sssd-tools-1.16.5-10.el7_9.15> H HtxHFcQ ?*}}qPΆ+¥CpxˆZT9 _3I&}Z3f29393bbd8147c6dc3ea3ab3649a4e6f9da66e6\B眜܍$Tf $FcQ ?*}}qvSCdIw@q&h]F:ez5{|C>9o?od   F .5 FZw}cc c c (c  c  pc!c#c%%c''D(D/D(0D80LI99pI:IGJcHLhcIMcXNYN\Oc]Pc^W'bXdYheYmfYplYrtYcu[cv\wecxgXcyhoCsssd-tools1.16.510.el7_9.15Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password * sssctl -- an sssd status and control utilitycϼsl7.fnal.govScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64xP0 c`P  KDV~cwL)Jo=FDhta4}O _QB7 +G D|x% < LJ sA큤cϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼ^p0cϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼcϼ9c816bdbb3d6e375a19c3e64afc9ff0efe82bab45c37d24282d76ec0d052d60c39e591f6c430339b9356c71fe9ed9fcf1d569c6bb88a0e0203a4c3f2a86c22d20d2b182bfa331fba5263d24c46d17682c9706fa1e24402f8a2a61f6cf95dd891d2dba9364390f8f29f0e5df0ef38c0b9572ce43c4cb78563b2e6e188f5f53e9af70f954258ba67dade3a4f8309e4f99c08f2805e60022d12b7a654007eeb70e08bf27e3b986f1d4d5c9093966d1f84483d189daa88c811d1f12557c2c7edf8396031946735a44bd4fa8a11f0386bfc8d3ef16dcd96c8ab45f331645fd9576b5a8e90e9a59b97980a54f8a3fd382b942c7040d0199d310e22b2788362b0e4a57639799c99c5f950f2a97c7cd9480c472e25b25f2654093c5063f20cdf572d1275137b5f3bb743b3a2edd7518cb7eee91450342ced68ae06ec635c0e97653292077c19653acafc44fe92d636a856caa9d22ee0ee7a9d5f082c47e3e58addc15e9526b4c41a79d1b40d1c08589ed11958a4e638700e4dcab6abae89b575b38503a08ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903da485321ccce4af829682300763a3e1f047b007e5e973181bfdb06dedf455f424d3de432d7aed7fcf75c970c2c30ef0d488959181cdf3d1122757151b5f28b106a4997b4ecb5f9e9d0cc46e43560270d4796d90af606832b16b2e6789a79a28bcc02572c78fd2cbe228c770f0a8a9738fe9b2b4b47a871ddc01652f8954edc5192a1ed60f87b01a6d5f731c3a6e7799931da738a4fc535a365cd493e7841d2ac52fd5274a5e9865068d438c48b2dec7fc2c465b9b769e2e5036eeddfbc83b0e078bd57eb77b2d5d2d3ee0339354d245e0ba2cde85a9ec3d6c85f223bd992f9557f3684484f52df00a84ca4b815ecbb0ce20986ee2a08da382c7363a24aede188049c8f65dc25fffc942585b0dcd84ad669d230f1d35e83abd75689c47d6b0102f843b9bcd1bca870ff11f34d4d1e078f3fcd10f039a2e5876d2aa5125a2e9b327126ff9a44558849859178ef24c818d6343ae1a83664dfdb65b1967fc0527c6c3a1e3ad20436e4dfb09c03fa39cef9453076d102c435e8bcdd11da0e3deced00f290ff29980e5f5f80b83eaf51e59491337a446845b1973b2791e5f555feb42e21c110782c1e7a149df0c7e2e20343eb531b64f0db35fe2695fa1109007f4f7d22444025b1e218eee36689ddba6b3088e4638612675d5eb8d3518b09bbab36f11e68ccac325a6ba4214f97531025153b88943b47bff6f0f86a5c7801de14f3a53bd5e0cdb5162069e46bc8758905aee2732e58385cd09856db1818234f6e1c07f6960b6a2c11e6afbbaf0261e35392f8ce8849cb84158b3c9a3e029dbad338c9254cc34c35bbfc8e2dba52aa37c7815d59634d285b35ccd476e662b2f2ab9effe7a346864aea51e8d17bb94d49a0b63f3de65116f58d7d5cec99d679351475e7e7ef6d4a90c66d553201d126993735708d1b8c57339b47b99c4a4b6bda9df6661cbe201eafd265a2e1c917ad4e6147f06febee04c40df29f03049e17e08a4debccded0d6b408164002a62bf8d7ade0027cad6ebc292dcdeeed122071f21aad8009cb78749177370b2d31d48a8f647c861a2d1af5c2decd3067ea2e621ac37ef757aa487c742444b5d870fbee2102707449aa83297f39e53005cdbd1514c13ce9eb1687517ec6f82e3c5a5cfa88247b429edd5541539a7a08364635f1823be03caedea15cb601b0c6379ebac374726fb696aa7813e49da0849708ea87b92f64896f7643cac2e28a162ac55d9f12e7ad2bb597cf86ddd979332b34f5056e3dde58866a255a7e282692f459a1c510dd5ac8b28b540b7cdfdcedca1eff0a2a0f5a4fdad62cee031326050ecef4930e7ae69776d50bb910bffd7daf62c2fdff08cd4fffa239def5be9ed023ff99911f4858e1ad63c5db10a8e8132b898ede5738d8a6145d962582cf99c752c27d64a840df06419834633dd42af762c8cc76c2830a2f6f99c10c94bb2609c7c38e7b37c9f32ab5f6b4e9b4f18f524d71a4b3ae122419a8ab3d03e474eda46ad1c3a817d75005198b2c419723b7f631a1048a8d52884d64903183ea79d1e63179194c6f3e6628c056eb5aaa489c1fe439540faf70dd153e4ac4cd8bfe20c3833bbb5835cdf21a0be8b4d308e18225de2ff55d6659c6d2d26023448fcffbba5876fc2d66428729f948b5a615f352d78da81108426265138c88c8bee5ad93724fe8bc3886d23e076a1bd4269db1a6ad2cf2a1ed2036a7b3a649ee69b767b12b5d06123541fa9dfdb0ff71838b97621de0a16b15f386da34ba2a6b1a75b4d512465b88535e895c6cc10a28e37ca4241a91c58592a45871af8912f3dcd7985344c6db005899d9f48fecf56996e653eafcd53a7fca704ff7a06ca560cb646c0e41cc59e683faf983047cf5738e08fdefbc70389899276917afec069de8977e1b4abfae717a7e7b22bb9ce6e29e80a4131badd330dc5d4b39bee497f2a722eb5d1e5c6ea610f0ab52b2a4da64174dc88e34cea5e7379f65e32f5ed793e92c29eefe650d1f7ae64dbdffc8ed1b2e471f21ce52873cec2a87c7e00dd0cd7784e39a4d11c357c306b19d19477df1dd546c0f4d8d57832446853c8348dccb19fd8c1b616b8e5f87e6675f18f9e4e1c7daa6b1831a7cb9835bbc14ca32d3f65fdcc30a660c42cdddf568d11cfbcc1e7947cb65391fb9265727a0259be252d4e483df67a360b95f7e2b0e5c20368a8527997f3cee807e18b40c5e5486aa626c32a27656e009e26f665bae85b1f81049a2b5902bf5e33cb7b58e07ab9a06dac6e3c9219562d138fdc7869a3863204edcb99dee5032a311201ef0bcae33bf2dea3879d7491dfa3666c7fed1e60dadea46c063a04ab79a95eb580fecad066b7bda448f9f66586223d0f88bfd47e5657dd12eb5c813815d30c9face16bd3d614738d751baea0407e6c51b588b849264e9cecca038f7471bb5732d5efbe84f5d43e1006c400ecacaa5f0c7c878d9b2470cc8dd667137ad8d497da9c5a8d9de1202fe459b4c46ad9e6baa0e646eb0e8424607207e222e09b607837e522ec1cc518f76d47cdb41f751127bd81d130fc9992bc8fec2614be7be31d7b0c2aedd74d808ae6406ff1846328e62a31ed1440300dd2de79176305a375b00a5e6bdd3696404c7ec3a48f19d2a7168cb4335947080c0893752de682ee2ef1736db15c409fa18ad9042b2f78d0522cd5b53fe9cfff17b91fb6b166d01d5c6dc8baeff96b5f9df6e40bf13141c929db4c22dcfcde14f127a194a58822801eaa02a9541b1638304c610188abefa2d2e7ba282f589a7ee4d7825131bd4e488af4e2e5a6253f8f0ae0047449cc7fe5c671ce529e89717bf2f746a6c00e75523147a10ffc774c12fbf977e8da117e34ea0d02bbae651414ea112384e90cf381f0a2c28765bcd39f2a90908bf920c23f7d3d5e84047319206c4b9af1d28ad38938e02b75677e299ef274fec274a4c65e14a4957f857124f062753e95afbf6d712d065534449d3c5b0ff28a2276ab0719c01a52d7fbb4efdc3686214e066b3464cb84b049050cbf6a1c9dfe823c6933b040b5b9b2d32c57d4ddb75db223f9b67c6db9620904c28b1ff6c86a46a73d4e69657263b1cf500b2d0c688344cf8b9181eb1326b3eb29b643098a7c95987e4db3bd616b10eb9a36b794933582d9757294da15d780cb49c91d5657865df63b1026c9b60906a3b2498aca6008d077187d7e8c680d7020373d1c9879b2d4800d74c865ae304f17ec6fb2727bd11e0e7070a876a0453e3463b15cf8e0defee400040e59b2b1395c2206f3cb1d37b964594dfc1058aad518f081e86c11b65a0f6f58586cc2dfcb12de84092abd8f9e13743f5f2ac65a60092f37083ba0de6157986819cf8e764dd17224f391f27954384e4c085855074c949096561b71c946f18aee82a9a29b004c8733f4e70f2fd0782827245f796cd527125d97b2f8eebc4fc1c382864155b536cf212dfdb56ed1e2b60dcc89137da50197a515d2f8d3b3efb2b6a9d8d0ee9e4b4b3bb5fc2bb92e7f020c7a3c9bca5ec20439e02566b6f061e89630906f166338eb52ca47e23ffe5a7a7438856f671e6cceef8d0f286620836bbc0460d7da825c3a3eafa89b87f60d2ce4d078f3045c590ba40381fa82ad011283466aac8767dd6018b1af6ae89fe26a91eca768beba1b747b70039f9d6bf15ec792cee2dca32dfcdbb9edc69f6c3b7f9f5dbc2f29ca7e0ed196cbe5382d482bee4f87dd7cf83fa4c3b319cef85bad0c476728bec0b228adfaf42f6e43ccceb1fe674886250c8d9024c51cb4f7b4ff92769dc35bf2ad6737965ca19dd6c206ad2786759048ec27c6f706b2e4ec292efd1a26293b624c96a82d1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.16.5-10.el7_9.15.src.rpmsssd-toolssssd-tools(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/sh/usr/bin/pythonlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libcollection.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libini_config.so.3(INI_CONFIG_1.3.0)(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam_misc.so.0()(64bit)libpam_misc.so.0(LIBPAM_MISC_1.0)(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libref_array.so.1(REF_ARRAY_0.1.1)(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_simpleifplibsss_simpleifp.so.0()(64bit)libsss_simpleifp.so.0(SSS_SIMPLEIFP_0.0)(64bit)libsss_simpleifp.so.0(SSS_SIMPLEIFP_0.1)(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)python-ssspython-sssdconfigrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.151.16.5-10.el7_9.151.16.5-10.el7_9.153.0.4-14.6.0-14.0-11.16.5-10.el7_9.155.2-14.11.3c @cs@b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.15Alexey Tikhonov 1.16.5-10.14Alexey Tikhonov 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2149703 - smartcards: special characters must be escaped when building search filter [rhel-7.9.z] - Resolves: rhbz#2149902 - EMBARGOED CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters [rhel-7.9.z]- Resolves: rhbz#2097014 - SSSD -> sssd_be and sssd_ifp coredump [rhel-7.9.z] - Resolves: rhbz#2107380 - sssd timezone issues sudonotafter [rhel-7.9.z] - Resolves: rhbz#2116207 - SSSD starting offline after reboot [rhel-7.9.z]- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abccacacacacacacacacacacsdededededededededeesesesesesesesesesfrfrfrfrfrfrfrfrfrjajajajajajajajanlptptsvsvsvsvsvsvsvsvsvsvsvukukukukukukukukukukukukuk1.16.5-10.el7_9.151.16.5-10.el7_9.15 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssctlsssd-tools-1.16.5COPYINGsss_rpcidmapd.5.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsssctl.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsssctl.8.gz/usr/sbin//usr/share/licenses//usr/share/licenses/sssd-tools-1.16.5//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man8//usr/share/man/es/man8//usr/share/man/fr/man8//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/sv/man8//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnu POSIX shell script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=31c7e7deef5cabcab3778ff51c845791263bd153, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e451e8f313aec6ad9c1ee168f6c035025f1a351d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d5c333acbc8b4c70ef6463f885f8b295c63a35ac, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d9687b4facda404ef403324d4b19a6681c10f798, strippedPython script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=8ec39555edfa59797a65ae015766330af8d440a5, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d46d3896cc1a06082ae1427487a55ca937a184b1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=028f5f7fd1426a2f333fc7f740bb6b3b5597c85a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=a5d86eb587461a76df5c362d7d022d5b1e32f9ff, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=435bebced6d7d6669eaa21cbcdd7959278321583, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=4de943597e361996ec4f897503d359d04684efa0, strippeddirectoryASCII texttroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)+U*W******,-,7RR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRAR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRAR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRAR"RR9R$RRRRR6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRARR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRAR"RR9R$RRRRR6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8RR7RRRAR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;RR1R8R7R)RRRAR"RRRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;RR1R8R7R)RRRAR"RRRRRR9R$R6R'R!RR R(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;RR1R8R7R)RRRARR&RRR"R RRR9R$R5R4R RRRRRR6R'R!RR(R:RRRRR%R R,R/R.R-R+R*RRR RRR#R R0R;R8R7RRR3R RRRRA?p7zXZ !Xm] crv9w pIf'Z=FeJ 5D>H_+U=l0:]ZX4ӊͨ{ $al\oȪRj `yƮn~rs16ΜOR!Q̧vjn3G#ɦ:tI:R@AJs:@pdNZZs<]2(Bm9+?!+U%2mV[69/GzDn 5!ÎCTߖ%"1L( ?{›xγ$絷enmr,p^찼B^?jXs*|t{dK␎P8i^6'wUhYy[p}pZ }ڕ^C,QZ/_v#nbZ iM| t5sv2^nr}/;# Ll/&pU]|'*+tJ}o=!BMW#lFsʗfZMW+$\ٖoC@/,O,t2o"ԬzUdRND|hPXq6zź]T"Tt!h{a%#@,l̞\0r&^* Kz cL'f#YmwD[=\Дyԩ˟%9i%e%ysB<;~ k}]NK]⯝/A:+wj>gZ eEM'9%K"c#F9y -78d$ŃNq—gXI'՗+`BgK#V]E W9_ OQ_7%@(SFgHeTk:."DO?Aeϭۚ8Ͳc+2Ora}$XgJ6<Ë_πrJд~}v52re?dh 3/DuIW`~~q$?kCd/5)(ULSvj1OaB*&[Hl˥>CBVQ*R:'"?5SyQiZ)<}?f a$rA-P%&;?p]s\}f(Ղz[zu,T[ƳMۯF9d3 FS ^e'' cSmtT_׍"u'Y{Kl>|Û@-lcPA^Íy`ZB , YBϨ½gh/76wyOe~`siʴX)ƺ:؄ {"wMJ%.ae +$ Kna!_MJTpP4#GSz4Qw[/o(!ENIshOiKkJXjrtS".r5} y0~B˸9 hs?qS NқJ_z? 虯 ]Lܞti15Y˄my\.Eo7W 4wY JKwd(gOWU+Y0{zw+k/zAow$F(^a/.wKEYt(z*h)' V!8.&V9y}*HK8CZuYX.ֻ`>I<~`^uYI>2^II7I[yyn7E.[ &h)`ZOM5`e"sGЂ*FU_JLPF\R"pܜJěkU{ೢblnӶAō6MIebfL4q''g/bm :\.v>jwZEOp ѹL(jĕ<YE>/]?# K_կ롾 {h d9 Z&1R 8Ÿ*s<]ըtphɄk):ypgD5Hּ~%ǔ-F9-J .(Ӹ !w^5t'-BD!ӧ*[K"g- A}$x 'q\;$m*e]lf4}FLc *ɢ@s4?҇ Z?}o_\qi?xn\b mvÎoDUjؕ3m@݁kFxb^]9dWˉ=~+"So8>DNB)cL +XiF8ڝ{`ʁޟ/e;J k4' 9+>9gA  9ˈ;\"`-{ b6ǔ:F}E_7流VufuB!$_ӭӇ"2:ϼ53?acߘXLcX7@4\NLHkX}xPmRKdK+?.fqBMFUJ} \7Ƕ)vl -x2z-&dI6nuE0vNRl%x0"w촁'L}1=/f1d rY_$44M(BH-b.h@z$MQ|&EB(ri } V2rgZ1 d@;XG1s3qR]ۅ/]nǃ"ɍ :07#kF^ccoSwK|H {|) y7U |X6*?æjI\5ؖwϑ3/]ki=P狉M_3.8q@Zd}#0ͳ~Ã-*d;yfk fVB CF/0xH, с G&)[\Qt$P#M~.~Gߣ[Wf;qm1q F$SsjdS5[$&Mު|CM-ZnoZ&xF6,59H@0~ZXؗ 6sGuu饅6D$/'Pmy(Pzur0;OO+Er.Yo Hri'Jy7Sg7%.-8d6ML {`f_3sPYKޡD&0I󤒎 !\ "f emj;(DRnd=ʞSB4ANܓsf QLD/#X+Z۞RM[?8M* ~[l*WB$vȽ*zx/D-(:H1vؖx@NŜ,X(Yrs X%y2ewj5E N޿bxesQP Wir;A JKr4ٚ+j|C1ڑ-\%zJǞ=-^0qܗO׾3,CK'Aۘ4wl%Ym+P'k7d6Rz N=JtLeqC6(A$ 2*h-Ԣ'>KWV#9 3o*`@eݒ 1e|Dk&m{ f!/zb3U2"C/La78_A8n xܫDAiG!xDgF2.=D利/\i^+TXjp!-QAaNVpqSbtcNL}_.p&DL}D'OH@άlQLX2شT?܃P /Cjnf뼨ޖV~2S$ʥ8nAC-S4sBh+*/zɞ u6M֩38Bdmu8L{Y%;XL N~:KNm(ulV^gM6j-ھl+wϢtZ,p16;@[4Xk1;rD^<@!_Z=UNCDm{3fdfWE)fhJ[tj˯ {) 6>Ƚ } P˲L( kb@[.v1sCZ*l60ח0#c*cu?1?l+7 ?a o3)>/ $W´ c- f|̂QzMӦKux?ݢFOZv*A,FMp^aAϯW"*y0Mz Օ 0~ۑIAwʣdb_E }7gasamV!Q8{*@YƏ?vq.]UGz(r=)֍,6 +Ǔ佤G;9qƈ]!a ؝5njeX #03:(ќh"wkI>aR@'˭3S1,0`-"3,%B#553_g` zW\nOiH6-Q Ȼ(on` o*v0@}!{ %^ݶH3emY3.-e.R$G]G ލsDoG_ fP-uO/PehwPa= Z|f)ɐ!gA@_ +\qٍ8rYAz}K—N94y7.wNv=_a-Jo|>2pOW>}_fE4X_Am DKUE#kK*<.`Q\&&†xeߦU=akS6mR%7?:ԫ Xs> w TX#Kqd."BesDjfU}Fp%~RҦxyN;'}}eAS+ydrNmO+Dl_Gx4w `ٲ7%z,^WO#$O'2)ZpR*#kDh8!&+^ZjR:APDe@A ^u!{_I92't]7 lRxI6Nfd\`Fuu$BbN༭đ/tcM" [.ٹ趹4I_Xn/aټUR xܼx<чYpIYIBۋC䢜 `S{X8Pn7d4$\rw:G06݀: 8wᗍ"Q҄>^7`䲹l2WbϹ0-z02V ̼%-M7(KxME2%0hyvnME͐]0wyiinOգ/1&^3&"Eҗ-R7KdyM>`rCs~fFQ x6ZX1Q;cO$e4YCS-^nm'e; ˅RMIn0SK#@K,$w_w ͽ8'@,X-H$v E/h%U X9x,TVNuj`xw~Є=D 8;1TƇkrI -@E~CK! tw,||Ɲp~Z+* S^fARMKV>STUYtUay {RexyUxiASUv(SJ2Q5z&}xկHծg=IQreȷs ͓(L:2nJbW<5]g\RL{8qԃT4o2ä2#gUvޖcûod)ZόV\9V䏜&`M2٨￶%>YZ3k6 c1 y9: 8j;N1C|nDb߷=o.cl +WKzzO˦DS%Iz%eK,TD\b NYčp%ujLqlL~#V-~+hKL_?>*yB?Nh\3F|M}ڸCNXdAq կĴdl뽾×Wb*2 e}Ae- l~KE\-Cpߔ[HD>ά{wOׅw.EsHܐi`.@xd00*f';8oԁ{h_>=r:+e kө @^˶=zf< \dܿljHޯdVX g+Wm\cqbg|,uUs8]KdAl..B|<.:( @Jx{cKVo>nmHGױ78fL|[X[j0#f-shИiKh dݭ{ӝLB"" :UF\a!C =՝4+eŭ6p P\BTSϕ۱@O6p-4@0q!T׿1D[5ҙ1fjf7$.7X_b-A?3M 8v:zTSle@DϔC,.(n8ڧmr֙>c~Ea^77=PڨpT}TqMґXq;wLO9`AًBLr&_*#H2"kl^Qm5b0&9+F-}P=F @yǛ.w!G!9^ZoY_9j3(^W&q38`hWδW)3huӼEd ªZ o S|ͦfHWe0 FʿX<uΈ][/~6&-)j,IGaD`MZBAE%d. s pejqk(i?Sy^[\Rl} Otrz&/8̷\4m7ueޠvNW"IlmuJgpͧBJ;SAPne~ᶨ"uG靊aDžLs 4$R"NmF/h= QzkN xV a>gJFn }9Mpc,2V@"ϵxR[cIg! ٟAa&A"p;;2AIHF B%֛y=1ol?|-ȝ1b'$ZyjUӢ)V-=rϣ;b[q˿j?0DeZn69sG&b4k!?Ѹ dl׸ϱ?Hx|mleFKM|$q+=,By ~۸0]f3/ laں~.6o$%nֳ v r6oi9ew=Wt-h]~߭nl++vPdag,![ҫt=?rj*0/n(_(axiEMmkD&HE(4&(z"Q'Gs#ĺ6hNRs\S3V9=x #^nssHa7"mDž&0h;YVQSDlHW&e/(235j>6L(]V2!Ͱ a߸AR;S|ޱl'鎸Mǵ{ss)Bi܏-h(;z]XG(M`~^HD(94gzd(Du$~k3X -@e¶Hs}0!Bh`!n(;,+nYަ,?SLZ/4Mv }=i69 =zR4ݿXxD= DLI-U[)LB\Z-ayxȓsN7]Ix@4"CLwh0cl&'^`6c˧76 N8tоҢkfv(U[%D6hY>ga%G+lWIhrթɨr@Jt9D (-s /B3vnbJg`,EZT uF* ܚyo m Ğ `v|JAdڳڔbU5(ݾwy$?D,jhA=n-x_!K- ˆw)XOKӮ%L/3"Y/Z#xU%/Wr\˳*4.e@s`li1`bCq:Aze̞w޼M}J֠Q-N}7iNB0_ Xed߿̩JqdVDӜwbX'dYl<P<,h } Ȍyq# Fpp:WqyUw敤]Oc2 FtTdgQ!idP>#i^E+%aԚΒm]:<8rCx #n3&9]]H\{ax>I3IERH"|΁G1Èk#eZa63#zυ[iK t;8tӝvS}^o$|]*y &NJ'D6u TBտSQ,1`g]á$z vcT{U;|gB$"'< V+ [jDbMdӡNyˑ˓XkIwňՊGg->J IW#CȆ܀HE/]?P@*?lH monEPVWbN+3d*1y]l'jXiv"hO)r+(2kLqeSS-jΤ:,hpU:6UAe7,ӘwT1EΙJ͓D|5pmedF[0"V+vҙ5{zlER䕏R Bq;4u{ ԗ')4խ 9<.(p`,4𫼩zX\646c{l͟Ng#($2<mt#r?vn) 0b+L"N{F/ْM Ӝ¼D6jɎzͼR껮i'h6ՠE28fB 4Cr:Ara0b~WScS9ڣKLmzQmLEV6R qtw'c#(?>:ґg>9q ]FWU<3P^\'}X\m-(jF洭~uƯ$?t#ʄ%g(Gz),or7:K0mrJCXn1cBc v~ $wvQ hٛ>jY̐&t8kr#b{_Vߤ&𣿁|T e{шD5p񙐎 LY޽+0z%)4WA; o-K489Z1>у*Drc5 !i©[f,0'|uvG;Rt IuDCn7mY>-n9 Ӏ-'KY?]?!zOm8uVh% !Ɍm ߐX]ʌa %mթg ~E_e!abD&p5l,rc %tD/_Zts^w'vma~4kYE#鶶5D6M1,X9YO9e~.&@SQt/AICqNx#jcB8@MLNH6xR~brSF|gKA{f@^ڐ8>U/qd%H;V @,"Ú1r̘};JyTB]pzj7 )h `fC&.X|] =G^l|R 3f'[|T:O ygDe)MF3eMҺϛVϯUf() ~Zd ƶߙ5='͠Gĉ0 Q(D='lBߧ!m_v-SX{BXj?ӰW%Gz|ڮ KRm05!&:FWܪ=TtC0:uC s?[/6*U<&m f LV ;xOze ɜ _̴ρ{]Wpċ B*ce.1P:cuQ  K+^Y 4Y/l;^z0xow (}f`%!͋*5W0b[PqUx-7d#@2BT ^٫5u` TSo& ^w;R@[3?Y0 K{KDžѮG i> Vix?]gU(m) :>c O_  ;ӷ&vE-Pe=ݔnz2`o^gΆq_mв\N7Gppϡ{X9p0}{1En6 B%@)ˬ*WqP\ 'M8`Sn6`FtMߟ+L@LTYm  g}I`.:KQӧ*4vH?4b?E'Ҝ(52h@]CupȺrc<=qө!IGHOp9PM4 b g˻{$u Qj@>QF~[ HÚdz[P"}JǙVkmz]xL~cǛ8!_W?Ͱ ڗH= `8nx.t)kDŽ/cgG3O!$(\d \׆JJ Aǧ_-pe^1ͺ߷pT`P0ZuP[ >5$@Z&l?9l؟J̾+5OHn1b"tC3c;걗#KBqf5B=d7z W0$Hvb{j?Ahr7'y@J/AZzPWDB2@7Orͫ\xC<4S56q>EuDn?RW"p{7ϥ:raz\ @6w# ЩXfs2\ H׳hbVftgY㇋ע(%(8V2(}IXPz%ZS]={ߞTW&j7wr xbЈ']\1y}멍KeR!6άh7\Vl_reyOgbʏ!*Kg,6@eѓa8URKv&n`k}:sr&]fxX|Դ ǎt;AEodH0nyIP_5)B'$ -_ OLa9W\#fTݦ&Z.kdFSZJxK4GRIܧ")׹]S=fHFRpf;k{W:pIwe].n!uq=3̛/*TC=D WFe$u 3Xs1fGqf2.`D;h;4n,SsO C]b'sɾۭm:!C'tL)X͇F6 9dMeg"u~[H.DvSO4fMx}jm]``.s{r:0=vt7(6kr}4_}y`mDN$yD\xp<#6qm`>%ViYoӰ8N(xMxZy ϶oE:.+H?@lAuP `Be%*l} xt3M)\O5cQᄌ|'5Y\0{8? )˕j-EZX(؞:*ᶺ#8~--w"h-TА@1!.3/lf;I+I)@-L#:R"حIW(V^ǖק`s@ٮ4KlF?Qjkr:R5v*{4^ǁ Fxhez1'Ci ?ފܧ"B({K"t88I#ۥ״e_LV`<#ځOTXrM(դUZ]$Vyܶuw$@֧I MGD@pR>O&eވ5mYq> :pGaG(#*c{Z^}9u#^ :Ee+N :Qf&|.Eəpjlɧx/Nya.Mc6\>T/n #לP6O%1l~E|F …Ul`dk(r{q4+0+X&V8axHG*+$¹N#-וւ&9Q܄ h:k9aIo`  2Ỹ"V ZĀQJOMn|jA1h $7❞6vyiv4ԖLړ6zA@i]ZǶ9P ={&i?GPEO/]QhNE#|4qQa1+;K" zJ..5vn,2bY:wơ9 }+Em3f\ ^hDaEIT@#?f]}rX 2e]@#k)dx s#4(P<j'Q) de,(_`<+B? ?Uoa仕3[;$R$F;4QpjMZiMoyy]fj5 Qd)p!g u#V )9.^L{mZBz3R>_k'.C@|e*4N=`obL[ P$TCl p/V;+bN'ZK>=rpYU~%!c'&;p1&nٚ76gYB}6:9W/\79{'Rh&,1]nn( gwPwmn F}VDZڟrsX42$gRh!_P̙ƚ}aPŲ_>㘞Ͱ4^hi~gn0gT&'BJ~Q5 lщ[:YΖ_#Mp x8ۦTI$,R12ri^NT-ZDM7=F^[r [솪?q (`Ÿ4'dt&i&Y>o~vo<|0RTt\XV+G#NA$ 7TiВ͇-?Zw> $t?^Gȟ^< C XUߤ Ҥ4{K 8p1?3G{b-Sŵա+>rhaݜ`^N?sEPa7Y&l P/戥*yZ_ lɯ" 1Jh'WdkPW0rh >=q*DtI+b8-毿aeAjahn~>$j=+gdϝbcXML\ sVënRw1[>?=i^RJ5v4+,(jSRlHb9CJc5bR3]tZsI) |wlʾP4{=G}vrLi@G:TVߤPP97 |"u=ztio;(l2|X^^C ".wJf|D􀋾~18~[+v@*>vOWEI 1ԾMؾ/17?O*j sK(_YYL7ם|Vwu [8;ZJN?e:Sd-O} %;Š1Ce- K#&icL9hċ͂-z o{hN=frmg57TBTOClU^FE Ñ,ELEx%7v_T_s,z .yGЛtAma$+hF̢G'c8EE<|ˣ{tfbkI$@8R 4kw-ϩC:%2y7w(7[Y0B~Gg&i[5KAl2}pb}m Α+.isch~;.3|Z?vnfH HM_ikֻ@Y8Q 4{ ZDRpgu}"*UJ!dD1+FyӴι)Dh"Dro| 'g,h#aҨk`W{˓\vpTSh(y⒛roڴiO'䌘2O I)[9}0E=9g~!ur}r 9ߑj%gyF S2d" ţqb;rف&TyŶ>mZD$؋[qm"X&ӻyEAEԅ ^%Fb h oQ-m'~ |^Gu?k׆ChBJb?(lxZ~k%(RtLԍ3kͅ˕,m]/譄{LL]d0{dB˳Kr% x>6tDޜ> WFEĸQO> g(Kxz \WwB$-oZWK'E^ :>j J_lL q,XpR2VT 5wWIҲf~|*fz[k3"9?!o4._{yM+iE|H3h_'i/!y.)m ߕ?_ +q'[ͪ640C+4qQI괢+E}L)Xw,c IZqwE#4j-Μ)ckvDhyBCQK,(b*g2SY`HreR4V1_c+ BI^9F' gGX% TfkWT>dU+LlDt;7=vg4qthi3\TuT: ~ [C@s'YlA=7ǘl$>y\rD(m b1S(ȟR8?̒j4[G]*l%gNr `sk='Vfj 3=aА#Z~6_n2SY_ JAl.fp0A lg7s#8r?}9+`⚝ֽ'.YzTuϥYQrHC mdN0Q\QY[HVTa<{ 5vl{%ȒqS¯67:|DG OeZ`|١:&Zպ+r-|{AuD8Џ$%P#Kt88y5fO:(iȨKCeu(U[ |oU7M](ԎqNJ(`pJÄ5}&7'LJeqok%?Jρ@sNDGx{[kVE?1)։cfvnʧ]m\tcVR+wiPd2$խ̏A7{$+h32j8כBDnyi;=OێhCC{gea`V_6BT^C|f}3 {QəayqFՕ̙bƱt,a |y 8oT 1 ?g;x7 L vmpu!^ ?.mlN_ $4FlpJnpk6͹ $p(O _ r ,nq5~MtK7 :d;aT =}b=05th<x+N`Vs?NiFeQ*Ql#D:O7][U_rlua+w}g:pgVƉҮB 瞾J<Jԍ2MƞHOoFʼ@UD'n}ˠhuN)+^wm?`I{ϏeD o8g-gk뚳]m)!Nr9L|L~OX,y ZMA-,$g7[J+N Zfuf`gq8|~ʏmU>O!'a*k-N=0*BGQbj~{v;ISA#fWx =S[# mQjQg!hb%A] Sչ)Iw|HI]6R tէӢ`(ARBF] !ADE)L .U^jSe^`0Pde6?EA-dUKrdc̤Μ1)n)ڶ쁤 r&ûDŽ"S3l&bt>QNa$X!9 txHVBϓ5b qwѯD#Z d!^Yh˜sc|%Z_0/KC9I|&-5*STu`_am?^G|eCVS9g\R&Da, – BV쥩iFHc Gf~ '͂(csiRP*M%)hLj?r5\aYzopd/"LG37ŀ [Bs=mFm%~rd;iYb@G Kn43!c=#(=KS{X5ns%;;)&Ա(XpNNE&I1@IDnG2)iV7!J _zc/*e=x1뱵!O;{Ā8PfMk;tfـ1Z9ٸ#o!W?OWta'YڴkU3:(PA#e%7;Z<`( L5qWnmX`):n^X~ÀHfE`. h\F0=˺h]#((ߡ$ boϴ|?no!1seC UMozB I!4aUHB&&d&U3ͣFLA 2Gs9Ge䟀Gs|I$j1s6冣𝝦bLa--Fr׶U`' o&Vx` ڦmxQJSֹR)v1N6ǡÈYX%i=bݶ 3YSp .8q-\FU~'VG9t2>mC# Wn,qúW74LEDl ] -;gr g^+H粣݁ov@g/Z⛞&A\BQ}"~.XM)x#\q=?/ \0>*:)kzjg+ä T?륉߃x.Na_-wGܥU~ٽuzƲ&$a'"V]0llFiP| y DNRTBDVWN9AsCeHe{"}ľ{ ߉ 5r]xXPqhUv*];m|P}`ArwL ٌ x  E1RY"ϳ>f'u$:d$@~;ɒ@ktX9- v;@V^ BTBRL=:u)(?N]L^k\e>ԍY'7?h͢ykأwWi/e@fhNLC.3U[}-/ 5LYD xӊ뀐Y;ŴR:w 4!{Ԯi+y̐} Ӄf67{)x^j{|f\W1܄+IImgg mqJ[.`P ]!ƠԃJo- sVWE]mPW|vC=&,#5K 'DBxZWo;s_d_g#uJ v%? N.Is1sj`AVj jWU' Ozf"5f`/N_ȅG`z^m UVMԦY}-jr||sE%ƇdNy,/:H]r]UdC-`;cֲ4">k2)um6]½QfPVgFL|BcLDA`Bm۔ /C@qVG9;"KE,\*Tb|jua鍖+/8 =0NJ#K٣vì:akW4s4 V&|?`q[ J1&t!J66BP,  a+jYV=D@qFo߬w,"0H444mĪy a@ Yy 7;(s.AAFL]]d9"p_\9{^jTت֥pJe"iFzl6cP[FA0i1Po\ՓX!JiކŘ`ߛ"sv T{smxu1HAQV?<ZkWԱ(K㆝5,ǏYpF˼@TA5+?孫W ,1}ԫBN5#Mw#۷S*opd螫 b'?h#M+>=ϒSyy͂a02˯z^y̝]PleXL_#v"nQL2P˕B_Q.8)ƇPs oɇm%sT3wm$,fщ] Znq#9~t<y o" g^ _;+Z>Ę<֙RMmT;d7d2Y._뭾AzQU_!]?VQ1Rtcr[F`=q ni2edO4b@juY 'zhOrcMtNdp]4D|%+lↈ1p1`u-tv|Xrzf\)4뼢QUVaE!,=aFщ zm!UV/28+OFi4J`\VB1ѳ*E`B&k8ćK|=jdރ`Ps.ˍgyiji]OF]lDž6e!y!!'[t^WO~psIz\_P}B'g(hp\6 gd<"p@gMl*IR˅z_Y;'kNwOҢ`gplO%^Scw_D64,NtA1? %/˪ zxȍ+dBI=āDZlRx'TλTQp3 ,:W\qͧ([ "b0Vd&.@zXCiKǯYPb{_b{#)v΃| SatpcHYU*c&\a| wJFm A8Lf՗ڀn&.Gޣ,+Y~ꯨڍӆ0&N? ]d*D"$M2QGjoW@v4#/$[o6c4!#~`K!#.VѰPt:}F!Lv}0ӵJD-lK0z[;aS'=Ӈ}A*t^|X;-* 1 faE]z_0S֧@UPh5ѫm<2 ¦'ߑ<_dkíSRx5d$,YK`ÑTPUi3S"fzή;U6ӭz\ƈV5 1[fLۨ$ZXjEZZ}"R44Qfm͚K}(wZ%cqR9S2{h%WV(:+MOE1@9pGTBI^o ?'p$ZЩr=,^`&/qktU8qo[^I!gLsBw)~A5y3PΫd"Zó\oC ,ːWqw7aY@oNCʅ u2^r4^'I\ljGAW TW\ ѐEf37^u!`B 6{XPnyZL H,Pwpv@#mBJ_ YeQT.jow 유l_&V8+2@^hD.nfe;sf͜F'Fhґ΀-@|ۗ2 t* ~K$9[oYNO01ܕ:/R!坈 8spF:)"y4[LkΈXY[~0 I2EF[|n =ʪ0 u/NL5qqw</t3DA`Y) h=Kt,)F_cѕË-s'Ϣ(U$O(bͪ3u [l#.%52U8 KV1GX7cc*ttll%'q/FM:/¾'BD'ԷZha@t?:|復 m$c57[^(;^#-idDaoG:cH7h9IoaJ mLԝ>ϒ}T,_~Q!L%Bt BgS yTdmIl ڤ Y=UWbD:'Ȑ+t8Uy`G@1xyz"Ȝt[#"}E" 2GHp4"ɜC׊~ 18p$Ҵ)(z q|\b\sqFj|,Ki Bכ@m6Z;cLq2*1, jxr*d"oexKA L eH1 ?&§HZSs>l'c<>>jPfxW|}aj].71]4H?|ib7tWk9;vX%H19t[%w LJy$2=Wv$zp }{ƬI#V;J7?$?TOz"RqןK `ᚠ5U-,Ľ=VƣcPN&.` }Vga镆<ͪTSU;6 =x" M$0MY}q~si}kmcduWqv-^n/MX.-ՓvbKe|3D; Ξ_mqkjD1 ]u1dYIBq1,!vA# "G;"V0\#؈IjK NnaA\]MRJ0˺H .QbWp_,_x)kq`\Q]=T!cu& ȔS< u_> )}ʼn1ɬtI*F~XC_6W[TaA!l=sh3y"Z]b'fYe#n?1`FҍkB`;cg5هi<$z=stQ]&->ФKO'3(p+UT)'AL I6m E/z kU.L Ub'vo-Z`c0mlc^ciJLٶ(d^rtM%8ߓutdza;C HS1)Ye,dyIo# vUΫ/`m9M%nyd7ݴ0"Dkzq2lwM+-eAu'OcKx(ޮXW5 L1S˷y#)LO8F ,LkEZ$9˜"@^:GBkƊ3&Q#ژz-H3n?}rȏt/`}r0l!S$jy5K&q&*˜vŴZu 24?):!~m]4AJg7J-%&Ac1::>`5 0_Ii }<&2^ r LA=JJc= #em)rDɀoE9WC,I94XovX^lUρD.Ǹ%Zu.=V`)jÝKodlI/H:Z"P0ږzDNG>]]dpίܴSzMɁˢ !4o_&Jq{M=$#8p\8>MVsJUP;f5c&8 !s?3Ռʒ7uXl_- {P 8kr_Sřp|X~;5kswxBy(}6}Lmm6}B+;_4v *CKS)t!*5 y)9qC;e! n3$^5;-%-φ2j=^-X&Osrբx\%8)6FdUo0~2=#%j9aZ8mŷuȮ=w$4>NۤيF#v(*ה@1ۢUW~=i\z]F %]bHjX9{ҤPFkcVR-yjd4GT۸1y΅2S3E7[>ovpH#A.,YR+ G&\O8'6jlD8WC8tٲT#W`@5ӻmj~΋O&N)@h^޶GWO熞>|.8T * F7{a&_vU/s4#Q6S’iC>!m7WBO.vG伊u6%5MZs&O,IVؠ͠-+0hq?쾓g6? !srů {j£XR{z@wt;T'OS0@qxvy,ifp~yƲ7Ԥ892UzL;|pں,&b/(\"7{rmLٔǶqha;bp_6ރA(vE aQ"=u5fr2TU'Nm)|^L6ihU%LiGlp@mɡDg![O)aOGt`u44"KiŅ06UOK n=#:s>մuf]:qKzeZؤ^qvAi3gj]*L{Z~41a!XChK.rVzD[9 mOf 1I`ad.o:IճOg2J{U3FV } *~=%˂=x}[(7$5JɶV`Fd$I23y.Ѽ"o?lC2yhke\EX=s>He9ZaElT )f ik 5n Sޓ LWr Vy%"ʶ KkU&"<883=:c;Fcd{&PnTi4',up({jQV$iШBҗtnE,;AUErY./x1r=t$.u D\҃CɦMegtr*o@ɚ'V1āXҧ)y:t-=[3͈b4uČOG!®f*(эӽ$(NzEk  A:uǾU6yH;!o/lR¨EKj3LunV$2 з/m*r(P]sAscp,%2J*NOe8} w׀f\YS-8oR᪛ҧƚ>+k]l5L5 y8zju!Kۉ6X1w܆ccյk%zr3+)Cީ`ɞ9(j*+5Ч ) _B*lK`M TyW FԴJ +qq7wkoɣTM< QL|n| đ밡{diN&8'la'M7BZ<Hq oP_FmuvV!rwBbJE#"N\hU6μLY.`FD"aR3I&('ޭ1Ԗ4J'l2s_;*-Q~ZvJar'X2yA)3*[hEFzaӆH/+!.ۭM7`|ρ 8|7z+ Gob)b7aj&eABmxң"+CglYkC ֞vsvLg iEMٹ7;T'h@ТFl'Aʂ)%3ǽDZ ^݁o, VC,!pgsH]{m `\XuCQ p KQqȭAU]HGb]@axr@7cI>t\.8}:xob./S~rT:+J۩opR1ْu,!N:H1"~C +j%E 1ڠNtb gɢkq#j뉞rIRg,XkkbqTr/_41DPݎX~i2@M1>Ǔ et-lU፮K0Mx `M |5;1~?uGJCDeQB \G=y$+`ҍVTfV2Xr (< 0ȁGCMteZ6s"}_,Q{3(g_p-ws0B)6eG d;35Nfg9J%p3t$1[ԫ~lw^zaB#Ғ`h;W3M.L!qO_) _ΝX:*SYBv=qNUo]9ݰp4^bUw2h]pcK9Z^|sɟtUi%,E}F,M`%.NZK[=@U!_hD3鸣Wds<,ڄ< oHCr*>5o 3xD(@H$OAjĢ_8Dȋ$5Hq2-o+f 䓛\j `# #|nɨk_wtvRRQ )-Ҳ:u;*U) 2k YP|l+\ ^ia/j cNP0!`S1j?bN:wx/WA¿) ߪk *S"SlBQ_,q5ʳ%s:RH{Mboi yo:RJ7pD]➥'n Oʨ :Zztճ_x @ |1bT3{ Y\b^ 9D5ih5"A0 ıB XW뒔T5Ȇ>K7JDže$bQp_&&>6H~.jx==[V U3姨]=P%9%|fcoyUsoB4VNyWinIҠs_<.ݻCE,0q_M " XQ̫<^rhWŸZ`$ toH;.v F&HNP>_7E$gbڿ"$\{Us!‘_S)7AbQSE.z8&h퓣` ^;"iO݄yD,]- L~" *,vn_|P@O(.ϒ[Sp"[;QK^[8,( z?lg3;"i!)6?V LJnQ%S azN^q3L@TQC̰iIxNV1OjMHMsW_~fbO&0=P e#r(~ v;Q]*dyaAsxD]nHiw. /(ĝ'`\Iv{E0u5*a<|bUc9:MO;0pgU9h ?\Ў\b hlM6T|Mݖ{]:p)fa.os3޽HĤ9Ų>M-) +%oɏeP9`Msj\xM l{\psdnÍQ@Jl}/rdtҺuYs$w:3y0_-ihؐՑ OJA;(Z#'O]}2K uO@3/¾N[?PK( m2V)|v_᫸ʒtg?hcO#׈ )o>%2m:*SI][)6uQs( =Sa kpK煥FH BQ~#.  VvEO!7:b;x',Yn/{&M^ST=TR696e>e6:H+ß ۾LR{&SތvDv-x$i_I?˲s]ѵ\RIKm)bowe` m_[ɷ?fIsvjJw9UE؝@{RދUH&'&I[.>B!ͭ)=85 6Iß%eMnC nhaUh0/{z#Zg8Atd1I Q;h8I Jp]y-WQw=\2tݽ#ع Y8D3/猻3J4$gk\"i1Гպ]_&Q0Hɤ,ݹȇx1rgn7YROb JvlT͍uePO^\˂[O=_d酠NwE/ k zĵyڞ<X_:~\UNv> <Ϳ5DPI>uwKKX%`Fr?9, &GqZHiߑy^& oYL*ywM}e>Gszyv7@B;zNJ|D(yk3(dh';+ N/c1{2 SD 3KZv=ֆ΃5&cr6\E+ٳ\Li4"QOtp#PN#y3 Dx0ƣQ$#Th}x  %F1-RFhdh["xYw:&A߁U +}^0Wh0EC -qsI4e^cc\K]13 >H>`>B"US!9#s`eRW_m峿")ۄ  ->suB5LYB|Do6r^I^ػ".i 5 nZj'oʠ,b_hl pG<ˢ4C l"H3şzED\yUp҇K1Bj4B]NQH9ow< ~ ZZ{?JR2o #tU|jYe{ݯ4S!aFQRhU+v.Ccw-Z>hsT=0V$Q(#~ bM!B'>/J]Ae tw $a+5\?dOPx Ow=SD3]Ѳ;b7[y :ۏ (aoזbyE1 7y/}91Rm. zpχ-g~<֤Dftͩ2OYL^{ePɱ@%`W ٷWn-acߝbc h >umy>;֞F *FYB]|E{tRB`zP~ ƜY(dp zS݊Ҋq_ |ҳ"t]T#<}W,/KRǚ`f㥑0RY'tZ6F-[vtZff }kaƚB<ۚI.u|g.X|C8{nb.Z? nz{ {:J\7uajbL/J|&+Z4<qu1<n䤿A}%3VGηc_aFzoF^JH̓w}[?v $]{O:9F67#\Qff{ҷv۲g~徆IuǵV _jb9HP"1w ҉-З% UC~|WmȰJOiL -P*# 34j@ߤM}&gX1CBڤERmɗ]>_Tث ޭz9 #;PT{t\؈%`P j?cMZC"ܘbdu4NN➠ouL**>G^ BE E&MvH15Y0?-c:{VLO3sK}8kJаA3<++Pڗ^ϟ8G(>[kґ;{s]@~'k(;^ǭ2EPbbѼ)n׽; ,&-.6I4ȥ/?&5y9n![iYٙ!̀\|{3ҲF0M~;.bHSnçoT7my ^@AN|=|Lu#z2(8s-IGfQpę8-͠ȣR!!GCb,F0dre2'Uiߙ*ac*Sg"o:JryV:dJ Au0on]06HGesnGy$|/%u=^Z1N%NY04B pש EHa,/FXq^09'/_x׍ 劣Ѵ. .,_XGaqџRQ\pX x`Y 9NՖ́*jQ׉K,?=(PR"]8l*0Wah=ȵ? HCWd*nwZxA{zH,۷>31H%H7$V^Ք8a%1gƷ_ƭkFvVQ/ϤӄWmi/"6l;7L`V OsB]*C>teJwwxp@;=/IV8Q- (bq9B8WeJѴ_ #X'1\WU kB*81vwu2[·3QF`~klIexT "F5ibԻx.1 :W؀L6m y+(T^A's+FzƂ{&'l!/w;r10Ą}pn[7>qTl=xu, Cz yryde9DI&x rOm#qӵq8 ?HH(W9x{l&z>ySu tݢIi,i@@-!Rg0+emEH׵KhnI˫TG x툦^zf[Aԑ2/vGo)|Hrž[Em>/jTS2 x_8 \E>%r 3F IQz#^" ٚáŵT?[s<]eT5rGGumd$\Xvv aѲ|Mq}-5;YՖސa cߒ2^ԡB{GJ@t 3[5^]:ѐߤhIcV޿7a{1Os4K,Ǒ [sζ 9NU~%+R8s县 ӯ4j|HN- ^8;c ps.h;Kjb0jBȱ oL:h /}onWg{DAz "Bԏ`0?H !R"̖n-]/2g/~ŇH7N  kHӾFhLkqva3_]fhEr] X.#Er!)DN].~ƞ*t~* 4}FZ=QlﱓT{n$ժe}7-ެC'v&P2oqG0+Kܥ04-ϩm.ȼӧN)':rőyqp `f|7d7p{;ż uJCԑvM6üa߭/c8/(jǎ%u@WRL?62ߦs%Eo)7*4jYzj/y{ I^q&)Jp #CB>;kiR r paDln &B,D+ >X=Nٍ%ۡv%4߫0!zHKclP sJoK\D3rg}>**A<$8zhز~/N C˞9qzj֍qhWC,h6H1PqPhyQ+7-3=YMNLP) 6Q8\' |, ـQr#Y3q!R´ax%7B/gzZ[m  EDtz~IP-`v{[kdZmF}ned8u32 =H{R_RChrp=s񨳹wŏJZ {#}@:G5s(ai`QҐQtET'}+?6dR>g,UiI-} Ga cVshi'&S3R9ґdH5\sNuG}e T\U9)_rA^Jo_EHć' H+]kE0 DӖ ͎_X^tdCS1<"1Yn|c3gg,Hy/*nfPr X s׍ޣb >R[_wiL /R+m[,( l6z!vYS~!: <yUմ}47\ rBBO%[e)Α3DP1㎂#sÇkЩ4.ފ(x'ƈv7Ak+[!M9,|8KF+!ӢԘr ɍ ѷ\;AsY`m'v2F"D~ړ4\䫺BO&#qy'۴UdId%Go5k2 E&!ʁΤx܉RF۴MmQ&߁ yZ'4f)%7Vf|:LV_U{8gfG늶?zbs!\{;<"gy]u,2˼`KJ  o1+[^tí4ȒY0%3@'Eyw4DGb+W`qj 2U׭C[>B|!qMg0lօ+V͕9qRXâڣ[B_HxiܭTaZo,9XP'`$`sp* |jn @'0 v-wN'J*MbE eXrIciC-H}ՆW`ѱ_]3ײ\XuxiWF]mE $xeX+Z}r)uqiLwڶ6ג"!*lNjjfJ!CO+Bk{X0.´V f24)?+f% oZqHoVQ`V`W?BM‚5{r>eOAw VĚLmY oQQ\dg0~2& .¬#Zru*:rF1:G`&Y3;SYmް.98H]pH(ᕱҁ 粟OH] 5$݌_S}1ǵcmkPdNTfW%ȣmݒ^v$j#C+AR䨤._Y|;mGWcTgW\=N 4Vx"ǥ2ooِ_nrSmQ;h(j0A&%`:,x-r") 0+)|@(}ɩ7}[IuRoHU2"l(ٽ@D<';o~U ^y Q2/33nMްLR>aY[Of\${ͩIS%K-o- FL?Ĝc4rLx9tEV,́-V}jװAʿhWB[@#3i4E<ArPTjsΥYǤy˚APEϋ8tlu%>c#T0N:eO a+/2 3FǛ} ^my %T> tFLLPT"U@Tio?O;[[k3`D{q^P" KA(Є݂ P^ m'>F&5kɌ+1@fkV4Rs򞡡wVDm=k\ggק/fcQ7W;=n#c.#;9Iݪڐhe.lFtb*hAuj`ox#/2g?A`y`j} q,{6zn:qE[_>.r3ΟM*S,3!掠Bg%R^xbz/|opǎTJfq2O.HkxIEYQ*ܬSh\^"R4.xM.ŋɚm3j]8"SȹS{/iŨ$AYl8FqI7?`?W,ݧI7RC;Qp@ +}hլ-98ZrVK!$xxmLuOlB| &4!~;[qEnXx[~ߢPz⊗+vj|8Q)fǛ(yFEp\ ƞG }2LvHmYͣ@mf:E/NFfiwR2oLM~l<>AAb[U0ndz4ǕpB~_ۓڍtw \񂢌|nzː;)%Z7?:Nއq7\#u7!!ƙ"p#?e-Ō顙F/EhmծEĻъ{!ۯ#-BOyH9!ӢZ|b+4ó% :&ѧ5Yߒ _?8A^I4Ǭ^w\}IX֕sU G̸Xy @DB$2AQgc4-X) JR ^:zߓ0 q\54GU@R]nWaA=r~13!50(4&3Uu"Se@M#[/NUТ"}*4l]!dͨe7'9,slkj\LOu; sh2VCfVtֶwe.‹r <-Di%Wd :E," w]({AWŇ]klj;u̽|thHe5xw b=#,/Y~\ kn`6ڢGwfh WsjV!?ZQXrF-;X6&!)8x:m!mviIf}ԉvkk 'H P=,J,%i w0 ַ?v#'($lyfۧ6[BH1q*oY]o]vbCԫ{|@Cs~PvCBd qf-JU! y< NgrL$q,Zwa1шRj)^v \:Uecoi[M1'EtעX%Yh67}Vn.IG˻hL^P c7*<)ܖ L!oƞpe!Gm!+L4{s"9_+54"5>f$+c&Q4˪v<_`<&9> ۣT]]>6 ͕Es6FML{gQ0O_SJ45}>:&7zYYęGcd:^&#.8i.3mٕsD)1g@!{cED$?|.eILl`1S s2gYqhKk%?E!xRT;onGy&)ԃ4ؕ>Q3=M{1N8|}{pE>N:d嘣nW ԑ0c<)teMs{s8*D@$dZEY 9n;:,\'L?Rp u|% Ns+%D1){3fF5s^U c4ahL #~7dnS}[S')h&XŖstil/hȳ!ue lrA-y@KYIDj6h 3vNǮ'G=Qd*p9~kaJU1lI$0 J@&w y!|]9UouIԻ(^>a˹l_XKn] g.$V6>V1NA~ӲRJ"i8-by$ۄYat튎#h_wUZovݡz8ޥ0>UKN3gy6 /x.NzI4w>ǘSgZ M2ʓ[]4%^/;ۉx"{b2/ gf4.Ȧ.`!^J*ƪoހKj^V~<~N)O)sZ?f7EY% ںЈ3k31-Fբm89՝#{5kIC:_|9o}!3UF)` KͯB9' TWJInثxVPJ ñAJ0_hʂ8h7<y֤^ۂƎt(!olD5- WYJ?-!>Z^nyQBY;OG!Ha'O3 E։!SC1ެseBn)ʈVW!Vv:-f3Ph?a?{~4XT=x2v֣BE/zj= 53\ITrp]ݵ5XE>\wp_G; N* ʪb@WO  "Ȑw@|V ':e[ErAeh[{]LZEw%,Xt5iK[b; r'lXkl ^u:7\,&֌Q JtDeH*eO}>]ikfIUZAYOdSh&`rzQ뒹VAnp_)j(ZL]5Xz.'PPzyNO:O\<@y2 ]d:ws@ 6W3%T h@G~2x0GG: ٰ׳e) 3B-lyYk X,Xyv.{R$",^wĚ\ӷbUuUcc2݂gX.?ۀF? 'I{Q&G1*4찏¿QضFpM%εROG"QF\pr8k.B_c%aƬr1KWl"Հf>~i#Hz/-Cd`Aă[z T*ok6ѐQlshHS@-N["bƎHNr2OAˉL-*BZʾHV2rm7sQ>ܥn ez$$@qؔLƘYCWR!?$fr pld<'(ȳ(_߄*0ƌݍ|~fmGԹ9! kb)X0}0Xo 3<(rqP bNV20*WBx~EX9wGAE@Hd^x.:&wBns3V\n z;C!Uِ$Lpk[g/J&WP9.ϵcK  09fe(hxMԶJqJYk~ C_=FN MUJPEuίa& N8y^gu(#_FKys$R(lg]s2_e¢[D%Z %U㼃.sj>D(ؗn:8:@ׂdh@ˮ>Obnd3(7o^Z>rZJ} 7=w]5A`N^μ; jLr+ڙ%*hVZ_$u?5`9P~9St,=9jʻSyô6{.F!H*E?^ im${YE"V H 0EH#@ЀAt+-YHp{US* R-H1/I%[pnzB>k*)V37(SG!]h6E9$T{M "i:,0wH [8SkrNGW:Vc㶗kn MY'x@.ݠ,1ȅDzDVxj0 /}{tQ\mSTc-#tZp26O ]g.Aw!Ք 5mz-cCمR5+/:ˆ4^<3Q3ڜ%FSL. OhXVQZZ!J!%;QYuNMd ( #yfY;O|xT/KXD;^MF#'ISc8rݭ15g/;C b&YX~jۄ;8= a4xHHhE1<xsJy27$!#-H$+$;86F|7/אk}\|l$_ ʒaG tI _[e;=W&x@qk4]@s,19pH5h>PgddXBg2c;p}kfj6 /)Q\PdD,u%[JmyPU,~Īf`9d[zpx_\8zwZy)55ѽW4q.`W}GQ'\h9{i5:ue$'VQ D NH<hW`}8vB +)>$ Sy^n]4 :NBlQvkIEҵ&y<3{!Rd68\C M[ko8׏agpZ`hɔ'bOstḻzBUuuG ؈\"&N?)b#C+7r^] SEL>MQ.X ȁVf⚣sH97alt_GEEқf\9~ocR硌A',ME?N^f|W nZzWFwbeGz7=E<7Lq6{קq D}$Ũ5[nݱQ"vf(ɾBJ$/2ŷ^(9J}rt&+3d3xlɲxhp%9άEq:0_ =_~&4l;.!E ͪmhPUdƦ]D<9o\8ȕ}Юd .9lbc-UJr yN^ K>!ְW+([_Fv "R>\6@zXq IOFdٔgM.29:69B" bI8^΋O$a!={gb#~BÍMäR6x.MHeڒW(f J.=!%d潘IItEbx2X Xf}L|I$ U9?9Nl_~b_?$>0SWU'r'5Z`5Zvoo2)x́҄6u@Jy;~Ŋz+^]ElR ^rf0aNS`ՒPu #W/^i#"]"uV@/ `9djq9I+dPdJY 1gT`UDQJ 0JV;fyGŖ1}C8xNRrCT |"r4JY?Um,4GWsIvW]_G`eeȰ9ά5 M9D FgS㧏{}Kjw˟΀<Cۑdğň1E.i]֟-!I.q*mm#lg MC(=o?e%8q`FHcD'8﹮ v<%Iɚ'=G4 8hIv+ 5JHI&^{<֭$> H(L[S:Zcj֜H=vciF#sw%ea6C qc,>LQyRrv֣r={|5z0Q:NX DRs"-άے0`,@)͇DƪT$Xnu4d:0D7ڌb Ё9)piźrveiHtAѹ[4RKSCM%HEv<@> CH޷9Dh$ jӨz2ySv5}Ps)/#wYZ.šr_[۾X6{\8C+aԇ_>a6~ kmY[k5b1sd j̆ʭJtu;7V$jĨ&Շj)S̿y*:_X"R-uCR6)g%7\2FTvoO!E"zgx'Q?LRHZY[Y?֗Q/rdI;j6(bKYr0MQ-_r#1R3K7EYdǓv|5JkƽeϖI3U`ĵ 6kAfBx7:]?RЛŧs޿P)G[ FMZp'u%T4~g*h+tK::s*1=_+w]tdET'g*S)QE aO!Hi.5Kq}F$Q^ռbJUx0O(tTֵgd8=~6ud >qnnO/ J+px?xKl/X5/V>l75ciZ-ž]}.=,56'D{VFZ|`<˒JhʼnԿ94$,m 97uV:m.%O[ӤFUgo^RbN l0`fyVQ>pk{^Q2t͛$4\vÈCB봴\(ⓗ{C!fgҺghRpFA`dPGD.Z=z,ܮwmR [)BAum~9QcKVM/$z)O8)@vRzg[i54܄W*:)H4>G4$DPK;'YL+Ȱ47{a\vOk#krie-8Ɛ]Hcuh6f)]ηD,n ~ur,SrB+XՕC̏g6 x}sfUV 12 C#0:`ԦY;-zpC޾ׇI2+ wE}UsU6wD~ByO,v~=fܳLOy-1X/]ct#KP4 T_էb k l堺lr>$ >-D9ɡ1Oϫ5sb]ԑ^ H & LƊ+ AӤ.|'1}9F^2@J0@W+fܶt嘨X)Fv 6(oD5. b#oKKS0VPjqǏD}4lX%+9] p!/hBYoBBk2Cyx3kegHe{m[l;_OZ42 O&+ ;O&_>zu% F'A 0a XہD6P<0).ҭ,gYJUg%YD\kO=a,?hi+$({rnٮ 7ͽg*P;¦t;K}x]罃zѻ߭!\i;` K^ho߈sК72Yd0p@@m9#,n^/Bd>tG8](:l@J4ls}N M#ޞe%cw[ DÒ- ~#3@b>N_LjJ=Ea|Kgw%H%e5D[MC0Qh*e?[H<,z\[M\Ie{~Af2' >,$ךavVωÕ@ #t6%|^#E*KO|@wN^߅YA =/OhoPe["ւ-.jڈRdZY;r_7wj&|=M~ NXC)Iیrʝ +u(<;F- X:rai8o'-*4i)9ΎWn! ߶"k/ w=(;'>sK%L^* ܚG"wX*(S'˿n)(vZv$\sl (y$q9 C3g~BAxϕ7Us^}rxA˕ .dGOmb`>`$(gX8 ߙivUcJbκO ںRʃ`cu+FޝL43 hƼ,N'~wE3q2a>Nt;A>(rqاtج^ IIM'q*u=5 $#ڲĐ}:oKqDobdeMTYwކ _|p2. Yfmr#?(;.=["u)7=ѡH5{u'B:8l&$! 5e*y SN¹oTXJfS2 ;UCuBpYQNl'66E^,`U_d1<q-[sȴ;G5)C9#!2n{jl}@O PM(5SmC2G_u6kbǖ29]נE:ԀJZ\-8&Myrl[ؤsCHAY˄G4JR-9ڌ#NFsӲLHܫ@IevT0O`?׊Ϥ+/^'Tvc/8@.w Hc0-)$G5*-D>+wßU> ϔ$F**XeE3zH02Cc31j@b%BhHƬ_ Qhw`NwwΙ{./?).RUX%cQZ?Vis|c Iů`.遰P>DV=d~\ 㻖U7zm?տ|ڄ-#=Es]dErE_- Ay ] =^ҿ$#(PmBneʫ~7zI^r a\VVR"b``' Z\,>SPr%4)nB\2RD9:s1/QQoQyGE~էpw1b(į> OX`,5͡c&Q)T_ak6OZ_8 )KF%;;4ϐMurn+Ӳx`"gkky-|V㮋ׇoE6`뮈ҐYPOԱ-\%Kx"ԻDGXyr R]˖\LtmĸG۞]s\asI5;PAV-R,[LW 8"wKi&a#pGSey H+s =LxiϿ;=PI X:0c;|(J{ůOi Gz[l)&"tify}#)lTJEw^zE4(ZKh 3;3)mg?;cuK POڦEek1ЄE^]A3FœrMZ/ wLHrАruw;\ V?-1Y=]VЎڃv۬5'Ո A?\F@j/䈜̼Nj3%\{:MZ 3P -!)l晛TW[b63=,A @ Lf: Wh{G深IC.10ԑa Wr!``E idn,s$8M10DɹȷdcezJu~`ENT$?_D⨘rCFI;?, Ym%PV] +<96NRex;E]0򷁥Ip(6l͙ԝ<`3Kp&4]3 bAƵVf Y۩.WCY:c;.k XK6]-)RWX&0Ecc~i+[$.P$^|l5阸Wz+xlunfARG#{%:ĮJ筹`D0ɿşn"}3\8I O9dѷC„5#L{' Ls`X̄u bf&IAԇG x(fW'{WAc67<ٵg) 7Ő Y{MFɟ ZEbdu[r(#YL>Hiuww.hЌd9mt:9UrP,Z1A@imdqN(45"Vm Sitk kis!Kh!k^=_Xڑ7 Z'/%t 댵-GLU6ט;6lמiS3)1'#9j![J}̷`^{w/J\3Hr~-,4i@>1U5_<g*xݧWmztgFuoxh80pЧNg-oQNm.h:z,,^m:G*ňIrN񴍕;_gy>= $ls!9!P $&q|:"-wmf)w9đp{%pmZER8&1PFg 47t!6j&Վu^W*~671}+RmOnL8g Vă,5h) z1e+F`c%i YhVV$E/CL0p#P6жtt);E\UTaӴL@R2 `þu)g*`ȵqx;#YUYT5QI *rJdo!ϗl5Y1$v1 ,f@]E|'l5(N>LMM&5CmeVޕIfFE艈@] ƃzN n褞J"*mOj`քW%3OpmPd\@JnH**THZ)?`? k,,VЕç[la5&ۅ%LwK>*6F;ipG*f)r|CbΉF%fOГx" '( Hཡꭹ3]M0A%|!ե1^}d\MWN3o77+ g"%Et4AW`އMәES)1zVjKg\/qʭ_GHuiXu?|#fS-WWCم)ޑ'jm_5UREP>K/#:o"/^$ - { p{!,*VsjUA<ӹ Σ&gՌ@@?hOQz:w*NK;+ 1a)>g;U+-ui_QbV8*im,_=I:MNB%/{9Pz[ t8Yd 4Ĕjb^!ƠF' e<#w ʬPvP 3R W6 Uĵ,&81x&jN_ :{~/zG0Ӫct/לQw+ aWHS6k,q.3*-0n PjuKt]٣)fm߲-AvHEIV 3R&.QbC%j_zW%9UHp5&bƾ':B8@?*rQٵ{K+rVn7i%)*iܑA,3]p}|%[\% C 🹈p7}6Z v[I2_i#XXڳ'&GC[떜>UUB!Hcڰp4P nL[)X hLߐXa@"C9٧޻s d/ZTL djLH^ޭ-7=O)v (o!ppʻ)5%s Ɏ^X+hcz\:1ΣR몄]" \S;1c.L[i*ӅSR u\yl)U&ҹh"P)yU?AWFmLPAkᕋ+ :p5zJ oQPḳ%; xi% 6 .}k5C)(̘iwt᧓7#ew\*| ^@W]c=!_ɕ;zz޼,Y@Ѫ{b𓨥<`J@_4.LۜjjbeEDToށ>B<ݔT#(nTOiEܳ(Eaj"<HdltTzܣ-#U6 'X֭(Q_P# ^tA'Js8!4D$3HUEpdr'OMU"΋'f,DžN1$IÔ3gs|21#pe/RƋ4wђ2VY=Q96˕pg۱|h6`NuIζMyRb#MIWgb)$_Is!#*]==9Zϳ)ikbNPLLMVS9n/ TπJa2| ei(t'ˈD!fɿ<\ "2JRNcWFECVrf#CzHekЄCpak)lra,0;LV;H9A&$J ɶ7X8`9[^ |2z{ic;;"^T ?>`:ůƑW1r1&t_}ã̈Vi hx;2-U?@Pk2pew-wK"FV Ip-.g}=y{ Z [JeM_L*Aмhg#3Ҍ0laVt4ۄ2_ÄbBw#A2I0>y$ JfLGLIM>?7װ,mI^tdad)?ٞ OUl.0`d8 yHYfvtq~loӵH۸I"Zjڀ"R 43- eoH-ya/-t8KucW/Qij汈I#hshRmepW9.'}9|u>8ܻ{pr`:WN"@4qTc5 XLg{b3t̢? 7 /~8ڸcbIg*\Y]nnPPxlhgG]kO!Iq6+"2 sϹr]?S@{*ҘDR{+ s ylU~ Ud'$)Ch$Ng´[\+rUWU&:(Pَ֕DԨ::" 8gRv ).Zޮ?ӔgѾ@nH1wʆ 4I̼xMls~T’>LSe9Gũ^ʜg/ үRAОeЉ[#_@z^w|]i4V|Ie6BȚ&(>eSV8Ⱦa89lHaFYf3Fx\"? "#K8>rO|D{ | )AXwzG.~Ft5I¡HZ"# gu?rc0R4v+o8ۚaAaeh\ O% s}]a|{|mzfU,/56vw`Sn^(Vi0?V3!D ܃ي @4ggd(YDNa<|0Y wRzVYC R=)gεBʖ ƃlAPMVa \VT]Aj#UU|&R3n=OhoҰ-ŗ.s~/Kds<qVBj}mo~³r1[Ƅ DXtڃnē_Tuvl.+m 0{we n0%14#2nF.]V7߿8|dL l!ji%ѱǛ*Sn 9ifj3eb,^!$LΞư`7]BɰLAP^SLnb/^zRK]"jh2I++>} )QoI/cݭ9;*6 =1|19:D9hrW{ҞńT]?,$#Dm$DOݢKZm) (ny +us…&" ¦ 'Ut_[UJjpk)cqەN~yjD,;VՒ.x[mT d@nћ_P]2u</@V: CZvt3:WNj(y6n9%M`Ti6l/㉣'A)f\/"%kGȰt#RjvXCݰluTP8S>u#k_zBލz_o|VguWP"=ewMW䜉=ƓΟGrv?.TV4c]\{D*;q3&JWﰓ7pT H'OhjQ 50/>vaG>vTn' S|b81beB XrJ/(޽_')4/AhBOW%݅*_"܎/Q4N6 7>U`{ X">Q᮱fM(*.I2ck9?%L[&dV';{NV#OnثK!!$Pc 85<(]ڜZAy,3lw!GNYb^861h[^%g}[R nÊx7Fp ,irWCGomYSڵ|gVσʇ0k~TӃE I4kFȱ^x&&0vcx P}^32pPxOd9P-#ws%l ~d\IaK3^x`|&duRq<- D5AT{4m/YI ( g6lBG]Ys2MSwa`Cj߅ڦNp6I+[-d]t@-3{dykLל 1[5?Pڥ1SΠFA}{*VZENOx Еs3D@.aN "Iy(g1ꀳR;_@#Aiڒ*û;rz"I`݂dg) xj\l'[lv<1U$Og=N"K ptڔ| 'z.ꀾG8Wc`u!r?'3kT@zBW̏GVY*LDf^ QASv_% p7 yy iɹQNclMwrQ3ѝȽ47ۊ11ᨪ`!^y?A`)G3n+“-. ہb&iBufG!J\Mᕝ[x:>?eW5d8Н#K'5`YB#$~TA~z9x[LĬhO~z-+Suе& H>lpJ1S6 {4JKuo!,"h3m@,6W {SYF@U-5kHZZ=DGC=F/g9ba[DKq2dly4IxF\y!F Ҧ~6{,`P_mi}ToRQ%ral^x9>7̨V'Oǒρ,"<1"THL REWW=!@(_ c%=A@ȼ"U[/ h5̈́(%M%^qX9f>` mg2mr 1X3qφ +tMOU)y]05.J0C8 .(r )>U|8 TR!D߶?VeZE4Em\>9m:7"u; pJ4q.EtM3o<RiyI8Wb(dSP_;;ޅRt[Fo=u3,qkXra~Cm0ԁ)n^=ST:z :~im;g=A;ɦ#s5Ct.ũ,Ȁ =b\c>.~73='JPv'6}bC d86 &t]S6M˶qW*B^2K-HWA ؃E@.̒KcW ;5N\1IeKP+ꮬv̞UŖy /N& WQ8 M.To!PD{]""ܧ$%FpVj|{VplOx]0,bJ[9 Mqk&F)4¦AW ,c|E{N*v?/U4Ӟ^\I9 zǴU]bB B !dn 촛VDzB װZF/_`0xrF3CH)1Ҝ^3_?M9UDp)e" d cn5Vc5m*V*Mg#h8p*z/e %R',Kws!KD3;r6dxe.^&ՊZ;Y+/>BDk ض{VPVw=cFRM)W-4pW"CqЬ\N/u3{z5_fŐ`F'qA#GʎezU21M]ZۉOG LPFkviT /$(pasl Z+uO7{mo|D]:7~L]I 9? '7}FAY>u Q'm xJL[@6JB>ڑيGPUsyBЛް$OTV᫞EIeaD/c(%kPBx'ĿOA[ y#[zGcĐGvs~jQI֜l? oW*>M\'"Gո(kE_`Հ̿N؊6 N J[.㓜=J;H>i?(Ļ=.6Zr4FW\2b4.=+o8Fg_a2vb-=_Hiu$lY1%#ix'dzhfĺeOx '!Ma-3ao,(Ry&}*Get>5K1%_m Z\5A|,L޵53E R7.sXΉ,M8/㔠o%PAg0[AZ4WC6zf gGuB) י6J?~ϴCX`(w!o 1FgX* mb !VH~[2 HJ0DM5$5MSf7bsSnj)|P8AbprWm! nG蠌!_ٵ:},65 k ^Yat('7[5h*&:cb~Bھs~ŗVW3eo:văGvݰ}^ߧMO1B %}3){][\[wIrP7!>{"$L_BƯ&dfǤR:Đ;!) W۩ Lj?<)^†nXe\q5xC޵z:|Зn':!/o#̀3S8S_ċ ^":nTnRﺾBSA~+`#ʷڪ-L-S_rLp =bDiN`r)m[+R&t(^MZu +]Lcp9`Լ)ù )m4Ƌ*ȃ=s0"z&׌Q>rAc2-$!ݦ]cgkbnKfD/o4wDz*9aMNa3Py 'HPG*Wx&sɛ^/&Hux,R?sh7(_^&R Gy?wⷶ a/pgr~@{sK^O`-Gk@TdHK9t5Qsjjsz /ћHd{9^ˏ);:7uzQ弶#>njݧXJF>7cmB”5.<=?n=&x5p1j^s֠%VO͞ޗ1j=Y̫{X`zЈ$4<}k{x %rn4D<yGbظ#V\G(q9+fCGଚvI:)L|c," 9јmK\. l<)FLL4EPO vr@>V՞vAp Ö>&+ ͻpĘ`Z YoѵV|Sud2x|%-Ѹ r֧?L嫝OM21Z*©&G# 8tC>ү4AgV6?NP%~+WZ4)v%tL=gGρӞ>EV igRHo٥ 8 ݅hZGCY5o=D˽Vz ²D#-pxB {sGMU~b!Jax^Cs3FNcK«w!T_h4,a#\}r?W_`lU?&/_ v 7F ܒgid$*VJ4sNn8\wxD{r(yWfGش*_6wH\UKFKAi`lF-/F5Yܴ#(k~\]PFs~rִ6YI:bB#*S2d a^%C/uAX7nu^gB/zhtP5SKp=|6+w. =l,_^(wmgdʲ9֟sҌ!N 12b3WmuHP)͒;R2œ &8L$'Lܡ] & 18,:PN Y;{ pcGt vO 1RH>8K,oRi$}FEV#aTg_U)u2t[6ؤպõr 9e9bk0FVOrc"aE[HOo?bqrws@ҹ,zvl JEKΫͼQ$a!6 o}ԦD'(yaÆ0re-s:i4q0$!*O$^G|@`o>4`(<`GG]M q Qb@=Mk DHJޱ NumBK_ΦꢊN|E[ޢ>vg[ 9QE]"5 ̼T)QfˤX22jĆ=MN6mRFi ^7QdxK#OQdfh|?*Cm5M1.?@( 2wvJx|:X?_"hklu/s|~~ލy0p"6 _&sL;@.}"AnRsd5ݳۥM|Hkk O?Y2h?g\wyefRQ$E}Y\hϰ=c$u3' \5Ѧ'MSl ,]mQy΃3l\*zFr$$X&Y*~Iڐl8a"s÷ hv>zK] P:u~IA/ΌwF#)%Π!'Qh&"0v5y!*Yag޷פYTT.ݥntoFCڞCLDMñGgivM~#ZuWZ4iRj pdu\,uٺnS}{֗A͒A+u*Ӳcx<,qW;1 o`5Q D8&^6ߦ7p(r2zFXΚτ(U4MI}ȺAU: (#v" *w3(75@Wo}Lv K"℡L^+ MaSS,kL:> !t4]ڵ I{zI*` $V\9}Wlx?쬈Q7WIJt1=|hF,M^Xb`6=\9*c ǥ0 ]'6:SHcHVB$yz*2ºH @&Y짾]wpTU^HB& kF4[p >ٹe?%Bzϲq3Ix#I٢gLଊ)!~ahjR%0W\)YؖF=(YWf/wKNk2E-Y͕Ҷ>W(7iÐC(6ׄ$c /#S<9RgulXe4ăQr3X {Jd詘.2?TP"\ElEB[C"3}T>#fWm7eqtn>I h|NFb=Y(j9@ kjipy34_+UԬq&v~/CI3_XgiCs)WGFIWt|N6}wT& HKn0qz!TVOŵ6gw#hՑ{ .r\唇qMLJٌf>Th}MxOκ`So~"2Gj_Jv32, %4Kmi+Wdj¢}LP^ͮi6bQ;{k`a'7<&܂ ^xovT0~9ui;܏пBHvI{SkhAנ@"NTEÉJK P|U.WU"^fƹw(]߅mد#7)7W_~M 5̝kW2gxw3E$p3$1!4+Wkjgb tO0y)x]tR^<i. R);Y M4@ߎP#O^vk A5<@"`E"^}(Ydޑ$i),iṅDgHt2~Dtp`d'ćɆY>)ZQҀnJfu99jZIEН/Hq"[JY LVC1A@ O=HM6i9k!&b9ޜѝr"vL[}L9* ('@ukgr yar #o@24hWQEJ+r /pϚN?:<,\k94dhgYR X!Yq:i)& ;U 4ʎ% 't 8ɿkxANx`%+ktmyuE/lH|eJհC +؀Oz ьZ(=]>F ?;'9rzÚ)uWvwtc qU VHZc>3-;Qǡڰ70m ti̘OB3Ski.<u1fEjX_Aj;cKkVd=k!8, +'3'th97;u m-Z:)˞_[o [nŚ d+nMݿ~Ȣ Tk%c1~Iv4fcYX @hc)ڐYXQN8Y8XI@%p6ELD]f-V0oMLA.@U$/Y Y+ԥ0VpIp/i1nSlfX(sRKT8)e .ʃsp++{Ķ!8kѶ!ϫY 47IY}`G:OPKkY%!8|PJey7L  BhuoB0؀mk@]9bOSHqvE+)+C4Z)&dt8Au@$mp2kSxQYYKaDʥׯpR؉0wseVmmoY{zz")vok'"<%汿 GNYəoG>:6Հ_NDc9XC~a6MJc4oDu hRH>Kiɫe-{{!RO6F%xRGJ:j&x ĵB&?!MB̲v]SSn-M݃_O-XƞNoUw^AKPHFJouNf۔.eV&EXǧGv>E_i H;xF3q@[:5A8]{oH5du'p 6̆U`iӥBI޷4@̉&u5Ϳ.5A{AGѴo)5ZQ 5f߁#]*Fu|<bQ27Dݲ$dvU}]6t pi)HKLJ¸^B7YHfkΟ?9s@_9 $]C=I>? ~ӳ,4msKP &@^D{-N~,`X #oUQ=H[lm 0V>sׯc5`Goi)T0tIakLV d.+V[ߔf6Äv= LɳnjcǥFX`U䬑 @Ї.w,U1zMo,GyRCi\X# R"&آ.-ku1eXZxl202EU:\բnStۧh!۠D'sR@uLD@AB S4{]ДO/v42IFh&Hh& |}JXUݺ %qIĿ_6<Ѝ}.jdž-σS>T v dݸ~~ Rk{e-oD;*3OV (9&z61HMK;(+B'\4)mnL\_㛢ۦ*JqUXud rZ,[O@0Nڽߍ#Mі{;ANBFGbx۶\APP0Ka,gQjɎ<6߿~'ra 2x#wWa|'5`a}:D(}ʨΡd?}c)41v Q4ں*L$%snڥjI:M~xۈ*zE4X)pdO[?QV--&2kstCbs$RL>ΗD[2z>o^Qjlw( {%I=;e|9K{ {& eC1?Zbm !|$}3X;q9u\~Md CsB#Mkmg-L#fd=g"϶6Jjl)=ysrB-dk!␖`n5/5O"kVfcYZK>LCJ -tzt\NL+f,8]ЯZ4fLWIԱd]q nBx2-FJڇ@QVge|֛8E2R,'5O{2WLw8r9grr79%1= =!G#RDzi%1IEfAiH\yThwP %,D>QWƭ"Yq W}I1T1O [U`kaIj!PoGfYpi g`0z|UV-U8Z1QS0 JiySɝyy|el݌EAL)jø7XzDpMqG8VGst\uԄ(|&[:0~B f1{+#yO  8P׉$)k Ѭd նL"艁4}* pnKކiky^V#B4 NcvRz (m>)- vMX{G1JJEv@#;=[L*,XEHD[NB jlU4f.\P@5.cq.)9=`땀3ݚpT&3^nɞ-{'ճհʱsGqi jQK$Cۘ@XՐʆt}4/mjXAY.zOM'DR$v ?-B$; ؤ>,:Z۽*?f|TJ Te\ S*;).O9`e6-jzk3H5TUP󚔹0̍X_`~P2r5a`4/c\+ļyVsL+~q ɽC]ug%@br|/|x3q@"ܚ?X3|}M*| |k3^ucuؐY)!d):VCR2&O,OD6؜Np0ż1XYKZ.b "lnjTւq>iv8a`-x)ʈvK#n䜙llɥZJLKC)xN\r"^!'nY+(3 ̖'ZVEpfnWͱMʴcF }e5(D V)lr ~|<>wp>w ^sժD*ŻTY.KB)Sy&%S_,-&9U[?̖ߨ GG[\16?OLPݸ&_䩐מ^UA<mS^w-6I45xJA4\ϏIhȯb֫3'Ba+R bB>BWLLzkS?N?O/*QL $N1fXy\F4Dיm(cx*2Gy\A 7z% *&ꃍ:뽶E}P±*}Xj)&\P'+[zJ4]ޞB "gŹvAݘݮ4+ĊWPN B:ϰ`/^9h$0 96N|)Bƭ\BRB>[*~n|+NOCG M {ͫPW p5_9g:c6[MZfч{Tw/Ļ&vJ3c:|%?T4_Q;oVN-ԋC =K}ǿ? &?+Ъ{MC媜Q~Ad`ȥiV9XzknަFxCwj8]uE9q8ĽHbN;EıƏd)#rar(' '17 * k'CIXfHQZ$,0ǬOn|R6ܔYncO!tFL"l-Lmq?H5ѰB&ڙ2}O [}BJ"2rgXR+k;9S7vc)h<)SʗݯYͻjlgl)O)~N&Fm93pFr+ Z C6W|e=CO ڶPhq,jʀ Oݰ[vjJ%V/ pU-4WeOEE#,:(h-K)>H75Ƹi%5Wbuȗs*rjŗV3OGeZ/y׆DD- ?ef2`b-G˧AV\nKNxϙd0w[ vHv.n [:hKOu`X,dF * $UދJdu f/:YToJLwؕv!Yl_}6E樏U&_~h35]4%=[u ٨ߠ[ñy!O H$U9$( "s_` ߏJ)})gQUWI?~#h|d\$4^| DԝMZ&3I Rz~5y 8I8s9K:Q R5q@#mCT:Hj;򺑖n?yu Lv pF{(e0tmABb'_Ur){GlX+'W&X j덻ՙqH;m=DegY-:wU0T1RSq^Z ]+j| Y/gwAQ &u"Bm'{UTgd?f>FenGLFW:5 (ӢրQn+MLp  $"<^C Vya}yLP{%4hFOhd1 >Aw؉k'PeY,: -*ö11B$WGqCBbk ϞTr8P3P8ː[3{PP%YE]Cb[W~`6j΅r9Pff3>FlOsL;ҌJq"7s}a=_y9 Ĝ\~,1fSɠYz" ,eÀ=:*26=ߎ5@-أLy!]Qf"0+Kz `:}c9K8\ iW+%&Âe_3w{$Y4 K zIx.g ;Y>t '?{ #̠se(9 &U|˒oFTca/{)LZsS*zxR~f1C(K^urGq| ;.6ep!7VZޜ0$ϵ5Ύ_i;#]x<9*A8YY:Oa|.h.6HTY2򼸕M3OjI"ճi 9>3bynDkQzcĩ$uڲOpә&A,DV$b1HI!t8;0E0d(LznE N$+dSDBۑPn# 5\ oX ~FN05Ԓ`%H"NgI_$do!-p65(wǮ8bޝg=}SVw4}*cAHqκ'9(T#`%zj[ڱ P^R(iI}J"3&@V섵~<6LbM'<"{K9)H?) $*cNƏ9C=/&*_ihUhS-70#AB``ô"jV׈`Ms5LKm]! J3ދb3&ޮ/nxd0U"S]wY̱Fy9 (Tɥ*;:IE/P55 viEЯeӰ-% cJY}shs1 H4Sքsn{f[W[Q/Z$T(N6F%n t[Nb*~$ȰlS4`CK(r[sWVҶxX1g|Iͤ*UD px :Ә]B ~\"Sq-(#s >9 RɼrD+v!B!^#dx&2[$P/J-IgM{E BQ]tKǖxY=k #{3uϵX*ob]qdi~ďkB^Tӗ= ~'*PiK/ CGidSmCgo:a@o(G11 q(/?)S'QN1^ZE@ raEi{E} L ŃoB$kvP`tsDP<(yR?QK)tujU7eh'T&_cWvq4`lN2x'|[)BsuD&T%Hm2j⺗,wZ;&nQHdXS4B`Lծ/my\* ܮQs3Y nΕc ]X#$m0u-ƚhH̟5 .VJ>)*l:trG\r.Q[nE`ESSe,&vչHy6礚^pG虵x0! yMFi~8bŌ'n+H,g{Z"RrFqS| п .T'8=6zG'˻Cw.:^r,3 DeR8@=fiA9E F86 iD?9/_.^bCc9IQFaVC,r9x o6dZ|\f]OnEbFN+^HI^Q Uwgo*, b^B\D;6u~PqB,N6j@I;_LJ $7BK-Vcrո 0iCW# ZMq<][JڼE$v{v ].n2thfw)+`IC~Ń>RTb}Գ\D 8Ku59ºnߺrRhՒ`#E#H$ <<8L(;CŀZvL(R;~ChR/oąJ`>G^L \J@CG "`njLd`tDnjG0~HѼ[Ov;ѳ`Dkk/Bb?vڤZqA| Hj1Neh ru$_ͷ-꼕"DP!v̫pIRؾ-dP?BgH?!EfnLh.]rf܌LbcZb-ŒMv_x6ܑle[IZaY4ިD~%uQhة B*ڧCB%ۖ4E34E][Î^dxUG!lD2E dD~H*GL$hqvVSՏ{(Jg7\@e3IDgUu8Z%j ;h0W{Z|C $[8ZJV<1EF NΕC۲L% TpQ#xwR<ۓ[$QY1ȅl6^HMnsz{;^4z9Zf>k__&&gn!Obx>`M_CeR@@mBm 4k'5 X6 w~I P+٩]I/EДAi/Z"Jv"w v ˭^qJCwͨRCujgQƒY~y&wA2_ۉFK/@տ8:%d\֘b4A]"OCq1Bi-0Z)GVKOx񙧩:h+&KaʦM`9@qoNbzzS{ΨQg[ {PVbGǐ1S[uUUqqcvv&jT8/|,`~H_°yMWb`\:,+3fN3K/~$ $Q?[0<|7g)Ch6mrH<$Q  ns1WmC@aY6R+5y⠖$@=3C n5| lS=J:730\~CڡlOPp&Dž~o{XLP`-ggQ*CɄ/NY [!f}tDcR~(MlRU^)`S/٭(rZZ>xUnV4>Ҥ<)w6޺ @O Wne2Ҏy*2E*b9a.?Q?%WbS!OȮ{}Kƃ=B~>=qtT PMJu]rG?- 8NSďUG%*>.RU-1[y97v2A9U~纕e,35)NP lI0RHwrr6q\rc!PTAMliq'¿_SdΈsI+8DR7_rл}PM' +e я[d,SbK/nҗO2SZj:b~Ey|9~m:G3߹HmO4d_ xGNkՆqC8WI0j7Vp](Bҹ!RBT@(Ԟђ5+Sؙvnټg"ݞ0zRh=y+Hڷeە\E,ZYIH :w7ο= 8Xu}k06K0_.#3ެN"`u֑1( y^ *F:JbiWd=>Eg/@r 'ױUcL;9bV@]" (缥2ۗU#l"|x~nnܟ FfLnG5XLJ]#x'Hoݣt#b*c,rYK 4ݜ3%uX|(% 3Q4NAe7-L~M1!]cNxf/h2G]SPBhnf{ۉ. a3^%Hx()ر>oc{Wx`_%F6{y#A3ѳRɾ[z6n-SR\(=dHgN_4/jrn9isӘ }kpTdX7Ci='Zc.f?:W SlcGvNǯ|;GzQ0g,զrB%`/L-v FӘλWϧ] F VBZѢ4q_`T~eҗnD=f.`Ԇj2߯:J ֝h[:SPbQZ {51ӗN F-2凥z$E^% ̫}C7Y*p Ux П s"6`$ST#mV>Etyw"LO'P?#>,;π$>ٵ1NI hSI&m3oQNIٲ#>Yp~|MA sʲLA55Uq^e5c"~ݨcyۉv4WhZ"b$A9@d 7 Fķk"\ 9ҟK*oJp\ hR0(^-@hBѪ,"g_nҚ[bUR΢4U _#ZI>F EV;pY_h]gKL j[J6ЊpfD˫]5a& "VW$Tm<;C-+@~@#AUj`zbpUl/) ~ \#RJDp|Y>x&rD^[ybDǁ}h1~UjJ:,}6\$ebyB\/c&>{LUP$e-Z읒>c& G(Zr &?dܕ__SPl(iET V9= Wd5\bo]=¼y;*bB.g?tr#N x`Qm"Pǜa%E &L]ĖlD)q̪ e>!ĈWB䷣iEp 79C͍FS߃@X`1<}tE HC q5.Z~h(OĎ`q=`\]*9~{`y8a AG'LK55H|YTE9}#H m=U>Ko씃L9uݸyô[d{=#[a w` t%7^JWFЫ`lwk!)Fd~sGw;Psp%PXRGR`FEYS+@*m&uπ~wpPNu>禤Kd% 퐊j vo1v|]Mr3, 1}A[zv~+k  -$a+8eNT&(NǑOΌ餦;06LF J{6:EKRe:NMiƽ@~ථOOq2:Lz gq ).|\V$mXTR7Dk5a{?* cDpf-^6V!n5 ~2-,U~$69_0I"S ⦅4RGdO`,Z|NYs]Њ1_ K#swdFwR< : EDL 5Xev Yƍ!v,X^l. r8{.*խ|m#1 ?z'Yt.3^ipevmo ZO!g7wu!ao~lV;XY յ"ØLco"s3@֤!|嵦bUJLg[5ܵ>]t|T ,;PħZR0y5bRoۧ(M`Ov=P̣{Q LTsɥ1( jICnj`J\pzmbةZG}c_Y\`FDt]; YuZ5ClX2Rg}pQ9O咱'=gy H20u& m' 磨ot)L9PՠK3 cn]Coj6-n!К9@!i!#f1[iʜi"Z3}*.2Q0x mhK>+8Msq0ofz#~ ۏ 2B^z/9 b#Qօx" H}T;WZrGyA ,H#]xn< uinQ;ߨ-nXzqtXzZ<`0=TXNݔl뼫N RK)V+7scFh\g]$AwjV&VA]N Bw!Yn%XQ{VD]>|)!u[&C{Flw5k z'5L{pr@B$شrwxxz_h^-LuemV DN&kjj_/y81P&uT6nJX*\־2)f<[ Klgv"ZB^Q"+SK7L}˻GT9QuQݛa1wg.A+kv?{o#Wz6hMmֹc7)TEF#Ϛl&PWJJč['~%Nc Z^}R1dw t \Ѻ9$t*stca,?ܝHٍeGaJ$p=0-ʁbUe'*ӓ"wK!X(;5aywmą[./<:č\&fY1,Ǻ:w5ܨzmeJsm}ڃ>#V<jC7m[.g,PwUӪaJD cNιT6gr,*JGNㅗPn/Ha@%RRZ0aH-. bAM1-f:D<2$e9$yRܚf*KW ,e^*S24ɠ@'ѝmeM1)k9d#<pT6P-dtG{XY֙ru" ^H>/$q@מ2(VD8ī#S<#Tpeo@X=*޾4qa`U9*s@3U?'yUe.kqg:ٯ>^&@CΨUdyM[kC vǜ7jwohF<0 "&b-)49IwS9f>,I[) ??~'dJˬ*>(*5Vϓ1N!nsƉcΎ@?8w'tm|.FNt2B믭 Hne7G։b.NuðkƠ4Go5Jk#Ƚy2ECq{Qkb|\8CV1au+ IxTo!?ӎ37>Xi`OQ{ܰN C9kn)`A3 L ug41@p@rg\ Gp^%>,bQ}óE8(wVz(QH7D09 \GD|ƶ1]S аx\l#cPy)MKR\'.w#Q\ 0 |)7u@4avX/I3ϗӲ%zo2"*YWt^Bo6+OTwj<Dmʞs!a>&.n5m}?>3M[1zNk_ydn"%agǫ$DBl;0;~,{̫K0?2 $G:W5"hA]p04#`'t9@on((|FοM&4u=H&1hXkk*ɼmH.|{:1?p䔄XB]dvQ>1RO?!^9I0/#||H@OKPu]ӠpHU "3}l p)fu)pFX-d| a݌$+k&Mp J&$v6WMW(mgn;CxjsG]5zۊ`۔|:;.h5d`!mJ~EC$,{ˌ_s#&9.F9B,Y~{Ϙ`MNx.~hI4_8p2YoBu¹ MwG!h=#؅ǣ??2DoPc^2k8:'O(@a{ފyh=[Za~ qbי'bM(x#ybVwh̓ qy*G\T9>o'mJ70grPXЗrF )hql `7n0=YSQhi  \uJ'7⾿ 3/v A[q`J ϡjFߌ]A! my/. PVѱu]%EiRR"#~d*D \͆jʆ&G )5pnnZ`dAQk`G1<\"Mgq7`0ز ـ;0L=3~(:[ͺW "0Tlj֠sExo0؆;>q$HM`T͊@eҀFz"Aٻ;3oUhP\ORyߋ !q%P#SX`Кhз}2GjzR0.qKV eA|B-odluJg,}CD5ij3uog?peqzP@1 )RΑꔢWo]VOyFVP\f}G[bVjT'nԊ)*jErُ1xJ|M J IbXWi֦vCx~td;w@k۝[ޫ0ޖ; wZt` XN9YEt-8 0ףFrˑae"dT?1C+n ?p-E1\Yp{RdB+||/ޘA'ʣz]0KԞyeq].t /O ܹbrm;6>r}g7~XJ)pT}9\VX" -~Vlmxw Mo\%"QpHu||:l޹-&D`axA̻^ ߒ;IklHuw0;sHtS2rDI @VN1xX8 ]Ir LBU 5 -몛7QI&Gߥ*8R83/L+5Ʊ;,[(nw%?o :D ã*\וFj}ґKu @0g ]5QEw v~7^ukBе{4+M'(^ЕВї-WFq3!]8o4M;Q#"bRBk8:h g4}ƁzX RFR9ݜDF,uضo%58B'2o33YKģUmtkfSHptGwH/r>'=&ZAtit} N8J-2W}/?PӼRqTO9^k,πY͔3?=4Fj_dbc>8?*D~LGA/QJ&|Ap ჭwܡU(GVB/a<~ n5.t`Q;9c$J2x-fQel)^[l~(N=`⒪7#eJrouu +-פ^2I7(~ԯy?f(,µ>p fXX,WEkEز܃,z8P9<ȽzdLxHX2KGڬχ,)ۯD&JXSE_Ʌ \O7I!.^tX%-+᳋.ussKw;&r8*klZ,YJg %p c8 D¼'K^ gYNa7jTEqa܄vkJd&~Ϣ^W/ ULNEm { e~ʌ|U@@ͰMZm58*FrVJA`YL„zRN|nPC]M4¸'%jX4d TaX#La5R#<K|g (MfkEӆ<!%ϣr$,X]#F ‚qMqI[-* aN3tʌq43_+iHpe9r8 ,jˏxM|%ׁ^.%C0Pf@ bLI@{ۏ {Xt\/k{F]ʦ|9$si׾9A Y*Hg@O\@p`5 1xZz~d|~ `^XK{IWDvag$RPߗnGcFD``Iێq.͔1<5r˶ to1kYg)'n+ /?l:ܼS;&d= .Fkk8Az].t6`4ed]I3eD>%~DWzQ)(ME.DnέȍX 2iAj|X/ףsa'@+= \'9ahgא'ä3@$■ۯ %V,ZUU~j yR?@lcev{1 f {{80uaH%Ӧy?qMlDqCr[чa UY,_=V"aIVu#8$a,71N߅~)r*GMو>;@̲pA~ +ͼBq`Yz -/Ջԫu"A'g~b сtBC dB|El?390&$Vme ;b`]̣f)TI{r~w%:_L4rud6ZkR2,j'1㑯`sTu"BH&Q^$[(H.Bh&i]sjH/Nyq!R0%Or$?M+(GIX'&=Wڢ9<$JV%PեdN\G!.&]?&_K%vAп"/d%6-C1RHFuZjULFIg`PesMaΞ9ǗJR1,K_K47+^j4n|l`Gt63CYoY< ;vH_6-3#ۅwֶрNn$A}ee8U] KS)_!H~Un$L ir8e7[Rz2YU50t@.PnnW3X} hJIu1ZsWH}UhЯMar'kqAliE `lև&IGC͔1/wa@mU_z/G~z)ejû;;@Dt3ʅIt ps (F^Bsڠ9*cq\"=/ZԻI:N=N+Y4xh ܊>D٦JCb$d`73<8cA(&hr]$ 8Z%zLU?`G uasD{ⲏ[UU'ݵd#:MVGnb +"B/vWР@(Ё{JLi_Iq և , Hpm%gw=u8ݠje g%\fot9s4FK^ݧ&xg _ֳ#m ^V `}lwLKo<0,O黦-+Qr 1 ؊0l녖:SQz6>&rM1>͂4wB!֢ !i3Y8)OAJ78sFAb-Bl_]fosْCWֈQy}bfu^+Z%$pI-;0qG Tr㦦I%KDҷ B,w~WD,|BEZB=Nxxt (\AIVV1"d)feDhܭƼ~4i5fai&x/Hb~]VCت_RVԺʄ7' M#MoR0*g↻WKIBFq Qm=–ݫOG?pO `Q>EVٗ9Tl!(ꏯ|z Ќbtf8]"*$P;i#ioAR_2< # |PQiabΨ- T~[P5 [4YO s @ U}m/ +,.ͪB޳MPioD N)}TW¬Ykeӑga Y~ ˣ%1cS+ !>W]-D0*%5 u \>{@+ȷf:,6ب&dO!ά[IQF?azg!:BjP<)d?M7Ɏ"=U{Aȑ}Ur?8~~VNLȥ )Ӑ(VzJ؏fR|FcN"{Rr*S B)D=FƮ-ם! SWVaOØiN(~Ә MahDi$X &p c՚rײ\0D!9 "H}O/~5ovl` &Y?W:CBf*W6⬂'E-CI*+ H*+k^aXrJqlU; VCs.c{l@8n)xfv4/cznR%ûuG^//߆.22C ~QDP}̑?N5&!*7yail$GɀFkvr|! L!& L}VLv%]Ńo$ᯝa͕O.s1<#R>v:T7}p_<@af{:̶}tZ?A
  • K^M^ZW8Gι@- [ 5I|w;jƬtU௒zSo~rJ'2#Mn}hù(YHHg}[bEf7Mk .h!!ӪdVRb[0 H'gBď8%F6st~2N}7P&D‘,f>~HN/E z5H-pC|/[PL=)6 '@*O'c/ k.= F{%%T5޵)kp$V|tZpr4H)R]I_< m `Y5mć^+CZzAXޮ˘ލ -PQ+ N>\CL k[aYM7jvw;0?4u#\/OSq^F0*`י쉢xWpBG5b,+{^%fa-ņ~to̭s,pZxt, 2^uwnMuoK0̳s]hi<XbJQ>rld:JE Vp\e5!Dv-Q}V o"? BHLvpjHMtZ ]eݣ,TV1|QRX^&'k{"8cZP^$wYvOQƃ#.HpI7CPdNź[9O؞$qB 1]g̃oKh`AW9bPwG#[RUܓLǒ T<4:roޗ:zSZ?)$LuMW6eid>S,t-^}~4)$TAbhXYR*:uC^Q2iP}86D ~ HphTUO?@ ٳ(IM<姼ΉjLQY o՛5\Firg@TaKkIQSK`el!1%~+|.J9uG ٘2$hrY}ֻ5ZQM) ̵Тر^M&@"ٵ4P4_#YGE4c d:Э\Kkq% >?ꤍPe G Gy%G1"g&kZePI'i*9%7Gx5eaEIFѹۘb ,-ekY~fS|YIcoŸط0s&9*S ,?tݛ FQO@Yaw2<4ܨo˦ ,M $LH.Agr:i^Y5m}sBgJ.[$1Q.61;P٘J/Z1/^D]>)ljoB 6ϨQ}e(Mcł-txOa \eSv?!mp<&yR<(v/roGr-buxӛ~iYK9â֍v h%n-*,Po U{\N{g`6"ˍsp=hZRrw:4sJ+ fNy?R#28H.U3k'I Yg4Ѳ`CԸv_zS Hݩ_tlN U7$^Bler&j3^01]lX~>mWoT4ōY+Y';.Ќ$uD*|+e!krJ~?8zNkX&?^(t[.??xBr^O4{Q(K,wUߒ0q 8Yj+ָ>R?pM5~6khMT;5_Mgݬ!(`V{ghꀚhAÚ.c}nv Q9|Jk|BHM^>JABf$2g%A6Lf\b[ff*!U^RJrD T_R+=K DD ^lyCx¬W_hV읫u46ac-P'UN--yɻ3'$ }5bG;/ͽX^ǶM8]$M@A2Qbp .Z7DH¬G3adӺRv44RU)YI"q\aN:io>8hj8t¸HKyJ bRD`SSDQOpN:T;yg3!wYVs2 eYYt6H٨U;#3Й,u &Lj,w:t3LM|U򮺁gEnæKv;?-B᝷ +6Hr[cs܍τ.vsW;$b'%/iյtNnkRh򨷆Q3 "gcӛWm)$滚!B;)4-܍yBuڏ ΃D7Ox#J:TwmLAi8^\QU#7/|έN )1^@wm),Կ;s֭.ډE|bYmB`C~$T@l$uj,u2;cx6TwLAx AW槤" p˃{\t +&vV9)рA8L}84BIg`WWg`g֘%؇ƾS$vW&J5+FzbO}r(/ܕW.Ejj鮯J߄B9#?A"s| &:cl %Mnl )|h h{lډHl01;;ĎENK> :HAD1K.LTeύc!:p;mlk_<R[]G\a?`/Np l~qsv/ VtC}N64uX[[A:C3{95LvZ# qI8 bơJ+=]Z3)Ǚ1ʜuoKgg%`=O‚ nE(B?>]㶯E6xddzk q>y&d2Px.ǝ͌+ܬI,@X5GM'Bb 0W dL{j9y97NaP~cId5f-\}b{Lgb5ܗq}XS(+s E}&O ɣ!n sCY"w\ч^0֐sRuMBÃ$Xk c?(0Jf]ʮHbA[=:?2x(m25.e~uEa/#;Bx}_y}' gv]l?ZFuZ:6 i`@Eh#lB`I0{02j)-l9]~R5) a 830b 믩5k}5V,BDS Uu ߎRST6Si7X!',Bn=-q1j`ʘe6`Ⱦ_Uo=䉅ǰ @9%Zqpd]+!W{N%*M wS+u @O28Z*YyDSV:C/ߗhʟ-͙@H.4 {I# ._z1cz"#Bras]Lwh MI,+pC}DܟVQo@0 ?1Nbzˊưlu|[):O4צU󻙀~猪z>/l̡TV_ʛpظD˪6dUT :Vފf(CB.颮ESmIuʹk<UE\i봆9&hOjRi`yf/-7lϙEQi>:iY~AAc" DL#Lt.1%f,%McɎcp? :>Q KxZhwy.fZX%u.PYw־Oy\9~JYw}/n5y[aN ʈ.!WlA1g$M& ˘r<-yR!pLBκ7}oR".Y"#Ť7G)?  (J"X%˷؇)ZO|x^dlFILJe522!erNxM{(8XCkW`VKy7 ]q4Z6֓$' *>jӟ5 z0W!oN2G(ߔгS8qR\+z*GѧC gjӃ0s;!jiSH7žFz$rmʰ;@w^"HYX5-Ʒ Y-e65qE,|t k}6Eڭ4poHh\fZ>/̱?Q j?|'ލJ1\XqjȇIv2՛k)G9 }'ޙ]frbHVH+N! Ճo ,NWuVUr!ćC!#>JOˈ|8wnƪ|qkx:0idYGTAu ZA5t2@\KD)*9aUzv[Z 'BFjģ *7ZzN7=$` |{BAl20b8}'N%5;‹իଏFA3-䰚3>T/+Z2i+ Z;*!E'Hy7fYMPGx4`Iئt7*Ah𩞐 6/uIu %qh࿍VF\r8jJQ4'!H'/8vJ'"o2]B7B6|n8A> Ȇ xfz-moFQĝ>d3Mh!p&7" li/YVo[kzA7=_[,bZPJsa4N-防a81%` BApȥUЅ#sMU!뉼;fk,PO@}/t<?B7<0+jwEڈe?RÖ{(kUq!^h°BD l Z-BMUJA.` ^k`t34Ht 3 f@Ckź  sGGKbGP~1FR7h}ԩUscAlQt 崗?Z9vxYfjPEx(yHYaQ.{'o3ɝw YLWrE6csZ܄^ZKyD`hӠk}k %㮅~S(9% Rh'bЉ > iv),卟՝Տ 8Ca1`YT^yMe-wV2!(6u]^㡍Libb 9ZY(fq}dw2.%T8mSbJa* Ox&A]XI.x'_,%p=ztC0aD0tw&ge *؇m8W \@/68mfv#lZHcVCf>X݈j+Y)vJ{ݕa)hVY|vSȾE|'= F乷ퟢWɧQlfw?,?Bp68)pc|G_zB]aZfIψJ_;C5P{$clpn28=!"% 3VA/_;AUV Ρ @>_ Yp2OT82a3=M)|g(` w`݋Ao+aVDIQpKU:Wž5T gF$nMr#:8$ʇLƁdjMy }o:\5&kl{rx:dT~D 9CpgANVŃ`Zr Ey`%帍7|\Qwg%c\"5-Q>Ɠt[sN9Q7{cs&i>O\6erMdDT(8 0L#qpiУ+q0\?Q>uO|VqOLT  *"ssIH2=WI1 gTжZ`BmN^NH>7mAQȧb98 > >3oh[~dE#P~L8qcAm"Q*h;gaGԹ[4`fBޘS[5zC>.9T&5Q|cX9 |WMP{f 4Z,&lq}Oz֥hEY؆DDr BYt GHPy\6~ f,'0!sSHb?w+|OnI\7P^>jͪGr[(AHo77v*?VD}KPڈr~8qi?n0yEAK[w_~v9jH-Yl|)YQ*Ty!, .϶J.R&OAho-xF7CAt\b>W?uX|]h*˔o# .^Pœ@>'q;C.N}>Fɉ1& ^4/JeXY@5mg裏 5Ѽsi 7̭ܴ:iq #N?gzU5aPK㋩/0"ן[V!N'P|[b:4A!и߼ǩN,wԺwͰ \V, #'jE;jto|f/X6O;)co#Oy%\`?Vj(ڥTy-Y,T}0%1 ( \GEM&5bwkzhEC쁊朵?O .RXvb߹h֧zx\) n >ETgYOC ?r8 3Pv[R!z;,da2(蚽 mtԇ/%'yGiN:\Q| >+oKE&j1G +y} zKƋxdjmu>a[׉ {O> pv/z=<ovI,o{zH?aF_.V9&`r{\&.1(/ E TF⑤KZK%X˻QUZP3A#֣M$/h B59o] /=;ξv8simOPmNYd11-[bv9i`{ƅHoYԩa4xT_%sςѷs %;X+{R98ÐK $ys~tDXUsP9v𖿎RӋX2$U@L@YSD o0/XYnp!]~ÈSjhb.=qј:w^lYn T;Z X pOm 磟o\,C}:X8|A8oF/ݛ),??L#bE}[)w~]Ls7Ϳ~ _1Jҽ5U~bOOQ/vs Df8 9*hR5;9?h^LUCY94ͷ0@¸:6A8ˁ ]FҙUR *'mcpN `v><-UVmU{E͵O<9d ]0o~}㞃`oYHShcgP>5YBNpb>v~1@*;һ`l(XZ\䃌 &6x,-9@|kM!4U5qU3 eQHn}߯~X.LA&frb6yПp ķA{U15p5<uP[Uo *c?+QN6CвCƣ,LKzw_ŲO]\ ` _yХ[DNiВ2a껇`}ovQ:keb6TgXV)=*oZɉ)NÁʒCkP6+ȡVƦ9K4 bu f;.ʆm\}duwFNAN ɔV &51N8Z'"4wJ}F|*0b O@tH7*psd7PXhx\6~G|uX\ ? rSMWfbC: 5 Y*|^=օKPR A#J랏#& |7*\Iy)6&-p7TE<|ha;Xc`./eVC[F*is;)AÀ~P6K 0҇fmT*rzKO. wzrEѹ[tZ>t}?HSm$<zАdIh o10:ޟw"}%}sh0v]= hohZPnz `aV`.ebm($u__)ROpBD?nf@ n0/i 7ܬu1BEQWV}H]nh~h\Q Fo5#qM-@GD§jrF Xҳ6C ]pX)Qȍ؎f cr75#Qݱ-:>'N᪴~Vlz_?uŔj̑Y ,I xbn*>hE̡oC󂖀5uҏz \aN<"nx\hJN*$MDNjyPiePKW ںu%m.Ȯ̴}~&pZ*axw*$ZJihAS!8fpgG4\sy3RGb&Hmr۴p; $ˎ> l=kp)b&Qq:8x2F!wÎa=bXа@5^TWy|6˸Leo`ˈ#&)Xg+R&g~{QT;=YuZFBtvjP(`VV ~~d+rCD mg浭oSxKw2/Pլ*Ts Mh\8 _Fq`sdϠb[6CuGbexVJϕG*CnUvΡ;V YYfϪwj>K $ػ80CԚk:LZp尒d2礮j9ҝ@JHmhJ}-FS #UCBUn6?d#^2F(‡|݌d/Lw荒E[]O:%Z,o5-N*>+V9? K!Du4B& Hq,9X_ൾ#.G"ox5Tv+5 TC,אH; ?IAa,Sý?m5?\S2N F]G!,+VM*>.>բEdAep[-.7ȯ5Usگ~MST!ܟ}ĚuXbѹx~ì_bv:,HJžIEW eU6^%זLC2/6b@W^,OwdX/AV Zipl\˸ά蕅oR8f ݅,e,rSc^${paLq SrYXg}> Kʚ}"Qm(wCw9l^ɓa]HaQmVKfj9#z: R&v \-;rzZ]ْa H.|CGhMpaP -vM [Ur5<yCJ,Byf/b | E ݣ&_E2TM) 'dȡfo=ˬ\“a`Q.;fM=:6p2y4wU xtJ̜KL0z-J?, sDO=X&ZA~bhGL c:B>>}URy*t*&֑ShtS[6m5W)6(~bgYias0"*層z6_NN(vW=i86Zϋ8c? 0 s%}&V2/L j`[<0h;7BO ʡNNd !#9(385wE|,dR sI& ,/0Ni E%bJb4q Vٯ{2NiGQXLҺxrUymn9rYT$y~+}P|[е!hba] Uz}gK*vRg }GO] m~ęh)G&g!ibX-r1Q>q( @jH=ݖ,9r%kbƑ]xPb*UCx/U+ v}߈X({m3^(YwkrVhI˹(Y$`@hpvLuVsPL,lNRkIӾœǪhG^dr"5`30mEf|/9d._bATlbѷ4(8d·lU+d4  $oɆRk&uD\2ń:|NȂ1AMҀGɄZ un2<;EХYI-f W1~a E 1&qg±~BC4:[xV~MJDram&F?xi%fo-aO4P_& ;ڀZ$? 6w?TПnkt6Yr ^:xa1Se'ĂRa%+X{XIF#{HFϻF2s-[Vy )zP֪EQdy}R 3={s𘭊kżmd'I 4εQJ?~\΋ mLf+$ssT|_ŤaqhnIsA^99^CL`"DG8ޛ^TVԾpTBsf`'遌O4,Jm [Hn! ԫ%lC|O7z㐌܀Zd'@a?xZ> lFvPR=2@VVhj;qM8?Re G*DKy{:[s() >0i""3E P-t9:$6* OUQksdw\{cbU}% ->+n:,m4^yi]3*T[-`|RNtzg KX#w4fCFltėax4U`僃(qzvhiW&cd85&]'_u`w"K;.0ErN$S`EeBa(:dA(Y7EYnjMy dwf^X}LT|l+XKR G8}]YL;ђ;(hWB,Dc7\L r[# |S6x^ި )geĀⳮSM?K۪䯆)rBA77]*-t5w#k/'uNf_c9Y2TLUۧ"}S RsO w~0!3Z⣹hIM 1 q* ݃ ʐ30t隘.pwEZf*4,H WCz\HW#R%7Bu<;*}{MV=odflB x=ߒ$|8>@evUN(O̞u;4b牓fArxN urU*m >dUkPAz;3[Pf쭜-Utۦ0I8Qg&G|iϮղaƺHh<=IOLRs¯ٽe0|qz0leR6ߑ՜jfw1;܇j\8{d5JZ.]p@.i*vjRH̒fͳyo弹q1֗:Kv[VfANXpD,/85rbJTl #/0634T;;xo6JbJ+4Η%풐dx3~HOQtIz& 7F5[:EG~luzs؛O8^uGR+7 JIįӖIDzZ^G)Üv[1ۍܮpwWSXEO< QH)b 5`Oގ`cݦ ӳݺs#oEK]_߄%{D!s* [6CKNX;rDspD 2BE `Ruz>AwY2PhMd\VãhqJA;-#IuHxt*1<}4Ie"@:5s4 "хX*hd lb֝BC$IX۵wUl%8AD3vN<pln4?¿E I:U(ޢ5EVooJ*hL%AȑP,ٚ.p Ozzƨ-܈.Ђv. $@GXI) 6p[ !}"p\ze2d+^ 픁ϼsV>4ӽOf'-[)XLBu-XbI3fb%^aîȡ(@eԮe ut&_($O5@,A3,2y8z1Np"P6xsLU b/d5ߖXsaN_%:qZ;h[6F 闞23nU_$bp47"Qo y**kڕ>;r@gԳüGM#3z}w,Uz9 gsͭ]5-4W,5UWᒨV$k*J^x:6wf҈-im4pm>)`pFAbJvr }* i}dI]O)5[|c^;^[|hEc3޽D叾u%Pq կ#Y\L'gfO]n ķ k=֩R(Nf"Rm\WoT JܨlL iJ1[r nnSj MaF8=[bPN> <̏g Sťl@6I7 d狻`j Oݲ nI-k_|kdǓg tȢc8"+[`F͓?ԔJ4qlQO>} t Oy4~L ?P䰸2+-K#N:us}4E)+3~bއ&4͌6Tհ߮$^f{ռ$sDRN6ԲCj_,1W#lpخBAkvoG[&)h[h/[ĜÔ2a5yQ~&]{V_ӏp&X/i-[S ZNh܀z?绀-X t*T#"ULG1\g+L ^}RO")MwLV IWR|>6D[5(PwV܉VzlgAfJut#1 tR"9smaߴ2A'1׌gTG°Nuy$>)/GEܿTuDn>V!f .=+FIvf@ɺ{|ƞqO@$;@rt6|^ee<4;l@ 'AT0 yc 塔&u՛מp_l Zg|m; vT}0jD-8$)], aW0-2!_IE~z++ᥴmcBDI%I&˽%ַi79[_=Eu퇺Wj=tm[W/ ܡUOc(m\.$N gJ@6dM(d:a؏S ޾6Q7t6@ΜS:lmLqBbT"pm{Zgol)ye\0$z Z7?8υTpC2U5fu .> *øW(AۺB?4/ש݃ɛ 9lC),9{)a.wC&?0S|/ .5:nvC5l{-y q'cNxa~0& cI?//ZiBǃJuEyNc ڟvH?^[T˯<7amU*%_k}YYA4S X.eW~:9̍PxʃAdGcϖˆ6".{L;[XJZկtlFq0+9[ބ"7ȗ8/;#)MIwd\,F [uiclTW5`C7.zxCO;S\'b6:ႅotkCS_nfH L:M.;t/p:^fP~i03M`c`.Z1霰!AMCp-mE7:it]<"@ٽN%olS#7X_pc$#Kȝ* Dw  +pP?;cne]25.9ۖ]\MKa%8'-b9^$n=]n"sx2N︣/RC !86'F RU3<{U 9x#9oP@vo94UeưETүqbExS\='SZ*5E=e`\ ^U/Mn?QfWlFw 7I>&+5ьM&x9|)w*J3INdj 0k &}@@dӢ7|5< 8(g\$"DDp{F::mL>'f 6zP ɽW\pO'G2D3R\h X{-cV|Kp~0҆GE]h\yytW-XZi=}@1RԭbJ>k/ڦɹ69X(Ȗ!%mxMyGruVm+}s\s1K0X%1̔JO!V<"~(Rܣb)$c2K)Q3Scկ|SD023]diKٖ_ mswj㟒Cς 6l‡=-9|#aY`b9%BڪePfոJbI!?o \&) fS K59<+bkrz[h1IS1jX+>PjҺXzb-v悓E[:qjpY;#8ŗBy*mK3v_{ mg9gDk ,jͭ`OF7?U77q+;yp0oϘ/h?̄`+YHD)om/7krfa7%q[Tn:/s'm|s:#B-FC[@~slCвK\~nU1EY0^ݒ5Ƿ~>~nKrƤ9B 9a{9 cK~΁ 7pPE㨄#ilaXeGV١Y6!|LQ9lq4q62ϼk^wwWCt8{>E[uO `T0 0lf51j_[Zl+&psJqm ʈxj$|1Wl1qA_ 75ufᨡ BVgخrW\K1^oQA7w5r4 -]d?_*#Ydd3ſ)O _̒<ԞJT!V6/"YBg9W<5Mzh"XQp0l79fuБ+07О][Q/1 w"6委h~\  $31~ ̦Vt #ٯ2pcJacIOBYD;` bq98BFF]͉/NR’^32[qӝ,ܸE?Ү`ϝ&9=s ǹNC(f'2oLmso'4`@it4&'p-z5ʺGE㹨-9g5䒲jcH,CgT&Ҍ=gCϢw.r)q #{6%܌DSNe!U]2;){bcTj#ϭUw sS{ /h^) tu&!R.P;:e-/X:22 -)i* ,rYڳQ2U:UwP۱hA'ku)~':x!Hx^ݬ 6<*'(dћ*79ceY1كdR]gʶm \ȁC 1JTRM@k\g!/'1| rb'cڛ†BVD@C;&VڋK:NB$<&MZ&ogR(u_~3>L1i[Qhu };"kZ PQQ.("kZEYCܺ%Ϯ_o\e%"T\VJϜHd H)G%NԞϱQ:c53ˆ;h>fd-#B^?>̊gu_ɞK}RBo"uI8zzʨ9}[H&Wo. &n6/M1m[p1V^5-~nA7=ղå Qԝ˱6hlt +\P&wE0ŚG;ʽ"(;L>1ɪAVȃZO<#CѨ_vn mޚrBW ˎ 8κWɦfVbs v\.Zo A@ϽSbD?h2;zn툔I㌄;ďھk8B)m;G%FC!p٬[Y孧"?7[HJ'iuF̀~:?V&.)[q iO='^x9Y5nz0I>Ci@ش?RJ""vq9oR:G$'f&  }!ڊm|&aʒDɿKf`zF{R$euu16gYa y`~oГȪMېg=SMbHm ARxUczש( 4B*":StQ _'PGm$)8;Xv <(@ԒZ4B $|PO\e0KDD[dGb)󘝡bHvv̈́*M'Gۆ{znD:-(U"O6o<U\J_R5w)T Hx> ~)S۹:7ž'ț)lVsȔ$'[Dz=IW {+ U@Ib H7nCqR XܼM8ҡtgzV] ./}LòRU;gVKq5OLpdv |pxEF/3\bFX~b.yTs,_4O2gYݚnz|#}MZ(JBM/8( AϱWVFhֽs? *P7gL$ΣhBsK C;%7L.MBgwb?v™ JadCj څEplu\ UϽMzq˭q0i fֆ9v q+|80m) o(y Y wfTLĖw2:ߣTՓh eu']H xFH}ԪM^]a?Nh&ӑ`^}ɢHb͋ѱ/$:u e(T[)"N>bg92# "+SC|*u)T?P4JKvEt=ƽ4|x'(Q%ȻOVz.RCm;Fem [-fxYcBėR-m*.>ߵ;?vۨE]WNJ)8*GÇkjVY2o"F f27T^m  Xgl.IqRTǡlj#\EqF!2]Qq.r saͦAK\OU:}"P45 _Q-T$Ą~P3Fu~PeI׵8W$6|wSWQ]}jѱ<J|) Y >=f[qQ1*oΘ4co:61Ƿlxc7OQ”o(Cn\eǟw`T$>l*E@na sN˭SgIS .W'5-IoU {axoﱖմÌfmlcPX 3ݕ؉R[FvZӃ<NT^:]T2]{C1cжSU\]HΩ*(&FtP -v*18;2\C߁\C䝂PS.Y+S.('y[hERL ĈP)zubH`#GsO`=ǵqCl/9Kx΅Z>KjQF|$+|Q _X%DzoH#YM9ӀA RϹYs[3nJGI"Թd"cմx]ԇ웎ZLw#h RڤAٻ 7U7j06\XZx%t9|@'-[sNO%PQxE%Qg^Fz Rt6Bv)umcpĠqGNOī|Ta+L6K{,j1k3A@fsI^ru8r+=碥tiQ(]L*2e&MзXŖi: /_jrU!&ǻ~"yR5$aZƱ[͛\qLBb|d1G ÆQ jGUև vaS\x#DJӏ3V U4=b?W:eZ>Ϳ/irm6Y&UhU?=Àzg9L9H҄3ۻ4\)! E`?JOb AArT6pQ!갤@M#>#KK`}e/y"F|mLCE8atGn'9.{EaKϙ,9l|&CE{o VUj30%R'0ދ޷mՈŸJu[b\L ԉ%cE>=,թ#Mv/O+GvObw.jS.L"4lQTdUt!lYr;:oèJvR{5m`OE!x.!ys[كWTYs:80nLxB>RY >sN\I.ukm/7G<C<.O^W#ƅ}"LyLdcC41ݞDKPV)NlƽbK4< U'cfAX\NH[]`8M@6 }]'J= t3`pอ)P1?g_!:#Ət(;~5/,_"a+ 3+{3HiCc܍د5u}{}gY;I$>w[وk)R=5MkI8@wkLb/3llHyf-;``.bT[{{D!ΗۚMN-t=H"|Sۃ?4{<ψ\ Q^ e\~{>1/ri|y=1Ibu n͉ߦڜ&1jjh>EŲ a[K!1A47[rTݲ._O0΅QfXI,p"0?;v^0MȔHv)" |=i^ DcPk=&Msnѐ%lo ؕS#&wDyڤ%):ۧ3}xnZʿ7@,᜸fm@/Gxf/?VZߊEKVw6p7 tV7_> V/jM.2^?W/1w%A{Y:Ӻ|ipoԎ T>s%W3X2UMYc DX+sOcٙMV "y2I>Uv.%Ny:t9YPKQި<<\`ǯ(RYHfZ~eD5 BÃulfVs[yQ f7 kϑR㱉;dqQR|qkOxϠСPy̲^IJrkv)W)'Nnq 6FOpsȅP,Kn?dr5q׫~:a a"b|Ir73{HCEۉc0lZi4~$o+ _֍2NԐLel~S+>s5?NmH\ -"E0 +>3넂ŝwAl TJK?En~ͰSvqhO8A\j6g#jָu *4SL+Bo,]@Y=bKZ ^Pe칭S6/ce$̓ťWxy8 !g&+)!ImT0Z#>&  T1XYvqlأݻSԎiR)׀` &`+AxZ#3U9=r(DMpI8^e_fCF:]..lRv# ֚DYߜ[/J|npB0ӏN#@ J 4x@ ,WycFԑ|?v+a෻9&oXW3Ҋot/f' cۛ IV+X _E˻QD%MQOj+FʐD>/l(zsR(|A7mX|*r@QrC*qy{R"IfX6řwSg0'-Z(Y9* .;^UqR@<.[%);+PO1/jccuR&ЬB6mc b0inmT |c$0GZ%lή3sBcAj?;D )&?K׀n)ocb/̰h;v)9J(/ 8SjG٫[:!nhGפ@j>$n -3p [&b뷹!grT njKk@*ir邕~CR^DEV"S.:}mL{Fl8/%Þp_b5xYjCJcY]k& B ;A6Ag^X؜=93Pӕ1ELNL!jPљH)㏨ox^5kug0߬m6-PX+huVOcewL_`s%gJ>MW\?w-停/@@E?7}~H)2q^tGZ;GIM';2 []$"}0:;E*k'`U I  ^HBj<(1K"gyܽhlbrj{vP6xpˮZ ondV٬rBQ߶DЅ3R!VUI|ѝt0lBVBBT_ľ=2\Gyk Og @Ҍj=-_~]6Ƀ\8Vw4ڭ25F[p92[DjC >/U]92]jQY4,\ѤP|!JGgrN@ѺTLo[ M0`G;vtHaTY\8rIESD7UGHa댺<4Y[n%&~0'Y911芍>mRp^d&v5=g`L5̟׳`&oq c6MMÊ0vݿpCuDEX}!ص h DTwħ[7X*NJ^ h}];1fV/e֚a=q 0 M4*cPɦ@F-N+MvZ"lsvmi=A6Ѩ8xk`՗iE~.āl3ƱJyg:&zFHCLǿNfoxS]hw_D1V欎ٹ@4]74(JM G ֈoưlgGX MXm`=)?I&|vNr"u0aƼGȑŵ\8E 8-m?תj>ؖQ~}'S/qsoRLzrI$ѯ"MIJ;1rݞ5kh!ވʯ&EA"tF.RG5 ?7c@˛" 8@=ݤf=M4\#Z`vʯ{׹H!;<8_{rcG. k\Ѽ 0ОWF`Bp xJXhN>IwUig:׎@G[=kCaVo`!`77dNQ kR2'PCqGTubFd=//zbթm'iDOZ<]ӻ-߻8ދ N1TN(+R{ ЙZCUJK*f >ey s&%״H jHtjDLn.9YK1+fNF |)RщvւXI$.GV3>nFn//LK_ hhjRb n6!O\m)Sf'Tin1JE\ѿAX9=Vc :reGi!Hr)ՎgWvb.@+ HR|"]5:ؔHx ' ? ׊pѵ05Orà xrgaޮPLވXj(GfT!A%ÒwA: :泸^s)O8O~q 'EvA{ oEIx(V oQ"Q1_4>j`NSP|"|R(^k=#?j3aO*GUj[+QM^uxһ8a<k .xW~+%o'p3kAUٟdfӤzzY[nZ#kEKU-"Oe*)zԟGmζE?&222X>-s*<]ݹ BO  ƷxWIJ!+M u4e)2'm'[ޝA~v vXzrmpg|Ѻ:Rt}~ﰩ}$StQcOf"qv*&z&9~9S'F2٭~Jy~m8͔y\$>erq uG$Ǖvn=/%^UΗ*ajml(^_jXTɻśbz. VB/іW Ҧmmf A@ E f[U`tx$jrHѴ8 rG ؋rq߰-h0Pke   R./ \n2qۥi ~F)@}~:h;j0˫..we9 %@Hk MLxS7 va9ssdAv܂AViL*oǰGEHZ9GffH93fO㥻o(T)Cu}PBI:* OIr()]90P")h2  >"DCD"*mxsF2\Rw+Qabtv9 lT򗾃lg"H%]FUy167_7ilZɘp#8 ͆Otf>*tCۭg u'!)/V4 A4(l/?dmH g$rjdҵqeUid%1ufIuNsO湟G Uꭲ\2q i ZP%;Mo]@ĕ MIɊCs| I3p +a0[Kn`쪒Av@HL#VI;r&&8?ᶤ;mNޭ06¨B@bg6J>/rK\UPAYމ*.tQy noذ˞50 ;'5a b9 OSIߊY:vpzDnQѡ-lmkWS_.gԳ e+%6"&PBH[B#y?":2cRS=d$.ϬWߊ0]H*,~ +"OdU.8"c|eAq }tFMK7V554F4:ޡRsሔ^MYƷLp`[ —#(o" SL0Av/ic!B }!!lԖ*8_ȩYuƹq !GB[.%X\Wd T| "ɾRN MHg6Deuhf7O %I/QKb r -ǻC,m#?ڊif3eߢ)V27{$Ͱ9`\5Ux":j Jc̞z ͌u]s4:1 " <:TINݤ:`OgtTR9T\+X p]- 7o܋E֣AUK Xf˶V3@[|xV X>o~CPJCІ{B8r䉋GǽҤ7\.DSJ855Ƙ.A{XR(HgI3,†;_மT]ʱ}C47**>LÿÕm|Iwqit)lXbJЍue&C7xs=eL <6o4)z儕~1C+r/ݫ]R.P"^:&Kp\563O@&7+A>)`&Mȹtt)-ݹZ$HEj(;h{ !g>rFQi?(ذA(0}yx[Լ}U@ȦD%lwXgpS;hY#n#H#Uqm{5'iD"=uw"ߜ~LϞ,IN_#?EJpm~KE'הοC3k,SU[k:DC9we]M*vWkqܯ #ĘOcC}L rvȿo a/9ai?0`m]L/D.Ev( tu>HDf50U|@0+@eG%{p#rh=$E%hSG &}eJH_ft t±:r80!,l]CF8aM1S,M6ƶUḡ8—iwb'͔iYQF=B}FIHN0%gK nՎ K "j.xV699qFpe}=[Cfq2fPS9ic +Xǭc ,g8Sgˤ9lUzsKmNV"=#pEn")Kjz)-i)lI{Փ,l 5FZ9c1oOoI{|&j4qI7qzx| <JS!@x&, !aMMHJ2ݤf6,owj_l\Xy XX׶󽷌B>NnAw=̹\N- (/F4PӓHHB0/GcѓOFl<Dƭ3aцA1=U:(Zԉ?>MS5k , S$I0>vѷJQYUA;Y`2E49`lH RZφ( Qe#P$=i|*`X5-9;wv?:āX- (|'8YעSf)F;jXE2: abxXHx,,` ezMɽ 㵅W)Y5`} u bSiL:^M UMRp<6DS!lioig$C.KʢKq& daչxKZ3&Ș nQȊ3 qsqO'rI [!5d{~Da˵759P򖕴 {Ryr1͵Rw&'۰]t= dGڞqقlK'P6I⯜S,=En<ҵJVf|U>g=D]Pa`6SUУR˅O3XO*l N!a]U=t(lzP 0<qJIcXp]C]Jm8G):q%SzĹ^c.֟n*C=$w̖/8*d(B) t Go6Eŵ1DS4NSEϿ-q1_1ݏ8ZAоJXn%m).I E]լsYoFeA8o+lt{O{>7Z4vuhvl-U;El, Tw\$spc"^!0>>t9 ȈB LDL^fDp胡RnVXB&W_o&.x#(C-v嬹$멢]h#Z&KzY̆ٷ{hcLlțd|"{uaS8~vr"y#UGXC |U]H9>nV-zɣjyfy!߽4uvc/%Ζ* j*X3Tޒ f6:"G@^7yQM찖I Y0xow܁5*.y:0hr㓨#:((# ED]T)W ĉ @a 䤸L[\Ö@\A\f$=Kewl*/UvW*9rF5?Fynm iPV'SJDřSIǙ3"u.T7 mQ8 EOy{=b?/)XU{ׁ/C[aK*dbP9-wPPD>^A_r#|=DJxZ{y^Z@%_􍶲/hI7xsԮݨY=4FdiĐ~㚖0Ed3_fQuAl9uԤۦ:_摨*2\}ګ\Ls|&6ʧ%~| $^SGΤ6zۿS#|Uw+GAcNQYMWȿXH+Bs^ U-$Hg$1;gf kuKsQ?54|  {!' K<ϹTiWE]#)xfI#c}OW"NuFxwd--)g ۍcM}&鍳E͝][4 ^PI쟉_v XgNC]r/t* SGE{nS3{CUvT(2Hv.1^I54;yĄ Uccpo\x,H= E٪glVb:nt^S)eȲ*S2OBEA"s/dq 0V4xXV*?k6 hh/e,M\ }B{`*GjUJ7 _ t \$n+<)3t AD\fqOUibYnt: f(_9mGAWeIdx8u: ܱ*U(GuHR ? Kw|Up{BnP?0!L &ӄta6 )Rji 6]6`0sJ>+Nΐc;AÏmpNiv>t>J>'R1dzz6 }"*TuԱt9bm 2C>!|zs8̄d&œary%5_{pw,μrlńr/)MBhva1Ji&Ĕ], ЩB pԳvp1gSҴ< E+\}NVˮ!5L!GfͣX4sznM`w7^څ ~ɢ]HX{ m26&Y |vQiQ)tʼnda{ly#c4t!V!O>OBA⒨HB_5D~5.Ff|N"K]ۆ}R6=Ȫ"xzɡx[dC@=1dМV<\*C;^%iy>^y?? X>Lzkv0R5%hX)^*]+zDeg+'mEBb*rS_j+:4;v % M3͚ΑWMooפ?MYDUim Zw,c:?MƎ[lRhX-OF(7З8Yp xW-)٢(l"AS)u/ + ,iMLᱞҵ)W##ΉYȔ{<}K+zɟnV$nTTeC&ETWO(r2J9mAGpdA<)TB-t()9VW,g6&5'枖lb:1\ "miLOܳ9)`KuD4٨lY$L?[/5lR\{jYsS 5hM2KnIL:8+}}upه8T "i Z@s?ɏęfTA^|Xw/Ev-ltUGY jq~5 XyzL l"rU Fꁣb3@njD`罋1^`+t ՔdڐL$"ҧ$@rC/lc1?N?/w%mAO$Sڦ-l 'jVWu\bA,/&ˇ5)zËr_]|+Ğ/m;D q%D9V!|p$Pn.3T9PY0-b]֧.xulPH:̀G)!؈mQT_#0 >Dىޒ@G47 ),4#e`V.1㙇9:Nb+eR ޣ%o S ^(;-e;уF3E~%=\:RI p$,A0u:F`zcGy@~㠋'`:yAb-;lup*̂rCbf뮂md MIs,#ePsO1bUo,DIZ/H$fż3}bBdBjur"7:^ʂr6 [Z65}v;BlYTjȤiO` zS2A_IZ)E9)AӋ*On;uuXITvfR01ZADr>?z<1X۵T\⣜rwc^\zoQ'Noܵ֗zc]`eJ[\Z Mfk" b|QNOs~)ags63p?pq[>ZiU3Dp瓵?k$|ټ*M?o"E=W"-1K/:Z?7VI&j^.Wkƥn`1 |O4U.JϓxA\r9CY,rk tAYYKL4CH#`%2z4p5uMl+2me?pl[jw1B7ޏW.CTC?̰!"qa) 甶ME"[ypQ ^!Oަ~e'Nb+*:bs` X9'v=UM|Ś\Yi:ܷ:qD $ѓ$e aКjRϮucps}s*[.X(;P{٘i`w6v)bg=+p) AVL# N?^d"AJMLY=Cu,E3 ~/RGP:J@6߯pQWaõ׶zw-ob=)׾ro;niE %>IsHX%,PG@O s@;UFV͸BAE_XHkj]yy!Z]472鸻fﶓqzQS&R}YϘ{/[<@J)Ji;!!C]Ce'ƕ2, aԽ3.ςVuF6Ӵew=<<<1Q*~Q=g vi:{& գH\zi4jʲI?LƓѹ`$O8$62P CFD}v~REnvt* VQ#I0ov쯺~7!=v1&EۚH Jeas0^%> gK~.͟5] )UE-ݤYF(i\@x M6$y \ZўVIn BDnBsu]2 ÏF#^f3_*D* W{& ,( èU4,p9_-(]q\`eF֎.#3$6q]D! xkAglaWᗬ&a3Q ;zKgywp[hFFB>ֈn!.m0*_huO;2l^Z^=u9x yZNWa8/;=\csʾF_J_J\5b4>aҚ".h E)`syluiiѸKYf@Ez t-XelCEb0]B($C3ti4 |*?<Jǀ+C༰萰|7 ꤄!}`W <[oq_ ǝtmTU',!',W=/G ?I7>r{]a7BFDէz1 >D(#Y^ξҢ/\p˭dDN>`K`8L 1Xj}tAo$Ik_sO>i b[YƜo t,rFWɑAz|e^ )h0Ly,Eֆ%Ԡ1gp"27|h=Q ,AMK??Ym#vGȰ vKnU&) J46pP?y443%Sb_:SB"xK⿀:vYXTk0[=6kpXN 5Hlfˏ!ޏ:Xnlx E ^{}ZU/#ԣ\/"6Ä gENƼ=rc{ fe[77oŮPd؈Lb>p{cAs!c7z;ʧpkJ%0(+ o@4/k٪_A@,H+YZ7PoJsQ}5D6@vaedEhy]3@hpbZD˕ $ǘж7F[i]^YcvlfͱL0I>tA ˘y{^}9_=UԲnS6֑SY[ /fICmM|ػgmVo+o\5 2 )!Ϩқ@3 (MQ7*tՆrX;!Ė?M^m(w>N L{lm+BtKFi6s* tfm}Ypp=;VY)qEj!dUja`ⅳ]0WvX{Yuv<|َ}N{]Oc7uJ$$6I}ukŌg'`})+},tQ+vԄE!4}3 =C:zoxّb!P Km-۴aζԮ]&ecx7K4b< c]aa%@.Iw\!]RAc=1UⱤG& jf%A.Xx+\ V2Tk[09ϱ(T}m!谬[bP,h6%* >떇q62ɌoڊOA Gu$|EL}}k:ȡҶSRX.@A5w|iH,%KJ}ⶕ4Ħ \&0AO&_ݯDdAYصuKOMf4>귪b^ d#y/זN='.UWOUd|w1FkXQ.@MuzGJtf%`MD$ZݙNdu*|ٞj0.?p] zƉi~\RHN. !C} >:$"-fUG)D㩴}ޯJ(Mﱉ,2.lUM}\<Đ\Sw9]f30uekU!VhU d(R݃ZsL(S.W=._玞>ueEvCb.z!P v) -$|j.&<0~J V'$/Bnդ![8AVW遠Q,hѕа:avoџ{ o:6Ag`%8־g H+LD=Ъzl0C| ah+<Ԃ.lL011![J Etgš-ucg~eHuז9b:EMhcIpksV#}Ir\*\=L}N>pLrKؤc7DƃDz]?l:Q+C.@7-T >mD 'HTښԌQyKcD6 k_@!}[VѠ؊۟Ugnj_lfIXX:z8Yw\D!.ͰjN|y!^C)+iHpM=:hU6ju4#$?N,`gpǓ u~T#Q_im@'d7O/Ԏ5w)e208T; |AN [p$!]ǡsqUG*7 ٬>Í$Y{^b|wxLM_j~WXN/B᠁s}pYOG0C"IkqK~'G%qm_́sxh=W-Z &i8[6jva "/ Xf&q8o륉:FH/Ʊ$\3_k:80PNd{Õ+Qs4 Xzrc/-QzNx%@:ceH^af$r7l8ީP،}Z;)KwL6N}]xXؾc*3BW} %JQVܯ*-t{QxW_dk93KWgB#ﳯ;tMjKϒ*y7W3˲Զ 8LDYBy"}<49A?W="Hkmr#cH}Y䙝k,`/5l G1%_([wtUb SQBүߜud=|i`/,a\I |-Կ!$d`j*;rfzI'.Yʃs_H5^zj†Nc;YL^ gr]`cl48xͦ9M3;^Lʣe2M@?_ULh7K.ӱ %7?UK{ĥ֧SfXf^4ƴ)kb)Z 0DlBpxƆ{V0 tXY ֳ,ُfz4&R<+yƼe\4N~r4#y7^ݞԄ49Pi&/1*ƋPgi 'H'(=œuk'~ףIGϲp|o'+t}QLw}&=V #u~|A2Oaogx̾/;VtU7Jϻy9GRˆ{7NrQl"{_y _\A`&c՛0H ;)C8Cxtq 1:c83< C77nݻ ֚fb'PK>+HM6۹$q₫ ]#/^HU_p?ᖟ փ|` iy% $We:^#*9eХCw^̐j)m=2f[B/ٙ$b*7ҵ/=iMy;e81Ry~v fK[k*Ȫ 25/)U9o9 JY'`&@T5lI/ji,g>o!i=E|+a"l̐[!) hSEctb/g[{l0ќ:~esD7;δjw@|8v.j./h`7(^lzAС=$-%V_6NA4C:4X,! ?erbQ(ܡlq83yq/+oW/'|,+} ~Mԙ6ı*:@,Iݾe|;`8za5l!xF 4'n,|vP.ùc^@#3C4V3<%+TrD4c;6֑]e̱WvAi[VUeہyCUvPQHvh/D .bMďuG&g4P㠽GikLwҲB;m^6x[M;Bʤf5q帜$'%8!m9m6uKc+ T7C*~@I>Epi|t?<1r&X/i';ry)hU@-]T0"&?/ Z,?^n.E`-0$1k~E9榦݉V̑տIh VыZtYUy#=ˇuW(35mRmœ,Rcv~QfHlCU xjeikvnQOrk4#[ +zzӊr+5/@:zN-ī!7B;$nR^ͼ/pAC0@$bԕmzeUdjiكKTfaGܬ6 G}%z?Uvk$R֠v-vgi%='~ 6}1Ȫ]g.7- +wKZl=Tְ, O7~i|Nҋ5EDB/۸lXڹK iW\$F[L!Ca΂:B ZHM#$@sHq|kʈQxkpNX-0y H *MyZyʄDxdW%Y,4^\F{D {Cp,hk $N8 |7Tw&]6;4ͺfU"&H^$Jԁ2u&];_ #`+4DQޘoQY@{A:S-ǟ)!>Sx5Ro܈_S W-Xtl:P<6_Rja&*<Ah0.?i^^!1SM_BiR+e g 5~?e] P)ZEx}t2=0KֈW3bq \cRUs8z=a2&2r1X9FBÆꈃ5Y {] m˞1.A|]]0! ;Y^khĩL,7R Y.QY|_a@y;#c aPsgĮdX1c+FOФzms |Z"Z5ymP_M~ո5sDzomCĒ8/wY+qE(n >|-=0aTB} cokF?h=؇|5̩(v~`NݹɆ lZCRU|P ׀$IG4va4_\=΃o_mf6"l&Iǡ'8J; ~ZȺ5i]X?]©$Ae7+"'rާ~D}BSOdIV"VSћt>䫌 `'Io iDۅ&znQQXm,H+U΍O-)o^ D2L)!1z/ŦΊ;}q@?o.G?rҰN=/]WpdjhbpEڢlM/EQ!}yƎA?bDxJ'ARtZTlusEbMT1`v/# *,]I\.O~:m.,' .t^LAT)8@񜯿9N6ؤe0\O^ĢuNТ*ͨ^"D׺_gWr9 ÿ́*_ gh`q#U@-=I&Z;]#>dQz <ⴢ3$! MaNM|3$nҗֽewA7DhIrȦl;T|nq6VΉ6_'%m R{ UACIEx1,+>j1 TI 'RIrVWи"D/-zAⱐ`>ȘldFc)װö>PF՜}2Xꉥ@Yк -Wݯ}g 'E!+( 5s`XP;aߤ1P&r;Y9VCK廸:dܮ,_F&yOW*q!pnPFoJ%&LS~r 7hse&CWVwҸKQ |$/ȥ4<[-<܇;f5!-!nV(zVFBlCUA6SlAPlmn1 @slد%9m#/~st IV!o85|'iě -@:dI.;_~EaU;-Vt"A|\vgIQv5Wu4$CyרG7q*ƣɪK`_=ăԪ'G]=2-XqROw=:!EWr1Le2B[nuu0g6jPL,gv..+Lds1DZf`s`y'Q2z,n1ѿ$+4%^Ԑ+Ghá[ $1da 2i\?:Q¨ :"~o* oH #Yqeq+1C#eN7&d:DgJθ4H ʥKlN^MC.2ϴ5[WzX}ޑaG;š c mMyS`[pPA據Zy6GHnvptXm2Ď ;7xFiKG o ,#F[em.E! n}`=X)( KQ\hy2FS^|1Ҩ1oA5.¹7.Pzfi)1U20}86q}ÜL.SpN`nt;Q-1 17.jW\6+,.tILQQJn~OpVl2u$ s)\m'2 rڃYް곶iX|Wy<2I=iRMbMXmQ5j{N,Rm3cm< [D'YC7kۅ *(N/Q#! hd? ."ߜeN>up*3ҘELPd.DU7˯z.Y 4( aq$M Ŧr%g8V]/D+g[BVVs /0o]r#罜8uKq=*Yy N (>O^h.}m#bme|bbz QZzf1\ߧyJj0^״-4 U ujl+HLҥݫ#ե:}{e[4 q@I< U"Q;ҏrliv77fP2yz@aǵt O8&>>І:Rz$(_-x ,4$_h/,&va^`V)m=`$/76NX& 7Xt\Cd xwޞtCoz_DݮI{EA^aCf~EDЭTc^N)]uc+$1jί掤塒)Q?A!o~~1Q}kmgSĕ:O p\#@:/zf<ڮTAA\i_/AJf`m:\q|9|Do18(*xoj4LaC'[yPU\PD>z\w5~BnQߐ1!* -9p k&xq J8O ݭmsڰ N&KrzC_=;V 9۟<|zS:iTo3eUv]`֪"hƗzu~:glI% o\ Lq` +XƸA@}s,i]&-X{8J86?5Ny.C`AȥY0FX7 ʻ{9c<-l}H"/bԾm›x8NjQiRgxxU;@r""ת>oi'a:`wSx[Ό'#GM__tҝlY{}մ&cuc)&/;df߱C (dIwZbFU>kx/pl-&'Ҥyn0wi i@|B .%Z2'06' r,~S·%!<\TY 5<, 2Ow;?7"T_y4bS< Ѓfi.iWƪ< +>FYڈ8r98Nx"pu\!:J/b0/ S{>).'#5 97ʶvu4BWQ\Ku~j<9 Ic%qw 3Z{dJɦ^:_sBw @2wemw7ACQSg\شN bѪMQ$Ѡ=>HB|fR4]vy mX܆} ` T2qlJ n'ɷh",#~K }岶Ck`6,PȳS_Qt-W#I;tt`aՆs0O:Z~9;e `e0LC6ntu~Z' Żg'#W휱4(Q>JkP>l35>Tk_OZ}ʸc»Ӎ-!D,^4+t,9Ӕ^}!ѷ= zQY'I5m։iZÖ#> )ȫ>YBA;ks^N2CcTu %3])m#MQeP[…hX(4BjDJx7{LHGuI'ļVϑdj +]TS &;5FU=gu-L~GQ;ڜ윷;DѶ 8W~V%(?RM KISɄ!-vXLgs7;Q ?Hֶ ϼWo1PBņ`Z6蘎-i"~aG@q}ArqE*4q5$ࠆKgzC]eny"ugѧ{ {UyZ\ BO)]t GAEgX |I)6cϖ-&_ uّ|׼߈%G0m7f$'>X?iRdT(긫;qZ%ͩ0WN(H^BP){NP\94|ca|#Z h*q=FI7' [@nk:89=&6qu#NY湢] ?Н TU]GA_rI%wnYNZh>u>#ODA]3bo: 1F(CgMDgz i ,F'1Yf_aU֋gF#TW!Bڛqwka׺omɼ֋{rToR z;67  PKvΐjeF9 8ْ(Б-z1X<6W_ fff.h߽`;,SKS*#oPgn{N;@7t5 ;x{GD墠8@$qb?3z<ޞEsOi Lk1@n`@^'Mg,Fe!usGY6iѺ*Y'- 0^gM]6~ZIkC'WKY@- TJ=hl-~3ӷGNKѽLE\^f (i^]S_ЪK(~:aqq X"pCBIjF>X؊F`̸/O20g(Z/ Y!v0r(cycK.=IঃKfJrذqGHiծHrW'%[TILI`8K%]ByFM:&zIҸ[Vf[T( bZ_Q nvD1Q-%Z}5P> a j}i!X1Iaʁ+N *KeV?!#S:Lv)ޫ(#bv/NY26d?jfY!RU鹥CYr4- ,4HXrR_%װ]5SM6PzWz$٣ǴqHZzyh絹JUoImVE@C|֦+F,dLL@:>ShˣF),dv yҪc:]/KYUPѫ"rΟ-3i3 S VNOKt#q݁[3=T}ZOP7d=,ٺ?=-F|?!?  I(z@ Xu {,Øw%̳S]eᤪLU6=ZmE&/48Nfg jVX!Wk 4lhZ ˣ6;tȫ쵎'I`,Z4@'썧%j27~Fpa4pBӧJ[)[߾i ~$p@fm,pɟpI7?M(r:UL p]aݹ;~W$P_+V[v h߿Z$H#[>k}8r[Vzېt+?7Y$*`\[|)CC.%}RF3KAykػ KOϣH |M]/{Kj=.49OZ۰bmav[/6i0)(xNtKS>T%ɧu9ēV~q9 -ėu[[evj_*+|UZߋvuHzTI0'DR:ݺMY$8 J~ OyvqUBCtߝ&پrH(#mrI P)W #.wJoeʇv#;gFƭMXHMu~R ×CRU*Jfw϶hkz1n:zơKԏO;TZȧlyoiwa$pq TcD'%kYl~x]&nl\#yMgR%A(Ut+T_do *F zIU _|v^!F@OIwOy 9_+^EM+(8fd!'-oe!bv A042`!ϪV8Y[78RDD੆ඃ5B,7ܟ{Hꑦ{ʺDͺ $[L;Q=a?VDɆ.1ӌP9ohkyM $+ۺ*Z`iD+l 0syoTwC|ȯ{)&=J7aG8;ykXnqMbɴlA]{ŜҙLf-72u9Á1O!2<\J qUUĕU@GMn|W)x9 \<0Lo~τ*iMh59@`vƽ]W%Bt2e Hv _=F}I2'yo:H77!~"R Q¼!3LO1jmʡVd"PG*P-M!,nl厀C)jsςUi*%,:ݒvnYocMU\]#c>J#tS_,`mk;zt ccekB F8yd臶;YHޚ$R>Ulw&aW!%XPHz_$g` sZP=2}I_0Fz{'+Dd^&U![dT_Ԣ@<&15XׂRH`w#&~ዙtO/:Z;azWg -ϳ}kb*h7q{tZJ˸BTFĖqbfٔyNÔB¶Ŵ4;ŃL02 /:V\ORtZƁ9TirV$+Cn4_yf{55a8bSœm˸\wR2Q>eOSA{Lo 6@ѴN:I{^% Y{_(& QviBd@ZL@ dWˏb 錒EXCFq6 X`/>M+޺ |bP5e9u,ٛaxc|1væ?󶉌JV!3b7A@T2LS{ڭr#d䨡[;'$X|c]sؓCe+ CXtDZI]GMt2ew<_LBFiH<θƁyM".f\²пJ#Q* U LѠx"dllw%`JUtDO֢=l5()(=#Eν^v!6ke$*;#:J L`ȗeJYh sb4x9)#k5TZ'N-n @+ȁe xi؋WqAI~ grN!NJyIպF SxoVj\|m xF\W!f %`T"'c0ˍC:(otpޥF/nGNrCI7O$Eԍ$T;} ^5Т jU:fB>SG:-ڡU R.ɦXu*1J4K+\s' +H`;t]Fo- EQ{+t)_#}AHB]|̰`nLnldzN82=7rmJyY3xQ,߮tۇlq Ѕu2,yEel2a_ᱭ%5+{\gcq.RiIļ`lytff%qΗ&1SiЬY<;kVXjOçs'T4׹lJȐjԒqs"qޢSiM$scutP?ӲǃÖx$dLD৶N4uq_iox`ZRpd*5:|oVlׯo2igؚ>T7ϗ#g58q+eʇPN1!?\c5^h:lǪ:nQ%@OT"-S=rإfY-Tf1&lɬv B &y`W/UNSoQq#(UI4,CQt6<WT`Gi t$0[g{qD3znIJ[FME\:\Rss,8t<0vijU|TLMD}RӯcKÞt Xƒ#)$4Y`~4a }*rb$#o1;UV&nN\5Ռ"Q52(pM&=z*3Z⮮\:j7w+dJ_/u)Gхņ}!,dImV09xXO>3qnWw2$V5qIiz?B\(DH͚6T'=O"\([lB8rT ۚɓ~}117vHrV7:|ͫu>"@:6RoUنg/Gր(X~/]Ibn48 4c|$ }W-ct&IJE%2`f)  Zŭ覶\/^]ʡf^r VUi"]բSם"M}Ïx [nC&z-O`gK96B+ 4y/#á~p|7;lYZ"Lh9:ovz o]iqnlܖ^gTy0J)Q\S۰9 U>gmLl{ ;βٚԾ,Э*ʥHa#Exc*=(O}ytSFkg}LeY}rV!V:ɼNzϨW`utuj P ; Ŧ0FFƎvCG*/ ֆl8b4yxY:LI~g'9qn#5)9dO!ѥ2t\x9o\\%nQ٩NOH:g5D'e}I#bw/F.JE\f?1*& ך_F^6?|go>uvl/*ْ<9@{s{D㯁gG|璺v(`߷{I 6v@|&ur0Z@bN׻6^U:L5q!#| kLLYJn&O UŢ*^„X5%@xuptlx'agme0iʕ _nؔ1{\5[oG{ßCk|#כPb!rrh$ِ9 #zYҟ0iԤ-;p2E771%Zuҫ8ͫ1 W=i>bmn)('8mi .b'kdjTT92|wHh-.Z,WtW C"[ae,nDf6 Ad{0 ˶/^9 Q+3?UG:1T ]"q|pB,DƄZ–`(WZkϘȚeM`Pv8\+|#tpnХdc~*%ܻ\mrZ7mp8x`ARAuY0^ǧyzۉýòpt;rɝDu&fVp>$ mM]#Bv(mP]*xF z 1IX^ dHx,~ U47 'p2V'U1m lOgI& [ǬJu c. ~?hhTmJBmsi* #5iYFu^]*+APWņ{ ][#]'ӨVQ.L~@2o?r,/h,+nz&첇2ufx-\@1UJSNa闞ZAd!/@0p5# lVeN fOs&:mjP@F:dύ sF.EqFKPu=ijOrH`X5&}C 녎kGE ۊQ`2s\ MU.8y"XٵQ)hgMDXAk_W,+6ivABۇS04Ӗ;9&7@}5bZ&[35"WSssOab4@i(h/tBoo#i[j1!,ss|HpH~TV╊(!ew>dK&NjWZϲkdOSD2; gq-OԶ&!␪ Yg'\6:YzR܊uG@pIw ])1INONׅAE-3m chȂi_77i3n"MQ5]ht6r}rI/V$Ѝ>lti~Պg68x&3p2m%֘f˷#\'iEC}D 8SMA]H-JJs}yͶ/zgAPFw1X,NYVwy՗3 v~r KYnBx`ӣv E>$$lmΊȲ,\)/i\y_/wlk b>qw2.z&I :8sYgtNƊ6% H){?wp W?1/Ce+*UR.-oCӹ6j6-L%,ǻ,]h.Ni]%TQ'Ғݰ鋒V'n?u{]h{)-5ɒ)'FUPɴ/1옅 d+h+ka D]熏 Ywe(Z҅Y'tR {dί orD,R Q{XrUL@4 q@P3Dqm[ƬD>)"5Gױ&ƲgnVẕ,ׇ,|Um kJRL! 2Q 725uH:#_ zT&`gTF-BC:ZFVJq;rCBFڢ=QLW}^8BabGugv8sKPu0u5UŜm6KR3ikބ>R.!zw&]k[-8d]كgT Q+M^Sb?tjؐnK(4wqā_?9nvIA1X7i( 9*F%?[)% yfr*4LΑ1I=s2 .}ltfRѡd᧿iIDN)"^ _ۖ G٠"/og *^#{nZ!U/`IWIr `p H:+A!AWZ:+E9ݽOF=/tU,EIp"%EUu͖4*4D戨Ì[d|u 켋k!:C>P֏^eȸ2A& ɧcwWG*2sa\߳TmJ  k{X",>{p+2}h'1'np|b"oR\q6w%hf*]Ža-)dϵXΈ(n_.&"_02E6'c>(ȸ\})(O؋PX]F5~:ECާq>=6T"eQ"U E#V#“ŕ_ֻ_~݆ƶm~, 4j;tz 0|  A*|i#to=:[\.#H`Ɗ+`aw ^=kkSGwک ^Snd}2Uoۺ&,'p~&`^Z:"Cs6mǙ_(&Zp"Ut)}EewB}X噼|zԸ Y2rAKU0윤c:e ϸkl FTN\`J-Ƥ+Af%8,1][BiIgo?#܀@&f*~@vx+  z= dxӟkq2;蚥;k@471M$8Omګ'۸R0EFLEMUS3KO2EM f HR𝥥xH؎x&兰(a_-4vޱp6*P1^ PZj|*wP}v9,Z~ =E͊fը4ndB7oP159Ovȯah/W*:/1!%}]hȅo>Yp+b_>Q6s`|??/WE{MhWr@z5rye`lj%52OO%xQGo*?~q[\'uVשi܃R+cYITq?RDt)v) ##;h;cC*Sߠ7bZԙ624c{?.B[s,J*=n1x᮹8+)Y3zb_`7􂏅!T:&W$;V"O־ҡOد:u Tj{݉NrB?в$qT7зeVqQݟE`'!4XO]JgmدΝ:|u`r/V^yMzvѓHCMkN@zV@,GF]Hڭ m#nF5wpVa+nNOY mF5#xno/fb @(ueA 93d y9fgKJb#MY6VنZ3Ǹ='L)W ;,/aoDs$G˻bk/D*lx~:b¶9/zn-nsZWf.6;a‹jd# [je ɩɔ\H~ h&ym@4 7X^?Yx8?[b3 IW7ǥph/r}.nF%`{|ek0L9eg-,PhȽN@B`x t6K'6+>2epK#x'ZEe_e%ƳrÓӣYLU#(E!AQ83Efh. Mxt uK2פu^K66D·&> ]x ?>^=&_-G6$E꿻n Uq'-f8dhrβc.gJ?fVի֌q@ĀE<2}nDXW]: f߶5J)wBχIX榱HW"0䂛˺eefu f!XpN,V2IjAч&r^8cJ#ڍ, "\fI*jI+laR7UDj2w;rhv\~W{FF)Aʫչ6Rw 'ݥ F4eb*_y1> zH+ۣyɍ$5v52 ~>Kԣ&H#7hWd7v8YCԾ8fըͅ(کd (T ANmtB- Xkһ+ nei b3 {1Z JN>po? n$u tq3Ͻ皻 @ QmA0T]DnW\v=yB-MHU>QYgflE$ L E&[V&-2I?%aj4;3nx2|xJ$ |IvO]_YPOd zEʫ>: ~_#Oޜ=C1d91Eswt-y^}'{heE-$Ph]Qm,fAk=6L?d}^nAY8pm=| o'_a =6U;яgK^dAeNECOƿ룾j颫2\RCvSf2xj6A>ZaIVc]â]m-Vg2uZa6mBLZoavh ˶'7T|it(kܮ/{|οíN]JUz*tReba_Vդ F|޳X棋ԮnѸi,oFl blAg08tXy@jg?u yăwof\82"(kj%+*637G Y^&?g#lhXAWʫe|o"'{bѥmrM̉0G =1XgDNA!2?\b2B)q7+= za/lݳ4Ў gbn0 s=0δK>3g70$2$R0Z 2|{DM' ʡAa5QErt&AŘ_;:xd7ie?QUR~DU ҫuGݧWTW}|@#} !]ݜ{?Kީw][HJ7*OlvW1@ @Y%2>_2 lr.x?z7YUκl/}{`poX7(=G.X3xkj1Zq36u=*YT݂5gdUmI؝\];l+ۀg{SrFДԥ^;XVf 44E9^8A>86H}-H'udx|#Zyd\q>-"(2`\=/zPR'/LJֺcEwt̄.e'r+K;.3"W uچCζDfQ՟h12 RWcVKgpqBClSb0JC*w FA<\aavF ůrCvd;8J1_=uDqٳJ'i?ᯜ@<0s&7s?TgG&c2cS9YdHL:~JHVsJvEjY)g>,~\? M3en7vJq5,#` qƖZD,%).PHfc V/^]diε:ӯ߯":yܳ[#a=I5p//Jt3wфI᝖gE8洕md?}lvhXCL0+ͣ+ } ˵w~VBNcQP*&| 8~k4&I*ݏs`;y:7/>߾$[)Ftn㪀]'6ܖy%ah ;G$FIo 7cB@L.$wZ0٠,(k0Dc8m^[ٻssΙؽ1m^54O;g`{zbReuJ%ðY.:j.+{ѪǩG7>Şx^I]iO6~o q~ nA ף[k(+!v<ΪVO LVI1^0ZВ J6%3o0{&tiw۬orWghUS\?O{;} )# һFl<J!RԂ=Alp$g̵c z!`y Z1jc[]~oFaoB+ l?J)n vAΤuM,mt NFXM{ dqЋ-lyf,spWH0W5&x6je}܅q],tr+H;, qؒ_}^ 2ٟf@3PYKrE yK9[z|wV27w_[ԋe#C/)Opҥu 0cvlK>>U6RiW@%o8NrR<]d-1$WߺhR.,䒿Pl wF9Bہ=er 죕~s+D 8kY>Y[WSDJ xr5W>w'{ ?Sf$FD!TSf]-/~#5kEɨ K.k]y5U=!~SO{,Eb4!l:WH2͞:xJ5 6x*7vŁXc!԰6LU.qj\@3\+_Haں ¹~븈˽>暇9m!ݸur<Ȥ2rןhսyH1]ކd#4^#J۰ ZU`p&Kv:0UC IeIk!:vNExS~zb4+ vBs %0`]ġ:h^H?,jS]KI$#(Њ;cG6_I46-lhP]8/K9Hl G tp_%Uuw=E^j 5#2RK^M7sBg,o^r5B}NOSwFy0#dH| dWX%Йٶ v38Uu yQbG cx]eRg™]Fa/= c֬9`:,Ʌ[}x&-'|8gEZ"jֱ`JT1닔wO]Y љu˒z=WŐ]՚"po}!7xUxntdmVi\P&[-Y]ip:mxa ]>A$ m2P &[<]6 #h˟*"OzSVCubf,C3Dhgr"MQq{2/>&c~3(0"&p-o lpTW쮉5sM )?z ;5fCTF;@mtfXK$)JQm顅yoqi~ꘪAFD^ߔs`|o; ,)nRyU~~6\rcH!B#}Xr:>~֢Uŭj&(6-WD@?A fCxʀE{`6ZEM285-ʜ鐲E466d|vm+ݸ32k׉_0a8=S .@; $ cav}RCN٤lbY6xJ37oי!q-CthH/!]%<7˝ `YFB PO).)C/SPM_݄*|kIT}wSJƤppzL( ӣz=fWTG*7&8; 4laP_1)eae-P]&*A[nI[ &j!iU ɘ[n5s:k(.lGsJ.A_ZF)@LKm$o xA*kfMc{ wsjn20hɆ擬˘qaCV螗zE {vz3Ri&Ըu{u29#wP{.4z ^-t=כZM!YƪUA]VԭgCe[EV,_bN0WA͟Ox^n4| Q6u]^A~&nmz!3jVM |sڍx~IB2ٹa;R[eq% 5jX oJ~= `P+㏘E&(kJw>P:Kź.]=>O27fBEVb=LJk ߶8m"Nn-zoP mr\%(O8)@}, 3"/xZp<WP,fnubQzv;y/PvYgirv%tIc=gW.GA VرU ^/6sƝmSuVȘ $Iq"ܕ7.ż*DuhPª/S]ɫLgWI`E4&Rh뱞 eMie8 'QO6!}EWFVv>{s5 UG3FN3"zIlU#bPv+-tஶ؏ q]Am{͎A8. '53[Zt/m6Ah)qG^uRj<{.HxڼNdt$ nG,PjN~{hZ;\;"fu ((tl} wo q`T86/`QLC qt{\…wdwRb޾e9ۙ}"meăhff(4YI%邇 ~͉Mj~gUTasvep~?7J[QL[8 uFuM59[i:NgkL5?tvbZ0[OAƃLN3}D&$T[?+7Dm2)>o)t6wBH*Ϳ/+2 kEIzMJ!坖Q7Gnܕ>ro< ">6ނE[H} ^ ;ncχjݧ3YRE[L|u0q@]=\vv3N׉{Y@@UrB,9Zz$㜗gspl]q?mes&L/J9-0CdB_f%AS7UI) ", BuO0?GZ;hqM.o U 0aZWBbQzN'픹 dF*E\&`ۦ~3][f`b10:DYga2WFMmjQɭ9?<^QQ.'7okVW>ZY𗆌=_(qS8q^u9hJC4XX$aoĎ\l{R)iϩwۙԴV ݯab(;IO? C[V16@1 LŕSGy| 7ެkNg_68dICQV#1u&uRR~*Z)?ÒřAxЛy3ҹuͼm4Pw'Wʠ'}x77Q/ʂ*.F|H3]O9Sj*̬Z+(מ8oB7o_RVWZlD"ٯNaǮx8,rm@;o:DѤڳe׿흓T%;Ѿ^ /Qw1b \ofzDaPhT`; oGJ}%\|}bf(`4_mOh8:i½o@>S E<1ִ7Iʵ@(3#k :>Ff~h5תo[`W*:էpTבk] wx/`gcrFwn>R$xA:On0g uA㏟jclUQvAΩ?_NKOER"ܠEw gB9Mc \9콜p:`g IsȂ;ol4ez5i3䵶 TL^U' ~a"Y% Cp&6Klѷ:B'.jRDBq}`5a,L"AB"+FHFر,]%ۅoieBT*n0>SSP%QG

    +]Ug)/,a ,o[wV{?[͵oZh)vY%nCSG/ cE`f#WRHTp5t?5?ez_L8^&{TzUck@!ЈRMya"H|/&Fz/0*^r=sn@d:hÕ^E k{:|Oj؆[pcI-}rFْzt-h Kam6o~ppT&R}aw)J ס?z)]H޾wl-2/>ڕo>Ay hhQ2o]KOUf K9rV*b $͆?B 8Kqh!8iFCoB5OZy ) V; 8;0=dZԟẺN<.7F/PfD3FC(]U: @oPߥR9`T:f%]XlVs;Uqn &L57!-OE!v.B%XC@<> =wf-8ByBdxD 첑3*PRoUDV|7bgXNo>nKW&?\ E]]N;rRJWKʝsO9&i2ˠQ swΊN^)Nt0dAÍYpIn,4^32(n~)"<grʑÕW_)B? <_],KH2qZv)InM1:x+л14 Q&ۼXD+|9gQԢMc'V3jӚE O+bF=TRar|>4Cϻ?֯, ;ƕYAґx7b5+xINlWpk^/X 8q)[hjvєs C5K}^6bPP5@dzulVUKMm|\fI]"|D4`Mp jic3 Hl508^uT'Dfx[A[ 4:)gwYd@:?;!xmfhA`^)V8ܟ6Rsս`ܯqYD/MP7Ӂˇf&)# D|d3-1`&?zE)M~}+2B.B&Oٞ;rrWHc|3`y-G pR]_-zL1%8U-`RG}bЍ~Qf=CdA <1XT[CLY 2|%rjzɅ龜 )ĸzIML=ȝ5qEvx9_wN\>@\.8"3>m^|{ZAl:Qd0*-.z*ͧ3%[/s*H>ߦhI;MB˜1}| 76 (YcPx6 HGٶHWՓ[f9RsdqVήkVg}7}\+R%?ރry:7e*q  gr4;Zp3iϰ@nVC i]yh#>h:&,{Qu7~iN=HǭR7v s+ g:7Og%S+Mia@`@tEcb5VJb48ʼnx @U(~U(?%-\ ybɠe%w!5XKB]"=Nn逈_"n{o%~+g0WŞ αusAS( t8cT>AyZ- ES|`4\ʒpp'ARB%{1|NW'Fb_͋0jDMDq)N?Fj]bJM j P|aU:,JԇP[͹JDXUðeIF&ikN.#D&З= K\u7SWDjG!3U.9Du%yDOY?'kote=+=50z2oɲ4 b>΋Qzv; =b/Bf9R\m"Ĝ9OL+4Sr?y)Nω`Q*Qy돲|Wџt"Ǘ;~+ YzL:mU`WtN,bJp #K ۧ3N0e4$P)[Dmn INpxMT^!g;9NXѱW%૥6)rE^c.iws>fE$~gdaBbI֨LA ao( ";Q4g$ a8 0L{; 6$Op؆p ]WN8 @twe)~J&y?5}(\$R*a/\7pk< ǰ]? ,- ʲ;0RM Ƨ&ASIwy HGNOZsW~k s睶guͅİb׎T_TgHa8Կp%`\ ~D ,2k\g[nѝhCɺ[~.%]lV-[ *ןx 7}, r2VKl{/GXO ,H[cߩϘq֣Dk6?,TDeuҲ),'XCu!U5d_͒>WF%]1[.gP2xv<3^OcѶ4=p[j 2KpvYcc>6(Ƿ".זˍ0W]:dk3t, #qk*2Nm,Ԃh g[Iq=i r;#%|u7DZP,`@o}D6OP! ~t߇PnjL(\ T+2l^ͺP61jFjl]c5 q؛"4'䫚-̐#t&h۰,X\xh>pɼ$vU7Vjp̈́Ȑ`vKB4 a@3=ܥgAFmIw|E,rʹ[s6jocetEkmג<Pۇ(ן "Bt2E._zᗢl!B2V R~_A{ JhgbiYG#%7y Ս yh$ȄuSZKx XýoV qd #b̊Q_8~CSUto{y/f\WN a,bxZqd {mAJ6o(G u{-nyN :$i#@IA퀡ru[ʩi !kgd7޼x4(֤~ԅN r!\l +({薑 hqmuhw?>F$hَ`OMfA35yj|#'iĐ#X,] 'KmUp^!$ piA*7R%8tbF ]-<wVX.yeݾ_C33hm*r낈J𒚃1zl-4^^EO86?6 -ѝʢ@P%؝Ȑa?ꪶ,n&V/O&m(X o[.+`;C-wSng$k .zTz'Q|tZJ^Ή"yyfF"FzQĬu$n,#Xō$X|h'%eP H%Ane4^J{@!< y J<-Mg6$ ieٽ'dGKl2jIץ %T,b94(-[ۆ mk+_Ȩ-s#^ȁƮeN֫؎zp"ԭ2&p/lY,}k!kG\!3 iRnsV{tvG{+m=6Z18%=vh(ă$&GuCƔDz$9 O58H+Ԅk ДqvW9J,+":~,٦tJHc- J}"`35x@bF5e('PksJXx4CJfGA0^-uyIqr“m"G0F 5Of7X! 5*ɓMÉ&3 k^.+G L!r(|f-=lI1i\.@rf >YHWǜ)XXtO6Ԟ:Ϊw7Y8"q!0#nh<<Ѻ~0&. %3dFԼWh?+˪BEL4ZMP>A o0vi.CjKվlrN*\]S󜋰C{ 3r)zgWdQŝ[?OK Yy7_"J̫H߽!tch:aq%}bO\&k e+8X9'G0Fa ᥊n\/~4aN&c=Ҫz$P`\/K(=惭b{LןSغJ7B8AкJy$ԑD[5aHWC/1.k)]٣pZz6&{8ƷZ)~7,8)6fgDc cB\XAn`!"Rq-i%o+&|%9 [bf~񍻯PH;uOGEq6v]ٺPlMi?`xNa+q4v9>z@hϕ@y6g?T\n.,m '/~O衼=AW>MM2 ~ΟlaTly|@wW YbFa.߮Ud$qo{zPT}Yo]VED:~ru5%<̑DUSUtsɠDrVLU.r/&jUZn f{3S}I @ͣ~A ҽ{ 6WTCAD 3cl_f4a,C ;#ɵ >E0+]!ĻnV]{WrAӦJ넛k^63Xjfx;ǡqX{E*Fa i|0(!ĉv _FM<xrfœDBs H|=ـ Vd{h[f}(y:%S (CzoM(U ³$> \,r5YDHalh]$ T.؇ bA h&W9]V+J QG)@,gH8+[MàIJ-^N'{/2sSM/ƪ gMfw½SxD=^M `vl1Q_!K#;w7%OŠyt4ǀ8;? tUmf:.Dv34HtFArjJ졮|QԲ96+>Ecu'| 9͘\$4 C ;R"#q ;LOp2N#)aC$D"dJ=?on<KȫEi[n(UT"PЕXHZ+yP/ b<LbUEct&-xY%c,DpXix}76;B_lV3|*b5!!M"'xEDJY)*C`~yb4Avvl)T۟$)C0`?hRd-}W.IZK[D~ʦc $$s-[FYk6KL](R+loreߋi:Eͮ#YN,jKٮe'sJ))P ``R%$[ߥ%D#~@J`#MXu [Rȟ2DR)-Sb]2e⥏ZNBtɌ>o׿n˧ĠuF;Mm'}8dCgT.ܮ`9_)ȊFY UESb^b23EGZ3 g~7&-ţ:| q ® Nܯ;XIL;˿N U`sQ1$-D֔vNwҲzOٞ[jy2V:2̝4A$D;o$`h" hqJƖG3 oe 33#u Scr\&701c÷U Rnw`&mp=禌&"7]ӧ*A&e4&E<5X۟<Q0K)螣@Yu4MRK/! Rq{Í`r<ڻ !:[К€#154Xu<~ࡓ#P^yiZI%>N{A&FRJ5C~尺DfK,)F?wyY+^LDC!_|̙6vOs,~zg󍆢G1eF8n̞'z q/G"UlJ"xt3k,w:Բ3,J<B!_L͗%c6Ѧ[ B!;18S͎k@Mf5MQ@PC0Vhq2G?H_9 vw g6y& <֬ks8,nf@q 1NkS/ikbZ'u Pˀ ip($#[cz`o^ #,@4JR VIKb+P}}f!CTY8'<J.JAfeFeZ JXJA2)GD6d.=cSuӁD|]i8UV: .x.Үۖm['Dt'&[/aur}BG8&1cT[ ie,|7cmCWLH^8NRLKhkL;#4Y'ZgVu Pӟyh! E'v>N?Weq1|H_A*-})"A w%mԷ8y5rmI7'ũَtS%.x!Vi|]8r0$TXv""Dmx$($τᲾ:%<$)YfI4b=lt*J:;Hwk>-jtGP=6Vm]+BuyyYKnoW_|M4 I@e02Le=q8 U}>ģ:%?ʑ 5SYz{s( /j趑䀆FߡqHzj8O/ /Vgsr/*^NԘ NE,0A|84'vÞM>5-8{ָ71m6jPo'MylӻEQFr򨲤{ lmgP2>bedHD:%cSz8y^7䉪I8!ڻAd*iYrKS| f#{ ObYߪ}x՝+muEa[׿$;ЛzN7b吝/;QLq=ȅKb\{gZӇCQMHš LL&֫"( +1^S_.2Da6(Z(IFhwƲ0! &ss ]`s^O zڎ祖yǮ gi G ` ЏHarAqfZ{%NX SvI$l/y:lx> ܤ"/aQ51+6^0%\-|wUDl璠gSd&cDBuctPΣGYOji?Gn>zo{jzu[Q7˪槶dxzi=+< ˼'RW4r'B[ڛHf6詈MUN?qEJ'"ẻNO?iwPxtP!/r|35aI^NUuL] ,gb^s\kUr-VᑋAFVii<(N@R/ N%x42'`[![#iXK'hd\y5#:䵸V`) )tBF[j8S_GS[h焪IoڶFb"sG’QiISJ7O\#$uV-A"b@iQ{^+ GzQl*fi*}и$f3Zl)qns.+ O6xQ M4;5_+lc.(' ncOә:]xߡ 倀jʯ VyA`+#Zzy um,f8 `J"!#7~V՗:@sw7qM7py =k_K[h&߉\E&{]^4?)0T#^)G 9V, HɜEM ^f1D$[`N_:j?e}y87 AP-2H)BOްdX=>2xý8KZG(ƨWd׻iA˪2+~R'9 e^˔) x'hNvUҀ+}?:O޾)҄Fa-#-|ķV@jе$LPܖW>QOiŒ[>O@W(3 vL2fֲF`IuKxLξ/@Yc3盽mkI*X6WJ^i_„8]N8b=')PUMzѡ̕=~+=}\=_UxyD\=ox)+[(xiw/W쮔w=')3z+hF4b$q0 G = fWznR,ceL˔;|$(8[B^1z@*iYy.l]K= KmsdTYhZbvhG ,7n$CB+N!-/z& 'M[!`ҵp-+WK:Gλ!IujFTۭ2X'ԣL]p[`$l BtLC$3,wJ+,y䞢|.ʾ.ZxSXߍ#['Wm?4Q d ]Z"iuDp[.Lg߄i{|w@ R9CKCmhOh4"YcpT\WYZMU1C3.SB*D͊?(ȅKi,t5\^!,&&fgײ|Q4ẋTݹxjcHR9[EYT߰+o@pE33in4HR?w%f~VkD(vv)kY 񢌰u,?XG"c2U Ɇ=$5@j|\@".8.;y,MY*I I3x83uP@"w;32wH}bht'R] "e\,;֘j:8!TbՌ]^@GF#44Bm|EF-!8Y;8ϵmTT$ݕ(XCۈigXsB۽암 }p̒x֣K1Ʃ*/}ʾ9qUh_Ij^ Cǁ'G!d ;,<6yy9ޘf?Em@iCpb[ﭫsX3b" ԓ߹J?E.[-$g~B>PzuvHmý&{&+wćhZsBQ,R7Bo}+34Xf$^>7ڪjOh +A`^Jܤ#TkY%<Jǀ8)(sMǽx.ƹ](썛:b3"oJ\2Br2XNA\Նڮ) LcEZ%鹴{Z0\.|fou59~B{/*d`Oz6.qE$_{Cz?մ/kd19]H0(ua50I4C]*:+m/@0]؋A#YG SovKlUqNE+WޢȞu5 @c>h;#k@!BQ+2sKdE9x x^# jhB\8:dZ8`0:cAi2#v.>8f5 Ė؋% ZJ% 2,"` զUܾ+0;"E:Umrg,s8ܺvyzZ+@>(fsK{/hk }mSڛ"Hj "zըTT*|/!TGE[4+9t '-x3 ۽ṳ>roȰ{kkbΘ]?QWavno)>T=w/}'F[aiZ";겯u̧G=[iR~9Ւ.@*a|UW!_ Ӡ@oF:ү"2>Kǰ>}.w*I<L(–9^DY uJkFf=x 7ĝtF 8cu@%-hih(~'n0(M90uH_\$ 4HwbK߳R6bg=LZ^$[LuG y wh#A$b@MfŌb28[GIwa> P)'\g [LlHsxcpZI/sV9o#E!V?LBb4>4~To5ǹP2ʑN2S,XkCXfe =b=\9Ԥ|OT0g᤮7cۦSE: iDrFm AeX[SŅrB21Q9 sXץ >V"ъ${WX=OO@.:.x+vp&喖HMgիVx s8Xkk^KkIYٗzӞ]T`\.C_l` 6Yɲ?D =6P_]['oN|0V~@ Wͮv8eTøÆ}ڛM\d}}) [ІZc1EaQπ<m@" _g0g\4ss^jq%IoBlΖBS/ oz~jUɂJ *ZHY6b ؝kC޹ΣXO+ [x w 69 wkE B&C_H6L٩/j7QdS|KL]&6YڮSGN

    RP%sb$&t )\|qՑy'{Yn6@}e{ _=}S2 ,F2Kv*7p|5$'* J2|46-t)o}QUB2YAU24_;'UE|1fY(UkfM ƂOE* lB%X.iJ/^`yɉFtQ!e蟇:Ctl{Zqaw|Iw┩jXt!M^b[)f?"ûƟ-1`xU%%EXH:%Nz0UE h|8-,kIW=L. #Pa2_ zCI ͕gl L">tjc eHJ|qMȒʜ O1HdqX“2}1ytuܠxZ3X =ɘթ6ޥ1፯*B0;ێ5җRbHC$f{B}=n2?֞u@m2^ ,/98Q/LoyZX-HeH`D&͒@i0dWӟRO& imDyw5jS*. IPnM]h\ϖsQ2%/҇xҺ5md$ocPntlܴwэ}I`v!Z {:Zye b2C۵Fl1=myΦFł2U4NLӃVÊ^5Ōӓ2**:ZEX 7{d6\5S)g]0.(2@$7q?|gb<4{&VQtXyș̂_@qldzP޾*1:hXjf>\l^(#@ktH. -`|^7>uCXʭ g,,ցB\i.񃮻RSvCk9::@la3qS9^dʞ 6Jx*{Bv&.z5c䊝1]Kpuga!iҮxڄφ#cBKh;.ȏFN9$2ڋ}M~e]>DY4_oL$THyI[w5R5s`Sg-qOO筽9(K#1#kX6ipXY4ər@e/斥Hee%IPVGKjjs[ jÁ@kr>#p 5T\x&I߱)"2]$^I7Pϐ &.<riC~+%"tf'>[nv\,ЍUjK󹊳MZYNG`+5zޓnCE55pVqwͺ_X?\|-,sCFVܷ r"/dt ܐo[;"|ɳ?]ڢ~YW$4ԼK8T_28ˡ.y?W`׻FM[䥳]XFi/e2KN5ͱ0,YG8D-$O@mAups CBF"=8+9iGބYXߌLLxm˸B“;?`E`*00,"Ze%xy;:AsԞ}*3pU'el3ǯUI햳=K]8"cJa?qB}X؉rpDҐH7 "VB4+o3\$Md&3`K&"`J-g׭ORq!?XwA.$['nWTZR4,\^3C[a4Sv=m*Y7KuC%??;`סױ1:P[̈́9~V=Ӎ<#q :%Ј:ZiIvWc0hhr.Vl!.Rm7HBU4̿OQF#T$Q SӖP3lV*?c`AXzMA2QN $qS` T@09xCgn`뚵M}dv$`A9]I=a2^&L02+~bP;zRUAԒS:bcc@Q@I69oC5췝l֓-'Ԅ*uB0mo^\UiVag3̕Z wfQc\Jj0}BN \ sցB2PDUzig*e@ &S x]VlyXYPTي.8(P>`&-0W@`t;Z©&aZYYkn'09zX*W`Uo#NjD Sfm[:>5>#yXx BBw| @S6 ]*qF%S+lnпA+K~jysM3A<&_YQnhhge|e咭F )|hx[j,fsMct#fBl)L fuWz)ދ8e >H5:33}'Tt=7Vzimyr J\*$bMp;)[ UE.Ġx0(2ZZV0-jv t ׵T cOp鶨 -ɂjM,"`K%D&=*?90KutQ #\@a3Qiƿ x9L/.;*sdj.0&`YB2"lQAP1'kjL*xFݣ;KmZF UVb+^L" poj#y+˝18_ѵOT#N `$slo˳ :5r1Ym.pHs < M'-o\#( 5˪|56,6"-`%R,6[b9@4עxꟅrmSh]F+w4x^)e;4EEv< PF1V)NIgM%ᴔAXd[IwN |XWIk%44kО]RNEuMSJ\]nZkdn.z&t2PJU:}=q|#Drn]_I6('H ' 8o_ 5qvedj:)4b]eR]^27b81N[No82bh${wJTWBWl1%2 _M2 ]qxУҭP=qVӞ|0v܊AzNrKz-J A-&jӑa'MrhYbUI5`"MHwOY.O&!v+E'dՃ.b}ONz}UQq |np%^7ބ+R|6 ԇԫSz`U"…'uk ɀpOjG +䕍 8`ܥ~}Dke}҄gsHQنJ1e#X ^wK&R*!5";BO ƨkRY;A#, Ռ0LݤkwWLµUW:9: r9WmAe.)w>cA-׉`Yb-Pz+$-W#e 5FG$m7/pɉz^~~Z}lfг9;p`粯9o銛ŇH3PGI,6FH){rmo+2$[nǠ߂X,5y«a 0[e@XC `=?>fx=f)bnvMQJ}桫e5SCۣ2L[CΞv沭x9tlﯓv^ !ioHR`2:VsgokqiCDZ(d[H*kl׊oYήߋR{n/ux z]@2ž]-\}͍X?ٍrԣ, abXL,Z;wgN͐h绣Vfui$ [C#3>X(pB; ywJ 8hyBc"%i:r]!MPSZ' ;Wa\O 6OY~ 8   IRf%2 ;˵D׊oS*&wO(^'b.]]](D*iD"޴hr9ibۿ~f& )pKwi(jK`wYv,$D,k&9V,LerW>vEnZ%Y4i#K#~h21=vr=Q0#}BLizs2q1ӷ&QpáeHײ'Ey{H0r[f}WL;1jKHx58|)w'S z v\E( iGB~&^KQ fHqSRPXz9"Y*n0˒aEJd}zoFl^(~1w҉m ^5okm]{}6snbTjodX b ;(m_1)0Պ+PJʏO!(]r-H -eL{I4ȃ!v*{O47a/Sʱpub^mA u88X[b ,Rd\R }s 6Cpr@`>k:+A0u!R>YQu 'SLN CDYOth~4KOx$Ltx^0+2W}B0x%QpOGVAuKf({GZkoeg #R5bLC YƌY$/ svsY.-iIO/0̆;zzH'lulAtv0,%-7us /J报J$]^ZЫGyEG~cT: RcϵPU3Ud( yQJ_h㌕Fέc"c p eYKW`YqjmcL-Rp(e+QpX!*KHiV8-sQFP;n=ۅ喙AS-ctHiߟE+ajٺkѷN[0cM.oQD ;-Mdy"?)Mn_Ā}/1 8ѬG [pvZԂπmwZ nK]㛮~/p5zX1H4ǎW(鵜2n$Ϟy⺧8Yz3PĭAJCؤ HM2<OF[.u=fF!BÂ6V Mmo)UC>LԾ;nn WF=A}F r8Xg@Sp҉3|! irY$X % {@P@sdp}/߻fW6=8w,[{z%/8Tı1YCm۲~G!aط"wí=a_~ 8gVaجzW`y~>uJD$ՄlhFS!e78P?:7`X!s.%Ov5s aY_GtucЈ8;9o8-)_+M&>Bt}QjE0dt[6wö)^p-#% w>n1Ue;XƑoudG;=>H5)|JV!k W|j0y r!gY1~}K%ՇwC>9 3ÕgsKF01< %1 <^2-,(K*ݻ^' aՔ~6d^lUx+}Q -UBc"2i:k#ʡѬ Dܱ:91Z`"y<2%J%LDn>0=4K}YΏbfK,+qZđ@`W=T0&׬.]P_; %`"-H[5b(A۬%PI(n'ֳQ:KcaCӤ8d?.~,GBpo/> ^n:xNסoHNǢwDDMk젆%T5Q!X&XSn"9zA]Qˢ=S\az&v_Xg6-+^mY8k{$.M܃:Z6 :gf@E$A0=P-<}xG%{TDi] 'Y}D8qiEjw5> `aSGP{79Œ̣`!\lKٓ A*%o)nLKyj8]i4Q /KZtS:a_n?;|5g/o-*=f#” JχłDcĶ4qvW[u)KDgwD:}pOݭFy1[>^1% taEVhxaPd 1E;?hK!r0U-kHle "6SB %l8ܷcK8Ju(^ ?m;}1 X;(R `x^p|&Xx$>aQhUmqM2jϼ+FpUaaD.&^u0NQ]~zO@P L9dYY_Rctɑcn>h'EPW/;0V#+%!5草j_%ط_PWDKRQU3蠀E,˙a0`6qw.Ve@QXur\1Zӹ^;IO I$\43-qm;5 AX:`"ڽ:/Nw'MO;Z8ݪԆT !هKE} P'hkp"`1gq^BpT]r\dQVV:OC/E4.gf}%Ct䚁c2Wz3E7qI"ӌ ̌x2S5ijH-T _ 34HkZwҙcX3hƇGDx?( ΅cКb1ɠ220T GN5EuFTޘھ6cBEGȒ+y?ˆ\KyHj@ sȐs{Φ#jĬvfoY:2 aⷆ.ddYl8ΐ'ό EK,!D"91u Hnɦ&IEmM^ g5WÖ>PFaQ*bw8=@&a~{%iD/:hEh عЂiӫ|;ttD0_[J4( LWMBnLun{MlrvGA]Iw8Z`X(vї\U:G/ʉYb3I*7e;#8???2CpԻivBl*& cCo!(g\%2[h^1}DMp:[|\/7ɥKdpzxbԼ-Eqj7 `<}ITCo?w- ӽeނ=JK݀# K$d%7+f{6au+9'PX,'7 UR'Z3T'},tqGknOW9yiȟ-m2L1 Hⱅ /։v#t1N,.XfCp˼'kYXn?z.غ*s2j镦^fnk`h&k^960A(p|'*VewBꅙѡ>gYCc;f 08ͿS4x6 b::۟JSIh$LUvV:j(.:Ap',۟P۔$꿳D2fs?Wl 6s5NGk#+iBvϢ$$sX@ N<QcDWX@%L%6E?xgo4G}]0o\;Ϡ@6*I~nAws|k8R{VkÅX<7 oX8X])6=LzP'%p [U:eǚydi/ ^͍=P$2hffRUP-n)OPwi /$WP26&O}Ȗ}e>g[^hGR3%PbYEpoYẃ\w!&Rav('M 3Z@c&1^lkQǗ0g]OYX9n,S'kcz3zIIʯ_yglsL끖PR!4QrɆGZ'XMr3`*8\+ MIT_N,"gY ?Zef׈$?'-r`x-Ub0LPq!MsihͤN4Si# lWjtZ e{ ْbj}kSH?WcyZ糃q4H$ʛf ԔWp9ߖqlK; me&Q8"V&!C,m@Wv5 s jF4ԗgfbS8 /^%uH7<>l**ϴwDosDbn;7V8&I aۼk} $⭌xeHA7Ɣ_bm  5^SmS+)ljڻeܣ/h0MǹcO^;UhӮQ1>Ɖr( Jr£as[|9].(D\EaAZeT;Olc:8Ob22R7j!EiqmSJ`ֈd*#ۇ Uc.S/TIݜ\p=<DS{T|8ng Aa}/)qٕF+#Â2yXBuK/8Cꕓ^%=?]yGST) AƁ ]fE5_ʉ1,%D $YAĠx(N7B5b6y*Y@a*x1VE-%m^WvDcgOJ(_T}w/!c,pJj;ϙt+ROCvKNc7g|gJp-hS6P$9e,Gjl|)+ |(Գ [=bqs\Nv47t'&]~*Z ־n A6 IAH{GM)\.Η*Օ=ejųxUA4^ lN$ }4ۭVsh~6'h ~Y&#iVfGzi$$[6[Sk)S <3,Qֻߥ©)!(=p ?lYȁ)WkLˠ>̓jOn-WdEލrע]IkZ.dщFlAm6ƵD0CeWؖ{p?䚢p*rCۍwp Qy{TEm_f,^[M ZVxR@dڵw+PN[98>3#N<2a'H ^Wyi:k3)^e^oxEQ%ê(m,=|g6zc`P6kw|NfdZ%_^Ͻ]Ίs,zӯh|)N0ްCw8 o#2%MIyq%\D8FXи+cBuדT@nE_5kad=r(f ǎ3j{;ė'qՆB:q;D!ڶ kBntt4 B:-69W;8/(=1l+GKg $"O2Ff\WCE$t"`c@"/>u:C3F?GF.A2)pg'k-ڍʻ1TLTҿOw#?.\BW*M=\K1v>ZO( BvE}K"_so?F`gߚ M`P}1̠ER̳֭ 3w ,7|z bMd<4Ss 2[lb`٥Dcs:Kqb轘>½N`ċA#avrt4$an dUXc381l$ab$֨i3B]L_.#y% gpD2 `4_V/Iyd~I׊Ll.)qۭ )Fh lR&+x 8Z @@&ia§r -z ĸ=2 6̞/$7xL [:c>sU]Ȩ{`O0K|P5{5GA(r:j0W:͏D!L"+8:6ϦqA+95XZ[ɏٚ?[:?! g'h*R6$Ѽ`4 H1} YYR&."ё[6Z Û|(O-!n:;?s dOЋ?^+3 G#NeW͔M\M ؓb/St?$MT&((N͈ ;0BHMAfHMuVbJy{=#Q;9WRkDnoRqtf>{2Mo$Yde/d $:X;(*a Mx4grt )0ۜkp4n%<]& @4fSe|/F=9l~|jmꋬt`_j.+c$(ԧ9ϧU{\:*Ux&ٰ_Hq O 8)DN`|>?(WiTsTF,Wm &[Kh^کp1@l7-$;f;edO5]SE Okd4}^cS/U*)[ U\D(q T ZˡvF4B3P%S^SGIᵞvПWVW5ib3æC T\y;f@.°$LGV|zףaʤ YgM!T8{˧ /s~8奮>_.CU;{ndዑG\({Oi Ub/JҞO ρ"ǙYJ#LGט(&yk̰]*kܥ++Oafr!;n~$ɱ)uFVOFK4_R-y6z3zٓ|={VufvF?=46#cMk uQ}Dʋbdi䘀pЇqz K7Yp=?WE֍&S;"|]TŸq) LߨRp r}ܔ'{O4p2:zvR7"!&qSA`aķlMkA8&.୎YӠw:~w˺5wI/gV3~8Ntĩ:1W?(`_smfQ Kwahy <"$g'z~kA^90ԧ`s]ئ|`iDNa݋^Rlg"hF ),), Avݯ{]wsYdxjSR_rÇ1PO?CQZW?3P!`$W~b8 1qlT>K'?P (x~]ǎFr R4JBB8)6,EE2,57zIaG~_n+Ø>>{a Y'1"IYEobd3]3g+Ayy=BNჁee-uMUKo jdZ;0d(bI2Tk+!IY ?|" sN^*.5uԚd8-_xٰY+;R4'@3x Uk)4iN?:0dxo> vR}^MlJ4OQեO .c 970x@IOx,j%º[1u, 'dI18YyC#s85pY*yyzOWz6us7P~hh$k3%yV1б5i[D;qӾ[4E ѡR55*J;0b|$;kJ׈^~rNX8jYCLg:ĨSJ6rd Rr5ciͺ% F9w(Z_K,hoJ|:s.j侀kmՆzpUt[ Z4O7eC+JSNgO5S]p&!nǠ=%~rH6ѸԷyX:sv]EKx X:)pS"#$WJPre$:lyڥ8fbBƧLEnG^M[G00gm6,`sa3-TdHl f;f~U}?'*& A_5^I}ⷯV f[ h񇉁5lI|/<:# Z6< bƛocM^CSU }ȨOpH*+)='"ѦYN_Ksx1k<0mAXTtj!R'NXJ[Ƭ|r) 64#Y! *֟bh<Ih#|?΄ՋN8g#`EJlB<51ܤv"0 ׵1N-0; feal_}Q{o| J[:3>D;^ZxͷӜb͠E`ƿc8VnΣ.7n\ ^6-Ui A 6RR{-n_KXΆc^;Ƙ;ONz?;RnwΌafyj,I!wv,p;hdcݑ>9fE,QCG?UJ[UKl hU O0m˧ /1й*|TYy貎z/Kq^U8lCF^_"Lӄz0B#rnBPGG!v=n&8*\$ͱxD&IXNAFmuj+ITj\N?E oc3Cc2E|cAX|-Hfd.ꌏ om*MnF 9Jtds\ݵm#_änĖaeȣWb͈ /AuWh7Nz70{QiN}-4rqgpVz7D΢$NJ{-Jz]ƻ ,,yu)"# :y i/]Vb`: fևNw;1n\ၸ #5Jog OogDMIexӴ#Z1i\^Mw 2%+8ձKaW*,"M>SO;:n)y>E<(_i5_"8"Y4':r: yɳFZ)ÍԃSq!㍍o,nm^ cnl8qt"B; mY% Dd;9-;D姼r;!>ziyf15M QdMbV͚4; Jщ=p<LFd23󩂔Ӭ2aWٔ%*Pk[A_7?ȡ# Ui`~CIr=H~߯ 0 P47Zٿcziٷ݀޺/$d{M4&WtF/*$sflFOQ vO !̙MQp~c)%gw|֪*- ]J7+ gعq ء4P#dVEi5>wOF\8 Ԇ2EQ ns]=ſWnY<*Y Ew/b65Zu*kN荋SY PkuN@';H*ՒZ\{w6M?uDX%燇LڎSpT~#Kg ʯ]b;[P>CI+@4C!cz3<ڎ”E'GkW$x qAJNp\.yT.3+ܻ>9)!w c[&Z'鑠ۊ]` M0b&n8 y,}Vj2B3瘾[yHGV҃(h΄Y_4*Ph[\\Hetʇghn(?jFУ}jT{>,A>ﺊ G-h'U퐞-byWv:Njuf&R~QmGj㵖c q'K3Td,.Cx/-u*z`$K6-~xЎwt`)! o{4vL<v^3`Y6Xsd>nJ?x)x䯲r@@p\#"0I JV}S~6kPyDQGIx8Y#U]hc: 9*aur3ՃzI"jnO)^Ȕz$O/ r)QS$CN,7![&}쉌\0GY;Yql3$lխqdv%>Us0N/>rv7;vX*Sׄqq A~a^ 3x.?ZXP]qkwE7t_ C0@nTYN_*F)]?FbQ#zj.x#a"td7No p.!#v ejp/v42ߝC7rj8r_\R`5SRYq9s?u/͉kdI3^+zJnhkX~30 ĥ$i!hd}w9Τ34P V@GF4QfT(ZhM|viRs|рs4$e,xkK)s3Cx*Obe`V+GQ~ tn !>3:}QV%Y^xѰ|ؚlovP#Wԙκ|C"1-6EWN\>6\?'Gd wU7wuE"$(uP"pV_D)|I9+0dסġf 'K߾ `YqvA%-qo_wbMv> v5T`9dGBdπb@ ΍h4C.S2QhDbO|l@⧟59zsAaU߫z hhD_1e`}zե Xdqm{LP`&XIr#3n04/9ALP[ђleb)8|1?9%[_o+SCEz_Qmڄ h׍!?q,%6\/Np 2~=YaS*cbڀ %1N}gfFW$܆+&A>|d@"(*@Q5CT$hіf؉s2߷<ބ ͸ދ/ @ 5? Ap{(>zhLbՔҢ[N-E~Xݓ2$-XR=V"Qk5ʘBj|-r2HRy,hS{b׌?soTAzk L[dZ9צj@VuY<蔊*>YV6~+LȖR݆ÂSs[3_'ƺѯp $K0W*SO 6#Dxsj@~9m 5~%uܚ~0$N\ 7kH4jXr9- K5Ys3\L+o\xw8*N}M/B/fGt~6B9jsi=Ћ·h ?s4gP:OKri|>VşTnUf4㍩#8암#=P>(N:is=ݸmT4w 2Vj, 89ƾup|:#J(oz)hu72+$CfTTiњp u'}~Jk9B^jKX\U{#BF5͟pc,=_%2 6W ܽ/*%^dk[(cx\ń-f`y%d/Xfd|i-a=HovFpdqMHN,l9.OEZ,S3|`@yM翫S|&,/>ăjcC%ZoJcuc5)wT4|mI,cj_ kJr_7Hwڌ~E`F_.˟佉cd7ɵ4#i{,]~FxjY ?ůȺ\2ev$ۦá;ٲ'u_,kq XOBߚU.r9'VN b#~4,&5A!uvkÖrUɍ%4OTJkGrh^n)j?m ,yWbW񡳾Z7^vF_1y%*UQTp+ՆC[D:kGe?3:|y^{OZo]_. 7j4 -.zКȭ_L[lai4w9/#<CS'Մ'FZe{V|eCMANLot>s9ugvp.t !c?.0ퟅKG\˪_79S ְH6dV>6P<2)jyÈƵ2 <=-mp $}bw N"m&3g CS'Q@eMX?[ z4ι߱$?Q(E$30| Mfɴ}onQs xP Rj7)Lnկ`ͮ c=vwWa?1TQܣIAk?D.'wmKL h>7X.rUН>篛>^zRQQ>ϞF@)B K>Qm6Cl WK>B`:9ѳ`os<܇ IރhGKMŗ)zSYܑ3ż> ǯʧV8{Pc:f\J g \glpC+3sR]e#E07b8oΨTXS.@C Wc90T ex B- X%V!Ryʪԅpzhh?M ##*YI0b>廕%,PIlWLQqFN,"ͣDq(RFz4̊ pX{[b!ɇA$<5f oLr7 5]ЮZ(Э-N|6bWϾKU߅unPpQ%SII~3wڼLt]n͸wV kgdm7 ڨ ߵRyץR'15\-aOiOpAK~ei}'ok(\6پUKri`ZUS2z| ^whK:Umen* Nbm=6(p֓D7J6Ŵ!lW`U'˾[]Whd6@]{I-A9|1 E@sb8 q*hA^Y?KKHMZ~Ju EeG (, # ǐ,D \523A0(Px>-XN9tQv%@NSdIISv R2Į`:gŨH~NeXB$V($s;!¸JQ5a'Zў~N腤&'22-ؙhQ FL@g`MDL@ͥ`/'U  5"ˡ؝^$eґ9 ttSCUi.ǯPH5ZUn~s&> =fIl䩛aZIJks'3 kq`_[/%M54Ŭ3Mb<\gWϛ.Rsπ=) O#`/[F3[Z7è):wQG{<ŏ&0p$dUORjI@]WB3 I}! G$Vj00yeTR,x cf fU2C#Z*M} nyT֙xw3Z?/8enμferjJ&@%5Lvh6{} m^,A>{"YE"ߖh.9xg WοR,K-3Owؤ^ַ]7ģVᶱ_YU y lyE6e vlqJ] .m# [GBlχe$- A5p_J\1%mLPςeއƧߙ}㠳ž>]2n6~Dhp %EwN p>H˫ClqiX;ռea2gɁ}*@\}~JZ~bg ړji[cJޣ(ʲT.QF5x+\Lx--$18"|Vc~ƜqJvi"Zp@"ZC 8)-=Ī8:7„p{ }O@v)9"bò[tB%aSTy R[Vo"/leܼ2Z]Q4x|(3塺TS1`(}Ⴠz} ՘lnB/'ӿ2Ɲy!z} 8OOC{N|ub +9nE5v~ &@QWw, _+"St[aÒu";^AnXb0U@PJ%}V2-z\ tS߫LJoj\8|W-ZP: _6R;mwogXTWD2ʌ?_zIUJf*\^j( ?Io Y.݊@fT㿖5 (IxQd'';NcNSÔ ^^KS =祸O@cUg(.X Ujǜ:Xb&ՁG0A؀ugn.p@mgC= Lv=7UU'6PR?hWMUH~S'\%fUsXP,dL9KYS0c.6t2"Dbk~a*QM!c P }SVt . b@g7Z^6Ådki5f7"HQ<aYc;~ۺSipRvҺs,#)mѿ}@8s_΄JVYwb'8b-͹̸Jƴeȁj3t gtab0F8帝~<{Ȍ y}T1HQ<i0j2S2W,X%ܔݩ6,z^g\'cr D.ªBU373g;ol e>[UF^Dkß]m!_;2I^Erhg!ÔnZINW\MY&e ( !~,ĵ?VP[ 12b%JL]` @a26 |!2cTyN[jz+8gجb%:HV' h5)o\֤9& IKX 3cw8eky+$5gg=䘊ao WvPV00htΘJx_Մ@܌߇م2rD¹h0Vf J?P'`?7C|X/0gmPW arg1<]'v{'(jZOh1e X}b؂X-&ltq)gbH<#t[&rP: fi? HU a}d@JW˅ĊJ43{5Orơp} ִ#eβ2ZD66Sc*AzC^#vcvŢWtPfasvhon6.{d;RmG)iDw!k HU 8aIG\4%D욣cJ0id`t'A>):$30}-A`H[Z]VJ@܌yaCwm1}H/tEC\&6>T e,q qڰ#To?宅!XEaAé ܇c^)L- xkh+1>5(a4 IaidҶ*Ulf ݁-85<dOʺ%@&>H *e ,5cˑ!^dXc-ma}O[tl]YN,re}i@"TMd{ŊQ7-=;5 0^ h^d[Kж;9|#Wh+yЁ L;36Vܑ$,Wh739נѧr|eߒAt wszxӎ~qk]3DMɚ9+S0[N^(h;oN l$"Pt Ԭ 3+1<(LT3%!k\9fA^AOt"N[fe5pL(8W\à &jX#H83߮ާL@O\#;njٸr#cjYRzk)jIZXqԞ{)'B2NYN='״^<dI&i[1A;T YN:wsY;&;2yd]UiۯxZcZV]Զ1~`zF=Q"nSU'xQ[n ClLikY\SD= ʂp KZI*Lt)^ ǟU$F-@,i" Gyç&u1'? U=Lo ^E&x)Аx "O}YI5qJ3)ٹi c]nc`T)>AA۵@X'SAxvp7K2=C ojƻ[[^㫓#!{lKs@&әJQYR٪eq:Gftc'17ųQJ0N Z{U_"ud]\Zm''sÁ\L xxۈΩCl"KjS n?f-卒[L+➬b`cT* Ӽ+kOh?U<*eȊ#{Jhkbμ&ʶ=ijMolL㥃qxtXGo%AzZEuƚZ5&KVp4IRHVzf

    ,lٞټSR=(vkȇ\@vR~5jY$JM6:uE57cJS/<_zw9*5wVotQIߴ5^8e!,>jۅJ*@q)،Rhi!dNrDe0T:XI}hN*>7[KabEaxMzs1J I]K%5nk힅b8BRxح53'zPv1ŮL65+ @N3p/M"#|v9wR;H<1JLfϮ4"l̒)JN:ɅO[NT'~Z](rtߒ:(2ǥ'5^qVsW6KAͯĈRr Р>Ģ5x'&߄̤gƀe?J@Biv UpWfyuETEZXrg-JY4T_H2J„쳅a̝"7)D޺zK!-o dQ10}@Ν-J^r'Z;e_'rcxYExd;6͆NQ)QqE<XRXLm ѭG4*^FFF fPc~);.r V#qX8 Q.C xs<pkWBQJּ_4Ӛ9VcK{fR w/x^m2z䢼mQyl]ݕЃ!y!qzPSm;4ʯeVI{Jf72 $P,Xׂ0:kes5r81wRӆ/q,YnLH1ǴټzMR5 jqЍ*3wKUr_[ '=ިswNI"ytIQ[9d zNo6xBȲRf1#u)c7=֚Bo{NK(ɝRQlLpp(K7Zu@U/ LF-iIs1 <rYM˂^"jS)aREJyrB)*kƖ.~sdƈOfH qjaí7~="]]$A  85ܶMA i%?=Y\Q0}(ZwuD ihtX["kwQlrRݗK * Z6.+ _)<Srk胝hmY$ Mztes eDkKa1*4\7YGeш=s׫g;y#%՛!YOΔq#Y5#E6@[zX6;8M[ {p#9' oqrՇS!f |ƆYJ`\i3PĊ\MP&FM"whŪť VT_Oax8j6aXӤ|cSDQm,:CG>4L2![$YAD6})QAp6/+Rut3v;F,t-뵅%7[վ1WS8DJ#% X^]GbYz; uTc`Iw6JpP΁8"NU[J'j'Hm[|;8Yxܳ`S!6y@ջSCbRqB74SD{|77goF~z"@2&D5p/tOW4m[mu,2ԧk>#:0Ob6Cԅ ,4!]A~j4McF'Lֱ czr?#Ie4Fȧ.9[QNf 3>IB$"!y7ē$f/u`EVBS+6Gs198̳ N7m6\ |kۼWK87s΋IZ!s ?ilQX>6jewUtV%W/n]4~:ѭO effֻh8qVojv|_qdm4| *=$Xos] )}/#[ͪ?.pT'4dfqDJ|s77~%mfP :)~Mhm< ,V9`VNVwMnYѮrj9okj%'oߙ4)Q>4D5ZWm] F!YϨ)!? 20NҥmhџFøDlf1R?++1t'QvY6Mq-b>32]s85b¼X yZ>4'\7qz*/+8o{5|ѷ0EJSd"L՘<"@!o:]9?j˺[%rBgbAlEJ HOgucf=f ~!I*7)C9 ['ϊy6<(N7 vM?5l<%ԷoJ5[CQϼNsX2Rx /@+WuP.KԩiK֓)oJ1fߢ׃mZҩAY/).&c,홻X 5U|vhl $nxÍT쳸bռ91R){L99N)0Feg2[ _埠zXtT!)٬g>WaЃx`Y2t6myL{J [᥷Me8!~QGJ#EgˍUi%{yrN.>S#Y}ci%!$+(U!;2{=Jx̧rO\hoTw+)mezb;;PA`9=Kd%ҡ,?2m6(/ea*=Ҕ04~ce*b*Vz_B'oo{|ρ/hԩFf;`ūDS' ٢F^O'&"}O1*ಲEMɦkekL(F c"؁JVS4a {Iq6n^ b`)R'fݶwU4WZNU#,Up3^SONjkvE^(ɰs(  鳯$Z^n%xA-hm*G?́VUO̼](~WPїvT\IV+&)k;c0{p0P/lO*ޒx.s0CnGi%_n'hY_"zzO@O@M_g)4t\\ׁ߱"ߘRZ .OWݚԀ n^Fbgilܫ\tXY)qNV#k$Mrvem|KO#mqiQbnjt L(3Xb;:"$Fї%Ȇ#G?} +#FS%07\xڲ5f=sCLP]Q\al?4 Húgd#5@3D>>O6wmL% U2sdý4?ؙz(`zgdz( ,ғ= P˖'^% xj*+'.3 ,(&{ LK'Q^UèuAЯuЭ j>]ʯa[hLhi.)trQGqWY Cl2&L#5mA$(Lgs*V\,K mseϤSE %ɪ ]A(Qއ9 YfQhoԍB^d3Vxl*`1"b+,Ǭ^g+0GVQ5}m*-I$΍$:Tf07DK7Ckݖr~p5C Ca&1υn €־5i1"|:,"Ew#lx0f!MwՃGy1֛"8"{^K!<.Υ*怅 7`#Z#l :y U#(`M NwarF)}X[~s]CZo2O^cKщ,*ɘ:Cf{*5tHbD^VjfхR0qLhAsi[}}OϤq5AeD/-Ὤ'M~Z/YC-q'՛yKo@ c"˴*b-73Պ<B>$2 ImX\7z;h ^"=J%%>ުb1H9RH$3bݓƮNtyr(= :6+r?P]ڙXR&mM-ޔ撪fI!c$}rӫrg^)<_F3N;@hԹsNi`\'>CQײ3J%^B<;*4dݶ4Hx@{dXq2(:VJh[ zam[ھ Vush/>RVȺW6!1cY5>"-GA2uFv^302F*ߖTd'+y ?h{JO?d{הNf+;:͂?jSe^)(W:bQ2S&vfJ±oya&M3GUdH\d(%47d5ROF^J& OFRO^d~1>07e$A@ עd0p:2a 6~I_f0yL, '* !x]Lhffhlh+?{*J m.l~b#D^4ʿC%PD|޸|nFiF`KzKeSH-xb\Fz!CquA2X'I0X5m @L(F_Ǻ#H.&])x ҇`>àFI(E]_0S84#!NPS{Gs8 5YUD[) ;C-d:9QPt^{o셑_0fI*DI&s/'( RͼEI}i̿e<UfzIc v5;O$3OX)'\^V4|5Ei7a݉tZkzM/;Ac9 LznC[ d^g'QT#uF5EErO"6zP\bx(^n41=D~ tźȕRLd}ef.j2F6١d(|y\C()y K)?A */E0df$uSԌZ)/Paԥtf7V|!d[7v.Ocf'K{z64mP7#}(wEJ .?m_wr!Fl[55F)`#uX*IҒrh{fr%jiuhH<н'`4" o5Tn8X]x{יrL {?󨦕`E"gJ]̱6VR*i>zZڙ9G;EXh$G0m*Km3 % _V-_ "zT?89Hft1je66ܛ/}!!ķtsd[ >3ެ׷r-I)”WJΐ&f+t|#kKcR04P39MA~xe̢|3[J fE'ّEn7 be$ 6Ʃ׵73AD9t 9YҌJU;aMɜIq@7< -;Vik4D,2W˦xNՒ5V"ھ`|]j& tI 3grZMr XQ.aFen Ҋa{ P2,خfґQI~cn/t4ʶtxC%||[d) ۟I3/GY؀»hdT*4]c-G򂆬lԨ ڐ-vZLkx.cNTz6| $>m۱p!fwa|۲ Qij jʚV۩bPzFYo cS99p!Q Ϩ/´{=w#[l.je#gA.mtX}| 0F8z4g*@.y^%/1гW%s' UP&*FVh^+pU#Y*@JwP~9s\E2kشy&+i}ƿ`rAT⣠2p/]S{? :|]0%6< K4^Nc67;,Su8"Pc'\aԽYѷ^m9Gv"H?YI:/X5WHJ f\`O>̖TF-xD1$G+#pis-u7^9]3֓™7Tlwz7DO1<KP' ɷkƟ]5A8pN۔GM5^JOu7"$ym۟nh^k^ M#'9GI"E9 w'{q"^ei6d~.JQY(w!?6GBm ŶtGMHT ^VO5|@OC/uo;-RYHJscV1%֔/[.dҭG-bh wOR4)6i1 r4Y >")h(k`]ihd)EkarL1OG̛ȿILEniwYS/N,rf3<1SnʭS̒h "햎^f`[.vA=orUa՚)aB6-6)Ҿ+yCnP7 7ܱ"yM3Upx2bLmC7[ -ClN>i3"ڠ'ՂUN̒8`zI2fgkiTy/!['h+@ /Wڱelfո.}M9mLHr.PYVVT0{.5o3~ k 0~Y4 ms崙ap}R@<7j潿ew^ZnJwt#ϥfTNF}Fz2O^&~9)}dh|HPr4-ԂBgAHQE^pkT yDHK\?P$ݎ^k(e 3)Kc?59eׯ\VCCk[^rozHw{)cQ[rME[dkp0V$ 3laac8𜏁S@ : #p0i;s_!V[`ڨOi߲Sg?]B/s~Ls@4 рg}qi ʹmg1K{CsL/B~mar5Lwrضwުᠨ)kaO4Ӱ +紼#`=f$>.5]e{5LUa/)rH9ulB6{#ѽS]Ns Ծ+i'(èQ oXg֬;cąS`${iZN=UR^${xo"NмwEAPzyU֞^HG[J:%B`ϸiVS콃>e fqt +ٜ)ý_Rv_{RaЅ d~t%3Ծ_4:+7wB]a\6LEy ]RfmmZ3N/HվYgwqs 4q),8NpG>PU>Wx 4k/$(:(xxMfc!_ W藜 =jF"̵ "o7քӘXUl @T@eZ( B?$RVtj](YX6OV[:;ѷ+~KɹJ|<rJ1jMO7,fo( '&LԝL2_4#ۍ/wc->OmO$!2öB!e51dEP@AJ X& NxE*j*߲ A@"s˩hkI(P%`a ƫEX5A\+P2>vUAŭNÁȈ_kk@۹ި2G`ؐaPï*ra&U {O$}߽IiRQjRn^~BDMnOq.{!! gժr 1TbԝVžRi!Pߚ2$֙S5 I1#DkGɥqiFWy< 媤*F ]Л ˑP>ؼ0S:DWp؎2yA^s*`!?csR#uŒS>B~ JeQ`!)e7.B_1f5&hUXp^GAUQ9Bsr>V`O61hy8r;D]R.VXe ~/E):GTd6;[զfN6|<o$KkIžS/EqH"R, :шY50+a&]lHHya"Ӵ5u"p۵M$p %oW@F?xT}&/T͜iq 716=DJdˌr݀VUx?p¦F)DT: mwcvOB8ma[O,N C3@3W FH]+m論~Mh\_W返7~5Zico"_BpGlV(-:?~ʟF`ѱәFHL\T`a~I5q;I&=ʑNd^ktM #К:'2[wSӒ,|E[{*lv'½8'й .Ztwg:hWFGCY plpH?Mɑʌ?DR^<[~qb?6\~{Q7n*ZL3`i10Bfh%fxeͺ3oƅ67gԙIZbYNZ ވap/ ⢕QNtH \dhHf=+Wp-[u0jLp/{M}+e/2/=:o q;JA2nװ4w1o$9 ^O v!P/mSpgGnKxԶS'H'@ ]pc6-Hl.;ώ,7C^*L-Ya:#wtzFrCUz$Z&;RR(ДľexYۋe{x{eIA:  mN)j/}w:om%g>WfS#sa0nkz%1E(:2#%bC q5BI -#ݹpP܅,M -!u"^hnclWU2晋ɘQtTd? "ٲUo`.O$ ([QvOԶLc"Q8DcxXc>(3xb{YaG"%zu V7CCYtԜL{!eݧJAgv B5ȼ2  bIg2 9/TYgۃJπIûΔ^N/(?M _0xU;Q Zv%uznd Ce0 qZnpRD{7_qn!tRc~H>Ys-e8Hxwe.y5=L$9繘g]z- )P_sh<&Xs81UjP~xdytM4aԙV~ ?`W9/٭ȱX#msj%uTxڞ^IQml*ME 7spVɖl\BKBo9UH AQ*[g#"1 S-v)t%@LȖQh&t\e TnpہџpZ \ %a$H#.Uhe0NKɸ_^d4kk‹k~WXt#i)K)&ߑXۑtBREie5_ b'-;Mp'6`'NA~i]NOG~\?}Muv @<,çﶵ.gxDZ ;F=Wa\0g rRNh𷇓 lBflZOV;֚YZͯ Wf YJThY^tn\'%:-+)jߗ7'o8 Z)>t(nd=٧Cl$P){ӉqĬ (Q0;U= GY.| COڂ5[ LuO0oYI`Ub9_(a-Q%߆J~p0/`:*UYFF\5;"=VF2Ζ?ٶNǪĖfAsOsvy/w0|'gYed$+X86Q6(=u i2zB [*}HJEzw٨zՆ4^J31p:镃]ӗdKo}u@B/^(.6lѰTH ӿhbSsqM g躔 Tk 8xVAa>NGFr2'ԦRxn EoHfPn؅a YZC8ӧ7~u`"G'l@ :қH9]N]Y|5Sm lVWߌ~8iM/U$N~p k< J** dDC"Prh TΉK^l9YBj- G6!M!sC+mV<6hrA~dzD7{{OVFn#FhUx<1 9v9[KT#=~Z\SݾcC`8'8W9ݽLb8^im$zwprڈF;ԈŔF}:#Sx]'xph{͡-abjX)2[i=XE`Upʡ:m о1kRa5q!Sު66VRX\ZF+w(|Y4Y?ռrU/QQs(cupjć?3y9?<+J"AJVVN(䗼 r2o~^$E^h2)>`AãYɦSEJKv-uDkJpiF&cJ͌o 2\& 嶲0F~?$W$ z-@-a`fP-NKᾹS2Q4؝ c|g}+Q"d|Fo$dLk 6YO]Mù#.끌44J6ED=\tܭZͮxj(+!:YV #@2?m rC`@HK̪?泗5^Uts0KB8) RX^;u'gѴ};\B ̤am&?7WLD]Xpۣ@&/N,rP1O>y^*nDm*{KCM>-p\bF;J{80U P^'$ `(|Y;&N% V 6dcTJ;EV9{"6"qShd?1, Tz.AoT&@trDhDnkI+8+Eֶ'r-&m+Y'+" ~j b xWDZ/GjI`kD^pϪet^>Խ.+T|Tԯj[Ks׾~#—hV(3(]q1|Fcٽ†14W+Nx˕I $1,i6S -e ɩӳ }MªP(`_y1[*J L+f_EBj8).E{T2lzߚ%(ȱ )x/РJm:/ "X7N tocNN Ep)^uA&K Qtہ{<v"ҙ`u,T8'v*XX0W&񭧯!n f60JpWPh[@nָam:HJz\šQyRR:ln/^l2xTrwÑdBk6&l5uҿ,'7wcvt[l5֪}[AIW)!y=89᛻tqbR{VJhc~b` { "p]m #RK=Nu1*fobMZ#Svazb(V&hCvFc"m Y.pgPJhr *LlW&@MHԐU'yIꗓ Ӻ~:>ƹنtky"j?O§㗧8#ˏr>gqd~#4aq]gS)qxJXE'CAoSC'4l$mKT&m_Kt>z mr䝃SL"T_C[n 5y)]bd/GEe1r|ӆfOpke9SJnGWQ SLFԪsy_1!,KHy<ɍ^fwv"jKKw55,o>P%8ܰg/ d/kT: t&?"SWJZqcv};ÃPsеC''lnѹx,D[!3~ɚcDLMgvh44*2v#*_ ´$M*9?pJsAUP5eR0~$.K*ޣ;BdX=qygj&/(jua!TfA^GWa HÀvDc>ˠ"VMO2|IJ x9bSé(|WPa< 4 DjIyI 爫[I nia!IuŢ;L; Ax2ef W"{1?NjBiSUd=nJ56o=Wq9hinW;;[ckŠ軭H02R{mFx<,طAwtuӊOjK׭ݷ#eڻFC`Bf`f/وk[d_Ax)ÆQ^n,s~RPg! '&5yd"׺=?xxt:yoWzo^[ ֟\X¸@{9Kdgd8xUJ[-ӐLcdC ){d4ζKc!͔@M2^"K9ܘҩW}H@_p_7FLZɂԀE^}D>+ zsf6CqT EvKB;'ӕQGgwҼ̘471vj Lt:˜>SKa8/ w.GFaEƘ\A}7 c/WeڎMX]aH_XJGEbf~< %F ёK}kogS)}7~2ut_ߝ՗!WZ@=ʼnDQS$\@5jtC~})=fX.y>Ru 9u=Dw{sZ0_%%cnَY.ĝ vJ:i ipSOP=#jnYE>,AzWy> mn=|? ,IJ T/F>BSC~'2=G3qS"ܔ6z *ʭ6?O7{$QDr0n`2aZ/ktb2:#\Yj+Zr:)||(թ& 368I29}l փNy}+8 N }=O9@KM2B! Z."1Qt⮂ gul⣙՛77Qs0M'q+ﻶS7 2a#(fmZHK+(˺A i6*QৄZ3.ꏑJwVgc =Oxok#݅k6.&-֨>FwX<.VzBq5*<6յ,44%3 EA!gzD K4RA\i!Se7cҢJG{ܯ&_S0o:-&z\+ThP2kHa/59fV̽8Nxlc۲Hc2͕ɑuB*p"&"%4 z[vk j 0=zpv: \ܫ'! gmǁ}ZT:QfYS}o1@UѬef}!6C V":i{ߪi(GO0m܋"VL.-7(MA@}&6L(pj6{$aYÙPNܾԍrm:C)cKgl[$ # Xg׷NH0 i1%1PU5P|nmE9};4 4[-|IG׎0$ܚXHDx ZYDL*9xHH*R`2.yX-i#Szck?^3#!Zd̝8N二]Viمt컼Q^ 1F"c&oݳV.-t@]-x&BL1l@070X |(t=vG'Ew굓;f0 'hQfX++Ta`6ڗ]×Sӌ O{BC^n2ݸ|ˢ? QO;+PCY{(%%MvS1.`R딋[uRHJ~B`:9r.]s+ehu;pM84+@)˒jcUɘʦw<%[;[,2dL %b7{t$}zz9J,W AԸXXT(HJq8{}UTp%rzwwgMSquG)JjԥNT{L0UPH_;uXT[8h譗E;ىWK#ח.7uS|nUmbgeWH'n`8j}hn,ԛp*>3NRfk89K* 0.B({ XxNSଊxva&1́lm]C>-SnW( ,vG,*J w7(}I !{?3G`9JpT5\|ׁ|{}4q5¸#uݪϽElTx:jdZer paC餾0RU첋#+:Ad[fFP4D2rDDhG6G=v?Ac![3Tz0ƶ#nz8R.Nw 0'L-G"Ťi~IK q4L G,!EWN B5T~;c!BQG;Mm>4HE:@Wa.Q uIMO5?GkwQ$b}6$tld\l+&5Ii(*T@@I+<(vY~--\y݋ ;_!7%JI5k m_w\>͡N_-?[='9( _. p6cLlHZ" Hu)rq`fAK~D.|۝=F\4|=}sٙ9A$!"*PZ^ jZxDnE^yOC *jLߕ|@-𢛖&Y*|]wvOb&r40h;LfU0Kҋ~b"e|bBKd%L5fk{*߹܀si䜨𣷅zdx_-fS] ̺a-q'm݊2qXl{͂RlPqPF(=W2n3h<32ǪoQp5'l_WLZyEj *A8ZhSK՘o_BeobߪZd J VsHZNplYtD_2KxQG/,aѶi򄀿"8jTTu۲WS䟐5e6[V%x >8<Itچ! t}`ҏYgaSqKCrrhc+c"$DZ.u<ƞ]0Rv@NeUűȾEY S* 9Y@:bYd:=✮{ݕuOȥ1f|Ciė A.EtP-:K|HW @}h^͋iML1q*Bς%.@I=e(m֧.Wvm p͕2452~ut{w]N.+D١ "۵Vkr\עqj=Q5@e3ma/BascNf# rI)`Oc ɽyllpS2M7ɡV-HRDcYB :*} BSnĞW7mK*%Fb')޶ϛ<&Æh~EL9KxV8 i}(_j!.W_*sCBytlo"}EWjԻ4d/߄R#4lwXNB#قMHKV3Sa{G\?Ai"Zf 5w9|bphF|