openldap-servers-sql-2.4.44-25.el7_9>t  DH`pb$ƨ^4gU\1?ՒXǍ]b^7uz[6*N9٢&v1rf2'j Ĩ>FbC3llD&ur!i/RmH݇=ZCe zRDJ$s`]󛸸G1h4pnfXl9|Yv7F:V'b Ǵ ;`:gY2fL,cJ%Atnj׀Q1R(e4 g#G'^gMFj SZK{2쫷kmSAc'-–s*?j'J2/G.R[7Y!YĺA$7\ցџSf:\Q\qqVK*EنeTPh Bw~}ɯE6db40ee5c9d4b981a9668ed6b88dcd5d9b33f10cXxb$ƨ$8{>\¨c:RpK?o] o{57.㊺t2/=ڰfnifoR]%Q^`F?F`nh$r gp/ݹw<}0|j\ko[ƜZ< iáG%O:aOY,sowR(e1G L8ܨ/O:ߞcǀl!V>X.iF%:4<"(|ti={(p4fo{E_IQ!2TtjmCHNlvGnߵ)݅rZ]׻25RUbgi?IN`>O` gE~R`%Ћu e p@`>#' S`U]v.KCCZ4!q{>`&g7ÞpHUf76tǘ yTSV N1oV"'k嚕YԘ")>8?d ' N48?H tDD PD D D D DDlDDP9({8j9#,j:]jGxDHDIDXY\ D]D^  b td 9e >f Al Ct \DulDv|wDxDyCopenldap-servers-sql2.4.4425.el7_9SQL support module for OpenLDAP serverOpenLDAP is an open-source suite of LDAP (Lightweight Directory Access Protocol) applications and development tools. LDAP is a set of protocols for accessing directory services (usually phone book style information, but other information is possible) over the Internet, similar to the way DNS (Domain Name System) information is propagated over the Internet. This package contains a loadable module which the slapd server can use to read data from an RDBMS.bkx86-01.bsys.centos.orgzPCentOSOpenLDAPCentOS BuildSystem System Environment/Daemonshttp://www.openldap.org/linuxx86_64M>DZ nemm&@#B!qn` -pw0ZIU0G!mS`mA큤A큤A큤A큤A큤A큤A큤A큤A큤bjbjbjbkV6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6V6c8d0ffb4f932c8f91452a350d0659b2c04c5d09dae8a19e65bb9c98c1d5b67802fd511510ad373fa7fa036433280e516229681550387e242db467badcdbc72a3c83dc244825269e391855595f09bd30a5d87d930a6b33428a7399ae8676b4a7b9ff1361da49048b1eeab07d640d0ebe08c77f42885891a4d220175c47e6b786674b35982a754ad7b92769b6597653eb5072ec18578c491b974932c082c00fa399541e707172e50988186bf8a4019697711ddc5d038dfc52d00c35dfbe5e23c5969599f2e3e46e386207d289ae3968febddeb73d0ebb222c39be4df0dd37fb652120d714e89ca5f2a0fb2011be6d215b33dd74633f22f8d760e2fdc03261efec6c15eec03a5c3e3223eeba22e096f1ed5532c55f21cdc42c11a0be2348c5a8f51a7da928a027c430875ed2acd9b26b2fb02eb3e7978aaa81631856a66163740734641165486ff26910aebc92c0386065eb4f3ac0c0aed1e3617f8086c943acb3607186033919fbf3f707942a037a6be78267a45762d353789282407c24c29380e110723edc618b7f43b7daa8ab6659239a1cd23634f0cc9cedb107d2aea7461c814fc0189df0a4e0a618edb3f77bd32068a9d3eb2ca4bd7c42ce10e22c7e426cd5131989c539225510e33c7d229e06ef19725b37e99388bc28414f7e0ff94a4d81441c8d0bf25896fa74069648416d8af0d87da855135b07e89afab0c326c6dd93413cf74ec0aadd207d1119399b2dcb20a7b3e869dda978b023a45331be9abf4df960d8ad464bb90a87ab2331d38100e99f5ba902a0c7b7585c861983836a862d44987078542763b5e477999adb5444ff77923a78e5873a6a163ea12950bfdac408d5d128264cd7e450344e5d56b76ccbbf74fa9868807e9ebe38cede7101fed4a27c9369e1bc495cf6783b445031e36a0f381874e8ba380582d44086cb17d8367f3d27c295ef1c5a31d0d78c970aa5663d00d5eaffe4c3760c943f818f081d44f90922bed269f48ac66e9805312c99e0a5a6d73a51b58b413700ed7fd1d913789a44abc4d59d8c1fc7ddf56f766d2aaf048d829964bc3c79ee731287d2eb7d9a929da2daac5d154c768ee4e175e365eaad25b5e8f87e377c41e54b47c5a8520f5b0a3ba47ec115715d517925d151c3d8d58706b62c355fa57495a20d98ded53e40b2c76b7bcd22f9029db89bef5856777f600da507738c22adfd65bdc3f3918fe239ff9d1a69a0a0b46f4f08a7d7fdcefabbddb8322a01a5e87fce43a60f0f43a4d449deb182364abb7f04421785a89149f4dcdac319d11f6073ea2df53c8e76ccb55422720542367e80472c1c44fcc0b2622aef4e7a08bc4b57e3b46f4605359c0fdebc8392531ff631c1f91885105cb44941ed95c20a2784b22a3ae0b96357941ac74546298a443153ef619ec8d9aed527d1cd52c6e5fadf8be79a1771ee18d088136526201a17c2e116b8cae94cedc895fbac4b17f3588a2fd486337d2b015cf2430987848717040a3c7391a194d7e551d0d10b47bd4d77b406db5e4a0e2bdbf88928954065912bcbdb7b5e6160e80fba73dac406e99b679ab7aa26a7073037428938edc91e94f8f8f1567e42947fbe5f2469100b5ae7a24d1be2513ec66b91c308e3d16bddc1b96097ab209c6cdac64a9df7851b4b8a5ab0d4a1665c5dcc6c9d254efbd3a3a8bba4f4be0337401dd27d887f64d0e5664448f1a6dd9bd066f746461a49cb7b966e43b0ab10a163fe6464cd3d78f002021f7220ca5960c59792e938b367087a3f83682f8fffc4a6d4d13ece4eba24bcc7d6e8acf1eaa9a472e047e3949d6471376c52a11f1a25a3dc706ed532bba96195d41d774d29567ab24e2868805c104d7cb2bbcb701aed6fcdf9752ce1095dd5c1c7aa8d87a72d2b74cfb89d19a1e6c9561183914d96968b29e8e73838de09e2f7f2d1cb19ef9b54fc864d31bb42220ba7654ce133ce79139d80effbed05a66e146917a040d5d7ca8efafc3ada4dabfd111d61daca3215625666ac65f12ae7f453db8b19a493489a452e94a490a774687bbf3b7045646396a7a67c1704c00fe5e910ce4958bb271753eeccdba437d92d4010749bfaac361a0b7325f21896367ef68bec6c4670dc2ca84f0a9a5fc720b98390b6534bc128c1d64be7a36a951aae34fc616ebcbbd3b9c265a1535c526c70bc346e6266b68ffb9ec5848b7161043172374a242997df9483546b6059c61b41050500e38e0fc182437be0f07331f6b7eec4e8e3f56839b6d110723edc618b7f43b7daa8ab6659239a1cd23634f0cc9cedb107d2aea7461c81312880bb67e1c15045a61f34a7885c004521b9e8587517041945dc2b0567015dc6951296bd475901df2b1e7f724140ff2cc57dbdd1c4916269120097a70c4c935c867bd3d4feab04c3d8f6e820aca04bb271b338265b6b3bd642641f68706cd673f1f7a12bc71dc017812d2fdce9b63fb59e72ff4daae65d14c6a6e71fd2f31110723edc618b7f43b7daa8ab6659239a1cd23634f0cc9cedb107d2aea7461c85e20e821ca3f6fcb86a1e453860d32f861f70dd576110af06c6812a9b93a408d8f0b4efc51a5c0f5971c0fcfcbc4e191689232f0656ad0db560971a86a423344back_sql-2.4.so.2.10.7rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootopenldap-2.4.44-25.el7_9.src.rpmlibtool(/usr/lib64/openldap/back_sql.la)openldap-servers-sqlopenldap-servers-sql(x86-64)@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcrypto.so.10()(64bit)libdl.so.2()(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libodbc.so.2()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpthread.so.0()(64bit)libresolv.so.2()(64bit)libsasl2.so.3()(64bit)libsmime3.so()(64bit)libssl.so.10()(64bit)libssl3.so()(64bit)openldap-servers(x86-64)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)2.4.44-25.el7_93.0.4-14.6.0-14.0-15.2-14.11.3a@a @_@^ۅ@\@[{[r@[+@[+@Zľ@Z@ZqZWQZV@ZOYZ@YYYY6@X @X,X,XlWQWv[@WL+@WL+@V@V@UU@U(U3@UUn@U\w@TLTxcTto@S @R'R>RURRkR@M8#M%L[@L@LΫLwLH2LEL,@L,@L@K@K @Kg@KrKKf@KUKKK y@K>JĴJ_@J@Jv@J@J@Ju@J@JjJKOJ.NI@In@I2IIq@IFFH@H8@H@Hz@HkmHQH=I@H)G@G΋@GƢ@G@GD@GGG@GGGNGSG/G@GFl@FF%@F@F$@FFF@F@FR@F,Eّ@Et E[@E?QEE@D@D@DDP@CtC@C.CCáCqCCs6@Cs6@CJWC;@C @B=BTBBx@Bn-@Bn-@B$Y@B$Y@B$Y@AAڅ@AvA[@A+-A$@A@@6@@@@@@c@@@}'@r@h@Dw@@9@@,@@(@ @@@@?F@???\@??@?6?r?a@?L@?!?'@??>@??@?&@>@>܍>@>F>R@>]>>G@>.>@=@==z@=z@=ϛ=a@=S= =@=j@<@ - 2.4.44-25Simon Pichugin - 2.4.44-24Simon Pichugin - 2.4.44-23Matus Honek - 2.4.44-22Matus Honek - 2.4.44-21Matus Honek - 2.4.44-20Matus Honek - 2.4.44-19Matus Honek - 2.4.44-18Matus Honek - 2.4.44-17Matus Honek - 2.4.44-16Matus Honek - 2.4.44-14Matus Honek - 2.4.44-13Matus Honek - 2.4.44-12Matus Honek - 2.4.44-11Matus Honek - 2.4.44-10Matus Honek - 2.4.44-9Matus Honek - 2.4.44-8Matus Honek - 2.4.44-7Matus Honek - 2.4.44-6Matus Honek - 2.4.44-5Matus Honek - 2.4.44-4Matus Honek - 2.4.44-3Matus Honek - 2.4.44-2Matus Honek - 2.4.44-1Matus Honek - 2.4.40-13Matus Honek - 2.4.40-12Matus Honek - 2.4.40-11Matus Honek - 2.4.40-10Matúš Honěk - 2.4.40-9Matúš Honěk - 2.4.40-8Matúš Honěk - 2.4.40-7Matúš Honěk - 2.4.40-6Matúš Honěk - 2.4.40-5Matúš Honěk - 2.4.40-4Matúš Honěk - 2.4.40-3Matúš Honěk - 2.4.40-2Matúš Honěk - 2.4.40-1Jan Synáček - 2.4.39-6Jan Synáček - 2.4.39-5Jan Synáček - 2.4.39-4Jan Synáček - 2.4.39-3Jan Synáček - 2.4.39-2Jan Synáček - 2.4.39-1Daniel Mach - 2.4.35-12Jan Synáček - 2.4.35-11Daniel Mach - 2.4.35-10Jan Synáček - 2.4.35-9Jan Synáček - 2.4.35-8Jan Synáček - 2.4.35-7Jan Synáček - 2.4.35-6Jan Synáček - 2.4.35-5Jan Synáček 2.4.35-4Jan Synáček 2.4.35-3Jan Synáček 2.4.35-2Jan Synáček 2.4.35-1Jan Synáček 2.4.34-2Jan Synáček 2.4.34-1Jan Vcelak 2.4.34-1Jan Synáček 2.4.33-4Jan Vcelak 2.4.33-3Jan Vcelak 2.4.33-2Jan Vcelak 2.4.33-1Jan Vcelak 2.4.32-3Jan Vcelak 2.4.32-2Jan Vcelak 2.4.32-1Jan Vcelak 2.4.31-7Jan Vcelak 2.4.31-6Jan Vcelak 2.4.31-5Jan Vcelak 2.4.31-4Jan Vcelak 2.4.31-3Jan Vcelak 2.4.31-2Jan Vcelak 2.4.31-1Jan Vcelak 2.4.30-3Jan Synáček 2.4.30-2Jan Vcelak 2.4.30-1Jan Vcelak 2.4.29-4Jan Vcelak 2.4.29-3Jan Vcelak 2.4.29-2Jan Vcelak 2.4.29-1Jan Vcelak 2.4.28-3Fedora Release Engineering - 2.4.28-2Jan Vcelak 2.4.28-1Jan Vcelak 2.4.26-6Jan Vcelak 2.4.26-5Jan Vcelak 2.4.26-4Jan Vcelak 2.4.26-3Jan Vcelak 2.4.26-2Rex Dieter - 2.4.26-1.1Jan Vcelak 2.4.26-1Jan Vcelak 2.4.25-1Jan Vcelak 2.4.24-2Jan Vcelak 2.4.24-1Fedora Release Engineering - 2.4.23-9Jan Vcelak 2.4.23-8Jan Vcelak 2.4.23-7Jan Vcelak 2.4.23-6Jan Vcelak 2.4.23-5Jan Vcelak 2.4.23-4Jan Vcelak 2.4.23-3Jan Vcelak 2.4.23-2Jan Vcelak 2.4.23-1Jan Vcelak 2.4.22-7Jan Vcelak - 2.4.22-6Jan Zeleny - 2.4.22-5Jan Zeleny - 2.4.22-4Rich Megginson - 2.4.22-3Jan Zeleny - 2.4.22-2Jan Zeleny - 2.4.22-1Jan Zeleny - 2.4.21-6Jan Zeleny - 2.4.21-5Jan Zeleny - 2.4.21-4Jan Zeleny - 2.4.21-3Jan Zeleny - 2.4.21-2Jan Zeleny - 2.4.21-1Jan Zeleny - 2.4.19-3Jan Zeleny - 2.4.19-2Jan Zeleny - 2.4.19-1Jan Zeleny 2.4.18-4Jan Zeleny 2.4.18-3Jan Zeleny 2.4.18-2Jan Zeleny 2.4.18-1Jan Zeleny 2.4.16-7Jan Zeleny 2.4.16-6Tomas Mraz - 2.4.16-5Jan Zeleny 2.4.16-4Fedora Release Engineering - 2.4.16-2Jan Zeleny 2.4.16-1Jan Zeleny 2.4.15-4Jan Zeleny 2.4.15-3Jan Zeleny 2.4.15-2Jan Safranek 2.4.15-1Jan Safranek 2.4.14-1Tomas Mraz 2.4.12-3Caolán McNamara 2.4.12-2Jan Safranek 2.4.12-1Jan Safranek 2.4.11-3Jan Safranek 2.4.11-2Jan Safranek 2.4.11-1Jan Safranek 2.4.10-2Jan Safranek 2.4.10-1Jan Safranek 2.4.9-5Jan Safranek 2.4.9-4Jan Safranek 2.4.8-4Jan Safranek 2.4.8-3Jan Safranek 2.4.8-2Jan Safranek 2.4.8-1Jan Safranek 2.4.7-7Jan Safranek 2.4.7-6Jan Safranek 2.4.7-5Jan Safranek 2.4.7-4Jan Safranek 2.4.7-3Jan Safranek 2.4.7-2Jan Safranek 2.4.7-1Jan Safranek 2.4.6-1Jan Safranek 2.3.39-1Jan Safranek 2.3.38-4Jan Safranek 2.3.38-3Jan Safranek 2.3.38-2Jan Safranek 2.3.38-1Jan Safranek 2.3.37-3Jan Safranek 2.3.37-2Jan Safranek 2.3.37-1Jan Safranek 2.3.34-7Jan Safranek 2.3.34-6Jan Safranek 2.3.34-5Jan Safranek 2.3.34-4Jan Safranek 2.3.34-3Jan Safranek 2.3.34-2Jay Fenlason 2.3.34-1Thomas Woerner 2.3.30-1.1Jay Fenlason 2.3.30-1Jay Fenlason 2.3.28-1Jesse Keating - 2.3.27-4Jay Fenlason 2.3.27-3Jay Fenlason 2.3.27-2Jesse Keating - 2.3.24-2.1Jay Fenlason 2.3.24-2Jay Fenlason 2.3.21-2Jay Fenlason 2.3.19-4Jesse Keating - 2.3.19-3.1Jay Fenlason 2.3.19-3Jesse Keating - 2.3.19-2.1Jay Fenlason 2.3.19-2Jesse Keating Jay Fenlason 2.3.11-3Jay Fenlason 2.3.11-2Tomas Mraz 2.2.29-3Jay Fenlason 2.2.29-2Jay Fenlason 2.2.28-2Jay Fenlason 2.2.26-2Jay Fenlason Nalin Dahyabhai Nalin Dahyabhai 2.2.26-1Nalin Dahyabhai Nalin Dahyabhai 2.2.25-1Nalin Dahyabhai 2.2.24-1Nalin Dahyabhai 2.2.23-4Nalin Dahyabhai 2.2.23-3Tomas Mraz 2.2.23-2Nalin Dahyabhai 2.2.23-1Nalin Dahyabhai 2.2.20-1Nalin Dahyabhai 2.2.17-0Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai 2.2.13-2Nalin Dahyabhai Nalin Dahyabhai 2.2.13-1Nalin Dahyabhai 2.2.13-0Nalin Dahyabhai 2.1.30-1Elliot Lee Nalin Dahyabhai 2.1.30-0Thomas Woerner 2.1.29-3Nalin Dahyabhai 2.1.29-2Nalin Dahyabhai 2.1.29-1Nalin Dahyabhai 2.1.29-0Nalin Dahyabhai Elliot Lee 2.1.25-5.1Tim Waugh 2.1.25-5Elliot Lee Nalin Dahyabhai 2.1.25-4Nalin Dahyabhai 2.1.25-3Nalin Dahyabhai 2.1.25-2Nalin Dahyabhai Nalin Dahyabhai 2.1.25-1Nalin Dahyabhai Nalin Dahyabhai Jeff Johnson 2.1.22-9Nalin Dahyabhai 2.1.22-8Nalin Dahyabhai 2.1.22-7Nalin Dahyabhai Jeff Johnson 2.1.22-6.1Nalin Dahyabhai 2.1.22-6Nalin Dahyabhai Nalin Dahyabhai 2.1.22-5Nalin Dahyabhai 2.1.22-4Nalin Dahyabhai 2.1.22-3Nalin Dahyabhai 2.1.22-2Nalin Dahyabhai 2.1.22-1Nalin Dahyabhai 2.1.22-0Nalin Dahyabhai Elliot Lee Nalin Dahyabhai 2.1.21-1Nalin Dahyabhai 2.1.20-1Nalin Dahyabhai 2.1.19-1Nalin Dahyabhai 2.1.17-1Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai 2.0.27-8Tim Powers Nalin Dahyabhai 2.0.27-6Nalin Dahyabhai 2.0.27-5Nalin Dahyabhai 2.0.27-4Nalin Dahyabhai 2.0.27-3Nalin Dahyabhai Nalin Dahyabhai 2.0.27-2Nalin Dahyabhai Nalin Dahyabhai 2.0.27-1Nalin Dahyabhai 2.0.26-1Nalin Dahyabhai 2.0.25-2Nalin Dahyabhai 2.0.25-1Nalin Dahyabhai 2.0.23-5Nalin Dahyabhai 2.0.23-3Nalin Dahyabhai 2.0.23-2Nalin Dahyabhai Nalin Dahyabhai 2.0.23-1Nalin Dahyabhai 2.0.22-2Nalin Dahyabhai 2.0.22-1Florian La Roche 2.0.21-5Nalin Dahyabhai 2.0.21-4Nalin Dahyabhai 2.0.21-3Nalin Dahyabhai 2.0.21-2Nalin Dahyabhai 2.0.20-2Nalin Dahyabhai Nalin Dahyabhai 2.0.20-0.7Nalin Dahyabhai 2.0.20-1Nalin Dahyabhai 2.0.19-1Nalin Dahyabhai 2.0.18-2Nalin Dahyabhai 2.0.18-1Nalin Dahyabhai 2.0.17-1Nalin Dahyabhai Nalin Dahyabhai 2.0.15-2Nalin Dahyabhai 2.0.15-1Nalin Dahyabhai 2.0.14-1Nalin Dahyabhai 2.0.12-1Nalin Dahyabhai 2.0.11-13Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Than Ngo 2.0.11-6Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Prospector Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Bill Nottingham Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Bill Nottingham Nalin Dahyabhai Nalin Dahyabhai Nalin Dahyabhai Bill Nottingham Bill Nottingham Jeff Johnson Cristian Gafton Bill Nottingham Cristian Gafton Cristian Gafton Preston Brown Bill Nottingham Preston Brown - Fix CVE-2020-25709 openldap: assertion failure in Certificate List syntax validation (#2040539) - Fix CVE-2020-25710 openldap: assertion failure in CSN normalization with invalid input (#2040538)- CLDAP ldap_result hangs if nobody listens on the port (#1989919)- Fix CVE-2020-25692 openldap: NULL pointer dereference for unauthenticated packet in slapd (#1895328)- Fix CVE-2020-12243 openldap: denial of service via nested boolean expressions in LDAP search filters (#1838405)- MozNSS Compat. Layer: Protect /tmp/openldap-tlsmc-* files (#1590184)- Backport upstream fixes for ITS 7595 - add OpenSSL EC support (#1584922)- Backport upstream fixes for ITS 7506 - fix OpenSSL DH params usage (#1584922)- MozNSS Compat. Layer: Make log messages more clear (#1543955) - Build with LDAP_USE_NON_BLOCKING_TLS (#1471039)- MozNSS Compat. Layer: Fix memleaks reported by valgrind (#1575549) - Reset OPTIND in libexec/functions for getopts to work in subsequent calls (#1564382) - MozNSS Compat. Layer: Fix typos, and spelling in the README file header (#1543451)- fix: back-ldap StartTLS short connection timeout with high latency connections (#1540336)- MozNSS Compat. Layer: Enforce fail when cannot extract CA certs (#1547922)- MozNSS Compat. Layer: fix recursive directory deletion (#1516409) - MozNSS Compat. Layer: fix PIN disclaimer not always shown (#1516409) - MozNSS Compat. Layer: fix incorrect parsing of CACertDir (#1533955)- MozNSS Compat. Layer: Ensure consistency of a PEM dir before usage (#1516409) + Warn just before use of a PIN about key file extraction- MozNSS Compat. Layer: Enable usage of NSS DB with PEM cert/key (#1525485) + Fix a possible invalid dereference (covscan)- Drop update-ppolicy-schema.sh scriptlet's output (#1487857) - Fix issues in MozNSS compatibility layer (#1400578) + Force write file with fsync to avoid race conditions + Always filestamp both sql and dbm NSS DB variants to not rely on default DB type prefix + Allow missing cert and key which is a valid usecase + Create extraction folder only in /tmp to simplify selinux rules + Fix Covscan issues- Build with OpenSSL and MozNSS compatibility layer instead of MozNSS (#1400578)- fix: Upgrading to OpenLDAP >= 2.4.43 breaks server due to ppolicy changes (#1487857)- fix: Manpage incorrectly states ./ldaprc config file is used (#1498841)- fix: Upgrading openldap-servers does not restart slapd when rebasing (#1479309)- fix CVE-2017-9287 openldap: Double free vulnerability in servers/slapd/back-mdb/search.c (#1458210)- NSS: Include some CHACHA20POLY1305 ciphers (#1432907)- NSS: re-register NSS_Shutdown callback (#1405354)- Include MDB tools in openldap-servers (#1428740)- Rebase to openldap-2.4.44 (#1386365)- fix: Bad log levels in check_password module - fix: We can't search expected entries from LDAP server - fix: OpenLDAP ciphersuite parsing doesn't match OpenSSL ciphers man page + Add TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 to list of ciphers + Add DH cipher string parsing option + Correct handling kECDH ciphers with aRSA or aECDSA- fix: slapd crash in do_search (#1316450) - fix: Setting olcTLSProtocolMin does not change supported protocols (#1249093)- fix: correct inconsistent slapd.d directory permissions (#1255433)- fix: slapd fails to start on boot (#1315958) - fix: id_query option is not available after rebasing openldap to 2.4.39 (#1311832) - Include sha2 module (#1292568) - Compile AllOp together with other overlays (#990893) - Missing mutex unlock in accesslog overlay (#1261003) - ITS#8337 fix missing olcDbChecksum config attr (#1292590) - ITS#8003 fix off-by-one in LDIF length (#1292619)- fix: nslcd segfaults due to incorrect mutex initialization (#1294385)- NSS does not support string ordering (#1231522) - implement and correct order of parsing attributes (#1231522) - add multi_mask and multi_strength to correctly handle sets of attributes (#1231522) - add new cipher suites and correct AES-GCM attributes (#1245279) - correct DEFAULT ciphers handling to exclude eNULL cipher suites (#1245279)- Merge two MozNSS cipher suite definition patches into one. (#1245279) - Use what NSS considers default for DEFAULT cipher string. (#1245279) - Remove unnecesary defaults from ciphers' definitions (#1245279)- fix: OpenLDAP shared library destructor triggers memory leaks in NSPR (#1249977)- enhancement: support TLS 1.1 and later (#1231522,#1160467) - fix: openldap ciphersuite parsing code handles masks incorrectly (#1231522) - fix the patch in commit da1b5c (fix: OpenLDAP crash in NSS shutdown handling) (#1231228)- fix: rpm -V complains (#1230263) -- make the previous fix do what was intended- fix: rpm -V complains (#1230263)- fix: missing frontend database indexing (#1226600)- new upstream release (#1147982) - fix: PIE and RELRO check (#1092562) - fix: slaptest doesn't convert perlModuleConfig lines (#1184585) - fix: OpenLDAP crash in NSS shutdown handling (#1158005) - fix: slapd.service may fail to start if binding to NIC ip (#1198781) - fix: deadlock during SSL_ForceHandshake when getting connection to replica (#1125152) - improve check_password (#1174723, #1196243) - provide an unversioned symlink to check_password.so.1.1 (#1174634) - add findutils to requires (#1209229)- refix: slapd.ldif olcFrontend missing important/required objectclass (#1132094)- add documentation reference to service file (#1087288) - fix: tls_reqcert try has bad behavior (#1027613)- support TLS 1.1 and later (#1160468) - fix: /etc/openldap/certs directory is empty after installation (#1064251) - fix: Typo in script to generate /usr/libexec/openldap/generate-server-cert.sh (#1087490) - fix: remove correct tmp file when generating server cert (#1103101) - fix: slapd.ldif olcFrontend missing important/required objectclass (#1132094)- move tmpfiles config to correct location (#1069513)- CVE-2013-4449: segfault on certain queries with rwm overlay (#1061405)- new upstream release (#1040324)- Mass rebuild 2014-01-24- fix: missing EOL at the end of default /etc/openldap/ldap.conf (#1053005)- Mass rebuild 2013-12-27- fix: more typos in manpages (#948562)- fix: slaptest incorrectly handles 'include' directives containing a custom file (#1023415)- fix: CLDAP is broken for IPv6 (#1007421)- fix: typos in manpages (#948562)- fix: using slaptest to convert slapd.conf to LDIF format ignores "loglevel 0"- do not needlessly run ldconfig after installing openldap-devel - fix: LDAPI with GSSAPI does not work if SASL_NOCANON=on (#960222) - fix: lt_dlopen() with back_perl (#960048)- fix: minor documentation fixes - set SASL_NOCANON to on by default (#949864) - remove trailing spaces- drop the evolution patch- new upstream release (#947235) - fix: slapd.service should ensure that network is up before starting (#946921) - fix: NSS related resource leak (#929357)- fix: syncrepl push DELETE operation does not recover (#920482) - run autoreconf every build, drop autoreconf patch (#926280)- enable perl backend (#820547) - package ppolicy-check-password (#829749) - add perl specific BuildRequires - fix bogus dates- new upstream release (#917603) - fix: slapcat segfaults if cn=config.ldif not present (#872784) - use systemd-rpm macros in spec file (#850247)- rebuild against new cyrus-sasl- fix update: libldap does not load PEM certificate if certdb is used as TLS_CACERTDIR (#857455)- fix: slapd with rwm overlay segfault following ldapmodify (#865685)- new upstream release: + slapd: ACLs, syncrepl + backends: locking and memory management in MDB + manpages: slapo-refint - patch update: MozNSS certificate database in SQL format cannot be used (#860317) - fix: slapd.service should not use /tmp (#859019)- fix: some TLS ciphers cannot be enabled (#852338) - fix: connection hangs after fallback to second server when certificate hostname verification fails (#852476) - fix: not all certificates in OpenSSL compatible CA certificate directory format are loaded (#852786) - fix: MozNSS certificate database in SQL format cannot be used (#857373) - fix: libldap does not load PEM certificate if certdb is used as TLS_CACERTDIR (#857455)- enhancement: TLS, prefer private keys from authenticated slots - enhancement: TLS, allow certificate specification including token name - resolve TLS failures in replication in 389 Directory Server- new upstream release + library: double free, SASL handling + tools: read SASL_NOCANON from config file + slapd: config index renumbering, duplicate error response + backends: various fixes in mdb, bdb/hdb, ldap + accesslog, syncprov: fix memory leaks in with replication + sha2: portability, thread safety, support SSHA256,384,512 + documentation fixes- fix: slapd refuses to set up TLS with self-signed PEM certificate (#842022)- multilib fix: move libslapi from openldap-servers to openldap package- fix: querying for IPv6 DNS records when IPv6 is disabled on the host (#835013) - fix: smbk5pwd module computes invalid LM hashes (#841560)- modify the package build process + fix autoconfig files to detect Mozilla NSS library using pkg-config + remove compiler flags which are not needed currently + build server, client and library together + avoid stray dependencies by using --as-needed linker flag + enable SLAPI interface in slapd- update fix: count constraint broken when using multiple modifications (#795766) - fix: invalid order of TLS shutdown operations (#808464) - fix: TLS error messages overwriting in tlsm_verify_cert() (#810462) - fix: reading pin from file can make all TLS connections hang (#829317) - CVE-2012-2668: cipher suite selection by name can be ignored (#825875) - fix: slapd fails to start on reboot (#829272) - fix: default cipher suite is always selected (#828790) - fix: less influence between individual TLS contexts: - replication with TLS does not work (#795763) - possibly others- fix: nss-tools package is required by the base package, not the server subpackage - fix: MozNSS CA certdir does not work together with PEM CA cert file (#819536)- new upstream release + library: IPv6 url detection + library: rebinding to failed connections + server: various fixes in mdb backend + server: various fixes in replication + server: various fixes in overlays and minor backends + documentation fixes - remove patches which were merged upstream- rebuild due to libdb rebase- fix: Re-binding to a failed connection can segfault (#784989)- new upstream release + server: fixes in mdb backend + server: fixes in manual pages + server: fixes in syncprov, syncrepl, and pcache - removed patches which were merged upstream- fix: missing options in manual pages of client tools (#796232) - fix: SASL_NOCANON option missing in ldap.conf manual page (#732915)- fix: ldap_result does not succeed for sssd (#771484) - Jan Synáček : + fix: count constraint broken when using multiple modifications (#795766)- fix update: provide ldif2ldbm, not ldib2ldbm (#437104) - Jan Synáček : + unify systemctl binary paths throughout the specfile and make them usrmove compliant + make path to chkconfig binary usrmove compliant- new upstream release + MozNSS fixes + connection handling fixes + server: buxfixes in mdb backend + server: buxfixes in overlays (syncrepl, meta, monitor, perl, sql, dds, rwm) - openldap-servers now provide ldib2ldbm (#437104) - certificates management improvements + create empty Mozilla NSS certificate database during installation + enable builtin Root CA in generated database (#789088) + generate server certificate using Mozilla NSS tools instead of OpenSSL tools + fix: correct path to check-config.sh in service file (Jan Synáček ) - temporarily disable certificates checking in check-config.sh script - fix: check-config.sh get stuck when executing command as a ldap user- fix: replication (syncrepl) with TLS causes segfault (#783431) - fix: slapd segfaults when PEM certificate is used and key is not set (#772890)- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- new upstream release + server: support for delta-syncrepl in multi master replication + server: add experimental backend - MDB + server: dynamic configuration for passwd, perl, shell, sock, and sql backends + server: support passwords in APR1 + library: support for Wahl (draft) + a lot of bugfixes - remove patches which were merged upstream - compile backends as modules (except BDB, HDB, and monitor) - reload systemd daemon after installation- package cleanup: + hardened build: switch from LDFLAGS to RPM macros + remove old provides and obsoletes + add new slapd maintainance scripts + drop defattr macros, clean up permissions in specfile + fix rpmlint warnings: macros in comments/changelog + fix rpmlint warnings: non UTF-8 documentation + rename environment file to be more consistent (ldap -> slapd) - replace sysv initscript with systemd service file (# - new format of environment file due to switch to systemd (automatic conversion is performed) - patch OpenLDAP to skip empty command line arguments (arguments expansion in systemd works different than in shell) - CVE-2011-4079: one-byte buffer overflow in slapd (#749324)- rebuild: openldap does not work after libdb rebase (#743824) - regression fix: openldap built without tcp_wrappers (#743213)- new feature update: honor priority/weight with ldap_domain2hostlist (#733078)- fix: SSL_ForceHandshake function is not thread safe (#701678) - fix: allow unsetting of tls_* syncrepl options (#734187)- security hardening: library needs partial RELRO support added (#733071) - fix: NSS_Init* functions are not thread safe (#731112) - fix: incorrect behavior of allow/try options of VerifyCert and TLS_REQCERT (#725819) - fix: memleak - free the return of tlsm_find_and_verify_cert_key (#725818) - fix: conversion of constraint overlay settings to cn=config is incorrect (#733067) - fix: DDS overlay tolerance parametr doesn't function and breakes default TTL (#733069) - manpage fix: errors in manual page slapo-unique (#733070) - fix: matching wildcard hostnames in certificate Subject field does not work (#733073) - new feature: honor priority/weight with ldap_domain2hostlist (#733078) - manpage fix: wrong ldap_sync_destroy() prototype in ldap_sync(3) manpage (#717722)- Rebuilt for rpm (#728707)- rebase to new upstream release - fix: memleak in tlsm_auth_cert_handler (#717730)- rebase to new upstream release - change default database type from BDB to HDB - enable ldapi:/// interface by default - set cn=config management ACLs for root user, SASL external schema (#712495) - fix: server scriptlets require initscripts package (#716857) - fix: connection fails if TLS_CACERTDIR doesn't exist but TLS_REQCERT is set to 'never' (#716854) - fix: segmentation fault caused by double-free in ldapexop (#699683) - fix: segmentation fault of client tool when input line in LDIF file is splitted but indented incorrectly (#716855) - fix: segmentation fault of client tool when LDIF input file is not terminated by a new line character (#716858)- new: system resource limiting for slapd using ulimit - fix update: openldap can't use TLS after a fork() (#636956) - fix: possible null pointer dereference in NSS implementation - fix: openldap-servers upgrade hangs or do not upgrade the database (#664433)- rebase to 2.4.24 - BDB backend switch from DB4 to DB5- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- fix update: openldap can't use TLS after a fork() (#636956)- fix: openldap can't use TLS after a fork() (#636956) - fix: openldap-server upgrade gets stuck when the database is damaged (#664433)- fix: some server certificates refused with inadequate type error (#668899) - fix: default encryption strength dropped in switch to using NSS (#669446) - systemd compatibility: add configuration file (#656647, #668223)- initscript: slaptest with '-u' to skip database opening (#667768) - removed slurpd options from sysconfig/ldap - fix: verification of self issued certificates (#657984)- Mozilla NSS - implement full non-blocking semantics ldapsearch -Z hangs server if starttls fails (#652822) - updated list of all overlays in slapd.conf (#655899) - fix database upgrade process (#656257)- add support for multiple prefixed Mozilla NSS database files in TLS_CACERTDIR - reject non-file keyfiles in TLS_CACERTDIR (#652315) - TLS_CACERTDIR precedence over TLS_CACERT (#652304) - accept only files in hash.0 format in TLS_CACERTDIR (#650288) - improve SSL/TLS trace messages (#652818)- fix possible infinite loop when checking permissions of TLS files (#641946) - removed outdated autofs.schema (#643045) - removed outdated README.upgrade - removed relics of migrationtools- rebase to 2.4.23 - embeded db4 library removed - removed bogus links in "SEE ALSO" in several man-pages (#624616)- Mozilla NSS - delay token auth until needed (#616552) - Mozilla NSS - support use of self signed CA certs as server certs (#614545)- CVE-2010-0211 openldap: modrdn processing uninitialized pointer free (#605448) - CVE-2010-0212 openldap: modrdn processing IA5StringNormalize NULL pointer dereference (#605452) - obsolete configuration file moved to /usr/share/openldap-servers (#612602)- another shot at previous fix- fixed issue with owner of /usr/lib/ldap/__db.* (#609523)- added ldif.h to the public api in the devel package - added -lldif to the public api - added HAVE_MOZNSS and other flags to use Mozilla NSS for crypto- rebuild with connectionless support (#587722) - updated autofs schema (#584808)- rebased to 2.4.22 (mostly bugfixes, added back-ldif, back-null testing support) - due to some possible issues pointed out in last update testing phase, I'm pulling back the last change (slapd can't be moved since it depends on /usr possibly mounted from network)- moved slapd to start earlier during boot sequence- minor corrections of init script (#571235, #570057, #573804)- fixed SIGSEGV when deleting data using hdb (#562227)- fixed broken link /usr/sbin/slapschema (#559873)- removed some static libraries from openldap-devel (#556090)- rebased openldap to 2.4.21 - rebased bdb to 4.8.26- minor corrections in init script- fixed tls connection accepting when TLSVerifyClient = allow - /etc/openldap/ldap.conf removed from files owned by openldap-servers - minor changes in spec file to supress warnings - some changes in init script, so it would be possible to use it when using old configuration style- rebased openldap to 2.4.19 - rebased bdb to 4.8.24- updated smbk5pwd patch to be linked with libldap (#526500) - the last buffer overflow patch replaced with the one from upstream - added /etc/openldap/slapd.d and /etc/openldap/slapd.conf.bak to files owned by openldap-servers- cleanup of previous patch fixing buffer overflow- changed configuration approach. Instead od slapd.conf slapd is using slapd.d directory now - fix of some issues caused by renaming of init script - fix of buffer overflow issue in ldif.c pointed out by new glibc- rebase of openldap to 2.4.18- updated documentation (hashing the cacert dir)- updated init script to be LSB-compliant (#523434) - init script renamed to slapd- rebuilt with new openssl- updated %pre script to correctly install openldap group- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- rebase of openldap to 2.4.16 - fixed minor issue in spec file (output looking interactive when installing servers)- added $SLAPD_URLS variable to init script (#504504)- extended previous patch (#481310) to remove options cfMP from some client tools - correction of patch setugid (#494330)- removed -f option from some client tools (#481310)- new upstream release- new upstream release - upgraded to db-4.7.25- rebuild with new openssl- rebuild for libltdl, i.e. copy config.sub|guess from new location- new upstream release- add SLAPD_SHUTDOWN_TIMEOUT to /etc/sysconfig/ldap, allowing admins to set non-default slapd shutdown timeout - add checkpoint to default slapd.conf file (#458679)- provide ldif2ldbm functionality for migrationtools - rediff all patches to get rid of patch fuzz- new upstream release - apply official bdb-4.6.21 patches- fix CVE-2008-2952 (#453728)- new upstream release- use /sbin/nologin as shell of ldap user (#447919)- new upstream release - removed unnecessary MigrationTools patches- bdb upgraded to 4.6.21 - reworked upgrade logic again to run db_upgrade when bdb version changes- reworked the upgrade logic, slapcat/slapadd of the whole database is needed only if minor version changes (2.3.x -> 2.4.y) - do not try to save database in LDIF format, if openldap-servers package is being removed (it's up to the admin to do so manually)- migration tools carved out to standalone package "migrationtools" (#236697)- new upstream release- fix CVE-2008-0658 (#432014)- init script fixes- init script made LSB-compliant (#247012)- fixed rpmlint warnings and errors - /etc/openldap/schema/README moved to /usr/share/doc/openldap- obsoleting compat-openldap properly again :)- obsoleting compat-openldap properly (#429591)- new upstream version (openldap-2.4.7)- new upstream version (openldap-2.4) - deprecating compat- package- new upstream release- fixed multilib issues - all platform independent files have the same content now (#342791)- BDB downgraded back to 4.4.20 because 4.6.18 is not supported by openldap (#314821)- skeleton /etc/sysconfig/ldap added - new SLAPD_LDAP option to turn off listening on ldap:/// (#292591) - fixed checking of SSL (#292611) - fixed upgrade with empty database- new upstream version - added images to the guide.html (#273581)- just rebuild- do not use specific automake and autoconf - do not distinguish between NPTL and non-NPTL platforms, we have NPTL everywhere - db-4.6.18 integrated - updated openldap-servers License: field to reference BDB license- new upstream version- MigrationTools-47 integrated- fix compat-slapcat compilation. Now it can be found in /usr/lib/compat-openldap/slapcat, because the tool checks argv[0] (#246581)- smbk5pwd added (#220895) - correctly distribute modules between servers and servers-sql packages- Fix initscript return codes (#242667) - Provide overlays (as modules; #246036, #245896) - Add available modules to config file- do not create script in /tmp on startup (bz#188298) - add compat-slapcat to openldap-compat (bz#179378) - do not import ddp services with migrate_services.pl (bz#201183) - sort the hosts by adders, preventing duplicities in migrate*nis*.pl (bz#201540) - start slupd for each replicated database (bz#210155) - add ldconfig to devel post/postun (bz#240253) - include misc.schema in default slapd.conf (bz#147805)- slapadd during package update is now quiet (bz#224581) - use _localstatedir instead of var/ during build (bz#220970) - bind-libbind-devel removed from BuildRequires (bz#216851) - slaptest is now quiet during service ldap start, if there is no error/warning (bz#143697) - libldap_r.so now links with pthread (bz#198226) - do not strip binaries to produce correct .debuginfo packages (bz#152516)- New upstream release - Upgrade the scripts for migrating the database so that they might actually work. - change bind-libbind-devel to bind-devel in BuildPreReq- tcp_wrappers has a new devel and libs sub package, therefore changing build requirement for tcp_wrappers to tcp_wrappers-devel- New upstream version- New upstream version- rebuilt for unwind info generation, broken in gcc-4.1.1-21- Include --enable-multimaster to close bz#185821: adding slapd_multimaster to the configure options - Upgade guide.html to the correct one for openladp-2.3.27, closing bz#190383: openldap 2.3 packages contain the administrator's guide for 2.2 - Remove the quotes from around the slaptestflags in ldap.init This closes one part of bz#204593: service ldap fails after having added entries to ldap - include __db.* in the list of files to check ownership of in ldap.init, as suggested in bz#199322: RFE: perform cleanup in ldap.init- New upstream release - Include the gethostbyname_r patch so that nss_ldap won't hang on recursive attemts to ldap_initialize.- rebuild- New upstream version- Upgrade to 2.3.21 - Add two upstream patches for db-4.4.20- Re-fix ldap.init- bump again for double-long bug on ppc(64)- Modify the ldap.init script to call runuser correctly.- rebuilt for new gcc4.1 snapshot and glibc changes- Upgrade to 2.3.19, which upstream now considers stable - Modify the -config.patch, ldap.init, and this spec file to put the pid file and args file in an ldap-owned openldap subdirectory under /var/run. - Move back_sql* out of _sbindir/openldap , which requires hand-moving slapd and slurpd to _sbindir, and recreating symlinks by hand. - Retire openldap-2.3.11-ads.patch, which went upstream. - Update the ldap.init script to run slaptest as the ldap user rather than as root. This solves bz#150172 Startup failure after database problem - Add to the servers post and preun scriptlets so that on preun, the database is slapcatted to /var/lib/ldap/upgrade.ldif and the database files are saved to /var/lib/ldap/rpmorig. On post, if /var/lib/ldap/upgrade.ldif exists, it is slapadded. This means that on upgrades from 2.3.16-2 to higher versions, the database files may be automatically upgraded. Unfortunatly, because of the changes to the preun scriptlet, users have to do the slapcat, etc by hand when upgrading to 2.3.16-2. Also note that the /var/lib/ldap/rpmorig files need to be removed by hand because automatically removing your emergency fallback files is a bad idea. - Upgrade internal bdb to db-4.4.20. For a clean upgrade, this will require that users slapcat their databases into a temp file, move /var/lib/ldap someplace safe, upgrade the openldap rpms, then slapadd the temp file.- rebuilt- Remove Requires: cyrus-sasl and cyrus-sasl-md5 from openldap- and compat-openldap- to close bz#173313 Remove exlicit 'Requires: cyrus-sasl" + 'Requires: cyrus-sasl-md5'- Upgrade to 2.3.11, which upstream now considers stable. - Switch compat-openldap to 2.2.29 - remove references to nss_ldap_build from the spec file - remove references to 2.0 and 2.1 from the spec file. - reorganize the build() function slightly in the spec file to limit the number of redundant and conflicting options passedto configure. - Remove the attempt to hardlink ldapmodify and ldapadd together, since the current make install make ldapadd a symlink to ldapmodify. - Include the -ads patches to allow SASL binds to an Active Directory server to work. Nalin wrote the patch, based on my broken first attempt.- rebuilt against new openssl- New upstream version.- Upgrade to nev upstream version. This makes the 2.2.*-hop patch obsolete.- Move the slapd.pem file to /etc/pki/tls/certs and edit the -config patch to match to close bz#143393 Creates certificates + keys at an insecure/bad place - also use _sysconfdir instead of hard-coding /etc- Add the tls-fix-connection-test patch to close bz#161991 openldap password disclosure issue - add the hop patches to prevent infinite looping when chasing referrals. OpenLDAP ITS #3578- fix typo in ldap.init (call $klist instead of klist, from Charles Lopes)- run slaptest with the -u flag if no id2entry db files are found, because you can't check for read-write access to a non-existent database (#156787) - add _sysconfdir/openldap/cacerts, which authconfig sets as the TLS_CACERTDIR path in /etc/openldap/ldap.conf now - use a temporary wrapper script to launch slapd, in case we have arguments with embedded whitespace (#158111)- update to 2.2.26 (stable 20050429) - enable the lmpasswd scheme - print a warning if slaptest fails, slaptest -u succeeds, and one of the directories listed as the storage location for a given suffix in slapd.conf contains a readable file named __db.001 (#118678)- update to 2.2.25 (release)- update to 2.2.24 (stable 20050318) - export KRB5_KTNAME in the init script, in case it was set in the sysconfig file but not exported- prefer libresolv to libbind- add bind-libbind-devel and libtool-ltdl-devel buildprereqs- rebuild with openssl-0.9.7e- update to 2.2.23 (stable-20050125) - update notes on upgrading from earlier versions - drop slapcat variations for 2.0/2.1, which choke on 2.2's config files- update to 2.2.20 (stable-20050103) - warn about unreadable krb5 keytab files containing "ldap" keys - warn about unreadable TLS-related files - own a ref to subdirectories which we create under _libdir/tls- rebuild- update to 2.2.17 (stable-20040923) (#135188) - move nptl libraries into arch-specific subdirectories on x86 boxes - require a newer glibc which can provide nptl libpthread on i486/i586- move slapd startup to earlier in the boot sequence (#103160) - update to 2.2.15 (stable-20040822) - change version number on compat-openldap to include the non-compat version from which it's compiled, otherwise would have to start 2.2.15 at release 3 so that it upgrades correctly- build a separate, static set of libraries for openldap-devel with the non-standard ntlm bind patch applied, for use by the evolution-connector package (#125579), and installing them under evolution_connector_prefix) - provide openldap-evolution-devel = version-release in openldap-devel so that evolution-connector's source package can require a version of openldap-devel which provides what it wants- update administrator guide- add compat-openldap subpackage - default to bdb, as upstream does, gambling that we're only going to be on systems with nptl now- preliminary 2.2.13 update - move ucdata to the -servers subpackage where it belongs- build experimental sql backend as a loadable module- rebuilt- update to 2.1.30- removed rpath - added pie patch: slapd and slurpd are now pie - requires libtool >= 1.5.6-2 (PIC libltdl.a)- move rfc documentation from main to -devel (#121025)- rebuild- update to 2.1.29 (stable 20040329)- don't build servers with --with-kpasswd, that option hasn't been recognized since 2.1.23- rebuilt- Use ':' instead of '.' as separator for chown.- rebuilt- remove 'reload' from the init script -- it never worked as intended (#115310)- commit that last fix correctly this time- fix incorrect use of find when attempting to detect a common permissions error in the init script (#114866)- add bug fix patch for DB 4.2.52- change logging facility used from daemon to local4 (#112730, reversing #11047) BEHAVIOR CHANGE - SHOULD BE MENTIONED IN THE RELEASE NOTES.- incorporate fix for logic quasi-bug in slapd's SASL auxprop code (Dave Jones)- update to 2.1.25, now marked STABLE- update to db-4.2.52.- add another section to the ABI note for the TLS libdb so that it's marked as not needing an executable stack (from Arjan Van de Ven)- force bundled libdb to not use O_DIRECT by making it forget that we have it- build bundled libdb for slapd dynamically to make the package smaller, among other things - on tls-capable arches, build libdb both with and without shared posix mutexes, otherwise just without - disable posix mutexes unconditionally for db 4.0, which shouldn't need them for the migration cases where it's used - update to MigrationTools 45- upgrade db-4.1.25 to db-4.2.42.- drop rfc822-MailMember.schema, merged into upstream misc.schema at some point- actually require newer libtool, as was intended back in 2.1.22-0, noted as missed by Jim Richardson- enable rlookups, they don't cost anything unless also enabled in slapd's configuration file- rebuild- rebuild- rebuild- build- 2.1.22 now badged stable - be more aggressive in what we index by default - use/require libtool 1.5- update to 2.1.22- rebuilt- update to 2.1.21 - enable ldap, meta, monitor, null, rewrite in slapd- update to 2.1.20- update to 2.1.19- switch to db with crypto- install the db utils for the bundled libdb as %{_sbindir}/slapd_db_* - install slapcat/slapadd from 2.0.x for migration purposes- update to 2.1.17 - disable the shell backend, not expected to work well with threads - drop the kerberosSecurityObject schema, the krbName attribute it contains is only used if slapd is built with v2 kbind support- back down to db 4.0.x, which 2.0.x can compile with in ldbm-over-db setups - tweak SuSE patch to fix a few copy-paste errors and a NULL dereference- rebuilt- rebuild- rebuild- check for setgid as well- rebuild- incorporate fixes from SuSE's security audit, except for fixes to ITS 1963, 1936, 2007, 2009, which were included in 2.0.26. - add two more patches for db 4.1.24 from sleepycat's updates page - use openssl pkgconfig data, if any is available- add patches for db 4.1.24 from sleepycat's updates page- add a sample TLSCACertificateFile directive to the default slapd.conf- update to 2.0.27- update to 2.0.26, db 4.1.24.NC- change LD_FLAGS to refer to /usr/kerberos/_libdir instead of /usr/kerberos/lib, which might not be right on some arches- update to 2.0.25 "stable", ldbm-over-gdbm (putting off migration of LDBM slapd databases until we move to 2.1.x) - use %{_smp_mflags} when running make - update to MigrationTools 44 - enable dynamic module support in slapd- rebuild in new environment- use the gdbm backend again- make slapd.conf read/write by root, read by ldap- fix corner case in sendbuf fix - 2.0.23 now marked "stable"- update to 2.0.23- switch to an internalized Berkeley DB as the ldbm back-end (NOTE: this breaks access to existing on-disk directory data) - add slapcat/slapadd with gdbm for migration purposes - remove Kerberos dependency in client libs (the direct Kerberos dependency is used by the server for checking {kerberos} passwords)- update to 2.0.22- prereq chkconfig for server subpackage- update migration tools to version 40- free ride through the build system- update to 2.0.21, now earmarked as STABLE- temporarily disable optimizations for ia64 arches - specify pthreads at configure-time instead of letting configure guess- and one for Raw Hide- build for RHL 7/7.1- update to 2.0.20 (security errata)- update to 2.0.19- fix the commented-out replication example in slapd.conf- update to 2.0.18- update to 2.0.17- disable kbind support (deprecated, and I suspect unused) - configure with --with-kerberos=k5only instead of --with-kerberos=k5 - build slapd with threads- rebuild, 2.0.15 is now designated stable- update to 2.0.15- update to 2.0.14- update to 2.0.12 to pull in fixes for setting of default TLS options, among other things - update to migration tools 39 - drop tls patch, which was fixed better in this release- install saucer correctly- try to fix ldap_set_options not being able to set global options related to TLS correctly- don't attempt to create a cert at install-time, it's usually going to get the wrong CN (#51352)- add a build-time requirement on pam-devel - add a build-time requirement on a sufficiently-new libtool to link shared libraries to other shared libraries (which is needed in order for prelinking to work)- require cyrus-sasl-md5 (support for DIGEST-MD5 is required for RFC compliance) by name (follows from #43079, which split cyrus-sasl's cram-md5 and digest-md5 modules out into cyrus-sasl-md5)- enable passwd back-end (noted by Alan Sparks and Sergio Kessler)- start to prep for errata release- link libldap with liblber- add symlink liblber.so libldap.so and libldap_r.so in /usr/lib- move shared libraries to /lib - redo init script for better internationalization (#26154) - don't use ldaprc files in the current directory (#38402) (patch from hps@intermeta.de) - add BuildPrereq on tcp wrappers since we configure with --enable-wrappers (#43707) - don't overflow debug buffer in mail500 (#41751) - don't call krb5_free_creds instead of krb5_free_cred_contents any more (#43159)- make config files noreplace (#42831)- actually change the default config to use the dummy cert - update to MigrationTools 38- build dummy certificate in %post, use it in default config - configure-time shenanigans to help a confused configure script- tweak migrate_automount and friends so that they can be run from anywhere- update to 2.0.11- update to 2.0.10- update to 2.0.9- update to 2.0.8 - drop patch which came from upstream- rebuild in new environment- back out pidfile patches, which interact weirdly with Linux threads - mark non-standard schema as such by moving them to a different directory- update to MigrationTools 36, adds netgroup support- fix thinko in that last patch- try to work around some buffering problems- gettextize the init script- gettextize the init script- move the RFCs to the base package (#21701) - update to MigrationTools 34- add support for additional OPTIONS, SLAPD_OPTIONS, and SLURPD_OPTIONS in a /etc/sysconfig/ldap file (#23549)- change automount object OID from 1.3.6.1.1.1.2.9 to 1.3.6.1.1.1.2.13, per mail from the ldap-nis mailing list- force -fPIC so that shared libraries don't fall over- add Norbert Klasen's patch (via Del) to fix searches using ldaps URLs (OpenLDAP ITS #889) - add "-h ldaps:///" to server init when TLS is enabled, in order to support ldaps in addition to the regular STARTTLS (suggested by Del)- correct mismatched-dn-cn bug in migrate_automount.pl- update to the correct OIDs for automount and automountInformation - add notes on upgrading- update to 2.0.7 - drop chdir patch (went mainstream)- change automount object classes from auxiliary to structural- update to Migration Tools 27 - change the sense of the last simple patch- reorganize the patch list to separate MigrationTools and OpenLDAP patches - switch to Luke Howard's rfc822MailMember schema instead of the aliases.schema - configure slapd to run as the non-root user "ldap" (#19370) - chdir() before chroot() (we don't use chroot, though) (#19369) - disable saving of the pid file because the parent thread which saves it and the child thread which listens have different pids- add missing required attributes to conversion scripts to comply with schema - add schema for mail aliases, autofs, and kerberosSecurityObject rooted in our own OID tree to define attributes and classes migration scripts expect - tweak automounter migration script- try adding the suffix first when doing online migrations - force ldapadd to use simple authentication in migration scripts - add indexing of a few attributes to the default configuration - add commented-out section on using TLS to default configuration- update to 2.0.6 - add buildprereq on cyrus-sasl-devel, krb5-devel, openssl-devel - take the -s flag off of slapadd invocations in migration tools - add the cosine.schema to the default server config, needed by inetorgperson- add the nis.schema and inetorgperson.schema to the default server config - make ldapadd a hard link to ldapmodify because they're identical binaries- update to 2.0.4- remove prereq on /etc/init.d (#17531) - update to 2.0.3 - add saucer to the included clients- update to 2.0.1- update to 2.0.0 - patch to build against MIT Kerberos 1.1 and later instead of 1.0.x- remove that pesky default password - change "Copyright:" to "License:"- adjust permissions in files lists - move libexecdir from %{_prefix}/sbin to %{_sbindir}- add migrate_automount.pl to the migration scripts set- build a semistatic slurpd with threads, everything else without - disable reverse lookups, per email on OpenLDAP mailing lists - make sure the execute bits are set on the shared libraries- change logging facility used from local4 to daemon (#11047)- split off clients and servers to shrink down the package and remove the base package's dependency on Perl - make certain that the binaries have sane permissions- move the init script back- tweak the init script to only source /etc/sysconfig/network if it's found- automatic rebuild- switch to gdbm; I'm getting off the db merry-go-round - tweak the init script some more - add instdir to @INC in migration scripts- tweak init script to return error codes properly - change initscripts dependency to one on /etc/init.d- prereq initscripts - make migration scripts use mktemp- do condrestart in post and stop in preun - move init script to /etc/init.d- update to 1.2.11 - add condrestart logic to init script - munge migration scripts so that you don't have to be /usr/share/openldap/migration to run them - add code to create pid files in /var/run- FHS tweaks - fix for compiling with libdb2- minor tweak so it builds on ia64- more minimalistic fix for bug #11111 after consultation with OpenLDAP team - backport replacement for the ldapuser patch- fix segfaults from queries with commas in them in in.xfingerd (bug #11111)- update to 1.2.10 - add revamped version of patch from kos@bastard.net to allow execution as any non-root user - remove test suite from %build because of weirdness in the build system- move the defaults for databases and whatnot to /var/lib/ldap (bug #10714) - fix some possible string-handling problems- start earlier, stop later.- auto rebuild in new environment (release 4)- add -D_REENTRANT to make threaded stuff more stable, even though it looks like the sources define it, too - mark *.ph files in migration tools as config files- update to 1.2.9- strip files- update to 1.2.7 - fix some bugs from bugzilla (#4885, #4887, #4888, #4967) - take include files out of base package- missing ;; in init script reload) (#4734).- move stuff from /usr/libexec to /usr/sbin - relocate config dirs to /etc/openldap- initscript munging- add the migration tools to the package- upgrade to 1.2.6 - add rc.d script - split -devel package- upgrade to latest stable (1.1.4), it now uses configure macro.- build on arm, glibc2.1- initial cut. - patches for signal handling on the alpha  !"#$%&'()*+,-./0123456789:;<=>?@ABCD2.4.44-25.el7_92.4.44-25.el7_9 back_sql-2.4.so.2back_sql-2.4.so.2.10.7back_sql.laopenldap-servers-sql-2.4.44bugsconceptinstallplatformsrdbms_dependREADMEibmdb2backsql_create.sqlbacksql_drop.sqlslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqlmssqlbacksql_create.sqlbacksql_drop.sqlslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqlmysqlbacksql_create.sqlbacksql_drop.sqlslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqloraclebacksql_create.sqlbacksql_drop.sqlslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqlpgsqlbacksql_create.sqlbacksql_drop.sqlslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqltimestenbacksql_create.sqlbacksql_drop.sqlcreate_schema.shdnreverseMakefilednreverse.cppslapd.conftestdb_create.sqltestdb_data.sqltestdb_drop.sqltestdb_metadata.sqlttcreate_schema.shtttestdb_create.sqltttestdb_data.sqltttestdb_drop.sqltttestdb_metadata.sqltodo/usr/lib64/openldap//usr/share/doc//usr/share/doc/openldap-servers-sql-2.4.44//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/ibmdb2//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/mssql//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/mysql//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/oracle//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/pgsql//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/timesten//usr/share/doc/openldap-servers-sql-2.4.44/rdbms_depend/timesten/dnreverse/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ee605bd3890bb417c8d7ef1519b769fbb700031e, strippedlibtool library filedirectoryASCII textASCII text, with very long linesmakefile script, ASCII textC++ source, ASCII textRRRRRRRRRRR R RR R RRRRR RRP?7zXZ !#,)] b2u B0RŔEQEL)Hn faEDeC."+c%U^Τ*#t1s>:f[e1}jB{n2ч_w7W>u.NJD\_3[mYV$ L`?NQ2Q+SS,}yo.jz=ݘ hQg>]9\L]* !IhuP[M rn^7٥u~T%E dy'(d@"+̩KbQ-G幵d>_| x3m"@&5 L(cP6t/C~9*9\;NYcl(' T`&AQlnI]3z8*)GafWRy˒o$ ^V ;p9 6ʉ?eUrg.IAHa\k%U*=zZQ7V5]DUNwԨ>K9 P ?mϱ rهQZkA ؗə ՙAmxPTA"Ba[:5̹ƕ`g,T]IEü.X7*",AwաSh_yBS-$~#e]Q~INkOO^RxBx iNA3juB WF`eaW 㾓0e1t;7U98_m f5X^@}S[A7w!Yiw}} O8̄$zs:6 *?uϭm9SߧpO1Z#?  %0)B| #nm=p.E,Ņjڡ vOlb<NLcǀGTQlgv,c%{QXR#᬴bXW"P[k{+1J-ZwG9{xJd=RvH;ȣ-G`aD^q_#룋6-OUB-C#솾.M4$NiO>f/}Obn҂+P%oB(A򛢈Lds Ӊ1bjL9O1&ymwrKPӯ0fA)ԏPj|mg\ǩyhC/끦48o5iS+O@T\` bMZ|x_YtDvN#S re+A&f.;18{MncՈx;7e kgw Qpr`8Q\IGd<;7 `m䊉՜-0-Z'hx'#¡)O$܊;{4V;{A%y=ߧ+7HW,}_˳N:A؃/P`:8'A?zΗA{wPmD E_^Y*-L~AnEa+\qe!=wQKzܒ@x?ݻrΪf~ # +d&);tJm\BJ?~le'2hu$ds8&V~iX[c=m,@0Nܩ*q>ueS)/d!d7%s0`$RAcjY`&m[E|ZæJ6<WXykQ8h(˛e i%(`PU0Ő+)a:W+,i(GE?e.Kụ0 ժPKFbX-w}B ~ 64x}*p;Ua=X*Q124̄)t!B5)-M9imvkL5I@!ixwsdi?V pvtqO7s IF߆pC `e2a_^}.q?䠌OΞiԾ/ajZIL>q &0R8a|n@ xg-(B:2%0hR:|Fۉ||0soIo_ضG'#LRՃ3VjÛπE p?n]Y/E@og7&)yĹB_aڷVe.3wVӕ%:+8Xm##jk؟-8o0yݾj59(Җ;P;&AӹeeoJf\aX^Hyki8MX,>zL BO:}<<-Hq:ۤaϙBlPCa7i"M3!DJ'W}HcVt/PY_ 5[vt #6}wZ rkdKjl RQ?מ&pLR'zfVf){ǝֳXu6 ,OkL;CJΉ*&#@2p;v*T4--'XJ>F56ͽOt9R@ D\R`v<&\ƞullhP>(Zk#\e۟v_I{>YrvȻњ};[OzÌb Hݧk]/Or-MB`mԼ@:E|΁S͆6MƧ3%fZ *مk3a2ŭy6,l<]f|'C|L,wXG^ʮ\IJEhJ0H0kxrgd&:K+ '_4̇VSӢ0"qk,穕%:R=Vi#u2FywmrI"<(y5y ?Ē 9gFB?KHptv8 uKpWj1Ąsvwxۼ:g{;"*`a?~ Ř Sݏut5U? {j|Oaox94d_u`Ҋu0,T<6V$Oh{+]CB-ϜkSؑ {_]%DJ "?OLa?Rgg9(^7-To~Un:"1f0vT0 ?h%$Aa%!_ݳSs݇QP<EU=85͢~Rp⽊l_wP/*"JqȂDNc+2y/J^OW0B22wi}c/Y,BkCme{bb|Lqkٛ&OMdn&#cVIk/AE|ak6(n~W$k۹"Nx7d- oہ]f/3I0  `|J(aG1jS~jLLX]o11V7v)H w$`ͳvdU88T2u: KQנz6\8!溙MQg)n-=@ xVy=yBH%pga>@jV(̘.ٞfΜi prJcK ϱ&Ήlk(ܱM~Wg'Vx@ܤ1( OӄmQ :Q|p.cn`xݙ2փݷa9q~DAw;߫T]_oy‹6jB sK'*Zb-L ̄;އM KȠ9>R^MAet`T h%k6ȫ*e5zPKӯ>wufk^[~ŶX:kEQA0>qntlqND}>{o~I QY/qBEu3H h٤"ïPuQ,rBCf};t&<DgH&%x8/PWN?6ѥW7{n5vߒy0 Ӗ5 G 39D#TezǚF_h7㌋XjC7e{U /{K۝|2l2Ydy& # `4LuR@BG &lϴdF5D! z$0`a?[DEތo,&LF/*lc\ID298"BMNnd!hA]fZƥL,VcU1v_OtЁN/01>%|k>l^(KSULd~sOjۀT=3dȃGgCFoiEYCT nF~"eO!VB[ 虉(yMKp: NEx}Њ=q\4H}5dԨZpᰒ[蚨f堡?7/dS{E G($z):ÅrWSs[EoSn II#RI.N},,Ha.={`T "q;kxP}]MX+;(@y8=U~L-i'HK`n!P)T痁DsNGܺހM)3# Sm)kJ> :( c(YRIjٶy xerbѩN*;CwEB:'&S ΩY\q7?ti۾[k\~MKLC-ဓX$d9gtLO\SH>é\Kes,^aֱ’t$A/%)򰯺|SA0IYn{8|i/]LcV[0eF{`*|3KSvB5r>?qYG="i7M\ϕZUC[4 2qK>fw Bqk0GY wJ}BÔeOD` 6;H y aݭhE*I1߂="Ėig]i,ѥcjf&B8 q6kWDOBfGڮE/dz- &nO*8U2l]MɼFxVRA}hw$)5$b7(I /HjQv_(YD]6:Wȗ"˅n*,nS>O~a좱]nGZ b" ty?#636@l(Q>1AEa99`&M1E;!h=hp.zi\$},<9_l;JSt)| kcY<ӕ5L$ 7 a&.1qvluM.o @ҁN؁?&5QÂL<[Cݬ>ltQuyjڮNW\6 $y4&Eݣy$j7d62`6Q|ۖL!]yQSGsA4BNO{ڼT{B,:tH=om[\Oiȫ${}=Zr[cV3Iͽ9R,?]IJWwxQ<uDP B <v؅pv3ԙ?^Gt-;,|l17Ox` 8/े?͈PV_"F;.Nls cjq':Y۞0A%ej6ʑN~dT(#?Pz98m_kA{"Z oŶ V }jIOzeԒԥ44VC}oĥ⚔zc`m\Q޺r)Jg"`WO9<>m1LeCHTUL>dh8j:,b@y(fgZB"W@߰3e[_mL,d4$G `:<qM@ҤԞaz: K+2Kcnď˒pSn,DOx_g S :++ۘ`zl)NJ5ۯx+^Ε.is7Q_Vt%-,UĘߴQܻL N"Wߗw Sw >^U,7}'bV7 G~VW /g$LV<@n>%n1*GPG.ǨHdmu|geӀ`ARLJ]ÜYЬQ]l\mf<$l+mͳ~K<Oqc 3uD<&.' k z !$kK{Dy@6t`=FXW)EI0$u5;޹Ҁ^2?ZuPJ:)(uɈ< Wti78a+OLJ9o<[?.>Գ5j(5LO-E& s$w`pxUD( p x~6$!^ yy\+-T/e QLqߥ*UMOًz?-\*]x0Whxd[#i7]tr8r0ԕ#H'u"2)&-# gXxJw2ߍ2RuLLW­& ,1h،ejoѤ{NGgèφ1K#LHTMZK ^Ϥ;N.]%_څ` ~{u. N!`jqԽfN2c-c/BB* Ϗ&wq=E!Ns*;B'wGAſw: =g>0o~qcG4ThiqLgW- i3L֕eNgxsqi7ڍoi]Obl_~e稽X2W[l&M;"*ګ7CxB9\!Cc-BGdus(90Uڂ~{0MlWXHHi*$ *GEeeM {[iΪ1k6\*$.DլÁvb䪇Ka{jUIMh:1aTu`46Ht軩q nM;UM͜Y(Z їq>0) ojV5ˇ'20,ڢ B)62ڭwc'N5trBbΘoE{˨f"7#?w1^?8Py4iлRV{uqX.QF׏sl\/k&?%KZu7M*:叞 9RBG1l}(*LRė7#N'=*NL/7$a$Z)XѨDӫ{ X.'+7@*4EM y̶$ PtiXq:/˦(sOp ƨWeנZgߡDGl$AUAÊ=HIgk.T5|ޥS"M#xt숱3J7 a V(vX@0"`'/2q*hd&:17Y TչiS" V&'^#5Uޖ -Ua|(0iE\iw0ܒȃ7\BwDOxqlyd 82$Y}2dWVU+i&TF[#R@XW/0cŇ;`[S9 kLt>̀U+vU5;cOT;^?s*#MCOXቨZֽCV=t2c׽ ['O Z ͪ߂Qc >A$Ƥd:|潀 .7af%>΍#q׼,pLəHZۑW ݚ3`ogFS }SMfH2_H;2D)IvJ`TK}Vq _,9L3fU5M$nXA@mz;z}uZc^%c)""t/rVi#\!jJ_zyGP b\RHJqcj4]cbV_E=sxL*?+m򙯽[-y>Ծgdj=ރLܾ8GR' GY5XfG ֬iscRGAY+jȡTW6m >uwAlobj=JuI}gVxV5ikrnr`>%6؀iQݜ't *e#]`cJl;!k®z,T.ڰS.Ʌñ"r^Pjκ1Xw7ڦ{84ǩsXGR{;qO W%@iSU႖,š(af༻m\&o5ʫ].鎪1#ӓT֙3 і`!)/~|^e>:}fgT槉G p^vDD5MDY|-T`|juIcwn/^  0ܐpf[cGYp(z8Tm8t(Kqv깸|ҵ/ ^ûeWZ0Z#)ژ"ĕL(UQ.4QYkLf:Śx"3mHZ7&)?9;F %WF;JRf̓]Q9c=&<\*<^3=1 (sO~4OppX8,qWMFO10#)2K9zH ͣ,q3^V6Op 2Ô~'mlQ~[)Y+bWw@P@oUBfgBZ1|Nz5;kFrawqRSm˗$8$䚮Ɍ%~b_eO^BƥǦK!|@D谭j7B,|~X-+n*GhD+7L "h*,&Xlb)VXܳ|;P$SdDJ'q!9  ufݔÜ iD}b\kje`- >E.Wa $G\^d2?[&+/z,s<'*|-Jq< /2+A~o6Z]}!ν!u5iE~W\GA9|pHxum28J_!cgjI̓j'9U5Y`$0󽙵C  A:9+BH -tulR= rs9~9rf!;P`%^>aq(ƋHon|J9ptnfwy{N9zBSOn08rfP$(Xl~.dM"qдNẖx8M{7{A@I=18{Ic_ʰ 3,u8kG='!7u7ӬQG gG(Okcg2J3(Q\v撩g]fd,<,qDM!,kd4r%㕮Y,:D͋K(H:mZ>.qްώC a7 W߆UDcOyl -A͉Rg;p t*"N7 >>ၸgb-~+ؐ234 UE{ҟ6VTqRI*8eO`y[` ?~A(ܲ߆ y&bA @SawYfٲ,⫈!ven?S<^v+H1w54I7g8n^:S07ѻC\cEt1iwW>B5Gn22M<#ciT=Nmz}=4|-q߇_Ńmt3绺 fGBBQx y0%TwaX_[d9 7o ,jY } LV+G1xe.SޛId}.Oh>`Z*`Y7;sFVBw.nb_3aDjKf*fN.>Mw_/@v}ž9xX/w&AAx7O♽ƒ2( eHiFqOp`|ã wZM5#,U"r"gKU i;EOFre\?LO`# ocA WF2Z:@S֭]r+N2l[ok3nTrUͨ+=)32Q@4ljZQޒjx!=g&sS2>SJ5+u=*@K}.52٥t,ܯlW%t!P"+-TgVw/c6"R92H@;8 ʰy6J(3=V"UG r0߫}V=#/2S#O/{ok.[ڛn$y\'o@iso) pg瞧rKN~ttpΣ6{*w U϶…[Qo*WEeZ Z5nte }8t3H>`v[Pk/ܯ6Q#_SSɓYmԴSe1[_S9B= *jˑl.Ǚd=%w=?C+tN^o;!!X.IJ/sÝWN4xNB vu,F Ϭ3أTiM~1] NE",54#{MvGTr`>,tK}O+H$7.NUpRxn*l_@R J+M|J%$oA$-_fJ:Q%qF!jpϱdu>b 'b~ô.c<|)+h|E:?ZhrP/BS/V$ĤT"{Iw̝Lј b8S4|]E2hwڳvW=(`p[4vpZe \Eoq=(tp(i80 5{w seg*$ّŴM{:[S}mpb R%ׁ$mݱkˊe^I'PpM @[hS6GǍ4&`h˝[~ےcH7{ȏz ̳9v(! fjm3napl~s]u8%ٿ6HAəAʢuKDDvm/ͽBVR^ʇ]ޝWB9iO~I9zR!`M;=^6U獱HcY"xډ0WMa1s7|AiDz: g=+`-݈31J^- _$,g=LP֨pDنal- ob^Ӏ;.k7069n?hP,I)}m= #~(UmfzVҲZI@$Or@ZWvPve%PNP| $YN̵B͚2yIl$M*, ]zI*eBI{>^@8ܶ'p h ћAՁf Ͳ3v44F-,T[5~}o*qyC) @)z_[nYf݀BUY==lJ5 !CyPb.u+Z9UEM [H$.[5 Aykk x= cп6A( 7wlC<6#;1Յ4$ @dUƙ4&=:_$<;>jzzp o5=wM 'gX77\bK0񩻋 FGٶ.y/LhQ Vܠ#ťLļ26垜d+sq炂 `_0-ٌ@$HPwŊ*pwFp)hJ,a;p[(F -$ulJ{uz R=Q!T"J ~ɽc:I~RRRr1L'ָVt>C.lG7(~(՝b,}y+vll?i!tC" y2h jd1e q=Bt-I7xJ$n^ }^̜`N =YKϥcJh-:4 ):{^-{@j3͋樁̕Cr/?3xxXlnG,YSiYO %K& ~Bߡv]j )(,K@Ue8vnj w4t}ކxO@[L68Ԣ. Ў pSgs8akb)Pӏ-҄|LS%uҷY44 1k]H8f턳a%-Q,*9HMt;ۗ?GU*"3::M9.ѻ6&{N#Q.Ep6O6ȭ2)jha ȍh̤eyYHH;c .uxnoWH-KGخ>ď?~w/>0_Cb5<1騚P5qMb$53:mCwAd댨 DփN~ uU&?Giuܬ ڼP Zgm@jRhL8G3{ȿ 0?9"kC޵XYtHMʎ꣇|_̒$j^5~ռfw0SUQv֍#/ɺx|6oh` .0?s8_zHIdZ%%\X*Bl,:3sJ7}3T֚ɥ $/+^F'vD |c'ކɼyi BZ:W #ڑIvsr"G|WpY(8stXxz . HЬH⍼){N 4Ხ  T8 u衄!'SF>(=3Ц$W(Vgu' vC.f q- 6+Xknu7Uy }g{^>/^l,Mk!'Ӊ Fi,}";4d:wY nHfaO5Z;¢D6H=qρfkqBpEl;侤^ϭrQ{e$MIY؅XE hDدVtE `.CQ8zo#>Cs#{[1^i,'.x}~8; 4aTCἺP(b_5dͶDеNJpa&7w[H`G`tY’Ao1GT.'Ap"ۖ>Im`~SSJ6ڽUk=ec$0쨓`Rv}Y\&@Y@u{ñ]>,0h lT}_oYJΰq.)vFk3'#.1ލR`98nS2|':`fxO^)`YjzlEp"*"9YK咗H Xj+2$A$j,$bVXct7,4cUŒ DS;"45Qw68\ٰk5PrV"Ϲ =gAĽ8(W'ȘUx3@Xk?15yNa;b}>}KI ߣFw3ZאySȪ= ?Q N䑚l|z$hkߍb7ޜecܚS3%S3vCܧb=%HUÃYJ@Ij(Z{pj!o9}j38wK|^f]JƖ^vY#n_=cV[;wD30L.٢;,c Un4.@`,y-h䗳pz>ò `z˿jt{@g8U,蹠 #ӦI0WN?XgWU$''n˖vՈp]৘RYG93ZN ZlaeQ !+Nr#xGN膒Fq?g7i[Ť+@gWgUZsYa6/;E#8:@e*cSwircm4)vY>&c13B,F=.|V9/KŢFQLT,0=ѣmbu]$g/H 9/;ge0*xgqPn!N <Nr ;561](Q^!9J2 uZcegxy4#mI_jӪxU,=%TB#ݬ);s^vs|霓T!Vt6A@,5i1K&yU ;`9\uZRe;Ed\_GI]ԀQ|*#=?hpeYaֳI$ (GRn== B9MW*'=rWWbYhYUsTw0u ~!2rڤ)* q0*cEjr۵r1Y h_P-t|̮JxQ#aZ]YøPʫ ߍuZ*/KAHaJGU?} |ꩬp(#o+MY:aV2} ~x|"7;(Zw8q4]6~xJPc+6rpQ8mI'sڄa!\tm렩>yUMKJ֤RsVm+\?BI(F3Rz=t<ظjKe;r AHTTv\E0#fF"=beb"4 6 3V 2 Ee mÀ8x 91Mlw"@9Gm W'iaV@MoiQ:hS鳄9:+BM轸JMfZ\|b[BHCUan H^}FSgS@X#>dF.[2IRZ䂆a2!B'PZ'3-b_ʣYA݌V}cL^{B)Ӆnr m%{jyPYÈ\JQ<試&C2+5j= 9is,lM@V徆V4#4RyL&% Ș1ѡws!XS6vp$^yn#AQrNHuGM &e]%r \nv!kʪśAjt RL\ }z웿)ky7n~+Si8nCԒ4IbfqL{%FSW-LWkM6xPJP.庽_5e\0j `5\d4ѯ*sPHv{p(sIMԁR}( +R9%_vZϖ\%,\? 0%=QvwNպ 5LUbP吇@]IK;f:yZ;h=m+/ض._ GT2HQL on' lr=LƎ,wpE}piqE-WR }Jz+F$jXR2*{gOh^4v|; )_"B?z[qp-*p.Wo`}аۢ^kN 0"*Xc8khu)vM^zF rlƫmN$] |P0tÜ""g-p}C]t*F}'&51R.Y &@HWAG9H; c"v:{&8|x!Wt>S>ȆahՅ}X(#7$bwoD\Z9jF:jI^W 'W&xz:YB6o6͂{0r?G /LJNfE[&B *TѬKezrЫȹWMg4+}gSjw+ǶOx^O` {)8['ARAi~@)N:Sg@IS9w/^uo!*Ȯ G'La^$u椸{+S=涺E.ϼo3"!L &[D럌KIo,5 iBqiYt;8K^7% HҐ*[nQ6-w^jL)뒊]/Yt˱)a_f$||̝a5JCg&E<Zfa ~f1iVڄࠑo9S0fit?کd_:!%,I6 Wk;. s%$BF*,D{w0Q*Az_#tԱTrKwi6n|N# vB6_.o (*Ν  ٩&:Ło-`LÎKvNުSVp+IBU,%lU4y.(AReÙTTahb F>{I`gSj0G8@swCo2MKt[lײ 4ϤJ :$Kǐ"pJCx6_elPuY-:v<%7fy$[tl}.ߜA3v<FIPNQ7+:u2K`sv빃tV,˱!HZD|{Ǹ*TG"2ȈJ f+i%#n>Ѣ]^[rFLKu*1'uho(lmg\Ha՜՚:j^8caǀ%`ĝn4AhDEe Ğ"=5tx]\92>I~}x%>8ź9aQ 2Dзfb9ZFq Kgv;c߹]/I){=ڮ, ހ)0nLB{3T3.) /l-cNy(Lb gc8dxk_Wn/Qo'RX4d %[GKJ> t-1 Zjc͔Y{PwwI(4~PZ> =KY {H1i oh/˩0,G}6%itmt vT(yX 6XuT-}ԲuO z3g)aQ ЊEj[N-b)OhET]F QZƺQ ܂TFyh7 `BǍ#[1d^@`qnPyNݚX/) Cz>L2Ƽv)d/P+*tFoHqd?)%LWe[%/`[ûHoN±O1-{,cPޘ5D^xsU*ҭy:1lc , 9zl?]*};[=w^A:R t^eyJR%I N ģ;7TƛurvWV*±!2:lPc:AxZu5QBغ=\$k& ԣ4f}}>ˇ|9`%?MʵJehOGbtYBJ7 Li@JX OXfj"ˠ>!{FyGn?`mdL\'6j&BHF5; ,J’JHc p& VJ`ӟuIPb"5X #SsRqQx2zBOc#(30ߟ[y1V><ほ,.Z,f:恈A4~!ydJ|b¦בN?zU.Ӫ!|D-a{~l7FKgE'6 ͥ,a(S8,=%M'ս+Y_A͚8(6wr:|\[ F=o7Da]@nl7CmFI孆<3Lp ֶV}6a2k \_i"TbY哰')Egyxmz8 .\*1f,nLe|@n{N#KAv/-)(X6KC$Q۫{]=䝝=G࿝aME)\20cm%p;|H:(J`9}Bz^̺3E b5x < (F1uI"],03=1y+2,SXΩ,{u6 JL@@`F W8]!>nd~\aV6lUHغ2v &=EïL$gEblp0MPxm-BYghq8/ Lu]=!Cf_pbeSogoSxCKLgw h0|*{\ETdP@cEA,?u'p FC[R{"~} (6MZ1V_B=∯}!o/#k0RzSʟn+ Dxpb>J|HJМ3QIZB^h msB)t"y4V}zyx(VI[nĶν0n #(t50 p޳n(pЙ|34MB9x^H/91/Wܜ/8(|ł(f|Coo|/DVk ^[4^gVI#b_G߅ x[S%f52ηFl~t 0ŭ+4m"5~>|cc&r(#m2"be,11rȸ]hl6U@<7zV1~Vy@GOzGB.gk腋hd 3OMT5AԞ bO[\"?>P%gxDS GE_&s O{ ~# JI g J(qGq>じN\ğN n?8(PR5eucdd&'+cNlijG_v運C`EVWD}:m U 6NpY~FρIS@p? ˏ)J%'dE_|~&}0XL1ϣB`$тUnRJ5魣/-L߈]pbKnأ-Y TD%?S8 F F(lc +!f|)9C͢ל}9:P 90!P$v-ȬXX'-E=Wn7F]v Tn%Ъ`}/Ju%7糦^Ѓ# A J3NŃZlг.sU$hK[秸˝=_Ӈ*C3NJ~اfhtNX-cuS>^P|%b#@?[ov55¬}1vF=wRVYPWl?DRhMYԳ BݪI@:Zt鹾 :Jj̇!dWC ۫c-$VX| ",O|]yPB@4;2Vn")5y.bRq#ruvl3B[>6`a0Ra}2]̂5h㸩Ij@=z9.?\!%#whQ d;/8,?y7 u1b/9HBHLM6 ˊuq8EO8ޙئU(N8^*-cͣʼؕUTU}2>ckkoXԍ@_LT#+֓&dW8ej FUȘxꟅq xIھy)ec;XRz[lBgk9TpTRH"0Ӧ2Bw?3amtq{'RAwMq ȟbH+朼[#\Fg&Y :3r#+h~Rsk!c2zq!q fU(^E/' d$qyR-anc[\Zݶ8"YEP|X  }=V?ɕo,-v?ĬDu]?BMm\RIjk1tWgy@(f_cXqکhV%8 &wѹdG,CuG@ˣQ;8kSo7^$A0e~n%td (\M'h{)w(sx0h"Ks Qt>DoF΀J^'qo}7$,vد.oԹ~qX $x ?-dsB 'HD+7 ҥ" ;iۅXLsֿ}"w`EٗX{A$L ovA6u/Q<5 s!uωN##iR-+ 6ΐhW̐!/%>ilrH.׆E{>Vs¨> ^JVP/1e[$%dϓrJqPPY\eBndŞAl>2Nl됅`Y DDݐ=in)6$X7z-/9?$d"fT+j_k#aEw!8/klGDH>քhO[ UTIg#w (΋g2$'nях8 kNZ3/r7q 8? rKner apTɅ,+}3^KK@8HbO\s1?w葴Fxfb$` )j% wJЉ՘q!58i'9oQvg7|jP>@ʪRWHUL>M+Lyp˯S^"9F2 <7=gQZ9)@/5nflps)8B1Ecɨ؎^\bf*u=V[(c P-r-l'RiaVK{0Som> pPMIͅđNiOfsBvLlVW[ʦUZRЅۆa9/ʊg.Sv\Ol' ǻL?^Н퟊fJ{*oAg>ԻZ5퇝fޢ|c%pp'l[c7^t kd(0DȬÁh#N+1D8Ԝ؋oQ'-yF ]ŷ_xWErRvଽ(+ʇe2mo?{-͘fGd,sc[Նˉwc/|YxFY\QO"R'.8S*{8`ϩf S5?-=,_B.觕\ӢKI3ڽ5 ta_Y!Ȓ5`lrl) MtVe r4ܾC߲S޳r2O?\:TrHWGWT[A?0|aM{@"lq%gA@G^<9gxǪ*a\ -1AL`LoO}(-afPjAe܉ RVi&"x3ۏG^KJϬ'1i^JCfOi[`UJ}l| eOYsNx塞`٧]7kxN4W& `3g6ӌ/Å)(ٍ!5MyBhg\MGcauȂM眥[S{LeP` {)fe Â޶W.|,sB\ Wr# ~)܅B~Ob.*pVE;5"'9v<†s{ăVbǂ2t3a1GJ6_9*"J.sk=bzx8IG>N@z. *{PK%*[BTzEc yF/&d2yb/5iwpE?JP$-2茡 0mGM𖏅Hc[zٌYq !骩8ĀQGuDC h<y4ߊx7,\qڄS|[5*x lW% .V_˪wlmrٵx>t?:5#p,mTt!>0]G*CN;8nL_)AvNBq]\h%,?YH}FX?k?(Zp>6‰% BQT/;e _F:rP!xQs3,ʬ^fTRq<+HHKo7EJNCP3 t./= nV,1}C&=ASuM[tAr$hQfx^Eh&lV_;Z`ux"NzJcHVN*ayIzK 8e0c9{x`֢u2ďHKR PB̿qsw7Sx &P8@Pji;&8۬ұa}2G0Gv,n!}GfI_Zn#~Tq܈LHv Д1|'`:5͊zHW6 q0[eI ͺ\X,V0 Q0'͟ϫQ71 䈥v P ,Kj6 Mcsi%a8IBx΢U0?1Nz2pL#;#@M4!kaf8Γ 3P6t8}uZ5AHm& דI"޿tfd=ͻGl켔ȾD?9W ,M;#r>W`2k}P9hj_D2$GjJݍ`߿fJ} olܫA_s8Mf`Esx4ƃ0Qg^Y/"@Q#2s`愑wpyTyB8:Z]KrLūvR6S 'B\neP'D*}l' hA`upiSݿ4d@d7y8tNo>2K9ʦli~٫.z=m3A4Q5.Se\?&sܽkt;Td œr55«jODxlQ5ncZ股K5!hn7(`'$7Kw5u9OHVCgDpMem;=9<:XZrN-L8FhPum(k)nv+UPtߢ@qTd{Dd>:p)%'8?g֊%ɑw^MguPҁ/1sƦTd4:*R8DKt*~"dksi MQ j exW2;:*PIEu"FlaI;WŊnU 8H^myW,@en%;B=`j`L6!%="6CvGyȉaW,YF"0 N#6b5/лuXM8:_m*$ ^?Ku-wShr:S'@'u_+b!?G#ż;Q($p,LWtɕUzQk画Otm{BGЃdɖְW]La`Z"Ρ*+K)E^B#y ջz%Xl\2{Jqbψ,HEn}|cMWaԺb0rpF,ѳz^?U} f3RZnm^MW;Hn-Ũ]@FpfR5s뼢 f9ycA~ZH;0c?ϣ+o?r b1ԣ3ݪTG#Gpg;he= ʍa`se &8sȞG3l2FeeIZ<rMFp1Vj'7uFT$X#U>]a5p`Iש̞٘_|MN6'Z20'ڜ e8񚌥 l;dKר9N1 QJf|YHcok3}P̪4)rs Ɗ?]O s{!>LE+}XAUHn{+ݢe ǖ# z ,w|΁ жq]x_V^ZeIý_73L! =>1N`_rԿ xq2> Yl;ptb7g](п-18LdylV}Q\_6Cgq2,<j 08Wh: u09Y%U7~cԐ*\=T`G-7B~W11r$Ĝp7΄lМQ ÇEV*q!p`1x &˿*vޥv߆"ܿ2V<4+9]v-g<#5U%(0CO,~T ){cr4bjN(3D;YU<,( )hw(l{},Ice {*dYYBX໎o&֝U nZtכbOj,-I$lWF>P=ߘ2HF%uCGަՅV@QtV;b)?&iCDX: J6lLIjn{^7|i7gXV|c[mԡT>yӼeAVb u!+9^яizs~T7N4<˔R$2id.uUV/& &2,DITѐJ 1 FM wK:]/!W8X1O3JE5K,ch%&] ^c5x=H{1< I-8C@`C-!xܧV|U%&X"*TLvL,%ޭ;T$7 ^6!"\[zb9Xf I9{ ?:#Nz}rO|[h jted+?SR6; /Iõ2t3T=%SAh%[mݨUB>7SKk(:|NQ7SN4rwPgl2$nQEEI]633 7(,wV"<>|S+sks&?snؙj'VPΏea\jy}Da k?i{~< g:m7uS^$%зO0h ;iRNhlL2E½%RAx:iݨ[tGB&wcydՏw~N3<%7##7s*#u,iiͨqDU?8菏FTA³G7ZѧaG>KlYFk57v :;#I bFKG*ݝ7w':N簜К1V[r?\z ԞIao /Xv.i.ƾl$2 lTxbP]" wDo7rt0_ZZ>ZlҎnVTR`[7uXV4K6 frxpUJӞB@t(*GVoCڑLW:lù~JxPb \v0G(J{\΃b ް?hxY4ї M(5'1dqGeK=AfO4-\c@) $tSj`aVi$S+*)Fqk}B MV:a풠'XҀ}ȩAqx:2铼Cr|/U2c"!jZwlHM m3]}~B]@]*+1]eKf{;/Dbm-v:^1FW([3PO~U}{,9He 17F^lg+d03)i+#w.+qEa3 j[ l`D=5=AM)fsJҋWcIգ[qw'5w૘&vp+f3E c0$%g=!I?-C>jk%5Eh ~{Fp4ηV$cɷM"Lʅ0A* 9DtoG$b3vW".6eyR\"r9TᎬw&aaW*r3c[+6VCc:6tjB{Iu'"P=۾fy^쐏8doTNz,۶y[t> c9&#}˵uVfzm[u pc>`bg 7 (4Or]+;mk_Hg+u) @a [f4Ctl-Oo[vףulD䐝5(}\|ѻhA١km~̖:Q+ n!!1d* Kx\(""f X)Aȓcsw?`AuI"8J9)2 @̒u:t{%& }Dg _/P GȠ AMcym?$P0!@N>0Q<6ŧv G(j1 Lfeݢy84ݨ^͂v֣Sv -,ڼ'Tb 9 d:%VM~[4Gq.oϱR=dv٪WGv_Սoy?lz?lZH,`RKQ~sK}8J踤*7V9Vk^࿧}mzn&gHlD-w#澠ŕkA4;cM <"5W~`[l\LAitsyOaYo{>Ns,3^ g9e6=%̕@/Ǻdz#QD Eˈx ?icUsL5tCw%>ONJ7+@+YQȚ.žF&#E1SHT8ҙ{25QkjվkB.+?Sr#3KG_5Y RI voYmaqqcHΧXI+A+@LF"TQ+g0Ku F1V,WKQ(όῚZ_\`%nѬmAD-%D1.l OY0{9m^1[]6IOzܞ|R;1tBi*#Mkr&ο=Am$B;U8s"փY‡$8 fڹo_iph,RI.T[Yz%e%U*uu)Λ51 Sůn]/) j{ <f;BNk+<&e*C `i\I|_ nRVF](ٖMI JN÷8~|W.('fk앢s +\dJD 2~!X̄q^&b9+{@ħF0F Ҧ6ŏYJ'ap!͡ʪe 2z/%c&@n`Z &od8 s0ߝq1tuhn%I\% IWV5aLДl隯I ޣu?䳓Ó֟j5Frk5!D2]>tr=D1wFk?YT(9*0t؀H0w0F&` Ӑf*[oΝRwJ_`S%MN@HJJz5T{2=EHQ&K{F5fN s/cs! ~RSr<̎d5RZeפmzݻ/Vj΂!u@*}+SuIM_)W jݔqB6lw^s buL^5p$0s֭sg#Q7ŊTVqLnOu!8Dfق}}Pja'-ѩiKcljK60`])ʂƫo-=:i Z_b(ik:4Θt_ ׅր-1g]8XxBK/.N4^AN9vM\`Z8%jҎ0 qS[v4U1;RXʟ37eMl`r^RyxaTO=x N8G}.7'lJ8Xڥa0=p bA =B~/;\÷g ;L #woL>(I" sgfnfjĚ o։cD)+g{%ﭽ??-"D,co{]P|tdXwNғ4UU.\ |~MOqztPҥ3hy P>W M&%!< Wl9z 'þ1YlJ&D!"?p?N}o?xF]YO;9SD$| +ʊw+*`P#t;>$V;_gNK~OrsZ~c+;~ϧ6Hz*1@r~2.%# |9atѩ(OSEj`f%zB[k7ߤ:t`Oճ `Д%%9a( ˹'cs%UU' QnF`ٸӵ!Ra)g7t>]I}cp&ybr2[_b:`u۰9:eZ"WsmJ)*){`K!9p[wnx o1oF O? tΉCR >w? 2alϰs0q/.Q`TP?/yD98z<*:sYP'.MHd~= V$l]J+X`Pw8\S2/NQ^ z ;_':dk!-~\mHWe2 L3g "nޙ,@f^^nVyyW g:Z讍Wlj9Q7>x~2'#Xgvcsm;GT d`A+4 e^g'l1sC3Րx~b:?>vKG>c E^Azr(D\ =x:c[4:qno3?ͥ!Uah]/u%fZ v35sLv\yp HxoS.{G9Y9LZ=ٳQPJA5Z,^Rex*vSp+@MH_.iы9ڠ(h8Y]AA`jPqbAE"$E]3Z"+ }U]Fࠓa5?ʾIjѮLL>5Ekh0rưO^5eUDG[7UW:5/MH3Pv~rc%Jyx[Ls6(ꛔO]Gn8(@.XcXL^d6Lgn9 KΎ(慜cGvmk\bkrisVi)TD?E(\,2Td% g t& >&nqZ27|xCɭ4F4(~Fj %k¼ 6+l<W?Plv)M WtJ/SNP]=H:&dR `eNp~ VO*,BOSCᒔGu 2WrI:W6ͥzi]u-0/T`%pD8!gΝe%QtFD ʐ4 h7LlDëGp}i ѓQچWq_&B(“&iZ#9 .fH"WxM|Yx*F#৆C:WZRoh) 'f!}bi!nM73-7$,,.`# @"E9қ$Z345_09EoՕcQؿK)G/@ ??w+$Kon`pl*+>VM`+. bD,y3v7b殺Dȫ`?b~ S-}C]vk_$U20G_gg)t ,^V*G-q"DG5~\&DQf[ ڮ'ӶJe#rbB&}Ã~ ?N]}3?&g5ʚzK(OriĆ~$~f>_> WT s!J/;Ә=0=kô۾Si+f {3%k}ʴ(IVL3<eC|#ip-M,\enaڠb%ͺ[+t BARmF)l0Csz>UnWhB :QC: =f8`rc6: v@QAAh­qL2p4RNH084 LcЯ0L}f0Hgi_H~*i! JOkIqgk{ݍ[]džJgU(Uj<d`;SvGUyTm|yo^Ĩ&>HX 7 Y*Th1=)'b9u- ,7" ?ɾ;lvŁbm6UD XHY:T܀>V6nt킏rPo!  !VcY| x|EuԼӝ@+s{GohÛq`XWAwYv!1j IQW<,v%^ž:R?IQ++FHy`ef6#jcƆLO9Ň, TK4"xUzr(]u"}\S!@ihPrw5=:Q8˯ǰ!M}8:݅Ȏ/0 Ғz>nV?'Yb&٦@[ْ,rmHLG6p+|[+#+ &\z'(ȸI;"̠PpEPMNŢ"܍3a{k}ޑz$xxB?;.žR:W]d;pJUy}xR 7.nWWjܖ[ 6ɾ'6<9~7fqo9nJ3,QJxS >C"V=KW͆-Z((Q%6a`@A/0%3G]'e_P "3GjT-Ϭ69 n5S8 +ʥy \*BG,p"bİJ;lG5m@J]}vi`Q;ø=(7XIvWttD=Qh?! O33:H f bjLs#9!ԗ*AXp}>΋;~}7L8̑:%kHyWR+l]AJ-bE0 Ct+Bdk7gQW:.xLJpӣmJWbZ>"|.BVuG'#K=nq phHp ULǚq7d߀@-xmS[RYkqi\9pqL/Mi#ɲ֨!q-qv^:hg.^ )xcz@ ?_U4m1; V2'DOCxF tv&][Ek{bJi'Ʃ({u ZTQDڹu\՝}NjP~0fߋOe557~y#@JxXӕӠR#^o[Iq0$6%ldQy=|@Ȝ\>s=hu e0|S ,}M*R)`i c'.J^0g`8or!I hH!ߦf+kkC`a{uLYmr JA."nװaV f{%iFNt1A#j6? s^iQIHW٤w^2­*0R ڛ.iˬ_7Q3ϙhnғ0L/٠4\ {|kxݾmX}Dk(Va8I!AF•FuFc$ O =F^ѣ"́BAq~K>BGD8~mt"ߵ}]}mJ1|lzBY,OamQenmCZj[oQ'U.]rYgT;W?X逄wJ2Rī+<j"HwM^v=~ W'akK 'WSЗ-<}h`LvLp^[9YY?FIoT|ؠCVrMg'"]OM1ijZ2d3\T IJ0 ›+K)ar'Cg| }v3Ff[t_1ҡYy1"1j䆨G]g=U} HKyY뇦Zyviu=UPk}"Z3d :HsoLƌ#^S4JEꁤf28 |nfnz٥65 6%j+i-+Si9ZZλHB^"A 3I&Uvlē}KF]xPuZv"|3IoL2_ 'J~ ƨR|۩ߟ{ixI 6Rnv?B5 K%iu6JQsZ0B>3U_q!rhA| %\ޞR@9A*5*VC"-.O\B,<,*/`Z4(%zV9s$®\fپ8vo*M<)jxGV:A<ؑ$Ҹ#1?zIeA ! oѣEed]bu~@X4kEqυ! HGMxj }\ uVEWZ}R|\}V ?:E%X犐f{d-έ/ϲUeO m.GH 8'%RQ0S*tRS)c@.UBhh ('O}IdtA2X(<#;=WNMHytt}P.nqz -V*VNXmma$47Ui"htBF0UBX6\p5C-q&aD7D6z[|TOh䧼 ǯtIf6`*l ;|m~4fN|ZNAf̳$ä(^KL:~+ >#J@H!Z;ۜ6X"xŴ-i2aA=dϮ;C0Ħ&hd)'H~LXơ(U0{ >ę /yVqEF^jvibO*2<}QL=>13$f֬}:=aD̓[LYzc>L׵uYnʯ-]l>;dͰ[6DQ]4bԳl4p 7c&veyѼJ ÿm݃(ݩad"t^. B,\U$ ]QHOwrZ 8ztP @6d")sj`|/jglf[~ @{QP~W9O+e7NzoYQ1I#T*jl9ADi#Q(Ѽ%MT UXeͲ-5|sD=:K"I=3sIt "qF="w2m ?ozM޲,p S1&HqU/|_!"RSdzp\@B 97l"XiɄ됚~\LXoﰣ!iXIp@]r#~ fFƧCO2`uqVfD@=Br۹C (S(߹Ϟ.:6+z>%[[JR`Ut0m"ߏs=B7l'C^*_FͥпD#m2ЈF8eUR9Tu5HaǫS[FYN >{z4H֑X`ڡіTIހT,E5d!\-{nDAוUM .CcSL.ɗrUBqጚ\*0)J+\|{.T]di}Ӻ!A->Gˇ9+'H\Pz?h-r:SuI[+~\<͂d=ҩ곓p+Ei4Eyn~-@<ⷱMCM=fyrH~₃@= |A6E+Ojpw"&]EJA7frȮ)|C9KW]Pz' Щŷ `wi\hhOWֺ/nPf_r>ʾbn#olZv# #viA W^`~x9$!z0cnén!a+JEHuYgGKE`$l]ЭQc'P%D"a7q5 lh/*q6%oO~y,5K;:5$8e7Cܵ& Aʠ<*O>@Wh0װz&[qZ13:q΅0A x*ru#xJƵٸ 9[ ko - qkR_l$K-7B1Jxػʠd+hn'a?y$c,.!'ALԮ4}EK7 -).\?ńrrr p ԅgw&j羜{PzN2R?+hD{倉$|_$,E nkK}cԧ!@=,?R@UqH0s}Hfj:!S.gŘ*n9FuW &QGKڛEq}fE ox,f%!|X= !.my~9"1$YqǫyՇ \}HW^Ǜj^xkwam})r!_%j>Hiwk׵ O%kp0j+<3BUKEҎϊЯJá(u[74seqC_ 3bvXTf{RjBC*_q$ec:`FYjD<&(t7nw$6pЊ f("jדg&y],㚒9O > D0@?}XTbßݐYaO^@!h}!z\'(gbj͋H(@60r[JV G-w$ӓ%Ž/ h9k֜ |-!XRFr+ϲ{uۄ n l@oIAp:4,af_?}>{8F܂žwYq?ϽD8\ׇ[~XOz‡,37a۩Md8 }еNΘaF^>RfvW)d} y]I/+7>}<7DAf2[ui[<]yWLA(?NeBY vz.!')2 nPzuQd<_$rm1 &5`3<[7:CAÅw6,Oa" /EX22tLDI gRVcz۳$Q$̥{Ɋԃ#M^v+R1TN> ;KӶ@^)'mj~AƢhC򡘑+υ_|!x;XGLN]#vuFiKC/^CK$HC X5ڞCbR)p08t8e % ;^GBՏ~Co[ tǻbw/4R4αqJD-.;ձNʢ8WӟX1DV'de<JfգgPNI"{Zes,G] _WR4B"SS wnFq1I:5sqKU6i%4XayDU%Ğϋ)z Q}Řz=,Ԃg6׈(*դVh !*k4]b?:ef;va;MxM'o,I.t^Jq0Gj]A'C=; 8<o %vi>Dݻ&!DICY{H%nڹSQ_Quj74 wX![c`Cɥj^iCLtGbJO]¹ 4<~;֣\uax;ŷPjdGdGM; QS3敮JNOM}c$,gxFoRR@i`l6$t$GF5yM6٨}Y?#fK;-˨y_CJS }&7\VK8ܻ+ղz@KN>kIsd%w"tBKi48Kϑʩ,/:.6rcg괣I]El%*B0u_8AEUc~h{D*.1qG-!8u,,$PIleK^Qܪ;IpEF1ߠ\@QAnW=Ko=\g1^""L3*W/9$,uK%!ژIk1y +第j tZ]+CfN?`*h;w*^VWg&L\r_v-Ata[{K G4\7 ( 3ո vVq7;R5JWrg\*Y"{!!^Xj݇~Y,BY2W=q>L Rmvx`^㨚2chu nS+ 2gTG^ۮLEvJz2l"ڦ$e3rO<:=*}e )<|O{ʥe7m*ۋ="w4RMmc? f f-1V;> ]{5X4USk]G8oUD$ ռVdzIswF O#pel93\ :HjB8]ݠl(~nK,GfhXaR:ޅYdE `_Kz_U`^䍯 mF>=N 6s5&_}|hXXպ@$$1lB.ʋN% R]#OKrQ/ug 3Oa}8\?faR\s;\۷E?9PtU7騿Jf"WSs o!Ve MXWs9nսE͙[XuJr>pY Ç_3!9/qͣ͸-:g6,9X"O/p ?`t#Xrh:LZ.vޖA W'ZQ_5G˜+RH>zi'R)bq6U#0 {E9$ hAh|#ac59uz/F sQN"Ż.Zu׉l_E!vWh ,k1ɤ?]fUW)6:5< V1ǣoN4?|&F5icmUdzEƃI7v]>1" r(~Oh> y-8ts"@Q?S_mzr\[`m# kKQP~v/9"lx͈H%>u1t{ZrЧ! ƫ8y-}EwJ 07|јi&T  xUm󆫮' I3ǺBtHH\H @/[T! S'-@U7=_ cktU_Tm{s^*zR WΏH3TP34B,vl5@@¶Lq"g@6h3a=zQIJόQ-; ~-~ϟ[]\< J&$LE x~^ɨ[T`SHմQ  m=Ŕ]Na yA ˍ^ԹoCky<ܓ `KV+,{x/̗x4ӴBC='x|2Xb6 Gw!fU-Rb? pScggQ H'[$yMKQLXӬĹ<4?XFD! ^uSnJ0!]Յ_w~wuݼ c2i9LC9I(Mc+yEA~9f9R=@^bu>Y#𭄭:4PA2q͏K81>P W/"~ }z%On3F47_RhO 8}`Xغcd%&(@ml{9<*_^"у:ٜ5|=ɋ`MR1m!ϫ fhݔI?nZ*6aGS̰̥kp^Q~^Z;&[(P :}4tPeժf|LUw-AJHohɽ#"ئ>{ jb ]Duq 9hP(v-~m;tg0 jU&܈O? |:qv}Zgb>L2rWشi*H!;Y@nvqc`w*UͼV+fEq0$CTDKD85b@%Vw&ȭV\QG/t5ڲ^ticGS #݆' ;"@CiB?a#sh LIϱ)N$!QC># C ALS)2f**`QA^ U0&>] 73pR} ` ~j7pyZo‹eiV/?~KIK]K[ VK%v5*gtd." ky68r{Jq}B9,24̬tپþ6ҋo:A~Շ񚘼Rήy+[}_Yy"!+]d{ui.쀫vX=?Dv> &8Se]MGd}x!v hxϿwF}{lv,{ѣܶhU颓Qd'ٙ+Cmz9X!wyo$o]X:̀CƍpXg)^#{RS Qw{Kd5ɰ͐gK}vPL G6 b6:kA CAP$N'I?-i:Ûč‹mޕ4]4 㴈):h֪'2WIBvbH*fL(GHVB&=.:{ n}NWy."4Ӱ/37h''3at*'KίOPѝ`O p'B}kU\;VT/J̵3DOwle=Z|4n9-E+ wgU[]rio|yO{#XeWm|΃/!]6 zwf[4HVrpj\l9T`*H&@-iRDzZaTl7+b Ø4RDu4;:P)}[k{"y R'ǦʼVzF=nxΩ87a!GXdDUQx!42ڮ50$Pk:e~Uݏ/xg9w@`+ }rg25$TBl?T,AӼIU'RZ <= =X V)wX2gժ6IGдVH㎅k$pd93ţO¦YR$v 5Tu2t6=+jMd23&toZڀt 姅85^ lKE^i7Dl6q39%v+NOБnXu sjO\Ig'Qq38-X:yUBTd0[\<`tÓvb2]Ӝxիe2Ž)Iį ENӐ2H]1+5(u\9Gr{Fgk[=-zP^L3&.+qh('.%=i(h^/kwjk1?0x롬hnي4d43T>,읿|S]bz3dZkfޛy,.Fڜ0A=PXπ3k;iIN ͠@?+V+ eQKjK!H#!jF s<zo1 N@e95L7=lGWQ u`H"5쿴UB,gYjT 8W`iX#T`ѽsc_h0_}F %-KjݺW2K{EV C&Ce}RVv5-5bU0>ےk)FzAKM9KWppp2:?'KH8Jo~UfuuddD}<L@aPJ3M:\7!My-HT`!6ƕ%F+ln>0~ʦ셖EBa~lK Sjb>_o燻ܗ!evZ: k 3̥e; W_DSaE8OrcC=P[PʾQ)k(^+K~^UT,B?HAÂă@Kk'`D&QnjI@dh.6F; CDɀlzT%CCl0h+ʊ8> ~) L`NL+*m' _ӢrD ̴G$ /@ptg"JL˯O6 %Vk^9gR\5ּ1ZXDmU_kdoƸ, r=E I+zϺfگ sp@츻""0􋎋,|ϋT&ں]Z;D;7_.|^Lz{H VM3h^)T+j)4kl 3 *MxS! C}D<]@RΚ*7eld>Kh+ .j^V<_7lsx,1 `=΄$m[s&L[04)GT>?bx'>N?O`#$Z)-@%@H.G_z}TYC5mdžڇZvz̯e`1q 0#D̂ QqU>B  @3f@4FJ"STWL-En&2B[^39PvrV8撅1kH~u;#,‡Wh;$C*mn-Q"\\V>ucչ}ai{E.MtxrtOK~r ̻2ɼj oX{o!%[q9TvEcSma ح;hLˊ/}Rp\(QUa#ax]ipsw肀'?| _k7qªU:i7\6. &-hЎ#~sjsӎCN$DbIN/D݈O(4?*˿?^Hm`PBuQCoF91cq[k-ZVQ %` #8{[xD>tz|v`ωHg&VsI6|;e\_ guoC/u@6uq6lZHEþjH326ceeF_Qu,ITk~vG̤00RޓGTww9Xz+#XcHSFvY B;3d|3u%&j6)۲c89F`lJnN\G955dvw{ ,] Xξ *{kcE/7T BVbr@d? `&K"KAkSPv=x;x2MsIβ)S ҬGQ!58(ݿ& ?5j2LDT"E2Ws'mgxQηF$IIgX7 n=!MNR 1Sۛes H!x^o8me\fJX)@m{ܪUJDM_ l&/zȲW5MX}Qc!R|E^C?\ƒ=ЇG/ z<8ͦV nP#?QT2~!~L06"J#5յ8zq#4hQ~\Ӆ(kuWc 0=~;K+oU@ʐڸš*րmAZjm894 RYg$R=;l6kr:[&1bZ!wk1UN*apAs-Pmh+zvQ;º]-ڗ@ZkV |[.Ǩo Y"ݵ1d'pXVx._HTl;ܫ,ݒ<$F"z^D7M&R9(_VpoПe9~dM~rZuJW8XX)RODg ^2 >N,cکB1|8[3_ dzZ^\X&W v>,Edh;7K-*?ohuS7@oTebSMm-yG2 ʔ  ,l^Ao?L_^$&=kwW6TTK)n)_dU^~zy3n =U^|< -[2M6@ɐ&f/nj(tF)4%v]MJd~Y[,l pЖ/`}8ۡ\{Vu2wvS2@;'76(uX:rP`(oZ1j[%W;!)LNj,\hDL9^ٓ{ ?Ksm2– `stjX/h"wё+fL/Jsds݀Uaϩ =m /De\kPLtmm8>QPc̓D I64Y~𦘿u!:002r''q|aL.&K XrQuߕюD8VYQ>uu^ѷ޲?EQuA2 ʽ C XoP4%^$ Oc4rj C& x,_}* Q>]17S_NyXhQ-P@='xFKl Z6)_ Zc &-PG:{&^@ @/ܦz>V.%~^\g2+tۚL&ɶ4뚠EK2K_# b$&$b\3tpBy67(ul.9Ͽ"˂Ox+}o2Kj:49"(%~tmј /ރⅼGkA)Nc w;X_Hu5z8,V3{x嵍31edSsm@c%s h=.ŦUrSXAɔB1eĽ[n"U]{UVIBȯm s3*:I68Nsk$=ish$}اwFKCֆiH{Lfz(U*/{p1B`4=|-;-RR帳|@ ˁ[GfScz<)Ci<]"ly]*Stݫ'z"۪'X"g8h̦ܡ~ \:lj.fgn>>k*HLnNO^}zVgi";O.\[ĜggQ BD\ҵzTtU6>^!?2NPJ6FA <+ZʔՌ9[9O懈ቱ;#F7U@U8QYoqk}-z fq`N|j @ pYe}+xfa״ھYx8it^8x#rw4^-9scP. TXY_Yԃ;*ގe= Vsv0ZH)hR,l ~orW6hbfs@Fڤ~^%X~!D]a mx ߶kxrjkzr{{z+ij\M,IhW]c3Һ(x ^HEF.#0>%bvAB1Onęm1E ¾米AUSyx9 ld&C;eeb`u0|^@fA#bKLYZ Jbܼ}q$xKIEdpZnl4RX\ ~m<_~]:MXsz|M%%,/L6T Ey@`P(˜[3F sG Sͫ=9B!jGϮwu=D؏ ~WRwLi8.lc\n]:# fqj[3:T#C6: 6ɐsn࣌yq7ZưCʝThBǼ2Fțo驹jf? 52J{!X9"?UʅUkhWܗ8bh9 <ݙ2hlDk WkLȸFl+`]Ež;ic}.pIjW!4utɉW uIרCoQ->نz5n[txip\[jLYvnKuZ^4uݳ{=} 1qzߓy=rH{8yІ fVUgQ1WǦ0Qp/VkRE+USkHH͵Q)=#x#L]]'ᠠ12>AMgPF'DX$[pgoHJyH5Klhl Su5V ;ybq;15t9s~o"o ռZB \qd~Y@"Yr: qFpO`26rbR/fs0@EkEpL_| 4,DMeb^:v'cO@( &n tL(n릺&U4 ^K] F.Cogw&F;% ,l r @qP0\GAmoF&͟O< CgyFЏmt$s4E1,찥;&hF˘Af iiF/USkZVP2-,OCe]ۀ!a׷ f3R$p'"eVsV~e~҆GM<4H?onGrgk9'}:)՛]x8YtMIbrLI֗wkxqcԮ]v 4uqH)oX8< 4s'8[tT~Z-5P3:J`Ҡ-+pig؛bv&YKG>L!-S&'=!N2ZN)(KZ}t#nIHu  S`OVMEf2&!)괉^,m<ڹo;ilBЅQ_XZ;b 4kaù% C3Cg9rm;e/d܃YxdoYD Z>`o>bƇ8ǿ, tZ{bdOϦHp(p@n/+4{j{_FYIKԀlDIb!IZx]>p; vZxqӠ3+7/v`l3?x/: D{"(#xڑy]{q%);b/2 3UI.!%}I/ E.} $'Gšg*S7A11gM,f\DX20:D9 1a&qnPs5GiZw(s QP!z儓`)4"\hVkܛe~Z(DO [gH:Ө5+#-LHG.\3%LN* {:INhOgetZt17B^-0G.IRfp^K qU`^.aLVb $3$X|B*@l_AM |w2, T&^> G7⺠oep\:XY~0`S[6t ytF,AЏrsJɱ5vԀ&cM Dܘ4a#W†ƪw.G'=OGCR^MKs 6/9F-@=MLUD*lKH 5ED9a VWd9λ^E!=l<M!gwL;U߬urGsuy~TbF<8J[܁%`( $hhG'B!6+τ;sFL{z$V(2 aQs߶ s6 HoD#o\h0)۸#'r sNNm4闢Q [\]m6(*UY{]`"ݗKJ4̇euK)(s-+ yVI/ jɃDQ6=@Omʬ7(B;3<9G)f<KM%ѩ\ 3T@rjnBfSJ1teS[]&duۀ.wb!|l*io(")LADK081\N/CB S7@ vl X/Du#Th5j qEȵogC_*wީ"4vԪ۶(9aiO'-?(#@qP.˸N5a-ąi wucsCWe>E91>`~9h:  ]PF ҡL.w9AD:o`Ah4t?JНP?%qe0C: [4N}yRċx/soqKj`?.^gmcUL+r9[`egS}qnJDV*)ؽ2X'lmop~Ŧ77mO'N꩜gMO>DVo:V|K{[L FJXU (EO{Lt<$szNE4'MPd2mRO_4,DwpGHBC(fu'_DC&>խ9V@LkjCMH3cu^/=oCUJJb1rMy{۩$iܟMeMo 9WQ2 ϴ;Ci*5e(h!{*36O9k stKaQN+~46 ꊱx$ν1[Na\>,7,JG;][^ZqmTd >뷠ZW"KzF<6(#013xHպ! CLN Dc>RẔ莆 6rwxXepRlQ;P7$۠ۅ3p,_.O!pz$p(A$=ߏ汯^DNc|2*[YК{q5N bs {(X;!:*Q%t5^+a75@7,|SN?(b`|"7USpawi/.8 FtS>[A<ŰDwq-"cU*K sËO8&" WrJD䔦aV'-UQQߌb#gS>Ġ1-}y+&33b=w$uK]+C_AdnL)eU6.̀c3%+ GB n rB)!\\=2ǧG9]|dKUN?I-|a~0N*[%gAI-|N#X Ƶc/$煴N{ c/ڌ<Ϝċr眠|쨤e1}m"ߤL2\ɨxDJ[~o/^sn2Iy6p5>^D2t?byfk5'c@ut_rTB{KLdzk-uR)d;ά&`PШxP >;^_m`ERpt( %c-vռ?7 q퐽9y#Qr֓4Lkk8JDYS"4)6!ҿɡWzEAu֭ [∖i_v[X:CXv 3%PhVcdvCm2ԉxA"m}/8̻YüscW}lB%HCk)^1ًms 1>o&WN/%һ+&rw"PNP{?n{ݟ O>I`"3rPO@@Ƕ;ͨ#f,lo#"=:[{[0;ܗ+QM딹AH DmloYb}w?DGYET$4D*Y1w}̿sLjT`^׏,X_:EA^kOPSN"v ^ZPnĹFbh|Lq++x/F''曽eOJ4|?J}\x'ʿNVG\e'qnz &-A:tF K!Rk+*f8'С}NU+=vr'ٸBzzC9Ltᴙ]Zu&pN*,CcODmZug C}ҎӦyܒs,}+QFwuw dC[(4l'F"̀ۏ8[y v^2υ]VЬlL=wcGb9rPILiRaT5#wC/DF('z vbv/^\5vv-=zg%RZP߀ hfZ>~Nf/rK~ϝѠ&Zp3!puD.C:?wMũ+2t[QBe)QeCy&W1*$~HI&I-UzjaC_@(-Pr\h, pIf"^e Px1GO\Sb!c7_65f2n^IU؛V$GWr<(^#~p0>uN~faTE^E|_q-|-1U܂|1#sXYBO" u%\fVUOyjM8X2(ѫ"U =j6>hЉ4@5iC⁨c损[Nt Ѿ#ċF=M;3Cj,K}<摂H08Yn4lFU`&Okv-ۭ/Fni NɈX[TMةwM[/d͌@V/y6B|_-3^ZjWA ~?Œnm{2G/{Of`ʻ/Uwp֦$|Pe Aq9y(k>Ȼ:`OXoЭresbOaѿ5)=Q[Ϥfpeˆ]WEnoJ"SNd6⢒yҲ"*%~Зu mHq  QTnN;@g~TZr)'xM_[fl:th*gaJi$KgF6+%KKfPusf!k ;ϳW 1kh>s6|f`kMZ .G4c<Y?ጨaO@7ѥ\V0j`pqzg>$V%x]JzѾĮ ł Ayb;T0ucVKUo6?]zOzgJ}b;Y|sk.K'[[َ߰"6`*H+etA6Z>WuǶ LZ"0-'Ss8H1(CM'C-!MC(h)2t|(]8s5d[ w{m~1gBF>p^>k;|K kH;J4 (mrExyݞG7VQxJOڡo^ad:<:bq{PmUzdi 6J:J}lu 6FL>,ԈT;1§G:+'>ާA#S_yRˠjwmNn}.f|Dmyc5 ]%F&ۓiY3C$b ;oc8nc F.Ҏ0";J.8 3 zCG2 o '8.F2p K흀v iEW&q^%C)PS2ұo@x|ε^QHn%Q*g}QzR Q,jas9I v†&,o(~W)O1Q'xG7XAꏥOVGl/kzNs)r%8s\:SMG) Yby™6 wxljW܋A͍Kިnv?歷rrSqpKALTRP0ؔ~ ș4?{o5&z'W,H5V,'̎!4]/"$~~oel߱Mڡ%xK )~% ^lsCqU2^H~z ~[>4HY ǵoqQ}9C;tw"J*)`"jeAֹ`GZ2Kưp\i>ֺz?\5R O[E`u87&c%#Wͧzo#]g(,Ԧ)PEAITMC\~X(T@qf vjӯB]e?|1tɟp g R$2@ NG523 甮Qo3h4;eI#wC~#L=-u&g~p|SyqkB*gӦѨ@i`Zf.-G{nܗG/P ]'17?D̨e_ZJ4糾Ŏ0I`?]gi j偌yN!woߕM% їʃN'TMl! 0yHnO͈Qm mB!EM9ZپtOƒ4۱9Jƾ W&rxGv3JY֬|t@8'qT \?p\N- BR | JĄ>NNlv\qBD-LnAՋ2t (A.TcF{I(Y>I2dD4:+qG"=aD$rkA ~3gݳ}ce%F?WH]K)B.w܁]@zJpvM'Ux4*}\_ʩ,݊.^B!iN,,3N>Js%:KWr\k1/NM{0`S^"`ELA(3ή4D o'ˬƦ?čbnh._C>DA rbAӘxdR\@ )ʜpȯ1663ʐv.qimӒ7'Nz }M/EuOUb3)-~#B/xhպ:`s;z8eǃ,z^;.sO[j+_߁l쮙LkjeO[ON}j5.֭.w;)FHL.tϋ> zCO!ik!}FLOOH]]/6ģa}woTa.0Mtov[&Y7m/X1wXV?AN4٥{k*-%TX)pqQX0?ҌF 9j$3Q,@uT}:Svy Z{#2<`$%4I`v wE5MZn)h\fhsB6Orj!_hh@x4&SsӛJpV0t>!/U<׳i8ϟcȕ`?>BIa]ibQGx$%`,dC&k} g]JU4TC*YzND2e_3V$x1X200}Qt|( G kJzT\?NJVL.eZZM!+恇$?DL1FSU M\@e ;r(ڏp/%#ӕBDQ}cR;qԞN;)cNHu%3aN:<^@u5I 9lFvP~~_gByv7_U90P29}E!=<⡗1]M/ 6 q(k(dKQF@F!6xtMWA`8KsY[UJqpysw؝WKϑ#\;VHAi0޻PΞto]l/52D"0D .#uw=Fk~.Gm:RV+ZxflPq{j BOogu%ZԴmfht|Ұ@eQz`sI^qOq+JSu`X irDH[ FƋ{+еٱBdL ZE1p]$yLQtH mlP:/{X d"kFLf"͈˺~ {ĞU 5U" B:( l.HuICa;'BdK DS/ Vj1cڂOG[8 Q+نPպVq ! .FY`\ka \ĸW&_tnL8WleO^ m-r:[ʾgi p,5o1vxW G R*^EF̗9Xh ՁsR,N@^VpF{*. |'"P#'_eP ?  j[91䥂 @j{>;5Ï$8YܦrwrkpMw7ivҚSZ8up2GQ-Im.gټ^޽.>*BY8Ù\J?qL1fKw͕.Lt\t ciH8PtJhB??AOA= ~jZ Wc$]E;[J3"a}Βv<s4N}aȐBtkeNpQ WW#ny^w#;Zs'Һ#O/| o[l +! $g(L;m˸֊5v^V;T9FKX"X?6ɱ--gwT(nop*q8Yb;߶G,ԤjC2.i~XHss-fa9~n4q8C1ȶ.=)*{ yDP" r!@>:lPs焬c\=8ۂCpi&1p,!]=vZ2=ڤlnb'Z$scy!#ieArwgHe*2x,86Rh=*]d9\ĎBfQ:U8^$}V:R(Ccӹ3,(RU.0h3L!PAqw2|#txiZkm)39!s2cl:ڢ )xpbJ+89[Oh9B$&'e센›`7N{ 2bh_0̶~ma(P ]O2VYY"\('#ycFO`9WH{Xճ GL(7Y4? u/ Kөĉ`͊)JR/"L=Ù08:KY g874(lP|+E`IJR^z!!+qϡΕO`U{Wt`eǨ(<Qҥ|uofvóWeCݮd; JFu𭝩+ԑ&NT^A)I^ZnɔA3-]JYF[P}4IVRq7tUs&p>8Ȉx3]z۟?Wo¤:%H !#Rͩ7^hI35?x{ lnQYQ G}iI#os/WN^ɱzNjzE>3S5"ns>F1o 6GI1-;5tǜ>Nd ~L\X S. B1J>uEg:Yg$@ǼRyt/\eX#{gܥyQ=B f۝,ULc't OOnl5kJӢ.M뷹RBU]Sѧ8lFw;U|`tt7XETs77[^j|;i"?>6%+*7:2('7ej?,ܹ\{}^a o!:s l,=ۇq;«ow(UhFR^Xo$A=b];qZ|}>^tX!L>(QVp#T^*W]AH(aSdH\peF>/Bʋgi&!ƗPaZXb [Lo- "5cG!qgLC>h<%/Ɔɬ6;g$$}hL1 >Zlϩ0?#Zzl.=Ѭ.2B\_k1S_SH!D .О[UT# x}B yEvuˤR,^֙3w1 BlLs68E_rgܳyds;4ۡ ƦY݈y /Ñ{  / ୡ|oml[Vڪ'o5I$\`kС|ﯝfi0 G#~&:S?=U>`U;X6-T~?M4zeɂ[|2  Yh@%kFƲ'GS@(1\K g%L|p6LDyvqò G|&"1!(fV)R3 p3?+o,(+^o5 ;T)$jzhKEulvѹ>*339S b;WEM<}mhR0oJhhvs]<~%dm$Ro+̲U*CL%FsxvO-낏lVY7 em#'m[q"\GN{`_vƩ& !$;D&vgP!w?tX} }fn&t% ]䮐rR(7ж`=5qWLWdo8fLFoeHLUj7Vʊ=>__gu`P'=^(Pꪊ-U|'o<_Z YZ