sssd-ipa-1.16.4-21.el7_7.3> H HtxHF^p! ?*}}hpJe (D?AN<PAߊjy+d2f6c7a7efc2f7a1fa8e4f5da67f9af55acf85a0nm8WF^p! ?*}}7Gi`4j`_DKp;" "Ǽ >>?xd   : 7=D   , s |PRR R(8"9@":|"=GH I(X4Y@\h]^bud:e?fBlDt\uxvwxyYtCsssd-ipa1.16.421.el7_7.3The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.^pasl7.fnal.gov ~Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdK &/A큤A^pI^pI^p^\/^p6^p6^p:1bc9b99ed69b05344a65e9ce8b97258d85a001807a994cc40044ec87864257b3b3fe4189b187ba5ae4fc007c88f584c827691aed2345d124d21dced6682ce4ff8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038781226816fef3107e482d00e03c1bbcceff78e595619ae9955b12f1768c5c408ed7e7ba90621d1313d77886209377a89dc4e9a1a02b8b095d0a6a2b4b4ee4cbrootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.4-21.el7_7.3.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.4-21.el7_7.33.0.4-14.6.0-14.0-11.16.4-21.el7_7.31.16.4-21.el7_7.31.16.4-21.el7_7.35.2-1sssd1.10.0-8.beta24.11.3^[^E:@]\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.4-21.3Michal Židek - 1.16.4-21.2Michal Židek - 1.16.4-21.1Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1807934 - sssd failover leads to delayed and failed logins [rhel-7.7.z]- Resolves: rhbz#1801207 - id command taking 1+ minute for returning user information [rhel-7.7.z] (- Resolves: rhbz#1758566 - negative cache does not use values from 'filter_users' config option for known domains [rhel-7.7.z]- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.4-21.el7_7.31.16.4-21.el7_7.3libsss_ipa.soselinux_childsssd-ipa-1.16.4COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.4//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3f9b9c35f72780b5ac277b3a1f17cc4fc84cc55e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=a6e84f63e2c364f030ac2f8d0eb0bbba67a80a68, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRHRRER/R RRRRRR>R!RR#R$R2R@RRR?RRRR RBR1R,RR R3RFR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RGRRRR=RARDRf'KWoh:6D5%+_Ma<#?p1"g);ͪٽm/*ە%X%X A<\OBt8fROd]UQgYP!Ʃ!7ajԽHRen2N|Gݵ}`/2+-TθhY!oDat”vE~iYOFMlݙRM^#{KSL{@B02M2'X Y: pH\s~d#kPxGOZ&SmCx4I3K9 vUI?W_R󠃗[m( y]k˵djCp=) @oIZKrjF^&NMSYD7 ZJHƧ8ffJ~W&Kl1 lv/ˆ EPѦ⽶*^z6w'ouTcZb4Ti\٪!|3X:{'bs\;C!y﷛rcc#FDX8jU' A&=auJ՝S jmuMBʨMW}'m ;zeq^Ѿډ-QCJM[*NÝp'`iFu~ (Xډ겤t_춖bЉ[Qqn%wLe~Aل~Px* BYq MdP̊2}B:M MGB8>Ty87-ҭU.=yy||oX+B VT")_vfsIĥ@x :p`im0X3j*o2~BDluUspȋx:< GpP.MWc/+65M~wVWBz͌@DxW܋}L$)}0N^ ]6;BKOHn綋g[vu6 , ev&ݐ)VKB?I2Zϼ8A(ce\܃hrTj'yso.V|+۟QW2/\?3ڼy:EW&_jy4͂ns]0Zo&cBufwԨ,a@)"B_qZ:68̉.,oi^jSJƞu;-xtT!_+mXZ[QѠ* 1;A3߳!\/NF<:Q/}0(#yH^.k.<,jXxB! K$ʐ^Koع4\c+7]:+IXknպ^g !#RJ<`vPF1!EfU<sbjU>[.f*?go;?ݓVl&M#MAh@t;:pE>y ajW惹8Z8ipн *) +{0 I aAT*6jTȲ]!GNUqwR]s.='clnTuЏ]7g1LkorzGo9w/0س\j.`p5_GBv8/#DkAIO~hdw~_KeYrp2mxZ`B…n8 \ʃxAO;UfU HM,u}a*K#v)?@[cq>b %ԟ`ǀ/[ߒ[a ?h-Y2ρAbǕod Iz )4 )O qܛܐCjuqȍح05bv0(|lMդr|3ZG{gH"5>s#h4 өf2u`7QFpl.H瓯;0աGKF6>Jv ~3j2[V13a+5:TMF.Ql`V7@o;PӲ=]f7&+11F\!EGBG*VJebW $ ae×Aպ4׼xmgK:y( $1"*pY"W3>1Knxх<JbDud(qcH栐IVDwfzssrQ%ǝ B%8$YP>݀-1Y ٙ>/paN};[@TlƛW~:cA #:5'3)t(OO}]n웲/[7-?|,cn5sv A<3C[6ST[uy3A^+2;+!i;`[ߡt=IfIul#hg~X L լڴ~g }Xt N~dm_!]uMd$DGݿ?U#?d],bܓ\-Bɷy ʇ-b8iF|#a)Jzj~\_@0vψܝ/V_ $r W:6z[>=ϹVf8F71(ĮN~&I> d,7mrVW\mcPCfzBgoH#/FmDpE`$i,Qb^U?v H9s3qҏeDJagde*0gdot. b,Ŗ PY(- i) %REmx? ړwv QiC.(^-zŕ?xS=J J٫V+9bYcB"#D7jۤ4.~qI {b0kM e5R)9etAsꭦ?|P+r?&.P^W X"9mG۩y~Y?m8=̼e wNyD _~LUX ѐ</kV=ok|8ԅCRvZiwÆQ d8K6Tx0P@gk3Qe@0ɎyQ5kv7#og:ocx`+׷b%C|=w<`>SkIp=4X--rsbέӮcX1O63kaqD C x s!@BFg.fqߡh८}R(=vH(93hmTw] 4(4wq1jAm`$VA^-I]!/6jPK# ׆QSFᑮ~TM&<67ٟ~M]9Ǯ Ǒ`f:Qn|S, MW̎&`esdhƮ?نg!+' =?LIBסMmɾ ZS1 kzm`e36Y R] j"ba+pWU}TT$L~u[m'WRRPd=8֙Htg\zn-*+:S+tϬ^ %ZtvH4-`n-{Ad{ XB18X51E]]B֎4ֲzՂ-߰k4C3; :?/Ռ;C{\&'žQG/|{t?3}cMiJQPQsB"[?nڣ=Pɰv\,œd7*h>c"/)8ok۶UbZ:{s)'ۭs$ŞA0cʄT)Цf3d,%ǴM  W_ q[W/'Qm7%8M#;,$X+(ڛ^E2Y70e~8"t5&9a{@jS\mOel<0 ي$#qkW9VmcddF9A*Nd l8ttlkadÁb3'QJ'1lUL?EoTXx1J2V c5q?h7xDUHl8J1x29-DYR7ߧ CWj".Ky KzBLFt)} RwSi2뒵eVHL"΅+m 2&buW =trpjv>t}yN0O菍Rwˁ1vY. /ڥ/,jzU?̄>wD jJA®3IsH3+#?'={S}ZhHb\rB@~|R~? -h#f |{%'5SkʸeQ==sd;'S`N.ߜ~vetWlD> Y 4|a%N v.yuYCfco[z6<; A+2淮`+pWezU*p@%h 5FᨪluOkYl_-SGkԡru3b`1y 33LoװQe¥Dي~N{/ z>&Cp @T7#fԿq$qPN ukY{x>K?chP/n9/\w1T|u0 &Ycb \N[wV3ijºP~T[ڢNqC Ys0$NcܡR44^I<  ̷'d  <+$a/]t:i%[<$=&,b]*9M52&7ySl~6*>Q*ۏ̘n22j-9v<Rr]?1~8;[k;uh@>gOi;qnݲy*燛@*_:{>`IXgDx"~&|h<8݄CC,Rt~&U焝%ڲi5C6AO3SEQ̨\rIάߞ2L^Gk`QK_IxoE9K6KDM߯87 60TcP?Ϛt9`amOs2o\5*Eq"Dmes]# 7 nzo7UXQ|7|-3A `rƭHCwDjı_Z],mB.!\#~6)*^K :cB Q~5 rPBQE+Mz4Ƿ*Uzҽ:$HڟKc%bE2I~.3/>"!8l"{FvlVeO ]]sq)9I>䠖]Oy\v0oYt'^oގ :0;dY߷V YH]b]X); TA`z#G'1uQ.bvG+f2/1%<&Gl#+\,-̷5 虳OK?CǓ@V.ee2pF~Zh].C۳u $yXBLZ DP?mGy/΀UUm%1r_s~aG^;r3XT^טs D~8;BwX `0,]d CJ۱;)2!)Rx+ѠiCF @;*˳ aB3'o!^ ju}ɀzDֵK  S琢 AobgP~ԏkVa_u͜,4nBRw 6 !rVv +BCD@FǾ¿6In7,k}%0Go.l3f "aõ,}<9i n{G,忮KbLtq}fKFXbZ_Y:H-_?`, GLGlQ\.gD($h.fxHM:]N4tJ6AsPu/|%s[e&R]|D!,'ݦ!ǮGJ,t9oxroNjm c55,Y-sV>`ݞJᾗC".vyyl>L=oZRNIrLj &FTYt56 F A݁Im3^*sǐmT5Is7?*ѼDR=-#i Э(>.||QSlE{>HJXS./p Q4}N{q% eI_N 2+.6E|(Dxʔ[~vu:'}9=U&q~A(]|bl)Gz66pvT; ,4DbGP&}=Gh nz'bET=jb.XpvC~qb಺l5:A`6ef )3B!$1)֖"nHא0?4p)8(P#"nov-F<LȚ .:|U73x؀c.j׷~TOٕO[^/+S$˭ BhH&벴?&   +Mո_J_.xv ;2tx>LYb(PkHb\2Wsb 4Ь qxtn/ m;G'TɤCԆ1,pcUn%;1y;)jnQ%I,ip*1A$j 6YQBE]lIf*1t.6g-(gKH=py= `\3 gk&ߡ)^Ū}?m/jP_Xz'3zR0J;&XmZ2Sh37 owv*x}b$cnst1B2ziVcJ(q}B1i843p}fS-pv"paϾٸ1mp´qA:բ? L4ɰti}ghGgnl !hm`8elUn_U(CE}1Q_Lf*0Re<}`EYgNP\Ӣl7I()&|.NW8=kLj&^MrZfgm Tu;"iMUp& ^IߙD9BqLi\u S-6=uJ㪎LSXizjXr+NBE@e+SKۥ&9Qzi~vVP8)/ fi^8)|M }R?) danJ3F!wKe>)!gu9 _jФ%AɠTA{!*kdGAm;9i鞋ez0a焬k=2$6mPр$λd]5&F;vpZ/򹯫vVU?b^{nP&D,tu^Uƭ17?pT`vtYmIXFro5S?_#ٟհI% D, C=xCl#EmCXFz2ـ6/8DvBi! 7Oh)*b Uc5M(Y^EsBiO;< b9I&Җ%Emm3D"=~ Z9 (Uj :5L^p&;l{pKT>LjxLDWۆh5"^/Sz>n VrA}}\rzY6DLěd1$YP n CpНuS`P6YdX%ZS:,$6[@I< hq8 /Wýf6ӻVǞu={Ҭ9>6XXw}ʙE86xCpQwM]2ʲv)Gɠf1Ju ~h")m}qIR\þu#d90| j87[wm/%~Steؕ7.OMFH9cun)1բ "hvs͟m'g"OdQdP,c9QKR6yˢج,֋U\R~uō3F`{9:!"Au2oWQ_O܄cnAɟ78BxW_쯢 #Sڶ F!Q뷩%E k4*Udݙ4g?j4lTi\ l戗ZdZ$.2$|z@ sf97xH@P'n,2縉I%e4ыpﰀ,1ΘqA!L=w٧bp״vv: E';!uDg֚INb$XW)'KRy!_ߣox&@ 3xm!~ΰ8M=ugC4[|]zB.R wDwt^b,5B$-ԕKC[dӬqYD/Ț>Eb\7XVm}}J7:cR[cv4kiV+Zճf }i}Lh$8.Ԡ&G:IѶ9g55:+q@jJtc1GmvXB`hֿ&1[m=lۆ {L/6yq(pBxuDi0H>)]//B/p{ /s_+j,VRٞi| ]#dLUGHՖbqn@5GC,r@3y\L<Ȁ,' a1r|#s]y U e9Ԙ"=ro;iRtQ1#j`|k"pF*'/c*k 'C.Mĸ`S眬/n=jO = 0)M '(Mbl j E2|]_v)!LQ_{3ʮsHsaנ:N;cL!w`lf#W"Ub(;g`Iyh9'?> 3<(4N! ~2b1W(PjU+23B"?29?TmiLjAA9BY cĶ*)c{Lg LX(MEiώ) /.e9H~,KzX6IL2HU2@`vMD@ i13J(PS-ˎӢ%`q\au%c-gTxQph'g[E{|SӜ,0,#B`xCz5l35ЏyбTȩ[XrT wpÑyJ似?x=yY21oOŨ\_j٥#cOtLð %7=a 9t" @K7*e(KC=Y9Byfx,|^C@*>4./ɋN Jg#2:=jf[_gF{mn}6%_3ŋ YbTP^ ͯ&@*mDfFBa?p]o햊<^J9ճ`XXd8!-Z]B?ջ\D9fFNdkn}I*4@U3y3VgP/d+?Qwp8l@G퍯_{aj-d)/9 ^\6UH9K}%s} ̿ yH &?DjXS5dqaY H7m+0-tl9gě)M\9Ҡ2ǯh9wc)sA!;Z<[-awuF9`1#O  3?[h\ [W,$KMݱ=gN@]efl9\uΒo$N<}l`ΈG OfbQ]HX2 A0}tF3˜{x^٭<&c:Ļjs[C{ddz'`9 d5Jݎ',u#:f's1dݙk~kn%FW/hl\Az1.z) Bd&ax-(19l6_&4. yr';3hݱk`Ayp1k (_]s=n p R \P2 }߶P;g;\ ![0-}!]R\gTs[=@D"-e@r~-ehڃf I$5@",m ]GI%-)rYdj.BNvVHxUלQqFN 1 [ChJd͞}0h>2@[*yZCW5(x:;pJ4i}lwel؞M]eǠ2 z4N CU)(LJn iI%-Pp!Ə\ 8C;.^aCz%&.S\3R9H ڗ{{DF]u4ȇ{vr=OBԐ70P;/١2lbPGv U"&|RzvˁIKJV)a2Qfc_пǛB$0#E5W5:~]ـ}΅gw2E /2pwgW ͙~go;`&KPRw5ӫa(As-[[a*Cg)WYofA1^'Z@Ȩ P@2UIpB[~ܾu]{h갵 ۡsΑ{-=9{,m6|G&*Tצ7*|F:^dT'ʄsM[wƅӭ¨_ x)=vo.C>R^L06QL3=-L{v-GH8I8;D%0@Y{(1ڣ)3'OL|*u7CESjVUٽ-A9P\HLj$G1ko+Lj.m IAEɌa&TtxI: IcKqўРԶDWv3ŘQCgKmE2jefyO+Ca%S7ҷ vuqvи\դ ]IΉL‡Txh6OR|Ryå{Y6LY# `efeG@M.;K.~(-tϢ!lB-\~84A^hTd%R c)'9' oاE=FJ?e UB+bp xș0]G hɮ+_ dD9P,KE9HmRO xpw' .$v5Q)_o~,,у /nog+$D`31jp*?}}kQ5AUՋ a@6l?\!6PF3'( ?.Ke_ޙ-z*%sCWxbL{ \ISsB{3Bm2wº׵4nA[%P`lmð%%?{,Ԥ*ݲj_pwHiR2j)8NJuYFAgZ@YyP|H13Vn]}s(ak &9"CϻKN9b-.q닄>Fx8,QOw-#X':\KIY髫pIFT̑E|cM:uMjnQ5%ԡV2<ͳ}`h٢)}F|Alh;[jQk&DTЩW@#=k"@ \*L}ArA Ί=LH)^~c/iDvvLn{h̷\ X͂.R]?z*]Xq X>Ҵ PBT 7a,m'iaz@dJ*ƠK~O:\Mx-ts܃A^`Qp54D[e0CPz)LdQ-f:м=0<%HlRm`Eiܡ PjeA2#ytˉ>T>F??7.sdlč~~3x;SnH$M0?0apRp'fd\7 c,IzS@YNLC`rѪzಹ8'9 E| hCIu$lVK< (<AuL(RD.tId9U1Ɣ5f^gڿ`8)Y˳㦥QA8?Ω" bUMmGfnBj!@NY@ v6}lUneJf-TE^]n"d~fꐱʆ׿:KA{?EUjTYGuzXT!9Q?.vۗ5G&,~o(E;O= `~gyҲ=u04-s֛Ԓe s2ǘ-*k q9>T X0+ڙ_#hrG\¡SSB`NbYRBHbln Pe&*Q'2(I Í4^e* u 'Tv5!0}($Lp.b{{muz^{G2xYUED0 Af&MtEz1_Hvc,r4 ;)u)]5w0+0_yl/4׎^S3Xu<P#RcҵCWwg$[Q)&T)2p\Gi8!ɕUY|ʳ'$_XT{B.t *Xg7ȝLaX v0!_/| (w 32bas\T B9lWM0564Gc3/JC= և˨RoTmqʬxR>ѓ(?Q4C@cCS@sl0ؤ 7PyB5]u1p=m] {ЁמEKijb旣^"j|*g@ؗl/I>H,q$KIe"$z-vQy&DK<!%gr 8=SqTt!2Q `l(x@-!"dI>!RzNa߱-,O-qXhY4&a]N+ ~Ćrď/]-+w-û;Pa`H&{Y(4\zS#]! ="YE6XkI+^Cآ[̹r41jmh~uf,ǘoM,ۛ{ƆiŠJ}iIvK7=\,{UJ{!4iǦ3TyQz:L夒W{]r:~Rz907Z8T SW82[$w!.Yy-Y,Yy~y_4FW]My桊j$bp2Yj'+Ơ\_/-C,a۷ YJep)6''$^h X|"y]4*%H ~u| 4ѯI{`]m&< wf~9*|_l%9 ALdKYfخ;yY~lsl:A[x R3ItF8k4:'G%$J1!A</NlRsOzii<RF_C/ ZTji OɀgH!atNa`w<|eWM߆ʩ 4qH-ѻ ">="<2\S}KNa2RO *NMpK玔R ZedB0R 2VmNA2$]뵧_=LbM#<Gz--"s/@ږXԲT|]`?nZܦ/P#DpdMD#y;ut pFk@Om;)oڱ*1t0_FɉZrS/>##abrTg+Xb>?Δ h-)\K=@_}c<5-} jLj^.ƔSZY͔\TAbj%/XDqa>`4:{_`r۩_vr Yr匍x_1ƼA_*r{|Ǘ pF0b",C $~m ԶI"qkl$a? 2ҏWkY]SAs+Prױp?npuX#'-&R2s,==Up`ףwd 8їGRVZl+Xg|΅3%v UnjwBV[>'eHdsj'^S߰AqWȬ_1 3b \&X>Jr%"Ĭ)$&|&8bL]@k1"VS zH"X;` 6(Zgܰ2zlB̺ۺg"ֺrU::| #o_&$ QǛY ÑaW`MJZ$M7 ="7FH΀VmhQ (ř*ga~#mw% FDJ8>eSO\ / wnό\͛>2 ׷]:E;Ydphz tqVX6;s/}L-SԘcNsm#3EŸE ,>a>+r:c2w,wވNxr ɱAb38풐:d|V(3DD l~b0 䴕`Re&kM qcb& Bdž&bJҠfe EB)͕@T㒗-ȫSbjFJe1 x`bOp&<vOsg\Re 6qșɉ84 J>kq?n_0ĸ5t/:OD 臁IDNrne~T j l /kgR^8"љ6rh|*h-vN)67t5:_$/ذ6@XU9̾Ҷ\,(yW_ 5׍&ubC\i#ݏu=`D}n8 F"^2NXD$Vhl<*+(xt&@G`C ?Ι͒w`~76fW1P{{j{!T/AF9tkݿ<+7RSed:IGT<,f`ROtaS [ċW-jE;d+[/b Ib! hf 8N0/Nl1j?1*$Vhie}xIn4p)FѺ$6?cѪ~ z!rM*m#gX:֦Ijm0^%Y 3@BAl=Λ|p-ܢ.LQ{$n5lR5[^G1$wOEopciRĽgK(Y>&EAc5_ yϔ^52*t,g#'ForcQVUK\Q_صYt?jyo9B"Bx@aYa71IqY' c$a{931^vK|,@[X=E!SuWvB%St&iNҲ>uPig?y>ޠF-]4V ,mD%iS_7~֠C&o-Ő9ܿ%^ʇP s/VʣMnMֲ]5x-3DՅ"]jCI鵁`{"־LJ5XMe"1 ٨ROP*->' 1zqgVo{o>- 䍨 h_3r( o% cnkB+v _ɡ1"u^ -}&xT V|e Szı 2onHuׯ$o-9#@hw3Xr"AAf!_8 O]h3LY5M 'o)7f;e)< H#;tޕ &+іrs½nO#C8c`HB+\dI/Gnp'{^_ 0L{ULX~LK(] B P3UU)+5ZFeGθ3w 1BDЯϼidZ༦H+k9{wf da&SU'W񊬕v@׉ߝ2}"RTs-[yeͫ=@?¡A2 |欖$7?C< Eh|OgGN4j$.ͮE,=r.BTZ~l4WgLWX^&{~v]. _`/Xz 'mLrw"yEgJe{zmhJ 6ͅydbv/+GzrR^1U^9sV`5OԜ)Wv vv!8J>-Y1HYlK4bY ;k R)g`Jݱnf4:WJ\yvAoeP::PǣIKv0}Gn  }Ƌ(EVl,| ѿqMHd1nwA9x4Fɦ8g)z' k7ZB<^yoS'cߪW7c~@y?H+v׌nuVP&SmzurNF v^K #EsB8 ܭgǣV{WX5mUkc9ۚ?Ltpe ŠcCdN"^+ǔ Ck%N-nCx\fY,e3lnl#PUo+>TF3O7X?{/lGaK&,{*!ύDR;)c('3,ҞЫ.h5l6-V, y ւc3G-LP|$?1pB3?QqgX¥1`2/t"V־Ϩ7}`izx;HU{ӎ.jX3'r!n@r3N ?i#W+C~Z)f?;efG$5>BVaӵ ΰ=gnDۓOP#nuSSt˪3E,']JhTI"2ڝM׭){ Cz^aJ_|W#xrkuŰ1*ĔaNl]!-K* n^}/%)XCl2 GO$b(Aq VwKzpQ?ا0N,ڷk*hKeY '+yX;>N8S9ە_f + ov]_?xQ BE}1 ȒG4ɂ9 lmsqPutj1ZA7KT`n# MpRwyHYW>kQO8*A%{뗶bPuM=]Y=\տiBwƾIU4({ZyoI}33L( Oѻ/B]SAzh.)u95QV>$Qy%oZ0hnG9FӰeM%ݘ?itf ߞp1s\TeeuЉ,bNJCOHNUNO)Xm-^x>ƃ͏|yWAS`n4ArqryтOmtyn뺸-$ :+)0Zmޮ!땛.\\pmeb-v5sk{u3pư#ґSh$f?We+ʄ׼5̀s=;@IͳY׈^CWxZP|Uۛ87$lMV| B./GT]Una@v`˱Hr賄<#pAsҧ:S#GDhP62뻭oͩG-̆O||8 }Q-\J@?2nL4uKn3'hXЎ$d֋1FkHr>N ¿ugm4[a+35-Tt]8I78(s \nB;Q{/u9\Q]Zs\lsߊ[wZ3 G5mu ۩ÀL 5Y݄iԺBmBBm)wMhvj0<- ɴCg &UYʽH᪓D&vޓh^>\!r!P7)w!Y - |rSLC%A>kxݔ?.giRO^k[-:>+_~ee$qv9I׭Gl(9uW "h&4WLfDnYr٨![L1'o3xjRd 6%ھC։x9qx}F`(L=xCF1 ƀsTv:ܡm?G:l}]pGa߮_8ɊX6s+7Y=ʛ/YEt(!#H Ϡ;->~o0М51Y_{1ax3Po1}|Dpa5} "ȱd">+w0O&}H0E/IQA f!ɢ?}~̿T b~zHޱm!o,{Gjua1$MPqvP˗֣y?V& dp'N,e"ҤM$:~قaqmDNHo2IaHej,-ja?P|ҀYZS,x%gQ_MD6,Rg+KD4@/h*Wηz yvޔI6Cx.2t=H& eDsK~:AP_O[lGki U~b$d)Z if_{T>9 ?4 z0$WW2`ɼi8)PybzJ$H0c˩_JDb@<Y*D EnmPu5Twڥچx !x 2&|١ ,{?=ET#"Ȍ]].Z/?-e*9%AvPWQȾp,^!&5Qe~[1|lǴ /]ǨYGArdj!~[r6C 7"%iKnM^T!r>\:wmU:]f,3TD$N)AVԈ(vTN >:+k+ Re{r`qqp6(p!5~/im˶WfPehZ |SG3L^@Rx5'f~ +f_ c`(4Z,ZZl%c=x4F^f<p"U9!%=-c Fr%8ղ y^uLvK> w_8LA.#~55}ilPP!d>:vȹ&NfP6 oD3bVA0MM+Cʯ=4D&/mH(ʷa44p^ˁjܴQ\Vv3*iHGf\yf''Iۿ*~dj;pN~`g'͵,j*2FLrPu̐qAXyQ=o ?R. <):׆"/S~1@6Vi<ӎ~S xA2 SBr;?%`+' -ޤv{ K=WuڪYTNHQ:J@:S2AL:Tԉ}K.6 Wf[>OΗE?orw],0zDeQî,%Xn> +wVj ɞ}S6o2'k2lC?nbDn@dYY7- (N{`Zpb1T4Hcg)R2 bXfvmS_ؾI"1Sl#vs}lMbbe;̃P'NM]XzusVB7i>`+?Ồg9J -:zR-w\jAlUhG-1  $538bVMW( N9i^wYB .!w|(iK C]\4\ ڴާW ]W#(@p"Po:Ծφuӄ5YS3|^n~}j@Jec.C}U ڠP!hz1e"ydL[dc)J3z+ D`̞UF #\8"SZWNpK'X&@lԯdB x"Fv:`M*vj>|䁊B2s>xLGo06ZolމG跸'i|7!EB dgД!LuA_6=S%nmPRy6KH5Z9m?>2Jz 3ь6,ujDvl$OX`ٗdŝ"_Է3?fQ1990 7ݮlUˉ>к^my.^wJUp B 9ɚN *ƌ b wn-#BOAW!ɿΞz &Y0(EYJOД=B9 S bR  H oQMyiIpI,L*>1o=A|/L?r$ߨ\\ 4qVX{BFe|B`[}2A!?RahOmFFK!T"nTI#caˬjf.뀭Ѥ2uӈ48d7C4Ywe-ݛ</)~1I ASZra*[/bowY +ĊĂHTIMx/(.w\1KKĕ?Lq3U1씐ƭĨ4Ӻ]y.|HVJ@`8#|U#&QZ W_b̓ !k}gt>a"NnBsjV1a蔇/R0cc1RGuGOl@R'D؝#讷zږQՅ\,v)wIfdS< :ϛo5Z;'WH7JMX=iH[\.}w=flI~wE.aPK|fϬ,Y Z7թ#X)ÊF$q[A%P2 N,'p颔:P5oۭ+ރ%.` WwSIa)3ah+'s`z[R3dΤD5C}8seUqY<5S`0gDPBoq铭!6̾tr |fm_9_j[0rrf;s$WlE+Ivmi*:RW1W]/zK 8=u 7u2S(MB9-IUZJNѠw%/I/g?^id͹\)Tv:td]'R0)'f p2scloG؄r@EPW{J09 2q2=lIJ-܃;nƎAVa= ԇG C9Mnc؉s,=uUz#B=0u=iW n_Zo|M+f7C$\pؿ=;תh{99 8Ƥk묖&=,:d8//񝾗R 8(9Ϥv kqYuՂyNr-Z\ZX ju;)o.k-&@ _Su+ S45}=pIALm<~~> cK{KMVN5PGѴ !Za.'p/ǮTBaEο258csYB@i*Z ⪒~*ƍBxm-]^XŴWb~Ge z$JbJKM+h'{#\Ly$0hQ;nx:qӯxLVd!;t 0Y]}D>Gj{By*yh4q-9XHױeB]A.,*M} +JHD6V.0M$0qiәYAf clFܚU*&ŬF}~T|n}(3ص^N<}]xslj D\-k}F۬N1%pv 60Ȑ)QvШNJG. b,V:|5 ?:tY&vЮEYxowL‶dY'ٻSĸ- iA[F7}+FPkvtxͺ4rJ~#hB!!9ŵZ}8^]3<'@cǤ" \rf S>vjb_kSJRlKNX19~ 8_},rdzЙW$y㜏R'-RāNTpC") Vo2&fv_ g60pwJ8n")}BS8GUټޑ2PaPJ7ɬ&a!~ 5tH@МipWdSBQB=ڽͶ]]ǹOB;d q\y尼^7<"y AЅ74?#&)E xU̱\>|Hgmk2>+FURI_(SM wQhQgs=y,6v[`Y/.6&\vN,d.o7grç ){Brg݄ t~fnL!rY n:Mq }1,O$*H!*<6V}';Mv  n~ٸ )ylBwiufyylĈzlGvJ?+хUuJy"u uOG}|y]kn6eDʯ˅جfWE?JW /%bi" T?F^EK!Gg$eжŻߵ}DR·_/bI!nwA@i W5.r&E~zr+]ph⼛=̻TqyTed_CԼu}C&. sڤu%{,yö+|bk NtR3v>؝UڬǨSڡ&t׶d&z+MTT'mM ]3Oj`_%7Zv-zIlh:P]HaU]V]EK3-+U=OWR]rq׵ǐe!P:11[I44>xĿ_q0&X=>qhR"N#-ƉC^~F':{<f <""Z~%(qpHC؇-Ǧjf?G-V)!<=<ΰ laӠK7}oDvyB|cـ: 0+Oz>>A" \i,`)#In>ڳŇA!^:Uex[ahecc@5%p/cܔ1@vΑi[){fF~FWV= ԟ ՈDt];:J'n@Da*hyj{ٞ5w]1+#12 #=̞r鴮r{ںloߋ020Ѻ֚\]0G=74TUu-JCA[';, "n=uP#,2uUe>ڊ؆sGEޫ/-QeS_aߛ,<Ň+URU]ExV-2{< aS~KmpPt{B3v/}dԏ@l%]$` !yp#/"{[k 2 ŨG`+Ǔ zEc5>¡>TU"tDW ׮ l(iOkz&q .4vgygV A+78̙֓!zx'kf?L߄Γk /Ѝ3\y<ԙbMq(M|>_8nx b"v~"H -?4>wd?G/PoxavA[y_'z>jǽ{i̓  OmܓAjAC_0^n-NU2~XѠOTcCP³ $oR PS"*'r-6+mcl[o3o]H23=@9 A>p[SCR(J窭L5"]6R'Z6B}C'Hԉ/G\ E7&0Z | KMzHyUu C8R$B;b+,HD)?]AiMAc8 G*!`BzqdBĜbPQ۹j^-C( XfҐHÌƅK A.鵍4fW>@ioCRYՑ|Bb %a}˞&,އ%BήlEګES4 s ~OTE'2E>lq`E=Ct_LFÍ4Lxkȴ,I!eS1_Ye8*1SvR;~{ bNkVsmHsKN|u3HSvpyr}ӹsV NieH<@8 S~,&2LlmK D鰊p l,~hM`uT`)GGfdW1{!x,wc.WlǴ0ӽoL?dƸ@cD`*apqmS E8K)yּ*9}Z=l:/\SaBf.-!S'%),#?ߋsvk̠n j Z%!'ZU ŭE]\Q^u*c ʥV- ) މ!~K49?k+juNa %;^HrnD{R`{&U Kh"R,7ײuه̏x;ϰk!v$][YVsO$)ָݪT9 =oՓPcqOwjZRPG*eF9x\po1_NPT׃1X14%IAHcm8E[w~!|5$Ll]ۏ\1r)< ,Jm"<\awWu3L V*b7Z;Cfb!Ux3 Iw)[XԃkwT8|Q B:>=I%w3\t_Q'-鏠m& ߼.^OPzb˵6[-Dz;6NjwRg}gmDYt' nOwn|-vq*[_ʔw_Y`܃6rIP|d!z1  `L%X O'4@A) n׫/pi' 1rE4u+}vs24xʝ<nwy}DNG@$DCؕR:u9:rWUHJzm?'qx=D7h&sTwj-`ߊ^Mh.y~sNA#P,*tG;Z!hUmj\)7/ qNZDp#d<ZAQ0?[> JNxI7 ě=P ab,yqc|p"n,9gWJ}W^ 5}b`vSq&Н:N+l]]=҉qbQ- YԲѽ_[yPϛhLúźLsS6_P ~U(Oi!D}.8z$IQYARAJ93Fӣ}ߺ$ByךpgYU#}>_؛&bO !l`SƗ!FK6MK2B7&G=??`tʦ@&EIV逸%N09 3e8V ohV by)l[2['LzWeFؗd7ap b1\**&p9%0yB՗-`yqot_3\?8*9aĎ7N%6kDP'WŐI*) DA-grXA/|l~10k%b˖ĐidOi*P[;b .T[jK?.ìm02?ޤ=#E&=??o\c͋Oڐ/kQT#}n%|yqo |8yMU%.!aJcɋ7+d}B9p|?;`(0e 0b-Cd$+ѝ;LT{[Z(Yѻ #ƿlP=\:޶w1\q1s5RnYcaw;e/W ^^>h#,<ؙpBK҈c'xO f}/ ,yjrWfy1*̓aAYb%z?Tt2MF啐tK;Y;AFu]h:sJ%c.CV<騆,l4򰣭F7_\[.}2V緖$%Rva`SLM_;"%j: e.Hn)TRI,:׃P1$Z|B(o.]o ]VSB٦|F\X5|S;msZ'|a;l/zS)Mm m\bk[T $w|XD/=vJe [uHǍfz֊hޗ5Kn߫/*,',v:*#o1ICAS0Tsh]F @|a\.Ƴ0E659E% Qs\ZXbTtJ oA MǼζS^08,emQ y=s:3ߧl(OpOA;2dcw5Bi,O{̧fG(wqZurBnDxXLۼ%kj}6(T&$ pn -G^Me3$BtFsq-!xJ!rfg'G 218p6D "/_dE%i4 hهILnoKU4 Bjm[5 \uy_JA8=z1]xkq= ܽ/╼%_b:3߬ߝeZȲF]`ơfn/_"=0,TfkwwM!Mz[k1t )i6@UI-SF/72 : )(PD14AѮU#Is!!͵/D78p?~x-{&O JW/ c5_pg_iR# +- Ӟ { ӳ׊Sd3Ge/EPX5%]Nɾ!M'eɫer}̠*P8ɜ$R^nT~{UbmbUϘd)v^*qHK|w@BDZ Ѳ]8P> X3y% y+az=1 DGn#۹eu٬<LAPGPGjd#4 ,0H$(|nŊɪ;f ]u} ¯& `]3&sΗ+ |{u2z9J<{ ^gGUndC?g.93F'(i15JU>Cl^k=(y !|V}_8r;ZGpՠ z9  =h3TWıOl#EAy:]g\#,U rDԂl(TXu~bg]O%'_BC|~\ Mokp/em:N;h(_t Xѭb?9f⾱'L 9;B/*}i.xA+oo}w j6a.EKgv!ox0eA£5= @aQ1c]s#rK!xwvyV׌2}T]gȣ S&Hv~޾mX!}Lu@) MfnWy3\fѼJH$)g,>lM"K"hZ<]V5gRQA l-TOsILq%c^'yط3T9* ?2phLT7 k! &c؜ngܰfʾ,eUl?ǎ+8gbn <#~*NQjU54lx:.2Uĸd|b] [CsqN{_l\Y0v8jT%n=mUiə.%7#`YZ xFv '_(д  &Nͦkܯr ȨtFgoꙈ Fn;X$*)rG'?MtH/(çQϜ;NR]ےB~"AB$;nP3s,[W:'TFfVؼ2Qr?z(# ٌ{e㹐2pT5):Br2P坂tϦrstiy1^D{|HW  U&x]*sF \x#/`=Y~b+sNԓbK*fW +ܶ⡀ām}C"J;s'E"mԆKJG F@fT%7|',{@qzgw> ~'r;9TlSqF L ^3pb˗3zߘ!#V𭦍+=+_BÊ,l dr9Ź8BI3{`kd Bn蚗`PKQ- ^|ykLkq71E2v]s!Q| ѱ11pM;yYuZ73nnM:Ql:ԌԷa0{As +B vHWgm'nd߾leGP?J.?˖$>Ya5t^b9O~TZуQlىb6@0i󎮿f><>|>$93پ,~Vm77E 3CNi[wԗ[Wod$c!WgD$G! Ҁ"( 5JE,6cRpҜ"qVpKÚa^]?%wq!,P^%-6p%Yց{xpi>,-+ dN)}zA}EuQ"5ݾHuEYZ zw5"H̐晞EZfw*gp ĥg۳~i<7+#|FNL{ÉC`dfMgu莢g>Ob5$m#"e$A|J.ik87JxEl+~"~[zn@ζ^aWz ICv[<)Fm;0N|߸opM.+kY=;[x[W~w{N9Zcfi)q(FxS I :xx6Q ur"\xqDR8BL %]7Ro;:k զ[<椳D|@XOQo+pJwGpj=tV~"N0ay3Ѧ*6w ;7ʺ?wd=͊~/AͰ5|;a|o׫(]KuGQEBUʒPcBi1=3刔)',|{6Jh k|~%GeˊW |") y P[g 6X7).2A9!SiҌhEk)do"ոZfy> ^_-W(1~2z)0Ik_;%u-}}g-- >kF'vʁ%tbGj`lezrQ=yq$DEMrSBƔs W҇l]d?^1,al@3k\9Y{N1kwlsDfN&JLǭ?!SS4BCAn0ϢvJdgBE测B0؎1#U2~*=,o$D$iދ]J[$TFyEa/lÿ钴tg/v$/WѦX`%әxli3qZ틄GjE;KkB/M3~3O4Mlq*Rކ!ȡtڍ\ ] \_,Z8Y{kߗ_qYu HkF[^`/dUr0q(&qT@@h&3XxUb}TH>ֻ4=?\,Y9'wiF}5ǥ_X),mDڻQS`9\YWB<%D :Bw8_XBEN;؊Fہs>Znto!_rts-DlC aY =UdMP6<]^-CPR,uJ3ʰpS{̯X4 :Yi~Zf^] .<3:g%`2w_@^dh@Kl/GRfbM n*!fJsL(R q*;0hr鰗 `C! sr8v6Y[@ޘdƝSQ:yy%nTt B$Ix,ge]zݶO ϣB#: o%--*DG" h+u`ν -j jbS#Vue[>153>Pb  DWB*W7F@}N` kBGNJ$dXGYdV[M3드;K)s:e4}5oyXԨs~`4>#bmb ̅7A]%~%bruxd+},?@2y|u:"LR\I'6;ɞBvwj3| ZdZ0-)wɠmYԊSK(cZ/Y~BZƼL ŗƁ퐰;֪`{1Hi/@N[x̆/)$`'PA4T='>fm$R@Q_tHs>Qr{7;K!pu8SM:MKJѳH+,&KSHk2")( BcQh'jbqu$*GEx ꣫Y(G3 ~QT`B]cP'4od@aks'6SW_* \b5QV /Ȕ^[Z&;k\C!aypɌ̐}+`.MQG1g뎪J@EofeꏞjV{٫+G3oO"?#j}KV%̮ Zlt $48T+zu7=ˎҬ|B8/BE'4Iz~yvlV*vL 1_h JPEUtDM.JK5: *o~LG@[YmeUEXr~Bׇ'H4wu"5SI4:#* ֑"~Q d7PDo.lDK`L՚`qO`dg3 yغ164g& *;՟BXLlS_ WsG,];ͬƶF2c֪Sի +5o.'=kō*'6Ե[Fl>$Xl)hGy1Ӣ+J%3//[ ts [&\WiM96!{VYu kҺ#On+_)qFߕ 0-_O2{hWkUƒ5yšO)R;3 ;, [ ge3rJsZs%!*ӷPBbJPH”c;8jW @UʳN 5i m0 /Kyr*A+Hw:X/ҸWU [~c M xflZWֿ>++.g&b>Ѥ`"z[K^rPR?S1sc pP^@o4W˅H/vOr0(r'< BP GeJdɩ%wjgYrթ.bŨ>=^rd'_ g0nHk&J^$xNhR*q['aBpYT~䨀t·Yh*Mg#rrdak7,fALSh;u\B;JYC]KÆXF#L-rí<;f)U"xr,n4F֮ #_ o"DɔBx- 1bpQsӎ!$͂evR[7^H}̻K&D(UDͼ㒹 W)u1&Ժ` 4a w~~TVTU-Hmɢɍ 胐 -ѧY(}.7Ams5jԟcY)Ӫ.r`11ו*= qD?0D+^jtP!XZGXG2zZGʞ[,2쁧,m7k)JRdLq -#ѕ)Џ_vpvѾ4q!Lu%D2%vW&sF=6fJ ƥ~>eB %"F/aش 7DC x>rЮZcW YȒsø)g &y {Ҕ`|B W[GV_UMsv&+1\[Z)&UUoK,~Gf8&=`G\`_'bm׆X4Ў XPhh5<7htRf|CK^U[{vɾV+MkB>5J$s6+iŦ@V a?\wxȵdKZ;J<2fVk =g*-4ڂk<=R8U). ,{{(]zn ˂ZxRw  %È {p:cxBz[4q9t #;{q֧hڼa LMp:S [_'4YDR1rC!mOxՄje  ܷ@;YIh.ɽiU˓B% LsU98m&L3 >LRs8b8ypEy{2̐vfoYjUDJy)e>/>~OH$czxUju*;}$XrB?@B9 \io[KR $Xgxyx"kMEaBxpYy=U]aE`4Fl5*iz[i7GS;ﷴos<ex~1l7gSBK+u Lp@ zʖ }8A̟jX*ޟ˨#hU3\׳+3hpZӰXQ&3;͋c-ѝݷgM;Q o3ݶ/t1 !Agp\n[q%YPމFxX6ccfoYJT(ᔺrz>V%>^"|DhI= LluU֢TDNUNgһQȖ?U4S~jT?{:0% *[(؈ ^nTs$ Rcs-qIn>Χ+|54reU)3!84❮'a9 Y͑(3!EaeT!Cm@^n8P(ݭ8;nߴxyǜ땔6)X,LCF1Z_ |(&OOwD&ZT5?ws\~SS8N2 Pwk =@,!+QsEp,VESmuQtׇlk}@Rԍp~C*k;tt/CcZkSO]̽-^APr)xxUAݥӵy+V8+``+$o}o_;f3O޵UC;I4JYt(2]*llS|" RrWJnҜwYr\8\N@*$_#ƾ_&A$gt"SpMI@,mԸZod]brz^s =Z0]n 1'lԍ"jqsj(*̠Lnm)4^nd:o2~ Hݦ`xĎce&{ i6fѿ\9"p#3UPϙ_O5_-zӴ5Lʙs?ƫܔ<° 5I `=..FHqi2mh zwU @m'4QeQdD=CɃFصdk6?U-ω*tz4vfU %J" wA-o" z#p M=y 0(֗%Bm4ěev$Q$hp]z 8yPFIr(KHޅ-oOlJ* P+3pKiH~.9ND۔!?dgRV9^k܋>T$ , &/JZۺ& }bgBJB@^n|VZ,1Nbw"Pz j{jvAU>P.d4|܃|뵦s ~r5tLwNO4qDMD<̄ń#&7W4̥bױTƍBj)?DG=:<A~[N|^6!2 W߬~v Ҿ|ޭWՙ߆5r}Սgrfq5(x w1T ыBHĠ~Acz+3a-<m*=CvҚ$dKؘ Y=t)o_EuSIݻ:DIR׊/p[Xl^#GvP04GMLW u<~JSeH+jleN騪qS=q7 Yx~?LR,|PylKv{;DkH*!mA2oC:nUG{; [#g7+=f3D |~ȐcTX=N'-k31*Y ӱȄi"Ia&WSg?~.C1Ht9T`GL%x>`))[{)poERspa^N+:#]HR[Dq-dh1*&/旔4~m \2tgo#b߸eЍeLcH4YiSx0p/#M5\&~WYL8"zK؆BaG*ȵ\H!v)zĖWb.Z[9w?ʴ(O6}MW|d_']g| WP#u/e81Q0 1L 9QBu {l\YwF# OEVH jпrb,I8f Kéj$PXq!^Ξ+ƞu }RiQVS8dYSZ(\>t꬏tv\ gpȰKiu+Ad0N+I^ϤR BND"$oD(20SܟaZ|bB5[2% "ELs omQSqPJ*HbT34[GM6>EdP%)GJSN'9.I"d4Sc 'HڋITFM$T4=W~NR>Nh0a(fRLԙg_iM&P=?4ESJvnu.LՉ)"+YT*~mOn*ZqRH(FXR墐qu_'PB$K49"1q6XqHⰲuZ(UNB彎P3z6p *K ^pj#E%,3| ,H3jmcOeEZ &C /u޷8xвK^[ѭSj=R Bi7@ycQq'p{P&ZRK Y\Poҁ;ˊ̿<)WK&iʛP!v136Ѳ 4p^)j b3ҁ$1:)>ez+@+|dHB־ "s-/ ?'+u73WBGp|]{(lFgۛHZW le"jL'Qnqmu[;{XPSғJĭ9jmLQЕRSV 5b7r|nn4zx=8g:Rض_m]BZ" w9<D+XKđO@DZ7q6U鈪#p)Ut  ދ:x, (,PmUa4sRugITZOR=!"CSZo[KL,W]\zEJv;ԅNvˋ0HO z)Ss@Fc+"4uq+T (ac d(yz25K$#;S|u4ǻ𨷗ovxxWυ-9=ixךsX0l fIJM ~Y4 _XBtS*lVNsv7CUmYaS R%9ow$DžZQwd鵵&q1u]urJq4j9v.t#F[0rMɪ8G@Rڞ: VZ͔| ԋqh0hh2myק^Gvzo '?|*rȒj077c~Rv+lJ#N|]J,{mx @<G`&j~.%#WZʐ5YS̊nS'Ct-_=k09 zJ`bW}Dgka(u6߳pW#[Q ,`1SCfl׎ &!8FɤO?̶Y>$-;@]{yدC<.+PQԶHv߽BO!=?1@Es{3'K ROYUv A%c;ڊf_X~NIYn41.֗"+3r?_sTn<;VQ");y){(!mK Q#H+E͗T;aK0la@G 2sN9sHNS-2T$ yvl?KX̘|#Y)7 i Ivޱ~~/s$x']N〾/z !7U^`ɬA0u Sd^aS'l6њTo9"ylMךI է."?Vfzڰ^cAdzkJzAN|/OkPws(QgɱE,βG ]EFKqe!}X` `!2.žW_Y<91P! k{1ӛ:;EV$#_K 5wA%}*4\?_@>ȹI&E'*g]3W24< QW>'pGJvͬZHIE]y E^<9}1;h@ڥTb -%[1K.U]jz}%Oa"Fbs]T^Mrs >g.kih3 5dJSfOCQ GMS8!Dh 1Jn$3 ^Mov#԰zȡBǗn\2%O шd?^G KU 6KJYhFDlj"µJJ)ƁƁv2-AoWÆ9,ЃN[ˬ1{h XFH!x)]q+w|MkK_WݲސxRߓh W)W+E`BXUht3.ɀjִ>{SGq8 ZaRgb*un1#dԮ ٶ6&qJFM!ǹ۷bm\2\]T @>P:wJncKVGuS6:A ^OCg3S*b~|=cζM!0V\aB7cl6O!hsl?u[]hG 'J_3nJ 68F48|㵧\m+)W ,t L]?T?8_Wh!MqQ!ﻜN,F2OZFFOrP}qXĝd/oBlĜKBU.AC c^^#=۞Wm~G):밥*Bg,\>9坒$XrmáV}w)7m}-ƊJQ~)%P  {ښ8i&^{@;mƋau >M|3;f ^C4& 2'J>l=#Rm8sn0Yuq%ۂ,7ߏ kSe TeB56^hGi+0<*X&-S:f?1{8UmSc]pnuGl2U3@-ɐ'F!vPxeUd\+i)Dӂf :ZQ^iF>᠝{ca_^_4/Z"FN? 껂_Quyu9/ϗ9GUfbeު߻sWqnc oH::MJdU8Vy$J7 ´/bMdɧȌN-&},Vڶ*tS9,>h8\J ^Vȼ㶆}2*; ?7CX8z6\_'nGWD%wR\ yQʢ2{hJS n @tk[r7-wM Ly$d6Op67(IkFygF]t.ULez)qLcɫ#G^ѮVz) ꖼɫpP~NC?qhBpB7@mL#%_ed%6PN@uqт4V}4N,W-nJFmbfՕ r5ޮ%ƹS W [` 鶝뱚"pOF4.h˂"I !jL>+Yoʲ=^knu6ꯐgx|3gK^*tcJ<;ڭ1]җ\$#uhfFb~,%!3"t'tLաR_3iݸ1߽"Y$EPڥCM)sܜOY&=ުi{/nxW+6| Z4 d|ueE*4 27ٲSaDM:hv+ ?͑:#?T9*V,amZK]uG  KNکK_p*8j|?T/L?}FPi<ѯ5=qh`A4c8g# . +G$-r7ƹN}]1T1,6_h &}dga>T()A{! -4TVK ҀYdA/[QΙmnp 8"~ZЯ{;g0+$R:px-] =V_*U؈3Ev-R=WBvjTBgvuxD8Sl I ~mbI WKT;d;A\RY~Yh_+]S.JoPG5Sil5 p03>ll /[<8 8̡KGu^ן8!gzp Os!j݆n'>-ی nEWK(DR<;CEi2_z.2RAaRJoM늛pAV_W"? 3޶ *Yod0~ٶC*״6PKI,"EʟqiwG.XJ^+b5'۠tǀ'c{iSV GJrצbsd=:mذ}ߗYv^Xio1S2@^\JL&mAjo@ T[I`9*[SXgWrFČc/{n3`P_eo*t:g5٫K Pݴ^l׼Uf6vtg0;v MthDxDw0;\c0&Ue7^/ x }IOU\Mۗ?`ih6j!䋸>l= t;?{UeR|N,O\' @/ !=1ȇvV!=ƥC|TP_Gl`g+wNj\ 33Xb!V'@kJúcc)hA'HK<)RR|[*GN7k"i;TQǮ7Z岰L$0Z@Hs@jG"Q.-( g1 gKF!}iܧ6JjL0ϧ Psi[p5 q]fᇳ̈́>Y5Q9rb {AM(xT 1z(/.qxYD`͇7ӻ[ datQA WeH$#fz%?(|=v5,Ih!|Bt[g6R_aʹ E0fWYʦMWRl~9޹Kcoj\"sO"VW{n7~:c[=#Mҧ/KEn4} 2؛ @j8j )'|U~kvne|eZ=,AzEj{r1# r6#l)(.WJ<00%;LI D fB3 E]Flծ2]`sHD$i+ 3Hř$5B~QN}f;>hPFjV=A5s9#ҵ6glOR;c'6Gse8xf%VM;\`V oIr_)Q~3{'۾_ۣ&Tv+E}Fn9myLbClh_+ŷ4Q~LvACDWLHz]L7yK7=ͦqU"WK^pVMϖ@tq]T$bfTC t_Bt$C. ^KVm3U5f|"9EBЈq jt8~,w&iO̺PR&rփIxWیX(E\w}GNM~Ј@-w@-o8$z#{C6xdXk-]keM78z@0o|ѵ ǧ{.mҐ-])}[IoB4(3 Iq 2=B֮|{Dx__r~]3P!O/Wr!iq][upӯ@ŀIiH :bX,A[,?9.QN=ioݣIXM>a~a\[ĭ).7dl:eET_(;|<)^Uj 3 '5R4c<д4BB-#mM0܎!Y$鼏F:dP*O:5$۲B!)(Fu|xROx21jnq?Y9Dq%W{pS ;ܓueJ8YxKçő&Puez5&ȌqexR_AVȶ$9bFa]̅](Q$Q-sd l=[T,Tf:/,L)/bבP՘^Ff-p@*fdz<>XЀm\R!ZR(5!31ߚ[9{4{RېJ˳@A۽sn{'(\I8|ʓcŬwWy#k׹.]`ji֪I!W J !?+6n:6ߪO4VIy%K'3 zp$oY[xT֣F!C. s~{]R*5 wAl"t9,,~ Nnljm.Mh=of-~3aS.9ўi/86-ɠH* L BaK(zp8nfu(U~i*Z- f@Y(R[DT'5b]|;R7ƪ(щ0rU*_OaM! 䐗Rňq>Ž=Hxt61Љc Sع,J$ei$@$<ݫ;gZ Q˕2CmAddA-gMŦl%4vh 荺ꂣU񅮎5`A . f=y&%$A/G>,}vn#GM=4lqi":ݘeDZU Fzrjin⮝Ĕ1O=?1pP,;x6E6fQ}6[;grIѴA2͸"[c,. mX^t"]SJN_}Kfd8bMpp [<-ȊInlhHJ%} k^v4惺 Y\%G2pBb40x:VB|KW*TZv+½W ڇOƶ-jKHoDl<>ܻ92,$sSG@ rÇCwyq .{ie!R1lRN7LtKBDt.L߉S6pR9Th𵋹B#xbȐq3zJHk㼻Rqeg\x~ϕ?,9ޭ mZJgRnx^L5Qj P/VX]lֳs IAp~ϷqT;DUF1\Y $QkUE\(G$߱,33Sȱ[\ͿSUҲK9"L~^{"2z4 q-%A[yZi0Vex1PY)ckye$'{[Jlӻo ܃Xo01>6n]X*cЫ7q6/"*C-\ȪvoSeч|:1npl)1G'T ߞCA.VI:-a~GD:uSPҵ.|*xvQ܉nMe lF̢g\f.#Gߍ8$ Џԋ:!&NM6|Td=T13WNM4<,ā&?A3Rj 6KSZqҊl8TÔB/\e[(EV}I66\K>p)[R Ed6k[E:v}!i[g wղp €&$E*@hH Pƌ+ ,֝cUgaxY`]e?Yn" +v%qx%UmV\ѱ#J{5VMɜ}'L?G9X7PsȖ {R0:g?v,LU/%4 >\n`K/Bi6s^ulyd\rhm #@\ei4n"A+85\wN31`6KL>pUBSزY pvM3;2xҟ]?Ĩ1(uJ:^ GƭzQ [ ?UXED5(1]ru QՃnQ~p]ՍBm%cB""GOޮwXaP̋fk޽19Zi\XId b77 G&5%OuhF?k,iIQ#NezU$%-vitWLU G EP!D Itn69 {1ՌY^7)_`A^^Bu28 fkB(MS Jhˊd&/!")w̍e87΍tv`̲ `3e#B%ZylϨ1>y*c 4&H9g>&\pݥ$ᄋ]wKtWd;Xw|;K(EoFR<YCopwrR=Ui5kf*;y3 (p?uœ 9lE&ak!`VlЂo/,u c_g?C 1( rr]B8nh_`khթU "h[reKpL e?[ sW,0H%fJ󴵠 <{eK2$,uZDu5@_(km1]5 ox}FQ$6E =bI hI^E w~م|_y) V:V[qyU[[s=R"9Brȭw-?k#1<|cr!T4޼}hdK̟{yTN kAj 4*(㫄|u6@0Ijם?bok<ērԭ8{" ٤:@=6V|Rr{\Yz2 <8%qB}h%)wc l$/,g@) %1([t1Ğu ϒaWd֢; e'| OnjNpDr׭>6䵸o K™f7E]{Br2Ni>IeLB :foe7NSTB&ۗ`/aa|/CUXaU3&): p !TX 9T 7sԺuPY}?]>YPXhT#Ps͈0*Ĕ ҒH2D|؊i58 Yg>"}E~]ĉ Ivr}]}5:nԾ&T/ǂI/u4*wvs N$" O,WyEK=]V ^ A:v6;Wu%vdOlq'S|ӗ:J7SN~PxcWk8ydѣ}8t fGBEK1BVxqr8K *aAzQjG.zޘPK }UPR'xg8yUzKFЄ{rD`'.)>6#9Ur)5fPt᭸nx~^. q ")zBytsEgC/dݤx=5U{;0ȯeN$ڏgg$H J:Sx(hJ*0tf%KN-&XU) 8IT331mm<'H,aO{AꕼPQ_`5pŵWм쀑TJTyvLNrSXrt R~3PK]M1{K/ꑊc.ULw-pZCdth/]u }!0f_fUmH[ߘbuҼ~3:Dڅ9^k%oI  U޵6yKӴdS|nhrA >|a^ze_ώ. [jҭ <☘T$쳼Zi8ݟ~|#0kIK߶-v/]$60m_kK +K^481ٵD [;8 6=΄t(t~*˯XT{Ae"Ɨhi OĮ 7y}$d]2hKOXc{?Z;@A0Њ,GC Sk,~_ ٜ?z6Ϲ3 az?Lv9q qU skįpr=:i"|4sŸxٴEH!KPp28,8fҗ?ZBҕD^)sjSr<]K`_ NNb9~R}itav wGJct'_ slK_$ȟs,L.%NT zww]/i@yb𥅴G~6fT0V8 򥰸wK%xsa8#]-t3Њ8V.y"-ILdh%~ < K'Qv"q,Pv1x#AUVE!ӵ6FjeYS)3'#p~s14+]Y؁k`/s,M&&yƽ ,f :~?|͋pa*.pFyS{X L*\Y$YPiPGRQ/dBS < *_9(kU:H5 M5*Lxv%D.ѡ#m)Ik4{kBÕrthu1D;*@Ȏ [9y^ P=, OEV^$`Dw1E}^}ݺE夀hlWJ`jnG5;USxG%`P4S(x5o,:t׷ߎ[}6 1ʰuc c+ фը @TcvNl&cK&GEiFqJvxzPښ Zjl'Gf%f`3Gg}(6>A{INr 6:]+rhB5 h#sbeH訫:"vaNyװⳭc63~fl8EfY\#>^%40J4~ekC)/ J*nG,O6Tʉ[ɉy;xXKS^٩y`ʺfPZ'_vWm~6LТR+g˨glc0ROz&]`>fW~pQQL<2,d[R<ْGG{t#\QWt,#'bK 7|+ r?|h?g͡sw'oil+}J*ŃWaZ8Av8j5Yv”]"۶L9ֻY;~~EjYS=KڝgcPYqS P&tL bR &&wMU7gO@u.E,UBؠiUT=#z?GIEۭ2*l~TBhȈx v Rh4ܖ 8Eu%hHVg92 c `\݇O/+A3 q2yxVSZⴂ*!LSq1 f@]6 nQIo;/_f/!qn݀N'n7:hegq0T׺ X @i؎Vq(mw8"tv&X >(jn^yVtG~Rn5VmxW6N#ƶ:F_IȄpxxҢKM+ιA7'}i=P6bFR&ڥ(K@aܰjI]ԞپăiL?أԒ5tFœPCS!~Q˔əi70Єb?Ta91c `SXꯆ5$W2Ύl3K7-dQO-+!z-E/qS-I#,i(@0pgϗ; ?Tei/bcuY2U6塅QFvUZ#MgxDw*f#{E Pl׫;j`P0^\Q50ftv;]=P \tQ7 F0#TVAc=6 RL\qB] tLB&`A9:,6ܡ.EMčsL᢬ EU;LXj !$Ex0q k24Z%J;[iqd䘢6b˗oq[x[mZF0`M59lGe&So $X\HĠ& u)aCs,+[pΈzv1$ϸq#`8K6Zru`ø6ta L/HU?8kCרߗH²uH#D1$)3i"*?I߾ x(.bnXa{ = yr5}I`Cd8#aN}mUO-BRm ԧ1Vs&I.nϩi Df|jK TR%Oۚoo*v(w e?x{}>hWwf*z2ƨh!  _Wuƌj6(cy:dUL|OvJҧ x%]tZWBcTp(~9KZ7ZA`N&ߧ2kGk5ṛk#%']'1]P.4J( #q N4S m6x{ڡ}Y<8\SQj)S2>=s\4n%[|_gw7:w@2Y*mhoFͿ-שׁfEWHI||ޱF 1-[Йo –˖}TVkٞj"1IJ3/?ۙƁ6' зw:,G1{[]J*-3B N* +z!ý !uyˈ>qߍ43r7s-+ѷؕ/X{5ʄ~*_xM.O×,r SVd u dq\]ìa#( En ~4RE앤T otMPPLT%qy=[U Vnk:L$֋.23GҺT8<(i)Cb3%'y;TȈC'+$6.RXaY wNӟR_P*#AiٸF+޾̤[}aۏt{_*}S̾cPP=A~Hv0x;BHdYXy|cv57pvD+b^]"7Avmׁ: g]B1xeT~S5O>z-efnx j~?a ݋F2|b•8' u~K}13|jP9 ވ+4w}z%g fo%1;e}X_υT~>PNS s @>Qpo9bT!E>RIxphIuCm'd0MyzAԖ7nX8h3:Lؔmi 9FA 7UkNjO8\N(zW B+R_rVOPWk@&$O(]2)DH2R h"k}zBIUy% 2w+9Zj='GzA9`K)x"ⷢ\ck-4] i k7=}êtVN5ƿ& @ ,g\@t Sv9 5 Wӈjm ˙/r᭢3mx Xfo%.AQlTcm.sډQU4یQwңH]9EǻrȄN>)v:^ѱ GQ.跑^fp~ Xa\ y*s]o(мt4/^t`@ PHe7L1N.$@2s?-"mOP[Be3WNM ~ @5Uo:A!Tw]Y}D6hX&udEIa|jTl-&БqBƂjK%n"c8y!(\ؔ,R63!"\q DwS[mFjm~b6e]iov8c3^wk5(͎kx7l -\ʀfU%:UyJݔ cL`T* {Wds*Y 2#/8{[Xո -2fwo|HGfBÿS"k~$~K=WE6ޏ%+ f xmnALJUAa7O|n,|fϑGGǔhtO  AX\ x7lDZ>0~1NStb/ ybr_bٺ-dF) pèr`L8WP(ɇՀ̹~H’-F8BĚ!SɔkHUhe27$3Ȯs}JxJé*9տb? _©^M%wWr,ɶ=zM=K?gھ{Wd-Q&Mt۹"tO-gBLI5ZcߐZ,3Cilaphe]ќK3d "p5xmf(D&!2SV}6cG浪0lv:9[. (cY& Hn'{:o.}??EOZ/2Jv2 f20=FގXqo,)Bxcrmcy"9GtOyu{ Yܯ~'JiO])fpu!o@Lh)&W![u"ۜ(m9 7jDp5#o{J@{ʾHk0[):ݥ14쟟jNu .y&LZiX:)-Vr9$W(NlK^s[q8~ 3 ݹ$ڕY[st544x_{n*~35ܡ_Bg?9}TsN;s%׾VB_x,4e.a˅yф' BoJq;*ݕ)Íێ> 92j7H~dc>^n1 :8=*u&(^#(c}"ЯٯՐqǔ [pIݿb< ؿ~W=,?hꀖ;8Q'=\;tR$6G`d.?B)@I3 ,FHqsH#`95jf0N.v"`ƯW!Np8,bp^Vn 1)vTEW?DgٷY'3;mF_~+qY)MSgٷ.%! 79\ϕ5: `P<8hس'kzsބƶgߡs,L*Vv&! ˮg*iv@n].TaagY*lNލJ)ׄҲgi8}]||ʝ@'~Vv $ꄘѼSv{ )p>x׽堦kQOqn+Tq/ !"7) P|zeDAϫ). kA<XiD8s&׍lA/VLEPtEI3-혦'Qgl:ڃǪEH1R߬2{=Gsiln+?1bs,Y/8t]{;;m MpXMO7d+$Yk~J2`g5HK#+F'J_,1 EԸg`Y#u@WͿS5_Ib4\ؠuGM赬 ]F?BFu(88ֵ :xGI dGh`j:yQLe Fg0+r.-]{&o37#8t.7Hnv-ݬ[FHa9-<jAԴ .F3ٳd> injtf3QdB)}B}YāC?C{4pє_fV?: 89+mwP󚎌TPY+3ȎO!T_s@~HE7u[?m. Hd6==P,nϒ#ZQE> j/1eg@}jŗy10"?p(ރ4V+0dJϦEC [ߒ7}*(7elРdDWn^zZo" |ؔzcmpJ!>_pgjV9-S:cE[aKkN^ѭ/ An2ڨ|p(Z4EW&)3ث,91qC2۫Uz>$:NNǩ v]h_Y- <%=t)XFetZs'MKtȵlryPXdsne M[!&Hqy05fJ4f=<݂#RB+eXPia]dZ_bSۙR[LMS&L P]O [(P}>"qY*Idt8oDCVhnoY7/ ږԦf7-~p$O W͓8gFtn~mh ڡ%A1 h*__Z*z"G?֟!V-*lN)ZAu>5(G81*C1㲔Q\xU*k$瑯Y+pq-U7D)(? sv|"0kTH ѩG~{$`m G@i}笭*s"4LZbpD>ĕle\ !ojSjY(]hMnƃ3"1"Q6(2~x^SieQ]oqWOtGhr6lt&]駔;  [/sqٵBRFm&_Ro#7oxÓB`Tp ڴGJaHYp9v%H&,az #eUaKݾtNT:~]5K]}#aY˙Vt`bw9y<`qi>Pχh|sxb>vjV-gj+adK\+~Ks&ED!bU\^cɤWW/75zsY@Kn9p|m` Ж_g1ue5FOir{SYy2-G&a"R Oqz}=D&_':߰d0n8/[b7t/W&2?OH2BiZ2=Mb MYV!R,NO=ȑC M M .@F3$)sB^Tq8УwOa([$Tu\ hFS SI^HhVꚌJzY Ǧ(+J=M#TqmGB95]ba2Vu _GjѺ0^T}{V)*_Ъۣo!]}ZX"6%3#i0/fԱfL0px7weSU<6U^lD-1٨:j%NR%_u=W ^|FIW8Iʦkgw9;꾅tufr-uoݭ7s4!57ۭjT+t SM5p)}lD*̐=KTGSx3*mJcQT'ܸ:_yx j~:uL5Ru)aN\wU>b| /z%XLa\8x*4ƓAj")n%`5/Rkӂ>q4Y$D qIt_N8(GXWn+`Œq!~gr:AMbp05% D)0ىI&݊T6mjfBJxrhy|UJYT D#&Ĵׄ"9-v77QBE=HX5-TpYYĭр}2qnQs7i43,},0rfYW"9ܝ\9''G'#tR$rpa4m(\e#aH֍ (M$~pjшXA 4nl/*(P#!P62ͤK TWѓs)PX@<ׂGWD5ii ZMv˷͉ssDUƈo9 0S`$"RM.~"Ґ#k3g0-7hmCּeԷ yJlNGZ?%#r7)O nʓz@b9W \5A|鿦GX]0%7%~ i n߿(dMFG>_S_uC`f0Q)#M')^kJ+Ld^N?g~E\N_Ǡ24&PScmqt 9I*ң ٷ3QA`|/y|H& DH&{}f=|k*QcpQz?B?{u 81}-@I^p`4f6!hD볶]-fݏߗWJPB%NutB.aژɰagZm#YIz#!m;V˂@g\\(NpO˚  wP\qɜH3c\Mk=S4.3=nU_pVkreCѺ-&n6:FҖXg=`r~ȱ8V\]ן6M vs,ڜ`q_S1AxD,> EwJuۯ+2ٜ8׌`LTX[UVƥW^M:I dzǣ{S*кKŖ0)mE"B@ kÓmH}HNĴ=,':: >"5&!uQDp8d)I](+&ȗM8cY z_-wC}3alBʬ 嶻 Mߥb?wMG|$ع9h)(.m(lj/iZ8Tg)<%; e\7ZurXW& Z&oJ,eb=E"nR`:}!h X;+4CfK\fsS(RuN(H&RG\G_M57LT-Ԇ9C'51NEuTq,:^x7CDWgv))|Mtŗg@Aa~;m+;&WdNZpZp_GPEW }Y(eRe i~;sK=etE M4<\Ϧj}<<Weo@gNf众 j:V@fTM4vlq3NM~S[Tf8`GلG) 에xQ3Y޷5a;P.]̳ى@JdBh`ŜӀ 6 "6_:^>V|" WpOĚԫҩDl}26Z-up ->{|?f?] άuO]i IeCMh4=P @rZ{^SJa/КwJHTMl$,L Qpf&?܎߲U ( ^F^ TZs$pB> } F7KJ(&SYc@k\Y+4ΤRFp Vqo/gao̲Xs<%x;uiE t"U4YLqc yL0XbC\P^€Sڷ̹^pkGยUv4GlszZJOLRgxQc8O>̃u^1>͉dn; w^FOtktfTgӮdž5/<kF =|pn*w"^锸b=hUф5-blp3!!}N>٭A-VK5 L6|vI|\‹dsח \sD"`R- mg .=:qC(΂`Fq@ sq?l_ R|zG[I˽.6MaٸaN؝CpX}ZgS!hdDڴTp;Oo<32m%l +^b>V6lsK8.Vw̤9^.+W5o< ykkNg^@#P<} FvRŦfR^5zỌ@s؏ƹ$KKA!皿f } u~ݝ5`H$1ϸj%nԴ6KvTb ?X1Qk)M-峏2T׭~>Lb-;z6΁+Iذ͘hl7PpU(2-Ä! FK /v`h30F8DH$ښJ'q `bfX]{&vpá*N̓b E ZʬOjImH rBŶjzɖ2?KK݋ѣ njz=`il<5Uyӟm!(#3$נ/;Rغ6Rk:4h( y%~gj|̾˜L6C6,K/^f$j+R0')2SU4]xygpi]`;SbE 6@Of߄JZ!C W+a)D\Wh-fbC|6B*$OLW[8 ͲivQJRi+XHLpSg4 oPHN.B-җ7UDžT"X^] ,GQHsnl9mEb(ˆ)ݲB)|'!{MpIoX GW[ }tuO V$b]Qe`wһ([co^&20CW\KqgrkVt+Cd({JbsbUcvHrdߺu?s8OIB{8~Vx߼r@~qssnAc {B[aZx&?/EF"!H49,cUĝti=PHGՈ@LspGP),&fܑF\gpr] . 38TeZk9(: H"Λn#$AmEA3ѓ0{FvO(?$,Sy ơG.RGGp48[ vT{V^ ro8-OC&EǛB-`#U;1}pGVb;̔yvp&U#ǓgNXؙ luLE )*`'/oC4BebݱRFOϽQH|`zGLߍJ-C_Pϕ95|ٜ4Law_UW}]g5p'z,pCS NnQ|E.m sr;Alt"q(H!*xVhlhXi jmr~] .yod~.hs>#É#shh+ڀq,fH3jt=\50/Sr,:՜8F} 87:7A[;? a= J5ێWvkHǥ)"B0#E_Ӟ ;F*Wxmb3~ʉў'78boFtߺV(AMIŚ%=/wy1EBۧ7[Kn)Hԉ u"1 %$]tو\^.gŎKQXcҗ7}fEN}\1&jB$:(dҽ\%K/I_ "8"fȬj}$H13fW;y뤫'UK:J_A-by xlnmLQr5쮦 -q%̛q0L zNkBS6~ n Ƽk8 ݈9 YD.3u6<vW+eQ )7X+t,X?frD&y.ē5H6+m]E^$y n!>IjtMɸ92,EޒYX ?:J<ț %Y;O%jHCZM0|43V`=HFNwhw$YDEw L"Q `z5|rCI?[s9%%ۈϫs;ox-kt%mFjd&KE~rE]ԛ5Rw_J)XoN5/]Gj8L<BIBD7F%+*ADT/T.5YKtu_N^WoZ,FUP# ߣZ^.xmwT{NHߌRJu(zP8\Hy1+kwGMٌH2sa{WU",yCX>뮲iD2y-p˽B hS˺ y`a|v$+fEjU$'!FvψM5 J&? Vml Ȫ_?B~V NfRO?"WKU^SԞr /Fia+^8y|˹M {҇{zA^zp"Is){)(52ϓ^YE$@T*˅& Q;鐜0Ey267?V˯TH`"ݸ3)V5N N" bY q;D?m~!sߟQkHi3U[#K219[WU>#gDM͇f S]\7K{(UYW?ݦWұ-xC+:!9siqD ![vi]y4pxGILa 7q0:58mm'CV; +xc)žLYI@!қ>fkͦ"y H#͗(YsB>`sC~F;,ڌ ٠4[1 m Ktٻpj\Ɔ:O5ca9MF~% ~5u6h[R]֗2.bK?a!OJh$DULH:EMt"s7 '9Df\ h+Io=8 Vɮ]z OV>ϾC4PM[+5'D2K]UY΀FUX.+WcG*ǩ_KNڹ o@SkO%Ԟcs KR3֙/TV0'GvѡhE3D 7?:kh&^V~7!& |eD? YT=*c+'Avs ^!,>&]cj^HX?}LLq%r'S8#7z)!SaDT`]Yͪ%c[}qf&z/f 4c is"(d-.GV`)\$Eʠn6_UмO:t\wC (He XE Jo5C("?~8u$ϗGK6`#Pd3oƜws 7Q.ÑkLT1YwLr2d.c,۵==kD \cZS {}N#{z_e_`gV4cfR^, Gh_Y@)^9@)휲LƝMXfcnE="H$ƭ~ŊoN!l*wO2cыy+;&]xzWG2WπNЧ$M<8Q,z*j\~.7-gPM2u!vF1xk:L/(t&9-ңtyӽNw Hod M >x(?loR\tZ!0Y0?[B,$0g#˄d8w8 _dQ mh8Q-v`\)yt>ߞ]@K|<3hDr"^ tF bxMǐ+$xR{'P 1m\y򏠑; =^ YܯI]HNboCxzӹ6E:9̶:B}Pe%H%d3Dd z[>71a|ڵ,I[SIhʅؔakyCT르}SR+n!ƄtG!ARe]Rjܶuozo%uܥ6;|K. #Ր%BT >-꠽%^2fhPGxwU邲_764&@{wR/1N*ki-D!UzVS_vtq4IfD>ՙmҗ7a$[vD_e|\j/(#tDƸBtEaXTFӒ_`Gϥ&3h[t(1~@z8ąc2+j!mdg(e»5T)~:sĺ k,W~AA d fD 必 1QPP@/@QD9K LHGȀotiXWH_To Qʩk{:b%{,DYQiwo R, v[zP:!^ʫ}oɽ sU~ yNAvжܝxy\ &&P >] ~J/Puމd;N4xUqR Q@PY?v5xnHs|tiSu=w,=LܙR#J5x>qk"kFmBbt;h&s9%Jnșky&J1jip .ZtT!!..K=45XD3%vh2 [8)!>ȹGa&wQ1P|>6 *W_Dki12 i_:)O d℞F1lܨg_ Mi%TP*V_ցMb L@\ԑNl!nGV1'pFbB evE2fѻ7y }dN }&(};!VF|Bzb8D( #{%?ECdn Em\ 7dWw]i\wGA(&'chOI s2)h0igx8O/Nv uI3"NP\͛sW鱒*xD@G3 y0h5}σь L*xCNF&݋>G*͠-:zoM0.'I(q^z"'=Q[tJ?InxHr;e tv=|밧M}z^_- RbFʡ!ZKtMӢElv+9/G#`R-)*5%'G*v[P2uPC[!uyصY5fΗma" &:8hO ǹ:""WVu }pw&cDSU* P9n M772sHkdhavBS׋ a O3׋8^xhZT'н!|M p{ᅧ xX'7RV2o`n^} (S*BR=kJaW&[(SCt6 <+""F %h|.}vN8H.c}^ȃ/mϽ]-KB|NɏAr=-%㹠!xDϵu+ 4\vƵd^h>R7zhmr u_֊Ɯ`XZc-LxT4Wʔh+rM/smf3vmֺ4f^E2hR?c,+Klb,Ztcʪ=JQ\ۋ_ԭ>kCEDTD2>ux8819W{.s͎ӝĀgVn^1,>n\|)3B(y= +T7lM!E>M9/w:U<_ _*[=GRcdEnL5kF2ᏙHN3w{Fz(Tsb̮<Wl2c[uؕ/pU%I 's׬^@8 Hq^=JtyK|x:8/m1U[mbuof7|CNSP\ah~3$yqt&(oETǖg0ʻ/V>YldCX N\ObܬicГA*2bPB&#%0 ߍ[ a^A>v2I,@ƃx3[mf9=!Uv2(5=sϷWC%Js"{()ں}u5$.e D\ zpS'`KB}h$ť\V|*]Z= |P,]?|=\g#JƸʬ_ m#Z%6At{!{ Q 'u`e,"zOWEQP䇧Vwf5w_QRs=YϚ8'dp- "hkv"*g#r s'ߵkd+.Wz6Kg:I,~Ol`N}H/\}>O {'i4'蹞 e+8=(DXZN L o'7z/[tn͔*% sBd X>׀9/}fԬ &N7;K>\U_f̜U:z-XW=бO4-̕h|Y 7eh*7b]}vMꢍl,"~h 0z_aɛg"&qGG\ vF,#'C+?asgoJpZDD@.(dYC6]Q MmTt#'k"7jCBqߜ,#SՏuYP˲8-a|ҟKe1gSԣ8<(^ W: &! &ä2o(g$~T:1v(#}[\Ep4 $>o?PmJ t?o'Z#`,x"r 鰅GQĖy"uH,nhˈ~݊ʖFV.H}bi#~wƎmyyL$^>EvLQPHTn{].Yҳ|Qz>f$ꔗ }x39J'?PK&n)DK$0Fn-tx@kѮn8#f'=m,`>K@z×>T"TD:߄@v! `6Ji&{E/̘#/b93I>ˬKqn˜m^GrlMQZ/r;t\52-B6TBl "-G쨓~$lQs^ |S @׋Wsٌ)HEߛ mv|1Ԗ$C6::)V b7R(hM1v xEvĀ1i5lrьV!R-wRa51*5@lIaF&L8?v_[jnz;/ONʜ74gQ7_To(> 556S7 @Iӌd%k u|A3ELC&厺a;yl<2T2@툍F;ޚpX5طnwIşbvڃ amL`:T0+FxXRUD,I@<F# -~ |,LҲiar CiU\jNMz}=xg3sJ<4dv ژ `&KNґ*۝h j)| &5J;Ehnro/zV@J TZ$V\$p{Z":#n'r] qi,uKo=c-{"pPA/lΛi_^^13-@GeN- LU#E8*|xbEtFk#KIVĐ8YɽnzBoiR )fz9Y\=,[9CJ.OB1( +71qi=~d&ȾfVC%x󑷍 ު3Y{@}٘5SSS.jC 0'dr0vjP<y@Zs <їIbhޤ2+RH^i$adwj.7*OY_ d7 ɥ/o"MzɹӴUf%TKe?ǻ8{x} [W&ͮKOa%7o|/m4jZ׍鋊es8I5 _wa9|e!8&\$뚑:Va\G<ɢ@QqЋni@N^M~Zos> +Bt|ᥟɩjW6 3bQ+]q?%:A'f? jmk[}3JQ8\ m%Mf6^LmWm\[LF"XkÚF֨G[ܞ^8/'\ @"Q/^ó!uzv'ϩm |O<sD v$5(hꛜ)Y!rJ$HmQW` rBu1lhcy?VQ"Ku'"8Ag5ٟͣt/¶$]#DCరMI\~#3M0#׷ԟlł*G^b0? ( %5dW!߭+PgIƱ>Qgcgm'UEKv<}QF˃6+@P*aFa-1Xxmb%Xwg!X>\,RL%y-`'%޸969~Rf&gO(A"P2ʖdκ?0?ClӔ-? <߷u><\ LٕDwe~ih{Iï&aJ@/23[I/Z[`] j#1'@IИ6@I WuG߰ `˾'ql+;9P4h:qoݖExK(#q?^y5 <<~A &ӪLl5%8b/Y|QA ʃ&w[eUbsٝ.KS?j5찳@9ٔx ql) -I)#^v0|{%oєU :' v7i9 3ɓi kjrG.B|!X[acN 3nH!weɂ1#6pD`eBjy-5,$T"=![CtuZ%}dlo_SpO˵E1M{Cf Nr,sfnڭb.=%Y#m]IxA ۽Yqx6,s'/eKM#@>x~rS'jXkB13K1;_s7%x] B/K=v/?Nec?O%زIr|7Vóe:\!Q@i߭#> ̊sUFǗ @> pQn:c/l3FB` %ྼN]a4!51v!]6@| ;" "esxCEuo'dh0 zAT>m,Oۗ)7, +cګà5WB^wGsUoSt6٩';'z]m3n>kA QgI*B3 $mO5?g2,{mEO\(zQ\k_-i5 #9"r68{3'/wbayf]0Z#asZjfr9oNk}ʝȕW6O-b"OgLu,C Fp<32gCy ieؔU S!@XG߳ :?6N{g&#&oyG<7J~lh+G\iВRSzrWTu `ʝ7r"PLazvZȁ`}lF no mZ83$/|iù9f͹nxd qc+7`B_1z>2Gm']Z["eOw/n!²M cͣxMd|iÕébv.(KIoMjțRz{/Xp³ zdQ{lrfa X Q.ӵ|Up.q/\j6Nk7[@>; {QvxjR{.`!u۶!: Q;' |?hE3uY\=#;R5 fo.Ygĩ:|vp$X\y@fuȳw'^~cG.IITm/ xxR:$ra;@;+b D',W92˅t>g"J@)Eΐ``sd{(R @36Y#[tp~ʽpqc+ 5VRv-cV1'^rQn/vRgw-%64=PMސ!+QVR(pW+<ٺs)YMW 9 6Ch˃mт-GcQq{XCȓ$,8{Dғ: o sݹ9$[&F"4SNd(I{-&zF'PbZ-3,;7Zj/ÍȾyXVx==YqmN#- /y26XXQ&W&?'/73D |k [t8 6%}/V_ %ht!r>y@jxF^"zERA01kˆE=+lp\:mss/ҥhJN3 #C7`+Fh`5@DP+{ל s0 \Mz̴?Zqovv}vJw3DӟAU'o4odB|`&`!>oWHX& )KZ(!p,xd,JV m-ށ<1˿6 j <|O亢Lps+v>SuRcH"W(ɮMV6^ưjgi}-?W{0yE WfcD[y$N$*h:2X#4x-B pn(,kbe>{jBB$A!Q'ߊjO cW<9Þ/t^srRHGC tiE]:5~CѲ73,2~G&|77޾~=~m.^`Y4KF%ĈZin\IE7. EMM<>j-HNJHr? iկ ]9įC9(K?0> gX F/Ղ_#|:mFa=^`2 4[aF].Y1 lRlW0I5e$ݜYԎUwԫxL3&Qfv>RawWUm:%[K[7 |S^bŜҳx-2Xs7Ė;7s=4DZRU ń; Àε13xtk ;Hg̜oHC@t ZI)u~^Finr(Ҩ HEY{\e-D2\@VO t'}Ou_IAܤ7@..!*ʌ4uhK[\v*/#@r( Dڂsʣ3\Ҟ%L&"CArr*ψtǃN^(msDd`n;k`шc 10Su$&K/$@k"$3 }k`.URB')>#0$% }sCޑ  Y`Ԣa|i*g:q2wyZls/ur<GI6*sye-Ӡ.[~'̲֭PO!xWƖ\k,tLմ.Y+Vs .BG|q%%!B_{UOP%Q.k:GlY@kȮ:"Ei2WQǂbr g &`wyW0NU c \j0V˯jqź|H"é_meW_!0C?l: 3\ $5Zp4OF-8.K̻5z%OSH?P?K08qR1;wolG~f퐓|`S I991ICf9F$8 LV!$ACAsKzzNms21TaCm2VE6By׉Dq,qXU0g{XA7 DDӆ-J:]/Or$uN6Ziq[oczUFjeeRXEŵtĀKڻgO&Wb* =/ƌ Q^Ҍ]ծ=}KGB,Cؗc;v*,IO7DTۃikSn6孑a_3I0$26^3Z" B"jHr/:%_@ T`s >pakP ) [M|QӴel.f(h%cpFI~`膚} V~':)8 㽥gҎ GLrJ5?Ƿ;~ڶ< A9y?* cVqY\mӎ+5g?QFOg O}2?&,=/Q_x, MUfF S$ =il ۊw\%V٤@WmhswV t rn(1CNyZ=z)ȑQC('׌)w_(uJN[5'J%A 0c' s79tξIpN[J=H8OJO6܍E~kXNGۓ+g.M؁?1Ia9pwe;-ę1MmKEc&+HEB. eW?<󷢑65o$:fC|H$/&=Uq"IZy N\ݼ99o|cc*oP쫢ͻ5>7Ѷ@ 쐖c0灣 aXS*O.o02:dEu[Mz%j+Sʎ+94ӆ! 2sSKPLz%Mx0'A biV3Kx=[J^zI%D&EMʒ `N7b̔C)pT4pɵ’Bf pɻߛsۗ#u$u1܍E<}b}G(s>cȴ;rSZ&=WBϋ`ke@}PlNh-hPۯStݖjHw@δcQ2$Ԯ-˱'>n`n%~I٩z|.SU g'm BR#o- MlZsQnhq@]+A،7V7lp/pm#giQ}W*E`%eY~@ZxJvjʧhwQ2}|bu9HP61C2Rp?~cۄ?9%+7r9%MWRW2w)Y"![:`Cp > ;0v5H"&AGCf-~Wp8֭XlTIJäEζr:xgMYFbs o*2?6*WIaߋ ! z։g5#邌&ǘhY~8< fnn`[7eXJ|ל`# =r ݊|O9Fq=kB3Qׅfwl! EN,eXͧBsKM(XM-wjRh1ʲ| 鉔xc:FP#i)' i|v5PwȎ)`hDQd({{ `.Փ@ &JO]?@6]vK>S,׹#jlz:G_CJxH֑(Q{;k:6hޝ!H>T4+ϮAeܯۖQ|f@.& *GPu]V:J/z,SQ*kJBO 3Ⱦ-QJgq0%;xωӕβ4y׈0֨br:1"#\a < {(_@.GQݵ;ݹ,f?qx쁹Xy:ap7sbTlnf[-}zG*kQNX$s|A*5a6Ӑ]Aϙz grw#ILZuSkb JڔfqEPիt~D(?Qb!"K7MR!ľ}y/ڼOYO/7d&}%M-Ӯ] z[vD:~(i)&.ܷ"Co8iC6S!ʤ^E)kA"x8 bg/dw1oB@9Wچ@\D-ֱNV07i7zg,U7F!S˟ZToRS9 \]2N(4hn\G,n45ZـojD.u)$:5? 1ɐ먑},&W۶ ]@?Hs Ӆ` b=so JҦP憃7u%LGeR1c 0S#b'e$K]}4A焎(R{:\?=ĻW0~k# jh΀dwQ!nQQ & /jDudrU:.Ď嫜?eΩY>z* ]צC6u%8*>wn|AH^iew/9[ W%S$RK_|[^xĪr^a}[E^|L[ \(n}<˕KY Z: ݶ}MWڣfIKo;QBR __,RKyg_q\dLEYC;ZyzR!l]~P&y6 _~Uys0*ovjHb J7`td<r0#CX| x4 \4H'ݼ5Q<_:qK}&p{Q!3CćKK͢8{`>Ӎ z~NxTHaưs,^!W3zXd=;h"G$=|aT=K:~yҤыZ?sK:sSO#ݘcC)gJoCPZWgCζAr{ 8ctPMuᙯPUrSW:dRszWiBDB9!DĨ.&98j9QWRMR-(fQNGS`tfKnZS3JS HeQ)3dB"Z3 A\?R0+:}H[ Shi6%gI: jr-=+eŕb`E""B*th1찴=ϳgkG]LU0 ] *FdN'@[asIݠӲ9; Fu3a5FU8mn ˯*Tye%QnJ 'ֿ챻8Ŧf|XR|v)2xzZy`܆%ȑ;*To\6̯%P-<D`GS߀L *Q\ֳ:- oEiVG*K5f$ @Wo'R {Spb!.mܶ6׭-JDҽ/'~iN`;L& ܝA6C^V v|>N]\ ~w6ĕ Ѷ:.TMeY+ en]oVt]Sm00 ό6:fB5bŔsa":[`ŚǵYtpla@P3@67/wPJf&Gjj;hz]mZl˜CՂތ=;2+]4%ÆH{׷MvY6mVw% j0s<}?kgiH=_xmh޳B62hUGMҷtgnNsuscQ<(OcmxU,G~!sdOO-4?p`8NԹj5@UV="<[X>UI p*]wۨK{ "B$$uHk ݝe׌2JPp~BwE dѳ]QDl`ELJVN"b4 ^_)YUe̹Ο,MvCt2[-"h6#j kq5SuyGձs%v]0{s)E7m‰ H'5PȞQ$Ag]D đS^dtf]mѵ3'y:[l8zW~XFQ=߯DG D6U;^?&ÆJ0VtɷHrJ;ay>Uֵ ZF#0l4#9)+]܀Ms*o|,h#/ nNqN)ORj,,42dFJ+Vzd0>S֬dx$U7I\"v`ư5Ѥwauz~KkQNcY10),p&z46::BuNWZ+g(RkZ v| @JZfV6mwDj|2sCtߢ-ޮȤ ^v n9ν܂4x4k08-ŕ_lH+牧_On/Ӆ-l45A|I kµaV?Z>`P5lPYymN!ɧDŽV+8-~d Bv0!7΍L}f5FMsVMA2lvQu£t X3&{UzruOKA !6V ኺǻYv1~gWkDwR'9ȹn%Hb-ޥm8GG˛S#j&Vp(`U‹=P(C_CVj<<;g! TfI!6U(s*ȼg?4`SbȻHH ݮCl6m,\p]Od^83;QXw€D ~1'`To#ޣRsOOmq, qxM=pAXT&C:f D;Q&8\2)I nlM!5}'Y?g<'S9~=Q`~G yTzkH킧+q7(?+n`CO3֫Ph=Qp,2k@UaÂoɃ:6*y鹚+mWhlݠtKZ5VMRDBk8%rt**%4twWU_jYsM ^k-^}GTƈd)@O4]uO2BgA|nGDPrxW6CVtaOX64г\C0G}oGUBMo(Hg^*ґ!d KCA. s׌dEc|d! [_&攭|2E2e _3ڋ< wm|;Diֳ^6 {YK멷ɡ<r`a &Nѷ^ @ .U/^7[L.>kv2jrsm(q\U/CAo3;@4'ݖC$ϋ2nO \-gjLWBųNRKIiw{ѕDx2#ղ=}.C<9q7u0'PƦWrDmđz F#2|6qQR)g9]V&Q/Ư=Q}K$AjJm J-vg@Lgr1 ۏE:j̜B"wJeq9~ b OL'7ʦwO{mnKqXךx iͨbF҉Vo#>yjD$)w"m9GӅb̍~685ä; ,1]7L$L3:Ai Rm X]SpT(+M |6t%>UiW6e'u#]N^Am~g[؋ ;x0:}|k' {U'6lVS[7,OEQ<Ɏ vTXLfTZO RYH#1jƨm=!@)ʚ*rn":`Vl1@֐wؚ3mg10[HAV7ᡀ|hRHvr^ϳfGs7W%(4Qaʴ46Bj*J6r<[W__K6sn| SbY d+@8n/eBNYW; OŴ~utm M9nb!5 CVPhq!ᬎ#am؅ڑGލ˃3]=[A'myӜWxAMjѢDiW;I\Ԧ-$i@h_(.K1Wlat۽nܺ8UjݹЦ]nƗ2Y/`IEvqGF: 0N%y|cn:TL=Ї63*l &o[v,5v҆˨Ocܱ1rnҢ,̞$v"Mc/d9;xѰE bzPm-ּD{Zf,sT2r̸4wjׯ[B[Z'F6!Dp\vKkx;@+"W>=Iգ(+qJ57WBHm+]y%Zs]-.{K*෺H.󋒔Pvm7/#z7(>'cDPIc! #{7P} 2k/AJBj3-ߌ@g{wB6Zh xtϚ?Z&lws^ ivENˁ=fyDTI>YKk2|92 ("ӬQ_ =JZ|B󨗭_{`Ӛ}D躆/r7*f,Hi=ȎZ硍 F~Q 1 (,Sv|A?0@Uak5)΂ .^E."%TX'J.{j o vؓ1sVp9TyQ?j۱nZ q*6 o6B<u^ޣ6 dR+DnDܕ_@RĭSЅ֒=m >'GuOI<]zf?* W{شz&@DZox,/*к6>2W$N5-]?(\8M. ֨?st* z~#_u+*V'/_H IJ#!X $f Ѹ/>K>`x ANke-:6~b."%93BT_xn1pvf6% !X":rq V $ Vf<%PW-PEqLy1L.M({J3A7>qIN ` r1r@Vm|"-l:/>8;ӬO˳^ D>[ǵ/oamgH|Qlzz$[IQ.km4iKM'J3Tsi:՛N,ŒUaFwA {bD3\ Բ+u&*8"TUĹq&\@H w/L<[4tf_yH@ƁJv^<}$BbgNni~o{r0N/„X-r= 1(_; <#lQ:К=}qE( I&#C^iXmQ7gdP]NcV=ד=YOXñamwJHCp'.&ZàvI⊱ʈI*f8: R#K)H=v/2tQ0^ ^>@GonkZ1+ ,=*!NV&퇳į`93II7.QkB̮*= =t>CM\0?ʿ>ݎCT1%&js7Yʗ$*SfrY;F8Q&薵;͊*94Su괼 ڝ 2r|-G4j9G NvY.F}*emI,z1KX1m]* >gHη,B:fRx9e) KɽD!_2iHy?EڒJ}n30^j ;,NVL1}:Gؖ#? %|S}an2L܊TDV஄qrMZ}eS{ΥͬzV]_E~#zp4a GQ"l E99x"rGV2^Fi2i<^hnpmqۢchV"b%!k2wKԣ+O df_'vK:ʙaOEQ"; n<lf]6f#4gx2bMJ7iA(-:{M@^4U\NF)\%VwԋU{nb{x5 A8UyCdHuֈǧo[TFz-эy~ݐ,JIH~LiA]w͎桍:f2ڬr[Qݪ@1ibߵD(wB,THf n,WYdQs3:(<NnףeA"A@O@&Bqvs$"*nn+Ic*$=ѫr~S[ 3P[6!?'0%Os^pP淄SO|Y!VrHig4-`ā~"?s 1)8*xZ>τnI_`\u 9tlX((#l .!ZDOvA<- Dijdm31WBgzAjANۤ81r6 Ee6=Qzjv^ŷ{v:;WQ0_\*ؿf.F?UBPXIJwtm /OHE5T=.BDU4n̐ S8c#]<܃65{W2+{9J>WoԶa(R~۔ aǯ ҺDc޺bo@U!b^Cd0q@|ƻUحoK3Q˚}35)6=.&֧;Оd.k=($un64֠ohwjBofȱ8+ ƧN%YWS PwuHC=[=GUx{zш1q!PGNOXsgL藂2 p s׍V ؒ#ZXg~%Bf"QriEOl[ҤH u":6^9vno`#R}W-OR] #@[@jCxe]+'kr30\:o.>0#f%`rہ3d>1b˖kL'CV|7N/`se1z@[ 'Q)k߲k8r']!4l1;~/3~1_ l>qCèϝD1%]93@#\AVZF .BA Qh %w> Okm1*x^Od@@Eo݂[hCᤎJkN7oPIU/H'輼g;djd#mr YPP.zI{dh%~6Z<f;jbNZ?6an$tOtt2[QuzbI0n0mgu. QQ9DdrCY҉"&39 9ډr&ͻ`*]P H̔&b}W Y/)W&`-\S AN%F"#y%3+P/5аA_EWM+-igIM׫2PXDR0 ;9XPKʼB̏eCSI5zrcutu"܁鞏p D ox_CQeO!\\mCj9E7bNVu;ɺXd4cC;$HC\bK7q2$џi>9/ Zչ G$.<Ьu%Q5ZÆo =}CZJ/$'igXv*:,BwN?O!7ݶ0 BKar}dC#D)IrVD^C5 cF90+8&܇Xc\ <~t8ޟʙ[NZ]XeYC7 r L/M&{|Px=ҐUQƒTr"RsyoiCR_?hF&N|$(fm[}bxE+{Z9-fA%j yWS,LZ`301 03 M#8b{S$Un@KFb!2qTMKŗf,OEx țvU|ԕULӶ8 Y JCqj>n=ޖΥ+E\t$BZyWI+esaټO]O0QKj8LF(:6"m ,|!4iHCFƥSc4JV`I&zY|C˄wh=1\F;$ogƯ[ݜV ZHG~<Ӹ^JLLw>meq{wJ6r aߦQ쨑f,1DĊR.ՖN*uӋ GJ}#Pmg]mrm%jfdU&B:@^` P՜u~22~jD%O/"8~  )W`ibӝ.VL=W @IT҉ܘ(U'J][EhfӿEmxΰM=9{5Bxn [SvE &T𹘆]pnI urVBAf@®ǣ pɪ+sa&E*~]XXeQ7U2!(Ѽc.۬͜cZO 4~r y$i ;s, Aڷ'Y:Pө4Gn)Nv=qo:8^Z&姫*ʲ#ƭ9.Pna,#7jSfXdX% ݜ*!'ѣdHq`ǭݙNt( $&GLC:\˝F B<ʚ{׸N]>p8E1WR?$Me8/R|TУ9[U1>+]ǀǕlͼY|:b/}KEИI+(~r6b+泸l)p6`&FL@%?'oo'rV퀑Q\̽=@sKFpT--)"6&e46fއEYvy1 B@3@^ E/&"E}l$Abݟ2Kهvp䘟>7ɋ{8 [C:p!b"!Kp; xY: rgx8mqg۟3Ì{4:M߅Ԫk94'әMc5Q ,J^Մ9㽱=jѺ+rAK\~V#ϔ6&%勐aU6{oWhɎ]&T8a\8^V*g%Us?r]*X;3ET-M1~ xR "*ʵ>A ^%{4ڕ0id.b=´yhjݗJ5IEZJk쐢xTD}MqZF:](ڀ N,5Xo4OkJ◪BhA09(nzjjt-(< ib@ѿ<'C>ZEµ\3`Ӷ#  UӶ=&D~Q s'ݹkӪ~!4_:C?[H%1(H4#oyޣvnQe0i>݃bɰ(G !|9s:,a8֓2I̵Ԡ?~IjVӾՌ[ r\ly"ju7WO~Is48zlļ2H}!q̢@02ٚp|D}EG}uV\|ɠ"E*𮵛{NH4 0xE"oFph%! gКZu`uK+EP^s5پPNV+p_^pP5 L$Uz 1qV:٘ŹP!E=z~yhաX^/(2̜"b] )7({H:Hr3zV)Szl5,:z.s:^km[):3 ?&,5 X ȿd#JɊOnZV]4:69ۑ#J,g"`@C|Lcʀ*e4i"]>=Q2`ޭJ'WM9:U^)@(/`W~sgkXjS0附h] {C`Uҷ+\1nolߜa'g5^BЎQNK+$9q*97RB_髙ysP̆̏gvZ[;Jۛr1YMJ՜uͩ:"д>9zXDɯk:U@>*IӾ[߆-Wۤ尤/r俸/%S>KԗXs*=QF1K) 2HLgJxo7#cX2ЀgI*va1-*,5Lnpx3<(l#$7}%\y.oeb|X)Œ "jEyq @%v$ؒxGktj`4BUw?fU fKpn&WWZ{(vN'ZW^>M'"Du+W-i~H:V2Je']FE!M87Fa OaQy;]=9iA%6̱v*v mP{>e 2i+sgS"?90W*⋳Ek1jr/73()b|򴖂c$?<=HO賑{R.YO$`5xD[-Z>Sʰ!]Fo<Ơ!Qs;7;Bnύ*EQ$d(/A}! +JʈG> {Ƴ#6@ ށDl@0~&Џ)Bm%Ĵ=\y·)IСb Umf >fmۧ߼GXƗ7oz~^>І[/E,JEߓW ;]ϒ%a0s}~-12-L\ Lå9:FhZ8 {-x&j,m|-% rz*%;ـ4W-!Q F"Nsj4KPgInNCxG&<=Z>EH^vWGy!0(섆LoZg̖cT.$3~P1aJ$ U[Ԉ{JaZ7kp}L2aL?Ql'/ `GV_-xo<"t|*NeZB/'Tå{@R1;&r=-]Yf=1D.JM6 kWajv^u˾Cx/3lcSoL%Kh){z]THp1Otv!ۄ[!@LN铁Paqȿ5U:m\X ?A kphQ(Z} Lrv!+A.1,Ő>7tڞ~m-EglUQ6f%l7H#.q'ϣ\+WX:p<ދe}n=$q4㴕QS < E*1yɀVeofiKs"L=؄\MCx>Қsaxw,~HP DM[Doufs%aAeuFҡٶ2;<9p6 TYڗ{@,z? c[* bU݁9u 0/JB>EJ*n<$g2T[u^~"'E^=WXQh9r5X~&DR(aT EjJk`@E{ߖCDf*S{ kY.-~z;j|M.#:>U\5UCEmxDy7[:YIqWq.T.ԉBBˤ^ZU9mqb 3+ ݬu7y9L,kMt@zqOn2AݒA(FeP Jп/p3T0EyR0-PZ㯠oKٱm%"&,JCH;B`WчͅЬ2#g_6=(_wYy-Ra`\ZxZ"pzK<3idkT%q҇ೃvmN2nZt7sjxj)#XWR.u&J<ΖXD|iY+MS6! Q= 'm3% "|f@RQA9=ys &; SA>׻Kު\72v zˍ%o)QYe,'R2g b?z|.eZD.sFcr%2q'mӧ@xIضu 9=GD1D'(<#ר%%Qo%gfu&aJ,wB9YK̂ }̚uSRoW-!qr@T-<^,YBCN3`2RI&_E`e K* ސ P]!~GqX:Wm"W< ]O|_s\Rh"hM  p8Y*4_k`gᲭF*Nt$ͤEi:00lL1kbÙYnj G&)j'i`ޞ CR$~Iӈ0mrYå&е ս?Sϻ$_V{ύ&E# v҅Lp ^ 4޳bR6z2pQie:YѮGoFiȹO D6W| ;a,5(8P0J 8a4 M+ @ ƶ>~c>9h.~!{:TiMƭ#D g+Cpqa`Gǵ{"*  Swo07 ՀǺL *Bcٻǡ5SAP%j!,rK Sy K͹-k:DKdc,ׅwu|#mS1;84L_[al0u3ek dN:(7ԝP]->Ɗ c[ڌ^VPZ2|':D0!vOvw53ZC" a,"e|CƬ~LS}fg"n<ȋo]V_ya _`ab!>#ڮiPaNRMpK ƪ23LAՙN-pObmGx~&. >XC|KTɺMF`ՖaySf#ۄ|3xOcM͡łU YRץb:ʵ.V+gR19ֶpTi'GW|jV7 \bU䡇z udj<D-2qC8̋I(DcnePJ"m;_! ԘJ9AO}B% d-TOD07T{/TCc ւ3%UOp U2h LZan8^p 41:'ғ]VTqIhf/ =@*Y=#/G62y1Tw9ƳnPC@:黗iJ1ZҒ",w/\8vCK"9:Jh`tڞOŭ4F߃%* wrǎCH~gSƫg2\e =2D@PkLzl[lhT~ K eJzIZ,fjQrKXU3[|PJI?&ܟy}YQmC;pAI$qZMhΊieEx4l}sƫvFP:x2\#`PP|L!VJu\@_*.l'4了n Z(F)5Q6n`Z@An2O5}4oiː8N1'IoLk>v<-ݪl"8gk{1O9;y^ӫ) :* :Su=>A!(.laLڶ,4~JX0~uZPf7 2O/c2N/Qy+(; @t0HiryjIX 8δ68<8^VN,n }}iL;~t03=*/hv;S[86oIBO'Qs4S >CTZ Rv49c #TD쎆*Z(2UOs0)kBF;+lx\sx]WҫkO/,k[g ]Ъ*IAxdyo5f9l!Lq+ra>~?Lѯ+#uJFO]$UȘk0Ac=e 0- ިK5)6ڒ?sTCH.t74TZ+>H-lO|҅ڲPc^5&袴<U(y&+bDT K-lQ3 I]^>('iOcgbY3&k_u:.*KMlvM) >-s wfWjfq> TC'`+~׷0Gca\_So8I4ݻR҂,%&sWe9X6Ę+*$e icdaMT"VRZ⑻"9Qˬeb׼^2%IT습INWUZ1&QqyN˧5 `y|Cx{1 Z˚9{z~2L$"u؋FG6#hn aoVPдC|ELFH;]3"ĈtU@AoW1x =^j,W,UpS1h W&25aUv55-_Iee{ԷZ+C80}EAF?䁮Qj02o;m p)Fσz> < ̮gG⹽'LjԞC,}:qy gDH?U7Z1Afȷwҽ$W@ _' ߒR}r*U z}sC`h).xl% 824jY(=VAv,8UA̪?AފC5!}+tk` d7Ú8A2jPNɊٕpm*үRT!w4km9ރ!hEioCgd2-4Da֠Z,uj``U)ՊhvY #`Za&gYR;SG2aګs6c ’PIenI;#tFRM4Q;oA{젭=Qod67サ&GJ'[OF}P'?ùa:vN9o ˗6?dncQD8a.=ʊxᮇ0J+ c'l"_\yUw.ཞ`4cDj 'No߱<=[; H rh;Z tjTԞlAE·FsіEL^(-Z7hÊVqd E L^v1[GJk@z$y ?Adg,B<HmEH`j~p9ZB^<~B6`Fk_jI!G'ѾlO{s ?\$;rX;B`#+z/;iuOQ95n3C9񀤦Qq1Q]g"0Cޅ)"J_|X_NqX.#qQXJ=q`." f/{ w@B;?BͱJ]T5yDXÚ/ oM[i܅EwGoE>E`/[9e=䜞V n'0?3jrCM>~fKjSǏ"":Mcޕ1@NJ.]lŒ#o~K8⵽Y|qzҠq VYEA B>#=RJ!M;X+\l#^2XvZ$ MӲTtP][NӼ;~f1cF5jG /Kf?@wR S-NiAlKV[W@ _\䯜iPNR}{G H/)~PKC n [Uf&2-`k,2ƛuMlmQ6g*Beh n4]q⽐qvx  /EY/G_En߆o)ܹ/9du=|Nlkka70! 7G kı9uO #瀤%G0'kd%Z2>if(B/3㢩epۣq1Z"?~}L4$SZn]Z: !cAM7X|/*P)fY?ЌG3w|U5 ʒqP^%yz U2ag^2`nlTB>P9/5ugR `ktû-sOnCCӪFk?9ᒥ1FMU˴π<3g_i,| QR_AGtZ.?-boL{fKo4Xa{޽Nz?1D*@: skN@q[2:'PC<#za]I<ڲvNHūtRYK Ze]9jq,ƒpbF2sT q{Ä%3*emE|@^9䈱>* xn%܁12k6g Ԍ-9bЂ@uDcȝqq,`_Kbg! ,jyBS>dC=姷`)3:}NS:tlM,:s6A4c/|G z:WA/;к_plsتX[ǦMNCpD-)V7nB\>.͘WF0{ⴾ'uF<|Z}=P+5nUb#{D^--!H ud]G_BQyiX:VF}d =.%זm~3NI <Bg' T"فTQ(ZOEh0#Qm_/"<6Rn[f}gYpՂrRNaNA#DY3#W]PlWXx6xٚp?zȿ#^qn2+RRQ%釜i [,ǔU2/Mrѕd$ufse)PQ;07f-bґp;+Y=JaM'!~:Z ~@o)%ߴf/%HuՍ;#x\uoE.8|/xxU+Jc$A6q pYQ#+=ZAkiHʠ,ƄrGbdIStF"n*[++{Pa1=GO'/7RLr tJzŢVvV#}2&srs?irfRϫR_k4[oADz7ׇ6G!hP#',m_eZA؅x!Q%vz{0Z@R 32+n!&`ԣS2;0Sv+W\cg [^eCNI*G x0, yz-n q񧐽3Ñ\p>)ͲmV |~xE.msՌk'ZCkrNɳ)K nxҺg|{v09F}&-vʡSbV@ Y]rLBT1m`  JR9 fm,WѱfpDf(K{e GiYf[D[d>L]Ra7׳ P>{KE^3r<#y̏> "`ӆ׾b%/ӊ\*yLf贼c9"ɠ?nge˕2VX"ʹj}c~:02Rx Pz?vl5wEDe nьN2TWnoUu3T1]ݕrtb}Vb$fk<~VZig@Ҳ[]no - L;,9 >28}`Z'IȮ"Qnz4,7Oz1+Pr=6!A0̜;BӋ6H걾$$w b; FH3Pgw菬5O?^0:+r "P1IiCS)6c; }~wfޢL텀UF CH.u$tn *tu¦[ִh4E@`m.@byzML:MV6hJl ֎e?ܤCΏawg)$I=+NqB_Llg rxZ*?lUK#" 3۔E˸%7utKwX w܋_F72 XkPAD/IZ oMW,/g`ow0m7%6M` 3͒j[= ֤}P=^\ HP0?#f |4vβ}Q7|KP#,+Az y|'` С8ڿi'C=1Nzyv"dKXGÍ0XL&Dy,#0{6/%]Jvi<]ELru^bt(%J+2~, ?&8}_@"F&[†q;|RBczq ֆR4p` ՜( Hl- (.nZIוY"f[ɮNF+nYžrrtZzy껀} GRyF~&+h {P?Փ9Kn:/ ,edg[nEH qz:_t~ζנdؗ%sPR\.'3M49G?NPZGuIJAX=`_I "Yu{1|hzDgj@O93r]i4`,ew==L#HL%lSV" [{Rg+8;Fw ﰌE,b 6c9yp$~Dg-/)Zrqi꿐dô]+xD(/dE&]D^b\C-,]mاgc̏1LEaj.U)`>h8$'* o0`_qݼ4/rQS~=a_szmD]=ܾ3d`?t5ŒmNL SƵs lb迓4DFsQ3PѲB@qYM/I獥Ui }  |ZӦ1X)H٢z U4L#-U.^m#dbʉ{ΉU\Gr\\^rcTGO·gJeTApqYDL0(qnx8ZVϬH7Iӥ" =6ƛZD4_p~9_B*Cw gBCGH[<sjZfoX:5s-TKXo{Na԰ZB,KF#.WrTlU8 5`AFo1I_}^}|j9`ըMV2{GMt+1rBBU\ MfI)^->O8 Xp^|;Pk%hԖOb>'ggxs^j:Wҟ)z8=T\,%!T]N" 9Ī= @p_ɠi(4(Et586M;uQ˶BDH̖Xh\dyM>syoB3> nw@y]A{d $}–{0gLhXii  <~Qt q4Ĩ Û3ذ-Gf?޳Θr-pIPs&oky*&-Ǭ {af/(nYNXT1$R3\HjQ?pN+y1˧/L>\N4!9 ->JEU;fs9# [0V0 7 J NF}2,$t&5 eŤd~V|Sʷ /itk޲eXSsAVT2(TdfgK^<_|V!պaﶸZ%Ց¶]#ש_U& *0Ϗ*TFE?eHOtGi}Їbϱ]rAU~*ꋔY,UL%,kR3̍fZgڱ{(ڏKʫ4dTb&IM_~PCQsV<}24SY:|rB%4ǎ2q_$ו`8)챘 ߖ3BLn(R}+eBVr#:";#7 q Hώ 5R*+$$:%Ρl7 o 6 >t 9AuaĎB?aVhzf,҄t^5%mE(oʨD4o7D[H3O/Cg䌺A=ZnSi;/-B(v1XZ2lOC2b/:#0<6gY ѯ'ВS;71v". -fNj}ey2ՎELCwI|Ӄr8v0;C`:spc!5Wc` A9Rf7JA;XrjHsG܀w DٗG󡐜՘*W!nxzm\1hT_ZW*C-sl46+,^Ĭ&|B_{ v@|i4ORA1+ fի /vQ5nWS!Wf?j\JٟG9|%ߧ +_򲋶HwviIz غc l/w@EָKr;czo/6Y`o$YṮ,3M1Q΃VH?xjkb<\Iy,K6d Aa$@4Fqy/z})gCu31\j#f(-* m=mTt@S'' 7L1eTKbKE0?>|Ûهo8 ksq9h I´F2GO 30m!BL7v('ߔkl>BE;\NaPgYb`tfk*'M:݃XrKzHN|\~ r~=$Cs{!+`紏Ômdiǎ2t\z*yDTl3)N&f]X9n6=NzH,J( b~4aOk,(*"d/0фEG |9acÎ>(IIhL̛?d[U H^䩒W0I`Z{*v*F(h.@AgY"B?=<@-5k&ɲ?Q8؆Z`>1r7x²9cI`ʀ73;P;rTN o aUv`D_ܣhj-O6o\C5-YD6BYMG/9!y){7&H*cc2gLTn.;UF'f[lUke]Nft~^Q̍6.Ac3On\R\ſH x`AL`+%w_ݰ_L#PA(L<>|/O۸:kt- ) z fnw c.Iu{,>icoS:ap~Ϋ|b07k|5IC|ڨN?cr٦/Ȇc~Ro}: ('Z?܌jhǣuKub?mVYtv33;uo䯥q/!^ղԘ v/al襪yI%GD@7| I &_ū&Զ@%M+vª 92iN Zi'X&H\<' F#x)FNNo`uHG !gMW~CZp*V%:_ݟ{N |ps:sh(쁟KE:!ؙXn+&_zН93򨴔D@ ryc( eGS͐L.XESEzС5 W1rWokx Zbz,jaWwܛ1Y34 ~a+gnV# Ɩƻ,ʖ"ӽc:m&h[<2"q>V[ B+M<:A !X^,@2i@5+8b ^HbjWŐ !aӕ'9y V`` 'ե4dԊ`o!C]ldᜢ:IM {I,víbS$r0VE-K ً}'̓4U_dCd=s$(,Qh=0闞+>nMNPѽoGSY{}Jf qNX"*+A%W8td#c(@#Iʛ_?G'e8kI\KЧ bU>x_f0O[@q0׵XCȔe+y촯9l`S\ވrdKuA/ ކ7=K\GY$8Ozq~ퟷB~}Pg̡4nH~; 3_V~"X=0an&*gTBQa|AjrC-ٛx,5,u AQct'$>ɤ} Af)Q$VS0x5:ŹXSU}_fL:NwOHG$ed3+Gx8`V@(6-hxWDTS|TgiˏHދ &2Pn)}TӡV u"=e` >;Y᷋>|L?wen, ߀1!y4nҫ8u/U8v}[ueMLA d٬i?VP}ߋ@в9_ % nSk4:Y|:E+EѡpZXRݙVRsXȃcC?5O%mcZs9twȊCpzъ/fm\gM;wno}N|txN,rD "8%{A rlY-?<8LJ:h7\@nu IUA٧\8|H\0@C++[t-Bq-]3BUg: U(J"~hD~9E\/y$,:, SkŽNAps̍- )Ȩ:M>V+(Oy>OU\G8 |Z* %X p>Qw8N4~'=Pl0oáb+0W`ٝۄ.+@1gžbhT;<´Xj?e>92[+jc1qJMN!X%0w0..h+@Kn_K+_fK dJwNXWdӊW^ cGQVo=>+çjN,[<} R&`JZiMr^4rVwf.]MWCfJI63nIP)jm̓m Si2RSʍ?~<g|Qd:l*9YU#ˍ~hubU-oIV1_|0XQ~oWkJ7ЙqPEKW7/ÜPb?lvIeAꈺ ݘt-*T/ &"?=Ϭd*TcY}d?" Y(w! Dʣm *>V`e,I NHjW@ޡ06̫V&{H &|xڨ1CSz¢=z $ GۓpM-h/"tk,xF Ϩ⌼oa's{Hsen(빗 G@ cn@fiR)ឈ]pC6y3L>G,!DGĽ.a5zqѼ/W͒ڕńbKdkGl|ן;{G)>^Ͼ. nJVU岬. o6z,ߞC/%'=4C/n_LYHXp&e|}=6$Cܧ/ˇY`qAP6]<K;+u\R%*f7DˈdwpNjFA`NQmyu<7nH0mPao"Z%j\P0؂ԛ{o}8?Td9K#l}eP/~2Kjv3%V|n:<̈v}c䢽hvj^2fd ii=Ax;K0$#*b$,Q揉;4&<%ɷ"1VaAQc# -Lп0!1~X5وALH8_9$YtUjg '%ޓH`7JY Dș8=V#~3Ĕ ݚ[~ TY)[og7sVW9>7 \Gu\I՞_٣ rbrv@O%UNOV+r 9ss퓬b m [Z(^<oΈQm2m%BHwsFł.iO 5''ZdWNsHǕX!^6K!-)AEvҫ$yy 5fo.#h34*4L. 4$Xo.~O!bq>j.L`&ÅvCͤm='^1_VmC!͋j_l~K`vν&k@~~9ޏ =BsǺrO -$[UZLן,eZ[rux|^ mm_rd^펿^*<7K kX˯S8D~f}~xB?&yK*/l<9S1g54wW)ՙ;hlbf|ɞ3rhȘO0R]6)x1|Ihw- MNԎ[0C p j=1 */\W006G*Xy_P"k&g *>S xV1i vtDVwU"nAeNl%*cu8:ކ_DcS]cq*q6MX#aJ^ |T4'émB9ҁUg[#W)k$( #4[8"czL#ﻭ>&7-p02mH;&Mبg$ E {N/(ƜgT92s)NZ-=I(ql٢;u`K'AУI|{cw68-ʴ ;K ċIH d>0u%3%X}erp$30^79=Ťp8exF%8<ŭt60(BJwj^Ğ B w ԕ5RN*&cc}b-wW6*gi]/@ k~(YzuzC"è&r8J]e8~K}ͅXUx4ўV&8Nk+s|#0Yw:zDE$j]>ΦݼGAhӼ]Ny{ccdnƉ (pM˾k1RK'ZLw-)[SFAȳWC;7 (qB3H?[ O9>0&O4Hq0ܝU-@ 25 Gиa))TO.<) qR6$x(za9 vTZK:; >@-mbK̃nk͎ӌ)@]%_U8fw LZ>2GlE __v,Ҿ$^:-/T'אceJ=k\ZG93!{WF:헕dwm V\,E4ؿ?C2P 8:U1;xzLuJu}qF 82}pO/e& =~S48eoXdȦn`۴ki{Td06Ԗ.O烈)xZ]ԯzӊ6Zi M<:3Ϝ"$}i}L#Kq},FV41j.~5Y+3El9*֋*MPVIֹJXFjy̻ ՟f\^_`GQU: GB}ۺd5ע,\S 8MxM4$$1cDq ;Yc/6Z,X(ojV&-=NbKo}L2x`wmR0_]0",C\^Nƚ%5( J\{EϾ_!D\p"qjZLF\҉sP%r`]ZTa 띤EvHu?{D$2tKd f~dUGW?cJ'G6pZ)1㡌OfJ[qֵCCx5sǣV{n} W:7,UâH[20B._뙹@|^eqxѲ FD~ ik㞖#X8\9%FP<_Zyr2"~JLIw=$#g3 4@-=җLTv(# f$I/fi7=xB2[` />՚+dSY-a_x(4\1\x=|}QҌzOe#L>s4H*2xBo#^2ƥҡ]-,xi~:>5; B a ȓT `\΄\ԎFT3[nYs-Io#ޅqm_`V$vR-hBPcY3IS\`MB08SS,e}Y=s6:!wYtI4 A:;⛟a!1.6x|(XͭCޙ COzv籽l`AZfbc< 5V Rx`wVQvO (_<`KAOTUP*0/~[彡v^kطeܝ@`>߳ߡ햆69¦'KG5#˱O<'a5%2+uzBbl-0/-`-G1cRJ)Pg)PE{BXL_Ǝ tvs2{. :}~UvOUMb{mӜ4bB q|1ix{;2cM_mglF~,.W['Ov~͍M+jN{:g6]&`99uȑE`2v_Yff%È"%"ܚaZpeo4笠9RLhyZ9zD13f;2;> Q&AQ8]+'$d#~:cQpV]q7 ;tqh |j0Ʒ,qHJwsJn~ufR[^A_ɍ0t(mT%dI님"4/ָRW sœ<}khi%M  v a- n Es$8t+@yg;)棣iBw?cއk!(ӑ>$]iWTYEgWbOȎԆ q0NW'HRimF` ʄ|j$? KL3,&^Th,X רq@dji؃}^9Ef>6Sm"q0c_` ^}4j(XR1UIuam7W2t|,+7@z eWb7숪uQ"̭/+ܽ+?fYU)[itlu21v/ [BYԿc0ɺӶ;U˝J-湁p;s9 va̦ዐ;\1d$råCH&m5ո+%IM+pK)BhAԼ\ꗪ%9鐵D͚4R v>͡mg3yfRnpmWby;Ю}a~N9L"[~8<90ޭ_ KW^. dY=7浙۶PCsjߏ!Ec52"s[du,ٚ!~'Q6/*ncNoKD+j ְ,P6ehp-+Tt *|F $LLߎ]qd,vԙn B̩6O:ЩZھKzK+6Nu/s.l">a_aOk%nȽ \OSy sv4x.] ֞ՉMHuMQAlc4Ê55Q2ǁ ^fn8xFŦֹc'ɀy u-T4!=*nF, -@In,(IBZzQ +sV-\ h~u1CQ\cld]CmabEtKO<!,zs{[xt18>WVaDC,WꐓéחI[jh eAOʬM]NbmCgIr;ŶeGҪYfM[PtZH*_Ȭ$۱ӕ=W :uSf8z$>[6W8 _[r 7 I6CYGZr|H!ܦEW&\SdjtOr.7 :1 U D[^Z\~bȋWgb)…}^V+.x%j]eřf!LC/1="/$4yz?/E73ԋ{5dbf#,;I]eStQ?]ޏ~+v) 9ц0 ^Ud mteC"? ]J=Z?~}oaSSx Xv^G9UFařrm2z֊ 'XxW>i[&_HjsPpL`\Ίa)W;T;$BDG8 E=!Lx,|.嶐f("[yg? Rj&I*} d*52P2w]CX]E wn>W`dc5 $qeQ+iHZ4ntLɶi("w-D+!\2p/.hF(miUlfػSD9Lf7DuZh eN$D)aAd^c+1!iyInJmvlOm詈t^~:F',J59柽u}8=JySX"Vm u5{K|ۗz`T2$OA` >dkGTYr^p ôF_䛤I/ua#% JGjb)Y'ǡһ$QL¼VR]DL4ohg ?.wjFq% y5>BWT \*}.}w'>Ɖh+?-p;1E+RV"FD0i5RuM<Lݹ_GAXAg,Ll3Sd VOon H"MstYBM <=kB9/V!!P)[ֲnJҍJ{3 g*`D/+#%z-EX\eƤz*ν RAI}K7f0 X= #lXr2;ޗ2zjCuȪU t7z)Qۮs ٮlb@7O8CJ ?MhЯ(o~. /4OV6F4E 4H)yGP蜛+PWλ՜W$P^wɾVe{_C&9/.$ O&Qm&+`˒ϴkl`ּԿNY[Tf`E.:oqxUwU}&AI pqೆӥ_7AMĢTW䟯һj[w솾R̔ϯq;~a>.֒ξĠ5m26g}bw8DUe&q`INaU(;8 *[: 2o}@C3$y=y8we3[J%aJ=M3#D>p ZU*Of*s(iY}l:M`qbSg67J6sKb:Y07UT޺&` dd$})#KK>fLDux"&U<~WLgl k-WBX3,f$zq_x |699)\>l9/RO'9 [Hr3ElyXo <ƔtE[KߠyH#؂7c\KpO84n U`FؼOd>*r)'&%L!ORHXSsZj3csuWE9DA\o*Ū6В} &oQ/xrOzZ݌5(T"'1SFX-;-_0(_Z0)kz3C'`mBgvݛH).x7phX.:nIKךLm.wguS= i[0ř=Cm$@ٯy$B%qd et٤q"e,x8"tE@Ԏee&ן{nU>l8N{-d4N[FdV-_;G=;rT:C1#j2jmkRlEgGWe<rv˲[$+o Ԓl%&L?.OqL4[^0'Z:51H=Lp%'j}pO"V,\/ 9nHB Ɠy qݶ  _og^G5? ېSuGwf.{+ysݩ %DYRl\+OR5kSÿ#A$@뾂>\3Zh[(_fNqn"ÜO`3sYQAfy-,~\1ՐR7[c$KQ#u.һJyS/ȣhT0TQd;kdM(D%\:Yڂ ޖb~w}hAE\*Q+rIm9(Ȍjj`:29fniؑ?Bֲľ8]ER0\\lArRs8dl.aIC $SڥG)lrŇWM!4d>Q߿½(2? 'vWqH "P`XXKW-F=Z읉xªnAZNu9[qrD!1~oZ[[fWn$EhSdK`9a FZ]Dg2*]xV4B1ҘR=GAg]aUn1!@ Wz~୵KS= :]I=,TFt3H޾M'E[vgDZຝc!x*q;ֿ _8U 6'8O骸;4CxO[< &bt kw^ÉF!،$L ѣo_h<w<]Aa*doRz1 # Ud;ЉQS5ݝ [kJ]k{+a}Oydc]b#"Oxa7?TO7Jg)'x.?}/YfN.8@H!☨;oPYxj$#kb#y;踀FA-,:~X1"='a#VpZQߢ|QIĢcz9-_{j'ADAGVUn~&Έ/ǜ u`xyhw0k<:x 4k%+u$҂S馴0/ґpnL$9AB=A$O~xL&#]c (@s?$0R'KT(z &qEY"jzUea^ZbJw\>?wmF">&\wsHz:Kh:ס1H!ꃠ@ѾuL_gXl?@edw-IK')w sg"Ce~tA3n{ImoN5@2fJr9s'q $ud@WA~͏ u p%蜋02t`*%ENZUu1>8Iy7~at8f$䁨Q$&Azo΄/"/sa4)YX]uف=逜< ^u̵9 i{~hZꋚkC+# #vcfzoY6LWZg= s$0r#0G,-p,-O͐؂B%Iǩ67M3A\ʙaW􍸕} Z'bJ{ g"A ǯ=~U> z&|乗oC'?@hq'VȾgGާfĴ7DԴCMCjyeah VQ %D3W.hP;R2~R ]^ElT~i.l](OcTaV_V^7A~5 &hм2rd^RlΚX7̻ӢD or ][^2e^?T5S'C/ܚ(FP,Z ;޹ҕzq$+՗qlPJhԴ0l$ `EX3J5Y;c{˸:ܾeFKFϡ>d ˡcOpTS[s8i< V,sRcs}gX$ , VNm_2AZѺ S'KGŽi [r9@b1J}ڋ}LRŌk IHv 8+El6Gm0"T~yv J똌;Ç&Ȁ?R87LZ'䈫o Uv9yE@^ƴ~I1/Zp9 a0~ @WOܵ%, 灄4L~R pc+c~ %xTzWtKP #(Se]o ,lzJ0GAH#+d2k+ F%,6sĮgKEJ b`mNhuT*j;x 1d[R7z5 u6ZEhYr(b#*xCZ*@Ͽ"սc̓r }sS ɭv^NTK8z~9k 6lPE7Boif&a>-eIF7zԓ 4/?-o`PIhnIg~=;#=8Ӑxp~+q@Qb+L8|5"/rwaN:,x8P7(Ue)c35iu͢Sg#]ڶ=V HtzfWꦆms-\*A%H֗_|x1rQ6Nu?ItHJx=G(0Y4y65+6*pzae*onqGA^hK2ů4RŸ4A*PI$/G kg_\`G>RCxS;N='HF/gc'X ~[8KIYN7hy\iqsap4ϑC$6, \4'1ͪTMGm{agSzGPܛ,P"@fqNi`*/,AQ!n^ g <Ķi("fR=~hS RTw%V0G`ULݒy;:%DvDE8 "tWLϱ=;FB*/EaVAZ@da?sqąEJh/22.bTig5.Qߍ5~:\p|8rKE$2iߛ@^3tz#$tfx2)ށCn,>egmʭ k-;ċ>jҦw_:izbd+H'g>}osJ./qK϶Dy;W5|Uy#gIORSEG7C"f]A #>[~:v, cMygg#CdK~V !|nX<xfX;֧g[D9U>}oM}jaK[n'}ۂDTvh8fqa62 hI[ q_JlY2=-F+ /C>*WqȋO:47:DJo 5` UQZ8zFiy!Z}`4W"'Q V #yy/w#m* |Rf*F'=QqYeYU'p)#ĝ&?ݲ ~Zɛ>cR֝Hle\׹uJLf\Y|d`ʊsHRP~QHZy_î!Xa+/rNZʖ݁Dk^"0%,q1_&* 2ᯟ jj&I 64PaDkO+6ɧ`"ms?Prn*lpRL h/Bo<B$)TPG7ZIDߏIajߑxPR<'9I5&ϿOPĒJ8d 7zC 2IKyDD,uUv®aá.A$ZޢV#3.7tGJzPx=b@G(RO20ðkI ڀhɅj\Wx}KAe5 zgXrk sH7"ammy:ϼ(؏wQW#Y(RaF1Fo!-̽E_?u+AVPI@a3$L|\@ ˉaRm -eGmA v;kz#LJ=[kw~~^=twk 194PE T3z1eO2%s60|\9_腡TP=] }`DS|66M:Ml#܇d3}g$Ѥ{&W(i{l$CH~ҞLVM2ڼۥH~}]Yi U D\/Y7r .Lh=N*>u/}V m{QB_0#4X,W J㌉GBKuQIJvsp9GACvjAl@)[0?^thxeg Aw|H¯kB}CG.%wsˤf~r}vm0ߏ8TfCSU%UAwT:SM=+Sam(8Fokt\%N vj0֊iL%E2B`&rOYt|p zwadΣ[q,q^]u]0ݮWF;m׼2+oDz dJE?4`} :M0r]3&$Al 'T$|A<.Pݝ0&F{X% A]䤁l/$ש3a>W2B$@xMʲ|o笁C$6)BJMT5 *VtGcEȚj #yzJ,rA[¿>u$?qjv1R߉raԻ7fܫx ?{{ ">^il_CUYdz?e2F87Dxkz[|V-NQN0+yܱAs&[KPbhe8N%춞eoy%tr A_AaGBBt{i>vuZrjt`>x9\4A8̈u7>KX:v:Ȏ8nr,0rz%[$ 0Z˕\ѼQsZFNWِ;9H^*jPQӆǘ6Q5BQTaD>Pޕv+ldA+P4oSGpՖ~jv(QWAc;O^4HDc̨\GA1sC4W<*hҎۼB?ir23pzsBxR;8RYSXABٍ)%yq1/UP'EUiEa==t#-v`*\Dw {QolJ4 oۭ[t؎kau7b_ @ -9XCG3蒇}]j̇BkϭrӴԅ 6^"2 tRk xPq A5F#E_Si>?y y  k#yW|-TZmtUT$eR2#[ t/Id 2SI%hʸ@MudBo޹"OęlTB$S 1D ˒v`NV,/jEB19b<ر Fco\XsEs mzl㢩0&tS:37q@IWw%=z5Dv`ׂX"WABvaB=4=t&RnCh=%0$y1H_bq,3CϺM#rB ?PT=@r68oϑ}gh#,aYN>DU41P<Nq8n؇X+fv:P'u4Mav$?;DsVR@^H%:顡sQ((=ť+8M<ǽG5uK,2'+l.KX}o< Ty0.!Og,r,KçOAe.@rS5,iGaہɣEцPx%R5rEUٙқ ]Z0.M϶OxДe b';΅3aoԱmmk9x GdZ\%<#wcKlϛRHA>> +6- HRP6:,>odM4Ho^Ƌ7}B1w*"Pl>̀)kR?w[ =L #X^w4ul%qí']MFcfclfެuE ֪_@$EG-t= S+Y: -iR=67蚯 -㈜B@d ppLB7 )(ɚ5cݲ~Zrїm/ve? .ȘIp&aW?b.4s* EcOT?Ceub̈֌FzŷL >4rȂ(IܙPV Q N_oaXB-[]&,,5l>@0]')eSY&T/*\aAK ؍ֵP ߘ0)+Ĺ'ƜW:+$I7fT=Cx-á x!B)ܲj:A X .t8>n ]γ'Ksؘ;(T^TJٓez/49 zbת}IϷJqd&IQݟz:B+\?+Eq^+my~ Y\yuU义e8;2@i<^ bwzl8h$M )F͏Jk@g5|#ދ@/oҠX׺[(+t9?_nfYVRR aZ"<'u*%Mie67Fo /0м6bd8|QXyX:w_e\kGq=/$m/VʒE`mI <6J:{sLj.dk/f^UBT |k&#jIdTVۨus{8e|ΥjJ[x )WHOӰ"OWVo3*4]ʿj5%DG1IrF?^UxњYnpv.4qoZl0 _kmE)x핗1i`QeY@}Y!P, M/"8TLj"p-bd=֠"ܮ47CMߌG rJvS{gޑ{2ztAŽ!ꖼB'WȜz--ي'o U+U1u\ i-`ǡO|G4KXJhhIu9T q3Dീ\.HT}jwt*;d ]Z W0qFHVrIs^&JJ#ˆjLM',ZQyiWyEU?~Qd#f痠=veuDX_dJ*6yD_R(=z]YoiZUiHO;QGHNJ+}F)`?ԣS*^ =|f.؄L @Do&t^D u+)hCn|*B4 RJCtˬ iXHdF=?1.s~"WTVѸγ09`3]}}/"s"Atl2b{*mi7D>ӱ3|vIZY֌izOY~ K .o"Vi, iG_Z ư @WA'u[nlue>qëJ0:'pAS}Q|axh3&G>G. ٕGׁ6_aô^.{Ȝ<%G#jp¯PrԎ/NӼIpלt$<:B@c fWՙ󩟀ApZo˜GNPQ _hEm}g-A>Q]DXHEђcǿS&J$zv]eZ]`kW_i-ҎṣC`1ZZ5 F} v+!Dr$NMV`g3%(^b!A$ vo>=Waz9[ rв̼5S"aW@ybu'!{4GLU#y'pOvLҰ$z6cp\dpitl q"E93>@q{ȴL۠agDVjCJpwELJNaw)QS,te6%Re&&rL)pkI*= msWk02(a  1IH}H Ls2AmLʌ/~\,_"+74l7O'ty0AG3ǣ]`OUzANT3!I re,}!<-c>ɥ 9 2ӽ~#O &y۬y4MX8 34Wc `|9%8Uu=%VChSI2؀sə+$F>dUo%qhs=i x4; W&~۽9]H Vl]9P[ +-`+pK7^3 輁dj0M;ŘDq٠~2~&ERKE̓acRCxKBKTSt$&7Knfnu)j D58k֨&H>mtzC7W'8FȹsZar }0Zu dw).sW329e(Z0܃WIn$@?i0 -0cH۩5yu>y>٬ a{:bIp]ffJJ4q_Lظ8mg( =~X7|1^r/ͻ s;E K݇DiWR7aP Υ7rifNOG?[M{-8h&瓔ĥvʹݑ;=ׅjx]1ي-#Ou:>3%v'QP#Q~ ?$)NVK|Y%"=ٚ@|hvb2V_>N%e1>T>( jZu*EPY2 ,l$LT ل fqpWFzκVJLn)<6#$q:s,9U)cE{6Ij80,)J<إ+Z^ Iv2B^lx=-8)Ӟ{hKǸy(%007ӄEH*|1۠c1w, ﴟNNT]{N c}D60 @)rs@D">;k_3IUV2܇'>:"~`lWI9%{@lZJ*|B~^.;9~K`!2 `Fp4sj6vmTR1k-0e-h+X< R?"=y)/s7]r{efkbQo(8wT-Fưhۿ@7d$eA/o!rwoJtmol#,?na8 kkU;Twiǂ`cej&g&U쮗"$e{^EmWp9KćғBǮl@Gw|>ƐXނ D=ȗqI=Ht ~ZE,>$H @v×w$XrR n~sZY /ݍΙoa¢{/&Kܝxۃ"!2;):i8IJQG=Y]~6130k8!*΁L=? M>MОս6$#Mbcs[2deD7^ 'ɬ'BIUǚo XpP;))%aCn g5/r y#ۈM|K\d=lϘJ-YWzh(rGfVΌڄwJ4^ixDޔNY0F. Cos-;"J;WC j.8-`4Cg쩨H!֩ 'ꀐ-uiu~=N.5@7"]s0CJBz_bǬRU{ ;H) \uڇ p 4dQ=tAƤv/Z=yFrp?x[o(lfIC*:4Cjƣ~v鶊2 ~+ Em㛗8i5_ƹP Gz7!BY"ߙndWoW*s :+(e ȓhN:)Qdff%O?X?,:UZAA7|?YH  IJ Nxݳe?y>7ʵBz-+aG[*}㴈9m'Qt<L$~xj 3_BW.ǘ|KР_4 i S|ɛf8-c(D8YFP .`|7t T)"!LUIêXG8 ӁDpEQss Vw1(Kn {̐` S^䬋1@Jjͯ.ܟaM䐯ux-/萦vRU4\WگEqRbxpSIҞ,@ 1 C?YhUMϫDK^F񱓠4 ]>R0@']PK!3MKEhu:y_9DC{h_e1ëHL8(O2l5b6W!mFQ9}}.rDAWV 6^a*w˙/VHb;h*? &[V\ :jM=1A!WӘkZ"%3RN5>.͵}4#<E=Gl7dx~f'"qO:_+EQlsqD[u\$/p馋&.5PfVNs>!K3ҿ'}& =t(`c,Td0Mp3F5-0 kZqaX^)QĒ1[#=v#e,DZ_2rosm{JrERs'-G'(V $@a~`o4Ni4Y|Q]FZhͤ8Ln!1^aS\XH/PD9=%P_vPD/#m_.!BA)%.R)5`i+CoyK/+V9i3{a^ PQmK/ =e:u'$YԞk%Upi1\Oyt^* gӟh+h$~%Ed* aiH4fH.nJSW",ೌm':?<q+%KM?X"^vj45GӴї:UNZEG/7z?>// <' %k^^n`eƧ޷3Т/-7lK OE[#qڹFk44y2q'!wQ&EBỘTZfR}B H c? J^M48wsJr5t ,EGoהgcl / UEv؄E,N">/JqB``neRvk9/\\J,+5[n.wR:(S=JƧY^j*#Vo;y\0GW]QE,BZVWWQT)e|{CJMIazZLlɃP`:l%P =;CwK oUn(щ/9*#vZ}B̄d4[g&9MlKHVv'@ȃ fA}=G@E T7%Mw=qqǰ1e g'50JX,.F`39TWmٟ}zDR']+V<=92F ef5H,mjx|{vOum9|]ev&h>-"f]1 *OYWI0ШPpLtpV<7oѺ_s"aZA $6xs|b%~嬬v=qE<%gMtkɗ'HB`Rk8dt چZ[>\4sOOd74Aj>:+Y]*4߃zx/J|40d( ejMPkC~2Awk&בeP66NNE%-S=GWA\]`Cyi܀HVPvc%J@PfMTO {<-ۏG#xKR1A6Fpoa,Ha֬YG5H>! \ac]F@S6+ k7ꗰ ǟy֫x R_BuΥܚ.ZkZ[ bgM#P߀h7 R*܃ b:x9zS`݄02 sZi[vki.AVJ1RM<ڇ9ݢۘܳbk_cՠ-ҽZHzA85r CJЮxvCi/'St 2XTΜWsr'0 ADc TQlAoӘ!%Uhx{mȅd:؟2XмH2}B/O(>y;TIu6 W8F5/+L>tF47b5˱dǻpLˆT(51e1oY7ǻ^iuYE#zn _ KT.)P[QϧPu?_IdHO43 q 9}4*RHb< )Ԙ4%t3pʤGb~kp"痋G}"^׊ 0ýI7q yMX =ݤO`|>Cګ%ĄUq.,۳M&سR9\т02Qr3{f@-l rNn&)/,^!G֪0 Q8pTvNL߃%/=iI?_uj*S&p̴tu4꺌2ᆱW ToכEnH"okSP{RBP49;jTR8ӋY>",I 7Of.Oܝw/vQz' 6dmn]]5# ismkHjz3EÛ"N31E#8"\=k]fuh&&T~;<5Ed9p/l~+0ph)?LfF!^]ě6El蚸Y,RV?e*boGAɟ|sTiR>9ZRx?&I k"DMFHұʒxks[} f H+VYq_ Ң=Fzlaf9-Sc ^cWۀ d(-D6>!bxLagDP8eա&ee?9Xr"2}MhSiTE_h)Zڎ`wl!Ϧ pM7*hbL+UYZa -֨~{uYn9.+#̾ KKzDp6,S%<ssBMϳaަ VH]PЫz۲I}&ɮH^Z-8 iSHa{8 >+(Qj {:24Z`_rԎ߅'nkS;x/$-2.9n#Ds0 /WX!X [VR^>-3?Nn\Ur!H@V=U0}0)e!kdX0=[P37Ŋ&`bw]Q*+ods&^GYɓ& [Z9s} ۝|2MĶ^(B1LOHBfMKK,H a(09fx5ML33 @뾞(K0, G=QOf$qcG_^L/sP_ \ڴ6& C Cjmk$;9cyjLܥUЦiکE' q&iһG`ڠm vDfh}hM"tL1X|X?oB#MĜuNF]\Fx䘝Rn䭇GAX2&fd+oeo:: s&IJP9";<^3~ xѢAH]Jlq.ίM_JOjGp%K2^?ܹԾ1+-: }AH؄æ >|B=8+? ]HvXWC"ΐ?V꩛ #䩲* M9FϾ~F_W*EG-ceemYЌ}KfH?э Ji JbX[nF!t*no**r;oC-@@bg\uk"L:wHn˵oJîXI(O7dzh ެeOmqaވv,}ZġVoZ3; HCڊ$QbX;kB#w"} f֨'kq 8@%lFٍs1VcuVA$w ! &MQG=KήXTI"b9%^`>m/ v4kvG[9@r,D)8c(z-c2MBQWNj WSGP ƙk:dmg"yrU9M6BZ(N8Z* .b, oG/ct<꿝qZW[;wlSiPmQfcָqLz#T'N$ }YV~IĮC`wO^JM:?F5X}(+(˅iM)׷lޯ2=#k941qN}؀y ]}74 3׫0{(g*Di=}Լ%rJ5@G"o=`Mf؆5{TM]O=h(182ܘE'e$0oa X_&s䓲j'.O+ ›3e%gÒZRkCbhW6{'EF|odGmm7\*nc&+UWnd:H-6s6ӉnE n4&%$&v拕gkQlӸ"O0͸AY}A8絮&p \lAy,$B%v饻Z $ RqUAC<10Yɑ''XdkND^ isXU"(/>5oQ?ˎރ[LJ;y&TIO8euMa-2HN /Fs;?}(vW 0X_L]Q:?9]RNvNDmWg2GoMAvEiC#~MK6(ܫ/}L4zJ@$ӟ(/Ԍufܔa"`؊F\XqKLHwnUj<'Ft&<1F,9wB ]X,\V&.5˷qN/wG/ؤ4C[! q1Hld_twc,.~k,xc lR;#dum'Q4BS0,5 Di?Gb 0)6!̪j{ c&h> uN@3𞍺!^LCp4xWl\8{` rYiXz K %ɦ_Lh+.KwP 8?YR%MDC Vh}T{T.`6Y\CH5tS.@̑)|9r_Z>A5>e< n ,R#D>1_܍W [HD=W(=9 yG`֛֦7I՘@+n*AʥiW $K-򼐄 .Z.!%}z;G6$]Bt \Yz1wJoDVwPG#>2qFX&crO6W$+8ha'g^ć'2. p6xhF/s ذn7,? v(0F,DwAm@[÷Pd`%j1HJCŖ.XK7(p|6% $O]u,3eFeP*GvUYI.*rgYoe#j?7v0LB9 Y(Q^Rwb CqBuu"~H7T1bS7ݕqt+ŸV+1>DG/d;pG .n8Q($O?5gHeou?rfTK |bK"ʧhC)QT%. }ߗ iR}'Uʀnu%}%,ʼnu{%mA#\1qA6-]₏W¡xy`vsb?yM@?ۀ'|.m>􎞕; tiIraK_W?|>4щ6."#UhE: Ypx1v9+Oձ3fLϿ& \g@aSb&UI5U^g8Kʶ#'p2K>[pZ ΥmFL-%C <$V!S d?pmRJ9:5ol cghBNHA^zwki%)u+I8Ų׮i']zeaAGlrNYa[pAC2{_7ZRZnKuPj@* Jnob-!# w4Gn kB߭eqq*VGx9){ zT-0gېڂϯG;d2p>m 9Eò8)/ҧ)($:DG{_OEe1H usTD΋x&DLUH,yK5%&<׽CF<x5UKXu+ņ_g3y <^r9ػ" !$}h|*wk.pQW'hA夸@-* 'eJ,p3xybQmMnx2;yL'S"J({ Ğ]'xfե븜LoK۵6lG +Ȋ?UO̳?ca ؑ N12nUdx){‰ߨ4 y=]Xtw3u 8 }VAcg19j?zYpd ڋcWJ׸*\bP}$44پƵNcRɅg9?& AҧCةuʐo 5Dq.hM8t.⍜*lj{ͱA+Y'Ks3[SzEgpCW^a_'.J=88GuP@X7]ĭ!N?ZPAq!ցsF/Vn#SLcR̢͈UaRYcaD簡եjpy-g#pp39Xi*sFbƕ6˻S SehKN1;QmQ19#Fj%Fp=4p=0¡1[-$y&0esl#Bqc#NIO?gѡF /y] j+lmX 48?*#v. ڧ0FՓW#II"61vGY$dUQ ASC\q6~a$Ȉc+NgmBV @n {-)_S)FfĐjY"|DN4D ;]g@-ʖ'ykZ;z%ȤRULE0؍Ha㔡(֢Mt+:#anÁ++I?v9@!%qjгfC5pVMPga@lJiRZޠ|ˁ9eW$Ƃq4ʽ6xTSVy]#x~&{7%ZiF{a==LIv&ݦ?&x^|\X,^r3r6 \[gjfA\o  "Om$ijHhBAN;v-1udչ y/ZgP1ڒ9kinGU'p2]s74/[Fnk詅rOKYY* HvR1`=A|(?O09 )1I Bv hml`9DS5I*asYofX]U2Z'SgN'};4L#F9|uYB sg|#'j_fq-WZ]']A`֕{ [8d&{qcSͣ{F63D"ީnUdgFg4ֿ^S$b#I8l6JtH:( _576FGjC"0;f灠!C[9}ĭ|(՞Ssl}3޿rܷ&؈z.U6̣ߕ6-wEE?yEx jokp<@}=WqS:Pޗ;HF3=l/QM;ˇ6ƆMk{;^ιS;F>; Ԭ_7v,)%Uc 8֏zNQɫD1ks*˴@eBS sdJyCNT(ͷ WA54%NNNZ#"M4N[9p-0j\ ȶqj~/B$*W)DBt0j훭̻YE8}f.N|f9Z:0Kټu*K!Fs x'kFuŽsT>|Vr( 7*JOS7gj :"BtpD, C$ibF-;{_q#Dmi߂7cs o>\}v.45[ `_<43$F;0uCGK4{U<*Nj b`?Azʑ_ nitH1pTXScZ!|V6B%HDO.$>:m/k ;ƴFWsXU'8?I뿊I,DFgaOE%J\S7r:=s;\h-sUo~S,8xji[ v"uJ~x #nΧcOfE iE.4Gc{kgf E8b2 l_|~WX`UJջdTͩN)1^.)0{``70OL?/:]Z?N}iXꬖٝAMТ1&XA8}WMSFi+q]g-hG hf機S [=Uc7\5m9z(4OI?uLDcOԯ@F䏈Nhtu'T(cO? aΐQpbv\1GGhgYڶY l.Lh;UvIӒkU0isxc >JbY9'WJxvUi5L^Н|w%̈́OI:v;3bA>j5o+& zpZ %o*z]0E&:_k3Q.gUeǎפ_c zx3 (gv91 oN"جR^Dx5Pڗ[o&90nq3GF?xJ[k1˝]4r>~tj1%JO{7۫}_hMRk0ԣw+h%7b8~f7=-)rѶ5j@M# B.jk-ܶmo#?3@uNPV>}GY6jkT=mO'+(QFkڰUel>z_75N#@<}8tAXnIzVdb8XtXI/NLf0 )pCKj&ƒ䗳7)4 g^T@ \ F%.sK<HQ6 `m`oq5$׋Szhف8#M3h2PSTK|o[TNQnbI{}oثa#0>sßeJ=pY,юOjW +V/Fȥ*l5ʐ쏩wC9Q4,@v.őog8]`+˜9 |: WRw@>%iPSH)w(0 TmxnoYQs+Co3%z xҚHHV>n+dd[Dw`28桋bo6=g(.%0w` ޭ/4G'P;,1RQ 8ZܛKIR8_Grhuh"rYNqzǝ 6PqӰP_t ੖7[Ve щ5<'%M7GQ@&O$\Pg6𔖠si;!* 'Joh?β".H0cZ_C}J;A_\iΑ(9$jy ;("m%'K$ L"W2N )3=! ~"Z]"=ob@Rd> OI露LECcTe;]PBro_2ʔ (} K{@ z.7Y@Ɍ#jvg:j%HI=p%m]&D7n9{ &mI&/ *d!3AUX6 PhMТtLCxC<_S}[r-|`Шx=W+HpXUH.ngҊa6(  &ڱ ;w<b`ܥu#=?/Plj:Qp%b[Pz3Pq~;"rn) }|r |~? ']kQc_ș{ ZYGٓ*>-i'd_{ vA gïVbsvKʍJ2UL}CqDL~+w(jF:~>QNE_qNI>dMe?؜Ѳ]JM<wɪSKBӑ}kHby g:z^LL<H*@ ߻  6ƀ)3څb*G2 KWrV=1V$ULjC'Ic~,Vn58Vjݦ 4c|Tg[TA$. { %UA\0?0Y26(ԛeQ1hW8!/_Fym̄*O1wNoaUxE.ʲPr"v?FpbKxx@u*t̃qИ<րs &dq Pkp@~'-!?IB܄-=%UT?mН}ISl4'C;4FRzo.b#WN۲Mn'rl0.Buٝ.D5<.*rVIgJWQVo} NȽr-B<©HƍoT~M0ϧ'4b6K ".H m @lL'{ Ž\ξmqVS^WmuA\FQF y?"xWuEi5@,|2pϳɊtA:fRf879̓UkL je!Vb)ob7w )&w<x0ᡆ Lj`u_L'Ϗ^PO:0i~ Rw|5l:-,.z9EY`|jOZ=Ȭp׺ nz^jh J+M ׹G:%sHJȵ= W|yG=B*%LFA8ᑛ/ޫ٥VA601YL<׋"R{{$+w+kv#mg{3au_Ie>@i3nΈVa=d%Du1Q6B؛f0㗝Bcxp?XNwM:SlcW-ֺ/0vV/& &|>Сx 0.'h<.xA%%#=9ɚY{892GJ>uDU։5Y]_@Bxl)ç[Iq7?wVhPyŏ]PN^mN%=$N&AR̫ gcvj}@*c9R8_%5V)l=|q|#6asa>0;f l6a7HR4]X%@Ro Sr8 b9q~C5UY18Ԇl,&Xy;G(Wf(_l;&쎦Eվ9rC8!@Y[b ?I$6O tm;7Ӹ5hN ]1M%?A͕0Vr2㓢GuR o2Jёz/ c1z3w =lz #3F } 0e.snF6sޝb p1?0GF MG(@֧H{h] ;7h 61NߚTgC4W*OT,RC Q.n0FW3w+~JGmA5@@sw/œme>g+s{`ZS)_mJmoʖ]/ pMBp/,LecF62 168.q=Pܶd4D2Kt>7QTcL[k%!5<lX1$n MspfViZE}'`'oy|R")ns_*5;|*1KcTORH `@Bm(w-ljbHZ|=+u|mc1 +/8D\ذz^Y//ө ʹw9 ߜAZ<2pݵ%HƼxkf r^yps yMHN oNMEbm<@1栢F\1L7mn6ntVo6rwq³-L蠅ZO:?{E}jZZ^O]OfM5G_PGALϑ:@K ǜe -ݗvv`Ԕf AəYxo~>hMWIxrACb cq K3m?*-h, ^yr::zj|ZpG,ūZ%ڒٹB_UYb?6?񂞗"17F3[gVK}t&>4e=Nִc_N5Es9DL^`Jr|؎[i9w*H*aPjg;SK ǔT%UkUW|X ©D|ϺΧ Hr̹OoNyWOU]e s>$F߸^ SW;1'C 0k uW vd)v=˛ N몓'Ҷj|%< `Y88l%w =` lȎ8O]p}? @b|,n_]˞xk+gG2ڙxOgz{v1 &9WQ$:)(~ۙG^Ƹ)Vr#CJruje .pHUcA/jSpfeH!5Xw΍D oۍgÂ>8c%SUM8ӣn#yM5[fO܁CuʚiO>0) WtJs^-N܊⏒8^}[`U[p.W[FxЭAB\ڈ*tY\ZD$rFsspT`al#<4iO`b 'NE+CXr>xKP GSqah2Ǯg#>2hlrΣ]zVCw݈XU,ļa, /uK@i2(%̑Ka]gUeNNJ` 1"q9 6c7AE+g6{`w$*9W7n80e>8H Z$'C#P7YqxÁV݄~CxR D,tLmG蒜Ee MLr%~Je~n7ywq. 2Ѹ:u{cFŤl`TcG7MΦوѹ<g@b2 O M7W6 j*Sōc\i>%mV2x醁Hޭgo<W |}GL_$Rv:-E3-P_*²/WKXi> +y6T/HI]R H۱ Ţedn-Ct,Q. =3]Lב;㋼>p!Ԍ䲜3(xFu)ts`T7i M-Ȗ<XϨ7Αd&ScfП- (-ICR 7AͭlZgraL.Hq[R-L|.ҎՊ[=rj(@m2~:FnokEjXA?^Z]O+DR쿐hu(qhlP4 aMz"1Sd^Sׯ4}J ,GKJV~5ECxb!us@.C^ l[H,HWJϾN"ppEax$/]qwjLŝ̈ gQ(G5AF)2eD#uSv_HޭHU(SF vYZ{KImzdqWo )~o5zSfEôîuŤweXeyBlU%^J{GghTDcʫWcgMS DX\8E Ba2Xe79:Y8Qjd(U:rGa}AHGF?>'c^bSFPQ2^ \kPK5R'~b򇫁Qd 5M,1m]6f9XFMtenrH3unC4oq<尃`!Haaer8?egڦXNuw)LCΐa)єxy'%6HN LBt€zsn;E(݁燕p=#jh@*COKՑ,wm^qR;1ӝ$#$1:PXZ /uQ n?/7md FQ~7:ӬPA;̿A]\o\Uem6-:k0v~`AzCGwrM &(޲=_mF[ {#e94+Ar؇Ubrqd]*EHIV0rM X]0 v:9bV0EB2nܱ_ʥ=jShweBz96QR\\͵e@ۖO|N1siEw?X 7βbuDwQEPZFAd4蘃{6LCѤl*'4}Q02M"Kc}!CpHgxu sz%a@ȵh+<3i.>pS;RκN:Nj"tEsBr_/*/.\|1=3m#D"o$mIϻRٟ%| ΙlE !$ ZVx8 Lz\KVQ#$s]#d$JLV/ [G u&C wFC6Wt)Ik/Yt3[uRga"U>2h  #5:4!Q#Apx"PB0FAt%a^a}[F~T,bI1*W&k;T~t7R\=ǭܤ\z3'Pdl{ Q{퐡Rq_k#\ԧtea8xS6M}HX2.vǑmY`aHusJHtpM-?\HHT3 }kD^ZnU-أ53HRx f 03Ѿ5[`6޸iі=W춛_ZyX_7X?[ȹlz?v̈3o8RpX@EP]Y޳Fd>Ig S햃-!YZvx]snP q|m$,if*uM<{F<ā  H !a暵~;p *~Rw\g~ޛ7C7N/NsoZ5n'M}jӖ Žm4} {#wSC!a!PN |L={1( ؿԓ//JPL_x>he`RMpZe_\'1/΂t!6}ۂ/}g-$ֈ\{w"6c?j>O !`Ē&[oCt!BЌ[%`y[A%}ĝ]%ԐN/p1 W#7|؏V͐qz.;ӳLQG*kaP i30V l >Hv`Xlb,l<^Yoq2+O,;(pV>*s\J=k[0V.sȜjP2Bػ]ycv$kN)yFUpJp(CƍPSJu2yۃ-Js42^B9 D'/ VBaĶ[[ҡ|ٛZ1ïqr~[frnCzMYAZHmØU'̘5E۠y|3 ~(&WOxS6eg#G+4Z٥%XcgW$Izl4IM ܔBhQ3ln +Åׂ0J=]G0 _=>9\G uT:ĭQmaoW+KjqpXStZ TΘ UlAvs\ P+cndfNRw )>^޷)}jF S+y ̕Z'V! 0 d7VxIi*6(FV i&/@;53_SIȎP%O ;6:8V:h~ͅ4'8pD8Gb&chmPF*׽hЏ낐6TQ+1gr@ȃRB$(S)KYoレh] _Z\,N:VXX0S?L4ǪTv4h򘪾*oӭi8rT1J0JgtVnh-dlmv 4E 9nq93U:t%E~ý+^f<FF8Vi焗je΅56o%T?ϤG&`P@;zo+NlfyAd2Pzo"7^YM"a<. ^eCQD_tѕ?HV >;BY͒j1 2 1Դ 0ךaIɡv_i{/QU?O_5$R=һKckpq:*m~~%9`w9(0d cyx]uh|ȋ%^]"Ñnx͍Y| ')26»Q0P!@T?nV& se_ `KH:*-_]ܜȣO? 5=?N>\BIWZk3OAI_7( h'Fջp]ҟ »/H*\ r{Tٍ0 "xۨvcMLNT.)G)>ƪis5n(OL't}r7rT)d7o7Zt*B/~l%mGb%WYV- cjp6,Iο\oiwdeKC? .*hKv^Sˀt.Ouݥ)옽̽>z_wٜj,9ʱ#'gd|/CIFXܣLN'YG3=$[#)98_ZDW`0,sk/Oؖ6pQCPw+MwDOiӵ<^U3q>Q`ڃ?*7AS}ѳX__[A*q=jg/4hԹqۿs0j/^GhĮ[0r"E^Bމ @R>_wf=' oy].[}^g 7KfmGՄ~%p/=Dc}H#C*:O/WD3Ly@xD܂ضq ,aT7¤v쬜81n@K%;Š\6tcOF4^,<\Ukif;2 l=o|ɏϵsFX9mYP *又iȃ!Zͩ C1ZIYkxtpզtsS0qT grou}&{`7* A)glTΜ!5CVo,0B+ݕ'J`S |'X<fPԣ9ċ,^l*Ï$UEqmQcq:SgnΆ;ѻ$08Pw*Omn6S*eTdyiIȈ t dA¾6#5ct#8 0Qwj @s+L(e(B*f7XBhC]!3uJ&G2KbfF^$g/ny.hUxAWWȰ{ $F.Ф+sI:-w?/#QH$Vpo$\0 k\ e |cIvR;qt߇"V4"p,"} 0=6;.72}nS&@ؑ.$._B!BO/W sV:r_<wE;k/' njuGx 9iB>!z1&Q`PS2X|eN+?)IV0Хwӱ*Fhp${BdORÃ)z <Ӟϥ}tic#\6^L^NBbBwعv7\ +vu@# -rcoU3V8RmDOqlG>]PS^h$b { SVgC`ӻlZwX|a` q jN֟Э_hbX (߅݀jPMxꤏ w̾JY[Ῥ}wG>mzB ߒ'g20d[: a&Dyf=m HDiJG 8V7-Y9R_&hjҸ`dބRxdl{gM^K7J 꽥HJI Mz{ȑVAOU-@dqBBX',\+x姦ruR+0۠h*Ga-Bs/Dbߡ_36K<Ҙ~8C^U8phq:-QSC pap{)VD1Iy~کE1TfnOYUe9.sSk ~=EA"~\[\HmɞgilpbJZ  ҖhF} ֤V y'so'$bB?nrZբyzq7Pmb>U1\`?vo'Liiրf4/;k3^]Ĉ2_IuS="7ב_2XG*ҧj1 S?lMeAQEW/&jS% fu!tr'N> et 79+O=JҚ <%VyksjEp\ %ʔ OD8L3Tת\A pj`Ȣ!u[ON?됢nbg 29 J٥jiulɿJ :+I&-yp ~oR^AMݯXC},r~靽dTKgy97?N}`AezYC˳Zg{dt- / ]=_Ar=MlW3&Xuŗzy( IS%3=| :#.q Kkős@}ABEUD)[m G9$b*llSrILN&[t+#J!BOw[Ҭ7`t\єkzMEѿZJ֫QTQZx?ՠ>ԱL4肭'xmP)3u[ rX& \81EC~Zo_,`.qe8٠>" Y3Ms2@\bR[c;/HMVBThBs=nGhq~L.2 ztmENKXfOלGz{S .O}Ro[w抔-;f ) @ cs/P}&7kBm%QJ;4(@{zpogZ!YbS|H(eߝ]ɆѸq@ -``ia\VoJ)df&GM=\w~Վ-;2Wp[[F.k0KM\{;[H!!`vk~}ʔq(ʃTU~FhXB`#h:&UFRi'ȃARP332,O;Оp1 :%,?ҋ?EK?}6#L7."-֧Xy$B{nkPQt(*aKN625'0';"_)E?H:i'Lq%) d,bX4LFM+ ^nY e9حpMgdd\=% ~-P͚J"ȐazI{蚘ɌmmcƎ]gavTaXR {:/YhkoQx"X^c_8rChHdZ۲o@ ڶjZ; mkY (94S7πE{#njgD0d x0zڧ#7OqyK3/=+y2%:ۙ\ 1`n vyHTpm)m/(jT^fPF`V]NO˟_H-gda"Φ*^S=rw^څ9$ϧ =qZ7L33WBCGd.hBdP ,8Lx>#l"(]%bvKGL(ϫ&;_74} ud5mv#n%}I`!@B\Vc )EWum5/Ce iʞ` jOJU8iҪ_=Acy]xae$~LlV2qMe>hQV@x[e)nwHg&>wu jD\I,yb`?f*蕝rF~oV;#wHM"c3HBX?@րEs?| 3ITd Z?`xT D>fqWZ4 mfjք&&0n g]a [eg5nMJ7h SR Gҳ}U@YH߁xG潂5psT`[S ܬ}ڒܲmhI[敆Cu6nt\ӵ4_r1s_[)ρr̗QyLD-%k#@MnFreK xqJf #P̭9-"}RJi?6LI@xeVRl&DndWcB"` #= -KS^Yy!>+قFRDN@Ē޶h~wF 'EЙAk- @qN&`;V|`{˝mx4[]>lpޠ%l5ԯ%6㕵lTE5֡WPKo"MJmk򡗪'UD65Ery-$ХVxUBإq{XƸL2WP],|\"ZwǾ`$~ D٫'lSp[a`0O&gq(M°RIqXr\n'jz/Pm[Ut{& ?;J{"!&bTcW.k\\@jnЛeu͜ٷJK|ȴ 踝n/LE3H=OWC;X 7$}O&JPrtE? >Nݶ*UčlzV]/D԰-"Rv %Cub WXy}Խ^+k?h` IuX_P+ŒѲ.O*r>pFHAमN_AjFg7]Hvf!~ռ&' B`ǃz Tk1cJg{-R5WcIqA v'iY_d =d4*NYףPxZA ƠVtoU"5}hyJҡ]b6\r.NJGZ/QUm^rOvO*fIӠQ7=VD,"  ! J}uHĔMLRj݅N,k2<P8\)ѽ$oQ#(3R3v}9+sl[p.6 g'ʼnY>L"$#~ԅvp%wRʝʝ񖥾pk񽃦g{LP a57(Rl)iNz +Qݔb2ag8HG8YJX$4ĭ4qĐىNV9U@\s@,5kfKF*hvHKiݴU` .uo8]K ItXSg"R=Tq Ӫ#l <(?$-%73݀y;Z;ۚ)Ғz_S컛ҹp)?Y#>ބO\U][H͕A "-eRXPjc2FKc?e`  *xJHk>4 ץɾ 'TKڞqBպ-L'En#`s\bgho'wݓo87{d ґnHJ>$ja9h 'Ai 5j-*s +Ts )iZqJTҗ0 4U$IXi7U K#ZV24_?cmv.Վ:b3OS>,vnPTA]'< @Qml=MObEa{^E{tYiya:bQ2? (<z2b֔KRÇEA0U8p\gZ}O%d:{F ٲCܺx%0`ٴZK(fОsq`hz(o@f!e[F8կz SSRj]0#j xihW|YhtFHuZ ]wgarmO匸 RI}BѮ.%8GĄxTqKzƫ5.`u \8+ g>MCY|;~q>;_& )K&| 6x3nd,?2B|GU \j|r"ckN+-E ffۻkA( O_d"Q\uՓJs @Y4}/&^ T6ݢ<1=WVLe8"\ɂҮAOZYM[gBmc&p+&^S9POPRk?/!&{39|{Ll2l+rOv5,c/,`&-jqȘcɳ׳ myh}u|1#j>(ĕ|L(y %FVhpL^Fwq_ ;شOFhn{x: (d|o5 bDȳe}HhANtPcisˎ.ND)zkVOFn#fɨc}HyQ8lז)CCH'coQG[!$h+˻ jCۼCE ]fc`r/pE%33wJOl'%. ا^_̠; k(ݦCfC[hawEպSGADYi;4#X@/ c*Y5<'@95&x+?_~]˗TS B)ׅO4hM#(Y-{EUɵOh!Y\Hm<E&\OMzOQc䕠G6hty ,;ݛ_NYN-9uKShkZoWHu<[4AS *u?ݶ YZ