sssd-ipa-1.16.4-37.el7_8.3> H HtxHF^4 ?*}}LCre@xyYFغXWV7^!©\%I(b0ae65f6d2e46e282a507a5285ea7b117bceffb2\MP~c ,prF^4 ?*}}DcBd f:Z}Cj_`էJoO޺N* >>?d   : 7=D   , s |PRR R(8292:2=GH I 4X @Y L\ t] ^ b d Fe Kf Nl Pt hu v w xyYCsssd-ipa1.16.437.el7_8.3The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.^sl7.fnal.gov oScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd "0K &/A큤A^^^\/^^^641facddd6095eedadfc67c29e9677db733f2f55ab931a1fdff416f77841e0e05f7be5cd56e89f3df4def56eae1e6ff6bea9b128b75619b556981fb6fa051d268ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038f90be2f2558842a9bae34f91b6327d656056d71cd8d2e5732e6a104c72fc9c0df1b6b343effa70222bdaf676d9e999e2d9f8e9f281ec37f2030a76d5dd5ee3brootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.4-37.el7_8.3.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.4-37.el7_8.33.0.4-14.6.0-14.0-11.16.4-37.el7_8.31.16.4-37.el7_8.31.16.4-37.el7_8.35.2-1sssd1.10.0-8.beta24.11.3^}^x^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.4-37.3Alexey Tikhonov - 1.16.4-37.2Michal Židek - 1.16.4-37.1Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1817380 - Removing an IPA sub-group should NOT remove the members from indirect parent that also belong to other subgroups [rhel-7.8.z]- Resolves: rhbz#1816031 - SSSD is crashing: dbus_watch_handle() is invoked with corrupted 'watch' value [rhel-7.8.z]- Resolves: rhbz#1801208 - id command taking 1+ minute for returning user information [rhel-7.8.z] - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.4-37.el7_8.31.16.4-37.el7_8.3libsss_ipa.soselinux_childsssd-ipa-1.16.4COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.4//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=bd43b5f2f55ab4ce7c1a7a639e16f18616a1dc0c, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=5d9665f21d47931f40b8c95c7917990f0e9be725, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRHRRER/R RRRRRR>R!RR#R$R2R@RRR?RRRR RBR1R,RR R3RFR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RGRRRR=RARDRH},< n-gIQ4$|d۩@|J EE> O2b1}̗u6]]E we瓈}.wV]Pq34do0'VO>4bf.D Yӝd[%K V,0.\ڝB&:_o^fa'(OBأfN=VR7vo%+Rqe$_ iq;N$]ĒsuΥWzw hh ($ϨuJ3%$;v _Q{3_g^u4zKP|DDۯtυlQAHO`zz!\錧`fXg:3\ 7PFm\APÛhŌM lXn7l88Źőg_S뿜xm{{ ؃6@BAu;^}&3(s vv w;&F_@g>t9 #^D_UX8.cmT7wC@H\%֒٫~~AӜ(ض$V#@R](E< bQR jbdt~̝餁gV[&B@FdQ)ŭ!_YD\؝ս)5dx;0nN PәM|77ҺShc諸37bV{O݆EE "L[(Y$mu^:qjt1{1ye* :NJ$/t94ϵZ-1to1\˹ع\[JOŪ$ͺ$L~i0@!zb@S) Vٰ eo:rq(Ae%M.ޗ7i=sVd#+:*&Dҫ5ZC\DӉIez,7+{`Rc(ܢsa-B%ۄ:ʄјO*kS 9@gȢ[yt*mj(_>m5cB>^a%-6XHzQ_DDdoNv㱮a-9NxSS@EҮ6RmC])څ?:,36{QɮD>wZz@ŻbdKpk4'ĝda&rz: zj*5ؓ7 ,\DoRY2<^蓒|7%YN<G[ U(n}!,0#[hfV?c-ɴo=Fd;RҜ>kƃ. pI;QPށSRB`86DQ630"/^ +_e2Db5IWP Bb32"إ,6(nZ)c_r*ΎP8m8z]%*o&$Khhq`v,`c;BdvK9|ua/ڨO皺|Wo]I@g6;1`:RpBYAv+4CFʝ]Vj"b=\N 'vu*/ lS}iS+DO%1 sh4"QըxcX>-9_Sp(  "hz:3O:(H# PVyV܀sPgP// _R]Yl^ \QRNˑ3&Hk @;Q 1]MRcVPuQL,WPgtEў HX%U4#h} +r~"8ƤХXS`ͷ PCi[hm.bTɮt4.Ӗٳ,ռ?K80 @",jS;GNW{xrN%2s~mĠP3WrG}`5pWy-t@FlL Xhu &jĂuZS6\qCutpݖe%]yznCn`j9*r9[Z<$)QBlڽ15[VR2^'7m/sM )(m<BKhiMqft,8_#^P k#3vJ5] 8WZ!{E.\o`Qu@PT%tRYe̮DV)rEzIGbUՂI$db?xY a$9Ɯ&d{2gk:kB&q6_ZjkIlB"ם NYCnG 43Tcy!/)1'g_u_C`8$,o6%|6SK:V.- fK3Y dmF#6ez&1du;Bpq64C~V\C "O C* `t?tǥ\U+ZcpYnp~}3|ϒ xsʢ'YYVF;ٶ`ˏ_BG[55Nar PB^/)vb"ֹtԖ@%J5tmc;~ 7 9ZOgBz~ v N隔gG@ 4;5 OIO.t5n]Q_up*j8oE eX[De),_QiVtK_:mOߒ\R2ZZM:)&w+\NwA0|`/^#ߠܥ{ChjI7*2pTؐ`R X_^A)Hw?ge鵗b4',B(?т)+mnײ԰i=œH 8Pb}ɎdAM= kRPMwj%W7]rR}${mvXq`m3sތ撞64z|i A&&IYիc6FO!%Ԇ#-JZQQ47(6mQ^]UT4n9E8U=Й}x=gP6 $s 7s,RV*v 56/1+ jD[,"|Vb_ruxzL6o|l.xUaaPxkj"l0Ȱb.FHCZ<;$D9923c.M' ѥ9nxȎ*TC`_LTEH$C|''4Sj1'dY`˴u'd&zRfJYUG.f;e@yk|)o (ڻ)Ry-60V +2%爼뗁hޟO|pEBAdl :'#ɪs=W O@bzu'V^TWRCIQg:w`@QGPX#5P *}0aEK5Cڅ}kxLYxb{i)S|56 gA~'xHs~N%Ͳp>&UHn6 z-uI C_~ib '/ er1LP޼\EQKQp"?z)RL#Q::ʇiep)Q߾hHY#@1-3 kFgԒ,&5t`mtK[݄Mdq_Ov| 4Z0tR3˛?{ުm\7C1ANU`0j4˓_9jAcdbL<]Z}V=RޤB?fcb+l U-F&0ݕu!{f=L6=*tCw >Pm*,Ԝ|FAp6"\<nj$K0 {ܻ0J޶z4G%P{#+N\n`)܈aܥPh,; ^Q <E+UÖ=kВ5$9[|R>\Aib'6ٓHkNWB/}3]+'IY4bhSrhݘ/FAv]p@fVS29gI,tmEb~K$G$Fn Ζ3GcPibb@I@<06濾>*t2Mqgo'M 1<;;rgd%Bzn g& X_?tWH"X[p(!RVGC넠.< M,W4nyK~)JiʜRT{OTs[Y!jynz7NقhКiP^T&j`b4HJS9>\MaLĢ5z|-ʜˁk3MVZyӹB%*M (Ǿg e#'%!D"ƁouD &yeY&9\j_LxH.^dhs^,g 銋p955:LwoI #, c|[E cM. 93_K0@mz7뵲s$7O7 k% pWnH\Kc*0RxF<ƁJ^I3rS(^!G `~olӹg%6SI Jb܅{Vh~5SWBҬIFxUہkZIA:H`XGFt@k}ˆ('ȌΑbq{i ?Ƅz݉npfĽ(S.ZwDiC-ME<i22%8Je^y,I5/$GH)~$N'(Au 7o3y ld#SFnm3 ~܉(LVaaAVȩ|>]&?}k|$VPE8|#QUNPz Y$/hb-t@ƀ R69CU ZbxC)QaR~:ё뎪JMV5]|~CqbTΦqk})\up7_VhV7UM3fREfT4L >e)Kd?C.T"&_6toJCTdן'zXj.b=j*b-hFf MA$ycYTF5rԃGksTɗJMS\^2Myxd*ұ[K~VQ V*0q_:k>M__J}]#r&\93 h3(,<4SA_GgY~?^;!Ʒ;V:I]]R/d86];?4]@UW&,n(hLavDPCbjwZ.w8pCɤz'g+Ev"?U3Z!(Y9?VcQ~RM=ZGi2 sZERS.=(PhwP{bׂ-}^O`龮Y‚@ AG 2ym-K[Y;H3<e,E{U%: }=2]7M߉:6x)q <8[{<'$￑R~(|$bY<`e\ ڙa\$~L3-&*\c0yF5<$6A:5-z}SG+jKx7p*M\u ]iWDЩ D\[8JYq89^Fu[~lN.q6<3۪ [A|.UXVpeK_̦"^J5̊7 ܉_)NIR qCJ:&mG?6N|o}?zlc?HV<8{P9퀧Yy&<ah#Jth/u{μM0|lJ@)/d"s+>ʢO!Ȣl/\"!]^PY/U%{ZF0N5N#0dM`oݽsY$wwG>nҍgA=~GS4!KNt_5ra%& Ǝ C,9iP K"^3K#~cQJx7g`ʅ5+mW!^)H5u+1Y18%s*JD9' Z7\2>-bcb w8i+[A3t:*H9jc|.s:NՊpZxʷe*|"7[j]v{Tw !,x .M%qe)ʀ؄Y ;d҈#lm%xG(DsY{҆x==XQt(uev/CT8JOSvE<^zU![ cK lM9- OeE :dXSMD G0Jݴ*Ŝf1^@>`wҞ[M7r:j7掑)I鬟 b1 U5ٰ+k bwtNeƚ/?"\S?cQxR;}m" 'ڗSRBH:J']`:>$87jwf|IlZZ &7>ЌkF}Go:q/p,p7_/ T`ZWL vO{^eqŜbfu߿ySl&i{δMlᥦhn\i@#W sF0;GleBޏ J.uL3=lV"^RfM'i-_O:l)+6`FZ$]j0[~7X%y_,0 ). /3{T4p^/h dDQs_X?_`\oĆ VLH偋gEV'K!3S0eWk)M RO/u9R4{h,#" VJ pm`! =@Fpó ;Y,T&ڎ>Z8E8v8Z66fO`9Zm7CP 0n%U^[vХSZ`J$؎ME;n<&=<$U¢M#5S (`$5H?rCk/X7Pނ8V>' &E{YS|=jvms+޸aN 0'5/ߗG|łυC;EVkBsvTӋW&q$Тm(+AtEV/VaJgOHmOiG16!%@p );_6 S'73(D,w^<*T䝤&7ilE^llrH9ZſZBӿ0V,{"zpOb_z,O=!Ŷ$KY9 ޙ'8Mr3ÿH<ض*;Yg j ҮQ9D1Ԇ0 UY!P D7/ρ}^Xb6'u7i͛$Dg~Ȋk0v'ÜNDs>Q_Up-Yx鄱_wEc: 𾛠i7Ji@R%bh]sbl,6na/2S?8`&=$P$]UU_Ql DYwJ`Z0HKpr~{.~0⊵Ԉ 9a\QUU̲+g+@h|Kn]Y IPujh+Nq\ yq>AhA5d1E=MyWZgH?BE`LV9i"!V=3<܋9΍厲U9 .F2tp ޮSkc5qu Rի]A8ǒ,N0rJHщ-Rc2v;H;`8)n3nœEj4O[AٛH*6f J-KNad?U Vd)9_K_U5TRe4'bP\c8*&Bik;L"RAd?VhQl54Rr\:=Rk^eŗe{&;dѾ[ɋr!9F*,:2'$FҹNyzM@)>єaI$ v 6 DZq`[2AFmTwg/:VK|߂xإp@B } vU^ "S9t䳢u10K۞wVa:C6iU):y4y*P0"]TRo[Qdbojd4x^59)˜5pVO"pe9vفm =2=E^7WˌbN/z{DSe)QBV^]?.+vgB{d "msZ!!N7ԜA;7^8[Ż660p^B*Q7!&RX߲ 8Y6[G3@$>DV b41F bj,"S%k t1x7J h 6!\KRۓr>U)e_(ۻIU{餃uŁWYT!PP4Fѱ|X`0کtOp_Eq k`N4$ ,=7j:8e_b;XĭP'(ECm~[P6Cu9k\$Ct2I$tg,;7ޤKʪTH;.mn{xdHJF@^p-rźwhEƻEA;mI_iXJ?Ʌbcsf*??AZ% %M$KqA sɮ؈BCAI-^h1IG"`ڂO]1b(\SՍ*U/?/%˕Nu[^Şkz+ r 6;fq'sRnlyv~=iD9^soND }R`JVD3 Ildl2lWQ wBϤsD:qr*rY CZ\`WB!.bczm#yy4uT< /@qA \sjHsYﶀ/)5nlMA(F\ 9Sz&ͤG3)dr>QZo=B)tş% *ڮK+vʿ %/qżȯbL@RfLu(r1b_S7+Kl:#~iMǒd,M b2Vw!+]؄KPl}u|蟖i)"`IYg 5gH6h[#S mFH =d &M{M=kj^ӵ#4vyu&IڄgC֓W!e+Q@K%ϾHRK-Ð$_Jk\ :]DŽ׶ɮ,ME"q 2~2NGs׀HW |/hz3+tÏL6 }ݪC܇I4Y>LFŁŌx!ʅDyoW|=1Y٬ m':!v4k Wꣂ䴖|b؃rYίM\Q[ik.ɋhABmp~qAj}]`ѴޝnFd۔bp (;d%ЙyGQ`@Vda1w1jJUz3n>ӿ238]%;)b8zaT.F~-e?CqVD%9Eٔ^!bR8eDs4r CR^M79絹tjokY˨@ D^Dlp~}7R4&Ls" uqդ2zcm1V|)ݼ&x7'RLA]ćJ0ŸY>^͝]Ρe2J&d;/+^=S##$ہA,E#!O/@zŁ:c֗X5PwM5mףT[:wx$*][P-!)\| RLpxlr/%|8)_*[ A>Z<=A 5g4>e 'uMͯ},92[@;5Sӻz$V[4a Z(%G(؈}p4OW;c@+Z7IIљT B`86jL)3/oى~{OW0 =pl%ej}6wUíR[U)ySAS P[gc؎lp\ 'Tl@# !/ 8xd=ɟ+3՛O:wo&S3*7-ݜ<MAˉN-;<_i:A7/#v*8uxl5oʛ7m FAr9Ϩ\y2-H05F6raў~`"'fm?gc?y)e5UcK<~qXvwݵL9.*v̊;[^n9 #S=oܟ;(:lW>]bqkktqjD,N.EEvP[ 'vt3Bs #>2 ;h 2Zw;GuPKwβ~'ue]aH >^m uہLe?WߖGԎ!M”Bʁ7 11LTIYv KjЩ_b`w*FG6%Ögb*T!aV߱Bf!b2CˠRү^ E Q:m FJCQg\s [OKNC6Z\dŤ0#4@_-#”NIPf%qڷ,rSs ŊPd-\m%L<=o?9SOG>Gʮr4c &eF:LPJXL4Y|WڋwK4RoZiͭ?ySy.ӑOR^{~UlܲݴAl)cp;D7w1Wq d2 W xIB"8>VD,͓igSpt1'׸C`i 2?3"~#M_voSmЍ';΋M"P¥O9<kBPD` 4AtlCLS`iY#^ڢȧ0km/nj?9m5* Ag'DUš6z~4!CF"Ьl'"t/*aߕA+Ó5OW,ѸDtl='mB}P-܇}͞ W\]r%4߶Y ~HL"-B c ~eSn;'+}/y욹a&m{{Оy>aNM3~Z7M-$٣'ZV;?>!1@at* h=,)H}RR4zqtZzj@&u[e\$ zlUEFٖkؖ7vG"tQ*՞a<4 bZw0GƚU{T|IlqČD_?l)c^KZj^]tڕ~/}uf^.aBETu*7+|"hpH?HG,+ețcClV>AsrF*_m N2;=A,FxvHKx/02N/Ȧв{lt-mtqtaREYSTOF Lk)h'."$Ba)QE~u]g珞)gXtA۹_՜EBX{C"Ou*b+RsF_:=Ġb}LInAiÐQoxhgPSu7'x/YU'+H!O?K&;u0-Dʿle&,ꌀZ]\ykDn/ D~[%FMOj2YDhʁ`fG-]r%N xB;ȫvQz톢'R;`pG^C!eˡJ_kh4m5B.^ƌV+'XiM߮Ut"kN#i_đݜx=%v 2gv %"u"t=?dgXaכWk:!^P64n@oo(f^h M{gzR1PE3]"/ ԉB]}y1傎D@zZbv.!Hl)2wpl~륢Н t{_8sZ+XUGі&(a~("V2ޤ+tփ I=IW}O*gec3 ?wD> wvO3ȎᬚCsFBC}O YG"ygQVHIo+( ,ꟍ}9*xGrPnG%iW o%,|S]s>6a޼` tB= HBNgg]6XͳF\ĊᏏj.R,d%QͿ1պI (l)5)¨wbDk0Ȼ LPuy誆Ӽg,vASt@yflbk{ ~IrQN~?z71֒;\ᴔ=ހ{½L| Qvzsq UH$Ki\ӂ+s;l3xbH:t&;vϟoԮۑĸTy,YxiLKyemHkLY؆Eh ‘^SaB>m-5^~`7cef~5\U'K\{OSDZOL6oR-٘ tmrZ6_€xWcЯ\x6a)gs'NJNVv/m[7Qc0QH(S4~幋 E+.6W{m];TL]ղ'~䥤Z㛩E<@lQm4p3W0U%xXg9L]Q86 fz6𣺟AL7" _Š}P?B'vOj6 ˥aKo 5?Qg>K,53 SDmh+ZI#jtbcmL?bfhτR)!;J9'%sѺGol] VCcF0*6nӞR#V3i(C;}j=vӄ7H3V(B'$5Aqq^ "3y_Ȗ33 ٠Ī# @I: ζҴ  gn\ <8A6 MO^yF4p6/I_%'WAѭza~ɒ v󶩗=VqR<}I+7, SՕg>ysEt oKk` TxdSࢭ?[s+flK/I-$Oj4PٙT0kǭ,ER? Aw- jǦM`g0G ϼ}3K;ߣr%Q769av)X٢,0z/`c=>,~%sLiUwך{H8L}UL)d'/;5d%zf^Làh%cK*ٙT3zI~cծ0~?z:NvP8;~BQb؆]FD=*9k/o!D]fd^fTnUD?e (<3A8s \ɛ,]qMfoRXiUgsN#\.f6Ccs]rƅvH9ndQ͠1*۔׃!FB;H!y^RznAc茽UL~Zil| zo0YӸo՚5jEf1%j搗1Cy>KU"lsASzYEr]{Vp"i< nq+SK ,@ Khe%7vH*o,kJ#j1-0:T}+U1j,p| mBY ȧ +>9].voOYJ\> |[ ec ߸R8OK,GUoiwdo}j%V>>k`X Q\&"(9vtiF /@Gi9RPv <F+slVBX=F j`22*(}VTȻR,s>w[@}YtCzf_ۻoScɱؐh%a*IO $_l*_/B@k1B̦IEFg4=RWkخ RM->-: ޹[^8SiBl#zqk#1|٘~)P>q Y6bHg P8-pd69#P ۵YZ{~{uf JmoP\yÏ: iI 3[#4$x#GSEDg8cG fP7Tնn0CX~}"Jg-0c} Y9γ0 .?kU0NENұzmm*¦(LS|} cWYd#OTSWq<ڶ@ɍ ٚQ#CU{dݎ# (7<ƛ]|zCeJP(w%ޒ81>pKwtU>rEO%Nbq#6CFO!BSwwK ;&T,ޟ-ThRij0v9Sf#E*監IK.@> ."@ejtk"Z/u FK<L|$QuSbM^FCfEQdMƻ|#gN8ɡ@S="xȭ߅l q0h>͓*5x,Ɓmػ+GgAw>GyX:"wc  3TR'  }4&1'(jB2I!k̚Nya/oԂ ;#nrya3}^g?]gZ`&G1nZ." 3a3UW|,lFÍtb>8`5%)US%Q[ 謬zROgYx8LWl7 B5uΨstTQvbw)M}cSe/&okVSP.ӝ,D.uTt=b@vOLCyͨ4i9IuNG֟Q[ہ8q(^'hjCHL|hO4;Z=FqsxJ 1It`95#B H)p. $VpQF;t^vj;t,˨~I,!]6!*d/C{ شؗ!*7$8gNiA'DÆ**2RX㮎 ^"0#wOk: ?Mj8u{g5QnumXmt[c(B/~ Th'gsN3x(5N}cs62̧0;&[w{xiE$/编O m`ʫMV˕ de fj1\IZPC$t0f{I/=R rf^`.&)'7w^1heIkBkz ?@]须;+orޱ߱/󖐚Lٹ{!`AM<b yV9Zϓ0 }G*Q߾kK{Rk`ǭXufcW;$)C/nM(鹍ܬfVlEYc&|y PIb&CO-ȻzFh"Ug7f$f:y+xe㪿_K[~ъ9ԀJ/p* b ^M^"DXkr-Co:.6WA;B?IJN*qz!yCki&W!ħL`}xr{63vdHu9zm1YStRGtظ뒕G:^/c1Pl/0 F[+i'>XL9jxKf=ji<|FАUGA!Hߡ׋$Ha/$}Kyk B<&P? "Y*O1:uє7f2a;H NBF,96E..RgA&uy/⤌Jtt\8 [d6 &vP0 ^0$%W1IUi냍 ^}a Ro5#eȅ> oURdEeLu:{;\]Z3>0C 8OmܟZtvN iw[ ߦ9X?p('5[]WC3ڴdJչ!8.HOÊ 6-1ސ~cSjC\SO0oΙsQ JN"u /04&e9ja#(ulhSd|VVE3?iɣ#BdmmX^Uʦb[qTG3 yBFq1x,HY[]l"~&_z]JKnFMTL5͏PXZ(4G;QK$T.܉e~%v\TxTX~^:h Qԣcčv'<\i2C6pY94eK…`Ã@:3lxpVCv. Ȥpņq񫻃zcF"݃]Fo)6 {>$IG -So}gDR]Xܕib*V7N,đo cc]a:}`B1TH9+%\ dgYd<ÖbvLU ń-@"&~3Ա6M7ڏQ=:nٖ6#bKI[i`t%30,SpzDww}+^Z}zÁHAT$6~ޖD& r)a|+9'rnsΑsf_Hn8xQ0ƽ|-6P`; MÆM*־Y5 Yf,mx2 7t `(Y z5G][B ڛ->Ieq۽S'eݨNtm^2[И6fުQVttZ}G mfԑ~;8'iR!päk-2jk<#m̍)S;K},l^W מ0peܰɹ9إn.fuR[䞻%ڰ3$ߨǙqR J2  #5JG=_9q%~ Tn"R#l~8oNZET x].= =dyѲ[\LL4%N`F=#'odk%TDf"ƒēZe8uWk.~ROWaUO)~HtK=t&gboN%3k/6%GȖ]v]^($LZa&l2T:{\{"iv 5dt]{BzZd5۷z|̯3Y]p] LFNV~gk>XSMixS\af!=y!XmΝwgwմ(/7*^ձsrvteʪ}C蛿9J QOuG ƫf.!uuŻΫ )=4ҘOݧ.+mʿ^'GuT)WgSҭơ~Ict;UW8$\ };uSE8uNOUp(˻}~2-:*Κp>Ss)/#SJ!7 o JYExq+lsbhfw#*gda8=|JSR!XӶq 6"]hl6.1(k)}Pkjyo󢾻{evr:ߪI2ё>g_^э$u4`3&\,:@JP.b5lnԘBo~ܧK(Y]!XEPE0d+OOCsR d&N8aHȡ+rơY)ޘ2o<"bЋjgD )i*cE`VK]gY;@g%Rn;1Ylk1Bt*LE|YJ鷋4/S )lzLgTm/#ga4n*>F&oCIXv <p>? Ǥ[5ɵ ˦KwxM #Øjj>~ 2Bydˮ̦0ED*oO8)DoR fV/1ߋlz] wMp97E :wuZj:oBc" \K}8PY(#@k}{{%vDAMYU~ \f|oHxِD`i͸y=)v+f5?sK}nXz'4ǚW:_NHj=>ا7-wTx9:X2kQÈ \PUk҉[469ld55G ) u#%{.;6m(M!`) yfńhmcɈwJ~傕3%h"RRωѷ0O_&·!l^&|=m8.Vl׵˓W6=R… nJB&T@^Ņ#,E6.= 0fGKD'ΑSǒh5f( zuZ'V{+fGƬO.e8TQwb-X6m҂?{,]57,%ɤ5QQ- y-F9Өx"ԎP E- 3kNtE &% n"n| :S;Z*ʇf4ȴTRf g=DAGn|AOHډ&~P[TciO-}"lTNFI@f q (ۙ.C2} lj"pDO5@"EtAY gi>ڲ;JEOø9i- 9sb6Vh"hR$Afl0+v/Qxwq[zal&䞯?*O3.)v\_r:9M"k%.Ӧ!bhbI?kuZNO9;0EϘBQ-a.+*PQfP v"wtTL>ܡz~1+QҚ<3 թ!\EF=.R;|qj [fK(iɁod5yDK7](3M{w`q^ӶU^|d˪+=\Gs( 6E¬A0X|.uXs'TmSkNd]J;+s0T*<mYFi7/>\L'Dz59%.aZ`9{nsZ ^_uUe X}'wF9iguz>M y|K:qkNܷwVw:lT޳=R`#b)=6LݫHO0p1:h݈]2dio.G,GHZ/ !Ħ Ua%  ]R%E= ;Ӄ)L\Y}8e~b@oݞ0AD!1J!0Em{t8$$ 1xhÚl $k@I5ҸiK1qG\W>PryJ&\ky o*;yA!$d\ _s]Qg 2ZL%g=͑l-_H5* d3mR](:<~/ЪCyɣ~,SY;̾4YIcnFIB=ο)9x։P#vɐv`b۲11 ?Xtut$txtE4'gq}Cz] dJH/ :o7PvV_y)8Q1Nxs }-fڢ,cls' f&Fn*)VNͨҦE#À"ɖ,ecn'}#9Ղ L6hmsqs]aT5Okπ E/7DԈv$ 9XsH$mHU!A.8;Q=ֳɠOJjla4pye^K:,*4EGB ӆ #kM ){ӿof@p<?Fybct$w1n1X{}_PB!' ]{E ~!=vԏOR=ADށSK!ח!GvsVǀY1{E'VQ 0?Bz/* B+ =WV9fZi=d>-dXuO _)0.u@iŹD .& k=Y(K{4Fv /2觊i. p1FҁyrX󷯓 oPP\6Ю2< V(fsqK"*tHi\L|m;R.;D6czϰgl]vPpN%:terOpQXosUP'M"<|]nJg扦 U'hE/*r<0re37c[}NWQ^x\*tE@V'`ileI!?K娆6Y.i!I%ޕ(yMҝTe}hpoG+@꼺%"W]EKK!o!t9||;!@4[g8__V~zP'Bwbn2h>3я@DfS5UAX= <ԖCt8q81-{R֨bz" `o9$E{{_WMӠ=/O7/QbIvQgyF|/5(YЏgLkvӎʿ>6lNnu(t> M))=9w;!rvzñwv)Rq?KX[̾x~9!cyzl\'Ƴ/&~u/68bǸm8|QzO/*"xDQqkϭdJlDž9d ._#QFR%ɅZ}3w8oz*CGɷ (Ntb N@ղ%B/B oJM\wJyaLNtF VE%E^ɔI-;kPGGʆX*}ɲe Myw5Whv$;)4uV R L_Px}C TӎEefʍ`|s&69RDD͝8`n'yB Ҭ Bl"; o=+UswڰH5 G}i _Fi F4bKӛ1gh.5vm cRs$ڞc\hX#6l?gwdAMb;"^htY!ƫA h?2&cmSQs6P!F]5E[׹d^^Pt]mΰV$}2h <{E6bgl8 UJצ33B> /n)U6%̠C-k;'ł@;$L1Ղ}w 9*Kh N~*jc4aN8k}VRief#RͧoMKX&5X ^suVQoJd}\vGVX6l T=d rűp0[ L mL [ņؿ1ĥg܎(ߕO*dd>!=lؔ~ރj(X ? h [ yћ&qO{ICdUcbٖ,+ؠU%BnخCWݫخݞ bQʙ*u1@HB *F755BH=C),j4-ȂR)HGa %|rW#t?Y\gˍ0/,w  tnKiH22ub|MwMK9\J#6q|S !jy{I*_(7XwR'?mn'CU<8YÈENrX! ӿ7n#Bʼn1M2A7 4?1<ሟ6̾S*<W1Jb;,TŸ*$0V`pq'DYc*%or#>\=g^N?&̒DLj' bg@iprYBs} ȧoj|@q:mM ?ٵw :=I'Jfq)ī+rȮoyVI iI?%oWYJȲ9:^+="Iu[:ץTUĞ=7Hޔah6$(t &%a-X p"xs|ɏ 5Pޔbj﬎ tw}zxa3l^=~)bXű} Tm og(oʘE5M)z7[&_HNA)iOy ]lq^~{.N.mk6J>dkOa!c,q x =:{ot ?=NuUHzdY MD?wH`L CV*G_ k=ոA5͉ )8et %|t?~$c"Uta+>aʚXtceE0Qy)gk 7q׳T־ dl+r+˓իwj.A2NƔ zz)PxM9C V(<`w#kZLDqVm73ǔ_z.=T;8sIufϴ=$mmr4. )3Ll;|p1Hch ŬMmxstDn0>0Xla.It 爋|C'~R ADKqY]޾c60Tl6ȝVI͂1A҈i|NnBx p1BC)KaH3ؓ$glf[43T1q?.,OGC>ZV0EXOvcH<0AK_r3Tiw{VdO M$:ebO[`\djv]\H|pP(ہfC2ripcC .3{!]OǜcoPUy-TӲ8ɇGڭ *'wJvH;fvf%(=3#q[8~5d5iT)8r儢3=!sMƜSL s1(~Y ]Yǔ 661.'HvpC`}~esOkTp¢~j,vQ:'Ϭimee$MTe`Z4D̒g¾&Yvlc'ȝ{0kbe2C 5Qg ŷrT@S04UFs}SȰ?Pz3aFzx ߞ?r.jt)uys5!~"~1qevjطpiP'SP?6Ya*):79_)nUbf%C 5 i‘ߞuTtQYo$^ϿxFM;AR; %mXprfPk rmk_ Rf^I(r[=}®J;e>_)_3= PXV[h&&ӭ3:~EG{ 4"cF {3o>`$)ڧ/ôŐKWn64YMnR#iETCt; |[Ң.tȑXV+Z Ec#I8u1xբv,g%?5 Zj#hG⎮ H xtʌ|y#t8/X5~-h}PL9_M;{aZ~<[.vQץvCC/WBz/bWI1Eom}3|rRgUr!Q9^Pl {km{_H)@ͪŶÙ鯭* m]p_Lq xђߖW8~@e:«I_0L/P6K~7U>D:F: F 6R\ഞi3c= -B$RlF1Io&)6K)z}0u&aCCwAcc"(bB:@/\LR-dQ Xpp,Gʛ#,ܺgC3<^*D"mLr[_/O~%@[mg IH|=vBs7[gyd4Wc^~!I!@&ϙX6X[|ɸ2Бu1djA~D^엠?/ͅ[%i&O5޺PDEiMFM#dkz 7&q'xiyŘB/CDH tφix$ lnMWIɏ%8hS I@s,^9zcyx9SM^z xT(|uumqͼB^ W.9uq>zJL')MD,0$“UpA*ݮ%L tA yy*&9Kߌ*Y7lNEP[if(m!]mC #F0(y8&^\U Xv+V;3r.Sڻ xs]  4fp+aG(0vmwd4725Lv֞H6yc-X+sD`2kꌧ"ía{Xo|jio]pR7MO8'œ.ߙ4Y)#Jx#c:gq.DאZ,',ضe)_.rʷ?lj:&FǬ[s oxښ$T7GK f.]SxTɨ]5D(ORקYEpiw$53@4۰t= jATSsWCbDJcKCtQ]/ӻG4S'„CIc/I |T~GԼkYhnR3]m.zuV~c hw:X o5JͣY  <1 mIևq_P7Tsfڪ?b2Fײ8 Q #R,eNxi"PoWH%,92m5JtO'24U{K = ïocUw ߹3Tuަ z])]adNEsib=RT}KYl_/yv;.ASO/<XJ8\X݈5b *,60OC'ţ;M9|101dlsl!Rg#Rgm#TAaDyk)NV6B^2vK6}z3phhYž]2E\j4s>z"͟=rj~l53E=H)%tGhg16 j3}A'#b)!J?2'b(P5! !<9*)([BfLRF'Q쐃>yiZ< 2Mdj}+02dCjHiCuaTC WZgr< o76<חRyaiߟ7i]Ҧpu]{R40dvI?#pd6pnzuzf ZZp^I-MXKDI\)DVa9lRncnǒ[4ǖp^3)nИ';5ދ({&7zu]A|O$J]#øcw݋gdIJddfN*;X-) Mǩ C'f;"sJ9gTV˪'O9+Ƣs  ,0V$K8lG"GL2CX[;+BKrZXZT)]5֗  3D(hhw>5vˆR9:|PɎCSbQpKZ2 k1LN+/|#%`\2Ҹ[y.f6mAeeа$[XyLzހo@҇fUa7 ۙ8."P*ң]|O|UOؼv2:&˝VPP54 eZN*";dvKCkv\`:qy=vO:'!J,w,8gЕڔ=ShX'oUEP !@Q@j|ͳi$˯A7TN Jt2|_O=`  ~sQoOBBXFFmhK`h)7ٚ>y#Q3kZ/F̬OhtrRQwH.rLNZl-g{K®И=5_tɳuMpxGCqg]A,uڂ̈3aM^ ϓĂNɜr֑ d"1C/!&~죾&FMMZ YIFfGGcBߥ(98RU(a bz - E"^ѩw=>=>MUoNsdGq!:1mfao\y\-H,t=I@}g@i< $Ը쀽nu{#CJ#dadkLd/GaקDtW!%TB١dր5Ą*MĨpHb !j\KS+rǰe40.:)vvxZMbq 9~8c{j~٬oX]jiQ01~] Qݢ,g؏ ,n@/wp"\p@ґTJr.Y ]lC=Ÿ>Š" #!=ΝoIPٺAJ;9$4 딨X˦t+pI->0E'W-dnt9r;ldL3/]fO] /c'vg5fez D{΢&G{}r&HlfӋ ix#|IUJ ǐRB&Ds}ߎ0D0ܰ ֗Т Z8zpA7gDyV=jBd̑"%YHnt4:w2 kKlO:Ii} 8ӲR}h"򡟒 G>MT+|*y4^?x(Y@!ίXfGld58jO%W>x_۞ b}!͘j mཤՕx9~'Ւ%"WH*0~Q1ә㰼xc6 - IS"h<}| Fܚ{V*6ҨW21o0͸eY935԰kgIaT2VVw>4 +% fd64^}'fO$Q  c6-{<#?{(L. IyFA>Eo,T@ aA0Л]W|s9Z@Za`ُoR(jY 9q1R-eZCxtZP٧Mڱ;\<211ײyuj)aHa.xc7ŀ?]~WmjS(fZ @"sHs3?O%ȒKǵCbQ`zcQGwRTԥaٟo3dށrAG6tr_cjLLq)IbF< S~ՊDE:p^Q~ ҿoJ4;k-B8*LGHu"e jlJ$Tsq)Fף%Z[>. Q1HX[ ;w:qLS@&!,hA-: gi'^ٚrsi*J+pMޤTwlvY12zn1X'G%F"x ܞL;h·z7 2T#V}d GA9-6.|!%:ֆ!ܳ I7P@a4R](]D 1 0F2!|("IFKsl LJ0__W⠶$p9eD #rGI//Vf+ \dKaX-Iu]X;BKƭ3zI;{ӊAd<`N϶iF1w8]|F[$aX:kE r_yEYh0C1wp 9| ,TXiR^p's (q =aH/e c. gƘF? "hKq =O GEP=.d$dE4(S }vA(W*LLB x5@a+Ƥۈ:8L!qPP&q 9[[Lam`[Uw׍3|_\l:X"sEft.Zdu(7nVuT)sK =TZ;MNxOZ廊. `8`˼>o=0x Y*L#Cje"ZJSh]9<^\d³={3 M> 0]Z&9s=VYcȭvu1"vc⃘ugZ\~9l| Ss~ȣLr:.8,oO$.@ 5VR7h22HVzߒPV6t\-tqZm'C)T- RXg#5(lb,$j mFZAZdab]SQ}F\,=zpߣ U_|3v!1~ak\''_)GW  EGq u ULvɁ'G“$JR*~E`NI* H{mQQ>Q Vl.&1vF4WM"̣D}H?aϧ 3Ek]de6Z=:<,&ʕ߂mڽAXV=rgeh9Wiʞl`j'*n]A9HDHC&"a91) O-f7 KvrVuIzm>):W]^!͍hֹдNo,lF]aE>>&W`҅J8MćPCF56'<,1Z*dj5݁}[Ux~t^텓l ~yZbL.t$`ձ'}(J \;ҍ]/S\=g$? :\k[ggk2%UnN;BFT)bʐLM= k'UPr$Tz -^8`H{Bf\hP5/KU&˔ZKC1/jn[vC_*k>UQ1qqv pWs'}Cl\۝bT*?ܧ7(' nĩ!]J-[2cz`8: yy" ]c:N05Е]ҏƏcBά L-i~&$б].LeP&ncF)b( 4EJPJ4) R48W\Chg55ϐAh[7Js }i7cZL~l FG3^ M>??2Y4;7mLc-Gry*'yP8Gpj+\V O9f) oVNİ6SZ-D  Tz(Nz1a ˆV~tQ|"<ԽG6w:d$0`rIWRq|HGoq/"8 tHq[KF JN=!zNsJTvU7:V,Uw_h%{j6mTwJhZ]%P[|̈]5) C':5Pe [bD_K8ѡn%p&g3yRXp UJХMׄS_hST(PN")phFP=0zR3<fF70J%j; DF'zW{f܅wR !B1+Y?ĭrN>WVMسS>?d+*1} R> *}cQNΣ:FcY-fF! \kls)%{. )GzuʓsP+_4OMN+hZV(1[UYưEX'udŅ~"Um>*< %5(^D˳TJ{^oj45 U H=gKH ٸdx-T/Zyb(G8yP98˧}.\k*u7BeBRWH|1b8>7ج!L=d0^ެR)S[_[q %ZP1b[m6jWz2#-5_L?7WJq+Ŏ$ݱ4Nģ5"С4Q{{!9T:{ Gs}!oמ[DQ69PDCEEmpb|'FZ*F%p`CJI/ A%q)){ZW%/&W3W%?1wj2Ru(f7«K5'(:91;;eʞmn@њǃf1Z#xo1'?hwu q۫АFp3;gɾ5::";/\Bӄ5|uP75ޥ)/nK* j¹/k) )<7c()b0H<t^Vgi,q_Z|Iq.J|M!r7ݐtW.ӀFXDŦ\߈DGf֤ Ӟ  &pL`?VH\%{2ۣdzTnʻҪ@b^ĻƔJkWvY[ cA>[]kS\euC,|&%*VG9J1) A>;x_h|l{ez/ Dq!,yYS?K3A|=Lߛugl_w뙈跣iqZfdIf<΋p[N}B!)5@ݳź9s_c_IIwWH`gm_. xw6)V9xO O. l " ?i϶H5[˃`WI'{1.&p@9@! PFSi4̖c'Rk UE#q<ȶg ZX^$D`4+ dҠ#`x:Zp{'Ě:ƪ~*†0vAeUr*W?2[V71j~M '{<[Κ=Imi Laws>\-]=zcܫ DP]<.rvݎ}z},YnWWeu v =g RwR<'GRK2n,W74aꑓk~yID ' nnl^SЕ;W?xQ}u"\!A0tNOf 0|\.+E ˯XRB-T=5WO^`&.`݉^ǹ̑溏?q"l4$7CRjɰDCT L_ˍn ƯEo-5%\~9&6PHϼ2\ād?B(R./D`Paa Aۧ~N d{{`7. 47YYÓa5TvZ$pI'{) - yXHh0Įua[mq(ݴu8Iq =P)nCD;zrȇNyxՎ ʿug;}m횽8Z0 =(pF,vl2#!X m0- X.s[٘=kwQi[xQ fR( @⣥M0pkKȐs4nrv L iCUphyXeWM:|hPz"_%򹙌d0Y.UzR9NP^~8fq/*LXGw}A w~ (} M7 lZ 9W62Ǹ_jK/G5+q,~@BZ1FO&ޮW:@MP!6޴]I\1ax{dEyY )W#@U bZEـT[( : 1 Сtsd5A5MF9~bv_Zb jΝ.9ŜiIW }nb)K #( S't $5ks(~DPDi dP-oҼh LKÜm?{QG44 F X R| pxP?%?rlgjh ^s/E|K220hp7z8ְf;Ȯ'ǭM%5\[k n;g&ei%>4 4i'WGߧp%i ,04"KN})n_$1m { 3$sp<^4R&%iUw̜|m`\![<cZ09L'ݐX "CqAr< [6 Z$<ËTvpr=O|L30~~B',4IRgX`4ۂT;m ?H)4*H,`[s"^2M"n=/P8-|E6/yuR'?*[7Q]pdz Ex6n^YV:OAWυVum+pGץzwc=ʼX@Q'*<{3/)м%!S_RG6vwrشB%s#S;y:)}q{tE^2Be=}<m}3Cu6WȨo# %:DA%@kcǶj;E⏍P*y2$CGǾDWz(!5S;Y&a[5(~0vݰTYzMjL"b\=\);,ʝ)nѧƊf`FYԆg£sKNYk'ϮP vt1^zV7E7 ˸jk$ORe>-]Ɲӽ9. 1?W =<',T kW|N0ƄG\z-:?X 1H%)M\zM=GQsGțzY,*LgˁYOFfeqj/2sʴDGqe\USKBӃ ,$Y)qȝp:m^da;QS%(@RhoBF7n;F.`,TuM~zxV;_VIIVCz`Dvns%u86>1o,%OWŽ˸=c8 8dXr ^@yDٌJWP Sm6DL8W/i0~o/ރGPcqOIΌf@] ٛ]Б>Evjx8M1;8s%4:MѢth}@JXYDeE5yO LGtlj+?$>e;yn7RYIǟbvJ"0US:`=uTG7~g0_g&PyovwlmTµvSGL峉Ⱦ`rKMڲN+%OQ@qa) +w4n[[=lM Uyr<(,_:.p -Nzam 0@;87u@ }^ yNΖp4ԳQa[|3Ae~ lܵS{pQkY uga.KPYC{F  @ &N2k,lT]DӒ֦\;λYh PAX ~W>vN͐JF81{`oB.qݧHYzѲ!Dۃ:@+"D]u1Q+b,RݦlwQSyDi lp ]WQ&^w4î9IRf|7UBװ')1ٷiv1{PdG vOiH1OL2%` Q_UJ ҿ5?*݇#\jZ#K %P!<̼s' &<dMvoZw<\,cE#g{ҁցuƨWm>1vIm˸iWWe8u@>JeZUg{UU!{09>5^)I \O# `b48 >9jSrq$[^^7ׇg0oy,k+P"DQG:n*Q{dM"I ">}R|9<$ɻ;GxÊ_qT2ך//BFKlni敻H__; }%+'J\P7E"=Cs\hF}Ɯo@~B5ж^bfmu0G0! 6 ~ DqbfM"h)kv#\Yl{v2Ĉ|i 'dׂ~붼9ޤz֮dVb kENY[s@ɰ3\ƙQ??tkȯ// id~a2с\PFxAj6)F͖c)3OIǯoxlG݀.(wIx{畱p5KPX5c\9ijl?=g^@: 1`#}yHZ/=oVpꑖ "kB<~ :x K[m0Aon4J2NG*i:q^հb ]o}/f>R 7ubcҽ _u PdxgÌ-84!Ĭo,G8H1|~tAN (ʓ^&SkJ\X(8yɭ:͎ť7RQDR\O;xv(̒g09$Y姉e޷{A>`]ӯ+LRNxk܆>",or[c&K??EM($-t8Bԅ+tG|{Yٓ3 ِ_3Kh+VhY}-%"e1yB"]ާcDe|krW}l0E yckgc0y?+c-FM/Ž-w#צ9ڦr%Lf.dbx}= O,F—6xJկQYiK+MeQkHL8R` RJTUɮK ,s7/*f7g|QsPM&xޓPIjo):\OP_xȗAtGCV7e?!N+;imU\T%JSB?Х*Ϗ  h]HߕN u !_Ib!\WKsk`8(/uNarlh$h0vԩeKCɸ k-Tb{!~U~ uD# 3P/^$m'h ?ʉA#SˇwsMPu18NUGju کE`ߕqnM~UD @}Jy|FlJ|z637*햎tWdcdzh?x[9h~v F٨TF5ޙ8wF>Sb"1󗙶]]oD[ Ȁ4F0*YgnI/E 9GT9'cTРVaeƿi扊{W (LySsYئ9N,!5Nn"KCCiܨd ûBP73!Mz줬|~:7AŠdnDW4{!!ָdb=akOiBx15948;-Yot/4(5=K_ ]p~ZWsN**L\ުCptRe~Ɇ{Fc+u(MUxOE#g-X>IWXspTjf]+LGVGVq$*P'E5k_fCK3o.!zy!ײkyq @ 8'>}aJ mA72s2O&9/3Hh\JGoݿ~>sBݲ*<>Nz8ЗCF~ ޶]F_9H>]Κ311whuI1xkV?@ XZF:/L}O׷Fqp[@u(& `'}A3aWA)O$m]$b%^E7* Hf0[R @l,j J[zʋDVx"p`7+0cX4Ӱ_Xڤ,"/6T5s%$S0#8e~)t%Fj_ߑ˞d NU'D%H|0iaOu$ ^POζ,3bڎP.w7a$# jT ~a,\9寸dž l7=Ο27L_ ! x.V~k& +ϰ5Cd$Tw;Rr L4 -ϛchylVz-_C~/o/,. kgG0I{G=a%~fpSٴ9owI?T{zḾE'&VV`K_52n=-Z͛{|gS@J4v9ܚq, G2s>v?<\~×aD<XY^sܪ'kÎ]b{[Nl&ӒSla _v=K֟vYDkgxI33w]J~]E1Ƭa$*\Nr!毧ŖQXɊiEgS6}ŬI!B$2Xp)S.0u5/ٺ*x7/~S5J[  t$`g Vu&E5R.:E$yętH+\LJ# ?bIUW&z~; 6k?roEVB9DeĔ '4 ol/ql&RZe8 N"h@Cp*B '-;;q[cȳyڝn_]m5uhN.b{rcg |HI\[& @y H}gqӌBOp5F]\gʹBX&;BFfX!oɴϘaɂ%vMk!wN2/ls?}U܈^i]JмEijQZ\ca7IShocne&~7幁^q%1Glxފ]6?VXNgV`Q7 ;ƂᧀqT G reKb>cE0Xb*TA_/o߆2 5/WH"7q7n{`;wZzQz91G K!ÔUٰQ]` nVFӿu/!ypʪ2%_kZȠdn^OwFj1h, C<|tN@Df!gb'R}HM{vK_䧶1ЄCMD=ph]xM!n?(s)mURf;A9}PP3{&XTNDw 0Rɋ5ŧ%1%kZnF>x>TfaGoa4`_ JExgcYcs#Fƛ=zCLn8l"ûC/%ԑWyM(yKvo4gIeF$60Ӥt5b qj/<{h[ً=Т6ygcу쓨Vw :zğHYià@e)s`ߏH_:UQy{MmR]y| ɢ+]ghI*eٞq/72o5Ng̡fL ,19 `6C8Ę*fEae0lvƒ/PעZ *IUy7:td\H3P)ح &U9vOd q[Sq)m4XpPv%~ʜC aډeϧl$V w[U_l`탐LFtcPΙXk#^ëU\YdIQ8VQ>p]5e m5mP+R*88ЗZa wp5v3T`&A)V}~raER&TXbcA HLMΈ"As}~fR-Lҝ;o摵O2ʖd4/ #0U:hj, 6q6>C3ncd cMǀO;=o@f!bͯn:jmU.N[@iTOk!QzO]dh&=}YN!MR熷]YldP\ڀ+-q2[*24 '/ߘ6kfZBVjkBo욞*6RNC[.sbZ2۰.;rojUO5toX*. N@.&l!Z ܓ 0n@ЏfAAot_!z8&in0Kq#kfzё_Hg"LI)HuXemԧ3q2͇tȅݯ iG>{{Ac+ݐvMAƓT @dݼw0ƋB6I+j™3i{'0RCHT+?9z,a:"t˼n@2b|w갃/]z1ͭNj&u~8Ai+= ?H1dg1uWߍb!r0 H^UZAbX+|V[NcVӶ$6  9M]F3OYd+;rƍsj,,VhіD=oyҩL&W 5O#%@~0PQ"]y&yA, Qؙ+h]?Q2'%%.: #j`+K\DĐ XHP?xD <)J}価#x_70d,ɸmbmL3zxةO'-}/ѽ%fOu.jz'@u&QZ!aWC_&V6@a(%7} lã[/ Jqd!e!SvHski]hn#}]"9N +4N n5A&}{ȭHȖ>G.05`aR[LF y]^G)g߄J#W`Κo(j ":StcMopC&=Fd>g ';V@UߍI ޗ[ݛFڈp{Djcq!쬌B'>xK]y~";O}g?6[%WqXx Hi4&Zl8 q%oaƟNUB{Oe^ahZ}]}4||ht$_6.'Vx1-vyGry ;S6$0kM ed#~/Q{GB9vcEIL֖.m]PMgVJ+@%QdNi0mhCQHL$]C_|Rmk7`kA!&i}{k;Qv36ģƸHyr mN;to}۔Os;>8$ @^m,^F!ēx/Yjk37g}H`(ʲGxEѤG' ?(Jeh}tO7m!<$X:G%;)~0Ez19b}pf“7x˸&ۦwӅR >5۔ᓎc)sr,P"au4ҮLa<|23uHwʮO7RcZl&ģ]rqdW/OTJP^@2,2N> c, 1<JMAb!K[G-RF8Oz4R\i*;hJV%}Mʑ'"Se vxxG_A 's.ky]tZ1 >&Y2=4L1g“)sqd7糁xA~˨HAw.:GRh3aǸWxo!R)Q׶?: g R~% jOR{څVT)Of8y{ᇡiS(!Z0># $ O!K[^ >H:q!B:i?ܨ =OוdyIۜyxs?:Qk 1ЌMTqQ:ԑgm@[Lb*kQQ!4:o ,/D'2t'LL niڀ_ ?q&>f~E2A~Ӽ`[3֘Y\4jlṡ󴘚]cO-ãgR&z2`Dd\T<؝`V^k2 :w^\Y,(t'*ǁr 3r ݯԻz-'yIVI 4Yp.&L~{3aYQ5vdTr=Zv3gsuW鵝ώQQ]aTaPr'O}sz 2n ,5!f3?Hחr1G] KZڼ`f$ߍK"ڌ1 6zey(iZ?ޘ"\̿T:VV[sҾ S*dr\%16 )j#ѮPS@9e 1s&zMٔO> Kr*3^vkʽ]cUMm&6vH,<tXfyskC'ebT\I} PT)D4Q[\_%:aYʭ5I0 䯽 ǂv7Rhb`^3z,nܽlBԄ'K{RL'N>F* A;ȣMI5'cDnjg@:ƩXwՎ}StQL$ t\ہ ރx0.@7v|H{_ʷ^ޟI b5RbT.9iIEF88u0§UYVa;$C*vs_/i[P2O9xMEKii |lD,i̹,'&!=?bDbP+yM?߷-/e`4ŰCxec+zvW-G@ 1ܤ޼?3`q؅@;Զv>;NC3O..#`jԣ6g˷+T\R6x @l9*JJq#;Z+֊fL0^'x&)5]Tz }: 4QA@+K;-Ԗ8m1!4ƔM"Lf]+ʽGKwUNS!ېh79kJ4챹. {ʜt26MPwݫЃg#3/Q6нwNq7y&!ۅ MSKA=Fr`F&V"wȻ Ev?īd+<ΑuFOذ1.8>{[iLYTM8#'qJՐ܌4` V;/P ۚ!%8\=B;ɥ4 `LTC|yb6+R"z=kkwa1[5[7/vZnԣ%VCaIAcafk.e~,= wS/;khdk8jǝ@*6Dn!oeџj]xqy).Y*:u~t>Fyj^Ҋjroz`?VlI*_j p}yNTG߇LqZP\j?sRc?,t"' 423QKls&^*.ib(3"*5!|E= D^ɂ^9뼌ԛ#xlpv. =n}> ־{@C+bG936` U25bJFzC,7sX.Xi@qw/&f9ԕZb.`hU@?7 =O**WAddd 8~EfEm`vqSDz!0[/0M_ljBeV< ߠ%:rV - 3Vgr||`RqJkDκUpbLƉŶ7'w)<PrͲ2)0^>|posRϤ.=asX@ %L}=456UU\mbTqSޱ=~mtRUJw3=l"' ;n~ J,Zm(OT K[L@Rw]EE&ʮ,}:r}rS^P5X Mt_Oȟbbs!g˙QP+g QY<Ad6s~Kі{"}tEg#Cgf]pg,l VdGYfOYSwM.Nd!R*!GMoW;K&MiV* jUa2n'2XMm!֘A55cdq埓uZ9G:Y X`pH}3Y (rzm괕C`ָUANLj ms㙊o.պ+JegϦ m.Ytk1Uo1@+JlBEWK?'g<0Ibl^ʖMݗ@`=q%pUk m&0$p ~U_Dvp/bH|%Kُ[=~!(SٷV@X:9itMQUC}e'!Yu@)G 9_I#2HP(|3{?:J&R(ERhpi$Z`E3wz>7^),xw3L,YFԌ l2s~wP ]t/Lq+eѲWiqp+U]ZӒd=ix[c*~X42 ++b(Л7%X+ٺa%"KkO8AՙF $05ZܔV0ޑu-5,HElmIqMAu8laFEu/emnHa&^j_ rpBOڽghk?ɗD+.-$-h'e}?2&%i'60yh3Lty!'i}MT.7,cn 0W'|l 8c1?e!~Uh{宷k3 -Tz V\Ϛ]jd%qhWLՌ#p&:7d3"~%L'HٝWnZ98\%땧|i舟 Q']52W*v}Ǖ]MA*.R4޲e>Qb ~դsMG..sXQw Qb,QBI&ڵ'k\&>Hʳ.[N?iiuNG#ډʗo]uw!} [h+N\z\.n\ 3%ީ[o" W}7q~bOg3GbA"^N4J8gO0oaht0].w[ϩEEK#zZEdOn'FDNNѩ~a&e1Kn[n:Е#ƒ~/156xZS[mx0w|ҙh19_Ji4d1LlsB lf}SlcxԆgS;ݣo oe5,"c_ ?>/1g-սzߗBQ!c09,f~uYOEa3>*(MKCY%Ƴtzs/T!I?9u^kڂ}-l'I_%n95~\~@l\`>i4\;T=.IYBz.9yYap2a-0i;6%v>b(L$/fշ ӂPc5c'5#^gn!x-ҟ'kq5;vj7Ӧ`M(3@jBoэM]Nv0×8HR*D˿VHp¢g`Z[jғL"аO^[#вE,I3),Rui *Ȕ(G~jiOjl{Ȳi|`e&3nԄ)JS\RvYsg ~)wrVi/) 2/DLppqo4 Q(jh$q߁\Dg $S5)%}.oPUckбY}،qF9S܈y edȚaQNLr m8* rZ;Ux47~+D{iz  Lie]dqw')+&c "uqkesL)c.K<߼ _do̍,bF,1sX/H,E 6{+0=+u.cn,k>#:qa1ԊƆu94n"̼Q֮,NA,])lc'j)O՛eOx{WVAV/_n`K/8J+*8fB$^z^.l$rhK6j}CCz.o6{;E5 gt$wG>qcx=p,tt@aIENd,OV"pP(̴ e>olROR\eFwdžA W3i \7dVۂGnXWv2#'UJ*BG㼧rC]l~HIH& 邦#Y~d0 0Gs/QDpu!lJ83uihJqYYfkSGK1{0No鬇ӑxen/L/a FS=B&G{-ۻw]jyHi &u wRG-^Z=^OW"ֿ&-鍬ȼbX0Պ8$8rǒpb /]PQOjo8et ]U|O^t<>bB?VՁbPT3 rj@lR "K+"Z] %ЦĖaV#a\ rk'¯ =i6X膁 4ipn)qY@Q^XY$Q* ,(; ᬳ |rjo`@VtF"f!2#^NXR>$aiGcRs'1Pb%`FjH8Dž,|lN77r/D'NnIxStg­~I_߬[K cR@!AVm6'˲DPZ P(5L7%w4[~ﺘei3䕐kGfFbiD5<@6Int0E9B_7ϱ< EϱQzK&g2k|_߶S7o#ͣtzdM DR-&gr S|W]%<Eq_ s"љq{pLjpX07am`JKU i B(gt֟U`1iGYbZySO6+A)mQ|f4!w 4\.XM< = &1rlr?s]֢{-^[E9,@H/FEdCqT? 1w9EVE$ f^\ÓQV+=_!__`6 Q9"h/gmcIx yীpKGX^s5$lj 9_R\\s" >8\eoj4ZMkôiRJІ`~ 乫?7|CtTbA8_ /kZ @RQ?,hޡaE^9Wt "@ 7_1=kV\HMtt̡wϙײ\EWa]ƕ&" 0$ɐ+Ɍ[ D&0!eY7swq*ʋ~OaUz9V>ūa wT"v>i8{dgё|O%S@Y '^iQy\? K_]&lB_1O"B͞Fcԡz,7ΌI{`O>tHΩPʝh7 curQtg\M3ŏnkp?n0fR_En4/y$Qd~HrCYώ<+4ȚQ󕹖*!LXgr-r &Ršt@[g7=2c$Cw"2<2b ƵtۘՀVcN[T1*eؔ- _5փˡtr =J;ߩDl ʑ! 2[}M,`ĵWƴ}L6y晽ĚTj|y\qxL`3XK $1dig56]]: ?|“0(1_7ڒPMAgd/U/M,)2p\ ets_1jqQZlYv;@vќrҘ@ZUHjTFg]bqnd ^&t^_HqܼYw \6sA諿ͼ[IN _'U+YFLM0n7a<%bz4ʆ YI )bbχ4DM,jٽ{Qn)gⵏƶ!,W_ma̪ǩ|Z~q6P!`Uб41HF=eOPx_?/Ě@#98wZ8cOɫ|ݬݓs`p)_oJ뚢w8s*R'P6V$]k뿙t]hB7F~. JCrhbukOi2 Z 82eSYY-5U,cPtnќ oK|Kb:*HN=?Zqfr9巕BZS>~¡IKL++%2MU*8d$.fBdlܡsTCNrPy Ӕ7dPJx K(>{Dr;ղ?\􉌎-vF>$8@#J 制Q'c>xcb`}v%|UtN"J )DoVB/hW* _Ɓv`l(l3I m܎v_Ҥ(ƬTb6¡ .Q|؝HD?\1CEЍM9`6F5}/%;9l1Q(w}V%?qC'T 1g?Ab+(LBSU UlNP5(E"}]3}G_/;7I R)<ߤLۈ'~m#@H~`Py(B a ѵ>D7ބQV{%AZW<-H{.P7EE5ˁu s,.ZjK m/3pkUJ*0ۦL":hzT m|]]k!&ͬsn`I!| l|*O++nwed;q}¾&e>(ƳyV{I}#k!t l)F]p;ka!{GiS x©Zs*62?j:~֑ #S]o-Q)v,AaH6r`trVZkF&B(xC9 p@.ۮ)05CƘ(:Q|]OW_hZ9R7V6#h^#"̲E2KR͵aNg{E W=P?uc9VDQӧ˳ܤJ< TIf*F:W/Y}'>Ly.u\@Mw`kwfQKEc`Q"VqB8slYeQ>o[ǓΆr7O9(a0ONUXW ?+_}C?ăbGףFEqfv,i%N,ǁQā)w?R% 37ZR_qh/M 2!4gAun9 \s"l\1jyasɿ4nejURwVXtsۦKy4߯EeU7z2e-qL”yiZݐGbԴni\5y5t;1xrV[fP{炥1XvY<k%)( % QBZĐhGf? p@ffJ 3yfMD>B7_:$hwFuځ/0FNj4sejy9v_jqorLKT6O62Z~-m(&'Ķy/.6C2ד*)_<'Rv<%ZOO,]c+VR5QR(.(0u֌52]l&Ym/T$S?:E&Oq:-G2Iu+=]NfmaAVIjOCZ>׋mEEfY/g ֯HVLتlοlFB5:kȲQ:9ʤŽ8'%Ѓ;r#D/SGOpjV#X݅]Yn"x\DԢ7HO~ gݬ+At߶Po=$=<->J\ih΃@PxZ *5†7OT{ΟC ݣ~[E%?kwԵ7١:K;uUݜ3n:V/4O|LV Mg-F`7}^Rl'NsZ^|_ ȟ6ʚzc*B8zX[f4#U|mBqZNzžp+{WJ-Wˁ#Z{bD@I*5dQy]D~[AI%ĜѤ5E"GUn _}FN  Au,<ײ',|,ol ʬp1AuOٕ̙hߓ":WAGԸkto蛫VLݲDiVED xS~[Bj  Їf$‚L;/likU)o'wd^]g#v٩c*U;E$$Ub~q1kbHM_gќ;Ȫ{\QbN+;h%P䋄4\{UBG˞zִc@+b0 yL20ۃ(f{="-ų"?IW1(,@\+Zj6ߏ&R~s.kMy6OaN=9M4J͹SMĂ>d1kw*hӠy{4Z#JOb2K^HԎ恧'H ]b b7ϟ7yq 9%̯4$)\9@t *R>Y^!Ђ]~R",uR(J Ti`VTxɇrHFT9aXNNэ{+!vS._~-URc2'5)]GR?7jk3la:Jڟ4@;s>ݸ]Ǡg7Ҹ\E({i1Z%7r<4eA cn[V6v0{._21E5 hJ̙GdeE.bߴ6IT'ҝC>:/ܴ>aYYdFʻ8F+SzAwAo锉ZfFOZ7-Gslxur gFfL8Sd9I߽7FH5?VG_Ȭ׮h|@9 0X] I L,GE8 N+3/|gj%>U~*\ k 8ʜն]%#\_ Jnȣj|M>P\'JWtFZ[:nIdF)oSlhFT [oWSk^Ac7j\^ޏc—++xg.YO䠋}!\0vێv^=LCTՎiHIeoC ux۲ޭ^_wMsD߭ BsKq6&MPH@ʣd8c'*;>WTK3jUCJ%kEEpX̜\?q IUr%iwq.QBBeV?l} 5* f|BƮj#[Sv@igwNU-XZ2/KբAٸ%pN{qkU*vpg/larͭM*1l@8hGxz<0٠ˡEܛ *њ>FG]o9ex: #HQUŠN)+@(n;Kl\f4'^+-Nz]Jr @cz0ue%vB WZ AYx ;]Nř!PCSO(X < T yQ[5[gtTPH(ދtpWmI|#^pj9>+]~,30[CNKՠ='h",aMn-5 X6[pfjݡOkȸ}?0sEkHVvk1+EtJ F$ Z:L[1'EDqiHE<ƶJSJP]~qxQ݋0ȑRHCkÀ$+ğw_\Bz'= ⴨#ASru,V<-ƒMO-ʟfyCfw$a*I08`AaTUͅM Q>}/躷X@LiSN>0]x ^)Op%@պ1T!22FݓVNUu0?,y\YNϻ ut ɝ6H{)0أ D^\-.m_ u=&+[ZH2<\g!ur}v/S/"F@*)> [֔:;]'XM}ٸ{aK38?[$@6ۨRja4i$Zm ;/:ŝ8L 'EG辨7|B#F_Ѹ߭;@ ݼ}e9dZm e*(k1ĪKe[Jo{w<\'oI5n٣.;w|p#'LD1Or+F.*-zNS:`ײh,/qޣwf%߅A (<72o+>#2p ZRr(Z-@O|T@r6}ثj]%]?ѕ5gDO:UJ$u$ ݏL1 qǑbh0]<`lOtO%)f76/ Izq| '&ʜb$BT5ׂ@w&pCG&rp7b!Ogn/0+-kci9ˇa}uc^AvxC\kX(&kއb[ p] ;)J|o@4ѐ b]J-mͬqk)0]fT5]I4,Bp^s84aJO>-C2[4$߯M )>^HTY?+bV,v Y / ;ǗmDD鵨 D ٝ>`ݦ" M+hm фNM86AE vB@nW,]M0m\33*ȗ(›[H}=twjvJNR;C6FgU~;Y)['/Ojk N`; q.Zk!KO9"}]x ֔&Qy8旋 q@ceQ `J|&o^,G/cX0GP%*nema7skHzgf'Na|me5o) {|PZlB-W>@U̖譶QYt" Au*leVj$5@f5`m.Zǖ`p[9 ,m|i%TpbZ1Ć98D :}}[v2>Ff-jL RD92R5x=<' }'RPV1U ዻJgCbq?WYCl2:l9DT*sa{w@18AXB7]<#n} ֿ-ѧUށ]ox:9Coe7mt]1n*#D$[z憳1ƽN0>xAUbY:Dr;`}bGVcn2ڄ`HP5h?!nU\Oa.˜?Xq>N|.mi-J-mi5.vnM9Z %ːe _C 7?7-:+A2G:h`eѳfyLqH/`Livi{3u\?jGuBof5rcglkY  smh\{3b=<~o1=!{$R=ޅB$ɣѰ"Q`ZƑ8Akꎂ-f7GPaà6/ns tC){ rءc)K:]YS (IB$kN7_it7w_CWYZ5U$EWvpf{.T 6jqg漀'Q7{766'"lƌ8u,3a_d<'.t: |%-|~>3Rq<`sҢ_1a&*۔TŢZi@ݙ`fc+:/RXt/`̾fc?Ƌ[HZdEF< 1 hyYUlhUC =V|&cq*:K_Ky Xj:9BkAB$ټiRd$K=A ㎓aSGs <1[Ȳk+M-<ߝ@%H?b(:2(Fv7B+Fx[ɲ.r;]nI4m gi9r}T;L=NIu{i0@Xu{}K 3J $^ fV6[:ս?r6$"]xT% ^&KE>n^z-K/`E_,PwLǛ^`M|'kSYqrrКGT z iVٹHJ/tF J),pQ4#K*5o})_V@]_מM W_NUaE&S_ 8lc9^v1CnN~XԱ>;ag)xv0IŢzh3p+ڭʞjDrg 80m±%YR,%G eKǀSu?jD//&iWEAak$,gm ^$ed BY˻M(L?C]ܗ|Om|y lm(4o)M^ܡ5[ ڻXr|`ue/*SHW,f11Fwz6>s>)⨔#&q^JS:(WЬimo1=ygH.:ܚKjr\2~1ʄ3 S[ GRYnridPݑik&iـ8l1[4T<üX!Q ٢B=6Bz*"+\q'Z<)ᚗm>GKn?ze ahIĊ6,@K;gsE=q̀`2z;ϕռ6А"'lO)2 0m9X~<M[(pN-3b%a˪b^KȪd6N5ytE m9%јm$Qgol82g8¢!yw?Lo_ka3R[u5D}􌱣ܘC6 -xe<V=w2>c]ϝ2bzපyf{0oρ{EIEIߢw;r_Ap22 ȏhVE5aؖ[!y0'l;XJ꧵aX(#ha7Z*M6 Y>Zr guű $tdD*-#fn-uVԍ/۶l]3ׄ7= PC0e:hi^Oj.%V~='A'5hYjY}3+~fN(P0?:/6 ` "g_(m+ YƒµdQ>>%\Lw'R}E1:)}:DL!Q$zBiBhs,îIN)$n,j28Ұvc1N[fWI-gL|EQ"n zgN0f,M.yy͋!*(Ss:.H>8!tDl )Q@5ȇrPx+t?/ĢI-H[ق͚a-G-t ϟ=yٮ2FN` [ ؍MN?Jbr{zPԴBU 'ӉrI[Q(O{(臭g3sEMH_/tDD,6 p+6LǺ#Gkf(ރpAǩȸ WTv{x 6#t95OW- o=H# !ےF"r'f1"(sȸ}Ӗ啅 "nZz݂iqJ\Ri,Y&acqZ)44cE=$:|"FD`y_|nI5)O9<Ƒ()<ݗ"k|bR_*xwU:>=*0x0gU7m$-J ou㧼ظڣ:9 >kn7|Ytes*Yn;+7\4d)O _=ݍD_Kھ#AMSzt%ӞV}vQf>#zsJ#Mb ^k;-  'փ1XySy 眾|79Jl5z(5ރŁ iפ2DS򪥜xqUu":2qۡgT闇Ūϧ1$Bmnć_rtM%DE[t_sq&Q=QU@& 7Go2ύ0K@BtճlB[O#q[>z%+ `cQYs2V! ,V 2yZP (/溿8HQ0]%<+q+@zڣl{(ʘDxT&nt>_t$L~{W񥭾~]B.K=V;1Zp䑲]󯿵Zߕ FMUf7-&cCsbBŪ]ɓh{W˓.]ތUHh p3:rsyψeE/PI[/{4|NLT U&suI$R_Ժ2GwraYѠp{ywy)b&qvP5[OkS| }i0ڻ骰im Հ7!dڕ&q?FfOrڤ#yad 6}wIPP-h+vf̻>3}xwʱp(1'do@[RK['^R|ipu?6EEeRRN/ osp+{by` qM2'fTqϾG'-#OV xќMH2Jb$}l  01V̖+YTqa 2ǣp jp)n%<@Uv >AuGAǗ'hLc}VꟃG iP_l5Rä$-7J03%1V+{T[sڿ;}Xke8@@ǔ.kЂ}UE$LJ=G x!jxQpheX,5eC봾+lYc$ň]..b^yzJR<$\bP xz'iڗ\Yڽ`Ko^ܖwef>Ќ76'`w1"/|$G QQ!}9'*;\Ċ:j-!1grO"bDDteLF[/14dZsCe^\'f󊖢̿orY}=#I?v,-,9k "?uSA 9ZQfͷzLkq¸[nDe;0BP?(Z1nfqzl:%Ęd42tӉOs( K2NA8JόSMlv"SFϙm~|+2RVzg BkYfn; 3Uk4KEܤ܀eny'GlS&h^V6Mynhxɹ$PJBbX߳v@EZ}0⏈K Md'-TpYdLjܻCZwt%Oϒ$bb*fϙOIPo֯&KHIh=wI0!U̯T{߿ :W*r@x]"&.ED<.,zRV][a_O~f@'v 3Bun+3xt$EfA GԉQG{(Q^?{IEaT";xO1/M}qvuυQ/)/l}RbZCW,A+5- J8J zeh e5Q$54)ЮceyY`pv[ >:{V}g,^>d2|9P*:^6X?ݖa9r#:z {;WI䶈|l@2.zp: JM[,4ȖN0Oc8WS2%G[,9 tT_WFn92盯΀u41e5_gf6f ZW>Cz~6RP(6 bi}_ hr:F!Pw}'p|c]n鑖]+ïK=O)#3#8CbEa 1VSSբt~XR٭Z1;x.b$rF⧛WG[_ܙ=dw}S5jnM=ݺ5PW\w {ܛh#6=ϝ+%ׁ*FQ %BqH%3dYK\qWUYB i8ѿ%XFѡ×CDIl=O! =kN6co8_Zg=>vVWڜ '˙"sV ,eCԆ׸c);NN`3j^me3dj.şc,v(nI( Qn*-X]K̩桟Ԣ4u,Ơ]6w=\*҅hSlIˀt.v:嫰z/a5r=F~.Eߛ],2:kE&1Q<| N VdRû[-y: ro!j4zP;Mđ/K)x=5 kSeXeHx鏵TJLڬR^.mD!*{\:iy]:ʱǶaU6LNkxI\Vc\ OΘ$@A0f1KxC[GZ\bM#N=~!$n Sc}g[fK;^>gah _h@$é28iG+륄tTYG>5z@wpEͬ 2'Җn ͌@&U ӓC j.ѕTIWvP"hמQr}Ŏ#/9F8ƶy3 \j%wb镦mLӳhb\C&k%y8ä_ƀSdeoѿx|UZW8grnQ -? gP]+I85M S =qg@~یƶ– }69j$cRbaCx3j:F{^* n&c0#V>q ܨV9L!ai=`G?w3)<&{% 00/X~ކC [YS I!Riu%-S~tP k 5ca񡘢cKlR"G^{~N]u*OdF : % 9Sl\*1BT6i[ 2z ye[#sޜ3E/:}fID*@ ;97Eň1NT[ DFO.~]A!D'fT C gL\+{C!共 ˜txxY`RQq[[d~îIFԊ,̔R?(&=&TM:*=U UP CDik=Z?-o-#snuvosh̡T|[ƢWc #tic-QNu'q@`<W-!NQ$;0A]c@hn! VR]Y%/Z9g`G ~!| CFkaT3 &rn!t DƱԚM+3m'p:6+3MW=XRPG>V(7 ߌ= "19rA?{ Z8s? dTP1ʬgFK0 kDX%3snE3ܥ|W ސv^̚G-wN}cr]TKw1';Oat*0.cCP87&+}sAlQ%fX~RgVdu dA (;bgDʸ;j͡vQ:| _8H56Cy:ȏlM}|c{Ghs]^qX3tq*VtOy1>'KXDL1I\NXO$tm}>dAۙY  |Hhzc@[̥UTVDf 2[f)Z` 7pTFHHc|rD/zrK>n񐗦|nᖫwB%2[be5!jj)n;1څЪknZ鏓|/_ zڠu5Q4ޫIƺ41 ʱ }ߴ70cM"{-2TRL_\y/au6fI>` Ҝq}~Kzt*ދ{Wlͮ 8)"Dskm>,E|+jЬ,ASMIUFpwQH'8mxgwqj1oƊ] Z2-Bm%7mB^)1z/_:jh[E#1d>FG?%@^xW\w3)NytHmؚS4~ Ux0-*Is3fy#n,-a{mS(x %[/1*ZֺRN?I`.ƤpW 5SQo<o{ݲӕ .nϡs,2I&4ʄ[d?sckhs2䰊"a[}$@I9#m+ ~ibʹ0ܛ eaij`N`  4. 5 ]aWc(R'_ǧ}!o!:gdD{+q̸ub5⤡IQ " !wDe g;E#ŝˮ7m5Op6tJDPG8?U#Ȭ0S#:zLZH4KeFkե]O fUpʙ1&wovr%9oOW^Q5"N\ $Fu$UFdXM H&ȔS;T 'ECƻ! |^ܖ[_o!{Ԭ.& }~k\y@2 tĽ#pV}τ`H߷eD NK wyC^C"xq=o2SIk/T:\Oj׭( ]Ok5ȞwqQ8;66dc@F((4ϖfhbrh6$բũHy됊2F3Ieee.HKe)-}R>Ŕ2#ʬܨgm$3@ZrhM@W͸7@i˄(PF⦧kx+u&cr*H (!>Wuľ|7x7#R'\^tݪB7t+8B Ҝ]a/6& ^x{C\cӵ\z> dqv#H=žux*bڵ#i/̨-glf3!vLr)m~ޭ ܪNmh a 9i ](EVQeUD(cR>K~5N!FԠyk2K Ǩ'wioRҵH]2xncgv|Y8A}w&R:oI+1 TAB T")52)Ppm[om>Qi>w>]8H(8)6Hh > qŰY*}s_;cڞRa>Am [osyCW֫[|y[jSZ]!$-8(C|Q:xA}=6 ˾0uE\,HڴXDz4d#-n~}f鐏&/jXF0˧-dǼDm(,|?Ȁm,r$_]!%{,IEx@=E_\]ja$i l8>t98O!Su=qW6E\R& JkGj2xό> β]8N%eo<&3p'ꪦ*)K6 WE!D t勩H-k){m/#_LԆл!sZBO0qShv>lH%gx%3mk;Ң$/D YjiO)l0pm!YsHy8 Uk_|xnM"aQ NTzO iN ̳h$Љ2©@Fk  E^dXB*7= eV!Vb5xY`:)\iGtSR24WN~-0R<0*Ͷs,2B[K8Lm aåjjO'1m}>ma~x&: UV!S^J]WI9K{gɔ1e[A~yuKb>᫘h$#EP -b}F*vjY@A'hf]M+5?ʫ Hi?;vZ+bhW8M YLnk*#!_RN=Yzr2Il,7|M8N:^ڪG﹟:Z/DI#ZsB ʼ CYqș_b=Gw?u//|k;,YP -ɴ[*{D) tXL6Cp_Տ JQ'r8DH[٪Űh %d^ T\XQN 9i 颕0tJP>^tk)AlH[Z̕S£gy2VaIJud dBaFM^ޤi\5Vb}499}]ْd'oTS2y x fwaiO4n~q(˥ϽͶqO7@%#SO3Zt.?IH>K$E|,> ܡ2 CM{H矀 ttyZkIi&y|,缩:eHJza<$-(_ ᦀ ']l% #.`FH@4 PNzY۞򯲌 )"jf1W"zvkkg{9cR-1!,G@Bݕ֐B *f#u ΏK0]Hq|Goݰ6.yL_@Yx"UVq@j?gu7m% SΥKZWQ<`B7 =(.زTbowo-2mLZ.{8ڹT#-SVCo*p9c)_XDdPܾn8iPx,?/?E5T}ׄQ*UT> JK.g›k:1Lw-|kBd?)w9M`wWzyM)tOwb{{ZGItBX\Uޤ1>7]3)yb}I/ECMq,\Cp)<- n"w t2Cj*Ƈa}1{yR\hS:-c`<,:""U?}Ԗ;jV{458x.Tj}֨7ի+tA\{LKw2 3;yRd-u?=i/<:wѶ*umT<ӳ84\²۷g}~#3SE:N8gzCMwf>1~M P7&( aw+d͐ Bgj$$ IRQχaH]oY.8<߯ DZ;kr/WK? L&x4i^d^O }1JO7 `<lE_PKK&_hxY3L5zJ"~=tJ|Sڶݲ8Qofck.ʬ(ߵʺh|p!8_;b e>wnhs])9t3AUƗDISuEaڔjLr|\1(x K{wlMxf~Ydgb 6w: DpEf{WΩq©3PRf^%:ܻq*6PDòg ʰbl)R_ ELU%;axsgwYi,a `'~<ޮ];y'bV?D=lGC1اWRf(!)DM(KV H8%f*WگE8 R4"xVG/%9NTv?%EIbɤ #!P2%NBi*^WѭE/ ]-1{bvh<(H/ύ")i꥜yKǖ(HDSj!vpf58! L?EDO©gX_q[EjdꚀn( lOpK1նFz?xi{GA d ^~H(Ɵ 䅨G~UL^i 2Z7 n,f*F2ğeP̉l/=ul \ L*:+һfcUTn聗nFiEH:܎2hcjSטP6o-+rOx䭦՘쳀U$jZ`u_d;3X;P ݷ'5D57"Ox}0gźdWxo|/"C(I 5qκ=t鄨~$ʹEGZp^2iU_LCI L;fmS}pE$f@_L<7 0 | TTmC f ΟiIdhc\s۔B J ԑ7D?ֵë qnk!(7H(R] a'GPЩ RLs`T_7 q'wD= L?8rD=7핫/O[w]t H]+Kk<T_qФW_g)s%5pŢFZ]#V>5L}k U_.lu0VUsVT1-5;q3r:lB ˥〶 ?Zۋ̈́pck›SW Tؚl9ԇ[&Lf Wx8m>*3EjI#m_t.{I*";,?HZ#{u6̡hAwy#Z0gV])oن5.B+?6`V@{}ڼ7®G{VA/tفۑ0, -iu4pIɋc?*b;w9_ƗJfv ʻ[{l.@bb.}$AIGtdJ!deUd9~t#uۺ7*=ixv-$"q:ooOd 2J&^mQ(]܂ڍxQ+xBSzU^m /3vQD"/Hoj.J_3>}h@%><}b-F~]tbs:FEz4'[tA$K $yeY탄gŸ4쬩dI*mZ<ю[RC\ lAp5 [8's79 ̷hGYɸlI9.au=eL@5^cê,ߗ7kF z[ob02hڦҧУd4Pm2q:Z2y<&C ^auqhH|edD(lʃK6PX\< "Og2+,b:&zgV-j:cmI5+' =rM0q r.CTh -T2_ޮ5W5~&Bՙcm%J z36Hg,w<@ZMAxu{"##x"zL g՜Fb*XZ e!8nLY6 U `<u-&YFglksR*"ʵMs `,4#b[D_YCW9U*q{Uk~t."V5\bū!nZB[2#͛OȀ;zˎRg/UX^\JW7ʠύ)ӂy%Hɥ;/L Ϣ&^@#,PE|J,\ll˥;II# %{e3Kl {YxkKɅKR*V{F(.TKrda{;6Crz&D1xb}5_=Ffv" n̓یH(C=H>B} ps עde9x))^mI"6s?J"!sI{ ^Vg "rc1؞_ܤZ~bWWǮ`MGwe]p+sX/A`ʰi>)0ipr9ڲh籨|]%E3"V;zrR2 6ZdS=Wv C<4 顛v,kn\r(cϿrdkNη(,] Ͷ3 %8@p JY!P㷁[l@)!Hc/1/F8 㳃24v_wRzc^ႯK*<`M ] h'U4E[U3vkX@tTnM\k25%E 6 o ի`Nzkɪʁ8QԹ}Y-T[nzUB{pz<K3Tg5p)HA76eXh{H G^w>4 jMZ$ Pk e=)or9WP? B7IGgd y)r& DՅh7%j_\{oS9ʹTmNܶP4ha?P,ClcF`/Ra٥$fɮh#2fI %eLC翠aR&`? ŊLV!6 ܵuum#i:h%ԯ(hzdt*Dq:xNejN@g*ݷH2OpG࠳7Fe0e0$?qwfJ3s^I\$%ec0nb,Tm%dTwg!=po">h1B!E}>JUͿSv.>i*~sZLg`0;*&PNDf5gMl /BeAm}u7Ig"*'+5MU/}P DP`.lVˣ!&W-!/5F7p9|P /G1C'.,W43-!!X;ɍ&*M3q v(xv,|zkUS pu&ş?7{yVlJ4}`Ǣzp}#BI HHl:VwjEt9 uU.xaao_.,*ad#RF?~D_ϓ'j2*,@,3\pY8 Y|샲E'eD;1ZG-hhJ;P77YD0,Vg^z d+ *餣3qy 8yx(c>8/k Oq{h|Yg.%Yk-&TI,DŽ=M#W/+gUD(z dJ/VW4^kqi\vu9$"zCI!au,#C@YΒ.u~eQ m?;'>SɣjW7vCh| M_1cPӀJI}BN%RUA{ށd';˫n\y]Ę:cKwG&5e4`8T (CM$*D̶KxYL6D[BIvF$Ҟ3̋-v+Lʓ|~sPD=2[Ùx0}{]y2j}8Okvnξ d?AZvC~EysD KF x=m'* xƛ)UFRY!\4\6z0aƫ.&&Esʱ)pĢG WWP~>ԽT.zIyE2lY^g:-!fX}RB/*5g@fQȂV $?^A(R15"HxM2m\y0yªUbEvX@AmoU_/-[Y9ΞLhS#Ӣn^4zp}%Xя9x P :m} qW+N#ӲejW7dwxaz9 ]Tkf ќ$BjQLt!>e[叭wKI4azUʒ!kow'ˢۚ|+y4# *GE/ڸz!LzgzZ`dIsRJ:}ovbܘ߁* 5LA kQt0/yw Nӓwos35^;1`|P9h(ӟ$Z,HXCHJF/?DqN3s&Hyiu&.3I.%en!i;E)!Hc<.6p--ׄB-4'dCӡ{\`<}3I-X-^xBP1NHÄirbmaKjEKW0HOv7OI8&+5 o%MP晭]²d_r;C+ܑ6έozI@smŬmEc8$k6RB0iDB]ՅUBS٥ͩ4a"C%} P5XB8h-Y f=Or#SbPpb='\{LٵN:^ 't(ܯO ,Vl d𪥿U^1)/j&޹ /Naޡn.$!)xEɎ emc k8&E!wXdۣRko2 ekb92Lg?C=Zqҍ\3ts&|!)9L:s(bA, 3!3Sܾʸd©[} f0* !/MS&OvAp]#0wq`趮^Ivfo )/CSȁfV9iH 1$1w*  6Vcz;Å vuzna MlS'7*>m#Muj!J]Fc%C, L *Nh8O'zNpbB fJh|^I#D_EXLznJx22և$2LD_aIo5:X`ʵ3} }f3@tU[r<8CpѲmV3~Gۧa2*Y;>WXʗn; eg@" >=:/ hZSpy[ۃz )3ճEL(t5{?z%kˇBYeGv&8OOR=jlwjP1S0i@q+of]"#1\Dr2WSMnܜ8h7ODW Ff}?J-02eNed)LY%" V᎓Tw&b*Q[#(~_;8'Z+9bfw:O>6JCpdk0?Nswk{AI=LtP<7{Cֵ;FtP^ԝ4NRf,IˢB5dٕ-¶^ľFWړA 9}'`q;Q ` 'P3 LlulbȲj:d(`X%&wrT^)|Fcˣ8ϧad#UpF~aN膮c.a/'nL\#j0%S:<¶nQ?4mZB*gJkebњvb>D_z *L L"(L@t`UpU/EMjT|`!M8"Τ7j T޿O3 7neҖ_9E!YnͧboaV4(bW, Wf8Lc vz5{_!\]iA:_/NE; Tˣ#3ne'@ )lI`-6nL~TꎍbLWy6; >5L5xt2%ԏ Xjs4V{kŒQ|?샊/ `x0`\07s4xqI_]n]q9E:Z|bV§tQ'Q5mLab$lO,NZ,KGAlV~tLh Ϯ5 qH* i2uM\;M"&_ (ϔ3<_0 cv>3lG_%˞ #e5օ nO63'-% J<>QЭ/VEHi&_i?B%6@U Vgk 7ͬ-#ę~,篮VT PuAY0wŰP7 )A)!D)E"?ֈDBTv S25䢢">_[|LA3탢bۦ/[z8k^ 2]ّbPzb08;\'wqCKh^G`/yT8ۿhZ]a\^ +ҹ-Eq[.ep6#BY=7:+,}_&=i.Zxl%69jz m`k=7xɴ4]؇v$\\LSSp9 #Ӽ;Wf>Laʄ\$٪x݊i&0 û0 噎oE ŏ5L#b8;aձ:&E$HI%۫xz!q5\G?!jYjОf9Α.1;hmP4y00Ng;g-B|FOcctǨv}7Ќ^[G= iu%qHh< +4%RUg\Y^MriF.oibfej1UCCkT~M;?4DuLޱ^ lb|DBt&ifxOf;duPx="RXB?A]W `a4mWtyF @ E+1Xא0Ed۩UR>dR}%yi NAyҌN~~ ټ_hBP ]ͮ/MŪ֬\R0)~@up.|)-Wo;3pvS.Hto#|Zf|Ӗy-:k=弅!yl~HVN4LԄQSuIv?#KU'Wh5w"dmúTS#']sʆ7>D[&nS|9;dd<14w4]++8NM.c~Z\Y" Ʀf)̗DƮ"\J. +.e}e!{PZ~Hyd~K7֫O l.wjCtKivP-Q˜RxP7u `& 8q4, ̂d:^'Nڼijht~!HϠt oME*J,E"qA K6ssw)ve뗅ʡrӕ9ۇl>T\3|Vrk/$ {24KXfMtL;;>f(A(t+3B>G#2v/"!ˡ\/#eڟ 3&f PhÍsqLW̱z]lh5alF4= a5/NzjhU{% a?t1ꄸoɾ 7VR,k#3'EWv>FNjAsq05`YWۮR!7T }C7Hbs8auAYٚFrKQw٦(#wuG8l ɃQXjͽ^B#AlGj }([H(dY4oXliR:cc@0Mfׯe5awWaK7[kډ1,eL^K*rCF8JJUjS$(?E6 KukR`Zuvcp'1X#$\IGGz dڍ|5jm\ct~w歊'|Lz(ߪx2wyQ6vMGk1`PaB[,4"mF]Aca"58h;侀>:ȵrf@h}W۵r&9aҬ9Q7 enP (&*@-].ƝVAÍTV)ս$ip'/nQv8nV^ZҚ^7c@Al3ZEuqZS[*#wvgdn)da!$-Dj}z24ޤW=29=taY#EMxPF"n}![g-8;1i !咉1e s.*!QcajE))fq|<-ZKpLrx5F.6(4gIs5\TtB_ ]ֻ7cΐs\Qz>F8*.j^'n%UJYBomcN 6vGesӺ,~oXpT|B<&舺jS uyPP4^p4,),rcU+\1~T"@#$%65,@RFΩ a5sI!TH~WAȏ$8z( 3qw,N<5.Ij7cL-_W;3$H^ĭet[EN}YL|%Ná6ņJ+tQͿ qLb IoȩL{E,F[HVo1lquq`%g9|0ԭrLñÇG{/-lpTxTeլCe:_rR0wֱav)ĤXe! #lkCV|`801Mma⛚Lhծ<~\wF; NFf4`N>ʨ…ߍa8F>DU_p kh!meH^ 1v:4a u#OkRq=A35,kP/Wr|1D g$G˺KHcN}җ}.@c1!wy '?l IP_`Sњ4P c?Q*=u,l9ԃ/&%y)~iO<͗8V+YV ScUrˀWQˊ?Jb߿;~t=u [љlj: ;}97R-ų%aKj>ӫt-/wYmwAW!} ;uBk QyL[Olo:qB!#&G_jZBҟVɠW HtTj}NzB,ngOֽ郱G&O6Dư@\p}CEoPB[b<۝MTt3 !H94!g;(ˎT]x Qw>+1/Ȕ759q ɑhlfWx{W[uXjJG[*ԑ^2U z 9ǯ0(i2/:MiZS.`+׉B OX ?1T_~BCYv'M1fDrg$hA95bVMýA_v'aۈZY'"5B;\r(¢WpM ]c#(\UZ*W y T{ϐl>0`دW"6z9%Z>[ ?'n$v—DImy %kM,#gj'X:~'R% xIWz>ٵ`o{$6q{wܡ#(ǸYs:oKVTc)sآsR>`ҡ j ?!%46(6.mC|"eјb|G||$6`AÃ߯_^w-I a(X%Y;p:]2]< ;1?´XU!䀘1;e1,qv8(lyNنljyUͨPq5 lPZ Q> mJKT 4[w֘*O 9UZq(8;_yJd#E[* GPT̨`9jpFSz -296 C+*O|}/MIk,,[򳽃!6xq;Zܿ;agQ:v- 9߾XY={=w9."Fsw=>J1s)NTy#vRJFOlI"wڨ=E<_5NO8 ]6tͣ 7T%<7Gx!oV`SJ#%x?CF-9tˍ/z0.kH!Ya@S'j<Hȓ_"1C.` ]U$ۮy'nn(p- 4J_dfe(g% ).RL&&=ܘ LXۮZw"ۊ#oΧb.*u_K vX}qtI$_OR8=+vFC(uP>\~KHpF u Z 6g737hIR6;dud"O}z\$a\f޺>{ОmPcPpƛ޼c2D7$Eke9#Jͬbv |ĄP]fټ\o 0+%/M k:S{WovDqd&ЈϕIq.o}~P3xխ_:qhno@c)ZqHڠfIJ-RiSiTX|8ꃏw}}s#-TDCyw4xaOOqxg*E=kq5B0xArpb>9Ne=[<JܒbJʞ'3 Bޛ&υM/7%Z Pq>"AWg EZ)ȭ@>*gN.3OۥJ) t[yjPSR y87'8pC.q7* _Ftz qVI__f'BFk,tA5m6LR.pU},|/LTxLfۍ4b,K$ ]c#Q@ x۰?,KۻVPZj*Gm %:[߷t͡VKUj\empa:dWUx?ard%&sNI i<^1/5(boc;(Pѹ$1كCT9Ȫ :VQʞW4̰X,`vtlL/)fYjv;ǨmR(s-c\TRF*Uۯ7r/wG$9gL}b͚/td_hYȫ$=ĕĩ BXQGp8K$)eUu<62oK{ ;\ق(y%l0B 4J*'{_hRp[:oRHN)=GZ *|io-b$Zp.\<{KG<96֋ܗ<rSCp=#G(WKּbT)a?,e_;x"E!fVد4~8$ 14p>OsT^d7#⮕o I(h4o95'[k|,&՞Ӵ̴!稴ȃ|'s :MP |S}F)]`Ϋ$sE_/Mv ="#sh]W~dK#nWGd OtRNCR~ GvZ-Eub.(*ad3(@/Sr6TqW{J$ ;)ib-"-M\/3Ŝo ;+yt?>Kl5xU\27?o+F#\;)C TQH`OzUh{ng56M]t XoLK_Yr٫wtCmLZv]֕ ŒrCWB!KaJ7(tmm!3UtS- õؤ"W+-,HB9ywJHo2iMMqx\X5pc%ԆేLH%=FoV ,ڔʢsc8i_[Fxncq/)a5۷cND}/$Փ6zJ$12) >)h6^w% JS?%@7 K\3ssV"AHYIhhѫg9[&@j> 1yOaӣƏuvXꆌ@R9#H'HdrWū1݆ [>wڴqMR橎pL+^3L_* ?DWx{2fU=? @W +(3{†*RS="1DOUS!.ڥQ6(3ϕv}H+IIlϏ**m5k+r!FێvipJ$bclHEe eb +CGz 2wUF8̟)SC%;R<ΡĞ"F>tn`7Y"MLYH Xt{WV.*],i\A##MTLJrF96OE(?Le Ylz]I1o3aGP%gRC~x]ڑ3s|zbv$T1|k"E_='G=n׻86iwL: Tz1dRA A$?ѹEu $"ӟl3czt^' (V4{8GPlL;)4):<]oen:OYױdUL,I^lXDC6ndDYoORO{a⟻YE%_J;)fUxl#靥L $^հg ,)1a-_yW.L7Isl & 9)d;|i տ$lEb[ rvXFξ.iyT(1 i[cöf QɞFvYgj`"WgyRfVCcaq@D}[Wp@8ΩayMFc*<< V Ƅn?.s[)h&]̜n_@e?'d(x9D^0Fy$sUrG/r[(C7JDCqrٟ?=ٖ T`\pǟJT5j.3]@~a?cC(rԵDe׈lqc}Tp!TnMuY7P˂\,&͹MkZ.e6Pi ·˻k+(V\d? <^g;4^.VD&;֙iBuH|HK(Ji-Ԟt߹/Ꝥ[9fҨ&B*V3;7+2D#|d[A@`.)BS5\m)Pg*q`KIC=pfV%a!UToS4y'O.~+LNAJǚ6[>@KEaL9=H$}扣m(;@/-0+u&>} -/$z hG8ӡ B5?'l#L p!_PḡƙС5^:5\3syr5s*uZ&7;ZT-sZ"fY_œX!W ~D5*iU`G]4XA7ly'fJ-tlHs(EcGEà >bVN.m -!&KD@kذH1YM+ ٫]>6kY<0JC`Z!ףK'beM-)WaO!"_SJSu)s%G.1Cur]s:?opr!ΨȓI.f*/DvLh= Z^b4i eP9F a$yIf٧ϩg!yĘydt| 5$mpqqI _0z^q݁ 4;TZ K3~-{3Ơ-I-ޮ,1aiK׿{PDnܲjv!NԄPyVͰX60r:kbnԽ|Ǒc(]u і$qώagj] J02Oy˃ lP*z)XZ!Rȑ5JȆBhS7+9˂ë:7(΁Ƿ&Tqoՙ}`gtºԢ\GpzNIQиM5AG5â{Sl끲4pd3;40\44Mn;W< 3A Z]\`3!Ё|`RLNorQ!D5- *cQHi["43CJY(.wKé Et@6*g =\0R1r{ _[Na M!m FK,Gp .f1,^=kRIё\9/S <7Wq0!'01%ƵYnM] b^+X)_eQ0L|v' _ü{ ѣ(ee×$Y$ .uAbŝBAC'阈$>Ӏo7h!5y ܺA^ttES<[ JDMYdZޝ'޴\}z4p|+=iHp n[:T|Wۣ̊$[XD**G9FˁNﴘޮw% @ztQ ENJN/jÑs4]m G96;\G$I^`QIk:k%w \=g޸VI~$݋]K@> DX.^IE㰢&LDN=F|*/cE,0}L5m6vh9{""oMN?0fFd]n 09,SPC;Wn9 <ѵ|[eDnRQfWk]Ak˽} fj(|f8 s_OjLc?SeEH#d٭A+UѠP!c0k%#(rNRmS?M>a7!X֠3ψxfcM+]u}֌^I0gv m6&YJPa(i]`>UI)Z\x$sճ Itr9Θ>LOk;܈<}E,ef;#cT\ܿi-ij|i+g]3NRuIw"@ "2!=q&&Ԏ i>I[ʱJK0R88)(u&z:vab l8] W{t*o:MIWǼmSC|s([XlM*wo7,wެ^F`VM,j>]&d;=_q)=hv7` F$6ßt+<fM&kqzL6Uff [:Ꭳ0ja2vCtJ,/])UAWeOۆyX2ij&FPQzVu9|wT`il ^:cSQGś( ӷHlj(]"sKH4)EͮKq{4dsk)`F)/VEQ@c&V5v-PlXqɥ%g=6bCǬ6N=#dH1`%@ }M&*xK Yh B[d{9p($dQߗTƫF@r{n^7o_ጟ(FE}u~=F!Q0Sa;-mJ|9H췿+8",߫WU#F {jq>m2w Ҳad7;:+/mMnŊ\1Q&.աUD2rҜTy ]>aM<{QGrXM)7 tN7%I8t)&| ljC܅Lw2A~?5`lLMM(qsw ST&!ydvf=C _{6'=:"+'`\lC6o AȵxW9=oӭPcۏ8avנ ExF KO@=dΩk|Ԁ׹\y/LV"2m!S aWyDJ7Wtp ,bxTm,oQO Arҧ)X57y+b2ϕ29~U[*1;:*.dCO8`lK{tEޭr?oOKvBfZ_@oEGCa.`Ur*LHYptb8RGn8"m(XEwKoCQ.{ԛyB[" @v\Lp39w ȟTA@ӯ:7-˧Ct0?mT۟$E0+-8=l)fWRa9Õ᥿kk=*<a'J GD8:$qz# ԋΚջZwab#*>m騹 pp\~nOF˩雊WܾBzOu[G@$oc ER6PLvJIO͒''b@'bfte"1U&zy0 އ=ń ㈭,ڐ#cO72`yıUDA(?Oz(+;eϷg\q ģI~h . hZ)8WH"UuZ篳ِN=,N1jn72aV с_.)i vE6NQ ݎHhÀ d\+fzZ>c[<\J$_NLw'M#i7'M-@ZN[ ƴ[uޅ@$ZxܵfAOQ alӾ 5فq֏A"\#s%y}$Y?V1L>20@&3 Ha#yPKwO"jdסM/50"7C2\RY4~<7EI=^FTީ O*f7aP1ƣɼR&B|gn6,ܐ@l[*I݅-3_鼯*aSpΘTuZ|J%YLgx/˫d.}Up2o-Хܳ k`R !O!"zGR^F<NJ̇hwPw}xb6%I ` ZABOܶ i'x6Ni 䣶(Ou9Qܞޓ)PXAm:?}+#HBA7pxWުW[J% YN %1DMt#C gG|JStA>&OL7vI 3UllDTv5 7Sk:?{=/b:Z(t;)Gct}Yjѓ*t1^ٹOBDw_?ǜ$ysEQO`bSje{ xzWڜ))@NjvIO`~s Z\诰Y&I_ꀿ␽4IUTƫyJvj(fs&qPƿp>e#REyr'0<6Q!+l{Nfst3KbhI0P6i Ե Y҈* QQg>ZeCbxewZُgBLD M+cs21ѐybDV~eKϞMeA;JĠ-@CkM6)L웼kܶ0&oFtn<۾Zc(_?un~a=K+$s*ҿF!I:y\*sDdnoo+ Ch)k=56t-Be m7 ZZR{U):¼ itK+dOЀrǽMeC\ ]f e<~E֛jfNp>"ƶ&V0 h}NǨ|,R`I6g` |e_J^4TDdIO;3c~~kjRRŐ<^ xniIV<88>}Ȥ&qn4JS3<'q;1 /PGDMz@$1, `#pI G.(`6"^+@~@++6;>=ӯ>a2@d?6I0n9Sɱ$g? -37)k8ĶZmeq-ˁFWY"-?JY ߘ6xoI8K}/yLTGe6<$D4ۗ35lW3FSF5J888n ]38ԉHkӬ!(M:hC\ oy K{MȤW5*5Gaч˄Q?f:͙k21&n͉KbD7a-=VXTNF!!`(m/z,kNޮa:yhiMOØOdʱ̲ ѹy6A7 vYzIy߷D>׫FbV|K&>V.y]ɹu{A5Yt=ɗ 'ēwsjazu*.KЙ1 7fO1VrZ8YHcs3A.qMD=7Dm'0iG2 ؄͕3X蚰ʷo{dc4l@hl}2w([S>ZAڟh a%K=3,&- NYfH 8.󧑳Dh. `Tޔ4IN״?.l9kS_qLUTy:07FXklT6 >i2Œψ*ԖcHۍhP]3i `TM1 #9o=ĮC%{SfJ?f= vY]{?NoI!:}.O?֋4%LM/g/G 6F3> 7<=o@o?F71Ouiv 'W5%xZ &q`q+uWP̰_,1c_Yl|;8jr s!::~Ws4$rሗ CcJfޯ0ŇUX R_;Z’KeeԘx$H̙, \f"k,gO3U][Nڑ,5+C]F;5-zN"}ʅª!GM =Xq?ӌ63, d;x- |4]-6MԸxHȲ?rv)skU 8![Jyt Nm4@c~lУ!z^5hi><:KҁMU I::ClxEVf$A!UU!pyBxޏ$ϜnL $|z]T" #/zGM/xͣ8m-qiV+ke9DmECDmCqǰbP 2 YD@S1ظ?ƟF|67$UJSWHr?ewe}aB05';@In72b5>t``_H=XN?rt[p JDݤWe/06C}WFC8|B|Qvio~S,n#  ÌE,] X䶠GW.t; ..8{\U&3Xe*sI;@3UpV)KVCa >Ct ȅAYYh?Νar/JH<K4wIlݫ;ډ:$9cիTsd?YJ PB9 9<7?DjbnUSY$"6F\Ԣ`$f 0(7Sϓ2fAf%3SpʯZt:L7GC6d\rߑ`7jQOlTJ$jWۺils blmQ'y<S ea!ZN`l yhH0=M9q9Aٷ(czNȺ+=7 [dHpnSc ]q Pv/K4Ӵ q³EC Z LD9uv~A p"e<'QgM[\t ?gxʟ9^aRkδe2iwT Aܟ腷(%̻Ýbw?G:؃?h4/;-$P6*gzlwy1 2wrDge71yOR_gPV4ߡqAvׄ"%>5)fCE( 46 yp/{.Ye:ur@ *[C~|1b"a= cc8gq^$zMN5zd-RLx35?ӫ)GrzzuI夗BFz۫>}I Wt։`M1DUSR`9Ҷǭ+(9֙#4ܨ{?%yZjW=2 v RJ%^UeQq! V&dtll/_tiBHސ^`܃^FaR2K<wl_i齛 ][z=Amơ꽪UeC'%uq*gcՄd- ؊Pb feVlaD]%w <&kaIo B}2D-E=2ye^ ͕F xVyHgiMUYo8e"Sp{yNOAC^a]-lT/]GP9x_g}_㝜jb}/۽B%@'(P? n ^w|=z_8mf*@O+, &gھVqY( x10;&b@ 1Ҩc l sjH9H.)ŤL>uǯsFְH^eHz Z'Ey5ś= \Z jO9 $B4Dl/aqP{5Y 2 YɾuxHڍth%IzsmNUaag+}rVpg#وrp㍷dz: Gc`҂wė-m=Eu]>J^d|+%r2Z7IPy'Mp7KlA~E|$kyT1ř)tiXzEovj =fLNp*-d3Sk1D}Uƥ ՄLNJ7˼Hg,8I0IO&g(5/t ![D_^i'!.6hceFfі1? ѩ}Fwԏ<6\Ϟ==ϻ)޳"Qx9nyߓ {O=ezYob7UcP)`{>fbZspqbKrw>kP0(,Л//n3"p\ "g~3C m5"@PgEADi2 "t Ap];l%\i;f;{ "}(m/{gDQ)5jQR`XРPf2WGh++@4\U r&dnt }5,1"3>/a܁":]eHRJgCC.P IN>,of?,vpЈRC\ٸbI|>}5ܒUGiɘA6觤 }cLWy=v٩1R͵_> ӄ %fA<ۜ]8Ԑw%<܁C. rp.ݼcpG;6<KȺ\ |KXNQic0 \fh.Af%!?^I-~kzMx;j>'V?1ehDy ӂߝn9Ȗ{W~ZMgX(E;3Z+}X h@,. t5%yL$sdko-M]߇f 'ϘdpW_3ߟZi;Jmhϋ` QɸB[s>61^oZ#?\B8H=qqҏd掷sFUΩYc q`܅U[LaI7 +E<+t3>ձBVb~l~> +EqE w+@MoQ;Q^1$|HvE5%[7Ϛ*aЦ$TBiXִ,5@~qZ=H g$͓!;z&yn6=3{?t?AZw02dCت κӑU;5#YsXꆤ؍Y_>ł fRQH8oAEmdhGn]ec "V6T# YSmjoA%33?cSXXMU\MR7JCtkHkPzvh7O:!Oz~1gG$=4̬Z-b%4+6EGO &xQ>gԅ[ 2L$wG|w_,VLjs9 OAg;M&7}z\roM:R։\ii< nidfj>wD)6yN2hDMT@#t\o\aI&8jmFdy8|ۊMs}$yg8|M * H>c1OӈVNbc*s" Y 1>Zj=ze9yMUrl~OK6 9$X|_[9&NnyvlM5A:jMeGޛwPu 2>Չw_L*lūd0 n3 ~ W}─m7,*}`2,@xBa} 6z l]Ξ,W*jWԴil}ӕh=t<{tDFcګ:v_s7kN:#*|›ÕZhK%xBxmXW:DWdc,dPK4@lHO`K(C0+(&I^>~7ugk˅mƛm*-HB5f2fp qII@w1s+g8_mPtޯFyxHNA!ˆC`=^.y9VˇSḎۅe5!wuQXW ea& PxxFe;VzGfTe VqD7: tڼ6Q,R+LB^o dhU%l|<~q BB>JQv"CM]z;CֻiFF̊ @>N +^ot1F| 0{cQBS-]TG =0h\);`S?ȟ4,;V3ovlh>gy 8틶L- 'ϝӡHP̧F ,_~so.lH^yq*KKj}yRuUlQ2< K>a#ƌf~ oG ЎC1R8p0DΠH#r 5#` w %}Pto%NbEKgPu7@[[O$2 >.^uQnROAoDMg ?ޏ~Q?c| +c9:!hm >`k 0 ?WRpq qi. C7Jkiw 3GMO*O[:f^^̉SV(u.KfdakKs>5fF'%R| ȟA^ޫ蝻j?6_W ОCE=ue ykCb¢uuZQY']>µ~O [KJn[~vx DŽunrؽaM/Gެm]$_.m*(.mZ[NJmG~Ewh.DЯ͹~ğ97kf`kr*V@HmmHmbvD.c݇ˀzT5 ~\8 i] {Ys"Q[wҦ2oTCRwD\k^;u|;>${I[{)NILd[@kqԱw}sFi6?;ǁ:pD 8,&3]v' [ۖ*unղ-$ bm&xW#/^hC W0_/1a`ŋVEWi89akE7ny)?>e#BzؤA!ȸM~C w4 f3χ w0);f=\ }[.Fhͨ)|G% e؆lŢjV! 1Ol[=/"wk}8;ڔoJs+Iǵ%t+U5dfŻByc`E59U-K܊}wO6[ɥuGap"gkU-@`}/dzk%\izVMԕ7򥬰Ġ/rjp)2hcaU]{u/836*Q 8X8"I|Y0>2-kGw7E x$Bu)Ԏ?zsi+OC<<í$iPH|74*D{Х9ȋfKE]YᎼAݦu1X(ÍVާԐjyzi4tfv$(\a2˙60DyC^^зp@yHn³_;}R5 Y?ȍT\`h4E8q,+k(^sjs_HJ{3aGKj>(-j>PJdT8U!]9Jtd& P`#*YtG6.Mymy{&J&l4%˕Y=:#-_ZAh*NpXS+8QW=wI4+um]gZIE)s}C8p )„8t6*[󴲃dQ iSU/w.}C.tiT*!KI j]A:UT|-:5aUJж]dӓz 63Y+#x KKj's.OD410E\FM'BrDb H/)LrՄNۃ0M+Dd'`kN͂ mV׷xj2 }Ykl\JPckfW[D-7=qJ'͇"ȡ ,,j?:Tq:H]>H:;FZΦ:1hdcB p/ ctʹvAah;DJdoi\(~G[Cy>_:I]$4Gr }nt Snd7'Q=SC8F}zvv@#x)1l=V bslpsK"K+{/=*) ,M%=x e%ya,#?L>xn3kK$]( "Wgl,"F'+UK\}xw׏|ZU* RJls1]}FcJm|)4ͭ_7"M#x͔oS5\ Hg,8_ЭA[\\͘IdRx0|CM%IĢH}6w4|&xIfЀ^,*ښFeJvF*)x38 f+X8 pv숓eD5yNt~ <4S4@? "&e{zj,,S[G xӀ>&Ja1PBͧb9% 2 ԧ5w^EqL aU. Q;ZoiL/`اFjsn sگz:$MV@ l5w^mp(<o MrnU0:`C}7 T7y&mf[Пs\ڝm#-ۋFYٗha笀D1pO"h[\ rw xPtc`7S2{ܫ]G }Ӻ =4zOS V~-hyI57 "o,[8@o%.:I;{,AI )QΎ8nE࣍p}ۡ/5 #p 15BJyt R - }8jvRQTx,:7]9kvZVd\?xڦ=i:R O~B_TatGJ6P }W)HRJ|^"fpOt  }lVWޤ2θ^WiaX) d{R"n >mM(dP /]6aVU,wQ(#IUǼD#eu}9?0&(:`Q"(v] .W[pqçM[ޚnKW6N+sv=W9%f^*UE!l`Q mMY3>4yzvLnq7*AȉǗ& i\o=ŁO )&2IdQkAIϯnBP՛PIb΋(mt0G^#ScTt}2$`N^\4ʧ>!P[HT$'n3!..\jb{UkPqY"3p.T;P)Kڂ0F4UitK'uyv~(/Mr 25GX>(Vacz9wl)c_cV`v Z}@,4!>=liFLb֌QG|%,N"MAYOWuV?Lس[ LO mBY:n5yM}#:ut_U7ޫvxnzmv;NlQ!G:=[Pb 5'~{%J{.]>3636=VL.:9r"v߀x3_9TqψVCѿ--X9dI8Eew.>';ĎDfG`.κ_Fg0;A؝]oT9 hsM)AjML: 0RmHҪϐ1F%ϮkAHDz3:mDYI70ɄZ(8r$ƍ9&rюpKsSUeN%KDS[&bR]N2/sG<~ 9Fm$!tj%C%e?s]zb JZqس&:z(Æz ORUibӔ&hSjhDYK{%S9~R׻TPpzjEl7Yh|ܮ y3PI" ߚyW0@H|:v@Ev`R8Zjc"k]4|%QX`ϙ16Gx#;A>Q,6%jr}(a7`l/t0bJK^gm!g+hQGQUs\,|@&=PPDb6ˢKE&__=jF&4Dl)\.; 8)őЛE$zSn {BqW.i7d|Z2=ts[GV$>~3Yn= ErD(I0-GP,~C ծ/k7WX%-\{ۯ9Ǿj#_lh*NEE9T~El1cctjyƚqyԥZpݑAx20H-u I_I' r.W)e٧c^,~̗bA|?*,͏;"(pϦȚ!?]DFBd3Gv3>sC2)j>Iˋ%eAjzy_Q{ǖw /&l2}4)T?"T)hM+}=M鹒٣;D;v0{bPMeKEDwHW_%$da&ׁNZ_KG V8I? tB;,+]}F&cN,L 3k޼U=[%H؄3vu>AE27;^]3oN>n#ѻ{ uzWFZO~C_ê"[:oNf^GY&Ͽt{!B-=ߋzU{^tL; L'J]X-V\=be8oy<vf_ˇpq~Vxqxi866,M|>?VԾtEV)GmMCq d+tEkCKNMfbĺڳ[ .?Yvv=7|v8i|M-ɦw GO6w& J~]VAa( 8<Wcr:Svśeu/%P]DcS(p]kSiK>F5@0wWRgD)wJ,1W=ȱ 6-!a')bڧ.$LK[|¸LN/'4nBY Wrj~62#:S9L%ީUյ]`ԁN") d%W.4Y,mP;7xOo ti$&\y".$t&+|pJ;tD,`@sΪ;oӱnq F%^$8x[X>]yn'fOR`9FC.*krS H ڳsn4,dZ`/PلS ]LKд5GQ:fep;"bDWe^&4gOQѝ0i&$ڬm>Pnt+G@[2fq䰆4hH _(_;WJ`:ӈ*T V0ʮ!bn*GNȹH0k|OE=y*_q -R!a $rKa# g[ Xlզ^I>ߥYSp<F9W {` YkTJew0#r7M2ݐo#tA)aηfp= .}VC8֩5 mA!k ̧mt%JXi( '"u>1.[,Xaf7#9d WХMspvOBN-SrX#}#N |ʯ.ƕ<_]|~Iy4WZ<ߓr̢]ӶJRvvkY{f|M6_Cu i&yZ51}SsTG>H+7!}b%YSы'8RzƺiQKhxDľw4 aΤdP`A#,iŹ#Xt9)SxKu#ʺgĤѿR'pgb:<"dvՒJ0xZRp[lve*Xz Z%r J  ].X<@x덊N?2Lo̲8ص8ٙ<}pij/Pػ_S֬ Ĉm!m{qoFʊP8G%vHX+vmSKm}6eDtI+oM, ܼF6d7YGWw|8|I~kO&fp^&T Vsk7lIOԹVI5H&i6RPgm퓢q$nLI*nuhsY;ZJGh(lxhآ.G//R$/-MGʷn 07Y;!'dtoE!C3#}r&*P-V,|p)]!= W[GKl5\,GKiT(P5Jh@<^T~LJuO *yyEj#VTJEV D 'PTv4(y#/U-և(ԑ,BtB&qp:xt>51kڹA'7M?huS+kZ)9pOUMXD4mM ̳g+o`}_|VsjL`ymD&kWZm #Ty5"ym%z:+gDInI4Y[\H8DD0.#YSJ#0sCJryF:= Gܺuz! 3[=~߫o鿗8egЇ ZNX 2tUf$3HtK3YV/)8X!s !.vMωQY˗vH}׭Y=6 >ܙMbv]}hH0QRۖ(j. 9!{Y0gXXP7Mo372-5R"g\me(ihO*szGh)nՃWԢ(akWw!ƁCq"sPrSf\3c,5"8JxmM_Z&j!+J "Zw8c4)ÏQ%= Z' ]1Vσ:M˚ϒĵx˩h#n1H8I(٩cJ? w oXQ|::EԲ<t!Bb<QNwW&S8Iy֬vqr…PZOz8+ Ol#)r|PAǠ9 ?ּ场W}Pq:'a3=Q[O|bx2 tS\*既@zYf+NDԶ xw-x-u()_LF) t6 LUљQWv҇dxV<"D0 4+Y/l( y]}ٹC،%àund5|V2,@NU\0?+13ng{czƣ$3vtnsplCRi9&LRM"jûcl|rn-J)֙7SbǮ@d\Lv!%+9h3B gZQ2t{!U^cC5Wbh hV1=$5)ba^`zi9ރA9W8A[5t9K`Ӄ[Z*F{(Vlb cJy*';?G _Baf;K`eC44}aFlIK] \={X_M/.I*R]z*9!ƨ,{Ƒ`X 5-taxxD_(5B( ѦrS UC"loYL}ؠlEUtH6nΕ'Ijw-rl$R[ĽI`徰ÆFᱻafHn*fmI%¸b6cn:iFkkU !}gX0+1%z5]QXMx@ckͧo!J2}e0+;7.,W|V :N&uQaaW5MJkȂ$O+CjcŽ [']b`Y=.~iHɬ$ۘEBxP0@'eU_ zN'N~$COВ~3!>oZ7/H2/cFYM/qht_0p{ST",T$l A\sIb".Gƹ1'5YV!Acv܁PHl4͜koOs-8aI\tpI5&(1,:prh}@b=X֫!xTaD ju@TDp2^v$~,&}j^+T:{cQ( b2+j"RYf<#"x`d5:-oTnTZ ;f'NM-,W2M=i D!R]+bЌd 2_yf@t ,k .)4xWazL\~=6mr +c\Q.E\aжLO"bto6dϳ vRx*WaTã Wn'^&~>n&=p>_E Pl>j0.0#h@[\-ss-Mha@D=?H=|>4F= Ge?|  Hu0+e]F{Mx}𿤠!ΒG$YHmN@g6[Hx?|}xd&5,U. /b9uI >/pzYJs$WwUMUKh lƛsy)L[Lⳙ*bBO҂S`~EioT,O0~xj]/!;^J8`cO/F<^B_Ի=;8G"? ::KR:JrzBG%:hץl3N J;&|bDj%Y\^v>6 EA CnOHo&G뮂J.Ke_- (*c`ݟ!km]\55ff!6wݺ=@+W?Kٚv'ݣ<*Vm˟CP$^5wy`V^URl~ヂx_jpʼhIZH2G,ćP[ЈHgpHXB\A9GAQ˫dn5oW8dyGKDm!\zUT6w ~+CoD *9ɂƉ`<$~؜T̽YJWtIKc%ćkFG,ήRk`젮F%i!q*7y3Ji2SI;W#NfgPwv٣N!7 jriD%A$/G,:O ^ڝdZ ^[I)`S)-!p ׳GulAJK.XjZl,~\8-p9Z 7ևFG^BOxru &p~bc؆oF UCwu`0-/7AI28:fӨ08jV:o|ytw&-A="]}R€P ]/Ӷ5YfK |E(LD͋磗$KMmp*<P/Oyw+Dӓ;kgafMuT?or5q[Lv xQı.r0͍Cmh7b뛋E=.:[yxLM`4+Hu$dp%~+XVHhC "1EׇR&a%~`/)}2z~,2ǙMe"$Xe6U}8H|#Q 9IoӡSzЌӞ@Ȉѹԗv '.#3([H^4'\+K"|@ǯKxXPm[50 Ϟr܀r$CuڠMХ4{z#Yrݖh[f{xZ5$r\Dɶb*:G o0>6frhBiwMՋBKM 7Ht6P}76QOt۽5-N͂3!Iv#V C)0L&|1FWUeu6UIClo**I2~$42#Bӈxzw CW<OGk7 p8 ѰW/^ x3ٖl^p ٦>U^hD<5u?ެ}cKEr3V3:e"2\7\zMBDٮzG;LLo,4{$#fEN<E7-:rB"YӮl=gr æ ja$ɭBINL(&r,"DؗFffuHΩ/38ʊWr3;K4c:>_G(mhNpfEWDX_a2 Z&WOfxpKZ3+$"|/5sW#N0N/RsUdqsÀ*ULokZS y,\g~u?  :9qt-6pl3zfn]{ A._83M&? 4d27X[Me^K-h&@dmoVGKkEpPW-H6HT\qtnl˪zT`grN5ܟ!Db mru֥bK M҄%s]isi7,qs҉+K܌uB{uH'%s2k,Ư}LPJocY քS<>!M$q2xY(PwY2 r+}gҺt&H?@ uZ _9Tǘytd߮Yr0!RtA(-~.uQcxXY.ӭ7&{e٦cMXWohH߀Yɜp;T1mtC  h9CBPI^QUJaC>Г2Q (Č L2LhQG} -@k,r z& H8@l|x&An[?HC[1܇uCgњ2҇ -/%yEOWWKHNcz#?K}_#fu{iDhG1QsNg[{Zfr4ޢGx 2 jPk+\?(Z2oo"rXx{)eg(C,w738-R (K3^LCu旱3MޑQ,n8c_ON66BIL`+",~0tꥌZn_玔;PAvNȪy?K$N;̓jcSJAAA/\t?cA[䔜!vLl. yx!gf \VIvѕ@-;S)\à "Ċ*rys,uWD܌kuh'd }in{d!TjTXX+&v&_| ;;(:}!_)|>(w:5u~- L"Ho k sˑx=D_ͅlz}V"0"B(6'9e{T|OEĹ8{>\R0zFk  ,j(\sɷ{gSʚEÙ#<6ټzIYF;93׈XnYud# Ҫ$z-ǾOt+- B:S/7U,$%"W.pl:bCufl ` %OQoO,}j"A}/#ˊNnZo?=S^EsBmXZFe~ '~_*0!|C tIOco*5`I&ayoB9oF$9_LUaUAnʎYB ߥ:)Klb@\'GC3Fڳ,1w]҄;e1;s$oj7,TPwMWL#hTU䔘-[GǑ ;sN   7)s` 55't[ĝTPeIa4lm'm?;jF߱[6jv6\#'K,;ql 3zVYCI] jP[u5,Div⟪l_N ui#fc6ٞ[EbmCku:w; ' t='aSGĄ.Ji]]~B,D,MTi P?Tq#~<9Շ ݙ5WM7슃K]NT/$&)vicvy_PR*Ϝ)]Ǜ)k3r)>D0,6YNHvH!z\fvFcpzIm{ŔLЕ˭IPH}3-w3"oIG^K4$;_3k_%(ZA>ǭBM鰜0븁A睁!B]q$Q,g TBbS6]Q˜@VDʺ8 T?Nk9Ps,pR{=*D5ϳ ]w͵49=W_JNXR v ʅ,BJD-P=6!/%*/Ȳi|@Ulc6e.[3 .C(_=PFM恄Q W*ڵ!HP7xѕLol`4%.1%NF_k .o\U*aP^^ZU{xO<x)N,*hId'mAK˖fY[iϢăgq Gt%N 7FOM:pd[W W܏ 0ZvC6@eow[TBԇoT~`,c?{;J`#|]Sy.eaj^(?%/%5넇U1W;ƃ?uίTeӡ %*Pd^4٪(;QJU"Lߡg07=͠KLBCQrbXn-ZFn"ANhdEȽgi'NPT.d@NHjJ+ ;ŏU(Gi.U*fYY Pgc 5sc4i@.?ǶZܛŽ앣Zq>l'JaF??g,Dut\y)sm=5:qyhLJ. Kr%;a3$ 5i&Y+(m/Mvo I6,ّQJ"I!za]j3+A)JvLձ; RWgϡذC^5p{&fNC2pK##z|=l,Gl^HCD{KĻ {Bm6AծgɘUm;Qccƀ JJPbw{y5<m9'0w6P-bnzKcg좑[@G߬^P.dp/È'%uSE/۽:cFʅeR45J{ .&9W:$(EF)Y)h p?JPxOvy*gۋld7o&PC`۰籗_iWm8ߖ.19". 6!uM'tpo;kM PNQ$=28_6s>.g)ܤ3q]G롊NqcwsE6Az|1 Ɂm}ANkDfF`.$)dN(y5Ԕy31L;K2vG)ljݷ պ/!-Y в!Lxr%JCA .5оGB20K!a('~(E>hiR$S,w  S _7ƌ+py5S"'IF[\/t6S4lK,ș# ~@~oW Jov>nPԻKS&:%|\iJށre** S:B2$c)Ye;@KyvI2`e^n9&^;Rs4F :)h4fV2wf$TA%ܶ|7c+>pEwJ8±/7\ {0ڶkTVq3xy8(_s`-XM#gɲ%@’FEk1q_lJ"v=ZglZ՛*s`zf}-94R|w Kx+v- ROҚ9+ivds/m2+e9r4ob"F:ŷzc % RHu_=2L~[r 0 7բ3{BLs9drbވkٝ/Hh ARjŷ[@}\)Rd >c)~NKBQ*l *Oj{6k 2;m+QQ`gusvľ$~r= v #:N UO4~v>]å]mקyR-^hZ`ߖNG+CL#nʼ# ] ǭ(%Hbjf^b(c5 qC_a=LRNw7cqB; lH\Ei$f ^ -HD~<dxhVP;4Za)C¼K!p[T#rDK}Fu>dM2WEOf"w7/ҝ#c)e6=sPSQ:c&m`KU[W2z=8UȑSd9Y^sEqAUe:DY ʂ- XAltAU(ɝ4P/uDfU!yiYJs+k#I&Wҵy7xHff;H@Vr(& A|np0y,O-/e)ݚ%vAEoY!q'T=[Ip+S8Q|'= }j'lX 'cƲwwO+u]?ORm+:..!)d%-C/ڭ#4oGx,\D,FmQdˈ *$.hm*y5IvNdRLm%iqV΂:n7)pN ZUhI0=٠:T?ɂ~Ge$Ҿߜ48!*{3i9o(C.0bA_r"v/j]cV+h3.V-ҟ/heNbY'o+i3WLBܲG چ؏s5 7_7L>hhvqbU&T=HY ~vUL @؛_>z4ħX`[Q`]VhەShW Pm=\w[l:,{ hT.3^/s{CvO;/+!D7v7F|Kd#j9R ?϶Ma>;ձGX4b6yED x?VURmbA9  Ɔww>ӛWY~[OX@:6b'܏Gt:5]\V}aD$[JU8AYz_ {K$&[8bW1k\;"%)@hiK,[ơrpr3@O6e&s* k#" @P8l68B[bz`vte+~2e;x|&9a zһhOgDOId,WTK|(-6/cH%kɚ !!+:zf%vYkk=qX.9ƌc%hR/p0Tֈ[_,s'9NԷ[v K&zJP^/cSU&~1s$hՊqRЛr*QqtniANSdLrQ5-Ř:ҡ~:U+z/@3¸' *%pDu!%2#)j9JkrwIV 0Wr+˱9-;cX2 4N{Cc1ޟ;Em. 6jЇ $pyq+bUڅM$YMq}{iZN.je[A0kRaNIfMlZSi ն@k&tC:`Mjatܻ$؂3ZKp N9GFG@YfvqP:.oުp.~vh[\+=`6CLY=E%4։" 53j jҒ׃G屮Mɴ uߖkhUv9T& & BjlТB,̃)f+WC29G}3Ĕx8RN{94Dnzp%?=>.h!қr!|u]K}&L73TV~xW1$G s(16bJ$kLT)>Rz<6(͔YK%d\ *$ݿ. AAKJ,@Q|Aa|t\}Zcu;_}( .&MulbR"da@cڭlF 3 gIc%A[ilZdz_R 19r,s>#^xƓ %fD.4Q 4a0NVS0p}bӞ`@q"Y!"u]~HAu>:$-uYƶuwCU^0r Fԙ zpOS:nDic<%tx"C)_U%?x? }o; PFisU{r ҍTM6'߾B#=ohjZH D2\3*ÑPE{2C4[ڇBG n^00Uh/@񈖘 V)ynygߒ6O\N}/3dS Ê1T'0Z*&0q^%"*&KMsч"b_{%:elJEu*4q}`VE%Zu&t2fE` IYV)&D%T_#!-%:>fJBg<ΥRJ.=oܭ§ҘW9o/c ;byTkQ.Fp7^X¥Wך4Xvo`O|"hk7_zRnĴâƂ>}k?{G Tp!F4q]䮋ZASޫBpzRXWj|_{Tn`o\ҩ:Q *۾ʏKq1H]ΌA,ڬ.ۼlr|qN ">FE\3"?ୗQ"2 ik ciJܜv*N3͢LCZ!'S`I"`G@7Q#rk4pgys$'ld0' \&9 n S$`ۜe0 ,v`A.Uc̆ad mۧn?nfawoSۅMμJ#p[k}DZ;otםSbGuT ]t]R*p^'_+c`l__ht!쪽THFۣ7w JwWc-bIgpbi[1ЭNaPy7mL+WQ H<1ѵb5xINUf<}N@t%Y5ZH|*eb^nCd.d IۈjV`\ɑʛ(ֽ,W^-|U*ʬW:f$2KO̓Ø}- K)v:]쌠6\םjG0 Fd=ÔH/4{_J߽${Vn# .+9)]Yg>UQiM >g\(0 }LktCqhbmC( p>QiU5 η[w뮲WF:mȦ0K}# 97A%nH6є-I}(0mJ+({F"'SJW2һ;VÂY2RD2 wKL»HFhӜmZ*GGƣ s0{ ~ĭOtXoޤDd>hŕ<7K|P @N) n#pSDHH*浝MeFN}2ҽU<P j9ٱ:,2:b:5r<%EEx(ܻ <ߒ4X%7`WI XWvӎ>a3Ϙ'qZ!u+Q,b3Qu3 07~(l+v%Njeҟj{7 AaHq/8! }l)@XX•~-aAq M gM;dՠIU%/Px)|zO626ӿy y7b f*r|0}<ڥv^TiՒ4CRd{=]͛9Pf6ܢ2nBti[ρqImP8DBLJ8a4mA] VF2X"Eޱya'Ԉ?n9g{1i#2!13s팜gs 5X/5.W_IݶovK˛D?A1SE?}0ApXx9p 0j;ybf׍i Y}{xdĝ拭]|KpP =/)T6˺$1ϳ3I㦌("y3pYmԻ9?8o7TW.{e=g5V1BJԼ[ t-Ka &ྠ)|tOI_-'eN2|U285hF35j3oܒoQ>CWG]o.vyն\5u?p ֔aLmK)PцA? lg/'iz}(i7}&vۈ 1EzZt̐ѹ-K#7bN1}%F5W9Kw|.1!p7<ėoXUBA6U"OifGTSC[kGG%[.Oۤv_4َ+MiײRҼCɨE 6l)Tj֢YI#-#t!*%'c~d}&T<ۤ +y(׻AAg~=Ac),T2{.[Ѳ_t[R4OخT5ךQy{:a 2*]Ob5&2l[T䒻O`^nf]bSU"lǺo%c'2#V6pGlیfιQʈ\6 Nlp:"j> )bYXoVmD MbJP#ފBmU2{{ѓZȓ?ai=Q8VځV=е-}t_xzW!mf㎤ތMXf_.E)li {g&AqeV8Fi3?΢5Ge$^#hy瀣T7@gkRtDѾaMH<3^({"H$+0&>Jh.ov&Ë^V^Oќu-f?x hs{naPQӂ7lF4Bw 3d8A6`,\9%F_z>+nke<7ogXV_IB8݊P;hkGֲGn')7 YIOJg7 :UFဈa3=,k߱Ӆ[ tύw>)rb] xQEg\J,M˔ +mBzcYvg sj֒:]^u&x#f#L.vW_sJ'@'(6?AZL̀2Ϋhu MW'zJ(8#"=KV1yX$dg$?l :;aq7^%Zpb QWwNOS9Z#Oq໓WFՉf5z%sP3,7 5|{ja l#[}eNǽ4HjXtg}Bu ۣaPL^|hi7'i߈s|ov(zre![Bd35"X;5y~TWT AYt`~8A#dfv:#g 3-9\pcaf//IJ[pFj'8FqOJCa![ݱ^{ij푣ro3%^2=τw9+m,ոۤgca6 AprLlVff'Կ:Xʝejel$/`7 O_i9&9zd d)/ɭ<򾺙!oiGOo`'8D;EP\?Or.4]׎̳mb89(.'Z4'0s|( 0VOaJݱj4V@ViQ螬wi)N U4@SyP6x/˔ӇS!zQdEkamW@ va"n󸊠l'-M10»d{/j[D?PcO?m hp\1F8Axq>`[uf*UܸӨ=J0&ǃ'y4_jU7QA Zy}+y^+v w_ 9Ys?;k*@G!`F$yMY}KsԤw5򣹪/0]Ů=]JfBr*eLD;>8,x*N_zho_K8-uK cGtwM4Utw3i}IԱ/ !ep,Жp_H*S@%e' lMdAɯl'dtcG *=*Lábɤ7,V]M[WkP96uACn'b45g r/[ҼA /LGqgji)$hDzyno:y'!~Yasw%r~pZ9j!`"1vy  '8b8v&dQ0^#af9Ҝ;q=7Y`6E i\} )ͰT͒}.נPX9M'[Y#PjЉ .q^hsQN %TiU&O^heՙ0` =2tC .ԹWb${V;O&.7C,}L?Y͇R ށ^~DhiCjWH?7a1[n2'w0^[";v7CS|a;Yt](ti:\ }(2}.a(&_0_u%^*>ot4@ҵ"۠Q`nLb}g_]KjN%[a A;syHDYK5E8uPyD(Ǭ˼Mt"tM%vMpde6VQ eLdDCu0Vzh3fQ2s>ZGOnBӖ"䜰}Pj ϓ&^{& b -A$Dl?+.>~ʉ%J}!L8a{Wӣ31eT)qXQDܗ{yq"-#1sҾ׉1X*>fƳbHڼ\N:8d ?Pn}o:P0rs̬]ͪ22!xsOe@zD+liYy59X(xQ] 8Z'栈M =~>tva{ėx9H_\^' C[ ~+61lup).':`?Nɨؗ҅Mx4GE(I!urO#=f:|k_4cV`dȬAq4'nL֛04`l/v,jՏ!̱so F/tZf –3vZN3#ȷQ3EoN.~K$Cbtyrt#;R#֚(1Z3IJDϯg;yqO}E0]u;F膄e:V, a泏춙1*ߥxTٔ۾RGJ=y5.WAe1Sӫ 'oQ#Jp։~ܪ NX!xz#W^60CAv(nzV;Ht͞:v4}q0\U:'b"ɧW w9=} vn#h PmqavlR\ J7<1fs}R).az42W y>s[,}qm:sQ3܂@] h`n /tנD|2 RM. wy]w~N@=Aͦ6KBP^A]i)uewpe$-Y!FPpafILfiA6b0mBiJ (~pO= Wm!?d8 i5}G; ˖픊SvՕ&m~MPPQU2 kw ٫ˍ%]56mq_ r?2'J4Ka1|M$R/am`'w1Mdw:f1hCiO [֚maz9̶̦[6\z9J&;](z ITSn d4"Z.AjpNtcFMZhdTu9eyuf#Kd+)1M63Fҡ=BчIڟ~j1;qա&X{QLPsaꦿץJI'qt2خ~NEn>&jb[ic!kq;$G$)Dy. 'O"]I/j"EH~KFV$4 X=N&c3_MN ̣l7odN vcB±.S~8ڹ'ǜܔ*#9L3*S|;3FYU](D;)ڇ}v;I8m;-gP:<;_aIU0Tw^ff`0+qDdyDBCUbtC`~*ר~˪lZ/)Ϳ_h]uma$]msهW3%p8 Na"bKͭ>¬5CI[26U{;v:.b^Qa"*Ejа# G]iTJɻrhr 'YLZ^m'#`&}CrK+^T!#@>fӣ0f&>>^"o i{Umx a^ݧd&&8DUq!Xas`I>|JHrH\~m푪=O_-bIQh_:U)~qo&؇/wtB |/wT#c%pd'Ame3&нa$YÁ%Ƃ^}~yz6e(jerQ3Vm,&=Rb @Yq۬wq֣銾3$6\MlQt%sbxœŮ_} FiZċ֚UJ־uLu[R݉v [^U7^a[-5z)S@ %(c#ZK~a58bg lܣxM~zY-DEM\eyyIl{q&7t`O*0zi6^AfNm/![g{.hrF=!hZ{[|! &a`?={Ky=GF\| SB`3s}E`Zb=UWvXgu)Mщ]E T2 Q1cSq#JW$q!ōl]!;|,ZoWH3UX>~*~<)>fE WU32T &|wZIb?HSxf;/5)gzg[=R8gvf$8ȏ;63R;U-S^iڢS3K^4,DɦP@`Xv {zĐ-PuP0e i%{tL]-%SQc^̛q V~njb8cxF4ƦhX`8hՁ#@:$Jr(_@? <"s@&I)>i0Q)frvH&}57y`f"\@KMmX{Ob?QM`\^p]# .1a [p_ASTb3z.hMوԆvj$Kr6klQU`۷ұiZjJVΗ, Gz@PiL M^}HExS5E{?9 XPANN/{[wP3GR[~~aL!G! Rň bQԺdgd(_ ;E8O^29#'9 @([nCaPP }nUY=,_!PgOzZ-XD%MGY whCDx]Q2ڦBsX}9\]b6gJpoAis] 08>R;E48UI0ݼ31[C췗yT/]wǝfH T %)O| Vm%j,D|cd3fOc$2S9MR1ljITHB^1ZQ`_ )S$FL(x \쀺.;8B/S!uـrLdcP @0ݽUԗHrO1[bxf)j*ev<}3kȶOXi B%  wռK!dr.=jy&dm`o>:fO#F&FT"O&ԯYo>U@Wd.d #?'Zm3<ٽXLzv^ 7gץ}I^J8w \al06TsЦ2x!VK鑧J.׾AoZ{ZTZCʼne&R}z"wFHm~waId!E xF(/5ēa/pf);t R#>@[Zq  eQ]vn]cGB(sҜOgՖzQǰ;4:"kJ͛4[157Iu7`8$L.E~} >i#oeJrġDz%YI} 5!T3sdI  ثH;恮Wzo>KFnQsmNU7@:q>v7R^PWmtP"awW|Ykn"A`x#U+ިtBN(: F"\@,EĆ|GԬmJ G~N;`$cH:#CsM8f1TN!#JkZ^=dz!ʎ3|fYIȖƭ5lPִ*-Wwŋxl;R͚HRЭTd4$I ȭ%ϊ𥝽XlVY50Y3Grs:W_u{~ǩr nrŷRHg3Uj+ fV#og||қՀP)LkpGz$ ]T6Hh3Nt+^]]8FSƩXFY@u3']*WxQXYD LJRphb!<уoFb>w?ncϳxL4 @Cd64A Rj@쀝'9@P78Ǚ-&e9lLW+a9m s*"d`Drl,NG6@ )lOcؓ8:@|J'^YoUgQlF(1r"cM-ak4ócIeJb!䅄Nmᔊ 7B@? 3VZ_7a?zKչDA[/.t}oJ,m9G% >-cwWb]T1TmQ"~6b ֔^w0J'A= :#B+-|piB8VÚlO8GA}ív?$cT *%¹^n3X^dS>M4/YH/U =ܴg{Rǚ~?8ڍUq/QfA*g3V^iYe6OUMrxB-_jQt#"^ILls#G{&ijxNǩۥ5hny\sm=|qmai.A4&D <}vb*0-(llĺD%9qO*3זZFNx)jyD ocܻ&=9o5oG )[(#ҵn:6 M*T^i](Y,%D2wJQL`eRҡK5aK*#gU"1 mDE[$|ʼnn%/RtkG3H-C(z[|1_ljx9պ R:ǔ,ZAq_Exr]%%аd$"p˿,U_хPls̸v%)SL ,w= B-h-yÂF F9o~ºOPWhpq1O לi :e],q^' fdɛcyDi' {w0QwݔB9.)!~$Ϟ/jPFA7+AƛM Em^PRy=>!EH帯c˳Jc]|ݒUiۨYa7>->Ιf@Qm HB7x'mּ꬗:U /~Z&lJ!OZY5,= kШ$AZWx9b,{6[nkL"q3>zLлJ7.G {_'T:U eRp-yZ)p)Q-(M?dDp`iV<%-J 4ݱ#iuKa8xg7kWe`s%ϴ3Hr؋ Ğ]hc*L!\u8JqNNnRJľqַfa ɍ4-2t2#y+ gvyw|Q1qKu+µ^%@V28.I8992k,<4HF*{=A94EwE4vq. ?O# R9 K08¿&ɭXP EWǺX!vXEdUCt`:CrIJ r-לjΕΠ&E) sV)"cgstc=wh Lssy63ߘiUވryTlbttRLex9\yIlpY{X}YYXTkrB}E:=f%7 Osu` (X3tslE*[ࢴn* Oy0G~V< ~qr \RV&1k!?"TO5XHDj< D &I{| ePv%>IⷶWF&s!% U&vsN AHNV^s(QX"ݭn qg'QYi/2yX!X3[;Bt1\AŠ.GևcQT[::~vnj}Q˙u_/&p~ \ٶ94bfnEdv[ BEd8ڵha:lڠ x:ƇxI0[)JDzK]\DؼټF# ֧'G&/ȭp-͢'%mEdS"3PR-| QY<ǕESsA_)U=_WlxK`:vБ ejzeԌjMfKꆩy&P uIJ g(xFp[^祖Xr#T! ޠH뛸0|; C߷rJSF$׋^-HtEv T#u^ &b&$z~H&`KڽT.b1TfE0U 3tWF1FWYLf񱢲bMg]0_|R$: sNR[]Gt777JߞYb@l'(y#13ƒ* l&-{nw zK*gzд|8uMi09NAh4UN(h w=WY0nbtgFmsHV 5NakR[:`?:dQM\Xljg/q7oAB fXmE.YX9;]I8z!ger=e-9'cYN-fpPk_p)/Y3R,GVGx仨i_9[۝wm^+'t[lcۿbXt"*~~$ qs`h.6Ȁy$Av%WW_ҭxmAj]!DY/>X~wLRv Mn=^r |7pk{Q2w.jV{pDg:K24VqZqFR ȠBR7q&YLX D ΧsKUVrmiH7eMS`R˜Syr8x5[P9 <ƞ@94.q ?`(k ^M;aסɎ`' }hEܞ3o^~sB( 4/R.ޔ".!Z0="+7{)`=>Jַ-_"XAEr,B[D uSvgl3|k}y-ɱmY}LX82JpXc.~'CKO\[ɞTDzBѝ:$3+͞2Y/bJ@!\0ܶCMD`yeda\BsQH[ZX[S{i佘DSˍ?!E{j;Qh_3ͶdńG4i<= *7`8+thJ-.]/|#$"x&P˅i%ZwEJF.zT8N=l ksd ׎i4!P# Y֨S 'H hOJX[fώS&rz_d/h=.gϔߐ Î8̓)A>ԞMzW"ҍ}rޣE5 eAiD$p\=g`#Q7] 80dU[SAkQ\o>ֿB<{@!ЮzEuE6'd^;Kfo0vl31S?dz\ f́g+b<A"ݍ*EǴX.{ZmBҦpWH[7ִ3UaPe,+lwVh!]MH\50VRl"@ʒٿdm3Q7gdh5vYdU8!] SМCfg[egZnE gWA*R_!M'KI@Ŏow5ݿN@>~k5){ߌ]g ʵAs vsgCp;cM b9b+Ϣz.DChvS`ybZOASE^ĘzIi;{xw_qyM YNsZZ<"MFߑ)y :;]n9FuBfc$uz3rXqC 4?}$L|,9xf)iuxߨ1ksnROOSVW{RĭoKsuehLc9`Oo M-{$:íDHc@"!sYs: ܳBZ-03 u`w&v~ aa8GQr;R[v)0'IbB2SQ>HZcP)~PC$Gc!QftnHC:;1d@f7`tߍ5o]~wvzH Вa)hбG^dko YǮ$R/mj&7& 7.2{z&+l甖,fqSZ*rZ R[k6Z^+'"dвޤ.PNȠ^#6v<0#Ť5bx]E:[g 8"쀴DũPa̪Y*3zS;k/qa Ssd_<[~{x*)jXnJMvqb3= DsVQhC:b,nMJ$7bxR7˓E]R m!}+#];d?(zY wLh'IT%$2 *U(q<,gK~^HTO?P&hn{PlmNNYA+ԴZCrgBmO^{wEI(3H3? W!L3PTd9j)YHޡ&*-QUg2a 26gwr";ELsL[ޔeqPm{0fYr ѮL.:!cӡ<Ά[1.xm]d;5NjijhB&;huN!5(𦉲o*֞p*ţM TkE-ǯIŊ!4id_slpVPƸH61&<?JZ_P-?W*e֬_ GfF__3N6n@hp2#plkOK2}Q\Z~=1ሒC9ZM6ٖ$P`ܟtؿo_ [#ņM(!,`՛aZ8"4+20O\]V~L\겥X* ~/-ORz ׺8Wź=0\|HP,_<W 0aCŦq5:fҚ$G@ j;ό>'n:au*3'g^ R(R%Tڞ` grh'<57pW`89Y`>@S8 Nd{uJ utVfK"RpN״cq&`u1nH5*࠳CΟ~Q w80bun;:@qp6 pU%H3Y)Us8Uqh3`S I֦LŤ=& KJPW c۠of~M ;e7oe%,v8䰜6{"V D6Nҫ v{DW47 6ϛ'z3|Zڰ;9vIߛ &nzk2)Gj/} /Hgq(KwsҎIR߮*uȃm"F75\O- ksf"ӉAOO(,piPnqt$5E,_!gלrӲ긒*am/M'v=(06,]Nk?4>=f%Fks%ZwXgyƹjZVn4YBh&=1k+c0atbP(Ѱ:бQGmO6`vV<Яx8;\8MDx*Q,笴S{Gr3T8M.3:|v*UQOXg+Qv?Yop!ĸ:RGO-~KEvihjA*&@nqtcn7^%Rae(P(D_G٠5tfF,"?77n5NdF05bL 5R/s#`x kd~exս0/M#q#ea]R:AW!Aq9p'X"Em3 ^RG{8@0;P)%Ҷ~D5yD0Bl0i|KIAɋo@fJz8}.g֓$-Zm٦FNrY]gPuٌt|kf\x $a[霗e:1o $PI<IyW*\?k(5+QLѿ6K'SJ dNYU$R,L5B݄LxҦ3 {|ɔz(03^6%WOA[YX*Hojn94B Tg3ֹ5ui܌&NNT\+̪|LIrCĐ_DqGwwf1lDGhm,Njm*Gyh WmCX6Iy-Gj9hIdEB)5A&˦%w9KiRvW'}, `K" ؅kEce5 @0"O=W5hCkd/֍ Tf)")YR&(2tTT<|#\}wZ/5< !['_/BfKu)!~0ީIB)^ה͌e $.B&800Ј> %KOV=b ؟NFدVKwrUa炱ΦP@{'Q27N9Ib|ʅQ1_~'^r>o2nƵgq,dQTC-baEMj͉Ewf8s_NbDME"`RÙ)52+$K7W>NtxuMM V]S& Ic5E+Ƶ|FGy0q 4WCDQZ.TO}&!k\.j{ͯ߼SjDhE<ԅgsW~R4cwd~UOC]BnWOn& fُb|!ecPu)jśNoЧ2[Xn:2c`L9RyMo{҃Gޘc/a ~L4jWsCL7 Ky~U%hE+px^\g"M{;焫ӹ5ET!W/p_ֿ]n<>/\5~|1u]Б2A-b+ ?8X[ivf[AxWr#xbQ΀3\clY}EK5ϾݾUa1לSJ}nrhс{ I R;>y|"!O3$8c?PbhT/OO R+FeDsmfzy4zJRsv_q,_g8, Tf]>)GчG 'G/i6&x3&Zt^eL/a˶*݁xtx9֮rgYsDgN+ lWHHn⭦ ZcV[G6W" UXu# 3x(ZҼ'q4#m6)q 6}&D/Zp[t[ZVaQׁ1QËJ9A:ҡ=WMrQ(i]8rji*LNp`clqk(F<#K3PV,Sa {$Ly]:)^8~^d7FfjZ5Gd9(!&%~/I'#(1K}ӆ(*7@-l%bRaߑcX4վ8#"2.%&s# nop ? |?IJjei.wBDn}D ੓(TQ)A@"Q\Q-t|WW/FRQcd=fDAub\l%/qpA -rL3*Dcz1I@mG n ȧ:% l:z|O۞@s]gԘ52N $:n᦬74n9+g\ % [O/u|-֢f90u]7ûIX#8g@J!o {2Dܧ4c㚖@GOHNj t*]vs]od<,,!m:_P`M}o׳MovLԃ19-!M;jI$hn8S1.^g%z'?t0?gy)u땏Y }v;E2AЬ3ZF(NXC2{ڷZETAY=tOgVγTR6"~B|v*50s!6u9髺'%L(V)DuQV@-wҕ;yR[eQ!c `᛼hC䜿fZTݓy+ĂDҗ.>dQQ!OvyzZY1tO,0 c(\z?<Yn&yi4 ; V%a ~E_ʅ;"<+^nDwB9eW*prLo~ߙLb_VsDVW!5U]t$&%܆dDNwY؇ܹ'jjҪt`i HvF?|<|^C}u 4ca 0 ]4\RCp7j = [2rӿn~p_Eo.Ę߶7AqOCmghC_:Q8th#0[Wdޟo1)33zܟ\Joj%q4"z}| fֳQT+}x-#994@Gjpo [,LtZ¹ibS}e2E^Dl]ț{1}vCvAL`M6re BpXY^p=`""گ-T9]aF+g5B] _UcP߾s<<$@ tYja|'E"I0;0։fE΄Y"vfǻ_Ki΅ eڳڔa;?LM;aVd=qAT gt?_ReM!Ҡ]!4kIUεXG>EݞׄN׶Xn(B .9`MЫz2mB@盌ܺ0?!E?El DQ{ pqπ b͕}7 8.槠1UAĆw{iLWǂs#jUsq RB_lIRLKPQ+)]w* N\Wc |?̸Pw{iڿ#ԳI%߃I}^P։i2KT13{0Mx/S4I=(!p0,1L#~1CqCˑrw@7dH' L{N l'T|5Z_jVr?5 }pOxM@Z#FR"*&(~m?;S]l$Z*-9B-̊(=Ɉ[}q_M8K$Y=k y(}j~͏yJTح.afVnEPOnbfBF7˜N΄X[KVpc _w)[v0{T]J*1.'^:m*:,DjvUG̿j}|1%kh>(Nbz0}cl;[`§XR=a- =[OW{ ou[Q!?|&%XwkAlA4Z.邾XZe3uF4ܖf{p8l<!4ꫢ>F]:Qvf.'TBpiJmh(N<}%KZe\̺JNEbF \dj 02cLGfR/?OWU_)\gkW`ZR# Pzf ܜQy f0R=Jf=*{DWz bc,)ʷJ/IЮ]*(@H0iuKBʡȩ_>O(`CZ=> ,^lɑ}WϤsGH| rްɯq!bJU+ajm3OA.jVN/ OzD>r"]7q6٨C.wƕ f%0zsvOU2CҜGw.^!W3_( ?d("k H$޾YhӲx]E⭜ 7HI8/7ް2`8F8`DBBP?Oy-[x³QfKrkAW~B'}$Mo&+̝ɱ{E 6 AdLPAu?lՆkiUğs@];vJ^Y=-w#3XDXSso{@Ev '5I(ErtV!1_0;>i@tSs􇮽] ~R#) 4"%t,$|2I`ϣgm$l4myM]kC٪Z 8)OXjS%@vD#$ŧuv% GO*$~ZyE)׊Y䉆_5 ڕ~/~P M4t@y*ܱ߼zjnaX}e1W[g5bxb 8_`(QPTŃg"gM U;tbB+~TCUn膏Z-z D2 uíʸS};eI]jMezĘ7`ɎgFE:X!Ӿ)ն_:cR@}l@ֹ ?7[B_ GKXBި~MFWĝD!k!P3 &?4S%8әZ"LsiMGAiD#;7lahPNgS6Pyrڠp6@Fpg^|ڏ0(%oJݞjuo c_:yl^3 L]@,Qh=bcF"񥓩pàke pc}{c$pEWz~"8O[|g;4@UzspLAw׆ hQ{A?m` ⮝aTxFͥ뉈VS"yoyP0.MY`[[Jg OH#ggR^QSیdY4Lx4,:MTJ= GOU։wa^'OӸpű㫚 5KėYrZ؉է~Px\:ᣊߗN6?Ku 18}%#=a#R<XE)֒yȻC-&ǡ_ BFeyʗw/t ¿Koׅ|@)K 9긞ҍ;j_pp32@b~t~h? [杻k~IϦЙq6\$-OmX-i(s*Pj6[(i,uTMgyf/T>x}.iYif򔿪- k,|&7]J&bOZ52z}[ђ&Kva뙑$bFs>|l W:*^S\ 7T܏F?(Z^*SR8ςsܝ[ư` ZQ)z,xj3Vb`܈bN5ur~-}'BQƬ|z?7! fh>d;:\(Lc#dm%oW<Ձ{࿧ T͉qۑm.߮O[:+JjGh<I W1/{怍NTuj]'&EQ16'Nan] Ӟ k]~s[&|$mi $Qr[Xچi벽Ą Z(G#^KN?LO\3\Ӯ45KjHi~\H[}3c:foMkm9if|^PZbyJ.zp TicMMN"YS1R^saт`i"$IDQZDNQG -nDW4;=O%^ ى8<7\[㿏 Rc y{ @'̇$4cb[6LN!2d*p fnz`)|Y87wq,x4F\_adV/vW\֮Lyܙo^TZz 7A,jawfSvx{XQ]ٰ`U0 (?$&R8Om#650Q/n6H3!\M+Z"0!@q,'+M8Ci  띊w:s G}}jGvu8.L=tV$t|h;+5B$7Z w[Mw!]HR>U"@pʎLՁ:0exʌ)OD̯ ;Fw0xHx7\K P5?*pĮ՞uiHiGTQV[7`W߽0Nl{AȚ @s2Y.0%#GKR@Aq%+_rSs{a{u*?b(.gRqW=[Ww/wڙ]~~$/# z$*iԍ}߆tW&[c6 Dmuxf Aʀ{l;t0O+[F-ecqVXBk{ܯpt/&kGL0vK?sLj3Ksܻb{ !0|#¨Do8aîX*GЈK-CC#O.LqI8Xa4AYXBUcٵin!a{K5@<%KԮp[T.ܡ?`|}z~w,Y9YOk1$:;2ڹT<$t, !#{%1UɢU>t^ ;tjfMN[DZDT@EfƽM7PX!ävdU #e FYn) f⹜˲Fӌ0KaI!\d]z' ׾s#2OxeD_/iNo@>09t,DO1]NXH(|5C2_Pc\vĎڹl%={A؝27Va ~"p_[dzG` IXfl2hW(D~WH5ԥYhqa W.JZ?Fky/ZyTkUMMnh?::?(7'¦\X쿚"aռ̅FK>;sxȍRXbҚw>sb9 EPpݾ:!ԣ'; 1e^0K 7Vcl_[$G $M O,ZlkQr\( #Ժ)Q|1:`-F=7ЛseG \*pt%s`Qo"3T@_kIAv+>$ +tm ByҞk sΊlXHxA#jサsbPz{z:D'$Z$cf[8Ζ7"(IS''iߋ14;+IMxGT B7kG"/ 1. oGO;0|-qOu{_M~>ybf^^oƱ#`FHG(1_:NؤiXkZU/T!cZFgl@R4{k1\FbQ=տ׏Cb6CvuF$hGס6ڙ&}PJ Pu*ف~ANEVM2<‚ _~V_8dQ eC@ធx@T¨U¼'ͧg'J0Y.sFdRw)FC+x=4ȿN~*mju]r˜a~~`,n9lD0z{GxGD_b}O6f܍SPNЃZPHe7^@&Z띁jw:vڣ1.Dv?W XQ|/fq [W?3fOɅ!I :=err_9=P {SZPPk+hDt oEAIy׆% J^gcӗ$(Rs{;WGħCr5|{S¶M=ʸ ePDO\5^L{~ Ǟ 遃ujD\|(onqt>}@ށ㋋c}Xay'%6i^|4b`/L Z}ymQۼt`vLeNvmA)f{X;#ϷPuΤ-*QJXERJ};*&3+]-.nDsZ cRB5%{Tߦ@$!cOKH؏%^?r:ၲ˧EqDz> {0[;2s5 -3oLBH3;)S׍\'XC??%6;]E.hURJdox)K Fc;+pCʇŰ<p4t}vfI'L):r^6%/V -X"Ljc fs"LDJE`Gb@NxxwN?X 81 q/[Kg:W?K=S=ˋ*ZjMk~D6@.{E?#Y e= ˳0PWN(SkPyw2警+CPG{Ʉfiv3JAv}ya~zh)C\pq)/c})qz*ȸ.9 ].#/=Zo 14"tkW] ^&c4 kNTc/DWنւKOY;$[=E^{"L Y:*ml)9w&|JMш!=z1eR-,| vQL$/8߮1(pRg[OobaH^R:Cx:_E, }dQd"׶]͐ESr9Ɯ/!PM/.} hkqYӅUF9uV 1 k뮹݂*u 躈?*ܒh2CR,k/<;H0=\\҇׷b&L%tNdמ%}!оx>,+mVKYp!UaAJExpK2]3.e*^˷MNffl~z7@?u\ČP5X׆5G.r9cj.__xáyԑC )bhy*3^R7x"UzꌒH}23?&IPGFʐ_!%bKEbTIE{ \[d U ^z9L|lœ.lj۰`tⲨWTCcDoӍA\iCAYE_AhP)kLWAC dҪgDh '1?S `S̀Մ2c###:#knѶ0&zc`bD~v/ܑyaLS&<tWE O8Jwp[&Jyi㼒2%"Ϸ| viq* qI$q1`ڍ_(*>xo@#l EO sA!5ndy'+v@kw~ t6P9qwe@#FPtC72҆3Jj]ɓ?*ё\/`*L6 +x?(W~kWU-@ WNw~g0VHiCy|?֢ g)XvMNt?zM5N|=FWat5Bp_(-,2^Y Dq,[Y1ԏ/m|;bVܬ-I5a EҬX8m2QA᪣VL'sjݝ3777q ˆFt2;jgy3 p75 ۔rzDfoe{AGq~F}Yt򥫄Yvvؽ*ls`{+ m6*T>Ӈ5wv8J֘p /QҌhGu zѹ0V\ ١Ky^~lc1$&9??C{v e9۪EѶN3!|Hf'M úC,!Q+nQc*WyAjwMiͻ^0뺪fV_Gxe0^ w6v[8B-&b'Ti!0CS]?GzaBl85/a:b,&h Va2_ x?LM ڞa_FMoxly?~~ x@uZ?ʓ&e4M2E!=?;az7|51`bUP NL"ƴd LƵwt̎=x `{"4Kr Й#ߊu9E!*afD1mװjs5gNb|cz.fg_sl"D8PцHFrf& Ou[ )T[fnR+*(;g~`)#)Jh`>JXa1i(ƀ$S^Y +՗4ibH%qO0s6%ʙ^LQBsw`N>aDkH,Ph~LK^JEqix_J.RmQ)=i wb*owS:L8v:4$7:.ނekp Xv8#s)'" e5<<~- 4>Uz̹> ko#U_W[#FBlz u.֩(*ĀyȉL f|,?mпՈ ^GFTaݏ$ȖyJ80_o. bͪ'Sܑ{qJ&R:h):3]I|8CI]r6֨,:,iH0|&*5-sL~+n}&BK \g5^_ҦmX) %PL>WqIN##j c6>2sΒ]T8R6} \>D򲯀vT67Y w{yC% {{@|߱<ÿk+DEÜ@GWoW}lb HipK J=!qp֑@ 0_{Ww|54w˘AAH.,e>.4:5,kf\8¶KU C:#Tfӟ>ϮUe$lmDim:f\)9鿖?9ҿ d=V= D%&O&lv~@dL\@66]$*TFC#`$l/KBeFg𺳇jJ~ m^uP(*a|8|#(x9cYqN&uhRw$P"~?QÍDJ 0IS|d5ޫi.$O*\ pDJ1z]-)a 8O"s:6uXz|yN iy"pxނo~%[N'rZ= F܃Acw2ߡ}U>k_ 6vhJu?'m< %uegxx2+\—ӺNJJE$oAfRw&MH3?QؑM3 X6|-=h k1\i9Yi-,G#GY:Ƚ`h_\7b!-*c\MX2|;66"3#kwN}V+n_712ԨWS#}U%MPG57Zg<AZrFڹW؏=e*FQN(kpFGR.|@L Yc2F$jqaK gM/K,21c^RoUTûuY jh: c ;=KsL`#v zG䛆7̽뱌zhYvC m4mYJhYʎ9 @Rf \[\gUV#v RV:3s:i9[_K ZBߺj`=7έ:gO♮ebBWBVmmH/'jEim +gň.kLw&-f̃(mC8}ەIHB8kk䦺o~ՓC~g/[o?*-P.iݲkU]q;i U KjhTGY,1׵,u(p54*w DsDO< !sΞӨ|7J|(='= i5UtCP(:ui{z Wf6{{痼&X+s=YwՖji"/;ɻc2 `8չvX 0pa ]"YlyH6@)MH\UxAu3E`T -$_MWL]Gvhj+x_ԡ0瓯)0X3V=D8POGR$5ePΑί@΅^njspq?>>ͻ_¬O+HUALXj6&8C M{t7 $FKˆPq5RӤёVهƈ fXJzbz=,_ ojUhyt$"~Pѽy ɱUT+9dU8Sgn^+Ѱs}Kjitlي]<jYqȅz4(еڭoL@TxZ >-pLFYˠۮ}eEG)`]p@} mB{r HKk%m9r3DvveǢƠ[D(fja𺔮%'0";nZ PҖH,&v"nr 0oc_ÀIFdT(}Q I6"qe+ /vR[+)2v~#p _W{dHj$V'[(+.#qlLű= /(5=^ EuFסjW\ěQ42}i.wbxff9.]*96VUR  G +O_=+2: ˡc 2&\׳hpȶo,]y ӊUU,|?/լV+((=tbH( I܅G~c jh7k׹ck q&}C;)i= AH|=` 3_a:M`_aB*] ;[<9]B(&{Ш|6CxB!uphpn2TnY7UµmMFBs@%2dbU,Q18Vi4`0$Lb?J'עY ٠yg#S*CsG6Ƹ:Yӕގw$ޔĦȓd)q ݺL#9';xpQZQG K{_?ⱿՂ% obɦ.N bo*^$*]v'gz)13I6)@o@:st3[aY"ѫ hSWrZكC+1ygrx?ˬ ?؁R5y;MUY\vߧZwZ끯(ga'4 .RhΉ ]R&9"P6#ՃQ^P80Z]v-Zp jgOg݁STfғo@+? zI#"`VL8Xc! Q`(t amsJ^#|ڻ\v.+|. qhKMkGKax"mRJ*{꿔풛{pA4#T&Iμ*SS8έ.={AYe8ϰ̥$>PFd*~A07(^b[4k7yލޭK4*-˞%.hx GBԇjw8+D[? E/,׺_"&KtswŌ]29 7R zZQ?XtqF&E`ר-EPC}~7_FԁIބn*ҙۭ +KL*aN,C%&=AqIZirpUeZB=K0z`S[r+7fiRqAo P9AM/E"<3O?Ҩ+[kGTrOm寤XQ|m~ahDA!mwf;J㺛]LQ8G%GĞĺK'Z4w^_J|CI|g.rU'9̿_%sH`b g/C2~"`>kCZCnҍr.fWDlzGPL~p+#{"+O 6JL;S4lOsD}FGwVPL8^czsW瑹XY{2ڠ|Ϻ \J!@\6x(ߘlt˥1Exd'3شc؛r>O^c@}cvyOo \Ii$K/2N/S#fi;?$xFwҮxՂPRs?K1tpF-#DEM, gy}zz>c,ȑ?>^\EK򚣽QKM='C?sA=C_Z&1肿5{Z}{V.8I9]L ?ٍ%*D:DPmť/y wmjO~rD~7PgOgk=e(4/aگ NL@ӸV!'< u= 7]$ֶJ:>}=0rl$XyW RTh'wlcg*#kU-% Mdizbd#~t5guΖo>F\;bZx/ G&dмt<)}bUCtExV ~uVqn5}kf_XR֏Yl̊A!idv~uG _ݦU/o(s+B-̐Ln$Y fVY6ʰCWPf=jZ7:(GkW1b]E,ϋ࠮ 9g9fEt?tښY`#50%|'ٟ5hHi~1BH$H@@븕cўˆy_^WX-%hwG`~” Bq&2^>GmGA~^l ,NV|Q8MCwX]?NKtA_|cS%t3D7Y]vP~CzO6'Г" x`fJqC^\86x՝sHp ?F̀?n2-bTu? 7:O<]z^rQ~ Zr8&*ޗU^s둽v)2\sH4[H^*P2(svHyJ7 Gkh6>V,r_(4H齢%[|1Et`&'z[6jB 8 0q>sQהd6ڀq*y2#$)7!{c?: Ȗ(Mr{; !mCR,Im=b;DeO}FD)PbǞ*o1 5jz|V˭\qx99!//ӄyDT .KJt/ks4go qsP=o¹aGj5+v[H7?ےwfͩlnK&WD ݧNP{F7 ov$_nš <"w(˶$A"݁jx2^?P\G4\T5O?Lғ8{" jB/>nvhrL2@F>+0N_ljj~+*śJU~fo]^lXlBƄ jH,w1@_;,_5U@O#sa;V$cjvnBIt R5VxD;EH)O򨫨6 Z]GOv2'Y31uxYQv =Z] / ;wۈKr>=Μ]6 + ዙj1 b^W& ZJEMADwW<9&Y DqiJao~ˮL*YJQfy|RhSzQ\TH{ {eȭ~e{wۙ<]5 'ͽetثlGܲ ̫̭2[1ʀO_8R*|>R^YJDD"E}ȦQfes{ZFe%iiu!S m`_lageM2uU_8ـ y@ޚVQJԧHhU?~x*Fߦ碬aj7X6LwFdpXz/.W38@mi}a;Nwƙs0`ƒY'гkZY9\1݇r^ף(#eP&fT? Z}VQfoݝ0Я-svޑ\!lur튻2(5b¥99,Sn"(c5Jo4*cⷝS8ގݯdWo" K,c T,Ա?@j˜q͢aq3 /&n74˪4Q2 L{ <N9C^O3ƚ%bRP\VRkix*"9A!Ojs]Wb0ѿ84cxv%Zfc{xɊ^|LWBtfԪ?J |`{ah͑þ1PJx:K| N=^{NTf'v.6|\TUgjEQomB>4 mD(kSPF#Х; av8ń2֔A7et(2_mSl`9kp=c>?kNɃW]"6P ^@!9 vZ  OIHtcQmx( |g3D?̙~K{se…iMtaOf9ukHF0yzrEĔ cJ }+lbl #ˬ:沈NՕ$Q&yksըlK/l45#rH:Uڕ}v茠&syr?. &htMp<9I5M$qՅ^8@ X^`.pkh-l-4kDkۜrR-|0ؽkSd;-/&m4y/Ɛ/Z-fr#>#@CrQ_luw5>;~Y% pB7" xY`+oJwܗ S8=ȺŪUc1.uح`@訪gdy"%5㵉5`0z9\b~k?NySL&>-q{)@^ZS+h!i 6f]v¾v˖/qyt|d K5W쀔#%A<?ywG=J8}[ \('20:E ˛G&L2] S\쌦/cOsFť&Y)G 1yZ 諅~@Ge'"\D&dҦ|GSq~&~ a~+'Xi͈sg$#buّ4!'!c\kk  qܩ*g3#"&}][= _zkG6wng'l_(+>WR, 8ثy٠߳2)27=.MPԌ*N\f yk)JM6Q(NN+S%+oD;y2a!1u̇fl|ڗyz0zlVZ7qt71l쏍&}e >uEջCDCn1¾l(5S]+AmJ!(dD|?m+x"2`+,gik%&24h٧p?=P 7`FsR]HчP^\74nE\j󃼉5֠5?q[--2AP0&A=)otoEmoR5=T ضT>mk^~E:- C0/3INn$jۤ 2.7%GpK@zlPߢ7tx:@5YzNhgERmzWY&OCȏ _ {̦է[QpZo7ڑIT 57do=5݋K[{"R f,t(m˼b#/26-: "k!FF Gei=(~0^ܬu$20@hQGpq#}=PsҵlRaeQ tڴxڇ\Hˆ޲;8p÷D:Yi;Mq)X*aӝJPO[Š2 oS>^oᮞ[d}(G]{>CpPzqmp%1}95f6{tV2̡8m;Hw^j@3`@jTS2Υ.1L4EWJŝ_oPI Dp =c $ZR8 |cJb׌1ϦSb.*onJJX3xn\GswlW,.P"͟ݑlkw ɒ&)eb36Wc̊M5.QJtXpšQM>gAk5NJZ*S%!?)o*U]3T?oXyټǧJGl9.z]-ѭI&^3 1ЈX4&<_A /<ѳNz"xnSd(i/[xldqiB])7bxYC'[;hxjONVCHz~ ՝h_npbhWj;IC| Qo4~ͱpr 1=Jxuec Ze_U-%([ϲn5|]y *%l_+x;?]DĎgJLuԩ+AHެ?oފ9wCN$pRF/0cjDm"}_>TbcO^}0&|_r`{^ \qdn`5 ?Aʪ6kt{V q@$Hym#wAR]侊;M]uCL$ꎖlhy~gD u{\ؤ⅛~`vҶ}-_뜃6!HXFy5~C|P\gcۤ>$bm~jeO01D~[vaq1CgWs'6DmM pQ'nr2Bb9V%~'iIY5[(\L2$-C zkz{ C$ 9 ɼ;ж4[N'{A5 `'٭9^wHQ&,ynDA `T4LZ1?z>lyu+'x!]w!Q6?86D%nۿyE>ēž?fpC0e*+UO}s6qٕ*~ju^ӑMVTWm{& KkWos (n...":س:(\SOɂcT<[k{!qah +ˋC}pP&;'¿V< ezzPW%&aYδk|rDЪZ5^"$|Hk+)E NXV*2ħss(r5 Y.ØɸUՅTuԓjޤ=z`d9ge%d$z[P@NIC94)DGEw`i2kbo=~.-k_Q^3e擂,2-N=Ԓji@ȭTߺΛ %+w?w?@&9y?UNi]4ئtEDȷ3l y~~,hcͻl 7 0yΕKAMw Q $wϼ S5igtǾv-ƒ; O(>ai T$RrW|ʨ2)Ea0 "Drl,=~[-G)W*삼#/Q!|s+%!Бq{p{ ^LHeIc׊{tGJ:7W||^oAOptѲ2@$eL(zD/?[]d%i}gIBY0>i-ؘA*x_K?QbGփT^Cu{Y3L_rh^0)XC%KKnxˆ.Qrj0I.H`Jʀ98iXMCȘ_tyWh6.8 9"F7Hџ *u*_G7idBmb 9bIFDžDZ/gJ2 t׋*r_jueبQؚlC[fn^ {-/rOhgӞ6=EHWsvns(ю,>2zʆ?!Vzʀ^T l q^aijhsP@8Tnu5"mr-e>*qpx hujQ?Kȭrj݀ђ }q>7޵ }[{xl )J&Rqi8 oY/JՐej#!,1V6 kP2`d߻MZWOf] }NT64:)^fAvܪ)~i:(YrŔ6gxhkw rl8.>oجZDYE/m9fH|-yWoL| S7d"Sp ,ɭ+]3jRmm{sDe:c 2d\ng;'qtCQ6JLb[- `ۥ[mG]3,_ o߿r?]ߴߵ80 (MDX-T+&r82Ӊ̇aEBƊcwDαޞo)NWÇr}&7"H|Q $Qk^ٹ' H%I(!~shhaDs--A0(Xx[?7axZGʮjjq]yژZj8mv3nEKD[ > C ׅ}V@JIN a @,:@wt4Ʒx#T%7s]Ij`j\}UPTA%St!YHrb#q x*vo֬t8rWbJIzfgE3B& #8:>o$vh8\;M@*٦nDV9,%Lvb.h\ºmFJH:UcqlN!2}&o,+5](-(1)P0׊O>]?*@J v̌`IqY+tX8/bnLS$ji;A{\:-[g}-+w28X ' ؖfUd" >i!&ڭ= nY(v'*|K5io!IOa_]S%YGpDmUtAF=OGl[Yj?--6TT0XX?yIdS]AvE{?!jaU#'+w?X[/c;q)I-i6V\l5SM)mLCe]O}jG'h)摇(+R= ,E|fwVQKɮ(_K @WĶ̟i&%o9wv&xX.yGI 3!F::1?7dH6Ȇ2=Ri\AWz74;4qx@wcԃB͵muSdn~-$]P-d{XW6qt`ְ]%H P{8FJm0|XAN;쭮fe&ǘ'@d]#.ϫT !Ac"7&>EpAqX7t*ɂ?Dor2#zOwtm[[X(1B {Ol}cOWG!|?pWg܍ V炮VxF1L0$H$8)Yݳ"go֗$}~?^3]>vN2\z=2z(- l ^'ɑX11O\W ȄBCϗ2VmDerToR*KDHeWDQXaAn}_]ah0 N^TxEKss;tƯL=5%s_ޥQ]{Qzבi }swM:x6嗮 %KL] Me)Jd~޼$aٝ*V,tр+Ǘ*+8d1IZϷU%./փiپC"_{ɒ mr\]3ԫzD+' QC6JgJ2g q!TDŌDu&S?R|qtw~i~0S̓!-+ zX + Awf%B{DXV0bwLa|)IR?yE=W=4bjeY3>VX1'fV֓zD59pN˲ X`=]є$E Σf0 2p ^){q8k]ۻYw~+Fë*&|rA=_R g> Ufؖf%8BU;w.Ǔ:Ťj#X6dN2̮7S[hķEe뤧u^XCFעrbiT+6H,V1=K~Fl8)Ma )}݃H1z4F?~xyJ`gwN'@}"0"i#dž% L; )(ie5Gs6'Ĥi9׸Mnk"9nDRc=ۀlfrfsoݝeu-Ic!rp>Ÿǿؽc"rVVT@{oS찀4N_k6=S.AU 5?麂t=M]mp;8tq ¼ Ai`ݶ,1k̕|S5>{cVKV `4]zQn֚.p% &םlϨb8"+ IdJ`|^]_u5rVV \޼a`nO._q̹ {0>DuѸEa[Ǧ6vil*laQ2L_! rc L^;uYqOjK pҽ#jc8o n:D̞2%P2eDzÔ!q 7k.STl8eV7GD"W=%Ҧ;rQ&iO O^^L2K"WoWpy;/I2_JL暸. 7(nƋ[uTΏ l{1?ROzhtd}i*a?9ȮmGBU8RvUYb$#=-l=gb|$>M(I3dphA9rܟ2dAEt`%&H~yA/)I$bc4|D1a2k4ufVc7j3 Sr>/ ൻ ߎPዋxUj@·MPZ1W|)у\&"a -eknttԱ߁ۆUlsV% 6v_<; 25 Ca]{EE~3/i4x,GAݸ{__.Ѓ.n})X 1 g-+AzAZ6 |}PA!:j"d |CUɻ?tW(@h J?[_cʜ!8Şh#fKRsh2 җ977G~k73%BYkyĤ{7t [}rujH v؈䰲>}}+̔PN•Z*՟妙3>qmAs)@ƯWdW|/8U1wLZZk` a]Qo(80 2|5x"gx1?V/ ~+0LXḼ콥dt kȓinB<Q@$S}?)ezp3p^Z zm/GxY,$bx,Х3hh B[߼ cRӾLXrQ(@[~/2MԤg* k^Xm1׼;Xd7ΡQVxA1?=ImcζbPh^͠ 10T`eA(ZH]/q/ w"Kª# X*ΜM v  ғ #*+ThMqHH@y`& #3.3pejʻK.7keׯ˖KCkz]Io2Xİ!lL !0\ ~͏=m$ O5"蓘1)@I 2.a@|kU.‰d<^P/}tޑyHFTڰ?|[B8Vec- h\}jFC13Ll fXb1}E?WVx4n 6qQIvQW6V>l=GbDa90aҋj#߆e~V悊m@lR.4I^^du1F7/\(WT})Uqsz7B`oi#;lHoL-+Ayr'Oć#;Kjɟ)?DOm7t|"]a\)Rdp1hWKiU)^:ݒ6(JyU5&9bg Pp#RG)/gI mv9TԽqol-LSEB-wl\ibq̭S}I=[36fƜʯed2 +N LdCU'HUM/[lg#b6MvyX "1MÍNJ&bmUෲ-B7o֗WZm59n=х MSqs^hy!ܜ:N]be,zSmjLs/s3Ig:HRL{2C%Zfp i@9ӕ MzLC~R=:iFkE[XmPޜCx@V4e5XteyV򇚰 1I HalrzJ%BsE,8j&{n?\?ͯ "īzb\a T7S(3/cf3#o#~NbwZÿUIӭ۟zJis"Ȼ>NϥZ KJ.0oGq$ikmvE [X%KA> Ka rr[ag+\ O''<+PagJקc:SDxfc]ڃ(`jgeYܨ 2,%¶*r_3S[dTN(UJWx/W (Zd)َHk6j u^Se iP;-z:Y)ڶtd[y#̆YDT<;lN Zq}E*7U: V[ k.A`Q-%I2u2ϳzlmyEsp==TtgA\eW~ҫ~@ϛІ*b \Qay>$~0 mYGNqi*F&<wl[~LnY/Ma#HA_eʎYCs1L(YGGWIX - hގ9Lz9M=J*<0`ES:ҧ2vK/QMq,^xNAEtD^ vlJ`sUrj<:.֌g˹WU7p=%PYw΂6Ƴ_~p7b-D9@,a%|h,!Wzx 3D0!'y7I馞ҳS/|ª놀ރ"j],חa!oE MerȾy6ʑ&Yr>pxpkԛ7s7$3L$/j4i)wo6V3=I#JX0jBt#*Ftjk3˖2^jb63"n<lu%K(`T`,攃\.܏Q;T#]1Z,ˤ1WeӤnzrsvi˙6-"ՋPz "WQ@>6An1ο8H]P#棙 pyG%fIu}v`H[fw DWH1DF{G-X{Z[;#vrIHY[vWU O\Wr`mRQ?b>xAw2~7De9~ݟB: 5;T\B3Ytx?:b" V 䎇sv;ti]h<`A4WTUލ{d>b{k@s>قD.v,B;@m-8Ej7 I ߆c|z4a qsfƆ4STvyBv E6bJDt ۰Cr ~E6v (nP2b[*(lo?'VWց/eM<#:b`(:i DɼM=ZO}œ,=Tͅɣ(?kUUTI )sRZ<VB0։8mijoZ<}9ku\2{6[ӲK:xFgᑗE]^vTCfH1YL F][ƭRu~=3k7<Ւo|6k Bfm V ?El{we/s"Hz4?R-Ow51cyPPՖ-F#{!]k_[VPfmkFn7^)q/~Q ϙ 7PP82Lų#;| 88ߙW=GKd;Q-] ZeM%? #^QC,=ӈq8h}_22qߨ 4xgEQ$'&ʙ^1^U> _ђLRZeɷDZL0atʲ8.@C. AmPC)6xցRg~ob?*BĽ- ݰW7ꅱ}fEƇ2q$ <@F#5 ͪ1<PH^fgְ%Awbs*Zǖ*vW!. 1aH睥jߖ\wq)%NM"Yj ,řTguvpJ'_^=f@7˙:RdՎY2 XSCʔcf`2LfyZ$= {EUgd/ MS8^/&κrRkGɔ5%Y\qd=xU~2Nǜ}U}T \H%dP8鿓Ƙ*Ӕv7Fɩ gwbTkphٞ/㽆iзѝPM}AOqlɋǞf ?e5JdLvҙ7?j 8LW$rvlvk׋J 3DRfj,fzCm/`ݠx|4c}xeDyfqq&N^TW܃AqRsFT qʶ i%q$9jcKPf.(f8@[?L|Cq7bЊg *ʴ4?^Nkеvm%Rw.熰?2IF@zO=0Ͱ炩:TAAW<37^ζ;tpVm-`}lvP9T36}cqK\J0oࡋ1]Z0ɩ95G}*E[5V5unlNG_u@umXre ZhRP܂Pc\_ӵSl9j"QCH5U8^YW6Z1! 䳜.:ZIJgOy 2Q9Q&@*U7J',` 3rr9SquL2 _J?fӣ؞ž𭾴{mkF*X&&Jy0[xĂʵn=;tͦZy>o4Qy= {)^iitO6kIXY[.W7n1*BI%kW| R4pb~.Xj.i"]{x ֓lx(¹Lk&NpO UJ8Nn܀ ^*kyΡݨmNx6Eh"|^D8I/+xHZi@Bd?69&I-!f\߆ beso;hT~ws` 2__QIVVz&5I1}W_m4C;wJ 1\B0Nxniz8VxL=㹆es}?-tZVTY"*ԑhW !UY p|IV;cvH}OvkD`(Apc;)"m+5@I9}rp|TH6SHWҳz俤]L`#xgX.Tp~ ,Վ|B*D tGӷMhW]-r(Y/7Nn. /9uM x3 Ҥ)>h]َt/Rf\!={N)cŬY51璯mC- !čCa X쌾KoVymSsw:!ї;.%u`VkEzfACyȬUEs#?ikyg[ߋh:gA^+牢2_mm>džYdEKe6NlCbvOUv/^79TX*hy^$vqCGOϫiBvtҽi*=X54߲*2]$LWHCvfH1Wݛq1ܼY $-"X?J{?劶c'V﷟C3K ֆ'BʵQ:ad[}J*T| m:NA1Lora)_+.Uej8{9j.,PZ/*m%b o@P j(daI~x;>ɸذB5PSA+KP/Mxjk &CPw+ MjtРY/.("T XeC,uIRMXyKɈ$ j +AWڴiY?K39@xg# u"ŀ4\X9{HţT|Pqm>hϙr3J9_#y|!url@ǚ Un#WzΔ͕iWY !Oy) tT5­dN KĻN6uNljbܳxzAwe_z+V6j*fue~gQ:P-  B|j10jZ>}!_oj^f;f/{6WaeODvIsd r=4j̝sC̎Ф[`ؐMvh%@m8i #~<LãzRrsBj9-?rbgly틻5DtٓV`*ȩ:ZӉx NoIҏ%Af*R+Y`zRy'(6Cs.A&AyWñky 6\Zʑ mr>h $I}~-*ndtØ,nb;jZ..yoI aKT 3Sou`ݘ'7:Pwm2y@WwC;=9  NJ1GqYaAbY <I"qn02Yw дNVQ(/X.2Y~" )$@Ior•jPÐH&G$m9nӿ zh_,>{ ·]k&`1oK݊pťL@/ (7-ZglXbvY )Ђz V?/} p MX$[#9$6d}s;XZVگ[h0#˕Hu&9f v&sMb쪁s@'_66#DDnЖàFv0U R9L$hD<)~$y 1+<&Z&`,vT:KY[OneͱE{LgA?o qKu9SJX8ԌԤK+\nPC >`Z'jŝ/fQ1b@YJ)+|3WdGE\V!FW╚k|;|Q?Z"z0}uya;UO'wJ>'^@ftҒ#ڈ=1;Mk;RGAcUH +#(ʑvp]. x3.u%yO,񜐹`*Si)+>MλIn[ [{ad]Hʢr ?@a8&lڀ)MڏV8=ob_=_&/.h.Hb'nexNG/A(Ko ХjacY R˒} Y .V}QFW.^ x@ N5f-I.E~n]H&ѫP~\K;VQ ѥ#bF>)(hKļL {FjC6΄  qX2 b3ۊ582B^PFaW<-=~C3&ZJڹ.W<0BA6j)&gʋ!X6y$%bmucH) o(xr,G߿EM"c e:T<ic|b0{@mZy0?w--ı10˯zHW bn^$s"emJ ͊bPzeVEQ7w 툒fxgx4My ƹ/eA[>ּKZ]I ܞ_|:Sӑ7.֞Yjmx(gX|_$Xʺf- m[TpoG)=7({9, yi xau._U9Q5*,ZZFhP䢑+ApV@ >ٵ8.?_'D`_3[~UPb(T4T;Z4ߡ0k; DY`;l(pьaris@2(Z# Y4 .&JӳE7N~G2WCRތ[,;EE8Q֊AK˴m~!"FƍPMg}NKRY5x}NLgΘX[S~N P$BC,Ǜ~"|ְǥ*cy.Xh]xq%:`C,ZMo#[ڦm J8d&ʡ!]s@UeBؿb%c12%se #~