sssd-ipa-1.16.5-10.el7_9.8>t  DH`p`{$ƨ:cnnmƽsn`S`AXA^ YŹ?iq({6=ۍ(6 /~eP4D^"ZۛrAx2}͢?*fyuBA 2e8wzQ)qRP y @i(x[cc *R?VM-h1*ї 0/6`/:'P: 5u$9o>܅T[>\f&a3Ǖ$DMSf_zTPّy&ʨFKݻLj'D)OݷO$AGw_Ni&_΂5YG:]5jnV#Y%Vegsx3wՍ#:yGxml|t=D~_j+$6YkIXtPq0ҟ^}enG1Iӊ.TL%[Ȅ"yvc938698b7038acfd1332ee924a4961e61a803ee1H`{$ƨIt RMdE EӧuT;CbU>1f/8'glmI`:Š1Ǐ1} WFqwq: I7EMA9bg`-^\]p%A#*e&^ҵ +e'2?z2,}3'VPȾbaFD8c[PۮSx}e̓D4bkm 꿨F VRYF r` WcR1g+IwPi?ERE1[\Z%{c&P/KЙ«T, GDb|` :n|Wb2"B1+Lo{kiTcmMmGΕX<@CdOvIƃ >=(?(d   : "?EL    @  @`TTuTHLQ(`8hB9pB:B=!G!H!I!X"Y"\"8]"X^"b#od$4e$9f$<l$>t$Xu$xv$w&x&y'Y(Csssd-ipa1.16.510.el7_9.8The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.`x86-02.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $Kt&/A큤A```^p0`L`L`L`_cc75ca28d2487b762e759fa229db2e7d5317b2b98fe491f345c9657a97f5bc6241e36a7db1c123edf196e29fb9ae54d4fb407b94522d55ef898871112e36928a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903315e929f32bc7f3cfbe03f7383a03001b93e3f3cedc580d45d00b1ecbc7c86493241099c13fc447ae4734b62c9df97622a2249d0875f8a5a9a75e0738a2e963e7a734a79f62f78e84e6e7c8ed222b7f22920ba76daaccdfb9e1b4d851cdf7675rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.8.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.81.16.5-10.el7_9.83.0.4-14.6.0-14.0-14.10.16-13.el7_91.16.5-10.el7_9.81.16.5-10.el7_9.81.16.5-10.el7_9.85.2-1sssd1.10.0-8.beta24.11.3`@_ _G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.8Alexey Tikhonov 1.16.5-10.7Alexey Tikhonov 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1910131 - sssd throwing error " Unable to parse name test' [1432158283]: The internal name format cannot be parsed" at debug_level 2 [rhel-7.9.z] - Resolves: rhbz#1922244 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. [rhel-7.9.z] - Resolves: rhbz#1935685 - SSSD not detecting subdomain from AD forest (7.9z) - Resolves: rhbz#1945552 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-7.9.z] - Resolves: rhbz#1839972 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR [rhel-7.9.z]- Resolves: rhbz#1875514 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [rhel-7.9.z] - Resolves: rhbz#1772513 - SSSD is generating lot of LDAP queries in a very large environment [rhel-7.9.z] - Resolves: rhbz#1736845 - [RFE] Backporting certificate matching rules for files, AD and LDAP provider [rhel-7.9.z]- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.81.16.5-10.el7_9.8libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=96a708a6768c552ed5047dd704a8628b70059115, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=950e480ee086c190533d8d2c836b5ff9cd6d5ff4, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRER89Z;[h5J%c<--qGgj5Y]؆-?6ffS]|vOKFx/D0x3Ux6!⚥sIhlki gs? yWTS#6SjVDfYxWO8  eΒ.hFh*~ ֱ>03_2ڍhi<Um[ek?pt4UX+-D3)<! qj&΍9Ԙ1Cy^JY[ /_(ލ#`;Z$*Slof7vZH:yX:6 i߆y+2QMSOv6C¢Uz?\sSl|H2ܢWhH ҼcS$ȻFUw U?/.C 8*5.NNζhlr%kěpAAk2DQX^k<܁,bo aX`Ǿ*Q&f=mHRePF;ly&q_~*HDs1\l/"e 钠7Za75` a?'-\*N~^FE:5Ϙ,VDM$0^n#2N ;l[<Қ,$ -6Z~s7zcStlDa[w$]x!+WY{>1(8`Dpunǖ!vBp^5/BOܡ @U(ZyHM52`/ײE̪$IaڕiǫJKfjYZF}$U_ҏjU5V2֫$="p%*Spdr4AiC|=i- ?pwAeI攝 7/eVBzɡ0d\ᔒ|PRZ)aLo% ʟ,mDOF{]a0=PLJ@$b2[EWrȴҥ7-gQ~9_yUߊ7*:PK.{BA] 3W$,=Gj:(_6:%= Q#W6CK4̤XvCPjӟTTg{|E|[Gܼ#fE95MfdH2!d2xBҼ^fY[M^SCu%*Mk&U܎TTVBWZ=WoBT\ry>Ξ$$9x.w_l/OWn>XQLjQw;,l"5Aho u_&Er w/"0 l.9rB U'(\pۖc u{:ںQpflE\j' t  Og0˶c@ 'PֺG7gQBܦ1 ʍWT{p`7=!eͨZ3;4\Jcm`-WOUy(~[͖WC =r6<T7_gJZ"zL#1ґv5Ε2g~S ZSvOTK'Lv,m eˇ@'|zXFDMɾf+ma7,f޻vw(@TX#A>\c3O?!w.hCtXH"' ?P9Jp2A2ja0m@ñ.܇MI:Iw4]:CYazR~úwRsu [xE9l Hz6š1W'dEǑyqSA3n [%iz!;AX ͺy,X)TSQU.FԆG٘[bMFgsUK0 7ٻ,"3_{:oNwVR)^>;'?"9kiXz!5X>w$|㓣TxaXQLJईt4Aշ8w) e]\@>N?2V@E F9yvm7F ;\@%5?̳Dgy@fE*|7Y?W(xGk:oYs#Oק>UCqC#7ל5,N1mwd)c~J%{2u59L~֪9`jBw^jߝX'OU !o?<)"+C=.Q9xpwv7@9@6@w9B1qxh)˯uKdHC޶<ёr:|w:$Z8^o j-a3mDf$޳:&ˆy[DŽAV-s"m4M'$v5|Շc %3gpȳ[znw/u//'wb|c >is;r1<|1~- "yl~2ЕPqmlةM/7o,f tt,D#"5B|B$>7~%C 3e(Yc_(jwjnxh͙VsAģg(qdi9G5274* 7j;v UKvE L2(O>]~o!9mQ .@zD[$b&ghXҡ'J}9nkBlv oHc P\H! ·B34fA|O~b3(,?A:7Ģ %ӢMSHT ~rzPWn4OKkJVgܲ5IR|fPD?{aN H9(@wսyWw!P7HI㘧hX=YϮ)UƇ5Ȁnz8+iR]u KkW?z1!(쨿/[B]hqZjHj+\#ߒZcػʳxClHP,nb*0䧗yWS37~ȳĠm iW@EZ^Аa` ^;ql ,7}z$.d7f&Z_c%^,i bTOF Yz=rMh S,]x|JIoW+]-i} 8[;bxKH5vBUъo 憣yGAߒhƻ{\ʧ6RGF_`x:}aci[Ӹ e7߼;~q@3P"Ø搛8 %^Ѽ7 NAѬOIk<{+F\5S#6*=& !k?ڋ'-oj,Qsn{ۅd}.?`/xp]hئM_ kJ|: kuwYcwd칃BPRpVh4zP]nqu2!öRvzrYEpG5Z1@S|'9r.e FsR}S#ьGf=@} I~I76bXw{=JӸ:̸?Pp7X4A:ej=PYa=]t lskm !ڏG9Xy!+^s)0\ΠRR=k3i7H/[lB.pi HVSi,^`L,5\ĞoV4b0P+{3D֪[0¤"%VĽTnH_qg[Ɍ(!yuf?@숴 <_81GAWs:r z x4;p7Ke&"F~@'MǐHT)B):NuT gΫOho-a`epBw ;Cɮ"}JRjB#];=U8 Чohi{Z\J2~6 ľu y*|1)|L֏-}^r-\FgkU#ip" aqZ$0>*{:㒺lOa~p9i vu3Ot{:k/"{;QOz .LUf=ބC ^~Mh/t|dO?'\W"+0jF/x`UndA! vFu hPֹ̝aJBOD>+cZwo|B_KmIN˿;D H r@GZLL 0E5&]Km8*UZjmC#Zˍ.`mUS^М)ΜXΏ\\еA˜)D+J -0wDCooS5PToXተ0Y*UXc3K&03eln&=܊h^veivc\5tP\xjE{I  h>6f6~V k w/8xtJsHJ y)oy%0pY~[t[=~ e7wX0`:| FSeVPieȣRIN"]s!Zzn0B?$JgQR-45}m0I_LdvեW*rKjUnbV $ DkbkI(a3O%@՛VbA`BTٞɫp [\XKn;\HLtC(~8xyFQ<sNUm 񭹙x&&ªD;Wdp:{>|.m׾Tk~^8zibvfet2à&lCy8Gb"<~ WhpwQtD ‘oQ1h*{b Iw\kܴiJUpfיM;kh<'U?!Ĺ?~Ht_1 _j* ep6F֡hak9A>^gUݚ Ox ( kb +*Ԡ_K Ys@g}LbU7 h=iʜ7 zH]o\ڬv]Ӎ Rw>G^ʣIlA.8Ս]A凓(MGcw>4bV^t^MNH%@]l7kT-?2bp /VL)+BtAڒZ=]Xn{f0rYHl1k6DSe^ϚT%_Y=ௗ\84B[HCS &! #N1b-Yc8>E}, UTTlKUq;k'Iw/53KDn cG*H1w$ UŅ5-|z׺5fG,hC?) Y h< =Ns DqLs1yKşdGu#a ς0 $"u{˖No'tf.}!̴kx-%m%UbL !*Yaޏ7/JNi u:J ;q'f_ v&XB.+duCT$ =:o`>y=Rn-g]ZͲ/鰞k (GUϒ{L yLql5`ԁ &9X1kZ&?ւn9䑠"jؐ (}@<.S<^Vjn&A1ސr$&_v:Vw_9q=Aϱ[RP#t!ÊĪP g[y C K~@+QYiGEXcsu`9f/W+.OwO=Y) &hdy7s ?>;$~1Դ^`>i..ʃk3gumf0b :&‡*2+>w?WdE WI&rjBjV#)4ښRTlȀrɏ!O#zJM$φ lV)h T?]KJo v*N%|*E>>.`Ex`ms|[1N03@}`q'%S ֹrj}L܅yr~_]#$!<$5>{- rax̓&hD@:sIzw$Ցp&j$ݱqTanc&{`% wimcә` --Sr͸ 2J}d45Wna瀔oL)!?X0 w4IK}?,?ǝDmeU*GٚPV7P"\;BIehin^Xlk[wJ^~,>;nRz҆ӴMn , N~!eqUKG!|3hLi&!^L\dgںU$VDzw}<_8|KJzXCl3o<NmQiUIUfke 2!贑ʾ|k(Ա4͡NhPꬢơM3p:T#se@FWGuy?+UsB$TPsAza O4Fj`;*q"-Fʴ .KG)NaهkugJ#.7P2Hl<7 |L+r WO? * 91 _i_оCv$M|=rauO=}H)s2] #Y4^c\EfMuxO[D!d]~lV獈_a=$Y|kȓW`@_QLrt_Y}JS B _(䭟r wua>ʲV~oG\b 2eBMr?CdƸUR\rh9 0F zo![s@\l\QN+^/V:.xbˍ=6[STQl^(/PO3Y,l?{(Ld"#š:tDl52$OA+hlt6/z1#SKwREӿ#֟ftaAY8aif/w)V%68NjMb( 0tW{=x;ńUױB{!Y13P_!:1N4/!ۿKrqP';!߂X6cZe1pMl, mm Hn+_ :Ch} [鋥ITik|f5O +N4^v4sv87=(7Կuٕ3#U " ERnvdN6L6_G1:nB$#/X,'^a4_t^QyPxR{]:?)hԛ(Ҧ̜DռV97"l8°<8zȓ76q|sCb i,:6r!>]-Bc[:Y/Fˌ7WupAF5zC!WN> Ǣ< %R65{!>%';% ׆;JH`Zj]rĮanH eh8BŲ]?w ?dÁ'tߖt?nZK}ڍ%#_.&{'%S!pwh.}Ǣ΀@K%'RӒc,0 (?_K r\E gJ2  Vܲ2o&P~i}^㛓dܱZ?VveUjB;}<z% T cw0f0)3':j`O[1bXg. 4FsNךdS&#}⒇.,_ [ԜG޼,F'OOFj|>-~]^@fv1sDJ<7 F|Pb-Nk<lv]#8\˜\ =]Ur+qGhVPſ`-vSvo>yMzv߷v RwsKz*y,Zҍb7 w]*KZ^b+QoCl%.aK;ʲ*FXq8#94Ŷ'P uI̛4D˅ 7|ws5u ҌOW+նSbCczYMZ2ITv!0E/m@Kȝd1`)o%wiR1)FI{^&qk*a͗˚M^8*w3lxGlVWaN܂q"pEiliwT0^'1O">/sVR"ghXD&hg<0 ]X9ʮd}y7Pzh˃p(%g"I,f EĒMwc(wb ^xc`7O pO4*;"hpsFCLy^LmODrb3պy&ʧV˰6 ݽ2#nDt0,#^T{RvҶ(:u9:jKR"B}E/):%nQ-w T p4Jad[֮vXuIO\SKUՇqrxƽv;9Z*٩" 8Rڇ6mɸc:D xZ4@KwNJ'|~ӆeVQ z扼|(j fHz7|؉E2M.P̗x~ dԩ0@V MsN$ؕ9aybI^!r=aT&߯t+ ~ujE^fKEOG?߃4mƉ a:g͇2WTשWzynnZrEt+/*K`hr>i4!.l#jvNx]C4D/]vDEKͲ\0#ġR-qQ@ /5F5P@a H$ȜU&OR|!To pCWxGI|b hH4\:9jiYU1c(NEKG {[&F7袠(}b#⡦ d&{{&J3(;O Df-<[-;O}\ysULz#1j_p΄X S3$eQZT)N37J?Me#=)O@av\9i8V(X)kx%@ҮJtpH"wQ? kWIk])Nu55Sn*'ǥlHVb a+DUOM4]|Y `ר5vEbnм0}B: kJ;Wj=2VO|1QD{Winn8QW2ieK⯖NE(@ m>FEِB4(sp~buwlPQ&JU,̔G+_g6+@]oO28'UQbx}bj/|D7jI SvG6x +$(T$A9ί5%8 딣cV/U2R3&LΠJᴷ@l5}I{Z]7+H ŏNW'UfEP ,ɩ)%SJ_NfĪY'{Aa,eyÛ ^t kG~:9{qץ3 2m1wDѷ٩/:Tty&{єm֌du9u;=(YSSMc刹VPld6WޤL[\"}a(=b&7uk 2P"4J*b5B]w;NĘaNx(o=0rKh] ciżix+i W2 yLňbWkzWD:< ] "D:D)y.&WpP@VYKaWclt١x] /jyMEA rG`5/G$QM9A =MU4gc}Nq yVu Xg7q"!qlŋNH{oMxT7_{buzp?Wz˪IgQRZ[O#p)<}.^zZDax˙ep:̏x CUYvU2ږ-*|F=HjsT++\f{6!fg/Jn< C `c_jYH:B;P|`du g|G`J♅c`(]9P%%Rw{+IkaWb_FOê5whJٛ3UlO :#J=<7$Mi8AQrUJn˄wܛ$ 0虴pt@ZV[03xY2pv֓|NJu ޾_2as>Xڢt0t}{LXi)Vz4i$49еB<ገ S[&Nog}gWOxH =lN]NDS/|2^/5H0p'n_ n@KkIFBWi_ws T"$h&1|$S^>o_ )eVyQ5Juuj`B#(.ňV#b`\p ?W [ 8-}#O* Қ˄ :'Q^ekyyH%1WŎ@+-q0Ay3(SGcnE/\[0vCξV`41v*SV~d2K@m+X=NmrCdЖ4QT(pF0N#pS(|iV@wު?vtیg2ABO W2jAj((Q$3 MlIsP ? DnhA(Hd" 1عkfF7L7f?Zuݐj]E5{xF.C܊ueB%p,yQ( *x/&# u4gˁ! @c];M@\AቦQ;! #{ՓEp`D&>ώ}]Yk&{|=Z ZQ9J8L;3R0AB؏ȷ' 6+-TcCkR6ڽ2 Q"3"噚10S`2 Yvhy-y9Eܪ{ Ԗ dW{פ`^rR 0akUhL Tކ~ҁ>VUg&9_xZaif cl'Ǧһ}ݩE9F9l+ꙙ :,xhFѱ]D4"U;$e8&9-&nQ -ն>jޠ̏.U>])A1gYz tT-<,SsÚ@4팉]-?.8~@8g%LdL3 9d^džc g ]=Ćk}یܧuUg_E#"mą&\6Ŋܞ@\>}:*WHT˺kB+ͬV䅮4J\b3IH_YexhĠ- 3=kV/uL=aw߃@qq *Go[kFZYw76uC4)?@{- YѱKցNχλ廗Uz ]A͞ .:'HWo!vǟіM]1B dYnqM+|Hc 1x *QIS97ǟ0`?l{\q޹nR3ƝH# އ5#,GBy526QcjÞ0nd:Q[˲㨻әG[^Tj̽e 2ͥˍ݈K[;3_;0Q#{mU䟷7>t,Q DaDdA Ɣ/}`0\v:rXs 5tyXqS$W&_%wX=qyb^&ɂFjw.d u LB(685yڟ *n5[noϥ]ތ)08Uv"2@ڼͭ o(e8>܎bp=@9m 'e Iul}58؞ԍ05U;AS AM#+Q#1$9l+dPLH;Sؤ1#i[J7>=Ze,p5b \ƒqtwFӫ|ǎ];dOnZ3pTGm'.Gt~a}l&Nue,d3][((MU*3$̊x ,J5ƾCZl;.E4r+ 8v>_6m0BYErl9aSȊ)w }E/Įhu{\D*K X,L Ws,qb0#72͙7:xnjA ' l+wZ g$h 'L'>1ed‰VؤKN]hG b:F"hdqa#7T]V\O}fB@UW &W GT< b* .A9}nųvx-i„z z& xf>'!^hgE:}_{60zWi]q㯌Mݳc jϾꪃ':<5'i5w!iś밢J + /ꓖi~ 7 J,rI#)x|Z~%嘴$uJM;26Ԋof4'&M^` '4_SjW$gRv\ʬc 5"D1j#48C;c8@KYPohAP8+NyoIhPs>qlnGc*pB+c'um)$v=0epcR_lo^ylt5ĿK"sΕx%hѱ'?SatSI,**g69u,5.PmJ |:C[wyz?5vf 3z H."Y &Luߒ@Y^ Uo@Za(n2WSH1?D0y' \tGPVOnx86Mv=ost.>Q lH8v_KbeP<0eugꦈقTcӮa?$n]:.R%C*.'9A50rJXM3F(ߖ/&s͗1Ҿ# ˌ|@iaχ3/i#CCVrIUj ~@/ 'A9E<=g[Ͳ G)@DGkhhƏ^o:W1;):&G38<1,fcrB_}]} #+O<3W&nEQ'_œ$i 5+7?+ުD ?2@EȲ3:=z,MSqOg/.'.Je|e7 P: U\Xy6M'q)zIٯ5ɯFp]* ^6ӸրAvai8:`\MʻT>e&Vؿ*kFqa$b O*,elQ)>ZM6?<=|SQ /4kg6V>_h&zr?EuF.OGSY^iv]&R Z906kQtMޗ̋K]L;x@=*utˣ}8ŵ%J,t;CvK0F[K?tc$x7dM~>Aq U#u Nة"` @b&ՙl7¸;5RBZuK I % n,iuzt„zE/^'9 :'kɶ`,܈q2ь-ucV-P}lDL ޮ/YҀU܆&!ܲAd u: w`tےĠ' J*{VbOLW:TVs`?$-%-5_27jM,@o<%1԰3ʋ˞=OL,O|b+f '%ȁW.Sr|KE6;lCW0 _xofH )7 &H,:\/ZgnC[s~ U˿(6/ 4?͜]d$v 8SU)>pU`@ VMQC¯c8imgt%N oN0:M t5gv kaǗV2z"U($Cǫ2K]3ܨ;&:[:, =|m@Nf}7og2u7i& Ư\MNr_D¾`Qh7\KoP-nu28jv-uxiTF8?D%̈>J+)g{A!Vz6,:ͻ@ޒa4@q |ZnGX\cX2BpNe:`|+:5WA2`}WVd QPXN2I#D5GʁDMD]K;[΄l1_7MgzR?"Bٙ!˲hl2@qzPT3ߦ5 fʣ%|K& o)F3r j=ߘ5_&yy&3{5Oڍh! f{9NED9x&%>Vpi AzA~JuVD=CeLއ29Uѣz IsH^վC# S%֞~1)wB~β6C4nwݼ,'}Y9iHKed2"A8ԝcEǃB&qb$ Su%CSfj}D` ?{&R0#j&|[7TɆ,gFaS"1k.b%|",=K>1@˱Par5Vus].:GQۯI5VoDG_5DZZm FmW0ߥVw |[j.bf9v\N&5HFN?>~ #W) 3Q=rͧȞQ3#=zQ..k-βeuNRO_-$$lx- uQX1X?DUR6:E کXR5w݈my :j|Iq=F%h;Kj_;C1Je,BW1X U߷Mxxaľt+/J2ڷ.œ.腈+K5M+Dr9<-"FAo:%ġR͟`QY *Ԁo/rՔA>mQPn ߶Gg}Tt'unK"]JX]6͹́\|+TʸܻV݌l4^jFݞcݸdTF$߷ܕ]i(pj3QxcN_y|^[)%X`ѩv==|F뎀m`[wI{%OS80axU=: ;pTG:, =N`4Tz <ݲx$+^˕P}'8,wW< KX|rPR 4:^t,Jnmk2T2"j/usugP]QğHϝeH7[f~-Z%dniȾXmG{U@%0ۣ7W / yI~M2k7à!\zъ@a888 :ٚHL2_>p-d㮵+~Ln, ]jh$Hid.*ִDlR`7މӶHZ5i48%%(`5phDfakWxrx?&pX'hVF"64g/^r'L8fULwUIQpmtͪTn$f]x,͉臆ݗ店aR8Yz\Fc%jmiwyniSe;[FݥR/(p-SkQ,kFoۚ؉ O%b#l”:>PȚyukq궗/4cxŋ\mѸ4+Iz $ƙ?h|hFw~x"Rh'£)h,mK 9m䋄VX@+==Nm5i17QtīXIxF5JG0vvO.OA5|TM7Xm2 R_9.)Uu%` խ۹xjTo:\T5*?X<0Mֿۉ#0Z| _cБMđ:Sm&T qxٯԏqtatPLLXº6{u2jS#eʵuBJtg\GX&dpII|0<~v(E3`廕2e%=/_S*v \Rڐ~&s2?inNez:m8&?D\B7GҞ-T,Vh* xWHλ۷M ]V(S֙<;={#I"tMVS|\m^+SxY 8yJj& Kx|IJ-i:z|)SRpN#Nl뜞7A<( BŲ.@&ǔg5HMu&ch(Ef3υ'4]/ɊYл4X: 5%CQ܀g]Yb?[ rš+ֱ$xJK%׵S8[9R/`D@}64isnAvht̄5'nCf+~i ^;[,t잡m w%J ~l>Tޘ :;䁤JsOf>,Lz-&A7X6˖ű#VvqkBAFib3l!nk#ش{R #cL0gvs9  &rCeA*ZYAIRtB,F`k ĝe^۰f3-\jtEGYsv^ #*ΐ|!1(B{[2o"(pT-+jyKR3mݮQ:pXUkiIRs@EGeŲG_ M +,it xygc Iiۖ97ȢZꢂU%h1ͩ$>l7`tOnOw tx)"ɞU'R8p׃4iίg>yo&y}w_-G?҃X78聟qx'd)M H#Bȕ*QM2K-iC4]^EP1dor1w]CO}4芢/M63iX[[v 2<$i@)Hh))'yy#kB+?Hg:_5J"{*GߋJmw)H:vV 7@Զ@[׎;Od:<Ǿљ g( d Yy'WA(:v} D[H9{˜$̫hJ}yH1w}_<,4/Efg{m̑BI2dfqQI1$ĩ'y5-4~$ ~Z`B 1󡜙=z@2@Kc;pC<5 7m=ae~b=yp8t0fm*v^ 6KcKV0;eH0Z{0°<.H+MױR1Ά =d;fjxFo 2UF{€V)Q$>$("y] CCV*rkG'QgePa-*S+`vzX8$`o"_8_כ_ ͷ9\`篮+9][[$ta?7#mNIa7ୠ5b,HhYx$^$H63ݤ@#}v w<0pR24heCUUX ]<O"ҿaA:)WD=¬v5edکMx9-1ǢϵmS`g2rN r'bW.Im/Vy(G,kHIStR oJ[e\;f%Y+]҉5?(}Z%Mf 87y}ڟ|U_yZ]wX&՚&A2yۿ{PjRXh<ߴ 6lY^u9nbtQH1[J#'OlzӰqb>#,'+N X jZ4>3?s(HQ~;Y>BVgV CYqdߥQrsak⬓c;p Q}sl@]i21P̫qx<̞ta ud8wh]'6ʵj6ԧ3/sރI7/m #Byۡp}P%WytVWhx&O!-0i+ձLeݙN1X]t}v|,9O3fZ1]ͰmDM@zJfÂXdu[Ⱦ$aup*0![F[;h=0Uc#5R=~d ~ȗ߭ad4F?m8sv؅[J?дIJ>؆U0 *Y3@OR+YllI'o`D\,Da-DobJ4/ m e(/A\EsY/p[g3" G?Ceܑa]y af_:k+?_5˚=^AQ=CyJ++R"F$@҂!(BWA_+{O>%.a=GŨBI;#Qq7Ɇ)b1]t}e ]4[kVddʖJ[ 0V8'ueњ"XԖApk=̚vCZݸf69@x^9I`7~$HG:T `< 2ԩ Ƈ\T/b7f_`Q tdf"K={9阸)Te 8`HqAF"2wnT9x3H6P6 N7 %Nhb)0zy*Qy -؟]W1Lq3.u)J -;񾬝t#ATghUN`,F޴O <*7LK]9~4:qꟆAʮd55=odU4$ ɌD V(dhYM=3IfFp4xcP+`-"kA\,=IQZeQhDI[X?T*Z7g묒f4{lT㩏!,S:=){@;^*NL?x¸`oêo*1N)"uG{C%4imŮ´ Q `Ś0F}$9x#iFI,)y$zG6қLb%4}x30GW 잷,RcySA iWz٦puaQ e Z="!^!QoFFї.Ebf25C ٢ *H\UQ,T_ m1Zo$SJ )Udsw:6[g( jomeYeMkDd*])x6Ԟʂ4Dicb(쀝z":ix6 Jlhʘ!@Ht~%{QNAH8GW*BVt#,a\ 5oz\k#Rl6l|B g`o{<^ ϰ>G<)e\8%{ܹnck9V0BsͩNi H*T:mǃTBlmWZަ@XP)5k/-O{}zo WVkL[v58_w~0,/|5> K% tEpgTy~\7?=Uw 5uy܁/G7Z'^^PhZbFC״`S'O;+Dk7_gu ND]VtcsJ-≓59Ð Xq99H֎-4m|:X&D[AuW:0; F{ra+z0M5a{qcP0T_F4 g42.k (Wu _|`ҦjHğ',]JG\#եPqfۊ:y|M/[ՑJ=_&. l'y#:D S}cmkYy~sp%{4$ 63L4*T;w;}c_yn o^4ȢO6I "ro+2\4d$?|cG؛]"PV&-H P&BQ %Mձz"ǣwkCJ&_1yUܚ.f]6=y=N~ș{AU FȇPӡɪTC).e%,wz$Tr F ,2r ~FܭbҞjuX/@2M'9p`AO0kF^€:A6iVhy)L3Dn+Fs*`tq H%eu ˟|"ms(-4HM/Ȁ(8qLϹ}bmaT;;—7`ǕZDQAӡ.؊3?,'tP^Tl??%걄fCW.?5ą>!Zl~)=.ZD*lSB|pS qRvPxc0]k"Bh4:CZ\tNan?GC?q؝CJ墮1b3rN0f]ߏx?P({AߌWKذqx|gv`n#)>]{Fh;XE( ˮG2*Au.VWjb vdg@qVE-X34F^@&hK*a? m3(0𪮰֏բI!x6I G,(37AGi ؀r:*Ty-Ʈdm!U]< 醒qm lGoAhF>#{L2 p]#&'%Jnb~FTdSzfRٞG*Z`Te!z' &*'7 2ܚI3R&PemWilK δ wCtPDH4v4}NlgVb佬$h%@f -K rAvOOF;V}-&'*,'tHvխHxcyؐxVr =|4=9#VX8FJXUqxt;{ o`kAqSzp,ܛql9BRפucu WӄЀ3q)5BBoz]gXxQ0xxo[H5x~hW`BVG+`78BgÀ2v(F<Җ텾spa'q; K;+Cn1a͉~OynҼof;U Ы";Gc;]:P\WS~$ҜmN֝:{tv >\xly7~Uy0:OqfcO p~ʍ y s!jjCRĩCz"^)P ar-*}IAg)?M8|)tROe,&ܝrϜǢDqW yϠuda"`2k zu!c_YbJyA~(S#9DžFM[` 'r;&\)!AIl1{fviyIF'2>2 MyVJSnqW (G>^H^Blh5K&k2MBԝH#t[<9/ߵmeYuQfF$ Mu3]J_=]0#m}P'1*ҿAnQIxh7ʷ%>1EXRN[O̽+ ^ !?:9ɠ6JZE 0 qNlfa%'_y^,O=!{{,v~q0%3|)R_WjO|q مa9,N}.F;4a`Idi?Ƥ5uf%ƂD +bI$ 9cG?ZK至xS=S.cB0'Qcn"Y4HQ$AxC[h5~]8N_5!Zg\Y0qi%UEhL[tWff!в{'CS7ʣ}6\=H4?E8q@?5h"}TSUqo@QG>p{gSEj7G^+^~~߇eԢ^2 XP9?V(Yȩ22Ɩl증f$ +Aa*,3n==rRM[ĂEtUiac§@ل`,>AbW{%.[HJ~^C3x0,Ll"*X.4E  qaz ݌gs=x3n$SՓi7}lI54DT\E캘FCx7 vVp8rRR2z Vu3rTŘp gDuB "oO9δXۑ;HLԡDrg:8odj B/  1,:KT8/걶ΒPb!It넖jMi`>n~$mtXNCɈvV_WzۻmhAN-Jeu&͹J'1qMiXg:6qw74xK@yE`@qߩmtStK)mFp+P=zE}{?Ozx܌ZO{7 oGq#{_+2kf]VM^@/|Yꬆ%Ћ5Rɡ_]`Mo 'GBWPپv?1"] Qؽ_=Y¨^5"NE\hi2f-!^5랫"IN:*SBt JȂ4qskJrVV\gFJiɍ KdEwhMvdWG|\ Vprvo= [xK rVx`%{e\"Km O; сo78Կk? ?qm!-Kͪ+pm3}ì)X09u +SVR-os32Q<]iy4)䃃/wS3H8=K<_XeSaIF'V*nhih~5 ^g{ Boκ0١}}>)Lj9ԽwW; .!,W# W3,^((o6H,BCUX:μn͓'-A6'X(6Fg:BPSꏍh1q+ղ$[ b{3 Q o9+D.MQdx*S8y+Ys ثL&T*EkY]=+ɞ}#b>Y2w[Tjt/!U4|x1X8|yvCPCoag9!]G;'-66wkrm"X9M.cESɳJLG/ ^ #NyM=yYS}kfHնW֟+Y}$ַ^''5s_"g"%029pIYB8" }H*2Pі|-jSmNl*vMzo.z54zDngMi%?cKhV/Xr-83)>ئgrРޯz./+o:~ugcBx=TT|۝RX 7wOvВ8 5 q\[? v$@ްUk}(1aIeI1G$mXAՔP߸  } QX-?0cZx4* e 혖<ՋdoK\F1zpOLHԡdė:.lF\;6\)0_Qh,(e}}٩]z/= OvjQH[݃>D+$ q7Eb+$^PTXάʐJ p_je._&G:GKȉq"=8[Pay褄5 GTw]Crvm(w!2ciBaq_}Yi$*'ڡϑB,l y]= 1G^ HcQe*\#zJ'-&MwN*C']i2̛YҔ4yXޤ("[> Fq#):jHi ҂jTC巓a33[z.X|A9Zh-(SsmփU !B`pOE NFJjZTǭ;зjO`CDG0rq!_w WO5N{1ZdMێ;E`͑_\ddXő`Nד-5ea`.eqdϳWE2ߓlR*u8CN-Bॅ(2Ty'x!,{h#B|ѻۺ<&iAhbٵ;-7!3pvrpnn{DW6O((^|$qI0zO94+cjoMwb ILb\9!n ,;( *=i"_ oVGF$&!He|B=AN}2kf?>;2bPcBla\0z4DIcw{f`1^}x9dZTi;| mN?27eEZm1x I(: nVȼF(K7!(!t':BZ0K*ݕ27WؤRG:醲';E#{"ùG ,nJ-/ =!@˟D*$dR!ސ~˩}nςmOr'9ʆ -wSQ7g2oG,Że)?*xrΑ;H+]**߮VYv֟tf^ؘg-\Ǧ]YHꖇm#7ʡ>"4 '3'XñF+>y3UVp(8Ѱh`%tgs2`r9Y5!u9j7GEgavppSDOPԎ)VhKb *O&cz((>HGB]HȄ>v c 8ky8tv;nA}qpC-̫k:1w0Bb`8}BkXE*u2wM,K Aӽgl<Րm%"vԕc8Ȝ![%\.Hռ}x${|nAR& -,x&w.vS߹xm2ԉ4ۋ;C_z+0ZF2#U|V9#y:\{eP<cI~̽aΙ*yך(6/4:C%%eaNkxP L6!7z3Wq\a>nYń/z횶v:A}ĝcnGt[3-wgil(mdڀ-ejklbm}7%L@%8m>ȞY-gIGog[?_{^9fyW/Knv}MϢ Mb3Ț]B>ZȂ=H:mpk٠`%] q[gpfcm@p^\.MEx:+Q^pt  an $2U$v#[U2LIJ;%+CHd`Gm|ZҴ/{WEK+>%)cZ":c@i8d(#>rQ蚮3&en?tĺL7q+قJE Sp&ʧ?_=aLe^1^QМ>CyWrEcGȥu:a 4dB{qy}P/4(Bɍޕ gTgF'8H!zD8,xuQ\i14@D,@ U;D+!A'T\ ʷp"pguNPu2$xOz].$/>K4%!yoH#rJ}cAmD1>M2gbQgemxD-vn Ӌ|$-!#p`7oC̆?*0ZֲƩo_tuBd8Mi]eFʙw5դM|d+<Q$PF{C7{i@Y$> GjF&[`c? L҂vy@랾9?-zn;O ޑ??JF;e[=cpk $tEn p)EES x h!lC% R؀_̸N`hep"Qp@2HpR-wɍY6X Y(3/<.ESҏz'a0 60 :|z]p5Ewj0zRDc5Ev8Dxɲ5VM[X ?)t1#:*;)~<4;QfLhM1Η˻Z) 1nW,(?BgC޵?jV\潪֣RguX%7pc}U@ڰ5'M򒻰l/>沴bz3D+= p-ڄ6ᩕ;)}my'ڂŮ]W.-eeEA8%74)~,TJ[[II!Hy?5@:{ aðx7J_pn`1;߆},,q[_Jo;/yrA!IґQN]עF,jC Ws'L`)kas7ZX2xA7䦵;Ij`0-^3fg(00G{wjsVe~^x-'UnA5[8 #O>T+uʳ\p ԓ&uܿDYŽΞrbL[i.(*6D~u ~)O SG^wQ@&y#@WGn=ܔo2kNQ4)s+8$$M+S*R%!|g'hB32֪ܻy2񂪐C6equ`=kߑEKKTH \d$xkwN.-_c\xE;ַRCݻ$Q 9'lO@[ƊlP;u @XT%\_G|iD1)~s0ci4Y< ԱmeL)E3q\AyMC0 LF7tCZKWrb/oڽ e덆U!m;ܗ(g#s3s^WޖM%w|14>&d>4؊\> J؝xG0,{r^P 9O1Qpꪲ5s&E-՜gm-|N.ֽPQq*r٫ngEX=SՓ@!7Ψ+n NR?dʘ}J嵢,g?V]Z8] p(c =Y7 ?osDWd,Zt;ˎWdXcNxgE䪺V Q!4VX&n*=Qw5Wz"\Tj6fK9q:AE၂>W18bWR<3,N Z~gfoa2ڭg1P7m, %9Z6 Vk_aYvP.ѼU -00zM2~IJn QBc)f{SHS̅_ g^@k99]f N2 F/eaCD ""/ӭF f@_}/;_],XNbxf\z&҆̌fS|϶06*b{:W`*ɂ׎e0Lݶ%rɚD/,~(̹+C_"Z>U✅|EihZEMhQx]a-MM%CU &3x}tKI] ̭Z 5lQ3wGuZsA@܋&ˠ(\9ojAqtVIHfn/,Fܼ)= mc@?;ѩE9JDXdVv[ R'O2%f%% JpP:BQ.h%C.3,lhg$%J\*X `}L{Mn±bdnϛIWyh| 43Ep\,A ( X8̢DӓZLO^c`-owNU^{; Ţ嫻s5BGH ă]#`'1,؇摙5)21`'YZjս8S5!bgbkƫݴB~|VS[[[R2*!cNL}I)(eWI%/#Cg_=e*'jw03~ 0nA14gDmu%7? i'x\cX/>}缅 f*YTYp,}e,hpWyR"Y'⿗ 17(OeɩO-ܜ'sxz(vw**Af%Rk$ÙƗ'htY'dRV8R5;|a&vz =`$݅F1EqKw$vQ+Nĥs4jSA 9>y 0X. i;Sj~x2PF]sׇMYtHljiL,'#p=֞J7fݸbx_\ǻl̕-%ɞVK +t*D³_ēY !((aL03`bt{'&gۅ{r0(HCf8^r̯=W e2pU!?|4J!g.0#~%8xՔj~n-KA^fX 0jѹM73>M5ۭu7@U\);9#^1Z]ūmr ')XPOw/3colqdrrt8{[z3 o\M g~!XRO<~QODi2TjW kanC 4Av8#EIc5lŖ)p*: ogmAtg&%ovmJ fԮ\m2-3#] PN.?'Y2J'_M]KC^st6}~az(M)h7, -# [^%bh`X]R鱞.lЁE\S&I6zbzē|SSh%x [%ewfCLńMc]VaScł~9s܄7j.Ӂ^[asTv?xq݊w#?#BxbD"]ci.7=[JVq8Ka)U:\[mgnVH`I 0 43Z T`5sS{ҿiwWiho_nlTK$u[\m{|zMh܌uEHD/`,B0LILyi,p$f4pS9j~4'p+m(s!Ͱ1jp.%S -&ПmLJ{$laE>iF\ Pz8 DSjg&Rȝ2 '[0-/WGU`LU?K̹ߐ:rmG3É 'k&VDa"(W _MT]lbZw^,w5d xkPoKR !yFx7Ɋ)#aGHD,ܡ[$V!ZA 3eVrhИڮ{\ajY>fb.ª*f[`; !Xlٌk!z,M?яrKRsc`hͿC7%s:Z1<֬k4Y\IB<Gl))(X]=,QWEB. mt"XB!o•*9fƐ05ŭsWpӛ)+l%,7oqo%5˪Dq T@n-0B"㹧*YJaJRM+ El{˥U 1ݴIP*}*ѴEQ箫K'V`=]ݘt%|@sTPp篍9eC$M29aXb-)zffFy.8Dym{?u2]M:lF y@^NnyׂZfh|CU{ѐcFnTp r*bNd?txKJKȪcu1SkiM2?\̐AJYRkE`OL61뻄BQbxZ>&s0Zt.;k-cPhd*Ai']հ!$}Bnwq-@O[0 6qXWHbQƮNb[ 2 ǿ߽ڨ>C,MIDқRǣuHč> eB9FÛ!ӥQbnD+6T;#9>^)KDIa.V"=!a@"Ϋ+Jj.3`^ GI4nrwx:ބE^.jRX05 CCV(_6ۍ'o3mÎ_*4vIuiS|-GdA%?SՉǏT/IqeeuVI8YiH"tDD!?Ǟp1 NDɛ{v#4>o%kaz;*q]󏪊rɻh2,ۺWPG 2x4mqygfuN* Ar%uJډ)MMV}`oLv9Zn>PQ N:.56ЖxPcU@^(]{^Y6BG?x5_-<^U(sW`3[KZ[py >ǯǗz# {@w3 w =buҘ?se-9:镥ed؞mG4OZ#c)*ʄod-~P#"sHD51{2XC$]YnbxpBYoR8~g"ҿȖS⻩xy8 *+dyFT$ײ'@w絒6{2fOb:C%(f.b'{bzi?d:i?:"%<ŠS:2NOolu)1bn^k$ڌ :nG1620U/ՇE"F{FVS6=l+4۩eQ,_a'mD p$7Ag̹n&ot@/g]E\ -pd%Q`00`vbDMg;x)ACJFDR%(9~F>1=v-fvyo!^sN aND*iNV Ku:i( L PO֙T@Y%:zE<9dIf౾ogMa&BcơZ(KءiA&^ԑI=jQ߹Aԑ̅hvJL} WaaD㽸7MG>,v. a*? Fn˜OJwh$N}\ϧ:Rl΅+Of|Mгv:NJ n3l ܡ/ DI ƋR]T &yDX /maR~@1A<moXZzyMbӨ T*8 ( (P2Jp+ne9UDQXTZ͟8s:B#?v\}9_rG 0. ì*7rES593 '!`)';],XOA]##n]x%3{8!D͐XJ<*֍z s" iWYZS< RnM.%521[Be\Uhޜhͪ u|)am.CKn).KZI wL1KX/EOIeX*) ;1]Kaם$y8ɔѪl@Rg>/A LGSK,mVfRye]`/~YN\ ;}e-fvzn(ARX oǙ%wd| 2=)д":zyJ#=*}30ǭSBv?@Grgj5z #Xl='Gλ`Su&BG%P ^VKi|+* Q?On4똷>3A٦5u{C`h۵ʀ,&ov>coOip)9I9iL֙US>:() ߙ)&Zk a>-|)f8w ruxOpf1:{~}Mk8I\G@/LY6C VlǸ ,! b#\fjO(~ueDXb}qv8ePF\ ~jv+ 1@WҕKr& 㳨(\1BLň !){&b/,f83wa/$b,{ϫ<^k91I`qմe9R)Gs nW|8y^P9-=Hl3 d]I?w25M }(yKmc)ةiaFqn]go:m#S7B(% D"l{̶◳o}+G*D i x)?hӜN]wե,Gmx({ױs_lڱ;c|: TB)B&MNx{ p t?YJNl#nRSJ09#Eg3 jQb34Sy%+H7t&( S SX7L[4ѲD*%fh̔n&L͔BIQN}xG@bwߚ:)#t}Yoh2A[?sNM?9^)I OgՂ:S墴>of$՞ V.;6[=Xs);ҨJ=vϧ)DlK J@=S~Mι & WޮO͎8[qKR9t\Zxyb.ü䓋즍2s 1c1XID z$0 9">),Hlsh|_lep7u*$ȝd&9f| ȓ^IFl񇱁n\OlUSufӗp6Sw2 sSf 7mPlkraO Fde$6x|Qj[<*7ek&b[vcF2}dpQnmCQ]AL ߼?&Ah4ؿW^ZMۥ/"=KsW!-LTdr{+HeH-㌊ W|f̢^F ܪ5bD++ʃGn:X2 {VA&ICq5͊N-ke{!g4=N~B /.szYGɝ_ӽ$~u5r!-5s5氦_s±AgiwY`{(\|!Fy7@v '`'6OB!zG(859~{ #sd`* al8 ]D^ym0&ub\Y!E 1\ dPC-0ׅ:1Żph ]|4l':]͋.I}xjTk:ہ3{U.uxoV*9^ ܡv^KK,_o: kk >_(h?ȫ ޾x3nWw@$ J8Ee^&N^=D~3QޔVDj}b'-m7q֩)Ġ+֥cbr9%eP `@##,;_}2YVc$1o9K;-^ݶۉpLRJz %Is;/G3I7^_ӍLr17(Jw7LOڷE:^R(QQ̍mMP׊@nRAf vyJ'>(ǹh{x~(L!*7ʃp̬@* *Bl"1|Ѫc!aW+ t$#I"nN@J;[EYM e|r+tFsؿHg1PH ?Ȼ?l&P{)45|w"V5_XKlp8Zfq!J*FsYBC<46yG\ke.\]<2~xoiS>A"Pk Dj󍲂 ;ذv Vǹdd|b Z%Z?[C$=q e~1k͸h-j-̺͋9$Cg2|?Mw8譖3ڴe4$ `25ۊ,l/yn4@ lr2f|YAnZX̖R^%{lQ>jYi&n3ᲈ3atJ@F Ao+ue) 5&x(6uXF9k;LCf1)'&nk<69,bŭ}VY>ThxƶŵOU/8F [vg7Dʱ$SGd0KQ }`0B.mÎMQxS`HZ9qTwF :'PQRrQOb`ps%[7ftnE,s/`-v2'dH@#8:K0|J~\*J6^$/D?\.;胭*선$tm(ko>0r6!_+wV;mbqM L[r1(9h)]m 3SF|&wE&0=JB>vCC4/umv ?O9ǖ}\l>a%lx,'шRз"`GZL}1El/hF3 /g4J=dӂUSGZhTtsn.bjbizTb<ߊZE92ӥKQ^bTnROwȀ0}f$܎\2ܡl iCSkx: #Op@`?)%>:z^m1װTBȥzO܉\ci1`$N0j<5wwQawqž69_wS0?̾]28gT̲JQ욧 1m<XgUKk:pSh}UT$'Ru+5) ܭv )|U"2o?+&WIjɿE-fxH ߋ]}ދbnVvP˜u0"/km{_|.@wRqQOף܉OyGf Nit!|lb@}qi5 Ifێ ƿ\5Yο 7%/VC?tߔ謍aတT]n=<.0 [^ɷ.a`/JF9{W@Ƣ-7#h<]ڃ(M·#EV8 (TŪ[qj#Qؘ/uglY At(_ O͈_V,`A z5}(1yNxOi$]4{#n\Cx5w9iM[Ĭb{Dwo3% ;7.UCӸq Egк\5@iQױR>'%F)jϺ X^`9ZAp=*=5 xYR+wQY;/#N -=U#9?_>Q*hz{Xd#J*to*볧nz( 6lQO33DL;U2萐s_SbM iza rW! qMnrȺΔu>~X䫞~B?z<'A\Qb׼h_;+\Vֽ_{M?Vo>.3;Ssʟlz3́G-)}?j ٓ;|[J/y+f>SJNs7&R fiO][ui;`O\._^LL-Mas2z grFlV%OJ^mߐ fpXT|MxV넙b;q]lEz}) 9V=>s+ko;g`ԗʬ[݈Db5\^T>^wFBY$qi*/ [RӞ<$93kIJXb="qDbZ UP^OȦcv aڜ{#OsٮK .}!F6>qY NvIYsk?Y 3{`1=zNo :8pSSZZ*<jk62/|j酨,T- ĺA91FwqR2 E%%~#VėU"70 @}\(3O| } COMͻP`a7v!Wm׆6΀3)b>ur5GUK_?7\F7j#V/jXp S1=`wyB6)T%oWIyV~ݠS &oZ[ɨavm(89# R~v+ClҧY4ɏYUހR`8=> WYiN<!OG?~/$ʖۦ/\#x+'ED;Wr^C ·Ae3<CcgT"8{l{j$MeiFa 3 } xo͐eu ;irgjuPj9?<)ttՆwiŞ'uM頻19{@[E36@0WZ)łIژ BڡA}.N8٫$G#AnVd4Ĵh,V#rl;čA\P䛨 [#ՙlPdEw%j3`0nMМ;q|#? WaaJ O8B ?oOXK43qJqdu@G2!LyTbJ@ :@MINgG1%mQ8GHUyjWh6-ډO~Xd`S֗s0jTGbS xbkmt~$Ey]ܲd|y^jxAQ НRvKhp$t -'UZ5=wڇ_R YDq?zCV^J<R@ii'P~1I͘FtHg~F@/O7`c|KvV sm=E |e1<.n@!Q!F,H䯅?0[m|fnc%"4n8DTkILcYiҥ}G^+S}Vs~VΑhZʹ[n%llӨ{c(Z9鑵 '%H[L'KCwW|- 76_=VG\L1T#~,-q3R.nWU,A蟱e(x"..w0tkQU)fh7\1]^',ZY.=ː9d5.w z(?qj"`NKJF{~+V/OYe=:T) cMUSSEe!iBc⏺f@Lu]!1&ePȡ?҂1* "Na^EC#wGnr5(-8] '%EL D(J0C:-TѴT[)D(^>ynaFrĤ Yj9p%WM!4Ȥ|R:24M$bZ61_A8߱DWpv %!1-hr8\;xe{˲"-鿥=Қ; [MMōZG8ԅy]hm8?ֈN)XmyRfۮ_M%Bh)i=->%lm 7wK[=J ʼnwҰ&Y<ǽcOJ4pE|j,5Yo|ň 6/@Š䋑J0Jc J(K=z*'9,E2*V1(o;Rbn/6V(d^iQ 2Zҹ9+d 3^ /jVolQT4 Ls\#_LäxM{t< CT.o͙x.+#E1#\ 47_dTV i`~[7„|0v6o*-%5I(Lo_;6)mmK,N^Tb0z/TGGr|5ӂsO3)!@ܯJN:wIz[2?WTFAH ׂ%PX3lH+l7)9Zp |;] ζ\;nUԒrY5r,~Eܱ?t^oQV,ƭ!bQBCeZ0s/,6IlyFB+eߵM[$jPGpyE S<IW٦ťR]ug_-]RHn %P"L _tIz%?< 䃨^vl{R'&cf  \1nQ.&GrmtRހX'ܴ*VQ&|~Ƚ&zn%m3mنent?#Z\U'K3x[AӄPd5R(n?k2k2´RSOp;ln@Q!E}[8F5ia0,/XnIr ?1`Fio?7Q";5tUCTÝe>rrEb'SdC(U©p _(%X*:sw!XsbY5tq|b.;&]|IS~2 !VBSpm7엾}᳃smƽPmt6l,h,B<ǝ!MM*i)a᷊)s8 0f-Ю9L%-` dE]9y4pgvϲAuO 5)%pbcJu8vuj?23q}PUaQ<řz?ֿ6XQMB6'z55ft%vmC sk\%^LzZf1)"-}=%nV )uB"hQ3fVaptZ;>WTPrU@N)f--xaN:uϾxgsG yU+JC,(H[)d eY PcY|.̃sc`̆w:ufƍԅ]SY!ꕞȭ32O=*KIy<%rm ipiOq zz %@*dעQnȺ, d"-IËTw2,B5v>5@-4$jn.1HlY .Pλ>^GSt6J#=jm[c>4ƺeJ}>`1 dh'sڲDUE4~I{Fվy *&D )<E m2Ԭhԛ~0tge_'AaKnP?G^ԣ_+3(YΤ6N@IcCWR-󒘂@z)s[بFGRS?sL +&oSB=}=p~f]33ʼ̸s&5EeyHH}~]uJaaܪ#B2SE]^ˡLm] u <4W:{"V9+e!`Bޗg|^ %]J CԹO%eR(tGk5<oU3G4bF*uT_00K*TN Aᨰ N bCS$j6 &UQП >& 9M~VŦ?蛀^!#Ww#{6t4| g | :nr xay} <^kBl+>Vlˠ]E"H !)<Uvoۣ(kD~n#sI 谢} =z%F .4Sߧe*-t\ ARxwa[IwmE",TJ6PenؾbZrf)[5m|јbh!ܠ鰗X€dZju2>9o ɚ1.Xo_`,;m/kBB<߬n&+27:]sx<r ,6& έ)G/پa#N2-_u[_026EIfV*T%n|BkzH-CTY)eޣKNJ#g%?2];jW.UI$tMtsbV)5u]L5"#BC'C{Q\&|a5#RrjtK@SH-=ONL)Z`N:ѿl`so[.Z?EM@6øD x0ޅ)Џ L;|O9@C* fHʟId;^];w#̓߄3~ž Zs[F*ӤpiӠL({P`E RC#TpD}AGү5&5⏯Rw`ux AO0h O(_tG9*Aڛâ&S\K3D$X]oJXZD,Тn@CWkG<43穗U~uZ\ܗlY7m'f7ٰ ¸nR0J$Pu :zK=&%Xg{G 2}=cl & aq.h$ 8VZ/HMPO 1bD>rQR+#'EPKY5|soav_$Ce+Z3oN&-@f\َFeIV؏$ZG?r5DEGchN@GJtv/HPf@SKeٗ{LUy?L UPݯsIDr0G&sSEzuH :! Zp-H3NRˏ:<.=3_("d68ERFi.֬ג~8t,?Ԓ'qGhfo@΅iL{\)m4#Xto?B\rY-ms9g21(.3YhGҥѿV( [D?tZ٪S&ji7z/9oi0cBGRP 4x=Y79=SjײVȒ,0Ewc솭1<«]_:,`oJְZm&1e#[=FxI; n![sSxMݙ:!IrlC $6qq[ v?>rndm1iqy/2^Hr7O^Q֛xafZ?Bh@!gwy#8Yu;O*hS~WXס5v3M?b;7F}vF@("V d7Gzx0λ ƝV~h~D#|]`@2y1p3~ '{Bmi/ȬSoO~_vd#y ,A{`绁0XK JlZϒQ GVBQ^94\`[+FvnyeIB^Ѕ@{4 7yU˻gR}ݼI QS!ytKLӤT:q;ZK_ddwоW#&8iuwZ 5WڀUBI۸T%gMꓦ}24@umx؍pvXazfO}B+?&$tdQЯ k>Y݀[dO$PIKrӸg*#71_J1kCrompMU4gM2"g}y#6[C:(Y~Hj h+s&j$:[=9GM{C{@^OoZ,Ż-?xa]NAX>ikM/no-S〙howO9輈/B!e%VQ=E ^Yg*\`=Z¤90MyevL8G,Sdea7Kq̇geHE5 FE;^fHn8juz$^ULPɓэU|lyWϺ?9*ְ~{k4Z< ]n DWn&kU_uCkf m\GzTjX89kw+7}呎iNL2&e 1']L[W p`v .h,aQ}AѠImCn(ne̴Z Oջf4 ?Y2]b-",PCU8J~OܝlEļbݪt4h }>Hb;R|g@/,'2-- +c#͢ Q؅MUcإ+]%}`56],~~Uxhs'OnPw/6ӭ!bdrsc7~Hj`jsDڋNH{V@=TCp0蠸Q"tUXsSKhj3[q]1]iS%FphiZ/@%iC|YYމϡ9 G1POz\'=gK3L?c 4+c[9;` be Tr90 KNc9ؿXѦgX]Jaʶq:~ٶ&| hyUAtgSUVr \ ;NrKSBbW#- QtawHm-SS/B 8I f!4WT6+DS EqMg_9- h@oF9 p|/;v,K4Ik'Ґ]I&9=$[Wa&2R"7_wˊPt8=IQawH[II9WK-;㋥@sx+`v,8*)M,L8 G9$!#T K s!]0Ŋ>-pn[/oz":Gy_@LvS&iǕ%=fc]Od[6 X09,"f%դXtH@'0rB2@O^jt`J?:{\(CMXNT2hw:gێY?1aG"}2Q\س|aH*d?B }JxQޗױJ)ޤq#ғoxVYJX0:prWwg&?ozPֆQ`?uCnOf'D]jcڍ_( eQ 7PL ܜ:c\qQr.4(roG ]<=ȼ•" Rp  Ф&WeD\JXB3Fο7 W@>vl՘rP>L#>{kw0NB0Xqoݎ)qEHntׁX’H هbkjuPӄ#L# ׅg@,"-MW}|$bo}Η}lH'fʧ*<+y"BgͫКb? k`cثB䯭nA`ً{r%.ya%T(4@Ρv. oB > R,QQ2NFxX¾i !d- `y0K| %oRu,VQE.Rt%k$–|IIW88˩ybb:; ةP~vG˃gDIciyoDŘf%|Q/ST.Vlxb}T S%bx3$p=G8/&*AH#;Ô$UԄ.HVKMf: fݣ nmt/*$bһZ.`/ş]#ҡW/ `Qܣb nP{ichXQ'W}T!:Kpbŏ;4lw^%/jO[ hNXmm=6rfS"B sc_EvQwXp`ȴoTe^2|5shuQ֜ iA%aiUJ*|rrﱆe(8eêEBXM M'OL#!K6fYnMW^wcB}'&I `0)HV "d|X/Jm[ޅ 3\U2ؠ$z_ ;p+MrrpbN꨺0:Bz#jso ":_߰|_T.-k< Y:A_L}9.Sa#+Uc ^MiЂΖ)ٌ3TҔdQ~ƛk“lD9di ƚImJT?vx)Ylb]U˝f3).E kг@1 Җ)ުpr'BI+ r [ (A Yf0r3g.`N zknKuӠ|Gi,XYpOp*i%A,LB>0d8/d~WY撝 a:Ia5 $r(] yt3H4|lN:N5`ܼ*:RH1H˔%^Ca﫦͑Cb!Z" Ik,KÁ"_\ܙc.= ~,p̯D3idM{M2B-xV~un NZޤ?{/<&V:*.9 c߽N-P)ecVK`{+hz++2w XXU'?c)s#m?tD?qW:۽#ϭwMޅ:YXN=U%K$$ы3яET# \)p{)]Hƨ7JCNx,5E=WTuctk##kS7T^Jp㹡qk .ban{2P?`~}[E)/&CaCcxV:#[hYۘ!lipCÜP4apUȀ! fpʐ ;} ؋0@jꆄѐ&=tK:~ȿP)SWpҕIG> {ܻr䢝kX,DtR<Id< ֜^3o_ YRaJޘAk"DrjТ@^`Q *~֏x@"Av"aPelN  ]ߟecoa"j%:ϳMN2Q^QVlkqm۴+wsfSbnN n9[\vqYDx`sn.jTվ2$j]vDh_Ш@:%X/M\.1G gJPv+HV Pz'X. L#Y*p+41UZLYܖzҴ]EX(ᾝĞ@-k'☍D4.7eۑp"Q)O3pڥ޶Q~UVMJ?yv 6VfZ+iQ 5q{A2Hq_gӛi8[+w%oV Ӹ32 +koPKܜvTYf㞾n;Am?;#~wZ|Wh:*]0'(9,<&Ԩb.2wiڱ~NZQ(y RPͲ !d8y vʷ>Qswȳ)ojGxwBxҾ [qf<b9\# xnz}`[xE|gn?A's X~py=AMW~ 豔Y; g4aD;ؚd)hm^gZY|v~h:lVw$9 jܧB w 5]! *\#kh1U]ƁWWv`ǩ>Fi"Z ѳ:Ȱa{ErY'?$dpYpߊayAz;+JĄ\@\i)ާ[<K`HFXSKPTIг#h9.ΧS> Q&uyk%}\ju9z. v9-gޫ|A'ؐ@(LGlyWqvQaKi: $2 4V@5yc{2˺/`C{oNcz=b}&g鑊1Pbqs<6^Rx sE b hpq\yM.o#%/+ia#|%D:]{/2VR͸jjONb>`OZ"Z$'+0$%"t^p^TwIɤ1 pPw$̜,a 뢈9;v—; X}Vv_6557WY&nGg{p,?+(HvUeޘLY-8[jCEqp<?׃w#:e iPf7ׁ}Ye!G{f ilkAcsyi_>`s(/F{F>[0eXs}df;o˼`$3d&#G yD,9$}d /3`ac&c;UX9VxZIO, $kh4 φEeI,cF6 U "@tb>p1+1O)SCMZd?@&ÐVxHoZwxR`5[_Sjb Oj6 Jw'Os(q" +iؽADLҦ(!,aD{"4N ziYFl\sm@a@l-b9r{A P!![a=ZfWuGd I[LmS-6sTFH ^@ktcn>{8YxX8ff]uoSI֘EWbo +\/sA?gAyݧz!vrR6 jK^kԗ{"F6$d 1 ݤwy5\#aO jdeS8inCE'=r/~ cʦGWdƸw.*v3'g7.G92_ܗBCcl/pf鍁{˿IoajH#}L6O9khS3:J. jmϕw&f?RLg ( 69Ɗ>׌O iP9D8uº҅S$BѷI9 2/̛ ;+)"$)'R[m:\E&j7701g ,O.`y?CWM}ycVH1*.&}ѧ6l~3!%St%Ůi;g0+7SLyoX@v W0Gk]DH9^F*=29j•)#SCY>qD?4R4hmX~vx{ƶ\ .(QMF_2jee ^ys oO"J mأAtP!buyਡp J)7yVA8@YKCQɽx)Qp8\8 W nqX-k͝ x@rH*LwsE:ZU81fE)UnUG/\M}{@>OAnQbKԗ:e 3do+*Cc@m?QI9F q8>c0=C }Q5L'pb.;im&A=vHiAEV^$ߠء~܅ |O) '9h#Lq=8)} z ~>)")E U>DWm2'*R6Ke˜tRp.!C9Y-PFn!Ymy!ٹ|i! i~Qo=E#* ~IaCi?몞zop 7 ߹ʂ!dd0>NKaU궫 S*kDjKeqἃ1HƤgpw{\9n+*~7NZH>fƽXQWWWD2QdUy5KӂUFl{n%li@AHB#W̗$Z Sql£!v\L/ .;WAs:l5y F5\5[5V@V-_-wF|i\Z@;"oqo ~>G]5,g{Q.TpӸZ *yvǕtUZ FP?hɨJ/;ߚnlNPکT=qbG8dEҴU?Xdz ]UIN{\yz վP)'@>w;2÷o~`9+-!ȟM/MND;܎ dD[l,%5r0 |G_Z ]hG ǁ۬G%@7bRԩVlϓnc/'-eui>6CYdxhͫl#Nh_A [扻HE>1 Df3ZQ=f`=# .w&8"oK{oCDm)0QM~@kve{#U`nu zli> 4ю1^TQx&چCʴ/Ag숇YKrM=RLyWީ)1Y^HЃu[}(98js~ y+! rJtDОJ'{a:YF$ٰ@cS7A U| 3p#DZ&`XgMg⠍XocLыQsMwwE4jMKCz~ c[x[V8;"UUqK-p7,{8'4 P+6aLDx%Y0G.|9D{Æ^`D MTRp8̱qf ;|;SMD SG?M3p|rX >VI7"?x(Dj0ƺ c1zI=W-uѭ(Sn R`^&H |K.|{'Bxo8ۭO V(z5{cxǨ ZIc:Jd+5ϳw/]Us9]ڹ2 -P1DxNOJ3[ .9OucNZfK$i&oP<\S\dDϕx4fvûS%‚R:v/<-Ka޷;*>C6ܸ/_5*~ ?:'͍K0.Gh1bQul #xmK;:&8P9CEC/Rz5z2wf]^s[WL*Q><ܷwru#ճ>y2-Uk$qGyw)7 [6AUEuuƘp;дe0!` g UH3˖"lvRֆi nJvK}HO{W]k*QSemig,lޞ z~P #$i͈t *drگ+T-4PުiuS.ZǩlG^S2mh2Yoe^~~oMpt$ՑlvA3k4M\K~kJe[q~.3+ Ђ X#8h /w ujuGRUr?A1{#Z٣<9nkxR5& Պ&p,H*go_ `f h 359PU|M7 g ؖBKh^DшB*z)r}BR,嬠gbp_\hϷa:( #$"v{B5Tz$u.y%-oG+J&Rܩb1fZ WڬJ7'6f,+U#K:M@Xѵ@+?b(ʨvս}+#b8&jhJuXlpL1M K?G{}OeMʒ9 ޽]ӈԾ$Y+\`q|܎TLM,kw粩I49Lz lvop[$¬MDgܽ`wwƅд˺H+ML6f:T!^M\Xa0~b~Q!Ziz5QiCԼ?69SSDB=m*mCщ>!K'JFhVOB/>/Ջ]l M(VYFHݟ"aA$Kyu4"B[?Ԁ[# DŁyq}&m P.䨥0H2`%'l7+4Y(gm >F̍O5:wkͽU"bXGm[B#k# ]9 RX^5IX,7qr?56;!+Q԰p'^ZmmeE/(viaR Gu@Ea[RyPц{Y4OM3b8ھ_>ٖ#oԮ퀴t- `'Bn&@ݚgZıCԀh  f!{YhNilv,Y׹]=>t gDXS\ p8QCGf11Fw?b\@'DŪ2?cC<6}Mw -zr-MЫҾ t56;>t%SeQk5ޥP9{U^ݑo7F/wCծ7Zh-.%+^&I2>]8Z}돥w42 l#Q1OriXoA(D4%qqWF(7J 2'm {7,wofSN&LDK~* ,s\B}QGӥn$=<!o6lѬypyQ.4slJݪ<#@ObrK+[zӫ7W9KK'ph&J#IGC).c6(嚎zJe)38yg#V,Pu UTt l"2g>S[qO@R}|5K.s{ LNߙDkD:s>@7~/~S7uHMJX5YHL?新+gag@p2Nrs%=O*}H%,tYPI4}#$#-t(^|1-\;&OKn1"f"o ̮1 XI'/kDZD3,P Ų,}JHWv_%&Pub٤dʬbyPV[*+xN Jj!ivFZ(F oк{L&8мܥ/ 0$&9cn\mXOsRPe=cX "xƬL/&؟bh~>e+BO#0J!ґ2ٱV|ʡ?ŢR"~BE-޳qi`BQ՚U B-s T(2j|YRN~ĆR4mVdUSuzDE]Z& ~7NfGYEͨp2΁5SN|0XYt.%>ځM?ۍ*Zn r,eaJg]wSmj~,@aC\Q1ņwm %EՔ?Wy`Qcb12Ļ}!ʙlb QOtmCRwkȅ 4ʶ_Pq;Z3͚ŋ{e&yg^ܺpՃ]h'x+X^s)L1Z3TΟYCj t< DH`fɑK Do%7Cs./="u6xt7 -$W6h6BSsHH-v÷>ܝ3_doSx%Mgr L=o܋iƻ>2CP/7F&j]׸̾Y"> ѤLQV%jm1>ZNR: ӑ:*iݡ)/9G`˥ks'Bp~(Y $6xUX+!B6iU!b8D{I2зz5+[֋D_M5.g_'t-@+m%k=,Hf8H{ڳevZ]BSz68 5 sd<>)Lw@\R2N EJK6.ԥ(W:Z富v$s(~ EtJm=G:4LY I'(,RD>sc)'I8[j|l-&4-'ͬ}]RKɓY΍uhZ'K^9hXJIiB78EUk)U_mGt ]ST׭u]QXm2U]Jq:y~oRׇl*$<;L$`%.V3msr}hmENPA8ɳ IiP ; m.&;Ş%x{zl -N)De1y6̷ۼRr _ILq).\cl%XʂWL -t :Bo›7Խ3ݎ`,ҼȞ}ۤǶ]+5s3_0=?f|[ߝ8 Kg 5>jMˇaОxzAPS" =$ W No:GvDHN)]]$rk$DM= [D!r=k_D +cV06!vtR Ɣ(F]ub|s^AdH"?DQFp'K҆6 }=0"A.IX貦 }7k'l6s|guⰤ' ά$s~'?tz`V;ē '}W# +r^WϸψXw'<"d<+Y?""'sޘ\->*•gg%uYj.7д͊Sh( 7>FE[Lh`c'ȗ=jn0ݳ~ AN|NahD٥ IuY16}Ip,@Z6wB-剽%Q'@FZB 7i!j^zeԈ:l+2KnVn|kأMFzD= k'r9Slجׁak}U0CCVP)Z {Wba͍ BN1SQ`1gzɉIS{{$^UA ?TÖFԥ#`MX!8dNG ,90ۖ9I.dG1y "!= !@6eA# q֚~^-bN a8e?T| 4 72k^fz_: r{7qJ_Ŵ3ZF] H\3`^SN (SEs&Qw@M:\9^]9 ˁE5 ?#"flHJymf0D#mpʹ'o&Z7m|=@rN8q} Z 0gTZ&W " @ڎ |XY_2Lůi97w HIޙC4=|pê!j;nöoU,l?) 3F?ߍi3I o+Sẃ TwC=ÂwGKg'{Qjk67 =̍FO60gqm@tܩ۱v~xKOw0 2浺Au©jR$'m9)+5]!U7R n8n0n Mq!{yA`#Kc">T%+Mq<8nY9#}ն"iGoY"dyT409/wݮ;_$MDŊUPjM1Z~Osu@2LԀ3%e V׵ r|2r"!QATRR}b;g ̃\wpG)^*|6ʧ ף ϿmiSF`2L)cx@RM^= H7yǂ&f'2O% ЕBIou:tt:pӲM<{2'E+X@rK -e0nx3iYϜr3E&2̽}wS  >9!|yKdwm5jp9&eՓ?F 1r8 -aegM SN߫$ݗshBD$JRv܄ IO6OeEK7y(p֕:;i[3x?sv2b4A##9stq oM*}{&07-82BhCr^d_|k`~7q%oJCa0:)X i1n h(to[ҡuK4ՎMy}K  mN@mB=7FI!~ %mpqyrOVr1c?Z_'K!#+JzH}Qh[&Jp`##oMcHӡzNEl+17'e nSre :ϖ30Z2<-V{k Yo[ߡD٢E2f/g|)Ȗ\ZUytCFAm8J8jߍZ^RZڧi{.Drlde6 2y'b\NXnX.NB2+hKX\ e5?C`漛2d:P1ܻA6.u*igL6(gdZdm)YkB;l9- X_YT( ] sؒeF踸Y: 5 TnNzi>TOWk2q) +aHoD"FV2 c+ eCo {F(7ΩVvets̖wkVsk ,àtfXXô`e =\E931NYqՊ/Na7oiD[oZ|+%mc Ȩh.-cM ſV{q'ګ…I=tń6 L]i$DƸ[ IL*EqA aӻ(!ć%ʢlhoaA֗|W`m_{ud[\TM}aHwؒ1[o&b3#z>o>$H5 hIW)~qL܇aM$З34fw~"𩮙JR!3X99 /Ott?J+RqG I-|_XGџlEݞw|UWX} ;h7>&dx7|u~8P# IDaP+wЁ$ '-\tͲF"+2:X\ОzKL;Dag&Ч`3BLPV<}ڵX߸:3~Mq+Èy%nNQCZ&qi c[$zO:><(Bj1:yC-sP9 B=~7.C( 0ޥZ%yo6~q>({Ā.:uxj7 oI>Ա$=bpu.u]v~hqYph sf~#Ζֆֹ)zq/y\t.5 n7OeH)r֦w:L#n!Xٶe*DV\Â]~ N rx6[g0T7Bh$Aw\:WPrʼ7>dǔ|)F=%,g.t ek{ $G>]osλ$ї}fFC7'Z>QFNHJf>9"q ekP уbc8.Y;ڧ#% R&4 2aTl'%r4g\5!ٕozs>uIwʳ:5E"Z3i~^]ŘL>f ќNxQLy=,Ao01 "}m1|qю ݬ_ZP}I*Vf2T1xO4N@`@o9-"=G ;_,6! 2n"u |uXF7S^V,_ U4%Vj-uĽ$G֢ZQe.*/U&TU<ż T@qIfYf*h'X&zc 2h[d A܀0(:Y4XF#j 1 ѩFKr:PNw(̗T6# kM XM:ĝ"チoF,ٕ4C _LQy^x*_:jotĆ %Go6v dX *ɍF ;Vh8ΣBД!瑸=Il]x^$~K1 Pckǚ(?5CH<  -*7edL(EYk M3{' HdV.zr$sU{ ?J $zqSgQL @ӱEپ}wAKrPˁc{ScrAfէ =OWpG!)R˫'ueΔl}W *lnͪ=4f:02wTM+Z̓FT8}/#a-l+ ߂8oM8rЖ 3+$ fZ:1R3tկ Jfut>9v_ *P^W&Sj2Q2b"S|!Ƥ4c3%ɯXNzkN>*] -C'݉дcx> ǖ3cn>(|NkNiHnJ$NxF~.wuÿc.6swfbpk٢ yrDuݎp[Cԉƹgtʱ_)&-\`˹M9]z#=8|Gxzm$r| F Nŷ(hZ&$[Hr')o2#@DVS[=}P25(2!qn4)^XcYkDe`,އGHB8{hB] &3|dxgyCxs|swn|;Ý,9)5h!_HDXebr\Tqe)ќ˩ɟfJ>RĚܶDl\Ssd`:eU)/%fg.b$L/Crl I8GRiiO[I= syN$zY:IgYƯȷ5sKD/:W3P1X-3 X1&ky-3XW& O mG\QM,@`uB\Vda@BZ{3ZP [*\jF0|0ayXMaAh:MSz^2%4h+i-V{Pΐ'O9~ I9}l:V4(qq" c B$9 S`Vu4)9&p pB^KWख़T75V3MjjiFkgƨ1cTr }x(\&QCEK;P(W[15;~Ziq0[=H1ܔ]Ect\,_%{!*>-9q#Bg,ca}rw *?Rp>zf<Q5Y.;݀ y (^ce)}EaNͽB+阃iȒ+qMH хT2lO$  #fwIfqN,so z4%kOB ƭ 0񥒂˼~TSX&N6_J2ڡ;yvoo|/~4T\<  5vd$3LQw0̜hM>\'JWK청~ źc)[7Į[.?rj;HdYapw;gR{KS!^:kq8F;#̨y2,lqTͫ-kzZਖ਼:DOb2GXƏ=Kd(r51t)i@ksP.4ʮ` ҒhLո!EԠbsx~?oQ/SXX.6Ѐ,L֐pE\V<&QV1X{gbXbz~; "uCĀ%Ԑhĵ<3[z cPW+3gXKW:u,GDV*ތ˺ܨQ>-Jtb?_fvih6 Z[ǞȕHbqh1͑8yjlܘDKqe o.X[n4n"0FF9>.7gQr%UQ~EBy`"O蚯:DkdJ.+.[šu]|3kFkG"r7\))tDRR)Vѐ]AΩ™>bƫ7'ܶX"MoK#F%K J 6FN#|xWqbc.3F0P'<۳ cM,kkj2#_ qӚg!3 ؒf ͊~$72P2ۓ]'p?uƒib N.+cuf6ds ˂`62u\^?p@hr]];ai'`.Toyf#52pGy P.ϗ[/1mAv%/Ьo'-&W:!V$upءCNqQ'$?YoK}N H6YpvCЋa (y70%y>.*` 8-MM:#ڭɪ>»UHfקÌQ2H\4=ĝ/J!M9,&B%_@{QHX%&Z*;B1y[fsv:}r @ \Ƶ e{oG NV*^15:73pd+ l B2YdFW0s:WXVKsveaH > :hF44D]AEg# ~=^jPfygnfh6cD*:a CKLK{p/`=[|Ґ|yjR+Kc5 Q֥ #a>SHOX-,!V50O7:T3U-I>9֢XdrJ +d偷QbTcc 2v h^vW\D) mYṬ $! ;^HZ#bX`D @FI (H%QToB//-j pbQyʥE;Wl/{> ސ)=?dT0~8}[Qԥw׈qHgl96@ cSz*^L{-)(@~O[o(|4@}+2 Z?xL+Fn͸/6/B|Gl'!/e#F" &=de^Q&-I+T˄**"^Y#@ljGXa-}O>[_orwݢn$XV* wj5vZvwE|D`n85d>Ѷ"cZX=ch W F:Nvm~&%,eK(mRxDmk `3Ay2Li7q`tO&%T4Pp haAs/Y_ b-Z?uU^눢ted|3[ p̶~AլҵF^imPC|pil250xHt-G*PI]З*Az( AU$9Sf5l;WZRO#eSړVdR{~{L_e:/,-3oJf|LGI"ff,yBmbӺ&~RZ\ L}B3lq g&gkԎ`(A^JjgL\^F쇫 s&rd]Uz[.^|?'{b]I9Iߙ=_yg 2YT8jL a$J5LeU;J',kHn 4=sJpy =MRxeq V_,&pEۥv{̷S1 tQ5lQVT,;ׯgO-=A=3;G$.ewkݷڦ X ]lNa(;]/ ies|X':Žپ`yw@}M2FUϘk8k!U&[`Q<,bAU ^oŲ "/vKfﵪt2:Ke9&"/}@dsYyJ/aNU8ͼǃM  &H>]`opiIרn}~f$ `6kNEF+qfI; { .6dW1A$1E}#얡)Y81m5yqr#hCB"#r;+:^\`C_SU3pӒiB˱Hv|(E *O?QIMlX(+r m079Rv(?c:*2H`4uw(qG{'R%D Y m@ŏ ٻMOB( rAaBؐ v-KzDЕngo^Gqd*bmCsqш;?8=tdF'جbgRRBn,Mqɦ!*-DM5a*v0i`ء+~2p6oJd10t9Ya}ѓ2^Mmˆ55T壎W ذ\$)])B42 Gj|̭*b *`K-}վ [& ~IMB')f%^3ҤR'X ZQpZDf+nR9GѺR3o1ગ|\1UgN[3ȝ%kNJ^&Bxb6 ܞW[[!O7-ɣc`.u=7SqTds,΢8(n( t=w}BX7Jsa _aݲ #m @Q~ >Lk섏]Ûmd c+m]A]U7*["+ D3cp/VOMTw2owbS 5±qQ\쾬Zk7CdK(Rܿ9`(GR/R%o2J2MN ǴaL`-}9vk bL6ÜY3*7g3l?d@0M {cL7qwMH_4O _?%-QjŘr=""baMfT M{m_rtc5DPfwMbRDdU}t~U+Cכ$L| tti])dsYZ @f/dpu>lQxn,VY^A:J~2eble>;S3s7ϲ:R>bM3m4U.'JZ:F"1U$yK5/O}A} /;Ԃu3u7u?koB#8FS!!v^^-V@due6K6I·2~!_xNv<̈@9\@Q-7]ںY?>A <]lPl `A\pTWC ݯ׶9 jv9W'%װt1#+y4YZ^M^Z`)L|JtNݼ!L$+d2-U.S7=rD_vOs?sH_Q)X]Y6tBXGbxZOh$ ߱Fk?3]D5? u=Ƚ5̫>խrjdNVc#zHMOLSW0=wVB:c n7px7<&ZXWVmȆp9= A#~[ D5Jju̫oaC¹'YPk|yRalWR_QB;E A#w6'ѓʻ=qyu)kVmPnк1BgH5$ЂsSqdA|Ny˅J[NԿx\'ޱ`9 Tl-)c)[@2"Javi aLGd,|uPD7>toYUU)G1R ۽)I_˄WmǞ|*ЀN.͟oj{̄yԬ_|ZNeWJy ͨJѪEFt^8-pO %lYd9Du%rYRF-`Mtdck-au(&(V dżLݔfY4uifszfFĹc;֮m#gA!ӛϝ =/%,PQzu&d)&WT[H>X~FxI꧃*:'*K_6"z# z#eD'fqPKWGŰeh*EBYPaɥ=9үH% ?~NXUv!IbQsU6iNZTn\cSTJ?77 n !yraHAPxEɬm1Uv Hkb}v8F a\n3g͒48$Qڨi26L "B*iUz{QbO5$)%'-|& 様!O5L:\[yE<_.>V.UQPVu+0vwYnzC >EGon3gVG@yAnpEZPDN_E~UI?v?Jt qΒ %Skפ x5bډwYߓe(iyۛ kŤ]^'Xr'~?QlvwC>1'c&ͩbi|Dܩ^;Ngow -~ɮ>wr?`y j ຊhr_w,ff?y.I_ۢҭ}QK,Kx78O s폧Rϵi栉[If`G`Em 3\"$v#*ו,(OOzn'+HGՎ-Wh*.khvL%TIaeq1Á͝ר$.%0;` WUOeBxa @IuLVwq.:`F<$CLG~[-~{suoT46u!syVOVxe1:mh%km[8wdl#muĒz2b4utMT)ulI졥|OpI92geAoey >2Pȇ~DK0F_=!Y}Dx\ɤ[$Da\cAEz+&}љ@)`ݍ%GI>' Fo2cYH<*gljNS{}Uouzm,Z2uuQh؟w+5=֤V}9ruYs oWc?4ݐէfg;O ?70 Qd5 j 398k3?2b隅 /2JL[8\1:LP0Ib+=t!zSOǢ6xk3!^`˄Ez'~}\I>oWéWB|OxP-Idu>Il RXs_ ڍqpGrx)eoEQQ`nZu!4ł"ZP~=,G;DbUg(CL^.%y9l$0Nit+|IBiUYgq2Dֺz" Md<؋Ffz_znL$-CC h( WK2t(5YswY؋TxQ4 P"_ؾ J .ok"(o+ۋ0?XM V}rwqJpiB 僻XU}n[ &ʫ *JvԌ7-Y5Nr7\z-$PQB98wzZbP}> KnpB:L?.dt_p!Ų7;h/{o9.΃Jߪ?2 b*[W%{o'HKtn`b5&<] w^n51L39#qG$L>ú5wDZs!BQ:!4f\ /wwQ/h䶸7IFwF`A9DEp'$ո:ee0EbJg_߼9w`) dw[ᏲGb{ :7Iqq@L[WKF~eKs; gaRs ﯨ\P@CxX2A?so{;^k+ M%Eft_˿m7&∆+hI%/(PVh#l7&#^rKſQsQ|}6hL/?G:GVGwc'v5Ý|;okX p5Õ&2CiYWlҌ>A*肎q]!P4"2+V>D@a(6nw+kQeGIo:y foޟKb̊ᆥ69F1yl0V W`8Ѯ;\-v"DbqV Y@Ȕmc/L꫁ gX3,x0_w+ݸf ?8m&>(=3hfa%mOؠz hX`tMS6X&/&7x6Br)qXFMO%8UWoȑ^j=Y49ZF$HsM_ǑYJN}HI`%(~e q:v)@ Yο^efN.zu*Uu&;B[ĂZ@]dz`69Ey6"ޱ\b˺jxweO}IƸ~\OldOhoݘZs0Za^P;^E8+VKP>eDը{R~EmW1Zh:/g pIpD-r|I+!uLЃ4i_< 3,ӈw?zP&ۼk،ŎO{^Ts@sr҂LZgK0kjXEβ)NZ89KeڟK~͆, eɕGmd $QH8':_YV@"z0zr31׬$ECqRNdwͮt/בfw)( 4zZ`Dǣ̉!#ydf,eˮ#H7Lqڌ~[FEM%Z7SlmYK:USc2rPx:K^nP#/|2-ؐDȬ?Nl`0T?$PΆ?no߇u:` {;'W|%-ÿBݎֈgQEr9Hqҧ_|)WyZK e.+A0yp W%} E74S?gְ<-ݕWۂ#4۰u MCś I,zS6 hjanp{ e5D֖&}vA*K"~Wh `z=)iId)5VUOE#ǔ3\T[hmޟh5i6{J'Ʌe\H۠4wlx/dn83(o Z yO|U/zXaVi3&<|)"IY~=H|=u[Uv1lӘЃ"KMpRǷIKNS*bByԭ8<7I[][^ ^0#b"we$~^=bje5F[)ob|>ZmRbu ž[ͧ` Bȴ&k6"X׊{IW T\2&&ۧyNqA2S?lu8chܐ"=}$;>i39{yMߏkyƈl7 wY7*ҁsVm (he7=g44.*B$$MmP1722?9РkZˈݑ0/4cR:_U`:0ʒwU-oZl]xpPC N2ZsX^ BO]+{َT,(HaTȡ (ݡWxyU06Kc g ijzkv/š$W 5h(~J~WZװQT`:iEɧ~˯Su,jcn[#:6 Ob5*3; 9"?0n{^Y VHD I?(UETh'z[6=(|܌EHq(,5#ޠYR( )4)k4Aϕu鱒KluȧkO-*鲄z)[J;ۮM@u~Ih0 dK+ އ2'Ϫ4ʩKPF3j091kfH&2^bvno+)1 hL~:_Y&VM p͌$!J앋ͱy-S=RV o,\N,MYjkKv*]t!26vJ.RG+8 5Ņ[fo1P"T){vZ8 tPI׹X%ݾ(+Bh6x똾bxĔ# E&חku>"0WBoem-P]QFúTxF%4B8/Ξ+ ׬wi9'zt+&^[&FnrDl2] lʨ/SGc/:zNvn`7(Ck)6ӼcJ{i›?]eŌm"u<1F9Vj> 9TrⶆbJLa{}oyEޡ `lqP{/Kc Q5$yO3W/+4@LI$)85~GۄIRЊ#hR^XX; m3]гth(bku DBku.NQg֤9+DÓ.eER'+R`C|HYʯ ZeDm2<_<<&U&I,adMc%EWl;$_%/5uƄd@7Y:YuK9uͷnO=6F@8A)] G32WH JT_>!Է4msl2b/B\iue^& [!dY wrXcwvU2"l"B%\ΝML͙P%]^P~[ [xg&CZs $)άf03MQE=,eiW`OG&_c7X @up^汏$CoacXOj&{]`mJ&a; v{}oAb{ùi}K3L DK.p.7e(0.&X%rSv&դ B>HLȸCe@H@Լ _-5$6Mf7DFGDTJRdyng Xou>YPO&ι9wk6&0k+z~v|b͸<=zխ ҆>~x[K#ZOlص2~J.|>E07Yz#:8W.ʐUzld@|* 5Ρ$˾0$|e *=r⋟ Y hPʟ_Ȯ {g0:*:;{!-5DHhrJ= E6yfs9DnqhߖYS,AVrբ A= SKkgz.n ^֩4Hgy~QUA5[!& ͥ> %y\,B46okUZ%OZ Y;B7VġYpۨ cvz_vUSR˕{)ׯ[cz$했S5E+H݇d`#'t{$;x ~1&J|,>$OV~[`U6^rQH3՞;( 8YG.73 pfg.ebFi9ړ7{|C4Iشu5/+9p)NU䋪  (S=M@ e)ڞ@^hxNЧ|/Ŝ?q3LC }Ir/ۆNe1B[ٳ*ruA2]xf0~MnAL˭dqVH(O[OQ­8)4*E3Q"rD o.b}"\']H 2|5D?x>_7K7B@ݬ)춆mlUvn|cp&B׈A E><#TkֈEhuy., 'rro IH1ݶwx V1'j_=FU>zޢ>,?:AqY{M*6Uep1o %&OcUm{!5oqq[7,RuDd,G2>ra.Nc.٧iT-ߐpDiSԻR|jK7 _~eGǨ.v  9][NÐ}/Q9yU#`"2؂XAtF.^fm`WNsЂ~N G2ʨOS- >'h) Rm|,CТ0./kg>I-R<"_+#kvЬEz' x 碟sWXbsiY06}KMuI#JΤr_TQhPxk8-?Ίr 6n2HB -PA-AΊ䊑ҶU_PH9U#19 6U Q%#<O59QNB`RV'n0Ү`zaLk~ <[7Ӗ->~gv|c6( / fO  㶅>[- TC@ !+aAm:Jąn#=Zt\@fH^K -VZ=S4u [[k5O ӏ-*?;GM*`bBŴȌc-R40fJBOE!g 4d&CIp흑/&佋c!ڒd4mEvi؇P}1KFXZ,0%Ю?+OV6J8{(w ]G7Mmɭab{]aڈBn g&S-R\duKiAhܨ֚h EJt' Ehݭ H%?vCA?#%l Z"cJ98gTi=-~Wp=QeRKaEl]JYN[xCCB6U:a{6SGV'O8 7שd+Kf _Qlt5ZcV5É }O\ȍui oBGtP XCy)F,y{M-:oG~kVW%dyqĂ݆͕~1ځq&W\-Ĥj&M, ѳ7fskӑO>a@B%]ږFN]kݯkziqiD WJn.)U9M[s:SW%:KTj m)D8V($?s՗&U ˲~Bܦ!5[畴H]^q~m1:u1O, ߟ9^ۺvWOM.ـv\4Yg% ל)8wd[_25.4(f]4F*@ x9v!)eV.I_k0!I,[s?uvpB B1sH-PgZdZQZr~z|W\k{ 뎜a,Mzd稧?<&It6B)O9tAH 鄰.8{z">[YWͼ#ɱT6Dr(`F>62ζ Ej T< 'UƁ6) ª^FA}Ӹc$ F?'p# zv>JKL)УϸrFʻvJ΋Et4rXHbO [ :evY`({ п&!?f$e|Zv&Q0?rmX.UN\f}(m/M"[9JBl4lDE}4){̛ľpLo*t`lݶA g dH˕|t|g M(^jEBX-PXE[a;;.ec*k´Z'Qnv[hkuk{<(SlDrGl{hl@νal'^|G4hj6#>Ftkv,bEp/GJr*Eu.Xو&bFy HnI4F,Fwf{Ҡ(#,3\2+lSFj?XS|v " ,+Gly+-k`BXӁD jȏ'kJe(2^DjW> II76%(p.O3H6O"b07wi*Lg=VL9u%6ٖ!ˎwb-qO. ~N22NaL'U) Cbѥ_Ru/GiV56@j2.(=ӌ>zQ{-)<9$dnc%\ɳ_Ȫgxȶ82 ;vo11G*ገ>L2d f$yAF^/s o៘ВMjIQPUF^F\gEb[&+!bl|@E:a 8@>l񞋪6Q+k & RZ NʿPu[ż!&`DL&\ZI% I*u7_.5eu=L`(@GV„OdK9"'ĉ!G9i R2tlb -Pg `i Ce! i6|CH J]tgg @ml˷C!/S//@/4Ǹi=$弹"a~JX!\.7X+cV@}>ؠ~njڛ_# 4FVBĦjGa*%m|M&ڇ8n||gChIiQ&|oxك"ϒhztk&M204y ͏}}V9oX3DOcW]W>YcFO@DU:Zn mݞ 喆{N]uYz;8N^^z"6QWFR{/7ϿMGuo~Ug[_⚞X$s`  !Rkd٭Rd;H=/D ;ɘ3.CkENqNw*.?Dbqo2 Jq7_y(u/. J4շ,;VpW9G]f>֜֯DCM}bn OH[g.\nP6/XW:Tp(zࣃ%%3^h4lXuTozz^@&A䗖+G碡s"${![+S4IQqyeo<$w:NL5Kܶεb=T,\Eى2-6(| K0* f*FA7єBbPop̶GO3\b׵QnHva6Q`( S%眐Y͍C<-m aG{##p0G0DWj/4#N L:Q_] c/gyT@8l2x#閲Tn$ 0ThDN [Pr6*K{8PyE4F<;Nmkq,Ʀ;( 7@<kh&&W{NM+\g{'ƙTN Ľe]n&'>C1?=kLH7.?v׳l0?:(>*("ߏOiDd^aWu+vaNn$_/h9xw(Y]aJĀqcbX[#u1SE+PS79>3J/񮑖n#%~o~bn%>{#,o,׀bRJяGǼ)Oڌr 5lkK!ĥ7|w&kA::/V0 TRaYt8lْ1~bֲMI"a49>1u#=ub\S.-;Dj-[3 '- VTwy8!tY= 8kM&DğMatu(raS|kK.D-[xRMVQ#7`I{R(Y8x:2egdhёbzLފ*] q1Um~/Zc.@XuE=; чfZ,v[Fp RKӶCQ)h6gMfR92{F%mL;N~+jཪv#rTm.SRBѿjk؆o\Nk5KhЧͬ墵6:{MWN/olM慮?dpOȵ%PA#Y^40)YX`IW4f]Y:yhڈ|H徇 |7ǺfNf&Au| ؉h -AH~GM\' Rۉ[~:n1>s mN L>}AǍɛ}SEG-kA:Jc}/*W`\ *zSm֑PXUrr-'Ri\gї?u5jv´ W3 @ޑ|B/n= )~儵fLn'JR t-:byySWȇcVMq{lKL9ΒCn;Gz侮{wΖxM)D\Wa}cL}q}Q-ucxB[ʄ;TSO#᱂i¸\9'[{ic']:/Y`WZmUTDt3} 7)6Ndr=pKjp}@{MkDAfj~HͳܕݵEv} yʟ W ̸osSSLS;mF1/mQAL4z(7+N8ﰥ+"_R(pGzd/p+ȡ.lT[XYؼe)ldiA.fFN QhJ w7,Hn0!Zˈҋ۳ڷ/$ b#{keyZ͒]nC#FީAi y]wg.vl_6}ɠX9}<ӟ9v$wDZLF=7ׁ G,lDw{6nFNJɆ̜S+ #FbB^h  UWG*}9!Wwaq1~S(:(LPP MGzc ;1CE3|Нn'djx^zC<\~x-*݄^HUHGW=SƔUrq`_&kw٩V浾Xt4!7NdLNfDIZ()X3;ta@-@7O3m8~mc=]sb#| #!KVwsMb,c嚡]aj%=tB ?s?f%yos|JfBgs 7VhrҕM Y?tő.ne2pDcTV0Mԓe4=Wf0ZtP/ߋ)#Gx1m#./{F-,T"xN8OXţǵvL^ЭqSJ xb;Ikw+ɕ'eX;ɱbs#FFyV0Upt??jj} [pn}K#YHJJ4bGv6m`%LDscJaϧ=p~$K;v<D0@! w0i%+/KTӬW{,eI -@.ɇ'dc:I3K;8Ȭ Q{S ج5b3V@>h9*^3 -}{6ߕw-;y uݝ$12c6ҰhMf!…vr:F j-r kY=EgUMNj>$ޡ+cÅjvY^LAPX/.#rbr] ;Be J,ن`Ă8a.\\@ wQCbTA`99^sz @-oi) Pnx7ҟ?-!ݟ=M[6I,'Yë[ْ!Tl ZV (si-#Ҿijxu9"ZI]1.[!&H LLNHEY߳x>5$T3y5(C/J7GyJ*7s|,,>YX}~Qfz3f۬mw6RuIdfp3d1hW9@_*nNC4cý֟#S# 7&~uTJ |xy-Q'wžh]h>1 12.NJfcFڑ~@RScBDY)0~IQ%pbwVw=wkLx˟J}YYKHRfևtO u<+fUm+"uIZ1188qhQr/〷Ѕ"0cu"Y'ޟ+:zSCw'羟֒f %//^?WVR? z@{IBZCZ%"ic>'N}`:ꋱ1b&PX~'$i{D{&}|l6QEܢ'dHi2e.)&(Me4FfMdՅ1JOl6T8 d6h,p=^T㠇Xbf?k2u_u5շ]vݱK=_r<Sk[;C2 wWU2 ٹgѝnOrLo@+{ƍbBpB9b-XvL=S\z>S;DMCV%/e1*QQg->Qcu #ԵH 7Yq4=Opp3 H_G)87".NDV_dnk~~q4$/cJk2et SWuС_Cd,f aBզ½0;AEX4nGb,<1!tBWmn:mc&c@#[˕|s]#=W6W$U&H#-@Vb& ! (93Kb#uù%J(2 '"-] `df{K"A[D=|ΧȔul$V@[ C,1>-Řzoc~@ԲOTӵVTv! RUhNFY&B`庝i!}%/r|ɴr}~ vM6iɊu5ktFi5LXK-W׾}nuB>;J!/-v[`уwhTc:>x[G8)_& W /r.XkqOkL{M!^lpMOz~@glÍĺu;:L%ZW, Uc01v-?߄Vc*Vjzv9)f Ā)ZZꀗRu{2-"uЭ[ tR[2*ٻ1#XY_9qwHU"a{%hZj ^[Z![ЀfW@7z΁叙"gAʙ*&POvIىſK) Ks+B1ں]>v%Р⊢Bh*5Of sk0ڋ OF& xp W'آ~f&M6~59.[7 0g yb z"$v!qaC14B5Fre"\Ƭ$ HowNkA%>") NF`k ZńIcR6#?~Q/HCU-l51b>0'qPS͹:Vۖltto &|`{0,-F%R9"[W0gŏMp>CY=\n}Xc!敆waE$=cHXhs_b%{hMs#-CMdgMfM@"L-p"&gד,ȷ=3]eLkJ|%q$dIPUF'M)drZڽ#Y ]n9c H}C~j&l+`Xlζ5L IV{]r$s9IASѦA >dĶE"OU!wBt%=]V% $LUG:@aU͗ E/U lzs~V/F>ĈϧbkbYSM8eEQ)OwûOH;k>J7]xu5Ѓ2v-Ru.Y[IGȀ#b#E.[s&=:͒m2@ٳCZ*Dʾ3KJ:koV3b(x珢ZLJt.(doEN.M!}wz~W_C-kU2G@ RDbF8kj>=Vf71{h&:#]<j|s <oZp@I2ڑk 'n>k\E`=hBǹR4ՆW~?TTk+Z+>ݦB0f&ᝎ6e18`sT<%fU'j ,w$f5Q-e 645[3""L^\M 69qzVҩ~4+N /dzF&g}ϏN$ܖIB{i;#|Mh8ˉ)$>qdy=sļKV8rGqps4 OQKq-I,8[92%&{0)$lXfy\ڞvnu{SN#/e{݄]|scVև%oj9L31HȶgJq{2%V<2$$v>ք)5+8 w<񉋝vB<^<1p QK I-!&v?< ]tw39w\пo9û5w4q9*ݸ5W$La,Z>+d]ِ=~Iw`2'E #=" ) K?wαT\2G@rPψ1yfUI!j͎ͣuTBݝ;0?ZB >.#·.Q%$<((Ky#o;&bLqeD ;,K ~Cj=#?Zޫn !lT$~BGdю*ltos32;ڝWz.vYU#J=cW(2/MߪjpC`-ZxIO[+2=ࡢȰ4↾}yW~+7]a{ W|/jBK D $*E)4rݞr'Ny=H.:[q^_*#7%S巴j 7X cx(g壮YlWؠi?Ak+oy,mBl,zHZ<$:V{1=Mqoz/\ɘ\gg#U C4:d#spQuY-g4jƿc :>L ^N3Udfui]£xb=H^ldp8Vُi1Ƣ>k̀ чq<ĵorVUT6O[qx)|cS3%hqtc.$Yi+LP7dIXwZ7A~+Z4 C ȩtPFB?p LgWN0K'#nUya.?MŹ3qHfDq; V9ipGZLm~ğ4 ꫅<y.- <tR ~C}۠ܓq8hVYkXTk[˿3%ҴthTSķC {V -/2W}Ph=0m1Mh G+U?ˆʲ; 2u}7S׀(QI \' 2]e+A\x1ԣȏ\vJ%'VEDy5T/{`ۈQkCTe5@Wx|a_;UveAem1i~ Ǵy`埍E 'SUeE)/ >s"jP('< r3z*=I辍#@<&®l ˡZ&v=1sA@4H½ :/Z_`(C"}c%<ĤDe$C-+|M 64TGp؉?2L.ǘTrV_ `pS1q5.Pc[I =waz$݀۟sÀ2֞ʕsN5>E K=B@|?HzdKЂK]xy|@NNc0fM{t,sUΏJ/=Q×n[2f +Tt(OBZ2qXE{M%G+W}b拉x,}xjl[R2 :$f_9ɠK?HdFʆV 3F\_pj9Y$,5uBl4]7jZշC?}o9gĥ U__n_]ӌBEh5^sm%k)TT q)L jqPj!Sb)jHxixGád+{q)n;NRAͪ 'YhuG|h!DzTȓnl]Abttպc:DmvB|~bs.g9j  ~ݠtH 7w}Ba1h}@K:7qe= n`Pt2 )` Kkvl jYuH˷̸'PQ@eQZg1o̞ :^DU!RlT:$78FGI4M䘋PR\BT,Xm {tq"s0۩9U%+=COG]~g"Bwo|da48!M斞l~}uy 2QT}"Dog` y8cEU߂wΪ`$#S"cqP ᒝUppiY n&uyb>{Xm#5ȇ۬(Rc$,j#AX2c"fff. Ujhq{醰o6>M|Z3n<\8L"&H{~$k/M@r\1 .y@7o_7 Et k{hjW홉g>\h l֋}kq.[bK@vd12%!2UW$owoR?8o=uI568eAS'Pc}>XfjX.5%;*O`=9J2Zi"ݚ0PS^4cCT񶽡]$S#u(`i x # 5O$Hyf)ɾiȸ 䅹s =pEm*OZ"vzr<ʮL9k喳HcvTI}U]ffFyJѪf410, W_H\K:zZ 翈8m:=@>:qF9}չP-+@kCJ\ D=~`C˷%;p`_\}X~/o&Nk@rZH\I5lK/l@dVmYhg=.a3IE5/Sw#.ӿ17+B[Enw'gW HdzrAehgBDž#< 1~lb1輵%5 ~ 1m8G NR:\rЧ1Wk"w! X'N+gF5S|RCE{}}~AF nmm`$Pk* zGfښ@+Sb(F D&/9_{T9#|dg %T`.f3qlfNFZOtj={ qꄯH  ǟVHfh;|?4'I'-IPN2Z/1ݷ@]bC+͟TLlat~,%&+ dmews^1Q γx ȫ>*gAQ,{4!ݢ=^5MH"PDh}Q(n3?~ёv 3} N6tn R"gL@Yøn6LqI.9I/60x|kdCONAsY=*b![?1-[/.XNE~W'%U`a (p6.15YE)}'ixdp[:J]h)bI!\̜^s:܋շB0Vxm տUP Lt6"r fΠCt햕 |}-Υt5[A&BdF9+e}ĝlϪ]zRW.R:]~ {\T*\j[= xVdƔTl22poÔ-?Lap)i9a;ڼy3s2p6'PR םelkBWϟy_PM yc,ݨX`Qa#n8m:481&‹op\WV/*-CO?߬RJsռȖڈAg]1/c`fk![}?$u*{̏. [dZ-'E eO+ }jėzӫRA9ii$1wѳv1(t|]My/k6l$rv*1S;=uOG%5 "cilzĦ" UvFuʪ2 QI$(V$Ww&Vʨm/mʙ׉C Hc֮ J7Nn]:S`4HҪ* qFTh@HrQ`!6 y }r:f(OzdFD?sZ%/%yK:7ΤחyџŨs_>-lTs,p5xlJAZ'$z*?z!U Jnza}e_Wy>.o ~q*A  z430ƵYx'Q`vVVA[Ag=Kr {Kr+ ~r}ot#7pڀܖ }e(eZ9jNs ^]2%)s@  $8Ѐl*a.k(;v!qWAc#]Hΐ~>󫃬bAj[q~'MkD^b'qK"wFv);3KjskEpf3{2ʾQ1`:8!L>G?Df%tߞx@Is@f$E6GywԮW z͆˪|S^9btK* 7 Dxp}߬;<~BϪ=R_$kp]vZMW& վ\R%`9]ЖZǭѸqۼ<t[,p"7wfZco_rziHd :{l&c'8̏i Q2jNeBpGv-paf-_OHծ&UBH?$j}G\e! x'46(uh4[Uٜ4TU͌6ͪϥuҬJdFzphj%ɥdp͔ i%)E,8 +fz*k)4W~!< :F71}L= ;%b_zXn-}JrB\o&on^ʕ̎o`(:|Ty6L̿/N*/j+16=FAly-[ BTmv!x{ygF>$aGv.#.jv-.qz}e0|`vlȆq2W!ts ߨ :Ǎl f ԃE廰k' \}ls`- ԳhL` 03{R[8Y^\|{S%n:~.Wnd8UKC .`%2O!%]a8ғwl5Q9g1/;)GaT'ɢӸq7%m7-$r-y䱠@P8"mn[f6ֆ;^+/6*" ?ֺf%1xRBOl(#wH7Ys /F᮫i$4): 0%ODX'E5kSz29ID'ql+oJ9^/7@")_.6h^jXOj& },d'ЏgO.j4 \xc8^(.Bs|OäD^+.@!p/" kuΤ?[+,%4'K(|q}]z) S  "i4A'V4sg%E l.Wt?k21<| h_Bx>0U8vuA_A8;lb+EH. _Nǒ:}͋} wucr|N1ON:x~ Q5kSSD|nBQaO H4|i%ߧ,ΓXъ ^8;&{4s/-.*jyX3}nGhJбa^ǫ8uy~bʇT]??r;E@ָjH6P`$ ].fۡCGpgTs>dIԹ}`Uhzk9?1SȰl/Ab(Rez tzT I<̺p ث3n%B (_hx}.=5ʿv`ҫh`ss-K ҫt8yR44ɐ9¤a)gп⿜ܰfOqN fl7C:j|v[ ߩtkIKV?$!yn;qRgԅtWn WHJK̹^Z(_RݦӪ˭8tun $NfO T(D No.,(r3lqLd\9sz`6xJ / tZK5 Tuhh7 X';%|P:;΍`U/i~RQ,؆ڶ.A1{ޠM ̰C0_,v0}^aC1FvyÕɧ@I'#5.TNh"s.Y ˑGdϽCs~CGto ޷fb6<93c* J׿ F"u9s&k'x3*ݓxcC(Dњ;h2`@<=1s1bJjLm)K$Y؟;3B(? l) /s8酝땽D,t< ZLc>f=d_,~06)7ݧfpT05jCR΋W)BqTkc(܈nH~ުd t0ijU>6~M}=AZ:gg2Λ`n{j[ـdwц9JCj]v@(5d`?GTs_G R%r(b s@LBKqt5$%2idxz]^wV*?JIz>/_Vu@:OS*zz8Y BU l[ =Yi9IޓUvwJ2)7z5he F~qN?8+r"sAk6Ʊ "_ard|Iw/md\7:c&,`7cLRL[ߨ_ J# AJTV5:ƫ Q*$\Y;ʽ`t~ЎQ%n8 su{h-,Ʈa[՚AR5;%V`МjmԟbS 7 poFAG+KRO1գ˅PWC4iĎ~k c^CBD~U|*eStO.:t ^ʧ8P:N+"8ʺވσ0b.9#(A-Gil~ a]7<''1[5OL4[ G G.PTnJ^ DuqFF>v㉩@(j3@;Mg]:^Eс[,j5"@O䇢_>}裛v.3ǮEUwz%0[{Lg[&F,’E+Ob?Зp!;+]o bC%ǵ_ ]x ʸs^MJ(k^P44 cn"q}m#O 'PӁLv Rb s?6k{WRqrh$s_ umqβGJ:Q T/s0T>HnQ꯹) ϹͣL3=HgJ!ե&x^3js`(\%fǙV:q_lR8/<[7(GY=d qs A9U2}4ɑ  GxO~TJyȂ⨹$*a_<]IҦ8,PgNL٨&5xRIMׯh9(w-".׼ɀ,EuAKD fO ` HBDE8~_ j@`X8ߤH؀'hG ZJv| T- ;~!uG:1+9A3([ :nQ!2^Kn`e#8_8ܧL;m qw.4nU[bzfӂG@*)hKSק$'ZR?5uBmpRsM~Gm9Vd` @zhQ3~b¢n9j+i녥`)ڎ13VhC[G Hr%Q|uC퀋A(XgEcԤ"2h!l& $ݨm m&bq2[`)߹h5Dҫpΐ;X Ⅼ|Ku 4J/C-?Xc,1x$sm ZL)7gpy /+32ħ>9LE dAhbx0}vmn}qOpɕ4Lm1àg*O[&) 0W_憯PtM!b|u,S)Q?z7ӟ`lǗs0Ipz gwSWG2S }c`k49ˀʀQ xKz1nF#pt|@Jo>!5gyZAG;`D |J h?^95'>ZDT4 z#Wb>M)U3tpro/dqKߟKCPI)9Y/1tFbŮ4Z7'f}8֬Sd6scHV,SU?8aR *M@cQewF@;?\i.+]K#2sm޿Zp:a4#\ EfF-; 漦qs&"h w%.{,V+B[BJ?ǒ{08Nz֎,WY-#iF5e2&IIU/ucSRؑwVrWBSkt`N4f2XSDPhtbs E\ljXd 4 yƞCZ R h;{6ٚpaT0X>O!:moKff)D%W>+2?_>C[̿B xT2#de}tz24|*M zӒԽ 8xIxtjj+l3-~,Q#q͗-}uq2Ybuo3b S_dR[o+^I;fE%AH݀Q!|q}6̚{+i339:0:kh=$Mmx% rv\({u@]O+i"=[ή z(chlO,R)lb]c:Mi*kW?!:Xϣ-w1鞾}sYZ<-#G-AhN>7ٲ c7,Q--DȤ(2V.14%L6 q+Zq'07_ .b mBZuU ?XmlsOaon9ґslAfq ή e)Romb=%osc[X\/y%bs4n_X<1ő"=jbg {n0{'r;,ޕ,ql`^RǥN|sa, O؄#<[6lBH/]<#/d‚\y)n*djRPe@Mq917"/;([ /3^B)Oŭy} g̀J"?$B7(u8|Eg1D-q"LEْ ?mfBù4<+9L4H28'#"xSKʻ l&7Zetq\1os]oCBw.zJ^/wofߒ:m ~.+Vz)b+QوfMkӯ̊o }˫ڽ- =D.;b1zÛsHDMBΫad9zjfE續T*6jtw6&d<_4R4w,DȲn8X[l&fCItr{)OfIgv{"QD)&>1NPLzYikOsoGxPvjjF뭓~@ *yjNV%_ 8ЫԿVxYSDqݭf-ָgbP $U"[ϙ0R S[]VTu`r(c)UL`)uû5mrb cl9o(ၭO`,"!37Б^R@DgR![BKL XSr<۶!3L1k*ұ痎xIX 6rvU2K.,t~ t6vl%2DD$tԫ),ضidU+BdxW.É [Gs{(2M@=93/G |˲J%~7L"W)AwoҽD')`e$]3adBxtn UX~ls?8AҀẤUPIٗkۢ=5l0*up뀷W`7]*~!aE8d?qdK4vq5AW0CD!t.E}//#)`^~ ebC1l#6(K#;IQJ|X2jrs`mÑUjPK82gDpr<ïiȳa'Z K31}IK߸-j9E h /SМTT`}uPrFLa:X D$ρբ{,J!mI3%h]ld-'l`Fd71+|枋62 N" ۫UYH{|/ 5"Ȭ5cvH㽦}C5C;"T#.f0?H'G1g#co m(;ػ+gBTYjTZycTʱ4RP؆Ɓ_`a Jf~vti}L;!,o 5$ Zc /a$EEv-_ۂc tsǡrvgW9qUuG%gLG`[@t&ҍ}" TeJ%.Ѡe2K)a1Y}]ܞ{84 &{oX1Y2\U4fP7ctgˏBH(ȉv'" y޽<5F.yM=7RC1/7 Q.$"0| Z?Qvu,ҝ+Hvnb|0q$n$8ʧḷHKr$G6]ʔMYA22|:pXsu1aʶm5Uu`/e: R!@lLDb^3fi_x*ZB}TG~̼TRGJavUȺm3qv(^TE>499ES$O])D!;!;_<5 'g:P]ת1Dc ClAW,.fOOrI%A&)2Ub^maGbciH T4Js{ \C]aW{|oz;JiD->P[ٯ/O< ,D0=ZRv;qj4 IȒQ F/dmt+2b`Kt=[yyωu甕Sk [/ߕ,éi\mѤ7([$-iLwx <3MdQ?B)H|.ˆ }.F ?h3yIRzJ]XK [:ecA ue|UF>%Ё36cy)sX@#x@ͺsGx̫ߘ[>މ8!޸^LQMe t!^b:'kIsW_/-Ao+3`LUSȨ=P-W`Řd>zS*  V[<{SmGa4ް Rb07ϥ/rj7~YCp(aN Bw{ՇY/0[fh4Kr;8tEd%VFB2$ZC bBR{SVmN_D !C岗jۖuvXQanJcu[FXVz+EA7SD([w +)%#G)uzhTtU/qici1E1&)oQox_4ty8g~ଳ9HvţJۅVӏ"8j' ib`D DmDQS;]MVV J-sZW0F&F]]|:by[nԈVI vbY_HIkw0.89D;$A'=%!Ktw_Q:?kd\޻$oAJ!QЀ y=by~=y0Uaǔ,:1y$R /u  ٱ?@*So40,E{oUR(q⺰#bUfOG"*/Zծ[A<)Ci+[CK[FR6L^<}'94*lClGگSPMQ.F}Yi9quYeaȘ 2!=+@xo `*kb_w:\J u~Lsm$'|Zv[1 MX@rՖɶ2MY:]n3T㵬,y d)?vqD,)}:Mn&}n71Ѣl D!VЙ8O.ņ'#MlEΧ{Ư^-$'Hw|V桬&w4cCt]Fj}"UY>czr.lL 3z_RB#Ow3L-,@%)<ր0Q Ds2Qf=Z  _{u`^* mz]2]?0Yi7Bؙo(9zUok͸ntOBj[`m BK$'ɪ MDWAْȋ:+b&3prS8a~nCQOIH|3'pMA@ n9?&vWsM0"msi6kK*eoMv5ive43,1x{`i'Bs00A Pfd=`i?)"Ts}SÐSX?X5B:6kw İ':^Oّuet6QSƸk}񷬶0lK[$uN=T9q"?H-20^ j]"¹`В~vmZk5iMJ4&z5hE{Όo. XV4i0(bjʶ~Km_X@~O;s@^ ߋZ .4t82 IQOŎ)G٥C^TÕxJp_iҼG qʼn_v_>NDFbU. nBKG-8ͮ lmPA qI[D?R ٢88|i{$~qPvj8e82AcNRЇօ BՉBѽH~R3Q i*w]G3 ƭ6~_"=*bؙ+!1rr A%H{qp„R5#/b2)߬X_pbᛂ}X^Я^8~d.Ow_ ɍxɩ<3r@ @SO/ZB#ADЪ=JbuOb5}sp3qW l Hq@]]lœ-,K; }lŹOꎄxgŠLJ+ޠϮO]шvd'3wZ_ĕo'6uiiMزp`K-5ScqQ'V=aa[=(8?"9z0M#>p9AezTƌ0LT:,Fi2fTot*gtUĆԭ;Ff.? ,`,w95*(!ϔm.y"3@Xi] @T;##W˿;k 1pp2 dզ$|o ӵGN,YZ_c%…_2ʒywƾ;^"zsKU k+ " pսS|V}X_qoz^|qefFGpNU+'jaZW}g'f_L>_ e ٺ r5vw")9WVC"%dmIyft} _BRcZ}@Q'/x@$~vhZސ";"x"u nZ5a8/Y!9 M/-M P&V^8Vi$iԛA"-3?wHpQ-~G+ZM31Si26 h4V y§L[t6:{( \n:qĶO,=x\ )P>1EqxWւ8+n瓖wF%%!%To ^ƋJЙZsknTAkj3#V!'ŁB98,eOs#32ٺ)zDz(PV׵>C-mMQƌҊ&4/QJbcUH}=5N(S-=Wnu6RPuo?Cݺ=eMYL]^pB2=G~G, p$9E]D('LIPj,Mջ x2zc~ ƳeswR`Lp'\1ʣ`B@SEP.I&Ew_STۗ}W(=aQu ts-1\IѢMn"3z tIp$Vs(=q !U}u>i~`CkM!fM.OHR\/)5 1Y`HV30JC^!\⤓ M󖝣 `DT+v1dg955-Ҧ ܡ䥼zLֈ?,vFd{ٝ&; j2sW٩,Ĵ\j=/F2ݬӸ?gu2^-9 P:_;zRdT(ÒƖ7Nە_'/,.qRJ劍xyF>{G.Mi(y2:>е:N28`  gYW6ĥvy'VP1b']x]>%|n`W="BQDҪMH~H״26ui(z,޴.1e |:n[[;b~yAll=+#nǜyޅ$BWOJҕ[-`fѥsQLie`qOCwY E_fߡ1e{Dv/Y0J>Ӽݿ=#o(`*ȵ*R~F3!7+Y,>Fm`0uAD3NrA/TVMް`3&wӊ!Ny rw43hiɟqENTĚUҫ Ө!AAX'" 9.8N(ɧCIeGB-6.Ӟ'5-%(cs]F(;DR+yjR7f=X۶B62jY +^8МvLrΟrTluSJ{ 6󳊆`\$BS=filV r&eUm11Q5 7pgsI:3Zson++k=edY _iT2" v aTve2PZNE;L~ֶ>op9AIVKhBZOP%lOh68uҞ'iZv`T"[{>!16c,@A0%񳳒H10wB-krxj%fHkmjz2!&{jAʗ;2ݷ[P$|05nx<5%󻠵hG}F5h|]ZDB0`u,RlRaB)[nYwAӄ(a}.BFmUIv&z>BL~J,/|y' _z\:To32!TGpĸ^p6/UFa6fKvm/PI8-Vxiw6#7CҜL1>TX\$,wȷh)A ӺVӛBX5*`}NGBW_VssH}7v<#Psѣ𨀣- \/HhR$'r:Oq؃0iVmMY4f;BSr2jAsm; &Q%D|-3ru¹2KOQŶVNju ki@g`<‰[n7fvf%0j-g5և<|}G荷H ]TW;th@}Xg郮ʫ;E,ƫ)ӹȧkRo(C}+aOtiRih.u\'38K\B6\B8!`apHo! T6Lڪݫ—/era@!FKc )Zn[/\ o%)"Hߋ:x|@z\{`va P+F*1. ։,u:զL3t)>G I $2հNB5aQ E-u_L~!MMaQ\klNJ[>sF QԧɬR6zɖWʝ𑾈zp4"$oӡb*& NiOI81ShLn%hHA*@pgC3 p(zs%zKhp(vfKV8OjD ZȌ 唓 /KtIbvHٛ#Ɛ} t'*k._ $@*aՂxO0yOAg1A3^>ߥv,H)CVl`&DZʺ-L0JUKM8L7;w6w8[m 1ɇopfjh"IGkI3S^bC9F]E8΀,ai_/ שZGXZ<2]&>A1i ۇc+5C?Дѵ-5mjWPz`Hb{ykS\y~ܧ5Q-kտ i5ڧEš_SxcZ_.QN-ƨÓ|2Gl7||qzHHjpÈv):A ZuZYq;IxK6')=} V5~8ՒTB['.;f݄`3UQ BQ؅/v;[L6D`2r-͗aQ>" ⌭#흙83[e4s3 ]!>^e;XN`P>@ŕ E$pF `G!\0xr vvwAw!66ń2Pnp‚{n؛C×caɪͺQ4TsnV"] R ˤQOx>Vrn8㭦飌9wFzG(RT$D ]c]_i3bJ^#cNc> OΟ9@Fđީ h9LΣV%?lz,{*L̂Ѡ3lwzR!TJVi6^&:Ex0'uyP\߄l'- NÖ8D;Dl=Tpy Jh|@"%93dO}ro~'Gٌ1ܪ:2W2{}!4Z*k\Ge& ʦ/޸^tG.}GS.zI&[3Ll6ghƯN1Α?bN58 9cHIU"5ńT d2roLM۟&KTh>>r>H^",ᐕ3p^3ӅM58!G zNQɺbB3\Ba1 mn+;6k_t 0+ sOaa}RH3tL`qsj]d0 BPL7x01%JOf.Vvl՜W*{Dt8#c4fhع!xB]T*Dk 2uO*uؔY^[4WDq:w=gA)66q!؊/&RbCa`(ahd3sÕJfX,C1 gf|mYg>6E(5'R,_ЉǨj_ihw.?|6h1B]+7WB'xF+*Brl[[16뢝T]깭opޖ ,ZduWSgB|Gb\Z||K&WFpY-% :VRW#Y"gm3fԲT0*><-V(#$IkElpى4ηDzåw$[ сYmXژ]^3,,2y0>4[PeNR69?M*3y_ l^wҿJzRr_ rK=Ad| 6yYp-/!MY?1b_|g}(9J߻7]]?,mI^7R]"h۷ך{@n1ҷ+\ABT9,:h;OLF$M?x@+IA+iJ~ 76X[V:Gx; q{Z6鸗pA~fI 7'ipӅxKrqcvv؊d@%sk(LGI@>#x#EM='D(R*jԿ>햂@C :ρK_Ï':++4ռW+VO?UVs6oӤ~eӮ•ҟⵛ 5nׂ\`-A]4H= UQE踒s,NCW:`>Rؠ255lC@5ո[Au˩ p3c2]݀si_HIYzFC?}JKD@<;g6?%D*4vH(hI-BzhLv#@T6olj+^1PZUSupiLQUJJ+öՐν6̣<}EZ]S B;-26DpB"|LCR8㻺s,m6R5 uՏ:qft+ !K2\@〚 7Vq, v 0QS1x> } 'pwvMnl`W+1EL1E$@2E-<"p}C$w3>+$& yZңŊWGW,77P ]ԥUE <#Q<{եc@X5ĤZmiːd= pf> aǵ:mbvPuhRhO#yNHANuRrpY[2"EHԳnc)#m%B2R}f΅а:ٻD!:PѠ^(>EqЂC/QtH } T0,3j+},^~/&cnōt1M9sE_Ik3nhZP9F.Lw&H-*)9ڎG1aԞ`(>*D{庡=_-5w+O!|K ..TP4Ы'7xbAh#7d̙y ~Rgeӛ6/W*շ|[O ߙaY mwC&in sh97Z8٦},֎z}lGTD<(`|ru>S;Le+OMޡ Hl 6U/қ~craW.*䙄+}gT+yƐ~^. D2J*nD8jض.8hlQ-!}*0crPDmDOƽ(( 5-_s>3x\M޴b-^6FEښI0m GiwwNX@5eal1`Đ39aS0Rˀr@ sqZ߻u@}z4?h`Q@J{Vںdtioh^bF m.fZL88oة s$ Ӻ\Ab ;_c:Fn77_g& :‘r:_VO_݇192=|_y' AtlY>wۼ;A_Mbw.kݒc5 YU+r̚0>l@ TOpԫ\$ivTze=ZҬ,_QvN%?Kv,.EUZEfߒ8lZ+6Grޭ Vzz׃j,M$r]eeФJq9l)9= 4p٢__-Fr@doLp,9u7XCMBgLZ&lw:z0Ůiե ͦ"SC;MgݷIJ <Ӟc.!2%;$_#dN94Mq؞:QJ`4iT*p/2TV0ʤNTu]vû) NyK mߡ'rzc ~CBC7K< ӻdsF,*Pjj>Mu3`FXL& c * he1O&EZ8a=̬c@1; fPF.DICX,p}ʐVD66 G:t~scimfR㾵 c#Y޳P8{kD<aJ݃…ޓWj]}9 Z⿍RQcPսR*J(IJBT*E]*9_ 5w6?P\ig MU5;=y>,I alǎjdiw:l88FY NNI䗆'1TK]t +,c`;X9BZO;hGNFU~b[ 0AZU[2Lo.yW;W:◁ +tصT7'SƟժV0rct2(ԧ6{/P$ᵝ4/Rtz KgH,ZUυP ( : jE+uuC8G& KfCXZ2gcƷxD0.N`ɡ?k j 7g% Gk; .%y)ur< D$c֊HlЃ-ŃQ \ᘊ:υγ6U<5Jnոj%(0-mְ$2f4H*ZkJþo[}O2%ޫZ )XHfQؚ*THlQ\F1B@:5TrhYD=џRj;*lyOPwBy>Du&w֨-M#mzjb)g%LpqT)yyNA:Sh߳1y ~RiF> )kŴ-*vU % ]l;$P%,pQ{umchifG=sاifFR zU Jk – E# I @HykZ}H-Ӝ쏻poTW RʩpqXjͳ_ds1u=9HX`Z%}9荼7ߡ/I_`wqb;(hS1QӉ(Ine5\Ծ1KLњIU;.m 099qm9hiE= b7I<^݅Eм]o.2c&*`"|*ɂv$prwoe`hծw8ңVcG]N\g~n(UI a'IrO)FӴ'A-^1 Wdnr#DnaR+OqPXt~o/hB4N/sfic؁O pU)?@mBWhvA/}*_k<]"d\sM,*.ʎYďLA~֢Q1e#:[PYn+!X."^iG+^Y+?fK+[&8!]mÉ^MGG3P .N",>Dΐĥ(Ԕ>F:?"a0j;2G.yhy _ 놭66hΣqzn6I]gκ:4ݯ=GY:a45i2n8f[}I 9as"g;H%A֧~6|$R<g?TM*MgBѸj^拀R9&V!$Vn}%R'XALܗ@/W.m4 dh!%]FTɎ4h}ekl3U` [۱ ^o ,0:_uM)A9\ C ._vgX.U+&K1eN_NfUJ(<0! rM-3>g˰,w8=\,G͎t 7.N,^r u ~jNu"2ru4Twv$G. KO`-K*agp89Oyb X6ƢpZ/n\@ s}mmgϴ9"^ isp,1ن뎫me'L#1󊸮 n*C*8GN 8iF)٪%4Uº}*VMdh.Ӯzsq&gC̞R;;m%, ?#.s~L·H;\e^+@$wv|;2egx]˸+fw/0{(X,,p yJ +`C~^ȢKR'<0,%y=7#k<4xr"Ǘub/6?.?"%xI!XDbCNW_y +02\kG xmDhа+rRC˜L ^@,OÒϋ&A]0ݷ̾>x UeSX A ,WZ rXt5f%(,Z(04KLC:D-VHL>1f^*g,{N_B&y3k?ms8Iib02LО iqV -h1G{r0ݝѬ4qLm"$s[O=B#|k#ZVrGEmNPx-_)ƦEݱ,\.Ň2#x2e{p7%5w( jiaĚB0}Ꞟde $ȻCa | (ks|ƣ*GN:ۗ&[d ;WCYM7BQDOk2P0"l}_E r4ê ZDtT/L f)R82 zJ[֫zR$psjRbݤw5⑕Q3=A0/ov :5T,3HlPyF3E>/}ᏼxnz&H?Ka@dy2e۲#2.<2EkEO!8nv9ug&?|$;HIC\ *:WŻ3+f%}lJ??,MEr \NυIMih %ɏ&V<*"-Xp9+GsB8Oh|Q*:Ǘ޼UܹYG3w:4纅0 ^Eay0P$_u5$|L)=9ކ*eyxV`[pJ^r 9=V[#AOu};L1=)e4N 1. aj"Vr+67eE јI΀ ByA-z(`%K%4(x!gP&Pj<v|n,(;@[5,Wʏѥ.Iid 1F$>JT 5.?0~@ǫy'[@>x;aY=hP..o P%myŁ9@˓cXNYlʽ |Ä&'F]36uYz7 ,6Jrcl\=mhcdƿ#%P~f-7+g6ż4ݍ`ko.Fz̛SY/5 eV[>3H&|XuJqA))ʥSbiJ[˫cNϐmY~cEmO"N>I(Ͱ7MN /d52sW uL#F'ʛ)Tz"7Wx91OA/q)۳0\4R- p Aݔ_{l14}qfot8 plXNY>A1[aP캅 ܹiBC'KqG2+GzF^s)0p⨽Eӕ o4hןP7Ii֒2̋Jqy8^?eMg{48~k2Z(Vk`h~z<92$$DhיmqmNt`s/ⶤr\Mb+?M 爺Y-k^2aǦe8R|8)/ 2Lc?8o(36¼t ͜2аʝ4tn4ژ(#ksN 61W)#^Q 7h91܄zU9tx0^u4| IA} q*v$+>E)ϣ5 6&#aD /χrF/]:] M]'mH4ο."Aʡ)ar*\h%k޳łH_NEXW,92GgE+EQ Y17NAHy]}gŭj0;{l#+)cKSȹIFL؍uUM) ( x_BB&. jnw3p PhB;yç>;<5"ejE: }vLy;O/حy0NS]B ûPdi<ӿnjX K w /cn\JD)(} *U1Sx=lzl\7hܲ:^޼\hUʺ7m+`19MyʂtI%xgq!F1tF{wUA+F83RS^ TH}`5sm'sVujr%mxkVn DaBᦼy4f,N:澸 ƚ\3H /(^:̉$t|3OsArT <#^!;fXaPWZr%زW{)/OP6DzC6YKm-h2PBEF`sT0_Vsfz2r]bF^_n>⟭i%%f0> @g;ktN`FohL=O}-DWM궯k#DRCpCuKTK%P!?x>W~.}2d q(՗e Mo h- t@oKԨ*X6cdgYǟZ#K;w8a=hHw/t%΋X|+5@MGh]>sYK"­{7 g,==٣TK/U +qB09Т?cp\qB-uYkfHNwtLa/ ? z%UOH ː0bVwV녋I`y~f*j'WD&.}> _7vg"=QfYTY-`DB"j U!Pb =O qeR"1BTPTJ*]Q~"We"Kfmna^ݶ`ӯOE'-^Dj9=#c3v:7fѕ^[!O0}Wb5.3!Ko#߳\@(\T}3ot֨܂z ΏVY E{ԏEs=+:&M9Zms}&z7 j RޅM?W[2e:?Ē!봇;w 5?'Sݐ͞Fl,_vqSx#cY%8y(`z'2LBSA*`T݂>@̾'CxC*3 XN M;-OQ*X/C" Do) {.w1\Zn%$+f*@( t WJsӟo*$QX_90C@_z_(C =QJU\h}$&!jc;v\ACpt0i D&|D=ER/g{= Ąg{e!t ڡ ҡM?oN3ygi7y-M= Exק>'ҮEl̓Όj9=UZ~y4sVF>Cj)i,3ŕ(\\CҐR/KE&}g3pinpn˭ 2f`aS=8l!{D<))e%GXZ)أ?ϰDSt֟)9#;J@& AY5\^tCN+襻2=BAH+2oI  @;|"h 2rxz6337 '\@Fq΄Co 52.3'^4PZxx{Kz!JYT-G).W"[Kf)3볺s[.VgYE$f7VUSv 4\4]3>HO1[y?_M}** J#b؏{.[VدdJ 3|9HBK6k8+:+%`Ea޽]`WA0ZA$v죓Ne1G9'whUz',= Ѽ{ Tr6Du6۟\5Qs*\90Qb<>?vj+!l}hǂi ]nX{r?DvWvʆ[xW }|Zc>E LW,zlrxJAz&𧴙϶ss%u N7{&Ӏ6 #֤W򪩊&-<ʙ,]_\FùfƅGPYz;:{o}R6[5]N~̍F\yH@~utegpb1BTذKp,JK-;uݙ}Xk 2iḠW+jgvX )DZg BWa+ іaAcLt1K͡=d(MYwL  qQt8/R xsjeAޱ 5zvӈ$F-R0 lv}=T 67>Sk+6ytae5g!}r#w1rduh[Ci<}JRQ; X{`ӀRlm=o`WNGjU]$ Hz=2e ܍:eDEXdLO *2ȋᬥ[::>i4 yQzt͋{^ bh-*1ScinS5-[f = #mY-\%ᨀxKTıvR>|Tu6[33ט %M)yi yoP9 ćs=Xp Gj Wڴ u=ޓ;w1ؿJN #Ͳ `^˗T|rGeroƠ9Z8|-’}DgwkX:"Y&t-Me ʠ`Nc9p3HM%:jgqƍ DŽa>e7'Ւ@UlIb@joLΰ1$J*kxC`Ŭ< ;bEPSʫa$E^NSC 5 ,{y hZ((WɿC>W@FBh:Ɨv2d/w4=}PP^?rK .DEZa *Q3Aī% Zbswfb3@߸ ]x |~ŝxd7X4b!}c%r0iVx5ٺqS )rzEv&!{*RFíIFuN"QbS&9Ȓd>A1HLރIW'0z (|S*(b! 8^TD:),}׻5g ol0>g ooF Ϗ-Ձgҽy i2+~ ӫEAem*.' 6,,{26}vF}E!oo#)al8V%y|[GSjL~ QLrn_,IMyنs9l"`oOUAoZdzh/ p6n?[rbB .:`JfP;90-CyS Q"~ӯd3uqÔɝ&,&< <=R3ɂU!w ۚ:qXHE,`]d0(%.<T*Ax1OٝASYWB4܇z?賦tXClxBc$Ct?~ydeߠH0g 1o)  ?m)1c3I߭hYdkOC k,N7߽~/$>Ql;=m:α^h.oyö ؗ5Az!Zɹ܉Z[h%""T=4}ho@< 4}ly+_|_ mWPJ64 &hi/ϡX8B\JjAc dwteNf?7Z>lH)9nzUwIG5nٓ603nrߚJ% @r-W(coN0\O ȐG$zK `=s3+iߗ )BF$l}[)4%20zIx1W+/`f MW,_3et$'ɨO\}^gg$<5fH[$ x]Y4EhGqj @:i7 ʹ>?Ԉ99G/wE6dBZH01aA 4Y9WX>3b% B8hE ]x*.V`" zw`WFv]~NN#Bod2$!+ϫG8t `1.Hrc!O˯-xd>۞%{;}mt344c|nit{ђnu.@zrES8?L$hТU0gH VW5t݀󴉺Falv6DWL}guG8uC(xSjn%NVQw-4HuZ;OnjD]F#GReV丞-'<9> gUNMuՏVDߨ,Em Yj[X(7&կ YHw]:sN,gcǽ`9Jc`cU@5 Gɍ֎ .#FzE`e^3 uPVYѺ:v0_n`qel5 4 /Zp U̩,tܯ˙um7M 8 '~i2V[IAlJ R1 |siT dB6?ܡ(P7ShIv+vc9zN[ @j3*09 _dQu2-dxǁ5ޗl'b.=@ldI dS(tt7!ÈcZRd_m[6h GnK9Slxr1I 1#djNv[Wk?Ƞ1q.vPS>]UElQ,Ta}UnB\H{cpxCSj 3zٕZFYy%JEIMle):j0j>_ yR5k5pn.yH!>~JzTJ@1p!` ;fx"rjP}8a%+>"*NH&[A1zM (alBD .mURRu½J5T*:[rϊÄ"'w窙zZ󊇚X8_{ݘ*ZkzyS{ Ѻ/2b/>9 4 KCTv(kxU,L[rkQdSyT智?pNEb3!#=6c( ތ&ǤXu>,,gu@S1-3հztY,5( ܞfEq^\>*fۈWC|J!,* 6Fn?P;#F 0U*HqtX1xލ*ZNCi8z% Kv Uٝ=| [L,6K|A8#:.t(`<Ӈ"0^Z#/[LM@n1h4CY`"BR$-z鎗K"lzA b7p'lXq5Jѱ:SRԔ,ԟC*]{4mJ5w$gԍidg˙$\)mKH(<76!n&v9cox/|. 7.E5({7q+~pܺk#Dn܏RuH^77iWVbyd$sa}+ !f;b\Y}R`c]3U{+T,7s0`)*p D8qtII-,3df*կD@LdK> 6ZWdA'~tȝ2UA4|E ćD^:Qz6]EwDf2°} ۂ<Ľ%k,9a NNH4\îTՙIRQ$d 'wEZEAY_QVVϗT`L¿W7K\6lֿ.=^%E=L'A|ɮbaytR8h#Nm66 YWs|(XAe.7]+ "@ސ붅z̒E>OD vR}h =Y*) ޥSH -=foɴ:X0 H8' q1^n Y?g)=D:_s=Vކj-뗄 7)f!<,Oz,8 Tqő-[4EZEfRiHk -=g^FT`qboiٝ^;DH 6.L(%؊"cxơ0Ft[)s0k O CL'f;卲Nm 0`˾?] a-EJo@ӂ+!G7\f2JӕSCʾ;=or2bvI WurT.82ޙC bL;OY^"3KQ`ijet헑YUcY|G4832<ݢeMC:|5:"xM힋4i}{-VT^i;6;ZLgR8vfRuՅn#myT۴ j4^69x9dU35KU|^Hھ83;TEtp&Z+* &uWՐ1}%/ڛO"y\*HTlBҿQL3V3]xDNIDȵω_E25d|u IT/NmB!M&*Э<=Xl\_4C+X\ p![J ST(–l7ef, Ur&8pBe!q!棿 /֠م /i`;.Yy_ yv4\/xʔ75LT8Љ·R$Htev΍׍e ؟װ~U^:\}JbWtOR:FͱU*w`] g&NWF ^헭mQFSڧHҹ /KVp lJt' stAAatrМICr23mEw YFړr6$,]F^H\RkZf=jJmPf utS6) ɴ[W[,|·݃ ]BNdm.'+b2NJ{8 _mMyg 6"5s2},F0]-,}EWbKx(ꁜW U^)S[ L BuBumL[j)RPy*UםPRS׵3o.j, 4pdt=JB4mLB>0h?Ybey~gowcl[ߨ6 9 j+ o5#탯ny=amZkQM 5eHnЯSٯԨ~$%uL+G.&> !1SJh42iO˰w.zyq S lc@! 0Ytg%A1-Op!z?9{fhҹC" 0ZW[~wwz ˥yԡQvnddfXo,[ě`)$d[4t3J&ڐ*)-(Ic$8z/"2/`K! >1"S-A0q$lPaAe|iso6U!ιXabR"<|H LJ/0d[6+jE,hXL`\Xzf$Aq_“SFLjyhphԟ]EС_5W0`d.e7a8qU98MDH@4<rgĉ䝯K 5B/o0GT L6K! W :3اt!70W?s8†͌#';SCǤ-4mOɨIbBS Fx gia!Sɡ`= oZK?3WaƲIx:u .KjI_q3?Hvf~n}g@~[HŔ~`n^y[ d7*hto,#雵JdR^]qG%k?E h#QhގjF *83^zSA /%{ޙ}t#; K%=mk$N7cP` rȥW 5 59dJ?w2wE~R9lCZG ߏR1BOe0R,pnHZ9:m͡WhsGn6BG}VxVa\wFb1vl+!~lט@r9S' }OvTvRz^(` S/z;e1X{z[qX) /8hFY,`.ڎUOta ^8rnu7`O8,m%_?N<^o(B#X?& -]lo=OJ~XkmqU|uPU-Iǎ3rlʠQ5@ZS (wU*(ۂ+J8wѪ@K$ m{bE|l &0:js"H]Hhp )!2%AFNs@Z wZȤؖ/b~ ;kRV)V7}V%6ȱIe~{F[Qđ [lԽ?it9v0LM"/x cM|gx;T.=)"P-sg}3 #+[ORHTa*2[ ŖqU$m3|huR|yJ;ی_$LVzy؋N`=752 ,I$>]vvl/LRYc㼺&O[FEI3Hj6]`W/N(MW\ەytjzP\fD9yGH{f3R{m.M:Ao;Ӈ\0_Âi?ui=VZeOWf{Tiؖ;閄bzR#KMEhr^pjnD]Fl.nif僊x~_;ޫ,qӗ/gɹfa7bUҁqn24OiZ{*\S`~@EOXO~_s$/33qĎ3+ >{eJw 1*XSKl0ikªYNJ~*"pTbacWTMNY6׭I_(|U\^ Wx:vu(7)g uIFW3XB~3_~;,Br19!cE`>H},< ybMT{\N4x` 4圉zwLW >.*o9\G cQAT'0V*9al^vWc;\ _8x@ӑndL{KuF/UnAi2ɢsu/7U4~ż " jixFq}> Nٗ˵dG~f7CM ^3Jՙ<9Oм[99^'^&t-S& g 0ObUvp7z+9-z` B9) >xV8pj:bv+LB(a`X ƜXְid*0:"_ޝyZ{IZ3_K 56U|Q94u1^)#J3Ciߑ:nMPH %;F<D!7h Vۗ$sؙ,TJ]Ea`ON+ZZ]r-m=C:"\͔Q!~"«c@_Nr6kXjG"R(=,DqUC1og:7u?hw,$!Sz7GǐGKV˶5pXLFcx6л]Hr"E#s1j'9ȇSɫ7ޭ8+#nH á{/HrʓVzb̸tNp=v 45U~/ dW&Y6##0W5:v!L2h8L#Uh5 =#tĴ?~r9|>,zG 0'pE`9~$P0ל I $ikڂ[YU!h@3ɞ!un<!纃 Cڒ2\EY: [ɳl51e0=E a&pT)|ڐ5Wv,V7R p83nsNڶG0jMn\O )|"n3%0y Aj7SOF q/.ہiR:]QGAAI2}:@My}T{g9fDV94%dT1.* wBa`:C"~!7sG5IZ[ F82뤧25΅=A|jyED6VCwY[p4[P8 Izw2 NKxgr4u9j-"˽H=kFU@9~x,R'h;nc^jvD.NXFEX!HMÚ>n5S9dNR )o25⒚fa2+`ăa>/7lg˾Dle<Jx@B&;lX֛v#ȎCfuH 2÷pz̥ןgca <Qy7_[K"e㨯TB4|?xq$@VܝbH6tC]#=hEsuᐛwJAS0Ы@ɳщRp)`%ݣRDFD}0j#Y=H1=1wl.`7fư.L ?X :E7:3ԉ/VuDIQDIީdfқ9YD'ޘTҕ&HI=" QQHO_ Q^>rڪP!u ӉZ?pҨi}H*]EƞIY> c|z)';/i쾄r bLt6unuJk}ii vzae/wWA ٌWi3e- kl¹BL[4u0g,*k8>XkW zag_>IOYweAUC4t\۪It>Va\`m}_9ag?ݭC,~ǤMP;T b')8S36{ @ӦZpˑAhޯ$*7Yf Q~ %0Tz:ƙ$#Rr}_71l<^J+K\iX-Nsq**8v^ŀ{d{CA4\7Wb /.{L$rC*uy/ɶ{Uy\5iuZ4µ`;n%6|rf|]KMV`ǀ, 䍅a7x94 ÍWIuNf[e_ pQc>ɡiTŸk<Ϸ$qfKJAXf(oLEJB8*ཝ*4}>0 yټI 9,zWYi {YHGҦ$.< PG#dގVڣ9a'[?#g0g\mnLޗ~tg pIL s/q])I7],|6"uw3eu=mӽxKʰ)s,zQM8lŠš}3B돠MvI GJ$=8[\bC39(g2pN.s+ igL?Bfc.mf!cˆ8 =5ԉ r%yH^/,Jee3su]+Wp;<}G ”DXT5*B.@\(}2o8u[wLAtC ڹL#=Ki:4R]ue^5\V2f'yXLnP&Vkͤ6Xr[KrY~#=-!S4Ǘ׹@AjYbTl ڢ't^||Кh>y>̱p9@Ħ1 `rΠ:]x̭@5zmG6HeU{t.e3Kf~s%>H>bWq.ؓG~1YC'2 aS,}W҃ڿ߸JVbh4 p3F#W(Փ-ʁg?!PM}۩VE3o*_V>_!PC׾7g<Ч id$M}/9$H- =Utx2~ܩwB ZUR'VD)6-6e;EҀ2E^v$H#Usb1L%Ky05t{q2ػ(Xvbm3OE^_}u E *d+R&("YrAɫ48njxqA9#X;\:8N!o`8tky˼-F +puS-gh?ݏܜ%J@?@ruilj#B  >3Ll/0E2| ~e w^))4Ԝ7$YʜT}r%LP#iv|N;w=cx1<=Br]:TMRP C`/ @M:C!øbi49_!U 0w% X=tnp]@ *fP}WTO1  n}ՑM 2Ո_0SXQ#4_C>d2b"M&8 P+]SN2?rN兪T*i2@Y:l %6R`Azm> CjK "{5>`"؀yT]_>Lv*̦{8H}hGv0*;x>zTI^3B,z:<@ǖr,'`I,2˜p] KdzvCpo 5۲qt >I G&od)JÒ>G[{e^m(6=?L\Y4' \Qh .ڂr@Iu !̟oٖѲ -y+8٭D/7R]\;}H(n x9s n]u w_Ʈ(a"nR؎>&Ԅ tAJ2l+>U6#1vT.YGK8{WQڭ./َ2"n1kCާ^%Hns .ynlsuh hGOq d@t/3?m9%^pHDP{y"(=5}ߤ>Օ)lZG׈еiXN[è0iVsO#H4:e`$Nyڇ)wqK lbiOoa/p.N}XYY4,He]Nǥٔ6R(TqӟƢ=~#,Xr/Lł+[w{%CZӑjƑrzĹe ;5x+S)z^(x`ޛ$~#w]*3}zH+4Y9\ 7I3%4Mr%haҴ`U}2؇iO_*-;lS [ށJ</PKo;C]Ty5+M|H_eǧnﴋT[t- 9VS 28"$*1`n_n;?ZK6o:@*xJ]X,@Pqc uS yb!ڪIb72Q8*N *9j=r&kGRG-$hJ6Шq4+-1\4Q/й%LnMaX~Z(OюkytnnhTNŐb|Pي`fݰi Q7u(0+4(X(oꨛߍ"L%(3e큌Y+hx Wr>C˦ ,tց/%XeY4LH+V+.AeݧoXhcΕ@l rTivm]ד1";oll Rz~cZoķSFX M_tT)͹'[ u%pP)8@9t\6L7~v 75pV3NA{9dDf5 ,[INsF? %"+lJC{FKD5}%Uψq1-}1́+(HĐn -)oQ5jǡEG[ʝ ݋B55RIˆn뻝g.^~>j(v'U."Bfw-wzǤw8v*FVWeO l޷p(V7qG%:0LFc3,'"0Ta8-fQ;ɥ{QaVܞa= GTNm[یzGfSĥLs˜/8WX,CM±6+04c+ F:Nx`׶#P9 Y;-tVl\HPtt c(Qw @0}O_-8DKƔ|ʯЧ!ܲ?_1ǸO7g3ɉ]#77(]MZ2O:cbN: ~NI&6k\8."yd ^-AJ#x^ɉ-탾}ȃU3lb;i?NKXfA/ ֗ȝu6c>,8q/ :"n Ϡ vk?Tˊ Jv^X9ѓ.Ü'A:[ {2#ZZ5P'^}Si&<0_?Of'qKG|wbvU|X\i Ucp^ }(tl0b(>:%Q9_C9{I;cY%A/6&ioFFF3.|>.oǀkLKRv>t4V?pb=%\D-’n5Ѹ%Pu c 9vQ0L+)ijJa=47x]ʶOB<̬z9W.8GI8,.7/lIHz:F1f1'\:No1'ۜeAFgLdصʻML =#K/ ?mXO9d TK0)IQ'9Γ4tzUY+l v-chOʟ 9B'jmm7oh7s#A8l |cbVMM&%>ղ v&FNSH$~2~w{e@ajaKH}>*J.z4R`ώEgP 65 TI8` ǧ~N&Fԟ:(vc#,Qƌ)rYJ-}R40ƐSr] : Mgnqvac{Q`@Eiɯ)]|krંIW9hP%"zVRL(/f~yq ""p@Ez:׭ݏn,彺mg#[Pd#CG"6{\ #r؁x=!= Iъ¸NCOH=U(uDj!CAငpsX:Fct4Ө4BJA'0gI6].%,}zh_vfz]LuJqKp|,޽f eխJ8+ 4غPCrX9o E*Nt#Hp/U|A cG lTX1h!j_L7'n}zmecI1ddSzR[l{m20-e\_._F{G$(E 3 UQu+l"w CuHj.?$z](#xra NzqX11I/`VmZdxhPVR0q[fāk^<\Q [r๖1%KhWtVW!i_dm=zN+ݤA1:k >Ta(O$ &L9ƍllw1)UE*SH))[OB=m]6κ,(41}Z䆾*.t!!wo(O\WxxI&oENzν bptĚӌiNb2 [JSQo~p}rS:M,9Ġ '*!L9YkZS+U,tS9h]]=x, };ݍ\T)FBN@7jN ^aNENa-6awA~H3dd`n0=D~ jen`ޒ;.m]KW2%Y@/g@cg鈶5ƒĆ p:P2v Lh8:w{O[S %Ng_nb1y,xCZڼlzy?SԷbkbrI̅VԪ-eNV!ՆmQ,́?A(ް[0 `9Lߐ~JFuݩYU QEng$XsqLL"\:$o0xU^>eZT5M0GMi2[!7x*;* E7qY!F:"%U D6v|:cpxiCFxU+ P/ zsu'l9'՞Xyf"8(5ЕTIR:vMqVKDZ]PUaiF#{ >7t/*6>ܫ/R 4׏Yљא81V}c R!УeT!~0t>\+o_ g.桤"ce;7 H>ժa`9:;>J˅Z q1<Ŧ; 6̈hHbs`C5ԖIUfߗ2hcqRʌ52yj_?2Y~ IDB$G %Fg_RNW8[èNYe.0T.> gYڏZ!h5 eXGep:AٱN1D تjzad+!i?UKYժSg.E0NyzՃAjzD?؍f)QJJ"/kY\ah126{.8z|OϺQ:!l_,Lh!$o亯wZ\` D2= zQ4=hom~(a'0 Nj4K0YAo6"VƧ`ЉslEp4{GhIYx_OPܑ&]=ЧpVH$y3d/wIMbƭ(LV#o< Jtٕu ׇ;Ef9fO &K04&.u*̬FpHfsYBYi5 j>R|KٓUmNd#wpR`x%c4MW.y+Gey~a~..0kw=࢑?b9xֿ*Zɭ5óhloϬs4 1~{8alزA, Oi'\?{]KA٘SWlS< -e;#\p)݆OPjeoXNeG9c'yXD0 4 kQ>x37|k7-hC[w#QO?}M;GF`_6O5g&38cRl9_M+Ϧ#|sT#+A'ITMN1wv ):á'Ҫ4Iq֍m :8 '54j2{qIll2sU16a!ǘHĽDZEn8, 3ӗb<}YHy:6\rvnx%ES&+yY`zw(o!i*g(G>.zMӹHQKmb:7R=/,#r^#o Hoӛ HI?(4^b/k0Z5AQ_վkil_=3SnQ$1CJ7f+'ops;WZ w j\?%a[!딷7TxF7R \DIH aZ̋<4ͼ_듘tLRQ*aދܭ|=ձVgzM͜,DB)R~^@p?S%X+)EP HKi;a}Pцe*@Ba~- ʦ9U*\kFs m9ӣvC'wJ*=QK R-X=zqidCVȮC1e|Q^|eH!Ou[Ꙡ`x={ ݔ"l~:i *#;>Qgj. BþP{Bh\W{t)tM2>! 8Y&B-uxQcsΠO@tS"WA}Ljs)#ed^R@F~_+.|ad;`Q3 T`Ϻ}Rkݢ`8Mwp|ǸD٘Ub[!A>#X*5dD 82?D:TNRc PI3=^ Nc_4ec[K2@V1sVv뺆ZQ BIM6 p"$z%jtdj ]ݓ' <\o/|=qVT\ =p8 wJ "eNo٨\Xf@-A+֖y}ڸܜ"o9**q!PKd0QsL`LEYA= X_hɠ9HB+k 5ħ3˙7i!Il &BHWwo{$xu4kF՚ Lb}qAy썛\#*y^!Sd{6aIiݜn5ۀja|IV`<\g_d|/^ȭӿOjT1R z^ 9˜LBQbz{$@a<7;C֭[R[`V˹ My%gq _0&R~/jcaO8?c7&Q :!՚BN e}i  8"7,ƻQ{Us/ &wv1m( \PQt̗-bY1td }E:ZcY #q$&Nhq_J1[Dx~*h0iP=Qf]<~X'㱱/OTvkNX!3C([Ia~QG0"J'yCouI% .m YUSZZLM}gdlFNZvX7Ioo4_4Jt 1ŠE:"5!E)Ol=#>Mœ8:J;R} z6sAdShn_Jpu%/vG1ZaPj(cD/dk2%C(?MBnWfSd[mvoQ_֔g?Zqeb(2AZ}>BjN BiNt eMve*jxf0xw\q1NC 50h}A=\ȥ=(~O/fz?YD Kt5_wlf>H cmZ_V\msP{,) _K.<QAA~͡_D?BQ(Gͅ9m "Oz֫rwFе%\!f\ 9>Kն'yfD{<|Y:%G(p㊑p`i&״:t[O4mu OKִ?"F2thiiY=;Cf佪4|1ע4_gAGErk?X-ĵ|n,%q;eնt1P_Ҏ2)AEfLJ|p&#Cn}77չ;H6Ff` 8NwEwsnE ΂XNX {zGP:C^?e-2JⷆqPYt!]uXl,c봬M|T=X-$"W^/H-tn7Ԓ+." Y١ϯ؛'-,0Fڪ[8j uξ |4|b D]1ߔ8[en'[ 'Fq/|lbצ>&[k l$:NO[=ԫ1[ XWNen_rQYs6 ?351D+B&?=.S>ufs @ ie44D|z"sEZ3R@x8iu^E&ADiRRc=AVt{:mۯU//"FyℷYJ'9\(ڮ꥿& 14N%R^}0cAz_K!u }(7a@o˅M^vyUsy̒jwnY*M B) #gX<&Yۇۖh $-aKIRUby߭"#E&NL-nXS#ĄL!~ٺ Q l1LR + FA)pJ j"e(,ݧ}F9 7AlT\*hiz^K8;<7Gy `!PNro:qR;9X%ڟcQrdϟ`:>d[ao~:]\'b;C)BSd-yaȒ;lt/EXUDZ`F$~ 'm/kɅ'0 kr2Rb{ggoc_FJuTql%UIžeޭnG饂=ϧy<'/󈝐mfז &dN ɢ(ĕ U7%;r8=GY)Xx*ɺ6l(6i&})aQ=}MԨ Ĭ }-O*T((؟gB>?XeD!xƵ$g˯bk ",덛D4(|t<YbyM WRlFsn]CDXO绤}VN۳ڨqst͎4PNvQwtSi>W "EƛyZC1(s*̘% PE^ /˲&S{z+W_] ژ,9PfnLh kP뱋L Rւ|%׫w*)ءB] ɲ1*VtBmR-[N >¯[#N gZ p/=8ZQTJA=8 wQq J)PPd^ (5Gg=2&ࠬq[wBߥ] FC"P&=Bތ0o؃=;w߁VzC%Tulq6vE;qjfp3ԍC:Bm%MαcAuӻBA9E5f3 `^nxb;GP1Y$Iq .| ֕,B5O$N͹aGwuub5&7URj`^||H8p\Z/40mN Ҷ\ZC\ Hys"l5/T|;`D72T:pO%VںFeGwý'%&fWgɍލ[eI#/X [ګg(~٦6%4.y_\,`V$6akv7vyn5nۚ8gl u0cd(hJV  /AOqd}IEk=@)5^{MC͹_f.Hu'ʓ$D垅ߖdi-w+N!nٓѰ0=Uƚ#5qEQV{ z^4'UA[C:P_}AY3*aվsSG_qVIxo8|g97$b؄tA'hwB}4Bc1h|ctibvtC3CdQQ.d7t`bNsA6MBxņ&n楖/)SI"`ء9c}D:)ۑڎ(Ю9RTAx=9i¿ Iǯ i}<(zj5Y1d0HͶQ- p96Đ^2P-ڙ|GH DXӋF@2y0E12|*ÇLaMd P,̔w6Ƨc.ya7 MښrJ'n'<ҧ;'&p[m]/]>ຮpWm` tϘd$5>> Ri=szUbIRÎ`J(Dj)x16% U6Ke=!2gsbv)x?]ՃP7CJsq3!*0Z#x',{[קLM!Է#"]u!PnJ^7ŞAYx bf/BGkz6' d֙@E @v( Bj"_E].'/} fMt w'4S"| m<n.ꠠ|-_w2l3҆8: YFa?Cvj6{"_lM5~ |^{ev%2*h`^ pJ` MP8T;RMV˒,tЍe~ИӧfH5k$- ݋51:c$oT,Ae6:P|\3/FI :nY Aߣ_#x gq柽݊RE6ON䀂:N a}/!I5' <h.J½ĝPfޕQocP T%l,XXG偨U>x`WQbR@ ::cA)=C 63/=>/׍z2 wBװ'Ʀ.T w|0P&(Q˙Uƃ8HRl?aߗ;f `_|zfcP2+77X,;MИ57x1 1,lEhrlWȄ>]6y^fhGG@J$URL߃G6 <ǦEZN\2СW-juUo^S-9|~Ar^@#CvZhEw|ID?4nsB\8PT c lze>m w+XQ4Cv+n-:wArcGQ6mHD˧yv&# 0ZY&.i}P"d#n?i]2P!֎H$(ZM˄8pl$df@ (:(Aֻw.lcACWrv4Py,L~ !irON<;f" ,kaOh\eggy8G%9MC$0d5CcBmM48n~fI Wc۳KFAyB_i2kP!E1j sFufBY)Grp0Gg9'}Zdk\S &vբ!W 5C: Fxg%~}v0 OkD ?y u_4*n8l$s KY,RQnSV/*  M'+ZwV>o{Fl>qy3ֈ]"'F<Q>h73XyK#ծK#[w̢ kWRB ;D ɸ[+/e€X8' ȇg-#a5NuˆD8A4Nx/p= PQ٦ʚ:`ZyQܪ$#F9Ré%IjZ2\Q StIcTŀ8lo!#Rt+YYK H,4"*1\Q=me¶ jDm@=p }?.K@[RL9$ 0>ˬs adGKLQU>\lsp6 tLeT&֦1%\<;dhrZ1x@TR 6zvY[,0p~%||8:4MN=u .15!"HӃ#VKW!%pLf>W>a#M*D mX-&P('/ Wn޴#:YE1R/qL(J+(f2T/ۨ--`G/'ꒅI 9~{ey{JζCǽZyOw8_ǞL"|yxdpGmh%产WpK6#$Z2A;ڱ.&l b"ߐŚ-9Yw=pl~z#%u Q:e1u澭Q>oWEq|liLy{c%X0.uڧ }FmE\3FB;x]npdmOy5!^:V9J>4DӰS2Oi&8ArjB>g%#عU7)rgjkL)ND ղH)ظ5yL6^^[^iHENye<1TY\/P}mDjSeK"ϴErp]}} yT`OTtӺ\fkDuw){M^Wus)-)Fn,ݺFsА=HYZi &Qҹ[=Rʎ|hk%yIS8"{"GF Cϵ4n0 w nD$SC-I 33@XV gX YR4Uɉo `?zlERZ]϶Iǯ:9HWGsM lM;DHW6Hc}[V^1s5wDMn,D')P軍o=Xn r}Aˬ%UV/ E N}D;F|\4-7 {3@; x-QԶB?ΛK>`gv^qܫAeydbYg8,R@kr5fML:JfNP@gY,jwi_{yUdӭ=pMW|fjr6b'붃ߌEi.K֐h<,Ll<uOw,ﯟZ!NJ^ ~EI4I6v_1O A,?ON9 #T/+=mE z`me|wEr39+ܯC &~Ex*GRZG(:)}(yT||?pBUЈ8VKJ-5>=SpSɜnI5^x$"IԖ^T&ay돸@ZV| =㊓u1޴`zR{+ Q_`5>/Bh2kbg\2V'޶lM D'-=̂RI.vZIC:X,Hi=V,gA7R!ۜ(qFǷ..OG_9Q1e[`e {/%quXgB!M?qBySÕV(S`e d%'U\<_cF1At`QҀD~(jN£;)Qe8};!V&UsHT9Ax)- qSҪ4wp7oCf/+ƣUw5XnGV!`\trQ"7eRTQ퍤~mE-P;%]?nc$i$~(*.FZ4=TOU vwq -Ӷ^2Ҥ}^5BhW{QɨxV, r=7(斮Wsos 8v=#s>=(p$`\|2%Z!Ζ3wU7&%3i87t;? 6xZf\͞L3˾Eըy(4Si <0hra>uLHHgd*deu6~ L܆$ʕn#RQ&v,@$?6sFSNBK>,KMW+hDJHwh zO>lt+$^e r'؋W dC|ot$HGwGxрY2PIY{U@G4 D*`b$_&f`YL֑&2Å㿆{MTߋQ\-z\Y{ 3#ɽFX35HvȟB "77䀱TUCSf?f9Z4ҧ koc:SȵЃF*6cs.[X3IK\Vk::~?׼v HF@bя]|b?6BbG!%N"SR%GT-/Ϧbٮ6ݎCi;CJrQ׾s T{Mz[ I=p&*I$ YM⓷9ɒQ8iɣR0_3WIV‹;Rшp <, FS!g|h+/, bCF|T3TUq7F%Y9{H |-Uv<;nR624 3dplw}'lrGR!)آIW>IrDbqUHEL ;*kKhp+ fP8Zbޓ,@,e쐗eYcDpGdd%>\O5r)` ÿF"u]@5S<42>1A0X1A6hD#}g='XY7}LOʡg1!׃v*8{3OJHj /msZibzŴϖͺx^ B6BGX&|& +E[G ( b~&òsV gdc˄*#8I8 B< pSa|*u h:G ~91m)1?b_}oPR_onUnM{H })83\uKO8Ę 62H[ V3[;ŏ7#LGc W+~~/@$k[gz} 'Z1oO_^yׯ[  ba\Q=u" =5!:^WeRMfd$+:oN$J=]-;VyBEᯣ9:9h)sHc_A?'_ _XV.X<5jmtLDE&:\]f !BCNa灾MױP$uG[lP55# r!w Q,~?ZnrNfU]%Z5e0Z#[Gϝ|0vpAKsFm7?P8\6 ʟ_J D ިHĬeP~`0l=m1X˜F NEDigQD$~AqBؼ.?X:{P$58ɐHL)=JxK^D~,U7ҲQDmj Y~\izs2Dvy_Rf Kxě񚣮`iF˯Ғ]pj20n* #F+ o;nޱ;/.sT_ZUW3b_ğ0!奆fm_#R ^ViBJ?ǂ˂h*M*zNK$7ƫp=aIb7G r {pd- {i1z4& UcD R9 ^|IF3nvR|}ow)M˻*tH9erp'4^;8+U+@b123st(k7IrBWpJGuH*cG1FK׭ ٲxz5s~Qn/tȰ7]nACj?t.Ж@_>Ti(#!|Pz;ģ &"_SΝ~$GOj/ppN*w\fW vOD"f<5 o)U C6 Q^~lguF_Z9jۀ#Knzp&<]v~nh2.{Y!oB)}D&@bϐ4/w?VBI,"ݶYu d.Hr >yzldyMs RY k&$|NkZ9SQ:q'Ԑ}2H3iX]E4 e8G:w FU76#`9UyP3`;Jvf ß>Bi%45Dp{D'N|XUeSU$"X=vԿ Xs󟩶`*۫>9Po!`_2hC4SNeoLU> `w x q`Y-:ܙ yg2^OϖzJlyt9|؞igo> 8]eJ[;𲌔Ő4=h4ubS>|I>(yRA䆿_&o&I=FsSDgGNr"<6Dv܊kL\iŝ%`Ư#Z'OU}T|Sϰ\TݺYFBǚ,a$nϓVW_dBgJV i]y/!T Tޗ#Z̥8F#^s$LVpT7x~4x:7ϣOlg=m̺nPw}cTjAndxId0;j-Ef"dR5ѐd+`X;Y(۳d!mjȿ_DNa.EeDmҳdLܾr`ƑgFZ- IJ5]pH7iL>];isD1~uYlG㝸{^a[Gy{ t/Ep ԑ\|\?dHҞz=[>^w% tt!hܡ\/F+;ϸLݖ$=Xo=́䱂RATKx#[t'Ү.ljtNbMzN-,tZõU bw2E^=T@"CG*Y|CPP^&szɍT9u.%GaQkd )58T 6Rgl 3v+f 7`|sOІB9lZYɪj;Tkic1hr m(?V扢7 s./  &f|W'ӹ7xВ[2KXdF,6gS1 CF̬X1dR֕TfB?>LF8"|Y9P/ՙRdW{ʢl %\XbZ7bSVv֓\nFR؉p9Ρ=8*IWDp}yİSAhV4v\%s1&9aLi"^0?4ѳWbpN8agOz$+ԗ9^84E5TX_MYQ9vyT"H vp؈R!`aBU߲hF FC~T[åPZpw:_CeY7C . UzBzvV2F꓅^1Z Kx`mX/ H;̺-bO[KτN#!%̧gNb6}/姳tb>͋f_q1WuSK躁  -/cן\w%y~pohUߨm6#I8d{`Eփջə`m [WS5mu+=Y!п韨\N(%=&V|;=1̨ Fü0S!* zߤħXLoQy> QJ2pLiȕ2D[)˽. J 1q ԤEX}O^'2)gͼP\kMG k\-,9:rGB J)<kpJyךodԻ6=:B&!/.'F(kJ1ցƉYcl&G,Nn d]Exs0#C%e9V: qںcȧ;`.EN::ԧҽ8: WX<9+Rn8 {H]":Tq0 n(}?}74jؠOe DOٚ#GO7c->yKz3LDgdK&4cI.Lyrn%y!gshk51ME 'sg`)D1& n<9QtfSyh}pjk"yx< Pxhd>25_W1لiϊ0όH+0}?WqkE_5ǿnjs,sCY\99@].sբtmM˻LX$X~vX{]s=iBcT]_ۀN}+[YH (i|ZcBͻ]mR |UzY#'/^ "1큿(۞ t3`V%ZH3ll詡;Mހq,7PK䇰k`(5MK >0jy# 7]%DGPS?PQIn#U iҘJ?Ӵ| ^sOA%n-]In֮u?~I&Z;W3 TR~M H2-Y+Eݶ.Y}t*.1Nz'=W~ChdG8.d }}n'IllUuIjYv߳N/ોuT4V#,|&ŞOsj-Z8WT c4|O5-%8-K*cUF/F) j(Iy1*\8Ydl>%$*+"c5gnYZ}HnֆnnZE\*S{HѷpOzg2I;'[(p&cM\D V,V[G]CWfVL7~Q vƘ{! ~XWɜ?ۍw.ǫ!=Ҩg&*rq'\L*!&5 $"*"zوr; |JiE_xpP&q길fBtOǹd~q(;5O0آwWr3u f[E0oqGjj`,My<xԁ;wt-S#Kdޟ Q-(<5RjHa^m$L9r9{|rWo Ꝟ`\>ԹyfXPvm5 Ud\)N7=9$<7SRRF6pFH< GFDqF]L L0@rZ"63F4a:*|_  &)2~3͚L-,h˔о64A9%xZS1i_}6JC3 PJ#Y.ۭdt~LW;2!ΌTSܵoQKW{pDbWip F)hZ/RD|:zz؏KuB@:ߎ4)D1܃İ nU40I f $vW-u((>'6[}Z x1 ^eU\o\Ftk˅Ϳy;Nzt}ȁk[IpBLc^ хh:FcOp=I=tO4ILs@33I; `suO „/pkG>P9" J\|VoxK!JkE.ej"ϨsAM:3ӣ¹>yC@SS67%Cp0aˬ_^mH"&!lPİJnAȪ0^)+_,*)Qzkɸ1:QG(_pM%ɣboXW,<`dwz}A a%~+w!7.EP;?1RC'/"}yokyUVZZtGYi]4=#%n E~;do>`UHnȢˎoFˠ`EEB3~j,NRoq5\yKkxR!؃ל_=D/ |Nƾ8Z'a^4~ЪӏrwbR[хƹ#b@ׁ^+x&[@zU* VE0(&[vTu*SP{z9Xn[ɍ[ T4'T2)9r Hl, #~u<#.ga9`i5v3cBZrzB1(>%9P(,6}Jd$#9qq^1q+1,ӶZES@R*em*P ^T.0Fgs.co4d*7Ap陕9@ `3z]Ri&6dC86ᒈ,t1\džes%Mr''䘃.= VТe/r,R&1jp u{6,GBݎ_ /z2 Vc̒..Ɍ)$Z`[2z6B`x;_ϕvpf0/(PDubւߤTn55ٲغB97@{9Ώme%ɥeXy)REd5?(w9d6RYg`>p@¯&LH֝D89.x-cvԥϹzA_IC+ra'>șmk1)wW1!\+k&©!4Q%Z6mudW Io[;tDxX.#@ '"-vlzZb#+/<4qJ) =Ub#P]*N3n2Fؒlw&!wX;.[E{Mn20wd'W9ֹ:RǎBmi=;jPsFYp̦{z]uFhVU`1';ncM ,pA ͌P_ (n|ľŌN^"JSOĭDfQ#9ok?zݝC1Pz7/ Jt%;ԡ2O8ڙ&l1|He8yb!P TQZ o2}K"RHWWAa?lM-[,T\_;1h~Osc78>+j(ug]`p,7:lQWބ/P uSc=8,wyf+` 6c@ 1 Kb6hcthK kdq'߲8sFmNBS \Aŗ7dMvlB f1ܒ1{ڇ#r쑩+7тj8ͩ{0?ϸK&zT4Ayir P&!d_nFR`j~\YRIwCoކ >t-:Ęw cڂn`AP]ʶ";ОiBQd231~ߙM5~2c*wzDhu|yГI`Er5MS)$7| VxK<& laR(:S/6Ř~?-:ϨU€54MEJH^^ SHZEbJMZ! UfdQOxH {[M#yTn}TS -HW%-ee ə6 4og/؄a/`]r C{߈/8Bf_s9+޸MIcOv\SL.3H(hCi`se~~I\8Rj>Aܷ:,F5ii{C'?褝k# (RՁ7+ *PjsXؓ5˾CxCuo_!6&:F ~ciMW}^@cETG,i!ڦQ!3,| uZ8 GG'.lZ  ڜ3}sxa™{<x.wɦk᫒`C|WW 50Q@N,Hsn~D$jl='= $x!z|8–S /P( )9V,V74r+$][tFį%lN>_~H XEU$[~)c,}yƹi?cJP]8.#|l)nA U}-}b<_ABCys,k,!9?P%>Ƥ8YL߃sFG ?sK]r۽D{?;9 6',{r* M;5tKxyTvŰ{rx= V;]5]p ?266bdEߡhN$(`-VmX ghc@وݍ((z71EHzdS # .z~0tYdq]7uBޜ*r&\S/5=+u 25ћ[3 E.4? 1JG1V%į;9m6D".Eʃr l(ZYEj!pF!FjCf3^3}K /H &2 QGa75D?7io5A XA#WΣt@Z6r48p1`B#xt&;)Br*cSNWFcaiM<֪F"qR\ug؅9̤M¸ݿRq<0.:)` ӏޞHO RH۰V6sSp u=n!J6X-1>;: ^5 rkAbRȾLp~,rKSg׸C`^Mgƞ(W/8.V2F!n,p(_h\v*%ΐ^moa&4A:u`%i;r}Bp̈́z+;|_Fx|?ݮ$Le6[LDܣ v%k"řW5ߘۧv`.v_,ҔDmR[;v=}CDtUy~߸CnJo<*gA!;/rҝ mBNf,;lGj($ aM|ӷp8Vv' 3z3NCq#s32 7 EZ5m&#T{S`i h 5O@2I0ҩYGKPWLU&zf& 315`WЙd@ STPQU][)ďzȄ_.dZLHGBІѯγyΨaCJr4pOa4+%tGWmZØh F >qη`-7>Iж@)qHpL:LE%>+\]S\rx )u+s;JpbIAJR>r:FԖwS`!]}W{mG:@|H.3MwsyżW/ĽtxCxPB:_=w`A*ARpAh@KM{)ܼu 523l]kXՊkP](5L@ޢMSC'4)~炫=ʷ5q< w^il$v⾔1إ'⽄#VNi?\14{:3 ۹ߌ:I:)jeѡ-WLc%1/qgh0ZMɟxVhDܣ4$Fw6*BpO7"#djM22ݶ@L{H*ĭ>Տ>R#cˣ <‡?TE鳬RMY{6 39!%b19s:((}RD{e5_#Zp(+Q6Q{NL`-udipdX+DIjY08J*Pgvֻ$-M?3ފ|`3¶[HK𧭣 {0T J\Z*{_ - >Q Bzu{Ff ռ`8 Z:;)`u\%J2Zx9v#w_c罋M ֏1iĕF eb"306OѯtVY)z8Q [x?M؜3얬*hr+ nBVp!ɉFLL(ẖXs Mk`cDC6TH[4snglWd]5B$H Qو%BR{cvy[k}~s-iZZ -{ =1 =d>ts`Ksy ZD+D< Rym5ESP)1#RO7t%[&H΁[UI[U;fS|IKWI/2 Ǐٙ=POKDDsx3ϱ+%l8e \ X[r$l-YbS$lA#KߤFGsMZkMIBUl PéXaѲxꯆPb:PŃ`#Qꬼw ll륇Li=uv/vL-/?qD*/.^ |1h}.-gM2l(=% ܫv>#@c'b*4u" 翑:.B$#K.th\#u1*4Mz̧4vk &_բϕf~n1qVm |ecSjg?`Oo-W3Gù4z|/IL0Vo}b4ٯ-?Chϡ|r|)V`AV(K cQ)dqZo*Q3" 쇐@PwdD1J9BuαzXdFSl.F)m|mRÈ%P|לᑵVm# WTztoxr0e4yV ր^FAE IwBg4Da }+V>rMgbM-w75#?|F퍻te't<ʖ9n?\/( Ӯa_Or=wv,}Dgn(آ\`59H[a1WowE4hS*M/f3~g~ssʇb1M` >GT{ޝDg(m,FM[K\f!W⋌Qc+",DRB΋ig/yc\0d.Fk >a:PL/M)Y;[a:S ɡ;Ab.2s#ʠcg y[/tGeP)'ϐ-+" u6.[UuDz;3יTFݷN?SH(3b O$@]Dx^3QjxŃloQ ]8s] $`eBaIj˿س t YAk`Iچg#j1k%v`dI+)nr`c16o3E&>1#:]D9bw,Ȩy25DJF<0M kׁ C /Pe}ݔI+/XI=uIU4R#G}os)ЊvB'Rm` [ŷuk?;؇? Ȅn4}#\OXg`^~B s9t#Lsxo๣("n˃0 q^&؁D~v4:Nz6lyE[~ܨ+_\#tet&2ĕ4Wn0f $Ӻތ̔&Yt$#t=oae)X?w`i4[,].y{fWv^‚!Y'Mj(QjyPdǣ#S$ޘTEZ -{F^e{{*bm;[~(hT1Y>L)_ Qn٩9M9BZ1.Q鼛X%gX"wO I9H9n֬B?U_TsxɹhjQ^e9CDؽ37ҿ!:%D14,RRT-Z=~6)b7 H$^h>(A-O jnK)S}&1!.}}x!pc0k'goQ¼AbUGC^XM](N}PTћ}΃6dB-Sޫ /98o8^a*Z د2FiQV^Qƿ[r?P=kw?h-®^rJ~+QvvwMB]Z l0v~q낎6/EL 6~NnwqdָN9U`u.5 ^ ߓy{x(asq^AN@AU(I:YͶׇ0bC:Wbm[.Kz)Rܭr E>E9zYSd4QPZ>iK[:&U'?ec +BAJNQP{86W!~m킱~V S0,'y B{+6(!0)A;7O׷< S%?o|ŨEC+qr"ƒMSo̫RP)|0K4n[.^]$ }[0Ms @:g0Nj@k螗}+|Npwa*٠+A$LR-֪/ "˒ʚb\ߛ.8 ɉsMwxVgjEz2ߟ}{2d3|"xv9瞨lӫH jԑZ7q8a'?}<;&~T=pzĨd%;VoWa6WXSYX$\CL %~hd-Cc(: jЉ n,*h6-& kBIc Ԩ :w+#~/Sʊ}3K@ɮt/؈$⬯xfoj}GH F 68ZlCł6j 7)[Z(/H jPr@`}jV;{#"nO X8Qmԉo(6(u_IF#NZom7b 1mm|VQr؂- `%qT}*yC]OU'{$ݹ}fO/VZͩYLyz$i ?@Od8@kDmc%2|Fr;gw3ԸX{@| ;0 /֞h3駔e5>LWՏ7IYGO[znds sTq`oy,\um#XyYRCCI+Tf#eOjtfP:!'844|C.}pX%dQ3(aK03Z0*M ;06d1;4 ż C?E@CXAu>#rk'y<@[7DBDSMW "rbgpzy]t8?;P0dz{ly\L{'KችK<0_a튟,G%>;[7k_WD0RSEjdm$P/4=}zئAd h!@0a vQ3u2 e6X-`aZEԍ<{ Jzdbfuu<Ԣ.6iB7gijp.֨=x`*Pk3,qk߱cC%oWlvn<>9LOCQqrO^pq[4Bgۖig-qpni@`KN"5 2h}v*?X{DfD[ZDJ>$ǿ5+j6uJI 7JF?"xF^%\ iK!`:d٠?eOY e)4 Oq*2:6Gu<v|)Ѫr5PkCT/`f덧$WO{HbukZ~1 7k*\v#O;ON;4 G945O-K0:!`OSՊ$dzF]0yב+Lh"GTt5b}ul M~"Ǝ-!HεYr 98#N]KE|/'*=Y_f1R~K7kKͻ&"iG7LI$CGfm`PVtsW'eO:S?\H^u\a&z6$A0 NA”^TרXn\K>'6 jMTn)@S = |qb6ݗ| Sۙ-? %0~p (n -Ԙ%hWlt?G38߶BCF]C|I{)o(~@,jv^;qu$AGYDr`A|Ҟ>|4t~͠A#'b_>紱/ON 8ƪ][7,ouw[[` z)Oh>Y=  p۞a[I|zc.%0t{/Šl|gaHs@S0]-ې`v4Y8ɽ5ZckX'fˉyx1`KF$ZՁ;7A9 p N3>4٘6@If֮`HПk(&h⍮ngH ˎLƒz#dc`&O(i~vqX'&bO[„j5ԆnG*HLf2%{=eQ]H#pKUmԮ Shnk4|/?.✒PR QZѩAsb\UO.Tw2ۉ36F$Aوhk'QgAMOU5sfb^Y_:ʅ@nUMGdI+O p{CٵP2>XוGtwLD9@4c}cM$`[&NlC@@% *%ۭHicI{TxFC< Xv */|~s :\_@^Mo(1X|!2EҟG$kGFL@&ҼWu& eDt!_ПGW9at-)4I%RȤ RAz[d`7gPӷ}w8=DIXkVIM. 6=me7\kwIRNs+>v2}pYڴ/DeI' m!Њ@R2KSRÉ߮05u5᪣u}*8jX1ݯǐt@8ޓ꼠߻9`l&s%%N_Fx8S{#\_^G\+̛Jl {zOɰXC .ۉ0kg0Kc:oD#~VB4M˱^~gm\;%{ϐ^+ >^scFʺZH8M;d@_jy(]8 bo,Gӎ Yr}).ƜpdQW[92 F]/(e|Goe39Xo 9t_ڲE¹(7ʾSi7d&czn_WͬseNչ~JB0f) e)KA v΃ t1{nGmewЛ2X@1 XxiLO! Ǫ{YkU2'%+w=7=FA UG,f%EBlm&e)tL onygD!;S$UY$#i.ِOA2nu߄p$+xz| n.*qAI̽EK" {p'K {en`/Bs+w*)7O(ݮt^ I3HdÎI1D,3ir9w/k6DЀ"$k*#*d+WN`ιLA6ao͆qG!:&.u#cnhcxDA~MȢo{veʅ@"y3ϣU&SQ 7+JL͍H"Bߢ,㦯LW@h_CCԛTUĵy}D4^_Q3Ubx"޳˂Ye}=Mн6 啚~M^UGM![9U Fv }=nQziũa䢉4"}fg;H{H WӼXk(z|HMom:53d QHOzOg'A TtP觉~Pڑu+>Sܝ>> Ҏ>$t0!o+p~Y tJoUjO#| ͱ(İ@[ iID]ir +ާX֦9;Շ5#;/+]kTH<䞾V*7Łx^*0{55յ5卬G4GTPH}UN5L]u\#g? Kȫml5Z$NtNgI_J2 CSZ~R:5쨽 ?ez~kH֠6hg`QwK=rv-D 1yT-[\c"$0egAX%r;sH v*sVxZEMƼ5Ib Do?CewQgQxE_p Ga+usk gH$^Z?!u.SBaWٱM3EXUjsҚyF#Ն#+߇34]*w .=kG@UEƫ*8g:SY|B8k wZ.P$)^BYGXz5&W%z~rnnF7^kp.IVSO~AKKjGDWK\B6eZQddL04$}a+SɆ}Is0hØ]V!~t fOb< .%Ñ$fm␌kC/fD/#T.qTr&ܘ| ǿ$Eto7b{#ū( eєZ ͕nUC[޷hHDiwK#ދussů-1fw#w ɔJp6^<`tr8})SaZ9(pϩ6;|þ"E';eq%@CI"TJ9:seіjSCQs&:]"5CA%z|*Au+' .tV[BfD DN8ף^ +4~s'jj## 2Ӏ[o\"q}HKw 4@',:A_^HtZ8L6k^aQFR6]ޣJeQ-Dvn(U]T]}αzD Iջ{b0,)UfR%ZD"}z@#HNhv`ݯ],|gV[cK\=qah%ƨ;GE6pUdN{_JގRJֻ;ãޥl «4b$ SsjƎA}O$R }=@πm4@qY=H;<YPP6m^s2Χ}\Br"ׅ ?Ls+rw(`1L\O!L6%; 26\˪[zٙp^83i&`T~T4ZA 蟁J6' 3` hC}tȷ]'h \: Qmցe@\;`G2N;EX1aߺx U\K[ady4A!Ȣ~r N\Lf“BeY?*i.V b<*AYlN3R)h4ݸd.SKC8_uơ|wpJ7k`+9OKXʯP2EE ߌy0P;"nc#"sԪxDAZcT3ߣL<18 ;$Xe@(dPlJUB!q%m-\8E;'{ym gD#y+uO ÇkVbE׷yˬjߝulf\`;QZ]Uzoy]G)-0@Ɣ.%HwRY?CDX{t@CE} ‘D!]9TѠ"oxؖDSe"P'3pvK}9}O=`LvLL\-Y{l"DMG&dL2[g߸nqIZtyՑ#p'lխɬrD'B:J5`P36ل2?@S[߄@T}+T4H2mC&9{~-Y@uā |)?Ivq}Q> oEPbTM>?e Y馊Uml&bAUMY zʺc|I=%c&Ωb}626|,#soZý&M,uDhm,+Ez&(I%:(Rwx؅+Iw:k}^\ԍ;iQII;{>vuƁe'iHt`( /R`.OCL˪x6~)է_]h{˴ƑASCA#z"i4#畽]1EĔQhjrs֯&;/0NU9;g0TuS|֝Xky ",Lpcq=^f>ssNғUK1ͱgζ̙m)f$mwuKM|xynZ:O[x"&_ܪAN5&ڕU ˆΒNo9jFs4b 8| $IiYW" ^GcZPz=t3=74WR3@ Ej{e7HB8}0 GxlRFz~(hvYɐfDk7h4wg3i#/u& 3X`Y*h|W,E`y'+nā`#Z1fv޼~ ygǟ]ﲖ?^d>:'nRيyDJri0>'{4cǃ}ZW, ;pҪ*h"ýa#pҁ_&,zk@5[a.oR~5-.# 4?;Q)Ss]hjW}4a6Z$ BKwpixjʋ% g6ޗQ^_Ü:8~3?巭G {rJO]W JR<)]; t-%eWh?D-ab8/:᠂#MD ՞mJ372 3 o돱ھ&5[)P K &NJ(7.ƥIOGAU6K$BĆԕ8D3duBٺj86/8@&'.|!vI0g{ĿY˳+DX^@M 9ߪKyE/ LԷ3#LBhBZ=;bF8U |t*'K?A$ѢlisLR""$~fݎu9aGJ\QdiUFq2ȗa˾{rQݮ˽~P:kXzYmvbu5hm.  $Aegq)EFԵELYo&a9Ϣ!3ڱPTam*c\Q@ Դi17e^h_mۿ6FI^o+@k\txmD2V:|RCrͦˤbPu, [^oZ+$z4ԷWc\̆UE H0C(hK7\([+,>?hsv|c0gԻIBM_`bӕyѶ'<6S\6u`n|~  _]FR !>8iw\˦5rzл&('Sի߃ Yv?o#9pm)z" w^?&rPe J:;.XӴhvIPB36!&vl+\Kމf_񡟺ZmTA":7c~QҷT`+YkS^Xe:Ch +E5';4ƺzQ۵ߵL /ʄ a$h"ܡ/x!򯶃Z RA|r )W\z7DB # ϳyb쇖.tkMY+,7ʭWz 5e+LÄsĜu!K-o_=|}H/muyA|~i.7Ԡ[q~˿>LD\}*GK.|4d(}<+MyG]h2buĜ"JnGN162u˒U?S3YVeؑɽmA/64Sx!霥;slDKDv>W\%'*2K;W6Uyy&"c #KIf;3qӓ&4 WRj`OQD?geXcLؔ HyKo*bs=x(2}hw%*2^]'S0%z34zX>_ 7 (9ja-FL"`W#)#喤~߮ U-UCPkV齚ȟc(i!ˤ,:tl꙲F##*0j+'a]qIQ4 f ƟYh! =Q םjv7Z(v|bXIWxr[-݁&9$k, Ͷ?yIy@yH+,}7%" DmJMz] M^#BFAB4s|* Fqj:bG4(76Xy'3 YyiA[[4~=$XP!@_ >tX@©]$JNN%A _ d$B|Vl`LL-L9npʗq4FGŴ*0xgr":B2G\֑b?QB<9HaxS=]o4;ٖHܐ^dG-f#Fn*=}ps֧w^4!m4erX7VJcUצx$Ez=@OTEZzZ8AWt+ 8C髉cIĕ qNnv&l9Vs:B,M# JPvΟŭPyh?/La|ᘝ5MG;c$gNލ+ȢuM%a80ڿڑ`K.V hЙQ׾Tf#7S%{cnƗWK_6/['}trR $roǔ|#M'k֨)x$ !xLʼk>U ɳ/al,giU PM $j '/݇R0 \!Vgu>|8}D Jtzm)cT=~bVָTYX^Dj[[?1XepG^Qa$V2ty+Z9_@ߔA@> _ ܔAe'ĸip]sǣT~ǐ焺 \,]hN.C*/vCaK5˭^ ;{=ͧ58w8#0!8 8\-li2PYǠŗ?h"ۜ#^KO߿YSHGBSWI6}{@}A<{)S-W^Mܛ3wq_BH&< ¡/m0`c+-K@H1]b|i&Zk8c$z3M y# Maޏ1`4HBki4o*y&O UdFfXz`êDvEK7%S$6I`G/ro_7GZ^p64`edQ TD  VRUO 2Wu׸YR'?:}9ߋ")#f;kS# C+jy:'M.@~6;3>{fWaY)3ajOހ vB791XX=؃xĐKXŖ8?;䓂& [1p{qOjLgXw*D*`1U5!sAK:1OBϼř:[=Pu uPًin9vP{/W&$z(0Ȧܬ/X?+#>6|hSrԶ`++T@`L|FM1*6^ibPz4JHzY/@Yq%C`nCG߄4s=*~쌮}g3G0>,z8תJ?8#d4?Gr#H Ն*%TYї:cSg>Me]M3P7g oIQP"7}h5 u9A6^ުrVtFvxd.٫ppͩKz߂"["8n7,DۨYDo1ϫ,~YKl;[U!x}Č\OR&q| 2?PNyս~wy4yE#:[.-q!bce^qw_m 5@`7S}إaΠ>keAn*%|إx\&8+'ϴ zlj ؉?@ƃ7h*kW)BWUOҖn9㘜_BbGtk}ƣNn` a{͞괗I@9=DF_8$ luYP ( 99Г1Cz4-V,XMW.ɉeϪ)&9I߂(ZаI-,QhN ==cG+"qM H>ISq}ix.um91MTW곎BIc&#pu 4Eēo`PjUyӠL@[j|\Ą)46aY2a;`):Nvu5~;m'y>5Yz-_3 T-ue( [>9 чT6zN6RGJGS?!S4T>-!cpy_*u_RdL _-I6Oh-iyI*@u0;w%Zv {갔FDW3hIc(` 9;A AUmu~QH#3,v@%Ŧk0l6*FM̼D.h\}A l17J 4ˀĕ׎(ʄo{mzϟi|-}vH]rACyE,̶ SG{9z/?BX&2|%p\X3!6FƥZ%,OF/o"FcE'I &zB"l i,y],1AQ@? Sza`*m*vHe&:L1n|Ik;D/xyՒ3Oqj%;9Z,)wLucծ媹ղmZl\LD}O&$oe;~)I]2h[SWkUS#' w<@pM]Z%{ڛ h乑O 08~-1UF 40`Ly !;6Ar;ޗJ`ZY2${1,%0c&Bȅ?O0,tO%XAq3JD,r/̇{kL'j>f^b_BW(V: >;E˨vX.ț^G>I| 3>uz5+0s+УHK5ӏu4 4uS3 2fw A=X=)ϥJ,abb夜Z|?J1MeƭmBf romƔH9I\ʅ+: fxl$U  H˦In58I W(ΔA*PH r(<|LT%BF t3G7(QpD떹9>3.223jhOf"Zpx<~&b3J M 0#]X VyO|t&(Љu5JThWq5̴p<J*7zL 0B{,I`ĭc]A2NnBC wm8v͚aF֯Y{mԾU̾/B)gmL0Y<DV{og?a_I9嵢|yqODݼF Pd}cq#TeMi0}۳$=,Zqp#,o6\GO2{be^9ʔ79?/ ZdA4m&0j~ăCfm#YĿR߰}lM$;Ѵ f3g0j16:"+$`Ϻk߶=4?:Cw ʃoYo| 3+Q5~NWz`fCaWܠwzlF!}cGBj zN̟u*opC]0|-aEw"k:mp+zubHܤmKprըԮw6TDMEv^ d jjA%(iQOY#7o^X2܊,p'!N+sB!g(L9xxb u./*dU ^ I#zE}( S&Ñ$r|*XIkbSr<7޽ 5kW =cC,CרSL^Kӱ^Al`I) Pڃ|^g?+Agp1.9{< MMƯChJ@fYJ}iX3f ݵ7I$3 !nZxT`1VMXREt2MA5g"VXH ޝvT]xWhW5˜CmL9* yE[\[FTϖl7?+/3 3f 7d<7]sçx*lt_G !b3J-5Y3rtJlq'#1Kjxpo7wU~Wݧ aVt4-o[|2B/Qy4E$ g2K'~UHV2ca ,Z(\/ZX$+32ҟ'%kVkǸխnk_8A ? w겸Z.X,;/zG&^7]wD>PȿV%8/ysєf52w N"y<@cɇ~%S *jM!9'(4B5P'$LzP7'V<㉩{8T`,0'FZN}X)91^]x.)-yoLf*&Vb Qn g FF21w&M\51\ڬ baޝdג!(?G-ϸAeꍳP˞#e,MI֨5-W>Q9B <a?Q^uJ_p Q uրzFu2uUHx^:E RsV:V񫊙)}Ū.ww(/FZ?i[;fmvb)o=&*6~s$fɌAd& vջ~AcuҜieX k,V"bdm>1(9^h! %HetPO-S8@^t > tʫ`S, &1zJ' vYAG~k< FTe}߱SDgI/wE}<)t60eCVDտday ˯Cm<">mJmve=3/33W+}ɮ[CVoo[7N֯OAx=2"O<;&M0R(>> -"^k5~ݤ1_VT! ib !q SVa8x(odol@ Bi,8qEME_06r @Hh:^L$  (;l$ֹ_#u) sV/gr*y\I1]v 0g8ȚqN2:ڟX!2rlzlE:' Nϖv~0(IuIOGRb&\rVQZٓkᄄvo\#+X8197%wϱxZB00fΔ'ݜLX3]H^ܖpPfd|~iƩZ"J~SPK< pM46No6oT#z8*'>dJy- 72ZFZTͶzMk3iŠ*~Hv1I+WXImrF$iN{יCGމV hx!9ЫP@=sVhF_ȎQ̃6U"D?5]2kbR>!kӵ+Ӱb=>n: yHTN,dj ZÐ:1ƗmZSl ]~jށ- m |ԺKbhCݑ-aTK@/MFJ3 H@ZWm{+0UP<2j! W(Ii~T1|17cߐ[y^7l&O+i4@GSWx(c[L1APε@k/1׵hLЊ]Ũ h;J0>CTLq4btJ@xWPfÝIx Z34%Q(rj^F`R7=Ƙr7I۪H36Iijy 6WшKbnGbKOyj.ܔ_8!`7L|idD_H]ԆY@l}}"g+G"- -6_%SشD*|tP3BC"Lv) [e ;z, .YAMdOތOEiLAn 9r 6|qm޹MuKikBovu-f 9 U&yeE^d¢fpwƤe%D;¶)jV]C`:m0ƧUoSQwdr_{6vL;E2_#o*vG 5眜1CG_cz8+#*_ ȰTL֎noѾ8)e>4]pn=9ɵmQG*}4.`qU9o4[6Ӕ |Un\TL7WR(o@P :6"C1.ۦC.ܓ '@r=.`CWq4Y%`{f%ư̪0t@Ŧx,.RP/&_T)çFW3w)F: rzɩpM̆3r o"Iu(|N@7ݑFu ^3~Q< ̲޶.O) ^1HD`Bvowݮl0e~V0\9$\Ql3@2e6w D%؎vCǬn"{w >  !r!z=\ا| QOy}KD况NC*QT _Ԛtb,/[aNefj,ogGg ub/Όmkx Ov}ܩl8x&85 )6GaVd[K"Ng%KA܋NLÚej^=i_*?>#&;%b(cfQnzW`>ɃY))\)2 do&ԗw:$cQGA{%ZjPjlfg\oϮL˚?aL(z@S%)!nRX@ 5 Vk:CqQwb3[8IL  rC݊,>ǿ{0y6x(YtO:]'gY&EY8D?ȳXLJr3Fg`Ձeѥ;Qۜk=bP9GB?з㉻nUcp7αhl 5Mf鶵ω0lgTQ޼|d ?/Z3C!{!M+uD 5d  :۶0LZ6HBY )~6iS}EQZs|wlÜͽ zd$-~aCi }gGZ)V G:YrvO6wΟ $띄JQ $ja (bXRhI?e[x. 4.I-|{G): lՂsJj6'Gz'Φ}l;mަ |ΉG?bJw>Zdsمb+ÈDy9oմ盃ꦪ21I]x!&4)'kzPeٝ-q[LUC뤾X J-w\X-ԍO!ê8%~u5"}?Y*W'|!xWg8I&S*wMUtYA% ޥ5K۬rM#'/ei:hkSPKf73fy}V9nHqop;[,rCx]F- M3{޺{F|ss8Lǰ/lc·lB{Y_]M 1D{v{o`pRT.qخȂ5ĺt`_Qɡ88h4>on9&Q侘Po,]XtRJLɘb @9YQ_ǟ~qmKusez`n l_ЅKbe?n~44ț71]Drf}p\NӑZ4]n,ӥINgݗ\f`P* C" d|"bGyڏ7bej܀Z΢%3qBU*ű'7ȩVv"t_f9;ebv\ۇ Sև]_cѱf?ƃ0ȯ@a ^FdYs@$|3G$A"y^ʥ' _GB,11 IQ[w ',s`g씒&?"K/@@%5Ҁ>M׭,lZ(1W~nQ霥m&~̲7_(" p@QC+e{|M]Q;5x|IaKOr$a& 4ϬXS@QߠZ*KGQyd5C毶/LE~I3#Uc44%4[H4--.x<)c"aĂFcR}=_VW[=mV?ޒ6C~qh}7r<%]P'Pl=0$y: `|6ֱ alG<؏Z("]fPD͜l? ~ck/'՛Y!+6}2|1=g57)EѮX5УD σ;v{uV⎚u;}$n]DNUmP_gg8\ j _4 9Q8y(T:SHpW4",ÈKdqFZh} n{ F mUy>9Ll04{{q%[n 5eA1]߬zF >20WK骧6^w>eTI3 E+AM(茺F=\0ƌ!A81Xq@[3{jA&Os/-v7&gG̋/A?:.b1jmNĎy͊$eapy/V!,K&~>nȿ Mc2,S`r[LC"/M>]5w-K,hڒ'CPvM07MEl.۞7f5]F̿B ZM]gT(acVH+A]WtEl VKIMg/#ۏJ^*ۄjǧbepеegV?2␎ ZgގkD 4c@ۉ["EJY 3NO+1FTU((oQ2AeW޽k ^㴌u~nWxOi ٧ A0nP3Ƶ?*nF%0EayE&yiIBc!4"XD8ҷr2V;%1CK|r8и[N", U`guLhOtHjÎzHٷN|W"Wh1,Jٴջ o9em<$h΢#Zw`q^*ʃI HױcЈ(8bԚpk$!RF 6?x.OƵ&AWxMm|CiAi '>5oo̯.9qItU-\Gatt2@~ԃʉAJ0J/2-Vg<'mΌ?h\QCKsnk)'q8pOhE '(A(-1I[Yvv1TpXeN oJo ppɊ&Z\n}#8?½c h*,@} )Aȋ=H,þqrrq𻄡fM 9jf7s-"%y`rg߀Z̳pNbH~N{1W%K+oiڜF! T'1 f r]tM*Մ'oѳ d=mR fyS0;0W81ڔiwZ ΐnP=h´Yo.B ,dC%30u h/RHzo0N8" ǭH5Pgw;IF~*H)sS:Ù_S/{ۙ*.e p@z12Z\ O]L(EݵO Or2'LJMƵF.9unBʥ(mE $RRWz^X< P>#$_ڔ)Na`m.7 F=Nޥ2o~1DՈOW!WѥLR2:GyCxI=eBz.x 8s\A!'/1psKb=\ӹ9:?cE]ءV& 2MZ/(RBΗ;(=NRo{J(E]C N.dw=%J9V ^Eԣ6jdNB`-}cؠ{IE'yh%ᥤO"Jn>˛ΠRRq/y ejw* sr6)9DOTPL}Ĕ3HlR*<갧\ZU!;c"?Z/n<|>P#LIqaTb=1Lܜ<D "y&y< s+h3nnY/'l b7bZ(ųWjz1`fNO9ɒZ?0Q2ĮO.l?*Yv}kÐsz_Q9 2=7\ <$ʝBʾIЩXo/&_SR;͏=A*(J#w8x}991Okgc tMMmXhBb|:16qx*+t; EIl0;jq͓J0\Q3 Z^WF#tg_Trt  0d0J'DD Ήr]f([| Cd^ >Q랰l6SɍT8?\熌zb!;̃oQ9 /P$l qH-F)H\#Py#[ 9Hy 5ALLCaD\<+}^ZiN4 )5PzXjHJ\^ӳki`z`,ܿ _8D!v"w>}V!;>KUPV~S+;:`"HlNzTܖ"˔1¡vfWnP^9CK'3&UsX,j׷7oa=Cނ@)!s%MJB1W‡ ȌͶ1 00;]TNdJa eku]%s`bʚ1>U}#3NЈ(X+-lۍL dS |f5>!xqF0ۮ*2]gjBi9fB=ry$`=0`1[%, fbB/3 W'JTw/ Lu02XѠQ~D⌢> Ha.lkbُ*xXl}Y/,B AKE.y]aS?@*Jz#:.NK 6XMCw%PCȅ یSx%6-JJ¯#MO  ~/t<񮬱Ȉv`pМԣTUQhI8+Z]\8SśEx]s ր=Bp"8~u 0CuUVLmWd0'x=o#=${w63# U4X6Sڀ^}d*5o Uo֏)A}?%x ׈!2+ܓdZDEa0B0-ȕ3d4L|J׊KnvU(p)G8p -͵`sjnf"s|j?8\Gm: <~~,Bc/\.~B铁$ -:༓k,S Aca0tO*ygLk\@az.1y*ָE=qj b>r3y5a?K(co/;` LwmBpd/4HϬw8ɿ}5*<,ӵU/O An{A3 !cFGSwPt90`dT3£Tu7[p='s W?/`MQ-Np HA-p.A{bUL_ѽ-n|)ɸ ƿqiu^Iԯ uvǴ7u,B2&ma:sJfHwj߱[QMmj]qp~'*Q/SNΛR$7 ?s1LS:9qdѵX^lP HR8—Arr?6VNmhxuw ?gf5%!ZA% u\3LU%UQ=10vDyG @Q^b @\2xta ۊY%DLsx ޣēun|oO4,>YdmƝ͡ҫYoq \ݜZ)D{r*e5-kG;?z05<pveٍ qO\s.!)wc$VSxX @& Nu] tdW2${]0SgEs)j$? ^TTlh p$.D&*kДtu DPkzp=oeXë ;J>m{h( 0$5 =KU36Ŀ0``OU{F^ASl.F8\Yg-w A(8,U\SC<2ݦ"" ucBN˳ ,r@}5/'ͣ F/DvNmh&WX kyrG+] GakmI: Z"CQP s׾׹BQxruo`;vYBfvmm]in)BJLjsv>q/Lw&M{ y[䰵e-lwlI:Я!@Z*q"&]I Gw ,v5CHo I(C&@ i,o9e ݵm!^B~S#/c?'i~t zhfqT*Ʀn<@:pMPOYc`d1+1Vy{#'yrެ|1M\3B{^&C1 >DZ0t+2*K2Q˃ ^Дfx}1F8Q#yz#<>h L*0"$oiW>,uN} .K@' uV, X=S4 *=3aSF28m7uHyy9yʁ wiFe0l=xF+TH|(~YQ2Ө]0r6,^B,_rpByJҥ(@Uy};'LUnhe߿GH cS'zOn`!u6^g!j~1H?GUrdFv1ɮI -ks _ _wHdCy3 Rxh M ,7eUsfi9 ^&fr2P6h+E#(mɰhP:F[(HY&W}Y,)f Le{Q:qR"fh# ቮֱQ>7; 0W*&) S$\sz>qx8ovH:Ŏ7D.ALTu`6.^bS;h)3| 3^`2^zhO,8}ÈzQhAYu;Itؖ%^^|.mk\|ACAqtG lzkv+[%%}˿ ;(1<.ӺY4u*`7F)d< XZ&ܴaa<4"ofcHk[#AVHA@m:鶵puv b` e|,^'֋s$]bf&̟5m 3PAi{C.5I|,.EǧFhI\j,?-ޔHA1؞Lo5y/  O-?Iێ"# s5{~FcRo]i@ޡ<@RgNQS`~itkE5&GjVrA.q4Ii00J4] ' [6}~ex4BPgʽkBh*쭭-N uF8$}+ k=::Lfs'ݼ{K_a\rSLJb#Ϫo7(16|X=p( V9xNETF9/R[q9\pItDoЩ~g sj8׸xBzq׻U}y2'N1R k47b܌j&Ȁ`)1 l1@駔Qo {U2𙅵C1f@'(։Ȥ&BO%X$?J^zҽ0Jeemc[zѺ?Ys)Ӛ_96@e?NGxkw"I4} 6͚B\0S~Wƌ"A2fM!n' A *=8IsHlM7`ii+ loOl9>Ə 6 ^Yb (;QDv]dF8vo5;xh8u@7ԝ҇~_C5{|)>I7˧ /Z'(V}憖"Uv'P$$EPr`~agJOSv̐wkT0S o V;-x"z90KQ 1PHCዖxaے@v8ሠ٭H.NPĩ'zSG7lѲ%-'9 ڗ/V/-5Y?*XTxB``JP?Ԛ˜띡YtPCJMuwq3c~疑]q@|]%jiS=Y^iw0` W{b ˬ#R3R+/d)1B$;nȂ =|;y{jŠr {{9w(fhW}ޓsQ ay pJ<[p6>=dP56ƺTB1bOa֭G>?x+Ұ19`!\%vD>j@i&m8_b!Ǯ#zzb1*̕U{Lg/51OUY3\RғP6@:^5@۴E.Nn#qd+2gVSXku ,^Z7׉<ޡASTE=0Sn~9ȁ$U".bLd7V7՝3;cN>D R`:ؐ)g,D͖TZ{eUe=r05)b#Ʉ6>jCjkc :{TҞN! NZdc%{{}nZ񭵃sY39!|S+) YZ