sssd-ipa-1.16.0-19.el7_5.8> H HtxHF[ ?*}}}{V 1D8d+ e w%ҚMc }FU:\Ubc341f221d918520ff4e4ec92cf3a38ed530bf5d-?S%[V+F[ ?*}}t/AfI;pbmԦZUPχx J@>>?ݰd   : 7=D   , s |PQQ Q|(89:t=$G,HHIdXpY|\פ]^bرdve{f~lـt٘uٴvwx0yLXݬCsssd-ipa1.16.019.el7_5.8The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[sl7.fnal.gov EScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdKV#\A큤A[[[Y [t[t[~5b3bccdc952da848bbaa129e0f0bdd937eddfd8a097d16a7332554377f51d45973986c057da1c8edfa51ed97c4194ff4d9dd3d1336da40262f5e32d31504f8478ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9034d81ac411f9a21b9452c5f6ee791f86d7297f4e8821bb1eaafacb9958ff336ab952ab1ba3f799873a768b3806664934bd42af8f73aff58fe6bd763ffdb77e5a9rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.0-19.el7_5.8.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.0-19.el7_5.83.0.4-14.6.0-14.0-11.16.0-19.el7_5.81.16.0-19.el7_5.81.16.0-19.el7_5.85.2-1sssd1.10.0-8.beta24.11.3[Y[W[Q[[Z@Z@ZZ_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.0-19.8Jakub Hrozek - 1.16.0-19.7Jakub Hrozek - 1.16.0-19.6Fabiano Fidêncio - 1.16.0-19.5Fabiano Fidêncio - 1.16.0-19.4Fabiano Fidêncio - 1.16.0-19.3Fabiano Fidêncio - 1.16.0-19.2Fabiano Fidêncio - 1.16.0-19.1Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1601360 - SSSD bails out saving desktop profiles in case an invalid profile is found [rhel-7.5.z]- Resolves: rhbz#1596292 - home dir disappear in sssd cache on the IPA master for AD users [rhel-7.5.z]- Resolves: rhbz#1594178 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 [rhel-7.5.z]- Resolves: rhbz#1583746 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process [rhel-7.5.z]- Resolves: rhbz#1580281 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION [rhel-7.5.z]- Resolves: rhbz#1579780 - After updating to RHEL 7.5 failing to clear the sssd cache [rhel-7.5.z]- Resolves: rhbz#1579703 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] [rhel-7.5.z]- Resolves: rhbz#1570527 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash [rhel-7.5.z]- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.0-19.el7_5.81.16.0-19.el7_5.8libsss_ipa.soselinux_childsssd-ipa-1.16.0COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.0//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a26deabe12ad2448e430e09b43386b221ed5c7e9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=549d2bbff5f7ad4b3881bb8a964bb7ec3c074d99, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R R RRRRRRRGRRDR.R=R RR"R#R1R?RAR0R+RR R(RRR/R RRR2RER9RFR7R:R8R6R5R&R'R*R)R%R-R>RRRRR RRRBT9?Qky_!DXJA.90BV݋8 JlfW{VljG[5>$0Ā22oxqj b|%ya,DKCnwrq7`iUáUJޱѨ> js쵸;u' w0#Nc}߱ù[uZ޳I u %^-Q1v^qE%/ " [C{YNsV5,ԒuxNqGLbV 6e$YK܍>VjoWW҉ uUafΙsF \&/t`ӂc AkҚsX|X!q6kSݔ_A ŧ [% l&Bɑ=>ͣԌߵ59yG&x(8lz򔖪giX߸_8I2PR& M#8NK! ^WJ0_=?1`pN1g jbnӆH4_s%䲳+A cJm{!TP*rIW$|tsM!k&@Y_I(m |6ݔ'y ;``n0x㭳Gl c/3~:g[ 1Ġ4xS(z?):ˏצ\5 8Y#2/^T%= B6c0u$iS=N3TBr4pؾ`EiI0B=I#RmUdkK@S:O7Ԟq0/#{"ًpu{mQ֮U*!SomU:_cIOa~!,VKk;qKImn8i(xqSV7Yog\!ècъ/;J vɉ?ȋƓ4旣{IoDY?F8}yJykI,JX_iBt5C'hVX+* kuA3Eh轀Q>-q+tnFl52" ( ~`PJ-3RAbQnvӤP_Hh$ 6Q4k}Ŋ!grm:;RE]wlBKrG+5ˈ=[r~\ ;IP `0 ɂh&=!ۮ/e`X&z6c)PGB %em RIW?#.ՍB476S2슖Qw&FlEET-o%LOV{(W߉ =$xGA)2ó[%02VO3N49<$o># 7ī3sL'l/xƖk軅f7:yfC;{CPZ>!"qU([vd.Nv^#r?`g\ Uv]&_'g]>7Ùrj j>tar<8|37^sc 7abF e7KrKC/X2[A#! ?;]:@KMOV`K,Ch2G؅BQqlyվ `Wm^ G?b~zyi_S.{P}{,rfn%X}#* 켹FXjI~{*f87z'~UQPT[c&"(zTZ+5DoݓR!- O7a.&Rf=O'VS«bPdzn[k6J|{T ~]4YlO/=ZtV6f VUs{|ÐtPnpIy0}/H` McMn(/FpFĮ ,! Dʪ}aAӂ=J>TZjJ]fYK4z∦[Y'GA:yExqA:^(kBG]h=YL*HmW}=px>CZEOAHa*MP}ݰכKY_PvDu`)b6d;z۩CN'R3:1weVD46C<޽nw&i/ S<[;W`sMja^#R=(|׵L.BCvPGk8Q_;:^J,VtfmpwB;gx_<"t?>S_`I0 /"TI}IN2QUpZU/|˿tâlrhHZ]Fè CʱJ/ 쪴3M]9\Gl_6l<>ⴟvT(W*%x &bd\"\"gcl`Sjx n*Wր7BcEϑgPFpaOV Xs{D Jn_Ld;ܖ5˵B)R!…%E$mcÐ+B9jƊ9 '2=WE~(? wx‹bҖ:ps.$zPԢ 0D3vԨڬsh|UqI$j<ۄ}Xk"q>h*Lq):"4?ݲ5=]J`EWϵ:yR'6%` 驗]ɤeY@xcs$sB, ic qO:JR]垣]=r__eexF<3kY^?[FUIIe$;T/݉KAw @Izw)Go hTuN/e޿iFhѧ U;ٳ #[_pK9+8I!{mVNbca& >DO7;U)j7>'NE*.whTP GŒp!n֢ v2'l7/xl l(}Z(##%^:҂֗mQQыDq)1 oI4-P%5n4`4:\B5Y^mv!Cg'Tn.2I-DՇNx>&u. c W Wd zC BMCO' \b~N'KL(>՜TDEPlL i(>](|d`EH _zLFJ ~{)Sjs}U QH?w-wL/*aBo?CcݕHfɹ Gn!͒!m90H0!>-5GLWb̾? ۡS1<{XFD/cB=sH1;П z2N#IWDa7z."ʾ/ȒsfSq>,`j--C9YgQؤG[ Ѱ1rY"SMȺ рx i A徾mu!pQ0 vi03G+Lhusm8eq}-EQ%fĘfTѫ2&\ iMb[#2+Ŀlv5Kl`Qr_nQorUN'Dmb顕ƞ-c֜^,IOmZduU<3.n ^*?h!">SNO/tLP(чhCwl?xᑮl74zr쇦FޕCdžy1KUgEdCDzi;ZQ# ݝWel{dRb|XtG5a_S1a>۫xeZlj+02/΋41UAlvpJr}ÎvN@*f#OTSs+K,&A(|G!=:68izo{'i8VKHy_Dnj*̞VX—%&ĬUEj\vBs"ָ,&)\QIˋHMT8 2¸tG&\xGH:Z SSӽzgN]样xa|W'=Y3h _Ѽo!c\4%2LRԙ /kM77M{g($Éĕ}d&d  YTPr?^(SZ|Tf{/:,/b#R-LF'{U9 ]gFQX$I)kΏ"~.3\]w,deoit1yzEWw"zO=xBf%OCk%񋄕z4jN!t]b ʳЁO, IK^i4\:_tB&3 HH-z[݂D\n3Cmp*|/  aXeʋ9Xv!ޏЕp(*\ʘԥC-n; MxGMB#X L(J&|`(vKWU =tO|K9Bstw ~\5JoN8wAyg ЊDcXCmeDn֋4IpG!&a?2sVMY?JԤ5eަ %O&00:L|MקZ ;ۼU9&~,zgQFyUB+8E\u02,VP Oc~9ϗ:Zʽ1sP4 H GLwu8"P: W7QS-vƑxD+*/뾶Y72{>`?Nфɥ{afyv,^]?jsDF$zQ{6KƋU|U@<\LyZ?FxɻQs T( )Y&5P]{SKfMw~jGtR@rwpGdT|W'1qsY_qUg}.n'Zz zJ8U 0G7IR7iND6DYB&9N8A3$N,W^A{hALE {8N+raFbnx~ /~PѬ4Óm#k0 *dKgHG@= D@.$BI G1 ulhO>q[TNz[ lyi V'gdxO yXh7ԣIX16"!+c]>^顩ʛ u 1KXWgͤicn784Kfz->m7rCkV PB^eP6;˟ikC$O؆l̺k{t_tW.7&t;LK\z ^NgŔA$sN۟0fkWXEzk*Hc}Xfg~gߚ6*ou1=I|lgp?|Y;BYj_Df yU2aM' W\K>9ߐ(8b_ ٷQp,”uĿ@}h/V!{B8X{.$Ǝ Ll>Sg4;}*nu){ê? .JN6R :y7hw77zECţ2ΠJ l^Xfe**TH']  SoMEG5"M4N%#,PIڍ`A0Q@(_CEWqdkLL5½x0xW) ,Nvj HS;uڕH1Tyu-;.l4F6wyj}_k~ykb?h87WCwƀ St.M\ED =a0m)I^rA8y7KKeǨy kWK/EH/1k9ZM0E&k哔<3yr4>qe,/iYLoԇs;\Ց5JKh (=}>X&K(܊y=Z=Lx߰Pc{SQ_ktGn},|}tR d<` _ ~nCk* ϯv/m&Mq9 6 Y;vC 1е dn˖6QZؽ܄.]u'KCOéJ6!^MLymuFPoЖsbЃлl҉)G92 ;=~OJ]~t4-"1rܦΪ>lwWg~ \(q,R= STof O`G`Em0oӾ{! iy;V5!aRHr9>SYe9hcwiZiB R#xY99*MdfPu)顑4^0wp=)~aQ}>˶r*,lHre@*IE!mBDrvfs$eC5mФ=.CuX_RKtY/u9rlųyL8;4Yл2&˿?q9D z)FE8lXyeMS(?Gf%V~9i xU9f{):  ]w92B~ {nCl.9#} Z$"*X|Q֫8CNb0 ׾ZԡC( ۠DX%+̯D+QBMFh+CkI!5ZZȈ*!K'}]s ~?ghZ-B$| EId ݸP3E.p]Ϧ F:1e%d)Ŷ5$tSmzѾ[+/{}!OɊF](Rxt3Z#­IfϘXtv1%(/'NMRPFORrQh+g MTռI,a f^.1,PuS |mevCeKy[|#3 ',WȈɤbH(%IA3)cukr3 Xa Tx7LC -;9^D<9oRpN\;O!KjQG쩆C>1,iokM6,s> LU{T8AuO5P)-gTt vd&5c(tG%~T{ | Sa[PYSv)^ڧL}c b&FJ'Wu_St+ݛZQwm2Wq,+\YMcpwb͋w=6{p+Ui'$Oƴ2n4v~Ws(SZ?ĉy^  !S4j%@Bd~9m4IשyhƣV6#ٚpШ)Pt*kn[zML ; h*>\[qf[[M16P[ Qfv7mxp7ӥ nj-,ÛЯ) jVݘ.Ur%ay,9s[?Eӛ33k#u{!+Ў>v9ja2 ʞ'=?K@U_U,E Tq fZm3U9,Sv=ř{Ȕ<;~F^@0`~oZ'DŞNeȶ{ᦚ3!細l#2O0I:+ >~fx[>wsP_zûo#_icYfO9aŶ2*5ޕR0*VtFi:F X 3fGc5 0Y6_-v>S| 4e$5i'iww8BWvV-;@g^fUdBb2q RCNkcgXC X Pm9? ^[E_mc>k!t}Ss%W:l3# ~%y0֔_b27le'sqɆdci!&VQS1IN5p'^Dg{IdzV|q ?4ojY'퇵&]zᾑUEpj]5V{6\5 -wCIyk+<kUq4l(*/))OZzh~,X{ԗASbBV0ݾS d]#Γ]0-4y%XRssH))E[A"N'4h666jz|`b֗OZ3ՐY6j 0Zm 7Ƶx2!3ox=(JvkPY jb owtN7l̰a!H*eG\ӫSj@qb{i68d#I #H;2!gm%X :[;(츝o+n>DG8σY}eU \<;ߋ3ėWMrj/![&8zZlؓP%FrQ]y|aDR~#XrlKU)zrIrE:ű&dKDNru|b eٛ$l94rგ6~ _PH /CHҥ}#5Νڛm1"8oQiA`>v̭Jصu*_5?畅q{&0u-Oltt7fʥ9BeȢIcݵ}B暍tmN?nՆl R뫄1@4%"{l{M&;@`CZ=Jd9%] 9Ep>ݪ^͇uFDO@)+H\cmeШH_X QP?W׵gzM4Sd*9u8;A#gNJyHq[@BJijuf@Un@ N/}}.ΫnAN]ڥc%s5vbeL|r#u-8Ӎ)e&/}9̩H"O Y޾Q 1!%(VyԭaM1yc51Z ۬`=F@2gt$沗6hZ9L$ ZʦIرNmut>7r%SN:4#@6uUECM uHпS; HvetY6IGņO 7fԭCEJR,~!nIپmI5), (Wi8bEgⒸ_Cs؂W)J' 2tzcL߻ƕ5Z|5Sq5oX^Gi$2C;==A\B)/iQPTyU+70Qս,&&2)_9gZNxOyqc JDVJ=Hy甫3a#?s%)qA VZ9nIcHk\SshEɧª>yj1Rs N {߅oʭn̼6/0lޥ2V;ѩ!_Lj% ҶԤx¤}uՓrعIvE!&rZID3җґ9ǑhiqUF[]Aiw28fg"柆|X!ӎS7qj/HҺ`sm ܳ}I՝Idqst搡N<OsUgJ`ؙ~JixjMi hC8~Sg%weô1e+1\ɀgP|Ҩ xA+5\PPs{mND6P;q[j=/9bn1 . 'WoةP"_:(2;̀1Dy9O76(V([b4F6[i_ q7pH]&2PGiり[QvZsՙi\__3n1uSL3wgTy)e!dE(FBRs}^Tb(ϧ̓YN MWC25%6 4ɡJ??{?ƞe.9|~<¡4DAl>"Ң頶Lz#^SLJ̤O'w١g5tll8n vt=SDsH'xcyZ^ %47úKnFd(Y ^{J&i2b2GŠ1& }!2m>vbtYM)k 䪵N¤["P;sA8)rQm'(`_WXzD. RɕwsR1K\, 1mh\r!!si 5CkiM4Kd7/&Y\=: ."\-@a68B5 `Ibg $Qyn9zTwH7|!I}.F`W,`o部HHnsZf4)GW,s)Hk2 MH. ۟ګ*'{z<ߎ2ư=ݵV=If>6m3.o#5**>tht~bS0 ~ciUTz޺k)TWW̫GY%7[ȰD7/$]0 *{C-ўVZ k_lŽv%ű05Dʹ8w\q¦6vdU7[nM !YN]f£uwo8B#0%Ptq`x" aB0T2OlrYf7oM$G  a5Sp g6Y3&Qz.SSZ, j7&^n{aUgXC1` *02fU ;H~h7`4J ņ)DQ44A3tT~N}cV7fq1ZO Έֈ%!Gn )Q_91ݢGA"JbU261}&;j:8&ysnNtHJ./5Pjw-P.'y%l-Bu-R4]-,2u4.zfdq};r))iD1 mJڤ']| 5lmr}TK:d'a-iRVȴq,02S&̂EnIuM@ԲM9\o:Y+XN|/܈<,#mw,MRK֪Zo#ySQ1RiHa-e8ߘg``ȍ2I,-Zr\5 v'9tZ@N5"Xi</1WkhRl\T8P9XV!՛,ANxqK`.R|gV\̉^ؚ-S.\`k=)A@p&h ¸_FJqn(#9S%Yn`̽75ܟgeT:p!7}+S ű&GzPǫ6ob5xтh" {~4 JKtF)[ IƵ|=~2R9Y έ`(3H$HdBS7`e{l:=?^۪:5X "vinv\&XHI] CFW2$;wAC@yx%E/>@aeڀ9L 5x 2HN/&LУ-(\ 18ygtVxD} Iop_(wM\t;Z+p.;h>Aˎ7D[֔Ji羚6(go BV>VM|LET-N wl|Z~@wIB? ?mC HQX8S*XFD&fZ&Tߔű\ ;M? $^Y݂++jwӤ** (ր (ͱOkE=^T:OMSC*Zk솎Jpiy_k 3y&eZ3QT\`qneRӏX.^na5H.>IC4XPgma%J.kõL擀M~p~UqEwq~=%MC_ġ}4xPmb/RA-Atq]pIq^P<>А <.?`Hm+rE *Dpa.D:/vZlbjQ'qMmF)1p @lQ-ZIky4 a tSn*hqМ8JY@*]שwWz|xu= 4:^+J_ӆRvE_8<`#iHȳ<%rpgIG?I&G!Dy:4!ՌLg*6=t6X_"/#?zϫ7J -J܃ :%(n_`! /.18Aׇ,eyՐO@ )"QJjvAJцJm;s?*։:SYb B_@y[l0UN2s0EfY4c!ˀ\@m%#,oDi7TN1 vrkA;$|}#6aac^}4nt v0۴'gu"xiVlwJh'W* 8$ѻ T/փS5sv5%gHRJG[UF3%f" !G6,JZz37F؜o9myl*ٙBZHen2!&~~$s9ƹ N[KFWT` Iiwc&TW{-eduHN6OҎ&HOr 4%t4*:#OdqUiBؗaoDgw cC}yKha'N"'*(@mf{ jR U4+AlbO!Ú,7d HдsOL铲U[n{M>O(dX[))ۿP_i!R8o ,Zմ7Q=Fb9W*\2'-r"ݪuyC6|mCIEҢO,I82yEY6~`R nuȯ' Γ;{#U`׫ymHr1cb*+^= |k0RC74\*{4ԙaDؑ| D[&XGO)=cm2yz{ ;1M+=In'%\ K.J.f?>kqV=&>X6vB_`K8S@U6E-lj+"!hfsw([ODžGz-e#M\hlozH#V$ݲ|jx/DI-R|0_8GN0' hF!v߽OA+̠eq}[$&ܱ=5i+s/9, ] ~ȭuwTE8(HQ3 e<893UIZ7l SXWk-I> o9n89C/4ӣE3?7~1A")JB/i% Q[ F1/86SX9nx5Ȁ,u2j<,7Z16nݣp: #=0 %G.0(c؆47J uB||Kq+tw=5tTjk~"%pҦ9gK^2iyZp6gӤPɬNcc%@j!9ekYAm2&fk2C.QCvV偈v^ bon8ۋ]~yNب)É$s5&a)"+!^l_ qB;SsV$A݁u1M%lƳԮ@wfYW^J<-L3 Xc•;)3_OCyADGgfeڡE}{i "-aj܌ \oE |,iY:uV~{(V6=fŐIØDʻJhLbHo>ҍKk;R CzeGIDwIgn[x{DKA~MBJ 2;-[@[6N>])%hD8vڄȱ4ܢg]B/S;dυJPsds ̆l# }@ɰCtŕbVt,&i䟴J ;"/A;eToj-1lkN<+nDЕC9nl<Ż[8`wu|Xmˋ˂\PsG#)/Y&6~TjCA*$1k?fJkMK!"}yyJ3pǡPTW=jy1]?Es+#> ɵ|`*uW=QZAI> Kwuprڽ<8C9=,),>eNLFwwJ\-o7g6Lҗl7w=]$d7$į7=ș!8@QGǝVqj!@5ʅ|wA ow(.ApcyohvFpNNi"Bg;(^)k>l0_SytMLwiJ-]Nϩ!֓u9 _I U9;gjb0md 6a|֋}G7 u71-HZπw? .n1^f(Ʈe֘bvRJ} EW&QZX::! +F^xnpqK&3jMZRm" LM_v/3\26)jx: 52(TކyqU7o;QPFL?Vkc` oOAh,sj 5VFJVwF?!HQʈQ9tq~w8Y6qkVBq+h˴`(SSWc{ vd*ٳi*BQ~2宽3/y^k0a߽Ae=DBfqb n&5 >eICMIۯPyD`7~i̱͌j=U@<1Z/ ]fg"md)ެ͌Ϯ&=uT\(oR<]6.K `JdΝ5cJmyf9~8i!޵s\7֘އsio,lvt?,$[2#l\eOyT E%Ki 5OniBqԇAa.#ڔ؎pQ<SJ &E})y#,EX,]Jg zZvV7W-X`k[RX͚4eJ Հ tCHNZd{zDw\7$̚} ;7"=Ҟ5!Dt+匋\ђ^X2{DK^;]-G W+h@&Y ^1&ӎ.y="ZF,i?h7WpO8x8ŋo3`6PZ}+ .}3 G{T%?GPʙ5FIԁj:XGH'>O(GW r%gHp!ٗY_T Н n5,961r`} `;/ Vi\7mfpTlZ` ce:LV:މԅduF#1arH ($g4u۬R{Rjը$fOɣo5,=l#'m+Gvzۑk71}1 :I!Qv 9|ʽR0Pg; ޅu0\64JY$]lQEfjoĝ^A ٣wUq #ȎNvΙb@m@E|$;[X_ i5D_;d%-Tkij1bRݨٍ%ӣPfpo+IYxHD=(N/2;tcK9A>\{o+Yuݏy0\nRcl<]:^0 vqzo(2Id dqQkWvi*Rd!2H7@3< =t:# M &vK4kт3S}M:,I"+zN)Э^gIk*ˁt=w_@7mv,X>D7ow`ܗ;įOL4p#Kv7#@b{ oN-,&_%_ɏ+Е ᫤ќ)X%/yTLmuk)#R1fX-.B_LyckG>QY'8_ 9lq< yγyvK9qjt:<{zWD\Fwa,=`(rZ1 8gv s 32ތߢz4SbT; WGX]{/9C67cJNݏ% vPiRbJqOZ}=8J% <ygzֵ@D1'M #j\)z+7H BMۥ sUG!9cS+;cŹPCE#H'^y_摛wKrxY%P>Иc }a)6[  r*v>$[k(zH|+uf/AJ~i""FQMLV8@89p}mAIz7/L7cُ?33_(z#jڤ?høCXy:RwDc>RhpJ /uWy]3iZ RB- F]#f߹߹2^zCZM%k8 yEÆ?-1;pW}BKs_L8C.p=oLFfбʷiu͋ÕD^SJjᔫnR%T^;2UJO#0rif&=OA~͑MLkZRe %de뱼P7>KU3ϴG/6Mh%WZ2B#$;,yvZ%naltNDbFDIK'O\sC<@F( rbwV"gFv.Fߙ+"6dzS3n}]e0%w]%L!IwhG)\BI~ࣲ:?mY":`hn'5x.L%/%K%d(YO|4(林!}a^ѓƑ_κ:eD]r姶Ƅ%@?/}_ oZGo]HƊ7|(/19+ya*;a<@RoӡMQM.١PpŶ5jyTqĘQuG5PQw!|7m-8 Ah-^ztq]55?cF^(7䡽~7γG BQ=<X}TY(&d򪥃 4$ "vWea<AaE' ufAXô\5//>ҹg#xӝw|2'% DDj2T+Žޥ^ C)|?.]:XiK15 YKzVRu8 ZD%5L)"i5`l~z)mGM8ό<ʧlY\ 8ڕ?7$1E- ShEg ,2Կ.2vdЋMV!ňP}u{b`^94$am{/26VekД@h˕a(Z<j"6>u# #3#ƣtS](*3DzCvDus-&U:`(of΅%k h MB4_i ]L洸]D`3xv T"ԢkºUXq<"yQs; i Pn1!hӚoG$\` )El#nW %>JI9o {#2O,bPi7;g G]'Ѱ 4;`lW+ w5"~ѿ.2 != 9dY59DBxFDfag!Acvǵ~4DeMKvI\ғؠCo')au4$c L V]S-V;g]~֖aJnxVjgqkPfgzbye|'=!)fӨ7 /3pRݞ(p5S7{`Wq[L&|~v;)̩2e?NW d-Xf~! gmzC5plZzIYe\[I"ow ӹlgno#A+,[vez0 BEJqUXCfN&ǩ&byU%l0hDKäs n=K-LS.CW\ZREvAvGYɝ.n4&3$"zQtVaXgvi!E3$n cU;x1@vv[|I%kp7ݍ&MӁ K9ߡP^R)K,#ZrSC>*SK@T\P-E,7K:)T:âkqTQQאYqAy_)Ӊh遬C+ \U*MMmW՚Q/7Ի y9椚% ޙ"imPh[_og{H)VhYQs1E° BfoGf: 2D"xHYOzeڇYg)e5·2#Q'c{,MRI=/tǛ0w2N)BR^n"(ָm}yGrčqiCþ2!5loڳ] Qp[\-54Qhcϝ 8Q=<جG`쾰lǿ*ud298  _</At8K":~;1rYmnku,)}Hù<\@/0~ܧ$:+rt9*pb!qlT7&?Vbz^Z O.s=]J+vB8$?q)o7jERLP j 3SZ!u~V+Qy&hd>%!{_KRSiJqE$HޞMGK؊^E Izy;9j5JH@)$F( "i:^ \ JqD9IaKvqe-$8sL;.8 !?s|Y)wqMwD$7u&C{!nK'{[ 8iALW:ŐO&rs^R N& 2+K'x~R ?˨䶺!FL\RQ|}g/Ff2qZsd_j/hc^ RѝϿ~?Ռ8  Zu)q&5Lacr[~j:HGvJ^4@X qt&j9ɌX >hsPx;VBb:JvI*P򙽙z]%V$psY^K&e36mh9"j!Ih (?)It /C:S4_ ӏꜼt%rF=hkQE!r?rR,/ɱh9o3*EVk/Ms~#sÄaH_ۦΚ+/7c^f/W,%96Qa1x_rc@.ǑnڭGᾟG%,05d_2x#ŪNS5'.Uߪe&αy"|aQnpdt /M 'N|"7rkE|dH,wD )u.n*f3<*֪^*㕬eCfsw-Jx99h 'xh5 am`z ab&GC/w2 fy+rwj iNJgfO7ɂfr^Orݱ%l!&~dCr TAVD!4 omƇX(2E?d>̎<+qNE|qlHڣrLH8g۲;R]IE׆fy"uڢME&KnQp8^3Fڕ0@1_QŎBia)!I isK$1|,ۢuė,5rx>s]mU3YH3Tb֌V~WkX}Qx߽pKSLZqfv_m륒NmԏP*>*пB~lP!23YNg6J#uNJ-NaFAFgdY$g<\MĻq!t L~ MLSB4$]p}| T^NYa3EȞ\yC3[\k@]pKx}S- Th΀p+Υ W~$-HZa1Ǥ=Q .]b G)usbA_yDGcDld3F JH8:}! M_Bg x1f{aN\mr8WDm10h"4ekjDP0=bHq=yxwhy2ۖǿ%I~UF,VbJǖR)A,yd/aO9 d|_3\^ZHyL'59RWxhyYZ3Ҍ]ұ#Ot"~d7'^Ж hS*~ f8aX>MiqXk XPN'0"PIf5"xDn^{GWa8:0?z:S,Nޕ3@\=W6A9[pIz77"}-W4vS$eLxSp8Qk4) @J*t{zzw5/U*G3k#q);8*# W}$_*:օX^`?TE'( :my![Cmߋ-^b-p,4gFceMGwlkMHh܍WtbX M.9B_$ (L Zdh66Ve9X_1bUq?8@]^Bz ݕEnBeTYx'EC0JOEg҆`6scvepJ/ `M5sUOK (K{JVf*3FODE~/ʵt+scV/ʡb6Y-06dlur\qTTqgJ5,(7aO3S9|:E k|F_ ]Gfu>y{r՚jyZ\`-휦'lfYG5[-)}JU&$NIWJ2K?R=y͞*)ck;7a %p3;uo4UUwcA"~aA@ j{FZFWOq*UQ`1+t<^p5K%vltyNY}jŃ˿p5ޤLk3 -WT}*ܸ/D`lT4LE8eFB_ѢQzoE yzsijqZڙfv %a"x]Ւ1>Hfԟ`՝pGkep,j{V>fl~_a4pS֤j }=lJǶZeȯ4 iw!.^/q~ PP¢mI EԎ1p\xSڑ1ci#SP@OP!GfH̪6d4&<@PRqO./e|JPLa8X!9s%ojNJ9'>l8f6uyd'}>/.'ߋoZ$ѯ]#06ohrGbH ǞwJ$H(8䇬.L;~0|@6Xo-n&N:C,"%BIX$g?wTt=إ3L*&{¦\}0m6U5.ͪnL)"xp\/mo`F&<Td1ΖBR۞V-}\ft;-,X~@Vݨ ` P ʲ_ƺy2eŞ3r!&o{M&ew=ڤkeKɒ d} =YJ%,`YFGQb*ݬ䆈" 9VN%CRT=/{7B-OCLJ_5183>}ue ˮi!v߲1_YCT@c>@5z$l|3I'nKO2|ƗmΥ [読%L m`=f{BgYܖ[ > tZ "E{@6UQ/C&e=R$js+ w]s7ui@R+sWw)l>Aj;`tuox9A2"m/>e)yBvgvaKxb>~k ow- HPȵӏ"k*l DvtNl1./%8jIFKDogݣ0vW nKՇu/no{Avw›UoB RxⲠM3qUGʫF=U~q BΚ/oEX'0n2[ xhpdFCP-(9:*%.f[0ns@2iG.!4 -i4]'y: |tN\xxy! żXRR]KwٿX\!Ϛߔj nǏȶn0g-j[TnQsY~ۭ#~_oOˌ:j7eɌ2ůգ5R(0ɫyBTX3]i6H$]ZG$f0U+\V*M3<vL:$ adg&uymƣmBD)"eL8R~^Z˽fY(}*jw Xy!̰7,āe7&UߕuOvL]jo| R o .r;O3#S(s'igxJ( q5OwU6sLܶ}V T F`)“dgU~EGzcxO H .c/B]\뢤)g '9Iw}Cl|"jIP зdT~5.5 ~Nn/,M|HULWg#%-uVx,?o%WHW4h< GB$vGO OM֕)HrU pJ<z [#Q+)0V('/#FeTHqf z,vs*Ie~12UV{o(u)]:اU2yMJB)*0I %$yuA8% ?_ 7"g-١B_As^ȉwMq?˭% ^*9@ |H2tF_ ۂvpl=viؕ?ΜQ߳- ֵ|ߕk242\g"z$w+ɛae:c6+ FB_.{jDyyT*Hg2IM/N0gΩK\>Tt3 &_z EPEzZg ÞXb*fA1Q+z_ K*\~~p9:n0&P`%5(\jzA>%&D<-b C _Vp gF`D叞ai0LR9Ozl2KKP$}K6I,;:J6iݭmөJ]jڥQt? JKNat[pwV"ޗy]@֞i{z6UҹIY0O9fȕ Ct59e$He:VD4c`/ʳŁl6J/ڔ0Rq*wUm'ޯ]Y=w}റyԠKyVc\d l$iyE_(LgwPUhȊuIj6Ĭqϱ*|.N[/3 8XY( ]y.BaU`gN8x4[Td2r',Uj+<-R/}cP a:,ef mKO )K, uLTȰ'D;#Rvh5~'C?<*E*63rK˯[5i"`ޱ._r.8r%1c)x$k+N[wpP޼$ÎWvL-fZ1sb`J ׏Eq&yW-r!JnVF\{7M;WQq| ԩ4ڲ|ؐ\p3&-Bm 9*;%Q.m."Z>\K=feHRp^M]@ϛT W\=fjVPND_nץ-f'QiM"Ľl HXɼ\4>Ps|s(x4 fT+P2#[hL~OM_+a(ojͪVHrEo_<\5ZB$aHW<53 7 Zv*wnx\@ %yՆ;}zt08CNӢ?n;~(GZ38{Һq&stG<$;k]!|Ca}-ǰZ~O#Z3=6&tesוaD N DuS?46CZGT0f@jD)8E\4+2Q78%p8D:ps/^.8~ zV68Y{wJ;K( D 譅+ AR)`m?Dl %D]#Vej,P~_3pm쁳SC_0}.}&ZN{1oce@ [K?-b<l!>XXzXfVMN]ׄ"Ȑڻf+9 W^7%uZwn c-{ ű:h; \%}i\43 k~vIC=>%ƺ<]xѿbg8|\B\ 2&+-.J̤ xXcT;vFS/p)O!#S""ظu*47qӪzZixS7ɠ}+\c^~5J*]p_JqaqRQUR asIyLƩf]2M&Npi͗! Ihj> Ԓpf#~"n0Me5)&.=Jr`3493M*_]Ĕ8|}q\NNe7akXAh:嫜fͰvspb(|~ZH sY-<9Y*yLps cG]:j1( .E ~ݼ>m> !΄Gdvr >]P%5ɣV I%gIu! _B !i˕ X3@:ӚpN,2.Ѡ _/,Dǥag:!)t{/Y{4R1xc_(jڭjucD.֑j(5eGMwj1l.g /Edbwo,QUl]:8B5^6視u/P@ ٻ" &IЉM.2}?S'|oDIT $^:_ D؁(ḄRqWKE0^qCwqV *ZI3\$gS7&~^B낀uXM֤MpGmk؇Q:,ՠVAmL'-5S?ށ0\WZ~e \ml npg"*]XācJBnmFOJzi™_yR]ov=V6mbʪ)@M H=_PEĤ6<ǒ O)11w tU5{F;oD4\+&;~%LBM|򹰔=!xJC1:{\Ԅ eT.@:xwRD=%4JĜ'<ط}EzWN9؝H\ԯ np>AÐ) kM\춞J1?7BV ͽ$r%AWfo$;LK`,ru}u\ `6 D%: ǔ Qx|ޤN ?-x؂/jוaaW&}2gu _[3Y6 ɺf15cCB_RMȭ{'f.m/mV) {㦻O}j5ߞ7RZ:*;~օ7Ǿr KkcMhds0sYTA_Cw^P$6j`hMm3㜈7fE6 DL5Hod4O iAv4=EIjr(>eE#v=~5;%l7g_='J4 y;^MvT)u W {fӕ7ξvcJL4 ÄkU6VUF'ya{ %@%L<1qՆ/M٩-;0h gf*EtEJXd !;O\o|ԔDjT&<C˃H=S^{Gtt7&cz4M#3C9Q%h:`lb>huC|6ӰE7>R?Nۆ٩(iQ#4ӖBhW`6,p 'f,}/J+FV@0SYhixkGԁ)zݥuD&>U# DǞ&0svj3KG{eȼPmV;"m[=nFW*(0B۽5M#A;@(i4R}Th]܈?=oʛŸ՗YJj^ &ùnvɋ Di&ȪPYwsh4o/#JQOaԦ]@]*"8AC(YUL^8*l fx~2B7&s)W.817^'uEV ~6}Ugc5B8>yzH;t ҐkB!?Nj[PȠs$~4@%2v L)靏~ɼaI~W>Xne3Ƶ]tP)T%GV.n8w Na, _SCn`H[E@ru7AS%5q}P-nv/N;_'` > \]DAd5BC\ .bT$r|Od%0Np+*[ sUpƝZay(9v[LD'GVvf"XHOn#MV.]/͒u-g*jUwб%{}c]w8I?Q7:TC`T[2ӦB10O'Iwy-Qi8PF1b9vy8!,D\1F& C υ2B7V$& {H{7j|ٰv6U\$/'sDEh  q=3D=XerL{h9\>$wJ^78vdJ }=1PY%pv|*֨4awku\m*7t ZcĮ!;_k{;l3VPRU|u) i",ndfG @ygح}ټK. WIq²MaH*Njk͒s=s;^ ]VZ?͙CPfwOmv0wO Qp#lM"t C2}pN"ڒtS$; T$ 1~Ubg8<GH+עjy(ްN" t~Av9BHwooF[uvT'LeqS3k)+t’wWTW % ?h$qNX5rZ3_U%q$A?LS%JDz}\.Mr6 o_t_ Tim2Z6sVz1͢_,oΓÝCS$ CO.SpOJQM‰ qQsl9D)񯦆KGp\G'-R$l1=s Z*'j) 9y/q*cC{֩@*b5P q7G[ ؃9L$ n fԊmP5dÌ:g`J.Wb vgߧkzB 9  Bhy^ 7;4ю?y 1=.Խ5I(deDyxEFO_fZ@iڝvon7#һ1>&K  3{GKtQKjE!JV 7hqMJ>E~6[s{w#$`Jܖ RK10&x20(p tm@$qMw1pI ixS,̎/$TޑSEbs8̷S M_JEG~F-֋QZA_ouSSy:/#NfZM Wa䏤Tc2ΫxB@iȕzt-||}7};\tQ%62ʯ.|D{pґMrc#uMw$@̛n2;}?p.`w嗭hB2=$59] qjJ+*<6Fw%N^K]?W[ LH$aSz3IahV_uZZA!{PUrdtƵDX61TD>Zxk,H -E˚^ 3}6\:=!J^D ur* t f`Q: 8|b}Hf]Cͯ/!_G6*G2?{=\F];LJvWmFQK\D1x0m >ؠ!wp!qEx5_][ʌ7{ o]= H-..\?+c"tNM:w8*|ԭ9iu5O-`ZnGZAGԗ=+c?N_< sY;cۉZKr/g@jwxP=0g1m %U6@kr@Tρ"wU}K}pȷi+Ȍsa뜓@ڨ$v'R"wg>QPONBq~Sݧ #Q?~)c_'I6 hCϧI;z@q3bRr2+/joϤCR7MV㤍Ǹ j"i} `ji,}T@0 c])x;eam#]G&ܴكJ*EJ;$O7,O/ /##:dz K0_5nr<6ҼKӺl 'rʮ.[юb duf! ,[uD“'>3t%gY0P6رhZaU`Y"CS1 Vv'}9}EWŸ[dR/XFZ`9}Ք! 9C!C}D+nYNč0P&`TF5PێT/w+0Ҽtb pb+j&Kif$C:ܡ@F0լ6LV$>K2-'25S>?1lG`-dGWYcd>W0@RgU<Ϥ˙0ث#ZL=m gR =GMtm6*dڔ]bF:N;pFma';62LШkxYU'y@55qY5e/ǨLaFqc*gʁw]D } 遠ܾ3GKE ddX$4tIa1+ u| Y \:a" F<kal4Hwyc)%t]T.!ZW^'?SIȱ$b8ݴG6G%3 ;Unjt}/$w6rY?B"LXh#:iiը2=I2Xk^&`)==T)D ( 1~g.Re:q6ZU;]Y6Fmor헝_uhpzt(,țYw9u{LтlNw ׮ωZPݗ\EliBW dϘTLY0A{7 I ìoJ,ns㫑YD7Hs5ٟMn3zE-@sX5(םD "@\Iy5U?g8U'Ԧ9c$k]j2Iw& &aHќ)S)SD끴2 &ޒ5,UB a̜ySDdD!,O{, 'h Ѥ jЍWy1\hVN#%@Lb2g\7Xm>@B.Ogzο"^ܓwg3̚;@+wϧ̗:qKi . \R@f>*I"9rGpyBm2<@Sn4ċGU% kz!)S ny r9_4,BUjoZ+_QSAgEB|/'nZ7c0Nv+ 󐍸ŠIq *]auw;ʡ`ݼk_@[t|K3RDO{d#‡k8?fU(Bj0>EXH: Ńp&j׾jw6~s$]{c1uyp"U 7H;~pPL<{ֻUQ_[S&zIR7gӿa_dͳbW7==Z *HW0RfJ\P{6#B1r.dv8'lёMdվ}*9;M[.pXH/w [LruH8ld5uz? [cQ 5Il:\H[٢PPWjC@^Q @4n a /ЅJU)1>nĆd|~F3ٝa7MfeLNed)Z虇Ei&rH1K#A1lt8<;Y(wO&p[`8@Iwv*.IJ 5%P6(pjp)RQsz9,ILJs^7';rr{+%MԘ68iV񭴍|۳,M7bRJMdQj2ai6gPIcO33gU|R:DPߴ՝uJD Uѯ9FyrvzF"BEڴwI Rd0/Zn뜘|aGA(Ƶ\aIx6&qssG+o|:r>:;j[bqؾ| Qs 矹.\iޖX]34g$:D}W`!i-_GC,`ؿ_O> lr`'uJxЛ GvikD=@覺bO٫f5 }prh+oR88|ȿܤ;}!MNmM~jq ^; Q>s3k 8_Sk?.@p݉G_7_ `QCFjBU<m|t*e䳉R_Vy XvvAido2W~kͥJh]uH`g@ Zbb߉Lt-iTZ8!h&jTz7Nn1tl_\.B2/= l-UH}㮻J'(m1mrWD7`DZ[L7\ҔfS>ٲ72=3Hv`?#aiK4hyG^k,.7"8^s=?=GY1VsĜum$/xQt/xײL=>G6tbHZ*(s-~ޯ&\ЩE850,5 lɮĥLm -w ea O+.',^Lq<g۱@8'̼܏Gvi=^=%gqe+A֬`̕-С4̘兞DNijе"M9mhH+!S!pвݷюQcPY~6N‹dU44X!X.GȨmZ/`翤epmEj!+mݥÓo. kEB4ؿT&[^=Ɍ$0TKjok4Ŧ CeaG~gCU#NR;׼c..+=-oF@껯{~Gs)@Tx%*tEv6a({i dNtH|.tɐaJ54,> ڌMOC(\dL 1 LA Bxxcsڏgb). ZZ<͸!"LL~8J:~L:$gd`٘WX£Al h^|Rsx^˘-t2Z$Ԉ7ƌB].\)bR`j\XJ63^xR"(HWJSbIAeiY9A@][@9ͺJ3BebV.EY+x[Ǿe+S&zfj @ZT"+㣫-Daı$>Tik& P˝=I&LZ N7ɿra<xgxY:GĀIr7ƃ+)ߌptFa}о. /J` rݟp>b"OG}.ïqeYou$[^/#IY=DpUtu󘵥Ʋ›K]HY^MS5:79p)fKv:&Ю"4{7~n0#@V>iJ(bT,"iOnmZn=]ỷadXS[gffLć攛!ͮ8VMr//l$HCA`,:*ytJaH"1{I"xhӋ+^LfI95`#Kpzp Ӥfd`[]nJ |1K,!/NB=xl,WY7!ohII ̄Dھ:=x*4#10t7qU V+AsxET 8|`FO}[?IWp;P&Tۚ=t]b5B3*UAQt*내UTScژDtsq¸ Eq1 S`ڽ7Ph:X||89\)͐;8ʡ'[gi%lABۛ=E 0کT)7!X_VP;x~*R9*4osaf}aCػ.QӱqCH[(/z]% Mrc0)aLzq:ܢ }NrZnѾ|dc09C,"5RJΖ0ٶ/15_Ⲹtb!t?Ƕh.=+V|)=>˴J(|gFlp$!.0N"XHyBCE옒h6SV?p,!4 i+L\y P/Kt[T=?"|sU*H \_kijWJwvn~|;eNR.]ޅj[ʈ'O%վA,KMqATb'M6OF[KI_o]^͔'35 + WBݷӽ?tл_c$޾f~q Z}W(cN<7;Ao6A/x,ZIT 5-Jvv_KQizνl]=XF^漅cTl9V_+%I΅=mýV9YSI\>E ..<'ςϗ ,{7ǧ7n+GF,,duc@:/l%O#懟g-|`OuCp4ۿ-TfKFuZf*+4 +_Ƴݷ#TJ>cC3 =hoKNյ<S//.sg8Mja% O2@pD1t oBl?uC gk+JZ 6u.\ O#p~@vk%HK@d2kU›kj~rpQPr(Ծtɮh2'D~Q_N2=ClnrK1&7PLP[I#~zOFT|9!fZzX㵷gWKv)~  SմbQ[\BftNU}ys<--E0ĥ/QM,RnseZ(~me=XRҷٺ S5DZ>UO=9h;5QWB5i~c-0LIg:>L>dkx0خtj0Mn=AS-H=G}ٺR*UPN$Rr e˳W.E,"gBso:~3yW wEZv3iK΃:0+hY_Jqj ԬNYz}O:1T eϷbm$;ǀUkH1dM > G a"k4Vao/eEV_8n(d5LBٞW@$sVtt9}Xx迀SB}_ڂVpb72%sˊ vO3ɾnϩ?GM 6Y緲-<;093 u{K"H-O1yϧϛd܅A0CVo\jW-/t}˿h[3\1u"- `M#'-oxMa%Z/|%P rh/\0Iɂٌ~|x04=|*@Wy>i٪Pc(,YYk$$nShe9-Q߮,gbK 9oFnO/Y55Gm+ YmtH8h $rhd>-o-S¯G.} \^~뼜q>jB%.9z*+ar^rܡSլaぇ&\l 3EjYĴ2tOy?A4;Ųg_TAL泀:U5z_UyESa5R$5"qMcSn= f!2)dm,K*GK&pn_ h% C#MrA]A  vtGUMņ'S=FA:WU&o}G191K5k cz(/y䤅nAiT5!sҲ4XR2+D[T!aPniZz#H6c8P8~YK|MʁeS>Xd.TnՎgKПiLg\uÈq}EJN@/8#h6s 4 Ù/yGt&]" 6/02lZt#"'t] J8iÄ+cuSNM/fl>m w][`&ꂑ$y+{x' /\?w]@% QzУϚa‡%d4! ?*kJLRa/@.V\!-*  Zܫo6Մ;5~a*?!V)VSnKce@kAdQY!x[ I0(ՔXsu"x]wf'OHyc^iLԹOR'ⲌFX`p?m9))4Ț-WXkUpknpN1NA2VIo.l* t# S}2h θN3=y'se9'lդ*4Բa5Ep|u'D#:'U)2wbaIԽ f>{WrV>C]\ȴCft)E6< {`ީѸއCzJE4%;OW ϡ3y:iu{XņI[{$NwNԁd/% VXfsfDp($zCdiUxBDimgI'-im:g`Ě0c $.Z mjs%?+烔J)RGto8wsdLz^5 36GVԲXq1_Ku3;X޻^ I5`²<)OQŌV},އ &G$gpVUǂ`՝=D(wYf+6 1^Xx~FwiK {!;6}mdg:KG@Xm ă`.,pM#ٰk1D6E\bU#^i Ey /Gyw,m$УK3MkoVu.KF&? p( "s7g٩=ip ydgjoE w;.id IOAEw 9\KCe13p݆ljq&f1X>/& cpv VPF,؎!IURzJ@Dg8Gĉz.wY+D. (9<:>--!CJ u<*H@}^nTxMC1M;N,ữ ̒DnS1'^ޞd΀seW!&׾󷣧G`p/X77%iqS-]F NN^<.:8WJmmea2X6imY <=8xgܙzmD+L~OgCEabN㬉/hkX:|3N"pn&9i9DϗSofۓ-R^nGHy%xL R łҿֹf|@Rݴ rrAT>fgoȜe)WXF4 7*B|}j*yBF՟CZW6"\7 hndTӣhT2a(b:kZ7Y˰:͹uMF Ph؞tCn9Hi hoL_C8ƀ]p(Mq*qn r)eV'.Y1fO 6x+'%ۓ9CGiF;|ar _/6i\MM#I fD1$o]<ؾ]-Hb'Yoː DZر _࿄/;H[heɗa)hcxݣ!c Gqk Uyݺ*rx *ǟ< }t@hhxaX}+SgҿKڹ搄u2gTe516l9XTbz02'&M83uYG=<c[W$程DF搔f/tCd3WFbK2aIƣ{ j4rl땲;j0 eb9]V-x?AcXi #` n)Kb\V7+읗W HNGe {WLI C!j1-q=!(#J*,cFHdґɜOۊqr, c 'Y $ >-d u8op]TA@.=2FZy4"Խ,Kd늮90 5~djԕMlӽlkLUr;{Rv|.^BzzʅPΘ쏨1\X-cˤYD>a@hs42{PdU$!hSkT|eԠ`֬llM3ծ@X[/CGPcғkɘ:tS z{OVuQMΑ3^~TCcFs"LG1JKGkl8"?W)8 N236[{)c^ݮPM^fBԍ?>icA{*v֌4D3)f+d CěP1O|߾Z0\O`# ؠ ׸;>D rq' {{ru+ oo(W@av@(P;p"J}Մ Kjm $]8j>fǩOXs3,oP258kˀU;+G->h9q F'`|2&wҸSLag >: V.*dK`{n8 ta њbx5ɩt.oQxt  wn=>)i0k-2N?5'յ<ͺLyAmRk׉ߥ,!# 4 =AvaJ6>|-gJPޚ Rno3ym-G$-%)?Rn(ӱ q,DgYj٪v gWi:%lFdC I `?w8 3; xe T5sJSN34;,vM~;VKJ_Uň7Elmνַ&z< Vn@Ƹ6>"$2qEJ pnH3Ajd@]0!vK1`48gZzय़CuwUdGr[Gf?맔Y(' 'T//{SK} Bٽ2WKʥ|d.]Glj'2VeJgB&I>ʀ5kh"}rJWܠ{CQCPBO|1@n7lgADA˙Zm@"ȁ/(fc[)OpLoҲ!MdI< _PBFki8I?u_x,;ZFHvb"[UbpPU<LE/sti֝/e9Q_0V/do15}@G#MK=CD8x]_ւYl{+l^{ߴSu|<\bW=3@p>zɕ_Y߿4Dm[]tF㸩SSUAiȎω<;<[VU5 WEj*; 3:㈭,FN3?=SAX v0#N]̚6U.C* h^ju2+wyyHsU h͖!n1F`oOEҺ70 :)oK gífk s讂Ki 9}c儔8/K0~Bq`K aJhN\CW J4])I>oɿN0\ףUV2?=#%E{W' f,Hb,V]}Ej˲ EB5vlWDum[XEt`_qeC)%A2Тm[oRݵ 0U^x5x8onwKA9-57eG ĵZ>~yd~id! IM++'L&ݒuV%||o@ݣ;|H83A 6H6` 9Q6!|#{\T~+͓h UCa.G7@#=1Y#;N|dH!GM^yBċz//.w {Ŷcy|ITWg@'/Lu#6گb Q!ZPQgl-?ۨ W.8h\>8E:|xaz'GS̿[̕1[oFN{מ ܇e#{:K9?ng0OB4wݱC^R`AJ *PdIt-k(n)Ӧ+ozu͈p̓M_?pZ ?y:;gjॷaL0tFjSRYepyYܼ<=G';(͐դ :4] E084 hlꝿ7۰#7_tEŻv~x*S=9Qgi$ik+pJ wRT+U'Sn+iIԩ{=Qj  f 0U8-(zWS <቎}4 jONnC̆_vDQĿ9i~ZWVqe+ѐZ叢ĤC19@xdu fr}6E"`cW:ک@=ѿȪMZN>l6$_8}-H8?DO:)̐Ҫ4awgC֓u^wI"@C eYD' ӈj}eRZ*qN c<:8juÕj3"Oc>qe,5{'gC"Qma rtR.8J-(ZdYk\%Ў`{b-y,䔮F\)ӧrr N2*lKAy}O o3D;r efIBRf#I(st}Fnd#T.ʷ.z=P,nR"aWExtvCxI~x)Vꗼ#vGo⤭ϋ3SFVoq!=.J6&rR B$6}pl!B LD?qD5i 89g.3s嬝Y6|:z)F N_ak^>W^9W}8 l zC(SPů̀ʋFMDÑf ]TT6 <H{y 9eN 9Z.|CYѼw5Ru:4N `gN/e"Y_'S<[c YݼmJx6Bsن5N*; xU# y/K&P8 1K.(K/:PR3`[DT^SCPkKa'|F,.&?±}U)Ԙ+Dw#;-H * QIW(ѳ pFtnYeJ/T~W'}0onǣ\fjƏjhBŌdсhZwA~Y2["W.jō@>Iď9R& 97@ *̲]ׇb-K ~N4[NPeL" F!RWb#~3ӌC[Y!'o΅c*@qgOSCsiz ׾65':t+ ڧcX rQ ?ESǍ"pһv]%zA܇]?.'enimA#K8~ՕGmD 0-'RfVL gsN+ܵ%9i}gԑysxLH2d- QYVȔuwooZ!7vʍΔ@f^1d ,ShuKPH&{mːRcXi="Q[j1%Y 'urLCS'rSv%Yh"%ķ੹{OF*MwqL"l̝k2w^lBcϼ7'mLZx^iM_{Rw8/-#PpZg:O%mJc1!775DkaXl`߄7;Ԃ.әJ`6?TMS.Mfqa= C TpPL!ީo GriFi2\ɧwMa ȍ鰏˦p" tsXDkjjk*) 41*/*'։fRw<3 @Yg4%:x 0,O0u"#'Te~1ƦdE?uq5EZ{YS5*: P$ rݭvXcv7Pg~W~ ?i&[+/+E"UUzSex`zIb- |f @/l&1.b䣋"p=Lm:QQ*ud*@Ly9&>"Iʜ bnA&24Ī5 n T!'<5Åy(xUgcف-a]uymZTGv'Q uy"*q%,H1/[N [ "R>E;<0xEH` 6g f8QBиEՓU܎DD !c3INEb"ahK1QS[}à?cc%xCg\?秪A4 -H5ީNRlłFOc33:D.x?إzq ]mvqXLo0aym`:e>GY&yBETq%^:){=® ЧuQŢYC7wK  D8^ #9N~I2_8Pf+/Mih1)Iev]q<2VlMD7dSk-Cי"1Dst $]fz%?a"9G<-T^BZ:xPR>nk+ŀ#K7Ԏ}M9 r>o3(}*kYK~.%zVs]a]6[:E-^fx4P_~r2H"E)pFo!Fx%Wی!͍EQ8DS#.ֱf5&XyY,v\7*emtڽs%D_;H RCPthCTWIRd]F vD z1 ZB~f?Fi~ge?a_˂dv\Kwyt%KV;-l(oP;h/.JB핑ݫuw|6ج^@ye#1*G()3\Kә53"v{-.qiEv~'Y!:=|9ax< о`Y˸Y7Q؋PQ(x@&a  |Xڂ 3u6Xp*_$-_6w5U<5U|ͻFQ ʉH*g9eբz;nz7֊C+3FNl蔴!vue1d|e`=n+{“jmX|`E0BбQy)jgșRnZ:fn7HyznY;դs`@X4[zvx&BM*ݱʒb:0# -•Ք,K 6&^_`k4x!`,Kٙc=y`5N:jqbx*)-cg҃G'2-1@Ǵ# )?.rƔCV0~/=aM6DT MYlBNϾ+x'fIJ<KB0@23޾x}npBbY>E"ƋL1#IFC5sh*)XB7-( zm^͗w0%@!cה?w05/]2@_/!xxGT{o&A8Q u g_RV`b,b b(rϏ0*%Fﴤ#z6n7թn9Cfu5CG af9Sゕ$emJDIV$|: .O}N, J,T߉"dwx TJ#d$+ߘ iJkT<[MN^sHt䮄BS@sR%SRRBbW {ٶ= 돪w *P6RyfydǀH<U}rSծ" H,w'2ݽbtN#Ri)>#(򔡴wSɝ!}D \K=Ef?"3MrX}]E!}*u[Տaπi8I52+[D4vH27Uղ6_pHp.DR;۪xښ3͸&lacdƂw,hu̓r?X̧N20/`l=]2[.+4x%' IJG7Smt eʮ콰^!l1FNbncT?o}KDsWqN"r7.O,>yV++G:4vmSD [h '%v̒qLpov)$r8cx{!){Le@HOCY;2T':-W+{Pܥ?s©RVYb_eN$Ja`g5澬JbVBZd"+HvuDxfizG|s HsCǺH GfBz8hE0c뭷>jk!ĴwIłve3Y/҈R99|4C/ݮ 6EQj(5e 8RYOh1MorUх V0(ہ#뺃6/lϨ3VB>ꢳwӑJ38Fbm@hB,mvd~fMurcI?35zMGCWʃ٘$k9aZЧDBQ ` S_uIV`Zùؒ)_CθVz;469 QrG|*E}#DZ!,y2|Gk8xFn$z蟍Hzٖ#ߐ1/pͬ'Uщwl3S/D ;L{=3g  c⦥ШFzUd=$#j= e3 ?"aPJo м$bv0n?*@0y545Б[0k%~X?M36=*f sdj7ܑ)>4X^d2<<ҀO75Ѻhv1+C-ѯ3yPfy{檜_9pu _jyN~os-ܣ Q<7|oZi[|Lk(V7x8B hXeJ)}.)"tWfY{'8\ ?ZXPr{ܳWs`H+ZiX1A!*<-{??FsԝpDK D ]}2l1l-❲8Kw(o=m}d uZGìˊ\NYb-QL8mLPx\@(Jg֪a7 uDVA ~Iry"O'ama}aufRT.lPݴAxW4CnaE,oNSX):pĝK^!I1иZiM+Ε dʔG~Zd}4Yrw.V?[͜. h_F>_.]=cοoǍҸ s^uy9Ce,| w` ]*G ϠپP:EX{k}a^rOJ+3"2*J`Zm 47|_< w~Z1n3A GcZPSs~Sb٠wNªfHȾ yJ*Lv'M5ў{\JKA+0^njǺ ^[O*ߩ&G)tѝsD V.Lޅ0f]eXdԾdS_{ts8?ڙX%ܑi9<x-j\Ͽz(zW%}B7 KsaSX>T:ՃrfX&{m1JގtDw]5l#H܍t/={F[[Dv5JyU@/-&.O_4S2vS'u9h@#[^|'UȤWۯmc9ی{PNӱ w(gIkTa>lҔgz-%ߕKHҪ4a'2DZc7 76c`%u/Y>&^K2H ?1'vH]Y1]=HZT0αCqobGB3P ΝN8EC UJ0 WN1?Ąe츭$E gId%,gäMqyz,qr 9wi@-XtџQ:܊_uڞHpWBj_4?fJxDg{ L߁ڈIq?R;6)ܘڢԡNFfBIq0[^5}&a?sqXiK8lj8Dx g*&$c\^``ÛHө=f2\ BFSsdnyy ac*8Sc}e~Uen7Sb?Ts""7*_G)L.$9B W#ZȖ"+4;+6( Hm&C)j`.x"[43j:Zܠނ~XD__" hrl7tJw /?V.>nFiaYrM sgn{XLB.@kO1afH t Ư/Z,D[}oiZ;z"Fc?vUAALoSf9j8{5rT4 CļϤhY]XܒXS_-AU5ciR#wO,w9?V*T1"t|9z.äѶ.(&ݲf냡 D|׆ߺgZ〓Nd A9=H6`6k=NP=Yjf͌3> 4j"49,xqbc O fV-8)~KېqWαLO^??Ayx",r83ۗ"?#/(^8p $AI()74瓷IM:R4$4 ݖJj9]3=m—`mbK 7)SۿpYcL=w¿bD0|#7N3AQ׺NLXL,10kd8JK c8aj LBSd,s#GN/ﶧo5\6ۛp롧4k_,V_nBݟU5p3aAkcD==`u d >[[sGhf}OsFE:; qv(*xW=& en~1D@(o[Zm6 8XwSID{4ʎ kD^ JY^S8\'8ǙaaW^_Ѕhg#&>h*N;<3s :t]υUe]p)]{,KuRZ:YkM ZC>b)Ыf q);'jf dV.dUTإ #w}Aג# 0 v1zV{wO(lýzcGCtnt.?⢩'WZ(wcߙ~?^VM4}zXi(20'Pn(CS NɞY*2536L$u ;2yj5 9}6 wSlGypT;CS}й&`\ j?Εzs!̲WiQl#Vm2HMll0 q%* Nyj 0OZ5.4`X-q4԰(>g_@:,0uiMYqFf )xgʲ~VL},$ݵbuLX%|&yqRѠ(Ohp5cq{XYY1{'֤Ԙ.r` [Д(yzY¸ߧ~6^[fl죍RJ_&1tg}CLIZ\軨!.yRd|!GT *s珴씺Xn^s:U;`Y# e4ؔ![ӝL$Xd $~r]C\$qyEyDblєeG*3e19`3c D-1$|HR)zUe0\o,>"ӥX8jE|ɍ| _ro(O_q ԟb% j[Ǩn#nT(o+@XA2]zw !Ҝ'tkv^@*2vǫ#`VOD׬cь, Sfgy t JRF@Anm^_E&0nD,Ɇc<# 让 [% .ӝ9v ]es1`AZN^vgHY5 IE}@+ҾV+~V&22{$*⮰1*%?6\Oٙv?h/R0 0Ȓ{usL'Jf+ OFcdMrӶIjn,C i'L&c‘L)Ӌ_b)i|/_Lҗ/26DfT|!+]C*~9ʛ'Ng}Røޢ"q`'00b$&]"[M@F 6b%uvNM*^1M|}<ՅzQAAv C\WǪtE'47Wy~,vQPW? -Ρ5v0W;n@ɹtd0xb{tfub j`}:I .*zf߂K4RurưW"L/@B*d4mj(( l h/G*4돈gRt}"DL1bZ8įE|su1;ܴBX`)3\1\if*^ZLro!D}t[UZ7~}7D\f{9/=4zI+D0ޠU!Jb m괃 ,K<]x|]8Ա漭f7Pi??ձ=}07H;:Eucs}F>lpĕ#àP*EwBI4>u55Aw{YJL;HP B,')m^ Mhn}*|p Fkvr-0g^%X 9~U@L 3afıʵ;=;4V$RASHT1`NHcnNQKp{~tZL*o4ǐțlZbQf ='+D|jZH؎Ȍ H^5& ̥ٚ.fX)KoJӟ=}r l TOCLFK=׿?笤h,/M>u G߇hlOw/u5>}z"'5Sfx2Ky|0){wT#K\<7OunJʬCGEuL]czH:k#ND/|5X.9gMd4*m2fBhmfX?,JhWo4>LLo ?~͸G0'lFvzhǺT{7zbk-Riy3/,H"U$UUXeZlu[0Ozw|Mjʘy+C)-o6Ȇ1~ߟ`kL3z[4}yU,SN0,Sq[O<$hv!.gXUvJ]”2:ӃuךVU?XPe/T@Y NK5ՇE]I6/sgi(Z/(V1{L)آMHMb ) i:8%NW9hYĖ`\:2Xg/˪27&|Re,L00\ |daO"_tD=ć>(zV*@#2+OS,Q=Wgm9h@bamZR~ Msc FdnDJ-: FԎ/nIQBeOiUi:jH2D0@3 ^lXɁ> M(%(yb9s-#Om0B»)xO|o&oHcí+h`PnJ$9i_~06 =j~SeSr*y$j< 2qc BgET_AQ[]EVpAoUB͌qd㬃f>,x"8ֺ$릟,{Vœ0[ͳ +sHpJl NEFr D5NA+U)}Zfi)[܋:r6 54JC(kc$2$OƇd U%Y0E?6(tfrp^Q(<خL*S( ]]өq"aϪh5=^wp}w:XrZro͜@.fBPCIPAH@8orcbnq@`|-8?'6֘L]i/B7kA1504$ۨ zb}ʭX;~xD< RgO<`迩,+8Aa[)w9kI|q4xI41FV!B02ꆣ|cz#ԕ!3 1nOh8CIp}42$GΆ_ˋvR*p5R/|Ƒx'WR$%0T Tw{I }&GTWs!*d%X<`Gf&0-hiXw.ק_9 Bӂ]bX)%[;.5гS}gnƺaL,$" h;wnxy2  ~߄5ӹt ~M0Q\}ꢇ7O[D aNZai/eC*x7MQ; ̞z@s`=Mm-1?ʎ9BE`r)ޜePd] +UY,+!2^F8 +zS#/ya | i1#l8]QQ'?$Mݯ;j"<)iiS*4%gk-Ҍ_ДxJJ!dnaZ.1*"2jqb{ &Ni 6CzlS(kb9\Gc}:>{5,P_X>`ffIҊf9j{ox0B;8k:•zDT<u `V~{8~W,kli@kpj|BY W`:|ynF R_ުNBiԖ8t.QcIEd)G up.8?750gS.8Ƀ5!Vewi#Je_c|Zkc9:0$"q8$;OOIKAK_Nv0$F=eѸSJD_^¤d~s+MjUxW&[*lL#26Y=|haѝQjb6-JڱfYz293mj6PLw(\`'S2ˌc N5NR 0%i{bW0VI hW#fZՓXtP&ƤQ,iyN>3JAH{+kؖ䭎)Bz3 s-ؽMp݉t\{bQ:t^r[B3c|ۍ~*8%"$>-mDb ,q] 2^SoǑBA,Ǵ-7pAWWfeߵ )n/ХvsƟUڂS; +?#K;%0r9ͻo:dW Bfӓj,yG3;qNsT9/2CJ𞭺Krdh6ݶ3u {FIJF ǚ`}"J,oԸbDml8 Ǥ-gDžFw:o wnfyR9pT';Κbj{+]}S8XK_SksGp>28ckN HC2'330eԠqti 1k8 sY Q!l{N/"viiA` DEpLخe@i_1.Er41{6NNv;yMʴYPL!ٽQ r,^4jrWV'y-V+-s6h|aXfhe2Qȃbp)Z X6d(B:Zm0WB"vnr~ô.؁ F_6@qNm+֘线J:FA zbx|G=jCCubI==݆z JH-s"ШՎ-nncẔuLnS(j_WJQdQ6o#sern8tiJXv(#NoK"҈WW o q[lдikY eN&Q5끿:AL`6}U ,N:Xp\2b!\G޸\N"1~Wѹ%1S^PwI^kDh[*nO{or52s}y_m$(!8.𩼹QPT7B-t4yOcVUFr(A8/S"BoO\HOwu7!uBgZTLt`UKFFVg+Sغ7LJ$ EpZ8`f0a'NnрD!߅l0-UUry Y.D?Ux2l@,cXts)f<du83ty [<ͣ ~q&m\gr";#f8%DZ.bPL%(vA *)zo0z >w(c{Ar TBasO0Ѓ1I2kFng\GCB?psC.pi܊/?#i)(܊U2/#tƕգW6y@Ga Qj21fNџM"*^颅Pi܊ס,NN9Lތ];8r.˖|zukĬq>N9ĊȣIs~̥S5͖]`RN/P;qh { 4nJP% 2I&VLyG-(P%Rv6qa/L>5ܙcUV[ftQڷw;ֽ{g[+aem V1 #}/sxC$P $PAZXλdl e0Z5-(CPd=E?3( GKZpٖ`Ǒ$:`Qj /BK E'@|dYM9*xmAE)nTw즹fG,2Ue >n-%Ndʙm) h!md~tH}`-%T )b@}D`nIWf!%g˙n3qLna\(E}NY 1bTwŖ;-q4!]lWW9}Ǎ8[+iݕ3pWQD^X ̾P#%IHB|`?-Q=VS?Snoʽ@qxY룠NEq&1 ;"D[b709LsHuHf[^[Ҫ'N}tJY^(VRy~ꠀBӑ(^#^zɳ Bf8lwK^'\8շ|" ɕB,-{G]VxDLRQ[;QgԢ<**lIH^i#I4FP[=gC1t=9eWJ3Sv.S.QBjuIMB}3mNv!>!.F[k';F3̊KQ1o،瑳wY{ ~2mz=w)okViu*҃ #-׆N ;2T J/De |,,(f4@X\TBzHڤ3WN6(Mpp I/5)uEھV1[.;ZbxX3{4b{5?CW0t0`x>ΠYŭɷj҂5r[۪+r` D6Pâ篈va;7A_%o8fD#8+DOuy= HK2Usx0G4e{DfK.E)҇1s^ ףP:ĐW E@:gύ }0 y1aU.~ȦSgi.`NX$aSMm_1Xҝ-|8[BP7^.12M}[+Ǿ5b}`Jk'빘KϲۅΒ5R9t3oOҶA\6bN+s7۷pXw0 )m͜0x|ޖDZ ٝN߬j-dHG8 9v'  ʀ|²RleK`k{6 ]`^`~<j2N Le=. WE ==׈eU>f:3M8g(?˸}._G (p|WB/u M x穀rp7ĵ{SeNvq_ſ?ad4rE $BZlYLs{1cfϼ9 bͯ`RIrGk@vNޮ7`=t90~dtLG [Ʌ0$뫱p RD HoecK]_+lD!Yt L-Y0Ns.9 &HbIѱيL)u5/m$oMk-_O><2Dc@/5ϧFHbG2GL &j|<JP[ &͙AϽ9D)&鰘W*,&ZȦz|,#$8$} ,cý%vaF`_z[w¯v '1$jQ0:vl?NblX,+F،N*K'z |z(oƟE_/=@+wg2=tdt7R.nGR^aQ3۸?5$VMY51OKLH;n͋B*y}olT~-ݴrrmC7ٞα=^"b~@̶ >XO$uR;&F1? O}#8bWk0l.ڗтejL= Xʍ}*/"[=,=m5'-rHe[ɔi$lE}kwxyn4G<*;)>&A~ŰN%۰Ę7gÿ VRX֝RSxJQҵ hU]6[ϔ!*m~X W0߂s_$IP::y)2VV.?kۊ"r |}=j'X| * jtFPI3nxW0>F+KCn=ݧ(|^Bи؏H+4'r9R,Hǥhǂ51Nwy+JAL+XET`mǐ{m=17簞   I MA:ehpd#(>;9x/KhfG,"R?m^VMV#Ygkt+":? Gt1%agwqבWWW>3-jBq { 4K $'@Ոd4NQzn _̪i\[Ĉ[9𖃪 o 3aF(_Z)!5g)[z*9E C J tObʇ+ ,1XlQXZ:EǡkӪc@}4UP^d!$.IWbGLHSg iY46'{I @!Ozu HyЎ"?#э>"S )jFOUR1_303YKdnP(JJx6'g}&>7QG,SE4I5ck06ܘbjl }+\ J~dJ=0=ӣ(RHZr $OQEx}$utӟ* Bpb8mu9$0bg-#uIP%T;ڟ?6Gys% D)!oҵW{sΥGÑQ9j EFȇ/o3F+Â5Ce3ē|19czY"nbNTHǕ >b$",҄%rګAN{G]b@&#|ZCŧ3U($VmSmc҂UԤwD^ D |B[k ="׬6!X&zMt&n&Jp}o54&Tp ݽWa!Ma &7T ]bGUOi$NnvKe QII8u sV 4.Zןyے6]-gZyDC,2X>gNZx@Hc9 HOga Ky6eY魔 (q)M"napRR>:Q=#lᴙ`G&Wt;>x :/=3=uO009ǜ0(vA$W*uvxx F> 9tOUx畊14 }9]"kfPL-=Gܿ/ZA)cpPZ)ehH >Ų+O!tlT}oUm@_D, d@`A`{7kȖ&X 8EYMȖ <樺] g9oeэr}ט =F2~aI2/Oj΋`bw2o: v WMbH֢QVUX6)`65Byu&SąÚUİ5a|al TG.*;gVlMpZr'FY(]SDZ"4]n46i@LUVKa60sY\qm,7ߕlN)VϾ+b@(Am8PSi ј>!L}׷] UsHB) 0/οӄ\Hk]~a/_FQY(C0,?`PxQ?`D.Y:[,541(שIT5rώ]UgZP2te>-5RYv.o>+Ud|V qS% 3q6ʖA *BF kUv{Y,(wAC] : Xs:N؞ f)G^~lG2 rz(zǂ7Q&C\j] xٸa"\Q;+ !μ⿎wg(Tv) etwoEGif$fV@FίG:iӋv4j P+IA {!ss. thq#ln ޓ7ziJ#+> msM>7XʋE~|.|y0tK%j$J3n=վ1 TC E9_.NGWa TGaG,91;~l待_ _+mB)>pfRIy ~IVu艕ȱCJ`}=->G[bxQEttS~o1iPL2;A)/zCKYsY/6S8@S//i8vH(킙b>)3 ZeLv# iP՞x6Y1_p_PRWՑ6' lH,Y*r*g[GW1% 1&lXk#d)7 {\|}El" _(ed@xMٜ8Kd{,;Z܌J<\N( 0O/4wŮ?=@D cFae.#=d"Ii/ l[!p>hs=?$A >C?RP{* lŦ'.#"??CV}eVb \WT?_ ﶩAoUm鍊gӻl:JjjgM5k wԦ؜".ɁI=[ Bwne2qeu 0ig+ȍ5@zāޯ,:J7nq/Vqã)*e?} O,eGle\Q,!nJsjPԻiv 5j߲%qgZIy -AF,Z+1"R(Ũ#7>[bZ 'y'vp8\pGH\@j=ll8{uҤ|~IE({iǘ.΍};`e(ϊiBQVACܿ7?" K T|%^'B\u>z }T?6VRԵAd_1HةS%esOcǂYwǼ^DguM[8 u#y<(wi:%N4!sbV{?ܵ Cr#G -!Pj,[>6 aptO%`X@53@<NI[[ͅgHkCÌ}\59!(cy If͛0XuNX^n}E?ȥ_+湒SMqSi(X{,_3(.YWer?+ce$^֌yo* FԔq8|U+MA3dJV}1M AflԑabhyX),7Yp׷r嚥 ^Yʡ)UT< Y%58Z9Y]輽VFEW<{]Zr_N6V,n5AzC$lb2 ҢE>:Loh_ h&/ BeGKL%E[GDOƧ/zdgje ,,}QsM+_oupY_:"g\0lV8 ;FUϴfǑkRlG'PioN ǟfMz}8Cv1='z$S`qZZcƐBޮXM2s݋ pHbEkM4f0'΍A|x<a:+(F_lj(=6ϷyS(,u^kf($V$9i l˵|D)A7hT^">H١_DG]@M>1Өwdf-xP<ߘI} Ƀ@9y"~fw@wtA@?W}ޢ+M{U:.Z:ƟraTFn%Ќ:˨m~í!Y{_X2 E/rf^d/歶˵=+x@ǰ+UR .'U~;)nbM(J%GbKQQs \_{Y_B?h 8jL-88F ֍@"2'0l|i!Ϩk`}މn_|o;Trk WR)C%Р*^:#NmAD6 a~?E(:BcrwJMZ :3 wI9pd_݁?e]VﶬU$JF`&e\V{S=*Hg|:xҍ[>tzo7aK+/EX5ielI~vs^A#uBmFͳw.#],dX ~[7;X-*]4OF]2Zu%pS!k--YQgI]i(2ꌊo*MU~߶{DODo#wܼԯ**99}R C+ a76cV56^b5rqsC=LYFx^I븵LsXGU!?5vBsA `7)YqO{@ 9#3aL JɫM(0\R#x}ug{#kﲠ5 :H2gԉ$th]%$Ē0ʀXTHvKp-PNNR(.`[;//ۛ&aXH#n\f gNe1v99n;+86`_j?lX'BIY<4-hȉz_΋ƪ6ZCDV%EeTd'X fcluebXYYUc|[V YHoo%zГ '0مH.xj.#sBZCb/[drC1b2Xxhҟ[&m[(xJie TWwx89&{GP4!yMyFeaQCԡe?K…0\'q8#>/y 2ꄂ۵܆ T}N^(=MkMBtĬ8V*k-Y*D${]\Ԁu dl7?syeYGsl?g_hjJ e{2;ܳ%ge9>s:fY_Ys d= 3߬H`][:Hq]|.nx˟.UJ_aϞQ-ќ~"DW=sx;,X*9VXk" {O6 y#"Xjm-cf[$ XG x 'oRvn{ͯA~G(dễ۶>%}Y+  X̲0E}> L= S5Vv϶̹  S7 2b;4G>ܩCn;,շ uS C.+и/{ӈ?5*\FL"0 w.t~~XToS~y 0-dy;LT>Ђ܊Zȇ˿Ilͺ\סTF"r3sֹs{y3ڍ_yi LO 0[ 5Y <&Gɤ>v=NgIۼBhW}7[,p[ @2{'0oΧӿÒGn4`Aá LTp#Aԩ nZ&ttZNF?DQBx=qV'G󞣹YPJ`luIͶ6V|XD5r14h,{EIsDPF1vb'H=s+SP$WH=l|;.w!:_9^]ڵwr 8cjR6Rl zбQ_tc};mĠ.`8S]C~I;_l'nYceO(2шY0l ޗ@>뜶c,5Q5B2&%u.Ϭs iD9 GFޣL/uT GnII>CL|4O~PҠURY=d@U)SV]ɵjNKcʯ*1dyZ65IgҬH3W0_?rd懥1&|XU,GRK4y=q{De|E*_\O_pW߶UB>r[!'(+;lH8IٹˆQp &W:Z"G`Chl^=%]6F F Q@Bk}b@Y8~ P>_t|]o\cW{l9>nFߌvAfKu{!J68-@P_:Ĵ8\~u#Q1 )e\|$16;J]w&y}](ӛ;"y_o޾#ENxÜ]+yyuH0"ň[büaAXԱڊ-M,&_Y5п_~w6r&?oSZt*i0]@1@wu~zSNQPSYKhF;{͞H0T<$]ް|JSv:ph`h;6do/aG^p1ן' D`]gާ\i;6hα_x1XE/3 B>`UXBY9o6A֩8<ʽdާ|3vVbY_x-KgWԦX Zbb/91P%trsZ"g[bhnzCAk2,Pw)X_,#^gQMEh{."9;Nʛذ\M WhΙ?1vǤ^F.!xo\} ?~?$+Dn^~OzY'ƎdHn1v7_ZHERuA1xᪿu:^H!iOA`@=1r2D86(E,A=HFaN[ǫ{C6aE‹|{,/>T #NծtFb/ػ) 'e'$6~j\c׳l[?%Iq:̡"6;*m0v3H@9!dab~֏7֫0xi~sD= N<=ޠ Q!B쀉AF!q>ao4O2VA]e;^1 Rev ?ǿɅW1zwzWDiIn[>h]P2/:.C~6gMLfsN>$+@]^A\HS DWIY | 2B+Sg7k}qtZ?\i߆ ʧT)Fa|^e$M]xa-8SF5K(oA $WC4ꯚe'hٍƹ3-'9fvAHcxk}kNa6w%1f`u3sZ<4O4ƉJ`hwbhN[ug/Vᨕ5JKR`7|loJ5]zwR@T=gr&peș&5ޢ xf1]9,O]0{l &\oK=/d(' չEPT<VQT e&j̢ʴ}3%. НGb?u*4x1};7ڶ9%2Ȏ(! &7R(&C) rjf[v/5W(Ld+~SH35~L G PQGHBqcd9]Ag5A(U, 88V%XK$~:9!N)bm=nӵL:~5A%ީz5أME_XT3c!<u<R,bھbB1{~{=SM' \D;NenH?G%Ѕx`7O5{rem|&Ivp Acݼ cb(uySziͮuxTpPP4k';ʓi/I ݀[v`a.vfϗn"9K36Qf枒8džܗiC*m߫+q+&LDW[RmҠ34/Լ3`sy)xZy֔ EMarO(ξ,u$(?l`%>CsGOQdZ8&n|zY9f 2~/':m{9@j΃[NA>Ŭ%x~1:3ez3Yysҷ7/4y7矼~\%3=R:wa( Q0+$L:CemA#Ct6RYa.IqY2{= P$6bpkbѤ@?kzX7oН@lz`9h}o^3_𤧸ьŹɜG/J4P2߀<} k7彌Ą `/(/\ݫ}ᶉ`>קs>gK1D >)X!eo?,.HFoÔW`EhHEM_Tx\YTvu–pt{FM7OeTRIu<:&IZ#+j_ F&y̋+[FՑZoc3?7AGaL;YHFKMԞ33aJHUo@d I^ l Pnl}`J})kN=gWP_II1I,r@zU(/v7ⓍRb JsyrSlU<A\(b%yw \n"3=:vnK<?-j J-SÜц;whb&aW3:a ^A80e)ZWbg ccy$W6Qn{]syW1R3RV z<2H$*;w|s;/Q&"A ֫ Luml3#Q)~\QTg%gxv`O#0+ܧV+h=SVhc`'V#GO`&G6̺[?f,pSƑ,G #fãFM8VI)b\h3|wtQ-KlL ZV^ 19~DxQ@>~Gٯ\⟏D37fYd8\杧Y2BotGB_? w֗v= ԩuqh M2gsY+kէX3~Q6# Bzc v5j*GD(5ow{~_@QBwzwq͖q 3ޗI󝍽DQ;JVxzU1 8f{el)B0je 1B݇y8j<OtQz ]S<], 幜yR/,&{.[$z۞jF\KOb".qí|ז _Lg~K/C1ԈZ۽<`C50 c+<@KQs,nY$M0ԡ+j6U~)[w յ܋sKBÓ%.Ydrھ`E_s-J崞MR3_ d$ ^٪!*,}jxJ<':j%T0MCEtQx $ˆ@)c!/(9BB \$gx C rVZ#\)\H3](//%(6V|cdxO|ݬ7 =d;Ϊ ەoY̅YK6-쬌&{ێ;aR^chf٠wV&[JhB!y֣R8SiA`¾Q*1Ike_?r6Tdw? ^n:6+? cxDF`K (F)!b"WTg% V]{XO*@ҬPY!r}0DEpvamz5wi2}(BEίn  unwnA'h+nԣ"L v>wlyͲ3 k:guso:Cq8tZ`yx'({|0W1K%_ɫ'Ds&lJeD cG4Nq0Z?>xN}$d8Fxg=#8n#e*OoԘMҖߣب{`At`zʶc)4Ec=|h_朿TLU`jƟ*f=][|?p 'p=)(ad({>h(ҾT^)HGgfHcEqYD޻(d܋l(EN ~H;g[yqv`X8Jx`pn{gv7Σ:|FV?R/Jn@%Bp’5SՑ)5<j3laFGkF߰]ࣽ<'X+T`nI+v/{u˚mQMA ~#8_w Z.vp)ّHf>«]̻?)^Vt/ u@>E1DD2Q:HRy,RL~ÈSlx-u[6?TLɾi-ز?K*UŸAQFJ(s$m >4oWVBrw4ب&1~SC//ڮh/ 9weX? & $ Wk㵞LI[C@/\\zd4,X5m&+ühb- eRi_)TW.)O"N6'8{J"EB+VX+YNXBqư*ņv1\u5!Je` 1H+xЋs~`7B~4Z'ܾt%y:H`4RY:;8SQ:_Ѐzg[oVO #)|s|AcN 2+Rf4טhxN:U$Vϛj5U geؤl$NiWcaE9 Ww!3mk[+l\'F(ʝ9?FoQ|hXc5jAǤ< xpWwf +$E MXLlԽ2E*[ph9c_?0iWp{8 /g`v ]Q%F,@Zq IvGZ<1R2&{oݰ1[IRiMKV[[%1Ţl=H~6ILIh]t2P{,Ξ;F)?/$d _2 ab82I ={읦Y(rݸ$ReEla;:̽٫:Lrkg _Psxw 89c5 O:bLI=ڴl{]1$2h)<+Rf /,Ϲ{9%3"È7=MyvhB N(y%6!&ȸxb[Bwa~iC;>pF0+,ƞx'={i$ UĹf.'DYb$yOlM@T_t*3x6ǮdmHr_EfALxR+[o;'`c+2d8"hmq*a`XP0N"vR2w2܈<ёH[k[.K/7s"WH5Wg214 r$Vvn]ɚ\V<mᢺ ɼ1]+kw+Ye28Hh +kdž6ӳ'B,r FӘsTF`4 u43 K6WU2.ŽDS'Gbkj$ 9^O ` ` h$C)~w[E[ykф zJz0f%pJtJrQ"N``)CG?=ك>;>)' vxAT5\Jx.`CpmMT,C7ە;Nfέo7,rqK-YQs+,cnS:>`^Ţ+m7y,V"Ua=ȇtOQo4 ն̃PY.5Dzb/n‘dx'O9gFr:ɚWƜ(ӂ L"TMg9meT}lJJI;V7j^)SDc "5~hSygeQ[H~:W[a5*\jVLh7 n~)'7@/<Y:e]"`H#j%A h]>-ARZ$V} ꉸ8(+f b$v BmGcêIV5 G;俱8f'0~\+lrw/dթWc(bhiKL.EFEd80H5!vIF=!&?R(-xq쨵gb "g"/!Lj !svKN; `=dfiqv S[Ȅg8rdOѰr~]ӿkD`]3h{&$qub I[em!C(xeG9Fb˻*q*uԾxnDA$ 9:dʨ鏝ӎ)7Ƥ+Dp䕇7Z䮭 6+;|=<}D'+TD ʪ/K˿& xwP&ۓC35_O]Jj}V g5rzua?wK?1(zC6u'}8꿫QRoxR$F9pLX[ab-xhq%¹Dj8Tџϐ+ΔZxcXF BsHm!¶1r˗2rKlٝ>=Ie0'>,ŗ(]z%h }<6YvSXlϐ^GnĢ#Trt _ۦr#9S8+˜UTAK@W8Nrd /!iTwՄ$ Qy9f;RË=)sV~?l/e(}[*IBA8gB9H!"u᭒OOFh~<wxn rGI$ "ڀXOPYW)_t0 [t?0ݐdCn/(x+限J6BH)_ RAktǦ^ oG{{)QTR'@3EYo?{/g}(zՉVM'~NݴRx(`+97R7?cwoVu!S@UlH͌1"*;pX_&k:Ӥ_8QDYZbI帞thv=\S}7ܼ{H><䜟ʪܳΉ{Ug<Px!o>M`KX&>}q֜w7g@0E@NZc]={$+dh!yg^`n"wtLg} JS EN[xW!emѕ x0`ɰ>Fj&7SaJ_S+{@Xك!g.KTb2V,̀c/bcn;oXa ꍂ2P*=iV<=ȩBr./&w{[̐xӮTHsBeП53P5kTj%2(c%?w&EVs2DSvlo(z6=)W3n&*3*kTⶪQr&A9eLp򵶋s1" tpqYh?ŀ֓`LhIWV T vJ 4nNaٷ'|d {GD_vA c[[soÀ#dtM^66W4o. 3=$Ahhħ֛Cm-[ gJ^S1ɸ`A:,w$ ͜?eY}tO:U m~{FN<aE,5ْu3\& !<ФMX կ9oҿ]P w1e|`ZJ" ^KۗRq.3ޜbNfkAnM˰_Oql4tPKD#ǥr 6g 9tZVWa5틳yph]mEN6a ׺Y[F{Fr!}3 }E=R+<ſ~N>\=6A34hDsɞ{8!(I Irntb1(4VQ22hH0sd,Ap'EM/HԻ;ian2+0XXY3;(^kg36>&'^R ||Lrrp%"]lsA&ჽXCʈ-R \Y܆j޲:˲k~Ld%/劉3T9Bqh+mȢRb[Q=wEx!s?'%jXq)7k /JBLBZeP}zfT_E 5)kH;rzTHGeP%WՇ{(|uQ/ps׆x /?i!*#*3[6,cP=_aqKkFT"74`=!^}'YoJ&2"=-C( o=~Kj]CXxoa߫8Vt誤Nt_*~d_X {_T;N$(V4DLrz?R=_bC!Tݚ7#,!<4{q #B}! wva2q- *e}P|hdnPzMEf8o.SI5k'vaVDߧ}nݗs}Bzo>PO lVAhB"VPv5ԙ0pmxsU?*hu4:'1f=jRd#wla&Pb`U$G"ę7& V*fE\[ :l_?o߂`$ idl[oGX6B.@F I6rYߙOkTQʀH-X_qAsEUw qؑ!G4e*4,ss^"A,B/խz\a빤8u.rĂ$l{.}_>r.WF2]S?RD>uT`ȉ @PXqVsYΝ8C :JMsPO_ [mw;Ķ%"Rlۈh])]b , $%{0 ]7/}gbxPMc$й=  ,ID-t u }v҉lк+E;ŃKzvАa.H,N`(oՄ0rŇ(= y%Cfbցu}#S%FJy#I+͢;uE6MeUۍ\Y~rH&; @N+PO,(n8|3uRk]ݜ`hOcDB9|:սꭋy2]ZX{0p6q>2Ca%DS&mUf9e}qRF (=ڌTLcdBσBsKx8<6&$dev!U }^ؑO{ndž<ՊFrSpo0""Pybg5vf|z"zKS3;2n5<"9k0*iiuXC܎6Oo7 X}UQPM1p*^O[6ү0{ߠT(s]=Q8;qGrcOKk$Ke*Vخkc;l;C3.x15ðj͗CIm5vb-&4HwcۅCqg7&82@+W,O :3*P>\AFw&nf6v>wFU}gX_M`*6J9vKaKYŇav~yukbg(yP>ܺ*i껙a[m=x:%I*(Dk[/Ivu C1 Bl̋OrQetk7v!:"7ϔ9) 8R? ]sx"RV.G\dzS$^ǥqaܖ&ƵwAKh[ o}{窧"h^YkElJt6+Oͽ>L@hR"^\chPD?j!0zΑS3|mtNQ?ɾIw*^ߌ5<4#Y,3xeԊETXk;!D׉۩E  27~w>HhP.\t}f2h䱢ϋyD-So=8`X\caܪ4D8:+ X9b%^I8WZZ`}=?@WYgdԐ5&m~\CfT$<S{ _HR1ł99jV Gha8Vs!,VOK%^fTHDS9F)}s;AryL5^Cuk=h{O!7!l]~.:zI얍*L|a1biaI1 g97YYE|#QN@I5u٤ (rج4?bvr"/ ro'U\7}.rc9iC߱)zcn{CSw 9Ku*zeP{S {J\8ŕ.qTڙnvh)t S$$̩(w5/jOs=1!F9FZ9QyB)Z14Z(j5F%/ܥEΞ 6ҺOq,{}Hn2'MmGxe+mk7z œ@plҶƙ8 0̚}[V$zQ.!+s4uHɝ˜93߅cC4T"kmuri_i:C_;o!88PQ{lH@,H8?l}~=&pUʛZEmfIc}I|m>;:Cqd#<*]Nm99:k[ZZ~hSx\U%4QֆnYڸc?N{DBA@" 3z_cTx7[/g6Rw9TuSb;`|CI9d`BXEy1N+Pΰ߂N 7;Jׁ@6{2Ĺ1>JD K%NKqې~QTګsާDVO~ѭj? 4|zTSPdd@ֺώ@֝QG=. aKA]6|x4b*u)۟bJ゗kGjA'PHs(dz-A*+BZLS?3#<"WDWay G! Spm8> +}-,_|` % մq4WOdiU$^~5.W80MɽDh'ES(|G9܅%lVjR:gd^GȆ&r9j ~5JXÐ,1C1|[d-Y,Y'⩯~[ǻ~P}|ydncV]6dHw20hbi^V.;F3 Wv%KGP5@ԀWRMն5q\;d3GNjD0+U>VV]U m-;#{Y- Q u EN,VBC*Kx>I֍f*%ldL%a隇Ė.DCy^͈ mS/ۚCu[u5EcY!\Q{T2x}"x-b8֫K2^2ǐvN6OטL 'm@Β|kj \z)ӕqǡAB*qSgbN@af>Q~͞$Sxw];mSz2KGI^J эpRxz/F=Jf h\۳H*XIv+Ha}|5SVB*#оB~0r{ˌ7[fxsK ĀTǹGPx0#vtTez7 .{$o~N ΀g^fOkSa1]ǃ7TlzRwc(m[( lϴ,iu^sMdQ!7 =qpE5q J%罺"zEc_.LUs POu_,l&Q. `g'(Ob*o.\rLx(xWG,wl}Wi61 ެ>mtvCw^^i!p{51Ɣn=hf-ƐKT@r_\Qxۊ8Y//B$eDb>(٤}`~_Ĥ3#mjkÒ S0_S3{1J79#wˤj(?+UE۬@o&*E̩2d(lǟcG!Zk@{nu&#l׀nʍf"L|hQ>xbrsk(SlWA;e!lQȖ H'{ 6>:"xf b_; dN+ zgDm 4B}&AyAЧ&=, m[>qC5((3=^)jd1dՈ÷>YzG̓gBoRc|B2dk`3 ^{_<%bxiv-]J铘]_V̓)%Vs>{"d-L:øN)gf WS7U,q Vae;>7df~* (cg|ET*^ z4}Ol:8f.__.mNJ#rxaqldkY?隷a7<`(Hڭ%NES.}Iݞ\Q97bgw!gG=^]WS5̭ w iipc/LNpԴ~]j5Ob}&®$cA ˃Ăk&Q%0Ju6,j⫞VL$ Qk vJ K@U/+e#Is"*Q@Dbk FvڰvYYUٗZśASon(kA$:G ±z.Y ADzrTu|w^iag2Gі%,dI{MgC"8"WM"H1%$uQ(!,/౧bWƪJ3oFV,UkB I72!/,In8k(޵Xi%wDŽťPa԰<U?O?fxmE*=)..EPr!C:XΡB:>[QV"" `⃞?}d{22Gs;2rŽ~ҕ"]Mf@gπ-,3.T*&Ψ}{r_dzQ\&0~D%o<1-sNX/i 'Ϟ(E_r= >CC.rSBr(~ !ʟmo}dԂjv}ob3pzT[aTqbP($5E?ua7߂̽m;i}RDy0ܮTQk#{f l!V#FNᛵ7bza8!Ε*`4',01ۃ7qa Ջ.Zꂠ/R7DնxdR*S4Bc;cn;gt'%'%Kb cqOGzV.6iw%M_i85YUA׆^~̤c6,ڡe)fْJ_icnBz6g,"ni.bўͿdY /&'ۘ ЊYOri*wɽ)0uoFAIB9tQ)"p@z 2E&X+Oq1wE/ 81{?JE.uH e4h[Op9Hya*')M"i4-!`yR>aL?"]i*M,:&ohf ou8|A?檛aK Aek!%傐vg9C@7` ,yO`ȇ igAfg/|Ft"dQڕLQ5xu5~ؑ3jJ@a ퟽\j \tjqΫl$dTd_ؾP7rCq*a3V}J ˷43FmLNp`|- MkBذ|nyxҠg-T7Bl{SmW4Sܬv^_Vs9kRJN>U|[Iåt*[d@Z h"mE3ftrL xm;\Pf8_H)D%r z,uEyvq^kE|qjNwњ v~>Xo5d Jgͥ„,dhK.0ȵ|=άY#(x>k7cҿC]HP͇#TEM$W~ʭo<7@+q83fɄp[{BP4 c"z}6F+wxA!rS-x w.,g[V ҍ{8%<9Gb X;Oq)]7GʽJ~ ߦK=vhM!hYƫ]rvʤj0胈Av[J֟B0+(LfOK(`="KE:P&!szlZ?QKǝHo5>"N/X={vgq)XՃ0[zmi)[Q^F\wW_y{G&dsYv,[L.)A:`ᬨht~ثLv`nf ?$sFNY 8,y36Jd@5?Eԥp b.S>3e{=G5;mb53a\H%*DSl0OJm99ZhADUouشw/p{L`TqbYgKFriE \aٞ袭e-U``. ch2zq<(C:A$s`0&Mr0%T&pP;xH}EO Dʣ}銪̨y8U>2QĻ#߅曛2`!g_֪\ |L4 N8(s!Q1J\U{l'FhixZrL5 jեjx D.q^/54X޸prM+#)[.+]PKYnQ#_pʒ/ 4z+sR߶UEcz$r Jsb-L>p:́J_wŭYVaic+\_"C_][8+j@yQ) Eg3KS}կ! ޒ֌KJd^U. t"<^iÕ[t͵SD7m8ߌF|DOyâ[!diͰ,nWz!Lkܯw JI4-V6ZH.T}{of2t}p V+^ 㠫^Hc['3Gsh֯XnAdw ^g{ nzt5GOKm)*Sf)n3ϫ#Ln MShj>F*U{x7o*vl#L `R/dkԌ9z$qpqGސ8frLuIfƶ&l.E؜#DD{eTew&Z6X|oWL5h y}Ќ{p|CQ'W XڕvPn>5Iud3<6eNF.AOLɆ Imrb{2dٛzN0Wev_:Njw'wl3@i'k6œe2D|?}ѯh[C8v\(S# cԶͶEc UН [\ytMM/`|כCq~5v@4Qt:NmxoZV+Ul{JNNtxpN !th8y3&7fo;i%{:rpCu$\{6#v"̜YpE DૣkF)h fi(P/vq(kЄހAUS~x #eryowZ!@md/Jp&&z:ʌ2 7dfZ@n׬~A9luzܾiCMzRBm -06%ڼqČ({J:U"ykm 0KX9=ּN)9 WL~Gצ0Yl2-;:,]p4Y!D NۼL0iYQZ@4Nci{@T+al5kpXNsW_=U[ZY?ln'A{Ty3$ڒƳ`=ƙ:W߳)*af -Gwq @[F+TԠ>MJoܒ,7Uu G %sh=c(%j9o8k ~?NSg@y0#{Gz""38\]>&6;@KJdtTQaƦ u; 9jɕHaO+Sݡ!5FSAFlZGI'V[ 𣨻:&]2QU{€G*Omg21S14ݍP&N^m= K]qoą3 i"xkH wߺ` ߚ n1<ړ+BҀ򼆾WM3g#&ƇfA~D[2Q 640Oqc#H/W 2Mt^zUHbJpFdF Stfb'fJ:˱bK[PSCCu<$NEs(G`J_t@n `8א)vKY'pˠGR۶;F6s6UW5&} ;ƮȭDyLeC(ץ"nq`rbt=JQtjlH6V#A>|u"_ 2_}Qm# ~)sVպn'礻$ )=~ 3뼉2pN &_ЛQ/\/0}Xj swGL"˵.ocCZ 7'١ݯIǼF*P0k3#Dj-e8#{Pɶ!%U 2Ll1ÑǨ%dyA(NY[Uw~AV&$E} cȥva5tuQsLPS ±uZ c*NR[|ud&;UH8%hpi BW^\`1MTzh-`fGg/NsG]S:>+ԼܖQ@5p㰇RsIcإWy ե:L7{D/GP|` Q+KOIF+[d hЇL;8ZƮ,)+Pޖ|8LJjd6g4ެ@@J6 +ӇFv%XT" `:k/b8˚̒R=jTuQjB'~PMN6"u/|.+`:t s"O9%j_y-j*`9+W4%Jq[wUΥ=(N4 qbgTԃGKvlgiʔRK-T8R%xcӈTT&HO0RxH׉!'6[Ti = ԧ-=e?<~ΞZTȰ&Z7I.|m gqBXH{8eLSkJ,G 0Y).|t1z`ۧw8O\.OIQ 7Vin"؞Kjy' <'K3ƀ 4ΈamTMOftH.) hu z`:V ,{6㜣(e8 afElzLCh!a)d[J솙] -RRnB }C(HmC(-NΌmMqsg`RR\u`mՅxBKKbͶx6-bUN rWH< -[#$g4[9^P<♛m9,> >$n~c> .\ய1ާK$=nH}Xʷ?:_`I̟ +^ab8 δguBq)=ast#x?n&t6LwD;jBN$`=,n(v}jjd %}[w!p=Tll;D~=VW;9 $1(` #Ș?'k﮹r)6eD>ndPc] نn%?`/rڬ!YpOtӽ{TLy}}k 4 ڒEZ96!`&Aaah~"Ir%MO,n&-ѭUxȼ3v[7{%@üBJ=\Xy%N(ݾk9vle{52F}.eyTF ''8/i"(0=}bnCZ2?HgV F>rB!=-ԙJPԈu*0{Ko:G׳ #O 1! XaZxD"wJӰ1f5:k2Υ+8)䦙у#/)#ogؼüI(o|#|nhѣ?`V2+7Ӷq#, C:>e#nE U)>NK,g+JUUC6ORr~†51ĺx=܇i$v5W7Cw 7[x+A)~uEɥ rI c!_܋QR2EϨ73TB,;*7OyY2EDap̆ `B$q CD-Dn_QRoNdFK'LpϲJJIfXpdQAl0$Lɐ/W9-FjW":kB?Amwu3)'~7*r[;gw̼ |騘[o\s}\ dFWP5({X٩yGc||#B43GYFBK]cV rSaYfgT5WwHړFy(q]y#"+}ߠ;CN[KPI4]EM*><ݩ;S<]ɑh@##ڧ99IK-E8c<35gқhJ>qօ+ QëI9mԵ!cpz4RAV2H)UpNco\9Z_{T9ޛ6qk\G}#vHz(>-'?///~<g@+>2 50:8=A fgrFp<7CεXOGg6PxBkDp﩮g~3y:tg! E1(_NB!v|1R2L82L3Z#ۙphrkɂ"Rрem(~Džz =M&yYi{O#7wqk/4'S ΂QR%FOLǝU ښ1չ@6&]\2T팰@P{ѦN-chBHI,=㷏 ~2܄ %S$Go~enB͝ J jAuɄ:4 ;%iݡy 8Z!P]1qbV|x‰E?yk`?WMIt1=gwɸ} VX `7XtcILlu}qiQ 4ɶe"6W}&#.'@:`o@T~@4,5!`KX 5'LДT"x}7!''w'xQ "}lk-\ lcɆmu'BeƷa059(uTO5R\AI4bM"ɄwWOL ֛v#FѬߋ'ӅDUm|xNX4!EV=Jr/VLZ{Tx[>྘*S)aM++mjyr+}g=|? ]_8 2`J휡:*MU& #=U#C yRuΙZVKֆR9AID+)P^{yP"4ܷϠgU~>X?TT5W]Tc˜,'ݴc-C4'vEjA ==aiߑ!B;g]"cfsiF3^-.TwmЎ}W5e,5䴧MVݟoG}*>f^S3IJ #p(Ҹ2/!bƛE]eHrܟ4*d Qe #ѥV'۰#(#%Ʃ]j!ޖB{kc~LngL? fG\ԲA$w cF˹d2Y2yƝe9rmUyA))Pk+ٟz!SλOsR[R=Q}fEukĝd£F Ȋ{HzJRJ4z~ul&MtfVV=}y,Kß1RD ү֠M:S*Ġ\8Z)UǶ1?EIP]/QU(l+r$r}+(͈0d1;`؝$P.$:$ª/\tjꭾsk:6Y J&sqxW%SzzKHQ= )%)'jQM4%B=>\+! ̀&qzґTJKMGyGy|,dF^π$u=c'\F~,NӹU.I+xkf\xQK̾(sxMt?m-^OrH1 bXqZTTj`.>QmbZ&t A՜4D8jQ o{:5c|VRސ|v!/)H ϐ0YTQHS+!í_d6\)eYµr**E[G_?Xz}64X FC5 >{H.RLm̙{}O#Lv՛*<Ȓ-2<8PHx']5|%:s279r(0:ҕ-Vlp&fΕE/< |"Ӏ|2͚\캔]+8mwW%Cٰs럍y (6'A$nBl8 6˩c@=2wy4 tIyhfgÇlɬKON;nqWX7^YQJJ]ywD?eУlR)tÛA&A`N˸.b^A{ 0fBJo:$OvG@:CjJ?lK > "`Koѻۢe7<oz@ߘDOMJRa[`M j^bJ9=P47vtV,R"15P;}k嫯!;{&{OέX?aQ&4LBۉY\4w|>iݤ1s$h6$Q?= ^3wCauȭ ]繝0w1@~kNnQ?"8*+p<@T$Q`՛:TΝī3<;|sj{ <=\ DRә+oqתlhSb HgL`N^O:N#!%yDŽHLU#l3Jʔ-'MuWZw 8nQ[tx]ÿܒ'irj\m.8?*# jzn.?C\/:S͟:M^2%P ` ӷ矷q}h1h3Da#DY=7}{83Ӓߐen?Iy@g;nV+2{4'Dc6\Ro|hXk =b ' ⑤?,(w_7]J}K5T0Arn5=ybkzUO84Fkh%лRw|# EjbWH]6Wu@'dL3x=,Gd%p?O ^ݲA5cm)gB@[QCk.K=Feo{0J8K'Y(!{a%Lغ݁c)%oUz&l9τM'xDb>5M)$0"RL-)r=2WanL;LCciY^0# Y=͒t6ߒ^s;5@Y7/7fagĜ .gO7)wJ|9CZQe:=\YH}K,;SC0Ah=JZ!QȤ9Vyt?|㻙zVs.֒0/ؚq~Ell]q)џSvؤwA.c*s8Ui)9vHz; Օ[Xp,Rnھ4rcނ册H?[rtNf&2MqWC ǀ Wl C;Jy@^ht!] ۲6΢OqDyPHգ45\HVZ.0$\>anfܖ4_Q ᡹ƑU->FcSzNIg[b4gciH#xe>qm҈0Vזx-~ i:G|U>qCfɎ~$w˱a4DV}>_O_ 3GhR.e@kڄ6sK@+ME#ʾQ&xxHB}wGF#nӑ hS-эfWպĖPAԟ—$y. cxQ#; <&a +ĪZj%nk(2fSnM~GjHGdaߎR燍uk4k7$ g2U!V2T)ݜ:F,?^^s WSD Q>YR?u6M8Wa`6/:0H'j4ڴ|>{OԔM6vO;ۍt2gQlP`#ěWszjd5j; : HZv 9z.mP48N&4[45~Yƨ@T+8'>L.f )x-e>hXu '=\>z$Z-=0 ^ JܤlҠ2_Bg̯h ٘wL|PyptRB_Oy02ZqGrqi(XpcVW=!z6PM9@?unT{ 选E^ VFxX z~o/֝$ɛ#c!4] 4},)ݞ7D)d,&gS˙0C&K ذ4,T1!Y_3+~;KQ V5.X;UA?\wUˍ찤^V򌾦6AQg{$ eH1yeȼ}" q=J8 kĦuì|?ؤ)Y w ^Cy'?|'I>N#RԚDL ڔ u| V#d-'lnfY59Pe3gCwh$~yR)?"?P E^eM7dpA K! iGaI>3:H5)ytqv-69<\tw.g) xܥЦynETY`v<ek$HgLCp-W$V-kAm%JiAl؃nONk[Lp&5ZAL3֡1Zln`tO^ܶIOU-<٥|QT~V"r/ͽsXMÓ]3+k 2;!ZR`.B߭k9պs#aONb}Q+?=;|硗qCM<]!Jۢ࿔AIzu=~ǂǧ@wZB K?Egy/>y%mh TF3Asx }#4&O:{M|mf:TD4Z/$aX'4!K-ΎYvaWj-o#Kc@ RUv͔,icQ+ ξ&YW2!jO<,_==Y#ľ"rT{[ H_F¦5CWS .)gj :>!G.̱P&ζ aJ׆P#ŵߠt?*G5?dJןÍ0Wݲr`vŸˤ+b:mKwc mJ,zQwvSY d3 ?%:Ckja#B)fOD4I@R}[#2h>D01.D]I^ve5Me-u4`λF&JҘ5ݤ~- rc& jq կ487q@Ķ a%&y˜N~6ƠiXXD{*,%\ ,. w}kF"9/D%H߿Ys1va,6iE!z 5RcdP;-45]&Ǔip`Ɵ;:eu+YQWwB3ŦݠG.U*XG='_L_0 6'}KZz)!e~p d8LS-ӌ`kCP\'qx)xnà R7I>{-ۖҾd]M噒f?5̮d EK@l$"*ί_aQ1 [z3F]L-%J0oKlk?.Js9w6ldFp+ 4[g ćMj xqfV !3U {VYguqhG! uOR~;'+ q<Ԛ-O9&ĥ2Bv|2许g5,i\p#ҟL?vmpJ{wIpKnYY?Lػ7-VOzO5N@:1଻#FsK l{qҠP#(]gؐ>[4x `fvUdԩSM{rf.! Ϩ2[^Bglr=(Fgk\䰩~ҭa 4]W f 6=/O( t+*Io=1|?0)?i VMQ)rH;/$M;ѰNK9k$Ŏ>GHwuHҒ;mc vz빟ۿmUH%5=6?Yb9D\YMqZ]Q/z{}cz'%1)]˱dkɯ*j#}i*l*ڞ5K;VFv`4#-# C-ֵͲ (Ԃ( wF&>pYџ !(lt 6Z`P|!o ׍F<\ŞF]CpZӥ,P S1Q@BaYcz' $h|a$\)x0фLQON s*jܤG,"8|RrjƹO;C{`M!1LQLEڲ^Cx='ǃvh/@^YϠH5=G0e7'18ORztHN6ٱӸH)x{ϪL7վׁNW:ǝ0'FuW06ӷ u{2bm P8ԢA=!T EAu,`]Fs0(Cn!Ǎ"Ie%42jsOUw/[ MNht,1~(CM;9f\e rx3> f#enҠ~"剀 .Y/Jt%8ny<5Y̾6zx`"=-8fڕ&o}U<wW|}_(Ԅ%"cD;)7NLr@Uxrr-[C\JAM5X *;}W 0q]tXq (즈m_v^kĮh&2$*I\KnWx7`b3rf;tz2+/ឋ Gގ;Ew<_TBN aF@FĔH?v4JsNz$74g%`.dC9LIHB}Y=&޻ U]Aq1LHr#U158B ;j1':q-'\=wH;I%V:4Ƞ5[0BtG;L͗&0Z]+0S$\iڄZ;JjC(_C+h^ra[T `w<L/-샯]@l{m"0U0x_`;I͉>%A@$娙F2N˱WΡ SzJ͠vyIi!_;ƅbCCBJ"醯m c1BRlyp*`BI#9Dݩ$и5 :W"[+lLtLV ),MYvKXIjzŸ!v!"<^rԑ0 C EOG>4P◥(;߯XVω7[yʸVDM2k=b@<pQwuCz?1GOA. 旵o&u`5x,Nd|["f :b+?8hC,Z}pFY0;Z`||"h#1n옭`0NFBuusO#ٌ5$S|)T 7e cr齽m&5I,6ku.A0 _LۑŁ<%~"t4ojt<*g .>8#,y[KU)a%K~85756*3%)F*<ܢIwq 4g#N;%,=yXKpDQf}lɿ׬:2`/V5kŧYn=gua>a6=$;9mKƅ3J}d6=Tl0k5:HZp|R0]a26ފ˂޴QTӠ?Cj\}h QCa".-20^ 򪇮20ߗ#yL*qՋn+w$jH 4P[u/@+3lbFmlm-㪛5w֮j;Ł7&nu8"026nhCktka.ptⓠXNbQbZ|OXǮ?xB6Ǣ+f7}fY<;4X˪hq'>G/ōͦ%_`fs1xMɍl;|Mfi?;),).RߏVDXFdp:V')S`9^wZD[ndx\*DA2GMKgB`!4. !U%@N6:?[K]0!0B !ظ_J5E ıZ\"Ù̮̈́"msYwO;D=.[}ݺ˄Nٽ}tv.`+< $!z,iw?8fzPiN ]Ll ե01aaW72 ,NDvv=US0ӕ<CY^N'ކ‚d+Cv"xzOS_6υ!!%l\_&[`+ 'A SNc;8pP9khJjߵ;U#s\_e߱_2x>̾d'& A`IhW_6S`J9GMHn0"{!OV Nnh1z _~{^J:V /bQHPVE 316;>q|2HA 91DuhhX ^96ѮP<+~e=;BDVCRj8sU.bH7?p!;$6&xosB\^="&T5v6E؋R C[DUpD6i> ][y+1đ' 0{<ƉmMY.! 'UA)3+-KU<Ӭ+e'4nګd1b.#p;:j{N+ezA@{k,>>׍퉰c+b/jXڢO}&*m1|Jj\ܧ3*6/T#`n=o.2.1mt'рjܚ wV E\>z0\z|:α='4g\, ^D,S~[EI8ҏ<=坆8:I´%3@L ȓ(.[}NC(lT 4" |6mb3b2 X&DRgd lqƿh5h.7.&j;@LRbԤV}Wep"83lEHFuA"~%s:{8UE@iPU.qߗwpko(h)+.AQ*dud=QeM@t^fQO %PzzulU?Q݀{緿t1^}0MɲHet(_jZc5ɿRe]_pMSYئ{pHٳs($Bɝ$rlz.uIzqy, )(ޞfs+;ir=]UF8܇dO5 NxO)4e+,AzbaAՃck$d9+ 1A9;g~YXhI8B⎸74sp{{!U^9xu4Tϫ4/գ_OH-/ڑri-sX W&?/m=E\cMh_ɱ!B$XCֿKU^K˕M-_fsS&< oq!|w"|JBP #0'7~no[b0#ALfT #5ձN1݆蝆pʚӐ@;mK4c1}dcxjN_dQh9}`G6@1!_Q[x =.K^j'zs2Gs 2q\v2Zewt\Y+cVE'Uu#a[SvЪNǫ5*3ԻC F𣻸n1QT)2t9Ŵ*&D|'H ]YdjbCtgWvEy[u\^%q7Pr ᤏCzA{cEE*40tW,Ddª{sfXm{htwwYxL4oYp9_M vhe3p?Q}">pb*Xe1O"@U̇:m$$h2RczΤ)xm}t:q[#6 y1ᲮxgaZ?jN%}aUSlӊ\ !oE'TxR$ ,6Qq&bA@5P]DӁ@XEoHbPRń N r,Z*ZJ/N =ɶw @G+hB(4q 1:IzN횎 PX:[HƠ1X:~wS@}jC,9nd[Ls*MLNЏpʃqy{Ƈ5j,J&\>2P6SywxZQ&F*:졊A66Q\ _n٦8G)8tz傾ZoDa[d=Ϝ'@U-ceADFm\a0#Er[|DO5x:#'EbwTvh/) 7ȇ"+:cZBdEҘƷ&,*0wcc(,<='^)^#?6N\tՓ7BIݭ(3lYx|'fj+yΊ .?[̏)u.7va$4drn$jts$kjXFomxa\L pۄ(a;G ajbK/ֵrDzON .᪙ t \a3Q3e!C{/^"H<Xx:m)׌#/d훵[qn׽? z# o5}_WUC_nP9߄6i30"zynyբX~ ds$r@db[d\1CukAb  P>ږnқ6:j4:R|W-0$ue*U=^T f=+%Ve e- ʼn<{?=Gbw8S  #,mOLgr6gٳQM{=2p-4l Y[PN[ 9 ٥N=fm陙,KY4 =8$?Ƞar2R )K8Yxb$7l oV%j42s {XLN)kXܽඤ[zAn%&uԒW]5b{bDq4b@CW |ܑ߬{a@拀@t|QC6N|=a Id Q8l֏'z CiVLfZdrYj/?]ڦya1sAo/6"}b91؝k1eo2M"K^3,8I>rU5e?MO [\,{۷aM4BrĂDtjjm5(!̌qqO aW\CpQ,&~#)GrnE$(&(c~u  V5@@,S{SWh@`k\8R dfhM B^Bܢ@l[X4I$^B1gr6QZ(`%5o浸pO IYc*&6SI Q*ߦuX}!̯j8zӇBַ#2/1K8s| 9kQ˒|srh_~tNK24bo>!ɔ"g Np4pnY_>Iuє=$}t򻂣SDM};V%`&{UJEZ^W[eZyfmMd/!;ez3"H=w}iԜNnvա02:I䵯O7ÊďC9͌7@i.D ô+{{ΔjAwQ;3{Tt# tGDsaCB٭r8_f̑;^ik@t] h+uW(Nw5$˸'k( ^D]M*L<~GqbFo` -HU>aQrȝ0l|z(*YHiأ ÁmЮ! ]sMFDLUĪ&n#0нd~&g,zgu>(=W3 O7c_ғ(an.=1i.Zy'Fmy".ټ%6y?q8u\T]OzhD7#qLV[EJבIL5TԑJ#,G$gXfr|ؠJkgƗd55^{iDpXH)zjGQ d'-EXJVBm*g+6\ twN4ah_nj'JsTh8OlK}#Y ܵτ_>g7ƹ#<{JIJ׋uNS65 쟋5}KA`dQ~~SXxU0qN!0ʦ >h|];S3}t3Ɇ;Ku)jƕz="vijcBɫ5]K p`,վT6ysBX/OʐjHg :@'^g'*dl}xk|8Q< B=o|YѭΗ{m3 Pds[ +9Ί?r4]a.<صy P0GC־5#@=axug6A?\X`Tu o3> ڴ,!2>3,5W90k k4Uz̶0Som4B`uH4t"vI?h 8` LN_ *c+нvG6nW6qӿɵzl5]USmD)+:ao>ʋ7DZ1生H0Nwpȩf^Gw_RH$lP2 ^>^c}0_ZI*)y>N6ί128n!^t2?ũMeERY+I1 a}:p+^)7zaj4m@/1=]ЎZ}4"o~yy%W2_T W&,sωdJ't~R>=,!q?ě<`:d4.@W\{LYEփM(1xp^v=8uν6v.esz801C]'dk >#Mz&Ժ4ٕc߁U+i E$~ǡy0)A+Xe1'pECwY> (⯩Oǩ3Dp\G⮯v 3 xoªZfTeXtl>yeQDlc;XKZCo4R#9x5XʗouىZʅ1!r̴ȏ!Aa%=ToӅpE࿩\؅#_$fusꜨ!`Z Z<#x H*kH f*):rt+|XL~M>[pC?:uhJ?A+Zl9 SF LЪeюlAL򵎁77v*Re۪U&$⭷ZhQ}~/i44޶jŽQM@(<:ަ{{bvH(L2||:I$boA( xq) ڽG oE}@{Lh ?m.D[b(T}O}`Jl?1-[ʎq 391m8~( =+#N{iR4 #vҋ- A kK'ifDg~uVH7_̬͢ðcjÞp/y7d}TPU_I%ӶuZ;.k"^ib:et;b ig{.RP H()7߹jz,f4c/^xCHns"rsgNf'$PCS5i"XKwCT ,-A!msF`1e)$ Zҟ(뙎W"BLmXOE?s<8`v>]Z̆Ǐ[E8XDʶ- 7/㝣OtK'DZ`"NyWe#0T6Gr #R3|MU\7H%N{uyE9'N|S}|eGBdFDUw F}ݺj0z$W$V='5<\aWEj83{%^qeޖAuq9\"e+ "ps8PL2xJ3KS:).>8LHIYa sN9`~ЮzEc~#,~Noi+,הg*J6qm!~. YS[KF4Tښ]t]ƒCΤP}: ikRa^kY5s 1лpgo;׿.d']8gkJmb[1B UvQ Ԧ9 iSˤoQU[;x윾^:ElLjAPs%j{h_a|:%~Ӳ2L=5̉Ue16 xrT8ŋE$!Bh3G]>.-캬holJkʴ<^܂_9\Ԫ{Z&Y:& ?#>t}pxLAt':$O:V1\2b!XrE,1ijTb_n6l=LJ56l^8c!ʴ< 7Ωj)eEOs+:}Usubȸb.=b 27Y@ gp}.+>"C &ty\A޷ 9l-By޵ա;coj0Bt|?BO1ԙ(Ù_?L*J{VDKБ*NNA4NzՇJS'~]P1զvuZ:F۳&t}ʩܑ~rH J } (ǯCaTJB5$ :z{iXVES!ĀRLp1o%GEWvB+̪e?( #]P @.*zE30)P t ~nj[&hkOภ#U4j3 [:l9-:M^hԫ|i;〿3 Q?Yk q77bM/ja—/a~ F~5,ZoaMlDuq=FXTJ(١?~a:^b;(%p8 #H\샵 Y8?ʪrR}q`ěeAzXv:B 8)9lpmQb`X|NB:&%h չΉ ܏-5Ҧb>9(=fXA^}(&N\:Ipqv:FHb:(.`GcVǓk!z&k ×BYJߢG1YIESUZ!N58-,]@7`x`DشtC83%]*-, ]xJgۻ<~G"uO zڷmf8`SGBYUUnJ ?Sl %6M--B:)C5omLh̳ 3R|dlH"ΐW."1BD5Dꏌ}V? ٺFc_½S0/5קvӈM;.݌P۞Pz4"\X)<ա!N@$w)-kJvy:s%;%' \Ҁk䡨9IZ@l w =LBX;|%#+&#'/u(&i a+j#BJX-Gfo$cPlO/мE˅jbi( ptg$*L3 g?2Cx\Ʀ+-V'$E)fv)Cc 5| ASY*c}NݾiA0.W'Y0LjqY<==>P!p/pQX)Wr:A"Q!{'A1gΪ\ ) s%ςw7$F,) (G5'TKTuCfHʨU}zlYPZpK*5n~%a.al[Qa*rWvmн$7tjA7(':27 wQX;.ʰH%ξ@%& W֊@]xG7Dk mY4wxG ^9f}+V;YMk6AM|Dz:̆"};.szw篧~ڵ~v.:(qe-*ĦurS}dA;U1E)UG.vsE{ LZ?N񾜔jJ"o-.'ڔїEr;^~8q)lCT0nsݺS/&׽bש$SjZȚ0u 8m~nًl0\NR8ٲ%0}p<4%Q=d71Se*L XksƦ=k(ߒ5!e$@3NI/!+"L3ˠs'r_ɑernך+P:#<1u!P1Pv6! N9;\O]XѴPFD5A@.'Q Z u Q[u!ūcGm7nJS}+ټfS((~ek| ږrJdӖ,u)q.8f{mNjtlہFzf}Uu6Iy!dZ!%9"뚘l^Yuz%J#~W>ftALB8RK2#a/Z9)t*:&#.Im>_"Xy0h %5ނYtNzsOe|FB )Kj⃌_f_z4"f`J ԊEV~SlCsq o^6or$3*'Ӂ'v;j2=եĄU2M0PFXG[_{%MZ1Ń]_-`bz1͙ f7[29j8 &-kNEɹ Ց2Q~*QG ~b>vvnxL2n1l>yL3=au /h5^D4XcF" P)ąNmMp?(Rbh_$em*8-ősQ#3:%߶8n Ɉh.+/lV[^8Z/ƒ@syZMۄƓ089#>o/8Gizx/0k.M4/dW%Eq`PWJ\j1YBzzOƢj] uR+gBzgHv2|ʰ66hcOl>Mbš_)P(~<}Q#´)e E,pV)/qnӦj-h_ͰhsNGS5&^Z7GQc5 [7O\'O`!qae*I hWl~HK'rW,w[[S!~Gêzy_LW3[5D.f:Qē }  ȁ?4 jI*^"7 PUAثvx͙țk;:-;?{g&oAdvT<.:d@Y'iM"0 %lujc\_nRQ+N(szBIOs9_ײDv!X2^|` bumO,$SU#oDo9NN27@;A=`"MrMw.=6P!gl| zH7sXgy>Ģsq G kc@?9F+wgbd} NՎlqQ:7b'J}$\{g7U!QB|Dp2|enۥzKH,]$Ax ÷6IJeᎠzdٹe1j|]B#CfxW")1ô+ \ϜOYɶl~N6&]Zr 2#]rmew-Y$ Q&VЏw'&;iʁ)!"nFeIɠvP6y=?1@r6 !)ZD@a`s,lu|8w\`hJ3z @_9 ;]p.8tn337q>D1p332("d!^gV!{)Yg/$tt{~X-ӨÌ c`\p-|@TvSȗ0d٪Zqhlw Bb`S4,K4W>uJIײ4?/Ry-ҦnIWIO#qr_9:aϵ;օ 9 FS~H4%Wҍ*F{ Ky`Z7pm\] ?cf096sF˨*1ч׊Zo᧲FblΘ\g^hgDp~"~ڨIvYxX 벭 ,ccU\HVR&u&RӇ#go뭉n t#ܠL9Jas_/^.a,o*B[#e;g1gMƆ%ˑp[閧6(9$IIq{Vfj3 gLMxxvj9n S]W(vXʠx5[ӸᷔЮrg3~aUF^?/Uit!{#uԛ/x"ĖtEVWWE.͞"%=iSZ ]/`lWR$Ic6xt ] VzYbπ)֠㢗(zs7ez/k%;oje/s)}ȹsqZ蜈?;CCrM.չ Y wo=д,먕 26/Fb˙|nhJ T~>a[ե;(XR Ud!+txQ/Iϱ'4hZ@:WY<\S]N_e 'mæ+0vG0]I?3#=#Jwl"'0zTQ`Zn<ڭ# ߷J>){6*Mk 0VR^8cӸ6e2c;@kP t<œye#k>،̎>ijb5hASJh*ɟ9\״) fg"C#c5E_ HtY|0}74=ҏx|NtNog \lķÂ4%K>75WW}M;WCQ֕Y/!a9l仏v=y2QHI!Qh{q 8C(PkpD]+Stŷk0W4%DL0Gyd2ǰr%.9l^ \QߥV=S>Q` >pт/g0(65"U٭Sqn] c_WkG]4蒾҈" FF2dt\F4R'|þАGe ]4U4牆gjڰCC|hl8ҫ(xY|vsԥ&C"u0mC[4qo⌗PE_x/ˇ͓ i[X.$Ϋt`/+!nCM)e|.c37*VLKDx *%4uw2]|Jp m <ДWOe% < |s~vº7wiqp$1u^Äu Tֻ<퇶 %M'iY WcoOd^ SA1en==IC,1:vȅkHX5 ҭiZ.ت~ 8cw39#&V}sRKP,ogwp*/ `wǍdfp,£<"uM $@u=̤9)* O&O%,&4;@:B!yFp.|'@Dg\ޢ]/܏l3+!SxUt DZV}Q֫J ]dOgR)emmբ(@4YMK}r3]OS0i~Gor{am =~-=1+! !NDZ)L;.lw(FiD6*@º~Rr@V(3OT%:Rk@!~6Gh$𣧵I%dF{S[W[VKl]1<xr-k$c26tpCr1F] &%y2hfưALb Q*5xASMG]\533Yb{3T"%8a:=no/'LO^"o4'O Y aśoપ8,$QI]S|6@Db` sCDjNjRS[(ȧDs `Q_1Mdz- HV4jܟ:чamE8ͭ]ګ{BGy˜e. a jZ˄F"eMRS!S5yOo{qjX[$B~*m]L'rw+M ^Rv+UwAm"Dׇu+g/Fٻ[ |.):5K1t3ek6[!!`T0%ҝg6Zx,(pji(:ZZ_M KU`tɤʰp|"69j|DeSM6.gdU&h!J@b>1#,j]'[e߬ ™r4t 4?JnXVChjtЈ~>7l\;EM$MܰܒԺ CdjL ް$u*Bdfc?m DDRgݪ<[~K #FQpzǒԘf!.=遄Y.[ @yWwU"LUH9醯A~Ot჻ڎ~7ɤo:bwGi[hFd;t QhU64:tݞlz~}ب5JGP0!u?R1l!ӓ) j]F_j1T |v E] mj !WO*߽CI+m)w]0a8ŧدD ԼU[t̿тɮk#6RP{~7`ɤ|^-0w%4}y:%=g/p fu׵JB^4RVbk3^-͔BYUUl*?ӿD} Oo*/l=֟Mqwkڰ%y4I޴L_MM0>ؙ耲WlEM^ћ%ӰڝTdy- b_ '`D q52D_o'E4˷hb_ɲ<&l0e i*-{txE&5c#G${K"*掋qb)Ba:6.[!zhm9^'=:וᶹؐ;BGqk-}{s ڏx*FZXBQF1Mn l1G- H{[N*OaWmRy|p-\/D\<ۋ/4LrOxh%(?[Okk0CRH.5 BRAh C2)x4 Z sL{rzhHf_+J(ۉ960ۜa} 0MTG)cj Ƌ?BNh<<ݯ D!q9s*];ZBVi ⸩l}삕B4`QRY)@5|B ѯErY1/4ܭzCnxtivAat6Y|dOkS bQtHsYG?wI,u n*LHF*m͛pR)廴eYg:84>BE W#R/C7l\dLz\5ʄ`sre9eW-Pz`hfv Dn o0ؾdLjg++UR4f#X"쒡ՎO- q&R'"gbƙi|gz +'j߀]8Y#JbV%8cF\`qwS/ZU@ ,aIt (/=B9i{#đ/3"Zd󰠼ʝP|aфQJ\wȿ>4z8R9k)|XY4.{YMe}FB5BR)4KtE<8G48y)|O OLPds,Nho)R) ki$8N#.9l\S'ە۟eɸy&Ͼfcwɟ W3O-0H{aGC8(2hx_p"hcG*r!yFE^ /Ƥ&蠿$m н(ZuNºUWjҖoIK*[+ |^&s+~eKL~YP]E]¤k.o(S<\ҢA. 2zjg" 6[>ag1CYw4CnTC#w;76۝ZI|rׂPA8Yl銮HZCGT:at.*EY \KtIFˣOYdXAi{OI Sƌ2qߓMv`zwkca|O¯f=P*gI1\z=6CǎxV3⩌85Ek P51Y0g@v( D_Eh!aY۞ȱ֘/d3[E/ aÝpD-gյM6)EL $xJ aE|[*my+yu穲h<^(RmBXx LHm뉾yϘ{BɖK)dI |EFO UW1|\XvV ӎ'o={R 渎5`Fuْv9ΐ8h*i0ѭ3 ۀPO(Ix-<,ߎ.K֢!U4wiO\W/ejw!֤nѷkʃM*bi$;+8E.*y{mHA[|fOO6xKB%tΥk|ʊ@`ЮDGaMƷڧ3* ò8\tWa1a7OG&1*Tl*P(LytG ~kJ\P񔘟ŏxDנ/䅦0ڈӼV#]rI U:HMlSaH:tY0rNI4 PY"`ÿ-P_͸7ňX.:o\Zv֬ pj681]P׌<8 t,>Wq7Ry+ifХ;T8.( 7;֫T!ӭr/ˍ̫+wrdJXȍEIj 4ݒR2xӜ?tsقi=onj 3QƠqSR+{vSn2_ř;7;*ƢR]`>P/p9A9\kkgz>i$SD(ˆ[#1Eka\<="/wY"/|:lMϡٓj- 6a3:A#Dⲱp/ wimoa6ϼyG(k?x y']#ToW<ʩI5q@o4(,N@,Z/hZ݊uNELO4N7uFO)>)h Ͼ,mJa%)pnSxeXHo SCb X`;+j>%" 9~@96Uґn_bo9okau{c*D=t:<% t!4u65u+`9Ia]-"5(NۄR[' AZ4 `>tJaFF:eUo+ B%ab5 'DhD G?;PNȏp !x%DDlG63 rJv[zC#@ŴgY0Mk~[}D(EβYI/I#> Džryʤ3&PpْBk'#>轿L饶N"?X/G{$0D.[8`LҷY5)BHBHt@U;e`:~D4RDo> %!W-I%j> +t7oI U޸wDpp3VwEt![M0c[w;d` )TZi׿SCyU9WWߢ=$q-sh/Dϒy^ =3l{{9=J$^S[x| kW4+-Pu?y]7~@u< Cw}zZʔP| X~'P80[2Qv©V+6@B,rZ2bhbzm]fTmSc֒ŒıT.4wfMyd͗ټ!+WgPdE:>w%7"$olh(FlP%IIsq3hVpCV=*/Zj'j '!)v[t~뼔AKc20+3z~M4>@ %;%s_@$o.?y@Lys@00v[Jt.f57Z[{hX I6IM-3zpw )6WOW }st@yjW)h0Q^"ȧ@%U)leh1CcjrHD֤8<^hæhfϱ YT\5G`Yr.My GopÞ)_i*iHRe~h0BYa+]X~o>>" |=ӧ浲Ṽ>3ϪLc=)z~N<#_p*)a Iόvm{e(2&ێUv /,^td 3D}:E5ˮvZ]8U3y|y{Lċh>2UpOw}p;E_T%/Q+ i!8ٲ$L_B.9v؂؝" F|U#-{錟-&?u~@;Cl#Fa6MuB /WV`N炑ڗ|}0k9S%$_`0\iecjwQp`YOmxuEh]mi 4K'XEg#tt|Ʉ7)|@Ԏ'>}(jd2__&Hh{YyMma }ppE Yh%\+g/ںůnka.l.m4tTPk<2V[0V"2R ´FUk>zVY'pqXyBsAǗ.F|m RP;sv&䘽WstnM_1&oGq<($&חSaR6r$&E ԶY=:sAɭ6zf2 e$Gaoa/PWS~>ݕ3kntG-4{b(zםjRLE_/>ؚ`>;3KpQX`uӌq1`x\!sA7X[I?oc^8Ֆq EKs?.n MЦ=.WnlNa 1YOm^h\BHAʢ#*kV$)v?c8TeH5cTpP [%_3'10R~͆ARev-]lLhh_fx(X')׭%U\.IY*kʰ}(Z{W\ XKE sE}=O-a{H Cls2_(YٸsxSâ- ̡)}j_"o ~̡aXE\T ?h NcP?oׁ]#6O{n7 ݶ8N1BG ՛o b[eO_$' b @.JLHU  C:VWC9etcP‡[x cQ~/&N ,Yd)o:Kݡ sη>Bo]4]ځ/N *➾MNoC?{Z|SɈ=o0:A9 Tr=mL kRzM3dEF#IWCʣ7z#B14K"YYfqr.͒ڏas\: c/`*ag ع6gbK?i˚i8i&2X<~sC^mCW]MzM!PPă?>ɼ̍@{d /~OgfmLXOb@"vZfP#j#}ߙ*H(@`B<]\_tre=j|@AN31b:[R{Iݒ'WydKLܲn' fi 08 /_X{0̸rߡ$x#NQM|Y*28)uŭ/D_8gRþoD JmNa•R_h9P<0ӌׅ#]F8c04 δrQ8[D x9uGJ3 ;{W|%Gx }gZq$V(iûW-ڧZ[\cҸe< yQtxVfRAWe\+xRf1U=_I- 5(6ob|7A2{&}L-Cx[ fZXmi@.4qUP&O>0|w@*3KD%Y7G'+' 8XQ@-rOs5,er '+T~h${R+RF]]8";1P-3vc8[d[F75S ;*njdZ[T፭cAFӺY"Jf }`k+yP\\5Ay(jɹήUl⯰l ܦ/k$ӷoNI+0$Z&s1';N{"i % SQ.?7ib  fS[xmS)@? 0ٓ -_N]-'Am9_h8O͗@Xh[d{}8!I654waTMy*q>WuAѷ .x5ؓm#0>hrpIS-xO3m@6WgoZÐov w۴mcpGpz[9O[5@q?YO |.ёM‰gnnh Աx A.4ВgK:wm`CNTŘ`1F4nK98?m⯮q!vV+!Še347J'/ڀ|Cr{Bg{Α1G, `9ʔ;uOshFu l5tۙAzgJwOZZIXo˵/aYQ`?9YM ;*(UWx#;(_wp<[9cTOdxt:珓7U;Z-fqAᝆr  =@; U C6L$46^mY\t( j_\̳$,I0Pko68 NKAi~b..gdq IZzCi^+g ϜZA2jѴ)kF7I(w-1L' yGij3el#%#ŤmiIdC)e)J> ()DRq}n*P9|~Hqdc{ad5ˀ'IvD?@ 1iXm"fGgZuŢ:WkşcQg7*dsVN|}@xOcd5a T\ޥ-ZP>pN@' }c_K z+uo'i,3vJ\Shkrk( AN<s!B}PU]A98u{,/_d*twAƈ/צ9ZASHo({AŮbF|6Ͽ 8r%:/`6C}I]DPx0?[gؾaH)7[JDž0 #$Ja&{A|$Ad5p%ijաl' 3osР Gwwaa&CY Ұ|,9Ey6kO+36.hrwANis(9')!TX#dGfTs Mw;{O;!%Td)]+&J:qbКkbgWEtnǠrp.(m2Yxb4b(vS%Ngئ8;q"'̍;鯅ST'˨LXcl45,*81rD^ϡxܨG=ɿke]gŬn'are;kM$Ie)&p)fNHPbvI7~P"+Wp;D!웯w Qe#qK!YVN gdny"~!Px^5\BJM2 hUӗJEmgaR0qVGaYcf?0kP9Ĕ_I~xn`8CD"|۩_뉲tJ‡*MU3)! U;dh ;Lyq³Ǫ1'-$vU=IrԐ9 06r.An # T:9J-saI4"ˉ9kgrC#RTR#Lք1wkݪAz)Ggʣ1w  -pi ##I6"K9 be@|(ʾr^# @x7 >K=m`wj#(VGnroo͡!`"rWJUNEe7f?8w<\lo_i$29I: T}'بhn1>Z[&=fTG|޿ڂl(`)\w?]yq؉iM_kBlMd#HA;i枑#XBaˣv[2OZXa1p~j"Þ.؞0_85@Ӄ @B!1_zD)Jt1qoĚ+n#T f?+=?`c52i TzGh%`ew2Ԏϊ>HK/;V&+?3ʶLG e'hNt:b\2RL!U l'n(ae՜؍~CUK7 vO ٿ\. ~T FoeZOnH>wOF u%L1B@FK 2gaý|&=Yy=g+.ML4nJOCЇd74x_V:TNxOOXÉ 4(o̤LVC,' #|93(6eJrt#Q5(MXuU "^j,4': ;1V^uٶ-HV+[Pa "}o7 <fTv0Ȍ k]:w>?­mvBs{Qehll3όeNIjYeB-ܪ`bjҗRG7Ϛ`Fe5ꪙg

J%r@o\{1=0͌v%*|:XE)RlaeDŽ<8 uRe ,JREyG ؁\A ^ѹ &u8PŮ~.k] (Ӆ0?#>}n W&XaO~f ?/q{3vٔ-sJ]hs1?}rS-eM5ױKGs,DbRkEwa_[S4ܝ.޽r|;ySpGԢ}4\`O>9rgepID3{*%QqG- Pn! +TāF#:8*XŠ2Jv+NPǞH'6tՎ@"&$6$iL\۪")f"R{mEJ d%џ*i -sUM(d%,;v+&ڔ .Lb2(] R .ʼn \κ+6(Ͱd>A&r +Ɋ %csR߲< Ԝ#{A֍RņԴH).%Oh%uε5] ډ}PTR{*#P>W[SM7J/Ch6n B)CY+S:_6cSV0hXӅUdZZ-*=ī^5ڔzS7HH){.ѶJTq[Gb8$. 69Yu$]IWG;~ M˧@~ U{酅>B4aon\bک6' k݂`*5^'LTn4ڭYҡ;NT%\Yqd&Pf ㌃>`k1҂%O.+g LЩ.Y RqJ#V {lwΧoEkl pOk#)^=^Gl4LJ"odrlmˢwDŽ MM]w (ɫSf2 օߑHV?RAO?snsL |V[cPe:6cC]DjcH% vl3NF!R)zPJA#rWf w۸w/o":Y#G!`:Y6M? %fž&-ee&KptA:o=.Ͻ?+zӅu[XMP(}Oɻ+U|"(!Z:T3K7_,Ju?̗9a&f]ݧH%vp{k%􃾱?4S Ytk?uiys}w}DCZ D˓SPtfaTOI zͿguZ'z, amsd=7zGS+QYύ ҿ05߰%U' !5QY"#QOmB^Ƨ ɑx* .w< i85 s82-$Q N=|;/PtL{*FgJE.~XE&<3iܮ64ghg|80DSx #\rDӛ‚u/l}B40kUMnֺX2r\*;6.*\0>3r.GBs(x=(Ϯw=h|hѦx$WRm@APQ[0u)V{>_O7[͖VfFfyo>&D*QIU??qB Rr7S~1+ZMrAP=,2tttu꛻0׷P} ǪazHձ+4jj q0OL+({D=i=4qv9-\s[meI32c?{ >"d;Q-$hNPԲ7ЅnSJvu~ v:-~9SQ ɘfA˛C Yc7k/iJV6o[<[_8 s1&Ojm̓<AY y:Egܿ/}fr /,lOg mNuVk |t6/R+gX &h;o8|l.m` <,VW_$ҠZ>:zGѧ}Z6²&~S!"I̷Hc̴ʋr'gVF ֠;js== &J;;94 i Slx|I\˵әWV.GïY#WwDO5+YVrͻ]m>eJS߸Uʽ}q+eH R/~nLq.; EUHq#}gZ/Kϩ[|",[g0qnI в3զaK+sE;j3:fE'&Mt<[N뺭J l:\ŤW =auAgHgUG00w+Bf-Ǥ H,rr$ <=fnd_&`lE?Qܘ!懑-D;X"O_wpV0J)f KtFɤhVۿ\׌#!:n_L?ZZv^R?Mi6aS(!' Pڎ z.'a =aV(j5S"lFCEf7R]VZh7*{Н_RXhlk/I+GB%`1tYVMA8cO"@s= ";]>9:KB>h<(4"Bh3o<0{\ڨ&ySoi ?MB2JK@9l i1C@OJ䊕Y*X1&BU.MVA7 wYy8 /h.b @4@yNM0~M>զggOzp5rInj,O y༅I#2pfM#l>f/%!M aOBƨ=Eʅ;ƩvgL]]O*=wf꫺j̓(yV3oу|rIW}hzT)N˱ӥ&_C7='2s(B䶽"FrC 8CYsxdvnwI74cdzWuz ۟f焹2x_},¡U*cCz JA|R[G .(g~3m!yˮ \/5 /Axour{% 9Q$ K%N>|Wm]I^%F؉yvJj\3bqoY@\@);16WEjy8@=YȠI zÐOO MtU9>&U7$`MD{NgCU-AD68GhCIo>o%vK56-{"MmU) ͨ[5L9+͐1@.zSgqHIVi$=O4$RĶ[ݬS;+0/ ̻mBVNQ?S93G%%RuPnrv8VjG% wſ3, ;h;q7|n,gf lI f'2t >aؓ2z .SM>9K!ѱU, U"ro١ ^@(N=13^7<(/,/S~^{QC^}3RZ<ƗՅ&; +HӃx$]~{5]{:&M!p#dRyK? 賄n>xp 4ݎ֙BK>e[h4ELzu^8ԏ@4SsGtca+C=v-xTGnb'u=ST8%Ahq;Xő*6ȹbcg^gk \P4ǽpL*SUhiD)YDM0y sN"=gن-CUg-6׃٫Sޚ٥*#)OHpOѤEH#R\/6zƲD @K^ATt|#3|쓵1)VYOe1XpA_uL `Q #n.<;%o2'ӞpV FZOpl3KBY-2*,쨱a3;S=g-5B%~R %JHMs4b@ h.^fdo@d /Fɛa~%BՏ᳄R?1Q^QkZ1&"hm{9P# x ,ҧvb|TbIAw 0)%{l)3li C\myQC t<j,ubO}e}π{?=s"N#1P} ]YP#,l7K%] w ( 91@x4\/sALgagg5n|,-d%!P-[j@܍ chUM/ ׆ 'W;! E| )m iWo2y}-r+cGMzMsFILMk ^GnQ$EՅAb(zg?4hߎ4D[K밷X٩@N=i#Kn{&sZؠⱷvSԌ ~dژM_1,XlW#;:eu]٘4=aQK(HYɺ!)C$t_su(u%Bvt@bms SIzRTj<PUǬں8g`E,Gn3!̓87ˊvLU-6tqG?dRDLf6 ȯ"ꢀŠ7}Lhfbu<&iuQƆiT/9υFp1OǶtG XO:6T~?ULmDOCd &ył W?X&y#Ij[u],\x"̡> zN# vuRd|ec#;#%3&7{Nu-fTyXSJ0nnΪlmXP\KwJ{Y-SZ5ℙ1ǴkƳgK%MA)qro{ LJj6"fpf'7DI 4>]#hj5:hbl/wq0f0<ޞIF* U\DgU-M{AEG_Top449~kaYޝd/6.Eȍ~n0B,eT#ZBADXJ-&5#T4v.t]sx wOI"?b{/aW0{5g{A,=>=ę \It4-oӚ}la|QÝ$ˊH)8K|2اἸQWYf?-~(zn3^Ox]#r)۲Z!/ g[5 ǑM*>2ϝ8ُ<)gx+4t":,z Ew ,a$!H\\s]kU8],{6Fn אzV J]쫲qw}(xl@5[;W&EQ-(Wb;}azc{n}Ben%>SJNvxmQqhZ"z y1nxz]9 ^h_(i\(_#~cY`ǀozVOS#ZuB"cnWƹGj#HI?譌)o #UQJuف(7q6ldEBk{@߮Z:K'?JG]noy#;΍)(BPB֊T%q H>ЭXMo_.n~Ǜ=>꾓-JZ:/»ɰİ*f~w`\0y"F, Ki#'0Ҡwaq]Ċ봵xGļNJ. 4Yw3_Lzqa(RrSx/][Y4׾Q50Vl>4̈#Sxw򌂐^. Cb~P(Zrn߽g1&Ym PF ִ>v xiX/<5`,7 / nܡA5<eG8O#Q>#I:+{?vS5,ʼn|UM ?Cbc+ʅ/ ]t-J'#m!p仢`\Ppӑ&v)1u+gU͋F Uj@z1?شK'g^dO.5؟D(c{cAbZ?J@$ޡ1}BQ7ScO6o3` u*)*PUG,WCTfU4x CY5=l gEǩ;uY18($zXĽ;,=' c4]p  /0[wXsZz*ind+a=d!(?@!0۵d>uqP-9iH06;m{ η a{h!ğwc&nh lmK)WuzOjő5tZ fDH+Q>ISǧyfm*S}JpR',,̂פgRqi˔o$<$㏺a ug-QZn:k'—Yr.:z5u{׊CHPjYYC}HDQE #Yʰp?+!,2_!9@z ֯T&V'$ʎ5g >J mr6橛5;*J>$ӺR˂DVRV ,m$M43 =uqP/ anCu4Ha QC@QTj~t4J~T#i>l( 4\7I7k.scbɿS^k2=8ۤBNm-h{nJڔˠ ̢ף#R9i˜x|xړ^/( eGqӧA2w0I`Ȳ5`NI{ds\u0u>_mrWʩTbU0!5usi.V &gBP"YtOlY"9# )k&On*ncN 9S[e*qᨕ,@ECʮf zӂ5p)@}Ij:&’X4Ec 裝R3*~`šu{~<"I|ۑb =NiDԈ3ILԤp:j)>#;&~VO֕tS)Nhy(3U=цۀfOIVX^~>v(s\>^擌PG $ Qvq=#]U4!\uj.]~ų#ǁˆs8*STDuO ?;գ[ϙQ*A_#̐}o1;gd͘I?]mI8=vV0`E?nĆWWz7N!B4cr<>gҀ)'6T2g\y<|*Ђ r>PT9b=nȠ)B1y~w.$^o] RPum;ʂzՁH#> +Cpf 8Od~b=:Kةc +OpxD}A@* w)^y a1QZ_ Y8ȽhVygƀ<tz2։Q۟4f ݰPw߆_OkNҷo:*[0B0Crϭ %FQ/ՎLU:אN8bG#jWƢ}N LM} ړ$dVl@ mP|dF~M7?UR??BborC; C7DQMWB%1bg9C`b&B6 #\e8"6ȱJ Ag6jiZ7< EĊZ@Ʊ ApeQ @Htdq 9U*@Hr-yq=5p+\ F&Mޗ'4'եDy|+{̡=e/RMGB))0IL尮VUֻhlI9^t;2k4+l5?ػD ~pEBĬ8 lSD>>5>Wr罶S @d=S {Wo:jiW\$rL<@ի\}䋞FX0D<0zTOաnXVA4ISR`Sͮ6 P"LK!^mu\,~v-zO}3^?'OPC C?Kp1dኍWlUjUGQU*2E:!:+\H[-S[aٳ<Rݝ1ah%2)-16ЃB;ߣ{iK\RvɊ1D<4bݯumBs#)R R0^UP̣ޣƑԴmZ$ \(7h`b@%*#ajÁS-Bvfȯ|ΚH/9bIXkٵa<Ю~t}20~|X^N;wmѧG|6A`3?a9| Gy*qd Icѳr\/؏pIO{o}M577ن`F❋+Z2kRCnMX{<|b]߉C!,K6: 8Pl(-;lY~ {w 'nHz$>g8 (maF9S#vTu'3.E~+/p0Bdk#. z@Q듽@Uz8ei>b9Ϯ*34h{,[j,T*@ ⢮.nw5T/a^&|E|8-U1ʮc*̃\E#r\&cB|E/+ >_Dl,s n1Nu IBx鮠q>'3Ca.<|#haH:< ^}76bRʢZT7D_-.:r\MUhG:aQ/ڷn )BJ#O~ 娴y&DS^Q7)+yò9TXީa kۚMc*0ݕKp o4]Ih6{چP83km*GycFV8CVj-N]&@b {0^Lm@#1 6Q?Ҝuoi֏=pDvACzz ~\UXjkd"*Uګs=]' VZO2L4g vle<9=y,Oށߩ{kLs8L³ao6 'ȍAo|HwuYU ls"(WR"D0z_26-? ٗDߤƛKZKrvFӇZ!4z]TXxJ(̼1D %b3.u|Xu&Ze_O`y`u1{KZf<ʫ)}>}u8߭\T3LHuil->sbnMK~Wu#4N &n̉zEx&43>1}$~@8.V gp+]J>d}9SW~T} n"<ЪʦkNP)I s4aSǧb,|AN1&|z vԘd yW{^v,l OEN7"5DF lʘ=pESLRZOU}f6ۻȈ2_6D=U S3I*$Fpa#^YZ6*?ӔSh>]'sI²wLaqG}v#䔬TޝW|Ҭp1_ZykjG۪M+IGUS)AD4Уm-T.RU!2w *#D[3̨IYe;x.okz)#>VK]Q"L>Z g2.-xnZ$&EOmQ Lt=L@ uTl0Zzŧű*,]ChՁ ]Y++f06} 3ܚki܈3^>;NlwDk/db@V8 T+߆">3lI K1t4q8[$tK/R"vv!+*J{6 Qעܮ9-l}{460j"jMsb>0$F=LznbuMҧcj&DO I?ge]˖gPM'U,RPJÔ|hmӣ|' ND ~GQvIE#,~@T/MAE+痲4Cd(8w`ڡٰ!Lp *=1I/_oܺ mqPZݚ0x::fMaOib-)rn19d =5WƢH:!V\k~sJ̦ih\]"tND6emZ=olJzuQ3OKQp#I'թOV^g N8 _UY=sqE`!h?Ǝ氻W*߻ׇ#nߗع^fɃ+Y&-CVbIHјc4R" }]΋#-=2fP2qO3-Ԑ׋G|Waѻ,sO~up◜B݋ :bM_#[9sKzc5OvB`s<݄BXfa+*972 4kOuU:/BiwS¶ND|.PF+ɲa<-|K[)nu܈:b4эyWPڕ[#1 ‹y$wg7A8TUR:X kC5_yߟyd7= bi - .`uW4 'y1áKK; n#I627_YC:XWgW(+rm/_zރq!=k`(;6Nx2{Rŵ%L-JㄳϠ=S]OztEpUu9)dzWe#~|y IF|uz`S]DO^d󵏿vm5G3?KeB1bh^~P++.Z)fz~nLtl :n 9!nG4i|\}uMA6+` ae%h}3lѻ8MZs5(IBKoQɎJV1ݽy0CX)*=P ,(vhS734yLIKE<+hA3Wr}&̌lJ_T@/φ{:o㤲j(PdY\:H7fz\IX7Xjfkݫϡ] utSL'j/P>TИTVy. `*-(mڢGc0GqE%2-jAʽkh^gj_;'=il?Ng\FN`SO,-(?ϠYe 2o+fG!ȫPʵqGg51#++Ͱ]bnH6Q@<ĩm >\l{[xW{{Zʐ 2%ؿG2'vvʃUMC]V(N=YWZ[T`pAr8Y`kIK h{I9`ѸL (N[Xd-[Z| 'zd6E:yފTmZ<'lP?|G2Uˋg'':]mnMvnjfxBc E6)b?6uRxc9 b84daY QV Zf@Vǖqyycx}lfp3Wdz؈".5&@;nޜiF:IQ*[Ex)Z98sߪ j*EJ%<--%>eEhЎXfڡאq?̰B~uQޖ)HBXUqLB)DW>\I?p &ɶynxA_/OӇyQ~@~t(7`7$ot\; : `UKITŻsĮx@TH`Z%""x:=x%P~l,ZkwoJ* & PG&)Ѕ}u|8x挷XgkjcOe3ӨH8a8TI=]. stS+E^lD;ۛ %vXmyMXl,y6IJw}6#TsBB{}lVf aqKO8e3 sbaEG/6,v`Pdet!^6O%I͘hz&)ڔ>o4d`sL@pci@aRŭХȳPzS}gh'>&%;|@T8NMef0~n F-JdѭR2$gs͍̾UӏQ o{WKH1<}HVQB& /쌢"܋[=}o-E_A@*P{-QU=u7$q34ݧn\q2<6\mPJOѲ0+ @T$TIMHA&8հhy*%-Xw;Xe=M_7|-u7OrbrzǪPH3&8Z!NTZ8Qr}X)}4.hڰk.7qjL}=[ؼجN׏,nQ㢜TGhǓ^c=YBl8T +bL%Bp})  isL\(-@,T7%lul c5Te\T\tnwhw ߝ${GiD=Z۽C='=1o"J#oAKEb (<:&Vh o;kP^D$7 /n[< omQ,"E)iiuwbP~Ѹ>/xsә#%ځTkYch_b'&GHHKIm>keDŽZG'ĩuhhXn}\/16SqlF]u@lgi= tH>O 3H.qq`)e%vʤ7e?\Pԩpvq_hTq;,[džN IP^~** *rAY[ kRrbB o\$&Ӷ׆2!\\2]q.neD)7:-zueO‹hn'.3QGm]/ {B鍯2/ 0LNSZo5csԨw7f!.,ȑ TWl8dg[1TMEz p_=6TcȰ>eA˕siYn,w`/g ʿaRdwPOf9^͢@e%˒1ӕ,LnAq^0Mà龧a"{WkrK6iqsIh|ot3eaHHCi.6nHƴVZ^ISf= -vtƩ} ǍP4) caZhNRi|PmMՕ_kWiRpt(O` FlS#aKׯӡC#E@+Y,E;zZjt<J}WܩJbɧٴmS7g; *>{q@4C.:O-ZNMiud_ 19Պk.Bco|%f~pg |u3GvĨ=(BX qۇT)w6yۄ465Ki8_E˰Y\|ԛS(C `=,Da$#2N"Hq_ϋ56y$ p)MF+tV(;VjOLA61~'$Ջoo}c~X{QG㸁R,6le.C<%rT̻OB="Qt~e1g=)RӳZ~_ ݜ9r/&(ΐq)J$^_lVnD󔝧^"װ:TeZGBS j\P 3A!. n ͸ D O yJ%0wgr$$3s/ʒ#TqLQT = -yed5Q/:!~x' Xi/ {82NrcȆNSdM&u+XS_eIGf.`bewx)(]n<38S^K$J6+$9,U!J">eF\.(&{6 @gpE71jY1w%~񓵎?󟧈w Q'朿Ib7UoQ9VǪrƓ9{CgXPZ[Ew ~QγFԒT+ˬ\S{HD &=1{vo&uW\Oے@q|Ov'BҹQNVBMvٟYڲ Տl>+,O`k{S!}6 .,_.f'}c=~FP_  C) 9>r ޝͤWr>ݮ(|cnJ1i4/#~yVmY>Aq\]#44ܻ#opYV3̣ Nu#{Eq7;floYA#1FV6UMwC S UաGe`5 V{D5"\H}rrbEq/]91V:z`XJKŤGvz"û?-oQyv/ϰcISpІRP"L:T&M$7DTBÍ 7L֖̕=MskiF}kWWI_晰DVBc^(\vlq%3Y_dhc h$mGQ$/u I]D-ex41Iwa6MMy*mwj䒋 ng5*EVG &%}裼NFte~`  '$ +]*/OF"֣eXlJR yUG"CI]KI"O"jlj7bu7>216kjo)eeOG0;1Voj 7!a igN*0 eNMa^Io#ax`)խ|Kn)Sۄ Kƒ&,'XBAԫ[ 't>sR% ꤃y>)Iַƿ<.B8x'd܁L >onSgy> A#{kCT76,~Fr腉EUawRW _S o2@3ۆcƀB &A˿>CM'_v+մZÛM ^ pue$K!Ihw<Ԍ_rLqy'r)b?]0^2ps%{]d[he̮nfh@Df(W=F{8lt5Lŕ}E(]Ud iz%J@Kn !OBNkYEur@" `:?ю<Hsp)5/ o_hO/Mf}o JBpV}E=?X $?\ʹ!)[L}=ХOeܑ˘-2!7LFlAʷ }\?L@ȁ!?Z]߆}[t6XC](?3E Lɩ'#&vů^+%@චOTo͑4HACq(G<!˚>b]GhP xK0:c1k6yw±z΂0gB1ƿP2Pߺn&L93g` Kg 0[]I,D%$ȿ-U M!Vb>dQH`ʌk$g|߀kmxt Fq"ADJgL ˉ[od)l W.,ej!|^i(PKm(@o`R7NK{FMnB2eM _d!h 16. V4oL9BXB1Io73>eUZa(#$^@3 H5[x3Bh1%=Pp5U&.Ψƶ\X 4Vo歑8xA9@O{'S"EzqFL"{A"L?%t`E!}wN5&)^qJ 41Myą+ Jd2ijo]]%uF3d BOg-.3kI'ڝ OJ[74 g,}.07ѯ Ϸ>o2ݜewj-d$gT݁J/9`FvεˉcODbaר@0PVm5[rxI~¤zcMR1BGwT&1D.l 󩍲47op.e0ɕ#t )l):%EbTGp—;^]~79M@ClX* cuX.€4F*2Z`-& ;<  +R9MB_[]Yc'{n(d,Nz.7S]nbLDqQtJ`+P5! 5ZjʘoX7u|kXT%!4* ys9Ijrld&-bpFͺPڻؙ!-/ssTx+ZT;r?cM?4h'&2okQE$b|wg+y||Y@%`㞅YnD֥fcm#]GigiG's(,5-4L8j%sCZsT% 砅+tJe{'At|y i\Gw廢dIvޢU0WCSw@z%zpRg/ 72rm)aA>W`|WHњ2:ޮh3Q$rg#^{O 0\.F 8ٝE큩zV>>-%~loZ5∟ /#``x4> |?BOYY j%9QkL 78zWiџ>F&42J~B3 3_F౦ej&Ńٷb(W닯z8s@~D@Sa!|;Fr2B{'x]؛h7h@5io!@5kDՈRettxP:sfU?G##-ྺp VN\|M8^RG:L#'(@cn MGd=ro2?^ߋ% jVRg-!@v v-2??Gc&t=>v3 p.)աGWZpjt1-Jj䎥\2®~ROrte)mw{dՊHh׆gPQږ%'.6 4S*$R=yW1Y E׃t'eQaфhpv\;E ԞD5EPKK*V<؂J1n Cދ" u>=&=]xwc:Mv q" sȨcH/5&F15TY|DpV7mu8~0!*+{}R%mo ѪU;q-wfҝu "P  $қ?*\e%=af^%j!iy&q*}[0 ov'QE~@5˪dOMņCA`[;l/8@ҞeKPקmT|Gv9(zةN&YQ{NK`'TÑ)H-b`~8 deO87Hy*i#RVu_yNϦ"bًz'8щ*]!LL{v}yWMH=4ֶp'BBW-eHQֽ-QpCz`)nIѤiI|[[;OMa^~F':ug\Jຘ^> 㬰-bX788/ґOYK#MlϊjپIwsR‰u@j'oq) K>֫WWZˑAU)ltOlHLqrR-M.0s,P=^={z& j.Wo(P@b,-^Y+ ܁y.V^S:;XQkIKڒ[2e:Q.Gpt-vv֚A@>txɨtccܠQl@)D}͹_͎)"MXF!X ׺%0lwzȅtҪ7;9MiFjvum=*Hyߓ2ȿgniYTiQ\E)h'q={>$YMʣyS%yXq^i5gfC77OScbbgLN3 =|~}I \'h`C;Cɡ՘0a4غ>MEKBͬ(ֿNi M-P$I&c\W!`_0ZBa`"}RK^-v W4>=[҂KпDsj/6.t8|M ÊK Cad햛(s೘V]8| 36gVҒ&2GUgmܘNqxvW(ɜ帯"{嬮 I.B`O+̭-8;ԡ؍X5:E0L㈺J+X,92 m\TX]Cz=U9,FurshU.ܥ@< BQb`@c6`O˥R?%ɯ7;RR C>X9뿗r!EP‘`ZCK/Ml%Zr1aWFɆz19~"09~o^򮭬A 7{4DK4+@9 #;VE:XatmahK9 ziɧa4Z>Aߴ&:[A?iҨ0@> `Ka' ¡;n'KAF덮 ԭ2jwQ6 WLS'Nl~n^GB! s3yp-41^yɫ'RQ )&`,tVGZLjj `όR 4z 3-h|&W\EHVOx<[(i_oD)."iIJ ^؈ iW~52A Hk">; j=U?DfyOQwbu3h|4<ډer QD:oL XrAÑ:RNb%wX+ؙ]kNa<󷭜`76gMSaXLԾǀA>Qs񻬡g(UeoizdWHUv5ӱRbN"Xiz!>l{&j>.Z/C)Btt_n3[,aں!XDQ9Mw&[‘~6XT|6XѹzYgyfFA~+ܥU.6WMo@Ae9dp@b`;o vwl]ӪMM웺 2¡jh zh*jGBjI}WU!S'pXwnw.U]v;vr"6GknQ?k75TaZ%6Ӕ,um]g ]\Z<ƛi:ݾ./]$d/r<!%3^w |4tHy$_zWLw]VYQ#'4 _zd&/.*;XFyC]~u]]qS,v(L1Iwb=bjTY?WEhE{D .@qG'0̊2HN挲m 7H)cvmޮJ7DRRzǕ' WOAD Rx3u. NA U]\IK[n Dc!ic?iNbB[w,ԏLvN8?W]˅欴{0DO_tDVoP13|Дa(qM;Pb" vxA{>~[T ޭTN.R{a6*fEH-e5"M0HiUC)Ñ@ pӑ aaV=C^kWQE> ᯢk R3QüjB "wI,[Ox[2+Dt0PSi)uojGxR3_ '5|'+ ̎S0pZXEPp;^Q~UhK>Xt'{`m3 H3τș^V.x|Ct֙c\\7GUg"[=6#n֪j29So*J* G=C7\ *ʙ:MX®y=g*0HF:vS2ap$fm-|LSEz(Q/sʴEw%4"\}}0͘U!4G`6d"2!K0py{u4>41b;{}t:{|qOngЩ)B(|+4^`8xٜj(#pǟ+4VW M:BlׯviQwhf^wa('h̒gcXLzo)1֯L9d? .Qx Q~FɊsD_'kv/#/X{v 1Ts!@1j!8Ga\怬t)* `Zk\aq>%tn2/2 )FZ)3{Q~iQPkTL¹nisSH *;Io){n# XSdVufr}E_ gu>(H9F~]Ccἃ۞]+{soR.bw97bGZA3:8 (-,r3f-sܢ˦hgک|eK~׵̄9fF6g^rQد|F-WaI@Ux#'h"W#UT 2?pLtxra/LV J\,kZ"5c0F6 m7iۤvKLi>EU.][w>8apZ'|uޖ'ueQ֊J$.S8a◘0{OpȷʄVN7GјQڋsٺ,&"x@h6TA͢={>n3 \oAFDfZb_AāM_yX$bg6Դ 'm.nJ,V(~Դx'J(/mAH3@Wir4@'E%ox.-y,H |nL)e#( (|vX_K좤/K^],7[>ī]\ LG-nJ]8~QIZ"VIz؃<ϋ H_j Q{]mrۘ*Sh~>li,\ 7 [*;(C_DYWP%tdw$`>9>dt"G?FdO5ƞ2^@!A@]=eM߳9 'iGta+fOiN/ CՂoOr`2zeoP:!J'XLeT*+en"ׅN %ZT XOA;COgj 3p== 䔤LufIFKgn$VPa'ZpOQɌ j).ğz˄H籸aL`,FvQюkR| *hM0W u볏?Tƻ }w9gXN )"_`hw#W}L$iomVY>|h.zӰ'tl:'t4E 8U>NqU>|UĤ$tF%>)L{e Cbݙ|&0h-X+A[~WkvBg~#!=oBɮqf=LV8TSsS:q'8ʊ×-lX-{Wh l752 B:rdh|wVH5vtwfؤ%ZQgED^% '"ߎl]ɪ*xU]n%^+#HV( NP@qi4L\]HDދյI &$^œ=±<@ v0Zj42W4$prxEuH稏\qڌ2s$rusǝ!xKy(f=5Mɍ5 XlLH^2Q1QcTl .II/P/wA)<=xiOFwٴ4U"̟2W;4o9'?d->8~IVY@M ©!*s]1Bt*9ֈT Nnz~l~xkw2= >9v^X?비t;\UI'zqN 9х9VЙ񎝽nxLM?+E,jv￱fBi*z6{1C[t%Dˁ%>2{ ى /ȍkQ{h+^̫_m£l0tgUa҄?ȍ]Dw_+1t3ygy |*;&OM>}1 X$\ޏS*Lƺ2^`,FGӾ >:$#1$lmnOLqqImًc)ݡT~VFX1cSאT>` zӦ)˭rOpb]W7^!u#Q !%gif3*xY/eK͐E>-LJ{~gUڱ9sn<|$D5+io"Ʃ69j6YzGq.~W1Ԝ"}T6Otz(Ѧ.9 {]+yK-\\8`H*l)=\޸-=ld~C^ڈ9^h>["d3L- X5CnwE{y'pZL/DsR^]b,!97d,\n8/k' ts+]R *y~o`CNruk&jv IW)b]G;q/o,v$p)Yd,ƸSP\⇧ ve%@}E=2fm }ޢVS)geW@ /=q+PJRrݮƒLѓrBuqcPD$&c~g<,@P5c߯