sssd-ad-2.7.3-1.el8 >  A bU]A$-:kv)mB̡RSMkr=qcCJGR YL"q֯*o82 R8pg mO ^FК]MzV0[GzuB1 DQ?ÖO<՝h+VK2woi?QN$T]CXbNCiٸ_7FMȹD~%,ՠ6%C~}~Lmg?]3 iaa/qU1KxE(aɉ,s}TQ0H X=z'z9 F492o`XX^0bf9ꇤ]{l>HaLXvHtz]E:hNk RM X_g]#zJ"k<5q?8Zx2$vPN'kӣW4ABm0OIuVˤP%Lnqs# :WN8XDy &+MdL+QY S՘3[^%D=!(7KV17ljeBa1󯕕DY+pE$?d   2 3PV`           $ X   (XDhD D $)(88@9:e G~8 H~l I~ X~Y~\~ ] ^ bdeflt uL vw x yLNCsssd-ad2.7.31.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.bچaarch64-05.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64'&EPK8L <O AAAA큤bچbچbچbچbچbچ]bچ]bچbºbچMbچMbچMbچM6319e65ff9c8bee81acfb129557d479ce46b16487be7b3516756f8766fe323718e0974718cc14148d1cad114cb2005cd38884b736bd2a9a68e0fa950fa6a1f1c8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c19246cde7cdb9ad5134a926fba3ad16bba0749e26608411b77661c358865b3d86759a847635622570cdc701997b8b5e1e8524160752737b7d263e476edf547e8f9e89d7adca9c8e1ee9853e234906cc4f129bac12019aa17b398b160e2cc56461a6fd4719401ed442751b0c502faf3a0e29b142e7a7c93844e2b12a84ccb41c../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-1.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.6)(64bit)libndr.so.2(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.7.3-1.el82.7.3-1.el83.0.4-14.6.0-14.0-15.2-14.16.2-1.el82.7.3-1.el82.7.3-1.el82.7.3-1.el8sssd1.10.0-8.beta24.14.3bγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.7.3-1.el82.7.3-1.el8 .build-ida6e3fd1d0397cca499d89b9d0b1a318e4d2ee222cd253b2d7915f9184d760f2210c2f9ec22951801libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/a6//usr/lib/.build-id/cd//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a6e3fd1d0397cca499d89b9d0b1a318e4d2ee222, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=cd253b2d7915f9184d760f2210c2f9ec22951801, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR9RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R:RR RR!RR(R,RR+R8R5R R-R4R/RRR>RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR>adclibind-utilssssd-winbind-idmap2.7.3-1.el8utf-8165bc3cbef3efc360af0f3792bc894a829af744369df1da53b49599229e354e9?7zXZ !#,] b2u jӫ`(y-lGˑm|˂l(]Tv(pN={%J}ڇ{k)^pb0fNKh6q&[!ae3;,C*7?i38 {#:x ;|ь&ܻAb<,P zi?TwE͒qfP RT=һSo}I P:)%΀-^ʬ> $n7+/HҔ82u4!<9j PDgzhyǩMV/kUҤ`]ջR-u!;[qX,at0_ œj_-wf~ItŞ$4G.Tg'hy-X#9jCO$N]ۆևL_/e|BT?C>V錥 xI8Ep[IJIJ֖6klMOGdEըaY' Nn*!(zA67/.)a)ym9Jw,-?Xn%k6n4Rd^=e=?>Ra:D`o .KE4{%y0W7,-YvRDY(Kx Hh!B FC.BD/Bo[], Jw:B~{m;$RHhY.+h R#m0?d%:Iх]?ME,Ppw1ujZʠ}Tyw@2Xjb`!"=-Yo4;txI@ RּWorwCx>K-C"y@'ϏN*D."V0"EQ/f|Tp <В{8~O]2_{mU ¦MF= hФ|d.63h\HWX$'5pYMMnt3_:"N}LKZh2Qt0%ޟ붳q*/t5"xlW׀~W?OuR#l#se.I𒏄tj0ǧw> }QG<fmÙY2e©,a~ 8]7m)ܱ^Bg,UƀN1E=kNyg1}Ao"j1v]BDYXX/]ҁ=";gߪVA9EMxBtTxj-s&үHUBCDBi¶;j#D{m澱\nW_sjrm`:<2#^bPU%xps<s)m2Fw 3U2A("YoY'*| ^So^Ls5MœG>QCN.Ȩqio?ЛǀVB3fԑR?ЃhB?Pe FxJrRD!ͨ]cq6U֠@ :9|WP:wFj.X{%Idh,D2(@W\{εrteQ4 mH63"䤕ڿipqW#UiibHAZ̄H0ss\oHMs2/-cZxNπ#5j7 \V)! uH.QRqn@i w_< Ja )YJfAOh̜m{%9ҒlJ{aO׶c_3#4%+Z"ŧh|#U/}Z~Z52Ob6lZN^H1\wF5uE?p9ګJi{rK'1T.+q6w*=4~oage~Wg5^a68[6ck.nH^xP"6cCC1<@g=:AsQ[-Tga2|I=u[7֦E|eN۝Bgܾ@,t\СN4a=^}H0xdP1 p#nB=S5 m<cnj5tbCߊ:TG]g a,#?ciɁ֜Pm;L◾vU_{(0˺d"mEQ5yzL\kwM PNmk V޾yn½Eƨ[,4E$/+DR,,: Cw+.m Qw3"! }UO64P<U*Q1^Ɉ_d~"4G9Gۋ`rtCUi9tG҄IG?F_iW}lX:Һ9Nx Y!J.j*u|6ҽgET\CX*!JZ9^pqU>imY5][<{6_3,~8vݳt`vY'a#P_4>8Wt* ít`=r0H#˿nWSE`tF /2bzy\ח +wr3vAk""STV_䘠o 36G 1Krpo:VlQs .E iG(E(9K~D@,Zo`]?Y"/L?L}9DrȔ6 *:KSd{4>KiFXңK׃pBKSB?e`"G!GV8Iْ&Qa [{dˬ,@O،̬ I%Рm(!k2a8S80` WwV CQﰒ^t{c.2Z`CH(T7I*#K4;63ѓ[@>a<1Mk4KAԞeUY-wBMu`#R/Ky Y? b AԱJP\}Pw`# V~"@eMk.M. Q%j a+땀 ާ 5fW%PdXϱ:#`!Bv kK HjW.;D )U[lfMeoL0Nn+&JƳfv&%q? - F@ρRaxEo+F3UN d7 >D|@vvd2VFl1RA7~y1v.ܩ).D=tzυ<͈ZnS^ӬٳB-x.YS !!''z RQR9s(6 Ҁxs rj VL}v^O72%SB lQLlSЊdl3%N󫽵BTxOyP5(h3D=M'X2ͩqYlo{`0DS0&o굤Sq)&bF-vw+4p.IqOUqP)qJ -W#/bPwl+^2DW1+_b'mq 9~me @ߝw~6=*ح)*$ lG z,2v,}6*G }#sR9[/vxO/F9E ܿh  [cUZ[+n{Dk,=/njZn,Â02=N4z=K,?zu HzoU*dtH!S7-A4 <{jM~^ƙFY_Aljr ӶEtQNP֎R ;Isڮ150iŲ..نdj3&Q-Qp8wnE*չSƣ*"젹O5:qIm Lo,'28)P఍9M=Â=+)1#S,(]tMdwf5c,[DOX"o r?j٬:(= <-Xbr>ڛ32n^dc ?+iRTp熿ӱ,:Cnߔ SO"w>w[] ]x:]70pGkK]rvo"6`p~{{E]t9p<_:#,m`ASYQwmIRyM|K9eDA lZtMn# Vl.f *y_IP"̖v?&*W3U P!fёH]p2%nϊU*JzI܁p 1x`/Yr\6VIz 7Ap_#iqa8mjڭ艅WnxqˍZ=E88*"Uw[s(qa!ݠ y3N_@_Ҳ9A+I|z"wc n(Ho fCXkIYkLa}Ў>iNl5\جj/[eBD =rXzj  ^Bn3oLw *5.g8t+t=ay4Xos؞M2|w&,(hi uWq촒H 36w a&H*7rQ[Hsp.90ܘ{&&L9>ݐi}'X"k`vXH=U:lHsͣ[gAɟݲS#I8E㶚.'57|>tk睯lM,]/mO\IfRaSm泘$QͰ'$ *`w: plzzmĈ{s1_֚ gS3" 4X/ Xkg(Psڂd[,Ou2gҺ,Ύ *_Sz5+]!1AN'H]Ouu|s{#_d$d+۵ ^` XZ1:tX?t $~ ۇv"'T;m"k5 m@KVW"cYFpt=vom diHm%!X9y̴N cC;(2EYgFJB2E~Jso@XYjGt\Ӽ*LcPeh9$ٮB&S D YÚjhv$P OS!U$81uɷ U5 M!-JY*2tlJ1Ӂ`7&?T=PvJFOTMH[ڢSoUOvZ #6(x kH rVO@ j:`Thß9)h(_F;6N'q#)C?zHNA?xwړ2%)qթK'+umdI|ԶvL g8%wvޣ'TnaT'?F%i_{a҇><1k,i2ل8y^`&NbҌdPH9Tj?=?қhRKxj[dkKF:60dc9s僑|IA@A s(]iNQ&Zjŵ.Z/ m4WiLX@>/KEE9^K]S>4>4"R|ysp%Y4Sn=v? N'nR3*' [:ɰ*3HA8؍ѳ3 MUSPweRQ'Εڛ_|jw{Yu{A- ! *\` iRx9Si{tyA[In+S q/@eLԫXi6VtÕ C#CED%mړ}IZy _jrId. )N8S \w%=|HT G*>%3**ݏY"x=Hb7&rJ_Z{d{/2H J0`M"qK|ф>Ɗymߏn M~jXh k,GhR+"X2hNk8wXv+`O86Ÿ$ycƔ ̤N1e(y_z`t 4C°*l" R (F g!߼hR兜$$Q`8{W#lٛ(M4Ӆq\޵¦$C2`4C}1Dwq6&qR NSP㚕Ynjuwc$(fyK}} @fc^NY?JN-|$:?y$!QQ{bĵq 3^WD Mg FxPm* UȜ01w^^nbKZL: }/SFxZª pTa@1sBP2E[Fe*/uξ5BλhC|執 nZzۏ9ZY]x׆wN=YuwqzIFR,/+~dw!!|^ސ_Yu+|*BEK|ރK巀=9{"q s{ sW\Ħc̬C:kҴ~m}<ƻkmJ)՗y⹰ϼ=ELe8Ǵ3MՇh dj6 yhuLdO c|R慡]uY Ûg?O!K[x25vdo*~Wǡ#S|c *=wQٷ3 U'! reul++gs^Y~{F *.VgBm=JTg^J폋 ?-5hsE*zdϘu`MƎ)B iCoX| jK/Xp=z%O|Wf(%?1hJp+?mӵ„3+p6U5q+l\ԟN[o wٟ @4(`Y'`%S^ݾ,|ED#Xo9-ot"n`s[zpJ0mx\?^U;6fuA+HjKl?GH 4&K(E?AXUo"IwI)F-eS YlOJ[l701eEW ;##gߛLg Ʒ*"x!ryπsWo)Ds/-_rQSc(!%!QJG#TBmw7*k!>] iMt{'f0򶥖oE'f5'J'ysŶ G MCڒ;q}9R bѰYݒiPiK \"j?!0;7όk@8=th twi`ˋ*B;CI`t9D`aK9z }t՟BYȽY_j6f~W}J gyMjlQ 9;7k:Y~u$Q^vP5Ǘ%Kɯ>N B W`l9꟯F G ku7μr^&ﹺ;8rG!!%xJ UMnLW3[(ΕIF]_PS?Ŧ5O8B<6]g43ᥙ"-PeTC8¬UOSr=9k+h*l2C ,0$79,ޫ%oْ{Rp,NY7';-Krm> )wk[bɒkȐ8]Z?Pd"\QCtGgO(ߘ_,pH5ZC0oP_@孢;ZLn5Bl*2窸gK':oIjz+ ' qgpoHՃb,W9 4X39WM LwʝĈwŽ+EQ?`9o #䬼.wM#|C8D|Ar n;ʒ5@v1 lbZPn\'qdӣG4 R"4sYo>,]y]&$1P:".l2M<(p'< 3WnLI_aÕJ׾y䇡Bgۡ\ޘg\;ꃖ [eN2nI@L5d,e8#]&"ܥ?tSj|EX,\)՝ ;Wyuyܗju4NuI"H }Du kVVu7iiT /LN@qo?Sbfʔ`Z50HG]x tek|?2YV{{ko _Wvv Zo.G5rZ-|QԶ$Ѷc@V{jDo݆ ͨn| 8:{#U-VX7ypb`fNG9a!Yy\{p̀H/ܪ=X-/_kY*ZGi116ݯCU`]٤Ⓦ(R*o~v%% p!_! tOoId;ѲHe9 ҵ<8|ZZ_6A.~+V$ϑN\NGߘF="ea*׋6鞅)a`ǰx,j)"-Sg|lb2SxV;f0e:IBdٗ ?7PfO㈍EW4Ū<* ڏ! {liNǩTxNz.synщ~iOnfǎ *IdAٵ+Ȱ< :^ rT/%"盡aO=ޑD6cWܑb:cH%rkeކ`ypfa^ T\0ԅP߱-|OP"qp~rzw\֗u6<Ap)RcYL)PMm9eZq(Z# >aN)\*^BɭÖקak#^E1P$`^vi"h`+L~$4A(Z矚O Ž[A(4'(-DC-:\VLȂu=Ch#nM8a )V")r- 'Syj)4C3'"5'.q,5GӪ/ ]KscZmPLa p(o={ڡ$ke!*u]3d pc'`l#\?T_|TεeFPL'ub㟛T[P~I>J1w2 lYsx v|W%jU&MzQ R+gˀ9`A{E9F<0wJ hʑ8!| 텠`$lծW;x])J'uӶ)A㨣+LQG=D:HAۻ|e[n*}H}ihؼG]u%n 4b4qY-u7K dT0F|.{3(ܭVSAWA.\sIw@SY7XCr,覅3f<Yě=rτ7ϭ!뤜p^;q|.pb$[_˘{J N ;+?Z^w u#\O@])\{΃b'@"C\5v_Vt<ݱAlw/.7c\EGAjKMl±l>~rHviQ:&ֿN-чn[/#%뭐`?֛D>{FU0軉|ġG~-a P@ɗhǮb.C3#9c0F *&+s#Jk:D*oP D1,#T^?># j}X#tt{Hz̽PB _5vS;ǯ0 vmYtQ0`s pCCd )ZNk~8,9lt.\Md~a?7ښ5VD*Bu!>(>n8 XŮѡp b]/; O3ݴ X&{-LY /V<7(Ԥ,!h6-yf#s; w{$0S&c ,-˸m5T6 EY ̋Ђ.B-()`D{ \ NKt%a2q_`/0AH6.::'}?f;ϋݯՆڴ`2_N1v;Z,?0yZ>B!T<}sJ7F)z\og3 J(, 3iNa HPF%=[' qmC-a~]a;ʃC19fVJ+iNTuqp,I22 N&ShP&B7 ̈Z\R֟MÒ }~DWxw};xE- Y _wiXӠ;smÓjgLBRq_pH[ah h/qԊymXJ׽ EaDT ܫb29҂2-o1p ǎיWqx+uhd1|9#XГ\7*5S{=cS!Ϯ,|e#A<>Xԓ/5 ~ݼ)+tfe!9ϵ-)m@jMgZˮtŬ PcB□S ˺ |;jZ[!<$ƛQP=nۿDRY3$fBVvJ/@ k u0|h9/pq=ixC9bnwc:B' (9,X\PayTa;YL vu| RxrZ(n(ևQ!ثO\4;% l_>%d$Cnh(xts%J?`x@;0=Q]2eˆn6!Hqt ʗ>H,'0ceJ0/'O qH"mV,}4w:NoW|)ľUK|Zji(I|po'=I[Hj^IyN.zb.59c&HdE8>y]^pD+Y!Fqp j0"tSe,ex@lB\%IX!R8yWQ\Z10sYC%H{8č烛]8;ꔟQH4D79R)g׶B 6TDs嬉e:5">Kŭ(I({A\̿ԨqUys$qNtVrTgf ɩ?ImDv|[nP汃_J`ﻭ&l{긟KDfC[/הa7ӥ[06<~jz 7!Usr>uw%/fB_V&Ҝ>uiA1zZO.Y O^r;HAj,Ѓ@TjSBm򢂚5y. :J93PN-5 Qv7-s=[Fk@kb8NTK߈< CS2 {t8&z2FmloG $YD.jo_ L,rMR:R% /[sŨ”tAGlbǤ,n 0v u>Rq$ab| SQMXE"a^Xt9kiDo˼6`>7 =f =Icᒝ3O rOCSjI&~!V: #ٌBR,ގehVs6RQav/}%}*yH4??ǡ֦ſ tᡸV>k|۷:LR̢v|< d!R6JD_ͮNӹ(/` k[Ot] TPM wp wsEDLصDaXU%N_Gp~1݈˅l/D.& )Q,UK<6ݹ`u*-5]dؙJ_ *_Hw4s!+?H,ȌSO:SйKv+p-of3 869L\iܫѯd' |>[DF 0@OvH~q@-rpzL<oIL4yU$<C…o\3ɹkQi>z8ΘsI5VX $}S<89~Q7v-6z/Ϲ"7&~1>7Ej}[7tf]K-_XϲkPotkpBM_vnѲ7 6J4x}?1>,\&V:A#IyoHZGoB^%ѝTvD*cWԖr[jݨl^ ЮUTӻVx=d@ $Ϳ MLkU8jGF)[edSʌ/ \sK/Du=c]{t@Y}ZjϷٽ%Poev2rX&CE,fq n!HG/}w =Z7ۜZ#x.9|g,4p"c΅<;"-u?õD7߽YB2d٫T<UOi ؜(d]45xv%I7x WG('/YQ4)7 ] 5($^na9WQ4`zqKUV^czkEYPR/YVB`v.;,IgLu'>{~[A4ZɏGD.pWYz:Y3z ͨ=Lǫv6dکPaI}t7CLX ,GY$dj͙P#)t2jfX^E~2G_ԉh'DX)ٱNj]5>F͍wLLߦ0ZO&юzIx h]Ve}U=PtlT[UH(瘯TXSݖ@u0>5Pe##RUp-T;g;H]c͟oH?x yXsn@'iĹAHA ntB3jw#p[ idq©]%jS$X,HgK0Jب ɱ稴*Je_O\e/&L{=&7(CmIt 1r{ģ߂H2$T"hnnb&FW48@4zkqxo7}TZ<J4^F$vޘ2Fb(.7?cvT D//9 9cr{f_֜ `}쑡OiJ5z,'ccJ#!7SڤM~&Ml|M̞%:n|3f<Rocׯo֪d[nTX_,Y#f,p#ݺe0Hbh=rD@g1-v\4my )P. 2KHut.w>_JkbR| tdR8x txG}3(- gį-5MU6?IJVG=okܨYCٜ9 jQrA0?%A1M{ewhN"=I|VnֿzJo [I/zg㜿"zLӟE`x؎jsihN[K*gbf;-~ u7gf#9orh\OҺ©?tt-l,{14 U Tx,iuLOBhoGn?ętV韨rp{(`-+;A 8OL-"4NJLV5q<&kSqvon*W~YX{Mܸn7FB_cf)}S~taA܌qey G[ok$̇%²^o0U+ TP2vCsz  hMp.s08JU.aٔ 4gO/Y:R&U>(HNev~+E,:h_/z@Qp'[~3pO|jG8һߵ8WT^m晊Y]̔|*%rU5ZT)IY)ohYmz} [G5iuTjlʟ/ b Jׄ 'Mfqe[,|exfm9an$MKhle峫!,]xLCJ.]C#egI 1Xw|!긹ҷckMANy=C9>\ߡrbW+ϴlĒ|ܠ;17lq[CSy,eH#:AxڏD7`$vKOA_Z!maAsF!ݻ`xL6,8bm[| "dPgY=7tކnat7u:= ?Lq%p6ޑtZJ]V25dMOX` ${^ )lpü3+M¨|"췾ò;󥞇AsP7`?kZ!gNF^=ˉf 6Q|6(d8g #ڀvu|åUZtlt6K!+' =(b7OD9iNLﹼx⾓ =# |DwĀǂ@/Q;ܹ0 ?M(&}CM{VyV?#.v+:o@2l6WZUFGxtouAi[Tqk kHDF2(ow! FZPX'oTh3)ܔMWFoJ[\q&MQ Q<!Er?BfHNszW4/gaSMk}uaݖ2\;]ŰND7#ZGnw.rg=EqO/[00f9u@$nurbf})pf)z5p6:2D/‡%^R[DdB6Pxݥ_\4&70֠%Zg8d )?Rϲ ϑIL# p|.D7|*uˀh9x7"SC9hP)q7(7g7XMNr50C'pQd4"J *؎69AZĔudzf. oa?Tr0h?`q:*2y!Ǡ1~c{cuB,MP߉PvǛq̞UWaCcv]81՜&x,SyD"7KEc f|?zQ S-U%ه#C1sdZq:ך#}zb澗= ycd ʜDDRnU ^>NLZ_ublT Y-YVS4y,]OtHY2 Q6XMEmǦdK niÈLWw6}&A#` yΩ5>^]+,<"Ўqݿu=χ6%d'1~5H_Gh S?g[UWvkXb 2xH@Kg^ww`tڜЃxRMGMw#}N%H; [:N+~" pat}vFJZ{>@[j{- "{Ig}ULXPd@Žm'Kٌns!~9B2)OIt(n3EOtcB)>CFoyan`9࿵#z0-Y_M˯6,H-s U1 1_k<?1VojjŵdpQ)U' i&15Q¦j2>z[6zNav *!̆YiPJ|([Y)P",Ѹl`x^@Mge,OȂk5=Kj97-x-ҩе& WldTRuWcMb+ߵ_G_1òō߿ ;d&Dt=2XѭVUMpϒbw4}e?U \VBFlC_=KO~X4uM4i3S}1ǀl9~KMx"/ߏÈlWD#ay0eAi_t %;Ơ5z%UPazI@C5ѧJx`5dRPgQsXZR5&OGwryNhqĮDҊ*`@3.h-Z$($6g㡱k6$:j' Yu8$NBkk+>OS'!qBiv[mp>Ȃm[ZT# Ke`mjLr,sInܡ€ pVi*]gҖ\\_zϛr0vz_λmV_6k̭a@L˴aMy;Xnj{[4,R3`@ iҭE)x22Bf's~<TEOOQEWκ+`pto&hȻq&WǬ:ɲDrޣt" 77 Lգ.:ES_i`=zOэdf؅k kjaTx-OV(+ΚL$I uJU8Pۢ9w/%b!c)ۆ:A- 7 5)&Z+JDEpH-{!:ׂo;U⏈pv8)U'Z=sj DJ~$ VOuZx[g67rJ^/)%J Ȇ5$uן1;]av\ry @<EaO[IKً0jK44O]cAA(.6Y1D7DJ\&cvE ̼뗓JOjwJrU`曍M7ەs'K 4iC轞gb*2+E>~W$ 'fv* dSWY)3A^u>ܛDV6H͉cԨxMl#gt+O0ܽQ n94@/Mƿ֖.&hR c5u(pJ/ zvP,+$KI8?RaQ7* V'j}G8?U(N Uz,y>XK˾H._#RΈN m?<4Qw3j WQ9i OA۲#hXՎzU>dE;=>9Su[ET}Pu2ଉO= Ma4Fc%y4Md[0#qP#Ӂi $K8dLp,0/.wnf4FI=01o2Zӿ ̋x6S54 7DP3ee v+ll\M$zxD0>ܟrN'3Y hR.4Q|tIq9]^lw>OڧF;iIN_R,LKas#ołm~t)yl[ӂǩmm2+Y_ҽ_˴QkUuڙs`(xh-ܽ"6hpg'$=IT;߇@VmBĺNτcv:%~AYrRZK ϯ?-%+wH㛺e?5Ξ%" 8|z8Ps4=>x^ RfT=AH5Y̔zWʍq^O/n;~8ѰGYCB[5(g9G޸̯ZʄE"?\/JP c@z@9Kϲs UngՑrAzu_tNgo5L{oQr7c"`jYYSTwO$?jF*ܹ=o⩅{k7 ;p4nz^7PF4X,ҕzȴX|B$/>rev%ʊ]'GRpO-Bx2U q+j}N:2Rz m2)N>:rl2Bv]Ee8Hܮ{¯|X  %ا6~pu)蹨!]j, ϨXyqP0`*;u Xbx}iW,Uh47iߍ/Զv2w$j'ܚGr ɗ~0)MpbW#񣯂 @ins;^Voܴgx)c>{gelj0 %qiՠ< W UgoHX+`v`[ԘCYS'9?e }򢯥w,)k?\)߽[WJaZTĈPaw3oδDQvض\F%-N-Ƹ h^q:"-varlf&b Z:,K^בʵMw:䛚1D4dw@ܲ7kෲb.E k>kZ0QS_#\3s1.]l汽@ęu<5Ԓ^F5)Xh khpK7/KAZKqgLCqsSv6۩12lf^ [h{$2rh,;ZHc4f }v/B 9e)ҞOkpF+$4nn3KUj𾔻0rYe .n,̄֕pqG=N?Sz^6Ά%UEcϛi*&Kq @SBiMgy r &&}5lXa) ff69f0։ j UK;#[P!-h·+iͭOؗPvr&ڀD%xv % 蚇cIC++KK,ٵM>Ru4Wy(. wٵ%aKlo#jH;_8Cߊ8NhykٛY8ϻ:xNO Qu yM]&oyB 'HG3{Jj (h1%*u^s|+^T/q_I L#oP$dq<{LYPw*N),9q#H_r;*ۘ/rD Eo1MWPeo`FB^! e劁Q[c.1‚`81LpJ nT_F$#C'x*B?uv g3\A}6U7JbV x%YwĬ?)z3;R+$ΰ]CZpFH} A+iz A g)csb\Fi}WDޙ.HR8K0N w&ۧwMK3JY7K5C +_VQ'߉'I\I8>>7iEspRbsS8G.s >+V 0?rdmz_ kxmHwɤ>K@g8'Qҧ[j=h\wJIþe\EAuċa0OO͐"Yiuc}MޛF僂Fw yP)E B*:m|{(#е!F 38vFl! SӶ+ػ%@sZ`2~ZTG7 )p3G2@FJ\Vhcnt.+ժ$\tsvٲ3Ǝyd4aN$P5Y7$S ZkQNݜҨ0S5;,&;w75Oae,DJjMIAkE0e(a^$ -Қ ^NcsLf(oF_q9d*e&{ .y]˧\czz2c$/k\wIR߃L,v# ➠=^J3Bpdc`ckѹ/>2D8?'}𙿴 ZEHcGGP).O I/DG=(7/ K:Ĥuh]2pq!X߂ѹ/^A4bxZ2A3TJ%Y@㭔Y8G6=Q8"#Ġan#@yfyȐ Od Ctkwk`ƝOPlR4QlH+Q3a:ٯ&+-Rk=쭞k\**"WX@& 6s ™:3IC+lN.PW]2iXtVMB w֌?{::sWPaS?W2wx4]ydG9:htw`<3doM|PQk9seyT_;oq Z7W]qlum)'KS?wv2$bkDPSHt(2_`T!ƾ f,DrGh%P:T?WʀCȪ)hdB,xd0} Tfn]:A& YgSF؅hkABjY\g;16ɵ&-ejH{/_2~+Ǯ)Ĝ`lI "vJ~Uw_VnvY;(cr龜RƯ{NdZ_^H}Z`bX^[F<1&20m ,x&1qX*e-+1W^Z;8t]xޡ"U}(ߣXc4[깰Bu-R!Xas˂FNq1ef`WEu4Lai/ Wq[Bd #|CI pTIj?J hCV|TN8 fvAf@BKK~,A7,HU{cuh8{W&[ QM C(a5xŪ+Z:"ٷ؊vj"2ʍa_T?AM`O*+=w5ƨuvcAq$q4B3ЭPU_~+E D,O`F"sFs;O[շ sh+aŤ^ݶI&pDxZPpj}#m*/[]c"@I*\ ޼,nG @F95:lX6<6L@1fftpL hL`n,+b2>d;/hu$zArl'&rqcsdq|eŅ9 bXܭ@hlT$b}2U%~]j4gr,Gd,PF ?<_ %եQ5}AQk/l? ğ-"AI-^tMEșk1&=1t ` rdD)Q<W@@":FhbҬE˯b `߼R-tyBIGBPG 2paG ``3)2cxh92ex\-fN'g7,hŭIHmZ(GQƢiNxU`~dj,v)b'HUI +0.k'?Pv=CU 0xHt0)(mx\y> 4]XpyB-t>̽_G~v+d\u: pRKO7+$8𘞹{R"smAt뮒T d~%. g۶,ڽH"ZD{h!ƞ iRNd `JZVdZ;[b'׆Dc%޶#WGQ (0Mڟ feߚV:qd۫_+$p# m^N. NA,0S^`Qіz/Q!א-(qabbF5׊>۪ÅGV#I5IQ(}rIl7b6Ndd5ᢆ9Dn9,TlXEÇߥY!5q8.#d zţQ>W^MyO.:@Icі%E"I&Uw锹ِ ^aUcbih2\~])u +LXEBgOiÌXWf{%*3)u0( `hqO&ȕ`0{T@zЩaEE!4AV \GL]_疵BYN/P"%fDmzU yPi)PޞvQPh4 ؒVq{loa %dj oUg҉}GPA >91Hx}EHt'7Czw݁wE8^ӭNQ;%Kx1aȀ+L}ݎ\aYPvT @LNtkkFw%g&p{`g_UR5.}TzRy9`W*: A8>k 毧G /=Avɬp(\n%58;FbJ2V_b<ʸ$#VUn ХaZ6ASLn _Xld`%諣&9]e-x*/3!]`iB"O<1bSb\Zgk {#SXJGWPFH]J E*c ӅD [w^թ5Bz%]|oNv;t:Gɹ}: )ԙ8E͚޼aiګl'^O̩C,?vA *% XNgc7*ma-duc3#M2g f:s&>_UT !9sQqg(T.no!9&É1Uݰ6KwDr3B{<Ν~3d)8?K WJ¬"xRA%8S6SwcW24T,)(zwgK u~O,ۑOYJĽ2X]%({Sy}0cRz1buԟ`}~S+N3:\ɶ7°&bav+NhlbA=3Hx-+!AY^ή AMAF,B9kc#&`M(EX~A*s#Myqm:}ߓJ%NDH}^:'˺aG1%mk(\_즎;wP1F~ń'QWn!r4֝&'\`l, ;CŮi3ڇ3-7U/<]>!'{#'Yfaj(Wjr&6$. -#1OhX!Z϶)=HIx=~b2i^:)oSA($7\9\$oܬ kTdS 0]8bJt,vJ&gU:oqUZݎ({tT8Z'*̓ݦ@V4+0U')<ỿY=Y)G.آxhX D.j|ic͜,#A $fi7THix6s5Od!)F6G֩Mi r(9XHιDyB'Qv\ ʈ?z'!$=CrD]vS1|+ɏdA=#a;i7W9)9+qNU°΁Ln? @)ӠdeLUZwK'oPG;u[X Md$bF3Ex5|J2=,An4aHƢ=3XiwIh.X'(OOأ(k*uuא$CbvM-pXnf%\ Ue0YTWb Ɩ=@2-MBU?B{T[ŽCu&nyw"daCNo*MPCY7m'f|11_q y|ʉ6yegkuyA-v0P>6tsV@(Qj"  [Eۧ_Y\?9NoX.0YSpp5^f^^a 6ZW ɔ <$sQ}: M@/l[=bF]&+$}ԑWW!QFm|L\{('׋S%bZ ֤G;#SDp^ ]"Ѕ3-sJ瞦gtԂSl -||ItԀ$ͰicC >2kSj<. &#-'t5_$Ҽaꮱ}wO}M⮫7A!8%IYuRÂIN2处@I8͏203N5\ B.߹J·(!J`LFhO#Ø{)WǦк/a;`q3{nIW<}mS7lRԲygAX7L%j[J4En]tݕR$~kcTkIsow/bx*r^hR쁪74yˉ5BEpyۣ&ȒQaԫl"< zj |ifѕ^]ic i qO| 6nr/;=B9޷)nl?9,BfΫ%%DqXNlb#xL)C:ob]r,%Rw'v{Yfa=HDKpNHkƱ⧬2]P AcM$vR:p=eG_z~b,x)&x"׹;S J.Uщ1gW aF)'2reyg9F+6+R{p-?'7dO~:v vy՞p0W@ UnfT, ـ }ӣQ@4K+6N¨}ÉګMFnb tWVPϛd &yfm# y5}L9SjF]Dp]Du/n蟞OϿ~<:+:A{~KFM)C*0fk$Ʊ߅ WKlmJ-҃pC -9/|&Ck7`u]r3Td4.V}cP'FLAm.RfQ!Lo nЮD;4L74Z9쌵8p֧>]ųCٶnvC 0Mʠl@\t€u!焤{F0%1>(5Uy;Y,fEZsxWAi$̀8st) o6x|n}wedqwb8"LZ&wn8~%󦩱ڕҀblWrڥm&B+\syl殴6q\!bsV4k..~G%E*/\2%.ObP̷u 5&]j64`R-S.܄Q|X7įxڤbafPK/H+7$E9!~/ hcxjQEx36v25b1| 9a|a.z]inԕNKF+_=LDZx*L86K9o#{Ճ mB‰ x.)MkpW{.y9n9 q~:ѭ\#[~v"3M}:?R\%r'AnQ;8H52:% Z-GQ 3(m<&[SqS` t9`1~I#wa3X0vܶD*;Zk$eAmJ7TZyJ8( >P"8?8|XB]3_W3Ugq.o ʊ,)TVu] ;̒bUÍӌi x}ykx0/rL!iƸn8iZ'M3tT,U+Mb Lӈqsk+̀ e&VWz/!Xiw$٧16ښɪMNѦKaЙD x8g2[d}{í3:]mOɕ;tp1ᴆo:9 ~c<޺J2E_ߐ$NHւ*Q^fRߺK:|TYE(kΌhE $28Q=WTlT߰$MULb>Fy b۩E--|1+=iM2T#Hhw[x;eb6~^FB@빴o/Df ,NTL%'kvTֻrh2>C!M˷(; ]?@l ߄|O.+wMhp@my`hӗaF{ Ӻ3G,Dʥ.];\ 槿a[ik'~o'vfb תNC&t L%ߛv@: 2. ]}{Y?yCcaB(lDR1A=3%J% EKM9niuU4F0%]{@*Й? jhnrIT *LAAQgآ]-== \QM}YKC BEkWG* s|CBjMqΫ _1-?٣oE_sU|Nwk~li¦ 13"~h5,`3МBy?p]'G UOK1 /i[Sň'l7Sf*VD/t&X=UqSۜrMz^wC,G1`e`&"_@bL 2֖r+3N@!ˡ4wHGT?׫7Q{41Z:pBm4=\=ø% o誅,]؁ـNi/'=a )Ό c`{ j$4I&ASa@ %Ր  066aO]+|0Qe6ڦ뚿 1-  jϦHR#=.Mq/| J(޳rJ>eFH)v w %)mlk-uueQ%ƭ`d |p`5<&OKB/]EhO743rs:d3o=LGSpAY~kFQ= !\!дLA@{n3Qn%HA/W(X f$)Շ}!ۧ̈MrjssqG0JߗDd^WNAoKdnEF6t9{P+pLUp`7Q:IMX0/n YacBDrRx+@E3Cn '&r\QGT֘\`|[Bf\rX}p0?",ãcN)B; )1=ˍmd~$B(}omE/Ҿ\۲^VbSh)v.湊au~1;geZ}qSc%kE&Cɳ,$,DmK=uݍbǼF2~ @'JGG-\|Ug― ݋b=S! 2ph{A9bO˪) -KccA꯬ǣxŊ yy!FMMhmT&yoßԷ0U$rqs"+:ʜ"0#| Mg! _tgI{*ɼG{9Ɲ'OE]60Pn:WHUG)Z8a=uV0<:lȺoK1&*Rփ]h8H|G6s$'(]ZtHDyYT>A'HE|BB8-K &8VpdlT5 FԪ gb䣐+IȄeQv`bkRx3R]=gfo0Fd%ò3" ǁQ{+O|3ອOm0EjzIu:Ίfk⒗-T8W*EBէLAU͏D1 E㜧VnI%e*w3x .E,$Ō뫧> fVbOb8|I= f'A˾3ػCʁ[\O$Q̟ ɵ8J~9Z,^(zg8, Cgr#I+Kerl&eV>I<_ur8+> X~l("Chj:*5)H)5T uo*u#$׌qXu"8R]&wΠp_s=:JN/s衪=̤}>n72]^rC[UPiՁyCҧ32Єh1 u}-+[D Fb0R<BR0s;7"b!~s/5kJ.\B4nY6C oOyFf+kԱ"[}k{Fҧ;, )Myx-bm7A5qmA Ѡ@qo,^=^cFLB1C4queAFb2o[i"nQ\qrSE6G : K:ƀEԹM};)V>p\Wt7ֵB6 }u޴!S>++1%VLr-157jDFMC(*tEg}sAIQמnZ?0zIYJ+D%*!./I\ptcZ$]$OY%)74IWFiv ;nLGAo˲SZ;Ďҡ *&`H8kv1$؎I93ivMۋ>DT 0]Nvlc?xc%,>(񶹆h~c8~oBhʖr>v# ohH:J>)a"%\ Nwym>ܙ"SuM$O/LN_;8ogq?f⥹('ţDɹ{#w̶j,j*%֭syy)^9}|2-z&}6;;9ðS 4f5(ot{T& ^9HD"[FO\؟1RC.^WWp8Us#۝3xB_1g)؝8PR"cWfu+&=/c+:T0J"yOT~nuPh+ 2W ӣc/ r}b`,cܬˆo2ӄ1.XEIA^(p,lD:pTȀxvFVJ8G┾oYhgxVm rC P[/IFpHڻY4\\~K]%@mOY+(cSSޒ@;=>K&;L54ۇuv˦oxW;aq4 4<~ E P[LJJ`Γ߹"Bk/lЂ?md?#C>"4|.1BN!vh<t/5\6Hy " θCfw)Vv0w"oo'6tQ%uuzn$xG<1>"cWt,n[#$1JoN o6yyCf腭X$-#7h} Ƅ#<"S>2r r>@4ҩl\>̀V0,MS =7űb,~v (}S NB^#w4. Ǐ< XeWEEtScx',`(g%f*?|Y~-f> @樸XijˤZwX(W?[l TOR_lA)rtǖ6Q}zfz̬˴z 폏h*OFV^cXy.?b{#mk16rC^o5~U:: o>LFum6K b&vJ$h Fq 6I{N%i Nw-JI\ݸ D+%gWʻe2`) )Z[y_?YR (T:; HdMW Fv)d^] MĕNxǔPe{Jf.^IFRrXJ⢳giҫbn13FN|w kۍ&vM_^Ӱ*D=E*$^Kaw$BYkRK C[ڛh}F?މ /H2 !1^)vɺLC?H )D$b,`M@lێwOgR^kx,xEMf$[֦/+1|S/TkV˓@@8qaI\iﴺZXF@6DS<\¢$Yjq-!҉McN)á"'1&Ny˖` :W=ݷT4?ZXr& [;D@VITYd';٩734z]i><7e-v(cS6IOlYզ 5ѼÐIoF3Dvj/z.S&^7.Fk\>Xg3m/>,zhS&wz&"yV d6PW_R6 P_EbO$`nA' jI gOpKJ; %zh1ոȋf&X D`V3iؿlku ʏPt)uHjUvI1%H4e ڽab&o;lLU /u!;N#ʫ,#N ; `RG7g%})1ok0+5pei31w}< >u@LwXڽ+yicIvsh$Pt$Z 0qt=q=i@?bQhwTc8Ԏ5g~|EnAl($¬M/\O#j&}awf|X 3u#u!V7;i,HXH(cv&8>w{l~0#?cne򖠍yjʀpNash[8ԙ>m]nٴj-Zk1noG Q)e̻cEc\ͦ73ҩn=0gC:PwLm$WV5Q=L!b(23r|@+W({{A+x"@P*9Y@AlɈ/+Bsu^UMx2=#@ct6B+ 3 u%:P%aظ_z t8Z5RM /C *GnvPJIOH>K% cBb-w[clpHqjլ^z ͜R_αt1NuF{Zۏ #ŤNk9\2g<,g(~evtޱ%{h .-Δ'Mх;0k*GW։(U5d3n l =#=REc nD4%EWu"̟7",/ 5!X\[mtjhi7˚$z]̚< $ 䢠k\ %Xi/:~6MPMmcɠzk%c1\g)D-SH;nk~&:cF anW'ˠDRq {_R]n`´AddżrPe}ʓ^Q5 pCaWWhqy2 *7T^UH@LCq^I 76zk2lL_Rɯ*ŗivf Or%dc1;7zkZߐ (9*ptF&<*xW f0Mn͖ܩA;cU C@;K?O S-i+DOn wE0h7~R 9 yG`<z. 6G Y'ճܛ00fWj l D(bD&8BzlL=e`nʆ-[PqP=54ȯ?NchDΎ8?vNQ*_NdqG닃Š'@63qx(AGt^OMA 7};aˋl` 6/j}F:M>ݨ8ft`Hx~4P#=Ihq'rE"B—]cNe1Lz+sw5L%ęB jɨ e6+WlC : <΂>(UFJ;`r]{k׶HWZILI|_ڑc@p0Д V 7F ڏB⌷ $6F=Gړ0G47?˙K9 I\45WۍS+X5 -^cI}D"|Bb*!=aXh'K*tT\Fx',\O!@-ڒ l& bZ~^ztnb>d|Xhz/«+4wW:ShpP7ĝWZER0Ug,4|ga0{h^=b28gDՎλ(C{6IeU^&h=nGKN%_!1Ž޻."8(k^mlbKxzGm gi]&-ab0=GUOcKu7z( pLK|S@\56prz`^>55F* HXvgMᇦŞDK~v;I~\A`fߘnZ=PQo:l6=Nu@u}Ypl +lT^l>-B4h:_k}*q3 eK;bH집+ L]X͓"'SX,^/oĴ {p!e@ꣴm# V@ 2+۸!~'с(ϊ_VOܽXK>:T*LFQ{$m,Tp'6,Ity8E\o' [((%9iV{1!|g;ݝj+,0q-w& 겛6OV/__A`GVŷk,{Cc!mM!piƩb_G\B&ϒg-,mRUTE/E59HBL-+ EFK~CvzwT ^vv@'hsxݻy$IZh_"pZ[ U^DEE7XVs5q}5E﷛5x#?fϱtmn-J+3Lcv'`#~"}^ ,b ^Ӌ`& AD=5l쪐(WE4􉈢H2!JE;xcn% 6l]}#`)>̡l2G5å2.D,>#rf0F,ҥ#_\ph X+Uj{+0IK˯mYxڬ2k3F@tGe4 , OSl5鉧Ŗ 9 vdsՕ=xoE\Rpl5(dmd Ezmlُ1qKm{?>hYS?? E~-MǴə($8^`X oУV~=願u`zUH^!5xѺZˑ[J將Gu4சɣDXxx )YZ7WEr9u[H~iJY8QOIG &pEC&{d2kԚΕ=år츬,[څ0'оunbȨ =ٖ[fqH 6˯vjTL!D'J4BY5̵A܋*t#AipzKdj+) (.R:JZaYBvmH`&@X~Cj[t Tf#a>Q)mL*[R?} rgy_ }41r7MyzVzN^6\f]%Ar/*)A| dgmc~a~S!8;;RCZՊ6%/ Wy2/@ l/'|pea4Ś.NK'7Ltْ0PAi|qNT*bGGkB$ΑR)=H!V%0)?EJ&Eo 8au*RY{t7n!7^O> RY! }(ɴ4j|c|%)vQTOKJiݘCcfR7b(Vs䑮npQ ;R_ژ,ڎCw*NҊ>QZ_]b;@ceiE6tm7k Yۧ9)ւŖܳY\V8)hiL$PM2Kӥ]o>HokD I}dy?f bszFOaEhdUU~=m+uAѪVNqVP9.ܣU?DTCm!~vw+oH26{̓䥼84f}H0:[Z.H%%v`#m bVԦ݁ :oÁ9 5m/Mw5`<` Qsw?ɱ>e ; <VEo${}fY2t0DЉ*eOіiГSZS|5LvQ>%SeͩQfs#\ƒ:2? *]*\=%VK}rdԿUF]0LlD\C{_+,7QV}QTw5y:vI$ Al ;D_[ Il)FސoX?F;960Alvb(&=VLK?s7==FU8f!v4Zv~E$hy&ig4}A#ЂyWU 4VD‘J}?6k SZfZtVB,!!Ԡ *6*0ԧ)9}!~㭛BijZS@#wʁaNKN7Ӟ+PhFx @d:-a4ňl_d r/{vXw'e!a&dōK*k 1#Q{*8UrmuAz"0<V_펕1갻`HK؀ܾ?:\˘lij'gQT5k&κT:7ejHo :UF}U=e#6qĚ!˺Ɋ0>p309X!woj҆jƟj{>cr$-,s!#ʕEh̗"◜~a_O ڌWBH0Mrm=A#7Fh}σ'A SO Kvں|eG&3d7hvp;(H:E5Fh"WB8!givIGIQL3R! v[R$V[Sؾ8+^3Aw7+ gxCk"q\8.lq\ANڰ'{A1, $kf+ڱ1 xj+jJ5HX.m :/<`;-Z佛c!"3Xu+8I?KMq<y<}P^0囎JW9t<=3%x2k55L3@-$t.:J.)ӥ}aH #pmm'@w0Za6(!`xM.W~,4_vѭq7=OVv28QJ jH}9Mc2pڨl2̉3x!F3Nt!9b<cda`=m+ aKÖTW/K%#hb$ mpE!3v2,fp :cjaPX묅O0䅿ѐYo%HFgRE<Ҧ%6Gl":$&wYtΛ?p!7nl09DG(Gd:7eaGY4pWn$STe,w[JP4*[. [3Ј`)>_Ai)kj0{nCifqQEvQ"x$ XfN- m!abVQƗ*gP| ~o?qzcVu<&[F+6``EAviSh3UӗẻNw}Dt&@_sՔ1OI0ks#A+s-3.P% W-"Y[$ t^~zLƉRWL 9x}%2Wj@V;@ 2'j"oDSQ=5ΝLFI/,FFL]{c}N?tl.2.ݨ~rdͿr'̵ghXnϬb>! I5;%]^,QG*'/kP6h[p"ԥ D0i(zÎGg"#.n&VN(_oQn&c "RFΓbTeCmLUvIRګ<(>LW#2M߆3N!ϰؘHdJv%Kt}#~izUeJcQXݪPP1!T-,)ć(5FfsJR9B9 ITWs#4JuZ4?0lO幸ArڍX_ɡ㶯K^ m>ǯGUbyOMJȦHHMݟ鸪 j nRx?s nŠ^J?TMt31&.@>X謃j$Ukcm=6›t?;l+-I GmAl{V쁔]&Ǝa%!a՚xo/O ĴM|IFbpc{\3hrh-AjF?&K_} I=R6 !KajB<# TϟU?I-e9lWvX;g`uAHy~Gmjѩ 3%O5nNHiVC=Pɍ- _?k:UnX@hED@lCrNkxI->ҎlKlI;r1j..a!6`;c12A"+|0lt>̕>^&aKwwK #SVsutxFys[UEHwE3wɟrbrZ/* kFQmCkx#o]O/ӏZ.?yA3=gCG`QX3Ҝd&F 2ՁmDbLt_@v[#ppg9仼{> Vp>Fu3HwTR1;a#e}К@fUb uTc &8Nҏ3lDv׭+h%XW݃3ri;E7QXIjtUջZ\)Df$afg@ @+JNn :"H +v@p'Lqrs9:t5LRуg4\Q H=4ӭ%9 `4>@Ȍxyyw`MC0Zt>c`DUCĊ¾pK`-WY*H(E oH:c}!-6hmAZOUcv 's-&l~iysgi=H"II6 b%X33sz3A(b :_b`6?Frfv2pCwr-f'](ڹ ikHX4y`ڹ| $DRzAeZn.D6fd},hi+eM$zܢfԨKƧC85TG؛7vGL/VO/${jK:gDy{QrP22^2wRc+f _4egZd8Z?~6lH|m@Ǘ:3b{4{0{ǮiDa4 3Sl=8I2'A:뻰(?Ӗd5~xWHe76.-eLO&+sXH벼䗳5؁scl6\ ianSK_Ǿn}')8&c晃>Ͷ}puVv K^z=Yeu$blW\ۻJË)) -UGO9lű)a_g -x!;Y [[SÂYI o"%},!{2ޗ=JKREWR[2/b.ÜSw*+i{ LbcY )(hcӏǕS3ݝ9~|-3W )i' L7"M_{]%Ճq0'\hη'^K56iw;7@VL]Z(ɧ("a5ꑭqo7#$-y4uhpɃ X ڣW*٤8-d lX83W9/u_ʠn%00T(x޴@N8y6t~u|(嵅A$cDT"Z<ﮣv‘l>)ji#b=ȬMyth9=GڑيYKi>T={Qe_>3|$}wv'!6j40#KR+}Rlug`R.'CuЪ Vg莒H1Cڄ?:P >0+.43վ z99 l8cS)X=@xAq.%[$OŪϠ `+GveĚ,3 +] VP$FJ,k;YPE@b -Fm8/9(N*;vin}awG_Tr\L OnU=Xqg>$$(G~MP*06pاa} C;0aO g^z;y@#ܰ/PBC cWIţL*!63ˋ/%Ўqb䈾WzؠjċW- אEv 2- }fM ;v;6J7AǧPHyԴ6v;oW8rEoDn6r ]/ra'B0'1:ə?DӦ "k4y+]T:ld@3C$XkۉrV l+got&x6~}f_0u [1Ƣ+ֈ"DEPT" q8TqC{[W),l_>+7ao62?Nf{$xS@©CNdw04{v\\b2x2*Ud+`INUM7v ׌~FM" Qŋlʂ p oV)T1׽O0ƸS9ߨ ~\'$~ A 5s6"BjP]da.]cP2t=Wk(ZN51#q7.^} œ519Gb|վv9z "GBP}Wrk!?UjY`@R ޼/Ϩ?pYѩoo'4HA 0&D 5ύo8ϻm7Z) _֔VGOexssM#3;I5 ZG׀bqZGOOM0TxLcp2 k5\_T@B:K9ѡ΄ vל$#ȚT#uP(j 10m qS>1W$}bqa@M[.(3$WL7³KY%-ji&O[KԠTfxm2^'{BfIbQ>A h\@QގVs6tcPzz-蜟۔ݤvB̘/*\}mOVH$Vg,{X{UMNRSK$R:y*5euQ%z>,y:XxfIθ5H4}bf>"yW[y>Y6?M/~4볱dLT9XLi[v*Uac[\  Y+r)ټPTZZ󓼮-%T>;i!7j7=`*-&kXa͔`{rzhx=^v^.0{}B(?8NJv;Jzm658D٠MfSDC`D'(B Ց\hAO9+lzSR"uGr]+ZH,|%S_EF0STk.@a[UEʱ%LfTX[Pkio@U0r*D坸8 C2?'`rjBsO'yaN4m7ΒWTd}*>?̕Y-3 PtHzwwڗ0q^ (F%;ݴPm[^(GOr T$]uǺ|#-T{vM.Su$"ezn 9351X1Jq6U_8%XZϟ`Laa;tě( ^'rc.bfD@:1,UXA2;I>%64|ǵWґ nA; 0,wrקd6ri`Д-òbP}M+S6p>A IpDDgV@Shl;/BSd=ZL1j`S3klx=0'b@JtavJCO(bƲYo /\%|Md6)x_[n#X$GIe%+6=98۵@&(' 9dj#R''$:cЭʚ3ñ(J V) (x%p VW: ;( .jJ$Hk(9<U5/\_אhڬnBgz+]j[jϑ1EAދ"$,,lBq2i*c?V&K L#j Oϟm㙛֗Wd Ľf3"ˌd f Ttŀ< 7Kk1P$ݴ ܽzÌ7h~Bh=9Hiv-O^m']5dLNqj gTSI;o[\:\.*^$?V(M0^YVL\7ŖpG gRDfX! Vj^!ZiC}#"]GI@<#'B3pb"T3t,ë@ε}hL-N%p Wn2Hit L۶o˭:wהJ۞UGh(1(RZkBOi2iX;xp4(RJ?}=Cu3V-lǧo|%XڏbV&X2{Y8m ߊ]wnʁzgس>NpMG_JZD0`z7rMvcseu&r:'N2'g:!?6FOb#>];S]CH2Ab3s%69}rl7BvOu`tr3tu\V)`åewqy 63袾de}1Gk[>V`:".s-o)2 6LbPɪΞJbpFy-#ۜ`HYxq`r ,f3YUɑaO]AW89%z^Бj= ؟I%%xEr, ɕ6ߐ趎1|rm&xACN3pqxno=οgo%1ve)惱gnH&$CT|?k|mE* Cg s\+e\eaˆ[#T T7k ]/i[p̴\d.U xphg\Vkgc?ﲅpꆤxT[d nW]-'A mK_{$&_ۮ!MʺFk0\hύN*|ka TYc4kSN Wi-!N%KՌ,vo3nJ{'?V#K6WݠT}d0u8cG|ŝՋ*2HD] U85ȼ?R -~Y~-G6Ư%H΢ qH%V;;$6ltKaS`y+?kx^:pP\yd(#3b:WQ4txi&|rηW! ?KxJRP•)&jGd..ވQNJUDi@zhߪ-81A #ho8Z {2d*s?^ DYu9/ ZG~~WlWKHI mJ8OYtfN(QG:~kYRd68saS |['>4 ㈓CWE_@%pϖXZ I|ւ:.BZxxDYܯW_仍^L}[I YL "PPYk[QC56Oq[@+@|'dȮr%O*T#"q;ry?'~ h`mP*"6ȆYp̍h;($izӬ73?Z/xC&vD_SSPmuk`Vc8`şI5}K+ޣ6٫N=r|x6s1>mQ=ɳqb5H-dl#q`1[?r*@vz" T*'~GqȲ('.AjpC$0Iy.chzQF3Do[Q&swx?köHOcU}9e:9^-bF[u MBڱIAL dz1tD9WyT`Xpd4?wxqFGm RRKP.37m7ތ_: FήQsoi9qP q߅lwaJm&܎H&Wk34$Sc*!WNWӜ L*c 7jr@Nx#R6ŝxk>1? ee}Ud3Sۡv5E+4:ddL"תo/f j |% n;:!n(eq]_[,x0W8Ep`+:TqqD$˭:6NھԶG;-8 /ӣ巶&cDT\1ϛ-{i>TpJ H*.hVpx;WO 7m&Ou :[_ODRG *S3=B,(gr!!GE8w틭]<ǧO.= G# N]RM6;gK_6ʹ< 1{ p2hD͠)sz\!_{7 t BdyZ'{*ת*¹cs_ش;Zqk Xn=kCڒeW {F}*G pT?BE3񵮚3SZA{ 8ɀ7MS`۝R͚ӣg]C^hnz#S@ɽƂO p&04A>k_Nho 1B=pZb;ϑ Wg3[C#[m&<C%FxsEG k &7B(ȿu& $||>Xڑ.)PS͟-nN@HrYh%;CgeG{9TxE4 KPYyTG &;e\]2^_}LEnchYxKFAcDC$?ɟTF|1IA7eky㖟I*m&90\4u`"ձ7ԽB\ ozv}sYn`PmoRN}&ϗ y, <5m~rk)vIbTܫ>3Pz9N - Qn%BDOW ` mDurP&ؽ; ,7 sv)19E'5Ґ+q 5\i!҆&lGPax&pz둋$؋ӡUoqu+uh| 1ͧ2;yY`?@K)BElyA3Qqe+R$ڡzd#7-AL\!V*t8)- T #l?Ҳ( /tfTcDIuD? 6fl?>`@v\M0еNo4cv40t<Ү"}S ٴ"8Risծsxtι- {V]{jϵgu~D$+s?falaSNz?WGb3ܑVLCt݉ALȉNJfM<>Gc`IC 6ƈDKTFJ?%WN5~JdI=2?MɚGm(d'E̔2 f[4'S v5YrB8AhLE=7j^V{=Q+ûڐVIWvn&p' E>$X)eh %H<ӝ8kQ){?!HP> FaK)#- As_<W$\uLmrB|-|ibܡ1?&֒nЯ# 6ޭ7,U? 8',ڐĶc#$Jd3E׼G,+ugm;洓*[6cJg=Gaڪɺ`[S3l.X`4]IG_}P"E5'$G!lq.h,^P9ipnj1H0bDb%m ÅIK5D/@" %wj"r7?Z9HpʚKirD'KnY=V _u9|Č/_ح(ٶ E/ؿs 0Qu=T <$ETnrdrJ'P ȑ*_t;wD%@}%ce$7ٙ Ƞd f+g8iD倍q>{v-ce1 gevga3&CCJ Su+ ~]szrvO?m"]mEŤtF0DG^% u둙Xts،ZoEu|U AGoxrϵuAFPf]ր4^꫎j$ğPHKkT|^*x(7ڳ|s0qE؎I_TfOѵ cti~&m!w }: #b#+fKg8&=XY*x b"P&UK2Y %sqBZgi&%Fs vY _CI}iRAȒiwmA[IJ祐uQA]/7s٪L}JsTW")+-Qwz潇fF0*! *DQʷW5e[)^pRs熶hLgK!;xgbҙ)͍C~sYz5v,|,Gl=Heےj4)@6mࢦU cy4@xE8:V=*^'AΤCF,~xaug-+pw>I}x ؾ*5i< qb QC6DGXR >:>pe&=;Vbmc-[@k PW#AT^EP`A%@W* DrÂwpIx%mύ;1c_ӯ֝4hg"[b vHTdQ ^Kf'"8<:*אϏlPZEJV#C|?oބ*~љA\þ?*-z֊u󲺜dČurq>嵊y])@X Lx%zAma+G8) v0(ʲ=sc3rn_U@4iB~.u1p/KE0HxG{آf|. Go{W$ҙ!ij>=9ݫ5uGEa?ցJ=GG ZU"%+AF;w~ck4j&/zT :Y4ґt BnZ=wkoI2St )X6UNhxn 1\Z( c`pj#*YB輄GfVKb +0zּc?\ocȃfctY 6Q_}M:3@{ؓ!wteb/\x}zY <&BG}b -R7V pvjChb@=/4v1ғwTYUh7 ?!Hunוc hLB,/|UhK.W(zoҪh8~{qK(93nLm̹dθs\lݞ)˜m">)ݰ+3T5lŽl#=$aU1{JNȎ90rK"f*{(򤍙K.}e /֖gM73^ȼ ;TYb~FH'KҊ {"zA͵Ƙ'L%ٺ6掑oi+.}iq? u(&+OG "5|R% V*}BQ k_}<VzX\)BLk8B׻xCܰ\MRUͣH|8Цi 5DŽh67lH{^[6f'anc'움} nx١(XT]fy<Wr/V\4}O~mw8(;tәs*+95ez=l~Q^ǎ܊ς2JЖlr" Hך!SmEUɢ-}8-ى|OD"T :[8 ilg-K H§ /,3gF-1xbKt̔ICr#Wp7q՘_ >"/yIuP?aC2wZL06(2or(ڃS 3GߤM!lT< {khhyPBp`7 zt4yee f Lڳ4#Fgs]J=e8D',%3CCkzY}.d+o{^ UAPknS|ܥ-O79P/ih fr6"-M7JE^׳3BA1v\L{/~\3=Oŧ'\fHFKX6E긊_LsiA~7d8DfŽov.i`͠⁡T[i1CGĸLZNTD}~<`(%QLRr8+!`:y9&fXfHBHM r֝)HKp沈IUCV \F0; 1٩ ŋ"L0`ʴPlzhJׂ % I|X{X4uK-'P^1Yii:ChR?xR*%;mҶӽKub9_tΞbJöK#AK@gqW.O$^8|I?]sآc^=9-фCs-m Or4dy8izIVoMY-.<&#VmDp:td3hY^`Zub5k.~.T)޽v= )Z~L:P+KP߰/GOR%iBX$NE_7%2XH`]ܖwc,^VHD`/@UxX&㯔#yyV4e%Ut~Q#}n)Wnid fà|sAK cENjZbL?^ƃT"b9RL SӋ\3R_X~&W4r`F4ҶAms,G>r1-yo\Ol'@dDѷ<[{a/ [£B\P!巜zIr?ob tT;[@.;"?`>P4 DQ+PIۛ "ᠦ<3us]bh6Lq|Wd璎fi#00UpIY&ݎRIJ\u/w Z{u7ϻynË rܶdcRQak1^j:Nt"RC#ffVWt}Ys ]f惩jlAc-:B)sL+_==j3[wC,:e}+i"{p͢gk}8U.W}XnAOQsR+D@0Y"lPKrsSV-r[9b?oa%W@1 va\.YmR%.d[OEZ&v+F 2ui'V0ej?ҍ_>=4 =|,_d׏]s 11 `X[Cau,5r=4u} Ը~ {T5{i]Wp=V`s J x1ӊE>/V<ߥ-}Jnơ7/_ĩTp/O TƅL5'SFLv(gyӞmהfO6Ͷz"vɉ# Ñ7mW_B=[ ùꂆl.G~XP#wH 0o6.!-Oߥ<;bi6-W _.%P%=ODW6=#XM@ +$.[nqNU TcVnXcO!+U[DY5X>FZ2M}<'zXS_>.MTO @:xD(Navr4 @-TC{#tkqlqdoV=j+!u! =~ Kr<|p@I99A7BOݾДKO<5ʉ\>k3F=oIa$ӑ5NXM*@S֗X>fq)d܋vIIXF_mJksYcNOC-o5fI ٚ;:gBZpdrsW __7H Š&v u^{\sF@A ks:ywVk󯆬 V aΖJ87F~h۠a5X &$V30aw{ TB8.[qkWa pz-hMW 8}ACC"Rˣy#Ex^(5ȄC8WO~łI! !Fvk~QB[IU}~X#~3E6+Kr^Hsr[Bo9惃 xJN`zh\P E < 'R;(=@̅ .I}{Ԕŏ݂ڴb4u6T~*/78|Ph7Xş&_\>gX bÆ[ᾮ Hm׾-{k*9~cb _Ȉ|iJrH o̤32plS)ucr ͷ>a+TUӌfZ8yDl{ԫP7Mir8wZXf#&:O^jÎ"7|,U":6ZK38J>MdzU+AÔ'eMWÒ;͘*$MVioZ3;oo0К UR֑Eykn(TP'p{л;ܫIZ#EUKu+, yZ%q6=N GAuw's(:dqd$Нk3XBk&cф8 NʗwM8B)Izԛ==E7A Ju\.å7gwm:)Pl!oW꣟ @DB/Ll 7'"p˜P#]Y 3l]q| boCسkQ2@nփqAg5GkKι %Ce\zH]4b7D9/TPyt:8k.5(\TݖQ[tΪfݩ^af];nfO!Ό+OnkkUv;Rrp3_PB)rL&ꮖ.ѺD焲{\*K<9Ն4j9:#@|͐U3:06R+P.t9Y>y@GE-YGUQ÷-ΜuX:G[#XZl-۱ъBNMUn]u(g3QmhD u=*2r"㝡9WRZz9pZ63o0Mt; ~E72 | AJ3(DHM+ 3-䰯^rvW͵dBUmsfRz!sIZ;ȞXrWIe!`tᄮ~l dtce+dKYa qpF/ε@&xt H$T )8U;ol\ A%oYR;Jh=\$oX?3:4}(t2 u?D nA8}S%(.~_IhCdL:Xjjv,\1RB)G=^h0},p]Pt,RIeViQ/q0mFhG,5ʫ@3Tڛ%{â~1k_>"-"n׆.=BT|}jnz1GQ M0 ._{Ȑ3&]ȎX'u(+-o~1 )رǞr%-9zXn_Kr]NY87=)ߵS6G$j/sEugxD[nD3r  E,FdVy=Dt:d<0"o3ø!;}〕Ys=Kg89I]Lof|k(Y:ɖ5ώP7-N]VAfN`$.T1zl"KY6gDϺ( x*=#DW~Q*Rxe̢$ҩ]z{%K2MAd}vbp]t QTцdmMxh|`|kJӬ`,|)wfeL*sq\nFt6t;JC=KϳlWz+nj_𕰞$'*p ;aCBH3d 'EP{ *%6@uho ==OWJ/#^rkbF~:UE$KuMj`exSK%,AнoxR. s_ ={#% 8JTyv"6g' cO]wNr9LB >vy$v Wn4txDm&}_4o`!ƙfh䈴00f6 Ǭߘoi] 3t;hg]qѺߙpOlğX06^?uTD",5Z?ƽi6[*!۪I ptIjw/9IYd*ZWmֵɥ pG{zΦ~P ;3J]@9VS[64|p'H&\6Q'ʖDlf.ἠ8R;Q?sJeDK_zJwfm]`00[C=y5E"G>yjICHAf]l  혴sˈ+Wg4}_QDafGNNUz 2v;f6N]Da<\)t:W:4E?:AH&go(t?ÉRZW3/c dibMXԃhiЫTT 1Lp'xuI52qK˜qc/>!,[NyQ;YO 1,d:41)Of$LyBsXЄP'{:iعJO!Eq,38ţyZ(k]Nkfl![yҖްD6YٸTgB_^$,O&vp xoT9 4D,_8(sC nUuRn KTLs}P̾RVk@#]r pEJ{B~N}M cyr`ѦoK|hS$U)|?2W!ޭ1QbMJ½H ؉!,JMxk48Wʈ!ɕH+@e%,_SQpLmV*Op~~4jQoS\~ Z-:V<ت"\I R2ٻE4SE6O[G8_[P4i!X ;F\SS{03ƒLZgr4EU/a2&RKoTDu, 'CIuA\&jpWa:2=F #7QRBZY36w/hOS\s+2R [0kQ8>Bjߓ +xiV>jo1|z2ߵaЛϴ3F+Hu`t}Q"ݢP^gͷG#|\.];26-ωA@;,Rq\r}EfY4(dCCQC苰$ 1!Ljw [YFdO^7|O0lnv.z]t]hda,˟`]$4+1Ɗ/!i)D %:/ ]@/X%{F` *9oLsmo`f-"QDω/D7`VȉL$N 4LmMĖN`w OKkO9T+q}>'S9Bi(%ΖzFj{\Q2:U#K,8@hV$RIjD}Ik`[$^y07 #^N1Xu |8w:5Ƙy}%0\ZHf\پMLcn-cxp)+8SoUzl=:;C"8OXn6s jzS"CrotL-|hGmYj_Td$ב=8[,tydy!-tkN2>LD_YvVf+ҋE3.U~/W;|HSC9 VXe3b*Hե Ju/)ZrjtU&2 1ݶR&mAӋs0P${)xbΟ>W춞\"ZQSD_d!՛ACXm0[8A[W)*a' |i0Jan#~!{G}ЈvِJs7wt5s0e >!d;RnMk7t3u_k8xy~9IU{8QcR(>$Dz>L Fe-S -I Woby%q_= CݢX膚#Ҟu8IԬw^ [q^MFm5](#XqP\~85a.gZΚ xN~A%m=Җ*\4H]ӝTbrl`wJ%@ia:[!wy ?V2+v|)jD45Q"OZg(e?`,∤= 89HO+P  `pJ-oGK)fd3CڑcjKc@z?@Al]2ǖ  xh pQ9Zˆ&c{fc-=~]$՚Խ7חG7umjQ OE(_RnKl'\%b404|vٻAXL}=.Y\֎jFGAǣ{q}Yz\H9N@+Jgavy1 ZxtGnFɨ9[I`'[=MqWRn~3śxdj߇>`!LJtvr>_WhQ<#* ".(nu SP655K1~ֿsγyst\e$%AOC,a W"'^y>mz ų"(hog ZN* VHЂOW<7@M .S\%*h(Ϯ8$Ҳ|9[aK䘣?_ab< l X19~1rV\uxGֿ.:*BVbUUON%]n>$!~zA]fLCl3N*:Qe&BYggAkX[NJDsdLy>4G}Ȑl8U9 F4d[Dk\Dp% ?l*Rp]YZEܿE5Ay:g06lWq-G0yQ/$w,aQܰZ#kq㥯hEC'K/ x>G4G%*fJc2B*Ls.xl W_w4v(B]D}f]n\h8M;3SZ\a%2|@T{3{8̓EK=*:?67683s SvcE4}ziPeaRG#TCiѤC'@tb6 zt ̘"gnhGL3?\G<ϟxKb66J(YfyrXꓮ[zqs:::EkJ+xBQ>#8>,+B}푄PNcI,t#Xdaj+CN&s>㘍(0h`L( ĠmOgUXɠl:^&Ϻ"4s/stW$7`Mu$h,?,ɤysQ5?J^4]K+\ryC*! |-jxŀY8yk_ p7#!>Ee΄kK#7YuO(`W.-i3~0ڑFOz@JΟ`O|*RJd[xϬLPi(i873mqr9H"PuF}!sF\8M/xJ#T'mrvRÌ 3<`"ꄇla>"uW`^bm+pE?Y&M@9#0 K0^#>QM xr34nnt 5UUGDgĄ3Ԩ|S'ljo̎C9F/7sC[piM2m 9=U3Fj; Zr9ZS_|)n"y.!/\^!mw7#+\Ty#n__xǜMS*I݀0mGrfx`!Ɋ {mI;y_]SClW8Miuj'G+i->8J޸ J GfWlR3l<%tAߴ:r?ݧyXf% H'Ņ;@>[z2MSIDB.vd:Kl RMoLLZޠ2`ͤ։{)v@RߺfY3B]={e Hv9A++DQIJ"fvV^]d FRX.Ղ@kWzKv48֧a0E #"߬8o2q':dbbPs ŶQ?6)SfPQ8 s-s L@& d:a*J>swꆪ"B1G]( )9#W [( #d2ʲ-+lNeO!Z \}6,<8FUcK,Dg)Tt`QR9ڀRzSJ{2l9X3 N+' 55$WVna,~r.6(7)؄-Wr'9wԹ @nLK]<0.l]O>a : qcIӕ<m|$edKeSS}ls4;/O݅c~HsL tptA+9~c)&tU+(_)T*Q.(00ksg:/3d Cjv$n(*ä5] $ibf }WP'|b7\ AH| @m/LXT- ^ܨCETxqA:ߥgin%Z`X&F;!`t5 l:\B3FwG]W[9c(P/4 ԣ߆&axڶsь`hm)Yr#bܴR+dH ȂOu${9nEE1fRL?YP1@L,&-W"Ut#tN< 1IC?Po^ʊ+AvK֢ H X# 'Pl9U㔃S7=3O9;5hc)T"+ m{2:, 5#˕Kwݺ銽VGt2KģVT5=cMgm AK7Cެ0F*e`1},˃#,&/EO:{g{&+ F9~LM#I"J 8C٘K#%ĭnySc}%%v42KB7=_[4`7LCLkS@&꩹a^h*qG2w䰽ˍe1sRWdKCxpTZ(mTtv{DCWaU^lB!hʜ+7ѴZeNmR#l+>w+Oc9R.slzmaC?|\d̻<#o.?L.C ?ۼE6Uˊh4ۀ 9Y.| ˄'j]œ2qa.|Va^pL6>LVT[8؂o޼: W#ȝy*PՄP!yJūԤa٭WZWoV`+|u%6k?*N]*tLi,m v-Q~z@b9̠#^%+Ej2"9+P[pq[tk3]M\6P6:ٕSg6^c$3Zy___?3Yx*u=C̿o1jt~E!px6C,Vaˆ;!>M@/^PqOUfR74\2=Xe64wB&LE':&V$J&BnMHns_v'FTEj|2Rx'\Wt3\{,yjJ z,2P6[erOA8 : |=9Z Q{+r<07&#w(-W"y)zH0@84MvRuon{pUsZLIemn}kHkPi[It2w_~+pV {FOGߎ4"icG] o7Wkd6M[fk+_:w=xy]^}Ϣx*PBle*MGבG& h4\d}k\Uq%1T9x@cxxZ{G^uhhS^I5LSI*k6_pZV?%= SxT.lP ܫ]AP [>+:m0Zwǰɂ~&cM!6覢!K<;XI懲Yٴ_ߢ+ BZMF%êq`mm,@+G0jn0PnM~'SE m~k{Hj7]ke'"t[9 K9x-`Eލ>I>/s2᧌M$#g'hdQ.v"JVRޑ_ mȊ@|*k8RvY̨'ekgy`NS'ҿ<6}G^_7jHhi?jf:24àٳa'up C#j<*U$~4'(q1~nG",9]Lx^̉CuIS~@Y hf1-3q=ځp+Uj%U9gfG?3.Җɪgr/GE@,>X]!ҳ^ ΑY3DLjkZ _B*k;ܹL X}Asf~|qt"¯ʚT焵/Bujv/ק2xY.<&9q\㇂\fZ.}kPITr6" ʎ{xףZK~5k}YOE7 ~Q[.Iq%vf¹ i x. Kr;kt 29Nx]PXIQV{=c S\ 1= ;cp#/ .Z'Wג;z4o,n3f|q4㫛}63kVYI:8a㛭l}x;nj08$j|?%f$R <)hCi$B j@s/MoitVPj+n.Bt Vᘑ!JP&E:|-i+ > ^dѬpjX c4ۄ+&Q Sl!i'wKY-@Xc(OKDQ￞hciI2)H"5 |}x{HhQvZJ0ޙ c7|&,T0 ぼ7cS|_G)/ݴ##pU{6 `ŨvLv QQ=&1m頏)X`\y E*2b{&V>> FfU,^_Bm"?s+*0)it*CS (A+ (Ϛr{r*]k.3{JTÑ|   ]궀+$QJ6#GɵΥ̗Fa^k3]l:ڊ\e\e~iT3I{FםZ\2[ '$mcN]}+[RL} 1& i|}>ZOޓQLvؼ9|tjQR!(pNb(|I lL}鸱i|rp/U{^ *G + u{l5ǁCv[~'eB- 0ETlg".\6#u-G(,O'^Še4l4/qP9dm4vp;auh/[34 d ($ޣ1 ;Wc3_V/fBsFA\¶f{Pw7BPwˊc`=)8  L0 |dNT\y/; _FL~h3w ޒoFII{vQ6Ԇ;d2qdͼtǖ \ozGvp˭ۨL z||;3u[bIO&NXB  ƭj, \}AdmP# ж&W1oj&S%!{:B,64[sl&3lӛwv+A$?=Bo휟;@' |cdJGasq#y5s,\:*t:G!|k@Cn4oBpw Ӥm-= 7Ch`Х-Tdž%7LL&Af)3*aXEoLEGo-Pxw[V3dvP$?Nf(3!j*= n/X0xGabvF0wh٭5h&|ޅFD_o˾BdYKY/r恒X e/e^0ua= 1Ç tMxi5q&F:]1"Ul]ۆ%s&tA'Xj;4e5 "(-% W3S M_b8;|FMа,\ ofW$JR4"du"Qφ >mWcbQj8?8—@0N3bhRz=Oa4W'#GWghdxl O)ٙ W4ɗjkRWS*Zק|VrH4*l ʘ?2M! Eׇ`>y•9) tE\ $ g :r>|U临[hyAW8UB8yeeپԈpdш)vv|Iob9 ! !UCˁ MtWD-;#o`;ȞkeW *T!YE1*ܜ8DΉ hef=|>OC z>6-@^)Â2Y €!:;do {6":U_ɉIQgQhsEb- ]5y&3n@75agxEeE By aCbi^IJHeyOf]Sqpiw/^7%n-RhqQ-nOr"5H NGvǫAq@|GK0V5IA6]o2V./w2³d3_En%j+ӓCb'ki ge$7O: Gж(TH]>MlVU+;jy̞[.ŎQچbb@ǐaOO,x sǦ^\튃EVF6t_ZIՍ.Z9 9GƵqo>D ,9[e譾 Wg`,/e7@6'?'}^#U;Śۋam ͗17'NVE 7䩦 Š4: ȗ ɉW&+/pR4g[K~w} l̉r QUl0.N" ʹjk>Ux=.s39%tz wZɉCV- :{& c}|x[ (T,uF5ޚ$fijvU<:mڿ N٨Wz ,d}c9Bvp10Vy/(W$42Hڮ_s۫um-?"Q̡2=yKMmmfdmg]jN2ang{K`~ˮ3GQ$l識h&Am)_]]Ef wxe_L7tNjDu bn#m~p Q JG9tf3GOf~['WQkPN!#UEHXy|rr" p ikވy>~ SPNy Պ+7;ˮ?̕Hnb޹q<|Ґ0/ef]ٹ yG[EJʒwnydزՅ>\|T6&c(مid (&м~rG$js"Z.R.ϜAj|[bbco "CVy^_H|([S$s+k<.ӷo4VE-WYsjS ٽ's n0Bݲs;)5*O!0p5/I3]'_x3|MB~38RTmgD'L?o|Ze8b|u,Y#){)5Y6f|X$w2)wj{(.W䂣N[c|=f/~l*STH;"#/G,AYwv;~Fԝ崃;M\_hxkGߚHrhs;5WJh)ܫ~5@g:,ˉT`Cܭ\cY:A`W]{2f톙&"-&y*EZOz N 2˓L>)DNnkUV 殐 >vYCSgŴ3ʈ]PGUJ"vgz m@"-XbNnzJ19p7RWjW }3Js;´c* -&+~Ĭڲ'n%I JτB0XW dyII^7tL[-t,YYN?I%;ۃ,"r GMгjP ?F-FBŃocl?(^|Vas{>p+D* l.t%۲I%¬jGCOdyud?Rk ۉ|E`^}TL}̚'_Vn?q{ ;׵z#+ "Tci-2UQrфUh!1*su⿄7??SMyBFCR(pь6@/)\~v_D!lF7 XH>•sy|>"g3yaBT jȍ!rzJ(_򟤹`*y( 28B& 9]0wbOChk*a٢)*vZN8xI$82FuѷW,!@#۝`wlsTA7/ f1rG'5 Ox45@R}ZV}p r|Y7Aؾ!WB [0|NЎ <::[t5̞s5RQ8A[/FI|ڌ`ZšT3"EK/ٝ(Rdհkƹ/VuUCH -71ߚuh=ߠɄ+sTr==8cX)u}8Q%@/>T7Hى:]DEWNçb`?:YPIh8PGg㗀{Ua+iع*uN> aeSaL Ei5Dݪ*my`h\0iw/f-CRZ$"4INg}Bzo;yE",wFy&H`y&A;9,@!eHnj{uKN-qG6=/Ѕ{TXsbuU|BNtڻWo~VǢ7V1’p9EÂT?*@֖\)G-ܠ,MګmE{fUh`Фkֽ(_{=|j/:qb9IʉY/L^V\)z *YR+?KdO|}I`x!7y'˦ZG*{vVm) 1$4lDvVby#s{(F92`(dL H*nw֎! KV(j[|LMtG_DiCӞd! s nZ!wh:if'*9Y?؁/ELޅMꎌx8x,s<K=8aEF$eD5cv\k"!qHw]rF>$RXr҂իG9K% S| ^3j5^*6gˮnP)ÿKx 0>1PŒ*Lgz&MNuPWlH>a:bf<}6z= \8"+Vx3 VKW ƈ)<0c[ 9LhOXkQU竍[swRH]v*Qc{dk;q+V%J=Va#e@8NֳthYoRQEi.n 5+uEwm]7xOD=+k]%0b”oOa;L,"ҋ?Q0LroeeA٭]=܁5aEֳii(r3 ]vs iQ*VmM+-m0w'6$2ljɫDjzS咷|s 5OW3K9 #(2xiT\w+INN4"vaxL b|fS_Кﭴ30\,=Zd[^ ѰZeZ?s4`*⹧XcfCB?"MmNh_W|jhng6Bz8x#Z#p`h/*8*aۭ>2EUP`HNx1IOFT2$W^6AIMVbĘt-g2L/@_"Qb/!|hVvT`^ّ&`6B])6 CK$8p#-mwR;0b4"v}Ȕ?MNU]Ɣx+õ||!bX'Fͯk{`IsKEy3mM{oY{ x< 9َFhu1: p 8EjxؤFe<çO, 7·"72:#r*|"}tNcGC%7qEH9.ٲ!h$*#_k=d⪪9eoO[KP._X۸tؐ3íMleQ1cō|n8F Vc-6IqKo-o/p6]=+9DVf_l Q6%t*a>_V TIH#3~oTyM :Za.Xn}-}c`nFuDg pQ*x\W+D[s/k';cR@<ucHhC_> W q*>y|Ȗ),)79M@Us1-umT e݇]3j 19j)FL D>8)JˆkZ;B^u3Dط(A{P.lEbi6pđ"LX'nLVᑷ rM (SRéRN8M1G3Rav/4 ?t|e;~󪟯B1G$`xqw&BӍ~ VmaхydG0\I-SC*pHp &?Ba9'r(K%#RB˶Kky$vu_R=_C,u+D$n9Y^[ tw;ֱQ&[ҲK"оl/( EmEzbJ~poZ%jzl>{2j ga7ŔåQAS4R"h@ }H;Sioflsb/p{ʜ@ڗ\͉ɨ8 ƬJ2p06 ՞K&<j]H02tEN}쏁B}[_I%Nb>ڛld|dO5&Ӏ4{?:IܟVZ4T8k 01f*0>ökQ)dF zj>2CB5D=C=jNⰊ2u;ӋQ ᕥh̗ Bݲ*mS&ZkE  b_-5kF2W׌=)mq"Pb›F>GKz zLڒJOJ)D17#N–;\6~yA(0t>ѽXRq=*)Hyq5DrF> G>ٜ;B%͗`4oD m0mi]`˜$kQRXq`O.u]w~p}AqZ_6{ƛZ+mUO>c*ac%Ix׵x¢`&x6& A?LٝR2SdUΪ@bDȂ *|+x Q^+Z_8 /6FqtF:0Eh3pjŻ\&–p v +jۓ .0x>;l'A^U:4̫Bes[l,v洶s n'\>_0S|߃50ɷ8xWZ9O?UZjاXOjv4Ƿ0v d/4m؊06VovD8Ɂlhb1{ IxNr+u#E57̆E{CϠn&R/Dk!+ְ'H]Az`l/M:!Aj`T#X=;'D>4= φSSFXz4uKZV3mWaQ|lǤ~In5]f'ˉ{C.4\2z`hqNI]o(֒yR"8JæmXwEo5gNHI"M[ƎP8ҺU׍7[pVmʆO1UPflȿDx؄Bf5\RHtLQw҃U]XX lDr<~N ;AF52r w(FLf׻?}a7L0TG5>iKG2no XR6pkL _I-%ډwZmԽhOrrǧo\B&Evx=Í v3 pB"HƖ@ޱ۬i쪱6^\NzfHŹdU$4d0qe1F-w9@ʎDaΥim+v]L0X>ipJQn]%:6QCZNڝ6h#+ɦ&9A[/hQoSW~AJM8k-KIPrUBĘ6[GTbA' P0^m`h)l uVP#!&WP3LYl?:3<ֹ.Mq䱗ڊ{E(1KL{V? lq[c: =& rۡ{2NӮ@ST{ `K`nB7wg&Y $>AE 0^E| z6MlLԪL}F@)#B;Z0nOnb~L %{ \SwÒqDKIlwwA橺pgExGQ l74ok=VGRR׏.3>! 5ȔNQ(QqT+gr lK7e D{6}'rm,+-%E؋QncDWP!f;`m }%gDV@D,5E2Lf;'A}$w 8' 'CÓjn5NJF  I*"\$W  u*ʙ0). ,!J ކ痒Dhŗf)1wi23[C?^~|N IY)S=w9<WAjXdma[>},Oq}>aHo/ܷYDI19H6sf1r6쏻Gr~$ -0 W(re>'ٰڌ5[pU{5~X E fP\- sf"BI L`M+qmy!S>*4uTyYW^vmerr>緑yv{stƛ^pu#xKi@%Oa\bh\6,d t >`b5t2/}6Iš !Yɺ2P%oDGl-b*u;xP ]ulDIqCP)֯4ymcJFWcIP%2j:?Mۃ[s80ź:v[3?E.1úl/rNly5$=^pqp,N $[3<׫_RCHXoi8U\XY]*e6|f˚1{fj *2yq{Gg"W" Y 5t2q?CaR|W0XAk1tgIq31i!*u؂,Vp~l(po,?~[11 kģzAڛ[gu$C]ꕤa"`{:o*&@3MQrP1ü{4dՓf02"jGQGDcl]1ߖp (f5l&Lؙ0U0Đ*"7U+6@OA6Qś6McTSв|wxz0fE @WȨGU#fg-;ByCzQaTh(E3ᅜea(AYXi @uP;KM?';F ge;V*+(6S_TpB'Yb㖀g5ϱe;%W)[ ӻcW3Lpdkf}Ց<'g"vT }T 4)h T$qGt~CRI2L&ڀӨKN3)qI>abuKQn^ 0ol̹(#5c_֞.!01"WYso61f9qr+B? +3LXx*~e | zM*@ K@BW>v<6P ^`$+mN1CS$騌ZHQa?#15NYA1Un]-])]J;uQ]`(T %g0=` V5cQ4^DNOIE{bAqH٫ohCBnyں2Vɝ c ыGFl+ЉR#|ДV򇞸B2/0\3iCaKU͙ & XjTygf !Ǿݸ;#Ey\ Ye <;;J0YcuwM< '#aw 沗z>F f3aY^:¸8}/ƒsBdJ( $Ыj̐xLOJ+]l&hR˟rW죲֏hK>CJ(HD=E[Kc~݁L3~_IڞxS+, B-]i-~qޕlW­־J=B/BT@]O}ԝ_=$I`&-$G*lSNNg s$^K1)/OCAQUuf`ޢ'opG< ] wGEdZmW9@e'+\Sb?r2x(|~))7%|hfqn@ԐCtM|)Yw.GOo-MTDgXp&ju/r| Yt;c;(NI;ys_*Eku\JiAWʼn9cx'N"V87ڣEworn`?ꔋ@ժVN4vJA3˔5yPʋLr qoZ<$vv y'\)]~(ǡ6hN@C'˾PtFRA I7&ϿN$vAeJ_}_mSVh M$6^_"vELߖA]Y4 {G2 w0+^$%683l-6sA\LE^NEhȇs!6<5U՚cMOh6͈ #,}af6~vh1hq>! .ꕊf z\ nF ]6g^ZF_fjdjP^^\Tt3ZcnXl śQߝD?g:zsJ9•cR,+КAB %ShiHĴQ2{c-pMأ-iYiKjt1%0eƷϙ[f)F4i@,N)+9„NTגQ[d [GVԂ[I؄-Z#6mOEC>YȼWL/N,e+].ɻ E3<?31h@ߋsz(h4d][xԔqL6]Q߅_]K}sMT]\Dggkgw]fmIa:Bҽ#S#pB8\}DS HE洣ΩXxpxN-"P({C<dUX |TATh͡U7Zi!mEqqG')O^m\O"Y/eD^˰ ^xw3 j!4et6IR'xmcd3,i"^Cb+* AGuc&lu賢&Hq'kIf g},{AV!5/@d0ÝF/]'t=ojx N|+Э%!#c 4a2U:1 x `3a_i ܋DDazz!2q/. a>lt~pSi=;5 <ݮa?F_f>a\YX4~EFxW&_8`e-7}lKxa(ƧjyzEd'I(W=j*"TSLbmU-e7$Kgn hSUpQf*jPNzb%TpYd0VfW.d'T-?3jѶ= -?Z"UD]IQnt# 4 n)8ɞ5`S-mLk*<:U0e S"ӈՓCN񥝪RgPO |22#&2!Yu9#(R*O4dDYz>.K*Y0M蘠:y7#%bիwd P8$AUUjw+L&,pS/j55dG:YkJ=q D:ָzq|iփ3j/"޻?Gh Tv٬ˉM7\ʓRڥEi^cNMv/ )JB+yLl'onwe5v2,A})R7h0Ѧ_N&FFUSBKcjL~,|OD#Seo}eSaʀ a7]9H7Z+M G-Zr8ٓ>!.y(E< 'i-DX|#f$]wa2psO'P+\)4_ŪuLH}n! IF/Ȕxi} >"d_>7`HSO| >7'9ÑhN\mУ-19>>`@xR"%VSYeWVԯ&,l!ES &p Jө02<`ۤ\t_%縅ޠU5͛@]kahC_6 miE/> S)qgS*sxC!WSFɱ1j5Uyu"? 5lmPUns_[u ]pxz ?f%+t:J 2K6+yږ&_q`zYm@ HM(w}IZDg>ҊQKoaF@ii :B2 7N, xkVC9g3Pg%*RY#P(DaQ쥧ua Hڪ{%Rx *x*٭ql'uX\EPt2!vjM=ԣ䌓p18hEQ̷\E GF`:?F8<*4c-љ_ԁid!2]`v#R^J,C)< ~O`xy>8C7EWG~kOni5hB-?k4h?h|"LxTqy BY* ]BiMmрcJÕAQzq\[ qNBJ"T_wHWLcdУnSϋ<]oV"Owḫ؜Hn6>F ϬA qAqcdTvck4t;t=½(Pl58C˜^g8Y5_Q*m$jn,JZJػXby8\-:"}Mk=S"2A!O$%~f`uSy` 6 -,9Z =D{b-h%+VOAhat##bA' 6Kv 0' a'f+%mqc.XuNVmsUIV̙?hz8s?.OSa2XY 71ѫ6ir+}=R sKc76ت=mL1A#zk_pOR|iFNl{DF:]MӪGLDQuA )o_xq1N m%<~uԾŞG#[Oq6G-YsiE\1ᜨ{~Fh0p.^ !^j#xlò Y= F)@;70Iu5p#䜺7cCofKUڼ2 —OqE/쯨֘MrT[zD=9OV@%dz@a_<%543+4C 1=WʼxKhcҌaߞD]p I>gDUt!yjH0،W=x!rzT< yCY̐?quT}z!;0lpUm!Ǭ˟WhSU >GQH 7u o=nӣ, >!U0E;0&5M(mEh* =K5/84hn-h*w*Q 'P 6vܰ>U׹b6YetZ~ƺ`v)6HhӯzW$Q(jP")f;~W) hٚ@^=sG e4f#h>$L7nf-fk<%Yo]K[˂&Ja-.;RǩZޔ?ohH/S(7;ˣ_RO`Ir%<KjklL[-%M֡'n%,fKjhbT3SLq"+q85tSrLtz{~lt[Mn?Y4 UJSY ׸|Y-ɧds_ˠ>򑓂8ey%(n_){hVtZ6r<ㅸ+o<8oig7mg6#M|wiog %*> w}Dk[Z .( ;T7]({\rR,>?ag:͓d?@H ~dύ1'-8C{976~f1~'gV#χU#4ĉf5c4P^8̼ OKu:QԤۑ zoEGZ,H-R|7ٰwG v}fDExۦ52{r. "/FZ±$gF9ؙM׭p\}^2Z?1=\Q&_Ixw}"}X@u/LN(<\ y$n‚}jdrж,ޢmvCŹE/mx CM~ ;2]Òqa@YǀH(vjnH¡V穵j rV8Iz1Z.ZZCMĐɆg^D-$\OM4mH;oAQ`j왵.#+z2f lhboNrм}^3)k~*A-DfEq]ՍgF彁i]ˆ< Mj$[|X#kLixa:Вs0>kw u,eN級룳pmF氁 /8ְ(A-m?x"[93qVIRz:h:?СLJ;6.~Ƽ6>(_vKo5ׁk`'_Mcl)8ަ92_F~tnj/P? /sFS0/j%.nLRT?^*iyb׺ |#N􀼦ݮU<'Q6X>,Cp3Z(G$y4om|?yw8&JorVYG'LS ʖ+M|++ppPlJYAت4f TvlQ+eX4BGpf#뵴lp.o 9&#CgLkBi(>PY̭nxGx[{CbR;ѽFZmKy&.[ݞ؆ j]59Db:΃}0(TwdXv=:j8?wVd+kCJM.y,"u=nu5KP oϠ&C;=Ƽb^ll2gDe"Ӄ2kUv쾦eL:}v*;`!E&vic&Fh i:޹2ծ.k~Fv?ꡊI aN$CrXg-s]!OFIB;Yi?n)]w7@nisul%4?ںUȱf4};cl nayEtVǼ=ƕ&尼L䷠ )]CܯZg930=ŵ3k\%[ kDa JtqOڄE;gDwrP bkDHMYZa 2%UQ~wH{a:;o}<&Dڧ!^v*sU]q4 3ɲxp Y_MϮDk 쏥[ڡ1k#T]%.N;m:(!Mh,qc$s3/'kUavlXHZosi&:X?Ru{O釙IS_Hj~.:clAݎe:'%y~_UltL',6Ěȓ 2|986dRTZN1;^!kd_ߗ`>H݊,!1\r[c  ".@}rĈIA.t>K ZVt ZB5qxЇ<T'u Uߨh~u"i \6ϬI'>N-G6hH>):'lrh+޲3>}k#se9a }V=5K,Zs>K]SQ[a9 !Mjm_6gET^WWO `i,sEB,Z[uՃه+ ݭ* )ް ݨue)S0Gſ4 ftW2U.,fbŠa5I7{ZuQ!.n;E͒#Ct?:!;ױƤ,͋GChAu(6TP]uhJk_dt:ׇ[ -M@$~- @J; ?K 8ο͔NEF8:x& ƛ-B}2Y$i_t ӌ>7?Ilhc0s)t5&(Yw&I!?*h\Ϗs$"ցZoN-τ/*ZeCڜ%%vu6ŇL)p?#跦7l9QLHj`W* y*+Mڮ1llr_˦l%Gcor`*p 4pI6eڦx@vZQFTL^ N@{= z㶲oQ]+th;p/]Mu?(SkX5~zHGP*dzP4I޶YrIVلGU|eE=Q<FX Q5S@|T߀@5b(&0N MYT1 ?_2im̨x``(,BpufmK+0՝]) x|)j6fd)>&'8@ߘFVa !NJֱqEH]@N/nG=a)!$$.8]@FO f>jl4s(i:M6SL,&b M\H2 YVO@i TU k0fQN1 έġF4)Nݭ>q(& qpΑ@E^'T{Vtc.߀܄4ltb\X!`<8u!Hl֫~9#Y}Iop_"ϧJ)UjbiD.4`+Ɋw=`8FIk_dȿ=zЋe<t!MCHq1b'Xk^/ Qg7>U凢Qw)\s^j{vefX\/}nʼ_HQ@w|ꍸ^}FIR(╴$e;kĤwq?"Ixoސ?Vΐ'^#Jvi#EH㛽~ 4|ˆW~7q:\ Jm2̅.\& o'd|=64f`nZO }~HVi[ Wy ʵ!1]Pc70z{[tZ_p#l?镓5xчC`Z#X#"]|̜)Ub j0,B8C]VŽLӽX\w$le_{nW8@)w] Eyi25|5֜&-Kz1Èӭnvw/SWS|C2}@/erӅx's՝K EG6ոp$9(^_lj|l , i$H G4R%1=eO,¬w]! }"] 2뉿LbkBN>Z3`9~acŲ )bݫ0~ )p2g-o&dNdŔ7]6$!󒴾v.(2Doxqpګ;<'%\k _FuWe {aNs_F-&1];;lvچiL Jw^G]N4[.w|1oaCnd3zMƦOql!+H@_=SLKR!=F~.wF[؃#Fú۔D3 ܛZxߜ2 2,ߑד/.n`(zѬ׺WˬUkK%?8Nt 9V=T"^WW,1D@ ֭F|G=v4Ҵ*z7>dY g.T;=5NFJ28g@^X#,6&T #wtV9~J2a2goH6;,'s" d08k"wŒ-zV]pbM?@)gMȌٹz8d@Y#1Mg;1coL >IFU}Rg`4bPwJ)a\P~-sFeYX|@fxƶWu3F'^>^bNN@>Au$(P=`#8-y6[HR_0:!VF“ e+ #ҷ3v^/q dáCk~Oj ,dVRYm8ÖJfd%ڵ!V%[n Ӕ ] ̷[5qR%G?H l EsS,kLUK[{ҥВZb{e;;=g ;>~Rm%'̋dZe؄E`Ue9܅z"Y1TYkmkz:Gt}UW/ cͱl$q)1e,`C恖BZ'F1 _ W?m7^V ɌH5#cwN@%sW+ݺ~a )֒rKŒMݣ^̩9mYȥ+]mm2cRQ#\ͤ {w&|pyʮCw8CQ% ?5I:%~UL`1EE/J]lmR65$ tY Js@ ?p^+Mt#ߺ "+.T`MzWWiԯ 'W1ݰ@6f7X} `W?Js签,(z E y5U蹢qU-mviRE<>+ԧr3sΕ*'ɐ pJYufր14hDN/rÎYP1AQB;\)ٺb*9G%xY ]ؾ5#DZO݂UA'V M-V lV`qX؜ѿ1u[ VdBvO< z`P@r r$;TѬ>'ΆFߨls")\zܶ\Nc}xPwH[ٰ=0LsFWwIQVUr$QtmiiUz7RJW`{Chygu; q7G8͙4t}jA}Fdc ``¦ e`2A=qW.y/c;s9:Ǯn5elM2Kk|ȣGuoW 1PMӫ90ڱ"kk&EAKe2-#H pƾmȱ>jфoj+5Zś:\O$(g.χ=hdŠז6[3br$ zw_ף31ZR10<027E;_jco9X egqf7( o. ykcXdEb: U%d"hV_ l#S"ҶKGJڋnkwIvgf6x!i0u'i9`v8X\v|4hKu?/wxWݘM3)jּ`=`4)uۃa:K$3ٓml&n d8Z P8(K`Q-`WU6bhN &_Z/I,9>A)Vق%qbבouA\sc8‹'GKT)QPwdo.UQ])Hr56GP } `(f`Ÿ'uIrWEA&_Hܬ ?\D1`}eA Gj2sYPO[y\Պuk8qA(Vɭ}H a l?hg?Hh`ʡSyp "l:$Ԧҹ]z})FNJG~vovc2aZbn#V]# _+*I}TGq9CDH.ɜa?X\^A!=Ur>@)gn+5x36dI6+i&Iɯ2$e/m>d$Prxe)Z:ԞWYﶨй#H#h:%uq7BC @_p kOU1ҵS"۵uv#ڢeo%qc; Z"VhGuKGA}MMs"Bh> haTρaw`|K%.5=kok)Hta]*YשacyӃMiw%h#?IY]FIRL1Ĉm#l@ F|4P5PFo<m9_ՊI EӱA}%|N^ qo Ȝj]K ?ܞv4ۖPn#9'rM ྀT~ЧЋ z3U eYa*RW (D@=/hOiPӍK7Sh]G&z`ڴޛX*m;'VKBLQuZ 1"hYb:ϬAkx;)+"vw g ֺ$r $"| 1ҟ:lj%2! ޵ޫP&.yGi#4%^N>23;ه<EQl*T~C?  +:Lu:q^FNÂvi cid DRhj^] bYwPJ2)ߧDO"FWbyOE3֦rt/\F>ptw2Vz>(Qgm ۃjtX.5XLdf3=A]V{f"38baէPL@2h+.2`P@N%\ +Ȣu$=}ܴ)?Zg"N,^yKRdl`oyWbٝ~E'jy|VoZv23bBUal61Pb \Y l-egK7W0D.Ds@`D(A.AGJAVNL5X˷ &(g#WKlg<{7 AnvQ:…ߟ϶܉ i2d覾`#%P(#M^!PXK(;}돲G 'FQQPtÂX &B"|\ej'.} aʫɔ ,8qD4lGHd"n46h fcS^%X"p+!* p ɤ%oVgċ b rKюͩYiAL%>>_xL?! j/py*Q$l%>{+qŢtpm_Ҵ8lș>?Fpߊ*% rxsٌO>H:v|͍4S֔S|% JG&+1^ȓLh2^0e6}oDHw !ħ@AEM\摐rg mED:@vU 6Of3qgOv>`ZCm\~+jwj -`w>yo쬽@zw`"= =iJ @m1.رk"7EDPW~77Q~ 5dž1_KոN#]N1UZh/7Yb3tzPAZaG:Ы_hV>ҁӖ`x:`VMwyw5?sM-KⳐ5Y\Bf:$)@I t|~~X6=4*=A jbTon`QL׫fe*ţsggȲ߱<2hkyq%84k |hS:PXrΰ 7><Yj#փvݍP)9zs:SzLaE? QނI;ʻN_9}`xg QE(h mbf G>;;d#a|VgDA*10^ ޼3JZ\pl=C':'Y=ʔTN%E&70^Tc tj鮿op]Y[ ӹnŽVҠ/OE"(BŘ[ qVֽȒ}6/-=ĽcA" Rq+o?8ɌE@ҾGkl ڍD{гeԬ=۪)H3[Y?>d#q:blZƩpO^c!CMvar. 7A,x ZgJ>UREO^)={~O,]hFY56YW8і̮U [x.G&`ReYʛBsmQkrr n ;diQ6/dqqV:-HԱNU*.f)>B\4KltzkKgcmE%XeڜldsӷHK:jAV״f0l(a` `aʇ%gG# 3=UgrEj7=#VMӬߵf(/)ΞcAF$T(1{tpxQ;i:V | PNg7-)-m(x!d hqb|{gm r6?NPU8%qN< +\9t pV( ~(sPYUh4}.Q@Yz>M?{7B\e,}]lIS1 *6JA2y01^H\e.IHߋm1]e0@cHhTXYfcG&tnDR֯QF bpiTԂ$GbV:>e%oOJϏX7(8.KzVʽ)`.[!tF3OQq+HRe%8r~-44M~ w텟55q K؁> KDCL$H4@Q"o@): T'~V;¦AU0ݷF1Y!fmSLi`_^PvwOnX` g}s ) Z+k7ԫ,噘2NDBybӝQ5F19oߝQ{g^j==K %J$Fؤ (阻ec[NE>z}ظ32`s8g˲};^b >JfxWRndyu* ?A65X,jOFhӷ)_cWhz^^ !pN]O۸_By4rLO9-hIbCoJ>}'HY=.PR|>SEB;\oy4FH =po3bq<|7hzƴI.6ڑ꯸6eQ/ǽ ׶Q^7K'Ђ{P§|SDM; M)=^p~ 9bl~Ý`Eϝ,L؀ +$x>r8 rM%!j Q@/Qw_`M5wHAÙi`RS$yk d$9ӄ :VNk^)'W"'e>->De*"ᩩMLT:agQ kq^PߍD0 ݖ[~.(9ƷɍG?SBq `ɂ2P+Bb,;#&-Ixfǵ#EJH@VtV>DQ@6(xHi@$%%ςG'ˣ,¼~|s|̀>X+M(B 9 OȤ wu >FLbXuРfo j1Uq(ܺ 2eʹ]X(P61P`bE>y}M040'{e⥣%\]]96F'R zdGI?uF*9:Vl1 )R|ŶÈP:cZʲǖ$A amx {h-5xKx Y ^c0:U }ОZ%A-eQyZ[{W4fj Y px_fI; xp꽪YdH][7|OO_o7 W҇3!S+O3-~6̭0@v~{Le`4l$LJ%$CY\s~oò3XE%%iN4hlGlؑn"|iBr]G,3'9Y'3zkb/;5)yaXQDJת$U[" "kQ[9@ݹ6d)%d3JoB9ͻ^!9xݺmۄ9P! )cG-Iayz'tBiǘUhv ?^"+Υ5Y&JJq #lԮ'/ߡQ8Cg#WW/ݡ4rnyA,iL"Ot\d]2PnW&mqIll' bn6TXN"*;ژ!*h]Ϝ i|Zsbn؄V(:?bEQ!?; VWh.  _"=QM#|ȆVTj ҊiٷOgi#L^ր;lì_Y`Śwõ&Z%vk$h)N5[Hݾ~0 yWzX8c2xmh',1T?5zu`ߋWцص%Sk͠jyR'\6[m,?'mH.N-x+$iA4PRrQ 5?i8--e ù'qP]Yx,èK iLͥ0?bhh.k<fʗ"!zv # Oݧ-; 0{kK艹`w._XE33 <ؾq5jTv-fqylWn~c*=c|dёlRK{QFSD4H-|Ꜣ[6Oxl'B1>%g¿vqC*W_œ_(q0iMe֓1+:j[3M",:CZ x?uĔN3\)69i¡lz0,⃕Wi.@DjJߨR9'X\u6:)#eg UcLJ/ZRI`pZ&à>ע.dt56(tV5IS0ґu \%o-Mu}-j[&wr\ܮ fd|m<q(/*$|ooVh6syBaDKw&}:{: ztl\ѭcFcd`lpG w&/_z 7*/AMu4Q02NM$Ch(s1җsIQgsNG4;ǹNZ΅mF$UcL:φ; I5y?5ͦufѳ3-i{c3&FWA[!:cRL cŽK *[̇p{ JCɱR s'F9]>t4 ă=Ζw,h9t4cIk/A/jUbwP ^k;Ը >@ӫ W·o'NTY;ZoIG>K/⌢n'ͺ;V':(= cu,9(t%ߣR4H\ؗ}7n;=} ${Yf= M<|Z<9|`Ӟo6_xdy9<_=2e'D/pJ>m̋JBLAzK%؍8)Zfo*6Ή:ہ@6jM34JKyȊjwZʚ 9-u^nݍ~c+&8↹#Qʹ0J!K?+$2Tݤc}r3z᥵i4sVa,_3e{猶tGIe{-ncSFiXs$>>mĎrf}n'zEgn[,ޱLT|<хm nq5Qǚ6×bctbi{zhq;㶚Ku^mΝO9-٣Ha Dde[9oHLii$jM{PsYǍU0 H9o!o uze]fu8ÕkΜm <NW3( R;%9I#-QS9GgEF$jiY$IC3 nȩaϑ#JccD%6I85${]-VzVA4v5CnRUMh! P$nC}LyۊP(hnM(cݣZ9ի8̍e=N Z!nS(~& T D1j_ yd0B@ I aOKBH?NvZ{f~"&N,AhUdw/Mf3$r]m7—Ƭ ס!<IT cA3 57ޢD;ErzqZPڅSjnVN]DAk-$ "BA.XT1]qeUY!8է1,tu~ SmAR%w`@S\s]~C *tW,Ҷ-EmT_ctd3-"{FZpOzHL}O1^Q|0ߤ=tSˁ3G}[B5J[ \űEuiN%=)> 5Y1Ul[In)Z&䥈V6G3!Svl\tu>}YɃD;HռzLT[eCAkZ@{i~Ad-BlE2PR`ZHݪyFlI'Y/ mf@4P^c+KJ8Ix_d+Q_̝e'z2^ Lu{1KxCVa/|^/r!wQaj 3e2P]K f8k6ݶN Ϝ @į.nLdSڋ񎒔ovTIp t ?|duR38Oͯ@>%oArd+%PxAv(v  klq|} PNPC3^<ἔ]}/{8e(4\ m^V~J$#6(Xy>I0~f}4krB j7 c۔KF7=a:ͬҬQC-v=6.Z&|fmW# *7~Q p' }]i_WfVPgTwXSC,5=asWϥ~w@AT![V+RHJD' Y>걕4}-<.3O)ʬK[o-Jyq VX[M.<=v+ĭ'yL1;סĮ7],rq' N=\G<0tv߾+.H5PmkC#dp:J<}ߤG˓'!wQz^ɱd G7 bO o$30t/glR| ^9%W@&>HV~>ˮ`Rţ~¸X, =q0fqN]V *e  EV7E9e(ZJkF^:.EJQnˋ0BɬEtq 7 {IPL]K߀ :.J(~P3=s4Ekӽ1*`Du¥p_C0 B*1S>Sb wKƁN.",kLJp5xʹ9 ӕY"Z\ *ZsVj}I/gP NS POUJALW9ƂΉ"'>-FS}9 X2- 0կm4Ȗ:2 `k!4a"hFEY,${ )]H,~JCu]OŤtdZxM|9I-ەJyICe0\9rU?vFzɨy5V'{ܤC@<wm'ɞA ٖH8ХùStpx?E5;xP1&*',6^`DScs"k|m E$cؙ%*37>}u3˒ 1y?\SoRV:v#+ѳ5scd'1;)aGCia|ԐqB~-© Po6CY7f~yLhk+o`9n~J$COd<%%d\R&Ϗ)[تF" PUGbK@#'` Ae_}97 81#ekUxE㴤iIaP4GџO{Cvo$'e{f̻:uʛ,5 WS"{(gC>fg(sҎҴ5"tc`-1w_94Z%X?Yt#븄)2tL̇s/bn .30\*V9D%f,Cnx^8D-.4FlTVp`':ks˄rV<ϙ$L>]JRSh?R$_㐀#Rӎ҈RmVID%찝PR*;^f&a\M]Ch0%18r-+P12%IPͮʴ^.2@0t LUbk7M+_(WjYkϗD?5v!K~w" IA ֭3CQ"̠+#8z_!'fa{QvWk$ JaopUy4Ig}r<4l^U4xHdNZ0KBEDSWxi2 EI?nsI P,z7vL[4Y[gz:Jo|¹X>7S1fƠތ CdH"5b DĒ/(j|`w 5߱1v?a9×+7%ldY7؞t484Ao6O5bHP }&~i|ႻZ$jaD[)5:#cx%\c\(hg_%4Ֆ7ݸh۞a ?t3D=Nn<ǖGpo4tT_FS)5>0و.Hz7 LQ볋<^v!Mɖ|#W֮ ϋRDӓ{'R Y)3^T1_wy!p.V|e]^-y 2`ܷieA?ESP4HWaG C>~+.`{0x'F͘Yߏ>آe8I kcL$.*+&/P&d؛6)Nj6cZ=JZNk`N4 #?֠d8raݨ}_p  ml:A2' ~Uddю{H;ݍ^yY"3]WE^j;vr~I3Ns;Њ(sC nahy7tΝ&oFuXǟG=Ya?0|?ûGW1rsMIRb jciH{p@d»嵥 %XNT9M~#{PI5Hc”,*b^i8tk5w !-&*Ƞs IiӃRfr沝}~`#IYtP*.ӊZ`=Lp6T?xs2{6b,G>-QsP?!tME[Pd2e\9ArR^C_kb¡AoG3{;wڎ @[AE=nVqRJhY6ѭ{:1N:/ ݿ7b'RxlbZ*jGVXF rS4XLVr6`$f@XЃ5R(ɜm -y'%vQ{Fi]?&\NɗmPRfvsw1ܞl]__u V #ٯ3΅ǖ_!562*q)2;<ǫ 8!\F,ES}* 1) A3yc.s4{$@=:g7"Z\;T1NLZ;dfT=Q: rNw@I yԒ.ĭ-0y_/ ȀI3ƾf-˔xpOE &|~jNM18RE/VodP} Dfsm(hn_ “I0}} R-B \LZ|<FE*Ѧr=4efT_IF6eW4w΢𬑓R(".,eW 3 e'ZI ((α>X4PjQ&{LT݊1H/:J[ֻ/V 4w>V.n@qRTXֵۗ%'˞¶"s_Qw('kD2T5xݵq~U~v);8kt"s|\".Fܷ7Ue7~z*/E3aÎRl"q3\B9I/5ˏ[z@jXzVOdb&+  h> ko *@FTqn{ aSL$$VbyX)՟.QPQ']-Rә^^Y1rowBeܰ χnp&.Pj2:Jߩ1:TH+P[HJ3eb챰 3q78Jp4 "0 8K՘hJh7;B!3ȀgxaUzm^ gJjZ T.V hڙYoŸS1Z#L8JXB)LMxkQ$ʹġn.>5N-U)AR[im2WJ(RnxY@b&/l rru"fQ<4-ʺu}lA5YRRy/BM4%G|U/(+ ϰ{w <#Cؾ 2Qr"M}ƻ/{Ȭb&eG_pY e|THM^/yaSzLti ׷@2!(IYO"p Gͣ # G B07e6#Q$&)p&J;G55f~ ΔM}c43sVǭ`*qL'6BNXB)xك DJ C8_ DO%mă *5Š,Ƥ\)ǻBF\š'NekhGʑK1|6hybcjay 9_ :^N[pio 9Ѭc_V A_q} Jo 쑱>0E+Ҍ*k[ǦXr/vOկ8\Y$>< @A#,({NvT:՘JCYwO iӧK!|89PXB:ʚ#]A X 8r6wXN{}BzVEzb-mp:M>D>6rs^+#Y HFTW,@ܽ[Q)cwĠc%,SV#!a=0@46N,e1N%U@_T(FW [_C y|H5.eYMo]Z3 د~І^R4i!:>M;: <^^Tfb@3:Ybr2`~B"vI\Z?XQBo^@jj(h ԰le*.XUf1>>"Tre47! tϖ {dYxl&hMǫK+0Ię][!(^{ t(b]3/3c#u'V PIQ-ug|ܓA q7Em5>t/X3l9]a̦}Jx 8l 0xXy.WU=Iakl7Zg՗_yڴ)L!E̥|.җ_;w٘AhHE6x)7?PM&VJgDң\QMɢ2 {#-hL[j3zNQ_xLtA|țq8!Ҭ d:1y%aV(ҤqalL:VU͜;tA:r'ùRThuL/t$<+#,:1+9.TFu(y$/27g{1z[k$EhOr>u< Ik5m0IT1ou6;9%Σ~" / T~\HmnA FEUW_͐#|A`V, YLL*{,IRs)>48\_XKW] "G3$LFkw=3c9\m UPZKiZW!V C.e+x|̍G'asi'yĕ{ >ykHNi nDޟ~:l}3ki/\_v*6B]R[uʽݷB uFn'*e̛lE/53k)Y?.bH}F%މ4{|JlTLֆkv]Xc*LGzM ZOBA+N526C꫿2̓BfLhӁ;Ѥ9 S"p]N_;bLfxpiU*0mJ#>llW>JKkIvrE\谏X)Uź_)3 xTdUe5))޳T?kN;;E# +J3>& ˾~{HqƉkCիu| bQq9ZkbRj gBs#Yeg\=i6cRM(//ǎ[?dllzCYWbjEL%am7hc#,s LmYֱnnz/(8f0g]yA)B֮7.F~pwۣHogA3VtE9})S^?M>@vzB[{J$iF w$TҖD~TH*$$hq1!%U?J[|^o}1O)aہvN^ UrBt9 WV"u\ *'E:A]-/vq4e)ѓNΊMO0ҍp(80O(V2sZ |rn.aA1 a%ˍR$7u /eǤ_eX-+w#A= @A=z7D㢨Q騌f,zZyxV2ԁ9e=qR웸7@|ʷLJoY[܌ԤQm hw﹦.j4^'Or p1ՙ $M0!3/ \<)>;MD9sUJM\4(Ē\S%5aю-`6sRgX4(VwG3s8*FN2 KQ.dv_";-%ck,G^<@7^0՚usi{&gWK9z7fU#`3+$B|,P-|-. :3p W#َt!δ.Y3%r+zhxod{ Lܢ8`;L }[jAq a=VmQui]za,.*Y0Bs;$gNZg3dۑb C4UE{q9ٙ7Co*WPc;K ۴* mU=O wV<@Ŭ@s8Uk? 8"}?GIL8X<dCv".cPHy3EnMZ 8KWs)bo۷)Rdh]M7903/dT,kMo"0&yCAyF0Gw|-|ZPQ]Y!X;7x5'moyZy͐OKe!D3=(]ndk!'SZ HaWEZ!Q,f*=(+a0I#((]Hn=s7Pytf9S84]m(rkr<zgS4"MUPaY찘do B\:aIQ 8g2DKN !>AaD־d= :Bv] i.lC;耒+w2h^ԣ֔}{|_舍y(0j.h K( {pKMǘ-{:L pe&wo=ikj!\sḋ–'Yu hZĹKIWgGS}|$mZ,{Ũluq=eIW0bIZUZTtkBLٵJ~}D"<N-κEw0a(uY [b]WE/.c]bX /\/ۑ}E0å LM] M* alX07%Φo_㨣}h# wM )f']R+ϧW9_y2RmUi qA(k[*)~r9#UK|FM jKHok)φ6D;e@ P2DŽ9x5zU G$r؈8.ΦL<,qTHEA3EκB`&e!3)U1HMY,9Gs9lbB=~q]iҌ@\Oz#@n*_rh$ܣnHQ 57;fB[`ȟC1 2RW*}H*L&\=74:İܬdrS(/hWlyTDH:4UO%k&U&{Keф^nr[GxLv ҄E 1"\:5GG5§IMY.LªѹZt^ `ȣ?AcbʠQ)4$PRf!ړIPou_B+#r)9g1Aĺ&+&"q+'i}RQ:zUT 1fUB񾇸 yh#`pcGHQ-Y&8ry((:>bg:evٺ nRr2 &w 1o_vDM 29PMľ AN;;\ nArq&N$::{Mnמِ}9C?74LM>'Et`!D$M \NAVe?C6jB#HA{E:2'Th,Lx# 9Ja$>DƂUIT.TE-? > c+NR|ujԂC%H"eH9< !z&agÈaB'Հ%$b"xۘp(oiLT7lmr4%q&44]0Õe 0-sw&b]UD&mBx{(B @0AzgLzT[fzݳ!GtjE:YM̎:^ƒ\ďu,g*®ӒvQb?Ѩ`1[F<[ 3>UC m7/[ӰlRcݥ|UYvҬe :yExNk '3u(jYI9Mo鰕CB(A]/@IEhCEj3gR_!c+M,Z#^mb+QMI$tǥB }6b@"o9uBǯ=K4~<q$BŦ$u4Bz-K_= ;u>+4)@ Кa= p\=P2g *uqFwcl\i> ;&HCqRE^ fMeV>^r^N^Nݪq8{5XlwJO`q+/%mOT–źLz1}y> [6@܄ 5h4kymg"g*vG#[;*4' }UI{7̿gt\%?n)3a}JdAt0I^u+,y?prZèJջ;VNl0K0 u ⁨`p$PV.q $RT#`X檊æX vV$@4ı_ke1.ZB8K#4@ac*XVF2y*J+)if9SU8#@ jǒǢ2A4A;+ga&0 O4uPد0{;r+l<'}>%׭.E C9˟v|:^ M;ԼV=ljjиr/gКCntD'{Džӡ#8`m\FlQV\zk|d[r~ּF"Nw cYGnu'ERFRz!Rq" "Wz}\[#>"iܙ$2w?qS(Z9!}!i VeV8aO6Dp:8q1ی],q?9ue/t+S&Q#^K/~NWYc1sI7 | cUa6=jyHwN_|P$r 鳴Tk^@oz Ar4Y)֪I+{.8Z=ZMpu=9IVlwkzIM6o ҄K3U`2dg0V佸OmH+m2m4!>} XB_˩1D?sI[ zoH}5b硕^UO,wa)`L *J+.]I 8 /S)_˥"6<bpj'"DɊW)Y[F,QD,C">I7=X˩/¿=pvLC?ae⯿(' HxĴ0 ,#/6?gOm9h,7=VfSwPPHr.1$-7:_w{{/ wyܯd=m|.l,S;Pf1GC[~PJs|%o4 r$]?xet=Qj m<"6E?Euzh]e+>t[0+2Stub֑C6\nV(4dj߾Vºz'x=As ˕/Y\Lwו'tHSͩ8e1Јarԓũ~Z2~Ѱ Y}:^G<[ F~FO،2k܀ʎ+(  ?pB@[3Q-:jO58g%&u%NmƑs""/ܑ=~Tˑ]x [;Y'yVf?<*Byci9HE:$7 Nh9V,xu_d/J8]}7,9LA1nDF}oŘ[GQtH Tv.(rga"WJ$Ή#~'7Ք$?+_&b6Q~m{ ";,֫<\ň=!=)d,)c+R|^s ,ބ3ϮVUȉbL)Fm=ۅgj2ٮ[(5vնu˯ ejM;<(8BAݧ&FgR 9E %nGO@g^LLE\j/Tj|Nf> mQɧ(29jߎ^IpAo'ސ ҔuOW͸*sp\OzL}/߶;s#1b@ڨ'tɦ SZ.jgd񘪝-֒vt0"^ӹjY$r#cPrZ!'%㨫B 2ŒT R\an y T|RؑVۍL:qc2A7f2L'Ϲ3CF""`E#X:ԓ8-t 8"<pC"Q577E9Ozn t-54s<ȧ@%͗CBe/'߼8$K-S X\ 1~LdJ=[̷hFDwaMPۀ0C9cSI4ĽOM_f}/R}EӪYIVd~Qg+ei҈7n_*P5$yѺcJ65C GjAgeM1EhZf 2IMk9`K{LZQG@[ -K1,S,B ,!#%"U {a8d؏vgL<4 i[jb]Bq6&WxKzg8v\ne܇0|BnFX>C7>*.s ~־>1~ g~o^iiV /(t mqqvjI޾)GQvmnK%]W63IN:4%0 y/脬8w[jQQM(X͹&AFG n# 'BM xgS՝P8 V|:.yJ&݀7F˜>)' JOmOwRULG{OXr@*p x9M(lUB>䂉,t bDe"`[!'Ae9Iekh!ӱQo2`MVk>V3ÿ7Ok(;N\[^Zo&+C'ǰk@;$ESNh*S50j"E~tg/YE:&u9䃜!ʓj*f1JzK<~쬡0%5eͣbma8JU/y-yJџA:.ĝ%R7Zr}IoJ?"}Fs8Zu\$Y(9w8e!_OMQA(f$ kndF/X$)sW>"DL$&pږ׾rFSln)>/}kDk+9{d_#^)NBr;lU65^x/*qу앎\kp:%^X }1ui;)?Y$Y=UJZ5lN*2i}e0.D 7bm-ܿA5JsmNLYWҊG{a6 EJӅcYqq@O*d'K[D)ū%6:__ $;Gof"vWÙ2@#ۅ}l"*D˴A@^'.#Eq1ЬM1e쨘TA[6DMgRO ḷ&"}ExXt]Ē k ,vi{˚ ylA R9%! 'ds)g ґ!ZAXJq5Aa b;VZ'[ZE$f?:a;[ڧǵ`B); V_,nbzп J0I~2{Ql h9Z.۹[BQk. FuU7؏\@OƥSpljDxbݼ腥35HU 1W_Fj͟PbV4̅8ق/eoʧ-! EzEXrbbc 6Rwhw΄N*Yzmo@͚,UyS-{Pe!ɟ<1HCS Fk9"nOdh,Cƞ4 jE/}@P~?NlI2UoY,G_W" L :e, ,6Rઊs>xħVu Ď 87Neu A./_[z'DiT;Q/zJ6' -Df*̹ X~|?^b8' LC]*$@#6UNʝok/i8~c'|4l@QD} o4↽ L3VMGzV7Tv>+DpXĉeֆ# 9߯N ø)YҗP/ro3(zwݤwNqghGK^J"fDO:r s' dc]ԡ QlNCWA@FhXd rg3[N2qck{p/Qd㷊)Go%Fy r/w [8ʵdƸ>?Y?א@XSvZ;{W\ސ70o3кt\':rH0FJgel h6LxRbWnM\ pY~X(3.$'ac%*I Nɝ'3! 60G#84r أ|Щɛ}[#~@&-#g!L4ڰP"#:;H3`.֙D0_zԌ6 *~ᬑ6E8/ڜq;k] TƎ`6'MS6]\uOj]'yл#.gT[gHUH(./B}tdv4Vc._t맪 a10jPUt&BkMg2N`OZ㨺7<*G |{Q%|۴G‘4fr4t]CO~&2(kVc+L%Wa$3辱+y `ZܝMۜ[){mLe3EUvF(_I+Jk :7]ŕyx/3P+_=},~~W'x*Bay*%-}{ T䧁WH,#+PQF^-Yti]M F9670YhUV]q5_yy6eEF3K$zF0+Ue![rf,b.391cH뢵q٭߬1v$'1].\z+_f( kE<ʲ|\ i 4q:)0k:=&d5nP ة|ڋ`j!ݕB @N({fJ30uzKvX08$-HH^-CC JDEu"LPP8/~*P[#>#Pw}тu@bT.^)"t.}L -[ m =ͨ . .-$C0WP ҆4o|# ~bY?X=?;NtE!f?3S˩/̠̾U~;G5~ƯuHX?!^֬9L  y(ՅI)95ʂ7Edw'Ws sL{i=9ZK.Pxۺq䏹!$ךH3ZAթ>I!F'5ct%$ Jĩ4dž%Ēnx1IP" P$pOHA%t(By[ 5:s6ܳ "(8;׀\#@a%ŭ$-.K7Ѹ#v!5GO>K O"qCP`MwgѠIjj+>Kp4 [& m?>pt\||g/#ȃh0ܱd_,&v0i<$U AZFYKLu˦m83Zd&=:y+rQ'>uvyTn}RLM['u&[{U%x$`'M-(P(jQS ]BLV(Za3;!ꉼPm+ȦPj!ϪP3Ǘ->'$dK^>hv/^M c,ML*1AQea~j&; }_q<&ϝqc5Ș+\Gp'f0o^@UJG9(Y aLUC|Vd]SnQ֬S"B?İJs/<:-fPL2|9oЊQJ=C{"dQT/B{5y KsٰANs-oGb,7,DF VǨA˭elEGS~p5Ui:mur`o{i Kmո IrfpfHKD&ᄋG[,Jn֏Q3SqSK0Ȼ=|toG&(1h5F~X*<X}ϥ1zjډ98MĘ-_Dy|flI.}0'gi0\'SeMஅ@ Uuh7^>U޼%&[Q}˄YKaP? >%<|l#a5hvOn7!x f`'7/OsJ~,H9łԡɜFcpn0k[W#A13jJКuґN-qCVUp*pjwNx wd讂2vj-_R{ihGIKtxl\㿿+RLJͱpqu9ܤ:U*t0uZfax^ ֟"g.&vEN[Ⱦnʝ"_7Kjvbmiǵacgc''&.rjϻˁ]xۑU }ڗ pwnEܲWh)2.j5sL o"in>YSU`W ڮpRi^hH;([ J܏Ӫ9 "HV辉i?&> % bl<ޛ>o>,1gyN6*Uj3o[^=h+|qѰ>Ӽᝥ!e{ERVmhw#sG:*Nbq޾5ΌЯ&ld>>U =Pޅxg++PnݮAKpѫ|=#QNs`E]BTL F8ʱaxZ10pɚ`).Cx4Q߾(e/6b?͸V|jdS2#j>O%#X >v%7z1tm^)?'{zwjtOioOk8IlIШzlYYrIiܚ6;Trs Z)QyU/ogF+۲T]t0-\@tLm4\H.c =,c'1*CdAA=A h#]m wQa[mv8E]fه+ye]/,M 11uЍ wKsԛA!BN"7*d]65%; 单;ȻGưns?SWGHY):K _`;4|UXڕV 7F5}e4z;L5ǒxFTUerNG" .&2rVם,iዔzm͒2Ȕ 4$tZ*pEql*|hA66v"0Rdxr%X:+F,PI:(wa[LFMd_H) y @VzǛO5;e ]9:VlFS/H׶ϳf?Xw<40m= >' NBF&Ry~ގHӥ3XrT=.Bunhf k?HNc7uڴ{M,?j#Qcfmtq F>tMnTJAg#NbYϭbw4Ii0Bju$+076.;>W?C^88 m%Q iIQ- 'r@ŮׅE% EEXΕW}ُ3Ja~_}J;Y6yMJ)\0n-19o\:GɒA*MJm񿽽t$S*iC$TqB0](05ňvt= 併خr`JQ9$3m(XD,Ajt1| ӥCrG]GxMv^.af0)Vyy1ᄡ#aɅI"F\B mг<~DiPfԨ5TOFm!D U@^C8l ߼a|}?0> G_d'Z!~cm?g\3ilC6fg\)_x3 JOIhɰ,.wa3r'Ĉ38 ]"E "pjrocK lw{|12:£I][;x +9"jؿӈfH\9JDrpd*6T'"DS[#~kiO%~}O6p{/7-tenrˎxF$6[>l@_DfBˀ.@yx/n^;OUN4ddjnƋAbj)##ӔmSٳش]9a[xc`6VCA7IQ7эjY] ?<T届N"?&:[.7$#x$5mGܟ!֢%l ڞepnY^%ڷ:*7YE/{.2u@PwW16D18lQ́UZ?uMcB}$ l$(j7s8.,qu}{`NL77Mc^U2hSOTXRFyN뇽H~`^s#.&yVDdB^_Mg8-!:nm4 =RTW.Sւ1_l`91)/ ,*KI=g,įRyX3Ty18.FDcΤWgT)u%XXkߴecOZ*l~AT EݼR_`Jz-=Q N_nE*$gWƘA+B`PN;NH7Pyrhk",+8F>楂@tlj/' }g؆ʮ\C5vA ~Eg.ʙx0_pIF~(@S~z;bIpfXRQc)a2M5XSK0'o_}"'w›%Rt!B5Ote:-4ZCĺMu}E^BА{dž:3m ieׅE`g}*HmAo?OߡC PC]XՠÅن;v- sDzɪTUWL&1 eAuekCFlJL#iBָzv#2q"!Gdթ$@c;} [|qQgF]9baM̮8L"rKX!^mv%Rsmg",BR鿲P>Ha%c߉Y- [Mny|ηBuǀ?g!!ӪilId/ MTUrPVvNgH=RZKhtD}FZoQjA E[ꄭ6ίG C5K@e UqB`#sU'"QϜ"ʗmv 0}Zq&4 )7X(۰s~b(gϓd_<N|Gi8Tp?xKٺo_jJ cS&b=1\]7D]s'.~H=oO;*.s굅{[m%уk)Jw}˓egĹ' F]ie'fn$=/_I|`gF*)q'W)(S. H0G4dVp>pC&ToǓ=:|x@IL Sx#eI )[}KF'Rh-n< u3!1^F7\J}9Dl4(`@ԊJ%: ]`^Edjtzf{A/ھ?IT<!G-ӛn޽gDs gyI qU|Vv+=f5Ҫ@ X8:u¿n[) G^B٘$0g{xWnw?^ٻu?G/Gnk`& 7\_ ]tPL=<:b{(N ;I{[HD-AgMD~ԴzOӦI.=z 8U7jT`WNJ]jӖAja:dM@kɓi ]vҥ"=΢iHƍ`_33:g1[ f>#>@b%}vHQ{)5:t fBz?MnXAZZb*JL#E$Y^ZcC9hN[B;™IUά hXV^- AS˾4c;;lGaˑt TJkfh![Exǂ$g2Y#ŽѢAfS4pAMl脍峦z :gf|  #s%W8]U_נWߴR^FvK #ZDW%W2BXY+Z7ǘ.U3$Mi};mMdEp)iv%#B<#nF COnds_'oBb;4XS S % ۱ϓU.)1aGEm*u=U%c, q'Mf#kV#9VB*=i0+`,ʽ#oB 7m4OZn~kMi6I,sf K8alk|PT;t:z߰QhUpǮ] +0>X)77ʸjVǜP̑Y׳) GvK::(*8sp4FD{jhH5v6>`seˍD>iH IՐ1/\cdkV ;\u&ոCOl /WD9 ܓ[6VX_^PH=虔?tp Bs86q%*(^cOv?CSArryji}AA{GIqh"P%xnD=-d% i*H.Z6Dng[)Xo\ yr(O ~&x¦oGP=ɟT@4PM_5Z|گd}j*}˒;nyð0CnX,?ہ5U{,a)G }cy6fLswؒۍ!Nl->F2p+@94 G؏*^lqXs P F"} HW-1cykRqdAsDvpH,&4UN[M aqmIq8NR/}a_&~)JGKANb}G_6뙫OW}Ѽ0#K{/}ߘ8VjX򕗱10W@ bMT  Yg\G ^k.H}5GaJpFK*m?AP@0 vm"hz礼7AWS-xD5/N]0ܑ[:NYC)U73DIMIzL!0p2}ꘝ?W1edlĜJZ<$_&t4MP!E6aۓQt? S=0-ޟ–V]5R*{({Oh0(I2,?ꃁdq(+ۈIgsaNW5jWVlߟjTC.S=ߌfӰn[, zَc-LX;J eK1h.^iu`P>#$S=9(ӗli/ndo2SĝU-K"j>,X"e#\z9IΑ :BOEտcxa'ZIXD'YfEP]U:Mmͮr,m0iՠF5,'jMNs02.Y@%1tЕi 9Ȋao_Wov(Gˎ4I֑08нja"}օy( }dOmY3JzF5O$`tԭ)qTѬVtt 1t/ Ov B݁ʹـOH4$S^„19=ˋMab^[O'0ulb–$Qeʩkǫ 9r2!?$r>uEaWMo4ZB3YqOfx;<r"2kKz9 j3~Ǽf}bzÕL};j(bd8[_"Y$ ݅Rǀ} u)$!qY1Љw|$\ʱ}0V9s ͂՘s[Y=A=ѝ;96-^tsVTIWٹoG\ ѝ`c˛sSs#JBgOU]A\5tGaIu-[\DG;a>m=` lXE0h\\rhXo>6V60du[q6Dns5N2 %|u6Xڀ zEjyMA =QF-5 x .qc %wTt(`LS KHC !T_QR =f3İcFtYh! 5p}(fo*i%z;j(T@!j6HŰab}+FJ U̬+֢C_NtQ>šXȲ]BfLi*9m_+ok5W#AX(7zrٻhe:n } eD}c͑F Xd%=QZ{__$V#30>N"CGfډ%͡4d͖gI8R 1p7GeIbl(D`Y{E2^N{R$-tz}803ׂGE<݂9lS+>uxų*O16XL/uS"Ji̘2Ȓ*7꽘!P'K?mHa_L!B"xOfaIZ>=B@K%Hth&SHUH_Dx0A[ƱQ °kdȅ6舨kU?s ^mk;{`,ڮvel9 '1)T,ms7F@1j-'\ A 2{[d*rPr* CexݺZ0{@ 7F'kp>R>;\U^MCV,6[@#9 `q{IP0u4Ia83_9Sغ*3Sx? tْO`bVɥP[x?pJKӈEQP_~jmwt z 2Gvd@zQ{xG,Gws~۟q .)P{/J厌9gxQS0(]/RU_[8W^eL-U-kɔUb|޸ vu1 k@1n++gr|CIgc pD2a|a^JNȒOOݝ%Ah'_™=lvBe]N&8/z8,&5ޣQp8/&dř2yb Ej螊ZLGՃGG#nI T<`Ԍt-|$0m5 ۪_,?`8>4!@Ў̬(Kk@a5 VZ\\ E?1LQҠ(!F2_^.i8 YY` WQ醾k$L}@Z㠀|r,az[t鿔)wZ#1Ij"j<^`5>K[~_dzwy0Kө3Y P:-G /PC!!.Bw5MD*Ձeu R2~1iWG dn <qZHV}Z8< Q,N<Phd>ɘ:X˟H]-@_;T=$9Q9׷'gwr9~߾MFU:MЕ WR6!<I &Ǘf^Z^cZ@ҊN@{/U,w=lД >Uh>oְt[f喱ŭ<. cmJ'Q K LC](KP," *LyUmr&4u Uvzv5D@v L9 Ծ2,`$^-%^X*:su L?ì7o+1LkZ\DǴ&A:!wӁGԥra`ّd_=4XŴj# < k>mg?L\\r{* }FrQֿ.ev== w˛1) ]}wH IU ˲ $aBI6@q~ `s œt.3Y:ՅfC* Jd[`o-&sRo(sOvt3Yٳgn`wJ7:d^E.|(ՅiTSʻeE-JahOV@M!Su',X#'_AXC.]J\@Q}f|z! ԙ/WX30[ɠ}q)m~ 6^S "C7&J\7OI :*$ٖ\ȭw l$IL{Ҡg ,dNU:iF#z*k?,l@)\QN,[}no{rv}̈>s#(ti(v>aQՎ1d2bi QZ$%Bt 3UX>Π( MU&n̼yUqeEtB'/uNrZ׋Zy!yz:ܛ{O=PN+(>1'',Z",wcy8mV8pD3, 'jIR`4׹ *W{f!G i}ߦPbYO NⲾmNċ %|`eWe3 ^EAɻY:cpc ?CwkQM@1/KўA@oJBJ0M/ e+f!9 !Zؙ$x SО"V@0 bOU"_ϨDSsa2!|R;Wcǂ{G!|Ky^rhzxs @D恥걿ϷӅ#Af zn̻{x L#x">D\IwfU)jB?-}B5TX9,Tg`_F bJ4D<BB=h1掩偾9 HN}vKi1zJ9f|ٜXFo\kUf":ޒ=*"ߕunT~Fmhc&,. =_6|SMv` j_I _6B>cW򢒳Yd1#b-p:]჆PBz"d9Ьí|u 0 S~_;R-F pBԅUv1C6HPmD0Zd! sgNk'Ȗ7|}۞=饫|3̎%4v 屿Vl|iO~g%=V-Ǿ̓𨾉FEOH4X Gjx.ȝH'd*~2HL(;q?Ѷ un= $ ' z݁j_ua4>aSSvv9YrsҭTSOgYe3HU3y1&W7,! ͎6xĘ$t?Z47%!>;S楳$`Y,&5M]%O& f0"%⪞̗̀U"C5r.jcuҷmZ݌ƟM' {ڊ'|й1B^ۿ_WQ<{~vy(F\Apy]Q*`bo)Ǜ$ޮ1XjQ SEΚi{uА3`6*ŐEvgAV|#y?ܬ|2J/y`/5ګRM.Ho$л$6ڒ0cH5S9K by}H. }sX ĝޔ*Ԩtz yb輒OM 0fnq^ D JƇTQ4~a(@h-TJogh&*K;QP'|~:T21˃j FX@I`?^ɲ&W ddQ](ׁǶ 'Bcێx {w8ZT]nHEJ)B2rq,DO>VdiHN)LATUӽhok\dHv y@n+Ta ְ# ;gɬ~ pR. Z$#WV(xT"8셩FtYz¯MkpMck L 7+&ꃳn ]` bH45tAT_[llPՈ2* %TF' X%[UPHӟ]I|P(/$7Gòf"P$7,n?BRy4j5志ȴ>u$bCAcw(%ޕ=/ նK2VNv_8~R}EMC2w0Tj,@N[՛l@(m=vt%}&` 4}|YYpӉVs*k""sixiS ;~J$ ET {<Q@H nNU͗̐Y5GU_sAh \)?1+w{-=G[FkR}ZE\v(Rʟ Is3OVVH$:ĹL+.2p`'^v]tg?7ϗ(jx`kWǃ [gWVhqj\Lǩ@GR13d0p])(U@5kk ‘5V%Ҷsg=RE7=|vV0#!Z 2>Yk^ĂgTsx^#Lh2*`HYTeɩFocaT+'+>2llvwRkpu޺TnadRߧ? `75ɜ#Y~L!ۣ ށHwp׻U@ I:j@kޑ<Sr@XL ڽ198<f)ErڅlhWUf/WW@JfsF.ݾ,ݰ%%+35y":̲UU,uS.Yo J?^g abc&A,Zv[r Z!ޕMHZ3䯫8%U4:b)5~qj-:6]61%ARȗO˞t[嶴?{$耻h2^g ż1a2+АKNsG~eKKŷx_8]3׳-ճGO_`LEa PAl,d 1un8 Ļ #J/ݖr4.VDW3㯥qkEBMlf?VVR7 Ҿ!<0w8Mb'r 8բ*Ardw2T=t$@om[ ۫Pܨ4itoAXX.x[ wFe".^(E['1σXÊMPNj(I XgyRAJMf5ї LmYl&z NӰnb)OG'LTv1}ٴيyѺưx͚yeՌGũw ohMq],;,TL>73TYZUj`+h~`s;"mY<"/ =|e]ۜtB y*SRJ:3u8-h(Y(4 @#F9R xr3'n=! '01d9(h FM[!97; [}{S&FLsmH}D״Bi3oXƍzEr {>!Rꙺ?Dz6oS{-W 5`m6h8klL!v}04Pk3>.B^x7ύFG|~QQ'8։Q>J1.;O%o ֳAy<f 1X=?B@vrxU$@@瑯T4%8'`:c!s-|Vam$Zw,e~X>x]v=}jqI_-?6Ҍ(pP ԾLp h7ݣ,L^E)'KhNǹy JPiɺjF1O W05g&JUN6ץLȲtZ,f[9K ZpDH O,c>ӬYhfŇ;bmn CR n=YJbţmݚyWabONJE4=(\/L SMkd^ӤiDpRo&N6θu`q |QuJkZCǯ{9 Ş˖pM1=,4g'r /f;Kl؋9$( bTFh[vޕSiNe40Y$2<$OrmBQ,oxyBѻ߰ ";rQBhH ȉ0l:80tir"5%p")?S E_8,.1<ڶ!Pܽ*;9_M~5* @"nZ{w)Eh% t 'f_d'KJFHa@cbĜPu*{.mD-ۙEw"៝dR$rK~%' ⸗3yeg@Vr/uZp~5U<]Je%D.j5X )mʅnGlצ/Sbjj_oWvP5d!Ǥ;VQ+[aE,3JAATIIYT*>[5F*!AJz83ʤAȟ4 W%htсKsmD] WKX@+#lr52Y%`:B[;.sj ]]`6.T{5m]Z,HjӋ6ngq.Ř˱ol"hb#ȺOm͂v>HBs]ӰM_w?s$RyݠGυZoNJg찼7?G1rcމlj}CH=OtPTW^c:P?%^܆d(XϪ, )mF^Y85sh$4b"be$vlB13<?ƌ^-_E,^"zWeݮyt]S{3 p" U\fJDB8K͝,@rB4 (~ ?um1{}f t(ɠML /w]1$gΫ~QxH] p _w,mI :K eOTe:C|6 !P_A|M\*]yy)7YW8ejHC fW/B8tpO- g{]\۾(`&9↮D'X=2T7ߟlY_lҨXZ^vFT_uXlFm\V}by GlI XMZ£}k!f ɱxҷ)j=l=LIx8aiYWgjl28Q]C XK1k=gu*\pބ:GA^O5\3pL(u.}! 9ڂ.%n; k,3AI6O *n*0PfMn6!$*$mX$PIC`*~sg\)$4-{HG>n4?(&yzѺ$-n  *tZ=rn,uJ!@ќVF VrT;Vg rRb/7l%_H5ɋ,\ 'S {#Ƽ+QCrj3zpN {duF;[ Lko=кa Nή q"n>jc*ǽ4!jv_S@XhRZ:K , ?ƷWw*'z8 Mf hq'h-֊[ k1VD@e=Rrm9}a˞dҎJ@Mgg\8J$EΌt j ,eE>z1A?y;_okG'Ǩv"0']-6 anbk2l2Ju2ۜ,ڮ]&C[@`CnZ\=?Ay#ҭWN 2"nLǍzte`0"KCZ;q 1MwcBYC,W~&dÝ8x78uqm$ 옂$7Klƺ~t,8 ;8h#CI1!6 a>0W~$,I} &NSP DLCE-ѵFԀ_d+Þ;&\Mޡj|\nVS%ڡ !%$L(N HNsa=HЧU%'V;j_JLr7V53L51qIfs7EΞm3i i wZ;Iӵz#}ʧ ܅Y!.#( 8ծ+dUPQb$y{97<ֶMޟ`J0!&"ZC)EMm[esSSk)po ?!%jOR/pi7%'v`K2leWaXtuD1 ѻ43-f8$GtX;FNNr``w2Hj2`sºW @\z) -1,5eԿw2~L 귔}XĴ$G=s:]øh WsN  =M 0:S3а q +{!@ڙZh5Z< '{qp^E\oB@vxC#&$2e cJ< D$g'zLQZ%/\Xɓ^2f⵫"̷:ђ3e/p$s +߰&Lg [s=:O[\lօw/.HHJyΌۜvpn-, h0[6@@(ix@˱Vc6u .F>mJJeҭD<햝`ID'Ǔ={mPab7~n8n‰Ft`^lȂ>ihafQH`cDQ>E6)}.P_0w'HSOP3sbG|,)r0-:uhAejM>XnÏ=gxؙd*/orrZbc!E$Ldbb)3c22ʉvy87th\74Mphe;6w1$&끼P-㍗NlP⤶҆m9 n \0`]/jXQC |PP6~iZvh-!$s֓:;9%<a 3婅bnE#2zXp+2B84s8#Hcӈp 5i-by񏃣ȩ# ejI= V/'4.+coD'xf,G}Ku|L O tWzn(\`y&5>w[oNKS)OF&qXAY`!6令͉ 8J d } Ԏ\S&_Ҧ+Ab&-ѳۜ%+LSWWϞ8ڄyFtּ"G> yc/4*cQ!n XYjVchЊ#Pnq|[ڋF\H_X5XiթDc(XmD鑏Ӡ* ETIăgJY }s  7/FWYRYy&Am5(sbPukSRaq7B96$27H[@;s>2#-:+iOx@aGxB>v4!sCZLf_p!d &2vHcϵzum0zM̨J\gӗ)2:yk|<\i/<>~YtN XOaxLZCש6ifM%\mt8vK\yVҥUh.N+L;)_@Xи+Y0u n;⌮֛"I(и-i-reDt _[P Vq|% cn6z.TZpboG&?7񼥑)E1)U pMDpMSl倹Y,ՇymA-{2l1,KWm}vavB< am[͸JuGTp0lcd:#[՞/ʐ'&b!ă[ +X{Yqq{JDཀR[Wpܦ8mꋱ+dRk&א=B}H2EHRCpXڸ(Z ]|GYHʩJ7omL>#X|p8)¬$#h6b%bX5UGՁ|kI-(/{7Oq5!L*_!zI GY6kGYI;Xw=1ebd2?$Sk2wЗO[*vN݌y\l@Qk7 ? ІcϞd(g{\?s B[?*rⰜJfTSr攓X u3žp0ñH/* ]ʼFZ,-˷.]Zc%(=]A :_NbЎ-&Q"֌7~eЙqv඿=mjv,6e'2~v[[⃤ӹ\ e3ki&#ڜA⎕wؤ%4'#xFi䴠jN^\#n)d CVtD0pÝjr=dJ8FuN<]Y}5"M"HoĪX(%wH+HAo"o T.'xu2!'*x&y-h >O]mO~Y8T7dms*(ڔ::Br ʾ@HɠK5?:Q>|g;^s߈a.e$Ռ}lF4/K gjI~(mND03gM.8$iQþznR%` X̰NrkM9 Զu9;EaIq6WEg*0eED,l+ZjKH^-|~*^_ӱ)8H,?wx rd~v]nW] T.œYdL:"[N8f;9dAs}he-%&lW$_A i0jhd;o< Nnzkv¡\#U ' h@/:."K]+QEVr\i ! etbfE\f狵4[@] 2WV,l0l }gs0Tҽ)zpmX-fukhοĩqC$zjq|_Niā{&!)S>ѹr'|t9_sL'u l}K n;d &DPo%(ɒX&9Df \Vj  m%#FQq 7EoP]Q njc8Br+ˋqf=k~[/ vr OWtw̡T͐l=@<:_{~-SJXq %D.%&`lߌ%M7q7N4P2;WT1T}Ftd41EF2.$dTFSU{ '.S*VNA#1rQ\iv({hL72dMm_7/Ld&?Hr'$/ c}CKm]3ocMY!Vg:wCZ#"M@^1h8>a܍rId:7%σ ZuuJ-U#AwO=ql\rd^D&kw2 X'bPa(4xGMĮX(x %oRR1.Ecx;ND!Mָb=D#qDP3 xH%oiW[7>XՇG- |D &b$*@VkwR_ㄭCoG%iDbNjf~kR؜So^v|,%Y<ԏkn!,Qt0NN-5/Y-JkƢ ȩYok~<{QnL\0*ʤ!'y^b_lsgnF%2^ۂBmH"3'!}f"ƜR?x!s&-wy, ]M!y<z}ڌpStwOtRbέi{w2.ڏ ϫ;Bc _w=kF0Lh@ǥN2կքIG-0HaӗX4q ()V$1L5]QN톔DQA$յ5٪vR@ !{v=UݚH {AK%4y}iaK:FՕr0]$)b#Gae\l+۝TS~ޔZXodcZqdA2o*>(`^i(t &Q³ {p"O<=핥X'ަjpDpGG?LSs`T~"쭾,"\i0PV~5Z}P,Ń3ltJ<݈צ}C 觧.1M"p<桾[6OWjj1/Єj_* 3 sx^*e9Tƛ˓K4c8)-GBuD.J.ȁ9(nuWٰ+xX>_;#%1 Ru׃ϹKmd͜м9΁$=eg5n]2ɤU$ w]ur#~5 n0~;V&U|̀"R ;z!rrO ^6up+ܨar+42ҁ oKgeXUIGafz1f_CrW&60@ׇX6vnuh0EN5\#%Y "x[Hm):R{D^[h~6ޣۡ7 -I#}bDEqc}K[lIu]WƐ嶴&\rf*`f'7\:PUiܪS`;|J xS*W'OM<} =s9ҹ3/9˓g^~q̩ϼ>}j%BjYc+cWQ8 i 85ˡzǽ._!P/+5AUF?/AѩsA ݵ]i% Ρ6 HնCL#nHG<Z1 `Xc$Kxn'= L,gR\\,3j64E’EZ 9̆-9ԎGWp:Փ6t9SMhtz.\2#SqKP KTrY: srފq1ӫf:gZqQ1JyT_(v}e85)-u: =?1O]u'NGvL c[^ T-DMtV6b;)6HAr8c}4^+~]F/sIH&ko*(4t*U1IZUp܁{a,\v naxZb׉ɎTk0zK(e>% d,\%_ld0!|r+ 9z l綏*tiyzb4 Jjom0em!GOgUCuRZ@ȾXn-U`\д[RkdţYҬMWG + Y*7;>*q8.v(}ht54ֵc?b1ިwf:n3T/y"7Pιֈ9}g*'qMDӌX&+5sDSݞ MTqӏd%‡:EaN :y-VF.~zF$d՚Mm.$7a3-0/wgPNexaIkY-g8< QJPDߧPr!X0bV58*)۽dRPC@>]Y|cߺt)}k+c'jte6kcF'~#_%Ky&.^(BUOKMmwHMm]=$5"~۽dH{j{;[0?qp QMuǶ: dBţE'5/G߼z}Bn72 ]L^.Almx_w*T(U+q{t_q+ ҏ[d'LˢMZG{z(D ܵy[8x/2m \UlT`S`ܩPe[HzrQxyojSN!$mamz{Ao{MG~ִ^ח,X&v7H%7+-?vz6m:? L+I=>II~%'bhXŒ38¾^GẽCa]P, c dӑN@_;}fViY\(D+PGCPpDu eD KsKC{(?ɮ΁07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!1?0J?-۪TA>(첶%BTXWq S+ YZ