sssd-ipa-1.16.4-21.el7_7.1> H HtxHF] ?*}}AB|>(?d   : 7=D   , s |PRR R(8 98 :|! =GHIXY\]$^|bdefltuv4wxxyYCsssd-ipa1.16.421.el7_7.1The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.]#sl7.fnal.gov ~ Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdK&0A큤A]#]#]#\/]#]#]#d588fb107a7811198c042c95708c365d034d9357c6eeb856f2bf04bbfbec081470b5b79d00691ac2859bbcb8819b2c468f76140b15fe336177b0736467cd885d8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90323d72595a7660f0ab44a51a79a5f9cd4f2d632dd50efde4ad2afabed564f5eb89e32c12a5e1a75d8823dc71a5e4c9132ac8bc60bc2f8b5198766af75f5e07762rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.4-21.el7_7.1.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.4-21.el7_7.13.0.4-14.6.0-14.0-11.16.4-21.el7_7.11.16.4-21.el7_7.11.16.4-21.el7_7.15.2-1sssd1.10.0-8.beta24.11.3]\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.4-21.1Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1758566 - negative cache does not use values from 'filter_users' config option for known domains [rhel-7.7.z]- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.4-21.el7_7.11.16.4-21.el7_7.1libsss_ipa.soselinux_childsssd-ipa-1.16.4COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.4//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d1306c23a64ca94c2291eca5c281afaddb3aee09, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=a6e84f63e2c364f030ac2f8d0eb0bbba67a80a68, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRHRRER/R RRRRRR>R!RR#R$R2R@RRR?RRRR RBR1R,RR R3RFR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RGRRRR=RARDRn7;Y$[OW('!;a\oϭЍz[; f%C&J(PݝjHe Yzb/fI;]QYF⃺0IYvna (uC/7I:?r/m;]6xhb:A[5 ,լD˫R9eNt?]麺 Bt6όد%9 Wкֲi_=vo,_RD-V ;ue jkZ[CC J a8ֽyU~!I'HR+坉!`iӄs~X>궰[Cݗѹw9.= ŸGBE3.ݦ?Ug/޲UX?9y:D>:Q>aJv :`b~[8ju}DJ.hAspzQD&2HWK+PKbY*%a0 o-(Z4HG4DMX >o:[&ikT fS !Od` Mŏ zCߗ\ )!J{}&Sp *L7ǁ4A|W(3xh%ʸ[thヒ.aR]K0̇HsdB0'$eMq D6虍$WglReC iъ' j0aּR thpL ,yf@'fu\ja邛Œ88uV4imy#߲=F$Erǔ3:\t(z=3׷h}qЉ;U渲dC _-N0Uy I͎}ZJoR O=gKz.jd Jߞ!Te/'R3D;b-5t/!h#^3 VJ4įP*]"mug$?IFk!Ej@sPXyA>(xь/ 0aF|Q_02,vZ(m W oTl=S>P ]q`8x\r N74Ze,u`I3cKa3lo,ZL**;O~!D l@~,}5̥zmD4{G6具fҒ\)Krۊ'qw(ޣSn-sA8k`qBXFVGAݤ.p(,3)Ȓ31+Ҁa򗆔U. m_oIU񯗠qثވ.D5 됢Ԯm $e )`G/?ISSPeƘ76;W/V1EJ/#ap1 &-ˋ{kPD[ُv?c_}c 6 I{rs$(="yIR~U1QQCW;8Tn 0 i\w#,š_$דܩh&xεZ'=ʥsD9.[fM&֬'oHǫzE]e <^+C&&mq8bEg2ԙ'zl  zϽBmy2 cI}k-sYç;Z-uE&D _:|W Q%ɮsG6n']x+5>,#|c]Jѯij:8Y `%Uxi4s"-"! O[tT*W^iGy#k&'˸ 山Pү3އj"jئyGk?Xs(c]ւױ$B\X4l =.&~g0?nGJGƞ|1.%RnYXUc$T6#0/2(Kw;XO/a x?dooIw,<N;b&{/s>' ΉiBA;kKGQUe wYyAPaIވ"&=k\Ã}G ֔I47dVI.'?`*).f?ݓP!HSwဒY%=#zZYGS@#z2@ؔ '~>2 =Șk\Pu$#$+u]B96n̠% JxpwV$;=W娧(]:tmap)d :X˲FԜYi`t<fK-R5ͬH Xe=0/}{ǾMg?}$/]i:nQ^+,ڂ⧠f/2O-V6p3h@`f1_(XVy(׍Z=cgJ_$,|DD AXM W$I*WdRsTfFUNÝZ^ '[Mݼ\_~IY92.WFNN`mgx&RԆ]d&o:QJV[Y9rkE8^f򃽬c-=BH8M%c1ruɶڅg^7ȑ.4Ԛ>^6Ə8ɨ pa|-`hOwc¨@K-?y s=t{9PO Peߟp TL>N}دj5 Ww f ́ʒ;RÃͅeqscrބZձY=PTvGӡmoRHyzY .h="}b-+i#eݘ2XP@h(W@~_+Y!N(-0ϷZ(iFW Sׅv nvO7>J"@?4?TKh)6./ȉWj:Uu|3C>wBՙ-` Lh 2ۮ)} Į&) &%)}N$d-3WZ6/>ܿfև8~^2I^Gb,?ih"ۛ`>8l gU>8з6VkG7wJx|m=y.pCۆ@#v CACL&sQfAX8ǺNG[pǎcN9cF22UfL~l lrS5 Dg(4틖S"'ְjk Wcc{?}9Y<"]גSD䅒z#ό>g(~H-3^]FIi) 6J)V v&_ |3''`6r aTo핰/G7($`",ظ P1[zkgQ@ Rq c٦~9ņ0a+a e;>hu4!{ŪؿY!FB{ASmӝ+`W`:#d%h jWZ*Uf=nR[U>kX "$nkzbHAU)~'N@+iWnu4hX𮕉RpssСˬ>ݾ#+7ؑJ3 'F`@ 7rnI*?F5^FvN;>4 yXxLLBL%}7el*q>RO'Ϟ@=tv^7zNSqC H dm𡦖Y]\ r bwkM~ qG^I*c|GG`*y#^9*IgqD%Lq)da?>6Ր T_Tgg|A|W*o~H꿚UX[ԚW_df蟏} Pe< X1I}W14&Fd$s]o{9 GwdHry79KP0fb$ޅ&#XVYpm^X9V_Y3 iRjmn댖_$60{ U{T6 w8j >] :6ZMK&w,פÎ=ZXV^?{fbWZ`o"ɠHҕUljg%auRa,DmW.4OWf>`X8`k =[ .4Pje*0;OP7Xyv?='}cIm7vwx:2 SƦjݤpԘn(yU CJ0s=}/ٵQ_³,3̊2J&Bqj~j,lKhЁgwc>[K_4|&HQQyN:EttYZ{^ːtu]F  4g>Hǂad-Ll Exx֝~2Rq&@Es'-58R;҇K;sxr"y>YX ʙ^&wUwe&^JȢ7&Po)8 EW 1v(0\ce$ @ES7an}h(0ȝPP'#oJbxv $S p x,I= NoqSi\6,]d8`=c?08jc U>Ay,q=䊧GXJG:9| DbG|eZuV˧49<8' ?hv=G4E34|e]=uXn&Qu2wggu $*gٲPN=9< (_׏B c{8+]Ɠ8Obh׊b\$Ra:4"mKp B!MGȃ26C.Ї"KDF}c~ovh),p>;Ra9Y~VWi{rTeQpm\%.(6㶰ğH"&_#^/g4 [@.6:@bCKj0pO7|\ƺ.o9yZltʔ<ϓ~OFB7kP(ϪFf'܉c %3*_R}ؕjR󺸳\hMp i1'?د{\ʫ09MɊ^Vx#3 Fe+{*Me * Z)?*c/:c*[ؑ9?:4xıDP^T![d{8f6Ozz1)>jy#sȳr-ѢS}"v[U?  <%gآ g;`:5r?ˬpyv5T+_S· kIyUg\ORsT͕gHZ2ޛ<p N qls f샮0gMBZ-}BV\(8K-q=a; 29) #JW+ #C'\\WfPDn [Wɔ2A| 4x:[ʺ w赸;Đ5u `q%K=$) 5Ob[_m;(Ž]Ofq Q*߸%Z%V=9 kFA"tKvpDG޻ kQͻXeB.N*SV"}=hDP~|MsZƵHI|eАt9WꝾWRWoNFF=i<=ѥE3m珔PG҄)z~Fr,:6DY]XyKeco?l]_gQ &K9ZiN75ưMąN6 E\́P])̣~LoXS<ʟ'Z^ . dxuB6ッaJɔ ~KՍQ 4>:q(jgCJނa?X y`ZAt&b|XM|3e_ oW=k(30jjL9( T/ѯʘKZ}6V-ZrUƫӣ#qpS2v*(\&Sヾ!sGf4+dPp%kyoΑw>A=$qڤEp ;Wl8I_TZ<J0`UG&Y'"F\̉FLU`~˟{_NX]e&}v WkJ! BM\L~8"B聩nf- JpM=oA`?'uAC1$pO)Km1:@ k- sΟƊ^ylZaifY]9lsu+]K\gD8 $Q &.m ۤHHF@p4ǃ|["e/ސ1#ǞgSJhzҰw}⺭0N~qx%ZB>;49,,QSaȝo=qm hacvy>;Q#Cy^w+uv;/O GԐu&{(ɇA6]{S{7}3NojSF^܌>,p l"E˺ӘY!#Y_ ”Uܖl9OetFhj= dP%u函c'Rb8ѶIQ)qv{=691ŇjG ?/#pܚ#Vc0wSUN4(W>'7aUԂpNÚom煉g2gQAAھ= GvLH# iPСʸ*lDWS˿pz4:Ǵ¢m+$j "FtAg7?"D+uDm|.~ M?FMvCcmUvnGwoH2mKnj!"W,} W gŋF ;ijSÇ5k0W&-$u0Pilc#ux鶴˹H>_aɒoTB=,Ǎ8)_k!nc{ ^([‘xsLֻܡ끏622YX@ @س00ǣitR}P5;6?P}ˇኚږ[Jӓ *(pJU_GJ*NsBxQVa9}K}[>ƺ?5 ɦĪjb.$ @bc|2 x/s[g\2$WIoiŢب7; pV:254];K_rf ?o&#-*blɶqW/_j̾{{Cۼ4a*`2qSgwV&onNmRML3sB,QEëXmRtUE eھ?k'"Tw|h)Pl??\a[k$]x]Lusԋ#'E(δ"SتQ M>9ε3bެ PjBW+v)`lGfQg{-A&$8cT60Jش&W1]vkdtBMk־lq?= -% 3ZAs՗tM5AbFEN6OEa'u9U*ϔ5IEX zVrgB[P]t\=mV#a2 Gг'sr`sF!@~jM&p +>'rN9ߦݱ#9yIu})^ ynֵFdOXRy]J6K6" ^nc>| l[E.. "ݠ/Po,{XeL_:߬ r.,Ri\E[h`Z w=ʸ]~[W}c}AEĎY &_,2"IpbO/<:$b{'.U2jdt]{ ͓03H㡪gV§!,gxnǶ5: 3GmxpdsRRŅRS ņKdiZ 2uaxdVe fog@^u \a"/JMK*vwMMbkAc!=jUuJ B ؒ=geuÒd;WŬF9Dx?lp_n^orE9ER9/l&"N tzF#5h Gb`fS-?Ϣڰo[3 î(LY U/nt j^9H1TD>zTG>c2vem;aK# =~`'YBmѩS oCUO 4UCw3;UQSuMRP)4bkB*;SjSxdwbT-؎ͺY\}gH|QezEV,l_LpfhTd((X۾Gv0L4n3b(Ơ+ 1ryQq8%ԼWtIO>DK[dKw)tSЮ0ov>0ȹ~|d:^bf@lł=0t=!3baJh0>lgSkRjOC:ׯ9rfDEW 7&E!1Y90 R+yJͱ9>è ]q͆+cҼMiڊp<|g4z_GhQc8B`|NJb@DY ]d7F/5Y|PE0Hgzߓ)jܡq<΁a?|X`oEfvog ?Ixfg/3bߥu0SOS.m 23ełO^aC4O.]; <'k.L~yϾ#;xeް w[rA߶ps>KVGJُ+Ӵw领++M@!j§ zۃQph zx?sN咰~b+<%'uo>Q `o5viMh6nnC#Jˮٲ(50ѿ0eKkq6? 7eǣ,eg,%C+kR` FƸ+7o0172[xhRxi*yo NB{`k^E;C%OXZi٧·. qmnU(9!"0>jߟNE9q~<6c5Q; A],fJj[iX#V_`u߸^ vQFJ~r<¢Pe*V~^qWs]x ޔm6ܢ+WދO.2LR`%ę4> (ѕF]y@V-̩0jnQː$Ut4_H9R^砓0: T{Ӏ倃%j<}( n ?.ԉ nh}v_/L,3>'ڿOJ-b9<1W-ߓb*AjX?yWl>,F9/K9L,˾3fMKUC{)%65+\ ?8}=hyHu# *Ѿma(jZTvU ݵ&;q{p^bb)A뢋g'2ކˍs,f`|LګE/<_lRQjՏy۳cSjT̼ΚϨ'pwsf镈1{a}H #l64!й+ ˏ){ƕY̪y@&[j`fөU&HMrD$S!zx:Z37bM:A(J(iaU'!JKN$ϔty5U7{@J>0DGbxe?ϲͺ{C,cT-x_0Qyw/)rx/?;B$h0`ʥ .:ke]rPf1jvLwlvDU>^L 3`Cѩ@0IuZuݲ]3(y(V 4/J1na"k8p# =ɪk]9paƷXU|qOEVﱛVSdQu-,F(Ɵjؘ3~n'Q7cNҐ35\vEy`~N̵3 W^ʕ%t#W}]э7+H)XM{RGAOMeJ 3y *t\l?s &nd v|HKax [[䔮!tN@ޞ8(~T<` O@ 񻱽'n~Yꃎ*L %v+ǑI3&H)Tآ(sRqҩV*:#}B A8%?I=)P7[qt-6oOoBf)CI uQ[؅ʃ5M?I'[_Xα1Im~pҕgDضc=0y[ |9&@T@W#2/~Gϰmz=X~]+0LTWÃ%'ID0Nm3^_P_1M#3lkkP,Hr~MYMˋk~U3=b쓾S ^B7F?ZaJWѦXMقg Z u7dM 4Wաgn=~HZ{83XB.gcL^4 f+hxhU;ヨ\"OqN**k5-~)a,}eޮad릿Yǫ#aS`Tr !<¥j{CЌ~˫naj89M u(-L4Q UvMihk5`4 q^fJBJ1ʼqĿۨ| Zz h:U,Iaju<5)l*'R$ERJglUn1/ޔMo:6ê hax 6; oU]eDNcL/.ġCuXBhkY9DJ+unhRWvB uAU2讇3Fԇ/'y&(`*h_ !!_Z;]c5OՓjW21@,Yo䫦k v:A3Rirb_~Ҧ#|8^ 4g;WqǶmi#rgc 43ͬt@/+öY4N0&"lqAŲ_/xb{M6ȴ;Qi1{{%M'JlqqrT),~f| ԉa(NȓJQȋcWK30K.䘁$r9]lerNp7Go1]b]+J&Z<1tXA2)sմ )T(Vв'_,ؗ ".ha/iy\(-{+y)b<Ǡ!^ 1QNFrd:U%6Eߟ;됿+a='ƹMc=f^YNntT s+ "_";D)$kN^GLlBY7 I8`/wܸՏ{!MܝhIFtCцЗܶ$g4lZF`bdџRPpgYF!#1ewEmPy6ݖ mMqHopzrИV&;f}/p2-fYl?&yYlr­j )_.Fqh"h^j$cQ+?iOBO S7`HIzQ`p L6c{G38spx Db|G(% @0fИGn1F#Oo_BmO(>-Q7|p0. Э(Y k;Q PCua:W-~ɀ9k65]D5(TYe @(d\N%x%Ƒ#>/THh}'M}r\ؗ3K<d5q^+]8TVRҾeTǦʵ(]fnGHQn$_u#ͅޯ hGhK_yqt;G9ݗ4lƁLj?⽅[G\G n]U)xu=ՖO\><͍Rm`}ep~: ʗ |7_Jcj|^lt|5~e Z2|>Jއ4q)\D`|Y-gu<+}O7vDK٠a-:Ύd^*vF "HQ懆3sK?y[-$O@2UEp-R4I![ZμOϰozhB°8O2g~+(C.%/~j I=wȞ ''n5cR}'Wۚ*c1h(ašL s ?jJO<&uU)=QoP>xbSe~OuyuE =O<'Ai 0dGZqKPtݬ'9:r (0֟+Nݠaj @#BMFCϒe`y5^Ѓr1 LVFk4[U ;˓r+enst5CEK&e;%_CYl;uⰶ4U:V< D0xKE&WWd7s$boEo}Tn# ' d(apR}b~?bҘfGczdQ=7xQQgYKT51~O)(ms'6N# YZN ^7]k>e (>"ҥ)# 75cxٹ1$g  /ά ڼx%4x۫Ymk@IBы -x$^⮌,UW On9_H =k9G}/ P :YtX߇B ZTN& "_nS}X~Fо8c4orKp$j}}f&I0`$v]XP6YdOZT+ZDDŽZ_!(|W³z!'a7?p_$1Wp.x*h|d D=ǝv~Iؤ.]7O(nVݍ5.TS?;$s"SCB6O>PzS=;Zo8YBS܇洸^9d6VZ*v m}#d;?駜VjI(ڦIa=n'I閆I/L\Z4y u̜4}1Ҝc5"|j I�]QoѸ>xŒ?|$uAbB&1]mdjX 4 YWpwSI6 :Qk5Ae[Ke=Y+}u(b~у#)S7HP:,>y'ͯCtexﺪ݌cџUr=re(!:+ :ڬwQֶZfF*b { GNtd0{:cȖ^So7]d>#jT *\O*xaA]!~WZ槞CgA6ciߨhH{WCޑMrmi/)2SGa;t1 f~wjMu|lUN_u/1gSz`~k`,Mf"|#Ids3KYR同t!5i-FZ}cWjSVкE!1z∙ ROz??{J\ܓe5z&:nP%Zv2|)]#Q01@p ?JGp ";D vH2pҽċvᠣx:̴z:.M6l &e܁9&4Ő+=)ܱXK*h}l}ڌŠyB/`p]  ;b}V:'kb}ڍMO$ԯ=9U}p#{36TCE-eR *EGn  5rB祥 }b)P.PҜ8{xX"B&IX$u|Fr"ehxE, IȃR) A5JN|хvC rHq6iUwp]|.J2Rq{OW&;6Kz/aGlQYjV^ ˮCrwN/s~9Gu+"*@kScҪWJs{i\9{ '=+Y$L?E^H7~au+۪m벃$moN@1eKk@W Z^R5hc-6%IRW\ [Ji0iuq:bGcrC"IpNB|ڤ>6FG8S ɫjݾ׍#!Ye4uwox̱sRР]3꣗2]6X! K9T1xg_h;2 NLp;$bRubEkQ::=ߌ̻|ˢ(.7*1X\T.;&[ 5F̻ }fR޷%$[Ոq(Ҥ# v(U9fDkKUxٮ$4y&֒-XFp2؜y:؟Ovi9D܇j bC8ҒQͼm#{>"RhSھ%% p>ȋ.ȹ) siVsI.o?{=J>$ոG@-}"ڈ#eg.Wf Ǥb9 B.'&xS=G#o`BfIYxB@_'{H4Ȏ 'Nʒ+hW6H*I-C6fM"݄D2 f3JûzL>}wty3rANֶ2klN!ذ ԷMςʠ#,ԇi+_5GgA"f3$.z\㤲ۅ}ihB +9Z P^A8 gX`uV]525X$tlaOYѰp}[˝f).IBmh]q=T%Fږu828`t&pozV&H<%Tpl'd8_<[_O]ݨxmS1- y;+/+ c:=^^rl`RpE<*ZG6_+C?S?TZͯ,+D~x!7o>:ZN?`/p^@nO^ A:玧X@9{:{6XbeC{@aK&a!JO594.#V0>uͳ/OC%N@O!g cGJ .ni]܅ $Bߊ {jcb-Ϫ~r}5ZdO¹J 4|xSuG TZN0n2TS~oC~^c ^?,b)05BbAk{pH뮴L ŸxQ)]h͍N_fn0߀RB[&L`hLPG=E_4o.|W*[MY9w$bϭDWڏX#nRfel0TՀhPnYqB:EU>)?ĥ0cx^gfAڊs0Kk3|s-#(+][8xѠ_C%7&4m ,>> ?+Y7Dwۆ]~̡&K왕^^dL%M&/G.4 4)$],z(RV㎼ lB>#[0ݩy@{t (Ʒ<~em7} aA< $+, v隩 }+~h">d߂ydJYsV Ko0 Hʫ&7l pƝ0rr &H#ixeMq#95UVyoDJ X2he}D!;[]u Il:?f2[ xnEOןAD ]W&p 7ZâkaFAE-uش4_dGy_\`wsW83:ۄh(>A?"Z qt=u[]7BjY-Rg \iĸ'~IhM䟤*Lu|M+H$К9jg}^Nޯm:7k$Dތk2a̿wK6[PLJRpLT EA fkGIo )jTZsKX2R[)K߃d[JDS|gkeR3bV4'u/QstV!OD0˦}Rtg/B9O}~Vuq2)}Q=W8BDvUŻQtLbbΈ]qkxD1{(}eWP^_le ٽ 0dt!w^i-0lX+ +5z3g5!^,9]*GKpG(02԰7֌kISZ7MП3D|rU[Y4jat_Wu7 epd=y[XmT=RjW&YԑT [#.t.u$LP1n o/Z:dn8r8́ڪ[1%XUi{F܎"TjCx) dpRbMrSʫ C% F?/MsFmT蹐Bֶo)IY*<]\Xy` {\NWm*0K+m\ ʎݯC׌J p1sV~.|Jٻa?O?v l#s6&6SbOl^J!RL+rZ` #+(|~=Bɠ#rUI__j\x[_frO["ʺo;{)!rr#:/XtI`"8yB i r0[Œu][h cfiqXu)FW3}>Ids=C-/*C8*;[]_a9J\$q7Ju0y`C>'wc>'+ RT@$WBo{Ѓ͹23wj}+pE\3m^˭$IP6B+{{eRV4 9w' K@S {~_#3CL "',pI;Y_?+4mP΀;v@"BS]Ok1M4/?.oHU$M_4`.tY{.D2)?JrzZQ#.ET|=.NxP3 Dz_9%65 q)E ^`||d2bkɔC:>X 2RGI=\'Z:Eg'aOݵk_ #gE j3n|܎=HWY84Z׬5}pzy%)/uBG$#@5}O}`Hy>xC^o-AcXo ӈλMWu\`l.Vpu[N5>rD3s T.eUc.kdzh(2 3yLx+BG)Їʐlkev^["I;ϔN^Û|=m~KȢHžmFA@ܡ6$˔/BeȖhK7@.WVQ<)QzNނQDRóꨑ wfmt93 Z%̄Ӄ`~|g׹C 8AR7pF.@D/t4B9 #Sr!yBN,B 9_* [w^7;'cV>pQ[93 쭗rrjѻY|ŷ0oәjM֊/vMq5Ú,|x_/oRc e: IY]%ۼӮP_Ϡp .Ñ⳯B10 1lcx c! cüs@W5~=.fVĽC1NȞ9wČE% .]?߽vBӭ5F&>%T̵Ně#i1s4c*vC(p)tfF'}DCz=DĽqt@ >y4hTWa:E9l+ .s =雃F{Q˳~KF ] r'G/J:/]^`iRJ(Zl<.7kJnxJ\fa 'U3fw4ȃL !q6 0à *m90t[ʅӑ}U 89Ժ{;r^ @uǒ/(e8,VwRgF|L<`}|Ahѵ՚ȭ B%Ml{4'N{B`K{,lL9/37i *dTa?J܎hs 5|}$yV~ f^I`X>`qSwIG+,E m[tuid G{lظOAX=xJxj_TT:vq2zLWO^j ?o¬> 'g4xݏ*r,M(I$N3H(Tϲ 3sS2a5E>W?6J lqSۯEzU~{-PKd(xaf|rx2(jJg}*] NJb 䏇 lp%Tՠ4K^NG}WTQ=Sa˝w9ZT~˺#LȌ]EN'/J|-yҺ#ފ jӑ2BxiS]w{PS:[ȴbzn&3H"{ʝ?(ҥ&4;Q4B:W\mPJ۫mI$\zX%]{dЗ`Zj9NLJ:Y,$'Tƨ#;To|vꀕ<dV@[0qLRĽ q>D g.~<7m׶nVرSwaΥHR`( O>k63楁`M< 'ʴ|s]׸]g!(a2*c_3$xm{! D6yI&ŸeXʵBSv?h4d h1%R"$V{r|V\"Z,BX!~}VKjXz $J}}3g@4!UCho)T[9aQNSW61jLjjd"l&h || ᒷE0,% ifySz56zW,f0>axUhCJb#V( y5@7_gľ6i>ziuNz*N.vfBw?9QN} ?cv Z'}榫pvcW-ئGsP8ϑ2nCU=\ (_[ii|fRi)@ae`]V3mMnT[iRT֟Z{Cd gX etdC!CқpϪ ܘxu͝,н-F?ܡ4p5KC-K}6"D mcбPG<*숆ƻ6+bY8] ?%ʃ8QmFH+;"S9ԂNf+hv 4h=j+zVnͲ>(,|AZ/9_$q%~q˭7WonW2ڻG .p$^*=*=Y,9i1KRp{tSr ւ^E( S?HW@,!9VVVzuZq0X4^GrOahH\ ɩ=go||0ٗ H`!cPgK>n$N0Wy&7DS;Sw!pR\aBf<[K}vlw5i&%bs«n+s`ۛ* 5 $͂h 0a82:BL/ ܇2N$Adwzܫ̫Czjw_uyCrhOjTK]r,Qfq<\iZ R׎Q8NIn6=ByI_P 1y/ ez "wJc@ O:A41D=AގUECzİPiTi_Nx5+qWq.d(M [C.*D×i/߈zͲ;s="UIk#dI'MUIC#g\=>QZAM](k*sV7H.4: qT'˓cPuvɈQd&%y $ͨ`Y`j7 ^  \(ryi4(Z-8?Pf(\2cQ"y嵢X\i&^S-uv$|O ;<\v~ lĘة?UHKh;a*qLsK=r=q'sޠ.{5vIUڄ?#g6Yu\ڗ*4)AJP;NP!O%'Lj>Ϫ: nSH%M*ZΚNa z٫ˌϱ()?]84&i .@ kӦD?.e6p1j[ AՁ\.4o2v }(g3?[[P*﷜yVUjM.eu̽@ݱ2y(6sstv=%*gfN')*)=Vv;=?ˮ@u S!G3y!_Q/n" ݦS~G m-9(K#l%\<pE$U]0oi( (J@Sk;R^NAɀԮw p[?p\tO}\Šp0!TDB%ʑz>SGilIF5 ڇbx x#(kMsa\J_moׂ8s<嬣WfPUGDŽBE0pqʯǡKMUyKODRM'h  )ey ρsvJE([Wji0Xuk(y?"](#8m:|07ISG`)\hSwY+21"vm,1J_'p} `y:Cs+64lj?eIAq.q)BzlH@zhzOb4;qʆ 6pߓ[vo"Qҙ饮v4&SC^"3*s=T-5of g#%cFm8a]E4^LzCe sN,7SMRV`r-el 2!`,8Set[j;r1]ܬ{(6T2߸\ 'ڟ  F!FseCmI@R @l VzK~ƉQ7ѐ+=h6^9k}%:M[Zڶj.mM/$&0ׁlK̉]`2H^xTu5īxOh"{ƛ єjmCPj!.- 4 U^"v 9:bv$*T80i;NZ7L;ygU8=wO~z m8 P#xhJV脵Pا!v$7P>T)'&-G}Ԧ s%.Bĸ`kɣ)-~%(Bb:$;-f%rK _,-QV!ɺE$Xr(-ʈڿW ioCoںhn9n/[uguX{X.~Dn&%@ҕzCŁm2 z^ ƚ-cyX^wjQ[zl3>pe=c'vRԠ+_`"2$<OyQ3!KZ Gto jW}67CgiٗZg$ :y 5HJ2aFG#i/69RwX<K#_qdIs,uõtybUfs%tlQ[CzMRnE;&Y}׈,*v1͖%T(Ǖޓ"&_԰ מ=@;H hң :@%rvs2o#ڢ0XxdEa,ϹAab)E1(n,,XνH^KH4+4 G>ǥ^=X-W/r!Zq`xdZV"(?p(o|x/hd?~nXn4WY(-d4US d o pl[`:=Sw@,cz^ˢrhK[v W*Um9jgf 5J= LFj*?bsǬR..ZDP1is{82pj0ȿWgےV Ofxmwe2ޏ{3A,JX 3g_Nݺ4`+(4Nڬ`Ҿ;/Kn3@瘏-$Sz# •QO[S\CG&EmԖTI4R{ߩ)'סxv@ϣfOʱu!1!@ٜ06z.Ċ㫣-8ޏe0vQ t6±-geSE u5E#) Ggz*ȇ3)Hdu[@iCC,6#cN9qW8TodTQ\ih\OXrW_fzZ)~wD|`Ƽ6F8ueV<8OdFWJ~O J"oоXePƝtJStXPf3]kv_XtjUq%5[r313W}Pv@W |t IM6j*h-ӓ>S8Ń"q.B'UP `7c6RXFQ3вZt3qWԣؾ4溦xԝXzk@ fʗI `v֛+N,p1n> 'igpDKeci >NV '#a*W+\i |=!`}bE35/s+QP_HTi4[3LwүZm BǛ܈ sGz;]L|b$⟬Ad3IB;;F@^E!M`@'F\#~D= %_t$@]]L'ЕM([ɞû>l?%yP~prKb%y8 Eb}~B`Y[=y8Z^r1YJS;kB76R|)N7X*d *̧c(\*H}+8h7<:clFE+!E&\1ު 춰ݐ;< iU}_ ]vʯ(3iHةkŕά -&'ThYb|vZSӒeV#o]:xEMgB6]A%+R܌JnoCw(DMoGߌrIٻo:i8t`~䂁j˻ Ga+}9n_q`6:"S{r}-Ŕ`CBIcFδ" aEtx덇]="EuSEpZ;&e:*T%̹mR\^t>j4b]bƩ⪨:ݕ3PG!5F ;:i* H>m?JApA[Ԭa*L .plL0DJ6G^D絪: P3ogM֤@)lWp%DHm9L?,A"A-jBC""OEm<x.\frFӻ9Nt8GVYNbulNb uc||CBu C lVFyPG'E.;8 FvrYW:]B3UZZtSG \a_ƶVW\ 8-4~<:tBI %8*F#9+E ̖l5'^R{T#ܣt5zGBx5YݑdAjWl0>`:_:h\_qZn⪈/Bo.$)6-2A!BpvYut;RR52:0N8Y(~Ϩ%fb^m|?L͒Xe*p/V;t{ƕS?#{jd{D*]0 EA"]c;\)tNSN柼*I4zG3~L}zGCԷ2]<@08qg:ySbiU ~fƵ$ҜnO@ԏ ~J9EeoE|.G}CpY׭0{0j7O#q)DeoiU)!)G;=g9"SpO_ŹM_67xo'fd"2Z%~3w2{[fym1.Sb E&Ō5ADrx؏Bw~I07?iCB깛5{!f0)7 ~ӶtB狢ct"4bTiukYL~r,˙nH BӖ;ĞAU$"U6<=napF5YBX*cuLӳO(4JDU9lD)r3EM8]v|n>Q4Bi {BM46`pVU!p~Z5 yh/yJؐ{2k*Z ۮ),G+GL{0vbʇ{5dtU.0;T-rW(շ_0x/(X!Kt0HJ>;J08$6*%?仜P_/4^T."t Jg ,)P]z)%\K%":˸upM'oY{[p4c6]k vtk̬8ڊ4QE+v/g'x|2ÚyUA8Ṁo̳ekA5A_*< b:i#nj~x⦥eMt+JLiT  $р郜БEhyc'%uڣBa>;^*8^C+"n8r2w6#'f |}ۇ/>nk Nc*h].ٮ/X{evAE6ێ g2>+-\V,A*_Y;-Y |;-|Kwsۋ N;tgBkfO zj?2 [:BD|9T]^2(okgJholv* |ǰ=VRnp9ȑ #! qzU:p"eԬ߫>%hXԪ/@ucр i2Xrć kW<5~OF 9np=@ke]ӼDpXtaQҘK84.=o" ^U3j$o;V LMՔ盔;{"̝cYA \7Z\'@!=Z<ͮzVߐz5;a>@\ 'qd _cF'e t}ҵnxw?uGH?Ynf8ijL&:X+ԋ[9`Eńu\\;2 1gڳ@o#LPa}$fzΎFh1-󀅺&qjMhؾ$%`M5jR6RϥUߊ<[6 z+cQ;/]S -9_V8j.u?#\!ձ$N7Z%˂M5Ey+^@MV︖%\e௑=bm%ҹ#fgC@P2ڋo vO?i~?R!#ߓdad#QZHcU[+Yg{͎:1(5{ąa,MJkrprR͖@rEӧm&2n{!4?7zϫ/]@GR@hQ:8&@ t/P˾Z8Cc ,(PX;3R8YFFeɾ 7h u{^8Le ,0 2v}CΒBm-/p)_oa5"~RMaςˍ__>odv`H4"J=O4][da=΁M c`K`/}Ⱦ*$L{*/,U)ſ`LaFG)M޼&vDU4@I>f.1;C*ZNU[sn⽐X.x$|”E_I3U;8];^vaJ;Xrmh݇H1\{?ZN͑Qy`z6~FZ-U؛+Z[/|8M5HFQY6#(*Ӆ{Q? "V=ݾ>ɀҵ'i3Ѩ{S ^ o m Ho#_wu+Nlsvds!UC%;I{ίh DfF5m9˝s[Nl ELي-v[  4Rㄺ,;P#&EcTu.Ngn`WBhy\+W!lC%/&l;ٕoVQԇ6Pn^-LUEɑY,#@s4+-RM2#T|?g1i|呓dzb ?h a%bB֠SMƬ&x:kcل` 5s;EK0rjk0yG y-rJONvte;58gɲ,m N&|_ 48)yHnlK#(Zm-#xt>(.8rK^kPH I0W6'54˾&2CIG q~ڐ m8Vf;Sbpee-_PP1]7{@5K϶`D!518-#׌!q'z* T&5+~Dҟ'=؅)/liW>^_~fY:j%һjqMKtF."o&S5۟7ځ&1ڿ1|dyOxZBk\@n<2ȐrBuF(Cqщn*Nk?׶]#f L08&'L,9Yv<+brbLUx<*?_p'nN,C6ijmE36)פz!ԏ{w1aLQPhiu {iOhs(iS/̕"Y|CaRQjЏ7qBT kb>H-|gC}lb48)5w buia -(SDl ;tO)v>g# Qt´%wgm7=˾'I&_KsF+e4[0zUCƀ0֨C\[yRq* ~Rz)(n>h2Xԛ^Hs-DlFlqrǍ>c&p<( ״APsbR;HjGew0p(pZ/^nMs˚A7A:, ;jlMl"e<]!',Z00Uɨ~cBl՟Qٞlt2z̚f8ZCZuqikO3AmJ86Cc8:,3SL}ݐo aOU:p̨KdƄ 6PWr^"|OE=c7e0`Hr?[j]&k[.ș\%=\F><,4dذɳyC)R]gHL#mQWN}^yز 4]Zh.~M~؏*Nz7|"T v-a\`ں/)D sǬ6p̞)"r*wbAJ>կ6GVl wwhxg=ˊW?"" )GAku.2=cY',G #b>@{Jp%h=ᕜWKC&)y\g@p.`.634q* RΤ̺֩­gBO˨8t$,CQ`a'K_,"z#˳%W껷1_Wn欚K.ʮ@19*KLʈ54ad; c;[k29K7-+ n$9%Pk!`2 ,cL"!jj;d.hLFT!`'!灯 IM$X"(@Hz;K-Bd E<ܖ7c$_·) ]-j調F~ B/ز\1Z}.T-J#8RUsC( y4=q n26 5g,vҧpv@\8 φ[&<:Ɏ6B0x=(wئo$_URQp`AHP hr}PsBU<فꫦǁ\u+$Xsè³EљLjx΅ål^@XxHrF *L)ڞv8qaQTpxB]^*\#KOX0EO`=N3X]P!F9_ ~  翻 z2)UQYwCy/MO[]>wa?d;ތ|xPRo9ZKO+O ·.N 4lA*CZVݪk/CLwD;3{,}6SJ,{"A"DKFINƚFL5.!ˁp։þdLo0gq Uk12dYuo%?\ BcT/6 B4_UWJ]:EDDt$>=z1W$>4i#ШdZ?g -]8qC_ ^VѶGD34i1QŢѼl/ 9 r̈l$nR%b+y˥VS^=!UFĻ_OS6-hf.,A _gfJ}ed@K'RdR5#au (OtՎͩqߦFq#H\\Ϩ6a4LU>3#!ɵBXyoW D넛;jY;:DvƏdXǾP!&åYLDR(llXfZ^?O<'yoxA1/%Jg9_B 5vn {G߯L_IG24SeV[eN*p+<4) 7Hp*$HN7/܌Mo5M Ϯ/kR-l%M>HUm_ C!u1>_1hN5 A+$j$]u"8Nl {`wۻ]Rw>qFxˍm C% BU|\nTRP;/fiZlYAc@x_7 Y\畁M}~yqoy^VQ.H=\ H.yMPiP7@05{m4lg #Ìj {^)p3aY~c@BPI?[~v>;&1EdIb?H5SdvjV\$:2p^GPBsӆ;& 1'":+}mMgٵVOjDԧ૪Fa,i扢c#dSxC^胷_.'ސ%["|!`o RoW?LTMʩևByb:&j%ODaچ2ln3X6ϦMə! ݖl.(#lZT( HTiNdMt,Ҁ8JmC' {G UlB0&J~.54U Z{>%tM)jKH Ζ>0Ww߭"ӽt$C4 Жl(OX[yL4ePg2 < a3MYXjD,4lY 3.tI.1yO8q`6+jz2߃Rx|5]g0sVLy-ͥoR/21G]AuCm okf*ݳ $h4ַ'+z;+G7~@%*{^P%4߯@v֌,bb@p[1tɌ=!X>j)KOS13aNN;yC o ,_}njͶ!ߛ'ԩ^!!#jnP '7q²,x A.2Vڈ:  cw9`5]LsQ!k{٬̶ᒯn(K,mg62ӳ[/)%-G敂S7(HNIr. Y"5o^9_whe{ma1wv7)mL:ѥ3%=N[J8Dd  qEo Yb/ ޶'kVޫNIJtSFgiyI}z~"ߣN4i[ _c9ma[lms2ZV~:7 ݍn1l)X sX*ѻ}t3}fD)P2؊K -n]:|yу_9W;y%=lj&p>4T3a@ -bwCKDzllTh,Ã}3Ya+Eh_C~qNG| m*(0HqeNn!, mpB8Zҫ+e_5|ͳNx'/Re3؝uՁN^9xM(1xݵ1ރlЗd'9ے_o1uXE'0bs6 ߂PGY|螦BNwd>y<6zbXmp3U%#t.#逽ID1P[dG`& <߻{ԟeW&)I rwFi'}gȔ7T`|U _벨@,Z OLO沐a2)\[D5= Ou 4$`M^sK`a!>B2.Nip8fwU]?{Ll%F{(-{ر/XE1% PsPRm~x%?;ːskr I--솽NHm%ٯ(EHv&]{vz!nžQr.O0| ݙw#7rjV'WuU!)P10%UhxU}S./F9:9XD2[O>Xv3K";BE@ Ը)nqzv@,)*}?K|5%_ȧ]~i0ݬlxgwVm[} \Bb/; wJ b𡮠YteWdnF#CKo𲰔"_6ayy ʞ~R"a2hqBCh:e &ƬEIOIqHNoi{eM9޽ NK\4Oø5N/D( Hfius۵u%YϘܑkjT,;,}Wb3GE{:KƁ+U)J'˘ 2EY䚪4J!G0P߅Y7(tzE.7)zF Bc,֏|&"7:>&迧N@%ʮM C*'6H޻J$+N?yhq!=ۦAsPд`59eH\O^jN7\n:U&)wycZ&`5p=y|L=h,'ng}@w3Hk2GU+_["fP_ɯG2Cӥ}x^p]øL~* )R/1J&}^C[:n9ѶQݮ8u̯1?wP}7, |*KB?=JR_>1 ׶ 0.1ՀJ_ңž3W/q3, :b>g< :+=lC͌L}- z%* ^?FM$E1\gl+Jѵ7BI41w(…_M^ٱV(%NU?DfU~L% rվZ<H+|NBXMk9`\ܩ&l?p2˪%zzA$@Ԡ;̱O%8sKxrT]i) >F ךM FH {#s);g ٱE]׳Xx7[#$%}dF+vrryq0+ZAi7L\MYjUŊ1/$~K84a\q?j2_/ҖZHlg*篍5jW{\#(>T|B{+"`p iIqb~pgbNnE< oԯԆ DHYh4*Q J~37&@[ aFڔvkS,{뾭ed1tHjuHeEVwrՏa圮]h8tmu8*EpRlD 7݊kWE1uT Q췺@eIloyLbD_Jl}Z?|w*«)H91QQ4Zegbp ? ؃xr/2DV)'3 C _A;$T7D'0 Wp&(JqE, DTpRyPt)|[(^"=mMsV ]aCԑ>o 'qHW=sNPϊ`mD[X"dAkeuO ٦SgwΉEנ:ͮȸ R"Kҍ0Уh ߭9w*XШ؞?L ގ?R5tdC;V݉y_U5z h;/*3P6w2j"@^.O?:/S|!jjNB'}M5)h S7%yCM Wgd:QOb\#+m`)+)A+6HgC^ +y\\ cld\JQk,Nud^Cjla_KI"oBGƾT(aܵ'SygB}I':LVƒk/Z*!Lxtj[1m|Ȩ_يAd ^7$8iEn@2\L_o`H?|H͝ @TJ9{MXQ C.r}{P~/'ѺJ%?\h?>ɣ2- Rf/$geS 6͊o`q! *vB(¢faCdD;H)do5 !5|f( ZM.wCwX R)( I_MLof-ٛHqY0z'BffC⌨D>hLʍo GWķ0lTIRz;".#l}ғMI0oپ>#+Ʀj8Įp8&2r:w~FգeI%{W<*T 6 {3թ-:Y {b!|j.6kH7ox֧ɺCdgLͤ%5g3if{L|fvиJ yy$PG vzV)"(1/ҝ(~ &GV佀"[!tu6}WL U##qES~1 -<7o`\+kt*,YGx }U8ҟpmˊNt y<;w,B&uZA~|qEy_*AfsuI n`Kw}n@;N)Hs%Cwtg_؀ `/x2?^:![YF{3!2ɳa7ᩘxpNBPByt,L('ݧD5t!%ا,^c%?) îΠ˽nS.ě-.+0H\"h4:~ zbC~Zd^d$rdD-BL)_]mc:lD;qpTFW_>Źo>!ǵ]$&٢z`~I;bh;ܔSw V`Y[6I4 hd=ur1gVX^ѮB]%lv?f4=qIDsQ-g~ьA}[hE3|pic_t@SkZr?peW({8%*4_BQ#m 4\-<z,GS(Ҕ,n6|C >*st"f9j|!bdwx<:cTEBh{F_KxHȪO~4D_A2"Ob%+j1z9R,<5~n7f!n$mC!N5?Wzh]V _gcʸ\OoKdWvH}e!LKU QONk! يHZ<*BYW|feYo/>B)w0 p0+}I [d`NԬ*ԹmǞ>mp~'N&`;kI r`':E~޼)+*v1ܚDS`@qͷ:A-v{\Ft ++E+Fű&~sqG&r]dNOկr~Bw*i~dI7ב+ՔD?s||,uzI1n+YnK. Sy_@WpuQ$fy20U|6e{%' k5auG]D$ 15H?ކ9L9$'#rWuf6Ȯ<`8-Y\+dVcn"Ɨ:e"1Oڈ@2paUQG|Oc =>/K,'Uj8"7Z!8hky?(2V1'L$R5/L~D_hJ2i2WVf!C4`^VKwX(Z$b9ft, T |-}9%婕וқe[ז2 E'T;%i$!=A!%PL2-x--/{lFN kOvScVSQ+!E]^ rJ%b-X# _:%&C h=~"9ƤdN ίuʁHɱK>bf}YG%b]u.Ў/0oFU*2~ &gKQ&'2c[:%|ط(%¿߁a'?'IТگ% ERG+/k\VF//[ΤR?Fpگ]/7@Kh0E\׵(-g{e=n\ ei\LP5$?H+\TC6L1[7cKR%mh1!(Ary& Nt[\d%̃ITx-"}gwj$,!C`HنsXK$z~Td}vg+P\S}ͥp Ee/M%j|/`MŏF;$ #<[Jc(DwΈHeWkEïm(1{zeݺV[aPyPpg#4K@d"q@:oU~D峍ll$ !wN{bεa8&ZW}i|,"`+lejPE|B<'Mv7*a {.^_7ÅC#m_bBkI{@vtP4gkXp?X 3Lq܃PT7G zc꧷M!# #ͭ'wyY2܄V֌a(sɓtc+tZ{7LRS0#\:tbB*&`8ѦyE)qwJFc@q :rf;s3W^vN'wHF3P0c 'J+<:P2xɊ.N~|Uy"B`)>4p녕l&Vn>l8([¿ָCrcS0c5- ף }KzN"ֆx@';ddS--RgƵ%ʋu-om QLݓnBX,k/9-_ ?<q,U +K,GG8;E6p~iB5:͖qODH+Df8ÞT1Xfߞ,doypQ ;}̔P( ^pDVG(䟦'Iv==r̕*t%KRUIsX;6?*TT};6i]g0K"њ歶2B?S?@n|ИǺ?0$=0QE7 鯣=Y "PUWF8Рf>N?ׁe*&_>+Z`fk(FR,Ml7؊  {SCt>[F暑a=U]CMiTB xBdF r3 Y  cͷyF5ݍbI.2"J"trSD҄.{-b 7ל-dϒI|w7}!&Ã[+!"[/wX?~xϺ.x$ b*ٖ![z0oId!}rj21^FvqxFT,ӫ]7uV|vxA3u0*xb"^DodWx̦Tr ws桲dΊR0}6NB{*5IgGCJER[귧Ns@u%gi沧  Ծ&ܦ6X+QHym tV>uYgLxQ1WIPZAC O.5tϕk 3kј~B-e+~y|i瀜0՚`, 42]1me+ Ifn$pXRMiyDZ¹ϋ)f":YVƶ39AV#hv3 iSV 2 x7qܧ^wtTE{ƫ$ǕvI)fyV2L@\K×ɛu5oٴlDM.#[\x`Y!$UN܅ JJL1orxlPA@;ͦsޭnu\Z^0wR F,s cJǾ \:З(,fc63#9\UR11_?7#+W^= p­еcsJyGӜCLd H%ش)^=33^"FuYxpM[ADܧ? (mC>Ż`\p2ku| W1)_^\+[_E>KK%jopFۉ &zLF yBH)P)?A/hʬ$u -U :Wẽ1>(ABlЄ+NjwD.g/lf' ^}%$:vXo,<7 <#Y?˴h>6y_ܞv<@sʢnЉml?t,H)9rkE=qVElHvg 71~)L`b?ar^eD!0˗yDrk.Xn7G2?EOo#P__FTd~)0vb0o!v$ +t7 ȖJw|\=R:MV Ig$$T&Z8eH* vʙWɜX--۽IB&iSc@oA̴9 C"@L4i"(:\˜3SjvW eeInrNS kdg46K}aykuVN: P?uŞl$ 3U3hIt7 ,N$D|_㐦~PsqBRO_r4D$cHZ)G\hG+_pnikDr'k헁O@hRpEpsdtKI?zDբh4- 4ؐ :;ořWDViw}N3H*%JXڗweaIDYcNu\S9\m[3/[<ñ; ޿oG{^cS)yE)?8Oh7Hb6Zn&Jٖnq@}m԰CʓOy%-ʙ!ag[5\nn -&al?3e%4tx[`Hv]fμeQQr>9fӥwsƴr_ ӽrŭ9{ ϷǷzk4±ؐ[K4 :wRFg [yPPgm> op?$Z P^:}B% ΤڐLOhov*G0boe ߭aXS3Oxnl d,!tayĆI=xbs/̓|]ݪ2$=[ haVXKCdd ~I&Ásk+'L@~nhdE UK)RA؞ R"n̝DPN7ѝvT2WD7@9HToGK@𷝉_FMntUqy>ArkRWu " qlOa 8K_S[o[Yd|C#qyZDJ?<ۘ55\pmK?+E$/$߶˕ vdT aSKx"I{ {b^yc ?|bρv}Qj U9  4(4t : ~}5)vԐ\:T%bߌܱ uqj+ <BB:4 hdQ7G>n]M3+]veHx},[bUg>.iJ6U>jZ%hӅ3b`E$ WP~Jcjf?^Y(bī)O[hxԵv e\N83%ͰXtl+U/i3m\?ɧ0q[PNö g6Fg/ 5!v@O_۪FUC9rkT73:kO?y!e~#3N%~H?KІ!>vK-9M6M̥:* 6C=9 <O ۩`Q YIn7!a }>GĦO|u pN_mL|&7sGFfNM؅ܗ-[k86N)/F4ͽ_R'~gMֶKsK#*ĥ)2~v"G_wueF5ч/Y~gr4r‘v弰+~5/ǵ]tbb*߻`0 ߫uk+HG%12YcU;ˤ,uWT7o[ZGN+T` M⪟+dG}{(|@2_yhתVfLYvC3?2b@A8дa|%^ԁaxj9I&xE_95%Ƶ},VvwOs D*W`{щ T ZN'4T=ߒE(u53R֢7 <3ك A~ BL mv8R'.5_W͐KdD))sj|v!X%5vL1Lnw Y#1ư?lk{b[4H qR 1QzT U <>rE$%њ};V44Xwto: w4ƨEcM9By۰GP~Ro@~';gcP\7g_*a2RB4 ?!4l0S7A cPb~Xo!3y˘P.V%vԹ:~0 ?Wk=NS69DOQ@_v Cf}"^F|tyDU3Rj|p `CTjď`ɺlb_&0PqwHPDd^v,2KfCf2/KqWpp r_z4m;rp ~ϭ?X hݮV0*oDS A pU߼4f%4((86-[ѩu:K9Cf[ݓ܁\7%xT{?K[i1 D#? .d݊/H|hEFH5rɓ?QRq"~o]|A|HtAajzis\<1pzl5ArSLϓЮ[9ṭgZdGRpUl[+%^<~߾m4AA<Űīnt[Ib!+Yqg[tOʙ"yV djNWIx)`Yʩ$l mSFK*sʭt0gϹGD@NҺA?cz tf$6tbјe1cg421bQ,'Z4wM n`/XC ΂kڋ4sUAҶ_4C_[{q_1e-zVv9X=SAxCeH٤vσ9%t_{8elR6k$*Ku%#`_{=F'ѿS*^][pr$4\xjЈM^څ5sB@o[3I(wM˘/ɎVBRFq#984\,+q}m Q}U^hgcViQ8elCRQ ,fy< ë[,8t_#}Nl5laR 2,j(sZ@&D65SuLmrwu톺2_v TcԥXL0P9xY? cEe35~/bj̤3oi|RܾrꂅGzևQ^\ΰxc,v V. fFp%flH8 j-fZ/m"޷a)鱃t%4/lvɅ+t:Q}:6 RtagSaLsڻEL(504x\6Qt%#&,1Ǔ|i0np}JCou+a JYYg4DgoB7 "oW?W!ȧ;|à"z!cR_H55‏+\#V]B [!%~Fv7N1,;"|t5fahPGQ̋{7J|0I=ߒSƐZ?=B LjQ":xU;XyٴnȔk/i{[LGOq+P:IsO0M^X{lBp1QWdX?ʭ:wǧheҢmD\@~"E#bXLFi0!D(w@WvA$MЍ x B*Ĕɉj|ϽrK{{C2#QbO'ɾ2zM_($Y@,WJ/^.t ň [郰]:X.J hʇەƒn0@9 |D|]ԯ)v 0DB=@%qT,%yҲAwQ +5Z\I 8F3酒=h,15RRzKd367uΘyyVrk0<|φ q,DPݖ~Z3} MC*ϷJ.629 u opem]fyKve@snJUTlKG@{1Ұ%)-S霧 _I4\;/@`ʧQÄzq1q-d_]`64s\r%yn2f}t>q$*c]5Ke^@s]V*٦7~8AZџ'ڕLhEBepNp6uĤ)Kp7DpYݽ-u!_33_dHNeuu:r% MWO8L[@cLo^P-$潻8]zr} NJ ppJU.?,V+;c濥Fg#ERt+f%Fnh{ή ߡ츂=gGPYp^)1q/tƣ|B01q xr'l_p i!n1#iܮ8jVИ;8n#8:=1ժӝ2ΎN x3w ߧC"%k[] %=t_T eoVHNLm SZ1ߙ ɸ2* A|uzSRٟhCZQY͡bb_jl}b6a$[,\!K_+zvi3 3Ѩ' ts[>)oM~sCNvRV#w@T\*Y_oI9>[*>n,+h|o*K5Ơ1LDbuXCW^\ZuyTpMZLV ;F+ *ij/*>dO1w*'i2{ p+*#Bʈ xI5|qL`cm*r U h-dǽ+vx寺alV?\}OGE܅̝H:e}3ˠ 1z{.u[rMv)*ZpK,:%A}֊oEktREs9: /!(#poD?9JDJ|KaM*x>r􂾍Žq|w=$aK.KdcMydo0Veϭ 2O؝gY(K1hQ/bwgr](2c5Jz;Av_2VMǵ\mbӣB?X5|SfSvKkNVǼۍ}XdWIDɺΩf8@P (Z|r4fރ)E>p:Ay4=<8yɦG'jJmM1RKHu JéMky~0 AZA؄yZF@lk*@?R{qXVAteՈКKH1d!z8&˅ݞ| {xCnqzJGOLZ4{BJRUc>+3$hIePM0ʫ/`9m>ȱ& #_`eIo Lfnp+2X{S}~Z8zKBKmy 3"e`)KxpwJЛ:n E._4)RYa^Vz͟͢}* %!H'R 9 #ߌ9.k .B42VXբTzHؗd}y:0ݵO:[m-QVܚM5ʉfiS"6Қ*mdѲ7o-Ym K!&k0tUܼ$B^XJ!Uaݤo] lrG&qn jBf'^_$ o,4\sئX@}+Y (/ƈvKМnNB7 AOUfd{J);˓ ,,g2pQ'`hз PxMPj,':s_skIoLRR]|3@r/jk|Mts[&,PzkNL\[%*_ǎZ&UF*ͮ8OZg[L[pl+qtoN*u$,ζA2G6 n-h2B͡Ձ-E兴+r3i@2tX u&%2rY~ tĔGTZip9gY{|I +,֞_~iڅ^yR(X@жƱG770 :;Wu)4QޞLh/eM|qo^# utڻs;)\AlNXI@ 5:".t%~z'D:Vq"(]B*MUcp 0)aoݕV-9V`/Aͳ +A$~[-s^%96jI+\ܽg;2iۺDI/7[++WhxVI[9yN'yBFJDȡ5@勵 '9sŅ-Q#L_a%77HJS/P4ilPGwuO˱.u·j㧐Qa-u[#dEvX'?QTnk>J7B)VP&$8el^lAӽJIvh34Nئ. w6Ě$?R132!J#A_+&)=:]!ҖZp6j]U\8SXS tTA<.P98}E9oǯz68Fq#a! {M]^GHx|W4irezv 1C }|I77 'oi *lTˌGg,ldz< qCCyzs#9KRmTD'ApD@O:YqbiuhHl'5ra gA% Oih<A{H!W#<􂯁yEoW ΌWB%ʛtIhA턺ymIbtJg3SLb΍HAyÛV H"|kn*u }OcWKAU8Ds\P-CMҜ91ymЗ.PaOٷECb\KِW~sD91r1em3c},g9w]Q>ߧr-#/TJhvڹ}.$_= 8 w!3 0E`!aM4%b?.# w 0kH4dC32e`q o0T6Ӄ'X7IWdzD9 @JMmKd0h4V<&&2w`S`e;">.='x#ž8)ځfuIP.SPs ~(KHg^],mE#ϼG# VARE]/!ʼna-.PwA hcڌbm N/D7FGAC&ײDw20%&ʲ׊k;Hܓ%ur{ 0B2L"CQ.2}x..pLMuf.j Yv۴h@}AWӢ[wG)H3;`l |N }k՗Hvc~dL5:C RV?mGd%adPoeQG`Ӆ/Ik$`<7]A1eg*fUPĵ2mfmO/׳ rn}1ʚbhs!]ҝ?ӼuB=&wud,5un֢0~>\.hVK{6" SEL K}e iJ|RRB*LH[2{i!̹#osL^bW0P0e1kPrS@MЧ H&6bQ~ v^,bu ID`ǥ #/ݚ[Շ=ibxҫ^c@9;QÖ́CWR5'Ļܨ]unBbe! 49i`Q '? lNW{ g|=)k$Z5~zB9υ oLl8nrZ좙/|f?4{l@rP= -+ZOn7NWJoDUefUOJhSq ɥ S˸qk 4nWqTsP*r_1 vK}`..|Foo8;[)L7f ]KwI&+YlBTh"ۣ[ )vyeu.؊u] O\;6Z7`\A ʾDܓFLvtg+/ Rݴa;ń0Kx|{Fx-Fl#]hz&> R8\UɭtPu1K&o'nJ~T-c˦ i I%_"k36?U #Hz-TQo ݚ[k[ {ݐ?փ8f>!1: j"%F#t9 [Nuڲ/<5#zR#w:=@I᱆pjYwj~ԏ9p>3MfŅl5}Rlc2.Tplkpf?5eJm9~B"!6/.ݳf" ƺMt~pejϽ8K)O)aX*&=%ϯ pBnzxQm~a^7Seۿ.^KAa@B6f~0@ZÇD"2bA /^1#^j38|؞uQX91;dY qH-$缺Q#iлesM)^_H\톪2"L2^˼V@=JfBOi\q,"[sh~4`9NR PI4nKM0X A-kxqGGh'Ҡr'[?*V)}.ǔ~sP:#~r%anh$,|eT)y}S|eS5 x8|v9u'  ]*'{D',@)otb쿨҉ Kscw@M dCu[bȂqOe#6̠]c~"nĐwu!}I+ }0p0 z2i+H^) WX3:r _Z2 ]s:IY-Kb!/H޺IhnwPg_s{D\;^. %хYvPcJępN7z6iS9g͸bZAo5j9z Zp˖pGv|Vлx=/S VEr¦KC+ýi_ /7)*c^[oED"7v@[A՝.%6٥KįUIe\zr)v1m2ݔr|O-U$B䢐eNpgقR}<|D`ވaR--k3܌^%MbkrfCĻCX0@(~⭌ӕ4|XIOȫN5u0SolP`|QNJ,@;@+vbhUm%~48#=]xWt'޻MU%e$r՗T8-1"uF1^Hū2fsEE{l " p\m_wʪztk7*(L!Q#pnXE~FYxALM.zYxU.l88 Hk$\CzR 3U+KBZ k'h)b>Qg*Iy (& .`Ն_ }q]v"!M< "%J HhUCǏGݔlFb"#arpϭhV+;[8$7%qs}j~žӞ1dJT#2A $-G92/T02F? 2.H<:q!X?>3c@'WC- $I2L6p.ۜcpuK䁉Ip}e=UQ"ŦA*r߃mK<`dH> LLent%B.h``Wpmjk;l &LyF;[z58-w%`K$]ŚeX&*F߾tnN2fAF.r Ȏov#5E WN뎲1hݣEԍC=Ax,0rf[5aL 9ԅ`hZD&z Q9"4H0 פdk16|\H^s6=c[KAzZS³beF[=:^@d0l= qB.KLe>4s $3R;cdA`1rBtjaa>)] ,}p~ڬ5rzR, $]l!im8xD*\=3Xܻ ^OB;G3i)W2.j\s?7KVlݾ\טN^K+]Jw-m7ާ/&nb=Xms-;G MJE/c:jLpIJ̎s7}OB `4y꯹)]Z@o%Rʶi%Y=Z:'A]z͒1pAgfgzV@D5$68δOs"_pGލ>Fa _|/-iPj(NN7]K3wAVSm[2/>z]UR1{@&@/"n\#N~f;F0WIl^X|4pNs d%5ft9(%Îdy&nۑ&%OcљҾ8lTp<9ߑKP5JmT8ayGie]^IZYXj%m8TwCM.<?Bf2.x!57g_,̜69yA_L%}]ѕ@_+k8C[ORQU[5&SOA쮣f6Dh 4vC@)<; 'Xq6&yWaew^,}q6h0 yfBbR@B|@迚3(#n'0\˵Br[%\XEqTM LjmwYc},'댚U,CuYJDD[Z`cz-nNT_aʋ2aH%Z+]FNe"yB_#.m ?ܝ1Cќ}T' W.>{#O3콳.MCCD\n lD}˕]Z(' }^"_>N|njdԀЂ|$3 "{Xy!3v:.QĿ{X9ա󬅿c'F Qo?pitYJ()ALT_3Lrc3.AFU#̽P+-=ˡ(QVBUDIM.Wb:"Wkig AV}ýk+bͯǗpE4f/b|;XH;3i+Wц;ٔ"oW|yqC+R)λx"O -nY$SGNWfJ!1IN\ĕiy)-Y= ,ubȁKz8f/ ͎ nx>SXU/HA<$a3Os\ˉcKhP7(@bHlR~ݜӶ3X,kWzm+P'M ]4I0I(ٌ2T{@u,"=R1eoĆ]!쿝1 ҏS(KC)#TrJTv.TckVz)L5MB&BL.x4虔 ǃ,ҠE}Hgˤ;M2UxJsoޡL\:>o#anAsvc 8> y1Ο;ZQ4cpջُj{>{ݻOZ36@qPU_9#e/d |$~E?Hړ ެ $‘oGVaNߔ;~g[8( 'P7}&t)'g`4){dLJdf.0$ Z|;"-E9$[b+ 3B{T,O &c}2BzLg9fr˪1'-d>>Z`U{m rnUCܺ`2S~Q0NTLorZUנGLIJ|e-c#(JFKOENf: ˮcJe.0j9^ȸ@p~wƔF)uvՊ=+oFT3qw ;z3Y 1˟ =a'4:K\M TYN2Ӧ@88,i,r?yѮPhȇhJ`ǦDӢ9+JMP>[ka~DJVOR|jq0 O=4B20͵6N]= ԅoW ϖFA#R'>q3pD 0wtefܥbuACphZI B3n{]V5c,b$ Sn?΢qe_7ooގ тbzY( } lT7q7ۑlkx涴ڗh$1p+ q^V:CT6|a{ Qr\J羪Xt\o oJYG.wO ߞ&,Y\OB.i͓\-Է+ P 7A\CA`{(XL+g6Ψ̹xiOB pLP1! D Cag`R)J&[)_%oK(G}NU VH˵&lciu6 i2޴Fܹ >vN7E\7|IKAl1|s) 'u`8vTu =EWamZ~5p蟹 )BLLB?:W1}Ĭ^ɸ͒::Y&lk=Ei[0Ǿ08:WCO -q5`D&յ".Є p]5ߝ r!b*6GY6ivٍ탏Ί,{`x"䐅ZJɉkNM !1Ģ`@Ek3t3 l-%0/|Tgnp%Rb ۅTC0h{%N*lgΫ҃|]w_7u,HOM/Rs1GC8&p.s X{2))I~-蠡ƛvּO !s5ΩC!ݍa Po3˼ K9b0`3q"0s:Tz{+؏s5W/0fB>+g@u#?( N0tV߿ՋW2K7q{{et>K",bLӡҿDkMF<ߘđM!5_zvqG 5A2tkK,ǍB8Awzfo?d EMo(cPbŪNr #j%Hi64 by72 hDbHcd$"&Ձd!NTzpd&{d}q>ϑi?7-dmIΐF-ZT19} kSO,8_qxiP(y3iV×uOXY/!>U( r4}5˵z| R ?5,;wxOVHp =b4m =uɕYyxX09Nl3uWk v+=/e wTtKVvhU[g.@%ޒ\ezQ{0h l-MhϜԺ 17$Zd(ea:?rDc,0e2+n%bR5r1ȩug~X鈹Xe]lhQh+)~沵-\oʐpEyh7F*ӰI)ӏJeOgjz(ybD$mY\\bd߶EN)G8qysR5u\oں6Bۖ0,u\,U e D^rk{3ig/J5ǜG$j /5 "_ePtW gݏ=W݂wl(0B60kߋZSrx`]91@`+j YXI) N{t~"#9pB!ГPv] eB$K@)) xؼViuoy .z#ug/I2<QYB( ̺ˋ)_d=?]Q S߻r5kYW !7}l(WxWDM0߽Z1zq3EEЅ qwjۙ_fL,Ǘ+{{0Y<`"ZTF2$c39<"}B_ϡa_Fb?2$/8*An ]NHX6Aɚx`!]IpR6u$lʮUqsO|i3Gwy,[& Φ It0 ܩ/D%CdB,[(7bIcO"}Ln۴5ځrbr8'n?_4 @:EO=L]h~۟p +3%B$ua׭GdmwBR?h7eDnކM4eha/)iӴu-bD Kd,͜SUC$d]3ڻcM܏EjH_n=_Z> Õf T0xӏo_3_{Ѹ(z-N3^9NȾt9Hi]o3wp9]:y\mvD[C Tȸdϲ\,5Y.=ȇ(h~MVA[&ufe'6Al9r6ls_޿Z'v/;GޏKH](> K0qS4a}UNX4rY#w:Ţ_C;ldOJH6 ԍb!h:jsn //nRm thLr)=˕%E<}RI!'|*ErWg,\(Lg&b'Yw#Tah"Sgy(G?>VQH _Ҥ>5 BʹiBX@%V؏X{F7a;x9ꎯ\CH$wIPL&?M~X}R (u9Hm'ukG#)LTSa5g1؄W~fY鲙!{vH$0wQKך:t;.Lо!)c ,s#lGv]c gMiŶCĨE}`ټG8iuw⊶=xbͧ*{ZDןҩܢ!Ҡ\P^U .,sBeݸ LכpGN^U[K$!4vm3`v'vb?bˁ&0Ф4x>zJGzWZghs:Fm2VrX,t(tɗGl!;-YbӒKRS fLq^lCuQ ;Dψ~i= ܥk3|fN*zj3!Kn4P_ 6n`>iCڄ~<ϘX|Yܧo2Jl ̩TnԤt$D\Qpo >}h1$ eln X/ SQ9KJ ^g]+CkM6;4mF.'K_m{6%ʞIt@9$7Ǵ+A0E|Z S|rȾFd|~FAkn긷 !S|nrA&!᜘Clbp2Cyr/(B˗gi)&AK>jlL@F_ ןSA`sƤC!zŢ^̇>I: 7y>!2/{T_2Bԏx3E E:|;{Y;^b (+g {n)]CZG2+VL! Fu6lU[~;Fo!ǰ ĀKG͂A^>ZPUw}G΃ʣgN2;[%"vء2RVe\UaʯJ@煏F,fsP OsK~=+Tll\X~d1+)X)#1CH-8bˁv /EmI#D Uy,Ѹf&Y M?FQO͛ᅾ_^N@y",ݱ˅4*.@]x)I6NQ@wZPWڀK:/y" [41Ү&*IHSqFXꚤc LKhRM#Z~\F&,fpO@(!I^]Og&,+|<>UjHGCHeQ+ NV(&MjդÀv;h^QA@P|%7TH+Qy,M.0H_i8L) o#ɝrT&"roR/ j.]sB۳ю'V6Ҙ*T(7'AAmqХЕhQjq`y Z.(jFZC|>7غ {QOAX*W;KD!g{}Lu1_8٩!: D+ I zx/=[{bhxbKdu[jTr굼bv@{uiRغEq!)bJ|Y.i3>οB@y1͡1p;Fl#i_oSHDC:?37h$~Aoub@!;-~RENБHMxw$)p̱,U;1`pNPlY TMSDut\(UHf>C奒؂-`0ឣ66 6eʑ4&Bm9ٝAh{~xkl̷j{=yA:vQ[!T By}N$6vw8NB+vu8\>vN_GzHFH 1~ؠ)rrmsŁmV sE{B웎1H/~&Pl' eJQO?ZQx3bQ^{)/y}K01,'O0Y@d6KNJM2D$Nd!z4xK tfoD"F:Mё+8#X/A HdIk-_!WTRW˞-'GB/ek6le'%TiG!XJ޿k C<{j*O̭::n% hq).ajUbZaau`)p\HzҠxv[S!ȎɈi:F{PQ}=}c6x 3'T:ϑRF6ZzJhjS\JeކRc:-=0w"9ADDPv1x~;hAe'.h{u+9[ڴJ)- K:YEY:![z ZiT|gn͟\\?b41Gv'bm̐HTzN]C}nGBƴ~@q'42sVmhzED&OU'r?Ol&m!1]rWAAV}C{ 0cxҷ 4~l#?v4<x]yo~[9Mӵ,y~Hr~'0V]W8+l%in m$Q/-7޼+}z|9EnFa<ރp]))ڑ0jLz-$ o )I݁߁]ׂ|ccd4=AL`gqkD]It%5_m@Bo] Z#.`&*Wm1^l@<z~ CYB#QCwO\0GA/`)qc‘P~bj+LQP(;[l0q8X5u3#@ߣޝA)A`?@) hQ"#0NeMvrU+IVA%i_&Jh2N5I~ĠHF٫:Ω(|tKX6&wmť,BF54!Lg jwv*(]gVgOP.ڪ5,PP 2fӷ=kCZBt}ɖKQ; !72-zE"R/"9ƬW? ]"QNa4=*8# q}ECBk]X$2S R=t.I}GI{vj~:K;„=&%Po6z۶Pj%V`Ƀ1:3QU2|j & IDSuR˅ka1yl7Q%:8l<фZQԏsR+48J;SgܯX/RYNNetskq$6D % R/O%rnAq1i1# D }1ϔp7dQXPSI`HjCjYB+L5Gw{64utc~|pL!a^xzd^GtˬO³YPҪ*x{}{x%42]zO)&_#E6OKT nk)dV:7>Wœ`y\򻌯4cA}<'ѣ,Rg@VcutʶnB } :/Tk)iJi(Χۙ g`W'R{#Qꈋü +:U%DZC&khM8z*Ϛ2ZZ)OGՆoT'.5(郹C 3Q>l~lSE䫬Rƀ4%RxG#HXlfHZ;xUL^U<˽aze5hjcJhFw[G{::k){6o'n_8# ~m'JV 򑬹:a(ޥia$LI՝LЊ   Y 6!Iuk̻FsE!,? rQփ;0Ho?0&iC3Xx"ӁP8 .\k7G|磊DzNôD&zͤ=_czHd8+,.7;ѕ']lUe£zV%wwfvN|W|XB#7-#R6Pn&lvh~ JN HUE.;F+;y:-,ga{΃'6h˸uMƴޜ2U;@tIFssӮ :> iC%/D'Lh@BݻFZ?濼o͊k?"5_ɔeQ=ÒB>'ŤyJTGm|ƦPNr.J%2l,Qؾ !6 NaΨ>)€7Z& OJQ$;4ۼԶyɢ|UW7vq/ `&FG b2ʓ92wмGUoDpK اCC)&r t@x!0{-D^$ho)5OA"'v 99!Ze[~$ekdlMo&G-c|"C>zeX% 8ii0 }X7,)v:tEn7x5"B[;)2 v:2meY,LLU toO 8x(O3? K_j)ՅQ(=ej uOx,ic?WV&e cӽ/^~ًy vr-Q-3O Wy*_ffصgy8o(wDɁ D>1 w&u\\Kb:Nl3 =8m:>]8ցۺQ!˜Q_?T+n Ӛ^2={޳Qo<E<1'/UAֱ[ӅTqXlXK8nz {nflLry,G8{QЫ1ʢɏ$M8ƨ}z@H `o yЋuRy@.v$G3Q9HA.wmfadOY8M rJ E5*Ny1aC4b57[ҍ=}o" Haӭ5z>DEAl}j,7Ԑψ1@#]ъ"zЯ JIbN1hӛ5uukΰ(u_*SHX< Mz;$Q_06#9 Hέ-bf?;:w~WOhi S>3p .̲;q4j T!_!o,cXгnF}нW[9V:\**~CW8EzZ!j. @b} <>0YaCo4aIP+-񦬱j)MK2NS^j&XK|:"Cheq.bSQW㆘-q6xD}.Ϙ@sW4 ?4NX&/ 5@BYHq1tOѿϐmjq]'eE4K6u(> P6FFd*a q7cOPr,Y*#VbGD2<؟ª4y€ ~S0gSlͧMX Zta8*'׽$jJBnit_p_t}dvP06jfVq׫am=G{Y~ʲ-4X TxbO(?! xt},mvl?vk,3?2,Ecvlz)Ȉ@cBzeR|}ʸ0ՕI'(<5Nm*dP)2&4- D: nX$wűpvuDl)MUS Ua07N #[hfZuP}qIHr9hq}wҼZJiQѸdTPh̽^Ʀ|yW}(KЇ `I@߲+i|LyVM1>Ki_Ux\U1m/eg N%iIҝシdxn7G VKYMsi uks` 05rpl`tO_ ZX"uM>X94-WR9/TYBG:o 4^h d]B\خQ[ʼipE!9I6 U^?ť$.i *t8}Xа0?} W[QKEe%Ihq~h8CQH%RQ8܍=RVpq yQXΞGPcYh}$5+\a oRS.ju093( $:B@-6+)wej [sI/n ݃ d/Ȋ"Jp#3Ja*W6[ ()!Y%NGq;"jhq?sjɡ_ {&xhy6Klukk,܆5JTzr_Z*%@rFՎ 8Rebז߫82YRBTcHʩ )1jh] KuN"y(xǜ R+0{oú=)ZSjEP517=zkU&P7thȰ57>NRm4uxI{x`bUb~]Cj1_h\.K ,ȕd<'kپb cܪ1DL{_8݁z[AʅAOE۴Ce~Hi<:J)PfkQS7oB,+&! ג#`Ђf1YSɕ=/E)Rc6gyCdC]V#ɘ79Pՠ%L%wՂN̊)'{$ QFWc:zwumD(͔,@R)#K ^%If Y珡/v~ůAE==ɄCb:ٰ@~j4ݥŲĀuW]w2:sVqM転]Ԙ3 ^h H ZF1o/SV]})dM0DyQR !nz"p0g iL%SI2iE#IKToT#"p4?#t&X.iąU+&!v,! #{(?ۿG{e|l_F\ w]lK,뤠&V\e>f yq@n`}p2o*=NH3ϳ+!G,zd$#iÖy}7o}m%uERo*HIeFo9Q5kbvXd#*i'b6P~x4/ پ26u|pQZ`v[X=<#ߠB=htB6 $qDmnx*zLBuAR̙5 g_koIsI o5F,*B6M6l O*tmT7?IZFD$׽ޫ +R8zwBAE&az/NA՞ e=qDk0J &K^."}O쉂T0W uhC=LqA l<ݲe}ǣUbTtfύhPw?o6go+glYfw׷B @=pᜏ ̯yOL {4̀>4S@qK24#⇬* "7ҽmlZ3?-rHB P;o Rc/IXl`(eLx n_>qc!p(~/byItf m^oyg ZP]tI*U٫|>(ܥZ)$˽1j,}Z#9,.k@C+-^ HadӟH:<]M0jO$*` iXUd4kn@?܁NbI  H^G>2}_tgM '@VZJA)U16;/[s0oDpս~q`"+pBnZ>gaG7a0sIZdq}_ȸ.Mjېe]%'̼ r>|',XދHK ̄sX"X肹Bs{tM\Q~Q"wѥԙIld&y<~90w5?#|zN-JikoFU~.)wbo ZNp:&X"B#%c}HF0ܞHh[NEBch?6( ^]twT\ړfxW!)n}H] 5; \[՛ҽ.Sx/Swc.,ť0;,ʪ '!k©K_ Iڮf:zK0TmMM@'[DGuNH Ga8ȔY"2H/VaHNz8&|շJ!wN)ͨ02馜jg/ 'ilF~߮)MC`}jC͇F ?ZE UALEl%G7U>?4驞 2_;LKs-FqmgHh{ICj?m *$G-+؛5Cr:uL{s;t޼I'땁BSw V.U6(PI6M"t?^)AstfEQʏ`E^Lu|4* &6b>w ~0(3FI39F$XԋGY5iXȍ0ܾEώT;xIQW0rt4ƪfi _u)9KCy`WZ<\1u0f#qK H1/=^@D6*jI؉ng7ߣ ՐG]R|_i4]!cMz".HeC8+̊e 0ȚfBqV%‚ ;BK4{Dd7wISir$uG0H#"Κ{;T,lpY劉F[`=aEH(5ɶDv6~9 è R`}9 jF5{]YLFœ~\iT@W[n1qa|(np]Нți%tnl'pYT_ȣEr(}IrX:^0rHgTÈ 5ɋK^ @%]A00@{$]sfj, 橜$B~uecƻ`ȌҥzNN.;wCsg"aNr) }7ps|'2&m#ՑI:%Ю>dpr\ M k|0ʴ vgDg}5|e?^b4-E?{q-[yqD Ij8?Ή(5Ƃm4-ѐ>?~pvR:ӣ!E@cf|dH,/O-҆4?? /D[9%+:icqbK伪#IkwWqna5'c΂mn_ ڴ3z!{NxVmm,*{y5;H "ԳΪ1I׀ n4C N]vC qHe)Tې}A_.Mrs$N}3"DD0ыGHU1g4fWQT C :5O71Jp)PCZPA~_NTAn*5R%:5kL(Uk,uےFINIbs(9Nmf;,ol?c@BkRm7Ú_:W6kDmԱ\/G7<׿E(pɻ?†syIiUx$5#'{JfT$LԹnkfaE^1kWtd ɾYk>;;0%ZK> K()R69U3,i8Hm:VU|Zú"rSAKΖFIoMa Q?S+ ZyO_>r>˱йxFezD|H3I3O@P (3*))_d8w6Ixj>Q@=+Aw-igP[ sowo6tOӈ8L2qoe!0N QIgpw 1v#HSe رY&"rQ TH mz2R#k (t! tvfXs>aÙ걺;!u,EwL†4P~Q*$ a/ؽwń^ ܎#A4co;1#Jˉ7zԢͿNdC7V̓k> Tغc;4+sV [woi!kS@']NHV┫{&@PfrXBi Pn_ D [kfi. 4\R6, ⍇#层 RNW6~}NV9b@]@4f ,weJFE,˚-.,JF8}1WF>)m[DKEZ9FcJԫ|%vap?HYqCQc=[Bד(iѫA(ʋw{ɗᗍFy00]!QmV9S1k,MQ V_ u@\tζzSX CV.jo*5s%W]ӂGﳟO. Y*{rgnmx\pZr΁cĔ][´&PxHΟo q"ʚ:\.%wLŕ*C7/ V(1@kgLd5-Kh܈#ĮMN0Y/.v IRAգ7#"ukJY/I+ z|'y~ rE M?qcmH%]G65ޣʠӐ[N`m(hy\qpp 'Duo%j7 t1!~|'9`uPC .œb:iT^ЃˉP2vvp?lq\'HLZirJ#lA7PoQZey!+>n%͑y1w风<6_0ِ8'BCvMĔ>*Xs& p rǸdo\(E Ƥ56ϡ t})=nK>D:Pbf"b9]jBZ kF(v(3H7F@^q.`wϔ1~`кAjZZVN44ȋWFhϴh"UU v$@⫦_<#_߄l[ 6w p5)5=}]z-*ɥ+ڍrx@(*LmkK,v)j66T9m ]h)&f':Ds $ɏI<]7dNHBg{eLbv6a%|9 iEE^FZ!>&hd.;U9!#pP_'d VB w~*s}85ͩ0GϠ0y̞63]WIw1" |qq"iҁ/M>'!YP8ö6 D5 +R׌~/ (oG1XYQ>ip@ S^i%b`_ST4'Fg4܎]1?tːuYaf9nFQC9AoKqg3*~27]g;Q|}Za{D?c)V^P~26lmtC|1MٶpTq9z'e]p_^i"q&1N-O"ЛhS&>dC5y?gM"KH*C CZ+< (? -QOTL#nqXȁyZsJhUS*B%j'Ǯ^@NJ!25OHYpAKE zl{Efj rDpo$~b_mL|WiRm;NFe@gOV^~]<&*e.㇠A@`hq焱y ~ C'$; 6r;;Jp= ĭ{aZXq_X6} ۚ'y;d+0X3&Z!QP0l"8BBC|7p?@v.&C~ _SGYJ(v/W&!b̓f]Qgm\6z4ܞ ,G]cƈ_(wy?{;d+Ua ߣU}~s,sXyR~^OV=#O4Ky d*O[n9(SLub~ϕ\1 A@ [ɕYY¥?>@WNa0*ڐMݛ%N< cJOH G!픵;\b^BXt1نYQЭY ?xO)Y ,xpG][do'Y=G%NӴ|B럿55ʴBEܮV CVL ;,B/wK0eէ59^9{ }/!O!vfDOT~FƓԋVU:J T+Žb5R~ځ9_Kƫȳ ˞,IڴWa3H M#Pd!yi=ͦ7.3)+3g4)U`hO7k]u5VBh,%4;m&ysMIF ?a }7^WB*#ҭȢRb#.[ q9. `_t?ണG@+ag$],p"|R'\f"ҕG9`O cPmJ˦'i竁-yP[##I 8 l(V9^,M0L))OmA#dv>D[pQJ^BWH!pK@*)k&@3[jŻةx8uԻd1rr5ssťS#B? qQb(.P|R!΁9fzly~*25!H+Nj 6X1]޿)"ws:nopb+1Wۮ0yTrvC71m [M_p_0%}Bv[~.RZԑ.FU1q>SJN/ ǚQXTvs\WȀ@l$Vlv/&93ϭZi2{ l G1=W/]W,D.gQ{(LXr oο5k*~|.kD,>w"2 nQGUtНNi*L9tI- ll~CІW php|}T%/8Vt=Mt䳼%<᱗6SeM 7{1@@n4q%[pވH0-aJpgE)"eUs Fxn*9̆¢EW%;T.Z_,Oz0?5TZ-.̝X2J`pwR&,Nqw^# y%NpVEǘT4aH[Y@ zqY[j熚1ۚt/o 0D{o؁-j_J$[U/nZF#5UC$"{Zr86ֶ*tS|=Zmbhr=q+=.dr_% OD$yZ0t|ɠrjŘ: FDՍT sҿZA7kV qG2Hڌ==9pksq{ߕӈ'= bISh|JLiC(XO@wŜ Y[wUIq~DZ%d c)Nh?N+Bn˔ݗF$XVCl oCE#yo2FH/,MIuq-Q">qB0nGRy5.L0jBٻzVmwd&~I# B p9j{@A*6(ՋTXlZ]7H@v6Fi;K2o֤}$0ҷټyPʀJEPMB ".8MFK;HfuAx+K/,|Nsd@Ճ?evVL*bɧ#Ww ~w4XLjQ˷hR>&p:t̳RD/kBS:8GNDwڹGti4[cRS6N+NTGʎ sg%b KY-)Q*}*SBت̢# "N%3*ÐTWV>.o&1;_ 3J∜~|FMsV &b WTɊ?#tww=^͕e|  ͵Cl?36>gE 9a7J"jOGOMV(V)[!:&_?Pa\Ei߮gm\+>Y4yÇOi| >^n_$ؘXL_vg=7G xGV/·ͅQ"&_ȳa(9iwz),0wubh*6[O;`lMAGn &~@82ZXy^ht=n|EwVO0Q؝ndf3 4&EJք啚q@~JAD [ZaG/,\3ƅWg^mTSMfaVZ2^Wo2X(/Bg88t~[_nZ}en̵oYߕo .t=츊~P8…"yY 494c闟foy<[G4`vBTi0ܟ{횑F-' &A dy%5gȢz egu1,]`2b'Va^BDmHHȜv]GAVh< E]a㸫|b@&ވBzy:{lcYѳe\ h%NfF2⃟\d U`\Bn|VXbAT^:{`#EctSxpAS~MPRcmKv80˺]Swm=aqS%j3e<-VڨzZ;P|k);(B7ߕa{ر <=옭-^w,k'CƋԙ: \OKkИlHch9vSNʕVC3]5 ,)'4Z{|G%_`gZn~4\" /w|>Iǵ\cCY2N:~NNm˓dp)DMzֳmc} vU'>;ъ':eX 3B8 &છ]W_$1%d@֜i,tP|[;0Šwtq֗{CW?Rb~`+EfUuRŮQ ȜGItZ툟`,C0aJDzl%e֊쳭٢h l'E QnK"aj|AH ybyQz/V!Xx%mq)]o/'FDc|s;VO5ϬQ&ASuZY3ncQWȄ)}kuBMpL S)|3=.Z'- Lxǖmѧ}^AIL)mvP 9tp5>#5%(w)\,M#o]Eʖ91Þ3s+,~iBFh9 X79hg*DPZ_RHgy}+ﲰ?* A4EDztDf I9zO;!{VSg.! $2ϸj Q)bX@7ǂ+L>}<ך6$| C@\(~S7bIu8ӵ0MgE;_ I8VabB;)O?HqShUšqۦ?$D z ,>ؾRȒ7f[D,;r&|L'mFS+&ߒ fҦaX#MJj G',X!O[ ~eP`,H^l dw;CIĄ Z¬:Y qjnjz!*Ҹ-#o(’weszw^o ^Y%KE DFW]d,T/"`UlDST zrdD =4YY"+6̀OHe5jBeuPB_EO3ĕivT2(/JO?Sf=[{2a #Cv 0)b^>c򴵯+^2fEW?[0OhF(6U#ohδ!z{2h™qi1slkq%/GFE"k9{Y`"` MJycj:3eὋv2'9T!3)WW8[E%^ϳP }s֔ogWL96Om@? o\.s̬a[=ݭ287LQU2,AmuvvUy W)ׯڶO,ԯ 4=k7cDb%.R&VX[h5KJc+2J|$#k<rf1(xLo_:N~0~wѾ/[c^!86Ĉ2,A41v!#ЂmW$M`yb2xQEeg{83Ox,u' 5bQ +f)cW"\v7) :Nr*X 7.NFj?+1$?KIS3E%h}CJ:+-%GRF %>wή^ U%>ƛm$j=)aL,4k>a#öݕ()fe Ӡ)`Ex<`yU^Ժ 5yAGʰ)e)k9e,:tXTv8^)ֽ45iucFY4R;~KVHC(g: v€kʔvqkL|{K<鞘S`#~Tםa9-K$0Gʇ Z׬2B2UQHTov&ptΉ )'t_xw(go?=p"&2dp]h.ME_2B?}Шz]?I^t%4ηD֏%;7T}|(J&Ҷ]%'!t˧_ L(] 'ܡAC[ h_*- K'0} ˘J*ExF,(pR )6o !SylxHhɏM޹0S_Szx([5gF8G !꼬o]\5 ;ڏ|D-za<98Qc2[ $ GH+9V\J]2=tp!ɱ/3LrIć3[J;/+u݅N&_w ⯨v= gRXD-{[J1|7X4M UN VoCvӭx XKGQȢ:& ƪDkrc73xt*0 vxv:'3f 3ui/>so,"tK$"&MV^ڤjʸADZG(vUtfTUE,=¯9T݀gCq:HzrG+d89O:Ļ__+k b@朓w. Y۬Qs!\5v䖭5 9) hCr\ZԿ<"7 s"~P <#^o(DBɥƠK>Il'Ђv W"TԷ0z_m_I&֍8٦Zzb!ޏԉHw p[U|OG{"V5Ik<_%T̔ڍaRI?3."bR,o]ex+KU0*[t8bz&_RZU A )mdn W0{^ԩ fӂe$Vl0b3~Dp$os"z92KBT S{ SޅUMW!a] ;).Ed[&*Id]p 1kK~*N9_3Qlim+P\7C\n b=eM&/_KbPIvx%h-H&&(y.| ufڥP?wN:bO3U]գ8"`t_ O hLqi;2Uє;hSYD5<1^6 T ANˑ>7Z9jw:xdZh*[4Gd'Ӆ,'S`$JDSd?k啹cSVIǧpb!,qT#"ZM6]ݗcZr1ϳJ@ݩW5SqHJlL>_ْdb=G+mgp`W>܄*MX= q.˔?6n'L@yڜ_l$j/spy;Jޠɕkϵ\mڕݸ,LUMl1 :ꥮX9 `K_nk5c7k jTAm-[VDIeG jP;r#L&` HUR+=O8mK}~j^EjRQ2?K}nWG(hu&=aG$D2E7'DjYvjZI~oph{kO*>8I[" Юy-1hfPJCelZ}j-cE} k~H K(IHqjwZٶNդ1h3nRXE6@y?/N_xpAxiP 3P_Dt*o|3%y$WzECҕTrdw[H>!z)+VK}rk'ɼ2z{oݟ"FI̛W[ ~dAà("^PXJbz %@#笄[PRxClmfU{.KD_%"@C4/!>1a\!tfy*T͗"LW@$YZ]t"ÖW*ZӂlU_A,I3%2xI .W^YҢL7EX L N=(%rMk^w E$&$tB8) 8? g+7kri sEuoIleCtqq^X#-rgڶ,%4`~HaH:'~fs :mBJ8}ʁhV˯g|䵀5zTax -uИo5 s^_u )x 2&)lΨpΑeB3aP7n?9oe!@:ʺ-M%H# dDͪ"eĀEݧ]iog[RϗehuS{3V~D,!o?Y:S\ ϲAAPg7ˆ"m,fo F?Ų$ w!m1Bc~^y+G;:ŎϺLމ) Ƞ:Sm`DrE@&+> MyEcvۀt'~ALb+#a]|8Z^"uVd9h7NqOZqRQ處^X&daڔzJ,b۞Ls!INC26n q{"2Fc2dmg{B^dlontHZ?jh/J_.bZV'=L1$INtQ6ap?Kizjn 3ȼ7u,ƌNxhⳟǏ%ʊz#PFvxajqJ<\!F8D/hnos!Fy3+A__\/ 9Ri|/e"L/tOk1TuZN'k5B8cl„&8'1S%Oj.&Mfk<;BsO (k'BAUS;R<mc45ҙ[.Ju#Û޼Uˡ#;%(1f Z6W5(RܾcVleF Q5sjc2,bJ}y©0cH?Z.8 d˛1%"Ay ﰐes`_Q)2MR o^*ueFN̆ . ֚5>Vj3S@MA_3%çQzH1좷(5 Lvb"Vg8260f5B\߸3 紱Vg GTNJqsbyk>%80چ*2%jM$}>+ EaLvA$ bMzz+ 9]{ e{ &)d|AQ~xr~% ,)N0CFU<1r&wקaF>ܴ+Lj{WFx"ڏ*3 n-(T$C'pH\Ny[,=b(U)dA6W },I+!Yj+(U ]g3en jRYw{G #"xbiʏ[ˊf6!J3:r5YO8Z!Gaup\sWFw&/֥ BBۈ6k0>j]:6:,BRcFJd{*"9uRhG,03AGh!j2(hfU(َXe gӚGߋn[/t/ SWOQo_\$@ͽhf=RLՑNeQLL< #uS[z*D!\W!E: j_"b9-&F{cr׿(4ϳ;gDؖكEԑEuB oLa{܊b!/_+EzeB}} ȹ~-K}b@}1 l M5NA D@o,wxwvG㣂A3,=%%qEW*JeU,S?IGS ſTN1gɧ xfY BVH^$E\08H@b4qgA'fцi8:I~dR`mjz;|/,Uo_>Dk?/S֙߁NFկj FTщeiHb+l_P;]DpA\Y {㤚3#^,;LMQG#xVXE_ޅ@ +-B1B_ bHB}" Z2bxucz<P6sYq~.t0LU_K^M7Ѽᆡl hJCC0GqB99HhR/^5M%g7|W<=vJ#S/뽈U:T,N*lS,p@J]X8PM444-BC͢?BGp2Aɷ#n:@O42~j?/WEP%v8rO2yЁqJX-ʄ\ IsAA?ՌP$ $P3Ilћ<[k6eOR(GJZG`'Dm猽qq S2?F뙤?w>OY&RͲ}*GI`@Rx~%W)Y;>/idQg⨂QUFyx3|{&ŬlSW5V/(t{^bR!ϳʢ> d@.vMEqj߱?L+= w58*U&-eD_XzРsYyXײ%zWjE㏟ӈ>6wԠI8L+3b(˒"Oqc,8Rr >ī0fG[㣿2kFrJSEp`CEߴ02PR0}7 "l\>;8✣Ji/OcKMOEtxv"m,[|m܃$a\w02BFuKHUn%e Rr"L}=+G\}i_r> E-G{ ƃ!F)DX_υ{@OEC8Bt-e A-z 3Ŝ tK@{$UTh٨$f%{Jv<:@Ĺ J kd+KB :p#, 8d^7xhi;S]_<1is[fpӳO"<37 &*}*dTӽdzۢ+kz&b~~(Ym _Z%$ߥ,ټZD4cBt!kӚӶnfy[B&liPYSx هNT:+%Ԩ?؝^;r Npvj]LR,JAlj?؃ ;rA >Xژ*&G cm^OC^;5S^H2ԌәZ!P;܏2ZWZ ލPGP\]a-ܡރ/?\,0# ai!(oV@>޿.ա7`qdJ{d#3bqr)92u]0@e)."L4 j @u*>p#ی0n>Ԝyۆ[T)RrD&UwL 7PGT«z) 6}Ly8ȀkļOP)tr gӞ1Oɜ z:w4F6hӑwH]evG+vCtJw* CROYƲDWiKƢOH+D0[~8:=w0w!x%erQ<HwqtxA7?*;&S"3o֞,L8Ob3WZ94JHv5lBײFAjCVcf}(\J M4ckRǟ:sRɳALJ3co~4.SEXU88ZE!Y..N3 VKY2~ox!"rn yTtL.w*h4McPeBF=8%̱i& =y=FWVFp(pg6*΀:~KAiI.~wu+ٜq s/nMvVv>) (V[I$Gױ:׫//-p~_+)<&d DɕwaY xZ0}4>m61O)=V3^²^@@[~HsMǤ<"=fnQnD ˠZd;њ_HWz_9l9 \zYk%ٷ-S%{ȩT]??~jxJC ʰ9@*1 n]]^V ^9MwO;m2a!/m( >fkvfL}P"#.p,=oSrjk1 H݌IO*uJ#5$@Sz\&7j>mdN"*IP<͊mb*MJ\VOLB7obyNW(Rݩwn6~YQyi[,zl|aFоXXǝX:>MOȨ E]b@'J @X1 [#*7' G|<1$c@ѦKDbO tݸYfŠâ_b0{Es8ҭI=h&ĮQL |/YZaZ2޺$hB5=zYYQX3qJkOI@JbEʗj-k\9W]mq(p  I5T5'cuzwv0O?h5xñjXWABH^wGXv9wPi 8[gPYJLrc0f-%'*Yq -v2'uȜ.2MtvZk0v5_>싐"ƪ_͆ѓ!5%>ۀҾh;] 4tM8gsٻ-{e_"@X8Z=8TvtG cb?0 y$ ѲJ1 A 53N.' O:1 si?V#(D\Tct^qm3aĥmjK+\47Ҫ#YPŒmU1j(ȥJ]`]"|mJ\~Y̞[.ۯ^; =A̦4 \Vf~k5Q5.'g]wo54s3n^7eㅫ XX!?Oߪ\:U{DrjD{x: DظqA`KC0wAYt  OBؙ^? :xIP靈Hafy% SkBǽJR kX1@ߚ}xXn I)G_ :DC"&Çf-D8ꌴWA!d( s>χ1`"jsgޥޓ[և@3~bHcpVˆyԛz۵<&ֆ-u ԝk$v$CW6{4݆f{upnJaLUMꈻzN--|7&qnB@4H[ Z&$Gr n aT3Dvcr}'SQQ6#I6$o0%Yz~NAG;*S^PDǴjU-qx ?444cT\<0ZHt՜_lf3+V8a2wlx }HJw0 ftL^8c7Gphr5ĩ(:!1윏/K[UhE8Z)i$ò%$@TWɿk)?_+dD8^ɮ^bͦcUi`B^\,x _fw}=y!',;#oNr0+ Wf;K*C %PM@B%`1t u %m"uZUfH !pjpW_M#׸0 xGN,Qc8Jy mސ RTQ4b."g~K1MbD 1e9Gێ2}@αda;#_?2|aOaՔfDkϕZ=JUQ_}`딪"1=XPϟƲcJ T -؏H~b1[@Hr'AU!S32O6 cEwߤ :#PmIn78@(EW:[)Pޭ) c^65 u9 (r-Jw[͐Z}UK_mh 6S֠Q$:{"]8l>7 o؟@#v&I^MֻVIxTOyc70~Akwb)YhF=]ٜ>ʞ:p[|.TmRl'^`+)v*KqNlf!P;GrI}Ȥ;zke kagXdPdu -{!Jzl0(Dl<Ŵ РѾeq!_Z)sۮ ,:t>c2tg9 =뗆Cy߁1̩@tg)*E$$4HAmUY3 1'Aˢ83xtvBlGjHM(C zYi B"&J6xXSC_,(&9g^̞ 9\DO6WxIe:z b;pg> 7x׵`Qy!AT_WB\ݟ|6`*(۽DVV9W;mK/U'Hl ~WXz:-Ep@I/֓Z'/Om\o^6Xun J3"kgXN4W4m9{[c{oY P I̤|լ0`/ O5R#RlUV T]H  (vc{9WSU/U=ı Y;Ôxe&r*~juŧ.re96WX XoCjޯ"W8OP%hj51Z2B;Sj:"w-0X!SalTn&}YazPqrO"DǨ0N+꾤#~ܱKg _r !}Eh-B%ɲ ܞD͝]*-tʢ)AD7Tbo̬ sC7 $ <&|/7ȇz[t%TAMR tmG ^+Ѷf<1zv4xC}[ бdE^cyV[nRKX@ GS Г)sşd#F_F#'@1g<5cm~\CN*>zv~8(7;&Wj Lj¹y5ʦ^C\4+C.M`Uj X߹f˔fI_b'߹|wrY<x#Xp !SΖ%RT]~1`C Tx9]_!\[=$J%&B^OP09'#{+;FmtvZ>Q(K"Qx[mו=Z0KsE:vx$7~B_w͙f2ѩ?f^BеP )Vm"cTob04jHtqѨ?L0{XYy&"e+ 5y̦ RRu3sRl涡aNM4ف;D+Q3=\rF!Sl43 S_Ն\ɂs- &Qn AdٓDu$A}GX4Fc^1T6x f]%ړV)On+QW,օr VJ`փej{KҋS px3suo TKDz T:q3&Eٍ`jY 1`6w~H-kkYiEXK6]rƖ8cIl(<&j?VdTwQkTP=9cxj'e-waD0ujdI`fJ\u_>)Zy 씏-"*ïQr!0\Tlj*IY~Rq䃃u~F8zzvZE@ys&f_Ef*SK.?/ܷc &`(B 8OzP-P# 5?mF 6/41FLs,Vky`g2b5D1 LNϕ3ncu&7\(5ʖizEAƅk3)Б{+4xEn6`:i!<-583ԊE˚D@hSo!4QҞDXRRߗ.Tm(mpjPGjGh=kܧ-Dpkr=G8 _Y>|~v(k_^m [%Om\Ff|b8zDZ'3W˘ t !MM +6m2{ 1ιGz>p>\ >\۰2+luU9B2i¢sfUYCU=u뻀K/N&jZ5WI:+4h2 zףvs.[ګ$袲2VeP~Ao*oS9۳{;\XٙVRc. m|䣧8Zkf~͙DDƙl}v%g\GA-2wLhViS-o"x'PД\UhwѠ8gv1v :Rh zy )a KFtN% c/CYL8H} |pfk!_GfBHjGkuڮbSG6q겜4\ o7i'?b&06!qco 2`ڞ -F]0Cg,WT~mx3xx_0hCa[N |>\ 'VSuMs۪ǖL,E'SS?bq>utB_t{NY"gAo]ġ;/p/{.9oyayx܍~IKG4b KiCuvDmNgJ#~ gJVlEx{:|FxOd~磕"lcA$ d,s*O>Q3~b9E (uND8܅}J)i3x ټreY=Ǻ`np+ss8E8Eјg#`I?!5gs^]^YJ5h 6"uvB3Ptx>P\ɡm?~ X!L`<*x>cs_u2*T@> 'rJ88| q5K^߿kE %RW@e{;ᩔ4|p4f"8}%$o͂;V^=Ea|b`9.{YoŖݟx/u__n;y+1'~B3ch$0'-!CԢ{MuW"7~%ҏ$"U-j;B >/9ˮ*6IZ1u˗oR' f٧RY|38 @;#TЃh3~8@+I }әh)ʼn3]18 F^!z'XȲ Oy Z$\NhbsTS.idVn +uUngw=? O<1bff{yHrŒCД02@+mf4ֲz `~ ,$젫aԁ$yn iL  ~" 8}%#Pdϯ`)>@tD3A^8C;2{.׭(P' ֬ Ƣh`hm>^Igo"@a=*LM,su3F).-|-TDF_=>QimQVICZWk$W3DE F6i(:١ oVwVjd2|꺺^VuLvKJN17[bSx@?̡RsP{i? 4WuኀUT>~E)+Zдz^v>p#xlWI$8dYi8kjNyysEP2 aczQRYFV!U9pUd[\Off+K\n""!N h潧ӗIP:(w9d@NWO g+UR|#|I $P<7,vAU@X%]bi(a!֭rИ5w߄zp T}9[}+=x~7Pc`˲r7.:^oMR:& ^َ7Ë@ˬ}gպ(ԇ94u&H}.o[}M²j{ለBN>0(HMw[Q# (~6*v42%¬~O3+.=C*Rg7eI*d\%)B#+Kې+zSdN#ƚ/ƶ}(M "0"W; Fg#TrlEui蒡/8=Ce(;keG8[^j_RvB5{鼚buҢk nI AtCU/4'L 6.A9§E3g6[R؉9e L245;)#ve-ekb+g73G,m  <ɥ4$k($uɷ@L9586ThX$$wBh1#$ZwaCG6C/TQ<25d9 V6.mjX#7BDy6[\{:8A_B ِkMН \V( zOy+bؿGyg:oNV"J dN̆.?G/Yl<">qZ}qk ,K!H5n#sbK.^4^$ЀkkmpEvUJC]\aH_sw6"#ZWANJb#Gh*+!GƦ*x}Ob-hRѬ%1=$$՗w)k6z{NŔ"ɬ2/\D_]rYDD~@`L:/(|oYJ+Dl;}Msmv ^k GW(5!WODl7$o~n1ԛrmGV=,๗:2Y8Rfխ-xa 8y:XX?$F44>2 hf4$9!/)\o@zson9lA{qKp ^ pBKݐyzG7t@Yf 2ɡ[ų6lo#6LD덙pynX Zo+B$CrLTJtKw:Q=vC?]amŗMWMݴg1kv"OuTjYEx(J_+EYpP!IEǝՀbBI;8}J#|r6i\x{j| aC'E.88q40%3dOMuqDzuS8T!tH1:_/go縬vxMRLˆF%rR6\bCWX59+%ND%' Ye3 :{F .NIK$~m#L^t,N*ޟ~| } pGPyD+뱊,'i(nske@lђ슋<gKǨNBgw 6"6^|tw}t\ ՞.2"V=!r)^[ޝSS#(\ ǹ0ʹfq55r"9EUPB傾X1z mn%^Gh H6 OcrRԮl0L "@/J<{|ވ_V]'{ETCHZ̠3\$~ ~ӻ'|W.E[ۺџn7E\H`mK"Q$#Y6D&]{+rH -m.7O{u܊pZ; ̗Ve\gHl9ߢcdmsC g:"њKN|$sӆ 5 3G>*v=F>sgm֝veo?Q6(tCCHxirLNL\;d^alZIiSݬ)V))aԊguk{QD9v~ G|[%eY.-UEc|,i hݕC J mܝkllN,yWejy8W %F`C$S>e&;pw #YtMxV/6gi c 9*|Dpt*ҭ9:zVJ w1B N ^+MKΟ '}gIC<蓩2ˠQR@K%(2y+5~Ó!&5,W(LQzGD*ॆ߃lIX2%k==;!5\.Ӎ: < {*ŮEYM A5-Oz S{x ~%\֠)"1xJxoK t@Zaѣ[i:"/)?{ =\SxqZs+FZ.jQ5糋 ĽBmu"?=)Z9[c8*T4"k@\46U%J]q sHDtU lDPS\ZPQɐ,A֓].қlSa.zIlXODc%`D(6Vēʨ pH#3hmI%>v+ñ0V\X}Wݰ#C<'5 {[@T:Wx+?\PFbU y $Muo%FZNivCCƋީ.?2 z͎( ዣ ΙPBZ7itzݹwȼ^A68|/* ֊^=]u;ɷAxf92BC~p/3GI9~T %ZXx{md!k\Iߵ Ǻ6lἴ1(/($Cϩ98 z,*ғ5+ruA@‡N,k2تH.]+IuZM\HkF d ]5`ʻ׳`Dm"UFL?8Zq-˜Ok(`+>iLjM:*o.Ci\ǁn.g(S\)(_*ne*mʎдWevÊ)tjyڮr;JO}{a! =< |nT:Z^( ; ܉|[j H>|8Y؀65m*:,#hc6}N>'+mOq j](&% U⫚)&짤"\O_&njiBeuVODU,l) ZMnK꟪rǼ^`#Δ@W- o-?gߌ\86П%殜ILTmM3K"g=.OŐmmjTqTɩP G}Ja Xrŏ!>ǾphiTO+u yHo7IX;O"Q#f@^+V -3}SBOc5rK|M3q\OLƑXNy[y.jS`|+Jʂ`nDf;y#1tSC#/oƬ% QȕImӆ4@GI·0%˿LK/'|t%ܬɠ+CNB.%x-CۓP/D4#VLCIP<Ar҈&&`ru@wu"QU*!O\% #?hi 1F3>)OahFJa9];R}8vz)?@6VIثcAVR`a1I I0{4M 3/H=DQ\ñ0XٸSÚW,AA(O#J ZeŤQ/l 7]eMT}3K`3 LIߕr󕼁;Ii(r^%rk>UZfV5sܕXkTveӞ\AS6}܆"GEsSN2  djo|ItaũZnr/M Ȑq9`KarGjz !6=n9cK~>59sp|S 8' 鮺.M?JG=@Pr6zu*b$-XtKEi("=?)^Ma$ zF0Fln'ІސGjg2;VDX "#f" MĮ1l|}#-3Zh~hbсkI*տ!īgq#/?Ny7 CL} YҔ`CR )O)#t˼P`WRf*:ZY$P}" ?u,]K!Xfj~_1隟`xfp3bBjҒMU1d7THfs2NUer{3zP>˓.βԸ\v|J:D*G|`ggD. [N[Qn3hNe^."ЮE--xDg쒔A;h)p 艧+%h%Iep. xd{rA=ΧLV9-+hߴH^ijVX{,a?І|ȏ)<'5ʭN Xia"u!Ӻ3Y4NwuqnZ-Ud62DiL4۵? 7˱k `%.NyпLi RzJn˾*oBЏz+8]vNR! xKa@(l6 -#O֜ n{0G)Wylfr]R|9i!l HkONۭ+!~2:{I$N3t3b'>sP둊ۏZ&4* >w7+ +]&–$\cDY{>sA_!򠉭ԠfQ`J! hk$;O˨ՄPrUCo_'bWwST 7RQbjsx sBNo]AD#qZ@\N]WoYp,N_aLJQ(/4;WQ=-$V!&.Ɍj'@UI"-3kАx~/4R,"Ra\#Q~-y@tY, xVTw` &|0+߈ȸd[ mӳ۫"LD>Ųח?\ӣJ{XB,n pVZ!- .@ %ǚ)p%)(^Zqnu$:I{4hO<͈bC/gqx&.blݔj;g Bhw`>qˮ+>M(aBQHY1Թ,nO2ų|ah|  9d=Z$\WPs$.ygk8 n8p"yیF0x&y]5"K~t٘Ft-wި'YP^,~/&}1>x+) G0P*co#hF{]Uh>GoAmm4U"/_`{bTu+`N F%_D}23do^IOGM,)+͓®1nXz5!/)F=NބBw8G$EIy{#l0!ȠZ =']"uWb>9h `Ta0I=}S(&Ʒ&0I8: T5JMVP(SxzόZgo(&ѝu1L`7ǦN7~Dc!#.6NDIE\U WGx!חH]Ө6KPoU9EU\F(R4 `ԾE,+v}+P9,Z$V!mQFTR:j,T.:>PpN|`}ԛJ#m) 2?7Bܮ9`Pcg DX*g հQYkIDOCE@] nv=D>rje b,Om c+OsWׁm퀢wk%xr-#@~l8Ւe; —pzMX|_{Q$qr'_F͆FMdꢅ,yu[1|Ae/[ʼ}nuA6/`n^!)Wst7 b/j B<OpKh\mm -r&C__\! {,umݑ»:sn5 y4)Ṱ-`kL umi"nw3ҌM!1u_kd;b[],@xjƷY avυ@ќB('\(p~u{4 頫v5C;_$MM 3f}E }N*uy3qX=Q'wna` ap/?74mʼYdlZŷlx(9R4iO'uȁXJս?6U.+>lKE P ưi=q|>[-q6:iISaT;FFL^nȚMCc&~dTkKZ'EQ*41`{s; n:lFJF*W52kؕvX#Noϳ' k𽡉Z~8$#uAk0̵#{{J$31t {mˋS3CXMce ݶ_hh4j͌h'ܰg2RIO(|GcazVTO}h:h3c6Sq7FkS;a޳ 8r`.3I4<0AjtDY,.Q!Enב%(U{NT?0:lݖb̰=I͎z&\uRIy<Vf|deݾ{j(LSBsںHϞz%Fc;p`Kb.&f`Ȉd3q c#kG3GkRoLJ=)ŭRA@^# )eT޺PRpɘؑ= Mi'Xx?HN`ra gJqͭ(3a@CꦼF#J8K }z<2O`[Ќ.XUt=3I.9@qɻ>!-ںU7Orv9lTuXM&H\1 P|ԕ䵭ыr嬅̐uՃw/Xna|3{.DGnǣU\Ԍk.[j~H<_yk>"K[=DfM4G,wA.odh4NUb9n.MnieV@_3#kIW#̈]FΙ۬sgL^}Y0S( nN֜ Yx %%Րup-l8{ KEXeY?˟``容=VI:'MR - ȯ^{^{< j)ckI-GlMп*4jH.~vӾeP1zn.8A N"W4So+?au2;iZk~shl$m!ɱ LWb&,g-7gw4QȺ }/d 3 Ի$ahiq_]w ^ff /zg~xD;A2# HVF"Yj|Ml (mUm)/Y{eЄQ:%[Hk~_e~4?{9% 0,]f&gRp 7JdVnWr g3whFhL^rx㎮l#a!`zw b=YC{nKK z[/ ΕjZ%g%pcX.||u5;!plt!-$ 8}:ųP/4ZDJ336pO`[,w-vyrӠKL&BF@z -2l.EӸ+֕tO<3;e_ b]ԛZ3A87 nү+VFPb; kf9v1QB=EQbUsMI.OUj "XؗCӅ`Kyqz !C@dъ)ۿ4KqD,k`1=7qN~#ra p930UnV3X /}Gc.hzϾz_CIiy =6a8Jjp;^(Uo |ܨJ]@nZMSL{+r=91I`@Y?:Ŧbh^IB՛$O1_+-e&կ<-Ӓ4P<`'"c_DVQ NҲm#D9NRKLIަJm 7v|lk-[Y :-dX0c'M&Q xۛN?UijABRC~r~'xגlM(jcm!bXuWaYw֚s豇S7~ ' c])&W}ʓڷ8 W&)RarW¥,8je0W@>ewsC*yqa1wv{:UT}-XRbaw9U*<6jXwD U']Cz>-/𕥕(ґH'HՄHhwi^w5GwTg=\M芓9,gMHm+ <bPjq;9J*96:7Gn<G3$]]Wb1{T{ֱ1n3L]Y^u7loWOjA֫fQG I>慺}G sMM/f"(_?7Ko0_kJKPcԹWCWA2 avܫiLG<^Eԑ<7<]ܢl+![Kj["0wM?3`4#44 |r"i}E E ?rlVyQ'Q0!/rR,b[eBlLKg|H1/x#I@%qx_^e*fVXO ,ܲa_ kJtaځ1jU4+?keFwehqzv/>K)hR1;Ckmִ7XfuQ{0CVr%pqb%o;}=iD5`ު۩ @TXP貫 {y rрF^-LoY@T1,CA$h4,25$C5W8]sr>ћP0}/|$爃FNaI@Ju9HGC/;)u]uXzt#B'OP EJYYj%)텎S >DF O3nvQBJAnR`.L89 IDFoP ̃_MFv!,͚CL^GS&n=LWD٦հ ~ s~5dK$A yDUE0La)($z rmB߶fmWZ[jV,ɷг -|)=UG?81Ҩ s:XHNV1"4ZyhxOg['ȕ;4$kv Kfyx9z~`ۀc͛&Rj{FKmut!OFBUmp.`ubHo|BL"lkѶ׷Mf(3Nt?!SŶfc9Dj?\㌜n||D}t+%_ۆMc*bpE&@Ƣ媓t%]Zxۿ|B" _ ~HR0]SKiFi穞#\?аT*]2VQ! %)J <ɟZ~ }V?}=/<6']DvwѐhM1 E.,y3T4Yu$:96M~=H D0ϧ_JZe:%yQ?Yt5Y (ʜZR%V66Ky 7 i:9J$6#»^aխ: U 2w{⽛rH)ª]ҍX6$9ulJYXװ(.ڧI-,0!3r=Z2ߑ#R~ oXC 1vi%mvan30$z.1RȿUX$R獺gxwp:[3 nǏpQAE! /36ؓ muElXQr<8.߸ߔ(6/meիYTyO` J@vNQo N$^k )tFnEnL3g¶R"yڥOvנ'srsyrFïYknt3X osxk4 0s$rQ ;SZPkɛ5S92s²EX 湱a 32^oߨo^x 'ρc"_Y4Ŝ{-m%c4\٤A?ڔ ? B]CeM=YOݯfaVDsz겗7kj4" fd N$zP!UXJ/;|bE5QzL4{UM'Ee`7KH%|&>FoӚגP|J)[u<}]T<[dĞ` Tv '$;!3Ƶ5g$_2`.fv$?}SE zSjG ׅ_obۉ+xjsx B؈k)](=4g\)ЂvXv:8"b@!Ezh6MH}Bg(Ey+OX\Zs<9QĂJ[t_=5Ahil9Qޒ+:2 lvOق}I wdvi璎crï` ۇyG*8dw-n\HUeFa OIXjZscrA#D_(V/ :`S(Vd|:!e;5s|8&$QX*><& ^gO J(tF`LƵ.y֯1 h$J0:C"82u; ˮo(\WB.7V;F%8ubMUWqc2Ey%(a 5| Y(s;G#\./qlugIӜ_<vm=+t2S4Gl !,[oEj;@Jz#C*C`qҟOŻ!e3Jl@0Jp5q[sPƇhf/ۏvV T=uf1:&\֬nA~th~ؑogv`` qGc:ѕh%Hi?$P/yfuhW A4N <( UE bhd^u@*^dSʚ&dž¥g@vcSka 󋙸ws.h*XՅy^cѺVU5%+y͌ ,BF >u]6zf`ODWNNIGAu&z*MO VF^#_3ԃ?Nܹ ٖt~IS">4V1]. dB@^4l! bD:Ddm%DP0XKDIP}Xr,,bM%6c+paf!w`nl֣3A䘃=E]ų} "t"YZhog8dqqߑ$]+UY{HY?wEm(~)!L?DtAp$=! A\@AZC4 qsUg"E012uC& [I*WLAҶQ^0 UC|:_t58ADSݖ& mZfc^eB4ԱIoFO֕? `6[ϋwޗwd|+ςnr,]ރg9ꨧZFPi"(A(|{W[ ,TPњVwPlޢT}1X8._w\i1GF99C"Kyw(@B $/ˈnu+#^j "]+ hwI[̜0+s09YԎxB!D],t=hw?8gIo2Ysd-.,9ʥ)?mP?<!w, E!4)Q I\}oYx5Y>B)_x!Ie\6cxm'> ]@bceY(erE/ i @V;Gm"ij.Ht_?J:0u0)u5jErU,ޞ = |wQ,ZX7I=7&*v:-sCȥ΋p?.W.F`,]E4z ^' yἄ{XLJ*V˷Q6y)I ipAY2AtX/i"3^Q#Uz:UI\l?+2 8T/Ki *SO yo d]FeJ߂} jr V}5IQJsm:.2fQT%g++!T ] ˵._\k!rnfe-l<x޿E76v[+ҫz^YMǻ`Jv:"(Dn"h缔X*D&jJ_m8ޞRr1oH-3]T 0ccK½70+=iBmn(.ng m*L 6X}'bֹȦ^uS)#×v zcgoLdc80Z hg63ki:Zh `>f ,y:` ȬoWAXkAX۫;f9HHw_F]6 U%7#!j?M&UPz 4Y"~J1wل7' `pPÎz0bDN嘈!lAqjm馂q 5.*\9T鶭 ?6|ݎΎnbUU9),; +pm&JE8PkU5 ԽHٿ0$٨Mw噢7J&\ tն6U"oi^Hlȋ5$ʡ2?J 5'X!5[cAƬ+@Ᲊw>+'oW\tB˺P孂Ekxnӹtk"ְ%lH W3v*\ف+̘v𼄩:S_ݧ1t@5j' )H'O$hHIjP8P9t5G>xeY'p0mfO3%CDoeGnݽlXEztt]GMZMx-)0e{gK3@:"TzIL5(l/Us 8_DqP"x"Hj̓R՛<4LAA 3MOzKlOd _3;\cPxF'FK_Ww}[/v,E\A~MYUy:PDwUN+ Cr&.S1dj>ɰ^:} kpeUem;tcy׬K3Ets-خ`8MFsKO \yQ$97]xdk\2IU4>aj ìk+Kt4hz>p쬛3.ܽdʨ"-%fbX6K]N_*.L?m5#mZI~{:[ VLQ8H̵BvĮ ^f]XOݏ "2Q[F|vbʤ[A˷t(UMj#$t 9 : }{ <$N8~2u4*H?P,&xjޗq|Bm 2DNz9Tj 9Nh{IXM`=yfTJqz>&G%+RF@lmY0)mWsE2N }hoY>h n.}/dfxzsmN9 Z<п x(g:\(y1R$"CvewPm! zJXdYcԓ4D_/qD Nz-$KDb]LWiv_Iήkx]fK+3-x@;ls3]("@b:]i5?F|[N\#'Vӛja*Q5^ww?ר)%+34ҵjo,BdIݦqUlaVg{OW9UDrsG :Ηg'rdyiZK>vaH4,Ԅ>wzU]8 6$*k6NR}bnbm>.> wMksKxGZ:2!!/kB0Lnh~Q'-کQB()s\@;0&D׸Hf/x?9X;bvpIN6C'S2i|TDWGbt'-'{/*Y\mXCE窇D`fXԍ*[~mq*JhJu'Rfy an~^.aI/B-|&ng`4x&ˈ짇fϗS+Q}*ⶑ0.ݓP$m\>#*S_y %R8gg{±J' Y-0^2UJuvC>]ySĂFyu޺^޲P _InŒ,W-N2w~ƼTZR,6ЩB?a[2UH>y;*,ӧ^?MT/-T ihhHj I!eY]ZEb]#3{}C`ͧP@ o zm!R3pL϶x? "T} lojG΅%_7g}QE 7s mgn GHzBspǪfNE)I>l[9,AA)B; Mdzˆ"fA"q`j =]FCa;w=7K2;&arf__T8`iJԌw1LRZU~Gkxr{~稞NZrB"~r8/fևEMg2֪/̅UCB_7@5j] |<`ٝG0;OۨC/ ď"WY>س1;C5h۩1:hX`]!K62h)[o.JD\F3t-mq]?:' Uu"X?4N{6W"7}E]U`^Fdlzx\O DRgD`.VzǗA}0`,EJ93|V] U`ܞ).}4M2kړN)j#+/g/ТHm Yg Rvg:Go_)@Ty&f .Q YKad8Y EV]nLa< P&H l7Ky;Db`XRAGOF&]c<"\DH LD_or; 548'B+Ak8_޲ #[\<:vya@'?B5_vtD)/)+ZٗY{(CK#w0ٍvvK |xUߴ))NcYX-0z,Nv]Jo \;*KԔ'&vP8*,莣H_q{/2+ ^[`ϗlY`wo6 wǽctJ6w 2h| avrSl[B*K2ktv=bDqػl CXœe,O nIdTx#n!ZBCN`_@ s4 7PH) I=ݸ?h˙Ҋ'[:[0dQD\.nVeЋīl*sOëc R)͚8!@XN%UPI˰ɪF .ƌW0x%.X+S 3c/sTj ;Yy F.)vGv˷-XEvBԄ|D>3zzk.?X0t;`%t% 5s@EG=m)𲥖!ICg L^  g^d/ toIhp̾Ryg^;''$2Jo6N\y+[U_ցGR{Nw^Zr+ܮz@"DzG(#nc9GY-9Cu\=)#gnęt6WNT| Eb2.T:˜-PGr7F-ev uKB<|9KΎGA䁀oĞ:<&q~ɿ&9nRXBÄza @02CaS_㯐N|n.# 3ܺGL-D]  iƪ)ǵDLC.$&Ozڃ#ì, 7}G :L{;n :_!81H܋gɴwKiFM,<`ux,ջGaDtŐ DX dYsyM3fPk b 0 t Al.te+TJ˼<8aNRAZZD2(`)t]s&Եl 0K ⿛SDL<8%,ܣV%TRF`ԧ. 伵?:7Z!",+GQ 4`zwjBh2-I)_idGM2z֩'A_n J8L`$N0h )cMDr~I$f[S;~dԊ6DS(.aY1Q_ <*Q5dzx~V- cd~ jMYA^;Qͪb/t7fŞmcczGBn2mZZ|sx)jF?#K9Gb\YHC6t0?lu|p_ 9\R|j%h  c^l)k}77X*v{kGqΡÛ0 iJ{DoZJnU p~r[c|bd̴-7ʢO7Ryx9`}jZyPDla敕/3?DY 5T=4+O!wٯ&<4me0,dU 0"J2ZK7q쉌="]|/岢;U؛"\7fWV")ԉ4"cyD?\[SoII7Ƹo^_f'mɱ D 55r+JW~{PZ,O)F{1@k_2;)Q xn/MؘUxYfnj9,Wtݜ09aT"y.=ZfI`lIN^%jCR*x o῵?ͨS]P0^Iñ9;,T\HGZ ǶTcg%/!?b7 є+K:h[`͟YV42lQw%x x@:A8F!J|xi6Yռ=!nݐ E2oq`Ls??GʗPrGwmsPE~ wP~HjP}/"LmY0| ]68+ئeMFEqbEdaQ1\\/R0*NƆrn2)VK*`~Am^#IGR?\OMq-"U͗TBwJ[8wM-@4Ō /]}r/aLNvǻ D(G~۫,S_w8m(~ 6c':Qj…Q1H3.Idw` KvXPYNK?iyo[ j)SڟJ-PJFl'AbTQȠ4i7^jD{̞.oj`((F[}k DPKqUGwu`_LNkDp8`=.JY.*Blܘk'[Ƶ ̑ؕNW`T\֤b!-QˠrXyՙ3h z{^{kbߖql[ ypb҂ 賌MV$E^A 88Zn<|8#S&)c!]ADUOq6y^ӒyXpp!Ub'^:(t3ke3m3ףBz]&fӇ2GȈorU|sojdL<(i0nCJsCBj4CJԙFn'z;{wDYGpTەA?&Z`sm&/jgy~p֦wbL~ex=Unh ƒǟ0|Llbc#PrLK$x67W-g WdГsVT9:#JN4 \CM^Nl:Tj,/nngI1M*;Bʧ(C8>MɆX݊dDeɫ iqx7@NQ-^% +6r~݌ڲЄJ(O?}l׭r3"[G9|mcΞBRGBm% gx."%Ifwݰ In)> XM ,0)t2vXh>AɪX8bx!?%ao`XJˡ-K96gJ鹈%+_tAt5\~v}z248MއǴfo4uo-@o͏yJx}ڜ1$4ic,1*x\2ˇ SKC~T3)q\g_λ1Q\' bWR^](uI%<LLT#]Lcݥ 5ٓiF)6wdOE'gBUa #--I,IpQB ({'IBL(<$޵g0C{R _?nZq\NL=6CrLhJ,Jq5!(2`{~ O2$@gr|mNLa@вi;i!颤K|eqʬZGĪ5;t`%--u׼JtָdU2obڲeMn},Pʑx֖*DJ70}x3@|Q},댗=p:Nc9hA #C2loAkI[ҦdaوuRr?T<'n`., /kt2ud &Zj|dTd^pfhvR$%~j[;C~ ~ʱm}wa뮄"D'v]|mOFrj+v44K.#0l !o8^7Xvkf|?'VS:,y seD:;QپpRBӇ3Ͷ>W#4!rS1ԄN˶&h@PeIAPɒ&EOT8]pRNطkP"T%>ㅜXMAQGwPV0G*ފI5 6qKO܌[a#;o=u @SK}U_*r`a^E~>72}c \Y8 3\c/Up'"wsyQ7̅ayR8=̼wP`{2oY'~Q⌔-+pk7jZybalXdcZ?(bVS7b/N{s@B1ԋ;oE"]rVY!dN׿žbn]Du(F@\ @Jr5aW\,&]`PDt *KRe|)=OGKr m̖;ɬb1ىJ"?6A|b糭reޟm0~`v/vRЧ%IgSY= 7K}PUv 7*)pN+k‌F3{v q 15iص5d{Qs&@UaDC׭ H$ҦssFl70_ [lK RLlj/`p٫2LI4PiCt$^`E3qr 2@翽1rʢcNhZyYB;v'(h_/%U"3ꋡvuIQm0FBAqf/(r7sЗNj &n|f#:5(+80x^$'Fz~*4edaebT[~~QpD_I"yU5Dz`GWoت3tsYIVǾ^-Vqp8UD<_NFWАC|jMu$<#/\h 6`e%D}B64TD wYܟ/Ω(do\6WJtqj ҕXIJXYfKaS(?#F϶l0 lDGQ yVoRjJOu4 o זxgEgj6$-wFۨaC?rW6j,ږ(:X%L1HҏH(=6,f9eI gXYT]` [3ԙ7|67[#+PRۤ% L 4dw0K>ڼWW-JN.nMҩD/҆󓎕k$"W+& 4An[Joːd`"Y@}q e 8wV6Ioz!_} ؛૲k+ĽX:s>< qu{s,$]6TRFč, lIhd՟ 1I$!G#Sj!W#.4~[fzVIkB6uw,P1A,*9W;f+LaW7k2PSX0Ǣs럩uBcf7Dn1$2fiBVL` FO:c[+dZJ^N%pK}@%VChHk&޶ $8Xz;.I( ѨgCCpUN|,pOкm 3>:H@) XF寜p Zݎm|Ik]ko0^ҬhZ7Y*.\jۦSmE.*̐ԦCVgbAN%ǎXcLx3Ig\=_5󞱫%^DNo(yOܛM-]ekfIDk7ҲLJ#>, !1YPg WXv_jԟA(FLKԃoN(!oY;O/֧?~/Β'荭պ:ºUn+ 1|j/ù͎'ݰ UVS[ɍ(Uz:_c\ƭ~ ȉHOmpRSqHEg b8a0)5]}6ӀТQ' 4 Tm7Yct~{؋2UL 3Ll$aFp$\x~ }prEK VVcptwu!k@ /- #'݊D2s%=f^aY7-M)@ 1:x,!*r~ndR[;XX⪛QHYWZ*r*6j0"֞g5ۨ$dǻN,ׄtynYYU$e#EAOɉ)R,n #kj^;lLK#sǧfSJEx]8&n@,)B #{Y[@#d8bVJљ9rW3c#JQ@-~|wefkEрGuu~tÕEhchM-A=]{N;u,s|$$Ccfmm^s,b-=MZ;!/Gނhy*Rl5gmˣlPn&Ǔt$f+ǓV]0HO,vldR `6̸w2?9mAƫG͗ bc0Kŋ7RĈ W2F7V+h!8,GJAxQk`'I/5J~ӥ %?;"/c*x֚2If̭$tHL{#KO n~3˟n`-2m-spᯮ,r!=VFG2Ov~hB0cg =5Υ:I OrϠ2T?/;yB_^!x,KcpfRRҔMpԽ;Լb1Hpr -mpl\;8aB_J{fc}7򠱐g Xc"1}ڇ m )-(̹ 7 7(|eѰP $"/\e<7N<G5Y躟4zY8{Bsn X*r:ҢmW>D氰2q㯓  #K_NjE0a:8J~$?$cAEdžVrg ϕ8^r&7z@E{Hh7CO%I&nƄWe=Fp"5om߱f2+mvCNѺ4wp-I)~ ; J:=\VTPNe`A>й`m%n~2o⹆%<$ibÅejU]`6Îe( Ңa2LEOJCD "O^X );i[);j? (\;y={̫mX ]-VCqd{Uj7إw P0ɁE(_mtlحwrb+ ,FstBcΈ".~18'laPcDdmB=:mj&(J)zJ6'n9cF$cVO(18\[)j`hIlLEZ͛C+ʜvڡ@&Rj7(8$i}t"jq)tq*F⁋Nvly$o)V»Dx؆uL22I\"Tdžbh"o7AY)&wSDblAӏ+Am2A6Ϳ˝ ecrԟcAɃ12bl_. ەdc5ſE9lK9S%n(a8].hvj]z$ 7<(zY=KKp-:=!_WL1tSFlt?KO `Ň8]${,![ZP a jcX-, .EtH"VW4%=NkoeO5(F;!3ޖ.!8_; t53Wa{ur8l Ө%e3-mUczy1*5Pvg-!.w|^b\Ӎ,SRA9#qup4m>|ș/nXyqtGA@kG#@Jמxޓ;3r ƷD8Wig22eZ3GYc֘/l| ! -R 8U*nHBf!+V EK,6&$N`H{@o)m]1TӲ>52j+Tͫoپk*C4@>TbkEꜘISA$J$rP<$՗Èd)6 V|VcЪh:damVOMHRpx23{ڒ\/ hve1ELEvgW3Y*Ӛhh+TDY $^#0^$zJmf -$2x?)jXyʼn2>e!PRӶIzfq/Fu3v<?KZ3Ϫk2\8?@%db.4ڌ&r+c,R)y?n}baN,A1G8nͨoh}ndQ߁D$r1=u|C (wXxD_0*+w"NR̙{ņO2(De!GŦZ 4?FtA.e4#6l>t`yMeRN%3䳖(oM[w +RnZ8M˟ᩆM4,3ֵyؙʕ`?}$&ACDPyQMSǹ90tZL*Q;ٮj>2j/?ɸjؚ(ć;rUbמxyy d_x9*>F٩3(U f{ŏwJC$sq7|?M}X">BT ]@9uIe%9(zr"3֎ WWqM?6 Şu 2h#iD= `#XÂUI1JOEEFϐi$.v7"~^#} DKWX[ )AKF1S̛zLc&r}`4C;fQ3|h^2Ӛ x5f>3,^>G/hXGÔ^{_X76wÿ wPle1֠dM !-ڑf_,cYDu^ "^겼ù9f*d9Kw:pך#A )$2$7I\G{I)* %-5I;ShUo#)D۳xnx2Q0zhez$5 ~)ȍdQX&7}M1:I@-#W.O7v+iX +7|BewhGsfա \я部80 ly[?~eW"% S?G͢mJ cԸ`7”aj˝k5,ILw8~A!Bkf˗ fYnҝ2!Ә!>2dy27yw'|#4B&`tCb˗"-@ gp .|o=I7:ţKMFz FH\P5*)wYb>glYl,W4A%:;E".2Cr4W}λ|%T. %G "a/-L{%\OCg n4ЦFZ@8TI+̧-IN,3 C2lW^ yBvZB]޵DfM֓qFttpvjʑ4a!bs[P #VܤkJܖi Qz> "NSc7REFafne$b)*_E2 kLN}GX d}Xj7bL°0E*7G V uoDժb.Q߃_Vc! M ʿ5[N]v$Y17Ƿ3$5~e>NjY0;]YZϤw|YVGCzLM٪dW7WC} |roNr_VB\%*mTwJe^ 0T6&6P#lAORB8Xee x:a3&>`}5J|rţ$?Td(na|(^zAI6 Ok+ߗI:ް"'r,\jSYnmV&c ՠNëfqy/:yf2GZLolviY[OYIMzRǴ> %p=Ss86H}cB^.KFƵQQُ\4" 2=e]Hn!jfH3.C`0%Mm{~do wDæ;.yHRj+6(V҉!C>v vS^~,& t1 HqCsYi2Ml"Òſt2]!g@8FH;*D`aZӒYFV b!J/0N"oJtg32 +ENH"l 󹊥DwS%}}-?x17b9.i$'jCk] K51(&u?6$uɘy'RmͿ K (SYg,ZBx ÷_2wHڊEb\dKFB5g1&P=[>] a7H3dae`uH^_9޳"/rh 26ɱK[OGfHoOWmzuvЏiBN=g8-)ڎ^%CyS2`9#8|(S^v[]_vpsb<4^r?D) 75|[>@db~PoxzBi=i:=[lq{?& J(`+zz-8ڄMRc O`RIBL5,vk<6پ1@jf3B=cB`mk>8\5Gx/kSEq[Nf%:fͲ`]mQLz[ M0JFW8+PR`m޶#&2gr@Ց6Ns+h)hZ [$akC9`]̶" wEftnUM7puUvʺ=`a zjm6UㇰQnQ! WZpOϳE2bw 'Mf{GVI,d6s(*,V%.dX9(DIQp$H- lTZw4`sZ8\16'{_*A$t8N ȣԊ.`d`q2^{t68o |("a:LJ2ŝs cCV41ݢ:{6 ow2 M̂F 5瑌K& !(rHQac\lgDM:G+f7arלKZ<ʰD,ŢXr wj %z//!b: =Ε8-Co#+Lx`#1_yGK]ƻcA99PF&F.%2qn«=᭬naN &< 1$i,ͷT(|!V"1|0d ^F~cyod?N){gl1S'580NԬpCȲ)[ǻpz#`&F4Y0I\Mf(ט^#=S;Q;8_*}8mJF AhH5CI'-V[iBr..KwFg~9 (FD:yaMڤ$E~.w ۶E[=+,W^E-PiYLt"ɛX$]/&*-a!ih92ڼ`1ea7Pԃ42N qD >}Q.|!cg ;*cћK/܁ YĬ[x҇_UmxdY*PiT+B Fde#wBhuRBn,@{h"΢yb[)qڧ% ཀྵE $/!O9ӛ}h+6Ps$rpRb r9j'@TwZ,P"_P-JIDFw('?\$qMp*9]=ؔ;EN[iZ:x).ʇ[@]vʡ@v΍b(L%Fhu؅ IߌY=# (N%+ #%vZ٫V"m0Φ 6 . L 3[!̡u֢=p |6+IqVp`.!lC5q˲9~'FSԒ+2(tФdHhWguy狕3yadc(If`!rVGhX%vK9Es꓍o/n+&CP24g}ǫ^ |wJ;\h-ɬOP.{Z K8 [SίrBGÈ7Lj3Z9¾xLux^5P#l }'T/J[LY7.u1TmFxo[,9SJ}A=er(z|6zK__`W@h<}az}Jk ~1f4-0$X;M|~r!a$ > kY䐗/z|7NʸLܝf6C7U;Ou5/֫;͗~pO|H2hINAE-1~Y7y|K@ 2&͸ gҟ$TCZ%q4*2weV;ְx;k*+co#^+J)>|j\Z뾺;1nq9CԹvKN nx- 9s겧X Ciou@[?k ^QF{RgB }EFAq) kfy+oLs׌D#wjuQOb!@z ä`+/\#UH屦c9@|oL'.uۈG,&Yi>H9' 'wZϱxPHHI>Wǯ=<-`ydQ=v9ONJ-QsqLTKIfG`gA1-GD{y-*~À4^cY8[EMx6I[[ՂJIidUE3ܣZQr1}R3=FM&\6Eܐz$23"*G VcY #Z~H,duVwvx{Ȍ\QRʫ?J۪sIlTG=w(d<Gmee?qQe 4.>\lI!%CvחE5rХk3a;dv8?P'W] JӰ(ZQ(]!R:d0 3pH@;;fE jùfh\H=U_!wtÎbSez CYZ },Yl4MftTŇX5;zDX?T{Tcѥ!4O{E `||J3 K%攧^(|~)q+?Ccy\nNS!-kPgWZB̖6@I]K|g4U55WUwQspha"ξSˑG[hi Ҡ:ɘ?Q#ҭMm3 ǀˏ_SEÇgW<nGk<Ʈ1d V=7='oYg[ʝ<6JF,r7~& o10[ѷ'W`쁇Yv[LYIN[#5wץU abh|~[m4!;K+y6?p&f:ޗxyّ?eʭd+~3 WTc1=wY4K\'a11g/KyiBP ?u]z87Rz$v=Pޮ^sz\y\A+5=ĜD䩊;hZM{=^(rT23d{!ri }1{BUTq!gtKD'ju(2,̷sYO67 e+?* Lvp'q~v:\ܹ 1/&HUgT#p jcri8^Prm)XWT:XP]ܕݽ͊|Ti+yJ͊IɲH$_/ %A9BhH-;@;պJk;ۋ>Ǧ4 . \dጲ_u:Q# *L&ʺa֭hrb]^Iok3PpFJӈ>fTǬ vQipgEy?L/c_@_bs=Q}#BgmIF,+B!R屭'nc.&D}Գ~rv7b?@S ^Ic NǬ"v(Q`5R=M\*Qbȡ>;h_ar#dK*osCHDwuV1oq?H@k[Vr'] ?dž!oiS=yǥRxN`5RuDBh37Иl:v.ZIP0mQ5Hěӣ(U@,Fgż8?,UWΥGL?B'][*p@OhUެb;^?V+Mٳ; ?Nd}wm`x{xIt,[q]^(+܃osZۍsu_uIiB+3(N^= R{(]5=bF6Ǧ`w FI P90 a`&SӊCs_1LVjy#7QT$nomˉ͸%>dT<feW#3A鳶>Q@/._@z UL  EU{B?rzd@{FpjM1Y6GѼj#4aF\_k.DΪ.Ufԗ ?CH+XE+1VNˊF3a|MpYJGڷ›8s0UXDY-XUh?%e#uo1VS|* i҇%K;=utʱ|˧Qs_9.'-jP ]gʶ+ a>1]00"F\_J5U<7~!t/[?^8[p8`^:І72~.ReZR#;@ĺ;%hmDgSDAK!߈\aǺ,tL%"D";{ l4Pcp! '?0fC汹s^ Wp/<j#!uQYؖ#Uuc<.b2VHBWœ樵O.k @8xXwZ,%4f+w a޻0KDΞ|3v1.9o>4M,w,h &sETgI FFˍ!\tHySbb]5Qx/@55{( ;.*Etl&g5+Z P+3SDi7#0yBBʌ\T\yPup/(D U{ʋ1cuZ)WխjG0q@+UEzHSJ:~ӬYZIG&\r&Fވ)-2yIr_/,rqXE/ARo"-e}z~[TC:A1PDX]er @T<=v*L-+ >@:nT&H"[cH%ţ-A5] u7z"LHG]aT~vPƆӛFL!(yk4B:C6ׅ֒Fq[MEsַPh##[wwIGu;2)մ6 (^(Sic"tiD1͢}^D8B'г|2up'ω:rՙo?+Z*3E cW$T4w< ptxHAð`ĖWbg80bQq$n)6|aR@`w_hz}>z.zsEXnc[oHo]κ-ḿ |3 GYL9Y͕P-SWx,ikNGS0Hqh) BWu:K9NB 7m,O,(Ċ$% fJH?8('KP^:*tʗ-LGi Vv  6HDq@ԞVO-u-33D 6Y+(rc#0X OpҜ(Ƕs7PL} 7T^*Svwb& fuwzq4-X9 F"J[b$cVbAϑ}## ONcJV{H`( o{\(\#⋅M7K(s5{^O.bV8R [ӱD.QLA9PڃEfS᳾&`dB|_usiCQ1IV"ԝlX]oRV }) TvZPy{7UUlh!Ep QS.63h'!Бԟ:q]fHfĨA4Dg ٔ2?J *f4`~ڸcN) *dzD@Vt #I~,z䨩~=r*1EꟽPE7Y^%|yH}" d땸[I2XMI',=[彉Qh$}9;vz@Y`0E7W,48nY{/w 6tuys{lf_%n(R`<(C4֏a ,`)N}Bdc'b#vB&&NUm̦,[h54ƛshh2p ߚ!6 WsUgʈ7c.,0Y0L3=?i j3fvYA%JЭJ܉$euD#]~c;7Zڀ;3#~nd |.R^Jrжq+QAG4)6b~qP}VP6;!c"2dlX:dlMXZ>K+^[<v͝W4m8Ա=ZvjKNn,A ٪K;hXСMC3IBY;Ɋ4gi[o <=.8X2wkyATM6Ѷe>-['Gsl| SH;֦j]EmmJuݖlC]]lLr̺ "d=9/&  *$C#Y9j4F=g솏^¥=Gw "F5{T?vT1¨U1ٵÚbdc,,*_ৠxq&/yl;8˭k2@Z&[_)uvJI^64/L>3o(שz{b5dA׍w ~)M$)+^-|)/"/:]&ù 7 827@Y2NB[֋k6#(;XّJӧM~FBȠ/S~n%"ZP`q/R^䷄yn)jWV 8Q<5р^HktIjwX T#nR2R ]!zuBf]c9K?إsdtI+XAC^%ڠDJ&b1>1mW AE16፣;}n}--PQ6*#I}y/} xO,g~CL8]!} 9_cnLW<^ sD:IȻL)  T'#tQgJ%JdtSADl60NzFMSAt:O!t%@֢[ح2fɀy8Q3n|Ãtֹk>.%p0 =Q^l-k~\J x-D*n6 Pʱ׬Mqd1(V{{OuY.k䃗m\Jk'z) 9L)CoKlkǨmZ 7<:3$軼xmg2$L[@*o4=E9޶@F+?\)3©9ٹJ _>Q 0 4 othg:[[q8pݤX7^zpWLt?u~+B@ Qz; {Ϙ.?D)v—^^9//}O`Z n(f|%̐8E,>aQ2oV{kʶHih>J9^TM jԎ=s)b+5A߸*݅?京1[dg%%ȧ@b]F(3WhKu7ҙk(~)RBm{Y+3:4f8R;fv4MrFֱ( Ο˂\Z [O"ĮPj=XqM'&nW/ΝiW#.YG%zdyFH,;P\L]/ j,~l@#083{F0"`*WV|ݹ֗p-I L+gFuq4%F<_W؄A\iXng@dMIױut  -tT˕K@ jp@pcB7a|A(CR-[ٓԫ6C+f E@BZ?GI;l ^!Du8x-tCf,=0Ji.qޫ0&tmc?ƛ5GYye}p'-uU֚ɎY䴰$ a:>> "W%/audbO;'bzb^ |g?);b(a ͋a ]jC/d4É[ 򼊸*  y!V-c,i3BA B-s/b24]˙u >%B1 i|ʄW(=[2Q$A057QiZfqŌgDB 5nޮN/CJK xF\̍p2ذ/e#]{d>rp5pe) 3*d=FV˯LiFհnu%[=ŪƂ15rq,4kUݴ=;Ih] [7)Eee{TRoz؇.?|},(/2>i$dLEX$OQxb]oeYoO!eB6whԳDbM3c1&Kexx w1B_9BiqlO!+(lGJ'Э~w3:p/ᮯv`jp!q7~ddɛ<Cm^--buW8 .i-ޑDg!#0YOB"j Hz*}zaRPz靓Fo3IHƴy/=ß]Ɨb9#aXfZj$QIUF,?)i< p&e,x2)o;ԣy >4s?Z$%U3zx/*ZecYD/-K_4|q}U$!WUx}#ܬGGEEXlgmL2sdڏa4H(d뙦+Je?3oӤ9o &Es؎U "Q¹#?,]ipZPO앺^B% ^4V9덂&>-Ŷ-@7]7|Ph|ԪjJ̢;}Zr]k\ݶRpȪx? ; aT֪wQ|dշypZBK Yk}[CqEe)ݨ9/t{ 1GS$^T_EMɳ}T rҞLN270:: y*2 :fɱg)]k3&_~3@rc C Xkۙot0vێ:qB!:WrzˈZ]CVٖp*YkW8k1SXy_~| Fw͂۶bi9ˎG{nlʻZajj~|rJX8K޲Tqasbqx`1lf<">P0Y\VUx' fNJꁦ9 83z-AMȧ\ݢ>V3jg k(iQ_&XPzX Zy65e6|qSOtKVYn~"ӟ 9])v+LRR!Qq"HƼJk0]W,.$6 ןڝm{^VLhǮ|_jbY ;mR܌`'@F2zOM],S7s~uԡ/WMbB>娂lFu"6Yl1)ߗEa5{=>5u3Q~|7JQaX27<6 At48аm|@`*yfI'pYzNI q[TQC YFvX!}>FҨQ[yAr5oK.XϹˁ[و &BᄂKH[]GAм,>\0)4m9{Nko:e((< 8+vF-RkX$?b'\Kq+/Qȍ g{ļ`ƊG0iYtd-@w5yLBܮVY%5BuԙF>[q-s_YRn8VCy>@EgH=Mn|(~oFx8H~,Z5'p Yk>mQ/كo_:Og-Ӂ暳<)]Rb5ZOk}u4=?KN-Pwu7IaCRZSs-u_ o,-@l!DQc/ffo:Mv-⹸| ~sc:O[#P1=(B:$X< jkuM^3ՙP@/k\(wt*bZ;x+HQ& ;_CKkUڎʤ4?-wUa)!g|u<h[:|r=q>ӥGY< >QL 6lIf^t)ى Lfk|Ϯ_WgxY_mFj52f:yS<6jWj5@@pn_wv@iR)KRf+撐 @)ĝ[Wq}WE!7)/r (K0cLq-l./LA.J\&̙ Cl 4o.otZ@=CyM] /Dž7#k[{bu0it56ƾG|E7ϣW;t,19VG%&r=Nf&fbwX}Ͷ4P5.Wkɡʼѯ VHr3ZM0y=bIiuʄ<3$Ufl,iߊlzI`! N -1hn8G^XװPLp{bp/vcY٣y _> _90Һ)FR'#JоH-.r*9c[7~! IԽS۽ A$sձxŖ$ O"4M~͢:d\q3:'wTqo&e-Åh7aJ4zp|rƶ4v,/ =П^ZLYb_{$Hܝ Yه/fu֖뼞1Cނ*-5I fzhxE#/d<,Ή!\nj'4t?`%硥5מqA' }H[rWrP*.\6&_{+Ge̳ſ:~RMS9p}+/T N/V ͅT}kd7r(.TC̗cͷ,_{PUvlb1W:Ci#\\bD;~oa4ɼﱪCsxR0޸* ҏ1}g"nEOؤX^F}3{i,F ÇƝ@`ShT#T̀9\^M".]“1Eݧd #4 ]l55=6n2iDRw(ĥ0~0ؑ`k%rľD3,4;@5jA*OiEnC@׼A]*r)}B(bZ5׃46KTO2CΉZQjșrQtgBl^h N l uFl}Q?/]BD{.{-g+IswN Hy=ssw;yXJ!{$B1m0~X~D |,O3b(R5g-Tͧчl6Y ?N)$qP[JQU/IZ Ok 8R:ekVq+yS/>\&tg^`jfo_.(}:5Y/VAwAH;Llni!Op9e/M$DekpjZv ·4hqFK/y9aGc, ҅ĪE"b9;+E. Z"6U &ܢw.f H;m}7RڴzFOd4O|9dJ͛x29}, 8[Ix#&2O,6Aw!*"lO+X:hZ>0IώFt,#_C&W^v]ۿx㹱&JQvKkʪ|,ŵ"䈤'z Z͕5$(,l4||?HÊ?Z^?KGH{$G4odM'/w'U}wMi,"3DG/ ;uIi#K+xsUWC2z8ٚmKNyaFEʹhO]VY=”/ %zr: ËޒFOiCkqӡZI:չJ3|SrlW$ 3虴 Xi]-*w鏘$:w?ܿ Cȱ^;e[1?29 ldHa&-i,Lm1s v-SfiX%ˁ7鐌YJ*v3ufF9Sz@K 5TIhۥ燕L#Qw)`襍H?Vn.Ȱ#& oJfBM~ÊjDpp߱ A4oS}6/5{O|ޏ~ZQQcrOߪ0*-wn]$"&icF,~gZֆmBF(J xۓ'g}c#aa*$gI9,rT1T84{p=%; Ξ.~N~6YZiZ?IfMfBqRc!QNv`Plo]>Y&l9*ׯZx#x632T 7ciOkzC%-+AR'{ϴ6dOמ*D Z%JȮ1i y q*m\Ba Yi ^}xd#F0S,Q+lP&KmKi }F{=ܵtY~!D+1IZC6eboSZqxRÕܛ3!4uM5A^K\-{Ht+sj8(Z潱0h3NN6X@\8l} 4 ˩$p鸆~Lk,oT^s?D^7 ט41^lt3U$ 2hsYZ@E*c$P+&^|%'y9@@\Qә:ss# t(k0WCf>HuM2=vJ,s=ǔ]o-}|C4!ta2# ~(1 HkUPi;y@kV̊yBYoSqm܅OQ%S}T7あ立 YExK$ԡB#,3i;@gd prR6wהd| 7Fq5 Kp^Z|)Nqw7sҊLV TJy_e )%C+'gEhuQ0kygy/HƂ轮o636zڡ3|s`;YT؝EccRam)+}UZh+5C<$wF++JS%]Fvp ڢPx j@umRh𲄁kC'RC PRW8%:p ԁ J@+{Cu7ӗx톀_gmU=v$)B Iҳ|PPaJXWլeÌ[Z!>Oq9'2^!.;KY!^Atpl.6_|Mv3 KMyW#&GB)ݫN'!`=$a= T<8Uh*]q9']M|S}+tVY= } @RX~Ps9_dA7GD6iuCG y "#9whځs1 hqi_uHvF,GMޣ5%Y"qTd8ifM<Ë1,k͉#%[J,fl˪P߉_61Peoo,22A+:s3T7%> ] Q@?B`%Ҍ>6lnn(hI0s7ڪ"c\O˞?v tS +/b2GX9JR!p,GHͩ'~*^8$ߓMX?Y;~ 1q ` zMkm|I0!'=a7Qq2SͰ2|m <f3+e t;%/xy׸WЭj ]ͭ7zs#ewcc(}X9;غ#6 xiE`GfQvXvaS'x lbrkB*p*c{UԴؙ4XU&f1+%ަםzb㶾"Y!/8^.]& cbt&kT6ORw&W-\1kyȊa WWK.}[ ZAQHIP~-q;e08g? }+U5+QoOer_/}?tł,{N[ GE-D[DgCNXwOGsx'߄+[ 9,&fI&_:G76(3eB"'u!`lFԄ |S~L%'Irazj;dr^WCG1`c2/|w͝-7h,y>kY93y [[_g-rCت"T"f<>T`߶|A(SV2mdnٳͺEu-jihlSp)_6:17monfFUލD@b}j(id 7l⪸4/jz Pu99'Qd,ݐpEx%X&]֞ΘN#W8-=jHS?|uWlw-op‡#J'91Uy~ZFO.%-C!#Npad*H]dDqr?7=3 3dQ_wjT{=I\1*Zȭp 'ە~``gGh1bzV ?GO^hqc6fv$v&ބg@о ξvG\ۧpy@F 3a??DcŮZ# dNkpc@*Vd[ }Z $7h^g^%;Tdşݬd6& rZ3&Sn;]5P8ٱ_@.;VUkFbbv{ _4-}1;>NH|*k_|j;{=uA)H^8 0TfMsE0ye/BP/`4lC* tQ IGy;I9V /ݨ#7kXf\؊cuqp7V*MX NWh>ܭxymv%w) ..[QQ ϩYPV 3j>u$ 2tyy(?)f03n)%Ŷ2v Nev R}LC"H -I/X_UȡSc\;~3C7#'.V gl!D1ߟ 'PAtEI HҍOlr֯#@ 3:+H$f=EB]7}T^pX+I6cծgJtH*Mog2fᓧ1?\3 *;9\]y:;!5FR#B f(m==i{"Zz4G 2'nі1j%&T~0V ;wH3`4Ɗߜ*X\[$'pi}9;@( D22EU"t%޻E_ru ? mΆ@8c: MY8:/p=?:J,iE?EAAځ[2{4q][gPT6YO諰Qj%uؾF!cZʹ KcFS$I?uo:rǼ NLUgpUMXgut'I r@@bȝÐF) Ō-.M$s/RD7u^?xv+6)İl:kchsnK("b::ѽ+%b.A"C\!{WŶ-1(% SA;'H4BAq+KČs䗡e/~N+=dzC\? xn6G~8YȿBKN+cؠT^a2~VZUU K(5W`Ybh4u]WvGO RR0kJ:w^l dj݅9X 5$&z%ZŢL0 {Tjn{AVHa]\HMhxH4*KQ ]}ܮ@Zؕ{p)$˲H/jB%I;Na/q֑ 1vl< !eXwxL]Ljv YMT<5 u]o@͙@NY} ,k6BTJ{D14諪8!b}>Y9rEub\<8W-vZA?j),JVc(W6Ct8r9#yۉ*MwC6Iu4xB3èrGyrJn 1ûnM~.s{+lG?Kg~$@ '1ca |@-X1!'~ҰRy}Q\SXqo\mA3G١fp7 Apz_MCDV쩴hh=ꠄRK\NW< TD`t9[rB9q4Rf;\9!GLxpaeʧW=, NRM19?3?kF I&Ӎ^WGG#wEdPl|K;t–3q 돜PA6[N"B7LW9 5/|; EɊGO͝`|?VRj ugk\3Q\_H\;%Є!v EXpnWIc zOCO^+L]n(ٗ%[6-=0gwHw7ig+ͣnf'=\5 ?hƞtCa G0v"<%j"Ng^k8ȌCYfHG?m1~  l^2A%d bkLҔKB2u}ky)7t Vh>Zn F$uŰ>_ kpsQx> UiQ8/K$z 6Zq%\q $H&Q-c+xWڬ $<4t)+MrǂݿS#0MrǮk9-%9F5r0T4j<.bv{9ע,-qc[;46v8rPlq|TBѨjc])'LSs+PϹ7s99v%pEU[,@ >Hn_vۮ j2D;YA3zW"qX1!+ 8>cnk B5{MAQkVk^, .=8Rsa IzQj՞-+eȏxo_ȱImdS.sڲ2Z1+Ջ[Srkd^@[ّx%hX0&vߌ2ψu53:E:0$e}\gsó2T20>Et#@+1aTKgmQ`s݇Qc >Z@ñq;E@7v ot, }b "[JX]+`x-7}< =f90W$ti-io%RR:ZwE &7{hHcPrF2m&屆AldbՐ)shG5 skh{y*&ulG[DKKQs1u?I/!p\Rfx~FU|7!T mo\"6ErbMԐG7sqVR Em[xK5ŵ91I vvO<@9N]p+~R.T:jGeIFURpmV6t s"&4S߼h] LU H7"u3=1 AyIw+}F r#"Y[zθdס%ƚx/qкZB\HOڝ:*x_*}~ ta0= MO#C0u*w?%jJt]֥P^tYL"%V`_qimcƠHxw2$7P5n nP[Cf:L0^O|f-G^]A[=GnD7lUK fs<.jă_[QE7|@ vB#%L+>vMC$4Å7 OoYެznmfT89ZЖ MYCcܹR}WH@@N7dľ'Bʪ %_!w3ZhAːj_ed:gMDT4]=fɂy7ųZ%{;3|۹Ky Z z!X%+{9Z"MWAҖ3'ߢPbI(XD(k 8fO/AMhݾU훀b, 6P}5|P&@ aO jHMeEcJ.Z-D>B?%~HLv57ɿ)\`VغEntE~4CwlO~t ,n/#JTeyܛk$TqeMwׇn5^("jG}.̀Tʏ{zBz: F*X, 2}e0765>Ke2ƽNYAZu VsmͰ=+MDo`!J7ՠNpds~I]);F>;xvAtd3=ӂi;a<;քP ${\5Znq{wrZg1ӣ؅S, քd@kA(K  _v=&2%Ң[1'N? ތk+`? S[ZK̠:Htl*m X"h oPj%+ؠHNݟC؇ㇸ4s`icBx9gh!RVhF=-etȈH7 Z1-T5h=[tĢ,PuCEs#~(a B\[%Ĉ&TQWqmc]d.e.icFٓðڄ 4@C}r.OLh`3!k3Q 5^xqR#ǜBlq;c;ʻxK{yb~\E^[ͣu0xBdXJrs:AC}(vΎCsc>ɣVC";XaR~ť.=oX)Q=7@`w85ǺU8 Cc{n[|=0["i>3h߾k+KX.md%i݌Y0HzEKfw$'+G~=Nu1%6GtPEx^7ueN\ï :˧k"33m#>؝v6'?tTPqǑl.;1۹W@yYd<=  z.p /*_:uMN)Է*Z^;/{+C*0X#}Wvf=;Z-&9\(;  x%V!x4y3Tk2e*Pz 1J_=/tאaLn  'Cn8ғdž0=9Ppu# e8(V,Ϙ; cO|Yvɍ>|Bg"h?sRr#V䊗 ~_Ŝ` ~,(>[a~7|dW=ܗw/v: Ibj.ϒUKipu[#{PGZ"f`cĹsw!R^;`}+"!6-Q' n!XVuрR`8=P?l$XT'U4#5ưz5ǘ[A uR~C\Tzy-`%?ĠL^5m7^x7כ{LܢFx:B 4%i#Sp52R=^2!R6C4Rm,3Tx4Kcܖ B Gh瓒؄Nl^Xap!k4t-"w*1+_|4?dۨ)g*+~CihA>{fCկ&) y[ҦCWR⮣;KI >4a)Uơ)&3Vv36$1шa˱vFgՎ)C)7=^B>A_;tL})[(Z Lc/]=;69#S$nkV+aƴ|jSzB$<q0OԃNI01D^/=7\.,0&]V`p^@@ Mq[3c!5xL9Ns%Ansy]2zWbG3Yv69XΡ ^>d[*@肝 45SڏNJ h3U&Cj>ς941Ov.E.A8oP#r4aJS:Fµ[2{cf,G 31=D,qyQrWL+`? ?2r@j)@jwh}g_${C>/eiS{tX?@N-C@Z.ws5~V<&6=6}k\*$:a3k]`Q+?D>(Y_h+U3*a"YށAO10vpEn4˙eE@L|Ȧ=qAoFMs3rqKSթkCy~bI ?9 }}b'c;~ؠEB@ō?.{߹PH[88><`7k&6C\Eu` ,Aɥ k!|Э7!BHkFq)*>EV Q}Cq3$9^ϱihp,o(Z CVhUs)ImaFv)ޗBBڋZs8FUќ@7|xWa؎B'!#ڜ80l/:N3H<W.mPU)Y/REңEuwv*Za~@_O{G%9ЯAˎb}^et W'G:ʈ"7u..a)stTM<hKv(9!e=Pp]Ey~U"XMtLӁ{ZQV;a@i Q0`(Zn 3*bQmd'}^;68Ⱥ}L\4W.f4= P`Ճ|9 )RQ ~^>QM 2hcn:CV<kn\ӣ;9̸\o@{v꧍OTz|وCx")v@>2 dY'y{o(ˀ[Ll< 0VCIGO9|=,72x)$:E(A8 SĒz vw=:bhچ%#kAE_u<VsC"GqX,P\媙pI/ʋ1R~(@;4+~ܢY(qR0bLt#Z.ǩRL ZR K8\ c< !tɯ{ϡ;/>+Ml+Ay]'*]p!+uC7M G=U_>/eimD([u4XܵNH%c?ZoMۢ >Hʄ-iH0.u38'.M/\L.ewx7.13T>gj+X2s3lkOfq- já:*9 L|08B`BFMxS^ElF ɘqA;Di;cyz*!Y$6}5,z( E60"Q}nSxZ"sʻC":NcH*8[pG-nSݦK~=.2YYyxk\_X@k^z0JArȘG;]%wRNf5G@6%W9s6{->JɨJrZ]  WNF5`)7? OjfEZZbh{GgZo|l7EJwX9C>i_C>}5kWN7"z8mn%D)?iȔ~D2V%v̚p]%; L$CGG H{Q=i{gkQ%cK[YxOڟgOKNN ~S2Mw=i?F}AܝrT,ܪ!;ʪ3:˽,a#p:(:j.CO ұ \s'g{i=ű&I#u2 m<v k^U/4OM% RzFIF*|0,$T)S`?Rkهq:  Zb{}.w)ݑG&={5c]f76H;྿_מ#Q.Z``O;G S!yX+'ݺ]Oiza+sj9m뼙2m~: *#_T̎UuбQDHO53 l1 I㾯؎!od¼+ir@cpP2UF5zRj>~Vk2 uʹXz'`cГoAymظe@܅t+;w1,auMPMxWN*#ZvZNa}UF&Qے D/`&7@$ZL%irƌ7`-`{~ }Va ulv.5f{& Ea-TFur֯iyY'ȟ34&aJ<} sUZ `N?%ɇ¥ 9x>Q*UKF5 J?i\8P"n/֞u`0dNQ[g檱an\P/&z6{̳uxِ}V=B> ![~+Vo BB/ܠ(1a9fxY1΂$ob}V{.0Mد24i* uBL;V/jD~@IBswi)3CwlGn&-xİBC`l"^µZ޷`l>ix^+kP.7~3eƅotd}]^_vJ?8q|x@ٙayb5F2/RB~ehhOCTDc,ݚt@BTҢ 㾠huFaHT2Zh3MCACeV^pE"Reg2pg*Nj棢n@mbPœ8"8n}7߄Foe8IX>bw c4jE|M ؾ"`7;38? -P@>av6oM ,c5X$'pk8/EG) /(3)@\@޸!5dTnj0=,Q~9ް0YMʷ@/\1[la ,cvZ)1ju6iHP*f0D:@a@}$uf;'%U4*CDa7~bM!I)7SwagJbέ~(0)9״(i-L~i&S|hm}\x&Ey=)cB5.c\(*y1aU T_U!{bsS7"hmv9ѫu#wSqj  A1]_od&|6Cq, ;"a5žga,oDŽ@=]a{8-{u;J]Qkt\uەшY}jKkCmӝgujWF_JGECKfI\FI7tDODJ|Vdq?\njx TDL-,rUqPq>)ӦA 3 l%#Ct"`ܰ6Vo]6x8۹EOoD'h%91BF.- ȭR BF:o|%v쌤!E[8-mfj}x,Z,?AۭWY_5+Aм!&B.07`=hH4ul{:.:W*jI+_/uNQܲutPgB1oD}7ft!h,=F_U8ʑ Z(*維 ==3=#RTRB< @<ߤPOpDf)4U"Î bvD#k?4T w*dǻR7jb~(?7_z"$iʏ'bĆ f8~A^JƘ=w`/D'}RR[F}eXФ٘ &v+@Y/\O Dƒ^_Y8u;qDFym!6UWnln+cǻfs1Gd;Ud63>zS_wH5O%'"+o51W#ZC5U']7^}Wt1}uƝ|߅KZ/QxsʛӬ4ik1j?l*lJ*^~8L)Muu̝a>(/Y(j}pY+0_=bLEHi6RR~NŢh' m13lA%Ai >@1jxM}^\GfurވpP )>1JJNPZ RQ; qġNU@..HOiXdE/ / @ b~sgwmn$ 7&6nRw/ Y!5u )]kݓKSx⣖P$ʋLlusqXQsR| Z>D>Xp ?7QO:6}t&^,RAֹ~Qnj67$ω궑_={!q d H SɲZ@G8$AJX4 EC_NN> y۹olŎqXL!Y[.A钍UkY*Wx";8-St;9'%FXIP'#b;2/6#5f8mh-Ф8U9,ʺ8v0k0 D Zb8;NF;&,ڪ&4ӬU'a2kzQ!1buѢps(.WR A+zܩXwm jfg,'n83zF*N"f3"4CWMecK\dAaf;̟opn֦70-Zu[ <;ҙƇGa2&DZd%#H,1D `=.Nt /:Lי'"LKX:q9!Q=k? pLjv>"`v\z̘j}h[:kdXmH\3{ǞşiAAlmht̓ MQ Tr 8O8~]ac6,l`!kχx\3+)fi^CUV`sf%h#Kvt~prQ9fcN۝ @wUoe)YD<(Tų銓v֩W+FZʩ^CmM^O6{^=Pa*;:Y7 z/ (=zG+|ҿE!*mJ>KÅPi;v8O+{զ\JbfbcT4Y[*g,jXi2p7*xhnn86}r!f⹉ZY@*]ɱXm<ċ؎E? ~?\|TJ@ ڐFEAG@O0J0\E<"^/'hwHp_nRVצ$*` ͓ٙKV~ tZHe xRTᢍ1 6œXtS{ 705c^yYC%/,LzfeH0*U")q)3j:iuXl7? :TY_(A%T5%?֬gw{ōcA"(3Ղi"GS^*)`}Uw4#V`Bb}&ZQw}Ü:K]Idl,4`袇Xh2N7 X7iM{~Qjsbe\ˣCm^\xEv7^Ǣv;F]F`uzEkX۱tLuzR=@.UqFqGyA.!d -!."j]ņ-C ws\DŽb,i$&9 q\2(sHH$z.!_T'.NfnFQœ%iᶜ:w'qr\Õ#ґ18 'T3fCi:xqw/Cwip&/ żӁ5@p6 ; .kH+`!P4*҅i[hWt8LA̖ F!rR+6>;(OɷE&SN;#aNi:钺zGUn*|O&3]'ceqtikt"}ɴYrAaFۡDv00+bʝ[!c7Z&jCjaO1{]f+iR/nk_?>6Xl2P[kѧPLnd*%g"8NNd1jt.QD hZȻ?1씏OvX .ebRXbCaMR8GꙡUv\ԡg^$ͿZiSnܳMN&ƑvMF ]`_Bk7{'>"H\4|{9!)Pj|ɛOI9v2>uLfjQWfqmxzWbx_ ]Z~v1\W \dHL3쀣%r\\ߚe](uf ~κV]>"ŦZ~9 K/!V]7@% 7hdٜWb-^Wށ5(dA?1a6AճS dtgߡߨ.`f_nB 6bI"'(BѝԚqÆdϩ~jac)|1bk6BF&P~لd`Do`u Q&m~a$_s)/W06?$u"_ޚhUCs= l7̸BTI+ݙ) e3-SDXSN$ѯWɹFsPXInN1cҩ[+|h9%;N(Q&{Lą3b`ٟT`QzB8/~^J -IޜB{K.j)鉩_[-NAڰ )mƱwX( A{,)BfNs)w"I -/Fi8?C5=\=@C;QoD8 zVH02+50 ߈#eh )2Ѷ9d5ыcx Ǻz{=£3B>};7bjI | b&p;ᔸdw1 k:t_r';FU;b_S%y=qh' lB[:EvYq$f~ØכAZD)r,L1:[]PE-s v35eȵW@nzn뉳uݩɫ/+\Ra+O<.½.{,)V+&V Ӓ{BVJ`R ( .L\.rbZ gAX 9O ٹFE2X4j#F|TKAF~91n6e2ͯ3O%o YY.睼;[AXU]-u~Tg[1LCUgN=o!/urAfHŐFZ6cB7 Jz`@I?r!ϓe C_A&׭%ԙ*C\ 1d_yk?Gk:8$HNp Z/DFs+#v [}YW-q3zGDH*u=J!2#gvۍxuBZw 5C>+WS{|ֹ5G &cMe)Ƽ1W_@=O )"IN l?by2]Nb91ф-bj/_pYIT$fҀA2T=U)\ Lhh\m9JR~y̤qs^Iҳݹ7a 9 _  Zъod+f3#?vqE9Dqn}H1j9!մ+=AdJxw-!S?j'^G9t'|O ת;hLM:*7LJ®=m`։HRR8@ eTr4qn+d`p4?c)pm aIJjr*~褴?$Ѧ/E2?W)7s/ԉ"'+pV|75v2P0 W=NzؙThQD@8(D*X4#Xzjns[HO5}ߓ-@r"8 n1y/؂ &!WY4M+٬,2&wH(J6!}p+~93 uE5{Mt#6rH˻ό뭿(A`L1-4߶:znfHLסxT؄H 3l Ŏ^a*f1yw Gݙl=Ttb;i;"m` :ӧ(3P=7Yd%r~qk ̛L0'qTK.x\^#d=(Dt-gMԹv*yw0b2atĪwnxr Fج;CF2 4YH/D9b 6=H,TpV밐f1/;Qj}8,å>OS:Z)]Љ:Q ,ā 5U2 œ&1ȾpQА(No#7x&X,ߝOk:^hZ0,(v$V3vZuenk^{j5mùW,BJ\F¸խkfmVhq0/35A">a~}#r@T|0SXz ө]bQ1djNZCŻ_T*BDJgED5ZH:آb*56ޅ@ng Q! /dV646-s_gMJwgvšrA"*(eG"pñO1 aALK 7`]Gq$v]Lǽ/Ȇl妀I -nz->IpKH}{˨?z(GMAxFYNdJ=7 rVQ#f|_x)~p47$nZg[OTĘK Zc&N71:*h \&)2voQ92S۠26?%g&% 7 -.Hh+}Qvtq nLֲYcG37iNF.ۻg$Dwx:e^U_Tu2g _on(c9#`D4e Ȼ7 /6g+_c\ГWZwO`7w[`&7&V?pMeb_nڠ!{]ѾR^k#.:U;-d5dYސjTt*vI>~5R#\:2_rGxLrB[){P$F"(!ѺƜ}<*$>>BZ%oq4dhL7?>~8Yvq>:߮2 +0k|H3>,kXvH4ףL:h ȗ oHjq>_) GkNޮrtID0kiUg*7+9aQܘ0ȟ9EkIgH3<ȣ򻪜ѴAB&Gt4o%jDc %jNHMXBڞOSjzv c}/u˫+.(k|+K2mұ8E ꄬD'$ +^7LOy_^.9IeX{ҎTg䣑)?]Vo Y{{HZ\j5Jq]mV2 o_0hDܱ@w#4"qľqϴ {|ת3@LpW":dT"-8K8بژӃMOԧv$=mo ?U ^ϋ 0\HO![o3&(rO\)܂ygf-H[ZcMLC!T&]CR[勦3ndTFc6J/ҙ~E?9KF^_R"Lc9AU~,Nbiz_z7tҊG^xy_O`*cyWHʊ4b;Dl bQ\٩ٟWQf,CEcD>+\0: 7SQʃϘ]_C|\ϹHlS ,YBQzn8'jļL\o2wT y`^ߣvXѱ? F`Ӽq}.hTqSjK^yLC=CYtOAO37*-]T)5y6>dvH{ބn QR ?:xe"^022%ysUeE$JVB.)9tlccH7ORZ)2moaqUe]-G`<0aXSaV"/s2fus8N#jKp6|wMs nD%'_/wgoCzS}{Ǻ$J>NكQТ}aa[Nh@2PT.¨~q}Lٲj!6J8{tR筦dPY,D*d?CVB;s%Y#}@8zBEgZ)ŁVFqtrے_ې.Qk`A]}w&܌L(3PM >/XK-oU5P[ RW>]Kii\iQUJh3[sUY5a|eWYL(Lf@0!s; S? S)eیb#N&E^Pl UŅ=BΒAqͨt}Kn(y#`1Y r7CCph3/Cw1RQ>Qsdٗy3.gy K{)Y0g# \rRa";EhwO/=FuPxrC\V|aPk d?_ΛwUfʺ+>lނdyd:1u9K>!|)Wʤ|tzNi17 aA@k_GJe3,g}rM|\_QV5ׅzU ]f|°q=_w@k3LHLڰ/`y+= N.0ҷZnovpjN"Q5 ^*'g0, ͯ$DBqX삱]> j%`ٜZ>ՕS'0KpËʽ6~;g)?&0P\[q2dѸ $5ƳZr%ĿHԹr& `>w9 CV6!}?Hm4OMr2 !GPvg0\3] t(X:8:Zqx2!6%O'Bnl+ n3Z ذuo4iUըNXl^x\S*HgRbs33z"*j?iùj޺:2vOlLP ă'\`@4~IX)9IxTq6X}|WP&|ȻT/gxXse;nF_\FL.gCgGhprj<hb+̽8,Dw ;ch,rMTAe\`E(w{Y/j;D^" )5FV֍`BS~n^E`dWZy_ZHt R/O,zg/BKII%v2;Tz g ͙n.S!^]z0c9g Uu ߕ2=_b`?[2Wl(sw="S-ȲqσilwKKrHERݮ`oyZTc2pܠ9Z׺U"U1]mdŒ*0ө?TM1bޯ):-9r{9c ~5eg>"'ޔE j~\W%mg[Im+4JbY%,)BXwD tFTr8V6g* e^\<uo4vUDŵW{8ܥ i8S |ڼJn.&\CO. E, P^TC7+V/vok=1ɑligH\= Ng"EUQˑHer̳ukIN܂/y+*e-ܯykr J(Pf AHsA&jYo%ԛCvbP q[B `Kx _\Q^]议U sQǢ]e(>!0K)&0lnc#`fsIҠ6)>IXB^Qh^X&sO;K_Q%j8+& 2k zxҺHKS|vE JLJ=HREL{&EcȄj~ $Xi`ZaI j{uId hOH?IaiA?-a2'(n'i@53eAO72LG"tr.='?D;#Y,I|#~Q;Dd~tT|#!I@T]ϻ·%,F u{J/<.T);dȐ6)9ԬEʹ)Peaݚ@Whs*!so?{Y)Qyao8(dhLhaSγZ! v3v3[9,҅'#laQwd E20O^ b{RZ*gMA#8 ODAQRHȃQji0B0_6hu[~w sd$qjiAmc8t3ix65pL Yoa yCnbyt~cHh#=z08ǁ`=/l-#Yv9#q!*bs~_ȸ^uR]46z#Ui[Յ ]Y!ߠ Qq]4}\*v *Օ YZ