sssd-ipa-1.16.4-37.el7_8.1> H HtxHF^K, ?*}}, {oA0u_UJ=Iȷbeq.49c433b3ef3e54f393a36f59133572975cf59831xH6%>bIc'F^K, ?*}}o%Pk9S") #Gg4>GgNI*| >> ? d   : 7=D   , s |PRR R(809x0:A0=#G,HHIdXpY|\]^bd ve {f ~l t u v w x 0y LY Csssd-ipa1.16.437.el7_8.1The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.^G4sl7.fnal.gov oScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd "0K &/A큤A^G^G^G2\/^G^G^G1815452e0b5216139ee4bea6170c3e71c11aebce10f02fa5d5952da217c5e99fa33d836e714520f3af8cdbcf58c7e34e3beb11e17c82318b069b9819b2ab07a28ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9032f07d3daf03b8624b3a656910ad9d6bc73a461f132f31b5a84be8e2a7ad3fc80c510df46e840bddc77d509525742e4a659bc0a6e7636a93086d0851856c8285drootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.4-37.el7_8.1.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.4-37.el7_8.13.0.4-14.6.0-14.0-11.16.4-37.el7_8.11.16.4-37.el7_8.11.16.4-37.el7_8.15.2-1sssd1.10.0-8.beta24.11.3^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.4-37.1Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1801208 - id command taking 1+ minute for returning user information [rhel-7.8.z] - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.4-37.el7_8.11.16.4-37.el7_8.1libsss_ipa.soselinux_childsssd-ipa-1.16.4COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.4//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bd43b5f2f55ab4ce7c1a7a639e16f18616a1dc0c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=5d9665f21d47931f40b8c95c7917990f0e9be725, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRHRRER/R RRRRRR>R!RR#R$R2R@RRR?RRRR RBR1R,RR R3RFR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RGRRRR=RARDR-:Υr0S5utGg!ّHq,"zoCsffw칹SFbH'w@,i!$ȝA"#^}ƺ;]p|΋RF=b+!8xc^;xkB[>u)aM`C< )9x7U|m˦8G+!U"p$xXX(e {Qײ)\7뫻;]KF i`9бGζ ?#ʡbUX^T>m۰)U_SjAvZQgAObʲN ,~TIMemh/Ć;1p5=SPFn !E%9/А^ȶ\HgϮUuҾn]aZGW>3Q9˛NVj.ѶߢOGٻ#ԪIr"Kʏ;j!Nr1d{.5_|X=MN e7k:q1dY\1~ ~7BVvD/i.HD;u_4pK1HڄTSbr5U􅸂%9Gb1&_F9֋2+ƽS SGwX¦[r ="c;쐂dw+orkEl F<NQcwePv,d+KW6[ K}[=a^_[38Bz @'];bsVśH7QP~)8rB9vq[xF=/O_yM>&gC>cE}ϫH|[@,PM6T~tc!OJ*7sMZ/D }tP 缕ITA+pזˆY8N,9n"ʽ웛# ||y؆&Uegq ]skD% D `p}fQ!MvQ[U"X0b47ΓW |ez}qf㳜&9j(-@:+';SVq}UU䂯˷o`̺]DIn jxbGp_HWa z,0]GaJSW\T!P 85EYU0S6H35Őcj۞*?gLZI _@pw Lppw)ʰ4jq ө^f58#&醿0L gO}%p=8 ]-K3qbR6|q||f"tʒoj0i 4*Zz;hp~B7V\V)"Q O)rϴ0l^oIk+ s 1U5k+Jߥ{Nl˚g_jQQm$Q,z-[ 7!:4CM/ﶾbn<@k#Wm(Ώ._f~7~JWpH`1dq2A#hs;{uk׆^-~%;Zak8*bDn k)!Fh$imHHƀ6|PωچyaN陝ln0Ԇvv9;b1ҴK_f fRZk/+b4Eb]^+b2c?_={,w"Zʖ CIVD_ hv(FzjqȘϓl!O:E\ !Rܨ5wnd\l?Xw9U|敃3F=i[^$C·wa;¯_5rN9[vuK&\:C-:(<^n@'ރsW3Ct}9IP"1`^P&`)\7 MDt l_Cy ^ɹ^>=JH JHj(6,JN)쏭#li qQY 2Xg[kӸrM $ w ⭒}11lH-ifQ.)PA3U! ],/K$ I!X3F<ӃWNM$CGZ4mjm13R̻(UTvI#[ ]sãB( у~Y68pf3-{lK=*ZycmZzRYpu\N >T $C(.^():[1TfOsi eB۳%cy_a` ZW~:'fߨۇ]ѡێ5Ӥi^~*\FqD{\~;v^RMpJM)F}Z%trevj}x)Vk)*Ʃwƽlg-SyY»9:gN(C"jQq%&bÛ4BC bXoوZ>t ] 廤_ι[/hN:aKϒ4/DW ƎPS+p\ca}%aZ'1qW+Z%pȫd.wN Tr<,'S/L j`}$VuOe#4Zjòg'%܂VRqL xAkGp0GY`(+R3<]ŀz@羄IiEHz$-KZcuX:Ls, /48<ٳ^JPiMXxv@/X4IlywPqpv)0*܇WYYFRGuSMQLIk;b'IYIJܟ< q~Ii aP#-v0ColK;AʚZ(OU0>p{sU\vdhs. [ki Ź|+Lb@W'8Z l6(@Ĭ$ @]qf($lL`4vPߔNX6B/x"8b?_k4GP?{*@+!g=3zɜ!ѧc|3@f~h&df6"$ǝr|_5r&8 BX1 s(8AQp/E1/!W+-rh؝_V$&m% 6sogY㹹E$?:NEf_Vhdm?L>hgdé8g&x'aFd4{D, 2cKxړAK:S>( N |WpQ̤61aeDKDQObWwХ~PȮSS cjsfF9b+(&6SGK=}rGzUH? lt?&Tk.)XD"îp KyBo/,q?nB>߁̴:5P2~J~kѣa]A:hܻ Rt˾⫋'}zh=q~QL&f:AQϜPd0'C؁i $è'A~"\@!VB;wJqTC/.~By#+>FP2_47jm=]N_e9še[L$&tVx`3|o{j-o*elpvui`ka4G܆ScvTeFv*"eY꼓BlK5Bw^;AΘ  OK9l;uFa<@rqjV|A_ؠЅgL`, vK*=+%\$B4#(  =Qvl'X0N7̓2'A"neh,>,jtǫ0;2F\*jã"qdȇׂ:=Z}W!*vR II5A\") 'j)mMF̛k{cgaN9;~=bBon-oEE<6D7m7;O^ƮSW6$BtI^Eg{T D{2@LҟԷBal8 ΀ #7y aNaBxķ69O7Uއzp` $ER[IÈP,m@^G"yjsaV?^Ҟ]TݷY}]H,!R377#@X\PE{A.ߚMRkH?JƷDD@ෆUy0wb> +{`ۃq6J>E0*JJ|@Z+LiތN*}j 0bvpxRּl/$*9 ŊU7ye6% hN ?7ܒenӭ1̳ 9? ǥ"3y 220Honj13@$3;o~Ǭ^TCN)j֐U-<-=k"g=E<Z6p򩭓K>ŒL/`:|xMTiLy}D7&!?gv:1v9k(<3l7ׅ QT'FrLB 0HAQ'rDWS TS{.$A, nݸJP4uݩc$):m`D]"+4,9 ;-[׏rZe!n4GaϾM]Ua^Y\Z.$i)櫴)%}̔!1)2|-݅)u?ʢ0d1~2tjJ]2/vkNqE{TTe/?G^Nd{Eer͡:ҁ&4Y / B:(i|aɷpZ\!<O&jXz|]ZJv Ot5͍C}u:M@D4BblڦͅzP߄XkF7W>юR6 Ȅ<.{l@_0l>^L5Feu?u#nb-琂o pEr?WZd`qͪHZϊqNyU&$nEQy?3pX0}!`sÿPg5^0*3+N8UP?xƒpT@Բꍃ^_j/Ն)6Ks7׌Q@Z O^>h%k+{%Vu#п1ԡa݅< Auc8Q}>`\V$7DnZ-"tHnf:v͛SE깄{Q58RNaƽ 7;?]G[~Rb@L#'|ZeY593NhyGptsNKl>L ] &yڇ >_}j_o8̹[KhZ")3Rr!ÞߙGtbڶd~G+"xY%弁xb-`}I.rrH (NI:Sf^O q77Zn`%F9z*6dDt/qި )2-KŹMY3i2 Fݮ5!oĭKw0?BƳ)CH^ qmgneDxȯ ;$=գ4t'*>8NU$B;+' G>yTjކ& =f#SpPnL>serZfmߦNFQ`.ŪGKmsf|oBp%GSȌP@Oxv jsi#oL\L~ܬ,JiK$֌HdNV>~kS c S.@JY2r~|l7 9nFZ(UɼJfv}w 3…:bD bp':ux|z͒KcxOwPBZ߂;j'.dPy]A:BLJhHJ傸ÌlZvZO ' {>MM$cKp.P5M9 0K->KEQ{육,OƬl_"qZ zG# &"}]>gzx@>M_C#j.#i+J-bv E<^彿Dr:29]{xB"$q)j`֒ ɃwPS>k ^했2, },FS@}&  R&(P5kWoְ Iսn^> :HlDq;_w*R4R/) T kO_Vec(/+әoX]o9^[D AD$W]טگt)$txa\&_]*}ןi=EcgtAa 7nJOl E;d笀˗ ?P-taFԭ:ڈm6:x`lwe39rp>+A @X˩=m;7&;Eq}O˯Ɯ $08%:g,w`6aSZs rcA0$KaN{WcEԠf, ~ic)=֛K<ɪ uGLmˌaUDp!p;i&(k3Ւٳy')I.SI<&vQs۩#K+ޢ1r2`Oyp#FS)PEWK'DV>W XLQ0 k`1`J)Jft "nX*9%!پh|¢Y:3z<K:uԟess86s5@SsX=:?XR4jZs,g5CJC%*CfR%>{Tz D-6Rn\)sGuY\_7vNyy3@oSz67Y.uv[7EZ ZgAYG FQ YTZrKBضy.wQ(W>_{:U40 ֞;֋&* <o3@{ע]uȬ2C*{N\ LKj%PVK p^ +969؞!`k!-zDnp Z*iWɂ_^AV6Ɵ  fc\FG!7onQ܊q~4 z5DT3ǝ0Yh[gr7tM/LLW'Qqi=;Gy̡[!&XnOm)y ىmB& gJ~3(=)?|$Jlk|rJDs-TQ RuOFh8n[xhqiO=Y]d<捺''k rϋ>Xj#ƽ4~ `Úrc$v0(}1ŵ^BDŝ R̍{㿫lJ_C|  2ՁhGD 9(Humt-~Ja1I6vh kU/=2#4h(I9 5?Tj} [*!a.ޙ!?4Ut*Zz< T{o>kc>bɏ#Y1IS)"Tey^4 ku ;=Ixq<ƞQ&Bxbkjr"x X/Y0 K b(}EnCRzf%8!X+ʘNtv3c?vr%gxh3ǒ[= PzݚSmƍuy@f,SvR-a5!pЇzT"/=+USlZT/FO?c1=bHשѶ3!@#sIeH^/Xz|yIB zoP人 I'$fu^Q!Nhӂ\Wyd|?+v89Gyq0!VSl5AT e!dU[&fN 4USߧU5 4;ի,䒲~Duv9ԡQ.lo<5!14yWy9|3Kpu2߾M+-*女8w-^ ^H|n <Դ';OêgN?^6%9&%wwɒ`@ MП |8Q94D{h ֞Q6YU!c,&D1gʻ1{磺|3.BXD 6a6.O6'nb$-kKЍazPW`w p#P֌$(wFB*lQS_?PTtZۆ6`{\0ԩO^X,0A?uk0 w ے! ĬeE(f5ryTZL1ݙ%WIEI6 grѽxl;< / m3o%=XެS$kYQM!\wEsu B8MC+bd%?p0k=ݾP] !wN%1'`l!cB߫9% 2BÊ2_Lݫd22Gm2x5~ }z]7<'|; vѦbʞ8Ts!e0"6{x<"h&&HsݫHAOdkHΓ5‹e ":~BEۙ'ȥ "B"g?F=$YwRSZ Tv;甄?3 op*F(4ҙX0X?)29LjH߈e)IPYiYJ%E/tZ^+fL»x6*^=Z:9JZ[0uC ߧ|nΨmǰgTs /H͒Hd*|NqyYH*Bn%Ą%6U ## 2NO\f&j%DGi UaSHమXV٭@ UY|<ht7SWVhg`Hp؇M(@tPJQ4VXxooQ' ZWq;Q^mZ챺o&j݁\^uPc[Tc+`x;3;Jӽb$y֍/JK.>Ԛc(5A4_K> i BXRlT.,f ta;FY4Km Q\6bh=emQ聳ݳE*#O0x0d>pMUFU9K"t(5eKX3YlW4j@L:?oiۙC@''2Sg]5iK75%3&`^i?W,mRC]sz_o%!ѼO|a OW7͙[bvxk*@ƆF@r{ax \룈HVvNrr)b95c)m֋3wΨ^ s е x aPPȝNk2=7K!e` 1U,vl;rGo3NN媨hrN06A , 8l=}4~B0?\?r S]&ӿ،H4~\5-k@LH6͊#Č>504#q7HYE&XگT3A п;룴F[9 _,:c#+  v1+jM,ELm'(Y7pd|H1DQ'G`n`:numR]]pJTwn ݰ0\"ſi 7h7k#.텨 FɒVTѩo4|ɉ }d wcB鲬ֺd64 FHg+$tw7 KI&s u>``"AW7h(}$g "E9Em_m F]Hmq- ͏Po#۞^g  di!nSi0_)b 5PǧW䍍ZtW@j7e XC@>X.QQ} #A=gJ1|zi ̗nKy '|3[ӦMCEqٯsSnSTy*r⾶~]xؓ\,7N]ie@·DvQ=AeMu| D2iՖo`[DCQ1L_m o[g \LRQ*~KJ Ͻ˦UUzU0;K׻V>V*N-fcڑq#j|@ET4Zzte?ϺZD65WzR:(8b?O|~}hzԂ i7[uߖk/QLZi~5?J#ڦOEdvȖc4Ǎ0&0+a՟mQ=xd;aD QБSW-Q@h[L9Ғ ^5%{<>k䧰+,E;$w7J|=%ة48m"])Z> ºଓaW](&v uz{"y\!a='Ƶ,} ձb􆌝{"..\[ѵ#dpu qzBrc7J?RϨdiRwqYgɒJHq{7Wf_B%ƙ9G> Ú5h)6o|Gu$&8_qGW`;7<0l=v uukuAf  =K [B;ed]o'y挔f~ a?HwRc,E}-["ޟ+3H1 cXR}_먪>nj2X/pbFNZ + ^<'UQˮr/#}ĻDm'.!a& $+g1bƫ:( @r0=#JΈyYX[YWד]g j!R#Q2{XXA1f\Iq:tuRd8ܕH(V:/,3zq57U|Dd)Ond˥{Zt ŖS'64ITn؟&e }Oajs(!,wRr&Nt!Dإ ORʧ,5b_(m#rP1; & IK &LѹP$^-8n>5/.CG j@q {I~{FZUbڂ7%VpH ,ԐAxnOxiF s/ddm2Rn{4mE=a7zp4N!ԩLɺnyye:O 7nad4$dߡ_({nB 9lC*H"W$tV)u,RU$I:=XC˥CvG>G%ra5Nlrn@}"XpA܎KO)J J4BhXkrrq6{KV&%{<)&_ͼXZ ;%T6L}kɘVIQPSXWQ2or%[8%Jj.Ӹ|LǨDn-n~ĉ^y͹k-&f{SgQPjgD0Ik (:ossDbZ8j<`pxL=u;H{j5(;pA 5SF^`fsjD"wf]f9 Wdz>[9ϻG# *`Z0#uWNG$Z46AM}ȑ@dYGjI[$I\^EpUtuPnQ0 (4kr.v GdbsD=~"wV=D1$e<ւFN!l[p&hjU >"b/M{QeSOV10ȋ, teEP#hXh6:v2&ɧ[U7[ٲ,f@фOmh\c EI/XwM\uF[o`|'mi?yVCcOiZWL?h]3ıx0nAFW`Z'> |v!Ɂ /?y԰H8%U>H3bYNU%6 @C>rW˧oE|?v~F!zqe1ɒ2 R9EӺr-%-?~YR(EKwt}*ynIa FlWs]1JH:YsgHxzi ogʬh|u`nt~vRڵg[ѻc-Qm)fOqўVRT|(")pp( E$.t P4Lif1HxyKMbGMV `A(i3 k>?C {dòOiMP/ND(@;ϣ"j(h$-ud +֮ f$9Ö?L kxeaFyq x ڵN54MƇ?)0Vlhdŋȥ4bDp s(3FaHC^I;3'W3$3oiMp:} &zo J݅Vv9: -ˋSivO_Vzϣ6cBI"$R2&4}Oi{g) xz0zݟ`fG7E\,Č ՝PT!TuHvjKl`/-za" Ā} \ Y#o{}@j Z"kvׅCkeŧ5U~Tg0ZZA 3k֋b> _R@\lsЄ??q< ڣ*D($վEw*ƽ $; Y{Fw5Dh>RDSQ2><_nJ?PUGy3 dK}%ќo^h/7̺q-ˑ |$O6Sw*\Kj(XXJ϶?}0AVul Gz] :&}#ocݹ 09h>޾p0 N":a{ NG"L=d5sE9˲7+ne Nk/Q%FW T2 ]-u ϯp )hfV49uJ4OmoM~otgP0B}4TMr1sE' OJQkW[%D A_q̣?S0@$id$s/%Xuw]_nh ^]Y23m KM V8p.~BCDAz[-N p|D/RcTԻҰi-9EnPI}}dnfYˢ4)4Hc4i~.\S+ C&:QZAoy?5S>@*Wۀ3?|n}#m͇zj]8:9` _)fwA!=+̠H] րLDLD|[hC^hEr0e+I@p*$u^{p)Jie#+芊R3֮z?c^˫38]q/q|Si@IyS4 ʭ.m=gW1RqR>¹5{Cpm$v']9B$\B#1X"Tb3Vs/JþMng$mE&`IoKPadl6ZƐ^ZϽg*/ɨR9$T84ʕ]b>-ES%ƍ1әo`e^b#LMGx^68pJ;n!w4%2~AXP?(HjZf}l7C;HEQC-"-O $w7Dp,MMNFuFI.+%J RVpSOI] ,[ KCk8WEb.ӢnO蠼F 'j4y8XL2h4<fo\r&VÛ9ȟO<XW)RA6ꠝ]v_E{ė GOENaO/AE"D%qx7dD;Ȕ٘EyVV=(PK۩#2qryb:PBָaSxm{C*G}.2OHBxl,|hΑ\1!4Vˆw^CzH=„S^ 20VFv$ =* b+5eUн'ѹ7K'0n0n xpOor[[-j ~ŵ Y:ɾI=%h~"'7 ϒ7yP@ch!XK :={#>xfO/H'F"5ɒKY-##'|u"K3QV!&4ШH7GmOBk6Z ۿ zRX /2}2T_q68G7$40-l2'bR:;$,Dj\ՕCgwmiY)29Jz%b0؋e%8SFΝ+cޘހ,A<)WWe?!0rH^5wFS(4"TD-I"'ُ=/ MGEaRbaY-."w,gWƉ٤ ?bDg2& bwԃ;NrM+vr4 .[OO6{λ#ן~H.f *l-v-_#K- ~L4D͇ g%|t6\Iq4sE {.kW,G;ؐ+o!6mH!-Wjnh6cO*F F$N2 LoFs%AƨIH\)II5o9#2C+vxzӲwZ95}QCckR[W騊idQG_=6"!sNjG>tdGIeՉ(`3X&OJ(Ftqd$M_UjLTIQ8o6k(^+$>OT[$dV<`!+H hִ&PHSs½0 )?u[M7jj*aR|2tpJc=^ @7N' H!d*E<. g-ڏsb@YK6*ileG9wy&+޿Oh:$Yqg 9AOH+,@s2L [^T89S,PZ6X!xF`cj[͝lHS,,}9ԺK๩SDюw!hH]2-A-jLDˋ`cXQ $Q Z`VbBc֏7ӄ碩kmƖcᕼ?1HjZOK]ffԑgQ $~Ѷ`:89#?S!;7s[w3ؙk "m* )5z"5w^lW#9O 1HkLū?,e8Xܬ $dJQ9DrI S}fbu͘"_$1Rޅ$)0`  wxiah[W$~t>sy K0pW0vt׹QVTX)#ءX't]eu,,K+o#u#Bxj$rʘt ',ax4>>ϋzv=C/gcZl*," 1r_,k~*/NpA(8Kٚ+uL4b_FKOuXeqԍe6UcN|ʇ -MNS^cT/pPUl-_%Q !lΪZ1aWCn,"GZhKV[λgã9&'ĒvA_`" ;h:/Rq^/>5 VyaMvv.&OBzN߃RfҘwGT~.\ݙdx*~b7ˌE{ن:CqC %A\Vx_MCIt"Y Vb>fH4wׯInWP馚N_U2!_taHFЩfO<3W+"[n":/Pg5P0vب.rOm1867T\DՀC:s^D| i3'Mal}`l&I'B=Oꁮ=FW6zGccfe-1i1Il%Y(G'DZCnҩ_ЎUbIw{1,j_yN'uČr#TBT: W3bvmKiC1L(#-W? C8g':}M;ú+e г9E tf ؋aG1MOd -]:125HuA5# V0JBĹٛvS`89,R@MͺʈU*"e^0XIb,A8VFgY}|GЛi'4 b%RNI\ #`>~ק=+mSyj&޴xJ6@H6I˕TEuZ UV.v+8] =~{Xӕ8}C\ފyMˎW[ej:F?RMchW@DwiT7o|#5(K.3LSdۡk`5/;ߛwes[1MIcx64fi0:;K.uQq]$EAn!(ftF?I2f*|s7wO=ef9 >(%;5Vk湸Ə}h2fsֆ \VŎVdܮe[EH\$^x].+cF{Sl #(߅Ժ(_NKI,b^a:߃b:.G=!u@yF a{6/>q!)gB,I~BΰjmR䔛9olH\r_4H԰,6TNncƀ Zb)nX}BϨZW9%%x<:$E?.()^Zw tvݘ= +I%V^UdI^-lˋ+PorÊ`\kZdMw[xɹr! 3C\؃?Ռ*am1WHrDTCaRY !9K$/vI)t+ 7z8Q؆<[ KDUiT!XW:Bfë s@#6Vm=چYXѠ3)&-9>pp/Tن~~єUF_/.wigt])z|6LSw-\!I3H*kwޫGpi%!NX+c"ph,c8mXSaR.{w 9-ƭD"/yė&e!B3<~1}&M;oXUeEs8<Ka'ʹZ!\YQ|B* =8sF~ =wa`u@9HGQ "͖3S _lV]m[%BK Y=rl ]x` 'n-m̎qXcN} Lhb1gpCy.HsOxsg͎N\1@N_ -pp ~yD3)@}061mr6Կ:ՀґHMB:[j?דx+y["hpWaewHϾ(AaمԠmB%;qpq|'T=8nd&"4M7v@sA:= 9pf&kHa2+^9yU|k̥H5zn}}hUpc3l<,gE:@@s͔@439ǧ˦bM - :6er>578j4Qo@GbyJ?r,Ӿt`C"/icT3q5qzǓIhmi1:yI GD d˻RҠc -cvc~ce?4 Q_h2/L=Mj4?j9kPn9an }g? K[e~E׭/@MEXqQ;g8b559ꝩW|%7zKq'd,d~V OZ0f]+ *;f4> \88v#Z4@YrIO~|3|,gfP[ ɝEl%[ nd XNKA:g%|Rh\GhB:ȹ8|GY.Ȓt u{fAB^Y<UY0C(_?Ɯ1@3^egI䐉{|SL.1-_1@UG S +sO)뗭 HdBtj g3CJMՎ2䑻?{lR'bGWךB̩xC:G_-vt cȊkR =9P/EO$ yW!G_jl<)[ŒIbŦO}~7zBĪDM9 L_.$tkrWѼ$e{b\2H|K :Pjp:vdg1FwZ.?SM%rRNK 6iT(?rHlz^?PE0@”oXLpclWl7,DX=Ϛ8&jCN ' OrL!Pف|´\l8k7l|ֆ鷉b圧RmSU(gQ%,Ht ̼s7BTuǏ(2rB?Gn_ gn@'e{[>8F73<jnoFlDgÓ} D!]#uY"PI@h˵>3ysgAUcG,mi-̗6d؉=Z@ƞy--p>Db.kH> g:6_"kP\q%4,+GPCOs Npo{pX+rw.-R+e*׃ƺD{5R0M>dp6a${Mc" }/-DRz~N~p0a&g%46&^/cAu0Le}1#j˛S{# wD(@*%`{Th`iDդp;]W0 FO8Œ% ۛ u~H²Mx:ܦe,>mmv"ۥK9'm-ET_![bD h66 tͳY܎CcVcdYsW`Y j17y?&>A+ЂnrPCw%g%=Υ0B;u \n:/ea4;.O94Mp?F(x^&1Ð %`Q5csT) \5fA"q"EX LL|iamIQj?b*+T2Q|[i*CjXIϥy1^z0C4d1frd8tйclX^anh/uRU~aXмҿ  @#_5[5i%PR :ұ>tX렃,Qb)ý!jhdVAtnFs\B[7*l $= ݭ񹓼̦ѪJ'l,=W D\D,6AFEu۩qZ4QO}y[kO\#7vJ@㣭5}Y_"OIt:8P0K& +f[LK޼,=Ÿm_:2?7S}zխ=;UQaVo%P n(D]}͝%6q ~(u|dx򐶺Ue>А_cYnNꃀZԛttŴ LܾNZ':1;ph@UVUK¼z%iԭ 1xۿTn{{l ,1 }2.Gj|N|u_ZZd_Q^:8S?,аnͥe/.^S],ڒ#lP*5 xt1*sD5 ln6a=cȼy:m !maT\G/r75E}WVkג4beDI ?+{(yQgȕݿJVr\ mza@cVOQ|ޱ0Ht P7ܺ t5ķ{?!fSgv4z [taa tGǢ UO+<+ ѳ{l0\%6wyn3h'ɡ4 %<+ "ANh-tR tKx޶yIvat:w ; [%x9m%΁"{ APd>0fTսwwTCu?*Jp}ḳI.:FM?7Yu@%;CJxOmI5pcYSF 2'>K>$ |;$:a$\zSl9Ԙ *m%]'%٫WzĤ)["K ̓ܽc 0쵈pz+@3jٱ\{}Gzɧ]rriN4i|7Ȯ_k9EaLdjb E{x2F:iz;NpHRh/tyZFf$Cӕ?U(`KrF mdb zWE΢ebg/;^8}n^#UBI|A+E[/^.o&D1P%%) t2rPXw?\D~Lw-q}|=\KNL \/dG t#~bZ^DTSܹkP MEɰSMV l kS~`VfzsRB$,4;w,sgAdMux(zۿf2 +S\ m0}]zsFF˓N dl> ųsfJfL[4}Q+*׭>KK C Z߸+2S=Ęoc۲ zjWF|R*&g'A{'p7zN nϦ`Dj91oR2E3t;h,*TRWvE-LH"zI=W.h xk> <dC?JЙ+[W%aإZx Dy.|$ 6qOiZ-;"^,m'ʺIkr#X|pAB!$mxmO?r +  .7w$ !u5e_-Ah"ly>Qm^3) :<T] IxEgm6U:l?ڼ8b*5!" 裂d(NG GL|rtw H'}Z\78QYC}4:'R%Bu}hfx! ֎hȕVu+4T!H1,.F 󼴨lh@L# :3ZV a(d:'[eFGt6-eޖ&m(FVc _ԊOWQ%.;[uOš^Fuec4Ls@_zT=^h&!t}I9OS"rU|&l^pƱ$mpV.JwHEf}JIꕍZ":,%_|<^.aFOSÀw4mlv$M?Wp@J(OP߆u#F)~] _7[X3Ke3ojTRg..dZc;@ygZLK~\6($Zc(띯^~ը%0HHSw$ ߇jiH`¾K&UTh5 ZBfQDžY_ͣWb1|4PI%]cXlʩQlS*x5_S67G3V ` K$ȶ^j=AP߀9K?e0KE2dwYtf񰫋$f' rSc@~.V׹5#`wgȩs0\KiƆkJHb3WMj>U@mLt:66J] pyf5(H ,:͸|/ʃ92.̦n5;&ad0lq(c&Ӂi0PYep\Elyiv웽'FJP/Woں.In9!pe 49XnbFłxzLJʁ-}} G-? =}DpS59U-˧:rge(^bA{+E-X\D^Z\ U 8 }eW7K e[u}Ԧ Q0H[W ܁RXNaڢBY+>G"fcrW ]\GUakNr35J΂jO/nTE_WsX',6ګ#YtֵL29{h +:4_+=< ]Ւnƽk7 CZN(/U%f%ĥF@]0 X/̂qO&oNݖ:X]jJ8*<`Ǒt#weKr2Tɖu@Xu1į܅;kOpInsg݉LnBfITPG0Ϋd泤N ]K˹zhTq evXN!k) ZQ43nٍ]i32p5kl$W|]֏IΉ C"o{M2Ny, .Gɒy\-/zy hG3j*Thpc{Xc/|)o}-(6*rnśjګ)h}wCo+s_ET*]%o#;4ɛw;@ [z6b e-t k\Kc_~ڱuBAOrYm&>oCqEDEJs8_@c{1~/1#߇;tzB("8SN%)O .”rhb)PFSޛ٘uj%{5Nw>f-N W5QH l$Ǒǜ<WqUY. k.*yڌ8J1F@ A6t#;D*&1͚' : va.8TS%#ذLg ;bՋ0&=ΜFtz3DeK'yǺteҲ85 076>EF:0C /R M]"` &j{V# ͆0뢀t )nN^SdLyHfd뉨(qˡ7TPPr^x@y-c ^39t+ pb})!ۙ kx+UiضL^ Uĉ `|/hjUX*]AcTT'rԖFG!?+qU{)ui~=g*&gAg~?zFXZDy;-v͸gvޜs(#Dx։0go < z B+RrddIimΆ&`Bp" hgQގ߭9LЛ_?|+iO w#v{0ׄ;@axނ0U%3:?7"^za:hFoZ^&>~%Vft^qvorv_Q^(ꂓ- Ь}u;ϼ%Sʚ)({4;ǵic{ƵbD| ~w%7wwOpnP܍ϴX&g +~K}*_vv#f4 wPJ^x% CDpVߏ*4%,$g)9LGsiŒzW;u*!HTFֿR"-V=$]>Xji})9|5q8՝VKnkPY_P 9$R!qcb-sZ "z8U*|&L"9H"7?p#W=ZBu>d2O- N2&K֗B;޺$Kܷ1]j7nOl syh<\1p<aW#22VuA&~ ^RaWX7BD/,]BPA꡺<ΑDmUKRvcY~!*a3vC3|\:5O6/~`)פ]{^-abmhȩLo?غ<-A`]ls%(#,zla?$B VVmiSzqY@4xEs2㭉 %ZKKGߜNS-'ۅ_9M46.ȐM'bDNp hTIH״Dۇh֫ao![)f{un$khwݗD#nS.:t#Ϩ;,i#J l)|Nb Kf, gէz%6kܗ!A_GN~ R1XNr(ʧPxgjS#JY+&d!zRp=`߈xehKۍeAQ%x;*IM:167٘ꥰ;k AyzGRsGd5(5ba JZ9G)ph ׂhr bB z睉mvP#FHs5k#73pO:kTbM:OA(̋&@R_cݣA~YOXC꯬|yZC?1X ^$KxCcںc_,zu0y(& eKF0Y^,7cTQQ{%ھޛρtPԮL3aqH!121s\+a<>-t)ML1$q0 %k&]qƐOৌk, x$S*ˣljG2CV۝Ciq~[:-CtqlB \lPD7XuިZcP`WAa=yvv/ fҨu]q;2ʡ#ܘпBLHõ/.gu ` vmέEu)CGL*:x;FkRp R=p"/~+55)8! U|3bp|_1h8!*>9/+Mqc4IQ: i֎ 7 ۖ隯$cŸDE:mpM HC+Z$b"NVʁZ]S( 7T\r/EGa^яc3UjwKmh(bqnE%aR  JUq,Aܿ ;~+נrz՝'/44a|8迅H]?.EYMXjsM1חe|GdЏ9TИF|qvS _z*r:Y37UECwj*Ǯ CvSh@iN;}7U WnFzJ ~Rp3>NubbJesEhMM%< %)y|{Xw}p5PPZ03%r.,ePO@kFn .9E] \ݝv@U/!wXKS߰} Kc1Y]I)dǣ^Vi3+L}T'E\WPCitZb71IK j78E#Xtel49V3F!Sagdt؟E)}Ӏݏ59\p'i6 }B.Y_9XJxuC_Xn8+cy4 lkq=>ߌ0)]/ֿ^]2ym3ˡ6o3g&+0Y\TPT,SКar_jʩֲ7f0t@\oe @4ZkۺX~|k,Ö`|9 "; .fv|cŎ11}Կ Q+ Fk*]%P`1݇xǩMq+}שTHKgQr~EVo{J'eZtaV{˓Ȭ?uFg+$0U`sQsVLƟ)ݕTngg1/Hqw (>T#X,9_$gk;9`/'fއKCu6g+8Zre4Oa_E5)P3ÔM ôpg2to޶r$Ʃl~m֖VLjK6$ѡyObik ow뉜- qř`Wc {r;ğwu,\]d O_tE~u203F-I|=$:Bʵٕۓ}CY@4o!bir!ˉN=tᘑjBq'i磬*%.(zѾjƢ93hc=`Q._Sn);x=6*J@rq"ܻ'2-!E!B{ 1} |?3IoNXobkLuw re%8Vz&T$uER.Ry1(änX-h|(|~*&+I ݗd=99.;j4ěSp{B q W2a"*I|뷂?kk6e6LjaIc('o'L_oxqq"51~[⍟7:@Hzlt#p~&2把HH kA%B.W{ڡ͌7`EV `$O\D14)Kot._m]: bM'9RP[&(J2ϙݎ B!5.gëv>kk T!XrKd{ K O?K.rmw7!H8F.)ړ\< /գr"OP"7q~ӱQ =9 *j6+YY5EnPho۔i@?̼VHCO72'X4 xA -P( /۟,g30t_c? \3^m =W?QL~;o|DRseotZ<7wxN('r p| ^R+?k-VנzEE Sj/ךluH+~Z9c*kg>%05s W4 4`2,AAxOMqI|@P>'Ԑ9ܒ8()^`tvzigDP !d\$VdٞҬ\f\{R9=\ %p Jd9@E1d{' -;^@-l(+`Hyu9Ƨ&$)jZ #fvs{ԡ5*`ŭ(pv)&t_  d#pzz7RJQ3'̟~!ž xW^/sn}EJpJt3<[OMS"x9]ˊKr@/)v(팃-vv+Z/+^RaXd9,XT&"#~b.#mN(X8Aa .*3=qY1YÏHi7&d^J{SC Q&r9 -𸼎z;x籣2 :nUL2uXHǦ*IO{_q/^惡y$YdxN\wd),}جtEޘ^{Z}ú1DHّ N'M ج >T/-71**P}Ȗ!;DVHaUxr$hMaeVLFR;za3-);,O|{slZSņi8KU.`0}Gٽ~Qw#fZ~-|Ȍ'ÒYRzNSF;A E*|s`آ&aឨ?'I/Q^7F&dZU@a=%B▯OFhiSdq?9vJz׷nXCayۛ|U[ Miwa\Tua2R+S'Pfm@ dzАM;iMxmE3kޫh_2`?Ik 5|\:K[|Ou.,0*?#XQZ qJGGr'm5[C},<̵ܔ ѼՏQFv3c>TijzWTiu~mF.PvI'.l@GE&I);:{T2*=Bl֚XQX ܓ 'BGԇ $f[6 ނlSOw[Ogv0̶Hj*`$) K ^ , q8e:SЇN'!UdstzNHu;>Ʊbth>Kb>;@BeH]RɤJi YKHgs^HU(7+v=S=˟Lp`1,532 ,͠oBo Gl|ARHBz.OBP.h(!1bQM1^@韯fhlc./0FNW,|qFxл:olKNd}ZZQq@z)VQPn@%4*n ~P~+&G+r־LPEQ=g'pJ'7P8byJHNKsiGx:VfLԻ;ϥSAkƧcѳy; F6hM&j-7h1~ (>ICIF~_u: ji2XȦg.UbrzW7L\dMwHrɩzv oKˌoGS~zNf$;eWfrl&5$s@ ̧aX-6` jcVt`%q.dҬHX aԌu o=-y'qVzƒRq)c8 ܊ gsX".A]B ՗)Sᇫ0%V}3 )zGRbBΰvW/֫KڅPuaq2c. yҗ,b+aWv18 mWePrbpP7IqRjd $?x_> \0 ē:e\US~a "B8$ kvʯXH_nrUY>T*$ qNJά%5Mvql, 2Iꮹ>lG !~ACDm$@j|g`9~*\sj[K u)HNp{OUESY(\cAcfoplX@^R|N=e t|ԙ{`$ȆQѵ=ct]Z )KLfпöA3C C'Ⱦa [TA4hMLm OMD>G^W?Whc= #tfN4RKq`.K 42h]sLmQtMM3Q\qmH'#O㧯VXŵ^}ό~*e~iڈ^N7A'7Eƹ0%ekRjoDHuG,8i0JukJR-2_ǏwV 7y1djaރKj0Qߠ_SU@3HVbO6PfI&"dd8;. 2 vDa)J"Nh(8_A> @`D+WkLILէ>[,e@*zJ6tFfUQZb6R5(ɲ\bI C +۝ԽeE[oϖ&ȇ-I1:PBñmtAZ?p6LϨQ yPDkϊK^DjJ^{PZnW. Ͷ΂0( 'JhFk5kX93.%+>_ /@)q-KTu/E7 R#kO:Oj4=lGL !ճјwӳ^YϹwJUZx-|LQ>fm"j/F1;Ss3@a^ }bpuS F^ Al7{1?S.s؅  k$BQ! Awn3s=75^D t:$-rSY^EGPGx )~+Hr*nf[#[e0SƎ, zҎN$vZy_?&kЯJyR~-Mc0oPB3Mr~erݎ M;ũرAh`k J6dP*.+f]mUV[[ k7VmzCΰNAbu&¤q;=,4-̾z|@w][Бm5]})57FUKÙ^vzFFRY%bTcsFYGW Bm߇G*\ڰV祉LnYۓ1&!X &}E)BpCy9|{mBnbl$X_"}&}PYh35dtW7~=XBp(otAw)dk&`pvlfhMH|YO*b񗋮u8%طKT_Bs?sbjW jAqu:)WE+_ )`2P.߶c ~M6.gM$pB;))B5?]}\N/ 2jr8պt2FtVrrh#GMi#&VKZDrϸxǯ& 3ɋ(TA^Bz'LjK—ᏤiAOy",pYQͣ!ᆝ ,-|~pH}{zG3lsy† vCPe1 p\1lk=) =ZG]aT!B5~MQ2AOJ)9sMNH'{=ClmGn T8z~>CNu_ T<=d&hWpm_͔o]#FO@վu^s㔄ڬ_̙dR=/ u~łL,Oc5үHk`?/.Xu5r'0TfUvF?6m_WBڶ"Ok\ǮqP[H&=:Ⱥ<=Z*ބuq)͈Y}A;Qܙ<=JUƧi-۴$!o^#zD!-'Gg\ףbwi|hzZz}GJW̚SE[0v#HCa:zq q1tgy`oUF堳L7[`)9KVPY=|FR1\qj5Ӯlڰ1YMHw2l!#rpF9/GPp aCt_B\p_CK,Ç*HթplbB y'k.{cJʢ6PǴF۽Zg,ęMNq+2M`,Hޘ2SȾU<מ>$ũG(mhxkr9u9P[Dn4lq3pʀp͏psFNgƴeFoeM5 i8@m,z U>Jq!X@UoُT]VI=uiPp-G4Zv~%ѡp٭t uy kHyO("Kԫ ßGKLWЛwVx^ܴIȌ3 21umd}py߯=#h޾LvYX_ø1OmS:F-uV@Rg{7ۏL>e7h 03Vl{IwEǮW%HлX]J$ʤg[Pԫ xA+ pbJ% o { n`e(^HA<#Txמ 3H: >*74.iM*< ݏ]5 T5~D־-0'-#O -yu>}ID{)N*!ĥqb~EV- F]$Y#}0X+%09:G߆^<|Uk6ke4ʇ.P"uK`hڊ«oŅFGͼmѣ,rtlԷ4=(lj t5&̶\U,h:x2>rKeF- KEo}Ša`7P3Uhd؆_[W͊%HǹW/eaP e3]K=SK\;@{\tk0SEq r\ٖI~_JpfP5|3E~njGɷL>/,L.3ା@CTf]f3E ^=&ΚCA g8Oj}`@ $sZ=q['aPbTnb%ƒ 2SI[1MLS68>P~ƮYd VXR{YYͬ؞ʭS8f#= E^k`= gB(Û(E>黅ÿWlJޖu `8"Ay=UOOrH^sQ] Gڅo_H=_uKG1`=VMeF&p0\,I֥<̓>"s# kbxG}J>Sf`/ʼn^u8D̰F%j\)1aq&[u{ AZ}o wK1ʞj]DBEc w)&d|Vugu Lo}#rlz|A@i˜щՏr{x+n>"!n˶Ķ6k<ޜ_L%pܵX>\qIK;fFNވp2;` ecҫ_#%e̤nf v6}:R@JJR-C 7un$xr!-/Ԕ\Ow6>=2IOx$uN1r(S SBLuib>\F7bKICmjy v du:Ϯ&$.n00o!44UV W 󚊛p'?n0,97mfyIP([Ndb?nF4]=Ukmb}u|gǮ'ZӨ~F`n'T̀B,Gc1ŠXA[SF55PHim>hXcbTjo%-w>t&Xbv:QH]{|i".6PY{^k/J(ID FKOx&1h9xJv?%~->x+_Y^Ҫt<굫0[D* k+hzkjddcY]apz@ڈk'6fL]yfy;kW!9dDO)[; ~W)<ǻF>bf $ʘ&o)-Tiܟ!PXq(#Z[f 'ݮq{v_, F#v6i)Iy9],W]Vn3.,P*cfGEOߔ m3Px{F[B}-N%XmZlҷVZod!5l Wܶs-1kdTlUD&R+l`8(9X@Do?SN^u.={85jП+D 33&'BGT0AIkEH[zD e׀t^ԫfb> =ϑlDYJf"x 1HV9Rd0K #+*皁Z-BPKJE ҡ!GK&QD aD<>B H"}{h5+s"R.64=^ ff^&AތM4<%s;/4F]̋2gGa q}8]򺬋>a k?d27Joƀb:dctBFͿӞ (;~o jc8怬0t,#.=|T BP#_NZ%^ 㯥0  xzov{Vى V8Z[L[E|Lcn o2'⹭/+/`f"<=1Y6C'GLbZr8(XЌ_`#oմsm0qw-KˮUWZy@,|C5I dbnƀyE;>IaC1KbS j3 $}Or Ix\O  > *\-\:|800y|P%}l7pՕoҝKLYp] 7Ȧ݌a 'G-d3A2^؎fZPޚJ8@"8n9n3Wp)jlgO5TaS6p?Q;g:0G]~6H$}ZD$\ͧ'Љ(64#.N~z鋩D7ZEHŭzCb}\(mۂE0_ f9GuW15gQ;DD:Ax2nƝ+''Fs%n]P,"n/1逄.|J1ϭMOMoK' Z"Ba;J dN  G-Cci`&d,&轔u򫘼d2/㡣'9ehӈK(!$+qQrJ2Le μV[r lv Gqډ}C5#DJ>*ѽ2g{zb]W MG0P]5_̱:r?*n4w42qshl0*f+Oy^XK+e̞j Ok#?,"={ ϜkQ +.T%h e=F3|>wXʀ;zv8.< *>o`4w wW.8Vu;FcњL1i++7ҡzȓ39ep-mc&[}2Ji߁ XDFә:xm-.;}Gcum`bЎ# ix­^V 6,NTXyWgݞ~*9jqA$'Öx-WתCÄ6p5WQCSr:vdf2J,c6F7[zL$7)4G,^ɐN4h[5MEW]% bKf! ΈqTtF?i䛮>;٨W|l;RWp\pDB`qb2'xf ux5ψ:VkRه64Bz6~l;VBb }5w+BЙm8;ӵ7sxLbb ]@>MQϡ^<&&[7֭rmxp[Uvn=eW,J~"kRmـD;/y bP<V 8UoUm2$~a"3c.W"jH_gXVS)-6ǰ~瑩}ղ^y4&I;Mg*\^ gy+L¾P=cHhV*a-|M޾ f(67R{k5\3+u"/=bЩif+4 u Qjm}ݰOgG ;8RIg?)ZpNE8vqSxLs=Ce.}A&>Nf 5f8tήh0܃ >. - {gvI"fGSہ؇rMo4JK,l'?vl!kX4tݓ< VXѺgGĬ41]0Z&eWzv'Czl='(qC`=waːTۊި;] w9j7el`OƂ%E&,M lkpY,9ʠOֹѹ~z)Eu%:Wu5,$oI@#6iO6c^x};dҼR\w=yCwrƺNJ8mE )g(d {f }m[jN\U*8356*&(U1\b&retPr Z<`d/+Kk@̺3> }=FAТX=O+0@H TʝOS 7.1S x6gz(hKz. ‰ܦS}׾ D-WƹOYP2Ws& lJQn'u-#2G !V4_5Uk)J-:ܸQGl xޗ& )h\D6;9`[F8j +4M$kU=ʤջ8d[EW(+yr:*z G˻wɷyl(Ɠ.BTYgDToư `5bڙ$$$#0Otev_ } gO[2̺ȇ0ʨ YVxeYvrJ8?qV= *]AxW\fQ#I" )DʹG c?lYy)zdMFІt' ½)IEAݹHA4TRR!N_%:iw}:WbYUޞ/N%9葘9D;?LՐ92$Į=fȭ* 릭УJ7@9Υi=HJR!Z1BTv?}׈5/5jK; ]CRbT`.r_I&Rv6Rii=p-"ޟ;\zJurnTg+<A}O'/$Ev| 8Mr{}PP)q89qAgw Sǫʙ't<<8J~ >DAOчPx3DN_Qo'Yr2@ntvHӋ"y;~qvlu)nkYׁ,9CPo%|ZkT?_Y5սydRW;Qs1iuahY%ųךաE#) ! W,eޞU{f*fL^d`m?yť4ҭDS&*rp|Q'T be> rM U>œZV7:#،lrxujgkYhH[Q3֍@2>lg~V[=PH5 H}/DZmSaPCN{WՁ')ZɺM,V94Q:r" b/ܢRN|K#;]>J΋H6;6C $6I0%?r6%6hә>D 8*"8bm d>Er~PgNl]VɚְٌY&by2s)݋wwDYw5#R}o1.QżY05xoO&zWya8pjحR.B>1@p,Upi_AGKB#*3j]~`-.#8U#l4<3 R3i=$yV4'B+f.ng ]٤W-88i]fD(%`++e *8-]%SU.!"BhwW+I~3kI1|ug 23C2GZĢLΡMb07p{PG2jTn1`2y⨳OQ5Ϋop_CwĶ;bz8҂0>ǐ+/ħcdR:f\x)Ib/ԟ;?nFű]J: .uRW"  UIu*{z܆k[Qc4kjj Xm ]#$$/x$@+~3Шs=c=Ԍ2#qjdNI`Y+VJIΌV/>w?L*@e>z)OW8ݕL8m'f'y&(0j,9w+|*-Gjb?E=b԰|{hm []߿PD-K_]^VJLFwFFUgiBs,36},(ڛg;e=ꀯd;?%xa f@sN 3ų]Cx w_\H沎a/Ga֙?7WyZK6䭿.\Xhg};vhu夠/\jU۰9*oWRrӸ:XFYh!m16W3)pՂP;?'VI$vSJ+lqu n 0 R+7 d. zeDmXQUڨ`gjBU⣝7D5N|.$BYӅ*n, lPz%ӳGa&_\{/)̝,dk(q4)3pXJ,ۭd95p$ jg P ZYɶC }09n!Mxߎ{ĵ\״{[FS>;0GejR{D/wG͠r1c!EȲк = Dx\ȧB$+HUc!f܂>V5D+)M܄g甽߹״o1s}Eb{+$ʕY뼈!h*haVsc 3-L +Ob@}V:ɟ4D0ǏSHXb'g9 :] r6wW"Zs 7*3؇6>˛W "r-L䫹kkX.VepxLlA yj.Cuپ"tz{ݸ3f\'7 GZw @$PI C9[Tt(7_B; #$ric;3f\=b$HGAYzeQWDGSx7SH0psX;]>F@-'QD.bVș7Zg\Zb6%?Mǭ%`eSv-՞rwrH UT\cl FD`*[]sHvZ&h$VJrqfĤY+=s'.xDwiZHJr5cBF[6r~<2ksTǘ~˻lw>=LYF|o$[&dł߉ O%¶cDREzp\3vÜ Dup_|6]\Y-~s#s֟& S֣R""~ !Z@6G7&8݂&0!w^ [eӮT]jȦ6T`ɩGD!Ÿ)L Gl1R;jLǒewފ\ &4L߫&lAH9 iF[CES<\G56m -}"Ez:J@4&%;59=67IO,(V G X 0?2a탍jFdJ ;wĴO|KۯlX؎)e'ጐ)N9D+Ity/ '?ّAXu,V @~ں$3kN(몁%#jTu,<BtjN[۠3B(] TV(8s&Z} <䫍e]f9t="(,z*h? f: KBAjFO44_*2z3B~1LHxnrDp"ս"R Q'_ڹZ)fII1fEEIt- J!)ȸε"k.)+*-)b-@xeqNCboSp5"Ԉ/ܜ:YXAV)2C0ѽ"QA)QԢ2T[Y`T乷pJC]gl):u]'T AWa+ոZc4 ('ݠStO7N=pXOD%m\wų.yXS^"h"qԆHd@ БduhSÏTW@TYCFM&b_eQ}A^$3Ht]'NBNn(7D~?Qd&;g(!M&rw|~c!s?ى@ܧdߦ*b>H v>r0f`$̜ܸ%ֹ#$K,iju7K| oD `yAƛ_c 6S[ U&}(kQ#F 8\eQ{ՕCHhƃ:ncɄ6o{5X4/fO2/(id@ \AK |Ʒ|2-oA\qW¸raA J=we!Qcve -H^/._[D(T̤M*hg\9OrIf57lSR[xei?Ok+|LF㠶_E%M<V3 Q~ \sƦ}Ӡz& i=gٵ؈"mz'!:$H%f¥0OJC$>(_sO`W+z"S $e=9wt:7 |%y0>NP0DC[lP~"ʅmXAm"͓<2#CaN5śPFOIgU1ԧ||HIӺSu2rJ;F/MCEjv)(G1\i9. rwb0CU hDW,ahi|t ٶcK&;yBo(+rDbϏCNdu<82\<7JcS H'|Kݎ?_h/~.T,d,/ztn|/Ղ%[4KdL2GȃB_-0$K3m&m;Ӱ#~]aB;(=ߨGNȕ?*1|6$0d)JĚlطa܎֟ryLw_8)Hh9v8 VS>h1L^V S+8S dvkeSٶ)`Qtj#^cNWP!LL^dn~ 9Ey! CC$Ár<IA4#\)m~VXo?5r; -#"h"xET6Y]x. .xPy7*e{{fz3@DֲO]cTܳsMugZmEM\%F7/;8~:ϛ ĂB,8~ǰJԓ-wэ7 Zg ZScIp3lEKШ $*@\qBLRǖ씹.&?,){td5Tݸx? r&jLw=-#U \9 ->?L_9_`μNF{j&wZȹ +Cyy` sӫ?+7@d]cG\Ko&0mgRCOEc7.q]26>3m]G ˀ˘WI^vT ^ӟku_Qkn !TJz_!VQ%Bڂ tȲdzrU@ٲz3c?:Y^ 4XxLB=*F4=d42[ҙ"L9spujأ66(OQ{ڑ]sӡvZumlx.Iqeko+{X0| ՗WZ!A(~_vCB#mx5ЬXF}_+ S}D{F7[@iOz^K@tU&SbαxJqD$[]妐џ\S̞;lj4zZEoWBmKS@;, 'ҴezQ._J!K.>|foN }aĝA6*DՆ!֣}m0QĨST:퍓6O?="a(Z%)CHePyY gFxbD=B*ݩMΈBljG/D,YbY'> şN)6g8~n>7(r|ˈ@|qz APQOdtkO@%y_M$-08n,oS0yO@}AkOidQ.0,H?Jr<~C?avz_ē|q+Q{,Jzԟt$],b q}a x4ʑbe;Ѳp3(Æ>t:OX$sMF։Fp棻{4HSRs oh60Dzl2<)s]. fu=W=?3I q[uI(>7O_YTG?~ Dݥ[n>'ܶX4#D DrV'mе8T < 2jhW{cg0U Эj-' tft߻ݙ#J P;%GhsWݳH`]_}V21긷2~y>d/8 y؍jllfU,-WW&]/˟]I踷L%OKtz)Fq~.gmYܩc#L Jv I|je> 0!,ӺKDd8I5nDs`0y25 #agvpEZ_g0HatkANp ?U*Ž4Q;>gSvoƃIW[;8MP!aP/ &?.' ^ u^JXZ&U{yu[lVlaΠDj@INT-Xl7T sz\pHgX ͊=JtFHCJ(m$eږ%#VPt??&3<P{A- ÁA>#ȈCnQKt$P {՞OE;w*%U=Q:v!v3Yޫ 3`~>1ye4XdԖ]c5EiS i@O(s)$`\ &FQB@+ Wpd]0,<|0ЎmTM&E{р5 K=_{Uj*v͒[B#G 2U8i-i k{ưZ2y1TZB+U%K#c {ʌmD^?gԗdmy"YbJ(|NqF}sܪYO,'SB ]n!=5OUzI+b) ׯr\՞DU{18E)ƿ3 z.͡ĶsV7KҴ=术*Ij ÞW9]( Nc7C qB!3V]7f'E ?&pov 5q`~o. u%33{22B@歇y wИvCsPtX4ܵXg\B}<~9kwo H[E޾k3gttl~g$ "q' qv̩>7)i./e$03]Z 1iיݢ%lb/eJ 5ڂ}W E9,3_\ FԤo*uج5Ҏ|5jbpRM$5"[+:3}L䷂{p>폥B;mB\FE-[o_?$]q Op߄MY'@|T@Jtmj`,:$-.՗.[Cћa1O"f =Y~o'OxM8To2#3ճXi]nVt8Hx S#PiL=ZK09 ~%G4asƿ+?׿זAΊdf]NC{`X(4 hHjaRR= /)Ξ|&SPQ4DDY)oy釹;—=Hh0@}l=+1y9CkF4{)da ?եEIm2|TXÍ0ߠ1[+R,mGE+ˣr#?6I6[/+ure=U9ưuj~/xxeF"IM\02]ysoҫIrWq{,E?kh՘4IB׿F Ud@T/ko\俛gEڀ D;~]G>ˣoވyV0,=ꝕl^]z 4| su/YpT@Y4wh\~cԭ8*͛5@ɩmp>4Ko9 \hJ.8K&7y7fT1g|2 uSk!#v3'TL{Lf5-]i-⒠4E?@zhSw}ziu択Q鱮 {RURGlC`w¥}]gQ]q~##lw %a5s!KEGl=ltG?MfVf_{.GչOLf?Cb2Ik{r0 s\$x8tt,&kcpe16w*ݛ[fCi+.gTu>B; U.&7x,ݘ'<]8ʠ?p͘F{Jk봮FGrdV}"J;DRzmW EOGePm"Pg;Ē8,Gbq3%;=frfK0#^%t(GrCNǧ{U<մ5HYݱ8p=}ޞ-ꕤT:I̻>'Hr+}K"^ù6 FxSYE*;? DCYO'0%?ۿd G܋m\82Ce1`؏rNj WS(O4dCfSuIh@n+ߣS50ia)%n1j>7>,xc<>Չ)2:X\&,Y[>F`A" ݎK>O9VlQ8h!RWzW7<+6$8n= `b<]3kT )bzA Gϴy7=Qv>!&.uOՠҠEsj(!MF2 eFvgM#F f$/s_;FS_`z)y*>CF 9Y FN*툟'5MӀ,<8b&J/p bur*1h9詁c. AZ G*VO"fq$bG~N2 )X^NT!˄odnc$Kd1?o]ٍk E1Kb`vf;/Ӫ#Y7{arKv}vWOHheE~>tm (`uhg2g4)SY+'%ٺq^*oɩ@D_^ĦtZX/:ShW1}c&ds0%hʹ&Pd-bwv5Kx1Kr:&҂-E]j]];LIO ?ot1.{xd ,I.:#QpNj7/-EO cl,z^9 +U7T^W0.oYdЋ]̜"C5c+󷚖D&M%ZacQƶobH0I*`Lt@/i.~vZ@yo}W9C)_hɢϮ'^?2$vdib?R݁:X+Q̅XZ̅V[1Ru$$zXSQn}@i!O9xBe?צ%n~tu#p֔p9dDJz*Tڔzn3pXd! _DS1q1j;lJpI?oF)VF$4ne]Ocf@q,yNO`|(sWgk3$<~[+? DnVB .]啩"Gn`V"^Wjr~V|½$Lcϊj.3e*/oN3eٵ}Z-&d V;69ZR(=R1ExZIP iBD aV,(@JɲC(_χWpgh@L~Ld$Z@$k`Y{ K ȁn4[ئel{A,5{+Ba^2p]ѯC$-.MM^J-)Ga%4^ÙWsȢWI* Ei4=*G#~ \?lKk0^eN$fth/G`C;&a;<+У{ ! %G*ze;mhC2Ժ `Ҍoч҉9lS>,G' B/3Ԅ;_šդO u%A2qad<%W(е׵'K7#^D|Ñ=_ϣȳoH:[chOa(ܓmv] 4EQiSÃ͹;,;? ;toJs%z6:ryOg;K5>jpE?=a5IfϜ6SiQ*Vb\pYTRLdRu*ycTB9Fvk:Ѱ+UżLQqغg襴JIjYzp*0D(|8I]ao03`L <D5reN-ܠt3;(Vл]+|{fH(7QsGjO[was w2#(z$TNEVϘwr_ޅ܊լhׂic |gP*? )\iV<Y4mF^Tzqaȉ Lz{Q(^j}vo*UA7l`?YA4{ u1ooNG/mPpM7\9̗,c[*rmA?XZeǜV"}D1dmZ^ WX8V$}L&6oV ‘ѧpDms'[Z%ʖdzm]Q'nvpuê_.p2ZP+H@j)/yT]7sb $ՐWgIA <ȋja:HҚ>Q|j;z/UF-bN-De ) C ׹E}xNmP3Pm3'9(FP%g#ȭ|Sn0bNX tVE*t5c|7`8>@:dw;@K9I>Oz/4Єj[T$Bn(ʑ7* smbj ~8(6Lv~UUirRݸ#)$h0zGF_b?W}1IUb4FM .\QCK<^aoY}ִ: eƎMB6*d+򡿯3qjJ!?$7}|!(!a !"! 1169N! <Քz1MW!tn[[Sdr9weak2 ;\#D̥4+ehEج0SJg_%>rӸpʆP DϘ\EW֪Q|V")3901~ "iٵJkSKc~^@6L3"e7 qcaP6n[>?RHͰK%V;K}{x"J&4e@xt9&$W(8g,aPI^A͛f/2` ]B L4}O@&fیfX L'~AFyשnw0^ M(_U\,%n؇+vWr e`ĜHNj4m lF_fM,ak>ʮDVm uTYM@O(b 뷙<\< 7XOWF7w7jH4˔K!߾WMݹM6WaD?Ң&`6zI]ޟM].ZXߌvÔ5Ź.T% ERH.F+YF٨i^x JQs6C@#|EX*AN\%.rF(l,(XCɃK孥bt3ʎû{! d{=1+wX ,YS1Sq+G9ȹ@!{9K!9Y8D_]4 \Ԓ~4LU~-\;:1˓\ݜ>{)$CA015]2xof:s֙ [I֓j|C { `i1.vb.+lQ:ӟg_Y=]\,jg4}˰"/ =y|oj:4bL(^z.2Z68jF=mKﮫ[OBo7Eq i<8 ް3:k-nrì6J{o>0 R9- e7wpjXp+r"cAc ؘ3IS0":C/ ?"*$I]Z-"Zwk#i.Zsk1ir6O 19pvg19{4(oGz $ 2‚ 5讀8o؉kd3̑V)/gp Ib7|;֔}}{Gz4$@Wz¤ ǭMȎ+'5 \k:3|[wN_$2f }6Ż >t'j%:WSŸ5j$ZWPOÐ]j" ?#FT4 Ad&9(Ig{oG)ԏGE# ʥ?8бIld.L#!oZk-(Iݲ;ySpVRl,Yh=Y/ވj<(\N 걔8:"y/E6<so>Rc|="dvta k m֢FP=Θ@Cӵ8h(8Ef)<JZBĨ&N=7ğ>15j<>z /QyNu`TEe  S jCAE6^0ؗ^XBR-7-VFZU[\(ʄ^c:vOemf CjWS:p#tq(a*~0 $=gGgLZмJȃG.F4S.u5DmՔYVZ`rJ*&gˌ, CQ.8@~J#Zn̫!SEQiW[nM%^ O{0}N {j%\(;9c=Dnnz})ӔcSù#wș앖1*6PQZ&US~!B}qGBiG7{9}H>*YfL~9'=;tKzletB1aPgcjԱWZ}KpAJwГnB7ܩn!,Z;ϺA=kKfgĀ}6+eț^ML vQ5Ug4-x"Ltu-ȵSTRH-ʂX jR! rxT(G(=\rvKRl0V%LTH-;KkWױ&}) (fP(1n睞&^K ۦ)S` E{}bZ0Lrѵb3!^/~˯ҽk=u$-]q5''MJi!$GW'9"БRU8*aqpKG18펾cHzNcTidsD\+aH6RSv[~ %3[=3.v2hAËtINYNQ7ly|4zK^ճi{y{WYJzl8nRmX~2mM&Bq;? 3DˉI.`X; \ < ›n'<޵[mWcXæOr狡eLSX>@6 98:Hx-WoiM?^Rw?f%Sj#SvkAT|F- nr{P] g2,̀eP Sp4r bti/:#Ԉ&-к:lpRc벢ܛFJtUS}ٔI+d2W*IUdVtpG"M,xb#qTjL8@36קLnxIR)"$YuVhh)NyCgG?Xm䙼--^ЭÖ977mRܱ{y3 *!r2YU)*em%NygxFWA+q(5W~$)U%tJm?U_RS̵&]$&@0!ѽz6c#$%^~>c$x5i#9 =/ߊ$.mKHW8I'&۩%X3_Ȋ7dB5xӊCI n!5ʖ19t(H pQvG-K5g"҄SxRr9Vs Bé 1xG/EҊgk~!@KAD .TsB[bEI[AdE 1N{6qWs{뒌}aEdȴWvf* *f9ِoŒGoI^5#!|8-c7eyCZq92U됖Zq?W.uI#7C~ۢ(AG-)bXAH 㽯g-ۂDyC%^bnL)Eh|VEpt5aw9хDoZHf}VVn +X%5jCA`@xZi&[43zI*M]qQKx$ȵO-zWqé8q2t%r=[/1](Bo5B M11O~ ۖbά<&%0rz SWaMr;~t)E#:!HڊNeE Ea{?(>dž50 !ιp* x셨]W0jK>}3KUSv W-༬5&FV ^Е`#<.h9:o`lm9@ kgP9GrUv00ms/_e?6$,2ށʿ=}GT5! \5Ħ瀙"ЫfsGZ-楦zeO#R\j˜ DTQ[@{שE@3kە # 9PO|8wTF_ѧ18&*g 'E%驻b8B'?_b,$󋶼eT>  &]t','pﴕdʔMyu>y끇=> Nl+)ƫ4qu;sj1aPl̤_Gf\{;O 5i&nw:I׾upmdG8R>H=`}=0Uo^KL*$ۼJ뻼LHNx\W V?╼@|CV>ZDq%_Ùi1cIKosa{BҍOa8"$ z|55_n:UV3/0!g%wQjH aiw-߆R5nwuV1?s5؃b&ti4E\cL^62|'пFǫ],\%B c~"daNաcB RÞAB] Q4^\'(F}V7OVB8$yhQ8ji?$ڱCL{!x:M?nQ q!T5}(O? }H='APqʯF<*uuCUe|{k)oyhM i,J@fQpdA\$z kPx_/?.e$9Rmg3%|@1>eɜN,yJqX87kLSH? ɕyqNTڡl a0W0g=_aď; 3VپVJ,0Qnl|ioЌG3F٫Yb9A,)O q2 RbZYj-3taǼ_ky#uϴ2uqA,)=&!gBU $CWVdC}c['lvMBg e٭Դ35(h58*>>cWU|hS Qn"u[#`w(vjl5vC }'}IT? v{n(wܴꋨ[OZ,/gk?հIk-^%Cu$~4I%K*[6g7+i c r|@T_V9YM%@kMyH?_ DU!Gȟ~$^ z?|]o`.dA@xE{}* (7^m{%MB093#O:Aj+^u:.t1jq ҋrz]bQ Cd : 4pmoMd[M4BDU(eij74fj_砮MH V?)|kU@>Ze#c?s|@>폸Ϗ;VSfv2/f.ק#d]GX)ƤzgjJXdC)!`/ɇYΧlWWJgP ¬7վH|j'd ;*-?aq\%,,qfQZ< JbKmXe㉂ o!& ۔FF)_xR:{W `c'zͦ-~:$|57"QR^6$w6 S<@-[AxɂkA;/F][l1J{dh nzdȪFvnvr3:fm/cŗPy>:';}؀ַ?̞ik) {cgOPJ5[t] >lB]rIKA"0"3-8)VP'uKk>K}sVNk))d>qgٯC0 ,Rq碛!fVD=kq᥉ 9l ?`'朲šՊۗn bg8EHR97Lz,ft(&a8NU1I>+sTB"R2" ժ%I%g u|*z@WR(,mBYhPL6bEuPk3LkQZcj8ZV({"`W uD9%t.D^6D B uܬ4# A 6 em*-F)^,P/yO9h\*g?Ae 8r>}@uotNKCbq&p1F)^w|6*9,(k7ص譋w Ē8afHoMRC\S Y3IH(8=Q2ĭ UoȂ+3y4|SlcG<#{ARqNT &>+uUxU :|X}:Z%WjZG%"ƙ%®tV^ ПH Fe}lr =-(N3. r^}9&C\:Үb ;_s';sVى┤U,UE09)vf=FPR'h2Vi5Cr )_}.8mAơs=w.V$ ހ\rct?81'&^h]+AςB!R>Y05Xhށ*燴s{~VB \y+l3YW;;]'A\WP m> 6sg?*BX̙9݋Doz?|Qd!;J݉ࠈFUP=P^Y\T®iSJE98YJ<'U Y ~䅇"B~s+1% .3M ՚ w#CtgHsrTx?'9ù{l&m?}֝#"S^I#vO1}EGiHcbvvp6(`pLI k-W_^ Iɫx'YM#'˶?C/K" bu8-Ym|6[mGW>Qv+!K0cWf-̯3z6  W[ #0m`B~ۉ5ɫq@hZhD,-ARrzԂf0#5/xRt[9 ܫUˊն]RыJk쿅My=Ř8cx ǡM+Fp>s7@A{q6l!mot^,Խy#; P Swu=!m;\B0q"%;Idw(3 'Dke]7Ga3c}vF&cn̕"fۀ+lGP! ]Ag1W]s40+PmϦ%E}1\TE8@oCFgu&CJVMZ3 _ wv>ȿQP~Ao @AO#loaBY ?~7?W=b쎿(땔Ed6Iϡx[mLJ4R#uUs5#\TL8d.!R\Μc8)SMq{_R)NipSw Ym٥[RAje[ ., j,ƋT@?vjS W4߉>.9M:8fu?6_'թq5>iy4T+;&8RtWfdy/|6!O&h!^*31SOr>0]Pw$.8bqlP[8_c/w@{xt0:d㹟k߾*Y?έ Qg6_{e:ժ \.̫bwd*ri3ҳը*]b9. dw}&Aٳ7ܰlAʟ?סnj,cQ_rXSJHC5'r>< .DCVp2͖[#[P*6zA1u&C9㚹F+M"z oOmmPYTYN "4hXP*_/4,X^zMxIJf/1BMC>wŤh+SZ3 kI8+eo-f1g?Tj(g- fQ}7tzF9&FzS txҕ'IqwE& 3ssc>n'o`l9chRoD\rD%f1Ͻףz P wSK+M6F*GXTIο(;8M+]@lNDh[/-=k&7=8T G7.Eƍ}TpD x1I\(8 8?N#` }s)5uz Ab]6b._p`یUЍ "k!zY S!^V6[z_LѓN- A`4 @s,bu-1#* W$u%ûy>( J| D.ͫc.`ro,5U]J6Bpv7~cʮELFOOڍAz(ۅ%:BCmG7kQa< !_6 +"s <9N$RJYCa> Q7195T콐A@:7.6~Nh AQxYB Q,P Fw֋Fc\á#`py]+(D+?ȉKrnş8ꑤ QIfxύ>yA8# :,͖fEKw(J^fҦ=`$\}_l86Yɀ-i|Q3^A˛ch.7XdNmӗ gx8@R@Zt{Кl4M)'Ɓkjw_#O, eY ӁU>y[SxFT݌ bI!e%OL`f֖HpӁ0o%eK96p映Zz3X"yx_WAfp'0' pM u#\o`?ayh۝)NzO9vVEيezi h%HoЮX_ױ&v;<]zM?M@o|6WᝀH<S"fB`n"ը5P=}) `|OZ#Ύ9]5fD!y #) (3rQ@'9XG8B'H}>ZawUt@U"B~|w@UջWuE@YC+֪ ^^9G o=61ݫcsr]Awy dzAZ/i(I⟸W ݁ڡ3M[&?B_.keR0w 2D9FS-6c qf-G¦Z;@qnt+ĽiBrw$m #$ia2By}諲!uc~X?$Zj!iLDsPO}B+XD?m~dcKc[5v tn\Zx$qIݨI++_\Vdɭ} 'ƍa̦2݂GβVG˖y{M?-.Qycօ A2z`/zw#GUɤe.< !dst-[{3Â!<"QOz&PdU1Iэ؆D!*% νsH(*9?ϓ=`⫸o8 d`{ HϮ1P!<%ZVԧ'ߥ\MoiƋ} W`:&[?Ka>މVɌ91fp@>ù.\rrVJq@ȱ*, NzkS&11VdL.W#߅yyV͌@7IyUp..-Om QuT=yrw@kѡ)g5Dҩb: (6vM鯜iI"V#UR-@ZEzc]uݶ@3MLFGwSqƒLBA@^FA˫KWe'3n,L\;X: Y\Nエ1D,64MbXyg  a8`ԫLtT!Eᒮ񾛒ƷQG}_{%H SZV&J{_y1z,m`g VO3,f4C1W/i2Ͽ7n?t(  VUSUo? /k=^G_%fYh{AՁai6+ oUTK@dAK;y 16fwH ZM?VS[{BOdf? R[_]g/Ѫj=Ͳrk@|aj^+MN`n#㗌[pAqH"gN-33>"%l7: zPL!>^=_4kgyϺ09+JR|z1VϚӛa//ה_MT*"9='fۤ ut7@OΉb~ 9OpKzNAl-d_Y}p iRvS+qTk;ǴG[bx/(j(`u 1z6c-$-hOy{9b>tC/ e{-B'j Ms{&ڔR'TZe?Lh!Hjc5k86J@Lk+۝;;3Auͤ l%t3B7? U4=I,ZG=֞]!p|%~E4n6āp\$޻ ws;<!6şSfPŰY/Nu黆׿[:'!`/ _18FhѶ&z"mMR̋|qg6,-4TÏʰ&"{U(X2VD1 Q3xEI'g9PxNjٸ(?%EJx򐎋||G 5ORJ)4D"ǐL[9 Z׭YETe. e--GA(7{sIIdFn}0կ7jbRiK$Ԁ@-݉LKgD:N g~xMfۻNhp jM9s~2J7B?5U130q*%:0^dFB\tJ#Z 0r٠_U=E-1'hBQzKvA"s=~O)E5UT#Kl 2+|>>HC/P7KbGǭ 䤕 x?(ra:s ^|w%]syʠ2 St͖+]t|/^C^:kS` }լ\Ù+^zk+%DZ;&pN|a1"}/qzdzف.TREl{#(Z4d'I%yh~{*HWw'vQVfɒ4ߓ&)k?"qcL0&B/XcL;HWqQh |]HM姦yH}%@1-o\TbQy  e0@>hsUNNtG $ ),[qk:C=zr\(ۻ{1arK KVUTC,\>J4U=ꂬa[tK5wZQ<Ф5mQ%F V{|G83Djģ~ =W"7L|pKw.ȹN ۂDbUxtbBuQY;.y.l>k},ܾ$;{a3:yBpu/q<KN dU 2?R"L u_޶aC_lS6ans6H:iBgiAto>>yGxx J05[wFoL㎈8++O6tdՏ$| 0?+AEm ~z ĺSVY*'%[FIϚqh }8e̙8GZĻ̟G2,]1pBso*=DRQN,9v&a@LޘԒ}/DމXOs3= kW-fv8LN3y}F˭LB%HFx̎m:~Ȱĭu~÷Z| tƥR:ՉmdT Ɣ-8J(1}9rA|CDig|uQ^gݟ;D.-fՓDtr ѕfbV)mhm1;Y-Smq78Z#{<SX.pVyWFܔިf5 o?HO_}9OĦZeI@|=XeVF'B(:IBH (2qY9j7tD 3 *KJ 5KW_Ak7tMsԟA jm]ftݮL!z3Xӂ{E-CMnY20CbfzdQhJ^CvDC7m R]-njo!AR^=Q87h~ ư "FcIC!g3"B`::ykW R #|DRו1GՂxndb&W s^۟_0_ 0)b8T@ttiŝ7 s* YF>6tUT R00ٻϵגt\R뼌_8š{J=FR&2'% Wu V2V>}Dx5#+_~. >͖'F| ̺4(682u㱛jSK hz]s5}y)4 LPiq앶7"9̯xʬr/`=! tΔݙRkyI v:ysUi5 cBdPb!JFەfߏpX鑲 (-X!p`(jNSƋ76(iygr~^CbSrQ~XKzoW`쀮Q,~8:]D&&y y>[>LkD (nf^3S|?8U!GtB9kPʩ|˂֮{$*| 3m w] VϢW8N\g]j hBiW$s1T Vc3j.F;&s\3P5Y4#1QHR3*bR| f`- >g"wG Ow(ѷ g:`{onYgqεrp&[tf05eT#X #m^aGٿN٭-֌c¼WvNxY5b'L:+(hBy{SAu4ivdB}P%(OznQEHUmgʜ* G#Y$_}jc2WnG#!FG :ء6 k'"7Gp(&7^|@2d6U6c!i\;A8$"e ? 拧BW <^,hMl~QGemuc~ R4[!vlǤfm#wj,R ׂʇ">}1#=$̔`[n^+zewy7D~d8MHz GgC3IR8b Ht*k/l! >𿵧NjlPuȥ==8.ʐC#NjC$#[y[Top;ӓV1[~u[R'd(e5$hS詎D{ lLƺZC"~sH>i ~7jW.r_frpEA'py5 WΉHk E)}|Ǣ,fF 43fT-1 \Nf<=|kAMy*`#W1 gKX(3"yTòvb;t\{rX+75 OS8(pt7~ 8qsa9c$⍸ppEaq>dm}3Wk&×5dph+UZ- o!'+cxVZ&# `f6L!|t'ݨ9v->EN c1m3C\ov'QlJr)K[d]}?L@1`m-T}9Zss, ,pq\|/;rgn]= {8.l\앓U]W[x#¾CTq nG;Dij=2NZ7F _}W"?e&O$Tj[~s-s 7sӡ@yiS7BʡHxM*kXFYY7BZ;qUT*T! #e\+2[ބ Syi횋`7Cs;WY+Y*˓H;RI(q3v /)bY;נGq}@Y43Fw.T'%nֹعN]2˗Ddi"qq_!SncO8Zќ NsS˾ :u}p?x48q6`ܸKdl|ǟSF$̓}`.5Oc"AkfnT=^þ GOq6v (4½JP*5P2'ܿx;cXJVK_H'BWSp:[x*G 4˅eh2F5M7^; N) =8c7 džj:&zᜀy_u)w[62:Z2E C4[>́.]+3\6OР[N>=Ȅ<S*gUkw~Ѐ$Ec`0}Fpl|0o7x@H\lzCb3 e}8G锨$+Xeć줹vlYFF`v7p7e-8åOI} x%zKCf_Gׁ{g8סg@Y! |htW\=aw.XGiמc[kW{J9EJpф V1$-&WպK\T\SԢ& TϷ TÏU7TZAieJÂ}bKj~*$޼F\sD@@ //ibBM07KuI5U1#7T|ګ6^)[㤵Ј?$@F3!g筣 )6@hc)M˝%ַ>[_h7zCq5<2<)-wDz<'=sS 읾m#/tT*K7] ; #W U.CH^ .Q2kX@MM~g&Ӂ{.l%@^?qfJt5m@]PqVgߐվaFYn[Vf5s]Gpl{ WۢHьF[|E+ A= e,0,&Y2!?9{찑A_ӽ25(n!~~89O[I^kVf~fS¢hQ v`IL,шm`/6~Cdxmʦ3Zq/9F?kr{- z䧡-R|UTzXjD4, P/$V+sge9AHݪvŸ;.+FaRL&׏k>#62}ʂ#||½%[dt($(c#5IGaRₑ+e-ZS ,]5Oڙa gpc`@k=Hf8p/ZYC[>j=l%U7o3m/WnϪ>c{ fT1r0Xc;r_K/L͏DPOv:e newRʣ-.T3 B+6[sY%**ԮbIkc!,7=27ôi?“?FDF}rBtF.۰PFc7Qyԇ00BF]~-^@:վv1XƮ~7~%u-?dxcJnd ߅Q;_b{KQBA0̓PMgcx<#C4&}lg &Tz<ʍ K_І?^a4p(ן)q'C.37URS 1{ks$!uպdk ]!IJwrSI$~A<"`)Z'5ƉٖZgz]r@ڢ;q$LNH"ٹ]Ɯ&܇"AYA[)]G#T.N8 $홗c6fj;׽;yviKħCsV 7NE1?V=ٜ'I і/*Aݼ}׫ F;F q.6Po;6_pَɒ Y 8d_3d#N"UiVumpooguPKßZW$/j"e?7#/P/q, Wg׼`#d$b"d>ΐL 2ٻ:AΚs sS4Xq\<+m';m䍠lsFuNs/QPdb_\,4lM8j0ujqntMF~;agE[c!\@RۈC hr\qݹE\2ɭ+AB*¬a|I3S:fn;TFOs יU&Gybj;3PXYhՋwew%,,`w*Qa WMxuү7Yezg,!1 ZzUw Xg ”u%Kwĩzݙ* ᤮-!M&pl= ihQFQ3{K{nL3i>`?#?C4MeHU_%)"#k&ͦu"9yFKb YePI",q%aw5gl{'zU-FœE`$[-u :!~GR5~(Do+f6Ja_ zO^S.^[e?KzYOXWngQcE F2|afy>C&bO?1C\넂T~Oc}Uisj6&WWOUsط(hǁZZAXf)H1^2 lr(㣁h zc}>5|it_.ۯe~ՍDv WN*khqw /쿼0?I16grY֤QNښ:!Kk\ͬ#K;<[1.U|Ju.)2)ؐ)?#%&1S-NʧTxLgDG9R9|I $:(6RP|N|1 w8>q0!~i'M>"ڳAq]QNfh[CQ>{R Zم}{>5Dsqm?l-H~Ð(e| S4`Yh"fhZ2ɌOF.KdaSN5 HcZ4CS H{ dxo8ǎHJ#M/:ÍudH*♌%!}Q˞5isPuc G\;z'; 8F8̅MRjm4`o,b<`(1!}۩C^ TlyAV9, $.u,*D)GKfN$KiK?DkpZ$۾F%CV!:Cyg G]zaTìOtT=$!sSt~qն;!#\>-#گhZfc1q Ƿv0,︘a(wDzWwHhmɰ) aJSAQr}]cliXm*B>56*vbnRrTѽ+"3MxxPt*wxy8V՚;œё8~jGk lS98 JtrooBI_?UkX>=0B&[ΛQ[_[ du\ ~MF窯m% tz; 6GI*Zv2IfڱKAyؾf]Z͠ " Gg/;}A H|Mm-5hD{9َXXp<"Rm; aߚO4b\T#(jnd R)验k ˦XVrLaDg @YPO$.߽0X9MKP0Nrd4!Le 7G1LkJԨ曓#zurCdt =ET)xM91~-quQdin3ibzQvW3y+ak.s;U8+c𛽀SXypb_Ǵ3u3wc{+&Cqd`&{K(LUzRp-x#)*&w?(q@^jj BިEQ ]xMnU–af4,Yv7-HKܴLø)ъ1yo(r@k*FN>WGŒ0sF;㓒&!+\9( | LP-v\f G! wG'0KRMXSt:MА̤r {$ D^z;ٟ ΆRa-Z~&I$ KGfa`obU'fX`}*&%͜\ E[ 5\Dpq(}|["#Rē7?LkΠlܥmҨW})Vsbc6sx!2|wHy\; r8lO!߅ݙ[=T2wh&?E6#OF~&TbRAy$~!~w|}ey4'"-c{鳨R0K7_GF >,-NT=Vŕܶeq4I\T_njaȲ_zngpY3W`㳴?4"RK/Q]5g x|(Ɵju%lk;Ưwp b*B/07l:[cV{Rm{g ipo9$c4%=Xi{~x!*o+@TVCd&YSy%ܶu8~#Ge>EEzD|0)wLlv{)XvrbpR=_S#J Xk'h9KYJ 3(N]^/ձTaдU>D.Yթo&qF ,\_;Z]}teٱw__[}p7lm o@EB0SVaᒡ -nv.@eoE9źJSj;F[ >H*j/̠u^%.T871=nB%]LuZm|2;Xo047/=o\P>sZoJ:(ju-ϕ}>r 0bϦX3E>Kb Q SIb~T( T?gf`LF^(mg)etOG+,8:DSж{|ƣQ5%AÑEpP'QX|g*gGrg+zLb$wx0Y1&͛Ƽ?{I{!| Mᆐ/$}Dyehfr/ANu |xi[(l|M4>kb)A_]NRaSl]f9*z뤎;xMJdQVH>R_Gn~I^{].޳.b´A ^S:``ݬ/_'K5G8hɱ(S_]3-g19}WJ/n1Vm6DS:iyf܎p |qf-)RXUwl\ SX59HW~Vr6#SY!GʱF>MvD|h/뭓͏9gϔ&]γZC~oFp78Pw8-̨)W8tuz8=s`uG8&fR z~iGK:.O:d+%{RG]6yF9.-Q8.ZpKْk/5uRP 桜:o;>mn,sT5rJ22-Ij#"<NXk"^iRsW3*BED9 w9y  e]5=xbYW#Z U:$n!IqSh^S+kZ:C(&c-nP(Cx]G^ru,3kWKfL$KFKj&7,~NwM,pm-B"piBTaL <ՏB/u2VhVN󔈫T_?wٖ LN',63? .zM1K>%|[׽/f ?nMW<3L/c+7{!5pFuy$eQ^n;iLU >{`n U9NA.iG֮_{c/pZUΥ2"WW@8$gfe`'2ư`@cwer$`d{_cE[Ie[ˏvܶRj7.$G HjTU0}&HY 5P1ydWo)C0-~m Kev)sh[w1فP؃Αje_O#-?5Zٴ(hF-X9opk5CDi-mUf'}1E4w@G mPN3b<V ϢKDIt_%+T֡ %T's+^NvnuX>!zQ箦{&uH,<@||  83k4 LGx񃅞@8 vٕaVŰyײ6" ?O3?,*K_ v8XEMzy<&ߔ\/<{\T7ľ\`9=ɈK~cA5k֜os+5APG9|UZ- f*cULAd$MdǭANr>:۲~jY`>t< 76j m ^|î;cRAw)Rൽ*qG!`P{e>*ѦrmB/s Nsm7Y !7DgZ\M&WF זݛ3X`^ AB.x/eҗQǗyly!MS XxAbUya1&AA%G1D2<dgIfN\E z!lTUHPŘcPa9B>P#Xӝ,J8K$H^}ѱ{·Fx=Vs.?Aja5k!s)Gf[<@C 2~8αDt9-l+\T_cfb2ZC[2T5H,3*etw]Q*;0';VEsPRf!ђ' 3P4&iqaÁ..J~ PKwGi.6zxJ/RvmVqs`H0_ZoAӉЂPu%a=?c,n_ ?8“kKe!E1WS!%PBX* l052/CR&M~2u]˰uw n=ОncpjqssbX^mm Qjʸj+7!'3q4QEHZ%5,9MJ"%7wja71NmJYp7,)YZ#nIl(mA{z`=܇^<@iפQWs4)0Yl{H+w_V_,pX>1o75}7:NI-8n@!'n+3}V\â=dL|9SxYBާf:c0zD kڐKbXuYi \KCb_ln/r`ą{2Vzc/|TQm~f(Caӹ7Q4(otryyVP_ÈЏ 7Кt0&MfJͫ^7!qx ^%`8{uRd=aԕQݧ^GvڝU6[jT^yAsaVA-3VƟ=!kJ_hNrȍ,4sY@q7=6QD^/'WůH1d:~ୟm*rŠRGdנGs=#&^x@( 9Da٘fBXAn*>UDHORb\ P钍9Ģ(_>=l"XKYS>QO!oU?O Y[xK+dulMU bf r0ay 5j,] _CMƨ x ܪq Dȸ\ί)c ֙0_3,&f|X]NhP 颃+=:f^J_AEQ%EZ! JVvq/;irĶqEax*z"cq%:o}pP58TFd2GXc+-i-J)aQ!f?tsrC`tq^x8E_ YyA~p: T.,C>oE&l$Ɉb\-`>yrdE+4`9˅ Ls?Ipޞ?:9Xre ^!!JYI#bL f(EH04\sHF%I̚1wW,gX6~dR ld/C ^m3ICEk%(G.s?x!Ϛt NU_I)]bQ:KsȻQRp-eE׫I֊kこ镕hL ٿk. qIj #oyǯPsG{+$䢣zdy4Ίtr`z&L#ɶ '㕪V I~Ga|o JA;ܨ-E7~.@S H@#(3ќ퀬?z! ,}WC7.o|ZQ{K'NmbT#Sj.A|,m2V|i>S&CPHE ^W6!1⫬څbKp?#p@ `3EL:w{|k; [{9еcE5e# # ~Ll11S<ȓRˆ~'kfQbP6:O2ƀ7#o^ygTAx:KL3 bqbs48O82/SX8 {Gzc`˓G0l+uiM0K-w<g 0nDٳ [׫ ^H;ʸyo{7i"i-[aDؾr5j*`bTlgOsjC)$[G,ݫ0A?5s_!&s,+gt;MEf&&(}Q ~K}Ek֐+``Ky* = [,7f ҙ0*@V_Ra?ᆈ^Kt쁊eJ>((eo3L~ 6VkFi.f]<ݓpm3#uSz20c6̢*RXKw^t|9dөZD 1B/xVE:[=IWV-{_HTŵS sڌt=:ʎf٪izGRXq~dD>)x vJS[KO* `_`/!wzU=TBCw&21l& }a؉/+A6WxL`~)Z\C()ˁqpSա,o/O#(^T0B#l2N籺Ȯayxm1(o7~)? %EA)26jysWcYXƺĹkm~3\!!RW>Y-\e{}iFq /ۨa6tB jy8-{<^;* |pUCK(@HHUsF~6e2W}7ݧnqh՝)a6롙9]с2̧v;x6vh;} ŕi>6oI);!Y7WnFg^׆z4d,XH ?i;1ٗec- K#JbIk'd{sXUY9'_)z$&ٗ6yz#lG5ʇ$tx{^o ,w1M,:a0X]5b"=4Ս.fIK˱} B ٸ#lܫYs\r~ۚUfLYx6O@<{˧P'ݓ<Fũ٦}LͅtRiUpd*@)THԟjN$)=Ǔò8IrVD J6D$;rW*0RfLS& v=Y&Ra؃+d ̓Mg31=q%E:!7eB7aژkA ,X ^wH*<.RXFp*Ak;g%-k/mtYѣF}g0،Τ13>z\{Q}pIEu< O)z-Fn{ph\1V{&&mLzΠeptk~bn~3o[q ^*zgۦLe,'EE(fvꂢA(`7Ęt.ah+= #;L4ccx9<G+3V^8g$̊@P^(+xnF~wh-ϴN+Cue/X/WvODfYm puPk&شh/ ySedPIU1b5=EZ1x,?9Zeq:2"y(9KZ_ǑJMl'Ibwܢ bBCaE-ۯE+sm\qd$N0 L|K'Y(h61lx[#^S / q~QP?g1naG']9)+L4eIwG hfG똩0?G!25O{٫yJ$EWuy у`h]Hܪ=ޓ|J՚a2^7jWV̚e< gܽ='t/ @i$j/=콌7-VOg(dm8;h^~!sZ (:De恜BhXz[h: C˿7J?{@8B([a:GW|KjZ2J˾#3E8d^Q8}t~ Doz7:o-H+0rHA|wH(*t,ḓa֝|V^{w-a+XM6qj[t.rIbwd(D4QL<[[ѷMp9"S7c 9&n]g5a(b-]kVPȦR!V֮~E{qT uY1 ?ӭ[_a T}s2~u9,|n(YXL^ͶR;(u$!t~$1,W0㿄>3[\v^B?TH?’,8-,J@ ©0’,/ Hs9Ę5s [I↳̞5uo~.υHh;`0d&Ҭ>2Zy@ҕ]?5ú H tm8͛׫+8 k7b=P)+ V4`DLi5 &-q}_]p De_FKHq$)s Z8طܗty "(D!Z 9;&Cq}R%"+Ǣ:>?W@γ;FN՟1K.܈/0k]/$IgtdGóe[T L8*hr桩JNl7̒r< KEemS/Ql0FyϷ6} ]P:AD@)@~|тGi ( BmPv&a5"!JБe^FDŽo+@udbAFӺ쒓h3I!cuƋE~f+aY.svq gJZO݌$aQ?%B m5jaVs_Kvu+6Iԅw+.9 ڢl"ֻW}Ĝ$Muj8(h7r1m4d}:C@'W1ż越9{5Va" :tS9rJdd8^$ϣwD4P,54(j -י%a@Sgtkڔ~.GUޮtq^qX< NB_;3LqlUM edo8В =%qa:RDZڅzZfL$}][MaglF &# |$`ncB.Ipc{siI uR,!Z}$g}:U"&#gc,uѵ\.l阮_{$䤸p5dBD $Gsذc>_(#uO`_% l4a??R;{:885mL^Er#8܋j=xnawFZGE!QͅpK R0;xRKI Xو% 7GE:_yý$R-Wxp9n/ZUNJXEesK5^9pϏPcw] M8V5VY7\<[亄^]%ό'(B[c"'}Uҏ`mfSڶ!ybV_iB)"5[)7uܐ6ެ@[~qmHylN$ fj9lDd -fmHL쐿˜^(Q|wL@u&Rm]@㸨?~O84 D͢]{V ZKJ١qE@q7ه$b oT%E85:pK5)'dϘ$? WBFu]4 fyE]Jӭ96Wn{7v2(a!h311n0N';{33JinuWcK黪+=Y+[!gdKʷOq%[~ ƭtq6/)(+_5kxJ<^$e.R~N #* R 0kjڷ7vhZ_WK5ִ2G0O92pZqh|7ԑnRjau)ܴ34MI|w A L!9 Q]U#uczՄXy&܈Dr5] O$=!r.# _sңIYĵ~0<"ъ}hf *JaP@z0C Eo^{= OݞRLcEaC(ip"~s'jLd mO"kX-h fӫbrŽm8,-*f w >BiGQwb=ߍBB~\s~O"oњjRxWN$1ߦ+˻W.1 lb^"gۯ~wP&)GJr OD*Ȉ{*k ThJ|P{0;ʮ`x\.ϑ<ǀx쎫Vh%c]qk!LX3=r!H3 U*6hPz-ܴK<?s&RUb_XWTs >iE YԗF'^ 9#/0/dޡ倇&3QLe|!KK׳pApSr3Q ><ȵ "٩LU?2 tymm1 @!/\+g`JvV@( &m4⹅lW,/6Jrx_Smʪv, loc7/G# ÔRKJw;,$f~"|^jZ_JIYm5z7: - όwD=+,[C ēnQ= #РֹN 02"nSvz`u#Ԉ~En{E^γ ΀#}ڑ[/sR41Jެ/jifczpc'Sd%FkfRn@&"hT к 0AH@E͕; 0L9!䷗YUE[(t,){a)IK(;ϠxuT:i;ZbbS}xAx39-3ٺrϊxr._ܧ'v_E# 27 ?#R6moiLz%7D<*֦[3{ G߽t%H4]#S| D<j6s'ʷ7Ȏ%g\`֜IMK%|<6{y.W^F*At%ؙV \&~ aPEEL~:@:a^r+4С l|j.0A[E(\o?~RJ iM/^V1/嚞WMr_T̘53 ޺zRYxh8_`|?V< OVݻ;"&Vɦn/8NF^ʺ~P=R~<&-CJpׅyە,0RB!02:C V=?[Z{3fت%(t9C W>xQ<pL{/48%5ځ:Vͱ8 2DnK\+}|Ͽg%URi? Xn԰ѷ.&#M}ލc)?ن>@ˉJt`/P57W-$*lъKSh%Fo/*&^i/e![3_ ȞG{dGn7 `,jWc}XgCCLG9h5~hrqu?BCJOɹ=(O]w f3eov~X{4J2Q97^KL;>dT[dvOׁt\'Sa̼?KVi#f:;%|L㋧eO6&o;R 2h`'B;Ka_uzq%py_&p^; Xi2O ejHsW  wh2@ i/.8@F㡎%N6r!JP$Rv"!#F}\6ob5j>OfW{btdg`R6 8g/a7V'r9l-DN"DX `R:7~k<򦛫Mbl !e)8@jFsٵ G 鸕#nG&<< iUhN/?hq+ 4VS I2 U|_0/`R2 씙gM\_AzeD=S^!Rkd;vk)rЛ'YD -_VA:ߐbΡHQVdP38`)\56gc#u1>NɈHt ZTa__aOq1}]DdDoFbAS 򰳚ߕ1|du=7j SFrBbz)^ͪ!-7,Ʃ!+@YY}Fu뽷úɈwq,lrSU0!~{НДIAfW0mO=+_eI¸R)A ] Z-\}G"zl t}9`d>Du! p$ 6A3]bIf.5RuCHs0˩OS}yư{p=BV$g"Gְ&+6}c4e#=ݮSl6r20FAHt5Tub篅*NKg̈́X; C݃ w9v$)71h[n%pyhy@,oerz$?~8m%Γڶ-.RshEzO<=\. vy%6@Τ2q^Ƈ 4/_{%0׏YFU]M svkZ0CDEȁю;Rм-6'+w0?0"3AJ+Y+K쯤m)`JPVu_4nHS 1-zDBpFƳ JMKJ:!!8秪ԈsZjHaS`ԦTwCp95h,N8i^1Ehjz }{dYg1pf-"RVȅ b }vk"&b^"D=> &eJT~ NF#}?뀍]P tl12a 9+Do4vD^kr**v70{gK67r?45_Do^1 ^'"")L>S!^!MONڳ/xYw쭗4!" J1)ZVE s?J!:9{8Y'4meuay%m2;< C`Olٮԍ^nIdw &4)y>}xjsrR|n"l\`k"XG 5)S`{Vɪ21 !k#:Oef4؞tWϘ<!^'TC'{͌F M3\o V`r,W( jS@ Qp-`xN(;~BdJy^P>ߙ#! ūoڗ֋D^+*!^YLGQQ?Snyx4H2ޠп/C,^D|WʑѩަZ6/NQ$3JV QaƔ=or-S= ؟8/Y!vҔ0#-\6f. |MQ?X1j&j 6ؐ>)ۡ\xÒE?;e?b ߙTRME--eA[vaGJ[טh=0f>AO29+->~=sN% qg7]5hg$JYh?uz?k jGքhѷ&n"X1-ĺɩjb X |?gՔZX fV8eJP:d2RD7&\ē?oԲR&pۯ΢0yo X+Nwn@5< PW?%U䔙DNN!dqNXɽ۹8bby `;! h>8T&#LrIs s;(r0 qhv,\}'M+(=*^òy羄VB}5ػd@(]˿?_ {~D,V͓j5bqd<-*P >w[r$>l% #{EU .LԹ60h034Ѳp}9PCv¡;F՛eT:R/#N{.`!ṛ́z+uʃ1roG9p=OᠭxO]! 2ę6Dмڴ:O<:K'D-K : Ojby젨Hƌ?Ys93ZEsqdj\y~ɒX3ӟT+C7~`Nw# ` !~KpuͲ7cv`_vo~qygg_30$ (2u?_ZY* uQ6J?, x%tlozH8_~lҲ/y4jDz~)Ēt/ Irdi;ʿ_o2(C}X;\8"F#|~ y'6$%snSJxA \ dG돐Tw7jqqv10=+qNb<fӅ@(9lֿmkWp [,hR/e.k3W0Kc".p!nt^@gh_yF O39w $6vf娀JI \FL/mUv(j*Wv*m\9.r.>?cf (pk< ŧӉE&q[FŐuXsȢdװo_"AtUQ\S9qPQhm33%M/yfŝA" fUuy=~L=x>Y,4<۽m|U?td8j//i ǏJwd+ЬL'[ FӲ67rzOIP_$-0qu)^$4U_uMh#ZJKqe@B\;z\LGk&;X$EpCՊ Κ(V.vJX8j`F4ľ.ٛ6*ZnA\֟V \_ކqĚ,d]'| uTC5/Ё6t̞ E w$WƏQhW[u<ތ8)!C6UM:unՖlUe@~%8? AgSk$*5{Gmwo5k_tr\Ho5W]:b ׷eܗ2I!'jNK8_2f7r"3?zstA/;Cg+ ')C?uHY\"'eHA@QK@Q)~-'ՎV$H_*tžM$κ2ˉ܎Q,= net8DCU{z X[Gۯvnz_5YѤ֖n'mpGI0Z7uMy=*ȤNaEJd: .tF5ph x!*c;@Bp98͜SU{Ʃ5l|pϟ,z+qnt)e R6 j SZ=iUOHxNOP[.U,0`{8SX! ŨiF*lllYSCL0ZȺ/|^ǘp2f>S&-x3}83'hqχۭ~@[+?k&Kk{'#^dcu]|'Ɋ}.( eM l[ X\5E"8 tO?F4R[;jS@/w Q/[}7qWתGI)1-kUP@^ 2LxO䠧 | /9e\GU{v6WT}P7"&3 虪dYq?.Hdv]fFp0kF5H(e*[/%<\uJ&# ѐژi^%{Y$<09k7UYGx;NJ_O/TA`bf6<5Oώ@еU%1rt[(K*燃'5E`0RH'#_܀rFXJdqxB񋔷j/c)̠|yQw#SS'Q<>rM "1 ^m"GR*nQ`R g,~$ x':@nd-|^-uVk]r U1~ĀʉK(K|}e[r@D)4jwgj>_M Y>!>(9VbMYپu:B)%Fa5|8oJ$MMO]5}0s(X,CzP&*;ZƈlV.nrlZނ1BCJl,kJs^e,kC*PΡɗJr D4l蚐[y1Q+W=F‡z1|Nxҩ:?mÈi -\,uYia3 eIU,$@Z ,xpseyŴ$H㳛I-~8ڤ"8RoN Wgy׌"Dy[HKB~@6~88J4Qe0lZd]M߳&0[KfqŐNe4ݓ^_e$WN sҚN!lb칦Wi%z,qԠtN#qS;h 汇5V3I2e05]cq=4Z-aHOM\J i;LeHVerl <T)Nрَ$!3\=M QBpjǹ'9^[,|yrSyFxدui _߉1DAGfCnFׇS䈞ˉ*>Vl6a`Vr3-3#z1"? 10in% _cSHAAw*ˀ0&};R$<9OaޓjͻM(eml)=Ce?0' E怪2d (hڬ|U*1m8zf^Z^Od9O+Gq۫00O|cA#r(ԥ6l_¶,C-~ m [xJZG6je%UPTm4.EJaZ]H& hikNbӏa\h}j2J/H2HP|tA\VnucIJKAkK]e᳷;L~ǼY#lx bXem.<ۃ6\w:aP GeurAu?nQd>6D %b#fEϧ0q} ͐ ! ˷mݶ6&:$:, ATXUsD_ HE oV kBK4+:NHk2yM-/)cח{Vf̡Y odUG.p/`=-~0&+rgyC r=/ qmp[BIg_]uwϯ"-w^Fk|׃F:J[K ;lFr7PԠU%9ϴMsX6/ 'حq}IY)ḺIl3ޫވ=ݡ1;@4Tr7hE5B kδ 6 mǭ ?xZtdo,l^"PZsurp ]U'(aQ`Fb1sW@<ѿ+2=I>2\ )t]tMOj HmM >~IIN+ [r s9UFpS|W۵DюkCo'"Aѯl)c"w"P:kKunONrLu$rƐ@̟#Uۄ6 JT;2m =J'$R#$B u.̐lBpqbAE sV5|xi͈ۇsRi.d_x5C°uy6[tWQ-SPurٝ|@j9;H|P_5^D?;8xMU3 G囶'W90qwUU 3w$d'ư{8%*_$9"c-TtĻA7DMhh0{/["MUZ=bb͒s&FR*?dyo HP;hu(H;B|'Ѕ:i:,c1OÀP:yLgg!y6*].ϿO45`^::Z]j^Y[HWG h c/pJ恉ZhW˅%Z vCbSR@ro)kܽn* %#46=râ9MyZ8c{/hGS)he6s;!ѫ70։[j_@HL:s6~{ U§$s`X郺iq8iS?< QZ^Ҫ2O/̸ &|g<͓0t|z'Bv7J7Ȱ{쀫Žwоš6ԦYBuTQQ-7ftԳ]ZqH8q:FTnHWQW(pxCof뢕'3` +> O.~l]еP_dTjP^댣WeݭwzVŜyZkt ^wkLV3] ie`et[Ň-I8K)Cm) n@S␰bah;E>(ѰԄyϰsH[1e?kK@Iu*&#"B9N~jⱕ$5.r®p]qef$+7A@SƤԶ(IHb%^Н x S9VgRk`#v)t3Ȯd#-%ߗU#H*^5+QӶ(:ɠh/W:ԥNn%oN<x%6BZkY,E[UVߘb3(VHAvbAoܛ%_*_+heng<|* *)qڹ a7K )匊gx‰_=:~ILWRxĞ~T$ڕ.l>RAFT$` <tdx%n#y FmMFU,FT)l'j90I%)KdY5 o,Җ2i)ABz?dT@^)Ȝ~OR inʹ%U-Ӧ1GpX`?_Â' h_l3 `9B<$21]?iB0Mܸq*Dx]Y](Vl{ ~0vwF+rG?5ZZj}o>cB >j'{i h>+Pt]/:>C'馼ϤU l^pR@k3˗ɡVA;oKb #6j=n@cuJKK貌mO sw\z$(yp g 3Xp8{(Y]n90˷-hX^m|JKGe/(]҃<.0;}mdXNzFXN,'ekO6zBdDUJ!KI#4* I郿~4: )ǬDk@Z_!0/ HVR<5LXOpxRUfOHSQU ߾Mi7+~~! ?M1;TiTS eQ* {]UrwR.f=VdL8┱С u\\q8Aj?{]ju>mC**-&NMKCSB! _vЂ*q{+R|;qO bb:ψt#a}Ɲˎ<^CֽpJtCd/RicEL(7bp9^ &"Zm<o,q p,;E~d=f^$*aNvQ~Q)h2] g{[ſnd}:|2bM9l#^m ()LM*/tQ\w~jŃYhAQZns]oWrGaޓQ~cBZK)VFDjn^_vE;ʴ^I.νղ}+P2@!h,uHG#lY{=ԍzU>;,.B RiWzqXT3S[bG,UT%yk $vR˗+J6@.on=ډs'zJQft^}zΗ.rkȭLinA!6pٛThq;#kaw}Ih.afOlj cH>RlB,TAOὈ~"XU}!shsHE!Q߱>~qі=GͮסWQ0|,^]#TmMQeI\ WLSרT%%d49!2K[jJ/7G0jG1HT]H7$@U~0$.ܜC LvCP7)s2t 6J314>D-47X`\S WA=Rڀc:8`@߹[We,a3[U{@<юׯ~ ̜1 rZppޒ"0ShSȓ%L"͙pGR@WfrPmO'>$?u6zUԺQ';Ӄw3oUi9C˗mYB0B^b a*bWV&[B0 Z2J@`DO /"wWyRYDTOH슈^D\P6}, iw~U H60`)Cǻ"+J^GLh$hG.^wl0nSY*5fDǰK9u<==N_:WK}tܲzfe*K,Xffzqb?ifU rKᘸdNNi_7PӁw +X!F.jlfs{&I഑'DߒMx<7t] )ep]T(aAwߐb1'1,edaQcv aYp4\}l:F}>뽓`:r$`5?Iߓ! &̲+qnu[զ-M֙w/cCwz`JVᓽM;ѰCL,ym L(N[k؛IMOV6>\,w(Q%5$ !{UvcĄaj8RvTEQ%)ԴW9[zЉԾΨwnx[$0x2ʬh4;i $>OֆRUulMTuZq2-Mh⡽-?X&Tq_ѥxm$$94Ab- md/ yس"wUwuT峾kºn85rY3*W4eǩ&O 4²~h.=wgTCH9wK+DUEGߒݼ X.*5 KFL q_1O09 % k^3`sNL\j@xtz]5}GaԢ!Z@S"3};ω<Ϣ [ȬCC]pM*j*/aU}HOdeDzeDq~1Y8Urʈo',A)G3ss~Ш?u4oO' 7#  &QG+X[1 "0u"S%!gf?Nzp Q|\셮ao |Ydx1hO$e3.xud00i}^5l ٖFtetoia.R|AB< HÌO jo1Q|nKv$*Xj(1)v su=|5*ʋi&fċx)EEsRV~(_6tsgCBkvQ} /k‘xG0C|cuiR=!^LhbC3 nx801آw`YmK5^(B%2B]Fst,\jo~SȓeTXD;PY}5}a$L^h<3׊w6e^{TRmm!~1QXl\{O.ヰh+9MéX㻚o:ءDIR\s=#pFWfe8Xu.ueB8 >GwZUb?u ()`I>*:5pI ,N?y௭?=Ky;a~;JbmZ9^r7#'p-s$k`F'nzjFxX""ciG$Hx*Eݤ a .Fg_K7[X9llDjA߇ml\rzÞR_ĝ "4(=߉`q>"s0uSR-fNQbkLWl&B@Jq/x{RE&ݜM[ށ Ķc%)͢vnnXxnDۯ?L̞mpbnUD@E{m b;lƸh{|,R2`1ds*Ojrޖ%8]tt+6leA9zr|6A[4:Ih*c5z7+hw~4 ~ f(8@)8qƞ6Ϛȫp+GyL9> "BZ0.`/!~¹*Hq*N6?zv0 -w*zh|*XgT }Z3C"8'C3F_6:KXy4D]cur j0xT uM[1'_v$%V/BmdN!%h_°~ [RVU H^IS#gB(#,# {`OAi}s,ϳ=HyZ~>!6 zt0\ ~9T.0W18#CnO:TB|-ӀMIgζu3/_aLyC> E%-K?P+4Kr7$M\M]h-t/V(Hs+o}3t_evV׫/V!QC{>Op\n*!]U}@ ni}g+7 /f$Hq1 c.z ™cQ'[0)Ŏ`0ˣ]9<}8 ΁rV[ňB&yGp(X UԀYI.IY2ElF38o;2UHM 8X{0ΦƤ샊5Drho\79:Z0yγ`kw B@jB3SۃbHˬ*Q[L_$&YTP,LBXԧVP3I9}JaVeqjV^*f X!;$ZFcZ;!ﺩOȸY=:RćYI0huΙOb ^ϔZ>!RW(YLxk{4+L3@<!`?D' x'3TKHج7SIg<ʐETEe 7[f_+G.ϞX̺*)Hbuœj-ǖQO'ؤ&y U T˨豝-I-z1pסkq78/2hi0i;vKubʷ`QMG1o*rTLq4z[t݁= m_ B"Pm 1O8fp% sx6HqKī#qEi+PH 0ʀh)rЄiOWEuGl}v}d.`TƂZaɧBHSyIi[B ~SwA?o<ݬ/(e vv&BL^ϾynO9b<b9XM>zY _:Xմ Li8\8AmPUЪk8;aީ.a~*/9SVX2)øݡqm>z+~cuJ!]6‚gflwYf#n@ZwcTh(?GE e;5bg;fm`wȊL w0-W*ctW.i<Mo;;RVXoŚ7Tp"H:a\v}JjP%> `qV(bUkIĸ'M(X`Z|ľ]gpL^h&+Ld_Α;j9[^P5Tz3s޺Sgj'WO\9sE ~ivR[,؃]^ gc'j܄Z9]@ƞS7\eX<)KQ4}*Τ$ğ' %oz2+H V!QN`[`>TR&R{?TΘu rGgQpWI4V}MyAaV6.mK@Wo=>m">Ҽ*w'1^ p2gq+mM+:C)[;1x/sZ\j[э#|ҾϩTH9e):eǸ ߞJ^aU/7kO@ou'L"--粚jG1{s^g[VץԱ}OfXǐ0 \ů(ߩL;zqɞ62.İyQV746ߞ^~q 3ĻRώQ6&(Wɡqt):qQ-#X ù:sd,T?O%,lmz:&ANЪ2@&_ݛ+ K jfnv(f![{SP_h)#񟡑;L63qqeeѥ[d6(%W*v$pT2]AĀ=ca#vlpfFp#ҠsPmAOv7F;i%:2L6o 97E3S{q,TBk}d`V>I^Mj-%4üaxmL%b˰Ø6R˰t'}ef`:xPWfslx#*^Þgf؏xWGˆ:"h4/]SH3'4:*F;cST)X_iff|A mD03: Ul^5nKPb$@ &~︸ղc*_,*h`#9%ÒT9b@u _gSQ;zn@b.܄ jXM*i%]D1U(uN{ %}}M#S@9Ɛg5ޮ8bMt_"2LY'໪0d4j(%΋vE*N ؆DlnWd.`xvq^ƴVAyG̬x5x,9{kJ?[=$G(4mVJ럯H A#da}wZh7{4ſXoo>4*!=V?Iu3}F"][!0,_ԻA.=g[5<`?sq?Ӄ!Ԏb91yʅwD : Xw(|(9ur0TUqh?  zOCԼ_bc_ "ZQACo0v4w} Cqѿ'(n" VAyx?iMN諤fPNLMcUw|+\3]pLղwՒ $j]o8b#bM"(4hR}rwvU'џσtޢ=|->n~ F~h~ÏTc@q\^E-:N4YVs7f7sF<#*«K$5RtK" @ L7SCcܻggrj%-I MuS.{&AiP>I?2lA4Ssx$JLBy|qʆf 1G; s2W u$JH5Y2W]oh@ܒDijih(UW-}CyyʱSJ0aNYRDׂk=6CeתvnDZ<D_3cU ?ryXoGѝPN a ĖR{“l_?%lif|cPIfSMC~{fDvg#IT\0ب˹aj +< qтo(CXuO[(i2Ce7ZvQe@ՙ^? $JPm?+t)6B3n4T@3~3GFfr(픳qDpY_zz^^LאXbN>/^HR¿eZ[W9SO^AN 1N mޤ>eAI[7G6#FZ%[31T Xw>=G朙JTm S(ӑ\3Il\k3QTst-qUt|Hb6S ak4P+]Y|]FLU *BTuFxg+R`S@Hj;Q1N(+SCN(*,KPQ)bt>ߠlFj{CX87q^xOEԂ6?HiK 2 ;՜iC$vYZsQl \uacKSqaD^5T)[I b%j^SƞzuYFxA hߵ(Sԃ^ 5В<_$B>~zb6G1*UTA]) ߠzؚR (fiEKڍPO%Ȝ1W]q2gző̘>ͫZ^Ax30Sr븽rh4b5C H=c:8( -/ lbըQYd`Z&1p+i'2ШKO| XͨNbOmruaFkdF: cO7uoYi?(9Hڎ@xYI26&U:>/}}_JJ^o=%s>jI Nתrs`L][!l(aSX7C =T*x/go_eCg_pA3cp%H ]% ӹPJJ522TΜZtR%\.J r)#yCK)$%\p&ݮab<L1\M?FTjK +t~8CJ Οv *a?2!Ji;)*CSIݿA{7(m:V Bj޳oeQrD#1Y4\VV!>#Xo/ݬ:14AT<<&]v4҆kc?Nѥߜ}ȥF$QWL V-rFs4[<g.Br CW{qRKR=VMU ) y(%O1ٌD2~V[h.?ʺv?öoGHEwZo Y0}!LO+UCJ-~!PYn@ѯ)jéy97ϝQΕ| U(i pQ3:_rtLe rX}WHGzFD5~qv-j1㫧]SݘT w0nf.UX+U)$.(Vek 1/mPOصL4T+a/^oyk!~NN܃5  B=*vSAQiA_9b(sa?KVdE@&.bV̢ 4>M;pG QEN.&!0~0[T6 H-D{R < c7fsSB#xψ1p;{۱2l,bOd?D~M }Ĺ\}|ebEɋ e,dUud{Vso2%JN}(H^R4#Ryf/Ӿ Wy&̡˧mq5Y?!9 [iF_qUe 4̅s`c]=#Yچlc?^3Pw^6q~'{?5Œ pҐniSr{n#Z6Û00Zф)%By[,XGKUd2t8P_½ɵGvԣG R،́" &/\G@tq"205{A3MS !^2ˁQۊ*F->Ϛ+@Ŝۀ`v "@!š0ciXӾ5֭mXƘ]ğ$rb-3= |uEK1)~e0O,<[ِ` 7:XP.봢 Uƚ{B;yX7p0N4|.wNqܠJ2#330)3!DE!T4Cp~m 9XCk1G%;Atc7 gm3Zê ??Nζ7z:bFuN\~[nkUe#4; O(9ČGyzZW d&i^AUǾ_ =z|ӌ vMy?ԯˤJ. ~l}obM$ V_InhF)=q[/AnZKRDp]7;S<+2T*H9jۭF}LX֒ ]nh㨔 ii 3"H]$-KUcXBVdJ4Q=f ۘ{Ri$pGlKxnZ";ȉCs45@$c yP= y+56 Jht n]&#/"=;hx!Wj& DzNڐâ $[UDAhS#37E}F9C˹[ n%"qd* W*2*1]Q2>U`4rr&۲[ ;*ſK;Y 7)iO{W8lٔ~ۑ3#~dsֺ}e7)wHbH# %BEwh Ae>墺H3 IX9l56N?W`n@A*`ipz-{lXh fqL3.MSܥp%Fx *]ʚ\Vd)<qĸS_Un A V Rh=RRKTd!n/XJn1ClxOъO phNM GU`Xs"[WcmHZKQIMmN1a] u/löBdmZr,&gR (o Ȋmh"*M.8'& ݒk8|7f3cK# Y.|hYUk 0pUʍds9e~XݶGco^wfEUg\IJP0]6fYD`Ro1 'Gev-/%y7a[$r1=x4]3lBB8X1k(H#zGؕDu)l{µ~E+rLkQh'Wd`^>ɐ#MoA|AIJ)d9325/*^*{?5x'qulocs|N\cӟd„i=w|/2yp% [i&`<+g6j9LDWBG-FMP.8Dc9{t9жC%Ľ{~_&#twmzzѹ1Bp7'h^%zR$jHY<ֺ{}cL5L!PG9;`V^%(AP+jOб_k*`[{P"1Es`= _,[fϮ:9^Z{L|Ȱ5Tɑ<jÅ*%#a#V- ku xMpha"Ob Fa*DRV5lJr_7W2TctZUtW [,hq9!Igͅ d&. oSMc?]7QuPNcٌtX흱/M}OI']9կ:=8q 18w>LE3k>f@ֽ߫fG^Ӣ->^O,l=‡xfbuJ v8 [ ^Dhv2K-aQ@Oi %Qn\;spé,$&YT4` Nc^~Kk/wQPDB*GI .qK;R "$E4t:zx21RD94{͔2`}!u3u1c:0 y)Wr@~Wꋦ_Wq:/>S´EjL-HHq֊me[oP mĬi2 hf vb) {!0gK&8Ψ%Æ8xb @K "I6RQ&S.0s8lhn7;\{`NM I˄\GnG}F AJ4oxr}o1N/ϸ_1^A$2*f| xN)eX$Ӑ9tpv,K0W# h_ *9o4he%en+(YȐҞh;TNƀg7͗d6 QK&,F/F_q(owdШ.<4S<Z 9Ѱd ʙZڋ-1e3#uh*QBCic wb[=h4MCen3νaq(f& |Dᆬ 7ƴF%3biHY1vS#Cͱ|ːu~?2~Gi%""p>^-<ٵ# $&/ 2 MGB>X$Fϩ#9N;Ll{9|vw$KjiS&?)ca ~{0NrpfPY!BfEt°" 'Ph/Kõ]V$apHFAV許ɇS''W4)͎yAdۚjU~y^ 9޴2fĿ;~9C)&Tp}W@%LMoG@)eO{,qiʷXta`նYt8QBUq$KQvkW܁b'۞TLtBU6#̇w,_V'F$3:ӊ/;cHp oo^ ڢyvįR؜ ѥD/ 5Z!aLrGXZ"vHW;oQ'jpE4e/+oj&=NF"]\NKM5D~<}1*Q|ۍJЊZ0N~g9oW[U5{U>YLZ";J5V 7ztK#1Tl.RkR# _#$sR=~vHϠ1߷TprϪ  ѹӂ{hާj":žY:Mxi޷1Z:Yu=JN0ԫ#:P,ZoR5Fl}~adbܠsN-`9NKKs"b*h ju׃OzEY0=Ql%^!cDCuMH]*kQ9qG>c.!bFId?R\0,ߌ $#r F̐ZwoBX(t#݌ nsT&+ia3{%e ǁ 96EO'E=]\[v Gܲ?n~ u;p"]q?@ڗO%ЩQ2O}4p2j<կmE8_bsǁ*Xqn^J#5PYh$gRyW;GmHS#.Ţ*G:=&eU5Z,tz߸<95%ZoR9|ՙGbKμch1"w͂Q4Bmnqa"c;+PVE4#z-syIeᨠǜ7B{WzdS'-W=1Ӂ 1B`$plҐ'fNZxdlS9/FS K,ECb O~m3B{ .H 4 ݥ#6-kuWYj6~}dE"Y&n3E. ~(M_!>?G@{/ %?HOc8W XDRn)/rCrvsK`kP:#Oy$my궏@AR6F5) `؂H`c޷-@N \Arr.+Ev âRS\rKϹd 2G  tڒX eގj,!꿵SB;[BV=3R"e[\nd dBRL^TDw+NYxKo3yɭ`߄م闓ߏs4ZkMNG!GliW<NY9J4\2dYIQ!_x&-ocB\Gޑ%N,rU ˆV FЙKb]k_r&zx{p]Z/k,SqF{b 81<6^v aCi㞚19JZǼ]fG߳* 9wW]S|~g\4P|˘?IZD wlou?z[ou[hޱَ=9 ^CZo N(zԇ̷kQr(#vWo㼪d2AԠ33FֻfŌ{]H_*[VK/7rLyG`=@(d8`Ŏ;͉#tͅdꬊPì5`)zςB2 YۘmGe$W΀/Rkm7ewQk1m #:rI?2 7eI^wmV%`w 1:4VKpX"΂sMsxq!΅>S_盶dG*Jo:HӬ0 VB!D99D|'|6Tl/VٖFγ▢Zm91l-e~3g7" ;tk>:o b4镌3dnj{wV)VǩgRvpa+H¤V =2[ {?a4FZHY^y%($びEuv*<")OLh<؀oj!* cw=<3%SYY2mvnW]\'/KHLPPVm$ 닩2̽4ʤ2yxuW0R][߬]v$U附t\t%ETJ#+I1[j`h~Km7DYꂂW/}m  e-%B@: #"|BtZ}u>+9s,<6oi38 ?[jwRV 9N#`/mdu4X'h(M>O~:Eq)2u=L_5*%fRͷe["ɱK1G56[ w8C?^9Gg [9BKkJ-Übx-:J)wEl9Țq9𮝙+^ߐߡWOadk&S >/fݓܲ93\W 0<~a)1E^v~kkj,5 Yܛ`/),>BSc)gOh$^5YHy8@^Φs:aQ#(@nʸsUwBn ,mt7s)0D(z]![&͵H1!z[Uf*>ӑc]MÐ BsFLT9JauBt7j+UeRkj~ Z `ֲ#72ʴ8+#QHyɿ8넝:a^426w}9Y%zLn%v0L XkW8B4}$JC3AkTќsh2嚥=W 5Wͥ$`>Npt@;V{ .HZD03/ %1HgjLKj&i:lһDG'7g7r9; ]r mjLnT>7w Yu>)C0;!r~hC 3}60)<B ŝL-|FO[mNs*dY{B־no"h SSWZGLF[\Iްm6՞Nnu 4N{za8 '<LEnD*`%,57茔aշt\W2">o`w9]fʒxg@`-{#b9I)U]Z]E l8N7j8r=c .#"O~6yf*E?k!rO9+eW+o.Pñv,0Q^Nep| ZeBFntd> h %6/to [̮go'e?]}Ǜz̏Y73OCrS̡nh?QL!~G6_2G&A\φ lfrXK`iT(W".I_`Kiat (W ݟ|q}WvUBww┓Q=3? &b1Z' (lD۝2Rg{L Xh>'pV20+LI`B(ӉUOݓ?DV_2JÎҩk 5c|=Tg*ׄ.+Z4\ϸ 5-Dࢉi$ I!JľnԭU р'#u7T͔R-rj_ [ 'dDhؤޜ ~xAc UJEE rf\d%md."-A!Sa&A#n0sB,ԃlctn^r65{.M¡{("QgB*NmFg|Es㵧dN Z+ F 1)DLa*XjuTix,6$/"~Eˋ+ ѶMI_5ւD<=xU!ulD5reVR̜ yn.ƹЭb*BK%p ScH,{ SG8 լ>F}Tѥ^ gk`Yc.#pZuOꡱ{FJl@5<+ nFǢf֖Luqh+l.وoa Ȑ"` U|f2ֺ--5B %X|D m[_RmiEka!7fr[6yW;>>ۇ]2 Gy.Z ;61Nw{mvV,+IVoknܟ-F }yݸZUI 6-^JcًFϿfS6W{E=o`P U Vs8/0ͱSˀEGiuNX-oJ&rӟQs5Q,$U[ ' \eLE z^;doe4} U[ҽauyD;M^Dqx;~lͿ;);HϾP1}M~VMX]0,\. Eof\-^oty_J`=cĠhPk:Y޹ݬhIpK7[Vf+u [UILpa_Tq= O7Ղue_}XԗΧ).vW/LB3nj9b{3N$dElXG(`I`)cG9Fmvo&+dJUu7n!Owm#x 6fۻ -w^<5dpi0AF {}#FFЍZ64zr'YOb&r@cD[x?|ٽ0g :16I&, " /"lw 7IY0IϪE q+÷,í*AAQuGfҸN7{5{~= grOeT 0KӎhbW/ij490 0 ' >wOHU#NfFzjCeʶSc@b?/ru?tf.w7rz!toӢ39b}:C O,բxdiG1pO40EXt;b fxG~%k`.wstƆz8dMKޫק5 nQW!16; 4{B+ʪ1 ޛ$*Z!q|Iߚ.bֹ*<թcaKwL:L).W7n^xz!ZOQ <5Di٭+D:loM"2\>`ŲHĸ1v1I}b<<iY[20,τ$qFpO: ֜xOFE2|GSIQ#{~]z~''v/Bd:0SF}/!׸}'H6 ecsec& +g l  2f8K/ΗP c8~?[iq}3av1B"//GR\Jq%-A6E`/ޥ}Cۚ+= MRPxI|9KiVR -dJ9`/D*B.HVU4/cܨ rgq7e 96;|< -!%5JKele by7mo~?DD3j|梪{;v_BY ϭKn]#E-AZ],a?&EWj[ak"< 7髄4ˇUUAi "K1z T[u0qۈWŕ4ƑElܘaHXy[/CwcoV<5%ǸfYV]W!!V]1[0wPzK x=jߋc6[7 \A?{,|#kW jJ` r|Ċ%dT]| hi|die:,,2PtJ7EWaz~1O ּSl{Ezh5ŠQ;b-w 6clJOrG0ɜ ( #&|q 8{10 p ~m뙺%j1v۬w6M4Ӣ>oA9)?*")Idf 6~(7_VuTMJԦM$hn}[~|ДH+YV PBh*=6h~26dYh4dTpVg)V4n"D#';S 8@3qWtI-9T/8$ =,j1A٠o3`裺h?9X0OfGD`;5BZca KdeEy81%[WwBc;Ql8ݰyo_%/9DԤ2 Y$L `xq4h؀#AOLP袏0`TJ& ƅ[^ZAQ pLlVf'?ǫ8^y5^:}/\v*ka(rW;@)#!sLrDTPb'Jdqti.i v|+5W= o. }_zNH0} h(B Ϫ)8Gߋqv}]r@9g*d4MBLj%8 miC䓽MeWѱޱjчh5uL [Yim1_lHĪ$Ag-<:ġ507ͼQfZ .piv3݌@8RuAA!hzf.)ߌpMgvO)V&n ˾YiWOCc˃h$3۪|Wօ l;| ߛttȺL2T B AǢ2T jW/_ Ռ2Xw(,vQs{RxjNvpyI ,Svyri)xc Ƅ<^طhG,"UTK6V5 1l4!m ;!K =}F+K"&=LH=Ï۰C'SB94=gI'xG m߳^ [nt=uNHkN'=q7{)@OOI>뛳$zjƼIĉOfe\ɑvK 9؁ /ޕOQ.=d/M N_t1e&Ю|}CƀⵆMfdwdra"O]}3͔֭\m? hA Ylw@^:S@'Uо9Qi[eq\"WzZLdaS*uVagɇ͜d6(hpup׿OE72TiƦ `lc&Q2rvC% @ZE3'K.h 畁m7TP#WGS1ϮcurfMɄI>O)+ͻ%J2HTk^|zҒfU9l{HT< ،ujٲ!fNqۑv]橇515YQx|7Ahm<͘U L]urBXnusx b' :]jrNs]ƥzC ${vx=H0%N5+&qƖEs@&#9 ec.*w@Nԧkfvbh u@ wC, Eꂖ7GFґLXWa͎' 1s}tzLL::mPzvּ-b YQev,?@3YB}QT~*% d;X5 jcϸ}Ǹh>n IMW\Y jU Pj։uyV]!I>k%VPJj]9'|H'XG_(A&."KU)'b3o4,@6/7``XRG ?lR5T1fdDUKػة9 w8ZX-VTf㡽(G [BحsVЊ/i t/iW 7.KhV/ѫ-6*& ?z}y,i]72dv┩xSe%%&HcE.}T(MVкS#8iw݁Xf{V8V}mRM-?Ǻ2$aqˉ`>zȤ? ߣݩPg6uy>]Ǣ pKՃ]C<%QeK1Pjt-Hx _HT0^jLzΈfcxԭZ:=Q2ᇋ aW'jI`ꍪؓ,b{BEx NfK60A,Y9εWxp 5{k}M1>" Y2RL9X2w:_>FgڢO|S5(z+J bF)J`|< Sa &E{si G*6^7Dz7na[t$ki޽ wPhZFbnXSWzf[C4:T  j/!">[fH'A;kَ*>!HD]@#Z_y]Eo(L?^5<2GA+EäY?TW d"OoZGػȒuC^GStKf&t$|$/1F:p"J箼>'9v2`OPy*?Sm1fCS>Фqޚ=2ien;xm/fp #2/D0`PyƵ9n6d!l/} 9b#p92܁ba'*Pr2i҆5pp-M̞bgMBEpu~Sb"~2e\g %L}PCȤ`Osvv$@йQ$16*9Dr}!54ŝLxlBVs_7^ms9> ͕] 0 )BL$?tFgw\ 5*:D̀`=(`6dLkm;Raݺ% j;(YvdzbW4pgU"LXքPdYEwmU`tQ@h܆`Oj'CfVOX=g )~RMmDexH7[:3;}ln(xHx%'DuB#.. ZHC$i{FDzש9,ǶAsLdX),YM-šl@U&2Ģ NޝÖ# a>ӓgza?Z5sOq&{`/Xa<,aI_6%;#bC1M$"O3Bʩ5w`0|.Qab:jFN%4p6ڶ g疄" bw~+ mQ t%~\/WCtL@5+" fX5%\J֩Az m'uLSӰֶkz1'яK֜PsAA{X( xFC:i:NYT Nr`JU݇rn5prLk H^L)2O pp"Օ` nv%9̪ᒆSZSZk ?F@gC/['R$c:RU"ɇ"5mAR<Z4;J mu^;H Me)k=vbϠ)GM&M&UH@cP#?APr|T=q@nL*8o5a$x,K j[ ܺF2PYRlB!BXp4Y&yWk#b)Q|Ar4l4 Mr5Qh3  yw Nd8w:݉A6%;.ܐHH.GnDEMfvSkFACNiB˕)_HH랐CߑY0FץD3 k =F+z]{c v`/\\s݈WN(tF!t M6&_ /n:‰۶-GP#CNK] ܶ5Tf@%G?B<w3HYu 5icwqa"{Q ˴T߁vX}lɉ%fma=W"x7rd(x(7>11.mH|֬>(>i'ϒA}9~E=TBഺ;7hM.#ISY=pd=kWdndӓ|0 3Pȼ> x)B?9pS`ڰ͚\ᛇ T'S%'{:>]#G2fIT:tX4̑Ckh{qf EJCiE"=/SI?W eNbOzp IQhxr7e/K6@N:&;E]ofinPK?% >8Q6KAVHC-M]]u@HBIjQ,('Iץ,%~'"~#U"*7wꪵم9R%J30ȍ@ekF01o!}2<3 ;%u+~!MYY|9G˜Bۊm/vNFOնXHnݣžђ:ÿ)<:ڐQ?Tw P M\ƫbgm,HQIbP,:sk]]%3(]Qx&) ?^rG¤#"&UyWTDQD.a6!U;5߀9i rBoz]0CDXР}PFЭ hNo!FA]L֮#VYMXT"* z7Z(A psT^5ɝ f?{52HԦhs= +dt7H3|݉5Rb1W7تBBǹ(wϕ ]Hꂖӓ Jauh3lm9D͸qۓT%Sd ڎR( г=H&V"٧pK;"=$>^Gd1>D9NԝA+MKN;\&܈ObP&H Fi.?5}':a U\[2"o6/:53ϜBh67Uѵx)N~Æ*Éy8J+VF;^–@`m_h._yHASxՌqfX%"*V3qe~"O"<|y_R;UU~V*P/gO+jTk070sYB=pyN}CoB |MS 7,xR d yU$Ƅ x˜uMq1rKp9hn$2E|t':\.*ƛejƎ殥G Hu %& Ef`oƦ2;9񗙀!ŚGOc@}K ">)?c`muϳkI,0İ]x݂÷7:&L{O*uUne+R 'znL}SZ\prWN?ݚ~?LfC᮷Efң‡jZ7rb 2Ag `'ba;\SL{Nq($A;O@q#XNJ/yD)l>/%+쥸2Nߩ< hGt|OC[R62h,w+ BrX o۵Ze,#AT2 ]o\VoQwg8kցԬ6u5URrmQ ,ٿv1^3G %ҍw2WZ~,{bg&)J2z{\rز9f˾lG葑Ԗx--1,A(KIָ6%uk%Shmp +C c{Ԓ1NGւ{,I/BԔ!б4rޣ==ZSC; 6u+l %K[!cUSKmEҵVRYR wg'8ev5 5,1 qֻ+ؿGq4[`80%F)\ݪMk@a:,8/W#F?Uv>UǞIO [nOij%PhY+"|`Ӌb"ѨkR"z*G*xZA޽x 8C\=&L)iV"@(]ɞlcbKZ07TH|E01cim5?S[")p9V;gFwy)Opl1,rbo騜A5ҹ%usI⾷Ei<`>VU"m&Ptߌ<):d(s-*4,c8Sw#DbCB,Tx.HBJi,-vʹ[(P蔶j^o_%V74 7AZ(% u Qwԗ[TUZbOyQ͋з \ИTk+Vnm/:㲢xMV4 0-"\a^fu <ޥoy~>I\A PFFD:cAcRՓJEe6WdKe02ٕ%n\E=M7Hqn#Ø%L{f/Kß%hԼ+م@yqs5 ۿAӟ|}HI* E4p4$%2j֜%ꁃ"U,U]I{${2ނuxv`獅$K`F΄N/xtCn\F 91ZLƃM1a`g T+@* !QUfc+;LzQk4XIwM΁pD7)3'Ek}:Q/1 i~M"3cib-tp{gX[ߒK;2m{Ԓ`/ZwJ?i$qr怭xG7bl U׬Gċw]g"]8}V<{ŴZ@gjo #1퉏C6ˇr',Lm+sB5+hzx12Ou´L{r?P^C}1pjhD$oq}68NsPTBai˖m/~lUpAY?^uq[G0ct`1p9 T>'Z=MWHvZer=w:tإTI l@p埣C T\<4(G`p8B;ODPI]8Z<$mǹ; _؄)x  |hFno IO*`:O?OIӟRsZZs?au@|S2ѨX{ x}.`NW$nC\}XR?@.͙G<,[koOvaVw[4BzKݹPPsP3ٿ%|JHT-џ(WOkzםi8Fvw:Mh7:G`r2cGh$ݥ_'jFOa=m) MqgwiiMJ RGiRLgK׳kyDڄ#xIP$qX#+<^8DЗ'JSD\?b3-rXims6+qSʲ_Iě@ey-` Փ ,- 5aď܈Eb6‰CႾ;Hh*jrG SbEPթd=[ p[fvL^%n!f4a'\nXۍ)GPeNk3x8BJTH~Ȏp/iqf'x sR|0Y;$*V/X(M[KhyWGcl!UU|LT*FcbM): Hyc=P'ki6Xs!ԝv2yc0e[0MK&\ߩ@8m` ~S GD4z4̬)a;= DGlZB+1=hCA)#1xpfC"^ 9] \Ɛ {B4bWčp ||`ҰW肒"ўv^x?U%fqFrľdf-8_6.L,=s6ݶ r1q+> JG$tDGЯ\0XKsSݟʥS'0w(Ϲ5Ԥ! ϳi+)Ӧ#yA[ =, ٰ2=Q3Qs5x$P(zgHH< ԠZ+,/9u2 fwDG9t L\2˛8gYq\g(Y y`0 ӁN'G'$8ښ48KJ8 J{/0k S.9{L)uτ|:*gZ] 5v>E ȧ;l24%OWF"rQ1ҚkƊv1߉E_9DžF43I~ɕWZ'}Lˮ ݚGIYM1[aet3Yc=U-nF$78Ӷ%#`p=OALvRlq鬇d# nkEY kH1.HʿGvL]p65c O^}ں5lVɦ]*~ Cd  p&!gq`S*&׽єo"p{ ubr Ռz ^Dص7}]oGJ\<}"X=3´l: @d\ tأu*Vy"m, dQq~zE &Vx`[ڊ[;>F%"?L 8- .P[KWfpg_D] gǽ_qMxI~9:H5wOk7G9|djO3Cic^Q !nH1xz["d0cpd8:u<+\ɰՐ'O(>~XwwZ @ڻ<$EWGLv-cS:(˟*f n>ԃ25Ϋ׮#.)᧲^C8FKgdaMI,zn2?琸ǧLzՐ,+6j'EMBR74한@37ηڶd//_'a)ҭSUιA{ޠ\D)fZ"ӵee\p+&оe)ЛfhNW8WN(#ڍܴ%Ž.- _)d*Q1A 㟔yݕO)U7uSiDYQ,RT Ѕ*vpa:d%{;[B(0G]bXX+b2Pϥ0MkB&\"H!)lF_̬&2qMe 9&:@ҿiݺT$$wB]GFgwwkV9츓e#c*rTΛ>>9Y= z,P:O\ ;c~Op,6إy0ܶ~o(d:{TZo [X6I0^BϮ{ۣD>bޫ"89puoZtd9x?]/#K6^ zzw$SG+R}?PsC P7$Z>*C~12()$#~/LU/h,-J3yxBk1Km;fY_aZ V>N4cyz z.PA|kTaVo]qG}%R@nI=gVSvLrDm.(چ"Y.,A'_ny1B|9 B;Dh8T6tcEr 96/tQ <İ+99`y.!S= ޹Z/FP{k y9jǹ/+zo^ %^en ʾmaH?rݖ?MߛWb0S<ιi_^|Qpait e\I٬5S ?[rpկ} )(ai[Ld\tF,v;ŖipnF ,pH~NcP/R-<)2-L/&ru4%^o'sk R"ɃK2Nn]^ht6<ׯ._}O330'VQ 5\]9>x~&8{ttM*k{ى J90`SEyRe*!l Kyt?ؓ_Ra8)9" OOfh \ۼ{|]z>@²oF7$,4|)K^rl>ӊWxoa h% pi/4./DZRп2uՆ>{R1V0~~Aɀ]_}x+ fy nqoϑ"GUN1pGr$)|Cԇ |I&6eD!S}$7M3}:]3VS~-IxO!3@]y7JUMy|kM0ĽK f!^~#Ph\g|mv@]N JL%甌v/MA* PՇ:K{&ߢ]qU\Ni  MY"FfE@ɴI%z`x7lZiK2 BV{#EE婼`aQy0:MpU|n2AQ]_IO.o> G5mׂ|(iYR[tp |V;WYOؖ}$.5(lB_%|{ ƂDc/0<T3O#6+.T juEU`9w@ۖ%}ǖcDQK"mBs.{S ۔~un UqW[ƜjY2 ` ΌL<}ytiwM}۷]?_^Pcr^=(e&'Z鶫(d5I{0rw3VX `c]F :Y? Ov^5^7mV&m*`1_Niz]v rc:08a~C7oUo=x -%WHk􅕪 px$LE1nS Ǥ6dnRk/HA,aP (膅ʢ:C'{+l?6jypϧ@[oy tLb^]ŰhAV5{6{AZKD.hO5Ơfhᗪ3N'"*f[<*e+/p58obWtI;}{wk:Xf} XѨo^k<7tRfh7"E~>5t#ڢQ%YPAA2o&&twG.R G4]x^2dqBMJBHev w)/!+P#y8u㼀CiS*c6fZ)bvf 1DH+q^UG ٤i4l@ӑCrƯ0<#tI;C.3cunrUy9BVp2lbH@â;V`z*h1ˊb`.gɹ!S k@niݠ*w6\*r? L_ !җ P{V$6aÞ Փq§\1WVn802ǖATA kC! a^HKtn2k"jYj>||N81[*;}@o(+:o0ZTl#tx/Cƿ}t2z8kAc"ȀG}auwBcݐ}M/(1 ҁE Zgm o7 giZ(X7rKuk.|iYѷD5"zLa8zb,'ްCQhX'-;W*3ɖ{k7+$eqN;)PpKxnVny-߃kH" #yZGDY s=^[ܔYy7H7* Qp `m,yQ=,G<zIZQP&%"/"?(a+Mz"zs{yAYjBbB˞:;[@O̺ bџY2}cSr&[!dԾ_&f} brl}S k z6X5 n@Xr+f(?gC&]y^!+7%\l\)hMu%_ W͢rT% UKfFhu{_kQE5'W\_s2pHWn,jx,'M8j [FƤ9-Kv O 6>L;3LHm?Je*n+YuW<2C1o+}ػ;E)_`iWs0nQ@{T\e>AGSdЧL 04cQgs5a0GA?Ъ7>Ȏj n6uhuǘJcyog&^њ%z!Yd^p¤ s]b^+fÝy(pNK=(iU!G(a4I}!'DZrp@򑦞V+{8IA4ړ9hR,o(Y9i*XJ}ŇTS`|_N´e tڝ)(b|h/=━~:<*?1RXΝWߒ$;Bg7?W6Ļ :㊲i;~b^n_\VBdauKO,PjRmJI}EPiC6WPaVҀʟɜ`ɸ獞VZg5Hr p?MqilU"<g E^c|KYz, ezKgZ8rMHO-U 'aydz[]6,N1SVwͫ9HDx@-odroe-w|$O(9\B4Q2d ^L?S`DNO K Y M/}j .ԣ-we$g;8@Gե t 83(P#@>h*tH-m8O\q' ypx׽]ۑbSҐIPȨ kE0N%tI}V2z6)jH1g q@eZ(tQkji]M.MKt`2EaxAHnmx.Uy~u ]f⓮2n61h;؝b /"Jj:mԥƅ ]6ɒ=MmMt2;*_MN-VEtc㔒Pd54b O$Ǒm*KUX&. 4v4'{?-1yRfVAq'JwCB2#u#8Z2FA:WcsǑ1| Nḫ4z(s \rQHGBDiD$DT܍점#K(y.mlO[ofiCMTn7d+k!S_zZ~*2:TkF^Y]\4ARIkk{PU<4PTѢb*2VNvMuD"շb*Q+zTVg*Z5A h\{T0"8Z۩0OTnh*8)F /WcE BG;ԧ\-ZDWMg#|߁P^WBf5buQ[G8VAnp,d]ٞDuy1O.b?eE?}j\LR1}9 zizj\%WZ U,W]VV-7%cdR }t]~WFwrWYJbu kT)κH"XӋ!H#洔JWe*Ky>aLOˌ4Sf <=Tqh i_R%NCt݆&DD 31㉰.?<e!9/gV*(ɩ }bS!hVJ$)ߎٖNJP%朾<7bűDsY-?V}H_irs˽lP|XI?'(/Ѩ $tx/jVWOxsFb8uϖz;M LVn9R\uLWCO}Q̜CsG䚷(y]ޖ^S$};9K\Phwqw{ $ۛՓSA_eŷ wV Fm܅RfMjۂ1.*;b TϬM<>j<O^oӹ9#S@\IQk  j!LrX!kKLjQZ(>*.%_kfў܃ZE=4*'{ezMν6ʝLUO`r*RtsrJeSx;wjQdNn2O 9U|_)Hx4N.m^_,L̪k?-X-fӼH.L?5}G o6WeĮ4^;C{c \[&7Ӽ\Fdkswx7v5,a鶫y~sO,A]SS(>HJC7I6Gpp:( bޗɂD-'u139i3§m,(wt5|r O5߉DEٿέ(M?K0sj_`zjko>2~C|w< [A-""PZPqtEp^RvV v˗.g -"e1bW%)ٶPb2HhtǠ٤YPCvqƙpAf@/x'."= WɕTNex`n&u?@TҕT*G}f]ʟ#j=-=ƶ1cX,A9zbByKwjS63׃sӋYIԽ,)h 尢:` KOzmF[ĶR|23`F |0n_vcNTP^ 0Ec4W UA^X¤r=Gl3BOF4i'N,Ӡ˝زC*@ y(}=ҚꦌTAgpq>5I0\&M"XJe ,3;"S85!tÄKʒzW@0cT!<ء9 T"~ՂP)u?rx:d"&F򥙿wˍ;%UO_z%D"Y@{MdA5~R_cXzPc/=xp.Zt &g 7sS;% p'f|~.P5 Zj wwGk8=jj+z wpV%]F,Ա(P7C=09‡@UE x8ص!KgewGšo谦'54T$ ls^tU;8ZFTmJpDosZ*~]ut}!J#vpJI= F84іt]ԌAKS4wO^j%@Ft k_E7jf{thvM 2K+4l+jk`aIƞz8,#Hk3Dcy\XFޕR\Gch)#=l>.z,OQ 5v}2=U1e΄g## Ą"5&˸MmtL lCד9)*cZxWH=#8<0u1^*iv`)cpKc_9py =)BRO2I6}7ڦ$ǃqgA3b|Ya%}U%2x6v$;_J"RFho e`4N\))+[V'^2PV)M+fJ|J'׈UZDnk[7@MJţΟӮ-cY:rk )h2!y2x:\a &2z?13ZEEN"a}M@[Ea\adH} (\&0eMREe~གྷ?ފuׯF -C;3Xalbd/\E̺Խ)k8+}^r.iϵFYi]nny FMK~B9&s0Jyjj/e7ⷡLSԘYd!^J2)g*(?qfW]fsP} M;dJ+y?+&Cռ٘?`)` y\r@&ID_V٦GXQN%HY1o!A-}6a!v2ʼn܃h8KkAeE52O1ۖiQԑ5ގΒz$jRb n߉IQ{u㔛b$ U\cyP %qqw*}r(`0;DJ;Rn?'oeT:O=-Ol4ğFp^k[Lk:IM0zxbM43yD%xL 7xD?V@ :u?MJHoU';!b0סdv[RcmHqj«(>ʄɅYyApB5ʎ낉WlٍK6nԓx31\Ǖ{F˜oqT=AoQ.yͲ/H0cR7WVπ{nr]j6V-rw#lF$h$&;7ĞO&$pzMS%X-@m Xr&7EpeJ?{뱁k<;+."j*]E-N/hagϢfr];O@LIC?h!ߜßH(~4o~IdX 5wB׋XUw+=h#RK7wnu7dAI*LC!'ޥcO"§sM=CkZԝV3'V;|S]?̞vf; j10kpCxC9y a89\'XhڢeSxi%НkK`ׁ3Of axP |]*0Bӱ*bH挻` R1B>w|p -6uo_E:B |DH_&Cj'wBFf]aIwb/=IuPfźmAvְ!{6dȶGPe0tI1oJ>jl[<@8dj;2\Z 69/C'C) R[t.}^FfYB".uEFؑ,쭐(9evL31kGA'd`ba5Zlsf^jh" `A,/\_he**iMHmyԧu"!4IFp̖6dgd [Ibqjp@0*Ҵ'ߴ._PJB`|{v!F;}A(T;qz{+}x'=s;:\ m'nng"0EMc۵(`!C2еN5g客ܜ28'5sɸT]=i\dd"(}$ogYãZkacTJ*0.$DgՄtk!x)> V̠1f Mvx}o%"^ @r}/~8b$'E+l䁵зxmuhTNni83ag9` K}+5.cJad˶M d>m FԄuRGLW_#R1'`ܽO<@:/g^" v}% 4-=jFA.t> ]nw QWI0 %J{鹤fl|P'ﵑtot.t[DYFm$ʍʶiߠEKUYȓA 6 h^| o{| ӑ3Wr=!M0X#I^ tVѲxB Wm]s\c{wJ}=YI(IЬov-w,[0qO ^|D?o$ ]dJ >Ž p\ 8XVKׁ9OkOkhgTAc^"ꧤè:5%Z^ZZ\1!7XBR]p+TfMv7) ͍g#(]87DV2_Z7?QPhb)1Zj9k}n̾kEY.,۽GW"2cdIP!- R=9=Wm(fcArCc)2s_#-otE%#2vFE4[WA3LnuwiQ\gaf d׿i; W4 #Ȅ']L}n)E m~x̞LP$1_11j6' mLL ?`r8; ϝb!WMuMR`!^)j2Gᓲ#ڊ-XX#LcBHpؑJDSTN[B {gPJ̙@$9\q;_1C* )rtf._Ez`tehb K}3q>`~0hP-z׻=0C !̖ (^=>tx-1I8&Uq3 7HOOE@J0j"=滥;R/׷h6hh)H5t_] -ҝ"?(Vru#Qg!*X.+n@a 497s@l6DƧmqvM2? 'Ny>} *? Yl1; 1'c \Bhk6[6[Q~J>Jʗ|3vJz&嶚zj|mz } -poqy"|dvgSzv:sp <Ԕ3wZ?{u(g1jstHv4,KL4.dв0H#+Gzf?4YXArAFۅ򚋞dȌfІ$o6uֆUHdЋ{bO_2B#A({Wo18d{<QE"D>ml hCFE< y>$s Dƻ9=h]EQH0ԝ{e㜩J&|O@#86?_3 }rkRW l9`%ۦ(ZL% S,~4h}GiцDoq!wEў]>ۃL {F$,.?]P%h }!!A4$5j]RCPa'ЌW szDr) =9¾Ev{.κ)džJ7 'ֻ K-9~{Bn+;I{^U\2q} ⹄[1Ʌmg<"桳/JPɲguz<6%[m[Ha*O\j&ƘzZVxʭ-6zPmĚzu !Mh߫uמ<$]] qɇDQeq j0~Cd78wއhX$AF[U&㏌y 7tSd1y^xDbjxjãC1%Rz[@C@IOLKa"37+2V%չb{1atZIxϐTRQkdUf'濿y˭dL=^fOW7D rdUgQ3|UNc`Q4eK}6}/p0< Q}W1>fbݲac "|׬Sús4m`UqDW{yaA4& &7*zY|lFX1`*ʧū+WMրFxmơe R|7e%'} ڃ RSK^%1!9aj0;F, R[+A>F7U{#bˌNedC*ϥ5?= T'4=KX|$ ep+*=T#ܨq Yw  B©޷(Z8BC9   Xa1T%Ck_ ~( ^ALW}9TPpТ41g"`E=Sc]D80"l/K\RܔDTv~:REDoHҠ\HQ~7Ur\B.$רY$v'^(/4=ӆH1@B} aa+ǗN\WtO^EAfxKZfj= :cC WD9O[0:?0!%USA[9b Às*7e0;nN}39aYe};ZC(?ep?q1wq٫ C)f_FAqSQ)? `aO楑bL@$39٥;TNC/ߏn}qge]xTy2`i;ߡ z ^ Gi#{Y}+Ld[ <}Xj)%h#oGO$=(Knl?ji85*S((ДCG ;> mibN |k'o,dTAe6AP k%x!?'SM*SG>~VU_a#W ?OɉuHqWgή'?{en^q -tsFLiz7W9M#m[^ oӰC,Q0 2<3=CcZ(14YӽnP[P U?)0_~qLA)?wߜg:1yePtJpo *d3{P^ƣW8~ᅝs}!/N!vi Ih'tGdz˵3`蛤eLakH:څv4(?s\X^z,vSn90:^̦N:tIQ:Gui H*/~ u.dtd2:ڒ!Z]v.HC99s\afJgɨ :J% Vh<4FۥƍˎXy|&;x2Gю7?~ڠAC?'pC96{HUƑg4h4N"lt,Po&bN罛xR |Q0gS}t%|~#h|09R%}|rk!P͓qlf;`d/kP\J˿PTvT #IRel(z;+/)AIR#?j`ӽ5at֞$OCT) >6;3u)&/M@!Wh9zj*cŚ:qaJ{ARP_9pEu9 R hxG)i{0Cj]&NCxz ;~=JWAj1^*_o3Ӧ:sWk8ɋ8ޔ%$A{[]"晼y) n%.9w0q5E۩\~ q:a |jUpGU!fL HRҺ7"eA SH1h-7@z\|/z>veN_3ƴ@y&m rei9 jñ7 ̋Є5FW6A0HWƢH sieY:3n*>ߎ%}Y#y0ݒBR!kZݔO)jRX27wPMȐio&]r#qbhdItXQj@_X|+W]d-)9ާEe ɭݷ[W{`XpEw^ٔmrn|#p 'L_e5Hk[|Qc*, '8 J4`6C/F]h VW"+d{ (=0"*@ԥ9Y/+ٖh/=f̸}cTNFrIG:LP%|u[Ǘ1NcJaa7}Qka qz8ns_U$K`JƇ2@*Uɣώ48&gS9=ϛjc&RTW{`KZNss~'$U3ew/k=>[vGtUGWhǑ16 6\CҎV@앒d)&ײF PD ]5=G,#)c*/;/Uf2~93~rN> 7;~Y (fY&'"R؃izaRov^gz]WJ٨daa9GնI:xEQ?*.ѵNϨ[fPVɚ=Xh £3Agl)N0Ne7tl_аCA2DLL#A`!:y*Edec82O/JAr$'L r9xH9~aبP1pz}BHZm*N+cb2=0=e@"{FvLz76"SIfmS sa\QS3 NeQ8%_ykuSlR$B>8Shtt7EՂKj}cvY"֠^G'X,ے׀=投<ӼeCչNXvR\.1 d6Q|B+B>d3ś*Ύw *63wW&1jg>GP[oƤUʨ\܌Ac).7]$r_l MDRwU,uNjp]ӂp9*3h!/aWv1aSؕGܞoa`'PTl4 ,Y [x\1GCkY?YNeXK@%6ɈI>Nؗ>7ӳdEFh!ΛPzd0;c'l $ jt80Ef:hbQ(愁((C*P|B(z&]fnū5[ ŷM=eyHP;qc!l;kcM<1+t^ ?&3¿jCo}YIcVfJ` E=S)db" VvBBH?GzO_(?a1wvyԭgȕ"I!G4%ODB2 7,V@ -Ku|GB4I|Z 0vbσ?]6}n>S#򲩕 #:NSR1>jH@e@c]EVɞN'w66:8@ꮃtЏ Fj*XcّjB^Um>B-x?)ewq1\u(/Nmg*.1"E֠ +WTޫ*|YlM0%Cv'b6}=.B(ŗ-ם% \!Y|.r|l!ř D4bWI",c69wS eX0RKW 0Qvqj,Y1O;x|. k0bhQq Xa jm?7G) Ci{޴\EvP'\] fh2tg(F^VtɿM΀Q4_'TbZNhsK #$eQib}ab ޸,Q^|x5ӡC Pdk&ámOJ2R- h~ڡa̓V7k"X [Np݇l몂u\0XFҨA KL7k#lCUCz4EO{[$'A5qFBq* .%3XH-LYI3|Oĉo{Bquؾ'1Dq1%aP:ɃE"f_M= 1ö@_7=`itX| %~HL>vE0ErC-FP#` ʔG2/iq^vP|(25Y3On|s9%+oL\|bu 4?Ȯ%N"wM>| dNgctϯ^A5e2@sL)"cmKU!4l{LܟzI57미3] e2ءLhHh;M0d V4鬒k"5Ȱ5* wa΍HzDSo=g6e؎htjՇծpp8=" ˼b@RrO3~Ѕ&hT3Oϐ$9!,:7@=D$2gQ S9jCPXdžJ)s ZBYpuXeed7@  Wl~nAO9D0rdEv+kh0xu_ 3-{ $Swߴ% yćIZ7ul?{.Qb!AO0/OFV6LXc1L Sj3 ξ3:|<>Ė"'v-k-r)f"G$|tKcW`~Ah#Ӹ;o+R6\v Lψdafm4 +OhG 8@7J~,T@f&\d|`eH_(/; A alŨ?RjȽ^Fm  ܎U0. ú5[R;AmQ䫞Οlpeb1$%| (3,2Mzk0ch1DMzaL.Q& >&![4A 7TDF}Pc|mOy%3˅a)`P24D]1(4NGI"/\gC}CQ__]}Z?`1Ӝ6, tlU7/%HO.r# mTZBpcoFU!Ss.cTjp!yy- ȭcVP욃C19XygX]hO)[r՛DAzp58K¾+\P<%PVD&m;ѪFAl>kax5iNUnN^ !R]~uK3 mF>e@Oe0 l60"b;R3B"X~duC! NyA}8~G%*M9]z)cŒ[CW||wo%* 5yNl3J_cRi *Ѡ^{7klȮ"'l r  ޯwzcM|eC͓d49Ԍ?}u;bB4>m򩄰 \qkβ@ze !06v6uZlR6 g/pVo.`2^84Mzy ̴/.hg].j%_ٜIJa]ğð$\T=b#Vec*8 R*G**Gؗ@z>a$M4L^[dlB4XRN++ v^fЖ[rvI4my$A3sf-:Eqp9QɾG@ny_@*N<7B٭š'f/2Z+Ԝ UY?nDkr"z9 gX\MmKvJqv3<-lzGzk`Ai#{Hr0*[37Bb#Gb^{sh)P3q6^K;Z"ТZ5_F5/i+= 7)4VC63'i}ž>R(X< x@:ً"A0a?p'\> 5vISt 5E\|T絢Xׯ̉JTJ=:xclNd8V88Σs6L,f3 p9>.B)Y?aj}|)% h'Tf g9 #tk!ތH6$b+=Ű0maMON0iD|n޻mNeWW7C_0`PJg4T>!v0jX=O{`yVxP 2Xl1M{لF?~О3u>~[?2sw)74t-#|r L} .qp} ~_&KyVgSj +me]B^(K{cGjlEx1@Z`c5jYcGm9 |jGH"paw]uM$҇1V~ޟy(/f=sތ*\ɟmH_ @60[Q;yn։nIvqvߨ*f-~ [0XO_}; cKB;'s@4Yi4Z*SxL\(Ff5J!`3z_[ G~a}{&mr N|9( gnMC"Īn_GYDȡ[o Hu c*+[ba~i6U=sL$ϬėgaEY/J%\L6U1,/CxeߪC'Pf} <X~FCOUUddG$W&/#CTcC.d&6sE!l,/,gPTp,0_O.t|dLK*aoBQQGet,rX#scY2[mdnSy;mL!dM|vq@l=K⼯GΒyLz欄OWP $-xCXaA-,X /s#qj PՒ)C/q@/J~974|k)+fփ gQ/9.ND8Zڤ}rǜC :ފV`#Gp T\\T_wĢYUNgcd\tAjlٞtw|XxPWYCY|L%LBvJpm˒Qg̥C Q qӈ9aS "n\)aZ2T6i hW$ Uj)>E #ԹǺV`NQid?xM J>c"89NIb]9EgM|Jr^aTgeuzETTxOk~Wv2f5 {X3km%MǖZ2|)D 3.X qgыxŠXZ3XQw /*e|!'L] DÁN0@'x{YgɟWh I;N0JPU"[>6K/k6 c ey͗T6LgȂ&g{MS 1*R&¨-@Mj}9L.42=~,gVZ~Ќ}/Sn1"BEЗO?q,T/$$1=R Y@қn %ܐ-I"֩;+Hctc٧-mTаdnL/4z4@Ų3SlWcES߼kJ!4/:q6`ZBC-?( $N#5}Sʋ H96{OMh}Vly:Ku:yp?mUSSKaHCmt"&h 9Mz)TRGz!s1s1Q¢c {y Y =*GE (5gY8\pESm S :;;9yII(/[3ٙ9ʏ=Ę/ z!IBq$8q:yFb_q1G$6(\GM=P9:OϪL<7{: NA6ͧkM.QY6ikpJzwe19F<_%8=ևd AOBfT.p@W›Q)c WQQh{Zs#qKE),}쳒 F/$Eo%#ׇٸ%mEVpFϬL}kt= Em'/%ŗy(aJ aO ~[}YL+4eLզO3>C朚rujyk^ţgv{l޷:o衝S4Wҡ߭t0ʓ!.2Rɤ9o|7L/#gcMuE.3jD#^|^2me̘oKG’ȽD'$ =uaPT;nkvTnF0 9;__{бχ!8vIM_*b @/wy*NE;m7_mQ,K髓ޛ` ;zH>|EEw7IOE?*i% B9/mR(wZ eQ(~NwlՎSݫf=壀|bq6 W xZt~\0^8(QЬWT0 ]HЊV X 0cnH8)8N;,QDg+ٽKM^Wpcg U,@:c J1_oqS)ޠ.dȢ#V4ŗ G6tR=l&KðnQW1jsjye_{[Ig/f,Y{K|q҉b/in暱*OLᾌ[k];<@d.ۅr47Th>gR.{'偽F鷕yNGIߌA5^vHy0D;}@eW)t\ 4 ޵#b{SiJI؆aIb+ qzh4 qȱ2,8Nf t !/ǹ7U_Z YW-UH#;;.1,bغ8˜@m-/){(~PeCHyґ77y:; :Tt x쵳|ْvma"beW&}ou+޺ұC^>Db\)g @=o1NG!U<ρ|t=,1n{ ja~j^);lfL+V;o|>*<.Ds{FOW#T璅'p`@r|mXl1kd-0!dq68B j;UaZ)GEPpHLNZ.WyIW,l]i,F!Go[yRRC40Q@b ˲{Z4+;@O%LOIe#Dr<~ }l9omga_8x}tZO %Y' yfOf5BKro]]%U#޵jB}5rYCR`v ꫅;"+*n5J/A5z7&E"T_+65Dek Nŕ5 W2DY/Ch"I T=Wλńk0Xa_#Zɐb<+35ϓY@`ǿ_yTWY;ɮ9Ѡ]V!B um~x9E .uiW&ƌB;"՗6dcۅ|zR~x*"}AL70)q=*g/)c3ǮKЇ%6J'i2a&E5<7B It悩CeO<ܓ-@1JʳH}uF)ԯCo%VY/| 'PgK7c]ܬ;P*|\?YKSA_" FSKcee55@{W =Gwרu9ul4RoDzۿ@+kt`i2 AүxY!?/8PvOH[5ey('LhGHI ~G{I(?2<S'.Rݽe s4X-eD ȖbdČPi) LAxPds0s>if㕥eH`k+W-Q0 Jz$4=!u+o Lωv zj>dICI/B* $ $)[<.ܥ Ǚ`LOeӣ/N0a爎=8A `ԓm(%:;#`u`)@q4[-'n|b;=(<^#2اACFXR`wXwQ_OFaT~0EkmK#J!5<9Q@ 6;/77E  Ϭw4FH/pI 7M--;`і=AL0],y|W7 1}a!*vw #,%7*hb+D8hdPZjPBf9Qs`Ŀi7YK|r~*5|E]΍͋W0Ll\>663I^ӛeVy(dp"!K h]|nQ[Z uGx%'ꤊPwƷ+n++,8u%jW7`ENǭ|<_+,s/Z-if>yJ{>#:3jzifm.oOmݬ8VCњ7\qgF.cn I+3{c a;6=$L+JZG}uRT1/c,i5| ‡'R>L4{+6khFiuBNx[ #𛹛oFĺHAVF8hH0-IDN"x_W7wo͆S%9%YR;8T_Vߘ(\ѽ~fqX&᥮]%8 ^X ys:cIdՒSk,2d kJLh'"#KH"!QI `ߵ@so$~2עom8@{Hiܲ|L\-?2E\^.Q<>0}œ$Nl*4i41'ɼ*,7NH)LcIs@$M^񟖆\\(3xz+u,t&=2'}i*pDѡ6e*XMâ./X0 8Qeu`APjUkKR#_ZqleYJ#99 XϸߌYㆦQ6W.M<#r:*4;kxxSR 7Ih>P(F_ONH#8)ֱ E ҹ\%\`LfQ P)\*9WsJr/0 Β$F/[Zۊ3nƫL;4$,W3e^X <{lAS}bON F̋}(ᝏLrLsNC s+/3f+7 rJө=KVQ$4Xv'+!>lfwyk]ao/<u 4N6)Ys+JcS:["~S1363S> ` 4(Pӹ#ɰ-1y^ߙQ|@`@!o?k+ocN_+{M^<(PG 7gEQ_v9RI85Kěנ]ak6p>3h?ޛ+ y.ukҤ"eLKqX@{IP՞@`kVeIZߦgLTwp\!{WJm?l8<G[en+Gb 2m j[2+'u6{_R*b1O'i&uZ!G$G1Vb`2 \Gģ8PFAjW{* cU?=;{芷!o[p! -v޹%Nf|3p'IlaBinZجBz|">9$koP&n|wr69?%좳kSKk%UA.LC%b#+ȘJNalک9ijI+|ʩWG\ s:S$rѤ5 Ʊ?ǟ~j" +T| (P QB/@ݒЖ1ar1^)֟$"7}+"TUusESwRnf.6b5I-ΰo,Iœ,صjNr8^nD+5'QqG+=x,QbL:GC/568q5-̃WbCڂy \r-[=D`myZ}ҕtilw(~6o1bnzesk֠J6~ c1Ҧߪ%}Ŋ?:*|~ \!^ϬM=#؈V@y:\)L;@eų֦bB`}L}~ Uc'vkE">EġД#$+huaBÜFB{j(f$k6rMZSO%bH04yX &؇9N;{:0KмʎLg-zh1zиirZOa׹jI ^fH~$?שr#LĵN'⑅ Ś<3 = uFjGPe`DŌƫQ(R~O 2uvʈ},`߭4Bk%sȼ{GFMd_.x:b?:2 # NBz2AaJ=›ǥ,b08A?j䌗BmC2q ,S d!Ǫm slс2}KYd'I@ęrGPIHO}u)Ȗ$vFYgT -/ #+дXZ8vҶECYjP(/#fWp T۸~}-ð)30Ǻ؅_QsZ< TP{Ejei N//5⚍} L4縟j? eaG?Xkt܂f*<(e2̗=6xtW|檗` Ҝg@h&L9eL1{kZ]$"X4SpcxGEGa !ąQnY7TrHd3Tx@Rt_pGo"H}3ۘlkcZŐU`0ƂYo(kVMBQ3bz#3d>&Ki[)tf-#X]­(_ZzY߈6X8ͪzwnZMCTzLpv[աp_TƧ%0j+IهUK.:eR P2*;[fg2p`¹4g }(ܞ̵)7Q>MI1:ѕHvdJ84+`+[2]b:#_\=~whrq%q#޾ѐc8uٽj;0iEЩ6I e?ٺ:MRWpD&PHt?ޓXq.;ay;}U;e gVG!w 6guq 㠷O gJ/'5<圐7CR)1DE> @6i=?uzM,@Ժ^j DZD ^"0L/WŸag'|'-ֽIs dKűuQ#& T=MM=^'ٜ7(7"3H!})d/kG9td+ #Ӝo wp>zi[# 8=YZDoq'֪`TESXW4kW35NΎUs6:~3ƷP$c 3@*.i^w!8(`P@OA"6#jM |*!w(ƁlTaEHd'W(Lv=&]8 m9#=*u2QR 4=u22:xc$}A OFzs*ne9"9Hto"E&92t<MSr5fl#Dp>hs 3O䓉F_fiE^qqQֺ"Z} +¶@r|%[PCw$ᛐ~Um_6" Z//ڿ#&_YKsΏoLeh4ǞLm嵕'0yLT)0fӺM"o\U!7]?u wȔQ HkV>ʠ[xNPչ z u` t8 +\Yq崢3-XMen*I$gp tt4O6@AiYM5oGlE͏~$*;#3)KBѵ2KTL*K\(*! ;,9 > bin zs)7,{SGd̷_1S!O%ˊm1gYc$PM;6ż j!&<  FHZM"llaqW;뇜bX#[?bj麤hjg;Gg`c1ȗlQ=ZӜ}mJiehih̨ z ` yWgd-Э*|knQrvR%r3lk*f:tYL==]%jX̲sy瀼9NsrNra }89|= Rb77+0;`LI|. !W:)9པ!mj! nκNw}ѱtGӬf #_mnvODӉRvF}QYgߞrKUpyR2C?n;b_?YUNF+I;CS_>̏;5"D̳_? dF^bpBŠF`ϊ?hV$\]=Mj`*aX >H9,g3}zSwZq<'G(;l-E7 ߥRKpkNmmh'.\>閆1S5\i9^Fɼr;BoUHx (s%X96raI>ܝZVGAb<%5!M˔|hͤvVt[͏WfAFL8d`9۞V ΍02dbe%/Y7emQm@si4"D#}E68-Otd[tW c9ذM1נ hu5-2qVj'gr$?rvEe|]vRt'ҸI2ޞyN=M}sjToDGT%jvXjȆd+GBlnFuN>0Lic*7Go<ܜA;}g`qJJ@ȑ 8:H4JtXV[^y =kXgЭ erjWLw$w_>SM{55E h>#(3cDf]V~W9$շ K$3SW[-ր" du]h%~s⽼:Ǿsv :7plVj$Og&U=G򨹪A ƥ&π`Nkʁeg⮂A]a&SĸA\] t@l1:H>eH:y,\'bJ:L.VP'lҾPf2Q͸MV&aph!^U]dCD6TnOEU* wB0` ;prx 0MMo i:K&ǖ!%aKE6U]4%)@ViTG b`ͤrN2y ]hL䨒c JO^S=Rp1FAeʐ<+SGmquuz m7B,pnXJBƽt.rgJl-2{p|(> Uwpka׌o~E cp.p>;2LL^a,Jߎĉ=%:K¬l_ӽi-xL2OBWGa6[אi׻.wPUvy_I67dhԉ{ۂulOӅ܂vYGTI| Ģs}> ZP"P ,i(1;$.~f_`rpAVVXHnSU@?զ.] 39Ht}?r ( >yQIl4؁QI0Ɛx%FȮ ( K9 J|̙Z.kP# =X rX\msI7(dJx$\"Tq"IwYӬh5q :9x@:uJkes%=i^%C0fIFI8U+) {`twv=`VMIᣄԩOږtc=sZN>-d4c_G?zvԢfn_!6\BcR# 8u?KZH._1ьh:LYPG1G>{BdE.]{{JXYBfˍ>;G_u2p/*^HEnֱ:LlBsE8XR{cOp"'Xݓ>P>DpxECc+}p/{클7 >!E,>e^J[R{<56ek8, 2юT[O?9(yɱ>kNɟLvqeV'CO|[rM(4E0SW3k"'ڽ]A`'a+]Q B?p0FؤoܼLR-$zD~~&*O${{ϣmܿ}V"4 NY**9?ӫdʹcAgx"0'/ ǹAg'C{ܠ.҈i>˘ɦO%M z`JW3Q߁}P=k(i}r5ߔ3/qEc(tŐ3H=u!סQ)=ૡSGb\pd?r%Qw'nQV͢\K\ư=Kz@KrR{y֤mlt߄3]q2~k _'da7 *j_l"1E9Ln_9Y3a$ t&h ^.ӝ,yn$~~W,0z']2 Qp\V}o.zb*0 *;(DF(2J\:ip-ه %nد|qQ,A% oӞƫYcE"]$C1ˏl\7[x5F]&@mtog+@l\^m1%SГ]R*<='tH2"6 e)d9&>)})8P>!ӳ!Oօ˺J:D:Nd͝C,>~E`b Cl.ӓ>]idUT1ZI[Pto}aF+ >(T/ hcjC7􏫌\%{\U=b<Q;Rףx2i6]Q( p[gz(੊C/6U9JٔnuRq!'&t9T( {\k߸ZE~Um*)&Χzk-N,iیJ[|wqCo1ܹ/=IVu!e͹e_ٌnⰡQauʰ`P#D >>z@vn/ KCe, u|Cvp-)㫴 0͔5(<\JrB  ڥ?bhE7xo&-yc;K`/€TCuny!1#Cfa}/j%p1P#EsHgΉ)><=dG#۱N4*m-my`"{+L2eYE P67K{&,K{K*IzDgf79ڏ`-%}:8g`,{ TIv ;9=񻆅:z #o@+b=ifZ٫)= 7l/ɟ51ۏF͡RlT{Kl"NVL S|/(htVuMxɧUgD9(u!rjNd3:,38a6wtR >Na. >x']e50`$r!u L3a41lZ~bo{? #X1G[ 嬲"IJG7oN@'D$xq- 8fM1"Dp0_)+ 2S^Lt]s1;?u$wl4HgFa]lkM؊@}L5#WIU0h("leLK+y-q.dl@1ŵaX(94S0ta\ !n~jYv-' Lyr#eU}Ho_=JέoA!6 C!x0k 򹒊ب :zn׈3T/ʣn]&"rjf!I5 ;؞"M}cjPpmeiqg~"P!y?p5eO.~;lܿn<$ hL"y0k>VEJKh$loSݮG'@_7h08Y"mZsZ7hNHxc7*U<9/ٳHtW{ >eb7#L]è4P[Bhk ^ 3xBʩm k\z80x 9X l.dp=CHB`vm}#_&&c ._{C9{Byrvx6ˀR$-6cjIwzdUN3ii9+>ϸ'Տ|VwkR _/R쏠bYkMWm{}ú^T2~/Սwq (WQo){5)o41>a^i@J0/Ґ5jASۻ-g)Y(W(pRH)&4B#Yxy)?q_BVGnQ}j&Oa":i׹?ʮ_|u}Oӓ2N?!zD^A:杩QDnh uժD[Q$6E\,h2{koЂt|Ԝmէo(mFO$9Lx fLZӝi>qWD핎gPѣ= janVt&}s33@}n~9~?/ wXbŠ}+Bś36Ӣ@Iɮ '`Bٱl^e(j  ﲹU a1*1̹sPT4)@r=`3MޅmbX{65lO9L%`I瓚n֨CͶIMyfi~<"hY7h'#7mJtT5hxf]I92*JL/o|"D62J[uw3 <ZVoEĶS,T\v<_#֩Zz&*Gw)Rg7Rd|OtQ3⡥$cnWyjY!l?ׂ56YGp<8S{^ 4&Vh~: c6 N7bTlZM<#*) %˫d ǦyE+7u{22 hjD~Z57}6:ع߬/N|a N;H~jLWNJ7fN@MMt@ҁq 4r9'0ujzS9VB+KJ@zUךϳ"b2X / rK_ى6p(8y"Buل96́50BC@SR3X WtDAz ns>rnWH5,NrRa\?aJaNԔn]J!AxuP(6=jiM ~ ~wpz=|"k{NTd{PW ^JEΞ"?0vL9""z{Fde %I-L7.uo5mw\ߏH 8T%dE9&e5{ ucN8nH9>uq$:vZLX V3OWMSDPj 4@y\.@ (n)֙ڋ>?U=,CA 7<[N6KR#~ x'\_;Vн{J#Ⱥu)t}[m~t\,kbz[\ڵvVfhlϢ7#ݥW dBo' |/] Dcsϲ_ߊ s9!p "4b7q,{k&y2eQsC[J^HbvՏtĮrW':aV`"nUf*|W.%h)vy:jPOlF$賦+)$B5#{t[Tjƶgm\>nI@ ߊOk] G#P5; ӧ+ͦ g=1b赛d^42؂0 jYtU`cNvp&1Gx]u T}g붶 Kbݏmn_{zq pAI/&0?dD9x Zkġe92w%N E$ݘ^%_+w>/7t #vZ鸨@]'TnD%$N *ȋ YZ