sssd-ipa-1.16.5-10.el7_9.13>t  DH`pbk$ƨėh~';ޥ11+A9EFtb'W)G-x?rлTy]APGdKơ . WE%s(ۛf1as$u ^O׾r/*,~!JRO6o.}CFц渫P+!x%5i}ԁ,yOnM7d ^؊518~R`̞{8E Ĕn`Ӳo6" Z{RaKXZC12oJ̀Ĩ0iTfNx @PjU`,Ep> Т'rƟ$gsQlvew5b}0?m;h:ƸpK=@5Ĝ&T zi"h)rs p=G7 $MIC&! zJna'Cxœ\X5>%@CmDugz#i=5tcAb[4 E`vf:ﮒ&Z)(G-dĢs &Gjx2Iw J9uYI̫xq 1P,{-VfH_=1due@@: (xE)-]IaFNO"΁K?Yho~ \էw 顫#ceG7$0ajSH9 r]׌ѥ`u< ObfRd tCyykIZ2K x>=.?.d   ; "?EL    @  @`TTuTLPU(d8lG9G:G='G'H'I'X(Y( \(4](T^(b)kd*0e*5f*8l*:t*Tu*tv*w,x,y-Y.|Csssd-ipa1.16.510.el7_9.13The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.bx86-02.bsys.centos.org fCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd DKs&/A큤Abybyb^p0bZbZbZb]6ab1270febadaf8b0cf653a0d19c7367d2e925655f5e1e27bf6e2add36ae7d4207a0afc433b439115f1b703129ef377706cc2ee1c5e0cc1658c089d2698219fd8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903db640627e6f816395046e3a171e913fa87c4a5e7d54dde45f8f2c383ce321b8e7c709df34868730d2c8c8fb7e44aa78bb35c3737fdfcbda12ade8725737a67081ac819d3ad722d7d829ae0635dce667e719e8091cbe7e7cdc281971d6f48ed82rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.13.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.131.16.5-10.el7_9.133.0.4-14.6.0-14.0-14.10.16-18.el7_91.16.5-10.el7_9.131.16.5-10.el7_9.131.16.5-10.el7_9.135.2-1sssd1.10.0-8.beta24.11.3b2@a@a(@aa`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.13Alexey Tikhonov 1.16.5-10.12Alexey Tikhonov 1.16.5-10.11Alexey Tikhonov 1.16.5-10.10Alexey Tikhonov 1.16.5-10.9Alexey Tikhonov 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2079441 - SSSD update prompts for smartcard pin twice - After update to 7.9 [rhel-7.9.z] - Resolves: rhbz#2073352 - Use right sdap_domain in ad_domain_info_send [rhel-7.9.z]- Resolves: rhbz#2006382 - IPA Intermittence fetching groups - Resolves: rhbz#2006866 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2031729 - IPA clients fail to resolve override group names. - Resolves: rhbz#2032867 - AD Domain in the AD Forest Missing after sssd latest update- Resolves: rhbz#1968316 - SSSD: User authentication failing after server reboot. - Resolves: rhbz#2000238 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#1984591 - After sssd update to 1.16.5-10.el7_9.8.x86_64 the customer is facing slow connection/authentication (due to discovery of unexpected AD domains)- Resolves: rhbz#1973796 - SSSD is NOT able to contact the Global Catalog when local site is down- Resolves: rhbz#1988463 - Missing search index for `originalADgidNumber` [rhel-7.9.z] - Resolves: rhbz#1968330 - id lookup is failing intermittently - Resolves: rhbz#1964415 - Memory leak in the simple access provider - Resolves: rhbz#1985457 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-7.9.z]- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.131.16.5-10.el7_9.13libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4e86221462f88a8c09db5df0c5322a377c16612b, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=e6eb76c037a33a556d990783c1c8f8f5fb18a8ec, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER؅v z|2rGq ZʼnSBơIjxƞ>EM-U? Az)VCU6s_hXs%'Mr}Ƥ01(oWQ7BDh=&@i |=^}WfyE3;6lkE7znG5_74@0hJhKְN/T4(}5Q\2` Ɇ?eZzmFDb_*ϮM`Gv!F5ϰÈ1\ӱ@>\ @GW^%}FݍnWǘ*y.mUQNkB>= I@"n%d\6d,2wVp3Anͧ4hxF;pHƗO\z:&-T%(IbւsVfA< '*͵;l$[8'kc:к"帼`B&m aFCz<Uﮉ 3pY0).j3*:b&)D :T7'd"0,0.}'FBP]/ U)Ӯ[NxIMM5c m2~6F G_%mJО SA nW>9?GRQd3w炣#jQ#I-14E`H6Qx bFg[0L#k+td14*$_k =nc!5)RNqcTmGl3epHߌu JWY[Ә=-p^C.]FX!"W]aTԑ%-qEQXoz&%e"}âm|ә?hA`/PyNЋez/[RB&|$%*?,ʩ u¾nCA+ g;6Uds@ib0ANyۥe!%ü>Nuc*㖌2Na$*dρ9v]ðZ$ƹ] ۢK>hyD},Z%ݦ]W}}x\|72d˳cۯ(5KM>Ajc $UvoC -WB.$1!ѵ08<[J1塺.vX%9c3hl._0w' `E,v"jOeW9L1m @TkvBre3s\Vc6g1ptuFݏ+C>`߅@j D2>[H'lx>n'b!LzÀXE-)IKdy6.QZXsqLؗ8 :V7o{ohwk66ᔗBwsQM*)3SP5 h;G[x(*hʘֿZ-LL0cʌ \'Fq8ZGM$I$fqgaaxG{Z~8?+7q\8V $3AW՛P2YVZG(F̈́3ђ DWiGP@2ˇ#MʎbgG: 1']Í^ue~Q yyB{&(e=emy?]* EE%";̖9U;k#"jn(( 3 t@1QuzxdJ&f(rXEی57Hx,:Ӵ_xL;R.B59i>6a+eP2fFS U"]\ZЮ+<7Ϻn7<,d H5ysbm#^QGEP2f6dfyHu둅:7?w][ uyQjV1#WݛD~~NvkVZXsk'M׼,@(>—(1%&dʦoZD\rOm-T~1xsWFyC/gl]9U&$V鳏 GjAY g)#Q3zv:G95[!GrY6HՀixXHA4 wI"8>3~l.rm$@) 9NJD/V{/Y,EV&A?_~q"v0O UF1\ ݺ:2E?CNE~NR01ƌ3eBj|[}<̳3:\vg7 bgc:ˇEPݻYeFè.<&#uڐNm*x,[>*(ù =7_B *Xc-Y]ɕ}7;?aurg &d> ϡ1^([r`8pS-ȟF(+NlJ&4Vv\ +(]'D*^_`|xg LHQP]F-mJj<L- M+GU% 1ugYn,Z$!!sB'旛3fsHo+2'RG>j2Dt\k->h.;_2ӤP2ېwmECg+7AH/Yc߾p3STK/,fQʬ"sd׳쏂0ޣILlw+h,}mebAl`!9VB@-clזJm6< '68~@@eõLhsGF)ԒU;[MlRTKf}IQ1'cDQT+%Q0>C Ce;Ư봺E˟hmR rŷ{ @z/e!!T}J5rxfKwaJ뱆y=gӺsu07׫o)KܽkBKee'_U5?lVF*qgZ3p/)אA}rrTZ<ί^=Kڠ2}xOIeSqx߾> }E|UN;0bbj.okg`p^|D4Nj|}}r2v]CHs~Xz }/XNZyk5+[ -0N&0|KAMG{2*;M 0DHeN{]F<@=A۲:#*=u)/HgE6DTJjBcWl0J]40WhT}Ðukh[ ً WĂp _ /LiH ~Dy|Jݶz+ePiDfkkPRD.Zy% WNrq5,'Ohe fBaӄrl‘l[gw4ގa]U a1#Zy0#z[J PS NNnyY.G"x`꙯M,yq;P*W~i@QC2EWj[ueJQ<2K~tSM fwdu>m/_ +C.9ṗܻz~~cBwggw(BHl,F<Ɓz],cMK?&\WVyej՛HR?sg&^*ѣÝl6ACbX|~Ox(S1 \TV13 KuT{64Obvb: 1d€F>oHgsK>$WB{c4|:)(lV~?arq՛娸y&2^p;?8D,t :WQ^m: ?LɄ#-AS5rdzxN@ l9zfaO.`2',FN](W\T/&Gv{:nsFm%bdV 2P>C;҄[7yο #,3fjCs 3RB ;g=_ qϔ}mDa gߖ6qI_sޟ.EG{R$Cy6tƎh*$?Rx8(qOQ[Dgһ2=e8.7KHᎆyNi3c ']zhdIKAh1lUoZ&cۨLQz!_J*+ W9XV]Hۈ|pNϣc$v${s#,9ŨLC[U"Q9=pҔJؕ>Y]˔@NisTkTC9܊4Q:K(|Q_OhBCCi bKo 3$rL,0GX],i&fMZ (8~=2DRɞ5-~pPmĔPʱyLPKcB$@mQKV>gн~noC&~z8ʗ ]lD Qa97 Qȧ%hMwUql~'3BVvyQ؎G~M9kH$8πѺؽ9IKVzW֦e-XO[˱P* hQ[W::_D1#hZ1ddf>lM[. 8n]BP$6yAL=ɷߨ/4JExm^x:Q'/z5; aErҧWn75l1)[fgeXaMTb=?̵G'g|zm`4W\h@Zj&6RP o)њ%BO7b궯;K{vo툔d?;/'"sg-\%㮚5` amzՌt/r\ omNI7$'2 :31gWRG5f?jD&9.{u$$}.28։MOD gdI u*+ aϕ"UZBw~} Q*s3-t(&kcthe<Ĭ\/[7bguzm-;I1-W<3) Ch¢!bOsiY%.vsfG7_dbuWvZ=+8WW- ŷ+O`Erh`|5?E:Nim|qYa_,gVrQכ-6UE_4*ӵɏq6L.b0|oӻxuFq* nf}V"$^%ӄ\]!/f!&MJd|S}PdUZJ-X( "gtݶˉԉ~hDڡt24v0ˮ £'X=H%ۦXA~쥺>ѼMmޏPl)wO z7W"j&儺X_f/rr tE=z^ +MPW}8 @f|ϭׅaoxtٛ8-GZb33^1 4^w=q0spyM* Épc*8! F]ε떄UbxZa{ۨJ_Wt[s4ƒ+RWݸb(EUbcT.#,+6ϞnIGF+ [Tri]b!  mkX._;NRʑX453z >X$#D ѕwB$ȵI%muTV_F3,HjXiy/*ۣȊ8|>X"}M.R'n;qKKmGmfH_L5ЏH/d%j-[aWZ-AP,%6'(m5Q%{v| -(@Ȑ S5HKu~gU=}W?6Txڨ|@^Oud)xDPߎfp wfɭ ^;+(c/Z'VM3HWdyxN; voZ^GtofA|38 wE,:o342]VJ 4Xi~&zHBX2.hb޸% 6-{4Mr#?-mUe܂P-?S)UO.WnM`Pq)?9is0R0r34 &|Tu/H<jEhRF\R;{,UGbH\'<pW VփRG(Ŏu63 m<)/ז ›L⊎MiJ󋸈Sjj^}0!-h`4'~Sw2{;Uqh+y0]Ûg!i(&Lr4B|8xO(64I*ef/1`wcyE#F*jXK|hpGu e]%}?2b ]oZΣ6_uv%L̇-';yہ4c( Qy ]2s{y'e($/s+QOhбj)pOҊ^6<2Of+!:/Uv)t4TS*r^6!Jhy!' Շi $a+""1qJ.;nm0y:KSu'JÜt)Zb{;~t*? 3BW5J{&GQW PX^sZRQ=Ck`fQRF.=4i&1##_@'j; Zh{8NmCLz}|) FQe=B&AYR*5j͵#;{+\)qc5 x̆S{J-ٳa}h 6e,8UF~h#I s,Yɱf1(zQ-m lǼ4Dw7~ Zm+BNI*r(1EgUY]a^ l{N5_;6Z>"[C೏53V {Mt,9`/p8Hs+s "zuR }_;֯!5 v"UCvF϶8 b]؃ LpgE}1YTC#VupyPbԺΌEB/ ckXUm=Tb2[L~Q[DH[Sy@'ΊLM8slc`*d{lL_ ۟]rr$H>WCؖEOrވL@lRF6eE\5X]ru ͂?*Ru ~R[d݂^oGypkwfl Wi2hnQ紷0ՔdТV~ʫڽ6?ͶJ ) 5sbo-8TC rӡ Kܓ-Kn oRG܏"1 euC,By߂ @fl:v;TAgo-X{˛f aQ`lS-[!cBqbL|}ˊ8? Ү29,s|R.w%/`H"ʭ))4QXHp0<=+"&˸LPdCkL`Br;(]T%NZSA9z_g9~Ci+*JA4(M IdpmنXcM09!nظDwGDj?h֐X$ZB*6*F|InS8rA|* #Ji \UGdcp Zg):+"T ;3u]VK \= !e/HP702wRGe/T{Tv@Э$RO'-9?g'T1%18W),hvGK+S?UԩCi&[ irdz9dx";TM 24}A^PIFZ/XxkWcfxcuSrtݗ7?Zu8K֩Y[-7겚ހv쩚! [M7-ͦbK2W6턯u kBcㆇ<Ss:bMEzCŹzOܔ,,C7 `n;'m֦I1z)B)dNB `)5X{sʽ5w3qD' "+#)(re.6x)~BLRsȸ[}g bǏٚ!\1 ExBxqtI+`.[E16\NzE"uzل%m\XgcfyB|=᚝1'&T8=?#{1.L CMV%|Kq_ Ya)ZCV >_cv-[qwM4r|(vy<ъpd:@ ˇəT؍Y;S-w oFD˄aU!J_ !5,JWr%Flpp?2afAl'WS dX:gZ WɧQrs?nvV 3X"X4}L$&!?rOLrF5Yp68>d֧zbr( A+/1kfvg,DG`N˲wQ=iyѭ(b7o˙.!$vHʒgz `6K9zI.syt?Oc˪bU+\I@U*x9I,+ӪZupjlO L_޸Ӏ蛡ߍUUjei}u>% ?(ک0Dz'E*O3@q0U3}rl0\e$b2lNXm݉tuXO;:_ 0f!m:4ebdk \fL*^]zSMwq7D֌4ZZbݞn&G^j{cW]?p$=H,Y'Ѵ[[lTHTi)ˏk Cb4͉e 0Fcb_6(B180-oKUtx,1)]թ`HߢQm^4}iJ'-|8F-68d.*3kXTʝ7 Vv<3ApVn*{o>W f1sɷ Rc z9~hGl=hhd:w؅8|mΑ]c$ZnșRZJNWE#ImIW=xSFB >)I&".1)G{}V`#e^tq>U rIh {ZҌ'ST9J+|' >5خ7Ur8~[8RMSG)c,r%UdP/FO{߶F, R厡}r>xa\EQ`RS@?c&9:Tsh`b!*k𪂦֏7$n7{|+8M[,|&o/ի"r3TvaLX>Y[*zlڇ%3=^mgA+d;MYJ~ KOTSİ=O3 |'0We[D/HTNNB%MGr* #JK4T5f)̔dK?b6 e7T?_^H×q{#N3Jx;Oc0ai4؜fŢ{ZQU{eN-&"Y/L0z %J"72q#%Szr /rSw<9xšOSqblV6k]5)$Z!ES8!R"UJhe{_s2m .(8D :RaN :u/Z6)#+0JTxyل9=xo=|9ӃCjA풒z4O qĤL'ϴ1h4(i2 ԖSCL(B}yb ! GƂPOj  N'Ԯ9+ބfAgZA.䈄c8 @uPUqDjف=2-QutY"usAky*\K#4p$OO,5 l1vőƾ"'zͯN'u/:&o폽(O%^_)A-kvlÈSq3cij f *Ä4X1ڳAeon6oN^t}>F6{6e[*t(x9;҅jR?'dEzԏ:5NG_0LHW -.㟶XbCDz2x!_[_+XDɫժ 6HB˅"X'л;;WOPf\HcN{2.}k۾ doMn1BuF_OyTtۗv\6* VNtX2Qa *w@ޫx x-tx!ik~.$6 gf_sf`t 2_}6MLʉD)F ۍg,WJɺOKSkQ&4>w6N;iʎm=xG dGeؑ؞N46mXaph( 2mW4.:z0y8Uwܟ&fkS~5>ۈZFӲj+?+j4 Ep.h0`o}öӧԖ\}7*՘$,rK'ZAnBfuEz6eҝs aSHdls:BvxhBy_q3~ӛJ ֩dTmUE ߧxY٬eqz!|MS?"M*,n0CSR"cj?7,588~C*utP9lA8:ֶARgg-LU.HkU>lG͠'CD60Θ +S,UwE#s iMp|eDxst{5rQ:}qJB'PpQܛonE2c2۫l٘|b* fXhb30A}Th %'!?O~2l!ȱ% 0ndW%?fS(kd)JNw0*QFD6Uy*e|ݮ S&DDL0+=C"s \«9A36b0_0ɽE'3?fbּ3"7 %4V@F*LmZg{>Scl̮>[%JS*Nfc{|f6F,WPX|ɇ@`*y ¶F,\zqlL ;7Fzr5~qf\*֑n8:Ee4M0:Ъ͈U98gN9foɫ%wX9m&IE\n}fwL2pZunH#KԘ|WWKȁ:zg~v@ vb6ݦDtOZ(^j p)M"YIm>v; ak{n?冶pP$GdR}(C [.hb!(TQH`$n=4Xmtkǒs>x@ rЂmW u9L V#;Gt_[4`DCԩ[r3xzLK2+ {Ͷ]:g\u: ?mAyt'{E(>L~w`xb\7?$ +L|"bcmsDd}a`9 m]s@q "?r5 4efNqFdDŹI9kgpx lw«ԕr+D?isD3rz"q"zz::*=!lH̲/jiڒЎ}J>,&blٱĀ9zŸw=O)f" \ށۍCQ/?zߔKQzJJ|m> 7D[*xPo|~&ުXF6)TqϛǿiNiUl^o$x ݘk. Ct!? ,F@G蔓?+Sϯ?_1p,<Oi$1;ezG'MXяs5ݨjM҆WD-)e r@xZXEUe=utP J8€!zFӣW*{'%V1=xU)i a jBJ\d2-F-=$1 fv8 [<.#.>E bT(y8u0~n G8ij䇏dۙ|Ć@}PG_w.'R#WG~Enq!Wڧ"v% ]`%I 6Rs:_P UP<Ȏ+@G@u*n`9H`7S 46\HEvfYt0"nm?A9b =;k9$f^ؿClξ qhstKnxݵ)ƇIjS7)hsk(-x 8N?o #$7dM@$9~7X;jSe=s ̗o)H3Xrre +p-;ϮYr"bl; UMB,+!?",ڮ/Nь]Yɴ+1ϹLj"7_]R8Iw:|GjXqG/Z܌)7}пKFV/[vbAO$Т-Z:CTzè͏jר~#B̓8}s'Z `ayc}<&H^HH]pRA@<;^| al9Z=7REzkȅ0dl4ZK}A+*6YcO3 p qWN&7dLw*;?\ҍxrxn85 Q9Z, Yᇶؖ2hJNOD$gM\4g4T[3IEV)[^ۮ{bz٪PTO2sU3K.kx㙊/M6F&/5k< QA|2דlAΗYH@'^?F?R_fML'"I65m)ʵ. 39a~\ɰe}]sFoj.F] ~Y. BL3HU$|H5 `nS;D~?f9nc2f>JC}K˞5^ۤ R >%L_[ֻ5, .l万Q)o1iS܇FlЯ0<7u>/0bqL5{#u#G%5` i=.d0in(׷p(>mĵ7DM ]8+X?qp^8$qSOmnntK$جl& iiAG֐Oڝ ]'5Qh ^Ġ>̤f7Jxl\!U?Z S>ֺT^Dk;{-ٻV/} |Bɔ`ګZ7S1c4Fd$cvd)p#̓$m|C8].Q@RrtCwU4 {^NI+F%Zg 1\!ʣip?.n/U˙#hYxB[^/j&`ZjnUA3b0<0$S-T[?Qcȡ+ LUjTx#dpsik,XhyvQo%ʂ}1aYNIR0=+ v5hw YJVCOWybw1ѹF74^j[,P-ocGx-@FʂJHEBg/S'vdPz3\C >2EJFo< 虑Z_~ \t۫`av%E@鑗L)s̴ GF*g'L^Co }?|TiMBuWCO9r0+zA@M0n[Bjn|ڞҏMbXM@]ϕѲ>c)ǒdG%{yl]x@߃1<ʇQʠ=/|_.4\iOV*e9]:M,uj`îg*uTj_$IAN/dtKvxQ>!k Kn/Wq2yk>LCYQᣙ+u//JE-cZp@Li-Fq!&j_PAwRD̴%EᓃnXA'@mBl#:_ ݿϟYc{>"wPCqb=d6=`u>ġL)wD27C~L8qoQ[CNӥSD)ƎCGV ÕSW02@89K4- AJb/`G#r)jP6#W~ϐ/,/igN'Dl@vlu k#q9 0Z8i)NJTl'uU5Z8(rA`qFnJoyuAO L\!$/m3aHD;/\:ƫ2>cpeWةgHWb "U>L?,6۔)++xJh6)(evC'Rk ޕ^z̵/'gn'yċMx<\ Tw r&c~HQyj{]@[6S^Zf[ =Rt,XrJa\j@P@D*Ԡ80FW ˻.=K|1ms3f4gֶ@4JC>?`/lDut+[b27?`ET 0`TTjBuk!&?ӭFM at=.uA%hcz7(Qp(OzN')IڳJ|h<+ -9mg_V3lNKS.l̹ t”ѼqWELb(r  gP?s Nnoٶu1Rl]6-XV@.#USy%eG2MvcQ 6Iq˙$5?Yj Q=ihҟhhT*OɊ݋ry?Lul!?\o4⊈gRRRV^sk -2aۆz-ܽQa~C4OרS 8 ߈N8Gyu`R.5KGx9*PF5VzBB7#M@lCaAȜ@ 0~1H͍R`Z8O1XeWq`vaCLo\)IqS~ ̖[v[,zT1J`0dY1q^q3QQd|>ڧ@gUF 1]Pu,ȳc(bh_L! {<M{L&3{7RtF-t <,9clu (MseS0r\I഼~&m@E*"-SlI\Ř#Q}x(y;9} rt_ f]2Mj0"9I]\n)<4Rcҕ''hzV2@ ,<6{wy5C\/'V׈ &H$S/orP=j%jMP!=W)snǟE$W[ʼn&_7CQiWL@PަM|f<';kpQc1<:g]#S*2<{ LHD |q蓑ͤ ļJΝ]E(zAѽnA1 > `o}ZW2{Ѻ,홉;pd-^a nHVO'ahVߏ޴/2-3F|])2 A@>삤zVP >MN&p|.pmֲyŦ&<ώQ=u}pұ\eGnU_R<_8f&Oo.vswo0S AnBqƂ{3n//v1c|9 jg S_BΧ]rZ8TTm"{'ME#[.y Kxˤg`P9-ڌ]\8ӑfBMhKǩm4 0pa`bhעAH: +mɞmOGp/pO]ٻ=YK|Mְ;^GBlnَa/ }Ȏ0" mk:;}K)F㘩NԤt684O쑸dh÷1cw7 0L(%T$NSM6*3fI3`Zf[lV/_p@"eft6_NGB[G1&?4h/}CΚe sL#'} uC_=d No͚&*ƌUd՞"0Lzp>>`v4*ͱsț+f9>4(,G/Wzt~AoIt5kדAuRjp ZXk" &&Rvq>6X:= }Z/{×xב`{v7PF: G8yCUN>GQUDDJK(>G>4G%sj^ȺVO=rzo ɔx~dO^N͏Fyt t2?6Xwd{ظBm6mo*3on;4d[whdC".Oڴ7nX ՜ded(tegup5]8@Ձ;z#Ͳ({~޾M!;G{>]йIx1 28j ;Њ'n G ,RdA9 ŨƸzH:tZöHnF@T-8/6 r,9?X/^K˩0K ƷK5/45֌TlǾ4"=gCQwp밌H3`)22{B\ҖIxm)ɊRzK%'CIQKAu֨28̓0бvTfL^oxx o<;I" kћ_ e.@fXa+!$Çp!p~%es_şhVb"\’-3ZΥ#&!qt迄<nOIg[u엶% nDe 4Ql1pHб!@<-`]D2J hz&Zád+`WOGcLMZ"ᧄQ%x=5iNaA ԆGSp.pYFAM o8_Lk@ThviS\ѥA/t3}ugM fgME6wb#}WbnP/dvT$`"WIq{^919 >nYWi"=蒷gwMEq;flFWzv%6EvN+ JʐԢ2g}%Sե cĸx]2]Ont cNY[`"-T+qwddNΚ}|:TDo@L j%`ّX_r?^& vjM:hۋ,*ӌaYc@*)vr12G&WX%B)3`_bMF"qs3=5R^z$#2g9?& u7\P3+W#U)t sٮv>ùq0R7R6UK:1l`I žlU9S1t'c1ŒKsaÑ(!fm:_w6aJ ( mg6g̶1%bݭM>W>yRVNwᏔϔVz$:Kl%B7Y 3Lȡ~-Gl'w4#Pǐ_͸s<0gP\2'-CX/?vtLVS\?sE9uG{V=r+WfJZtf%kHGѷWz&G/#\qg*}=6KyyhF {4e[ ZluG U/Qpe7w+V5n6c7T1 Vik´? zL tIY@2Dk懲Z,iQJ|gt|zW0[HL\a.DI2~Zw9&MA>!}g8'Ղ)&ޮ鿷BW[S_ΤQv1@a-U:ж ‰?󗗷0Z*5M* ޓ yTK#ԝx4ICHcGx<#G^e{xkˁ};ڟtW@kSLI4'}n+A'I_CkcӨG3}o|F ϻN{2mE`}&Q*F3gIIxeBDuO`rc֚t8N=je8¶1e~>',]O5hN(M 1:[Z-_Xc/ \4Zv_<-?}k3/;VٳX=6?ysZ36%WfFAuWTFay'g6^vqԷ! C 2jюi\KȨ+;3-nz^9$!G,F7-~ .\xGo6ŗt|uhc601_' \hdcro o=L[i;j]зfV%ӱ@o{[QR OmxΗ8)z(+519_fyh Db:uEUavc5nX{cN\MZu_#Q.x]"MJS` Iy]ƑBW[d̤  ̷FԻq=G:!7=H;|L(B{h SܡN bi&O4ۢͼ*eYD@s*XF&(!vC~HUY~ė6*$B0#Yf/P NC[w}8G6 i85SدZG8% &ʫ(WKV4n⛨lHEhVW6^PSS[-33nl4@@3J_k=-x>si̜X/Yؐ4ʵb5^mp qY|YCG>hR)E; ?躕 ۝8=ӽ~tK{y@662oCO${ġiCVKFgs9o+#K>I"w5RG{ [ ҮS3"w85|? P{!(A mbzE!eV{3yqa$ ysUP0(K*ddV-/v>ru6EON͎i%˪VL+aaCW, %CsøvE$h m5͍[rS xeið!IttThZƆ>Բ!Mn'P#dq$%^Y֤ź1ꦩw6`=C2+VI\0ByrkD{n` ?kڵ IytcBfr܀ R08>$D,j#)2HM$D+'fSπAr֯Oq/Tܱt_G-h)#Hl^3bY''M< /JM%ʌyĵώȑEvleVBE F c A͟bYJ\2/% 3-Ȯq=EvǾ`ԨNbĬVzLOѻ`;v|I=끸Va{Dr80N9xՊR̷ ܍R+ٙ>!~9h?Ik=j#\iŜu:ogԪ`1W1Hd BG;ɏrO#0 DfXJږLW!҄"@q&9'Cϐf uHb/t!.ڏ Pr֞xq""J$-j㺘ҭN y 7j_/CK|.q͵*v<9.U,aegmyEtN/"۲ 4.߿з SڒI ΏD>+c{TGl/xP!VJ>3{zWf," 2+)$bH23~yǪuXxq1#C=>s{n(oF&)34%!0$N|Z!(W9Vw~ D.Y}E@ T4`x[P=kZpV[g 8A eAQfx䶈^1'Axܼle0`y[wd\.qk}FTVwgSOѶV[No-vNւH?g%lK Xjv~Q5eXP=GR$m#FiGDd!3-:̡84Q$V+ھ&-8$Nt $:TzmDeۓx}Ibd[a1ʞTѸm?dCMgIS 3%%:!?'*ˢ&mU>&MmQp1h!UCtꪡPD/  Bޟ2ݕ1Y,_jp-# !k> _n=>"C1 A@N1ΐ~p) *K6wl ᛪ/RYqҦ LysếĞ3299w81NU.A>Wb6: #v\tރP_8P0jъ{^m%Sd: 3mۓ3!9.-tFbDJX~ל[UrY ՟ (‰j |'F *iG Pӳ ZF4"UI(.'8M_#vͱ'B2J_qdj nQgOJhݫSDI:O&ynM<뼋_[2D˞:Gp )lweۀD`06jR2ͼk/;<40M9JM]A-I_Kxx1"kkHmP݊Ol.eaP\Tv@m֫eR0S!(40abxs&APC-#RѦZ߫Ӌ%VX "CR_@ѿC>{nA4kOk/̓:*q4NƥaƃdIĄLol*]&,u;oqrP_}jј0l:^(!΄OgBXǑzD?flT!)E9(?䓢]OJGb+Q1n+|FQ5^%\׎zQI/W2Z?"YL ~k#NZ7 Cn㧱I K㡨!}J5Ts!բ ? QaPA~%HI`9e l1P]9^77T[Ir/hK=xͫ;JS;-mân'jpc1e|N<9MVg21OCw[A=n! ?*2X}ϸ3Eߢ].qx9_0xWr2N*;Qs17i2Fr1D^3 FOgkVYƽHCIK '.䔈s2SÝIw[Ȇŕ,TeҬp vcQ ڴ$/Qjε K!]'dr Țʷc1tWm aDS9 n c$[z;:Z^1![Ғ[vYcxK|'Mb-Ma}K+mP_T&QdsZBT_о+u㔯}-AіWon3L=0&b)+;}'G͙' ̮`ܣ)k0LbΤ3[WG sY1Pϗo76:cvUھ&զ9KO1YѺ:}-5:*őPR.; |ջL1giN:3nƙKzK+63Lݲ/ǶT# vKau̬d/kO6S2Aњ !xzw/o/LD=N{is9)ԦB\13K,H@3ץ?掍!*Lu1CəpOvp4wN5<ꯀHBDؤUX1ِӺ.IՊvSD嚠GFuh6T9g 3fd} I~;̺O&#6O!.ʞ8u=7[izk =KfkeR=(no{f):  7ǧ?͙f2|EƵd.uP}61S|^uY$YjsP[ggm%%*Orh)k˚ # J_ Xո^a.ܤT ؟[H/YzYy \l|]4s>d1ήFK_ ˑ퓭l7rAOiܥ{:Hq|m?WG[s;0x;x|gQ* |rʩMEg5MjĬ/ݻYjԽՆ帜!_(|CЁwkIe.y6@b棆+o ZXOZOHmȎPWar׋>#7 |4T FĠ/T畍4NjTjܥiOOs#KWh2bds7+ IrN w>lQ  i4}%f8-F?vM &GNv_ 4bQ 2EQx*ֺc zu9ʉ.g{WOL4h`1%T#gF *Q+CXCpmҰ4dFnV|F"YƕYR\28WQc#Os$)n'b={ބ H#et,+3eA#ͯ=k]fJ/i#G;䈜?=>FWXVs75nPb;]QZNT- K]W& f{ .2Ͳpٌ. g ӄ(&hhdJ[R띾 b*'Zo@˚Pꀚg!=?T+GO( ҃6xtvyS4A(R)9mSqn֬/dؒpx"!#e7-WЅApuCzx*x)/^A1>Z#jAc>2ch\&X>'osA/%v},sK=0qSI!&h sc`7QykBثf*81ҩT>ٶ9c7 ESQ.=g|%ʒ"'k ^.khפkh&,Ke]Euk ^gQ0NT)-5jjr*Nm*d)Axǃ̝gplq(Y2YgqML$eRȅݰD ,GgXj(+ ?ȭp;ۛ婺ﻦc6mrz/\ydy,_.l Vx[Hh. mYyļj~a=cZSx!-l!a/[02f{%r=|yjصN1xC\fWgHk||[bqn9,I k׏=ŏL=D՘?8$ҭ!!F+k ~iN&1ruJ2k=;>|+ḇqj.p% ФFJ.oQ+v5YB2.pݩuFf4}( 95aI@)~tӑg7R6:x<\e #g4BytFʀU7G1٫ .]0ɟ=a:Zx!Wg7YhuuVj ظѣ8`| LEo^kI7OR?-#oo SQ" :A1DCɔ?sPb^v_*iXTEMU>eǬ!eBda )'=n}ʃi6޶T #+/}M[[+eVhCv1lHo'e_;.Y-IXAψR׆_mv<-[Xnw2qe݁z'l 3 vNխQ3I-^[1S&<ǣ0 =7χ!gGFӇ!üqOl-j>E” Wud~L;egwo|U*ΠUW70SvsU 2z7UF0S/Xu*A7};܌EX5G.V ZdIzGsxv`93u~j/ʯXAGu3EE}LoyԻu]wf9qo͘e'OM**yȶbW|Ƣ= ~wvTQ47_gQW?A]l䬃 zx zJÓ39vÔ7)X1 p/L\hK]j}If=`1SV;|j9{'C ˬ:6nx}Z.4(o+~'}n'Je,Ǥ, ,0'c $GZQ*upc0C-->'^AUs VS_kw&Eo\Xs;&ZfӚUU`W#-b*5QE8QY㨋=s^ N$BgLw0@-tjV S J?H'l{(X:)[Mp:}vѡ*:X"E7‚Wyn&^/r 騑r_fGtB(x*%,:CeNWje4X+ȫI'2a#ATFn$&W׿IyQacyLp:J_$@*Ƚ-݆#Pu7.20*z6,*XGYnkdW頟v,wc'i#|l^&u%5вW۬|=>5MNԒ@/P.2B>QG8P++Yvk ,r )6E݋дxsUŢ c~!yb9e!^ARa:P:iB~to( 1~N4 `4#k:եҦ<.hx}H%B8J RENS"eJa$}9P ݫ [rBAy,,NnWAm3 EA.~r/pM/ ?V2eqH_@S:OH>OAiIeMG6ٴM(U>d\i#T|YΕEH \C?}?c|CIKR|t?k}uHpLZ|upNB┙k~6Pz'lV,m)vaոd%$#"ԋ9%hbFץ~l-oBS?ʑ8Jpn-h].Ao=XJFlj"N͸ b^&y1ommbDXwvz%@X i^Se2ȳu KN&tǾ0"w6r?e#NT5a+w͛1fd o:_Ai2=Gy/%d>a0˜^\9Y`|wHD8'/[޽Px/yTUsB/?qd2e5nAc̽?k i0l]&az;vĝI 8։)"Elm(k3=\R7tjDg҇mr%zsM H07m @ZQ Z8;mx (7\cnFuRص%f=H&%2|EFc6 9I+v|G5KUeueUU'r8yhĤőʋgj$m$3"3 q\gw'<~){_IBS1!k ll%hojq'Nꗯ}| x߃6Wwu"7#o[-A-w|0e60 픷GTC>έ8+uY+/v YJ)۬QoJӶer1LBcG"sr+p3OլYEbA6b\ aQ ,bꍢ҄9`"%u_˷+NRP)`Jn UpUBeC\*Zp FbY $%á 쌊2.Fж5 Z[Cxg%`"~ԩzTe%n`e!ZW׳^Ƀ$l) Bc^|cЇkrT4O[zb1O˦yout|H r`YzCdAg: # YZ)bDDZcEP뜡gA-K>^/AJ<贵>;{ݴ;)̬$FN*bzf$xZ .$Ue1K1" #zG MJ*]gb+FBYGcS 'w>u \@إ&P▽kK-vYʱ}\ӷI~ WYlSN#ZR[vs$ϖSz+^t7R5 )W-'&r陂}"3tHpki?:eªuX hՄPu ̤cY8(>=Nn: gb.*#E; D7l27; ;3ϴԛp9ںbM@/v\'lBzX=;vPM@WyN=)X_# V 6ʔŸɺ?K-2|G=D(Uu,ӢID1 i׵` %<;(o`BJnLE:&tͧ:>>|وK6 6C7iD!62'빠|OFj1խH{13P<#nD2)'Ku,+c-^^t"KvB_ P!A>Aj#舒c]l4um91& _qvWI Wa=78^!YWqѴ/9RJvµ΍9B{*̀hoەHm ~ &Z8}XhlW#emycg"iPۮr FP|0sH䵳ms4{ Qr0[ &uoiVu)0SWWsFN~cxG$R]yObh'CO:_H$ye0RD+KPSH׍*"߸$.-Q6"DcDD]X13E5W{i=篝Z^aGMQ C$da_U-͙6:t$*(st;5V(%A(߅'ԩ"_/Ya0/3YlRKى |.^Dw/HI+8!%W=AzoYYr )^˻_ p!@Nh~ű[ 8vΞFVjb4&Jyy5Ul^KtawAHv{^ ^K s=#Y^d>?٢EO\}V>ZQkEL4Pchk "5^N^pXzr-i&/Os4׭˷Qa qٖAkN;Z LlZY&HH {\uyY-NkQt\8hC>e|/y,ohIaCB}෾}jݸ{0As-]=^,cj]i)Syـ=%i~iv@?:xQnwrP.ngUw1WB0#n( i%V!÷^ެ\ؓ1Oiԭmig|d^OP5Qέu`VPZ.Vܩ%)bU? x3]8fAnn3MxV$J˳m:QTI_&?1\SxHm_F刍{jl̓MDIln,v(fÄQlH YoCARrQ v@m;nâ~fH 9#z[q/Îw>*'k?FҋSL}AKk?bDyC|tIK*wߢ46x:'{j\^ /ZdA*c:U"6+q7|`rӶ C*7z"un74eC &[! Kgv}%[E;vmȨrU3,f2;⎇o 02ؐ33_Hj'(JKA9FΝn̹#(EM8MNC>zJaS+Ѝ#O37m$tP<bJ @λ G8[jܣ lhYKmNJ,Og6K.̡hwWzyh Bj(6G&st^FJ(Yjo3CJ] +zp#'LDpA];QyGk{ΑHTkuFkk˩XYEʎZnB{¤k+9+ݳx"ɧe2bS2b j/44JmL0ϩ(RiutdV 3C#tiXIU{8 ( zfSRoii2D^]IzsncC O (@Lm@i010c"!=q_}"Նs3sSz}ِ,e:;>8-^ FE"3V+[$D{.&Ȑj7ߖ!eAT&-.Z- 'D;;41!:kUA:.!66&w{,` vYLK]Vׁx^vc=Ř@6,Px׍Y4pj%X:955*Jo4)1n`*ec(fDM䔤Mbu_jOh.7cY B`BG>0FFƩ{\ ߠvoIQ0AD,q@Ĥa2b=>0N%wNiޘd`[*jaU+q66#BU^|BaKёvm4K`=1ZdJo\{rPo/:L][˂oFKw'^\GK8!/ڨ 2­I=XrC\NhL/L1&7ޘp8 CYU 8h}1/*".7ijgOvzU?}䛆"M Hѓ 8 j.euT]1z!n0%f_1TKmr  ßc #f/jD,';/0~?e3e) #vXГ:8eIfuH%a6GdSLYaWPN}߷$Y] )%VиˡSeԝP/IrZW%lxrAS&l6&C 0Xr@`. Z*Ԏ k.+?1fjs:_m-􈼾IcxtCw '6`I04K#U}go%aI2:4Մ:y a@^b0M!)7t"vF3bӵUT̎^H5N}XI9 (ΕHfZ$-}n%S&krWC9Ń!$Z휄l#֞j\GPv)D\7/F ġ@ȉlU?7yoy-p PU&(A=hh6RS#:eΦDe1҃{8*ɘ:j5Wkܸ&{(px..0ƟGX}uRdXn'y6促yuP;D0%R@0z=柭w%H|57S {6Y2Elj$7Z<tR[ׄc£(R3s6QcXwpLra" XS>i@cĢfZJU'q4R^'q CY_Og^ 'g0pAa"V_Wc4*۝vk1rxP('QFj@sSCEМ?Mv~֖k[Q\-7VīX)5Hdg?=t`gFp[tERHm!>WIVKqع/6e!QV y*[3>{1hC&ZY~t@uzG8\/g\ns)@ʺzxJ1L%JwE5ju­`n =>F (P= {ˣxձO@!Ac:;)m%/>G-QX9ކs#ɱHE mCeQ@)8V]T8/VV@ľ RAw52!3 2s||SckɵVqB"oj $ŐBN"wΫ@M@)elB:3j QOSk2a*);{⧏"(dK:%Mҡrȵx2ھTg+&O5'gdO\ )ͷg'q̄Q&@UKTQgT@3t. ҕ~.a/EwXؿD ~^]!l|F<fmN˃,6IyQKBj׀j-x: ~ I#qu"=/P ت4Ԝxߎzqجquޭs|ݴ͹q07F=q'c,^&ЛX8+sd i z740E2y|{/aRcž+Kȋ̉RIn'%"EֶH$IY˰) oA5wN$3"݌3u*4ec#q'!/N;\TxY)7\RK@ʧd"'L.7'd7}tH>]ȣ.~u'l+rK`1ȃ>Xq9E+"aꥍP||sԜ$FԱ`BU%VN%vZr!кphA-i*"؋[ VzF5U21=Nʣ&)͟( &5w5}ݥ 1‹mj$$6q,q$U`ǜWļůDS~a5Ρ:Ϻmnѡ)+hKIFEkvEM{gԃޮ'E02Cz9"A SJϽ%~#"nK&GlzM@#EeK.YǗ*2>K` n^2s^,b6 : ௐoLY$bX3?'޾*98Èl;hEhZ kVnrg?";ϲ @rx(Ajϧ7%+!#m k`'#JT wnmZUۨN !~ŧ² QLdFR%? S# Br[2t/|l|gjz: b~EQ7"(e0= kU?> X+l\wn3zrꢮo_|9g ཫz=:C9_0Gfz?^GgR-իȽcJ+iZ'3E좓ţA*rFc;fs׽ Qp[3{lm^TC@)"8+^JcEFbpH'58Iu)m@=>M@x25]Dk#pFc".\z i)B3/ ۩t`YiͬΔ,Xw£s)o=!Iù1YˉB蚵AD|Vu; ֎=ZMɏI]ۧa=S7,l[>;ku[=ɲ{ޝj ]I8ӰV[`:9)rxa)c&GqAMv%$McjFSlf:B(@LV{`[sJkUBk3 3mTT;xxF]<2go{ *`JCֵܭUoOOҪ*veGnPfi@.AJ]~st{ 7eXF$JlOI o˪ُN 3g/H~c\Jl#YU9: y*&N 5aE/TDC3pyɣzYF5MH/1(ٯpv TTH?4m{Cq}{J/M\\} ZC(:}`]N9'lHV)g9Q:\5X}OXVx˽3 5x#Qn:J .V;oG#k{uQKdƗ8>*j00,Py}aR/wxW tfz W\EkuϢ}gtrvo&Y YJ!\*xCPL^^61kntY yN\[s־zw ɂ 7q^o(NL6NyVկҨ{*9O0qLT"oq,%!9bvP[a&ڥ&}?b #&":TەE[?K{ e gl'5v@W#Șe_h4s޵exy4xA]< 5r2#9Ez!z?l̟a!ʿpY榡\mds?(^!ch,䨠_  A~n7"ħVS>QpTA*p5Y%QO> WQl}7!5“pt!k?HW9%| A9$= u7,ca-j'pIN\l<59eM)WFGif {κ1ߟp$Gw ɺXtFFJx'VK3V-{imv9&mVhĹyAE;eFђ?+Ys6m?Ơ+3x9`e)k#qntes4‰fHoEKTa=Z͵}76_;M,M@&Xx$?MU, bs`J^nRC!rBy:GpK@+l'߲7w%{lU }nR9 "'W7IqUゐ)iM[L#K֡mJ ̈́LS7.ׯȞHN/ϐO9CzT:t&s E*݀iY/1^bJSAq;!6Q9&VO ET ͞l C{X8y FG;Hma 9/8"]gқ^&M+2!$Y&*ldvydzRX eRY7֤BǛg|1LA7`  8ݬTkY>ph ffX"ʨ(/+)ł.OfJxM1 a8c|ӧ[VpF|ūG}* ]q!JRY IM0nkZ1}<$F([HO3J.T>B;^ Vn~^H7VZ 2{XYoX~j5pr%^𫰝's]"ȑĜ)" 0E{)Zl_Jao6 u 5HPQ ΫcG7`=.YQ<|1 R$=D͋^$vc2Ur&:a*OMR?6 %h_ }egD=LnP,Ëu^RU}ƯYl#P#Q_(=;x`yb=3TRq(Bzz6}ӵpg2F x0ܲn7@㚶NsSAr+$֩kVn~ř,&>c=w MR<()/m7՞8Hk2 |DFՒ9/8f@DR.Sfwp  )xE=?|;_r[՘޻ZP>#,PG2M $iծ%_b,S$EOem̽R CݛoXWx}mcAQP:f8HKd>;47/ 6*5}sJZ"fcsEEP%_\2q?56p swĜ<hawe2U2MeoB^I ;۴8X4voL0̊i5*NOxjeÞ:Gh-KhVU5! xRä#m?䗔s;b%Fmf*a5WDBg][Dgr`z^ժa$><1R9bc[\t|YIğ19fpuzduŵk;h0~۶5ZCh;wנ-ʅCA ob" Vu"5Hmes$u׋.!Sj7O[7Of?U!k$w]3K8q۶oB&g!KmRL^4Ckp[رALߠ6Z;hD*^] 졑~\ɉ_lkbm-$$YIu:-U ʞeH{ rqfrڏTx|uoL_;(J(IP,tp˄2kO/#oZĿ;.'88BF{I*aOD#k&:F3U9,XlгUlȷ| X&U_^ꃼTq=,)ި3(.m\FOFj᝴Vc*;ܴ AB}vP>!&tn!5 'Жff->TD!^[cT~("AaHK &JAtG}er\mpN'5hƦsTJ;}7h^zeNiՖDA6&b &&] `/CN+Z67ܹ{5_SGHR)ڙmu*g i/ژ#/.;Qv En e +d ~ʽfvtvLUJb+*jF#Wm=BBY#$NpLG8VXnqOHѫ$^I\+G7yڢUGc2 Y}6%I`{OqC5yû {.n+0p~b,^w֗ahhױ[[55,!(Q_~"N H!Lq&jWo+ۣ6զ!)"DOq\~Q0DVShvƆ!I\ݶ|=~Nr'<!3p{3d1_q2KWls&[iEĪhNJQ3-gi~ͥCZT`԰&AU^$dIBB7ȊՆzc4蹈 z~R$'Nrܯ+8Ri4.9|bT5g˥~D%iۨMF ^IIٙ/oԎwh54[QybSWd=mҦy"DUI(J&Ε\T%8KػY]"?;}\K*yzg]|Ϙ^x0E7L4'=,Չd$aTgcq@+SJ7dDgnTݴs㵼5%CI,:t6 ^%v:!xT!bQp%kIOV'毀e ٸ@6ڈH7hva;ahVgC}X/m7ʼniB!W+p{b }ɷ9B7Ŭ3  dk:\o{Mb&$ wD( t!JZQc6;2G"XgA[R:M'ϙc2Έ㗫! z` R`༠(Vu=..=lD x#EI'2>8f6ir u~K}o{wrLz, dω^f&XO mB0`){zJuU#hGVĈXְ[AmB8M?֞vPPII4F^,Ԋ5$Xݩvbcͦ߯Ɖb " @zڽL/MB_RB$yuJݘ\v|mic;px]:݊Y_:rn4/%M(wra]씨OϖIK(Ό%Pϻa ECI H,*fZPi3ko pgqPaq)*-/wswܳ2Grhпf\ 7Qٙ&o>)IN>'C/,Kh*, cҴƹ&fY_5''/3_#-fafۂ34*7ӝo> ]G>~Q]tGDeZA e(0d.&q+wn '1w '~BԔDDz4-dNқ|; >{%6zVʀMwlf:E4ZoS]%M9E^Zc((^v;1LTO1G1חqϣUS +1/J֘FT(tX6z2G:{b qtEe2V*(Oi-Yҝ B6'7˿_j* Ԛ}Wx=f`n %U- áPD3~}j9@VCBIL.YRRIN1pಸ'a!@2gk|8,`z悸x-Y\ôCkg~yg? wfF(=/ CiP;:}ߖm.|%q-׎qviƠ/|--8wX.agR˿E |+%OLtixj⣒Fv3`hCUMj|ՙ 2вW;~vwQǿۀ/|1"ހfxKA6`\ h W'z|`8|lEAap1*$:U]+YߑϮQGi3?o>f'sN}6`*/A>Ͼ/ȏsJ9bA7xxd/[X+r@U{5 ~9wC-ɉtShwwާ#5Ò.^+M+ۛi)vN+R[C"쎔Ɓe+:!,f~y.|\E"o/U ? dE+أQT zMw,-p1ε̝Yi M wF:);AQضjj$çQ%nw:(GQY@46@^~`I,"p~{:U)a `% :sϱ:uq)us+-"_{tob.h UUgV#1{]|lVEJdMPL X%0_mq=D~m=!\O܏hcMWG yC߅0Y1յمwZB_>u{.sORn5~Ln [HN#Obs#K_8٨dH (xu1ј B:o벒 T!VE`Ն*QAH ["7 u>nt nSQ\nWnmƳ#:#y pgf#+NgH\N][BbL'ei3p,upb>pdPE搻'63i¨+،\W)  LmHN ?)-V4r| Jq5r5uN7ZbR2Ax al~v,wŽ<3p*å j(j vU1j tf$HtK U{yR7Fih7uNO١h!Lv%ֺ^ݺfA+_H}ֹ\F3ίdfJG>P,V SH)^g4چ!.MRa9 h+ٞ GU^1>+z[#X"J8CkKWĶt$_ 6 P$r,]W}q 3%% ہVM~Uc:Aa`n"}OECTo׹έTX92:Tl6Ze V0UM9&PcqS Wx:I1C#aF,FUUVqO,#uZW"jȧF \> XwG *nJZΛMӎ=~G{vLVR ).@i) %WAg]Q`OY<*F^ Ӵu\o ߷`4V5D{$yXAF6{Xlid,Î(]ħN&b8J~Hf`a \P<y#E챊\\/C=ajF\F| ;$H+"z3 N(ʵԪP(aܢ|k)ӮpA4,KWdsmb残b)t3\Ʌ~ Ax='R&~]m4޳m0%|u 6( r\тpT^VIr8S*3I[7*.dz9\GI m-~*z'Xe'庉?bITRx(\DfV'B}oبЈ̜{su[kFW']6#>5Gm(=X 0wDf3U 8u5r:Jj0eI~W/HO2J䔩߅H{6sc|Re$؂[Ƈr\H4ܫAJs b_&c'?bG`5^ MQ(`V$$z܄ۭwF Jg.@-{k:#D 4%k>3@D|(yvݺp/|z?kj3 [ζLC]Me}+C8d5!% LPQze㕜<U@wZx4;*4/[rgY0(.;{X %ͩT,0Ǟ}GP,G{_q>]9c3D) A qFt{ 3N 8Peg+E|B\Q!dC~H "=nH` 1|;$"+(#Xm4w^VDޓeGkO A>x(.sTzP hٟK`V;T-TePj]`n^RK[Ą{8dm(?"GG̅(`0jd:27B$A*ù rB x@M{lfK%H',Iq0X6\{a1J>XAc%)d9A!{,y24 6a>fimdf{^/5*Mo%}X'wYrGSqִd]҆"1U! ^3%f_劊~q$EBezD׈4P Kv|Qd՗[}x/o%DUgITe1E {N h]I˯3yP^enzL9MkۋZjV~kqK[U&=!g -^z`}>r(D5&m07 Y۳e]XU4;وn"].]_Fp>oEkkE5IQ2mVo c)\7zJj)t~X]xY߈vLEƠZd9L:qd?eH%8V;6wß+X}06cJE7 K(Ii%1]9gAC!S6"?aT%ҖaנE- @ppi-xG((J'C2)({2xU\ QW|bsP^LPX}!ukRP)`uJcC RQ=PB X;UjxĠ)cbfOdf\f) q9qwkB-61 0 NJӲ$Sb^?+A<3ע9EW "Ì5lMHT`I#Qe*|!"lJD~e^''_mnVhJwb^gnUi Y-Ʃ] e#BtP>6dcN>LW;W(+ ^&faVY7LnF3*zL7Mh0L/6E sM~ B*ahژ%q/Y-> ysxwPψc^ǀ N8CѾ981iGap%ԏ3}4(WF4j_BYHGk}xlDIZqf&@dùl ϯ;m9_KZ Ȅ=KfT|mh`_5Ԕ#Il8 x3̈dP~GVnE~+<ĐR,Zh#$LT|G!S5y$4 JNx0ƚ!Lh-sRE< ALҁw>/"_W<+,XNGڹ@K5'րXSuEioˏv# lQxA|,pTⓧnN0'OI k"*|"';כʥs1P%,Ҹd_b=poټg| ;ᾙ.GV=]') ޖRCS ~tw9dH5'0CNcr 0HO pܷ}h$T/ƒ;;B.q"E{LA {=28aby ydUqR aΊ҃>̶w20`bC_' c8OA;&2h'|(\oMɑ9-[ħ=I;8TG#x>eufӴ[V+D*kިM,;{tQv=kNN#b>PAA&ןovELx6ҢC$d+MF̅?S brۺ^ ,7O=1$u*$  tf-hG'?E hE&?6: wQתrM6=` sn5A'myTf[POΓTwCc%(jU\+wC ٽz d T<"wVF\ &kͨm>U0xhRg!@X|_ bS㇌ UM4[+nހ4/i'Pp4ze>_TX*edTEj-Yk՜zl iSk /GnhGq<zͫӉR:V:;8s(v R6f:z at%j8T=hJV"&s5ʥUu9d%t$HdjfPyR31tIp+;b\H1f+Ƭђ x̨lov(T7 ] o$bv1WC{[KnAl@ ld _$f|ZB7BQA0g"-& jZ {-BZ(w\={1XˁfMQh>@4[U2ۛ:z99\I'yw!0 >s=rv@5JY3%Ƈg~aMχSS*B\f41r?# &ydKOXE: K@a'hoܵKvz#?HAA#?邢P3򪒢y(08* & 򉺷k"fFG=+/ʝI;Um/MTJTpwA8hnf݁"Hv`bc)X|Nqͺűb@?_vZA) sיo?je9MbÄW0Oau/ɫ#~)o܂к@p1D&^ֆ_hb`;!/'q =Vh@bS௛zffN$x"jiff3|PONI!CJɝ CsTpV9~ߴ*Q/E:$(H#k [oQ$A)w։@bUW?V`GS>بj^4ȍqy*F V pUBĄp kO#?>sPw[u~;>fHݼ 4f7) ;3 w#:0ALja_5?TgPb,#M%5Mv$6pejd:,gfe' | 3lVW}t&~*|Z>-[u U')8LXl۶y>jE3ȍ'5 T@!A/W7Dn"-c>[2AESeZ}y=/r>¢fԗ_!?r`'uě![Y8>ǧ}wb5d/b}X1N u_X0cNP|gங Rt)@&Q\ث::߼GdiCQd(cy9e3͏J%}5kONFNWm 3* Iw?1Ͻz;DSA6&hVT86mg1 #Z!'uOC>kLKE yExzAr _X7~A3wQiSJ. 7mLC'ŷWSXYN|PoMVf!FFdh+8Rׂ6 [!,}`j*OHQTMM$f+i\,@X8AU%wb,L"4qCZD0Vm.` c nb|/8Q(:}. \bVɼu٣e Odx {_ 4E!E|$f Zc'@΃:1 )A <Bt|O(͞z' \^^9~2iLaTRqgۦ#Ѽp_*e7YeZ~XT4Cf) kJ51Iˎ<+k$!> qIxs$[_ K3N"I[,vT`̲;cFe_z?wNc/pyZ.eotCy-2w! g.+yy3 ;h%RJ-"lU976gJ[Y¤~ڳE5n=¿qJAd1|?0GGⴄS/VE]!Z-֕}yH2 m4aBh!~.=2z(8'ndψwr=$݀R7=[밨l;ieI]:.юE3omdp#la>`ʛFu#Wg:]_)+wL[!n|?D4k*''`1mV U^zhPڵʈ7-wѹk"CLNg$[OJ0zcư)9/H Y2B05 n9#g6Dxh'O| wՄN0g60ts*g<̫cն:_9"q9FGQ]U;q٠p%VbWʐ|qa"GcG&=8e6Ρr"<~є=YM ҷ5; g`a24dĝ οSX I2FKtW0 \" Moj̊&}rN }E {rޙTcn^Ll>;g]!ȝv-) "3=  M28,GZ5-S_ *rdRq߱Bo uF}qiڼn4; ?߈6\3m~/bjynLqh˿97l+8{Mi;nT b$@ g(d(%#>Cx6^TyWf}ܓ'8 s7[s7bD5ۏ6W %_ L\ ~ W"15$'/ڥ:&;~r'{DJ*pĖP*@s{ ]Tp0c=(i vi9qa>-S4G!m:*ʄ.GtyΏb L^Y-w椻Dsk1c o1H[4A`'u^<(4.)2XOX8P$uNH%nOPj{H(1%Ng;"O|~,;[[lj12X֞D}};lR4j#S .Plrxlv}PiRѶI0"$ȼYʽ" ^ϛ݃| Q]]c`DU6ꄃ~;|#d-u W3-և0>/Zuo55CNy{L@?(ȗQ=bX(:,H̋ 2+?2$MiblE6E 3:i/ҔON2GW4.yjUxce9{d;;ǒue T6ΰK(S%$P4o|E h1Ȭk5[Z)v _QLAmyX1N Y|>)a;.6pM%]+k$_Mtbske KX*^OLO?WR>=}H,r:XdeS!3 .Kq0{H\X"?qF&Sʺ'&G*S#B]2L}Swv&p8r&5!p^Q*:PP-̴Rt6X(;)Eu5tyKɮp3xd`cRTG"~yx1<3ܥO~Ds<C1'Σ_2OvcL_7^Z_1SݦlCQ]hhii.F,)mûw̜!לUbuf{7%Zƃ| ٦fl>;P`H-'1WoC  {k^IVJ㲯uНJm IuXDU:l|T.=k\Ѕ(Szi4ι~O|8k|yjں[vL_)U>fa'N'T.6$|vy?U+6 (y0D`,|&܅5!= V%Ϗ^~ yAXMjE'/ -]!ϑXsp2ܐvފq|y^<^:IL~I4bۀ$R]o#73Ռ]9_!fAIԩ>x> dK$d9RAgcRn0~)dxJ[FhS?9.,DkN% =;d&E ,#%ˮ9;{"ijiprIG-Ls08}qf|F#\J98] 6wDv0`0ҩGeMj\dc7;ppkd6ےeᔭ9m@i%?,6BgfZRk74t2)p2q -?_bE!R6!$t--pIX3omoI9C^v٬] x< l=e@J1xM}l F<#|m@eZ:jթ( Lo|a$`/v!(LJX{'si=ҒD.3fC%\5z˳Q@+scGjm", rVs>&frѬc">Otzq/Igco KVe-_]6'U2֬ o4S`W e3KrhtV2\C5:Q1τ^qa"dN{,؜H=aYӛ0N+MWZyXrNݖK(E^:Ec?:?$ֺ! ʀ~." i݃SwNYG [{+uw*o~tI,09u~ dBװ;)XMl(\fm'E\T4$]%jefKwD-lI_pSuюahW<4fƐo_~ ǽ*Q,ϟ 26Fj*tm_qğJm\7ų3αߒY`Ղ~%Yb߻C‘yq<;8 ٻ@ ~Z)d`ﷂ49%2 {RΟDgD!7*'<#cE,8F SWU+6b WFnPdQ*2j\eyE ]coJPӯCc꩹ZD5$iM!Բ a[v1:Vo,-ԑT˺ًDcmkf ߌSʘ ́`1V\d:3/HD˫,%1ڎFb f _h Hhf]}'_OIr mG9ډEkWy8S#A'yx4DgfE7փ=Tu+o[~zV 2?Fi[M5'B\%*5'hڊXhYX(L ŵ8k rc1=+ m|԰aA-uxx{A-5Jh;A C;Ԡ7rIx=4AtIJ= ba3lTzST? σTTvVDaED;kbOգԀp[zLd;-ln6z%ODn\[IfayVyvQj[| ݺ]x[ gKTPUQjjvltYRV[A/K/Ʈ3O4^~a//% D"Z`Pň3g6TQsdP 78usKǃ!^!Nrd?\ϐdM B (.B*1Qf'W> @7h+2B.] \{#>e:hHx$׎ n/V~z(u>Q\ S(_5 h`VEbhr*wQ5Q4aQ;8=F)m2ݛ;Ǻb޸lLzQUHF5/1lwUS ȫ4B#N+7-]3#t}ႍqxg~rsbJ$(ڕ"WBcF 4)xw|T qQwqaJ[k&/UwQFF`a0@&|"%-m>,Ĕ4Uת[7.m>߅?D'T&CV~q{,qD#ad2z{F3/BS|vqp,T@S+_brSP{ MrXx)6Ax'ƹI~fOO4ATH Sȍr˂r@1WvNk03D`LE6FsÑz@X9REua"4S wI` RIsQTb~dȍ6XY" A@AKK6x4+Wx*y&.Ğge# ||]|fu#NOwZ7bGmZA`WCZ ;8fOᇐͬyPNw(f zs2yT4E:s҂IX;XK*co/?`J:kG)&Ӟ< -Xh}@T~,xOY= QPp+")J[Fco[چex6^SlRduns{M C&N:? "QyV6m1b$iSmq= ߂L'(HY5Kro;_׳FШK uV(,wE@Ֆ ۚ%6&f48N:*oB w2~vUIq?2?OTBp{:g-JZHF_D_Z1+c84-Uȷ/< h]_Ty r7ņ!(.+ `w,})?\dEYxvcJI7[>||#4Jne~KZ@KVj!kPJud岙o cf KgWϒU˳#rۡgmHwffKEue`JCy\fd@L4hȣ@_y2NțrmhhC ՛L+-YϷ2|坆E-o".sŅ.F$gș@YV&oZFQBmXI rz7E@r8եA+ԟP$ /$#'"9bh{weȌ]V@&~+-G!?ˬ{a]9f;{0[ 4DOhw2+_4|b+e(1o?o&Zφ۠vZ-P|l YQ;CKȠ}Xp!'cNR]tTg\G|r:Ò״&oџvLM-cГ%QrԛyFP`we#\rem*DȞh-f2F: T[Y "El;1T<uo>u*Tm0V~@n;Msl/6^R3y`즼LޒfZOa7\7кХ'ױVM2_Q;-文|?AiԱDk?SrپZpo91b"vvA}̯|IнNM$RjBP=i܋~t\쇎(],RLS1,&l"ˍYsB=G4pA-y1"IcV"(_fּHQ0aRMdc9D"LYF=^MO6@@5>jJc"/l.cL =kW?p=ޮVڎ-7v6,qe`?0f螀~'pYOel)݀HOcȓ_?x}DygDnGb5׫-@Ww+7Tb`^7?@I `1EY$Ny{&^q "TqNo@r((+~VԆԀ-4dhCGtowx^G}I+_VZ% 9Jiʽ V*o6o+蠹eyRIKK59wŃ>뵿YW8^oB8wDdp}90N1 :zi{Bp?<{ 0c\ ?Z$с8L ىj ?}+XQEbs &mh'%fA,Aiꯑ~an<6"Mv9@7ݲ4TA+\#ir)IG}It2hmTq|=`9ͧl\hA-9=XQ9҃Z|طyW[P!s#VBz̕ uUě,JWQ4Xh-qD$@G  !3]){⊍8)FS=cCcbbZCr]̭ͧևpJ\F KgQY. =d &p>;4x d*!I.`ȵ( )f iO}Pyg _N@OWX(^ػ #dp)arjʧ{Ӓmw~ۙ=3vN͍-TQuEHʦ1![GTJc@ۀu%&[aE/NkAϨ:t?R2xa~+/?Rti*D2ڂ@efx?S&5xXyJbs6URIZ6Đ 2'~Dd߻02)RS`[3L;B$ &g`ϲCzU5fJ FDegBugYƮz"2 W?e0w _Zf;MW9˪;>^DO^R:;=RV@fxDK[V8L5~K@= -ƵgŊ\ij^w=K/&|NN I4!0E"ܟuljEړBa/m(i$is<=K\r'MXf[kCE7Zg߻X׀V4T12z$({5^LCGH1hiLC\͞r_0,X║YG}t^Y4h0}D8WaxwթCbz vP~jnT}^[ue~ky^d_S&Ц-5nHlpV(̱zȼJ`L zǑ洂" iA/9HJJY{C7 7Lpe0XxW"! W߅ByQF*R " |2+,WP[zJīKFg >t/~q ~*-G6ZI :CaBq=a9+<A]xӹ35_FP` ͦdv*l~ES2sT0BR eTm7HVQ ]E\Kg"C^0'v欴=:4^,,KEzn: )%s n65 !nglN(W* : Oӱo,7K ͅOm niBi"ydf >9WB&:O3qKRIA؁-j+ȶ ِP(\Mt0 `3ߴCt<ΑaQF׺,ޘ/p, ߼{q{JP% ~(Oq*Quf"8_{ @e-g.RӡPyuـls w^ HLXά"7f~CfA*P%z,'H8ק$vǘξs}|s\& s=HqrԐnլ_P#f`r,8rIn=zD57LV;K~^BLGN܃µ^([6U*-#Qk򴰭ϑ^>-9Mʺ0^nGB?VC*&E=+ n0-o&|L@"L_T_3eߖǂGz G!.xYry NйXFx2Ec-g…05I 9nшg,BrzSmz"y+ל] p 33EUsh "`~-i$SZFƎ4Nʚ6~xҐ/`zcqoLͦ.azv?<# ~vZ"Oyu6PA}~k.\[#MaQ򵯍 F4?e B(Q 3peםܗ1j8ٹ* X҅3-nT\@ x5p͆1$oS-4X`_U9y/N5 gRqIfO+ JqXQ'%^]X sGfŕaL1cd(iR>vg-(/ D7)d'ږ5& nr1@rE65AVSY<獻L+wUMs\[^F^^дLG?(u- :6\h(ihu|g=P<9bWΜS?ϜtmقVDDdw.`Nx::˧ 63&T?"Zpk埃Z3s~~V--pCUrѩv*UeHnm/6PI?SA[)+#C< ~mg2o?npPɸy 04) b3 5 NㅣMϳb:A*xo<+ O|xqO?=}C/7J?!,aZB;:'< _yw_$S.:IŚ..jJ˱L׏#U>wH\0=!34!uv&c :PٯRRQdZIj%q k_g&Y}9PX:!js P@%FۻF9ڦPX{xU٬s9Iu|7E=ȌvC\oQ-"Zy| Ne`2hP<ՕtT33ZٴYJTYӽ $(G瘘k@,1QK(,=.PcBMO$4c7i 6]i-xo`W@glWW4R(2h\57ˇ)jK{0߿=iPm^ B|=6{I.- D([!g8&V.2~$FE2YK1mOE8,&^S{ #,@hhٵ`("5z8@LΉf)t _.~Bk@znneJPhբEtM wQP\xrS S;."1Еx*S}; .Tk,t]>~0Gs6BP] z5 4ůnZ'г53ԷUW,Yl͹L<=VvSQ:kc\f@״mVabGwj6rUJ'2?!brGoI*0]ш{Z$. "w|d 'h\MP- ;/^11yQX-3+&??ylpav{f=EO)'/9 (:<>C)}GZ[֛@MEMf6ﺊ݉m@spU^{ۺ`5UOP<iq|x`u~j}ի,BX|#ǻPw4)}*1'XX ?ZĆ|09ѿƴO ak|%w;frkI{: K;0ԃl{\klU7L7gVvլz)&@a!@廅N[9^&yn8ʋӭhpQ4pd; &r E^/;{+SA06T'DvJec^@x\iqs  7' <ڃܳ%M !+1A]tfBɽ8VGXw2.UR3jzlX.1#Timʧw'8껨6~vB!`FLQv[m&#ĩ6G]EڴS{YYchTQ6P~z37?X.lEc%q["u XY]8GSrγG-U$]U,:6c?=Yj(FVbsf3jGnI&EBdPNp~W>HlС6Mv9@ "~/8t%\)ShKLi(xQlgn(vrOiFNQ"W>1<\xN} iI-'C |1iqgg:H Cl[-+isQCdElftu.0T%2/3d,W*[uŗE@!ϰ@h:8){ths|>:v6xM@R9݌7n۰߾,$Z<Qk^N 4dLHMWCh>*pfsw?ӥ]D(2\s_jGpCTKwUܛ%00SSdShe3TL<9wXsGo*QNrN@tJ̚dK؟'ci#gZ\&a0g%@{5ix~ԇa1{#~E5= =.u6WKRSK8EsT..V3 dFeYWe*m>&7T@{Em9oj[띝vkuVw12=5Xx~ `<)Z%e!:E(V+ցHO^XJ*ҋ6a6ydΆGPHS_*ASAq+aɣG17|& ,nM >aO @*C ;A9˸C8f54gjqçOObEnH\%A.-$O1,O;s%r#rT ?5uFf%7eͬxF(UC?ry"R6.KѤS_<4JxE7I85nBxq_SW@B7T7:@1f1؎ճOTcwϿd y ;?[y >MT|żwxPɉ\]:a7p&ﭘy[XiD9\ə1N>mO}y+l[*wx3 ""Ø4u9n8kf-:-0Qxٜm%r2yYR $fW_ 5+Rq!$`t0/;ViC%Tg}zm>. 6kgHa.pM[F=+LoMQ,Aé@|@n%K,,ZJl6# >+.CejFKt@HWR[ 7ބU?bD\}׏9"ġB>"1#w-i88dl8AVoN4Xٟy_ciNרRv?05R5BEFq&]'!f2;yI nR?`֫bAs-@Ga36 L3JZHmc D' Uz>- @"f^Hl{a/o8.V,~t4إM6-X;lZ:;+S2gQ.+A;4JsSB3!NlxzI)WF-o?U!x|yv0 Vx?shԓn~Ū ,w?ͧLÒ3W-ЪMp(.9SԧՏ<{,smS -ChQEZFW܇TR>P@]bS&_eW4n}f"%b(sz>҈/r7ACQ=VZ? (yjFԣ$Q5ϗ_cDn P.])% e\nLS:E\d㧙Jkvvf"ovآP]շxCq:e^έ4A[sY@j%Sw\QN-@$U2m-%P iO"-[K2Q6~2F وU) *%[Ĝf>\E=#dnfN[Hi*"wdv.C8u9vv +2[ Sw{\̀7= wO7ْ`aoMaAO[ªM w>={trYo!j~6]*L'y2贕kh=aúJizqmd\m:F j鏑j1}&2`K<Z4!aPQb*乳A#sfs ?Tgvz={ᴌ(dz-ĺe YI._G6Y [HöeӒIG'3oYAjDۻ=L +QNPTb4B?XlU0S/" ]D:%h,߼l(r%w6%"#aNΧoNPU&h*1<&,=$tu&9&ƹ Y<ա 紜Tv b`cgﴫ(մzf$`6€?o>ճ5:UM##X XR-+ḹJNՑ7C^xmG&%Õ(vXG9b8X9[y-Nr6@^90nvADI)"FIT8bbnf~Iz/XdoI+XZQ*4|ȧtـx`V㵖:+QbA?Hb,`J~t7ʹrVBgޞg aMlu%:tq,U&A9vHI7q4C"!4ϻ<3b|SPLq$pbNQ曑Ѿr]tVE-/5 "=$uƤx9 .Qآ| uQt2MU5N1V 5?`ؕ~mr<2Ё6tkPūxfSRm]0U3Kh'N׾:E9b+oMA㖌!ue'eFBeS]G4$Qy>0Rw0纏C6RټwDI3¾E{F H,3׍.>8[Sݭ{{h  gK#pZJg;I1)lYiB|`q 3 ų`G0ai-4/)p1Jvnr.]i;=F,i^Tq UEtbh0k'@t6qWdfcunX#9 +0zәí[wZ 6{;lY}WbOU '*лBOp>36C \0S!3跌0 yDuf!cU`V\T<%pZ c%E}ˋIh݂cpZR\/"~ktaY) _׮,80u@wnϠt"k#bqOKrմ Z,jm~̤9at4Mo=KTVa}ͱJ;7GA%8c~Fs//ձAou$q>~3I03oqtʥc EPzm#5_G 膰Bw LrtlNI4|%׍>wuwisZb<דZ#Q5b6`/r/D}~ƩٙȖPX F#˄VHΆA]>?mpwVȂfR*pg7i2GڸB\H^ޔ0KvF`ARV'/*VIpg8C}h!2g:=eRjoӭ rk^FApK45UIPڀò4Kto{w 2[V!;Q;Wԉ/ı?QLiPZ>1###TK=FkD!Ծn IrŞq0M%!rnپc~ 8$'ÂB}HhGI܍"%w'JG'G )dYY{mmXg͘GPrgGXW-OQ3`8)vFWZjRH;e^HCR}sHe<u(Y)mv]^o #//q $F31 R bVY"uȬ?EF^oT8רJPeG!»KGI|6'` "Ux9#>F_Yn2d]Pvp@x9FV xnΟ3=TMD-‘X_/6==!&:x#` ]: ow *꽶rsZוZz=>~4j [C?DÎ2Z!3/4 f<)zD<_*SL`dÒJ[yfTf$1;EW7G&#qDm_ eC~TZq4~`SֽNΊdX}[EqJr<}a`ԒJdVuvl,Fղh;gfG_B V<^\XƓ/dMs0W't6Bxy `8--[i aA8I7ȷDpbE%W.vIXK:]id XS];S'b?X~Rv$A_ҮAɳfc-5m*L2UOiU e%A> ba^o#о~T4X-hZFE4$yP/,YNFķ*nP ,1DA11.a(.M-+sx}oeϰVy+Rͮ{.?ƚNC4w1i8H9b<!O N-B``k>(-(-g"X+qhL=G3 >G7\_g1SbY+y$%;uRF+E9AzK6KH! yih+-]݃ ŘUdKjfĎ w^è8}\PmGn.PcS£M'a2IKpRz+ klYTKYTA)zv]ڿZY,/e{ӡCLw28cO$VE3O>5,7Zi6!sᲝH@BF v|nGizOiȧt`^\NjPwio7QIWn\Rv2?61Z2kGxlaNJ1w=J0v ? ^IC*4UJK4%Iؽǘc3N= یa.vnݲ>W>+bǏ}M#+dJYۄDbn6ǡeWUjgzb:b򸫨@N%zM"l];+fWvLxr>楱NkneK* +#GXBOiЊC/cOsr `%\P(;1\9[-84-ҿ2-=[gI}s4_; G 'eBڔi^o0Pu&h8ɿNԻxډuXEb MxtO'⛛p%إl7.J.#7Lm}eB9+;dѼ?q."K) ulˉkZ̢fSk2QѮc\b%%hDUJg1&`x~u=TYYD p#-CG*Ufh7?"1[T|s#7 U? ?5RqlؠEjՌkݤ~b UEsPDۻ<s`$@~",6Q/ <.Wze._6gʂ˭(k)V!cUkVQ.b=N&= xv H]k+slHBq#3N$ozmü]yat22\V@5/ld 9rei}t˂w3+,LYmb*w=&vSwiA|9Ck7="=[k"ro!̵Dg>i  wkIth걄<1Q<T$Fl?F10N.RY"^m;b YŢM!J30,TEy}p=ؚGJZ2bݶp#zTW/t Eq)6jO^I B읚9U W߫13Ng 3[+:s5AC_K];Q/s-En&ΆNܫ1Y3{đO4/OƑK:D W3QR{D: 0<º0-jL#7YaOP´ZBhii ץJqwsf.szc3WxܜܰaH::M)G.O SDNqg?u=w׋~?3VKe="eFV>5VVT^,G;9pi`VQ %'ZjL"/b"Ƭ=<9qXtq7[Zi}wjG^Qv *S>Fm^kxhwy4mn.LBFa7o}5Ÿ+ Ջ(rqjZi\`P3+!rd0H}ۉ]a"G( 9\&;P9vIaџTD8NOHWh- Ex_40i!vzeN=Pv/5!1iFi8H/c$P[Gl Wg!+KD5ZdZ35wX4 v#Te$3BЯ{6sqV7~ .*fD7uGHCw9r9_q$  ڛُK_V}d4S4EaW/f+W a*$e4|~!`vROqa8y-O>05^0l({R?FwVߵp҇:գ=]ȘH`5#~ pB! %]bt 4B-Rh9ѦevݱtQBPl4tzEߔ2gk˂i6V ոrrA'[ڶ:]r?zt{Mh_8xTっtE\tb~C*FSÝ][,RHƽ_.p1M"WX3, yrwc6o@i70xA@[€}.5bXp3u lTcLD+ؙݘ3eѓ$>Z]FxB^7 /TүV2 1y?cGrさ3ϙ,-(as}I,.ܙBug*& ͌3vO:%}i㫼׍yt)v!_-`r?v]7É5)[})/͏?Pqf;hόAEXk|tv'ֱǕK ޭx6q D2+yE̟v.aA[+5nk&Sl;3ܹǷ1yǝh> @:NIօ ;2C %!} xB&m"I7,R`I6_76T! IBO oQ!k؀lfoc8r!l̆,k=Pu~ j?^w,Dk\b7tގ~ 9vd9y܃T)ٴneS-~$ InuD7`=q|5Rz-O˟ .B.φ34ڴ+Zn[|;%qSL>42l 9I 5H8va}ۓڌ BI eTlb8Rb_X[m7<5xH*ƃU4ʒ;>o:?L390qa-j&\sl`H[/-|@>oWq秼( q$(P?]*P[e}lksZAyp81L&~rŜF }$*(3WcAp r~#m¸T0lk,ȽnA鸫fZg9~I9tq%` \ 9EV!amK#4RBX\yW:]{OBb'ݶ @\E"O֌S6sBTil]u@Y232IsZ j3VWCsHй7G &!)[}!ȇxG `}[u"|Aka l{2Zno O_3B#d6 eTG]E*%Jt`ѡ## 4БWڙ#I_7 ?jg|{:k7 h9#3GKApB*Nap]*?ǧ Pѿ8^HS = ̀OH}g\":-ʋ|X0vzh!M28f}cgRcT!7HTϭ3 [ n{fԆ_ЊEP~ex>xS-,wg\Bg46 |~( XHKs"n,Mn⇳8\QTV?OČ0u"89s#tQDS)ȰRm gڛA򒠔N&)o7U;j( d ,+JŰ1WN(\!9I; yQE hSMn?{cʚx~|/x[+ ս|,^~[NX3MM'ھ)#28[,J)DRXg`SF{WWQJV.$\2BKn[Mn"rA$_o*ObqAu {F;V֦(n#u;|x6mu?/uM$k!z uD9CU{x|v@#)d&4 n:U{!'{'mX3`"JEܓ&:n/4+؉A(r 1AMҲghPM&MnR2Gjl7=蝰hi%IDSH)qdURF+q,Nxr|bիrс$7 *d ɄH"0؍VZz-P{ -p۬.-\d-5Dw cQ ⊽p`rvEoG YN$.cȝHpl+L_Z% %[Y\?H%cj[}Wŵ%+bo&Ey3v?SMÒ".++ jyVt9^c4g$G'xoV0{So4Iļ{!4rfl($I -o1a5BŤYv,;Q wRꯠzUh fȡe3[4v,yøTL"Oys}m9<¼'*OpUIoc_*dgs <]C.LFƫcv:)ۼgq;2W} j |ҤC.B.8xH!$z:vb-ٳK_ -k"zgq# zF&kY  JNoC/Y|oX` #= M !^p^K$mk:܃]͠BvNDV_c-mҹT!Zoc-._͋Y= Kꨫ†"))r2Mdnӛou8V᷿Jt8o(>%+Eқo|= )/{h3zr?X-bvFk/b lu6*5 1T5,`T;ǁ#>Mn0upy4=\9;fwK^_5_/>O'DFp:F1W oו92e\8EUwH-.P xl~'հMRKMuHVmCN-,=8/j5jj56lf9a"&-XUi7R%+Z&OQ ng\qH>0Tճ5VZLϕ?Eyv8,} s!+^Jسܷd2ԇ?6-ki7QY#8vpA\~nfg㞷r3`sQ`ei #jyĊphU Ր6:Ȼ}b+A _vCn<}s ~Q/+?#tv7?)%".ͲZz$vK`UU2_犢$0IXgxlVM7 &[>w`wJ52%!{ܑ皱r{ր:pN{#c ZCvR m~͔NR2ZY<2VM[d@ =Xl/p5*ţ ݩ|v59po;ziP I~S=bG/9cv큕4;[U Pa롺?/R Mћ{cHŚsMb"%K{HaYKZϋSWRASW0Ŷ!q#X!kou5]; ?2"&E*Ut<@̚e z*s)f0U_f:8cdz玟io43D@ I(쇷潨wϡp>7w \nϱ{(_}Mšn.'K\`.n{#ΓbzNϼ\Dt?u# /e8GCՊyr erKo6bLƃ[T^&ϼee#B^!/N@4{ͧ8ʤaWXώ#,knx3nK &T8NJ$$t{9U ܅l `wz#_EfÀJӁXϣjsz椔g:C̟׈fNXfEn][q= &%S ,/rr:hR.S'z5"|Cv]P M)_Wgk4 AH^M}HvXQ1Ib93PF˷k;Dݚ[ݗX,]6nmӮ1Ntl_e)󝋳szMJv&R/u[]YEM|PPv0`?y~.{K1`sa1.*!x]Y+_C %jAD̴. }.~uHMe%ZrcC6p u2Lq&sM=d0 ^0K'SߖT iOtF?X)xIV7Z$ڡXY@Q4UgԞb칕D7.6){;1 kR5ўB;Uя[v=9`nq3KxhsOc\r>tu`$ڪK=d"MqO<"򪬶 28"> /Cb5[uQ]$m<xP%A,lHL%uMOzALȤuo$+?z0Ds1p[/XStX x з{;a 0-:6 \0~B'Z_* F $TPQRLC/b,ܭ܍ryֆBJLL@w])!:[!RichaCEJ) QԜu Ĺtɮ MczkHAO؄ĂӘ0?˺*9QA&D.E EZD4EhbACG^6%Цǫ1;,%ho&Ykb33*͗v2rHذ-` jxG|%)iԃ߷.\TycuOFBLE+b$qH]k8ng0PQǐ"zGnnj)a`.lH W( M'< xS sM;^| H~ӑb xcs3HQrʁWڈ&'xy%+׽f1y0tj(G[4uNѢp99='iYR.7u(1HQq`Aݮϒc"Vy %=bi5e1ҋumi]َy],vF$@u|+du}]|>nFp׵ oxU}~ #Wkf 8Pì7IkؔRӫ}9!.O^P\;1m>3!x);bY$?$4OoW5Q`ԏl:l>o97YsdրkPw͢fʣF9|7$Y?y{iG` ,@=ާ v`fx^t<]޽*B`co Yn@_҈1|,ώԸW yYtq-tM9S+&\6q! mLȾPơ e{E$,h|{iل!ȷCRp69x^;ْ@S|'.ogtFkgv׍x,ѮN$! EZ j6cLH9N6a02HtV0: ,`!;" :c̉"- Rvgf͗5c`fɷS2,^7ta( ekWQ4Z-g \~T!(rzkǺc, viGou:k೮e^eۀ S),N]MF{$ p6=kUyT.ZkkF e9(7Tsڵt/ b} 0P{vb| +ʁ#604ϣhN`^tYoI54I0FO.(qݪw6o8K{`VIa D&d\\Y'MMyg,퉊rAf`b>zD}R`SI}t =Ԡ>A˞q5SHX1zJH8zHٮ8[߮!-j&pHd0%g$bRzwˁY6ZxouΎLЍFȉ3:IZ,Ķ39v[(кJG nE+=&#^$;4.,Q ? 8ba hDfm1a<9YmiPY l^( Ҏ&bn Y# KA-e)gnl;b> XHQ蔦¢.]2egRAZ;ojZ3} <]ىv~ڨ[D[l.JJ|в'%?p(iJ!Atb!"(~CFTLt0&nhkkjU)ۈϔv}U/gE18!W2݅[~N 耯jSd%q4APbR6{:>W}֟Xai*H1LҨVJr`さ[y^&RZNu7b`ۚIߞc#Ѭu2b;w>a*G'>^$OEWCse] 3BVL]^&n4/UY\>Ԡ˪80֠ % Q6ur;= A #:bb2 ')Uv 8 oMLEO/jDch(t͎V^ Yj YMն1ˢ>^gnET@MĴ꽪5jTod (Y$$xҽ|h技ݜ{9 ǭ&glWv1u7WiR6&Caw''EWwӪ&# @4{XglO-}?.*Vo9o&8"TyiOǞJǹ ^4A [y Ҿ%/$xQeq3;'Km*rUrV+ɝ%-lqT1{yZcKV{ζ)PTe r&ώձː|1rAگ܍z$߯A:mLd(LA/CoI;RaPYL_ oĉts#5B:s qֶ9JOL%w$BHb*#G~Lvzþ[|ĩCS'?U1tBj"bdlb$ȁ7#Zg1sKA Թ[cVE#JL= f3>9콷cF*hO )+P/z++ ZO1>U2 crjwq9!S<ӄN/;#".Ceg䝔LK@ W£Ȕُo9^RD6qAzj h6gJwI__NnMI- 5%qԖij6FQexOQp$ w,illƕx=ghWByduv0ֳa?"#4CcB/ɥwҦvgQGG7\Ǚ꘵89ZUgdPa<ۄ@c[ l,|",AŚ;5z>YBxd)7|< F5zNE#jA d X6<ˡ{iaC436r`Vj#GGByvuBVϪ:1%F%731,= uuj`ioƉ -avm' V fS|ËD w OZ Eql{r%PҸeB#%.p7E7e"30KM'cy ͗7X{:QK␇NH_P𗌖$a.{jq&՝7gC G_^SWd˥gˇ]W|8 3XSQHi4+nBSHz0ʴsX!ݝ/4”6i%Z7H 0I+hwR?M&dgIdFʸI':J7Tˏj0Qk3~cX#kww\!RWtX] sս,q뷚3"86Kh8A,z Ha׼bF$Rk=b6mpn &*&=РzX.dɪCw\x[#nn (ti`\[J$wi6diF^ə v0+рrt` -= ˃&MBO.A(Sb1TEnwI[\A0%bD4Gbgfءضm7Vgk$m+;UwRs'EvJCm.$/'**hʏZoꞰ2πgv~"~@UzZZVņȮ\leJ3_T_଀Cm^Uy=Vgͽ;sUhNh\GǧdLQp'b'PĂOƒm ,0N/ر4g(ZjFƘD'zΫ}R>|i@!a~\uGR&y]5_ݚKL IpWu\DFXEUW)gEBpSB^Ȃ]$f,'wN>f C65Y~3,Gu{`һ}(+*dW>KČZ@HiZY*Z;4\/7m㻱?&{+JD7<۲{tH)l4H\n9J]:_lza05j ?MTL6jQ#be-YVMg@PuHlmwlQF"9]?W\xy߇HDP 5q7L" QƏ3Y(ۢcMLV(B܂aY}\fK;O>C:M*GbclӭUIr:yhSѤbnWtLIMHO $HElH]юvhtڞBg2#,LPt_74:͗SK5j(45 ظ !8]:?$;75aQJm6{}:m+InK )`[N00AdnJ3 1ĝ_d7Xt#|9:3 :).JNZL4UBLq J\HIgjo''@hG[ [ɖOOCzcJ=X}M嶘WaV<쬾1GxWck]bMʗFdډ+"< Zm2x%HJ`X עЦaU9FU]͕|1Lޒ9Ƙv_YG%kث9#Myp,wQ{ Y(3}J^YQ:2?S7TNng齍9eB^H?ȯڈtەznDjƧ09]#l#n@oWHMbhj{{+j`cTR! oYt4/w h,D*yٷ}N;15潳mL_nVCt x;HO0?A' ?oh58)k?Q 78QXei抝A"HGnϤ s$Q z$qLR"vr( lȌ*ʃȴB>lVkyٝV.q ޑ_T(¤feH Cf L^GBd˺7-*ǭ8i85VV:~K7Sʨ.^wEPor?Z2]p[w~S\ F|1$B(:^rkKs57Ӽ05Tԕx0ajD! cQS?h9'E͸1>&?ǟv>RT**ZolWc ;}rX}4Qhp_h203&ZJ5wKU >XWnW7C4Ώ>wz t"Ty#XE5na ٶN bطY7nDU80CDYyҫbl2A²H}*nn|SR=EhawKN:Nha9sV\7*eau{ǕbAQ{`2zk2"5_Gy a=+<4#+DgaSL9fBFu+A5 aQu_ QJd/-P{r8`]U/ᒻϴPfBdmWj# 11-mJ?%%ٷ9^Է4RخbpuDr?k֢\Zـk==1j ;>X0ѠYxJ;.ªxkAjƄbB^a t8CWc5d1Bڊ4GHY?/6z1zO@}Ϻ4Ze.(4 nidn`5)z3*mdn -Ɵ7đ!| 8@] [[˹ZMҩR| )eo`9;_˺";g8!CfY% ! njuz}\( ݲYI4dlEzQk%elL_P%I(U'쀢I^(|Ёo-pǙ!3`NK{b~l/3ɈWs!x3g8ױVVS㧺8d{0zP>}Gq4w%OmꞈT\ (–s^ȥ)^ooSʘi؝"ޮm%Ac-r/y[e+ؚgu;YA3r㹘΂|k΋C&}9kێ2\i`P.EiJ'@1sDhAc']6%!Nbac݃(նhƐXr):3="kZEvG4 9G:ɰ )@= Ons_۪fֽ{xi d+ H`x~Pb<+4c%赎h60jga]sD#Ԫ 3q`*y3x`F! 7J kvd@u"m|Y&jh5YGH̤pHڲeQyUe<dyx5;>XI0Lc9;EJdPspkev,Taus䲡ʴ Ŗ`5ԞΤ޴7 V ` f%*%+ǂ?M _N˔leƧPƟ#9ͼyJiR!^ |(r3 ͻR݌^ }]E=xL_p' ?G rMW:GV% &3zuƌz6euqd<Ǥ9()d}NC9#Va۾u1Zi{Ey+;AJ`W(Tq)?TbO$ &-K$X.4AfӪN٪ =|g N(XL~cZhOATP&LJWt_GFuAl0Chw|̛L=U$c,MW4OXLx^_O4iTÓe xDb=W߼}X3 /[iNbQP{}ovfoK]X6=$J'/igWAK4֎mK[,o5;knw ?c2 *rGyT'I  "?yM 'i֔Qٌ)pw2n׸V!lY.S SSK:s QA{m%IzTT]\;$Ȧ ^ᲯqEOdKݘxgsG|qCȴ'=jF],ErOB8SOjuOUW= gg|&wJ" ~O#a](EgVU HvYmQfXܛ@X\>?=.$b(@s=&Lv-/>bfA/e=[! 8(fGT*vڒcࣩWw$[~q`i;F~<)JsA8sN1gN̚&EVW9FxwՕQz6z/A+SU丄rkuD@#}D~H!vfG)cй DNÅ5LRҾDt(5vL wQE~Lqbgh~f ] Uj{k믵WP\W@33(Û,i[r:ߞNAiQPA1$|wiL 0ͱK1Q'hUR 3[!+_%?$nM+R3ckii;7a%x4 4<@~RpJMK/}HJ'rݜ8Э *6Rzer)w$Sǃ$wl*AF "C`wqȑGy ˆJwA~yke0~g}D?Jٻx~ yW-x?{)VN4R!Z BuHgAfæcHYȉԜ/99OdSP. }:zR0픊\y]6S{NS}./P /_HcX})فuV\T>2]6-/RH6o%m˩)` umk7=gTU(f() %5-m8iP7M.nLAD%fCaH/X‰W'A(M#0#Yp˜H?sgt!fs.>QԊ}tC 5wE <j0k{ۏ=ھ/=CT1].2pB%2; LQilzGf;TI1~]MS\?qI}j6oLJ\ڴڛ>rtY'+ g1*`ˇI(G1 ME8h㝵dTC5J -S_G+Z~F/WlB^N"::ۀt:tsl"` J ˼CqBB>Cx/፟b]%) 8/&2`"aUPFzjRh/OG ځ̒,J% j9ap R'~ O'blZNfB}ʣJ͉ըBNݓ߹&i+G-vh_ m ުZ3I'['Rkgźo<PS|1-CL7[3jj' rQ̲rlˌL%IY03J*\_2$9zLNtIϮ,$&ңrm< \*5UB{EnȁN靈W'hЗ1.Iy(L }B MFS.VVghio%fWK2ٸ<4akZ! L3p*ATwt Wa{v D.; X.p'|J6Yȡ RI;Tc3` Ǎ5 Xe1L_( 0|7h{ڷE8z#c~BnH+D',HiT1s~y@c&dvIf|*vZljfA¶24?x"R'8HRZBa[njF2{R E&u 쾨@(#%fz 0N.?foIoD/\NuZcoUuiRjfTS ky4T-T=xYuM?mBVNx^M"΅ň(Dغ$CKr\ϱ8d|na|GRDo s %?"HjY$I{CCgD]#iid:\D*$ˤeKָ1UNL䲁c^y&5\nba.; i]d]97R3h;-Fqۧe`o(^? DФgQV3݈E֏&녊Q!<~+[SSá=!A|C r9hU:UFsWr%}w i&ztn%KE 3 ei%`Bٌm'K] B/_fu: M_ RC3o:rhYhdR~':#/Mؑ ribvrSQ*PzynܸЌQ$f"q.37Q 5aՅݿw~01$cg#3.U.?wQqW^OZ]bBn bXEdsҺy\d. q%l i2gr`n6j\gGtiAUAڒx\,^4XA(@L O8?Bs<*$ڔ\"Z}uH)#0eܞm;Ag?/Y8_UgG&$2u:6N GeA2r'6 <?Hy#o+}bX]xTӉ\ydgM[)Eς |9*DGr)Dv7m JKvdX@~ŴaL`\qyڮ!xoWx*l γl8kz{w mY&X4Go7eJs`BRAjӢ L?==\f0Y݃`hՃؐ_Kyl|k`S*烒K j;#%zp5Σcn+f<,jh'BҠhe lY!rT!C`)Ϟ(vATte^"1\ϾsB9>Hsn`v.p o&> ۓ(LqZgmԉ>ڢB ehpwNBxG"k*XI4؏M4qy0|F:JMQyb_ /Lckz?_OK^I^hYOәdд?^Yۅ}G**+`ޖ(2=#ϣW >vaNEؿloΘ4Bh1hFX#qWW{R`` RэuRxwCHSQM``b4o?*s"n|:J싖m)>bw[rߖA`()LM֍x% i or!heOcfs5L>&d@|:-32B i)Ц]07 GϮS?##"H~;ޓKLL(upL518<!~`<5}CXW,Z>uPزc$OcdC搯tNB G;{H+?^Qdj]'ӌٻ!A'XU2ѳ M aŋI 97oUP(u5?90]@$ꦖLNE*k[,U~gkiXª43[9l_QAN:$#`l~ܞQn?;p|-mBIO v/jڋ>Zw]'PVh ~"t4{η>0I<'E-otUScq ;(#;4/?\g/*{ S&7k[ֶɍjI>pi*u 'Uͤ]33x@$Y$Զ3;r,[r2OyEUU);*FHy!m +&qE]ٸf\Ğ+𗷣]=5D`P ju3>d~"|S[ ,z8Ҏ`*4z:RiǶպXْK|og[)J缊QDO(d&hH3%VF.޼T~6W O7Yx³鵩uKC4fU4֖IPZ2:뽫A^|I&3$tzc[l&}E&4츄EoTf<j4ht>AW" KqOOqig~za 9ñ.dQZfC[U6QF}ەuFM$\-;Ri*C4rc؜X&jDt1&zA-dRJEA޹t¡\ Y݀u1_cWiuӟVKXгؾX#&#totoV7]R%]\l:xs)~&18+#*RzZ6A_:Nzv`SYB}wQ%pVg((m;Z*IwF%9rΜoo-dtZҩ:"aǙtP8KcO$-Q ȧnY8l<8=? ML%j)z .~cTJ8/?M\ݤSזsSJUJ%Eʺ~?r->2"̬)07[z-Tq!D5ݩuMyRe1PfHߢ KLPf`p[~i6޾ʒE]V16ԃ%J7~G+/NKGkr493YrQ[.*6b-uz^G(qRd zm #(d2Kg$ٚ(BW׺>fi $Z ېѱ`X?p%(R"吁{`>? B n~5X^lDU7ݑ[jLiFwUxGf$"\/#"PŁ'AaǗayΚq1?e ;`TVYna^*]F r1? Ңʶ<;q htS Sȕ7:BDYK)w?w:EёVY&Ƞ1aߦ}R{$aKAkƎ6n,lMmTì!eQB`裙= ToSVO[w@ .+9~uCOU u. Ђq´doQ*38 {ĕ te~2.oRy^NW>%FG#H1\=dvjSKw(@C8%%ᾂ q<U2_75EBqײV2&ugB?S7EkGri\(h<y qٓcG%ܻcF gFkΠ !Y<ܾ<`=94ZzE=k8 *Kdtاz#hZ|SD";&]lLbɦ47b AS_J=3c "s`A0x 8$օL95b/ *YvrIo$ԩzgu6bziXiҀrDH _hӌ$5"'9`Y#En`0C6:24a BXݾ0giDWaD;Lo8Z+Ħe`X{e# Z~6/ͧCHnbTZĔn%ַ܅m @^s QQH'0TwB\lLD:,#viaȱBLO8!s3]k8wPrf1AwܡǪl`z\','{aR~|d-T~׈!o(\!4WYzـŬP25>ޏo߁yUpK][}BjI#=_[t;ݳ!>X58 22RfzcSZnFs&HhO4f%oyhUxӍmT#x}8~hFO?w&ܼ6YU$"&. U'wyyNlH 뗞wy?fm2h8+gK>${ïwc]%ԭ3 9VRé|ǍX`{xǙB Yr.#\k"\!,swXV hE\j"1zFIӷ^3!B:1-|{ + h=<w_4W- }Lg4&3!(b"5t픺@&nV0A;30)&(- X0wjl* QxLzYdrcnoq͵ W){pVf X3hFLBU@ QmߝHkz%3^ىlLi7jpIl6ŕAP59=/E`lrHvR P*6.)Fqgy/S;t+T4UoRxJ4i[oT/ެ~k|ޔu0e|q9D7=c,́4B f4e=u}+u;;XA?Ӷh E~<*)+.)Y0 bVHή=j@$ :n9!2]8JkT{f+vs`RwY'/>bѰ{k{ vy ֕A`[9 "j&gfya:y XH#Ju*߂MEz+t0*BxslS-ҳW􍅣#|遬ӯJNmA^Fcn@X'%v|EPW, mr;N6CPдNnr!5 YR] X1#szci^x_zlk[ Fq4l ,ZsbsWH; ~eR#([w@)Y4MRk7EۚXygtvLFavWݯ> ŒqccCP[aG~yNѱ%`$e:0i!eܤ ]#@w:mHu-MJpc;BjGp}v f mчU!OUsA{v%2ZkCmcPخrh]#Yl]~ar؞o̶dmN6IeeXp#y>Hڼ Mɜ ]hgt3J t _y8J9b_[ɯJX:)g(]_(; ]G׋Z4d`0b cgČ!|`p'Ag;ӵfjQ.N!sPOql߯:Jl/ypʏol׋`~ʸ='\ EoO7B'a/0>-11 -.Km;ǤnpfUpt˰!*I)e-/K":ՌYy|x0މʯn?9c=-eRLGnQsDjuXΛ v<1*^ҧac_Ssgo9)_ 笡D!wEVӊtô,?*<]FK'c2">Zٗ$UfMeb'P L+;2nup9}T!VcYq3|.e$H1D2+ֆJLh@MlnVG)(r$l4UJVA lqEz!yGfl8 D/ezkhN]K1%Ei)22@/$4٠enַOs}jO"# 5%nC?8JQLϛFv$9ks1U8 ,cr `(5ɴXbgSB*Mʧ\heYcpN2_mЩ©~ubr*K`T1jj)иչ&fDRSa5GPF)N-'FՎh@ʝ0VP:DKDb6'YEZӚi7%P)0tyU;_] ?*[QTAMh6]o#c OH:~kאO VoL&\Mu9Ocb}l }.,T?J=ꤿ4JR5Lg@]^?Xm=l:'yƢI9R;ܨ-X 4JtTXJn˗ 45!ѹ,VΗ|j&0z?%2E.X;;e],L# IG9r?YxHBǕ ?Z"GR^(>f#1<̴:a>UGM9یr\ jM1[fHA5&+t6fSP`Du9޲ػs_AkvA }3;%=܇lEo9prӣ$q(7%U(e Fr/-lZhN8 ނ9G[=RV|zID9?@? &TY7q[-l[@/nlڠWgj4Vvq1>N$tlQwlIs5"C9Չscp(*`1e^΄h>׸>zΑP7'"ύݧ-蠝%Y2%|`j!HcGVN MB:*k)ox ;JHh;]@XU^-> 1D5ʦWuP_괔}#cN nU &^6 ǕBErH3|79M9}2Yf`Uj#y$guhX:6U͂QC2y ك{-E;3?$eO#4,™z%GWe#h28;jI{*r-U?|'Tio N?ϗ o#hȧ,8;#vĿ'4ƲBkdWcxhis0Rb"D=,?KIѫVկ2ӏdqO>e㸫ފFu}Nއ80h49EfZ';LD1=g?4QOEl[?c$'^5P .GSpXD z.A2锓/:Y:_P)9"{Ԩ 6mty%ʕaw%ݩMh:M-(p>ccRLZCs)zF'm", DY9TKs,=1;j80c. h y'M ~6`eS5s_Qe>~J*LEzw/ 9n:gnWg*4i/]c94ߌWJ?)PJi .5l=klRɁ։UuD}`jgpy݅GLhϩG_`uD%*V4b0b 9)NSۥgGWE|Py3D#EcoW* EĒYB*$ûxWKAx |Bi*)ig`Wi#88.3v)' -JP5=™rDԇBn_覾J 9Eh~r&ju{a_':-i$/NiCJP+yfELgFPrhF$HeX{ܭA%74F|ާ`Ő{:1x K90OJ)Cb ?V& [BE٘Cy[nBCd#i|RcL5;%bo/TphRij!\hiJ9#-@['MV o7_k#V9:' ֆmZ{O;?x!>@i p,r[t uEhWZko'.Z9.^޾gbӗ&w}yr]ˮ{?|Zq*BR2^X2U+3 IZZTQ ~j9d 3$S&ލ@a IGbP]-1$=N+!pmcC$M}A<@a+ $v?,P!eqO,9}PF'FMeQuo ,wإJu' ӈC6f|2 w}"ZI6]Z)pqRifWO2%|-I{ţ,%D}>SvFLsvk3Q$okmn'Z*;B:ydDhpϝBy$ J颟$.2cg3QWwWA~qwUHjǥU&o``뗉<CT׮UL>թEI8g:?UݶʫHf`gtM) xܡT`ɠ3rnJ2%NRoP=ḱ7ޖ:s,E,7ݺ5rg6奭AԃsZfE_C̸M_X4rCB@B/ GY<AZPt{))MȷgAIlCLӬBv]ÐWpe0g|.BܺasQTQ=x g:yP{VZ'*[/ݖDy~&DCZÐi&(HI1=>;ҳJzmXBMHL_` eP:cA_V}K٭CClȫEΘ=d 0"Y1nuƋQM52?ٺOU9hWۅsFy 5`~a}W8'Pi*@ŜEPq~=} !Y.ч(w S0ǩ_{elι/gKU _OѵrZbX\|=Ԣl4']iz"Zj{c) dgnH\ސź}mk1dN/z?L>mM>y:j|قe#ks/76 WnM繴Mߜ[J5dG+CFCE^>DCJ.[nR,aah!u5\>'>LҦTbOCIn⯻4J Zjd>W>K]7uਉsiyI>EQ˹"a@sͪC!1+P)B3 _1M$̵Ŕ#iXYW9žDca|]+b/T-s"5'FYWI4LIR 2-HiB4XI_iʖݜ[>ؗC$;.l׬)J}-d@q j4}D2G:lq =7l4 BZ]Dƍw5XgV`h֧+` 73Hze?^K|"&a+!O){ Z+!`  dTvͬPJN*tSl_,'uzY28JޢԺ8蕇yfCk+QТ,ǗZ9_&5\" _En͢9O{>0cݥ_" qqjd@t[ ?n2A.9 ΗaJ+zі$/pXUq\ˡ-.zf%&WQ$E˵YxA-Yz&:A"9|*b"rR7?m|G˧f2#@iuU9 ڥV`B^PP#C.Yv.R }O`ڙ r\-`]eiHTWhnqMM'LЈ$,Okb<%lsZ*5msЗn*]^גne%NXǍ;ds#v`ݚĮQ~ϒ}r MwdyX,n_A3Ud>ׇ u+&y%M|k 1 kn~|+n[p&wX'U3"hA=㨠cV۟2{) ]j[NL^5xPkw>?8[=8o9_ IObQݺg 3 ~sB{'c!W+Q1 zdBc>7LȑKD`4j ym2s4GSqg }'By#E9p>#2ͭMp.JJW5xڻ+.#GmC[G ]Qy]M3sB#mWTIZ_L'x~o!ʂ: a`4Cs^3\ih.SFj fwBԔӡ?Rzzp |`DLyx^N1~?'yU- qŒ{+9I_ɋU0?LjTT"9joMdD+XX;fN@yY8nMu}c:vpڔxuy@wA먂$z{/)~R&κlw6*LJ,-™hcB+nϘdT#P薃@0)1GTqoKďt]M:xDPk}UJ-ؑ.k q(~DǯCq iۃYgLƫv}0n>?#tP'$Y2R~E'9ԓ2?W~,@儀lf^ɒQ\ tȜN;bYb"iNI' :Ɂ(~*, &r"?lcb̦|1s%}"@`>0c ~~9K57H.S(oW}nM}?ġ0+stR]/iu׹QKżWi8i.ӫ42odir~Vzʭ`ZcSc=%S B 68̑_oSQ%&prkU$&}% 2o޳O΃Yݯ"Ă*v>yӽyh4:VEQk~՟sjmY^A :`wxFmH?cv.ڮQP(5SE[!˴]R{td=/K$& vZ.;tSd^F1S[Y>K2xKqDKL<ļJJ?ެFpۧHXƎd 6 NR&n1c|Ix2_lg"_1~Wam]a[2*CVrzxF^GyECJV{Q6(n.g4P*xo{X0G]hu_7&/xHiljژ```E7!Ne3)xȅ7L95?"MxC_݁O]Dž#ߕB0uP5* 9׫ .mЅrt1RH}[,*J>Ԧȃ\ [e^bG(~ˈ"`ƵUm :Lt-է~PBn'& cEbv8|*[\gaVo4&>ǩ#yJMgqa.mDP!p:ͭ$T->P.ض|Y~셠,JMdn0+6W>^oZ`cܗK{ FɖuSRKF"o*Jnlٍڥ4d2GqXjYyIjz:qBh̙1WzHOq̸jrOumo fqkkMǟm&koRɾf&&}z^DZ"eV% n:DǷ௥ۉZ#CW1|^A֤5{`XNF*Ȥ z"ؽG.mH@rtSʧO"F 7PDɓ^xD1r Dʭ8nfr6~=o|[fv vi>:U8!UI[npڇ@_++hOK{IGćv^1ϥ@.ŝGaYH$rUjtڢJpPV()!Ho2 H.~m5ӇB>?K{K0",|L [Z2T>P :/iyiN?\ɁL}ћ'"?vXяzPQ7?qR)k~QS 4˱5&OEey׏=(AHN)XsI}Ά' CI)5f~Jt>~Mchc8jd ;Tf,G <- EܩZ[[ZA_k+q^:h\vcYyjc^" b}BgZtg-q=$)J .D -ʕ̓,7@6# b8xP'l-,"4wj65IIEJG.e9TIɩ d@TDa o.'Bc.Ч;$s6(/.݉kJ~o yfAB&, _i\ ]fL7!}20˯w8烦Xi @aaӚ7AZB#vaϴՂw~KGO>q~?iyLebmv΢w [(i-.f]$p9HQlK ?#&u*H**^u۠Sڇ 43kxNk{'75f+B' ;cg%důi5 U@xxnoQ}I MEJ%ac$z^3=+)%)aZ{`T+?_m_h4@o ~ˇC=*JmC"-k6 i6 ݞE^`@iq@^1-Hr- &. ڍ|o`ѿWlbTwN n%q䬫O~,n@bXěC%//Fi|e\2ekhw 7-q#@ $ gN$FrG5I$l2d4MB5 IGgP @8+Z"Q?c;IfVy$s;[t#pRuq97~=Q>06qci:1d4Tfr[8蒅[s:@~ sM!5hDXW鞪KvD+A]?Qq;u]ݟYCIcy7}9sR[|lg8yr_O*Oz^gsYT9 ;Cz}Bsߝ'c/azөRD4<À˫̙ U.<(ΈXWm}8z^jVXA}Ap9)YCUjPFS ǿ=b >uB z,`~hM PlקHWZ&V݋%J֦ ҐGژ4smMUy} v̠-uV6X@ԲkL@Ḛ*,y|T=9AS^PF!ۃm7o4c78Ș&Zf Wm p k9>嶷R^Fo%KK%8v0PޛFmfW:Z|/۾ty%N;>Xj5z*MBGsˊ.Ğ3;OѕojU6m{r95 %gvEl2V)bF3εo{A l>?}xtڊI+|)wsO" j8 g^ ssVzR#jb&CHjpkD#E٣Em_y: zLYXPDkKG.ڴ51 F8}R6D*j֣Z(\O/qS \"!zպ3i>mHߪ['N҇ao֧9F(%EaѩRU<'Y8wF"s5αpO  pʎ0#`_^lwEѡKzL}3{[#ɠ7%KlfH\qRB,ٚP]~y17i6^(vAJ<@lRCge k !CnWmlA [>.v5O;<-]VY qȴ>rq8V;\"%@gQnƱla2<69ﵭbi"Zu<@:jnM ~#Hpwo`yi7UJ*?r"T&ZsuGozH)T@; gP0⯚}L!9`. `,(}jzϷ=̽|9ˁ,?y쉀-5dnE =kX`]c2񈽇16S)ZP~tť߹!WJYpP Ԅm/Ax9QS KUDݯ+hW\Q!w,}s isK׀^hmްW^=Zjhu8JR#b{"zchy'@0b&|C Z[pv DzĦvXmo b>cR|`;`gzw7{J_sH/Gu+3PKá t)KYGLivlqfa~zbƩp5FbT߶K ]w۟mDćM!9v|E.,3#E>ŵ&KdJjퟶa~eһ ;8OdW R#3skpOj͂򆤘UjӭC̝#Jr8;M}C.;/0(0wDys_3I p(Ҏ;ݡ*w9Y5dkQ/]K _ T\rqKm#k;D åc4f,s`*j*h]3ueOͬ1-|ˡQ"Dr!Nx2D ,|YdnZ:{dcIt<]|/3-;=|!!CHeBO.B }c`Θ2FCzXc8dd.P(; 4k <]p ZƓ`0Nnz<'xII6@{խ7"P[tVujUӶ0=e_ԃ^#rHU'е? Y .on d9=߭ozR0ǻ%d]Mzt@ʟ0Y'&H ^V,V':7xbVF7y.Z (݉WEj*-JE/9LAY9G=*NVU##z_2 O&.ΆIJZO +Y@<G ;nH[w-9Z&%('7.fO)p^N#\QޙЖ9f5r ǜÒcyAq $M%rْoo5U?Q 0(3(ii9bD=$T ]tۮjkSԈ˹廫Tc z X:#bE7 L;(xFAb"I # ju4Țg]\-s* \<"qЭ*dMZcpKT/oq}6zJAgf8+ /;`i)@~u'J#IAQw\G@1;bID{NTPMW ϣѓ4dKØzS1ui4F$`̿\;ydC;GrШ>0DBEV]r_4]xyCN8‘Fo Ob?>݃ء1Mg-4ՄX YA'}ݝblWtJRǰeY.lZb6sõ m) C쩩hCb>׬(4@ەUx6ne2O9vd6j&hD➅dN?A4-*~ +G6T5 $ @L%^:ZC؉Ʌ{YlQk!|Rn_6'O{,Qv`g <o z0o'5H?.P@ 2I/c7m@B!2T]NL=P0tmw/ہ.*i!=ފ^]!7QOP.qZ2Oᒈ^avE?!}-a! jw "zCQb^T; іT ~Ə <Ա%W!E>=y wslYv%F)󅤥4ia^SDtkĭ60O>̀MͰ2ɖ_Βq48Y7 ι^/`n GPtX:$0Jā;]TJ(fIghvJ9wuo2S1@yBmts~ˢt􊚔sBLtԸ ~ U4|p Pb 3'n| pU%S@lV`<}ő Jӕ($ܹZrzwd󛮗aMlm1/T/k/96)(I40(m$?M)Mez皐H8~y1umprÔRVDWv¨E)):t*-E.8R+ ;?溞2wnбHN+/XcwܥmHo[EVjKmcƲ] /p)7z}3][&2u׵}i.*, lq[malݤ n}Q̊J՚fUҍyΫ!1d5v:}(j˂eXpuX ,dju፯Dťt<%g]\`!H_ W=(5,ߣ'Q%0z0@B٬ʷJ $r\کp;!qFȨ&h %ܟ@˪ GZj{v(f5QzHSdĭr?.FLVC}ZL$;N%O@ q6ih~ UQ r/vᕞj| bHĘkc x[A*EWٛ?r|m9Da [dRϞA =zd<=,]>-tT0D6^bXsu2kqY/-zn 4w?t)Ȧ8*XzSkZ< Į)BŸrznVi1g5ͪ\E?2/rb(*JE:X)6by?;:q+eW?9]ZRl.Jg`*שK #Zӝ+̃r5{M҇=Ul2uH-W\=[ji ㎉}kqv f*rU 4KLοye?0AҲ g0 &Z~?g$b=T W 柝'.1U. )htO{܂]CR| 0HiMr^k!=ĽxR<k 0 ԑ'mZ:2|pk^>xX.'e\c~]2 c}u$m 2z F(S-FIrSg{ETQbNUn̉)a\"r "lߏs>蹠@ةxȲ/͚ݪ+3}QkBb[kgY')Uȿ Hn \ @]Ǚ)-8X2(4YDJ,9GWe8 I5字Kpp3Hvf4N/x1l@f?R\qqͯ74SdgP*ߕRι?+Q!h)}j7_dm|87ZjڠKvIW.n5B6['GP+sjƚs/=6lt`_Cx5A8yt_lVXJb -+\ufVp":|c{mD-egAEUzj{R@0Aנ~k{ ..ȟ.o:jQtV. i7 !`pMшǞ?b>M pC?8v#z=ugfM׶7E#AeȽyPa18k:ydT[]:"Iv$\= XH"V.+vqWR5,q*.[*,M;DJ"#5rgfi.$蕠B-kkaPy\xmXxQ1o{ ]л,HYEkVކr 5xg`ݴ3 8C'*p*Jp-> N ns燰D,w8|=` /cyRp"3բ#9&Hlmv,ge.d} iK[37n K@0 aF~meʲ1I)!k+iD*O N}]T Bzi05!ՙ=iGɀ٪fw|\泒@f`#+̵-6vS/0DתgSH:Gi{]}#Ãf P'Mm*B? <0ȿX*c4F{NJ>@yF8Q C9_=I3jkg<7 m@Qýd|+o]SVŢ-LpQ0ʳ/-Ul12$Ay|u@d!e:#~vX{&#k3ŗTccnb ]|"Ij%ISe턬Ws@-aH ԛIUZ]h0ߊ"|`i뇫mvz"\pI1KcNU\ x>92݇r+t UA۪Ǜt[cYo؈$fz[ b]|_>H. $sQEQ.,U)HJJU3߆JAr粇fKu{}c& 6'd!fп 4 <Aa)e]{ f~+*G6*GTSw;-VsOp Ӽ{p^l Q\ܑإbi_Xji_y7gyu&:͎tEVW(Bdb4=-LW.l0b5:m2ig&Cj<'oyV$Gbw)OA}G2o a!U.7-"<_a6}psLIP6\уR8Ym4IJ? *=.*.!A6Ptd_yޖˀ`媬gLd"jBfj":YPG l.WfPϣ)uahz/*MTt9Utm cM_s^|B؟1nu!' D"$8 H (j;OmNV .3'!X +[ )h#X]>\T+.3ހDnFuono=QJ™>lb'[3"ػX?̨{"I/,~еx ̓mW #'ؠOش_'t?VP_b hPyG:+uC)zbUj -şQSϟtrۜbf@OC5͊ohGwN5XwvE . *e 5 ujdWJst/)ϔT-rADAw)&lmuiW8KrTNNtH,\5@qriBK>LGUבg[lI3n}˺UTVcf{~~ HQhP+z ([ x뤧(Z6YJ<hfKQs ļ!hq UP:ڙV"N90D5_+CiP駓X)gzuĢ&DHsy$[*KG#v '>-%+&n[7zF!Y0 j<9̂ q g{]:!9G TJT[n?IJ#<-]æ>;~X!T@Y<~{X%x(^\,s>91]we~u4YL-7o cW|<ÿ TReG&aF LbUDFThT4h?jo9Yn{/yڙK>=E?i0slKYP_.}ὣ}l|vE]W% t Ml=U=޲[z*jd4FOh/~1p s 1o 鹶=(^wT0;=xr<2ןT? iw# tm1]f68 0fXwWM$MP5p!Ƴ`uYS @U _H|V 'sѷ+4eC&A&O"jlm_-ŵ;67,JӘ([ڲ @g{[Y+K$K`5jO#߆(*ru5IQx[{"tyM^ Z?LAx* ٴ*ELWУM{3sU!XL!M$֨@VvPcPMu"J:i -rh=/ZX:n K|(nI'L.%S5kѹW䎲@(\s;T:KLG-dd`i[.6{ 876٬20F}ŨlN4ڍ쩀'8%Dg 1NB%UzFV\vr'If3x'?-\Cr?P_.W2U !Z%`ql6WѫLڵ _|Q1*1td&x\]npul$Ts:b4vifNb&E@SogNGruݶ9C~gs^(QgOBɖ> B՞UK[=`m? 8'|B"t]K(/ 5 <*+4N`fmެnc"]>_-Vb&UMm3aK I`*G@eͼS`!_k?xN]L^e?A͊E.VOe{d0K_$bA迁䲆.^/' pT,#zn/ [=DF`q)>@=5Qb~ .!Gθ?PSUbѨ6]W{C[%6!Nb!wAm="cTAyY:R`aKAi=H+h>';<Ĺ,E1/)0GW_`;0߆U㕟r) cIθ!EtbKM)ębP9QhK 63=:d ym%F׆ˬymM!NYy3َH΃>#[Uk;B#o$K PJJY4vA 6#V= |&R?Mv 1sq-Ҹw[yCeVV=7 3G!km)'! E$4l8bl0C*@H`xԯ?6@юS8} 'Gr`[}Ӂ @ɔVhO5!PdꥉV'FG!Oγga!5"ů~chڌPػ{jwڽFʪC-]0 ۲^?P#hu>N?Fn."I!\8ģWPSyg]lן_fDtt=|g}N1UҰz4, q[ e6l9 _ ]JrB]`X؆}߽U^m4R_Iv1(rSLkٌ jR&x4K{]ϷK9|';+=)&)dΘy7ڣܫC)XZ.=S?śGK=gw*η$% ú!Q(-,dn]&aX@/;w*vEt!4 2!|BlJP? g}=8躖T 85rk{Rj(0%Is*.$q]XYRãڅfg+N&E.ˀ4*.-Y.vUٱ--ՄݵhB o[~r;t |*bL1E)p,C x]^PţM z ѓ\{sq f{͞D+iT03Lj!B_]Ho%݉Z2>hkVqpڞT2>RȵCQuzE@(>\@pgی0`m,-WCZ#; J.)*.q)g8fJ /]3t'+ _]npzrd(rǕ%``/ ff#Q4cG񨑉cWq=#E\b>LlAi`D)D<g!:Us"CGQZ.\>LB< lN4/U_cۡz3 "Y /,+M~$@ L"!CVGpܹ:Ǯ#B Gi"K܁_X'ٳؤ =4+@VHTt5 E*vxX)?KT@S-at]3"[r?tKRn}N=5:mTo VY]v÷TY*su ;R.&sq}D|y1\;vh#tt`6!O4ʡp #Ǎ[MW V6%qkM ow pV˜jDE'\DҢWSHY$ I|t,uu?Z!ᏉV⧷_ (?ĉǰsdFj:G-8^ƽQh= X0Uma 8WC8[72~Z0jPw)ɩ+U}9]u&ep珑\{-.GU۰g|k ILo ڬn|6S<> 0ܮrR9W`+\Efo݃ A.AGInӼWz G%3w$yK^[c5v@E[ZPy7VC4u9792YܡXVL:{UTe`~ vSߠ5K|2ow,W]q`F_( W7j[:@x$Zbe`cFP \DG)I/1a͖p`LR׍BL<׵>a^D^@E;9U[ؼLYZvn>"VޠD? ^ >{ {OҔAǫl̅Knj^(_0p1R:=1t.bVPDV#̀G):2-ju!4뭏$NFn2d&ֹP@&M2ṌV|R8mRgu}TH$01 U ExC+bWm0ԏeSc۱=U+[X?BV!bd|~TX wSsFp%2] O=]ס96;""k]Z@?zJ#' ,^|N}Ak73n:A$Ww.ΑTr8н}(n*2]SF9O/:W$8oWMck,dt}M.Wpoj51LSS Asf:3@(;,. 灥{;Zvɍ9Tג1ޖSv$=1( ZA¢؃ 4Ho^G ̫D߃j;f(qOrxCN&XUA'h,8FE_94dW^*C N)v2Īn60Z;jbCb4*hb99w*mxaw5`*Q_zo)r|sc0930_kwXEY}āzX; ox"3Rav%(syru}[ve="c)>@uD:NEfrauWI[W0lTSYH´FA}{S2|Gx}_4FvAZ!]{)'*ȹeq`>|9]i=q2dm7F%tbu>A#U ۿBMoz49?R ޖ7= )m\#`Y6Ѵ@`zM=3ʞff zq t1yP]~o1sSpxlf'렼F_8xm]Vh~Y~Lgqݩg&;g46"Q m ?EJhQX$ey~cS8͋ t+tƖV'G1~`1]CYR+gyU|$+ܲsnukJݑNB )x(t/Ó'Tpws|oh|ÿ(Uz&7-◂6FCIy:5GpZo ۉݟ. YyEmd[|ߚRD]$GG9p'_9<&l Y~:u9ACDI[n2UMPDPӡnU|_ _#7;Wo/LR4.{>Ȏ/ҢMhQ9#/ԚmV\*YC@+{]0%Bس_B1!:Fgxpo iv̞+G*]9h-)"rI\uU~a !ң0,_ӎx1_TZ1W7eŶYD_sǽf/淁6B޶Jt/cdUS򹾓F"z؃2A;u ԮZP;Ś1EUZl)9n6آ1Ee*,PmOvw $'u~(, +6*w7`sc4,X?(Dlbve1,JR4h)C~E9 Kb#*f:8Rw_a5<~20'ëvO$pQn@0Dx Hwـ({ &<$̧KKoǵ@ SY<~U~bETW=#_F?#74l(;@}1Tf;Gd0h };u!)˞Px7TM LPSix0Œw|2/#Aeͳ Tw2٦=ֆJ4r61< T9g뱫dP#:I~q ͋'֝fZ8umRD%iwT|?j؂hު{!ϧ!P>=~3 ġ;Rp]ve>uz$ֶړ~b&.MJv0b-^ź߅wcAUjlwߋdP F3iE\hvnڷܫˀҨ%ӳ}|8L5bw`hr_J*BG3ݓQLeY8L^PF{L6\8*i[lB]#YQEy!uNޱխլЗ|rhZ&ª,U"O7p)Us94*M<7:JjZ^4_=2Q.][wE-u)@$>ܽV`*]'24{ŬJVMʵiJIcP!FoG-?=ƴ7W5Dz qt=rD쎌i䕸JfQ'T{Vjx@Y ;%L5 G+)Om觻pg1ioiIiTW-Zȑw1˟'b\uwܹ|"+h~\xDh_MXs$ޅ+ɊnbveoL`aceu4NtJ C޷`#7K ̞1Ndih!R^JJZˎiC9WOil"-A8 rdv8jdVRC|OnP>kߟ҇!-9DeICz}©?h&VtsHb'()!ZG^,0slMvY?}'FgW>Z}ix4ros`|bL8 Cɑ>Gb̺áIm;6_؅̚`/ |t-i#xI^=6>(<2M?lENC=Q 9Ev6\2epuu-9%?ʯ^](72=BRאwMRx*|e0~Ȕج;=FΩp6c+9 JSM#8J6O>^VFhQDZBBW7Q AZdX&Dl/|q"lԭ Bq+:z !-0M^yN{x'InR1u Cmy ԶMqU9g@;eT!%/=Ű-:] @0eLᨻ6K['Bq[nV< {c PU&F! ջD].Xt$ꈰڗ eؘYHL`ѶU){&}2!N.cYͼl bzHdpZ~-´ڥE,犝}1)&ǣ}V9AZӠSz(lǸ-KFDcf$gBk$Nw)TX!%'M*+j1FyLkR 2sb㴢#vgh5Ha$Hb~Ek_N-OSWPv96~I^5+JT0QotL2a)hqN>=Sؠ<ٖkvPie\x)¬IiC>&j"jNb!ab*g+|R@¥L;jram]Ϯ cOìxA¹,IIm0*hwf;߯nJɀcY_WEzfq\זsͧQfu[1+Q")) [/qMbf2B}xȢ`hBuAXy Љ. @8_EBځU tyEp41-FjV{41Ռ=B=hǶR"#F?oѾkBy'1 WU<~rQ[؁L6} PЭ.Taipp/&t6\iQ3mߦU^9vN:T9z^IFOAzHy;37]I"މxr?(ݬ:$m}ޱ= >wkey EߓL Z 6hb>>uۚ˃wnA{"m ;q#<u8}t7圠 {E֦DX7u(8Wk|I#m 7&oUA 5(=%O<"5)ą.>[!%`?F~ń] 0݃hNsӍ7p}5 iw$c0HzĆY[[h{T{BQn0];k71[ahEoY`Y8J˗kkp]QS:]^`Mfm<'H{:_f4T{^#MPXU n}:mQc\,;qU>7[%%4S dg]uRe4L$QZ9kZJA ۈz^Mr47\(.{JgyxӓaM|T"Ngif2vNNBl0|}Fb<R0?,wes]aVt{Ӈ-|$h [ӳ g$y?ϖ͐!̂fID@3NV%DO0 b&_[X饶[u^Va}< 3+;[0@4(,BxC*h # ۜ`pgU]߿4[ wjxN$,ՁP=nǘ'\C%h G.wV9B0Y%~3o8G #Fﶾ;_9֓|;x_ٍ<|J!s?!L~f3c5hSiK&&J'EzIJi3-/%xH}B eCjFUNc:ybR۳Z"+!^fMxnAWDY TzZSjբ}lT2r$u-P%C3คXAvyw?SgïwGTAGv K}2.&،~3%^J:K+u@ϗɕ<ٚ=k 4e3B`<yaBHXM;B7ƭ I[FˆI4.^ptOV̄/b*[dhz9:d'ecխ>2LiyIxnVV(Vi3GC]aꬣ &}rE}Fm2\w |Q҅p5P~Ԋ #؀0~ZmA?0Q|rbێO>L}] bI2!3͈ ck|Km/syLƑy7Iw(Rf#ûŨfrR#(A92Aht+hUe )r4ٳy'gi$!.WIYn3ہ^AX &I:!YPeM a`3 Ba?.[z(qL5L,X)=xG_Vf4IZԮ;YOG 4hrʩ1&k5&)^{P;f\*ƭi6!Ƅ搾ƄFf]+ea)G=wy31q[M"zF `KKo N1P{$XkvaV=# ϺOR"MYfkȕ>FRIS8~L-V{cneDz5 \&"9ٔpfe% eK+~j:< DOnL2'$0E*ښ';E4of=ZWO(Ynr>U͊m+P2ME>}U%P=%ELWEo j(`ktMu~1j] adW>: i,y-yN@NT0b}d|ʏ\Mƕr3sRcʵ^0 aJ)L8#.;A;@WȍP0TI3󖝕!s}9CģN],jg(x5F"FR:XFCvbdi5N QM5,'.6ICp$QN Ѧt Z\mVK|L5V%ɰ0(VdUg(qWYbx#?l2॑hBf.JrEmU47EeOblO4fL:: B? x/j߭a$%:s6/n23MsLZ%2)#A[DVl43QF6ouۨ#D4X%Ph9]s" ܍<05$>v9v9k!ym"۷I'`n5*OΩ] _ivcI'cΖ`𭌱Pǀ6-+ Uz WoՕ[G+ley*64?_e.I  jHξO^#t _H$кDIJ Ÿi.~`}#@ޚE1E;Y'RRP&@KR&( iw:NyMo$q݆؏&y@*oBu!$}*ŤmzòNauW}KF1d;qPaDB]Rp!ixD*Ē%"P}ҬO7_ oYvMu%/9lǏ/0 {Fe7IlwC@v`tZgt[K_:`8Gv՟-\zJjr#(-ժ4O}&M@/8 JrHZO9;';buc 77hLD*nRG|.M>gĸ)uz[F#pX?X,iEň⚔T&$'cr695sZ'𥶟z݆Ѣ6etƱ]l1Iw;KMez1z;om2qEF]qkkVēCKYYYD̲̥#͕) L#ߝ2oô|b1q!VR9}]fKkԨS6?(Rgۀ>4l EIնוE+6ЫE0De)jWY:IxF_ǕD;)-`~NM)@)d!~|X!g A $:Uܓp&:íqga[GWK5 >Nd_Ӌ]9{NG9M乀?%+}sI@q] DQp-ULK>!tk,qlUv,wNZd1 4PUӼI@ߝJ`l-1b1-Q./b:{)ԥ5(w/-"Ս4mRWOp`=DQγ_Ry^xz>~,".~Ĭ#g*V$`YYٗ3tՓ]JG2[R|P9HI>e^(g.=2{|o-ן͋Ir^.U8XC]?fN{7G>taUAjiZOiXVDk#uvo`yh'*JYWFhf:MV&_(Ď1vtJuı=f_}%7QMѫ OGΦ1%꜓qpLk# :[v®h%V?&Òm!%F?n 4gIH'ugI'B2`+=SUnOP8)*o;}=+?{TwRr`I>*?BtHaG֧f `_6HLl,P("!%j)16qqFo ȣVlp7G[0,atQPc Eu,6faُuWʌ!4 pe*ױF<;U+ɓ k*<%H䏞>,<88;^Oi9`AJ["$M9u y Ԙk"OɊe[~퓸LC]o%O]ѥ(Fse\$$[;_ôkF=$ =ـ;rl_}k Hc=7`Z -k $RV%ʇj֔Yo0{|(Q3Vovd#R Du5 D~3?kh|c[,CX|Pn>_M'Wc1!0mALkXT3 KXQs ژ#1SD]UjCMʚS.T*v%p"P,ޠzE"mF:G.A`7a?KW#%KOcEjKpn4Y^ivrF\DsB,1S.t~IG8$2 ۴ka)>Gxurjx A|3Z|-6z}UŊ!I?Q,ȇpdV΍+6I̞ҺgmaԆc!URa[PLq˃y7:h1.7옋Š#7N AT!1 ޵njU<' D9  &,-Pm{$"\L Lu`։]0x_a>]j\#={K 6Zhxhw=js;j+[셍rQs?$m SYjlRkdW!V(C.V=#$gȹbf.O$ & [@ Et֯$%ymo͠+\:Fܵ<W҉'4jm;.K> G6(6b/ЉbXli0GC/ӄIM24Fu/a8E;]^F (πovw˃`>x$qLGncGQAiCWԦ2N>嗘o ~!}*Ki-l10mΜ-V@\*wxxS}4,G\ )L: Gl̊ {Ho5\ Jή.076J 7P9t1`[.9 r%5מJr|ZEh` 4 cfY6ueU{'g+><5nUBH<0 CD=Yo q~YG\3ęgqgգ>M$:e]L(aԐd?Ŕ 10-hi^zLzoV`{+"L' ۨ1lxlSFš?ũt1DP ] ^aֻͼ.XF"U4>=B[T[>jOF8Ϻ  MsP5EWpf nO{$:Ua:@̾MMmh QGNw(uỲsPnw\&Yۼl$g0ȢY8yPz8OE E(ͨ,cvp\VULp_6;y4bVD̃iueokSBCZ2YUrww=ȜO,WQl-::$p]y A}6ழO+ !黣"TI5I< EWt-_%x:[wԿ0sRm9zYлSR=nwB&?W=0:$WC/Vj/͚"y gK7m|N #y|m$GMފw j 8J=  NϭWۻ )C8hd)PNi ~=hPS".ZEUgd Ub5F d{EΦ '-.-NڶVK1#}GI LΆֲ.#;T9{ɮ~}giyk/͠YJr%ApoT#;40g/#(>?==Cgzb,`G`1M`V#BE#[&Z!q^)ȿ+fGീ07IbO?M'Hbtl$P5tD:OoDi;q#gm(ξ*(8+drlVR(p'fKuX7}$)NpkZ(QjCyᾷf|vX:LAVF3Җ-E,OjoJ9֮GyE_*}z_i+ט|'!eDZWBiK*Zx*è0)y"MQAсĶ"C0[[}[0x޾_ ED 335Uktx1?1~ g9⎷ް/gNΕś;R+BaOWDW&LJ\aO ,MҶh$Q@R[]F+NmvsLWchP'"oVk'Oϟr솝a vNU5Oҙ jL$8(/z|r[@]K xE wr&-ZAT2㺠NGae'.O9*rU3'f:OY7YXm).jJ%KXk>x˄oآ U R觨#xa_YlGJ7> O9e%VYk0\M(~EV:eou.nrx"5O)g{\<DŽLdI7hN((bB*Jl9pY"xJxv*ǘ-6f۷8ZA^}>&@u<<'ؼ 7rK#Ocsc(;S`̨É<ƽsɱ_1k.h ϑȸ=KxkPBb~Ww?I*>i"\z"whpAπ`T7Ӂ)m5Fa;tݫd@S_tq` >Wd>ObX{?S3KڪڤqΣ8 c%-Zw0i0b,؛> Tw\y&!i|fяZӑ`uop8[Pqz Տĉt 8fD^A ._:"‹8Rׄ"80?M F\T'a)Z*= "n:^zkY;f`ӆԹMFv$r,0Řlla u $KGʡZYB:2 Չ3)^./pߙm$kp!_lU]rRu 0%7Sm.r51PrI4D{56 )c<[{Lu붐W~ FU4w*u'n00Ni(rA%{k^kM\x %zqNҒdAl:DJx_)#$'uiFE}x$_n " zNN ^n-$ @Mr?4KŊ|VH<ߞG:J >O'z/ NwDD N߭ln,$ixpE #O–Str~V^!ENn+p'4(+kX)eVQhy5.p֎OJ:7e'&lx"Q3[F4#POtj{ų/ jZvZyrU+`#v V3aԮtt^;ڇA4pB;NO\mh[T>}*:9|ܴUG^Myb9l]q ux_>Q( ]+36; ev.>K3f(F@9C:bA=%CC){/r?.u-ISϑ9@4ubƔe:;EC8Kt!ݦ-p*)jul*^H5Dw|"ߜlZۉ CMr?UR֔,kxݨ65[{6|9xy)_T+f\G@BfhY3&x]CmK Yo^ xm bL؍UoxT-'byJ^FU^Jok _.(j (\ YWZռ_\&b|r/&яqXmtl}?q%6c&A23x1'.y%^hZ}ʉ<$U3t'aCȉAn'j<럣k hyqJug8=|XIIƌm\'m7ʹcd?RE71?On .tbɫ[k1ycRDA-2ڎ/Ji Ԧ0;Dx ѿ]ھ6 %\'?>^=>/j+XJpKv2h|K_j`mlsǖ ^, κ*%%=ٿp (E 8КhWnETNcĤ'zU1[V9J#3f7G2(SnɎHtk/؛hF12h(bi!T8 ¶be08މXM(`PDF͒U4]\7X {'f,4~lA.u4Ҹ^Y.&^D8aE ̦ Qdeiʼnvv=: 7"b/ r ϧUv1QT:.Ǖjt{oxW1óLp/U eq?_w#maGE=UDM1<釫FPPHܩDBuc/Kf'Zq[Ux`G+BhtYYBz5Pr5 5'*^K1#B_) E8b#9Ն%'_=jhuѼ=;A}35N*hDs[f76Ȑ`IgaP꬧$I Qd͔Y}|&+R9z-S5EEx8v*ƲVUm+8) U-ʈv[\mYuI~A.+MD"|"= ;U2ROoyptŲYL]D[#f &ݥy3o>Y xһ~vI_<WzFKAeRj9H3c2-C~J܆m<~.ZtTGJLۥݟ|&3 QGJ?Km-= CIQ;w~_p$5e1fWa@)lvEmfk9Vґ9%9!փHɚ\PA[']6Ԋ1Ԥi1tqۣѶGf˖8"oRktl'.jYNd(UI paqF e%C#=s=tC9 7uF=,춛Fa3 ʱ<_-8 GB~tsr8"Ę:|üRaX466hxD$mnjB{l Zcĺ1A0@w*݇WIN=AdOoCc͍#$gʳ*W󜡬 ӝ-̞DaPM6p<ӔAGlxDOkG#7fbKr/lNO&nR@͟y#ՓܘqP&E,L=K`mwr=G;ՁNk"w*I;qvٶ@s(;Vf! F߽"Y| SJ_ lit軩;ȸkpOrxӓKYɓRh PpJG%ܼGm0l:YC&!qzϲ}o >i *!UQ؆1‹qL~o}m-:1']m@R wfi~݋n:&>ipB"`nonڿKuϖ2MG>O; >Z+=`GMH֪$\' ]4n$ 4gtCЉ ll?ː(3a(1`SR4NE$6@TH a,Tc)0>D闝 ~>[{-"ḳI 9^PI Nz$bzX ?I\23 NQF^\MT#yacY\DQُrb%.Q4_4Pԟw ~S$~}9@Idd'҈S(Q(|\ RZ]}1$2F`;i ͍-?^R7jx'L e# I%WS fInӣaXvΦmzO{़霒B%11,W f  dz;-b}Ҕ1weq9$(V5E@O|"tpKt@U?9Wtc6Jm} b ZU 8WTS. @ٕgD< U(}RBES2h:~@y.g)qyTcH6x/_{K':&3!L9XEBil:c̑2*.񳿰YSC6=XB'ut?#2.́LK,P{LºGb>7[y8$Qňi)Z mj.֖=%ÞOz^pca̟]"*Ö ceaƃP(憄- yTl L2IVtϠ'y\~<2nXPFSoR{Pp.^ #"%uz:g@ X~h՚^IhόWA{N0ď'O|rQ2턳]xlvط^=0=#G^=>/H<" :!i!|sUBX.3L_TJZ늏ǃq)_ǔ~G%ڦDPbb0I!W?o>|C0/Xԟ6T5M_<czǘv@ć>jŀFs<CMc势50^-w3RRukjRL/jAFZs>A~Fȅ Լ\AJxc,:u,C b܊{" yGu2DW&c)J([$&>Iѳ}TjtLMwZ3y*z4 ~vdȖ%l+qvGRjdjWX7$/Šfd9[fgҪ-U:^B|ώ#Q"BՊ.?M433js;|(w5>L!{t0G<"H+[nߍ RFנaxΦ T,Xm 9>~<^v;ݘ~1Nu8IntP'n!R,!g9ZͶ/U)?XRy;{D ,jl]h [qlGbHP5sz龗-h)(UL r&~b7?tR 8"c&uߢ} ve“+JF6Z|˛c}ŐG Px-t'EeAdi?Ü| 3ԄaL"%9ù|$IGsjM;X;Pyk9ʠ{ـE1{XχgûJ,V/8Y28m$rCSE! Dzs3$nܝt *Z6E17Xꔜ=AX\svEHlߊR/ߎN@\$h3n=>mUC'pk"eGT4#2|pd2Ñ;h.FhjWSp67P}8F>)zY .iT .u?]WR#=BE9 t5\;v {ٸw*9nWc^uHRZ7e v!/-dc~POw]m#Qzi#;y\ (HP pE W ȅpt1aB-8:fkK` X|ʿ 2PmZ{Úá aEp&&DB\ԍ/ pu<ۡV"So]{=`"㒸ASWEb#TW$#3hghx&F,2ǚ~o_ Da)>"[h_f(Mz[;̈́m<&kZ<`1j~)SbLۼs~b>E9mgm߹*YOmjJRN}l,bJm#{?_и[J!(]LM ae6k9qf0I2 (C>0dLMZ(=ÛKIxeD+ CPVw(_JQ?Ceo^"D(ȵǺh]Mq 뤮lX_zAUBUDP:@)œ"j[pqN!`FbOsL}qvԙHiHP+/gR7VACB\\;6Z'aw"e0WFqLy35ݪ"ֹa=2ϭd 'J?| [Y O"t;cn`\&.ѥϐD[0븤_u6(cgIOv-4.U]2ۯmCfR{:EfY1H?wWr}U+%dzF`^ɓɪm3IvNSE:+緓:Ιc?H\ **#p9ǝ|oukɝೀ^W°eiP Qۚs՚c4oBVtd*<̻?%o{l(ofxHԇ|M"x}iLd)FJ a&|qzw}P 9< ʄH\?V|搋^0@ͺMW(_@ڦD+Y͂XײLN @ϲXJX7ygLS6G0bBX+e;4=46f;֗~9/'fqvNܓ7N$ɠ zٍPP-LW= @fBi FWͽ]袡Af>1qRfąِޣZ:/tAJSO7˹b13lȣ\tv! /)UeSEPv-6Y;K8S;Pp]3b}8@Je;mvjpY8[DOi%%Alϗ9~R/(pYr4V}mC=Ry lN}{.Ka.6+"њ8^Ipd3=UЈDH17U+ gOh3 uq6|Wj7~8>o~iɶT$vMтDʴR6c!x#\ʞAAnC"-j%uQBY% w$X_Plh;o_0suv]J}"~;n MBڂ$e :,tC^֯>N5xH0(<;'fЇ/!l~ 1keD[4zBLٶIC&$`otNk?~2xMwȨx;6˿LN62]w@]V">b$#]{8tulbhl8l?loEC)dIQ)ʨrb.BCe 9XV?C_OOOxF Xzc)P5l=i[ X8rݲc9enP '+. C9ĵO7/OzZԶ> >*Ҥў8O@c6;f_uyޞOG1:h`㮖ᚔ u@r-wId΄cی%rCf Ц7$έLp+0o[l 3 JTN`BL-^*`ZXuV#}Th V>DFeٝxzlJd837k=Ķo6giAc1"(pt$3ba&tA`rT|[O;fߐa{;k,&f'=o]?j'zbv?eUSkZ@f͘ztRuE/Φo%$eiBN#`]& [ML6PyRez2I E "2Bc?i~Yy`BL^"p3t :ЀlM@q jq=+f g?Ue>h 0/._> 2pFߙdo{N b~;/`NOQ#>5<@K~ i;LlƧRQdȣ\=e#e9G:a^mzsk7CFi12C7o3Ӝ%Ke,  ҨopC~Gu\exICG1.9t/x 8CYֽP{v stt:J*A@P_NK;߉ ||N`o -VO7tqR.H)7Nbc UJ~ CzW*tʟO^ٍͧc al|ao_*Y ~Zw1 a.hiT\e7h}cTܣj%XSwcsj^*Lk  ~E:%arJ{>i)GY1Ar{_Ra~JNMoI.XjDxB{]<-f!J<>;d[ţf$ >tVENZ X(+桚VKb `BrEXcd`g cDli5fɛosX1Ivas}"Ht_|}:asV;;LQ oE6A@CUlnhfօS Kb ҋ08"K5X]{~࿤"a,ȡ.B!#P;1X5fV>w'e4bi^Sդ&^tΈik'nX&:quhtHd(̂l .o2wP+C-Z\$(ǵKiRU4͵uh~1+H,JynεYv%jp(M#aOZf;4\vu77Pg?}QvVk8qp*!gG1Z*s؎ Voc:']F^h3~D%Pj1F܃%T3bu6{f%T1lgdQ٫5ǟU䠁gH'Kv}XU4欢R7^f9WbRQ*[6A2Ƽ5ZzE&uFJ9cjF8}gz_rLAI$%Ptw0Knp` 5تn!"33cJz}!J!€G1 C8̴Uk w"*;c L~P|/x=cqG9`}b!sg&S6pillAu'fw/p@ :Vu(+ ڰC)H0 No8e:_H+S߲|Ah2ωsO؅Sz:e ڴbe. x3(ţG<"1J~6qE=9*#4H-& OPs7m_ ¢F"qv%1K}ɣ5< ]йGT~89ъXL'y :ZZ8gdO>ⅲm>JQ]Գi״|C@Db/cMWnwIK#n07]cÏOL/vV 2sWI4Q '=-E-l6q$\w@I} hȃBP'kcӼl&$#>Ea=`jczg=-8!:ƔLDˉ&#/=. ,7a8y|J - 5Uq)9ٚXv5C.ktdX H^PSqFh,B 2l \;GȍEJ*;RL3J3â*p`mTs(bV5`m@ L.84wp%QeBK'EF6 Ik~!Ӯsw((2v.g(N./2;1)"0뫻o;}5t/Mǰa?v+\D&ҏW̄geoŋZߨגWd<.mڻ*=Ə]46 $k[vH_e$ n&] q^+cV+_9;h9bnxZv64̽fKEW428+*CpWd\Vgb$9="QS&1[*"4JI`d0޷<*hT;00qҽ#'+J)SUs@z>_Z8<})Zqm<ß![I$`F87,#}*:#nj&qmL'֩sTaxAB1_8~?hڬWن\b"TF$凼\05IЦ2ËB;/ύ'cyv /R nZ\fW/5@q!~WOdⷻ*n] k.!,xoFbAV9)&uayHg"bM6cm;ۯH^QN$]3A-$$_Y4zEE O-Nz{r)d ZoZ RyQD ^U ] ]]3(u'>f( !DZUD\.w.:q8$4' L={H"Q:ͱ g6=׍\pu22{SES+كt_uª.=[j&ugeƛ+<:=UUUJ UT|гVdqRMrMKv3:jrJ; rdp~/o %.GQ'4LKiW(D1[Lc4LKF]MF:3exG׫fB$Eܤw'eEna6f6xR:Fy B{ ,Yꛣe7R񼿼U'MMhu d@.XM}lKX q_d@բLu{F^0I]I ٗh(/ xP:N=z0k2i N3 ~O?5[ E[-myvOGyɛ'= ~oPj9[ >1jK;n+-0l-җd0Af{CҎH^lR-'>6PE!_y\<3$,Qf!M ;؋¦G`)tpJH jLN?5^W/L;n#w2-YXtP<>ԮsmmB_~Ș ?⺍Tڰ4?cL{X| ]w"{BG`"L/ĤemВiR}]Aǟ+;PG8#?|d'VY]1w/aE dnxaM.7B6_sMR~癆, cr]wB_uEiVFf 9(>۩NN~puW #_8~WeFcų`U&rN1r?Owo.ΝU{/R Q9XA=_A%[v!qpO94Ԗsύ+t#&nU<>F}InH7CWu<MCΉBAݔӕ_Rfy5]0|Sa[KQZ)cٯM`nL(s(vZbP H!V;ۛrcVjVhIO.Ljޟwd)'jf>Hk`7yMV&.eۓی5B6d% IM9_bgaaG:ӃӨsj8!Eʕg'_P/ff14HvٔmQU0aFu%tͬ _KW)mfi#ÅnI'uaUUt~h1c62X},}@4`@wn}7Hyv.[{X,&a l;= e!h&k mQN\SyX_8l͟P?lǥ!fP/\RMp`ZL1qjnDw5e}=泏ft&!sFX4ê11mJ&>GOh ՌA:8KY~D9B;d퐟>"vxt~ ޘC麸lzQ˰h$Cv\NcS Ju5Mվ@29ez7Z |шҘҜ548Sdg>eyP f)W,3INxg_A5;vhMONSg+rbygglrΥ,{"J# qAxD)EW7'ouʻ0ְn`Kӳ6̸o bŴ%1ԫckCԂ&0<7S&^ +t{ɼ+ƈblKps#F>o$gwq/94)׫!J4Ľ1*hGhICg=hjeyYQ|2 *FEK2Tn2Ӡxhz"L8S8jP'P q#3:PW2=#M{:}01s ؝1NRcΤ Ԟii )ݶKjk*vc:1?h4 CN-QNJ'ڻ80r.k'`yd7OLއ|֐d 3zU8/Zfiu+gR jާUcC-f6`@>O| |@L: i1Ed wDzR- , -~@.7#ſD2^Z( U~DS5W(X7S^FEIQ;jE*V^b96AB&,ii?R]:k}RVܡ-՝}PFzt$`#w,FwF E Ҕc'icz3$evEkcREN( 3uM*ZMJ1nӟ%~*hk&_R+G$r4\i ֒DTD%0]z~di}ّ.n@1-dt/t,U,ɝOZuuN":5z\Nˣwz`޽¼u虰־ Nq 7_/2O[zW1=<%{b^jcu9[4!\`st-h558N۵g_ bFT_L5!ʣjo@kۆ2$JIg"ך*UI+c39tўr/5O7(i0z\4F t 7TmVԔ7Jz(h/=E!"W`Nj>PW x_|yV@70O_/P yfƪ9XɌ#E@[YtxQ!`qt|U|go8OǼ O- V^ ĒU|}le0惔>Re#K?B7Ue@3FPcmdc*7b: %g7ۥ uz[&5W."|\ OSĸ6а(Q$L@ ?d.v? 9hGonX>Tnl?ΥNjnJ:O*ںwpm&CILo~3X ΏGXIXk+p6*];(%`H/mZ/4VߒΗt% ?,[!eGT=_'_x?`QG5h"yL ޜBsӞ)V}"籜uDfHyIj{Sڟ2bz\\%Vh.zWhQ3k!~'1O$y?eT?4{zAV-n Bmhm e/i*渶\,Jhq&H!PBۜEGPg9]\.-~  BH:^2;l0QWc "'|l`ޱm!mHn'(iQy~D:E(8S˨UƒN7dkeᯋMlq NZJK -a,T5&IK&`'4 ËPAE"7pV"W\'&vWqDtf#;(]m0Fj[*ס k/ Pstzg|C2ux#oUswQO(^3ЀA9hݳfMa%!<y #c,K?}dzbnyISV%+7MeBÆ|ALme,KsO#7Pcz ?Yc~g q4.7a_H0_{NFe'0k2,uNh$ |2 %*vTQR8,2m\yfiFr)B+K7ɫ@ʌv&#ve/|2Z۳|?>w"ypn$~BxG܎P*gS[X۠٥dR9I9HEbv*W4  9oګf0 CrWҎ?NW[e5ūl扸k/8fkbmJTOzWc-wZu/-2e҆ugfdS0?b:ګG@~=@ځl$IhuOwy܊'%f<MܾLϼ >;LI\0LuXgzaͭ5ܰǏ }|Fn!G5/8D!Xw g_EM_H31-f&<ɏWaDxR&`A֡,W3HSieC+ 5V!'GiO @'mЈ2jbڕ;bKvj=^!Z"CRluTiDS=\J*(Ahd2)|r.:OS' iźSd5R vOׄ:%>^7zM'C "k_௄@[q&crPnRڋ/|7̍'ތ !G5:4~U{~?#qk LŵF_mFA_կ ݈y$pQX7gcSuCyt)Wp23j,WeaE5}&o0skU-7ft_ jB#𻺝E>}p6iJVH3+s5J96mdA*[wib^ؘ 6< vR4Աf8</_Gz_o4pvXbDSU/J=6M6G_& Z)K ĦX6fYI '~8j6ߙ}6?r%P^:n*vXv: $KRsCw"v5b2*CTQtcO!vQtZM05]J3:4q9'HNB./ģ1F65Hi|4)e[Mdb\څK쒟Km$w<2ņ%kԡiV|̕ Z8i`wM>l.$9ҡ^*h4!L#ĸD"5q[)6=W_=$X.X.ȕ7N^oCd;9Mg3V~3 po܈k9jݭ(*Xn4%jkjS8CRLM0Im@9|X GgPPidIoE3gώ.!.7%6\BbwU`D%\bEkO^f2Ïg#ۑx: __u<#ZvmBōZ!s%P$$W?s>)'{$vDXt&TOmT,6S0 ܷ\!)]\~Ceў&%7&p}r pe^]pm ~FzxYicvƫ(K_ӯ9\LSǓ@G.qk (LC [zk ٠;=T5mQ!뀁u4ܕR|߸?2T2%t ޓP=Ip#z XT% Ruu)죂^0 ζVɵ@μz _Zt_S% c5WbE뇞{n_吏7A(X2.¥ D"ֻ5qfܥd5u@z~(&JS[758{m2d9LsulY+DZKC؝f*I`Ch$!Ccq;,VX9 4RO  =d>mc7eJ ,Ky+A΁N%UK&R;u]9ל"KTaI[H$ab+ -˜ #b= z`4ję/rQ9_R(]Nygh/( hrn7j6'篇T_b+?K 9B?=Nmŕn"`nJ`)/`+;LͪC'NC$gFF Kts#\R ԪH/^ďm]'D2ȖPUZsg%n+Rۡ@`$T 3ֻ Gf:L2qr$(3ŬX+Ꚕ%n2|P5ꊫυ㉯ V_`zV6``яBXFJzNeƱʍpP>^֝NHoӶaqx+sVA*sV[::i%Bs N(VoՏNjܗB[EV }HЩ[4|sKx5Pk#-%m{GV > Z)BmА3/ŅGBs_Y{Fn 6"`sv: qJdÃ2+SDD): Ԯ !Yn<_xc1cZfĥf{tۺt4-OϨjé4<oطۀ6rĚw>=)m';אW#%Jnh{3k,*.PS|t!@c -2KQ3z,5ʦx+ qLoрw͘zC3*Dvc'(̢'iZhK1 CZgq7JЅRqu0#$KYv\,2' 8GV@aOWoI0>efjNj|B/=jAɥ?<|/\/g1G5qB/=w\u-3*iUSpư(ly,fQ2pLvۉ%946 2nZMK-\<L)pebh񜌖9tzsgi'?sGfEyAtfj7۔X ))6"˧ 1LC'B5 p"rǐTi43(ɬL>A5`!ؔ@wtXQ6bgEv!779]Fk'/w?*<~/q*^u4B"+ sv5jVh7yaKBPS8T\*ȋsĞ* Șxn+[%aWߑV5%d$(¸H!t8)fwtyHxURh5kӳauP0=0/EqwlLOYYLgAH{z2AѕrҦ;GJCqTWD5&

KUmˆ_[T(;ͷe܉|y'>GX,:(ʩe@0 }+BqX˫Pf,VyAPnJt^W0r "uBUNtLļeu4})"=rDVUKI _qs@LU?|+e}4sj͂7ḣ3$>!Fr4y#K oV uk_8$U-bt5IHwq=ő]bY V /_LQDFnS>BpT%l)4 NZ':^ڡ9k781:vڎJ[<3cM~ d`G+4s ?ApL[R p2sWMpj\78 뢊]aO;Wy.{1PxdEi[l^jOQT\=03x sSq=3 +ka)!ŻvʐAڜT\ł6imri5L- <=vá!<=;uq7qy%ף.iKr2:{yA4b3]0a8ܟKNI3PYD&گ mܔ[:]MQ)5!i_8dj ,xo6,D*V5 |-+@;Be ֡Tn9"GvI8 |nR'## E[_o9A sU|%nVQ/Q!K<,;jL ciWm0ʀ]}}i̠ Y)v?~Zu@8lY?QW=9Khǟ†НxBrkF7xr `i2-,V R7ijv[`r>)ouč1!~ 72`|[@ ZR| \m:1<ڝʢjL09_ y?,A.}ŦRZY~(ro{ZsQ}/$I)1 2ZE,.m|c KaVv&]q5WoWX/щngC,%K=M09R\"q@fR aQYqzPiv5f'QK^-Zy ދ`7SJG_sh=.e8:CEϓD Q_cjqu/fW&p+ /x0)G'SKRM}\a&,+hYn S/j PxBUb囇cXʢG{~n0x*F$ChSc},/g`p]@! WCDG[١P";iO?T NV"R\ IBjPØ>BYǸyTUIG9 9 bhR`/f~b!7%*!8؍ c!i޺msl$ù|jƞFeXpK fzdNdTBǓs'bkoɚ -j/jL[:l;L"*ԶfF UV6`I&>G =TkܢgC~Uij7Ph&bdДDhcZ`'x,bu!1߀ \okAbOuKP_W&?mV{pѽf0W6Q,Ny0#g0byX*J ZtY̡gԸS~9߹ѓNV_Iz0e2]jJR=Ux3Mz;'WX^OyAcĂvʫ/.%% Hc[͊uΦvlb"+Q5#v/gEveGnlx艹V~R6?@ǥؐu\)ڄuF:8ri5uvR pMgv g%j)zish[58^*fyyjXO S7DɒN.3(0} UՒe ,Y.f[: aXŷhʜ-D`ׅ~?KXg DQȖX1ʊ4 lqcYZ AζT+}LI6t=4\CӠl:>:SMcdU[m{gddfH鍬>3d,=O$ϸ =7:_K}7hm]cTs&}AWAtR&b[l)A1U.?t$S2JnH* MJ "Zƒkwbޞr+72\cD|>i}M,&vaXZ5>{FB0"k-ewp. yQ4S}ta[ˣV9? !6ƚìAx\27hFYDhYUeI[FrX=Bbxb< "L ?@T5CrkγP+\f-`A2uSf)\XtA[vu{A96$W*9ñqX>{-_GЁC|'Z3Yys,5 KZi*}+:.ih~\."sɿ1˥%V@sZg绁W8D q;IZ>8'vׇ Jl&8Yfp]iɓ\||-8y5Ypr 0h0zEhЄ+ $g捇(_/x050|<b[us4%ұlB=g uQb Ԛ&pЫH؃r)vSX-,Ɵ2"db, Ah?Q$q+*ذ$, ׽u* 'E 8S-ޚF%YCjoO%/ՙK= x{ (fYl!>›5HSf:^ NI)MA).<Zr\hZ'E˜40Rbv_%R?Pek]{;nB9,:}2HBեqx4ID: Cc5^n p~Ƨhfe?ױ×DM1%2e$=N%:/3.%(q_m t2J7PNTRu|D~K4Wj{m[UB^L:<$h /`鞬Ʀ)257y~l |LٰZ gG3aM\t>*\.28)?$0!ەEtVR.V:%?ڃ6N%h^h7cSe"khm=bhz6'XWF?e`4މ 4!4u|ϫ@#TvZ"ye1L\zw|WL>2~Dڏzϡ@AwWX_g+hla9:ϑ7Tist#M lJ 6uqY}Zzm5}{8JZA$$E_$+\ ::Z򑀲pJU~6|j~^ccr nxH[:5;aJtxF5.PD]U#-9^LB[} I eqؒB p~"Av &H j J ۅWl1aj{4JX /bٛPlnAVdlZ36b -\S^U贏yK Vèd.EȞ OU㕙 :H Zₜf!SpEU317 9͜~l]D׎Df\8ESr5,# xl._δr5ɦxPcV 7T 31R/ 1=~np'&1ti,WkwLh:Ɩۺ e{&B*WQ?~!'T1hSdlRr>P1n@覠aA|_2.Ma3?5p{D; MM[|EKB_^m&r&oz 3 V'["E5^jL$E&Gd~=R\+˜F.լ 7E㌬7$жѽPxW4v͍cT5v틌|RtdvJ*ksƺ{lIHvt:ŨLަ" _v3!a'~71;M\?$VGg~OaTkmiJ<@r1a$C.9gK[r"ԑHՁ" y7ű:()y1VAR@sݖ@XVUQLU{Z'g7UuhfHԜTi*LLe?^rڐ6đ1&N ֎]񸚉RVK}Wy11~ː-t^{rGë ) ZyZyOL@9emԜ".z72_frǨqvl2x~%d8I0Dg/wl>"bC)R$ih%si 2¨c{y] gQ:0}fwӴqgr CkMP$UJC}#Ev!Z&2-֪r-rh~]E@=h0S( oه1:/m? 2T\Nm>^Sc\?u4>gi)Fi}ڹ#.gθYYN>.&䊑aY۬mDހ~9ԫBP"QHT ?8iy"SgwƇL"|wԫISɥ|KKHZ<++\n(?@蒊!0B=$v 7g6yHRW=Jƾ l$0JI* o{P DC~PB<-PYVtz HEUg1J90)- i;A*UFiKL%8EN+񡳓n|qvB4 ϦetW"|T%a"iU#6\ߧ _kյ1eTr;Ir"u\Ic:YРrMug/1Z-G*ـY]g.5yz嘹 eK֟z.b;cE|ks?J6_4iRg#5yۄxd=&Nz_ca?݋s7#2Zc;`/@Pnfo n*(uNIw9ڨ ,hB J4wĖU/Tdl$t_ *6?g28M[<Fi b)s" M) -).WDn^ zHx _ ];!inX <dIhE%!:S(D,dEX)oyJmd9^rz}/B*puS%S0㦨 h喯`j 7t)r'd `@`qƺsK"ۣ ݂,k sJI=FoՠwQw. .1B*>Y3m:⒰p~ A0RٶG2mT%DPpLA!F7ٲA<*^,C{jmh_{5<>*EaF,!:XJ^Z]Z18y~9咧hf8/ usC (|J^Ly~m5r=EAN/Γm@6GC*$iiD,|7CxUv dt|l^J^*qtgc28myPD(FÖ9Ib%!frbʕnՏ>L]0r5K&2 4c^NRF̺مAZ7jKuIȼ)o|.|]_u+ Y^BA#9 7U[s>A"YPoqEa_:4̠?h<1H i2byd!Mx_ 2EF~,gcC.AC1tбn[9mYouCtYL˖:V#E{UQJp~2^g `uhi >~nh6Pq/빟hdKg7 ԮۑMs(W?LuA&ydKᆦ6Ll<%(LFcdkYw3(KOl+FZil5cf}2h `o0? c#ܑ}TaJ>/;btj[QP\. x355 ̐+X6deW0֊c%UQ8 C\="d/ ]jd?)7i {t>ߏ|ZҪ5鏾 )Iإz lkImfm4ֶ TuDՁM\|7(ՇX3aAU$úSqrvX%9/ R[w e6۽ܑ#΁sbHx7r|>Սr(.(iBE O,`A; +GA9 JڼanG5xkuc4a|r!U)x?fi2.]b1Bء+eCE ji9\gMT= r^:14D4F%8sWLWm`m*9N2ĭ %n\lj:}K*ABŊpvPp:%l9;(mcϜcGß9M7iAɵ~D*}que_ސ Ie;|RvhXdȣMl>/_ɝkgs0AXKc+3pWV[F&ĩ=술ugzl15-6s{!iKuHM2x}q/X"%.L[`()s:PS<E%h@t\wʋֳ3+faɇoYi/3#@9u1 vTgEk%wlKdXF`^T1!7V:`Zy~bЯ !6Hub{?v ĩ<')|.0[F-t˞T4-3b庢E{NXfJb23:V8+\Ev-6֗nTBѸw4&@sxhSpra dOެV(fk͗-~M5qQl)Դf#ǑP`&.QJH}kXd#R7_ĭP?;Xb˜{-~`3-w! !TViB3jgJ>[qpF(^jaby?p^3!J=kԳ`${VQ_[5C/o u9!6țyqy"lr/ш0o&d2w 7 7Ȧ/XZ|%cz*{S.[Q46Ir`]%O#r: wy ՃûE 0 p*H5( 9$(%fY7@u nxT;yv#c8AD\'+g=Z)'},7v쇜s^]L,z^^09G-m-6?Z1-YN_nj83ۡO e{;oKɬv)r_'cV3N&oR@$Ahj}eBӵ7ˊSK''i BA! /3ء$+씳~/i^ [}g! d `wyxw34c6>CwPt3^T1hHL2 bH \ɼ%EI{r[6IJ zjNB|m{+4qy.4;2_lWv7.uc|` "d (S[K74]$mHGiCʕ2=7"D_T]91MVœ"[ooطڭBbЋne vhY6KNM i@ XTyBJ.fEtNM늞1ŗ);±Rc5ww Y1ppERr!d`T(B'&ތ0aM+M4r^WJ9C BpO6d28 u+an) U-]ީjv](CL/|+Xykqm~7\w]  yimWlխAN|Goy@X-C5Z2{הNW}~EJn2IJ0腤p>xl# r`P$ 7DaT}z5a@/qׇ ,+gIZtz^Ѳ0ggseu&`g78~nK@ UYxr/n *z \jg-X`nSwm 5wǶݓ^l3!EQ%/ܳɁ]~1w?*˛ą2tz2A 5AV#a %!h.JrYٽDXV-=}y ƹL-8I%v 7з׌CN- ǮDbT|Hh3XcwksppdFAUa$}EIK|m~J.~Ũm-F .z zDu͛F 6R.R7gʧ\{hqik1?!##)CxSjO?U̓Xf6%>Q2ߥuWlؠytF3AmHAI5ck0=;(]nu{HpZ=`Z'Hw)XD7@_'5,Hb-gRӃqXx/o-3.z<~'}Y8pT}?!aAc'&F\-7\:AzE.юx)GBur%w&yɝ連!=P$ 6c ھ*H쵥gOp $>u +5q:FV }g"MLk|o돣sZy`ʨi߽oʩ\^oyTCV#vl׸^#Ms΅mń,}g)TWEzRF *s r4y'=8ync41`=ɁB d*Ρͱm!XDYۄbHKxӇi ZxڋƦ+z-zV{]icd7 -BȻV#I o4j (B=׏ oW(ܹ6r lAVG/ŒѴ*~h9 ]*S\Ka wh^:=7B{{@,vپdx=݊\zM?[VP$VP~!k80M0WhC֩L2^Bo12m[8H͛RkAj%$0gjE/IIVDd$:A%l;xlc*$/4a{R(kPRl\n9fG.m#MwkJ[ Y1;W (+J9ڰВ%NFJ‚t;N(l%(E@FR-Tv(H7pRWn|q̞VL,W}bMRβ&Zz+)YΝ^̩uj.')k3BPJ D?@;O6}sTJ,AFKn$V.}b c!bv:AJ%B&O#LBK;?ixxIhguĉѥFxvki ZqFQلzs~尧l u\ ~} Qvwg1S"!Լsu1'MX.3R]$6ˊbȧ\0GUclLp܁_Wvy≕ a V =<]=L ی xs#NJ0KCM,𣑤4%NbP*,ʵo/gOu*#c)gTMCԿ}>$4v27Ϸjuj+{|vAsWixkoeo{rrv(yQ/}뾕TDpxб)LV4 &rYT` 2[ .!TLW%5#=^r< Pw>]h+~Fo]6'ȁ mxy落D)Ņ&`!`?0:Erv&c dV@/Ã-!NAe|ݨ8K*!,mCYx]$}hn>Ifσ'ޣ.ϊp%<a7#C_z(]MDY`sJ EU,%tNOi?.O0,BgkU.|Uv[n1#S%9p/m' ">(/BTnpWqd?0Qz1l2Ts\l *oRC¸AC<EeAT䬉NpTռJU}^;ni״ ,}>T"eQ*v`rҋWȅj`3ŘYؿɶ[ `*o=M$ދbEV2(~`OqPrc@҇xm#@SEpj^HS!uX,`~37Q$ {pINq.It,k }t̶+5?RxF eq=6~\OO$m? ۵ʳ\yxL_EkG^ڎxlѿT} Y~phz$pw7&C6_=բvysaFzb~+tĬاDGĚG*ͯS 5:bb"ϻVd'/ ziGcˊaR~${3Iz{P ,diӪ/NI X Ui,qኼ{Wxy6!m?6SA/VW.\w©#(u+BP^o9GLy!6E1Xؑ? KoF)zNy=m^( o3zkfIsH⃗Q )CHgzF2Y*˫I4Nee>o>X$%I >fkQx`P}~f&?Zl>ht;bWL-e#b< l%[—Ѝ FaV(ZoKMX}p˩E߾~|D,H,YC7UdےAS~vTk4{Uzyk1o m?A#v=N|xƙ πZϟDnmt_ccMĠnad*ūׄȴ(JTzQPuKV%d._ |bgP1k ax;n>Q1{ڣGgOEԵ&2g)(DpAb%^8c=iT;(R#i֖2ZDD"CG%st2;K~Sn_,%/3:.@2Lyf.>0ȕ晅$%'vhf?5zHq>Uq9R?\x᝝ԜGy(~O*'f!dSN|Qtɫ7:8ӟX(bV7٢p+69%I^>S cL\n%-ec:d*J<5M'_Z*py(e(A]snY YPf:\L+F¨EDyxk3Y*9˖h YrA9L쯕DQ{S5Q N8rYp> 8?#$A(9(jd$}hO>( rFKI\w xiVm}n:Tw8']񽨵NIN2p>u݄z 3UT 2 =t)xNy|B$kuWr,>,6*[)J&B- Іs*lIl?eKnk( i1G@T1cCѣu-MuGEx| q͓GY hw/Ϟ#7D39Z͙,(Wyz iwyJ p#(6zے5PF$[yoeFCGODDa!;ΐ-lգ'6=N/1gnOrGN~XYys2x.F P{BudݜO@"k'AK,HG.pq1#tTAM85!-ӋB%jX+d r^Cp = :9Kf[Y)n.9Ghlr=6bv eC>f$!tGo(tjo:P}αOg--$ Csa|2.^Y6#pV#Xe 2RITy qi_@X[/lEt6} 1DSt`~o^'}`,=u͐ŚlW/T?ӫ}Vwo zck>]ر3_0DLj_Z?PU@j7.dBsfK+5W?tѾ +%fف` i4u{ҶyI$HaX0s|`x#X!EIFH#x|X\J8 ]@XE{T2(-YauBqp<'xj32s^JT̃eIxc\$h} t(Jm !rLRj [.^@W0T|%| m_Z PT)&f0uq*9bE,*&]٧BgB`Y8}e7n'ū`:Eb!!Zt%TMq9f=}H C_ΗGɋTqe_q틭:tfױױ c#;15-֓9,҄0s}軛yAx$ۜ}\@|[p dG4T;N(;k׈'swB%cح!Dj'b%:yzR,=ޜnsy9tJJ(-}ZTG 1)4RMM|VLT/ljubRR6EzIg-xކcvtLb.ȥrN# w݆ȡt!J[Ehm9*X@jLL/c<u\'\u:.8, SlDvP[n.r 8^{y%ܛO0tH[Y584=9gjgzgr-hdXXeҖ>$4;_9BW"yb3ʧ m'…K5ʕjlMMX;a0 ۞ w=:9'V<%$0;f z嫷.2$ >j#E8t/ #1'WB ~ꂽ?a+Xl)sTًj|qgmxv'4kc / ,u-w^G9?ޕR/_}KF"), ? JkӋD>N/]֜)/mmW!VODE3/ޘҴMV]]z,&=uK!(hWrzn{O`XP\ sȄz'i~8OD睃fãdQ8$1if,^o)h͋^B5-Ux[қEOr"cl7g%}#i<{WO 8+WYBtҷ}$ *A*A89!uպp,Н[B%oKFA#A1(CMl}ȽO{K j3rpDϛj^"5x';ŎP`+p 4AVJմ=]Q5T]ovKʑn<7&}68FB~Y(/_A p1p5Ǩ:_PMaaWÉ J1Rʍ;*_w[gߢ{-\yY3OIt.k/d:}~/ G# iFtğPSY(2a*@tzT}ȮrO㗂)rUZ x? KI[ڱ7 8hsJcr[a1X#{ݯu N($P(O^ٞ$+1+}QW2ߦՋ]ӱn@Vn;5S=mM7,XDjdwox'с,+!æ-y0(~e4f\zPg@Ĺ?;ly/%HU(P|bB=E Od%gȐm~2i(736U[* nGޝFqfñ/]%?1`),l7n]}cH^Q£Dg9tjEřE(3*6 {BvdC` b)OK#eUfX?1߃lAᢚ%ڥ;#*m]ז1_ إqUra5sW㈭Mʕ^#5Ko~£8)~R Ŷ08-qccglwD)O=L e(X#ƕd& *Wu-Rp$jIP\oV MxfֵS(?LnE v^m oԫ"z/1cbF $}yi=,L8PvÙ6#X4ߦNȲ|OB0uM+IH#D-ҶN&f$Eq.u~: q dpFJ$b5 TfK3>*7|Cc< 0M%7ܓ^l/ZYFt/0hDc %r4x5X'uB~ aAHmK`N%xٲ5DŽ:NmkiN\9J3SEI\n{yzȫP g5X<B0GT mYܳ\g7˸I7{\tl=q|h k&&Á},LaÎyvFNksVVJPՅOun{s‹DJ[ 1V!iLA0 /{`_mYįBj*}QXv a_]OV\`[\Hn@}Y?ً'GM' mgt7SݎPM-o5.غّf,.Lu3Z[H$zc0 |BN =*=?cp) /K0Kh51n[]4xE% rOyLuWT$6j}b2\N6{cl$IY Lٓ: YT!*^3!1sgb6#J\UJeTt*qϗܗ'wd^\IF񰁢;ɿ@%D`>a0"bЀgkeiۣknep$EN<}[d*F`|:M4g'Be^FPY:K bpv(,*?#bW'19Pac56dgiμ-ԉl{ Q VIxk@zP(嗫(+zޚՁb!d:[+G~hDa]|ƙAiƀςSM29u3betbY#B!! tT{eq:D3Ry3H>EPEs$rjPSu 4OSqc"zbt($tc 1g4C%teQP t.EQ44s?uz?@T} ADjyS2ɞZV?E+w T4O 5PR^N ;ɂ ރ&3{BR1rc>jkzdGdW[6l‘UJc~Ȥ3q /BQkK=vDHS/}wa[@`6SžAn{R`~ ܇is5vJ[4~|+5k#!&E_\G_ycԴZ E ;9G|ZOB Z%iVWO͆U}ϳX < "ʅuқ޳8loJ6tA`zHTi)z3QV6c'ۨ6 %ez3:iHbCK~b: tQ9[ )?d*:Y QU>t k}Ʌ4%ESFY`{ )q6Q-,Nh#Q 7B&`b!cY /^g57Rݭt9fZ_ ;K0Bm9j5S L+$wKW!.ܷ߉]x`u4h epVK*"-e7gjm,cc ؤL aU^dEy,m'EkP?m'$PK`'J&0m"gٴP1+@l5ӕ3nobAL]O9M,O(ѪF7ST"Fu?Ѹ3%& S'R '_ ( cgz yN&8I^Rnwr D>]ۄdtZ^q͂(Q_m_쁊`a˅][ܸECro"D=p9'ysT;qQ/hz<7NC[};O/'D_*l2Sm2Vf QKe8^ iO)Q҅F$rrQ'D}}P~a T?ex$2 CE9; 5/VҠ\n(hM845dU^0,Dbi6f45hwGca4Qw+qciܬcG7 V^Gf%@6<6˽3#űު|z/5dNH tOCnoz 5R$@"tvY4Brh%4Z,N)j!vڀ!ʞF^X4*H.hAHhb"" އxxb;Tjt3Ibd[`302tpQ;}[ztW jЃol-ɔMPh;qF0vbT AyHv'a+cFBsZP❣Wo  CqڛHi 9)zJjnP/lg^(eWoƚ˛{[xGEj :qz:GozpsƖPГ!BΗkcUit;fռ!~:CGwyv)b߱ŨJyʼn,b. ҂IH p!Z3/ }SƦEX"h|J"W ,z4"]win;7ߞa9 U`lwr9^cv=[PIKgF戀8 v P EE 3H#$A#R?dO Hss l}qDGo6"|^ZN^A:̽Ro'P*#:6p+asqM2@🀪veV>D?kܱTݡ_".ZO{ 0[@Y/榓Fnۅ)wOIt#@kng֫ [yj,=W` v78#PR"N[W7FBwM祮.wuX˸3A*ZBR#nշ@_W'L8Wn":ur40o aWD˨q-ϺNI  YNUm ׍Yyħr[Q>-MZWRfpz|a_7C=ݑ;v$]y啲ߊ9Cs<W 8Z;+=2nsI J$YuSY*2DG SLAzZ9ˮ.dt @t<5=(fr=j */*zךɞy ք _,Ȼ!ׄȊt"B>]x+qK[YzRZl"1[vn:k QxdWy+w/qπ a TzoS>6<1pN\QJVtz)0O/2.UJRDʳmF+fIdV5/FȤ -vXSXcݤT̚˅sK^ _ i'0@4|vDl'D~8%ؘ$p ,M Oa9^$sO; *:)!3y= -$Xf6yݼl "tm "ǔLzs vj>yQⳭ4 /u ~(%MlkSnMt nin; :f9Q-n i\^F? "2!|[ {AS:⊋xFE^#x;3,WUq3n$w.geB۠b4vk:'1yX,?Ҿ85`VQ3eGߨUJ;ȷ"0,>d TAbo-">5\p{ ܒcXP됸IzT-m{6cIKtB)PB1ݸ兪%F"IS< Q dJH9- jᚡBadl/U~r ݊e֪XC;GTǬl1 3~[ z%={tyc8۫Frck>|cmrDxi٧SmTwXԞ!/_5rSTns#Ha2H82+sȼ+^^YQO0BMLW2kff.Rt5֮b@z\ATm*JI!CW8˾ZpytڵFdPXA>k޹\80`hl8F L#4TMu :忘^cۅDO;1s9E+`o:7VЯ2hΓ?(8O4#>'n/C,5$E#PyeGv鷧8-"y7pI۽Mgr{ \xl, 3\LSj<ֽ}}swr  sSr[t ,bĈTlʢUHjxvgm2wlZJ.lPlRy~*A=_FB92ؤ<`mlOנ;V)rX0'q-; i &sU-,q 4[`2~W"hz=\azϏ?L. 5K!P0`N4Kn< cbwIJk"L Vyij ܧ&ok~7rsEUp|A~{bTwm=}뀖Z3>f4қ0fTdK/^I Ph1#.uN*n$!Fu{"[" ;ʩpu|-{cnD(0*[f᫽V.%?y&O!2k&w'EqR2"$w][sI|\7+ܲ_]EU3,`\ӔdXv(dA%((kfP(#RٻWTbX{TZ /ȶꑱ]scZ2fᣌXMtHD۪r)Eܯě=>4rRt GȓGT/1sfZ5^S4zu}qwz˭'ܵW3IE+![N*%4*dopέ,/j=5uСx#Z>y%(J湁\˄xg{_%8 i .­![y7\K0iU@$ /ԾD ZÈ1?Q{noAefrJ[}}"v:ԑ0܈g~Ě+,s> -o )E $M%bGltWyxZ}4S8">;mJ$rPenI-f;^fE9Al:#Ae_Y BAu.i1 ~=YJL8I3qѻzTp) e9wLQZA&iml#2& Ek|~;To"(R&ܮFU/`uxeEXNZL2`az.  |ދU[{ ?f+U.s9U LP$TDjguvii]MboFsP84ls#ًQ5Laڢ 1;6(<}6jԳM`'^w1^J"}TK xm !2&xIO,*Ǯ4aN[pׁ%Qd#FG5|=$tȣP${G@pig;+pJn8`-i2.yUE@[i(!m@$*C4vڡ._R=i'E44獛4MEu#)Z' nPa~Q+d)x;`, mֿSIOnF;vom()BٖyHԀbosm?<;㡝h.Q, ק"2yD><6MON !@ `IHo:x`b]~K~T@a;&Le6BSi8r0čÔיdj|a@/ʪ h˽o=Ф±DҥX OR"=Zc ,a ,s_QGag{sS90]5le &Kڔ)o7-|!v5MKI_(pAf~hM*X[CQo'jMi˫-XVxoOM`?5hH_:9.`k'v\~j#roclrmjkPrjaDa1W;]dŝbu@?uՒ.VMOW1 mNtP0~@}@7ACD"ԝ'2V$BgrбS ^&0Ilqb9ehکzi54Od20qpgdXZZ8xL@KU *M'L_)+)sm5Ж/ \KXufX~:[3gMlTtϻ,HJw0pqYBgCAF5$.b| 0eXUbyxɝp񿙮=|&k+( {# Af$~{v -T"?ct_̗S$Fٽ?gkCCi@[GrNkR❼^й DN3G1֛ϥʭYBWyt@d9'SJ;o]sk_$ږ:.@lP47(J?#>H'Ys?e|ޯT?{G mZzW a%VG!{Gb>u>x/}V_oc%OcE<Eɬtr=frp1"Eo N,ǠXH v*cYó:,K5*3硦vxoEMiLPyG9Pn6U?g2$)Ue$7ɭIE=f[w@*SDHiX"ˮ)&1<ŮJ LkeEΏ%Aa_"(jW UU^"#MȰ RU'΀)K-9*+58P;t@Z<:09_*P&sU8T_+ۗڝS]|0cCң5ӧ{l)w?9Pe0^|]ΎP,[8hӟզǀ4-;F o=2oٍz9ANN_3 anTz UJn\S^@f[eBpv(ͅЋ1Ps%&:P[*6^<@AJؙ'3~p \웓!@(3w'3a1m]~,5OcH(eTDZXa?A3Ђxb 'C[]^NaY2{E tL"&Ǭ t~^M" 砕k>56B ޠ@5Eҋ>${8KO*R;A|:^3V`I {C3_KOW[SK|$ i׳$rt鶁7/߽KZ)O\1Pdd@f'_\nNːlp~l7Z7Q6AqfmpM2u&GGI\9@o;%/lEoU͵{{1× 3tWZ 493G`6fp sfn!t3|OߑXmYvxwUH"z'#+n~[n87 :r;CVr)gl9%J5dsXk}О]a`l/)_%>{TeOx`Z/e&iBQ٪"mܯY͓ϲ\*KE604/aύjZk;|QOYjA#A\^ɻS X(;*>~f}KY.w5d{ˢR$JE  /4!/8n B;ů2 {u_<{ !FG["v+DV֩{(uqӷ6JȘYY#<3ԧ ;2 $Y]|g$E^ J=WM#?VJKF513vIj^fxE,*˚ESmaR#ѽvGࣙo>+f+>m: 0I[Pcsfvuxt@ j:T 3tnsTo t:ǍrImS+y;w'Ǯ9UPB w3 őr`"ɕs(?r-Dz-AqXAw3YU}5piDļ+$Wy=QMP'cȶQȂ/≮Ϝ_B4iokQ[ՋևPY+;BC5~|cr 643"oB~\;d_Qy=m{Wb+9am 䯚"Qcdž/(=W.Tq[]i b3 ɒ_egЛ"0C2F #'7Pt&]~ 'W̡RۖOsVD\NC΂V}ʷ\MۢZŻ+o +K#У~OQj8 .dRF]ҭh8n[tĢJuD j)A[ǿV}Rx,Ml1<*3ȩaWU8uDJUϢ5 ׫:L1H $~@h%5A.gA+FONRnKIçp'+6=ib;V9SM[4a_q{Ҥ}{sO0$JQXdŹ!Y>L 0 |9k>MSWF %o.(V]Ua.ő먰?41wW#֓tqE>5}xr|qTW#[m4ܤwÒ/_ S޲+K+Eysq}ٻXl3psRhn#uWJ3G\>E߁+1tT> 83gB=tf& v@נۂ9.JB Hq 'EoVk3>XUς:^7s-,] ^/>OaNsTuE|GmVV̜5pePl@ZWY-<&RrŀGpK[!jsJ8VUؚ ϟU \92m8XK&];FOZ1U##K? pkb%;ȟ,2I=ҐbIjq@GC KWeTLlG Bfw$7H jwZhHYWu8D~^^ BzSzddyV[`NrBYxÕ)2}UUΧ*@Ct"aߴlz@ZM,Vx(*&C A":v0aTwe{ipcp<NI ؟kr [d7lc(m.ƺ/JUN# Ǘ<6܄' *RRȡ@Xr[<rn 6]tYr(ʠq } o# Ï_/<U pBW`J͛XHۚՍf6W*6Q߁aqO 5_βc1Ea.2bnu$ XXTl)LjV&rT5̝A !f6_xJ~mu[Ⱦ'@@/{Bb [{HXɃ s[A KaȈ1H%H^J`UFBU})^t>=@vxw 6u1ݩWK|@.G*!_,iGn,B&1DF/%.|Lp,r0(ȟd #W 5 I]HԮF,l*Rui-K $UdJ$(>Pmd.F 8Tߋg 4^9@kW.Ƣj3'R͹t2C\hJy5݊iLS FFT8+0s 1qߑPBm]}P¨~?XL5  P{NUn»7h3]]s ]ts,|>]͆/p͞md^4p e\L ~ ǹ PY&*WV%V Z$ˌA'{sNp{5܋T$/~ S3' ?Ax hm.'E$<o4?M%6cyqQc؄>WY ])W&EO* կh>i6c"\-Xr^c._X~kj}N06H?,qj)Uv?Ew5kthjDy[K< Y$oe k;kKK,1=νnJ ,CL~xo?7/n V0e2]t5g2v`ߍeq].i[Jr[B}d;4MP/SYewAH5I7t c#ºb]ee}A `GĈcEhL+LbmvoP' _3\{7'8 ?eX{;bKP4X?P?* :H}Zm$#vC5 Y{6_n~<$<.NB2oޭ派[!Z֣j1Fs+TXhih1 xeW\ *nħŷQ5uaڷsr>(Սpm: vJFXod[_m>kh(<#ry?+wS`iIcY@GN KDA &)8o 3ȕu9Y쿾W]PeDP=B`Bdx?e'v}%5dHS ^{33`n5v HeE9"R*7'k/ðEY73#g7lXM/w5 jDDWp'/mAِӼ\6gI")R(3JRuA8RB%dEB`9K)CM\Tl_1~7"MwnS ˭H*KASlITʯ,&g#p<*V駈ƪǸ5y50Ea)BdF =G0DY0bnCCE>$x\HŐ3 ZsA_ϫ;&56zЃ-,WP@\oYPqo碰+}^<;(Q`ˆ|BY:o%WMǽtf4OL \*YZK20rb6>n4㉿r[4vޢjUO J!k]2a!(p# :Vߍ^L7ːI1~PO#<+i/.cV?^iLq _Vgj$d_4,Ҙ'T<=l,"cy9:V-C1DoWJ["Y .VJ0 f$.9Sa_""k}-ďz"WT)!r~cHN+hЛ>qǗHXتWEpNwُ ^N ߛ48h|O)[9;O=& o5)r^  ånv)ڧ'Nr*%nww?O*'gZt-z~8 ӓDn SxE~nsk$Rp?o>?غ' M3ចm8t!g#Ƅ3lޤGKYfpClz$~?;T8ewG)bD/c"AU#|ĴRT`g%? u$,io+w+yEۮs!6T+^9q[!2˾0nI_63N\337o&8}Q}ד3Q%"2T /Jj7]"Ķy/oN7"he:ihx~:GN7eAʦndY[cxctUc{̉s8Mm5F /,?(x}_g 8}>2_tW=I"k '5<ijtU>Em ĉO)JEi(DIKB+SeE48*YKֶa!jXT7ba=>K Tܲܳ7vٲ \5+Ԑm&: ic06/X], A?jX@s+El}+?LԋN/sgD^eXRoXOW]F<'q媬]ѷ1t?}a!\k~sOQ^ 7'U.8ͅ/+;e=?FWŪ7z`usCYAiGPH2l0Clgz)3VwwEg-|pPM>lM>\mߙOF99JIؙs%hHRg# "̤m* DO/\#@ޏ5fp3;!ݺ7*Y 0WBག[Eols{jP `5ǿNem׭#bIWA=0 @ e卿'Ġ7Va 㒤`ki6ttVd= ethqq+Aֶ1\:?Hz6"}4!;S:bV/-"qYOUnлަTe8VjW 4*s4ݴ娨 `I}# Au!&DGe9\k{˵3CmcN%ݚd%Y: Hᇴ?ngzAlC!k+o[Y<KG0Z a7c#!Մ^c{˱i!ǁý'}|mXgjUb5igxQGXe [-|Ӥ@KJL7_MI@eost?K?ъlw.fn7 (Q'z(`J}-/|u2P_ L%褆$5S;\z8"~!Ugg7C:#%Ek7XaQ4?!m;MQ>53ß'I9&fs*^ +J'tmC,P0A^Lﳰ󍧧ϬQi0@k~g67Ir>kjΊ_~T!OS}~߹c 㶣=]b61GflI[ҢwX WT=<ѧ;JQfpi++V{_[sɶ[j!vt$ '=^zCbĹz9d!bLYgE$ic ʼ ~K\I [ 0a\SzLvךn9DŽ3:`(2pI^Cwөod|jA/Wi_(AQQLV_d2H@&j#SL#l?=WHѮ/k/[Sԩ=lU)>tțJu]u0_2ЉK7X{9)w2Du J}%HAzkCAcn9"ڷ#6Oa K@b;"xyv^ 98G8HOq5_4 `P zgh*Q [m\!Όi^ QxaJb,YnJz Y[$$\eP 3b+XHoeYm=f+MCR݁‰(2y]B*V=g}*[Z_%{W_c.FQs?39>twOE;_G''Zm N=? T}c#G1T6tΑ[NY <,L1a'p1>B Yͼ^[Ls1UBFG00tev@_#TJ5 j++%hlӻp\ÂEE:m3zoMu+oR&{mgC߈v67'=>**h+Lے:/v$fwʑ9P`PփrdR,۩ml;f`E/,"9dC {jI#|W36x'ENS9Đª9_JH ZwDZq8 q7G Y^;nL csA v L-2ҁy3[4BKrŋDcդa1̙ZV? s[YR:UR;0Pm ݪw]Ǚ pgWB;X}P7Bzu9|1QM];WI -<6\E+i9/(V޲[ĦTfPO4\q;QT9Z*!3hY$C{*=t|C rO/\bC;lTEBr~kj*:{C#~ SG  Sab.>EgdG$tVO a RHR8i;ajV(ҋ=mo-QioMotsbO,L*|d!ݤF=JH0 ~ #Q\-_ "/ c}xZ>Y@&xhy /,jh{  dgXԿJaܫ eOg4`.(R챀CmLl.3H?߄_yiz0oY|27D_5zMTvL]/ڗ\{X7e*zH28}["\"sFv7\/?Ԫ;M]XU@:;rK 5NuJG 9uԖNd 6*z_aliM W7)D3?i8ɫ)ʬNj7Ы~L$c7;M|/{i*V]1o*kM[cB1d5˔?uO7A  $l gpM*Hn5(C07of? wh?2HÉa^2#GHU0dxC%YT-#jOo+IЦi5~剁go3=h-|4m?(K $ڔ~$.M?“}%.V ='[/=.;C \l V4@k=-Ym>ԉya lM"ޙ? Yo*=/@-JqPT̹t0j^O90O>A+sXF?OaҼug["HrUj7D}Q#U߬a`j󦣺 cuєCTCBK‚\]=x|2Ud1`n~̸`,_Mb` Miq=KF3b@,_md F/mz~u^t\dc2^ĥꥻ&̦!Lt(wٖu?9ZOiqjrm7=:,QvRXbu8 pK}/]x=3Atƪ8:V)*&2i:aZ/pWڕ7l2=^Opr%8eP}[}e2Of)}FGXbQبWl6 BWEK'}R=0yO})hDh@2br7+nd0:3?m=OT2!LND4~Gm$2Q]m"Di? ? \.Zlsz;u^zSpc2bAQr3MD; ]u usKpn2R:ԙ V;b&B!djciόWKe&jc mrCERLc1w[@;H891XͷqE^`VAr<(Z#ŸŷGv^mIr`O1Ty!䤝4#0V܍i~Tm 'ADu]$_%ы eB)MُVdDf,|Ɓ}KD&.tmN= I>Pnك-byB[C Ӛ%h$~jC;L tJ-.\ϰJvOGAʅZ=rIrY0f޸oΗbA%̋L^~I2%8s EyVN\5rg:r| Nl\{CMd69RlhVIj-9,@Ux@w HM"fmn !xB޵~{tU@,d@8Z~8,njHsn!CXm XOw!np<&4ʲ}L?Z3![GGtkdIhɹ0khL<;VP08[&֭@lI'jp en1# ᣧgK`@{jWǒX5Om7ӵm_ԭVٞ>=^G=$=9(4fii1?jXD`FLnō6Aq$'F{EE !雤{QLI%'EMJᄌ>u.zpXc;=w֖@b6ke`bS ۥ_؃`.- ×}ps hvNd#Die Qu5__l͸_w{wDy}`L!o)%Z2Zg9<`Pģe Ȏ}JnLT\ xba^ǻy &<xՐgg 5Srs(7dW ˈK (}P4Vi*ځoXr^ )mjddI^ƔWK."t/鳎 K BzfȪsQOFg:j&ahwsf=#!.I]ydƽ5?NNi& ؙيF`"#ꝅB<Ŗ@=d JmwE&*RvT(yDP 6*j䀏;׊|5m%p5Z*mпA^>͑u@O39UL-ˌ1rBNg=Cr rΕSƺM ?p$D;^#ڽ.GSA lECՂ0g#M9GQ+{u% 7FN98?RA9n"˓8+S&+"XoHڊKzH+K х:ȏ,H=$LO7RvR&@]5W/cDE},v` )J&t`gQV'aSFmMӐhiY 1[7 87R O ☼|ȆM?ݽhxZ6c6n~H_~c=&ۂ[-pqcFn]Ye")R]WR[unY ۀ:tKn!qGKF "+9SҼrϓ+H{iO cC1 vo&De3Diƾ7[}83pPP;9r~6}h/$ӈ 2$ÃiTgg%LC}Ajdp*#d%r|fr, 7Ʒ`P/,Ǘc@eCLl25\L<#cooN-]T AWjܱ42+1N_ܔC-8U߄=uZf݈C`oXj;O %YscB)2ȯoY_: P{,:пlz%أ#Ա&\cxÌn J%,a_LrZ|I+n3Y2"w°-&."srߨ'?@(3S=gBMd !cd/C/FbaKe7ʘlI#_Mn{섈lL@<]Cp)ˊ>\Ὧ잤c} H uƳ6%|랽++UA|( NƱOD7 BKyZx>:1;B,Nȼω6,So"}Ǘ\jH8~.,DK5{2,Er,ޱꦟ5뱎nj0&4DB^[j`$ʽ 'bw+_#ttz= }ML}Ӕ^N`6)hC~0!f-wi؏Z2q7˰>^p= 7ىft)ÀP͓k*ڥ+lW͝5uJJC )ԍew{+j2s<~cZJL<dK@b(vnb4x4svC: Q# Z Ω%baYf_Ro WNRaro rHԬ!+ㄻu/H_v?f0kFi+S=C,-/eZ9l7`4(-"z$ϤPȴ9>z.ˠVVά-iK͡u?Q VP!V╽aЈ-ɷao7A)S@,Ubՠ3 M𻱳WA+Y+'̒ rɬQsX5)rwǩ"=WN=w5F 6eے`NBp+c5xOk 3Dt*@Sxsӡjԍow";bX͑\Q.#w2R!VX:In>qW$cb=@Z}!kz׸YWAVW{ 0uhe+-[ =])!lg7;LI>|gUZMFʮMZRw'[8l.LEW"CeǂniP{"%Iƅ#F.InP*ögQ JϾ$]mZF# XnHFnnhizy@HiپFܫV8P$wWOh|!r)gxO{f #䂥Ѱʷ4Xͳ9 Z,{1wyb ʩjx~YD޶q )u䬅 otaʮベ+'a|LlgˣNIbƢC1Y(琼?n#L󮾏փxƩ~`JG,%Gӵ'32mT6opKztE:y͚Vc>flXG:)GXKAPAeO } bKߥvkH oI-bJ7pzG#Vߝ\ZPs|dx@hN)\$*8*iQ<)ՋEgfZ8p}23G 2AwRp a`P⊈+.G-{ͲwB GsIVF=XqEB_pL´Nشיg: ࠛEr.HsHvB%9&* H&kɬw+(Ա_,M!=0B+Ńñ'ѵ(-debRZ C ߉Xf29?A.̧M뎲vBw0VUa&w=w>%]Ek~ӹGzErsji836RI}J 6cU}aGϫV'XNW @cHFϥHJqfr ݐ{F##Ar;yq;\3 RU|%ㅊ.ߞ- ҈%ic%HwŽtT-kH^ ی05J C:{DΒ1`N 5]yHx=ۉCQaAjrg@=pbċ_ Wǁ|g kGiMUZ7H˜ԙV#"8nO}R+{ $2R +KϴO IƏe8yՈY{cOSЖo4[sw\JeX *Kv`,t&9Q=i0Cc{OZi~@Ơi^02UF@j@@9NIGaf~x~ֹMT6QCɮgXZІ՗Zo+W5&u?܌m4#3ۆ Uyԉ-kcE ~yJq78S lt @_XǯH) 0\C;_t5̔'<L^*WjN]  I1#۲Ok*\>,I2YAWCO\ZKl>b\f?lDZ( DemPi{b+H[c hTh ~ѣDi19s N 9{ {8\0 5FC|!JO_ 0'1н.aǴbxǛdWTV0]-9vTz|7U-aMQ읫V n^0C~&B|DJsylDF(Y Ѻ)ck?@Fl~,+ȶ YZ