sssd-ad-2.7.3-5.el8 >  A c~RU]%IGS j(7nHedïP$ܨ+~@IЫA^=> QJp\z hDpBG]{P!a*ddA@:QřH%e_[]Ea&{o?դCEÒ1o>K .^pne_NO~bZU f|3XXk ^ 3VZp2yvadp\Vݭ͗ۜ ~ 94vb瀖n9]xQ |9;V9~aǺ-'Jl ;l.`?'>f4]ȸ]h4yy1qnㄼH$^7VEPIUbBS_1"7f81e2ca453612cae17706e73da78454c232faf2ab446ad9fe2fd730488c684d5382364c9933df542a68402dab65bbfe579efc5dc~RU]srq:+'מmͧ) a!>;tN% {:֑5g'08Tľ\ YT 芳 X]&-/迁?I#{@>7)X'M'm?fnurb+$C{p;tpEH?8d   2 3PV`            H    <DLD eD (8$9:eG| H I XY\ ]H ^ bd)e.f1l3tL u| vw x@ ypN4Csssd-ad2.7.35.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.cs aarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64&'EXK8L <O AAA큤cs cs cs cs cs cs cs bºcs cs cs cs bf0b5ddcf7153ee1d00cec977b9585c73daa9de4bc8ecb4f9b5d90b4ca7795d74c92e7c8d3e4792a3de472c8d01c09d8d10463e3d83175f61a2a6b476ff21fac8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903b68e5bdea577b0102e35b987ae82240f339e347600da09c126aff54349ce7bf9a3413b1a5ea9dd356459de91a42bd1e5190c31dbdb043501b68e5610d0a3194c535d415bd0739bcf0a82d65d11c279050fe31b0818565d36a7e466a8ed8746adc01fe8b92a8e2f0640a8c17c7530c8a4b4640b4f015a63f49feac323b9a374c0../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-5.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.2()(64bit)libndr.so.2(NDR_0.0.1)(64bit)libndr.so.2(NDR_0.0.6)(64bit)libndr.so.2(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.7.3-5.el82.7.3-5.el83.0.4-14.6.0-14.0-15.2-14.16.4-2.el82.7.3-5.el82.7.3-5.el82.7.3-5.el8sssd1.10.0-8.beta24.14.3c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.7.3-5.el82.7.3-5.el8 .build-id13924fe455bc9ceb48d06ac5000d7c29f3c62fd9298849c5ebd27018f02b654310d1d9f1e3c637libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id/4a//usr/lib/.build-id//usr/lib/.build-id/d9//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d9298849c5ebd27018f02b654310d1d9f1e3c637, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=4a13924fe455bc9ceb48d06ac5000d7c29f3c62f, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR9RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R:RR RR!RR(R,RR+R8R5R R-R4R/RRR>RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR>adclibind-utilssssd-winbind-idmap2.7.3-5.el8utf-8af8d4ae4dbbf551792756bf6fed4cd2b5da414fd1b9e9e2594f11b168227c056?7zXZ !#,k] b2u jӫ`(y.MɾUPkɘKx;|M\ p/#) ѪcO: YX9ۢQH@)ط׆+;̓O]% Kͥ:pڙzT|`쬔79om"|/C0~!ήT$(뺼O6,HA%vA/6|Jxyt Rz$>ޮy9נ*/[Û4a}uC?yP?tGgCI#'Ɠp9OSC;ĦoڨdS5{1a ۬֨ gNV_GFdM!1"ti0"(5ywT]!Or%p~|U Fyls?3't07$ؐG%ȣo'ocGW{ UsimQZ:a݆z&߫^MSNe[EhH酝xiT-\NdQc1ncqi J$yuK]P`!`sT)z_'*O14:c9D(gRNä[ JV 鏰n"sʚ6g4;Ag=z@W\ʐI8i`=}^F.ҷ=ƪrj"5ZˑeI #k(^jb|WZh&t4 C|&j-ns׽As&+n+@:#b`4~6LTqlz8e>.ddw&sr(H-y#ܸ J3rgլb/= *yp`f 2[B.tbsxqR@@Ku1EyGd" .H ;Bj/a_6x۠[yn0|Kdi#܎vHfV F uRYo&M r[Nנ}?ݝ{aObOML:$(c=SMSUZFhyqk) -�x4V>X@[ry%_?ƀ` ;Qx|`x }O&`Q&u.5gBqIC&K7i]][9<Q -#]# >2ئ%{{XX(g8=M۪I#u#5I@27t %v8l\(f$/Snd[ٌC{(`mɛ%"P;EI  TP%bpF{ _[~4P\r˃;Ifd8[;x>Fo6D-$uK(x *R|5V~Nbu//&7S@8[}EöĠ^TWv60JKRQybV{c~,2Z;YPu@'\L[=MXWI=2 Y7$JRkA 撗4|uK4k{ifaA_V8Y^!`dX~ӿw]GTO 2CgT]W-Nff*.෨j#^ Bwˇ브YPdE)Āԝng]+~|]TaTV+Lp6Qɮ1'D0H]h5\5GMP8ݵS=Q 뾭݋ ۥܒ]UeG] W:pÜù0CH֝1BG4Ž IjX:/|Aw^Hʺ:;ۃ˹oJ8G|)R٬^_ ɐˉ # 5}{60_A 7_'sj-A= qB2Uٞփw,m?_sgӞ]=n+ګ lߏs͑[2 f膯#-1d{-1Q'K,uUfYXf䚡4#HoX228ΞDF%#)}>)xLXqpysެY4j>C$8-O:mtIيi{)ZYv nUq8SV=9["_1 7v:PSAv.pltv(Y`خ0ϰ!wK+Y}=cM]cBB;"rZ#\j!`B|ƻ׹a[WlG *h ˀ#$Nw"`XTKŰ3{Jo2~H\wPW|(#s=̣\k޹=c- X+w-3. DQ8cf-˙"RlϘ虪 Su[NlphH6T?60K6{b o / 3gBA~p'j\R L %EIkQI8:D6ac! HVԆLXk "!"gdQ ;E#yB wYh #y΍2yXջ\ |>˼5azL"W7iØ?x JcZFD7dN+`T@MUx%; vڬ}2PAϛ~뎛;x;O>KOf9oFÂm h0bd$@Ŧ,*IqEbH,x$yf[ aUx%9K&FGJ9۾_gC)p0I8럪vZy95~`+El'F(Fd'P<8oϫ W@L_M5$cpEg/TUFuZOscZ8[I O|\I]9]jvhZY)oT~oO*Cƪ9LFXj{KPQYKbauUgge] 2Iu92'?/@P5se^42\>ka_1 3L|#'fQ G޳#lrLrΩzaVkkT.|?q1B q2 6ViOA㨡/ 0ܔN~ιl6?|ފdZyLݴ "8+6O+kM)BTh7A@PB`z@pR>ҎDڑZj=q` (Iw9dgQXjr1+yVlj+Åd}yD,X9v,L|>1׽|WQGtd } tmSP~n0do% {B=Z 4NVTA5eK>FYId*,!uF Zp5Y"<&J lS|adQ8YI|G᭠*>}R5_`3pQ }ÛY?CH@뫓:+[ׅ N(/t}8uux6Ϝÿ}s 2@HB^pSZ pLCK_E!@~E @|͓3@Φ)!IzAewyu -;Y.ltrc%`ó:7OD|2$5"N4m#ΪU؂z)),ՊT}fi6U(VP[U3E1a%0_ l/O5 eЊtq=-yq9&pV}5Cl@yi)@*BA5O)3`˷®# +2{{< 3%9Jvߔf?~P⎻ty'nF 3DӽP‚M^z59 M+dj/J'ְE׆4"߮&X (^79 %cXisP3Rk5bKϑ `sYY~].:u6Tf|zoY_u%H"<Є?!A~]j? lT\9` 9R̲=BAzmkz\IJ2) tPSږ͏-NN)_^|B6Kvl#ľMUeN,ߦq G06a]U#!$C2CLo+aXŷ>MP4nm-vc>}IngAU!{D7,fH(GJ*4[  YZ \탉A*霂UꑬQAAamH/Q}aj\@xTyK{D> .0IlGDLPآ]̐(I&]^{ Sż䇢%%v[ ѽ$OdrQى ö7C RBCflM9+ddkb>V*AL*JN&ן,V 3_Ȕ^ĝptr*lu:IM{:Q緻H.&g+Et]em楞%{B;jhJ 9SR 5 ,)ާjGos/0h iOdO|NdF #hCKT5$qZGz;M~ow/޻0"h&ȱAǕB%eKXБ]vtR(7L8W`(|\ϥ!w&J(ZPM34e^R9˞\a3"vK|?`uyLV?";=2u$Z;rPvDi+ :oK|bygU@ U9Wۑ# :rE^zb\rc%ԃ9|b9?{#\]S\ݢ^K XPj y/[xl c9U1(4P7ۑ>G+k \$Ӌm4h[ĔsR,amhnDТgSm.q̲vTc艊x^Jf7d uE9r?/^yIK}=Ao>3v B ױ }_sTv]I]SYSէv~%H D)x8CkGkkb [c&pHVm&tbdvEu'azvDi⾹:mYa\//n? sR~aⴎ/g=tլ%w3_S $O`ȽxmJdc/ZYTvh%?|0cy DcS]:T?86k|n;ڱZcc?gȈm޾lyG:I >"gdnJXm6ߡ䟉MЪHQ$ſva(5C;#/RKk6B8i>M,7|P\bb YJƉO{vR+嫍uq0qK/ gKEYtQEE?+PY@DJj(Nr}]:̊ve8jH$SwI*Db+,/'lБdkSUtk]Dr՚ӤCGh(IK8Ho qY4X:R- g cOeLղ!f57wDy G3Uc]T7¤ ?Jx̏:??ΙNF|Hw!VU"+쿗jv_W o-%lp%c"&u´ߎ wZMiKTzFnB ݧQU|FH~ݵ{1"0H_X8 40o2k^s&78zD>M_IjqGiws0X3vl@Gc${ҩq78 tyϢTl=%B5vpNcXK1#p{d#zyUۍ8;IM\!/8"/"BPnCG_)!@ck 󌠰_Qt|]T| k5vn?|'+a3.F3JRJ<0DFފujaL/]B5%= ';|}MX2f!q< K?, Y*H$K(]ͳK20m滅cX$} ;٤ kK5}&]y@.VҌ- >3c_򥉌Ol:~ǘ\HX]1s ͯ+xHx,Ő3cVӠ˔̅fLj#"Ed]~|ECW żb;SXH '+5IY/4J ˏlft{-ZMȜIAP@9g1]Peœ׶?/o I.,o~t[O`* p+*[Opn~Xl L6;˰h v>.0W@ ZBϪVy͠!Kycگo偁;2Q`Am 2[IJ!g''e!yy^CPUAԕ%nCv1Boan~\^`G_3ϔ'd3&VZS(r4A ڧ6vª~Os #D`kMΘA/_l5Mty1PI6TMוׯ$gJ&sf c e*lƶ=„:0v~{<tME8%0sA+-^O$yVRXfz=qxM1vu;P0ޢנLjK ])gYeR7zSE4nbE}&ѱ(ebEf+ơ/4<8J%Co=ѱxb"'`ufN|:".¯Pi͕`3Ye_>5rOb6-PfE٘UOheDT)*lK^߰q+iTDţy= 碑v#p!iAe{k]ΧT<" O.D2# EK$|[6U;(j8Jl+9daQ 㦽gW\tԶ{' .Aκ&ǣ2+??t_$ڇ+8"eY1 ,Ta3~@5:;e^#0Y Oqc 9?-dqb|$T+u0_&磡9+K|-WgȘo[ )ЉKGE S3ITX!믂zy$NH?Sv@I@MU3ƱTQ)Wrr,iUI 1>f`^D~F}܌Oګ`E!Vj6)FPԣG6l}ֿBD؀LP\maDVnT c'նJ1M.g@3J(;LϚVt,fj(W!"YWٖѐ3*| g9|pLjX szi^K&-K;U}Ro.Kr{2R,toM220;8  7U+X.(bB,iuoq?/ڲr](bp$ՃZQbA6rcTL2')0[ iST!d`N633f.$}|ፂ")QM6MMG/MY#YյCG?C(.x0Dj7i,䂺u.zjkCa|J(i) S,+uo2'ܩXʻZcW)yIq'~X](2LUV[:Mmpx*CD)jI6YXI0B{fb6%%(UЙ;]5 *vKd# w.%Knl@-4᪕GLVHL}?#}Q}99 JGy6jU#s<HGhG;C';Iyt0vL&1T`MៈK-C On5 u~{40wǍm}4M4ru#D&&=L%CV>4IƆ|T6,DuL'F7[3Dh aQIۻ,{B,_=E"s_KVcN)ɓ.[r6--ЏvbMKhv-`uw=,U^(чΛڑ &- qiBp7upu/ZKG yz( [pk ]%1IecICN _fKxUӧ ߎ>*:: 3٥ .s>}*5c2hA(Xu6/6jy3}dO-.#*rz X/hUg^{ed3-yR0 ΌLNUocP.Wi᳖\Y8lT8P[n,QvվCTk2N !H]vI/Q0)A[ E6S!+YXh,U0j5Nl}H 4&m:.af.A=A0~I"R}&I7܅rpJn?K 0ުrz/zw-]1R t* CP" >U=+mjr6U.* ^>ed< Gdp$X%O: ^*uʏ;P]u-aۍY,ГĨ brn_.'kц\N)#w 8}bt\(ڪԌQԅBdefܪ:oC` ɋp](䞬S֖9*Ǭ{ Gʒ;'(c`r"܉[|ON:mͅ*[eEb&bDw"dԩt)a9F8֋ӞZ7 `#K``s15>gRŻQ#k:6\%WA_P #8vQ>#% i 40aϜbdw܋ec*Y$ {4E}sJ QLOG}4eǹJo{ɜYeXUQy}Z)tH8qiJ1Δr\>iD/8GH}Wų{hcWl =-8Ӱs{U3\N&~ uE|n 0 Q cD:X'aN^Yz 3^O!Ɔ=H}ί^9}.M܍?Ҭ5% Z˷F$Wo9sԒVJ@A¡Z9P7Nzs„" >`{LHC/~o VQ3epJو&O,E6b h?MW.E*Agw? 6Hk۩/L_SPJ;[z0eY +WQDo1‰+#Z-01V-@'d8r_K=Ptę^$Mp1-#38S?t=. t 3s%^vyGϖP_u7Ygu+a8POauBipt=hB7+~y>o&0N5ADS'1(Z5RXō#R5Zž|~Xm^ E wWʪnW@FÍIٲIߥe*zOUNrC϶A*6IԚ>=g\XKlcQƠMw0Φ8MbC_|d#fK$min'-@J-5".#POߤ.0rʩIƃ>.pBOd~=Azc"eDXP6w`GJFϐY{ kU8D0Id/Wɵ|+ҨYY:Dn"rx&\n86Gn7*"1? }ik#?awzcs0sz^̵td}£2ѓ𙬾drAuB\wgb\m* sOY漘!C^{dCqu7BtCŅI̜B;-<0s(g_7A};D$d>Dj θ͸ucjWI\]jOЉ >>[SX1?Ws!Ut< ;;28 Z;$l|Xq:@^515K,t)EEі#۟yxA=-PS)H@25:+#t#Ag v7)?,t73U:Z} , >8iPˁm,IKnw"ž>πpE'0$Ҧ=XPUœ+JBzF=&Fu?a  ث+\+TS}%.QҋE!si%tUTҹLfP_aV$΄7s.nӈź 5%FTLg7@d>m35zr_:UrVVgcؿ̠k;uc97z蜹 {0-Wsg=Þ=YE!6Դ,bx ̃/I~pﲮnaga[ҽܗM#zdPyYv(TI:僆>cRyCA<2ß4CG|Rex*KdF tT cE)U+W7mLc6#b1c'dmti77gAa O?j G;R\OE5_ A)7p?8TC${`H&_3Ivg/Q~Z&.ɘj . XRԑuA,===7H_τνﭦ{Qk\RQ{W/Κ=} ǵTsoWR[Xܲ?P2nz6A1ɰ / 4# A\np2JgG.Ix^=k & $_oN\-1(2D_Ivim.cSJt Lk0ہcdK6SrE5p!\qc0pabwy߯8yr:*RN[:H+S(mrٞ MUcd3".4dUQܱb?jO%xu˹BNPV&eQX_ q|,?l̆h,0]/šc$ijS%Ilz aܺݞ` @w]bVaNimJ5,?|-J9箥|\Y߼*m%x,о;7#fXy %Uc'\kdeR.p7{@d-qVEb8"3`9GqnwJo6kGyL2~1L`q5n U-B|4dLe)־)&HJUPTkxD`,dd&(J ' 2 z;~j&5|尠϶RjVgg9>+nQ` {s=%`9~ tICK:"Չ񿺌BHZ!xni|>rѳ˝pijAO k IIG4cIa TT\3jWSg@\VzΘ;gN+s`+]Y{qU`RՃ$< >E^~w,0x5ٿ~E mPZuTeT-a4S7ӚH Q}@t]!ր,>WxNwp*POKiZ Jv&HŜcȏFr)B~#ΆgLشP"+r#͐zS>΅2-λw K/ lᩇsXmJc w P@rQd;Y`2Rƽ5sJQ[iiCxPaij E4FOTaD^b=O܀DŽ" T<3 e`LMs!vu[)rt#)$5FO@(v1#%&L^dOm($|.iLE-tjcqw!GU;x1eKS"9ݨ3Ošʏh3󡷞$'/ pAg.vOX_2 `CX⠍DVMj:]c)Η6ҩvD)\fg7iIJƳ{=%zl2܈B<\7C1y;O]#\bYJsM,"i(Z )RuST ;i}r۠Ƣ4;țL,( -u}~ubh"/XCQJTv-JDr뽜I+$R|-:c}lɟH@4:sm@F{GsbP) ["jx2Yml#h0T̃ Se }=f'J~ Nt/Ne lYZǵ QdokGqV Ln%p*߰†L\11ۃ(yXE Q[q0H^!0?zӵS^ar3O/4.4t}ˆFҊ 8hހh ߔ[cd, XD 7y':I3.E,e{(gE5Oy* ifr+%pho;N29\Yf:".vSBtwtM=z4:hʨbyYl@8f| Z"ML(E=Ivτ| >T/*T{ xܓ1'}qU Iixt' H2'L ?UAHq]|r kųLbO˫xS`##ʯ&s-[@Oa }v{U4*}Bd?o!qũ9>67DѝjЙ$bQWO4pys+Q\A#Ž2~poT8_#*P6 S=-nFQsʶ)f"Ut%9c2^S,$E3 EݫW{W~W6)fitۿBcmn11Uo;%St`d+ z " e{c>aZߪT޶(fEu^ۿHL X APީx ͆CbqLݡrwu]RXaC%&҄Rf ptW6.=NbgmBWsa/@mОcb6$RZ)J)D\O {ZYBEEw`MY+"io34j,1!Oȋ_8 dgx7)8Ch{_0K`V: Pmœ05 5_-rYR2|2ϕ >Fbi᫢г0e^Veg1eqETjfwqB )=3q(\eUgUwRc 䣀6a֊W9o28p:Kɶ{*,sM}{^&wub&~9 1c՞75);|> "]Q"gtyn M .r_.m6`r#THh*lӿsoE!ߨ7R#؎"9xʣA1 glտ`bYp2aQ jXk7 o`Zq~5Lc2,Bc YHC֞h6=YNh[Gh]Vo<[Q6RHnUp,_ c2^,E9<*7?j^@" Ox_Tu\,I^`HI:Y͘MOa(x=Fz$@"!%=><rX\ ﮁʱh:r3\=Lw5ȭ̸`˭=uEi* %j6\Rp&·a0H Ps7r*F瀤9Pg P7ȧ: ƸyYAD\P7=(PTg7֚G@IꖣPzTQw՞輙U1 9јi„2˻ mMQܣ0>.\Q4N̰[Xo8/Q"v*SS+yh)ױʝMNXLpp~\?fxl.0PT&fg]UXnuW9F--AniZcW|Ƴ=͖IxhV~t JÉtƤA|b==}0U )""\,Ru qmVHU_3,N$N$- V ;.  yr>uʜBg,tz+1q5V&Gm*E7ůBZ9,?y+xGǣڡ>My#[ mثI'NϨpՖ/l5Jw _Zfrs&d%d%T1nǹ/jI4P/f%tpuhU2O6Fn[oȉ}h}f&;1< -0VDSٵhbNzFcH0!f.2,Jt=RJAnýx*vo<:OH_|S՟Hez` ޫ69ݦ=bΙZmY:"Mv=:T˳p1t ta}-q-n 1S a&0>np8߱U@zt5|13pT Eӳ{+DZA= NCNGʓZC'Hؾ4URStR]Z[ wR Je7${?PP JbSh*T muNW5 C;:\1e g``DSB]u&s_>56JDCϭ jm@Gͣ`rɁ:=+)~;.VFONG!xP!X!L KH+y `U|) 5V %䈭03^4*4p#3WDg<'KY uއfb|Ac䢃${`4 1ܡHZճ4cx:Ak|ʶp.,H+`p/W˶EYbLsc/e'KInMiN[v`~I(]2* @0_"U4; 'S _gãЯ& B\!wU]0AHxxCwIiO$uĸ)sALʇ\Y-C-<ۊLt9z?|11H';鉤1 $@,fcԙd1+BGAܔԾS,OgU]k|(u)fȁB?ezC͟fG/@2tq@ ւp"v:`TnIJ;D[?K׌Y$2kDo;:GAj5MƗݯ M !_0cDE9Xy܏$i2`Oӄtގׇ b2u,2ysx Ҩ}Y4' U?5eic#Vx mW+'!DkIrMQ룯NU8[rxaPn0A/>s|EM"C*:LȐe,8̊ ¼y7sH Vvת (ݷKFne `INzYmwprT9Jٺ٫tL8b<V}6KoxQDFZ,rtKVaVL2+{%}<(c`J.bZ-V~Dׂra> 1Y8>uG$DpCQS)ifG_ <- '갚d?f5` /_k$؃A-~89`l̪뀭юd'`uGǡbdž S|xR :4(#QYaf{ɠ;#&޾[rL!'I?%҂s49v]땨aMN'{߈ z:79 ĵa9 bIJ+=Q@OE/p V AswϺIvaraf 0߿%MO)wdzݑBHGx[yAP(vznrHNNjsE1h ͞&ɽPŎ7b?܆|͛]-Yk%H2VI׈Qqd3V?xWvzbK ?%gEzM҉1m/P{-m?$ 6O(\H)Rzz6%P|"B؏Cz!ޣ^[.xDE?^K-69Bh I3tJD+<|2;3T]q~5-]aTk1ϣO`{F.7=oʈPX#*̇cdb(4b ȗtGGM'!:֟Qa=HswR^̻—3FKirN蛾Hjp0aZ5w7- <-Uy#BHzd7McQ-Xم-Jr ql(˥L,oI͗;? Ǚ;?<U1b@d'@tIv-)Tj[Pv7|I\>kzG{}A<9 OGV\ip #_L32Vks/,5&Ny ;FԺmhCV( ;M_wgIP(V\@Ep)Эc&*we2Q>iG>- F17QD<3 7RG;Inv| mpծO6TyMTG@8 8Ub 'u &Ђwsfe{o`a^tPȠȔeNN`En7}־:ױs/cF[TGN/v Y𴐈.Y4j+Ɠ aB|08h$+iIU$CKu:MOdy Լ_cpZCyի˥A`VA=Hl)(# Ӱà ;,uf=@K]ػ4hI%+OEű!ط2Sf{pÌb,U9_ܣg[7YHcEljc[M+dAUPR[^ɖaB!fA+^yCf a~Y 'L!48}aVȡt<+ibB*/Ql)!W4@2o;G>y<$UF#~3YOG<7aL"+2yn%[io4ΧcPğu uzv%䎻DN4쌼erzC\8A5%BLFhen4\rK$3hP#&+A9yPNSCUg ']cO> $wѠ"T9|:zzk_'rI yoN0l? 26(DRsظF*g^ "e+|܂ b7r(e) t PZI"Φ' 1bn0K^)G/Sj"("Bl[9:7kGgZVmB`%i2:8Ff}{t>5:@6.ߢ=vIz6NFu0OeyHP/18$'pc̱9my+d5" lɦhugi'Uܨ ۴`Rq,{4RLl}s`(J4Y[Rg=\F;q0EjY>L:1ӷa"g}t-R \4:aV.N6cuVh.Bhmu@-kMM_ N+CMUСq%>ғMAe[|(,D?R ME&M2'K$ W\}7mMZUjmɿ)V~v@֎p[>ƹG$RDiΞр TBD^g׍{׾4o(yrR Rjr9<[M Q_ zK_gߦǒjܦ*}E-8P48\>ᅓe9yЄ ^ǯmEcW0/A[ &{˪/P /ZX[dy> {p+7:JJ28LIrĚ:b܀`6i%yX4 {$|ua瓠]>R`Lف-uVhS9U'6 ^GXb-숖+kp,ͮ+#.|Q1lzãg*83W }UrdRnmwJ ْ`w:"?󯠓G2zT)g蠌\䱙=`E԰2<0-&'bXf b(\u?pW#e(xh-䱥Vm b9xFވQDN զ8KB;*D~AmR).od¤0,፲Nn9Cʴ#eo96gB.2}:(A u- .97OU;rtZ#k2aiN{T ]R IP hѯ L;pGjjN%5~N" ӶT)o ]n e+݀EPbbLF ٚH:0"VUdtY:ag, -sH0btŜ9mE+ryb g,`HfD!j"%M:Z22˝>eN7ZS\L5_Yh*l@U 5SLtnMZϷu8"$->)jܤGf/xԡ mUy[a^Hu46*}nDT>kR5Oq?GGk.z_jhSEf^*KZ2QN~򕊍^$knX(R ۹}=,^;vMcKܟIAG 1yiڭ'#@t+]Fz3% WҧEwQK=cP}^9}+&īaagRww-S?ه?L0P]E8q{Rt@0Y0I]@}Xd߀fbzXa S"@K! vp z2|SN. ~uqъrB:styo)Rܪv_*}zCr"{|bwB[J#'F\)e\ɫ湘MEGVP:8(njk rv33)t}Xu>i7k A0NA戻/gGAy l(e1tv"i"(R(1\FJ6:-GOHl.pnTݵ5mJqHE,\,IC%(&<&g*6|QG-;}R!|sc>J"i  2γkJ*X:)߯qQ vX*?81`A1Aojquc?şʹnZ#easgw˼>:5;Nx|cQO r{3UgA=zJ?F%=wIUE6$ϥ#lvI?6P!8KV֢~:M%aI>n\P`hZ qK qSosW}Yl0{Jy)S*ک=Q٨#^@+˚ ZIv흨 r@^p!N};z~bVW,I2 ׾K3<  'ہS!Qm;Fΐd|BK8$E"Ԓf>4CޫKu>'\xgÛuCh^h5ėuZKMg,nszIfsw k# @уLՕj3TNdx8]!^YsVe]\ҞpTDjz \!8ӅVF}'T"2FR5M[ɽ神xsfʼnfRl8, hTۇ1rd=Niہ*7Ir&lZT4+JZVc]%$KHH?Aybً[s^d n=rdS3446סi<ޗ {i`6I\ AڧH@}ᤖc>:E.L.Yq$6VˊʊJ;\.+23eJDUACWr^dv{buw'C]]F%tBu$v@нB 3D!.Rxa3$˶#kPX,Z$oD̨yR!=%ػ__1m0|\Ua5f . d1ͷ3uD5b5|z&[6T KU2o r$+@?'iب6)[2;Z`N!(X`-cA ;'5@ sΞKץȴL@㯿=7ml/NX3d7j)U8NiR{u9lW-0K M,&i۟xBJUb%7҅3 )p/$R1r߆@ ]o l=~W[>gNȏB^:[!+,XY[̿av yG_~qYS#ul 6FZ{5 l*cb̛o1+?_ bɠwH,0{l>f2ǫ! f1P.JzuL:g+O_OT$Zc|!] ^[iNэkUH˧lmX .^;IAIwB|m1x۾ ǯFF_HQfzd3.{I gSN A1#ݛ@m؅\Ǣ?=!%Y"g'#o7Ap(P2`Njy.F$+ʑ9i{=SϼuTYkT.|yݧG:ܨJ\n|\s(^2Q -\̀:bӱ!:Sw_29 5Ô"Y-N^-~ھ۳)䵹#3- 6Gk~XgYIbq}_>ZVY, &k=X =np( RKSpc[e|=b'wzaPkX<.uv'][S;MF|A`FW#6쭓#Z;ieF\|3 Zk8av](NsC udA\.0G㌈Ooh.J3d_\'DS"ZM!"~@݁;τZ/66O1E@[e%x)-z%ID92]''nMAY[6[ﰉė8GCUjg)"ecЖ{5~q  B,QT]|d-)d.@$+!ރpYUu'XM[W/_!"XwsrZA4d@eh';`.pIބJbo4,!H]yPпo@!躽'h>("EP%>zXHʲAE)R4r7jh: ^R@N=ך0IZ= uݻUͱ` -˨<%':c'XJy9O ?,Nlu~v Qjz?!~WZf2]vFS䁌۪ޜx?xz-HYdO\P?(`/Н-\o{X3coy=7TDː4S5!#>OOEG68e=Qf1Jc#@G}r Y(DcS?hW|0SQRk 0idUAaAy[ә݌-ܧ*?v(D?QnNjnlQY&܎c1>s|w657AvM[%[aY?rCqκ M u-T>&A[2ɧ, (1JлP2?Aƛk#=$Y[Ԏij5N:ֵ2RšW[%pD/U@ߜ%s_Ev``..0$nR v!*`$MFI:Y f#C@I Յcq_Y=һ=v#bϺLN0ka%F0G$΃tJ'A!؊q*+r/1ئHx3cIsMVAjIvq峬ZJ<YGC9W>0+ y~38֓?HbI q|ѤVw P #jhyW\IQJO09@םbʪVYbQTt / d7eZ:*-6mF#tn)dfi#5QC8L>n}!ο= 5nÐx #h&MZ. nSߊ'6wYlY_ _C?n3 iIZ]#7er =3B/pF^zaT;:y=S1ݶʼ42hi2QsaPn;~hQ訙v,xCڤ=/PQRke&v8VD IT;aOI|Y:{\u74^f_hz=E\ sY:.!I\қ̖nJ:`KpNsIIP)ۗR{wr65 Do.u"B xS<4@1F"`L7s;wG@f{Vn2 M< H+5 4Ugq?SϞBhZ~^Ns>IMG'Ӯ1GOU|]ŵHA0Ew;k4o.S9A> < ^,C-.QjS/^NiW"HV{Lb߂ϭ.Z5V3z3 *6*?O/1\?T%兀L[HܜpgL}ݳ$! ŃTe8zۦ NnBd`,46͈=vS-ρwN-+vڀ~;_ 1_3LG ή۩٣y7~/B3b[~@_LLn y+k8.8fs&süX$ $eQH@Fʋ 8& &F䘀GĎ?nRo0ltb"[CaǶڵ;06\7Zy?WMS=AD)\1rc_PmSEH/dz`EpᕧB/y?RآйSʂՙBt\\ ה5`I>spqjɲL*L @bGL  (+oSdoQE/v5q-y0!EVYQ@,h mﯦ㪲 #od!}F.^ I;2#ph<$Zw[aR K? $F6ɐ-okOs(| t=ɓ,Eв ;@raP5kjOp?TS@&|?]N R\ʻ=C;HW~WE} L&Lf@b*79ϑSo> ;EYf7糴)j~w"&Hw;N8dxWcKrXN_ZF%$ 7^l|9GA/J1&h'1&Wx&L75 AG t6%[ڹK۝^ npWrl$ScH\f0qFE De~Ʃ\x3c9?V:b+,¦ki, Yj,8"ДGA:/ G" o}۲yM!+1bj 41j QΎ6_?,0A%Yu/{0udڏ8kloNM%lƊqDd %?F;طX/!tO`{ުJ I q<5p3)wl9Ak - L\8WP˄L[Bɷ6g( 4囕Qî|pUV&SV> K^h{uq=;/i0: Sw`6_줁Ķ;eHtOwIJv_hvP49gr47h=Zjt#8v[2j)Ҿ (SN?'?8&RC9sN(-eJ1o !@V{]#Tn!e'.ȵko rY8U W-P᧞op uZ려hd h#A}R/S҇rۉw/1ϣӰ8p!WbmT9 F̦xhbB#e&g]æJ7BN+5n 4uys^z) ƕ FW!T\aWqدYuVn';ru#nQ6XDA/Al/d,N2n0Obi=؂~<{,!GO߳Tf\yQƿhK!ndp@RMceǑ[XQ:!&2ێ Q ecl d~\DveR48qÖL\`y60k+ *Ö_me ]_FxTu!v='a!lo };<'%EܢS.㍰XO|t0 O.hd*[}{NLzqCEzLw&-]g5E*.W?uEv/Av^.bKzٗ~ya%"-a^ ##}1V3~_B(|"ܩdr&rj,o7H6UDeə)/nud:),fmR^k+٥~ܕ$'+Q(B:2MNjp1뮥8J+ .n60FpnLF5]Q^g;o5UE+jj7fU8ub]<{D'ҧ+ %:ݧ]حY!~ ?h+.آ'ٚ`bȴ&S#DZin=E̦ 9] gF 8ꨦN7 \}]n]PJn'l?<1 M^iᒽw'Qpк ~ImX昍9޸&Um]=(JЫ j٬-L"`D,*R~@Z+q0ze Do|sm0Pw79n!BnC{Q-HQqL~s=̩w)*Ώ-%8%H-?\@('6vVkakh.:(_SVl >$KL.A\B7Qr>tUbމ+uKo j; K+Xm<}U{MXjz &<_1V>ѢWF^q!APWҕo>2Fav/\)v/7&gCjIm ' x^>NTIOP-qt1SHBN]x>~-zqX>%6rx.گfM`5S=)t 'G\x!OJ) }fܳd}%c٤._q,DuCY^TDrԭxws>GZžvFkq?atpq0;åwzp3;AFL q&BlԶ[k2,a|Ux\95ϸKb &dhW*ǘZ>jR#,6L~ra;ėmhU5.T ߷Q 7s8 |,rr]AJԎLAH)-]5 z0 J:ފ&7Dps=gʚ#[9õl\ۊP[фiRGKt׎C8P N' oPQhx_P/Ȧ0Q;mX2nا^!u򽦖ڸBJǴ#oW<^'fS#(z 0&77qHb](ĩwI?]=ྐ(u}mwZ ۩Q QqxjݓD$DE D5u ڔjɵ<ͳ$MYfWv{Ʃz:- l,dGsssp̗դ] 4')Eև׬aHdvi7GeNs[,*|>qHEHv)yb, 7x*v&9aMD m$ zu{<-*/ؚuB%89H5ewjkPoߢ2H.'/#Rvh'ExT*89eE &~VMM14Ux'̯"% hjsk)(ȅ [*98O)B*b ~;Dr?bK)Zz8ú1ڱ@ >mvAU4Lԉ Xlsx C1QuĄO\[O~4H4w`KX L;ݵ%uG.Q,ۺ?H4/~-ӗ{>MR },Bޤ1@,\l~k 14H`Y/YBK2OmOn%{irH`Qmc`/m}z}?!J4v ꛹>;,-F-yq3@tOE&sUcVj.ܑ/uw 2C yVQX#>3b C  WO .7"׆עX%0ܾV2+=~c(9j/8(}D).Z8Q·+]d*WZJ_^eq#وXܡt86ylR-5)"M_Y=Km~ȵw5^v"Tl,dRضL<AgVq._ Shj}0Uʰ%]WEvc8̼mOcs "(@]%:΅ Q5q:ar_vYT*$βwlj#;JpIӳE~^E刂@iM0ݨ+l-;ծmۓW>afx ?92 UbU\7 2qjL7֠*%yhn$ֵsE}̬͑ZoDǠ#;`׸gFmڇTś/m[NM-0u?Y :];CGFX@Yhlh.ΟJ p1ݬTxn !aU-3T`!! q^E Ppw"j|!Tfޠ:ʌTlÌsv]=o~O^98sffH MKԾ QьJu1|!+ćF)>Af&y tՉ2 )I~\z漳ޙݻSһ^!hJ sDa"`_f80e 頿zrI6x\qܘK?(Bg]Hn7Gᬫ7̵?wC!OkGOxɑ&Ra" Ih𯓗EAȅ+WE$llB{u&Uc2鍼a`_" O>2GRS˙^_qr%o\k-tƥ/OL%"BfăOUCZ &I^woSF;}p.ouc+jx^&as7$f13^FU|ƬgRPjj h-e/Hö6!^- fhv@Fnl?@x49yy-Ql_2> 4H*RiY`I) KTW wa!lAar&?jxcכ[RlP1Í_/ (7 R5u`cu'ۭd G7IŒ,ˈH%nĉg^$^?{G#y"*^W8 Wb2 A7\|l@n-+<ʻ7d 9Ӱp1meAd&pS pܝ[m >__rk XreɢG UYoF ٬IY,4:1RO* #8H#&tCGﱽEt,}`{jŒ! 8+PIS(kvTFl`V<=̺>[=O!c2i7J$3>=zq[71|'Զ~d7 'r2A|s/ )"0! cd$TG~2N+X,&f[BLy{$F"G'IQ P*MhܩK)+G6idm.mJcpdzo% )T="(!(*hk'uDS>UK.qPC:C2Z,,rwը 3S"K_;|\(v Ըp UgD mЗPRHڜap-@UEȍ\7aۉ!< 1)#O㌍{8USn!:c$cZv=x\.-GwW7XV҃ev&/}[D0Y 䤁bfȨj윢(gǬ|ڶ'7jfC{ 2J9bl^PY\mvݴ&@*~ z{Z_?˂ jvӐ;RKߙʩ/6Xu$5Trz#jU<9dN`@80#ێi}uM!rhw!lїhO,"8k0d*/@9B8:idWaT]6zDUvvn{'v*+Qm!I=qHAŴ;~.bQl!l=SU6C3P|CVTIp^+[ xⷴ{VZ|U4Q cS%ݩ1VI#㻜VapT4f!7ơ٢ Ox.V3ktt= ϡde`^)?RaRh=΅>?u0x⵼J_1 ,mE` ET<;Pδ ym/o :+r"! m+V>!L-3 beBPf4w m^ G`%\*"Bag4ʲcٺh㉆(E$J Ic$dܽ+UB7=RIՄԺSؤy,%?d~~;|?wpHoǯ/Gz^݉J!,4V&ޅHȜտ֢a3Z{͂G0I~cL6&0yy}] &4-YaJ M BFnrkR? { spI~a ~`5x>7Q+vyWEz.$T'& p޿׹K$–T |'ϽY:)|wj/ʖ{nR2k>zg5JӤzl"w.Ք-bD.7K7(N\ I1Cq$+LM&.dT*2)<1VFW'[2}؝|'p9O&B6ַF3s`A2 qOT=g\Jծ+qA'nt]dBNg;s;"~vs>`?lw9ȭϡ ŮP]S'Þo;E"!:C!D6:ɁiqZSH1^,&ğkIjGX;}]HCcK E㯁_^ #Q1?\N !헾J9a]bm߶/6'pIZIjIH4!e,BT{dI<;w;7Cd0#˷THTi,#DbJu{ʕ+5ï\ ET&&f1DwiD|]YF|p.kYmnbf>t[ż? .Rz-o>#x^=G ңA/*4cǍtjLC5SFx%$hPCŧJN_&. 5/xɳ(S։Ӳaz"y\e9*%(KYnMZ8f8M |2@uI0ؙ؄cqlSL%2MHLZ6*{逌.rqJ4" RlV>5H T `8PHų_)p(젆dσ;EGa/J$VVt!TE޸i ~lMV=!l54IYǒ}:,iTn^mߚWKkY͞ UO-Z7n4u"Q+uKӢ$H -4x\d!$c5?y̧ %YgkxJҝϦe OܿYNg0s>jVTF͓[۬%pNsIs=Gko@e/o*,fpNDN@ ^62S9:m Q: A3d8`Q sj-7JZޏE촵5:|D_'B݈~M Y,_llKSi<}},*n[-,,D%(ϡV` W;ٰM ^ab.ɸU8@l~? ehYc¢n:םIfHk_ }s#jPcER59fb\3陀5_좿]jБgSm>\x͙fћ^$-L5' # oHLds~8*XMoV2.3h# Amſ`07O+> z$nH+(̻¢*[6BNyIK?ϸ& 6oI=zkMvd*qxF\N1oqJGG / TžC0#ErRrQPЦ?{+bnk}X〹6n6 Dig;NӗˉnYa:"+cUTyG.&{r9aIcC\KABUkMUL бU>֡V|#ɛ$[>/]A\DLZ%8A?B sLTX'f \ʖ"{eX- (>A55Ey究[,+:,a޿!ad:搕4,7=t5cKb=5үpb~dg?Q%"4VV3至[/FK1 X[ " MdR5'Y"Z=QE&H(O*Fŗt6!L]L\\AS3gOy;'@)pO\xk=DJNꊈhsr0Qk:U:үQ,HZw`ځGDe'-SRzfSx62@6ZnnGCT0tRahY.4$!gv0>+t7KN0 +}tV|&29y9=$^\D/ClP"͂\K'4qn[7GhuܺU! ڣ^4/GyǏntDqnGy.({z4WJa*WDd߶L@\KaFcWS'ڰ84"K*x4Op4ߞ',H73D*'VP܄NTXxAE8 ˕zc a]FӋSΰy#4VM@͈dJxF6xNC5<.8-B=_0QOϋK~'?C6vrZ B=`<*kfâѐnW3F^lkAkԵb~ 6FʁEc;^VHA}\Έ hcd$\^/nu0~_ܤXa?svo9/˃Z 'e2s&EB3,^ņ`ζa :͢Nix53Jt*@_-U?/Qj\Y<5H]cvi6@COﳙ~m-r,F^͐rnZk{ gOb6(anVU{PQL K ڊȾA21OǺbaqD"sCoC +J7Au<{nˣ`MiX5^}Uꆬ `3vhs^s?G~|m nG˗GY^;¥A]YʛJ9@30{]l/a{ko@!+Ϻ&߾)4=,8̛ {Bc\Kq 3q^Qp*ŷ '$'((*ț95W]+o\&_te]d? F1 @"ip/ m\4Qp/œ96E ZV 3V1_o n|P4n=')XPI ()[۪mKy {@ugM8L? Ó4ZZanħSuS/$i\d6"@`g7\%!j7A9wW m-> Tc7<থq-[s҂2 ď);Fȟ쿭8ּSAXt8>^pH׿'pV7>5N3ϿWO7UJ`l:D۰DPƞ{Um牕n= /]`ïye{шz- l`TA/:z`kN|(!xe*qz%s_l.V@NjxU].C|_6$1Bx*@r?*dh=z DȤ6:R >UnF7TZS'3QWgNeOUMoG|]})/bM筀B%]m(в+<" tx ee2g8 ˦p{?lA}`z\s~4\ ܵݺx jt+ [s a `ۋ^#NB1 U{܆aF HmPa5@qmxj@ZUrjF;pژFN+!/cq<]q+9OTF$Hȗ?  tyÀu8}G5N:[={闎t)Vg%Q^]GJeoTB`rʓ[A?dEH:VM![4dp nlrS'F$-Oy(OtudG~y=,D4 8 ?mYɎeOGo[x hxW6ڋtD39R{3Hg eZjz[ikaMN܅{R]8{[>^QVzޠ^w󽐣 : 21<4zJƌgOӷYO 3 B 8YSCikTǐBfAv(O_>wVU*XJpZH>P=Hpȇsu8 ~l3r x~u,KllߏZs&v;p*ImVrKPy:םp?hcXQ<ѭc<ޣnpD˳!e53Y0:=0~ΖPs-` ՠIy $KW^ VFX9U{To8kêQhOٚu/N'ևOC;KIݿ%Cdhk"V}A;lU{{D݈Q}v,wAL"Ë66jwicT vH.5/7܌h6Xn7 5;YF͡m6ʑAj@_ř1x`5'q@/JKox*lE%FE{(`x#mu{0-9S~FMHWjFVjݳRn!k\トY)YpkxI~<']G$-2dr4܈20×jm8+n`>'efe:86k~j8]=kr2[BH=E\5 EEh!E|{f 0' S۽YeI93Ffٴ{*Dr{$?Ǫ$mBETxvy]4[0y{ t/i-wZw^CK.\qRa|Y+f@grhvv_1*+"Z8eE|׏[DzwkU49's25fTJ^>v8T*BDHwN#Lڐo$W{Ҙnn 9J S[J2st|TkŤ3C:{m Mg,Lؕ4*e7< צDb6$c3ѴqKQE':6<U W;CKo1͂4kqM G槱=ol'\h U vߎib#] dGn~mj4pS@71t^r݄>g倎Lf(  V {&Ą\q'%T[PMLDY8*D +F =pX&zʻOBP&kQa_T-hc9jqȧ差6ihuO{j!j5kU`Az!=x.FQ|JLbS<*ʔ xП6=bT ן}>`&q;>9COjuE|3mb3j`_MtzxB5tPI*A~3,~O1PȦ̮zSf-(7u"َ ˷`Lj0(_dC^-l5 "˲."^l]͌؟@rtNgpDi\;CM=F٣urzu3<6rPsX n+b~d $C$Mw&Uol$G++E#y-ĉgXͧ2ۏd '%?qTSQz,t9wufq gN!ڳƄ˫DTNӀ#l)3 zJF̳-vRCZ=?Y=\9O\7 ,AG×s :MXp䛗l1PA wřOjZu /'93$ykJ@`k ANsjbUc ]d 5JO 9`- b'[)y\k[͘o`:t٦iEQ_"j]Q?}&1:EQ3[π7A> ř){3IijQ^-q{"c) nz%eòT'4=`^قj?rq[y-"|_Uݣ)(щy*r9!RtͶ^Af,97qakUBZ,ԷxXl C(F^RW]TwU ̚׊څ"GL"f ai)WD{zZ"KxsiOFʲl$fE+" zY.=4N[PEm\Rd! 4wxTݭπapNVszYEQ#S yf^[$b887#wzU*W$jY~ZfhiÖͧ})lrDrN42\X_Ydkz,][N0$Q4E>Pv\uî6o<;}*hT^jM#y͚"),2j:U k WfFc)O'MLo26 47>gH3œ\IJ1AR>؇wy.C3aXlh&ǯO+jFM3*/@RJ&Adg.FC)k.^+gF=cbCHLf\bkKA;H ԩޞq]B,A#` !k*gfqx8>FiH:2El$McoI1T BS@ ㈍k<Ě9GUb; QHbf 9$ø;%`FԍdE;A|-X%/S9$vUvAZ\EVe鉥,'4'0IΡ~ |eyiMo* a/B1w!)W/`1 RPM٠ jsۻ͎,} D" `MJ"t۳RyXiysDNDzicV:Rxm2Q$K(tSt*2-}Njqo_UJI 6(h}KDp^l%d wBti?teգ~k5O56Ɇ6H范vFcK#eFS!5 Js72vo k'M)IR,&!T*tF B¡x9&{;8c3}q-jF4 y5|8٫tI$ Rf)82NM=oH9}:c1p*58uc4Jd^tX "#1BOei;up6u,tE枪ZCjsš!B'AgQUNBTMYyn޷jaAQM@Oay7e9]*5.>{`vP$LT6޽I-:~=>O&&} UrI~Í5t(Po%d^P(,?̛eR]>WOU/J2NA|e&Y pa!C,XhJ@q+ӽj5ٶ܇lx[w.z_HX:#T@gAmys6=yɔY &-ؚlISH.ۚ0& O]%ܚJzD:sMnbFUH,ay; RE/c9Jk=q B)ƥFWZ%6a 7Tr"V_)_kL7UcIa_ڞwi7}kMZEKsOv0xPWgVוC2D@Lm4=<)68fn0ң`QAtWfV$Pz}1٦\|NeS˟YѰtU/2lOӉDObJKT&7Y)s]I>*&eu@qO^gEt/*Jm,t]⧡ٜ5sxܸM\"ZQɇcMۙuQit*P„DU#Ʉ!hpݓ'Ak-U s/3|lK** v<އ^^كZ2mBr$7:3+x$PDPgĤoMh'W-}gքٕΓO(U1/3w1gЉM KZh/8:պVo+y ]2I#[ҭƬ'ܲզ*lb!2~BP3aq(C$-sLbgDIQ&7_m? "kgPaj-6&[ t03Ȋ%̍f:o>OtS߲]bKt(UdБHM^Aʪ_^B'zVUUd{!Ŗi`ul-,Wo0&&HóaAE`cOC)ldx1-eͧ՗qRu65 +Ms? >yg4sxM\dxElM̳uo[T% 5?mwnGX+[a&}i@{mDV{d)Nd{P;NB}U6#hk7+;eBjq:KA!5?{[bI;d9ӿןv"^IWF+R p*Q3rr+z0 @aOCU>Ί{:ǰxjdZ[4uqOdui^o⛐=0$ŃQ`]Y[2WIRr`7j-IWGdxѬD5-8d[BI]`= , W ^f`tܣRLk9O-1ßozKMK%Q`Ղv#xE m-mN]a%$]?9sBhOQ^02G 'Lכ4th l$LA|z)pN[7-9îvrAKf,4=]FTzm dG 󭎿VDEwJO ޏCAM\RFR/#J-Qrq`9ώ^6fJ=IuDB (,iOP3m(yH9&NǍ/bN6!m VgÓ`yĚht o9`&{e/M c`]v3)b֫p;!X dž=M04 U0 :үW05j#=AtX {wej F?[9w>˨@l_Ñz;Ci2NJQV3o@v II`ECx٣-0])/m LI\.7/Vv wNkk46C2jI'_:82f7 9AqL`ۭǗT X=zP4R~]y@;\ߜ^D\ڧE'!RC2V #u3#kXڊM E0kxϾl}||$s=/ _ZЛ\ MaΎ)H77Q4 Jx'\hanйTdR ߉viI+m&pVp>Mj)з6&;:t<ˢ&f3l_Hb70i(_G'$3=ʣ?b% 'C\N\Xީ[DH:5B65@Eckm9CllVO@fmJ}{r赞#c.ւpeAHռJ-3+ 8gy 5ZBއ}p-BbVð(;0PaXD_$l͚8hD}\K&NIgW-6Y#°AP.%)% N1Pvǧ P^SP#kg C_ns0 5 u\p۫bx ^\(CSފ??;,)rǺ65̖j!aؽ:py+;o+[@l7(1o% ?uw:{baH֝2pz͵$1{ã9AS <,ok~MVqk`ݧ4?0v4G&ZN[3\[8#<$핍!"T> c=ܚ%-? (c+ Ue4&Ӝc VO? cATySMdY tY;<y.'~~A-LMGat4t[\'[4#f~K޿waK86 (3C =v&ן, FsTmK%&,qѦ~ޛ|^%-iG5-\2 `c+=1 29kPYFĉQa!F2K0--+[S#;Pm֤E] X }g0ib3^.H>R>W%2@uæܾ!Axngƭ'#lmD~Xd}Յ~J>$sE?HKl1y0+23、u)\I I pgr75BwytuP8oY-JS_Fԕ6 sQK8ٓD6/۟=|(J(=9?IJ;ߒ \T/`.hA軌K@ҩeJ)uD8+RE0j{P/,jl|,]4JC$L-Ic4*} o  gO?53Mx, ~+f,9)s)/pԏn*P> fбZl2@bl8dU :>J16!"/aD[%t_L 9jf4 yPַ}-6pOTй#˨< '7җj$nE&3zΟ8PdnAPP}L|M(uҍh6 m \\O5|ndߍy[GZ/ˢWZGȑ^85Vj z]Me \ @)l쮂V%9-^/s/֮6Bwe  XLKij9 HK>ޮZD_u/ϝyq(kf $УҲm[pB8Z&Y6ɯ;M\cpZM?5qlD&M`O^~)q|2%t!gFS)YsrD{bm6g fi>bj~8ODA_1Ug?:DdGyC: !SXy4-y)m2CѪzˁ&Fx߅`\Wtߕ~=Kl-PBQXO3;3paPr$GΉg 'jg Wwk  2m[. Uy?gch"އ)H \dvX.EЀOy\+bw!oEFv}퐍ʅZ86Q*ċf-;Da^t^)Q:=rhucWWdShhWݗNp'O *tCN*ZEHBJڕzn#?1d@3jzbEo缺mgGBaڐXzQRm鴾Nq.)UEɦ(\y-13?'KSPNFX`eX%.ƀ^t"P< .oQD]!ҭ"{{\1']%x쬼* ݿD8ELN9eB/D.@ًsǿ Ͻs})^U4G;D 7#& jnjhLx.^'|bUKp+m@T S-;ӛ~Mb9B1?wv{5(uiSd{*fS`IowG()yDH7.{F~F+`2"(őWxކ:$ s!h;#TT5'E5߀еH>hϪ8gsQMhV$)EUbȳM!Գ5ȶ%@.\IhqeY{DnnnNLGce/v}%x[f3>EE;J]i] *omdFU΄L/0 k@O*=HA;l@ETAO_0^JP<.EYvA45E,W@5]28 ZZجG ~ $p AKXmiO+hpTtHT>5ߢϐdjET+l'cVh~@#.RBmXg[%h {ٸ;/!PáKoWӆQ4Rmmz^!j[cv\OY]k ~>;( 䣯oZ?\2{=?G%[FNL&ō)Gw?LeC$cjEb݅ -F6+L1dQepAL5Y+lON0BKz;+hr. uIk?QnGې|| )G+Ū m#?guŕ b:!ƥV"v~QSDi etl|7Ёe.**b r;1>;bи6CMJw 9^~(ylЛ% w> Bֹ!QI7$q4b1n.H0ƟۓM̴٘@ @*~,ؙ6q4vwEi*9|_4F<]DNG<){%{l I_Ad KomnCKL3S~n"ʶ] 3?`3 aY2H.݂511ύ OD$<女 f{E`Äbxd@"ԉa+WJҢ'xŇ,}%sK9 R|&"})gyA\K[J^FDirD&olCR!aoe ax瓾I8~cU  f3Ck'hpVL,v>H hKPQ\t mU8n8?Ј~.eE2Johkzqխ9P(`P %'dśSfbzdUU& 06"*tEI.1m2CƖ-IH]XC<.H4`h㌈4,qASyB>ps[ v+.} #"+)Ӫ_JD5*>MVJp5 R;,]UȓVqkq zIVKoP\ fz+r`RI[yqh=5_Qь g]%^1mKyx.NٵOs#&X *pE&Q @?(;eEz<^LJ'KbsHؿ`9bzI?֡qVMזHDɤ0J1.n7I qO07R2>`J97e6mu).dv ٺs4&_*'Ěݏp:)a~j u܅NY/VЦD gK(;EabڥXZX 65YxE9)>XGRXJy TfLG:q5rqhQIx5.!5(O8& nI&JXEГ{X#bi|&x U)Q &Gqj gK*N|=rzE֭I4lhDE"ٞ%O9Ǎbd%yA{ʘ`̕ . 8,x"app{w{虘di4W8:Z՟xDS"Y$5A/{$C:}#Sl LLɾŶ؞"b*hyYP{L_v YBO4TsleMhL &hgk%\˴m2CS`Bmy+{>JBXWs^S?G8 &ubCzlʘ,pi"zuZZ 7yjP-UG-{#j!TaRorFa:NyM F>&w}:zH5VȀgK[>}WƋZ;uM]ǠQb5HR0Y*!7Hѩ՜i~/6z+0,Z m>eb&_3Q߻ ÐV-Gt1߉.拾1l3}{ Zo+AbVWF}K,Hv2$_łr~/Ǯ-Cj-ze5n:CWxt*}If6#W|a^fW;/L { (?+(;uܶГWKhkd|2ڰg]c<` 41L&KkꊬwRwW5O./S1 5Up2;ƪ_FY9~\,a% GS5"S30V$KTbf-QD/ r(aƨ*/$E?(t)8GHc'hR:$ -*03HAէc&\q'UA@\^@#0"8>{Rutϛ=0]}~LB<rhrʔrv,w(\{SnWE8#ʐ?W6+u|[orsӀ@.%T>b6K.-,Z`\ѥ6peϏz͚ ,`\Xa̻)_]{goU+(á=#$@tO^d;\G]:̒?QMYqR( F{+A.'% |XйFݮ)-R1J4!~ ܿh|^b6LGlri@y/hCM6t!(IP3'A݅Lp7-赪SV)O qxt*aao̹2P^ XIqh(yRI ]{, ۺ+۟7t޵(l}[[@h4s029 HM:ZL|PP c@v9NjNV? 5 MOa+*GA߀0me=U7" ?vMccamU'??"2:\xmd2Z*`.`O:$$V+W-y5. p͝deeCV\ʋ׏qWEk>2ۈPOCOLXnS=@X{.mLҧVz#y#-YVP$i`fq:М"GjGQ$-+/e7J ͫ},%wPh3vU쑊J/2_]J *s]L69.PĿ_F_򶟆6SX \`u5=PWobD5x0;ʎ'6"7#ajW6@zF;W5nt٬;[~ ]R_,g+4=z#[XU9eE?蒧 #V#'xl%h 2H0Obk<3v3f: G2xF*Lp MX9cwѽ<\p( J8o Ϸ&?ӇΖutL@g'V/dUb!D&mpVbXhYztB[Dh?_(D/BuG WK0iiD"`pEU# rjPsG5}^'x]P$D.w kVud:D{:HeH } ݇Bk10j) 5,Ѕ[SsI}y!;$:ϣydΓx2{}Ihp`0A5(7(f25!IxwQn&]#%l W" L*4;SށAZSV=Numy9& /tq$KN^:Ay!%0;Q[BhߐP~ȓ8Ay\E0lgsPh'bYÑ^:>nz u-X+\u=h}z}{=Tu/[{NñʟCܾcUW!yߎpyt!JK|YDwS`-ӆ((Q/ax5Z^N EmѪ7sDO9Br0™QCgA/P4p[T,3=>9YjY$۽ Ajo.|U'{jt3\rKoMu!^yG1V"O5[2@2i*_ms䷃w{;UpΊ)lYSZ5S`S#G@`欨t&ּ07t]ԲQN(': /&0kW GSpla"C$徕|O%qXpC>ŧl -Š%.lҶ/{lR 674,9j+=)go]jfTkFԨ_&c⒞08) *YݟdM2O염70@dS}}4(\z`Mi*NxHʃNwHܯk9 G kkedH1>]7k)&ŕ9hA@rMp9R-r]չ'pKi3]J~<:\uQ"i ;G0/x⤵1 Xv?s!9ir)W[$(r|HiBۡ̅c'h0O G?AI,fa[DFJ8sogh!/!Ol--ۺAf07=LkU 3 `04tL|E斂}[Hvk<`~Ž~!_P*  sk埕 v\k^T@-4Mrնe48tvBI0n~Qo6cV u5/%e)gj1DF8U*,1VI$kjEz8ntt(Ԣ8\#G¼/O!.a^z~dVՃ6.LC :Csط{:WfвoQ `T" i-ޓx@H5:dxQ hy*';TmXA=M];~.N֟),5H? QX -\U|Épя!vfk+bj WhQG\BI}HӦ%TWte\x%IW9dt]\LYd g5^U[cL{>5oͽ7]N"g(. n}=.(K߆=q)m&'dMPә1-Vi2{E {rzO趿xA5xh n^ 99"ٗҵ{?hS˪g5 7`TUp"!qˤ6Yd5i Jk^͢X8m^ FRW|G^*.O]GZw "D4'e&s.gȨx`z~7Q*HzQg X1&O/r)m#x ̛x۩Ȏѭpo6VpmcKbNDix9ȸOjg|hā O+x"Dh<#pP~ #N`Pwp9X # 4)g#0_=qe-:ɒtC3+ () (4_QhZގ~pDȉOO?­EZ~,7"s@%$9>֟h1}VSxߩ (Zoj¯fQ >͡XޗfK2D~ ܀ x#͠X.#1C1zǀzFg7q *}R_ /pڊ e SH 97 5$Pi(8Ť4QOiJ¿G]H7?+3p0'w f-:\^CAw3i-Ƈ) ě!MTGV'j]=Tj\TRnd ge%S"*Z`΀lݳScffުQ,~Qq!;N*}Xͬg)!%:v wUِ?HX1M2K|^CoY9%%t2mEg-CbG""DF.m-xsBd{ m Z! 36,c-;v]-h~;櫾>9=[1ʥ|O^6T` ?gߗy(9Fqj|P tb-D*n k5|9U~M0oy"TWwxU#" 3A]"r.=I0jn>٨,X`^%^oŌ!1ӈ)؂6=>OLF3\yLi|5]v _ MjχtRПHRa޵R`-HKfDWJ607|(߉ t$Ը,ԀQ87؄ȇ.i ^nQ`G@'j~<+`#,+hpzt#=ŭ'n6{"z.Eتޕr;W [lT@Sp3`5^ dLSPKo ہ1shFAV7Mt!HEsW!vB$οbcFDc jB0,^U8H ;|`^6 &t M4.AeCvvqbЏPb!+WҚlu8 @BvU 8HTͳ.fK<˸2I/w{68ׁ<k븗̡%c.C{JgpphB@i PB TX>J WNPzn#IECR?IQ>d>)'4Yi-#مD"(E3Bm,>[R]tkᩜܐD@7\!F/s<т?P~j c gl#?τ0|FR}R<(wIQ`[CVppWL${LPtD"CU<`bHpJGq),e&*>.FmO [m# *We*q2و"zfٴ5z@{_L}m{،@@,R2au>eh{Bs'Ea~Sd_}`腵!Q|;jAIiꠘCĝ~8"g[ea/aMOqۺ3ƒ#QW5nQu#{уEi3QU"E1~(KbјVgu9*/$pdĨkXWMD :6fJ| 0U6#]!TOՙ28l `Hu¹Ǎ+e҆(ޟ!Z7ęDyk#> ܸ T2߱laA)j\jҰiilx{$C|c؟D@>9w&d" 㚜oT }i~yx¡X-#!e̲~r/¢n *WS%vj`gJ￑8$fAtPM^kDއӂ7(솰;MӢ@_p' 4ÁZt Ekum8Hizڽr"[g"fyNeUSKEi(0zzGas( nHy+e574F|^3L1$ɖR5jP"?7nkbVdߚV3龤ڎbȳGB #}Ð&$ƸPw)ALI@xQ.h6U *։'N ̡ bX)MllHT]azMZ!#'N J> _=,lS׀"hx[FpE1l=Ѵfm9QC*"kaGQ&ꔟr⿄52AlgʎlVK|pVS/`Q0 H ~$Pl*ȝU29$Ҳe= Pv~6޵?&4BZU[޳6 _gr %Q{5 (o.[ ַ¡u(R"(q&-,A}6`{]x2:du-Jpij"8U/& ]1`)" Bl%r9LY 4JA uQY>SK@h 93t+pzAj :uQ Yϒcȏypk]t֠VS!>2"s7FJ[ny* o b񓆩|U;ϐt׳$ ;襺ay&lVJxofzeʭ1 `P Ta;a(U_dAA%c"!M BԹCjw$eL$6Yzs[hg3i!uY06PF}-<=7 )H(-o@9cP`ȼ'ĐA,E%K5{jtZPl\S9[2IXljz/R `Ѷ@hf%p#r|GSs2`Ou$r9ma S(eSHLCKs~*/V>=@@Tqnq[jERvwP*0|G ӔkYr* I3i,Ӷ*I~Rm ^UT`CI~]xUy.7\v %4,KОK"D`@TҜdbeYv}H9@')Fؠu㷸C&׌n- @a2ău8~ctH'fmacfLbTY5j>T_LNhOc~YOP)YaI?ѯ6鄚&ނjjP'KAߩ/!)UDy?:BI !Ӯw¤J^T f- H&zWNG4g:ʏ|D+!L7mwV+൪[HxjR~Q( Wr T+fZfw;UF+(m@H3,DɖK}P- W<4%oɯ0bi=' 5~kN{.3k-4)@w4l 0ڤj5"3m7ŁsS&jRegQA O С<v6v/s(1'q>.B?w8bW0ٗk_ [Bg\k0ʇgXl|2q 2kM-ec2]S&!˗fDθȌ{C{n|I\.oq o16}k1Մ2ѳjjz%oJauor$7P$C%Bq#=Wf1!'])-osIQ -DT#[" 1t}D")m@f af (_ط _(va(q ʍ*Rv8g8U?~'lDgO3oڽXZy! ؤb|9@^,5IYE Zy*8NL8I/8Dʃ֝*:"y8 QZ3SmK4T39G@. ȿ/q"uG :gs19fWIrM%V&nUs#A;[3=Ub_5T[r}G{7̱ܲjCS>ƙX051!eci0!B.|KiT2ɌbQL8ċm@D3^bFdZr!=X*(/,]GG\V` xL7"'V)yl~ }pa )㨁ܬs2!yp5~$M:^1}%E֫MPv A1c˹x͓.6BGҌ6TWD59k>x;'^nڴF|E2TRj#\p@# ɸ]ҊO+&+rt(<3eYagrUh^? '~=GExgq\#уB`D ~ AIvh71Vs*S{N6MoKsŗxD7)wmQ&gDfuY;:Kŭw-KȨʡн՘)3$k]0 <2)k@JSy746m1s9cxch'RPKpP6XlRpΨUhOeQX{!Ǭ`1ZG;i>aFe/,EhgH*j^ntz!j z4monZd;f.jUE92re//\F'9I_t!V#V. 8zH(]XIB_aTv!Z%}zRrV W½Kb:RUg~:&;ߋ1i4#!t qi0U_öir `$ OZ|MQ;dzq9 ^vX PTY}WRXedug3W8o1#4Ab+X%¬ӶbN%FƞxZW=ƪ/96Pbѿӧo *R49WI(_G#1?iy]ךNo;?bwos&EƎs4}55v+jNW2\ /]2W_|5QL oXfui n SwS*,LƉiFmR` B@dRb dLNaI:dw!7g*tF5={`ɘ;|ٕ B-K/S&ZtI׏ ?j8>OfDY9\rd6\Kg6~^xeV"Xu693!ЋZzT$=\/&7rK)tʔ%%Fpfܺ% xF1K#ڮ^%v]:W^wIOP! iUeehTZz!ep\ {e!eQmCSoNƼF^z c!,%1m;6d0:aL,^J"3!%^i~\³M>-AWGmQX/{˦07h'P=COE!RrG^ט=JΣFKmOke AOɟ[eL=Iyݭ繨-ؾB: hh(Nbp(sq*R?%/mҨ6oj VB ȆeHam+LmԨ%6ϵsF%LOq`>;jΣ&o{wh̙W,>Wi.sVU'>ILUdorZ Wq5(%[PQ8/2Ur+`$=Fds~;;)D^GÆQ; f+6[c˙L \V<w?vrVrbN3WM| %&B@[H(I-6 S<+./c;Zض|(Mbr00Kc6{ 7ԪJB._ger_8鰊MwZ N5]$.ǍfZVua5!;^mH#O3Jw`|Q4y]Iۈ4)Ǖ7gF ]rB&ĈD'ׄUm_E-z"@b_ok#x*1ıu}i&!1#vuh4QrlW͔ªS^IEj&H9R4}c.+@ :՝*V A74ܸk2UzAoQ5cnƗ&'˪+~@oRr!hbu*ne1)!`gg^[NuJ71[&GNu39YXIςDŽmB}]mgG1%S[l#W,cV)]GPEڈUӌ.XCz AWBB0)f?7kA=x9/(v!<@N&cJ1 /oGoLg*4+}Ǒ0.e v:1d^:&-D4[EC,'IFTB2&:J_R֋6a G͞uiC*[7 3@[bSK-;,"AW-=:H $޴~j։{ś.bW$75˳ 0 S;O'U e{d\┧:w0v>6< ZU`: A-ߑ8MIKj麧L9|뫹f7&6Tꢸ`WP 3;˴z'! MUv*Kn WrkΩ S1zUG+dW}ȄV \samrf..aUXDא}KM?]y\g*.ɜ 8crPunT#Kꜜ+AWI0?aF>Z[w޿"EXy){B[)o$o$ >Dwr (.x}\~݌qf4Vh ?X==n{)VDP$߉$M +;hO/OG7Girՙ 7Q(|?/.09mlBu\E>fnf>+f/M#%ag%I3QB+l7XT`?~އP F oǸ#̌hfgKAhF=Lt7g"Z62^r8yҝܠ^TG(A c2ޑ[1G{-6ޝ@޺O#}mowP0k*dC8: sWt1Gˏ[ڝ%O{*O]~xh,v{^>vuTĿ|3b &S3xԀ jVih&AYlmaBawAS}wJBb@D)z"wHgZqÉ\4> ï9Υ|:cE ޞI {=ɾd-erXOP%T2'KHѦ@&sܣ6 &J>>h!]`8ѲOsؑa1A^ :;Z,len)n"j5PS{޾L|eYhz gb,|~ony8c̩#&/-o𴔱+x{Nfm־p@ 3^_5*yK2a sOrK J:فeͼg424tU:Ne -GW'>Y)l.uĂS腼 )lЌ7Zr ܹ?Hq:6m8mkYn1F+$nTz%P=B;mVi6t^ErڨkY m 9#7"L/I Mus6!t$[}6ypU:UjFX/m $`agLG\W^2l9N\lQrH/CFW씓$7~ͱ*9S `rDhS6anU Mp潶6A#JWf%dgnS|{`Sι1HL,p%RUq2,*Dc*9 .i> er0 / $8,%e>iMmb %:yn!Hg UৌC"cz%nL~n(2hKW:N|zX,W@rlz70g;_!\i2BdRD;42cY+?}i~'Afe`Z 1Αd8,VOt+ bEEޥ"(0e4.%@фw+حK8Ջ Se>FARu̎+''DQb ^̜5h+VmVa}Y>78(%t!`FBm7ksౚQavS`{,(s|3|&յ tBu ^;@~?o:W;"AL+^'C]/Yhg{MeGƸ;4=bd/'uiq6fw.%8d/m 惫i ]g>V!Ua ~sO!nCdjOH.DB.K[rZ<'@gK4}RY;`Z} p+j5XeytCYDt^7xk϶2 @~ZB9%(Hac;ȼ~1E&{n度^g =TЫ3p:Nuyʀh5Мޔ|&^ 0uvgVFU"dR|x4#fiG.Km^ED[r>ٔLa&u@ 5uLe r,5c_#M+ltp`\u^m$LzK`lN=!`.XSny~]JGE1lxLUW 0[?6O!$ 5\iF6"5-V  X\k _!EMb?Ro7DQ2[i$rl&5wHbrO㱓bh7.KItP{ kPEY)`4Zvl\l0ޠrRRG*6b+@cjl?l2IH,iȝӬtDP/GPq)O8G}~#S!L6}} MgI֫^+\i;.$6>PshxG ԇKmT}1`>(J {0mptH^֝vr4+9"x^I%2ކo`Ф>a.jBYN53ͺ,3?c6#=7Oҙp~HnjP+R,/{E1vbպkׯ9f~F< *}3:ÛD't UeQ8ͱuX c89k#߼(1M'ʭ0I'{)S/kb3 i6D+va/N(h2&a|^=̀'x H@U<q~&)-~|ɟ{o.Nd쑂>y{/rH~8G5.q1Fo '>c[á$[rFbBi=HleXJǪ #~ ?e˒ nbY˯ Z$Ü:*BPȯL" `#Z@z\EW6;c}^r Hl&e/@kwT~$)QB }E%>9KAmBNj$gr L5sa*ӁJ2m? =6<&aI[=9t$ok5m|O)_OPieIr9G~c6P9o-;k_)"ZC,'^НJ iS°2L(TzWP]Qura^v7lڊHа%G%e2#ZaB*Q2G0&s2oy Ħiq0(R%]މߙCz( [)(:@1:&O$@Ȉ=@f 7τ7x""# 1 M֋<8rߴbj\E>ʔsZP44gLc,KXa4;{_NJpc<8㟍gؑrFj?D C\,Ukq(M|ŝ[ŔRJ|Ɂ¦zfd357} PFV!졉 %UZ.8wmzn2`;q wh *_/dKg{KǬ0аXRR[7hOi 6~ Léȑ=I7SujjZdZ[RY!ƚ## ζ:aE;JЙ sDeqJ(XR"dz$jٝvsnxn?5mX~i v̮ ĺ+n1/ mbdCD#ԶFT>Jdڻ;P9/n[Mi^#"NM!MwtjyHeTSR%\}&uC1BXͻ04mj}'x7 /6QwSу{+`,ê \|D5>jgb3)FmMeݠ,ۄ\؛T %,nC'l3_̆E" v7v Qs)Bs ]4l, 5q70NR:GzpiaEo$)ke~%hUH2ͨ9F_BG `;WD/-jzɽ=u"rZ 8+!$/[{QX"Irhhbࡊ誤-'E(AvI|~d$ݻ Xt`ge:WlA%R$֙<{\ʪZ |qeהF2bTV ̠8S*h6z[@pdJBi0; jz| hQ:wytKt1 (Ż9cFDT5T҅wmqz.lsT#r;nM# 6ta;cy&}+(Ud<p x{6I\dx)ǿ῟PIszUы#i,hL,V?f'뙚t%%vFkIwEr 6w4f؉+eRӐrQ2G%vC3My Bh{@l73LzIk3L_4 <FLrlvd`mR>@>:@'8s@tf]?FQaɮ$B-+Wy|0mAU\䏩E>^!xSE:kfmy_` <@lUS~+ JsWEI`\4NćVt~7\w8 yѼէYO  wjuG D2*'bTY*N jܾ.-f@j2=i@0tu;GEؒ%uP'?Q~}E<"2KXxp 7&kcjT3YPGRfYi:+Xoďda-hf?X%Bb1iQNW(2K* xr(vy10~k(=Rnh2ІEj񧉩-0GXJל1@xܱm k [3DQN.a@57E\ΎZ]ԓ~sDl0ip/`ND1i.ķf2 6m* -?< ? e\o#7@Ǒ:wL[*QKi|cf x7b`6r]SVG1zR ȧUP .zqMІEZ>0S[W?٠CsUrd#^רRHZZW7& 988D6j)!c"Z>\p-E.s"ӨzQCL3:,,JBqP|q~ KZz|khشqNuO8 ̒`n伨KBq c|\Dg& ::*0Âkm0⠟g'ی+ @F~tkW'K?P9C$Pbt4(L`^ZxG_s:M ]8~~>^ԥW+٤P7<[ L4 GEP稀M1FmW7Ȕhp m:A]Ae`fWl\ER=BLF&> ˉ}VO !s Nױ&ehSɛW+-dD*/6`~}$c`7HSn!268?(\]R5%ZƩLa}Ծ9TO,f_"V9s'zDi! tM~VT`UTw]nn3p{݈'[d]hT$p^J'n^؎@"҉|oyE{.l'N4/I{D~sD.ELTxP:ۜ(` hh.OԘ>^M+XYjb#kq11pU*~}e'G9wOkWA^dfD!㯒9t;mS\C<Ƚdj,aJ s~tPec] UyV QM.H'꠺!Wl{dҁYf@hktcڣzv* 9#LIj~XJ""9Ǿg_;B&u!|HP{Gwsai̦k8 OhfIic*#Qѥ8N7F]nobHc\SG1G81PHGK&oMє w7%J2hb;oH+?Tqd6 ^o6(C`TdHL:DJ<caMS x|is7 j:uIQW6E哸zgxrbė='bHFSzf,S:MV$W#Z˔#1^΋z(32q\HU)m}I )Zk)b l&0eDa12AlF*\g@ze٫}Džz~2櫜!<);mb3c*Ap> ݟáZ։ b5rJҏD` 80eAʢfLdC9;V ~/;Eh|`*R$%+G 3I6;b hGk?Pބ'@vecs3JP11 crӭlfe #0TG T9ܭӠ KN!_wU;Mܶ$cy^I~Iپik J_5L ߲F+Kn!cz]s JbjD:R5WK$g)7rn C`Ɍw=Q^<:!; O9^P8:v5 ,*XM^- "\8Ə^IJoE8if{&\7⻘M&9 Z{ P-ho[S[WunhG>PGpPm3Ww `xJm=2qSPC na|m?s? d췒;]-#Òhd$NjzƏx(ZP& փE[7 yhOtt"[]#xT!v0mS~{P7eF|h/';"݀/ ᔮLNSesk;_WId&Z !R%/(M<>#*e2Rc@,;:i]@"VgF:4P|jXn;&+khV)<l51nҿϪՈkD9/!Hp=6kL9 Bu/ƂmhžH:iLoG|5ǽ"8&I{7Y#Hdd9K!xǩ8,uG5O5(L*CCmv-nm2Pwz!?Nm] XtI"S&alMN_F1֗6 ȦZ|_*\k:,UZb(0f^1.Nfr<%i] l 霗YBiY3aFtˎr9su^|,TtLR-$e_U{ feHj,ѼMTT߶ |2C5A6@\`jHn6Ɍ) ژC,/@= i -IKZMP .&vW^U?;X7Xw졔‚{gv37.+ i!FFL41)b %ZXgN7aE;Ilȥ ~k?a iƕn(*Th'YZW)iŶ֏o џt"x*5WƏPdx$鈵(EY^8iO  #~o %|&M&c.-Z@c6J/oPp3~Y;@N_տuB8E8 Âk?t9mrT=<n @8xfh A{i/8]`߃'VVb ͐?BŜW2@?FCHg+ڹkO鳽E Z+Qw ' 3;g^H'~>a6Y3E VubkYC@vԛ-Ou_ZH  o.c)\V51PrMi5 ( یpa |UQR`m?BGu1*+, ծ屝 g7d~nT% ^lXuP%k:-(jZo-Bhh՛7{g\U L@^ɯqgΕsHf̵ be]!E&/{VZS]\]ia|>V~3jf_)4, L%\s)LċiX>:ށVK|hCg^0[WfH:S`ܦ[,2hBn+X^KK%8PRK$u=/m}Ȥ l,6AsQhe7-in5!-FQ6s" yŀ YNZӤ+g"nsHuS\/^"0}2 ެ7=De!& a |.9Wr^6B>Jp~a:&I!lg&Ti}4ĮN0ZNAJ]&O3pQ)TFCVB^\"!uE*чS:a,%3eT 'E.WwY.kd Bo->r?!vz6΄jx20hh,8Pi`?[˺bLԨiJl# ؑ3Plnk-4I^xOMUӢQrs3Zs{ςAne=k5^~Sڠm$RFw݉6sGE57]^5E_")-ӯJH,M03;. :d1BDh>In@%‡)DtH|{,ɑ6Du۷1YY A6gNW(xFT_ԺK*.FZ:O5NҴK6'a tJnqg2D)DNh3>GTo*IZr>LRIH?=}G͆!-0 JyJlOI1 ϳ䫱7TW8W=IS`;J//T39}:4Z1AuD2}sb(R==hfX\#@Ygױ)DE^7gCH@rj)nx¸cjҵ5_,%:'@#uu|j$m]my_l Գ֫DvTmy,8Pb >#h@mi*CӻXx+ѪD2B{HJV\1kH#w_{3ESGfIPԶu%]4\G7G8L @dp4߇=r 8cr |̸8=#Ңg78|h)#& w$Ja};3DJQw Ŵ-3jq+? ðhDH?o>A ]%qP҆q=@ǩSb/~Uwn'CFEG5x5.%ak?>MGK}L&j0 TTNo!2}U^Mf|9@֨PL]Vn&fܞjf!{Tz?\Rvi{a \`PtNf۾~GSl9s4&D&m)vH#P.T<7JVw|5۰wƧn7Ouih#(Fc.k>"D>yj,=8|@c"g'su:]ڡx+ o*pC?{p TS耥?s:Ru{cPJIG H+|g?Pk["{:T!*IE-@G^0}2c ,'f;KA *$@eUF4;H9@n~CSqg92>qH& G k"нפ$Db:ַB'PMG㞻2C@ₜ\/\֢Qš2WkEs]!+!:1ǭ ; :f&X%-t|x[P ,/|ΫMX(DiHk8B&ohw@h- ۟ 2qW۷&Jdz8EF }nO 9S#}0+6EJ$@Llzrz oEU:u;qS@ZWNV!>a;܏s47PK8Qt'w:mjVjaj3'wo5P[@1h9u`Br;wSiyFTe芙1CīGT Z)(LJ'\v>^ Gu= 4BxvP DUߟ̉&Pm̄,8F+izs2VMjdBbEf)KL5 R>]@pƩmǝGgY f#'G98dR 5Jo9/3RkGFyu=֜#70?"'D8wPNyw (nr4hImvI-)NGĴ%9XM *[tn,}s9d۝<:\ɒŊ*:qY~@{ '\cYko<1GGyנkӆOPسs&] WBKxIR,vG <%XƉ);P$/87I\ɽ^t0 4N%أoCߚI'压oAYV>|a9[*^`Š降єЎUIavG7Dqgx7ܠ5Bv߃mwCXW݌j)缪2}%!݉=vvMQ {_.G]Uw2vw蕀 {H5I4cAԄnyÌg@`UyO7Ǽ|;"p0JO+UX^ցZ>܊\Nw\0fdC Tnhr7㛍Nx}#q%[M `hm جg6lGmܹA/ܪPV1hZm$9): L,!Ȉ܌bBZ~<؟av0ggnkb]H/g7ON<1]g6/ >0hPR^TJSWCܚnHԚ2:yk@D4'^V(= M3,yǶҥ.b6a '@oj|0(Cs):o^7EA1 #ü"w }. Dl[LNRXw0qŤ+ j]v+Vp< qW֛Z6 ;oIz S\(Ez>SKE0ac^YYA0WlB~3VexHYdM' ?$Qq>wh%ͳ6dld< hz5fK<TC-qŒW]j^"6^͹D3"BNh-C±9Y]6rkRSx\X̀hq@y=@igmwb3)1[\-ukyX͋eп\l{ x-;֜֯{x@YD OTų 94 ^Wџv%GV L@zti_G=Lb8R\u޷?Ja_e)4zQ:~ʼntMԙg,H D%oby2(_)nf/xmvd;3/pNݻ.L6ֿdsrFyZDUo32kR<9tSZvb8b#O3ѕެ8Ip ӁeR8BqXXUD" 4e+0@C].pyV LN6X,q;bMMVK|R҉痑_YxZ8rrwc['@P1AV 3-A/% Qq.qno(1 ?V'?t]nPzF)wxD3H$_I.y֏cn*VFh؛ Э> u%S(!p/fU}BqeY-FӚE{kl)M[_ʛ؀>ϠDJLN'&e)ͣV2R~<~j^@W^#Y7, \* t6rE fU+GC|Eg>H*RF jq'FECZ&%+f_*2 /m̷@ }2MV-%]÷zۚ1!& x WiFRrp*)+Wʩb^"?#JwJRܔ/Tk٫aTWqf0SH=W:Xޯ|cjtDR6qGu-8PB(>rA-iO._{ƛbeg5C ,F3oJ!4vUǫjC YIjJDh>#lSˉ9dbu܏Kd5[_'wI"+X7~t%63*u6?2^K_(VJB Wo²fu'oq$kݙv{n})UV Q"]~j}_NJ%^e㎾"x$MuXΙS\TAk[ry6OUEײj?d9+kT+aO 𙽀`FBiO][¸lg*p,O 4'YNƊ>l:s)@PqDm.?3АfC:y`*./C֫'Fw7B6Tg""n?QajKa77="/߮gB&]p?ʭNҨɢ ^ ].](^UYW/Jgq#t{c2 ڬ6_Muk%CL?Xide{1'Z9ۡXO]8{ KhoA"+qDgr{{Q4n%!Sh!'q/=7ha$3}6fM* i&}?) 9KiMѥX(;LX'MvxvK38*&6fJCh( 9A~1ܢn)EsR$V`+&&8'T1{ĕoq8qp{&T0/ ]ih޶;ze.xvhww e+26oeydJoOۃ{^tSnf.pM`Fn(-@tV\4˅PfD]ǂh]΁;>$Abophfy!eC^qO19iPp&ZeRL3וH^хAC!1fzlap-guSDZ 4ga*svX2#%ZeU,f]r-u (%  ]ic3OXo&޹n޿$ Y-ΔX*B‡dۺ\lm*x{ɺ/_ޚ&,;16T$u oJodtci\&(zVRjfղr‡>)M\DHAfy8z4NJO 21`+hs,q- G'+xMnb 3E\p]kFq j5оZL34pRWP|Y+LI_jސ^ dV- K7r9sL"Bh;7ރl+m<0/f ?, ]^\@#P}nP^Uy@{ҒҨaO ^2;ŵWN: (SihrwjPݺk񷢈@";ɥj#Ɏg՚y,tvGgprtK'\?v/ ?:1N$|!44r{A>x܀8u\+" [f>,c<ĄIo~x?J'9GW$E㙴: /*Kb_G=rmiw KR` Pkj?&z6c%JZ{)}_ ^rgq#},شcx?/Ж swA!̃[N ϟƟwo-4 v}L:OjjzmbD@=]6̟h֓ϡO-+"xŧsxգ ]uLQm_.*Q ݋?[Z|e.1[r8//AfSHzPה1s *wK d@(p)w0mM66J &첊yvqT>7]k_SEPuT]9`DfDcBtEQFrCNXgDiP@q 긍zqXp6kqcWp^/ی9`daCЅ92!s/pp&@/:[ssWWb_d].s {ڢdx&9Aәf^ oE6n\=L;,UknQ)&^Un\Gk_b|l!k ~ufeT}Oe\5<&UMQb6+W&4O[茌!(E*?ʇß^eink*t8ԝ8xS+VQDNag)KC=^xe2-i(1@w*zoժ"Xuwk ϪA[{vR_|wن:U7q[Ɂ OT\=qsCc'S5e^Eh|TCz܎ [ !fǑCa2p]+h-а@S`-_+ݨ:`0[(\6{<b)|tًn,/w 6 @jՓ50?@f_riNl2_x,pI&3`{T=?wv)ͱv8McS3Iwҟr|kuW4# R$@7ަƗY7 +A)i_r%W[hipz?;(/azo0VC3w{_t5fR9ӲL&W`y }8v0NVc й`YIj)<#;1rT ~Ǯoj.THi0R*X4Vy =*3'#r2-T%Ě $eկdaBN=JaIwq[P>bo Uh爦#:٤Z~`_3v;@hO_ŗocO.uH_esَy8LDEP`m{![)qm'|.TNxxPDU&[^ z0WwKI;kUa 2Fearx<: t\eDBdmRcqPeH03ٓ&`ҊP,oxtFd$!sbp=)ߟefX-[ a>'wByY vɵl'b:騣#f̢\D1<ЗNq$ǿ ߯7OkL9S~`U QZQk?#sf, boR4_eg7d '?ތj_1M nYtiucL@B؏T6M oknwr[ϞE_,dAD+ &U*-=؃K-i4J?IY"4Ynt F".92}LŦa Y[B7M:R]%1`FtVZnlڙ) Uެyxuooy:ޞ@aLlQI:)Ԍܰ?_OR>@`gz|V>kû=K-H:Xmv*hpL nfwޑkET(m'RK=D 8 ] t,kLJ9GTtҋ+o7 Cj%q׭x#SZe~z[RкՂWVWX|4̐N}"]ZFV}[7^M5Nwyʣx ܝ5˕SX,9`~M $~}ZK3z]oz&q`7Q+LȠZ{FW~!fLTQ7'12.mn.ճBGk̩x%!-ING$b?de} 来 >LжyzvgJ+~VwPUjByR3P!|#,3]AδEGԕV}e*0Ϥ}L|1Sbe;`bAhuOQyG(9Ne8lOeY{G] Cj~~2u}mdӐDú;z_ly/~wͼFoyk16»6If }Ԣy?̆uݱTf7T5Nڕ >;9v,t+,]zvz:nTDtFI74y%-'yʟhrLji(iNkκtf#$_'jn\}b58IBSTMgօuNG7nIi+]͘#O4T(x4o TUz~.I[qX꩟gz`H0. \rB|VZ𧅠+%(<}'5%ەʴѪֿ&ug-ΞB0Q:sh(t% ΊKe.zU׻V%ᔿ)Yd*@$LExU#풖JT^ s⋿)@Ii~svҝ+J!QqҺJU"fēƼT?Ly;F( `'T=Q 'K&6'ulr@SR" `FJ+C_.o3SPzJ1{FZu:Kx$.磭zwJKI -u~3a.0>bM}$>NiJyS}ڤ|H! 6 9? ;ޤ}Nł7LJ:?oB/(,g]ܷy0o,A+8p<3.`E͆yX͞|^rf&r;B8$*Z[8XٜEMϚ#Wo$E{7XTJ9&5o[7d]`aԦw9k?p_7\ӳaKjGJ2XX|% }P䴉~^RVmt,b-oeXiZ!҃;/6lZKi'K6ZNWEoCˡXÏ> *W쥧]\ ape7 $c48BḢ'^ұ7qonz]JNk=ӃEJ;CjT=D BpgyT;g9΅wJn%]ԾǘK gaEV#})4SCGP[.Ȼ6,́!M负"iL)c*\y&^0K޾&Ojv_UmmGdg4G9'_;Y}, 3 o+ }f셹 &&#G׹uLMC F&?=d;T/oa>bKut\xēh]u$s҆Ѷ Ɗ~j`G83xvj<;.jDI|ᨺ*B> 9&B@G}) LJ/p Lg2mEmS?z~jHEvͭVB`-XrDͦ?jWgSIg.A"&RzpnJPH|KMSb\T3468Jo#Ks wWS|L$q[ͤ{-RߤU܀Dc_v;Ul sz~xS +rC[Z"s"Lzbg!F8p) r&V.# -9>Ym)'R/D޾97<ƻ!,=~țd x9G|;d%UUO0Ը )qMdc!u=cB5G*1ߕ't{$:D2 ltv.FȔ<1.dIfO[yџL ZcBFU耈rk(f3:.^QSZ 3m[8c s@$8e*J5|JL{YGr<̂6C$}-HBiAbFҺDY5.#cf\% <ލp5Ŷg{V='l|`TMl\"[ 8\! :R2}"O)){`P*JA X+>)b.>;D\#$ ?.h1w>Ԩ60I栀GpI|$w;Da9fלZ{/avk&fKv4{9NIQU9XL&r/3H=[ eM_ٽD 2x JaV9z?SD n MaR0;ZuDY'`@$@ҙp;ʯSkI${BXxt|,(i[eJWs=f@[ Y(O fɶ]5 .$fb~m ~̇GD8*ssF޷۾*OkX6MnD֌J{]-q&\'P*cUp' %cpmƠ8b{'lHI@zɘer}Xiz.9 ӈ ?i]y\nci=p:/W[pXrUdb~n~iu&4 "]t50EK,ظ܌$v5@횽^h W'x4W%NtaD]|~^YYV핷j$q{*o/@wH:Vf讹A"{+t0=>D5691mZthyO)Rw*OUP,p%Oʐ޳Mtu5kRUŘ#o=Nk(+}橢Cעju%*p{.5 ƗTykv>mXΎfWLef? b(VhIJ0kA&}q#[t*/_Clh?;@.qңk@h/Xj5hv1痥*b5ظצtyE+>qlMѯzHL?w(6K0c|wEZK8U۶x\l 4YQ19IX r%6P[ɗU4oJ [U}fY^pn˖w/Nw!xwàĸ ;h yK~E|M#*:v=[?5 ;|O iD&NbT,t~^<Nsa]aVm$0̵4@@: GH:>#Oŀ}_KS.V0\lʫNFP\TB׼tmnmԧ$Ac7J= Q19Է܌q)B?ש7' 1|UtqpTdΌ"A.__uD~J)^l~vw<&sY8E3]b!n_A*HCrk{hhS>AAu"cn[} N28EL=ȶs~-{4y!8~" PN2Ϋr֬RɁGNG,?`Q )98hcN5tt.JUjSss'/oͨު: lʆdl! J,_7D/;% $ |~VM³o~X붸9𞋅K}# 4ZUwSDH?".Z%L dn iDAp߾: oXTwZ0aTJMr1~6<"rth`+4.VL䦱B Wl~#Mgu2M.K Ə-r@ 8X@ry _o ) `S3Wn';œ˥P 8{oQġSCKBYo!@~RYPщej9c"bU;y}Ƣqw\Q=Ԍq7%#"ċ\ ,7TUfh>Y&"R,Y0_+UmΟH0@2#C *D&,qg9gݝUU&&CW0EV&GsjE7wDL-\Y#A KG KQt1<T qDMk! y$&'w][Z +(ͅCUoZ<_٨GR2Ո_1ܬ:P?fta^8Qexc ﴴ.3MZR܏s2f q/gx.BCB-h&*0 4D}Ӿ_qfeo%+ !bgUE ?qad(CpٗajGq#]W8e U8YV*?}/wQ͵qt5=GT/}:!-yG І;Y{˟}ߒgr`QiY-h v-km5e+;W4m\( qV5Xs$9CnwS 'xj37hӂR Mdz؝;Ec\FJ{(Z'o"5h$#9@, !Rs&Z<\ϡXr\t pzYn(T:sHF?P@xPm황)d \h_Ae/K5@rM~- )Js(2Fcɡ6x6Բ[穃XO]&nED9k3 R0@ 3rBuBz:{l]0V y/'s]acU3oV0'{?[)QgѶ}nxuyb;txAs(rGY=ĔY)n5\$ #/ j<4> +-pÑn\jRXg ZyGfk#Eٗ6i|KY[˩ov8cRˮU"kr{))7*263&cpTu˽,h%;M>J'TFT-_p5 !utlsfp 3/IcOhLe Һ{,(zWlž4=:yR@^r@{uiEgfdo6/v!T{,(TG.@ZP\dQY~(٨x۝u)v]{tD5s,UIԧs.kQ z]e}Zyʼnq R^ +qJ&ל: 2d9BuJZZ?GO}+f8=_`é^/:TЗMd?u۴3{HBe`WQO'0L'ΦEHfR?m]F<FsogK@!Q܊| bTl|n)6cjZ}2:{P,٘I3+2)w<\,,ԞJn࡙OK'7LT"72}~ Yݢ 8^&;G}gfLI_gt5!o=>L 6:n. gц zEe"|F̱*W(ɟ*( ΊV[R v"۟~btfNz9]Q} g8D<})XElF ?Arڑej8YQbMkײ[d**Y>aԹK+uhn6W `ƽ&"sg*<X% gszR0יgYԉIl{t.0'3 ~XPmY4< pvM9}䞏RVu0"b<%7yɥĈ|KK @V{gIUc}m*3HpҊwX6Obw5PΒBrb5>\~?Qm3-H5#U<$y4 3[ʣ](IoX|Vߙ<2Y7 7 dLܠR^2qc_ꡟ@Ы=ei&R7S~Y]qI'8)GQ׵=U4E Oe>5'}lכ&@OvuQEmg7|JNhgCb0$2{T r J^y›wwY8 =-i~C'il^_ 5k P{5ӛO! ~z"SZ% ^CNB%h~eF+廙!\&Z Ӡgm9^R8f WIb]! 5hԓnuvۺ޸ˢf34NؔG4zH1*7~K“bm@#Iڈgj&=mȞRgMOwtF2>xg8ł<'"TIk.5HE9UF%F7%#&MEb̒U:{&lع ګ.I[f2l czY_:}2Geڷ-vُ>ᑐ1nq]zgU$ R?/؁n%dү|MNj̅#hJv>BnƖtI_x |/qA+";q3Dz6waF/*1~-_(3$AFfY[9RAisΈ]G˝M#U 7ʰSLU2Z; [^)xף`1tQR"eг,k5.WO%- 85"QУJ y ou|2E6CV-΍#z]# /0DkxvJz!|xGE> 'C'sƸvA!Z!PtQZof.|ʵۓtMo!#i@ȏ\L z%g3鹭VLLpf3`0HƐܖl&D)K_>3O؞ ˥X= io *ymx4l#:ZI iCM V v혈D )M=Ml*K0/0b~[/E{ )B,Ұ}ǚWs.jŔ;qh8_JpPoҢ3ȩ4 0v:{{% n`74LWqAJi{j_TnuOL_۫Otoc\ iwȈl%g:=t^G]>)=QDy']XuoU~uJL1Uxpԍ!wFDƲWtr4[XQtɲ8NxA:L=G*N˃{R㢟,ٰYtN^썮 +_s2΍U"E5^曺_ 穋oSq 8G'@ W'`2q QDg[Sg-? wPr~hH~{R94P6(녾C}9M `Bl /׀A>Z\U!RɭڡAy/-2t%PpIb"]H$|mN-֧tdžw: )M'('.m"ǚH#OSyd9rIZ0O0(ʵJ|e/vA:# ~s#iòp5hT>>!v٫`1xG\x*g᳡o[YKWI`+?rȋOoxR:M֌9 (nC@CXa%a_%Ԣ65*Xw w͏U^EZQ9{?X^id҆7Jp*s9=7IR+˸"_>?F+'gS тZԠz!o2 S m`{H2|.9qYΚ|Ѝh6(ޤ 8$PwCb%(PuA=/kQr9d'Kea 2FLYB m{NWB@T{BGT+hNI4 ܕV`X0n/&4D4VSNc+eu|=XQik52NZ Z Xfl,+5q1JyP ?:9L5a:mjEy$;CkyQ`zCdWCtX 7yձOBvk/i⊣hMszAV*KT ''tT*f42Dy~ϮIow6CM .AJCFJűqKx,vZr)&ݴCv_5v\,'Z-ZE[+p?Ug<2];UV`CLoQv؀VŤ21s6oS=tk3EDooޭ@ TR}pbȪx&Fܧ㎚_.YΏ;/CdkE8Z 6@?NA~[[:܎q1Ua;-w1!zpKL8a#IqdOM `)B#̓'V@ʊL`O:ʵ4/+L1m.!HЋU&08 &:?p1qf5Ip.-ᪿUf%ZRNgK*;ꎀ$(wm䶁¥[X; bTe>4iX_czOf(KJԯP7!ߐ<2FZ n{DKMivᒽIӖ[j öWPcZnP۫\gGFefh=EGDȹo p8ϲ3SK_A>6mVAsnC[:b12tS3t&BҎ(7xwSBaFu%ezQ_XuOȊ|{^hyڭBS pZ/ 5y`( m5Z]Y XZr淧6ɄU](23Cx9O0&5V3tѼ;Ej),"= mv_L}{E݌Y2S;x'^2 =j`IbRǟ!%@U4]ӡI :ϑU_1Hu(!L/L™HI`-?H6z8ݓ< ?Q \ɣ5S=MFΘHgLM+g]w"4h'G FRT1?NVqhzi= gvjkni3gJt??I^3@1q5,?țѸl5nYGhW1d>VCgKsKWP} ȲSw#C5ZZ]V=d,"-[0| f_PP:h7-e0}qATVge%O̩!ЄҗœʦImOhxeNh>jSI|;Ft`Պ*t'bᾖ4y`iRg;M\C-3kʕwE2?h).>g-W4}r,i Ov-T+6j .1mtc"R x&/a'R-<|v\]m cR +tVG8=քI;~ I2s0o*YsqIfk'MKo}!(q 2+Ι2t/}^WDhǯΠH'aC& lx4j6HReWҙ0G%aYϧǚ˧7rK83ʳ-m_kA ,>qH!UiYW<1}$]R D8P#bGqQ4n'Z,Vaw +<۪<rU<}IВK yǽD"wiK@1.s}ʡL (!ˋG7ZP઴Jg2Uu{z^ K&V(H%u䊾2\8+$[%y]q.Hro ۯCJhj(yvmJ炜FhiV[FjӃ2X)AH'z9c`T tlk"n&Ztjz!PLyF|f (P鏂8t`j6-I^@?s'r,[VXeB!rhYX޶HO7 AעVnIXkG^%m=fퟸ"s?VS,&l}Яk Jnh/˼7d;([2t |@hݸtw7c@P7e_!B0+JG<ҚM]}r /pX-abD"*y!/C>M\/*/:N")bvA\)6e؀<Pnғo! Qa=z* Z;ap )/( n5;ًD絶-vMH\^0^ߍf}ٳ|CKd-{5Na)Gkx aoyx}FK# o3c\!Yc/0kѤk.V)EJ݃E@Ү @< EVhZԍ4aeڅbs7En2c;m 2[;Tk@x۬P0L Wlr@zzQFVl&;ǎ{@eJc:ElG]hbRGGY`!hpie:]V kP%E#mfT_{xvs[Ϲ3q9h#,אl_t +*uD?h8=i1o)lÓN,xn4w*M,eAV|=#MKtrVxܴ(_:`M^$^J< zo'6cd0͵Ljs'M}094{̞p趇( ֺNzpy"_튺>k_\. ״~W0dcC# h@?}iM.-m2n(uơ##7rjQcIR%>ӱV(@gQqvh1(ގs/- ЈBP<m=<ʋجo|IaY:Gr9#?kUס{Blȸ9N@ hIWx$:`sDSQ͞Lh>q8]8(\$:vTv'9(AiԞ7 +h><3E} Ձ?PK]Q9 eAȬ<0Kslٕ>n>bNA ̎j';jnқ5:>`LcY "n!&g^ Yf3 $Rn׻#3-(Z+ ^T{Z=(ӏqeI R,k56;!Y=ؿSݡc̦D|Ѩ3'GvB#wtM]zH> %$He,RؿˡqZupeϗ|!#t۹euPqmnN/V}uwӯi}cW]Z7gs%z: #Y>:f:džne'SR qsgunK,` $ŇTjص~dߗ!FҮGG輂9YOI9 y[ Ӵ2nV` o,;zgn4?;N _}Vۅ]# :к]'C гZjKzcԥ_T\qLx>`j`b$N!8vXbpT%܍R<9:c&Z:]L!LeD^06r[%wp&i͖Q+/U^ukrW-AƍT0b;}CUѾ1%ޒXrܫ4՞4y+^.eXp~vnB7~-6_TF=sUH2 RH77? 3r[󻺯(mrU-?ʩьkpnfѽ4fR1v'Cș ݞ}`ҥpSoSZK+G H7 ' ,j #P̹GwV7m$j#s_w]"5uu99 ?]ע],Vbw\Ut'wL܈Gh]a1E %pPC =wz0 /bүG]c`' CnXଓ=XjGIf{sU*yȕcCDT-n)`HR;3]d/~m d5f}#xn%:dV\!`!/SgBf'@ɬ1>?'oӼU~(҈>fkwdYu⥧EWbg*#s{$tҎ1'}db:6w$F- p-DGz] +ߒ%N< d!keiv0 (lZ326Iߐ'!/罎o%9E-?qNi_ Ux'(Bd<=r2ۤFSzu (]W>(m2&$Krfwv}_Ot0 ߰Ӫ3X^%8k><;F@POZpb+ KlsiZZYRb(X1#}$K},;R̎ / Ka2aTz֫HS׃N_dE)OHXFEiB^ߥ_E"^ ~Izn Ѵ!Rl,zg""4"ՅҶ]2H\I<]uP 'YN~L!gZbɤ}rDFVM56x%(P,(_N**=tA%O*>a9`.wybN.l ?)Gu-.k/T'喹cَylX"ɔ\KWЇtdʡH6&IY̘")y8eߡR,2b;|RvއwLvP ,7Ɲfy"UC1ÙТ0becUUS pN4g+qzEہom=O[OG L.[ps K̆Fơ%R Wo1AX¬:Y#*7K73"R[pSҥO~!ϟvA`I&U/tg5=8:Jr谴%w}*28 0O";e9԰3&J % PPM{8w,1bRJXZ)>l.y΃ hA}J竝}S%Vxm濘Q˗m/k#2@P忠A5[ vrע-6&3txѿ>Îbʦ"/=^,in94=nYj5A'p enZ%1?~јД4Vc< /> [_[;%YL.o͆r9, P[9/ Z$ypU]Ņ==()m?c6d^WSλC"=z~Q]tR_'\\OGˏ&K/+<@#3"?\E`uH 9CÆo*/*_V Xy:cxn(q p kys3IG ,|32ۣTѕž8I37@xZ EҧGq|A&&4&rIPt{ZzrKPLJ#KL(Y_K7>~ A]C&O!ЮbxHߊd[?8W5k?ـ1y^,Ry9.R!ح*DۃB5r\=@()a @:ʷr_XJBrZ9oӠ[4mX|rJDxOPTB1-jw(jp#iOs@߀\uG!3e; zVw nb8y)caVϯ]T"袐 B EM3~)2DYu x(U]\3|KU я~mۑ9~V4Z!pZp32LgϧJyf3h i9y 'mz :Cܵ'?f8ѳ>Rӵc]̰(y+<2q?]oŔ$69|x#j"FrL)x\Uzxj4-x(:ILg&+ b\eO;c|Nk"+ ETorWbũצ?FƉJ7f8 }Zdw2jCWn}HKǎ^}٘mt}wr\WP'5x7APn*^kRlOQl>ʢR]F-^PJo>Hvػ5Z0c>8.U7 UJՔa4MvYXXua#ye\S'sTuysep #{0~Au:H r"tLs`:_-'ߒ[cS }(,"HaP1̏/ʥjzI9[ѕm޷)[Rf;h!myL Tū~5(cPgL } v eG7t?B>vg#ٜ V[}jF3<%sM2(ux@x@xõ$\h,O,)3ԒS>6a(L՜_9%MIJȒV?Iҋ*#pqNyDGŠ _B;L`C*jtpϕ=p^RI S{4 Z9yu`.7/< e`̡#BD\ZV$ 67Ofktl?1P;ruoY+4 / Q >b!YQ×UN`I`m;a>8vrIQڱAG1=/ TˏL;==ZByi?6+,u\C3 2D}1_/%Ե?/joTkj/!!IC{RɜBuALrtaM3`7 Q@0{Q<ûkM%ƚ .06TxO52[gE w|A/QےG~ OHoa8l8dK*F/Ab-GF['r&f6y'46+b2i8"sr{?t`^,ӰjO:$m1S3Dѱ&-*_줰EkrZ>b0U2{C6b4M*kw[&XKȎXznLɾ˳`_Qg"ډI' E&|X%{dq` &/3ST5~Yi2Nʼn nM |Cܯ0T_6$+W B'%DPw~[W@)Vvd1  \\9/ fum@  T^_𼿁xC g+sϡ_'"UЄAsftI- GǣVV~69R0-e$(`y2*sʆ K5%Rw{p4I\C5w[ƙr J[M̷`U(.R SL^_bdf5#1.P+<_pk,쇬]u{"Xuѩ=@©UXEG'$ڵ: vhߜްMK$kB~(L@d(LAU|\es/4ԆNry,.ޛ]?B3w~bx" ?{#_ݵ~Q;!gE2 1- AiɱrW݈eB5+gIt';rr.C@xmoL_^L p'v?͗'R`*$yZjC4ݲrHlͩ4+=,`m"M|zW!Q?yU!M r-ZPW hUY6mѹ)K])agF;-$EIc΍pK0_%u8^s#^~XRI@G^hp0. bnvRX6U}ȵX//7 ܻZiYŎ#v\lji`hr'l1W7a]jء4Lܭn tЅ;ʯei"! P |:*S ڄ҂E׵E<fagߙWV5Iw-ŏGKԔF<#nOʬ& _$I'& * h'&*_5+TpPs@̷ dՖ(@(~zN06GWt3H;5r?ųݗ3XMY9o}"_ N;q+\P*,BԶ#-eI5j@mkOEEɢ-0 x$nԷ7;.-6F-:9hwu}Hv^6>VL="3g8X;"&DX1q'r#BA$Vq#&:@hj%v7 3mNg`ض,3fi5jp |P-ɄU`5-H*. ~\2) D9Y%TH_t:nn7q8ܘҙKB'[5w=-)%)?=ʜ%Լ^I( sLs]S _j/ hQTzyHw-q@z|;fQs\1{q9hP Ivn6!kfWl"3VB!Yfȩ{ߝ\bxO7]8sDB7wG uËA7t2 j}O-Fo#`'+,0G$s_7ѵ!}ANA*Ur"mbQTր4GCNSjVVɤ O$,i4N;CWTI6m⭳`؝)w' 2Z|G+WmV\RcSJ啍Kb}MpJJԼajE6ٹ֟`K$( t0ϲ Cuq7֗09yzM ٫nWR>^ d1jՍG9.%C!NM)7yG}`[B{-';ѱP*5#czMʩIak2D8ɳ|V`x $.)s8r8 N 1A:}!&wB:%Ֆ0I]O6O$/W]o#D7sw V\r3`iy0X@)D90z.L+_O,gݸzةR 6 vG0MyiEhb<*|0bq 2k̵ ևSTkOguė9)D%+!3Մ{n[7uV/d #b#Z+_Iq&~՜r=i_~H&N-w[68xkVJם8FIN?XtWjeF_@ٝxe«8[-$9s~ qˡjVU?qHЄ22ag|=A﷌$Dbu45 }vs\2rka< HMㇴ[1 9.F_4sTe󥠍t줬:?wt*#]Xzw.L9fLҒUM6xUJ{c~mѡh|NR-o4\}k8#dhZ&Fp1*#z3J ~N[,A`2#ЏOt#o]Р 0UZ)˨1l+Mŧuz;,J@z1eqr &HZz37iNQ<:j2= ̤1%e)G͝&֑bG_-!O``:QgQ, -EWI$9zuyx#(3bF pGCsz多m$s53S0`)d*m:NxᛓliyJ ,bH.Yjy`d*ê)0t/q2/H`9!cvQt >orύÿ6G. zϢt{rGw,0BsqQ.`NP28>2,P?Z/!]9MNz s6*֜uL1݊Wnw[0ٸ+%vȌDeb>Ȣ6Bb1t於gEj7G 6[i ᔌ@󆅱ϻE8AŽYe݆Z=p11J}Ddk r>KJ҈5ģ=at~g^kq0&o)cqݚ{LeEJ=ѦmXzBO|3_=q;vsu=b,s;J]K s/J߃(WfUv(Exl᳌x]Yv/M2BpzD0wA>KY5 (4fX Na7Ll%{vymxdgcÓRXpd]g9x,>ߞK( '.PDl%]eҿ4 -EX 5dmѽʎ siOoNKP':yK7s.QmGj3d<5?G`WC[n1:,'|چliU9 `Kf!E'|1kn"mR@kܓ/sK8Ɇq^zZ[DjTR+dz&[cxeO..Qq_G /!"quLJ3>+WV߂D]~F'ЪHx nrܿVcjŜ[q Zi=WAIQIjqe2j BÖw%F17q_2wsm*ӉgZ!6NI銗=4f%XȆepM!)*!Yv"ёO~b%;WɾV^Z(C )Q ;#a~b`eQZܱq |‚K:07 ǖcoA>="g32*"K-i+p@'].x vO.&K?Н[ ە'xNmfCzz7EB_["sA.aI]n 6<H`d2zU,[5CI7 #ol[&s]#? x AFE˳2cJ:̔ cv.i&jmG_ " U2 D,"Ww "x;{;ӊQ`cMMpChh.|(? ԎGii~#vs^eN ?7l>'"fX]7\Yn1'KKU;HЎ4+&Ӟe# ‘H,NO¹416h V1$z{CIIJ') ~ԩ_[hU(Um+)ڿ:4zt&:8dHSuzɡkO8IKve꾜mzcu䒒\Aӿ֊2Ifw"fb2'#ܳN~p-M _Fqլr~]؏~:!шL<)oڕ4|K0f)B8BJ DW<\i:>]w6\huE޶wwYT΋!zn"axYBZ䍢MKTHz>G+*>vxNKjC4kY QiEp/bn؆2"XC1GD5>cmev$jhl]Ps97#kb7qqrh%B' oWh,F,Z(B72݁K u Ӫ쪛)#{>ι;Hr%:(럛 g'"T>Y_ZQFK"Hw]'jF+w3UuB{ S]݌֫& 3KyLiE}K0j!kaSOL &'hXv4\'L}iN_ V i 6d\vƸ!m Lʼ~; b!8};TF -Ve4G?0Wu{1yom%dʈ; ~8qᡋCQ5HV-|@TpØc{s,^f&" QaҘE&}?Ed-K w83TWyB$aV!OoA/=N%8V,Da?|'6℮#Q`)kA2I }kĩ/kI`@12|Qol42 fǼByt唡qu-Wu*ͣ` xE:m8%k.HZ1/@\~8pM̦vS呛(Nb1T1xm?3|c"״gΫ03HWcL3Tɾ*ռNJP( )+*^@VcTgD}xsAL WP5v@ A>a. `6$i;,]pEBϔӚU0T,µx1C~0G&JW$Wa,gp\3>_")%В4m΅mj/ sgw1i1\IP$ԽK)G_p<`ы 97mZAW h>.e`W>.وv$RyO.'Cb-ɝmWBr/^Ui E)b] 4|1on>K2~('9!##cҖVMmGS%edzg-񗲽cp.9+u^ @!ygg.U>kuD^o0~"HR# _ E ~l ך@AiPɳiγuU^dB{7ޱA!1Jǯʵf7hrXai!P ,Gu9xN.CeЪe_z"j8#Px"-"JnFxC{VDi'8əE%"B8\5)6"s߰VS|:sn,m3/W`\iR& #J!{zuӝQ\ ԢVY܎ڤ(D2ʻ=Ep[_'DkjcMe^ <3os5 Vwy;_zrl7e6LS+h7QѦ&7wg#/-BAH`0YlE;rD '$H3O$*n<5L}@yҞH&F·0ު. O0?~!IY'TްK* t5V{\3S˓' NȜ$Y.'rMY*ʖq'<O YZG=+_+zΨV!kJuMzza,ԑչM %?0CcZPΝP >D΍e 'Y}Z"^wO?\)-.sSBB"cL3mM}ҝp&Ω3 LO"&>+ϩn4&v/+P!70 o'fvriźƃW^لz9 1Rfn+A)o{ߤfm/Cua;٘Ʉ]և8y|O[ U :K^+sCArPqÀWSsD|MDHcOn!P@`ahar>͗H ?С(肒veIĬ">&)2&XM'fl8:ձ@ R6& &Ħ+n,Ӭ^ìUa_heT0rc-Gӏp,.O` ]V_q؎ i*Wk߫{l21rm@!0olﻤqևMߟ NTFfɦJlQ)4|;lR\ߡe n7W3 ٵ{r[{k] (/ChĒΕV6WfS1FMvac[biqWYK~~s3Mt˖-2+!B.(?|ܶ"2с~ŭpC+/s)X-)=vZGj0-PߌY[+|W$;qEK[-Je,]/#T$sZݫ,Q7SszY)) "]Y[Oѐ%[5vΕ'siBy ,z2geIi\j1/hsRDHpt&Yg)Sϰ߯QyuckdVK-HA9gAr˪>ljxP(pչiI]FopĀr2iHn @5IxuXt; ";Z~>A皡/y`nM?ȩv[SY>8 $g6yn5ћز XIIOWB;7z 9!6IB1ɄL͊_QK} U,bxLSÞ,iN?Mֽg]P\%62Sg ~ ۶flۚU2o*ĩfm^%Op$i# jMcO!R\cEW 1Pڷ=?z+gT“~ȦZ|QYu4kٶ!0㤖m$8q0":0r=6iJք^uzێ{H_/fl~qtHr5G.?{pbW4f>%թkiUT"lTb9\uf4X39W;1NX^ yghG8Aa?U|MHq<9sk0},"ETkawS]d\4vj^LIћMh8NJ?f5CiyR׿32؁!2*uRӱzEۥRlCjK_$^5S$/Z {)4q?geݞ躈G]<:Te yh>c!RY˖[m*^|&#Kt)hdIAm8N1F`bKx{GN2Ls%o.&}XPե=9EVfN&tt#6ImgfKobꡮAaR%N9^B24iqTyϕujд|dlWlHoX^jC3*'MY Cq:J 0S1+ۥ _ t*^ў)Ev{""1͋8D4(-*+mCIn+c 6UA# ܑԥ3AВ2:nϽZsXҙL/J/9$r%ΟCEޟ@6/Ss&)ac3}ح)Rl&~Z7w1 4:V*׍OcuaJ%f%Pǵ~:6 ~S]:Kiѵ t"`9eEŔ+d妲VHPz̻p:B@D8|u%€8GS /!%~N't>H(6iv|o+Ę:k{O)|6͟g1R2r{k|%%AA 82[vۓNT@UdX[ؕ_@㠄9L9io eD5`Ü"/vC9 ON[!} odբ 6kW@xar;;u~)Ab:|+?MAރꂀTԀ^>i3.]dYk+MB{Yt!5\s%n_@m0Tˁ"94Z7`{񸑜z{ O2xG& n<` :.rܒ` Zf@0 Mm~,)W#1CzYI-ʭ Mqّ|P{p_6_]`5OF]oب8@lȚq]EP=Wƅ`7`!X%> QK[V4©j_:Nnde0g69f}\n, Lv4Ʉz{t 6˦&]I`X"H\^^bĨX)Sw `yɳE ,3$ $&a(C*hQ*r4~kEEH`%e(W:Ƈ'*B;dmqzխfuPpImZ<;%[} W2TX A4N)j uƖ/vp_3U*ObqͶc-gX;nmeQ_(;ӑ8I*ߤe:Eu;ԥV] 0h{/] L9djȊv@`JqmY'֔ls<4/cMVd*PH*C0o)|P#1VQl8g|*b*&f7%hS [. (eުQk-9y5_͠"v0Mټz àet:JN \Bq.ep kነ՟_:_t"x0+>o`.-Q6Ss'otoj˥): @6Vہ,6?O%tWqhR9Vqr.yAGϽ/j\A g6ƥu6'͟,tni7κ*:nW/{ƕC?KAkv8{T /iO eRlG:kb 8%=&HĒ2b63͟`)ܞ;Rԉ^Gፁ٦$ }LF5( VPtcQ*hCrޅxwL6\c&ʤÍ83#هAj nyC>ZG3KsD/ʠ" }̻7擽10bd"%ݒ5( 7_]PaTa*bYp8BRwWj )x˼tfz[zL9e\F/'ft (A8^w>&-c l%(#PAP2y{ԙ>iiY %ӭfYƨGPEmL( y;$3#\4'5bP DmsEOx"on(dj%P1hqXGt޻&V2YBm풍$uB+!- 8}F? mXri+Մx y> Ps^]dT  qH3pd$ECH#+) ۗp-1IBrpU;}p3׌LX0<ܨ[+GpH6.@HHa>$"F5$ =[^3(fZ@n;?ao'#i[B$~b9("DDytT5q E†#.Q3*1J$RL_qTR /u7\깙e!DKθF#jĨV=n3KuNfCj[4a&2?9K&-%a>q䵱S]FJ.3dFֶx>11 {w<aYaiݯi] @m pX=%¢N F̶-],'4 HQ*lKcZݝMne\Z¤j{N`#oŢoCRQE UB*a_W&QB ,\@FX9w+ Jרަ!qK.,_PvWr[vgo9QgpZ@[+]Lrl eѱeB1l*k/QENejz*\ ʭp5c]+n_=얔0"OE+$R-}h3}y %yIua̴&1J2dMEz%7f`.sE#-YBJ툍{SH b,-QN2) B,5sJ]a3h+f&Uм~j!wra׾.Zyb{#?]@qha6j fz6wWB{~fγwK.U۝ [ 3 Xt+&{w%}q8 ~CjS lKkb0DەNR!WbTxh ZY6+ J ʮ \V(4j/udڑ ԗ)-DrÎ쿦bX\Sl);+9i.-<}/=x^cHkBZ/ztT#WJ;wtԍb36~>.A[Z5,L 唈ry(i s~Lݻg#*S sZ1z%pfa KM06d]?^nޫ?U3w8~~=W6=}|jUj^uHt~BfCjsmE"ZGh.tV`aШ>ި9?ߜ#D$f쀜~ܬL/Ti]|~Rs{' *o% [=9 8Խ$&޹K{5'ܑ܈R![pG}6, ȱ~X+=~N(\"Ky&Ľ6aəxju :*7_>7BM~;.uDU3t5BҀU+˳ vz&[nc)sfxۉSuH tu x^,u̮o Lɓ헠U(ht⒲9&t-Ƥ@#?a987Sz$KޗkoW#U}] 3զ`+=%a5׋bN~L:'wvM iX%M6BfJݒG [%:d=G0A'QT=f݂ߴW}) 96W/n~P$ W?O{!t+O%w%% D=yB.T ZbeeL_Lo*j}`iXQp3VƄvEs|kF->`2OH&q&4S|~rgM /TַE&)6 -b<?\q|YR5ޭ)7ktFg$.#r|bѿ+ed-IS/07Ÿ Zd4{uǵWl:B lա^?tƾn!yD9} &2 -i̚C+X# =29~)O(3(P3w 8DnwT2iWہ^O8@r_z_[Lt}TTiZ?0pYVW/;\c0ۊo 6}Md Ii\ zșPh@v?D,rUVe&dԬdLz6X0^UA4s5QذQmxE/|Yfn_pfrr4I}Bln 5Q?jtܼv KPĔsև/Z?Gl8SNoFN;S75`TJO7Ó0qD0ыM#>Χdp[}Evu$Bm=c-gN U.Kqz F)nÑIG|`9 {u=J~buAp~^W)&8(FC]H_MN0࠭#0:)9< >Z bB&RCl%<]WUcm=:{}{=S/yR|vsmi٤4lY&P~3lPQxLVb5j-vX/=U}゘E3ՔpaYe [.&o9<}k3_2e 56zt!-B9 ExSfm*ŘQ/1: @ ~ c0+( A fÄ[!&aޞEmg '" *a*<=lъAMsY&.{1':qzQ'6G¹iI^y#'+hbT l;8Ğl܉h;SOMNeOy"'ˀ*e(wїIo$&]wNqr=le·r}T%cդp-ݾ gz8plQ40]aͷ۪u *}ɟ%M;%te.S Na(5j ?Mݕ9R!!Lu5aV{42 ]:`@% ۻ>q,IU$̵&-nEo{}SX?*F &;W,[p֌ !g{K~ k3܇*لƝ[ nx 4iR5iT jU٤JGn ?uD3\;OI y]F_t8#O&^ȣW<:6%Y:VK~qn=<}oy,&Α=ȸww8˶Dư)^oR#oLrB)(mbU*Ld)7iؿGD1xFlE* Ȫޓ5ghڷ lܼz+4_d(Ub8d+D`X =^4:~eB2KBǺ_i|Hx\Q$rOR6Yf],:a]dA/k|l'3Ճr.4;aaaXV:{Dx_BS10^źh5o,Y"51G"_3ݍg/;$ב8ᢃԇry}5=L 2>.+Bh9Yz9R4Fg"zSg"Rc,=DU"1& _ ש*i"MM2;U8~8WaP&B/mAm(%FP]aAmD4t%a4g7&g<Ӭq2ܝ@u^xWlsxA1 VNYI8r/L4I9Sh %+t3.'߷!s%7<$k~+PbHNel#VR+lNZ]dC ^QAL‹5mEf+=T6<"_M:1g,00:;r1 ׎s[㝲v5.`LtSͬ>7C?53`%qCaL@~ì8VnճϘs[E UsKG?c[܃K 볺AWՄi<&8d !'  $UiW!f6:׊o"YVqNA ҂ykr a H; .=:0tpT5SJp~*MPtPѓ.D s>?A APz`;Wj0{\d"Z3 X<' vfO;f^:.SʆōVI|}ă-"LEXt`t}ETA3rlmSEobNt%g0Q[y2f@դM@'RrWGskjV*4C~n;N6&3Fў;Q8!841.r3MIAy2S9]JD\񡋻DKFɕFSLAHSQO ®aziXV.lvgg͓"M߶u1Eg虾X†)=<Ţn+-rKЎT~cR(\G;tJn!W+Ckˎ(:{`4`D7R<~[M =OPW5{U-}Xtt"Y.!pO0cMoB4L/}'N;*|!b`IXXW,?dPJ>Ev oT0^d`luRAM OX*Yn|KґVBLUZ<`rnE Dx@*Oĭa!Su# >ĩw9.->oSd%K ۯףI3WN%:AM qh^xg#R{t&9YBV ,ҢOt'G )Q߱ti+mr@swƖD smNTiQ- y 2wdyTխ>@ 1 &A)9;^D 4[skº vЌ(u``:!UU6|_4c-{>]>G@ ]JM쒜5rȊ,śh:`Y>jC"'*͵,χ2S^5`6$9ǃ/^kǍȲ}3G(4!KzHnM[%twW`܉7b/Ť:Bera# ?Q &x=Hь{@wPmg%iF&T9cHdFcCEn !yemrõ˖[ _*au(9u86NY떘ڳOfA~26vRdѥ-*"[~׭K/+>W4 AԂ"Y_ {# CM.̈́ڴ{0WY3P獏'&Xлr'Ro_碩}1eZ` UUYK@{ȥ)%PYxVkdk ns_BֶD.qmX%&t<PUea:5`{~Nl 8lƖU$ws-zG"= #n:zۨLH㼶IԓA9Rʼ:/xB5ћՠJW)NМhfU\n \;oNlRG*l̚19~a{9=LяxA#,'֥A,Ӭ]Ct>Lvr`ar:߀y0}Z^T\J)-@"˲DMM%kfJ<a:CDisjzMʜ9۶{SR$c>7ݫ`}h,+ PMA-ӌ >VG{]#?h%: V+aq!c4Xapdd??]|L+#|4[:EFUfe ;DӁ=$C3Zlr7~3{oa>| @۳34}]t(AC0\ot`dhm@4xG5ݗ~>8|ItJe׳adE¼LP٦1kaTbհSd6 :DyBx*FhGjtt2U|:+p&<s]Rxy}X):YID R0caS AB/YKB@UKG0|k`fwB~싆g'p o[K,&u3RWh@iOZ5s^#) ;?9zk*}}3?SyY?!7!xs%C 'RBP In4rz IJ8/u` n0GS=Qo G1Gl{ í{l_̛ƢOwG*iBTSl9Ӂ"a/ϟ$!<j( d*'z2-=J_s^F>z_(t6bXu2֣Q4u@E0iVnqF򖡜52;߰B0Yڦube0C7Oh)n-8s=,PxX=}m@Ҝ'nK+"؁'oE.K} 9ho}mط(OUhrg(G9FOpuX( Q` yl]'S^h!.eE])oWV[g\wNH% f~w dЗK/FJuns^~2&mo@ݯI~H1;ц%Q݃-;b+\gt6jej 0[r~RhMY4rjCNUM}&~>寯{o߻/ gY2̩˧4eE؄6sU 4>Md,1TlatAyr \d3M1JoĥR›19r+<7W)¢-V)_EUݙiW'ORIa$Gvvh`ftN5tp"Ŗ>oE!`tyxZs>bVd,QQ\CEC Ta)Jwww憽ݎP~Ś`, " 1uS p.\@j/5UqA60Ş$D'͡"!T{[0&/]vζptvn?bQq U<B6r:t0}W$k$}Cح[nxOɓ4|$LW 5\@"8GK1 oT:q) G 7,8B#/ ϔ l1 Xc7anPGE4]ǵb`F,Qj.3TM]i N5$̐2ԾK=ޅ+vTD-c_馝%DPe?)fRw9cdƛRWS :) ):_rPY dzaܺ|Rt)x @N,ox):sn:XqLjroJ8'8F60V6T=X'&sx/!;^Qtʲr$- M^nfg_)`javP&D¶yv%> 9Ic'u!S7 D~2c}'Zϱy{3O _T|$UZ x-莍: ^w$ԾM+6R44\/F%j=lT4ՃoWy$rKUt_K}{wdBw:wخ%&;ݾߪ(xbD 64Xzxqzog|9ӊ /q(Y(NJiT>&/paN>o<ʩED d:u]eYoȰ%²RtGߟ%ya.dAX6.GJs/,WGhFTqX\T@>\֌x͈[{3}b&Ƃvi*Nd^'bxB+p)QC.$'w`M3#ƈZ+7$:E';v.g%_fQ.,9 IӪ\ֺu9 lDgJ1K,}XkP6{5JU5o"``ijnN4pF kƦoriu ( zĜ[[QNA冱Gm \Lr{0]xslc^vYTEՕm&)RN}·IL+vgԲJsliɃTs*[4]yEyI9&z'07aƻ 4OYEb& @y=wuuS%ǢԔxY:+[=YBk|p*%,4os%g (oM*!z{fNf|aq{9wN=,s􉦆!$[aȂ D93ۯ*sx=NX8+!}m[KB:yQIz iW- XS7DKbY*&1#Ѓd>l,aV(,M @*q_V$,a TYƔF4 l%xcRb^ga@d#l=J#u0 ڧh6冞h T=|3Uhh%E<u@bHmz-UWƧg Y6TH@3y36nL@-NFDxYj(]fzH/4N4Sci,vB$;ƄD{r㵩<%>44BAjQ@zDw~!NOag'1>ʽxWLoIrgXzX'!qfq͟ՠ-Jd:K*w)L6lcedB/G~A3qӏ&⃇[RƙFRluxU_h1y‡aŤTQC]{G ђr[3鰏^A5]Bgd.]JVN|藧/u|b&? JkV9N Y;$?_c#F^ntOB0kD@ Ulwfn /ρn\m4;(8)cF]j_P*t/gISntq$UebΣUOtQ@ u1ZX(J-ةyrrx~dqBjvQljij鉲ZWuPtZJv&[!;J~дq4׹NۢeXf,<ۣj~c]lLJ0!-F+1Po+%d3bXr nտpQ=s@n/s}TJ6ub1\-&g|p_*in;=`@F>9{6:;9+w}٨[ N9hWfȇQuSl9_)g|~>:6x@(Ǽ,i#in` JwwNʉeRFB_2 Y#`_\1 _ŀ3@,KoH2<O.ԄlPIArIݵ0r/0P pbcPb/KdptSH)r"ѽ@6l?zA_*nZxzVnOL3s%[oY}ҪRp1l%jj{1=Se#Q)~k"w;i?#6 fK6׮~ERg#>kfg3 %[t?_ 8gi=N|HOI?iW tYp 짦xUK/ ۄZ rYKxa| ;4$8_!g)p7by :'Q-U1 ~p`]×KD.ο=vs,?wnA? 6mHdg r7Y21quaxCV 7 Qpx}SWnoE?!JNxU+?GnV>HN`:Y[\w2nq84'"T]GYMHf{?,`H%-£5ŸaSQWF`PE3%|ʓ*3En>񾍖Sw!֮@TظMSm_ih;Jf,<αc=.-@O3@2g[*O *~>:[…0@MܴbwW0Q yl+4RЗ_@bnH_Xrx]Soۏ{đ3qӷ!Bn*"s"6X.Y vGFvgaN}X*vq|)-&H>NJY+ZՙK8qf% =9ej8d6O#s59CKtȼ5%_u\""/GA| +_iP6ޜGʴ$Xh Oխ33֢qT_C*YMSVNE08>aJd&Z޴2ӐUGE\ZșŹcHI|Fqox$6pop%"XP jp`18<,| k9=%KW-5s^{-NˆH !jgtN%7RrO`Y.|$>  ȁww"p{s}?@dE{B͓6Rڬ'좍FR*6ȡ%ʁHs#H L!Wotǵ"4Uvb:ӏ PqU\ՙ$$38sCz}țl֖is̎~o=SmW~E"vQ|yrƏ:y7m\ѱoNG!(WPI0ϙ)|23a:s'V*Ohր )xOrb͉Uj|³Qu;o\f[+ E;Ģw|BFa̔Ŀs.gmYk #4g92>[_!eFmkO%#>{kfJ+cc3bcWE"v[!fP9&ϕSqb$oyy0ka$)4wylri5DPs}rq8F]0v>>6r\@02l) DeH;0n)\~ *ZyKV)^F'_4q?[ĹɱHmyD7*W+|'9E'9!vIcEԗK.j i*,22(!Ԕ3J_n%SB4o}qNlq9.m` Aj8zwp&ѰXL\b=Xc4XWETO/_Mc9x!( VD"k9BpuY ^ 9VhOov,l]1_U$b"VɌ 3F÷.T0RαaUOByR=?R{al.E[>dĆ')H\YЬl[, )&'1;PŢѳ&NWl-QRHi4G*JUn5- O9߫T'Z>BW ƛVaYDfф+([ʺeTURggFFDKӷs) <,dI䚤\CSݼ*.[N]|m*) ( +hZ4Uq%i4>$iv"*per>J㖂MnדȔ=RӘ֜>,"#cs RO?{,g1w睑\i{n$W4 wKs! 83 nfPa CAݗB{ Wu'gS f˩S9%AʗQ $Lurm2g;,3Ƽ'3Wr* bLY|]A_'5RLn 'vfӫo$dpbαPt KTKgz.I2:y `PG"Y, 3_Y,96aH~תKO+s+nzK<# nUI2>RBD 5Nj!—G0gsw%HпmM0]uqlu^M !ZdjE< :Heɑ@tF.Ђ ~ l &p\Y-eE\KrU,6>FnՋB].?txެя8b{ 7c_8ƽ8'cPvh^)M19 /rg 4vzrrKGoI M*ilDڻ(m'M[Sv<њmZ(ՃO~ /X EO[ $U;&s?UhL%zpat;nUЭ.M]a_={ƘN[eY9]+ߓ-Z%e[׮<~V2Ǔc>8E%;{ xRw KV."~ugw{0yUtˌn* teR܄6\3z4pC_? <$ Ǯ%u+5ىaaCk}e". : /00:֘e߿K[x!kP}ၦg~4I SZIx_3㼍!bqȯZ6F5ʣ  "vtuNme2)Ekq`}qel 5ƯU!􌄢 5s{9tnb,O?MÄNC3xg] =w]2/m:IsԽn!Wʘ)D8P`%T9쪊KBLV(%&Mun8X\6_aA{-hD7_(ݴ8I]M8-]{woj>;lJ DTQ"ǿ?q#ZAY,\̀a!{jh}[;_ V1XP*2Fp9Ůg!cf>2-oC Hq4c^Tchf3k1n&QW ĀP0?{rپܖeܘeپVʛh“FZ Pb7>{J?&G_+}hh,C~560ILQrdNa{ 0Ϙ{& wP*^KԭD.N0Էґ 't uo eǃsz)( ,JydF"{[΍0ߡcBK[*#<} GfY&yi_\RNf_=ioK/E2UG1ᑧx4krS~& aF.U7H_V6&h7ӧj?+*?ΒA;#$hvӞS!53BZb(L,h*t;RiH=x1׸$_+Ti-;Jw:r7^ ύa 2[7='=d`r7 ajLv;r^]tS5Rn=Ko @丈l M@skWJ0P]+{zMm.4S~/)8kúVcLB}Jg{x">z78l=o|´҇ @S(Ǫ~g٘ThqhkuLV};MͲ6Swu `+Vkћj" <}kPt_~)zWv}sO bvpR=Ia&-Wl/Z9oly]rX]<Dai$}=0>6Ef^09ZL0Nj܊pMaVOPpl!W/B/jޮoT]PXėvCt=6/ ]ADo.._}DTd rew\ǢǀDSҝDYQ[v6X;=} Τ-pХ}dDw[b|g֝ ҡJq+}JH4go0Eݰp:pi3D(٘98E'R4I LW¬ku+#@?mBgr+$G^hs@ebTF'g]ZMHaDb*"嫂h/T?h6Pg#8r2  H"VcvhUO?e@,Mx\uTSⷋGhejYk(Ʈa?4p]ݧGNѻAQ W7mSe!farHmć98-'R>k]N,Z`v9JwljL2; &B$cB:3JV5Kl7od0 sGgy,4;8bb!Ww/Ly?C14_ {%: s/!22;uZ",:Qx*V|!'}lP3 NUEQ;u" O 0qb3(OUb*Dcm(fFHJpS/`o`]-C!6j?0|BHFFĜ)PEnnFג"NwB&1/{gQ`xr PP!cE}!$ ͳݫ8;ǖ Iw~~,=6; ;Td8h|t%^Lݩu?K1P5 yf[Lއ/g[(U"H#J*d~Lΐ yfr|z\l?8Wl| :6djsYhq4' N,tqLJвo bxv^D8ShwPj.ް%5a6=5qu6\'W| ?{$^sС "DjrLݬHWE.a"vN*/JfGE7} v2t-8 6N`cy}|40;ѧ@ ^5%4i2e|=k|]aJ믬uK" qG=/?ӃʵMA%?AcpWaz-dCB*b9z&$-PmFsWQd0`8<}L8񇒢w/1K4=b( ]N q5dVwm_]@IAJkhJIq*ʊT`qq+ȇZeU}؅Ksnz}foYy SJL*G7Wp2/ -b U {#v2So=+v4 _}բw7t :`L7~Dm.>ld%#de$#֖|1̭Oo%OucQL}śaB(Đt32fGiSH Hp NP/N dRᅮ%uޱ6}JNY$rKzRJ[?M>ʧ=d}18>Ġ|( $ S,EH)u_{F۝gt7QS^D*G_z7F26g2+u/|q J\#J{p0Z5׵ FqU W;_} AٝK!LM^ލ'CP /JW|Fm2Wãq܅({5[JirIX3:kTC? L?SUQOkZRFѧSm0@i H$ghSS]40~"3 ›ec#Hk_4tSog7ؗOE(Pj?'|h9љ9zӺAJTJ`z:d%Lz-K;'MV%R8'zKO"wc dGr&#晜 5.v}XKv;"H]8'yP}3M>B]-[eI@4ygޖ ZK+'ޯ—rs_t<7&ϥ_KOґı |P+LM p`uoω/٫ŏoڰ8Cs3@nR_XZ)A6Eu,7qp,ù:2Ciܖcz0ڵ$ EȚ-d5i1AߐE;w-B ֳsǘg?tQ*S-! YNYd C3c=W׽^|OrW_ 8ADx6ztx TW _=(%*(YgXE0\=3` _Ztΰ5DVIdmc%%k#eA}{p^pUl-c>gjZ da,mȾX8뛳ڃW04Lp0 rC񪞚SMkpaV# H_"|FRC6bF954&ϛ \G<Yݝic͂hgQSg. hK& ~2&_YH;~[G/b]W9 "Q+D!Te^H9S{1tyau%"WN 0geFR1]{{Ra%hIZOfsPJJ}_* XWˤRc8Rq`?AzU<9'`i<3Z@x݉[;4B|ZN,⋔MfXY0$ c{2/f/(򹕸>i&) SAXw= %[Z^0ĮW!%gcDA%g8N`>ę N*lr7=a1Z j5M!x9myUGUpҡmTy Y>5xmhvJkʌkJgMɜ j_l2> 4[pBZ#ʖA5!-㗓т1>8$ӲWzBRGoqn_y+PhlպZbǥGȫ7oE5g,v{ћ6x?o4F(Cbd?I] 홶Mtxs @ܙ8 Wމ{5U | U >TydhV# Q<̒U7XVVI[G(R7=ԜBjbw=P`K3Zp_HiNpI.KJ=PT"T@,gU0GMc;Xyc"yj,!~k,YHliҘ_VsyA0X>͂+ plk,ЩY%'{;UEJatY*lan.g%l󦳽m+ÂVH/{'2OEO="<d˘~0#pj(,4· wV?F|=nԮE`eCNsm4,t?stY0)c6%*|VRa< GY/R 2^:ۛ:c|6ҴC})Tk<0%ɶT?UAڲ5C}gtF;*ob ^}&b f"51s8b%> >G a^VW' 3XU#+}y>VR'5 {\4K{F W_>ףu 0c"P=rJnXZ2MKeoZYe]:8St1 Jtlf"3[G+xB:ޢ)[E_U "\%9D%!-#wsF'@ʊ爆UG:(CdTmw=ߵ%YG=+\l;5PkR>?P!̪= POI] v{dM"I Ҋٺ?n߇M=χy N,e**6p +; S K/to0f2)-!3k/$R6l[P2rQ̆<(.G+>`~%B>gˡh2"ے\25+3ށ%{ af Hv?E=]F%QI]b0M>DR:;%8w ^)AnGcJVv3ӿuw`m\ЃJ&_X(_(LځǮ@6_e+tI`â&?#Ú _slUk/va:4N%,G{q~WQKsO 6a\1`t%-6UE+΀&ֆw+sKOĄU:IHC2u="W#`7Mh g]=/wܨeh ed ?Ħw̍MӵSm3渄.~Iv~pg1~pmqiN˒RBp4umST#.Zt56w6wu8A()Eۃ\jI):ШBpʏ!htWo }#w |,T8B hXzo"r; F9SV.IHpS bGŀ30s%'`ɎSZ `uVL}Y}8jGIƕFr%CD}&s(QM҅-_nX ldhcl4U#Z@}҅(ĉ"Liz$A<=zEq(/u S lM.u`,S3pDB p,Z5$BgL&W\[AJ6Z (b[d׌(D],nj8RKgL(GIm%J{nJ ic%v`8/!g O[feFb\?SAGBD鄌;_jv.  w#fdd!y8\+߹7떎˓4j1x:$& anbk2l2Ju2ۜ,ڮ]&C[@`CnZ\=?Ay#ҭWN 2"nLǍzte`0"KCZ;q 1MwcBYC,W~&dÝ8x78uqm$ 옂$7Klƺ~t,8 ;8h#CI1!6 a>0W~$,I} &NSP DLCE-ѵFԀ_d+Þ;&\Mޡj|\nVS%ڡ !%$L(N HNsa=HЧU%'V;j_JLr7V53L51qIfs7EΞm3i i wZ;Iӵz#}ʧ ܅Y!.#( 8ծ+dUPQb$y{97<ֶMޟ`J0!&"ZC)EMm[esSSk)po ?!%jOR/pi7%'v`K2leWaXtuD1 ѻ43-f8$GtX;FNNr``w2Hj2`sºW @\z) -1,5eԿw2~L 귔}XĴ$G=s:]øh WsN  =M 0:S3а q +{!@ڙZh5Z< '{qp^E\oB@vxC#&$2e cJ< D$g'zLQZ%/\Xɓ^2f⵫"̷:ђ3e/p$s +߰&Lg [s=:O[\lօw/.HHJyΌۜvpn-, h0[6@@(ix@˱Vc6u .F>mJJeҭD<햝`ID'Ǔ={mPab7~n8n‰Ft`^lȂ>ihafQH`cDQ>E6)}.P_0w'HSOP3sbG|,)r0-:uhAejM>XnÏ=gxؙd*/orrZbc!E$Ldbb)3c22ʉvy87th\74Mphe;6w1$&끼P-㍗NlP⤶҆m9 n \0`]/jXQC |PP6~iZvh-!$s֓:;9%<a 3婅bnE#2zXp+2B84s8#Hcӈp 5i-by񏃣ȩ# ejI= V/'4.+coD'xf,G}Ku|L O tWzn(\`y&5>w[oNKS)OF&qXAY`!6令͉ 8J d } Ԏ\S&_Ҧ+Ab&-ѳۜ%+LSWWϞ8ڄyFtּ"G> yc/4*cQ!n XYjVchЊ#Pnq|[ڋF\H_X5XiթDc(XmD鑏Ӡ* ETIăgJY }s  7/FWYRYy&Am5(sbPukSRaq7B96$27H[@;s>2#-:+iOx@aGxB>v4!sCZLf_p!d &2vHcϵzum0zM̨J\gӗ)2:yk|<\i/<>~YtN XOaxLZCש6ifM%\mt8vK\yVҥUh.N+L;)_@Xи+Y0u n;⌮֛"I(и-i-reDt _[P Vq|% cn6z.TZpboG&?7񼥑)E1)U pMDpMSl倹Y,ՇymA-{2l1,KWm}vavB< am[͸JuGTp0lcd:#[՞/ʐ'&b!ă[ +X{Yqq{JDཀR[Wpܦ8mꋱ+dRk&א=B}H2EHRCpXڸ(Z ]|GYHʩJ7omL>#X|p8)¬$#h6b%bX5UGՁ|kI-(/{7Oq5!L*_!zI GY6kGYI;Xw=1ebd2?$Sk2wЗO[*vN݌y\l@Qk7 ? ІcϞd(g{\?s B[?*rⰜJfTSr攓X u3žp0ñH/* ]ʼFZ,-˷.]Zc%(=]A :_NbЎ-&Q"֌7~eЙqv඿=mjv,6e'2~v[[⃤ӹ\ e3ki&#ڜA⎕wؤ%4'#xFi䴠jN^\#n)d CVtD0pÝjr=dJ8FuN<]Y}5"M"HoĪX(%wH+HAo"o T.'xu2!'*x&y-h >O]mO~Y8T7dms*(ڔ::Br ʾ@HɠK5?:Q>|g;^s߈a.e$Ռ}lF4/K gjI~(mND03gM.8$iQþznR%` X̰NrkM9 Զu9;EaIq6WEg*0eED,l+ZjKH^-|~*^_ӱ)8H,?wx rd~v]nW] T.œYdL:"[N8f;9dAs}he-%&lW$_A i0jhd;o< Nnzkv¡\#U ' h@/:."K]+QEVr\i ! etbfE\f狵4[@] 2WV,l0l }gs0Tҽ)zpmX-fukhοĩqC$zjq|_Niā{&!)S>ѹr'|t9_sL'u l}K n;d &DPo%(ɒX&9Df \Vj  m%#FQq 7EoP]Q njc8Br+ˋqf=k~[/ vr OWtw̡T͐l=@<:_{~-SJXq %D.%&`lߌ%M7q7N4P2;WT1T}Ftd41EF2.$dTFSU{ '.S*VNA#1rQ\iv({hL72dMm_7/Ld&?Hr'$/ c}CKm]3ocMY!Vg:wCZ#"M@^1h8>a܍rId:7%σ ZuuJ-U#AwO=ql\rd^D&kw2 X'bPa(4xGMĮX(x %oRR1.Ecx;ND!Mָb=D#qDP3 xH%oiW[7>XՇG- |D &b$*@VkwR_ㄭCoG%iDbNjf~kR؜So^v|,%Y<ԏkn!,Qt0NN-5/Y-JkƢ ȩYok~<{QnL\0*ʤ!'y^b_lsgnF%2^ۂBmH"3'!}f"ƜR?x!s&-wy, ]M!y<z}ڌpStwOtRbέi{w2.ڏ ϫ;Bc _w=kF0Lh@ǥN2կքIG-0HaӗX4q ()V$1L5]QN톔DQA$յ5٪vR@ !{v=UݚH {AK%4y}iaK:FՕr0]$)b#Gae\l+۝TS~ޔZXodcZqdA2o*>(`^i(t &Q³ {p"O<=핥X'ަjpDpGG?LSs`T~"쭾,"\i0PV~5Z}P,Ń3ltJ<݈צ}C 觧.1M"p<桾[6OWjj1/Єj_* 3 sx^*e9Tƛ˓K4c8)-GBuD.J.ȁ9(nuWٰ+xX>_;#%1 Ru׃ϹKmd͜м9΁$=eg5n]2ɤU$ w]ur#~5 n0~;V&U|̀"R ;z!rrO ^6up+ܨar+42ҁ oKgeXUIGafz1f_CrW&60@ׇX6vnuh0EN5\#%Y "x[Hm):R{D^[h~6ޣۡ7 -I#}bDEqc}K[lIu]WƐ嶴&\rf*`f'7\:PUiܪS`;|J xS*W'OM<} =s9ҹ3/9˓g^~q̩ϼ>}j%BjYc+cWQ8 i 85ˡzǽ._!P/+5AUF?/AѩsA ݵ]i% Ρ6 HնCL#nHG<Z1 `Xc$Kxn'= L,gR\\,3j64E’EZ 9̆-9ԎGWp:Փ6t9SMhtz.\2#SqKP KTrY: srފq1ӫf:gZqQ1JyT_(v}e85)-u: =?1O]u'NGvL c[^ T-DMtV6b;)6HAr8c}4^+~]F/sIH&ko*(4t*U1IZUp܁{a,\v naxZb׉ɎTk0zK(e>% d,\%_ld0!|r+ 9z l綏*tiyzb4 Jjom0em!GOgUCuRZ@ȾXn-U`\д[RkdţYҬMWG + Y*7;>*q8.v(}ht54ֵc?b1ިwf:n3T/y"7Pιֈ9}g*'qMDӌX&+5sDSݞ MTqӏd%‡:EaN :y-VF.~zF$d՚Mm.$7a3-0/wgPNexaIkY-g8< QJPDߧPr!X0bV58*)۽dRPC@>]Y|cߺt)}k+c'jte6kcF'~#_%Ky&.^(BUOKMmwHMm]=$5"~۽dH{j{;[0?qp QMuǶ: dBţE'5/G߼z}Bn72 ]L^.Almx_w*T(U+q{t_q+ ҏ[d'LˢMZG{z(D ܵy[8x/2m \UlT`S`ܩPe[HzrQxyojSN!$mamz{Ao{MG~ִ^ח,X&v7H%7+-?vz6m:? L+I=>II~%'bhXŒ38¾^GẽCa]P, c dӑN@_;}fViY\(D+PGCPpDu eD KsKC{(?!5΁07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!Yt} )*$ӥ֔B^9֙]}A&  6 YZ