sssd-ad-2.8.2-1.el8 >  A cPU]mDa 'zcwHWLdffє`uQ}x{TQ{k{gc''S7f4q5E o]&?$;eA㉆ൟ,AzA~CDeU7Zsdf, /cU>c^4LlLKm=@WB{ naEN#%w~V$.ei\p_=EaOXQ\R7 -[m3E\(:^SPȖ~8"+Kcyꈓpa3_ZII<>&1:DضF:Ѵ.k+rR1(- Eؽ7o71+&=R`1 ꢂT{pqFϬ\_);bj[o$Asuu5]EcQf/QtՐ SeSdn7WFFA+$o[Nܟo|wWӋm6Nwެ}@хW67e߱j0"^L-AdNFѬ3@8H;Doz,7O~.(},q3_xʾ ♆Hn#1HM`䥺Q䃻>pE?d   2 3PV`           $ X   (XDhD D $)(88@9:fBG H I, X@YL\h ] ^U bTdeflt u v wp x yN%(0CPTZCsssd-ad2.8.21.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.caarch64-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64&'F(K9N>bQ-AAAA큤ccccccccc,cccc06cebefbf49b2b7c964354405f0245deba1ec896580cbc6d4835d9ff337c1f7fe8b0a9fd463fa18b0f4218f835f4b1d5e6f379bb925f0bb4144a8bd1e81726a88ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90353d0500f6f588e508f830a2e6e0114019496719f1889bda67f0e513cb0515d6e2c18644edf5d4853921335e89e9e85363012c84e8825e9793a0d6b648394b0f1f0377caf5cf36b36debe18af68ceb8df13b437eead7f374a1ad435ff648d7ee41d3e90fd1cec78ca70187b8ae65f6668cdeb61692c00823eec361a23eef5921b../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.8.2-1.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.8.2-1.el82.8.2-1.el83.0.4-14.6.0-14.0-15.2-14.17.2-2.el82.8.2-1.el82.8.2-1.el82.8.2-1.el8sssd1.10.0-8.beta24.14.3cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.8.2-1.el82.8.2-1.el8 .build-id130ee00fc854ffb7b0f079ba8d95192a9cc7af946d5b25955655b29d257d91dd8b0d11e1be6953f5libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/13//usr/lib/.build-id/6d//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6d5b25955655b29d257d91dd8b0d11e1be6953f5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=130ee00fc854ffb7b0f079ba8d95192a9cc7af94, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR9RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R:RR RR!RR(R,RR+R8R5R R-R4R/RRR>RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR>adclibind-utilssssd-winbind-idmap2.8.2-1.el8utf-872d12a2fab3f5548792d4efabe397087bb4e90d4899d00ad034a0830edcf07ab?7zXZ !#,] b2u jӫ`(y.b^mnUr6JO@'WڏCs.0B#B2|4Fx$ޮPQ>$F[b-0\E?vxV\^yoJgfOmCBk=`k-^~8be%ɹY0Z-acWA")6Hu6m/E'c,+ĻtջsHB0q٨rp 35Cb0shucs* 2Mj<yR8ˠCCZ>8<~lANo(_rpt BqP^].LqѶdZ9U3yBc(I*>(p/1{e2!*2! N'$䞣u =rϐ[~P]?p>*Woya* x@I*`rCjt~eE>b̏(fKԯYߖZ zOFy3S{b.uƧ IΛ$nX=Rðy^x^&sf2ފ9Ty -a͙v.8+7ɖr3#*t;`r@+,'`RvԅHk.qUpYc7S'9e t(`ʚ(z5Mw)&HQΟqb=/R߻udkח,w3FAbM )@ۏ@s%sȵ=oZzҩ"Dڨݓ4FQWT6lZythѶ|V2g!k._{P|j|J708٫J*}ß>J]R|{C}z;?pR}  8# off/-ѢPuyo&ITfQ\Jj.ѰPGbiQtPuCZxRuH~4C,l Fl++:ɗ$r~}(pe a_G'Q\gv'ūߍ7ÐFlЉl݆Mn'|ڡLj(:2Q$K-?M7\v{fF cwtϭ< +صƐi[ԯ|Yb.4[S&ӷ)d%I^IPɞc$*z\)]Dڡj0 MM޶yHl#` s[%Ɖh\s<]S8(K77z^v Z/:-QHx^T+׌(7"!#Rv)8BU+ed觇v{|{$_0k~-`5oGuξՒJoR\pƐ,[O3k||# \V4 f`PHCigzLՄXZ'A[#f3$}S* Ƙnjm)=Ù@R6M;Q@=3z **ڭ~Щ;ٵ$hlzOh"P ^U jN|rɟ_̀WU[ AmVȢVCX9&Ϟ'"l8_rSoӼy6i汼\`^LCkr=0NKE1TO7蛲p L$ ?S%f5"JN(VȞiʽgq,QZXݣk[qd'o*a$"6ױU^,P4 ypvE~6T/.J.vIշ޲Mo[DsaHAJ oG9ujd!uf*i:UZ<\Teky1emHu!5[0d GVn@%|hDXmUq? ܐ^B?\p|-vKzEJQGMݥ~`8rQ](6t]tzq5."Ǧd: V\-+ootNL3-+飮Rd0ǮrCu=}kwN?nXOJ֟j|Hj.w4EJjd? {wr(rNQ.>ѐ% 4XK`A0_(ET"|9aVJ`Z(0a 8o1]=A;gtvTZ1vs^S 4] 6|}4ܓv\ilO_l!"4h_rŢ)k( pYS.ho*}תa⯹/sT"hҿKkB$wARf2X3-Eܡwdd͆ڂ+W4BF:1l?\{w%੮> F&]9ū)Cm{)L0k8#5XR+]T2%Lz#}\|J6U(QsO1 u~ttvy3tP9}loÎVȼ*8Su ulx@x=<'BKRl`^q\>ft~Qs|,V4?R7ѧ3+?;(C/tZ4FԾYIӂ^Fn#K|\\>g0o PCLeФ'(|<|e)*_?5ϞZ))"4Z̥$w<%y kU 8Ed(i za=㺦cJA?vӎ\!c ܳGZ] O蕵GO_?m͏ᡉ^D~Zg1$d&ɫĠeJ.ߢ޴3޻#wx繾n* W1)!1<^z DYU6l oceHB-ckK8QrHS=XHd± )GنQ( uT9E- ߡxvȯ;?r[~ (ڙWi.vdD>4λX"`Ze6],}(DjC 8Y+&R]MLBXPa'l^~cuPF:ƒ*1+2ڲF ]<&rr#'C6ѥtFht >V?QP *ox { AYGDJm1*(q$!ϝ6 hgf{^6xJMJ $gSBh~O% EjOx(!L ۽HZ̬^/SHScUfuNfFJb۹?U Xvkf@p'ݐGݥ 5ͅ. '6]-R$kX,.sJW>hJe.vwz- ЊZv䒟+)l, ObT!fe;}pGUO0h%fS۠t~uYMML 3f"+e pT:6of%d6({\iVDL8ʳb_~i*<,Z a,̰8^95pê4NdTۆ$c>6YGKϩG gG}8(zpPX$O&a% *SWL11yAZPwn9&Ճ#tpGqZQ7G9^]]Z;\?z#`5{@zP^1f[l C¬y?O&[(/Z5l2Fõ>]CCf$+/A?z_E}ܶ%w4 7 -ir*sUm?u#ƿy-k"N `kiΦ#(ªCnci*SLUfb[(j-.F׉۔`D}c.hXe$ᝀr`FWiǠyqcW+|/w3 "H9`5[T:+8i~CZ$m-pJc+ Ck[;w0w{H'NImoܛJTÐ#}ZUȸ m?HFn+!kNqy~5W:vb5S2]rÓWBʞUƶ0 p z+ H5a:nK98WUm !zQ~!$Ŵ^ aA2& ZF^ M=G$>M)G|QAV"/w i2 m,i9i)3<5Q ? bU"!/ -{L+JP(: ՌPz@PO}Y<;'3NghgsQ< [}QE^{*{=<ՒC ߃2d)W|? U;PзT2zV.}`SaVs`)V>g-holSί^H.sND{O0 >`4ΖAE~sЖ^rwhj7>v.M@a9>)/=/3<^; @ k ~&S,ipՋ4Xm`ozw  20"b=T5g* 2DWX lhf1a2mRT;0:~g]y-q;ۢI^S) !WW8{5"LDr'@gNzYg6E}-EgYr/F|ss3VEZJó(%A䮡&,R^4n#N `P c>$(ɄQO3Yn :ejq9SLW6tbFڪXYwMP *dֵ\ qm:P6gwo[MfJ?AX *$35nMU8PGʊgPnj8k3EKWՄYIH.P wb~)wʜ#B"EE]k ;&$u^ <+vK:=}JmkAJI+!!G?lKĔJmǹ^Q 0OWT䊖Ϳ*+M) %s)-)^8[,{61_<&uSxzi+TQM^ɔ"x~gL/C9Bl C^]A[ݪeB,I_ t ; 'k@H<('k]OjB}t=!MaSčVOyYŮz$+CX0V+2ujv@f=.HZ25ȻO9" Ehy81S,7%}J rOr^c*_YY5f|AWoNߪ8⁑TI'|%w YӨ;ި5!i`f]Id/<>.j 7ӶSM_2X/*9[#ߎiذhzWŒp}Exy>A; _No&ĝlAWv~ ƊϢYWb`nNYN>g;C6h`K:2 ;[DWV P v^vQmc \]>LMd `[ !}K4p+& dD=W>)rk]>=!9:箽p02(m dy Fr7Ǹ[݋҂/NNiffƛ.ᑣٌi]vL5p19-n` 2'VJJЋw{]fVtu{vp#@kʹw\fzpj(ol`r=lg""#$lԻ/6[ WCb6(8bj 9Hg2tQ.`>кx,bCU mRGs.܇g!2n8̯5'ץ.U zg&)٨::ۡΓzeE!3K6 @7ŷyFZ02i96L!--ޅgګ$Ceǐ cih761k=w #Œ-tKŇH⺞lh06R;f2EwVּc TNXXGpY6V[fxTVϯF?#>[#$0MȢ XmoPb7!0s %4Z(,=tv*Eb3 7ܰ6p+?Rb6EvYMJ.=8^urgj7 @5FW O QMţCz*YUVdˌBm|smx|OA.̬";=+wGZZ*r[ $ ]!|HOwmqU\szpYI?~y]ʿ+f"fLv.Y[-58"91N g8%/,P=!26N]ρ(Lg]QAÆ3ޥk 2!{q^kY;6&,iE~Y০CX.2LciTWܖ:R AO?c\1g"4v^3&6ȱ dyڽ c+ *!,эjCbwsskp7Fem#ERg]%*6*Y(`rT/aLKtj<,GttR~9i{稶\^.vd<RPX p<5wJ=c*J:I#/tTʈHRɝ Ajg|ȕYե yvLayZ%-eIj$6 5X@T*IhҧiV#Aᔣ. Z۰څHBf /j)G%a*K٩F^q#viO(F$<.3z=x} qo3&>~_ScV9\EF`Úꉴ J?YxӊLGOWx9a.'o~yD 3th V(h&46TNvOK`{:NX m1 ^jln緙pV,Y{"h_yg.C\ /lIngL ;$"BB5 ڵYVPzU^͈-ok vȌK[X3@Xmܘ$nkpbnRz:Mo_gj}/l%/$}t?s}1-B6V% 5/x,m9ːX@8aӜT6b8OyLNH2m|fi f_!|k)csUoS}t\j"w'tar< S熻|a\eAwKaGFZ8ȋN\Usa1U=2Jtď@)Cɗkuv)QY ^w=4<2[V{jb H//B,:g{ a ̒eZ+=o!B@!6>:˻,$0[2ě1#$n" =w&E@dEG6l<2 DkGfWRJ4 Y´H(2<cp=&tN33D8cA30;+w4#Ǧ$+1}>d!,6ئ> 1?Gh=9TSAxtE5#³ƄáKA6D~:iT~x[麝`i>t!A"hY} hytZ%͑,,7c:N (*!3yHSjD1TY7EeZ;1Gd4lҺA52 ނwjЈ}Gm(<Ɋɉg]L)*Zg *1|Z)Of@7uK }Y /*;|3&fnH,T5[uܟo%i(4?c 槙%DX?`ɯ x K(dxvRJG+#)f,IF1j -9'GULۇ\6TqL?7?&C`KtX-05b"sŭmpPʐ Q7  Pڱ뙾/MþRVuZKn'kʹR؀x =m2@TE& BNC"L#͝UΤėss=eZ feoɐbbXCb$I^iU:vM]Q ~;{]H[ʴG5 'v d찁ǚ0s#S~0EYm= Fd4_QnjSal7_A",uj3@]yf/pA {` 7A-5#QN88 "s|"ڌ$?Bㄏcs+=c5o;щJ㆝4*K2YZny u̚Lx\!78_q Dj;̷_6WEߠH>.2i=q<5X5usTU͓r c없(O4(]ϝkZ"g_u| B!=ҏj<3?^(Q:oDZ'5]AҳEzJ<8 nѸ`~i_Z Zce(>R}8V_ zlW T^#/Wf.W/&HT4K 0QpWeN'A4\N2@Iy!¿}&^UzȝDFj %H4uT"0k8~i,Ȯrs(uB`*MTfuYH> ]JU_z{c3~ ؍EyrTfyfWJ7$1olA"bTJ#H*8 FRƀ<a]0N<"ёtB] /gLbӊf\ EQ[*a-2wΗٽw!6Hhd |;^-#pvy+ uYp&߰f^b),~k!f4_לƥ3T.i^TwJϰ.3QN4߯0%9 W2nR{Mk#6J-|ߡoKhR8ukq^Mآsw+9<jyHVjwh.-unx wh)8ã yKr 1;`WU5/ ;1ұ?}^]zMLeb?f>N›yo;Zȼc1ob Ǒil$R ]R3Z[@ܾs] :D#Ul?hȚl=$t 9ޞ}ŃEj%4ЇGd׵ _ ,bѡC?Q* EiW+Ip/ljz'qw[Ϥ/\L|e3m.H(6f8~$cfd\"jjW"DUPŖqtS~+VcAHaBKlwW7J+M[:u!T@KP`x.makh'-#3dD<­IvFqQv-.a%9DfI$R*"\+>`l/+EѬ8\:zN㚠te}cZϷ`ԪM{ |—lo ؜[-u ΒbQ x`ELln#P詶yΤL0EeI# vJBz:;aVg4^Q-JmsU͙b~RȤѝss98BCu>[!?\vs_Pmወc)rOYJYu-8DJ}g C|Y!n$w1wF1'u)w3N/VVJO$SnLIK^ic#Vo(ŐpƵxu6:Yy^ؓ]6qcAo-mɕ0R ذ65~Op1ztDŀ ; yGf m4X ƒp$e)i1tKIZYnK7R4Y& "5%}OU5wA{ZHf82&=nѴWL[3@^VFLNT|V phN֑[(MV eIu;12891,ZրɞŠEr?N-On1bea 2S92p t_m@Y/ZR #{(!dbu'S_ЕNU,qjvW tT l33VSIa&onb.􋝒#gjC=θQe"1=xRAV?_ZXH =ܧ8GQ4I5?l5^m~"6d~B@qPKy^S֥Nȹz}NzLGj, o"SBq gr6Y,f׻Eg'È#Ð<]Λs1`żD̀&7WImI8_ƹ^CW`@ros~Ҡ ۤdVV!MoZε{^;.B?ǣ*?4$jژ)|W.E >%Q1OMQ3% Wq5Ēw^qzl?Sn^N -*®FYc&[Y,JdV+]uX֍QKx43H· ̃Nñd5Ș*lH_zysa ԒKzϻϗU_MG4ϿgЀR֮c8%9 x#rR)㝑Q/ߜ[POPv .T #d"Xx 6bzŁw<& ѥZ~UFk=.ew:_,7ف v!oj63@0ڈz~Nٔ9hOV[{ `A3O ӷ s2聋m0R:Ԝ1`ӬFJ["8rXQ QǓ@o^m3)x^E86Ǿ+i/s},cvragV O0`#'1sy@%%\WQcǀZw4w Hf~ۂ2e9U .?}("Ȓ>a[dDT+ԪUQ@Np1 #Y>g_mmجb2e/[z-7 <2ȘwIu* YD>9w\Thd6$/Fb6D $I[.npn6@ r;Ec?(VX`Sl(.i B6V yXHfzy^i+;}4~{22~X+*nv Xo?h[`Vw5uoodyUq,=|[3hg˱ "sڥEqp{J\ `D i7*X }ToO&\W%T!Bs6!Ov=pv!Q\\g_Ru ވ{YKZTӝo%3pHJJNL. +^?_ ClRgKȰqL\N'Yj#e>F;/ؼ>a}*dWWZ8֖dȓĕ N̯"'AU0DlnC{ugUa̷^)yL{|x(cw٭'2O{-0}upVKёj_F<^7da;s ڷy|b(qQ3fpў!H Los ]j4;܁/4IDSmֻ))AR;^'v7rPRԮSm Nx? &PXb!FkBK[xCܤ}[ \Ӫ,~2N@79< n/ԩPe !)DDJ|\S%[y;l7YB wt,AnJ-q]ajg0LK\䩝O2Qۀ {6)UC/ zQsKh 9qӮ-Sts<l̀?p`yhؑƶ&]< &sXR4˭qEf̅"G5{N,nMVZ"~Xs7 LkY$iB[x:LW0{Fޥ0A@[ַE TsqG<x3GawFs(\'9CrTPRMeX-9#[}Sԭa0>`ҢAO||4a芖~Nj]KLy ~F+@bKleT]z5}" $=;P#Ĭl Yo.Lw6WhՒ2f^ ^,H/,jom'xzg>0 ,'gmbg1[ymKX8lqsOsC!#k;`λBYT#6}^Š5: GNi(PӇGM+O`u<\+0nF)d|MqݵogΕ81X3-EROQRTjfOzb 6@.E YJ00qGb(xg8N"C]zҠkI݊iPEes:l:p~Zh84{mZv  cRA6 6kmjZ#!UEjݙ߼eߢE|VNȌUSpmnƒhMR@zrL G8{M%KhTne:?>ʏŦ7ag%1@ ab2@)oa}G0K=+;.$mϷ[߮*ֿ듓 ;"y '3:N7\- %%EUܲw>}KOGlh4&U)'dؚͅLd4 wD >/Z)]~3-o)/--ɬp Z(sS!KTrȷ ϵJ|&!{e89rEG7M>ZG G@ΚV%RÃ),\2"r7^Lr{J67+hG6)r @`[ *A$*JE9oo%ixl15E3x&dQ S,&,9#t:9Rzs$֞ke%q~3~;dK=`eIs>j I7(uiڄ^a<DAg59'DNu8<LTH|!0G@B '폙L/%@gk?&uI HSR&C/mz5ଛ8]TS^"b~}\#p'"%JʘP­s]׬wQ槇>0J  ݺ)ȵPΦqcG_E1U)}Hs ՞K4<({M x\b4q*(;8nWM{M1N8d&& Kosf2F/Μ"@]w!i+ W)áe(*3Ld37 @@vq4 J,z:y2lZG9yn =WknS%?%1V .f *ԉ4{ -gL<$[y!O{:kz+چn]I7k}H76qŻ{vd]jiЯ^B,/zJȡ xv2#;DN*k%+~Q h=`zuSဝXOV9TiF3:)a iS`j>@1-{|7zyo/H8  83c 2ڜ U)LWT/zGPSLko1:W^akp~b 0#06=Dm;Eǖ\3W)贗n=,##!cb|KJKu=Ws&׀4MwΒd4|oo=_mO4Ukp1$K>dzg#RGIS\)%,5b\)fHddH*˿!^D.B7"c] ښ.|Z W/ y ibPVx}M9 -%fK$csƥv ֶ<jX|?GWss<V OK!ƻCEa=;3'lo⧼,ӻMh:hII 7I5r~T].WѺ0#V=? +Trn3`:B01iޗm&s_*`԰=n>><0Ol,ӫڠ ?.\yroٙKg.( qynopDPƎ!O o$99O\|\F,1v3o2}?ak\rrvh Z:l*DؖAGנ܂]n`盟Oߌb}0#D!<,@偓E+Pau+┢"yr%@ 8c<&zAw07ۯޥ4l9bCE}c$- 'SD9KB1_[9EE`lt gQdۊ=\UnDY\1*S";]=5T^ζKq~TqŒN^`I@v5IbVx7IÕ_4%H\4y{[ɒD9 cʧ0p_^һ5Um*`?EV+&Z^)7@`CqՎ}y \R}݄qʿz zJh //%[k+%VЛ=dOtxv8,KA<.O4|;$݉\~r_ԫ}2(\Qנr"L7**hj=H~?I`MϟXmIx $}"o/GBMe `(\acAI*LҸ҄h9Pt_b6g@Nv#] 3 M|r~=XO1n qd_(Dž֥$Z_2[F-H XSFr8YF1Btkh˾Vg"½H'VǢX_ᇉ ct+,ŒОy, P[=5%M JMHHQg*mC |Hˁ~tY*@ A&pՆJ6P.4c}!qHl}ܻ[BEG|S5~=^בxTөw<>2 c69`y.-G =]7_&Q#f<tuq`%5ݿ0=.v_;r,ÐPY[>s|KwG˴@P~8M̊=CpHFFFVoiR+or,qݗ̟d`o=Wbdl5"QOT>\Zr$Ep֖4,ơ٪h.ϡz^ *¥ԦZ/6 2-%̎?:|5Gc?jXHܖ^D/Rks|Jt|k$FǬrV#kdҗLfS6rtJ..d_? )8!HU\PcNHu MN7 ;81chN}"2N \??o2_ #$vQW<(DmrHT4]CY)mѼW1pWOay/Z%/}P4ڷ➩;+=8!HWxUIt^;~e_¥=[U\ٞH; >\ΠƳri$#cY)p "_n>܋ց!ض๬0H.9\ :sg\u/o`yFVe$~nԅi=WDpUd "Ś 8Ϗ~med׀/rUP f?\\VLi˶L GZ4X`;Tgf eH၀ObLJPsMC% 6_:Nz-x"F7E*|/dF_jUNKQfP5,ρwAe-ƌbQTtir5L%-콖z9f&~UZs (ȑû~j!ם {=z}~/NrڈpP΢pvl+C)U4>iS%+[aN)u#63ȞD"}_f֭k)O)QhHT>%h ^.rhC}֝:-Lt3|cni* 㞍ʷ!>O6FT'}}TB )/(d;\0VIQ uJڦiz.W]n1/[J(tUCC0B s!EwL'{%f0 nyJ< / fi/dQ'kuS|ylx'qW U*^Gg'^}Ep0}Mv2St}m-LY!>DJUlďK \D45y_RpיާIJ{)ro{=/ 4nlE_)= wWszSWvga2e:JO )A!Ыcs)]qvϏXjq Rje)ZX 7!^πQrO@w.+Q*E&cpJÀ+Q,T[16TZ@ xf &hOdQ.c ن;_t6Gk .l8d=ˈī0>1e\PSc *K6Uf~.<ӯ8g3 >^ ӆ@?@9%x1Z΃Z6!:TL7h;z#vKGh(iDo*N=+zMjߺ}`w5@ΩѢGx@ G'C]EF(^2t0'LD6ut ^ɋlc(O9{)2m6 -O'Us`yY*EB޻"̕ 5l|E#OUot.4ekzo2wsâ) V bVw&.܏KφYxk^-3OqM~a2EcF/Mg@N]uR4-FA1$~c^!H&~jZIBWm1}wQUj3 ~P9ѫVx9Ѻm8ڎ1_?~ `mSɊDI7 FXEBQiU8-U BfQK]31Truֲ7laˋފvҗ^>$EuwV]v h[:jAQOU$`Nh @=bS׷zJˆۻLV ],0iiM@,'+6iQtW_pn` ?ݡ:+q-fiiJU `a8T~ѧʟ˅Zܜ㋣#"g8.㻚' ЦtJP 4+#؇'!M(w`T TL8[.-"&By>;"awѦ{[rL x>f#ݷaU_U]ֵ9_Eu.l*h D^֦֗ [`*|rD9guhh2/E>jR-#Q+˕hvEJP2՜~MU Μ^A_ҥf5ۢ ?Z3ayeРwD*Hu>:Z,wmZemeKU>D7?&!5W5>U˰ۯe1\u4*W,HB[^>`JR;Mfk[dNi) 7LpqeNW!G n0(sL$+;uIt\1MvLY+ngm&k7gE4O9 w7 HKyjhBj hs?h~6u5"Jq82.HH,aI ,.yy<.µN.$S '3"EpݙJ%yP|<D*ֵf;(Wʀ߇ZS %So6tZcwa6~NA^gB@jɏNWx\l;+ &EUtL1=p0#WiiPkL#e!a0u@2O63zty/ڋ/=eG_#ռBӫc}N2gj²\ѣ.Ȅ&RiAZ"V}dFٛf+/旌a0xbËZGNqƊG10:;.y_Q~:DZ8G"tXpHtE.ޝv @͠Xce>\]+ Z\ ^H 9'TvE78\LtboOVPʹKT`[MؓQJjn(g<&U%TV,C9Y.W(RXM:Qh 8 PLcN:?Z+]" xNj+ڰ%LT0Z|St o!BZ(o}Rt@LxE8KAá["Eggό4\[;[Zf ǡ/YfQ ŲmjՋցS6!NNlz*va=JwƬĄUXȯk U!W^![j@,"2/dV>ATco3+keslԆa\2 RhnIߺ:I# zpL9b綜kEƅ=>Tc&tԩ 3y5b[0q޿LtA*F$t o&.]Aڋ 2458l]}ۇAhD^q;h/yhպ ^OFz1:9/T{CZk7vdԝ(͒WUEgx&nKLE=sp~Φo{<:'@u8ԋzXP:lY4'R"`(U6i[Gjc:&"Isptq,؝KK@VPwKX&:^9Y)’0<͛mrQk4|\K |>Km\0:\(u䧱~l1;om0Ek^|~Q*&~ 4c*(&q j?ImSoC:dIyNm.$boY!<4u:dJҋ,jW^^3U+" tItTxĹ4IEvVzdneH׽}܂ḩW𶖱 Fm-1ܟ*s=Z=ǡT4jTǘ*~Llqp$1`k'w:P:HpAOP,:m Ԡ~2^&(2ZV wAóvF*ۢ3<7qwHv9Bl)Xp9]50gSIkj ì٫Jf'r8]1.0Wa^@ƹAGyh XW  YK䓛uՑ_ Ή]~%Pණ ½ { 坡o^KhQa#CFQ:(MeHW8e &=Jl''_PIM l騔4IJ P57bCc FutvHKjE1E޾\-m$Ȩa\/wWvB< 'S*Y6I'߁Q`D|dH-xeA =ަ;$m6%FrwK;yY ڍQ@![J,kISWo&K"GA93/;o"|~Np_Xb(WVGca"ݤf|₧S$HSb`Q@yI^c:H+~.0ݜxb>6.175e}**-!ν@e);oCm%Zii0VrZ/k$\KBlc&[yPm~GJ˶fI#"Lev5P2;1Ƞ%B߶o ; ~ etW zcDdAb됢yI_<EhP|uO-Kt^v²QڃxB|nY`[tWvR$n#sקW 27*;!l3?eo̟+-zk4eݤDf"2465Ꝟ $Ce QWG'|(RZ@LIq@ݹZ^ :ڔٸ m}fP;æ !nv64Jwa{(]I1{<@[͋Y6Q7Z|^'ZԜ[,PY˹ܡM엩944/~)jG`u[D?ǧl"S8 7S҉9RRvc t1Lߵ<Ώ{+eAjHp^WDzuH)2D(sT,IgQJ A(tL* *Ԛn9^ȹ9?fGjNE CG<Tr 0ܪ זWqA ,y_p'JyakؐDeSˍA7b7Y[G¬1*qV]+MЫ$ @c |(息e {(Z4.|Ȓ8!/w/qpj s{'RZDdަrOES#x^$Q<4Of~毨Y׬%_1|7 \k!_:=#D0<\.[>apc(ъGp]=Y~}[x"e w7ɴmۈS[N},m\C( BCmxs|b( A%X0{Z"tGLc: >o_ ƕ1?+ʖ,*X"z xweVs1`B&?yIe]\R/~ i™|*Ʈ$?ËdxȢWv[Ph] ~yt~M(kȡeD5HsǶRxKr5i{odz5g}b('C+:Pr/D<}=V"ΦgjlbMK@0 V oNJq 1M"鍿ڈuҺj 57S*2DRwrT?iv"M*Y^//L\8\ `$o0ੜҚ?X4%łdiCZm[KzuV D0X xgNd8}覺>5! ncOc.>挢jAJdY. 3 Qn0VTDZQ% $~`P/>jPF;S`?./`$wpXI&J$k键ȝ7_+&b "mSĢA/1ƨl|j@*1ems{O1ݔ8%C+7令(E TM} m ~LWŠ h-JP6yd UdkCU JўޗY5!KW3Yuuk\׮ɲN,Q"rY-q Iq5eZBvĄ>_)qt'x]PMg<M@pcDB?eM h0U R3#-1|aQ*>wj"Ǩ (+9+9 `mXȌL<;xuD/!i^+%C3CD ڎԔj|K̊"BF4$\hQ'jS2ZW{Ku]!<`D2izYIvl=3QS+}iZ94bNeyx^ s /d*;bZ5%FknPvs__ۏmwOBfk\'!#`|d] 3/:qPcR7"4"{q2B GW@N]`$87Φ/|wlQc-*JjCM0(|!jNjxOKE0olfzgҚIOnM%6= z8(įgn[^a k;`~~O $#g>:Xj{Mi+ nLƻ(~P{^ssW+]n[o:(zo/ve@O RbQ5GZ86T |?)?,|6*U=$j/@V7IFvDB1}c~ԤRH`).te8?B0:,NU);vO\4 MZ,x{lLoK]c$8aL~YFuSТausͺJ(/ islr"e*M z Zh( .H`vE%9R 3x`c7Q__G _~L7,ZN$RiM.2*}\K,?#QpD٭%mi] Cu/G>tOqUsTy(<^C{6%< 5*ur"`s՘vp\5np}m^œ D8u<$ /;R3b:0[ ʑԪ p\gcpQccWFt'${o~r .wahsb*8gBIl$6U|ǀfFoJV=)Q<>9ŌIغ Z>*8͹.Â.E?\B)cn"k~|;M;GQu/'L# TFKB@jOj\9J+;x;rhRK^%լLGnfg^x\Hg8WLE߹j][ZbGS g=3ަC?r_.J >fꛮwz)E֓xћ7Ͷ"wNlYhڎqqGȡ1>%Tȯ_g s|vSlΩu`Į^Ez0^r]=ޜ!N =B1E^e>HYA{T&r'i]; =? XsP,Sfr+~,עA`ABs` sF楹HFRiN k_֢SggA5M 2hfNB,z8,L=Ƈ3~5{,q\2:fSPsn. B,tF Um*RBGF2ly1 DG}_wGWÿ&Jb zPeieJ/yViDEDY/<ȴ'~ DAFpصT7d f~ |A3* RI*߯/y\O H$b6Q!rͳEr$L{Z7R(ckc'wNm8܂K%  ]P<( l>1ݷ@HQvB Ǐ1Ff˺uʪ!~/ԴZـmj$&e(RO|=P/3.tV9gGJ,CIG`|+g=w5f@{ e]5-6NV֒#c_w)d&3{a^V_bSz7%Qq*0:./g_7-#tA<$& ۮi tS񏲳PVrn1{LK]DA98AZ1;:SnyKزƢϺDž~vv q0ܞ? -Vꑨq+P/Ti~l;؆}^f c"{m!/Ec+R! ^6ݒ,m79 =-kvj0=UQ&n@-`(wlc24;+C7$dyw>f{X` hGhtV|;SЈC)H$H; _@bQݰ4 ZRgǺ[˩OnDT81;#=zV5Ve}@?&ֵ1yh5Y+p_N{~JF6GE蛣ug.L&eup5M0DhB<$׈Q4xXjЁ' =U~Uƴ(`^u/WﴛG;H^j{+}a#2%7 l&Zk_`W x5Yo ="׫4&,) ;u/ hⱽT1scwS1}FlUa1l?wč3ͳ21Hr_Q) Wۑ>04ޒᗧZ jҒ7EI.B~%\ҜxMɭsfS.(‘wus;O~fԘ}Zv2k}&ۈ^"~j4xxȭ`[ cgH]<<3, IJsm%ݳ gC'5gi{Yyj3ŀP=[U']/;π>$Pan/S:#b>5?Pjq#xDCzk g{U_>u;TyU_nEI|KES:hC**6~hW삲5ɜzӝ#7[A{[~e4#F*%KarY >6QE%ReP r"^{ZLrC;JQ⁘f4'o;m:"i3L-ȫ=y(%~gC=hv )Ev}DTƔ>r,‹v#& 8{}?JT4蠈h4yAZvX{pU[?Dƛˆy c"DsViou>]n>Z$*4qa+`aZsyϻ Կ!Hؘ딬P)XDf^8'pP.;:qPX4Txz7 ч;,VÑ<-+D:uϙlbޙ.td?:LP&a!ifG;$ﵡ5YF:ýMKQ;,c.欖@Dcx2)VA).J42>}5q:u7T@h@rx$Lv 5FaR2U?FTU LbV̚S<9нI^7IBҭlUS^CjD~bz2-5+mGNEn Pg~Xc?=_ e]i Dm47YMUaW1 /3./b% k a:D3YH]\E/kKRxaC~ ]V70 ]:YowɥkpIْ]=;?arͻb>o]YQjHLIʒxT$|@YN,"~!mJ*򉯀8C}x%r, 9H!V;erTMs9p2'qDYT0o2J\ pb{g@T)youOIcxPfxfr(;*J>ThD`Ʈ\ꐻ@:՜"ǰs\N;?ã~,UyS7¥G|hDyQ(qʄ-XGsǜ@<^6/׏G (F5#oL: ÑB_z@ooƴXlPf= 0i7V)ēy]LlPVG%ݲV_d^ͭW}q&Hlc@L_?oeH$PJ[AxY7^RA|?12 \03 N";hf ">lwW_T<_Γa4p !_m/׍.f&rU&,j̬D㽑MxneK*~G]]GAd&_wZD0YN&4ɍVy- Ph >1wG{Tv~l|;uc^^""^BidnMb/Ԧ ;f-wf5.@#)4&kLL:L9 )1.?J?̳Vni{~ %|8y.8! fcdSD8a #wQ+%4GcwF讫MYvMG1N7z~^J؋ċQtFI"`0XBVc,` ) Fo8pp 4G PS?TaY \wj4T,`i`JdjɋY&6g7J Ɂb3rI訛/{pz{VG:ia,]N xO@ y5]sW CCs׌1T}) WIYARViSbfxF|07yކO# &M<3?sj4g\t@S% R)x $r]k=#Y.'~&T߬T0\~m#]>Ġ/9Y0ز7!"Gp$ d8 Tn !.kзPocD;# l2Uiwt.* 4o5'MsL?dj R]f G)WZ.INYp0"0X#_o`Z岆ljۑ~a]Vx4.9OF0cӶB;&T,:`[/htjf_x*b˺5bQ>Ίj G[ݭ㢦3c9D`(E jOB-%"4d 8R7=2|rq`HjeNdȷ5@U`RXEw.jM^s(u>Z>vk͓z;b/>/=F{qHBau .=1ʚxzZ8_HI|IjHi4~J xj^7pn2xf idIpk|_7c"@kSMlt'W+c wgWa՗uBkۭٞ{&ek6Y3lđdPCK)*`qXa`%rGslnι/pE4=WA:F5y]! ɢqۗIQH)QЛ{d `jfSRgY˭:mנEY<6>>{vl~'FX A.U:B,{[u_>xJ+2hjv5>>ُh1eb3yWou?u$Ng}"ROwc^:07?`Y՗" &F喙ve g{]nQ>xލ3;ѿhN6W]sn:% b;t{89б3_^pm=g\@z74s;O }(`йIm.?MbMf˚^<ܒ\B#67mm|~)LorZ? 1 Y&vwSQ=Kp' 'ʮ[O>iU-$!H 8ۧΌڞ" }"Rwq;9+,2R4 H)#v*Ws{t&hcR< ,/ /@ϟ{-r¯ukg9ƶ?GZUV9T?87I>v,m &ҥK87; .lEҍ#̺>hJ0'"J>gWWbF=uY_Y\}ûU2):#5]# ŇbTCzI1u!gNmٝ/\=K~ X-eX]L_̗e^ssRis,s~H}v AԴqQ=.--ӵf]HesG\a.{2 n|fX\ѓ7bnD}vqd#Vs%ZFʮX|ւ:Lmu9.\V -43Հݭ@X233YL7#R\>GjYҮ /|(F+i@Y_0?38xGPǛ8 }%#A ,/hR0Җzǒ<=X@vjX8ϐԙVUSJz64F]Se⇌4/psP2 Ceϋ̬s#!в6x}=w(_}!s-Eyp`V,WWѮg1Pڨ7gKzmB@a ?t 5aDhc1b 4S^ L I cr墌+F3{/" ě!"6AEBcb-ĩPgN mH(bG veﰐ ¾Dھq4"MS&v@^5#MG2.o{4_o}B,%VT ;S?-˵^s}jOp;A, WCmΡH}JXN cWVFBeZ*5 h50o+էXEN', TPҐZ;u͞.sfA`]>$=^QB;lm:j{b <8 נ.-!O Cx$fCSX'K-ePMaRA'>?*>gnU%IWJc ؛1Y*SKW{G)j o|_V&䨭9c7/f! ^w^ N׹NKto'4>PXnͧAX )PԐU&![Yv 2/Ak۶cjӌYBTsfCZՖE( o/?4d׬3"3U|ߕ\p 5)(>V'|+}p:k[gmeC;"ٝUaQ$ze7nN]D ScM*;  ' o X2OzzAeU 0/6R$;4s Y)e=ceVXۊ׋$Fq XdMLc[*,;^<$ pI0wRBpT<=]Mk䜂(J_e(g+l8ZxסH7Mt*!ZQfl|YF[uKq40Š!:YQyC?T!KyxRT 1=uk]0'M͵&MxW6ky15`6wߙ7kYK}ƴT=XiX# GyLۺ'2a5 2V:[_QctTBy*jQvy|8MϧX'>8,aa6A?>iHdco,0gԆӼJ;>ۻhL &/J@+Nj^=ߖ7 #6'xި{%ˌUOH5+{!~XYC)ǍR4W7]aO|_ke*Zj4 \f<)m >Xm?d3/ ]uy\>;m%7ºCP6>_AyԞ+I<ӾY{s)|I9{[!.ˍ Fjrh1{!UhPt$ݟ/.kNQP`(+PxMFλ* 7k l_v%W T$l~1V]Gi^tk7@gv:d?R;b*NCq ~-1,A598՚#6"zFͥ dsCjzPjʇ"A( z3Kvخ%ByΐNᔦwqs] !Ɯ= KjA!0ΆZJʓqlW2hxU!cnPܑ94TÔ;YWg{/E B2SmtU4Gj6B;,}U7`tF:~ltʩ EWw4Ž n{<.~62:k.JXAB4$|P aRʩE}k E[vΑZ[Ccl*xQ>,k9J Zԓȑ)#! jGF S-ؓ(7B__u9aRowC2[oi5 |fA;-.${IL9644/:ѩyOZa(;IAqjbBY)l<'. x?Oyi#YY]Y{Y79##+3S&Hג[Us0q{9U: ZrƁ "߼IϿ8>؞Ŏݷ?2e}8٥9<=e"{2j,D1oT)g)J+t7Y$O߹,{UPAJ 24Tˀy䒇|fOWI%-5d k|칕 ,r"'+o&⧺t)O ihk~#'C1%%АZQw cۑaŢT)G+@Z+8lӈoA) ws3(wBiÈBJDZ%ғUM \?;Un=G༂ "~DDZ47Oq Pi(NAC*OTfU @> }*_h9YW.iaƛԀ3dEk+&m'ٚ3n? R ~ pG_͎ў!S/k1bzz V5t;ZTXa+&xe)e xկc|}1-/<^ xo_N&{f0ʟ!]ao2lߞC#}l@ >tj BnE]xiɸ4 <> Є?ʿLseZػ߁ W 3TcUċ꭮mH/), qAfn\cAvaM 55hE586ylA?ˀ@c2VڪA121_xTT&`UoFl(5)7ؘSo_*tO=qfVT_x>,1e4 ?ђDӓc[+eeA]$' nW lu/'>Q%C(Ҙ).ڍk!*U#EdR"Ĩ(?+%/,D DKE4ڕ zNi+lVKTX>sC)HŒx=hzFZMEѻ\'\SA%Hn2hEX`:Kzƨsi%mS|E9jh>jw|ak4}}(|, 3.//zTUV_*p"AzdlFpI9'Y@ {LjQZZ9pB7 |[2@Cl ^z(B2s@{E \"x}Jnf93WƮ@ R:A2]߂  yAl2"i#+' w>i &ECqkm/N kSF[š2_a!7+{QMxy4Rz=$D FzܮN3`HP)9됡θfDY*CԶg78EfEV j(Aџm̓w2qCu?L!U`'7e?E/`}-cwSc>/{*`c7S bz!*HF?~{,m2uxS%/$&RzwB⑂s9>7ͯڣޭB׈V; 7Sut7 k5(7V`\W&̄nM}/\ݷ(5ttRՙ4p'?r!'ڔD 'ToSzKsN57&d;a9n-)-GVnQHwv1Ubxuod [6eV:lX9<^&i:nJQօy.U8dY6du\RdN12:$Uz-[Sl2d%qZb:Gb&vZpݲ<͔ξ ^zӞHәX `DrB/_~\(̗ш+4dVCl Vyc{3;{'4?}NT f'zaeEEY;]喇 "D{P$rJtg9o*w*(^&+*AFt#YSYx *I+oڧ"R<! ~ 9P#R jf [Is)ߣ5mKMƾ h]!?u1>#p 9{}6ҰQ9ԗf"I>4R-0.0ZFzy"З99:.>CSoz6M{ǥλlЇUlWuh(_=A?T~7.Xe:$^;F m` =8΋Eç:"ę f7zPBW-975k7[kn!T)*=@^yS͜_~qd́J V_J)PH 0X}X%YDoq7+YÆF-8U$ [yl'r_@֐b8&5]GӍ .eW`,o$V6ҜV^@ cwܧ/A JuҨd?Zh"e.bV(VNfiBS C=wg֬6WhPyl"ˉg'gϔ_$AP3nK㌐~ FFfU=ijwfjA8'ږ$p3D^޴ 'Ҧj}ٺfj"#Orwe$ YUƛ_IE wo8>tE/| kREZG-. Sz9W ۷^.bJW>(Xk k\8lT#DNfڌ,i]#_FY8i Ldh"gX@6#lG{2jY ) &@.}L^Dهo: vHs?'+g'O^Z- m)l cO`oЄOڧ% Y7"=-M#{;"{dߪDʹH8[@ ٱ<$sV21ecP>Ig<1z%QMn>="+ͪ٦Q\n"6&rGjW≉^9B R ^vc?IȿXW&DTpA/NB5q8, ݓF_Eˡ:IJY ,C[c`5[+АYx_u9+Z_0gJK< @,-nG K#d: mȥ']1{bJb᜘[Mj#b|w#L|s.-))76`aSIl4kAWTh4Xs!mSȏH?FR3_h|6s.8"xhʥ&VD\aW_;ٮ@noA)X-='8ko ÔdluC~4_uo*,Kb G3bb W@®)a%\`%*+Y{AM}gôL\U扂z8 YH.*fD.c<塮[L}o*}5a]xVg)_-PTxrzJHԕMcą_ uA@V3l-R#|gegQT?M6{\u~TBU{{H^baԵڶ̻2t>\5޶ؖw=`G6. d5벓rq6E]u~F͜q$76swVAM>rEuOp# 2AWu(/aw93lg| T } HP'¿ y4ћesAk{O72+գ֤-Vr'KYLAZ kU.r']%bbg:7EM9`A 趃gR G.} efF$iyi-2K9~@V#.$Imi᳡o4@/hlq*R+(w7x|4mE 93z._\|ŞYvmFmU ɕ_FgfMlRquOIid!Fߞ+I\),cA"E~oP0q&8tjh;Q'éX.*5WBB U@>½[WE ;n'j _8I!یiet@['Zag"s%nq\jvU8D< 8-FgOֈaF:ݏG9*8;rnwfUg iptq7.txq>BiG=^L?ˍx>)PBn,*A}e{' C<ec>}QkMW4┿Vܠz"e$Uh"/@퍾o}MCfxWfV gtiDI2ܬK`ԏҷU4^~`=1}fTlͲlhف;-`ds\x&:束r|m?8_&ǼKIC~f9PbEUqeHoGH%)N]iih{_6Pͷ^x:\)lEaz(='x4"+|ꟷ0K醧 k-UWL2?|#\B|&b.hqSH+Dg 66K:$|H" a])v3ٽnN="_03wKwOOggLE`ȍ8C%lz@e7:ñ%-)Y}A x]\a ؍l䠯eI-LaƌjϘ7I^,^`7Dc߰ʥY u00qh%Ȑ4&+Y=P, \Y mnSJ޳AslX_΄bS 8EMpmǭ==֙gxme1ABv`o tlWI9' { Edε>H؍xsZFv`\D/dN%%'Na҆&(j4Tg aa rv Ğ=ٴ rX4t8}poTpHN$_;'OG7#d٢#Rn7 ͦ+-OAڴ]n mRJT[:͹/Zӊ0x3(Y(>@60Co9xrmhIP(7^Y3D{š4.qn:wsb [(](:Ipo;t{81!LD<2K .&=l _TX":^H26' ۤFJqƁwXݕAR}vDvruumO.OhԲ&)eؼn%cA}/(9rd.s0Q!a~W_]YH%T =3UyȬ&}t`$j#f񰑻]B/P?34:á/W7VfԶf{|5@p'Iq] 1$ξp·CvnfRHiѴy&kl'-}L{~KGS̛E ;: @iI;%BmxexMUD'ʭhf dٌcT6Mt%T΅?yCUz69Z+t2RK ̂G@sݜHZ\e;w%)'DHҨ>ngJr}y"UB&6 sRFS 7T Ìt?^jIN!d-d \[dvǜ:\4~1~Y..pGj^ղD^4/V0qߢ13#̠^yѭ@M }&0U48ȋ(2ޓ,)#c,ؤUOA 0U<\k>STCB]g/#<)gq)SrFAz`mqC{KAsɮ%.:ZN *pOT[?ȷTeN\@kmpv myȔ&]WiC{Zmf47d/4 C,Ϙ8(%d$$Zn}cRɏrݺ=l 5x6IgׅnJsT`$P4fd y(Z|Ab(&WPڬXT[tJ BLgzٲ}~4Pyw6>\BqOi6$~WBu\ v8nUn"؃9RN(@q8.g98v>>ֲ 0nJKRlqYOUq oz"UAk{=9=.^ߙñF@ؗ6D$@ AB)&]-3ܛ9;-@DSH"l C $ف/HB,{{z<'.xl#O%ÂHE2/_ZX/{y7XOb>:,55fbNAȑo<`v\§~θ6̅aO2Qa,t*k|'% L󑆍QڳDSPF0xaKVl .mc.t*A4Gd$m<V 2<:#N[;|?фd*\Ò6yƯŸ0a. ǥ5moim70.7xLJ( ĥw1 U($G6''(Β"pi5fR#,ɌT432c6%奆dY/癴x593h_<(h,`W-֫7<['.&[n.˦ '"{0rXNNR[;E߸!N`sl7Ij|k$<P0`ȀGa}- V)4AcvsW#!ά>8@Г,/ݣuW}  Б&试IVD &03=vPK5;Ob3G \LA`}RvDCļ0ʘrr0%=y `(ZUpA]*x9 ;9}Q xªk'*t 5 zmG.g )d(YLYS@,j}XR7ѴfL$1KAJ_66or6$_hLXXygAOvLj>:'*|tGbWQfƓ;RiX1nVlu3*>TuB`  +Q8!׵! 0z˅+rwrx7沒\h0%=?ճl .SΊj8Rh+/Yj\ZIG+ؔ?(e- /H&YF@8,lrKZ%N`@Sxوj;j>oPQ@JzOԦoOpI|HaŇsqojv4OU''u=2/]n~Ur+/Wq>7 VB8B N5 )s>TY5z5-zIPL]]¥Lm_w͘U5bu"Zn7:x&ϋ~Lq+iBpXǚѬ]jvfyotYvϏUW^x<3`8$^&문g:o0H`uZ^X A+7Vl}\ ,Z]<,D9F3K$w[k P[S2l0E"R% vVt\S0V642/K9=sN/h>Z 9y SI0AT12|*MBb\Yěr}*E$#7YT ė{nJٸH7{)@Q᮵UJ^FuE[ =^Ʈ!bC̗o`qR{c(찝xxll++]PH=($vxeT _\^g}Nv Zi }H}00DA ԻvzAh$*Vs(fkv Ih|\Igg R BV]9*n ;+%HP'aIRaƽ ]Gf;v0YT,E-{+`gr=3 v̎X}g,wu8U'c{WNc1cs`6 t˵{$t2ج+F\QFblш5G\/Oi0{p6a>.W[7(/CZ]Co dWqQlՂ=]qax>ɇI$]}=HBS< ox_eeLJ|6ᗋ1uΡn]ڻu0i[\[qnGk-ѻv.c^Lh+^DԏJqK>1Gߡs(@E +8@:"gȹ- 'm:vyA,¿d@mbi6t%,OeL]/UI XG{7 h,sĴbąb$2ܙpv#M5o3I{u%}ïQ ="2W[WzDȞcm 2 W~+b3t5@r96% ƈ}#6I׎읅0/_]% .ʪ?'xi5<,hRS hUvW$m )3VQ 7Ʋ?2F72SoM}&BXʺiXbY|qVbN͵‡ʌhMa]ÿ2}++2x y`e>󏚈D]皍Q2eAcotFHހ_$+yۑ:=ֹTeh,!l_(촬]#yK]2yd]%,|dLuO$XŤ;tŨgCa](M8Bo.4'U*Ή8&XRIex>xξqT$ʢAʺȷh.9N&N@,i^!c d<˟'r$7aU!]ha\.lH[WQ@J&V U4(#ZG_@ntKPa-b@W+Ҫh/rP};/b&4& Gv,25b@hTjݴbwN%I{2P?,aaRaer9I:Msc.vAa=azshbI,P6 qoS!䴵[N, iGA6U?!!ZaN Ϲ3@ܴWcn`׶rh}x_>ޝ^-^>0zW{ -8xd7t^֢{55;s/_KTWKƦ5w?J@K1=r)``692?mChN<8E2:D"g,6DlRzcmz{J*M"MHdi;yjvAJ@óe&NsW86H} POuWIw1sЅ YPDqbe,-PLxV?F >{:QI ܳC7 !!sjͨ!ı*C<.#;S$hABA2`Qc0w:L58M5$8O( Żxɨ8*Yn||Wy0L(Bt@{w.| *TQ8ے5P*nEڮL`)Wmys6{8T+zZÉA eG(jŮ&wQg+k2|KA˓"-zmnRˎүDva~in<ܹ-B] cIgD3j-ubQ1z֛XZjhEF9?! Q =x9hlҟBzGۡ,]LƯeMN=vMJ-0gwM mk c:s4B7EYYP= AcgDN5"v$\7r'FעsLx3]oߡVФ̮sxr|/hx[^J'H[tFtGT`lTN*]~WFHd:;FqoMk( 5DϦ_.t8RY"Eިm^`᜜10 AbY*9W&t}=*Ⱥ'Xl #1[ؐNT7`5CqhH Selg6sފ U{)tF=GVebOi OP y]FWQPp_ε|A5^y~ώj#xC'8 p q[yy=$_ar#SK$l_3iR)[W `<$k_e颓C/[mzfBon/_)H/soF^l41(TrZî"Gr.4N:5czEj!􆙊dCa6Z,~ DyW n)Nc^^]pږ~BDߐ` )N; bgB3ǷlC\f}8h'x ߝ9WT|˯Ǿ{M-̋@3ۏAQ4t9J=EaIqV{cK >gn{˥)^K֒d4Q\h$6V%kKUf !|Fvcz%|( CoZa ^ د@*̣f"Hz8-{{ijۣ쿇RݝdO>O|BAM2bvfK߷e^.]ݖbw#M$X*FQ$1+}lVu^T)\HYk8Uggg#Rg×UݥZ$/_gQ;{I?,pY$v⢅%̈nlrGu71K^: uk d:%r'e ܃bPs5t*ZL~J y#+00 0촫mZ`Oxh໚2axR J,G"[_tLj)/@@A)@iئ!(<.T0dT'ڥ-@ N9Nrdx*>N2{gX3 Id{,y$uNt*Y+c4?LwY)&yU0uTŒ~kf{ӂj2 G$W GCa_"r@;h%3zA*z@}>Ң/T b_0|>ۊ<Ó̯b}\wjX$64uݻ vŨ(NgU%Easz Rz~j/dtU'2)%S'(h $2J7`4H5EI۱$.31X)jM$ ݿ(#3 dR̴?xəaO=龨 6lRQ - 9+}YN؅5|-me^~Ͻϔ8HzZg#*1QpW؟0ex%& MHAryKh-[Ȍ6@9o>Iӣ,@&*(lKVk> (cmy:h6W1Ek5f-v)pXٓ;s>X|LNttzI| C_kn'E ܪW5/'mzVCQ! "l|T-c/5Fϼ1J$h*tؗabF֧܎Yh̀cie}ظP-ቩJ/!RFjV6@3MMy?9['6b@Co@/dSsZ]DuK*3,>((F'T%: !v5Q_xӻB%NptGVHpR5Hjb3G*_^c qsc/өSK3ii@vn>DfJїz,n8R1~/ d_p{Pxs;g:]O9;2Y-6ߕduuMĥt @geo??ްcƍ ejTђ^29:M0cͨ{ A؛ >?Q"&0LiuͶDs wϫQ@mT-))9Z$ .Xj9m#$t(12rrIFEi$\]{P!H™WZ3I9Zξ |i<쒟/' qI:m+YKW-Xj W\dTCc@+ d@&tj,DPXEms~C%i0WMN^M3C,9+as6Ͻx-Tz9 5/F)IaȁUm d (Ki/ƍDid034ua CUĉ|p$~ 5'*+3 |zοhrPMavL)N'4;5b4jiv)4mw\]''X)N"# ,^1rG}z;A~nkG17*Bn({ϓO.F};+CPtBuQhVS=-$>XWAUg-Hu2ѝ{-oyAYB &/(Ձdꡲ8!sL3 ߫ݑw [jq66XU$9p>5 xy ev딇 $lyE\7 pR`kQ_ԍܪ2=4p]W_X rm`^tsM8n(QgU!޿~+-rdMhDujV%#LM }=?ᄑTq]>[rAN&UsT>mqŞ>z1H>{|O Oeߗ7%[eDŽGS6sx͉g&cQ;jR ^u d~Nk\4֭$>(V]Lެ@\"73 n,/K2v8C/ZT$)~O3ݺjam&=ޓaU~|kMBF{vؤ~ȪqC2-n {8H&oZ,eIWw()@_x/9:@56\?dM3NX:h\ ؾž'y,,Z!/bQց{P\_>yK!x ?^ oNV#G sY@NGaD6zFC7Tb}? f[fT"E׏yk𢡄dAz QJmS__7єkopj1b?7NoW,R(cߕWOJ}bf^.-d#k0|>8LCU ]44r ,J(V—YQ^*َ/|Jr 5 ^z~?V91Hi+a[R\؄iFADqV\YY 882-ZpLNc 3_*ǘ{[Q{GkЇ@6+4s-Y@ZƴL#cEK.uv.l%_o~7NF?S[/M"bkYwC03ѷYP8C%f`t| IQΰ$-)/PM 2ϕО cQGGRG},w{nMpKԑؔ^.ޘ/QOHv":#ퟕL*\y<}(/lI9O81B2R&0F#p_SCe=O54夈}5?KlH h5s/_ },c~I|>:5C0EE8/cǮPB|eDWBForŪ0yr$ ' hu__攐)g ^V'Go4O((ԒAO%1e2Z3RRlËXSEvfڠQ@3lC v.^ 溤l;':є,H39Ol'h)ː#]1UQ]dd]1ܸUZo{kߤN 6vy]; r(N҈'@,`Q_\BO8D__ sAp nZ^,f~: }kzUe~5F΢n|n:'u@";d>):!D|"1F} UqJ VHtxI4BB< ":xˣ j64҉Q~?85ld 8ov|}Vַj z@WPΣ0ܫc)8©Dž"oS/ ~#a´=N $pYi_F4XS_g,<1d cY{q>,oO_/G󶂜 ՂGOa 0[^2'7\UWOk7)@TWeo>FCj؆^*bwVNzi\mdA@uR*+M jw8Ξf)u9Kv&Dž M?73&+fVnhb l'nXQ m 0~Rp_56؏ *'? DCdd9w WG[_rb1B]9vqХjB4Um](}&B՗9Ep,6ezVc"ǒ"?yp'M ~zxop[> ȕjMAZ6*t A֙~\ݽ<?V7A׍;l_xJ[ 0ڇl ;Bzb(5IKoRXѸ<"F_SlvvKDL $U代o}mםJWֲ5l-eAWa3DGj}~Fh 7 @گ"8]h-kP)zń*+ fo^8"uw#6_rjAg,P4Xi֋10 P(jT*Η v!<=I>/0>anD8 !٫ R0-͌,<#a|_fB[x(n/ѥw( /L4g۝0&[~[l`O-L:(pwF%~qGY .T|`2s&nÄd^#THeeiTmf֔xQZ{>  )fr5&UG"uD{~uRA_O16:›bd.ܓ[B^ 9T_(JLqlK\kyD4RuԦO~AJQXڐOGlё}FAA@>!:9 `oK.klKigw1yR r擢fU.aio㴒y{mf~+$3"Lp#1=8O,Ǹ>,xTG-mA1&6 5" ]ixE#2X^ߑ^X-ȜԺ%׏gK*Qd iR{D-4)(3JZGo[i%},51}wD7_ Ѓ >а%=OU83Sjl+x^Z:ynhbQ2!q!/喃r1~K2Oe V#^˒D(\js˼ >4ɻtA'Yepɭ:/qƨ-P E3'02iנ,kV$:,d]4 "cD4ΜfRZv]vDo|QB1bѪMFI$rKԲ  kB4Qg(c{VC2[O'jɒOP=6/D Jc[%tMB\ -ܩOyw 6Q UZstAݣՈpqW+Ƽpu3?Z Q58&I0s%dӱ}|2dHQrr&Uu4[sO!-\lၢ(L /g>58ז͑$k]{fIl)Nd_u>s i٘z;nQl}hLf>Tad"4#۪*C!KVndr>DƔݑlM27@UKn\I}ʤoaqML{Hf)W"g,C G'5YG>9KzB ~pG BLW|TҒs#NÂ?l/t!r/P79z<6tRBLUߊяXWn+M~%M!2"UN\0ۂ)ڈګ~otYk5e$ pQjNK_+|؈,A+5#T駺u>wh#\, 1U7j%TJ+lKc+{:W|y5`QT j}nX[DDwCENPKGG]4j;/@?ydRI/ zM[b@ơ<'>KJ5AkosX# GjX=M4gA.[51.ǀ1h@7Cs#z!%[fgFHz{PnDŽ F#nR/}ČD; p aׄ] P< -!%^mcmуxQvI~KDMrfhy' )#D\u]pg/ڏ o9ZIy'3ZaA8/Hn)Hp*@෈I-ڄEN:FDAZ%:*8[V%^h 1\+eG;ܕ;}bTUW$pl,9){$Cm4PB <^&]=0SOx>8\spZ:1j #\#[Rt82ԫg<ߓzj;LƮ)QwLec,J\yNZI}WR~X}gP>#KV+vp#,=wBT6ƙ$El]IṭG, 7 P)镾>bhZY@r-=;FJd+gZNb5d&p5ЇƋa?B hQm8$IF{,M4 ɟul]\鸄i !7L$<2}a@_ L ܮd ;IX-vqHycGwݮRHgURZUf0]TET/у]I hn9y=GGxh0[E>')(g-;@<3ڤC-ht=銨WpmNpl.Iz42 i7 2hs~Mj,?v>bDៃ`~Y!lB%Gs;+W!L.MV*X-~l] TZ()qpvGs)?E%&c.B-cEMwyvܕ`7q~X];Ma[I[)Q\c 8PtYKgcF:7 :?VQ8y"yBO7l"(WQbr0l❠b҃rH2)+)GZ0_ !BμV]}ĽBQa6 ,7^_s i(E\3* b_0ҍP/'rcrhSh,Hɫ LZm>%~h:DV)m@| IjvIp\K1g;m*QL0"v =ZǨkKp:v+*"~gXjY{ApD7k+&j`ݩ"0 T6rxS9 I-OtT+|+*UG1[*6Db׍I@mi@Č&rKd 9.ZUՑq ƐQKt~®3{V-8~ʴov=͙\H+8]y Ksqn(Eri?# 4duM.6Ɔk݌%g0_ UA.$1 ,TdkxnДonP1w&l7)QUΘ"mm|)VNk 1ՇXV'Al.jK0o$qzqqnqJa 8х/gŮ}dc+s8VRP]L,6WsJQ͑1ti?[ye4/l5[jS Bq!!<ƈ t훵{y8_Λo&rHedU5X֜:++]oMd0bo>-: I0l ھx_T OCV٢{Φ8 H3/>EXJ13l:Fl+~c,єa׳ڢڅ.e( 55JAHTMB==Hz$xԅYT:kU8%ܲUhW $O$sDgNV~h9ABT-k{dLg~GxL̿$ʡcn1 b@FȖ[anr,.c4Irғj{ Ʌ[̿nST^kuF#6 I'fNju-D"N|}j L3%y4S2lrBFtFv Nr2I Abij82 v)`l;B+vOY.rlU3/5;٥&UWX7;.7"O?Ա.nX=蔃,`c) Pmuu&'X^FeBY*Gl ^S4$d@8jI C2xV ľ {cG&[Ek,)Ag@K\^BCmA{0=K ۿ̋v]E!,nSt}-n˃^zkᴦ[s[V}P7BD?Ŕ*ޥ߈|XPuDW?[m_:F|/io}X)ITeh۫][ L{{z$J3it8 }Vz=G>_/I'2ɱ1H}O)E DH{kCỏ7L!|G,nŬHϷ9YΓ)J.w^wc7X4%ܻh Yij]R',W\sM܋kL>rЃSEXuY}=Tt%ڋJ®&GEi9@"L~i Z5Ɲ:o^3i| ΦMN+g;J 8),nvVIypԥTF5B)HךZ|fWuzxEL 㽒Ts+;-0DMDf"\[\(`+dBmI0`V6S鐶,uWfu%|u(D~Ms}j%yI-Fl^BʨC-ʻ7ĝGMg3N<<:/Y}JY= 7M;g$݊;h>'վ,7>c;ULEqZ5k?!h:XzMNΩe)9Xht ƲP61ul\P;;"[@B~ H5nʚ@މ̌\Oń2nkh#QH-6 `>f֔ðH7̤-1ϭ`$!(-G`F(`HPPTV.`O .5Ypp'#Pf}G^ 77\!jv/o>5"G.Yތ2\704娢s@eSpoPE5|5a6r9ii5K{YaNjáӹ^1e+g_Dx^cu[1˃RWגˇf1X@*zR$ NO/J\g0;6舻J#:P+`6d!>e"= RD.?,")jbxZ#c\Rezב bՖ{G3pNP^rTSOE2!f!=]5{sc}-*y}pX]_֩ʱwr"T;:6gI2g+FpoRjjm'vɦ)ʘ2s*hb@5:hr?ͯLf>L-fb`!m$\T|[m~nqOVmT/>(Aˈ% X=Ӄۂ}o%J|La'聞IeK F4E;'*vFVtC&@M/"}kuVɞ4GKN>`T4oyg\P8Fժ׺{!ć;3pc ~#dݦL]\)a|kɈDh@De *.oxeE^s<Ҟ:_E2̊'_P0} f wl-w`/9,׬~Ӷn;=d'B[=8M0/ .Ҁ(aqo aUa' 5o[vFĈXJ@1o*U=I 's 9t| }E; 53K~{e(% Rg]#8ߧ1RB⥦,ٕx4YQZ|:^ KBJ#U3҉q[~)^ PNU!v79f A}jQNS1.R}Qj.?>gY<L8± "iv Z3QqYû+whq*~1v;-b BGD LB8ZUhA$)D $/ICNt):l=Bv]5-jdv( 3kQlv·ݲW# .(cma LGFyz:V1D8<A >ӯ;b4Ծ!7V.+}Ý]ն4mNU^SovTEWX[HW@#n撪nPOQQ`23Cy(% 03(J4\T8,p14Ӛ0T[͂^c~e %1W8x\;DP s i|`N\& xUOS}ԏ͔(s^R3T:FF4 AJ#rp2 ;AL}'[lB;ӃxH` ={"R2"i~xe!4[#%*ҫ9,c'صVJ_IA weF?ULB`1AOq#>(L>i(sea1*I2,ݽ$)\}.$՟6q ?7I?2hLİvՏoF緼>A8QWN#ڽn(jy󵵊1eqq<x:ö3R؏Zc[ؿ8Q]bM9 8**w2^Nw%_{y-ԥÀ!taW8Â\f\ׂXlJ*X6(~%Ec>IM,UXh#W$^ubO} C} m8,J횳PV!Wo XH1*Hu#%lyH=ѪfRG 0`pkͦ&h͛ջMڰ 7 sPjd %E |oM{ j֣nh-*#rq{l.BdnO|XaԻD/^Hvqj2Iֈ"^r'oNE0l` @=PS^(3,U~p?Nj8 7S' (+$3OU7Z~WGE)%A$fkR!dQgµh\xYW9V4Tu"Bys9w)q.mJOtZn=hO ,ګ{|PxY釒q*\LJn  7*x>$Ee'@2٘B=qN(U&P%m-v:  7i9ԃ[ȿIah=} ('؞;~VP, < d ]^YȀ`(R5ad5vPI^L֜ G{>s&'rk,scV6_judV`yb14Chrm_dhC e?b M4j+?^;lxмͬҾvcD/?5CVJrꩣ͢i5bl<6;p{ϦXC02boTFsR5P3ѲS'ցt$["A ίVCWSTh}"U:I@0޷WWhw<,@aa>[|1y&B6C *zl1=S7슴@cMj)vߏ~ a$Kk V<|>,GdF<"FUuai|[1Z<6f͛>?4}4G@q)A r!ELF(!m=JGj>ωGzRV+H;Jr}e哣tLanhxCJoRP-;3BvoH p5j]>Ͼ &"h:ph|fI0Sz Ak}j= uK:X*(|&#x@ًY0 mIrN32J:.U%䇜"Ƀ'X6cPk؊hXgܰ';F\m [T7So^v qvUć*Q=Yt0/:pb(N7KZmb~&sϋ47R!szJ#hhkH4kIEhmwɂTyB H8 Vd,_1AeTGH ~v$I:e/Tu#DHt V+cg\?7=7ۚ͘AO7Xj"d8IȱG)!J'<ٙE) 9B|4t67zP<8x`&U"w)]݊ ǹT~fpиO׈x]M)(3Z.[==3K<$ 1h{cg){HOH<{瞺\ܟ8/T(U"*$:FdkywQ>,DflP*, DkB}pе o "v~:L#p"tޏSH3ѝt a5ؖKHQ0rD$ɄwiVh֣Dа2-pEDkp5m )j1A'@݈њ+W'jyY&z'Xs"|RvpE561'x5W1ь詗,~PNf^bu +'AnQ#[#Ñ2 "Z[K+)_6Du8Js2o.no*䦛]HqO"6"sSFx.WsD95K~1ネw\;4wt+0WV׭[hq%` TgDHswc//=Q͜iw=e7_9ɹ ץ]B+(b_qFS7 `dQH&X?qNPaQ¶F5̅!.T.{l{ z?N"8ơ˨[}hQ[K\d/o7s5"E]C\ E3`ѻD5L.fV?^9{IBdЁv#7hw .ܩ7LMdH+tQCB5X嚸2g\4 9T<_=1ކ#ۖd׸ +hSz%2F\$Oɤg,×Wzfg@,p8~nG+k~Px}fݶͼ R`ȃ* [D3w^g(l<W@KA?Xg\Uyr D+˜"xgHTcBp ~UEye`dֱж-BC}~r5vQv3Ccԋ0J%JPϦHA=KR)y8Y<ðDB<2nܩxeҿ3W kt8,l,b֣]&}*6>Ѓ#.beJl'Wcm<8k`on=x:^+G9,"v" bo}RҎvSn"!sԝu[Z5p#Cx U~Ai Y/21u⧰:D]8XNM` ''L9ao+8 Oiq8/F|qz89E<~P6~*:[zgjP9Oq(?z#z|Z{ [Qxzrc, BMj;/c{d>ot:uϫN#")GI1F<[έ~}Ea I_X6dWvN^ӝ| 14?qVo;I:xC@^7M,;^Sl F :hq[ǧC6xc^CU|칤 `ʯAL% $?}ý։qYèZEBtA$3V2%y݀{mߧLkUg΃r>5jatU;9  ,U]&YI." "@cqHmgzy5'BcAz[yw7*Ř<4FR1`A8# t '3XaF@T]nSh†u}j[݌p55Yw3Wo(Lh4-y1x@Hh X_fJJ­MK) g[ 0 ZhgDjAM!%;Bp$=%[_K.1,ipl&= JT>5&k\[- Ph=\K).:' I +yrInz9X0koG V${YpS6'GNY e6>5f's[RwJL=Ϸ9(WuWyb,eOr>)˟[=qg}L!fJJu|0;`j 4lM"NRBL2YeL=5QVFސP# ߤw1glqN XoֺDŽ^Έ+ua Omst=^4ã;@)X; YN3FOsl#82֧(kTS@&$cĠWKPR?wG(I -&N1 NNcB &yNLWf-.sJ2S]dDqzJFن%IKTBS8H:\dlH G[ hU"5x 6Rk?$VB-K!4؛GJNjd(P(@ <{^[F!_t x&q r1ANg9I3I POD_Eg4*充^ z h`zxը%ttkec&H>kq8$ѐ`Rݤ]=K|GCi8)-w|C"?t'_9/6]>}^ S#1.<ʩy,Յl2:(|gݻ0`F!V9[ATY^r4^xݡ 6h8+)ykO ¾Si)ީV^^Kf;v>R[z^AU.쏷SۮU5zT.2E3n&O8xÐĆ. ]~tE7AUxx%\ +k&?Sudr"m?*2a]zza'πΗr:!쾬w8WOŌFg|#ȒeY>:eܡs\cʼVq_vPuQ!I~4zS:;v` $ܽysϯrgC~i`}H[ԒCPHU_Nq0T%#RFHϸ7cPkXp[@]\:ԣ1͊`NѦGTZ@ ѷA8=R6\ 3Ry?z-JH޷(k+|ţTA\6(dH;^#};kסUu D+cs0֬5dFy-&J]Rirq:}> eM_P3NNv0pF趾IYBX-Іˤ)y>oPjD}**^ {k ѼuoDhN2oujȳ>߿~ *z5ej+4'bJ*ژ 1 r =t|p8;!> \<`hL =_(cpڸ^~3*rz;%}ƃn_8Q9ɐb72b3dMMw"ߘr r쎍}Ε@MpvFj^Hû! Li꒑5,~c_9uM}m=:j<]EpD6䩬 W@ ]feH)TNK&LK$mAJwMy/k@o&klĦzSM +w-u2=j9A$r.a3$R ,-|Z}G͒Z- .^@n½D2o҈cu+4YQҀ-Iƛ>GML1I빔'ћ,r}p&5WθƷg+#i /$kDQ)G<y)xm\ML%p5sޭBhjXICw3sJ 2POjs̾. 76ZMwx{9)fFyo؍d54fpn읇wc@Kk T1s1Ilitƒ:Vpfγā&DSvo38MGuMB^$]!bG[UǛmǤ'm!fg:yQ}!|=TwMLݻVNp8Ĕj@Ĩ|ӨEeTfޓ w&)e66m:>-ժ"ӛdxCd][OtwxHcS9$#0e2[[畑RJSȟ}6L1 ߡ*&"Ag.Sj~8UlJ Z :S*)eMViD-/yO)-aH1"<yECR݈ΛM\\KcSz2Y)yw^yFwk`l6p)$&xS%TdCQ`A Mv+3B.hj3"<|~(2g=$]$x`n|5 ی+KsgwA>WF+^]AٜQT{Sj.%: icb?Yv|2IE<ɹ#5T%f"woſu:c S{<_e(@rOzOOQҴ-٪njENڡ?j4c9wiwn %2{~a=(q: Ⱥ|?6@n\\B[P@j!ϏDa85M4w+U͍ɉw\)zYg7!8bk} };O /IM`ʶITב]8chSn5L>/ЪO㮁BRxV/8˓_-~'> -= 0{+V_eIOslCZ;ӯr"/{k4ټY94Fj/-mW85{u!TMP_d8+c`NgzvJ@\FuyK:Խ ;yNˋM6=JHX*x)-i_?M' '#tLtQ⾲\ < _ <t=y;4qf:òX&0m'%DZ"K[6wwH,(hB5#(廞~9I3>;x6WL 5>ǖuuʋeեeH.T[G AGNjI0sq"8v;,M;Y㋂d&?hr{<фJs89-yq(%o#F 1pCJ̧dLz7~Cf 6d|7 q"$Y*"e)mj/x].kӤ.8g,]wNtnwPXPcG[곆oXނ}'cU2Mw'̆l]L]XUh9I_Z=1Gz D$N22~⽿R|?x m>A 8 T%yD3xcF+W75" lWj)})^ teYd:ƆFTkKS:$A|Go0[VE6H`ZqKkUƵbC><EA0Os>$4l{?gaEj|'98CEiVsyM8V꯰|ċOkp,"l::+)JI޻ހ['UL|L3xdm2Bjl5$~ky_ǀ|Stbqlz hEFȌw밟BOt{&L8d%H?Iqa8ь(a.И Kv{Xs)k} yxVw& b!?߶![^IgM&W~A3ݽ%grɒ5k!G k4ԅh ȓ6u'oI ߡIW'3~`'E>V6/D+$␓F1fzq=rJw%H8"& Ѻo3|c^1iwJ%s(͂x<߂ PUw㪞r ǸjxKbWSޞZnjD7X ɍ 0i!EL@FAKHNݖJP4~|N ! Lwe׬.k ^ < 8fظyЦhl!l<`20, ]OLh`Hz$_{ OOp^*9@+,o:fo7]&u\~i+80*B`dgm8mƊ Z6k67" ȿ["!(c!(J8NQ-gM!A}5.D'Or=u}#Y/!Vp8 )8 EO䢳J)|C{0^>mzE_v(LcoUYQ%ML8vCYva苤2&>qqm$q2rup*.(KD,H==S'oqRwn2>P6X>>˖t,+Ԇ}뮒O / /{&:ǩ'f RljRkf%siȵsNMOP` J@ nJqQ"|sm;scGtfcR׋(HΚrħ|+Z$5Ժ7ut11' Q=@w1O:MVDH&$ {Xm k?%hf$2>7)K=`|DfluzJI숀']t+,Ź&6Ź"/pA;+*oG8Uܯ1n_e;**mʥ"`BPW=MCK]+ϼn4m 6*ؔ]\^-N~a8m͉xḾz9r6W˷@ А2@rȝ;*]qmHXbv4 W7+'Ex324Ԥ FDER'M_s0ANXAUao;5x31w` LlO°k)ߍ`U%stB-/P*)p4I.nl?k6X55>¥B |E.$/NrU`4̙\)a3xHwb/X$r j| U%N}%ENAE!iЉȾ-8Kּ઴UfFgd%F2\'l4SggEeRsʓJf`vB_)8%t\w%jER5L{%%GFN\ǎ^Q3 +,p"ӲJk;^hD% 7DK(H}/A˹I3֜( #X-TZD-gG]Da~SqKyԥzOhrHy>s?! -<5t;9`Tdww#dT:a?aZ|ܻ#o?T3E}5NVVM9[4FH[7#m[G#7r]ڄat(f.|E'1g [ TV!ZA䵢3 pwPfiXKǮI0砪@5-v3Q%~Ps-2Y.݆nD&z#I1^ Y@Mp-:f2F vϑMy`n\2z ds3{܇%kVpWfDM/Tʆ1>|dԈfm~a-J ߔ%}6:tm}K(X, Ut^j^;yc8, 8Z "aWG#v꜓+Wpdrhp-&ЏmsXQނYua6ݻQnbP:?j-jL3"uxXlyW {THҢN^(w%,X=r&x{Vy~ήbUdMLgz?fl a$05&#AgcBފ8_̀4&'u_nmlP!x%5yqл/$홬^Ǝ[~<  !X9p)£u~A!,҉]0t4N2ϋw5o?14ݨR7wʚtOڭEHH[4b(ut3W鯆 SyoXwKWnlA7) 0/w)%#CΚ-) {F\Go-Iq*->!ƞ>a4xk+y6QIݾwI;U_a:C?*B@{f9CrQbˇҥbˋQ%TDWɳYhf7]Hߋ-\|,fW ix7,46թ$AݻfE}(GkUE9a˙⊮Wqሚwj5V p,i-مKfz0֦(|w/jES.ՠvUMaD0g;A`Tԯ)DɃihhFQ=N p!} Uɝwh C&>-ZE0>$!:!)Fdvr|Q9H)m$Kd]C$.gW_[Y3`R}sd5, vFEJelrXq51 ZtIkƼ){czʰpǦs OٕyDT `<`;RCigPZ8%FE+A(NCH;ée9MS( _( Gon  ; 6j~#r,;z?6FOps6ᎴC0ާ" ltpW,U]ʀ)}aB$Wiza k/ʙ]NFWG/dԋu-ЭW0.'`.zdNĻ6EJ.Z4mpE/7i߳[Beg d'HMfuK+iwdN44d*(Do8n/>㥎SQ ޠ&xr&%cY | VKڥ$JBa{{@ \8WF ؕ<&aJ1ǖӁWy=zP ֬:gYӣ|ʟ o.͉7@>7 ]QLڄCA_:!s"q2je2>U`4"ChuYie'Ah (~ʷOj}NJDr|q.qc]c)9d7X8c8PXwHtoEzx>۷a7a'c)ݧ }DmsCNzvXQo0svn,꿓z}(zp%tDqmԚ{ zBەY5oP͢K['5b/{<24-Fꝡ|1-q"F)&-QjԄ ,w/:v?ƚIx (>X@`;#ra~|E"π2FT\O?D$XBl& N^{G/;jtv\"\CL$-^:nui\.E))br=p%_@Q-;-0 xX XcQʴғ[hNыìamd)M1j))MiC"'H͎8縰fZFȫ䳔@MoPUɩnJ ~l^w-?K SUFEs,FILH . \`&r>BX>uVɆܷI%4˖fA 8]j3EmHW*^A&O>I^qӍz(jzM!+T/Vg@%k5 -:mq ,xpN33%܇{=ǧǎ:𸀢>ʥv1]]Ao5&,qRm 5 It~!gМ14[xPՔ B7,2f1TB".'[ByzW2 2Aq")r0cr7n IPPjlФ(Xyn#ݕmWPX;UrJ̵ȓfb$iʥ+W @L8,n0C +&grZOEmiZC9Pb-3+N=dXeG~[$wCc7^?RP*3BT Ez /Jyd]Q6B.(6i3w ޿ A-B`ULŝrtҌnլRD뉠kLz&D^9%U6Gaq!wwO\@M~UqzdPh~ڸ81j+GuLw<@̣Y_UAs^uhl|{"@WXQTIh3)x qZwQ+sݿQ9A9Ħo ?~fB% ovK?1|ABϨ`3C ݌)?K @uK"#s m7ooEmuul:9;ą25[ ^Ij XQt6maZ} ^&} D| עCs9dCgyJ0-ָ+UZȃy0/Bp_77Tj1;4vȞ'ڊ^P{S\xRU3$ۺ㤼J9߰Kbq]X5IJo>].LcC|? ڸ]ҎW(g(fȖ ^n[9ʑQuC>y/Oҕ#p4RRllKpV;p (')AY 5QB{}XgS:F+3H #+ƨc:0V.Te:grkH0&6_QЄZjdj_S@q6, McrZ֥9BX]i}ߨ콟Ue~} Ur_^X8Fw+2WRyeRM3!5uqsufnRep_/1EtcwW 8ĚekO8bq*KV, TI9Ԇ -"wy&u8},mv{!ԓ.,"qQJXV:(8&`t}_҅z,I%h:(HՃ:g8sJ2r=I+ f˰d9p Ew>$&ۚmYlblVvYԼkW١۸u1 RkV^ Я>|R#Zy _nۻ24/kU>>N0U.$jb)XfPDvW&|u۞6l.9vdgnk)(W}]ܓJ^_Bz_* bo38Ata؋Y3wЕV{pmq/")l,/ƴxziYż4$V`$gg@)dBjz@؆jiv'8ڛ2C^M$~@}ST5] iN.qVA5THlvR#S-fKKe\#-U̧fs9'ud$PdS.S^UVIg&ݥ(Jǟ$(1* Uw3 OhCV ͽMc9 `Y*H OЖd2y]b>G@8X2*ˣt(YԻTU(mBQ:ZHQu>k͗Fނ.1lmvfͷg;;}4sȸ L#ݖ>񠯯BΕ;q: #4iHoF'2^8tWrAGˣp92@N4;M=rQ}BfQ|h{JL;z$/ac!_i# `#Lt fǦ=2ngF0_Ո-̒ZSI`h'Rg*VQg=u]V|ӈUg(63ѳ{;>* 6s)TL{eMzyfLP3HSZBw=c6, t|=~U‚& 8 z)ZvL-5bTF,qAa'y 9-;pK3{@+-立OF%6?O^Z&s7Jcyzo/WÌ޼ٸxkAFT\/BC\ߚ\2 \gFU! R7Ch 32 s(]2%’˴]S;KH a#YU&7ҐC9E;v].kRkQ2! U͠ZºynPǩp~rWO. <w0˚AFo~C6=P#4HZ5!^, km0Kej7_8{}{Q0A8>0ڠ7ڲ"PʎvvU,K$Gy6Zm, _tKr>ﵑ?!i8xڮgĵjT-Kكs3rNR+.ύY*Fd|'ųE%|1S',D֐EZvYûXĵWp5-Ӱ^"H Q#oؿY/ȝml"6zt;]?zvd:F=>9rӺXB@nguUy}4P%=rCcf\WUs?P @Ò H$U6GԁTF9X/£ז=VDRy-m_Ӭo ޿ >:~u|q)I'cP5]WN ?LPLg摋]rOdb6}:_Lu4˼''ӑB'ʻl猐a rc[D]YG GMv}sn.6!⇏SKߊ؀oZvׂ\/z  JrP-p xٌ9Pn;ђ}b|Kй(ސ%mKN *&W4E$Jގ0ݞv\m@a[jAk GgڛxJU\eTd +Z[ Qhd CUhc6O * @?`9ABD y y^`nV6V!:OMz$H>nhZ9.,[C'J"@?Xy0y{Yoݑ6d>dt6r|Js TyE6 8@+r3UT7m sfW8 B*G=(\J{ p/L" # #wn%1(gdj:Knp/ ~8) 7CP'9(zZ Y a(mj7Z2Vf^.4=̅R^t񣕤l1 "'.qHXK%]5BDΚ?0svP(JlN;[tFڊǂքRVi(0)($xb8{AvL*ѸN崅5ê\)`)[1Tʥby%*x!!Ih]x lJTbZ2hpO<>(>W%O eqC%E #$`)_\^7#[p:SI%bi ;9 ƹaꩩCf#}T W*f$ )ɠ#EXזVB^sŭӟ hhuBˋe߃IXhNQ|zƷ\~PA0P ϱYlT! N!8P#Wq )#Z1A)91(s =(`~J}W`r$z@*\OeX·`(`,bv:|%t" XTqe\;E6U^/!phQKӭ&/cÍ}wPBYu4 j;h!wfom+cPb`FWKyXC70,o \ \dxB<8THo*/,p#'(PڧVB42G%w"}zS9tuqFPhF{6MI7y@lĀGM'w;%f3e8*KNC*q:]K%l9Ѳ ژu,3&XurplNyU .ݶx<̥Q]m LKffO `'='ÃS\ eA"G*uCQrOjby"诌!U:v%QZSJf9dKxsj1Ӆ|1g!9Bɒjo%ĒL>t$Jq Y#GFOA{a'(6*1#,g3˯ g3ʁ9Y DΕ($@[dXMU!$rRSwR& E _ǻƘ:u?ʕ>1ق=jy+rt10ZMoأC"xbO8o.e2~Wm`F RK P"lOp!cw˖MQ^1,ascНn_NW~`#e3WXb&pˍ14v?D;%ɪnQa3*7(n~@h4dHs8ߠ`U&#DiBj)y +c+s Ptn`ȟAN,ׁ$= H$d).rk鸡~K!UOFZ|gPQgG?B3 ˡuQՍL2^1i-NZ wmHFqpK#]r6Z7V" H G[!;l[;:&qR3L$9>.C0 =q­P)uw'"x7gtN,3p f:#GSңad;M7' |[ů ݪ0=KOzOUB'*aX P-Ջa.2e :^'dCp&^ǮjIũFi?MеAFnzma.V@h1Nr/x#!퐇ٲsXk1xYDKYb-S[z&MZjM-jpou5iӮ!@hҙloNY[#EO$@je3-㋎.@/Hͺ8"$ ?eUKRھ g> Kq+o?Ix.#P}\:jKPDPBH$.~-b;me|}U\-++n@9u=ӏǪG$ ļr/[P TMF%:'Ȝ cX##,7[}9fw?hr%+LQsLH0Vp{2p8ۄVs}z)qO ɚT9KF3M]o6FVq8mTo=?޽"I]Ez189 #N. ",sO.-{ڰ:H18:V,=1d_ Me~/g "L*M`~|l^mF+/n)smLokJQ|b'V?) H+V?m׭,Gx*#pr :k0CN#492YRb"L0hqMeJ{iIbU5צjwதsXY9b;zV|S u4"V*z?$>Rh B}PayVGtw Q|e6 _ڔlSIJ<vX]  dsf` i,bwlȰUJYI9p6 9j=|5W,;lToX&Ŧ\qNG*0'HȱL,pJCj/"^:#*NFj/ {-꒣ˈPd>!׉TKZ=SnHcOZ6sR\,T#, A5[$Pϛ"*7*(=.i==Y8%HvJ|IT0WXBК>_w$ GX۠)7D¨C-T68 Z%!)VH󈳦WwK1R|d\FX9;-7= 4hQbW\ɵ0ʠ`*HQw- 1Bc11.?lFas4&&])&8at娇3*[t< t}ƻg4_2U&3(ۇ5/}̵~X&ux`):MU(JRaLwl[R 5V^>ȭ:Kc(xC3'Sh,$oRc^al5>,BAz\xDUu}?ܧP;K{6WQ:}P*ACbvKz.A)>*•v;/ʤ:7"uֳ >nz_)Ae)o/izK0LpS*qmV*PԱj$pNV4~FaEz DiuP1?`_ti>pIxs !XZ =a#f%2ȑV>j1!mqBF̺`ܟ^xecSJ23wB*W:uB4%d&s"I 9tTP$u4O>xkkn(Y5,Vt:`e@0p(IG2.x ocZ.K_'yYr sNj\꾀hELYhGy'7ߒgy&a-2#Vʐo}v˴OgEj6+챎hkwwܡ ]-_?u5< WsS,iG\2= ul׌ -֯Ї8%Y9h?J0EIZDw,6+.Wx:#D=~ذb]5N6 -x=id̻yїgCn;WRjǟ<ՂKʋ<@X*3hq"Sv?)rPFXZ=yWz>ƨ;;;$;8>zrҗ{Z  d4źoCf /N< V"6(bi1La,TH}vSdM54d[JLZ}<GT$ A|^Ң v@%"pOI`ހTɅܡAIF`@=#n+܊q^X'rtyn_TXCh6& s8VDT wH5&r798^ff e,fsq7-p#gfUԈZC>jɾn~U%>2ƅJ]!׶Ydb{WX跜L-;7j q2XH\LDӰ楆<-CxIE/|PRxcu_3j f%H*W@+jMc8NDŽ:\[eqtބBͬc|8ݠy.M݄%j˚>\:| )vM9hCN}ƯP,rq]s2b_"]{U!6:v+Қ]{LaTDecf]4 Sjvڭd1Fa\m|k+>t^G gM]T{Ϥ~C ҿE@1 $~"*/\M߅DQd58+yNkAxha%kQ;y.uÎ\. Om{Z@F)_ȕa}f8%25oǕiՠr.Ccr6\(cDj0ASQ!/.l\NlSp!a:[ ~1ۨ.kRCK*LHg4.+m)uZxWTuns*"H uUa5IcۋQ €1+a5F 9D5,,Xx'{UJGRޛ7HcgQ ^mYiށw%;0ڜq1=燀{݇G:fم|MT'NڜYf|q&W@E2CU'څ9Y1;ӤQ+ vi[k_E)ax',)0?94(̫!KFh&W($R+̗AL47qCz" ЦzWAYģ(ݲcNAN'5mȌX0Id\ktRZ 6y,~a7=ӎ-D5u^OɺA:VGӥfÜ{M@k[ CLV?.Gg(ēAlx-_jyWIF`Qc/S_e W(ܤ 6s_.<+2QY.ľ5ku+%?"‰FVL5'n'_&BvDbָ.s $9hEK왍:K*v֘EE]^؅@%`vф]]DOLK&`bX5q1jG8bjG]Pj_M )J#u6ո`!&7'.b{Hј3I'"9d8AFĬ}SW4нAzh=|FǶUiX/4w_K`Uml|Wv,@1Ǒ% K$(`.:`5sӶWVØ\+l*Mq;û1aDn\ۢ5q WHJݞ2'hg*(PupSm7n8qG-8H:W9i?]4nP, 5IeܹΙ') =DnNY~=SV[,i+*'qq;csy(N]j[L:\q5U:" 9:y2e\w]Xbr#sm{qGz 64gIv~4o.2;y sQVF1'Dig7BDH/ŢG[-Y42^/|=5- G "A yUϲ(~(uu2@ըE.]:MPѭH0"|!' ]pCĤ 6|rQLqO)6Vr@8b ?㒩gd/x҂Jf`S@~$' {鲻Ŀu/”Ƹrh:uk$M/n$VrYMGn%ԒAA5*N@'y.O|mCfl KEM_Vdh⤞<C u2b)CDͨ9@32WHBY M[K(0O1k_>`QR`vIn6X^x&ul5g)'^r~Y9D $:( (NdcrZZ^!i3Xkz @z"BѬa`fk堩ء,֥(ml\i{bN*)tkmHnjp;J>뛗Eσ4X aaɇZnUl蝨ؔHl3@dN )%b 4ӈ7EBYZ Sn^.l杷_J8ї.jDKN[Ӿ"M:ȝZ 74W‰aad1"\(E _$d *@/d` %HT 9KO!jskv ^kb}Q@,kGA9BKk*nT\gM0eޖHݗjY.s 㐁 97dW;1K+9d>w?2$dbM:m{ZUu~P~'PH}ق[m~`i]6ruMYlk&ĥp6'Bmk6!Vlwoi_ȶt`*-i[Jߖ\K!w#NU2< `#p\GXA\0Q cሜغ kۣ'ݧߩ 0#csCn@\ۼqƵn98|e"3Au$NhU'D-2P{.*[kUp~VӪlY$uJ30՛ Zv:N?-8n'>+Ven޳tS_k_ ɗɧcT\R#a`ms?bҁ>e~9~w]Zğ$qvo'A=pS!(F{0ͫEr4|OgSk+v3ܺrwJAKm7tAoALC {+ણR+WB DFǣRϚ}+[n$!g;;Iiɷ|.j xKYWp3_eQynh'@y]!Nѽ(0)vY@9ä?'Ibusa鐽` ˣJ`"A̠ۮ,=[fm{t]t4|g傮xRHM#X ZHւ41nw¥' + IdZӋ+ۺSym.< v½Q6w v8-r)sj!7&chnjNMmiV8EOV!ôޞ^aI E OnjjT$R>j\d!#pVmaLjp1N-P"=td@0}^Iѵx$ܡCvfՀEe.\* Xe6|b%H/GL*?9[؂S"Xsc}Nzj,+Lʐ%cڡn⩫p=<dcu Q{f1H~{h +d,HeF?բ#aЫMڊ2"C5^2r@mp?S];qF 0S/ /3=Lcby85fp\%>K O{ZHTZ΀<"v!䵿AaJ.6#t^ q;쬯ϙylQ>LdGt+| Ì)XKTe FvKjM)w? l 8^cqsz&&NtCq.fZnjM >X^˄Z0 /}݌,h?%@4*4vEZ o)O!F|k^(zh]{mWu$Y?ZY:4}VGŢmu|Rzե@Kԏy[,/eC1 k'FքS'w4[&޵_< b>/#$ٙ靎DGrx[3-pր?@~0JP 0[拵v\s%lA}Ԩ `=J!>vzCAb4w34#ZNnl:K k.2iPWV'"x2**8 @T$% )/<n+TNJx"h&ͬdfX35O*t(6 <9|cͽ&H!"w}YPHzbnڱ㷿\EނO&,#a&芷Xr9#rj|nndŞ;EmlE1N"MQUm'xx xEU)tݑK;AO 6Nڽb,WT7&sEa2 tW QvsJ_\QyJ@wڇRC+IӚd*%FTX00:d/,ʗ?T;LMK+ڪ&iac 9հ`B7"ݱ9b-v8~}aZѥ 1jƀ́yOaQU;-L.5q:o;tB6EVh:L8E^ոw5Y ~J[ь\g1LX \L6Aڳۆr`ei@Z6,;,p҂>`R T{v즇b(X$0}YBhMo:6M;RHQYkcW(M"E*6[+@(k _6Az"2χ?`$5u /mS\h&Eud8q^v0n헸33kn© !X"mѷN`C NjpX+ct5lb*1!#LP{LqT_ ^Z$\(n [ И,^vY:RlzB"Q*vk+( n9s44@P) r$zeLB m~js(2tT*Za"OaRȺ2 X,8$.Eҏ(V;t+_M"fͩҔЖ痘Ɛ"vx9 ˿ON9]2|[y٧Rk&pJIܳ#GF9awc"{Kϱ 9}Bx\B|!VjOGQ5Pf$()qb-eӊ7  δ-$B1m!JE2l>]PE}Qq!sinoe*߻if|8$Fk u.2*@'"S;5^>XFǠSc|>6Y}k= ['V r} tzVDo 6XOBKj^[?3Zxঋx>B<:Ќ'ϸ_*+J:}0 =3auWSwd qf׼Z~ X6UC'`[8a*Ķ'e-#"\;smNԕEU9ELr'HX.oW/ ~#`D”PEeD^jAIUN{'ӛ2efˑv}_` *ijrKPHZ(h qĮax&rAԥ:" itJ*b`'|p~#)_. v. <[GE;U S"7L);eC'R,%ݔ֕-%dr_ ˱o-og*}ćCFXIr%j7hզZ/o)'jM n&Y^* {LUҥ%0P$ubQ>,kq:Ղze֭?!d>+WNfEô5M.vI2 ZTp f3ȳӻ8fCCD792J>Jb.kGiyG\VKt YlrʔQ[n/钂UE\:6ZDjQrCe>sM H+E d9 &ww'U \fJϘs?\ H->9ͬbQN?fx!:WYlOC$an4J}Sh L1,)+ܴ3(>H}/M3*z6U^Ht!K:yß|4bYXXNrdjrQ66I61E#Nq*L^[[WH:Nwb6[د{g}-Zq *޷SZK-~<w妈Iyyܵfo8t6 (Ha@bt9ZZzt6^LeQRWAq4:WaWf{K:\Pn5ȭQ| $+yZ `׉Tn<ÒpQU]gōځ`{Njjލ V`"R-$*g.)vYÕb0ga\Q]O[a7B{ɰHT?V/Yݷoԭ#n3$0Q- g-v?I9E!\/viAI+^U 3^GI @K*z)Q'<$4*,ёDZ*=w#)0݇7! BS3H͔6jڕn(\CIg"@Y80j[t2>Ae׋&'vO 7p./l b~Ya}!gr%ԦkFi-Bt*'z'|M쨻I vT@zEӊXCd5duZ?ѐݿd#C3E%=MVuH:˞'ǛK ;Z9rܨO2 hBNCRz%Jkoi9XBܽx2 ;o[RJzN;}KӓqƁ]Sʱö#䑥K`t"$omKY9i{ %}ܽoBOM\b9[6'T^_7` (ӄnP&r=Jv;UAj-F $m(UbVRA"6k0 HSDp֨%!ݿ&ij&g]̦I.7s+ؾ;@Aͩת}hөr4fj|*99wak_WTd.01QnPD>~V,TIgb^# qo+籁ǐQ&c!Ad_ |(nE^V1²Ȯ7#Đ6Nt](->=F|2w37#viu,/%8Sr fj_t#`{%k&A~xr,zxMFM~`oI<*ڡn@6q׏)A:w/9,dbTeO sj]MپPٻQs?=!.JA+Z1^HAOFK{ ߟthbٝp=ʴe=fۆ0#pN7p *p$VC4GWCM5yP> ],) yVJvhjǃ2f㊃ ܉g(qG}fK~!׹wľ&^0Y$k&!D4c=mlNEqܬkgYn`]]@5B QL2b>)Nax;ȧ”I<׎d~R*b&e T >R/EcjdɆ f/rJHnͥ#I{>A[5EF%` $Zn-[Š[(tBJQv0=6q0AeB_*FH++JCCQԣSٗJ`&ьMˁ<߬.rn9|raș1Ps:2˯'tbWI}$_E]/V-r/b+$r΃G~YSS;AǡY:۲l++K[&[㖾1H.êgp4ߊ5ćP s$ֹ(6d9~={4m.X#R\ProY.&t /TTD'ߚ"oұa)O;1ՋhbiDF}_R{^s(|qgoiA7 @U ܩc)w]i#bavtCHF[F .80YrU|*J3eȲ\Fti,rS %>$vI#Dz1#5?Fӛh D2f,wv:K:p?fK;sO3\L/ GʙK/L.Дx7#̬+b`Ǩh'oN/̍3B𶰀h}o4#BE2+mG\[1ij| AF¤ܺyŅݦal\Y@:8;?Aw k"6Kv$' \yoY4߻1s(wBO\@D%,#aaT8ڵǭ [,Ӯ ۧ)3#SJB‡@6%EL',〉"Z[$!/bGd>n5H(z>- Ik׼!+8%gý q;gTlsVnO&4CPƙ6 dqÈ@6m |j(?"|Ɣz\땎p7I٬/1FpǼ/b J+8僊H{9X6t n8vvsFWNﺗ~IqtUSD$ұ8TM*T$W-"^gzAHH#(F9BٰL.&P\[I|+$m#<.H1:$QsމuK6|=,r$Fs*1Oh˷|:qhlxd%&tpٔ"9AAgJoE " c}'\*E_ Dže:RP THqyE?ܻg-,&xluz-]txRf[yW(\,u U8:*yAl?Dӯ" UgſbE.&\#9Pԧ; IN8p}l y`9`>x/E'.dأfHtOlEMY'0[U˫W3Ci5ݟsgWe XB8A'G&mw!F0xM& lrNIZMBZg<7|MЈTͅ/NzJRj b%5cysW~DA5`TŽƧ!ِ2ݤ>Kp0Ixk;mٶ>OS=’K>&.Gy] Ԙf[M 8h'Qr&2OG+ Cdn:v٘'٫94F8JhwS6Z,ZB;Jso9m~ʩ$ y7(3 %0>wus<8cW )}c _,p9D6fwr4Jc12{(e3h:lJJGI]!Y#EB>r=ܡjK0;2gxȼI[M:5ٸ sl+UIewDI]}s\1b1&i9/'%DO)6 "%t9Ǿ!<W#vdĺ#'֖OXBԛ֢)[\}G~wwz: ˛x{v㪺8W/#h~1m'^(p2urvoԧs@rםbB*}.r N*/ N@.鮋*Nbۧ rӺ}*9;!DA:49MwcBe/;j76Ff-hj Y B3x{'~? Ih!jM ƍn]TOP}OoBt. אvf]_[n5LE& XI+'0yFQst} #of'@$i>|D~Sud0uҗ_㡣i/S"|H ߴBR_cq" 3[5_5 9">/lbkr H1oc$%ÀK{@*"c҂M`(i&ASW:nuGnJ\cƼ^J.#Q=S]Ll!+RG ]0 ~!Ú5 #d+ Q~,uIܯ|3ălivye۵QNf3ξ`~jpyWBǃ"Khc_ygGEg=͊/vh-uDՈQ+ZbH (UӮf +) ][6,#<ݤO=K=tq:3h,E@w9<:rf4S-#ڷ'ltZuԼPg l:{X7*X?FCY1Z}=ư{,)6H5ҟ6? Xl =xa=;|J'l&N`3A Nͩo`?O+8.&2 OGEakDp ՇK@[sJM[9)Y_?_J"%rKض{b0))(sn>EYC9Jz! ay4D]: #[JU5ɿ? GI ZtArԬR_45HKv,nV4i˼O,WkIRel܍0?m4 P~H;Vl Pg1JWʹ`nʊ/?QyOpWNY7qi]Ib,fo3Ot.b1yqZL &&<74 S?~@Ϡ~>g FqNBmёIQ<)y9h6/ S˧)1?QRjK{S6c(7wG޶^M-9gPG3bZ_,h`WذA H5 R;wa1c-k7vZ^|WŔt;]qdbTQkKQA> kaygz${pD.2d/m N&V<L1u ]Z8 7_.flV4I}JA6Hdw&@K 縇cUT7W57o{PV 'x0Y!Zj 8Г9IPČ>u(B~JMfXc`Z&OT)DZN5}űe96, @o}t&- & 3 _]ݜ6WRy/hiͤKBE)!F_tuJGܓ/Ei#+//CBxXZ9Uz{b61 ś0aX _ҦEɫ5fmDhVBJe] ]Z4m k6p8:/֮(!ǝhIV 븢r >j䂜@m&jhNbi2:׳ULojwDqcia1Dkׂ7D3d'Ŷ -[5IBh.gyEr3%r9rxAΉWPFP4P}4\s[Ѻ"CUFeT}{.Cz^#w?6tff l uPo0"^v2וU5G2,xh !S Æ(gN"pkZ ?8wBKA3|8_(bLߴ%!>zE |Ɇc-Tbڮ~1_\D5C[2[bZ p HEܽ Szi5׷$+X F垘#τ4{}F?9v~Ni@T# r]R,64`Le>EIGJ(H G0,'5SEޱ4<|f^6%2J&k)ΒID5;* ߪJmAA4-]+?.Se(fdl[Lt7VQBl+*bM0)e#(k*an 8kl`&/еة$0!9 42y!(K<#/'a9+痪̣ iN~T2t)Ru x5}cGm'4'c|-$BCM}d%eaQ$B2\_<$T~’J.N$2:&8-*vDՒ moj<.ԧg> xPK鸚Ol6ga$*8*)O~Ji# km8 ,^%QKfr^ >lh؛불 #0a8x"33šHb]6I95A4냇K;6{2=U kɦ[}[q3M+41oТ 0M5~' S-ݖ ]o>~W>ג/7R qf^urhfYH@ó5h1+0?XVfoUEUK(O \e~( E}Y{Ɓ)Vag<~!ZZ2-a *>Fyb#ˤ@i*?hG= > ɞZWѡ|´4 qR +$6 Tfu ee T.%}_51Ŝ-;z#Һ!8,Ԥ.7 挜")~di@Ӷַ#Lp*!o$z^ϾI.Ly!iߓ5/ֽ;GlILj+(:ujΰm $rWG,ذ-.sޓ1z5<ex?ɺizاx$gd`w_΍Ắr6m)5kKsiM:SMlH  cq<{󸥢~tY{.B|M35T>稰^ENaG,| %yӯcN^X8n>K7iQ@+ٛyto\Ԯr/8~wW,e WS#ۂWl8˜Q<" w*T;YU" %}U*;hH#Cn<Ӯ`WY ,"ЛKvwITy;hApM@Ry]jD;AUmn۔.mw4bcn0!}q @; Xy)?7ѾgїIsGmKԾ|4lWR %#E P[qC[aWOe.qzٹo?UkJ4-|AYݜ~n4eU?hP¢I9_k:N@Ç^-R{~='ِv8k-[Eٮi+ J6 X ̶SٵR+8z8~$e⹍FV4D_*Tw kU4]пӛAaOC*Z!Ljr*%O$zlEMO fx ~tzI70pކ a[Sky\ }nC.u/C$>` )wq{Op!&g/m4+,Kp447 |i\%^'!ҽ{]AR@zQ pJ+m2r*eY}ۗ^ntLa"[|||7D`ޫ ӆQ8J<\m&8>*wr탻dU{^YdC|BrCV;U׵'AQ)YsW5@fӁ7~"|0_YK!Mx3 `dyK=ə^ EN~>w qw62[rJ,s9džvؿ[ Z ~FU LUlZe[LRy9p8$'BPOetޟ=p`^#xcKAD!<ĥq?4-HAV e/#G%'t7?bh^aczh9s<vHEe?ފQ&CJwbԲ͝!zKfv? 0AHG1ݻtϚ&H{\mMǹ"Gm&!r.M\ eJ}7]cG2e=e^ r:WD#GwߐF ()Hmf;.߸x}é_ 2%,v7GgCF/Ff%25NsUk׸; '*oGͪ;."n]}l  xSsU)5BܹKT uh7 y)Ʌd#i&%9SvBU|U?`_qyaH[;ƨJ.BەP`洄e&2(!B0v+U԰jz;P}!vA&ԸFpU'X򌶼gp>XjzxS*< ӱG.mD#26q[=NMt;{V!N_=4yyTBXk]ԉGO>JIw%ȋƊj|Xc]!jD Ύ_,KFoQTA뺱}@3v'|2z"/doF!$V{zim_(=.ZABxf*Z\Bt. (㱕s9'.z=m%u9NUfU(Pف%߁xac$a"׶LǰBj+%!jS(~ ̺_\fTrȦ$?P:@^Y6_-o{hrPbB)u Cb s@On;NIm0-[677Wx\I) ].S1"˧Y@M ZQy0 'JUr,NT: ]z3]h#@1 -rvF;\U l*[1drqVwZɓ$ kk$ZPߣy  q$f0B5X .WrM-@:OTLSbM& 9XWd(mÌQ`ߏ kHt&!q=52ѐHIyc"gG2$9(W'u0P\fLF^R-l6S9r rCa$Ϣ`hlrM m>*Ͷ]"@-Vay{4kh#+q`6:ύ|0'Z(1p܎.pY1y jBP&` YT;lߟ %p0b6 ' Gj嘨IWze B|hƜ@{2eäEpv'񓩌 ZQ Q3M_ԑgs1wo!ZU=FVLj3=͌|nF(?-{rƢp};rXVg bUbԲҎ*s_AjnԎ^:|t8GL41L9Rmlx\L T YLT.];w5 YpI兛|极.yw5+! JUf&/Jӛ4]dDp~0Wr/{jƶnXewfA@y|Œ6l*,[SdU,sJ0pK8MEF N|Tj-c;e#c(KA%WD4@/#+bo\j4[8EQe!I7$ԷMY=( Fp-K.]k3y/tU煙&"p)Ҵ4]0&M[k.;*W7;?۱~ZIYD{>uEwCزhQTP|հf1H<` U*CdcG”Lt5Ta솽yo $3ۀ^W: \dx4)Q6MI9%\UUʖ3='dn/!X;}X*a "G><"S rn%X ?TI.p/CJŵЁcs6 Y'UrA KcH,,";֭y 2c{SPJd [+>7h~m~LYl*KF|} {|CPPh%W~>LQYq 62 *MoFB[eJPgG wq~Rrד_Tq:4 ?6\YM(XJ9s)k͋^u+T)%Cm:r͏$]:1-Ùk uC;2~E|-NZNh5m_ l̕TN,vT8NI M>K"XŢu݉Ոm؄dϰb}ifȆ`$ E* bZf;@b1\[o}{ɹE.;ˈuEIabgO̤hNȓ'*|L{_/Urm.V&׀o7N5[YP-3(yzc}@n"3|߰ 9Pܖ/%P%Pၦ{Y%+E5?p#?ڒҕGI 7rЀj;bDK\IfNT)͹'}QuS@Hb`-f7E\ 6ؾ-k:WNHR7 мJ%="u}Z{ '4QI:7yD<@){+yCފ5-Las5L{҇p% a&AbR&2!]?\} ]ꈓbjӖ9Ӽ'ڬ#I_f gOQ񄉏 n2$|%0I0;8bW.:F^&KG!'~@)U\ЄD_R_T}5Ћ$(y"H`:+esj]a,eDqͯLӖmqH]&ʿ.#䙭][kA.!r~f`g笂mttjNQgT&jRo ӒU0zQ,׾Gy'?"誳0{BL3(z-j4tND ao]S|L a㳅EY HZ :8Z1$~ڵ!8 U J=9a eUW+m\S |[1ai1;crCFHٿz/Ǖ_.N|Z 5.Rȇ5)=F/KijңQU}R?9tx>n' [B |hjS:6WA5yO8=Lif0D/ /eA?h#y۪dPjh.hzpj7N%o5^yRJsdC4l݃!kI!!BTYՀ @R"3VضwaKLv4K{'xQ{/MXZ; *qvr<=Щx|g03oUk 9 D?,LJE} g%.=m@4,'F,DrRP"mv X{:糛T'- ا&FKx]|H^eYnL\'8)+lv5g{kv%/~Jz@o-bL<1F\u5G2_ ]blt]5?.Oӟ77H򳈤$wZ QFйK%k9BE>*iLݴͧty6no5Jֈ+P.'\ sMÄ.O\fSqC#c]z2rm2JCRRիLϖǥTգ?OE܀uoSyO{z}PK q]]RT:*` {(w2p/Z/iN65|DЉ oT&o<$H ! *X\;@0Dž\Ȍ4 Uf_DIY /oLό^UCZ2yxqʿJF<oO0(_f <*CmB:Kݺ*c ZQ٫E%ŸP:J0!I*!\1jV`Z/s_ gW~ ;AK|BcKb`Ϳ-ۏLp2+z`O.' wct~r#8Um3-mG+ gЈK*n<'Pj ZJ==pTXnPk[4-.~)оLòWbRhQh1 "G3xOW u_FQ>A5H ^-֗jz2`^ztN) 9b עcmF9SECd1]jlMڏ%*X^:#6착'%HA;0JmQO/KAǔRMvi0e`NtD&mJqճnUpc'wflM9Wd m4&bzw  _m^˘|:oҩ; !F?j6{nyYP$ȧ{æhpBœΠ0$iT B嘺MDԋn2>905WhyWi"?0 ^Qz_" ]\:7^Y[ -^3xjYǪC_ B6g] aM;ړLZKVhdO~î?&$$_Njȭ۩3)%mH{O:zO v %O^zኡ@'g4ezXY<'9F-I0]zG{C+?o"́+okN@?_$GLJ4ذd.qqC >jb{9Mp"`PW4~{;I2Eo/=4[H@U#4KN_$RE9 "7|s}@yZ"Kob-bsB<P%alj tE\9x`t"[bT#&{&ǥoU .YhSwPdԱhdܳb@cw6G 3ՂĿVNo]U1 RnYx8$P Qp5$*>)ܐ˽H *@ Ȏ@sQCSn ]ܸ0lPRs, *8=F%E*O2Jv0ner¦x|ć].G<*P4яWD9^@41y%5尛>OyoCmmnփUK ;aַEHo#,ɢҪLT8 v f굕'hMWæbgX'O^sݿ=M]܎}"W2PHt:hݦvSʨ/-eN \CRL;zԈNfp@T/D!0 |P@%/[w[կ|7w$*Y_Y9EmLO{jTކp(c4+l4-`V@(Ha٤ RRHSw Vy8 +MLΩ]C w҇٪|x)$u5aBhKPW:6L|ZOc*?k;z^OI[("PTyXt 1O%ȉ3hĝv7ϙ!l0kҨ{?MWdqO@kgd$ZH#8?j}'.;D+F ;AYYGh/DGX@`?f`Qߧ2m#N.ޙH-J\Y8T JOr )s= Wz?F]#jFΥ;sr:]%E\zܦp GZv*@My[vf6Rw<,nD@ ,(ZKx 6 t4wj>ItUw~/aDƍXm)ol QhOTܮd`aEkЍYЮa8"j \$g#WV(>5d?{$qh(2"hWN =!],Ŭٸg≢5s}&4=#G̶-[ZZ(dV`_(ö:ƅ\zynh|(Κ1ǧ'+ѓ3;O'6f@|~jj?q]ƽij`WrҎ܄QԵ,;,d9ARߡB[3;@2rNK?l '%%+P4@DEڢȶǽ &'sIE.( ?-^YZYj9e3 ͸3$2\vEЈS?QMN)8̈́v~75"Ԥtq _TSQuz r2ϫ3~X .t PO, CWVSU 2Ljґǰ<=}.19k@Qd [z!&[پ݆mRPg%,͛l q-B0wWԖo5DX|ާ4t؛ 603oIZKe3nav;.ӈ8h?['*`ӫLp uUn!34ŸȐ b* 5' [˓鋀[+& XwuyCHۏ9n<>/tDRzK͒{ywœ%0{y;n;|ol s~5<C )5̎sL~iC%wPD0no Oo\}[A-̫^2W 9ɝ g%uLҭPtuYwGT+*R,>)Kg/^ Dy}Lx;?S>U}3RKHR*&KokJ| pY%v>|/1ӽq-9=Æ1Ypx3=rj8d! }⥮U: ~A㣸m<'|sݧ)*]= H߭2؟٧<U *9{V~WE 4^/Br [A9<%ըcI@ŮLoD$Ȳ{[u`~nN`g%1u[[]!%aTیgH%q;ξeIQc4:n{uZNo3YYYr먛l{˜'+B"Ve|i'Yؓd9(دڭ4M%BFTh#[q}~3XBϟt^& R=ZQCk%[SSZ9_?'js󸱮 C:RbC>lаY~"M0 ܾdPcCߊ[Ǎp/Z[9`,6te[\T~m1B'9`%nP:(qLd/7Zԇ: )7kj(lX(@ֲ)Zn}e;2 /Me M|~-[>/tu7+FE{2>Pb\l|A p,0hA(^`7Cw-uiȍWQѹc (@m)@\;`p;W,'D#'2U8\OEn l%l?}.sz#e` TM"O y`"~W ^#_Ijx eZoh5:db+p<1vfI$( T嶈sq"1R AO۲jnѣ?4? z3om8qhv _m]VU[{] iY,'Kc.(mQEq jr_=' c JQP`^D@9b!K~ |KbY7mBTQW,Nu TQvҙxš3k>vbV#4-|#T! JT92QoF% %q.3Pc%#(m>ׂ1\Ѥ|YJ+?*DT{U 2oN̰Nu;Q58V>nc 3N%FX}>=^4H:8i) ~SuBO74;8w,B6v`OdI^pC]GH34F.x[`~ 8CDLlh `Ї晹wjdD`࿫D^buf+zqI|; LMPJ, %p.KnSqgHxum`]2*֥ղb۹}Rڂ&B턇U Ewﱹ-~]9oWr0l4sj TI+BvHAR)ðwQPwpHW U/A%-K_qm " do?!9TF\DڟdBZ?yéCaDQ/M+_}hP3,$8I8J%S2 .4wm81?7щhbJ%R,`Jc;H9ݣ 4-"+rnM?+'V28?m?fNgxA AfJ}^[mG5nMrK?NHc@k>3N;}ź sVlrэ.;>oKp0 4ܯD*Һc7Q7]ymkb;+:<9Odſ/M>mT)^ca& ?e.}Qմ8N|H"Qd ^<\C|"B+`4'"^#)\@){V7ddȝNJqPEB ,mtF\^iGskt>̠O ڌil>G/)E9?,Qgjf`$8s/ڸ*po DI/T'ó YJs( Zr)q eVਹdN/G_i7yn$AZfa,К]@vV[ڷ&YNE7_3t uxRXvKcg_I>t?fUNL2y :OS<c؝[?#e6`] Rޅᔤoy%a0udd̎o;u +ozan~Ҙ8sPUK!n#k G3_]TR`~'K'6ku]HW3LʋG &Y92 ,g{j{⽌KW+I,PjjyܼЁSB.q>vunxqUL9#Q&$^KV=]jm@B$,ڧJ bss3I.?5xm!j<)} %A2.JGD] ]m1W9B9No'w_Hu9&yTy&ݹ[8~"/Q٥q^$EMdlp1$=K ᨊ͂򿗋=«;At&0Wa֥+ʹʚ̨GkUJ;i וqfdI5~.`p2P)ם--76zQ~r٘^s 15ԝFF 9T$YN00ez9ۏ;5/p5g> 10sp8?7%RsWSQu:g`9; Es4qV;;1;7QehρVp>Q'g_5ʈzq~Ex/QӿS"El=uNL)Puo^Ʀg55p ];'lNlz6h&$DrIw7?Ϲ6HaVAK4y7%Wo}Z$)O)0;:4hl'ɩXWCkRp0גG6m(A3m1xR.wm#K_!bF y}~] ;|['J&"K.7s%L! %۶h+8a&'%F%.!MW/d8@ꯆ4B, jP93y 74Ufk%}G ż̩+nnX&z9-ԩ)ZmA_ʿ.Ar#6*qLC*G:u /+8DUuSBy1LIk,&QW05LBlC)Gd1'NʎdҀMe/x }e:"2eZ ]q@׈;Qz 2UÙ;)cy/i]ָ0]/0;L&#UP Ͽ^mo6hׄBԸQ!E<~"\˧(Ƙsqs2FRfVA`o-T[Y# %o/0I,|9RCQfڷbQ5 :Sv@`M<`eUhZf 1kg@ux5*j{ddT:BJfF% S`^@ !BD`Sy>}&M ~[L"SoȄE[pnt5Bm "qx<`z {'CycmUL,m_vT~+9_ hątSo$Iý6{ HS,om s5]f}\t3m͢~L' 0W, !~[rҿHFl(@m-f'Wq[<$lV)m*(裙u+x"`ds=_4`ΟN/LhNצCrۺ eÊO2/?`*.R ح%,^7J^N@DpױB7 |4 h5LHJ'\U U/1Vgb.CY22[D(! saPrGz %"Bvv&&q EP.VPp^I~u*\Sgt(؏Iz:Zg}$B\NNJ|4y2]k9#FQ(=+n\ۦP56-)fY;gr58A^lW"xj%YХj5c<' _f!dT Mf1ʙ ²㷦/E# <ſcU(? wCSJFSXSwc Ō(aBMnԑe %SN>VB*@X*O[Ba:S#=ൊ$1W/N[m8VzD3I}'DMo!$]ЖFd%c^Y 'Eb4c'PR jٰ7 L(!c z\r>s)bݵS%I^BtOty@p7<ۄC7D>5QE@ lW#M@@d :Zc@ݒACp󃺼OTl#R%V}2DI cw)~ך1Q XM[E\˫I Gq(q!v2F*Q"ɷٍu o&};`;uTVi+[0;8L]î۾Bu!oGSU9#kl8d|Xm4O!e%6=7)bfyUeMS q-4b_4Xoj$/k,<5 ݊&d۶yj&?F1+&3}y>h^^c'0[?2(YMǗp1SIFSδZ=̹\N I4O9'u 1@Z-P}6k+;2YEg Fξ%`䚾A 99 Ft}o<gܣ!JSXbUߗ&<{BO  V9+٭.ý|ոѼaԤX` t׏55oAO < 䊒JW74*oht-e[vW;ks\ojsU|r74>sunLǹ|`4sW~9ᒽ-!؝a W(=X{tsE4|E[C h{+|4.i*}Uor`\Lp6>$σNِ%ekǁO{kKBKUG \7C#%'נuxT@pBUa- V#:i7@sP7və6.97? SK"`4y`'=Y]60N%%]%nm'T ་070x${ MCgq 7_k(ͯ'I1V* [ 09GQA<4~f١W= m!saD悅߯#ɵDo\&:/UzK)bx4lYӟ?̱G4#GNp9%OY$}Hj14}=;(+;{Bx̀' 6g5tb$! GIda n4D|uWW'\t7K(; ӱ¿Bp(  5|qzc6oϮ+cYgQ&f✬ 3*+NŇ'hO=ׂ^x1LkI9t(|I~_0w‡'MYۣ̑_ޔOQ9LѹK?CZVg]`Wzt{|}|xΞJɏ 2"+4i;`ًsr'S%o[*/ Y{f]1oDoCav*?a36myfQ?Ϙ(,1xz)kӓNc}|wW+}3yY-ܒ_q_Kݐy'tQaBG-ங/- "}RK7#]ֆyEY>Kz_e{w]3VYAW"?#lЪezAǟs43Q(Owl+gr%./.nk %p s:9Ecl5B*Oe=t}&v{г %`vP(s!Q_$.8#h=zM%!L⯛tH4&}{,;PM60JRooIQgǘOJCO^u~P[i3 :2]hYaw32mta',uD5e_UM%zi+,w$k.[GΑ,.'Ԉu%׃f^z 1[ylNӟ#\mnҟǾQ/^h,6Y5+^{5gແw@oֶq`BB^Z]0*R@U0Vx6EuE*bKi cmo萿WɦBl:f4# :W XXr :ڟvEDs _wqF[ C4{qD`ġ:B1g-03i&,3iۋt?R9@:s7p oY[#(JX#+YTs##L,\]@"|atm+@ӵA0ztG9ĠsC>/R\#W }&X,]~ auڍ_}+V&:̡\J֘IdQ(BUWS CvIFF$@ b.I7fԅ,vz8Ry1QnX7HT<% e|8 L.g mtYO}x<]?3B'"b.p̱.3ȑ-[ lH*:Mþѵ*מw?ZzJ2E*W1vy[Рk0+WgUZ7} ŗBЋ;Ǒe? ٜhAhQj2|dcңX8m' "Q"'GDG-'xs-0.Kp;IA 0, n7dxo/Y0sewgM>1mIt2.C|+nBGpSz%5`Pȯ@a\=QIfMt8N1a+@mF0]4N2%^*gpT']ktk,i>kԉƳd(;U<娌4EB c8L^_go_CCOȆO?K ! <I#MJޯD(re Ez3ca'Kch"-Ivc񟤈i_aV b\s,HK/kFߚ;n%&W"㳨%2_جM@%74{1 Ӎ6 2=hDo/PBtM_%t+f$$c QV,`p~4a<"Br/c4B' >&ZҤ!݃9 "|w=N0 s@R"{1}jJ65F{]ս?ՀygّtwxE*HR2кj5tqptNгqC(4s`J.gPwx/40U6D г<]8 B 0Qg!`ȸd}sI8R袈08N"|~v".%Rnyt9xK:}jϋfb2#T)Ѕ)r׽`u[4A7L+{W%hWƳ ēB4!oV2DN4zA Fl= tX۫2?Z8WRQ|ʀA]=Q{Ne}>B+*SAC Y3C Rx`qn]gAJ=((80Ndlko}7F ȃK 5J#VrE5}}" L!>qQR7-oUWubQY*E`F#͝8fJJrk t` ZARgtK-(ꉙD}8}Kp8D`^>r$(]ӥۛA_6 ii רb~F3e7j<™qt߅`dTX@ᨠ~~8Ʀ0=`2l>~þ71Z+=.=cjo7W)Z!"+`2.J&;PdA bw|}p;aķ/aFm1V0#I )2Y 9غ#kycUjYrO2p-*&՞d5}.GvӚ N$$ *9ʞ-}q)xeUNu<Oc ~n$=vho+.G!􄮤-{2wPjT\p$V5+_,ïl!WW|*!%޷qA̩sl̋폦E(tH[Nay\:Ss/|wi pPv&>j:3OR·JɷsUYWGQ09GnVAwvF%6C~zlhEp4Y_ģE8 өGnؗe5gGA N1y @q#Ҽ` 2U3>mxY N9OU\5nY9>],'Ԁ   ~ią 픱sp\Y{<YPD8%qK'bS v (7?ތ;d^H!upr5qCTzk8eQcrZO p35lz.jǖgܕ3jTirD2>놟Jw<|hMCj I1G3GC,Ԙ&F[PVó XtG!ж12`^2C0 lJrIKloRpOmCPDLt;ptZu|2yhTaS7i0hE̤>o*E9-/h~ b'@[rdkӇGջn5 #Y ܣoh+f =[ ? Nw4hϞH>7.6ZInCY5fX e_#6}.p 5:t1&=C5'jHLP4'a2WW|M 'u*"`l0RqxHd`!te/Z34s> _>8-ٹ%vyO3EĘ~/C£5o)U{k򵐜D$]ٱ\t^c |; 8`*b~4"uýcHhvmPa%EhH9Nbqԋ]1!C}7Ѭ?v'P [[ }+'1ZQǿ ScLve20 βrfwJ?0' 2̯\ShkFq}rƺmƴhr7\]սE0.MtְaN~?fM֨VAB396ڛ'd!D`=?$E͈TUٝ{~z fpBiUjμiq}@~|QA2im}_=_6NǞC~>H1/P0g0tTdw&E@ADŽ۠&GZyz?AXU2ҨoFɴ# 0Je"4ҸWf2VVԆ0WXlU}&q:6LPS&acsx]q 5Vr)KJ|]ؾNQ[lxw1lPdH2;gt֐+o#n(Z}b'ߺ+n!˞79[RЖ'7hJrIJK8a8!PWr >̯8m2;C>ſAC]m焂׽V-S"4C.%$X6ʃXZ 4j'~BkmŁW&y2Y;:vAST; J`Kf蚖Z6k4@ *!Zg;$ ^#)u =>/wل{@6si< fId+t@nHO9%s#K8,DMS~tQGYsSL7iLqß{MU}g4@lGlo~uTuev$=VZEk%/)$ߕBg/ "[\t:;~b`asHm:.'2V5Y;W61c 5mt imgZu*C( !ˠj|UP~QE$spUw)[M١4yym Vkb6tK@oyө>ƀ Kz}r^Y(${"xa-gb.ھjՒ(~Fj&T8wS^q߹\ȵp//4$z@Sm |ա#[Q{Ż],t,'] L{YNWN]5 ~,Q}A5Y"Uǀ9R^We˼/mMEymC׮]MOqw_UGoH јㆩ .>5c}|(vP \PJ4ac/} wDʝEiQc!+[j?uIV҆A{-9#T`:L.jw;Z C%^n:襪yD<5\M0N@>3VSX~P+`p.&mtN}+FwD|G#:5Z8d\(iHD9ee0y ApWBn;|d>O>iULJqg / lYw5 _~-tygwUQ]y7O CE-8#VBj߅PERgc+%I6M@g7Vj1͔N/R- eySe֯Cz)9M9PډnN[ɅVZ1k>ukXZkJbWH$vOpåx8́>GS6A9W(rT!%Vwo% g9zEMO@݈O|qLRbz0w nF"iT giIB0On$ȥ~QR$-#3j%&gE'V!4j^0", ] 2pDzT!.vޯ-CmPZ1=˰4/ Dz;$9<+9zd|1p.ZOPcx]i5q2[@qk' -)'T'DzÇ<em VMCv$90oX&<®SqM J]KdV/d/˩aĢ{ enbE*N0\!bTCy-iM= Txjr$Ƌ,*k {t߉d{'LXi߻@p8iR'Z  x2~ qlȍ\"Rߵ9R#ꈟ%p%wٿ?9yUY27|g˱jmnNrH:+ uSٗM{8R0Xoc;o౉c4p0H98B4J|X$;VaW2gAwYMϗ ! jOey=U>Fb.<a쐑QPLIJ'<˽XeAT̂XR{E֕(_B#;oFzx݈ŬHQva)C{mV!uCa 2(tuNa*L T6iBB8/eCKZ?/)ChcY/HfH ^?UVen)p4Wf$TgE dlf P#U@S(L{3 A}r+A^G :[n:oQ? XUs0}%Z}LĔvF`t9Uϲrl k&o T]iPt avl94@UQۛSz75U2`NF?]ݖ[Yw ׎ ?3LȤ)fu돺ڒEqt[3]E`-}S Ye(\c)9&%JbҨK5B(G,IUZԑ !8VG.4*ÓD̈́13Xajb== M6{q/VGC֥:G"z )w|Tk]l,p>yyax~{]Nq9UT^:7촷ꤻ Eq-d@\\)pbFvQJ6i(6^;Jj3a8״ HzDPIĿ qdB2=NB)b{سF }:D(rXݔSF<9\`11 OpgQ`0BZQqGp;1UϸN: | ڱgP| ]iU 3~i8{17dSfeip6( .Z|,8a<.9v3o4\w)۠v j0UƪǸεU>0H|lmׯT,j2+aƯ`;KN-^.74Pɵ&}|6Rٍhl k%Nz}#Z}׋8$ 8AB5WWIʏDF6C}HDW:<&.+RD:Th~EK{yCHg#P 3y?f+P٤+K"p@0H_9 7<5 Vlu֪8` '&-1KnQ8Q) ѡ"eH4H14pAPh.?\ȡ$2)K:1 (aVNGrEgh1m%'ZCn Ƣ)Q8psC>qe /rA+trk{}i}#0xB=13c@P+btmּX(pޞr Q(nmTH+xʍ~l5smwQzɸ;y3uL.6f|]pg ̹VRyfd_ z\ts)/n]0g'Xd UCk ?&9", NP`Jg1Q lfW͠ A!u1f+Za >H8 eeaIKw|%P荕}XT3B4i?E P6#c[EAeQL}@Q=^5k|Mڟ V -5`/tCZ ,='Gx"SaI„ԇBxjZAN#  . 3heF_8wrXvNefIu%asF}ݷ\zj/LYkjѬĐ{o%]V.YG2=4*JSk#yָ #TJ$g 'W)Jb(WHçWؖׄ&]x"d=tPIXHVl~;{A,BBQb4"6ܽ,L#4^f=עWtjس۹9j#^6v:|F?Eo9L')J ? W"l^DACgd!mIH(rHy pdQ'P-gY/#?k79E=2M始#̟HdP!+%^\2q/'7[m7n/>0=aGyN=̋''f= N蝪t\`x[!rj*_AxPtf#ywO!GxwRФ&mB+cZ;8Dz! :H -D}HKΒO5ډ~IwY[{sY6A~\N[rGiV] KLAIo )<"pO"u˿"D--/CwU5bXa0ydڰAM?/{zиUL7Dv}gxz#= ;#;q8lH%YeoKt |$ʨU?n>HI"SkOS0Wԭt)S(MR׾e--4EOv ď!dkR_.VǓlueԄ#yb.\zv͔3HR!ﮓ(Yf=b\)ӻ]4g3HVVA\0֩RHXdLJJIԣe? )k;Ⱛ0qdoy2Lgɉ?##@Dg2x+uscr<* q˕N1 G3j[nAU q!0n$IQ߿cƀUp/cx:UVf2ʊ\Tȫ9͡5qd;RJk2}K@ps}2I#-7u~թhOP'FasY}Eue<y9O1~D;Oȳz 0 'U_ SH8BN4-# 'Y)7,ا@2ηDnX+x_`=ml0u`{38_,s0JLy3f%?gaqA:'In8vl o9% E*%3o<OwhX3)6YC'!.ږ./WcGaldӎAe>BmkILB_}w+L4+Ml$ ]+Gp;7:eݞy!0X1줆خ;Y&v2.t[uuYCkmO@mϷ aaFl [57Es)8KYy%m;<S4ͦHM .`C%FWuiǼ6eIy0߈gEAC xjMfIE%ډegR2􇧰j coVopݷ o]%vQw}ŞLEY|묬z6n))N_$RtD8qyv>1w~;'LnH80{HϪ) uA:xwW?`=lұ^b|hKzVdB*ZgEb-J`4]]3Z*A2ڦL\71?RVػŇ "btT@o':%1D! k@[V,\#Rm@At 鳪f>ߎkf*\k,~ Ne-!ȲΉ;?9\jk[PL?4+QuX:dN7 mL< T4 cU"M>vHZ_T:h,c (ma&拘X\ PdGeUO׌2)pTatr1 \:KMHxx2s +VH @V=Nqnwe}Pi=fNɉi c~alYF:X?rW&L_MH>_ V0~-LVrVB1U͎jN"½yqlT;0 ?E^&XL!~$z5-󴎑o?v8M)qa%6 )S)Gh GlhYxI2%a\^ *=MPt+Tt8UN~&8An\dF}rEebcqdKp,z0cKlroU[G*?2yAzlneP, fZХW$lAN$hݭ=oqt+Rľ%>sxػxg?bA,m(RkD|ҙGiT*;Cء8aO޳Ջ!.~>@5+&1x~]"F$מscj ]FkϿ ^uqXr}2xWk`T|T۵gWo)Jq{V& (E,И^4jOPSud yYo+%2T',qqȒN~-Qc03{aˠ*|S)7@(Ѱ%CSu)HçnN/SD(0 S]mM-܄4h#_pI kaFf a ]OΌ6bzuSðHʸǎ;"!_[ٞ$0thca(MNpɸSKAԮ1߻%^),ze}+Am2'??6FV ޚ`Ĵ9[쫬|;!`r}=-Š,S;<69yD҂<~/%{"8ڈPųAg+iM # {IRi t6>kh60 -y.YUQv &.ǠQK2`*wcI{MɈ,{e֕jg FQJ=fvǝC!NNG*ӻC4$ʭ)AC ǬІsllt7->B3o1 %;5>=κW>DرȂ]F`%b .9^({{ˍC8 S gXtk5cjBFoȺވq@W*5~)Bӑ=IJF$?XRXRΘSrBjIK|/K6)mו`ῒw]ϙGj\7&ukrhMMH@:`H^So) &mcSLJ >SrDYI8]֘t6=L~5S:&X47I몽/-OrufgBӉԉ|NXYWe BE)Rɺ6! SW(Zƥ'!؊i&-7nMWYhi0fpŖ9灯sѾM$Dp&};>ΡZh}GkN1z ,7.Ng /\&"Ƕtn T46bm #=ˈC/[[鯖D]t@2LAzjOPhE vp MD)"F=v`` CU4pO{ ;>O9ޮ^!?&yRk'ɚpAgŸ%Gbm4Ju1Ӱ>y~gynN wMc`Lw=TVQ;K6jH~Hc}a D[ )g*ZYzq+&DҶD>2O;Qpy lMsP-X۟Ӭ;IVnVS!Q8)]|x~|>˄>~- P>VrZG6NJP CEUE:j.̉PAP\ԡk T ږ|2g_z0DoKԠ#cTKW0QBFvzj:+j}MN8@K 4@) -_4PE;)rՒ^;Zx"5| l=  ۠>NxB8w h#tecC jfBpoA=<߆LgD^~BmRp#XçQQ~t:Xd≕eM.\*?&sp.P)=>oUPt x! vPdPXB{[Рz1 ojBt?c@٨:_Wf>/*3#^RpȨ}&Q,N%'6] MP^wm8`T4z,^LǍNIRK~譧g&V7yM,;_ *&.80f)3icbFP9S .C,lu%Gi=CF׷4gVQYtf3Ef[Y*\8nRi@v/xo =ozYg;kX 冗cw~y!TlgtמGABI :}f:RY\z9F~%+eoy{-S?D2Q&pZZb83*-og4?I(“yfjWzw{O-H~v}tjqcMlJZ Cݩb@BoWwB]J$ӒS."(#JT749! ˩fe,\,&f Zs;%Ā,r+{Y!ƨ%c1x۳Ah`ި8?zTS|=2SH7wN'U]O-J$XXm"h pPbG# 5.{A6C:7Rģf[h'I=K(u^& 8y>wRrpXF5pTf{ 3֤5HħDod?*X|lOvo5 ]q$5n4K ^-3d^Ƈ9zP& vɾѓ0!uU?/xDSQOGګ'D~Ew6׬MRxlӭX١"眈5^ޣY,tE0,yeZo|Mg; w`{.'gV3W,+áҬ,D[N nd1}Ra(҉q (jvm|Enfc'wH8hah=W`p"Mc*J绦kz˺7'lm1rPDzXU$GC]ˍu%!;s9@ۗVLtRx؝F\-)*ܗ/;=Z\&~^#Ӧ0$&Vȋ^EW{ Pa(796µ,)Yʘƀ$ٍI{Uotol]_lYM,Gh۠VLbÌ}0fܦ|uLR O`w Zy?ߣ+3*dSA\=!W )5\5w"$ih׼`I/됩9k'4(qeXVSaL lVuꕔ-4)Mh3ZVW}p\YwƝ -!4{M~wh"wwycdhf~5 r ѩ̬T'c0yq[)]cI(>L1?;Y"MU 9?߽,ylH[(Hձlяţ0=AEew<,MgI.՗Kb@mvfuux!),;s%QOH+h[U_Kaڣ!˘ZD9F"uMM߇D*8Q&BAJx~Kq_1j0Ɲ.Ϣk: wB}c,sΰ4lkѶU lNomS e;ƹ>}="(f<%^ 6*28cI &goN-ӈlR!gռזy1Щ6tY?R+Ns6KElRwP4R½]^yy|gƣS/GXBpO$KNIr-VݹlAlG+nlf~[^/ûsnynhSMHFL mOlS7 |]7Y6Bg斪~XǢk9 '-/hI+QwdQӲwm%Z w璞M[]9j~x#xnJt2V577N 1ӯz DħWN2`ςE4AT2&FH >6uvJZCmބ$E]~rg|P 06fuzcoMMM\'ԕKߺ<+^f{Q6EHi:o*] iPR=5g.Pk-,V4]@VzX7^u+٥oƮ)#.-éN_Δ "FiY})J0$Tq9huqoVEf7yAx5s7;2hm@¡Wk醚}-ٴ.ᦼg[3}إ HHЛaPg!22r9\.VMk)ꔋÿu-E3"'nE`nRw -mRC~x\s]֢ rNVjehfB_F_ou[wbP?o'~Swt / JM1pOͭm|K'7nmf~jmNTmNztٍ m>G] e3jOx>wշ84ɰ(lsh1Sr<}%nreM8vrH\nf/UY:OYNKbz &Pp5w#h<i`D$A_b0cAV4@J O 1丢JcfQOS05(#0E\ `*zd 6-=,"\c'Mf5P*@RBATĉ+t1wۃm&i\m$$  ,. u< e:zt]ͪX<]ڬ5SժRM:Zȵz*Ii=!!@y<{(561Ji:"Z+A,T5i[*Mo7=u-m㬄p:-vרA[ -Zuszn6%8yEum"6#zeIٟ@LMߕ:;E,)3]mx>cz,=VW>x62=uyY:U/ iu/|̈TXZ& `G8Ji}tV>*K:ձsgԾT[2 o:Fajz+o9=fNjW6v6>ok'FO C]GPqޫ]wWȪTHl;x^6y+);L[ÌpN]v@_<^9 ȁb 1)u,~J)om*SߡH{u3R$/wn`akxSJa "Zv HW!ףdd%tS>շv.>ヸ!9:r1uv;C`YNGR(w͗m#ֽrX'ΆL,۬R9yCRSN{Ġ~KODLK).}A337ѵy<q'@&aT)ܙhXW.$3VB3ix2w11N1V2=߄b):FLHd"xIOVvG+^\fʓA2f+"u=g܅^PI6VnOM56| {uf7vu»W $l$lktgF]m΍CZ[b;8G)}ۄ 40[A@(ix@˱jc1u .F>7y a\~F4kɤq\VbAB (Za@OLu:+^ 4'0n~!%"p>U<",ݳauNU}t$|!"9%nl yx?f ؓxkM ʻYgA=6n0)JJY6 c+TcyNdҞꍫe՜C׭h0<&;q EB{fo+LQZUG/{o-|k`ݑk0"09x$}-yp㰥b^Kf[KIf!ǙxD F0ѭG9UȄo[C 9yA>`]f%٤BfN]Fݰ˛Jv']8tO[K<\w/sшέ$E=w |?a5I9yK@lMKE~ʥhf4zWJެ֗Ft)^YV/Yob-;AwsIxݨpO czjT M=EXu꺅Z|vmFLX9 b6Υud űDu\-ľ6ژ&L:5}l5~"d+N"ף1qLOjxw.x<ԐEt܎6H؄Yad? X<2*0"4Mg(B~mdH[Az#*P%:ww[}.\H+RmiLQI& Xdhdl#{#L\C]Ap|tl?"Dŵ_,e~RW?S./:xm 9|`sD,;m=a0V@̃p`܉zt;Gzӄh w~(-ԉ- 4!-qۦ`N[oL~$8*`;OkLA%@_'Qfݲw=Hg >}BFGcŬAe@|mv9q-h$S&R+nV! ǒuiy$xl.8Fdo*^bKh=%X D:aw.H\^ZqRO2D֍n ,cX 26v/ [:qj_BRWe ΄909?s /+`Z:3dbՉYɔU loޜ9;ˋ)ّ ?LRj*Kq%3G <*5[Rq|)㹫7μtȍ>u..G> ,ecQ!n 6.&KU| eq 5vW^tlc!yc'R]Df1N7R5ȉ=qtvrh#xX S҉w&h;EJ]멷/ON_x+\ 7;$-_ m70@ևG)^vfa}r@; KM<넬)$-%YW ^y oM{H@%8MxB>5!QrCZ+%7p!b٤ 0=vHc/Vp&O\|S# |+p >Ԍ5P>. ]:bxzc.uxuΟCSc &]7=WՀtiZ MG$BӋ`n2A?4JBf՛θ8+QIta˷%ENݣJ{A^1atc[e{#$2&Aj MTCa`G!?79U<)+ >pVl ӖY-xmA-Hl1Pm}bn< eԷ$ӤAuGTTp0Ω;y:#[՞/ʐ&c!ă[ oS;gG"V[޻L%*h N6U_<_Qkt3Hlj"0C)B EEH"#}؀[;ea_p-`gqdtP5|PN jWxk˕Ff%)CIf%Fc>(22&>B|F8_4n^p~ŻM.x- aW )+M.@5N둿,V0:+)q3CNf':r61̏Z%'-H ;'n2.yw6 FA|D#\h]'"gO2MHwwğ-\9sXs*A%zs JC9}I@4HaO}X$WO9eȭn .x7FIaɟ/'p595\y NNkZU4KTdqd[c\ zG'eAşDcD@q5O],,GIŚazys0CsJpx@ ? kp,NB"E@ ,@&&͐⮗$ʖ  TuFd#ln2u&P0^_]1膭~Q"N׌&8~;ЙqvmGv,ӖeB ~:[95[⣺\ M3ki&ۜ'nt +ﰫ i5J=hvEOe7Glu &ӚIA m!'G\GS`i3 1G wz+VypHZ)fRװ<ijwY?aA70ȡzcT! TV_j"[3\RmZ $GvQi}1JbݳKua2T:daTRF7 ,H]  ImA9Yej ֥5{0JLmN)FeߙL=#VGHN5V;@H54w N#َ7b~K jA}6Yj{#Klj##2ѩΊW<ta-ikH'̕uhNtRrB޺ܐrRh"HF_Y"?q]¡';@$n@:x(ͩ7eU9pha %}EeDVヤɠRv4|~ GGګb< $w2/^6o'(_1 } lSVr/ ${r[˹Tތ|k7[A~=L41yl?%.Aj*7 @tr)w1mjj'%g (Q>oﰿat אQU eTΧm\J )?_gHǚJ=^3ETeJɘ3Fvu,ǫjtg9cord')Nsֶ\/kydepV]kQQ7Oô;S"5'gf[W#X{Ֆs4nCϖUSAJ `3?ؕ\#8SThjlAu+ ,x(N&czՉr4^7Lqgwd{$kIC+k%3vg(}=>j7]m냜/*}dki9h2~гJ\PI 13QHWQ. 'T7hEKa3)LQj\<$G4?垢~6&rkgCGwؾ osΨ@/E㴿##`͞-5S/S454z={E'W7$jE7¡\cU g+#h@/:."]+QET,VrVOjz{L Vk"b.dFKqs$rŅ-2P7(DǫA[Gg\i8|/dN}!\BKuh2ο̩qC$jq|F/ތN)|MBRgEʩ[ d?>6)_cw"[np2(/]0!2z.QF/{Hgp M'R2!2c>A"rkp"h+!(0D1ʀMg!ews#YW{׭.u6zZ6^ZB=nYB!p{毁n! y?[گ!3lśĺ;"gr`+EZSC{%+=y3_UР%7WlbKPX+ S5]qi?aOo{:RǩxmoZ]+@ؒ3˔G@ѳ} a4ӏǭ;@a\yR=W80ǰ8R=ӑƈwE,nɸASU5[\N5.rGb@upP٣M25ː5ߞUȧ0#ʝX"/|Ïa ZY~sK}7 m6>8@8)0Wn Xc9BY>*dx<tÙS8)7D !pPc\_S^e{F H DkwJ_ㄭCoG%yDbNsffkR؜So^q|,2%Y<@n!,Qt0NN-5/[-Jk׏Ƣ ȩYok~<{QCn~\0\֤!'y^bZttL[PI^Qt(O1؝Q2'2;2Gw ebȜ`]dpyf dewH&O;Uhnx7Hꅙ5G'8^6c ,!ӬfM=)>SW:ݎ!391aVo4=;DwbIUȝm1Aث0lݞ5#xk &4vMX%ӣ{ o}h_H,5q]'()&$1L5]Q톔LQAF$յ5٪vR@ {v=UݚH {A(4y}iaK6 + :w1aY)*391zSĢD K +GÙ WSSYvW Ǽقdؐ)[}-\YUY3|*P2-6PL0gVExj4+K8N*M9 jř Pd[}3-XDT`Nt2v~kfk4]|#^NIym=tb9~~_H"-@!:$c ͅdvRׄ8 -I#}jDEq}Iu]WƐ嶴&\rf*`fO8ot^tY ב<ָU!w:8ѝ9M^=93zffIsSW_9ӯ63zO|'_%v%0V2v5@aSýwHO"ESs*t]ѤXĖW-fg QSޜ7k\l#|'C^61{ z\/Fke04o lZڨ Qy cS>iIdBMEzX#&Iݥ ;p|/ԡU0M7 O^+:1ّtMw9墽,t7L\*rl;dOn$@Q-QqbҀ5xQj2'KꚠVS8[krpV5仗(e R%^33q(0/vWnmn;Xv<ICsCHUڬd)]̅nqa"Վ/C;7ʫ7"jQ4Ǥјf8fQ^%wmƱ=3KS" ȉ~.xt ZTTEY9D6:XCWoc* "TY)0ypo.eh}[RkdţYҬMWG + Y*+7;>*q8.s(×F4,* suX,9l.1=SD:*97Ic;qb<8ISƝzy#˞Ս>޳evhnљ7ELg,{:Qr?i,|ʹ(0@a{͒m`0<cެ&QZJnިwIōFèӊZUdsqԢZM4v՛Ӈb,*jGqgNn - <~U]rIaF~]6?4֢Dt+?hkj:F=UHVAWjnܨjq3SKд8PTm@6sмŋĻo_0OX _˓υ޸x͉7ޜ {)ҙ V{ {|3=\#'sp3-/ϵRsyI <ˉw\