ipa-common-4.5.4-10.sl7_5.3> H HtxHF[2I ?*}}$zgu}s19eEll{3wT3UA_8cce4f430aa651b0c4cf2301f2a50bb2b0c2bbdc:x)ڸQF[2I ?*}}q/ⱒ `)ŬF@)uj{KmZ +ь& >><?@W@V@VVZV@U@UYU@Uݪ@Uݪ@Uݪ@UoUU(UK@Ub@UJ@UU @U hTE@T T}TTZ@TZ@Tp@T5T@TuTto@TsTl@Td@Ta@T[bTG@TG@TFJT)IT%U@T$TSS:@S2@S1oS!S!S L@S L@Sc@SS @Rb@R@R@RUR@RRx@RR=RʚRƦ@RkRv@RG@RiRz/@RxRsRo@Ro@R^RW@RNR@-@R/ R-@R(r@R7RZ@R R R@R@R@R@R@R6QQQ'@Q@QvwQu&@Qm=@QZ@QVQ(@Q@PPPPPx@Px@PnPj@P\VPG>P@@P4P.2@PP @M6@M.@M.@M.@M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Scientific Linux Auto Patch Process Rob Crittenden - 4.5.4-10.el7.3Florence Blanc-Renaud - 4.5.4-10.el7.2Florence Blanc-Renaud - 4.5.4-10.el7.1Florence Blanc-Renaud - 4.5.4-10.el7Florence Blanc-Renaud - 4.5.4-9.el7Florence Blanc-Renaud - 4.5.4-8.el7Florence Blanc-Renaud - 4.5.4-7.el7Alexander Bokovoy - 4.5.4-6.el7Alexander Bokovoy - 4.5.4-5.el7Pavel Vomacka - 4.5.4-4.el7Rob Crittenden - 4.5.4-3.el7Felipe Barreto - 4.5.4-2.el7Pavel Vomacka - 4.5.4-1.el7Felipe Barreto - 4.5.0-21.el7.2.2Felipe Barreto - 4.5.0-21.el7.2Pavel Vomacka - 4.5.0-21.el7.1.2Pavel Vomacka - 4.5.0-21.el7.1.1Pavel Vomacka - 4.5.0-21.el7.1Pavel Vomacka - 4.5.0-21.el7Pavel Vomacka - 4.5.0-20.el7Pavel Vomacka - 4.5.0-19.el7Pavel Vomacka - 4.5.0-18.el7Pavel Vomacka - 4.5.0-17.el7Pavel Vomacka - 4.5.0-16.el7Pavel Vomacka - 4.5.0-15.el7Pavel Vomacka - 4.5.0-14.el7Pavel Vomacka - 4.5.0-13.el7Pavel Vomacka - 4.5.0-12.el7Jan Cholasta - 4.5.0-11.el7Jan Cholasta - 4.5.0-10.el7Jan Cholasta - 4.5.0-9.el7Jan Cholasta - 4.5.0-8.el7Jan Cholasta - 4.5.0-7.el7Pavel Vomacka - 4.5.0-6.el7Jan Cholasta - 4.5.0-5.el7Jan Cholasta - 4.5.0-4.el7Jan Cholasta - 4.5.0-3.el7Jan Cholasta - 4.5.0-2.el7Jan Cholasta - 4.5.0-1.el7Jan Cholasta - 4.4.0-14.7Jan Cholasta - 4.4.0-14.6Jan Cholasta - 4.4.0-14.5Jan Cholasta - 4.4.0-14.4Jan Cholasta - 4.4.0-14.3Jan Cholasta - 4.4.0-14.2Jan Cholasta - 4.4.0-14.1Jan Cholasta - 4.4.0-14Jan Cholasta - 4.4.0-13Petr Vobornik - 4.4.0-12Jan Cholasta - 4.4.0-11Jan Cholasta - 4.4.0-10Jan Cholasta - 4.4.0-9Jan Cholasta - 4.4.0-8Jan Cholasta - 4.4.0-7Jan Cholasta - 4.4.0-6Jan Cholasta - 4.4.0-5Jan Cholasta - 4.4.0-4Jan Cholasta - 4.4.0-3Petr Vobornik - 4.4.0-2.1Petr Vobornik - 4.4.0-2Jan Cholasta - 4.4.0-1Jan Cholasta - 4.4.0-0.2.alpha1Jan Cholasta - 4.4.0-0.1.alpha1Jan Cholasta - 4.3.1-0.201605241723GIT1b427d3.1Jan Cholasta - 4.3.1-0.201605241723GIT1b427d3Jan Cholasta - 4.3.1-0.201605191449GITf8edf37.1Jan Cholasta - 4.3.1-0.201605191449GITf8edf37Jan Cholasta - 4.2.0-16Jan Cholasta - 4.2.0-15Jan Cholasta - 4.2.0-14Jan Cholasta - 4.2.0-13Jan Cholasta - 4.2.0-12Jan Cholasta - 4.2.0-11Jan Cholasta - 4.2.0-10Jan Cholasta - 4.2.0-9Jan Cholasta - 4.2.0-8Jan Cholasta - 4.2.0-7Jan Cholasta - 4.2.0-6Jan Cholasta - 4.2.0-5Jan Cholasta - 4.2.0-4Jan Cholasta - 4.2.0-3Jan Cholasta - 4.2.0-2Jan Cholasta - 4.2.0-1Jan Cholasta - 4.2.0-0.2.alpha1Jan Cholasta - 4.2.0-0.1.alpha1Jan Cholasta - 4.1.0-18.3Alexander Bokovoy - 4.1.0-18.2Jan Cholasta - 4.1.0-18.1Martin Kosek - 4.1.0-18Jan Cholasta - 4.1.0-17Jan Cholasta - 4.1.0-16Jan Cholasta - 4.1.0-15Jan Cholasta - 4.1.0-14Jan Cholasta - 4.1.0-13Jan Cholasta - 4.1.0-12Jan Cholasta - 4.1.0-11Jan Cholasta - 4.1.0-10Jan Cholasta - 4.1.0-9Jan Cholasta - 4.1.0-8Jan Cholasta - 4.1.0-7Jan Cholasta - 4.1.0-6Jan Cholasta - 4.1.0-5Jan Cholasta - 4.1.0-4Jan Cholasta - 4.1.0-3Jan Cholasta - 4.1.0-2Jan Cholasta - 4.1.0-1Jan Cholasta - 4.1.0-0.1.alpha1Petr Vobornik - 4.0.3-3Jan Cholasta - 4.0.3-2Jan Cholasta - 4.0.3-1Martin Kosek - 3.3.3-29Martin Kosek - 3.3.3-28Martin Kosek - 3.3.3-27Martin Kosek - 3.3.3-26Martin Kosek - 3.3.3-25Martin Kosek - 3.3.3-24Martin Kosek - 3.3.3-23Martin Kosek - 3.3.3-22Martin Kosek - 3.3.3-21Martin Kosek - 3.3.3-20Martin Kosek - 3.3.3-19Martin Kosek - 3.3.3-18Martin Kosek - 3.3.3-17Martin Kosek - 3.3.3-16Daniel Mach - 3.3.3-15Martin Kosek - 3.3.3-14Martin Kosek - 3.3.3-13Martin Kosek - 3.3.3-12Martin Kosek - 3.3.3-11Martin Kosek - 3.3.3-10Martin Kosek - 3.3.3-9Martin Kosek - 3.3.3-8Daniel Mach - 3.3.3-7Martin Kosek - 3.3.3-6Martin Kosek - 3.3.3-5Martin Kosek - 3.3.3-4Martin Kosek - 3.3.3-3Martin Kosek - 3.3.3-2Martin Kosek - 3.3.3-1Martin Kosek - 3.3.2-5Martin Kosek - 3.3.2-4Martin Kosek - 3.3.2-3Martin Kosek - 3.3.2-2Martin Kosek - 3.3.2-1Martin Kosek - 3.3.1-5Martin Kosek - 3.3.1-4Martin Kosek - 3.3.1-3Martin Kosek - 3.3.1-2Rob Crittenden - 3.3.1-1Rob Crittenden - 3.3.0-7Martin Kosek - 3.3.0-6Martin Kosek - 3.3.0-5Martin Kosek - 3.3.0-4Martin Kosek - 3.3.0-3Martin Kosek - 3.3.0-2Martin Kosek - 3.3.0-1Martin Kosek - 3.3.0-0.2.beta2Martin Kosek - 3.3.0-0.1.beta2Martin Kosek - 3.2.2-1Martin Kosek - 3.2.1-1Rob Crittenden - 3.2.0-2Rob Crittenden - 3.2.0-1Rob Crittenden - 3.2.0-0.4.beta1Rob Crittenden - 3.2.0-0.3.beta1Rob Crittenden - 3.2.0-0.2.beta1Martin Kosek - 3.2.0-0.1.pre1Kevin Fenzi 3.1.2-4Kevin Fenzi - 3.1.2-3Fedora Release Engineering - 3.1.2-2Rob Crittenden - 3.1.2-1Martin Kosek - 3.1.0-2Rob Crittenden - 3.1.0-1Martin Kosek - 3.0.0-3Rob Crittenden - 3.0.0-2Rob Crittenden - 3.0.0-1Rob Crittenden - 3.0.0-0.10Martin Kosek - 3.0.0-0.9Rob Crittenden - 3.0.0-0.8Rob Crittenden - 3.0.0-0.7Rob Crittenden - 3.0.0-0.6Alexander Bokovoy - 3.0.0-0.5Rob Crittenden - 3.0.0-0.4Martin Kosek - 3.0.0-0.3Alexander Bokovoy - 3.0.0-0.2Rob Crittenden - 3.0.0-0.1Rob Crittenden - 2.2.0-1Rob Crittenden - 2.1.90-0.2Rob Crittenden - 2.1.90-0.1Alexander Bokovoy - 2.1.4-5Martin Kosek - 2.1.4-4Alexander Bokovoy - 2.1.4-3Alexander Bokovoy - 2.1.4-2Rob Crittenden - 2.1.4-1Rob Crittenden - 2.1.3-8Alexander Bokovoy - 2.1.3-7Alexander Bokovoy - 2.1.3-6Fedora Release Engineering - 2.1.3-5Alexander Bokovoy - 2.1.3-4Alexander Bokovoy - 2.1.3-3Alexander Bokovoy - 2.1.3-2Alexander Bokovoy - 2.1.3-1Alexander Bokovoy - 2.1.2-1Rob Crittenden - 2.1.0-1Simo Sorce - 2.0.1-2Rob Crittenden - 2.0.1-1Rob Crittenden - 2.0.0-1Rob Crittenden - 2.0.0-0.4.rc2Rob Crittenden - 2.0.0-0.3.rc1Rob Crittenden - 2.0.0-0.1.rc1Fedora Release Engineering - 2.0.0-0.2.beta2Rob Crittenden - 2.0.0-0.1.beta2Rob Crittenden - 2.0.0-0.2.beta.git80e87e7Rob Crittenden - 2.0.0-0.1.beta.git80e87e7Rob Crittenden - 1.99-41Adam Young - 1.99-40Simo Sorce - 1.99-39Simo Sorce - 1.99-38Rob Crittenden - 1.99-37Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Added Source: ipa.ini --> Config file for automated patch script- Resolves: #1579190 Improve Custodia client and key distribution handling - Use single Custodia instance in installers- Resolves: #1579189 nsds5ReplicaReleaseTimeout should be set by default - Add nsds5ReplicaReleaseTimeout to replica config - Fix upgrade (update_replica_config) in single master mode - Resolves: #1579190 Improve Custodia client and key distribution handling - Use single Custodia instance in installers - Resolves: #1579203 4.5.0 -> 4.5.4 upgrade breaks in ipa-server-upgrade: No such file or directory: '/var/lib/pki/pki-tomcat/conf/ca/CS.cfg' - Don't try to backup CS.cfg during upgrade if CA is not configured- Resolves: #1565519 Clarify the need to restart services in ipa-server-certinstall(1) - Add a notice to restart ipa services after certs are installed - Resolves: #1564390 OTP and Radius Authentication does not work in FIPS mode - Fix OTP validation in FIPS mode - Increase the default token key size - Revert "Don't allow OTP or RADIUS in FIPS mode" - Log errors from NSS during FIPS OTP key import - Resolves: #1565520 ipa client pointing to replica shows KDC has no support for encryption type - ipa-replica-install: make sure that certmonger picks the right master - Resolves: #1565605 DNS records updated with all IPAddresses of an interface when IPA server/replica try to install with Specific IP address of that interface - replica-install: pass --ip-address to client install- Resolves: #1540361 ipa-advise for smartcards is out-of-date - ipa-advise for smartcards updated- Resolves: #1458169 --force-join option is not mentioned in ipa-replica-install man page - Add --force-join into ipa-replica-install manpage - Resolves: #1457876 ipa-backup fails silently - Changed ownership of ldiffile to DS_USER - Resolves: #1409786 Second phase of --external-ca ipa-server-install setup fails when dirsrv is not running - Checks if Dir Server is installed and running before IPA installation - Resolves: #1452086 Pagination Size under Customization in IPA WebUI accepts negative values - WebUI: Add positive number validator - WebUI: change validator of page size settings - WebUI: fix jslint error- Resolves: #1477531 Incorrect attribute level rights (ipaallowedtoperform) of service object - WebUI: make keytab tables on service and host pages writable - Resolves: #1529444 ObjectclassViolation seen while adding idview with domain-resolution-order option - Idviews: fix objectclass violation on idview-add - Resolves: #1451576 ipa cert-request failed to generate certificate from csr - Fixing the cert-request comparing whole email address case-sensitively.- Resolves: #1421869 Unable to re-add broken AD trust - Unexpected Information received - adtrust: filter out subdomains when defining our topology to AD - Resolves: #1486286 IPA failing to authenticate via password+OTP on RHEL7.4 with fips enabled - Don't allow OTP or RADIUS in FIPS mode - Resolves: #1494226 IPA User Details not being displayed in WebUI - Fix cert-find for CA-less installations - Resolves: #1498387 389-ds-base crashed as part of ipa-server-intall in ipa-uuid - 389-ds-base crashed as part of ipa-server-intall in ipa-uuid - Resolves: #1503022 ipa-getkeytab man page should have more details about consequences of krb5 key renewal - ipa-getkeytab man page: add more details about the -r option - Resolves: #1509288 IPA trust-add internal error (expected security.dom_sid got None) - ipaserver/plugins/trust.py; fix some indenting issues - trust: detect and error out when non-AD trust with IPA domain name exists - ipaserver/plugins/trust.py: pep8 compliance - Resolves: #1511019 ipa-restore broken with python2 - Fix ipa-restore (python2) - Resolves: #1511607 ipa-backup does not backup Custodia keys and files - Backup ipa-custodia conf and keys - Resolves: #1512482 kra install fails after ipa cert renewed - Don't use admin cert during KRA installation - Prevent set_directive from clobbering other keys - pep8: reduce line lengths in CAInstance.__enable_crl_publish - installutils: refactor set_directive - Add tests for installutils.set_directive - Add safe DirectiveSetter context manager - Old pylint doesn't support bad python3 option - Resolves: #1514163 CA less IPA install with external certificates fails on RHEL 7 in FIPS mode - Fix ca less IPA install on fips mode- Resolves: #1520279 - rebuild against samba 4.7- Resolves: #1415162 ipa-exdom-extop plugin can exhaust DS worker threads - Resolves: #1378892 host-find slowness caused by missing host attributes in index- Resolves: #1388135 [RFE] limit the retro changelog to dns subtree. - ldap: limit the retro changelog to dns subtree - Resolves: #1427798 Use X509v3 Basic Constraints "CA:TRUE" instead of "CA:FALSE" IPA CA CSR - Include the CA basic constraint in CSRs when renewing a CA - Resolves: #1493145 ipa-replica-install might fail because of an already existing entry cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,$SUFFIX - Checks if replica-s4u2proxy.ldif should be applied - Resolves: #1493150 [RFE] set nsslapd-ignore-time-skew: on by default - ds: ignore time skew during initial replication step - ipa-replica-manage: implicitly ignore initial time skew in force-sync - Resolves: #1500218 Replica installation at domain-level 0 fails against upgraded ipa-server - Fix ipa-replica-conncheck when called with --principal - Resolves: #1506188 server-del doesn't remove dns-server configuration from ldap- Drop workaround for building on AArch64 (#1482244) - Temporarily reduce Requires on python-netaddr to 0.7.5-7 (#1506485)- Resolves: #1461177 ipa-otptoken-import - XML file is missing PBKDF2 parameters! - Resolves: #1464205 NULL LDAP context in call to ldap_search_ext_s during search in cn=ad, cn=trusts,dc=example,dc=com - Resolves: #1467887 iommu platform support for ipxe - Resolves: #1477178 [ipa-replica-install] - 406 Client Error: Failed to validate message: Incorrect number of results (0) searching forpublic key for host - Resolves: #1478251 IPA WebUI does not work after upgrade from IPA 4.4 to 4.5 - Resolves: #1480102 ipa-server-upgrade failes with "This entry already exists" - Resolves: #1482802 Unable to set ca renewal master on replica - Resolves: #1484428 Updating from RHEL 7.3 fails with Server-Cert not found (ipa-server-upgrade) - Resolves: #1484826 FreeIPA/IdM installations which were upgraded from versions with 389 DS prior to 1.3.3.0 doesn't have whomai plugin enabled and thus startup of Web UI fails - Resolves: #1486283 TypeError in renew_ca_cert prevents from swiching back to self-signed CA - Resolves: #1469246 Replica install fails to configure IPA-specific temporary files/directories - Resolves: #1469480 bind package is not automatically updated during ipa-server upgrade process - Resolves: #1475238 Use CommonNameToSANDefault in default profile (new installs only) - Resolves: #1477703 IPA upgrade fails for latest ipa package- Use OpenJDK 8 to bootstrap on AArch64 until RH1482244 is resolved in buildroot - Resolves: #1470177 - Rebase IPA to latest 4.5.x version - Resolves: #1398594 ipa topologysuffix-verify should only warn about maximum number of replication agreements. - Resolves: #1404236 Web UI: Change "Host Based" and "Role Based" to "Host-Based" and "Role-Based" - Resolves: #1409786 Second phase of --external-ca ipa-server-install setup fails when dirsrv is not running - Resolves: #1451576 ipa cert-request failed to generate certificate from csr - Resolves: #1452086 Pagination Size under Customization in IPA WebUI accepts negative values - Resolves: #1458169 --force-join option is not mentioned in ipa-replica-install man page - Resolves: #1463186 IPA shouldn't allow objectclass if not all in lower case - Resolves: #1478322 user-show command fails when sizelimit is configured to number <= number of entity which is user member of - Resolves: #1496775 Enterprise principals should be able to trigger a refresh of the trusted domain data in the KDC - Resolves: #1502533 Changing cert-find to go through the proxy instead of using the port 8080 - Resolves: #1502663 pkinit-status command fails after an upgrade from a pre-4.5 IPA - Resolves: #1498168 Error when trying to modify a PTR record - Resolves: #1457876 ipa-backup fails silently - Resolves: #1493531 In case full PKINIT configuration is failing during server/replica install the error message should be more meaningful. - Resolves: #1449985 Suggest CA installation command in KRA installation warning- Resolves: #1477367 ipa-server-upgrade timeouts on wait_for_open ports expecting IPA services listening on IPv6 ports - Make sure upgrade also checks for IPv6 stack - control logging of host_port_open from caller - log progress of wait_for_open_ports - Resolves: #1477243 ipa help command returns traceback when no cache is present - Store help in Schema before writing to disk - Disable pylint in get_help function because of type confusion.- Resolves: #1477178 - [ipa-replica-install] - 406 Client Error: Failed to validate message: Incorrect number of results (0) searching forpublic key for host - Always check peer has keys before connecting - Resolves: #1482802 - Unable to set ca renewal master on replica - Fix ipa config-mod --ca-renewal-master - Resolves: #1486283 - TypeError in renew_ca_cert prevents from swiching back to self-signed CA - Backport PR 988 to ipa-4-5 Fix Certificate renewal (with ext ca) - Resolves: #1480102 - ipa-server-upgrade failes with "This entry already exists" - Backport PR 1008 to ipa-4-5 Fix ipa-server-upgrade: This entry already exists - Resolves: #1484826 - FreeIPA/IdM installations which were upgraded from versions with 389 DS prior to 1.3.3.0 doesn't have whomai plugin enabled and thus startup of Web UI fails - Adds whoami DS plugin in case that plugin is missing - Resolves: #1478251 - IPA WebUI does not work after upgrade from IPA 4.4 to 4.5 - Fixing how sssd.conf is updated when promoting a client to replica - Resolves: #1461177 - ipa-otptoken-import - XML file is missing PBKDF2 parameters! - ipa-otptoken-import: Make PBKDF2 refer to the pkcs5 namespace - Resolves: #1484428 - Updating from RHEL 7.3 fails with Server-Cert not found (ipa-server-upgrade) - Backport 4-5: Fix ipa-server-upgrade with server cert tracking- Resolves: #1477703 IPA upgrade fails for latest ipa package - Restore old version of caIPAserviceCert for upgrade only- Resolves: #1475238 Use CommonNameToSANDefault in default profile (new installs only) - Restore old version of caIPAserviceCert for upgrade only- Resolves: #1455946 Provide a tooling automating the configuration of Smart Card authentication on a FreeIPA master - smart-card advises: configure systemwide NSS DB also on master - smart-card advises: add steps to store smart card signing CA cert - Allow to pass in multiple CA cert paths to the smart card advises - add a class that tracks the indentation in the generated advises - delegate the indentation handling in advises to dedicated class - advise: add an infrastructure for formatting Bash compound statements - delegate formatting of compound Bash statements to dedicated classes - Fix indentation of statements in Smart card advises - Use the compound statement formatting API for configuring PKINIT - smart card advises: use a wrapper around Bash `for` loops - smart card advise: use password when changing trust flags on HTTP cert - smart-card-advises: ensure that krb5-pkinit is installed on client - Resolves: #1475238 Use CommonNameToSANDefault in default profile (new installs only) - Add CommonNameToSANDefault to default cert profile - Resolves: #1464205 NULL LDAP context in call to ldap_search_ext_s during search in cn=ad,cn=trusts,dc=example,dc=com - NULL LDAP context in call to ldap_search_ext_s during search- Resolves: #1469246 Replica install fails to configure IPA-specific temporary files/directories - replica install: drop-in IPA specific config to tmpfiles.d - Resolves: #1469480 bind package is not automatically updated during ipa-server upgrade process - Bumped Required version of bind-dyndb-ldap and bind package- Resolves: #1452216 Replica installation grants HTTP principal access in WebUI - Make sure we check ccaches in all rpcserver paths- Resolves: #1462112 ipaserver installation fails in FIPS mode: OpenSSL internal error, assertion failed: Digest MD4 forbidden in FIPS mode! - ipa-sam: replace encode_nt_key() with E_md4hash() - ipa_pwd_extop: do not generate NT hashes in FIPS mode - Resolves: #1377973 ipa-server-install fails when the provided or resolved IP address is not found on local interfaces - Fix local IP address validation - ipa-dns-install: remove check for local ip address - refactor CheckedIPAddress class - CheckedIPAddress: remove match_local param - Remove ip_netmask from option parser - replica install: add missing check for non-local IP address - Remove network and broadcast address warnings- Resolves: #1449189 ipa-kra-install timeouts on replica - kra: promote: Get ticket before calling custodia- Resolve: #1455946 Provide a tooling automating the configuration of Smart Card authentication on a FreeIPA master - server certinstall: update KDC master entry - pkinit manage: introduce ipa-pkinit-manage - server upgrade: do not enable PKINIT by default - Extend the advice printing code by some useful abstractions - Prepare advise plugin for smart card auth configuration - Resolve: #1461053 allow to modify list of UPNs of a trusted forest - trust-mod: allow modifying list of UPNs of a trusted forest - WebUI: add support for changing trust UPN suffixes- Resolves: #1377973 ipa-server-install fails when the provided or resolved IP address is not found on local interfaces - Only warn when specified server IP addresses don't match intf - Resolves: #1438016 gssapi errors after IPA server upgrade - Bump version of python-gssapi - Resolves: #1457942 certauth: use canonical principal for lookups - ipa-kdb: use canonical principal in certauth plugin - Resolves: #1459153 Do not send Max-Age in ipa_session cookie to avoid breaking older clients - Add code to be able to set default kinit lifetime - Revert setting sessionMaxAge for old clients- Resolves: #1442233 IPA client commands fail when pointing to replica - httpinstance: wait until the service entry is replicated - Resolves: #1456769 ipaAnchorUUID index incorrectly configured and then not indexed - Fix index definition for ipaAnchorUUID - Resolves: #1438016 gssapi errors after IPA server upgrade - Avoid possible endless recursion in RPC call - rpc: preparations for recursion fix - rpc: avoid possible recursion in create_connection - Resolves: #1446087 services entries missing krbCanonicalName attribute. - Changing cert-find to do not use only primary key to search in LDAP. - Resolves: #1452763 ipa certmaprule change not reflected in krb5kdc workers - ipa-kdb: reload certificate mapping rules periodically - Resolves: #1455541 after upgrade login from web ui breaks - kdc.key should not be visible to all - Resolves: #1435606 Add pkinit_indicator option to KDC configuration - ipa-kdb: add pkinit authentication indicator in case of a successful certauth - Resolves: #1455945 Enabling OCSP checks in mod_nss breaks certificate issuance when ipa-ca records are not resolvable - Turn off OCSP check - Resolves: #1454483 rhel73 ipa ui - cannot del server - IPA Error 903 - server_del - TypeError: 'NoneType' object is not iterable - fix incorrect suffix handling in topology checks- Resolves: #1438731 Extend ipa-server-certinstall and ipa-certupdate to handle PKINIT certificates/anchors - certdb: add named trust flag constants - certdb, certs: make trust flags argument mandatory - certdb: use custom object for trust flags - install: trust IPA CA for PKINIT - client install: fix client PKINIT configuration - install: introduce generic Kerberos Augeas lens - server install: fix KDC PKINIT configuration - ipapython.ipautil.run: Add option to set umask before executing command - certs: do not export keys world-readable in install_key_from_p12 - certs: do not export CA certs in install_pem_from_p12 - server install: fix KDC certificate validation in CA-less - replica install: respect --pkinit-cert-file - cacert manage: support PKINIT - server certinstall: support PKINIT - Resolves: #1444432 CA-less pkinit not installable with --pkinit-cert-file option - certs: do not export CA certs in install_pem_from_p12 - server install: fix KDC certificate validation in CA-less - Resolves: #1451228 ipa-kra-install fails when primary KRA server has been decommissioned - ipa-kra-install: fix pkispawn setting for pki_security_domain_hostname - Resolves: #1451712 KRA installation fails on server that was originally installed as CA-less - ipa-ca-install: append CA cert chain into /etc/ipa/ca.crt - Resolves: #1441499 ipa cert-show does not raise error if no file name specified - ca/cert-show: check certificate_out in options - Resolves: #1449522 Deprecate `ipa pkinit-anonymous` command in FreeIPA 4.5+ - Remove pkinit-anonymous command - Resolves: #1449523 Provide an API command to retrieve PKINIT status in the FreeIPA topology - Allow for multivalued server attributes - Refactor the role/attribute member reporting code - Add an attribute reporting client PKINIT-capable servers - Add the list of PKINIT servers as a virtual attribute to global config - Add `pkinit-status` command - test_serverroles: Get rid of MockLDAP and use ldap2 instead - Resolves: #1452216 Replica installation grants HTTP principal access in WebUI - Fix rare race condition with missing ccache file - Resolves: #1455045 Simple service uninstallers must be able to handle missing service files gracefully - only stop/disable simple service if it is installed - Resolves: #1455541 after upgrade login from web ui breaks - krb5: make sure KDC certificate is readable - Resolves: #1455862 "ipa: ERROR: an internal error has occurred" on executing command "ipa cert-request --add" after upgrade - Change python-cryptography to python2-cryptography- Resolves: #1451804 "AttributeError: 'tuple' object has no attribute 'append'" error observed during ipa upgrade with latest package. - ipa-server-install: fix uninstall - Resolves: #1445390 ipa-[ca|kra]-install with invalid DM password break replica - ca install: merge duplicated code for DM password - installutils: add DM password validator - ca, kra install: validate DM password- Resolves: #1447284 Upgrade from ipa-4.1 fails when enabling KDC proxy - python2-ipalib: add missing python dependency - installer service: fix typo in service entry - upgrade: add missing suffix to http instance - Resolves: #1444791 Update man page of ipa-kra-install - ipa-kra-install manpage: document domain-level 1 - Resolves: #1441493 ipa cert-show raises stack traces when --certificate-out=/tmp - cert-show: writable files does not mean dirs - Resolves: #1441192 Add the name of URL parameter which will be check for username during cert login - Bump version of ipa.conf file - Resolves: #1378797 Web UI must check OCSP and CRL during smartcard login - Turn on NSSOCSP check in mod_nss conf - Resolves: #1322963 Errors from AD when trying to sign ipa.csr, conflicting template on - renew agent: respect CA renewal master setting - server upgrade: always fix certmonger tracking request - cainstance: use correct profile for lightweight CA certificates - renew agent: allow reusing existing certs - renew agent: always export CSR on IPA CA certificate renewal - renew agent: get rid of virtual profiles - ipa-cacert-manage: add --external-ca-type - Resolves: #1441593 error adding authenticator indicators to host - Fixing adding authenticator indicators to host - Resolves: #1449525 Set directory ownership in spec file - Added plugins directory to ipaclient subpackages - ipaclient: fix missing RPM ownership - Resolves: #1451279 otptoken-add-yubikey KeyError: 'ipatokenotpdigits' - otptoken-add-yubikey: When --digits not provided use default value- Resolves: #1449189 ipa-kra-install timeouts on replica - ipa-kra-install: fix check_host_keys- Resolves: #1438833 [ipa-replica-install] - 406 Client Error: Failed to validate message: Incorrect number of results (0) searching forpublic key for host - Make sure remote hosts have our keys - Resolves: #1442815 Replica install fails during migration from older IPA master - Refresh Dogtag RestClient.ca_host property - Remove the cachedproperty class - Resolves: #1444787 Update warning message when KRA installation fails - kra install: update installation failure message - Resolves: #1444896 ipa-server-install with external-ca fails in FIPS mode - ipa-server-install with external CA: fix pkinit cert issuance - Resolves: #1445397 GET in KerberosSession.finalize_kerberos_acquisition() must use FreeIPA CA - kerberos session: use CA cert with full cert chain for obtaining cookie - Resolves: #1447375 ipa-client-install: extra space in pkinit_anchors definition - ipa-client-install: remove extra space in pkinit_anchors definition - Resolves: #1447703 Fix SELinux contex of http.keytab during upgrade - Use proper SELinux context with http.keytab- Resolves: #1200767 [RFE] Allow Kerberos authentication for users with certificates on smart cards (pkinit) - spec file: bump krb5 Requires for certauth fixes - Resolves: #1438729 Configure local PKINIT on DL0 or when '--no-pkinit' option is used - separate function to set ipaConfigString values on service entry - Allow for configuration of all three PKINIT variants when deploying KDC - API for retrieval of master's PKINIT status and publishing it in LDAP - Use only anonymous PKINIT to fetch armor ccache - Stop requesting anonymous keytab and purge all references of it - Use local anchor when armoring password requests - Upgrade: configure local/full PKINIT depending on the master status - Do not test anonymous PKINIT after install/upgrade - Resolves: #1442427 ipa.ipaserver.install.plugins.adtrust. update_tdo_gidnumber: ERROR Default SMB Group not found - upgrade: adtrust update_tdo_gidnumber plugin must check if adtrust is installed - Resolves: #1442932 ipa restore fails to restore IPA user - restore: restart/reload gssproxy after restore - Resolves: #1444896 ipa-server-install with external-ca fails in FIPS mode - Fix CA/server cert validation in FIPS - Resolves: #1444947 Deadlock between topology and schema-compat plugins - compat-manage: behave the same for all users - Move the compat plugin setup at the end of install - compat: ignore cn=topology,cn=ipa,cn=etc subtree - Resolves: #1445358 ipa vault-add raises TypeError - vault: piped input for ipa vault-add fails - Resolves: #1445382 ipa vault-retrieve fails to retrieve data from vault - Vault: Explicitly default to 3DES CBC - Resolves: #1445432 uninstall ipa client automount failed with RuntimeWarning - automount install: fix checking of SSSD functionality on uninstall - Resolves: #1446137 pki_client_database_password is shown in ipaserver-install.log - Hide PKI Client database password in log file- Resolves: #1443869 Command "openssl pkcs12 ..." failed during IPA upgrade - Fix CAInstance.import_ra_cert for empty passwords- Resolves: #1431520 ipa cert-find runs a large number of searches, so IPA WebUI is slow to display user details page - cert: defer cert-find result post-processing - Resolves: #1435611 Tracebacks seen from dogtag-ipa-ca-renew-agent-submit helper when installing replica - server-install: No double Kerberos install - Resolves: #1437502 ipa-replica-install fails with requirement to use --force-join that is a client install option. - Add the force-join option to replica install - replicainstall: better client install exception handling - Resolves: #1437953 Server CA-less impossible option check - server-install: remove broken no-pkinit check - Resolves: #1441160 FreeIPA client <= 4.4 fail to parse 4.5 cookies - Add debug log in case cookie retrieval went wrong - Resolves: #1441548 ipa server install fails with --external-ca option - ext. CA: correctly write the cert chain - Resolves: #1441718 Conversion of CA-less server to CA fails on CA instance spawn - Fix CA-less to CA-full upgrade - Resolves: #1442133 Do not link libkrad, liblber, libldap_r and libsss_nss_idmap to every binary in IPA - configure: fix AC_CHECK_LIB usage - Resolves: #1442815 Replica install fails during migration from older IPA master - Fix RA cert import during DL0 replication - Related: #1442004 Building IdM/FreeIPA internally on all architectures - filtering unsupported packages - Build all subpackages on all architectures- Resolves: #1382053 Need to have validation for idrange names - idrange-add: properly handle empty --dom-name option - Resolves: #1435611 Tracebacks seen from dogtag-ipa-ca-renew-agent-submit helper when installing replica - dsinstance: reconnect ldap2 after DS is restarted by certmonger - httpinstance: avoid httpd restart during certificate request - dsinstance, httpinstance: consolidate certificate request code - install: request service certs after host keytab is set up - renew agent: revert to host keytab authentication - renew agent, restart scripts: connect to LDAP after kinit - Resolves: #1436987 ipasam: gidNumber attribute is not created in the trusted domain entry - ipa-sam: create the gidNumber attribute in the trusted domain entry - Upgrade: add gidnumber to trusted domain entry - Resolves: #1438679 [ipa-replica-install] - IncorrectPasswordException: Incorrect client security database password - Add pki_pin only when needed - Resolves: #1438348 Console output message while adding trust should be mapped with texts changed in Samba. - ipaserver/dcerpc: unify error processing - Resolves: #1438366 ipa trust-fetch-domains: ValidationError: invalid 'Credentials': Missing credentials for cross-forest communication - trust: always use oddjobd helper for fetching trust information - Resolves: #1441192 Add the name of URL parameter which will be check for username during cert login - WebUI: cert login: Configure name of parameter used to pass username - Resolves: #1437879 [copr] Replica install failing - Create system users for FreeIPA services during package installation - Resolves: #1441316 WebUI cert auth fails after ipa-adtrust-install - Fix s4u2self with adtrust- Resolves: #1318186 Misleading error message during external-ca IPA master install - httpinstance: make sure NSS database is backed up - Resolves: #1331443 Re-installing ipa-server after uninstall fails with "ERROR CA certificate chain in ... incomplete" - httpinstance: make sure NSS database is backed up - Resolves: #1393726 Enumerate all available request type options in ipa cert-request help - Hide request_type doc string in cert-request help - Resolves: #1402959 [RFE] Universal Smart Card to Identity mapping - spec file: bump libsss_nss_idmap-devel BuildRequires - server: make sure we test for sss_nss_getlistbycert - Resolves: #1437378 ipa-adtrust-install produced an error and failed on starting smb when hostname is not FQDN - adtrust: make sure that runtime hostname result is consistent with the configuration - Resolves: #1437555 ipa-replica-install with DL0 fails to get annonymous keytab - Always check and create anonymous principal during KDC install - Remove duplicate functionality in upgrade - Resolves: #1437946 Upgrade to FreeIPA 4.5.0 does not configure anonymous principal for PKINIT - Upgrade: configure PKINIT after adding anonymous principal - Remove unused variable from failed anonymous PKINIT handling - Split out anonymous PKINIT test to a separate method - Ensure KDC is propery configured after upgrade - Resolves: #1437951 Remove pkinit-related options from server/replica-install on DL0 - Fix the order of cert-files check - Don't allow setting pkinit-related options on DL0 - replica-prepare man: remove pkinit option refs - Remove redundant option check for cert files - Resolves: #1438490 CA-less installation fails on publishing CA certificate - Get correct CA cert nickname in CA-less - Remove publish_ca_cert() method from NSSDatabase - Resolves: #1438838 Avoid arch-specific path in /etc/krb5.conf.d/ipa-certmap - IPA-KDB: use relative path in ipa-certmap config snippet - Resolves: #1439038 Allow erasing ipaDomainResolutionOrder attribute - Allow erasing ipaDomainResolutionOrder attribute- Resolves: #1434032 Run ipa-custodia with custom SELinux context - Require correct custodia version- Resolves: #800545 [RFE] Support SUDO command rename - Reworked the renaming mechanism - Allow renaming of the sudorule objects - Resolves: #872671 IPA WebUI login for AD Trusted User fails - WebUI: check principals in lowercase - WebUI: add method for disabling item in user dropdown menu - WebUI: Add support for login for AD users - Resolves: #1200767 [RFE] Allow Kerberos authentication for users with certificates on smart cards (pkinit) - ipa-kdb: add ipadb_fetch_principals_with_extra_filter() - IPA certauth plugin - ipa-kdb: do not depend on certauth_plugin.h - spec file: bump krb5-devel BuildRequires for certauth - Resolves: #1264370 RFE: disable last successful authentication by default in ipa. - Set "KDC:Disable Last Success" by default - Resolves: #1318186 Misleading error message during external-ca IPA master install - certs: do not implicitly create DS pin.txt - httpinstance: clean up /etc/httpd/alias on uninstall - Resolves: #1331443 Re-installing ipa-server after uninstall fails with "ERROR CA certificate chain in ... incomplete" - certs: do not implicitly create DS pin.txt - httpinstance: clean up /etc/httpd/alias on uninstall - Resolves: #1366572 [RFE] Web UI: allow Smart Card authentication - configure: fix --disable-server with certauth plugin - rpcserver.login_x509: Actually return reply from __call__ method - spec file: Bump requires to make Certificate Login in WebUI work - Resolves: #1402959 [RFE] Universal Smart Card to Identity mapping - extdom: do reverse search for domain separator - extdom: improve cert request - Resolves: #1430363 [RFE] HBAC rule names command rename - Reworked the renaming mechanism - Allow renaming of the HBAC rule objects - Resolves: #1433082 systemctl daemon-reload needs to be called after httpd.service.d/ipa.conf is manipulated - tasks: run `systemctl daemon-reload` after httpd.service.d updates - Resolves: #1434032 Run ipa-custodia with custom SELinux context - Use Custodia 0.3.1 features - Resolves: #1434384 RPC client should use HTTP persistent connection - Use connection keep-alive - Add debug logging for keep-alive - Increase Apache HTTPD's default keep alive timeout - Resolves: #1434729 man ipa-cacert-manage install needs clarification - man ipa-cacert-manage install needs clarification - Resolves: #1434910 replica install against IPA v3 master fails with ACIError - Fixing replica install: fix ldap connection in domlvl 0 - Resolves: #1435394 Ipa-kra-install fails with weird output when backspace is used during typing Directory Manager password - ipapython.ipautil.nolog_replace: Do not replace empty value - Resolves: #1435397 ipa-replica-install can't install replica file produced by ipa-replica-prepare on 4.5 - replica prepare: fix wrong IPA CA nickname in replica file - Resolves: #1435599 WebUI: in self-service Vault menu item is shown even if KRA is not installed - WebUI: Fix showing vault in selfservice view - Resolves: #1435718 As a ID user I cannot call a command with --rights option - ldap2: use LDAP whoami operation to retrieve bind DN for current connection - Resolves: #1436319 "Truncated search results" pop-up appears in user details in WebUI - WebUI: Add support for suppressing warnings - WebUI: suppress truncation warning in select widget - Resolves: #1436333 Uninstall fails with No such file or directory: '/var/run/ipa/services.list' - Create temporaty directories at the begining of uninstall - Resolves: #1436334 WebUI: Adding certificate mapping data using certificate fails - WebUI: Allow to add certs to certmapping with CERT LINES around - Resolves: #1436338 CLI doesn't work after ipa-restore - Backup ipa-specific httpd unit-file - Backup CA cert from kerberos folder - Resolves: #1436342 Bump samba version, required for FIPS mode and privilege separation - Bump samba version for FIPS and priv. separation - Resolves: #1436642 [ipalib/rpc.py] - "maximum recursion depth exceeded" with ipa vault commands - Avoid growing FILE ccaches unnecessarily - Handle failed authentication via cookie - Work around issues fetching session data - Prevent churn on ccaches - Resolves: #1436657 Add workaround for pki_pin for FIPS - Generate PIN for PKI to help Dogtag in FIPS - Resolves: #1436714 [vault] cache KRA transport cert - Simplify KRA transport cert cache - Resolves: #1436723 cert-find does not find all certificates without sizelimit=0 - cert: do not limit internal searches in cert-find - Resolves: #1436724 Renewal of IPA RA fails on replica - dogtag-ipa-ca-renew-agent-submit: fix the is_replicated() function - Resolves: #1436753 Master tree fails to install - httpinstance.disable_system_trust: Don't fail if module 'Root Certs' is not available- Resolves: #1432630 python2-jinja2 needed for python2-ipaclient - Remove csrgen - Resolves: #1432903 Set GssProxy options to enable caching of ldap tickets - Add options to allow ticket caching- Resolves: #828866 [RFE] enhance --subject option for ipa-server-install - Resolves: #1160555 ipa-server-install: Cannot handle double hyphen "--" in hostname - Resolves: #1286288 Insufficient 'write' privilege to the 'ipaExternalMember' attribute - Resolves: #1321652 ipa-server-install fails when using external certificates that encapsulate RDN components in double quotes - Resolves: #1327207 ipa cert-revoke --help doesn't provide enough info on revocation reasons - Resolves: #1340880 ipa-server-install: improve prompt on interactive installation - Resolves: #1353841 ipa-replica-install fails to install when resolv.conf incomplete entries - Resolves: #1356104 cert-show command does not display Subject Alternative Names - Resolves: #1357511 Traceback message seen when ipa is provided with invalid configuration file name - Resolves: #1358752 ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full - Resolves: #1366572 [RFE] Web UI: allow Smart Card authentication - Resolves: #1367572 improve error message in ipa migrate-ds: mention ipa config-mod --enable-migration=TRUE - Resolves: #1367868 Add options to retrieve lightweight CA certificate/chain - Resolves: #1371927 Implement ca-enable/disable commands. - Resolves: #1372202 Add Users into User Group editors fails to show Full names - Resolves: #1373091 Adding an auth indicator from the CLI creates an extra check box in the UI - Resolves: #1375596 Ipa-server WebUI - long user/group name show wrong error message - Resolves: #1375905 "Normal" group type in the UI is confusing - Resolves: #1376040 IPA client ipv6 - invalid --ip-address shows traceback - Resolves: #1376630 IDM admin password gets written to /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf - Resolves: #1376729 ipa-server-install script option --no_hbac_allow should match other options - Resolves: #1378461 IPA Allows Password Reuse with History value defined when admin resets the password. - Resolves: #1379029 conncheck failing intermittently during single step replica installs - Resolves: #1379858 [RFE] better debugging for ipa-replica-conncheck - Resolves: #1384310 ipa dnsrecord-add fails with Keyerror stack trace - Resolves: #1392778 Update man page for ipa-adtrust-install by removing --no-msdcs option - Resolves: #1392858 Rebase to FreeIPA 4.5+ - Rebase to 4.5.0 - Resolves: #1399133 Delete option shouldn't be available for hosts applied to view. - Resolves: #1399190 [RFE] Certificates issued by externally signed IdM CA should contain full trust chain - Resolves: #1400416 RFE: Provide option to take backup of IPA server before uninstalling IPA server - Resolves: #1400529 cert-request is not aware of Kerberos principal aliases - Resolves: #1401526 IPA WebUI certificates are grayed out on overview page but not on details page - Resolves: #1402959 [RFE] Universal Smart Card to Identity mapping - Resolves: #1404750 ipa-client-install fails to get CA cert via LDAP when non-FQDN name of IPA server is first in /etc/hosts - Resolves: #1409628 [RFE] Semi-automatic integration with external DNS using nsupdate - Resolves: #1413742 Backport request for bug/issue Change IP address validation errors to warnings - Resolves: #1415652 IPA replica install log shows password in plain text - Resolves: #1427897 different behavior regarding system wide certs in master and replica. - Resolves: #1430314 The ipa-managed-entries command failed, exception: AttributeError: ldap2- Resolves: #1419735 ipa-replica-install fails promotecustodia.create_replica with cert errors (untrusted) - added ssl verification using IPA trust anchor - Resolves: #1428472 batch param compatibility is incorrect - compat: fix `Any` params in `batch` and `dnsrecord` - Renamed patches 1011 and 1012 to 0159 and 0157, as they were merged upstream- Resolves: #1416454 replication race condition prevents IPA to install - wait_for_entry: use only DN as parameter - Wait until HTTPS principal entry is replicated to replica - Use proper logging for error messages- Resolves: #1365858 ipa-ca-install fails on replica when IPA Master is installed without CA - Set up DS TLS on replica in CA-less topology - Resolves: #1398600 IPA replica install fails with dirsrv errors. - Do not configure PKI ajp redirection to use "::1" - Resolves: #1413137 CVE-2017-2590 ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands - ca: correctly authorise ca-del, ca-enable and ca-disable- Resolves: #1370493 CVE-2016-7030 ipa: DoS attack against kerberized services by abusing password policy - ipa-kdb: search for password policies globally - Renamed patches 1011 and 1012 to 0151 and 0150, as they were merged upstream- Resolves: #1398670 Check IdM Topology for broken record caused by replication conflict before upgrading it - Check for conflict entries before raising domain level- Resolves: #1382812 Creation of replica for disconnected environment is failing with CA issuance errors; Need good steps. - gracefully handle setting replica bind dn group on old masters - Resolves: #1397439 ipa-ca-install on promoted replica hangs on creating a temporary CA admin - replication: ensure bind DN group check interval is set on replica config - add missing attribute to ipaca replica during CA topology update - Resolves: #1401088 IPA upgrade of replica without DNS fails during restart of named-pkcs11 - bindinstance: use data in named.conf to determine configuration status- Resolves: #1370493 CVE-2016-7030 ipa: DoS attack against kerberized services by abusing password policy - password policy: Add explicit default password policy for hosts and services - Resolves: #1395311 CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod - certprofile-mod: correctly authorise config update- Resolves: #1378353 Replica install fails with old IPA master sometimes during replication process - spec file: bump minimal required version of 389-ds-base - Resolves: #1387779 Make httpd publish CA certificate on Domain Level 1 - Fix missing file that fails DL1 replica installation - Resolves: #1387782 WebUI: Services are not displayed correctly after upgrade - WebUI: services without canonical name are shown correctly - Resolves: #1389709 Traceback seen in error_log when trustdomain-del is run - trustdomain-del: fix the way how subdomain is searched- Resolves: #1318616 CA fails to start after doing ipa-ca-install --external-ca - Keep NSS trust flags of existing certificates - Resolves: #1360813 ipa-server-certinstall does not update all certificate stores and doesn't set proper trust permissions - Add cert checks in ipa-server-certinstall - Resolves: #1371479 cert-find --all does not show information about revocation - cert: add revocation reason back to cert-find output - Resolves: #1375133 WinSync users who have First.Last casing creates users who can have their password set - ipa passwd: use correct normalizer for user principals - Resolves: #1377858 Users with 2FA tokens are not able to login to IPA servers - Properly handle LDAP socket closures in ipa-otpd - Resolves: #1387779 Make httpd publish CA certificate on Domain Level 1 - Make httpd publish its CA certificate on DL1- Resolves: #1373910 IPA server upgrade fails with DNS timed out errors. - Resolves: #1375269 ipa trust-fetch-domains throws internal error- Resolves: #1373359 ipa-certupdate fails with "CA is not configured" - Fix regression introduced in ipa-certupdate- Resolves: #1355753 adding two way non transitive(external) trust displays internal error on the console - Always fetch forest info from root DCs when establishing two-way trust - factor out `populate_remote_domain` method into module-level function - Always fetch forest info from root DCs when establishing one-way trust - Resolves: #1356101 Lightweight sub-CA certs are not tracked by certmonger after `ipa-replica-install` - Track lightweight CAs on replica installation - Resolves: #1357488 ipa command stuck forever on higher versioned client with lower versioned server - compat: Save server's API version in for pre-schema servers - compat: Fix ping command call - schema cache: Store and check info for pre-schema servers - Resolves: #1363905 man page for ipa-replica-manage has a typo in -c flag - Fix man page ipa-replica-manage: remove duplicate -c option from --no-lookup - Resolves: #1367865 webui: cert_revoke should use --cacn to set correct CA when revoking certificate - cert: include CA name in cert command output - WebUI add support for sub-CAs while revoking certificates - Resolves: #1368424 Unable to view certificates issued by Sub CA in Web UI - Add support for additional options taken from table facet - WebUI: Fix showing certificates issued by sub-CA - Resolves: #1368557 dnsrecord-add does not prompt for missing record parts internactively - dns: normalize record type read interactively in dnsrecord_add - dns: prompt for missing record parts in CLI - dns: fix crash in interactive mode against old servers - Resolves: #1370519 Certificate revocation in service-del and host-del isn't aware of Sub CAs - cert: fix cert-find --certificate when the cert is not in LDAP - Make host/service cert revocation aware of lightweight CAs - Resolves: #1371901 Use OAEP padding with custodia - Use RSA-OAEP instead of RSA PKCS#1 v1.5 - Resolves: #1371915 When establishing external two-way trust, forest root Administrator account is used to fetch domain info - do not use trusted forest name to construct domain admin principal - Resolves: #1372597 Incorrect CA ACL evaluation of SAN DNS names in certificate request - Fix CA ACL Check on SubjectAltNames - Resolves: #1373272 CLI always sends default command version - cli: use full name when executing a command - Resolves: #1373359 ipa-certupdate fails with "CA is not configured" - Fix ipa-certupdate for CA-less installation - Resolves: #1373540 client-install with IPv6 address fails on link-local address (always) - Fix parse errors with link-local addresses- Resolves: #1081561 CA not start during ipa server install in pure IPv6 env - Fix ipa-server-install in pure IPv6 environment - Resolves: #1318169 Tree-root domains in a trusted AD forest aren't marked as reachable via the forest root - trust: make sure ID range is created for the child domain even if it exists - ipa-kdb: simplify trusted domain parent search - Resolves: #1335567 Update Warning in IdM Web UI API browser - WebUI: add API browser is tech preview warning - Resolves: #1348560 Mulitple domain Active Directory Trust conflict - ipaserver/dcerpc: reformat to make the code closer to pep8 - trust: automatically resolve DNS trust conflicts for triangle trusts - Resolves: #1351593 CVE-2016-5404 ipa: Insufficient privileges check in certificate revocation - cert-revoke: fix permission check bypass (CVE-2016-5404) - Resolves: #1353936 custodia.conf and server.keys file is world-readable. - Remove Custodia server keys from LDAP - Secure permissions of Custodia server.keys - Resolves: #1358752 ipa-ca-install fails on replica when IPA server is converted from CA-less to CA-full - custodia: include known CA certs in the PKCS#12 file for Dogtag - custodia: force reconnect before retrieving CA certs from LDAP - Resolves: #1362333 ipa vault container owner cannot add vault - Fix: container owner should be able to add vault - Resolves: #1365546 External trust with root domain is transitive - trust: make sure external trust topology is correctly rendered - Resolves: #1365572 IPA server broken after upgrade - Require pki-core-10.3.3-7 - Resolves: #1367864 Server assumes latest version of command instead of version 1 for old / 3rd party clients - rpcserver: assume version 1 for unversioned command calls - rpcserver: fix crash in XML-RPC system commands - Resolves: #1367773 thin client ignores locale change - schema cache: Fallback to 'en_us' when locale is not available - Resolves: #1368754 ipa server uninstall fails with Python "Global Name error" - Fail on topology disconnect/last role removal - Resolves: #1368981 ipa otptoken-add --type=hotp --key creates wrong OTP - otptoken, permission: Convert custom type parameters on server - Resolves: #1369414 ipa server-del fails with Python stack trace - Handled empty hostname in server-del command - Resolves: #1369761 ipa-server must depend on a version of httpd that support mod_proxy with UDS - Require httpd 2.4.6-31 with mod_proxy Unix socket support - Resolves: #1370512 Received ACIError instead of DuplicatedError in stageuser_tests - Raise DuplicatedEnrty error when user exists in delete_container - Resolves: #1371479 cert-find --all does not show information about revocation - cert: add missing param values to cert-find output - Renamed patch 1011 to 0100, as it was merged upstream- Resolves: #1298288 [RFE] Improve performance in large environments. - cert: speed up cert-find - Resolves: #1317379 [EXPERIMENTAL][RFE] Web UI: allow Smart Card authentication - service: add flag to allow S4U2Self - Add 'trusted to auth as user' checkbox - Added new authentication method - Resolves: #1353881 ipa-replica-install suggests about non-existent --force-ntpd option - Don't show --force-ntpd option in replica install - Resolves: #1354441 DNS forwarder check is too strict: unable to add sub-domain to already-broken domain - DNS: allow to add forward zone to already broken sub-domain - Resolves: #1356146 performance regression in CLI help - schema: Speed up schema cache - frontend: Change doc, summary, topic and NO_CLI to class properties - schema: Introduce schema cache format - schema: Generate bits for help load them on request - help: Do not create instances to get information about commands and topics - schema cache: Do not reset ServerInfo dirty flag - schema cache: Do not read fingerprint and format from cache - Access data for help separately - frontent: Add summary class property to CommandOverride - schema cache: Read server info only once - schema cache: Store API schema cache in memory - client: Do not create instance just to check isinstance - schema cache: Read schema instead of rewriting it when SchemaUpToDate - Resolves: #1360769 ipa-server-certinstall couldnt unlock private key file - server install: do not prompt for cert file PIN repeatedly - Resolves: #1364113 ipa-password: ipa: ERROR: RuntimeError: Unable to create cache directory: [Errno 13] Permission denied: '/home/test_user' - schema: Speed up schema cache - Resolves: #1366604 `cert-find` crashes on invalid certificate data - cert: do not crash on invalid data in cert-find - Resolves: #1366612 Middle replica uninstallation in line topology works without '--ignore-topology-disconnect' - Fail on topology disconnect/last role removal - Resolves: #1366626 caacl-add-service: incorrect error message when service does not exists - Fix ipa-caalc-add-service error message - Resolves: #1367022 The ipa-server-upgrade command failed when named-pkcs11 does not happen to run during dnf upgrade - DNS server upgrade: do not fail when DNS server did not respond - Resolves: #1367759 [RFE] [webui] warn admin if there is only one IPA server with CA - Add warning about only one existing CA server - Set servers list as default facet in topology facet group - Resolves: #1367773 thin client ignores locale change - schema check: Check current client language against cached one- Resolves: #1361119 UPN-based search for AD users does not match an entry in slapi-nis map cache - support multiple uid values in schema compatibility tree- Resolves: #1309700 Process /usr/sbin/winbindd was killed by signal 6 - Revert "spec: add conflict with bind-chroot to freeipa-server-dns" - Resolves: #1341249 Subsequent external CA installation fails - install: fix external CA cert validation - Resolves: #1353831 ipa-server-install fails in container because of hostnamectl set-hostname - server-install: Fix --hostname option to always override api.env values - install: Call hostnamectl set-hostname only if --hostname option is used - Resolves: #1356091 ipa-cacert-manage --help and man differ - Improvements for the ipa-cacert-manage man and help - Resolves: #1360631 ipa-backup is not keeping the /etc/tmpfiles.d/dirsrv-.conf - ipa-backup: backup /etc/tmpfiles.d/dirsrv-.conf - Resolves: #1361047 ipa-replica-install --help usage line suggests the replica file is needed - Update ipa-replica-install documentation - Resolves: #1361545 ipa-client-install starts rhel-domainname.service but does not rpm-require it - client: RPM require initscripts to get *-domainname.service - Resolves: #1364197 caacl: error when instantiating rules with service principals - caacl: fix regression in rule instantiation - Resolves: #1364310 ipa otptoken-add bytes object has no attribute confirm - parameters: move the `confirm` kwarg to Param - Resolves: #1364464 Topology graph: ca and domain adders shows question marks instead of plus icon - Fix unicode characters in ca and domain adders - Resolves: #1365083 Incomplete output returned for command ipa vault-add - client: add missing output params to client-side commands - Resolves: #1365526 build fails during "make check" - ipa-kdb: Fix unit test after packaging changes in krb5- Resolves: #1353829 traceback message seen in ipaserver-uninstall.log file. - Do not initialize API in ipa-client-automount uninstall - Resolves: #1356899 com.redhat.idm.trust.fetch_domains need update after thin client changes - idrange: fix unassigned global variable - Resolves: #1360792 Migrating users doesn't update krbCanonicalName - re-set canonical principal name on migrated users - Resolves: #1362012 ipa hbactest produces error about cannot concatenate 'str' and 'bool' objects - Fix ipa hbactest output - Resolves: #1362260 ipa vault-mod no longer allows defining salt - vault: add missing salt option to vault_mod - Resolves: #1362312 ipa vault-retrieve internal error when using the wrong public key - vault: Catch correct exception in decrypt - Resolves: #1362537 ipa-server-install fails to create symlink from /etc/ipa/kdcproxy/ to /etc/httpd/conf.d/ - Correct path to HTTPD's systemd service directory - Resolves: #1363756 Increase length of passwords generated by installer - Increase default length of auto generated passwords- Resolves: #1117306 [RFE] Allow multiple Principals per host entry (Kerberos aliases) - harden the check for trust namespace overlap in new principals - Resolves: #1351142 CLI is not using session cookies for communication with IPA API - Fix session cookies - Resolves: #1353888 Fix the help for ipa otp and other topics - help: Add dnsserver commands to help topic 'dns' - Resolves: #1354406 host-del updatedns options complains about missing ptr record for host - Host-del: fix behavior of --updatedns and PTR records - Resolves: #1355718 ipa-replica-manage man page example output differs actual command output - Minor fix in ipa-replica-manage MAN page - Resolves: #1358229 Traceback message should be fixed, seen while editing winsync migrated user information in Default trust view. - baseldap: Fix MidairCollision instantiation during entry modification - Resolves: #1358849 CA replica install logs to wrong log file - unite log file name of ipa-ca-install - Resolves: #1359130 ipa-server-install command fails to install IPA server. - DNS Locations: fix update-system-records unpacking error - Resolves: #1359237 AVC on dirsrv config caused by IPA installer - Use copy when replacing files to keep SELinux context - Resolves: #1359692 ipa-client-install join fail with traceback against RHEL-6.8 ipa-server - compat: fix ping call - Resolves: #1359738 ipa-replica-install --domain= option does not work - replica-install: Fix --domain - Resolves: #1360778 Vault commands are available in CLI even when the server does not support them - Revert "Enable vault-* commands on client" - client: fix hiding of commands which lack server support - Related: #1281704 Rebase to softhsm 2.1.0 - Remove the workaround for softhsm bug #1293340 - Related: #1298288 [RFE] Improve performance in large environments. - Create indexes for krbCanonicalName attribute- Resolves: #1296140 Remove redhat-access-plugin-ipa support - Obsolete and conflict redhat-access-plugin-ipa - Resolves: #1351119 Multiple issues while uninstalling ipa-server - server uninstall fails to remove krb principals - Resolves: #1351758 ipa commands not showing expected error messages - frontend: copy command arguments to output params on client - Show full error message for selinuxusermap-add-hostgroup - Resolves: #1352883 Traceback on adding default automember group and hostgroup set - allow 'value' output param in commands without primary key - Resolves: #1353888 Fix the help for ipa otp and other topics - schema: Fix subtopic -> topic mapping - Resolves: #1354348 ipa trustconfig-show throws internal error. - allow 'value' output param in commands without primary key - Resolves: #1354381 ipa trust-add with raw option gives internal error. - trust-add: handle `--all/--raw` options properly - Resolves: #1354493 Replica install fails with old IPA master - DNS install: Ensure that DNS servers container exists - Resolves: #1354628 ipa hostgroup-add-member does not return error message when adding itself as member - frontend: copy command arguments to output params on client - Resolves: #1355856 ipa otptoken-add --type=totp gives internal error - messages: specify message type for ResultFormattingError - Resolves: #1356063 "ipa radiusproxy-add" command needs to prompt to enter secret key - expose `--secret` option in radiusproxy-* commands - prevent search for RADIUS proxy servers by secret - Resolves: #1356099 Bug in the ipapwd plugin - Heap corruption in ipapwd plugin - Resolves: #1356899 com.redhat.idm.trust.fetch_domains need update after thin client changes - Use server API in com.redhat.idm.trust-fetch-domains oddjob helper - Resolves: #1356964 Renaming a user removes all of his principal aliases - Preserve user principal aliases during rename operation- Resolves: #1274524 [RFE] Qualify up to 60 IdM replicas - Resolves: #1320838 [RFE] Support IdM Client in a DNS domain controlled by AD - Related: #1356134 'kinit -E' does not work for IPA user- Resolves: #1356102 Server uninstall does not stop tracking lightweight sub-CA with certmonger - uninstall: untrack lightweight CA certs - Resolves: #1351807 ipa-nis-manage config.get_dn missing - ipa-nis-manage: Use server API to retrieve plugin status - Resolves: #1353452 ipa-compat-manage command failed, exception: NotImplementedError: config.get_dn() - ipa-compat-manage: use server API to retrieve plugin status - Resolves: #1353899 ipa-advise: object of type 'type' has no len() - ipa-advise: correct handling of plugin namespace iteration - Resolves: #1356134 'kinit -E' does not work for IPA user - kdb: check for local realm in enterprise principals - Resolves: #1353072 ipa unknown command vault-add - Enable vault-* commands on client - vault-add: set the default vault type on the client side if none was given - Resolves: #1353995 Default CA can be used without a CA ACL - caacl: expand plugin documentation - Resolves: #1356144 host-find should not print SSH keys by default, only SSH fingerprints - host-find: do not show SSH key by default - Resolves: #1353506 ipa migrate-ds command fails for IPA in RHEL 7.3 - Removed unused method parameter from migrate-ds- Resolves: #747612 [RFE] IPA should support and manage DNS sites - Resolves: #826790 Disabling password expiration (--maxlife=0 and --minlife=0) in the default global_policy in IPA sets user's password expiration (krbPasswordExpiration) to be 90 days - Resolves: #896699 ipa-replica-manage -H does not delete DNS SRV records - Resolves: #1084018 [RFE] Add IdM user password change support for legacy client compat tree - Resolves: #1117306 [RFE] Allow multiple Principals per host entry (Kerberos aliases) - Fix incorrect check for principal type when evaluating CA ACLs - Resolves: #1146860 [RFE] Offer OTP generation for host enrollment in the UI - Resolves: #1238190 ipasam unable to lookup group in directory yet manual search works - Resolves: #1250110 search by users which don't have read rights for all attrs in search_attributes fails - Resolves: #1263764 Show Certificate displays in useless format - Resolves: #1272491 [WebUI] Certificate action dropdown does not display all the options after adding new certificate - Resolves: #1292141 Rebase to FreeIPA 4.4+ - Rebase to 4.4.0 - Resolves: #1294503 IPA fails to issue 3rd party certs - Resolves: #1298242 [RFE] API compatibility - compatibility of clients - Resolves: #1298848 [RFE] Centralized topology management - Resolves: #1298966 [RFE] Extend Smart Card support - Resolves: #1315146 Multiple clients cannot join domain simultaneously: /var/run/httpd/ipa/clientcaches race condition? - Resolves: #1318903 ipa server install failing when SUBCA signs the cert - Resolves: #1319003 ipa-winsync-migrate: Traceback should be fixed with proper console output - Resolves: #1324055 IPA always qualify requests for admin - Resolves: #1328552 [RFE] Allow users to authenticate with alternative names - Resolves: #1334582 Inconsistent UI and CLI options for removing certificate hold - Resolves: #1346321 Exclude o=ipaca subtree from Retro Changelog (syncrepl) - Resolves: #1349281 Fix `Conflicts` with ipa-python - Resolves: #1350695 execution of copy-schema script fails - Resolves: #1351118 upgrade failed for RHEL-7.3 from RHEL-7.2.z - Resolves: #1351153 AVC seen on Replica during ipa-server upgrade test execution to 7.3 - Resolves: #1351276 ipa-server-install with dns cannot resolve itself to create ipa-ca entry - Related: #1343422 [RFE] Add GssapiImpersonate option- Resolves: #1348948 IPA server install fails with build ipa-server-4.4.0-0.el7.1.alpha1 - Revert "Increased mod_wsgi socket-timeout"- Resolves: #712109 "krbExtraData not allowed" is logged in DS error log while setting password for default sudo binddn. - Resolves: #747612 [RFE] IPA should support and manage DNS sites - Resolves: #768316 [RFE] ipa-getkeytab should auto-detect the ipa server name - Resolves: #825391 [RFE] Replica installation should provide a means for inheriting nssldap security access settings - Resolves: #921497 Incorrect *.py[co] files placement - Resolves: #1029640 RHEL7 IPA to add DNA Plugin config for dnaRemote support - Resolves: #1029905 389 DS cache sizes not replicated to IPA replicas - Resolves: #1196958 IPA replica installation failing with high number of users (160000). - Resolves: #1219402 IPA suggests to uninstall a client when the user needs to uninstall a replica - Resolves: #1224057 [RFE] TGS authorization decisions in KDC based on Authentication Indicator - Resolves: #1234222 [WebUI] UI error message is not appropriate for "Kerberos principal expiration" - Resolves: #1234223 [WebUI] General invalid password error message appearing for "Locked user" - Resolves: #1254267 ipa-server-install failure applying ldap updates with limits exceeded - Resolves: #1258626 realmdomains-mod --add-domain command throwing error when doamin already is in forwardzone. - Resolves: #1259020 ipa-server-adtrust-install doesn't allow NetBIOS-name=EXAMPLE-TEST.COM (dash character) - Resolves: #1260993 DNSSEC signing enablement on dnszone should throw error message when DNSSEC master not installed - Resolves: #1262747 dnssec options missing in ipa-dns-install man page - Resolves: #1265900 Fail installation immediately after dirsrv fails to install using ipa-server-install - Resolves: #1265915 idoverrideuser-find fails if any SID anchor is not resolvable anymore - Resolves: #1268027 ipa-dnskeysync-replica crash with backtrace - LimitsExceeded: limits exceeded for this query - Resolves: #1269089 Certificate of managed-by host/service fails to resubmit - Resolves: #1269200 ipa-server crashing while trying to preserve admin user - Resolves: #1271321 Reduce ioblocktimeout and idletimeout defaults - Resolves: #1271579 Automember rule expressions disappear from tables on single expression delete - Resolves: #1275816 Incomplete ports for IPA ad-trust - Resolves: #1276351 [RFE] Remove /usr/share/ipa/updates/50-lockout-policy.update file from IPA releases - Resolves: #1277109 Add tool tips for Revert, Refresh, Undo, and Undo All in the IPA UI - Resolves: #1278426 Better error message needed for invalid ca-signing-algo option - Resolves: #1279932 ipa-client-install --request-cert needs workaround in anaconda chroot - Resolves: #1282521 Creating a user w/o private group fails when doing so in WebUI - Resolves: #1283879 ipa-winsync-migrate: Traceback message should be replaced by "IPA is not configured on this system" - Resolves: #1285071 ipa-kra-install fails on replica looking for admin cert file - Resolves: #1287194 [RFE] Support of UPN for trusted domains - Resolves: #1288967 Normalize Manager entry in ipa user-add - Resolves: #1289487 Priority field missing in Password Policy detail tab - Resolves: #1291140 ipa client should configure kpasswd_server directive in krb5.conf - Resolves: #1292141 Rebase to FreeIPA 4.4+ - Rebase to 4.4.0.alpha1 - Resolves: #1298848 [RFE] Centralized topology management - Resolves: #1300576 Browser setup page includes instructions for Internet Explorer - Resolves: #1301586 ipa host-del --updatedns should remove related dns entries. - Resolves: #1304618 Residual Files After IPA Server Uninstall - Resolves: #1305144 ipa-python does not require its dependencies - Resolves: #1309700 Process /usr/sbin/winbindd was killed by signal 6 - Resolves: #1313798 Console output post ipa-winsync-migrate command should be corrected. - Resolves: #1314786 [RFE] External Trust with Active Directory domain - Resolves: #1319023 Include description for 'status' option in man page for ipactl command. - Resolves: #1319912 ipa-server-install does not completely change hostname and named-pkcs11 fails - Resolves: #1320891 IPA Error 3009: Validation error: Invalid 'ptrrecord': Reverse zone in-addr.arpa. requires exactly 4 IP address compnents, 5 given - Resolves: #1327207 ipa cert-revoke --help doesn't provide enough info on revocation reasons - Resolves: #1328549 "ipa-kra-install" command reports incorrect message when it is executed on server already installed with KRA. - Resolves: #1329209 ipa-nis-manage enable: change service name from 'portmap' to 'rpcbind' - Resolves: #1329275 ipa-nis-manage command should include status option - Resolves: #1330843 'man ipa' should be updated with latest commands - Resolves: #1333755 ipa cert-request causes internal server error while requesting certificate - Resolves: #1337484 EOF is not handled for ipa-client-install command - Resolves: #1338031 Insufficient 'write' privilege on some attributes for the members of the role which has "User Administrators" privilege. - Resolves: #1343142 IPA DNS should do better verification of DNS zones - Resolves: #1347928 Frontpage exposes runtime error with no cookies enabled in browser- Resolves: #1339483 ipa-server-install fails with ERROR pkinit_cert_files - Fix incorrect rebase of patch 1001- Resolves: #1339233 CA installed on replica is always marked as renewal master - Related: #1292141 Rebase to FreeIPA 4.4+ - Rebase to 4.3.1.201605241723GIT1b427d3- Resolves: #1332809 ipa-server-4.2.0-15.el7_2.6.1.x86_64 fails to install because of missing dependencies - Rebuild with krb5-1.14.1- Resolves: #837369 [RFE] Switch to client promotion to replica model - Resolves: #1199516 [RFE] Move replication topology to the shared tree - Resolves: #1206588 [RFE] Visualize FreeIPA server replication topology - Resolves: #1211602 Hide ipa-server-install KDC master password option (-P) - Resolves: #1212713 ipa-csreplica-manage: it could be nice to have also list-ruv / clean-ruv / abort-clean-ruv for o=ipaca backend - Resolves: #1267206 ipa-server-install uninstall should warn if no installation found - Resolves: #1295865 The Domain option is not correctly set in idmapd.conf when ipa-client-automount is executed. - Resolves: #1327092 URI details missing and OCSP-URI details are incorrectly displayed when certificate generated using IPA on RHEL 7.2up2. - Resolves: #1332809 ipa-server-4.2.0-15.el7_2.6.1.x86_64 fails to install because of missing dependencies - Related: #1292141 Rebase to FreeIPA 4.4+ - Rebase to 4.3.1.201605191449GITf8edf37- Resolves: #1277696 IPA certificate auto renewal fail with "Invalid Credential" - cert renewal: make renewal of ipaCert atomic - Resolves: #1278330 installer options are not validated at the beginning of installation - install: fix command line option validation - Resolves: #1282845 sshd_config change on ipa-client-install can prevent sshd from starting up - client install: do not corrupt OpenSSH config with Match sections - Resolves: #1282935 ipa upgrade causes vault internal error - install: export KRA agent PEM file in ipa-kra-install - Resolves: #1283429 Default CA ACL rule is not created during ipa-replica-install - TLS and Dogtag HTTPS request logging improvements - Avoid race condition caused by profile delete and recreate - Do not erroneously reinit NSS in Dogtag interface - Add profiles and default CA ACL on migration - disconnect ldap2 backend after adding default CA ACL profiles - do not disconnect when using existing connection to check default CA ACLs - Resolves: #1283430 ipa-kra-install: fails to apply updates - suppress errors arising from adding existing LDAP entries during KRA install - Resolves: #1283748 Caching of ipaconfig does not work in framework - fix caching in get_ipa_config - Resolves: #1283943 IPA DNS Zone/DNS Forward Zone details missing after upgrade from RHEL 7.0 to RHEL 7.2 - upgrade: fix migration of old dns forward zones - Fix upgrade of forwardzones when zone is in realmdomains - Resolves: #1284413 ipa-cacert-manage renew fails on nonexistent ldap connection - ipa-cacert-renew: Fix connection to ldap. - Resolves: #1284414 ipa-otptoken-import fails on nonexistent ldap connection - ipa-otptoken-import: Fix connection to ldap. - Resolves: #1286635 IPA server upgrade fails from RHEL 7.0 to RHEL 7.2 using "yum update ipa* sssd" - Set minimal required version for openssl - Resolves: #1286781 ipa-nis-manage does not update ldap with all NIS maps - Upgrade: Fix upgrade of NIS Server configuration - Resolves: #1289311 umask setting causes named-pkcs11 issue with directory permissions on /var/lib/ipa/dnssec - DNS: fix file permissions - Explicitly call chmod on newly created directories - Fix: replace mkdir with chmod - Resolves: #1290142 Broken 7.2.0 to 7.2.z upgrade - flawed version comparison - Fix version comparison - use FFI call to rpmvercmp function for version comparison - Resolves: #1292595 In IPA-AD trust environment some secondary IPA based Posix groups are missing - ipa-kdb: map_groups() consider all results - Resolves: #1293870 User should be notified for wrong password in password reset page - Fixed login error message box in LoginScreen page - Resolves: #1296196 Sysrestore did not restore state if a key is specified in mixed case - Allow to used mixed case for sysrestore - Resolves: #1296214 DNSSEC key purging is not handled properly - DNSSEC: Improve error reporting from ipa-ods-exporter - DNSSEC: Make sure that current state in OpenDNSSEC matches key state in LDAP - DNSSEC: Make sure that current key state in LDAP matches key state in BIND - DNSSEC: remove obsolete TODO note - DNSSEC: add debug mode to ldapkeydb.py - DNSSEC: logging improvements in ipa-ods-exporter - DNSSEC: remove keys purged by OpenDNSSEC from master HSM from LDAP - DNSSEC: ipa-dnskeysyncd: Skip zones with old DNSSEC metadata in LDAP - DNSSEC: ipa-ods-exporter: add ldap-cleanup command - DNSSEC: ipa-dnskeysyncd: call ods-signer ldap-cleanup on zone removal - DNSSEC: Log debug messages at log level DEBUG - Resolves: #1296216 ipa-server-upgrade fails if certmonger is not running - prevent crash of CA-less server upgrade due to absent certmonger - always start certmonger during IPA server configuration upgrade - Resolves: #1297811 The ipa -e skip_version_check=1 still issues incompatibility error when called against RHEL 6 server - ipalib: assume version 2.0 when skip_version_check is enabled - Resolves: #1298289 install fails when locale is "fr_FR.UTF-8" - Do not decode HTTP reason phrase from Dogtag - Resolves: #1300252 shared certificateProfiles container is missing on a freshly installed RHEL7.2 system - upgrade: unconditional import of certificate profiles into LDAP - Resolves: #1301674 --setup-dns and other options is forgotten for using an external PKI - installer: Propagate option values from components instead of copying them. - installer: Fix logic of reading option values from cache. - Resolves: #1301687 issues with migration from RHEL 6 self-signed to RHEL 7 CA IPA setup - ipa-ca-install: print more specific errors when CA is already installed - cert renewal: import all external CA certs on IPA CA cert renewal - CA install: explicitly set dogtag_version to 10 - fix standalone installation of externally signed CA on IPA master - replica install: validate DS and HTTP server certificates - replica install: improvements in the handling of CA-related IPA config entries - Resolves: #1301901 [RFE] compat tree: show AD members of IPA groups - slapi-nis: update configuration to allow external members of IPA groups - Resolves: #1305533 ipa trust-add succeded but after that ipa trust-find returns "0 trusts matched" - upgrade: fix config of sidgen and extdom plugins - trusts: use ipaNTTrustPartner attribute to detect trust entries - Warn user if trust is broken - fix upgrade: wait for proper DS socket after DS restart - Insure the admin_conn is disconnected on stop - Fix connections to DS during installation - Fix broken trust warnings - Resolves: #1321092 Installers fail when there are multiple versions of the same certificate - certdb: never use the -r option of certutil - Related: #1317381 Crash during IPA upgrade due to slapd - spec file: update minimum required version of slapi-nis - Related: #1322691 CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118 samba: various flaws [rhel-7.3] - Rebuild against newer Samba version- Resolves: #1252556 Missing CLI param and ACL for vault service operations - vault: fix private service vault creation- Resolves: #1262996 ipa vault internal error on replica without KRA - upgrade: make sure ldap2 is connected in export_kra_agent_pem - Resolves: #1270608 IPA upgrade fails for server with CA cert signed by external CA - schema: do not derive ipaVaultPublicKey from ipaPublicKey- Resolves: #1217009 OTP sync in UI does not work for TOTP tokens - Fix an integer underflow bug in libotp - Resolves: #1262996 ipa vault internal error on replica without KRA - install: always export KRA agent PEM file - vault: select a server with KRA for vault operations - Resolves: #1269777 IPA restore overwrites /etc/passwd and /etc/group files - do not overwrite files with local users/groups when restoring authconfig - Renamed patch 1011 to 0138, as it was merged upstream- Resolves: #1204205 [RFE] ID Views: Automated migration tool from Winsync to Trusts - winsync-migrate: Convert entity names to posix friendly strings - winsync-migrate: Properly handle collisions in the names of external groups - Resolves: #1261074 Adjust Firefox configuration to new extension signing policy - webui: use manual Firefox configuration for Firefox >= 40 - Resolves: #1263337 IPA Restore failed with installed KRA - ipa-backup: Add mechanism to store empty directory structure - Resolves: #1264793 CVE-2015-5284 ipa: ipa-kra-install includes certificate and private key in world readable file [rhel-7.2] - install: fix KRA agent PEM file permissions - Resolves: #1265086 Mark IdM API Browser as experimental - WebUI: add API browser is experimental warning - Resolves: #1265277 Fix kdcproxy user creation - install: create kdcproxy user during server install - platform: add option to create home directory when adding user - install: fix kdcproxy user home directory - Resolves: #1265559 GSS failure after ipa-restore - destroy httpd ccache after stopping the service- Resolves: #1258965 ipa vault: set owner of vault container - baseldap: make subtree deletion optional in LDAPDelete - vault: add vault container commands - vault: set owner to current user on container creation - vault: update access control - vault: add permissions and administrator privilege - install: support KRA update - Resolves: #1261586 ipa config-mod addattr fails for ipauserobjectclasses - config: allow user/host attributes with tagging options - Resolves: #1262315 Unable to establish winsync replication - winsync: Add inetUser objectclass to the passsync sysaccount- Resolves: #1260663 crash of ipa-dnskeysync-replica component during ipa-restore - IPA Restore: allows to specify files that should be removed - Resolves: #1261806 Installing ipa-server package breaks httpd - Handle timeout error in ipa-httpd-kdcproxy - Resolves: #1262322 Failed to backup CS.cfg message in upgrade. - Server Upgrade: backup CS.cfg when dogtag is turned off- Resolves: #1257074 The KRA agent cert is stored in a PEM file that is not tracked - cert renewal: Include KRA users in Dogtag LDAP update - cert renewal: Automatically update KRA agent PEM file - Resolves: #1257163 renaming certificatte profile with --rename option leads to integrity issues - certprofile: remove 'rename' option - Resolves: #1257968 kinit stop working after ipa-restore - Backup: back up the hosts file - Resolves: #1258926 Remove 'DNSSEC is experimental' warnings - DNSSEC: remove "DNSSEC is experimental" warnings - Resolves: #1258929 Uninstallation of IPA leaves extra entry in /etc/hosts - Installer: do not modify /etc/hosts before user agreement - Resolves: #1258944 DNSSEC daemons may deadlock when processing more than 1 zone - DNSSEC: backup and restore opendnssec zone list file - DNSSEC: remove ccache and keytab of ipa-ods-exporter - DNSSEC: prevent ipa-ods-exporter from looping after service auto-restart - DNSSEC: Fix deadlock in ipa-ods-exporter <-> ods-enforcerd interaction - DNSSEC: Fix HSM synchronization in ipa-dnskeysyncd when running on DNSSEC key master - DNSSEC: Fix key metadata export - DNSSEC: Wrap master key using RSA OAEP instead of old PKCS v1.5. - Resolves: #1258964 revert to use ldapi to add kra agent in KRA install - Using LDAPI to setup CA and KRA agents. - Resolves: #1259848 server closes connection and refuses commands after deleting user that is still logged in - ldap: Make ldap2 connection management thread-safe again - Resolves: #1259996 AttributeError: 'NameSpace' object has no attribute 'ra_certprofile' while ipa-ca-install - load RA backend plugins during standalone CA install on CA-less IPA master- Resolves: #1254689 Storing big file as a secret in vault raises traceback - vault: Limit size of data stored in vault - Resolves: #1255880 ipactl status should distinguish between different pki-tomcat services - ipactl: Do not start/stop/restart single service multiple times- Resolves: #1256840 [webui] majority of required fields is no longer marked as required - fix missing information in object metadata - Resolves: #1256842 [webui] no option to choose trust type when creating a trust - webui: add option to establish bidirectional trust - Resolves: #1256853 Clear text passwords in KRA install log - Removed clear text passwords from KRA install log. - Resolves: #1257072 The "Standard Vault" MUST not be the default and must be discouraged - vault: change default vault type to symmetric - Resolves: #1257163 renaming certificatte profile with --rename option leads to integrity issues - certprofile: prevent rename (modrdn)- Resolves: #1249226 IPA dnssec-validation not working for AD dnsforwardzone - DNSSEC: fix forward zone forwarders checks - Resolves: #1250190 idrange is not added for sub domain - trusts: format Kerberos principal properly when fetching trust topology - Resolves: #1252334 User life cycle: missing ability to provision a stage user from a preserved user - Add user-stage command - Resolves: #1252863 After applying RHBA-2015-1554 errata, IPA service fails to start. - spec file: Add Requires(post) on selinux-policy - Resolves: #1254304 Changing vault encryption attributes - Change internal rsa_(public|private)_key variable names - Added support for changing vault encryption. - Resolves: #1256715 Executing user-del --preserve twice removes the user pernamently - improve the usability of `ipa user-del --preserve` command- Resolves: #1199530 [RFE] Provide user lifecycle managment capabilities - user-undel: Fix error messages. - Resolves: #1200694 [RFE] Support for multiple cert profiles - Prohibit deletion of predefined profiles - Resolves: #1232819 testing ipa-restore on fresh system install fails - Backup/resore authentication control configuration - Resolves: #1243331 pkispawn fails when migrating to 4.2 server from 3.0 server - Require Dogtag PKI >= 10.2.6 - Resolves: #1245225 Asymmetric vault drops traceback when the key is not proper - Asymmetric vault: validate public key in client - Resolves: #1248399 Missing DNSSEC related files in backup - fix typo in BasePathNamespace member pointing to ods exporter config - ipa-backup: archive DNSSEC zone file and kasp.db - Resolves: #1248405 PassSync should be disabled after ipa-winsync-migrate is finished - winsync-migrate: Add warning about passsync - winsync-migrate: Expand the man page - Resolves: #1248524 User can't find any hosts using "ipa host-find $HOSTNAME" - adjust search so that it works for non-admin users - Resolves: #1250093 ipa certprofile-import accepts invalid config - Require Dogtag PKI >= 10.2.6 - Resolves: #1250107 IPA framework should not allow modifying trust on AD trust agents - trusts: Detect missing Samba instance - Resolves: #1250111 User lifecycle - preserved users can be assigned membership - ULC: Prevent preserved users from being assigned membership - Resolves: #1250145 Add permission for user to bypass caacl enforcement - Add permission for bypassing CA ACL enforcement - Resolves: #1250190 idrange is not added for sub domain - idranges: raise an error when local IPA ID range is being modified - trusts: harden trust-fetch-domains oddjobd-based script - Resolves: #1250928 Man page for ipa-server-install is out of sync - install: Fix server and replica install options - Resolves: #1251225 IPA default CAACL does not allow cert-request for services after upgrade - Fix default CA ACL added during upgrade - Resolves: #1251561 ipa vault-add Unknown option: ipavaultpublickey - validate mutually exclusive options in vault-add - Resolves: #1251579 ipa vault-add --user should set container owner equal to user on first run - Fixed vault container ownership. - Resolves: #1252517 cert-request rejects request with correct krb5PrincipalName SAN - Fix KRB5PrincipalName / UPN SAN comparison - Resolves: #1252555 ipa vault-find doesn't work for services - vault: Add container information to vault command results - Add flag to list all service and user vaults - Resolves: #1252556 Missing CLI param and ACL for vault service operations - Added CLI param and ACL for vault service operations. - Resolves: #1252557 certprofile: improve profile format documentation - certprofile-import: improve profile format documentation - certprofile: add profile format explanation - Resolves: #1253443 ipa vault-add creates vault with invalid type - vault: validate vault type - Resolves: #1253480 ipa vault-add-owner does not fail when adding an existing owner - baseldap: Allow overriding member param label in LDAPModMember - vault: Fix param labels in output of vault owner commands - Resolves: #1253511 ipa vault-find does not use criteria - vault: Fix vault-find with criteria - Resolves: #1254038 ipa-replica-install pk12util error returns exit status 10 - install: Fix replica install with custom certificates - Resolves: #1254262 ipa-dnskeysync-replica crash cannot contact kdc - improve the handling of krb5-related errors in dnssec daemons - Resolves: #1254412 when dirsrv is off ,upgrade from 7.1 to 7.2 fails with starting CA and named-pkcs11.service - Server Upgrade: Start DS before CA is started. - Resolves: #1254637 Add ACI and permission for managing user userCertificate attribute - add permission: System: Manage User Certificates - Resolves: #1254641 Remove CSR allowed-extensions restriction - cert-request: remove allowed extensions check - Resolves: #1254693 vault --service does not normalize service principal - vault: normalize service principal in service vault operations - Resolves: #1254785 ipa-client-install does not properly handle dual stacked hosts - client: Add support for multiple IP addresses during installation. - Add dependency to SSSD 1.13.1 - client: Add description of --ip-address and --all-ip-addresses to man page- Resolves: #1072383 [RFE] Provide ability to map CAC identity certificates to users in IdM - store certificates issued for user entries as - user-show: add --out option to save certificates to file - Resolves: #1145748 [RFE] IPA running with One Way Trust - Fix upgrade of sidgen and extdom plugins - Resolves: #1195339 ipa-client-install changes the label on various files which causes SELinux denials - Use 'mv -Z' in specfile to restore SELinux context - Resolves: #1198796 Text in UI should describe differing LDAP vs Krb behavior for combinations of "User authentication types" - webui: add LDAP vs Kerberos behavior description to user auth - Resolves: #1199530 [RFE] Provide user lifecycle managment capabilities - ULC: Fix stageused-add --from-delete command - Resolves: #1200694 [RFE] Support for multiple cert profiles - certprofile-import: do not require profileId in profile data - Give more info on virtual command access denial - Allow SAN extension for cert-request self-service - Add profile for DNP3 / IEC 62351-8 certificates - Work around python-nss bug on unrecognised OIDs - Resolves: #1204501 [RFE] Add Password Vault (KRA) functionality - Validate vault's file parameters - Fixed missing KRA agent cert on replica. - Resolves: #1225866 display browser config options that apply to the browser. - webui: add Kerberos configuration instructions for Chrome - Remove ico files from Makefile - Resolves: #1246342 Unapply idview raises internal error - idviews: Check for the Default Trust View only if applying the view - Resolves: #1248102 [webui] regression - incorrect/no failed auth messages - webui: fix regressions failed auth messages - Resolves: #1248396 Internal error in DomainValidator.__search_in_dc - dcerpc: Fix UnboundLocalError for ccache_name - Resolves: #1249455 ipa trust-add failed CIFS server configuration does not allow access to \\pipe\lsarpc - Fix selector of protocol for LSA RPC binding string - dcerpc: Simplify generation of LSA-RPC binding strings - Resolves: #1250192 Error in ipa trust-fecth-domains - Fix incorrect type comparison in trust-fetch-domains - Resolves: #1251553 Winsync setup fails with unexpected error - replication: Fix incorrect exception invocation - Resolves: #1251854 ipa aci plugin is not parsing aci's correctly. - ACI plugin: correctly parse bind rules enclosed in - Resolves: #1252414 Trust agent install does not detect available replicas to add to master - adtrust-install: Correctly determine 4.2 FreeIPA servers- Resolves: #1170770 [AD TRUST]IPA should detect inconsistent realm domains that conflicts with AD DC - trusts: Check for AD root domain among our trusted domains - Resolves: #1195339 ipa-client-install changes the label on various files which causes SELinux denials - sysrestore: copy files instead of moving them to avoind SELinux issues - Resolves: #1196656 [ipa-client][rhel71] enable debugging for spawned commands / ntpd -qgc $tmpfile hangs - enable debugging of ntpd during client installation - Resolves: #1205264 Migration UI Does Not Work When Anonymous Bind is Disabled - migration: Use api.env variables. - Resolves: #1212719 abort-clean-ruv subcommand should allow replica-certifyall: no - Allow value 'no' for replica-certify-all attr in abort-clean-ruv subcommand - Resolves: #1216935 ipa trust-add shows ipa: ERROR: an internal error has occurred - dcerpc: Expand explanation for WERR_ACCESS_DENIED - dcerpc: Fix UnboundLocalError for ccache_name - Resolves: #1222778 idoverride group-del can delete user and user-del can delete group - dcerpc: Add get_trusted_domain_object_type method - idviews: Restrict anchor to name and name to anchor conversions - idviews: Enforce objectclass check in idoverride*-del - Resolves: #1234919 Be able to request certificates without certmonger service running - cermonger: Use private unix socket when DBus SystemBus is not available. - ipa-client-install: Do not (re)start certmonger and DBus daemons. - Resolves: #1240939 Please add dependency on bind-pkcs11 - Create server-dns sub-package. - ipaplatform: Add constants submodule - DNS: check if DNS package is installed - Resolves: #1242914 Bump minimal selinux-policy and add booleans to allow calling out oddjobd-activated services - selinux: enable httpd_run_ipa to allow communicating with oddjobd services - Resolves: #1243261 non-admin users cannot search hbac rules - fix hbac rule search for non-admin users - fix selinuxusermap search for non-admin users - Resolves: #1243652 Client has missing dependency on memcache - do not import memcache on client - Resolves: #1243835 [webui] user change password dialog does not work - webui: fix user reset password dialog - Resolves: #1244802 spec: selinux denial during kdcproxy user creation - Fix selinux denial during kdcproxy user creation - Resolves: #1246132 trust-fetch-domains: Do not chown keytab to the sssd user - oddjob: avoid chown keytab to sssd if sssd user does not exist - Resolves: #1246136 Adding a privilege to a permission avoids validation - Validate adding privilege to a permission - Resolves: #1246141 DNS Administrators cannot search in zones - DNS: Consolidate DNS RR types in API and schema - Resolves: #1246143 User plugin - user-find doesn't work properly with manager option - fix broken search for users by their manager- Resolves: #1131907 [ipa-client-install] cannot write certificate file '/etc/ipa/ca.crt.new': must be string or buffer, not None - Resolves: #1195775 unsaved changes dialog internally inconsistent - Resolves: #1199530 [RFE] Provide user lifecycle managment capabilities - Stageusedr-activate: show username instead of DN - Resolves: #1200694 [RFE] Support for multiple cert profiles - Prevent to rename certprofile profile id - Resolves: #1222047 IPA to AD Trust: IPA ERROR 4016: Remote Retrieve Error - Resolves: #1224769 copy-schema-to-ca.py does not overwrites schema files - copy-schema-to-ca: allow to overwrite schema files - Resolves: #1241941 kdc component installation of IPA failed - spec file: Update minimum required version of krb5 - Resolves: #1242036 Replica install fails to update DNS records - Fix DNS records installation for replicas - Resolves: #1242884 Upgrade to 4.2.0 fails when enabling kdc proxy - Start dirsrv for kdcproxy upgrade- Resolves: #846033 [RFE] Documentation for JSONRPC IPA API - Resolves: #989091 Ability to manage IdM/IPA directly from a standard LDAP client - Resolves: #1072383 [RFE] Provide ability to map CAC identity certificates to users in IdM - Resolves: #1115294 [RFE] Add support for DNSSEC - Resolves: #1145748 [RFE] IPA running with One Way Trust - Resolves: #1199520 [RFE] Introduce single upgrade tool - ipa-server-upgrade - Resolves: #1199530 [RFE] Provide user lifecycle managment capabilities - Resolves: #1200694 [RFE] Support for multiple cert profiles - Resolves: #1200728 [RFE] Replicate PKI Profile information - Resolves: #1200735 [RFE] Allow issuing certificates for user accounts - Resolves: #1204054 SSSD database is not cleared between installs and uninstalls of ipa - Resolves: #1204205 [RFE] ID Views: Automated migration tool from Winsync to Trusts - Resolves: #1204501 [RFE] Add Password Vault (KRA) functionality - Resolves: #1204504 [RFE] Add access control so hosts can create their own services - Resolves: #1206534 [RFE] Offer Kerberos over HTTP (kdcproxy) by default - Resolves: #1206613 [RFE] Configure IPA to be a trust agent by default - Resolves: #1209476 package ipa-client does not require package dbus-python - Resolves: #1211589 [RFE] Add option to skip the verify_client_version - Resolves: #1211608 [RFE] Generic support for unknown DNS RR types (RFC 3597) - Resolves: #1215735 ipa-replica-prepare automatically adds a DNS zone - Resolves: #1217010 OTP Manager field is not exposed in the UI - Resolves: #1222475 krb5kdc : segfault at 0 ip 00007fa9f64d82bb sp 00007fffd68b2340 error 6 in libc-2.17.so - Related: #1204809 Rebase ipa to 4.2 - Update to upstream 4.2.0 - Move /etc/ipa/kdcproxy to the server subpackage- Resolves: #1228671 pkispawn fails in ipa-ca-install and ipa-kra-install - Related: #1204809 Rebase ipa to 4.2 - Fix minimum version of slapi-nis - Require python-sss and python-sss-murmur (provided by sssd-1.13.0)- Resolves: #805188 [RFE] "ipa migrate-ds" ldapsearches with scope=1 - Resolves: #1019272 With 20000+ users, adding a user to a group intermittently throws Internal server error - Resolves: #1035494 Unable to add Kerberos principal via kadmin.local - Resolves: #1045153 ipa-managed-entries --list -p still requires DM password - Resolves: #1125950 ipa-server-install --uinstall doesn't remove port 7389 from ldap_port_t - Resolves: #1132540 [RFE] Expose service delegation rules in UI and CLI - Resolves: #1145584 ipaserver/install/cainstance.py creates pkiuser not matching uidgid - Resolves: #1176036 IDM client registration failure in a high load environment - Resolves: #1183116 Remove Requires: subscription-manager - Resolves: #1186054 permission-add does not prompt to enter --right option in interactive mode - Resolves: #1187524 Replication agreement with replica not disabled when ipa-restore done without IPA installed - Resolves: #1188195 Fax number not displayed for user-show when kinit'ed as normal user. - Resolves: #1189034 "an internal error has occurred" during ipa host-del --updatedns - Resolves: #1193554 ipa-client-automount: failing with error LDAP server returned UNWILLING_TO_PERFORM. This likely means that minssf is enabled. - Resolves: #1193759 IPA extdom plugin fails when encountering large groups - Resolves: #1194312 [ipa-python] ipalib.errors.LDAPError: failed to decode certificate: (SEC_ERROR_INVALID_ARGS) security library: invalid arguments. - Resolves: #1194633 Default trust view can be deleted in lower case - Resolves: #1196455 ipa-server-install step [8/27]: starting certificate server instance - confusing CA staus message on TLS error - Resolves: #1198263 Limit deadlocks between DS plugin DNA and slapi-nis - Resolves: #1199527 [RFE] Use datepicker component for datetime fields - Resolves: #1200867 [RFE] Make OTP validation window configurable - Resolves: #1200883 [RFE] Switch apache to use mod_auth_gssapi - Resolves: #1202998 CVE-2015-1827 ipa: memory corruption when using get_user_grouplist() [rhel-7.2] - Resolves: #1204637 slow group operations - Resolves: #1204642 migrate-ds: slow add o users to default group - Resolves: #1208461 IPA CA master server update stuck on checking getStatus via https - Resolves: #1211602 Hide ipa-server-install KDC master password option (-P) - Resolves: #1211708 ipa-client-install gets stuck during NTP sync - Resolves: #1215197 ipa-client-install ignores --ntp-server option during time sync - Resolves: #1215200 ipa-client-install configures IPA server as NTP source even if IPA server has not ntpd configured - Resolves: #1217009 OTP sync in UI does not work for TOTP tokens - Related: #1204809 Rebase ipa to 4.2 - Update to upstream 4.2.0.alpha1- [ipa-python] ipalib.errors.LDAPError: failed to decode certificate: (SEC_ERROR_INVALID_ARGS) security library: invalid arguments. (#1194312)- IPA extdom plugin fails when encountering large groups (#1193759) - CVE-2015-0283 ipa: slapi-nis: infinite loop in getgrnam_r() and getgrgid_r() (#1202998)- "an internal error has occurred" during ipa host-del --updatedns (#1198431) - Renamed patch 1013 to 0114, as it was merged upstream - Fax number not displayed for user-show when kinit'ed as normal user. (#1198430) - Replication agreement with replica not disabled when ipa-restore done without IPA installed (#1199060) - Limit deadlocks between DS plugin DNA and slapi-nis (#1199128)- Fix ipa-pwd-extop global configuration caching (#1187342) - group-detach does not add correct objectclasses (#1187540)- Wrong directories created on full restore (#1186398) - ipa-restore crashes if replica is unreachable (#1186396) - idoverrideuser-add option --sshpubkey does not work (#1185410)- PassSync does not sync passwords due to missing ACIs (#1181093) - ipa-replica-manage list does not list synced domain (#1181010) - Do not assume certmonger is running in httpinstance (#1181767) - ipa-replica-manage disconnect fails without password (#1183279) - Put LDIF files to their original location in ipa-restore (#1175277) - DUA profile not available anonymously (#1184149) - IPA replica missing data after master upgraded (#1176995)- Re-add accidentally removed patches for #1170695 and #1164896- IPA Replicate creation fails with error "Update failed! Status: [10 Total update abortedLDAP error: Referral]" (#1166265) - running ipa-server-install --setup-dns results in a crash (#1072502) - DNS zones are not migrated into forward zones if 4.0+ replica is added (#1175384) - gid is overridden by uid in default trust view (#1168904) - When migrating warn user if compat is enabled (#1177133) - Clean up debug log for trust-add (#1168376) - No error message thrown on restore(full kind) on replica from full backup taken on master (#1175287) - ipa-restore proceed even IPA not configured (#1175326) - Data replication not working as expected after data restore from full backup (#1175277) - IPA externally signed CA cert expiration warning missing from log (#1178128) - ipa-upgradeconfig fails in CA-less installs (#1181767) - IPA certs fail to autorenew simultaneouly (#1173207) - More validation required on ipa-restore's options (#1176034)- Expand the token auth/sync windows (#919228) - Access is not rejected for disabled domain (#1172598) - krb5kdc crash in ldap_pvt_search (#1170695) - RHEL7.1 IPA server httpd avc denials after upgrade (#1164896)- RHEL7.1 ipa-cacert-manage renewed certificate from MS ADCS not compatible (#1169591) - CLI doesn't show SSHFP records with SHA256 added via nsupdate (regression) (#1172578)- Throw zonemgr error message before installation proceeds (#1163849) - Winsync: Setup is broken due to incorrect import of certificate (#1169867) - Enable last token deletion when password auth type is configured (#919228) - ipa-otp-lasttoken loads all user's tokens on every mod/del (#1166641) - add --hosts and --hostgroup options to allow/retrieve keytab methods (#1007367) - Extend host-show to add the view attribute in set of default attributes (#1168916) - Prefer TCP connections to UDP in krb5 clients (#919228) - [WebUI] Not able to unprovisioning service in IPA 4.1 (#1168214) - webui: increase notification duration (#1171089) - RHEL7.1 ipa automatic CA cert renewal stuck in submitting state (#1166931) - RHEL7.1 ipa-cacert-manage cannot change external to self-signed ca cert (#1170003) - Improve validation of --instance and --backend options in ipa-restore (#951581) - RHEL7.1 ipa replica unable to replicate to rhel6 master (#1167964) - Disable TLS 1.2 in nss.conf until mod_nss supports it (#1156466)- Use NSS protocol range API to set available TLS protocols (#1156466)- schema update on RHEL-6.6 using latest copy-schema-to-ca.py from RHEL-7.1 build fails (#1167196) - Investigate & fix Coverity defects in IPA DS/KDC plugins (#1160756) - "ipa trust-add ... " cmd says : (Trust status: Established and verified) while in the logs we see "WERR_ACCESS_DENIED" during verification step. (#1144121) - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server (#1156466) - Add support/hooks for a one-time password system like SecureID in IPA (#919228) - Tracebacks with latest build for --zonemgr cli option (#1167270) - ID Views: Support migration from the sync solution to the trust solution (#891984)- Improve otptoken help messages (#919228) - Ensure users exist when assigning tokens to them (#919228) - Enable QR code display by default in otptoken-add (#919228) - Show warning instead of error if CA did not start (#1158410) - CVE-2014-7850 freeipa: XSS flaw can be used to escalate privileges (#1165774) - Traceback when adding zone with long name (#1164859) - Backup & Restore mechanism (#951581) - ignoring user attributes in migrate-ds does not work if uppercase characters are returned by ldap (#1159816) - Allow ipa-getkeytab to optionally fetch existing keys (#1007367) - Failure when installing on dual stacked system with external ca (#1128380) - ipa-server should keep backup of CS.cfg (#1059135) - Tracebacks with latest build for --zonemgr cli option (#1167270) - webui: use domain name instead of domain SID in idrange adder dialog (#891984) - webui: normalize idview tab labels (#891984)- ipa-csreplica-manage connect fails (#1157735) - error message which is not understandable when IDNA2003 characters are present in --zonemgr (#1163849) - Fix warning message should not contain CLI commands (#1114013) - Renewing the CA signing certificate does not extend its validity period end (#1163498) - RHEL7.1 ipa-server-install --uninstall Could not set SELinux booleans for httpd (#1159330)- Fix: DNS installer adds invalid zonemgr email (#1056202) - ipaplatform: Use the dirsrv service, not target (#951581) - Fix: DNS policy upgrade raises asertion error (#1161128) - Fix upgrade referint plugin (#1161128) - Upgrade: fix trusts objectclass violationi (#1161128) - group-add doesn't accept gid parameter (#1149124)- Update slapi-nis dependency to pull 0.54-2 (#891984) - ipa-restore: Don't crash if AD trust is not installed (#951581) - Prohibit setting --rid-base for ranges of ipa-trust-ad-posix type (#1138791) - Trust setting not restored for CA cert with ipa-restore command (#1159011) - ipa-server-install fails when restarting named (#1162340)- Update Requires on pki-ca to 10.1.2-4 (#1129558) - build: increase java stack size for all arches - Add ipaSshPubkey and gidNumber to the ACI to read ID user overrides (#891984) - Fix dns zonemgr validation regression (#1056202) - Handle profile changes in dogtag-ipa-ca-renew-agent (#886645) - Do not wait for new CA certificate to appear in LDAP in ipa-certupdate (#886645) - Add bind-dyndb-ldap working dir to IPA specfile - Fail if certmonger can't see new CA certificate in LDAP in ipa-cacert-manage (#886645) - Investigate & fix Coverity defects in IPA DS/KDC plugins (#1160756) - Deadlock in schema compat plugin (#1161131) - ipactl stop should stop dirsrv last (#1161129) - Upgrade 3.3.5 to 4.1 failed (#1161128) - CVE-2014-7828 freeipa: password not required when OTP in use (#1160877)- Do not check if port 8443 is available in step 2 of external CA install (#1129481)- Update Requires on selinux-policy to 3.13.1-4- Update to upstream 4.1.0 (#1109726)- Update to upstream 4.1.0 Alpha 1 (#1109726)- Add redhat-access-plugin-ipa dependency- Re-enable otptoken_yubikey plugin- Update to upstream 4.0.3 (#1109726)- Server installation fails using external signed certificates with "IndexError: list index out of range" (#1111320) - Add rhino to BuildRequires to fix Web UI build error- ipa-client-automount fails with incompatibility error when installed against older IPA server (#1083108)- Proxy PKI URI /ca/ee/ca/profileSubmit to enable replication with future PKI versions (#1080865)- When IdM server trusts multiple AD forests, IPA client returns invalid group membership info (#1079498)- Deletion of active subdomain range should not be allowed (#1075615)- PKI database is ugraded during replica installation (#1075118)- Unable to add trust successfully with --trust-secret (#1075704)- ipa-replica-install never checks for 7389 port (#1075165) - Non-terminated string may be passed to LDAP search (#1075091) - ipa-sam may fail to translate group SID into GID (#1073829) - Excessive LDAP calls by ipa-sam during Samba FS operations (#1075132)- Do not fetch a principal two times, remove potential memory leak (#1070924)- trustdomain-find with pkey-only fails (#1068611) - Invalid credential cache in trust-add (#1069182) - ipa-replica-install prints unexpected error (#1069722) - Too big font in input fields in details facet in Firefox (#1069720) - trust-add for POSIX AD does not fetch trustdomains (#1070925) - Misleading trust-add error message in some cases (#1070926) - Access is not rejected for disabled domain (#1070924)- Remove ipa-backup and ipa-restore functionality from RHEL (#1003933)- Display server name in ipa command's verbose mode (#1061703) - Remove sourcehostcategory from default HBAC rule (#1061187) - dnszone-add cannot add classless PTR zones (#1058688) - Move ipa-otpd socket directory to /var/run/krb5kdc (#1063850)- Lockout plugin crashed during ipa-server-install (#912725)- Fallback to global policy in ipa lockout plugin (#912725) - Migration does not add users to default group (#903232)- Mass rebuild 2014-01-24- Fix NetBIOS name generation in CLDAP plugin (#1030517)- Do not add krbPwdPolicyReference for new accounts, hardcode it (#1045218) - Increase default timeout for IPA services (#1033273) - Error while running trustdomain-find (#1054376) - group-show lists SID instead of name for external groups (#1054391) - Fix IPA server NetBIOS name in samba configuration (#1030517) - dnsrecord-mod produces missing API version warning (#1054869) - Hide trust-resolve command as internal (#1052860) - Add Trust domain Web UI (#1054870) - ipasam cannot delete multiple child trusted domains (#1056120)- Missing objectclasses when empty password passed to host-add (#1052979) - sudoOrder missing in sudoers (#1052983) - Missing examples in sudorule help (#1049464) - Client automount does not uninstall when fstore is empty (#910899) - Error not clear for invalid realm given to trust-fetch-domains (#1052981) - trust-fetch-domains does not add idrange for subdomains found (#1049926) - Add option to show if an AD subdomain is enabled/disabled (#1052973) - ipa-adtrust-install still failed with long NetBIOS names (#1030517) - Error not clear for invalid relam given to trustdomain-find (#1049455) - renewed client cert not recognized during IPA CA renewal (#1033273)- hbactest does not work for external users (#848531)- PKI service restart after CA renewal failed (#1040018)- Move ipa-tests package to separate srpm (#1032668)- Fix status trust-add command status message (#910453) - NetBIOS was not trimmed at 15 characters (#1030517) - Harden CA subsystem certificate renewal on CA clones (#1040018)- Mass rebuild 2013-12-27- Remove "Listen 443 http" hack from deployed nss.conf (#1029046) - Re-adding existing trust fails (#1033216) - IPA uninstall exits with a samba error (#1033075) - Added RELRO hardening on /usr/libexec/ipa-otpd (#1026260) - Fixed ownership of /usr/share/ipa/ui/js (#1026260) - ipa-tests: support external names for hosts (#1032668) - ipa-client-install fail due fail to obtain host TGT (#1029354)- Trust add tries to add same value of --base-id for sub domain, causing an error (#1033068) - Improved error reporting for adding trust case (#1029856)- Winsync agreement cannot be created (#1023085)- Installer did not detect different server and IPA domain (#1026845) - Allow kernel keyring CCACHE when supported (#1026861)- ipa-server-install crashes when AD subpackage is not installed (#1026434)- Update to upstream 3.3.3 (#991064)- Temporarily move ipa-backup and ipa-restore functionality back to make them available in public Beta (#1003933)- Server install failure during client enrollment shouldn't roll back (#1023086) - nsds5ReplicaStripAttrs are not set on agreements (#1023085) - ipa-server conflicts with mod_ssl (#1018172)- Reinstalling ipa server hangs when configuring certificate server (#1018804)- Deprecate --serial-autoincrement option (#1016645) - CA installation always failed on replica (#1005446) - Re-initializing a winsync connection exited with error (#994980)- Update to upstream 3.3.2 (#991064) - Add delegation info to MS-PAC (#915799) - Warn about incompatibility with AD when IPA realm and domain differs (#1009044) - Allow PKCS#12 files with empty password in install tools (#1002639) - Privilege "SELinux User Map Administrators" did not list permissions (#997085) - SSH key upload broken when client joins an older server (#1009024)- Remove dependency on python-paramiko (#1002884) - Broken redirection when deleting last entry of DNS resource record (#1006360)- Remove ipa-backup and ipa-restore functionality from RHEL (#1003933)- Replica installation fails for RHEL 6.4 master (#1004680) - Server uninstallation crashes if DS is not available (#998069)- Unable to remove replica by ipa-replica-manage (#1001662) - Before uninstalling a server, warn about active replicas (#998069)- Update to upstream 3.3.1 (#991064) - Update minimum version of bind-dyndb-ldap to 3.5- Fix replica installation failing on certificate subject (#983075)- Allow ipa-tests to work with older version (1.7.7) of python-paramiko- Prevent multilib failures in *.pyo and *.pyc files- ipa-server-install fails if --subject parameter is other than default realm (#983075) - do not allow configuring bind-dyndb-ldap without persistent search (#967876)- diffstat was missing as a build dependency causing multilib problems- Remove ipa-server-selinux obsoletes as upgrades from version prior to 3.3.0 are not allowed - Wrap server-trust-ad subpackage description better - Add (noreplace) flag for %{_sysconfdir}/tmpfiles.d/ipa.conf - Change permissions on default_encoding_utf8.so to fix ipa-python Provides- Update to upstream 3.3.0 (#991064)- Require slapi-nis 0.47.7 delivering a core feature of 3.3.0 release- Update to upstream 3.3.0 Beta 2 (#991064)- Update to upstream 3.2.2 - Drop ipa-server-selinux subpackage - Drop redundant directory /var/cache/ipa/sessions - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost - Run ipa-upgradeconfig and server restart in posttrans to avoid inconsistency issues when there are still old parts of software (like entitlements plugin)- Update to upstream 3.2.1 - Drop dogtag-pki-server-theme requires, it won't be build for RHEL-7.0- Add OTP patches - Add patch to set KRB5CCNAME for 389-ds-base- Update to upstream 3.2.0 GA - ipa-client-install fails if /etc/ipa does not exist (#961483) - Certificate status is not visible in Service and Host page (#956718) - ipa-client-install removes needed options from ldap.conf (#953991) - Handle socket.gethostbyaddr() exceptions when verifying hostnames (#953957) - Add triggerin scriptlet to support OpenSSH 6.2 (#953617) - Require nss 3.14.3-12.0 to address certutil certificate import errors (#953485) - Require pki-ca 10.0.2-3 to pull in fix for sslget and mixed IPv4/6 environments. (#953464) - ipa-client-install removes 'sss' from /etc/nsswitch.conf (#953453) - ipa-server-install --uninstall doesn't stop dirsrv instances (#953432) - Add requires for openldap-2.4.35-4 to pickup fixed SASL_NOCANON behavior for socket based connections (#960222) - Require libsss_nss_idmap-python - Add Conflicts on nss-pam-ldapd < 0.8.4. The mapping from uniqueMember to member is now done automatically and having it in the config file raises an error. - Add backup and restore tools, directory. - require at least systemd 38 which provides the journal (we no longer need to require syslog.target) - Update Requires on policycoreutils to 2.1.14-37 - Update Requires on selinux-policy to 3.12.1-42 - Update Requires on 389-ds-base to 1.3.1.0 - Remove a Requires for java-atk-wrapper- Remove release from krb5-server in strict sub-package to allow for rebuilds.- Add a Requires for java-atk-wrapper until we can determine which package should be pulling it in, dogtag or tomcat.- Update to upstream 3.2.0 Beta 1- Update to upstream 3.2.0 Prerelease 1 - Use upstream reference spec file as a base for Fedora spec file- Rebuild for broken deps - Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1- Rebuild for broken deps in rawhide - Fix 389-ds-base strict dep to be 1.3.0.3- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- Update to upstream 3.1.2 - CVE-2012-4546: Incorrect CRLs publishing - CVE-2012-5484: MITM Attack during Join process - CVE-2013-0199: Cross-Realm Trust key leak - Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1- Remove redundat Requires versions that are already in Fedora 17 - Replace python-crypto Requires with m2crypto - Add missing Requires(post) for client and server-trust-ad subpackages - Restart httpd service when server-trust-ad subpackage is installed - Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes- Updated to upstream 3.1.0 GA - Set minimum for sssd to 1.9.2 - Set minimum for pki-ca to 10.0.0-1 - Set minimum for 389-ds-base to 1.3.0 - Set minimum for selinux-policy to 3.11.1-60 - Remove unneeded dogtag package requires- Update Requires on krb5-server to 1.11- Configure CA replication to use TLS instead of SSL- Updated to upstream 3.0.0 GA - Set minimum for samba to 4.0.0-153. - Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured - Restrict krb5-server to 1.10. - Update BR for 389-ds-base to 1.3.0 - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca - Add Requires on zip for generating FF browser extension- Updated to upstream 3.0.0 rc 2 - Include new FF configuration extension - Set minimum Requires of selinux-policy to 3.11.1-33 - Set minimum Requires dogtag to 10.0.0-0.43.b1 - Add new optional strict sub-package to allow users to limit other package upgrades.- Require samba packages instead of obsoleted samba4 packages- Updated to upstream 3.0.0 rc 1 - Update BR for 389-ds-base to 1.2.11.14 - Update BR for krb5 to 1.10 - Update BR for samba4-devel to 4.0.0-139 (rc1) - Add BR for python-polib - Update BR and Requires on sssd to 1.9.0 - Update Requires on policycoreutils to 2.1.12-5 - Update Requires on 389-ds-base to 1.2.11.14 - Update Requires on selinux-policy to 3.11.1-21 - Update Requires on dogtag to 10.0.0-0.33.a1 - Update Requires on certmonger to 0.60 - Update Requires on tomcat to 7.0.29 - Update minimum version of bind to 9.9.1-10.P3 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1 - Remove Requires on authconfig from python sub-package- Rebuild against samba4 beta8- Rebuild against samba4 beta7- Adopt to samba4 beta6 (libsecurity -> libsamba-security) - Add dependency to samba4-winbind- Updated to upstream 3.0.0 beta 2- Updated to current upstream state of 3.0.0 beta 2 development- Rebuild against samba4 beta4- Updated to upstream 3.0.0 beta 1- Updated to upstream 2.2.0 GA - Update minimum n-v-r of certmonger to 0.53 - Update minimum n-v-r of slapi-nis to 0.40 - Add Requires in client to oddjob-mkhomedir and python-krbV - Update minimum selinux-policy to 3.10.0-110- Update to upstream 2.2.0 beta 1 (2.1.90.rc1) - Set minimum n-v-r for pki-ca and pki-silent to 9.0.18. - Add Conflicts on mod_ssl - Update minimum n-v-r of 389-ds-base to 1.2.10.4 - Update minimum n-v-r of sssd to 1.8.0 - Update minimum n-v-r of slapi-nis to 0.38 - Update minimum n-v-r of pki-* to 9.0.18 - Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1 - Update conflicts on bind to < 9.9.0-1 - Drop requires on krb5-server-ldap - Add patch to remove escaping arguments to pkisilent- Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)- Force to use 389-ds 1.2.10-0.8.a7 or above - Improve upgrade script to handle systemd 389-ds change - Fix freeipa to work with python-ldap 2.4.6- Fix ipa-replica-install crashes - Fix ipa-server-install and ipa-dns-install logging - Set minimum version of pki-ca to 9.0.17 to fix sslget problem caused by FEDORA-2011-17400 update (#771357)- Allow Web-based migration to work with tightened SE Linux policy (#769440) - Rebuild slapi plugins against re-enterant version of libldap- Allow longer dirsrv startup with systemd: - IPAdmin class will wait until dirsrv instance is available up to 10 seconds - Helps with restarts during upgrade for ipa-ldap-updater - Fix pylint warnings from F16 and Rawhide- Update to upstream 2.1.4 (CVE-2011-3636)- Update SELinux policy to allow ipa_kpasswd to connect ldap and read /dev/urandom. (#759679)- Fix wrong path in packaging freeipa-systemd-upgrade- Introduce upgrade script to recover existing configuration after systemd migration as user has no means to recover FreeIPA from systemd migration - Upgrade script: - recovers symlinks in Dogtag instance install - recovers systemd configuration for FreeIPA's directory server instances - recovers freeipa.service - migrates directory server and KDC configs to use proper keytabs for systemd services- Rebuilt for glibc bug#747377- clean up spec - Depend on sssd >= 1.6.2 for better user experience- Fix Fedora package changelog after merging systemd changes- Fix postin scriplet for F-15/F-16- 2.1.3- Default to systemd for Fedora 16 and onwards- Update to upstream 2.1.0- Fix bug #702633- Update minimum selinux-policy to 3.9.16-18 - Update minimum pki-ca and pki-selinux to 9.0.7 - Update minimum 389-ds-base to 1.2.8.0-1 - Update to upstream 2.0.1- Update to upstream GA release - Automatically apply updates when the package is upgraded- Update to upstream freeipa-2.0.0.rc2 - Set minimum version of python-nss to 0.11 to make sure IPv6 support is in - Set minimum version of sssd to 1.5.1 - Patch to include SuiteSpotGroup when setting up 389-ds instances - Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled- Set the N-V-R so rc1 is an update to beta2.- Set minimum version of sssd to 1.5.1 - Update to upstream freeipa-2.0.0.rc1 - Move server-only binaries from admintools subpackage to server- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Set min version of 389-ds-base to 1.2.8 - Set min version of mod_nss 1.0.8-10 - Set min version of selinux-policy to 3.9.7-27 - Add dogtag themes to Requires - Update to upstream freeipa-2.0.0.pre2- Remove unnecessary moving of v1 CA serial number file in post script - Add Obsoletes for server-selinxu subpackage - Using git snapshot 442d6ad30ce1156914e6245aa7502499e50ec0da- Prepare spec file for release - Using git snapshot 80e87e75bd6ab56e3e20c49ece55bd4d52f1a503- Re-arrange doc and defattr to clean up rpmlint warnings - Remove conditionals on older releases - Move some man pages into admintools subpackage - Remove some explicit Requires in client that aren't needed - Consistent use of buildroot vs RPM_BUILD_ROOT- Moved directory install/static to install/ui- Remove dependency on nss_ldap/nss-pam-ldapd - The official client is sssd and that's what we use by default.- Remove radius subpackages- Set minimum pki-ca and pki-silent versions to 9.0.0- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm versionfreeipa-common bncacsdeeseufrhihuidjaknmrnlplptrusktgukzh4.5.44.5.4-10.sl7_5.34.5.4 ipa-common-4.5.4Contributors.txtREADME.mdipa-common-4.5.4COPYINGipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.moipa.mo/usr/share/doc//usr/share/doc/ipa-common-4.5.4//usr/share/licenses//usr/share/licenses/ipa-common-4.5.4//usr/share/locale/bn_IN/LC_MESSAGES//usr/share/locale/ca/LC_MESSAGES//usr/share/locale/cs/LC_MESSAGES//usr/share/locale/de/LC_MESSAGES//usr/share/locale/es/LC_MESSAGES//usr/share/locale/eu/LC_MESSAGES//usr/share/locale/fr/LC_MESSAGES//usr/share/locale/hi/LC_MESSAGES//usr/share/locale/hu/LC_MESSAGES//usr/share/locale/id/LC_MESSAGES//usr/share/locale/ja/LC_MESSAGES//usr/share/locale/kn/LC_MESSAGES//usr/share/locale/mr/LC_MESSAGES//usr/share/locale/nl/LC_MESSAGES//usr/share/locale/pl/LC_MESSAGES//usr/share/locale/pt_BR/LC_MESSAGES//usr/share/locale/ru/LC_MESSAGES//usr/share/locale/sk/LC_MESSAGES//usr/share/locale/tg/LC_MESSAGES//usr/share/locale/uk/LC_MESSAGES//usr/share/locale/zh_CN/LC_MESSAGES/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnudirectoryUTF-8 Unicode textASCII text? 7zXZ !XF] crt:bLL'p'8G$&-Ph e}||ϚD"%^>,67 ļ3T+_H8 )RI[|"KxY=1 aM=C$;A+O)G$p^C<̉1EhmKF,$s#'&Yglw}$ U6=2I';yn} =%c/J$+%IWn]qo^ m% cLu]ᤊ{4j^uŊ@D+I_Hdz@_-wC~6pRʊ[kzehq2]@j*p%H>:*0$6hǒ~ӒY@4P@J'G˖#Lp^g;xһTiﴺ N kYl,m>OtHc *X_{X)<]g_y@ߕ1k =I@T e w>gk=з BXndQ6WwĔJGOc6cݵT׵gրDJFڹYYؓ4^v 4dE J8Lke ԣS}u顩#2Pabٿxں #KE\/:v%>$kd=0O;-`67$B 83x gnyyQ`2&݌GJvo?x Y3vמG}G6wWQ-tUcjcfArŞ1HHٰv*P;dQL/셞lMf4_wwu| }!7"O k[GOch'ӽm~_͑_iaF 5$ ?My!] m*&xP^lК__cդ9#j :cC=>:L$NGi(essRDfKeQKA͓DlWF\y'r aNz՗NO>M@F1 ZWܽ`*0I!AKj4# /H= h)1 B X>TS3fѐfb:L;;$,UAUDV ւ$^v3$57)fŢkne; zbQ+ Lsc_S xo2:#GZQO#]4۾`^*%:놁+H] s?ZS[0qVwZ#ʠR^fKӳ3~c^p+,Nk"Zi'}%Ul Wfk4'QPE. 2 PWαJIh̰ -nYRcF;(ۻ/N)imˤͺL[K,r)f>ߏK ^\0{F&{P/Iw([T@U|nU;QpXᖪ=.Ax0wLoMՋ7B*i>v8"ܵo-pFx7&~Bg(pYrR;_7QdVAMX9%\IjBS M&#,9G mUQ\NDW@twA "re52\/L:ZVƞj@+Ynb 7p %?_vYh4*\BȌIavG-.! F]Olj{nYczD5آyMwԒBQf/BE N`=2X s{=tBpYmfB[!q2 Uu 1CcPivSĠ!Enu\d)Eڦ.MTĺO\\֬4y A'몒>ɣ{ސ.,9y ck>a~n3b_%yBr 0ߩo-#?4&w*Vr;f#wG_1ӠV.T^ J@M3K 'H8Yz{,i}+mUGndo r0 $I. ʨ:'./wCh6y$Sj=ґ^y=ޕ;$,L ւhtXr7ЌYX_`9[R_ O6 By0WamŨX资7«iLcK>_RS5Zg ALlmAvɯ=Wmm(2(uMknךBDA}d^'C{ܡ["6kWK3|q|bHAN/9 MIK<É*} [RdC;y|@\LyQcpm!"d#At̘De=Xi-EከyX$D>-M?/CNo9wsƊW^e+7WE @.hL>,;[7Xe\G7QiGhB"fћ1v 2ȵfB}bZ.=R<ͨ:;q>Ɖ4zp/zA͙/}~|v/8U Ad/m;ЮԠm^#QNW׳[k[ Bz:<%ZY;Ie.(pwyZޅ77$jY9<rоV²6+NwQA!eLM9+zvT ݏ&9WN|LgV5]%9)d ˟;2֜h|J@p GW:'"T)nO2`T["wkPŔ zW{OW^]I"U; :Z <,ߧҒg|S{}I iyc$鰤'-uNdR hw?l1/g8C~r7꫑t}K+osABEMut{l'~l0`˷Պ0kF0K_Ğa@2H|%@ifցٯsd¿|=6|@Oەec%UuYiδAGFx/&w%:~J'9:52oU Fp3{Ւ_+\5׫IFћqJl6Qrg'Ӓ"`|St_u,FPeb[BЀމp"H8:n|?ۙce-M F&:}鈳].2]v5$ЩZT d2%lȩmh"$O!`ry^v9e@ec`*S-fOIf7~-&g g]F)f`4-gE 4C 3W}l'`?.(VHhoӣm;C+#h wz}_]r3^'Lj肤4nTRchWf;h{9C 6k4`EdݽWFf 4N= NlD)3/yLo9=/⣰hg b=M[ 4cMK-ES>7CrYBhw\=M eJbV铽R`OaHmˎ/d!B2b򇑫fMU?A9̘r<ة~6(E. A eQR "IoO[!_ZA2Y;TJ(-YL)JYA˲R} 7_dK>mK]"ϼ!jS̃Լ;T.KQmxoV|zT,Wp (D*|eoB^v_ eȤPY@c]IuNed nsL|w{!W_i=~Y ^}&2/%J1q8\5m$TffMgDn[2P AceDŽXy }@ڼ$ @2mSyu"yK܅Jg*)ajnxvMMbNWЎG< %9aI>(;ټ9B:gկJ{9⫶Yk!R$UVQgOp` `r(̏o[A|-@tܬdN%7 nj\u6$'ޡ({xߤA]"5$'vG &;9"{gh)!-ѳ#b4cԪmlz㏃P fFN`;YVhC0NVqU]bSǯB4r/cpr} B{({OfeG hV L!ԎN X 8{7X:|F2qє6c-fW _xs;~+? }%ݗ+oGsoiY1~yhiS7RUӆ|vbW)ynh[&pYhMm$l-^:ta$-yk _ Vk<݇TQzK8ZcH7)P3cهӁZjvb9> _fچ%MSom/xڥv57DpAx=D&r8I3v~mD7$̂πlKRd&NL@i#أYxE$6aNk"/-[cMvO2C+q-aDWúNFy;[V»*q}]0rcn,7:#ܑ1廙QXyD6@&f~[Ɖ"n . 'гۦb-á愔s'Vr_*RFM=Th^K@|hlzQ9+!)BbK,aW"GJ򋵳{Lieyysj%-̛ TBO ;`Pl[B>#WͦwR[yR/v\VGKV4zT@:b9۬)l<5;w!V~_;I籀K3bMڦ_L؋adVfWd|l/}Zɹl4XQQn;AXbcUnƤ[¡Eja8ɻ(u:7Bm9>?bo`G%WBs P mUµh@;)a?֊$yb:RԣFnU|AÏb2$j'E+*.pDRpGzXvQHihUxQL xGր@FmZ$e E '',:R3'[DRlLΣM#[| {/AjZ@`.9<8.=#M")n{M͈2^y}8+D=5A lm7mWsj|ޓGq!<rѐ"wCr-9 k-1 au3-$ן{dkrb[4&rY߷CP٫Y&Ʀ 6˃ZEg\UWTcH~5`)0iHsXV=rJ790L;zbuʼ*ۉwE%O6TȬ7^'8~ؓ(nh6sz T"Wx}eVXs[> –C5OOjgX $6XKpg4mg ws5+1AKzAK9!TW򑷺+x3G4D8%VaY n$$HM? kErKxI# ۪q v ) "Hd"f"  HV4+ L9?NvdW>WjM#dbOǦ!QwD]hMs P,K~7q,ہ? c"pd?q[dazRJ:jY413oBTmj:|L>h \ -|nQu ,angnb6B9{ؙm'E>Q{fo"mkQ`)#z (r3/gZE|Zgj0̑1UHzbY$|[Zao9!D8∏)b3 ~VhyA.y[9%RMۢ1Bdڂ-[GeAjѷPmONmEKwK6`ss5JU29_1>&s5EV;n,]lu9?I3!~kloE͝S{]2OoI\m>Z̞ )F4nyO3Fh@E:Yj9'*V @Ҍݴ@HvW iإJ@{o[SmQw%4!1v/]@$ tKk@c^ 䒮~RxtynFQ-_*VA>M*hxسKExB$w{ g;I7r0M [yY~hf6Q\ ,,zk\ci*OOlS2ȥ<VN? QM4iCVb1ah_7GS ؈4QI%|&ֽWɺ_(PI냢~hŽPLg:m[[%W}[u寑pR_QWY1J! L(n>bOAڭ9T7mdl!IbU~@xoGڕyLM~B{}?ݠ;؋QW ؟P-pm?U-;R9kz4IfOM ,7/q_ ArX"57 sk %? !=Zj" mC{zmCaHU.$JY2bpPœ cNF_;hxD"7 Ƃ/_Y䦡 2qJtty]{d1qhS)CUPQUfp[GzB·̥X6yW`/]IQ#\FDioi3BpXΒv1;!<WROE#չǣ_H4\ œ8> N oNQQwͯ]" XG1Y"u'-x8!P.=z>Cqe3ֹo]bu $/f.2UE^SrZLv:L(a2wvK"&;J ue&LR}!2jɉ /PcnTT4c6\ QnNCRQq";R03^{}8Kd E̡@5$+ٟX\} :xwp9g {G~a>|$_eʐE(%+Ui!Ӯ.P/grr[ߺ8RBSZEYQ[/Z8PCZ?y,\pf *^9tGb.hԫR/rGٽv? gT ;1D? 5qLfioYg:FqCE2kPKnbdJ i ]'hpF9vڗO# ܧhb l2 >Q d$Ieockl͍oD8@r {{g4)Kp"OC`Uͫ$I|ze:J]4G: k2](298|/$h㦨R%ʾN 8Z$"2r)]Kjf`.CY('u~G4_2 R*ygs3%d~<8X M{ Oj7TBl% m^$UҰΝ q>|$M] fLO4q {u\{4q xSs"^k1Öog<.n|ͤ?:J{|\>lq~mdbN4FmL&}D}"jD#u{*oցއ d s: ; ލ[E}R6.TgYvI'!Ô»ڳsFT̓u+KlO@żMN@io\KYp {ŮB8,pC$NMѳ&?]>Bs!Y!gmIP~Y 9,&$_y!eUKuʅ_1|p`s7~b71dmXx.]j̭(w*%=KKcW@ɻ)Q߿'dލ.IO{cXT1O*݆|`rwl4;Ge)e|Dqv5̦G% n>>gg :!RD%.O"{NE@bj"TS}4f7 aR)tZP F8]\9 F믝)q,!g@mP WK\BUa1QfxՅxsVZȶN%ӌ 83!B6v}AB`IDK|;>\i@_\<,B+b/f?=~Ӈ($^9m|vF0^lBAj0K1ׂi0d*m qvxWh7w3[ک'#1HCDPLGZwBE.|WO&d%#d63{J+88%%hJFo'hw^OjL+plAQz]Qiqp |)j.,& ڬJ >'gri&Vlntj?n!#\6*93Բ/sCHwT BϠ+} qƸ&ORk8m|w% y%7to(ߔ@|̖=vx:&5-/<MPradssg;G-p.Ž,[bm$R2Lzb;Z֑W]W?#W橦Eu.!4E+qVtw$Hzધ\j>YFUy^a&QqFvZ@?3CvMOB/(r!uKDJeૹAd9-<6 b2<ϸNQqYroBBM/|Ĵ0RZfAr?&iGb+c <gU̽}ᩮUxFT8.KQnC۩FKg+AWf0rW1qƬtc&)kHMtӕ84 k#ȚYLʑLZWRdFDcͦ9mѭzEz\ K^i7}I U<$.[ypMU{PIj^T=]!.}وʯ5 HL$pcO0-{@"Z5V TX'h+4m1os4i4mܔֺqm(pͿ\ERz_su\Y (ku~ UX R]jl'd0ߐ7BUT?ؿ鄪/8¢ec]b Tl[TtZAx.g6ӆ;+@Wb6w$)~|1٠J 6f@rLV<*햹:o"Ab7N߱Z/0we.q}=R`LwКRVm%8w ܆E̮ \-Rm[kZãp-ϯM&g m$wdaoZJu}ƑI-vC0`LNps2OauQ CΗnkY5r4@a=V=~JATkψЀESf 6_-Y#&6ϘLCJHe)ua(&)0AT{xk 㺽u,B!ywvҟ#,)3bҬG 캿Ty6ǖ_ r)s-~Jz) H^Y~uYz!>il|Z`Ā`QKܜN 7uDON=Þ#Wg-R wo ɹ -%.?1~wy?I'p܏D3xw P!g5DkzY)+ Px k[o`ك a\@< 'Ӂ[чB`RIb+uNn/Ө+['2( #69BT!՚ġPp^S M?yYLn@ϕ (ig0#;vEi, D%>x|`mkVq{-GN10hYJUxsXKwP|;|' i%opsSS eby d3w[Gcgtf8DY&VEfK^(:."`PRN]| 7JVh$ =aj_6ufZR.C.U H>͐+gGJ~_CO?{K˙ɭjc[Dl duL2rP&޻8_Q;k[Q"BY磝(;2bp 9KIݽ+/ ~i4r >5EFL:`0DBYϴpm_ 0n}%  ky#~)\?N ž&Mrnk@Gڀ"q_&+DŽP.IA2ژ1Mi7-ogEʯ6Qk[UQ;2"0M)eq܃۩OZ,+S<ױHch<0 L:gmȮIX#ku/(1{-ER>ȞH,5^Pc.3Vz*Un~Yqdīuٲ61E35hRXI"* է#Ŭg-O=" Z%mxEͲZ~hU/SEy8552If0v<kcgu|YK;%whir@C6^;6w/>z%̉0$< ՠΣWu#R"@",weBt7L{Z6.Ǯ8YI`M|<ܠ>,Qt4u6 G$7~Ӥ(+#<嫮}O=ێqKey8Zp,Wl[Áœ,9XIT5gK 5.ÕO*6]ǼkMP)%:åFw/ F;BVO!쭛ń8 ,=Ed057P41chjooO ?Aq\H0Cƹ hz =PF%>0L܄EΠz)&nF(^oQMcX<ڒڍ%2ms3&qo`[^']vd!d;jȾj$Ճ*b4 `}.oM~i$z0ӰSW[Ob{Lε o89=D؜h Cfq̬hp[cv<⚝kR/_yφIG ѾLXw1s>4kU% h6t}fKY3.`1h=%l :$Ƃ4O@u~&(QL̂!h6%:U9kk̩׽ =kQ2VLovtݶiZ:\t +MPc0AlطB nfuu&>Bh[Dӎ`Ab s٩yke(xm]zXÀ`oKJVlG_F ]_uɏSdYV$[By%ǁ4p=(3K5^AG=O Rxjj=a~^_uw&T\0^_n Pje`G2U>@k>)*)g&lAM6-kݖ`LT26Suϑ9/Ш%_ס 1+?:6ŪK%ۘI\PGX2ّ$DS=ZTO#v&l>DZSG⯔&+r\x`(kM"~xdMNV#&Y#HLLpl7GnFS! ]erڠ̲ 1<+XEXr_P\Q]1dPS vgG1\|:-wo s* u)79!"^g5_.V jڋy=?΋=E#c^nmYP}Sn?UsyGVX;);`D_@*i_;׸BYz i]ïFp&Obi[fc2:RB7Ǘd]?qw=Сl`A\hMc(V83ci>M@R ܢ}/ɱ8Ʒyew FxDlSBP_gCX6e)@-6S%S>ׄ,<]` ܫ#3rn ;M/4䒨Cb[bkuŎ>^ ῗVZ;UHbz{+i?H7 |uo:n-prRߢB*3^m$>7ZT1r9D|uI7ZVx C]$f1&^+XMm4lk/jR_!z_O!Яϩ %_o"_vbtܣ?O4K^0&xM9|U4!qoKّ>eis&}Bw7-\CÛЮKdlJ885R\p@C۲H+P(F )wLp3͍g^ ɜp:moݻVc8Qr a ^ge?Wwx%#I lS2Twה`/荮u]p7үnCݳ]]d+[?K_-.?eލ/%mGHgv`ΒK\<@iDD&9L(uǂEP_Ȟ[#"%|d>2D7CÉw"O?Δvrrz/HP$Oʗ}Q7aN_/v^|;ɺ(Qn/Hta1\HfL:@Y7t\$ByZ1+]YX`“kGUAX/zVޘ1J2J @_JR ig J6 =„9ĩ Z|qqA/>pt⨴QŒUԷ&q@D uM(oA =I&ќCM@4bSiR(ϥn^&6Z9 _wݎ>#dxxֱDzTHg.T'ַz,3zd4aX~PRjUTB25bʌYR>9 `y:}T?k{!T\U^VlVHE4 Q3 U~R Kjy-vqmZN2;@ivE2^UK| ^mnp`Uɞ̲iMzI!sUR&1 ;ߩ #Q_ރ;VO(:PmcWiοpݘpEVip@ƞJU^dfK*=|𢃍5E~wmD !aGuR^o/չtMF$ͰxDDH'SŒT־Pi6rc ᥘ!*i)2PcFq#>竉 * y? PX@&[Eg] T Sԙ{.մI:9_mt L nn^Gl*^ Aĝ!G&:Š65wuҕr+,3wl5\@0mxY+t8OF ^*#zL"Q-vW]QW"o9HBxCH-vģuvg* YD|o~&18-fd˰p]i~B%/n0/׻58FY`>k4x%)+%3R䫜صM!5HD;Ԉ2 WAl gj4}T NWIXH'{FB !#<'cty P:PdrC{YžL*бp| 9NK4 P,i9av*)z-}/sIRmqZ.ԣ{ۉ{,K=b@Ϻ؁ͱpnoVsO' $P -C仙Yyψ8?̚芵Y!0iNXȣV!)El,b>}0hЦ[NG~췸vmbx[ 7|ee!ݺᯚg,A<;+#_4;QЈgʧq oc;"A~EtD;->y!NN[#0+T׹ Pf0]?,n5{ ĜoEُRaq3*b5m+7 `$oC0։^J*BRt.kycFiK7=ޭPP>"dyR* ٵq2/7mV4a^-?)J $T_.Jw׼|ڣS!şwνj=)yDhCPOj8:'Ռ9:dr[e*U k߇u)39}ǚXxhMӿ4wǚZi5%dR/O0[BaPӈJmQE|;5txZt<09P zQn4Hîy;>_UBĽ%<+u1`a*E5VFj߼;EsheHw_2¬ ySf[ٴO 6"m .?1<%nv J]X߸RaR{|vCcAcq/U[/wXNGcLHtTӭS4}"m=ّxmX5:]K'0I[%w&o'o{KqgB3p9ǑK '@~Mlp O!lo۱@7΢m:qE8ц8hyy&$`&DD6{R^"f`z30~x4}ط߳b=xhεoS@EY2OŊ__9G+r(Q-j:^f)kx-|7g})ilhN3jh} 6dEO%`:bˢO\rYΘ,uN~R W!rhF H{Cڛk6ksjkSnBѢ">lFO#446aG .\@TήL:BA^B^q ryc@^%Q.A!f5HAl2ͻnZz(uQ\QHa/=o5{ m&^nǒz8ߘ!y{W-,(_ i5\2!>aA5j?E޷X;8Gor̉ $s,=*|\R5}Y@zifN"4)-Y=)mNNLYxTv |IihFZo9w J`D'?aڨrP.[סv?j" (LI1{Ӳ&j>1 bc& s  9>3^֥5~:VjSy&U|!_ sQcwJwr(${p膩@"(TL=my^gU"]hd%PU '^lb2}9e%6kKI7t 5S uPˆ7 ŵtA.9q01tdh>5EM͟dOa*(1n__>vOڐeQWBִ!)\qRh{ ȀuR^֑l)顥庵R6G16!;TC]qDe|ӯlnǞ( r:c)qk3KY'jK-p$ⴟ2W5o1at[ZEƦ8$SR9_hT 9ʽʋ觝Zk< `ny BuZGG{4*oYzF3,9rѰ`SrV|1rF̾_LjRaQQU,i ӎڕݫ Y3 xrU*1+6؏wX0ED 1} @xbA)G̬\W.M'oEDP~}boP1Dܱ6J>(oP״?^q]+I" w O>MHL&d(b{tQ MfENW6q4);-*^zBdti:EKHh}~Ɯ #ì9 vDpx?n|bi^6QG->K|Zs z{_3 )*2Hx8F#v:<w\Y=)yi+yYP6R ')ҔKPtA,v- Co9`eI})@`pq6PLSG+9xm{y;LxztpWeT~,Ü0 (~gsް>fZ6M-ݻ~3_I ("67ցk~;OM(s!R ~iX._CyzF=_A[5{ƺFm88g{{+-ܱ>a"@fݎF"=H=C R{mq c5)]LaTTU!7<7oXHrLKk~QziS\,vU׃42Rs1,Nͥ""`VAnPd qyp_-AT 8QyyOx:U.}ZX^cZyRxp*mU{5])(mĽ-t:'w u,%pa5\:)M}0B xyLw2'= Jm](!j5ΡO:ZR4HS|b/9֊jBwIEֆ",0{&'%ɭӐV߯ `I1Ǒv\cnOyIuP F /3 Yu|){ f?=\.&-93M*wjY[z;J],Gأөl+=5d W<ѓ\xW_iU.m}tݡRjXqE{&,.(w6oGES`^N.´uD<9+H%0zIey$i$Q4ͣb[X tą8&4P.cEw@>!)՘ ʝ&+m [x֊ݝ@¿09(?Y7Zgu.ȋ2.šdkoc$MvV0}P2UQghq^Y~*{oNUMtbF (9ƬN;uN+ΕwTrkc\.[V;ath=0tbw!obnşyC,O*;` }ܣ>hMS1o~ߒQRfj0(Jvg  8|1Ȭ/XY!5+Ѹڟi%f+zkA3M(Gu,b+'ux9F[U?_#߰Ie@</CoM|x|4~㟾=ْsTEn;+%e`K Qɓfy+D7~?  ԁ${p_IaQn֡lNW,P 8 lSC!E%ѧ8<~" ǧ6EN~acpjYo&k;)HV,]R6kmRCDƉO-/#v) nrC:#m*y]ڔ ړD_ MήjP@fʶ'\K$:r <` BX'Wܫ?vSrEoL\}F<"hGN5p)ܽ0f';k^_/ k< >_OoWZT־chD{/(N2/glL|\J1?Kf<wXifJG ۇL`:EkVIurZ? O)OOqS,9@K:vZn !ь$zR@ Orv;BbFVәr?z@ _pJ\UzmF6_;*Zd(AkVi'Yqh$N,z;!h3╌h=Eqg=Oz8Rݶ"lTdJhe0s"hN xY&sdD0嚫% rv Pq9p|ٽ zZ푩RiTmodSϓDN@,AhQ4ZE/<hE,D!wN7fsEDhYtp8P'g aR *\J1DjF @Ť0'sbNK6{ BJ} w،|gS?LuI$ˇc*Ć_MW]ѠCr$@3(oK'6VҺxv02=Nh;"(AbMڹ~;6milY˅=3QyyXWiz 8Ow)6?eu] nΡ7:[ }CA!9$fuP3M;E˪WhE<EX!m'Mݠϡ>=a17R6_+%=tJ KLh1PwDV7q=NjpSfE_YE6ϻVh.?va(ǽbs3X[Q{$e~p(竣x a4 ^J<)^5,^PrCPC^;i_I۱Nc{ho[F9)U'tEgprh&EyS{"}y'!h2Qb R,@pҹY[}Z7Rs|N h9 |M8Љ}DlWIvPaSb}bbJMзNjUVD THzWM ˥"]R>Om[A#%0CfT%zZ`lگy6:ŭ[NTOnqc`ԫCX# ]B>fbSx X;]Tvj̣Qwk˄: Gu`;4Gsgs1q!~Ոn8SR+:ڮ"nLxk 2#gm0?!y9RiĽGSqo-ܥԖbG$xm!g+R^b?`A^^Y֍ rB8&:R{˝3P_OcyXr6V%rUpDTAč@(T}ZrRs51"gjEtu]Ն!eY@e Y9{+S_ci%߾$ ?b.m %ܼ2O'nq{՝a$=s~JRmj~^W4_T9TBݯڟ_۶kx<%/`w lsiD,onG9-߀Cp OaݖM w[X rRn`5?& 鰜yދ𻘂yd )*;MG\q8O-y.iři;T$gg@_aPU|$ZS^Xšm [4 G`1Y !v|˛N&WJ}d m4To%+~ p]QhNv]ޏ%F]l7JĴ.ZBSoS/,G\ T#ZzVWMƍ#uAd%RJbO-[gXšu^hfXӥvfwyg(IM.W @շ"4l:'93#z ´'Do-͎ ^ %'eB"`+s4Ԝ\*^Q7ͰNRW_ZV jt>EOU]Cz,ٔΊ nJ>r9\d9uZwAYY5R f7]A]6#;"d ƈE6bp^Ln{kǦl yF<7_/ǽ.r7@f44 `V)UVT:u@WuB/%9x5^W2GNdc0v^̛nV8zTW[7qʽ 2_ [Zu=Mڎ ^Og\EE8f ̜)W,`1֋MϘeblwVp݃=PPɢu+j m:5&wfYGꤩfbm0nfu2j!_=)y" ܞd$xS; : TWJV\i{;:ה&tt3 i;^ L(Ê<@ Z_x] ` {c5:#јO[@2!ƮeP"cm>9.汻߂ЌmΗ#r@&58 Sz".S!HK/QOajy>dvhDssA#EfK1߮bh,p.Qw1J뤙T9/V2G-A >"o]8}lb 5(T2$І]a"cLEVn*:잰ɐN'JM#^`2,Iw ]lY!t)d]HR `wo}'aMrSH|󈑁4,$f*-nܦ/Llg:V%-v{DƆ7|>0 &xaAZ©L444 8 YtjOcX_|2oklg*dDXfNwd ^+Imt^upl5B:ꃱmqV-VJ Y7rNvd׋.RL82ȟi4ǫ6yxsrvꑦUUSBT$w4}SDS˼yómx"^,GqUL4ݒCm&cmorc{8idޟ! ҧ+w4::2y> Ɠ$pd;?.q ̶yֲ P*|7* h*JBaԪi%sTR (O1RB~ 6&xj(*$4qW29 XLm7(GIo3r\ 핇uړ.2aw->w@HB"ڟz8s5FRh`6JTF =6` d;!>no׽ o~0GJg2a\U뗇]fiަֵX:nl% T4>uuwmp=[k*:M c̒'D7™ 9?T0 JH@7;oa9@ E5> &kӟ[Mvk:%;ΊKP [H`Tb)Tl {Piɕsz!Ɋ6RVuؼ.ӖOM,r4t),֝TK=/U;24TSa jvI'ZAn$|+*o)o5IK= qdL$zR~d}t_L <*FJJ珙 t5&7!3VsS|RҐi;0b[̸o3ԧK+GOl ԊcYʽHIu:hEې%`(C8 R?eOnACN۹cB!G´`p5پ6>8)'}wul}?N/R k scF@)֏WÀoyh%]9+NrsNՕMܐ&xť &8)Q4n \ sfFتVcGٞʜ6WDgPiĬUg6b]ҎqDGN=Heh.U!Ќ}.q y5(v#&[_D /бZ8NuE-L\蒟=Gmn Ngvǭx{jo$bΆ$9G?A-b m!w}ߔgNʩP_~AL؀:#;H%&x rfPo y8),m3j+29ҭ~Jzts$"aDzyZS7$xtEu1 #pO\J6d3 Qeaucˊc!8o6?Ac>E<4.>`[N)\X vef79h+JcE6s?9I>2 b*L O܊E[ńz 4 uXǥ'";z8!8TM!{' h8yHJ4[#םqSp&&q/C2;>yQPIb 3,#ʅ?"/ȟ F2x}4ͫf$;6O@~t+x*W:3P8:&|J҂eيyN@W1]b(59T')Be8 ]Fd;NZCO*|# C Ax((RFȆU^Gcn ǪGBo-.IQKс󬭉źRW Wl8ǀ܀Iلuz3F}]V+c5$ClH߽I[% Um2d׍~Օ]D^ 3"SƥJ (T3,4<06!cAq8p #kV bRГ:}YQ"9!JeudSXQsZEG` yloA=*nYe ¾DD#,U@H6HRӨ-EeU'9wk[-ZKٕ3Q]Em [сv`hU*u"ZgV!ȇ/YPjvz_1IC'YW?L`Fwv~%,tG-Omy*㪀5Ue0g+JYxMSg2%UJt~Sx.w .ω"7 .|N~b/G6^Rv'$Caw(*M-Y沖X \u=o<J3c*{scofɼa8 B)/6&.?V.Id3aBKG=M{詧 JN05x!\^פte6 w&! ߦquӱL%nCdZ{ҫ,qr l1Gߍů|D(Y[ zSXUukVYُ'/ʗyeҺn 39vd;Cųqmb4:3-&=Hк.Ӈ:GNXqJm4>`4̬K@z30U?6ZYq"4yg-kW!ײHVLH#Br c&nD=PB!7`xla1^5@w9JĶ3ҙ'$*p(dQ9?P+.%`1mz~oyḮ)j؝-tHb ͠'Dь~!nCXӻQ~9߼RuZ(#Au&E-s[;_O3iG@72%^7I6ݸr$Kwy>{Л&t8@M5rm]&˴Rx/uL<1/xL4$|%%i}E6ȏeCKc /1r:xbl< UMM"yysq?<)M$s.6/o_,D+" e$:9=0My27)ZĀa'R b[DQ}͛Nf )v:H9pWhc9:g<w h=nq؛;ƭP'fd%oVk/N@a*fy{mKL]6@E p} !C~D 5﫰"qجο #ΈDdN! g2`$Ӏ郳0bG!Ixg(ؽV.fDžFJgo'U^:F` * `Zglaf=-vR0ubT94Rt?n_qrSny_ۙ;tpT7:@$R ^rϱM3Xk{˜A+ \K19Ѐ*MiYBc\ *C9rɮ3Z_pO I.WLjK +.Q8G >TP>-H(XwOWS;78#q!-L_ ~eS𤣧W> e+tM*.JOh )݈Ȭwv۵TmdۅM]EyChqÇ7LA 9C̔>e. \l;3^S;k_-b& ·\B;2!x'ru|aC1UF+s{L)2zHrVZs:|@ˮ ֧_NA;Ws nAZC͌0鏼[0d>y(>ۛݞiڐ!&zNQ+M/53\2C-5G{留~h5J_ %;A>ivnn7LNYPͷV 0BL3&JM]s`JS9-#E6X=`-{'jZBr |ITO,\d>e;M¾yy~LPBg[s6amm2rۧ=%" R]i%?ė cs.Yu5'.BW^GQL^g%YIaNZ^q'p_]<=% {yKgphd?&v%V_DAL OXX~`b4J_)9Yt0~: 6**-$j2%p}tMل^xQp 0wk`AGpK߆*NT Cά N%"1?`WfJr$pE0vjg1P%{ьdxJ~Z=ى/*4 *ĄaB 'ޭ9k}o6t O[wf#8qkF4? !$kH}HNR!^F{L&)`3M.[7V$;rQ 6Nf `r+z $ :fMb+bl}}qBpO0I,J 6ƪ7J#\}tsN'בkJx5/}yKlhDf|mI-2Iֱh=/"7ُʖ|<cC@Цr}&eq&T^ϟ09,tY~f!\GSHGcG\KP!d q#4/A),Nn3!f,.9- 8ϳ3y B8RYE2zuj #;AzcQ4*i=9rNlʏW 7v*p8}W5>?h7MYNꨙ.T@z)F?X*(7Ɣa5̓Qifk*cl"Xf߿hYJZnb*8M?>#t}# #!BXd<%#ؿn=*g<$6?sM 6l6lޗloQ>-+ uѫ-.zu}a!KaX#**F#WZ*߭>w@[z@ݠ>{} ȤJ{Q||3e,ÁObq)>`gGX뾕B1ehp“:w cZ[d+²pdA¶(6kJHЯ=t02NZ4 OU-w϶8ğJ0AB|ohw&^9z/`7\o|l{ {OY%o׳PDwwȨ̋>O:h{)WRlO!ςc\^ɾX+sAyczhh";>1V&l`R"Y^PhP7IcJRoIs|Zܹ8Wn-[iƂcrQ3~ ݆odh,PnGfbphN9t~4%YпL`\0nbk+;Vk h0[F]@z1Kw GK?FO^%cE"NK`MeRMFjv:'C>7a?o{;>`UR{9łV~h:Jf}aDq$ҍFNN}[7YBK\_mHr),IMc7P%synL)Ŵ23dI7@TA rC(5ƓyEZLS% #IPʂ~IuOЎJ\W( $ĺ_ {EƢzDalRUQ! ^[O%$gmnrFFcCRc5/߱O8@O"2V#ǕFzQ,MFnrro@&1{6+-W%ƚ[@]= cZ2[2S=xrM׻b%Z8AHx^=Ea$K}CgSwdo='M*AN, mчǸs']Jxtuhs 0Wo/ ){mKPiZ>t'zyt8]%X816a.U ߍv(vaŅ7_dҵ@yAeۘXZ#ʬ$>gYbA4WYUJkrV<[dɪu՝ q.Gઃ7Bj ܈+?{";.?{? L8,e%Ȑ_0T̲h%$:0p@a;MI.VR8<I '0g>~rṭ\B0~ 坡Ht {⊬eBk&*|NsaN6{B"l:ECh\Dn,C~a?" Zs *qxG-y&yxҌ QZLtG- DSp#ߥ/1) 'mFTC=P.}sY)(( 3T1D o 30Rz|m(js5& kJ1F?Ϝ-YqE&CQ:bZ$V!;̏LGmv*A7VΗIwZmğZ0?Zc%m!ffgn6lLi =\ '3w{_+m~tƖ˟cĪx7w4IYWFڲ wUcbc%@殂$?i\G-whEEr&VC0\)~AzvfX@Z̙K46A7]@eT r؎eTFH>nݧfM4H"CCB5# 8m~W1^t#Bx֮x Jlqv9(Z[Pl,Bt&N„=l4[; DkbUDG.{ Dl;ȷy&] Gl$a> 4a[ykb)CaW%C,9Hf W++ )L;~7:ﶜ*UChQӿ&sLڀԖENbz_@3g'#VwD6a&]A?hE\)$SmON &L$"*.+ɛwRȅ "AeYXe2nq̭7KhдO3``{P=Եs¼gkL♣Ȅv\VO9Wѥ@ u v y364Ea1Sy”D—rY$qIx':oi VcbEښD431x2apx~3)݇W]=.E3JFs筬+ uc&鎖j]4[8t.T?Ƚu׊VV]¨U [w^%e)ekٟ]I#J9(z5Vqi3  K6@Ur6~IBV\Aϱ ïRһӳȠJnԪf\EMQMI˯.V# NݪfEIZ^F^8N"9*V[ns8de&3ڀp"=&OYgWXo3$@\a&˞v"ņ?\r`9oGX]=q~"=Z {VUT~2Y(5Aj]IY%Tt$g.DoR&c Fᴰui]zz_==Grj28; &6eIX~p4q9DJE|h}zXyJm_'\]HBBƃ[Nb<]9>0浿X{3B(_F/5:(cn#@*1싞h>"[ Tǒd 9i~>ClGEɘxdaT&z-Oq3"XЅG#ŠD4H7=Q#92pykr7Ve^<d?o#eѳ4l;Y b5-lgJy8ζaҕDjO3m v~2TcTʧ![f_SMj0~<0۶ñnM1 77QqkF[k=J0lH=6D{>zj"~@]ɺ&hjj݃|Sh~֡RE/0 鎈Bnj"/9ZR7^qHꨌqtЀ!.uH~6fGl%.I'#d5f`of8|ړ2Iœ$s'qk+ᢩ sД`pc)aBԱxsE5NHzm&Y(]˯ؗz I'+;js=f a\vcU5~VvI GUOutUw7 Fw:Eȕ`/᬴s6sx˅;Si5Mk3(:#+RU5,v\kX ]m@SS 4pv}SΣ BPū,LXAa=GG;ysЦ1,+6 mJF~E[Ҵj.n#LmE*Lp(Шypc |s9fDI/(#`Gq¤J_iJ:νfoiG1ZKr41v_tlB$cɏ꥿I5ϸ7L8E =X2wt[ԺQĮ,`o[-k$ VQE-|B /j8 jJJP kJgҪJ #T6EVE )s^-o>ɐUPr傉DG#Z/*b}m]vr,_ M,)a~B8]L#v@ \^U>3=Y[˃}DO4n&*ߞO;B:z!&;\sb§Ȩ>Y _竸}䯏 ΰP6'oen[ȡXʱan}I uPrWN9*GVp2 mл,?!+^԰CtNF>g!~+sVB70O3{&5.nNYG7Q0ׄ}9n^3@Td6%Vm+Y @V9xĮ@`{!s1ڢv$/E9sZJ̶-W)j,ZؐM6[&KH !gJ3僘;4>[xLSH/r|R뙺m^<xGY 8>T OS`U7"LU߿˷, ' z+T .vmBQ*hMiK\ԣ2q7$7aR܏3|]1zw"yg3S^:qA|l D5- S '!=U;5$2mu`P, MJ}?tXfCAɓ NDxHGD&J-̍ maKkȘI`U;{ a{| w2 I&P7eZ,˄)zؾ$?:B_EeV+ wu:zs^ jx$@dln o\8?5wÕ8wTXl.5I #N(v:`w3ccJLv7ͅEj]qW)*\Ӽ픚Ӳf#Oxl~xX󛭷ɧʒÝLyVBų"NeC kvvZȏ]N!w&հY:yRqтv+˄<`{1b[:e|Fw +xYwZQ} aOO bEHhܦie%\E^5G@{fl Q!Tϝi0!M]_ >2޼O>6Q*[ sw_3p\v/>9^v eAǞ6usFSv`?D`6n7OzNr_|G[ '=1hY$Yt!o$S`~(3(Yqpݩ>6z.2o fVH|ަ(f]E %9̇8Cj7\@Eoct81XAu@Vpw,kꐛ(_4-w`M{_ZΡnpj HiIH"0Ɏ_ ^Q]t6&,\!akpn}TOeop^gFOVč'ϑ1hF(t]_#BNQޓyT@ rM`ή˸V`iBzH,s$H1'6ϟ#,=$5hw:anz!'ԪC7äIHLifDf6($+$ܿo%>Hkڸ/ȱ)^&ǷpW-%ӞO$;"$#sqVNVN 'Juz$eG~pC0;5Or6}~:^ s 21bswpIf,U\=9ȇ9T\=UMFpd|Nj}dQk?UU gU%k?J yT\ NL zǾNE|OS gM'˪"NsH1bT,кgYm]zY:7ưJ b6D^nD3%7V|X>bHNѓ/\Ecթ1uS OU&#b+g頛[xI^SKaYԍٟ\7(PQ߾GN \ tDOY+h_揈Ha̪44 5%\p_R69Uf,+O -Yw= OTJ=- 9w3)tCJ MI3W-%6ݗt {^2U4%6Zp)JG"4שjI ,4nYe[c_vd60@d Joz>&|(aB7e;Vrm]1R_0_"5=JR$q^w/ ^헾)!"JoIz, C$f@  \[@"l.i!5./P%nqɅ#jbT&q&'@>b,j78x9 a^ ӌ/dnl10o̅UkݴusBgvEm (e-ș`CQ^9ndyUuЉ\o{6s6iq Fay Yxjf,距sAʶp OawҚ<?|  }r} =2T;<qmk{Z Q)3e_n qI HK ZW`s{ax\?PP]KE|Rnl3;YG/|L|O#"Փ{P&)(ԍvp{E8#u.xIpLEO  0$l |Y+dǩa!YHB`s_ ; Uc'Y< wLVu08C~) h\&B2qrYrrYlNtc)hnvG婝/8B- іmj/~!112FȉZo-8 ݪz}.PqwF+Ad Τ^!N$\`-4r.4)Ԅ-f>Gg<˛0uNƶth}[֯GT:a(ni-d|P?C;vaVb&wa2v p,6f#&`GZK !R N d}vY!sg1zYJ ǙBK2i!R٭,`JiP{wˊ fJyj`WSrY4Nu{-O貧6D"0_hcwA 2eU )nĴ8csΣďQŎV5kۚa^:)u}z&my0ַ`~>߄9{,d*)ow-cfftuσf;o]|ŭR;\B*qTbTih/hKY&P(zChĀg綊2roX|-Uϲuq>2jS Y s#-z8n]vll)Q{:'w{c֠:% ܸ{ Mm(W-$11~hQEOwX6@P^6ҥ<57}g :&"(քVRJDU@ HaX#1 @H⌔OrR ;F2v6FZ7 v\\6'αx2QA--{ڝ>(ɻcVsoM`tNS5KN2gѪs&nKD0 l/a2/h`%v:o6Fi_/xOY鬤| X.O_7e*mP9k;,8Zrܘ8Otg/r:$2T( !ᇁlGo'َ`+1ZHҗy A"&Y\L)zuX`EO/Li(}OZ*Uv̧ wX0J.2q(pC(`'q QJH]E>UU26)(S&^SA,jag3O^0Slyi?J T̸ xX_`Έty|~SJ¶\4 IӀ v9r9T՛,?u/De3vrV6bqS΃}ύ: 鎈g[Qk&:{[{J0(i/H7)fZ/ 9| ns{ 4jhXXncJܦ#A8`'҈Ok/eD@4qRb`:{Dyu\9 F <|f;əY^wyeGR/G(izg.d)F;:Fh:_HAe=Pʲ"s)!Qˮa߄_ʳWd%_BBV$* 3SN`Z*aNYOyj v=ynd{$8Q~0>Ho?0}u?a>S`0p ƪw2vt4JO w/Xޤ+[ǭ-<&Ic!ul\iG|g`w(^3pffK*ٍ^}qmjnzðT$~~ |b0ZF<506gQ@F%v sgkEtv \Q9|Wa<9–1 J.~d 7]L" %wޭy%{js_{S`GRjdҕZ}z:Λ8vGIW9'ܮ]%Du׻K7390K,Q7%c44Wk;+4N>s=U]& W-*Fï3؂I~ V {cTBv^KC5F AXv/#^78?1ER8dXCx˪$JӪ#dBvNGC'MW.mGԄGd0[g+GӐЩXÆ_^FW鑿6f>熮m.Eu CWUO~ԩaׁYh<*etl , cg8bxh! p u=+gDޫH+6 0 쮅Q6s*W?b! BJ0֣mXS 5LM;6>uKdwh"~؍$ݍrNpPxMQǷT|B6l6!ae=R9t@'fFW,9wYOUod)D6neZzl5s:Y L!s9Fjc yR?B?S8v+14h5XB/kO))z ڋײ* [\zUlRV Bk, YBP!F`A,mHHE_s/"20LKn8d+e<Tj<I>hAZ2(H@cHAEldAh:i~%u<~@zp< .*_[H*738D_PO;%궕/M8+qTS͎Xw gd4D?bbl' NTƿYFpHGjAo4ʯ#ZGL=L4$Hs+g3_ɔ4fA..ܓD5K_B׊/poY!0O]CűkG&;GǷK:&XtyY&vmYޑz8iNyO/YjcXVR@E.yJ32އ4iʑ>pߦۃQgױQ6.JjX h(ưfd?][TJղOS$`c,ۄo㨉sS`:p,xTmm=፤4ÆZE̪|w=ʜN_՛Ou{ qS+,$e^*۠aټK˼h*Z iԳG/ilJϐ Hްh7몋.e=Q$ۻQeU٭36 R|жC w∓?6rĬGG- atPu LiRWɄߌh@K6AQބYFoPȴ2˦/\qrI:(,TVfTk IHvWx5i 0x*T@h~ u%~F+·NGyeHzLs< q@n] ?KB"y{]qHGu©6_ ?+{Oײ ױN p1)+mzyN-}97otEJwFbLI]kp)S1[ r*TbLq_.OJg#όYB?(١cqy4< sn:$iYdLjJ\>>l2.ؙ p^EF,n7 ρxA+ _H!uy f^54{hɄ8dMc΃ @EEdtʐ2S7[N!>PLu,2}h_صʃKU'G0ڹNK z]d̠|M8yݹ$ؔ0"fQU؞oj}8PzqN!ZocHYjfV)km }:^ ˂ٝ.T )=⏴lp@l[ȊK1AHԣ*vrFT(wIP'`Q|x{'Z, ;{c!3h(N:V9T `H΁M;$rHUR],!/[e揘(2S~.p8GW[0%cLLR7c86oNu F.+od|ɕcG~ݴ3ezJ֡`SlA[w>PUqRIjLUI48b{̓KrL-A e+ RЧ\8q΍/Ўnt! %dFpW} 4XBI[c嚩#Jqea[z |.=u1;Prx lN_ԗb=بL`|PfbJ(50MW% ^)H"3i+Kȹ(({QgQ LuKth=-Z~8"7(,V̡왊"F\rN%mN_]'q;`~8rm]7]:㰾Yi Rq3{w!z1D#n{GE;o<˄g=w“__|Z'}Q!(vr9URV.uZ *c1eZ8?j)W8*Tl.@OmI7=rw{8 ^Zb=X-DduLَ>Uu1.QazD* SޡESR֭U2O l͐,~crG4u>!@:;vi/j}N /6v cfM<*]gD^| c'ˣ$&[[g1}fL`efaJA M3 P3HE!/ oJgV8n:*pvO|6f|繂OzVOnip3LSxb Q`Ĝ !`bL.Uofl/&#˘ UH _!,$0껷z+E;_hw&FZ;s{min(O.=?` .;pm7uxq$tpj`53}RccX@J/)TFJX,e MbxаKDqtgp8 (ڒ 0F(oM 8L$:X9 sd*fw-w;#nzʔ$Hp/RCa D<9`b A$a;fEPma5hq&Yjv$K͡z5sG@ )t.vṮ9:^}ߍGͻ7aqr2bj\(iIM|*9> 2#R 9VMj|6_0 ߳GH< }CxGB7j~ ?Ef:wzh"B[\a_x3/r mP97QECG[Շa~[#?.Se;-D,+hFu/\-j]WWKnzPJP#gO(XPMCҲaz:UKguײo=z~[)࠶ /CN*TdHIdi7Cg Ehrta7cEcsY9'3vuAFjY*ey/sb~yiXb19PY`XMf&GVvh},[)e$eD1`]u$Ot]ǥ!d.#S|ǝD'qo$(UdS5[x܇d֙Qd}C QOn{^&!S%π+ݼҺ@'thbDS: 0/vC6Ϝ[J^@}S!DGEl͇knHcD93%u;E!0ÐvQG6v:e-ctaGnOZo18<}`tXq +; u -s 'N$ dH?6Ա moLӟΧC C_j?krWR/0QL^ɭA;ubՐuCg %m'Vm}Avcb vqR#ZMp5tu|jn:'dHy !8!ӽb>E y3k &;^-$8EU@4h~Z] = % PD*y^FMNˈfWDW_O^W>ITH0nYH:E?+FW8\3ےW0(2hqMo:_\(G3UC[U\@ 0cz[,B0M*f  U;@#Y7X|1.H.U|}/IaӖguR^dϴ/O#Ei'ȇU>\z 腐$#hvc йzҠu*6+yLaNԣrQAQd$ )=G{"ƿː\atat6~HwrieB8g@TP۽hPM?dCK.-T>?v fX o o8r\1dI %.K=j;vu>N ݬl bC,BC-?k֥zNѹoӀj볻 w5:^&^Q)IEeѻ%C;QO#G5rБ֔^X$Z(T70O42p̋G,b A|e"zn1`z e)1t\fʗlwQB~sұni ho1*o@asL'B(t2l, c4: q>D=iӼPW,a:}ܐq: )JAz +W&,tWb!k/1٬ v\G^Q7/|=&} T^YEyx.6;'S#L(HwG'Wd-~87RO\w?8^ΐX~d7qD٨O9^'=Ja lw!sT9Qm*'"qGJԃnVuu0/5_i8=Z<%vVұD.cʠe}75yD1g;I$ktl>t<BިG[VdEݙZGY/1nVƌ/?qNfXۼaGQO 1srؽ0? U Ņ`kyf˨ M:!kO/;N+hBB!zت:.qUDNH>Ap ٫49nݩh$|w/MQ9'ѧ4ixH\O >uRf՞N]vw8y RtR'K RюK(QSx2pl:^^eu1L\=PAB}IJuj:g\I6Ɍ!7 Ny>jgԄ.U=a:-TArxC\+)Kj:##@\]|M"*t P<ڞ~4sa=#yb]1bkB6.؞"ai16oE`Z]& e+.zk'-{^OE1)7tI~xg/]FP '?(\ּ,'IiUJWw|Z.md.}힢ѵ"j❣qѩHv?3# &yl <[ ܎nuIB-&jM&ug46sceo&(:T(*@74Y"Sf8Oٵ ƴƣ!Tƒ"s" e,DC@7eex3* Jw;GbPzbJv' T0ٽ(fq([j/#훦\^BAt~%=4;iHs@D7Þw?Z-|<2T9rq+'G1ɨHHǿ cQ'y^kƕ D(}ћVjglm@oitۓC{3Qtg`xi0@%)}0 U :{@ r;D e͋_~?r@Ͱs$5mc#Qj2*mF :gZG{Э60HVMj|seTZK\t4sBl*<2\usW6`ԫ~ #!aD`ouQG xjSJ] 2|$Szqtul H\Jx&r}EY17)PQ A~t܆񋔐^zN,ܚjw,nheߍ EBuYT&x){C瓅4k7"ٷ[hҬh<M0b`.׷*p^"DA?M;@P[1 ׶sg)1ܝVFv;K;#aQY 4Y)<^ƻ};0p~r׻r:uxaBP[HӹWŮxj:.,1:X^`c)w֤ŒYm Ǧ^> 5t搝Ҕ3jT>z$;Ǵ1FyI3n),\ʆ(TW Aƺm .}6s{tYW?u0s7p]6 䶔-&߲#9\%a^<-UY;Jea?t[Y{ (8;_3%[gl~@ķI}15vɀO`%nj贞(wF`ccNXT`guvY 6J^̖f+E7'?fxr{|׊ I*O`+N/v.Lzw1iFuz¥ځ"_9e=F^Z;qiG+wļȋ-3O7ަ46Q C- m3"9@h| ,G2z a '&+e}ls9iLКJ[]NWӹ?"=U;H *.$oDQlo/^q]rfZ:!BH9#'%Wl䥹~f)yؒϺߗLg%p'٦̾i^B[cx`'Ż!+",izZXUϗTh&Yc,!$Т!ãR!\ g~X+i*f[ do컥R.>95\˄Áe~r&6eqQi- cW3Iܐθ(^;  r ҥ,Z}Hq'Ë_lfZ8]]/ ȌQ8jYݤb6,X35Z.i%]k`܌? 쉎rFRNwHS;YJ(chJo9>1WSvW3!qVR.ި>qd yJܕ՝ުԋ J'W~zVTP"-B-(5P5~ӂ_\a5<:˪Xirt@fX=&ibFk5̨=rc! +: =e="#Y #AS'MBM̷I~jղ6:1VkaeT21TM'Vb 0M7?>^ 1`*J u{ BϷ8(% C.Lʮll[*cqO*|ٽ"N*²7zLjjal2{T=oʰkE,=^}^d"#n{۾5ʥQgƀ$W*/5Fp1`9}5lԕ~*p򶂝-7#|n+vx:ĸ*ai"*ߥY4 F]B]t䐌/˼\όS'Px\KQ&xb-gؒ%:*~6yDs Xlqcd5yAa?گ`8yqB;/U'<NLz^+fQy"m|N=x:*+:\Y#gξ>xz"'bI9l, CMK? R!adRvs;Z(^@eD<CxLhm,S$ w%A-oϞ\=EI:(fJX_}xjt1uKṃ;tOMyUk({kZp{ɜ`/ *n8wawP:-͑rJ[ 2E-"'~` Ml# aJ$VtvqFY3@o8ch%y$6RWːNQN/C& :Ԝ)ˁ͚A?iŕ;DpN!ʖ)J ٚ}麺Ƿߌ]+][qɧ!'Qmn))<-k6=fE2 4}Fy5S%~*W% m_f.YV)QIaN" {E|<`ӑ˱ Z*Ħ' Tѩ tue[[?Y僚Uø/-Il! ۫Y5[sV<㫉7b>U\c:/Ѧ:}ɦo?tZK@ Hh b-ϪߝG7֣5^DEjFF|diϭzsc춶g˲ʵ}?ِ#40MDULEJu3=6=#.j]9 ?4CۛQfT#6)[=1T/j޴;쒟=K[^b7N3 iZȫj ˄3)T%nLJ[**khHqOz_ٯ#gRq]-7|8+*=Qs&Eٿ=4[VD ˳cuУM 8vbIϓǹ/6ݱPC ]OR]{VV꒛O %IڶEBQ~@ 7THkY?`q6| " [ϦMcnз 8M0 \K62UK/dqe_֑L //("P%u n*Xpon-sUk_v =YZvi_Tk VfX6/7Ɖ6N4 .H\Hod[G YrvCspˍJRN)1׆tPn 6VDخ+>#ޤ"P[~2=WvZVUⱨR9ubPbb|up)qr݄f W$pT8**$ު/-P*? K{U־LZoK[gd[UVA߾aEAUHɘ\CsFh#]-=%N!zH%:+beuj.N3k$. [F5fX'd`Ug6 Mz'󗪜=+~!>|o7Ȥ)M@1Ϳ<}>I( 'vgo(VxbG@0$|CN܁uw72MYK!OӡZu<}bbsQHq;r9DZW?jKպo;5E`` ߔAdBbzVArAtaM7 B̽,T@ȳt(%V0|||!?I/L,$IE v `(\`\f:7X=j=ڶI?1R|f:̴9*^Z7"ϠOl\ g,mXO>\Ux WV> bٲ#ADuu#Ln")ҁ/o@+{C2P3u$BnbPKtsv-̷~9`?ڎ!;'ut9h{1⻛E#sT}|bhxm-=\Z:0uyh"suO7:(cK~P!ev?+~.tRbݻORg528b݄n$>@B{;P h qO.,oUAc KD5obL*gJW(YGjs;srXFJSdh15̦`y1&\&;&.`_ J~Sy7dayt޶2{[><^mI7Q޻+bp>z;pgw4[K%_enn0Frث$'&}R}|12QU5$7>hyt͒vJ;9.iM>KAIqiܦ+![@rė nx1XR>z? V}COyzb:۞Hw{o mQ\ٻҾxsLR# oHjՑ7X}z?԰pxc:(QB 峜:-wv?`&6:B!-2Ag0.{ϾsN9HCtĒYk5{ԵYãbQOY_%7mnr(*y<y21\پ/cM,FZCὒT |OɁ)g־,w&N:ds?;dW%9L"G1?L<{ՕXyt.u`&ŃwӰB`˦*?DG:uđ9#.deA8 ) 09RE}.7s@!!+؀5ӑ`Q&F-\^ü[)J7 ؀x5>>M^+uSگ } DO?y܇}#RpҢIVލ#cp&-ngٵ Vx;e64ҒDW!U\.]6HGC=NT(j}@0yaqjvb;Z' |fRf8Ci_\@!;[UX\x?4JN/e162WqkF~ˍE@O9Bi(9k*ALQЄjuC,0W@G7pwK1>DW`e:gMl84C[?^iibE 4 ^Z;@ȌZ2<\;bкB-Nw+s\8,=|R`8nc:I ]@ Jd@批5F;v|HǷ?.O}?/yhene,;Zq2@Htܵ(̶\4OU”i%L?A%tÛ?k@jD'OG+P?|^6 L?9 X\?g qF-j*\sXrëQ[`qi'mMp,lYBtQ'[;ob՗S"IFl(/>=UlQPT~.lqtu- $x'6D8GU@$J"l2G tlf%qQEiegfvJQզTվkj\15,?]30j lJᯆֶ:fԥL1 9?֨_僘ڲןF9L=ЗxGxOy Ù -,%YRƖrNԡQSW{MKe( ӝ۰E~=lfxZmfZt(@>͊TIl *h k;jAAaTlwXp^;1L$j=5城x1x\cJG:\b@5ddӸ 1P5k`edPLeZ8,hayZ"ow5Wxdm7j@$(3eKS6Za] $n.غA]%.D}k {7pW@|hl貿ol7Z畹q]ZͪZpwPyzWdae"(4d%蠀ȹ\&kF_;~p6PCySp(1'C H@bl[SeAnؽE?߲PqY>- l;AK2ZU`U7j=UPMlDi~oDe]ߖOGݺ`.`2LeTT:;tUa02KQMus*282vϥ_\_GtjXo|$'o‘>'b9\.NY_Yswٯ!Dqrtwmqx$!T g!>)S"X-^W.% E߷ݸ.<X eQyGDoAչ)9 SK򧘍{!o'w (* Nw?M̘@+GVNh y;qe /#x HA(t~;+~nDISDTMT̸]EHJ|)DMp/VaN}zߢH93BNL-%-Np=K,.] h335;̀'TH33(rR7Lz2&.pX)6-+.N$qnr I#\\0/& PAV{t{D$\%nײM G&sv-*&1ʨr6EIͣߢQO:S`U">!+}JZIfԞME-ߠg o,ګXoD>ށFw3agdt/(_I4J7_ff7]*) L6y JNϧ̣*Yޱ%PU}u:Jc\pנj"x8Uz2Sc$kt!YMSIC6/L4PD!ڑFS. 62=3𬼸M;wbXtĆ% 2U~]ܯyw\:cƀCJV>Ne|7Ӗh);myra3)W2&#GlNt2rؼg}c4oGsxp"Yg7[;gzyWq +&6qUK%<Z?6+z']kRn$[(1 R\C=(l!#ys{a//Q ^r \iPĭэ׊>eK8 r j_;rk4֭Me8I1 ݊YYҮL!9Inů[ :4q>M&_tYpzji %`^ЯzGub?~tK= ܱKP$=UM@ XV~2eG 9#> jQ_MfQ9H+vPGTS7qQj nqECړ riх{ UA~&j%4+$nwο2Y00-P<|,(rL`=tfg6K1$:<#9#^PFG`!)c܃YOe)dݣh F_#K̚#,H},vQc el 76,E>a;WcxܢZE`M3.Om77v\ƒ YΙ0 Ԕ D|5`;e Kjomcex1=Wj,S=:L8`'^2@JNXaT _;"bru}TζLLh+ 1S1JX Ić>$@ d5bom]1Izظ)ݶ}nUVu5Kf}'[D\霨Xɰri0sAa_A;[Ri::.ߢu˸`% -\Q~"M^x%7>7.#sW\C"^(51Gg|Zak_enM X=ng[P< /O2z`:/gY<wy8f_w\4<]ۿ]>!*-)qgI2 qN^O\|)7τgӛEX,a)UAx2+Ӑ d q ƕ*H+)+TGLFZSb$yIqڙ[ vYQ;~ VVpU\%MQ#;Xݖ=;fp~:&{1'P7Bo=a&r|՜my:H?"{{N8&j/ ^HjRqDqE8Lؑf,"wh98V_綽[rI89;!)4jH~ɟO2@{, ΁CtIEK`os?!Z/13 Ma7:]D->Ks ܌""م)]v7iݖ]괿 ;fGAUj0h|2>VwMR;FcW#&Aw60"ڣRPș(-_RMrob~" :aQ@Y*. j~}D ,SS @!~AW13܄vd4I$S@:If .MG$ {%uWқu (z1y$' 36\yZ7pׁ*60RR.7>%.Wt'UZdxaU!mqҎąBT-A՛#8+>^*LL %'M' @j-?j3Uhvb:vÓwQvӞ:J>T;I^CDbWyƏš[ac A#%_'-1e2w\p'hmqqiny%t^֠\jH i*>%S EK,ys^8Ms./Sdc]&,Vl!>-)h YM>ڴ b29T`uUh2,R qzӲHuJ_diciIFp)|>[}wpz1u6goK[q$w"r@W6*o^SJO Y^Te>q6`1~+{΋6_wT҉v9hS;>r:j,V_4%w:c0\#ӷ-joCtф~j"+5ڝyH*jH qvf9@DqCM~ @ eKS&J*9h.b>bt#E\F7YNITYTrn?~Xrwvg8fJ:х1l;P(K).PoSF23(z8F8Tat"xì XCm.W9Ϝ3Z[0˫_ ڭAtkz-,Z#9*n]hTԜ]kvDf^/*}7F~Dg[ڟNwQ`T&K3^载w n UFߔij1;ef]tspOTfĈ\*Y/u_<"2h \'F*l(c r/^Ps>0Kcuf;GLul 's{b.z"@;p hEЉH8P:uګ% CK?V[cճ 0+pMǿS|䁟y$SUߏNxClabUt0:ZJfK\+[lfV\cdU*Pؗ1YФ_AM YAUcH:"CM-[T0gӡ5Ks6) :;Z3Pgg[bеiK^4VVX7 s@cRt~p͌K"?o"٦\D4?پFj H]UM4!?q5 :f a0;Yt68pF(gw.(L1 "1z1!J |o3ijATMTEbJ 9M֥J+(v1M.i+jOΑJ-ŞYme-jBW. qGq(t$px SٕNu?eYO׭h?$/p˭/l ~%R^084I@{hs tP-fRd98O5lEّ054zRJñYi_Fc*)D1!V1{'H}YQ(`KtAFׯ\~}{;=t-S=P8{@xj / gP CG\W~#+ær`+y¦UZDYR2OFӱi۫/z[WKk:ߗʹ)h+jɶ; !c[FjzZٞiS>ǜɜŒ kP_70n 97ًOI0zxύf=;RDJ35}K>Pl*l&TMPU4*)40͜[ٌVW}P@5^֢KL+H8J랎׼z?i3 g0@-)x({yrJݒO=Y-B& }oFUTJ>УusMR,nE@R5«$yԞqWn\^ƬB_8b/,}J78-2(db]'+֌PfEt(_]B U/TF{2.AubJ:fSwYKCZRHفum0fĥ;s¿#ȫ}zN,@"p@RTF.!XhĚ Ue[-؛I=$Dc[^^,oSzq~WIs]䇅B⌎ r^z7fB7hE7(`$!@ajF~XE׳W@$.z7u=_ѧǓ]'OEbKcKD%ܼ%]0Cm[+G*+*|nݿw2SރOLkTFʊ8+ hxsj3 L}kLvs:IdN+-?箯`K21a[Iy;>BQ5rdS?$f:u13w/oi'=(D۾Um2""F~#i3męD?2F4Vim6x:׳s N2i)&\Ԉ?ڙ\_c y 3}w[8bDR^Wq2|Ƃ~\7=\Pe@"ÔAVoW{@dXd,a? i.M9&d>G4qG3]-Q #j͟$ݿaR]W -bsyH虱3V,JfGX֤ixrq#r.BRӫpv|EKa/P"}Uo%4ۦfp| x\K(W%XRAcZ@v{[Dք uK?o|O}70[+H?3P4;< CjGDTx*e(C̚:֎W\)SDye x@@wPJtS<{P h6LV9'&"WgWOH-W G61zݠcXvl&U*2gۜ;zP:з;V@?|FEkOKS:k]?ʘ<+Z_ٵa9N]M: U^i8G]^ ؚ#shc=hIj2@͔a\5ppMKk޹G=?U>Kt\{uǺ (qAO->ƽ&OMv\?jw!Sɟ6oeH~+!gNKʑ>v=op-}w*8Ӧ}|V, S&p2>bZNLp /M=c2`s1%SVV ;Kijo;W#;91Lan2f Qna*z~Fh/3Ry=)вu*ouu'uT ղ< ;a\ޙvh}'J漩Ta{G"',:R(6ose%)Ȝ*pjTۢNV7N[ضN!*څ)׏]S!Qjv`J)8P ^X*h FoV;Y$G䭥leloFkɎ pj| G0/"hV0ŲKr*d{-Gl`k/y׭;T+SK邖o>W/. 5t3r)_3Y G%>@0dX!'xǸ?*uoo0LJi(E`42~⎃. 7" ۰ql jNILFWI,E8WDR/71Dtߐ{ؗ@~H.+6 axy?T/]BUX.߾O5*#Za):m7穸z k ݢ))9څwgRPRk"M0KJHl`)&j-bYKLfp՘TMK00 eWʎ2aErYGzˇ #m!dUW; r%;%g36:Hû?% &|& O\ սKF]|'$Ho{b:Rsy0BV{+ڝmR%NJRp0M=2[RbsddM N=Ӓ<,r؄JG4!a R+ SC /,g۱ h߽\䏲3+#¤*.e/4%!BspԵ?0yPRZSH;l r4q2Q@Gg M\?=)[2R ?)G5ű|'0^ACl @gl]9iCU逐sVP4_A2,Pr}cpK53rT9 iWυIB=Va'}5UW6M4!ұ[mo23-)"%Sś^uSuN_tg/0q`jA9>sƻmN0Cs6_lMLj-G, -GNbE5HSYZI>GKһ6r|A_fi=RGx ω"D3 HFߤ!Qu|uP.@Ma,kQ2^tAE3)z?!/]j]Ze*Gˠ.T*fnK_l67f;ɩKQ#< )'x>Z 0N 7w`3P& 4_Sbvk.!s|'iPENHA 7Fˀ$XMtqqzt^bc~Y)/`C]z}(-!p Ǔr] =. -`Tn]G9EX8W.>TtB1?iĂZzq9yة(C%A=nd043u#GJ`#&7CwAljsqWep`jHTwӯCs#zDȯPZ >: Y>3嗙u״8؁XpѻgWOG-E8԰WoB֧4/^%]hŰeQE+D/Ҡ/5*/ Յp"΃zb_2{ģ;~}%Rk* /yY{Kw{FzQ|*rrDg؇a9PQ>AW0IK?0w+7ۺ֤Xg vT,Bl&M:5$Me]rrXlE6ZbKXۤ Ow1w'V@Aܳ?>UU+z.Z1:kXF)c $Ocqx^LKXee(ÔD,C;35;jiy16Os֣ %l^@=RS4׹MuE q Cg&}Dq+iXiQ&' -ci,Ϣ}PAEhQDA p7yp `2 Ԍ9$}1z'}r{b# 4x;$ryXo:ݛHӘN޺q"QY ow1n!Fdk2,W̲F_u*1,57}FJ ?4`p[T'p(+s'k pN.Ko_Rwʏ4|8M,?v}VӺ?3qΩ,r̼)i@ J FQ`8j5nӒ39 ;}AcS0~l]I$'EVGSUqsY&4pHt؍`%wU~3pbR)NSN!|(yベ,t3 }%4ⱑ1G8ɺ-pX H|ȡbZ* ijXr"okE as[m\#i ,ejKN2ڀ]LZS^Ս6J S9ZDvU:fHnD[x1? xd4w4Br<Ofht n ܡTܱyőO/k 0 >5բ&J_Et%3$ 7d?Y8+ǚ@}!IL56 4+cI^],u2 w[vxtRĸ+zAsM^Ed# U !D2ekV{A$esq=jd~WJ.žИetRz#*wU*bOT7z_X&ĸMr^a)ёIƢi-~JMA:IgN,ut"'=E]'}scCuif K^s\HL2ٳñ0v^Dcw麕x6 mWRv5Nu<^Ra{I˥6ϮXYpA}OcKmf0A4e5('/1h@fjcPLm#:ߐdOC ^9:QMo۱DUR2Z&,n^ǁ L&xRBꫧ!\69c_>u Bv/VZkX@B%ڵ&9`H߄GULck] pG;VA@%u]Ohk0 Uby4Ґxt.D̻A$[zWH n.H3Go|JCp;{בU)|%-)$tZ,q{==hg΄UW:E5_{ qhv}SmT p]bQ[&O?T}qvs6?g%7+Qu"ƐRM%| ™YrHYt.@ m EL9?tв.d2~๬vz8y2ľ뇣\0sv!50ݨ%G'xjoAԣ#ZRd&~]r6Qntd;>{|5e2g -HOT_֩3薃2f1@0Dm L\Ar]!Gr+Q6ol ~Ҭ7, ̝k$9*dg jDAO2Jo{ jszonal aEh:1ݓL,!h8ZLV,˪|#ZZBTECW+Q$SiA7Yd;bHu]b>n/* gUCz:`Nk-UBD}oIT{/\&pyA_e{/m6:tb2UxK) $%.lJOm Kq_Rk"+ġ@ӃJiC.:z@B/$w-m}k(ֵfO9$&솖-E uE4&mx"EU'Jk)༷?re؝*|; =Ir=Mhx"B8r#__:PHٱY} rN*YuĢ/+Efq}ri*g|(Dn*-B+ dPbN`\ȟ~W47eY@GDd Mlkn$H {עye(o>d?y q6_P 9[TneJG*&"r}GVI׺Q7mar,}j>Xˀ)b`EbBsE&HI $BuetAnzT%c uFcʍp6C찭?hhho}rFB*~ {Co*<དn.IY I{.J woy=!BG#.fqm|{*I[rA2-9_še1<^;IIba_ncgd?!|L8 {]DEl)]AwM܅rfхdnmk1na1ܐBdj}h'ME*Rќ2*v#76gߜ\CMm^blsb-Ml;V&\:_n˝8@Őg/ x1FFAz Õ.dh׎*lW⼪40hh-gK8rxIڠ鿁LuٳP֧0tRvӝgcXa'a?!5(S,mG`Z3 5x4#/1QqӇ" h)?ϫ1qI5Y-3[Ooߖ44zIO tK.0[svHue7zy/Ej=rRFMJ)\(@bBۣRp>{{=]}xO8,.愫/6.ȿ5oڑ>%t4S;:&tG0s}h]Ÿe8-gjciˍhͪ΃^Ԫ9n.r0ϼN#OgۂThl,Wk>06ɢ3e=DQ8· -ݺ@'G CYCׇ0.;.ӏKqYYH ,!4n0kJZ;fOS}+Fbt}-X%C/]3ݡ ڰ9Y$*-)ep2.Y&f__1$'ir8c\=F廬P: ;JI^=9ɓaNPφ>MLmв;20n-~ذ l,y7݈ ȶoώg|N|Fe {I @0Mb,mFJY1{h䢪FwRj*Cѧr_,%zs 77"P>QrOњ  ;E/' Qt`4õ ͒؎*2u'w{7uj@jq[61~~ 8t"$Ѯ<&tZi5=XnѶ zf"mS5!ET4zE2IuB %2 ,;iuJ܉K읦B!Qxrظ3bе_f&ҿ% gos:G(i[ A .TdbZN<}S9&,^GHƁSV&]÷KȌgfth!W=9XB~A:U4Gޠ>MLi3^4d̚GCxbs 5F}jٟ{DEh,k~rQ?C1n !xuB.L`$#Z "|p[=׺ʌ/906g"4Lwst I("tpaXWN⨸/-&cmdq(rETtd"nOIUtљl\'$j}=QOѭ86x4`H.W9֝L#Y+3/+GrrVD^0w##'!85Kz뷻V֑ ͱWEH|T̆aѫ]DJ o5G8mq.dG+h-ٝJ 9AہKĴz)mul>rbfǷn!'5ŀχOqwp՚\(1>u6 R $ݟf9~iIjԭաZEmh,:.MpawçH I*Ջk|3o@-'cnB [Q.>(OC[go45uˀ.-x+XgOJh!Y)KM{Hf?>sN)~NՕŰJ OYX難6I#}xGRʐF~dfƃ$te9y"8 *ѫ&X<] ])[1˝r5inϾ5Gjz*Q95[w|Kd])i ߗN'lIVUWx-gH:hL Cv7]0 (@ u[[\\֜Y?B"a Ţc{l2Sb!'FcZN"9PlG|~z6@Œ"T`?P X0g+p7;8z")\1$d\+D- Abq:s%[  7`:VQ.^SYZڦenjs3gWԋhQK֟nrtvz+trauV ʊʳ b6d76Ylg6ȓ_t:oөe) yBoM!@i&1FY~/!(~!6Kl,ʧqKJfp\؄~Dy@5V_dO{ߏitg@RV4<{eՋseΗ55B 7ɪteWN9:NV4+cT9VkZARsJEʏ()QeL7Q:.&۪]G`G`(t7^b f`VTxq+{)9}p pc2f y=oФ*U;OeHZ).L& ^V?#J.B7̰$ܨ K@Ͳ%7mTi"S@fwń4u쐇rc1{b=n[~4/N9W4*kyVmK3AgN>WU&򹤜ϡ`O7#I45gASNrc}J..ʔdWx2Dz\,DD'SљtVYm!WuBv9 5BXJRPIkf2v\tP( {q#QoMZs^9ݖԚdSRBS |_v6Æ0"I3G(MN9m]<PWce&<^/=OS6#i߃H =0wdG xA0MgSM'=*?mu@' %fR'Brlfl}~ p!24`γ}]bܼwVtDU \uwoEʹ [%fh̼&fq{P7} ,%X(7?_xbZ-c4AEdžsw+QŢ uę8n1S v98C~5(;⌞<7C(MTS蓻tZ' W(wW@E_ r DU|^^+Vژpdi8e92mOp q^ǷW˥3IȈF lz b_QhR0䳂/n|!9:Ò  NCZ-{ S{5s$|W$7By/j뒴ޚFzե srDME:IZ5-٧{^8O6zLe:[yY]i MǡGb=K3[ݙA; 1ẻuiu.AῊM@.ɃP)⸚R[nՓRvbFʭL ^6s:BA2-n*S鐏OAzjCeKm O88_VR~XvhN VW{ǸuЊ%OyD9Υ[vkem;`O "4,w$=sb}QJmך}xȉP3A;uF߽e̮ w!1"f8 4`S+Aϗ-\PX]^yǨrWʩ1`80h~k$_&JVPVYQ|o6eFcCQMBVP{8]ri+'6aրE{pkJo.<0/Ud}.H}B{lմ/1K ~QNozW0Ye9Sټ[`Kf^X:d'ZƑ?s*gVԏtV UhXAZ^aSD6y)?+N,yNѶRӺ/"77F!?j."7bة+fNi[y_i62N JZZnU֐N9q!0B늢!0B93v5o>+c I7$ߪ2Z:,m~a3#*1s4~NU=c%mPJ <$JY(_f8 LދͤӮ&2s\fj S^2}&^qs6\sSCn 9?P|ۉZE$AR%AWZ">{vPp@dЗG8)%$()^A3?6fPi+?n]*F* (!蒆 YG*bC sʌ ˠBtw=3f [ o<,=DuRqVUo>$CIEį@K''vdoZ{=NZLBO2%=wh+~|>~̯"H"(ڢIo6zS,%t'= 8n W+RenM|nC03x#.qd5}dJwmnebMc隠UG09%GZdj .\ʷ B`7HQM (I~@fT#]J5j* oR)4T#hhMx|>Nd)A@3( [Uzr%)@?ެ}moQD-x/ dzgediP،Uށ, Sԃ!g IGSp0 [J|hWB19h#Uq!H8=y3;8W7eA,_&7Z8i\Dei#y~m^Ҟ@Z /[H,A#k5澳)1*5Wkzd@Hٽ =I ["h?2Xw^kR;ި^JdN"Qx`eKfGCJ|  ]މlgxNvk%·y&NPLDIJSXR$B):J =U .+9( Gl# Nd'?Մ^ag3fv VZ6 bKw_|Y=+b~&ҊrfBPjPR WT{- }D#S _Î\H]d}'NU})ۡ2'm[ci\vĝ]N~BdJ{`M?&)rvjbz2[чU}“(t((%}l2m*u5 ݮ>XCJ<9la$P&Bt#+x|߳蒹q0ͦ3V}G=|m4x|"ͯJg:5F8M[Ua4qANG/dJ}#{ĵsv;>h-Z1Thxxܹ+xWu} SYP֨ۥ.nzA0murߺ4F6?9)?=bOE2䉾xd@G:Zn:0/`驥u\Iԯ^7Zb_BY89T$>{Rh1ǀ%zO/%"Bֲ,0WX&1FXqz),)27Bf`3 jIAT ZcCV>Z%/"p.hrFTcR$@;ͭ0z9t&ِ47ݧ`ܾ\j۷; knrR㤹揷̇WOCa'֠_m,n#bj8e|6HM?\JK7z>'7xr#mbnfDz꼈kmI` KH~D<+tm_zp˞.h /7n{]y]Ƿs }GapXTSȄl}h!2,yFnh㊑E [ͽ{2tz>bak}Ur,6Z %D9 (-<utxghD[= C8紺<3!~[47"új+1~Tsi5]r7'#@ b fcQO,xDT+@S~R}Ot)| yUDyh+ލ21 ;`h,5k//Vm689e3*N*6=+aGtKۯBkP;Sq>JSIqhsUIɳ$?*(Y B890Y{HIon|d HN-k贈b$|n}'h1+k?ӳe(8]U{R|*E'nC*u4+9fQw[W#6#U\/O}Ǩ>p,@/›^T$Q2Hh AB1o woBN)0 d!?nfZ[%`@,5zѳ1L9tW}z&PAy_m<֙6*yx@)໢8`aO{>?7#SwzE<51=,SMtɰ͢ߩ-ws\KH+\ Tbgm!UE_AxcщWL.;*{zgU>Z[{fݚ"(ݘT3בVDCb`sj!ܫuϻX0WڎaN5T*$8`i%-ud/y/{`!Cd!E+lR {dʄ RQ0Diyq?]6FY ~m3)J_8gvV@B1ςL8V~B<جVq9TP~o/%ۍa{/W[-W]-2.NG 0`!OIm΃f@l'u-$"42w'Sta]R.6nTANCQV4F\'xg=):aEeGasU[/ D7Nx0C LY߭ŠDӐ$ oD%gв S-!!o9O#ڱEZMd\DKi%g6_]VYY΃*6ՕyҜ1t&xNsB"xϼf`ܒ- /*tơ67WuZWɭ}QYu6P9b-(40)n_r^K~ ZSxb^Ő1M?iS,ڷѓܮaX€u7sԣ&y}mh#G}QyE6 Ɏe֌4+Vz !{bxzs!i$KcCW86ymb9%Zzj@S PNP)o[Nį˵8bn <6| G{s>|Upc^u5sܓ肦wfPs{"M `?< _F?;#)N KŗvS_ʡ`*:p1k~)vW I1/ ߾:* _g[lш[`cXO?̵+k4+0wnuc7>jϫީ&IPCDѯl„7}S]A'-b1]k__'p".kh!I )qTbcUt4诀XvYY0 Ir~^U(! !Q%Old4y<9ݰԀ&s^xaJ N0zŨzX J%(>P+ LҸD&=3\h=f3&җ^u>S1nbcwfz]bL$Z݉bяӝk5"L`2#h.L S UoxVx2vBh} >_Ɏ564lr;%퉷80X-9\wK\=fEPs,čy9;ZVvo1XtFZ2:`xXٲ/kz^%D֡L0@nmlFR!7K|5Ymz e!J5HUC hoj|u}5๖?2L+G%c TU9n)99"e>GR)Bm_F')Ą%ѱ O!qч7Ǚ@[= {e1h<5cAVM՞xĊrѽ>˜[SF~IbsV'/LŊld2o7gjR-Τ P`b< Y!dZ%4SO9N-gm #kOT* $8kQQoh7Vl6ݷ;QOQݶi` ckfg,b vZK)lrCqV$r"4_6ZY4z>j8FwHkg]Vh0\90=C-5R-,Bw [j|bGlzdaDg7M4o<|gf8--*`.ar;ʞu7QF DDuٱ QGAL{5|&mqHe grZ{6'r켍jGPm(gҿDٟ\cQ WBJڪOhw -œ.k<*XBZc)Sbm϶SD$(p;Ba\4[ "ȺV'K~ 7'餋3,ˮQv{6S9@*J]և_AhJ/[~;]k%;&\N/Mt&"w!zشk #>NN2lB\;g\(<#SU 1ֵrwy=G̍GsgB!r!|I N]8Q8YF{I9TʽԦ=Kt*ڀ5GtXRɽlwkn{xޓ?B:o6U؍CAG \|#6m:jg;-լ*nbȰ'aZ믁tdZ[C)yW9qrQ NYѱT-z _0[ӓ%897ЉwJ?c<)/ dTSK9=ui |w)uw z} k c]|qcQԽk/˓Fg-ڄTkOffd~_UO9KuKZ@3kYS}wgi()XtЕ%,>YOA ;/Rp}b*1p{~ɡ[LvjY5uVɮ+À ݄k\],@mٴWiR !DGqu߬֞A#ăHmJCC%*j f^ƛMuzM>RՃ`ZRV熰X I(U8[|eQ.n_RU`"`;a %@eG:E@ 5P}#0l#$mCm/Fp^gi&O~qkz\mѥP#zw$~*Eb [n|߰K*Vcp1Y?g8 .,o$* P]@iq{4>u(;+=uZB}}G$'W}=l4 E!DlNǻTX Kth.ZB^DKoYu ~d.]茖¨9B~X!|ۧ `I/\͠uO3!-r"+:.$a>ȼ9JG!gJ>}5. Pk6aj/u`epNJĩ}jL&ݐUUMl3+3XC| ȺFKr܆0viEP^.ϢA3jPAgEcp" x=e:cy2F.1\*89Us+ij2GZRcC L@"C=toD;!bWB8TO9\.NvYp,c'ǭҼl1 /S{ڝ(2X)[6 3ʰ>~d9"H+ɟԼsrWh'Z^0[ `́P2;)Fȗ=s.0W ޥҵ3!. `Qy[ l 粄;P JXd:ND$=o/ kbF[@}tq0>Ϣk7AiNd;&;Cb5CPiA3 6zNAJ6A-E $#)Il_5~şJQiX l_5Mˠo)e :@ /+U"[l~8S(*+rݦGksg4 1k5w9z8%2Q~p:F%W214H/ֵ>y{TJ$؅$hM\pRͻ:/Z..1{Bn_a~;,X~:can |Юυn"=mdA G5C9e`k.W&Y_~6/Ȥa`3rԼ9VMiM4|-_d*{ƫ݈ɌA{B!@Vg,7bжjX¸JM LRcI $\Sy zc]KgQ[a Ôcyr@1sFl&eDg%5U.469U(#Nr!@K84tJE, XT9ؖVD2=J^୬mFOC`7Z 'u2 ۙL:ۨb֊}paУwAޱ+S`|&M6?0_j\S1q¶=cxiTg'7NΑB@e}LBheQ̮o5x]7HRN1ZӄϥZͺ¢U6 '8}=GY1QH6뫛apĥWSzv^JR(#8,x9 zՓ`x=FRMkbiD]7>(xPV fAg`#! UbK#g8ۻ /3Kv{{P#3d8"|>'/ɽ?@ey=sG0[|Ck6ZR7l/kvQcʮt+%) ϩ dщuufIj@-&0Ü?9),25A+&MW}`p"Oj:f+M7Qlxqy@cS0EYhd[NmAk|%~GL .pfO"䲓Po"*{32jd0ЦB3X8Nҁ#[G=0ԅK#=>sE;ߖq$-x{ޠ\a;%t,sP'S|>?q# P ^e~V4nSGjڷ{;y>}lχ_SWǨ v_Sr\2]:jŤL(yL. ;+~Y'<*cOfsvM5ym1X`-t- b!) /jN8N_]{(a/Z1UM@VUN2z竈O)(|M,x&sB,8w a䛗Y:Wt1v8ngjM Dd0_9ڙ4lI')|YVEu,59q7Nˀ~g؉#$\2LNgP3Xj bO1]E /z{ y y 1zfTh0Wet%KZ۠@nLEar F ג4ˀ  &lQ̣YZ$^ 4/ZE޹ptz[x"Qr`#؃OBV`KNXӜ oOk` 7 6`2BNm$ R0z Φ]r`ʉ]]4{j]g7~йA s}Eb`8goUO䟪f_ !>^Mhw~g !Cnu- k;;Fp0Ժs N-g6SrrVX} R|M7^8,nٸτq{*#'qgg~y3|2J؋8F۟ >қK#;̫~èZhS1C(Bs>Ǻ^bnxir#@{0vwI x'<<Ę늬~b}!CӴP! eq}ވ|wh6[ [~=/t)ƈJ8Wx?B6fl4ی h[ы+vȱ1L@y_7B{dߖku<LJLڽcm fsԬ87c0I9]+ͣ}%^= 7rYi\?|Ti^kO}{M=3dcA,fr77Xx@)>.H96{4u[T BgBLcUpOE fԟzg mUUO/>3r5 oS$_8uT45sٗN6a҆aD~MgOn&,V[_',:L"=p##2` T^-'NǘXe 9"`Uf!Y9 ѿ-%߽GwW.kGɜ=Ѽ2N'ΣnħRT&"M@2S7Pa,bGAd!ӎ^FHU4?7v4q5H@b *i.wL9+qߋkӲAJz1!-Ո~ P6 w%uB{Q ܈j$˛$".odoг3y6rSqjysOAIK]&UU$K]ٚ`V+6٨tZw p:+1VF~dm(4\F{YEjbY]"[r09]!+)KJXd;#u\ӟYݸH oHXfBɱFvmٕD9-:{{QfRS<01aH `h0 Oc E#a5p\^_SJvզvwv`G#-@w |dʼn# KA%\Mi,w? 1 7R#r1BՙxaM _ka;m~P\ 4:'ڐ|q'IbɺHoT !2HuW ܚ) >F"ne`MaґF e#N|G0}bgt ds=t  VcOwUɵQʨp"2`7a^Rfǃr_z"Δ[T鏰Uq,3N4i<ሰ*P8UsCėVRH `7|(*js;aψ7ֵZ]dR~*0y\G~Zw\PnbF~~#l}~Յa1 E^lĠ̞Ƌ{izCaA : z_-;Gj Q{#RfcH,|s&1:)iNhR wtqhع.|c`UF !2#;Ҫ X?wb~̼Yq5sMВ_dMXQ]x=ڱ̱#[%&S5[B@{coop /gD3XM:V>uݛ'5%"o?Rj˦y t/<'xjrH ?_r g[a0etJ:=]hՌG\- *3c5(lr]_ECtOP_)4w i캼u*3ezd6>frl􎰀katrUvTzXֆ" %L3Jȍ cC~KC5`M; q> M\W9hKvO٫(E2;c/`ȋpMKoa#hr4l꼱/ÇZh=(_ &gÔ,_Cv׷+M`:c1?[T6\BΖ U@;)ˋtR휤xIu\;n J6)T26~])@6 UO}[="ZßHb^ʏfǿ<Khxtm\r12}9QٿR0%G 4V=9*3-zV3jy: ׵qGd9FIU_kSDɲI\Woٶb|ŎiXe/|3=:nL6INyA^}'2Ԟx#F/'>u0x'\• ʇK~֝ +LСQ96n7>w~uVl+ Һ,jj^4(d=@|R.!J @Ini3W' L":!sЪhBƓ̜VELzgd] :m л1;¶QDwAh| _Rueqxfز= &3 }h$sC4 wRQ$jNj278CBxj-jM3ȵ|`_Z'8+z`xNT=[=>}"b>SՍJ8Ӄ] sڊn1.{DҲ׃ {kR"YlO u  :fpP^xao Ξ Sen_Vx8 2}R>琥sEIFDx.Y)"o0VOo:bNqtH$;lV\em4^N]<`B``%)&Zh.Mq|`82a:0LZ9X4S;[Gx"]6/{k!sC\y\K`.юOPGDq3BVʴ-:iR셂aɗ(3Jc0 ~bgv0h0i VZ͚([In} o9/97&~#5Ǚ4r4KƗ" ,pNCvd !ZD H'xm8P/R>-eҵ5/RQvu˗fxɁPЧ d`C̵"\+h@.:N$ EQjB$W}bA&t$Fr|W=8tk뛘HZ9DuУ %9nEF'PGwL>LN'*</F^I jG~I"F"hJjaq+GnJȔ5d6|pUW0P0C@KOyqL#Zh,sO qLۄFE7H7Z8Ңl02^j1uJ 7]dt `W&vgB sv+pouOw}*qhY#-Cy̾M'?t(oiGlM:j8d ~|qg@,Pry,N \>aRfV5ĽE_o ֖e\jz>A'Al r'r~<'1mi-/Sb[TZlNJ,e2K}_"wr#b9]HlQ@5CU`t߉GiR1oEԵȒ%$YοI}[uՄHe7l.‹\@ -*e+`ƔL<4k(bgXuI1]0Hg-J@A>}AvF!b1!9eOe~>q|Uv醵Q&+OcHf܆gf-X<_8DЈ{q/h_ɣYdU~rC@} .TpnO̷w#'Ry%<&2 ɲWf p* w4tm튅E}_ U_s1K"JZ+3GTKVH 3~Y$VqG X:eA_{,U"sS6ߋJSF,01K23 5#yI ?qR:/o]"9ӯ 0ͨnˣvzjp{ 4,?[?Ս )Ķc{9zu` uH$70'4Eakꮲs*AգI#Rǔ>邉榋_*5HPJ: sJBoi 'KklU& {Oӝ-7im޸3/l~ 0U: =R+A%Cn .6?3N3ڈ}b.c^&ضFĬbyx4RG#C}NiYk*&$ηQF!/1mn~[ʷ~!ȁd}* Gf/*Pfm}|(;zQD̉lٽܤ;g;B>@|<+ٵƎ#%#y(r49ȳYRHt[3rZ1~}G& 3$ LV=Fs ':A[oDj- ^NYj&9>2~)M/hg︻3tJW2t8S2&d^Ǚ=b^MrK*2A]EkԳOև<Hj=\+^BfM%\C@ASOCo hF}Ȯ6נٶD.`e_nbpl?%!Pdh " hh}8*XgI=gDlV ~8Qהfx`?-?P턝&'7 laRk[ d^JqjES1"Ŕ/ qG_[_4$ĐJEn!Yl p|vJf H16uIbnpQFz0EC6} Drfyo}LlF/]gI<I%sg+$ljXsI[̥<"7Nt"%bLQhm<0f[\h ct-pV ҋ M5ND9 dLٌ0Z 8]NF})HVuw!̟FO˅_)#m ,/iѯ+ !oH 󜂞5ٽ?9ɨgΕOu1 q47&U>rq$4U'r[o_ܥj+$̤|mQ4 nlHGau TW_%g?T}T=Y!=G?I̬kTԇ\6, 6s38#nOE Jhם3R!0<#?3_No4#y kF&]h MAw}lxMp=|;t}OKUZu ccL/Ct Re N6`7z4aq 0%QT6en>#' 9YïL|΃]}<0 phJ^_^t Gu X2k׻> ; t[l0ꛟeP9o] &B0H 7&zV! G)y ϺA tHLܟsY:@qz5RBm걿w^d$J=k<”ӖǶ 3"{;v_8 3O(j%f87rclk}xSJk5a)8 퉒h_I\K:*f}2$eZ[g !JVLJw&>N$ԥTpvLz$җؘرɝqܻ%'9|ؑUg=Cn$|B)_ hz˹( +7j{qLȯW+/sL\aCn:9Mk:8OFѬ6$rOI7/S<=I ο}4%: )lN:qv$b'"u2i,"urx_|{c:ς 6an͹UNqSr&B&-:`E=vCÐ=.|6)X u{J)7DxU/LmܻXæ~+>’+Ω}an' s̖g0;eXUב,i,/C_$ IKwu,ZUOHġh<@oϛp/Q!0n ڢנIIlFٌ:q<SW)@Xr:cs]>w7 x1>HRW&%3jVF'1{Mkn<]ZCga-^ÊCK[C k7ǂȊY>׭$qiWNqIﶤ+̜T56gS }cl>eV Rc~ T“b@YFgߣ,&- ]ʓkwe "z煨I G|K]E7A;rSW,ϨHOG[_s\ iy> <{J\a:M#w=Du]*-{UHB*no$~Ckŋ@e9P8͠Cv<ĉ{fdFSht=ݾf4m1C%Rð#ݿ`v,Pc!8zT\@Y g'(f dN}ΐ', UVGퟗhDSַ/-^guŇ Nou62Vs1>U`e{6$O'ZxIi: J%??M#ӄ dCD T`PLJYc91 zw_ޝ%SA@p}i(هWd<.zIVx;SZ[7Hm!ޔ&"Z& ;Czoc,|ӵ}^*!:0{Hv&c=촶ޯ/ns.,n|G96GL*6qt=oa.#(tjA ~6<%ůQ$ F.kuhh-VH1M$VW~&Ţ==<(9KcجO)tyE\SE [[Af-h1= KOML1jiQ:tAOlSϣs$ :,KjZAA<q Ԋd&9{pr&U"]I-2,3t8;L-tԫK<jApnK~ -(c0GzZk;=j,p^U>J׭)U JJeJUV+L 'CZ\uѻN\.UH Ģ<*(V56H BtNt:B:. $݀I+NMaQ ,+vQ]>GLIg`M4㞢ȪZ OjJRGc*<vB 6Җ~5}vpEw+D~7 鄓9kl_|%VD:Wnmӯlۛ;iu" I-N[)K @G x yX6Y-{sײ \2_~eMmɕUc&%`ܖ{qˉ|#?*;Xq.$M^ Pb&=S:C>+nG,Qg_IN+! 1x`&wm6̘>,),֎m=OMq_u(1-yu3\N 7ua:'ݜP`:: jEw d_,F"Ȇ^iҷT#\3Ps"+ba~rRO*SAcCXnOK_DxkCt69Tu1^2gy9V fMjN3wrٲB܅Fr+zvg^+|Z%G~QB4r@1Ml<[XyTc{c Iи6=GXhNӎҳ`뛏nCrTƘuJ4?cR(1tm~HΡ6J\!7#{ d4G;3Gy^yqr [Pf 2a>Oɺt9 pU٫\k֤EٯK/iYop؎L13F% uJiOWte* s| 6 ] 7<{Pu7Wm@Q-7}"3T3fWf7(M`%dl8ڶ__`(k(V}W+&d#k{p=1 sU~q~,8 *K! Jq} y:szu$>{ !MԒv*)A>?î8Du߆kp/ 6_]DO\¾vlر, Cje@Nv0PT1!cdo<ɫWk"4EOBQϏe$~ =7.H@E=,i0yl|joZY6Eg=Cz i/8^(D:Xipg &X@U-]Op<\ZGJɰg}o!zˮbBo05I&Ȱ)ƕִ8pݑtL{OR|ۍT0&%57櫮hZ9B]ʤ+ U4ZPzV`&.EQtI2* F7[c&G@@gh&v 2;|t:N!B腙+>|hX32OkGy[P>X|~_Kk7o>v3'A(@z'(n`n{lﯞ%ɑFp'n{bzN+Ƨ 7mrI Y#P\ .Y6-4J\:!H?]H tfsu9~g KqyB$ۏ~EU4NZ؟~^!& MS:u]3iSK)>BQ~ S&?M"ٖ=3QY t1HU&ο ذͮd[ T#AAQ+K-MbC[,5DTDJ%sكEft|bi7Ub&0+K|kҦ@ֹY @WMcA[eso 흊r7ʸǢ9K̕;oʳ@}~V3ڡu"CĆx%Bb]o0Tm-OMs~%>bX;_2SIS5RĜ<,D̸hAXx=ZfU!ԇV>AM LgayBm\,*ҕNVG$u[ڳ7ႀv`̟B_l_YǕZI-r HtM{@߬tx]BsVr*I3@0<؋HF}d$0;`XJŘH5ʹW7":}t4W_ $%U8Xaȏ.֣D5*28{\i3C&XzGOFlqN+"N,]DCN lٮ޻j"7NlzDbBDTZ)$ӌojx-f>99 :zr5m!k*. %p)|rP$Upi,W#BU6(L\$mT1r ΑAYuU>ijSʨ cӹ;v6 xhgݖ9 IsƵsRlĿ-p?)=]xG*#ҁب gQ7tRX9*X| {HFC.GYu̢2]+R"a@-Dȏuh-PޜC}JEw88 AufC鿺Ȱos, ׿m)M؞=ІQ!_ԯc'QD\zA.C'sE/h*f#6>ݔKk P9M͠!$4C$ɕ!~+fЯU5U2!"gZr[0tI*bD-PenݳL"tK~l#* AwW yVn'9j8~uamh,C-Cg]c<qur·[yG<̩)?0M@]q{ͫwTן:SgH)r 0ˠ'p3*5??HvI׀A:~ #&_`PP[W|1x4MfK חiU7)4yߛl,>ab"'tb%\PNL;[V8# *b|F, C&FP.$6"MGsJkhA.om6_ڼVti ȬFǵ);*kCZً='K"2&!3H⟱^ O-z.W%`7}1;B0RG%V ˄*id,ԍx;;YgT'xD)Dƨw^}d鄙þ'UdaSMz$&{;yd]2O`A?uA,F/3p%N\<0í*fi-3KeY@Id$NOu`'kvw.A_ko5\$Wspj`$#adYset43Y]b-l ?›Śt' 3)C?|J8 @H$E>]`zw"ƮM:1Oit"!XY(FêTTD q;)}d GѻR)z|;ݐ`]7{0h<=cu06apb$z!t(VM,g<ͳ|JgRbPq.}>Y5G{ צrJ3neQf)j=6gZ!uX,r2 FˠiZE|%v&;E™:'3y[o}[~_Gco v)H"l%D7)Nz.9(vTU`tF#ů 'iݰS,,+d.?B4MU7Ǎ@Jb?Wl=C쪰cteRGyMYa7+?%%4{gyh[ %w#qB~UG*F J ӺS$uZP |m*:pdhd"7PLp|b!92 '͋TjQ 迪31K>Kr{(.}{_)[-C/'~VtLJS(kaڱ |WJ|y DA=v/P^DdecS[dYZpoꇅG]y嗾Lo_VԐUh7<2T/SϕtLjCҤbO=4a o رc5!/ԟ (dK##_>4S6.Ԡ :q9VDvCv͇|ӈ/*zM:"g5KfN <>HD|y Ja;!k<.*ZgjWjU"%d ZIǺ j^397 U-kK.Gp,k^{ Iʙkbz #`ےJ_)*;F,uqoM4%DmDGD#(wOƥt;Sx*&(r켂I:~۵~9HbW-C(^tñW(|+1ŧzG f Y:QX/wBvGMG;{mQQGe^ѹ_g˯+H { Iy\&xRSf[Z;-Z旰_^}тMsϰB| [ÊT1c/p2kW1$px&Grr R[Ž @T,E[\_9%#n)9Z2,a@mI 7JE]~#/9WqB/s#ࠥ{R-&e. \Y-{9%chY Pi#>JYx17?9=?2KG"7p\*iNcR":34\9Wol qZ&OhWP m'ݰgf vq<9=4'b'HSJiƂb[nhr4M aZ7!Țs5BOSAQh*I )@wn,F1M{5G,Pf{Pud%A`q> yݰKeL*~ QTOz>{.~B;fhGQ|yP[!f-s EDT5&3L0կȲy|_iaۧ-]E#W]ַ{`U?ȩ$ 2<Bd'$u!9G"Pyx5Ug\1Hb!dnj3p*$ft:_g*kXc*Iesv_r0>DgJpHt(e_ϗI8MhU:0:=v;''y S'xTnyҏK[a&0ߗ2Zȃ~s<՘cȿ(8 N$ld8=u ;IYeTMe2#m9w(0}F֠АB RYhȓ9yv\@N.T^$XD<1ohn]23uq:Iҋ\-$hEZ,X/Fa+Dblj2WAUc\zTk>E3 ML6񓶟ۥ8zQuG]kjBl ,q ='Z%%44\T #%}|械sxheieSa͚a'B )t~M6U8 I:l-MJXOiMT7VShPp UjĘd6vr\mÚhyE$@.Ү?g]4 cYe zTd|38HEF=b,sxg 2G|ʢir{ۅ Ӆ/s}qLm8Al(u l {lD-uꀓ3(IXm5zʯzCM' W^S. *K7!mӆlU$RWV&o }ޮ~B<ĹHp#TeWr@:\$s2*D`F i7y%7KjCg_+r\gΩigMKIHJ%IY 7j,9:r1x/ G;syLݥ5k|FߧNjk#1 [zc"ʜZlTQ'R+W .h-'5PEt.J3_i2CimTANnqZG/R06DV,f*Alj0LRA;JQyw2ߥSun1GoNO֮# _NH6VM4F,_ w ?*4Godu ׍ތt LB?.{2䨐rv,ƛ{39r" 0gd&o$8:y׉4Īfa/̳8O^y{ܱl֣8x?ZJܞm&WX幨Qp e@ GZ,;znj/yi$@i4$'=oK_ 7ͳØlkMSoAAci_ΐDl\9,*$v`ӭ"f(vb"D󼁟UT6 &=]Cˬ?'ۨ43[%m7i.+At< go"o',،=T8_ߠ_+}> 92F WGH ̢G|Oo*MHC)n 䭻(Ug:\YH i2ZNVWdQU{JZvNꀭ4t S ޘ6~ ^`cvog9Cqu gH"2ZwDoIJ #һNE0i)QH7:[H Z 8a90e- ͓יr[q +8Qq fA?u}g@1iy|t,Eq(W[cA&d})PT~!ug/lzh{ 3B0TT߽?/z"y\v񀅢j{[h@_9 I24d?iеv*1Iq4IYv⻅ ç-4X&u<%s5S00{D7p!AG/JvnI׫I RTUxw移sZG0;nA9[[G`e.<`h4@3i՘C!&P0^S8\IkKv$nl{ou*3M Imw/Q^ٮ8[\8:<\Ok%HŲ=+b㊰7UBB@ރy܏AITwת鱦>K6YEXe3 Mٳ+-j*JN^GP,\4kꤠFf%Nzo2.~~#l Vr;e1S1- *nlk >O]WkrM[ qi̷hFr$:c:Eqq$-z0|H '&[0lō(F(|,߀Dκ+[Ǐߊvɤ)B#:.{Y/P.Jn#(ID0KCKrf9R13iqC{ 3S)6lfꡊJkIꌮ.Q*%6F <k+O1WWl>m!&)+sG ~wRE=z(*g/k?ʍ6Zd8[_G%t̆P)h#/쭞j lrtlyz”o $ ATח PRAߠ:(<[6 ¬`uu?|%9iP"LZcm‡9Ѕ̃h8#B 1bMJ n`悘juRg7ѢT^c5ї2COlTxn(Mj)&G.Ryw#q3dE0dz`%:GBiDt6E]2طpu Y!FLfgwo?ʾ"$-mhyLV)c#TF&6 N I t izOCPWlj3e:Z|GSz804Ǟ L6_Yp'4iӈ2zNVzBh;lsɏAfyJK)&RjDbV [9ގ٢xU??MޯE9%!C#9F[ 4Z*R4,9`whe:28BQMhFD ~ ɶSI),n3ۂ S$jGW+s&,~E,5CZr|('P#-uA)Bp!;r<83Vиx["dZ/"Sw`ȚLE7#W1C̷qXr pgOTȾ^CofLbH,+Uȋ`@"C>\8*A\"Iu>ȞNUfcA YȤhC@nȫg)wPȒa~pHFg=c6G靬\bCZD8?3Z:b5KBn^mWtQ_VJ;koy 3̷=g3RyIZj,i1^fL>C@Pe+$Q6A0UR{[@@i.Rr}Cry@^^?1vټdSq`/=̎Ch*{*I=  ac[l/ /iToE.a kP`ugX>Y!3j[fTZ,!ޯھ=m rgsSEorpqXm?ڃ{3l:FK_:8_fl:U@(VYP!U3յx_q6ۧN9!Гv(yV8Eة|T(h2ΚE6ݙ9އ<-C,ofwPo>Jay_XBhsN '4w"$vQ> oU5=0<-haް>9Al9b Z7<"2|֭!Vȗg( fWΞŋ7Ģ@4{i[%EAV)g?<..VtQ68s)E{D,UJ'MK&sKo`r_ﴍ{ە70bɬ(3>7qo_j+GDxlrK\ ,fa~;"hPhYl5=_1 ,Gog$)1Euźyg)1qjgoIRB=V@C͒b˥ N\^԰K"Mf1xOgصcК@o ȆjK1mWk]rC$v8ҽmS}ʸi@+c_yӤf΀照ǂzlb6h@c/xp}a+f8]]"Q l7eoOߢCHBOZ=[A\bbكH493D|9qr('x8b q*MaY LmiwĠ sK#&1EP 4tfl8M!\b\QwtN\Tftf6eG/pJHGo)*ʢqI tXcSܠdӜ&4@e3aG9x&AsRRΏo@w,/u0fEG ewԉ&eSŧ*H=:9ȣ+ȴ=HV7䥷q |~/&tvf 8 Ȣtu걒BȆg1 Y;}R s&pSg` O C&t P3R^5C˚^PK*>Pw]*Ǘ;pYm!][d|IT%$f7j]t"D u.OXm[V=tۨۋ>OꘆG.:O\vg/@P{Og<Õmb*; +xEޮ\)Fev-Rd9IT<;ڰQɮ(@;Ď//0As樼t0=m`R}PV\nmB8Vr-uaז|+v yhw2Qh &tBl \ORMd=Q|dl 6/Dz-4vVЛƤ}1Bb}Ap b:*xdS~ˆa~f0ګ0E<={ zĞ.[]9ݻͽh\Yඩ g>yjz YU£q $CM"P~_EaWjz@傒SnFw]1KNg85LgInY k2n77E_7)a).l "%YCc<CAǦⴡ 6n9嗍W  WQi/w-+Ĝ3K4|B*= VsZh,?zN f-rLޅ'9q 5Ųt^3<Ɣl86Wr;(;;-:ą;/:'lPp\Ԣ&hâ h=#'".oQ5ր 2/) Ȥ 4$~0#{1\%}GmCʵO7o)Nzƹ"$ Ì} nhkQf2GQ/h^v nǰsƋ6:4H 밢dα̲=7q"Zc^0VO+xY;`4{ fỹg M#FEk=eԹ :HrgA 7:xH\BS`[q* ;qDPHʀ8 jxP2̸knU0┩VNt:BwW]ҧ \:΁ImJGgMs۶9~2)C|y[5]|&r U<~ 5{* ƚ`{v10J*w){O&1(Bd)~t<7zko#@ov5:/%+l?GUf`.'Bp[ĭ k[njU5W@CnaɊ!{ph*ߞeZ>saMܒp묄PƂo s_@[$P w;AR45T8pJ@F_ѐd C,7sb(>QFje9G7 W~0Bo7G yɫ܁i]u<0Y ABɲY#$Z4Ӣ IWPr(ykF`0t0pҾsث830NR̿|e"NovB_1R@NU¾uU7bw'fnAz e`d;>_p=kaMXUR8U0߹| J ]bUl-OڱY@ob)GfXy5?]ff{+bsHǏdlz,)=i,/KS0OB]8.ǽ8oZ"=&T< :WR4baKw:[SV\(1A^K!?]@sƟn0#v2y( pJ&GK 4A{/@zώӃ<5dѹR\o`RSb93ˆ.[ae>̟s]VN%,VА9wJׁĎ?$Vj`ZQ{LO ͈oiBq>&o\0eͯ'H쓋iM=o,ȲƀIJ!P3f,zro**|soUgKG,Z`p iՇukW̥m)DEsK~!or]^A{'.qJh0Ř, ^{};U4  l^] ԗU3W m1bI%$/GJ Cg7g , -(<:2 _>(f* ~HqxAuA`$kH4|_GƼcA!2Wn9*Ox!r5+}` @D&VzORFQ&(DKTc&':~#t/y T8P\5FKLsL =؋2Z*$0(K:r =~.witJWm$ɝ1_F*+@0[f;̺"eI:r' ۙrCjIOzhh R5"{AmRl_{ƝLH<(6' `z^&Z/סM" ˥ˣ@f[("Tm =ܰ%(A.g[,!w߿8r9&hB0z}TSL6+U# 2>OyEZʣҥL:㝙 J%P˃ELWwK5ˍ]h+Xܣ}$FNq/XۋSə3,]gjZ,3 g~jJNewy`f}hiɲt`#Q_-g xHBeA}Цu۠dVePĶ(V-_#eg9wiZ}la\LS" CdOR7k`:95rI%.J1ڥ !Hi=}EcNg`-)@ #˄vUF1v!n6ڜ.U384zg#Fމ zAzBiU&Rn^ɉ<$OȰlBGm(^Ԕ{Y'7([W"U{` Y!Q$ DY$kXf4qErds7`!޴Ccz]X9qAE{JOI(i7WJ),@j*3)r=8h 4E.錶2u49NUQ!LDma_c7zG^nlgV$l^' \a@%qDvZ{gS?1㗲"aDYEnTT5= M?Yh#Po=Ovyr,Xk|Ko氜f)؆`: \`oe$~O`[bƅT1 ̙LF4w+b%-kO Vr 1tmv?6OG;·͔ XDcǻ"#4J2VT{aC睲FKZ$R HScE@UηKMVpT-LToi)Q뽃@vr;\tGcfqANO5ֵ1A]y@pi-|B뚎^hZ!nׇMHm{ԣ鱽JĴY !3 ͒H,Rb 6nZ9rɞKj6-[Rcϐ B$,KڈgA Ϻ%\7Jt'/oh &,RV3mՓGo$[+wp9{"UEs^8K 0jc~R^IBQqCM/ U5~GjxV `,~ݞ$-ɮ6Z?P2n9-&f#y8v)t:+X&0ێc"/Pސ?gn̋AKO|@4\pYG룓>Y}m U3E_4C Ȣ'Zhn,8FPȝȡ+rM_~u5b .\SW?Vp_{ilay:9Zk&xx^w0g9Ba޻Wr>1Bl)A/M>O ieOvG׷AD 멩U|ͥp,:4j䢑bpZxC# BͳnpHj>@>'?Ƴ6d&6֭b6giLn܃OvY**h?AB{ Ѹ`R^&)w "]7%)EVecpbbTmܦ|#&0svy%$8,ƾZ?wڌRoi']) o^$ujxǦ/Yhk<'QG[+@{\2DM(09[8#"Qq5(s d_7&.e%KiI4HPkg尋l9Hş#@?J vW,8*?\|ET>,puU g`jT?4T3ӛdFrIe5<8ūsLVM1f:GKMA|ףf lz @ g}ǐy+y@ {R9z \*KJz?tO9y6Oop!ؿuExĢndpY[}¢:\[$ 򕇣:m`Dhw 8G*Qj d^xDrxBn;0̼h R22EhE(LH|d3T?d =fHFa?LqVVp@N c1;~1x34O(ҧdy6ƨSVJd2熉nl4`{K?Y050rͣW23C {%!bR"]BoClMxrߦ5UU|SLT '$>X6qjr!޵Y MWg {D{1>" `.tyirkA_#<m%*#0wM-6ŀti[\^ ǒ0ltW9ЯU%OQ-Ξ8 ͠s.\m{!ft։NX#ςWIcCAШ0v8`b;'?,$x؝L= ;iW p])26ܗ2oy$t#()?x _>8#Fykkev`YfbsiU>IT]6u= b=;IT9PΡ|Epg9Y['E, bo^SnreChyG[@>OH' _P4gviPRsP6m{-cIJC@]_"(S`_UBWY?⦍k[)MAo .5BwaC-5~MBUTߞ$C/RFGdL-ЪD"J_ BK6k|^h6Z)"]x~<N אַ)JeJ:kw]DƇ( M k1SG@oS@Y 'ގ]ϕtA(oY<dg.3T/]?䤇O@?}8GOJ(ZCNhW螸E3tR.avNɛ5#6t-t&Jv~>`|+7⧷-i3ٲ*W"ծ*.Z'=];e!JL0b&V[.<$F <|B;^{ȋk)2l N-~ r|.*UF͐ G4U~2ՏZ*жikgElaLLҢRDAKOh63.|aqo/Bw[z-tچ-yB[5'd'5 n(}8}5T\>8F}F|ER6C :s"eB/`B~`~i%An1l# tB2P>]|1$Gd8%+„5PqNĊx״t-luŀ2Oc/xT+%Ͳ΢EL4RKZDm&#cn"w;6XwRd+К(s8N2N ɝOLLxzQ2žRc1:*i:$:AEpD7[V,g~f9~,M'B4pd:ȕ,`!N8Z宆mdЗ`)t`šxO9nN$:Βe6_F Rx )#r"$Nz]A`݄ :۞f=zw EDץRxe4l~ o2w4TGHM#C q tO+Ͻ>u;q ,zzk ʁN qNA Ha;}[|0[2Vթ|<]u+4e` ǭ;*=RA2QWk-9;ܔ/0rqsj vBsfy>}5xN28Cdt ϭfUdy;"sX@RhIj$f 6[` gc%V5,`w2lp+}=hbW9pM4ȗ?K!ʐjT؛ INN~ (2~\*2].2VsA,+T+MND'ӝՙ%em+HpY| 3^ BB.Q  f}x|7 4G%xKK]#>cxG,5[sE Qr3ɓ=$p4 jkom9شu!^ABe<jb FH|TnoIAu𶿼yl5zAAέF &} ?!ouYԭh/?e /ӔjW5*zr#MiMM6Akdŝ@. t\ gW}s@reO3dGLFؓ COy<>ΔDz RCy=R=xU_Nv9suN? $6sVL4s5OX ثMk\H.vt/YvS\}꫖m_Ĥwz9<X]1QY NtRo_}^klי%{[U6v\]-,u+jkoy*1(Wu]-K- &YV3 d}K/q2j-M/}CL},Z6z RT1J t1 ,,aWJp{:.TDIK9 34jꩶ1 hJb?nDO5tˀFՔG_˞)dۘNW3 $|A~*x uK4^*ɟcK|G_pmc8Lw;aIˣK4xUO?|?RlH0~OR:5-$d@ܯUF#u.x#uw~P?Tx[Q ]D iU~ 7$:,(nX@ )9*Wv\3ZCGT#{;duhb'9HH<j@j5Y?z6BOWnc"sg'ÕrN /1ȟG䂎~Rk2:͓Kdu+3PCK_ B EϘ¾`ܡ"$^QjV!5&MX7n>}ߩ<3zM7W-CNkV| `UQ cp=꤈7J.#5bwYdz0nN^%=nh" +7d{]]WtIc}?(~OTBO@t|85˰Ԋ}Þˎ(='}7,]ˢt6Zۤƪg@O8%D>>=M!~Zlrwgz9(,ۑѹVaIfIK4ZL 5FO'1$0U] D18ؾs0VK^ٕ?l0m¾QZ!84k8Ofȭr엸 #SBVٟ48`?ՃcQ]cPwrcb݀v.eऊ ߩ7Tq<)xW>j<z4&tQDy;VhKU7ibaLSLIM4QUdWaD9\.0_d(&asÚ?V$.\KQ nCxÈ"[ʯ/,Z:D㟁|gjg ssb[XQvѾt!T9}^Jl)@$6?u} Tiv>䯯 L,^3h{[yQܠm9-`8C _CRt"cMO¾vTTAGgeb4խx i7ȢVӲŮ[ОW2_A z`f? "M/y-EF -mYag#& HS7բS]x-!"H2to;zNgSRY^"u z,5MgIϼSO%Kp3K=pNP$+f<YUTN QaYb4Xo)W=f8jUkyZV3N't{cls.HlޤTs gG1u z;ϧ]itfT3>G} !v!5ߩPn)`y}*{gBjlU_&J"r ˝$ЮտէMS0g%_/gHТiEKL7[CJ*c~7Q^VW`3;( '`b6Vby2f+?rai'o U?:S#r[$l1t k^ri ;W [V;xI <#w-UHD{BtjU*RIEuճ_?+C[ 'jZ%dʼnK#IKH.[݂B,KM0J>œ@LL>[k܄7`1eL*1T=RЫ z$́Ã}`Wd+j-`g%"_շjR}`MkA.ŎC \.km2ciWۉ%Q#םWC-i,m& G}.xdD\XۖXI+R0ǜ~y7Sq\DpEYl5Rk\#Gj,A 59zGxvS"i$vaLaQ[rU}`O*>hHABM&1%FboRbX2EZM6f?|Ǧž?%ȉw'@.)xIb0lr0LƇa `=5r$Dg&ͺr{BOsh_6cX8E| ;(\{0>}w-DP6g~UH?x9;DqԄ%Kī2(!ZKjO~tխ'߷]]gs@ͦU)f|\Tvyl4ӎ?h&"gK!T$?=G[ ,L&5|C-S Gr8SBrǗ~yD^]l?gW v뒝񀘷 ic}q]K47dk>|2@e bt+roq:>q|m̑X-hze4o ~Bqȓ9-j©PKN2H;TȠT`WShRT^nvSJg>rN;Y>;pFd"GΑM$WGA 36t 6jD {UUAgo>j\ʠki襁jM`=r~uP |,L'bm2$rz@$Wr'[K`rv_ɱQXHte?iz(܌R^VqϮóŦų (C+Y2tCSeM6 q2$rE|ζ@;gOJ.<Ҡ n)AX6RSB>ܟ:`ZS~Oo=hjp[g` %1R8+Y{Y5d\dޞYvFZ=`ϒ'ej}{Usr|oV%XDqŽEt1`?w&KZsZ@y&1tMC!/N * ]uTT٢N1KSP!|03h Wk @݃a>1STÇv5C꾥ߏk9ғIAIhfշ~QU:&/=0kSP<:믱.1 ͝YAǠ@GiÍ_юWqZ6%HzYF|L#Eu>w^uvo09ɡ#Ǧ=ЖuD1ּc1۪(iFK"@:΍$UOٿP '?-BGx-~{9#r%j*qX5d8G>'yd^QO557.٣K6T]{`Cv 0bTtTu|4Qg0^~2ZĠ}g4/Ov܀<- $(1q-:_w۫'o\cA)nwةy;($ͅ=FT@ #] 8pq(_ $4,9\ t3*[YCGZ!egZ ^%ಳ7>L7DbƔVpN:Dufo5pBk\`_[GߚQg(@_ E]Чa0˂pDmw*L ;t .ن*.sn nf|!9sU:qpC#Hĺp\U7]oܒaƅYi٣3[:: LNxRs@mtDlĄڟc4[@~k !+[H`Y{_9j+|~QWc 7C4?O: ůiXb0PҥjIB xstC!GQ݌$OG(hq ]+}OQN:桜0=q?3<~5y(5y׾GR"Bn D]9("Άf*X.28z`>/A54 ?7t Mт jp-AW˫/X'#8YF-vdvgɧDByaE 9D=Fd*L'3a;5FuX0ƪl=zË oi4Q>;?dr97i.\Dnـt끮]Ts7VYl@Lld<Udԟ~4Kкb}gn1:(m/+`׼bf8<<7,+c^,'~)iz?2kؖ4s6t8܋'b"}|WA7E  8*l%:ķdR d@͕k6W%kvu s r|y)', 0]gr(Zh hKTqLW, eerLErǶ&eUm' 5Ljڨr"Y.Lu]WHsMĻLxAʹx3ׁs9-ӯ} R.i[GkO/x_=K23ը< KEMLU`C;h!h,fL0i 7Xv)R#e.nQD3٧<źD/1"yv%<{`CQaӒ>Iv#F(/A}eǯeqGM(W2 мHm/ՇMϊU ,yw]WtRwM ּuIXdAS$ӄ"]6:؟ 12}z.<.#VH 18wԧޡN {+00`x1J҃z>!2O;)q_[B\~sܞ:ie '1TD2΢D^O5ZmR#Q.nw#|WJr(J y2ޗf2^Ҳh}MOi~iS 3ݹ4DlH3h?b>TD gܿl $UY~bY0YjcWǴ'U J!@FU.[dv7-%HR%g{{0 A) :M KT?ڵK,7B-`m7mkJ!K&Jӆ%Qu^*5q#=71qqԱf<n" \\7b 1ՑWi1F( w?A\k]÷ ÝVmvMrA :Al˿he~;x9n[$'%\2X ƞS1i&`3[a:@%ރ/7HBцWQW'ܲC&<#jO|N\r$<%ߧ\H߫uFAڍZGA #ΧR̳!= [:WdM_g7gP`kPm`n\[a*w@_ OCZ ׂDY;߃@O֓,&wcN9^ғ'yukѲ[Fż3׮x 9=m2Xy,6s_Ris?@<@Vy3"_+0m +RٻzlJ?mME9U=VSx>GL}uiH.)3#K$$KU(%!ec蓱Q^ld޻m4 WRބ@$"x8G'c&=,6 T`\_$ы%>[QWEJ-(Pɴ9vc3.uplk^?3_Mxi 6jB[QS4ƥ4S- Q /A%=O_0LUSBUCC:mH4: YZ_Me%p*%S B-}1A0@Q7MfV;ͧԍ[͟ſ]בq[hU 8;xKw5۹8οlwS,ue8ϕաԃE;hVJhB=#E4:WW_ ?YшߖϚ9:(צTgz)`6$DVY5x1 ᡇwjZm)6G"SpVtFpd2MUJ dEcW\,'~B`0#: t0N|*EduJka 0fKu(ZxLA^9i ;si_f!"`vbE1xb!;Ht)+Qi~/6ᅏ ؝+n142R%o NβYn2 ة[OOTew ?(FF&"|t_lj00/ɡ34w$xү^0,"> m&ӟ)JnDlă0-؊t3Jv/xW9M_nz΄TWqXz:G0NvzTN Ajv`PZ-.4}UYuG-\&lsɽh$)W+Z,ONY<$H%h`|'1VP/#MK$`@ K:D-*SBHXoeyWNdOKf#@U|, iÐ$v~,LAPzZJrP7E;y>*olɱ-ߒlҗsr#JܬǪ+]=5(] ._6"xiMFvz>* -K!Ի h +J.U EJqT\hg  WNM<"UJ0TaSeX^(go:VJ}KvR&^ҍ%^&d|5zζh ZnhB(vk$/;nL*Z EMewj".Y O2 L? t$|k~|7eݕ2n?{4G1l#dS1_#uxa ne/|G, yEIґ+b5ݟCzg[EČz9+ӯwj?Є/XPnFan:ᯭU KBU>|jhg4r |溥i-#r՜/ ,b(i"{ZSijOœ9>JTgQa 4̯Q(/%k/ kPN+T9HwjHBYCs/$"aK>kz_a}=+9N ^H!Y**VTw 6{m/S0<.թ iY*_ڑ&(!ZRs3#$, vSV?R%Ny?P1P4`#!ިQZHt YJ Iow>/ASP-rWn8ʧSɎs.'۩ޝ IC7]K&<1([ro$" OcWv?(~(An'6dyQTB((N2ն&(Ņ)ѿnCg1f*'ٗAes֏r^LݕsNd-#B+XU3A>ol/䃩>g+b#VT}2apHAx9V__zkBcUHepv?kd1QA" 9Lk *[ga`@nИ<YC{ci)cR{*5ؙd#; ,TSKffw7Lk;?6\#rB厥1@2C:p~t9T#|LhCcf$ dx古8Kpm-=7Ujs SbiPQDMNx "B:1 .()PǦpᬑo"Ds2Ipψu<ГIx3vSڛh[PR1c1Ygsk,rd,*{!U~%^[Y ,@Z/Aw8*ieZ6E) Xc#XH$m{v%_UKb['H<$c[l)G]z6*ݳfΛPjv8k/N1;=O11PZw'B)ʸ92fTm-ްy}&/u |*I OI\q'JUF@M1X۲&lX #g9|WӔxD5C6f%V {k8l<u)>( ע&6U,7BL/B5_kz TAyY *v|KYyMuRഓ5$Q 36ӌzN)@y[&o k%7.äNJ@,.N=Fc_kyȅq0`skFǥ6^ >$GZu"ꫝM AF%̀3y"K6DCE9=]@u%6T%xVwAXK3_'œVծy|EnX̒u,Q(/vKi8Ք/fD,68pw?%?0%1:` l*jbR \h "%ɸR]_ߟv#j5F6VWHo .fx]fTMtOr)=G\yiRe~rqFbF8mي<{`m31pu$-k+fFi{ wդ<~4L#2H@@*`{Ro\:ӠHc&jn!S AgmW: یňo@E-Y?ÆH﷦Jz\wPr (Ƞ{q.}0̿ٓ rW_d~O[Vfx c1||ĻrD^Ck%PM")|E !k DgaZS!ҊN(~+qZ9҆c7>zeL6^n L'Tw0蹀Ջ²"5jwRn -˄z8ug-^D 9,%Y2 2e|:V$Js dxK:؎yv4_P1)e_5Gv,phGι"oX硁rQm,R_A <4up0F_?FL-Z ³ ষT_Ma5ǯ;R115ʤRG$WP F(>ǟ(to)-M0<[]FcJ~ሬ bXV˅zDˤZӌoY%qyT褌[Fë1ǒp˗9ȗD&@ߠ$*<} (fG>S,@Iuˊ 8#x8eʈ*HIlFhv zvGTsxYw7 =/aF &vsAnZ!bxiP#CKiqhY ݣ 6*4GIҏweX XBfy{HIRg4ç= AK34{j72w xpDRY֣kMZ) 01Гc?Ƿ$n1p:&2Mvgb?¶~Voν[BL(+{}]0zRR,D@Y8iwX2; 67wШ:=X[de̾X ID.; dl f4'W7o%lc1bg ]["AZK|aap2L'2Rr̫ ps~"J-ʃTzUϚ#ҤhRVcH]ب2}6QYEى|x@b  ƅnҷaxzLXOY Ȩ鶷XѠ = qÒpr/^fǟ5 `8/S5P[zC)GwKV#Efpd^n|b{KWpOL9/x>ʫfDPhA GWPdQ鸕7"9A.,A#WzS$q%q/[<'*=0G ~Cge(:̲> " CBADtAǭD($ƪ3HB/kӛ4<I Xf|4&RW*3lէ18-Xž7y`1^[3g`g'Uhyh9o. ƜKLڋ' [X8avi6xeNw~cF֞o8 0TSBiS~˜DcWɺu8uKxqti6AMeΥ(&L控Ƈ% Hiʯ}HֳIJ,ڜ;;1`%$m!EKx\PLA){K [fFW:b زj䶤]%̮-GyK`D/Bex˂K<>J +i*K~~ "a}xGI(J.1+7ӈD)rSvی7{4({nHj ŹAl)W ܐ[۩?~O)rvT(^;_8)mq q>?FȠxe,K/Ua̮뤣j2VB cw1 n%ڥd9DL*1ij&8Q{Ǿ HL퀯vʹ,3CQ`Gmh׌S׸7 |Nzg=!Ё;Ş17 WxMO>6}t<_ /\1,cBZCCmG 6GtXTK$2%<uuߴ.Cb+aZd]rn,+#8F9|hY31O pwM4R7`ĝ 6s=BgcPT +r6 Xq,175qe^ǃKC<(hB38(m6]v#s9=d<߯szvP'^6dC3/@!+HY= l߄cH !b5Czuqt]BvS2~sZnJehQZc(}P= m؟]  ]frkǬ0uLOթJ7iܢ@cqV("v_6* na@5kЊT %(=?ۧJGs | 9Yxhx'p^xBe!eoot;ؼ;}Eܳ[?u%5ⱻ+L?@ê+y;Z}G,wSgPl-٥tp3:-yچz%{oiuOʗY컀$7&Vc|sQNuLjmS'oDQ/-̂FShk xVխM[Smq^%zSY@1]I+6kR<6KC1[] N94Y֥@5$ DYMbM Z/gj][7 }pTO'LݢJ"^'>LF: S-z5vPWL9qˠzp[,3=⎉^,9C=C!xi'Kfsg@A@0Nf.b0Fs fBX떾)nV=w 'c8}Xnup:/bE, /g/{o˭d74Lb1}ݸ?L)Eq2<,Js Rm\-3$}fn w "}jeO 28X+ZV+q0YC;w~?W qZXKg H|܎ 0 Psel1z'.ix@#ey a+t 1wڸ_=7AZ+)d6N7KaI GRhKf{F-fDf&g"Dw<, _܇{Y7ccp v&wüC>vaDpxHO{&^C^^̉C׿׼ieҧJPP*M>uX $i"'w? Ҕ..m[}*.*(?;!oѼdSi[Ds&++\X&PXPj}19 N件 ؏ ܡ-bjRSALةܗx[RmW¨!ڰw?G7`ȕ [C6S&STq`IH hKVU2tywvȭrpx1ݷM a0@99 x CPgٓ4f{jË D[xh{ }9сt/8'24Y8I"*UȦH8S}D vwr|S$u.FwWdfhX^_(B1]患jOi;BduRCVVcT[ЕaDAܱ~=i1~;lpCѐk/XD2rpQE:2uOFEigGQ~r<7G#r>T !>0F3t@TwEAQj>~@.Q1s5X'櫻V69R[B9 ^R"#˥w6/v#Iš[sLV=\!&JQXӔdm1ٗz6"c?կ4. ]3eHhFk>%clp{a=j̦NB% C%vTb:;{}3BתFӞ/_|av0(YܕGMC=EJ1؀#`=).q}"I_qwyIl$"8h87P쳭Rg&*( ϭUؓ"ՁΟ{pn>:S>O.C2pFUMǔ浆* >Zf{p}}̢U:*v^zj.(pCgńc.̀go16Slco"/6~#ZͅWr ܥb'\8u9I{ qFI5u'RdRΏ+J 4@a؍_AvW2LDtɝFa& ,!\FOjj{xuy ~zYHVuM ] ' '/ yz%n9r,Sa_QFԕihau1=^kz'^D~:lvO^˯ ȔV ^f^lQEkNm1l҅ ~K;y+6uSXvl!x`~:LuVG-MؕNjPPg`'ب G82¼3a~dHiO# >nN ͓>6`ϕH4+>/SdiΩ(% +Wd LR**Rl7!w!K^ { 6[wN3#ǧnP C)Cd8Tyrd^&2k ! Q֚Z[ZV_m'{t ~CXFصZI o=2xW Y7Eyq߹WPaSK}^ 1sV*hVM!g"/*uH֖tPW1 WC~ARSƩpʊXU-n2XCR}Vײj"ŮbW|Aq(Tbs\ZDɋz}`Cr쮗 jzXyMҋ/:cBZ?JȓP\>xއ/0VԘ oF0aEPk!AbP ]Njzo# Q6UB8ckS 9Paԓ+xmgR wo݁J9=[ !P u.90'Ew9kTn!PD79jsR'"b%nT D"aL^qxBBD;$H LŃË>H kN/,8u!D߽y9^Ix ժ$J쉪Iy%{Iz^Ց<ԇͶ\Е+J:A< uxG323(=cJ~ܒ)hěᴥL}r!UpPD8l!οԈwTlznN`p(*b^1/ 9کehǤeBRE ]7gF1O2|>Xt["Q-Rܴ &0ncߎpviUH 9H2D2 RLw}{b hN2m9TK4=b5n<=4u{UMՐGI=|@gP]vڜ',`֣a7ʹ,d[>Y/izZ" S3s\AENԇyφfp^5rIXM!ޖ~;W=wuSupA!K6QDQ5=)B!D=p<+_,х?]AL1|bo:V&093*jXZ_M0Jр+ G_ܥy$lՋ \R,w&L'.ȭ̹;VfG ͅh#4_](lM{C b9|pkZ:ᚒΞi?qG.tY5rLiXi˅s(Y'ArƒmQڱBu!@]Zȟ/)<;w*Tֶ{ ԙ |PHsJC%֠bY>0$gp2h-#Cu~Ə)!\b'VRWViwH1NM/8pLą${Z}Lw ed)΃e&/]=skƊeܑe@F,C'Z>a`9/2>z=jp߄q0ޜam+V G͵`hE6_Je8N{]bKUk {S]H )` cTYD'+ʔ}$Op t8T<)_GǟIe@+CwuŊ"F#76B=mp24;l['IOYya Y`yw]j3";Qs:ɍas Tʣ!Z+VPQԎyv7*KU^h&g#U{*alP?O]s'|b)}j_4p0]#rL.[>{J_Sƛ&#XL϶f!hP d\-2ts`_[Wݗ~g E$R14aں.' xrM*Zչ,8g2Z QM$ާjSEG0@UƬ3d"lO[+BO .d8r$+m!\K3" uY@ބ:jJqş? 4 h-h g@ h B]-ȏN"dc%i#q&ZJYL<Dֆ2HS'\ǽm-0 4ZD簠DC&8Á QD>v;a_V[T<\M<Tf\,CʭXګkX*x Qן3$R!7=*ϊKJpiW I$BWeb]"zitj\JO7{WF/=ޖAbs ^0~@pg pC GtQ2dfP`0$UE. Ծ&atFszn9viLs?\%V ʐ?K `2WјoQ#BZ,>M [pQfzY,WGQԊ" -Gk1Q|V;Ǥxgo~C56Jm` =6jhfC3 ^1~,LKC3YݣpA{kb`|=,$F> a H6,R1+t(UFs%GpѽqYۘ|+`,N4 [yg T r-06lEzd͌!ya1@H7|oD{)J1}RV>*oKTB1?9ᝣ~$Nz0dD˵sT/{ˈK"d9y 6A6ѡu* 7LxP7]VҲg٦\ʳXUgr}4&7ϠD@JjON12Lb1PFI:^y5o;k ?"ݥu:ÏؑS)xCVĊy8@AO؍v19 GR|6wcu ߭ = N9]׀P6';myRKx[fֆBzHy(pv ghmHW"H酸qAkE |iat f7֚%~# M?屴)6-H6Mo9uk X.ܘ70$mz1k"3ӹ`Y+IH)Ѓ]4+xSM(|U]*EXu[82.BWпFI N`T㔙b78H(H”隙y,, &B$Y?A,m~0Vl.[rTto/ SʓsO#Dub(a wzS\< eJ5'e[[d{._X.)fKݚ|fItzIeu})ro3MlcnJ9Cnn$.gB -o՟%nFBỪߣ3t[" x"M >yGmP(2Ӯٴm Dbȯ.kO᳙;^$KJa"pX .VFZǘRvaפƫKS7!^wleCŨI3=Dgu Ѐa¢NK[(QI^ ̻aw5tTpוU';=lPA־p!>c: G/q/<(PRJ2Xs|OTiH_ b2|:QVR"3AFܷB.,UW8-(,LVOoj0ͱD&aCw917Q!J+KHF9Ǹ)䤲 ;O񋍃u ;&F BGc1N:* _p*I|vN 2O"V;dy󧯋5~N#{.BLDX+$ ~z[x9 A\E?])bD[- oIu8l4L$H;œx *\+kDe [u?5_D&CՔNGp}_$z}>ZeVŘ32D|,P%])Q48얨q/ |X6 S%;\.Wig#Zj.z]2';N&XfnDgkƈ'C^p8Nt W gUO%H|ϻ849dnF {2.Vאv6x7 V"nJgGbkWHϞf)fNNٯoG1-W|&h\@d;`(.(4XjzGś化%M'}bLmPOux8yay' #,ۙhEEw23js*OP{M>lnc◟vw8ķ φ&a=t,p{$p˫8N $'y3kc?UJ$OsVZ$Dg @ť`y;"W`?AWʢFcz%UR؄&L *6܉fٗW,A 1f(u$* 岁.lJrQiē@q@%x XɀqhU=I Et½E9z;N] GR4g  QL4HC{d)Ю8EAd m=D@6"=k ʾCyd1bV̟ݚ;'HJ,]F cV~ِ;1nu)C0V`l-/vii_TF'p&y7HFKHw7"N~xU]~S2߲ I' ݏDGZ[("d3V*=Ei;$ATp o1NWHWJԩePG-@=|W*ne~N,Ox׳`>U ";: q9_yR,u3 gB\)bWKncNC2ute)?б!WNacymv8wVWa}+\H3/\n 5$}s:dNf > B3֣*3-Wl^[bh5LR1(dx% wkO\sIeb"OҲS'Jf)l&>d%X$?a M좡WS&A kjܺ&8__LBW)Xy}UXc&T@ziM~;t~w_tv j *kuBbX,v' Bh}۾te_H*4y>HB8z$7,s"NafZ?N(dQgT|YqF/ޒ[#A [fq Q(WzMQѵ^ W<^1Wp 5* /x%źi{J0|$P2N{fA{h s@Ӂ ]z̴r&}AK67ܽhoXACV#f0E47ɟA|&yґ1A uv[? (o-9#r.R\}LIA%Mw^a&N%w@j5V@ǎ 6ͤ8E[ *Ze=ս&,4_FI!S{qV_ Lp6A$)? #ln1\SI[r6#(0V`/0xS&pCI5Æ禱lr (;HdnUvr!)QWf UbMjqn4W[miסuwWk%)r_t~!=kI]?y[VIEV \dr sY*ϧ\x@*wq 7Sy|=qqk`N:H&MK>םo4sQt)Aox~vEO{(0ټi+f7LQq:d?70Oc9pd37`qFLi~|Cn-m5\.*)YvW%GwGdojra9ALrN)!:T7C 犚7 Ȼ|\êA;fި̉ԇ5B5@yŎZx_5: LH ?T!BPɍRIέuØ6קYsgeq$!6(~X[*쟲E1;">bX^LYʲ8tUwn 0 hKzu+K;t5DϐMA5H3PWs’RY7]E":Sͻk.{sԋ׫Y U|r A1\M(R3b)VJ"R,B,{@Vl~) 16&Cj> i1@->Έ;΁=VJ:u P3ډuCB_s&t ")ºLjyRiۻ7o # J *VzZt$ij=O?t)w4mmz Mf""}%9wr w<{MTZ-{}<-sӽʵFڼEYn;7NIج ЉGh} T 86[*o!$:7;MM^꾀 Uӌ%HYX'LK*^^D~7&gX8 u[fېV` oj_<WyΒK1_xX, /}W^:)y%sQ$vjt}Lh73Sx2A!D~AR.Iv!M:9T~3i~4hnPnnt>LQDH!!0 2]F7qMj9MYsGlT)n[f-yʼn?#yx.^ewtw2/MCG%%!j0?JMy<]ylLudۚu\XZUv @__X %9:vmClVM9Ws"@qZ] 2%~W=%RslAx`6K~KXO+D~kot8?ԬEZѺk(  3Nw^f;XB-#أ6zw 83E~>kL=pk'los>sdSf0s(*Fw_/oj?,@I5s!Íj=`˜|R) 'uD6,޹,F C=P:|U17m@ nuLRFs7agXzptfѳNqz LE T PD)%X+ula9A0>u O1&R@ ?RRlPd\\ .a2TCv5ṯhLlGƙ$$AC!L*ү[n?ͬ7YYyz.P{>EyyV}mQ)ē v 0V|}l}\jG&"7!w a&ޑ#,Tt1[./yVS,iռNTJ*=7O 91)1: Ra~[@ҮSL}.) 9: 'ʘ+UeV~ZIw8÷Fu!˦X%&Lkѕ;W;|v|ٝc@ȽL~/pT!NapWFlA@ hWϘQ"mBqdKXr*P/&ʾ? 4Lv)zàΗgMC@ Sk ہ_4lͭn=<-+p!9?e)*6ȶ>U36oݜ6T$9IҀi6V&K#)7cno{XNg-GNꜼ&8t7xYF` S䯹Ks`z s]x)O,ԍiw>-v$LxӨ4|3'M=a(6NTJ??D0 Ȁ)vVcĂn&R~cZ+}|Iⵣg#4pc"&`Uv298( &,bF6PqX{TqRY0 BڗV:[p!q@͏hV^<^~>rV|1:"lwy~K?>LKKz<@\T!7QtBVZy+c+,CP!,`BFd ?qMUEp&^w{̓(+iT" y@UETСuJq kaS}bD{E\ڗ_X?<$8pZ#Q4dJ]@H,{i6@Loray9Vpڻik[ ۬(HD+%أguyHO/g|VYt,ӛ-\ؔ0p$WbI+פ ԛIJL<*g*dKI4 rYRybW^.Uu(CosiES'o?oc Z Ӗ]ؤg`Y-(rPj vU_62J@ҭ.|P }nL ;$}6 b#aã>~5aGP쌡eP[9=|gkP2B?EeQ@ T)POQ5]Κ#48^7b )C 4SU}U4ay$ /9=umI z°hAՓ2> LBhhl$dwRy:^{pqnj}7U 6;*-nc:n6ZOwnVN̮g)Ias<=niK! Rx\5:ALG}Hens7dj<Ũ>No[IS* b->)dڟnm|z#ka~yk!D5sk!_nS2?.ˋxSGq613a:D^Ei!FϫlCT[8o!u97!=ytޥ[#8:GSNg@_e?CasLpElNoy.(蚓_`8R诲o娺qn եci^3yb)Lj| &ȡ[MA:ա($EZ1Vd7 6m C7J [qf=xտT,'KMTKm㸺CXN?/?ose ]De])z׼A[b`UzKO->櫐w'bm-Fσ^)1vU-+qcP!r LGǐEXq|FWbA 4>t!;y-yЖBC/3Kvr,uvt~ӎCF[kÿ;%b=E )^I~IK/ޝ~`BRd$+imHc-,R'l- Cg.ZP@mk,?_,V7\kv7QӘ#lJ7@CTVbGMB R+!b4$@{T2X5.e*xai'}h[s^-׸%bbQQ+k?9OBiW1J1MBO)lTJ؊r Zw!EewΕc!Zv^@T(Mdv17V8@[\4aPf m(ʺ'^=g;R囬mr!LP&E*Hu-ի[?@QyM =-r/GPER\-A/|Uq}ɂ֒ʘD-bȾcNF9/Zew0 /Op/TպuFlُ6GG'E̴'j*u0Qp5`7jWF&䐚eygv9ޙ"7؏o=̮C0eq6f̘|m3[Z Y>5g}I.dnunCXxL7%F+f VB(0o{}8 ElD`*pES+-J b!*&K[{.A~ V+fx:{TZ|θOH~?8iF9H3ҐxPv{ݾtxZ`#<ӉX\oSγ3N|H Ώ~4vQP5LD$-(9 L`*>i95LS;s0@Աw* 'J ?:&ޛY&c:ȱOSMҺǓVӂF *QE@)K$n=m5Ş$~ȶsr5Zz.\^ΦTW`PwdHH 1H}47`*8nߠ;=)$a*$KQِ<`QqִV={cFǀ\H᣺Q4blZTDz(kob$8~ )3}O4! f9unr8U3a?]a6dS+)\a3<"=]YbB!lo?leE瘓M@ V@nZȅ7uxw0I(U⮀~p[*1gCsA|PK5Aw4qV2ثm'`fG~s5NDV(@|䃦U )tbp-On3O<7VӰ% Jgs9Vu«B0)AKQ-baA:5nCaהBRyGn $;°4h6 wQI$ .hO96Z0[ufW",!Q U2;u*÷<}?5ESɚh5,g"z0]M˔˫xzaG x νZ%&CI}L&2b8N |8#%*ֻ';mW(wr^g꺱P17S᢫o%[#:66aRP_N8@PtKcF;wp-btNpKfa.ܾ~f]ȟwr@e=3!\agxnM `۹||]JY1.ω QoE4OS!3t303p* ϢjzA`f۠2.Vv.>ǔ6·1`iD8_mTHtr0; |K><y yP QjB&8ɔ@DI>!\QPy;Db?SMq1BH)PQaʣ|4%A6 exsh,Ħ_UJJGYTḢp`n* H6GHYTz!_ y2C4%j׼ rwcTfuĘ Ddn,iKGGi 3Wͭ c[P ('n xOK!Xz+֑@zhq#fh!Fj|ѴyBMg-}N|xe--ᑇJ1=>'ro}:Y,²`rpȁ}Ww;#m_.F9鳋vXY:[1KPF:/f\B_:dRcWZqTv/E=Z:fgZS Bhҁ<%K*)4ˎŠDhTk͜>VsJIԕUMWȻfğC7 =G]hՈC}`nqӶAU݅EVC̄h%g{S\sè`?--VIis-ЅvU_Ӱ8?`|WŇ CI6qAyEϳS4d4Ƒ,9~]T<{DUE(Ebh0^ِ17j{Zw UF"LP_8'TU!i-׍.TZB@@Wb_ڰ93Ҡ3BvF]KFu]ʹ!zޜr"ͶxЏWFĹƂߕ ҖUz 3p~{Q :X<ni)6%R)( P:`AK!yqC 7nj$Pf Ġߠ',:+Ou LWVڅgYJ/y//R00~7: R VYWjx׸+M>S4Fdj)[TH!o?daβ'Dy<jY33|oҽ79|#l(_»Y5 58&<>3 Be̘@UrJgkE!b.WΞM=qBNCܢs4:Jj6g/J Paop)j!O ZI"qѭ1 Զ146K$(!QF" yQWUDdXIay TVv੍}"6Kw(ř^J#2ˊC\8-ur~r39"P`|]Le}&|i= ĶX4Hɉ'xb45`SC;b NލC~ N蕐cuI"]0f,T$"t1O2"Bt\c+D; 4,FTJ/ /VrR=#g`\~ݴCir, L݆Vקn+[VjMSaMY7aԨo2Bh"NĒFg%~я.BWC/0{WgWM]@(18J2O[N㢊EIOJ'ΠgmdEk0=8k"6HCm$7溣ڝԙ~'c@462WK2ػDL\.nft0Q vja +zKm7z +z]CJheh.[B=7EN= {_J-nB r" 84ZBSڭOt SY݅*YbH ToLImZW^R%GJboS7heH)VF#y4]Ǡ ?ex=QW! !Cu!xmbIl3$l@ixO9%㶶I_ kED^3BxIml"4 Lw̿q>'!O bK1 y27 /m0QSʊ3/hG#rJ?,V^iIvr9@In=2ձ`;GAtAhF=@v?^F.QGCR^  W!,t+DJYx?/ ]ꄊݝ7U>g6ejXn <. {,=ѳiٹ| 1oҩѵc9 \5{n83*jchR.ȄupK{R%P6*gzZR`)^#uS:̿xfa<ɓW .9c3{F8m.lU1 # l v ys錡@^g=۷Kb~g^!Gf dAO-V)GO%R>2oXlKM@䃚~Ps/6:Vlhtg683٥L=%}p~f9I|O_zXdG}G\tHH=&Tj0igowe^SI#-W%zBP_ uݼ~$l].mU7"GQF ߈u'RЄ}! iV+EZKB-QdC 9$ ,q`PH(Drm|bLx|ZeE QW&z~iZRP8fB0t >XHWS6nyDP_l\'̄"ZY- 7C}5{&O6&r ն誢J,K 2"غǖn5S!q(A1) k0zO5Iؽ0u2*q$ٻXHBDMD{cV>OCݴ*c7>33\&Vpa0?6UUftl+Nاj_Tm }JP6Am<~Zk o4dhro/ǫ~0; jޅx=ezx,NS/RJH+?pY 7 *i Pu_dz 04vs[y_.9\\@ fՈt(fz[K xdQpPƿL _fIVsxfUMȽ Dy U Pz:9"]5Lې?Cu$`|gG&v5a7Pv*ـm6\E0Ŵ Ȝ3 do_<ӌ# Gqoq{=5XֽrwPfM)p쿅`ӲMz>O)+6?Nkrc{ۍGhr^ o OgHbvL-ҽ޸'Oٹ&9e, RKGJ=*-OuK8 P>z>7H<GȞ9Nwfa4.o~CI-#O{"3nD6}KavoY!hE{ aؖ 6fq#X + ~r-@}L% uICٳ>HخJpi'Bx${FN>W%H#RW#nA\ߋش0cӟD ce#ƫCi+I|`f}u%VS_Trۘ+$#^v/O8J’ڨb st/n$IwLl~*k֍_z:;C>}-Ap85MtC~+A3;ΫzR# vU^ѥSK=r;Z*{g7sBh0MV)@j!N=r(%'S(5IѯK=3Zk JRIcXtIKfVҨroC Q^OƓQ`e5^N,8[A*A%be;L޻^B}S'@җWWE2sxwW4ÞN;'[7My2k&ERb⇗:'= S g.=dR?&m Abjx#EEa#G*]ޤH :4"J JĖ#X4+͔)#vFqA:cis+? 5N?|<fđH윪][ r+VTЯ- z=M%`2aѐ{UҶ拂 Jh6LCNERmPg̅p5?6ޯ4.u /5X&&#Lպq;]w ;{l2?`\=dո2)))hS8 3Dm!ٖb'RhEh/4;bbAiM2 sDsQrlrW650 Ko~ۦ>%Hl34$RNʪp#dOGP  Yku:J&g _4{&O=W,ۇ 6KAxs[D'|DżSu">G{eakQf˘s[7G"2]Zť:l>-`7[ nk(֙=@0H}XبDgm?qg:S $ c3(*5LuO.z2bOfLzmᨅl!_j% 6tu#;ys)c}=3&Wl3?,֑At'4^旋JbbK.ZBk+Ɓ"wXJ2ykKftʐ=H&ߠ@VrاDTQP~0Oq5 G"+vә]li'-Xٿ@r|3t47Ό1n$|qv?s$,1BP~w*2Hwai2YTh QL9:Br=1CK)^L!r3dZr/R}Aj0ݿX/3=g笙R 1 O!j/{ꩮ<7znq9_&vRHƧR΄pMt>|_m|Tx:%Bn*.B.qm߰g`tWFܿ=*g=璦,L.>Zט"擄*O)gHd'VDZCXÈ`gW#}}k3V ,s^A [D^>z,}b}c򥘖2*O6kNދR';DU FUt`4*'1b@Jf _rwuqki@|cY8 Ș!]~pNIvEZ16UUjG+zj@3"g~Rf;TDf].u4r3IXxjj{52 b͵й5 978oBtY=BMgq O}ElE ~1s\oۏaprЯp\oLP'[(zL/_'6}>3G?K!N҄M.$6 W :+ "!pꗳǪ+J0xV;dG MzwGEb}M{ȹ"> jeӟxxvspRhr{U1T@dU8{ƙL|V ,(bc٭;2G.w=T/T89h+]!SuNA{B<>4m\Nsd]T>f't 7s^k#BVKj(k;b-ǯהf`Vdn_ Tj):WHIh-hQ @, Uc #V5&`BJerw^~v(gQ p"Zjtam1ݔw yO|]q{$R%m;SXLٽ}^yg`y.oݖҮN#Ks/`t[.%&"IJA.68+QMvZ<6wFY0]fXo>`k* ٺX #TَT c"֋~ qFZlWjMdb{@F`)iaԒtRX,320 ca33"wɶحʮnRޅ7!R\"MMlp t \m=&_ '$ WMwB jJO99j"}*D/.Z}N Fa${F. ~?3p3= 6^T64!S7G`Ҏ7Yj(w V~1)dmQ9Fy=N,~ A;HuW3Q/^Y!v_A."J9kr[#/l1 =/-ZO ¶rmA5)'qZ}N|F^F%-5C=`K^I;Ib-yK1%-?HGBGrۀCsa4TW#ÐUFe0K߸t: P0)W%]ti,$A" >UaZX&u*sbkÁ"BVKS}Փp'$BBIq/b֕V|YXG}8\rʀb?іl |1㳐KŁo0i|s8ǶQD)d8(0Kx 9 : I&F9V5B0Lb';5];zbnw/ƒ& H6)&*n2Ȓms]󉅷Q<ؠ sDv#9AH{1BHZAV5v ǑqFE,ß\q)`I\b8o^~Ā[F"6DS;ɏN4`m';Z~.[ji>X7T\ CtHb܊%M%l]EPpoax xWi$Sԗ«+҆lb]dsI\r{2 0 ,`J"1ɋ P7-2l$2\/uɉjSz Z3jX_ɣa#gFy5Vo灞S3Iwޓ L> 6g /ھEvP4bosq}I ϩ킪PgB4aԄpӄi}d\N"-d"H%3}15dxPwSOZC"-Iq?I ďE*{Ɯv3,mg@4uf7hώcjcVж+ff Y5 :e>(I}/\k1&B#RsVU<&]UWdUNrVlK~YuRns2*N MR# L26-#$QV;0ހ+W>FfiCbe^r8'i%$8[e ؟&`P+B) 5 ; ]V^SfDU7̻ŌN541<ؔ'rP-%v+Ͷ#όI/>#V )vR UXH5)Qt<ϗ>LnqH[.#&}kԿ*Fg9 }isxr/kTpjh/IKLk11)6<:.eGbaqq4Gz2^њ!h^M"?3TEu0.DGcArv LW&oPp)kP4g*@60vǐoB!1S Wo)DuL/Ț*( *aM4dl59F*:[p:M´`nuLKmG[J!6g%TF2x)!|#mp>߹$Lفސ!G՜G! 3YaKevl&ٗ!G~(B֗/o{K`>a?\Y똏X^o,8Au+WYQA&A!+yQ#jJZ;MoWEUI ]IO,S 9O; whB-#bرhFh/AT!@#h2ݒQMKjDG^Vo 9?z1?F:z*a9㽉/;9]1*:p=)_ Z\R&?Q0)YR I.}vZ&\va5L2̓yT/e:,cd/gW n w"v6U =$qr^AancKFȐcwboP$ba&nݔo[3Bj.Clxl6&hF,qαhaGcP?#{Y\fS'=Eay7,y-$[ IqdJ07Ys#5Mhݽ2U9w\$8zπ3! dݒDNʓ2nMWo6A]m!RROV:G`)9V=S|2<=P.9Kpst`Nhˌm/un]`. o.#/O.Ihj!ddc{E^ħ;"wO"9/JړbD=K4pL<o!侉1ҍOHVc4 jk!ZiYapl6@U` 7ry9<h.ǪHLsZ ? ߽ij,p{݅L܀F, l/T ߜ%>9+9 E<Y>GA~P2ycЛ;Ǚ{$VOf=8~|$7:"zڢDaY. PfGay![ bsi'a3SG'_ħ&R%9K^"evM ~ѕɘ: Hq_ٞ]GRV2'6JJSiFhňkGN>9 r"&?%i:G$4Cͧv\U4&˺+#L}m.%c&Ɤ󉙏Y׉kVlMtb#>1 bҋ6lw yp|I$LdLKjVr Fnnrp˷zVn_'(6^-z+4q[ě.a DLӺҨU i=p+VBbuL"[M -e1_6P#LCfyx ,6 1}3Ruq_NFX| ͿhY8S[6V,_OQ];[`(43 gZĶ>>f /W&ҁׄ=.ӕf y;KTH:| Ds% !s^X!kj;Bʅ*hepZ+b}S+x\[dMv -Z0j`Ǚ$ SH4EHvDl9i%dL${8Ҿh$x%|64M_RHfDQw1z=8p[`+T|B ʝYX3I^i)ZEs[E}TW)}{f]rYt?㓵Xa MV:gڦ'LIQ/)_i0\$Ӆ<%Z{L@(r|TIc@]l Oʼn !ǟHl)VkTx{X7z?Mt, **=^Z#Job$p%t)2:0ldBuksţJ.#z BI& ‚4].frQk)>VV5JYvŸfe+X%Dnxz(٫Xaoݱ0sP }~&~xJX><-r4s;|V!J\kdq#t4Oj@Qcav>.e5C& K}kpX\#3f Jqj`Wݙ˥^zi>eΠ14j+sFLȩoAfVto8MY`` l=I<ܺ1]XTiZ8gsvp u # ؠ5Y'APͷPn#.p)&dsmJ/O]!PaVqLoZۋ%-*>,;58 EU&6]T|pJ.ƃ3K'+6 n=Q r_F+4ᶎ$<_'Pj+@(O#i?Ң6*;R]7jEL c8Ϋ14Sس;ǒyR![/0>GZoz[Os™[&= Jw":ViC.@ ؅$,! VA(WzL#xQ,G;L_j{͇uR $quk 6OnPse:@Rx!to,El) '%-da0?DŽCyS2"V0lkCxhS-}SZLĜȉh0vT( ʊ%-\lSfe~/EBL=nlŖ"j Ơ)6N;*h`7xuCh)Q]LP2ѫR=*L~u1b.Y 3djr2 E>~?rn>A{KcLK;M+l.2ɧy'vGn>GutjZ&.}$3#b4ELĚ߾ZQI)""L~V;V+]^ SJslヰ p[$#t&{ܓ!H(X]3G1 3 !0~n3y=e: cK(n%<15|e1}+KƝ797cqoKXɀ2` 2y!~K_Pԫ\'/s*$0!7DwiFC5>턈DaeJ<251}F62n~۵ ՗PyמjցA&LR\=DQ-u9EsP'9SDDQMRɛ:mUɹLW;%YE4Mwy<3 S}DˁqK-}u&yY.9 a4$f.- ?g7v 4/23ƠRX呈\ś]ŽU5㷾 L`WkЏ9APU&5uX5sNƑ7N~2g/I?',  Rhe%ԅU51aƷ;( ;D2lM~ò3&5)=0' *udKJ&]"%k$ A!BKw~\IlhvOWθ[>E^% ¨`U?X/}cqIAu 닽"g'r89)J.Mj#m ӽZ J)yzOe>? ]d.yC=`Ec&cmY XWʮ\11ȪjG3Q17@ ^ةQTRXc`Y*=LǏHƊ~;xn;W$h!~r3vr#zeM p`7ݥh+* δNoRC+|v9Jn,ގv\dİ2-z7?_ 4zibu sG|}V/FVwsh3Y[Y%*ADeRr:uiԣ[HH)Y,7eLҺb*s-n5],(7!tT{MŦW"^iTPP)Yoer=#6*ZC#٧#&Wx|=xha<9/w^P>6N*.gү.4x׽t -M E7T]y/'.b!Cq5Լ =ؠ;TudksUsVG:4跂*!_;gVwOܷ'xNk)%Np6NFDI36'}+*nO #gG8i܍?]uz)!Qϥ,xHSõGO+R 䶸ȑPu_bϺ ַVWdF5ȋjJHC>1yr% P |ޫ Yj r*ɣ4l8q/FJu߁&2!tzPtEj:؟Ҝs- +7CRԹW{(JLӺ[oO.ܬHd 8D x/?mkUNE6`~&6?LVS{YLDT x rcƒK Nlz`״ql,̀Ƀ{X_.鬗ަ)Ricga6֦/[f1[~'V%lzL`r5rcS)t. ٿ%,Ӂ p>Bpr!ڒtL7S l9J)6x,E.oq&=90+V  NKD%1lǁ=]1z΂}÷YgTc :[Nu  <~b">ΰ鬻V+Y0QQgӋ81p~ =m:X009b dL_ ߢ`/† ܝ$T>%Ė_Sds#%sSxa KZ:JL)5E' ˛FAz_:CF=7nΌY:lB9I[ V="1xw]ɦ;%!A]猊qdA϶iL.viX_ $>}dn/=`BJ[Ջ®vkw3Km.ɂ?#I#%#,%,^)q ,-lSc}H(rVcȀ-tq3D(.ZQx*o9b\R*x_!ș {/Z"+@ NcpPp%`F#SK\ゆsGbr $XVbxоO3 lRMeU 3Zn"3j`]^5(+g"Ns\%E\U@fq Ju{n~+qI8`EeՄKJxopBUt3,r/ZCzx$=;瓶`]_I^VssUG8kplj,Wo?|ēGFwϻc߻S=ɩeGqv "cx)MdzNb"1KJO epЁbBAL΅ĽFu*~X~D]Dj$sHͩMUPzhׄRQon)C:g4BUK;Z\ʷeg*]=WƏC:g[]DU d jgf!A|I3=w) N{kd;o?9x;M{*CUdpl6{o|)\Hs%RQZ8 ՖP!?>>Z-8m[qLQ>3o&pam1*Z+=R"TjS6 th~kdOA >)Bs!3۔c"Ft$'Q7,jAERJp\tƫY)9Wԣ'0HƜeu巕=1J?Ǚɥ:R\_vP놙 JYoEKݶ >RPۂvwe dBF_/\[JRP~1|d$E;h5ؘozc}H_끃r( -ЮM$`DAn#j; Ha+k@$"p } w4BS<#e+dGw[Jemq Fp(`+盤s[RjـߤJ?*24@upM2`|O4tKE,+ϧ "?Ϸ X9N;a`a ַ%E_k1R}$2;>F :rGOP'fɩ n(H#g+ZL̲/Q׋'Q$4860߬c%oA_8k"yvIr¹/pfwW}fZϮfF^ɑ0l`/bH$œ9{DEVbFjl+-ary_J5dUh:&<@=P!{PCwy^c8l$-p6i8j z\\lP!މr42Gqg3,u.18v({m>zI ʙE AHB h+/. c\Sřx J ]_X\\/P{4 öD&z,_#:s!S d: ;VV+:ZlB8W6>>'/]ɠ#'cm~;z&RCzXAs6|Y65&WE4si+JVgʹz2/!7THE_.KڄSuw*?Gb 2RF4J#~M#zn?:z*@$j_KߌRSNpMq%<"Q<*?0YryqןY”ϩE<'IX렭`ཷ^xăޒ"w݄00Qu0Ur'NG ӓ-zQ]䘱7A+kY9E\śQkeI5}nf J',>|ٔ Q9#hHC2am3U#XcVn ZrSg.@rvp:A> NvYUPve}9 Z;;+э`aIF LutHڬf 2g[(H ݴ-ƃ[Ҹ]}ZIx]W?l9GAeRWV(b)O"m0"?|ń  +_!")N&еwdFoGVNМ]opq'3$Cb<8dC$_,?MhɺP,`ϼ>iKLpz!Ldڽ䁏`TU\)~!Cz#0T1Kt9O^hnA[Dv^M+Q)wEu?Y: ث>+{{]2cmڲu3_GLQ,Q ,LFi,!2O+7\iĮ>|$ʨs׊BMw?wƫOYx]8yEx>lr2J|K (󒏬jPL9:Ge2J x:(Olx\To,!T#ꖨ l@؉z{XC8Y` MPy0jOMYZWHkqiD)*tћZ*X"tMN8i` k}n+RucA`{ogg?1GHf Kp7Bm?br[~ ˉ %N Фm8" <*c:Thr|,Y׹rvCd!cZ@C iq͛.9S9E HE_i={Cߌ: Kg<*uV݄ҨD /B^ KٔLe.xd_/v2Լ}jDoʢQeMpB [6udw%SHcj8)^*BՉ1C$-,=$ (M~bVURr?N:F:{1d'<ھ~~ w2w1g^'UM{:6 n-x; +p./n7jx#?d y$χ,3պ25vߘ.BW[ARؚzl~⇯ :hvʜoD !$8v_ymn-',^2+NR=GnsH+"(0~7%{FrgO^&v=d 9ՑYJr'.Oo*2ȯ;נ^R8!sE'FvrrB6"Q]#GTt,eas~[ Va,<gN: ZYL20&DԲ#U/G^I$eI|Gg2O[h~9>tYK{o%Ԃf'\5,\@?AJ~ƤepfM%Ϥ)y}ȟ1//?jX0.5rIT'zL`4;S~9;w F)ͺچ/o?G&Q2xjmlo_J35 UO,GGW!F0 i~4ZiK>41O,^_q^|쏼\Y2~ %GOv*QZƄsTfNI42al}kPQ"`"j@~4uE#K 4`auߠP/O!oav>|6ƱglM@Fl&`V?TE)@HB[}X=yn_%hqoڿT,;1t8Crnoo*Cv~RQ gN\|yB3oy y'5Uʬ8N&= [fŰ| NSGܸor(WTWO稍ɴ8T5nsv9±(%w ~&Ha,Ufk5J-يGl/ n1萛'fRm%QDj[q7U6#rc8e3J<杘WZgffBhh%O!s$TXx)9k"9 ,]Y!bN!si"Qe%'7E~H*,tp$0{j휂S%QH*?)k -']MG#ǽ½J< eae41~|؃ʾFJULޫjg*ŘMfr`w2\m=_$t[+Z")R* f!#a@Cpr~+a7Ȳ 5qBJC̣cAvuh`79%:'KVRGϧ*|X;]7.\xk>W;[1" 0 w 4j)֖$lٞ| ύ{uv&nK+N`)U ؛Fr( Gu#£-_{]?cۦCe'`FU\ղS -+bfn,oQ՚?emݳ Zk+\NH9Nr64gQcZV^-V-xsԔ-H`+.΢G:> c> !;m\%?*gI6`4hPjGmmߦԍG*<)#W v!Cչdύ35ȳZ΋hAz'}?i ^-S0(2s8cvH1_Bs7|]=4;f9L% l#. =%7 Vmhp'GבS/Lpn9|NrOls.-T\.ft&*ԠD>xe!="RuWG6^*"غiHTAV`fvw5)>!TZt?)D6p(tCkz탡#Q9Y돀~޺kX/s H?&<Է @{0oH\m ]Ǭx"C~ᕋ(a_i %r0D ߂xI};,w*b*zh4pl Qvwˀ ͈g$jgnm<_ܧExKfj܎0ƏȆ>>%eV-"DڪzHXtI;w #{[C6$,? O"z \>7}Fޒ>23[wdie1DDʍx^Q{Sv˩I&S{%gcV5ۊˠˋ̎xh*Oh(@p%)aBD0 ~O(Ӏ/^,q/ٙ}s[ک_([|hF#)xQ]8y͋_Q7Uq58RN /:vF4 փ19=M]VJQXMo($WtuKn+Ɣ/T_#d+RrT<]4m`JnOԟOPI[Q$a}90bh@SeBYyшWZi0#To{R.>q7Ä>('8dgqEWzncO;@< z^o yt~cyA2]pUI-&+BncAʢI`qu%ZѾS7K\ǟևeL$d=&JԐ?%CBסFeQ߽egj P+7XݚGNUfR{%b@v|u9]gcP2J=|niv㝘mʅxEmIuX]\X, 2e{u:,>kWdtk{UXPIcN+Q gvש*iҖ` PK+1B~o9{+) -.?9V=X'$LJ 0})^NƦ\67"B8D / ̎=#2$9ne>c4!THHo||A/Z4HS'^ls@`ȹ;U`Ҕ3\#S[[ֲ\8PSU+}!>W:% 1#}~ fBA@/@޾wjqdh>~[8d&Z?Ρmtt|_P??O_^;AڕΊA0׊;*pCcbO^O57N_$lmG/D-ȮJh˃;K/cU^ayl/z2c+!WI4<=3 %Yڂ!\m R3A+ ,>W 7bef>dWZNamNYE5!`a2E̜LL}EĀ@P")r6o~<3:>6%!`~CMv,mI G瀅[}++!#02""~Ȏ,; b*,FlJj[;\ҷFaIp%yk.X #/E+6.b#˂p֑5WKΞb8fH}dp$\h&[*cK3 F\D{'gjX=RA/|`a/對2_ds布r?Lt3 uol/NQ QuBzp+e ~4L ѵJA2x[m=Sy9S0VCm*@B_$A!=ͨD4lTN˜ZPDq)ds+e8B>{ATwR:E3AH3&h|W+_pMu?䶈Kk)ιt`NWJ^ bvNiH|Sƒ3I3 FbAEY%7=+CoUK49l]@ Kd(o|F:Q ʊeӰ[֞pDdPR8թ1FOx{G+cҩs#Sgp=3D:=?.00q3#lZzXr)K3&\[sl^9:E q 2S&4i;Y=XI_LjTHH\)2wp0^Y_kw<@,YM&ҘPrxWmOꂿe`TaU BM,iHW2~ u0zG&=qt26 GtޒYert=@Q,ɞz 7ZⱞIQÕ>CQyϭ qG{,-.YL!S43[j/W رƗ 0WTmO+}E&)nBPUGvgxT\ "O5Z >F&aθDOR?Ѧr3! wX::_5(Heků QXwLyKsz6m| t2NbX!wZt:ʘXugG?#Z2h=|sWWNVĉU]XL6|pí:_zhyt]e%G@:QRW_7)~Hel#`!?z/~3sa30"/C7g*[`Z54pDJRP8jk1[%w$15ѧۚDѣ˶fɣw!.PC'j7H0i 4^\r ,j?mAE0z238I,<|:ƒψk$I=uE6(ץipZ;Kgh61w "l]Hhgg#2*j5(csYmNg1ΚE͆v5$p]nmTFˏ}`:S> 6YJUp-_~=8hڳ{4QPN` }-0tn 83M(ֱb@`eY(.H0z W b}.!%2jv{XYjv7w:E 8ǣP^n4Ve_,">eLx8E8Z˵ C ZDoJ5Kke]ݥ>XV̲كaJV9.!0IH<繅MB4PMxΣ{>5pmj:DmO^w$a uUAtbf7d2.fN7JwzRѪ/ 7l.D1*D7Fn2 r+Љ R!zخ<.bb;'W~mQ[*2b9>0(͍fGNio W*֮1wn#Ԇu\8W?Gl<_"vy\ 9;P!5hx;&?V+_7qu9mFdZ%g1"|ģ%RՃN.Fř7>M+F}Rju-Dr#7 T .D 9"q8\I*o=\E98A{rҚ\<䛷46 AroOcss' dPA61ߵ\Lswzwl@b e'[zMR_J}"}s~E.UDקɎ}ӏ ayp1{H<%ci3VdSWʺBgn쉹~B#9R7V ?B| @Tk[gTemv'OĀ([_\o]Hޣ @AvtkЍ϶Tt-iiCm Q9N-$\@ Մ[֩p>"MG=N[ s6z؆5qbC dDAҟ6[Wt\dj Y-ZB (V)Wʗo!Tsf+確!._ d}³=NE9ium\JƸf)4Vp՜eGrk`Ny=MZ<$QNsFf_8՜#|Bۧzm"`u! C>@pmu|S\ 6[QBXL VQ۸uPY-isp6hf}aAIm O8t"$1ɨO$qhJSDbTG]r]цv$v]9TU;pCPA!r!َ/ܯlLl^5T@OMI@OA{U r ^|!iX|p_k`hSuNkMKw)oNYTT k+$J}29p :ڝQ%!<{oUAꞋ^֞A-ڹʙ7Z8c^PR,QaWPGۂ3eĆl/xm ݰ<3dbO[+%D~j9!sN Aja$oJng?ḝٚ~V:Y8 Yujl! j=kXK ZGU>" U99@Udb\@ו{W2o_ Y=@q+;Sy2)Nn`8߇zRm 㳞^O@|"'Y}JSb$4Ly a=$Lsm [~53m>hM3]U!lxz%]'t ̑zu|)&ň瑻Uj]\(A)sm%G+f,hz12X^N\] rK)aW=7H +j-pdY6%mHE"'ܘh%ĩflvVI|L9hޏ_-~E5\{}@0Pf &.@[ *uTg)?hS~=X쐗C[O)A߻# c--*3nj~Oع |W]u:c<jGa|Lxkb?jڲ]>?Ih5BQe[qG;qgӘZH}D5Y: hKa*Iwd/Z, w_tl Bғ?0$>3@N]c/Ŋ뤸 G9}^Ҙyx#:}|U+!1H+8D%oTe'ǺLF-'H:`Ҫs+5;sy:AȈ0m7ߙO6NoY7/T8-t[rښ߶8g2U^ALq":J{:!k5?ۤ2୅^OS|q1-IԄ2Q ϓ%F rT`C};6Vӆ!JQPN.$5z= )f(_{B }S"_nqVzm먑'QP[:ec~H)5sW1珉0z/Rhl#\()(,crtՅG@=}|hKOuO&)${rJ+3ԯ\Qz#b\h"N~X`х[E8G`0>ٿJ0g(cAo:I6&NP(*^٤]y8$vNٳե 9Mkº]: ;5Zr_SA[FT:9 'NjmZ;1iXl}`q"cG)h_wi,i=^QےZՉ~锺)}{Bn#ZU@l>Rv@gh\Mm5ͱD`q[ޢQ+tSP܉4V3MzQ-~LFIn8S J:o`}ϫ~KbHđiZWXu>үs:҃l sV7Z [)1VM٪o/y _}#W{ 8i%:䴇RptkO/Y7v@Mb<>]rch=ӥ9t")lgɭ}uZX|re E)5AĆu{}f1&{zgjtwS@k)m@&Ri!ٻmU'Y鞙\56N f5]ăY(WT8ny\xw0Xu̼n E"HU/\8N΢!x^fG0c+U#KW߲[!["XZJ"C0kLṶp< JIُ'l3hna> 9MbT$(,;=]b3B'{kdŵݬ\UN߁}߼ߤL2& nVG㳃#G.9\ߒ8\BI{Ӏ 5|$l iimwoMCq}F8YyfQt6k )q~;I .y}sһzY? c<`H_li|XX >}'%.FՏxt”Ŝ/W0̰jv$=$R6 M^ge!jrG B4ծ؊E?Qb3}}8%qwczKJhҍ5i=Ӝڵͺ4 Ri$_|"t@CpZ4QeKI!jJ  jhhIS>F*t8 zE E `,9ՇOs kR -ZN\]F+~WkDKNHDb)ܫ5DHz2 (ĮF XGF|;3u.CRUTDo!vq_ctp>Շ^줊Hw&uAr-r$k:m""}lWt478~VYy; [|ű/mǞn3VL8`?H gc/fvEAhF,aB4\,%xC2yS0~?wڽJ[`FU8 :m8".?5j17Vܒ/pO.` sϑС:aJ5ˊ&7dYN&FI"„vC'kl ))@^;|}l%-H H6#s<8t0r-DGQ V4쓾ӫ/RJTAe)T Y-\N6sYWbmA,흚ϼq5DZŵMvru_(4G G̲ GO`C'-Ri%-̡ =`itYMZ蒖Xl=Ihu2Fš,$hs]vlAvg ߪbDyhP4}G7ĩAu&%K0^ f W&c-խ`؀ BG g-ϢPm8iˌ9FyVLOdP]Er lqHUr "ц{3 5`R$Lݟ\v=NJ"HҀ]ԋgTtXO;ѽtAHQEMLU )?# %4v>$3l+eb JT~zMY +_ϭd'Ap|?a]-BCc?yVAە: `s챾[QǖRU~*fNWaWdN2La7o&ti>l"`4lU8ZH#q\rN"'&ccaVǖR7iO"綤t]tU.v<"'7^0#h \:UA\Ҍzf?:ԯ WhL[Zpg+P ez#"7U, XHd/4s4:Ҽ^ei͎4LVL-I$> XW8gR;ů=fݥNdJ WWu%&C?W1bY @-³}:h By>H_coWX>H=B5b".Ը9S9㩖Df m r^ HI[ Yk[[s4V*X:-m_IK51&e61#cl|/lAA$%6 KHHWK5VJ 0$/nA=gq\^'1? Q[ ^GeW^,}34Sм_ꅭTi@/-9HfϑϔT i띟`K## d5HZ3CҌ xfEiT/nJGA.Eyp"F "ml!f;L3~YI wWs>/z•Mj(& ffoh*GCa&!^» 3"l HN7'Elb&wEb׃M2o>=Mnvz bתR "~gֿx3ZN3:Ў\~9e^muۺ/@Q.css,K`%աK|rOjyW&_uR-Z {/t</y0E@eHr=Lm.jn|.潜ZlHKZBw_d^N= -oF(c| [Pc*ux&̱;q,tu=ٽAnAzӫK~xVN]Qc]ocј<؏H7t. sJ Ɠ"gy)a4諙4tW.㰟>ALm \y.}ճ $6a]tkVgf_`J?RK!&g ,O:ZjSͪXJIH'b,Y1G-֗4cG2P{,C&8ظ)bqW#i=:}%2G3ǥ̈6Q<~>ڢ*=pnI^s Q8M>!}Z% 85Ek?;y=dN|\ԩӠ}")Uh Zg('*!+ eT~˰;+@$t ,QV*5]Po*<8Z.ל1؇'a2zAO%0k$9ʽ/d2GnG`? {a NwP0濨i:aJ5UyG h .t=TKI0ـZ=@b)Cq%0g+l<9JNNԿDa= *89 ;d+sZBXZ4z%2PmGB38:\Q0'VbAn]XμSQf&Gf`/NF%LL<ݩCVȢ~&Sl.a5ٯBu~i#F&ZNҨ{nܤ&˫uG3Qw<#X3~܅<z dKO"궂"*`(i*"E]mzp m5YaW<_aYAo&>N [a!zs? s'@ԃ&ꥅI s_1q4FMY J'"r}'zd-Sv-O>Շ! rd!q6ud~tVmkU= `jӊDB 03p}`{(~f􊭻r.tv`$F8wfmhQn'G<8+72+h3HhozLo}kojjS bC0q!p-<9!( sMY$" ^igذf8`rn(bς]cEOeUg|C9rx Wj3jO+Q%#+J0wE_d_xY/[Cgo1FT&`#O?yRfg ReX/fퟱD߬ms㥰(1ti4YYG yڞ mY2E89r GفMpVKԁGxӴu/n^U tW$OHb՚ΧE_L.ȇW7Uk]QɄ՝!?mn Fץ0?_J"z=$֐ oX/acbdrRZj6d O0?mw8E^R (.5cK1u^.s+Iroz \+Ϟk!~)B3+z5y[ "s*ܗQq(3{dq{#\`t!]8Zc`}m^ŞwǨK>vEII%O Hk@{@Pm;ʺNBRMCAjbK{{FYika WH;45Opi~1/pw|6$ G2O_ DU%Y@i;dwo/ RUJ4uή@b mw[ɷ+Bj`z#h%iY\  K 'dqjXn,oiS 5we5C.ҿQRO%6w 00`#*!g~OKyFuka\DQ-==*DA^5hH]QRU')P (YWIKzb ~\↩VQ{@)B 0X VSLO74 tt+jzAMRVQ6\g Et؋(bnXU,Ұ,<.8^+91z Tc VQdSV*2<-l>t9YAFu$WnښkwZ9dM,bxdԞEO\O-U\N^?'~ܶq~ U'Xa17Z :@ HLUhWyub2 9_O 5<r7TX'OB<9d'S#o2tؔíUO^r7׊"uGtWMt kpTvXF2P֑nb7'pb_[>}+XE6@o9,pB=x{Iު i$~ߧIWha^5nhQyZ34+XGZ>TK;C Έ`BfD7ԥuN#jv4hll?4pպ6+@/8ConTw8#i-R^!+dn~fT(Z=JW5g )䘓|KiȡCPN!iqT=y%p6$T{j{D?>x?IT'"Q2SDtCgVzN0I[_#sVWҘclɉURd"L%~^U"K,OW>cvl,S(ڤN)WҥAUIJJHtnL1kpltO%yYK*ۣt)f`Lh&N,+AaR</h:?SIs? j"Jz>D=\a\EA WiVE=v9Aa)Ryӂ/ ɠJl^^L.I1D&VԲWYim\.]EM~mi嬼#6ZvބgA_KzfO2pUX!Ϣ}݇_n)#yNI@(hz'RqXɱE]@);y," 4,)lTUbWroQro 'n>' sa Y1~jঢ় ץ/ tV 0Z `. Lx#l<~.l 30#ړϛe\*$fnۛw4Qb4q[<ϱF_,7D]DcɒMAU #ṝsBvKʙkN J)~pʙYȆCxz-{cvZCZ ꭆB3MK9=Q-4GD1s(4; XHJJU'5Y]Ά@=o\I{ oߌEo8] tp[Կj#0h-Hϣ\W^(16ANW:3A<7e~)?{ұ).M^3}%E-@Pub\ yr'I9rls' gd:7WWlN#,n|:5] 9׉w`4p^y G w(K@56M*O5niלĉsYvc_=nQ-s$7hwhb Yq [;SpmhsE?t^|{mɍcP%&dUQF` laL2S2{?:'T=wW[H=\UM{d~݃VPkgW`!0Ys_ %Wg 2Oߔ<9*R1Ri#¬ HMx*ԓ{4}pB/B^;!(VPTM׻v1|B^bH$֕NldB*  q@v ɢgYv5/BFٴ kGŜќ-7kWƸ٭)bRp0Ya% d<<7` %I[Y=9ᕇcuz/gۚ?R;zzGKʹS;L#;N hikˡ8l \:&1!T}5ȭD~Ҷ>AY}v"yUnXJVj C;HK&a#KQ?) vgml(M:}G d&Y<5a9HO8AJ~̼7T6v{5RAO<&'ӎG2wWJVphV ۂ9\E3 *9noM>q7w `1WI-*1"Xkݠ u{* 5+Oa]y&P(\51rcyTf8W$c;U:wDNK3dϼe9tQPJ$@u{Rc9̋GEwrR3j$tkbɓvqag5oEDH'Wy ʊ{O+r8YzԳL;e\@m(]'^`Y\Z9GЛkur ڼ0l㉆شe". FF¦KruS] |%l/6X :BlߙLl^j+yra3>i{Xi(X~+˶\95IGc F-wYhDʧ$} }2a~8+z]hb#~8GKzT]XJ6`}Y۰q߉?9zBѝ,-o* XSiCYi0.$f'Qg웘DӠ*A!˄wžzb`̗i i)㒓q`! 8]^u\Ρs~ d t/˛/*7P K^P 'EuGCw'KP;`kpvÚ6 W1QoVvHƋw”\j!T!t`|T9Mi}圣۩& CȆz]tsTUU vsÚՇM,~hrQJ2zN|u tQ =<>6?w$Hpӝ|a`kΑD_92YHR\B5KP6STF h_ByAǞ7Fi(=b#ua3FE]zTڅC=|:?Hh&QJks8(5: "1a+>}òtdmJWLaBLY; ~ D[iK;>ba-3`j&PV Զ,}9\up1'iT%*^~Ilpˇ0k?6%4-uoe/)Cu늰KbRqE˯FPs&!Dp#mD?D \r-30-wJ@Čͨ [PZ?^KW/>M+ڭ<#d8?㱯Q&O[6YEܨMN` q@'dJ%<Qz$>-ۃ>'RIudp:o q~h^fl!%Tgt'a'&:? x|WOۑ'At'efnOD?F=':/BOTS 5SSUƷka#jUqq0 ի_eBڍJO|{/t]+h,G`n+7ZTNP͢,[zQ 5>(DǹK쥊Cwp~ Osc+"2晌vlqQ qHF FDw Kv0VÕX&Az#r%/L\RN>Cp09S+,`W/ ;]dFôqV`ب,RoGlW]TP7 wMo²!#9 U(oN9b s^\a(±^rX |툿;6YTfҴ{?R;*d!0>cO2%7} R uhN Mi!dm|sT^ {:]iD}~N33 4yuN,iZ!+ utO0@69T F”8$О_=}~4 UWBRGc#+*Ы#?x<`,]ʤ恹r`5M(Vc$c"}T}4Z؜g*2=s7w.U߫J?x F˳8gb1+Tq=rg;*҅ٚJ,^C!m 5+?pWno/90\9/@5W^~:(3PWOV#7გHl*k=vqW@26}CMF pv/G/Am18J&vム-g}N.^6nG"錘\oK،f:D7TYы;*>j07FjnmS:(soCuJf˨Q1|ۡ*SD@ rTWUEîݤN$t]3䕤&o1sioW '.C|휟m'v4 !M,z')HRr,:K̎f u;t@$GO7 6ea* 3r0UfutFf =z*C7ph~1uWUaSLxyJ$ KcbIZCh5+Q+IH?#jn| 4{[Hq{%dPc,.V^*QFW["άWbzsl,J 硳GC4IOދHk@Yܑљp*T2cCގ[Z|P1.u`*?oަϊ< qq'(bhl=`t0cfH \z<$>o׍49γSCĺăN5/ g%͝=)N.MtVGX{*$߮.-'Ȼ6sĐy #~8cZ?;*8;w{KX-2z=o +)ɮThskZ=umxsj$=^ۢ B8F0m$w)?Vu>k((O8 @6rh90SmV.F ]Y5HCD^qz7qqDq)%kq]+[ WJjRfӛ4c? :aŒր8e􍘡P9_pWOq }/qv3FW7rvsjxeHf#sJq i!7nM61np'rKh3S4Jq^uU+v7q;~ >W]Shat* 3Lh0[s+=!{qFrAB 43XHKxt톏3O YVX L6a m2Eωnmqf)g:7;>˜$R;71;ȼd[hLbݶs "b0wΐ ZMؾjŜ'2Ɓ%|1FmG'CQm}iM:b`[0j=Yvh=6;vR}IZHuf#28,>y-8:uϫmaXg0JNn,f&1^!62^\<̏NdbSH= lfeE~QǂY1! f1|>Q_7G zNVqP} ёZs (`Qlj KĹ%*s3!ujy/*i\ X|ہՎEB 0@R5V?EsadkQl&6$ybf랅#Ut@J))^>Ekz)W"=`QuO0UE  L_̀Q7{ʮ *ջgP&0 ݖ EXu~S>6%v.(V<=4<}P_<_;Wܼ&iáq X Vj'f4ϬŋݭT F>BF'HEyu,bWbp5fo7m=3.#K2RR1_T!\|Y3hA${nu" E8i)3@5!REhJt^(AUA2^?C vkira vI|)"AWq):-{5~|)'wb;no:y)^<ЌUubNikr`Y)w@GY>& ZV;4K {Rh$EKL6e||% A*Z4alg||& pawUKA|#?O5U#V[g'3re.΍soP<_uo=Y i|HT*А?raK>C]a{Q3a4\Ag?&syFC8`,N}m$)-Ɔ|GۭY˲r[>plpazn̸aVuXtni0r!FKQ9잠ܼ}#.)2P|PIVA<@‘~> h(`, P2:O`T1kC  ?ZDUPL^_tQJyЕ)SVɿ/C$jbn>p~`D*T@vpK3#Mp.MkاHp -TZThሪpu.V@GVU'$ }9N. JGl?q/2CtsvU`U>@2-Veݎ_X7 y*(֌3*nBM*&)fF3氓%Dp87MG؃G}%8edDWr&c'C:O1˟~YyrxEIqJڪ 6v>ͷcRRK֏"{uMvIs=z޼ t'.; 0Bл_TUyÈ7պaOg8STh'Ce]o>$FC0-Ճd,iRz0Ru#/=7!T*J=ug h sH{6W--po1.S TK )hyr%7rB0dsijn VgN @5 -pQq .>q D&A(v%pgg/[ݣǝ7 OٻYܻld4#+u`@"WT@=cqEm1b!)}fxGObvlB6Ur߀ s1.['gɂG'6|B$Kj/9R@rޖP 2 = $ieʋ޳9 /*K˪:XeX>'͉`x!(5ᾘʙ}1ÖB@oLPJ&S(a`v"& &bUj]lBK]{+on;h }t?]/Z ; -MRD{@)jlj+=H ݛM$ ;&Νf,Wk]ymX .rAP(xĦek<T#z2~UQ kI*)kA[_&}2|L"oy[sAM4U _w"B[[R{|x;5-F,~BBxNdA{PϬl{H N VCOaB/9~cXz0nYӜaʋSW4e^|Oe,"ٽyؔAYc 9]wT"-`ةs8"!*-Gf2j&Yni$7| ?WZ˞}ajI[g9u3.g5e:Rz? |]r=~.eGYCExZ+ Vj/>&PM }n`!04k9-%Z*փT<ꪄb2yz2>Ckڋ\ Q;+R]^c\"nnt\U|"b5VӒ"V9S6[\ɯemE\m;H˹ngZnꮢ8{@㛦V4-`wv<)_|әl̓SB}!)_Gd2^{PtNt8dYR>[Y>-!4\PoJ2`z$YN]Ťs Aop@+1– Cf:2&_s[`Ky|X$lđzb>h6DòQ֢课 o3;R)zpi4st6x4VTq~v1$IGik*HpW m 퓬*N`Ѡ|v1p78,!+ eD0z db^)" ӦJ9~`nW74j?е}TBPht)y7\ `<9>e*Nq|,^SLJj0ā2n4ήwsgP?Y꯺$+]/q )X\5>CVrY;Eˋc.&ccsi!M8T(D7kE?hut jǜ݁~k1%M~%cܷQ@\yT3h݋ș*@Jh+LmOh\ 4B 3 p}z$G E#Px(TK&P]0A+r @1D'\Y~ O -Ԧ>JmM6\;ZtW_MR/(\=Q4=="w8ќtLsꔗ#gDTr>GYLDx7;҅9ѤQ/ytL0Mqr&v}"̔7Bk4r%UWڶ$+$}p(& l>Z32/W}R95٦DAҶ-9&qػ!<ã,||+8nI5wMLmR>Y]pʕ񍼎1;-_GnV?lѥc\W9A}#6w#kμ+Y>AiwpD~|75DS@ɵ!LNنeI(|X#М;マqvݢ\`#o%#o7CaH~JQ8I:03.'y¹'qej蓾O y*4ƾalh) >ӑM^k;X$nC^;8oDd3·_XhQ/0NeA.K~߅2& 0%@ȹWkjMTP M|3R%[ۯdm >X0Y凗S}>*1~ R꧙7ĖI[E?J?=Z\\F.KcdPy EobKb.Ry*\M/c`)!~MgHd}څڔVP#"68POvK8<?!%͛R?y{\ L! :8fѐy']J}!m0\?+*\--`b?hVV[9Yj˹Tgz6V*5ʠܬ*!J$7WCupu'A@Y \@G+i>( Go..wpK\ƙ@BE򷁙Ƭ3EW'Voi'3 ה P#j+0Db/k1󤅐<|M w<vq~N۴? +"(l/V@*A%Sa~޼ 8 _w+>VhA[`1_6ֽЛG,ݳHu c$Yֱ?U6R& |0%Ds2ns}N#3F_!n/PJ~X`~dbNijv+Tk`50xCfao5)G {D6 G$'޲ %XSv*a[mb][-\t6 EzϋK2UUrkbTE%#zWbL]?ts4V=,jW~:Zp2 >(vruh 3.(Qӹ Z=y֨u1Q4^sA/;M$1o'*T=Uy1>9̖P8!кhzF(OyYEbAT4 gtkeY6\W)@`؜Ipsҕ%ҡKz(+~@X;H¡/RԆC1xFf[P_{|U +2թI' KֽX`|kX2 b[ޜ W3G.~_VrB]pSɃc!{3'3+ǸOI RU2 v>@bi4 yz` +4,`b ^TұJfɍ m3Rэ]"7\YܙKWvL$,ɦeOuB>NHthNޅOL\R-7S8Y<8Srx7aj>?\IzfBal_ =.=,fjUF2۬ovJsE3̝5##id㢳Bb can^mXK(r ~:aT~w"Ps~ǒZ;q ū uƶU">0}!FN{)NO_AP =+/spܿ\'O4~AH?p8[̤/5ʗ81@Һ3uΦ i++.;j𙱵/UwE4 t\ R4mµ'̘̀4ȥb :0m愔aԿNxvgţ\ԜqƔIÞ(;'iL|v*Ho&N]LշBε%5̖_5K&DIƈlȩw2jJ@7Āx*vۓIчpW?O<NaKI;Eʸ )#gir*Wk#qxL=c -g>Uٜ{8NQ~M@-iV=.b/a%o8G}T1=q KH4Ǡo)#FŢRNiuˁ4w{pEwSNO"iY 12YsͳMFȅQ =nSv/M dcSfV )L+ޅa`q!U\||DMhFoGc$.qWG:1zFm懒]쉳f=W! {)B@ [5mÝv%vxY:oL',`VJp ,*X;cB!W:[-땈r[E3ڒ,WNQH~c_jX^|Eu{DIPˠW4 % Jfn.O,(+QDNudAp"$-2 J()R} ) ̹8@:C[sg{ɏТaOANOxrNG 5٧O”9~xIg"0fHW'=S}cmGythiq,5=fGp3y`yR 'xELad[br/1` aƋ.A( 4:R3x|]5$Xů][=bk8;,Akj{6#QT3\pݧBkB@Z]\G[zB ʩnҌD 0>hesV?S.ؾt :ToJsÅ%0{<5!b3 %/&Ixza 5+ڦtt~-V)sU};&a J)SjfΘN\s"؀)E,Q?4>LXXvj ~59l7=Z$Ib/N9$ƽ&mc"ZMz wI߿"l=nx3im*\#*챀m}₞mVՈ p(GGDG@m7>WVN1revC=m\h SդC8m0?bNt{`-I!g(6zXMW~D 4$m|^|m%)H-dX:)Lټ&.+9Gs1wtc"7j4+#fqYFG0 |,!/GWt%a恎 L*2-L-7ń![Y']|u-#|bZb|s)-4K9:L0uNNZW_rxG6 Vv˱0{}59M Q0,ު/vyԷj&L:Hbih1$Zgt:~|Xg)?GG;x\|ʸF2>PG]D48EܭLk9|,ȀмLv ^88ox,9*u0ZЯ?Br 'b :!J\ >CᏧlML Qkpdw1 ּ`o8:';Q9xQs)7Sh?v5e-V1֨S@egb5Ҳy[(I414Od/gJqtR# %3É5bFfk]IOoEy]KS,p$BxqSxT(y5Gm+%| vQ]A:XivB+lܯ6_IG*tT:Y6cja\6: `FWo+lXZʴʉZBmk1֏Vu{ @fs3mK}" ǀi1Z9]c6rH)Z p+;CldȠˍ@~{{řɨ] m-/"B.L狡 %*u "_O@:*BiXMCdJ*Oܿ]$h&'.6뤴X^0!o~""LC9d`8s]kǦ>Յm{@ \nx–IƏI=IRHJ䢻G3[¥D>:m`M̅_1s45euݞlVOWr\Q5 FJj`6jB!k$>^t]n H o72{b+L+€T Xݣ5\y$VNV8^%urSz6RVڂ31DjX: J㕗㑐QybT dgͱAZc0Է6V <ӵ3NB,Q=XOq7b~0)*AwxyԊSQ3ưZ{^4TpHzL4<{8{>%{xsv~Ɛ&' -HjD{宑la$ CL"jL:0MYрv*qr(j'okRs@L^ iJgC'WgORdli7(qv3)P:Vq%+m#+7DĤ6_@-xJ%cƏ6JS jƿBdp!4!~ %0pz:pnӖ?0ʄCTM|x+-rC&JAZ2QymihiStkY Il a+V2\݂߀\ q  Zg+Mm%觛I2+JD:%Y:Y-N\!S#w)@&Ga03ut=9?F  )#4Sy4PQo?YA2%!8?>x pW"̸F >1k1]6#TCL`Jiѣ4q ;~I[O~ F{fu"7(ro $,ۧԗ@emX`_t_EKd9Mrfi97*si8M@XY>r運GN˅+=E6mmSO._-[&jYgRfT 7nԋlIx\F-0n:bDg- iԊ"OxII'>CEoYrr.e2UbUs79<'^noXߧvyɶXVRS:p'>O}kMw(N\~NbY YI_5}mHC7hJPpx~}qzIާLnD`7addzJ簤PYg C:O:6> Y'H4FD |]ElТ9*{}´X7^k-gAcm;Ɵc)ʈȅbhOQ>ķU{orA;V?A@HZ-Ηi[{S-;_5Q/d,d%YRd~s^ㄲR"MF:R@d`'s9cO:5Wf e46w;/tC^; VCï%%qՓJ%]&׹܃qn,EDf raZ̤h+]kabgRw!ҘDžMZӝ-DKp>+R[y/ܓӒ6pH0\ :k1" 8~lh!u4E>˿Pk ‰WJb*NrP ,kӘcbBGC#`n5Pd< (!l B{05j.W\mrEcO4Ϟa"u6hlKTUӎu\5I.7mwu] صI8&hG![;FTƠ tD"2}:fA"e^F폿u0۪ U\Vv7ҰG;t{ݰ/* l JW'"K (aլ*yӮfW2_*kS0ma]VuUۥTK7PɘذhG)!fAdV_}6:%eOK38UHa ~f*ykI^:m[J՜$óĭ**=Ю <JҨ=`KfQXR_\:rj80IbN BKŽkCֽܷg!zQ8┼.6{WfpRK)DBVӇZvՈg$J9Meե.ս}UwPY09}7m"MJ5SH`q_1Qv`3sxBoU En5D7 _s\>ċҡk7!7fs"n|F ĭ彷vf\(Y yq F E8 ɜ*BUpb[b\Og\YƟCtl7 @\X`G-ͻC"١Fqvh|J]3F  Ξ0Lv'#'7Klƕ 'fdv I%_eTa{?Y/HxmZ`{^>U<.W:eRYO\:?yU3*= 8: 6ؙ),Ša8'is[򯔔Ud)iNɟ:oq u?m!p6-Jm&Cϣq,]2ίD`@AFqkڦwn<Bj6-ѻQ{Trqqέ|l_Ru /CW %Qj da[ .~[HY!&ZlŠ+l09kZȱdï\G .4B8"/iƷ -I~M=[oM[d[l^ jS:Y$pzϻHayju [ɴ&r3K7(Xpg{7Uny女U&Z=Njd9]sJwQk*tw("*hN+ꗠv$k]?wJoWfH }a͡Nk(vQZՕ ĄP zJ o@#ѮH#BשS~tҹ{l9F|h|z(oO*\n 4X9fyg a5[pDu&"9|io1)cV zy\k&@׺A֭B0e^,u0`BrJ ]A0v5Џr}u>[y@r6R|ٍ[8hrb*w%"q9.>WNQ:K-S^V_ߵbD*5k! ݘ}} ˗X667>|c9fi^wi0} BwW8{cuuJEy !!lA DЩC !_5m=AO҈n:;Ɂ.YJff⎴Q~6?h 8U> 7ۂ*g(Jfxt>ez۱>;Uݸ+)# -?؊9Axr}bk!8M5(yF4mijaP\&Yz' :oL5w<ǧURX7^DY gYc$y_IN;AZfu<5BZz vŁ#E{IA)z&iG'1zIB075ɿ:> OvE][)8Q]SOVPԓW5j y9bVZ `YuZ Fd:Z<5z .֨;l#7SG~=wdBnふdήFzXuuRRr:8.`m>M3KnI/qcjqv(R8yj:2t؈pE}0J(;fIt< ɥFWVfX%^veOiT7]%i?UC1Se~s$ЏqTG.:5?4z5_Ri'ơRpf!3E-W!x&)m6O#r'g-k&-=JURP ݊h)eoP bta6TFT _Ʃ Q8/O;S0u%]=d // ӭ(6慊~>I| 6aTexn>t5@%RiG6Qy-dzCЉNmR ]"a)êG'$ VB.դrK#t"~4ycB=57Fl?g룈`;@Kńz" I3HEcn1V .4`jJvHq TReoLΔE7qzQB'I3Rv'ZIt3[t@},_I"̶Z'kJxǔafM\w2 Ïa%Qұܟlq䄨.d"][w&`a1as--,úf#Q|>݈ήJrW(aލ &!YB ipðDsR@1/5OCȮ^썧SZv ?jbGyB:╒InC" n{ cVN3ækS}Pf d^Ew`Y>{n˞łk Y?erb<ݵ*:<CQfpɥ˳.`\) X]~a:yk4_ȉ % b碤E O/SQ=16Pf6BK=%@?(CEYa֑ do[#FљbY͋ջ*zrj&*7a׺Tys{`\gix{ƏfxR 9ź09u)P!i|f#$]H<28A+Tr5=q D">]e5G%QBCEB ="E2} 5u*/|EHNY/sP>%ceݪ_u<M"C4lm~ma#pR[SAÄ"nk|_n؉Ve;#82V_Hu sR+u*8}>m<{.;}"DU׶ 5ߺ) nY14Qn _Nb=o݀ks&"W|"[Us Zװr`io+J (s$`-/=Bw !$\%f cpA NqJFfhwQ͌] CweS vG┋y3\36Ǘ}}?;q>+0wW mz=kPqYд{"؅f4gE}61Ӝ[\zO׫<i .%9\#k,抑VuEskLG6vE~CO4ly=O8EOiJ9aJƊ ɲv~Ȯgk{-s[ߪlƭ'/M;S5iPŸ ץ mh-1Rj#'&cltNpG?s jK:hQAU$lE1Q 9 7 mh+id#&MCH[ y)vš{J1sua߸մcm:hwfUI8$!xC4 J>.^ {(XJ0ALOb\xʁTag\2SY!aU(SH$aoxuMovTU[eh5 폧i`l0^%8!a` Rmr4sjeJm{a1N jV,vw0r#U~;So(:rװv0m$\R~h]{7;~nQæ-Fxj2e[j7ӕ2Y"`Ԝ=C[TAFtHJlD?aGAkfqy">VnvcΏaIЧNOzù5b=^\uVqE{aFMgG[T,Դx#CG#f?I?.L%?x5l9}\_Flo7Nߤp"[/ ,XI BzuD2BM__A>V_c25_QYсHRHs %hz'>jXpѫ>AB2@H*[Z痚i,%VNƿ'U[,3 X€N @@aEw~<8 c7+ "V|Rt!iA@$ǦJaEH}^ܜfڢ%CHԮl4 1?{| *Ϫ0! }Ji͏aq'ܲ(KCClDEhƙzc dayĒ@^$RbQHշ!hbXkNƛ1E YDp{O{ړ`%/?Hk'nƘO5Ȥj 3MGE ڬɱ7e wj/s?3a4`6i oF)lO7g;bE,C~UݡC[bL=Œ\#!s@luZշ@6>e;])`lKW4tkrQlKc\wR )Z Ɵ-}ŧJQރkXdOϓYj_CXfb6Q e3jqƅ2Rz=!v//Ln'+1 7ȵJ̈́ _KG J?5^R5ECp GL `Cuc,Vd9#;nRG!5"Ff֬ [A`v+.5=NgX67 mjve=]#I6 S!DHfxb%QDp.`b{BSru_=s!r\IJ{怷 SPѱa̼ jl ) 3'X\͢] sT;Q+f*(+9A7Pm1O{Rqͅj`,VO>|0S!0a0pe;n\Q*Z(7Fm7J ah "aV]<_4`H_ *j/'\Dk6͎/}Ƽ tCiȋB5juZeC:jt VFab'>a÷l_l;Evu&B"EZop6ؚ9I 5몧U4rjwH-"'c+iЂC߀HF݉BgZ> B VF3-8iM/\L g8gF>1i0{7仪1q%kY ,ne )uJ!K^~s RC}Z@s4ȶkYz#%B ]*q6F_R( V3n[d&=%/fVUkp6Exnŭkѣg{TT=5"iYD]؟=()-ӬmV@G;~sT?@jA. {*9gxjuyͣRݢ \\O`ִ7LD/9C$ы[Z-7\`>%Z  1wMxQE#SYU(l٥xSdGhu Yg7ѕ _וedުF M7:w$YHDEj}>V >ߙ ]S`敔p-7~y՝8{j *I%T<~-RTq%Q2VRj@0YP]9[+IbC7Te7>Hobm.2oSO.G؂-@F*}lNӍ<AH ;!8|$4 ap+\+ ɸX12S@V, 2~+Y&=- '8 lOÌ?AY*Q_Bzಂ)|n6,.2<:KWRJKjC}hCM E |!2rpZ ؈ulpY|[-SI)x {a'Ѱ'gP $QՒm=z `q$雰g 7ߺP>]k֞"*>=:L ) Anӽ,Q{d8$^*4c?iYX#;-|I=:Z+zٸX&`/ Ƚ*EH;h=jpn!M\Þw%_{q%e{pTx:CJ'E䜿f=$gks蠦4LNJO.h B6uBRkL4c7Nhی _f\+a%󃯢d:iN|$ȇEu>I9C8ZNNjoy'dW[1Uw_zPTcvGڋHN31s8529wUd3UΧ[66%B ѭrzifXf$Z=/.( ($Pjq/ 7Fo`4wP;$O!xA!,9Jڭ&x-LW8O c`)ʠ9FiGlSۤ`(52%9RSs"M]HqW.Ƥa16{! JN'.pcH[`(bA`@:M5|X= )l#$h|8|v_z[sÒt7!'A |`RPx F14QR!B$+S,P%rwD^Tbs\IAUD7% %FN=ь#;8 J͸Q|7IUܽQ,qk^ T:TQ'ba!*i* @'Eq :tyñrv7ͺf/ۃyv\3;m˜T,!8AU(8)?^<@q2v 穜QIrI uo.*4,P*Cm*N\ Ξs?9jW d9\j:Q+Dxj9#7v(/*H#L$f3\p8ap[e~i-L3q_H[m ~oojZq[ ++͏4H5 -MÇ) {g_\4 *[#>IYFxN^3(O09`.uLlarcYoRP8y7f/b, _)Q~u6璀pfooA8 PH/ғPq5"G\Vzո9M郈/21;uV+w]԰O %1I#t~ !< ʊ[j<rGE\f#S /}$`~~μYn!;(ՄL"#z =p-PͿU:X?eGKyϜ.j4s Wv0ѥ#~xȤ#!yf>O{j8hps>NN̆Gѷ*{TfFXp@ a_ٌRU?UiH#rG{nƵîp5˴N(1?Ak)]j6X bK~s+Y\Иr8ϴްد\Qj#u}YGr2%.hNIL PKm4Eȹc;2 '(PbiAZKVβ#&G5zA~8<λ0z%daY敬DDŽԅۜSGݻJQɒ>4Ǵ-/ @^ډ+Է}FbqR^|L2eiXإ!]9Ğ<@k$nyP5V&0\^yO \삜/T*&T75e*}Z>n`! ?eeSXGzJdDc/F[= ~A>a()<֞[ 52z%`Cf'V1.=z4gW.B5ͣʯYeݍJ dsxp<$`9NO+#^[j*P }i*güU? fmXBE/b$HՖ r4H901/_#W`^`Ws_qHq״D%(||Sǹ2E]Z^+qiFu a9Be"ByumE| 6kQp[O=C|8z#V6Dx0C7ϺPe"y9h%wYOq{g!k f0b-잭z`*\*,۫]aOn)sIǓMc]Zb?d au"?rFur3Fb^rʹsMyRkyu1hLCS{ԆFh;wY(mƨ [ʆ*KG%fCjdV8ğ >r},`~Tɮ'!nJ BD^mNS0;9i&lkPsk+JO,&b#YU,~ۋ@ȋern 2Ey+Q2Ojo| rm{+W1hJ|jßpzwe Pq%UiRGXhJ[&}i| ݑuEjѻ.XUI밵?-йkׂ>߬ $ȗ@`\1hRQuIThCۻJOfZr?8 U>KYggY3E 6fu'݆%dUoKP6,! >~1m@|Vɇ; 1rD *`lci8P^5'#3AJ;#%I=wW&A-хT]#vg8be;j9W=,(gѰ| M8ao wG), (D;Lkx/p]13J6ޟ< .*9_CUg -;7 ^)^S*|ICbykrls>e:|iו,;ў Ӂe ;U19/@ETS|)o o+>58D?';yۗNH#ixdYU&j0 a$TΟŀ+iu WD#$Ƴ B+G\ʰ-ƛo)Gd1dut(M-?"05Y]ċX$u 1P9zbGZ?h=-م*f)Dvs ~Nw; rTwo,t Z˴TRt 8v> 9:"^0 #Wt}Θ 3>cк*U4nA4w~D䕻qpp,ml/lʙ#'n8ig=zIw mT{#pC9 dȧʙhW_S_^H@fް{wNmKYOЂ?bU{ `q b O-E(zAbƽ`/|R~z6'T&@-z?jVCpE!{ J׊0d"Z1g&g:'#FlFZJ">6 QEVkg~.]T*?ȇ E,'z*IznWl#\CPFAyJ&*?T֔)P+џ}ERgЀ`~^ pov.$`v;/PRK7K̕syN믛%Ţ} $4I:TA?ok 3Oaq H_P0RXOs,In)qoC9Lm(0h33L4j B)+@(Yvnuy槠 tz pecT`Vuo(͚ZGbK3W;M%?Wt?_r*}ecg^ŒѓKTgeu-*O! ի6&tҌdӷ92{63Gc3[j;-rgӍBd=f+ԅ>2B\) 72_:w!ӌ,Iu(㉎X݃y;8y^yc՝6KrdC0a1/ih\s՟h xAA>#6@/m) R6$|6:U%O譧7\'%/Oi/m(}wzKYq?Ryfu2^; f1[JA=[]3CYv+RhIGth4huJ ,盹 m:gq\zr@˽u@|"9V ~_Z|Z:ౠɫsV_*6ݝXF68A&8pրC^Wδ&S:z"ͩpGsob+İ6 ۿFb+u?eɟ@OXJm䭧 Q|W$$drBHlڃK?e [^' rBҿF(YZ9 ZL¡,pǡjςITV?1GŎ̽Z:b=t~-"KOah+ ,ryK^Y>hlwJi\nݻ9M-$%q\Ad hR='IDy#, vuL'CZitԝuMaH@鈷Ap˜~݁2LRCo#'ke׿])3=ƯȔ+ԫhТu z9A̫y.hqv^;Kˬ=S>ڥ!hT,'VOd+cY ={nWdIOEÇ Us@d ) ΈL듟4-vjWԥݪq|V}#sX #mܕq{`1$,2\Y5};h 3o]c?{_LgQca|(۵3u2 /fr'\ݮ͛ɥNT* /+7|L^ ++0<90N[`чB&|'- Rkb~u:6G,Hk!J FT_O]Gqˮ?LXY)Lv{էaTGpF7d.kW]XZhX|Ȱs}'дU)-? ʭS?Ϯ`ʭvn$gRhC,>#}a j;q$`JFI e>h9$X*M+# sG0f6ݹC1Ѥ7mP;CB8yyb,}͚_{KOHdi*?b],Ka|zóB[D,C7(*%Z3#O gNJffF^^ @ny cÚO$*lTir|qWu1UncO_rWJE$0mZ۾MUuljwquR/u\cyROIU BFaE4Ou`Ijjճȹ+oq3{鯢wzJ{4i=x\n/ӞE. ]YE=~qʓ:KUlm6BHMP悊 l#(-b㯟wU2`áR\&3G|fx]N\ W jۢ7Q5aV+P%_`؄1f 3A?:j8$e+Ls-_X^qT6(uӓlP Ks=/t[ĵ)@AˑOg  ͑t k#E^K{&zn q0Bӷy[0QȐ%)) YvD Rwr}Lb6(+⧍7#Ntֻ<WK~Aw3ehB\|Ϗc2tnW `H+eZh 1hq%z=>tU ^4=k `blÕUsFR BաeRR1 :ݕŨy6EuN^$St^HY>٘UR6`+a#Z05Rrg_ČK)3s'NUH0~z*LֱZ~oo`38]6GJ+1X\6vHnAW <`^}y$heFu-d)Ѵ@A2G:iaTo|GM'3&61@QMuHNdd?`~m0ْD-YJ)g%v\U Wnlg9t;&s.u`>#Pu+[{>;@|Z2#\ut]d m@MwR܀oGCfX5$e=JwQVCRe\ ^h IEʹ&bN#0`Bg竫y@A:8Snmao $RdMiN_ao{PdbКevV ;CEaLcI/<>~ES@'}cZE=Me阜c#Fc^9]bl%dè3z_6#4˸α FUɘYfN:Mܵ"3z-@ʭO9>/U;{z(6*Zs!"ɨ tx$xA-kZa)m9B<B.='.0ܫ0[u5J]*>ad>m[e7P~oARax7<07 w4ђ )Yjl0@%@@G`M"|iySƱұdy="2/NR\](zKԽL ,;5ysu+5~<>S?8<8\a+stxg/gLJ^ ޱgrҧV~( 0𺠸sܩOD*iDG! mK,-j;2k1 ,.A@ 8aڅn<'PDIf04 <8e0bubLm,>%%jp|]ۗm=yd';]`zַ?Af9Iu8+Dlf$tnuP" &H$1U.+x*zs š:e gV -&(e)V!ȃkt»6L򜩜>ZUJ6GqkXz1KR;g5,WEմ:FwO,}xVON$+j .cHu n+8)Ԇu7 ,i,!?Q3@28 z-b\Pk, "uܗEu[I3#W"t\:A+ H2Nđ {pqA\ M vSbZVr9e(oW}Th\dDfgi%4Hӣ̂WgkBzaX= Oda"$fIEJ߄,V%KqwL*mQvE5g7:7}ED-'K%>'|80.9]w8ODzǽ'Mgi`Sui 6ʋ{({317oȨrbB# ^fĂ\dSo!f4 G]xi|V䮅7тRJ$s%E[lPvʊb惜"0O,`mJz5u{sGZLߌ.N;xR/&T_rgWDJN91\|7 _ؔ*E̘MVk8]*9Tw:ЫdǠ4}_0"!\HP2C\r7N =T55x^C$'J'{q^gꁊy{f&*=̽G~S]_۩CDW^dxy7K-wTVM@Q~o?~3BH r8}o@{?]k^$1zQYc=-RcN;,U֢-j. -ˌ$NgANuB,Ɉ}iY#6|,dr=_.]oRޫl6=fŕ;}#\~N#nxӴ/JU|%<ʼz**>KHoȂ?t E^kl+hA=>dl׻> %8Ii`pcmx zU<ƿBʂ7C27X|5!@(m̲eq!󹾯&/. gfח)yY IC&%i )TDYqQ TiXZb M :z@6wQ)|`]"B\)i9 z̻5ѵ7+yZ%`~=ףAP^.3;0NUP?y%N٦<{ڀZ|a\.=GJ$DW7g!^1HI2;z喏$=j[m#j[LO eZ ۙ%fd351G\ZV6ZFIBbmi,9:5C_Yu$n×银Oސv ;HGn]V+XTXz;gӗUIO8ޔ<jc}5*=y0&^fRg\z&|Bl6W5Нڎ{H*' b߰,HP#6%Q‰9ܠ]LW `>|8KEnZ-ذ]{Y1ĕr}wmPo2@n$}3^RFL νl^F<9K\Fg3 &}I6+ I!N~cnF;֙jB b RE|9Y-cR[bgX|FV|gWb*--f }#­ 3Rw@PwJ/;[` |F2X;]|n$wS RW1_%97PwPƖPi;7e[ ôz|#8vu>[2kzmKvzb +/[u>vD~6id_AkBbwD7kᅧt`!1\՚rʛD < +Fm&,^ U=naET` ;V(*7|g_ޟl}eLhKVјT6oBlg]j.۷k+mn/Jb#0 N&ڎ'ۙPr =q25;!s(Go¦x̊o2>jTEÐQ36)sQbE\ Pw _e;O~>t4yp4_ЩEorzǃ<Xx8G6t<$n/Ů"iW_x^tf30{%Tr`"#UE)6B?:Cp3qnz1RH2)$h&*'cXq+DW]}7DJ>Ai:\Bm|j627]{@QȽ;e(r N|3"OHΖ%УMꎛi(ċ?|[E-\(DNHlnY7t:_h{rGg`hJdqmS{18 16L§]HyJa2}?*[#Vx'0z#;Á!S`£أ(5;w`m704! @3 ̈́/$3CϙZ0TDj)z$.itlxDͷ=Y>> ɭzWȣ TaL9D;b\m\OkLmnB{iYr7h!m¥bejZ/\XՄXܰQꏋi|V+ί욽חTd,4Ly|h|,0è?n= NkpYLF֐7!#ޞw ]/G~:a4m+8F:EǴu3 KTIJmTŞ[+&w-P+y`FyG_wp O mzi鍾Xf3'1ү)a[~'11tAWi8ޠ R;A{°_Z2VITSCt L,n}V6Jv,KbY̎dDZ+.ҍ}߻; %|-J0erPk&yzwh4t_&B;f᫅ڕrlǬ?5~Bɕ⌿' @>Jډ?|0/*ؚzqbwq1cgw fAf&YjW>`abEGj.f:%Csՙgs-M_t:N8Ӱ,j%ߩ^#Ϫ]@aa8^;꼤_kZ9mǢ2^ań۴ر/<;?1pkb(^9W1Qauϻ!w+*, ɇWgCrG7Z7i>&n>21s z׻K37O"! βR)BƕCsgHvD?Mh"ƏEG?;]pT@Dz]*s`"ڊօ!;H1Vr.ԟ, d}t>5!QiL-%$i)XޞQtڱRVHxw1s%T"Ű V5+BSx)ȃđh~hV?GixֈCj_H2@+qAj+Pr*[g9'E,?6R/f^3X6mTaJML Q)*2d Sz_bZnIN5z%MOeQv`gO/y!̷^:U:`h#Ս{ڐ!*雋( + h^; @'  =DB9.t o'JdzncZp7+Mo#OHfb;:}sHU&R4tem3 ]-% 8Ͳ@Z;Fŝ9.;cNgre?D4m%~p5hqccBqг0̽63ȍlJ D=xP`kDa(_5"2GN׭~}#(:B ! O Ej{09^AvkK!` Jlh(#=kbR7 O TIo;aw7Nnػy0[ WrJi6jƁ&d ~i>Lyޑd<̉l#̇6 y%XYPrMi=b*u]¿X22n%=*c!4ogO^I] /"9cZhJoI%Y9יV?ANhVhޤe.!s @0KF*͏:rT"Cy@!S> ;/,[Mgde2q yMT_ldDxlB&iS[_xL 1YȰA;  #[#or[sw12b<݀qUoBa#sCwfH: D*59g{"^K,-TGmKDZA/Bц hy'gpHV*i|ld|chR9\ '?KgjPbP}N3G 8{o08¶% :`g%u O >v͆Xt.;F` ݈-ٽꈫk's)cmܷNuqnT_9Yۛ L[OWT 0o6· >'RMYu+dgh+ru-Qe/WW+wڡie}͉#(޽"˓l\AAm{&p~Jڞ ɉb뛴0 JXH,aF!$Y}ܰbguB]!ffZ9jDzUO# S 5I,?5 XJc| ^-(N zfԵ#9vaoDS֨CVk}IXDf6 C37)JXvr=qL\I`B{An1~f\U>ʸ8P?>B!tQybQtж-RR _ޒM xm\:3Ӭ>z΍&hPQL*ɓ6RȨHzC&ʰe]۩nUYdL D!y1Zc2[1}q]:FXӻ{yT.6ϱj0#M=VcE+Ȉ9W3Iu)HK%&mc>WȒ }WF}GZM׫h(bvm+z3AClܤ0&ka$tsjT81CVNjmVG!t@'RbJ"atZ^KKZt{/Okq#msYt}]Eq5">S"E]eSEk{g5V,Vmrg4yeX?ěg^V M7ػO[voͱ59ЅcH2KsG N:El;~pYt:L`-*}V ׆̃( OelY~.l~0)?A?Tc"oёABOA{zB`#7 21AGaxVR^ȕ,0xW/uF6c2"2!F.|X!X9EA_Qɔ~; a[r=k|_#KgNl7ߌ~RQ f#O.u뵣mQ !ö9CBzZ_*-s)PoBRUOa9oe܎z2Uy ڟ_j4j)C$jlh< BshL*|sC&owe:oQ<2+"HŻEAD76"N]4JᤣǠ{HUw_LнYR=^HѼ; }]4b>Z%r|-8J'W.!! goI+Rf۔@]AN[Lb Uxl0UU+H0Mp-!9mJƷ&NeC]^H:ç+out MbhN]83.v,Whg4 }U9Gd#%z hKP[;P@7("e#1hJ `tvTpt|7/@ 6Eh1' #=3OU~ccvyr_țɄq $Yh0m'N.RYCypOϘ'f7>-Cgk?c!zH?{DTHg%ͱn<|`rG[=bN\W%X6, vZie#[ R? 2jl8v©2j7_}/&U5nWYBl$37d717afjWU\V2aE6*)I6jHx'…EPvnwCAׄ؀. R9QPLr|mStB:J[cߊv#RIb g<}݉F5S\óRߗCRmvri@Es}@ED ʩg= &{ܸ [y,:2ۺR`oF)^o=48v%r^[YpKտ@ŒHdZnނDhlGH 90gW$$5]- fTfO{┢@M5F'?l+ۈxulx§qnRRd~5ٲA|9uO hw"GK?yY.OC1,iC-Lb`M#"lq%Y*3pRs*Sp{䶭!f8O03fy=rk -Π_J-O"Sz(LCcxƧys\ls˵Y}X ĉ{V"@f ~N63ȼ>*˞{=Qhzx-X P ?mΪW7C_F_^xHeRKܹO9lE"nMrZi FKAw)Nય~Y;sL7ZaDu{-R,F{U[󜤘sdE߯Uљ9%;p,hyҾu"lzG؁ii.2Qm$C7@4ߝ]Zǹh.=Job*InɻB\#Y$'4N~(si ?A+ǖqU |\"mS14@."+.\&S1sd1ڬ{v" Mxm$J 5aV~_rNyf21r1iKqv6Y|Q?TH 'C2G8DC垌`W*Ǿ".HOl[tZ*1$>אI!U/]}2qekhÏvmݐ5e`A?]to]rZeVSw=f2``Yוn *URk؋:_f3^ds} .m!9eDɱ%\b,g'د 8e8q7^qQ}!=A#夃~PsԂٗePbfMS 9ǖnjJ{IJ`lFs'tlu?Ծ5Ǣ[%uV IR ڏIISOF8[G q^뉟2y}`1$pO` -&@G%J4% D0ؘ܇^J>n" 󦵱tμ/žA(> 9D^=ʬSB\sov@#U@ǃ6L- ^.exā%=T:B},8vgj?dtz@WUuӾV49ǼQb:VB'N3D3nHsfF`!k*yGteUIfI#x!ڠ:$\5,_vN۷٧Q95j MTQ}q՗>^y_x%fDg%)nwt[ISO 9hZQ~nG:0M,xr)AŢvHN:Lw<6˯5o|Q()~܋U Z5]M2k䬞fum*&_PJ2ZDV0Zt.%IU o{$ 9Y/w4i_~Z1kb!Uv5ShEe^Vb~lPq+єGBҗ(_9q7\V[<9kXYt}.I15#/O.Ks/>Z0BK;88K|юM,1 %pT ~cuкIzWLjSRȶ dVLg4p /"ׇٱ!8gWsܽw22!"~gK:"\Po\Gṭ3Z2_^@т)`h3{im(dց"=MH63y ao(~6u]5tc'N>}c%?6I@CsfJ͎oQ=0|M$:]9}ĪX D~?\yxBR+ix]łnrL!46Fb }swѺN]{ΰZ&D擸c8MH$1kgt[]_Zpe ~ᾲ1" ZL`&ǡ9RC fBT,?U NV98W|VQ _Cjd 2U2@!e`ҟ *Ow-V@@|D#@fv[;F!^ W2$Y-)e;4cld r"O=@ `"pBpH]=\ZIz䃚qAMH"IfHScMC.uulBĀ)Cc>>,9i`mB$ 9(NA%WqV@ͻ=)8% FAPC+ Oݠ}964 2pB]{լHk ]chxŴQRb*)}5(`CR>짬JsW>`^݂~ ^dzfT Y*%qT[Ŕ-ȌrBB+nvho62) Yk9ZoڤI΃Znsy|ًrб"n}n}<=M9+rO2_! xa3yw{nܰv\H QymP M*e&Av"?ɉ xV+:"N'ɧLg_\',@AR7C wdFBk<<(s)+GN7]ܗ^0ZYE}?)tZ-b)fCGjV P_@߯_7"v*y VaSqJ`-#@$& } (x4fHgܲn076lU,]*%[loϕ<㩻Uf7`}qO(l>Ru<ѷFQߵL8f`#ɾC@U8 /dbxDxYh6eM/#t+z`1i_^}2kh~md`ɉLG Fct3z&ђ;UVF#o#7iݜ2O&'~ l'"IZ*Bʕ$|b{\;(ӳ0X-+|+rgM^9Er Iq~1SFLZlq{{6掦AlvvQxmS;3oT#Z~!t(x{O3DgcaW~~g}mOrj#niȁp K.^7C^NCv*`}j*Px6,)HOp]}:KZ_a#_Rga]t hKR[:nLq.)ޗsxRȎniGYb-=rKwruA LJ_s*Ii[k0ku5eDG.T7wpJ܈aՀ&ָr}!>9zv\_yv 1,5~H#LyU^!/yQ} 1%X%?UQc uBInXd[ el~8D'?O+X-B]“C>6c 92`=, Ӱ6H;? g9Y+:ɳI`t ;Ϫ I92fIl 5kJYY=+#+Dd$ d (7FWe HOx7Ϳ&~0S,.UM,@NM0sΆǭ4)[/qȋsd?WqM\-G%t(BQEԩe]d8 {I i*SjYW.VWs_o6"%u5{'XY~5_xX20'H4q@i\<\`"Gb /WngcGR^2'9 (!|5 *ޯ]MOj( WH=fSMUj֞!L(^G׳܏gT|'c$=LMҪv;OgZS׌h27 h]ЧUƻz8aY'b 3/{Pqp{ zV/?Ia8 ֭ؒ!M(祕NIR b,$]@ eyk;[hwז^l)re4 K_Q 3x;WBCj=_3򲅮d_]fQ˹YJ]ǡqͦ?ĆM;$~jMX>Equs: j.(FO T^s/gUk+vcmk!,Jt[oChy3%v'bl+/40z3MNwş(kya x` e|1 g ap4{,,7MQU#9x'a޼h)ژ=cS|𔢂=.{ĸ-X>}=ڙO1sR6k1GB4އ,bM".+1pB:C-8SsUaqmNIFV.8]0#-1>BO,RK`ݱySj* wdkj+{ 4aeI>rR=gf$ 9lØp6- kuݍ N>#%),w[zm'ޯYg)t:b'Vʯwj<pYyqeHmgBewjj Hmpƽ_75(y8-P@5`]:$+-Q0jFnjؿ/&1bղ5}vPߜz{g9PpOXm(̯RZN5I Q(QYtDm%h'hBAc g 1X)y)J\B$S1`I^: xhiG3;>6| 11U%OE/$(l?T!7F,hj.mH)zi/N(L#/atwOĝ.VʼnM=/Z333A;GT96) .|\z#Gˎ*]hč83 cM.كyZlË-&̍83 Y@Jw|1*-=ڣϥ҈qʐ%T[#PЦ7->-oX^)5cRX>k4gӀ9>~|@ @!RkV^+,Ṉ pZTT*SuX.86an:$ݙ"g[e&bh-̄A_Ϭ"/-P dcIε %yWIpf1d텻@Hjn_ >r?*M C81 f-fӚ/ ۣf9n<0D?W|cǵ,𘒬vӘS:SA`Ndg,# 5zgSB>IMxB֨UV1-rWuGj$i.{PtA{r7fg~ (4e%w0+UrU; |οFKR g;]UkP㇥qءON'Sއ'2]J[gU/Ɋd]j+gmwGfzT~ Ԩ{(&XZ#{o?^&c}!ȐxdG6PNdhl*`x16˧Wx~gBX1!0UaqҌ%cf`ܥclKjSg0b]Qwr<P'݈%iJ4~X;3TH>ny}xo@99 e- D;uȈ5WoSq !EQj!Wx&:i1 ‹G9|2z%g.yOw33ѫ7 kO8aCTO$Y~]:L0\ksea6a@v!WVIRW v kś D<R Oy]3Uc(G',`^!{wfjDf.: 0p3?U5@xĹi5)W: 8Վ8*Ҽw-?7ŷLE ~Qdڋ/ "/׫K9*/5u&9u]hpc DͶ.&߈?%WtERKѿR{],A,$9z79 H,~8vl6S+'],J,\$,cH0)Sx}z+oK[icdY-rs"C00oAᆵӐ}ޢ;OP+pɁɑe>SRǵvJ+R/]6No0SgA wn \7_NpFls S4 do8R2R7f~\~M[q_>\~3*$u~ /$O󞬿rBWսRh|lPZݷy²s sFgO:F}&F!Rl=R`}Y<;,Ex+$W0]E)?yơxhmsmYEKyK !M(/zN$ߍAyҾ2'Q9H(SPW'ۆ:D;tQJi-#/@ֱ;v%">C/p m5Ds0=XG]5)E馪Z 3 /{Gi+zVGG;p$X.fhO# x֎+L+XU3lǤq5%F-<\NʦULe ޙӋ:8T#vQC`S װ+~xOmZ^IHBDh@ ]G1KE\-?=4sAFBv2뿹iahW-9>QSߜ? b{$ILωwwZ T *\T8RsB,Sۤ?^~gB+4{y]Պοy{X$g\OLL3MmOKؽ3Bb츺]e0\>XlrU?HE`+mzϏ?^ 5 kGj={l#iG;+*3rk28^qf/03=A]:"Jƒ$Žgqi; 1DJC3=Neahm`^HApxA'n ,eW ਩fW5,Zkcd. yqd.{`7J7&~1<,2(ep kʈ6VAʳ̂>HKCjt 0ĸW*} j X4h]tJwONxE>)6C1lE[?+۲ 30bλH%Qq~ 4R}e-d(".&?ɓ~ן>:kM5p"~ۻX|=N8LkIk;<"!C}UeI낅wjЊ3(%EKʹ =L֤[Ĥ@YعT8g?Xxuϼ_JJBw.D{^ׇ` i<[ѾsQmUn͕B';CkB2?[/ RpU?uIu$3eu"1^b  .؊GXE˽}[vE8 mtJK@] rƴN\CYM!%q8#YJ5Mp$`jV ?SWwZXaXCB 3 mLPGa/HیDGepV N<ШH5شWưa]W(VpMNviz(csSZPБTr%dW0u$R3!Ov\"Jmh#DuuJ`4^j9,&P˯Gd (|o?D%j fyfXJ+| ˄h%l $ׄxZ'[dX)@"U0RJP4h؊,' X,x_(/EBHg#(`G1F fQ KsN|C,qfeks(}@P #bRbMzM.E1Nes00- 'gZEr2So_0$JF|ڍ9ɗRl%@8ѢXm{ r?;|e/ĚN[9% ~d's(p3IM_Y怵 ꬈PNznŜ\T'-׷HB Ȑ,0F>TEbQi3Bo7Nb-3x!CCw82<4>Q'8(΅'J, 岯~ZVdԂ}g!b5? K@pZ)*sܜ,_"C'`sZ8A`c ձ=O6k`f&dIa^,B2s7"EvbptL\'fUzkkz\\nk9q77v ̳ճ e+^kreh.a:UUڙ:fҪD6Kg?Tg֭fpRZLi3~Ky oU@Vu * Q%[@t7٬99HRw]IVwV2FiȺԻ| .h6IXϐϭS9)y I{LMى3UO4aR"IB|Xٸ)0M$ƃNr* E!o>N `G}0bFI~IEJ[uuM&6jֽ_v9;Td5>w1ɥXyBI^ uq\^2ST Er@Sn3YA8L˥3q@8d-gx^݀|OY:]"5(ZC&w↑9RmVLWǜDK47PnH^ss]Q_Yhci0}o,X wGh$R`ϓj-5340ڣo1gj 1OymƑPUw:6f;{9t]Dzu0] dYabi ֶ&Yvؑ245)?+EEpeԖ~ ]* io%JѣZp *q]÷/>o:8jfjsﴀd}o܁so,&Qr~؝ͩCh*1,ڠnB!*/it%z*A$5gpp랠l%UxgY N-[ Q;7zֈhݚV͝"#7]x}=2Ɖ KqZP BHnk2vzZ<_y,L\DeQ‰R&RbK%V`L9z^Q@W> O4(Jׄ]F,u힍)ַ/GNc+Q@~ꙴ:!CfNi]yyD̘E3r P:+;Z̽^_<,G&\`X<_N"P 3o zI"+FH"B%q7P6n>/Fubc~&We2E5/0ARJhr}ʻV(C7_UȖ(e.GifT9/}qnE%tJc6 C_ؒOwb.׬JVMUY0PW񰏢%Ib{ej!-$"*;2Ovg,$Eeލ^e.G,3 ySzO7qݺ!F-*n{:\g7ԪǶ ҢcvT4rA&OӉoK$a$z O[#~pjA=H+AZb[Y3{솈Ѝ7S>eNbcbó";2xk=,;߶} FW5[JU o#ZsM+{\NP!jyz:]g)E_Ћ'e٤ro@UTG)ܲ&JjXoX(z|X a]am$t8`%!)TY8m3ʷRɑsQwb#W\\ƆF[̟hq{H>n2N,ގV.^@EI.DSױug)$LN Wze +=;rA6a ffMAb׋b‡ŻvƅOɠi6\*vg"{\-$Wh-P0""TPumLyDOG^bHxp=9P?Vq`?:_ǓAU*'<ű{n`e_6 opp41.TF떅I|LHT/B 0$YQ/r[aVQէOM`^*ldSBd&[!!]\oi=}cpnU SkW6],`@t.=)TKV }ݎXL3"7si&)@&h*@抶Ԋ$pa_rRJ씳 *e8I}3 h ~gFAami0ǧ硫D fۋ孿Ktsz5~d5hl|IP=R'f"ӲB2y=wƺj_ Wz=A:\7rY; X'"?G5J,1rL`n^梻ڭny<=|Pgaz49i& X}wJޚ5e= @6N53ZG҅ PH3dE.P$c~<?t&h@&louKc]NIc)8CA0<Ŀ+ʑy!kS>&L_rr<Q/P}(8S"ilf(.ymI%Uu{=Vq#\68PkON3in%"9Q8hA4=fQ! 鶔4vl_?GS&۟HR#3?<*1S3{bˊ_/FXtȎFh71P6luz-Vl֖VV< vx]2 v[Oч9@TFqSMb瀘zgK9jK v#!RJ&ЖW ta" ˫ )_⽠-(f_bx=*^ +V! ,d&}#+r=/9RP͚YɢYlVЉw`C3@`OJCJZAW ^HOF*(l!Fբu*/4H;T<У C2jBJwz?S8{ڹHv szK:ykQԾ)P iSFɹuS6 _%ՖO !PM6饌F#$~3Wa{,# z -hH Nt1Q0IAU.EQˤ^}9唡]e¬,YlH>~@9ፉ\Gz?ng- F~Rb`bv2Y=- eٴ %8Q UMW L&h;tX_\5UU+r󖦞@^+Gy()Ku@0\O$9-鎎mV˪`dV @zάhHD,j,ߩarFʇHXǿt1-!s^L'Ԣ\o#J]e=iD~H|q2vrm-R99sjD8ǰGGdVBgy%;#E`ĉzQ7.ֶ=sxm&P.@D8v'$n_bFO8}k/JFVF#^˾.cD[9u?KYc$7]]q^I<y^RSO=īfH O26+\6MxpuȾٓ޲sم" ֔Ke ~3uxSZ tAC,"KmQ}KۺDosrǑ0 Ѣfyx 1ç*i#VnxOό8핵6' M˙.kXhý˄呆Pza5N:JⓅ^6Yi'p9'Î7Ipr>Kve@p3iנNjцb!̿> UIIG+t_O{Sxc5H]i΂vBpGFBɢua$4.~ZKkAO >~=}mV2q: YL=9GH/&Q9@tS" 0̅3P'>sԖf|6jiLH>,.dRf͝4xc\:n^p!bo'H/S(e:gjЍz817Q 5WBM}Vw/f-{U"LmkE=߳ҽ3-E:j|7 LϾMn'b?V7 g8Wul,/W@UW-]N'mk7Kt6N%eG^ >cqy31$WJ[ɇ~&hU2˘$'&xzu,(TTJD栖)3ajIY,YxX*O{:r+jLX6c7TRFPwHG/P}e ۗ`lyH7ekܣIT]Cy4Xcp.X}Q˨]|b(qtG kzP~͎5piT@0l%v^ [ T: #zB5Mz|8kεVRՎ|K1G2(U(ĐWe\Fkyxd3?{(ځbh2^F&NEO?ȹ%`%Ꮻ[3n-FK`3^80[#ZY?=Rb&k:GZ6Ga (2>_ hHv:ƄRvzJZKe1u婛}_'{r{&N\ECkn r2Ou&N|%%|Xn/n0~[}"paEWIHY^O 2(wOv=Vs;qq-`W3D\t \@O0f!2גCЮ©I3.~ͤ2370PZ憑jdNCNg(_aE?[hr.(ryFۡVg̜aXEfH/ujW <IZKĸ TUTї|PWIA ^0u9|6l0Kڷӣܳ*xw^ ?TbOk=kX^sq+ԭƚ,52UT:"劤 V ad%׷&z8孮b^~א M|tIEb5/:(WYqtl!f= GEe}C4gӿ[@t{%W.g6(s_+?;e*rEhig),'-r/s-"_̲ >˨ [zDIX[b$V]]>k?[ EDa ]^Σ^i. sJ>9)Z⽬,$"QJC˞`*L[?ƙvX=^}_Ӓ*LֶOM6{I.v)7X1LY]Aā(J?;hݭZAp͔EBԄȗIOVad53Z#ވf d)$w.ƧB3NRL1ƞjnG3:_\ jC"#m12ŵj2Rߌ-1& [6EXMuhԹ{˂-BUf0gx̒tӴ%\G.K1Ӗ #/{}fJ-d|F`,KRwF\+ߔ"ykL%9%`;6U/\#:wO;:ZkmOk$S8@i'w:XVq1]:> JfF2Acx'80+ <&h?񥏬?r6%j'%<}E{1zV~\q-y,B\KB7c̃!XBʭcrٗ\VuN;4D7@yFU=K[}X1%* ~EŦ]]^g)N{P33y)w5E30GCIjyq9<=)fM~7Q ?˱#~b>쟛6xw&{v&nWz\xNM)Q炈$xoln̉n±#@'UPU.+S[cͦ^⢕sT SM[X@CZ]DO%U>ߟ|HȊBBX'yAKK/xAMհs{{=KO80 hl'BEꕷ0:'{>h57/]|LznFqY\P6wRU&a@ 'mʅ]rmI5 8cs<jvEoT :_GS'` F orgAa egH؂s1Gg=,i$yDIX:; sUt~Z#jmۧFCb~RPً yü03[ja>0߲aU%b. 'τeԽ7e z}+>BSsL7lzN2Fܫk%wVD-Ja1?+阓72RWtQ<gk +jYn34:g %9@D0:ufmjW%~z+ 2aU y~LH, Z>1ֶK64EQnY8`Y͗|J*PB\|Vn $T?D[ hJڷ֮[L"9Wx&[`f};-Vsb/ GYq%7spELm|2gTHc0C7);h". ېH 0 =or 1^D!de}1>cג2uߥқsƓnNd$ΗRb'Qig̑X8=aPC)x;Zq`DAWb֖כ[^\af*!Ho*auVP7Ȇa)#m&\w?J0.vVpbq@&jlS(:}Wܮv#|_kΎ̑&'T rX/t!dT[!la|*DPl,Dӳ^Iaš~9obRO9rj$Ϟ5/:A`FW.|zuqsn}<ֶ[_Z6. r<0ڐ^\=_x8|/mѷƺ]ZlFdΙ"x*!9lyiQW^~hحLl_ݸ`FT~@۶Y/6;r `+41 /o輸V ^*bZvsw(D8]kdb,jr 쳫G>] fѠ7RQFpȢ';s6 J)#u=}Gڟ|q0i)5Gβ6K( QUYx'Z5Fs_p2L;zъ?/d﬏P~k˄A\UDH֚YBZVʰHĴ =KAL.OM K>Z:{Nڵy].ZO&x/ {xy'lZ +ijك?9 (KSg/KpL24nwvW3y !X~h= |8!1Y$g(ޗ#EQYfҙ>INNzpuK$$ݷ] |pWd| ?^F6Ĩ#+ljc6jfެdd\&(ؒz@dm(=@t]^ `c#jhwjnh u~DzM21~%7Us䍠?1Kj{v&~==m0#&s5ടa|nra5\Q@fSf.AT ١ .ݧ.>EmfR!$^:/;ȿ 3.zwN:|hU= b<w.,0ό4|ߢtL9 5>tbDpYEA rMu})F}):P^^Ґ{s c/wYMym꣔\r̒rzy(-i[)]gdXj!Hu0ԱY!cǁ&*5 +_NBXFu6AZ&jG:rޅ*pGQhL%)+L*h%$<zDl|g gȼ屿>&!WûOb9U(p[C7~;'J4Ψ)Nm&9iD4?WЀFk}g[VdPRS thP{K FJ -/~Ɖ^ɢ7R|L6Qn(>pey5?f F HLZˇqNqĸg1%lz= ZmAS kb]t ^yhrMlJ>r!fvbJZ)68] Ww#Z: 9@)K""3:Y`/8vfȠ+v*UŮ Ky&DFsp W-LaMBF՝EM/1 }ۯFnDSfRa˒Lt+U2Iz~d]55]&Y߈n4?Mdp+Jg+񪫺!Q*{h s@7]޿ᇳgF7Tgԧ[\HvS$zUh +Z? ~ZGQT*5/xomdh,&1-۽S =NJo*%H^gjSAk7sD=U2ʡ(BCĝd`& h{I /B\ *'p՗%}ׇ'H>΍ 9s23XPZD$NYjB*h/q}+g2?1aG30M5?Ǿ$X(jAJfNux2^h(et]t*ǨMVH!'>VS̔iCEZ6;raP54YsgfxQl;•\R}9й#>9Agl[6S0lPxUS΅lfwE xdʻدq[۾z3GV k&qѓ#Fddz]7TW;"ө-lWcf uAp]/4~\J xi7w}adJ#_hǶS҅EJݍ$vϒn >iqaxi'#avrͨx'ה(eJ y}$F[cxhWͨ$~,n Ґ=l`9WeKv b^lEJ3pq]'H4vQZ Qt"RN; -RTw8dRc2b@M7C'v 9ty{ZuYRA6V9B? iAo!񬕉[gjV4;d =gM3ZV:[ ,HUGUDuɍ)/[J!:>&mFq^lmSr @v>ĹLㄖ߈EG%{GUwlYhW[p~XW0B ߟ SwB&}rsL*1[+ΓWؙ!2c=yVF=xy#&Lu_.KL<49$eփC˻2Q6`J CŬH$ZF]2tqIW\@IRMϊM3VC-Q{J*9nIF3dlG,'-V 7֨ b,&zW?ݭytRƶb_s_57ORznįF.v~0.'4L(KѵtK(}u^ΕvX{UO',d8মjJl&z#yq*W)yˠo=yS#;48$óOJOY}bhBXygO!t@]3j-_+ Jˠlk )B}[$#%:0I2|i? ")cPS0|!Zh$J.>ML |rz6"px5dZDg[JH$Rɿ}k2fV v pox P̿*M/ADR{b+X7'.FOs+~~8q=F}cRf<12s<)A}퓀\ ڤMua`ݿ%c_qMAJVcZ#&nX)RӶpK۩7l0h=c~ oЅ _p&GgH5}.,}u(M?ʼnl=8\ڇ9VGt*9&PxOa%a!tpр*.٬Cבa$WoIS:gWZ,gCr~ڻhz_([Rb5ȱ-w*!`Y!&ӧ.q/3 LY6ErUG=q+#Jd !0gO]S27}bS€y ;)3>4Siډ̱ 8`RU.@%eE4FK7L7Ǡ%fODZ6#p9c|&'/Jy,B0y}b0+, U^>@7oi5쯄ԍIrs{&l3^o1gԡ4\c{$}/2V #9 փz[SYm{a-6Jh Kҩ9(w;~TքppN:W|W1"0%hidKmWcfr͊}&IbkMeȉ5z"b>Ö o63!&U8 Aeb_鴖գ뿞6,V΁b%J^kifWe9tQΠ Eu{*ЗOΨϮ>;|倎r>~{IAKP~AS+U_>7*GlGkԮZ.|5v|` %GUޕW 52jVٮ,y"槱Y[58ećnuVp. Dvڐn!ǽߦB+B=4r Jcll(9ᠮuR hD,{;ee*[QI|9f؎ l\;[f&:y2x }6sXMt<ȀI.QQ} gTTtۉaGVlPܸ!a#[eu@gX;Z,}ٸ7PZM7\ { x>9sŪ,zV$/Y2KyyO'?J~2@q{z/KKBaE tk00ѩJ9oa~FTaZ,z"o= DxP[㕣tUjzm᝟xȏkmvc.WASPCQ ʀբ@6d-Fdm~~p]:Q2 C sg[DL]C^$ HӌT{q^WՁEUʄ6 gWx,xl"ք?0dBQ8z~]ŚrQ pR4Hj[_̠/;acJF ՏbØ\z ;'Ȝ^0*,A02FXbR_whaEVSe%-̯ C|Y0=C;{tCG'oD%iȤ҆ng)~uh:vHHtio2ݼ'|_갼v<7KqLNV|4jHToF5ۜFFo3 : 2,Q:|5QeRn|Z9V| 9AdC7) ~I7NS/#8 vKi[,i(&/PU6 f2mvi4)&.%MZ̀qV\̉A#=KSFcF7:  yjgA}6†eˌH@ʓlp5I2jE^S,' 8Vvq̍A4@ N/IBijFCG63\CaD%."x?0f%TCV{rʢ7Y4rs*,'q% h`\(<9&^Q7ȐroUs"u֕σ;D* 3LTO8@?pQ@t`iR$P+zrA~P!JallxEGpC )y՜"HZ8 K-5j$dؒ&ruCwQ'Q1=O,5;dB.]- )* Ŕ̤*gryZv9gh]p_2/b|~/mYJXȨh-7mu·sYD@P,)-P8x?~z1pqnw+@jѩ}3FCKOMoP3Q?`_0p!k,m!w]4oR6 1$}V gy0,mɏ%Ew+- J~2>/yWeMxAˁ ~+h)=Nq)r"m[6?":0(]C%{ ,bGe8u!u$c}iJۺ1փGbHcʉi14lx (o)1X#~\ܫJE}S+e¼Q袭e 9}Sc_rgL-h$Ѷ&d y1&8ցeם4V\} ^{hw=H79zS,|&$/+"WC3gBxt~bF; =XI7Q[XRRvPB9${)j ՂEYe|MO]gD1^8d@NxJ90RFx#>S6'Q! #!*l@D-/Z#tM6-?}YF>:: aρÍSEG~s8}N)Я;q7]mt;lP-Ҹu]UJ*M .3|(khp%Y\z6J[:Z0] o |yC&@ጆG M Q~ ̟ndlch\ Q>Uq̕V;zDY*(xoHQ>5Çk(DŽ k|&S = Zc1 oKr|"ܚ :=7(`Bwy Ro'_ 0Kiغ7>ћq1=/O%"=kc,&>s'޾%"wplXr24y΂ׇ5i2iKXy[w &ޜ~#)N>4̯9BDރ|'3AjyK_+.|:ʟm*S ZJBZ?IVF9-!ozu` tH3 ߆;@˦ wu.&I7*}ey9֨+M1xK M g!zkTi rRX3g<%3uK a=BG/z S'B Ǚ,w,fV1A׷7ziwW P12k'vXUwjKiZ5&s37!`OOi*GOit3jՕ7pHX@I,J(d3IL;>gqk 3G2&3>˞sl;o&U^/} s #jDan!{Cw2%*{Y -F w>Kl-`$16BZIǩMmv; \߲[ZNH5ww!׾;~V+P xHmF'ViX(ä9xiNIb(Εc{8<:" !6x1QF$ܓ|Q2VUe+!ژ, gY/_/Z,8VxQT8dQ8!h.4P٦\#FdVpsBBng?) J< ދg$ ]EBeƖ1$ Nk1.žLMv-g@>]l{=7Rڟa6^߫Ixh{;ӃI\-{k嫴($lf jo&5}ěݩU~{ }rP4Y=T-GM{֢yhġ /j~7>фxu4+o-}[9鞜tt82vfMMJ^S\g bC[b$/Bq9<e@#8Tp^yYDd^BGW*"fc>f˓oFcV{Vq{J]@h"y)L lM[_T.Lŭ0nק"8rm/o>g9HjF;uQ=$>:qڌ>H{Ǥ-7S ~kЮ9Z2=(^P/uwyҹOLk6shg[/Eĝ|}1Y*(iPPIp ǰ>2`sEFCGZIl HH B(n?chF"Ho=Le'SiهdUFN#^pAI+\]sgk%麗,E΄c:(ݳ |p> D M*On/W%-. Q y$nt|?k2 WPUV_{ KF zY0Pٗz{+1U5Wd$O\tCpg+&^y^6VT0FYlY&Q:' :/ȁ³.w9Zg7I sC<Մ,EyaMbS1|M ZM)?eBvp^.MXOi0]PHV@*Ұ!QuNCɭ)RyUƍF31ұ Q7^$ 3Y@olbxUPM| mB3a\1߶I<'Qn~P {̦B&¤f:Glȟ7)+3ab|q DRanfb?_&Rׯ=$T3kWW~{?W>緷KZN h!'wfJ3~VKe(KB#Y!sa`@m+3N תw E1[+5,zrʪ[ dCK\a8󎳎/V7K0X"21Q;e 1G"rm dozW)PiӶJ3B/3x!8E:T-F>{1EE_Dtu7]Xɐ*8PYhR Yta<3v{ԙB 2IB ׁ>bmr {ϨDh@x3jnoEH 1m#TWn 8@(OpF;;>JTY b2|޴`(tahLu6'~h69wy&6%j/ximmov%AisU+:.[C-~f)?+bxWSh)ߦU[[n ")jMX.gvbsfϞ1'e۵Yo}b<&|?G˘6O*\<,CS*xߕZÔI AX5zP ?Ig aR]>3~x < 6?/ h"F7ڠoTtGl-WU xע9G'>i5ac0 "@{A%s2߂B`ܪm1fWTl3Wl=]0Fb~",N]*CTw%-|/5o*#Bo)1X(Ll xÅp6 X}i2APxqmܹ}]Tamw<Ő.*@J(HJv*9&ި8atIؠXuc̝ݸZsrq D42-AUŇ1MYGY),A xd0 6Cw|T#(p\%^~[ eY6L]W"!FijRQ].78(疥 ysmFǂ·{a;dtN 7ߢ}ї9dè)y4(H<|b tX6gV3m$:SsO8$ݒSd:0ڎ;Aǭx!oGS 6Kxu5 8)`gyyJmlKSV[)-9`Ca 1nćfk2fb Rw;ks3R{p?-E: wST$J1|MsEAa3E _#b#6{&8wP7|9pf~U r$f,{cAWf.0b`ы:!wf-! J恊jK5Gbg[Oнce2q4%@fudfg@hNۤig*qv8vUsIW_]Ks9p=Ӿ q{=4<"QRà ˍ`޻ͩoqV`E1`5o X lc^a ȟ*1TYP̟smxT ˁy\C Fi\f@V[`0%G*.!#3C E A+I+O"+R@(V{k #'vp[XaNo .8Du97QjޗBV̧!HeCs,嗨+;`ϒhJ 5/44p -Qִr2Ju}kz"F#3;r~F2#0W<޶Rք9ڣmo9״9;!,Уe2xSUM` qLz^ADH!Y/}nt@[gI+&`7Xm[[Ûi&)H€_l8!/ڹz[մxub ]PhR4_au# Q3cvE VT&ch 2r"inQz7Rۨ+H| Rk V=j&֝Q+nr֝[?eOm&%DK=Pb1 w(2=,)'B_؃lP=M_<`,H01+''j} |&S^$Al RkyxS!:ipТJsj 'R`6i #X@Hu Qc,M%i^<\_?#S@ lh8:NOb}Ccy _Yj,9@OuMiOjwV(HWqX]B ## 'NGJ}N?*X]-M˱_pbSiRUK͟3Y t"\?:\y~u=HtǙJpdCc"upv1S9 @}/.7yE5A^.iQa5 T9 Ȁx56W6nP?LPxa%81s.kmܺF [lnsZihC"Ϗ6fi wg#c`Z w /=>cXCG|ډ Z&zyY֠i߫`]G l(u*,"JSNV!]TMm[ntqZ n,dRpmWUcIُe$LMkw^6zӇL [@4j=Y3}O|q#Ȏt=Fumf3Ut{V̕ecL$2"S ;= dHJo mB\iV"'sED0P̞Tꙉ"R`nzKDp;e!C* m]WĐK)(H&pg7 .i~,.ݬAz&0-N=:;8GO*bk}:lv2wBrz ـfj9X=<ֈA*,$p,$*UN'5I&{%<RP 5 9ܯJPsXEI{Lb/R>BQ Y߈CHl{Ic)2!便OJ%]6/H!Pp[MZ.! y睂[U.Ow%5B:퉑O>!N-;"!l&LG{Z, .si2pK,.]DNъd06J"J~ qc$#UF0ot" hՃE;;pұ3X_k W[IǻƘ 8rTQߨ\8!i dkhL`$K=g//Z3.r7":+тoot !o&P|}o/D?/,}R@Rw*4?kuNQJ]pELS$:,,kA 8]5YvmHNN:>L/SPȣ=Xu2R>6K` H!s-y<{pq+mSHGHHJIelH(.KMk]JdϠf<[Ud"\oKyx/!Fs0'3mƖ!6HvIwj(5jRr-L^xoj9~۠0dNTJvi -սꘜ{5s<ιt?~OP#JJlPk*{ `lN cY>#$#K49ES_MH^7{ezÆH<548u ~|`P`[GhEYTK`QЎC-;¹tcbGXa7rTu1:xhjkHnٔoە/#I=+]1,~_+o|'nl~:Z;jYSc3l3"3A6iom\gZly4j7lڿb cE9mlژ mis`"d)xs:. GXûB!y"P+ ŸxK$'Gә7 fS2?5,J Ww6:y1A86z튺!>@-C\PRZLSʣ4"mWsSYk-Xd*;_ni䆂3o֘IM`9%u*5 kKHjLk6g)5JSOLgws|=;A`O>j2]:6 ]8Ê'*g{nM\.!$t1#x]AYhG5߱‘ۉ7]|(넷C?L`פ.aQTf $8GmtJ}Gߛ4FlT!3Ǫ#:"MÒ L@ sy`?zL/8ǘ}8!w 5D{1|ed`6d?D׈138D&1&ůA8Mebݳn&MmTr-ό*Q9W8ߓo6jƗm*Up-ʢl|PRt gHp "i+5`+oXk x7P%CJ5yph՚Iz'F{  Cy]p*'~ Cuu;KV7nY{"I5$.)SZ2":@&Lq:>TYN#UTh)b<-*~UT#1g¬@ bo}aA|3SF~' "|j\<SVhA]|S-pjυ9}ZT,Ww0l)GsZe&"\ `*h˖6I3qHɱe23sG'#bo 4IѿӠaN$#.ON)΁ p1 1T7V].>;CLZ;!Aeg/VUOFہ`dO8MWD.s\BĪC bajzX1)' 04'M_-:ࣼW\7^M9"~)mh1yޒ-1oy ӈY3afuH;^ܷҧSxhkZ m2tmWSgoڂTkgg`mV0"S>5u#,ԕܱZGylzNaӂgk z]<9K5# j%Ode30߬(VDF}B3٘rV63UË= 7!d;ܠ|[<<@nX{mm < kf97t#$b(hVtff%r:a`[+:05T@-'Jl716o᭺9@z0>) ^HO R^mEAd0K:&P+[Rf4G`ʱ_E'E7rUوB~pw%hv;V쉤܆?rjZSBTyzvX!Y*CR!](Ne;2~Q ` DŽrK*ݮ$[YQ@ؗ ȶ>?EHy 54HsfAת7/>gc?m5_̸ڙ qM|Bq\ɖ{Mc^d5jĞ|A[+zK{~`˩{`A@u4zH7J&:$X fqY4-!6'S6|ȂsHgxwT;R%>Z]9a/YX~7uy% O܇P#"ZC[ ט)K<|dx-3MFV)8Gco9ik)Hr lio8 Ta(:f+Q; `XO!TAQOyb}xr*SUf?'r&y6Ey=+$AIw1R{_ˆ)_~K& #5^aÒh\UMQb-"ۭ#qu;Z,_֎X){""FLq1oaHh>L-c . 1IN"xS~0?dBe2שq)1bJv޶m}^ᒊ4- /&Hn?䞗pN`԰6]L*ZWu.IT3|!2iKzX2>3< Tf7 \y=5U-,H[V4覱iuB&tDUjs7FOF:%?{ZX )<&X űNpsb{PF^) ˷h؉LL\Ѯ-us_ ! CmO$\6'd9/Xb3V*Yb󑣮nk~!CB}Di8R!ALhJTvVqJz>`vu5sFㄳH pdd<W8 98W$Y&10rAQWϝc\$}n%Op!`b{i 2VoNMÿU~4 hzvT1:~o)wĽ0մ9Eî]9Yܑjѹn^ AIݑjtO,o!>hF/V *hboZTZDƂ$DW ')fi- }(g ʏ&eGW_B@! D׷,4JÒ㹣JgTd"q'L24i_#1,A=dخw-]# K-zh[~f\>5Wsդ5GBNhF CVk}')MB\SK giuAz0CyR{(ٽMᔌ_a"vX7`%>h*wH$>zLR5T7Iu;x|rAyדilM/,.bJ `y7!u|p9w?[kyǝIrLa ѥ}~^7cy.?' xwq-.b7OQǩ.owb1z[@Gp2w_:YjjH`wjDmx"p}&Ӱ/h=xHOg0׎yOX:ڼȓ:6IC?3 2$ ;8W :ǢLLn˔^B$ I$}Kѯ`eMݼFvɑ$f\|rm< NЩާcdJxp(-XY6#, xK7L #{}֋+>H`Gl~4;ڕ>Zm̞,r۟@g=P,{S:EÄT^{ae= 7)eQ藒Ȍ6J_=BI؃&)DpMV󝒸)+QXad#RoY}, +5:Ifpe< 4~/l9H6>BTl}D+%OXF >ޗrUqĮL.نlVEEqmY[ç`z%`K\@[$_>6!Q7q2=O``wwӑK0Ȋol{ljdHzeITX=vl~ w"L8;ius͎èu,.2}X;um{^ }iIxLWèbF 1豮r{50-$Y[t @jwP$Ҍ0;#+M)]GSN͏M\g'vQ@9Ӱ 6!yM'&x ! ueT8<Y_+-9`\0C28B]w$$}no2gA\5Tfv 7 y!i:|5dq̅s}$*2 5\V.b/ $wD%rっcui5 ~2! RȄXb6,@ɪ\4ԁ{W{3bE9sIpwoWx0Ԙ́p7QJg~XSp%DKe^ Kޞ33& Flo%M<'$3W՘_֩$+(p1Np}TJ;vfXEg;Hb!Bn8ss+z;iƠ[{#4@ 8dՒE(@7Zu qkDp\[I֛D $?Sw6CfŃ" Ss4Y+ F$l 9Τ)nn|b'dM84ƚ7Bl6r9,9V+dV z4|^GȮSstŽ5O܉UhKT f?4E$]RBٿٹfxվ(mbŽM%O$z'>iq? bJb?T.@bZv/W1-WLӁ9 ݲŵZ옹aU8>h[6}t̿M<81_dj.ɜ+ !Rv-3LܺSYqBkpc^=[l h,̫23NI. _-l˰%КoL ͿʔJ6RBdN'ӊ89b,.d %Ë sL7Y[6NR]fSf Y ־22t2S !PalPҗ?~ IkQD IX:_XЎfj@I`(뎹ߞ$B;s- U#3^Ru8 L1Hř4'cK ɕT#wB[cmuM{K6`5 Ff R5!"A d!E"}A)4Ƞ,r s?^A ђ~N0|"mlze S8 iصbx.nEy_x=&Q=a,7Hާ7el+z:f%6`Iz#%KL)._G1n#5N$?ox4+us6 ?'*|`ӟ~E M05|[T->Xx .B7mʷ*x3$]ã?F(]ll[gZ*iN#騆TEdy T'C#ɺ^ &[er}XWwj}{]-;9x#YNINQNs痦{qnv̯2RUj&;m߂&34c)ۤ gu2DhUe{_uPxTĭUCR[E0L6l.F1M{{.!A h/uu0~I#射ufxYS =hSMPw=H916 8~+31~ԡ-K8Ȋ}}'hW7%GmJO1tCueWC'Ѥ}נl{sBm-YzFjw±Sl^ +sQ>EDYR|ڄÉe?kޚB ^\ Z|apFޖd9_kR&EHIÜ}m^7&p|a+*"댚ǢvlVCV[JbW!75ޘKW{}f:/Ez4j0y3PV*Θ eɬL1iOQi57ɰ0'*T -r#jbR@\YC;n: fmOBEߢIͭG{yhDN˫(J0sq?uI%IV_JKs>㓬J0KESۣ7FҴ{3$wc$FFMY3jSmT(8Ѡ, ǔNs`;LYd:V#Թl(WiPᑥBƁ|}%DK=ܼ{-[j?#]i?46?퉘HD,XΤY-&OC\_BԔEFoh\tw6!a ^c3- =3[q)+dz/_%ڶXήuW_F-^ˑImNl51j[pO R$;TxwmL<ۤ [C}$cL`J@L[}/0 8^|^!D`N1-bxʶ\?ớ:Xd\hOC rȎ_r@XcRLk3Ym 'FZZb򱚑'v9 y t#<>@b[l9}ɦfDf}{MMnLyĹ=$1)vq#tSj?Aemh09'IiMجwҗa:px!sRL~\q!SJU]48n&XůC6˂",kX7)w%~y[⬀yGWN9h@89[„ ߪG9t0@}Uj *yx_6r/Kl %xӢM:Zzq}y-Hl##^$ o–2"/4Yxb{%.hEbZy=)wτe\=E6`u1潹 j'wݢXwt aF*"h5T uR6KC}J$ےK]`#/Gv cPtGy/&)R[O|TɦA}u-EBe{D0~ :x8[ ?+( >a\"LOILYODƻƕkm 7B5O~ͧC8XBE!0y=0ccAKlL|Ty3jE/>5DNrE|G f”G3ôhc.c;V|g0-; J~8܉R" jfOjN?LMɈ_PT!ٙwx1ƙ^Iq-H>?e~UpT K& WhMIZkH*h`%ã ..D/(%2HBS~BS8%6h,8Zc1Xp6ڰpK "Fԭ͵ݫ4F %F/4$:A o*6˂觸 s6pH[8Sz+?%v^!agivMr b3jtVӡT``y\w^cẼT_oSn#wOjg9j6MC[&5! 4a;E2tt;VwJvgq@ 4)a66(@*ϊ{MAs"X?é~89LvW xJ_$NW:?_'q5_Sݟo\#;7 .EY}6Q+0<$gN t"\nB6| |O,ImN&\5$h-UJ0<fNH"bև sF-Yk&z'-EP;S?DG([_V^R?☒1"}AplhȾB4IqkJ9 ֱ&;¹;GCqcAфԯo|:` kF,(Cg9&fP(eN#}+GEXV҉' 'lnN$MJ? ]++?[&Õo C@uN-#r]\R:,/)E_Wh$ ׆sɋRdp2_:$K8ѠV9Y:y;.{9`K"$/ٕ$m_vߤHdl ken mxn(RZř %mJC!um#pߵZumH~7FEUIJ@ks }բ殮uReZIX7 Zu8P9Gn݊&]:]!YBڬ=d!1#@*]tm"FWqEѹ72aևBBG,🬏Һ%?APPz|uegZ!Ĵ"v2Y`"*^N@\b@Veg":Zh*?dZZ8>ڗ&Ye~΀&]9 +Z;8؂_ķ/PCAҀqek ݜz6EmE~ĔkE_&Oʲf$-uK~6&>[_q]fdA07p-)tEXyJq4 e4;z )nQޟSh,RDD,{*=Uqj)(e ݛ`#/ޛNu$m*P`0 xjFδഖOm+@ge4̙_P# ڑ1laҙmei ^Tws:] r䥲@e|َ \IVx^$mI}z}ύl&m.\W!ycPwEYv8آ^%^kq8ۨ -KIuo4o@f'88  >t;J0%Ͱbޝ2' !' ѻX&_sưYka\'5Afj sLNjgzOqx ѴӉ!K0_+:s'u ar4 ~8 \@MI`̐6RqUrS `&8O޷_NEXh@`{Dv9 Fv! g\Zg&Cp Vbaqӟ@Y1nڤ=*..D+cc˽tS wrUs(k2./ @%9\fM2}GP ڵ!A&j3g1F.կ8 eC M(?ud{vGT [HuC@δר4϶?o0ݘvgTTEQHm]6MQJ: *XG~-52gDڠa{:E׉m]18oB9 Vc˛p?F WZXj3As$pG7Op(Vb -$1@O}ԖWhǴd$⤁TjO)Ęra<-SR$ Œ[`͕Pn:ZK_2eWd=p_rVZ>9ϳJ4nON-}-_hM;dP=E*N4VԓmG2#p.N cbZOSj㐥ev?a#.rxOf!ǁw؞"dnmi^zIG&e 0i]j %3NxwfR3#*qkjیG ?YdF~|b`oBXh<0w`Σ7DAJ4 Y,O 44 MZk;U8:M Ag @8RhIKIhxw kPRy5n3]Ic.@Q/Ώg1C|11,/7Pi(t?#5+).3WFJ]5XLc11p]80Mx&8͸资}-92!8O|4ceF}n|>^&'EgeF=",h7r865A)dW>\꾧g]&" 6hx}F;iR2 vTOXDޱ\8+ĬfhaX슥V-02'lKi36PZ`AXͥкF֞`NZ>(=aح:J{bL!WT"^-V?(jNѥ NCpKNiѸ&QXARccsVBёSY8޼L"zPlDZO2&yr% No9y0ѫW 0Dzm65^9 $wv7?8'E[&-Rvi8go~d㙉";""43!}l]NteXx!j`9<'~KB!.үM޶bl 8+JϝDxk^mqKXGhWSuu#8W=.rnQZ3 * l('қIh9לM8~Ktnmtgd*YpFIڦ6FrU\<ڦ`^ ZyVC5}./8Wsm 70f}qj;M/uܩ V ٖ>=YE;8-8]˭,_XpUR]{V6Za VnRE6J Y4a0`ܠ,F3_XGC/8˙+osa7"^A\(Tc k`JhlZQ_Wi88j mڬԘؤF3q=]Ӳ#` @3Pl#EvU.yZFMKyȿEOE58O5:>!z3yf/OIz}эrxAb9sPI{3Qi?\=2@NɩB.|CQ+AM%ay߅fqL")W-5+uHӁt yx-y[l1c (>\$-Ѝ Sl/A%):,LCt㪦Tv7/OjdXk` itN+N>@9v;m !u?-$O5 >U}]Kf~U>^z==^QՃFf( H7R4}^7G0&>iX/MmaíJ~/wHBzPQBwdrʜ7.|/ޞQR *pHjk@o(:3wh_(z6lzM0 ǽQgGB [=gOݯqXfV5Q!\5i=Sq9HJTN:R(v$h0B *rzZDږ=iXyc=\auU$pFіXye?Xxo)?*׎'6L*tT?~>.1S)SH,##Zj\KDSb]*uAj8#'Ug/n5r隠j < 5?Fqalђ3m]%_@`{ӑ0iVg=T0RH()ujWI&ȥW&B 8Dl׀qTAmO|G2,w6⹊t`ATr' 6q|^Ʌ<@~yउQO_3p W1G7wHK I_э*G]++Q WF^ίLJ!ճ} +,K# en#?;`9u|4^˯GHSo '9uuX E?I߹Ċ߁|VLʠ]rs[ߍy;@ic52;VCA-@ئlTiB[ R@Z6_l(`wkLQJ}Zq$ FxTE|>Kv !!Yvv)Q9$QY] *у+rޱhVi;} PpO%醇Gak IX|IcCDu(Էc1Dj^@Y3*Wa }C,V`;x`$|cGx5kF!m] œ; p D1\AɈ# ᢾnJjJOo&:OxdGUɇ][;XWpWvgGm zO=PȤpǙxA[Qj l=$-,- l{[ 8cӤZMlRbR`ȢQs9+ef6kXTԕ%\XVBW9p|H[[mlDK"бnl1`EZ첝b jgK}z[zZuqpaM:OOc,s}h9ާf-ٲ^rrpc5?O,V^[!c>ٯOK2bq G;)&*rtp%æĎzch7Ŷ+O? XuѨ|PX?/ wY1b®I:$Y5 =Tom"-W.a!w!Y|HB/F+0M<*5.8Mmh/LA(cO{Oifjxr= ܺmڊ׸gFp/%Imz|:DUeQ]fU]2;7vŅrʆJ5*OJzH;c,ZC]#:BZb]uB+P*Q\(!1+ǝÙQk21ʘ/y`侣)&/ZKcd65瀍[o;DK} D@f_qG ["qs",3KOZ*is b 3^Oha}~-ZY#A,&Tj^7XXD~eoo{lg$IHi0R3f* JDSryVS>+6"iCǦ8s6vyZ\'g"-N жD8JTbwGDZ=q;0.G(Cҽu}m$шuW\lr2i=#ȧ@3[:w~O YI8e߁寫{x~QYJ0 th3!-.𳵩nsnMuQ=Ӆ읒(v$vs> d+9l E,==$P.#w ^Efo*L@l1!𾀖=Njb]HWҒ7a^ﭜUOj AAIʌBfxnY?P K)87K(у#/{Npowk6kl.kofSc y3#;B/d0i"_^ 2i|U!)n8^GBd {\):"]xS0mYbO^8aprr𑠰owߓDTY-~R6puni%a#m@Vܳ,yH'蹍A^9,^X4}*fӿ4@w}:`BҚ+ Q:i0Pl+ &n3]*(mE 1rWڔ{CRd{J*C) ƒMaQ?%%'?ŝ.ƫ?ќ{B:DNdgp#-vy)(hL~k+<חМ`/? lNջ$J&<{7}d.'҈i 3!Rƒ*U,“¿B@?@ v+WwwKN_]2 ӓWЅ!nHfid$ h@ju50!nW7I ut5~%erښ_dMMCLv_珅/RqR}{Dw.rфs;lf5nbzנN!BVsgGW&Op?s~=k3ɂ 6qns>``EǏ'0ko;?٢[pѰXQ{>W&d:8f Q=k5 4h)$\{0 ~Ms |Zq(4Rږ@dem`\o?e+]d+P8f2tS^rbQ&W5{*VXq d7*'X7~Zm^mJ{j4{dUoQK&{q2.q RpWFb᏷ X@o_-y֩a[-2gKf&*|] HYˠ5GbW|ޯR)1!۞Vq#hk:~(aw? ȸ bKA^b^ԞK+Xzv0{o_G 6'4tŝMv(DBQ6*L/H4.Pe ^&o1WDWaOes"5†bZ=saG- ߋ=ռs#LŽ1米ˈI"|# fU޳^1X$0Yk$9 ΔJG# 9~@I0Fp%#(ضDZXRf  |+UgѺPU(|,s$#sc{ufA(1 ]7oi ZLyteƎ|OGȰ׾iY[Uzϩt0qFCh !n|ξ͒qpʨ~ ͵ DCQuq/J=:d"0{,U:`Y3 @8j[s7E8-ΦLJmEŽ-Nss?}kFkcJcˬx"vS]%.s~EeUC†5O 7Cgͽ&^ BOH|ܩyx PVMߛdy$!A$1fF0O9f&`8.Πh]1N" QB,3c_Zo|>p8 C̱tz> "d.l]tk!5]x Y:YE T9I;P]ϰ ׀k%o3Qu?;@'^i_O_1#]peס]=pQ 4y6U&]ڤyqP}qbUOo&\! փZHRD*UgT˨.*J# hPAqQ*Zg3 @&_Lry A=Rs;:Ʃ_j!t^u/μY Z'\E !<`R@Csf*^ݡņ*y9fN@ Be1ˮ]NPƸ+ed|O]JmpYqzPϱ5B\Bw=0lt/^|݌T%5__g YKlֈ)7EunA9x>z~_,]s|JLwՂ-?jipXۄ,y*z : zKV|T%2OǃY#%逝XsލvI!yDu޸W1ܦS.qP7[j4&Q@=%Ӄ2 !n LR] ?S$qk~4u4C &2ٰQnDZrzt-{EϭZ(Ov xG}H{ B}o.NjvN@P<o\PյX0?wX]F;uN].Vk-$R^c3o  fBE^=zR#JD{v0x'a @O(38D;N~ ݌ 7p6s=`$]A5k[RdNT-gtSI8MTGV\  ^ۄXZ9 "7'ϺZ+wU9eΖ2C d׊r yޖe>62j3)a B#f ~N{w^frǝ')I2}tvWBpMuUB! xnt*KWR;+ә3͂#{.%,}:u &9D$UN:? ceX7rߢCRMS? 6(G&Q{hd-xŒg1,)njȭ66 UySđi);R* jCVƇG]{5/mG!PB˝63Vdiu>Q M\I\hocBh>pd?S#&˃N C~BfB6b7Y$\GDrjhj iZ'kqm߀1aMV*h5wojΡI7I);u"${JܿCOJ=l9t9ϕzțCkR'ي^y)Qry֪̫9:J=RRs(JжDCw[e[Cgs8L}ȲU0w~lh`Xr;Gx&MD ,&$ٚO6Kdp"+>tV`/gN$r#lz!D3܌p&%/B5A}imooX-"p e|з2^5%[j^=z<߄^p@ذ?*OhՄ cB3b,,mOk Et W q.6-k;E`b¨Ҡf7C^7@(_B"~'#yG۟r~F|vO LV 56sJUIyJ G]v+(R3vhLZˉ%OTg/v94}!OSEKcmXQMBdE_O7M@W#QR*snH-%臊|KPg"+ZGЫl=JK(rdA;㣠lșUcrBϜ-2]Sb s\Mi+5kpve#rr+P$/8V6EֆkK&mXǵcjiL^a1`ͯMq"^3yA~J%?tB(gM}KU)<橗ѮdB@'yF4?f-j^~ŪǮXZXR{!L">ڢ䓭(9=I0ٍ80vw&d' O|v*TC6 =:]t'A(_ c{7K!cCů̆a2̊rl=,_]< hQ>->bIoHoD>EC#Vd{I_r^8 wp|Yĉ`vg59Vά(:'0iCZ\9YwbUXI>L"__J+]p!;E91h5;V*= O'ەu'*ChQ'B`>RAuWI N$'&PWj|Ulԗ~"ڊAX'|Br%žrk02rW+7|XlՔuh.OC&5>6n}>gcV>'*v;JW>N^G'Ll/8n\h觤ciܬF'kbWc(%3Of>&2][etotG^obF2A=_kw n9JVRXlI-*J 7$_W}q "?L*wI֥Dp] |\MΛ@H)N9ُ{XM s!"T/UoD]]6iS$ $pCR#|eBΓ֥9isfH( ]~j}_: r()Ot@wnI1h`c oGi[(͡N+df Iu+_)[O@jп1PV{$!AJU33.&ϳ,MO[Vu!?7aڃ dMޯh}z~nb Q؉kX6q!ñ-K[;䞵t nVв?t>P8&6"Sj<\Ai֔=4XźsnOWp\Ox "S64x~Nu9{53ea͡%H)z=Z|PC^tnzˎeng,;4[aUw(%"yTD!\6e@6(6TPc ,C>kɃ͠iJB#I\~R vj"g7QMln _3#V7j\7 [Чܫi=V"Aw'%mǖ`SeXZ6Z!2X5(33*VYIy7jǦ@ V6ƠՓn/KRi7='wM3=xʘ tKZҲkx. 6YJ !BKc&[$rMp)0D<ʾ||qFY@HSRE'5Oh;?6 gv}`f%Gَ_.-Ētz . g#‹Lg.:뇥iRw(K#ZQoFيYlR3bZDqP {$Gz@zfm(+4рوt 3̔HK ƒ[fyTMn`y:2C4=Y@>bClowO =f Jث?໯߆6ygֺoG6%|ҥ@u'cRU1w;R);yfL&C>[yw5Tͬ/ ""O;\!Vz-l4pո5u_ȳefpkż]bzt6-Dx6; [q˪򟋱Ҹ[*E&3W9qАÓ9"A6Zr=u߯izJ~>'ءZgj?\ lv}SlIu#ozQAb946:Q+|R%WPg B&H$%wnT?3.f7OgQ/ZR($:P|>ҳunrF*/ Yna908@9N:OAbO3v"Y=֟ z3 -S6f.qKFIk:O`xA^ 6*;YЀ FWvtwfS/ӷ#I(%ц#㿝5z2:;nx( \Fk=szX=P{4{79$/ ݆@=vg-Ch)*NÒu{T)8{:ck^;; &fYضK(aHh."‚3 + UU*zK ?䗬.WF@,R-5ꖅ;D)e9hT̨qnEk1wf?.H! g p4W|it˥xVp;r-wőmOND0&{?ϛP88\IILyK9:Vg!2ЄBlsF~ꌂ0 >ȀeAb3\h$+/Kka|W{͠{ }v Vb'_G8)X,ؙ;Meo3gY9ؤr4?]D0>&u~4~?loK{#f=bB?I!?T m}CB&=ep;(dF&g%抪WL)oO{'szoB} ֧Y`Ngq֫nPѕ}"J)xe)Fo(irWÏ@Sl Yݤ/cT B*J!!&FJ@ނXA?4K9m ?bm9+LrC.$G^yZ&9b3p`&ޭ]jakpfEwcՔSV:87lƔQ&8PnS3GuT;[d3};` !cK KijA ,5MjvX뼹5{ofI5.u }EImi 7\?à"2i3uQbZv R|ava,e1=rn$nw#)leo!Vϖ}rd:lY|{#XܹTlF0<[>Fz|.vȢK*7@nÕ}8/N?)5'h@|sbgs1H'b˜o+?NO]8,օCm*ꇆvyZ1$1;]vND2M{;mr XB/n5nBf@VvZ1l*[!Ikvn}!1i0t`\QםwrL S]u!;/YQXMqns8 8u"C3#<6q8iWIVB!D^2Q5qs^Vkǂ6Y{<bQW;L5 \O.GQqZ+eRFC[8,\";3KCP)lGDWƬ~DCKN^JCқ4 ;Mgia` OfhěNGp/D9"=ft!~{!,N%%Afp&.\N(=FM[UHLUpᴤŖx[4ڕмCF(W9Kd rA0$141^|AԈ m*3282"Ճ0DI4FGno,ګ҅~>3)=FبCox`'R],O7 3^ReLgY2eZ'}=F^1ѵZ,J0"utȐY¦׋33#{"1i4Xƣo_&&!2N?4k2] 6aTLVZ81 IP;0Gm~"`&Ve $o<.6͚W\ 16+4J>C3~dwzJ~Gbh c[n[;8)~bDOǕe3JkPm_6ݒl$.aԪ a\/ % Yq. S9BTz[@-;NIO_(*0ٰx2W酞")K>OC_v!;zs;Ѓ,oZpj]#[3 ~?b;ݡ(ŠngmCMI"C0W|1OMuAƟ1;y.wUoDaA ^Xi>XvCD4x%bo7v:?!2[vxN>6wTNTCc2@/$s"2W\ʶNwR l<'hU5G xbبEts+i-"bʋeMn rۙB5e-xW'&T1vN Q՚4htMqt(dX݄64L. :%<2fI-^e=E>&>aOSн=R+wEO!FG.O#X;9p8Vg7/KȊ6A:ˬW:v*Gѯ+nzg.UHY$ C)sm-"93?BؿA e֞{8ROP<AeԭQf !aJ?u'EIƋ)lp̮E>_I)~ JB( oɦ)% s>-R ~NCD7-/װѶyE>tYR>bhBфmh/M <6 J;3/An(,HT`ġ@ a)ep $̍HK A嗸`]W ^T,9aώ>Ӽ$b'?w_аF&)eb<+a~)@ . (51o+W f"T( %+c]yJ s]8-#lPRĺV"z(l;kiӠ޼8?>*㮝)6눅$a^Ld}/IP$}{hvN fLBW))( !RZyDW$7`3#Q{8XAhhK+ a2[e +E7$bk e‗{77a||5'%/ sSIo✢̓YbSP޼ҹzO)rݮp%܍|,޾ ݈ />K.ެPKwcۛ,9ّ-C'OXUɩ%~?d:_ bs \!6ݬ.==V{o$Ks{Q4`ӨKczҬ3&Ln%j&z6Dit?:܉:^6pG|z @P% :Vdѱ,j +uu`B؞ןL #ΉwQa̋9=\# 4wP;N"1 >/d˅Qk rwE7ƶABFFK"0“UJ\C8z;zA$.MG6$gHm#cx%Wͯ.>2? }ERf9x5#%65ff"s$p"lW_Gzr"e}r0<&$w 8d~fӉ32ޙU9lt{k.:)IØj%:L;r8vb5\˞YotG16Zj Dn~z*fw<ԜE1P7+bC$rӔ: |lwVs5n NO k 29Q1\Dx΅DVH"wy+F!*be3( b ϕd'pǴ[}:V;ԜbG˿\˷_0w*euœGMCU u&|Q?,P }/(!,WML/]IOqat@[Р^5ݩٕ"fd7-V?ŻkLj[$/.Z$wR#-~}?4~xĵԱ eE"N] 1T[P?qFnO?s{.:itTTx}Lve(0cd-šV-~_dVt5)宸BF% a-9 tyTَ,qW!V|u|U[{"O4uF]Yv#"Dc !?%LHgUuuVO8ve$He竎`;c;v|-{mLb߮ ffD a>i48ʤbzQ1SnHůsm ϔ Ed,{$'*RR2FT[ӬnWkƓNn+l[J4a@П^ࣲUme/.*?7AC@eUӡM߃<7; Ҏ9TL @+[:ċT΄`iC-i_)Жߝ~H$Ž~eYMTQh S5^6SqNNfzSp-p㾢$V s`$1{Dmݫ\3"TIH4:p1+ѪniWTiǀogdQ3U'G4Xy Nf㪇2akKJ4EۛvR0uWunZ`)޿a_b 歂{aRb0J^K`PZUC7H.IG7_F%߫8;-s̳5RfdXݱ5'{jr.[cXӨIqOAmR:xE j&E] %tDwiĜL?mWsD[^ջd(;t0LI UC[[d1B/j`A/j*dj!`ռ$C;LP!$ kTI f b)?ާq,6srLM3<||M܌ѫHraSü{)й!W/X- Ab;~p.eDL< Al{)JXLo钑lP?M *(ynoR4%:8n5:w?j} S@N,=Ӑ&<F\]HS? ǶqzÉH8K3_) Mo'Bj;f,@q9M[ \T ժFcjb1OLpe#2(Tl`:A-*QViSV :tCrvzo3%g=q2wuVh h~r j:#a4u4Ҩ,V)<04, F +A1JDRgqJvIo/~R1,K ]>y>HfojB';_mm|XtԦXXd$kt1KC].H y#EW-/_F3Obt:$,}nn J,[HyFSq]stԟgT]b/(<6/ `1iIA!`;@r̜ &@?:D PgftG[ary.N ſ"XӄWBsEaB2}DUɆє @P٨{>DnPTp@+%2"DdV,8wRE~\$inM9.u~ב(o)n Ξ1 X ltS9 @ ciFzP\`Jw2QapZuX{eL`ޱB3(CY C= {Ov.?]6Fq I#8)۷H(l{7X9 n:{?dhh/SPd48S norї/]'NQrnpSgft"&XܒB >❤ɇI૿0PKhqdDڷs3\ueKR/AJJ٩5Z+ڟ6il pN2i-ɇ$PKc /[EY#3D\L;툯]b^GmFӼ:%;{!sp7ċv!^]Z%|IQ}j}$or_W]ėAYE#u5wƻ.giWOfC3;[@b:c$߀ft/@E(S״-O@}q /1wG8Y4 3e v>۪9MѢVbu8hu1E,mn!x|fYӏ+9"}LsD`#:\’З8LɿzZooI7`ƨ. b3}fB>b~&#þ.@ o4Zk'Z(NvcnCqg;Us/l c  T:[Cn%H0z׀u({v Oݺ֟"4ƌ\n.7īrzf*Wp PJ hF/M(vü*O509jm/T>eNჲ06,P3#ڢl8tukdJ@iL+@%yMtڔ6eA)ܜfĶOv_ BAQqv*h Z ̎Nآ(QjoSdXo` }NU2rMª01ԭI?>{6't \#ѻQVdU%E6[L4"w;+fx2usخ7o^{fhu Q5}4esP#́PzaxPL ["ϸ[G"Ek0*LI>!|5~\x{}Z"c ^4/B[]$K/ ÀL6@~~kGieCbmGd擵P*]k˃d,˯xA"֐U7_509DrWZ.r| D=~|9s|8:D!ww{'Y5 !GqvqXF_ȕ+#5c#vaX|LRp7U=&zT+cM5I")*QCZ\ {`{ U@Iw^0Lg6J.X8K57cl%\ԝ!p-Cw8 1 wPb ϯ/vӭNqj9TTR1889s4(aюhzPI3Z[UI]]b!\-uEq(T K@l…rd@Ʒ `E&Ή3y0aX./CsCR2čḃE$rDy'qNt:ʈk*#sJI gqKjfo'/ G*\_>y#(+u>  nv"ΈdB4drNa隈l{=jȗAp8>|BE7o0|0Ե }tZH#8UWyQv[*90GoNr%$cl m)|B64ߎ|$%'RESoBkF0q}+!pROB&ُdگsZ(xUQy5T(Žt3񨠮[:_7dh5΂ĘˏDϕkrnTd0)'A6c QנOsl{MUӏrwcX׊9 e9SKwY 4hKޭ5RoC7SO )av :O{V^.ri[aA'(ߟ9X(4]u5uHٔ 8۲]$m𞾩VpdƩ-YVe߀V͆2Pykte F҈ř0ThD_z|O-nOƛ Yu"\*5Wy^tAb)>RջMʿ>^0s0br2Y9ӓȤ08ݨRʽAo#C1܍}@7n:c'`-vE],ut:OV 'Oh/-ug s(DzΐR86^@y,wO @r.C77_ >/C*h9.OEL ʠ|1Sd#\}k2+ߵC^yOhC~ f^im+BnU$l4Ft$I: .e7 2es`!-|8JIG\~QwXjoƨ)qoOZC@0[n/60+ kD:tP[}My#2/'6紭kI|\;f"wwi> tRNГů4iH)d)|3fh;h3P#VO}B$̑H:3#"(jPpڹ熴S\\beE>fd ! T=K_Z7Ο]%mY ֒šuGRo=%ݶZrmdOnGΐ,V ?= z}EhG]gH'DRj8 iP[#&٧4)'~v?79x?:G,FtL}qH ID!nJ+AbkifO^@'^WڎC@m!0?[;_qV@!(+zxQS6Ao+bR*aTg&^\ME%mh 5S}${6( ߒBpɱM@ׂ!<bSY/k3UżYsRP:5H~vcSiWޥ[=,p呉[ f{#))F7x+#X'y !Q$fhUb [&>4 P@N@H|+iE9Ƣq-:'H8gpә`o-7&@n{8 z_>/ C$K=j:+Xd.!9s2tDi7ֶm@4"߃("Ƞ((4y9d`ٌY2ڷ^u+Mr4n*buue3DғWvPs9;GNvgsQY<{֣E}mw\df[j4dчކ ͦ~;0ؑ'hWG-2̞hNBuDR;O,E*HSC<4}ʀßaHUVz!-| _Uez,c_zZ6 fP7M3);LOh֘fLW-ϭZ%EcZM y~G!N.Zty/~RN5ݲy ãTO/Hy7YO /_RjQnz~g@0g5 V :;tCÞ،+=BP\Bf=.'' b zb%;_D~+J,dDK1u i KP)` |Gb;6ewHT-hVcL&Ohr`WزXB {l*)KϣU6dQ?P+H4V #Q$9i~V&tr$qw "lJs!1|flz9#2q|#'`KN{¸7R3`4z`eҚJUn '6d,\\kQTSTT4ҖjMJtO ,$&RN2FDk(tc_wui,MNBJJ#nZj7I8NS/+mWGҥa?+ʐڅqx\ﮯ /B7s.`Y A$6'\]®܅njbXG,vq\zڴA>[}WAhcC[]݋:)cpB:D#dAwTGo7(W"mNQioY,3K+,#rr0֕m74Ҷı+d6]2XBC\"RGpop,STP7qO}|s@*\ursheoI'0!秊&)f5x8Yz+ }ljB _kUhf$_Y+x93^PIF6t}%C096ĜcαLbuF:}]';䏣!?@zXtuU*z NKo _uG~_lwYa dx[:^l l^Qʎ{ ;~U˭?klhPǭg PTŽKvo}V \&tR1…c79pG[SbC PcOW;V{0KM_k>'clbmCw S-⟒34f'k#Y}J/_AJR!gk.5b(fKX%&W}FKȈ0O8d<)ˏ λ\D`h>dꤜH4}˹~ЏIuӝpˋt!ɿNuӁעr.~x|lg Y3=a`_(zԑ\+l{ @v!'ZPCϦNeG] c+x7pGQɭ>\t: 9] -"p3-ڜ9(OumMNi}&jK j f`Ov B4DF2.E`X8k0͐"Ɇ#J( XIm~#KF ujF%wx)wM+c 쩑k%r*z/aڀ9W2$nk;p^Zetd6^3ËO;$\{+v+;1[4X`Pè:^.z1kN?N*QfLL|T:ri^RkN !VϹAD/)<6pk}@>n9V*F,b6~-^zu}30s>x,(Ğx~?̑<k!ܙ?N+v8gHt7iiRI-yGTƑƜ;e\*/'!-mo^1qM%\bVS -Fes^5O.?Q8O 2`20~2EݐZYl=7,\mR'"{,ffK# &j`oPDrxo7T̟ ~av ޴>; #_|od=DŽ޺Tď`ݢL 0@9Е"y5"{Gh0UV S 2wxQ̆&ģF<#3ABV3`CH%il9 rQF4{Exf!*oX"wu1-C.bD܉JH .y#X|A^_}x-9~ԘF N4V`QHbTMJ>p2im(\➤c ].P0f4GUZn7)Y^H"Jow4 ?J8U D޵BTbæ=g/h 0KuƠg֣mx6CoMھTVkc[}%=ss(1gb(NE2aͬ(x>Z/zNPR bk߾/Q񩉏Kylm L`onw%~No>IkY5bbA~Ql_M C\6 N+fZ=~ ;B=fz[4QKY}5<ѪK:AV&1%p(k6tKSpxSp~y;,p~x~8TzjyCw/\G|LfJ64'SSN2>F8}9e$;WYxj 7"tɻWP>iyp|#ފH&ݣנLIZ#e*n @,L  ȀGr,jǼF482/9EѼ >CẃzVʪM( &&%C%A;(`sp 'LJRL[nv3cu@3/Ip׳\IEݣHE-8ֵ,@4Z'U"qL]Hf` E1|mˇ#ϓtHr`HyΈ<#aO``hK9j~ DuOD9ov<yޮ9m4ח+OB8ɂYYŋI.R?W ~rMS1d*v [ c 1xtkո0 B_c~lN)4tfh>9ev 3Uo`{Dc ҉6 򇱄[!ݣtnt uخD;PV_b8YVai:<ѕa2dH_;u|,Έ!r Pqq0g 0S&L@@qP_\0I JMk[:}8c̶_MX$_7^~Tǻ ` 8T͏}C'`gT8(.SR=~Я=mw_|g*ZB~MtA?f㗾ܸq݃ B7Mh2 S^k5d~PZUdl61ŭ{m`AM0$-Nm(-h3bJB3KSDSf"* \ҸЂ*ӊ/7*%m\8;B}~iL_,F7"/u.?/@{w7\FttG~sw,K$"Z*-H:K8`h݄@ˤax("6Dqn/ ;ƨ0׍ix*V>V3ƞcrUTLǐQO<Ȗ2!6O\#os#%臼wu}ɬ$b2* >52^~fSl~}`>t +V]ǁxV˛,͐ ";,_i}>"Z'%\SkA٦iۣ jʠE_Ubd膖nІ 9n*NI&>bLo%V9Ǣ C@Xx} p'r$SS/Z`1/b7C}\T](Br"V,KqyPG*[[/"wrdT=nFCA^E+OЃ<liUU$;*M31H(:/WP5 duɀ?V.7ڨwp`+ҙ/͚[Фk;1ݾ&>F2KwJG@ 99a}s(l,XY( K#}yu|:~S?X<:﫧],*=+X0āw3χqzXKj2.w,{ì¥g2ɮi2 aQqVJCA׭{;X ʖWLfCo&EVfr+$7Eաkt9E>ރgT’d ;қ? =H??E23/xO?Fʭ1z`'Z%x'Cgbon28%QY%#NЄ  (Eɼak9i1_@vIeW,[x/6~*-F 59VٹW*7Iau !UU"` L# UytNr˅ s[=vG:ŐN84>'}״"nfGuL⽼Ok)ƄJn2k(.ߘioE3~Q)_ iw 9x5K+q% L?T=Oj~]mգ/TYѩ7/" 6M)m>"ŏ?h)Lr09(,IR?2.w>|%.PnyX ނtUMuH(1XaQAb C{od"?_i&P"HV{WJ v ~-'[BE˻6 $wEt% m#uxaMXTAyጉ;} 't#Ί ʣh[ЇRs[py JF~No Z()w`sX /uq Q,쌤?BoFwtl@ʝeY-:[Iz =)a39B_Lp/N$^pكw 3B& 󡝥D)'~}5vL >Bju,BTl!gN.ʌ5o*ЈQBRXعv~:2;RL0XhD.ȵokӋG͢wj [)zsȌu ZU;w(/Knylq>TOKr/m7Aqܽ i#n}X\.v -&%ג/4p% :}\N0.&q2GvNόiTʀʖ*9@ySdڦG;u!cqT.u]qЊ*D a#s Fnw= `eV9QPUc >{& 95um2k*t,"8dɄ׫fHt7H=U˒Īܘ x6)mi o$z1Q$fJU6$hHpwq"Ǒ1Ur 8^ôw?}S0^7 >7 Ð'iVn{ES +J&}@h%[Wj,vOT8GʼQAqWֻF^DZ JYFn ^綻I*z4\kƅ]g_)xNz+}[pGqyz <6=h"D Jj >'uƒ `c~W:kuV̂_=4p2xqUN8"`&BPTM~fGG&Q}_9E/p5J\KuJsA(]2jɵlџ^8QWUA}槉kCv!B8mY㓲nf8Whoy&-bq(l#a -C?5 碤0bۘ 0X\0K^;*iK)(@1(T}rz9h(f5[tJF3b|>\`$*G.gokcfA /n6vp(.008S v_-`jm'$xDQgdO*j&*=2UMU=oxp>gH!Y#s}9Rxlò˃]NIv$EL+zKiR20ӼNiwC|GQ.>Qⲁ"Rڟ T(CeK.g4ݷP%0)}@^[v`>2F*xYqa`kV߈υ;Q"G{Wc̡GҎߋaġMChс@+`󤐌,-e80˘HwRdU⚋n/T.R4g s=2]X q4ҭ4 ;]n4iٿzJ⮌R]0K[3hJ!7) ͕qolA'}L -XYڑ`_8, jmvّ¬=RUFZNWJD  ILɖbw>cԭAPs o|BaPK _R1j+NఒH]+3?ҋY-\%iݫ2|ܥyUU5Q/XكMߐ'`9Bّ9ZPq2+,cn@U $:RuQESʭ0QT @=|[DFT/"`XʃkǯXGw;L?G1iö27+ŧjZE]-w9&[wx]97NAtwڼA}WHn'z\19 #k$Iƒ2V<$\=8x+8.j2M#deBo 6"ߤ?HD'tƝKuy8l'",\jAFs׏ {<6ľ >{X"2TNIBZ<$ ZK?<]>jjM>WOIXLbSe'Jp< RF?FcL}aAyզ15[} 6v݇lvAe"Z ג'KIPQ?@`mD̃Y(9YcgBe LB C$2!n%h WG޵bg=|toQR\dÂLa.eS6hN;u߫Q h{>군%#5O{zҬ+.m EW"O_i}yW WvLu&=)1%43zev#zwr>Y(jVLE:G z| \ j4hKYe!:\-5H Quuqk4ͻܢv'a¨ݵ})B6J<]&hF6mbm3xU=՜7MnerjSBdL!@mOWIP-\< &OtPuU/(Ky6@AeU;ߒrRXHAO&I[` Us@gl!- N[rezk'~0%'6鯠˼s5a^S.Kt[B\M<j6#T>WATl.*F(e,&^آw).S |ymqnTKF1`]ΰź`cpU?@I偃S Ntsd%XQ%ۈ^;a؀S/ ??AI#馒:}LX/.":G-J&v7^;֥m.@~$Q+{TnmZE0`ncZ)(3*c'Zn͗= 0i,7O4uX~h3U`oXօH" +P.h ]dRhfV; qa Sn*w9Y$2Ge،u~ƛ(+#}(0ST/%<BsB+Md4J HČ0xy5F>6ؖJ* a4(&$#? YJruLL3\2eWcWMg}isvM6K:=]R"a K&~GxrfIAahݲ^ G_JOx?;ژbAő cHSH%zOpw3u k;V H&U=Mr>CBzC#.C\Ŭ,KUw_dIt͊O<)wx6,E+d&K.=?,|n_!Yg0\zs6Δ-4GL!CPrA- 0[|b !"Bt8(~̌zD ]'?c7eC|!tiCf cXj]8n=#j] K19U|kzhPZ̄Cz)-ؗ3JwF|%t-%VhLʟ !\vo!I_eW^ jjyW9ę<(/| M YeIpvTf=TILW_qehcv-|ߏF;( E_oL!7_ǖ~;WPk,]#/Qˈ`s|E0"Z!h&D3kWrC RU'͈P ٞbtO.{2̎#i'i=νuHH52E178850 ~̬Xn l}N,K[ K݋,^nq!8:ƀ4HN]Ek/O1fC:ovwY՟kGh$@ajmuQrp~1o>J/TFifT8<Ϡ @r1IJSiܒ,"8Og !jV(1NL?M"u'ʓK 1AG˖rdPϺDDCDqbZ`WI%##qg(Tc$p&KG/3\q`nZM.*:,{u;(#큌.-HbJxvDrHD7`"ׄ9tvfT7Ɣ^l91?j*XBe-ƽ/ɋ aN̤my} *bq Hv E%?sQ!#2l=}m6xCS0II1ChDy!ˀHX#jgU^c {+e{M,:}G#]b,}`|8W^P?%?L΁P<>̆]!)F/a gAwEبs_ZZl“1a$G`EUSt:D} ʩui·[m r'S|`dif7 =Pp<ʴ7YZSbML ^&@ rr(3'X1+crmVM,/y05p>pbe:Nyf/,񎶓 W-ol[5q+XRHF'q$̃)~# ektfZ7WujS:5kEy9gRg@ n!f^j,#><3m+9u6B>VIE_OYb?6 zkko{$5"TVv۔!YB&Yv8ױkn{LI9?q5Hs͸R֕P ǯڄh[~|gol@{la3/k`8^ɵ!"Pf,VLoeAttH]3| XV74dн@ ;d_U8*7p+)]e), `jŃ'Nֿ(~OR6ё# 3M ծ.͡\^;b;%eĭ//{mhV9c-(72 W;L5 iY5@5táF6T$y=\Zs 8_fĖP2Y3<.)(-l_ag^N{bt yLT7➀D|KK$bv|#[j{:>> LP(:H!IoHk6 ^BϷ=. j+vM@5 Ψ1B:;+=8Qt(>5wLCŽdgD_8.x*ٚa/hr9=ֽ5':-9'((̈́%vď KNHqSHșR}t\.เF9= ~$$s=1 E'g^1ten64qr ~1tB+s0 LS}?;5D40{\d5"xld?#ytK)Hz7Z' c yE>1|(w=Hg 9P*,;M3}`6ȾnSW{[D}d4 5L(zt0*˘I^` #a_G=^~ݮc뙲/}p25Y#Ƌg  ոYa$m ׭jSzG/#Hɑ}= N ' M21JZuT`wxDzgJ.aynC6wE߫oa'SsU./YЀpj PH=>pn5&ٺIƖ<k0Am_YyI;xtvbn{4Ki`ŭNKպs-Q;t|h_ ✶N,LYsTN b4[:5_t}"A܎(ØG>Ք~=]PI/}CQrKyk^7 N3NyYdXC*X3 >S5h,\HyO@R$$PObz@IPB' iu'LUQ₄R賾*ѺoSuJ[(T 4s˫r>l<'7rI62+4Ź.X>]c8 0Cؐ1Ŗ{%@3wFjж3vN˚laW eUJj;oO/2_^zKu>P{PK`t|#Q9n*+pTC1yS_@n5n^B~+/ҙ2=rkJTHUzU}9)q=&5|{攂_R q̼?(Je[ ];t%ڧ' uE8T-QChG~LU(M!LS) :.QlَR3L71Ь(K;S[X4 Ps OYct52\wP\S>>W0z%U秎6)⢍p  w֩e鶩bpXAWAB^$_ӑھ枪FӊepB Ji\ȬHrB˳eK~{kNJtP]ʊfpN (w?ڤM[K mVt$xWÌ-;,r2Z7A*>:ԉhg7N0.;JBec>X[LBďăh^lUV.1CɭAa'2u1q4RM- ~՗H~$c5!m4̠#Dm76<86@3|@n8&89u o7,zՆ~cvnX˭>D[\ĸസ+/ie9PLsqH,v7Wb L 4zBTm;@ֆ(`trMA,< Vtz\K&0 а)r,wIpr5-ej^63xOsG/(]=% o&j7ɰ RU@P0pQXR_ ()5Mn 8= "XO_̓3OEi`'-5*-K6u@m"CGf,EN aLh>c@eV4EEB].!j)??=c^9~s"3L[r.> /9 daHVDmW;OVexrVsˡԧ6˅khWhԭ1Ves~W *&ÄV ({E+EXhd;d\ȋͧ|yseD)4Gxk;kа4c;oLGp8x X {v׷ą2wULy*cmL(d[#o{XVMUBw #ܫU j.~ 3(NU19-Eej迖~V_ԁ,*mfP i+n쑍m¶r ')(IP}N CXoYv@2{0طو9#\*31PXTvg{]`[< d=Iep}TDW-h]~M:vY2Jnj!W1ǣrca+|=RE.Qn8m_!Ŭo:ǀ,{ {I6R)Œ>8g͢o=k]Xp 'kؽ E C(lȜ4a jJ_}G;&, QnpEszA20zW{϶]uWe3<"϶4zhڕ}^][֎{V,̼B&pLWN\2j'P-!b} 10m奧=gZ ?O8>1^ːҔpljy;1% &mYZqù^pQg,Gp^1SM'E-} 0_N .R k\_s1: B-UDL tapPW~cF4{u]B .D%Fç”pZ =Xױ(ۙ\*aqk^Yın/mi3* ILܠDA+Ìyx=]܎Qm)_K7IXN^vy3$it~ i@2)(E@S4D[^\T*0R]:֨IH1Bn0YmvgesiCws;TDryMz hXG=.ŏ_=eI0ʑz0TVm0'YA4`D^{ ,9/V?x #dm k f0H̭#fZ3";V ז=Kh~H(':K'Zz&_;Ag3߈B@SWכH2[4qقd @̺ D.S7ea3 se8f!! bp vO"w%8?`w2X9>/,YnyK^T5 ϗL*ya1R(mƄˏnWBGaYC4wb*2jq;vynLȓ*)Db[nsNaѦ#u.w)D?農wkuȦT$~״=0aaF6HW@!ݴ4.6ȶ>)B@2Xt]F8$l 1f1[~Fly1=VYr> $&+:3$HW{_CLѽp:M{+k? OH?U~ TExAanik'sf(#̿G( XH%5W!Ht3!|f2xZBƲ|fgɨ' y#ו/$X|.x]`+A9^$[!߰a .֐:VX+UL!c캘INsdO5lL˞' %v+AsEoY[ ͪ Є1Zns:^b4bNOHOЩYiE,:X=GT!ʽR nV3mmCÕ#UUм=qi9.J&%{9ԣ]5% |(/{|nT:BwXd=͑[_h^-1Y֚>l/Kx/e{O/*O׺NQ:o1*;ELĠhz1XTV+Nȸao1R,"G:U{ _dhqxY}9;Ӫn<5p=N^"xhH4S z$r-;37ka$n>Ip<Ս<1&>VCXt}\ՓlMڗ'VR,A(@D~n4;B=w; |Q8˄JN:U49AQܺ@7)I)83{^Y had&؏j? (OIn Fm':j K<:kommeUCn C4 B/7ZG{2݇ڥXQl BҖih];k͑dIvڎ9w4<>Lj<}蹺86k1֤n5o?A 0X´l0^R0,ruYsZy~e2 7,ļ.PH]Z!Q7kq!PkʙÎzQ 0ɁЇc0 FG=vS$j&uuv\o㊟E _=/6}Ãުse:5O|*$H :\[H Rrg}QW|G:{6ӻfP|Y{[׻H4Dx}B#lx5S=l([lW' ^bVu1`_Sx|uG+@W^ԅӧxs0̃0VV8?ʍb.@ݺ4n= (x2UwXJs'.%x ^#`I=NH}AЙ~`?^JVr'%D߸T7 ^@73&{IbpJbE~-ڷjc]/&Nz N؁7xDpfJxmf{}i[ڿ4F5+ܵb(<;͔spiZ1/"#@`Ux)*KA`aoa`N퉌ho : N!|E'%GDq@0p0/ucx>(EaiNe@B5oxO9ZBnI=Ö@zgi61Njp?q'ˊq:E ̓@b'Z" vlqg*J>j?ň <96.WUVFwSNJ ˅1܉Bx LNU5a ¸G>V{/uJǵ e $P236Z:fK 9s aK!2/-(ׄ&} *%{v!MAEE[^!Rcϑc729 X5/xk_\E#x|&}]e81f)7;ҟc8Dz |km4g>b\!Ϸ!0S#:$r*Du_#l)!KPǬ|xL>U;o>9T gnz4< fRr Hgq9+4&lBv"N:XGT2\,_{k2{dm p)bmҪɸ3PKDqόँhڮ;x,#tY:W=E60c~Yq5IHO7<5aCŜZu+QSrr\<Eh37g~]y x~*+&H\oDFc?˪=q Iۦ7k2eF olqZר kEwڗpR V zl=˦68oW:Hc FDz0#ZKo2LNVYP+AXZ)[=`{*<0n* ٠*=ft 1XQwrtbTjeHDtOмF s;~'&PIzİ"tR Gت=rfGe*M??G]e!Gsͷl`ad+n h>'5}:Q)Bl<$~vtKW|/HmX6Ü)PP=3 iVg @mlLZDN$/ȏl{-{%RLC3dv zjG@Og5 7 *Mأ[Af R}sDB&[xQZ6fM0L&^0ضOU|8MQVN,+5%gjY%;2ԙik$R' ŚaW :izc#B7UXy "7t%ߏ x; &a3/~d:^^FN3ۋ=|QF׳Y$/ZFy{y+%Ia#c.(Q-;'O$ V(h|j69ш;/vgk{f.X*{#P'eoᶍ΢`f⡪~[J4%W{Ğޖ@ +r5آ(DjK=%,CqѶ:RMlaNB$>rmZ]VgB#GQ4rg;ʔmsρ:nFՊFĺѪfc28I+^W'c5ܕY#Q66:OR~ ~&M/;C/NmNoNBAӧd5pJ=4iƨA*1*2#Y픦&WY7,2 vw!d1u&G<8kk˷RfugԐ̓vqkZ"#;ĿUk|L'YTͥл:XТ ^R7(hĐrWq*eY``X}w шpxNQdBPI9LX=Dc#o$LxHjovڿIѡh-s m4k&Em6X/Y>C؃WxV,?G Xzw9jL6C "sa -ĬΪH=90g9ԡrX2Q]wҍ4JIvL"QV`c0eI&jfؒ 4&M(QҨBuk6!DӸ?km/[x~h@ ]^4C|}fMq.Tz=M62}f>p k=ͅ.t"5c[DO#8WвhzH[Ld%RG#" Od2/]Y"?!{tqug?]D9ceՒv|,qA'EuSwYFW7z̿5sS쪽{+a-_uH23C7=G$ 'Fߔd@=Ccއ( ] ìt]YU=bWxVC"T &MrJH^ܧz&O8]_ɓ!bDvpmt$F3 QW5|VnU9_ e`o̲rȣL1`c ά*FSpIFaD3>=P|y ;$beӤ? :T?huO5?X3pXGU q!%f 0ˈ)5,da`_J'* KJ]%UHWXD7JL_`I^ UoM#>@Fo/ɘF.ׂef+6-^v-S۾ zCA\Pt-qziY|rp_xPfMM|qz7p+1W}92a3#y,2X,R9Wop9&([ܭI(=`S>W*{-IR畇(XE=-t?P\ 1RQ|~RX(agK\N wUA$l'5"` &0JlݫD϶ӹ@[7t|ֈ3c$8nby8t邷O iMD$ /g鮀b[M=&b`A/A2 kH/G@+*  '<Ȭ5E w򐀥l*d^ET-;=CA }J'ZwpW^6z7At/V몈 Qo"ZBZTWpc-s=%`NG߬;g(cu"ؼ֖uC|9&c0hC֫зF0WKUSŢH 콓mf6|[Ry9+=ۘ` Yi=.)܈uRp-,tz/}B%0 SC84u31~Cj԰+KG_K捶rO]wvMd!Q`c-uoa\5qU)*/A9][w?iny~AFF$٧=S$z$amBysYy5ìᬃzZ7p r`LCy0./<Xbv"qf{J [tކ~S)@}zsGJҋˑ& `U Ǚ:@љ%Zby -{bAI9h:pVKҙG [c<&з ^d¹/\zFTrG Ow* `sv/g |ϳ+q M A8RLpi)13 &Y "bA}- m=2LC>Kf|VzW pn$ό] @lIs۠):Tq&<ַkH^f޼?rL[<`k7RGS+nF<|(o՜ :yY^c,>BґQ KbHl)bޖvFAho$0n~SޞH~"k1no5\5p7c! 8Kie#&>`7ڒ_ 0dž.*SfJwN?l28 BFlc0-OpkH$&al@UQ.|R"-G+hߤqWA+NI;V/"9MݷyͬHWa"Ճy0/a'ۇq!([#K],v 49d-qE =8 )=~a!ȴEO }-ynEX/[𘶘riU%. KTcx*PtBj#lMƆgZ9^^ Μ hzPʵX%bͭͥiBeCz(Ve^ZGd*Ygۧ\ۀe:DFmd^k^~)@QfCLddt.,bw}v#9?ҐRo{^}'XN7sH|A4f- F2 TѕߡR>D\9=j]/Q0! -0˕^ TzHU-WSe5ЖKPb2Wb5b eM8PP:t"o緉z5eCqxon>mV8GGOJQ4w{JkB\\6T6( 0NH8p0p2yLKʼn?g󫎱C2uexPMTI36JM7ʷHĎJُl OpƔʑKWY!;P܅㚮8]"{9X] 9ȓ!ԫ^ +)P{50޿t~X5S$ [3~Du[0n{c<9*vȚ'BNR#: 7GM˖ӉDKV!fsS]l۟)n>׊5%{cvF a"hvUy鴄QXzVBn!|h辜p{v )-hXߪVQJ;|3zy >E>awCaZ V7T,~{sAxt'8f=YwMJbUF( :~D7['vܬ?Q [*S2([tL- "igݵϏ{5b.dݪ/^LQˑ!K&(Y9N7DHk.oב.ѷ䕞yi𔷃sLœNԖr +SQ.Xy#["^hQǒLp&MI&ϖws艻 d`/;cڌ\nbڜBv圕n+{i)ϡO.k}PA`uְm]eJ ΖlbY&7]P7|:[ID\`9퐪@ ј exz1I:M~8@& h0˜f/ y6(dMFǼ2:L;ſZ3&\9CH@B$7kOR#n IVj8[kKEml;5pOcvZ{ǵ}Rݤ8 sV8RWp>> kjd|3pV폆Iy(%/0wp.eg1 х (ꔶQ \ŋT%XnWt(_!8h5B`= :j(˒4C,HzTpr=Fp'Eyb57ds(\]J6Ǯ[9se;φZ]4#y~jliT0/ABIc|KJÄGBWF\=e(Ϭ%cbq1R0,a3`Dž_:&n%҃l dj+uLEbצwf ]^&&e3VVLR p0Lzؐd6;l⺧=Ak0ҷފl'7؁; :1\I}XBQfLEjJkO& J3'y k}L?(җ` C<j(}=D 44NCKlO/Q]k)w%N'ݕcD@i:H@7]`}*QmI\4JaV/mGFCrԇPof*&) hyBlJ/@@f̬hDh{XpX}-O7# t:92fl{*UwFzH; "f%Oiz!Xͻ+\0Th9禥5i>Nl͈YС^/h$یni%/罣/`ˑ,DIq!( 8dET1zvʵ LIqѴ5Y 4htOᴆ{݀61n#f [}VU#@nQ:8o_|س4v>(h ӰԶ˛TS)NTSVr\ l1~C \d|atcfš28CS% mމd6dwI 53i9T΄wWqN}U\WIΑQbE[ڮ)DѠRU?!6KrCJ efp9&u0^/vQBU6!: 1EH^r(ɧzVSqAX]/A]ذ&i@2VQH@? ;[F7"&PaZ}6mD`|w|OЧrjA-i%=Mja::dVf ǯr ]mԽ,R1W.рW6!|)k:?H^U$C MQ&DH%ߑ/m0o&R 䅠dBT@p\g)XhO"U ͚ tRn; no"ua(alLQnsf}Z7uWMcTaS^ 񠼆A鍬Zʪ(\01== t;60Wrxy9bZ Sǚ6Ǔҟ ɛ{27r߷&矏}8%wt<B>ytYnL9@=J v"Bq߭caxUGȅFIB%Vko: :fK!CM<aCcu{_G)d b{cd[ɏKLU5:eUXlK0{e*v`c¶Fzc3 nT1MqJ4 Fe 7HD_d<ӆLEM%ʽKOųp3u5Δ rCBxBGmzѐ]gEx0usW?./֣2ʐ"_ÈH 6)%VB7 )4ւ:<+P? T U^rpѻ¸ju0:XXr_c2-BA-})]"KԄ[#ҁ֋^VeQŮce;y?yqcujreވ Qa'K=T884jB{iHl`%\%zZ^\VqC)O 3<bk TUS~{Or*YɼhmJ}l:C!^@W}( %4i8$UӬeȇF 8H 3_ܸ3.7艸L;a! V,%i:y8jJvV:bLE Y! vmƃ&7A m~iҀمǽ{wm;^}@"Tg⭏mtKi36qa.]8?eWP"V.}cWܠ\h 瘪-Hgp)} VB;/|TUI'((*y*`(Vs2z#I jd ֘dc+o10~if tW%p(߭`3޼N|68o2 :~[3m2PwFj{:%AW۱e/nMy =uHqt7}Jٹn_B5$Z?gtpKzQ+8MV׷qH?8Of]J8?<Ҭhwe7ǣòE=O=f dϨtr]q |-{;5ݦObAt `.1y+N.K\:ܥ*~l$0HTo%7!c|- _L=m$q:uJgvaxV5!U]g,09|50)g$ AK!픡ФU(ku`'bîUVN V, Q l@0HBJ"*ïRڭ6 6*Ee,s#_׊eЧ$kT6e3ratA0 l jMA_tZJځ,t=uř$/4hܻǯJBhtd5oj;I:Q=;\72IJ]u'v#\R"ZŲT^_ zAuDqM=hՂӼj[|gv< *!qM*98G!2H:D؇dLǎI)㙟g?yz+&VG<[]`^ le,ԃ4!uw0:QT)V"7ydХ2#VKݭSة{\AǪ)/-ƓTB5akUf=,rq~ɍV#XK^PsѲkHvQ+a_McCD4L_l./V }/OmpLPl@SoY!"V9JxhAAj>+(C);,#~ӎi0߬(~{c @bTd3T{ɪO%2L[/|EU{rUioj@?k" P]D6 aȄdK/B+3#3㦐ZZ}:W9cyZ%ջ׀﮳JJjQ41rr2ҹU1YB*#8~-6L9ccX8mSGEjTxgB-;Vm'.Bډ7Fb2UlrtbIz~p*׍WoE7b" rXNTml>cL09nԣ()S2ok=4O9'$wXE*LOX>r؟S9N@T1ж w{*-͂Yfk^_L٫{w+#́)k̕:0\pEDқZ ?,Md\guЦ$&j^k GqЦ Ӑ 5Wm2RF[c2 aP qV@N}w~̽4È4mAh*7U ٰ#d,Z) ]\|U E\L4׊B5~p6vn!puf}`Y~nu^Vy^mz.ݕpMY@!0PO -Fj-#D ՂXsѸ}Q8$|"(+[u[rC]%tѡfb f>}rzg$މln7kÛ̵HfDf @$_%,Yic)a9ފ96JԵ$ nW ,dN@7+7ISf$ DG('R~~;zXB\QƟ՘fYQ8 $(kkA@6Aa#m h\^LqͽR>CIEѶDCp˳V!zӝ9RYKdF0?`-W6{<VDROYY%pA xGy}'L3(ᦏ, ۼ2mW Rt5󊠀yhU1& _{)dWH޻X݅{X|z֚*6Qf%9Kli|H}+"lZ0KJ<܉=O8|?X,iֻJG9 Ѣ +5`֔%!s;NqJ} sJ?I`!Fh ,i!2'Я O1%Q!w<="Aಊ*>[Ne9")Qq}CErb1<.o؏:/vȰ #FJ6^i7QL؍']⧀i9{qdd jvB2[ Q6dKԪ«A79}ؓwHԱ~␝%ej!lB禎ZnWѮiYXM5ݑ z\պ$TVq.\$m$<-xK1~ԭ䐛HTY!)"y@#PRNEM~L˙VD.'ߠ=lH+2]13ƃ?G Ϭ뗵}E V$RT?3Ǖf*@LYe78H;D#pPB }&ꁫyCӱ3ubyG?2mM?UXP:D<ۀ/>91R*iHಫT c#8mz^m# 'uz`0L<&"{}ܫc_|[b `::o 0 KH"O&  |`/CFh%1']ZA=GxsH >!;JB {U&ph jfx7Ң(:EX@x@qjyTt6GZ`,6Ew3>wQl%}G#kS ޾m@/O+RwN4Ї|L7ѝ%Y|('\D qt2*)rkXI(}qWpn(ϓpx62T'vM=dK;~: YZ