sssd-ipa-1.16.0-19.el7_5.5> H HtxHF[2{ ?*}}a,e~~bɐ\b{&v">?d   : &CIP   8   (\QQ Q(89:t+=KGTHpIՌX՘Yդ\]^@bdמeףfצlרtuvw<xXytXCsssd-ipa1.16.019.el7_5.5The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[2esl7-kojislave01.fnal.gov EScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdKT#ZA큤A[2eg[2eg[2eY [2eE[2eE[2eN7bc16dcbf44d5b098d494969b04d30c3d5d6cbdb2ad63f0f1925438cc2c123540b69a2d87260437c8476171601f642554b6b0f7244567b79adcfd135f4afefdd8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038ceaf6911ae2147b3e34609bc57996f88f7a3eca6c6cf28d00bc09ed164af54cc8f015ea3017276c7c03cc5274c8bfbccc465b09a7b42a2cd3f26ada34cbd96arootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.0-19.el7_5.5.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.0-19.el7_5.53.0.4-14.6.0-14.0-11.16.0-19.el7_5.51.16.0-19.el7_5.51.16.0-19.el7_5.55.2-1sssd1.10.0-8.beta24.11.3[[Z@Z@ZZ_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.0-19.5Fabiano Fidêncio - 1.16.0-19.4Fabiano Fidêncio - 1.16.0-19.3Fabiano Fidêncio - 1.16.0-19.2Fabiano Fidêncio - 1.16.0-19.1Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1583746 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process [rhel-7.5.z]- Resolves: rhbz#1580281 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION [rhel-7.5.z]- Resolves: rhbz#1579780 - After updating to RHEL 7.5 failing to clear the sssd cache [rhel-7.5.z]- Resolves: rhbz#1579703 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] [rhel-7.5.z]- Resolves: rhbz#1570527 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash [rhel-7.5.z]- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.0-19.el7_5.51.16.0-19.el7_5.5libsss_ipa.soselinux_childsssd-ipa-1.16.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1d499a062e5dc4242178954fcf96c003ce16bdb4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=fa53b9c8ecdecf5601b1e2a329926b8ccc28488d, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R R RRRRRRRGRRDR.R=R RR"R#R1R?RAR0R+RR R(RRR/R RRR2RER9RFR7R:R8R6R5R&R'R*R)R%R-R>RRRRR RRR"Rade7l6@.#q*^2-Ma{R۹{7L;7򨨹9%L^nDaD~S\D A4`ij!:@Dž?$WˢCrI-Vuk٬=[nt--_ 3` 0ZKGoᄄP@e?TIiܲz«`/TU{Ckѻ+A* ⟓ު\fHFCK@o./6m3SP̰ |ьIڂ5@x״jЮn#l?D}Ѣ'vR͟_ 8(`V-C!8|Pɫ#Y/K 8LxqhF+ڽ20JG' ݏ~~,X778)o_:V͂t`QB_)g ޺%ص7Ik2R\$Jˡj꿋4QmUI"uEOh*BS&4lHN. 9.6ǃr`)[C/e_kG^F-S+bg9"]Nz0ws<m+0^;xeÝ,|܆QUSRDbHBC愴"G]{Rڮ͆r;[E[;1 zdF"d !.PQ4ihJ2:NNΗܗXG4; Er-V$9;3Ѓw{/q̽x p0m|Pnaj$҂44ӆ H[fhc!oDS( LTm/NCun2G1,{uQi;[&8,sr޺$pk(7Ӊ>Ift) (z|pU0<Zvb = -֓pt6啹-VkN=Ze9I.uzVJEBF[' HS3ˆX)ʹ%#Vrm@."4I牸KRhbmM8fsI ݛ}QQwq+-N-,(f| gRxr*ZLF|~=S.z {(Ǜ=r\[]'wϏ֌9¥$GϤ:5Gg ..C|xۈUÑGa#hCg0K n^L%jcߖM{Bv!nÿIɼO!,,DAvK`| f ^RV\x)>9. tʪ$cǜzOi:^X}3=t;HZՂ~vbƻ~rb uT-m( ZIOW 6Ap~Yg Kk@:ePC̳6J7wWwTZߦ+lۑF ]m7*Q =ǟ@͹xdh;:WQJ'aʕFyKc[H.~5]2NL|ūJD-_;gF𤀱ZҪM>"8􁷑_57iZe1߽%HV,JTfJ`Sf m9(b+q ]N7-I6}w@ǒT!/B{Y*F B5ʅu9]g} TMi.Tϓ PYXC9b6ϲv71wPYb>Y;IuP@ n-v@yM &5wRUp !^X:[6I7u0"C41Ege#1ʊKٙbJ)g;w~Y-MtSH#Vݖ. 2?9ejxX͛~Zv\:nCtw~jg/M{yVj\ X紬X-W'>RX9-x~KM%mp) zЛV @e P3,'Ǧ܆ha2:tD@7Jp>sz2e)NiN$m?9%7:BlGsei&xi1 Tj CC (@:$Z@=ܧ{޾.)#zdrf(7uZ cG=]bz'CV57 'ї="^yk.O@ sfl7EE`2uPτ)?`Z;j8wkha_LЩ ™T-tOHY(>APcˬAXpDhA N]6 <MdܦJAlsތYvʲILwy3&=W !6(=;++|4 rmʮBPPB"i@//<5xHsxOlaodXM)dM{XL`n0@ht 9d%B>FJ^$Z*+1yEuQAcHSl:@-ݿda!/aDL@BYj/9%5.մ=o#[Qf&w-/ 'j i(ꀸT5ƽc Y;8t1qܥ30.Gc%}jS zSֳɴtjo_-5Ke8U2BsՂ`6JS"oSForM]I\63(7;:go0:V/ miУDN.[#RXI*`A gQXNs=9 Оp=P"'@˙H@DUtv/.-M*U 3-чZBXr&D03dm*xE~Vo|,<(/ &8c*:rFp1F㑀hk9u ' - Ȕ˽9`ĨeG'' z> F^+qwk`n()̹-rNoA4ҡ+1/Hhl\t"&E- 0 GtȊTG>xY^oC](19fM(vyDjGwoӳ́T5moo==r;a(d6D0rYkD *CXM7k!?2Yظ,XF}Gщ:J}PdRA9{DX0-/mfi~tMC}!T9enĭh { ƓlT}4EHR=a66hҕ33BkuՎͪwQpX6'<15W8R%p1I#]ן-BL,U6Z99(C ӏ49~j\npFpQ4N0ΨYt=bϜe7g]ư$f007 C^^b?o'o6WajQGM/o|馎$ܶg FL_\h %|*o37[Dۣ1\]QT9R{ZHvx)"25y\k |+t= 4_h.q%prz]M7( AT 0[-/v[DI+*L d.P[vl|+#j(=^h$9L8܄q;vZV@dz<ֵxaŽ8&k5vOD#ۭŅmy<""UnTކ1R5q=ꃠV aZ)zx`#9RBX*ZKG噱4x(q܎Nc/nɃLV z8c_wLJA6U)2sQ'a3 !(wUVN<~F/J*:<w8FkM!=$\vfXKєУ7jJMhms]IyģظeȊcàvND˰۞k]ֹ>RΩɾ)@_0_CS hKs~IJ[9 #覈,.l7,97+D$-yF9o]TlϹ,5|dWU\AfyWQ0>b-9jdz88F68z.6#l!E'ҲR&\CM KگW4|nМ(>3 _YXVܹ!-o$AXPy8+4AȧjIĞM3tqx %06\aZH1 ^Z )w'u5y3tT["y=h$SeXEi3{J&  ~DR"}FV39Wfg9W.DA*ߣqw 5~F"Z|BP" ȝ8.:]ĿZKĐSJ0\nL ˔pG0\/ǏJ1o4L=`>+tl`L[J@ߚ4ދ" =tw&}wB_l^=F&Q͓ ^ >G/UUHQn(`~<$ݱY-aO:mS]p<&OF u+S_Ys:e}HĴuc`ܰ=Aq9Kkᰒ}.dX9oaNSpxGӿvJ9NGw0EI! lY]M[A禼vmi}ߕ!?3O(v*rU%&?ˤz_&05d V _(mg,$ˈcdA`ZqKZ)^k68;̷2Vʕ_[,_ݴ}g}8D)1i~HwfCmK x\hjYHנ؟ jW{ EN!U$F H gLU<q}@&!HAeEF\/6&pzx)?:b3 x(bnqX$t}>MpQ:I\8+#)FJ|ɺ),+\huUXI$.i H|]7('`"xoᡢFDU ;"?lGW`tlU,/#oW ۚC3h}&7bShѥ:FꅐE3Ν]AǴ0<ȍ QƀK!˕x5w5U^={ظG^ +*A9b #J!?ϋ*fڈVJ0m0=s79c_P6o1J> G;,?K`RPFw;g0{{YlK{z\H?OQ%oj=JX"Hq -+8VQ3 ={ qA -hm*i6zfH,k(+Xa Kq6<\̢]v5ϖ^X^zow\dو(cY%E##ڝ *g)pd0֛MH|IYhigeUml~1YU STG XZe|;][˿]6O3r?##!z3Dqa$ы r4G݇[_W]P*. (Q/Xp}dK&׍wz{yi~$B(Zl?ۼBm0 ~ǀCىGPRzn]C Mkga1ʜ`\fV5E [ƽ3McbA|̖{|zP6}0Q_GƸJCRMcO*a(w[9~|#[(.Y2m::IPݝi6]ԅ3zGABcaReN>n'=o5:M0֕raAatX yQ'p\4C>y5a2,Z6>q^hלY+C,X/'|Oja(UeRSs+[t,\۵9C\U]%z@xkxq$ fA;+uNzVZF g@2ü5Nn8ߗ ?:^r$vȈ+7Ŝkq2 =YFOډTM;f+˜WXpZ3%qKY.RŁ9[lq >q>E\EGVPC %e ;%m!< J!E>I@iB2c~ame/FSuA75w0&~MON ٳ.:Pz'fm"ֈ2\ 1dŪ_偨cҼwGW~d vR.>)z.kBZFꯡ4rWST5]]T )g0DuUw(|-lM Ȅ;l7>veth!$*N?Z=܄hLcrϦgq,ԇcpM#)j敄<(q>)5넚8@wI-gV}yxDzNWʣz1#3u%GZ'<<u'zW/`u,]~֮B0Pk[b[= ߷d}DecD6IWiCԙ+Rjĥ_1wLt@ T"^x oI$!z\.6!ɱ} $sAO֯0m.杵H<{("L8`DJxf Thʲ xcBZKmBH$Crz^knɂKo|Kp^/cNYBƾuuv~=W_}4Ǫ6ԺR#<I( 5o+?Umؼ( ;S_ 1Ks\Da J$Rs`+  osR7~4U*/p}<߈Qv t+g>,UL:`q{`ʓC],<~YqyR~WtB@냇stOXGPv%3d~ ԕ)iwǛLN㥪'*A-sG˰̢ŞS`b}K(D0^X42}> Gx߄"Z)/=c {yfTL/=**YN*¤տ%]jss^@WbN/ru#9ȋ"V?=ۚ"AHFf+R7ڸF,Ϗ:aa_Σs6dLd'Kh/(`+'r $sYVw3fq/¶k֧85RtS:%{K%5b ^K,.\z~E(N[z:_Zn" Գ}&םZu|֘z lAט C)k|*^8 MY%HcUrfsͦlBwm3dV2J|+z;Q|CFܛc8@*1] ogAQNWUq2FSxp )pJӎnj_RS-2t2|=8³ (6i&'պ>[չ.<3fN;{['lS#ʂ”t FW>JB Aru܇M '$ =}ʯlV)Ɇ&^hP&2$}r v{xR9+;[jk%t`<}Z OcWlGRl]ia^]KZ;ݺ!5M=n19 eI cxooǵ/9,%8e%#.X(o!wDj Z͂'T7 ؝{XE (q =:R۶sB.$}yBH` aL$_* % &uaY ͖|ǂ1o?MZz>k >\*J9ΎћX^qf冬ʝ*tw45%֜R3b˺{ t)YBZR9/C% D#9?i|z iK3YU' %ͫ1I(u(LQi0Slv FYm{ܲ/㜆R%6 @2dh!+Le8ۥͼyH&\ީ4M+IڲfدI'ň8ur96iNDL-: ͤZLLUVA D:Q9Mc34Rhn!Ŷ0~Fh4ɾah A7K渇vf@Vʇg93Eg-4XJ@Xa<:Qn106$=*L}vpWvtV1"ҶSbAO::q l/JݶNklAne3j *,BIE0c-SOzҘ CVEwÕm4$Ps #vw" ~YਯlDLwk ?ʽAn0BA z9cuv􊤧6"qkFvGeSꨣw5wcoC:i?ۧO#5TJ(6PO>Wg%ڣsl6EݧddkjOCY~wd =NHn7Ea|> _NIĵ I-wr fNjm7Y̖3`r|dCbuP aQ]gvʞsc9u]<؞EfT8Zm_k=aV՚.&0X?TkslЍ:U;L sJ Ͼl4QLAD/Dg)譤*iî^SZ_fhe*tUbS:{9:7Tnu; 7ϕp<f :8s#"Z5vw_-4}5=lUKMD+]ɝK :AvQC]0p[PMn*~x#Qo4> u9`lٓHGrzR\=YUU'm1Ս-#Ӹݪ$ Q+W(})JCMԦ `P. J \\A)_Sn)5`ֈLSO04<ŀ < [Z8Q'dQt%_%ԑLz](-0rUyMq:|sP95:aW[ עw;c6pB~dc#FI}ӳǂ.-{ m%ٳ0R!GbW֨qwskG)3!Q iVuucfd K \ 锃&P46O BNX^)fo\G̾ke *=E;F,nHD(1kKS>,{YCȘIhZm?>c,qCe)q0Y|چR>md1dmLS@gåq`"Cq_~]3RNb'Β1:'+5}E]e 2_ˁx9V>,2ͧ7gn xrwN#Fozl;ĸ|gFd 5!ڑ ÓRE:w~px:շSVoߚAg10KuT-&j y*Of1z]P" 峸 ]''Q+t~ǧC3f;fqcjc, B*?<8@dcW2 *Í!VYDf+^Gk ,#g5n3"jx ?A1}{ly$}@BᩞC* #4G&;ܒΫ M+;wg$q項J"o@ӖlҖF"Y>P>Q9O0p?F ̎?V!'[OhЬMaP1;mf=߬j.1\Kj!U} Jλd\lS4 ?X5C& S: z6Roe.OhŅv^odaGBN5p*8 t:H&;|Ckt5`1JW""o{Ee3ØbT]\EKDX3 _$"F/ e?Ӄ_P Ez]+ h' ꫭ]e8Ia +V·M>t$ *{zUr\Z?Dn t7.1M[>P>?~6tTsؼP6Q{Ť%ر= 75KVؾGgi -=J:Ige2Y\5YD.ywe|^ꂸZ %qkٱhut4Wd <ИutS`h i03qbly, MH ;hV xFFdtO]g*qCS>p GW g Z?v]Nٲc%öTڑ+3,v.]k/%9Ar@ g!@@;K2MX'L\fyTևq&fjCxuLqmZ$D3/X@%9SKώY%5ѣ&̗q sZv_\1U) CtBQ)ocZMvm~%hl6CVzH9Y7;8vX.ըpA pp7%dMc^UJt]9F</#ױ$? x^sljB:*_%peImAm{=Z,x;[jRNX#-?%CTYZ~^k[ˆw,-| BW+~hbZXQ^sOzִpkc73 1DٿI{vL\'2^ME)+hew &B(tcl S*?\c%0ۖt~<]t:]"jFAzjQ(qF4ѱFOD|?3МMBCdlektq[B l /hUzWm5)ziD|PY{_e-&Xk뭲i\ :]&xYyB]BiVKm< byEnR|Vu7:ŽQ&+څa~WCBöꠠvIUβꆭaL ^_9uaG[YpjUF1{Np@3,/6~">,pٶͶ.i8124 >hjg* 4܏* ܃Q.B2#05f+#*:$I+lC;˲0Ks`n<| [ +OY.Χ)9u+ $e 'E,j YAƎRa3Y.'~ZYZ~VZv']co/:˨Zܡ*sfA:KaU/t-qu{G9'.ǼC_n&=8aڴ==Qih#%},i=sP;K(h&{$j&' W7"z l:6Z!_,{UUp.nsDW RU@sodϩt8ʶ䬤O ƃoiu:]D @~3.ҫ+~;k-KoGFFܚ#ujݜJLK 1XB}Dt:m7=~5~3l n9p5)p{#uuBؚy[rH4NQLa1dY#uM&*Sƾ] [V4NˠkWc46yqwTH[9TA{vIsƒVd~[ѺĈ}m8`J/?$5+9jB A59mHA?@^J.a/^9 ݎT9H.UPg&ETytο†B&nU]I?ymIu ]Ո &}uPRsI&Cͫ%,e0$F8/p: RJ:Ve3L"gԯ+Iך06쉥(g0\cb=螐>Www2e8ezH,%HMEDYAqk ^IU$F;7k}#~"/Z)1Iwrio(goFR%kzLWROl]v{oGzՃڋ3e(7" ᇫh(`O@޷oBa)BN[0F bnY.%3}7I/Q2?xOtg, y-Vոm1 j?4^/kG588iUÔ2pdl,:;CnBO,0\qIzrM6vCL>SM13naGy߉=Bh8׍zc<6d]$7+,ן{ˎ^XxĬ;Cigc1t|K^?\b}y\1<h C;:CB$GLx,ўցK 0.qln Fp]FEņOdTD58HzO´nX!t.lj۹gE37IH!x[Ւ^8 "hp{tJ訣ƦL9 6X"`S JW6+Oʋ+\'719&?0PBEj́bu*E'"g\yR+4Y"ewǸkT0d #Z2УYL𧵉%CYVԯ%D˫ya(pkw~/El;f8>;m&2ٿ+YsLn)CZᱟEZ GQ u~p+fSq> ]!Gw\-CJ=  Y|槆l\eJ]8$7X. 4w0*;,u&|Y8,jw8ƣ,tIOQp?O8rq<{lP..zԶG^&Uwineđ O 5'8)b$Y0퉠{N|,M~S4w0!|a5=CS]1(?$$Xd0~X!#[S$&rI[좪t鑙i>/WboA %KSGT'o]є[+Rp|~O8g*@=w V^ނPGqX[n慝J [a:_ic'I'\@'I:1H.t5Rv$o|ٱ/xT I4N7_'K0^V}m;auy㰃&NN . ?{ `]|%G;mX@I8ipI҅ 4+'ZB4Us`JeP=.ws,9 tazWx*;*K?2IbH{܅dI9/̭E>Q?qM<]1d8!9c$ȿsIa K B-L]O`l ,K_rd>N&0KgROZ`ˁX[%MӼw_5Xi0ӗ'rJBl c)&pj k"}AI2O!1m} 8>`cL B񓢛b;)Ë𛉁Xa L}@MZ1=a>sPwkOXП$_@%6EcgI/71?|U J$߰~Q6R{'JZ'ae!ED ڦ^Z9ɘSJl!E 1Qcy߸ kҧa;Ӊ l2+rӿ'9X덁.D3^I sDcch\Eh]U QiTaS90)H7$6W_usLI,p4t :n,e9u)o1ȵ6q ,,2f}% '>ɽ"QUzOE*/⢛ʿ _} 6xkl@D"z /&3KoInM9/B;M)umnaJ}>u#$BglfܜKCaR yIp'3=ZθY1p>K?ϝ }c-T=vCsg/]`Q*㺔{=@ ]W'xXDF$ kJۀ_D 7@h,U8K&P`5oxbaV+{x%oDZj ]p;AF!:fk\љw@zwu3Vs_=5ZeWiM6E-Lb2jˁ?"+!T<*B]%qk5\ty2\q}Kr5:'k\šD2lLc9$WCWha :A {7*)3Qqrϙ$R $a\v4CePMhHcOf6Fo=Q}`eְ_Y噬ՊRe$~ #߷a\aPdՁ)V^-55[»iv6΍ÃN?"#WoFdU~6gkc&Z8uf7/yLyzŵ?q1^)NW?P:Kd4j^í ݊R6AGɺnxVmmHRO xRg+-[|X|fcQMpSx@3D牜=-P)8 6+$%JYalmV`w2k6 v*+UM4wV/Ns2WGnޖc6sPژj]O 33.~Jk9⊁ΜYG[̶@ my[?Qp@G,Xh*ګ*xK ^=(v tY.«gיSmGg\Z{7X\zTP+ ?=$IRI>XiCK.KY;8fQ-uӦYQc3eY,?9̜"l%LH1eYY L3(nRfsR e8f.rVAvm廭Y!"zc}!*͍6-{Hq^҉L z]I{ <#)|Otr{*q XN+h͢Eqv<av\߱$[A mΖ}H"ӽU0+cOuY o'i%d,KE/8uy:{ϵM&%֐N H< ؋'P)|#7_µtSN.vD['78dGhfʲyu֘兩\&ןrMRsҠv)_TC'܅a°T#d5ɻ:3ugApbTrL˭U˪L+ovEgLZ&Jh{Sh>iC公.>  ޠ܀tSZ>V"X2Ι㟼۹'`xY@ ]{>-uKPF>br MvBQu[^}?c(6$0agVIՀ<ư;wo3 IߢZqIK21xl1I=02NIFA *M-X\r^ne\O_IV\[G5oZO:lR IDHͪCN}X3:9`Lyo@ R<*?>H /p1&W}}vam@z vc Z`o{8yK#=Hq?FPmvI=32AɈ d{Q2dd2Fws>2;I_7 6S^[Fea8JMJ?v՟_0B ӂ?jd(xITP =(W9;,HfNn|9٫Vp4|b*a .GJⲻ7suQ?[,mǐ&q Ud;P+eKjCk=?LIX~wƇ:&R7(,Y;cGM,p}NFNJ M+ oyPդ1|Sɜ\E6#+ M n0k:B GdhvhU'.B4:([9'>2vLb_[T f>}S`6R&wX 0;Ͽ{<4h};^f_]9'M̑4{yS V?*2YO&ow& f9mQ G]ǜQG#9{豳go!޷mnJp$.QמMd ?dm9۲jHD? p@{6V~Aa-a=@MƟ8dF$1o7k7` }R5X]¡16p[jG].Ė`O7WLyh}"əUlc ?s@Eqбw3]ޝA7oBZmY"aJcX< $p}[}_,] =%['vKf#%'cV~ӫgp DQH 0?S{Mttt,GH"s@J譱lM ʿ6.Vu>2lx.c FY[ |9٫ࡿ#sYwo~"dkmA@]ao ׸>=Ncig*Sa;ƅ (_*~9*U0}N ]yP<:dTY7b (8KsqAM kvT@a('Qvmض-/ Nn4I}Ŕsߩ;4u L5!Yp@ }}Z&- M Q;AM&mb#|=Ha9%k,7UL+Vwl|6BvNG3# 4cR+jee,5V Z`\#. ꞥȲC>P9% >($/%ʔ(9Ӽ;Y/'Wjfs՞>i䓴c-(^sOMڭFEx_\9Zh @$MݚAlw,W*VU)T2V-.cai"-׌(hL5,ȩL+ hbO%}#inZ=/ U,y pS"$к=궷8s Sy4 =A+ASt<U{'JJN*yDc9Hj˂QjD*P8M% {nW5m7Oı,OKjl/4@ypHU-SwۮeHPwwlFP]Ųpl@ ,a)RaB9 }Zk`'MXlΕq;ս @?@W,!vYt>H @K\Gq`o6& GaC5PܙIߜjMwLhq-$$(h7f FFSޙg-O'4\SqZH(%8(>b +d2rmWK/dac5rH8^K^ AT;dm;Ե N=Arz!KO @l~/qvȍ3gwG~n!LT! *Fomg&rMx X;4Uh3޾!LifkD-8Ʉ!ŕ^Mw8?4U+n!cuA`ҙ-zpogExw>Py߹+qmnE!A$)R<| D1 A 볒|i7 *:BO{8k8h՟!KY?Fhػ'z ̃ P8=h:99,sSG5pݓ_9kJ$=;gGzEdmFY:ƴF~D9Rޟ*xwL}^М!SH 86J!2 $}|9l"rmiv<;=/ּ~ܽO1} XʶU%e_')V?!6,T0eHA\F2!5s&ǔjA۟TUy R0IvAa( 𻮘@J@aGo|kBU+N[M;Cݗ 86ɎWAb#bl2㉊NjfMA跠Prt |`djFb'S%fdlKd9R4 ]8}QҜ2j1\ztkɲWv]d·beܯ5jh=qKP^.Yw0.!_$I p9Z * 廆R3dtY{r*1$. LL!{)-&ٙs2khtXED&Kq,B "e+rU-6 Hpd}ss"L<CbAfl|M}/+|o7 >& )F֬*PSh~t>?]ŪqU.Cql/Z]oh P`\0cq@QS@ۜT]㔺P(m]y` =F =&2*Z=} rwתfрm1XlV7Ծ 9n¡\)kAX2`6,RK,oϢW&i;p€{-Q^ce;AplR>-Rc(| YDۨ:WcyNVJhi}mӥ,ώh7:KFfD!&dViG-J}\cMQ h ҈/ ڳVE;Lgd7~Q tmZL=5%̮]Rðpe\߹JE%<ǍZ"D  Y0P5zHTTG$[DƏcbeKtUIEYlaZ;%瘔$B 2QqsT803EJX:{ԁ7)>G?hVES!ւɦmq|Zb6  HO?ޣceYR7hƳ/s2me#+9]aEGikaΎ*h ^Bo@q'FD K}QD3Y&3Kw"P..%#c8CԨ~J,B[l'k{@N"X3-ͰGooX'|'Zv~}$u$ו b ƘF1.g8U* J]IJe 2MC ׽00`MǶHU͚^o>o p9LQ(*nc9,UtmMw)X<2YvsRBӛbeM5A П38: $1IjVpF*kwCʈ}sLtFlW329=l{݇uEmEȝpɟ}(TqI&tK NbF;{ʬs,hIbo(fGK|:q2GbuZT}xJǺF*(=( zh|dX)(k6zl~9#*kĹLZYxk^ddIqc_W}w ܐv Hse>{$[j8$%*BHԪ&}ΠYg@dXd{HAB4Xv Kz'fT%u0^\lt-fiE3!LJxh[l{WsIANfzyγ v  "5>")| &HvuV.cG{nm-'K[Vcv4 ,q*4YXLXԯcsZG2N=) + ,q@taٍQ'=NAc4B6F^60%03^P`HjJ,hK=1ke@shLXU3pDy9Ͽm_Jb (`>pmnEE%ÄtٽpT-J@=iz{2XV;jW,~9\׏TuRsdg̓hB#YNf ](uxj ՛q:BW{iJC:^-'ꋛR0m7Wm&ZJD},VhRz tIg1慏Hæ&*k}j۞R!홽 bNBkI4#cY6QDV\jn}&=]m'=W2I3C#Ꞹ2~B6 wY}Ҵo@x a0~LB+쨪hrv LӎT:X)WY6׶Pe4ހ~o P.e07pThBԬˑG!%x<ߚgG-V"kh ?n,1nˎ",[Q)-H؈Ⱥzw!Twfx}cd㙂ʱ;N9da+.=^d2gY+"*>P$gzx"͐U;GDZDiZWٳ?q|:iՕ옠1 ^16(;U|Gx)14pjq) mBX-"KMdFϿG_2^Od-K颥gpz(FpljxJw荳d 23il@܎WJȴ!0@.w #vCО->Kq̑@ռHG yq} Ӭ rʹCs." j7Cv.= Ce=DK~oietoGQ=h+/XbȸC"4m݆spiW?&FͱӲ5n7b1z)h`' eM3:\Z@Uϔ4` ŧ[ŀM;4m,15XxŮꬷ6i-qGam|aIvm$;y;3N"""3UbKṴ]nS 8Fxb=9)*⸺S)1Q{|MR1jZ ;F /Rx<'G4O>jN쵺׉xh !]黿/lbŨ"^=ػFثzE6|A$ }AO( SԣUVq νIǯ YQ"wMmBHbQc5h8œ1I=N 15h*FbGm)ryhu$o;,ËD49HD#%0 [+wdBL윂Dd oZX3k@e\(|NFAq{lLjOƃ-k!kbL/{Pdő{=3ELśY ^̗-9CPq}2jM99a$yWd=7׈JImފ6c*lHX~iS8Ʋxw*_]CSi AʎpFY2S=rPqWe@)ž ŻvGr.}/|eS61!h,2i;UU 8"| @Z4ǘ;O| =ǘ ~8r|]#~νRm-}lDR1I8  )}?NAd6 ˠLfwKZR~x><&GhIiy-(#Օ@LjiߣKAI3oz1kՌykIj3`(=]3r5BbzB,.j@+薈3SkXK}*Edž ҇̐Vm%E 'yV5/MTsI{.M7 ?*{Pg)]+tÞ_EՆ̦)OɾAzHq5͜~CML͇67Ű"P\.^ܤƀG/.J֋&VcP$ѻHO8aձ2 E]5Ssa z:`ilA7Ͱ #4 硔}vƭ5NKC24ȇSuJO/i_￾&~D̸!(V/B7HCg H+IJ};O._ ڣOȆU{dijְ{ druƸldN=zŖ b{n&+"T]@m{Y^\q<(1;6jYjxLi-g%n;*|5j,X浙z6.Sw3iLF6NsV'Rݓ`R~Q|+i^N)]7b͡(Ժg?MN)6N[;4Z1ga#p.J 2|0 e"ȬYpk3O:U9JN9sɃc <ۨ ,|pA${'cN\ADu]og)6 7TD+N"8+[f#Ǵ !l/-9L=UFbp/benic FǼB50TzLM!@SyrGٜ+IcWO;BtU2.PD>`(]|~/I٧]>7Gf(1mz$rݙ"oMPCjg}dsQu7ZQWY~dMM2wzKQCԦ *N|V@O#GuUеVd5~0ĀC`|t@ѯ}Y;8,g ytňm}lE B :i*9.X9PNuԄ+p7  -n4c8Vf5Z.ZI'M®Kx_ U)U6^5B>]ߺ/01f]xf Pk.88.ׇwSۭ2rL''d3Unr@ aS/Kz{\m7w'oQXäE'<Jd @[jɲM&jV4 vݕ LDJ=m86EYUtut X8 \e!|W%IS[2LhK ̶ªS Hq4&DTxbi&g*F'V̂>V4Xg87 GExd+$Yη7٭';AUE vDܜ3.O5?\1=ae="gK ֤{C>bK+?`{\7\2CF D ˿ xw!| ,'$ظRW0Ҭj\5l}kLBGM]HtLT>>g-NF &sOVzbqY [8ޔ{&$6&sƓJE>޾VT~wUCƩ}+3S5¼# 0JJ!l "mX]f`MZ%>]@4̐4y(A4 ?@Cs$MIoB8۪gV.!0V 2a3!1,!(*ˋE:3a,>$;E߇PAf (]8F_yT9e(*ޯKEwJߎKNaMI<`ҫQٗ蒁V qUkmYK~ JY+b')׵JĉZD~=B΃*s4'H>2晏BXv1Hذ&J?4 IMoEٗI95j/~ @?zM>(>O[3/TAa3) yA~a[t1H!r}ٸV$՝´zn鯯pA!RG!ٔI|'bEk Z:/;Z&ZhPn "+hoAOQSkB5d_- =7XIuƯ %bOwB+"#|.nt@tlm^0\ kV~7( 7kC>XCd1H tcȪ ͱ0uuS^9ݰoʴz/;eRht;|%8:/OkVpCRH×`a{X ObTOY2&Ђun׍l͝XV̌o͙tYXTWn" &6E,9 I$wn3z~%0)ne-%ENE4A ~v%f)_Mn*`{Mku-"0S 7RK\3<t1UDlʦY G7~CQ?ad]p }o"i O m %U%s ˮZL:, E$eBL/ %m{DDxBwA_'Q0 +fؤB[y3`7F<1??1Dz2E *K)4egP#" 7jΜcâM;fK"˷$Ͼ}6x2Yj9N{wN*p5rKMٿ-!:_lS$ i 2ea.IBDAu0'j8V- IrГ7.f^i H,xL?7\ $0xtŢ vV>|yai:M I-T 0 כzyquz) Qu Wi׿o.UQuiغRYC}c:/)`Q`ءiGu"_GBI^~e%#P!r"j~q,N^=AcI =QZ,)4ZįUF5-h}y/x"atijMصH3IKgAݰkfwl1fF\{\ 8 xgb3wIpDbk,һ2RF'0^J͑i\ &˹&[aBԪ|} c|%ahZ "kj #Ƀܝ|2sOE-U.+N~C_4 }kud:vlJ_,de40q D_3`oDmrx6\* G˾n]Vro%EK2+pmU~|.a77w{*~3hPsO:}AC<"X$GθG ;.l'CQ xqfN*pE Er_q=?Bf2_+z5.pM4ܿW큰'aFxlʆ(ap7I=ŞrmUiPPiхvptzta Y2g䨃SanYv_)oz2(:zٶ|[Oijx% w }i)ٟGwGpOAP WUBWU+XE1`B-҉qF-d{Tw++IGM#p-|ƒ;С> /D7:lkH L($OF z D}RgI+ @.mӜA݁4H.v> xCxGl7s afϺ$iފ]_:'5hKo9C!Sw:~um\/;u)TBfe[@(={{ay\yp8x]˛GpQ2usP[=[_en !loX֫Ov&k)j;쎗RϤfVELs-<[w2DRyE<+;zePơ:<GezXt5Z'> Th"tikDٟm AhSBɘ*t:(x@B?7O lB+=Z|NZ&G% y!v3.%d Qbbp֕#% i8!}1|ZŚ-K8?(:z-r7\@SZ)K%UI+]8=Q\-֙h[NڣWYWNB_jH uj.GWyl0غ {Vi 򛊻'7iFq&DOeH:HîFO O 5n{c#"Ç$ĝ?0L^9 ǾzPa2Bt96oj])W<1q "0& vuO n7|L0b |VrtR蔋 V@plSd h5}_Yb%I+cE7B7/%Miue)8U}+SD[` 7MO(bU$TLfFTt{W[A'NIZ ۟a9y6wӣ5qxZ 칚&{םLme@+5 6!,=3>|HUkGkoㄈ{j>%5Wo7ig$y9iNIu|w&Rq|z;,3Z$%^ 5͠7? Obdclj:nXπˌ5xtx@kČ/u+`NYSMK;0qvr<ָ!>A8izgu JFwV4,7-OLm5v۩3oXKTUquR"jg'Cns@ a.Mכ*Ց+];رJzלrpYMeJci>#|؁ң\&QnYŌcPoM9UuRY 'fz :1xT0MV4N(%(9֩пa?3gE565%fUWZcY/|gra.Qir&ڼӎbu*$NU ؋YX<!]$!/Ah2Fj/.l$3d/THϽ# #`s}{vK U+hľ&g1.Goq:zTLNjr܁ѱoIZ) Aaڸ *Gd(Wd hLΦJk&=D Rd 4}kP1 ҂)3%vˆ (YW`^p [ $ڢA*7~]:ih: aT^ b8Lfg[!Op8ܳ@dz(lK>YkPGXᲳ|ES {3/ƽ.ҭuD]9rx.1qzulU0[nz(QZj`yX$T&vɜGmZ)o"`9/u SZ36M=FwaDZ|/Q!"2ʼnSP - uJ?}+}1R4%p"nP]1VLG,樝SdunvRhI-҂+U%lyEY -{l;I?l2HTwX#gEszot9.>tOBQQ5&Y"i)~x>7GŤ呬EZr *v! >[9YoѣWWHzfݔJT'wf0/Xr?z W{7I--j*efEaDn;mc@@.".hAR{-i}'\È:=i(]LAo0FP RFJ6HwȨgh^jUiTDaT4Ǯf5zLJuLŖ uܬ&#A !谓qJW4j졨DwH5Ե*UXHgW+DN [Z뀊Vs}~ |^up+Lӟ}/ᗺY€19*\o$mM.'[7VChYeMK/]6X7O?ɭ;/Cg=i1vSue*W7M~; nQFKA=#z+yUBSwo|R ,w F{ޒ-|A¦d=b ]<+\$T ÝZvbkl45'mO/Bh+-qUxkv>ǚ<ԛbaYW|AG޺' $A+&h`Mi[ uY֏Q2ѷ@!q姎Wk*>yj -M7W/(ګbya("RonZQSTU"J'Yۗ}V >*1 Uȓ4,32ff Z1,( 5ej;qiEz?CSN//@7>hEe*W+ZI|d wQ4Vۉ\o]73k&UU;7qt-pڞ4 1n /ڛwK'Ԑ@i:ry]<,AyɌͬQx/#(FuaӞYibDZ䶱60 ~_DZC?D?<ݸ͍;[PE~RX2RR~$Oz/ ֌oOpkƂhje*o(YoZTR4zP s:ԗ@X\T0ְ?rݶP*0Pe'. ʛ{>r,g)Lm|;ؗxI _EAPxse>W6w5, panym3/ K9X|nTܚ !8ze܄JjaӰ3ge7wZ |~?ta{G2)0|&w0[dgPX[Ol?^s1x:,xdл/M!sKkH\ oa4uD[pA- ?X%XXޕDEyEjГA3^ ao1(;d1+G#Y'\CS+U֨K\aϝyhBq8 ph`#(4I/x nx$gFS7Æ$xiD7L>~cWdtnCfVqEe03{Y^6@H]BTjXS*O} 4!/.4/0{Eץ*fNȞ-%h C\Iwt|ً}P12!d vCK P(n C Nڃ:Mseb!X!D>:oыeeã 7od "s:kjsThM*t_#Ǒ@BzK1lS9l*%|u,ʹZ*7L`7׷{qv(sHfR`pttVCH9pl\%b>Bh]% uqY*x[۴6-2J~8­'Gp;/I6C3|:M9$lރ !,z 7Rj-̿[@>5!h9R̭yVPlid+~zж^o Ԓԉ:>yjU6=m7VvNsK-ʺ Gd@CBv+sAf9I+};sx̺|Lbڎ"/k *H}amamp7hN G~|\:˘i. _k5 ޶||5 .w 09} i^"' ːr x3!vTVX㝝R5,ȁϏ u%[UKB[Bα=))4= |Z<{[Y[\=aҿ*C!qd&ly:VsHBL.'x# E'y |ANP&v,  7qƱAoCtҤip`k?Mp~*B-ľȡ$g@=cn)7N@QCCS/myT\B;U2t8Dg̝+]u~˶fKͻIM˨np-z&:nohnEx>cvklD:y ]:vFfʹFd2!L>*l7>#]3#YUqӫ B5&Vu"t"H۵:<^uu"W. qix\s;:B"?έv<޶Xߞ^~3tMEB$+..  FɎTm4$@FL/>y©5@4n9 *wwQv(n

ɾgg:J#!$7>Ds_oŊNC"ҰQeJY)w&:*BE?0x7 | ?&6]GNIa }..?4ar EZr񪤣"ڢ%mI6p]%d,gBޟXGƫA7qj `Ɯ#/Dš:4G]r|*SoЃ/f .1YSpU|98E.~Mtv@:-i\k-5Li%0/P2*،AN 'd+O^,]**Di<^cK[$^ r|Pd(=IޯV<؋M %ln|v`yDx`  T7-|W o<AP1z 6 @ .x[2<+ <~[Ou(RgG̼1) (H#O!|hsdT0kKsRX>M QZexhQeaEvFGC쇑ckw`ϡPk`6@M@Ix-$-,Z%@Ad %0naN`UT=>VD w ^;4!w(l!eEbhASZ݅Y ˉB#`G^1gѓ!,QnI&`hGBwC1YIǜ<`{Sz5F*o1EI)t$lЪwVJAҘuJ8K  Ca?m+ﹻ2M+"$k.ҥrfA2 7Vk<99sH~gВ<  ruG0xp/]Q3kﱫbRL`3/1M7ba7Swbpgb~Ui\X^c'& ZYEC'va= ю jrA88o =ޏSD2 2{aFmwn 1;?t*3=@x6w0uQBY·?wgqQҖ~}x hj)ʈ%B0ƞCuۉLy!JHTL}J0o`"b罢u/& =]IQArzUݬu`:oL6/[4\jL&6{%3=B^Y{.g5![eGroLt64A!\۱ģYo4 ҧt+Bӳ}&(h4G+czr~~֘2۪&npbЊM0}~5פg}f'W;4еM}zၦ ک豔T涫m'ޡٓT 39o#׻BNOwKYaty9u+TLУ%M 6K#q<8$W2IXUt oޡa2J,1-d}vUnr&=)ȇh*Pi4f}g(BtgMI2@V;^k k Dm>k&c\5~*H,xx˕zDl}X6y9^ȧo-CM!tV2lϓrZ` l:0x1pAnH"Lz1_Wmp%j _h~jRIt,)Y~Ȑ;9(!؄w6 Ex7DQec#%7_`Klhk1C.:~'{v:YG4Vw&W)% rUe jŧg6npjJt.$r;E,IMaZn (i zկ* Qu3ۙ2=hHc .F_SdYYJە G" gd6ԉX(b[cnD@n"$:S#cRFVJX?2_B(tnl( a"qk%$@&xKK}Z>?Ǖ3Af`G%؅΀p̰MދoH]KtyZJRS go_!Bj2DeuU/t ZQF8!&]C`5_󝭬DXz['@ n5˘3DA41Ci iim1 a1[Q.a pq5 7D ,˱a y#%U*Њ2"({(xp+tlXCb#,`=2 Fj*ȈCr*, CG.:B2}6¸^p\,܀\qEnC@rqX#G} )Co<}tNy4դTogdZEƷa"=r1nظMe}ox+M|]v4n>Yjlːo?i}^~菺z.GjHpINJaed T=Fsml@~j(M}H#|Ey}>DES.+3^{%z3Pg8I>[߮&ʇ80t>66sOd%tLK0eط4϶h*B: +V|),P 4mj ]@{ݽԜeMY,F tQˏI(&r5!x',uNq3%+LK>Fo}ץWSm4c%ZSyzrc0)ߛ= 獹.i/(*RQΊRo=HfD*zdY>E%E̢@"oF6jJDe MIfF/r7Tۭ|Y0+ Xe[bav71w4n4R@tbUV46e!z،-O/`8fMϜl CCNo*?Cgҟ e}{OyR&IՉ;]* 땇x+_9>op @ <.jNn9-&2bLR)O@W"G[!7I sn6q=ۄ] +'q [CRc,+d34kKvy|J/՝:˸.Ce-%ͤg훎\"q *i+7jlb@kR|Fp1(93)ҦCs7j&R}plQ"b;%ښRčY(pWi%9/l-øDq^qUqN#˖ UQ7_^?OvY#Si& 3"Ź pp7c >'wTYe+3RJ.&ju.!dX SǑ7^f8PqBXMmZ. : C7mi+62~.I9vX [ʹ/#bwo/-kƛrb{(a8B`.i DD/DZ;Ct+]"!C)UEk{y,?tV w`*XUF.][獇)t"CO#CW}̳zI6p,3@Y$O=D{ggkUm*LcΠ?< N"PKEFK$,O7Wl 9'Kg+ Mm QR_;(qo]L iq1R.Cqkp AĶE&c€a uMʙ}_5I+&_Oi~Z9E:{Pt'tz%(YkWYq{J?f lk773!v`%qG{D;G&?bYɫ%,޾].K_MьU=$m>m'Kh3sn `9O-G\l:fGs$M#iRx[.\ÅvxRM8l?|0ZtLoJ0nmQo[i`E䉒-?$Ka)>Lf]\sW$+T)4tZe~}D Phb~2!mԖ0(d 7qZ;/[/gm cC([˿ +}p ulUZC f qn*"@*|1Ema[b%y`8ok, ^HT+t,T&֧[䰎꥝IUa5N(Oz(ƐjBnO`'7l}oU ;'4q,tP. ;yj:qxnT[ Ǝg3!>ǏܯXTkPÒBqL?z0@炼MW1b8X&q=d|Fn{ɻ9V%e!|f[aH~ڷSMFQ S>A76YIH ƦP^6 qyH״^`6ì_ in}:i鶤<@i |1^6.k0:| < /)=y 3T,JPr\-s p,ZoM/BSQs11F$Z~R4ZۿҹJicjoĿj`[>~kbĕ([b+xHޮ|w>88(CUfSVV ,@<7̮x$W"77LΖ֊A1"o"-u#NhP/J=lv/v"dUisb>Rm0v=FaB_H3i*SX;XZ(/QuSڡ PekB"!Mrxt=B> }lGKX`|nHª^[#;Jlde ,tsj[ek%Z]ƜQ׃~wOv+ W|4' .j6IfAEchI _ R:0G-tw/\f{֧buy-΍yk4! 4 E˒ԉq k孲@է]6񈕘_S׎͕`u?0)ρǣEݴHkZEndskK)l xӭcvY،ч)1c `nbһȂZ*78[/5ǍDz2-a;l~%(;B 6=onU6$HC-.!mg0j*ʍ@NϱM @>ֽjvA:%0NO(%8jѪ`Q[Jr@`Vu$(,s2 qwQ 4k6Ei]=8_%81UԂ0MYf|C촨zntgpU3!\vJ`=nnRXQׇ!V Դ-v́dS@S.<ZF0)fb >`蚯J@6*Q(;XXxT]`JcF1=y=}8Q(>y"3VZR6PCnNxBrVquLĹPu/{kM=j"]/"Kܵ8n=+@mQ$Cg1:iՙDz Z'K};p Ǎ,CKg/&8hEw>G0>k*'(5!<01ue;zVSﰁQנ^~}cjX鹩S@(_[b*?hUX:RƓq# i)CyM!vQv.T1 ޑ3@%w͆hfi >He,E ES,"m!ilFh~>(d q!Cwn8PAU@p~+ZPul8 xD|;2L͠5x|lmdyYkб_fߌg!ɗqBٵ%LN㊡q4U&N YgPyq'½][@ٍK:ၭg.d2U.Ha+ TvsG(ri֓N@,LTkA%:_ z Œ}2W&xҫ՘0̝tg :/T 7B[)/#N5c$~ԈLp;^+c-g8hpxjX^H$>?{O.tM6u>hr1N)[̦to>\gD?7v~M2l"[_- 7n>/e{Kz#*kyrWt@w4Ϝ`Z Y}-5/;'4<'czbmt yicGzө[:ikiX^L+{YHn3+sp=_lW-":0vn imh+qWݮ݁RӶE^cCSg 4 ;5nb8z -YPZI!RiXcVSŀ q )=3+6D&n^0qO~D_{?"?գbd3g)ǢzRNNk}2#t"px bg9& b/Hr<qZy͚HÍ$u֝ M˛E0[{CVWN4W+96m$5RpǙ؂O/"u Q jL$\ ϥ,T!ro[t@`7:)ϩ-|>l]9!jĽkM6JBz$y(oAA*̒9dԣB_hY46(ҷ5FiARSb>0c4Mkp&gξGzF @HdIy<φn%XbIE+ZA׻8?ř eײ SiC4~L#ֻǸ͛J nbRj7ID6* JY=MTyF g!Ĭ!Ey#A(Z5 K_1tj O=8._ifk3y]VXxGppN"8c2yGD)Hv܎OmAjtS {h T1 [w)CNbbW]5qPtY&;LmZZSZkZ|Htw44x+J$Sr*HW|rGN֌L8)x anKx؎2c AP]`B,C[wAJϏ<i0ud*>0EAH"ч26Cu<ȟ7ڻLv$䒙mQ_i h~::Ё^PQW?6)W،h 9?WSn@bj^i.S1 ]N+:t18Sφ|߫,BX'e|oM%Gh)Pos#MW0 Q<].ǽKz'UܓQ#x+#TmtYB/CU8fOKmTyqKbO%6b `q*nSumV"GӉ8z|b26hKp[+ œY *䈥_T>r\띛do^NL#/U?hPCnt :N|Px} ;݇Q,=(Xwu_EuO2)<"n,} Q҂-=}D 9bN~ʇOǁٟBI%pZ[B}u95}.DAy)  6f3VTp<28#I߿(^AXo 낅TjBM2`؝C#?^uౄV^Ȉ^6S0HPA,"!DJА_w;bLR<{$Yt3[K$4n]${ [eg1(-<2 lTG}3[O9jkk.: _TV}H}.68eis4^ncm>a 8O.Rc0}cI %ILB(t<4+Dbո!{ߤǾ.wjc+3wD0\H h;RE9cBbaBJ_Xl=' q){W4`I-k1{rpk[nVikcdt;a*xt#I3Fwy*Ay`eMzk+bx $y) X1ׯEz)HQ6!1?#8>.Mݍ/5"JHoajLfԓ~_P$"? ȫ\Òys uUh=^:kXN\AZS5-ldޢO.dʁrPVӎ!zmݧ[?ʒY^Ȱg߃Ehmjm 9V"P/ \AG1Q#z,J/No~z\.cR2/scC@8FTg[ѷU{Q}p"`c:zBʃC;*BH^V^儕+L Sv)e/;t,c^xɼ&۲ǴgK ҺN7k՞np\/LPgIKi5qլ!@Y!@]؎$Gx Oa*#zma|^@c֛6a 0EŌǟLh~z\O&£U5g!-?퍵Zi<:r-C,; pJ?c?G EeCͿq oa%t֨ 9OK2ڢAv6k ]Vm0 dmAMz* F@8Ϡ Bg`bW.7.(k7 hzD+䜎 ʗkH7T:pʕNxWchgScbma)kpr [qc)\5f+.Ps1f"B1`\ +0Ǧّ lf#>:y ENOqnPnC!tZ?zVo9$Fa oO)8at C;RA߆w|IsvZs N FJ]:$0!%mWnZW?X bMۦ~A*tlA:KS bŅww=u]R :=sb yTAR[c"Bdq=vHB֦4yt|z^@iZi40gM8 6rFjPDȝ_/ ؍]kb0Aq7?:zYneM.A.Tq$N ,׿ʏUac%i6Ғ$S/l.TrtOha,5%@?[WIڷ=xr_/>>ہ}uU/ ~LiՀֆEF\;'5Ίd\rge" ׶srOb6+C`F}e aUzȥ4<$uf5۹8 'W|դ_#޻1Kc9V^Bv,6rk$`<3P m 2HY6QC) mEGx+ 覡j啫&uFe gNYdC*|3Ś娄TT\L,60Dz[h<ֳ/5!Uju㉥(cو{…pvxtJ)TEK弪 ,BI޶?0g/Nڊ]#~}Qmxgpd}_A(lB.t"@,Oڶ nYGLN\ >g=26<5.5?cTy "=͐:xdOW+Ђg9^楘ޚJd|!lRQ._v9zm #my=co"9d!/h6N2=rp2Wo\J,t=pFonu*Vmjf[1=~>&hf?WM|e! HlL#-Mא#̘֐TCi!܎9,@$?-rdvJ{D:SUr5L㉈8X lO_20 o$0r5/oYL/udQP5 7'BUB. q! ٿ"Hږ53mt+Q]kbfB`/c|h3%u)MKZ9$Dk'pĦT{/4q-M⍫!)hZD"#B{XIΨK1dB?,Vؘ͘&,/1X?g;j"flPkr'>)73H~kt'ynvOg+as<=sbNzL؃8d X{&x>GظŹ% g 8ЌxZ Q)s %+):AC5ΐϽ UQ 3<HQ#9N>%vd_0C?`60N {G{dl-􀠮b p(Ï6ǥ|Q#}w#@& jں˅Qa]+ 9Nul]Ф"i ݇J8P䤞q=$ӈ\}Vo%VUVmwQs^6-zPd_,N~hpSuKv|sO{%"'=UNt}Ol rMOfܱa<* QA@>Iڡ[N@> ,Vc76nq8>❻  a탱 (v,rQcE7l󓄌(CG-M"|m/ԝ8SN"/D!^0R?ߐ{06uѺ w6sJv#,&7BʉrJOa,0#Jd|&DO=4q/"}7tO٧T<C:Tay Q*]xꝄ"(, F̖^^/.L3-n+pC{i?Mo Q-;QQIH5q:2hM tYD絰#N{IaC~."M]zmPȞXWpOT)%/{\J}L'0OGl8=&QGֳ @A~ 0 e0HЊ{q߅D|/Rk Hf*WS#)YPC:s| TpMuߠ$o$ܱo(CHsu $;\yef| ߄>db7 =)f2Ⓧ7TG:򂯇}qC$ɟRCz'F;+!Yɲ߀O^y&fRZ ',S\El⢄-$2JE]uzG5PG?\+Ԭ(tPʹ?uC'`[z}'V9Bjb4N5FXxOx(lPoN VTpQ\kc Pʁ35B^'I#DDRsj$D"ћ9: C1w.H{P d܁) dmf:t%McmF=Njhסi}cG9'F֢nČJ+Ղbc .ĆҮlƽؙ^Ȋ0x qzwST2g <,xKo.Z 4kV >L;oZ61{DMx&ZS2W\"<`}"{ 4CxL|>NF*{z%*yƦ9/ *REN`wl6/6i}^_!6'?$l"& CseӋYhb>v'Y va~Q^Wx*xIWz Z"_:w]Pi]OKA&9fwBT`|zh2V|߈2$fĠߕ2]l:O1]s!֓Hخڬ?-nz]v80a5JZ5+?˵vWCPI5(ŋvY G{}C"3<J5liER`hf&SS5ҢK5p!lmՅslܿO\K HJp4Po(6,, 1.c&0KSx5.=^jr{0ܜw-z˃"WP:!N~'P@ExlxKrظ>a>jXv$rƱ4 i&%p/ .o a/LSU>|zy0ޥD^L7dx[UW ᲒE-!_oXCXbm p MxVEOv܊nTn,lbO?S$o#wwM4U?S9q/>4teU D9 ݑДޛ W4꾷72?$d.cMB0~s r7&p!p4e9f I \Uh<#fSzW 4i+K󵚙 o]+(]]_2UaX> e㽉P3Sґ.&^:B#ʶ~30ϿF!S__Zf;5ͶuˬAj^dOJw"<A9=ð}+S AADy&bBoiB׮⥬i6j ?AckCuB2,j_FNih,ua"qN0SݫL`[vcN芄hgZ s841+GH˘L6y3W9U!czʣ/jOԙ,>F))lu>sNQSN3\GyW8/-a#̈t3;ڸ;kqogk7wc/M1 u3ЀmdZI uD'tiLTyB39ɺz؏7 &Gn. yKpS<VzXw&ʁ觥~`Q2Baro3^ קhAcu.fe(|j0S",hH$Rt`; lr *vb^t92ڕ K"N>.[+l*NHgeWR+@ވ>j:80iR/\o0>82"y%Я9c MRC7*CLF'XHny4d)PU~ \_@ „o{:j0%2V&:%|\7zh |4c9qy)VFז@ۃV_޽ө7GI>qxnڷLypndX}70?Ϳ0}+Ɩѕ(BZʦG;+$/2VXrH[ճQ#L Ag AXV1E Up)0 þ@#Տwt1;KS]7?=PIhP6PX֝v}  M$f3ӎ塙̧УUégNѐN3T|Z!rv ~LQ} $Ng6P@@Fx0oڒAsɎ&:*=Sf`\밯V$ك'.1>]"$bf@^ Um<˂L`y`|~, 6-Lp+֍ '~i 4̰ 4XDթý۩LwDΙ9$f"*C#<YQy 1[70Z1L p|rMq!l,ZGq~^o<IŸ=}=ų䍷hCHF4"9t<\18l-nPpQm 3,|toDT97ro3Old%qh8Ї5 UtPC OPԚWSA lt '憎뉖[^sEC^fhᨢ̱yUQS3"KrR5Oi\If+-OKhӖ*Y  5c硱/Ṯ a#Ss9V'nX.ξѾ(<t\ttrǚP["_Dq|"d F& r4?vBJjeT{sgtG ]ZA}ʹ"99|4</ssi4^A}&;L,ߙ$Ԭlۘe9ϘIN.yۺb Etr nvZ)ׁ =foTNM HK|c 窬Ep~R4N Ɗ($ثzڢ,J Qao1$ac:%=@r ۘ4^lɳV0Nwmg;N;Y߂!G]Rf)/F&+(~ŠS֣v-)N6 0&xtp[ x$?ϤPA2u]1)cruaU.5/IHxv<[>ں`7hhOV4|̚V^HqH&l6qHVt(ֺHMH73P K[;~FH _mf5}لܪo3@+i={͸:Zs Cp8Eq(]2Pj׆'j.a̛O[3H{LRrMΆmp WEZ @ ~WV,ImʊEu@Fo #C1CkEz⓭6(zv)cUYո6$JWdʣ擱[n q"<'v>"2+[q+o.Bv3v9PghNϼ Mvc Dj d[׳I9qYɇ5e~U:U督*oֆ ZdM{ܿՠ] Y-Zmk3zZ'%'Oە}1IAyx@>3nx,㯊7D Q0>D!EX[*knxG@oI⽗֠F4EϵTZ M"nZ8*$ngݕU~XUsd _ 0vaBpGUD6QқvdPps Ei#sY-gd1*X+Zh䡣viI,n0XfPZeOy3Ix~Sn?ڱ%Z/Zތ܂h9W,A҈?{ -#$"HrvPסPL 3D?ߕ-y"ia=σ JL6g>!FJIu̷j+E o#؇TNyyc, rJ3v-ꄫ (/ DWV#E9\X)?+j+z "~ L8\'y&]Ƭdꨗ&J-nsuO,i=۶SQILᐺӍl]ϬS32:Buҁ8a*hOAaS Hevta1˾ Qj6hPba7“Žε{jq*Tu!,/FhF'csLp*g^>lf$⣪\3?:ǹ*z3I?~ҞӿBDo͜'ng[Uu(3,$"m*3%DV"V $nJ2uofc2vF !kE9wBBrD~xF|U-~xBifiG ?X4oP.$dɷVPY:ɑo`h<'sW!Ulj ΐaTnF&0m~JԅzpXeQV eRqxlj+#]slV#jxĩ1| rr`l#+/̗A:?sڸ,+b #7(ۆ2N\ έlwe$X!&X[$t# 'SdU%aq+ wj3qiCa(QL繜m=\S ߱§8ێxk%,t ~ЧY쫭"tlj٤ʐ}Q>حQ#[bC0ֿ7*aMA U;),OYM+%4>,JH21 w겨ґZs*ܶ&*ٯ02{c-DmQhn0UH'=<˶rB6Z=}KЫ~}S9~$_ȹ;,)T( t&( 'fGy^0߷K񢃦 p6Ǹc)37;2'Cuh!|ICXik/_c11ḿ̾+/+Q,_?@P,4UX ⽑͎q1Usv؎I;aHeLN+)|3sv9/-eF@^-1)Y6 dTs@hj-%9C.6E,J\.$c̻r,O|1N<[ crP_Rm{Xh NKd;] fS1aw!c#%5Zlf#KHn`]JP_fAoS;! F-'^ki, ?S1;t1?f3%4l_&Ez3Ϟ;t?NY(0x9,NWduo3/FAl? 9vb^Dmt5Р{G̷V”N<N b uKb3лyhQByzEo*Dh…2m`lQUԔUEeW EKFcz_G.hėS\wvτ/z-F~r)m|+񗩳WjI-~==3FM!N(*aeǍ,]!v'F&p#Cv;8ަh5BqnMLdԨ8P3jDђ#ny |i_x/"^zv>:蔵o̿JEAE;rq@I!@+ =:}&MvS\kt3!v,Lrfz _5p;T2Ԯ; +{?2Eoe? 4n`o[eEơQ$F͙*7E)#=>DTWYVnF|ĥ@1m[t4)Sapb@s̘LWj*se)iK͓[̆ufq]S \!v OLDkʑcQie( SfҠ 3>)L? P\Cjg joiG+κ %eeϓ$n$Xk[κ:ٺQynOe5 oCLܨI0ymYX[i#tN !U;K|Ea!+#8 ~@/1+ Uk :;Ĩ1Ьms6HBR>#k =OGaXD}hb?^f[,0'k(A=p#OI1 Ee\CA$6"s")E/J~XK^0,䙇 g !ndQ}L*(kOK͹8>bcu]$tZa22T9YbQtTN{wt*?7p4d\;ey92l5 c8ܵ.qgV?PYp|Q˛ x7:խMp]Z9W*NmPGMo W|'c4pCv Dc#:HS7d(ゖ^m\-t_p(ĻzﱳFW2z\[h1 Ԁ !H̿ %8pEK8!X#Nx~{hԋ*J׉w,0N`ET@d:֢cE%9U`-hx@PR0C{EGxWVׄGTaB>[),!IibXߝ3t5/RM~v0'^H2k$kn`dП';P e0".-C~mwg^<%X̑hלd%=B m;)D W5Iyz.(T:~GM`RE;#nG{#D$39v{U#X* AiKn] qF 7}3 vP>? >lh`_Ó7yқFW(S͹t1Hpb|2xU,cQ-W0P|=tw'N%Ӱ|m AKVǴP=[oFwB0EmWX?^%\_]6c2%fwRl]_dXW(JɘZ I`A''72UX;ՙb#wx4~0g oQIG7Np&k1Oӿ+ih[7 cO! (b15+ZDz}2/Eb 9~~~n+LK#G=gh-nw3WVFzAA2j(UK? L`?FcvI|l:{\{<\`ReT/T2^g,Xw8#I'?/ТXbB7FÊ4jG)x(gs}Pּfܚm`ó/BR_w"tbцu8`gVC2g< WC ^ j;u A1.a<n4!&cKuq(zeJV]#*AEE;~O~lL2y" 5_׉4}K@]Q ki6Kϼ|C/ q:dsҮZqLYV#>/41^{Pz?4D /iZJ_3A\ZhJ0B~K˧oCQh5y}q(@H8Y q5b]I^]i?[~S4@WR>BjHZs }1#_abQg xTl(`BҥǟƂ13Ì 0,:W,f~x3CxȺi& ɟ&d40A5c hm܂Sb"OA)/ծo>c[U^❋QJٍP!w0h5CyԣA7{C7C\sPGNŞGM8gPB*DU<;kXUF4^wABFc7њ -2yicl*VzmhUUIzȶSk 9H6yƑ=dvXw3# Dwѹ..,qra/KO,g,QhSנ$0B Z 명L%/B7ݝȭ;߲̬X7ʂԖ_w6Ʊـ'ΩPFk`xϲ%ڲYG$L'mo/e[&QÓ *ƒ̽=!e^u:FU"EavkIP:U K<4K ֵtP7"-[T6~\"$s3s Xwv?wZ>^+/[9W$‘1']~΍s%[-T36hTX{ĒH ]jsyUŃ֎!Nvi@nk+9x{TqȲFys*.WÃ^p&\S,!N0#̨?b6qjh<ۏmhHCt\nd/eIMN0xA6}}^u1sϣKw ȸZ_ 08.HiD_.^;!)Z\J1Ui*u^߼ޔ[g(I^*Iܔ j7`dd?W84i39DZ=0:{oЕ֮e= }d)\|Ja&N$: +ܲ(~'Vrṋdl El} 5WJRjN72цoDɄ-ѫbF?DܽʑQ~hyFHkw=,Sk׍NQ!B s7p P./ zgz ]E9脹+~d 67L?Df0|:33ϞYqOw:vvc!YX~K[mIrHȆBqk|5Ef#Slv**L9: pD~&53ۏll>(*ϼFЉSKpD簻Xg"xHںڼ) p?'z.C_&QcBiynEf8֠ ͐xXg- 19o!}~6MJ4Ȟ}?kBKQjMq I KzR*Ky8Dvlrhm}+5#lk;䃡E? tAiDRИ)^iStln{}M8MWws s#[ ʆWs~iEitwm7YγP^>$@4sSFIJϗ]jN8D'm3[8ޚz˜?̂#t$Q`_rq 3NJ4K*acd[Tsp OB\/އTmo\O!vhD26H @Y2ag4:pg0 iV=DGYc vk6zwcgYI-6w T d(;V)U1TSB" B{^VtdĆ O5B/6)˵㑺X{?/pnk; :n"d{Zb~Iҿ&k~Brmq 0m爠cw'TqO qG ْE^ ­̲%H7c{]~=Q#gJ5p.xH^N"8𐏖D?$N^YftuY-Ν ՆYB%qW밻Q&E:HMGh]ӄ;ࡕX.U%Fhn X8}E:̤/<'/9]\֑^uOxTi.%j_E4%7+r3euY L5YڿPctjNaA9_-˨¹b#n E ڏ*BSsZق|ATA PSw(9Vqc\sJw}RVC#:~ 4ĝ% fo1[p  kTUגYRfUc;B%P#Wg2JjJ \2 ǔ0"f[4zc"q֦Q 0UK8g8Yyl&5GoƏh{vx_5$x%LsJ450o3: a OЯs/fD bZ`P] ]{-sƐ$n1wt<ޔt1Q̸`nU:Ek|T7+TX? zck`~!0)?5{X-ٶJKdp7rٰGX Q4L㭹-CbLk"EDsĄBlna=+9z~"7@9؝4_f $A͵&px2h0B>;T= G@"B'l)AZu乶 /=? o2kx{ mZv{$euGS6Z#&?}167\ e ?L{%֓=6=\VyARp/:Ncl& [J.ٙLfxٯ%-A7w(K?k];K^f=30:75eRSZ4z:%|w<.2 7^ޣ.Vdx4^w7dYb09I$ LX{' huh '0ZU?'3lQԙ.8p€y;B'a-b`Nmu,c[:_%Dx.m?z lRݝ﫫oTrf/ZS,Ad[VL~64êcTӶ{Z)n(q^(MBĺ$Սsw¢[D\}>w"[6wm Y` cMlmD2:x0E61?xFL_Uad@{?uUHTX0:tT t ;gȚq^rG28F{~*Ւ2흦#0R,543MlTʏs) L@7{K$"$ ,ݓ9Fkq. C" % iwm1=%."Ü;hbQPrS)S-@BʳN24|LR,`udFBUL{$޷TVvl4 芼a~Hy(?FAykьပ1bYl(?UZ܇貟8wXl2K[!LZR_ˋV5{l;k?cz )ǒ,vHgmGOFrmk:R,(ӐM J\u՛_آY4Z@5뺗LmNQ7ɄMĞ}T 8(2Dm{75)Ll Z}%'ROeׂ]ڥ7[~>Z%s)8)SI-PǗ|UfdPmj!;[}`_&jJ ͷ-[V| =ӧ+A% ET- 4v k ,H0R'ͭ !jxTF+ .;Ʌ{D0]No=ZBڻ tY1xۥ\PZ )%G8K6`7=+JX3:y!t51IYѲMe6+LE=[+ R^"le vy+خVxYv,Ӱ#_@R$kn$/áV^1՛&b$$?q'~R5m[A{ –zۢ|1Fނxq={>ǕN]z.&*_!sRziVc.0Ĥ#_8B=GNK7MQpAc.K>[-IJk|xʫ1)+Efi&k]|k-[jU)Yޖmb"ЈT<)V2[i{ٲ>78ѽXC2a+IKxTX3͵߂RS`?`1XNT{:L^m*iJVtI %mڸBOe_<ԦBq yPM~Zި3p~8wƤ_DEFcn=9lc[uc$ jzq{7ŬKI:|uSڛHZ^g`yG0A㖈W^+x!aqpv wpA Ew_g]Tr^bNt,-V\~xN lN"a17Rɼte~_Km}b#jo'S;ir"IuI|>)G6XswYۨNmw,I~Ώ%eQ^BatR}*;'!*Tq.~kߠ/s9"UmNR2r.uHU:j P; }+F,UG,ֵ(=l%Hrl2)KT?t(l"}øvBs(KKeey-{Gh.sMݤ)I&-ܥk[ ^)_ éo&u\B[?`nwM:z& oDJmN]Rxή+4y=D WV$J[#}qO@Պ-&Yu,3b* ER?]t3PD/1u6WW1d.aGG\ 4 N-;)ADt"XHՇ#-|Y'$nY L̙6D y*Il }&>Ð(OmG+tZoc9yׄzn?Pq*ڸtz &lUdi߀3KȎks`vJ(26ǼEɷO"$lڑ>8J&:""2azl8#4),%u{ǜIxLuɡJ !*yȋwӴzs7ogZVS8Hg4U0c$('*4bwbsz<ў|Ѱ[ e$nƔP@MPiMɜGIsP/GM}Q!IxR%;SL/y#l/Y-6br;Y<8`"v:p@+qQ9KsQVSgC(m#fs$4k=} b3]G=FD[&߷5"x#Kc߿ýnl*uiB..AT)U56ĩG9VVuO"!e'ڣ-,hIK-i'Vo4ͷ.QMI"w!ȪMeOQV h+{gW1IswpEJ)f&&:s!v:D٣-$]O>UÉh9ŒFs"ZzpS|qу'\mY^_ ,C9PD!8? a 07"(Du8P,Bu%]()khJtn33ݲ-_o0z-ۧ٫ X` zz]Ѱ#ٗG=쇽}^wEiE0o&U$ NoN|MRޛMQ0| !hklh+ּgN6*h$ F1bY0$iٹ:uinXҷ|r!v%cc_l?Qk#=mXH4 .r !-Ů kwP^SLudAgq}I3~{Ņ%J3ҧGll@ut~̙ցyQ(K2+ҥn6^.y/a-|-Zw]Y?O~P=a|')ۥ͒" yLX9R 1ēCBkcy %lz5*A7.:ÔVvB랢q !>MϢC<{9 Y6ut ރ)'mf@ǰ_`a]@-R |0 1ZZYʺ TF[b4O:ыtl -%4[pBghHHdC*2Y~4^m"I}c}a}O@LP5WA*NL Gvnc8ls{LD(܌(c+Wp_P[F?27G,JC{;0 KU0 =}o& 2X [6GCGC{,4Kh͍CAy(竱'n>VÖj(P5ƾmXKy= ɾeщhl /!"څ%Y"HnnǷ펕?h=(räO"Zn-oHod~IwQ΄s xq|gr%|c..6$o/bNO moP*=NQ4~6"ct: 'w:2v֚6UBj7T-ETB)A .Mӯ|AK^,ęP".p<0Oyn\š˅q/{XR -7>R_e!(fRVS~: *0248j,V02btҖKBZ~6'y+TGeu]E򳓶rB4/[Qcs>ts9':N[+f׸"QJ](fFB J_Of6zwzʞ~+lLϿu1-9xEE7½[9oP{N8LFNI/-br-o{?_H(] 1 I #y3m jqpD7kЋSh QZ8<z43'a3 HY T>]l2 :&]3=2q9P眭{6mB<1Dj"p6/!Xyg,?=eeG~s#;[r5~˶\jqS6 >"MSc1<ņ|.k?NPG! C51M tMl˿^wSd Y/ J8XO3gsNű6%q=j[c%*6Nq|,:l6_@jMEs*&KCR-M'{D:W:0{*Gq]3Vkt#N^6lY 3'eT1F k _JrIJhki}RH4ǂ۰I:LU]hzūJC+1Bxpj[ f *1+j$yÜbX(9]7Kf?4kT(4^q1[UQ*(5>pX,w \35) 1Qaʥkr me`7&[r|WۃiEjxL &]J7rh +F r5'? Ph 퐕Qˍp@7eA8~ {ťD'1䨕";2h9ZPԪ-Z^=n]GО?Mޫ7F'~׫{Ehw Eo޸Kjb!\16Q;L'zs.S279 g:-$FҔ e+UBHTҐؕED1py6# җEWN(B;C2bIsEdȎ +ILuhXp'?נ@VއKC/*/n<Ǘe[_B;wXMRY-NBqs:E3%̘vCp .Pp$HLuZq Ո?*qT /fx_1>_O 9 9IO5A,$6RJ= v_Υ;һc-/w}$.u FBGVVsD+P6yM)YRiv;uҫ@Nn1WWgԻ oEHa L{" =upvߖQY>%ox33>JJ}B,8neN-qNwvl5sZ.4aڊaE,X} xP!"n$Ei`ම%-%\ʨ2xH`_*mgsTyӨ̢+B"'0 ˄[ QVS(&3 ĄB:fޢLt%|KJ͸/ key-iyPY6U>fɕpIo}E 'm_a@jc2 2]Ĺ9[}hKe'@ l Jcʛ?xz(G֩(%W>`7ב<[ތ|cŇ$sOptL|?)&ߏhi2'f0 } 4"]>O7gm<#FFfwʀTkbW]=)5rYWjٿh} O()M9~@[,k&oC2Pǥ8 *N%5*%8ɏ^,}nzti7  GfxC_tvVaQi"߯j_QN% <[7WۻuR<QT%:ɞ%u;17 AFE4խcK9 @oY>$_P)M]YO瞉hKG}HMJT-,YbǴ2 =.LA З3I[c_bsJ3=úR6Q  M-2nS!yAd}v2SW/6td) ni^歩ŲRϬwQ4g^a;_Z f@ZWC 3fcO.H鷞 B;9qrcAVvPygI 9_*˛U$%p҅+M{a2 pe>@5_BGnQBqLn?sRL 0B,u1!@߫HK{ Q@"hRp D0aUh:˵q"NO`I?7p&N*?9΍YiW9&TWŀ8Zo3 &i]f4C>sO4UX{InLUыQIg4Kq&wZsƜKVJ H :1vt$7]WG[kLfUmá؜[ӎHjo.M$b:a:D<v}չWi&H)e_lo$hjA l3f! U=L{UjxmյG/Lj3xjq(TT'Dt+9{S| r"o2 /'q`fY0u\9"ROgACD̈',bQL쳊W>QtʀSݹI7הr.]rL߲-jStj->xs-ܡxER2f8dv\4Hpr5.{W47G^-^EN/k7<ױ֫G65;rzl=PuZe^wL#izusqe1!Rxת%+H} 0Rf^yƔȔܲ+qYѦ|Zq|S>eUnmcYCԶK5E~b9= ka$Ulz5੩T4h[C)P|-€!ԭٗ&εse8 4ujwPJYlimvoUdC)Fd4Q%MKktܬmw՝Q1}~{@;.rhVLǮOã=yO{h{fXyLRPު[촆Ed[D>#,=?LSH[RӘ΍L.ѡ>3Nu|GkF 92s<ʃQF93+ LF 4@D8528} 2ʭ_=M3ֹhTs}(z!d`gu۹ G >c@ؑ y7 H@=YkslϔtdXWHK [A$|K5^5y{p꘤뽖 2QQѳA_ % d%1Ue8Sb1vULEzKօhR֍KF ҝS47iⲼ-%pY< q.$wJaNmʼI:*"/ҏ)CNBYrg ?kk4p}iugvl̺*p /ud+AYhVf5ʙ<*%7%oyDF%@-)WN<.DqVx{ <ر ^".֩B/ё'7@IZ@qrn3 1Ga9$X#Qy5_OKk\ + /~!6E4n-tuXr.$ұjqkTIVR+ՏIbY4:USXv$l3#?K *0A?yImo X^-Mг7?Zi9҆ 8?ä"-+{Rd3tHhbS JK|fKs r4ޓnq󸜜@=}+QaɾDIWXءasF/0W sst([aW#$Ʊ\v“SpW90LD4}mw7Ɯv"g'5Fꓕb|y!NejŐR;hا"hػ \@,"Tkv[rypHZD&/^TfPna3kiS؄zU 2yBQ>u]QV;=ٮjA燸I/ɓT&Y8 H`qUIGV` $PwMEamJ7תt97A깇|3@0{ԟ;I=B㇅b!\5PxX-@;t5Ÿ eul'r{9|r@cP_Q ̑Wc{j__jEHnC=jQrK嗈BY[KYz;8be鳊aQPgA? 4W58EI4's[cr\ɴvl-@UMlr^g]WDQs?ʫXIa6Hv!.os8'Hհf&  Xkvji= 0K$ֶ|LI= jQ|G"^•.Opls Eʿy|@oNGGXZ @;G+_Ed"ݦG6*߂a4 _Dћ6G+Hϗsm@u{/ JfE $"fh=I*[(Z̯vdrguk]FYl(3M|qjgFl;nηu-=#,X8}$ PWBȉkЍ0S,Sf۹K*k:ՒQCWAolSkoVi;K#loN$WU5{@4ߣ7യPiO&mF8̈>\{;ok`^Zi|V2[t/*OzqĐ0oJ$,tUߞ=@uY"HLk^9T_Y9' M}R ~t} 2rnsn!^|Dgβ)jEkjʄtxVN Kf Zr)a"+:[)>U~@k׌`^^ǠW\CX(EMpap+yF2q]8ؑ%MuL+ )rQK}מZTWʹ ` pwiBB۷'h 鉎L@R1za#π I\|oIҀz29].ŷ#ۧ.wGRG!`Gk8ubg0/&ஷX`D30 #ys6o{y4|ēҖ3ulg+37t&܇7I֨5D}D2Fzeocҕ!aIŧkη˶YqYX'm#pT3VбG0 ~f@͆+QOl1#B '6TUuZ 5W*݈Ws宦'XE#mVB Mi YX6VZ)F +Yv,ygy!+ .`$3L 'Ȓ+h'A z_h"P{U-;߮\<.kWq[iKLiNW~:!k=3"XT¸qvu xD۵Ed]h}}x9k|_ܣU1+Ұbk6e#_s#t4- RxF5~V0^]?ڽ$6<;XAZfi5VCr.m^F׭S7LRf vu1ՔYs3 q SR bGz>zj`}H݇EqnnzK'6sjz YT1 2"K>̒QnBr!$xv’δJv0xiS@Vށt'_;Hgd䏄 _Ÿ%{Vw{>Ã<r@4b4یp~*NAAn di=M)=U`{РVN)`9sza5rhud,UZ *a ߏbroncB.B*g:ChZMfz Xw-jL:ٙު*V㬏?QE22F)αggm8[&(J!"}l0>+Ү]U53++.0f@`~N0ssP3ߪ?9vyiurJO$]Vȡt7/!%m|a8}k2S2+\7.mڼ=Cŭ_,6b"|[LkTH^wWoz}G&ŕB< ̭]hRܸ&  k{]-jPr8\+lUAY'5JɎLb)(v*zO222Ɂ~bl&5rfX;hF H> n9[wV}|& h|@E{=rLlfTtvY?)MR*vM¿,OV/7_k!YŤⅅW+; u[^JlpO@Jҙ0?_D&*WCٗ\Y%5VpZV-#[ɓ6KA1V~5F|fp'Si-6WؚAK@X9BcABSSؖEC*G H"q3j\իvmzKJB`HNޒ,ee1RO]#2LG.c2%nc;hЄt@#j#AZo\fQ?D?Ts]֝f/46)mi/>+Akj>#jNar% ЗldHmq^j&bF?RmR}iyZt6!ȕ퀅N|n\ZYmڒ/uLUiS,,%O}'ؖ<5;un$9IĿjY+8Q\*k7<vɂ <0 yQh~+^+Z˯J-`Pܙ+#;< }[-}W+Ʒfʴ^XKm6&$7ܾr\KEG{rZit|`5ZDQ"̭%'de Eɰ W0$ +׃# #v\H-tGbbu͏ ??٪مVҭ";_LC3j{+?Ty8]Al. %`)i q@s7"+9 ˀ<9ɇﰜ5ff.\^vnPbDU0f̘߀Gu+S/c2hU$5Ё N_d7V0!VI'+ AjJ3[ ;E6n&uh-=>A˩^-%$W!N}6cRJTyP*{I:ƏpZE)TLEon#`W͐y]P.hqw4Dq|ڙ tǦ|c%v̻ nM j 沆}btUv}54u @U5pFJVے(n ų^OD ܭ>À ! كfYj/s]J909dpQZY_LL:H=(E:izH1D$-ż(5+][4$cQT1ĭ)oz}+0xU Pv@?YTgH&<6u؉GIUe'ߗ궸TT 0=tQ(~CK Sfn@ Z@y}W4IMЬrNZfpkVUg%t|9R%F{5#0N}FvB[rk;\ĭ 0~)2 zj<cz?Zn2pq7Wn;]pCXmFIuS~>B5x<8|;ubeLz$鉪^m}M ʵ~>jx՛Z9APEh3f9.l;891] ,3}ʵ:{Zq"hGަ1S+xvvkoI?#K=nR>C>u\'pz F"@Q #ߗNe~p񻩂wfm9,k`9vHómvW/]K;}o`^ ptZe1 ɳ OI}ep80=TwZkҴ+4rLU -(,yqzDl!G2. k".ӅSuWfy`e?nn 0N-qm:DF6R6o;W9C+2'R[ cEln9GD ,ޑYܳÄ붂,?CR`>^ =ćd&ATSHtO SBbx󎴼1 s CB:ZvPsfIUfͤ6"q=E.cK+|Xh0Ca83&\k/ȨG8ꍰlQe/8gIM'Q2muEw"U`MM%I`yj<,3x j d- U3@0~i/!P2wTm9(Yk4(]T^P-~ez8~0IޱHT,Ibd 9j%XL-X@{ˋ!jA:RI)J nf:թ_6l %hdat*%=9KOH 2A)tqfIvV_Dhny뺍Q9vMJRܥ$&Xnaa}euh3ލL4\`.5 /]1(bM`ȷ02PrDZЪh6ڰD|?@ѻ>\iIbxP~ ̝dsp9NzfI fXlO0G1D(Hhq饿(UT=3cr&aɬ[}Seԋ,@aX˜ÜS 3iܖBɄ'܆ P9b3YJL8[;!'6ؙ3}'p 81cxW%V%}ҰKt~48bh]FzWC{[q,y{V^kB!9m"'M{b[kv?_(i%̙dDT>pt\ qs[LJ-(ڔ}RܫQ*Sjn$z,?"}Brƣ|4-[O[Ai~Fp. mJ'~7 gUJOҴU9 jߍŽsY?=E/<1J -6RBOQ Ww@Q )q)F =g&\+;8m#'G#$sJ0LQWu@Hu#ӵ{ܲSvi;Ocq8mZr-V{.؆uv,⩛+ԙ85A_D4Ő΁һ%˹70F܌92DX:Lu|L8eA ^[р%zrklTqx|0~1!X|c TvAߺlhM9~_H&e8.v*Ac<|3~%E j$~,(p+2@Wcؕ21%#y4Ėvݠ#~C^0Nn[s_H[r)P`#jA MB = @H#?5UqtD4ԯs Lq4EH__[2ۤSl T?f\vJC+KiH$G3~>)ɟKK$,x^#hX5D|ŏre]~7oMSXr'܍n7p ͽJ*6e+LJ'%-{~yt8D* ꚾO s#X:Ӂ e薷uLk#NKaGB-%R d}(jC8ϗbyO!ͪ5&7θ$zF43*F>,!7BZɧSV9ҕ/eʊ޷!U5[YΞuahvЉڂ0'G`1TuQsB|^ݰ8$Jx q+=5β?sӯ E(tfrExG!)ʿ#mT  E_կ"%_tTlK+'2N%0xeC6v6*kV_v%"S\'HSOmqwe᭎2(;jA=ca.].x,`EcxXE O=&#5k2g'ڭAn3N-֦怸jo=cSr^#4@^]i[ tc{`uMeխ0Pݷ~͟3#>VBtn1R#8w}c Y`*aU_߇a#rio-jGӼGFٸL҅M݅&ĩo>wwh~L S!$ IJo'6"DiRywܕ9 Ν8p|H ؙeU1g_gU=4n?\I|yԮg ~qwBebU!v| MW-asݯk|܁`4?2E|&O݆uUV"~6q\zZ!^ʲ&g7g'5Ӓ]iWήVK&K^^ W"9BvK*gsooVY11֜^XգDŽ iaRdP'US'Nߑ;C@~%S\@uV. DY}ߍSLP d_w~&;ǟʳ('n)IEko .Wzuhj@niLL^`;cG$պ&Va5#Qaň_+?4a<왪`?]h4BYC_a7ndfBl FHr)9 ^aTZ z%Lyd$%z(妎X9f(,|,gQg,db(v4`n2t{0)޳Ǔ*+6>~-)ӐMA>Q#|AݒXԲfG|2++z~ZY5MנyJiJGNqB&%EKPhʈ{Q - `q܈/=. CGJJ(Fx tk&3=J!BӂQľ;m$B:y6~R}qs%K%PDyW>ƪ<_E4JqӞYLXPrTbI`7[V=^{ cl䪐@zP=I kr0G׺yFuq+f=JQutDRBq;%fn1eaZS '?$y1N("M%vdVI~6ڳoͪGc˽lziE!cr#O- ԧ𬍅9_2%nMղ܃#c\R]#JWzczÀwC+! UqQ56`(r|Sp>pd7ũ>e;Hrb8nB[vφIw!0?Lg.bY[%>ʠy\_Гnc\7@_"}A!%ScrE9 \;?xuHlgT&28bMiQ ö[|5vʨ!t {Q t!n8/x2[ P½gqvxYdfo0yŶ+f',{-lT-o݇ [<S1`_.w4Hx1=Ytcj3<: ߓnqpN jZ\nnm\P {z4NTe <; *=͍m!NԜD1hgGl4֍a^*CԐGre+)+V2uC$1c7Fg  nL+ۼ`nmb:ux8'8& Aq/AZxXvZ6}[ t IMlMsC%An{,nVgs\jiĔojž:Gtk ƃ)4ߧid=zmɱhs 9ߴˮ@[F(IuSJϿ\@,_O327"4mzCwʒQ-!XjvyhSb]97['}sh9t+T[špmKba;z :LHO~!hǛ[:v7kOa,<|,ae[Jbі'fъnewɥcsA%e] Q1d]#?h 5B**eu+܏&W{ >1&.Xdd̡d HQN:CkLH; %ۈ8w *V5nW~'=='ϲ;:[:x;-JX%RvE}9zm0oG> {ęuL+oY҈2/iE noTY0*nq4ˈFuّP ^T g1"9d2*YrWC1PAsah030rK}l$ZdžzKFdr; LVvjRa^o`X5\H33R@~YcX{Y?߶'@9˒+m 5bQDk*;N!˜7 ڔ>R ~"2ϭŞU vL>bH t ;L tc(J݇Ԛ >*.)x9P ){򿳣l<1zV/p0!et6'(15՞,aүpfb62[ sɐ]7%zL}e6`p[U}=!D4դQUb~#mJ(DǦwq@/B5.RWۦ}\dbɇ!2ۓRƏj-'Ig})s+1aU67kbwb{+;ڤ*1ݞ\6f(fj286y}ֳge[4%&9rUbP*X^oqCW$vy;Eza&& Ż єV- (Ui@ D! (qÂF\ I<qi8$bf0-(U /E\䰞NC~'9wBhsE TMTx{uNxfMcw /\*gy/d$p&H>4c[ YV+%^sI)b 4DmoNJ^rvrucC2{k.aXO <=)k{4<|vdM噘!1l=OSDv|4Q fLm҃^Z/<\+ Z%P䖴G0/{!*I+ qQ̺j!\N#<Ė;ҎPqWD8ݕG#5ϧ'{NSq!f߀lCd7,Cqu̲%}^shԿ! ovļM_Ϣ N˹i=jl2}&;-D$Yq _tv$,Xėh9[7#_Lj+Qc/v^w+8¸+:HzC2H<7!d4O>Co{&bE֐_Lf|gjόmJBJmN6޷m5ߦYIۿT[C)S]pUh\{@ 3Ts'X"O`]SaD@Ye`qA5>ᾝDC_S}%v7_q= WLF?u!)Q!Tپh%D!oM0OoIzٿ\UkFJC3]s?xL zBױ<)  l`NnN}"fUSB%9# $l<=9c!`Io%5SZ{vz|o%tUYIq:="d۹slFƩo[]?0.ʑBs ~cPoǃ L^U1~u=0=[ߡxqguKMQ[D0SBH8Pkf: D$ME?2Y#XPAuN,zRO[>m jZ h9@5>44gG4~ƴ#SHt"=ko0͓Lo AJ#x9 ں,)e+M))E4X\-d)͝mh<[+Z.;8hfk1rq^:w!Hgvfxt Zn1D!I0f?jaO94#.V`Wnv*ryw{J.ЀRLs*9R,I**_tѰd a0zY+9ptX5-[ƁF%(,,]m}IXy,HF+'L,T*+=LUu]([w8{)#ҟ,{MGpkI%L˽$pCd2V[tnj c9o@Sh~}bpD>Q4 {抁8uU=%\ƣ6X" Ŷʤo/ aF`S58fܨn69uc>P(j]jfuV]@DR;( d<+gS/QGݩVC8 " b2!pD]X,2h.zwP!ʉBWGuJU7l,RDgIJ[m&*дY;Ñ^yn:2V9LDyIoZY|YLRc"S5h-"b.N]J*<=ng @@Fr/U)}Rh6+[pU oKh+1@>n&-!@x/hF|Ÿ\T߷9woܨϏ /?\QĩT6taaN"5e۰=I$5͜#*@%U͔sdׅgf/sAAYmd^_ |^3_LH3p]\a}F\RJrl$,֟oA"8'OZ3U*a]\$u73N Vdx+;# H$p9\1٧r+@03GL?rIUKZ]]T7klDo`9}@j ezozedۘh0G>+,XSL^-딳-RJri[1Yд ?[UiDRw[d@%rbVh_9c'4 {# Ⱦh~Wi!J(<7kʟNSyiWeiT5YoZ6rewA;UP_䪊>[+V/RjB' [A5$dH RYxY]; o"d1@aqr`{|B&D#4-, Po+Ǧxa\&U 2+37;k O`@93Ci3\J@MTLѐH-nI{}v8ï/iO\+>t>}@v[mTGno540DO_(3 <%7hIJqa076ʮj`txLΘ/1VKs;#2m(VY&],#"|0^}Cs(j⚽Iob.ݚ@.YݠC#;XR0;Fg={iU*´;&b$S/B3fKgmfv a"o*+^ \z]9pzER"ѫ_ (V ̮2A"!OA^6T_pgK2T('&o ƛż%+Srn"Ea~Є! BP zD,5g3`d}tvyz[X!(-ϕzWF獧E Dž& !V* l5G~!Gc)(?ԵJ0|ԕ@N7)65{4 jˤyTr!ҿcI|*:#יuFmnV+þ7 G9+heZ CoT7ͫecxn}e_R8]Hhq@YLFF.V4i'+ZQ S@KP Gk1xtPHJmZrSi#L8EN;#(Z8CghbwJn9ʫ9\_J"<`<خY+p%FV'g@_!,dkа`rpr^YwJ범(!3/o gT4]WPT@J6R˞M;= 1-Ai~c M<90`4A5E}SK|L eXG']WiFka_?Xd7ʾz »O`#aJv3 L +_ǂ53| cKF|ŗ(Ӎ~j襭7O ]jxTeEa$1q'h]ͫ8 1etY,L,L!6Wnځo?[l9Y{ݪUgh7rfh-9뾅aL1~) 3Hm8 Jf域ך DE߹&O6LtgG? 5˳{KȟؔN"ҧȻ3[5?0;$xsڑn ^ڹ@dmP6D8$ْyH?]&Wd tiaڤq8^c.E_U\}">u>'NeV{)LʝlL4 \v otUipg5[11 K\b0w6+;&v$Z?[ul(vO&U6N{VJpt3 2JeaY۲qgT;O6&(D=Y-?k|⨢ O%Vo6ѯI5^t\h1l<Oc|js7u L'5cusT=KplL0k1MpRm•a^qz=b-FD^,ARLdHݒaw&6wcGRzyne9*%_[H&˭,Vہߜ?Y=aůzk>wnM0R;+bUN6Z|k!&>uloR\M%dr(+'r{}x#my)J3Ko28 kN<;zBTaS 0L]z.y9d`es߆Fq&6n)U1s;2#yh~^g# B%dk!ɹ.FLuSyTmmHAr۪(g(}S|>bE+T+bl hL_]ɖP}cwv x2ZߜVEA|Zg-@6*xn#z&r!m>>Qf pغExYBcwOozBs=.KU|-kgl/ʵlXMcVgUY;'~9!"^13ݣi[qν_\~.  Y'sVSgt 5ػQ$.<[(aA3!'A79)k>.u2 ./)BxRz w+c@_Fk.jYXdn7И 2պRIs~{9*Gn/[aWN!:Zc=iV}vgN_6_\>hBoqYoRZ9DK1쐺Pfx&!q$;4p,܋"n?yMib */hzL )V; B-Iv٪9F7V:̆u݇HS. |DOQT;X)y$PȢJ ϸ}i5}ӘlP dq /5Ou@ 8mk_}#vyM%Εqթa4~ :v^;nJ?YPTCS3}jYD0x)k8'VveDS(Rnh ,/OCAĈ^|X h?c Z(sHC"hXͤ LomwU41& U"76 J3s^uc3ai1p3ΙkpNnBy_%ۜ &hűMLFl_<P?@~Hܫ. ">ٸzIe:d@){HP˒")M17 bݬ03;Bt&S)IoĐV/I}y%^޵^e%2E[~ M@E-K8+#fi4,[U*QbU*#N؆ za#ϺS@UK."HG?^"b7F淔y х$-\W(eBȅY! P~|KOE?AĆ K!nm8`:cb;].b=!Ag@'_; |l'APn_M򌴛LzLt 7`M+ȅ `B"ՐB7BK&'H[$d4]%fHz~Q1Ygdt\(aCxWm+~c =5_w Hf!U)rtB$0MPPOA|-D5bx|it@V%k}1,ZLU!6H44eɵƒH>8ew>GnjupoQW06ߘRN)¤H=4b/8Xٟ ,:[;g3Pu:NE+6859yhT< K._h(ksSl{|BI&Di/iwC(aq *zbk1Dؕxn%Fx<*WfqE7m[Wb߈$EΟ7VlaIcGooM6ϥF?ȉE@҂M:I$!,3I Cv) լسJ10;U`€tI~>~y%bb͓GqYJ3YR#b Yu\{}BfF^RP-q.G z!#3Dh$G3zW#A؝i t}20B$&pyv(E{):xu! Cy@5K3b+ ݪZq c݈nUZ>,@ & :]3[ ? n)$FB3LմgI)߷UNPx L͔Jj)BNiled}$m:Sv( Z|e|E[i]ŵ;YO*Yo'$57,d:(X¼jϑ&F(#k[a|DײoztY$?@5ЅɘD#4taF՗0<@{=dN{ni8OxF5me~BE~9gS΍Z6Q?*n@b9Xb$(q0;˒u,rr9@bPU%!pYăjn`z] 4:NKK{0\cg&2}&Ln* _F>4RSTYZqZTBȅ ˄2%Ԩ-P?[ze.S:RnP3 zmp6Z4T7ITѸ~0;tq'tr9< (Y$0<]uapL*Uf` 3f4scIoN7&gTfA}ɪ-c/J߮h dEBEbkrz4U@cM93:jzR~6^##q7Ve㠃 v_MNl<Ş#pz 7lAVɚvJF/u!+Yyt"n-O^چ-vY\6jT{@ k0#J%r{4ͭ]XK40Ci訧RDW$|DKDݽ26᧥|7(;T+۹[(OfHB}fws=\.d6=K1b#@=?jJ~#5T4锵,a*&nB2ۥ(0+zQ%Ӎ n͞ ^%9BeE6Sؔp 3gW%A3?^Q")* 8a8^_h9R=ΝHN '{Uzٯhlp3[Uu |V=l튇iN#.5 nz8ᑱYECw/]hJ-0=edZ+jd*ζLGn9fZa_EcԢgN hJJ`B4)'$Wr1+k9ڎl&\:i{rУ~ڧz>k7X ̮ = ޶Hn`)PAn>w}&`ei+5o桜JhBMЪQLݬSȎ F׊ళY3Z=W[2K/笌THio&YwQVE+9H 8ϳrc۞dV}޷vma>bf@?G`7ؑnEl*#b3>A!`2&U˺=zHPoNG,!&&D':c<C.Fw]# l? ?%Lc(O6ՌDJ70B0[ *>5ׂ™46[LC`|)gȂktp֋LBXtD) {7NFs~/H|1Er`N&o PR #ϩ9^E1Hq[Zi˛ bj'ɏ:i!ߎc,,mBx#[ZHKW3&A.? QϘ7#*!q vOU"8A$*j]LEkԫɁ/ՠY[jv'o#֍RȚJtkm_tf -@+L(Px NK9׊'Q4FQ$&12 ca- Ul u`|K`qn, _R I O?% xj0s~W|MZ1FW)pLT }㋑ReIΣ3^y#+>'zpMcDW7dE~kUq(p9je72w-Uڽƈn݌iӭ=-ZD<6y̰LzKRFB蕘Zw3XUحA[LnC1 bS\NSmaS@X"<` ?ϔj4 -¥\4CmtGs?wvs͐nW|;Y3q֯ItLGӘ '>pC!=hSY1o,uB+fokP%7؏$[)t1jmId| #s}ȟlTԑO`/DVH|g=<6|kU'ϜT M&ÔWMin|bWWYȞBR"GʳT"c ݌(\"Dp>ql9ڨ& K%4۹Y;UbbQ_W/U Nhp7'iRu=_"{ 2e;LqD >:^+w d?VBj:$;2dE|baU z^n >@:ޅL=wP}ڋ|bjBx{bP%q&f\ּ>)TAtܾ!aC͐>~&[)sG2 Mhl/ E0#g_W1f+_LE@`&a*G$7fPZ &G% RԻ jVYL!&))mkcK'PzwtU*,hyͶdW@:ul Ux.SX( :~^N)Ɨ-% $?-QYgxWقj^Ӷg8MiX--#66f/YHa+ZJ_Ƚu)> +]xQ-l~ܺ{Pv I]ߝ&LJߜTۅ=sN!\L%tר8lLhoշs2? $ %Wܕ'SYvrKԹdLl\ZGмdui=-{'"8 d! 0"c€!wr 3Wv ڀL6MgιdRH̞&]FŤ#`k+FG%k~.,>tQP}_ ,P)͜,aX߀r TfMlT-j) UûHSsojuzM2q<`giJy*\L^(ow1|ū"(À" @)'@^ ~Fj _1Y׷Qu0P?Waj_o!nb&̲{q7w0h%5 >< OyK7~Jj}zsrM9 ֖ \IBF0# $%Š(+2U6Z3 di-DLw.6)W:ٓ6& H.D[JE7,n!mE:kr eݧZV$52r29(q4qБ-Bzuxa!OȒBpF)*y~aAgb_ad$WX\{r ?9V9;{r[/XϞDIJ0F!ؗt"oP~!@/Vk@`_p0Oq'(L~aN:$6Ju1b9KL^a# 5ah,z[,$)W=x55;ٳ}qDo2h+;(7̸2) cZ&SZE+ٓM^kc@{Q$b3>fbD֬T#va\#eNqrǑQTrnyKXɥ1^ʆ :x{ca,~-{ԣ8:;nEj1Y bۈ\Hri s,3Q!dN[ &΋Kpgkd} r!>њKgiK8W{^ИjCU͂/ڸ/a?nSiqѩzflO؜\8X}5j5/c1ȻfSwQQYCHq*Oi<Š(P=>5CcXvX3q"3t!8r[[soa@,Mj&UC*p.>D7Ρ{/2(O~O7(!7zTEYIixk(w+;w"O[ E7ǣS&#wE2EPհ-[W8ŬYUN̉=2Kb؇V>li'k{>)F8~^+L0x&q?HKplNq7z74ϔԲS[|a !DuU; 3Zݥ(O j`h'! \vG-5 EεH 6Z@WPD[`GpyXZI|i[c@e~BYS4QߪKҝqcT,V[lj7k.d(Vl苧*FG }aWk yoy+<^H(fRdÎ#>J^tZzReWX[1g6@[FjP+͋cE!r/ǎ_h`#N'' #wu5q6ęТ[0 >bͻ)7hΥM\JZ֫§fKVi`?-ލLe)zs}c mbq O% j-`>^l2jT>6X+^(s->wHRZHkRXYG>|q]䔽]dJ`S8R)~||oڈj"/DP@ NRՈ2] >InktVjZMBAHuhY}7T16h+$WK/ܓ58~  zDeDZ?%y8 w p9庰a:U+WEFb KgSC*zq;7pAY-4w s+P/)NZ+LPm5]~]lXc$u hlsdP?wV- E0a7,%ͬ-F˕VZgDK 6Qd޲Ha7n>0TDim^Fƀ2^9Ai퍤jlYrx5&R`  |#`UpG ܒ!Y J'.Ƥ 7.+%Kc="KZd@a}PA}8YV:6}@6Vɹ u/W1 S?& ד^?0Fר3c[\ިH4<i_ o{GռT1G`@H~";’OeyY^WD%np?պlɷl7Րd~z>6xJ/-L鴻4\3fx @WYX*(Ȗz઎4^r>tz/=59 eb68B`w|(b>_zP)2[yHf %ZF3O˲r _G(^:F]2:a5ƺu.#][Smۨb%sYsW&d k}|DyPy*LK$z易 ~dfjlr\K%R2:GjĿOe$T# _';48TX:)f_k6\(_y@{JbCŇ^x"_AdO(Dӭ@ ^/ bp`rqfn1 5>nj%#)?Iv(k4DG =6;KDEob%dkYswhy>3<5*7X]i?`Tڥ/,L-6M,N Ёq#v: Z7S:+rqzL*U\FqPfCBjNj:R5[ :nHK"ne)3#GGOcB0x>t; Y=i%F@@ĠL8_ T,Z[3P|,(7noa<"TƃcI]~P?uE~y Ϡ7VB\b0WDk-("WWTD2/>\1zfU!?*f-/cK\C;Hqך'{!9ߋZeX ݶDv28WS)zD*@ICH;4|iFմ giZwy^ 5ϲhYo-WhJ[xp.v{,3c?7Ba^LpF$f_i3rUX8z2"p@~vD|d29G] s) (pb@lx;LֿzCWtN>f\ׯAkJK4.hdS#ʅk kf>r}*r8+_/:Erut6ᵞ^!W:"A{ɻojkVHǏp=U)1G+pR@M}pNx}͕ p`eSPUYBb*ڞz=^YT_N?$N fHt)L<͏̕uB[/9x"C/!$#tK+f^Hj`",0?{ꈻr 'M b5S2'"o''JXժBMӬ;Exyj\&ŸlX! Ѕ E}ISOgI&SZ{TBq`M1ISߡsHU^՘:xZTط5x0U'r% {do)QfO.Qŏ].;7g3ɥפ'+NxW|s[؅$++|" MJjG2{N%:g;;))J׶/QSU[=X5?CJ I͔}qDq0!Hȝ%6~qo[<zEdyb+4f0wH#űlu_uMk ޾(6iu+kЊ:QN.i%Jzҙ8,[ H!Q Z v;WM\8YܢX=Lף" F}*gQݯ ^lz@SxU8n<T-f⌍pPw\>;&#2q.yD<Փ4A{9 a\EdkQ8: m2~ݝ0l8GCTEx͖>'K@֩^vtO\t yr/$@գĈW3nIXFMyuYחɪt}|TKY&pEm`q*OؓMv|w(EV-@.1P)_!Mp̙$xUzHVa=js?8hXed4K5 14 }^|~ r]J41) =@),(+01}ՔpItxvk8%!YVS {لޕKj`tXʝ(K_c|=}jٮ{nUQc=Y6'^,hմ[`/^:=(q9X2B1rzVbZvIdQR'l|F I! KRA(Z~v 1#̵;p\9ǹo#Nёp;h j?Cyj_q8Խ{n;SO.BrO071)h0F}pB(,җ&O5E$UWi^J'ql&lwtQAq̨8IW~@ :SM8}I/2L/;܍v$8@Fpj?dBg4r{^²Vs2A1I'tO#6yL#nlGS$!_,v%fdEXܻRWFbT},jqA)InK]2XmtegD\69hVc =Q1ߩ{6(x?Z2XuJ1MaEt=?5:r;dyB E9VMDjRa$;{_;ev7W28{"=`Xvq$߼ӡd(. 4 IsqbbBdGTP&Ύ$/oؓMX;ܪ71QL:Je2o(~%0"EMAFӴk-=)~蠶@&㶶 N`X(J=e5f;a1#sNT:.< w ?~J´*b0* 6?<\\D'UHU64g5K9]TEuhz\ZZ~/e ^FMӟEmiDZ}vz√N1FRbp*sFZ֖ SY_K^`תΖJ2 FN1p)b)%_7u ['[<챆;l#_by̯ɖ~C\zd=6\L iˢ~WFוetl,:=K\R'EwjReԚb`M8]3VX)0@G2=/LZo1mIl/"}[i {Zm2JȌE\xyz)(Ƥwmom*XNMz=x\G;p Vm\HuT0͡&xi8^Nh,|7yhyDcpNR#]ap3+m$^Gjdp!@,]! u:*#\bOa`MY\/-|4gaY(⅊ ^}*<.ty sZAhP#{dE6\Ͳӥ1Fscy) ;|GD!~Nv\͝hju%&A@\btv nF f[OsުPm}2;hH ^s~0pX@A 1~!ݑ#%mbwP{kf:.sKÔC5HZfq g1$&%x[dܫWڲ/Xy⃱A5.i Ӝ֚9طx o*c_bSEY s%qZh%Qfd|,P>l<4ePfɼC. 4.5" )X@s6CY6exG%RMO;I({ggFc) lm25{2ɭxxRyHڌZwFMf5 6ɽ,Ӌ>M[3G)gx|N,$쎦3mwX庪NgBWխjڏ3X.P"}LeN.EՔNDҒUddGr-$ q00$LU5ӓG|R8]s0%Fg*;RVCt.2`7 }xJ盗 2C!aWZ 9̶A[!?0ESv_tO U[rO\rso,QĝaSZAF]& ~ٺS9;0/Ah^IZ'Aŷ|%p- Ius(Aﰀ A\!c}Z* W)3T-1㞈(@.7;%hT7MvfzP4z~ ~)! l2 ئ?(I3/gm霐fbV,A5wbj:&'<(%4N:&(D%kciACli(|YFsʚk aA RoH_ZSM(3(- &(!5W4(D6cè;|%6R V[]Tl 3 Z:KT"G}Rz={߱Giّ[.>#>w3uus'[b sՑis 8؏NdAȈmn8I{ + JVWep#!?o;|31jDzpx\/އRZu$ 8\Hݠ蜞' mb/%C'-u^ s ^HoXu ~FZ'x2O,c;yWc#9-t5Cݧ0iGRzb[ݳRKS٫H̋lڊrD=Z'o =WSPo+d(Ηko̎ޤQoɄăY!Iff)Q*MA*U|9s;zsx6Lkb0RRaG꛼.uR6L@O+PQ^r`;BGmțl>daG ?=N0wEV};Yz,w))u^0'|z2GAlc\eϺHDH5VpӶVx6ZB}9#t$S6[IJh93@94D jVVjy5WeP~gWvʵGI-/g wA #X (" 6X)#lLڇh*Ȑ *|\1v1+c {8޵{~(m'|?fq7?/d}됼V,iצxeWӶD*tMWH&M]MG1/fnb!'Y|Q24^9?͆яH%4:./G vZЋA[bg/5-2$(`Naa%3M'qXwXLjý>(hjbuVȮ$3u?Q-kbud:_l#;ܫ+ 7.o.-ޟѹwܑ$S*p֬/&z{ _γƧH[""D,k&lOw15LKqtەќ.Cp0ط2sMΚ$l\)SɄUh'}HZگe@IV$[p4)rs*?>?O^e۽"#Ӑa%c,}C ^ -Ũ,5lfx|mY*9uJsര`bP l~>I\6RBrmg ^̲Ī>@)PI鶲fgW38_Cڢg[AiԚŮH<Ik޶NOoVPR珴4`bfE+L{G ^u!{S(k vO֨[yu J<Q7rޟ1E9GgR8|8 >-j&gw1Dtqz6%uy7 G=iNsm2ngWcxUB[FNɕxq#$`L~_H%0۝?( Kj+=,UG6 2e\N?IJX{ NcO7ڼ0PP n.E``vcR|iGZFk-+?Ku/0xl-˺"1/̘#&ۦ!sc"hs)iS JTei_k* 3/.Or[`'=Q1U7w3h O}Ѿ%pV|dQ7HK'}f5:2<Տ,qp\9ΌHFX'F@:--`R-c*C&Xus ?q ]G|ͤ_;wdY̙Vgej"PD>}ą;%햟wwS]V= ]-Le{ԆYRS-V,8^?lN*9ݱRX8 s nT/K{u= n~n=N_5b3'<d73Qfj!Y{ɏ6&X?.ܑH5rEOl d9y,.' ^)& A/,X) lr]3IhhkK@^Kj+礓kܭ̙%CG?GtOX1JiT?G8xKx%BP䠌0۔l?E6C~"BF<esɆ>hzS/]o9)[F=ɰ$VU*"ZLPy][vCeJ) efI$*u=~JagBf[zVꂈFm= |Z;!bmS.nCƔMМ4) `uR'$Ց.MM\UM# c5+t"KXEqq5,?E>& Q dq&-e)5Q)ܱw +#Wd;Rl!2˔aLGUٱm`/ D_%][]?`~z%׏ Z0MЫ[\%SȇNk" JBaG0/f^.ꋰ}Q] ,g,SнDCF3ɌQ,q D NB B(T; :8@cE?S&*(NF %Ϩp x1_Lk#=ݑ(+6|fBj`SeWFЅUZѦwfdG𖲪rVfJ\*9C:1)[Af5^=lHI&`K(Vy"A3qN OIb[{թayJa:Vx*F6 :Td,pkDkĂ$VoQCrd$~Dùm:4A.)?鉠ÃOeUO .hs0Li?}|=Չ+SL q^BkZ#U*kSBsITⴣC:. m䱒l{o}LZ}bX1mwQIyK"-zY1 osej6Um}dH~}R-jZƐ^^,ru`#5TS$?+4 ^cܣ\QTgQ77Db]CTH\sϸ&6Z9-CzyúO[S]'I J6=ihXa; \R뗯!yEXA% Ykã`}/:ۥXtrgv \"S#c*l/Ĥ3f[S`?;Hnn%fϝZ%%&;|wBAw}Q\i6ɱaɡY\!Os~}1 |gן#%vgEؒ,%*Z nE>h胯 4 ewJ4qhqo|o~!o/@ZYcy:{lxK+\#l,(: J>",0J`g饵0g#&vc%GJ4}x6lZ. Wpv_s-nHqσ? Jcz+}IE6E'kܴE$]T RkT<)8Ejqm|-c9uU)ă ~RZVIQ,?SΞiGyp7r M0uK As6jKHU]^9]Ƴ`*9b*&1vn:2䝖)̝/]^$CӺv"wp. y͂5ŏ VTTA里i80y0SmjT> Vkm$M(k7/ރ9~zU?ݸ;2qj,S㸄̑P()A2ΜԬc7d_BI,3{ 1T䃐^8z`r&~"()7QLw\ kWC7YnJ8Cp.DpH34 /g5\ 5wJQYhHXUP)F{A~4 5=*ḍ)L2řÅ4WE6#2%,ޮwCs ~P |0~J)8p[}4.9]B3Y.*K!N̺X#>y b0ĝj VF!ՔfjӮG%r R&^:tbIGM_0E\dL1{7BSǣH,hTF_ Rs)a yg-g{>XuWpǰ qضm!dsSFX 'BF<2U9Es.oG*59+&_}^NJ^{DvxKj3 d6vXW`o΋jJQ!8H2&BCY u"s V?] kPuD[4M/8x0f 嚱5MO1gO 8id?a3"wc I}=r!xY;Qe'/6Cq$O Co룠 uW/"T$́7qrO~%ƯA?@p3u!]}6&g6JyMY^gZGsip EiP %z[7)dOg{xQSIz,ݠ OtawkQi!b+)̫pWnrt1́5q /Zm*)\.utolecR-8$~)NJO+&+/^S&Aqr]Uy<$|k6R=[>Բibveq28ᇉ:Y,h=-?mMׁj7 qKS"n2OM!"MQ>_rb5p -2Oc>6JthOFJۊodHF&C{Ӏ&BbVpWiVJG"n[㧨nЧ?ehG QuW2 j%Tl]eQY`f1HUr͸v1ǡ]}Zp;sV1u%AzToƕ{#sςK >kOGoNyqTQ7X ^^`tٙS +A 4cNЎIkaT-zL`Up @ ɾ@Hi*r"x\jN⮞8IdXJ)[g((>qX̏C!;МDS2M3j0o-nT2t-I -LF>G4{-{Kjg08oW/P@jD*3ҵೳ);h4tz3֊D".y P5$[۞궯 xg@ɩHnSa); YVvi_mm!U&ęPHVN8)2䩭Y1^`KNuY<,Bѻ=It$ n;#Y6xiodA+m1Iˑ,3{ßO[A!#)Lwي0a[`N/fX.Mzk!Ii2m7KܟMz (Ua^z?r2U1`.뤿ȆGާ wӼ74}%pg<:I[X@dOt#LH9kiqGBDi WkSʀD+Sb}݁@=,M8i,ei)Oj ^~Ӛ69q$+ 7[5#IPGY1VoI_ eaKZ&== y/`) 6aX-gਓ[¤37#)k5gCDԔ) k@/} & ؏L@+p+wz<]>s)>byr*Tl(R:Ȱ1 [Js&C($Y$إ&>žͷ-5@-~oS v̔t=?Cl\3AaؗM'9*7NJމL3y̤B (i>K#:TboB%%sAf !$eZ=B4Vĕ}(ųcYqz p#j*Wf$:)#4X͋Tc[wBjf"R#ۡ؍ DE"jcѤ-Uj#$W͚4NU'ݱiIwٲeAb}r=ro]E=pwh,HVRIu*~^rp0|%^cDHbl@Y e|'4Zvh#3谒|)H {=ϫ3\'p wG>LJXwԁnRa33b"9:p3./ү$szeVd" rY$RfU/G2]Jɳ`1KA yA8XfOPDIhK#*)H깶j<\_S5R*OKWy,|@Ǵ]t~=AJhDh0 47I.mb0OSQx Jh A#e`i-;Eiql^E(s 4ZquP QF3\eD"$|8NN*O%B9,$0SH[+m8TCJUxZ?+>}ǩ-qˎbq*\0;uy+g K1\%@T:<*>)\PPxP0>V`7f$vKUr^&8o"ޕ⿙VkT}>sD o\y5>w )ATs80ڇ*JdmC6zņBAnYy]3[~S(H_sU+/fqE3u}eVX<(+xs[K_ ?]r.b(!-@"]pB?0URT!>O GA8Fx^~R7(8 ?-wz[)46$?#kT筓.r ]<ޥ bT>һw_zIh̺bo ;Lf_A{c9D]';Ewe&85jӝ;.́=6^*᧱K޺(׵N6ɩP9Bybb$2]Vd$s366Qg]ScblTޘ=`|Ip>$y~O΃c3#ck1K0*ֿd"YWE4φƐl(8rf=c4!F8T[uO\#oQfu;  6LɿH3 ,3>.[t7;#JߘJ)zSRVG-$mKgF.b\%7u(tK }J=݃B|Hڽcl__>RjfcY=ބp{vE\Q.cbtxmT m^h5jgq'&Ѣ  L-5rbWVP[(H~%1=u!й;($pucӃQ8OAc\[M %|MפnatJӵz 2ݯ";PŤy! jJʑ@%@ٺà+,\G8C5sͨn:mUq@uh%ƿ5Lg#ͻ̮W\ЈX >i[n%>*Va4Py."hq+y2CxC }[;:fXa W؈hk9^>Yo pQ@n أ)鄥sw_\DR #(E4Q/kY \v`ד[h$ʙ! 34!f"~f7i4% c?gU`YQp@I\8* Bn w ضvLQ->f&7teCD'@%*bZn (o-FeYfm!akxV/ 67e<.<õɌBt-|vkGZ+^*bG!/uW4_QCoK?XVК8{  Ⱃ{I:<:棝 Fn-\p39ޮiDYɲ{]EY? Jrz$ s@tTk0[;FF>8x:܀ԥ-eVD1PN5S>-_i58R$ywN_KKs!v<=+<~C9<`CǽXAKh㍀E>H{!44xZ'yF]< kgA#B $Tʁ?P4TN{tܺ -5`X u u!Nޱf%JʻM9Q6W_®վ1fCuK;apuj$r EIx"˙ц;dmzw<Ҏ;y>f@.)tcd"k k+9|F<$tǺ{ ޔ#̑qZCIJ жAI Q㸧(qg+K ;4|JD6j1֝T!!lSvU^KxRNG.Dh}vRRϔ8 Hy "c]Q˞IĕZ\l]V9aF%ZOPAc;w)QPg3+u[3[J\ gIz(5@9}]>OYFGR5}҂x>>AD,snL6-qv~p mC@ym^OyXF;QF 1hؙJAf}l-`Pbc:i&.M Vs,|{O $ψY|2-e~>ж/w&k4MubD<8Dn\9 y[d0A#p-yZ2ctbmx,cȭM.:Ӊd|m׎2ӦWku: (Wj5Gq\օtr_]كVstVȂssKrLi4q͠$S&j,:m53NvBQR NbϬZٹ$ɕcB朩yhs-) <%q4ejOqm9M.cVk%Jq?_xOjkzTWJ=S:+p |)z+SNSvH \'=|FhR$)*F.JVz5CXTt|8I͢DP?Z$ReB`>x-)H^b+#dYz;FG S߹ekisdnea3~ 6%fSt<©NA-{˕;e8>d ICH+es̵JKX6G%KNUqxw$Й2Аfgf7~q2#ѣ֯*HEMg s>7PHq~U{IQ8#Ju]Y[+n0 K`W͕ BXgSP;i7pq^+NQ*?H搛8-,Jr2)` 0zi3,8k^jqo4:{s?Q%1d g'NENrKhؐ3⊬6R&# ,&c,gdK~FfJ3WV.ـbɌΓ_Xn6Ix9[@W;9|gXI푷O+~=p!njWFv+2W>eM-*? wwΒzZs&)m|6~`M,"0jPē{eJl7WTmxt1(>%U` 1f- ϔ;bO=F{k#mйj-9!_+mAGqK$;c^ax;BkN P~IL Ï<:y<2~&Ĺʌp#1DPj?o'FEE_yvÉW*q;ًQnsoT Q#CdAS^+ _.ͮ^ =I絞E=^-|TPI\͈).vEy :es CCAH5|Ɔqԧ+ @"Ճ /Qz1yE㿚p H/)"D>zPXFua85[&(=@z![ꬭYQ usY-MUQt`ԇ9mEڻ>=1m\7^U/%TFy`f&_k+ 'OÒU) VjT_Ei|uչqԎ6 G3_ !RI_Uⅱ6~n ydA*5)'xQQ Ggp?ST3:h8VUȱ |g8 H'hWڧF ^df`@xet$rYWrOIm{C8*Aػ( [2L/֩ 3i@3TVjCΗg~P;hސ\gsQql+m+ d|B+S ϻkx`΂xĖ:h`ai,`a>XA[D1 ,B-BCF'Nu17 a8~! ̚7}Je+lչ#?KZ)jF$NA3%UFP^2fXVW]c(C0lvJ'γpf#<{+M=HC8ߚg*cw5 0/k)'_?VC8@g*NByCZ@*}asMH˧/3 y- Y{U&/Q+IS URJǑ-07jh **OsW"PH/WxH+$@: GӃ=Z@i;ivBF&PHFs\oQd%~`6h0i2IӸ1!Ӿ%eTtڂa5} 9(ӭ+xLG6.JAVJdՑA{l(1z1J{!Jg6d5O1z[}//hLBSl=)~u/)&?]aYA&9" ץ6ݬrYE؋9&->~tLw*痔<'79f߹㻥~k*׸'AZPHSha nMNGbc-43s*kkR/yƂR,"!"Vi}m78?ḿ혞ܩVx@"T7~oq)tC).PP^mJmUjFJS }2;n+rRcW@.P]٤ĭ*˕k5ZyPw&wsU$M0Dl/s&51'u#2:0]f|?p'ӄ?$Nc!E2"fJ, z*mb ϵx-eU꨿. lOxnC]Q_!81 }) ۮb/-CzȞ%h@3M0cEln$w#?(#002-R1+[{ayWo % e<,_Fΐ,ZL8׵J'9c!bYB%!r%kBD˟2Q}[2cn]X4R߾M,hu|+&VXZcL HTQ{8n Զ[r&-خU>F&hR]4$eGD^CNpUeل/5&0BmH3nC[*k Kۊ<(KK֖҃gEkT^/(DU5z,AJo ^ZM/A$)Paj}.=#ՁIWh /D&Aj~p}l- եnz N-J Q(UfLȰ\caHѱg$nf(^qͪlŀ <)\(=ARi^K1]^rguL(Bzky WE9y4cN,Wp?0(q}?'܇ UשmE L-}iȤ<|&q #TɣiD H*r0'] jd@{Z߈p4>)}XYfcG0zO|# ]?N;aTr!Ѹ7>+ʉқ%dq ߆L`IddV2y" ֩qO$RwK|Ǥ!BAŲrN)&$|C//3g}` ke홊;bfWZw)\-%7cRhd>h+ӧj8(jF MIh o1δT"c L@597Lksjh3 T9+ ɍ&ѹ [{MB9Oɕg >ov\ ri;c'jn]VKWx2ͮD7~v|TWO V@RJ3꩟k< ]U2@A'oMD6^qHFd =o: .)E9[/酱q툽)}?UTp,Qs|^̈=gg#4,t lMcK 4ј2X?d,bg2*^@eZoUv(NGREr?{16dtUE5.uuwڷ%ک Y[sNtBN n"p< z(*hEdun?ͫ)>Hם0\@q~%^8@ڸ. P 9kLQ?n!exn"Ho{x)7K#[ t0xc=ոh)˺ HMg8*.!39 ՃdJpc8ƴ>搠J}GɴaniW7│Ճ8& OwxrbY~Luz m&6,LE+@*o.3yQpl`IE/%]T:E!1ad%6<a[DS;N5o([;mHѠRlϺHL3 Tela;[[4dS@:eF&Qos Yo[sA3VIࡋ5!&Y'H?ou ^G;M(lٜbF>[V 絼t68a{%eK2p̃(ڋm]F|kY,ͪxg_GEvTu3Iޖ8$4I+Xt>F҅w<vaIR`,0ٓ]umtZćP֏w!Tʏh8+Lrok•V.D^iX7[eq@qY%iX{bʬij8'l`+BpzX ><%d9ޭHڎ6MkȜ"  ( KxF9Na)WuY 2NFjI l[ko8{ 牨0/1u]ecwvUkWe>JvW*AdDz(W 7G+yatIM&HzOuvP~6nz͑*k#/ҋ2/g# $@k_V7S}ή w{!RJE3O6 m|A9<ք!?/WwƋPI˷40Va[78kp$4ܒk}N*hzv<"̭ .e{T/H"%-$$MSgn7XONe3+ ІPe0maDži11L@KUh6|z!4" DXqn󻟕2ak=TOqLUhrʁN+ j9ͳ n/LeI~”#M>p3D-C-d/𖿖)YTNh"M2/!SC@!:dSf?5Ȉ"hqo bSFl3ߏlk JұwUݾ(L;B֟=A1-ٔn:Cֳ7^0*h~VTuVpGšGi@9ݴRB㻺ab}:P)Rq(=eJ9! ԉ9ֶP4*#I.9W A)Uj*֛0RV롚iN"CM `P%ou҄rϮGXI l}]} 1h@)LYdW3Łg'~W_tDÅzW+cɺ)1:6Oj+)]EQe+QJ=t)/ HAc ^z闺cĒFa'IRIퟱݺkw#"Mkż`##G(Qi3U?RlJe0Q'I挄 H9"~u#3Ћ-Ԑ2[VcGL}2w[ 5wO1%CP) K8JqX])UM 2%@6! [|@^,϶@_Cum4#P͹Jµ٩5CEs&} N/i\WN.׌g[ɵOMDF4e!j NBe)ǴYjT6GZ,<2qګ X=ӇTTfܘk\Pa2f;\8!/&]PT}iVp*xZ""$${V ch\ x=1 %pBlaXz{KY܍>v}tE,nZ[m%|e2|, ]LE3K0W 5uJ;!S,<4Zu47cc\g= ]h_po|.Q ߫z=8r+t?㹱Uř&T%9DkxI_zN XE:u(wg*nt i 长YVv M PTMG^F""LuA0Z8͊)CD'W?r3S*<l{U(L7CD_RO-F;2,z9pPNz9O5aՁ>_k>Z>d]_v>1i}e6p ۸E'/pЦb.tx'<[`+t( 3o6} }a<[Xw'.S|nD|B%X྾(az&< M n6Jb7 u)n;MnH$5Kw\wZiv-89 ƃ?,Pv㳫S@oʿG?fk%9tr.@ !@8WfefceJC\)5Ǝ6YCP:zf 7̂F}&e278/B StŮ&|?n{ O 'pW MQJ{+R@ˉVR -onbeg ELDTwS9G4* |yd@/曶uH&lרt$?ɇɃ4M/zϣ*Ş;+3cov,x 5Y% 9q/3("5xO6 (_8>q0g-45cBj&CjGKľ\(Jd_Ds^0J/t{QD%FO%M4j_kۈ~3 Yڞŭj%M󹺅gVqWQV]}1pB(LVB?Y]uLaR^bRppwjcb"T [5e=ȗ*i1>g2]\e(zK$i^ON&}ʼnIT[h(l__^mS'=H:l~4A'j(vGow@IqpYLwYT˻+Bt0QGHYiƌZQ@8>rT ǦUߋc;y~A\Ps`"F]3c0-AIw?JՂiaH6O([dјr? .c@`M;(L}vξ+ՁD:*}΁.ZP{lf/?' xEoU>)}:NŬ6kAc uwQZG .xrnbIiIQڼ(]&ekc]N+QpUU=:*yEY- oJcCKbdއ+&EqLv:P쓣SDk M.~ıHSq]Fa,.c9)[oyZ|;lOGB<#N5.8x"oTu&RckKho{\&Z*v3 _)̥MFg|~3nnʍڿ_Ti ~"@Y1qmW!sGQum<9e2g&`&X/x BEƇOeӐZyKEWg'{PD*|-R"GLnvG(C;}wet*]?wk)Jzh(C{B::='faN04_ϛЍHU M( ugLMdsEݸnu<]=W;;%;xv]ċT`ГY>'g дgDYc-#y"UH)0UaVm]9sp"b'cyhsXŔ';RpOJPjA5aJ=cSjլpGƴ8TBB?~z\yЁ+;b۪$Rt2E/ ^O$\g ?PNFIX+Q#?ؗ9 A\5Qw 4Mb~+A7;^THR+)9sxBm&BhJT#v]Cc׸9TDm&6Lӓv-зs o ~mPFbl}g9=ZT|\qa[ Qn^i>|c|`}ζ!Û݃ɟPZ+̃bLUy8!Ltjԛd[%m[ɿ{U v,e.c t2A{ CA) ]q4ѯ9f9FyAz ^ms:X)8Hua[ޘXJT.<7RY殯!htb$ N=fޱX^)x;b8VoÝZ{\s~3igͭT\Yw^@c")`y9!%GU]ҳ:m@Y>;~+;_LVWld16Řyf Y/Cm$[_ůU~F%(@~~EO'Γ p-jma\2If1?cѝҏb%E$Hg)=vn{ c Jb,'{~x PEJqLQ?JB-Z3.֎s[#D-=#EY:i14wy^qD̺ F[ 'f&?A>c0vk e?1-@->Bx욌M&R}-`IV 8oVL}fȻkXx'LdvkGԎLJ3tشl f,e01ˎmDFcI([qb31e%3?.FdZ`O^=Z 8&jFF!(FHxg,vBo[ hwz^PGNTa9b/JmԭE^F]%9li`"d$b$#~kjoC_zuY] 4)q  }ƧDM89'KxTϬ}_ϥf++*)#oN=(Qpc$ӻPjFlq9aҎLRCM\erj0K=/.OyֺYxԞlCD_F傴|z5kYWؾi0_cS&P-ltLvezs;Dz>@Q?nis l3zԩ#݀ywȊe)y!1뭦&zs*Qc5[oWR@K YbdbxP!逡y:"Xop$?M h{ &7*mgeL`EWY Nuw7o;pN8ANtd$ 5{ީWKRc]+&G8:hcCHØT [ Kxg.yk ~p*DGII %:_fs#2JF<@i(-j ppT^'`IoN]rx]γrRoڙ:)AUwu8hH9~K~tܴ*k9ôd>0=iBMJgrh<6KE ag]QtzC'aǺs? }wdpiY󝵅/,)M#`^_It eDⶶqڝӴ3Xy'%Ӗ(z0Rᩇm[@9IlE}~(@\(QU$8혼)SBa_Bn]%u.IFiSf\Tk<BX zhfsoXbQzyXTGL^w٦njq SgVU[XuByt(Rn`xS4|Ҩ.68jWJ<6"F_/̴C 3u=Q+#$q%|Cs(8E=d;hJ`<$ ~̣P`M)m||hؽBʇN}Xod]_ZTκ^ y9qDܸMyEUESH.ͲNw)~Т۔&sMs1˅ʫ,5tl%l0?l' (0ŕq'+u<(?517IDO4q益 kM`.LlSm{p!z,W }X#\Y( Bt9'BGy& )AKA$XxHwZXA)җUtoFe`-XԿ"ve}ǼjySkz PXY|(cz:P5T‡NJ5c݆rAo&eQXW_-Fߢ&0|W}Q1Q6muAa.bw$K7go߄}1.Tr<߿SF~U֖E2 Dg58A79CexJNK;Zp XEa:1> 7;&R}ͷ<w@hWb~/Sb#[s `=ΚR>*Mh[9MkY=ոKwrٻ.qS޽J+X nQ蛴$Rw$\`4DB9k̟{ sV^w7[δW~Yf!~(A,Mտ,*mY(t}8Vlbyk*齅uOX;'Ȼ; 3e^ J&uʏ fnA&^.4ttnZE]W!bvEF1,\H5giE1yS@OyxЬ:`TiH?굉Z7y ʷc!"ZpxذH@MmݟgYt(刖SWg;?$jUhTy *юf6d`*'B 5eg˘dx c@ % 6O-0}1) 䟬ղl ϲy\VPFwƲ1i(B&mvJ୶fScN`!͉K:;P̉mgEmS7wW_fX&!yfIn.}YJJi%%o Kg"Z`DZ|Wc&~hK<7ANYqšii0~}Ln3YJF?aQ`FP_bbZTԢܮ7MgJG@+{l,[=dT}G?\fkcRaa@~oEV{Hau6&%E/JȔuםxeـhY0A_k==ƼZxHU[C6:[@ h$tHc܀0xo"NJފ]Ha>h%< =ƨǻD{e=[sزxN57*0=gﴉ1c}{RegK (<ٯ osp]M/DEjN#88^XAfh->W g^;2L/9neC$3+\*#܃<ޒY.8Zs1uAƟS!og|vOͯ{,$dys dݾ#~/ 2y?ľGPV !*0$'d{W3pGN7!Y=143?V:Sƥf~<ҷj&q%Wggo&^R\HH'^)O0%9=h<%8t&EmA Ư NDXn=tv iq_%qՆVL$9cXKZptzϬ{}8FPrН/S`iMOlwTʩw`C-)ryF 0.A㺼yyORdArf(g\8zpRE\֎ix6 yZHA#T 7m&j̍HiKtɚ7_u،Ӱ{&**t"YZs Hg5]0:@ې??0_m%xڡCr~{ۮ/Hk9'6Hy/>R{ژi4̆F'iC+sB-ǡhy#gzz C| OPmۍGs=a3BCW\(]7ohX\cV.@-0}6jjȪ|8ؿj8:z-IM=|G'uDB+sw73ẁd9CtHk)`w.È5Ы~`k*-!K`!usvXC^ewi͠:L iˢeۄ쾭Z`'֗֫n#{D는 X$cD+{R0Em~>gm~1$Hnon::+IZGS_xwS\3/J3婏6:]M_'9CΎ]Gp͆4Ψ"ĨןqQMfPzu2` Q>Pm dQ~S=pXh"AyM@NAO/C2Z5АgՌ,ݕo7c%Z W*ӤGikF;Fs!@89`MDıh@n2~iКJ|]KK_eo=.< 5~qU}ox,ݣ28u4q%0Mi/?&9$&h݉#l_f()[$5EeYJ_Ɣ@+U~s(ƙ>q"H/eG@/=_ } ۟#J(m#XfA EqYGC--MTַ @22 +"APARN ͸` u 4ޥ<5Uݴ: b$O2d_i3UTTpd}HJ+ǭFhNi~b!dvQRRx 㚷!n⽂4?AbJ=H_aKaB#vDЙ-lІlI6Eն)[mx>0ւ7Ov |"c>Sl0tF38l)dPD0/gۤm?ѿ:훶:#BӤ?!:tkq|Lt߫FĈ=SL;IG6[pgw MJ %Lzo_+ ٞ#p3jM `y_^F*ImjR>bwlgܟzabH e7Jk S9T0vf} Di*638Y񌚣+a6jNws_F3̨6l`}'%ue(|y+-·|D+ ]fl[DfbY_6sQ4-BuE==n)Үpp3!2&i\)m1^MG|\۲rFA?^#֘rfE_A>>*祽ַr+EE<{DZ0uP5*ʖxsbp3ZF&z)uHxc ; eg +.ܻmg4[#1/ȍ~.kXA"?& z$ eA ?㢝% f }I8|eEd'> #w63ܝ,w&S6 ˑWum1C܍#d,.kWO' KS(Yxs4*:?R=^W9ν<=+^ɷ!uib)Ma@ 3c"KmTU.i' d4=c zf c3A*" R"Vyv`/`in q0[&TzEO?hE,-eu/W`FFڛ[W/^[͖XSh*P>t:'l93ICK*? r2$coXB) pDv9L{g辨٬ۺ;UZAFRT^E>Bz.T'!F%O=0߮=e8s׉@+(7 7AY w¼̙C~P[U~d62$y|kTk끻e"EFĂ1h=mY6܅tͦXA>}"OW4mf&oXD |f)$o`c/+aow`0UWoz`s9.*4<#tJCFٺ˪ҾȒp ON \Ʌ%JLmAݦ:l'\, y=Y0>)Z=q/`Quي[(h즨*~U932ao#GO,|?e!|Fų@u8뾸ݻn/spOW']WJpI]9\AFp$M Yqg2̥5vw[z}7X8n[xُ$e}f$r]8{d3QԾY$ٍ!/<:xc(ntNmJt-^Ԍ^Y8!`2`?A*Ak6b/+{Wf-]gC*=cfvaiL$L$6,9&s8ZݙN3wq.N䗃z|}>P r=d%kOؿY">SOt״Q󖢐;C-#e TLByM'E ؼys.̿(5?³تzAFO^:mduvoj%&'_ND?n1 |]F $Yr?gEOUas4ZO;5D.B{r+׀!6k㲃൑ZGݚ`fDy:(' փå= j \og~vlNs*2[L(WZE+cg۔kn-|UT,>!9Xp̱fm%D}F1㸢?ɰV"nq^@q2f@ WW'g= UmP+FFo\Ja|vaZ)]hnqpgc#:*M(?LpsuGŤQ**Q")t;O,W,AFe Qc3Г9S-\=Stx-!CG}6bSڢ:BMfuߋ`TT҂rqfMSH_U1;p:Af͓HEɊ@ϫ.F茁LC]ܦ5gw12JrrJT;lG%E*SkV=ssDq>[{̸qPfˤ)$/Q4O>nhYGkܟ޺)a|U ^R -Фm3loZ) ־L&ֻ1f颏 +~XQ&XMT4&[IHnEClsҚ]7]9#}[3-W0x|B`U(Z͚F*p,{T"+om։5*d3X_p$zT=kL& R֩kY` 2yLqxXk%P*u 0x$ Z"f2`h|M286U (3aeRNwA-nlDuY\B<-m?)Uo\<Ѿns枂12/E5<*=v8"Ʀr;_0V@Cؘ=:$N*#͍#e7sWa*f.4'Ȧ: ^7) ಳk*yg >WmcEZN"„Fe-֭|>iXtut0N"C.|Egס'&S\SڙTqfwjO4N"2J^9n~IŔ1>x? {҆0IgY&xwӄb;"xIksuX$!nԕpЕdl&"InCih-'É`wQ(zlLl 5V)LXw9uA(E:ejgH*ZLM* D&º;MU%ʂ}L-P4m+b+CF ‹[xl6YP*` ԌIWD7C3ǁ ? gb%33נEgUv]LUueDԾmĩEŋ\ ehFEM x>(a-"OM^q{SoveϕPj3,#b=DGr %HL]jˣsm~2 9Λ) oI/azwRy >] ZT]{FuuILCJ-hLОئ-*RE'ONu}*/rG?L+dC1Cvu4>@M-&Ld_Ph#[nS5 ^w7*tl_+ۂ҇lںK$ﹼSSּ"EJſPځV#1ki.5>*D=0E*0paGvfi"#<9XbQTy9 }ߢ f)WήC͍¡ e@zN06v8uFf =k]}[blXyإ>di,Z\M  ."~c#i,XjG<""[E3ŗ_+N>o8g \cAaaPBσ 0hC?+xu{Gβ#x[H\#sނ=,fn8H2#͙U ( 7ЌS( LV֫;+:gil D>4uU+T}^C`&{Ff lN FRfs^XٜBÞAkx^F v%|w(ISZڈ@D% JȬAyo7~-W0O{9T rlL1Q &^Po7ѽ~O8D1cTZ`@诛L/ښE tYcItTnh}+MgdS%2'dl߄OE$qL*T(u]`@aNum`S E_:)7ǫ{Ͽwm;dͥ6NQg)^k]n۫Ϻ,ճ dtcL |93d=mQo9g%ؒa>C)i9erTi!Z5;J/R2c.Ȍ; "wЧ>2\G:;ɧ V=(4*㹵D|8)h i;6wuyIrJȼ\5x#E ^P_>Kw,4֒W{+ѪL{Fh7bz^T^W+Ɩ[nxE}<;.wcG^WQP`r _-&{lK% k>B_4|$eIW8k^  t4Mޫ.JAO-Ac p%ueJe`O 278ld1 ;SJ(Ĭ 6hڞay(c] hVYtuT`/+ $Z 1[y)M)ޛ K#GY[EԹ+-˂,QCi`7RehF~({RiR&; ,ɳMr:LNR-p7 馔 8`s3zSՉ'h~%GshJ7N V7$Ĥ+3z>!0ADՐ j r=_tlQ3fX}kz>LRpo҃O.zCηfb6@Pd_֊x'KsU?axՋEZ#VigbG;~E-#`\%>ə$ |n.Qm!k`o\'e#duqg\E'F%Þ_r RV]Q JSc<4rUHl] nT d2&%QqK9ì3K]bמ;1>"5,zSv/|qa${:_㕱3)P@Y#O9rJ%~^ԣjF 5ڕZ2[ zyt^?Grr5bcs*&~e}YS*}=u/Y1.}$VQ7 9QvDoR\'Xn+J ȓxy{p{pxyň!Ic]Xxq>py| xu"ǻ(ρSJꬔSnd& P G|Ed֭SЍ{j͢Eyߎ}8k+WiJQX8 лE]t(hPJ+Snla}dWY/X_VCz`ɀrjr ljX*0梢VH;CBb_b#햆j6J 5DŽpO*k_?OM#3LMOaXA^}C0.j^-OMlnjS10QUuU⯓+ S 9Ea1.0L5$&mמ56ҷ|TM&1KgjBBzŠƳl1oTp9ד\-=:DNП{a$?wNd\_~Ŵ26Z~/( cxO[p嶛h=+ocX8={ˈ\zPL' S o:݅i3xI${;Tk>x`N[z+45=ӼP`l.y{-ej *u#gJpYLB:s?I {`ݭëpۧY/#ףoa[⎭E;NՀ?C C.9{mYjNSPÌ=Da։U1? E6j=L!G6"/I=?lIRV, Iʺ,8k%\Dܛo,1] L[a& s l t(M?k–&E2l0EDw gC$0 @6w tѬ (EMj5MvIVr+elFBdv5҈ \`yUQ s-PU)>ˉl,Пdw(^R`q_(yQkHÃWxju"T!DlHB鐍Rj7oaP r=zL×E6lBMMa‡0mٙ 2Ae"j v_TT/12f:<,SWm<,v[@P&d",ml7]5#ƽ4gy[SyH/cD&/ۮ;3о#uYd=Bb=IQs7x+Hr},ߖ8n$n 4jni|2sۅPu#rݓrƶ9f+"^:є_,3RkbĮN`cK:(ٵzsVr8Ew7j+LkK;3Lx>EƆ|:ou >\݌S G8}2XZuXBuD_17FV\aX)4 /]Mp_vLDS95i]ψbGK5[$VL|h&ܲZRE! Kh*b8䔗̗+_lmp @H+IowRZ2S*8d8*|hWdYAn-1xw+<ra, L {1 ϧl!B/n׃%b~?vfYIҦHK{"AI^!t ~a:^ }nlj4&$>;e(e; G$v )O1KIs#Z9[67c_iB*\-a;>'}|Cnj_z)v͔y 8.v)&*T4G*Y zC'm9503xE$뢟[C UҴEH8U)g#D}w2SA?%KrC!/2Yh[|! 5!3p"TĊ%0x<(dQĪd,M "y_U VCajL5")Rjk` ӶVL-7%r/K\Kd$D}E Ixp.BNByr4xvs 0K ݞJhi#0<\OWzpP8E$M K~l&09;F{W.ո%˘$O /oY>v"L@{uTwg{$M ʛ,X0/uķ(wăTe~2y2OJ%G`j/$8A:(Au5W`xkF1T>S5[˄Eg9{ݸo 27Ce@`LbNЙ@%Gc҆:9k 8F"R7C]ۜrMd-tE/2(V''vo;AM-u+P+rf&M7&G LfA:0Z W} U6H,l Dn6W{m1r*᭰p6f@&{!3Z/sp-| $祖%2W0vhʷhFL'h.}V@S(>9ZzBwެ(3ffY mSHDbOb^ز%8YtbLc/))ζ䛅.[C nvKQϖk;2Ydۺ !L1V_B6uY%[g_eU m9UQG73(C3 *Hʺh3$x,K"FDXut*OʺV(VҺJ:{d,StocY ^ ǔ`@g6W[Up:9zV?ۄָ]_ܦBn%D6Z%=?kgbL#z!\_lqM@Ku5>!mݍYVWFnu'y@к?Xj3}&u/ݘσ92(yYjOݖN/a $iք>a hYwn"o{ܦ~քK,UԵI'"*е#I;tczs&k;P~Ԭ Kƺ3jѵx{$)6eS /]X7lrZ]=e eSAsC@0]3"cܞ  O$+˅(Pۂ 4"&^'̯$>k4 f!}[槚Yx჈ѷd]REhh#X@t:>iz?ڽ|'^=qW @Q%D+64}gIMzSـ$`jY;ƈO=1|ު.GBs԰JI,VVTބЫÁNHOی:[IK~Rj_9N<!/dNL?*KS0υz|@‘T T԰% l:Wok̋tLB`Ü1fkc_P:Ü/\uap96Dq+̛*D̪TBaJO(!ü o_ANjW7bZ@LJ2Lu)N+n읋 @vZ)+& Z`5lg21iB |X{{='4 P?8:^Mxd7צ~B_0Ś2d/:o5"ĊTk1#\% wk^,m=GNj^eYz#UzP[}IV\l YxQlQ*eJGqrG򔒞K' &"\RC{ǴaMsz9NI%RR]B_Oۚ}P1u ȴԟ51{]z#i/lUrc0:J %ѵ bOmȝH*>6y9L\_ xL)JLbFd>#>U/ |65;@M&6yȊK: YlN*kRTg!KAqX5"ڍv7Λʥ諔&"gQ%ZIV`S֤2z^iհK<-mzxazLݣOk)S½D/\%l [d{{6MVĆ3G5Ji%ϔv@$Ax sO-/z8z[?JV*uxzrSL'COT&|P[8$8 ,ep@ ``IL ̧_Lv^!UKԽO,!u3Ε=3F!rWZԛ 7{j {)& J`7)ΝR!DD[6d̲UC``AU=5rYVQ*K.!s>S[*%٨rl[E}u&fڿ"[O_~/ɴ0˭wNH6(nZYN3g"Ɯr<H8Wbau `@py2h]`}SB~O@ 9Y#HќAӕ>>Jڼ7e2¾сC_Ejئ,BK[@-PG}6+>JCM$];Y8 fYNzMHb]#k V`--9KJw/9B=m Q[j 9O-jrGOh0ʿyOoVJI,A" cisk}8@Ǜg)嘴l&(qryI. W,҆*Jv^ŕ(h[Q//OwrK[[6&jn®[qt#1x  O(>xDtӹ(:4&'̸ϺӯQy[FZmսb S~h]NKERsR#|##)]"?Vo<&i?ұ(:ZGDDL͏]:]{!.凶N+/##B|֠n>dG ̠a{j:PTiQCugͻusI TnTЍ1X,۰sb aZA<V( "oYC@{`8TF \%V~H_!հI:'%/-jJD-[\I~j%(n 0{D2]F*CesgL2!ޠ-ę=YYοjP_3}Gm~XyFkBk?zef`cOfq}j\Hoid%;FGfW>ߞd.txgp)L͒.ctA!@%A"y`Q-9@lxރFN?i0BK @u֚޼hjd߬1*q>៤v-hʯ2ͰS9v֗T|~(4Vy$DgkqHn|V(ZXpsԤﲇh/^7-N޼-(N}Yp5otKO}B;ɕ@)]ϝk_pkGw[+:nzAMGqO\QxIr w N-%g r6㣔 FN%aR@)komuqv{-gBfmI9UPM 6{ljܵT42#eKC !Wk{2A1@g4Tȶw/;E>d, [ZݔiKn0,ηW>xR沉d:C^oşA\2>UrFU`+=1'KzS~YdS<A glY7tvfO__W)Ǚy8P P{ݟ ] ,O}2%1K)X" dJiuoС.Wr|ѭzZ`Kð u 7bZe%F×Bؕ+\7m䦵!1"yXg ,!sdQ F"I@'0-KSJutEJor[+a󑔕hw`qAN?mMjGlX :efJE"-Xq|@x>-4axy>y:yK GeK>ȉ>oV} {Yjp9kE/phD\>J/L>"T%b U+)l;"]K>ﬣUa޷L#o~Si}bj܇퇽z 5M twm:אo60(.PC%xF jDs1wUH^71( ?c5EݥD("1֓&-Ai$tܮ=ZۀNXXo,wG@z]3QL}rn[XXfr~.0ðXֳ/nkJEٙ^t =ZzFʊx[Q1% a72p[czC@mû ?{ 40tvp׊l$S^5hͷbp^$Q1{*Q? sf}<tr̈́X`4MA)5r>9Oh9 ަ 'd h~)[ wu 3>FUuKyUrc[Y@"sJQf#͢~o:l>Q91eЫ(뀸mQkwI ^* N_=5Lq\00J]hϬ!9zKuC^8^1 n[m} 0JcolbPaR*gޕߠt:N'Y\R cT\7˟>D*XoBʓd9Џ߂FUre"*\zNt6h$Թ'DٲW/x"R7Wo%e+n%WXMH6u8&t:3W"RƖȋRDB5[VqNBԶw{_;#sMoԃnPUc7"*qJ["gvݏ=^h:2թ,[ǣbpKH5ÞtvvNCΡԊCiaCaF2uroQZ #@ 8-r8!"u3AMhY0!KאL} \- Lf^s`k-05Ix&׺AK)*D  $khLLC"j#^;,#ü.F]g„̢pdcFeIS@[>q;I(Ąוl剉.J ;dDv0X x|R-wF-Wga$r މn9Ӕ)OEvyAK'ߦ =0|w>桫wEKH.px<| D$N~$EStזl秭D2"J/Q_ 2keE+aBd8SLrʧNE;U@SI N h}Er&XSdCx/ ͉G~I|e D=YVck_A :ZB\f|g\ݣNi"cP}y_lz-&}e>!*wqX@@qcD?['lf6Y5MPsi1~g*1 >r,!: K7^ Q82N}X(1ʒl+l꬗rcmRץ@s1{a/zm,6.X-ΝC3,7~!Uy4٬59ܓ !^o3dMȏ4/i,d*kXdJgSFR)Jx ^I4p އƴ)'`mj/AgUW~65HgpGʂTdг~uٽ U* 3?zI6Ti ^NF?thKb6C?#9WRnCNY6_!qsxqmPRT؜,߿#\8&4GKA+gxVIqld?՟8- 1cH,K}!n] <R E>PRȺ(3#f2:wFXʘ'EQtwSQ"8M.Q1JDK~J)NqAْ;6?K-y3u@Y2x#ҋPBF]|7 \ű_ xe()cU#mN4ߵ^.*5mz$f.8Pd[`2l^vleg#b ލ,wD_9f ėM~^ yH˕ :#tlωLJa(˥ݢCr48>YFjJȎI:eo|g }BQ40dsRⳄux@R\N CúS<7p:4o}s'&N#N5fw[twR) ex=38g>hnc %3'" 3Aw.(/1/_Ic:V-k-~ΩL}XPj"A4˖LvJžqz{'|,g(w 2 &zUg46Эá\PP!3H'}Bؼ Ypv2[ơ]( ]:t`Aio b=Zڻ-eɚ ^`}BC  T; /8;M)\T1B˨ogD3U FRWĒ'݄D:GĞ:pj M jZ7P:AaUa<[OQ.}pP:ȂY, gfg<3{Z#5Cv*bA&gBg{xMc8]+YU_(ǿl5[XۈXeƩyt:;,r7 ^8b8KS >51q7I.<L2\a'e$%m\ت {ƣm; 3d RmWMx1]LJi$*_#LoEJqSC'@PŰݪw-j&Y`ʎB#ө>F6UJa>Uroj jaOXd;q׫'ƷW S&KGC[oWtn Z! mۅs^#Is-h?' <vn+ J?X3_1g RV3rFJL3ΐI@`ʔl ?3x a39޶YCVpROèvp.|St=+5LJZCFP|>Ѽo$; M'UG@Āq өOz XCJ6nlvpl3.丂_{{3w53$Fb[&ׅ0w"H7r;ӥ&:#K$ FO~20>=R)V#%pd/"g'R[_IF|_~o& yRLrQx hU?}u 웽u(Fn<4. <;g+?[h4ͺ)R~1-XK/MP>uR#|nXƈxzKT4ozDӯbU.!" .FRdH+]yi?kڤ8$@W.)R$STxyfCM<`,O7 `z>>[s1Q?B8s }jԱ@#2u@4[%`Qc3l}y xmG5a:x*Yj]" fm'C@,%OA6= gCr0Da@5Oi\Az2Q 3 P3MCwQ&p&єv]סzSzڟT$ox=$-5o$E<4Fpa^(i,gDn;2^oa¢%Aau( v'zb Mxj?FӔZ)R >ԃʁcֻa vhco#sP∌A xM\_r})I?d ^xoK'zzvNٸ44'mBD Q5!yf σtRK|BI &)oDI#r>^[~_#2e=Źwtj)SRLx;eqKT]dcF ܼ6sۭ0OX_nKrX 0S#`}A(MCFƹMכYoSkJ0i2zA  /_q&f4jrC?\ 4!xMfmN?H衊$Hc.;Wss=*_#9*Ba#c 8 UCքnFB%c@>&4$Е&?cd/#c'7 9RYZkSUl˫uݱħBinDz|:s30XJ4K-J [=I#eq~[U2Klq'u͌i [O ґE"i>A-wF 8+壏JA<_byϠ-;;pI0z ,d[͇}lU.N E;_IȬ ݵ&rTTg;K;I8DPI<:?"OYZClA^ce 5~S_|A -W umM1M PR3x; L\2""gC³GkzwL@5=-iKU?dHes6.Ku)_m]y|u~%K?A|j ':R+$f"2zזk)ZgŠR_ /}-9X KН#? εϰ u41{<Ĭ pA :Z]QSKH$HKV>9{Z0#~/] !?R:FR-MT"^|)W"zyt=kBr+E+iȆ^|7f˜fz?#̷oJ3Nvٿ٫8"hK"uz6͑܉qrr-}PJvr]AVZ3bAI)S5ߤ6.&m+sx'xr;Z=]dq+ݚFL=5cz0=1!PzTbYB*̜?j=Ij0Lˆz :|_}V D-t+=Օc_b9<Ѧ!nMGA38oi'0L.LGv,* Y5{F$Ye,X%! XGk {q\(bD4%spz&$RcaU@lJ\7OlYuվ#=%0 2{*fAy!w @rA $dF!Xy~k>xFD92>oo^EK-(aā::jB*w8r[6t^u91Q6ޕЫ` Q7NJ 䙋E8.^ /φT G$+IC#b;Лֱѿ~4Tz,09d$kkp˫ |hΛ꿚꽳]-7Q Y6؃L:&9yCܒLI2exTԌoj ]\¦`L _>NL.Yd R7Me}tcyMWd*_ ӻ*n7`ƬJ;]@7+o9ۊjRs*z`P!=!fƑEH6uWA4=&{d^YFRNp X  u*58Cq}={; WГO:shveV;u2=KQCwH&Ie f5QK⨦-♁oM g OߟcA[Mwd2HB4%nLcvilPi4X}/1BU/qUqSQ=c=Ȼbu>7W-QՁ)1FtF,3fuR3P bYiZŻlcZn5 U5ٿs).YmrbsY]Eb-qft>&mLBs+<7CV0|=s#P:P׀nX61?Ldpqtp.xF6ꚁ݌8~(xAOyƿFpzՈ=bgMyؐd֑Bj}1D ,5i.2smd-që5wGLFPՑ9؇CW}S3:P |2 +7nMA)=@h_9*ap5́?Gbw[$g\euBwhw^7RFQwr(׏aN\]l.t(@$>R?/S\wb/yՁ,pAWeLri3Gr ?PWJAP巡2pQA/SmCĮ9εM\v>*+Yv!qq,(`7IÒd8oAy_12hvq֏.T|\ėYbH&(:^~ٸ+* Ȍl?>'i 3GS4)-|lvj+em?8NH_w/žE`j!lS H5dz.KE2IjPjPE0P) ~_q^gN=xY؆i ^halj]q"%Dip*hѤ\[Lڍ˪ k7'_Jy@Tne#Y~ DaOR;A*àD?&! py5;`}5nXuOtݴEQjqwFre*l=ROҁ'?g#Pˇ[k&ʬڋlؿ Ah`+zպD-ԥyoP 賡\#V6X+C<ҽmZ'`ƨ-Bl¤Dp+fÀd"ݴ,9议4mA6ן ionc"mu7ge#xz.Uѱux*|WQ6MͼfQ NP' %lݟE8(:w d2&j||v!U5 h v.[O6TD?% OQBH1V4,AF_Gg9`)h!BT0?C֓[ޛ^ w켡BI4bq-RpR-o@R <\$F7 t;{qW]qpn^I)ߪg B_dx%wFveah+n^'4-#Ǭ8,Eyt>6SP +ׁBt~Gr K?K! k&Mo}/q@ݣ d (%oޕtPqX}Xq[G e+mE..l/.iΨ#$MǍsxc#v Ӏ"S]wO WJGʛٵJA\Cw={/tjY9f-,P3<$[M'۹9λ&AFtS0D=\׼ŹIG<_'*fRdޛk)"NI 3KWz:*,J_\C}'v´ؑ1R¾$A}@0-'m4!?Z)ѐKsecQ6H,s,,L4 ĝ,S%e[} 6)]+T %ñf{@&<ՔEx6}u5hE8s<1#kF7mLARmuV [.0Rکᄥoluf{*v]Z 'U }ʺ5 ^숗 Aʦ;wO'90(n2.ЦBrT5]ҽ`۵e`'wNUb(D4M<'{s2~Ńs cA Wz#D]f&5j:wT$G_Ih>s.uD]#gT?K -h*+sG8Al֢(:LWQ[ _-9s -mȦ٦y30LL4SIo/C àP }eBZ8Ie9҆5 9fq^~* w+ Od`y˃~1jPj] FV$D:{Bnݒ  F)eZcpoۧMﶽ"/w{lXIV<0 kD6R`k~Є'㋴&y% &$,Niks,>i`^Ɲ>._(<ǬUvfŎCA*iEǿJٽa:6Gq43HhאyW@A  .dlwdd: -HN(1vЫݙ۞`Ǡ-{bˮ6[0E>2ՕH!Z!/bhZX$ 5`/f~p D_ EVV7Vl'hJ|[\YՑJ=$YxoImJz0LݫoOdsUI$pMFP-V{_'v{w?C(-*LLgEP٬#1sfHRHL=T#Gf6lFa'; [b;* 2 ĥ pH0Zׁ$bj9!ɓ1)Ļx> X-ǶB>3^ #ҊP<;EZGks=yiņhf*v"vX{_Ӛ3lǶ$jv*D\d0=6ߘre~YC(d^g3PՋ MEU #3~' {ʇ>(TD]VGgҋ>6g3&<jYmrc'#y{"|4?2l]d\a4g& 6ߏjr_O@{JWf];ǐ]ƌ#!ٗUJd53<;K׳ldr0VCSPd=#,K(˶݉0~ j$-e.N[[3\5uqP;eL늒>E5}qI!>7)ꌜx;dؔvp&nXfpG8Mm ŝo wu2@f+7ΜH',5j#W\i~Vbܗ~qij{1U@MWijRmE@L W5ilKƶ4`*l0;g Z6#EPkuo2f-5v nb;r^X %RM&D PKThqzh'L:n9mO4{iYٕPx#an0| uR9A"t5FՌ]-^6.\g7o뾵iuf]vG!} y981AF3u.j"_ίP%ŒB>^<&0IÎ48mBM!Dduܗ7_#qpN/'|բ#Q OF_ǻmN;Nr[9Ajb!^FAR1fSY7ωc`ytV.sA<ǩ vt8VhnbXHKI1dzvKUQk0E>s'kǓuX8.;ҏjh'H~>;3hG3Ǯ -G <&pMlXjh[5jPS@ @0yˮ34DtV yRaSMhLIMs Icϑh!sf׈c0ȞZg/aI;^7!$h 5cH ^/MϮR"m5>m=).jH'IY v)^.[5f'@x^ ENWbz  "|zfq)΢^kT }z>i%k~qoMW乎 P3fЖ$- N,"]BXZ16"kЍүT@@@| P4l^l ӭe;St 2LP9X!>(њ%WD|҆_¥BMn:WlwB,gwVwU[/`g~O02٧UaKFC53s2eTN=n*>鮴 f; dQE w.(-;T!%6g+Lmn 8+=xh1>{Zsp8+SZ?ToҏP {ۑLoAx.39ăf`o(\-K=p %Ih<ᇘsE42Y(y{vD?O\*_#,jr1<B_<]"gDϑS 9?*ci5$2xu9[] wQi'h8XPqRWNNq~+=9ixaMM $2/܃d QzB]*fZ猤vd%(#M_$nX@2ْVӝmt1/WgxGz!o[d: [{{X08(mg|X\UNJbhsgJ=c<5 Pɭ&i{Sb/ǍDMx.%]wUfz "qGb.bZyq8֐=M:$cȈ}tgFqі~eKYᚄ) FZJ%Ipf%RܕO@Qj`(1|(!^WjvT QMbJ͸LGd\V=HаT'FurH1m/Vd(kU6-J?n4n´ܒFJΡȯ{[ ;\ng+=&! gK] PDžI h!jcD,L?Y8Ss"0<^ᲅf\s\rFr [dC퀿N5OKiC-E'eF,#')|OHs);RPIi3Cܙ=}gQܠ K !Z2m{%dG00bI?O,)uxdeEA:E]Z/H_yp4Q4J!FC-A]7*gZXdp .UZwo ޹C:1:E* %JgT.朜iMn%%ABKM0:v~.=CGZjBVVK. p \,saVI(}9w|V*Ck,JM:,(-?w"m\bUVO"H+FLρD`A[)"/GP=qyf~h,݊,ӈ6ˤ$R *Qzgn-DWR&*,M4l 9DTy[j>4OeWwPLnBHYӭ ދ x7zmon;|r:ۚ,ctW<#Ap&8z ʿ'd蜡ljQ+}8 c:Y7*J_xwKĄc ~hETv}3_IksF܇*?ǒ|R"<*Or XB8jqFS*55NzJNM(ltE$Q?86=n{tbp)oo5,mNLfl+c4GOI?H1.BS§]-g{0E & Kډg 5+lN k/F+A@&hF)=,Xl^` oݯɧ\ٔ4ӈG4d ~;^XmΌ{HFjrGWI.ݟ.xSlbJJ/# Rkm$UbqY Hc9ditVu ̍r' ~cG *;qH$iJCLǑw %:|~&E}uD2'fν aaeOQ{B˄6,&+ `Yy)XzQ[xmPDԖiνSnK.N̤I@ S=N٣޹[I^WL;+;fn4lw\BY<Zv@`=4 wgz cN鱳Sx:S_A|&U3+ȨOSԦu\_(mOctu P]K)ΣJF9ݜ0ULoiX ;/w//Y9w3~W^s#|b8R0ѻGUNg3~(j:/?v`CG{G\p8co,`Mc@w #Bԛ~YL$ó[7: 6N !֖Ze>rJ| L;:Sd0I7İˣM@E͜mbOzOM.j:ͤv޴mjeF\|6׽Yda5~(yW@Scєw`}KJM ;..^|yјTu?J-d "8hhOD75SjxjR*N쟐 m?_e HOTvNY}|rN!qʎ!6*C:40!MU]#C60,j%dRw9L6=|3ӲmʠP#ĉ=%mQbO[X[{62dxUY{&|RvGI Ո;BL{|[t?SEO0gYNj3eYx#k<R<i8DZ67j6e|97,n}z_SOTά}טsAb?M#PSxdQoWyT2}N"}&Ӡ}/JVԹi; =mqz2®}ޖGW0Dz<21:sVWu=aJo;GF=bEV5 P=h7YMrd'~KS4#1h8DڧF tMlpGȍUZ9 XN& iyb! <'!_c_XaprEcaGP *dq_i?|hu 8"Ctfz>g<åNcD,e@ڥMݯqȚ#l?VGщW`6.myM[wQ,G-:%@cOIޠI9X_ou0;&nQw[ej@?B(fSMÈє=ot$IO "ld7#]u*XeA>zK3~&CKk_VSӚT\NO37v8Y:ۚ9]E^5'sJH5F?qp7 ?TBC)$Ȣ\t_gp[))[ܽ{3&2 4VKbKKJ-2xYX;U!H|oO(m*WcSOr{-~6)036لʠqf(HjAI&RE @}ڑ]i Qp[kz<Ի%gNK3lX 68%.?p6]gݧ 8/#Hѕk?>T1MPJWGj(q̜5lE0ɭӁC`|i)lNhÞ@융o!PyZUL-4'xeL-^(સگIK xw:8m~/z^0,Aq\S/ځx5R6S/{7['*8~UϫgeOKt|,Vh9;Wgc5t8 }(يxqzŊ)y#C{U V iG ޭԟsgU6s»]7W+4`6C|u^\{3Ci]esq&H2I1Pe'ȯ6>QDz~2W'2kwhvt6e.S$B[1Hx wR2 |-@Ck ,K/X0|ӧr? ƙM$}/ \lC+V1nn~/ǥE^q䫇_>ßɾvG ;h!w(*(jJρ0etěeUlSU@/v  6L-}fiabX?gsuY g#Bt2,eCWMlrg,5}j$w!K"_`JonfavZ6l $ KD YH 8mŃ02DzZ )rǶ YZ