sssd-ipa-1.16.4-37.el7_8.4> H HtxHF_E ?*}}=Fn) aFam)!0gID!,f5e6c58bcf11c61261188166b0504e43ce642cd7au {n&F_E ?*}}D˃|sjQT >?xd   : 7=D   , s |PRR R(8393:3= G H I (X 4Y @\ h] ^ b ud :e ?f Bl Dt \u xv wxyYtCsssd-ipa1.16.437.el7_8.4The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._,sl7.fnal.gov oScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd "0K &/A큤A_,_,_,\/_,_,_,ba1c8676e4c041730f03c6a34c03806bae0e4441101fbaa9b20218b66bcdbcae855c62dcfb39834df05749193810dbaf9c5fbcdf8d8ab7d9a7569dff58b8ef808ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9038d7b250d65f24e6637274596ced815cac97ff098904aed4a74f30cf529b693f1cd4e2b81f25710e89049382cad30e33832b7d2322bb6f2200f647a0c582fd513rootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.4-37.el7_8.4.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.4-37.el7_8.43.0.4-14.6.0-14.0-11.16.4-37.el7_8.41.16.4-37.el7_8.41.16.4-37.el7_8.45.2-1sssd1.10.0-8.beta24.11.3^n@^}^x^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.4-37.4Alexey Tikhonov - 1.16.4-37.3Alexey Tikhonov - 1.16.4-37.2Michal Židek - 1.16.4-37.1Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1842861 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing [rhel-7.8.z] - Resolves: rhbz#1845009 - [Bug] Reduce logging about flat names [rhel-7.8.z]- Resolves: rhbz#1817380 - Removing an IPA sub-group should NOT remove the members from indirect parent that also belong to other subgroups [rhel-7.8.z]- Resolves: rhbz#1816031 - SSSD is crashing: dbus_watch_handle() is invoked with corrupted 'watch' value [rhel-7.8.z]- Resolves: rhbz#1801208 - id command taking 1+ minute for returning user information [rhel-7.8.z] - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.4-37.el7_8.41.16.4-37.el7_8.4libsss_ipa.soselinux_childsssd-ipa-1.16.4COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.4//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=803f7816e0fd60797ae5aeaca270daf4bf7ced59, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=5d9665f21d47931f40b8c95c7917990f0e9be725, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRHRRER/R RRRRRR>R!RR#R$R2R@RRR?RRRR RBR1R,RR R3RFR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RGRRRR=RARDRCYvt|pkF罴b^ߋDVmҡZ ~_cz/Ţ"3sVP.2&EGԱ{O)(Z^^V2Nw"}O"zXҔ"j"cSWۛF3kESS3x8H 䴎 t"uYI %:ʘڼH78Yޠ>hmAהg]lE[1thMR.V%>t)p;1Y8z1nγP 3YBtf7ry~F"Qb`|L<+{{z:s2PkX+hV_.|i/ #Ɗ;·T`"fUޯVHXcՁ )?y]W%!h'3'u0K%vS4CE 7 gVSP> ,|*pdUFic譂ZFK]ͩq?EM1wA^(>Z5M=wrʯuxpgrC1sF#}EA0dmGf1f>IxRф_c}h,dxr2`ӗۺ#ώ̋{-`n օ3bb>}zՠGҔVЮ000oaI`󩈡&tx_ |.H=r9^)!%.s* L7PKEtxI2!.Q"lk{iZ`A1DdK` C? P84V0o/ㆩ8ۮ(!ʾn)VsY.e$:j?H9ȵXw/7U2/tUK.Fbf>ci7lbmZose#$M$O&Ժ]x#˵3` F>om7*%ŭQR^6dfb%9sA9ht]'1N'0;|yIhLUhvLA#豃j%7ZX89WO |7Z .ֽ%E6y7NBd~0Ӝ7t&^,3mHViqW"447(|5K:qqznN8Ŀy:Mw pUFsӚE߽ BNqyld/3-~3d3+"6ځάzi'q]bYOFB.Vg_2i,ZnJnEk'~}AH1ʢKʤ֏w }MxJJyɵ?54'r 3ߜ!]Z pT"JG" vvkY4z>l,<}8\.,7ZPQlN OM֏޳C#9Щ5w@6,|T҅P ƪBn6BʠS@k>pvlSa"?0Ʈl6(i^E5ED /٨òuC3E]:+~Q2x FQOԫ9X{CzB~."v1kdALn-vBilS4k1581#>:x{sgelyFrV] êW vN7\44Dlt-*X9٣2Abh0V䲢F<20D\jx# <轍JH5N}.@<Y ҵ "|ĊI,/_e%|f-y@ϿJLB'6*7wv,< bLI(R㤡>WyW:(>b.airrK*-&ۀ8!6|pġHPm ʥ^qP% 9Ćl"Ĭ蟬fV3rd*OgtĬ.aB9IqI~[a{RYd!rRJb7q%'f ִַ 1pYxN6&20}w򰻤P~j]@pv4]jX:k~owun>KT{o2.ޓq9Q\BF+>MWY A%VJ9,~jG-0`iفa1u]uJ1 ^̗ o*YSnҖ",wpy)DbG{vfQ|t6fY4 DQy 5A^8qr\MinVqܝ]8hԕ&P4h̎?> kS֋!8U#P#eHN:}JvѝQcչ&Lǃ:$g0Q'fpRxBt3w7 =ҮZ֥Y'c=p0f.77ij~~-֞dn>o1s##{Nw<<2֖͘Q'5#툑cT)ڷq[ -#yu\ l<8)Ok#bTWkQ΋7->'U+)KrCQ6r86Zk_ܕ5-XuF8+R=IGy* k?tp~@_3VXHFkR}B?Rݘdwv'%,$s ΋$X5iV}.iBi>C:qЬ2/ym&U8Im]ͫ!,2lv:G/8IKM-`c5<, dxϹ WD1.&LevL.HщAFwՆOrOQnrC&o/,2e!qh{P@eWj⠝hck lxτp*6^$_kY`cQ1+6I~hpxt'c.cUxY9Y6㕠{ȼ}49pN0{ϠߪjvP>e mlS;A?bO.PPRTU r6a Td8*/;bU6 P0=Z.);U%Hca`geհHn4ܰ=T! v_C^61^?m%or =ğ5g ttRBaPb74:gs:jC\A֓-w~2M=~#J- }v fW6c4z |V`LnRWy,?%:RC6\ 54օ±H1#)`>\gWoT`܀ckAz]ҁ/ gt-uF4Z)iO-[S!*`σrx,jw\0ʪWnCpyɰZV)'jC_jV(@I/DޯyV%W`r<|wTERzKv› Fg $G'=BR{xsv{):y0)#ŽX3Iaᮔ:_h]Ov:f;3,ըrGB'([D 1RJv;v^{w pp,UVS2njK ߶vc2旱WFΪ? O>!R}=(X]]P"t6t٣j%.wݎN6k7N Qب6XdFX,:ŎA,F^kc狾فvCuZ-~8Y̐MG/#٪4i$eH JΔ튠y~%B rߐoyΗ5\rna܁GVH)cک!nqWMor3W{)$?6 j_Z(\zMȐM#;~jL'+VQ76,u~q?ʓ(CWRA@@y]{fsh2Y]sIk[(wuYI{q9DBP|t[s|}j_iο^CXj\<Vi_lO*@ܵ9W RtP\zWm:w{,SEYBq BSb(bڴ%sK1MzgO.;۷?&a-+FYHӘ 嶱s$4.(l~QVoKeb[K` eY]pv Ƃ6#Fz()/ڊgjdl~ȇ Ge\J[1:ؾ!>sf*lg h C8},8CH&w1ā6^tVr@F;-8KD4$L1tٰ&`R7 ܬjy7pl~&`B]0I[2k2ݜPȕ IX9Y0yҭX-<\`|5@Fm?ߪ 5\ M_Kt- PY@8k̺PpJñ!Hiz yxh3o!WLqÎen v֛Oظۊ*8x"L-$+=缘F5<$jSb8WaBO^ICI2Sf6IX=py>?J8@4ܓ+Ԣ9~fIͱ˦qV罠:U >=~#Ꞅ?/Fa5Fld1#Lz#i;=n"<\/]sų+E9C:1Ѵ<1f~->Zxc~wLxUP.],-y"Ö;"U b-xCMƈ2RܦdྶtM$EG֩0 J+ĞH^HP۹UnXD3ڒsEy GBYq{!fUpk6s]EHȻu~k;~#(N-XqxpB;:Rf$˽ڵ%:DÓ^<}~+dHOn: rAau4GGz3R6y k&ޝGڳYPw-h(8&ė$} j|$LN:d_EFm/]evvi8= r]K " شA I~vS0]].e R~<0 5_;_>u gIoX8kaEmp%t(G ;|mZo"V1~#nia_۫NiьH#wMmC۷ى%_싽#%Oa|hT\ڋ=~T.$,џ0 _6}8Ob3PyKWd̎ 6L=Qlf>cEe;@p7\Yߑe|]s7AݨH{k*z G aEe&qL_Ix{$+3˔HHK JJq} DBYeҤ5]pV)G[m[P<N/lUé%?&Ib& 58pM =,p}eEPiW SR4izo(PPFD }La;;zX)XsZi3a햚L[?Am+*/]tD%0 Ȓl׊%ý A+_oUwj J -cbfv@Y+P(oesB&򡓜4U1nߠc3Dy,MC^jH2h}h}kш^:UN"u0FhD8Zxg33Χ=Waa\Pó,l_=ep )b)6{ZF h:ߓN+s&rԂŦ3D@i(O<:IL8Ҕ gT..8qީ0cpe/GO!9ABm+Dov?[(C$cS\β˛o::B%Sg_2+_2)h]g6a̟ >S~hoEK): KY=G(#k !S H;=xF3|BkBf 7`?:;N~ɟR 79rgX#Gw0H'E4MkA>QQ=Ф<^X[&=?71PطqyfacO,4H+z0 mAhP(Ò#RD?&_C_8X_+Ezet;z)b} msxk]kFC Tm2;ӫ{L] `\UQ?cO4-p)]?P 'u+r1+xloQ7Vg͙\ہN#]uŹhem/ $C er&%!!3!?»eE\xQཀdl Ц1خ@"y < kFJfF)cbsm =q)o$2D^-@oD(wMjd(b XQ;ԣr.5)7.$&#2w5r*^j[ wq~@/DY7(Ԅ$ ]_elR'bPk@ "TuMto3g }bK3Jlſm KUML(؉<2Ү++I@Vؒa=Hl+ ̽@[c\(AĎ_}bzc/{);c;֐f}4Ǣ N]mA?n  c(s@ExfqE 6ժزAA2<2`>贉;Ueɹrh$MN ±s Σ!C[e?OUQ8pBn5%ݎ@^`j.mk;xuDk>4НͻHp,=pcC/8ۊbXJ6lAjSD$&[OwDJÞY1!.9FN 2]dQ(ȻczS('D,I,~eDq,u!Pەs 0tbVClǰ|o++;US44T0>,8%π#h65]k}AӶ0Rq;MV@?׀ރ!/W`Gu8gX\GW8Y4wu򊩤MSQ7 G8B}{oEAhWExBI.Ӥ_+$pFxѦ$2] s_!iTOźUG 2mp!~̂=e9@ݦ4m&ZBEWf6{TD  ]D˔y"7օ6DV7m^5"PM}L321)YF0u6X!b"]Ϸc!6"u䇓i&Wc*+z݋ ۮX@HQ-N%,;W3ŅaB.4 nC+02jR &G!P7l~@ X|EVT1%_/P|-y[UYh?]G`j"E '9 ?b8%S~YԻAg CME/\>@k~_1TpLRy LpZ03mP9>.3P K(B|7C{$EN)5h6ߪkafdz<'o}}/ڌl+hhC&ab 4?Yjީ(]`AQˡ }XmM.mw;cX⹨rit/['I։m-a.H?apih>S7hgqWï*=YJeE_,{sXu4=1; 0+oǁ81W, O Rf6H;£wgtd>+c ?2זճkĦJuTŢc0((|,T|]{7EMVNe@/(q@EHnQnmX/.K!~'#>8Z5uX˞h/0[kX&N_˹dl<T6&n}xmNF)X'O P+mRVs8zI"[%{F՜"89e~p]"O-zGv;"GcVQʿDr!@d_&!0QDh-alv9u:H2zʺtHpC]$~i[[u, fd|_7rTK?L25,s}en)UW:J& ` p10wur/儾6\RvQ>4H weU]r \   vI? D_Z1T4r6cNU( & OаkRtxsN[U} d N h~ǵRamUfnt$(L@R#:sͤ)0EϢ1bo}eejR@\~K\ \ǶۀSou?~⽄a8k 3}ttx?L6gT|׶B7bXA>8+AV:AMg} }k垜 /(t~G<鵹Ē*@)i#e{vd.Lz)H2),Xss ~UQB2^u@K- v =3[cm}܆ߥ v nP ~7wcm: Y MBr)p@Uq`-!յ0 v(tHt6kEŖʝ/7Dp̺ZR+öS!+H;d_n,jyX$Q:H,C V6f8XVmjҝh- 3 a$l\Y%f'鼼ۋ := _,6yyw$<-%Dsn^5;ev&e 8V#! ܘt0!1բbȐ\XĒׅ۔05XL ;Lf >QU"dkX}/{fV_+ߕ6*uG[$oRwBdx lyhډprowCJ+m[iPn -F< |g$T_@Ay[E 4 t"F-:p!j{Tn`tk殡qNl'F4>@ѯ;b~7 s?AUTz4r:N N]yhgrL6'?P N*ԹRӹu Y]xytTkhoYεOhab B4"Tb&0{(v_-3!,!rO4~uCx8'Z;y[W6^-A,qNvb)IIދQ1X$`ҙ(S7Is W~BDֶƕ5BYyisx-:\CFTg!䉠^C;pzM Y \-nsT9*<}47O՜U'_+>7b2͍3 Ss.N#oS_> ڽ2-VZ&?NY-;*3oZ ԙz9d~|Ḯ̫YR+Tߺ>?O>Qɋ>C?oMjn>Z4հTts|&FjFJۻjJ ZθU._9싮K%3cD caG[L%*nAiU(ioIN7N( w,vp|%Rp]FR>`BD+YFa3UM9l0l?kfb mZyږ@Ϸ-T_aa{01/R [vz5R%N8dr( ^l̾CvgT5\:=AP)oȇ^hдq֎ dYjH)3 mA+P/>#ČFR2i\ Å77.3k{&|nwiHPtTU0r'VϧY:)i8e]pˆy>P< {I_46 q5}hIt_XFX rP~:%ϫX1$vU%{1w^,-q'5i@>7i&KRGZ}oqq.EViki.L2otwnጬŻؿ"yz!'mکtNH ׀6բ^/xp|K-:iQޏ_(OU8JY]r}9*tTG@ n:&ls .'DӒo_BO͙3 ǫz;5) OtH"Dܗt'E`}O0>~j=D-X=GC?ALqZ*n0F}Oj]s$G5 ierԢ4\nN4x<=Z{|]n;D q|ik=˅БE-c9fmTnRb>jNA`Uw=ؚP~_6x\@jvQ"xw8˛}9>f;|+O TK40Kx}UW2tѰu*l9,(uWy!6 i$ J~jDb: g9gr,k TL ciw\BMd&*42?iq?w{I $Xk8©q,V){OIʞsRْvOİ q÷m%Dў0-gK\L Ҭ7l!vaQA d_i*6۴s}yЍݾo1Y{6Ӌ$́Qca]ᤒE[6(׈[zJi-cۥO|}'"V-~.%'e{ Pz+ x}y#lG+ԣuZ0ֳ7D`?"n=v|UµSb^jɌ(\Q{j{d.=;kk&+ŜY zЉ\`LF18+;JN/ķ-_\*xbQn~PBxG5#S;4z.n;{X+pElRM#JAtѽ{g6-tZ^iڤ[]xwhR0lkdK5 )@e:RbweѢ\`mfAvpn{-d79K lz2d`*dO\&UTcH8UWwPlEutT [Cז՞lI^Lt+D7Fi Aq=H:O:2x;NϏecNgPmкz."&ݒ~1{V2NyË^6 Jޡ>fa5edd&&_2S9},QVId.?vD0Ӭ홠l3wf8d2X[Kуs HE*oԐì={ L=$j|V-Ṉ PSp}]INb,%9AS3,:D aV.|cg%o<¶NMca*`មx/Ѝ򾛋(ڀ c_c7qXI&`H@ۡ}H^}pɱvÞ6*{ʅ a*b 2gLz*f3bȗ;Cp~{C[rRq j{!t6;F"t"r7rc`qƎ h$p |&Ʒ-қDIiҋIh+}>(o߰z3c8g|d1R /ea/,f3F9~t%i2yMЃG- So_Eq}#hXeSBN. Z\LEtu$^IkӵfAY%(9߰~m*!а( S-'H2pCe n1Gd_f6(< b۪K15D z6њ󌎫c*?LCH^nSp!l2nR.'z|mʸCׁ&6_27єyiA|0]yY nlYxN r\r7j^:ܒdX7WEO<p,WEU7F;$mTɨ縄4dÔ6{Ld,a'}=1V}!k>t$ ۖ Ft^ok\_0Q[0Kn!IV.%^y U?v9t9#ʊϙH<ڹiG0v#GqƲ*< A""r38*..c 6=TmVKUHͺo؅ҾM7X1]B,[|*DZhʏXՎjHLHv)e}/ I9#Ov/{=6w.ʼBgGЈxԴ)-1%d0my+>2cdPvT& `lI邧Ӯvdcﭣr%~ FaD#mV zYc#c!Nň9[XJxBZ &c̵.K\)T\Xw^WE Zd=\cdJO9(W$C{s"ʥlm$Ԓ ({:sQ;A&2Vq 0X @g!8Ou6S.)$a"k<{V^'WWb1yb~M?ɭQlM*44&tn5o >aO) {Nv$[!Vt'$.紂9ɚHq%Ҡ`^l2m Z" ιɒ&-؅#d&s049Ovc >\M])t?Zn劗 #j ѯ&n5P3,96%rCq-X&{ CF(B|} 4ah-NTT48Ny0Nf>ѳDzDݰHoi%/6CD/fZ=TBUdyf3Z, d_%g)D:m094^ {ncND U#%t4x|f]Ќl^Y~ܐ۞><^ zkPM%1לmTr Ɠ .L`3VL_$Yn*5[7}Q$(R˳A?bdm[YUA8Ư(UF$;YFb1=,4 O]_M-,AK+&rD迊$ϳ5 ,0tea25Wz.`!Nxuu @B "q$oO5Xhd;rA2pܿ 5i̻'BGK4XMCFB\zwߞO_{rUA-hCnc,J@g|r*iur E*KR$뮯;]WP\'p}}]g ąKߘ3vNHPnD9I%D{WC||e\^X^kv nsNB!Z냇{~9!v{+B7Oix($'h=E8liK$v.і=ϫWlE:&OH: DJ<"fjKnfCY*@T0]F0Iu̠] ^LV&SqJ/lb7C6^$A׿;0 3u\kJF̫$O|/ޭ̟7ګT=h(ԚWa ;gu[ }9`'@?`s[&Ż }3;<3 1Cۛf*Oe}I% BN's6тwV ziMpkYU\IW(Uܯj@Όm<72{ è>i<]톀l{ ސ+؊^~~o9P3H*؂mR"g[K+DVxh,ٕ `֜hZK"Rc(_(8(s :K7Vr`S"E$ IޓFHDgF"q2nd?>ȭ)ʢW*:QvwGAQSVN<,]pO7(Q8M@zjh#fv_Ű5O39h K2Q] s|5%yʝvsrx `{@4_C0.>19_ƃ?*ZĖ.IG$ps' 6zII ^$Bؐ*0tm J WNظT-[hyZ\L[)g+йwϽfȒGF>Ỡ-gW 4B3±~JYq/qfD]41c1;ŧ˖IBh1km+O*]0*W]1eT&Uַ#ܟz%B$ 3bN3UZG{8KF5VexX4Fw= - ]`./N XJ6J*~Rvֲer! 厊F#S5"`.<6%L-ZD*T=< ̀o Lˋ%Oa29 o.Vwfql!UM{G&7yYyU݅%vZ`e G&oS+esTa-,e l!Z_ 7B1n j qOo[auJ]w:\ ϤIm\iYMD(4cԧ^oc7_PrMC\VGi=0k oI6ܞǐ.9@Fg^oAމC]؆H!brV Z_Ĉ` =tF9I>n4xU5ɢW:3 Dvu֜ 2FYVOvqwؠs)9Ʃ#h*y=2#Ā+fwz h(D6cln(H&kQ! *QfqO%LGׂlXVY qr%{io78@f/S*R' 2|h2e>B/Arwt^,@/<9Vrf1 AoalA?^Y86ŜR3ZI~X…[&XiZIS5ʉ_/uۤ9>)vɐ'J@ _i7+#dIpxse^ѐK>3GKK [ 8``~va,PR, 9 "dB1 nqw[do"q=ƻ׌ a;m Wt`05w}GWF`%ǁO5HtFOøUM7j e[d-6 ;4KI">{=zDٛ.O&1lF2OG[Ll*E3 Iv*BF1}5.=͆-Fv(+v:%zqS1Z0wu]Z:㕑U .C6G/샒 %fa6 %{؊xIMw {3m.}㐌W`/iJR` %fٳ %Ҳ/-OZl:@uO֌Ws43;|mhdu[jƚ&p-0qo?b7:έqMrռT!xYV3P#19:TLa-D:_R+RBSe2>Fkl[ 'sYOF|g)G/jG)X8w&ٌfKL#D9Łs1.< ?7`DYqM02%)`‹;=]jU5j@n˲gR#bSA. o+lyDͩԡ!ϮH2Q;25q X^heE~[hרTCX$䢓*憰|:pnu/b]$՞ד6%|U@`\2_Q0.+L *vp|`.Z/o\ km7—Y/HLUqk`WuJښN ӝK7 k]{f=(,\r;%RM*R#]HA" )¶5?ocD!Dx}4eh>h-J T^/֌R,9kKG 2ڻ謀da(%[K\w6d[P؎e] ZOG"8#?<u&):.NcWx+a=~-NV'D`p@qvIܞua]F2XT.QX?YX.GtgH6f6gB`ZY-KN Z~(T ZA)EU` ǠSJ,?gUͼN|QSh#ߵ˃ȏ,fЄweH`LRL4»TtS80Y,-ꌪɼVr?QTPCEDe†gf=aPc!{jsPqVcˈdsEļt ^ӑBd ^-h[K߀ 2y>Gv'$bXNm Yfa-Kл`Kc͸` Ү -:PoTd>E2`ȣs)fKwW#б6UOђFzDn5>0Lj~ct: o Vg| g2ٯχw \'F:ȥ岭3vуެ [4^󬞕$ϳRߎ]_gvxtJN <Tw:)Ѐ>|& #-DWr={1MFp)zqϩHtr@1>~^=ͻL"8\3%yee=Fnچ1P9Rils@np{S.*͔Hq;(LL枾7!?$8bBI#{KPMY\2IZyM5Rba-FR-ո m]J)uP[լq ǮsTem^ qYNmbR$<<8BKWfo׍;+ΘJV ȓ!ߵMӰ{~'ƂMxUmyBكۄSK `I#`Ŀ-] AIgU:P=0p0J4PC@L`-W{Dʽv:?quDQ{6_YCݢY `~Exvib%#ؐm_rS őj<֡ƽBPҡ[l{_ůjT@L%+:D~ Xvw`` ^٤y *׺^;?v6ubr:p?TmdJf8cpтɌH!o|-7=7RiĬ܏߃+?qcF{k nM)C35V< Axkmfv86Q!wʛ[!O3&<>4SEN3q'<)(}#d_b_ _wӒ1gne ^cgTVnctc= eK&t sjj#u*敞C`#'q(~T\Ŧx_BBVX\v4Wd'ԃ,Ln C璿@Io('}0'KQNXYRY|3eo Տoʿu7KӐ$^{:D6\D2`?a\^~ƾ+Y1c싯;;r9Z?Y<*o+,>=ڶ[QdyUDܑvaم+i|.9#7 K?_µ*d*Ab|93 FlѸ{XnIttlwxZeM;dk5XɏAF>sڼ23㍢B'S\(;)m:0zeђ//$3C|쟚e,uklݖD(Zҭ[YuNgm`/{*6ٌ_IGe0<Kڊcy5ԝi+[tx'&Tx,Y ww"]L*vEl, 2>[ӿ Ec?剨(:zzu1 oHS_0\$yUwg6P}Yt?i&E|-z]'46)y& >rl.\<w}UR h On]RoNGLx*6|7I1Nև9b7{R9ެOh 00X1DaH+|3?̝~ j`_vTD@RF_6_cXSQwN# 1]r}A^(#,~LN!%y1C5{boC]h5?w=P5U_~ə&% =Ѣg;esD;!"#݀,/Βq{Av#ȗSb,vR:ބ7Yyx(y[lK`8yXC+9C|LQ/,'MmptWbg(O j z[?ǴH2Ntva.qLzCpk3osD(KY8s޵j敮 %@,si,ɊY:$N9絅vJ#N8X_1VDHh\MoSw&GPСai:a &ЊZzիY9ۯxkL鑄3:bb"W?|Iz]Ls6E@srz> ZO  Kcz2k|hX<ߕ̷#>Xb _]eۂŷU`#Qq \`':!,w0J^! ~#Xl\E j^?15C̵#&$PɔA-+8 E98}E_+\Y}[C:xG?gyC\6j-:`xW_3@\1mW ؊2Ÿ$^G?P8;/PF3Kކw5=:Rt{ ŇC #7P,繎T*]츮PhA>DڰVJb\";y$3+՛4i"0\9e<*M:IF3 `藰Ji, ʦ%4bQ_Dvw!_9~!7 pNe:z;CWcE~u4 e1/ZUn^ao nY3¨W`;x? #]o &1:[Hl/ֽ4x7ѱ+x+$ɿ,zMx2/7}vai\lQ.gKg6y!0Ht^g,zw9ГjDPI%n?B m.4cV0S.:vY{s;3Bi o7v<)ÚX& ~f6{)4;{1D 1v]'{ {#yXI&%Rp.r!N !RDg"x0a, 0- a&zxO ~-\-uMgzG/^EB!-pDc SDhnbVej+ ~ZQX,ܤ>rNcW]aAJZb)Uဉօ =6(l!?37g*8]gEU}8U~7Գ_ N >rʅk$I< ȏYAj8Gh2SU3vr܎y K&! 4s-Kt ܻWMEqcV5 RdC>g@!aDЩTyf`Tt 7Eݲ"ys_qŖfjW(q)3곕EkӋ5lDLetDf[;9SdtdMWEs61&xS|V[`Ck7+.7^F.UV= ;nW+Tg_`THZt3S8_'@f.V~%]b⎑D >w꫍U‰d q,P8๒g20i^/?dr A9L9qW +rPu/]ɛ 񇥗3x0U-jqx5otWVgՋ3Ԃy| qµ`j?#1Ζ"l~0ySa+ߌUzIv|D'ăeBw0JBDDӞH`'v LjAV/ HqTe+bXuo* L)lުy;]A(bQPCejtm3,/E?)/:%QoԥXsɶ$߸Y*Q!|a߱C <X D:{W{s9 KccVWk,ծ,T_M+`s4a 2%PJU* ߚs =.}k-s5ͪ`{)R+)bG2 'ĆǾ:F{1Vd~Km t;KOǨ@6Brr'z1MmEo7tpa`g;=XLsg ilmeFS|s9loHe|#a8fFXsi7fT?Wpy>LЧ) LE;GnKFl>[_T{^t/q%?QL&ƶj D,@|1˝)UIw& -Bb}z"/X?+ujЖo'[74Cjq(ͨoY;~@~M cbhpO`?S\AR_X^GfV|[ /@/5E3 H-VjT|ZJ/ =jN椌HN^[Esy}:Aˈ@h Cq;0޻d+5K+XQ[.@NhuZy.36n۲Cu'LZv*, n g[0/87,T~"Eu#Y`RWˤC~OpГ(=Yl TEZN=3 vgǢhZV."s715qWX`gx40&f73Cڑ AP@Z0W6(V9*@(m4f*۸r81ttoHyY g~4iJ6uH%tK/`tY?MYp)1Rʧvd󧧼]o5KeN!f`{LrZp}* \L(/15h8:~RwbUix %I%~9 y_NWIOM|ԤJs{AF8}o31CAV,?0ju&[ ӏ˝զXRkP.THfs|б&UQS&uJZCFl(8*C|>EB*+sT׸;'$h%⯻Wp1B\<fTפJ'Ngϴ ć)Hĭt a?^vڶAP1CDn, 쇴X,}VEY5>y|<8|G72}:)ptFы %v[c0?Zz 1|}2Ici -A{jQ8F%r=}X q6 IX_~3^ P ,D#^}{'T&kd_g]zMqe*AGH(KA|Ώ!{Y[Eȼ-^I 4@A׫z/E@n lB$}ﴏ&HKx҇Xin~DYZRPZ.WmΊ|ںrkn(d.ޘ HFK\05ؼxPYS$pzKՋ,0纏oΦЍANH#]i 1(My.UzT/J Ʊˤ  YBuqu2paVPa nv˩& ދU&bdMzu [Yb#"]6'9-`H!r?-Β/Vi|)2/{RD7%<@w-b)&{!Bª)!mDDz _TOf xF-)?82g 2ڐgܒ>60ڊ2+}gD^MϞÚN[܎&5Avbg~7FG3,_XhUxqQp[9+86yuσv970^ĞVpPZ9I0 S/y'ׇ~#"p+zK U[ 5Ju`>S?Q>ۃcYyVH4WKPmupYT<t]W9Jk|&gIRDTq|Q=J@8aq웢YXB:W^Y0ۡ mz08hP]sUQh|W_Kem݅ʥħ |{ꗧ=RX_cŃNo(g#b\O궭 |Zeb**TYdK5{l0}gYqR:E#p N_? yi\(B o錶~n[bn6aNsdkFH@k{"_rE}qo+.&4/El1}S2KEpȲZ4޵'̶QT(qa҆zZb/0 ZTD591OƑKC']\R/Ej~UR8&h bn?rLE Y.qBãoC,C[ؐL ,e.Z=NL_>Z"] Y׹=2XPH'(F\@ ?\ncnL OciJ!Ge{fՑ/Ug0RqY{z8a1/lL;yEC^)ZXJicqhyl #Ns1OG[xn70ޯwIK8xNW_wlp2LHN虌d3A07: I;}a&Gq֞ơ^0M\TO#3j-/xOA14Xd8R?w> zSk s>ujT-H{GڥILy o9o}qG2@y!L5JywXaxh8)淁DJͽHFf"U{Bq>,<6'7'(qᡷrjږ?nLF&p/U>ѫ^v˰k?Z]ƍDcbG\ZkV[[1)< #uyDXp &gQw eI0Dsm]QT*X-3N i-J„ 5ۈ[}ԇ܈5 ]ʺ/ FX T%({D;bs{`W+E @fx-؃peKr)z=8*3 2h{ʼŞUQ2sI?qnYWFv@Dohp#ja .gi#ӹ?齥P8yYÞiSy^>`1SS̴{C/?Z^܆N1~X =pE,} `>qAO3Yu+afO`oLٴ@ 3nAkR֊A5L*h䝏`"b(rIK LµjJ4Gb=׎Khh9[T]ת+#aX)9 :2oKWҮ}vS+VAk½ ^qC䠂cwy(V-l1O..gf.)yzV (x<!EFfU7pkya53x tv=)iB" u@k+oXk^2~0|Wޮ.k7Tׄ}PS"oV5v`0tpLw(,vͱ V 2p֮ iM}",x*> \GR4 '&(CJ^q?} E'NB8%@$dPJAhT:p /" 5hQ)jq'lEoRT < YhW*6LY*Σ>\ig)#YqNg(^B ?bgo}}[-$1Y3 xwAdE1CCx l, 8!5ԫ+J.+Ua[TSko=%ooA'i+doȠ{;ۓ[aUl;=ARN"SIgk߱u-2H M*=Nb?15Wa3lqmg ]R~twuφPle R5-NX6YcR;cG MKi܌Ku߫n(T0_^q?#&BH̖%em*oj,kXPdxXqme$d1ωkole!8+R.V4u*l\j[}+%C?9&6ghAz&1VG' FK3J vIXuE|+LF 2x[j~7i;#˜=q0a9)fߑ$2a,BU 8tIx;,>L(a]w!M` U٬V'.{6BfPΣl7HSF+@Z9 UG=}TDm m G;^.1OI2">?́,erkFȄpB睫U@*)xM_odk6a"2 Tf`(B2Jl:X+&:j XaH?q u-M%c}nŔ^FTL'\ySd6#Ah6`ۢF,t9ܚߞ -|{%{d”U >]4/ƨKJ9GW .ޏ36 G{K$PlNʱY&?G2\ pie4[Grmoh׫e^/U6Tdʧ &NkB%:1F {reSHEhي))~ ]fAADTC=PB Sb]Q֌J< ƇlOPVPCU'>qm ʕSw#*2ٺI#"],9݂r<#N}sq]TKO | NPk{@~?ޮ 2`X;@o2 :m M{_gӾfgsmv۴8n=\D35[=(z4@{#fC1nߝ단E>OI>;Xt6^|!UI boY{ъ^ӫxl)n֑Ev𨧧sc-i14@Y:^ZסujmZ#oqf2ڞ&ϣdUGaˋas З;^`m}}ƏX0sAxTš84*(x/q tު$Q+"yyȂ,Qy砉O }Y:ȯ 6 , 3j>29e됖ڿ-UGVKN b/AL1!i>)>'+ǼTbW(7<%ifS`Sz aC4,-:^^ `gbCw$P)Djel=Y?R%3SG)no9q>M]%QGk-.&*?uD7wKZ=c LG PC@EѾ$B]&D>!j GxqMl"ɢo)L|&l 5z׍7^E`K G|-i2f3>Ho!=j,(U74IőR%^)awRCz}Ƕ x{q"{o߆`]U[߯y*_*TzYgcL2o 4lŤYsQᘯKP4.1BZ@OsmUWī#iJE%&`vg99QY-*&AŇL%5g( dkWe&') GǷD\(tio~8CXP="C 58ЗpkqRi'^eFc6BeBi%` oʘQ!{d(V7g*GWm^~#9OL6VR'‚ry;|omdw*T~2#qg`6x3o` q7PV(%sGg .1_DRWPXFݤ%&_S,"ȴsӻpreLlf[Zh8#L N=Kb1ϵxp|jg<4&j؏: #mѣNѴ i f6uXJx>Ǝ|>&8'wn\bYm hb5jA_??;ď4A3ee*]?!6Ѡht`opi!WķnߘQu&y8NC $(ϠV>[/63:8^6nқ408˓Am" iuV7YNZTYȪn9 M\%]0]Vޱ@TȈֈ\+9# i3ufb)g%0-=K(c^j mؙkaf5s) ZKCP [])T#Vk^ݷĦPD;сh=_a6a惾FX6m_ q&8Seg@P@w*A ߵ02>3Йj`3TL,e(pɪ Q'PodD.:B,)4R/˺pjaTN 閝,-dv8EM}Ȕ읱sF*,]37AG,p #vĝ#6ފaxN!i>h'FV⏚ת+?=A1 EvdBVˋ2pynsL^:jVT I_K{6o*IJ5CG_oYJshu ֠G9Hr/HV+ "VKVd_R Kɉ*#v$q3Nը)2G`_)A? m"}TkM4%5 .=XEE+6rX_\]D,wXA*Z֘)V0mAxX<Y{, 9LO^)3тocAFjcUou˺~cDw#vM|Hz?d.#h$ç2bv8+ I1vdD3<` 8(+*kYW ё,dJ5:yz~K.&GE0&%$r:zF"  n6;bTHˮ\n~_OԷY1sA۷Cul V)b±#F$*>d.'/zN[dɗTPJ:m)M6T!U:IvqA挫wbPmY|)d"?z27xSG;o 3Oryy@8@YÎ8~im:?=lG*/`"\$lۯ.!~hcz!\( S'\Ε%wel>|lY1{u>Ɔd˺v=綼8ٿ>Q?{;9T~JҜS=8|zL7mQthÓBḑkr*gv]B|iϜL-{QVLϚ]:UR3i }S{J S}t^Kc}*Xr_ȒL͠ zcM#68HZF'kaRCB܁έ4^! !Ķa;0?ۿѣ=wP^Uɑ-^n:9P/F=+ai-25(\H媴>wy&LI7?W{jݓ P7Em%o{ s3pEnuR5{M7*r>[_k5|hMAlx E%]jSҌ=2p xᒗ4aTqÇ2d1׍/,Q=IJ"mJ'wx9@->Au `#s޲@;a8'P,dJ&=Is\ume"2_&!Z<%z=Ths}*vb`]cuz_O@Bg+ٌY&`4lj1-\vN Ma ]8Gc2%'+;F7A U3aiyw[Inע,=Q+0]FŎ#]q$krb 'j' hd%/`ŽdL"wY1 @Te}е׋5=婄=:ݮ<2i'!nJO$9T8q;k${RT|M)7e(Ngn7Ԉq.Q qiՖt#w1@!>{xZ0_^ؼf*'5tWqd=ĿsvKF~»޹9Z a=4v4jDŽJKHVI92b5-Zh݌8f"CK*L&)$zP\DnfF/p+3^r&wK4`ڂi Ku2ũ&5P]j駧!t|A:( Ps-^D۠]EV{DF:"i}b6!S"Mn]6 -lm18T[͎X>g8߄,ꡋN TlZ}BSH*Կ1Yp; ďӇk1!/"ch*gE ᶭl@^QR*PaXYrNU(iILeec 7J&fҝ=.ۭ}-e'vsXvݘf0T%~s /#d8eX+Vo8jshtڷ2z;[_ȗGc,<]_~b6Lckc)w&w(csE6;5}>wio85r1JbtJCPaq=xgBQ ;o!v%Mc*]׳OMDIwC4 {:7:fnMl`IB$$0CǓ/S6ǕU!?Cj1>lk)kRբafp]9 c! Өg!8$"ÞHuwf-6fɕQ :SJ9=qLNj#2B[Y6u NVe;GwqzOOKAƷybd- \ſ/s#bY0)(vhة4I?nѳC+YN2"Xu+ ͰRD[%5TOUN鉍WaD *7]/Ӫ3zr ǘUc ,`D 4̀s3-z&/ PO ۯy!9/IwCxp* s&gu)oR!ׇvY8"r=XuOi9d-kDA/ G>=:BÕm>ql.}:4--dhgsT2F&]BT#@Fg%O:D=:Gb4‡rcT׼ {CZ&}}.D-$ZWý+W's_jsτKQ*;Ϸi4Q[͛4:8%N "4WFe–]Lgau0޷3HˆtrOˎ3lkP!'8hD4 >RVTq@B7\YH ,:\3F, 5;FQ¡lKSH7\K+fDf*,QVQ# 3$&ДЗV-~^ VK8+٩҈$BZOH#3,Qc+IeщRd9_nO 맢%9L)*fvд 9ySriy硍V3O`x#W₰QF l78[|&J!E{̷H{U*4l#bDmHXY}֩rY}R4 +Q2.rT濷ös138p E֔4y6|ܢzO .u )~I6 !Of]C+~Nw7=TvZuWUbfyW;|\kzɶ,Wt!jUHMwIZGD4rH:0@e':ǤDn/QKU}ׅh/id>v8{8Ǩs2Z&:< $v<=qT̯d}m#:\IG{R*%T]]aK ?wS‡d{StGϙ@yZ)i\nR:у<sZ0Y ޖ5 ʸ;a7q_[nsT; Z̓OJ{76_uJ4wx)62kh*F7)͌$r;;4tS~/j$9'[Kyvja,$R}#H]Nݣs.B|# 4 Dyr]W …Xp#.c\EK0RQ[G{bTVYa[Lb3"K]ȋM+:c4DF( c|2.rZ1S~HL } 5x [4A )B9ҮC"ܪtb?(^~e',9lVaD-뷺;MF֔HGf!j!hv>`baf]߷ M&3'2PcPu+iӮIF[ A2aYy.ƪ7,Osd!_4tLK!=k*++_Bj ŅbUn2ޓB]_7ԣ? "[*6HJO8ů-RQ4btJA;Lis3\KYCJ<>jMk裯JST [ _$EEՍhB s!i73f-1pc$dvaH1-#2SD pcMyv~`80!8HT@Z /-C(;<@rbP?2% g@ ayFzJ:bM8vqe?"^k"(WF!j>`zkg{}dyw.1 ؤ2oTf҆Q8ܯ{7yiq4{:"*7vs"*ɾu1;jnv%= i)/b]%IgQPX[ © d+lS'vEi pde/ {xEy+[BUA:9q.11mR!6Ăk qk%n&fy݃U^Lp/a%]K`:Lj=?UQQ9MS]Q9<)Q pV9m=YF;|3Qh/HyӛI>}MQ8Qu y4jiUr}-NkYUa utm-iǬs̘RXUoB͒s yN(,5wIP(LŮ~Pnsh^n`f 52vL~piW\4l\+pi_XA{8. ;YY3;V!^ZpeY{Q5z2b@`}xҿ4SQ; dEz L9N\MOn(_kp)iы0U o.+kժvug#.Ihn <$ǡ^}J[Hrԟ;n_#:A ז2r޾3֬(lj^ bW2y'ѷ .VzP)R GTF~8`KK!Ar0C6 J5ʈēN \RsN7;[ҶgD݀mdP ͰPUt}X2&ø?߬*G/pfUT1 [;Oʍʦ |.+:@fN?Hb_gdYdC99hM˵gZ%8!oo8f;fskDx̦ s?xfIq~J*H_㆘Io0WQf^ VYf`9l\ D*!;0>RThk:]nI \`81g))'ᅼ,d1?q(7`H!Mbq|e!9Mᤈ3bEҸ+*Mu t@<|Cn!)*ddA0<1]33/`2) c>-1bjK_PsȒlA# v~f^EJL< ŽO[8w<>)Qa̋SAmv6`qzĪET^D#V YOhszmjXr򫑣FuI5Hw wx ,:q|Qݛ̢G]Iu@ ܵWC=y0 lh~Qzj\x?iv(:SeXTp]EMכa1F{`fy7kM\= {9[sXbGF*rM YcCܸOkˁ}KCPIc?;-cgZhS@?:8] }пJnYX8 &[2Pg,Ǡ|$}^.iљ^6vHxYgN:ѡqh#j aqx\WD;jFHm? ϳb]JaI۵ ;¶yAJDT c GIzy# o+F@2qӹLar9pZ-|.,h7ذxVΉ==I̔2Ԍ"B1 ~J/0j}4:=0K!9큆'Dy2:~ZZ?b;;e)Ԉٱ8V% UJDYElZ/%Rϳ!#F2{EV wykI4X<ĮʑDZU>ҿ+ eQnņ%"51 WU @sfiT/FB$pLa&5_t: lUd }O1ܐ:=JoC ysI3HzՀpj>V.ؐ=C#(O n :oeE(P6>7sSJvf ?E![A}Զ5+TOݶ #7=W&.xy iz|~SE>=CQL؄mE#^E1`UjL)kcþ:ѲR@qLszZ%2w]șLLRO(XHƐ HFx=Eg 2>Gv yɃ? ka[g%Вܦz$,zv-xN|{-Yeuv :'?>]r wP3`fO :e(x.زvLk|%xد@SˢyBYh0M@V@CFIނ 6jG%CӺ IaЮZZйنSmB'ꭍP]=[44Rs{#5ɩdG,1;nk<^NZnkr\$:C5+FE8^ޟ!KSv`b5\Z%L\ #q7+MJy aKl.Nńܥ_ bZ. ԃ/| Ċ<0;G9' &IV)q-\.|Ny_:%ūQrӟ^*ʏ9@spf{*N9{3/;벡+dhj^FՐHX{9 PLHIj,lB$lx%SBƩyU'9BdϦNV {<ИvMY ܽDTW/|gphr:.IwEl3J+ͨ!LJN?7D@"XG'݈7Đ5WZDF UiKC˷/2㦕X]PV"qo%NwH2H϶OU\<4\zb7Zx7c +E sZVX ȣ:i##^QR[weCFc| "Xf1A5qb[!Lf->LvF-LfIENkrZqlOOi44`xo\H(xBZH=}LB4HXq5+#;7Jr卖J.Tq~53WQ( Qb9i},wkS\a_a!&)":z@abS3䘀 h6hzrjPWڥ_ ;SA _ţ (Kx: D 4ϝPIW@G;^u%gԗRqE sǶO;(gkQUt/EF=kG Jr +'/{2 l|iD-|_/CxrcII"5:ȴ4;hmݺjLH߂%xq&|M/يº[t[W^a]U3ʵaו8H/SWȴo݄$_":ON;+SA`ʮ|3:4. UM%VrZ2ú"Ї-ͥ^q|Vc,a5dA#2E@m86Y0b &Boq!`4%aJ+]D A-8*)2%qu%"-It-mfS<\ 뮬 gUBz}&_K~k:lrLI`凼^PS([#xTWa Oo}c\DF(iZ%tÁus"Yhk'lx_"14?-5P/'e7ƧM4̱s?2HYJߦZDlŰ / z&\w-$N:TsU?J =,1U%=C((^4]O]9x@nZ(r[ ¬۱}:4Bȸ#u3I轞P%)ىVq_L{>XҎx$!;'6R!6"U`ۻ>,5{.Bi[z9I%9]Hoՠkk҆'9W/q[R 斋oslTlxoS^Q_pB&J{=1F6U1h^$T3=6VPjj7_OcVH_i1k(/w3`"G9(#7_^ѳL(]Bz9dHI +KSi ooNŊsS6+)Ȧq\< v[(aQu2RRv+Hy T~^qW'ČW[8 vpU&:C~!6=ehgC|4\i|㠮)uf"T(\'\ :4?Em*%]O{PżrjVk{7T0`. X)ʓ &,?1 VX47*{)8W]mS$Ͱ+T^nRGɿw~_f m$RoWNxvqx>?Ҹ1[4<- ̓2xXvspttqٍ/G+8:ka98'̸)w&!:c{Ԏ wп}qI}}srs@a@|]NeR#c~qX}xX`LeF |"!&quP˰M*,5k=ff'*h2Bҫ P09TbȪS VRZ[E;Bd&At:=(1C;ſ_ yζ">z{>ݡGW!YS㬎ùD-$x;ގ7յM;8>=OQr1r4s^a M~HzdU m"VQmҮe3KHhEK(ǩ /6&zKng/iTH4XۉhVaW%8COoḱD#bAClJV}ھ~<#1[zJ,.JY ǹd"6? O@}4+NiksSNtEuew賢_{zQv+9Cv.'?uzYՄ-%dW&f{kl` 3ĈSIsi la`}E \;֐Y& oWJ6M5"21m?`~_8'?݆ xMI'ȣ=Xd"7kk);z~?W,IbͰNH|A.eQ`"ҠVGʢExKvn:bV `nY2¬r_^'K15swiPΌ1mD# w;J^ EGĢш%톄J9:ڧ#5 nX`|Ǫ]*lcpMIO|˴q6/E W?+(pmpu KHxL(-OmA@0f4セz= 7N,b;' ha`4*Jb,[fymmfAxɔLHYҎwX4]}(zKvZI&}eQ͟0W˿/M:?e]=DYE(ʈ6zVzg˃ ˖>7]CCctc`n* V_/bԍu (OKFh= _U 0aSˏM ߫xՓ"~TGjn4Qt9&M؏jIۋ@r\͍Ql[Z?Hw\p_#JOh 6xϷ& 벓i:j6D+H2l>=8_wCv~ݹVTAVd72*y押W}l#W{YHe@Z#8Nڌ :;5HD/k?h5oZ2Jӿe9cLQ`¦vәTtbyZ@|bNBt<~,'G9T-ie0kNaAKV7@9v;p'8 Y&²B#% ccWo/nBtӤ̩氩S-ƳZI > N]c4_d_qD]#Nx/e6':#3YF8d3pUjQR9<ʹj|zoqYv_V!PN` c d@C',poM}n[ r^{L+4BHFַr+T/H' 1BJ=ipiY?B5{|Fu9㫸d`~2nR|9ʂ_w3 BMOp k9N7=B tLI q^/@J/q/ޟ<7-hsj;zp(8Uy}y֣[%@Y]4O 枈6Mt w*奷NR SYµD5@'+U*͚/F"ܴX/ ~?}2/6 z^{ / $_u݄p@6>hwPhLU\&Me})n<&mG;]r;I3}L$Ayפ4>kd|B=L{d||6uLK"n䏪@ps, myk9dH:iW֣ϛ|]8V/nsn{絼[Cˊ֚^ WB]\?p|}*E:zW&n$`d"ozjs0Q6[ Q:uLb|2I lCEJE}]U.·A49mFWvzAq 8z6Xe„+j6䁙60V{p _k%ƸhޡtJ",^y=U]j*ztfFzT%өQpAk# pjm}@0U EM[W3/7`A " JYpOex'7|ig9폀*|,܈S+a_u6,ɒ @]kVEOu>WwҮUW,+ڝug-G按kHSCCA"V0ѭ_nx]'¤#QnPGB]V fV-ƯNIGXB,%~[ic-}M H9`}-$̚`Q0TGy~CST<jP.ugj׿?F B7,4Dbi6$&U~=KBĒ>=..\ܟ;qnNz^ށjHGDk><@F aMع0=NdP9i#tBcT(#zmaJa|~"`tFU#x%?K;mDIzp9&EwxV(;fFhtv~  Iwjn.8z9tpͪi}L0uH~U>;l M7^v& Wm̚fKSp:U ETQ!zN2H W,mmH`KDXήwkiQPص]2-S.XԀ9vU2u:XIa YYoDcb(FKm47F-hTkD@K>o1v+{wŊ%jY7T҉$#sB4\AA1No#Igdo8 Fm,=4]62Q!Ty f/DOru#O_LHdBZ^4\(9^1J?-x[X;h6]7, _h8(eְHxQYitϳU\ƋAexS@ ɫ6"P Y]O dE|iu Kygrf*<=_ief;s;KVUMp14b,#}R-2hR'uCJ- as }h羠cTr =P^/5{c}(؟Y#je5^m8JRƅaZ!N5u슨*yVЪi;U%/0 +rDs ˾fۣxxSam7?2$YۈXepӈ*#&yd 6lAj2UΏfs1GiB&Mrm[ȍ˭~]$oeCK~Qzlk>/lwpE@24"Zڦrs ğx5oo<*\e?2J>w X3Ga+XNKRymxbM:c)dyXj}l veS.mwo5ϫWqH֯G `e}C&=~$'d$!gfZE/vɚ:sV )LcWzpgB} dׇzt47%KElJ%餗Tau܈35uO~)[+"'2[ei}1Ve0u@ 3qdelŔ5>0wkjѷ\Ln4ɬ ~"?dp9*.G"!ЯhV#̋z֦"dҨs?WÛ %6&1D[Q|z^; F.)/Iĸi"*K:¾'OsiDJkRg1PIdޕ͏[cMW*wmzX@şwz:*aEp+Rh-a/pT\"Q{-p:MqB;3my!hT/C}=F?,񑲿RZDKkʾU%5OG K,놋ALj׺1cSɥab=|^,D0Rs98ż$9-B3j d&ʶ~ w#YAL GռpVjr/:`gwma8JLCqb"s MmEƕtKC+b#08yW*4kşNk 5J0o @/?:"ʶ,H r٨9GċmRt;+3v>T$xGչ&įuRKK0niÎ$.Jgd `ܐ8 +|KY΄&O")8jׁN+e1j,&E&AAw=zky6'T o +sA|_}4kFTa*Lu-@'&~kvWIBo봌ב7Ko_ .6>I|-% ;e̐~ЫXtpM%EQ(p nZaML:x< kQ9|SE#|{X|$Dr> U=\`I[BTN0Z4>)? G\7D߱/At)h\E_ց>Ż-8yKvbf0MnJXB-. E;u6+  /n]HTϲ^,Lsz ?ó=pӬpq>:?0^RG* t]A ;#G_Zܘ݌G5HXfVvaWY1.nZ :zW0HCw<T1OX9{_"B@[U9gϑŽ#jd 7Ia-c2 gWT;1'TN":] GF .:2*6X܇cOlaY-*0ؘ e{K<EI,wN_n}t];-mARj=Pa inJ˕L #gTgL!VU=S$\w6p _V[B0!Cl5Mޘcg?=Zx=%U]Ovڲљ6%qO*P 3sCr\B)j%go غ tm*H;N17Gd# >ħs|~5oAC<0ۚva%*h|=s7r:͠A2kjԷ$#$=rO!.M?8:}6J7W68l+ޙ@EMU0s{T;t- #t"Q${aC>uy̓%(qu8tQvEb2qЧ "Y1fCCHq(j+Y-Bz lys0՛!SRe'[vνx+ws܉ZYH:,uz}$jbďK*9eoaF&{~`{MNv8.4š1ձXy(BHAUMGM  /PY{S'5]3Z}U\G0ƽMr줈y;䑔8ˠQ.8pDCIJauX rcaCw Y @ ,9S&RclF+dKBW/ȜC *?\*?ieuj"xX~#RJ@1G4v ˁ. 3*$ykg|Jի}bځDaקŊb$*+mbP"4*8D %'\xp- Y}NnpWtuk9+'84z62?66ú Į~ Œ#AJpfΏzG$Յ})EF[YKe48<'- 6] 0Αy+} }@bJ%?}p/׹lgnʇ@sCC~49W0j>$b}T|U|+fr8;u7QVv6JD™/ \98Q~ wH9%A-[,N<9c ɖDq3_a~؎+%6M;RlEtT~iz": xNĉ('kAQnFln0ZCnkLD8a.FV\J\[/o燨xTMnaWibFRW<Kh*j ꠆@|#|Dkqr oR-F"f[ Na<>0 kN;"[peKmd7hVfdk',pǢ8[Z)hm >Qk;B\KAC1 luSB\s.Q !:xܨKx`H\U[8)e顡ɞ$J, U"c[wnJ.#X7Ȩ=޶{}'gD>s֕j]u0R (\G|7zw+>=~BBL J]ꌾ~U k5װ)QwJNI(-c'QCdU@*Z. m>fvޣHhegDJ&}1&^w&HДq|OMj0s7󴔕1e?{EKp.ttدWR,j^D!0Cn6ߓd4\98/?[GQWkeZ*tczu2  (6|3_nO3L- A38n4"bp.;S j}/TDWl~4qY%zm>.B P2=3 d-*yv!C7UaWd)'\zjLRZA| MγG8) 9Ce\0ԇvm,6 u2R4yi$z?'rY1qfͮDν z'EaVA%+ M]qd>P;4O3?]Ս_5oZg4J̏%&%AN "aee@Dܯ > !3ߥ~ѓZg vv03/ۦ. enM$ "J,gEn?)Y ,8,>:BAٮ-VK:|V17LeGhv ob 葐oex܀ WGdEb9 8$ϓi3>777=)^Z S e]ٜqVAP  -Ht!Oh 3D:n7Ֆr)neN\lBpex,o! B|dck9HFO@7/3xg^ӱPJ,3yJ g( s sᤊGnBs3; ŹHKQ^l鹭N[Ȉ>7|g8Gv!cNՑldxD)/j )5G}{Ƹ+I29 Ím]P{ϕEB\ߊ&W}as `C6$=)/ݒ:H7!YYvad{A){x0-mdRҔ0FULl}5#ųr\p"Qvz#ǸWkބ ϖo6_jjf=&nD7`_I@Ufۖt/[H?2K>}m>Jrm8rRVTӯqG%*6BۙviۈATL}wbNrD{j&wPFGhi,F]-+p8.kcvbY͚ % ZtC|,yH& OX*[ v.K>b,hx#{!|>5r fQ1?9_{l(Oٻ+fI?0!"R/ Co]&euJ ,AV(+sR!uԬSU'*&80f(t ,Y WfŜ&+s5{eTo׾%FGF.!3>*40pip)BD> }}Σ{z!;4<㝬|{P(Zee}P^o4reʡWw=b0Fa׫ezhxdTISNIڹ=t{&?E|8'uWtZYi$5&)yCZz)|U*'Іx7ƍɸJ  L>"ض?!FZ;im -~7܍m ,!. /yR)XKOlTRolyWLp=hw7V D۬Xn"RR~_=vT]i8gzvH|#W+K ʌKH`ړK#+Viu{ԇرBO3DRfm(do;Ri7ﶪ<^Z>>$Žm//#̪lĻ| 16uڴ†{5 7Om>3IaX8ͥ16O`?xw328:Tl[ʂq&r}A_57INt|"ryY X Q;ߒIcAxP_Զԟʸ-F= rw~? bqxKF7;ų_0Wl,Um;դ"{܍wtQJ2IOᩥa}Ǘ@+؊M! !T UZ{tO zPgZDaSj#$ErӡCXzl'[PqVl` d#Uod&q{H~g:RX~ZSt1fy_3EX7J@W3ZZP[`W+cxkCz v|X?jd= 墮J(Iͻǃ2hM!(! ǐs2钾>:eTއ޴.;m:suMkMS1CNXFx9m7†+av遃#nKL*7wޗ.#\-ǀC"I9AVą=@PINDB?x=0( sR+tILl# Of&wZ߫zJ5j{Xg;wELyVW"a%\^Hs1{ó[^`VnyYw9R4J%@鰚aFxR>SX S#LNwQjO-5Gz8n45\6i/lH4kDCB|];V6QjY; wh`ukɲC\!,wr>@DǵC+槗}0r'I14Y2kx7g'GY:ѴƖ\JۨB Ӣ."䚌6G)2&U3.}W0Vi5c&3 P/IA[ևuJ9RrL)wLڬ4?{<d6EATt{Ų`G1.k u%* 0ާ`GKofD!Źbx, Ah_ ɪ( 4D1ТovlzWAG Ӂ /SI0M* NXAcjdq- (<s,eż@?d #}&h `Q'Ng&_,G}OkqpTB\bnp޽JKFȷwL8A@E3Ɠk5|h:ߞɞ9yP}dŧ}Nf\mb<|EC wFAGт2c>ĕs'h>ӉϪfmdE)rCSqbXۛ^1}=}QmA~ @ZV\$ ̎83HY,POwTկ2ф6qǸ)°4rحv-a3^=A{MS4*/I*f:C2 Y[PTaW)at$Im9:. K»^Ss<`’)q.zyd .6_o>ģ:EbBcGGWqie&}/uA!%Cb8OQ<F8}\2ܝ"r%AΥt1tEiIӍg;$/4?D(9G(dd |WvugRvIT{Xw2C)'<,n/HLʕXYxZ,x+A _T|/uzRB"ClbHq1!hr>{@R(lMe2 \K K)5@eh F6 "uҵ] xy˶UmeY^nNv_فU~Zv>2BpUg{W!_jqwk ~V p3|j=$Q3*%2*ZOJtX ][\WMGw1NDȃNoZm< fŭr ͅ8}!V_z~Bਗe tR=100ҀڝlyBIr 1Q&DUvG3ZWAS*H!,|'>aDOH ?a+LW-tI4S'Ҧ+NRA@up9q\Ϻfrֿ?]CxS?.`Ж%."6ys%Y>wd<(ӉFTH[U.=c <7zG[ց ~HvMGCZm B+s l[JYy: bX/{-s0mF(;kl3U岕ѢonKoӣݰ,( v+$|ݩ; MYੲy\Rz;KTەIeO71Syg& ++iGlY؜Aʫ2I=皆lٙhO^ 6hQ IkOJ&Fo%1lzwVՀ˪vBW*Pz"?$ZXdj6D!q =Fx9;&k0k܇˹C?Eq.׼LXf_ ٢ ΋~h5 [4OrQ8!7SYu(̱wYDg攻2IrgQgU]>y  >Uk?Q+حİJpڧTf$c4 7~Pbo_;.]_{(cv5|`G-O\Iw5RR`{Q}̼B^HdM@~>]tq5y|==ic Xi4u= Y" 8T$Y& @/{t2N>:;\hSB̗z20r/*Jf玺8'SYxѥԧ.GS}6-_K6˟ VƖ#\ʂN,:# 1m81 h{U rY=<["hYNvO e벧\܇zenT~MA˜ww-6Io#rot/ ! dlƜQ{!Ѳa1[D˧7Z)ڝ,y J18|&_>&I|5,jˋC IzV w_ ۔ΔV3x[0/1-걤r;b_6`krv`uq8pzXɽs;)]je;\> N'D̠hu)r8_݋y[5w5d έ ]L\y\.nYg>¤PZgY3s<\0)6]7?>-mƶܭ:M:T;M5_wg(v+~0Q>k@ O/bsM4v||Z `ۈ4 *G9+Rhoi{FrumG҅9pe*[:&ZY`tXL<+o{>C j6?W+]\z뼍fq;ppsB_̘Aܼ&e#QU%]r\Li360f[PNI=abmPjZ>AgWbcN \X;`bsϋVskլn4b, "d}O˞20l'HǔHȞỮQ]I'g c6)z'#]r?5 ^/_+gia$&EޡQM2U "^oSnD׻ԭ0! FU 0I2$<4-|5Q{(x p3II90:;8IaYRά˸ϓa+Z{5@wF p3:hb9iIH~Hԉ Kx$Bv!3ƱLK!A:հBs|mw*m/r$Bϥif~ =m2?< l$ X3%Ȑq1  ddng~kC=ĸ-΋EXԴs- Zzڋ㖷L e8>GmPܝ@sh^~I J%8a! Mu^1 ns|=V0ʟ s$auG#?fre4A%>ܜ:<46i!Jrd򸚔z఩৲ݡbw"F DAQ~_.FQy\0 SީeQ ?JZf8,>gyk [#7V D[kY?Q U٩Zg4aG6Ľ6,7(a̓Dm8hK{(ٸ˾QK^bbd_UɭY$HEvϤоԐj#:[]mw﯇2a+'l]l;R))RU\4L )}jؠ0 dK,/=Q1j 4Kӣ~`0|RM5{DJ &bxfX?( @. Η_-]v+cւB-bnt 7c qhcS5RrwIΆBM@nyh|>fSH+Ց4orTAAHЩFntm+|\G ";ղϴ.&e!7Y-d꤮M, OsݴGM,jn!p bD0eB◪<(IPgq=R!HGf65X~`RvWt^MEmI߹ )k3U:%5~ƗS,XdP6gf3%1RLg[](>IZ*Gcڀ'&1eDsW2~A|a)0R?Y(tϯV˱t 'j$E7 <.J{2%H_SW :A&0[ZMaxLajk߯x"ʍx+'S"Rx,:⯅Q/Fsjf{Ydw^a [x땉9Q:K化6^OOD{VL) tbgfRyvkh( at #ރ)^$Lܺ}93 [aI%>Ց=lLoO(h+MwG_cjr D hJ̨44S{#[ǝ]\T2qn}|R!rx.;/~o_o>`t2'iOO݃.ۉ 6~P "xJ^ˋ>\vAmgԴ(2M<쇳lP ۱&V; LJ'l0r7"#đG&+_UiT% e*'ڄZaPO\5>l6?&m]Xiaq."5$*[z~Ro4%]2QyMpW4dcՏrˋWXq[_j0n(JJL&5&D3,ѮxikA>M9( D/ez >%dgGtk1nb(\.Jģ+hi1!jF,L,;gioŪ${;i= lc@ٻ[psL-~z|g?Tjρns{T̉b`b$|hv^c!PWU"Jn0QWkBNEz (+ 6@@۫ԓj>M/y'+ fYzTN`T˷!0>;ixo!Dje$Y&q/MR~v'zpUk1?V/\q;ҵ !f}|-˲GRC-o\{VMJUD4Atu\/vĎ0'u5Qx-X]} %8/R0&\˗E8Oy.#Mceٴ֘c+p^8,ˀ-Z7`㆝/N vDf$P3jAS )F%oY  b;k[>Ih]ϱbi`oD&"kth<*NeVDDW養DjTDIêq)j*a"L^ ͹b[PmE'+Rz5dʏL Tk'c/ qc:tGx/{gMHȌ{3Q,Q5P7Ao{ʩj̥ _? u׺fuQ׫rÐ=N<{69hTS< S*XVt%㇭I JQ}~mRyګ O q> gÊIL$7]S%[=G6MI'u-mIP%dvg^8,LYBgZ B3x}pV&"Ww\Fԇo} ;^1~v {bzɇf'Q £ȘyfC:T& ?"cqQzjiR:7S(yG"YN*,7C(0 x &([P$r g Ei})iat:+9Y'=n)Ru5A&j |WddUQ)P+Y-N% lS1}]\ץW SbFiCL2#$A'ʍ&/paG7/_U"O;AR-/BԥC 1Ik"$i]/>ڱ\b#Tpe&CDg u μ*=%_ 0yd".sGVXpBKA&B s*ˮ2rSzB)QҐzE_ly}Gl͑rUuI$Y3L mup} 6R~oD6W܅+|;hVh>}H=4ҭiRa(gńHb][bAdJD8;f͑_^5fmOt(vbDDz׵*`nFML˄gXUF_Su ^T;×QL OgRycQ(V2vE@׺#?$)̃\>QsDyb1cdu^s(>x;npjl^H]p;D?tI/1Y)"ۃ=>c-섥=9-t夠&{ ئMOM`#5Wp"j"~KmrTib2cµM>!6 LXDž43a#!Qz+^m)wax"ͷ9DXl\9UY' ܡI<EnH} k/J8 ޑNLm=Bc4UzÍyl$wY[]@*R7atɶi"Lzcb*>=ql!\-Čjn/n6ΰ&gp=j9O>ا22XSJ@2'9g8`IV.@jPƶyj) 7]0=pC$cEvI0A(c0:0Osar Bed\y)AMͿ, ߭kJusvͦi11KBʄ}3A*G,ԋ.$1;Zؼ6Mle\Cr\ UDiLRAc] de6A*10;A?w_SO2Ÿ|h&/nH!(XU-5۔۸~_=P5P(ĸ[׎v\yiƁ*:;qS#_FUilCGEk!4^})0`p,.Q&"7MwnD\!zW ʉ:$+ږ]qF<ݤQp0١;s * } /0ۀ;b* |-UYMHEls! b[0,tw;"ۧsEtJ97[9*5E+Z̢Ֆ}VvWBv UXwM< ѫ,Z|}s2Y+\N<+AER=L@&.ZC86RvPrBE̟V'Z'F7EcUQ e;z]зt!v_b$n =N]0 ⼑iVHOs&Iv,LJbA!uG $v+6h˼leJq 4$Jńdc3_-씗D&.!v9.ċpbu=cSKbѺ0?l4Oq JZr݊ x#ݰrP_ٙqz9B.d?}njU:35_wjAbqд~‚%9}VGZh&vk2K^´a2GZe+P``.@tKia& DRlGIh융RJ9𮧎"" * uGP&Zո#ѱS2_kФ}Rxɿ+{tG7$fr9*Z=m7̖eGTܒJMtN92\,R a .YPuى_t?h # iOl{FgDLmB+7}+K2!3f *IDUJ~SH[OJ紇LB#ˆ'BP0NSѡ#Ǡd%HA"K,|{N yRIٺR?_Y#NO9>bHXww2jQΑUQсPpj #֩/QqJEΥvմ {XHN/}<>ϓl}86/5mǮœ"Bff%we$w ~8 KH";QwQFwa%+^(Z!޵ZHrߝkg4Ef#LO Q? sg!0'KFq]RQ4$yCF%W}{;覇2?̮s4 ͮF[0< |c_cǻa֭zJѡe stoa {g}@wO&ŗt0E;1=F ڿJmD@kt7ƼvPYVG=. 7i D9)5 &юWMρEh 䩋&V:uP<<~X=T>KW~ &qHCw-/wD v}&T땰/VWjQc 4xcC,YUX'M5X)o#z ଦW%25kӳ0C+9T\:%S眑W \e9]ڞbtA1$4:@}K2R;} UV}J{u %mϞv NS#?΅:+ l618~S'<(JwJd$B^Vk‹ˑ,Fd8=i+7^־jW2yY}*btG;dzx@kE*q>݇ (): 1QD| i5[KYhqYaCe|k9ʧ9nLRXUa4 {x&/jscQΛ!G`1= B"՛&AU$/X\ zf 7X$)K#kl66kڈC@aLsK>v_01:&@TDx>(x< $(RInJ2SMǣuՉQ$76M$?gO0tNTsKOqt9C(iiS%mk"_20mԉviA˝Fw}E]q1$!v[}@Lr6EH"v73X3)a:A6?p$1"2IV{ =?{n"uDH+aY2.Ƈ dNjhRZBŚN8m17Y={} -P8H^:v*iCQ z^^cU)( (3ɦ.,s$F3ُ D.ncSmjax{k߼.5 ta9Pi8rl? gE~."+ 4Sc趆wm8&sۯ:Iƺ9? 7}i7v6^z(8NazR].2X@8+N~ds]`@Ț?#D>ggU- N:ā$[S3)&.%c8Tb/ Ϭ@4VMm~r<\PQU5>ݙY]vdO`5&68|ڠ9qĀTL&5cEQރ忄`Q!d}9z2ol?';SaVAz1}ucSRK:+fS)l!Àßmojyh"-x2};p'~Dh.c̻ةL }DV̸F[*(sgRAgpFٴKPc^xm bEK^|Ap,(~E]Q߂_,mمϊ|&ٝ)R85Dmv[ I0~4"D gR`x"W_1"tqJZW]-/ha>@q !UtT|awF64~E~9L5 _ϩr^-%P{@#Fuzl˻ GF}C`8K%0.0=eQZ,'d=ς3cY&6ẹyof %;&jP0Usv"~#}Q2MM+̜UWZB6mWz8Ub02$w[7!/5ҟxS J|ˍgD`f~XP<_ KӆDw3Jj[4m܆@{t0 )3TOנq-Ju2>Xn]o_S$}riva.p 4T䢟SjrĤUqMڽU05T&{9wH-k : PJbٔ_ٽSD>N<7fWuvC؂z2CUYM&Y=vsbR,tq&# bW9> v=脎ocʂ-?|${i'\V0Aq3/w 4l+,_JNvà[Пk֠kA:drJzz@84);4BFLj 7B#糖eKK;Oj5v8@v7I =}}FM%Cϥ1aN-W'͌ HޅU)} >u(|SrhSn;D$V]qWs4/JN8x Z٥Lh }Mg:ّ?}ۋ"7&3CvOò }8bdTwBl8r^/eۼ&JZf_Jˉ<5:xf'1 '+y׬izpI PLF$X,pkN6u_,|$VJslb?j;^KqQ4$Jv;aECϟiٗ˳QUb74M$SRN5 {S WdoYm=0KMhVC&vtVtWnٓPݷ\NzX++$0" 8`p6?WDq}E'Pʌ@QqV_3- k{J 票y EohC}6J3سǠ6,0l M޶vȾ$L{ 5|9bS_^dHݣ">fĥ2g@_nb("Ȣ;),HZr,f9M3@=McIʄ,)S W@lV^ SZ޾ꃵg/+zy$ҧ4 iI=[{mۦ!UR7D)hIDPʤ4O"QchwȞU!ơ7e ޭ:x棿U+ݙ+bkLf1ok <ᣝqje$hBeE&3xn<w 7z*@ssA/=\v7_?yJZקeQ6mVp{x&Ó\:T)h?BzWFإhD~hhNH)ٷem4@1ksjQ .M,ySghK?N6JyFx|rsQһ:9>/v1|S7@`M9edcкNBXw]9ڞYN_.z㚳ٍ8Ç92ujAzUba[X}b>w6YrúGIwbjR}tOi;CΖbquY i2*ë{iB$ ` ږ AN gFDx^Ga&2|6GtpMUy;'ظglŘ =w#{*ߑ|2p@EAc4m^*Rl#xF%%.ZY"9hQ?=f^̄A QѿD4<%k-ܭx?yt5Ӎ:6EELmT! =&.zw% XUUy9:k6%[g8pv #6پiQL H0z6~l|pT<-RUK '-if, $pLTX0l)Yd4Ac  d@ K/q>'[_'2x^.6-thyq;q0^J]S!z!#N?,oLW%xjuo؛ %Nb/-F1Im&{>0hp2JMʾ]o7++b~Sn<24}X6OJP}uxvopҍȩlpu'"f(Pf^pX14Qv˼}…li bVAH4 ʂv]*}Dtzs13iWy= =b)ȍa !Kij5a*>6đk_ WPH`\iG9i;j%F#pReQgEN寮q}P€;Rc/)d9XcwC%+z,20%P0{qZߵhFb\%9Cr"^ IpXR|P~Xϔt ;#u*lK(.xʳOAD\S ܧ0^!3]}Y Zy^;S>4MwC<?Ȳ#~L&Fd (de}i%c0U82CncǛ4(hyUz[:+NĐ~g_ *F + ~YN? [8Djy$B !@A0G_xpIx8V"'Զs,EL&*oHX@3s灾Xϯ$]scwRhQ.oPˈVW,-!(1X= 1N\j :cǑ@r

nUg&qѾ^3d2WgϹ֏ ۯ<(jyXC Hg+LtAWuhY13htat )/)21&`O<|g#LS/Ck/l*+KTy7\Z.,zDηV8z~yĪlc ЄGP"ޑr!+6fʸ)K߾(d:Qu-SO'sB7ohRwL%1jENQYMh>4ڙޒ%09 e­@rf6]l,G2"{r=̴5wK$x{LimokVHQ\6LIau8XbAK :}nOcv^s%^\FgIj$0g]Pw'OCO1boޠ MHT51^i'D#+6ܻdNA`eCbaR_68l-_GFm~ M!?eZ|r<sn0 ?'5'V#,p4?00ލ0B#X^X.!UՄ(jkY4}S|E.<hb%YT%A51o{ H|((Tޜv73݄ߜ"^'yֽUa7pf e\,"멍(f̭Mz"Jv,TY4y(֡" B:Mxt`gt_ѩďXx7ΣטΉ#wz_3ðEMG gy?E `י.Dр%*#q1h.OVGf H\2%6n7g.!Q1@6nA"t M{M՝Cمk3ssjMRD{S\= fڅl3mYlY?.kL_@B~e_W [}G\A90QrttUv꜐ahUߪ1{ KqȐ9޻`-6]? h.bl-ĵ]m1>-kI| zn]no/O(,INC|APjt)r"j};TIE 5hzSHF;ޫFZn_iq05Qby6{=H [YyxUB^:nk_#93{Ү?Ksաqf¶cY##u%|q_Ck@[P\年W0U J4l%3c9ƭmnw8qʣn5 \Euyۉw~G}0K c(O^&R}?:Z^g\V9Ҫ|tO/V&Åe?_G̚Y/&pEJ4: CE]!/z>0!_e26 MqMKۗPl-qm w:-X@\\sg)a\TyJ!}hd@:#i(I&GHd$l^"/Q)LXGCzk(y\t#A`Dt/}V8>mcc{vHEqouĽkW)cǒ*Œc{`JKqzmd`bwtv(<rk<'ؖ8r3!4[YP TCbcz^Zy.Wfo;rUQ+\0Lp=RIm!{;d%& gZ XkCpܑLI 'FWɩI?L1CӍR ~1" Efn;*Xva]ϛI 遞]C3Qyz?={4V*[`C$7u<3;?e {Q.\ u!3@ J fFj^X0R,<*BL?k`b FԞ&OC`v6hN~ ^w,i-9Ni/k[BTCtzd=*ݠ޾Oi[lT%CcҒ( 0rPyK6{aiiF}ӓo~_X{Qft&FBp5g:mZŁNa^| )h$9_)ʰD tׯ:/t5ES9s(v/?o˩Uv6k۲_p/M4>eyoW%G$$|9A;}ciSI~H!ٶVkH-9z#n8݀^U3ɿ3-t@q#ѴX\PVÌW[JIw?R#+; Γi8MQXLu~9hIDᅖMGg'q̑/^ peL&|-V!V`άŻ4ȧƑ,BFТNg õ2zr1y勳t%,-v'p6ӇT7}w: ǀ X}f.R@|P4T2>HUBoJib(<݃*[oEPu}ɈqX ˕ [baY8N q~{&u+R.Td7_༷Q1sI5]s^hC9uقFUiKb|5G)H(CJh)]dSJlJ$,"(_n%cYf/9T.E\DKx3DL%x.7fU1EChoFLt* V'^2;](OA$Nb-;A藍I.hW|OaXLl ݿtIk!L4{r]|6\30uEf1c9zރp@H#vkbgBw@7߱8^f*ː$)Lv?=bRo&d$t8<^ 6ख़ߓ0oD'u`<":\`4iqZϢdP~#SFs^4hAmnUuta|nӤ"q ǐv4u 1w-3s J$uk{ =8R}QB[,W ԼԃB=l`1S2fcnO$h^/M]I0dTPQq%" )QQ'6+:rJcMRD_3cˡ]9&%ANI['֐a63wi ,y:sHA _rMA58[bm*gPBw#ݺ 0x;sK_ƺS|x o}k, =lYƙ+c-L a1́(Pᆜ="9SAF"rES &}]9W,ҁ4秽oT,Ih tU$63هkzSi$ S?R3n}zqXJpĊD6 )^oH!Б~@+C^.XEp2(0˜kȦ2{;@ozvIM;lƉ4ue_w(ݏ]i^?߾T _EDd?946VuP0^[Ή_օ[YFO ,u1a@%yϽg̍ʱg8^w=Wž/'˿#2Ώ߽f9}XG.j:xMV:xo&;D1NEFssh K@R/DĨ8*% O°ݎ\Voŝe"u˝3դ?+GLB0ˊgoB%2C6[]Ymܝg;qR,Byk&7Yv܎Ծ%Ni(=# l9CupLcp2s?뼉w69 ⾋igoъwqC<'āci $ߪsu~f߲YJ9yt\W\QјD)З) _t7O28,Ei5*O)9ڝƸm1 ӱ6|`Y)HmTX(~ бS=5,`):9h[ PX_O&>OOZՆ=:P'i.i޾^o&2.]Tnuٝ[KZ?mxdZLPf38QM{^T[pDy4Q.hbxBM]/G/ЭQ@ 46hn62 }]zk4-+x|ȫ!s T\Pjf5tH*XsN/E)j@7ꫣ;?COsjdL~>CPAq IU{o 5oZf>E>.+pWְs ք<@wὐ!;hF:o:CIf-A>,vð$G~.Aigs4Xͯ~'b))Dc0!Fu9F]xeS!7eFyjYBD뀳|& q,L,Rɯ7bR{H?-`_Vƛ@lzX/tqe< haW8)lsԜƻq\sc>or0?!7=)v yO (޻=z\rҽ=Zƨ \09",l0JJ.s-4ƸKV s*',<^=޼}%k"w%f~OKٿqhڴDv)fI TcŋdpJǿ әa0TI?lo&ZJA^r0>QZy.W<_uF1r*6;Da[0Qeww n Ͼ8U$i6[J7ny{$HBp=:@RʱnF*D]Ac4 ;"ryR}Tڮ@<){@Ʈ˼d”- LOOh՘6\p:JatvAI:׮ T>RD~N>DlSN&2%a4;{AmÄP\1詳%tЗ,FJѩex{" S#T`@-`=W؂$y#@ˠ;81zBkߘ|%I +!7]]GYh08~Z j;*nNmYmz\@>8}rUJӂH0ei!u9-7'e&o];jxqQvL 2;K9SL;i,w:oLo7X O#Ǽ#FlX>BBQ1@u:Ȗå^"ܓ%(_mYъKSX[:\Zwa.{>֜!7m0UMZtILwY`x @d"4kF 7_13qqc3 "IO?"s_{DN%G, y_,G$:L[# " г<<(p|·YfrmZtsp!]B{QD.gýZVLeO>TXpՁݠi#Suž<-h{fNwĀVRE6PBD?&3Q{92ę/,b"j.9~] )H(9_ gJd8&ы<`_o$_ SN߀<旘0"O~@\$Ql`{Ӷ#`A4Fȭm>*taVOJcZU(F_[:hր?A8mdd籔R˷?l0P}ˈ9칭=LJŽKbQ.Xo2H υd}UN @e6u^ep) CҟKOaJᛳGC.q?x(,V7]&oCV071 [B^j1*`+j܃cHz[,".m(\Q\e)3g({A>fzF/'/UAk̈ Sx̖5=ġSW\b/z-ZI{APR0ưUI%4TSy2c [ !^-3L Y{Snş̵1=k+'UiQdŵrh..Uߝfx1*SaZB궼@Zl5+.۽4x0؊5QaqwBJE h!Pa?^4Or^ f{m1:AֿÆ!e'yItvxK2Eȩbgq[]5@))ElT=,749E+̎x|07 X#Āit~Mq rf2㇨ ]7-0FwLaA>}$30bST l /zbLIxZWlj!v?#vpwi˰H;·7G紏Ґ|̛^4l98P +BB/ b ۬{~>4㪞[Mgt+>CA]Kݱ$yӲ_p zqp:=`H`fThg{&kvVyU%"\6<}զз_k" .'&*͓~~oq\H !Knd%~=lc!o"!\SiW;wDhVTC-ɂOs$k^ak/Il9ֹ#9ЯͪKH"#6>DbWDQu. j`фGy^=\yK]`saIa )?_?&& 4`Nd;;ҁYX yք6 XRV *?yU*j쬁VW0a In~ E&(}@0B']ٹ{<zQg衇xEfCIGJO ;c/!JS^TP\.[1Bʌq+QSjF?d>5BFZuO̢ w3Ն5-C.QaWX#?=DCg~eʂRJx`kQJ0dm9xr ϶"d%xb(jrk)¬=8&Kt4 P`@l7e[`*0_<ȼkv H{64|ӵb;dwzԙz|G6N?BCk4"H{P^:B✋IhzءpxLlddSycƮߒ0h%#4\[12_!ZҳuJj|WFL<8g4OSX`#CpqA[âD"ጧ qYA"V [go3;/&)r$A ɔK9#%kFB-߸ʂ,yvj6Zj|*\5y[ɇjנqO-_Ϡ$L_k!7)C')/HD۟f{:LE` Zj{6)7.HYR^QQ.H_J0L=5y@_%/\P\eL5-&g~K^fL'TM"=+Y[DfZH}xYm^ҁ/O_(0}P -;#!f@ ŋI oo"{` 1X]Pwl'cZ2(p=SoNp될FA3A EwGҌӽ͛͢&*izD-XG"&;)CcMsIˈ$7 z{dLb*J"q-Nd+Ho 1v;<틝T0͆Ŀ d7\A 1I?$L >DgUy^673%/@[Ι}j >&t3]eV(;O?/ fc .4;nzJ_%?C=혬o$M Xm%:5ܿ<ӧ*.$RuGgڂpTG>vG5vK(yƖij5?.ŀks8ٞ~8d~&ŋ5;Xҡ`ue sF=3w 0=P /n>kXdFɰGپa0= 7O] 79ʌC.MoY{(wM_{=Q*PO7^LF Wv\^vjp-i1<jȋ0jwLIkEro/>5j 9e952@tVA/ . UjU|h+,y3xHJ[G_`Z0ڥCUfC32VclH'l)f::T-~ff9IfvzC'2h131+A~IΣ}R[X+g0zk/#v'emކ`wMq&s)ӓtFצ͞:P[Z1^_Dי_ȭ I vahi C"c؀u׀yx5֙눩/4y)} 5.Lx7G͚ !5ׂwm&/1ȑ?_*Ed4ȦnJOO9h"}(YZ8ry4dRblzִn;o1'!ҨO htK>"nj Uza4 %Ȱ!՚w91C'7<&(xצԱv% oySM_Cőg0%4bCF+Y@;uvљ6eO5g=Nc}B`<0v~lWi2I6FIiͪh@ufaz!z/6{(Ql <)~z&hz5НU4܍`ڒS)Dn.ߏutqoSYK?ODJ ᰱȪ ,a:lDRi,5.` H4!2Y5:2h -ƨ\` ֡$|+ ;|I\fqAJY(~ `- jU>t%y{JGubϫG=蜶Ewz_0{ )H wbb'Xַ́r'vbSUY)ܷKɟ4 Ḋ FUA.JjâmK *D˂qEn4FJFj"o*|:i_hL 6vݖ-M\ftw)1:Ee-'0 K~w H?7лCX3#k8Ԑ' 3==V4X9>eoY~f Z5px+3ZU4Xt,i֦ZuV3o9m/Kz0! [jIg۹tNn7Ot0vDcpl%]'¿ N;(+q萊;h9$`LgG޻ j·vP)&䗐Y忉HCDTiYMDnd} !(z#:73AU RGpP\%y9AZ+یpkSM_WژC0sHnݷB >#n =8q@e.56AxVΧa #ꎴ~xyGd3Ddc )ABi*\Yjܵ+rJI+狮MbY6#99-;@Dy2/1+oƨ|BYq{dK:JSe5 !w(raSK#Z$r21C©_L1f٣.O2hQ3pv _?{Z坉13ߗT !]{F빠']g`= A鬍<SSve Us,0!{aF].5D;mIM2Z.ױ +/n FIՏjVarbvgjgkYɏq^ITK!5{GFЍ܋#qir2k;FpC?PcH m:HUQ <#X$=씝<>P3ܶbp%'[ɖS@fscS8FϹoaE$幌t" A-/й+崉PJU*ĄD|<$:})O|;'B)we׷/Jn1N& hk^Kc 6nhV/,DDf}h/Wɝ_jKG0Ϸs`f.kF0PgT-Y]k˷oGA(LoT*̖" 5 wrijDc@!!Af9٩l i6h"pHG7.,BVȡ1b_i,U7?@؄2=3=*lP]rO&KHAI]ɍPoâQX@7d#yXӟoJ1FD{{#oMc=btQ"/ ʹ];cs}'8OV$[ _P"sMy:)[Hch^.Fks]VHMOtQ%57])ӚlƴLy5ٰl~H{PP)w ;B|=ZD?9;e /Rq/<̮N)R0xI(-pcݘU?b='Vj nN_A0#iI+ҖќuO4]1Nfdqw叕@i&E>5@{va~ȟ*Nq䋟Q7.B} BO-}?CoxFGShuv&myˎsGyȚxwm&/S5^#{ *I2H'ݑ7ؑ"nlpRh(yyZeH!{FѝĉHYzWiq}Z]fS+OS#|'acUf`/[ c/d`u볋qZY])Z԰G9+ ,c25 )l5I\ klzn ))E~6ҸޤY\~-+FgXN&G"uAb]S/4R֎^856K&t'^ e p2j uki->)?xQaĴ?Fpf!FސRB*B7 BT asQ{UV)*=.ICSB)A`|iԘ:JwKȡТf^?z#}^"?N*c%9N%ZKeqS=\$vUlZ"?KXF3dL<:"ʑH8k]!.Jy4?E7 &z"㌀|ZA@ 'n+KG*X#pO=`G|]Hh[\nK*ʕ]S~v~FŝM U$S 8TA6U6ȼ>đ~cxsM%Aw_yg`)}ݻQ5Q,  0_h\2ݷz9č{CC39<}l" T&ޮE$I~?3}U`Dۍu?HQ6ܻI lJڷ/o#&zhkF3/@qxSy2#-Ѻ62^o6c$qtԦ^C8F]!"$"V Mn17seC~}+<-+<WNdwz\+ZY?$FcpZ~^)PTqw{o ϔ#/C ?dÅZk+kX9?̓i|V;[7AdN4jG AEi,ߑʾ:^o7 mV&@,NN3٤R"5 nЀ"nюϚsQED(s!ΦMh XEvs򪑼aDXsĊgg- A8`\i*Mlֿ 4se#]Ÿp6+Y 8 C?.W\W9Zbsji&U 9!E;t 7寲dK[q<7pr /kxR#uK4Q;h:u#B#'`.yH51gPoBg~`WHfF΋ Wf)JR'kqQU#0&;`!]Z1**2#Ἁ2Ҹj;'Abv+Z8ViJ?geiPoҶKx%߂Oum;|q3g@hNr;c^J>:=g| P <0/ H7CJ'rv׆\8@iz~Mj/XyŖW#Nn o ځf,n*9l%sٌY%z|GV@m >PLyxq0u`V} Ca9a(` t` Y8 e}׿G`GYwqPdq('1Ye dnK )3C`[]sv XϾi8|l_P"rMtF[Em5.% O:@', Ƣ0"f#P!Xym"j,GȩHJqx{@%~MAy\ XM\6R)GW-x2o2/-řUiuA#%<ŏhWY}Viԃ;m@)gqsT^P]H0)Ko3_zB' o34Lp;hH)ppg[[h7Υ]quO(/ Ɉa77p%k͘(űŰ]"& ;2#e ,͠edOV?nSC"Jwgdҧ?dx,"̙T h7BKk{!)`}糳#h6-R3t(lRMImC2ۂӡ.tI({,j(Kɧ=:P*Lu'8{Eآ#caPֻl%|1ZjLLc)8Ձ^6&krrŇr]ln }m_^޻XcG1EUkd]_G%3YVpyWN#"NL5R/"K3`Mj ~FTF!qer3cfĆlB  s8~Ӧ.'ҎhgDbũp•)ܹf V3Xɍ C$` i/meՈsGlPJ$lj``} rYN#su19!5nR N ; q-wЦ8(=@t=4yYёySx%WAbIܚ?J(rLE T}*m:UЙzvMS?`)E̻=K"rPܮwQPs$y;H4Ho$r^`/D(8sa:X(rcu횤N4Eۙ}/ eLض;{0E25°|tY3Ft5[#K'2^"@_ ,bh,B ?JH @wx9}8!w}W6Сq߾D`p-²THbXW_-EA*4{n TMcI`z?WMEÆ1A38.ʒ)?Tʶ&}a8QGZDB.LӉč葇ܠX!d@Z U=dž,נxK:8qIEG@l uZἩ/QSf^'.;a\s#ށ|<I $O6wշ܅] 9wŚ=A'rÉy077Y n~[4b6"`]= s`\'RJ˹miȏuRDva7@ɒ%\d-DbU.K)yo(6&pVM|NBPo/*+y.X]bG(e_VF ƴ+O")ez nkhG;ra)r[xXsow٘EwA0yP0,AfAu ,eu%ymh~@wky ǁҷzz<zZaV YMcwY1gu #KbD,y?x^V!_0Jd=!R m'~cȱ@QDnY9x}=z,ΈmĆiڟ3 fOktZ$c& ]51?>sG&:΂+ŌE]]B FvX$d=_I3`E|E?ׂJ}A B.v[e oǦ{.!Yda5azF,)`2* b#Z?֖xx~6u&c\"HIBK H_$6Lɭ|a3Lk3wn]NRƜ|fϔQ U3F-mıT KlVXw.u7+-9lAQX3FWP$*_Iz3 atyv"OP&ӭ× 58Gԟ>U<<#1Z~4T )+곖+%dV<J5mޜ'8 W?5*#aFףaWٿ00rd3fls]X4wlnyy3MvB bA4_EDlK1'-`nl8(0=#iI<6תM8NUf8&E-/Z*Gfpߏ WF@Xܖj &ʯ.UFJ$ad'`k%'% 'kIW%ú_ql\|2M75d Ƒ,O)<w5hKe4 ^Cu6s_BxT7q ]YfkEĖŵH" z 5!fRJVrݲywD?|O.O9 | tFt A3Ph*/U%x:T9bݘ@'TÙ'-^C*,GUiR-;Y?E-*xik'9%[|Q 8XJ ъV39!Me ;Xס0MKg8Ҳ:f{آ2uQ<;w^w-d:P/F>(;]Xl`UUUX 5C6Y,_*C{6JのwJGou,s0xt$oyDWG!3ms~m  (7@9F_? WȷY?1SbgZmzLUfno1`%Qiq8*JSzLuB%{ T( tZ2Ӌbt(XnW*O-F1k*\&G"$N Iy^LLͱ>ЅS MR@ %j!N8yg_Ut*E^!vzA=Z JV 'z?5QZd1f c |8OMeA =azV@~I˛&Z󽧺k2v8_axsC:ĤW0AX9SOAf2G% +E_LLw@ 8^"c + .)jL?&z2vcdDsM#S, l'"pVoY W \ەC ?ZdBUqcP:BN`_*\ H@GȺ\a"EIx,rS,oJ\)Ml8i\j N ~}LD,VN[IG)%{xRP羴}RjFF r"31[px[– G?w88JN~Yժ< T& ߟ锐mXd|=q^,d^S1'@G 4#L9P-VLof~5my2yh(80 "Ho7Oً)sogLL/iT.S[aw)z@#02%˴|D}ѨC;W)'-7-p_Aȡ"Ԁj8?KHpz}f2ji0l!7}D|W}/ʛB7a濽P1LzW5x>ȗRuphm5[ ov6UьzF-uexhDaFΠI?ۄyx7o*ນ$1)=>8'[,^ T;1B,l*{(CO=7qiEγ&g>jEvWbO)/VAжWAg1;^=aϟqR/~=x΀8o|-} 6;8xi`fڰ.=D$}5zOpr]4.w 2o<ҽ9"z]XVRv8i&8VNB\6_8-:#4$&~8cW 54[j0:wz%Ǖq.QLphb> mAGFŠ,<6Q8&st[_ *95W E|FAD佁ҋb! prI մ1 D -("kVr4&ֿBL$k)WPX_ 567W- N;A,7;nZHu0 43=}{ A-m~gT$ Gz1#lr=ň}9:Sw#i+j}T fQ [g0-RAY } ߓ'yidh=[>viqd*aG|$ȼ^C:#}x*xaZɍޣOB_QoPY`yfV|$ӕKX:"z6͸!WL\nsmc0YX"=3D {^&3[D3@ܖ]Q'4жx'{ᗷPpm("UlֽƧbPadb2U@ņڰB{&K;ʊK\Ѧrd[!#G;"W:Y %)n`~X:cAjKD`j!9>q]Iw?d29ƦݦnjSsdo=3Jͼ=R3Zg,.i1ˀ* \o%VshFF?ex\/,5?ZW D >@K3_0  cF"z Z?ex}4 G(b{M1uԂ:cnod9j_(ϔBjsDl1O[%˫4ȓ .f64ϊPjqyi٪JL.>>j|=( u蘧1<8>b4CCsAIHUd M$6Y^ܿw@j (C&D?35Н(j\z8h*-3$pѴ BKE$ڇ0Gi]NAM㍅8٩>d˿dCD8pNNHM=?&p%-3EYS~L]Gȴ}UN+u7"G 3B+~Jpt]v"9y\1]^7q, ~rn^ lw;){gVRӜ Ar>K҃Sť0oat?N3itOWL5[H!셯Jy"9Wsnd-co\4c6lTf ]KvגimD#f;qg*0CPۼ4ޮ/^NQ9՚m؂E<.?9͒냝u8QG|}%)h:L1UUc;U*y mog{3~9ʖ@'#Ğ5;tC89c8 _YM,=ktKs*ɔ(1V#<@ 2 am@ S/U@ݹaZJ꼍wS6"˩A4šF dy%`,rpivhB|[kvW Dž_ϑ.7D7-w2jZSFV%#cHLPLO ؑ S0Vh[ӆϚEpٹdX: QdS9;gÉ1Cts 0 Y(/hpHɻ@l)=eɦKjY'J?#A#ؘgDZ,W *¶8KI$=՗U;.A@Xl#^<&Ɛ5}Mqn7m r3 OX8h uco@?.]03ra٠,=ܷSi?cZOp`a,ŌqZMҥ_m˚2KeJq吨ɒ)pD@+2F9x-.0W_TE**%d!: o-Er=Tux S/6Ћ2>uv>hZ^8\/n5͗57EoyP cL1#?+ӯazHR_u_`\SXϪrq̯y;`7H~ W?~$͸M[PtEN$$Qo-kI i)K@252:9u,uOg>~+3bJ̅'Pa}[(i:Qc@+JY:`m0T& Z[ b-ϑ@u3ǡi.;#Mad>ő JŠsd]'ݙo7NM2gj!$m&?OXuA6_D.lXYbɌ5G<$H? sQeRyR8҈ >5q5Lbµ.8dXx^B"6w*`~(册Z(X>v,4oi8΍˧fvi7NKNLހ=.dь ysLȔ* g$vQzB⯎k?8+Uoñh7%wyYI%2 ?_U%Ng8m,LPͿwX7DTv{cZ1/Ϟrw"I}eE#sVT{8}I@*@j724|BK©p$-WJD/["m(T@F< A݊Y&lR2Uva\F lA-nl,pŮ?\Iƞ2\&ce45;qؾR P*praQ1c:]hDKn DEFSC<:ts"ƹ8W Xn8uyu9?ؽcqȫ.vc4\ @i hs5W1k+kuoe2y#Uϛx45v<ϛMe"KбД*}pB8D rK}5(G6a"Q1HE enx=X5 5<3ft[Q7WV]4R|yS; SW+l\?a7@{qqVʗT5g&3e1a:?k1?gPUM4&zl`3#0=K݃[, Aۯz`[32|="rX߲\OCL^\}(,;mP5%LrP(jmY?'6[7u)le8^ۏKVk&k只w69O*]{oz̔aa*TPA<(w+F>962dc_ڂdl# Zt\R/_ &UHDU-GG&:BJtXT/8|v9RKE u|+iwgD%HP\B#P6ri/- n嫽sb]XYѕl[ 4~5ow:Ng"( DL=]:)&O=ޏ0Gس?nړ(#Ѕ񪃷-J FcFD8W߬A6͈ ɬ *brNϿBȆRln!~7foO1"骡*B;Z ex@VV'^&4/lt\!b[3"c2w%JiQ̘M_jQ1Ziңݛ;:yuԔ4m*aDQ[ζ$ ɤu2\{a`'z@X4'uXY:hΗPQD#zu{H*yImO:D |୤`Bvrlx[ɹv0rؿHUQ,5 m!]uT{Wz?=\ڲHQ)637 IrQbr]x!o$@'y1qjܜiK*FHBW`Q2!Oz2?%x&61b97066sفY[3C& j ]ARhL $4`C?Ea24ˮnBN ]ӊ[XgʴC< PߗnvH1r !i&"Er 4XE`kߟWt(~CIpuNlGqL/|ZE!W^o]KM H#pV6!.[j,] aO]+B++U37wI!P7C2ق/0>$O*pVQ€$20wYGԕpzN7N9}li%\ 3eY*NGtՇah@p8\!( . 7pb>ML*@w͗14LER N"=mC2дQ (g7;ȝA7s.NAz'ԟ(x\Y'vuUo™lh(-_Ze*r89^)8C㱱iLr /K<;qп-mb '\;}uͤ_RhsVJe6Y "q>_QGLOU'=t\сݔM.Ҭ+t,vpMUU+Lxp!)]+s~4%'4~`qjreJk{0b4Ճh/KiZpyNrY,jP+rt Zhad$uw*YvJfu僴I L`hWUv 7P!diq yOVg29㌅v[A!l_x:ql{w Y}788C-4#ӄ JF(:=@* !q.g.6EheX`P>?8{2ۛ&pRhDե`< Tub'~Y{󺧥ȐϠi?Kpu~}`QKH4(Ir"z-涰? w\.QӋ0Ca44DtF5 G|.Aی5o^f ~/Z% Z4 E.#ݤʳK͙Lhu K툀ٳmQtyYaagA:|[UERgFA.ZeG*(| çRCHnK4>0վˮW+l(vӏ t?셈Pk!}t)o4 nZGOpM6#:`&\ Rk 6D4-^g,C/\x\qi*,n *$ >b͌otv@(ߛy5@_{j.8"$E .f{yYfZ7oAX`f䇡Ǜ^{l)PWhJy . 'W h3",~ Rě6r^V15qa9ײXػ> 2@7# 뼋LµA,W7-Hz"~`N,"w7%tZ.RnEm*ђs!~S40p ysKY=$f|v Q9:`'|FDqA & fy>@=J01JnCِ1A ǒ)\9,!U/e_t?~{̂o#V(́ 4'?*a.A ݊ףdnvس:t0N1mz2sGsxlV9basܝ]bYp5ꅀP= 2B$ÒNZej$8jҶr+q9p[U VG&vs}8ekӖ,h#V:oT,*TzmTb,$.9EI!,4 E|[Cњ2W]~)iN-+A&yO!R}:{V!;}dFêG%7.ّb9 ߲ /*ľ]>Kc"y*Ȁ:y+ޚfT[x-& D1k:▃+ESMJ Jزz$Q 7G[m9 HsPB#*Y5 x& ug52YDb sƴCP&xL|Xt&?hlk[#.d^'$z~ @bfJMʉJ*%MPSN-"nHT%Խ}qxE%*Ƣc?;.佘wUq8z._3xjOȤ b[(=/][W̭r}H$՝;`cWQ97申DOXB e+χN)Pdw{ Z)D 6H Z'V!N[ʖv*UUAAOQum(; &y-etVp޽9JHwgZw'QT~Ԋ"UBlIǜERiFGxj/S,놊ꠚxiZǂ[)X7t̆[79ąɎ&2?'>dA* tkY$"s#\HaPh pv#ՈiZG ;3pLY(ťje,켋4O4>LEjH :(UfS4)fb+|O s*th8a (@X6jX[,-O'7w 9 I+Ɉdb+xIU8\wpK,gA n ʌw8=RENO> 5Uki iZj1HY;W!Q!Rv^s~T2](Y4<+_ov(+'BrXdGUC\*OqV-iI[]ۓY^[uJΎi2EXe=R$m UHP`o 3fW(:z{ WT>>뎂۫H8Y|A=Ƿr^:S3.'$pnDeu!{ 8I^z*`#N?":7A9O2{Cf2>;x0d@́G|J夓:E&Imr(ة7W諺>_#n++z.VTVB~`a]=b=^R'po_;nԓ&JNn$}rNĸL{HU*qtz4\)T\U#d9炳@Kk _ @3EE!=u],z?LOYk䑎>Gsl9@7 `u)YCf7kClC̎jh*۳G%tj=]x=qpS-}l!/3m%gSi2ʥzE~mRU pG~S[>U+"*RyOiHWFHo=zma >7W`†ʪP6aF '{7'7Nc){,:9|Ռ2ފT\4^DEȽQot9ADOKl|P}$A F"#Zճ5N:fZҤ$}YAM&onX[-mm%Zmm;S2΀ֶq[J3G77 Y˼x /{ǝ\7NčbPf $jd-,ǺA086gK:lz|DnC*s?./9A`yEly⣖( ~ځW4v86LN`Η  9WyֈeX߾w%; .3ի:^1 ĕ}/:@>^;f<:SHU>W,!P}t3n(C#4x 9tu1zan? v) A 3*kE .k-%9;¥?3/5|3lN~t'BEn N<*<bT(ؘu{z?hKPZj+5-"zO I\=J"3-uX;~BڙT(&a%U ƽ~ ^3 K |U~q,0 .s:=Wj9vl]fǦvPh%D~dl0^PCO=}94P2ӷv Cl0DY\Gom2(Аì E^IZ<"Sw+Eb9.uX7[|:;g<]UpkAJj#wdX $b'|S$zaW9q:xfxOnwl,ϖ[ob%}锪!5McVw1mi# J6U8?Z.6S:̮qA6|{rZ|v92&\,̿ME;.E&{rd!VRK[clJ7bf,!)~Ec"z[7}REƒgsv b@ŷ 3 @dEt$taJW֞ :>VYT컱K\( jǥhg8BnK:՟|;V_QPcAY=62.%ymmOg?mVК_˥]o/]᫒̏0G3Cjhb&TUuihmh׎7OF&y^3h2B,ow ST_Dhz4ٜ,$[TOTT\<ʾ/^MI Hf:-x*ŨUhl.K~6>4{iw.6lƀov ETFtD I"c[fӇv:8FK[j Fr ~ሁz)~/0<lNˆCHqFOTY K5|?x#'/#LΤy њ.kRkĠa܄RUky {")V. {vATEIxbz Sn 'vb8eY!~՟m7k@pOXrnJU7OX\ swY\t O=Cm-wr~̗襾PfNJf) ͖.xF%&#/l{rzud =U63?N}~T;3jQֶ! LEMﴄ^xao1f;PlyPe79cr*ego $V`bUu;ߜ%n*R:iE/Aߨˏ{@ƽ<#җ@qXgm@Hf6K|CIk~UxӴ &f+ӼvRd0@QCOZ=cf/h@Oht\ }ċP&971Z??IK!kX`^ʃ6㲉3”{Ij$^z{/;S@;7BdD$"=n@DPUAԇoEvs}| &ʃrȈB8G=@C (DGs)hثc'Msll}iEqvɉk>N@K& Y`1b!1+Kn˛v#⾕} o+phV);N+N|Tĝf) p28]O"Y>b{w!CX-=E] Z"m:b[:r` 0d}^i"tLJe1$)QŅ^4ӣH_""kSu)3dvFdmhϛn꩟7X1](Sk+/^ 'p7rbwê1,Eosa?Q{IA '}Wz|2X1FR9,WM*'vYPALos5 D;O{F(:QRƸKhÏ6}e̠>so%E# ӈe`D/.{m1VtRvOտ=.2R YmV65C&_g#ɲE+rToI3cbv\ng|س|l4&jM)/Z0ʸC~5ߴ47sIYj(؁;z6*87h܃RuԶ<3PƿBMa*2,臹6C{ŒUƗtMcBf @kZIM[dHJ0C9䐁Ij%؎LRJְN H~Uu{4%5fP`BBD |\SOD&8T0pflG_QwKP _[ՖӏybX Փt դ۸H1%ӕd/MN ANg,u-+ȆO5p<#ߤc8-$Цm>`%9Sr<?љs8D&aopJ8UQ',2߽!s$#c'C1ꘚ7'FOe{CgPfi t:,<-&yW5{)$A WsdIX #"VؕzEE#…GZ G߈ d"'ׁjS2ЀY tKf)GtF]ʯH/ؕs7bڞn xi:5DP^ǟKUMV20$" 1PZ}Y6N.1;̞.¦>a&LI4ɳ6.s y-󼼮-:}eda3ݻU JZ.6m2">SL{(C(a:޾VA *ʫ <"]Oİ"DhqڸseNw fwڿXo}iߥё5=_兰̪aH\~WUBl A^#I|+P1LVmًZb3*8@ q#6T49ۥ:8bRpFo({a_dOzp *:1nD2^qD/k,W' $?Wݹ6P>JGTt7{F'Fj.7AkVJ19NejA 粒Ǿ{)?d7pMSЏrّ0J; If9D6= !RH_^ Ggya32_i͡qYf1Aݰ3HZ#/I+Ս%E*0`n$ھ./1=bM8W«fU[|``!}?fdъ8RxSEҐx&#?}^-k&ҌƜK/UR+&DS[ԏk^? + 6oʒQoCIgחW҄{uckAi=UU/&y gEOىa׊{6jkx~=}߈)mXAnߔSueh NAB0ŽG[Hr g"R񐋞/n<\m#10|\[RE^QyfkY,dkOzpvmaD3 Rhڠ~' !vǝ}{x6Md_YȗO$k2HO kkiʣ{N(ZMV{1NYCXcS Hf(bPg # ~⭍(rN!A~Bk(A)CGzJ.vd]]~9 !rrTGf|$ 8eDg%,/ۿp[:b9K-<&12C`@| }g]sR?/ st/("bUznf^MJeVLQS=,Dbj܃ETG[EѴ/ǡ:hP==P% z乹P0,[wmnّAs2 {|D@XEqj4ˢlO@ϛ pҧ3(N- V.ll[=`3TowWOy/(JA$J/G0n{W,Q~ƞjg`*KFGg<+0 7ό҄@3MsRkݺQ8k9ͽ 7杯epD*tcqb&٩D Lę7Kѝ9_x\ `mRSiy D)/B tixƿ k9Eq:& "Y Z}xIVrZx&C$Ł`yPKM4!{J4k$ h^=6M8ZJq?oH}k:,_.y"t_ڎ$R;B̧ڈ@%*Wk>s"B ~|NpjD/,ⅲ@=%s5SS-|[(_|W Q#Ɇ@8"ghdcjP_G|BN YVGMLݧt@C *gMt8r ;EYCKW[( R^X]u[&gXɟtէvf zH]KG/uP34ƞe1kg1t$g[dp!c0*a~0-It0Ruś> H[Ȏ7CR6 й͑ VK5H&Oq ȉă]T5-9Zh}_hs5GӬ:dm!(a0q;U *_p(N lڐ] {M 1e@}ZPxClțBz3mc7NY:зaW}R$~M`ndZΈ[ '׷uAjs&F%S^2 ^rT$ 1Mx.*s 4'|"DےτۦKc1{--mCux9ԝ@c0j|F_epvg#4ޫC }i!Sxϖd1 a<]Y2MCer 70GCcY`qTxHa_ƭn6>CŘP~?wp%v[ &GWh!rh&%W\`=Tcj2S>p9J]YG8N lZG x޺1BqHAiCJ5E!.>|CEXKBAbWYny h8Y&.wAIyi0Ù&T)Oϟm֤hҌ :l䭴]Ғ*qu-qcT\$ o5& 'b,:QVFPŐnɣg|!U9זF릹rqW"n%o 0seBb7/$^ޜzgi:ۂ\m 7tS/˻ۻO%_2Z';;= XڞutgWsA`&"2wdUĈLCmܙP'0!m` yAE-vr긘_ukiϰS"Sؚa< T,M+TԵsEi_)"**Ä!X&.ƥ*IP4DC9C LHR[=r8y}B4KS4%oUn 98<Mr*΋U&& [g}B}楉O`-Z'C_E6 ~25;;3L;&E3s,[\4o¦\HD䱎Þ"q~HXGŒ 1q}]_ZJTx.6K߸# 9d,(=:Xcr- ;d$zc0jݩx7wm8Eڸ@G)2za xS=  ^KEIq,۴Kvޏq9P԰hmFcE,LbN#/s&/>|nx!M:ز 3"G"^D[,}R[t?b,"U2|Z߶2;f/MXcO$8&lX:"܋zjB eSsq75l,iAw `ɪZ;C<ՓeT1[a0Z@-7>Ѐng8F/>gZ5MD=8ZkS*  /{vj2}w@&"~,M@/B[6B՗#TUsZF) |YYQ3ߞ+Lz:ZTO'{Z!8xо~b@ ʗW=P]sa`omD\p`px7u>oNӜ`s̈́Gku?j̩{>l( Lt0cWҷn#ݕ,vCBgT([v޵In>ʫϓ(ep-(I< d݀U r97An ߽` Jz;I, 7v'4Ӓ]#TSE4ł K>@-U^>)T>:)~ z;n0f܏^] aR=~*w[_$rjJوځH^ˆnل)!_@&0Ǎ6k'j hc3߾`MNlU`ۛ'0OmLЭf7G~PE*9ЛUՂ)C5hMG<]IwWz#=KܰL91T5.JA`@dT^I}rt)t, % r^dczuKf:)όK7T I#.Lk6yp6߻!Y!RTP)[$H%D#F>$9ls\騔:򓐕_(iR 79nڈˤTz`TV~=A tDž?-q sY,m-Z,2d%ZA`P2HSEv^0;~@'\7 x&cnfUO{kg5pevhIHܡO˯L 0-I˱dtJP8[Ρ~wxI6biD~`zKu(o,:&CKg!#W.v݌EMp'Z4,!D'o">&p HSoɞ\^2{TTAu~wo)/Td[qd~xagy.4 HH52w,3ֽ,Zdy`H@0P '\ ΜŲDY-bxd$UluΣ?KͭwK-ҠVJKxH;;XX%)z@[/׹Qnkh-uگP}m/L=@1|^Z(f[3k.3/Cs2En__N$ソvޅ;1%@\d+Nۣ1ct]t]p\U]G(*B 5#YA7tfИ616eOQ́PZ־-[#u6~o=OdxUy~2Dw:,`?6tF&uB+@i \eLFCͦײĻg?xr\ bAOj%fBe=r-WcP+ ҸѴ߭`S`h0Nyw&Qhk3 CPUzΏD izu2S7@UKU5"< XM7&v~Ą챧aC.y_];0ZוZDuHRZo:-R"S pZHnQ>2 %,^Ϟ-XC2݀5_kvt&4IlcK ȵ@*MwI-NCC?sIi1LSifx o+OOv:'*5,4؛q\sI#(r,c#nvR >qpߊ%P  0Y,Kjsmir;|;ȁ@Ԗ{>:k^* (3Y[jT2<֊=1U sVwpW+V̞3mV};RKZ6p4wZ8ϔVJך$MG SϠb}V}Լ+ƴ<։bAGVpЊ튤eep<'(CߜC$r.',j xl< V9Wbcr~-ǍG3k]|ccqvB!h!t"~7 -тdĊEKhy!lP=~K2H 4C{slzcqXIoÏt&hG*fK3-ЩxR ΢h1`{α"iU_F9QF+Y!3a8 __w 4O(egY4B<}eAR6MHT?a L)o$8tOӌ^H3j*.ԗa?vƲZsO@FjPI^(gV~2D@I|Z&=3wT)"B=1q |w?~JuOGOoh3wQH򃐙a2v#j4k-y@^B >>͔[K+oaO霻dVbHѦWE\C29WI2.yV9'a]DrV]׾(J~דsAǜ=`/c{HJ+pt<]L[!jm}?E>"^;墾m'a>?"[Ş1g6>lԃ*fu-4lRV/>Qg5w {H+.}:Po\BEuT.[ OC P|>r0qkNӄSF~-ؑ0t`aտ?v @Y۽)dc 7q8Nv\uiXLROeDUG+4/V"2 Lyk4X?ƹ2fDE ڲA<+=c-j{pE}hSh()O1F"$b DQs]ˬ8dN,P5J =gE!W{ȰouyCXk*U(w"ě6pt;9ktl3r>hP,?ޙjmIZ 8qw85v|U翞aF(lU#\\z^j6  PTԧ=coc 94[C{Y&s{ީǛ^|vuɤ֊x:XH Pd- ^! (M1?z@^vQ4x9 }mW߄SÀR)wXhj(cnv"~l]^j-XԸ/;`jejkέʼF˝#'( E5X@ _էY'>V2D; -cyMĝn%{ɧ 8+`l_esf'uoSݬ*@=F~voЃPVG)v4\}X\UQvl4x*&uf`DDIP:h2Z frN"= ONpBFڔ[Tg>uڙgxӭh Ílp9> @A/B/RޯJ i{߫Wr{dvl _l%9wVTsUT1^RAZxj~>w2. 6aF]9E{V ?uZ Fh,\H+e%%.ђ@ԔRP&<@ڷxƲ p8`V>G=hcF:/:]FMT4Koc>zMzN\xxe1M;c٭CkBnZ1a@\3Oˀo<3 y:x7uiHmo'=62w'V8qe'0g|R~#P6n߼ĢL \^ }LwF'DQK@MS5,vR/ ,0{l=lӇ&0W/;A#nl ךq2@'Fd'{5 :>+[*5?(r;@AVBzZ2=q!,yY;L 0Hݥ>Y@TŮ_VMUA-$T" eLm`0L{[7.׏vӧh6*!B%XnԛoD2 eNL,Wq>##t~BGE\竐_X7Ie< G 7=.scற榃z%]f@,sH ğO;;́X{;SnKӢ//6TK,:hFxW`zq eS4+Eɰ5J2>WTtfqQbv6ZO9HHxn\UgjlĘTïӲ%Qoby?߯Z+o_"vOQBr dq' 4=U!0oX&E {>I2'.܈)X흣OaՏڰeR2ᕃԭw-S1S8uw'UBEVݥgp 3??pu /|tਖg[lfӏ~. u,v z햇 ~~OmH<5|iճ9N;.g@ˈJ=~?aB`̌d ,2JDYkrf7g"0^edȅ}/_m@r2y;.mgrˋy./&充D?=4TƌCO'qّh$i)H'E7HopրսŚ3T{^`yyV& !^[g춱޴(رI\{]7c)`> h[ Ԁ@r~Ah޽uae$Kw*`QмjPa50`֓ H- ^%C.*cJ da`D>)Oh-=ݳr"a$?w#l]sOUlH+OO|my4*JZPI^%.AlԹ{%Kk J`~}1O)f6VR!;g;׉EUsh#VHeW 4Y?-߽lsB1Y>HJʊ)-2znLlƘӮw8ͲȐbl${HjL{c=qS>Y J<cݟKȣ\ rJ7XoR?9P ?\F (6pfB7Le,ߟqi6?IjNX`Rͽ+@ZsRN|}4р L@ FiKPm̼QIr$ɗ" %c Q֩e8e3K# .@(EPPbA\-Ŧ9UEU4D]Il$B_֌nVh18W!gdAi tGps * T|qo!5{l(!ðMrO-)z%>u˄S:9y2sy˗Ԛ &@zpl7dE9 zMw[dC( 1`CCfI'?!nI y?;qTԮŭ1 ;)`_"/$]zV?Z>|Bwq#Av2~ cJدܣ@B"9LWܱ`\jWm;٤n3vKO3m꯯]p 5?l .Ivԍ9YN:PL_Foe< p L_*&xu~~RKB4\췠ž JX8 $ վMC u=qM?HDCDSr ָXZ_l~ݖrd1s^G;w` q.fFN["X du}ZO; =%Ń$|#z& {S5.%nYID79nbkp8آD<1!Cwm"~<[U\ `hC C`(=A@Mp{QfۛZÁDuٴO ޣ)tfGax ~wy*}Urh4At,I,#]]K%#-nn2rTIyS!Y] 4o[)dg %Њ(<-OARIT~HY8T4̍ XuH',"}}:TmK-MVJZZ`>-rB0VǪM^S/ޓQ%jGU<0`Y ?0$%|(|?E3 n\Jշ31# `g@ QP%f+R෻i+;¸;-` i6tzs2pmOpa[؄W#~ Ut1!40 4y:- [@QJLsC(W4;LʫV*_2Ob[u%ш\} P 16ndX9a> gQ(C1"bzIL;zRJߘ;ޮ$ƒE؎ qZܶ #CYZQߧL TWp!Cm!B{ؤK ]O*ӌ8yFJHch~?#M Ȫ%B%ݟIq1;AЮL&վJ"T| %;ހOg@1,h ؘ!|A.jcNj/+;[0X?`\P scK 7Xw00]4LOIR&:]Zc;P:~lݼ3vq>m۱s#N-݌`BLLw U 5jtUr.㕘Z_y&2|A-գGA -l0p~l).dKX? oħP;=go6xCKa#nz8 gBe34 ](8De*%W !`-W%z :92rEM]0kw53]:a< 13 >jfri S/#g7_<Ű.n3%@`ߡ\L0ٵ >2'Za53,}?wr["LG*%tKYr-}p"LE0m.&\ ̲ugK?wShf[ş D Q^!w2,c:bePxU9qS< H=,%@bS\&xOu?D* V0:ERqV]ؘ. %t-b.y d A{QtZ8gqj W#ɉF&e6Emᕱ\/M? -OFr6R N+I!5τJ}L0z , `XaHyx-[Y[!Yd=Mq(z?3 dKĒz.C^o985*T3rNM"dD7q+@(}3M(kB.hl,>Z>4;rtH?7 O:#=/KPe^Ǟe[[B03(7_GWHNfuWxW%F ~h ィ n⹮ ={ bq2ԟ#?qpA-^;+*YyH8fxzo$ n+yvMs[o`z!^&GޔɑBEU\5K? ];Ցf=CېSsK߅u@cIP-}e)) i08BlÜ,%1pd0~F,!|aO!*L''USH {c\ko$zeB34mlr]_(YTяH'2 + e!^zXpS<&2n`a{zL#+` zN˧' 32.%?=1>>ž+7Jz/ĐG-q?otsr9r-.JL2e겺?5 3U ϝ8fQ{?v 4*tCI\#@T.8C,- @/dus_ASmVȠs`$@^vLXor.:jphUZ[7oȃcg%l{!Wރ=t!z1"-UițPtH"=ˢt6^'r`ykCJ WRbir]6+!;Ŭ͒ / P>>?<ܩY$\m;GIJQҖw!`?Bmٝcjj brKՉ'Hj X^ōL\XXITK\%.:b,#LwUCM88 ==x{. io0q9-L npHcM40K49ckdBۆ&WƻhpY Sg9Z>PQLJ Xߣ={l,yF=U4h ַҘ[`_Z%x9`{_B/]bn֏mōbbz)6+gȔh^QgTOF6 gL%</+|w2뀞ă7;IڐL7rJ0tDuacS9ڼ(zkfp2+,o낑rO;kH7r6%a(#c{PM'P4t3jdey#FJrLf=HuNu &aӏPϨI]|^MSʿ'|꩷+tik *r}/?}#) [WD]K:M( 3}MI;ͰFT"z e1 }y?eo7I}ʁ`_PaaHa_8+ݏ}Zvx&25) t}R]A,59;: ]8e'+sxKCz4V1 4oWBuGj菫ݗ{3{+4nW)f>}j߽O=qVeUϱ 7D΅\b9s zT@%]ԉ'RI梳v@K-jwVD)Rp>`GahyMT]qƒ(_X ᯹h"T0 Y3y|4Y$%4o~k˙d!|9St 0m]fY?i'<b#Ի1|U1%6z#|@/պqB,fd:T}6m] !29&Ƨ#>H6?+A ڡ(T\sOcߌmzP g!F{jQa3S1 3-XPU>YNS"lδoP#=ﭦC%EZòG4Xn Gf145 )' H@I!{xvHZ"ݦ{lIHq:U-H\':'$jJ_Ճ)ӁGG/(2+T'2% 8u!BT)ɿ {Q f( 7Ts17fZ_\Qx1۠Sf%w;dY*2gRˢCj(FCWvd'Y8yo$thc$B#aiDEgA|2`lC,Rz[H E[eJcc?-0 ),B=J !u)ojޒ0 =sEd:|hbeuOE:ߝ*J־5ֲȆw40mԷ5ILZdP w#l>l(^,:gyްa. \2ƾQ˃/NMY*8-ǞhwiAG[B5P%ן^\. E(XQTof/H.=~ea]!LEۘɡ4-!DY+ F#?Ņ4 < ʨh_Y1 \#" 9s W]BCNߊp2Ptdm)x(Fqʩ69"LqYAerW*}EP/k?wy;L7V.5X N_kVwQVD-x3\ocn-B0ㄢ7]Env3Pհ?G<OLzkޑiw_Gal))m3\P0p2c ,G(4;q.F~_U'ҟ,tޯ?dEԑ Y<*&bϏ<'p*NhRr뗗I\M6xN+Z˦tr5($^a+&ʋɓǘ{ԤxBQYik?P\y3-ȐX6 PViYfKQK Rs{l2^]*63JD|Usۡ1b*5<^TGgR6Ei etPS.a?br|zo/-``da#4?DwΪ,po[@Xf 46u5`ݙot VfoQM!'AZ[9U QOe[7WPa`HH#AU' [#&Ӂ`O;"~a2eo,yEG,6\̾k3Yr%V3[U4>G r}Q$Uv= fxv'ڸ,hb)Ix鍺k*"Nڠ!ߤxdspHHdfq !bRӰ7RzG\uydFTUcDΗwm#O +v.޹`KP9xVkw~B3YL'Fy}$LC aQ/BDغ F:M9Մ"e4[SbJR9ehԿfk̜ODZbm,yCZ mR,I"~M` $Nƪ^tAo҃R`CFrsa q003S P5Sˋ !$z=f u+GmXi͐J1IK2KpT+-6qe rHW(dnUB8U ;I>0[>~ 4^")̚d5H@B4?N7>D o2ԿhmJvLaOUWcZqaQߌ$Ǘ) #8oI#x,oa[:r 5{bdIjx/"xhlT "%z?qf G2l^E0\" +RJھNFNǶ 죓rɛesfta$rƢ`)l*7x~&-[qf B]YmFl1M/e$F odtm )duxf` )(?Ea ?D ] q\ߪވrjĕX3xWGNl Bx0tw˰OV HiIA7ڞ+"pL{~i+D+0K muB;/F́TwĴGuq<_!|3z>H|ܫmb~/!A} kf6pTШw~㇛b rKK]{z8>`?e>D5:IFTGY}!n%lځFSFphKR=hc{9 #nc Hb MÒ0LEpU!'ڮ]5[1ŁK\]1OGJaoà|Z1}1m1(H.=Hq@3 uMrS-|b)~qQ4R]7MӐ'jݖ(䊌I8/u(U6FGZ@I贄 {^iqƌբ ]5sB3UCEN?\5& ^XwQp:dU@W_r#>TGj%#c{U_?%f+Uw :X4'sսs4VZʙt[0NNؠANm7U#Ys\7$7?8_i?nԔJ->k7 >(N9/9|FYbRpig]DDy~8CdQWBm>=A&=`Mޠ-ҝ"cpx2}9ME +?\kVoX·|VR0Nnj?"Y:5;67 ٮ:P4tJfF@y>)61QϾGӹ Wb4OqbuR(;i _S65c+M@Bdl}.^|F,rFki",I~qv #e:xs[㺍oCujt,_BM@eecey' Μa&X]-ДSi#+D5^`$N1AiЛzٶ$ڻga[ǭ=j $G$&`;!\1kTJ={~{]0Ҡ|~YP箮K3.Jb[E3H'(.%Mnc`?@}6ܕ=f.Mi,OQpd:R9DH*D?CwSNwsÂ#Z7qsAϯLyfDޗ %I4_ <K ʛ[%TWVtM2XhL,uwO Xe*5 ؕ}h 6j~O&u覗Pؒ+V#,B$(N+y״=ycC3xvb''x؛M>)W".@ 5be,dI(Fhg\7-3L'Ar©Xa+ ǂo $^$Nq{M#Sy` 1K9m}keOd3^zC+)_Z'&Lönd_JW3'n.u1:P0fwY7_8B)zp[8Y]ɫr9k`{\햄%n;Fc@!%5v>obΜǐd;-YWmY>X`_ǩJȡOsݨ{ܰ"~vUC&Pjs 'jױ%LgdWV%sr[0Պ" RQ;9Ϋd Y' …hy UoBD",Sg?.~9Z@H9VCxjjMPĐm7U'7LO?pKY)!(AFݟdg:s_I2\bL^9T^;FG(~[=71/97|E!V$18>&pyM@ 6YbL^;InXs&Br%ifHp&RGX>%Azۙnkv<2:߭Q f{T-Aԉ"S"X]t8Fxo\QGOg58a o`߽TZ@M&{{B(j>rG-f DQ#>倵IӹNwoCb8! }.`bwY޸3E8MxhcAfXTVF`z97u|aQ2*gIagn:{);4˷nZ˴#AϸHT:|xmɂQ@y`D7WhͱDár( I?JAM0Wě wS}uGf`j((| Nt&/ThU5@4QߵD!6Ԥ"6ф '$-1trn i"R}`؝ 8ƅ?=r\֥MNU8II{ń.fhS{ #-*=RNgUqsBptR#*iͱ6u#Ļjj2%]TBD4Y!Dz\Ae -p|ffj5ϢV;yT.wa=6#,oVB'%|YQR*⁉=C!zڴ+Xz5ݗ!l+\R pwehy0gZ5yvuL{2JJ&u0\R ltum^A2J6zɃl[Ffc^6Te ͍{Wds7\XG}.>'JUD՜>Az {G3cz;:[VEJJү@|  oO4EQs NLA]aLPn:'].%7 {kHSpYJqC ĜTvgh3 eɗМ^&X.E*@kGC2`Z)cJL/o *IZHߕ* x%26=ʶ%\9NK^ Ub#qsQyӔ̇- u5VG5rC ({:VvpgjQ<YQDMtwrqo4ْccowutO&a+ؼܙ{-P簆_=|_,0 [<:z/q6Q2Vj:v^Ƭ\> 9q4nf[eě*bRY"ikcq\^/Zyu@m}4 wȥ1&\{)D]M:U$0(P,TOɆ;_(FIi *~/EidL:F-N#G*?7]?$A!H7-%C{rw/6a8vJ@`+ԑ-n$P[1F*yeqen u1d +S}o.뇬d (ArhVyiBb{``B,35B8R\S{hyцX5Fp2ߗH}䘥NKhD zV5ۢ{QBll]Zt-`}d4JZJyJ \ky+(ȭcQSif="$~8uHԀ} %AbۃPzX—1bǒOoJ\/'D>۷ӄZ}9_!na[V/Jj,+*$DDsm+>ٵ=l&} q! ȵ՜E(ȇ/#ȝ#_OTcf?Oϒi UND(*ZٙH'{"Iq.%1yfɗBwa+%B\0x HH%^{@CJ;3{)胣h\ Pg5& UIF'1@ }\s늈Afx~/2BhncuG+` ަn7hki"Z3nb\Elbs"XbcZٍ/zLWޫ!D6NvgmFS{;$z:2a^wtpcrpReh5}6ޥ4+ԗ[ ]L$04^-E7d szu-/] uw^Vҹ - :- 39$Z7>/ZƁO!@y39&yRdG 4 Pb`"M^>;(+,I4):v=jm@/y(!r< n효f59ZF,&Y?*xd{Qx᳦ Ķ4NX03l`x66 I}-\(+oAGיuhK#;v3;R!B I;6/ i(#LώK54- - 'JFq~c䈎E`tӈ\(R^ j@r&ȶ#gQ '9jZ߀jL-Q{)fߜk~xd9[xD rsNhzzkNγTUJ|FzZdz (ΰ rO]|\&I .YMtHƒP[Wv]fJMBǍ5zG̈4s&A lZj53 yxJY?ZK{Fp#C'HUlF5@=Xcz 9p ?97ѣ EȎО1?n1OA5S^+_3SEyyN`?1k8U}~ԍazoV4–,7Yf/C.S|m0ґGwL\SK@s]#I4m0ɤn<ȕ3[*pO=Ϗx[뻱Gn78FL_[ҋRxkreS<P]d?S\skO|mMQEqklP+r|nq S*W41@qc2):0UZ@}|o3f7=5Uu8.x˜:phWJn=#&E+LX|^"`tvέރ Ȝ%."4T)3grQq@*EnG#-0%AQ #`A/Cpkamj/ f\vtZ. ~Ps) -MeK O\ DuUIi,JBUʕxg3L&^O#l1CU<8ݖCt( &صkйAA$|n1^)+Y/<᡻r^msVfo!Groj"3 L(WB3R{t0ڞҜ 4tZxz SRu08t>KJaq-`_/~=b\e4 WkUu|f?-K3{ `b-A򱪛L漹;EIgՙם(,Lq"g~9K<=l k!'A)xRn2( %M$ ܑ9e"}И_GamSJ2J$Ȯ@<<[hVIكAS(AM3/O)-s8A#e1%9ۿryz'lWKd7OS8M 6B?\~ zS>?H!]רfHXhԉ쨨JLX7huts{qu{{dͩ[{^aR&6-l/ ,`˘;읔I9*5/BA e'?kܕChA^\8["Pyt}HJ{_p&Pf, E$ЯhhESGRCL>yx`xhpUnq!+ ,*xC%Q!eyUxlɕr^MiLάƗh]$3ei趬; Ky{L݅^V"X b!ɯmH?cIgruRըc^] bA 3uJFsHqĉ4W8YxJ"yb_ׄje HO(Sx}f6Η6AK,vO| J ,r`@vyJif!:25cK!f]l=8j{Fj02LcZd:uf`SVN+ fAQSAaW Anȳ^.룒63=5YBC6IR wSb=8;]jYT!W>BUI, J<0óP 5JlW1W4gJW+W5A:9VAwfZRI?LɟJ v}W(mJg8JeՁ*躖%,u)Ydpm欤Zz%ISCHP霱CdW]gdh=L/Ů/OȀv uq={#<7u$L)7HK'7;r!w ?Nad~ g .Cbӳǖ>XAMh2,+.K{WbHْ? xEW3ѮB%o谢=\7ᛨ-,!c@e@z4p*470=z0[ L~Rz}]1œA Ǥ:`Fwa91vd}藺vOBh<@]ٟH)6[U6 ĕ,5ܧzøpGȮc,zlt@3,ϝ?42I.w4$10owCO[ُ)":xܩy@?Xۣ0CEnžJ1sYr@Q | CR1rzͼ'B / -Lk, ,͸MvfHѬHn|]  <㚰}{/˘4.IN 2?ʈዔn$lmih׋2`;.ǶQj|  ࢯvIh*F-*WM7j۟ˏk’M1$2/w.џMl |jƔ.~fuڙx7Ys >J\-x@ v {EҢEG,bڋBe!T#BKKe]-6i iqlyF}h;,˙f 3{\DQvgr͐:N{`H;zn*z[۫N#דp=d:6W~&!lhU~Y=[P)*22sWo*G>|[s p.P#|#* ;}n}_W(Ow-96Ix2rh(cUog*W HmbXr}L;w]9?>#zwYi)vvYP4Zݤ?sM! n\چ<+.Kd2ğ H c՝;9qXor".">D?< 0O%wrGtC=_wv1_(^U4r8j_/1gC\I bL7zj}Up[UP`J ^ T9]x셒0`[ ۢBVHFyy T3sٺ5xcESc~ՊS{1z")l2Dej[8m/s89-=IOhkBnmV񝙌$EQ Ţ@3ZQWj=le|)3 Q/YWޤGRzZWD8ІȣKS??HYw;lݖ*>x{esse3X|M܏ ĕRew䠝87E[)4k!& 2X*\7`%/ 9l 您_D}X5b.^dѧѡ9 ^~JE!{9;Ϗqx:<+;K~W—9%(7t|AԎ ;`bt˒E[:d:Whf4ԳMӄVJ䰱MaiD0w0,GJ}Qk-'”o[ \%7-]} . L,+r"H.Q%BH`%[ 28]@IRU8cPF^vf.AzL VSn|tAj;-=NHP|TϮAx ki~:Iv>7ч\|Bnh &).6%A."1=(ҾrD{w|ʮպnQH}b3F;Q~݉ceZ^DV&E~@b DPC, ,Km M{` -ʓ+~ADĄ8"KF)XbOu΁묄)њT^gn'6uP=Gu44";G: _-OXXek0@$P-FV7#зt'L6rd`mDxM ] (qDh X\1X٣>TL|,wEOXe#eDE7,&L̝<~]N%9fm* YYWiăV/܆f)*r=P4 RW–n-8|lzs^0|It6b˵p-ߐ y}ktΞ%"qmJq4˖(LJv di  nh'MlttA: V0;O0;tcZ쑠9Ө?#UC~{UG_;[8b+p.ȘKpPc $1{i` =c&ꖛP;#|h4J@"'-& uWfdAq )5{ XqO@ZlX #5Rq,^,5Lڭ$K-|<p+k94uUBjt7,ZN1-#o>ȼdZ5ecpF$:2$jAAez)rf,aѳaٔn^hz(o1bCӅ(>ȉy6O/w,WN1}2yA@CAq`bDv]JB8'SL5A`R wz0FyJ (ku@J[oV7l['ƣ|&ZDM$ ;iN^͜{2Ed,wB 8;=qJZIr"#({]f*z,p^rMΖC%u jȅf^&4Bn,lPAVl MD)m;n ;oO&m_fNagRI_*֣$;`gX(d1[ZBB#EWk"aUNY;9+ʑNW4hlF5ʳT¾I]Nau;qE&3NktONdҦ IY.\78n.wtN\FanŃS K3ǘ<UxRR`\"a==i ygTez~1DHB7?ߎ=;vP VW,"$ƿH[gNз`cCAi3tD,Ҡ)5l+C=-2MڰLJ$;|R$j@GWfb&y~xHc o@) :U2h-άbyGw2p4HurQ)shP2d!˨[Ag)jkӬvwL ,ҍ`G! nAZSmd졊Zb0Zw{Z *M S$"o5͑D쾤0/;rB+5jnXwF \u!N}Ui(4ԡ;ư27EEKxWjѭ͙{\iXO k(o7LoАMKuC>ր=JڽYqM۩+dW狢cfKUNHbs4v\ ?..>Lp?RCl0ޙܾ˱ 'Ato8Ά78j,8Ӱ VIUDTu_W>[k}=$<4~z+(@-wxj{ƾ¢f$gnJ/i\*֧0,DXcW}tΖ*%hS W,.b )ْ-L8tLj϶PWDx*j| 'c}=:Cax̅*[33l&  V ÐMgk}bki9:lUvߩ+J(>9!:?x!v* LI`W[~c33 {$ИCr+[mU?1mv9P<pM54Vԥ0U;fXTSPip'0qe)'K.?EJtژ_3=H/~ /y;RbM( M׎,mLP\1"3l^Vx7`i#t&OlE|_ Jf5)Więt{X KA9D밷 +`գ/!Hra4B2t*h%w,p*Yԏxj q}w!S_jgeQ`޹8 ]ćKHg$ܾ&:͊-sFL/Ьuۈ%Lyzd9y fYp2Uӄ6s$Q-@4@];.d%Z +ȟMvQʚ%Śc-:OD4,ʁ b _`0E|dLM4wڿcHŤ҃12IN&wfxB e&(2Б(2 tĪfxf=}^w(]ZּC Ky2|r"&4N-6Rs4"M'^{dw[R0g ͠%9 <G;5sYn4PCG[&)CMl HgUV 2m"YoUQ`!~WHy܍H }i߄5m\ʳ1M{Fkj* `(HhoX!J!a]V{۷$Ājw/f^ lX?Dy-dckĔ3o6#LAzG˰./Orj34aXjfYߚYxFֹJ2δg jeKoB]o0f_m( OuQVH QGgV(.X7Lc$׶rnllV =z~1A< c%KRqΨZ5֓SMA㕣*Hͱ+3ʪ8*X{ʁVQʗ#5ALڵ o>0p(H*$Ӝ1mہ3:/^ 2 N$nzOA傊m`l6弴xC"m1KA@ zWjkO9Zt)mûFdI {JR-ǔMRbzg@U]˔8TIcd38f?E蠊* v 2A<@wBQ 7u/* ޵Tl߻i u]}Ry;?KبNn }a"WSd^Ӷd[0wQj$#yпПӗHzd`Q4K}k.l팉'Ŏ^UWЉٶj,uyb3Hߐ$LZLxsiO}@,xD,D>fhۀ2x&pARe' p͂*eYrc!{Qиt"h5M oi/.Vx>LT@ahK_~ßm7)oM<~Ca8MgC{"N^8.fm '35rU5J,50#@]<zҌo FU3)bOFn,b=xS3+=-ˈ}[V3s8']4ػ &J#}IRYG 1O3PRjrGJChϿk}p{f٩' / K6%!sprv'/b\gA Rt_DGh 1 ߤ v VxdS8>wUnr,c/Kx@(~;MX'ƛ߇@Gy%Z .Q~+iU Ԅ$-zLbTS/W7kW(oϠԚ,R%r,@ÏyLƺn;6p_=MApfG*Q$ZR͒ _2z,s`%˘~Xq װ[߉b&H!keGe%Bx"tϢv5ʄ @ XNFȽ{Y*4$K ~Ӡ:,'ṁ @9Xo(&6֮rUtueX}:)7@cc ],kߨ- ढ़WGܨbYE)*-Zfg|jORmՏ uC ǽڲ'艾+U0!3T*+}p#6]n,Nr&⥅VcQV× Ix5[vށ֒)y/A) ec&MM#1:(C3|lzkrB 2ػrMۇlҦ\uqzgÖ4ZP(3hr(.9ݍ~~|cJXYIDyBz;+ff/7Zレpu[~Šk*a-$ѵ>'.p:}i>R4JI[úTxz%]Z-$ V{ q7&hWUՕ[KbkȈ=~Ԓ,}RJTM=h!Z0}Xg}Ьհ$;s _̨R9W 4gƥ]UM41 2tڐs8e)Ƕ3Q깸9 7esazؔ|LW KkV7VgHGi etR*B35 j;Otgy?El-6uP,GC>V1+\x;Lc'$Kа.H3xDᦝ,veAjĤO(!*Yv9!O}2 V|FR>ƐDh/RT&Ηq{%:28fR÷~+ԩč}|)A"RO{^pчUBmB/nO͈A Du f6ZdWмE:r!nA̙J#H%h%Z@$3)V#71rCn^MIF.;ǐGТݩK{R]R]Z,8J;v"⭬9by ɉ#.meӴ ?n"R3F@mre:9-[EbM6=v|hx\O˛A]$:{'(U 45Q"L+rV!NwÇ?77s~>w=i=VÉs8ɾ6SjO{jS~[ zia*; /c,Kb"1 ЅR]z&r6qR|!zUZ J\'`/SK~erǧWѿG=C4. mR[Znxx*`GKw3))jݶBhX)!bqT/)tf.'vTMiN~=8 r<WR0rY'OƼey*dܟܣ!|Vvs8-$OT4Z)A׷uHNiשt#̜Uyj@-G3D2|`GH(v}@ G_J4nbzkr4jŻ&ç6FV+ {9\}RlB@M 5/$ J2^S0 mw2OZnR}esPVIfg= =G-=wCz^H2[n(1E(ys/T0<,70̧8rea7SK|qF3>p]h:4Jl]Į葆:w0r; $;'5ضO_A:2\;-TQMoi{nu5 oM\=mb]MZ#ȿc.6aZG _#I$ Rv)4 ΰr+OΝg@gګJN'STom-i ͰŽ]9keʒ!g؛Ǔ[~I 承v܎U RWSFZc?k.*W#i3ş, ƛSqo+:`ʌ 1-c5ݲ[ģan_^F~1a/y WэcKݲ5yNM3rz,<%gԟIkoQ5m@ k͈橊3Pڼů:E͉V(|\_(X6l|&?Z2' NK 6qfe|R ^Y6 c eTbA2rL] @Jn1mrĀ{v8֝-EsKSw6!K!h,+DNNNO568 v0dɖ7&Ă䏪ONL8f=LElrT!TmڊQ;񌪐/՜w@jW$nhu9-"SV1迢5t<7븪2W"vTTGKx0p]X^}ȲUW o1\D0@ +-10p^9,-0r ɤ(Fk|En;8k+2`5(uv1bY`/v_]sZ5 ?*Ek ҁ$oOecS=݌o_ó`2˚ߒFP2 ,';v1V|0v԰Iu,]',ߎz+9%.v]4c겋>R)'A :`"B:qUKFt̶Ubio 9 gSjcxw5߶1́D2mYO} pOs9hW(au-,Me%ܠ/6C[Q8y9~p]6A8u|ܕ^S_GH@ySz۱̡9=mӡ߷'9/Eh96E˃4[OEAp#RPj*b ,C#COʧB+f6Y噴қx[pSHHx$SI5gS*x/^CNr}[ͤްzC9fnԛ8!kT<' VlKM`5ױCK=cd+s_K!u~EL T8~DN W]HCOOι&[3g@cnc(\QA00@+9laPAj ۨYEd- !6j faZ9. !l=`8s{R0o܇ΝtIXoY9d#%)+eP ϵR: Q_?lmpJ ܽv~ӕ9 z!}?GecTnl#nfWDUgeMTѮeLBRyZݧeA (1҉XS) @+G@=\az+Dq'3]fv[nW9bN3T!` i8.G;i? d*OE GBñiRAɔÍG:>< #;& 'N6 齒! 6a]_$5HsemX0E50B(+@bq]aU+ݚh} 5DNeT@g>C}D'S iQ9/NN7٥; ~R>N2{S}dx8YlF5cN#}4&`^sιsYJZ>$VŒ i!Z'Giҹ~elc`$ { ҽќu"4f3M'{1%QqvXY{ViErYMK§9J 0ޤG҄6['~i>9وQ}V@ivEKCUk׎"q۝YA]X~kY@ziZ.\dyH( ͸ Vv7M~ `q1'Bo̰j)֤!ϝSs@yNjW,URF-bوc_s]b4.. #[?Uok_:i2ϣ j~# ;w[$2Qs]iԖ2p+YSϓʆ[,~pzU{=kкDhX̮Q$\rG#F?4qK8!x:7-+ $w<hCTأr#Q#[ _\O}bv^pzGl{r*43$g9F2>3mM|^ף &ZTɋrajSAz`WfhN^aKi r~ ;;_ztJMw^BwHҾ3?<_Kavca5`{Q؊f>lrjdnީZD%¯߾9V,GF'|2y)8(rɥp|s:G/.-p|綡QWL}wT1B_Jh j=}$̆ÔbՓpU~JKj#B%Bz.=93=Tci?7;]ЄnVjvE'0#/nWE7l%7rtw B_S< Ρj"ͥD"(u(!>{&. 8eE_l`a?"js84Q˾5J*[vL-CIE7GH[_z32g#CESlW4$@񚬬GT˽$pr"ݽm~c/ {818d=3~TQPU\Fc~{aY8 a:{U GF?,:@wy򪑆8v̖|܀`gږL|nwtkE0_4~C17ȚxVa+" ڸYcl iݞאd*~MSsfH&~X/j2 mI_vP˶k_I1>(e3"'g [cvCg}W4@ vaǝpq81s3jS1R) +ꆻxez㪫l.V}%O cajK:6|Gr@MRVE4m 8vXvmo7?@Ks>dYUNW$ͱ! Y ȵ栃 e[4,3S%GCc'X,nW~|f[[?؉Rb ȿP_b ұ6g\ty GdK?|Qq6089SOԆ%5_1@rQ28|J_*` cRGש~c F 4 *=5[ fxA$t~Z(3z hT_ %D'OD4 N` C i:a!~rT6 S7d׀Cku,恒r'ߘ #]PBnK$=~y&ߵINXvov *‹w0=D/wQrj[O6yw8NZk)#ģf_+?~nMpPda_m [v Cq.h%ʁRD{jl?FB#e:Ռ13T{LsT7,A)&mݕ.V9 zwnO bQSRp-@}˯i'أ T)|)< 4buu S[uj{E+Sgo\k9 :͎B ;ZYobwW;c-b>HqCwQbm501X}%;EgE4:{N'R b B "/8+eƩ} KŃ`); 9N/qe${5mȳ 5afx&eHP}?To0~ ZS*3j$SfD&p'Wɖ'Ѻ~ϓ xneU.}w\=Did5z=ZXj9\-qلeh͎ܲN? jf tep7d=Շ}}ߑI/E/FQ}]:_XrͶ'1=̵znQ/out_߻tjN7M.>SvҌQ@e,J(5qXE)/WE+Y1rc}R $vcT9ϯUn[%DGrE$_B%d(Cruj4HoG>Na7Jm"NVBH:{ʏ%,̉ŒSsf@J'*tfm.nYHI$5\DoFp<8hF<s$,4QVu=*WBZ2d*>G (fRiihrEj*Rރ QX?7k*a<#zj,?B>`D!OP\caJs:DSx(6|9,*hLVxLxx}c8G8sptDAqLYQ@1IZ ?ʀ* 4k+:*d:6迠kpD$\^`;W7*3|ſdvl3!o@G\w$/E.')hMQDG]+_"c[Kdlɯj7,u4L,Yd9a+6 FC]EF'QDT'RVnoI>DZ-c1!1~mZ* ʺY+GtjGBll*I}=:y/ ,ك5,pq(}R{h.U&Y"ʻkԲ^6BWTZo1aqnL},4s|DģNFrдr?_ℶL:}]Br*k'^ 03̝ѡkeѵ1hfBc+pxW$Q|&ǣ[3|?vM\oBub.G<*3BapUկ#be&XT+?pS_Γ_*4&bBX*SJ 5Bʩ+r߽'B\_'CzRpűA̠kr-0?ْ#U)zNv-Gp̏ fE|x~sk\ū27L6̗ ?ثwV;(t\} +hڕsxsDXSs`,P(c*,0!cQOpY*?ʏ~˖.%CIk xf.uO~0wz!n)"ׯͪ4^?#0}5d&dC\$ zIҔV^(lHI.3ZKJ5$Y>?xQ jn ޻n_ 0~z_ +!'"i"-Ys4tfE^'GO隥$#|0٣Qt<#js"woc,#eEj:e]dacv@>.+ĚH/Aj)̋\m;S:i=|%Zh}$y6mDfFp^m=gp7 { h0#Ūy\UQ`&_qG؅6zOMKqry8#UA򯐅7,W=3V0fFrf =6:>NC;>K֜?RO.9GZx̏ B] A0{Kf4ƒS ^7*y+pG^"ln qlbC4WGUGg̅#ENSw"<@$H;H) @<]v?'++<)S)vdFřI'jB㻨VY2maGg׵SɠeFQ]!XnRx!6*Wm|1 vsȄ%8}[. El,++jx6Mm;J[i ~~AngGhL B1l/P8sW,|cbm٬*rG,: xg|%7(IiP &]ug O]Dd9S#-S6𛁢F~Bui%~"mF d<rbH7q2V)XĂN)Xr²\G\ҋ%qhRnZ_ R8*˕yM"C* Ҿ1ivM;閿 Nl5W3 驻zm|ʾ[7ЉO") 2|^Lm׎M>Ơ`F3Ն 5ǧ(}b( |ybs,.@jO2 pWv*j\xCQK*SN_LX ~ycw=4z]Tazz Ρ.V<9z K]+dwyo ' ~Ϭu&;-OOi^@ h:cT}LU߽ňz`?P&@~{m=(@PT 5]tKƶz[0썢H<΁??uŀTx:<qÃe067iRY BeY@jG.8 3qKFSq_Qv57k F4[ U원Z-2by6c/`jwV_ZFT0+4jE记\'aB`hOCm. G^!кQQT-X[4YfR"'OGBBՇ ?{NbY :y1nIخWv>s@T]gHj+DAOA"yrr:Wvm2eǑ QZN+^X{o6e{6%ztO[+uÔ UNELr]͑ARUVP*κzR)K*YaR(kj8R\A Egf/(m7c%~8Z=dㇱm,*ZQf#q"tQ B[שyj88iFkgqVȣ Vba !M^)|t9].3_J lbz4 GI91!q sm@+ziC,lzTVP s3||*!<)c)Yl4(s2--Ko_䌺wȓލ3NCM}So e?WL1Y.RM+S-0Q O]8ihT$Zi&t`nᨫ[ }h) -÷jVC-r;&S_39g>&ւ?&r{>_`)iGݽT@7>#ŏCOpʑ1_R ?^DT::ގ^DiKke5xI(OJF`8.W ,DK Bx@W8#*gYHU:ԲEPBJƖdqT^ 7/usl,'}*R9F .{z0ics @qnrc]Q i{#_3 EaHsS r e|;XtS,2լ SgNN*@B ̔D}B.DhŎU>.}?BىJMmvA׭V`@køgջ,IxFEpNy%$s }L4zHݴ"!7.UQck%UBPcwA?ިtC,|N.d:WNy>X1ك^'U G Q=*+d֘nTfMq|$5^ҵWgdZ^8'}7g&>]X4\,4T[‹Տ8У@2x~NϠIjGN4/7J&|b08^E(Ty;ag%H9JhsC׈Ji{o@A[ߞ6]X̵HtPhsH,G-.߭ts9% v4`{p6:*wEϝƹZe${ʖ>0oCE3lfT>"* WM:be;IXǑ[<3g D7SI8A{ zsALe,X!j$G>T58BU1O"(;ylֆz19 io l0E2#ULlzh2-Kćp1 `ZPO=”2 dl1Eq~{0}ST/*R8<`ZE^V5| g ],u59C\È2 CkW?FҀSb̞Yc2Iv^y n9oPom3 JMNѴ\nȺPD'TY&*E|e.kE|qkV*9T&_T@pbLi?4z&+Hzk+Zo K{ C8ڒgpy^A6_);;oO*ԫ);%7|m_(z N.uCΙb́C& %ZdoYm[BvhI  ^3j k}4˓A]}6|t_XR".Q&UjfZ|ajy]Lwh`QV<ے@IηCPx=::G7]_o(TI:Ĉc NFIKC_O@ ^)%u~AU#Hz?0k.W4wcyI B#l4xXoK^gHCZЙ$;,u.|,ٟ/,\2!Ț*hҚQ%Ta܈-#<,Cx"m͙ Љ QEcHV"ṫԯQFрbmT/;GcU 8lJZGnBmR/(_,>;lk-u"-Bņ2;fU DGBӉ2>$E^K~s'_*|>j!M|lwO Yy2- UR@𚊎PCҜ{3kZ~g'F6,J,o.Q.sD:pǭX T]]hlqm.ţ|mۮ$^qAlE.&LnwhwOҌOkv ǼJPO[_dNՂSdq:S[7Y ;V(l\)'ITEi̭J&CLelnB2x$Mv NF<{`"E{YdX wua&W͖ @gJThc{v4q CrnrN!?G&CIupH/})wɘĿGC jZI Gze>K^9ڀ*[cS|MxÞwৄ{=!A_/ܯ, To*cM}1[@‚=:%w4z]z8ø>D)#-?6P@,b!_!_xdv0띥/ĖT#jr5 _|]IK1J:C3-L\A6Kv E_[)ݗu}c<ƼcTTZlF垶Ĩq"8c]!|0XYī4'4#U'"xygf j7qkּre#%BOgѴpV6a âI}HhWʄ7 $khCR>vӳ8]c z6"Cki_w[[Yw3M{~p/ܺՁ`7 ){{S6^6J\v}ct&-ڦЬ%u(I!\%eILEy#k{d.L|>iT.A4d?b6} -ΨVSwƦsSSRs?U[/d55TlBmc3; tc"_`GOeXj)T%X&πe>f8(L0^`.ψى[!{G8l^f9LW3urvCC~$˧;*~QG@ 4O[igVK$UV{ $Ȑ+@Sl=RǑߢ }+׽2ALw`O`ؐLf ZQYGI1[=Z$͉]I⏠Ci;XII !]”;ے[gr ΃`v}8K=M/Wٴs[0q7{ J'|PMcf t򐊑~'€r'E=C9^$RTVYf'bsCO,%L/VmCHD={ca (t]x|rii G QD[H/J: 'tJ28/֮9f|:&-*VUQf)'c7V2hm)K.&ēfR+Z^oCsFnd "|r^v::ڇmENڐ؆[oOI6d]yΙɤH[sPu2"zj c&Rm50Kt1&' "V䈬 V2ݫh8vjدB-$ƎFXA64K1D$C8Wዦ urSvgֹB3~TүG=A~E"*)!0ۗ3]9K&:F(^ƒ5"k 0[Y9^GC͏f]]D3ǎApȶ1K_1 + }v-LΒ99ɵ}Iĕc RGcKK&i 2)L)Vi< :%}C&X[I@x$ 8S8϶ľy'Qkx!UtZxLCj]d݁إ":O[`+ tAӊ(Bɜ~ɫ/lJC6fԆ9e|SXCBvxr"TŠ#tcnsDNѸ4,Ft !VIFbM 7R4Ep&/2PȆAD sH)u"=Y|<~J;be6]  @aǾ!2Kt<+bn].NPC?쫮n4e1fpF3zif[ZҚ/,9ԥhDҔz .[]#4q/u7KcLWm tTTo~ቼ[ Vo (E`j1QWt, ^B';q$&7/^T#XLpElIsE0Xg^zb wZ7a0d"jZuo 9X%d$7`rX>v|`lvݷϝyniChҶ%WOIVn.sxbY  sڙe 69%F.8!*ĊղKz# "0O8ܝ~1wC#Qg/T刢#*O,29ZIG),\MZn1QD(e5f{9$IW7ѐ/ :@, S/D:6]IT,YdF< 2¼X*%veꪶ}b맇iszmy3I}ґj;J[I@xȊJ0HZd΂ګ۵1%~V,+<%K*04M:(C҄1 wnXH9sgBѓ̨=a`7BSy49Bu4mx bX0Qw[O >DWeHșz{PƺO-]K),V --yIoԈX#u#ͳj@q{N ,۟Dl[nv#ir&cpՇ'<{>*RZ9"Kh\tZfq8, hbwg}x^n,l ǹėT S6`(Eu=0qI_vӇqW3 8wsb {ɘ$LSU BѤx4lf6,*  u6b ҠrP [ 45/.=#un p-Ϣy7|j]_.] ~Î+=ΈΪ;k&JMx%g&y:5|'jr? vnY}sR'JwpE_LtE2#Q:a8RotX48!~o65=ܱ2١]]\Ë rU85}QYT]HӦ!z:DܫF`&֒ ~װaLw0U 7_0z5I̵&0Jf%GVboj?jM+iJꄯ^-~W:"-u~=׿`{@\yh QɈ7LYKۄrfkzS7cOjeW}y,MN*sk 0VeMBg/g`U%>#S),|E⒥7 m0!Zu iXQ5[]j>+gjprB3].~˙VxK5'@(ħ܈0U(s>5< ?rb% KfT)Q 5?rF76CtyhD !Iۯ`_z7%cyRo&k @nRmw,gw U>[kL@rykU8 e,rTb t{ATGi.bk-1-w?&)ԶiT`K:Л%vun/6v.pHG &]ROqZr}547S\ P+K8qnpz?3zY6N\2x1^ϯLÕiG`>srպ>xE.`Dղz˕DBmY(g B:~L[@q{maGBV% iqwGK9Զ}v'Nt@i{l ė*dA#|#L z}Pakͪת!`4AvLjT7}p l͗wń7rRJV`05[XAW/LchG@5Y5d9@ [CD"`-6[%`AecO/ˍOzV766V@Fx-d|`@1]#)ӼHX!;iSf ?ڠj't߄S`Q@˲ZI5 9DTԣ3CjMG/E1H |ޮ¯{)־.;\eDbHx59ИV 5zZ@3"V0]k(d)Ѭ[a Hu,uQlOGG1ǎSOhŦ@t zDXwTjT,wTtÈ NA0~pFĒ=`2Ppmp+JY 1j!c^WqC!wfD,l~f:\8()vpn`-O:\ ^; 5'>!{XmH>#^aQNÃ}3\6VcI?\Ts~ eANp( ߫~IH'pBc< ] ”zdX*9Tx4 `w  _ueJZX"3E\It.ȉɾ솶&A&%&=@uMʵ'4)GYMeul7Q NHgie#ss1.Q9ddU P P#!K%:ꂜ|Px5'QS7|._"O=Ws/&кͺ$N%D7,0$TMƩ8,`,~^Hl \ha#GY1up]\rnDRBBDn@YB"9Tyv8 lDn HZbE }/;iao?_D,68ա 8d"0=9vIx] xŤAX|gcToTW~v33t}p &WJD*He 4qcaW:kuf#O٘1Ȣ: B1)~`A!nGs;/B\/uo]Y>Pn !A/S_4Kx4%OXx]bDN`[}9DZ [MI ڸn!;FQ VD׈ܵYv*r;mSD&6#_#!V}|n8=tK]ujv67x@SIm4.b!ú̂ agzrEA܂рR.Z2FnSA~<&Ŏ<ݫJ?hؗsT8UQBحݿY4n4il.~[b[Im8ٮ䜀"^t:-$g< %N78Dck2R+8&v^]H=,%^Ao=w当bbdѣj0]=!]d K ͯ3SrK,R4r(г]jй w'^u4;g'ZsE)/þd$}QivM͸yD VQBdTu`%6u1 '_ӾDq!)"FkৼDspgi.Q5L B>Poʔa"5&ܧ9'g`̯4oS`^|+d$yjٵ$!&b] .ץH wA*Y`Wu_oڅ,ũT:KʠB27Dbf<":,cW OH~1FOa S,xiz_ciUD &@%53;NE]R՝V=9?{qv삋 |˱/%R!m76Փh=9-ENu\ptGB.&cF=0.y)h=5-dFKCorI`TIR+!mhajL7'AmW-I)#(jl? SŠpҭS%G蓐/~Vp*p'^!163qU ;q_~݃5e3$]?P44{qq-*qok:%Κ쇤`_%2$ʅQz1<[^A^qyQWFGP9ZW(x+}9ֺ66x*of Y"WDqD &Q ]a鉼e+МtG,FJQZrY4P+ r. nl^nTx~&5G.YnP7HKǵ(v햕ZĄxK5MYO;/Lo'6Ijq>J/NL̫\%-Y?^`&A^ &w :r M VԖ gĻ9^2O)Mˎɶ4L? cRt)ݟRe^JB9/ls$魨P/u(!`cSS+)tk _HS4qKyUՎ3Izg,| D94TV~pXka[!#6](_ d ͠3.wdEioMvi HC*Gb"DCwڷU+zvZ%oBCX4]{2裪ܨ!=aʞo.a 3+6r[ ˈ\DW9]FɪⰞ ~ͨ 3&o/K.mÓKWL'2blqsˉFq^+\`&aB"׊$WG?a rTf1DMgLxwb8{c_d 5pYfVsY/یcpy`{MDc6}Ve-|徺Sw#/32x˲uɉ?^3kd6d|c,n`*`,3DήZ sδx ڝ e4cTf|ޑ;dpV #^\Nd|Y{@|hإe%c]mxvB:!fw'/~hGheX5D-sۈč}ȤYe˜JY%Z|3UuZX8@˶5_iFz@QKؗ7-/_('mqh"*{q1Ar^мNM(ɝhH?YAMf3l-I7f]>NgyZL3amRHJQCtYF}z\4=6> Qb#.\?q4rVQwo*ndbaUNDoՍovơ,iռ.wֳ pot*vn} }2k}趥*|Le,f8݁=ň7Ojkfg[_hD /> /Y8CrJtz'h?XE[4!"o$NVt2pdDYu;ܹX Nrb1y"0kPt5f8RC+֌nɠA|UaWz%&._E9/L~-]_9bB3xiq4 ̮Yxݖ7n("G9V\]r`E !Yݩ5,/YD=jE'٨"tZ&.˛=(,xW̪ XGTx8%YlωxsvP]YXX{yI6L)f 0M^V̨L[c S/#k~KHkg\4S02֣˯cX&G%ǘےU3m B!3̔=(a+J{7@vO2,rthi01<_3s/JeOTiiH׏ KYC|]{Ypl#٦]Z=`24MAϳaAPx9XKwB~C:bw])F mHh0p \az ij"hZǥ(ɣt2 WF)mzc>o62:wiG|>fZ3ؔd7ǠRs$ eQ]&RA(9K'@^ bITM?G/7$;DtQ*ޟ&S]ԧsH 2"$,m3pM M44;mzOݚC߹$pk k,s5g[>7uβiIȨ9Lԍ|Vk|J}d̮sߍ8Ѭ6)i@e|{wv'7"pe%pJοmS t |})4KQcPٶH"H--My8}4*OУ5!)Cgs#ĎgyBÙsO8T L7$b< K]3sOU{V[g'3QXT5E-jWz f)W܌ԯ:[2V7(>2eHQDӑ!KJ':eynSC5ݵ#Q^f(? 䕉P% H c"k7J`W.x$ђOϦ$E}o*ڏ$O3]fYAV.2t  ;;VoΫjSiTj hѢ@u Xa]R) "2]? f!vKT@a!핛& >J9 xv y!(qCScM|0K1o&3|qr̤BDՐ|VlzH:HxlQ!<.X'z;݇3_%=PS<_QP%2+iYlT ,UHP&[ pp2 q5ӎW3;"ф9ʋjwxu{C^Q.vCq~tp]eT p 1IXt(Xs6@uńT I h X *c7_(Jɇ<:bK& t|0D^RaKzts+F׿+j/f츽(+yW7`lfQ_Mo @%tE`[c{meԘ E9]e%Y8@Wsݡ~?z:oo3P LHTdDr>Nq^74H=jb^*'wJC9xa;zyŵ3 3V4̵AJiBlc7FFweTQGH#A;yђѝQe]:>XyKIJ{$cw6U #lKf6l^6\3#uөT٤Ԅ._nZkLe Ԧ%&Kۮ'y1ΒͺM#{__0.=e>mFkQ+5Y)p*4%|`3\%:.-SDT)$>iʗ,"7A,=X7=3/f{;\ѧkf; eZ;u],Xt3 !f6Cl?62.>:ҵr'ͳٹǕLA5mU&a.dFP.U&[ 0٘,waĢ))c m!#xO'k$\^)Di^UQ4! Q3'M;pǬ;?iH+/}#Cл杰kGRv73ٖjM{JZ ,bIgX*k= #y9u׆wiBfi?:(CMLw-`_Et6.=}yH"c?v*q; @ܶˆr-`Q,r;]aU|IV[BN.C|DyÆZH.~܊&^:Ś NjU˼pE2f5ò}co\G`8>.|?cIz9geX?.0/$ is.=Pj6 #2Y2qߩaM'-}xk߄yY2@mվNl'rKHP=pWGZ'rzv_$Dڬc}nn^(aCy1%g" 587*7M7f)`O JЎACƩ*b=Vst."{! v"94I NwEwQ!u5SZKYiT?uq** H\—M!s(Ni:ެtEXDgEO 3ܞE5M cIfW1 @Z}ے>L}",/ .1!9+ԥ3X 4NvZtcY4qAĸj-#1oޅ}\ ⩋DV [҅o.;YMj}Cb,texզ24Gj+Ry_Ħ.)ĠИ[T|R]* ,, xߙ`HmhXcH;_z +KB9' -`YuI?x,k[ͅ\7Y|6;ܺ71V gEfn*Dr!W7X}pڍc_q+XXf#0CB}B:#:dGiZ YjSG@*\=nyI?7pT\5pq(A x".X!4 llj+teb;v(9:oIw@= F(cEϨWK0Ȕb@Hh$}㌌侼&5XԈCnEv1]λ+RV !C<-΁~I@;|5 1Ozw<-'ǢdłZB^"jK{@bMDa9~&h{S>9~ٿla0zQ8rYqoXZ=Rqy GoۧpS'qCM0dj2s ԱFP F&8Ӂ?SȨj)4ũ@qX0_^mNdX Z5uZZSI"65FqNQŏX:byyGEyӣ"y 4@pbG':1;u%pvwaD?6\듿w㛗iew w4;O=\.Jm.{~N/J?ي]IM<ge-^dRJ蒴LVhNn5aR')"D| F{ O[D3 _clQ"\6qa  j8S?BtS< #8ȍ6,)#WI5AiE)jӂV»4VTA4_Q%bcYƾ:@n;E1Fv3t8n;^RXgw$Xtd*^ #I@\1Χfdk2&m=-l5f\j]ZlIY(; ѐ/eڢe%M{0n -A*^EU.FY%!mP)ʝ$;%ldI7E / QɠKxs鲷=SHvh-=;n\?KЭ^nggavdF8+]w{|$".bѽZXU Ɇ%>ýx%_  c#?* "XkĕOqBimL~vRf"4{];!Dh3Id~s;Z_Hm^1)T=}7OIr'e)'T/p6(i CӯEZ l"&~"qJҲVa㧚-e*jJIhuf!wjYfXlooM6>%]nhV0P=OL)3,@W~zVrWe]sp, ᎏ%@QrV[3c$L^8^PsmX(' dDŽ^k$Cb_uBZ#$R=e6ZPl(m=@]܉ě\MΧeگKl'BFꌟ%Sd3+ !i 1+k:&1݊vy D ]|(+!l$4 ҳ`O!u'PSKf GtS8a%|xEhe V !:4~u+gY9A ?#rtPG}Ӥ+9!5@ՈOguad%z/:['&U^Ypj9RŏckNXm,5gZ6vX հG৔F6{=L+!rHk2lSN<y7+dcG"׎|%{}|Bޙׯ9Bh- z?,8qn'E!vxwn߫=a!+K\> e떶ɟ<*R³/ ym`=j9 TN@A,wm9.c#迉/l𮢃Rӹ.smGC}:Xk e7Kg4;n\ݡrvAEN걷/kmQT7޳汖L&n!(H6}z.D?b& v?znq_w- K#qp9K4ɦd)@hPN`:;kh.taR ?GfV5.<\DF ;FgAo2)8@g(GܡkGCV ֝ƺoWDQ+&?(fzM7XD䐒١kRCrC"٫%湓D}(Q\'v#75F8';:  ʳ5i1IC~-j#NPѲMdRqDg)-Hĵa!#ɣXXi{hTY];ɯ>zRÌf%EVONTdz(Rr0=*66vy@HbkPZTf·XUmWxAI@V  CiLBfˬtn)xܓk/d_ƨb~ ':+BWS*~ c1 >Pi+RQ$;1H Ǖ`\0t4/ſ'Bw"5N%q+a}E(,x0V?xrt{ 92Y!1^rD4Iďݔ]Rn:AЁ|_,ښjpzg8j4w.3W Hop,ʬNFULjۨԳjz)n+wB*C-)Du3nkxFuZ*wcz^":rK`BeQ?qJea~j_^|fcf&Ӂp:Мd_!+fYaS҅jJxYgSYN6 5EfˮU8Gs]0 no),4CUEgJ$aUqod2Q́#~` Z5;xeJ=k#EI^m Η3m/z4Ak.]}+r3NYE7nF' yDDe0A>x`'FqΎ53[=UkX筅q'ZGv⣻ۗŖYjJBl 3ڛ~4k05J/ePf3W> 4ߌ jI[@ ,k9xVv҉@ldҺ-WRJgz^p֜Hf 8fU#eBY7.Pu퓣M'Ԣxh_jɥ׾BA=]ۍpSNnf[bC"ۊ4R)z.Nc HNn΂BT'@"18o{y<yiF擓Wr9P)EF38Ou^;>L׳oƔQ2zP8g #:ОV&@r >񫠛]`!%-&Mjc*p}],7MLd!h8y9cWk@]rf`E6*UZef.hFcT+K%bB9Zr{@C kEޚ: mPrffz~]G.|@\QWK M K9rdrl)!tV\iճ+ l$PRެ&[imҽtH).֓QJbD;HMu|Q,?i>OAE%j:)JW^H݂E{ię" :NCd \>fjo(Dx;\OecF Φ0cH~ϔR$?(wMB+CWCy|>^^Awp-"V,=hamUMlFT,՜.uY;zwQ% aG>x 0@7ۗ%Hq!$A7-~XK# Li8_dtH.Ug1͓ hoK;u]_8.֖Y#I hqfP]tL_~ @ H-ٷKԙ~ye8B&ݫcx7k)|S+,[+@V.Bԃ%(-+}U\HֲsO& Lc*Dq#6O7PrsabrM&ncsak]Ύ~UeK4vvNop`ynwߍa bQs/R;1Q _@[_8a_mQ)Rw}?0E!-VAWW$pz R)%T!S"86B36w܃0h \{Uejoު˹5Mb^!p{<7jX ✓qۻ*#+*57W\a"ߤa!tM'x37N6֩UEQν&:U%ꔱPhij z8'd}Hf1 #41 >$I)(!g _Ҳ(ˇ0ǃ9Q:n;WRg4|d6ݜ2sGer+/^Q06c9T$fvWV.1E:A8!ct$n^kC꾐c]Ư]"Fb-ca0ىjSb'SW*Q- I.*- 7{2ymU-2 'wmo%#4Vq{( - V~yp7XK7 oP,= lꝁ0~ F͊p-M=p"?4r =Z,]9 .CAFS3bgTdiLvs\DPؖeuv_Uؑ%Fr%Uki瀬zydWsi}_nJGna=_7 yUU$8$ҚI"Sw[ @*AdtX,5OaZ٘~ %ubJ zwE i**b!^ 4:k(9R<S%.-劣EKF\st%ɪ񻁅DtjtR Qk$2+ Y)2<)aLQnf6ᾘnROI' @Z^/Nzɕ鞍mtm" n̞Oݕ$-(Ä8(pD&,lB1YSX*3m5P\(vuMoT*@vclS@;7/2̼qTƼ==A[ #rґlk I9C^3 _࿛&v.:ur> 7auPx'|;RKR(,ݤC [#> +_4ObxbGh7e>Qn{lr36$5Z6ʳ F"q/,}< i]q=p$nK'ðm1F۔vslN SiZ&{j|0:k­yWereٓ@\ڰH=OވQ @n]PQʙf R~҈ U%rx]GʽgXz>Ԧf@9|0H/&MJ̱>YP 67W Mc)j•fkG,Θ܆B,ts6@#(9/Juh7e-+Y@5d3)GT tj_vxn= K];趦խΪ񏶶eoA\-v?ԌNrDŪve #֋2wD}Gد$LMDv,Q54TRGkf2WԴCh2)d*W _U ~8w%?^\Xmxx0pbߘVFzdCIK땰/G"M޾]zV:j]cUq@Pb93VnGԚ7=w$! lvT9AUv'4tg7$$u;Dmѯx >Oۼܼ[1D:VX iTKU{{a9@֭&||k 3[zC?;^;+؁8$֧v+EBX6{&ʿfjRbc,"_pU''Kx%lhǻPXqMd#`^ W$ByHYS>NH $kM:h#aZ%ww}Ed {IjrI!7u/MM*"Ȑyk#I~bUF3j9nz  _"zwA)8ak1E?nB}VHd&g^iW6Rc|=:ޑz:rˁ dyK:in!0!6+6M5Y {19%]х*i[fe=HCƚ\Ce594*NC  g丼BO+slA\mq}:P+]ӏEEg- 0ILC!5{A]y]D@BEd+"xGM ϏRBUg2 xBλ6S"3 B/FOdLΔ9rNsaY<ӵ9Fabᇸ"sg<OpHj˜os]$;EE]\p9bqpFe*O (h?]0Bi@娠S3y:Q۫§eЀ/(~^eTa{@].-Y\[얅7Ê7( {0ʐi(.`}.]$ fu/3UJd)E;91PPU4Z0-}X8p3F)\ү;*#[,6햍WcݍJ5t{ 3FhWcIGmV%Bt2]nR f/z>Hdհ%e%^-6蔍Q#^lAOj/@OWl_p$?:]v3jQ׹J\Vt]خӑmS. F%?W_tk$ыsA/ĢHʪkU+OD #7:ʪbghdPKotTD3}Li4BH%2[VfWKM o<9t37ۤQ7z8w [ao0lQ !0H{#I hc.EJYtHoy#G6/,t7[9UtN@fa*%E2͌-sq&vn4h ?bfk˜&XO-7೧0RW/ٌ(I?8ʵ7@ [ы/R%l"  I*Ƥm? b"G$.|5@۽)e;e_M6tD?Ao&"Հ-&Tͽ%Yxj4ڑrVPwJaL2,H0y[>;ZĐ}E6/~]q>f i'0r|W~x*t''xȮmxjf"n%`݉ w~LsӴ[n3[$N _˯U͈n=`uըC`gOf}lNw)Au}G,Ó&F=Z0kq`#$PÝ)1O0Rr5%bY[uh%*ǿ٭`6:"q%a6*)pęzŰ@z~< =Tp8Q:G-t)A=Kb#tQ\u?X`%kD`7ŵp9F/4z7۠'6Aj{c&m{ (@g|YraKWOEPn^ {PAd}mqОgթdQJ̶W|S {cdPeμV0ZvκNhwXT:NP%U%f˾Gޚ.иäUߜ,wJ{by]0[ƚ{زΝ^^%|AQs&%4ԋ[W -my <߈zXTg "+84>O(bIduylyݘи='$J4h[on6y 'R`m`WӛcPB*v4s3g)|0B!3K 5gV/d\=G`ƒ~/se!`,<0 ] o;o.:4R V%+0 k .X3 Cj6J^e3ԏcb$-SeK$S;±'xje<=6|Evz:1@aFԧ |QKU^'[%O sTԻMWAoSI4~PRDDbjH|Ge[e`#@\ni,V63zp0q~ `oWa޷q4>>~}/y؏3 =*R΃^VYЗuPj-50q.88OԎUAv,ðg뷝 4M3&u"#ia{[1bH;.pgF\G rIlUt)rCjGyĔNm##tic6,/|Ip`Ԑd$ZBU*YOa{'l_-TJnE䊷.=0a!&s)#!IvB%&5QM]Oq=C@*!ʶR08q)[Ť4ʋOAz|Y7ZMmc?{ҹ_9/B4R|0?SeNQ(̂țORԳcSdQ p'԰Kva!G?G$2~GR~M!p BQ&fԧ&H|Άb1ɧY hÄ2.b"͝mZEGvFHeF"c 7)1Gҩ3K* l&?:N9B2ct\q3_WA%fX^P"!}1`1_uqDg]0D _YUvFK$Fx 4=T>Wpl,$Y!0 D*MbJŸC%(ɬ/bmzKbi)9\iM.lI7Y ނMUO-{ ) wTAxM :Y&Bܨ)Z ޅSp/ypsa,y2@fj˼:: 0hKp3Ml[h?&9s8Mnޘo$RPSh2 +NnE7酵 eѬl?ұʮE0Ir_ݫ`0ۡqA]x%>3tf ҿF&ShP`4V;~V-Wep7٠ڌO1}b 6;zED3JcrkCUJr(=[z7g]Ul( O#7fm2'7Z«i'~=Pk8h"L"* 7D]Ε܁o}o1>nTAe4%ʴP~Q GM@N˴5-d& @ |Ƅ-ˈּ=t[/tÖs wbqe.ZbH*E˶ R.Wv#wN ]buӞzWٲ>[4{DDMTC4 OlUO~va yU񠑎j߿.+f N,e+ YЁ̰^%ȻHTZ.ib粆F+#Y?Zh\ :X[[v֎%4$XSUǶ1Iފ՟"1Vn f ;3X^,<5O]Icfbg%'`eC8~DBE'wG^Z$M3 `|3]} 156g33÷G<*5 U/z9V(dZ'Ḋa )/:zþ3ij` gdM+)J}Qh(}*kjiV㤵AKLʍ \3B!,.2^0wS4UI8; A*[7Ql8`Q :Z IYDjO $/;aAy#eY-{t$,I@*dk`1".jhs'QMNhqe0) 2^#™[} 0҄Me?i+(S`hJ Q;]O2J1Q{')6Tv 3iLdFٴSESfLÇмs@\17k<&%K署r|( rO U  Su^R)̋z7zd}ODF8~!INt %e`̢#٦DL`O1myL`&.RHCjw.kovsə3oW)΂ڼ]F-XP2Նi&h=Uy'dN G²C*T~|NE .{ɍDX6Q5zcmy4/>Dhd[u31~?\aQ -Xۚ%E"flk"fTu pM7CۈfP|-iROwb\grՄ+AY ^,Vu iEW/bʹd^qrœ.aSλzJg!b1;3= *gspA:};F^oiP@ڲSe }&Sސ~yYݏԡAQH1fb4V5c-|2ǥT,X&tn q3v3IR<8vj,<auX3W&lca;#`bf >{2j{R=0G]$l 99dn8LtK](w'W0yx6 30̴v\^,\F&CX&QȲ-i_}FR*4\p_L+^24隷,49=6pDʪ3Iˮwʄb"Ida qagwWnrV'lƯ 89ˋ6QT^jPA5[Ѕ;vND GYX,< jj6Y9 +["G}ʧ2ɣ'TPP \hlx-u0?ܲEpsvDMiN'2s?b&Z Um)_ 6^NH}bCQ~s9*W 4_04ma# וqsΩj=x.kϭNxG|;؏-@}3_hL[^`:^4?5͹եSn@i(z1(){9@3Bo12547U.^VWH@Q٪XDVde2W"F@m *eӥheu3D2N"7uEƦ"I \뙻JL'0'p-kfk'c7'O emIU 0l|Ѻv} ;8 MZ+D`Z5Ms~2¦oaڇ bOfDZ$w#OJh=abD=I˾j/&_8(-#9hP+8Ww0֓ZG$y#n5ĝBD\OLV2 :-& px嬣&wY\OqSI-;mh9{Q7tY Ŕ i;nێNX%h!Vbc=2ըhET8:}1\sdlqC/D$ISasOS`ؙ:۴ST-˖3[zyGoqpRq6GJL&A(+A>Yd,գU|k&+;Xx7ejZ8P·6)+;5]"yC\MvksS!]*:+2jCF*D9<2EYlN]Y*of4ni Ae5]!I[92+o(QM4GnSS4xCUpYlY<ڲ=#Y$uم&4gJOZŃֈi,Iw <ω@\E ̰i ɊdU`_`ehG'E] h,Cݣ邹5/ uM5FB-l"P}P}_i-s@- -feׯ":f^r׷a 8v| wK3Xy?և4jBV\Zg Tݡ-u~;iTsE>Nwf2C]Ȍ1PӨ3JoS}e. Hc$&3b5SG$vctJ2Wwwc&}o)YY5{=6KEӪec;fJ (kn`fԕoƧDTuW`i],#w} aw#LF,*llqt tQGnfC~L~c2|RlS2 ytgjSxfМ0 v["-yamhyU7 {!Zx` 4+Ҏ6/ڕ\/v'[] {. S%erxEN BISPF0͏V <2%lH~TYUwV!Š%{-]D`qdD(dJA]id {%ɘ#O *Qs*QW)uw$JT|df[T2nGͪyE"wp vuxʔcL 5K-y|*D~2ߌ!V#/wP_]3(m: "mAj2Z't"LVdfMf]U4آ\Gjٕ_cG?rNHa\2GIx֋81FDDym0z h}0*#|B}"]w.3#<{}J<89rʎHk^񊬲 T1YnSS">^3 0|j)p7.@rdVuh?cS}0-cdN;=pÍ 33 tq :m%W;V+4,N#+_ZxCX*Y9V"*ֺ4OpbFngO~4'_n'DSJ>p{Z8ݭi h``B QC%짎0Mқ#qwG~.{ڦ<OUOŒ|p>C|,Jty]g Xs$ ֓G :G8tx1bʧvLꪃ}z۟Lv}}qF=ޣcǎ?(ELy0RuRӯ@.^fh#dP+@~ .*)0G4~+"~J[ٍ9'lt`odN-9$>B٬Հs<1iB6$."kUُڱ=LͤsMICY5Q,D,3k4OVQpUvdP̕!.$ "CgJ}U[_gg"1%{6Tc [':R0en%su- xOhbu_*΅kPO쎪 yg,uMGLfy\x[O:R 7@v!ͻ3T_z QŤD+FQ6/NPNhHp"-OEشUߺk@1PxGk}El N_^K ¤^`tA 9`CJք+uH_JVq,~ScpJEӼXF ̙_6MD v+n4RyԋtGU@Ym6Ms܈ԁFaYAi'Խ,⫦s,'w1a$sNjݦN*2*1zpAߏHRj4$zotEP\ftgTVXv]Gg9,T13S]B,D6K 5{eޭ9K;vdJ||_Ł-)3>7sh4Psey޾2e*0I`W3.UDZC@uא-umeGG ]\/[N-~E$'5gf~<[QW2'bI=`Z <a 0N(T>5/5'RnRM Ya쌵񉣁{S]x'TenAͨ/}wwtj}~363>Ã7૵@^;{D~}dC?V 0?@(@3 ^F0htZW#d:p1FQ=NkC`Aɛ_.^VHp}bA}(!> 2l. \ ^`Pn2OG >47AiGQ%mϡu{^E )`AEzJ ζCЩH yk 2dgM_驂5(Bl62CpbIr|Õ&Bj}acDVOMt~" 4{F(_,Gֵot~JB>ְ>Cg ^G8Z90S%{w֥J8!mjG[£\JK[=Uiͮ'fӶ]ǺBb)nj':Ipfmi( qfJ%}˨^RTP7RWlkL\rTh0Hkx6qϱ|` [tә;4 L#xa9n>YTwE@ 6Q=[,Eӱh^ gʘ0?DT8qXRz%ZeSsB[Y(I5 $L5#"y>F1hXwL1zDάx4h^>ǦD!^e's#$u421SACvgP8'kDD;p'%pVt41= @.LD f 55͸RcI3Ck#=zhhqGK>B6|?+ "C/{mH*d?c ƊXڧiG Cû Df!>P5?R|Rb5HsF ]ö@3ޕhr8"lFBU$3)@6fP[ywEAf%ke.kl~EK˵Gt.A+J}w(J4{y{]4gCW+zuҹF"\|H;򾎿d!¨+SY#9+DJfCHuߕv _dxSeϽr2u2Џhf0-JR:㮏HΈ 6ڇЪUAB[%8^!` \_`ȟk3hPS%BOv}9& \*hSIFPf<2LN~b{ qcYun hSSU p +\ X!DlP]UF5m,,gr;iRuq-63$ ¡#k(ּ AdĐ5Gb1!cYc>y2v e){q-NC 9IUrûEZWxY< 2ǯV$0(&sVHb|0zuoO!zvݖKiZ(N`h)8-xKC P"eoેdGI< !h{t72`k&׍ -$c{k!t5!Z%W<= Aj:!@nRmwjt<h{^~w?#"z؛/C2k#DJRTZ=z H|õOfԅ0g +WrfzxRZ6X;F2gL)f=P#.O[ fq6\Jfi rۧT PR&m)_oll_7Ir? x(3@ܹ̏ 8v4v֮1-,d*0Ë1Bl-WafmhI3,й_,iZB0g ?Q7RˬmR;:N[ [tךN\CnQL,]D=թd vݖ߾ [wA3 ߂F3X:_/=XzԺNzlWKahA [}4L'gBʉ&81|ইw9U|>*MmΖw 8ꟼ&zx6 zV$-pH}GRԕ]'UCaޜ,ҁm9"$HuddLW Œ"괇t>ЯA"[;$Xq ;-7+XCf>TOfLs~]W;"y! ?pO2DɹZ_CL i{ρ#(^<ECJ=+Ze4Fp}s ee^-iEN`KsDNd!V(WVt9ZԬkQW>ӭC/^To E.-mehlo(@'?p,zW)/35s旴з===l۸~-GyB/{HjA'ܾW #BPh+8QiY7.0{fɕ_@/ 3Y|L,wR2`ME1hn;$[r9- 5ݡ #"P˵{t}¢"¼? bP{םSU‘ڿ^ K1q GWDZV}Ҏؗ<g"j4?:o3BB/uCՉiMḁ̂hI3`; +wq0Xz3R ` ph(nN1qZm^œ4'1;P 0ݯx4.mHl0 MO'/ws鞦6LJI;pܠ,푋f'srm|/my{O(GsZ)-BїǩxNQJW0dx] _)O=g " mI+'Ф}(`Yvnt-&zPm5LT0c&4Ue6J5-c\l[-)IlZj$zUjJ۫|lZ0<;䏐IF5g GT85I(# b@Ri4V亭be!1*"A(?}˯?G#e'g< ]e\aPLc8[LXq0x+ &bY{0!IT`ܛ:ߘ2*\6CRXfw"mAPnhMowufi*>x:x(oFS(1)3 n]E bB/M"U(E g~N(JUjvBc}2@R0 H2L&9TaŮH~-М׋pЈG4ϔe'}A> Y(Y]r{_ *(; YZ