sssd-ipa-1.16.5-10.el7_9.5> H HtxHF_t ?*}}dh87q_uz=| rbѸlL\ЊM!c794283a43916dbd2aa57a4f981814db7c3ed15bGb]'$W5F_t ?*}}?+q"h)dBxo$j|-G U >> ? d   : 7=D   8  8XxTTmT@DI(X8`?9\?:?=6G@H`IXY\]^Fbdefltuv wdxyY Csssd-ipa1.16.510.el7_9.5The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._t&sl7.fnal.gov }Scientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $hK_t&/A큤A_t&_t&_t&^p0_t&_t&_t&_t&fcb35d924237865e89db32869131924be55a0c45b127c2cd9504f0a27fd8b4dfd926dd9ba3e28e2e26d605d0dceaa96f15cd0e37bf4154ea6b947fc4d6c1c6058ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9035abc9b0923eee64da922cdea5672ce8ea303519f119a8a7435a4b8c3b0154e815322f84449761809328f9e348d27d01c6f78365c4afd731a17950a2b3acdf3f203dc4af2abdb9088d7e5db59bcafa90824fab9a2f4e60cffaf3bcebd9680d3ddrootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.5.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.51.16.5-10.el7_9.53.0.4-14.6.0-14.0-14.10.4-11.el7_81.16.5-10.el7_9.51.16.5-10.el7_9.51.16.5-10.el7_9.55.2-1sssd1.10.0-8.beta24.11.3_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.51.16.5-10.el7_9.5libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz9x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7edb7e9f0f3d48151eee9ed67617139a588cc29b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=684bec1e5d69b676c2a4e2e43ae42e21d04891fe, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER|pkY1Bʼns0R@Gąe@М4:0Q[^oޗb) !$LLEZ"ɗխ`a ;xVL=3Oo4^lG CrEuɪt7Fbnt>~| v*i ӲDfs $M߭Ɏ#YK~;*`#&3cGAv?A=\֏+Zf/ߨ۔=4xrB}nJm ~c'XL~o],aϜ_۫g_JH/a T\`A{dM:Z"½7(O42wF4mUO{0+`& 5ҟ6|8Yl:?qg"kP~A 30v GA'T,N,^aWVEJijQ®ZeZD}aM*m1r˹\)ŸD[jaCӜB|褲hv"9ifΐU֢dҎf"Mx\T 1 r1܈ə֝gPũSv ܾ(G>cz\a <N *F%~U{a dJhΘ1,q L5џkC3g?xٍh)HVEq3]U~p$;q 63%!uv>)w枱ReVK%lab{]-hvBҽ_OxȤp}L/]KZ7e{o!]̾IϦgSؘ#sCw>WL§1уt]+*Rt }9Pg')x/[[Hj&%ߞ2` *9Zd}j>40A٩ƚEhp'nV0v1|#eAkg.RGjGmw.l1!gYnĤTݒeF5z-X:><\J ڌ]d)"Krv{xM:?Euz!v^vs'MK_yV=̤Ϭā /ӕL4͈s$wPMs,li2&C Peٻ;p^WQX5UP@MDdI3!yeZ\_,1u=I+w-!n?aajI!l1 8ٿV]Fqi(LJR|Eȁ͢}WVSYt]?H:9̥pσte=&f\/)^,11cz?hׂQFp]Җ%Rغ~(0/v5L{艉wBqf=S~sxwb+ [m-7kbBDG:#B{G"tZ>HN#3 dΖN:KK7mRڏ?]bvznb9~L@ C g,1U{âzb()dMh(N>9;畊Wڤ,^q:*\ITU /=ʳذK3B~Jchuq2c@$C8ZY_JЬq rr?CD΍v‡.^E_+k/h =ryUX7pq z2 uN)H\ yfbuڭS#w |yo=1oXe;zU0D]Dߥ/|NMp}}Mp(*"d52 H[B!)G!yB[pj1Aev4gk=x Rjm;tuR8k86OkPb I}L@+e97VbS;WFBg0YlW>ifaX5`72DCˬ:Q&9!bSJ8/2ˠksUWF^yS3rܐsRq_vGzoq"`Eg`Ca*JWU䍾e80GX&p^8Fg4 6ʄ Ke 2A^eFsXnqJ`\;r-5ؾT E0#291v&J֒#V*q!yݭjv¾&Rq5Ⱥ /-Mm-(N}w@}N|n͝37e} p(C겍|o99-p#ArbVcl[]uO3 > t뒘!j&N3 1&A W9=w>hGl<쾙+;M#\nĄϞ^ó99fT{|L9ӭNGn '}.${G\K:!f fV ~k5(E08749j{j,bά~zy#j Ǖ<5|HaNŦ(=+)5^S{ v8xԵ)U- s^cJIi@ =RJ}Bzu.]gSaOGbmx֝@$K)/>,7.Kk+hȧe߬%~qiO JMq+IKs%QOЊlj7bKo^8lT{>)ϖ3 ?a\kIz"uj0$?in6)'"8,#Ne)fvEӛ>bJ}RlP#: nbC# u3o~ڤZ|o})Ԭ:Dw]U1"ɘd 3za?ONC!s)on߰vYj6]jep'yFjPA )xPZ)?$3cޑ@QlAٷXDQ/%XR艽;!_q̨qci74&?`ۨX N6:OY]lRM ʰ!Ul+\3?N@%WIgy)x/pPi]N&zr m!6g}!trLʟmjދ\' 8i41d{u~ *=6>N'1#i^CsG7 HzmT݁ Z`S;AhU5hs_vޚ{Ȼ\PHJ~' `cp7` oBEfp xr@dQ\K `D.*l{'<ôf6hCFlGFY~F%;$Bn4M5YRts^[˖9H}'h}P=e*13p8@p;\G ]`2OʚȃmQ -`: ORr;5;r^?Hn_GZzׯ̖mn`s.@=ho\.e?}c yp4֗g,)9@IɾL/jG_vZvDΗAw ;T˦nqT5(@1mA`ˎ a'Ï5WQj(E^^98jDި9&`o(}Hm$֔Xm4ۓĜ5'I/qƖ咋G*$ÔeZJeUGV%xyPv/8;zJ Tܸ7>]> tE2<%% .o9 ScUdpbip)tiST^jTU 0rJ'6 [{&n=R3tZm@£rђlESR1`3;.y*р.sw~Oq$~12d10trP:8E|fIq$@BG$vȭ͉Z9k7u-b >i_25o BeC聅K1S0;g!LK*.&B1 p:IנW*aEy}JxȕºU "-m"$ #TM,OU~WX*K=W/䵮_X//JbFvϫ1e鹥O#tgK-taF̏KwQB'!r|v(+/~I<ȓ+%RTi"F|_ %zbk>@l*%{2HtQ2ʭRҔUt}Lrl8>ۋKqTncuɇ}dS p{`CKHu KJmH%M9[KGAjdL \6p}x8Œ6B,2RYp50,8:ޭR (<+!k7CUT&~qXR&݂ЩssݟTR)~cN+qyNٯV;PEIЋi0*#IR[fԨ3yuL8ul\n$s]K9=y~6yZ4!58ʯ[cTֳw9C?c(?DXyM_ _!?z/9xg1H+Ý6eLTn^u7x˦'>N[H8 3xoQz rcߖ(%[L3Xv!W J T,΢V<(:k.S:t8qE8Zx]{t}M&4e/zqkGBNrI5d<}BqX++.ǽĮ'ۋR\Y_#5(Ѫp,Iݨ,#,pT;'=@S]+3S_>`=by@@če L)cj- .! ^6}Ky/ǿɺ/ưDT'0,b?eaU1A/ЭiL_3aq&z,R!H} FOPLeW'Cr42,]|7~dfv:jIQs8(&tH ¦qCP+J)$hzƽk')R9J+:\d6'p{|E%:A LyMF{Kq;tS29}aBI А '#U-DM[3g$ġP&.ˁ[h3ҰEMJMUMy:y>b6n=cX _wjy!a;SJ}(u >9F䞢nj޳ŹɈPtN¥4Cw,!ز]wvu">Ó7mz /Y.|1^*}3^&m`sjjc$~;4qy|F<- GzRI]Hyϳ-ؕD8^z[ N|7G+|ܸ# ;jbYnH=Sm*p[&dZVLc0p5OCWr8 Ԁ^(>>9b2|E=:xN &D7T.I-:3!|ar0LD!cIG\)~ ZȖZ4SٵJ>Gd5V Զ] u{+xnIV̔ ;އ 1d(`CZlg0)Fk |[v/m4Տ R'5 k}c)i⣷d5Qɮm /ffߣ+'^M6LүA4o2λr3gn/vZ=ƹ, %t5DՈ}-aעo˾5e}ATVi`k%>7 Ki7eŇ1j9ow.j/о[# פd zֈkf^v&l8;M,3vMwe܂Y\N}8SkbkQDi.cYi^ ztܫWO`M`_Dsg=8}sFk[7@yc.,0ҸsXTMũ,s>B4SFzB@TIAwzwH~FqD E4J'<-2hV|A%2pTC gl. r/^1"(ҏdC5q=ri;cWGI[XzZ9o? ^>)fL d]#nc(BgzYfZYQf65LEi璽6uS Ηc'f[rl{>eEQ kI41_ڏmƃZeިOue-*·M? ǒsS )wu"XB:YwtpeӢgˀ2=V/+J5_jB .SQtT;ǢD^xGىY4zNex7ɪw1٘::L(.j_@SΒrrzI8Kv)cb=&ێ٪0cJ}~v֞™g5OߘCHu,4󀭧 \ 2OKr]p[\<+((wvD.c=lq;$ثFr=Ș^ c;Iq>=BĜR8p?œQW N"ٻ][-7H(gž@ARnuqխSaǻVxVp꯽e:%S0m-TDR&tLmD+ IM+WY$?)C``[Ԍpf1)|igowZP R86XߩE-:J|>PG{T _|s|ibb`UNfJ]A/)~(#i$04e! QX|HX pXHZȷJܓY+w XmPB¸4G}0`BSە8A 0,(0N7"i,P4T1o2`G8$5h6wAR{@Df"$GRSQ[ )5.rF :J÷<8ġ1%`4?)R]ׅIo?)>f*픢J?KO Z 灐\$WprtL>ZQ{GX-&dT]1}E(7 כ(q9"D'/lwb ޡj=}K3$5l䁗KV .wȮ#""KlC h Hv؛:ݝyɯ)hu"?7=y}_$=ieU_Nst嵱dz)& [U7R;#Pv}!5']1eGfܮC<eiٷܚʰF(CH,7`۩qvmQ.Z6Y}^v7KKJ]/=ҴAz"JZ&e+Gz흨ǁ'|*@7OaRj;d k5q/ݘzಱꉪz^q #cF;~xy*뙐[+@y}LivY6^RF  Jm/U/!V bt--Z? kI V3^L=1Rg +<\*P?(; iKBj˒cB)I l|mDa&<B ROg6.4} 5Uk='Z%@:3|1aP6ۡ⳧nH| Nv|Q!=s':DT[5ߥ 砧jn ٠6TO{h _Qt$赿K&J#&iu p*76zsK9S:L7b Y()#gcs,#4^A" '"4b_%]xD*m,B3gRxt)*"uWUv‰߀լyDްΝ<\qЛ%MHdJVxϤMКi _s/Źl` f`mN ?DȠR n)%\PTK)!;.+ 9NGa7 ZX﬊}Τ#%w$gh4aˋQ46aIf z V!\JvR]5}MV%>>Gdd"!D'yZ1\Ra'X#p]M9N < rj0Sqܖ~ot+3l?]88"L!#J ZFHы[za>Eo T;eMUpacx{=ɥ9>!>A{y,# 7ךlgDin2G-v}pPBa{q;a K+OS1)֟&Uwtԧ SU'7ص ,^INOYRAJ ;+Ēڛ 7C}MdQ+ˣJd("շQr"o]^gY_C)x*'{^A Ub԰@Pk2[gK= }cjL4# 4el [?l.GN>+?{$'gbVIs-TWHIa"36@ סuzi5S 3i%YDioits`pwzE[<47J|lEو+cnbj8)7kl0LUzMйb8,-v[mYTzB=ƿtMu 4,ӻjoXFfrٲ#郣֋-A-7w&*< wi\j^Lڍ) ĈKV/CEoYb4^c_>Rpv̑Yd۲?&YPŅ1&tk;S< C9 ;L>'z'6a7@S 𽀵3V'!/(JEYJ 8 DD(K/Q\;d~NGwF ,H;[K]& lz A0gg/r3A+ow^ V'(pU84IH$oRچʰa$ ONxժ4lNWW4R6'lXDßԣ0݇Уd@W-kF؏v:?M )R1 f! W"566[<9$qe%/6I!F_ծrR8(<!A`Go%]i-{ʋ #ؼa5՞1yL1h('eYncHZ  0e"71\yENjW³AGҶTr&=$3LGѾ~'4_EY1Z1;ߥQs†|IbY? PX7}6w}xFC2&R^~~e"vؒ>z>jہJl4 pN&v @aFn)gL &wR/PN'+Hv'?s(_31e-"yl%$6-)t|{O\+ë[F']t3X۬!gMj0 t4ܪ+l'T'>SӼ(0ΨJMnñ[d6#t䙷`(6Er1IPoe2Iꣁ_/F[%B _A7V =9 Bܭ?eCω9eW=q?%*u ށ50%(z(+{#,LW{R$|160 ɻHs-* 23S TtqW H%v|͖=%|;1t| 좞(OR# Y= 5Hf# -8Wԡ_蟰s]ܦؿy~gDv&.[O>C'Vpx!ΩUf(qz o2v 7!SX#6/J7$Qp_>i@`b}#:ajݶ@>Z\ʧA~VyC"}זeY+'nLP:u|&>Eʧ.] [CŶcbϷ F]!+dׂW󷍘7H3I^)㻆p?eK7ѨN6S4W#ϖ$L֢ٲ!s)k [#/ָ*8@uW*K~^5؁ s3W!o3kYA(4 JH/'BRz~&* HVLa_k(-bLY m?D[ HUt֑,8}NHaGr̥OW> Auʘ7lнW>1[&$'6| ; JkȴBViYzTemolJE4?H}KO;ɚ}3dQaak*건PgƇO%΀(%`|lƥ=tK\I =lN~jPkRr^n'2l!#VZ ēKYv^6n:3OCcVnJ zhj$&WڒC}{^A/H툝psgmuC.k7M@%qG"65D\L*3Z.;ŰcBDMsG'`RIzϒ0}cL#Jt=> m XKLW- f`˧sT_[)Nd7S=]?|[OȰoz]TqR-Z˧xObWd8̦arX-(bf{6;렖`97ޤ1@CkcaX+\m|#ߡBU*>*pɠ#HݔzlH.)Y҈8)Hc2UeU&oLweo Bpe Ӆn2`) 98FS6'[gLrA lܰZ+ql&ӱ 8T 揘؃NPwQ^,b&&,EJy8IcFH$8%ƖDG&RXbפg.a,8M'6S XAm~&o\ $zsՙi1JI ?aN(<=AbB ];~cӗJޕ=v(ࢲH ^ Cc˽Dg v0>S,ʦzjI2{DZ WEy"Dr[rt1뒌>^}*Kv3P n3iDzMGB>Pk{j! |LP&U,͊MdL|I_86M}L ̃h6-6%Y0 8v .:<;QnOeJ,; NM넦:gޞX !F9FkޕB\4"Yp'ġ?Ǫ]Aߐ+~%JʍCU5/lt v Vm&h†XXO{$ ƫ2VeKS |d 3uگjK2[9S#@-4r`ނzԩBz)s{brLq郙LӪruCWw{gϸ$xn&CH!mPiqo^?+Y E9gREl9b<ɚu1~;ȿ+A@6niS ]"S;Z@=dJoY_&!68b~X+9}΢&4Ȩ, 7fx"̯oup ɦ[<(H< ۧ]KJ0N{ibt~_chk4T#xjD ;PC~\; wYmޝѭ-!+'OܔW n#?`GMjLwEƘcA/l˕!yHVo&hs'wq8Q;+[ʵsp%{EiR:LX#c(FGLo`I2EQ-1ǀ8}hK"nmYH\r q*Z$N2q+kq \}3]Ba=TS%VB b_ې(@q$T! P~>Z;Q'&=QgpSAH|Q l(Ybda jH6 \SvNx8vNvnN4^7XNyOJ4Ȍփ<hgb^{Yyx<܆ch)xK]Zu-X;'/Fh|V/'7Cw9a6 S!$n_ګs@u X,KLO)4a{+/.Yrݲ)Y)jL**gݮ>ן _&P*kݏ⼋VYv2I Lb/̌fHy觡%"욂f 6~Ljޜ$7i߭C ST`϶f5-36uN_M1"dDyaq6<tF{O3.{0273x-U+w@UCgI, ibCKi 9ŗЍJ\-Br*o<(ks&lk}a6yq5Sl"YdwZceto#j|)[^~8,^MR@Œ2~X_7啻^vӯUPo;\O^h^20G8sr$eF!Kb9bx OE3?靗Wս 5?c`bW~21 s]!%OoF,o3A$jB1ٵL&'O9:%T:itô)Qlם=)걉Qea3|B >I[DO(equQ4P$p.'u ߌoQ(F Uf<̭ۜ+]]A-6g}ga#e&/&1}$Q,i G3*C6wW ٞА*`j4CnBHFh|q9)ַDT,:熖8|/6}Wwd'PKH`(9ilos-qcEMs@ÎQm&:P:UZ^A ŇS9[սa!:ȥ,IXU*UT R BRJO܄zAٯBNV )>"|zM=95sQKa)aPB1ȟ PGtX.(r /A:UAz0c}+[%h>0}J3xCU./nm$|:]Jw?Ү#Glo4m.G[.12'|eܤV2ҡfnʔ官PQYm~[Cb])2-qQFwBdaTq(Iጔ:T,O$l'75Ҭ2-\XMZÄ?3lК/M;%5cx.(pE`NV)qqzdJ+;۴gĝWQ#sly:HZ* %#F8$JR`cZ3q`lߛ\UK'l,>=cL \IdvR]O^ ]ePg-w$긒>]WR|;)%;1s` ]2-0l4^Kxk_{rdN^?z{;PfVo[q`?\=eu[4z{tO4:.|Y(`a9%WJBE" r㐝CK۫Q0r?r {oy3xEolp-a3Zh|%-vEK$K8ߢc@; ;Ox}Z|&E[\>' k~dT~8؊0cY\\gqI'uԾDʂvez*w>d"!>1O@Gb(BOHM4QE$lɲ؏h3)w.afMSq>d<#<]&fRA4~CO=.p!sUT.~t[E1{|WMJ73QKqGY# 294;[:+d& d  giQ ۱74,nTm*p2h*+OSηGv"T,yFO8g 5hY||D#'7wՓOw9n'*P/? K07"D~S|}𠇝^YiuU!@ 2Z2 bI=C>E6:-4+`MHtܠ8C1Xv(NK;XY/̨]M6i#,&jv\Џj5UYgF BC[$~ͺ(ĩMeK_8BSx+CZf)S-F$z _͐<!G^ޫ]Qɱ-o!\+jH[:dkki*bu3KA+uR69BINF;`,d25HVYYדv>SBj֧{`W{o7lH㗭L'3g!$^9eu=U$뒘=ZP&jaj;\6GUNkE&ʫR_&t0,6'`0l>B'@5t|ِtTb$\[|e|W0WK2JݍUL;_P-K!:bI?m[iW@Azl(ߋU\w=tu,ܞX+!=u,&>Q~A=rᛇ+No O7 nQHdKG?xF[#) ~ï\j\e$}Iv>s~"P6 KZ%.eڐ oJ:dIIg`45ËC&{ecܰpWZ]N?e~.`zZeHCJ7 <]hnMo`{_}&|A=`uaU{TVn YPr O,Mca+5 5sQa2D!T}s~J=@8SaЍvMܗێ44Ybe:ەӊ1ɵ>d; ^olBW>#-~/ʌэ"2׃ 2/Gs XœǨD{e/zmcQS]<*!| 'Ƥ[_K۝t=Vd:^lN1]*PSzđ]X ֍mXԈ' "2aw!Sޮ{.07&E|22*c#t$ؐ o5e#=9ު >W+3߹ZJ=7^]Ƭ 1|ֳW@ũ3mOJ4醃1a!OV#6^W;KOooiw($x7E`dڪFqlzht ϒI@n69ڀ&:(ægY3{,FMN.)\9b y>r/8C4 Z+wGQގ8-FhԓZ&+ !R)&" w*^؆,kb 1-jOѤ{X"y4mpËq'`zLV䯋)R'KW0N~$VsدN5˫#zeQ řZs̛4ۖnU3c aCh@'"Al'\5k{f:Y)nnH{ ?^lZ:԰lQCv 1 L{&w1H{kC)'rm~(ѺjsR\:+f_.s|clTr* |wyFO?,$UA˽#}Lr7J4uu,bPtbq gŽ e6շC iu}!tw,6H#F+ĚԡYLk+~9S+(ż4}^1Lp"X'"у f!$L|:?mN{J ]; nz!اUd= N4k﩯.fCr_A9F n # Z:@FutuI Dcp"m{Na^ ZdT֧Y|}cu *5xq ^a~7z~f+7gk+-ABUuWJ;;`ipzVaFsݹHj؏׺xK#홋zՅç%i~/9 =Xc{gco|͒ObzB G&_LX 7xy+3OokU  {iQ+. ,.@4Ly7krոk&}7{)\Sm:GcU8k])J!gi)w5"e$>PCQjOfxHc+'eviՁw8L7Y&{9ǽGZ&R yt,23\A;!%=,aNtXV[Wg]SߋcŏCo;eId7 W<"ʿw]heer[bQƿz0|TPEWA)нFc{HúQq|0wVi΍6u`qąTq&c:5Y5u]v;5{Y+塪;C@ aƢg.n8z}xe6\4AP4t4b3D=]w4iGq@ ^c'7c{ưz?d^eJ`vTq"{ϗw?p qGD,E1+qz>W&0AF&B| ~VnDchDn"ϗ~)@m~4v5ןYtj[@' jH={'@S,uadLW큹}T&Fz=H5ΝgdXu5 ݿ4n>{s "I O[0#}~t[6nLe- j/D.^{f n@xAiCt$2F _4Gκ%8\Ўm$m 7>_EsH/5Δ=\x ˤEm*G<%UF,=Ιx?nUw6OR?5-arUpuV{~AE_=E|U³T@kv=3+?0bpInSSee \f'PIM9 + +`ƯAPf(G/N9Ah|@Um!1g+q=^U#!E;J5 X:xf &҂II!:$H}s-P )\7*WTv9 (t5qs:vKyذ l!#bF݋&sP!_5tLOM\?xꟗDyǂ:vqϝM 6-tګ(n?ѽ6Ƞ^L:C6L>BQ:H2VaW榳;} ?Sc#abW<(2@F'Q%_'ѧr1ʀ ĜPq8,+ohc^@_᥹A>=lwzڃWӊ࣯_XMHI]̓$> DG{K5H N8wQ9P)c"!2"C~CpU8 qF.TGYk&tv_(,. 6h7ksuʥ@FQa\fuMXT2S]JdRk8񿺢`9ڿ3v^l h}S\8? E_fyqB0'@,2ik'e>H4&Y{ ^-=kڋ#pfeaÆ_UF})eFʶ4mCQ_)1$"|vMFG^poI:Ԉ%deI1T.'6"r-V񙲰4Ln,8 /QO{c'Bj,Hqsr7{y0 B`>imT&&/9H09R&-󞠠ڤ2;#ZixK\75]Abdn?(M|< IF0̻A,7EKd+]M ƮD&oÉCʻA׭+(S!b0/ieDRrMunb ɟ?Қ`x(&u:7Eo^b;X. >-$|̟{'ˑ/;SdJ.-(/?Kq*zƴ ,y]iB3DY*d s>]4C8^A#a(N6?(H0PilGg1azEgMiq*(" #DyAF$=ГZmjLi+P!Pq+نϟK"GoGU>Xj7=B3 թ K-(oXn?Dyb :wY*pPWRk{!vx]]s( 7 ř°j巺uCOѠe(!,WlPbq(wԙ)#uPxEHH(mjD`e;7)=+z)ZVChڞ}L) Cɠ_q^6r8sbw148 ]NxMYBd %^ŘyA`7t􉜾-ذԗmA TGDUNk.K``+9ÏMz&A؁% 9Qb6` C-L_9Ġ!'KF0wh|=k:_y>B:dTI5'q^HYٷx^C8/q5 J'K $1L7jn+MFʤG`&SwIEӭKʭ#BsZSnśFM|hw~%/t [= P=ĈG.ƥ1>rU,嫠A~8'82ױ)ur6(M\ۥot|Sj.!~7l@:$+psY),Xܦ uKR7o#OXxPgґyCV]Li=6ϪЪtEJf 1$cGxѻ"9CCDs[iS*)j喎aq:F7_QB}#F1}BO{YQJ^a_aTVH㴓*pC"9m)bKl< B 7 <2@_+Ӳ@sƿ3ՠgDJ䙙BR9B׫Nhem `wIМ2ﳳЭ 8lo"yy;\Siѳ՗h y 14<;/R;4[CjM `U x];g^e Cų+GcӦe[A@s PԞ=3ѣXWSn$k[ƬųBPD\?ǂݖ#15j{+ҋ<U/S`My͸:4?z3ɪ5iW׎^`!`taGR'=5_/B#?EZP ܆:;e-ս7]H%Q5W5~ğ uOSWE z b6P?'p/EF;\' '42RPkXe / Nmm&%Wdד٧b=u10V*U 'SU<מ 𒣃\G/izl`_6j u! Dcd=Uj<7?O^5}R QIKJi b:꽮y m3^ƆU=g ϼ@3ڽߜ!`&5ǷzV3VW8vjAJ0E@#͇7miF85X:\N~ƃɞF# Dhmt?BG(Q)AF i[ mrXYrUp=[&Z8=edKifG_n,&? ֙eDe ToY%V1ϫ )n#sѿГEr[@q*pWFdG},r~HrZs坠)*s ӳ;e-4Sʖ0OE. 23}o%?y\%Zn1]"5uO&>Ѫfg҃?:^؜'g͸3>Ao';ʇ7Qswї Zk_Pw6d4˹PMT!nx{36rdw/B#@g{D9x45A:O)|V:(Ķqg4\ARoUdg}F`F `ɱCd~4BXTȫ.֧E92 k ݉-tWG^ h2 1ޘMNc%\]XS?T shu3lD _b%ڱW|O$T!W,u0Axc8B%.&mf{L= e\3L>[9\x'栮6/.Nf5 u Nv{ 881R4.MO!9؇[Ԯ? i2+Sy5Ǚ6[w+u:@8tmtUYw-;#{q-4H GeB)1-"F:׼8vv#hy֫ sH?c| GOOR_ZNwkw]#YFXK;P棪Z$QۅYzWy2تF3 I/ӊ0FW"\A(`/9-t]KԞ,Ś  Ili@e*'Q&RL\f_5eDžlBt g5^q'@qTj΋w3 :=P5S6 ٚsdP6!&șJ j:tƚ]IJrttqfpL 4!mKX3"r3+õVWCџwkѢ C|.d `;h u;{`e >?JaKtUa0i}SM$M7SqZ|z]dj}~_-ǹ2fz)XE#PQfVhO&3S95N9˹h!ENrb~ڹ؎`l2ȘD2Mא {x/t ~`JGXD-6~vEِrS~;zn}(z `;4m!>!8SU4i2+3+|+wpknA22&Z*_0րȏ =NWJOV(Mq"FE:aԩCcZ j' 9L̰,8KD\k%N<:XXc/)LyPY.Jwh4K-ƯGxF&Jlq; 3('zLAG`7#и;_F? )]yj-s²exr,# t\^J ADB|D2*uWqHj;)78kflKh:qwJSLq(ó"ãX&t>>ѕ5q]\o[O_aB}__q֝-`-bΞef+S>eg^'aynfS\諣cFiED=DxE?321+ȦA6H,*A9N@0YL ^Y8FSMr l}-ϦOޠHһ":kOF*wCT&ϬJ]\Y>+|ȃ3$A3A% J-h=IuK7cW◶2CCTmT捜0J+ge]RJ˻XL` B׍=tٴmq*Su:fۅw\ySU& Â&f95;+hp&} i?1 QJ3ixn]S~~4ul2QD-}AH2#x/AfR}` fZ(֕M NyAlWi9oY8TEpـ>7hsV)=ffll03F:RQ x8鱡򤁖:ƥ~}`0!ґU+'11;!דnݏR GVΗ Bʁd,'wnK8y΍/tz كru˚L!ov!hAҪYיPU95[Y\bA'p #; ]zw9U=|1jHNXnJf+-^@)t Ɔ<cb-Vڜע@MK=/'O߈*]Ml|%]Ji,ДhF.ib%= z`6*Ŋg35wA-%lE$,dxt:W$ Ft#>4"ŧ6)9vz*|ڂ>j#8՚ԯk/g77V CshfcC&VMfQ%2%&uptACF\ؔL;m~57y3Լ$ɴef:>z2%_zRs*;'N 7e=zwt,{>`7nRJ|G_HT.J//odZq=QU^NH,T>r[44dkP7gJ( XKxf ܲ1\]џEJA;U?nbĠ=hA,MKUNXgUE;)Te4J= zguE|8Zue/fKv<^JEk*`傺 q{^w%zdQFZN9"&x\:h(nc](D >RbA`ّ"K]KtB;\F|XW12eb")"c}##?,KxXlZ+dHC><1jt%C[8!kC( hnf2#D2BLzF%}sddYQZ9)2d$o~R7>fm'gت:L]p`ց/7.m)I14$݁xZaJAsx"uTeCjA|kt&5]> n.Hބѱf8NZ-tzNr;#dUc0:fD".fzV<1Jqx^ߴ8VIkƷG;5omp"`ٚfA e[Ma4>Ҽu2S3uaz^?z٘U/ron6`**O\[`bnAz& 1"柶g><Ϟ9 h^ ))NH)FMcs:elgЕ$z0X '.kҚ8 2BYb+ gb:(*>>VD8Vr~ݼ!jb1 qb0'n.:|2T`jjʛ1YAI|sًw'c*B5QI=m;A$/\a's$relB).>*ZV2hf3T c4 aqehJkM=6\Xf[Ձ;YyM=LG :&-c  q&:H4edN2==Ѧsz(y6#,S1 ]E*n"b]٧I:$9l\y_^91gp@Rܣ.urm U5~ږoBApUe25#:*#![;Wfy0[JӬwQ⃏I ƶqw3jqW?A(h$]6Vx@j,,|y>WҔSp߹T)DiEH@/jnƗT ~xOK)MYNyLGvǭ٨nh]=^(cs$4phʁRC<椦sY$=YY;j}竓 DS8Wu_lq%a~#Q,tFLS2 y5e0rm!XW h '9utK.Qdʋ許;HyD) #b`L,CɒW#\x_ lUO8F,e^P1Cs :`X\ rp hZR'yQlKZ-C8e NqC\YQ#d E^Us}YqM >vL,KjSO]A}EdT9zb pђ bY* P\qEOo@O̩CC{If;lq@9^mE.0rc#yu$`00ZJ$.\2S`Ժqs\`؂ƻ ^NUTb Bj1 t\7 8ŚΝyD J]R|QAPrNKٙP9RDÍţMZ(d_f|GApMnK%sǝMXD<g^wH@5uv%Ԝֺi+ ^"h=eygmy(m5p§jd𑖗vJ<2#mv5yꭘOn`&H!@Wťrn}ٛH}Q!Ŵ&8 {ў覦40< ڞw$ӐfA1 Eg ;Q?Lx S Y^ry8ef[?PvUgm]<L%QoL&>J˂9UG$wu^maPdģhHY {9$ǣ6?q? Ky }䔅f<ļ<=8|8O'8Gl:H80^sOυs$F(:cY8m Q6"yZ{`a.e^-ڞڵV3FcnЫoJ_(*M v!B~%+!9:䡪HvjǕ\:,0(?KY&FH`s7E`IVZ-OM읠vJ!~8ҬkiUF(3ge`fCv r&0x_F}'iNuC ʽ~>l5Iggz| gUKI?16Kz\b-{eη-MI(;jh NHn]1sE&QDZcZ>7F7ۀZ@Jw ޿6IvO4?*˻I5 (, +1=Q< 2@f^y7 oԏLjc3ݲ saj@u'6]Mn}v).?IQ2$Pa9*F\'fe*8s)_,UB*z/167ZH$Ym9\ 4ļ zjC79A]d IeͩĤX}UD~ >NS/y.+8_w:3mF\o(=~ۥslhcy`g7CUL\0wp 6f qE'L<;]܅Ai4ȚhN&t${L\J2;"՝nh`m,w: Xp:w)/v`A}1&`\fD7s]`K$rqG[1 սۆNF^) 4J뱵)0"qqzNRV4rϼ# l W#<<Ʌf̞,ւn%vZ`mZpGv$/9\DIÄz+[ TȄ'Ml6()]^ 7u5ٻ s"2|̈Y3oYgQA*[*͎R?: W%[#dl҆! M\LH϶PXǬc>ٶLcф1@PJAجLa8)7'LnXuHO]›<[5Q\w[cXwRX?BT22xH!~NFTS9.\ȩyh"c*y8G}*ݷ@L| <aW $ } 4<>a*=-e,e1h#VB sEK U3. G:HہXHEbm hg_eOH_bRF$Dݪ 4[`1Ǟ&B4D쒆q'M+2[l E?3`ibޮ-"/8se ?zT7X"C@6;k !l9H6>O"Z#X O OpPRol-.9BE~am+~r|ݔ¢sYO/Lh [䬢rBzr4w/ J%vl1MQµCpC4BN-~lMSVt 9J]`II,|Gm$?A0Bñr ;l`]?4{IB'2`De Jnd!aW )Im( `G#`R  TMmIvԽN̦{RR'^ǝ=?p 2"$((2N Rrk,~i#*EOEѣC"8w!MV Rl25rJs u5^U qLA .6sY]4}13YX}E NſO^]$3D ;3g%^?:r[g錐 G8\*F?ePFEoY!OAo QbAC臯5F9boR3 &{0Ov7`̕8.>`I ǧa- zƎ-M[l"8B?E QkZ~^mp.jJCedj#?+%o/ӵlrt 8G91.C JqI ęGICaĨq.y[~TAROn3l'mkQ)+cpͮ5[x @y]LlS}2X}AzrO&5/[.0=&<3Jڭ>JXED2kU_u奘7;ⷑ9_֓7փShВ!snQu} AWqA4=xG6r 81nMoco_ ,q7^F5?5ώvjuAگW ؉H EJ.0+j~pz*9cQ#T}?`X:kIz"2iw'OM/d}Ё6ޅG]W/w<X$k{=@,kfU@dETNLPEXPd\)i$.5,qeԂ.}a!ԴnZm Z^FB0E m@kd!J\[H͋LPQprsbU1*_Hk>ߓGلR|2Pxίc[qT cK=ײx&a+M1ؑb6qL1;t;JP5$[qIwڣ1e\!gZJ\"U)\&d^ GkzꀈB Y\yVG|d+nu>; #r: :|6d5TzIk@d_Bğ{Kkސ6 N̐W_$Uȓb*AȐ{4;4|fxi7P>ѲAt6]GJ(G&PG 갡5v6 0ĝyQ=dIr%LdjPR`XpҧrgLbAUwɶ2:9SM-Qt94Ɍi[ބ6ۑgH'GbX zq0v~$#ҹ eB(j\R)\!_h3ǔ8;y~R!laK~\bp~kնc BW𸆣Y?x .T ء*G z%&ފU{7ߧ›.)jXQޯʼjIv9MAr&'Q4/ޏѶgR8oRpxInJ5MVH*|@Ѵ/_@T48;eRClIFN'`*7cpoj6HG\.7Y h~f~7 z  Z\/>X!My6WͿR͜<֦`mC_fۦd;e=` ,*w]q|O,2ΎC%5ڶ!?ct~ :\?3ͺN@_Yj#cҖh.R |Xt% 6$Ayl-z-3ظ4ړI-9V+1O 3x(:de-Y6갇b _'Mj{?k9'N9̌t;J xx4бbjՖqgqoJy0$Bօȝ}[˥H[p!a+@Yn$`){w.Ś^&ljgK9(u$0eZv$";ȶk7=2'A[!#NfL]Tǩ 9,jMxTdzJ\"_ UD$``fmyOwقZU$! &? {쑕 0W6!$ eXĢP7'J`1}Q0︿E5pqҼ|X h1FCQfrFed<7zQpf5){f#)@y\DuVrצK(J]Jw fI|v{uV潣E" "7˝t PLF;4oG0 ;͗^z-"MaK`@V>tQ> ;N-wјF&sxrEIu krũwwJW, i}W|WLeC%Rq4$](zn^}ڗCOF&nm+# ɕ{a ڹCQGgw]áZA 5Xݰୄ!$*(*Ff1:v5~J0Co.G(}cEoI&HאFZt4]V`^ xxZd[W†*8&k[vYv}h~2}^cip Kv-JuekUe|]OPy`aR_U[a)΂=q|f6,7]oYmin "o-Ȝ6E-Gt2&xq=4W5Q'_jņG,$!*,(I Z./h.f^nZ*{+Rr?+YvU{"Prά<1 xᙋſ|}5Y?jX?.視b_Rז>faw*W}n@@]/Ƒ.Cv5M4+~g4%;&=6aV}zߺV`UL8J\fpi6찃fV*Vڦx42)ܵrUܬg֍ݴ`Z'_VCÖ zW2W?ؼ5748e'/Z[M;ƺ<_BtܱXl#L+>잸 (a+G.XD8ǀaϔ,_g;ބ/iz0'ʥ҇lfa "'rGB-Rhw`?Տg1;Z7b @?5+p$;&HL,U.Y:@ 5) z4!Y'1wlz^GWR1jG~nՆr4^PzRq[ ߱MNl xlE!H8Nf6Cdڹ;a KhGh$"v2ΦF+.~I70oV|!В>krS/@E8xŋ O <3^G~?%O$ b͓7$<ά!h4 kN& 2. 2jB0kX\tA"`;)~hXSFS!ԗݓ%v.RNɺ28q#QOJ[Vex( quX*^$IAm(.N]SQDfvq44Wϸ /mͷ &>MdL3 v@V c@On^-p `[ATzTC?-S{KJzn(" OkǍ;;dh[j (uqEa:G0tL"L|4;-^-.Ҡb2H1)M|0RΈ쎾nFCb eBf:?i4\.%D U0[7jCVO̒ h F^R )2]oO`Pd{ဃ:buPs4^j*/n*o^_1$&6K20+  0HVyaЭI6w+Ĩȱeu"IPZ:m$YbRyrun Godz_m< ˕)Iɭ YV=XTrV$OdbCVʂh(5e64,n`30UM/몡E~VG*QȆ8sPwZle4onTJxU X@ƨsIb|b93|Pd(xu}Z>JءC#48w2*Piwz[yAg;z5B53~ψ IpbR-%q~FuN>$%8$=HVX'R2X(3nPvV_uwxئw0b%_J  ~ |=TMG.8yw>j5Prށ")♞E`c:.ݲVzWMud[Yo *TG2#ү9f1dk.P|MիӸ&^[*ynU4|P: m TB@=Se4{w?hRpw3)jh%djaC)C,!Ț7@4])@ O.iR :ɰof2P*/¼Un$j\ρ45n#$ՇunHAxVrtYX6`?ZXjoO5/S>j^`K([}3W{uxwimǗa$6`{layEDDsJI"ImPe/khtϩ | -5^erumla QIU(Υߛa,Mm@̕7S-Z<@a #3eɕF`OB7آj9Ux^4;9kΑ(;\T,z] @_Ӽ_bV`|2OQdNg"h+ FKTwP?7dlqHYw# Q^{6gY8| ~ULa}ԏz>~1HOٶ}$dƭSa/i`8$W֊UZ-U_țʝ>sX'B|]E'9BP^.I:LyVb,g`EX!J '(;&X@Gl#Jd)frsޜa@^f :?v'}w`%RHK`.`\?=lo3%ڰ~wJ^& "5id::٤a?}Wv;p TPO'(. 蝩FY. )a@V tV )D&ɻq_A̶?e #tEYߋ2a(恏Gj /=79Q;Ae4_c[##e#o7Aǿhx<4 \p) #.},|:/_+1:FonFG-̗3[RdM!ʲ/-}rV" snᴞ݂;<_/-+\60yWFku|M[]`Uۦk_!EP6/?hL vG+b?'rA u]}* fXbg3DG/hS) >tL\kiWWty4}kgB̆93v jnuK)o/sFP%,3|Џ 5X֛ǗG bUc ?*ɶJ/I_I=Zrpk.jc;)_ϾI'BgiD4^D*SZ`ퟓ/&UR8%Y!HTf?~{OidR3|ynf62VH//hz)3[U2EHdl'kF\uk[%kOj_ $yUg08Wʽ F` H u|q)ՎRm=:=N6gapd]? +`BHo|n/b~583O :=z|hMgUF<7?u0 ؅fͿj3Ӟ.ixWQ80@Sꣃ/ >-P"۴ j5 :%,_tkuTMQux95eOsPG.eЁZw62~(jMO rju:/`U^fk y5biVtTH56N.a {ڝq9z63h8&0YLaCGU/_шxuR roұ5RDiy۶-Sx nqdl,d;H'P;s>H4J!jo}2)*^a#m5(68ZX~W?IUץ] FWHS~w5FZUэ>l{K6u0#8A Lz[X1 S#;?A4È?h™Ԏ1N/SzGgo+c!ƛK &P)u3R$wJw{)J. j @07:gӑˏ/"ҋy-r-C2t@>D Y˯ InXaoIF/4@lq2@ǿЫqnFw΀J2IP$Fs^@T^1i"^渠25tYʂ`4˕ևA4S0jD։A?ۆYQC}]Y^ }4y#83s;EU"gL`zdbh_ᗥCk`I>`of;ΩDCh"{jvR=,K8g~Zd-o[?.\=bᒈ2$`%=re/Ѿ n̪Xd|aB5M߅xb,[EAlE,ߏty j3fp `6',t7 Kx#VwFҒCE^dzX wκR\94n>֦,&4hy Ƥ*mj%#!+O _W mo.KSrk齛zrtZh6iѠd8ܢK"zFQ7]Q,Eo9P]=s22-QL+ԂgGC-q%ws2Jͤ} E-޼Q}8Ϟ]xPvt 6h\`||{?`##Sb!. eS/ _Â^1auYiцྜq[˖w;V ^u҉o@=j|2 lDo5ӌȃkU {se8}\ bvy$.&p|x ԎޕHCF7#WO0XyӽnT@ϥmeb".7*o͚#`zE]mz&8\KHOFilqr2K/W*q-ਓa d׵ݚyHFV_uNHۈ6`4Aprtp1' h4a*˽ GơH4OJ`P%[qtyvFwFH@ MeBNy60v=_gҢO1N,{.s* 1b(y79WLɳ^8iJcc}E's-?ir??ןl7س>$'ȅz" IEy#?ۋ&nD^Rxu<% Kި),fBhĢ ;i(t`c:&7nU|ʿ5\Sӊ@M6?x޹Ԓ (=Ɛ*osBcT` O|lYpɂ'Y`-{_iuWrimez-zo'* 8^naJr0v%u ܭ\tXg'V˟sw O4v=?xZ$EY73 MrIF/ S :zyߌ96|a}b|}6S)p7^Xah$$vAPJݐ: !͔NC޿jkPJF\Ԑ+Sl(lzDR_SG|n; 3UqV ) #0_Zg;=٣P.֓ Zj?I 7: |S)6aˇ$`KTD?'? /cJb<#9et[=V:H:lQmU!̇TXy-Y{]A5w܃ϑG}޷aVq#I!^^PzatVoK19eyy[\AvƩI3b1{vX DpOz9m4YN,gx}o2geP_ǒqqx 'cFmiPZETwÉo|EaAZEpYi'2C\iu8`B)ZZu oP=ߖʘRn4Vwk1⒣@`G{W][ҍyN[#'62~m= S,H"/T;l S~ezs4Txhө|^VMP|jJZ{JbR\wzM8ΊZCC #&ұ @UnQ߉Q2l/y+ / cǂïG@n=[r<ӹ?EN}RvWG7lID/OR0}:+ѿ"+zx|hLmԽs` fЀ/t(t8$PW~Y!|(z\ &[p.Ϲ!y7>u@I6J+ܠ0K t1[Wrגٳ˛%" uOe.RcSgҁ|Ʀ^62XH6S\j^id\ue$b jt0-6 u 1ܸ{.]_Д!nTb+#mA n~Aͯ[xώp8qr{?XGj}ske1GAS@|lpM%@"?0ȡgx";8:9̯iޕ7"V{NQeְ@qRE !W#Mu-,U8AOj,OfW n FЃ"i 2 E4D^7bIKF!M3kO\$%]4/CV[MjUZG2(ulFFHt=Fp!р,$wktXu{:7=ԯRgƦltǤqE5-ISyV׌ųJ\~И9/-oQNj,PKj&Zz w~A:q<D%G[/?-XzQ>|Z!RZS$vԎ$qw gLXs6\| Uyqb $p@(2EN=riCT¤ PHb0mH( @ĂV4AVCCː, MTP 7\#imu 0Kmקt3%'4Shigs\ xj .I8v ?qG`jEH  pnux.3KZc{\X~XFC0ģul}V:=^i&s J`BVzɸAa&0@("R: &p*n+\Y +y,|Zy6;C?Lˁ,j8K?&֨Ƭ9o*1b1%*yȩZ$phf \y>M{2m+PeaF6R%7%Xf*C-:PrCQWWIB۸u M7?،?tj%ˉ:\$X=^`Z8'gq$C['G)v)BE@C7՛̃ YҠVy'ڃn_H oT P7E0U ;Rr Wx/v &ٙUf!ݍc4IqP`*ڻUu91fGlUCzMv9KzG]5oTbu7m;Tm$~)dhR S/Aǩe%p8); 1# @jpbG #㵏ixoDOYC!ZtP§)=mR3}MO|]W0E*_q'*,?}?5@'|tC:;KQt@vǏ*H"j {|݌fa5AYEvy]k6Hɸar7ȴ(!n҂=;. 8ӖWr~Vyk.ֺ{}:b`( 9o=a[~P_ҤscH+5_˷j?wC$2܂1.hûBiW)T gۭ46Ԉ ?=ٖS3, ,/;zpܠx$7-GM_1n`,d׏Y*9+d%#[)E:582Oi\[J沽`gAz2mf!Ri'ZsH|H3ZBZW&\MJbYyD [h)ٻLJ@<((I@jp phfeZ4t =.q8Sڗ3r/* P1g 9h wSskJ&Eվ1QK8qu8s4x,ȟɵ99+~K$|m"pe+bٱfS .sZs/l Բdh"6hA5bd>&FJ߰#K3ݦ{GmN@Ma -N8iA& yZ-b7d\JCWq3''{_ShIS:ցWwXG֓>Hs7ˁ"!WXTH -ǽ2&RHrSChF*èa`2A-Fȷ+HF+z z Vu%sXn("l7xX8 TfV?"CqwD*5&kVi7R̢a16suc @u`ωAWtu*iNme\TH4%Co15 &[nѫ@|U2_ SzrSܜ(1K#fJ*)&UG @T .$q%{U./6c3*q0oHNX3aVMqP2ɦ)FwqHTDENǍb> ]MxP91Җ{e2YW-À vcN"ln9fhP8pﰃrIWh ckfgEDvE+Rr]2yq/x+eWMW7'.ޖ4g/?qZ+\=ha> ^<A@Rm;'S9. خF?\pəO]^N.=$+h(>6{ӕ[CNIsRfHLMe&n7+ 8hg# ^z_-(U,箯9: 9zFa!WU;} hCnK<|`a %oQC/|:dr{PP2 (_MDl-o -HrEG8-CbZ : 60l`(L2'8Ţ2iBE,f0Fr5\‡+,͜D r`ԥ [ϐRyyNG"mgK9!L471ݬ>V[krJP{[#X5`:֒j6“^; |#0ISVbӮi厎1CfJ"Hq\OO ʖIė9hcT EHKך<bY'D>YefS=2bz mzRFۣ t5sU0'޵E"*+ZmѓɛV9)G(öH$NuT}e'w.?4шO:lF9iSLr*BX@HڎGz$|QK| 9 ,|SD)D? 9B [֩wB۠?E=ҜVtכCW-!zƯLV;_R y N JVoL B=82\:2j /7QxS! ~Pp GgRB H<:E@^rX&Qȳ48hs##}qq5Nd[(i+8(9)x dқ|(mk{Bed 'vZKc%s$t療tF5FÛ` /% 0mjj&,U$ϡڮ #U-[!cA쯹1Rѫ@ߤ, ! ;Vdir*0:ұʟ= <E8PIoP'eZN#⧎R~1 dB f6Q$;A)/$cgh4ER rs,4x֕~%uFNB@]sƲ;>r% Ȃ3AVhU΍"*aV@$ᴺ r3 R]iRN7{maL,3.ézY7so+)`' ;' ثB/9g#\:ݜiOJ! O&0Y0k;[E.ĻO6xk Oq7^4#C@`! 6` l0{<{=]4Wof;,e/|' ޅ⾤PĻX9Y},('[ 0YTj]$ZU_hLx|xϻD_F Cb7{ѷ0\^].K&)n&܇FoT\i9vQrݻ4?B~أRfMY%ҟd\дIS+_}%^̯`BsѥOu0qθP] 7 E)\>}{;^?^Kc7c֟PgpSt[+36M75*͢7-е.}y-G6Ɂ·2eҊrA"= he(No hXbyjR5*Yl7??}vowʫSv%h=^1r~zU=vB(S_zsmoփ%KS|O{N\ IU5€smB۷sʮ΃Y2꜊t=H6J^%8[*[w ډH8MaPU4b8 !?0q4':']Jv/>.%Gx\ AؓEh'n a{+ K?wйяVU!97OOd:Bp0$)CMcl AfUI,s!Ý~nxTiE=7~ 8(PUuz̩+4z$c3?wF/@wZcn̅,ˬ pb,=0Y/37#i}]`"ժ?F)QaeO'wI?6UR09 QE`wܢ9LAծ5**yZFĄ^@+%1L>PNɿE9 ((iJihxe\{xD@V+.xD-l^5F%, #j;xj7G0,HJ#J='`.Av#_D K,O8g_X|MRɼdGr+nUGgUew{dm  {qy&bZ:@ {G SWSݏYyD 8kv*Dd@>Bny)W&DR\l;D/DɖBOKqZ3ͥaѥA'h2!$nkSTd= q*g䡀ΌVMTBq/f`.ǩX '^,e9JZƬ`] XȣvK| +la uH! hhŇKoFx%Akއ rƢ8o)8"TXQwzGV3 jԻx,-*3UW_L18# c':f\p7Ix P5JH)aKs>~ymte!3K7k(Uq](4ϼ ;tYA||&!+"Lw:>G7voHp -{[95(ޱ2m9;R)>1D?F$|-9VLt. v-jEױ]YGA +npꟶ3WX:+hwAzh~$ŧtԞfJYnLEXl_j4 a o#/֛401ힼ_}J?edSP1*9f2C2]iAey45ͱP ̎oP1B6clɻpm@K2>`HqdJ?mr'4>mOp{Wy0?7xMxhi갾'aR@ڠ.j̙h+.L*Ua=(W.ږGEE%hN>]|L 6@UHq̟S# vjsvҮ`G(}A7tB"b쐋C3] PMJc{+0k}(5lg\FsqT 5JYp*WmJkP^Vo5dG7( "PMR ȝb34-;zD@:~V*Zn]qT{ϳ/>l1>^7e4|?G^Rf1.42٥W˅c/~4@"P3pR,LRͤ _4&ǸTT!tPd iP-]n.JKX9dZߩL$tHc?<e~>Pq[iuHxq\~w I>Hg"YmByc[}I9p M?#o"@7Bn"$J[]}W7t\-@P}xc1al7'`R4 JR^x7Ηzz)Xf0;_(tlԕsTSi>$1盹gSU9R)M$"==; pT&* )z~z6 la4Q&DM(&-ҌRf {azDo\w:vl g\[AB7=Mv`#R!2kBS {Bv{2$i# Io盛.ߣ\Tv@K-Y Mio볁 (fJnG5Z1#W`L"7I#C`)|Y(AYxsA>&U d%©k-eu\S7q{zummbX9 VBMS\])3mYvpM"Bc Ak/8t䎟`7E)#~+9>Ʉ>KS0S%Ы)г# 8 |(/9ҭ&a#uߒn oŦ1" ÚpuA{tE~6U:yF`6z5":1"(k)=g{_[I\B@uF%=loh4K-Z_34T$x{ _`,~U>Y܌8n\2i7x$3}3hf^Nl JenU{cI}ԗGruϟ[(T.H0{q\ 6xa5'T(3񮚣C!`Y;h<6=f`yaYs{kx uLvRU\`ܒ:\<*Lk NYFDi'{#[!mvv/~ 8ڼ';〾=sv驖l9UwQUSs笖q3ǨGBE~AP/C|2t]苔 NDPo]Ȫr<]XÖN/Д{u8U.S oޤ݌I.S5zo[}׾i;l qRq?jTTcI:*] 2A+-F [Q:`w-ڀVf mR W %I}NsdruO:jw7;OewӱR{ &+i %m}@s^Sv $SsI=gk'vw$ 3SZ^xҵ5P!DdKDF)&{@{WDq5c ȽVvl/!0u!Ħ\:OhH#'-THožےۓC l294ET!9.x&Uܴw ̶MST; @oħ|sƪ8t ZVVչf50V_ ߷H+{Twq"){zW1d7}kS{{x׽ Xl |!^|I |Ç./6SY"86)* rL{=l, 4WPL=oE 5|jϚ6,P>EG1ˆ]2Is[DT"nI+Mc*˫Ph2tx+RQ-= s\rV%kPz[ЖOʅ^sb8xmhyV0p5Sè3O?~1+-%yϠ7+_ '$zW`H9ru{/[wG h\FL='ԏRVWTЏk;p'F:7^JD!zb/ O&n13Wh<"9n Er9Zk^]9QxPk,@+17FHzȞ鼖lYY>ي;0RT2Y4iw Sf~ W."<^FSyv _y@ Б+?>H9%;2GFƣ#{f\h)1eep̸]ͅ%mZ7oUW3|EE }Ud|%>$4\\}[EOOf=%ݝ&waa|;U㛙"}ڛM܈翩NU\73N9AӶ1׌͆q8KNhounn8E]gUj' )EOU{4A: #x̊Xnx|6iNL}U?\x-Jթ&[t|Q"$T( 7g׏s!3D 7΂M$}Lb2Qh ; iJ?FaV0\"pL,ot%cߒCSe*3ksKoB7]&6QYƊ]G5"ZP>:3\3%$^>ewY $rd"ˮ+㹱O_, Rf`MoBU]Ƞ/|a\4-l{Ԍr52'lHG#3WX|}>lxLa; 'Z(k濽_sqD8D8# Lzy~ck0 ftr5}LZT>G W>}ZP)O䌤'ڭ*'rPE⯔<3YOj[jroE w:ר{–\4rw].ghJQ&׽mYotz@NĚW*%Dpce;H>۱vakHAA mL@\Cܦq5p n( cgr"ڏă zFDVIoI^ jv;~{5rtZzٜ,)}/6fNXB MA#H\U~*' V%**6@/P mi  Zh,V]ؿZ2.ĚJs5B|#((Y JW,ʄ<iG,>k֫0Qod)bEҴqcQ{?el_O&,J6rŴƚq&w`'C羸(d@a!d˳f-=,M%_,Mpe (~ ]G^Mpzߠtzm!؛^l;Z<3d; 8tf;] 1fHqҴ|ZYei"lsy$2ZN"_"4fō+V4SnAoyksSx|!8ӽjLe-%s[;- 0חRAX>a UݏF0S:4?:5!J5\ @pmѠ(4K#2eIϷ5Modx9GVm66YOyn6= I#dTWWVhT[M8)7{٢Hۭ X&(7ImO1vCo 6r{&= F~M;f:wl ]eџʹ: Ӝ\%~VM.*^)܆bp0g4㙘}< }ЕD`T O/ ̨^)fWuy`΀}j`X^֛2ﺲ"]b*{ nk71 6HhzܙvoK( E/}-Y"˛" mmG@ʈI\שNvIf8^"5-DxaNm8ym@i%TdRLpG K݄WaJ">\ǰP-% 5,TE#,a.'UTcz (VvyzU yoYѐl] KbNoD\۝P&Q2U}ʔ¶X!IZkJuJ`l[1^hi_tͤ dl{]1딇6Қx̋~ mO[Wq'je~CUQe1s/IjBJk sK?9enf /3PEER5?V$\z fr#ٞ_r\zfNm5`qn2cm44T+m׆'3tﵬCJ2, 3yŔ $؁ws=kD{W|ik Âz)uDҒVQ~/¢|Q41SL3=$Ns=_*K 0Lx;0))XS*MVҧR˰Po즔9p(5P|vq0Nt&o#CurP#`OaYEtW uɰ۰p2 844x񊪤>o*,yThE]0Sߋ=P\i7,Uzn}~9ߝo m YrS0^_*^cn;#@tbB4x.0,Bbq0]7>!:V=Z35MT{/\:Tjuʧ=yq-ګRt3ae߻UvŬNs;<${ eM</ h=qh,%V~_ eDU\Ц;Xy _c c)/5KB nŽ\ sOSm1(,+hZ 5Fgb4ϫ*#9yl1a^wK&YbذGQ *d碱20*8E/_8E*(`|Ua.qՀ(sBe3Ct4;VXg2gwc39V/6Igm=T:AA /FT)Ֆy$sOo8?` DYL)+|غOٞxƨzЩy^IEinCD hK jIq:C~o_xA?G .UXl?k3"[0/2J  K-f[)?(l2#sk ciEX$sJ\'=B :JT 9 ٤ffF>᷋h7goб7? &l9iJK.IUم\M=f;L^EsM"!uĬ>T-eYYUs(͋F4RҦLa| \j~á@ Dd8#=[\{$Ԇ؅_q9G3݇֬gzkf:ADa ϦZnE1:U$ 245SikǨ_܂>Sq W.X,29e^yAgG$fⳅwڷnab?"4hI)@S1qphMbTجfxJ4 ?3qc,2g!0f /JqZG,[Ek)sYIrw(u潦AE2* , mj2k%r7+cB喕<W2{rTӠ [:hr첢ӟt!4eZѽ'N`DɵAkEh)_HOmDqKWtb]&ǩ5渋TI$ Jݲ}îsJ-9F< ^Sy~ RjөojԊPIjExV,A@A ]JEz/Vyg‹ɀ}Ze{o4dB' ;VU^pZ,o Y/V?1I7zZ`ɻ(:rJ>6W}] {> 5][E']paky^ҘFD (r d RY-v XSIR(վ};BR/:0a0A6wJ>N1?q[ϔٶ9@fN}3cb;.ߧ\9s)F:=$>8_kܡR_! fĬ T#+$UT[x3~,{Bvx@gAJ\iMpȮ D-:Oc+7ŒRnȭ%; e1vah PI nSy-Avmu4v8 x?Oc4tc:vc`_*R9U+Y{8#Uߗ, Y_~(q>Fqr62dqGs5 pA}I>9@vϞ#Z_.|&ZGJ1mĉ.6XPQbuޣF`aPiݲ6 Ec4Ĝu~UC@ ˪(w ¯*i ǿ/i(N{"AS?)]nn#6A룟m8bbTC(o KOKk:"S6Um³ptq5dl5k\ ö0hmHt)Ic5wɭq}"YL#LOjT2RBplU4!MC2u` W!\6^8ܖI $qp{&0JZ:{h0psEOL5N4w٬Oۮ$ TiagP6 jt?b&(B57A$%Pz^5TlZxP\1F`gaէ|<5G@gM◈;DʗUҪ#ʙvPJlL"R #깿@ 4ۋT9TvʍAp]dMmMo` RGz`@Ӓ!#1X]P],öj0$>a3} #;tF o_??S, A|ә:=bv۟?Gx}`Vn2% S>Q :VlvlC]Pعi G D=3pyUmX' TN\ 볜t/oa$!:<$Ḧ/8x0udF'Y|yhЃ-dkD%@wM8V?\3(EzNSIHZ)'装_$Θ vvG:e_%)-<?/B=i+z{@~oWF];4?PjvE=%Ӟ/MxAys襾E&>֘V(:T:1Oe>95?4SFB WRkU"xNV`Ƭkfׯ{$1tʮz8^]O&L$vo8YcȞj[Su#x6?̼Y/%l/#Kw(7;fgYw "wO(HS\~I0u3F$ߨu5!'oCƬK X[qޑl&bgع< uJ4z&tC"6oT1II +ľ6 Djl5%X:%v%Z`A9fg`9\*u}Um EcxU'> R4@Tnܑ&qXnj-ڙJSBmͩ{^wcQen$etlnNn&ˍPsPU+s蓠CNJ|]m>躱^WTL,wklDu hߔ0P0G%j>wQN?tV9$vVn-h۩bxea's}`B7T-K؟̀rP4HDHDiߤ@y` Yhrƕ64{e|\X86TJm\T)-)OVVo BsaK+oR0ntLIu+s}R#:Hrobv.UD8F|䥽MK HJ֥k?M^߷/(b pU`xƭe-]эS% 7/IC4မE CT%4 RLQ͍Qyj= 1$n)ӷꗣ~MpGZsD.n}ž./zHq~aݒe0{xGzv|Gs[7[wr.鮺B'E |lc D^;}wLHua#XT'rn /۹ښ\' lMy2 W^|OuOsU!j>P Rքo +ed)}ԏpkwlp/ბ>l euyܔ8/Ixgw2b!dUFVn>GL, -i3*Ƨrz[Aѹ+FG),o]jU%ҁqP"dȖl+f`F\,VLRc(~{Kq4taodkb1gOS:mXĔM唲/̂%U8ra;լE+Mt?VJLR5'>}z\%3T1Ń8g@Mf FO>zUJ"P~tU\3P-}nXMg67IIu~:5s)^beγo#k9&*{Akq6Jg^2"`u([,i} *+/I1am;*GƷ@#e/K@Q2G{a: dqDׅ|3nVx*[跰p!#* &.=(ohV/ԋ受z%zHVr)ҩ9^^X0|,"fw& XQx&Oؘ-5+ gֺY/˞M[Ov;F7(\/4|V=∯v%yVp R)rRj_UէOriXuZ.4~\"`᥉rg#{k\ ڄK̫mQL6ĖRPAiڹ3u4#B>җdA,L ٻ?&G0mo;)λ==}T %b9I6HFTH3xCZv`R劥.")#6u .^ΚI0|!\6J Zx$]JѲ9դxbƱm5qq۽]b]u70aJkE!-TAjk-(**K>\|Bas÷Y _k[Bcc9_o`?>&ŊC1-Mb0TKgPn7h԰Š//uԟh%i;Ys i(LgtEKs!('|ڳ,<)tyvμ*ixow~?DInieo,~(Ʀj nVny[,0%NNM;7~|&H4x`'I`_IB耚R $B0"B]R՛w j9(+l;eP7ʭώA4 3_!k?;:bi4}Y$zQc99t HE E M~/xK[24` ۝ݽ az!'c^|3)ppnG:I^ou~ ט9J8SEdMzzSWNJpbsz#^%w1{Bͷ Q*t{ :e(ݸ0}U/cm$ϴ8v{'$oHVf}qգU_m[IT=`o&ʬE\=fK Êq Uo(Qyn^! Ƶq}yn,EÅ/=^7JSz-HE( w7ו(W+Ӆ>ܷJ:-KJEP$8E[& |n3! Hq E7SߙαR&+,nq*{ G}goq;kq;\@JAXd$T!kWU; C|ABc]7f/A 7t!}%N+N[ѝJ/e4 qtԸ1NMZO)g3-"l9`{ ꯼#|NtkBAuf{&KЊ) XNuӘ"^ `3 `8wtݖz5DE 뎝@ʤA%6޴EpZvf`|fm"{ gene 귚 ԑk!*5uJgyα9Cqb [iQZkm1˧Y'{3LY*SsEv׻S\'P,mqA3Оő0{S%az-9jI CE"77S OCV* 58@ՆMC˂K~ž;i]Q_&,Z)HeRXQwLۚܭyp6@"񌚤 Auh@ >Qܳ.I&=| k,E9t<eC1o*Dr 43$̾~H0,&CC.a-QI{򼺺?gqXX/:΀]#"V7_E"-prt\B<u-DGPf\% 7ЋM錀!n.b)^GcɝW mzwӣ7pд&UZRX+v`HfQ|tb3`YJ$]hR̝c0f;h>uEwˌDZ밳.ږN-e;:8o аV[!QwũL9R  KTtbVYb&]Oo#8l[ USh~LT@^L_1ךӺv T z| QM6l@ڊRΛ1Ȼz8+p~nj%kO 419k(e!FNSxӕ*Y3&DwfO0w1Ɛz`aeeSm*uz6d0?H s>+ORyh\9џIzaJj(OAQ|jxDƘ Rt[dׇ Yk>0>n/."P0=  ڸᥲ)ȾN2)}7b8³hul[(Q )byxЂj)PI)xGB.K>(AQKwB(Ѣ"?)R}x0+=lSwUCKU/aVSUy*qmFc!r@Q*౧W_Lg2,yf Vr1Ip c[R%} G_8~ \q"Q!O[JQJpْEj2%:X(-WDg OgruG5JOAX`?r78͑fFڜK!aQXζ<Nf8T'Ci#t.}ެ*JQtD* (ԁ!Z_^An2^XDFo{ >A{53&/vf, 00vMLYH'/ILC12.6tңLƱ#5:infCK6]wsm޼đ6QYlgLPa*gs.u22W &=rȮ<^^ϮdnΞ <bsrQɞ|D{x.I, 9ꅱg [D Syhu')_1ЀHA(U>>%E<+Rp޺O6:nX}=>XBtQ79K%ӅoB~7&ڪK?,T ȒXBIf ^ux2(KnH$ ^l[ 1X*/Fu,2y4Vb]Pw: :q F;c7pS?z 8ztT*SK9o82#5ۋe.$#-ʚߛgj00I'JMq"gV{̶V'rze&Fi՗CmH0UK~j#=TEF$"g7- |U@g Uv6=Xm'NrDe-g kdQ\*&1ItN )gqh|J+`%Fvwr(-=/ 8sH9lF'`:&牳vhWʼ eV:^dYg$KN@YwG$szbVLkWL=v Zl]é2obu#tԧret(Wkݓ$/ڿ46=uhB%kפENa5m7:*3K: H}M6֠,j |Lu}>7 3DǓ@| ô>(1X(RG A$ik`xFQ߾܂Iȟ"0R%>&L>{k@:]6 '&d$<<9IrՕlmtrMx1`'׻J}Sk7J@xP5*{@/H$YGB9mG(N(< zbWc VyB1%K^fԁd+y<"@[=^VXi'w7t- PbS3܇EU9A/8\6_ -2n(zF1qzt cVVA |wz<V=ۆZEgBdò+>H Gė//Oاxv=q!bO\jl<QqC BPj-Pp% 6#i8;V8n)kMӘυZWL[!m@-{$gK[>&#FU]5E㾶qjb.&?GkD&_O~kQ>\hhj߬OI?l9 } -0DG#U?eS @N._MQnx [~vH0+`gUH{D'u0}\E9t}hD$\bWOfrLd_>B[/n˄E|W;[fD-5R{Npn/zxtmM1Hu))~ȸY5߫%8dWX?YUr:(/vBt0ֆzwd@e)?.1jŋ,n_RDp3WͤW:MP[0ۑ㋏ b )-BS;5IMFq/ϺM"5űNkAE bEL /q)-a}̤e~ЩBǐa{E1J+as>2#B uV̒T_k.dހF;]6EjHؿ% n- މR.88M ) [Lp f|a^RK2pVl]ۨRa7^r78| Z7#'7bWQWxIb Ix-e]E)a椧*hxWBPjEBGnPP @H 4R~2I]BA᪺ء2uvT;1PHVStq=;)*叽K"+be'>CZ]]u-uDEjٍ#Qdȿ`cR"{@ pÛV.?(N`Ir0 6Xz 㿮o"Z|b9n;973\{:i2_@&rnP>XF`ZF(cjR}%ΣJ6U ى$N䠱ryl\'F'㊅DC!h1֯Ir,Z |Sc Ai ڣrmwӎe]qdeM%SoXo͡=x|IL,2>bhT L^sW *UЃ6Zk"Bd[wѩ OQ9" ^ iE1QЙýV3B&M ha4b -"l `=us wUżK : q#SΌ jg| ,7BBr"A=~o_H8y-w4r3G~WsPjDe*ISq=螰~ҡJ]q-J^aRb?K-^;Hw'e:9 ^rؗC傪8>(_%6UpbWRkM"G=wћ4ɯOI-նU OIUh)kxNQ`0rcv:fG ݇+0VVOHZG$Y$K-3^52!bt ꆟs\rxO[!uYҢ0huZcVK˵4I~GNk{h GSܣ)eWyزf0:; -"6NwVAQb9%V8v8?v?\]؀fߣ҈rdW2:WIgN`{"SsM#mJ)ZmmN'{X=㹳Qti;K=<~mfq>T ]hSl_$GP9wtɜRq$V6m8`:1>X+94 eyeӯJ m4WZG:)I ;mUD*yd4S|Tz+oE &2iMZi>Io)`7"nkGh'Dv)sO Q yGɟY.2ّ]msg1-O,žljaMb bq_J=_js*.̄b}_4 >|+AiV"K;dt?':78%m˔;34P y֞iEbմt*"JLl"hv3Q(dU=,L/>8`Zfk%`KW4cV 8o~ntaMܕ*,扴Qz͍! 76s9dٖi7LpPIVPT[65]gǗ1i? *|87Ucǭ7m0\rG5:%t҃(o^ 1Vln@9(P/¢p Du%{B5 qfu,θ4go/T!]n 8tx3䒿e[iΊ<)$+dT'6z[uQLJ;A%.&tiW_J&hДik9MYp#t@%)b7l˷N+ߕpu7p*F$C]s+0Yx4\bR` ( }[pfLܬn6-p%? \-| 3շ3 )P(x*I[ŘrЭgYq }}N$rx/[{@m 'f`a.b|BcG7un1;ϱ;ÁuPx7^(c|&u` &#M6nE9_qf7rSƎ*mF/ʷt`xq;4 !T(': (YS2ͬg~U &3b[?WY8c: B莅kXFyn Ѽ$rqFK-,q•i>4Th_-ڿ1(^ .R16-&0bl1RmNds߱|O*}Iץ2œs,^vz9'2(cGӏ:>Uc53356>A_uv.n0T-?Zؤ`)!9n>_۰7eeH}MLΎ殗f.;Z7>QӈafMua)*LtevUR!h8oX2{x "eOpuQT7|NO+ԉfCRXt.+"3R2"e>:qca@w+̧Jx)4͟. |:[)>O3w-7#_GqoXAD0H&7scൾHsU!/{ ԉn)_`ڂ(pMNx8ō^&[ZMΜW9'镼D"eJ UJIlAk~ .1RCaUrB<&-71]\]ZF2- 9/'{TF`_f\}ʖ05yt=x#?䵴k@dS[_:tu]Re({Ƙz)QiPo x}ϰrcX:q 3POb5pK\˹g8B繩xض>M R䉢$A=<NJ[SV Q΂[bl 9fiD!)x(>Y1溙|1ks0EQr!Xm;ښQ傾y#I^qo ;Š\S-g} ĊFDQ!o4r: <5-E,Wn1;{I 9 +It8z9D"Stq&̇54MnO}k>'1nuKy5aF@dϸ7FS}:|*G1iauz>J`㐝y CC #[~ {ВL6x=Πρm8L+~EfDS}P_Bw(nd|FNUJOr4y^l桥6' [jy1p/Þ4sJHcFѲ[;I ,++r% &obʅ3})b.eC1U/N ҷ\N47 ȒM'XZ\J,Lu{3EL納|y2MiW]f#2t+O$-QD+IvmKߨiCQdxLQ3Ε iϡ .RiΰѠOD BDT[xCfÁmL餉K*n(=n#/8q53$p)zaD}I 3++G d4)=SǂE%)n)RĪuzoD{5pn8.]a jNlŜAۄ$c0cH^*_}BgQnc#wOP͒JQ֠!<ѐ;)0")vLNI*@KJz[\S OJBr,zܼO[ (&;N4#aA[8bq>&AM 3;[ |wL=1T_U.VDEP~qH VZBrrcgW9eLa [JL=͈>)5Ĥub{Di/X.e<|J1k%R߮y~\dVPF+ fkl libvv[O"o}00W=!It'6т` _vâVLS MT3r$rp4 6kex3XVe,BjXcR%r6܀J=ۦr=m㔚BW.D )nR &$]m쉏& xYMx-^,ؔIZ&5;FEQ=۱i8L>jpŹە4?DxrߥH{ tNJnh@Gl"RT>r@Ʈ\$3K!dE XYnXP* roIDw1ӹ% 9@lsǎdYMrĹN}_RGSAxwA-3un/< $.ŶTGWySw+26 Y69etYNN /bSzD#iOFсei'V@@hjsG{qNHiȎ~\k3G$Y_jxTeO\Z &X@EF W^]*z8R^3g ʬZ.\7>hHczz_ݥnnAg+ YaYa*pZrCB5+C-=y z3TɄ ȾFD184-#ĕ$GNt[RӸ .~7o ij(y+AچJIɨ;1k^]*)-;TI Қ@C뾊`I3 \˒DMp1BE(T.}Ц+-!E_V*csH'aEr`Wк25st#{Jb#[ 䦅j/[}{8k& Aw1 s$A" p8#fg KP#G y>*/e&Rk`Ģ+x/hݛg*g-!ۢ8Ρș"1 Y)Vɬ> ӳUzPPVK^AC32M`[o)tp-(* n­Αc9QZsKw}{@{2gܷ֋=ʍ-3BcY ^LL5yBa8pAsӣUu}a{zN5%6~j7i҈犪I$x|a0dK@1L#t%F\`e"qLElL#O)#{H/= y'qr^ʃ:r6 g}*S{_Xښsv}x=!^;i|(۹+vtq[9{n ⬈K!f>D]ô#vXc D r|+]2!t9/ z3\jxZp~367bh$p-pDejP4W!EZCGSN<"u}_{.lWc1\~2fb XŒ@@Ƭa|d V/d; nV PJJVwN+m >kP0 2=ShABebb$`u|gCS[80kS۹)aϖk"mAрqU+X:T8fOy:/bvˌn15!Ɯ7@u}Wp$fL:T)]PrwIh>_GA'%cL|6uQ!o:BUϑjAP 1-yg6PC`6XVqpg^6.0kS|)*;Oqq@mIZgm-ٚϫ>p53HN@UGd5}dt XbyBݴ/Egqf'Z~n !rgyZK 8sp[ Ht9ǘ߇Ê8Ϛ ҙ^bC` [c97O3cle:"@DƷFg//)>glns&oye,0j=OBcPS /s'B1n(l8q_?=/X9s , H(-5,Ctxv سk0`&@#k뉱d&&Qg kD)n49HGZ 8V[BMq=#p%o9w5vv˯TAy`5VN4)EXg誶0}~4_ /Q4 aٓӋqqfQ"* Y&2yQ_h:I9[4#_WNNCv+iWVox>_M f(LL>0M6ߜt gſs1ŋZgIH]㺹ܺ9yWt 8`MTs[ם*_ۘE)JtXg/(~2Q#YUwN*p^!h;Ä`Y5k3$Jű ҍ[a&F+-:|GLEiYWx-%;PPJ]Տٵ`i[,5~5)0._sX}B!rۉ25{,ss,'e\ \k*S.:%{SW?P^=J;Eja\S~?0R5 Qri¦Ř'_v4';ϔ8%bӐ:wy0#l/759,/{&..x- 77L_cqXk-#Hʼ2 ExL~/'c^‡Bgyk'/%<|PJ|tMm𛅕hpQ&=K1„&pg_պ$JIUcxuṟ;~ N{ߠʐlSX^e֙KO,ۮ(UB"Vοh⮱M$2ӳW`ʍ${ $.w_1_q-.X'j^Ο"pi 6Z Ly)/{UVQu dɷF3RZPl1:mO"lD!\?Tޒs@-^apxWG|amVG@N.uoZ L]&$"-HS!%$++IU'Vxۍf]ĬƐ LKiB ]0[q͞$kXf6qdv~G6a'{q@-[C_׻|WWzj|wT ( 0h٬َ-Y&zؚp 2ׄa(=H YXA7Q;FoΨF&~I¬SG;Ьm LڰzD]y-nrۗ7"Rix@]ɵo>k>2e 4R= U`+-B USr2`i,eC d!ԗc\.m}aǰ;MWNAz"Sюճl/i>{[$ШMբ0@٫iL|Bztc_).Ra"-p9QP ^Mۋ&7A .slVm.r,:GgYbԟR!r/ƿi{fD0.‘~J9RUw+\nj%ޙtOn'&^L :\3 ?gP%_by4Q*HCݍ cK {^0'r~W]Z( Fo$DpuQ4+Wۗ,KǢF6eA`jHE#J4alzKC[/r4!P貯a;Xp;~uUcEU0~n5*˅6{*r&;0۴Rr]r[V5Ăե|̶W9Q c̼N_ I*3,䤤E"#O^#wfAB'Q^pDҕ$۽dN4nDeTRxEqӊa/Seۜ-0͌6iM7۪r]::n^婋]@ ) k-a#P(sa*+L,Og=NS<8.` ]Mz4S 602X&MbsFe&ݤp&FP|8gqkB8RlbZ!xkC< 8=w62(i_@"ܤUk4b(ſ7˦|KoXS'^/Y(HV)5O{҂S, ~piYغo闠Vё\! J!3;VȬec"l i:Fҏ{ٌ"Cj#ϳ5u=#R@L+WNzdtoS/IP?0.wmܷ?AF|6ߔ{.\0Ul5D3Hc F0X6F*P w:n6 =\I? @q'7H|(`'k" uK^xs*TU?a\0Qx`z+gaeNL/ӟ4Ǻ`[eGXvL窌l.B9#K4繬e23r6&N9+4Aj64&$4 Dc4bi6,w3`y$sN#?8-0tkQcy,3>Yn HVY8i?P r\"W)؇$VI"z!6ƳøDmR`y݃g EXft˴Ҡ52dx|[P;X8U;@N#]2x}Za x_\guSzђ-.7`Fέ*ʏjRS+w?do7F}kD4|,9 XI A$_ļw略Aʚ 9~{l.kIKZmM<P@;Q=,x`Ff@'dFf0FYf7D};HCxp(^;)6 }rxTwp BU8hO@@a ß^}ne&[jB}IEXCHV8}Qrc_R}?|L(ҼS3 eRƵ2)CmQ;dPbsɍ`\ S *b ^2J۝a{WT)q~p;n?ac텄oU(.[$<)3ʠkӝ6njbpknȚ*Yw1 iKɜݳ'.^Yf>rǙ۷TF4ڃ. yB}s^|~ԗc" -1XO [,˦/a3,pi$qeĒY+ h4k|hgVYI-a9eN$Gg[(|.@TIXVE2F9ҡ'ЅͻM_ ,#Ai1kLtރ%J8kCįA8|6GkPwe>ByL-¶!R``nNì%۝F}AA8q1`_g/kt/唗^ՙȊzbscLʧX2dfg+0)p}?ʹ>npqWh`xީ4〙;2 c @evCvCV |\-mtu-,?#kт̊&#`?F6-ktwA{iuK% VZlf>ޞ6k J77Eg{#x7SQ~ҟctQ"MԜ\BRI*={f˓{>ӏKZuE孢ifD(  -WjS-Lk]b2yK} L0>w |t0|ٵǡ(϶$MDcsC&L!y1!brSAMԕx$2y1W881용VIe{KgF/=Ϯ6a$fSfQp/D:kwmoIs n[ 0B{.șnk>ΝFDKؒB"͔XLRmJ\+R@C ʨZz]l&3^w˿ZʛytR5%&t}n7WmB}^ $L^p֍6k( es|l9qzf]": J?kh(6u(o-E%;+6RfJeGNd[.QRa p:]>DcJm_l,GfQ&+vV e9~ċnzI@`&?(/ǹ+H;kMr3kʮ9"i`=Ӭ|?sKMpeZ7̕b-u⬧6XWDYjS% ê_]t*ZD~Lb~FIKbEB$=B~h+d#}C]U R1WQMMRPtiEsj?Kh:q%ZQ]%OMzН]ۣՓNiHYcmvUebFg&) юT8S,G(8 ]fÄL) O+xB_0y;~wt/oaR(XE|{E9Y>)bjF+r+6]P@ؑ.3P@:<$P;Nc uMR޽ؿNn)Sc^7HsK1TU*m$HΌV[` ^[o"|O}t+] fDI8JAg3tbZs133{3䔴r% R_rdUb6. HF%ztGswFd{m|i.ǟӼGEi܇p((eZjZe}bsx)$ _Ju9yᕫ;|-G1,k\x=2xST.[w/Yj9=SInYfB,tvnjo+<"hZe5x2Fݕ4󟊻*)2]ו\pJ5x] sT(_+xylc܇AdA(WF$=I:K!8ƒ[NF?&*\mK+BNDx!0#JJrsXxoU05Yd7*EHWr` P]]cҐ.1:uDx3B=Hiނl$̳tj͹јCg@3Fz83O$PH^=#Ho̯28rSTPvR-*Gf*Cu­! `Fs7m @slI gbL慨E.dviتˉ}"fGz-Cf"M:~x'[A7b]-[)D@ѹoWrh WA$WXCjgQlv> uEM{36c%JP'=h5aDX^4'x$9D153М7i˖Z?g+@A1*忼/Kayj/ BL8:^q0Bj 3Iťդ%)\%7}%' 1H6bm`vt#lZ%9OGwzͨĭYgUnjTTF{$i͸%&dwc_DSy͉ {"C9NoqopޚWI9b&s|YnSG<HsfyגI<R拱gE Ŭd];JgӓnUI5n$-1c 8P#] 4 ؍Qqs;ޯr- Y=AmJIǦ󓬝X~) tCiV VzSeqހ>c4.hx:𷺖9+\EӆFN/&^T~H,𸗟豎bT`9T)k)tVUfZ:K5Fw{i' Rv6,]#DT GJ6Ӓ)w%wX_Gui Xw|Nj<- `:YZT IIHs!"x'ӍXIVQ+ΡNMQ긒d%3wz`nn 23;rY(O9 `ȉHC.]BJ~aJcxEm:=iW9gFnOvv!R.P+W:vvPdd1>xg[fOmݰ_֥6d$j!kGb *;CWO饗 m0ُ-ʽ-G0zʜT!A^ 0>#èS/mx-`uy9T,I]_(EQ:(;LuEEtJ:! ˵lfͥ?FFlLBz $Yi*# {e5Y\ B5Aj8X"P\ߦe$$`Zg\[ :!k."ی@ǻ-Xf!ƙED܇ZNѱ۠KI u+N' ~T.}+?=dVyych4*ɵ< SHUq)CYҁSP8%*Tp-]VGr2ѷvJsv0LCu69&,? VR6* 6V8X\F7$wB`fLF0*"ĹDXjZ' DeVOSQ8y>2EأP'L`9W5cM~Ɔ]HVnTicm7IE5(,#iSBjaSJdRO!T{tJY2\ݺ(Iv3i[kɺz4܍`\BHY[GtGBaѥNf쏄\DǦZ}H*Ckw03 n%2j|4yE?*)`oSگTN~ΛHzOsG?|~,ڵl} rq3Əl\㜣U>Q:3u͓o&Q4+5퇨GrnK;:jC"0=r߮^nX2bXxH3XۡϮ=::ѢCfU_w:lu%'Շ\pT툋?$:a~|2eoKD=БDUhQ6~?Оk[I`*8/]*5Ŭ7}r弸JuL(glcܱo| XzrϕHZ}?x{$"LjQ:1DΕ -*g$Sb.* wꅔIɖ5~=uPCAfm51lVQ\(a,d.5T dXv嵏P@|2/ӗ& IC?qQm*k=-r]ljč!K <&Gw%{+#\hUaup" O0)LdK3 جYϔh]KL= FÄu=)u˱a"YrŢ"U\` 9,ጥiMorWǦK]abCdW6Wc?7r?bvmqFo1qJLJR`ph`8~]X$bJ!A+jW U&GrX2ܳ~F HNY# 8rV& lmj:Ek]W#͏ysg<*J#p+0ಓ ?v&%+V(1ɉRli"n,4d!X)j^;F7 .7a;]ӷR;m|Dsc<䧆eMhꚩ;`* ,K]w7r'VG\* ́/n96d .膝Yxfx\\`ᥱcnRG跅R^ $SO x pIط:V&Qҗ.z2C[!-3Gcl窙a)PZ!ݘ4UQ{n&QtF"' 9 ^S<+iƅaO< mHpnѓ])1KVWrUR1uGvw<k-ABT@$c.md_DDO9R#A:l#=,#KH/x$Oy ,n/:H2*iJ '}6^7JG|3!d+ѥQSn٩z8icCX~|e5H_q@}C _$AynѬQAPJ;|1˷$; U1Y4ht;" ZFᅦ:kV`9SI}0v. k+4u7ݑ+M"{"iw0@AXn?ɨueq $?a&j;farq5<28=t#\apl rJ6[Nh/ng#8NWd7CR(ns;һ ؐSolw*q{t9Z%캿63U>3R ܖPTEtM `1p>\_f>W!&j+f.!Oˉ0$L{+W >уIL )& 2@͊oܿA5d-'5`t7)gJe~uBƔg4J\ \KF>+WߕH:ik[]+5yuڲx!"B{7mX(WNR1Ņ6ahwphhSUجaBeJ~swٹ qK/4<8k^ϑ`d |8Q:DDI8LN5D8;xCޖq 37adN1E7_0mN}w*OG毽`ۭ;]ɷ߰ Äj+ΐ̘IH]"~,TɯB[n'j3ԏZc ˟0^vpF=A%A :j n+Zl2b>)L\{vdt" سw Tԣĩz"Ro';0>Dm:*)gŠdXaCHyAV0%+o}Th!1*($^H@> Hߏ\IJ;wD:c#ڼx>`k%O&`~ЬP2.b-mHj] /+1$qlXKۊBud#ED.ߩ'NZP%A7lYo]%Ir Jѫz2Cỗ>3gix$Mql5[()fid|{ bRubBe+xu=Kv)g,M,֦O>u%>v~@wAw16K WC|)z>ZW`q%vo;y>7}IWډJ,jm@$xJ"@lX/NiY[祤|')8 QvF{-|"5?߆aӏE`y%P9l+ Pv@\פH`?qLF¾MqE\x{,u(_MI yL?ӲR] <#ZjW˛8Bޮ~A73yH0~^w: THVZ_IHWj,,r8)?| KkBa $ib@9TeMr\51K\'{B=8RUIƄ=D֎eiIEfNBǭ *^h?GkCg/ƪ ? 2j60 Ŵ IdWy=ٸ `e_[ȡ%5c=WrtT55eT#yu|tsJ ~@eo! `^(鼂auÖŗ*1ϕ$^p( I.ɋfQoVaKkO|JF,Ik0gZ埶T­7 Ρ[(6٤ & l'ZrtpӒQ):[,!0Y ;q>Q7iSq1UEDNmɩ?Ig)DТn6u"<aB%_;3<̡0k>~(wWr cZ]#B;/) fvd,^Mṟv?>m4!{M) ?H. gɁ;UIA{oiU1ltA ]bh b|B&SC:Mڂ[z]PP!Vӓ8d 1{=%S`t75x6ۂ" +H{Uv&$1~.VdPG+Q?4Ct~tO2@:Y++Y fc,$>wW*X.ScB/`^=M7? GgKu( '2^`lN(%MC: A\6}AB\NSa{k֣AT[ڣx"\bzP 3:x#sv~VzmGT-h75,$0aD7jz_zdV)yXt㛓vB >/nsG;WP6zV *d yZMk/jb@v01bQJ:qBsQK'C՟|ep^jdȄC}1;I)8DkM#PEC!Hʐ^ɏ^80Rɩ2?:T䒨aCxg7@`&8}wTLJ2__SYtTf{^ oX(%AdNePVDFdf۹{="‹/);Ӗjﴈ[Y WR+Rޑ,>VFuVu Y+AV d{]6R*11܁L8^=8C6*>Zdph&S֠8dh-,OxXm+卦`ɗ܍>s;_SuR&iH|uY=2%5o.8%dv~%I8|hף-px;B}Z 8nl2dp+N(Tģ!ϠnyMwK۴p*xF_'#~:jhhMl~M?q`ɮ} јa͏K3AX",OWC { El/TJDht o|dYD*ΦuXI]MW߹s&W'xzE@M=?͵goYϼ_#^[l+yY;0!;'MV9kB\-tpgԲ*-W["3Vo",YWPme(W >Lڧ(8 N¯U~yt,q$9DSªL((tixEqoRg2e^7ɀŠ|2"lP@ Ct*lv ݱF 47= ID *> .s-fH!41O81yv0N {pW/7Qs bUQ=9yɕ*摤.=Ԟ &UƖ=HfֳVXX&)/o_ =1.C='ad%)Maҡ7b)Te0(z>gf6w1+G9T5]!.A9*Y$|9Ñ泰*iVIXݢ'&aKݦ1KA*jb{^p"C6Mv*z+_ Od(PC'Z A44t(1nK۵2=\MSK_Fph8xsPm^sλ컰7wPϨ(lr/up`Y.?k&I\>hP\wDuИ++a#)7!ECV)}:< q a0MhL N*l@^陝xyx?8y2}`Rjb-gB6#zzlJ+bZ;{kjHBλwꜹ z?!Y=iÚn;53Y#' &˟O'Y qZ YJ+ Hv Mo?فdN, gwV :J),5} K}?M" -q4BCa:1KTͩ'ChcP<ǩȭfS}ҧ"mFV|k|?Ypq-wM34`8q947}6m@S:?x$E.$SRȃ gx:tb¸ S=o'Cȼ);#Ac}G~ x^u[ٞ?Lk)e>$>f+LR,$W-nUj;%g 4펚Qxff/>!'P2hI`k1C4q4$`KYMj>QS"W}0 A$Cҥ-]kjbEG;a|_2ĮIz76bPr:k޻Kv4PȍxS)e9/]|Gڝ6:"(&h-wQu`0˟amEI" \DY?L"0kk[2߆.-q) |6Hc+eA洊\=Xӵ'a 4an4UTʹ_!;(UMH`Gk'6CpeSJW|wPW%J]B7BahqSw*نQ+nϋyb@GqK j^"-=i";\(A1Kme}$9<[©kt@s5HF7Q5rsAQ(f洤/s䗢6ٷY0mPM,XǑh6q.kqʻ $"2,0>)1HعfK44G\cSDŴf'9pEy]*(bG|!K+(q ^؏f ^06(_VB׾<3\̃%&Pb# ~mNF-JyS~DU <2%F N MZ e1BOB9Cը8MH6(_餷GECl='5L͊NV _<7 + }bjP Ov\:{[XfoPDj囯# =j] z{{ưS2:sc-:n6,ZX]0M6g,_5ZH@9wwAr[(gt M'gMrl:+IԨ^LE{aVċ|4R0zOMhx*S.ә e6> iWbsdH ;y=g~cnjo($ + gYЩ( XE l-O5{D grG&tnMp Q/)-z \ŜR<&^c|̦x%K8#.2L^ؿ.]wj\kG҉,zi{pt2LRN g5*[' 50TB;fNq 0mB,{;e?WN>bR OH◅;fkU$c;Ͳ}c~1L7eEKV ϻ+@]$ϧ-3sY Ǧ,Y7 Ku]*4;M.`@rL5!,K6nO!*w߇:xHU޹E/Gaiw (_g{ a*Df`/m򸝘6jӿ71cB!LDƾ.8{d]:P+U$&࿎/4l?1&K>5){$?xLjAj{c:Q'%U[ B2.9+5`ίBQ:Ag/Z\$76:,t]smCQ5bJsoRlΧq몐B#K4Z2聧)]_ԑ ])Y<WL{N Ts+>$k =( kN@;G/ֽr$D`Ško8.ڊfD ť 7we'^gxLf_gWZƶ[rUA|NA@T8##AJ;j7pbw5p̦Ѷ..whkۏT z8Ya1Q;. '.?WH9]%!)! ;+ٮ˶|F2&64:&x٤;M>zm<{ I4X\ﲭ  Z-MT"}%VT!̞Z)cc7mKry5^"(߯? k_)'~M|. DQ`)7*NKfg*@?b"dp (@߁Xl X hºfM;&7`_00? JKP|hCO.BK"!9f7[+h/ CK5-L0 xH0>*S|)Qm=@1f5xCI.$gOr ϏaRSO^)ԜGcLspf*:>l բ`zb5cfDTU ~͂7:ƒax`s.$,5vl~FGL >sj>t]Q&DAyp&|k=sI  g/lxo.T,) CH(YrSYC z c7buΚm|zRsd5jX-i}n@ޏLuւ:WhS'sO~8Q+Aʺb` ~~Z|X]+O*Y0LϪJ׹FDpt k[%<ǹ!^C ڹ;52$sL>WbR:[Nb3ZDFx~rADQu WQci[|A9V/PhTɥh˩clFm6"uLI8m^٘P?RjC툚lU[orٰ 'ȟ( 1ֆ.}_h5qɆ"heU)_?i" q'# .\U@Yq".š>$5 Ru|`x}S2rI@5:R4{0jҝ].kّ )َa, \sz#j(5YVqxx*@nΗ6Hsp'e 3a u ۳׺ 3 CF>ɜR`]L6wEasz^ICqUCGHމ@.< i7p(/+5t>;04ak]y<.P c@+Ee7'W CGBh ?uhC΍LNjW1tCcDY i_V"|U&unެהᕲJitb}wC` 9m\%~֞U6&D[# ,sLܪϬhuh% XƸ\:=fD$*>Xǖ#^YA):_9%ȱ~%%N,ӻQ$Jr*݌xԍE{N6fd\{Zg?霨t:( yնM2v%GFq7G\?xbJxʱ#pR~c^1Le9*ƋN^Afvp rtyUCrcP*|#*=Y :d<#Z!3&'yJ7\2T Ť\ ]&0w.`GZ' |tQ\SSuz65f2Nmk{̲>A*8ex՗&%W \?.oISo}#JI;ϥk/bYk ؎X= |C~7(ko)&<(rrvPW䊏'q珊^#w'SB*k`VѶUkBT$PJؖeѬHmP(sIM"v"#po~R񍧸6g%ʳӌs(ZyGG_y,#VZulA̞P%K~dՠeEN]PeJʸ-缻D;( POk{/8i8NW {f;2nCmǠCi)@ i3D]:7 L.U_b`W|Aj ¿.+CX 8|Iq/$%oϨ^y8Q/n*؅٣v)};H)-ݖsi) 8[B/ƁЉv[6!cLbF) ~դE sL-J46KZ2cȬDo(;G`]l )g3#>+{Y0a枻f]! >arj(mmo(Hr齧:18=e57+K3cÐ-AFN]ذIVFSĥ+bqݨőu9vvջR˽LK跚`Ld*D:X`-daڧ3~ ) bL5J$ qK͟%TzlZ|\'?Z{ceֲg7>aFb>1F@HKل=@/O:k&y"b=r)ho3eW?bӫٯwr "H<8h_D)ͅV 9ˠQ$JAKR QzhzrJp^ӆ&8pgо=9`7vHEwO=ǂK#yEGbƋX겟BAA}~!xC%\F*AC aLG0O&UN.npeFp3QJ$}ϰ֎VQd{ucfzxlFesx(Ts 镒_TOMIqb* @~ivUj=e)V87 @6iR28O.wD΂5t_P!|kL`r2A* y7h|J N `+hڒIoh-!Pc$֖Ft,Q'0 Wvs?s۰@S%jpDTcjTkU]fyٌ3 Zf#e˅}aIF >R&Ĥ{YIu~a7Oǭrb@Ë7qv,EJ\;&^H,g0:k4n';#X8~LUMR. ~ kl>*/~ >˨:4f"_^?X_:q YqQ䱾R@\PzuGjpb,;kgR,P P`<ֵtq," 긪^&3EaS~'m~$XQ zОAxyAes|;ћ./!^XߙHZ5m,:SݔJ7(<[sble*NT8a4rM8I~8CRc#=5`8UB7+PoZlJkv JUxp VY_b3.v$eMV+SхIbV/r]MϲZ\g}Zdܘ%#!ǔ k;Oa鄏.@mN}Sm*v߼t!R0 >ƧyF/XIsToJE#6N&Uʛ|huϗՋ:~j͡o@]QxrË1qd=!~c<9b== ưR}nhxdsV(L}\MU'Kk,Somn{eDGZQe2ʶHfH|=XY2?"^d^LZ :L,h4@=ԄVJpo̜UJnQ]@>ΗuSkC'!僇_" 7(,&<޵y6Ox1"c T܊^|{ah:cjB#vئ`>qK8WDc¢@Ȋ邋ɉQJ&_HgG+YX|׫A{OB/:IKVdNF,Kta(eĺ}4 VZ ɍ f@_ƢiF><7Lfi9\}t\ _+Ky%-}`uI-1af-x@jTh.]Y# Ȁh cU9*dUXEMpy8Hٜ ^>]45 F2KPxQ yEC Tc;iH*Ă3tkrĮJp;I%[,Lq]XlSeMdr5&_):pbn9<|9 &wDQD@ q@Z)5;`T8|Dy3'*e3-W#B؇ׁ=sIb֚YZ 0mQª 14swZ5!0M̱[fSqU:=i] uV=1ū: 9!砡4 ÌljqSxڠZDD[1G7t4ԡxW,~WqT0c=K4^E|$LzbnP ց>q|[S b~P9WS`HŽzW.r_gfЁ +ޏaaFḦtذu'+yu?O@,gU֡s6''kʢ}Fqt&;B9EmX:czEFwף?lOW4yD141.pR$A~*.=h,P 91z| 9kD HRzmCBfG 8k0iʌZKKf>9We r3N{#|ҟ }w6ppXL|;d5'x} -N[Y<.s*'D˃lIm.Zf}N9a@$bIq *k "sdF?\Vu;=o'0n2⟉J[C?P:U =EsmH0Og^˦/u],]YIfγ.jct|Az&\eAH5I;ƸZi8wc3^\:ۤ_ov43`2OE`v }u`&+{_D#I6ѕ ]mKO1 *(K%˖S ҏIq1ݛ:|hنWkP,B)Ua*k+J"ޒ&ȑhS'V%7;rE+B'dC@;g_N3D[lׅ1>".fkU:_e3r= -y4Pw 5oȲH},}r ݩr@Xs_p|eّaKKX 1̵yꘙTţ4p:GDs xU=G]⁖Cp.`F ZuR+a]3pFjr1GI50@zSk9jRԆdh>P\/KL&Zmh OBk7|!+F0n{vLdA&!F,h.(@{G1?mr,[[Ltܰ9Fd8 e!Νêr`62s. 3tha?Ę:6q#,lnOB6NaQM)mi2 1 swpvt>.Q_T஛,ý-B2ԌnmƬ!`Byǹ&eGM3 *~iE8 ,S+Ah5 ؊TTvƜr*T << Xo+-Y\GחSi-Sk`0n<-E*IF/YLUʿ^g|@dzH OxrXiN&A“X#.b 6n +vhLAOz|6\y O&f*!q]MnU# C6ԕK<*T *Wb1(]axa޲Yh4oAݒی 7v 1s_#7l/^|:%d4T\ih @1 ːBDOkOD.1|¸M :EME'h6Xi=(b-H{>S__ZzpJ%>m8!6℔fQb>= 'l@Cvk5&DYҾ~94BI0LRݓ>1Q2X/q_Zʞв_g{WR!rۂ"|p3քok5a#5*V^]WɒM''O6O&,~9\OHL!,c$SkC=k-xn־ZTZE(xWF}hX.$AWTRȜYѨTN~@|UH,_ bjetђ\PB/.~8GTG a.媛d<;GbCe+0T k.KM8P8_Yq%ͭWg_CPg2i@r>(#$=ec 6 nJ'b 8B&"z+ J3Cx>~x;5O IӃ>{]Fm%T$hBޑ-/7m>ex3JZ>Y-oSs?lf\tvC[ 0I3\8P4O=̏YW7/7O3(ft*^){]˴snZ7, E"@L1>K щ(~o@."$¡HSѬRP Okj*JB8E&C(($-9KE*(0o6_X1v4G,U$&\/ W1?U¢Q3Yug=;|L;+aZR7@٪;싹ԥʪ}AuLJ /g8+X_U*%,? p<$:P{)JZ#J#pNg׈}xo-xPoI Rqɞmiö rss2nu9e/h%Nq$P:YPze =H9hԶ،뀄1%iN]#,@?:i r6s wx3F26Is ZEOWfXcwڈuG`8$jL%yuήT<'+; ,,O%A5.ˊe_Zkܮp_5(֯4X<|fScYV +.\{-0]"`BLສ!:&Q}p#` WqjQq^vc:d{F%SdX9dK?*Q0ԁ4Ρx;`Mׄ3cg7Ekiϟi2 $eQov kCڇCUhKo 4v aa.keʁ|WﺌUT~01Z{[ORZY& Ф:ҫɖiCۅU7t?pdT;;q&ˍejZĔ>8p}Bi.M󿺬d%YR]Nlnv-0D_FI8M'4pE<<t#1.=d1K%ܨ#M$j}mQD ŋ-CQodXRѨ"8۸frtp_Ώ +0GM9XJu>LFR6۴= mD7"ۮM@3q 5ˮh )ChX\:N2ղb[Wzo"0T t/ 0 zw<ۘM27w8zk7۸Cyཱྀ\ER_=ڗH,vZ>8t 6l-6O}|sYÇ2 %]tv UF~@#ԨQF?T(֩'+\2eJSn#׉BTg-x*IQ0pdU}kXEy-A>$bS\ c'$K-NC551lԦ`~~&'t7ݍ/^UoD aؗlj˔u F0T*c_3@0QCb%i%f2C1de}^ ˅+:b\[~hitzRXV7n.PyB{hY6o#⚠H댽 ղ^٫CBM}VB.j̕*nsV ꊾZ`5$oȸ|ʀ ͇4nF&Tudi~ŭ0**填J+jTFFO/ϰKJp-+ ]궲s|vBLSEo. ԅzS~/3r 9iq_$ٍCܧ>!Cn8K=ܮdc\Bo,?n2ll^ =eT{4FȮ;@v)ܘܭI^RJУ}LFkQpSuBAoKX7ԎAZ&7áK)|N1b>R1a-d'yA{W`5 ,UՄ9L)=-p5vܹmns g2$s  W DL@5`V ԫQ7i6kˈ3vevFLtر =j .Fӈ<.N ((>e vqP|SLQOeL:XôD箋R(IWn([Ecs_ܫ<_[GMRyRFnHC($oZuJ ʤH58F@0SʭbȞ/ks%=m$>(t3습uvզ3įcGvBkL(K]#u@Cho.\Klm!ά͖ %ALD"]l4{0XF>3\i!!okd~ "д9d9]"^>{Vz*d gLW!(ZiOE-e" 7zn Q2.QyJCut3? |K$OaۻROw'sϼYLb9]imo1LY~+F+ɛ.ck3>;n񔣵كS}5P"+.C;=["!mWjTh-jȹbd&ӝ"Z@q5XF~YV@z$tu,9<Кo̓ڰ Sj˧uKLr| @{X z 6$ p.ꎕ}p`PBWli5TXH ,_tm `%giUyxCJUQG'-cݍ:AGon~!X<K~GJ* 7q3 ^ʞ TZAQa!T{\]4{|ਡ<^ l%a5JV_u"ho%Nnj+0aBB~*05[`xB/u}{7'l&q+&dpHZU ψh&K}{Xp*!CFckRE W̗Q=sULN_EQLꬲ%*ke0.v3Ɓ2faê&8]H>D,n^hv c}TjD =b^DuYtc܏k[8Oæbdyf;}=DD_t𙣃 G{JJÞAK&*o|VګF92R6r?ST^*LCΝ!v*\+/O#$׈j5W򮠐4:샿7/6$}A3>V*I;UpD/xئ^t6Y6O^gN}F--?:F} u!*jdJ0+Z40.u3irv<""J,X-Y͙n`xN_[+% :%qw*|I4D1NV-B tGpс[BP/jwi;'c^6ػ %#pqNxW7QknbKB27٪|5Ku]O C(S8rd ;U؝T=2m2Ij0H);$a4{B17);s34UQQ`U <=XzvǪ]8o1 ~=d@vHIopQ X?`F:˔7Oqj«R}\6Cq\c%VQfY߳eSfq Vqizڙ,IuIoK@O/(cg*$ףV{>>qr*5yxưLe*01!V5¨Ծ6fa#5pbbSTDXc̀GC#Kٌ;,lKTUE`PXne,,zNi5Cګ߭b׶jwd4LZ>xku5O"M*?JZ?5y)^FzD(xkT vݭTb/%3(ᡠIe DRm™Kx7ATCbxCACr'+8x\[É$ÊItH3izP)Ũk)Xojbz$ 6×;<>dQeW. QF ~l}ʒ.m"&mw.; xz"oO>ϴ>p`neS]Z JI6[ @IƩY7͹z:4,E4"OHס9E饡I=X"_Mcm(AXm[M[+KoEgm*UKE6@;X>|>ygr"02%YljGṲhfF0s)=Dqc[!qϐ:c0:eȴ'#RG+35ju)5]QsxOK}:RIUdlK?h\e?SǨJO{F";CHfNo_4ʛ+:@^h:ާ}wbu%G$cjY0",fgO]xкYed+MdbIܺvNj6G\WMѯJ@ 3 ]1VGvč6CyuV#/g1x)_<]1 $t;8mKЪ9oK}k +m 6Q zi2ulR Y ?]yxyuJ]nG=Q xM:R%\iaO93Mȇ<w['z=xn<ޭ| /摷x"bfB}ihg*) ħ$fz(gw|UشH:P:\Pp6Q&>N':V5Ydp*Yys:p+vYq+/&B}w>=!76QbNN.+.W޾}ɡ(Kd"f!jHfgD\^Q S!k7~U8+\(u3cu k LJnYw!ia`y#/9*Kq:*+"ܚ;4BqH첚Dq^[]L6cg;^iA;2Ȯ1_n&7UCK e{yetD'^gpF< =,zgC{`VZ©fR|>3$*^%Tx|SmlZJ&X׷ڨcaZ:<.U~ṬQ%6}_t Vr>mͷ>/`Btv9-cK&Wy`BΉPU pH㛼}Szb_Pgkl4XhOc9}mۙ}.*e&An5C(ˬmB(nt,Cb(LZS'0>بϨMu~˺6-dv|:Sܬz5{N l#bsUkfelJf8*؞쑌@/p9_:XgO!9~VPNۃa*iݏwJA7^al!˂ 쌉j y2^چQ,M0 5=^r'l7p~đu.xAE`/(v_|&_gygSg ƘTpxru/նܠPƉ*[Wx,!?s9Ŭ;k-15sQC j/L~F H1Pn' SmiARg+/di4K51&i T$Oy&ԛ7U]OMcҚ0-䐃 +mСRg[\\'$6)wS9Q|'qƢMA5%`yTV~,&\@hRCv\ jDi +0J yN47\Ɇ.ZlG..q.m[C֡7ceK0.goAѕ|nyWx4OT k\MqcnD qvc$UIPc\X ɏ\Da\_'e=t1+ݶWٸ/!!o 5ڽ(\D^%>w`4U/Ή~#h"QvAuұ%U3hn{Ylmȕ)_K5HnC[+}*龍}Yhgѽ{\fC⻳Z$Po:~.7x^$z EhR?f܄3]P-`8}2zØ.Z0 Cf/C =({&!z+E'Xo>,7@u0{Sjxf aƸ|`-@NxƛĪ*\/g~{OKXM/ϑÌ,5=TӱbVZij>pW+9.1CF+zٜPfW^^QxZr8辌>RϥAsL֎hH3B sCtrCk֕{B)אڭsIy8"ӗߪǚTEZ・񉚚 X4 D jGaa[ {$ҝD]ىB4k1x`buTPD\)aE|ZL3sO$_j)-HbrQ!8a%-+pRNg"+,!>@f0zc<)hA2:`#e+5FPp+G{jl2(_a5Ʌ*ՠ_!zcg| {>{Y ~9Yz )<륺|!Urhw'eeL/ L']kż%bg[k)j īHבcBJ$L:lqfvd˘g/hc .:RQ4/\5D1F 3#Ѳ쯅.җCkк9"-cqAlQnk 12 D /G\?WQRFG^ !;!F!C 49q:qܳDŽU|%J-5K7jJv9GD|%jӅam%_DuWQ8Y4Nc^mkWuiI;1-D %5HZ;esXgCȡåIсkoyЖlD*C Rt~)YNUIjRBY>I - 28w\\9m,&ֶ7ی+FWB&jp+Xວ5O:I^ru̧q*;&43cY1plHԢu숐  8XWޭ͘Y7fԣJV+8>;iLjz /i9[@05qV>چbц?[OSWZ5,x%n{'/vg\C܄F9q@Ӕ`gv;s0oH%%$5#c"Yz3(sNj]~G˽' <Ze{c8jTJ9&8W@ 2b^qW[!B2 #J˚ vrw,l;H3_W1V_ZA&;\_&6\0̧RȾ) &9T?ܖ ݄e[G+qY{ot Fm5$@ Igw \ `?ϺXOé仙2Ղx.nIeiQJEYҤ3Su][+K((GU $:<_GuyE LǰkX)MM @H2;DE(2hFeՔ\VK"뱭}" rb[ɣf$eȠy/Z63\]Ng *yO }AAh*EiFL!눜V4UmP tX(YHdf_;8 sTKY5Ѓ< w?+ukcZRgݪ9< M I2Eg+dّ, ̏K[R֐ y಻D9y n4a2(APx}ޛ%g{NI+>inRE j3`8g(G'hҾEt)Yu %n8Xl%<>p Z;.{0Uރ}Dq_u3Ub~ \?fXs$`\ëWgmxis[2`ghNzwĆȂAEA4=`&Bv+EJ*xn<ݧQV6rWP L&2Ձ!B5'|bXRbxsD?C(%n;, iMpQSuPt&~ b);rHƗlB)/F_Zi# hԙ2cl8wY:+-_z4 w}ɁڗFIҜ'f32 9i';aٵ PE?8W3R2T <x@x]ehޖbj#+!cݵ+vA:Io$.fV]&ר$eg "D NX%oP?`+r1rU{N')L2`R1;m29gh_[unx%Az֚퐔fT)(ljL|/s;! cg`ޑmOtŜ|pZ#~ʧ6%9="Lϻ`)VafiOlYMxC{+3f '5P}֨h'fRM~Dwrޟ2ͱ T޶?{BD2?қOa ˤW/9-(cRGH˃fsz6E%P{/<_GI+R ?ywy>j,&KYĀ^XRB|C?.sJڽ 8k,ԛ]pC~hFXZ3c)6ٰ†t\Z('rZoZ>v@ӝ7wR/S@4Jtk#˶<",+f8d 73- f-Ưp!:wZ0P$ &!. lr6#<c5`J͵;ʂI%* ^ҼdV(9 5s箥'gށ)皡b2Ym$LT.X־p}N8*_`_uqH iАHBШС뤹;#Y~ /yl:i^kte5?Io+.+E͖1Ҷ\cX/ ԉd: 3pxGBoZ-#V=5ۓ 0ں:0{hhXZ2AG}$ԋNf{#!*ߦUb|nY6XfeŐ %MBgddh, /&s6EVSw *N (!BL$3t=OQDkf}-KC5 VCS\T !t"NvMgЮ[k~4E:!F-f3\N9Zr~8W4$ +Kx*Zoh"Xr,![;U@; bx.n;6<r ?Ƚ1}$W_7IċMmA#];Nxgɾr2iFSQ,T0Y"pM8Vz{ƏOb]]uz dS^t!O|օR/aB JRltTNVUs>xJv10ß7ViR ĝ5G֥y$\.`(l)Kߵ:3heLGMm2邧J?bf #Bk_>ׇ%SO<90{5u2*I #*O5j:1 3b^3r!itXM>b)'JI!LPEUqXNcK=#egݜު{f.l@HǺf 'Iڢt.߲l^TbQn/x?@XRKIH;!}Fl64/2g)yi<\A!jc#I {\cmw3Z$V4-dTG'U'#2 ݼؚNC_CUNQ dY XL欋5%g"xQ\_ƨW[Re'+X֐.rX5AJ2x>},Pz@09*wW\+P\FU@ ϘQ%TRN(}u ǣkqYJcZϔR0/YBTA'a :lO>96&Y_~s"#^3#^a@MJ+LKfܽX83iHGBȥ%t}% { $pQn:sĺ2ַ:m@#ZQg4viVÊ4 k?wW#qQч zHOZHt៶N m[*3]dag$t[(PQ:G2FVω%u˶4ž2%IsD~(YL Q E L,gp8';{F$cAK/|~WS!솆NFXF ]`# gքY>96#Z|1"Aw['}Cy-tszhw_SIY)x1aUh>EMx_jx5x6ޮ@Q~Nq[ҍ5Q<隯m{U}wavSH ğjɁh>!}ܓ)_ɕUcUƹ)Q'V"ܩ+AsN!e[׊W3tXQkvA2A3D#@Rځ- E?K6GRg?S8f>A[4Cd4 bH^${A*5$VaQxT,bc E8&r~+hI>@)Š;KëMiNmBE|S.P^ l ߙ3q\0")?/]T,{*?dW b䒟H~7"5zcx8cŭtJm6-P-mQGD %z|XN~wjPf'v0Zϯjg}tZ.#@)L_ `/~=>, \4_g%Kk_ Qַ>K2UAkr_Oe CgX9&0e!lp  ۾UËos.LI0̠?H KjlV X2DRx #HXq-1zul_ʋ-O4+b2Pwbn[x"XJ3o\҅F [t~DeSea楩䃕}c$șUNzU5 6yW<5Ѓ$wT pmZEMՆR"B׬ԋBU>xG9>| uJ!dbKm8$5.+O?K g_/X==4 À%L=7ČH뼬a7Ec^*pkb'RF㖥.l%nh¿`e X`ZN5CcٜFgn cѳWZ-Zg/|f/1 8y@Q2MdiVRCh`i~v\of9EoN,ŕU􃖡g-")D팯ux&rKȮsb{R`9N^wn.. LQ簵W+ߌV߹n~(nɡ3\okMj1N'>[3RxY0׸by@yj{[>8H! $A\XÛ,'i͹^^lA-y B:D1dM=NjL䠿ؓj%ߝi1ݛWY #|ϊ#~31 úk ]7&4TSڥ^4PjmZ5! ;}Da-*Q%l_ _ ym @o槶! :?+q<&L1(`.ƨtbcDGխGA h txʬ9?Aw[rŇgD 9+8< o.5R{6_g^ lld'> -:go6kB|瘞KzIUf%QpP^%$V6IgEd*4 ,9 F9,>buwRji&)w#B|WC!9<<|z#j:*GF32VpCow.'sr|p9(z)$ziĿPo1!%>nxw[9q´ LW_jYvc,ĄfuqV/S0ZXmQ%G8FVyIRWwΥpAv8tŎQ5yȉ,pq6xҟ+ -?7p5я5 Hy+7y2~Ŀd|8k+QcbQ10?EiOeσtkl vVN _%uf%7 8CD4j0CxiVC ?lV-ܽ=v\< Ƥ8J,!;PRNa>¨z6+~F`!sUZ<ҫXbG4MV{|Su#YNTRźHϬ^V7ƜR#0 9,VwS RfL@)4m D}&Av#aԺ8r~>p` {a,qk?-u #3N_T1byn1=1=$5<Dkn=m n(LV12 -$X@zEP+vZ Gn(dw")mf"Vfp0*8B1l;hu/`҈H/' х?1z1ټr*f)ì[İ-tkg7]Kb9_|ޡA>侘!B痂8W75cޑy㶅N/|?BȔ݋UG06uIr! ^TF)TBPvPySg@:PՄL;V8J&+մ]-u}Qs#pF3z@YFF*8r?`+Ǫ3_CEմ&':~F6 8!2Xv(mƊh6pS`>?`rE# F߿mטJQYA~q55Y*%W X_)usA>yJuuCS[oTФtRCx3!{4rTRh}BZjBLgTJEI="eJ*ȓb/%{+` Oғ0 !(^5Cu(vj RH^[.$l`9'A?3+HL"/l hxcWݧ gFN$hvp>=_/DSku6zn ߫IEH3o;`:!51&Y;3#;\8л>^Cp1r@BWc߭¬E ǢT`F'd 8`^iJo=S0qu$yg2I F 1M飙_hl (Ƣ~]3L3 6Bq VA<_>ƜK!8?f ~Dd{Ѧ\SÑˡ5=jF"l|i1>~)Aٔ5NG+OZR{g/2K]iӊ0}(V[:¨cs\CP(jf48L?]m$~Qk*ijr(S$?t,/IA͂N]FWv:70 tnæk ,?+. W D53;Q=@H!KJ죌2܌0:z~ì[@ъד >M.I_\~S:zY\m|a9}1;P}R׫km]l8ߝ]#@>4 0S8r%\P0`=^Jqb<+lwbȳΛ i2̾I`/p=:rAƇe5ʹxZ`FRԱSNmw3*=! VyC:7**,ͶulND%aLXz77i$M+bp K/yVd3E91&9ZHv&&h$EZK(n; Uim4w) ۨ 5TBBUrG4U^UdӱlUA=f/5g@ 'FlU0 ";{-GF "AlГ190KE4a%_? > Iȷs7TmlEa_ę#Od^>nb{Msoo.>nXÓrJ00$B91vhXҺL޷4N lRQ\/PS7iwTE۾JE靍]S*k?%~"kĘ1s}Y_Ȭs^<8ALH藺bFpP񀗂0ܠ+`PnEQ8X>k"`K>j_LN9qiM&+)$Ay!5 fZcer;NX9ʋҍq]a+y<&Nl+eNۇ% +]-V#/*Ch{-T̓.5ڰuGy0 7F<0 #kQ֝}ܚ# [bU!N ORƞ6"$NJ".ܙ=qeӧpa܀1X76(7+!Ǻ. x!Mxڶ~5ȊÖ)\Y0ϱʕ䤉C×J <$я{P"^&:#,B:'}FZ) k;q6BYǏV|px >'#N^6. Ɛ0'q*$2+/5P˪ :axf++`,R+j_J,\VlQ]Cb%Ij K+F2K !W~>ǨFD[XpC65~j/^2OB{?iq{U~@qh,Drq]xƣWw]xJΗy4+|0D x\`T,D1d_ ai:s?aNx&mF>ct{]5K\R# % UF @7$^&bR^B_Hbg mz%4/=@91ؼ:`ZlXS$68;էȥ?4@ mE<)E=x6jQ}d^p$OT/ΪX9B 巌7+m.㽛jP՛;[r0!/XHiZȷrRZ> |:CQͭ;0W7WW>]%b%:$dl%Y K #@3Zd =ضZcW[YF1RY3} O~(p"Gs;1<KEC!5%hXx^F -F `tmFDg>^Q(}$0 lQ9∆rbW>PiM)]6qVbKpŏ~7ca21^Ft7 >|sFfEOkZ4 sb}ԆS`Pk΀rۿ( ͯ*&8 j!^}d۩TATB nC $:?BO3&ZEf ݙ4FY)5 68ɆC̈́ LceC7߶8AI)Lc$j ۠zn weq~(RHjo@=+½aʼ2@~[Qb4!\*#JWao8 &|^\ȁj*xm*n9?}AiH DB.>6lΣӢ8zxͥR}7dLKx%`QqR,j/%meVKм"LX߇6s"+On@qj#=AMZr~(l^tZ!ȶ^{#П{>̋OnqI)(pU.ds׺MF&C䎐,V}#NRm(* 3[*#9XyF6 j*J&v^Y+t4zT8RH=VyF𼰷|mB= #`X /zCJc;3ИD$VX>-(xrnqjeSY_ }vsU-fBгFrR ۋ[0]:9J.A>'BPZCԩl}Bʳ\C$NP'T9E T󂑘?vޖ SvZ+ C^EM@PbO$P7?lQ_M1:*x87o$_5_@njHYutc"b$K`aǐ!`4Ĺ42G[#V"li8?]s HId% ##[Z^M4df{IV]̭WR~"Z :Hd='#?_'OQd_ 1ISwwR\ˆȢ低>BYw&A)_`iSѼ#Hk(wd@Ń(eA9oC}{ֳBeSaVV`x\39vNmf Z E9MbEmN)M&n$onMMKl'K¼ Owr;X;ҝ˩Opz!DPX?GBǢ#$O;TکJ:nP^d)2_tܝV[$LJORB=Y &ll^ք©lu$ h&T7pHj%BzH\S KHiߧfr O2#3Z9%CzTY7=4Hjv>$F-`ԧFLTd=uMӟ{ѾNő8 hIh+i8B<=hG)-P"3ЋmiI`=76 f/2L%\cC:f(V7"PwLUQKɵs$P`4X9hf \BVUG&phh` 4b R%yBcVb]*6wt綱O“^n;vn͑kΔuM^nKB O$6yĿm.v`<3GK{91Bȳ\ʼ뵻'Wz=vٟR冹dxJR*v>I0hV!y^0G o/ xslE6;n 2tQN&y/@5rdJk8(=+ƫuXj--j|iE*=8GUko Ůu0\G쓟4e-Xp`9e-K h4 [cP)r[^7Mt0h;QX! bYsªצ-霍D6 >@@d/nl$|P8z`G^--]*Ё;xT;l=1)ê*!kTShϣCJCd c]>DM^Qh>lf-"\\GU3hK̠6̈xbB(/h RIMoߣ1.]#doro|&zOy7;BGߛ+7qWthܤp$;{h:L"*g=LR>tFbh P5f#J<+3N0>@[6_3߹flԸٌ/m.:FGyyd.$@y:A𬁿Sݦ%Mx59'AAhĤڱ% j &/aU+ >W^fa9xWqq bPxuM3T ?Vٖ[DҏYVMe83XK_ԩsRbFC1>8W 3Ȉ+jL&"BAe-Y1)/ʧ 03%o+n/_E6[|8߽˩`Y)_1 >K -ҪeH>+ӚKDؘM#q=\UkJ?+*g.p`J5,>+v]Nna4Mg5[(\os#̖'r#^IKBB/.P\O?}pG ;}Z T?6ᩴ|8*5 zWΒ#؅6._[u BhE'yQH _vϢ#%[/p" z)]5TYm7,>Hvf M1H3Ṳ5GҶ=WXeDAP",>r)g 粡,ve_ ʭ{P[Sx28hђv)w灹}0(ƺM ,uB?# Hq#B~bD(8gO_^Ntr5 ԑNFbR4q tj37tsYSMYs?|:ʇ >>Hm -cz&e\~9w[VW3 {tInUdD9M$jbܣq!fzv%i2͞l sJUBd6x&Z/Ȑ6`wy7]+w%F4W[g/|>t ~}3o։?D1_0ԀzRVM&>;H> <!(j.CZ{DֱDNiv^!,tWV1:B\0c]@tLm&xJ gro@m I:+,Lӗ:gzԉB[Mb ْb4j7Lk ^sC"'3!Ƹti,6 Qϋ _Ȓ7$^[}qS?}t`4' >d)cm8:4T* '`S̜Nc#}ې'w7vέ-?>`>0~S^ Ɠ~0.Y[fmJZcEe}%y6 h]#O ʢtDyX.VޯΕ mh:5N0[~[&LFBeY.߽9O-i0U#ֆ1f^Ȯoބlf wi2K=nAV uOUڽն߰SmcQg#Љ㎒^۸ʫ[/9lu\Ij4f:fTfgffG 1C!+ku 3̑ {G|LtL~q0R^*#x7O”}"fsxLu"zqr0L6nhqP՘i '**e>fh+ZpMq8kIE>JFyGsQQK@)T'EƢ c?tgU4H0=IW.w^;+nMR0480XPй#{x֫uq_yb ISZ!'4WUDҹ5A?9X<SH1M(nh/ Bd͚tpUv4B/O3A|i,׊!g-Li@wc2B*n|}ޅC,]e<Wa&o~YB=TBBF UbNB(uꘂCN Fi1a >Ƶ?^4t3 Ek'5@L"kEx[q]OkOss /} ?E[tJ|m߷s76iҔ8yy6ƞ>Fd?.o`Yn .Wƽ5ͧ׎z'/؇eUKe9@8fi\&O/++VeO(r+HR6bO f:iewU!S33/ V 2kWogzsޢcH4F Bg q:G’dNפUȬkYDP)\xJ^<a⌄N29eZM5=0#_«%!=`@J&Q RHԁ̈BgU<6쟃T5`J9eG17zD$!?@:_,TuBAn3tc ,Mcªض r*$4\FM_ce7 \ ̥ _AT(55>AJG <9֓eukAnj;Edb @Cݵ+{썌ԓ LtZi1M2#w^J_I{UwXe`@ݼi^~78L>*yt%3ryQr^H8[VeV7VٚOءȀl@2&tAK8֑U|];]1v8:f]HI pp$R4/7sWV }'pnDb=Zp3fHY"-;IͽLtĪ$8s-!l ZmXa >-Iu?+ˊPz}w}v_ ?xN7cU?=]hqC&an>ǹ\&mMk*Ғb=j?ۃ:),^_P d~4dCt6?EuTTfnc~Ώ W1SjInQXXSr{*ΚˇNe:+z__ӱj 5`iZ{R+gי!)EC'EfH4yĵ 4XE+yڱ'O_o9)KaV{Cc\/UQ|("„4]r8rۅJ1g2de;ޯk h{ +' (HiK0EVIɽ&ubL,qbfNWIaKq_QV6{o>%]aґb+E ~6%xfeAvGSnvVI;Yk+FH*76c&o>I2ȴӷk Au)#kJA{, 2 Khgu$=iO]Wq[l&: QyD m}լ~"WDI$ĦDҺg iǮ4R1 bXF1-17|GR=r jTtJO.2"[" E 8ǙFqΏC&$m=ΐ-ɾǴ~w3\ ;_TæoR&~>{WnvSv~NUf+J( ̎hh?n+ _?LB?0@RgY{E[x;\_;-/Z+plv,OeTSJ7/\Vh0OK-G[̩Pq-SP>78ZkJ̈3[ԡ 1eCѓ`io^T`:7jW>]W"2) b$dCvρRMJb#@c" lZie!úʼntX[ JH': )"FW'E!Ϣs-޾A͒f"g|2XdC;R `wƣb|#xj&j2q,7^H M 7F{? cw4Jq..)1JsP N*2l|OlXOh WU //ٛS4?' ܶ>H( ff0zЃ|E|4[:ϜDu\pR`NXуoK_?YafW%MC6-eክ0׷-a"}6B~B+CkFIFfc]X@VPv4 FMznMYR#/uȈ,VH &[gi&]ğvkj{$j6`uj%d*؎њsYw?&"-g:) ~gs|9ĪyFk>w-fH'K Fm%m056Iu'v駊?5Sг> ϱ(WV[q;a PYU |K5 3R#cSyH9(_(^6Lmy1T!gkЎ[s!: ,:q+;tI 3 E!0=~,nQ RuA-wK?@&\lֱ]Z Yw-H<:`-6i5vszZjQ;7^ $B`<48;n:+Y앝SJu-z#OEG'ӌzZߚ?6.:h#MR:HX[ PC(`AMʡ;U#O _FS/KE<أ2\Ȟl d."Sg0%Š~*m61c mPt=\%˧" t$Yi:D+Z'11Wu A&j;Z`rx%nKz8^a^EF .MYI\ʿ:S?p^|GvK ၣ)(/ny _^#T!`8Ӊ9ێ1~{"qsFm6`Z x~tbᓯUrL}"`0Iԡ~ym<v4hQRY{\xEw GɷR:fU5 8e:D)cޏK$ыlQƙ~ZH^Ig$A~GzF_g-97PGB륤&0={o*\1r?!ܮy wʢ]{#]tB[a!5Zp?!Ԣiw}$"lZ%m ?ij@HrVXHf PxgnycLà%]*Y&vE?~,uLsh Q"xR+Dn}5y;'I}s|*>cHe}膆^zSϠ~0.gu.!*044&T4q94M r? :sfyQ$554xH=\{:*H|`t&QfZDifgKb\FHcZN-er'/V']8+vʓqGR[02^CsT=>;>?HtHD2o̳_j$"7 WR)q& 7dC)n)M:<%W۠}"oKz_1bWbCK.N#Jzж3`}LeĿIY,o8Txpr(ߠ;\w}nEyfb~%[;3FSԒ og egq b3 yxrkl2fyFӎmT:(j7k1j @Cz~ tP!ȷVQ.]O$c~K1:x1&۶DKPo7_N1.%oU h(4^"&8y?0=7oH!Xf$ RێavFN;3Zrp'ȜWիKlIM-^37 ,T?+!aNTڮq(KcNurA>5Jc}3]1&Rl r]ҁ~C >#ݭظbn^ӟ9uDݯPW ' šɁP6sIYt ǪKXUndO;_z$+q2, xm'#fM]ɏր{r:#bI aB0001H0Ka ;A\c`* D{dZK@Oڰ-1_1<~AHѮbMЂȁHs`$ua#;K[dn5 8p\fys%Cn; dž#gϭ"6)v:{Ü Rhߠ~29dC[3XM@D_u"7 ky =`[u#G%BQ D||3khps!:n@Oa˖nsB|`y5$#$tă#p,vQ~.&)_ׁF١Hz>X",@$3[*iyzR=K"Z\ kзfF9j.W1`\hZ9f|δKr@9xQ)Rf|dtsl5yX`mӹx.yzA WPk|,譒,sDFYञ̳W4vYV$0dbL7?u'r(aW{īM !c(CYh hנCGiKN3u֛}oH%yQd<^^~ ԺsI_Ψ2d5Bq$K3s<NY ?xHСW}%h]AٗF}K_ݞH*@}(e> ,Iezߜ|uĉeE\4fBqzd 5SZY#ۇ|#r&FT?s(Y "=*P_E"fs2`/E4!;8v`¢rzL&kXocTsUސ}J4fLds.L./)+ *n󵎰T6sw y['GP-ct8=m+Lkۆ&JZ 0ॼdR34A0CU# s*TUU^L<|+;z`TeŊcSH:! %h)z%qXB.zu p&A8@,#ô c(,$,[iWiVnWM8R ݎl׽[4]PC \I;*8pR<p/QJ7L>0cĽȨOU'Ck֤=<NAvɕ75 WC"/^93Dhݧ QfJ+S e\&o3!bc -{rC!ZtW2ӄT\;س`q;Z%=0XPҘ3&TwOE^AaG[l-濱)DbcAl":a͜ZB\mXXP=Q~ R0X/OAQYLqnϳ &!8ZN_DS;t/ի4:hтBpV<6 Eg 2X[.97%FQlUvTExZpR_Z99YzLGs4pCt.E" C썍2Osau"{& K>XA)#}ҝ GIsG5 (e2|T*׷T|4iJq"d܀=.63ʁ\z8XjqnVmYV^bhݔTt'\l=z+;(@I,]r8 ]?35̠p{`-Y5l_{㰋1dlWU UNS*6j3[ı vl5b2 QjQ!UpA7اY2)yI%4 -wQ4stj-3 D[~b0&b_P}*'=]~M}@8 =L!UYf~H=P+ ՗\έ>W(Ah/2L;Iz.|*D%DͲM97WAv=IXQe@V0? 3&RpBHL=[9E,(Yohw][`V&BⲮvLݪqf&ŻRs$O}F+6ڕ 8< Xs> 9ddeMEk%g23c&&D=S_ycy⥷Uc6i]JS~)v".FmA84{}I@/< IA wXV' NJAKulxjT81U|jA 60s)0Xi`ۣЃ?bI%]qy6xϹ [ ڏQc&WxJpb0Y b<7vDCb?^FLEJl@n|u~(%VQm )7 ),mq;mD*)ies+aG..TR폐LIK(_W8PWFvUpSm~GB@kӣdЗKkCZ:ӌX~-+т? j=c'T50b#-\v(kewh$=*dwA41%aQ 0VOF(Ы}qƖE`غH&,Yhg pQwqJ׋Bf&P|&+$1T~DݙMlxɆ/-On&/6,"-*+yyqeǴ\a 3g5x#8g`@#\\ T>0cڭ|&e;v`kg]bt_}Uwa8jNu^IhCOc.ݍȗpML 0 8|3fW `ٙ ᚍi 7]Y& c&* o9vnBX!޵ݒ<[uߟC%\R<ܖs=?=K7YĪ3nnVw\h#NI G@P3IyCN:mIZR=SuD u뙃 6{^w7mHUCހImQQg,b@B,!UcI=K!A{Qsx˛#_n͵@-:@=Y{9ED%V+P33 &V {3EEHJTsI]{T:Y>|ҬjB;&+vLhnx0UegzzUtANĔؘ֗ Q= A)K,]V1:O*Pnp2JjM{rȘCKABWNş}0Z}Tanfz,A"#ˠ>ʝܵo -=U߂Cn %(tT5e[쯡pJT6Sd q+JtT+y"َ4L?iGafN/HkX r<딹Ѫq*D4{_YS2'Vcs/M:J43=ϒyލ*+F48r=d\#V3%w]{ȃO| K~gө6,R9}aHW!'Q]E?3SvFP zKX-"?!}/u닔G;cyROzCoIG.9Iz &T!3]b.6NbFCdu.FNVVgpA~{m1c Kg61a}}pZ\\;MՕ@P >@U%T-K1@ERXq~`WU|߷-tNm?-D*`Wc =%]Ij}z1DB%]T750('1ь.J!@Vv Dc8Ggމ2PbH7SQ8 2|ӤශO+FK/S;Dͨu[0PZFR/cA>IeE PlzqTC;QԢqHZq\~,)gK B[?Byk ak9xkw;/. l]ק+4/m~'4<ߛ *Wldbrtq -,v0l1O'.2=<h2X)θ,3ME?ʤ%^RmӇ pҩzוKf/Q_g8RS,ﶧ`4>4[YjSz`\왰ŧzA 5i$3QM}PWTln| ,r_7QawAwp+V:a*݂qٯu[d guq P~^lp Ʋ/+r)4pjH=0xS$]T8mҭRMl&bqbd+DĠc' l'[~hAvEeJ_Us~U7͝CxcһjN&IN~GZLPn?nuGpe]g0y6sw[i4XL,Aa7ɤJXJ,q=}# SWTԾ~phDnHh $e$90ϴwaxBjQ9J<_谁LVcI^ȑ7/|* 1T SCp H5H2M#I0rMR5(LfjOV -H[yR qV-ދwj)y"i{6]M"r6qX#U)BmefU ~kάLڝb!fS1ɗ 7t~8V?o(8+쎼 nNKmg~|vjs{E0:\wVכbݱF\&98l9OpN夞TJ)6 jˀWJ;O+m۾9E |,?8: (PKM#Y ĸ۸oa&(w}o*ocTt)g ,d勅o)~e \0#|y2j8O XˁNo؛ Nce*n*ąmTYo+sWzHꜻGV.L#s^*e oaG-. m :jjF<{Ae2٣oo'P,[b1\^h]`}!7/Ե"gn.e'0NJ <ޥ}QlEs7)Ly(5Bv/{4(w6 YB:[3A;MF=;T]bO]o]N`qe8ul+3gZOr>s}8db2HCNПBx+ܖpT 6CK`ϵP[! ?jfunK|- a@h{8Ӓmnjw8_0'nJ 82A9}Iѡc82G >^B1v{ۋTz,3cRݲ:bsvuEt!B|_tw!)OuHQ+GPet{cM't9%8,T.LD~20L$ۀe/OѲ:Pxzd,e 9Wb1-k <+W/4V-{}0-bx'S'[1шa&լ5q _ mkw_R,?:)7(bTW4„}1z[~Ubl +NNM{}5¶DyVS3भr ~f<tyE`ƌ~-K >^#CܑݴDByp>ځw5ͭzPD/hRw ӅǏX' -Ti ! b`lrfmӽ57iJOv!-uwVNf$#D 0zO57N0PrHvݤr UarD}4ғܤv*hY:ޙ%r`=w\*u >*_x,Urf儙f(ǃ2!X~5tJg/^3&5%$NL*/+N#,r+r0?pJ(59[.,Gy]ޡrX >%kWmm|R9~d}7inh$?ePefmcB2l{KrٲW%i}2PI &ڔn\_od[5D̫:3zb6jBy;}gj/ݿk_<@}) F;ZNәxi"Z=ngRM&ҕiêPkyJ^f! ЏJq> ; 6{`071G<y4 @ئ ;rqX3tL t{7C/TJμ ʹH$ lgO/o]n\'ש'UiZ&0B"fk}16l))ga)BwuWBB\jCu|7x* j;!aUፒilNn:ۗݩ)Iuꚯ!X&bupͻ-1$AW>$i |sb } W~ȷ56VBnzW/N;v]p*Qb@;u>~HtRt8r+c?wl5MGy)(Wm5TQyT8P*Wal\O$r[w#c邗*'1!nO7RZ0i+ᤛʹS׾(rQ4"C\;:F ˍrJb0Q)N\8:#L j &yK*; '߀F) F:͉J UvzV1-@{<^SWC$e0F" k"eog6Otiy05X?لzvB$ܮ%^Bf6ĎMT 5G팫,ԩ~k#UrQ)4_>h8[ 6X^$t^/"zSl\4-*~]$4 6P/_ݮg/'+tvPro c2+6J45?PcE_ i] ryE 砪 '4}+73k0$L=Au{k,寘=O~r&}~`Fn”8k@AY[ї p`†ZKIC_/UNY;,dxSBNOi*$IxMcJ9X!`NV75_B9n ~iXCr񖼳 e/abN: 79υn%D4}R܎A"NZS rwo2qF_vqõ(M.bQ/CuS. { NĵtotA`m -JT ͜% Y8(4BXO;)s0pbzIE #NvxIkο@5n;\NN,JC+FRV}}d3먦-9&߅1!_K )CcAs5\6Xր[P⇆=bϻVThBԣU]Cq,(s3ᄡ.tD|8 ɗ %]`sXv⾻f!#=/#g[kIfakm@]4 ڸ ^ Ye.81}(S]O 狒ZzlTR5D7Qu$ ^Ek{Sn@xCtxtveSIHrt@s0 !/G}p|3uWETO3-@f PB]eIZ0]@>GS2/?l"~3Q40GViRK22e6:hPSvI% ]Dڽ#⼭mJ {f֙ue⡬<[sFd&8W%{k|w[HTe Xa++SR sEOb7ʮN.C?-<[ B2@i%K`eKEJA:ej4.lS}D$e`fG0*Da9+A2:(μ͚ t9*"dLe@:5;KSNcLkt@F.{r ,f<_k-f h.09v"O*m"aҪv$+X tFu?{&T}Ch)t` AJǂ:VG=A}xVxĈAD:*džBVudO%KijPhi߷5G1e%=lvqE :N]⃕v0}cRv/_ajho~AN ɁM!DQ}TmX =^“yA 6!%R`|H5 ` ]+ 9߹bT#rI@~".i.rRYYv^Nۄ+7fyQ2+w /qr1sIBlե4^2_󀉬¼M^-ah9V39 sq 9Ip k6LG';`TǾyq߅yŋ1~AջE!)ӡbv5S7\7,5+cϤ6cTxso (/ߙlC @ǩ[,{Z]xrWs#*V^P z{;-i |8DSf%[|3uiv;8c_gr4HQv,Yyk廒Y!k%@)Y# 3TpO18WTqĀ3V2iwKsa8 DCU2 J+ 'vT ;@P^ʘݸNDOu7 [kEww&Ƶ_`u+%#H5#{5!x0őՁ5^c+EJ\VmdZrSpЎ?F S*(H^n k4<dGt6ޜ}alz0]@>ڐԺ*VXoQ{˩3<7"~ ,Nw]g;'/,c{f5U*Ou=\Eq<'d% Z5A;Hv?T+ K6'G}ճݜ^wƅEVvUi) H T2=xVy7S=-E9f/ ޜ9e";4W7baHM_$91j #}"9^a%SI1y.4ǓE` z3_h=%9}@X{R̉ήo踣0-wGIŸ{!(Ƥs& Bޘڄx YlDCdsH9yǰ/#sDݯ@R?;a5pԁe0pyHt1oTYXt[9q=;* >⢤98+2ZPnY ]P ϚC|ռ7T"rGFp_'Gm 5#)%, Cᓀ &!]Ԗ&^w $oPk `!jXGZLt$#ڟn<[OPk 8xVP2} rl'a ZX(/P"tCD k\ը7w&h#gì2?{̄H)vR~.??"}y2$bY`$$}$Ӑcn.|Mp CgW (v򞺭>Zc.h ìYuhp CS<_p$nGYЄf)!̊Vꐽ5pN#~UBH$p+2- 0ZnVu+=)H̸Ae0o/&\Mj^;;=r\PקcCmo@>)O^&67}DA *j\A5'.`vw2amkTā5\O7uFTP?bJ/31. 6Cjx@7Q܆ HO2*Sh+jmg|CN.Vؿ0|':gEm=ܓwoբc;aVI$FAz$b)es[};: 2|]3|Z "Q.L7OSnw( <19 =,8U ! Iu-K6(3)?GlTd1j3QK7 BzIӷq$n6Dy Ϋsqǩ flDg9M[@d}CQ,>F:^_YvX@E:)3~\(P*T5okj. &Wԍ)p~C邏Msi#*fy*Vgf'a`&1rM|\ôQInjڵ!gO= 4շJ5'm"8qyůeݮl\:`1eމN|USkvхR=wMF~-`]u ZP5r@ @g6o4~I-:'a`6e)EGGԥ_5/Lfd", t{aݵ('80@Tw2xP4c[Ro{l7qۧ4?^rkDbcO>A ]&"W慎#s4=>eM>a c&O'sI?<ҪyĿT쎰[O_ducS BAYmf]9h`ctѕ'몯ҡ5AG/+M)s|"sӣM5A9Ί:2\fC}eO&Lץ'8i,>ޙnLZ8[5(U;/3HC'041cT#.5aaqxlPeaSv(wħg^wʦ-ͨ)"2}bR my` 2yc>&P,80:Be'l~fgӷ4 R_]+"KS-KW{amf%0"*Vf"j*c[/Ϙy!]2L= *sܹM^vu6gȩ;ZDղgdRKg2S}M:[.U;hOڔ-F7Sl= `+)q÷G}H,kkkcdM 1^R&Kkv wY1";*MJ6{ImעtC|-ȀAMt>: NX,%N.Y(j\~~N(mͭ}Z+Dv/mBH,;E?6H&|5ﬤ;/+ף:k\\0=5LFY&~KwƲ&TUF\%3m 89|t\dapWMsdՙ'y +ɓƏS Lcܥ90" >CZstM#HSDV;&N%ͥLdܡ0۟$k}K'ƃh9> @7,R%$١ `2"PC6;2jʬ-UW55P_K?Π+#AoݲpzltdݱdXr%n(OF\>2eoSy -1v6Er#FSU# T@@{0ߵs>;Z4zDX~GJ L $1FZ6cȈ+u:YBl*F߰jt?ǀl9jm:ſG@PzCE|FOjA&zU4*M=io^쵼Ȏ&d08|bo%"ΰ\8 EcAH-Ȏ'AjP]( ϵ;40K*bJۮaiCOW5"ZJ^1 o0@|tz1=>@r y /MK:ݛgݓj5Ԯէo g_}vMveL7 4ir-k3iFƅYQ0F{9s^mZ*r&S&&q$1D ~_i UWvѷgh.Su+x.fNW4mpo'imîMxXxdO"IyRu"~} 84,|SE0:s>bWs謠YkL |\פ;3^f)U~tHF?)iՖ c םeZDwJ Y=,#U\LVXC ?w'f5k0-6/gF>L*Dٲ櫽3lF>X"&5w s5z&"&7i}vMVz*sb—ptT?^]ID\c| CI-qDM9mwRMD8j(xcuR_t E1Iud =Z/4i9iBX=( Nzpן OD"Qw~z@;B[:I>|:sy3g?*[⯖`%KIɴ*wyBKﰀE>㫲 g >k{?lq6XW FOlQ 78Aǒ<$bTfYnݷ˖$۸cBKMmmpɠLYCYˡ}6v$ 9/Yao!Dz"VMV_!76Xz~ L}(EgX11>IDwY-;G9B lUE'/z)ÅGh02>g1̦7{+>JDл$p:1)gIKm$(D:AebYu5/vs5GtD 8w*dW;0yZx>L(^dO OqMM!;tt۲Ɩ^7v Oh"ғ齔>l6W0g-1(a s@n4`= aeעȤKaVŸ2z]a\v4x}}Lύ _cp3Evuvߔc-{VXMvӇ(-8/d1,6nmnW_vW3E&&)*AV_oca%ndDSǐ(rpq2Y}?8hE|n5R{>(D#$bX}7#T}P@Npqf4Q"lH9ÑPuݶҗԱ =,!OiI>4:O%4~|! %(5r(湟%^2P_tWg^K;Pi7 63#h+ r+qoq7 kXϏH%v_K>?<6PZl(e{h%`S6`7KbHycF]`^mA=ŧb0M݋#bRǑp2 HNT-4rEN2)5hЀ2 lcݍZC@L` -c8!|2TGW%qJ譫j J1I?r 鳪Հ1X%Ztz j,6:R W{rںhq&x[kg"LM> /]Mq{+q- F8&3.PNr|!F'kk=֘a7 jeB䛓'GboQ:;,=ot;2l$&sԋϲwJ#1%>;FOKbG:-=lSg3Uc*iH؇"{(2c]j 쀋,sG;Xy\1k:=gxv tQbE[$,Q`;E?+ p4٣A:5;|} " l% c?Aes=wxOi@7b3Mr:jF%R< &%qHg cKB;fvΐ~ާ MIC-99_YEodYmN_xr!l>{j!vk(Fv-SP]p3Av;S9ŌMϤz7BNy*9f,CAľ96N t=lSkY]Ri7֢d!&*⋼HZ oWX vPC߲ư"O͂n񰮔a&j4k㳍c,wn]\`F4 EC34[*K3*!#ۈ`i$1_tE}LyjC-A0}T;7[g {?58l" {yΫ4 d>F*~a"R|3`HT?ݴoSJlۑ]WakŜzdg;XM:UDXCk#c h0.IF=)2o 빤!8ߝ,˜̈́M@U_Ss{H,S(LC1adxh>zR#ea1.hVOz/ E5]`3Jپ@J~԰CWsjKdme>`xp*olt4, ;Y!)dum5 jΙpFêWlqjE-/LX¦/ѧNz ϯQ|Y7SjL$a%_E*q'.{ Kho%?nE.l+]JC2Lڋ^/;)ŢjV6[_?.i,Uƅ V.ҢkhOw]+~&6G,U~zKݯ1»I_CIqqDfWLBzqY{^7uR°c;ص]6rs!6GK  #jA ;ĂNj<)%xt<[ E|:[(Isˆl.K2>-ey ǬZA7NZ!4(GgRY4,v,ber'571M03w'p-X|sSFɼm59BkIm3׉TF J|( `ܗsG x}.Al"4{"dލA@%'KSbeln7E=ˍ9Xd{*<PI6v&&ZYm3S K|ޠj7!NFX17\Aeq;FsoZֽ?k҇R~H/ n0&2_@ U972R+B*TKwIH2$5<}҆/=bB5kHx r9IܾjL5v?$DsK ɖr6ŝԣ#C\ҳ@(Xo_ ^S*q֙$#!y L^.s6yxOaª=w;&yMtNy%$AJ wҔi:*`[$qS%4tW+ms!7q< Ӊ h㏿s3 q* F%M@VX!ձWR@`%)tzݖC`5!FsCvyi? Cy*޵\Q7 تn=,%}Tq (t,d9S*$x;<: d^J'acm|ɨN$RȝӨSx_'3Ixf⨫,-X !a8_hKdg{oBG =}(O : InO_N?9ZGt/+$fco0,B[v JQfXgS b#29٬+?u.:qN(x9Mƫ/rw(+$2/PMVhw=U·^*w$(@Ζ-dKohX^ cs/Y`x!JfFs]h@C(Qˊ3\oo _d&$Ej,ƁJTKX!b0ͦ)cEsÂNeu"*{:ùW-M&H@7 Ufi7PAqWtd&4WOoVi2r7/`1d(ڀeDŽ_BjӔٳFgSu%e@5A+?ʄl lh8,>;CRr*XUYRlHt0ݚte3Y<試lHg kA?lsPBfz# cr (鸊2`ϲ=E\SO0d_+ rM+UyHkJyE:SO& hxj[TV8-`8ek˂+=,`V c~eCgt=4<_nM=hCO@R^s0c'B`aSb.'ڷ,{A r8 ѥe r`͠$:N--_w&BZ)ٲ sEaa1BD}/[%ŧ+ߕ1.9`f5xvprS.tstx 4S`$|3`t"0j6KGC&,:"8t{7D|+n\ P=иA(Vy?e ՜Nn*IQ~r]';+b{جQq˭FoWͺ`ÿ!낾5*C6oַ-:Hj>Dwͫ0&rzFj H!iXMZDlZ;`' s~]m ?-X1//2}(Ȼ"qM\nQϋ(əZyя>1D%e5,S|H*[t"zNG*bh:;0+OdvZ0|C,Dg!hTv)y$;6 k@3 ̙}bˡ/~)bM[O1uNQT]蟾-(=)/raB!b$G%PT [إȅƇ*6Mx@8^"48PSVogFRRn8#V֜ pYPߌفhE†atɭu?@ޓ .O)Ġ杨\BG1p*q$lPQ=l*`b3\8 {S >15]\ZGD`?zGg~!? wLbT1 I2'kvF« U=Ox|/ +Ĝhu1f| $Ij3qi~UOup3⯼o"l=wf8ĂW_͚MճcJ9z64woh|F(KA!u}|D2_+fxWqJ=65sz5#l5e?sXFIM5oR~%Jt=\@z/\dԡJzT,~+`* a&-f-r`>[~ Yt#S~fi|xr0G{Y!B @pR;=onUg˅OaP{;&d`N∋tBPokѨҘJ ҾL%x:C u :Cf\ZUo'qay~36Ctë82Ľ:?ƒy6!^ &aԑn~dGPXdaVz#6JDZ!}ҳPiAFlFLkzY9)L"NO2{\f|IG/Z)j T%RdDG D@K~?iw(gHh-Sz\[" z0iV% ud宄dJL4h.}E %pnG-bQx U܈AoOr~,yI0ǥZ0X ^K0| GBι$SMW u֥s#F|n&qNUArNÎyT娔Cw? Tg3\0тЮlZE=ḧkM_w5pS8&mnpߢ*1U5HS`Fz[N_GZQ5}hε>&(P} NG#K9;gyA$O͘#p7 #V2?niƽI5$nrfzW:)>^v2KLJXY|2lV}Ͼo6c9I D؎S~?@.Uaqد8 Vn@5YbӂR&ʯ1WYQDzΟbMO0{[:`2TZ G"3}0A if%+OeZc٧ە[E B'r@gҶg~ ťFoAhҔ^ E3 kFўy G[$rU2tH.6nϳߺ1:~&j( T\qR̰x hԌnp591*IFo|(#IV?ctmI,EV ԙUղB-B9  %>6 Qx \f[-NB5oS%WS8_L'K<#XP~X !i #LB^KäڴZ1ؾ{!L Eobebvǁ5Elnj|"O刚+6n6<\!KF?~${{jRZln0]pظc_WlZ%6E&BC拾8njX-,j]cf PQz7ztTS R'uhBnXי밈<3O`OSD NU3Ե=bMF2IJsS,7+Qy.!4&j[P֠7dk>Xq67(g}êHwI߭JpɪDջ҂yYsda5A'ɼ65N$O0)vH ZwWH cֲEEG}N޼lD0-z G {YCdAfuc9q Qa$PI4L[xCKQ;ݎgwh6d%zMvvvs_GqER9\5\ƭT.9˶)5%ߵ*}N!F~Rznjk^xCpk=J_r'Pҍ RJѯHZ\](W4\5_읔9JG/H3 z f%>۫p8@aKL`Lߦ TUWZMt;?;Bkn4DDlՁEXPD"$7,9ӷTYcuY ,'<3Е@x*8/3 -fLlO*]9}68dY?,& 3iI#hDj+@j|i4=y~F6"\iPn׿3'C 3XIΎT{\-wT 'x.l1qO\@jv_ӝ5nS<4m7 ,_i.JYHCG8ÂqRF /Pj@{MZJeoJ<h_mttN3 S8VJOUo]$sKApwHh">jE #>] F?ׄ8;^7,b]ItSV'۳r Z}4.6$ߞh|C*+ZF "8XԌYǠ = "6yP 9 NʄOقY}-N 6xYZ`sL |1'ŁNլ^pM 7\W5Q |ie>2~6Dƚ}&``v%b#U ϥSAߨ?f4B /$WO BqfA#n-tA@97Q0TK`:)܆Jt\QRU2_?5PUG9$n G""s~S-I4M; Ӧ¡k_)!P}p_uoż:\DyT(k&Ԧĕ=Sx0-ؖLA1p 6Cb|q}CLp'9H"u-=2BSl>t ]xf1Lcݳ7%!6NJW A;Vۂc/c#A>K dBt]<4q`rIN]Kx@U$','ĦuV֔rcE|7*~AܫoݥA^s^}g%h. \0hXf4HcYTn'524q*.Ҭ3'茦@Ŗ8+ ͼF]ЇMYm`D4]/癙hEtoyGiEgYJ L!I{U+7ZE.ҟ{d4c(3]G KTn6[1j2@ޒS,tQE`85o`+VV*["KG'r ^!gKvca?B#36}V;- ][UtEP SerCTs/0 H4ZJ?rJo^p^pZZW P |7+ iXe/MZkQ@Kޫq].Fcٔ1]i01A\N8 ,尷ׅ$ j[;Vʸ͘{eFٌd!3j.پr\J{ǍhmZ ㄦ;E034$_PuA1W|HlGD<)=i\YmogXFS(yS裹['K Kjj.j4Y'k"#KBU^fu`ԋ>GnV$Q:C9ud]xqދ|]u"Qr4 *-TR:FIPQ@d\&r)Aar>1k_ᓩF؛ Qq}ߖ$t*ӓփ΃w[wG1XIK5ǹdǥYaAS&XJ>.Sj14hXo<(E4@KLA2+6`)$˞$*3:&FE Qo0N_Dmpw]-h6HeMc0vo{S||8 K60jwzz`#@VoQ=^īe1$FlKýUx+pȆ^_ڸ~R$fdf(0< 5pxg՞Yu{VNeST'.)^D ɬQ6-yHMPE`~4=Ʋ >W,'x9/0qΚ㆔KtZA{P;T/:UݙO8<SxBIJG^Z! A@IH!r;hd<"/:g7`Kk6Υ@v}LeS> jb"Dί_(Lq?E~ $YP`gh k w&ͮ v#UD1>˚J_~XN,׫GY./WcD%8/9$94/Í% lNt4XSRᰓ½Ϟ}mmK5r6@`%^7^21^lY\ZzƉ5aˢȮTɪRO68z1~a}#w+z=$qZ̴$XU&;f%D22^EdIG] ffq[}!ቡ*A.9l!θ{GÁ, }DIB @Y-!P$;~".| 3KV sG||JHˇxo8 I `^eƷ( 1642.rC0JvM}!tʥjbkT#.v RFP=O2-A4kbaCrz!5Ǝ~7X}]z"XձHNwJgب{5ꎲ27i(;=RZC$="> i=y!sWa~(3]6ddP]kg^6vZ݌ &7~|ː_N+J 5)X}vt>9̰ߠ,'DIǚtDe9n8jh45)\/pObUF_jwGR舸y@| djp{6e1x{a/0GLZcR7́h`,I0ZifDQyd%"߮^<293FiC ٍmԆ;SHʸ"v^z::$A姡NfIH |;mH Zk:%r3[Wz]+ :̇ lPz+T*|3gfpȗLi5zrogzBQBRk eQ$U x ؔը䩽 .1?8"s=mdn׶y4:c Tmo@lhArY{ vsMT'X X׾Emn+Dw(tOOYrhJ; (PgSU~Q3:@Uu 6L˄)!Q-Dm! qew͹K~4,թuRK&hs<Tu~d."w/,4aB˝te(DE_E*O^j/PoV=&n\t(u4:J1# %9 ;[W+a<-lVIU;Qv`5wX5n29.WI5%]YSV d873t;0wUzA_$|_g Bؽ'pŢz耠/oi,GƍN5͸*C'b0W=9UD@z4/-j!Yy,\ vʯ_}W+#7TF&K ˆol ߄P>n;Kn $ʚ{/GجNO[G}aP{ i)(xWؐ`WK2ԇ|:vqbxbU?;+aԣ8 !U˞ap'H&~:Lg fc2 ,{h*nC/v,:sD)*dX-@^=QuAx$^=,JH[ .u,!^gXZ(k8_3 q%p ?t08uzQݛes3}G.*o'%t=A=nX3+ZAܑC|A\bS¦[y%Y~8foϖqygNs00f}"16M*g艆mg]ҝG^*&+.'ٴEbSe )7TV^w_NSR)('䈁o4`MkW퇇n42+xn?^X&=x/ tLB[CH5dfP[4Gt}!"lCwQ;o34+{0AswC<Gv;q9Vo$fߧxU w;*A+0!\?#* €HY!&+PQFƣM4Had5^ TA\Ot1ݱ&& @hDt S\b@?PKDJeD"H@;j[fL& ?7d9A7R_=:3:Dh=%]f |B{/l4Ps C\ՉXU?? [,63 Đl@b⍶nUbX cD6t̕הKa.TV-)rTJh~U@ee#Xbpkpp~&֠[J&=$p豕'ǥh:BMX (ʐ}?chs?.(]o]$?}sg$g_]3cE>&n&Dɍaa]di27AT#x/???~lF~= H$-j\I)ᯫ}PS4_Hl=,b&#:U4P$mX e9 Z[qNot'*)`>)&&"J\%GuNeP۱Sw(|&''?/vҥ5W GL\R fU)Dto66^ =aF94ږHdY;{m|GcQPnc^m 4V, -R{(?^K8dCQP-#:M-ѝ*#. 0IoT[;׏'jhn RcDžDZdL0eO8MovvYyVTFrR 'ũM\5D(~UIQG/` fW Z+eCͯم{8}6+prJFW90@O̚Ͱ7D _.4UǨ>Nbc5'<Hzyf*1OG!~ m&%(jE/U Ǎg+ nlo[Hei @@LƘ/?OoiZfE?Q6'8l!9AxgʆKxjaЍx3~ |(4LǨVY z)IG>$$#fZI 97Wg 70W1$Nxm8&;ġ3M0ZZy̓<GOOXp̪pkdu:)%b7O R^ NIuxrLae8k_ٳE><ѻGU IjW$=;#m$П!0ړqeN5HV^J>RzcZ6ڃT'koAhQSSHώb;G eOne'&ժ !/J዗R)~.5,7)l5Ƨ븶,uuwy]^06KPߦ\y,0ὰE"/*{D.cA J9,wʴ#щ9富`j!g7{r6K<&V͉1X^I<$Ƌ962 TVU53>Q`7$,aLtjMibYzŬKضq*Hg2 T"M:[`&m2pzC\+RJ۞d)'%8 cfD#q?baD?C &ǥӠZ@݋e˖Ps/D@=mƛ}~Z`\?m)LMۚ9XsvJVϣYks yщ YhLNZbh}P  i$)xzQV"R7GkMrLl3l2]4)TT1l[_ɤH,ccJ5kn]G4H>ϊ#~Et%襠tA0֒E%3C~L)4f'\JP:$4.Ю[-'Վ)7aoxdzolPJPܰ˗,Ž19;+b4?{:0;=>O7*sPƣ[ʞ45 ) O%b)o+IY`0?Za~G}yА S/A> `}nʞ_3F\C5zX_CF`_U$bx p@,uzw0m,"iISVJt@O6}􇪩 o>-}̋benrpl- (/u˒szɍs(̻18y'z0 s;\t#AL 7b9`x9vܓD')AA)F V}h4]wqrGFA8#Lu}||3,oNP8QNC7{Qo8 ? )\T^LNL7ZU1'+閁k KauюYGpo$bavb/C gĦLsphY1L=օ0iV&Dȷ W=Fx{r17hB߆#~Sd"u\׉^@m݇ oodi T0ޚBCu0ԢGX\h/VpF m\ wh<s-221Kap^JfۋcFcYTp k21! D T[(+1Zӎύhڴ|뙲I$a$fJpVEl!{fݓOX +3AR9BBfd0C #|ƵJ^VuQE '~tީUED3>y?M5OjG,$I=>R6-R̞;2(C|.%2\ҝNNp=w0и),Ђka_ ?QTͥa cC/R Psy޸ɢXMӴB%czL)P#lPo2+a"$_d`_FvqRԠ(Ϳ $Y3l +c߄7_ٶzD=42~ABh8`n4CztE 8*ŬfiK_ʵY@b@(JxU/dM(fUВ:!EDĂ=@0VWbzʍ[vEmN1o 9 h†A $ *0ϫqj*jMz@[y?$Hw.:3Smz(V${g@:\mb7nk!ԏpFdØ@?el!t^%jzČzaxZ]x-A*ЀopU$P#to"~-IX=j &D|pVp%P dZ钤!/mblӨϋC}??wMeQ8pC]ٛ!W]!\q 2V??zk\9K߰ebIQ ڑe=梶U&7J&z,$vUALSyY}-Ld:KP rx]gTIm Y{?ǜrYY/HL˄@j^gzoڜp!Yu\m)X$("3L؞ʭ~bZ)`< 7 \(幫OL ԇ,ljH䵲O&LjaOhllH#xjr_ˁ򐣴zM[KmFF ʑL5잻AxZ}$QtdҌ`KP[Hȓq1q= n 'i H6Q5>'WXcea\B<J3 5y a60PE]8>͊SU q}ؐ wVl2< [W(/LM8bE*E]Yt6q^0'b\ZY׮CU-/P "ɳR/ l'h4O(v"}iۉҗԔ flPmնF;q%deݚc(ߗ  v~fdj2. sDVWLv2H`D,Z{>"xoʕV4zid-6J_1# $O)_J/,,Z1FAE9v:N 9lķE*T:&oFf fuyҽ{(=@7@dTN .hC _nreDs?_$7$b·s\Vӎ3H;Y@)x/mdL=H'nj~$2>m<%_UU.UUQ7)|Ą$i.fSEq{, z&~[3zW~_wCy/l,}њNCWS\(|G7RFm@.H.zᐈɫr&VXJ}'Ԟ,wׇbւ~+$.FFfjN%|e YWםgLǚZ巬E۲]MDSLJĐ {x=K;X""t~*UAL|[C;/r`׶VfU{25/NcRU}Ec?a'[YٸyqJh U3@)**s;E-'<{'mӦ' &GGDbgä__eSĂݔ}xe_a)4hi͡l`(GWсpp>!h"䛱ނ/) oGNx;l=gt)OJ$ TYkEqεCwԖv(c6ZB߽Psp'ŅU[@"[z~sl%a;ZËө0R!\$;;m(qN$:Μ5=C^:8=d Y' pD%"c9; I=֟40ԛN{z"q[c"|VOPLpΙFфUyyqSzS&t~OXSH.KE'[HX6ח#cZ"6 +\vE mpF0V:I +A z'>Gyu^$ʯK!WӺǨ 6F1<g |oo|+cKwM7 V ;"T=x%:)"_gx&Jp&szϫfM $NuP9U T.2S-guԵD>O]%u\+^H6MWn^rJ@70<'ЌΛCT1{ b|˜c<2[f27o]T͈O- s4[쑶{ֺS!1$95 PDk; ujIH^q&-дs9$1`ivf@L.R̛u>B?oe@|@\nuo<LJG?-[̑[$ 'sEJ򼼩Ϭ`!$xYPIK.haa6*" =p.#^aӘbϕr ֭|=ad`co'4Tle9ƍo(O#"PtӀOKNNX%+_r9-X"qri4t$skYꕘmj]b\.c4=$m ҋř <ܷIVyhj@ 2|72A9ƳM_N=%.M<ɐJe+D_@D~sـ?YRΆ=F}XNFzBRs鞸AyPbqLf^@ZfJWL2Jm}i![>'%D-B=훖] "Z&{rT2TgI23/13sP*,ݫETyMPg>Gމwtc S@LYIt-Ro$`W8q@9fR Oqb^U  I<\ y9;f tmcNLOl͝.q݈[r*+WI~h2Lq0W|;rkNۚhfOƠ5.$gƇsg=Ek4?Q Wv ƒ{󡐀px/|0C.C$}!d }L%s {/K_ ^Zٙ/x yY)}(r}K0:uhFS>A5PrLN|nU+V'pu9ʰ3zaNY-*Z{Oe_bB;yluT'_u._"Շa[WC< CzVt&9#Ais[9fW+RtjVs2j"4٬i.Gd̏D;/z+ؖ>8L۪^^\pd4>[?Q؏dƩ-,ΦԻ:Zt wE]38 jT,w&F2#Qo4D_9ԙW+QWE UNŚ?Y6i}Ygm^} T˻ AJ2 h.LT%2te^cj=IV]$zQ$p{.X[ Gbl0LӚz{!kę[ 貂 ժs*?!GM2y Ҥ%kLϞtmQU79,;wдim~{yc, ^9 -h`QS }o!l*Q*U),Jz9unhEMs̺w(:E66GYEj-Ds7& bIhc?%C0Hvџ{q>-VbKT h{&}& (5]0dT{WokO'm洁)-`!8_ (v^W+b9۳ +8i\R/WXk(LKc:Sj)dLρB)؋Jəbب\)>mp.I>PX[)fTlZ'W{eW|eʋU":gخ?9,򰯊IWQoteٴ>>GֱjP yy\XHȔp5vm_Ht~ |#31_ȁLw.t𯬚qܞ,# n !ݩZb>RJ7zm wj0I!wGZЈN()XT{$ d2J,$u/+5,V)T+wk 9h5A68(~A\>A!y9zf[7u4m m m0oxif(n9fzthzM#B&s#xy_죘EF~)L)zG݌v+B̈3uo߆"/ajp֣ɤitd#qq!qyt}Jt2vm55O]*T`=갿~氐99}y+IZO,qXjnqBD MF[r],KF>D\+ ]L*mr[a+>~rZ5eα yvEwc&*-gY޵Ӹ^]I"⵬M(ku饈H-}NKe_8@=j+BnC F'½2t$&vr?F;Ec|@u[iϫkaI .& 6ρf )Y2z,m7صJb1>sБ49LxMfYޡi/-BX|x(8C\qp6+dICHnqs>oD7qŻʻvjJ~p O1UQʢ5rdD@睁(cpG=〚{5fy.x_rNL#,th! * 7 bKĚ}gj?&ss_m+qMѫj(2 n76A0&7y}얰r'L]LE2,(̗$˅?86)g?. q/d)#HP0׈yb}}Fo|"KyEF!_ U3k\󏷅p>]CCjWWs)G_[}NBgN?F#esP6 ͏(ɫOgLGg\ %)dhp%ƉO~j[c&&G=zڱ# @lA+ %ο$^`bҌ#T(aNt˪/ђ|6&U3bv6 Wkf ,ei".")(Aeޞs>'^)|c)ɯjI6HY`Tm {"m݌c(c8tG[mt ڣ`'(@`% \POKsS1&WfX2m8 )ɞbV -Bhˬ73+~& k霪AVd1zԼY67cퟧr51BO;\]e(046NgoTeՇȻ'}:m O闝y-9CJ9(KAqm--7nKKms _߁ݓ 3T )Z;2 / W"#tveY2"z)n[]\usIABd_~zule$YjEǟ F_bU4^(zXWnJ+k('BJ CwGͬ73 Xj1BcExi w4e}֢O:C^|l]т8b #d ϟH4 D╲NoQTN0&?YO~ oy#, %A!w%,"G3hK.pgޜBX~n̐,&8fݯh.>l9-;AeS:¶/qaߪ޵ E~g>5rEw3:Qdϒ8{ki d&8,(̃ El1f[xM;c|E2Y:1:Ɨ {?T=mz<ђ:H@ݕ2JO4.*NDg)/39A'cT.O-VFViT؊ǮJ'MY;ttevvJqd*$I  ownD:.CxF0Ǐoꡄ!iQM -D|J}qN)ؐ3=tz[MC7B(ښXͱLpv,w +M{rbeGE!D%'[eŗ<<7g@"6zSIJ&>铷NFxdJ֎63BVr:1%%"5'*m{}l Σ۰ +#|r5"bx2"0AbyzKvl \Z_*E/ƯAK}!X-_)DS);'4YL󖜆!aekF{PI?9%`?:ůDNP"2* JpaIO*4fǷbHdSL P?h%+pY.r|0X/mS5H[DtisUf Xk;!a+,rl?IAy_s;M[%Zͮ9+/}ZLWȟLe${t3*8A!k[VRbϚ7ߜin͠룪gǴ ̵..`YL+/ Kn^GOQK ]4.SUdWxw2sa|g,gW3l<˜D4ߜw15j2"!~YfבՃb7P<{p8l }fj %'p:_Z X-1T>FPa{~0<6l?$vPq E ~`;^FU)thq}@[B9sЕT\sUYj\uik{ U ̂p;ȊxBwaDR5;Y țm(y)r+1)ȳo׿×R3 <3dz&q 儓m+9OUp@ϱ}MStl Zg13 YB4`iS"emӋ8'*\@4{AԗZ\v8!Oh*bǻ9jBަ-AGIG0h6n<3q0]$/**)%z/Fg C85\lQzH 5Z m\I߆^k(o]ޞ~{R.Yarw6)y>d*Rtş'vBYh{,:+מ1[.j=h fj-e: wc\zƎy\#8kƒ:2ixǘ ;֏-ҷ#hΥ5,K˧/:6H[]B{i;LfMۖ@!'u)aQYoz EuOaTWv/t"}XC8^o}Gh;\s'sgumTl=ӒgCa%uvrL(9cw~0L*|)s`(#tKZܫ\Z:j\@3RIIaV'FofuAG&'σ+rdwFjҢMBnR%1Q-7|E{Kd!(ܒ_Q#v td+>Z1nBzmAW)ҫ5,a'|B 4Rk@@_Bs +^5{k]JpH- gHFr^0\+*fSqrݴa\Y''e23oIZzipؤ‰ՃYu>}vB4]N3=WctT iI~xBܒ#YhT_TcQ+$]31Ky/6r)E!Ļ|=?S2,kKն?BR^Kθ#(4L ('^K鹘,^?,IN@Y//"[DbȊ7f|Xctԫ/AM&MO+7ݗI'h8~YR >@d4 6V{dJ@L,C[Q:JJM[8'hQ_ !א־0Xs-z rCŮ$ 6O7gtIt> ऻ#H   n^Q w/5je0px;eceb }9~gnXK:ťDz(J9:},u;׹S'<]PVzޞwkZTʰ|ema˞dN)E=&Б,oghOF3Nx$KE()%v%¾iѽ!I_H*vd< k%:!|b#Gq/^nGlsoH%$J=H%*ځs'04E,9AUJRƖ>>sʀTW#N}D wv.h0=!F oQB0TUedY=!\cC'-˭{2[\cyFnȊR`5Fy /Wgҏ@pzz5ɀqrb{&;p^Bs>Z8,TSiڈg/dgWq#eS7@mk:UJ7zW ʈ6QBZ>uul0.`4`l?01AO␨pZ"ϡ֭<:ai?LH NN*:#IR Ъ34"*$%7{\[];OmG\z_a)Y(7nxҮD?n~QPEmn&`T fn͏MHcA+B΢KžO Nڈb;VFFun Vk^ E莫K  ?<6,}SS )hLKK.|ZOK=_AAMwCuǞ8B[d4ܣs0DHwY:xuz^ayZ>pdW? _dK%g3O[Mvz؞ĵߖ|w3/ Hnu ݨ :?_YdT1=(`,!z쁚PCf釖!d y{)qh gqP6ic #\AYJ6^\[5`ְބG5l!fU!- S0R|(Optmn02{a P-Nˑ*zjXÄ0KE0x̜_z)ґBJ} S͘c?#jz Ll b4ᦕzdshS'^s>3Y;!*n4^ K} jzy'QX*q+ӪЇ<¸6d$賨 xᮌeCS w4-eBmמj'Ax4kJ]=#N8_h! F;v`֌nX"z4]%~[ Yx[IasFCmR|. '(X-!;cª?IthڢNx%eU}w`~FvۘODnd["MX֔%b'QYྒȽ14ov -&B@ HBh8U3s,zr(v7ΘP G*Wdk-Dq>V]瓟x f *|K'HI3պq^&<,@: {%`GF[XP>!XYEd{7!9x;9$K +qu3+/6vΎ`>縃&^vhVJ#s"z瑷Q'lw 9=V! JZvh/?VRruhjzCc{ztԜj ]3$&l<0{Ծ;4n,X4Dx@o@օhD3NwPɍD:8)"p}tFa ڢ,-!=:FrG,35v7(u<4JE[iYIlq*Mt@.e?=Y#K7Wa^FD3V`3Le4&+sPN<v˫Kh m{jG}ݢqr%0]&F蚤lvLgQ} M LD3|R* vDF~HcDiEYz("y]* /`" /fMeoC@Un~7Y>![$vܼr ?J;ƖMX@@TDk)x4/xU{ ppY3.ьN-%ci=5?j)$N|Zcb'Ye[ee)]:Lˌ_{jTmmmP6>[)ްZX*z@w#<fbsQ@5(q?~J%Wr.{v wL63~&q\"?}꯴&59n7d[,K>1^XEV7)?PB<攍۫?Xiɔ:Ŵ :6vn%C[Z.W6",ʠK?Rʐ4`{YJB0zlTPg0Dt2.IF3 4{C!ߋYQɔR05BC'>i<'ApS'^o\cwb ^b&HX"XؗЏf0o/j7ΏsPc-wûvF1gt :PtGe@O?qE"B<%iL$¼ye\tzͽn 8OWb'.{ȋ6%.Lj@}傣66a<1r"Z2R+Vl+F7zdƵ&ROb蜂>( xg!.;78 ϑfȽGɩCƉ d]ڵא>M,"Q(B}s?/&*.PtQؗHt٧!b>' p_L@?I6]kGZ|0Ǎi)71h i+/ΐCP k³$rC ֔5UmYщO;Jk #oA=ujbt}lU]UqDcP+la[aSg?.1Y~?Z}K 5E/Trx\DGԉ-{̇IӀxA]5b / TW@n00I2 L#>i]1Ysux#83%3-̐Dy].t40!$Tǭz7ҍ6fCYB_VhR< s/|  H&2lH:sEX=.-`D.Xǭ`MU!Q-}5~`4I{2|[HAfg`! 0;k_Gky L$=Joqԩ]nʤ|^s<+fFjo<{TՉ=ZlZ8C|E{#jڪj#9}\SFғoT`IAݰH=̜a| lq;,=ZC.p@M6 #Ry:h-9?NbjR[!J]T{Vݘ ?(,SJfXyx,dBcMT;!׻4ZcErec9UI}yc4ZIAB)ȵê8/BqW+ℶ'2{8TP#$8~:KcR b &ε_KQU9r&C=j9Njs!"dUCmX@ptv+8ϔXO0\7'd6D?1E=MQlz8b4Y[6U0֓jN9Ku V tq9ukvH*);oC\g7~98nkt}yEљs[OYģ/)9ny~$R^$kE{{}'NHȭbj_GԪHu>E%(R.ȎOF77xubk d] +Qa&RS=SEMMxB X7Utj$ o;ޔ m}TAZ"U"L\Q87^PM;Loص 1D bM4ʯ1sMfO]q|TimËt8~ qq]>yQTVivdr 2l_{ޒ)tYQAJ!ܻG#dUuO6E -I|3oψa֦a`0zc|_Sn.^fT= \6?`;M9ѽe2>ȧvԝz^o'KĊׯ2|0,R B] ZAS^ >| E2)oZ^fc2y<WH`'L9_wg* pheMPpilnR !+A]SEE߅SGFG1 f`7aUd_3ZТ>/ e?Ko6 1# 2/IOϋyfà>Z[N|a&(DZ0Fm%lP s)p4<_^1bA> WK.Bj/ɝ 4"/sB&gVkH4i %D܅n &#TTv~Űum.%3I*cOn!_sk9D -2l6=Q^`KeE[2j·b f%8O#&H8>eƨq3 ˁ3KZ+5 RӋ4moTNEg9js#'!"3@97 "x2NG9 s73(i#¥=wfqZ55EQƐ|a@l)=lrϕiˍ*!{5Zݦw"p KBp<ܦ *mYU]<?=!4C wMuTl|ZRHn<ؓc6F=l^k;2CH%" Ws- RSa-]*NrDD mƫP/.TIn e>5zObI*vҋ dVΒi2<~>5Y_]01^;"1DPI7P%;gPҜ1m1Vp D:7IyxeO@pwdh_~[%l7 # +_vH䃬L: mf \?eYR`:ΊV 'V_X{ޛVSxn8fDF֪ۚ;_q+׌Jq[ }̱)-OJ:Nȯ7}E_+T!twSM( sPȠ({V>v Kr?9R!3'fjڹ> ҭ=ķӇ"){Oq"UepOC]A5~~ `F t<΋{fƳ-^clUSN;2ɷ7EOHr݆ m">f^ZzmO>*=AumK2`c{k) >zng>BM+ӴI9;2+[*g ѷ^' GQ~j P[ q()ktPK} [אv"AiɭȿA'KR+_;حKӔ`vlFxl(c_F'*NG.f}Uy6Ў7R:czOTg3*ݠ߂].8fEf}Z,e؈gYǮVF Fk/м:oFae86j)Krmu4OkAw- @!ېM}(Q|b\ .D> mڭn`vr=E`ZWdx")+MD}Fax'U=4d rg! PYF+_p'q]{ŖFWjX tX;e6+  )Q6`T|1h3h]gw]W%GI?W.K2u / Se?;i\;eu<-Ⱥ&> (sPbGAZaHFx*#u F7w48[2r'U-Nn1I1'k_%б v|Iy+;&~w ` 6e0Nb,Gu(*)K>щڌʯ` Jk4ǜŽ[x3}d٠.n>skSC0$GӀnv&ql` !~p̟'~dS”)4B76S!ڡG٥g85z'n!Ĕ2\0}llCS}@܌ĬiXJeYYrIy6Ɍm#/qfck-՚P:۪|(Cf u,ֲmB%Aa}*G1W`zKePN4%vfnt7ǻXH7\a9oD^.B(P&SN/Bs,z.ķn:H#`ycWBC`j)g;̉ӳד1I YQTMn:$?nz34$r3PS,֚5kr&6i$4!" cO+Txz3#O P T T+m-g:F΄?T]̦FJS}j*eRPQˢPO1#w|Zzù-jק!YD0>*g:Bq'/% zLfH]طu'9F.Ꙝn}-\$n.N Fd6S8_x3@8f/.|zy-7*6;@| _^s9?9& fy2\ѝ3_cÏ^iO\qҏDU qMM,CS,}gqhh^`B-.5f4DܻcE(7`̍UgPL~3:/EJWVgXσ(ĥ!Uz4^ttȾQ!}3N j M)K؞9^;Pvt(1 ;ͣۛ?~ Һ`#0hܓ6az)rH?R h"?VƻUZ3$A[ q)y6q>S"W^tZ˳A3f C?६:)r.~tm;ooDe"7C.\Oq HI+jBl,g6(P|ȄzvTk~ o١nSuUG`["@orR݌Q0N,w]l^iS+a%? hةY:E@v*C]/0 2`~$z7Gx1I''G'hgd۩W<>]X[iQV'J!OnhYS[!0xݳGjƙs>c}۔t"/K (A~C$pB)7_$5HpxPr. [egh$nxIyJe{¾e'#򔌲f:fe%gD]L 6zx~<z>#2ݯr HdK_p+ Nc^!֮,KOAA&|xtP6:p;BmG9"^˖ Y=p>4k :m֔^eǺ#+?тNG\Sৄ"_[M;*ny #&[q^XSʽZ,;ZǠi«ĆԾWy "KQЭ5 rM_Mcfو/rSr'@J'=lu[)`riqm:Y‚Ua9=: w7Wġ bOS s=̦uy:6R!;hFJOͿ8W}-96%Vj-gDvise ZE,aѭ&;0& zCْ8wIMxbj/Qب|6G7F:dQN4@R LsAɧlͻ$#7N(%JZ@)JiL]Ǘ yĢyT=Ơ[a)N[w8/~y9+ɮ@2η}Y|?Oqp| _&tƲlXz lvGQH L:N%tVN_ 颵f.Rb'孥 ~qN|$2xowQekmt՗IPajݐJ#?4sO{AETx ȰX5#~3f2إ,Qj >|+Dh[^- +<>cwQhT?[0ƚv~Ftg|Q(_uqOyQVbWXzG9uF1;t+8)?^WF#yM*RrWZWF{,",} kr#!M\Hǡ׺f]n{^kWWR:=rNn5uw]DT<X*GKy6T榇ީr)-9p v7ΰGq_m&f϶k<$e}EJ ڧ M<‹AA(hn^vMB[ Nm]8m ]*Yۂk1{p"v;> |/ DD=Ry~:ip_ Im! zg,zz|-6A-;\N'`fƌ\=/igp1,ȥY\ᅡǩghǎ3!$9zU3 l p %auKۥ\F 1ͤ)^tʳ*^cubsxHzLç~\m@\/wSվqV7lߵ3Za]>o{Ud;}iJZ*EeCdg Ŕ?GjOkTpn$Lkuwis"̚K#i:UJOŰ}Z ;PeJq@>x s߷`oyJ%Qw niWu&!ci0 Zu )6^"АJw7eQU|go6;XrS"jA2+CJJSMPCf45s^RMt} {ͤP%]`92 Aѷ6lXmܬ9X_` /VLR%odžfj.3-͛pd"U4^B=~laTMm'4 wMJBs9 XQ(p^JG0 Hg.BLZ&<̽@aKre*J)A`|\͕ Sjk ᯩ6%R`C ,TR$+GԴUQWH_30MT%Mz2+934v(G<&4`eGT9i\.ڔVm1O%${n@2/䥏X҈j3Do@0 $80osY~Fl-g(ZZ=8;NZ%29az IFAI'_wW\Ө,6`7I1_^:BUSw}l9v5qŹ?sG܀+Qy;5D*\34lv^̔3B#E ai1 /R tKM?gTc)޿Rڝ:=wREzP0sY˥%qoOdTB74>Vɀ>n.ri; 7t2PGt,HHb!Y Tz30\T.kPVeZ+3\ty̺W&v7b`tz3}D_-/-E߂uy9ZDw5ۑQOBXN+y* |*~ڟ9T 9Y+v;m5ϩ^[zmurJŵ`- #uQܳ*d0DQ@Rz)/] Rnb֓UK]O[@B`OvY-GA]VK֩\X@aJ\WI:nlеefEa#h΀ 0ֶA"7f'f(!:I1A} KE NM4A2"*]X2tIgA SݭQE\wJx!kCfj-8 X'1nqgu1T!E:d$Z^)rM>U4r9ME[]-?T 'w;ad`fgL 2i31]ej`KPNhcI;fwANg+C&3Ld{Z&,2ʻrSm([(ַ%BC6$ԋץB$ql=(j *gncWxvp_!L&;/m/o<5폻K~7OZI ,2`ű2yȒbkPZwsjP g jXRvH4Ҝ$qR3eB otp-M=f1Sg?- T]}5G- n?dD㎘B"uaPy0Va.<C/iXjr=C91=$`%D(!Lc#nuΜK{=E=%^(3괷 ;݌4tyiqU=p.4+KRnfnaEK>ahHk }&8-UǾI@3ቌ Y5*ni ;Io6ϱlܸ&?46Af{rxK'3r#r8jE?w\dbg̬|U 54"aU0+;RldkvҠM3L=+zeՆ&&rm۝x3&b&Z'V+w92lC|[~+=.X)&RHzSVC4/ͮ;ù̑wIOt "U$ec=.+>AaFr.ٌˠ*-hT4(,"f죁fOέ'Ȥ~hg8C~̢*х 퓱hbt2֎JN8i|gw4;TO0ITҎP< 'z2QqP=B9M*.~|FۋRnP7$lkpܿ&kij4 ίI /PK? ~t;29󲸝)l֣?sUŤe|QIB%\Mƞ<L!J}r3wW `K24pԓd03Q^P΂'Vb"8T( qfÂY