehNIz)$;(mME)Lφ!] A ' (qIXY7r # Ora쿘+ ID)iNѓhNNg?ULaA.~& a-Y YZG[;l8!YvȪ2N.ve|V yI{OuzĨ$j2'Hjߺ֎< ] Z`]AP]$pg ):6_MBu宔Ezт[t(zL0z~<nk=I>T)3{pf 0ؓ;tIVXݦ~AԑΩM";S e*T'[T ~)髄qvIl1<:X?!R+NX66*^D,eL0΋aD(/ZY̓/jI*y {1>43 (-/ o-a\]jp0^nMI JhjpkwM g[,3*).ه}-KܠTuHgo3ͤ 244#3f'eAnt.&FA)h2 E _Ffv ڞhdd!ú}3@a!hϠ|Dr [k f~ )Q5}/~'/lL3϶t7kgrv@'qTj0WٜYUpfd\AZI~1B}mzb 3V7/hۛCeSUe2h9ypJ]JMA-h0Y|UIkrd7 adƅJҾ:wlYIY' /s O' .?-p x `õ~ֵ.1q-K2֠NU= 8~[q]{VO?^Jj-#kä"@8K7[ pCMr8*0jD:,jWzh$ʕ ť,xB$F9|s6cB$žeܘKX[Z 9xh- d =ԅqƏHA(/6J@ܷ.c=Uz&{F\oP LPO tJoYkw pHa?КR^/TwdtǠո 6]1ȹ]fBL&!0_R^MLd'E;h-mu5 UTٝ cpMZ\w US"on\H.bz%덧v@Ʊz!] &eX4e5bQxBĖTFA_vK - ^[v˛gEe) mH;1vnoh2(TE#z -|[NM"!r Lϥ:M%ZM-nv$H#K%֖1TOL<7Bl҆/ߍfܦWSnyCҏf  +t#v=Σ&sno-rQa[īqBk+fATǰfEb o֫ YX/"KT|zysy k`)xY 3bGD>DZzTJfH|K!ւ.Y:bZq3 e6P. 8JcTcD;"V~Hzo!{w"F%O&7"?z_%IƓ kg e]x, ohRZ+/V4rB6sq$eEeF0;ʠZy$&&LfR?olɻ'(,f鄇m>Wu6.ZDEBmg,8ۦ{!񢮾^0} }t;?!Bb*lQN0S2m(*K{aTRGi  9u;a #$.;smNwZQ,ZFt S%SOO3]d"(zާ.DЉfI[nSG*l"I<Ca9:\"B(r*gUƃ2+rͦ2mY_w|iYw gc$N vϜ=4B (jN|WG hkZނ8fi>p,2,\*c/fo_LRK{*kf @IJK iFuRF'd&v .kL2gW,іI2_a?@`d`eҬkq<Yr1ƒHa<}^_1 r[ 4}0LQl_ʐ]AJP>-wM劼Hl.]́0nCq@ /WjŴ9zbp%O CM@\=crHo}hVmiLݰ9Db]epSKuc1 0Tu>;;,} 邝 Z~ <ҟ/7n&Vw4xEϽo/ hGeh⛘Ǡ]v2I#BNY8\^,u(ߧwmZ>j8_P|@<5LD6q.>Q{t~IK)Qrv!q&r@syqKgX;mx)٠ݾ׾忊Ghy.\$_Sw`7mr5ej 5qfėVbSRT{!?7%d.p(ֻW5WN@rl}l}sJp=91 t= 3v( ]|̖X|ޫĄtC*~߉* l_.zhzM#N*[  ؟/-qԥj+a.7w,jKA  4w?(_Ћ;n8DA%GdP&C)2WQyͩzy30l#,Ua䑄ʢM6VNNjw%xn0 h^ШGAwE5OՊG/oC TǹwTBȋ Ix:k0z#2~MmtvKZ\P1gQcFwcWׁ^86χ3z::﮸/ E^Z;dx/2Y,V /6-`WdI&߈PQF?וi[P|.iKVč3Z !wͺF#K*Iu 4"۰ ߪ9|81G i4{WbM1H;Sa'5cX6Bi|1{}k\ You r* ^TAJ#UgvA$^~ڵ@RwMnBy_5nC|e?Y˦eMՅAH}dZeEa1W:тvVmϝ 0ogaчVCKr.rاRW`w殐cz1,4`եܜ:8P,H=lW988Y/1p]kA࠹v}JZ X0)4d$iƍ`s`I0X);a.I+WQz?Y1@p2 >* ٨ʣAH?^<̐t.ϙI6%](@)AOJ%W}vwa]78eΧ= =}7–r ۗ(M,@ û́䘀s+ArڬxOŚknyM_T$\|np}( /m6$D5i%]Y uV>q쵕j'4ZZ^ђ@^H|Tc {UL2&)x$OVڛ~&n]8Lgؤ>h͹] o z`V:\NqrqDIg(ȦUX 3K<\YMonvfdnf i{{r|@Y&D tB0r)o g$nG)Gd Ń:ɣ)1JiI]a!M\)FA׮O›#g!U L 6~s 0Biٟ1e3\u F[uxPsW{\Yͫ8h;W&Aryk~,cks*~LEޗINK/}ʅnP4$0{Ղ2<룀y RIfgF0oYDXJ9D39?/[ Yʼn !{CB8Gbkc΀0y6Et~9K{y12ᇐY|7{lF\*tfz*4w/u 8YTW%X*lJ\$H5pZAZ g2P%{7=[㢐cRD#_$<濩z8U}ɃۨR|@i APr$LdC\1Mե]G3`[CML'gZGG⨗C~г3NQo:kqdUPҕP{|>Au[̯ؔ&!j.[g:U+⊂'<1PodWw7}Jm>ԍک[D,d*1Aڎ)] Ɓk l1RH6Thǿ=poq3#&qwC ϩG.=2g\r#M/S38ғE''p4 B:9t "2‡8RX0`ņRhˉ/{`VDuϒΙ+w@ ̊q>;GbG,Kz;`N94L 8uv9aX#zˆF+2cY.j)r/+~P&=3cݖ;""8N5؟wȎ 2-+.+HoM}6m٘c/i}y`v 5Wd?KcOTb[1{(3q$4(S#~#Z>|]c&./a҃q&|"Ѿ+c¿F6$-o=?4 u$LʵOT/r q>"Hn~! ƞiQLXMe_o޳1 ہ@knt/`4JbGs6`UoB&ckf7tpxh}{mX/]D/sRXhHs.-cDu)1᫒VjBfGt[.3u2:vb[?aq]G pz8 #>PX7Kh:,Q)>Oԁ clf$hm_bj AiϬV'gԞ>R^\蓚@BӹϢ-+B>O0ͅL*b}(ZbOS Ŏ :ZPJn&eYm}k[O{ `BbElRR&Q{D0nkRg>9ǣmÁuXKl!\y~[_>vecnh3qNog ^Cݾl} 7_Y٘NG0;2Gq^]`s]*&^12 UW- BUDM)m,3"PQ9)ĊlZ!HVcP\|`z(5$o㦀5u;:Mپ#An8GȠ"E8ROブ>[%Xy"ھT{PUnco)%C{sGkjqpSH>m1X-@#vy|.h Cjx6_*..wcXq|>nj^JRe-Yk&~@n T[Pm_#G^Zf=G,`<(ޱSe},hT0jծMlL~W&YخĤVs`^@:(wCaY O9>'s4cn 0%c(>/Q9/#CДf]@GRoJGs ZIhL ڪZԱL!j3b>hA)j*uӥj2ބXG5QdM~rL=;<k't&sdíQbXXL/Ur[,`J֭r,v k$2Q@GKUhWRD ^g3s0НOM*Ӿ9xfС;zv$ 1撤˸Hi (Ϭo?LLZ _67SHUzA@ }Kg򊑇]ߵΌ ſE D%pޖ1_qCl*DgM{2'`*R$7:lx2P'1ɜI_" }a1@BeM7I)®kР "sB`6Ӊ(=,Hz1FTm=W,`G2,.6V'҇b7Í#ߩ1# ھTl&N oB[,Gn2F DFqi-plɼ~4FEO5/2隂>FH hS;g! Fp\6Ú837WT/~ ?#\fq&KJִ53Wu;zk}9"yz{0X2?,d_\Uaf ŕD[& BKRvbYlHTw*w^S"6SFZL5'ZMZ *x-Y6`tuMnCd=ҜONo7 t)aҵ{,o$aM‡dfGO[<}{@$d xcZn,ZWoU\֠c!rtň0vʋЅ'H2PfO[!)ہE| A6J =%(o]?ܾH$`g$J2NJ3;c$rl૙eǠD:?ԢU u1E^hr C<ˑOe]PVF2/xER9*%(AZ_~rk55ZSiKx[ՇC3OsB<| bw2@(L$-?!*X]S]g*~17,%5 j4yڇ̇L!K3FIe|%'@w56ʁ1-beSEo|^w9IaJJ=-]g Ȁ-ph_ 1VE+v Ya|#7_ sMs}!6~]߰ ׺!)4#ͿFQVF4\`.~7y!(RՇ%u@7v*6N;p $;_3lm8+gv|я6 M]M;# 2-Rci'm$A6?BG~fm}'t_wNaP!a 8ੋM*1]U;_!`]cЁ:.MF+S1#V +GFtC$Od&l V!9q>y&'ڤOz#ׯXs09$IEOY\TQ;FJ(ɻzw⎗1hD!kڽlNX3~+e#R͡kb0q7l| V8] VPe0xrY*)(i FxwW<&n jc")C*ⵍ-uLje J 怕FjN'xJDhӽ Qm$?\Ն?QM-Wu59vj7d08 zyȭqRfU|d(^B6pS427d{BJ jk7W1N!W-=b$ ܆ZP$DmX&Z1jcC⫴=C^L+(`9WYm6BP:ls6VH}WrWdd1n0jwp_?   oN\߂sy80^GQԌr8)K=C(i)unAeѥd18g0unQ~:(9\ ́y8)i)0n-Y_)O,2B>ʀ"]4YufTaRBUfA?rc=D*nƎ$f\.1fQ$*Dlz% Zg*MtL%B2L|I@g+B(#,W~sxr(N~Z{BlC਴ޯ>ƪsEQ, % Nռ^}$j|%jY8N3#J(tZO`=k\C7B*>/iԾ@pRuONDrt >҇S3Ifx2O8`cJNi"ݰn#?3; oXh #'X !l՘$REoRfi>]ZSg ۬zYDƐfwx\+7YsI"48\$`lPs4s rC!;8ǐ eKxW+L}8C+^rH4K+9%x23i3bJ[_sGp¢i(aUar_ :j,F'Ze +g*4/ie7 Bgh%7}OZ Av ]AIa O X4Ԛ1콭_&>$k ]^?z=nnQTi@mm=%hrsޯv[ǭ,vH. 'J p"E<]i3ʔ\X&|j4^ Xa>?|1!a oRS%_ !:aU>B\3h49.`Xn13Cf3y.26+̘֩sqCnݢ kW"A|=㷌t:l("l|\^L~t~2 nLR:ߣ99iV!aW Wz<:Y`,Iu4Y]L>x\Vu\T|LQ\8?"{VcoiS"Azk}]{xJd3yP fM <7+iB[~\_t;C!ㅘrm?ߢ1 qd[`,.Fn)O-TO,G7s Cv;H:;{ܴI6wK]+ U2V0$N".?Ϳ+PQ hՇH b> >RQ)6ZIϲ r reA3I nP+5*ʐ[3>bEEFx|ʉB2r"Pr7p!6.pAJUSGpęZ1t*sק}/_{'ǣ4ТR¶tl[DHbo +!=vK[\AmM5J?1>R6}gz˘a/ӰO;H`t7^Ā#EP6#q37 DY ۥp:5P;0. mo:juUK},4 !̦ jc®)6lz )MdЄ`<]w5!g S]:WP.9Ux66eM2Ȧ2< oB)Vl"MkҽCrLXKl#I7 -$^l%rsBHFKaؕH_qT?/'r<ʴUQ)De6"˦fQ weˍPydrt;L,` 8 t5s k}Հr/WSRo bln/VA=jH@ nmd8/ Ԩ`X]yOA1YL-GFoЄ~7c'1/kt'=p{?oV90qh[XóÙRy <p`Z?4bG~;onW'{bͷ#}w0M_^e'ŒMsϟ[Oo /N%!*N!4\Ş%œ4q` eϒf}hflxXB}rCyHNf 6(@?Z1w}OC'EӌK7cg-*_Z痞R1{w}>}(<[jF yŧQ0= 4rHC:ipR=ŦW׆4Cg| #:\pE#ǭ/9:ƶU~&! ?6P4@lNG1uЂ:> e?ވXmTǃ :B}u70 O{#6.:J!/ܾ͠UVEHCC.K|50 7!j+mR1v^;xa<=ub6u,CQg yQsudP*rEJ;p3wd'q2B0`RTl0tg7gW/Yۖ$XP?ij!ݱE[k%&|$A&VRh)σ:K)Տ͈KAby]|K 5` ,(eb뜻pA<@R"֍ tYTEP+4PԀtI)7*KG%nb=6\* lWiD=l)AV;\mYz1V_|~v;Dۋ^s{='uTS:"ԱAd7Tb6UR'(q!/ASBwϸO |53.׉3ʤ ?q$\qH=:vI<;xRiu:ކ,ѝJ,~dpa.J?bM!gm݂' *NVh;^EIbGe6]`s_gJ>sciqDgsP ;'ɂ%NmkSITL>@jEMG*RQ*s@.ViTp7Qm ]yL)7@$_ :j(|Yæm`9aPDD߄ѩNRf7q>mGڄL?"]2lpMIhgM5v N]"v 1ޱd} 1b -ESaxufB>ƪ.s-3^\u&S &˝8K8(kT 7"Q̷+k='s 7I늟Mݛ*w"*ZG!Mkۛt6%/y(fYwj{9ΛJ {q$Ké U~q_o=d_*lS8P#?E'16K"K> E@T Ј2Mn1с{)JFx˰1o%$Kfo dr6%>[d7=| o`C @ s* |O$y9`PQg*ǣtݵ{Z}s/eYǹcP,E*:ĄGI -gS?ZF1dLIaں_IC$ i.XB xُ"dL갍#T/ BAX;߰`*1]WUC[|pǖ"{\\OyzB@ǥփ`k{N+<@[t^ 75=g6xλ`ײ ~1S ~١ LKNXFit{RBS郵O*mf ۻuEoXA;& ߚy6=1Ӓv2VnR)#&b,࿻UuRip' _/l:c:+G켳Ŗ[֨:wBA9 9JQb$z(CM X֓)l/y 3ƒ]u CzǣE"tOU%} h}؇'9ɾ]yg@ur`k8C~4;ȰaOqo/aW9j t}Ibm~E)`,qu_'EQ A"wק=IvSs봀] DHulB!X\EJ/d[ UpNCS[B <޳q0xI9Sv1ˊo>w郎\j/f)kq˯ Y<U%gA'.Nf(3jݙtƓ4Qcl6~( _?Jq;f%iAϲXϷeh#h"7 &̿CB$65 KH _տ߁#Z<%< ҆x@W85q['r\M3zU8ݺN"QAsJ:|F.vyNK`Z7.=h=yUVYT֍rFT$n~}]7OS6%nĖbbs; Mvۗ^VaV$E*$B߲(u۷=&^]RL)<+\N坧1lf&j|H{< |nEWd > [bz& oG?PM*ZH,*Ɏ ݂ARL@q :I/sdØWwvp 䔛MЕI?J![/,^û+!G`uIccC<0% `b ̛IdU z4K>q :̑CRzA#Uȩs`xaÝR5_MҊ@4٩?(' 4D#v4V$RAu~_qaMq:7C)Q}$N݅{?}UJˆ3C~ZFv̓b7TAby#b4@lYfC.$IN𩟩L%v**A^ ="ͤCx5RDz1(]UI`B;b0۪!2_!̶uW{.s 4YH=rC0 ̼&X H kzvRƆ$pVTZ/c\XŃaHܟwxh,lםNy6d:2u;X%tԑNOt,#nLM gjVncDY$&fošϵD@D҃]dI"=SN1ژ<al).HHc:XQ%ܾ!% 3*`{D̥$ʵjBuk]UwIj+e(GCx̝Tdlث9]5=T8;Jo c׻|Һf0بlUBE'v&dC.tUq}y1{4n)hnCx{o c2M؎λ\k% DF@|:kZHφw O{FⳀR>yZq.Ľ:kJG﫱\tNΕ\~ 3!DLaPhRfELHZ] sg`q ɟI}5F#߅Rɡ`}-,0=aVUJ&kvʆ 6hL$MZ)7N Ivv8f Oi0ɸI̤._ TpaVAwV!mw ),X 4n/C'`,QR2e3 ,B mvr+VZM͂2N"5Q$d". Яr qȒh/<qNK^v>d%#1=ILD}E5&֗ VL&QL CiK.B&Kzѝ9T>"I2T 'WE8qIs(!u?yxL $J(Obhힳf%"eIdǕ=҈RE.:slETel$źs oR< dΛoA@1Q*#A :ZX (*gbMDř@p>d$(Cߝao>vU'X6xZ?~3 q&& .vYWgx]q=(43觪)p\*mņmac .TiM3&W$fHMw׼ zm v|ma kkVwT`0Bq%O;R548A1.Jv f ~m<:QHmki^NTyUoqG<*XʒymF[eI؈V*e,xbޘ#J+TOGM!=ӞV=J'2T ,(\My(" L@CbECh{z-"&P,_S#̡ٸ+E)9P~g l/KRt&]I;Y?)r&Q$wwLqcZj4,ueqhmm\ݽ۫FSdl/Ht R\tѽc0?3('DsPTFqZ&\vf5'hVfdi_,X1S3/vłqnn)d 0(6l-@XB뷔6c7{׹/KT &g-s Xmߦ\]QV }=A<{\msqutܒ\ i;?Acmk z4f ةΉSFJH.#jDml#40% ʏZsNp)IOZfV0|!IlYk:A*15d*!gN!Cfp 0ؗ1skm0p?#^%3gv8>2$:/R]$9>9=2{nQ =Iq>\g-ߢW%0BLkSC2^֖SoV|i3Pmͬ>, %,oLVrX`Ӝ`]Z$FLxS~ehA%5HηE ~ ۣ +8a^F2n zyNdAdɲZk¶v}?҆u6eɏc-vzk\niSrɞ+v"b+tIC/-FaVG>T(Wij膴1 Zʰ} 뇌= -˗MtT<rv~2RE4:~j_Pa~!'qb;Xyo\矆\5û/KH%ڕW*+ܽu贋ɛBKdɢ??i6~ 86 YL벱czki]S' /zXդ8>H smN"'Z5,"@TϘ:b|]%B(C6XJ*pVa_0bOHk׾m{3 Tڄ^`hDDI$~aW7-ۖmދs yI'u`.=c%4Hrp8Q ]%e惉!bA]J@x¨t{?-[xT ]:W "6l6hʿ6JU^gfb4}ҽ&<&6T;N,4wJbpBVr/FUT`fbh;*,nx|\)Y~l!(G۝?UP5cT5hg>=4D/l2;썕غ-vcT)M0dF^G;9IK@Nd@ k2dd8pW`޸#]l)ԡ4kpIvuH9势 u͆CR3{6ޅ>)hCAIјN5RG.\N!V @އn.h lȏ* "1#jGڃHRt Ž-:߅ ͆g2o}7[sAX lUw^|fΑ{{վkuvw^9,rIAmyU5.V!o" VsW7g]Q/ZV>&zh`K'C|z ߀)pmW5=OgAC-kXv]ڦe0Cm1Lp˼ElGp,xn @VΪ EegB\:c ,PNtƓ>E562dc_Y\,yL$}1߹0DsrTp"gaMmBsߴS'79nZ=u*1bZGOƔRakO975p:2J͝2p9AiL?sNSP.֩^eƞ ( [c.}tN[=Qcg0lA|;R!Z n\Qo~|MY8og=ʨ6 Lm0'0ZIbr^I$B¯r| ~2!:5v{OB*#ݕm Xxԅr?(3z~@5ه+_"aݠ ̨ CQ3oc8`Hr!~U0JYb\:urj%tz9Ek~LG %3Oo=F <ĮN16^c"]xwMG<$@[D-]zuL6%|\lxM7i'QQ e`jdK,RB;ksJa;jv狫cP$2Toi UrtUHg R !ٓ@jL}@u]#??Z?M{6qz]6`|Gɢ([zwTf$f-c" b[f#;|Zk*;E.&B24!5Qo-qtF'8CH23/|d-R72߈B@o5|9M|Y,9TG)\`rL0,(J8[d7JVHZv "=ݐk ջQAIgbbKK9Kɳ HA}$LEtQ9$pVÅ&%(# :}TYG2VeY\ tx=4n܇\͸(M| fF( /3`㛕HP(v&q[jsAե7`3wݸ$^jPt b02z8ĎS|'YB[n{ܸY4OavI\?ym X[kYzIva" u~֚9ԝIӢӧ1.+AO]ʫSBwm nSֺumDqn\E**$" u8s z`5Rs}CY|UJVY6X޽XM28m 4/X{_/u W< 9f@]W0h7{=#7h[/N~wY2ﰐ$Mv IWti^k9dPݕdQf&Mr&t0+(`%K~܃'3hyPw&ѼQNq-{"44sתk) /]SkOR@[rlquT/ZZNp ]Ei):gbx&]<XLu35<1^+U1-'l0AeN96i:27a5c< (*E<8Cӓ+hA0@w$ XGKOD0iB 5(pn׻Acmk Xghf+5+ỏۗD4AQ6g?P+u,dAz'UGڣ@.yA_h}BBy4ѐkwP1`p^#_mR/R,Lu5@n`3 Of@6-{,_v2?@+6dhk& 1a ] @ UX)iMoͬ&!A!9;2 f'.hnS5+b+|LP8YBX8m{iZ{Pw Q•r;(zNZDBQIC*BU*;^P@f{ba#|o,$̓X Ҕ%:xD9_1E-Aw%/cII09D~ux&sƊ6I-Nm yaD$/9%İ=Y=γRQqx=آ `x:yZ&iKk؅D & ]V]n:t6wKC ?!_?/d`QJW7[`722%V~;[CY84ɘH0TLE6)hAJ**oTV ;6u ђUo#\?ZBMb&Ͻἄ(E7i*Tl)e[l8;ڹFz5GTbbC c\kjD6ڀ|M$* 'riLdFVuޑj)D0Y:Q5I,z`~v~˼HbiB9o0PjG: MĘg.q̎"5("ϣ7ga/b=_ am8Zu ى\ʇjs+&eP2 3U}Ѻ27j?>n9%顄3\BHikzAJs?kfz=~@rNXOt{{ H p|pMh\h'eidB 꺍L$_-H[UnX>y(l_lʥaߔ1j"ˆ? ^}<@ڰ{b)B2d]!sbù'*>kj<ƥ0Il ohT.-'oW{F*W㭴nX+[פ2%\j:d3eqi4q S(KiCr!2{54Ș 멯d޴T}}-xfYՐvKq{g`*i,AdQ ARyu"lwn_(@+CLj|ˆYyzSJu zƻp:媯צPOSڅWaktqT/[K8Ar=y"tSPL:d9{0F&]]".2-(=5`ebˋ؟+3'!/8tyx- $\>4$jx\wroUV'?Pzxr vBݛ@A2D_YZ;OEy s9i'/="*\ H%3c~>CՀ8 $1.x$M4Zmui}Gb} ~v#@<:T8 u)kY4,ni(gE"UsP;(2aVގvˆƟ{*<+bӓeY}CɔTg![ݷ[4ϝR8M*rӘ[Q(>[b@!4c,.EX˹}H1UrwxUc `A9.} 8P jdk0qRr+fTMu/}:/aԬ<:1~Cv>yr!TA}ݵ`Q~1)8Q#B28V\%Abܶ4<)xFbd}Hz+lyݏ1p01nwSOִvsע(Mǧ6LrA1YF+V+$>CljCiB5T+K]N9T>oJP":j'd Ir8~~\5o'=q+%"qH;_=ӓ M|&9Pwtp-hkrqQk,Kgǰ#|Jiet@x6PǬ I+1bԱD,ʸHOwWN(#]$X:lF^@lQAZT6B*D .`,dspUf|!}9)+JD 1x U'*oPG$k*xks4} ! u只IXxjѣVcpFc&2qMӆs%6딯T-* a/K`|/9>7H=-3^M7,TyIKps;8{ֲ8V(A9:PhIj{)\NJ_m:.g$mCμ0!Oҷ!݇yh8x v Z^[(PЮV c]OW]iUUo6"  ]EY:i%:L(mE3?$ww ndzb{Cx,꫉BkT^70C&m|C+O`ze+mkՊj Vz;9.cgj-B•zVǍ5W/:gf+yg:`zG~K3]Ru|{,%|1TIB}OL`nHGPl؇%׶2]P^^[;X%Ba Z*yK G5#8\IrGrBص" X%eCJ3i?>8pR]GW7 XU@Cx]CeY]?Ce8R$ Z- (B0<_:aNb!aKz'f$;H9 K*/m>[/?aF39$Gt̰_[7g\ (5z 1u?o`2?ݠIflg |aq3⋎d">QKgc ֝DtI/;f@Q@wCD"7ԊH\6kZ iםX0`Py?->@IMoM5ui[B}qǂuV[ w/M@yo7C8P!//귯#|+-_PD2?Q~2B˷ R+vţ#OJ}-c(@&*ơaCiHΝ6T ,HV1P۟ Pe)zg+0I=Z$"NV u,HR8~ٟ nS3VI 8[_ewK`{ټڦgP\Ey0|YFKG' P06,!>6)ϗ ܣMƄ>oUD>w-(0C%N|a^ˀᄦJ/0KN4/*btNNN&m=)̀z(4_!ft4ڭP#f^HIJoVnBU%@{Brq˞ֿ?sVɾi-iV5OV}cn#n:|XGc|8"Em++nPHnlݿ.;^{yvN(&8/z'v'j_/@#o(,F;m|WT+؅.9Ͼ2ZvmnX+}zÇ^ҵbK6hڙēR,[Bk%5&! + Hq&W1`zG311D?N/|{ .V68|_2`M ֽ (oB ;bjun"'7;Y$]=0kHZhΌ_:Ⓧw>:ZЌWq9Y@א KJ~oMdͮ7:?}˟DNgxwQ6ZF1~VHyMڵ'mu ʚ=A=0 z .ŏI g9PŬ>@ ' *S($ 7Z/Tk=#v(b0<[?%oC&4"-|~du'hL/>0 }_FO 1y?j#B#IPܿ F!aEZݧAlsC Ð~{I%޴4:v'1plk<̂q~>.y#vY/ #1䮶ԭC޼ucPRϢ4FVX-azq抬Fkpb;}N ; ܵ9)!&`~ IXʔ`aaCnj7;'Nq^db*a.sʉwx+b 9,Q4cU$eOU3=- xEv+}"9Ciŋ>|U߳sTӰ i5q!J YHiư&3N JdyexN8&i :h·W0.WcG=,ԉ\Nw\9gK>.G! (8Zc,nx NO5bEqaS 3yO/ھhf4z1u[3GwC %fBuȊu:߷tdB*<*}BLGH)Uɺ2aəE;P?gF &@ƿ)݉]"?8JUWVۻA=|CA;kwwPo[ǷRoL DNCuKopAZrovX4sg.;7 a2&$4 '0m T'c=78wh F]{VyJR6^&l%z!lNCL}n@<.Ee;2˕i-+o>Tˡj4O\:M1`}^/}DnLK&˳ ( >miƇv2o2 k,$'tƊ<'  >j(yhcdx}4X yjF:!$٦u3Q޷bwFUç seItjGlC_5n3NG1DD=_ޠxD2cFFGs~]Wǭ=ʓeY5rLzN{qٰ;+%݄o/e 8М\-PC 5X n |/BL d#v\VvTWc//Aˆ*t vB3U.a0b.X6vپoalqzMiUkhOGx.tS‹&:,.@L3y%bOmV]> ˶3eO 2Y!jvzvB[vU@ W6n]F$ ʒ*s5s:ㅦONJ.\N~v'/&ڞ"uzӤ>9;;&ڂN0<:M ,u!]:GF.6B$dΚСy0߮opXA$xZeJ;9*>df\ alW E]Qz8bpMW!59H>+(rõ;$%~0W;z}xhRY: lo"RFs&*p눷.4@q{xKHnv-K0~ 5\v|J^V~Mu242?zR[NPKӪF"jS-zoG OX<3Qr7űAq_1Aɝ~Gb2RA' >mbW4/U9|5'a`b : k8!|v[d0%%_ʪ+!{4BыcϜ qل.l & 5&!Ds!*L}[㨰^uVm @9)˯u-=tt6]ܷDzrL/$G1C2GFg6o*2״/OKE8j%cN Z1iEuփņ7=T ONZg/;D1AybkUS!5wNѠs(>'g0Zb`s9lؤ!8 5޷j7{{¹0KnN"s צ'W$m뒏2ΜzC y܃iE v&+Ĉ̳ibTq׊M!مde2:ƽH1 b%ur0(Nmlu=v6MzQ2 ?ءHvŘΦ4Kl)3f7Os Biz"nTckf*\_=;Y~,$T 20RSu~QEF~Q5goj'ӊ@r$]PF}m36䶑*9ΉD -4y1 xj@9(>\ U]Q<îfC8/ᘁd\x{};RR֕l5Tj?7tpGB]شʲq3 *YOLS\7jD6x'C>>GE?[{}0N}5|`*->SoX En;hw&Vh;dN.[MI9S;땖Aw% M,Wsmvł?o^FVԊCWSXto;EO{0ZPHZ P:S(lC NUVu69 +iw2TElL#I޺?ͻzD.LJD-.hwyV'6fa]x궚G풨 w4_e>_DpR(pڰ5Q1Ufp/ o⳦SVs.UjVɌ^)֣( {/Rr׶cr),vu_TY*Rx819BF#QՙDsbS ,pMe {.O Gk5)ט•恶v$k?ol.jИ-hY/iˆj2$@ȣU/:?-= Vp$d 1L1mOpiJXۼq0PYpXj0n[K=`>L&m̕܎E50=ѽC9q6ۄ1365U5.=K/4Ky>+E/o;$H4F_rD+fR, ˔88_zD<W)_@n8`tzk8˓>[`E4<G349cE-eD4 &EۚOwG.e$]ȎzFNZ! OT$ 1|-Ư(NPμ Fڬ^,Sʉ'GU0 ,_ఊ5 ùY|D ޟaS<#ugn\6_ܿ|2<")9pKjl S-eSÿrh4q"v"~KVm2ECt,_~Gϣo|1r?67yCTw--n7SsH|/;[_썱^CO}o; F7d3]{IR߼I4]076ObJT%W6<4s 0jb^!k`B B1R=&:.WSψ ȸj9T ߥubAi}_$B 2.)+VUƦ]GA Q .*E-HL1<$wvX mRg{I&tz r/Sq/Lܖ: Xl.e|~|͎T'휭 J/ψGSV!:U7"7sv@~eRUN]~OG=41GKT!+D1_ޠaۮ1 @&P3,/xtNzi{QȨ]21fq*?c:\Z? |TJ\d([*iв!T[AmJ<;%5Ec2k%b!횲\tĠ0iI]Hۿ!s%* xJogtk{Y0n 29v=[򁞙z$t/ #_)-80]ad5yـW7h{Gy'zC߮*{HPݔQ8H3_nךpL6%L0ӡpަBEvfu)Od;Yըux]qչWܶ]+oo d㴗F!I,2!#OV͈q8cP>`ZB*>n~<~!`cjs"j]S+d &(uN .l? %p$roQ婟 F2zӕܦ])^(n;:>czfbC{ý- zKi|x ܃0wtsI 5ߎvǦ--< џ}Pͤdg1Ғ2 .,1?I*vնPM'}bLQ%z:Lb"b/L VE_֮g7Z 58q VmNRWR,1 뛪zC83bzêdrZRx 3L8_Q8JDD>:AѻbWܒKݩ$ \ӛYgQ}UfkF01A6K&ҋ ;l܃NbuS{V8ϺO8( "i`?ٌ`w*JaE{3,p %B0/!ˆ-0 .cҳkٵ̒6sߣ_kӿY vnQ\B$PtC]D(r1VÒB)*۫Sdeᮻf]7ؚH-xw`<ŏ:DX; |n1H7b]o"u;ρ|Ҹ-Ko:"r_JJ}Ac0j쁪g~8Sv|94+<:iI 87M@#xb*.|-,``J3jAZ}O|SRƇʝ]QCSRpJ=:dD m~T)*ap$늑Efїwj  |*LjpwKb*4U>8ß%~B~5`P+4^c<djCXgE*:,(QFT3sF^h2=ex9tYz]#WYmL1nk2TTs5yE(rg٭OW;ev h% ?}Z)pjMBʴE48l Su YO]mBL*274y:z Cm}a{ 7ٸH;ڦDU@3!V]k+ K fNHJ}_j6<:c FxI ˷L8[-oa\fHUs'Qei*96 X+z#,ÒZ.ӂ3A'L(/D \H^wp`-G-QzzG ;Ձb6 ?hsWLX(q!nxHtG]wO&)]a'7"C3nR7;SmҾ.J2݂bu9l̻z +,'hۀ ?ث д!4O_5$}7e3g>(cgػ#z"t_!be$  (N42I*}ȮyoYce-e܌B­F-0^:6%L:2XN9A>,HaXO8fJOHx<)V6]ɱl,U§2ZVIU rǻUֿt\}B[2QTõ(كz$!PS"k]Va< z~~Evyf.^& MƑ*7U)Hf'^w;iV1jGWC_j y1)*eq;v U=;"SNW#Bz޴`9R gg;L 6ٟRG/)c:BW`zM#FΊ[È|:U|B Ռ L;t3D . kbBÐ< %zU9C+|}9,JX$ |~NO1T﷤Y(W.Vb2i5:O=qw OFLvg-H$ hgvk-VV-O$qA 7Ruf&.)!daYWc< =|R_;%O=YdtUǒVO8s*p~qa-hK죤 ¹wfƔW0E#@ߤOU(R1à i(NLVFޕW!"Enm{0Ȟ~.y9a |'#QyRy*Ͱ"TyF<.tq,ߜ1̜e,R8PtTSż܍j7NCICZF? IXEġ" yN*?to%ЏT$;x b/DM m(CK딐7mpW=p$LxL9'Jsyile;oTҽ jw/*勛!zò } Lt%>K$<6 `'uOذg;Ф17863>e&Oql3o#4ڊG;r]8شOnUI?\ N헀pĻGU X麓n\shkl\pĘF-UI7 =}38'Hܫ$#}` /s2~aLRJx栉 AO1VGy1@uĐTVvDVQ#|u<;rYNG}%,, 7M@N٭jsd#8xihJޤ$@@@U+Կ0ᖨVŪqE%o3#'_DI0݃71Ec8- @&ڟð+ߩLsijQ_FfFokMCGI{0Wi1UΫzɅ0NhjJH`>!g:kM"bbaPWqۤZtU#=rnPE!2rt{3K]Mcvi ݎ"w2cCΫqD8 .O k26rQ sE ntp,d]ßsIҿMY'e%Sh$@@?wFE{1MO}ȁH_ʼش#&d\⽭L;:^jܳ8Gi8ոY^BF,_2:R.%.=#g`amtkbpSJQSyߴ*羓kަ`J>I#rpMˠ-XAA(!G0%t]h1R.Ŕh,)cjll@OZ\(*1΍X+fN,Qϐ7iHt}(>ɦ\щyKܵ O?æ\z_5n}xAXѺxan"bJԳNI 4%YFXPN;j4U )G$%A%,s7͝W|" $Ok^"d9Uy۽IJԝ߫fL-4b$72HW-[S'^i7%g;4y#]KCliڱn( ٮ3{,6(ۍ {+mD9fGR|=h~!W7Rz'#Bk^+j26ֱ*(v1slE Ljȵ O m0ڲh67oy(Xo\pVU#&>l4F)ݜk(e͋QnEI o(/yBp39=/k`)ʎ%zq>?×g@)~a LW0aE>趷ܴ 2]ȠQq9RB 9,@b,ۙTc LmS#3DgE>&Q!0 ^ R4MKo԰l0, !b4 D8!w^"LFA|PLFy 5x޸i'(ғkwl9B?O+DPRiyA7gpZ&%ܶ3;V i 'zVÓc@&\44q#0fA{qnv(k}ݩ6e9MFh ( hbO~E/ db)M{-xh侰I"S6P R;Μ5re_<}9(o"_S$Ĵy*]db !<$ %J=5OxfB;U7LZ(Iaaƾr1;dO/8]YuPDs*y˧!DGĿ:q*m%h +e+STQ,Q":7V!FӮ9ﺴ5d)ut7T KOܡ_:e,_,IjO\qM4-`G[N/ƛ\4pjz5TMʂApKz⊰MͪG1 HcgI%8dێDbzcd,7ĭk*)0עUyT(@bݱ (Ku:baNJp'zZqs~H $)lȪxf8|^E]PKO>ԎG9A 4xU& ENW캩2@ չi˽TW~3>O `M"G '{+>+9 /lCJ+u3-J!iVʹKh_~1%*&δ4~[4L(q/QOy4{}TE9md5xQQ-J}x#/9q\d]v5X`aǣNLѠVY0E}Y^.?\s$~'NLէRhâEYrQY؇ >քͼEHwEހ8$9z͂MQL_iik峸d+f^Zr]|D ^_;+k*{iqe<B]~S2?a^׌2sYݚ1TFB5TϻbeF}SN< Q:SU$њO(ଦ֖t"̀W^W5nj@k%dCwp< DViQO+Q섔c`'ܑ@#q+V*}47NYvQVpIUOu93J`@loS])J:,DS.,eq8j'At0يFt ⛠[u\ZyaVMx銃nIVRSajܿw9gLwf oвzUl*@O֛L3IȹZX_ d916Tjj.@=w^ )#.e&L)?G8A=S#Bǹ8(3.ZsaM톌$Qѯ4EaБK:䗕#Oy!2Nf ;RK5mF8C ^N"[UBYI,f9Ay<'lh8K'Zqf(TNr?*qQi*Ւw˕M1W-u;9::?ͣ ri/!+UW)]jP9 leqhWʋDi VcCR7AFo:R fH"ޕ>YνflY-gߛs1,VjЇ[Ӿ0:1nhtJv %Bg6i |;׳ i4w =GwX'N٥8}#rj'5nTMfV{Tŝ|+[;hI# IRM8!7̓|EybĜ1e~;B,ɜ-c #C@jh"OW-pu>lKG۝nQL,tĉpGK1$NSQFYQC.#3hf&6Wۍ_&") 3j{)Me ͟2(J.SD-,]:eAOIq\.N[Ty]o/c<͸G9-LHklGXƵq&z[G!< LGb4zp]+Fb݌/W_JJMD @gܠOo˻ ={-<q,EՎd(1h^K.o͂{fb66z^o|k``s\5ZԮԀbe fn XSkyy E~~K3>i(Ebm؃(v?ujzؗn7A!(>^()oNT|I3,s b)w. MhBVn]XOGQ-\8Ced1fu­: oCKeWP5՜n.io Dem=,§Q/[G$8yu(r 샐$jE X:͔jTs⺛* gamKn`ECz?uF IB"+4NrP9 f<{!sLt~#HBoʥFRQ6E}5MNL[zx%wu6tjbO.c@= :I3biD#Xqc̕!C5pIyR >*\YA݂/ȉJ]{?$ c׮kyڍ:,lci xV.~\RF{D4k~Dž唴TlxMM;j{us)a37%u.'cv0X/D]U|VjߝJU UR*#/V.>G/$zWivg٭vkl V@'ׂZgQ&S .Z$ 9+q~mGf*fA>[q^"+I EʫlYQyi5^@< X4_˳hQ]dZe u"T]:Uo-[0vEMUh.z6f(*e؃M N!asԴIPk1J{ Fv. |&=|ҾasGĿ q8:wt~<1+8flϋ=ͬ}^NFQ7t A+GgՖ1I\اAmI<5pSjܹU,<II}{](<%N~P_ u7r蹼d;B%=X\,+/Dg;j"X\ ĭjߟ-?0O.|:~kPᘚhMcܑ|\nYebPK1BAG<"M/bc :< vS*=Ե$h n{*ۆq9cSN]5: H""DH obhnדV. qW##E Z,M: lOQ=JKeȒ _E构`^Y܇uɣɬSJ@tW8%+);d Rqʥʄ;(qVm , Fu bwVG"׿.@!w;/x$1؜8[S@UJ_†% ,肥u@ F 2Idg;TPlL-Br FΚbܷ® a*T+m{1[=zzcgXG|yP"a81)j`ꂇ_(zIg-0hOiu _|RRķkUR+ү`(x͎3%WV2i?--@; z=fȁPM`$7z0B,'$-? 9o/?I?!-øؗUu"Fk@?X-C,E9%zwkvQX:Է="XRQ`VX^h~WN I?Vsk2-Or ([[ڷ"%iJ z+NCvEd,[0S2ą#|AJ;-,P}3q۫?Nп$&X η,G^1^vaUcy7JyP%@ iEDŘE2+:ъxjwPUJxעzSHAG4R܈2KF)o 4 Qq\eǫ];mVd=9P@KtH2۫mmN}K,fiK޴):4W*rJygjIѝȶ-җ.vM](wslڼjהC'f(CahM wTTS͆k7)pw_Zm#GKiVc^K".v"vx\mQ@uPQ2tRZNmgjD'lF*y>F*NE;g(J$gApTwJG_aM/8ºtݔSL*,t Cؼ*0֍VK8#^fi]#'br"ԁPAg(26$k n42jY*5ee ʻ:B ԡhZ&6-48S>9&j+\)oJF =Y۸y[WiTnWn M#XvopNTg+yb ٖ-_aPp"vRvke Fѐ[%*s څd ;p]@^W{G5IyQ9ϨrDr(cġVH>ᠭQj-A3XORtH+t FWT[™#V2eqJ}+zZUͭl q*dBJ}}6Fh>UPt`ڣtDq߭btfhe&렖G;(A1&B7#6:]D)F#=H p\+0ɱF64ab`^8,fg.x0!D6ܴ0?)2VSVl,$RaFOu(P߮`ӼnkaY?#k}!^6$ I򿩋}ڦշk֥# [+ycy#׵@:][:(H ՛ZP+^P1xЂdzU!`HI> kBckH)P)|H )A 8(l5[ǵ-VZ}~|SәRl'ZGkۉJ#0<:Lѹ5!H!%P iݢNUK@|_{{ƨٺݨW}fjk=^/kAvg/#abf Iի}T㵆PKjjO5EM_鳟tN&lh[* u|K-0x { \[ #p8^/vu2ZMwXT1XNQ1.Wy('tHqng>6(ť?4!xFE)'Zg#%-j*NoHJX( ,b)?)Rc\30&26OM[IoκЯ'\ l;>8:iX8eD3jVdf=VidV8aQq+ WnH'`LswY-Ll<ť_<"$?m˖Ip,5myˑ UMfJ=IF츙"=A[&[(ĠxRn6OSӟݹ{=R2r)+i$n ӄUPNҸ<!vvBѐÂY)OQItw)R5::uRZv i_h>|>t#%-4773ܣOMWC%}^,qȮ <χ=|1Lr0JE^0O#A먪NFjq 0$ t:ObzVx lSB10E8k7V.$†wp?']{1G7cH{٘٩-/wm[+ }vg).N6CP}[ø)W?{dWG8KX&WL6{")WP5cj( s^g8z1ހ%'ŘRwc'ϮΛzDm*EYz"mm>:c5Vj=x~#U6l ';G-'I][u *N&k+M2wr`$$vqk+q!dc"d9 0g!+5S1zp>U4od.B#?Ƴ>ggՆ=eNz$J%0slnP)pk0ReU07eU L[Jv0!f29tBjHD!Ġ11*F qpuKaVc@\S5tUybHn(x^4;CR1\ o, ?`#C4M901;Df;Tz 26D/x~qaz|ٜlK q@]E@sKDqSg\M$ڄ>yተ,{r'o\/ݨx5AFרu>~m"zNj4!|c8ԹZ˵>+R(=ڮ]a~@0$#/;~ IV)Iz PGq%tqz}/ Mc( T\VU?xTE/;_ˊ eX.mύ&c(?6+yjb&^&6P18c%m3ۍC?(7+KY~\4ֈKsh a!{q,,Tm.uhlY[3H {636AHIvwEcY&~ymu*,LRiS}ڟAs> !?~cPx\'Kln2 ^bM"{(7"55lN\ԇI⦘JÿE \uh60 EʺҍtPCvͨפPbO{m Yp 5YfhB'thS|N V<}+ ▅!R$qWۆoǃ3zJ@ *!'*KmZ>00Mn(O9챿񪿗t^2yFGJO|<0`ݣ#fˉt3AX{h烼 @y"*FK?LVUS9B l}͟jAO}Mcc[6>Q @W)9yEK2qsQ^W_pspwdjaWVGTc@ƧEg n57 tCM/u*0DĽU*Qv27AѩP'rHnv@ax(+aw5}ξ2SN[_O=HH\R)H^|#-5l|gk4E WzAMsC-W㘢F2Q\2EL!]M,A51COpUE=AP!:@|nAixtgˉ<19mrQ}?P?"ž9)jO :P2HCBB> W5# JXڙi@bm("ÖiIt) .crfmE.]82{k9H^07)8XGŔ`Oþ,/{{q3Nj SZ_^wbweYh +ʕߕR/6ɌɄ*E/ѝ"JC{ {H"%EVQ2Z܏;8EgT34=BAQr@!c$Sʢ`oDvP=ßy7:R-ʚh t>p[Lʴeop]}^[[&̻ ڒ=zswdL5-(6tqzYVO, RN[ 5 'Β u= `*%K˂iVPѓfy%S/Ԧm^Z @􏡌f8~/`ixf$do ,aLԯOa' Kύ}9tzL63HLʃƋ`I++#Ɇ#]>VȰc%쌮gݞv,_فZ4 ={]`GMawe2kaQ\C1%֪ S K<2FBG]BJ\Ϧ98 d1;n{>l E+9ľTbH:ۭoapS73e9w)%@DŠ0%e崙=zTC씼M]HtLq`-W0t*\ɩ=x0KHn%$g:@ LW%ϯBv윆.K(a^φ! ? bƱ@s$;:_ P:蟷'M? `ߖzksgHl7G k- ^Yk6s<ѿ%r3*:~gbTso>2Rhj NKMX/G_ˋ`aBU@!zΩCy[!7%ʱi$P#.7V dX#D>fpO)E&bzڻ%q VUL6F:*)`CC5-@-RWei4:*YU gk*)W#˽D-,ww|a6qI7&TM ycm7PWJc^-_reqwbݖ DŽ{Ŏh bZ$b 3UEp_`aHe7Lvo'!Wh+h_pB fݍI,$VDH.Ǔ7a'܁v]K4.X/Q%-vRTf+o1< 0?sN/iPwU TJZ,?b}x-qWt&zj%=iYa -U0Bxs>$ *լ dW{1еta?҉FsꉭnдMĒ?Qh&_=Dyy7mdCMH#fuF\]\$i[iVdRnclmSn+ױQva&_?ߦ?=I|W$z+jOIM7`;n"*AYe(T9ind鵤QmKuI򼆊)?!Uọ}ѱ_2WL}D[BjIwU7+q'4rIۂ@v= j9}')MIۇ6nY,YtD dm82+cnO_c=HB[%`L&Y#ZdSO:~%SFNYR!R n--.![ƯS)݊@F|է*( EL~R$KbAg7%k-"-:fP䑳a.3b?mxPM1l]b?92+Iϥ6v\E׶&8BZY\,>0#r_QFpg:=%y|>r˝~ݟL3Ґ]z; 'k *#ah/>Ƞ7TыTJ~ pu Y9z!eh~n9a8;AH"~l'ۓ0l_le), ` "+8:'ieahE81Y LO4ӎ(5GG."OCLljJrᆩĻo;M#6&ޯ."; #M(r>T~D[Ws"Z`8*4u= 9v%6K d%m }a'Q?w%;JqXj$QqЀljCy˟ɰV   @S*ka򐕫;j=0 ҅E *6*yhOI>6\[),[]s+aRl -VQ>d`~($ß4jq 3| 38^pWΙ<>oSVH& ~u!rB{m5?$heo&쯊R/*R?1yCT?CSAgj8N/E]u<ci*by i/C>ߣQ6imYߟnxDZoX80(d^Y봱WHz"<:OIw# {ao#-BJB 6jF|E׵{³_BA;g-}y8䂷"$`r+Aq̄y,-֊CAMoOGrdZ+!On|$ld>Q)}^ZF0RlB2WL/&5~{,` CA=ہ6F]O2{L}ޅy^S`TLuV L_AfN8lJfݦmlk'OUvy5C 5 ^%{MM۝}xr?$QwYsֱ0~H5 H/ylU<7ZAͯQIAvƷ(RޝQ~R*{+*AsݥYe&)29,qUnP]A*/_ , 8p6 Wѕ_p2g@gxe_3?,{]&o2lX_wC >{*G ΣϚ^֬ ߥZd!Q@D5E5<'Eq Df ,-- v[ev'9,9$* SLa֢.}6=@x MqD=0Du<=Xq3̚swjc5בIcf*U$5+C.Ȗh[e>4zH˿,t lY0vU6|.qZeS@\dл "gR+EjUvVg ٶ,B/Z\4,Ul|]'R!냊3ֹrղQ*j(&OZ|6t fpt5jǷ 6ьFN15P<ݣ?صBx-I?OC;Uj~ߌkZ40X-uZ+֐DpwhegשW[ qjm"_=/xuu,_k7>=Q~3Lσ,cȸ}!b#̠ hbƸal(G…lC-s){Ek3?#aKTOWMdop"*WgYPqETKcZI7lHWokp#lq51][S|5/]SEڵ:.,tM"r 5^>1A:pՆ7~rn P5D%G NKK"ꅔR &9SʨRXHS,u6 +*&I-/RuN~*xE: >3YCIw BD1+3Ay,B\y._ Ye(srၛW2A /\/afڼi?5b)T;q@4H5O1Ipw"(Qc$ݐD?ÊGWz=j= T+}f]NT Ȏ60ڮ2WMä/ABrd|" m/V#QQ)9wߍ;[G7 _( q(O~2AbB7T]'2662ǫTg;tF7h!LmVXj>|~mKbv$ `)oꡟ SI_xKHlzf hQߣtl\Էtw5P A<ޚ'D:nWXf-Tj % ?Ad#s< 18VJP+`9;S;wΤfї"a)xFMpr6M?mLd]eHbuC.s~su}NLO vwq/+>\0HRHO&? 5}FN2?EBS6u٣@'lj@nLV3a?ꆯuj q"I#G5>zp;M*-5J7iw!Ĭ:Oa ~oc7=\W 5j$AMI8:#N"*X1V(7 dƷ.Қ4 \20x+u<#!bݥBM~ԵBF[&1h@?m(RTG*b ex"H2$K|^:_ Xb\6PFmIɲ⾕s4%alG! IGAjy\b51m#\ 1O1+ڐGSHR1HL8YΙȏ C.K ^dLBFZ++ތ>Rfxh-y T CBfAؤO}ݒv=>5?ǭ!=kyo# HڮX`45]gvcC.0޵eȞ]_ymhvi {21V#,CO%MS5>ᰭՓ_>A1ǙJA; HC8[z86.se@[JǢpj,.ii0"#7.j?dl4[z@)q"$*.({1:Tuu.-u>#.Y܊! tOdP͋6vYUbXNL - spN@2 *J{&٥ ?d]^3ՠ l,Fq_5ӡs @\'lF s~c\֏?`_jZ"]>~X T wp K#݄3G&Ա֗sGiޝE \Qj5_c'xy%c;rI)wHpa( Uj崁Mj+߽V?ﬡe?Ĩu¹mUB*vgර:9{C{ũ"mU%ؕpL`]qwd]5oss<.gʏFD⾦ @TIMU7G?D\O+VQ2!uy#I#S)>0U ӏG .n傯'%􁚮?p7!2x21SL5 o?kL˘dԜ\4wF0&asT4Ina+_22RUphBnXADsy1{>n5kz[ bӨLkGbնlrHɞ-Hpʑ,b!wL3qlۛߔo6ZXI\.XEٽYeu˓pw'5ʩף[u1FX![|k*nJ``px.IFkYb | gxcn:rkt%q^ Dφ(*Uwm2y.Jޡ2#M*&a}NKվEN#J*{ߑ4`&}7-#п[ucRf >h8Owg-)itKnٻeBhvlԼ BLeS _ :%!X2f OEaşO{e>BӯvwC\2s҆~~ Qt_pd\LJbp*M/ֺ8|/E{NJvK}L+*l9:=o6Rk733dR)U-S9HcJ,j4oԼ)<8cMwnZuky+Z*7fآl2:W>3GePMOr^[)D } ^<љ{8Yb):2 7# TЁ*,4NJ 8z)~mx<`pXxPbLo2a;oYSTBX|obb*@!f`k?P"ԮhB 4o?(ϊ|btYy~a<=|`Ww,6Y"& yLuLeCzWbiZkT:'[03$/6]jC1̬6V]hH)5R teP)Q ^ w%Be*g* |/r &eVASgׅՆ>tdڝYpvA6ke߄4p ƴnC;mx օz[R6DajOnb[`gφvM=d*,q  }4{lHfof\{?aeñ 2hW]h_:LHH6m.Czb#@ؒ)'- A(9^4=ťUlnqN@7w8?XQw 5ĖKp|3%DM*FxԈ4NQnLp'nLd1#'DLrckݵ1zw@;"uPC jMhqٶHs6}Ε50ҵ^7cjq`݈#Gvy;00 *PyDF\Cx%6D{ {5yHp6,AoJbx0˧ŦH0}W] X2"R,;z= l Ѫ9׋\ RtFe= C>Di-U:* TPk>73'g鴌qRRg n|C8dfr1'L1u6ie_ l(IsB/,eͭ1ܧeWȭuvZP`[P"vrU~lHRU,j"+U ^jw@1}Od0"a RpMReԫn>B/dqhFHYXf뀻y 'pؑ4OWCױSZف<=u Xfd_9<^b̸ζD^o_+ӚVZSI` >YN^U9x"SF9 4:@E~(zihuk| ;nْܼd Ņ6]oL̹}̨$%aSFêJ|6~\(mP` :>gu<&fo b[M(g셰b1'xTd.d3aNO{I:].`q@)Mҿ^>~ic~&:/}U5RƛPb!)/#Xvtſ NbMǡ-E! V+q8#%է׽! RiԖ9DRP#"_ΠI/~kjr!S۸(!"tt-Bjayx+@Ġr<1ls1c-;@#fǨX{o]M[4H3bHfCrDl(4%byA<&!y87Y x.LR; ^lH6✜};ÒD[nQs 1)gmٙ&K0I_MhƸ@}P~*O_ѨCT.-@p> M`KOH(6/RӰEra'ḧw#;|ʉm*-D5>0b bvMd̴w_xH߁e8'%?"&+,͉ .i8!<{r?# ޥu)^)l.tTT;%P5q{$JaH=OS3q@}y48m} {˥yGdjO|~oE+"U!M̧j a|v1ȣ$ \IgF-pz8yl_9suqER4UXǷ y YJ S[ϳSm9 l 1P:!W-W=s722y bǃ P$!Xl{A7Qs',%)EO>ppOyf4W"è^^E&)bc$,[d!s.+b^\]lp(D>jK:\%LTe/R\ُ9y$#D1T,v>-|D?Z\K{b`̼CF&~lr zɷ9“}"yh$@sLV#ӤҳC#viRJ˶4ec3 Ѩ  cM^z!k2ɺۄ+l yӜz(5w:b2Mb$;RyV>J5s@`r ^'Z7R~0O1oߺA&s)PhȅSݓ0A?D@#貶Jzh8֊ }#VZjI٧s!Ы46WՊ/JH@y[N`8K@7~eo5jɦD,Z@Iګa2>+q Y\ wgyItË}S]F][QSAsČLJ1к}4j}Dl&VS ig4/ny0beA]0|sALdy7Q~ -Db[>g`|9qZWYa؆Pd)œAǙ3DI  dxP:< dwُ$ Khh O LTūx!Z04"|3Z˲1nAbfkcƸ"* x OƼ`x6$NQb2o8(NS8{Hwg3n0-t^{̓+,O|sttRp$k-rvL?'$Z69PO7J֨]Ll" 3#"2EË (;|woKGP몲 #1 r5сc hNip#1f!glnhfkn' v‚<ڍMQ+6[dD\-#$Ǻfd#96$Gjrx?jbO1d)機QaK1QEr,́/9 R!.zaetd~ ƴ 7;o[b :>FBodEC2>\_fsįi90(KD-(7ZCoEGu?ќB|GSic~< Y=0$>^AyCC~T7W#Yo,qMX< @$ y .U~ xNG,֤T^]HMƫ8%6;kf㐛%3=j(3A{@X "siT+&c+=:rΣ</h ž^j?3= A*;Lytjn9/l`s^5)ч& rC7i:n2l $kuҠ\3oo1ϕ Y &uJQsBE}#9`\[^)F5,ew8s6"*(l*3Y1 8;aMHL>bA':7ˇҌ+pGT LA]#TS ҭ+ pM+pȣtP cg^]"Y 5J :bM Jy}I3guI{==)Jc)IGu9;?@y>L.{m [N*jKb%}7}5 |‚LCM+?2Շ)*Se;{F;="ٲd`~8K)F711}8쓙Cj7So P;\:Iz=ϛQV` h LPP\,1ޣ85W4m(B@.Oq?EA]ٔ8< g1Хl,nV׶#;[;շ2"'k# sx ʽހ]>'ob!ڰe&L|4 8(gɨEZ->FY"To\ǃ/e(3zm2n%[GEH>?1\8 7. eEJF7;#DSbFQD#ˌ Wd.3Ix*=Oi7Ғe#6?L)#[7 KY>9N^쇦:zU#pM2:蟑ѾfdrBW^TjiFpt)}̘s:! b~P67ĥ{a,Ve4\.V"O9|}:{]SUG}B:"8PF$sC66WE'a q㔽"-[ɳ6JM^ɉ?Jsv( :d֑R6Z,ATУ}:L5}@ZIMQo0n;D@Bs=(7ּ$|xi/$D9~/V6.l E\mV[ÚWy^ȇ!HbۦClqssS4;7\ bB5  @~vuvh9@k3riΪ>eB5@ "s+EIb#@`} JY_ { &;Uy:{`d2IdB9]m|qpmJ%,]FP_-HJGoLӾRƟsL a~ L^+6$TWaG |0UÈ|5D*l si yAg -f]&Z+ ՛/rdA[Wf=Gc3I -zV*y+BJ/sn干R -1h2Z8h"yMv1[5q930r WS=tY?^E<ף_Q=)tLԺ}.삳&AW4+XY"4IST Ā0`ٍͷqklicAÖ:Q{n\/Q@4u0w#׎D`N#& Q,j% ӐW Ib姢ODZ~wGRÏ=XadRK5F^ "0"riB'^}VWO,!3NDbt owF[lp4 kQ K9%Q-B= a1$&.R sUG:*!Q&r;b\S-K`md#)1бZd7k;i48G)"<5c?%ֈ`o v5;à✐<52/Eh&pW2a3&(CrX[Nk$uq d[^-K[XZv4R!NUs (BtQ`41AfT9[7i,Kl׭UW9-d P>[[iyϠGQJ_E.&y33 ZJP\O=nG֡hmWݜE3a"5&- ,(֗ "D*_Tqm4s(0OHWĀkBnI[d"svkRt uaQ0MƐ3GkG:`:$z_PON$7uq?"ŏ1 y]Ҳ3Q~D&=tɉt3ʍ"ew 󎖲Xfi9W4uqb|a,!*),%N.iխ\b_R=ȿQNzڦ-U(*Rufja.Mƚk9۳]`_]bFNJxG{`Nѷ4ٍ7JA2jcXq# ʣ=aŖ$mC?/ < Dﯵ e٥PWZ"N3U};0LCυX@D5TbD6EXqA#'Ă܈Hy)o3(2턷L8M0I{'[ådGvEd-;yp2vB¤H?iAv 8VYY Lu~†>.+x=Bɻz-u2BT^Cם%X׮Nǂ H#ܿq#36R"~B%qIMs5l%+1(bh[lA nSHIؿhk| Nqh7lRA2YcXb8dOe "T|ˎI^zf!-Z%).ͥvC˺:0Xߢ(MW4aXH]$篼qvֱ&`1g ?lGd3AõYfuu>N0$soD[>QJX&Z9`:2q0ov)Ms.g|*?,~8"7C: BO| Y@l_$\6.I)"BldAS-'r B00Xrf~K6L5>LP W JQi ICZAȫ1IfE)1W/sL,QϥTC͑8SpjsI /od #!0(ͦ7;‡k4Ow/2Ap[&ny{EЧ,^]Fnfl`BBx D~,몞L%o{!2dTW\+YtSI).?#\g-{Ɋ7P(|\ɿ؞՗1篥&mjbPR$F3T8.ͽk.LK r5w0jÝ atqISbG dE dXZXI‚F}#rx1R`w^Р~. Hт⮑{ =bOq%\ ~&YA jZ,;!F )g:$Z,~ Dfof^+P$"sYL% {r~t"yC6i?{`Et|OT3DĉZ9PnK=Rƛ+%[_+"#5ª37ԯ`3>/kJ= ͉g`OhL L y iZrS؈ $<箄Y_i# /%+‹Vh?HXIuV@+>&}} _hLok "081%Do\*J_w*Gn4li,zn:#mmn5w3G(DV0chERm0jU TӳYuqZ=tAFYG* ֝DJC4iݠ|'B +T! |7i>;)C ۦPLx2#[ίT@+[F %_a_S5_,]GteWN / 撺ys0Z{߭.3:#3 {!R=:$Vd:X{t0w'g{t5niو$Φ (M8kQBrg\$N@?a@8/\Ab,X_\k6I,u,ae9x䓞@<=D'[u= yM FrbGYFSQwSLجGL!h{`C/ɻ|7-\^ʲ 5>BD;ǹۨBڔ|]'.R!_.CLB|޿x՚eb MZdCT4k4+b wF<&F08yfc &BmWʊjJw9_/m-ynh?nhQDaB1F# $&è5m%&]uҸ/뎙_Y88ަ)A<Ċ#򩐹mImd}+lXcKFogkŋIN:¨}t99 wM{ze54EZAY8-Bܣe3h^[dUT_p[j벝랖:kRq"l4UXHA2V.MJV$!%6My,c[N yD᾵R,8zwT:?,&y[kdl [' w_ [\/Ej'=㥢g%gg1 *>76z@;as[pKK\b%fA(c+ebw !CNxrpɎdJw{>7ekA|3;=v$%#dƯG{|x嵯t߄9a[2h0 z"TŜNV H,r X[W?M۶p ʀBFh$9[ .fW-Wɚ}\T^!$dAϡ񁡡ݳ1'1V'' p^c}=i/!jqF_v'aJ"SåsN~5 cj|Ucq idL`\=@0HT?,$1ƬjU܂Hm77~t0-u4!0g-ItiTԲ2'<"4K'|Ҥ5@Q-m<7 ‚)+K+R`4wauJ]Y ! $n !}^?R哗_BԽVh޾F0SP8%.JǏpOBLs9ٔK4D7 A;ήAlDj/Y"GY¥>;sa/b$.2$;!gRwYv󈍍:t(Ze]u$ +˖tpqH$`=bsuq˜=NC\_xs'p:hU_p٩ITg]k#yʲꢬk0h/|v&:Z/v²<հ rZ1 |<"N8rgC5OvFy~3U髷oZN"օβK5d,/OVb9ԊF)80'RNea,jI0h7E:x7;bQtg>H%_uCI`W,l.4=:dҙTmGޯO;gaYx:K 5>;mwV*OO]U4<I\lHV%4iqG9hD@oIDf~ ĩũNW$9v2'!f F(y;bۙXRm8-`2 ϼk*,r wӦ*舁[.RcBx N5;v^{'a2Lƅ- $m9WͅXwjB6nY ?h ;VBĴSI@dkн7#u!JH_ʤz "t*PNs*$t"c& t5r{1V^B=$I ]R>Jl%mF'p2h ^ьH;_>6y8*{dc$$IO qˀFxJzk 8$'J] A92rlbQ[Bg;嘵<+Z5'/kI'UPROo>8XAU"ӋF P(-HyL0 pm} >iQiH /iԁGWW0a)*I{&87u]~ȢE1zJվ%RpGb|n~Ì'dXTROgvP;=tofTAF%l."HsΝOCI *--:_pcLKN8sě]ڑ"|b)Y.qu3` k9^ ?@ Rn<]lKc6XNe%6vqNY;zЅݑ%Zi:\N36ـTReA⾌m8-`'|>ͽQ5$ġ#R`hA{ c$2V-rBA%~,M͞EeCfIM)t"p@rO8L>$#dbZ?UY̺s"rCKON3@B;(OFVp ϧ#Uh˖q1ѮM"eO\ =r5``qߧ;(b}ޛ;t_D!>ylJ9iسwo׏B]?k,R)# asۙqR 8WnOTQϰ p}Gc رcj.<{|rOلWPP G6K19J}}hJ ʇpk)E{mxTe{5߽y -$eOn6o?}5bFJ*@"QR43!YRFZi["MChwjB`#;].OdG4?ʔ'ÿ7CA3dS y1rVYJDW̖AϏɝdpn>XFO5% F-ț ւSs!L3ll% <1R%i 0M |:wmnUt B8\ITcn>̛#y#?t0b@mk[9,|bBXC~)V{^"C|sU3 {:Gn/J-j7e2>y Vzմo (/ELy8U hƱ͊؛Bh.Bɞ:tGhtL'={9E} V}x e8BKtM8i,@ R䠳>LŃ,$n)G6j9(NAU%o5oRnE^PޏXu:h=Br ҝǫG2y!b,E+6P']RvE#t<fu7t/Ҡks\lWk>y`)SgƲXq4s3ڶz?g ;٩WV'V7IY6Ii˶DdPة10cQO\ӺI;`v%5NC@\;FVMvZ4'n'--FxXL4Qsy+G&N$j嵴#rnҞ$}mt]9(b2ǨZK6nslIdamzE(9׻7ȏwg n @d uzѲaƨ2wei!UіH iwÉ4Og[I\(O nOEu_pQ-oU֪Uog5BdVi1El:y r+؄LퟒZO.X+eݷYy|W.eMsV%h#x5x@|3gsa z쿺SN>ɃrgIUqyWQA}rU+ʵWEjqIjxPILVA}eѳpyqY$- ͱDŲ&.:.ȣJ@DPi9) UhrNlЩāz_:J1̽ ryp-XN6.O*,v9!x{MxRtӗ5ɶ`G 69vhL`&5Nh(6t3Q=_q+|x !`ئEiq@"8.e؅*sX2itHN)[b7%Dla'·i<^zRFkktik*3^ 7 ϣգIn½@=;`+?_!m_} fb/^R@v\>g썘94˯/e#f20$%4YcD-ߩ&8͘M ]d60J/0Rq悫XA`̝6|!B?dc; ^c[V^8I!LÜ())%AOE"RkmP X׵pΛ#9bws)339-(u碧 b CAU4Wor6h-3OiO6kzАn2b- nHl!Ss,2ǫ𞌛qV@* ~pơp1#pU)ƳjKP7g#L>lfG}|IRz٧7rPq,ǵA<{C%#C)RqqG.\)Q9o$Qaқ!:hW{Ӈ[߾Hny p[1Re 4 D;L`}NqO{>I.G_𷊑")Ln;qhkG9Uog 1{u+|ďńwkN-,XdX܆87ծ[4GJXF' Oͷ[ZOڈ-2X37LZ"Q2̻4jf'Fyna7ԋ A]+Y#nddq$`GZ#gW pj 78dZ@' PؽRZ[zLtCeg4 ףŨ;EU+6p)<ь8O'j@MK<P$]oktΎznKq認hdfe7_WG91b; ~>/{bW}ޖRe_7M.)S kT'nBp+&A26-X7Ϩ '&lL'Q)Zp2q)dMT>qC7blނMV7 p.+*^lpD}D,π"19xR3*}aHAЙgeHy]UJQ*[0^nQ̸ (*(CxXgH$Ęo3DP4n%MX2g&{:!A>C)NQ; ҃ pf2u4c43~}1b<( š' zp\Z%)#U=)1) {Z4ЄdJ#ja' :0_XܵC֔ظ8L[kҟs*A)Ȼ*oN-h"t>Ai8&J\)9O|Xv.|DvE9 To-=͠s.oS`!hT8?Hq4?T$) vh$h;rRgݔ!P`DDYrSh6C#_ jp M1IiɅ|e8VI(u"ȫcnA}gNs.+ ڃ&^=~?~]o8^6G >>ՙ,8y.q0[kN r+!SjO(6U["K**qɼ;j?㘗7+(& X f:r *H~a*DCKUNzW$hWC,F2ä$X4"6+W->{n|PTKFwMgxEq 92;Wb3/cuFO/ B@aP CK +s1ʟc ʻ/ `NsCk7bǴe-cമx{ ߽wo{Y^Q?%kz+]Q\}LY'/ t4/|~ßNkGtN ?ij(l ĸ kSsԱsʧ"r &!N "&ckɢU[aps̵{n9>cYOISq wل `&r&ΥL}oy4kVՑP o^w04Sf*_.1XNeS] ]%gRY8*閭 iYc}AK]XA~w1( %[wL, * DZ9lW>rNo0si M[ψɍiA,2Z`Qnl=p}Zwj Js-/%*ЇС_髛:<(#dL Mڕ|\lДT0k%8GP76eQU RͷA]jWXŎ9,J&RjZGsQ!dZ/[t̀"=$SB諜0\ }u9-t;cHc9 ȅG/kUq#(GMqLvXFNoyШeAjXvt78mX H%^4NID$扸A}EаԌ%hZC-t:Wr֪'C[ E9tAI0?-]d#xDz`'#6a/6cN{{$ȼwOC )̡DvZL "|KIQjwy3NߥBwSğD0lgBo>\ת3o4" $8tF-zDEފZu9fC4i!@ Hv<徠/:N:~8, =JR>Vhʗ!.@IRkscRjh@/}obu?2e7%1ٚ{cūͧyIz!=-5Llk΀Bz]CW$Cc&?G8rLrߣi#tu1&p gPC^=U*؁^ ߹9pþplCl8nZм*C'ymu"G-Hᬧ}KXMHpt,8 B2:彉Ig[X}*a|?؟Pdxؐa@:u7^?8sI"txh>Ъ>핓N gY}VBLL[dW.fB>ĻwT" kTrȧ+v68[2ixɶ3VpgNX)o|;_+F2Xmx ~jp VBmgĊ-4}L&og3a,(k]hw!֓,W8lc([]fbC<#DpulG7z(e`.9?q͞!2*Ƞ/;gx>ޥiߍۦ+xzOMN4" '}aPn: }7i&_4~<$"F +YK f Nxe+dc}rDی&(58a8邳MhWCjq|vX^ޢfGOVQ/yK|2, v>R?D]KpN73TiZvnf5*k`s8|+mk)~N@ (AaDk r[a50(7ރAЦýUes'Цtnr+"F$QF/_8IYY3!JKeA2Uh-(IIUu=b33 hӹݷ=ȃYXj3`ߧWUo$'j^T;4ȏr>ʬWr47Z(S͢p[]OiGRgN|SXEW[v|V6nJqjUF.cUO[A۾}Kȕ#S8_Ol+v ]f &3<bk~;߳;~m:rO1cAUh"qU-Ca UBT.Lr!zXȧ]%`W-I @G3|Ln07=>q&9(b żĕ>GK7w72 8)XZ1a~Tm`4%+^JI XM`Qz˿RLodFLx#O 09!*o6~) W"^Ư/l%mruނx!'[`-͒,ly#Z3ڡ1|pVO ѓB)4v3a EGSb6*eє%ID[§gռe_L )Y?$/-=beQ9IGˉ %EI|KP(qia(o\`,S}߳NJ.])IQ;Y[ӱOZ% MR-S_y*ťi6v;xZ?4Ԃ$[C_d,Am؍!Z-kT!І-mz?2BdA#e="XE^Ь(C`X.qVi_iN㹊 ,X z`Uufqy۟D-y۱$T/ -AKpƿ{[q։@杢Q8eʸ_͎qsRlvy = V'>Ni7GܹޤӔm>"g˞MfԾ*:t|50 ϨGȟU'1Yz]倥Gc/G},Lu1jOQika2Ȩo3LPާ,ܟquִNs;KAGz}B{cuZ-o8$tPG@1$]7{+xm!u xҰ6VY(0_%~ayj(߱ Z"śV*B&]oŘ~3G8.;i@(\^{R?v륕mBwQP\O"a %wo1|M"OjC;YNHR[ 1 K?&ݽ碫>iJR9BŶ7~d)ŃshA$#3FUjו]6:=oC~aDbHY9ksgK5=XP*"Ƞ@e^K[}WqKDn`\ ÛQdOkj|`MO$;r{Þy*g3/< "!r0&;8ҧZe⭩ZO,iVfo~6$T6Y #o_ $}(>][ieџiKmhr*:D8[+`\>HI݁#QMݏxRpCUQ$ZDlLVWvn)5ch,w.SٷQW|C8] )q&sT{H rkd^'nHhu` c}@+Q3|Ϸn%?)w̪A=INBB*x)g.s =[`fCj*HAn'9ɪԏcr{Qi1+A2Ԕa^fyWJVK|7<[Z$&SwA6Uv+ֺaFm% ŎO*EbO U3Ғ<)U8.EA% {N~54e2#*w4ź2NZ^ED(gUgXvxO BB‹`dϛlג?S¢fx&kWλ6Auqkɫת-!R ,a~KJ,TQf=bp{8o62'V'yg 죵G!fDdQm]28c]`iN촳QQ-5kV|)ͧSvϊ1!6aХd4!xܟʢB9Al%<2uF3:IZaA !\^V̜l\D DlQTI7 ֻ* OVń by&,l6hT A hmf$"T,XRԼW6&3]2~c0eؐ6r s)( x[5(s]&la|1_v0e iJI)r(YB ~}Y5)ԭ`Xk$P ~N=Cꣅf2T%WgbR V?)$/l!iœbk<5y{Yfw5YoA󼔹:s;aJ YSHA0Ba> q~Rz¢֚lGbٻpx(#YmTltZ"1 V&D#O!n ӧΖ[`QH(MC^MR`: Ǹ;ƉHȏR;Z  ?FTNPEof֑r^®p\Y C1THO0P s,XT|"rzf.DF\Lr9r+\{"DmQA*aC &!^M_ضv.PARt_=H IxJ@ٷrKVVo51횓p~{uMU5q\hݝ#}!}_&FJ.Z׍VXup38Ტ7@0$x?~q/!3KKx졁g.=+ZqG{&'*1 Jitu6Fhɩ7 Gg=G2z|z{˝Ҳ sRD9d޳a1 VCxq7Q:׋xF*5W+Hўߚ ;雞%ly"w6R [|2$\cz$̋(pú>Mz }ʕL'Xs jxj!ĔFf,&] BzjO`E eO0 ܘUR{3fλ;-@H|y"Jy Vj=[N"t LN&P4Z&!xJ]͋n(.4N|m/ kC\pYheatvyЄ 6uFC9VG[8a'[̦ig0.!@f6cynbMd% ./2WV*7Þ? RjG$p"H.>5$YrQ2{9(:a_<71JbhOWA}QyS̰B.;8_b ef¶g>bp|tB Nb5W#RVb;rtr3bc\F )V"5s,O]rcWsf`f)jd-иGi%&ohw`єo_[4yCV2e[6|!6@~:r>Zi 6 cxJ'*<[\MqJhE|mEBZ!j@_XZȦU.Db)4L>?!Y g{ 8gw=3@\/!:prb>b0)F{ cǚ-_@NNէP?/YVw85ޕuNJf;MJ$[I09ٸLॶq)}<~D מ~5Ervn@l= +_6H<(aTv?ފq\rN Lh|hPU?2R NEPipKPN}̬O.uww[e另6u͆\br0\>fN#;Go9f/HќM}q9S0Q}!߈@ zW(-6㬌:/E]Zz0,{>j.,'tA[Qi!%A4`bwފKT &)%X6Drm @ν10[a`t*ub.zUz&\g@qM ;Rs{991ltӺM=3bf=ѫ,’?0[8|4c=92ޑ3i(1pYVZ^xK<Ž{ "JF'2=<Wޤ>sO݈Z%QaZ-SG? +g.%fi,ᖟz8McdCf)t {Y@fW_[:'-0nbtLc6T" Z]r FXJdS5l!"k$%hBZAUa!V5 [N RD j 1>`1&+bz\5q-$ȺAEjȆiɭc [HLa=@cBb^E[0nr/T chZ<8 CHYK|QA;-F) DUsPxJ `0o *8[4A%EQ= 9np`Ip r* !zq$ O~}J~2J_9SH eNH8ܚIfM A! a.xQ*檚u5WO:rzԖA!; +p:4,^=Iw16/Ewt#f)3NY]8(aq[qa~^z$Ds^xwKÑxH]{N9!m@4\Reo/`cCn!2_kA?tJ#ؘZ0:[lW|8Tf3: D|m,;(XW3FIUS茍XӺ} ܍IoI-ӹϸ;26ua,>9A 6gE A$S+D0[P9EX $2"}yITdW~2(3a.i>kw+=_s,Z{TQ=LYq#?KX^oUmr+5B~AvOnъS a>VÍ=wj;,6싔k/xkyާnK6~屦Vmo(>Ӛ 'Z\ؓ+boa6W1(Պx#HF VƳ֢ WW Ubs}hk~T)ukeO?Y@^Yp]R0:j4{0W-l GX@DQrs]"D~Ni7͂{0/TAkV+'3N)K5|noeh9Y߯\B}t -CpQ4R+qvA/!{sv΃9rS/3CPܾ_&Bx6=ZU2s@->z* 33}R:Lp bMnXKV$̤09n/uݑX3SC&} k~P+>6Tf=oA+20/a 7)0- 947AF4q /xgJXBIc`HLiQ0RG$7b{}5u3,]-cAB#Pת3UH9y1_LHb,_+4hx8XJL<HE&~@Wy~]Rz5 M.8-\~kBQM]i'Ҩ,[$* F3#b$chɥ̀c_ ArTV Ъ kj(1h~Ÿ޹Pᓄgh36|U³O|gXJ7@P8jό=b>66ޚ(zBS)roYC558O}7ڕ rauw K`ЪՠH%z0)W_t )^L-~w$rp\ /C߭#(??K“U\?,F\ z(Ë L<4JLNeO9+T[O6ܖӕM?T~l&W PtT=cqvJ;}-} LM&X`x7,f}vnK8# V5Q"\q/oRCzw9Hf @w_L_~TJ#AĹtBjdU-Sf-eD|U%* ߁79hRD\OeqpuH,r 2J-?dtЇԻ 3|o% lzd DESmY9Z~ZrTwPjh :!}LhɴR*tY:\‘ M}4&`pW^<- 6I=b;)@bsh+@@su+8鯒Urp$j dv#gςҏ/5#$,]$PT1ZRq-azr#ҨGRz,lPµ6J}-e~cqud;զޯ<+=9y_eurc/>ԧЎjH(F1tuO  t@^,}`b+r[B Uy[@)$mbl?0$o(.ѵޮt֠(BH}bE^Bרzg2OLuAU_Ӑ @ǑC +hRك%vLGG'>H/!ߌRcM=d5S+ϾT~N)bw |Q0hZHL>A? K2?lvbd^EDQq(U8$ăb G|l[Q~~mw[;ʹjU;v}<齗Mv ( TcסH". ULS.[@ S~*DbVKʭsմ7NNn-h Iw{͜6RMU1 ;CA x3 lUM-w?^hkv$u 7z LS PcB`F{Y &2ܴ(e[|3P,F/H{7yͨĚrx8]k$"r.}(uΠ9wir|цuG0(κen]!U~OIx]z=UqLx'eMVX Y`\{V.V_Cj-@]5Eq>?KQ$)a.=ts>kM=:7H( /YTjӿIv:XOɖ4bd)[ailRfڭ!;]\1U02M $Yù m_60ڴc`^;9ze7ʶ6߱ImK͠G1PG_epjjs#~HM_/KfO&%Ie-2Җ7nJ\qsnbFF`(}7rW)c#|&`3.234ҙį$%+| rIM#Cx=`e_MvWLI#7T.7 كM\g Ӆ6NW; gЈq.l&)o\OёQ5G;Lݲ8PA? G*֡ ^0`I{ጓW4/]= G`WQY)ҲBίpCpZZQOB8c^o`90$ĕվ~lu4Liє#7hG;="؀oRc+Kpw D?P`9Ď.FAߥ:C?Ym`gM< l9= Zv 92k,hﻉw@t/ I*=HB$5z0?[O7 YXzkv7KN3_+ԫ!N"ʙlotsDI$g1ZabZ aӺ |Jl=},6pE oĠz$  ?J/$( iڧu8":ws^w웁o(?$>њیPʺtnp{./^D)1UƐBuwލK !lϏE#Ė iEЋejJǶ ಧV |]$Ue^6$xanOI.?b~ ||3LNegW9L*hs/!N&qKntSrrk#crdit_u33jQ66#~s. /gnj<7#.`xog'faDcZP]EL^iƉPd!@Zr;cuzsjIUU[,iZcGqiSV7$1gX+7N枦Ph t]͛y7MʣLB9ڞ(~o_^G}WG$߯22ÛC30v5-8$a/sP]pXIAad׿ɣàNpMKVM?i 'Ir@iۢ#Hg-jT NB^a!UǤQbd`7MH2U'?ǣ1o3(!.u&YSA\oT5}=);KնX>Tf̩eO9">&o> U 0|jgSvSF@x PPU\uޜjNxQc"AmbaB# d}jt;3Zai_3Y񚍩QU\1G!BG fWe4~aY:o8RSzc-M 3g))bP{9!$[@1r[t[kr9=kl+CWM<K ]s{i+ >E[)D'@Ei3V~C -iW#_*:0x|ru1Ԝ uyhRhT#_s;2e=>7PF$Jѓ܉y fDŒ{tFXh|BSъ@EV_h񑊛-$ϱdOfAGˤ^`_JMs:6:0}rV)RiH%-@BV#VXI&@JOeB:Na|ՉI/w=uL'!ʇx: ΗQ܁$!ټ&gdJF<h'(+#9B83S64&z(0JѬ]F! ~.ㆀlJ y!P/gZX@lފ9=p, ҷuvdz` 2N"i&Ҋyg#,HtJb&Rq0-%kJ3S;{gj" 2Fn9HTro HĬjhVO܃ˠDL^?OH!áLÐ+1xE|gBk:昒`HHE3` y2@nL)U5E P :q) sG2 B@7gaVGQ}##V6it j|4 K V翟hƢF}E*X3Ê۸_t8cӜC\X>QϺ6rI^;BZMAt#q^BFJ4陠Q a ;  J DK%\ѵӫݾ|KݢC9%Y" s)S5h"bE 147bI h):J$Ce\Qآ6 C$s!)r  wQߵ^93ޗۮU usL2^eX ;ȱkоr~ؗ.] :K"?ya:/V^"| 3a1TRRZ'p e^:By!wnդFKaRĨ`,xB*PEu3sCdFTXG&V-fQ;fdLEƥ[| 2&ԏ"Gq#ڗX 3W k=cN@&+B'Pȓ l2?uihYea|:K8),)Wڣ/>/y8]U!UMBpabo6BY=}J"@4 B$3*t|-O!Y4~W %5F L-y1>ݸ~#Hp>\)~=LuKCBΌaF4uzySÁXV2 YO3rC5FsL `E g]!/ My Uѐ)J-:@bĐ;8 =1c`IƑ?vS9zN^QY`1bPM;omOI6rI1{ȼMSSC'V 9IV K#&O?y (E>%)Y_OY\:=F: ؎ZrGi^iyt (M=WFI.Vj;^]Q#Տ!p R#-]c4 .Ւe}8/s\5BQ& :bi/׸4ïLj2|]E6xI5vr#>%LĚI}́vx8Zᆣuhx#tG7Tn=%i *w f84v5)sdR"dU4S,.BywM ,Ӿ$uHy.髃^̚`ҳjwӀQ3R;[iFs<:>@*w[$:Ϸ;V}Ʃu"!eY9hD!WZ?wK)S:a/3-Ą}Rog:2mהYK \89'>˹/LMG_StjY!o4HM!A߃h9;ts5T lR1@refy=`@!7In> ,*ڿw޽;HdfLz.C-MϰlS+ @ "+U `5M - b>ɪ5lrĭ+ܞ)$Sp [6"X[(" wY_LR {9JksRә?ퟕhG)>9zssaӰr:n ڶwa9`(H tP@b4T" G߇LZ>~+103 nWYېfk0N.o_ j0zu",뀌qh|9#0uo=+bFcǪ-Nlw,JYpc4F=p4l.{ :s쀪Xse_evos XY] L>lg9SIGZPk* =үI\EmH=CYw«:f9]Th3b]Ik%˽F+`.S;?ǞūƦL3\^O}2A;nLSNBftF$p&;CL_ Ȫy.]b5 Z"t7:ycԡ"z-gշްTґ*}ntߌnIƹ+l~*9}P63eYoպہ(nݹ[T Rvz` #`s=qSql)d ЭQ S)+",0`K~h\4d FUFSEW~ c3+"mVH!)(y?,(,LV>9 /Yy*TO hLQ=K!bTq0-Sob>Dmb1)p/vbJaQd3U'Q庇NiXd/a)3c&Iv[w-\L) i޹?_sNJ;NrtZ->}mYw|k([d+ x˳Oe#\]MF}A :JLM*t,N: pg2map T柰TQ+]wOJȚ' _iq:߶~n&yg!M){*їv ݒTm燑כ=b&U}ͫH Ͻ7ǽjA!Ǜrbhv g0wR-e^Oƀ>p>#nHa=ǔJQA(wE t|fMyT+jSKe#emN DKVCe(Pb1x8 %tia%n]@/>I/$-/}m6YGMAxTƢ U[x-7;џØ]pqJiZ rArlEc7K~U^' F/+`[Æ)5f07(?xƗOnSBhr@/ ҏ%ny ;L ZYRVvYUq'VnY&MDev HonqȓB-ή|1E(ڕv?"uD ~L6p"X>nG曬F`莱N~_Dr?ᾂ+-ao=fdvVI1{gYJ[|W5ء\v3YtO `X1@Yek-;\Ux ;In7ˆiN_+2S:{ '}'Q/x+nO;TC9ز a%]~?fRyʍrpg;=HTt<ڤȖҶby3bREW"8n2g\0Mb^}lj||pd 1NA8M^gYqb冿kDY]mM 6_n^xr~}=bxZ*T=waMW(Ĝ(EYmi}am) khT\"2C5huyg0ɁkFP P r =AutLgF; $Ӈ/AUz:gֱaHAoc G"ocv p=a~q!,:Vd쎶J;cpm3(&0t~&CϒGK]D^GEx=ѧdkDfpzM_p?J+t̼K}߀ֵ<-ܹQ<>8Xxt=}H[W 2gwEh37-x^׫WϬrS? bS44^"+74ղa$z$1 :6M @bR=0i*eu'[y9ڬ@!ē#떭4ЕL:5LTU|4O̦/=_1?h؁_/X3~}c|l{E){ $xkxmVZH℥Ydd`IpPI`35&4}׺C-H(E6:)G6L?L4Zak 8vǘD@fbVkЎ^Uo1Jz8MCu%ƘJw*B D8"dR@9ǘXKa+nx1j %h߭Ws8mwgm `6>`rAI_4sjK*IQowk}+8k Bc(kd15MtEo8q3cJƣQtYL;+"uᾭ`24 YF"yn=`޲Y.wij+nJ~B_.I:a60Na~hIzKz!Z<:;vO,3b%y9Ӂֳ*":m9s̒^5n;.WK̒ iùy`$R0?Ϯ@F:b!}RFHZ¬3!P0Sh+Mj"܎>gFLyVA'fkkRճ`!;@\5g&C{]LVbt#õ؟YZ54 wHCI4?ڥ ݧ]r;0 ^D# ~'ԋãj 48Gu$u iIe,d\A=t@9țO˃L0}K U%ےI{v2u WO#L~$75fW'rQ)q@|6ozB_>7=~;m^Nmp}j5FSb+Kx $eK>ٵsJ>gY>C@-p6#Z`rˬ1͠a{S<ܛ)&FP8^d^X+#HK0BxR"Ԭ{kLBYbq Ix(2 K9A'Do)Bg_jZ% 8n73^G+l9f:Pv\2n_;-"k12Z>߳:q{EW(l،KE -GP?6t8֛7.A6(*2=qL;dn?CKhB&k$sCky}se>{[*R4T ,WLK/ZKG,H\n>~f|" '4hi5ˮ/`-@Ņ#хR2~LF*>B˵z ?[U3 r"+"XeGٺv+jy&/J ¶E%i Ǻm+"չ_Cf`ѐ_pֿHhP^5NtW΂~ x8Q)ZQIKߓ1Q_!hZcà[gmzmY΢/U4`oIp"3N4ջM"Xm^ϴizyb[psiMGϦB6崌Gà=2~dUN宛 ނmqlTBǀո0[m}xTelu3.LQu ;nHA^k֧ZJxwiF UT}pOlWgGe,3}?_?9*EL Er'Ip?hP6Ix:1v* q7߅F[sX%[uEe}75zg@WZor<\#;ƆQ^@0,g\ wf5`׾O:zZ ;.stMD*K %R~ꉴvo =xcv:yDEj16|f:.R ed]j ձ*wޖhw)8)cbwZd'ʲp<#QǦq4@#B>pɸ=h⬢d`_`Lƞ@7鰈%w{]YrDB:}9-,5=ql~)P&[riָC\3&\^ia]JO(ɱʸtsXhvuzUyRjіDŽD/R/a']bMD4·A48?3_$*EQY1\L7\[HP}8:]7<ݳu~|ʗhuy&"ɭ>9-,-iϲR ;k5z 8=f:I+To 5~?AHW|{5äCsy~J.K͉ki_sI" aW'…!^%] ׈N}=vDmWsSKތևOwTjP!0 nT\/8cZ,7,!ʭjx?Iʿ̸)InVؐPmo_yVz [cUSm6x۞ʅrEdYɮMW#QCfc(X,λ8 ?'|bd{.J*]Uь"JdqqB$#ܦvct..GǞnZ(Gٚ1k\zڪpELN ͞!=8KIoEwAũh}өKCPR;=7&0P_a=5UJ>$s~z4t@:'lY4onf/%55>#:>nSн!Jt1{6`),wXNQj: L)%WZkGz €IYTl9ayu-I "g92|ހ P`U9(n8;d8)E]OoF,C{{~RZ' ['?5΍2\*2;vK; jj#ȋK֣ќ;>`n@YEfOɎx*Jiu:ĐbeūiqX[PF\%ܿY8= 07a.Gˊ_*^]n_M?s }i2xUFRC>doMw/OApݠz_7"z,;:nv :cj $Huvo/|)ăzX+x7p"I!yQltt6o+"Ͳ-S'iݻcTVc ?X&X I+Dzu牌ߵ^S$ϣ #L多n~v2!ZQ*,U7n^V@ubN\.և".fUAetPlV'f&~`B=[Ss>Za PWj.[;X? ډA=JI!3`DA=ֻLQ-/[>U3(mW g#4ȶ3L oJwhQDyRzձ츍Յ,8:PkN8,w@H7=)0NdJvjfCњiZ }iة( 6^18;Qd ~}XcbQX6W6vҫ +Tɩt} Vi.vSceI}5G{8Jq#{^9;`ڻ!c$@1TfuBnBsUĂIXzG:RB$bʏyO})lp~*8jǝqWZ昖dSVlM)ր8篂`,zL'g [EVv~A"1~g5V:WG1>uFiBno%@t?Ci7&g  mAH_` c%@9}x2N1 6u샴󴴹Q!ƥB{}RA(x% L(md9k oّS=c}Ԇ-g22eՊ!f$6+*dv,V&o $E%nlpKOAaI]4*ԪsV.\V{pGTMWD|nu1OGQM 0 l9 S4I|lVIkx>]YǥV,}گ6p62;a5 ļGYncM[xp&'V%`#Ur|6̸4,m.16lHXYc;X=ra=)Vnʌ.*޻N@;Hu/ i^| gC4gnrV4hwU;>]ͣ!و$Yc+k!"n*pQsurgUoXV6P2S1nk"ϝ4geXV=[/;5' C'"~=P0.0٠Lj @A+ T>{OzҘۇsEAW PR;4GcWZ$/f0]s^i D/OXrw< ks+E vw>%UUgQDt!jѪA&W`}) Qڴ,aG!aH{G܅}xwsѰ$ !\p>fRzǯQnR`\\o-F{>R >v'3~ o%ٗy=Nr8::"F;ݍ.fږ-Ϟf/_v֦[TI++EN 1*2q)@xp!*~+)Opբ|=^cA37`<Ӹi!F$FJ8GsK3[E`V2$7G ~BiқV0+> 5ߢGvj7|Ɵ%g[&f ֻp]tT W؞<. &☹6_*D}t/&OB /dH@pP`T2D{MrU6%|PwYw#bF(-#RUF67Ԑsh!ς~uf9hv*xt`zv{5 f+:N_P|+lI; \r݂PfI/uw?s_U^Nޯ &7vtm>o w%'\5y!=3K\kx,ߴI) 7T#,S 'EɓqhzS/*i}R1˦(T[b͠GS /il=w0_nR3_m^Tvw`06j#8 A-,}K\lg?tO[>9?ĞF<0-{gxg6^΁nJh0jzʡ!hSAT2wЙ_F¨:Q"zt'e/͜+bꐘzxK0=v:8\LbUGG6 "CvvWT` PKkKr r]x4cY(RolUP 2z6GG+u;U rWV(NJIQL 6F֯^M]Wh:`y׭[>͠=85" $ #-bk#VN/) !|3ڟw@JU$g sQScX`A@p9 w:2=|{iP?B7-T rcqVvI/=g6?vb;NtJG v!}A!QB3c12g=$LTiNkg H{#2Xq8Rų{OerU74`.lb2}b*𻍍T_颧7Ṟ3&RK 9&tfx|.$%?*~ Gku-̔Tu'1R,IE!_b<·lOn|h16FWqͅmt2G<qNxyQqx{mqK$FIv6gQdf ~^b'P9U<;XPfv 94_DTE5V>4-gzB@b[0B7IT=9S :15އ *K6*G`s ϒ'Nes xǐq?o)Ƃس5`|o Cۊ58kaR.G[.APOfyHM帏=mvu?uRԌ[| Ag:k=ձӟ\w;>8 JÁp.yxG%%0J[&HcL04#QM=mס$ŬNX$gNp:{~M*jUf&QԫY@OAf^|xا)1z;YE_m}} b 5w}aJQqyĆ+PLxc[BfT#{O4-z[6m6% zf{ɄvȎYDCX!p1Y*IĚm!+YˆLu WI4=3@qM >kf˽:V#&GW Pȍ*uG̬i6+sA* )p@֠15Q179E󳗂Q ,P֚>SzhZʋTHHdFl/I^EWNg.]PہVb\rY< = 8::Kc_~^A!CÜ=4jCY`R4m)Q7 ۓĉc݅|\:ݩ.JBv-]WTB=/+dz*ٞV%e0,8.)/֔G$q,Umk1Fʧ@[2O"< ^!5t/R$:`Ud2>SY(:zԎ/pMdF_>gUǢ9be|LF $,b[aRU[JqnaFbQ&^mHYG'MBPwS,ZSo4EC&coY"&w\ara&#;իܗq=? jq[}S{A==hJ)#~s/ F_} MXwB^l)gjVNM{sT虛bq-}N{%n:W2kL?`$J>&q.e(i}G$6$[4+XC/̪Q򺋁 [<xi(_D&/KȀV~,qo2h8F*%&~u5C3֗3`n=p0W*5]`qsM%cb&$A!i@m+0ח DM:mV˅G8g| ./' K:i*^̚d-(NHfvRbr5Qȁzs؍)B03ӫߌ&cH(h±:4+2sKɱfwTQΗ 1B2 ;ukEY>)$βB+kRI$ЬaϥI}^!E%B+H8mfu$톃>9XMkN?t-@0HT&JuAtg /jqOfA>+?/mE"r)IZW ogc-x$=6)^6-hHg8ui:#:Uei%CN^YN;4Bl&k[x6.LH.{K }s{u!3^m-մ iDlX-@'@uh 9܊E=0j<$5Tgݏ>à 9]H,|ޒxcaUQPX VZaez}҄2KfMrEs>tml0!!(xD0aݼl=DU).)[u:*H;fHa0F<ۛl;SI*RW/S<6^\kl:ևYڃr =i_zm/RpwSCcov:a0LZwܤ Yeb;/7J& ny$Prvda $B6(_ŅG5WcFƵb`q7 ik㚹:@u V W|D ;y VVb1ďA' MH%]R]j7539zk @܅f^e3@3XAX'f[#2e~z=q]HTv-,n{OB&7Ԣsh X9$Z*@sq3H$ m% TܫG2,juL=~ I2>@0so.b:~GW)⭉zVv J\@|NڹzCYget$ #.괹O4cpFz1}6"*|6c iŎTCfy h='Cnq \ 4cx9i\s >ew|-cx E;zu &1ph5aԎU΀BdH٘wJP/J:YaNU:GfEz(U׷ w+A[S̏w,jn> @z9G햤& |y߶F1 U%G_N;ӞJ1k ~y"߇ɔE,}*Yd "e39W#]OqѤiC`h >Z0u ֿYG^^EV ]v_:835di>1-Qz[R%;9z]y80B9E?ĥ P@$<,t)tx:_li [MտfNLFn^BWfTJ^~VLU:$ 3HT캝9ۅ]T+)I#Crܗ(o: ']47G'uq!6#]/1N6Mipu8rΝ)B߫z\zND)&c m# 1;kgD6ck<0k㛪{!+6v.L~K6@(]t4{MbDWW:O7 fT9=#]N J,لȀK#/Q8;7##_fg腜w.@iZ?:sF̉P$OC={8 ~.V "~'$mG Z؞S4Bx~)-(ӳ*sF7jaP>s{XY5}ztpp6o'ԱAsD?mFɭzq,~.Ct _*Dp~[5 'nWDk}t'TnW$Vߥ`OΠ"~gǡky 6L62w@P=M|Y:߃>}J\sܔ9:-Մ].N%UD8k`;vWqDC3tIP 8$qU'̤sҽJ2̖6d8Fی*.ʅ\5gDQkp jiW0A^R)c6Vǂ yOFa2&`.|\d#`0>h}ޱMH*?&׽ڢ\oSd6+c@5qAR9)wՀaoO؈Hw 1".Thg)tey7#fwѩsב4aq+[O؟bUg 3zƩBF"mG?dT(Qu0ƈ'4H#xgEU?Xc䏇 _oPk99_A4{1beK[#LsNSm]qٿbӍgc4.L#[-KB6\[ D i9 ڱu'$!ZuM{,C#+.j)8?[Ts)(Dy 1{S/s`4\?ߩ!&BAi5`t܏]2,^D9,P%GOg%.LPY Mc3ؚo^)@ ` V)ؿ/Xɸͷ2_sG d{V"N^Qo_K;QYzp` RTs=3)Gn =k~5+6 szebzb :ag[7*{eV Q]KP/~z nrMyۢ=A05hcZtci'(vߨ\z`KQQX&*.M1 Ŷ&r0d;7Y?\W/eY*m\VBz]䐠/ {<X( .5( wvm5 d~s*}/}U ʴvrU +0=9#C66tfPY*Xz.hߓK}sxӋcƎ- #K@k3 W{+ p*^9ԊJK!i1Q629o ,J&u;< r)omy.G6t~:8o4ђTP%J%BږhTch W'kaA"24'C*=8@ -3NSXƁyϬex@Ձ?dm:B17/+d/D-)ZY;)dȅ#MM]鰫҇?*$gmLpΚR,#<{zf Yٮ@L>bdM[f (XS{r6-{\>E9$rnaMX-if&jmr{wHWB‘0e>FZf3w^cm#b/ᴞr/Na6=6Q̱7GA~ aqDtEw^Dh>`3SYٷ)%n8^)9/ beW3GA0%e6LpF, {7\ ܗ,4[EU-ۻf8:uXp$Y[ _@xN[ԋ!2_R/ȹǂ|ʘ* a\'mDc #L Zȍ G }бGY bp]Y:W3SZ&pgB<(3@_ 9k\UF7ҏ[<8]f("%*:],m63( N³i"wDVQjܨL,+(Y ]:9uk#ZX= ?h3ܚ^Em0%!+E2DB (+ }RB3<r<^ tyfp>C8a."/*EZʲ*?|JTg#KcUi#RkTQ]aORYgֆ%:Ib{lH{޵#27=$a"syO0^bw9!SH2 f~)`oCtnd$+0GR?d 3ƺͯYiaoLĝ <S((~*L(0)*}MZs_bHOr X0L˒4a:9{u&b*K [m͙xž ؎|޻G(1v͠욙 7J˥)9?FU:SLFjG 3?*K%5U^9<;OXpyB͏Q%LGeϏX؞x,L4'Dp@O6$h%t$q斛ms"jGH&ټ&X$puIؙ@/0XG>Z>{G0G?.lXLħv+XF O\=#,#w`mH'QrB^"Άr}2}.ݵȄtOn!^{^49(Nq6xC؃&ofXLp8\05Nց}fLr2U֓d߯;̖l>E͡$& ׏dLـez~oP%I5y%"7yuFG E5W/oA|խ $AAvLa! 9v1bb}igtƀ쾠TL 1J`|!r4gmVza;)uuhn*OBMD^awzzD`cףz˅ i$7R*}j3) ReC}3 읁"Noz=OusASQH%̩+h`/Tn诶Z0+NNsX/OYk,Ҭi>jȭcNR\9a" ?'ⓓ64BwsXaԾL}??N33 v5O|x ;$5,CJc H{=LJFj:;8q9KtK_j`{ʈݳ8E؀ة!ٙro"3~tJ9XHl[ j\/rZR|bR2EqRIQ5|.{W((xL%r,(4F@$B6YQ;a@}s:IZPx i(q!ת#Ԍ.ar" Drv/_Hy;̄6zx1tT9c6%]ƂOU8Iu9^sԿIS3e5jy9iI2V+;(XA+wKu_f G7⛴FE9VJ(Z\ ]--K*,`"Š%/h8"I~m Sjؗ%NopsA*q>e0H㡝F@:]UʞOb+6FZ|F-{Iq}isjvH|kqUHB7';m:0A8qP:G0H.|]b6W" @e^e$M TCpE䒄Ͼ rGz2YL\8Ֆ#؋i5ũ8ŴƒC|HB[@1zNK!DgE_eF@d 6zmlb<!=KӅ(_I^\okBDLL *kL`5U!hwM,kK VXJ+5IRYB="ǡ`[ _n3 laB5:)-`h;HIhbEC"xBD xIUA+wC0h3!>t8go|M Pk YV.$2ؖ=0hl"To9հE}wPi΅Lusi#NXN;8Vgk*1A1SJٍU|&4yzx]h¿G7IQc[j4f6'H`5'ȳ+Зz9s̟x~R|` yu=yi);E 17IigQ?WO<l׈Ϝb4H:]Xn+y fDc~c<ԓr%:"m]L9kibxJ vi_0:6Q<Ȍ M1XWܪ^^ G޶X]Tv+W c#RN(Z%zޮieX7œKc+̖hʋ囟* TT\S9N$ϲ49#ں7Hp@C g$,gn/D|5d('_?v5FYJbw JI쇊MI&OBM^Tq?Bq|\uʩ!2`HEmQ<;|n8q"+ԃ\`l`a[؋8tS`Kc)0w`c)wql7c`ɧ*'=U]<|' 7n%:@BE0m=DoΚ=䯱A]Y(u[& )QvP{Y3ܣrв*>9[~6-Qbb[x7|ݙ|j Ff'Tgk:!FƎo'A pyAĦ@-!w offs=ܚj2A<-CEP[5ăZm@v{BwQOTsZZU-ʐY9c+_`)r*YyQ!:N7Bb9'?Gak *D֓YhI3ZXǸuK:]!cΦڹW4OE\ܓ/Q@$l2Sgl8T#v^a &1'x&!$8+$bnܮqu QAS!浹#>;|  "]w7_B]adzrh N`<b̮X RV5ӿm(t䎰M7|?hư:;JbM S鲿,Ncl5&X_tciK,.^Ǔ1HyĶnro/ڼbR 2N;)tv=B˴SH2m0eg9~NMQ;*lX$$I E`)3*{%=<`uC(8p;p8x4I,pc]LJ,/cp{sc ;^ЋzVoRaq"(&ɐ'Up t !ssMC,I{H&&ܙ&WD~,0cwUcQqe@?`g$tnrx ԰cv1tDi2oQh V/>&H@}vjd\`265&k16mTߘYf!$͉R(NuBb~q,b{E-;4 h ӎؽ[t ߻d&FfBxa UX7^ƥ‰Ŝ& `Rdf% zTf-~S,<"_8QDB~Ӣ|PF@6#nm Ѱo)?&+dFP n4+^ ~:-~:j\Qު/F}okyF:a"+#ya1{td/W1wnf2BM]RSÖ,1= Nσ'YW\ +%dD'_N77y6ӏTU` c%ZLy?d!J1\Fe+J[< ;0w\ -l]cv52Qy.}j]˫l4`W 6H6TWqrϹlj7'axA]IX2OɎ ر9KS/5s͓p_OdӄaQl|鱒jbqw,?7]/ZѬ`S ̐NRtKKQx3ӌL (X ^d/{?x݅Gj牳xR9ݛlv/N8pd۾h&8X#!t pŖGNƑ 0S4H#is1IF9?yDݘ?HLblH {7_뚈>4 9)ǝ)))݃+cnJOʙ藸\aXӷ;Kte1*6O: ,51[\@Mf4p8&}lT19%Db*BĹ@iׂMznV w6ATXt%w y >hYຮf"vDC)EBʮ- %]|jsvmNk^6gpiŸ D>1.-=<=h\tQ+OLb*}Hbjˣ0^d`? Z ;ң詇PoRV/9wN9x$nWx Wi:U7>h5ܬ׫ (zAC3?j^/|8NhҜfYy~UC-n 3)fM%j0x#U˶MGn.20ntM*Fs LI]PjЀH-qAFxHsB7)Ф,R z6q?Ro㼫ӰyOb9tfIԹOV 3ÍnpQS^uZ xYll{W Ŗ@HFJZ bLBhWW :gbS 64;-E_gAR($2\hH,9A#ٴIt.ofZMt,Q6cE #f/Jr%XƋY.ϖ, 9eSx W2PJeٽ~ $J}NĆpˎB 4$ѹgnq+6:0k%4bLS v[f\;hѥ 1 J#BPUZ #GuyMb(#k?2%VAJI_|bq纹u<r)[O3MHΆf:b.pEvvO;藿x/UȝC"+bo:c~^7U^E$|PZ~Q°RZYS.̠I6U9cX2:T?{KD4[:׊-LFCӻ9{{9Z q vʥxt+ϞC8Հ2 O$ Rc6bi ogE֮|0*8_oKM%VcHuF4uX6}m嘝s2DlAA}>EZ8G]o/؄hSFP [g!Xk9߅cKb921+<6W׊tnLn0tY6OM3MesB$'oez[+A/ol^HM6,FkQ#MLd:vc"#FJ[о.PIB#yϞT⻫qlw Sk=;d^ 6!_k>g;N8!.^pi)H > 1 I=v9z7^Ӓ?^fs5MqMsMS:!xXD ~5sqID0 m Jļ1[_k+.-ٟ8'A7[,(s w-7Fۋa= K1~ҵ_+6G\.Q;\~_-TT9?Qz M\1D8Yਰ?CkWFQõ;-oVt)y5R|]hTܻU*L?Rig˛1)8V]>y rrطs 4QXpW^x',w '5t|IͥE Pȯ''Av"7[n;qurN5NVd>WHlx_zk”}*U)JmG0G~Tξ`EA 8M,5.G"NDP;rrN!X:`a>qk;tKk $dkTSK Լlo7i{a Zs$"ǃ+xo-pI P`OMNT<\;е s׾` OdyKkUhړg=EEB$1ٰ,{Gxx$ޥ%dQBkbt4P3w(ɞSW\#Ydy̸ąK{ tv0' 'aҼW۪j5Y/[{Bd!~]5goj"^9TN{FY1L?eȡi/G|kEV蓕&ލ'XE3DֹlyxBqXZ|GĂDgbb'3Qwxط({'⟰f %r/p,l4C->!>a`즴W9_o.2դL * uOG ,GYs]5;~:O2 $ZQD Ŧz<+'u쫿#{;^r1&[9g!ʱ-oݿ%~Y74Tq'p Y|3ѯK0^% R~gO{Js" C"V$G*=E }zUi b޿gZf"+?Hw~ѵi_'iBp+fw̑E r}b_B_\|޹^npmi<+D @=ٝ6zmܖ~/KL ġNR-*vrpS$ .C@c̗,`:"METL Y*ߪh2h48tƺl\4 u[SӶs{umY#BrP]D= ?3yTgCivpjK='٦\BCdr226k(Y!\e@v@uymWя{ۿp|R@Д12YۍOV쐮џ pVݳr@"2UhKk yj_lޠ׎r\ȕ2xw KyЪzVQ֒`ROwIԓE$y UUFrƑ#F#R`+1=%2\DJCLQ$&E]Qt( ΞBt [oьfL vJF*9Sq-a0kVLjj}wb~ I`ݻM>L9z̻38~,?.l,1injn[.@ְG0.'+.S: \T7}pAW@daҹ*JB*dnHׁaSUzgk8$m2(B"ccT*MGg& _i>ꍽK{a!~#t;~ꨋOCƭu' `!cj&Og.wQgv^rFD95Z/:&<}p4i>01IB_?;3~V5-`x9Op>^ZPS5n2HȽ7eb)GtNSĚ;@B)K7'3 C1xLH}PJy㙳 %A[Ƒ`hNFHFW&i \Fdfʔ9T р@"MxXn3LfhjoRDa`; cZRuOT]76L޶~1֓ʑX7+. OGh"Sk1O$ H6n5UW^eѾuݕ /  Hht°96ގD2ʣĝl;ng! = Uw.rЋJgHҵ0]i(k@?O& ^:XBPk}ǬȬlO[/-O]"d@i8S4"&c9]vFR;zA\u'G pmc/ېtЙ[i-^ĸLQt+"g|W^Mu_&$Cy] &k~CK|8L.J^'zi,8ojIP:'N{o"6/2SgAl?&O*93? v5hD^FNעBdL`z gƒxI`|/(-VaiS=C)fVt&A@yqMviof]?n+,e,clDq + kVd L,D졬YJծU5R~᳟ FINkH8L&jEjt9xߗm1.6w;SxГ2q$ sLS;!oYɶ^$Jĭ 'yZZc`-Ԩf,_lGow/4rRJKR{PR||?]>X=4@㖥V-jn);$=zaT2c*#dfřTi69' J" OĬV0} {Eg;+Xj?Ƴ-{F>SªRϋ<=6tkFaQ+ \ =ſHNTr\:J oHiy"G=~FY2r!+]!i@Սq*R3(Wlm i5Bhi|E i$V>vҐ7uUf}޹ZO+_mozցN T [v~] BI8Zx"(KWM#lsvnrSUFZ[ ;Ba+%”MN@j\p@_ ~{i˩leFq/^ؾ_zV* ,h]kNtIm Q Yn5Lj6'TSU7 bMDf&>Gb;k[e ؊pIhL+)si/b&GA33(ny?yLFʍDB`:b#g"ʒO7 x`Ǯp IE)Wڃ |aKr&YqF1]sS:/evD&xn9vۙ+p_Y4jp!#(_tWx7R7T> =}H]q\ f} pɡ=?ȉS`G,ύ¡@KԀ_ZR8;[\VQQOwA^ C zѕ%9yiKzzHoWw!%h@H$\g,taGt AZKJ>NttR嵎ߊOP  ^,a߆؛>QmCw.'`=͕ңЉ97P1M_^Z A&9ifC sڬ$n5kN$N4 1b"McD+ ƴgrZƃl& m}fZvz,qD](vPLwl":9#K&nk,YȦ )oΙ!7ťׂk#qaS+z3wDof>V]L U2rB-AG4?w118!YIv/'M "z"+wg9+U]^D Sl?oFuURSdSLPrGqr<3zKS,5.xZ#QCbJq A6lΚDGp 2|%.{$~ 8?{7h!(7"g71%߉xZ8p rybIL\/jxh!# ¢(-%1"Tiϴ4 (s,&/1o8EeEvfR!>ץy'_!  =F3 0 &z>㙧z޾] !/Aϵ!7=aK'CtY/Ryf0U  >#8U)Wv;O l}aWKCfoC"$NG,_Nե>š6`zAG?Gn[8s$]G@!/jïQmă5|~bv ÁJKrPXG>_vt݆W]^C/Dz b.L9S݈AwT>&jUNJiפZx.:Eŧ`Y C%);u}z#~~/Hh|z6E!ӲJt@S:~kvqz 7)I ZQL29i`k}v3f 嫦۫]y3gH,Q S3.+91d e^zFWB0,~-^Hy- ,UbB6m&T\$^ſ_Dz 7YFz['T[ 6h˾*$3: zm=kVVfZL)>C!zԐ%-p2'& lKZ"Y7Jwn`w-#-a,v8~rH=TaʇbK?˟-rk5?3p.H;EA3m SŁ]6~D79s#OoM۰1eM$U_KT:X>2%R U;vK*Y8F/11;8qfr;I8r .:9&䖩I޷jZݗ=fAuVfH'cv?\Nh#> knJXJDcSz^fv cCa%$ E|| n-D([$M^aۻl55=$ C] Ċ}0VɠW`s<:cQ8 ~z }ܤ"Kk45;v„9 6л ~vՎkCqxG{e΄-7=)ҙ jU^dMk:>`$-z(&0P[f]S5 fi56qտZmg|Yڒ_;Ls: >QD8Ц G6_Y'>?J&u^HH 6OkKPi&vl nTGzP'd& o `X, qSp []Ԩ㝤d\]S^q;3`] r7E tуN{]h.m ]A%lc= JCZZȯ݆6k&iGR@nv8WEC8]#7Njwrj;k5N8_hEƧڌΕP- |31z%va*RbbGۤ6G䝂b|D^Ȟ }B5+64i=pD3t7b.=JW[0gYߝ>ϠLlBVKϺvN i H 8#l; *UQil< E+[Ҷ7Bc (WaA%k/)^26t eIHot|aeDJ6K$DBc$en6Z8]% %Iw]iS̅ZjPa;`CmmYKy GPl`Sُ`@P&kp>lcM~TeSFDSxIiwcc; >~4#ZڿC?R}Zѓ<f жuϕNu>d sY](a35\D,;QQGbz;>O&el n$Ee&__Jv.a4 S=@)@ V,A^Vgצ]=Biw;38׀%aEИbb0ky1$Kx#'${XY?ӝoZRm)BX8!v ?FeD&Jy?.껈T~X (gߓ| 2m1YR,lRH(lBk8

b_CmPɂ$E4~:4z 7) %twi,찒rLHK-N$y=rx 9ajfV~ܢ$_uC Onj^ 5mEG<`ԜiM⠪gVŵt!peq`hLElZ-=t)Nq-̈w~B=ANth#X>}Ní?&=D6r2F6(]iAui ϺA1LzsֈL8G/P:,7l`I+\Ԥ}vʎ[I:+xB\txkQ?gIӕvB]-L6[ uYePXZč]'‘iv 皬W`bȯAHGI!rQh.O=YGJq`"B KOM6T7dxT.ju{e0Ya֌j}Raӈ Hx|TV0ԋ8H(ƹ{ 3 l}׏rfj EaT=J\ikU_^/`o7 "Pll@12~X.0vj\ߴZ南ظ[%̳ @K"ݯi Rr'U~/',_ zm5q(!sc]Ik:N>½̀d#Ǜ7|)08Gd9.s5T6+|p5l&?B aL@|;Z(K17^ukgPhϛE 9YEA "$g8wGmBr؇qLG)ufY*5^V$1/ A) =.Cr>FfqP8KK1BF n/B׷ )ȹ?]9q[uU(cC)閅DHs.JO5-CC+$w zAO@^(m4fI5xvm\ /5yI.ohI_Q.Ch"(s̎;A8\$ uG6"j:X9}lG'WhZն$ cÎL]Ȱ0^cjخt˫d,kE~Qkf f(޸ZwK0WC JR30I_=~P m?R $>d w-H" ݺ=W:Py]\nl;\z&74.9סjeT7' a }OF{]Ŧ*H$cwy7CZZއ;ڱ'V1TV}7/.M,dxp%Ua߻k 0cSih"./p=Mb]֘SqWu5XkD[|.lv]w#rAaF(E' yP(䍶am|!r8kꗅ;n4æxŻ4nsrzMZh[Py2jM{P%sšte4`w6g|i4;kҧ}wLrIS"f`uNRtlXIaO Fy-5Q-ŝNgJj7A¬!~K;/VEo'$,ꨝF bSX|VQh0v7h4f#"3(H hIkBA0O.[JxNLTGS<*ؽ[zaMKIO*;n48=Ֆ,VAPE nn9ˬ6##kd捕F! m&+Kb&U\^nlSJ-ٺɚ/l@CFt D9/|t#4h8z9SKfJ*^Lb;gΧI8A/f Luvb5Wh7}&x>߫O.^w 6հx6x>Miz l?ʤmuf WIqFrf친3梆!#"iΟ5~S$;gQJQ`Sv^_T%̌hbVoîd)#EZYDX!TS>kۧlvJ\Pt]-YlԴF+$Y@ bYn}t?Q(J;ux_kw=uPQ殏@jdJ!y]4A; PMy",z,ւ'+ύx7[1ަPPAI’;/wx!1OG^)=,0vUZ,B0= Guʂh%אp&_f c}]t-A%B9i${&e7$/~)$R^o},^]f> ,pLt{OBMd:ad{@TI8G tcpA{-<1.iXɭiSNtj6SQ{l'9qT!ͦqFjCF-)]Ci`j7|f̳(h/"'4-P G!5).4ӱ\ bE&K53ԉN)XP7 ~Ey 8K0+=yXQGFMuH^- 1^C"cƑ3$ħQU!lzc1$@ ʪٟ]E-JBf\-F| +`ޒY^w)8Q9634'cRxi^ Q7"6ޓ+G}2y6ЎChHh8F\R*eؑcRpnFx Yd{>>#zF{\^V px}\'9x&4ؾno[tc2xadc.^@Av=.VKHju52Zy;8BObE \zmǵNǫG|"WU>{(dJ)΄ 8PmI\Ku@QqXG+~d B;YI r&#PF50C { ./mc])+BCa& :H6^7Ix J&%J!OmE2%m*pʔ(ͥb`mm6#~ 1Nkƒ[݁ˤWE9jHvMh \CRcR*e<}\}ţՖLeQ9AnmiL) j%P5$Sq bsDjTP//SSpBۘnSL,mX W|N[OFvׁ& .Z_w Nhgq g^w[h2yU^û_-&ë{(ΏY,Q^8' ˋ :wX[O 7viC~9jX [YF-,(5T[ky­Eld-a\N%+ w&A%(YJ].8ʉbe8wu8V$n/oAn|_A U%-Y鸸bӯp]wJd69>6PVW,8!1bpcuoT3GvҖypr6)3.EBs2}+e^t}^#gOIW92 \UMnF[ ˗1fũioBGJW23$*|99u+ #^` B[o?ބW⇧EcFe2X3V Ö#SnD=z}; ͝ԅI?-+7R`y#i.$q%%eji׽lIڍ4EMRc% jSo9?2sao9o'`ix4SڣJDr:HToG(D4qB`6_NTEȄ8WxSlÙ("{-:B|wU2<G)]<`Z'%PjyI̡&|x=NpHZa#*yuc`VQ~;ȣHEQFJg\aҫbyhhɿ ~ `XgQxST))ztUBabPy,W)QM={I*Es`z}z\M7l5FX_JG2TS(=|G M>\Kf6_'IXhZQC/9t.W-S gLtEa-2Զ`̈+Hȭ9g|GVgo B:1Ռ޽NbWT"W"13q`3އ,eSW& OEJ^TnC/}L7U)Dj̢rx[Aw=^ >d@OKN><3s|{+lP4;T#ZyNɢm*e\6wk?R g5)ib`"`=KfkaՉ=5H)|Bz'{n'PTFTQJv8,07;m06b|^G/"83e0oęl/vlV)/"0IO4w9`/ߧu^[ m~ Ej7uT.\Àb˃6M(xnEK@'߽q G<|,qj3'z5қձ;1q^ӐܜpO7S\?Z;0 @ ]S}3ѲވP .s,*]VY NO )1Kg(|6D"V(#Qɺ:ZGemf~]@#c^ك5-W.>cf20KoO?f&XdvukLF^x_gֹX޵(ts۔P~9-K$HS@'Uhs闐N_{hOJ'+f&G@9* (afvH X&)0l!lRZޜeT{[/B: . %X6 L0boMŒ<:4Y,yRR rϯ,jz9 /wVxOq1Lx)5 vi莙aab#{r6tC?=vKԷ x֟v3 ʚ1YGhࡲxk 34b?s pug=(z JV8܎147',Ȫ5]TJ_!R-mc>tpZoJۓ`'ǛK<= [0w0IF+Q-P/1r\)O4x(W(C"YRY@lN rا^^=꘱yf-|+\Nw$5ې(gl9ޒh~Y?^4k-k<6H럣Xi  !vUɁfy&XD_*@~ /`/0NjCw[AdCc\Z/Zb_gg6b=rhN,:qgotWn!eag{% L=DZp03q>mr[qPYgM|5+>0C"ߔ[ܹ%*Us`ۥ4q$ ,,u4#VD@+12:ۈX |W=_ #PYqr[ی M0Ղ{h6cўr} 2oo0hEcA qyng*RdȚgpѝe85RyFb\6+ev-!ӰŲѝ%6Oߓlȍɖ#kH娱в-)&ۺ͛"!ҐN. g8Կ17"O ⯒@۷œȿDn̙˭8;D3M{}W5#eF^*) W1w-=j), lV/AaB/QXjv濦;0#X">>;Pt3;`lP:OMLAAw3GYp+pQ:wD)";Xl⇓pq4J}'6 kwu3Mh}K!U>چr.'+aVQdM߹as<#|=h|PR &Ow=DrlcrNgw{/ SޫXlj5KR9t܄_Iq2ta|k.M)7d}pyii bs{n1?l}~TWsZ̰tZGC^HYE@;6g9".ˌ6֨1TUkCq#(JHA'>a&]'z)ىZ8%-O٪ezsuט8R,ܮ  F,khߏA0`Y|*64_ǰj,-B ʝ3eE‘I\Ia*AHwuz%Pm5w^,]&ૼ Ԅ*r<^;L=" *CKgb}N -tn?-0~\K٨g|nN;Ɨ959eorz3@&yg0s!RU]oʵ.[؅xрHFНzf 6R ˱b52.̻Xǔ_ղ:psWUЯ5FFƘ]}vV-V&#Ajxr޷[%U=LYIΘ"Yj9ڠևNkVb|_#zecE_-JwLv La4|xnO V HYRd }1S/FߍcvaDFTAn NUgjCOI`T5 1%R86vO{wFM@u,=ϋ(I/Ti=s2¿oЗ7qyQ ev悧XYdg\#䂂rT1%HᯬP@ُ!B%I ȶ_>b1S tO ٬qƫLXkH*䉩?Ġa<6\uN2:\E@Jp-?iX66%voɩ ╙)"fJ#DcD\y)]+# Xrbw@CȧTUREe^drMX w@~[!VD}͛_x䅀aNHpz46`[&`1JĂ=mDJ%Ǒzoq-W LTomNdK_h@|EAH="?:g}_  Ⱥ1ZoK&Ih(`!G;HyV/ 12F:Yevإ@7zis%yh~NVD~BE[umB1xz 2`DOBotRnɥ_I.rGΟBĜ] DwU$U ^DJ+/.%LZm9Tg Hh!;т)-w& =Cqfji(1Jxi$:"'H cΖDܹd P0 n#Ux~USˮ 6iZ+ˬt\L`':O=!"\e CFmQح8r}6~zpkO,s!M.u0*7q{Ԝb y~;-tw?JjpST#^Ȼx% (󗧊峷Uf/QDXf͐gq[ )Gm]bCK-%8)(+o_߃_Z,z"X2J=vjNJ^i  T^wKL[}آl>2=N<|nLg#Jah ?Wl {@>1JtAW)CU汨fK@$?0ٸH!'H 󖖬֖Q?&V`r3RFIsRRPQT4Y8 Fɑn8)$ Pɦ51N f6P };xy>|zOV1@׵չF^4}.MFwưI{៥' i6b޺̫/nDL\؇2,w4gA) aF;f"_MZ+Q!lX /,*`OG1E{xS M3?Q $2sFk&s,! jkNdl`[&1P4l&},cy82 !fDYT-Ro3t$.!%vG2,Ԡ楻g:? RwXby:-J}Ĺw@Ex~B~2Y4?JK;/mL' LHS漉!1oa bX5g|4s+scƣp~4 wA $dm@h˻i}+A*F;K[U2@ $65[AgUI] z )Ms' kB MWNc%2(,[8)(ި瑊ֳzpo^Kz]s 1z` d4[tU*}M*nzϏ׊1M삌F0UO(ͺбԪ*,Bb~@~6zb%JvZ'iv"L bl+^(~ r~6R H63"$++JSWD@NUl_Qj7z.nVBH V>'dRpv)f(Ŋ#|^L` iDY\sBb܌"?;ГŌk$L%Sa1<{Ov dw2/9]p,EꙩJ38EeS'Q rTg) ] W9t[M2$o`"ș)vTZs2:X F.>h-I"dlJ]E #Ў;rVOD-O1;\]žM&Zd7PfIaDJᯧ:muӉODtULi`kkQ~ _3%;A:)'ǎvk{ ΰWQo/0r Lk0I.f5y@V Le:7xY̩a'a[ Kݡ9ݛUԇRZ-)9bƉ1)OZ ##f=Pē*,Aj`[ha (#I j?ܯ0r0{ 1*?9EJ7f4Q2і0,S:yd4ᤥzmK<ɜ۝RoTWPD#AIXOF:Ne+\ƻd͜.8M:[Ȇ5z7QWK vUL[QLNTRln+4[r57D:bə>.Q+NRvb:9eN#VkF(-5kN;~u⸇vJ*ttPw]qQ-iUv2J8en_eQAsf~3LQӛ8YS '"fBۿ.Î$t|u!vV2G5]BX@zg_%8|:^.[;`PhT5bIz)Rh'a~~'uh̤I4-\:b-21'UM#^5:FcNʬx_-h-WU ~[R M!É`(zJV1f*垵ưx( VaB@KG-kʔQR̫o|!Fڋ>)Dak7_̷r\̱ E*b)\tԓvZ<l;alG2ځUds zNgh-T|?gyzTDFH -(8=վ`DeԼt'oBSLTEue*v[凧if%s gY wVs&6$u<e'(QL܏Ycӆ[~'0)M(9ASNk t/TwIj7D ̱nv#w1Y2{4P+E*KZ ЩC&^L}lG4b(vt0Xxc2_t 4"ݨUl GɸĚѴ5; οcv)!y}!vU@9e|qP ̩>|M.hR)c%MSd</X*|vX|kaʫҊ) _QCb6-ٶD$J8 w`fNK&H&..&/( CN {6uiߺ]b<^Ƽ6ٝpo90%Uy=Z{tϔYek+Lon^wN v|TRD"I}m đ-ks/bg5Ձ-+f AܫHS0Y~ 0lMEvMNI0 -[$s dz/t \3nٴkwe%5YKJ2ȌUf6 ʌwZrHu}^u\EӯЄhOPkoֽ\M "# rӘyY/6NA8 ztYEMg3LL!h~#UwU }|3旓qvψg&~po :>ΐ0:OE';<Xk>N8ތQ )H ~4.G܇qbtkMAHa~н;5`a˟B'f{hE*Ghy =tbڜciQd`/="FYݬJ//O+֙sвз,MNJvކ,%7<mxKzoS;'Am`U_E Ye#߃}T:a8E S mMV (IJ%hF71\f)T#(tW6W̺:#2SO ^oNq9Tր,o߹r'g,wXI֏/WH?={ӣQNч_[u<̖)HAubAr5]Y $|v@7()gl0UL=MR{i.kabY^C*eGGQ/#KBaVSIA3<1+d+G/VRhV"K$RW9׸ƋLS.9̵b=B ~a+JpÈ©طNX[> ?-bH)C6 bW[ ?q8_J<ݬO_rl<\VVF|z I$rsC Y2.| S> d̡N IH.LsT޵֐Һ K4JF?sh=/2 % ,P/'LEr߇M2"dS<Nl,/j^02]7$, + uV:B0qp%n=^* `J%b$׶Mu">\F(Akߐhګ4܂+oRω?ezܣV,(BMڜN!Fbđ˰>IWXѺPڟk Y`PH :ɝ42D@&r:esSfiXT"g!ƃ;p)ǿy!iŎcyv|8݈^JIpۡZb/b;\đ)X[jݭ ᓡ݇e'iiMĈI<'}{7q| *'T25M O=ACR<.E8u0ER܉{Æ *]cj0+]Og-p߈7TdQϣb{֐ҩh]-Q A:\4THfY 7Z(&.Ud<:X04;O3 @S"%ˣ8-D:bЦ.HDid{Nk9j58PZXBbk'##%&a ZT"1pNXMseb>e#0AO^kZ f;43iXg TFu눸lFDiqķ9M>5{~ZMC|M,Af:[{=&N >kjщ)|Ø TY緳O"z$U$>l]~9\ >4^}in*0wmbG}/b DQz}+p]bj1-#PokG,܈& ?*_ N^>LdMXqTТ';z&kN}? "EsD ҔEeH&">6;(0:Е(kpRSǮn|H1IU] 0,+Fwu40oG*쌥E$'zہQp 6 YRm3IWO߶BKyzq DbQ+$Ŧk)t L&c;shoY[.ɐ9^jb=DMbnf@)12wT{[خӵ Y#=v绑_<ϧ}Dz9K` ]kAq͵e;]y7Ux6[y_&?]/b4W2+dO&iDTt[GMQ^_!v(,u/ )"hk#Y<= hp^抣 9Vϒ,ʠLu5[rV6&qPby _O-Z?oROr3@vNTxr|竗N0߀Ye>${jY\QeOdh$ e16C;Řڬ$[<_#aϤ?^wNBxv\Vɣ#g L O ȤޞjbV{}QI0<"/v$W=y:@Wlb5L~*B<@ - d>*{7}i~`cGG|ׅe/,(Vc7Ś saڪq}(Q)?].&ψC;1۟ 8ƭCǡ5L(Ⱥ!T iH*04'As\ Y8pnp [4<>v>#{1B0zB.7u[v8TR6=Le;b!z/9ksx~8X:r\*ۣT/2la. UPZo%^ɨt^.(1${oixP~-n_"ؐdȺ,VAt g]ffH-ҊqeVǷv]n~CHґjŐ(x;*j-:O9J,5L_bVHIF\cjOv[jNsH չP;:ûɽnүF=NS/  Hc[[M=gr y푧9k9zܩ, 3Kd K{D [).J>oA >=U IYlz^y/iGLB4o_Fv4BZn+l9Gǹw.TG{.){a<6 +yÖ=WJդ>]^ s>Bu Z8ޖer$ޭ\ޤ1"<P126lMY uv/{|D2q911mԚ?*ZEvlCP667 ly/Cw&GQHid em0}/94?` ̐V]$ |efO52;7axR@6 XDD()يz),)0ÅIkH-ϫf.<.DHڣ̋#o]a!7O+ 5q߹(䤢xo^~_e)HdV1&Et^z9҄`fV/aC{u*d.Haj-:5ZsuսfR(<<XN"oCٸ0X>Co`2 (;Qu=nSSFER?\< nzxTW` 6*6p?ouqӎ^ fע#voڷk!lS6[炑Q=S?^Krߢ,9Tr*|j: k|}Qcc;NSoviqQXߨoe@ahu$+86(z0QVzrh󋿷%$8XW߿S^uB [X8YtУ@ s.6I3Ο0v)3;ڄ R8JTMn9w{! 8N&p\B *]GK? Orрh#"qaR'f#xrN)ͽͺa]|âd[\RI/_;ޠڝ $U#0gij,ZBŽK6Cy6c378ڕ}fOOL-V-iPu)׫vCP4*O =o_i\8rRX% !BLH_a,jogHriºLy/_k*V}%KY+d ukdwjnЕ'x|ftЉf_H7[/;Kz/P+ma+] );cR1q$y-6ow.%>SDYXgΆ#Rv6.mGiI-N|[jvؿ3nY#+R<7? TgKe|sgв*†?'{͗Ѯ.HpA(.0E׿q-DԚ] v§;Xl2 3l 7`Lk=K$Cfv -W#,,'Ħı5|ɬ`(]l@?y8+w'FX6q$P~̆tk{4 #{E7׭ ;͋Z!n4P#TնTܜ:-!FC҅xxkL^l=T3K;r ]YoW9% Gg(-1kOSga>N.R2lHw~2xIiAߓP<^7TxGq2X_ E0^G'QP.bO۷S.X}_*g3fo ޗL%.>J1Xda='5cn_F~!{/˥/~Sb\ץRY;YX[FQyfw|tXQWt*`ql[j)Ҡ.mB#DN>.ǞF6 3x*0r!zR%0sn\z~~-B_>55h!2NTŕ=(bgF % KA%<~t %e,GOnnp(܏ SwwG.REEFh嶻)trdDTzpP+1rqeuO&HE'w &|}zt%;fmʒd G]rX>igb\ٱ8fb.8t%"քM.BvqDžEW>̟rVw-Qi=MN^gaXeʎDEEGA4V3Ic=1֧IJ2v| _ S?3EnF}s_?y C!;$U"BU3>l[+=y}OI0FŽDkXU9a2Jrju=⦌SNoP/˦ +u y"oYo٧jOx7GpNS)}+R0i؎0mJ;H: |>x2t&4#6Grro;SQGA?$6gzYLc)ÂQN@+$UJ kʾk]o%^MSedȿ]K_h$<.{߇c}6H,>(o'@b)")tdh+Ϸ*s2~X{azb厖SumKPd^"%R2 S4w1'')czς4'3~$j?j.Znb8#ˁqA=mC~%Ӏ\W&:槮v/k iE / C0(/]zA'5&O50n=.xr d:C1Kb<=RyglQMm,r 5@Q(dSH9o`.(Mx2ScltD f+{(2XW%rݒ/qXV>a0c^ W0aeL4.3xon~ fXkˎvT8<@n(Ŋ 7KET/m/nzzٟDNFk,S4g̫yA`_9$mѬDOkˏrˊ}MDtHDi&Wv|#F#Y Ƣ[ޣrkɑNmmHz.: &\)-؜^P F.?(_0b3qe t ؈t*ֽg"J$d\ ؎EcOvHa|4QZ l^6w3砎Ӕ c$LNU y޻\{D!;yF=mn%ֻeldDul:'y]_WP]R^f|xos0U )+=ͫr2SnƤ<7-UZƹXV&cWMC TT,;fv< MֆGX߼`ǒa!W],Ákc.O≅zPE eO`W]yQr6+y/rݷgShyK*~2Һd$z9EZ݁M#?Q8>W_odYÖ}P >7-ov2ZyYo #ve8w*.{? 5g/̆VkM|I57^hHɍ|Y%E]ZҺ7 jfs&]x^sګ  x?4-a\4UWu),F3/:XbGbI"/D?[$ą0|p:aRHWb*}%׊yc=j|itf\Z1{V0;X~sG`Q?!})կf Jݼ6J wİ0zP]4)8ύGI%.4Ԁϧ\F8'78Js>dFgWBw,ڑlpJOsߧ5@JE=7|9UԲK[X^kK%w? •Q#֖6yJ&lCT,j9Z5؁ԳID  }(6s4`(OAD3[ =[{e ^ N%K\J +!k<)b~o܏r%gӸSOD! 9-VۂGq=d)$ 2z'֧.]VUA UylLM P{)IC5fq >܉RNx X2[v&! 󉅟XxAłZYж&SS04ԙl^oW.&"$KTG8Az*Ybb.d`5)aY ʌpH=,Q=Z-l F?[@+%/.MNj܂ HU==9[G*,{%,"wy C O%+X3_oX7t3tY}a4 _cpC.χ"uhSZ4哼׆dc2?W406ɪoHn-b\#]1mo GBQ[?2O[^lDLdeۈÆ@H{y'w𯂑*1x<Q]،L6$w|JO;,8EL>Qr$k9\G(픙E-֛VХe+eJ{J֊H-o!Lf>N.Ƚ3o>x;edG\Sé%ҫEslt 6r# B fkiaˬ/v3M{IQȶX8•G6[%$V>{yOV,1:wWu3=XA:s ;z~-^| vGBƘxfX-}>#׭u_{h\xZk*ۣG 5.>Z"_Oy Xޟnz^?J=9zԭ.sb{X.hK#AY-;od1Wˆ%gOzWOTʸ? l^SS}_ &Phv~t8DgpS.+mҋ!2˥k> =ޖ;TܠF$O3BKvuNo !<+^<Ӷsq|F7jRM+W Dn@ ]\g]98JyӂmS B$FT3~NfL2nlIGk8`,,>]>>B@6P: uTCۊFMX=X$>X겦r@0p<,]yY0xN~|ul0I~$T:օ)ű"Lۊ-F﷥ԋ,L0k΅)ǂ/|cOБ]>YWXU0z,4b{GLdդbyB p$؟r5D髃ʂ.?aƪG{A֍z͍K)bbufpjhJDF5R]z:lm.P'Cn z7xk [{lڮXfTLp6$YT!QOu@*7~N#}*`KoN<jk8F||$*@ۓ>Br\pr gNbqd6߾r.ǝfE&!֡CH$Rs3wp. 7yȯV=@"i &=N^e(F^MM'vyg |$REt]7Q;Ӽvh]C46f)UWGyQGLLD>,f棜yI55*bs7?Nnn!="JC(sH; 'ۖb^ƼBHͮ#؁c 7In9?`]6Z̝qE[kJ=Vn !Sq9!nIVhmO#QܲR-K\eaFϺl > wNdAil $H s=62wXb}[YxS?keD2ظH*l;CcGHQgˏ͆SCEuq*))FJE=Q7ɕ6 脍Vp{~(DR񭖔:$Pp{V1r?ӪlA Whۦ]$~.Hozrwty}f@nmVjD:~ɋ;sT,k] rѨ3P/W0u:V[l}eWOIt+jb*y(˱y$7U5#As]u|}yWp5|▻ vn3 M7\(?[9EvۦUPYO~ht]0'I7š#= %,L1[mWdwY0O/1"렜=t@Ђ`H]\8MϚd^*-/[w֎7wWyt %߸ZB0Uu=m7) $;  &WDCBXI~+:%m髅C*%RV9}&QlF Y*u6j v1eQ8 D"%o8($&CO4@Jv*x5M8"Z}t1sdu |m^lDtkOQ#A(hq"Hm2@ U|_Ҝ~Mc'=O~ pA$M%x[šCT9GQ'`21\Q*!3f9}E6M2x#wiONuJ/zo,|z)u)ZbT{_|mKTKR.ήojX۽ˊ!~"l݊ !~QŤR?m!Ä~H.Sb[+0/$7skU@Q"^9@ cFo~ mBl!bbb隗<@[dz̃OZ Reum6:ZJ1a޿ ֺ 6T& )NiX,[),{'] N)  K_R3jKrQu_}V*FtR4P4Z{-W:oڬja5U?ORZbFCs~  ]gS0GJEtNknY0X߸a˰MڃJbX`>)@sgJϯL͌ɤ#V ɁHʍMoMU;}OK{c:'J}~UmѸUc$ Vmn[_X&9ǝS鞨*u`9\E:sz\6$ëE 2`=ą*8V oM.K1bhAb|9\m}_N6'خɒզgZh][kVSeIĚ x !~ڎ QDl* gWڭeY!0|~ȶ Y1\nyk6H-V 8s`f,AnjT @-j֜NFN/ЋQ 11fDfhj4$ڦX4戗LBn3 ;Ů@Cp^tW}y8uVw<*e;2z?uk.0x> c*SFWVS:s5:7&hGuyUaRW7G^PV>$C;PZ75 j[˚E"s\` zCo\Pms}zk~(X167[!nPm`nu^^w70FP*Lq[{~:];&!)-͡\ O@>Eju\MН6BWKɣ!ǢY|^Qjk߹uF=i~h)6D9DHQlcnB=!JAר]aYھ.ICsSOҗq9Q=;R2TbcDׯQA yijsTlPXaڛ8>)mK3gCTϴ|\o/7eJaⅨ}doi`݋yZd*aoчl7 Zf00sMVU̯&n'r1ΊqP&xU䤠9zg6ᔉn\.ѲocEn%7{g}01jp)( N6l ;w\PVU]9T ФVoI`H3&q؝[J1=j:Vr8O@ksn8җZs}wqay/!^9שj$ *tP1x d4g傍/ J:+ya9fف]mKYA%@D6jכ)e36j g؋ŏj//lN1.P#Eh}Jځ${#x3cyܼ>Wq#mB^XYfC⋙Z &\c/G9o RukCXF[LU[7C {DnhyP遚= \=4Qh'^L= QDsŅwkt=Hckky[4;ܤyd a 3-A9hP87-VeEf)K8YђSzC[dp⨳gߏY=Ǽ^i]7GHe} dAnev.'mbqUwE6J $6w*cVQw*6]DNPOҢ@?_ٛ݋b@M_9rڹgW1D 5vg ޛqc`|d:6R 5GZ個5o.>6ʳJ2U"ȝWA 3+J# K# tHWj<˷, ZY1 T< A7kgM“m:8%,{\xfiG b=wOP^#(d22ݷKuJ;`~ G/7DnٌA?䇳L/k~d0?* !JqKz๪!WQqNHM=mؖ]U_zx5> g+3\@{)TN;.0 ?L x ` sKvT4}X;ұ\tƮ #~63HE 1kAԉR7"ĵOZBq>V!"d0KM4נDK?Iw5>M%Ьrl ꉯ3(sk*l `"*N"X"e5hul(R/ BݎO_ c e_v Y=^3HzJ*=ZGxF5]n M |X]|w_NgɋXqijo0X)5޵wO5@sTm=,(j|Zvy2:5׹PW-//-oCIG S\Mٯj!9?4JkZs*Íҩ4@$8*ۥ ${C%DN?Ȉ-_P"PwT)^O D:9ۅk#B^v!nYz-^@ /4A ajr6v~sZcv9Ԑ]n(cw3'FL"1[՞O&Nwb tLa6W.<I[.O+"?qn{׊/t& _d){D@ܔZ"P5>`cMࣹ0<( xi*ZD`GUȹuU:U7hM+zg-ZŨ>k`YÆLO^=B{SL/v ޹8J j-w"TV`5Xm=<r Y>տԊ"NjBw6Jj0]Z_@sˣeMvШVhr&Bk%nO.3$`@nT* :EuNoF!13hVqiR5o8CsLFgogGOSCͶsx6r"R&j$V0}t{n S$Oa%ހ>}U!} vAR-b* !ںnGV%/ïmC4wgmVJԞ2i 1UXG668"烉]!ݻv5vg"hE3+fv:YrMUSPWfq9ӁkKo]?f**O-3 \F /]#Ga&R,땶 YZ