sssd-ad-2.9.1-2.el8 >  H    ?PTpd U]S~9M7e|iEFtOFaPaXTᲨQ愊iW ]Ȇ_t]MEbzkw v<+Sat;*N,pÇ}kI4.m$ܺƭHReeyF|vX}#K JfYFǗGz\$C^NqeX\tiG.vcUo'c@#,ЎM¶KJ]tQ}m=('ge+͆=EK[X+ rtr F׾T$'i.'*w&Ѳq`{mؿ ϷK>PE?d   2 ,IOX            @ |  4DDD ]D (89:gVG H8 Ih X|Y\ ] ^ bdeflt u v8w x yN48ILTgtx~Csssd-ad2.9.12.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.d8\aarch64-01.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxaarch64&'FPK9N>QCAAA큤d8Dd8Dd8Dd8Dd8 d8 d8Ddud7d7d7d79cb0d488e395c0a69bfd7ff6e5d4a777954b9ec3ef5ee4627a11886431dc115e756afafce04ee4e53b2be4a7f1e5880c77dca0cef76d77d62b13a2c5e90da1498ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90328ed8efb8ab1770bea33a9ed00af0af67c9f00ce293e4a22b9fa5a889c8e808b8117a84ba16d7bcce751710594a62e35a9662d245bff8f8bf582e9a5a1bc7e430045765c8a3cd8aa4f0ca9e7838d3af50e1800e3738d6d5975ca436f5bf1a28a59b5325e7f676d8682ddbf41cc23dcaefd3f7c19c72756e869d8102cd8a60dbf../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.1-2.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.1-2.el82.9.1-2.el83.0.4-14.6.0-14.0-15.2-14.18.4-0.el82.9.1-2.el82.9.1-2.el82.9.1-2.el8sssd1.10.0-8.beta24.14.3dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.1-2.el82.9.1-2.el8 .build-ida9526729cbc44f54aa0b8440c8d3845a57f7afeaa321337caf6b22ed7ceab1032c0d14b9619f80libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/a9//usr/lib/.build-id/d2//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d2a321337caf6b22ed7ceab1032c0d14b9619f80, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=a9526729cbc44f54aa0b8440c8d3845a57f7afea, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR9RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R:RR RR!RR(R,RR+R8R5R R-R4R/RRR>RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR>adclibind-utilssssd-winbind-idmap2.9.1-2.el8utf-886f210546d27cb7500666a178b65ff455364dc27e35b93b8be958453e1ab7dbc?7zXZ !#,] b2u jӫ`(y/XCX(;7 R4Ӻ7~Ծ}`6-Tٍ{{ÍMtU[gTp;sin(Rf 1jIN93ӄ-7Ѧ^#l{B+D_Vk( ӷC,Lzmߓg9 yk2! \(8ފPK"`yM+E q_XbydfʅhFb98}TXq\yd]\WéѾVJ >\I8`nOe3GxN_a]51E;nەaωCZIR:ƍ8+H30b&k)^3t~!&(V>- ;r|@ f?xf+^=Rt M(bqI$Ͼo#8¶qX|F RZ;+&3 3f;b:|J"?MwtUC&[xp Y\/!WO:2_3߲}}!r|..wcհjc?fPm0y@ S2$cGj.ڇA42#

S^Uv(NږZµZmlf[>D.?r{7;!M8%LoWס*@5׾He{ 4C1>8y-Qqc|HN]EY"9&gL xoNב}Ƅ8o;>1U$M5o\E4ʢϣk e"#ٚ͊S hZޠTs^wdf[4{+xޥ'a? ݏH`B!EUC 5l6O8ax@$Е((W1l.=eW.&40Pz'l9 9DfHj= *{A.s߽DDڿ> .l,y4ԳvTTڜx4 slO痯R-4 1-eJ|bx< צL88ws5GZ,YuI 5}b0d.[7"aG\=7E?GSc'OqζX*^n^ ۍwn5ݮ,Gn9`Ga  Zj* k1%:ŤPYRzc_ѝNuACpя bᗶZ nKRTm|aO*,IbŚuNhQvɽ:` Q,x*8|fivPhu$Z~oj)Ġ%zHk|gC$ &i6&!ۮW,َEAfdȦdI_ JF5`%` trPMp~s_mItNI (G"Y|5ގ%|4{ p܅,PT$[d. 9j 0C^Eh`Oc潝k6vxQ^ c*k@@MzbX° m@&\Rfm)^SvH#v]lɤ!(R7a*'A\Ȑ  0PN,yxAL| %bA ӂ{iF7tv. L;b{!0y{nhlob"/g5վkb-- /^WExtp$KM ffV9`IxC8XUs,!y9-T0O`vNKIQen8S[ή 7 rDm1FNFH%5< %3kvhd\85s&˪ {jE_y@w=,mGXM2}Ӎmb!!#'wxY+R/B~?ݤ,̸[#i\AZR,ǰNt4r0V5Rhn &(BH.G+cYWL{Lfe^8Q=^h&*6%m3>K%F M۷e6{%Ёl?@pNV)2Ǻz^W9[fQnVMz{o{ɚICМC46 l#o,{zr;N~)rKÄFk}kj"C-O;?ug<NBVw2s?3Zq*(yNS sd,,ꤧCj4riIRiOxK*3.|GgzLNo࡜Dp@ӛPNbFC'!UZPIħ q{ 7_Ds$en/ 4N~1i0P@&U5`=}M'4|Vܛ9g8R]9We}3 8?N- iVeqQJoBǭ.m4Zg6,3b'OTE@ J<;EgQM>9&A~F [\ 扡hFuݹZtq)>"1޺0?& RȪy=o7U^ G.M@t͏KƮG2)[7.Z9hPkåAV_~$ʧ'tյ"bFGm<-=N08_ kQ>xW!i-6\c;E{< zC|uBzT]= Ify-uX1:ni Hola ~N_a/5jt&U"ժɧ`7T9/m,rh7Atw }J&0B2 iSy,FwnXyਖ਼Zy9O^ҁ׾;)ãRVb4N&k"SPFAĥ%L0FYrVB緗:#,43!DfDuINz0:rySE(<˶u:W,Zqa |S}P5!NP5W{EMeMcx-8LNdz:yQ (EՉ xNNg=&42".&p9E]24'V<UH"ǫi|jV 16A/3QїKS*QO%yxϯ8*(e upkUrПDqϵTyJq'c'ӓq{80ݠ TCyӥ+ZBVS0cri0>$]˜F- |6nWܿ p-] ? x9[XkzsfDNS`H= e\q=QUϲ[5x]=mAYG"f+oPG ik^&+xGmVIBX5^>6Coy]Uׁ$QL'F{0\j6Va~I66c?&. x T7w(|noULUIL 3?ꉣ= oODXI4M^bh95&o7xԜ;'Yp+nA@fG?52N-m ]pc)CרL= TZ  RTT}TfPOech˕ъ#:dĬ#/21ds2KF 0Ԋ/lOI@^tZ,>pCncrϻˡ {mM3K19]2;8Yi}Q"Zr =koɐGAFT>D$i<) XFnT9#[Tu=p7RFp^[7XeH=ToGcl< H5J;`&A ma݋ _Rh138ؙ0C"qwLW+`3$QS+,u/B'4̷mꃍD) IVj ,ՔhF#Ffw[Ȁi[o'ŏRH0Э̯ iujF WX_e3 puOk#Zi<rŠhYxnBT^éJ8 _n*!Oy5JY}Hݤ`hQc}a,qwm9Dbzt!)V:Jc*ik,Q̜e'GJ(a .{\qYj@M7um` ¶&_ɥ9"„Q 2Ĉ jwI:jnavW-($VHn!= b#*Űo]./4vK4OOp1pLw&Lj=݆Er۴oK6-.~6 CGCmS7x $})cN]q'0vROsb[8zZ^Q>YԿ\6)>80،d8[_+w 50*V[?`JZ0P;kƁ*ЭlǧٲE& غM;'%A |]%X ~8ɢX\waD  " XL/{/ #z?<^3q'r\C<}9T{Hu}ec_7C^}MTQn](mCY-+!++ vDP+J[+"T#d֌4SӇߌϿK]x[9򶷁*x=I]>6 O6_p]A#= 3t>bA.g\3ݎхNȈ2PuDԅoyT #BEs=CMl/l-5"B``IT(-YE;dV;q Zяffy=pFSrP -pq iy=ۀiݰ1h<T.A;0Vǝ/FCgu"#uTMR5#Rl*cƒ-B ug[hs[,X-jZ}ۻLk? LmA: ֦Dt(l8#G0m.sP:+1nٙ9A;G)n/8Ѵ2x~AFTPLN.#݃w̩^;ۙwgr"UgWDL}vw19PPM4v1I X ǰSUa ;N<81Y}viᨿ*bſ[۩;h.mhWݵ G ԙҲτ6c@ǒVf +>{d;*[b #Tv ex"|n6CZt~-}!9"'P!>J_C>|0[oN':AY/0>>ʡ||k6|9zD g{cCZ]EFc$_"0ܒ״@޶f5ڢbY$9Wka:mMAbq3ʄ.I doUN}N[Yq b'?\^x qkVhQX'f#ݹ@,NjaF VψǾ.=l$e*%)P~aǧ|&d6~߲ ĿHxء,ʸ><{6A`=(va$;yh =ug7A47020TL`TO̡U.kasFpɓ6Ke(ܣu1ϪR$s%bSIPF}5}G pJJyatLIXahYI^8 Kw9V7~ZmT\ߜNj\&¹%,Y>c(&,F "lS=3jF&| +L&5˶hi1)mnkt1Z #Hܪ>>32_b_. eH]Q{XukS}|%*4 @Sȅ Wχ%(PO׋m|.E`Tj#2CY]0r` ä3"Z1^cKo,:w/QAaN]b'$x%`FqM]~u(:үxI.]G਴zs3PtQ>/oMtO3tYcqɇkXm@S  4?&C1|DbL3?"8,uE%j㣴>f>*Qry?֤;{QV0Vy)( )\kU2ʲ VI|[+yx TEc?䎭X,/Qz;P:q.Am-+~%6v@x{$EY| JpHJuˋv0q- E/UGvŚhMWt/ (gb?Elwy&u,cuۭ RTs|3_.@gXO}l,3 T!U zSV#p _US %IjGn8iOuG M}=f#̋"2*Q/rj Ӌ5e:.g ˯~cYIwH\=Q@,T*evոa|!վHN .2hU9J5lyw̼&ŀ98z! >rqQduR03޵h=OB9JNP,a)6RTrA4oyr:?DjQϦ.5ovx[S;:.adyl+ۥ90\sv$ 0=#sl(XaNCr*ύ %CFT.LRs^)i='s{1».]FKN&w7ˊK1[8q aD)S)46)ma[GnS\8 @Tj8\S9.ćCc,u<,~(ʵ9QLHly4 (0ni>U|xD޷Q ]䡎, NYNJоrTPNMĔgz7E8!O-N+3WWAU0OHyYg]hC%hwN/e< ,nH3,`dY~G[EndsBdFw=ߧP@'QFG:сkGzS!T*T-kƬg)"//6Ȭ_bE`OaV20sB Ɖ:j yYKEw]hk HڧinENA%2t}Գ"[PY\5?J"\lZŭa߄\6$T}qvU8gӹ{Y;+=L>Q)Yj+t9 pcah6Q6eN>mQDwBK/)q;BJȀq$ t 2 _Ȇ&׼hzīB 9~0P%l a[SY*D * 6~B}t7ɘט' em/ED+lJ1j1W<Ӿ?ف2%;Y4CTnRU-]cC^X E=T71"TE(n0e'lc A^Y H/k9 ֤PG*`X=[!&!I%-L躹e1*PO7.-ԶVIc\BSf{MCfx4?3Gq0nGWZ!mO'rA \?P[2UbNF4YSУ*oU>sb~7!TM6.c.(5d\):km>+ 9><7ɲzt4hSoMwA Q5}%!%f~G|.dޖ+ZJeD`s0ؤ1^jqxJ7sV ӳ1:$5ߓޣ٦I=mӤowH)C^࿓;a Y PIPaAݽSG@0q@%UCx%.B¿o8](pxkN,üɮ2CDzfJsV [2 M^ z5ZfAxщRԟ2`2tS"+L7;"7dYc N' 8'Dv_%ado R!?:mbO]Xܵn; TUuhCc?8)Y%FTXsͮN~&8D򎹳)~h,' 6π"#5 #w  )X;;tWP8.ij»vѠްĮ+5AvK$\c~*8`^6pT`԰{~mx睵.+sPa${#F9|_u-nZ|Z(i/--2Ęq\qF/y13L㘩MJ{B\c:"eXZۘfMcyB_nfmrA/_-/3!O̧NcbֲZb\ʓ" %SG/k<5'2.c֑hBƑFV|Po.4+Da}Va{ytsWœ._ӑ0!]GL&dEfCPς^ v/:1!GΣLVuҼ+W TwbCP{;)FJn8qR^p+Ίq_e tc}I} L-Ԫ3]јqp>cFr4j~zw>?|cPXtEѴ+ y\_RA@qmx_uG@G֯t]dߌR{/"9$ E)Ysm "p1L^AǰwwJ1-VVm˶K?3*@m s﷗wJxz K70E#uFrRs=q]Csz@"6Z7R11K1UT8Я`d\(M+gtѣ(i%{>M뙦1 v-6|E1<&e{ޓqj+i|nP\TJ}T.Vh'3ЏNY$%XĢ}'aU/˄Z*@qv TZ=w{R+Nj3\hlJ^Dn{»P&['Ű5zt7q6MybMU8=gTWm>$%Դ9® fJs0竐v';SȑILvz.2(zalK*2+_v̿8yJ" "}0aEqu4Z,Q*0jvnSי?O-:ı1m*v~ !w޾ ̎팺*(n7O5Ve#>›_Yu ^R֗!WGo=J=C6¹gݰ52"5w/o$X]V60ROM*tDA_#) o}CMЈ_JVBHyP{ S[vX @S{N7 VZ}6xdJ-*Ql) :]̖4)]$(ֻ8? }g20 ef޹(fwx=3f A 9j&(x?m .^mºaujSt,/}U]N2aK' Oe瘊g&2BߺhAW.Z'Gvģ>S;Kqvp6Ss%-C/"M:ݓy~ LHN\ J8詎[]V`*ky z?9w$<-6Q ];.Yۏ[~]!!oH?5@~]B& ]1-%).@&`o1|0JʳoS9Dmd, {]VK U[EѺ"2>Փ(J_j3[n5K=p*+ψ^sjvk&HyPOGGwj%ۥgv \Ñ<)P=}; q`}\ Dy{Kw$)P"9ՌH#KCA삍Aæ_~V ^֚!C `eC624J_DQr31J(L7l 8%ԍ`1apbaSA6)smnŒM[Rvk#-nfŸ׌5Djtzj}?X jM#䆪.D)` V7{srXHXm96COFHi֠n: G܅7bTWP"lZ`cWXz7H,V5tjɐ~h//l!+`~d5|r4(U!lqC:'x!OBj' ;[C9^ D+ev]5D(jX1w2SGtozhm`yqjΞ8 z T/9CIuro\-6Cn- v}P _z6Ղm:&}5Մ`6s#t8!Vp&O@\}z?@#4MWVOQ0$ 1x6, g('t?e[4@ڥC]n_qimķ~cF0]qH3,=2'/K_ڠ#y[^ɵt?K Z -kgoh:Q@_ *Wb|B GDnNW wn3Һ:v!{t3폹7YNrs4+eMCoV-bRxHmb9DG>\鉚k!tRs&.(!`l( .@OpC!CZSLN]Ɓw1Å>Ę{o(fgcy.熎0ރt?&$6"3Žc㨉W`A+Htqɘ=?xy<&EԈ ! oW1|5S~QLGGL`oq 1ЩLV 9,0yվ}6yC ТڻkN>$Nj~RGf'8w-.,lgV4x*7dov ZS4V5r&0un@^)5AA6g/Ő'fڼ^׊9~8 09#٨3:*+Cфdlyo0t2 xL^yD nsYImPY2S4(?3}C(CL#&#E 0R0!3d㚚a\GB-"59G Vym<$rw^ǐSI:~/+IVGUXE[$17 ^ߖgsYjr'16*PrjfGe4v&4IZ1CF.}6QGrVw: R4r7>!+7S}BP Az[povU5oЦVtN0s5;V o F"9T/LxSSbg]Kj9,2ـn l  UL|p*oIHt9 a Қ;:K vÉUc';Pjmi _~ĬXkX OEEQ[?\hZDP04~V{t1?~X.;u}#0~ 4Se t.~ёQ>3akv 0GDf擮Jdϼ^ףC_9%YLƼ`D`-EΡ\P7\BLxkR۳LfP3~#<Д=lY@aށثޓL"20GjDcaϢzB/!3:._QFVGj>ORi1&w;\|;P-Mc"'Jx(2S#Lܴ^HP\/Plw1'Pώ wʤ1r& %E*#TNI,prKZ}TI-u~7{\ZW=y--*EZSiƜNrWE ^E Q;ه66{*//S:J.w`|q{lRLF't#)'{ " DTd74G݇S&5Qfv{q7֒0Ev۲.MLyjV^ꝵBr4޸3E|k !CS#nݸ4kD5;NB~uuAWլf=mi nU??C6W6cFŐոth׺ox\I j(m 3<. PwNt/d&Fh͠Ga!VW[4]T곂Ho!rJq4rm-X`\\165RDA]s aEyxն%'![(Or(UofcihlXE;#a!MhIuCF"BM~<0F-R6Nrڏ0a`t]+|6{A$\RS ҢlN_b;I§ޞ]wn^^9D ?}OUb e0Pc:6OбrK7$,!sbgK :!嵠?qR 0>(=ĉD$d}hc+:Bq+C4Ѳ'ZIvg_׍CkWHN@v2K&,OA|'D'|aBۡ%Aq\?ټf8TaL sZPdsoޝX. E#cu6ߤcOWT!5 A & nd{<@U|\م.@Ao]أ$@jMtÕn乲 |d>S5tw/+mǿ=<9KbwԄ&vfneߏ[\]:\l@}Q厾H啫#%4?}T>m&+fb JJo4an"G9D'.*N: `?a¢+%ϻRƚdmI)]fLg.tFUyxR Q)"^Yќw֝ RL&R#*A3Ϋ;Me1"DqV c&6(| rEbfˑ()Wb8 j"/CTʚr8U-1]` =EԯUu-, վ Z3H9PtN+dw̳՚2JYFhv"Stf GϘf̅򧫯uDGllM۾ϬM>ALhO+L[hB,س&*Ob !V ڣ#v)eĒA`]IǬwiqOd Ӟrp)3U8ц wedzOK/{H̩!5}u@{P住Y ^tIgUƸhZqz-VU!/JDqe";<GyxvzdX@?u~P4%1,R%CQ%\!CHj1hsytvQv4{Jv!?AQ2\%#+⬷܀,o:VÃ0172qg*8h `mx=JP0AH}WrZk/hLX)nL&͠uc$$Wݰ0DG8;%CU}%p _ay PCZ-E1&I5ڄW387J6Ac[RO9~yqz󄑆OR8/G!8"f94nDW6-C9ꚽv饛1'U@+tݚyhy s\M9Kk}Z C!9E׶TEvs'd.M4BXk7!qBRư7E9T Oq3TIj쩤+I}z2;\{*N\(iXKEG% "IXB ,&ޡ<ފ.B8_VnQF?I9K. LRC.&Sz~ HYIr \Gӧ` МU=SǠ7ʇp1b1Tߪ$לNgX3Osk"X:6.T'HNpB+_ɜ^%_sg넆LK{e>>+Oao Ufvˀ7,S$4=J:iX<'"I57 |z>"L&Bk7py楌Uh ATGBEŕ=O!  vP:Ww,&ԋx]SXUz*d/"Vozqf.i`GQ |'Rw[8=@ 4oFatT"۞|bgpkQ6@ux-ah`fm x l.wykK0W2³|IvSeNZG*XSn^ 1;RxE/}oxJi<.6?r_wՆ6zq־k`OLں{!KyK"6HIJ9($TUK 1PIw?DbǦtB' rL,7 IĈyS\ 0(7f-ӗ<& riOZԓ@-HGP៻$[) ZeLJ\T7L%hji?c89OƋ(:ȻFG|J?aYs,4g(0;x/L X4`ZdH'R;/n*i#N]_ Xdy]d:ݪL6+̔ᶀ $#& :ے{6ȥP$sCwDjurm 2xM߾pحQGzFԝVL UO6Lp؍51R䘜LET3.w sEطv'K-(CO ~2 _p~@zL~9 yqJuQ÷>ҁW!]܏ 嘥2 ? m8RxaD㯻b?CCSXZYs_Zf" Tyafg 튜TucvbD*b@ԯA2âǐ-Q%$!})vBk*V?xZ1o Fvm`p[r+ͣPtuA%,Ϫ>J!{߇ 'K)g9OMv"mX~٠>dzH" I׬YD)D~QY8Ou@MaD1+hy5x!$!yeC! bccEă mT#_"_~!k9rӑ4n,jOr@y2>+eڄz>u.T3'#1oh}W(`]Dl/,,낵ɑĿ'O&B9&*A]w_]?2)lifm׺h"9½\͘m5J8#UcxDYYwQ G&%v$5jI9ag}V5üEAq|}1=16!9VY&x+ƼOl߻a&VZww;*n`CS5#,m < wRD t$:^XBCdl!G ^Pp75rk!FzuԬڸTp&LM9Sd")i ؠ?*&grhh+R^ewkz2nFfy9`h tQ/K$ \T5# <r?B ۢ(.F췑?61z.Y9?ek?0EjݭĭBfv Y?0!T nƝvi&dlTSP_U&ZA=ݜ#k^sD{ثIE,.&D~p{6JL` \/m oU& ȥҷ>KaQ l7vƾg)*޲d)爘T}\U#MIP}r<1` c/-J KFS(gJUP&ڊȟ- #)BØT U^΢zsm2lj544&PRH-y3̳k(-~Zÿn;|}ʬaAJ-5' >_`<߈-whҤii[$ҐEA1F^Ql,)1rɃ 6V|_=ZfQ>7hL%Q -"B꛺Xt+X<;C퍺 UbD{C#Ї)ozf`RӀAtL/6յKl1#r@\S9]yt= wr]AU7o?#[] "8XJV,[ͳpqmepB598 |2'ҥ_aEa|ns1I}s!ݜj' Jb&7\Co*gG þ+tCܬ{U}Sq Snw \|Ύ` .XWK!•J9U}8y~ifH899>bPpK'84lDkVR1DDu@iKMWlW&7/Xvٸkb^)@8xaRc3Ocɫg '9ZFT d_Lr1e^۫BbpY (MJkZU ^MT=%vxd= qi@ųD%_Vn@gEG _wLgԣ)Q| /!BsUcOkG+y g|J8z'ϝ*bFr f +c ͓)^`wkKlʙ^Z/8HhxSMd2W !+erY1+  eoŒA_u[ d(0CkIZKVp6ɦsdAVMcM{kH]?F~B@IxsIoQ|0Xmhlu nh BI^M ˣݨq߾Y^ZZ0eZ;}peҘ\DMr5M7 lbqg$C$7p`&1k5!Ak8 ة>`Y|# 1=!qhPH`/0Mujc oѠJL|9ÎƁh Ѹ JeɃ೺+Zc%eN~l1ǞgM+ %4(*N>p%Ƥ2l9g;vEGE"q%m@IkXg|_E͸b^ %Ȋ&ZȒ1Eg9AmR7aV=MD<*@{`!LZ3Fw{Y)r[aOʟ[lXLCbBA@o%xRDڐ5X$G:B gK x,%1QD]y]dl{Bν1aPMZt/PÐRZ75,^\\gU!X;N0,|dzT9@['$u1\-oKNyt#j O4#l-BL:BOP[4N ʥzQ(VpN]Kk#3 /Bazo}:# rplq|Jy]JI Lr3|a~ }MЕY<9y͍/Z~A$բX~=2h 10d&wc;{dy>Y"jff{ (.#Z^IFެ;Cĝ7;rlYmq6RAA8GuBqN&/ktPN$D9ǭIQ׭a `^.0Mb%&}%D6jr˹Ծ<.dA=l.~&l%!u(;] nf~?xpl77IsVT=;LŒ"4{ 2/:rJCimŭ|.{ڄbu3r]9q4j[&Z֛I1= ĹDi6I2$@|y \6|C:r+콓`6Kf%*I.a?ub?$eٍ7&ZoM/ŋZcd*bBcFR3EىRs83qcX~ dnAQW wαoy)-ċ%lu3Y_PƌjFlE\zM:&QaGrSh-Uw9NS) vJZ[gÎ>&N8ᡪF/WE%3"j>Os)"P!d8}[O-_=٣ͱUC0Iڏ'A53ltyOqVHk y_g72QփZ$@fnq*39HZ.ҷ= `9U,@}qׁumCӋ=UkKGԽfڑɍRwFRyE ( E@8wKC);DW`&~,BŚ'8ATTDs~s0fSa6lwW?;T6YG02'" G:V3WW, ּ(5bƁ˿ .yEA_PӎX;{')mABp4փH^PhEMYZt{^0"ev&ipl}tm"9=H?_pyc{,9-lsܔiبJ&~^X\Ԭ|D9pzEBwlF eZF>Kubaz K| ȗ*5s1қedVÖ^˰8~=cv1]%8+XTچ d# ӘiZ7[֨~;&%Ϟfi9kzkAL4c`礒Eoa~?Q^^ @LU|g9ցBig]CJ24 0 2v\eԢ?9cQU6dAH4cTYjP b5vNN76t2ߢ_wlm-j E#NCnP{)TBace>捶UHUF/7zPYYW8N>9bP6t'/c;_M2%&D;B=kˁaԈU%R f`g{qG|؜˘_4w(ϒg#zyIS̝|mghG+UZL 5Ua'X@|N-̞ݰi5Y@U oIF dJZu1IB|Rϲ[nJV8R*c5D5.TD2hT܅(_j!39 Z$jǀ0HS~9(ɎAoXknIofjTim%Hy7lx<ĸ?9Yt#sՎaH6W^<օBɏvpK ~ӟ׋m|d`1p]qVmx2Wj!IaOm%'+Afq)ESȎːr,*mR[im<6V&G9{K3rḜ,XQN„ nFoH}a@`՟p^%AMC5'Ez?*(l[?#dڞDS$%0"0N[b[#A< Ϻ|ACqSK"Rm)^TA(#6B,6XA+$9lPZ#F33ݶX¼ت 7R<i-X3(xZ׎GfCcx%d?0!ӡ t knBZ}Y7 WYP#c2)E.hbC(*f5?ͣr?a(Lޗ`QձP6\} 5w ШK 9üqOv{n7c/\]Sz^ Ge#=._]W;0wԮ?v6K2ZH&:2w(3Nt R\ rS#(E`a z5.[#L nsrL]uOXK,[t@ hװKDMpwXzY+v0hj?z49:eD63oijgDW[әNab|u/>GU'6N)KsR7NێA86~OgdE`ym\A$̶?6cdG&;U$=!(N~D|~Vyާ&08j.\21yh<9d:"l̇R l@GP }y#>XFH|wӘpnßw ]C"=mByM̞,>͚F6 %N\6w=|e#V8Bb;rm4ƀ mMGbm{sdm{nrP?QFķ%9g7uMdK~K^wD#|l3> *gT{EB)K'>1bssxu;F1)3xfє--0'B*꣇LP3`B0aAϲ&OM =y~)}jl(ǨF@"ȕVV_^ ?p[4o" XpJ5)4zCFa1XY,)uUi?GQhv|@}_i@+B:^9:bfd ƠbH a5b%mwo?Hi".zGr3 j+$۠k{|σ ͜q3Gy^@̓*g7l>"׆w;S"U;NkWSީ?R!RWL_, 2ha@ Ā_=,{\iރ51<_8E<լ<䬀2[y~ py^9 sB΃o{{t}GqxѲ㌴T"j6U s;#`Lʍ#ܲDڝTSGO C64Dju >. id:|j%;PGDeht+]mEʧБ}ks@ c9߀rJ؍ٌYTnŽ{ku)8i~$"IOr3s&_ǻ윦G6Wmg΋/.{U}r]֍/#_Yrb(F.??˶W sk Ӌ?3.'Nd}d1peW7Rc>Eʛ 5eu.ِi.\7= gp4!Ca@5-џ-%b_ zͬݞ/||S;Ntd$|lK|a[C$IC!%߅j[ȖbDm(3()o*PNvO3{!O]dQ~SZ\bvpry<wtL8;S_2.ղAv*7QA/I;3cx}P-*?9`8 p8oڏ[zݣ_rPgS# [du<8 Hzy&ywDApj%'/obMd_C,:[ n؅jk}ZbNg@.r.8ds~{ǹ x)HeOr^ڗgA˷mGoz6эI˜PGP^7ۋtgBΚ^ 꽹zpa㒼<(A+ #. ?[J{S}e/Ėyک"+"#CP@KTf}im/Wm[teGo@6 IEdi ltLkPfqj218D}8ФRyYʻӌ&:zGaVcUIbhh_OE*\Bt,yI!Y;FN1UҸR9J}y7ZqIH")J.f֮$n x zB3S9o D|_D_To/\ƫ9cÒ8/ |}Zu¦c:@i3,: 3ibTU9, Ql|_@u;cf(3w6\bh$'܃EKܲ3niY~SqwȾ`\[DdKn2"&7{u_&֒Y6~8LhrOP2 %BW~ʾ}Gbky3DCj!C2_V IFtWcލ%/K_ΏٗvapYHչv8OtuufU77I@CJ^N&vDߞvajxI[9f %2}>$NBDLTe=..6ǻ=B5l7mLl u"cjmPj `[@b(S8`/!20ogj7oBok v#B{-J]^(V=z/"ail! mm}NrsiK?X>ÞΑ4YƷ3G}M'̑OuֹzcZ7j.6h$`A Mh&>4>ŖѦl?K.n]]5 K9l/bT 97K!7q]{(Ee-tUyhS_ڴzyӌe Qr,o9{ E)HǛA8qC GD.KFdQ5 ;AB ijwoD}PfLRv2Dj # fTH9Rr{ o6:}t8 q}>SնmӐQ3nX  !)5,V TC1)u9*BM']yIQCq\Q:<ޟe`O9;=<%/"q]N6 ]&]xP%iҨ >]\vpu >4z`MP,#! Kiib=d/]V- 8*LDZlR֙H'GqEVjnV dQRF5 KLlNe2FgȒDљ#-;{Ҽx!a5|C Q6׎D+~r5Ep_1N\@H䙤I6iZ5#f;hT렓 FO+uH&l}/20NqoJ$0RhAn~ᘨ33)]cUqJ 6gqc姿7Ks pU8K4uS:kQ Ѧg 0PYSD\RXWHU|DpT:;=JU'.u sQIK8\bii?t!I@\IHeRSJt39 W:>HSCqu%dʔ*繥eFPnyP7~W/k$cҨ g&"=WVrsdx(V&\'Hӂ}i-C%=0e̓OmQt5gMVzҥ?Ŀ]s,ɉťs"|%x?tA7fvpq*dӿE!꿼 M.R9,&0yEx@o&#ůVr5rZw<M5y)toa|'NMyb{]>(U<47Dtj5AW|No]LPnJ =x.t_ϨX c׀6IR_oa3XK̦ .B#DowD596 dR11\au#"coYu.ݒ/cЄ8`悠uj܎Lޛ2R 'HF8 .d36`P]W/1p52?j _W[D+ '{u[1M59:3iՁ? HI`GS+? 2tD4jWJ"ɸ:*¸^_` Y'48*λf ;8͵)0aIbXOX̻u%ɕ%cE^R'xx%iį2 DaO(,]'zChHg_2G}3)>Nwt`"1ǿ-hra9%񉿩K&'˅|F6Ml~=O~L{ѰUl9H`!&}Nͭ>i 5ȅUym2[]KNZjV]QB ?"ABPk16FgF͛3fsdВ= X;C*3hg;c77 ئJtg^ce{YK]hrҟn}}x=+ˀ[M,02R{G=L-~CM. mUF(M"VpT;5fzr 517܋pPXNvНIڕI8) z-Q|S;;mW!{lC; B* f \\UGﳝuӮPT,2$sEB6ӧ WIG|ponM %j@!(r ,tt#-WdQ;+ܞQI$Eoe$~#|:H^T{Kl)`?#.|kv  xi5_Z@w*'m".:ef^ل'|}p&2G_'=(xM? q`z,jC$=6"h.v+y7{W3zrrFaIuAg'f?Ed!F0|Ϝ:,2gyfD) &=j+ft[Kl26 )4u6鴆XǾ- ZN93Ir>fU_YMޏ$\!m@TacҺZ'o^_PnEFEn9jBͮ!l8^+ LZ6T>W|%ΐ?*7EȬ,MW'?"O5N0QwXUZy(u&=,ȹn9SdpZTn39\+BR#ǎ5xϻBfqθ*@>ą? MtԎ[:_ajȼOl|.5Y٪Wwj%O/G]_%R x:ȼ؉ANhtjRR%lЅPj H!63b"ƃ`:VΟM0&лgD:i8ZGЈ60u/:m#):Wŧ ˢt&gb$]#fxYx[=puP3"[6sq-.u7@qybUXl!L!*Xj`j=[cVe5Da$ypS9ڛXUg:-7)An/)6rp=O zWM w}LGW.|M﹫9\x^{Vv[GvEIde7݁;(?7+sKZ?ϪE iÝ*cq3ObLufkeB&i%mCv~R*oi3e'B~ K/An%&#CmGҏh*52VO4rlweTRySs8d<2}'RO*!ߑU 4R^3}+)>$[;A6K8zܳM|`w5NWJJD" wK6JaFRʧRbl_N{!S] %qc* P\NY[,uG8È{!+|.Ob(EC.lC !T}#07!☇D!^9o  S3ۂjwpi\S]Z:_2`*1{#8 J# JW_=b|RDDrAY.0G@>ߎLh}Z/9Arft)m٠:>zKa 6[p~Ow"œxbϼ;h;#2p q-6i=A;t$ͿqL*m]Am@7B:tv$(0 NG!J*Y 4&4w\ HDe (Kx[ g7غ){s88qAQg o5G3+HT{;22 [e-! ٵi~eTi/cW:|d-&zS㡏:Ъ#8@v{gAx!lg)N`s 8#};>Âܼ(y=q76}*R o{fCVC{GIrlb+Rdj] ԺS V(% g2XO2 3[h8 V'>N0k-7 (Qo U ֤ V@\3 }a($yd.jom֦헒:⒣2!2q\9Jƿ#x^_WGZ53(V)z_cǟc']b>QH1JɝPFUpno[QøSa7;nmȜǬOR0(FɅNBC/ѽ6Bs ݸ}5 =9\mFy(dut(M E!9 ֽpT%E#nx+;\$X22T9.M@FÁI 9di8Jho`;&5~w$ zrh2ZSGD磹2׆Uj*~ MG{f kK&R CIE[{^j;+ rE!\RRCe ) 'RszKYUc"#}N,:MG½7ZB`5#2[eC tRJ 0Wj5%?QJJDr;VXd3D!ղ]|ꪥ w+qfsO2jFAِGg{5w2?oz*Uݭ4s6AWԕ{-sg!y"ıN;Csh$T .&KNYJÂĿNKɼ+X!жU&iMɦ] @X?%l TaK `hy ?.lg׻؂a uW-<*}?F ?b|>eT[˔7v 7WŊoƒ4cst"F5'o݌;wIs<`2AvU j1Wê޸63Ŋ0X\*!(]~BgF Xvf@ 0MJ|I;%g `>W/9| F >#OùVvbC}&v g &Hj +kQQʛ Dȥ]\P}Rh#B`dp(pJ&oa"Qz|.jtgt-̺QRD8hÏcLc7rK~m_4o4(i"tCJ莼(gq%[|o)-_ /Wěn1(䪚VrwgV#(*֔I_Է!S3gZ~H.lY.)9Vv/w U,dxGݸI^A'#Pd5yvSk#Y~m4XnwJbo%~|pn)7d;u䯬6-jƖ5E<DVSa5㟩k*IsnC $=AF[}k7Jwty M·8Au@l,xFc<_'7X Q@)vq.DT솸U!t3ԤKEM"(Ӡ?!TL$$8OD2&|3U> &(Hi#j*|Gndk,o}')H 7KrHhv0~h__NߨE7USm_ߚtV) NuP|[˪3^hTHk!XR$!M̎)(8.6eܕ4 lPctPZ!şޚ 9 Sfa0j'뻉[i^"zB >PcNv%n܀!mw3sl*Ɠ V t7GmCuD._랧,8hLDXK M{}F-9Gf5 Ak5~R"F;۝h,&ҝ=#twMI7iu cN?1C׉@''q(rjYZ2ҸGP$qãcGÏIx*,A2lIlu3*7O7"]k?K-$uN1i ""،`*Aw 3d0J(q$ܦĪ"Ρk I y? `lE'V(]%:{ }hu-@c6jIv++KƧ IՒ(/CgX>m_w>㏭fƆe>,g?9ܶaAs"NMm{Z=Jlʵ aNz`f,l¯VxniO=d-; \6Ǔh.4.ST-TɉZ6'B%mH[?#koS&TD\\~5a7f>7Kjt_ $d:vV-UJTa ì &_賈 KvqE$c(vC>`yn$צ)>DJN `#1\y!S T !JSPp/rD?3nwd4͒2% \Èa֢-o_c:ড6'ɌL5z#` Ą$oOݮ(Cy&=-5Ad&,D3ǶA *\fAzV60n;Ș|=d҃1T0Zm;$=Yʇn^)(fؑb#=hU}~I(oDdno úˆB.9MoLzj |zLvlLҴRLԫI<;a( jv~n\GEadTɫ]b^d(Bb) nL]^ |ji:׫I-H僂-#Ww5@f\@Ic 62jȅ>q+w (t/?l[^vRݬBS_DE-? KT ̈́񡖣bޫQϋvCs~XCQzV(?( Tjtq.oAT!nhc6J`ҫ:ڭ#|Ƹa0.8tv͚R>A<P_dQO IB=ϺQlX!ugp r!Pld~Ét̊J_{B}s>ɉ,:sqy]LLrBEdV| cP תxJitOLt'g}؅ TMP^16;Ikx9E/Na_ͥ?k܋fz6x_ 4Z݉q9bS LҾB䛢A\sTT)h S܆J. C_1t:pqc/,ߕ1j̭ն]C<|۔Nu7Ϟ[`CTU.Ӵ늬9='g2f#b洇AufeĆuf\Iޏ V'uqLƉq[vb{sl*GCC:k v/t(yQUwr)>[ZFk.Li&=^*7O(ek3Kvv\"[kn:ghnً.4};P:9D%1e#egTc VXS3RFLM$R: "!߮g-d$(0e{>Z׳̻Aʛ>gHw,-|`SӪ3}8{Cc<ӍKl+v/=Gl_fih4s▖Ҋh|"(T' 5$. wz_!=}CUt 9I_ᨴj>W~TAFdp)edn1GK~idd1Jl~qARQb8_>BQ "J;E]_B|`cO!%y'Vٵݦ0/p1cagp-8 CFP!!py:̗U9#L}-ۯ$)ЊD qm&jN*S߼h9b_)yȴGMlUƌd 9aUKlcDw'M5vvW 2+c0գWǜWMQ w2-IUYQ1.nF? a? 01Rru_RBdB{>X~PGgeS"a!]"[3u݆ENgP= =q vCSq hzcޖv,tZ H£ H;kw fY#R0(ClTbEH$N#eX(ٹ `|el P'!:@}y\L3GW2[WޙQ`bsٰkP%H[F@>8}7J'ت.ssXN/]nX\FSb߬\Gؔԑ[=K_"{FZzV{6g7&L?ѣ܄δ#)?~8.[WC;~Ũ7z`UgjdGgȒBb(B^"I);z>R.[軺-N՛XQfiOOg ΊѫF{q^^?fq$6e?^?~6yHQ c<$8>Y Teyi3*×Q ~r snFtd4 ꟑh4yÉ%B/UΤ3CgzΣUw֔C'U(:J5迗#!ߑS@$x̟t2~lwdH"fxļ?xJUډ{CcyTesaiJ?ERDzE6GR+/G]49ϻ]o7/F-}Tg ?bio͇W m$];u^gWeȎdAOo/EA/n%YB,hfoҊ?،n'uVbtn71Fē[mj?8j7wf)4 ru?ɿ_h 'SN$Ȭ6\Y: o%RzUn8Eb"" 618MO~ 3OS6\5zJV䥉8aC)>h s2/@/eִM&j]l3`dBmNl0@PeUsĻ-҅Hsg3} 9.2$9 ۆmBtLeO;6sIyq?mj!6[/Q^_1g@Ps/?iM ;[Zјgu]E;БʯA3#jԟaQ ֠m%T= %:KIJ=A|ʮrd `NkJ+?4~CX2^fD+sJccuSfH7BF'c>-؀$V6&wEFYva3/,.zAI8KD[|,?ҼuxǜĚfʁnOK4PD>9Qp.xXqȀñ)'J"gT4EQV ,Exϳކ(*V7 ^fCupNmWcL4h=.E5bݷc/=^F ݚqC’3LAF_RvO^?:p \``9ĺV/3mUZVx `ec3q 6KkŤWYAŕ{xpuޓ;n S6{.;#nNZ렼,ዧwYj mQ)N[ u3Bh.=2p5HYÀ3|ӜyYwd3 6:l+:+T/j-X|(4/]1: E1~(e2ow)ib氣|?CRp_uD?Zp;M@;d4 6lKgrފm+/48ip.G37zun66 !wg6GVIiFGD32bG ]=LڳJ0iom5F j7Ƣ%h$y: \~Pj1|?Em|zVԛW[-K&19dЋZfR"ЏP'oqJ]{nݧ{(^D6a$-30?9}) T>eV٨S`b3֔Li`Z(2)cp . P(SIJiX-UԽ;:J{V|4vfSU6cj)OG{SvT!vu֔WT_"h_؟{cK,4K,s?y\qQ1[Eׅ{ efd0mxk{1BXwZM(ט3#V]ryI8b~5Tː')p)3~9R}^sv(uӞ X{V T+}ġVOs듒 }KCT8/lD!0NE-@z^ml֌;c7\8bZWM$i&,#Đ]IIAmڇ͵fY!M@ͥꗠ9YyP*4" Öv@%Y<.٠b " 0XH@Ɲ\ !F߼! D˙` ³~z4t )dXǖ9ldMrzF%ylYibl(soR(\QNǦ?|;'~M|tFpik8>u 8$be-Ćj3 ׁ$.cb#X+R,UT'H|oѕZ̦K,hAW6%=>*ozngqQfEvE2,AKͰA[Q# -=؅ *hW+j8H)e ߏi5䝚/G & uJT RQxu%RUyLPj3|JN% "SeP,_.qU/WwF5^9c+:DH. o#$5m!YVdCp븯ǓO%3TTy]:*7˧m7V됙Ɗ3a1D4捾 O9%HWz\/0 \@:]18caȔD~J>[Dӆ;~2G\xUu+)ңOTR4w:hl:n|IiǶrT`#)B.aN8/S#9il&fwS&xJ Y3.ы=Uof5Хnl-'Wㆴ;۳XEȎwQS,aE*ü/FLTLAG|NΘyb.4 KrQ`e^K#,24=\3>Mr!8˚Ȋ,(_W 6 _.8!FoXxQvK:`n,w-oηao\+x2qpJй+=}IaXsu$]`ZTW?0MRpaVN!%J^)!\o^#cYd\u]_?Ӂޔ';{kWf'k0hIe( 毵a'AL#5͹yW؀j0"ߛ0.?7o[{HXצ D=~P7C&F @"7=pӨj*W-3xQJ:$ս6TCzUu}h!s.>ȴS9_?#aSWiT[ɸ<.F.7z:!PO,%/ {P4qT7dﺨqףԨ0F F\E4O 'nYF;!~y?k& &7b|broGy)-YEքB&Ȍ8ЭCٞdP;XK#I4l.)EBh\}7QERVGlk#,C @THv>Pfrj]/wfz@K 6j@n0y%\){tiaezٺ@g+龍.15SԓYJSF^}#DO _٫}&pQ`hCkP, ygZ(?lQSq9pF ƞx\+`#nI,. Ȁvo²mWGz8-rA]!aռ78Q&|A\icCv"nи0G.2, L׎p?o22S-+6k4_jCv(G]جe6"Tk&}LB%ZApuʏ3oMD=cPm8~ `xE+ƴvGa~>8tR4ꩳ`ԎLtbT,=o.Ga 0Ƕ bUto- -h־ AUuơi\_ÔuGʸ'u;- E$-4I=g?YkooXX>إE~ 1v|횦fG}nJ8}u] :XomV3N(mZ^ep )~m{5f+& (Kj˼0+> uR(;bcb`4yalQdScXER*ᮯ[[B4O؃i&߻)Udžet{!`-3^H/C7X$]d_5?I.)O%u*CRۖyaneGbϱKe_JʝJqdWFb\@pJa+*ז)ɨQ֢@T7c4'_ ubS!ҿ2n_.ť@ gf\ @ SF|2kMxaxEJ%=T9XOٍթt0ɯ3oS8-2({1ĂV^/o)kC E (f(Pa̎0BЋWKRwA龲h&BrqÔZ$^[5 `D1d 瞪^6$UR@C< LJN -d ,ŪusYlj/!!X[]0 40ҠĐ$=@[Z2NWE]^ˀBt C /@_+HQpv`5V'$Ia=f^/ܭ4 JM|ʍxm<нo*D*3UBk-xdiQGVbK-bNd=cD R3WANōuj~XCe{l¶eeHxdS!0T8٤Jf|Ȑf VB aYƧ~<ބ?d(B: L4W)NN#Q!;e @ RRDxI!UU]Y\)^J9esSO52jo)Fؾ @#|)㓨wy- &[ ?|S(f geIfnӑwuejLxy2/Ho|]0mr5܎X<ҟbV5T玣a2%F1AO` "\ZaMZÎ.w=e1/U &hOts+=_A\~B{j\ڗkUgSέ](ÄF]\f|ĥOms GGDN(IAeEdȤ LE=yݻLLJUTY͂W*E"t=Gl%7^\d C *s2HT]ُ fN'2OH},Q~J (L2}7Ӧ,Eh33sQF{ )I%IF[t+Ν_?J =.aP]NrgՑ!|;/j2AVʼnIl0:FIWe]ٓAѱdjC%c!XW]~\=EO8t I&x%1f$ptNF_cOmrג0;]S2MvV/Χvl"L`[i^ f|DWasJ[ΰpI-`_/lCP!^?d ēш+VYzaQ hxh=444[^YQZa o ZkCg2(Tjb+'W1[ j& J5U! vL,UNWE2la<<h )c1nȅ PӭwPxfnDJtNղ %m{Jm!YCjJܗS'DG֗9h'Y`!fM'AyݖobiLxiӺ R wI⪿ƚDC޷t厫K9Gn}FELBr)cƂ!cE39¨5~T|#tR uc>oV  v 8Yo=blLLة;scQR#j0\4l,ӍmoW +X7J\ 7F\s/KңUOPJb{I@s,Kʺ` x~>E]Tris1T_$@pB޺ǹ;Oj !0^G\!HWz pgj~ P,͌➀L]Do+>swow7l:Gi":ʩx(~k&}HOz.b}7] dX2y2@XiġLX/`MT=ᆬ=b}"s;@hpýn[n3ߊ&:B֥w.@Pp] ;A|sZ&B~p8k-'xfg/zӋ$5 W&\Hi:ɜ%X|sTuIhnFL$B |Ã"}]F`8ˀ> ۖkv|?pB]Dy4j)>řJI~4im!imbԋ^ >"~'NpgܤMPԱC Lxɤd2y*+m]8~>dkGI8 19sqso dIZ:&~VV4 ̚Mvsѵ 6\^4sM:ɘAh&`59adQ6kԸ`9]V_L<%ڄ$PtD,"%:9 7]uFxH!` 9Q}XBRUM}}.wGX(s` `xƳtn~`qyJ)C"7/oVejRa@h}Σɡj#^jBol5wI%L݀jjj 1,Sة/QH{zc~ȅYcWE:ҲIQ]Kk'"6E5p)/WHȟm^22j+D1Xd'F9n\:+ؓ*DQ0vZ*gp铹"Ǒ~ŋv3*aJn߬ODvUM%.T 9̵@ \,QIXBz#(>1fGKjCbCH۽+ЃXr 8NC]D.$H^I0p ) =z R$(C_\(`Rmh۠ xtyy6}f볻tM#\w|S)L%$䠂twz@o<[g$٤yc%nR˹ = FQw=0na$"X[TYcmI\8t,V-)"wo 0To2w.3RI x@F͸W+ G< n) `1Y{LSUF#,8J!7ir#p}4YSZF??sh`@nBv)) 6xxY8hr!N|*Kcjgz$UHTzO+_ 4V 0w;֝ġ |~}m8-A?+. ߓ'j#9 /Ϭ\!2<,\ O tgu5Z'S~vQАyu9ߗ/oZ~*`ViaorN-< 7^q-`k_l.rXPGEBUzdW>+5̶֔>T\!G`' S]~GB V1jX0 xA_;|qvAu{B-7فp1z~-qV2ei:~/j|sa Gc x' yq#U4a:.])t /թV.vksdK[ ibI̦2O$̪{D p( ?MFcZ v?7$6GMb uO5h)x^~0iB Qm_ű [3(v(ݸNf/7@dߑ1'_dqc t2 ܾS<'F]BQ:eo+15/J+G~s!s&%X;k.fF#K,.3IVY AD䝇BrjE=m- pWu};]2U ȽQ; 3A5@A D. YJi{{ R IH5|v by^.YPom m;,!vJe-A۬s홌'NRKe|,riv~ǔKfOⵣۓ+hQUr'?Wg5秼v7M`x֡e* тT: UJѶdAN70>љR+PT4;͛^HHUeR#7YYٔ!%͎zEU<-6z>5UΛC=s@U6~Ko!ds/_7ƀtJ$ґ9E5_` eXDƥW F/њm%3}:Y˖ĆmU^ JnAxlf5uj#0hCJ YҸ)r2[mx+)繭zvE؄Ln'8%u,m)|dp 2,sfQ|BܰI@ufL&#v<ܐj>6*M9MO%VZEOQ@o.F .+ao6Y; n;/AJRxIِIvZڕ$,0q%3bkj*l0M]b }r̀uroKN EA% Ԇ/0nxJhy ,KJ. n )-Y&,xN-qXp-i)s:|3PT sijCՆ^5rxg 7g2T%Z5ŌpE kՊOt| q_S4wd࿪Nm]I(kv, DI]@YMסzOd5" ,bi$uXݢ,n[U HK"n] hX9[]w^$ Чv߫w Mp6J; sw =7q3Dw$tjep,7Tߎo :y )n~,3;T RtmH~*2sN$^з255;{Y;ě|_S*hށCU@^3Ɗ=thpn=#h,^6={:$p 'azK#EۜqyCm\}#VBhCqZ/OxNQ:b{1TKtbʇ̸RFxi42iMtA2f5M◗uRn08τm~'A8eYn g|B8Iz@'CfI[ -ZsY#,AE=Abݵg=%LbRdMFӇ"v9)Or?Ţ/Uk:d;-Gl!"͡_ϔÌhzi8  9 Zy2y_I& #ΌӪ oCYElqSV JvWwc7f .k<[4_R(FK͹gǏ|o K ^:ZJfB4/T<㭂}15h3ߏQUy 2[߽̕} ?064>4 Jɦi=G,,#XS W?X ʏ+nu>#n$Y=%8r7ށu@JXaXbF@Jfx%Gş8* @nHqD5( Dq"̤./5 %Ftɢ,"&G-AAfre{2.&VưXEx7w>ȱw[ )F2=YmgA*\;.D Ã󣄀]msh% oJ q48_vͩ%f lL>!ŵ CkPEVՄnXkIRzE܋|{Oo|dpA`30au~ꮪZNaim29 (¼/ x٤U\ƵI컡,T"'J¹=}DJ qR\+'6Di!5\ :_TI '(Zt4v}Vyo+.d޶:MdzY&@?.!\FZV>ICu=j Abciک.\jl'bXkBaw[ #ΝɆb6 IqJS;; d!}MxmQY Bs hIeŤfϛ*?tfB͒>,HKJ$&9"$g(LMQDZ2asڥ#{0 /V.K"1tO ѓ?&g4jڐrBlM [[v/f cKywߧkGEۻ:ͅoFO8U'S1<9jiJr[D9ɞ|Ej_ )xYf3X5Q,l ^Uxk*-R%K JO=K>Y؞a,bnSȀݬwQ*mCO5htf꠺K]v_IC|[HcuP庠t'7~ݩ(Voz˷jp2Y嫟7K+Q;3,m׎c(BqnjɰBQ57(ߺ)W{WJ>V{[>w{&xf1ɺiF.= }#U'蘿>3zg&$ f xU_9F0W0wn SOn6 J+:#aPG Yq)@~"XeQr2{$G?#@Mxx?pT[ʿp2fY22^+mk Av3'[WE#V1Y2@"1܎dˑ"^5~|VuSnEh`\n$H sEߏOY,iwќLd G̨/nqnCa;n:I;\82-2~u-Q5_(O ?ےi+dBOAMbtMcIF/_곖zHqH(ș]@)xPZ\kHWsvر;-Kr KH1*"VuGSUǨ ^ x!r]A#Ƿdu%GN\Kl|pX -[$zˬZle&G'"Ƀ5if4q}AEC»5ţ Pu_Ux0}PZ~"Ip *$ɚwj OE(@Dշ;~@-Xa۬1)tdke 2f+]dƓCTWiޓ ʅaW21ހg `/6rlۛս)rg/+ޙUyfKpRrJt0q>R~L!d8IHd Yq#C԰<^l9nu[O,oq:nvT!b0(4황"Ԙ0M pQK*XPX k}p}[>Y51tp$R~R?/LݳuCh LX]C9=a o[?[px"|ӥKFܔ޻3uL%T&f.tG7gx?;d&%afnn+4mjeH|-Iv's׊߉ 5,08j{ᢹԣ›MN}wz*KvS_SYM]ͱ왶.R}V#. nZ|pLX'?8|CȨd 'mc"!sjm:1µV%efG([fΕV$I0,# 6O> Aqu@ 卾ZԛCFJ(Md@7~v U(aV*yo-afSnvagٵk0?=G䜼ղW([z&٪NFXi4-1v+_,YC:΂PB@K8]9Q+E(LX[+%7rb+m?9W5BIS%Gc]8 JzY@YY > 'BIY+VJpѠCb;Z)cGAT"g^N$߾ůGGUxϚ mΉh}T Qv@H/^GL[2;Yx*RĻ,mʛ fTNs,rśolv,Uax頨tbETߦ̭EqU[[3`JNeGDC#+TK0{k-%ecZ{j\ÜHJD)C /UOl稠Վږ?:GlDvO[x4/=(!2yZ N~ߧH5j旚U%ȖI3&_z\krުqr9? 1Gs .z'(R0w+3yWZrQ<:yX:y|.#P7oi/A#OݴY?nV]+&B%b7:4vEdJH "HyE!^D@~9Lxk/X>G b6:Tw@L@L;_6PKB=rhwYt] F3(TQF_F|e#94(Jk?5S|xnjAĻ%EY6RE=4 "E^05tO/Bw^6Jg~w)P@~(hMY Vw.sp@OLEU Ƃ IO,d5HX|j W-p"]N{c7LEehqxW"+ PD|pY7s\ˀNз*il0n˴.b<*>'' f*7yT+: 0 ]8%H M0X r0, I?LI΁ɰL}vX( t.t,򊱆0@ti2#o)\7k^GpQw>aؔ&0/z_{gsʫVQaH,/^lѳKlMsVLH%j-ecQPq^IeOJҪ(/C_qAqt>:PQ*K qhh::M]WzHgcEp7(_:HuO. d]>P v!R_Ń^#f )*Xߢ!K @ 7+ےh߫>& }:˂8Ys]qa+/Nèr",iz s`=+yҢHsSO|i.8 ؍ pkfS~"O.ffegMD('z_/ئAom¢< x-;Q?DxYn܌p@![R܈7$"Ѩ-c%[Yn85jq (}f T0n*uo4-Y to>^ŋ+K<'}U-+, }09ԱFS"4-PK5'VqTôԂWǯ4.k3r6˗ԭFF͜'3ZE@xHEJ_ zB]eH1@d Fu;Ճo-nLS+x09T5DŽ@x,/GUs-BOwN%[ tvW[*%)zE1مQi-oLyE}4ݹkO(CpX>dֺ.b[AOaΗt 7{c`0lsC~HQ`&Y woW4|'J*w+yǷy?_[ 1L{1Dg+>XJaSK5ro{pG.X(#=_d"s7vaKV(}gW=h{X1D`vrJU"{t=؛K`C۲LbDƽ:4J2o,߲@+X?@_="MtʸϕmyipZ2I!:)+1oيAA̝+ EC"$T#Xgg3WWq\O9e,hl,c8pY,E|_=񡜡_LJm:+B {uaU-j- w&мS'˜~u?0e -"}fy2U_YDT0mQ%$܍+Ⱥ7FĤϬcQzMۆOHaIU] AL7p >[F-G GLQ&܆],!fúճa n,T%7uR8v',k[6⊖n@m6NI5P#WkGV!hVlpQlLHfHG/N)39}Kk޾LXhV 1t1T4%KVa AXp@ $TIc x47?6/q%#bZ@0~_Uc$Ё"Jur$ڋ,0np 8A_`3DX*ݻ'8:!e2@9rXo`}3@2 E`m +$;+)A%,`-* ܹy6{jOQ7 MFm>Jj. nHkYh[,h`@>!D ,3p#6-nR /v1p%bb[\fMͰy&1̈Z=j1#L pp˾uQɣ{[c}`ĮO^񔛤D* p8<t#9Ŏ _b ~ 3O x\6,ejgR MlК+x|w^eVxi% #ͺGq {dkICbh_Џߤ9MNm^#0wOa{Tĺ6൚LFik.̸iY]vu@4:V9-O.8oQ>K)Q? WtL,\i[[/@z֓*3ŷ r@QlG+3~4$ $V7%7OW/r9ɨ̠mW>^=|\ #k˼qJD XS_ȊZ/N=IemcCsNA<e }/i?(cs0,`[kƟ3LN9AC;Hg)ֽP= xtx7oF,$#~cޘ"l$DQB@[[U֏|$Fjnk#QKt2}x&ҟw’ `Ĺ +Ɍ\cX@(^FcQBCZ].kLk@eԖ<~ l%3UcKtIHzdYDzӂĩA22Jk]@˩>Sb%oH/r 7!.]m=nP lؑzb_`N\hͅ/cg U&/`WyA7+ Q7~Le|[v24g PUu]2r0!!څt>&x]x$Sv+#`Ū\iA=R62S$Fzn723Up$MGPZ¶Iz}|'L1 7K Yt>~vDH XSl˒64k/@u@:M,+BiG!t EX4{WjѦ)_&ןRv^Ze>ѶH yk2`8z*~36AO1la`3bb^X ;s,Ly YF4CܝqiByx7ș ˕ߢ1xF:K 9gDu5i.SB>'Tbk(-e{4Ҡb2?#z\=ߢ?K=#$47f6Dɳ.VBD[Xovu=UxNAȣ~+ 2ib<+h,7^fV{@̓MNʺqVSq5VQreJ΢r9hCg<,ˉ%[1s 0A&3ĬcTl۾"k{PR&YsyM]$6zup5D5Sl:rP⒀ ́;#KkX*XU6ͤwBC=Wփ-䷻X|M%j`jU7>ޥ^1bJߩ_{~1& vQ4?:ڟIodžGMΜiÆVD*vS.A0>@^ndp mf#ig+t/'CQ;bݽvW\}avm<…AX381Z dzYR'HLTBT7VCU>zG-b"BlŠ$zuڒLr̄No{WUw4Rͻͥc_$ۃRTT6@Y*,8@B)G.Ұ!'p=1O?yHaR[2 dUu$M?"tሧfȸ Nv4RXD/!E oZ -s_ZB,S[kDLBoDxY&:!.HPޗ{0,dӦer5mq7l=V\s8 l =v~5$'DfB~=_Et P=W嘪osiϘncSf}59h wU@%.a_ؑkA8Y'@ /˷nFG2Y_V~>0l!lޅȇ&4y*h͡v^cDB4kaH>.퍐=|U$hqxFsHJ Μb ZծkXD9zߎ52zG+4_KىNqJ?.9/y[݌ >%B@ z:'~j.z=Wdz5D#l_iuK][Xz@ϋ}e.'(S`ę(t0 5HکHWAhQo4|Cbs=4{F`R$o.NQ**o֟PBӹ&.UNw`^#~냟Y0dY_GbY!)SaƓw o+r1\wgf> ?7A]>MYљ_K7C  CRh[ yN=ܑۍhƄT֐ Wᢎ*L $a>ݭD "7ĒF▾M͝-(Qenrf23GA~b =;: 򯮦]/K,dr;c%`l!͒:rjytHZei AX{5+|M Z ~Ӄodfe хru&z4V+NbLh?C}P1*C-Vl֚ @" \ 2 HZCq>F.[^3 T\eV&oXd_h~O/fTǸo>\\À)Px T Lu(_vm"v\XD-*V8U'&ȏݓ/!snXaՌ2Z\j^2+÷N ̔(Q0U꧘U<} 6HآX´_PMSZi/ߣ18>%ywljs`p&l30+T7OL\Jv4Xpz"MRoӞkrǗ29awϫBߗp@WCBb]VRT=z_ZRGdUpX2CN?0ׅ ̢? OL M57KOhF`TV[qF۷^K9DŽV(R̚ KEؒv~/z@DSŹ}H_|gҋRWkbw*- ڥ)ܪa;ෳ0g4~F6GҙÑ (Ie!|ԡ H[b7pk1![qn s-ycq b'SKȸXFa}`{~ AUcOMwp'ulQ%BLE)(sN``4Gx_cghje5IT_~ :B3gIy3[`3mȶX"gϕVҍcVX5 llcli`^8Z())`# Qn%u:A㒷:(phA9I=k }<@!.`Rb֓d.Rv |R+oIw:C4J%&Z56QVbBp/#7]To;fN1%9{.`} RڌOq-HKož>4FUj\.hMWQwX(UWp}PqҳBb"m674Tܾ::l[̕u$+4X! 3֙;,Q"[ y.A4R_b)[ FZ Hvz,D 3}M{uܔ6U<<js`Yl'd @k\TOߨZ"9 9q;avk {d1ZvBkiURؕ`%&"c.mbGb=54QL ;-H`"3\۲-s)qCwk( r撾:E80az}tD.X:s2*)e Ź^$џY 0yrOOڈ@3B7 WSg۲f pN.߾zOZԾQi7H_u9,.5a2h' r?_-6R?/]B^ڳoz ,U ˉ t< 1ޥ hė6Ngr h#|++x_RW0Åˏ*@'C;ue~h\Ŏ=[J<) Qce%jGrJ4! [YUHO}!Xhhg[ .M_eW(Rv7]$x^^< srx~{<4wv]9 sB~.C|I[6jLil*d&+o? _TOL@ؤEFN^$bC%3d|\1`=}ǃX*mÏ|.Z6jҷ 3N=8Gs*,`jx^g<89;=i [ NLs}FA-h{qֺ|P}(6q\_&K ;,}S|F.I)Q5h!)ΘlBm[Kd$Co _2Z9$jW\$osg3̰̜ (l MpY0V&·NY-:9tל2e5Rv@[2XqqpIvҺ;@6gɮ@UwMMxĦzv.ⱦ<|u?\ 릨~:&XulE&UQS&nel P yEK+겎#_l"/TJpTlQ}tqqPj <խD"?epwװSE.'f"轐2S8V>Ɍ W+1ZIq,T6( PK\bU:KHu UA8^qG Ow`@Bt6w7zfNg^Ca:y wkvKW6g_jL6ʆ,YW<9:_(:y]c\ڎn7MrQwE: N9cUYV i.ur0 $\' |\kJ[ A`B0@`[{Agr <}VڵM5CM:2] +Bw Nlq?Jv'#s&OB3j?oK|Hđ:1ՃOe SP~Ĕ$g2NPZ mw&{XOd69#`x.+a H2H .CDPP(nj?AÉ C?iyx=Sn- Vnm9JJfl%ٌv/b_9U$_c/15{ *5c"L "x5mO( vghuuM ;O$d-6{2;#l\P'wH ^8j@} wP뀶cE9="(QsiV˯Tκ o.T!ѹ&:HᣲϨMn1%;PꮄbdY;b6WБ«ظ%:{>M~M@Ema.yd3wao%'dx(6w-S C2l=$;?Zg Ny[o+nBFC&0@m;Ӎ{cpsTY!d?M d 0;u<e[o͞A'7]#~R0-&>l,V1M|(iSw.u‘ۢ`gIIyE<jc"J/G]oR1ݦG tfF̏ e4>]ު.BBi;o( \TuRYW O] H_a J55!$^p4=ېny-no 0LA#G602dSxqd8|L'HYZFrrC|(L[)6c{gS7~ˇnY 3ZZzTôiEWͩg~G2$LjCs֕EBG5ds=y!~tcbx~OǍ>݌*ߖաLF5`ξRLR|q{bWɓ^7$rR(rBl|&~˼Ĝ3?.E=)oU՞4[gW6ޚxF9-mWi4h`Щ`]ݽ| /OXH |IZbQw~!'ė"4jSߘEHˆO7M@ƂWּ@rn6o* F+}t\W(mpo_|8ڻl!4$'1W@\BKЏC'eT$W(+MJ/d[jq& IٹwKO3󽧴lYؓzYFIC#QV%mryN,֏$&29tCس|)2C\ [ogPh=۶:EKh< =7i%!z@ DO1\ӧH7^Gq^6H[+;Z DnO#*ŭ)wk7UEYɀ #u^+(C1DT2w,6jƟ赏vsBbЏp5Y_}OˆGwNx C}QgP@:xm ^:XE9p[1]P'\{(@)-mhUgSʗL=ҬX&眑I2Q˛J.:if?)uW>=BlS$`!11mX.d ],cT5f:uuu֝jJ12xv4|8H{'I'2|DQ~Bv%艟.\T̓+`׌MM`ֵTj,>ia{>)v f;1 W5mʥ^JQ{5mCْbԜ *ȥgj&h)ӳ/QzÆv޽Er lcW]yύ"`;a q5hHKPű9EmXyv `c Pk-O[Hg78L_9sWypJ"hLnrKсuX r ;!=.HmGϥsEN$jՀ ;wScȱ9.@3"dICie_/̆%}m!8[fHrKY`[MJ~f[(~8Pbư9,!=Z> Gvl_LWkՄF3!O̧}f|d-8EݻVPW Aq<`:zM E`+L}>ʁ[;qJ=J{4>)I<)nۨK W c _q|bbU2BC#ӞBAfH| URVHVxKm{51LHX,err C+Rs+q ;( sǚ 6(" \S ( ^G{"šm)[Q]V) h\~Q,4t¤̈ "$3p&(XL9U*\)!P"+OA\JR# _ ]x“<8 *ᙃT/>JEc4-ţH1 b~Q, \5b]~9_\& ¦ PCY0g/$9YM@XNXO?ӍyTvk;4JoJ߭;[eenvnݰ r.igiI7-x#0o8 %'ͬ ja|vh..2?tSZ2ĠEN"wTuZ P=jq`׿i\4ֈ푕NM\`)s(vplr߯-PoNCƻ b}9A^( xI%,I p mV}xB1MajK~dc% xfGc?q{Dɪ >0H0- ?JdxO!6N.瘋p)defY `[>%z~h€´-0ʵ39/A1Ie}IQ8IW) vŋCyV).L{8 $˓ۊ\1b9V34}=O]n+wv +*8VEr l`故&q-s[bBo:X_29)L BLWٞNtÞ0Ź\E(o Zf[Xx_l 8#¿ST8p"Ԁ'uʿ 7P7p6=X* VpL¤ApN$=j2LJQ)k B^V|'el ?דh [2[S%lH9\II5籓K>1UKMXÍbJ12.H -ڨ*K,S-R} ?y) sIZ^{'fzQ~z+-'c2yAV? T r^\ᓯK,EsNPzf [I3tTW3LAst,gW)J}sc n<1t$/d!Va+"i?$>p|>xg!k4˰~6LimӃ8D+i;E : ZvZS)lq; J7sTaYņE';t\NJOG-'X PJ,vi-h4@`|ü0 ,E=*(ٞ97N%-CГN`ʼnyritkS'01Xq:\ɇ5VKӝXH_]8(6qn>4Y '*uvU?ɲlyбwI. JNMwFEȬGzyŗc9);3&%0v400r^ˣ F9 靶{1Y;ԄTF ptkC},<.Or׎qZ9(fᘲq̕}OǢe S kN) \ (BNTl`.G]I TQ`nAgCf :EFGβ`1G9!> ͢һkN|wrvBxœ6iéC]j+c)pt#詩w 0R2M]_G؀MAѿf2O;L㉟sn)$R2/0=.I{u"P e0 D(.;;Gf܇34)&IWjE[e?rTĕnv6oi1 L LHCpIҁH(۸Vl,A5qujf(Z}ոN:-K2~J;AT"3XhO6m qsdԅS4ywYI0"|w?,a5G$̴yZb}DbXe1B/B,?, B59:^F6ѱ(U``n )2:LPIV1z>c`߁!{ ;l%=1C9*q8%xd:𽳧D&kӦ|ed.]O}B5,rc B6);l%qq<"U҉u ^:5 `+.e9i*ؖOKO?=iCiYpt=7l@$JKk_W/ijhҟFS۶B5X|r i"~sBi_=me{@4:C1Wyqy'Y̔I9E/#>NsZDSgij26Iʨ5ʋ4wx}\S9~3, y2t*q*gmQ8 . %ʽ*BӗEAB:s1)&B Hf[˪+{ځ|D9Z~RF#: pbǎgMa|axO.a\Tv慻GJ@OS>ȻΈDk%1V(!6`,̛Sryn$ou_4W|ĝGs-?u/&ʨZ +s9tʋcJї-#Y\aON(IάUzd7 FDE$HZ[i<&\(G>eOf'o0:W5[eDn3fx0 tRm Z2kT{4tLkd&Y(T"E>[]uRo%KH NS2ഉ|VB͹P34[/n>Yrgl 0VB|Xy35N3x 2ZmɁk,jv@@=!nJdm=6%X՚X:[ce M5nXq_O`da/>6Z Lq$-''arӕYG/"꛿䂦QLgrwj}9qyR8]pXP#RC&zߖw'׺J%= |ʎL}3B x9&NkUcjƇbSݚrWTvm$iNd"r`MT@92Ъ:"F/OC/1eOrqL7l#X 78mE_e#5qh @(W7xUF7T&Uel>ZQ0N"@`+d%0} ?OyӪm\dئhDXjL7*Qąc:_NZdfIU).D?<4qM;!G,hbMY[|V-Җ VĐ6Q\hڕ-}۝ɣaAȖPF9w:Ix@6*бN|q:Bvs&ch'K<+n']0*o,%2&2b 6R!rG'$ΩfĩRdNWz}:liXA$75зiozVVn2(sA,SHU IUj`KWi'#c-)@?fDj*xfr%!?ɤP5{J&8(HQ9hr\3pq 51f3CN\,HK>[QdT*rfu!S8VAU-aѓíE?rD7@FcSeB+(0jqH>ו3(?}xv۹K0k Οg1 BP*@m7iaD@#e8NK%||ܘ'e]:fi3p<%J` uB0T}I*I4D|$79!OJݢ*6˭k!:fHH/Ac/1d!b~\Q?ZzR% Yj5.WDlx\*LQf qHqE1H^=u5b5p+oLjQvDeSedwwa3f'GHO6uu#V cUngs 7gs=v=sEP|#hqrdmUJ0|0xSO[pפ0j Ƣx¸ΒEΩ,:&Z;RbkvOogyx'J^; 0Y&.Nٿx]UƵ=%UU~Xpߜ(TCe~VFK@|.S)$@eİu@)DXٷY& O3(kV#SA=<1N=1Euԙ֩ l]m O0R#W0-pۛ併aA&7? .1R(ܝ;;)da%8H61[=Zo3L}픟WʖɇHrI @Gnr`"! !Z)ӍN89E$_%_]~'$4KYPB rJX=S)&ډ{LP?oF; N`:skAJ0qpAW퀖%/҆BRv ?nzJґW**cZ"$5XʞX-Gn9B{0ko:lj*EN>AK*f'+<pX^CPdPQ-}^]EKPvpWr'i(@/b`%3/\`K&3ml ֨4}věJ6 ^/x9&^p~ufaoo{PմO[>xџ+홦9v Fn0Qqטo~) ;vV*갗@:eeBT}m-`R _ηWg Ҟ @p:g4ǀXL ka-0/6Ÿnu:QT#eNXdRõNr ,a /P%?hݾ:k]-z7ID]-zQ.@ VωQZAW?NDf݁\N#ٻ}_/W Yʿӈ%My4$Ob_LQ)8!S8{T"qV&z'N2~輠Cy7<wDƤ.'2BQ5GÖ;;&qO @svwbz jGM) 3mŵ?#5_oY[Ǐ!LE;4Ojvq#)¤`M$DcΑy1z:űFU?ۨbr/)ުxԲ)E?5-_HJP~y&U:jUœ='=cg2 ۚWP.*RS>LX>ӗ2 C)tE22fs]x9OQL5Ŧ_.QZiQYbGxr4YMB\eQ #k p@[~O*n9#tgAUգSo`߽P81F[ǫ|U)/?xΦ+F&0dRMqJŷ nG*xi{݄.Z6S՚K0׎ma e6u ިqV׎O^wmk=1[ؽ~jڨ%V'/Ldc0]fLGj,4\'8к` \NԌl."&RZH@\!ÈhsÛVz h.jiSt9F9eU١P,%O,=l1uŕyZ!' r-x^iSı]`D;;CB:#d4?smbX laXk9heBZ{^\R)˝;CU[|F17Pl?c%K-+D.4h!Ej '!%JC~f6;S{P2Ɩ?ornJɣn F<$iNaVhzm]M~%,) !A⿿" m]GgU{\-_W_X6]P 1d9-~rr<_a5673ZL+|0LCU[xa'jxM\nP}JgUE'|)Gbvinֲ^LL >>i2JXD?;c_?"$ k{-o酜ڮ$rx>&7GaW2𧠪c-L};WaI0z27%\Pgу3 V"T:Fw6.̞=BAM{th[eWkW`|^֧Q:.+gȾZ2f*ܗ;y@b=9J 6E-!/TF׸"_<-D nXNB|goP(^ ƯVļmqI3xLG} 9DĀ4ҴMoT p qp/lA̵nLJqŀ#U! ,Jn#BBf@`_֚I&΂hrR%a5{FlWVF@ =gvC .ڭZ38_n=Vf"Ls8B3ǻ>y5;%KWDbD{g*^l _v33RMZZ ַ̝D)̮7%=1DoU=jz1[0M1Ō7R[okx5҇_zFeE(݄Gv&-?7?3qک|b:서a{Ќݳd]/'6LA~s@g}Y]nV_\nU k`5[|oG)7[OckNĨuGi"SW~w)mYMI|}.%ssF4¬YZB֯pJ@SZ@T!,WDc!mYY5Jmg`:r+z= +e0c>0BŰ·T/GohYN8qs !L;;Ȼ"16ڞ rAY ْ^sEY(HJ> A=pFŃivO NB9imLH<"/pGpqz pHiGՖ}f0]|œMMBn *N`k~ACJYV{k43+>D!ǹz"m0nETh)ޥL˶5=սE T$3ɢGHׂFk=+W<.Fs1-%Q@9E.M{Ip?{kŗJ Ց,Fg X/U~CYB;KW.8Ri|FOT*0AY Fy <CCC Yy:Ҥ7U 03XGkD csscQpo0G4eLPK܈H"S$2h]'gcv]~w6X\v"ΝԦwօ~HIxm4ӰzE9h͟.N>&jhd .Ήᡰ[e u#&?Tˆ+Z«>U7ݰr t\߽=GcN6;6 zJTsLSw37}kĎG2t{$rԊi1C*_aT#%B rd!% dzqb,l\X}g_f̼QދIs&VRxtj (KVBMٱGG.[B.LM(!tQ̨lPdЅ/mL {3n(Vmf}L"|MEPnIiN'4IͿ҅l˗)ѯIV``"&҄-$ɽD#zSZX iw Y3ص0)?KG"IfvVB4x'0>U)@ פԣ8,ɊDNJI՘6$G$zuiB#nH| x Z!$'j uyG4 q J =q=ݞUC$^~)WnhX|W/"b).)ٯR_&$ugӎ>M 2ǖ ]?#&+#MI<+J ߨkT,e|kTi>Mg>!l%]v=t?; &Dp'PdNbռ 8>oC:zvpM[z r#@4WU~6rA|T7G;|W=I(͹ WTc l g{UHn㐽^4bNZd_H+b97MfXXo˭';Jyɀ)Lj.$ mr(˛s_>jBpj6iiz% vID?ǝyq >A_@]C=FqϛV} ?~VmAZ|d<"IjBKUjVzԐCr|׵y"R#{ATOњ|U> g#eg)<e6iW;WV)_x רg:}GB+,,;S- JhL^ax,XZBPg},l(&o|,9U6(qJoSߥEobaBSa▌/ԫt9l! yf&,G7[hVq۬{$;tV@A&/IP:j>_T+FII/xoUq֗o_^RS{&Rlʕaof9=eS@c(35Jc*7 @@RY1(غAwh- @~YlۥڈXvfG/Efxs#-X,*KN'vFXTy/|D&AҴV1xLwU{2s Ga lQ)7Y:_oHeT];6ʑ^ @:Nb=Hsb]vm*^|<(Gß|"nQ_?+P}Ҍ)?A6ϪW&(0mϲ\u߹L抺>L|bH7sv?ʝOhbrfE1$d6X\y\TFF[NYZeuHF+ MB2ncG f8Ѝ ^Gn ϛnEw/Dp]9|z cxG݋B:Xf Qp)H@h !n׵<8v)I2Tə"ԺdN&P|}t6>Q[focRHMLn6Ϫ1O_9$YvTl`ö $)t{0,G`/MA(4ŬG͖XGtqMR#j~h]5M:NCeEPDXqJ$1ܠ`O,;#ZBx֋찂>fmEM|gzP z.|%Y/l`Nƣ,RqN;{ d5GqiPoΤoS0Ԏ?xz _[e ~^t6 cnZ=&2d=66~x$7ROc'dCcfw<JP"fetK?`ʾfW2Bҋ/Y| b[gv]Iizk+}4q'B;N?Go%"56`ra۠HJB 1t3(Q8 kT"nYVvV,ܟɰSerЋݎF*`v: '[#Wl0@o% ʲuϰE=6/ӱ+tfKBj٭n ge襛7g:ZŢ3s An"pUUO@D +jfXB98Y@y.ZǨ Uɏmʜv~7ŨN𐄼-PXa"|ܟS[8?I~1ץS'Kǁ%RMO$q4CHզLtO= (.W2X9S>.2j Hp@nBCWOy`;a횁ԉ$:HXYE;} ]^hj1DX ~N]|?wlj?J9,ynO?/6{h{1m̗6~E,VEGB l{fjgsΪM2 7=FJ@=>m*.=$`b9 ҄&ɵ ҁ&qB <&Z36>9pr8jȕwgTsq+\/p1_(`P3-r~˾Bbr7yi]-E3 MԡߥB`<,:%V9~h}s~.uy-[ܕNīyj;+Ug SDD~6q}p X/<:T3m@AlҁT*"UL7߿Rl5)i$$|<&{q|HpוU)׎H6gY9!?hY'NRJ+rt}?D v'Nя׋I-.ݦ{CHFlXщ7%r=N#wŐ2w1^+Vk$X{h(  z@?slje# 90Q4i[@|ɳ7ɼ^k p) SS &#ʧ }[4^L=o3i`"X WDHKtCHOPN*Y`oؑ"{ rA{03,7^E6K[ga{d-2F _Bˬ ӑP.)ˢVXLc/VMJ$e"7X@Hnaqd.F,|2Q+rFR&[tSk" Uۢ)4;]OU%ahbsVW)P=v$S Sw玤4p&yjp`lUhAM5X\+b+'>b0 \W$wT[Z<('M)RZ9*4PA3ȦA 0b&;*B]{ZW/Y.4'r"^lNzȘu؝TV2βˣ0ȹ)]qJO@#a^݁]2 [j#͈Yؓz@LoB{s@V g+~zdy8q=FGPQU:%28{?ٌsauk F+:bF.ZEj aVJk}De/ufdm0gPz6 CU'oL3biU_z¯+ՋG"ИRj I()6:~i@({?7ʅ F̸o=.jJln#)ȴ@ 2=WERY/.d8ԉv9eF"Af[D͙4vk@;'sDuo~ L>Ə4<mQoMܾ D~I9Kq^TD6o@+sb9]>Q탈OP]Qq-xzo S f#Ϥ΋zX`^(wEzQ~z"074Y?K z3f}]}nZ+Q#,٧KXۥfWvmҡ'F1KOḥThzg<Ƽ\\`Cі!c]ӻJA*jXeYE|rϓ`"@{:PfNuXt$N5J#1qXFMFR{{@`AI,01 [JhjQs%S63UU̐PiFǏǸr/p7Jl<4UBv1Я?Ny|B\GEcb!^Ed/:>}=Ȫ:f*ho$p[aEJa^C$+ڐ6/mR`|c ʇd~o\9|hiX#7񓲻ҁBGO>1L"0+\XѸmy2'y} jN>_foy.ԻeNA,עek9 F9ې ^6jy֘?Z:L/o 1N(H>8(~T ! `@ 0k8q y9u\x1HjW:p66$*MxaDr @ <8. Ne6埡.g䒟 ך;˿ĻUM⬚uc$W4'Cq2CO 2Rdy "3\t4* i}[`Lkl/.[dhXUud?;N)#T}0R{ytfگ:3p^w?MÙJU'j䲭/M;g~{"E1O_WXrՕ]=@Y @_Qwi ߈>t!f0|Mg; `^Nq`,߾8׾p6z%[]29w}&Y0/1ipu5iKƃ=h%t$^pN=kƸH~QE{ -e836YHyN&d铌D%Uʻt, Fn(fCa.qHD>K+Wm' d0@, 1ֳ寡0gQ3[T5YV_xD(e #߁J>V st;mKڄL(Ԕ0-tK ;w ||,h7̏[ei4NAЋ"K~*'~8DP}}YTU({|:cw!34ɚs·h`h3#-`FzJXn?s^#In@S 5%V2H ttg8$c2nl|ϏY,0%(d`Wi7^|%U3Ύp߈].q3CK Mɸ Jnj{)FNl.cHџtR= ]{a \5cyuH/L2WRdzt/!qJΔcBnjh,L5e>"?@r MìNzΓ@vgauHʐNuoE\J;u;ܟj:EJN=`dCvS{y.e,ϛ# NW)l$ &P5TI/|,Ҿ$ҼA֙=r,5";Mjƹ>r&o*M<-DLy0p\um]-Wyf"x`LWkl~>%Eo,ҷlkf޶4WȪ+*/@so=D׆x8 `Y.R|6yh#5Tkܕ"2n/X:b֋q*&vfCKH˃1|6H|| 9>ڶz(ϨIY_f9cu/D; *3gϹEҭ]h?WϩdZ+iMQ@;B\}~T VAj}” 0>;[G{Vi80+PQREW"Ѵ,339j !&hՋ0.j!yVUlcR ZtSϐ"{R2A8|L* ~3oF3!5dhb8(釤CNĒdS獱{ռm 3H(UYJ4Wt3xji8(7eUo 4uk)}A<0 Lf"0s)[.QQdke(z1خP'f bZז d[ry-H6p>VSעb= aB4yِq5 ~d'@8s;!#_aHK,pAbC k_ Th-muI}v D6 (y7)P=Kufw\tKxRs>(9oߓdʹMDiýBS9v^qJ`تcC8ǘd(zh&@=tL2[[=t!_W %n#aS+aaT5JL]u v-W{d X~*T*oߝ%=n'b[ Fv{I Y'`Żb\`j2E*f|^ ;̣A/ Q^H t%0*, ۊ_ Z$|_~"~GAt>榞\^ct 89?}o;0 }8Fބ )clCi B<b^[ ӥ,v>;v TSMGDVH%uzf?2y 7 LbwGtq:V0`F,E~NK *X'PYGU? 74lbee {}6@ϼbB\ Qik n6 nhKNQ|*4a*`O&˰#O=kOhCK?ZdHE;'xo c6XR2fUZN4O%6vNuD-·( N<J,8NnJ8#.4!]&Q$,k bȦS#k #V k'7o}:5ﯖ^`A2UcB8~]LKմJ9פ Ћ8"|Y-[ ~~!U2qqy<3J.jT01YnU!>$uL,-gfPY5])Pq ~t>'TO6mSαZHO雷 4 S (Lo(s'԰aaybxʼn8iƾz_o4N/BK, l K Я}-{Z:[= J4\˪Ic%VH?jNdhN G dž CR *$/HsJTYxT!sBi_dfxe #B0hstW*vAK4+ߴ]xo7ȩK_/@WA'YߒE*^s3VTQO 1-9cdM0n ;ܺ25f*=?9o*S;z,g T^,H=^ ^;* LTee]@4#baIdB|l!N+&ΐLj]yUmbI&MŁ 4&L q-$GE=ݨB%\!+hIeSFW^#dΝiFe8shBtu>ahߵsհXZ|fnaMQ8\ TP6bༀSb9|p55*7Qi Vp%0.U ǶKrp6Oewodxj/[q:(|Y ARuuQmJ,+aD\NQ )փ7 ۭzb83D^Z$F 0. R`C!_"TN%wF/~t.}8P 8ퟂ4?j55DN'X/FzGU[5i X<׽Vzբ IqEW[: *@?E%S-"Qކֻ1.XEB%H@gUfrxG ݿ!fftE9D^'?UFzݲ9N4Y>)擤I.IJP~s֑@eiyycE-)hI'`ֆh߾c&վo?r\_)/9wH(z Go5ό ]1yT c[w 59ӍſGPf>S`ryF>L& z>G$ioXs&8рN@ϷIS+Rwdi 'Nb\d)GM>goVZ;2(zeE*bAc;anj$ ob- -簳un'aIF56 M%W+y4P.^Z0IQ]xTHl܆ GlvCf]9G"*AOXg9n}>2C0`>tqz=AH>뱝1Ls2Yv7MzD!GZAc|IU|bTZ!rvSaهL .Jv7P)&@A 7FVUVnϺ{A{ArH}Q \ZwGlHiQbU1Xv1Tk,1k9v*`dWItMA?NRE \f5˻~_9& p;E  "9]Uy3 tu/31IKg;oo^Tu)Ns= 7]붺̴d/բT`FKꣳ3& w"p}xпczsR!{*ʕ_w?.maFN5y^~-w1B@V1I\3JZſ?Zztdm1}N`H7;ɰ^>aX,Y[wQNٛ)i7ZXV$l2G8lvdUpsnlB}J#kaȺ!Lq 9P '`E9RIBW5>?]@DnwJrY;ʒO9KrVWNXXFmzdQd8* ug>a[')<ȂНDC2ߊY|pGUX:D^ aoգ$$ٵM Db'#4Bg2N5K*a}__~Φmt%W3#*K7 ~*d.ZV-Ly+kd-j|krsD@s`]4cC&d1i O>-IJ֧,A̬DY v_pXfY|ʹ)'7DQ4[(HW0Zf)|u0)ƬRJuӎuK&F6Mm%õt(ϳؔ@LuEZY5fR&m51ݡdH!ŴwVa]3d&e{tm CVMg*R)Zx>.R@9(,dJ]M< EHWvUjb;g3NuL㿘&F$k{Tg0b6tXϋAO q̵&n&S}Nw_hrW*o焹m煚ry*~^19q(3LVSE>4r =zs[ؑS[X@pEfCC9 V}$Z>%/dӟm6V?1WP'$E ĉ(LS V5d4Lۿ$د$gC|`ޔ@bᒬ94J」#_ ثgwb?XvY}W)G/9^bq{AjAyƤrяE ).m+cL+.:m3/)KN0oGr W仭Az+k FK)}tH=~sG/+qx:]CӦ;xN{s>n!ȁi9'2PϫtsNֵ_7ߦ02}鐌=TI I_#rPG /:@ElSt6uQN5h޻is60 <]t<ݶvdl]`XڧMcʝLQbA-7 .)W&ݸ|CWӬM2C$aXƚ>5æS0uoMqP0mr3 o`[ 8 #+!-D!Qt%3DZ˳ڢDT {4L%G1$㽾H~2E2M45J}T2P^ſ5fh-k'ӧP%7͔'vG̝%jp>#?aufVqQ盶087ki,Uג4ڟdFBeQ:v{86qXw[{A@5 K i:=ics.< *(6!+< ?5}R(&]̮C`{rnú]VoF B.1%j`p*}4yk̢J!>@/|݁їƩw:rg={d3әMbw&8oҫB* v ?u6љ14"fKFǫ-*SwL ]LVYqۡqnJ1<礟%;Dr4Ƒ>&g?Orh cWpZ)KFX⓳=]Ӈ~l!&π^_Yn#PM-1%87[ PUZ-/BQ9b W2¶HB=邼ͦ':7K3Y[j+ r{\"]D g#i+#V+8r>b0zb8s|E[-R^+]?HGL5Ml(;'u?^H"tepA}r|-zhA`b} JWΦmcҚ:TZ! 9]ōQlQ4kG_ ҒHPg-6;`AY>ԩf]l8ƷCX{ tr|DQ:T*HAP㕶 IɁxz%\"!bm7%Ẹ̈K )u.I#(Kzz2]znWՀ 1@ͅ>:zݸцP;ICnBJ%rFF\柳r0gW*MSfG J8JڔkB%R"z\7fl{^ ss%q+cy$#!<@reA||7 [Ւ+uqǢh#^r2Kwd6p? SU£Z&OA'[vAe P S-DG=Aexى 7qQŨ6C S_oqvjNByFvؿ(Z~kMzI&h8uWiHoS!$thNfT`M[͛qi@?춠d'fSvTQE*r9}ynFWjw؆5J c7lP%]Oz_vwZzK]ds%-BAmļ"Vl"vlxf{v #9l.ф F(Oɣ]pq+-%K>#EA !!q8+IxSq ؁:ASIrCM"OM$'Y'+DO|ǘlCj!Vx=7|f66»9gvs@vVԸзak9YR%.+7ι~dT)d\1mX 0HZ*GEF:~c GIqɆ@4Brᆛ+l:ihwc 2Z:ዞ?3}_K 8g6Z˸d0sg%y%MrvFlQS)eIݘ&gd*w*aq({!H>bЬΩ,,v:)u. gQYֶ(wxƑ'/'ʱ:Df\$2q oh J׋^jv gh)B>1ʒ/VnvhƧ:}O=Um~^ %Z3dִ?]'/CXW~z2st@1ܕ-QyyASt, A1h&y{zr<`Hrm2W67wsAǰy\H0R#R4&N{~o%Es<,|B 3e?T{&C^R0v@Ds02nqA,qG7[rX~N=q{n 7>ic"b KU /[1Lξ|*ħ;T`-PO` ZyiŨk@=Hy82ϯsU @{kqQʴ/%s0uӷP2{!Ͼ\83c!-6#)ZT95>#vPGuUyᯓQAښM"&x]ДHN\m"3>~lYk=ɐ tvri8=evua.dr/Fux\n.n-!7-[D6A԰Mg3bX drorԟ} HvzYvsm +&9%cC2vĔa4h]E!md;ֆ!'9oj|9j<)6p4e*WTW췧$(m^Rۏc[[98,*8G0f@f$p_xUhЅj0@{C]`G^ts`.L* >seg3wU{;D^ % ~pvy?o)f lp)Z5uW-S,>)l0Ĥ}~pOhDSC)GSXAFqE($5D!y!?:g U+`]UL9Գv@)Fb#4Wp=)|[ԩ :׽ 7Aø֘0+ Z(*8qSG.TKsES"I0W`l{m"},>V*ql@KԼfKe@HbөUz;{&\H9-d|ߟ`EZaM̓0ar@OT8"}ۭӳL3g'qFB7ʮ'JԹACU9yS[ڽ6biڲ_YTs(#4}r48&m ɵtz|eMd2c>}ݖR7yu+zsd].7 t+XYڃՍ+]n+@"_u~q/_E jd>F{qѽ+6Jpmk*CwtCݾZv6q}P!&x:M@\>qȊºGkG.fte]ש٩P .ƊlS DRu4rMhq |3\ H2A?ӪL"ąk_BnM'ƙj[o~HtI;?:aX$ ^ut=aпz#GeSdpz4zKV=`;:¹M 7{H{حkrq7U{r* f؞ ]sxc[1,=O<ck}58}\>܉.8&f;e'EjxrtvV,cMsĽHm}&q}G_+2g@N=P4#v40;x|<Ȧt p+ dvvŸ$ȀƞA^㏔!ޚ+)?Pbt QHW6PCYL h'D5!1B m8T)boz0wfY>ԙsqeP h[eU̞t 8 ]k1"`&@,^幉4Ft_g4?p"fJr_h= sh}Pw&OLj]6MӥSK+w?6xJLf:҉0F &ko)5 MCn9O;cOc{r&ںM>0FJE#iv^ 1,?BN2vcwƝ>2%+|,[^YAi26Kh0S0+:"OC! )P+d՚/,u(8PЅӎ Ex`6}s̬lˢ e+ud-_PxX7P x6i٦WہWq~oU^[N,EHPTί^ŧbZbrVݥxvΠ!PA̛܉+TT6AA36L$=-h[9ȤkՆ'_rCl6j|XZc)m47%o|Lm&lJ;KV7qz4s^NEjWj$LCЏ9FIk~xfkfpo`!R5v-Q@SSdoe]1骡C rVhP"J)΋\.ik 8\)TaZ\I@IJYL|^ڼP8;)ӬcL=TłG>Z1~hϨNtt0/1h{b@^U&Жj$!ɶ41v|aM9w'֐}ɇ:%IE0Yҡ)V÷-#<0D!:5cB X#*y`ys $w]ั^x{b=sT] -'җ7Cޔb;}k^t2XU4Y(\tN4#1åWK.rΈ1Y&C1wB@oO'3҄g8B1I%w}PaP0q{ 7h_ O@-<__Y4?`rЁƤmGl . A(ȥj-$ێ-ΞqowÉ6]yJO@v,cF# i~TKmȭD`*}qɤ\p" y/ȶ<|TUqU퇩4f7E@U보?RK /Dq|5,J)@o$l^nK}%{5l[[`-vU萕&#[ɺRR߳ȝs9$ziܟ;4!C&ǃÌ&ҍٿY`Z+͋p՗圫 `_kO=.6·ã11C(4椚lmG<ޛMN!]9fNrbϳ v@ѾooPP+㰈b nX_8\lJݻ㏖4ZEj,(-,Ion</vU"qj0 FϬg kBA@zQvV*U2leH:};ɖl/ʚG9|ؙ-0=:S=4}φ31 jb^i8+ 9y, '2 Ϩ1$mi"enlKUl8~ vP)fpuY7Cާ>0ʷ_K.%Ly256PV'CcfU)]D=Uv˶!2c>8cbk/ ڈnB'<<բ|k Dt=X[eBIC⤢59YŋlKf(XkXK80H`eLgf)cjVXrsAp Si(nZ#,:.J%oΌAMx:d)8^i>]_(TU%@3뛜TEaSgW@!Q1{`5XF#ܕm.K%^wJ,VDes}78n,?p,ȻDzKxls ‹BT"f0"DYBrnil26QoBRqld8é:=H!XTdm!DQtHH&aa. / Bo_`C:>ǗiV5-F{RЭO'mt% ٙ6͒D#J_ź.̃.Äň޶"riukXa:̙tqG)VCW فE l=$ ZԃВgX#`;"vYǀ 癈Z@%OfT+X’ʼ^7ۈtA ^Τ|onĮbvn]t:qo&x Uyjge5no{J 5`1OfoP- rvE&U!oDaw{xm⩘JᙈS1PJóHHrp8p" żx㐞MߜGn#M7S}W\ YK^ Z2cm uݡ5m7p mH?W L!DGe@t<{S|٤VNǗoOl.~oT>rҰGrp߼j,{Ooˁl@N@`?, zuH c_fH;-F_{ =hߟ+16"X1&3Y/2JrpW膂1\q6tL.v7 +}Rcܽak*a5b iL ŵ8 H`F,g>x~NqvzG.ESQ~8|u'^$㋢*%") ?(fJ>6.+w#lrTnF,iBթ;ک㾇ޯ@A"ͳq@(vI46 q бVTUUT1!cgzHŠNc013)8Lo nTOfLǑ|gT]8.q79z ]VMÉ((YAJ\UW Kb152n'n6Uٸ1鲌 ֩zUmj2-/Ô0xg qN4l*`:4!M@A ,j`@ ݹKV zњqNn_,nj?NT|7)B0Ac>XrfI^ʅz|.=_E`w/Kv3]qՅ҇"~Xs07pzO baDI]}q$+`︕|zy_!J **"ÞHaM}C돟 N࿷*v9iu0#cSےUXP]#L>`$+nWPxGHk闣mhc*8)[Z/K0˓^`1fySY =<<$ߤ&Pp2EuMxtZVM;u0@yqTY^j,BƩ9RwY,Mh i.Yf wVSga/+֍ьga#ĕ\zoK|Kզ P#ς$ }J*SRKK4v㕙Hzy>?W 0`OrhWhֿy!2a;0jlB"eu[;f Гg\K"s7+!rR5fzaXл&\XZ> eY>%ig7O(r " (*tzJ WR݁q<*=}lpL:=K[!^ZG&?Ȓ8wW} -Ձ7 $ȱ XnA?5`>HmK1Ar}೾0P2ʘ7yL"Q$rƓ-UhT}(|4ch 0dHcK"A屗! bOIlO 8\xW;)&Hϣ"(? n5M\wmnJ~XV+_!`-ԟlO1b1ko?p L" ]p#|WDc%\%&y0^f(w&ԇ4lf4t0Wgc>H i>&t'snPYDA̹qt`ORпHP:nFuF5*d5 'E^b9UӦ$cK#HCn1*NKB hjW>´F[U-ɥǗw$$_j>nC+R*OrgYrDVjȦʘ;9PnKL7}$=#5~{4Rew?8i=˶L.{w\J\tYFbq</w~j̀Q …2Qȶ@9#u<χTox4H|r]0dKc)$Zx;||r(tq9t}L)#|v~eb׿tzr%mޣVhNu}HhTy)k((ds>OzzAb0CǓMQQB0S\/Oxe_| _4r4fhdW נ}gRw(1`l8@s}h#8zOD}3|'M vVPFdwRa`͊,3XByjY~8Oqa1v)g)/uiVɸ>̈wK `q _7.[*@"$x6o)NٗlZWalR$&GхJ+8Ř ~2ӽz9dgk$Xآ<ǰO{/Osv:{ߕbT1q>e1ېj(?؁qq>hb^^7U6tH Or`Bxvu7_ 3-玂tZV" s3{ >1kM2RMs ں2PAL-6_AWGĸ}䞶Gx~Z\/gSw D}aZCI;ݝCvPCzJ3*=ár$8~cJ\1wbO$)XGΓ 84}m=J"d^W+-))'ϜvHw6j+]SqH9[ɟ ;g؀)6#>JMzwٌ9QjgĻjFѡa:=9:;qrm-VJK3\@oyFqK?);`KIlgm07YoBկ԰Ln}8MtKA[žϴszmnG!ɱ#jn9XA@l-XƘi'' gيjӵH@2aYm,xqB4yQXJX&$cԥ'S8WAanƏr}w8!Ȯua#"GuvS:pفasY'Q =<> iMG u8ew7|6vm[}D&LSa*nd%0ֈ?3Rorj}s=L/n(4wu O𯱻̈;4kx [ rz<O2X|۪&|'E֕Xg<˴#O|[(@%D wTb._,I7xE!6~Nҽ 7\.euZ*ЇȞJ= KxEL(qH\fA]ϩ?dEfM i2P_ W^C];H LtjTS$Tt>sq}SacBh Lámؚ9#6V@h*vt4F[ ,gQH-X^䥻 #ْEz)*}kc])y[@?~ tؑ?Ѵe̟OTpY*;poeRVVm3属 D$#mpqٔ|_ĬMY zG+w˛\#KWy!SQ1O`b2\Jxϲ~e ; K{cGt }:MH4K&#*I?͒Z$r40Z5p;ܘ3097]Xe`q2 Ei6ý/~|׮,'v ըidL/!Ouy$Q[`OCLg{胧.Ps>FT)-!wf?\ (wX=4LH'-I[-OA'  ss,kro?1ydOAM+~.w5Ν&*-7k@twfqB&:_\Z)(;Qk!hYTij3 &!㭳TAp` 蜳qIz_Y2%4㤭wwmf©ZL=; Hip)>zbA$dp~e<"ޅ#R-?ѽ/K/25GpDCov]RLg>T9TҝiSךy_ʷǞUVI!ҳbZ  z o7t܂*?zm3s _8͞.SIяi*ut1@ ]v SDa"*vqdEn,r.X/} j&i,pR),y1v26NAu,9!3cFQ:KM/~~g$p"ǞUky'ka {Xw kD,Z!8 ^r(a -Ly,rbV!e쪲/3Kgaԙ5ĎfB:A;$iicq/FWXӌ%V|ӃI |C巋h"EAYdTlu1c%Cd%P>z轸jJ@k&s{^$lյSUn o'Q*đCMtO!,e,s9T ؁Oafވr1$1||P:g޲x8%wy9rH.~N\='l e $V˕4dbKIˬt'P,D𼚜((i//q^̼t/24eb͂U@2~#M: >{ЌyV>p"j@nAsbjž= }PnSqMb9>g͸w)ݤ9aQiG1~ p#h ?*CK)4k׫!^)[9['`nDXR1Э~?jjIW~VP{2P?&Zdӽ2Nwũ2/ d_N)y_B>%ԅ>ڦX>i2@k:|hHfb Էδ&oN uycvG@"=)Г(pJW }QF<^Br7߸ SQd+)P']sFlJR-"Gkb,C?g+T*XP8A$SqT"(%[wbditebe"%|08ؾR=-< ",|}+ft:,Wң~zJhb,޳n|l=e ̘>8;51vOD `ʶ"V\ԟM!"?ZW& |cDC$s$1bge\E@/{Z3XP!7.|YwC~s'h X\tm$#ʜ»̽B`,ig6Ý3/=Hn5f"\(_u GGIۦ5|5%0YǴ*`R*򷇔1XC{Q*Ȇ$x}>ݘTe58"D'u;GZߗI?x[151?-cnO1+20ynr3no4*PZ@w svS }\r6,\MYvOUߟ6*,+!Gap0]S{|#{ I&fn%spNԗ;O(:W։u[=!H>2QJʚ*~"IkK긗~AX@N!0RjudHk 2&yNUkIϾp=Xf/QؐI~yR$SFXT ~}"mRiSYZ 7kSC&.|qLqo2T^w|xl +s5$ZWm I>@/c&U')&O|X#]5X/C@hF>م82OR0ܪ@tw^'y <]jPsBT`bYME+@Жu?k}! J,9e _ 6i-~-6vPP+ .H,b *:2ڟ<2hY 㡜2{֌ #@cIKLQPir\ 0Px[)9)H)Fwhk]{$CO|nSx@nq:7ຽBhڍjO߂JInduy}#NwWh> !S>w5h6]wWWQxCayM֔ ΁ȳ,6ޚЁC8IjU'p`o̟5%%$̞S\qe`8+vxpHU<3*ބcT(ЯdܚCR0R#6cӗfFM񛻕mW.ԊtkN+|_'~ǣZu6(vGΆU$p֛A5Ts0mCNSEuaZGtJ?>m Vu7Jˏn?A#[E#B\ɔV;;Hi7wCū;@BYվB7<35媭钟R'%@, 5տDK2.vM=:71a1:s#W?)h'Y3hA2!nT.PԊ}6;@pkYrYVVyoOk]elP3{R$Jm<\ X*o!'z^L vȌ*s>jwIsw p`YǰrN|x{vg3M`M%4Sw CǞxwSMD9#¬yp^Ӏ ?eУ bD s֥g F`JFݣym:Tb㭡Po⬞.]l1#ƽ@71*c߶i37T OlX!TMh&hvH7zmih)Υ"EuU& Kr4!"GWKHղ\F`$QrK!yEa)g㮃|qtsg+VMEOP`(* 1B.=4!r*$gLx(M!o(#"._fNX<{'nS^_9Jy'^LOGCEz߄ -R,@s2®}NJMROZzG-؞w5~N0t|̌gD0 ҷ7Tߦ!GF&/,9 p(I8RRB'>a~up+>3Y#`9ײ:359Q#(4E^DZQ3.5(zC4\W~-5p g_8ZU(DT]|3?[K'˯JF^ve.YhvL Xo]\_g5n}4r4aA>EZ$~ +젎uզG&sxrMw{=ZwOpYOAvR16bmqՂ?f!@ta,\pO(+z>kL_wёXjm/i|P2v"\J9T5HgėئOӮj–v; U[a̪_JR}ua=ZC,`4(?/{j^-arUoٖ?F;]hr&$[-hH/u}r=S7I[|y%m޻~u=vFN E {0z9;B MI\Ri Xo;ħQ r`hQD đfA5О_Ew(` Jַ$?آӦIoVn"kg&  UGN{Xkiɐ ҫρ1Jl)Owz?݌^쏰gEBF߰0mW!֟Ϗɟ)gBA-\z=/_Ԏq^wDW䍗 u"ʍg #n$}PxN +X@|CM  $><9hޫ;}p״ay_ХH]g:ɘF2yi&c96XYaT5~p>@sh=buhϜ> U.je/_/$wTB} $0[gONb`E468!![d鸼jVJJ -i@bZi潞@Jy|9Z69%5C"{f߳ƭN8;K>ٝEj t^ufK=J*靲!("fCȐz)ӞV Ԯ% ~>IrK$P26sC!74{#:Q΢tA[͗M˔}+_6'[Lh8yGY$wg~ȼ'EG!rPcW!o/=SGѿ݄P0fIuu `v<.w"k\?&d`dz}[VO A-gZ=,ldPj#-`GR!Ip1C0,˧Kdm[|a0MY`t=,Tp:q>8o{+#+\q׌LY_sn605g@:#ωCݜ*;{C^CQi.L !&8&Sdx'U\\Q54'dW%Bh`pktgu+P14&G/Mn8Mah2ǙɩspqM fZm*,[]!{' n¤4̥7ysJ]!Fq\BBeTul(l~ n5mEP5mǡ#K^WИÿwPaDEY>VUvEsguA7>1h5 LL'W{Vmhy1CFgyLKއK}p4( e/ǿ\پJ~ ( kȁ I 1Eb߀ꆈ[شEqsGHQ?ơk;mѺYn+(4unJ)l?ָ~Jn51]*6`!_-fWfիBE6{pI[Dw3k@*REH7o3*xdFL4t*?r0 eR<[dޮ9ٛjL(/IJ< VC̻r0C\$mW)VO|H/ӕ9}a}6vNFy9 *T.މ:iXe)56[ IGb(7/ )MnUa$Ec`+ htTi\`1z0镴nw+,O#jh|6V";R 4zf'm&J-y"\I~cVRwSDpQ0"[R׋H՗k&`[)ᝫ+p{W[+Ė$QVPEZDUwGkz9q{)qǩҺBk!(d\TvG*dѲ0Q?HّfhN޸iqz$ &vۛpBRxOW)iq._⢿$0&[{B>Ūc=*A0d;1Q徸; ]ِw Lyt&Kt!wF`VDHTAq!Eë́!`aQ7sy^ 3ZCk}Fטׅm.cohB~bi6- )-".fIotV3$h+ӿ&MbD ڄ?D2[2Lc+߈T= 8 <J_uW._4woylhhIQQduk 6J{fC5  (rNKq%7]3`^ 9ƇHUt040}~ vYC㲹$o‰K-T"ĞC[ig)LN 7d!39V42"/Qg!@ Ǚ,g3/V?l҅5$N<hwY` fDL +Y% wXCPx?KL*$7v|וZ  bç3\ݐc 汚@0Ww0W!jNY5Գ{K8vx=n/I-6on:cTq~y;}QZVP4ڵ3uHJ< Vv~tg#^5\v!f*,?0*׋б3.jjXH %|ו̨-ZfіO$~"m}Nl}Ty/ӫE6.VW;:|:E-R Xt L.8?bb%etP4h6JjehŽ3ix B{bҘn)Ͷ81d k8Qv7@\~W LaU8DL_d@Px7ȸVv SWIpCy}vp ]xzPxLJtzf#<0d\*NHfC5jT`nsBR@ ڵ-J"Xy nƊ5l'6a1b]IbBZ*.v1߀=+ p1k>(|ىe!g4|1XҶzlW`>~Ήhvfg5&wSS'iځ lx(K~%\ȈpuNR~3;z~@wm1h ǵu7^ض=M!);N$Tqn*0,{Lu5_m!*k&v; ~~Cߦ;|C6ǫfAjBԄd˘)%eu+MkK3(2 t`0lKaJQNOU#i5,O7=OTvIkqu5 -,. 4D~Ȱ~RO``+lߓ{6OX@0!@{M8ڵC&W[,AL߃m;6`=^)rܽWZ]U Bhq6vHsc$OuB/p@y%dOW/HwE8cHob%Ҝi%{Pvu\6=yKꝋ"ۑ T4!dT- "5=:68R '~FO /w:ԃfd9>vp_LqM9HS)Sbu/WtVtVvuJF$-k{RT\2f/ d2 Yՙk!W%SKz2AEs5'ʄP~(|D6fQ!S⸝y3%j$Wq`.ޤq \t 41h˪Bڜ&4킹 quѾyΡۍ'kYNRdphNi"TCPM|sF[iGi#]bju4ν3`ը šRJ>nglItrqa'P{w|8CsB,+8TWJ'{e:z|/Y9^')ȰUf,/ V&eغFC% Q/1nޫ^ Aƽۖ&WzM6mOJ&>$E8k!Q$ 5s ^_X'kHM84GpjgÁ $] v.StYo"lWb2RH4 ITtS]p0lG:QMme戴tQxgqD'zp2_q"s!5z^v K7ʑ\]&cP~Ysl*}œkn)2kc6QD'Cx?J !0:\WG6y h hTI",0PĊ3]7$‚ٽkABev[(^G=çloUS:uF Ugn5x{=S !43$[DVSNj'iӘLρ +piJ`ʂ(AEt1 d:^Vuna%A0 CY2էߵ3 bx%X0hx_ rfߵ-B?ݗ߯m9鮶 zux,lޜRpZ)gɼnZа_@=G3tbQʞ;3;н yI[y\5R]6ܩo D \ƽh;hYD>9pmFzP|"CfAOJ 6c}F+UU)`UB)N֟U5 n/  XO\Zx3v;R+ -MFs ɻhn)Zü r>hG D#5GMKZ|Gi)`$nߴZ+Y- 'Ns%hJMEOP93b F'G^NNj`9$`GK$+o?0[< K.d/ڈUrrrC@AQ.`a!VU~}FA2?.}˹N0ERV!B8#zr}rd{ρL^~a!wNmX8a>a %ȱ,)" ^ѓ_jcӮa7l3"ȩ>Zkz"SZs*R# ԺEgȨf5o-mbvE~?apNVAx+fB1n*Q]u `>a+M$$u3̬Tt 8y$M){7M\6EӮo7Qu61#1wՙ\q2h^D"6NՈ2!lxfh%Β5M@]oR| TE2ᎍm7Q 1N^_(W.iBoY6Лm.coM5\`7HfNRɓu~BI3Yv*0dXw$H W X#6J/U `4d6ZAYbUlȒ 1m rҙlƓtqzj*C #}`pyY9J'My LԌ[ Q㹇a7Sm[;M1Sn EVhkGj1L3L\rfJ|9sy?Y)*ĝ(jWޮ|jrW?b_m]9GGC0&nT"ovrCưl7VϢxk3RK8FڳU~IaELT&@e|_9|b) .3-ȿB| KXP>[Uҵ諜?ncb*oF.C drj×귂O"*A$Ͻ 9;_TCGb[Lp B61@3bbP#on1pӗR1d 5c+< =o0%6L<$Wl*,Zq?ߞCtO# ~14eKAcЖg }h;b_y2U% WY|ps㹫}j$(!$]ĻzsjQM8t:Lt9 Iqf2xbD-;bHyF̘^[`o&N1\3q=i], Gkױҳ~cYcH")5ԩ=NJ #;6#VY ďY}.~*B{KHƖ]cB:m5O.pز`;2o*HկmצlX2nlqê5NN 5HƎ[7We,&0rV9 -{8'@d9E(oƑPBJkug2NJ&")D?#ʼnuΚm]wu64`00[^yݬDkt`԰;g:e 6ĐX``̂_JlpS.gэr:- QP8.py~揺>3(=&t-ӾzJgaB"nPzh}l'o~k(p \0xv'(<ۻ з $֗k~^ B -34I#]L3 u) WTo_p?eGFuc S3\ F|&UlEOY, k'gk!m`RʮΑ`# 9,'G{DZ0U9&Tj )t[Ⱥ,dP3X0Z RfJo~̉!.z< ;"]`T+ "HNy|эZQh!!NϊR>=σ}ӫ wΘ"fUkSq+pk h4 M0/qVGYVc}>n^vVPG0"(7` >k_HvJ|HA</J.0(t]=dIl]s}[Sţ:K]621tu1A'+9%zw>xLX<$' ݽRq Q%˖"l;k^W-[#Xq̘,i^ Ny'>V>f25{~4-6F*|P7pkW_6^?MgBl G 2 'ŸrKS$A}tH9.#pċܶA\1iqie܋4i`PګVMx=noGK|c9Tg3dơ Yh&X Ⴌ-d0ψ"~zCQlc| E*WU 1-鋿]-oMu@sqɚ;x! Aص1y]q# (݂u*~nq5YOF@''y}ka}CQ4ѰM 3ڴj"9Wfzo%e*"Ѣ 氄:b\ OA/0\ʧ `Ѕ`B b BYT<(`|w_\7I;v"wo.OFx\ >eݠѱRe||:k1D-R;{ m]LUPA~w0$c*bN䑡%&9~Cـ*|7KEm6ȋM@;vĕ<38ޅ SJ 2~ :K nJ)4`MUF7MU<7{VCOef)(a,:MIl)>p)HIy"u (Gq?f AEi4~>4૞nË gB(:P@gyVVh?<ʆ?uA98XIkk<; o'"vju~.lhyMJr"<iB9*&JIDGA) S|`Zu֙OX 4vTRXi%P\2530tjWajgV"2-\v ~ĸv*)ow%Ihq>1_zm2ucduo% 6? LN#DGBaɀ3U cWi*k&Pr%,k`sKlfQ~;&àg5%mMQrgHxJ ͸c#lmgZ~kĄC A^^{IFqR (粑`'"p Fz覫F ;VEЎ`JC~PrM8%_.U(di[,z<,r;C40uk $TckZ ʔmN|& 3mMD[rߣʒ ߣW:8tPNy5]pN(!5Wi Fi GeJ2+TGtXf,F @.oR8BXQ?6RiIth ;Jlߊ5@/ۋfmp3d^GWmd(.+5WOxBuL>&NEoƫ? ;0 Z2E^ }c7Lbizxt"N|Iw^J/4OdUg2:aۋ8 eT)a;L^8-yo :y`&n\0zn'@vJ!fub~`8$ 7=aCM mW;DM8wu>HOPdam|<';Y(1i-4'²±7R]U=5P_QfP>ߕEUyl.^8=;bw'ždzӆef^vzQkCiSADܜm'W`>O޿;O^6<;6 (CiFĂ&kG.Z&z57<—Ϝ6)g& aELNT]Kz ݪ<K3T^y,q0;Ӆ «#L&9$0-7arc3`Rr `C|B-?2㸂 +޹zۢAЈ9ִ_w6ʕ;ąhV`)s6pO50B7!6I4~D` JXu:ߠSЅۯ9!Ft .7jroH=OrVLA34=KKo_`lx1"w|}*zTU+-MQqA)X0-ִQ b x-{=d{~lS?9p$I3AᛱEdCi{2gՎЮ)Pʼ.$~'_N7ɕI׸`C I^Va`?c⥕:HQ%X0a!<*IQ֚߯_!@v ]f<>s.ڊHX̣I27_%"O!;"^1 x'dH8u]c' (2w8)NUo`M^͆yG"v52dY9 R)1ny(1^Yƅ}'BDҫhdY M(jFf sEDU)--aIbfmh]6vTžOt7paݼdݴM&)r5}:B'CH+)!gNI Zz!cjߗm)4ӴB|-6U7ǥѭ1'qQIhv>Q;L\ô N2($vC+BoC+^:ɀVNyUo ̷ 6}3EP䚴iI90 `w>? k BWR6LÐ$ihQY'X@[o-ߎvBYV͆mcu%oVguS; RR0#pwH? <Ōhcz*($/⚳HKI-<#1RFj\p/0ɧ=AP<ފgHn aC*˲MTw}o*[CFaE7 ~WMb`U2t߯0#9qJPU?u6Ϸx.& {NƩ?,QXIZ U߾~t{R Ү;Ea% .N. =K!h j'\l:;;Ԇ${&t[ϐ@9"i'F7,{0]"*o%?K/M爫r· ˏ4+ b) ſ w>„LVV(CD"S4F=@W9{,ym!zU<j5s͒inLPQD/+D!9N[ko2`eH? zB  rU/{]fzg- ƜjE˜3bU'V]K  ѻKՂE%rU QXWu?) /o<w<Œ,';MQ`p L{COKǶ꧟ ]E]jEPQ;㞌8&@"zv+Gc.-"w "J‚]', n,)9qe!CϘhxEڴ_Y-R&"\a$y!`B r D=f~)«HrggOtvQCl}XT'y1-,J=48.]&BF{}h1J1y+ {, ڏXX^z]B{1RrN& .3mT2X gH1!%qMsoXTˡAP/oe{V67hN:0ҊŅI 5GJB~Z(g|Afa㺫v>7\E%,YCM䄣}/1+7r06ӪaQDS&NɌG2z;S)Ӣ]f`0#ǁ&61Gӟ^@U)ʇhξɉW(ɬ^>#=9LRY;,t# ,_7+9 R!%ޏdܞr Y}n,Woq(/pwbI ~͢]aY',ϮZwr^ϳN^؄'Xw/pܠdg VSU{V<:>T}YHTS:WRW=i4[MԊf@)}_ OgIJL<mj,/("XAJC߶ ˪+j{. -Gu>odzN۲G$h);qopvGj] ߪۦ4Ij qN!;S^$=6F dWCî{SR4Ve͂˨M}h"7M%K5{(8ҽod4  ͐B\tש$~aR&.Xq4TAU_5H4ғI F'h>I3CrGba8y-v%HxWՐXCa:zB( pTM&#'=ztw_Tk=JE nb'P|}»P<Nۨ;Uted-6J^tX;< |43 Xx#_Q2dgO }17CuSg1 C6gpСn'%nX]B*֥kJjt9!ZEׂΊ"_phb4(DECV Km$\S'FxAmX;i!ۓ]8fLt=3ay$gؘ-9h.VL&SFG HC;ݚKۘT=$6?p4 ӗtޏG2O}ǫ"˓5^ ^hH{!! ԍ*/ 63WiCSPH¯[8POV;,;/"|]IRZS&+,>K0V6=Ҝ qGBbH'м͡[E}l΋i;^;4ں\zΤO[T@drU}?K+-@ c@3%ܹb+v? Z3"=tpF}r"ez<+GJ&}SxBſ~:yemp4] !svY(߲]]VBO-242:^?n\û(zX + 7<߱WvJ]NrqIۯΧ>^1c3.gkL]%>GpLFoµX@Z[BDN j4YZclO{0W 7Dγʊ@ OK;7\XǙ˞Ef1UB^[FN/%]:qն75T.j')E/߄ǿ2S5p;^tO=m>.qyx 5A)cvώ˯MWQsm0h7v;ןuzD ab`v|䩹XvйC@7HǪqdY&Hn2>G|#U@ܫļ Bn8P#u;Q̲i[] ĒuV0Ihv Okn D^Z_ދo؄N5hjc:Tw=R8 )۪'w* UĢTu9B[jL5=ԸL qo˥cQ'1ebd֖*&7KsgJV h|l֊jE~eQ1m;( zؖ]rkP0'N,8Oy kBy_dDYt҇ߌ$dܵ,3mx 4ٲĽTA,Eg&uKFݘB5eOֶUەk&&RDYAEZ 7S{vo.~=n /X}6W_s70nlhpJ \3Vّ6e+^M| Z#`]2øū4} '-䯚O6pOvK`}ϼ-*+LQUԴl@2SN''iH." Ii=cG<P/jDzI8o \J,-668ZKQ},nu-1wͨʵ )$YT6!i@(U C:KCdbZ.8qW/M S9en 8Ze Nq|o3J0k _m{^}M{ t  t[vͲWb/]o>6kTq n`wmE:`> Q 5sR@`𐅕~P<I.F(d2I.(jUZr4j$3+Q}[>ശwֱ\PԀa%\FJ&űL`[Hja8kARq2|ӯgaUQfK(􅦂@LCl"zm5UnAOMi5R&憙ROuvKOXN1=\eNSBQpiCp%X7q! Jm<)'}<T k{h1^ܚvV-0^tVjP_&ELLϘ2=ˢ WJ#L}q'A_h/VftV|_wcGnc62SQKMãjs?O.݃ZȄ&OYfxhK?Br.0gf Ō2@G՚)!bh^榐D<KUGӋ.ќM1 -͘sk0mC]! x}M[פx' lm.<J8NPF 79'xCOZdOpQxa|lऑhTV7f+K-35>-}{G[ׇseAEH~`<_}X7J3[}A; ~D8d;3vU3Y>ϦoWK3&|QK戬VQ)#3j9L0}{ڳD̕ghqM׳8 Dq#$[dHeSHDF.yҶ6*\zY?!/b6[YdjK?/Y Pr܅kQdB C0yMؓuԿ3>>`Xhgկv)~Cdcb 뫹+YxNfٗw䄿*DʕEJΎQ ⛲d%ps@g/$*/R{gO4Z!h 1~5P:}hQ&#զ"<W[ 5)oS4;lK6ȋ̠9 2Oo=4?87EtnAi.9Bhw@EU d=ЊÕҩ-sd0%p(xW:x!, 朼yZY $x`0 AqOj{-;v)zz~?lCo|5D-!t,,O,-@^M(I&rRȝpuxH !%ίG;:J>觙zW;_S Z0ma+aEA>ޡX Ba=O u3 RͻY"f*I ceb2RgYpo,~ &@\ 7gB)6jP8dg@}5κpJIڵ33Ŏ\S ǍkrLqZ-*= vQb\cu $)M T7Yo̲&:r- `k #N^D~]]W_5қ+*CϏΝ-0~N-kzlJsJtͺI(a]Hsl;+n@vv|#ACNbˆR^ɷGbyhgu4gGg+ᩣ<_X͐]lD^c\8$i:b\pdF&"c?Kqtt'Џ6; ͣ36TABv|{ʑ$#?3 q I]q^_[:-\˜TڶWv2@'ۯ!kۚa0[RpAby^z¡Q%R SۉLsv1seW/A_3bq|%Β-YЋom5II_Y 3>4"U$i9)>,\'dGQ Yڃmpt;_ 8%/휲I͐ >|N2 +p gV[//!p..}I/\tɺ@o6)g3V\ن9Q~TnAyA]X=:AVHxwRGܕS"J`_ٴ%ݬHeG oe S`$ǒYBtN*y#V (~ZsawS8Sf6.Q)42=%  06E r1ygH9"YrV# Bfv)36hHaǣS c!_Q;[VaDx~y,z#Đz U)Ųs4U6rY1rKHmj^ʟu5/\C*6=*mƥ2W3d }ľ 58X2֢ׄqݟWlo^,A5 - ^0`P*lW"Mń7q,y_:2 Ww ( ;Pû +_9]?(g7L@KL9a>Ũe{0.\ n&IHo]_Xek? ٘j=OޫA@n?ĭ:*!O1Ljikq1 zu>\0,6-FUU$ *,(7Z9G#x+۰ P XjXxYtX&Z] )=saz-w[j))׶J7;X=qGΪ1t?l JȄyZwhyݜ*Dɫ4LPS,F7(X 8 t%Yr1%SEK07={}1tսu*~pxNͷ1(j5?,:+5NG]w (-5uf$$9%$Y8,Ӭ $q?>ֱW偮RiK?Z&dxe+Nvc r~A@cI12C{j$"85xܷ N˪۾o}mBMI%BV?bcIzGB穷~&҅{=>4'A>KNp۴=rnq!:%Y&BR;vV>d ]tM'{ =U: ҌHkXTnѥz0 %7BD\ sy盧 W sӬ>$#8]ri;|D N!.iBڶ))u1D~}4Ԃ0rW}I.ƲČef,\Sh4";|6$Zq^71FҵgD.< ¹g4E1Uh -9$TOc9P#_a}ύz5FQAƷ 5UG.}x0^/0x C#a*pqnNW:D9!|o' 8<`›ևǍl8@̲=l g~;'~ȼi5h6b`|(fA# `l52t'⣱$UU)&EI)S#X]YC4ɱ~#'!G!:Ǫu2'9|DP1n3PZZbTő?-#*.E" ,XSӧ!'D|$(e4IU9(6,uȹ=LF*} ^TE۠NJYżT+W}u[+kF낎AҔJ|lk%QN7q]_xצ!E"8*aB94kl[7sTf^,zkYbEnDF~;MK clJdu˒1+y8ȲBxdKu8`ꔧlW-R(—\Xk(~.f?mTY[j1$ τ6rĪK~ K6Xᛆt"-ȮI˾yE^yէ I2k /Yc;_>0=YIxKytՔdy6b2FG`qTP6W\9JfD8ʏӊ%'/q~}1Pt|X>bs$ 2E`N4ly~]yR{$y7txhJ 7gxd],1Ƒvw8%r*c*Bt_9WKYyDZhC#풙}RQQH^&3LLW,USU W%ܬ!W±Q8F@!I_bX:})w+Z$t#C}},[Fq7i;RpE;ތ㇭[RqM#wܬ6PmeZfwOE[ 8|@eT&KsNt[m,˒)aЪXt̜E4穄eYc%YU%ˠBb%3X}[b!LMf-4N_pފ0Xk b:|Wߛ@c_$dY@Q匍1{#Oi$s|_y%SIԙ!H)hD@[I]?̢VdžC>* y(Pꖞ TgFm-C˶֓E*@ Пjyl-<m)KI7CBHed)%gQ>eZjDWDoK|U^p?@}hpRw[G%tK-e./+1%F,2\5:yƘ\7uBA"WvGNVmX(c/4Z-|A drb#MWQJ?0y͇Řޘ')À XX9Fj&P+E VH1 %K51iMޮkFNP^>NlFMnl E+ bb'w/ԡ3*sz'9-J]{TP i߳8έ PQL؂BG:& ~n6AI|*-<`E8V!ِ? f製Icz -Պr-X"S_k"1m˹pond9sp;R{Go\[^d7A$(9j5 Zų8>'D-5G@eeTqVUt_֒E2n&*ʹ5:Y/|& <2"?`l$SbgO$o!Yʭ*:-X?n2Cu' T%at5Cvc$؈3l(AQsT`Y3(Ռ/*;r1| (U q~`4xgepAFV'[i_Vғ4ؤA][$`8 WPw}JP#ظ]~-K_[ǐ݆pRyu*D8V%S(l /OL%:_:C.. SZ(DP[a7lwDӚHog6: 'T˫LN%mi/rdƫ\E)8r]Bf OƐ&G]2F竭p&T u6,YeD]x%{%0(b%Etf(K36-8OͤNcE_^ Ҙk5YvNfMX!3zkf96ESR5b X>[:&ri fV} ? ksg}+~[d ¦!![KB^~~ l S׻_,N$KFT{:CrPW*hl2 &*Cx&F&3oU+B' F 3,,áU ̡LJ!U;@G{AEZ+LEUUtdYr%|[q1m"0*8h;01[pV 5#SJ*|;妠\m-L$ƜP۬uY Mbv3ey!#J P|sD'!}lB ިJlI\Peq7~KIeq鯎59hs"!TbVAeVHˁ=?!{s-) a]G_dXkLM,Rk V+י2j)U T pR&@L&\Q3^=}@JlFtkkc<1KT ٗF}wo$6Y {A>@_&Ҵ/* <(y&[ !J|2rX/Ȧ]@/ ;l= n.)@M(Ϲ"\CP$<: ZSORkaHD\4D\AR>wJ9x`42? ;*%ϳkpz4΢qŻُ˅+"^DӓXOrvj;qpZI=:w6 >Yvd($!T62k2}JZ."ۋKM!{߹_aLurv;׷2dIrd c=`rĮ9(-3L5/ AB6Pa~o$"0"$Ygjj3@Mh@CCcu$8v'jVlN'kk8aT*Lgrˀ O<,y08%B+;ɮb#NJPzɦ."w:BUDwJ,lAU.hY7l ٮtȱgoV|PQy9aW-nK)duF4Mͳ x·G2#9E"u_͸Nd3y20n{+{v/ =2OM?;YCirn"R7e< 9z`=9l(ZCR8q3d]O`\QN^|`yOv*2U3#L-m5mS}k op9IA\`QъKro^h55R-t8i`*K_썁 zyN_s)p~ղ|J-rFyr,_y-}^Ñ+)I@M4e±IlD3UVd#ۖq 3v`C9|ʼnHr8acg طVK 'ŗg// 5~Լqj+:N H0>L*tJ6\L42k0K98Q`#+_n8"]`)_E2IrJ30ڒ1B[zMR寊,+jgzk^8OK+ZYl;;Pt_dv8]mZ8F@$'PHMEzaNs|jD̾53Q1ڵ6@ʓQ?l'ZM̭`s4`̩Ryixs˷Hzؒ!yK-|S;'iLS\+̷Dqou ot/s2}>Ӭ0 S;;ǓrJy*9#=d-E~+ӛAO)1eɮwalضYH9[`;Ȳ#FJ(G;?nMj+Iaf,bٰAeؼq#f x ;/sH×`Ē|Dn};ޯ֚LY"(a}ãg"/G+tiFЕ.թ&4/)bumdVEĻ]O`bujBF'J+5X8hFP7̆o],4^胛ǧw@GqkXX{H'1@JQlUX-[]qΟ%ÄG U9ɪ2Nvz(=>p$"'lyJlP5M{pWgdPz$NvSːa9[>"z律8ޕd4oCfҸ6{5_RxT3#v ; t󿧌Lc_}DB3@^>^dpx~7 GJmT$6he[ڝ+*K%F!N K Y ,nВO|NM49'il57}f+b#5eVL6":JW3nZY(bغIO倒W$3|a*Kk~7y$N$0a7Y#"I8s~B.tgot-ڢT.v(EfPKtňBSGPI31x_TӚJY蠫SKO+2:CÊh^!`uxҰ>~۠2?{4Q/U|qg%G:lс\˲pqR_SSjDb T3ف^{u=ICHεQ=Cx NJ(щ/σ@Zo9n{O4pw0eTבB5E@jծf:M2zoK}q884TPVnT/:֝O z͐-Uo=)|fK91=B1z#z2,J'_{ 9C85}jXi6o:C{C^kQ-l&L%j>5#ygzĽ8l#l٨4Pc\p izN\-Xbu+ޡo D ʘ|S.gGCJ\+ AT,zB!2IxfOcSv໢`V7?N*KQŠe8q5끲/WFE*eEXۜye%L}ihWABCsUIK;]0&z柾xHXVІ؞h\I!˔Vżyq3MSd6j(rWL/[_5vq Q&'gGErjT tXcWK) 93Xr͇B4ȇ y+Q1hw^W\[2Fr%-ڪ^Y:O=M0QD2rE!n y*[p1<@Jt+@*mGvGfvZurYYW,RwbipGs,mLRVPٺ<#и'0KuGSa}dO4DzR&BWPub!Siq7ݭVWF@A2~\d#Mct~T?{#~/h]~_3,ۭ; T\}~"R%xhðb/Z&x>lnZ޶,|h,Tn-{l+a%@=x <9{kįZ]á^Nڥ!e"跪ث @/΃~g]D#;y=tbrpʠ Hݟ&\Erɐ_H~yB B\';RKh |HzssrME̹luY QZ"!tS>NwZ2s>qX' =NJa(Uk!n%J 5$5RxȬ"'Ziۊt|l,u"8 L5wdw|{ꭎx[Ok8mf¡_wW'HiFPm׾='SAN#>COr2GκVp10yȬ=a`Jc2x1<޶zShqDﵞSA6 * WA/YRt?o.\Ѵv9'5YFGAh\sj.*f`1/I2%V\B]^#<$e@>̘EIryF2SR8U4$,Po&p6MUY_p SNrpw!m_?_GtǏr* }Ю OQaŒ#V8^nl^ɔ6j!spY\@(BB`#7z{x{r'Wެet5 [qu= D@/Nrr$f7קA >Yv gSspɧb##ՆlxNURSBK͠a]]JpJ 'f3KNA̷*4[qQNjg7Y .v8~#񀱭R^MEvQwg_`L.U"ŧG:-4v!龠9,8-"H1TM#EFia q(KÅh]D}Abb*Lv ?z{z?\'S25Wmj%!nr6,7 h;%2d:W*{3V$ҿS2aI:]IZA5v"ܼԁ)n;῟ XD;,|ۗW)RB5FnL1[@._gQNc.@][Gj_;)4 |ܑ#ܗo/OH{b˅{\JޑZ$<ͺj!&cS,_a]cBmzX( Gȕt+i79r{9i$x1QhY3kN tY8>=, JzLض]biGiQI ;x.^^ ]3&!d|/|Ŋey*αURE rOGuNGXZӭ$Yk"\tRBFkfC66fbtO&۷ǕT.uHvt( AtJiJ]dz1g@{XQg).e0@`Q$%"R__7B5NKe?(Eb3߾In?.l%Y\H_E^aӧFGMtvvCC*!⁍8,9:_COEvh3e8,yΚ.8܊:&~߰-YRQg#{~N']Em8PFrwD*0 jj}}8˸\( k㶥LZ6Bs3&\O|fv*K@m3͡ H#noxgs%ǔ+pr4`LjE$I86ӅM_W[,2K"Y}bJͧǝJ%(J뢄,(_3:p:5_D*,ݜi' mq+ЖK\VaEJ236yIzX5(j] pUͫ7y?;I^!󗵐Ds:8$\9`EJTZya Sp ?2NRC`mC7iO-8$@ZI^aꪇ̋ %?պ9M]i}$Lk&@&˧}~f%kQƩْwJŸ_VE>f徴ŀO~x#\AZe(|)0mLf cW+lf&y EX,ߨɬ> D4ySCZs *Έ>ō='feҟg:5{p_#"BrF2c|O} E*m[ [젘&v4C_Uqa*[Ȧ'u Ձ), 4~gcp\Cݍ -zca#`κ_r'Ky7j;b3" j]aKڐ,#q_ScF7oK͂cuQ߳X]/2#y])Wi Ar{udשza]W^^&ѥNy"Q9o.BLzb2,vL-9諟gIMT9p`pi l} `U;grEN>6l T,ospcDzP=ʖqWUD.uYF.6XlTOʭ) ?^-tjUƠnoPlmG鱆b &TAւDکh_ U>yx\qyg:YжB_ _Il6_ %X2VYAQ`ABP\D'uL`0 Ƌm_HS{tu5Oi0r;;> {T7Skcr>x.tzZ^lS)2A(g>Uw6n[v՜pAY՜XDܝ)_ƞWep'ђn?<:٨oBWh*+dMZ@90=ai`/gw@=etiRbLf1u`G چR@tqT-ÿgp )KA$ngMjU"}>}1h!w`D0,h19iG];'I+\<ѕ0sQްI\/'3# ]y5ӆ@@GJ?0ѕ2c3xޝf5 ;` Ƿ)-ǯӹqaD@&T*UwRFB$Ied3!mx%ojɊT~ 1Z=SG;m0y$磠^8mc> Za RגDom> T"S#+sF4fTہ\nDS툊$!(EVش$o@o}Ђ& F J>Bq#~ڒ@aOau| MTF@3~iU߯&<4>R -e (ev @X>cAGH6in Ĥ'sp'x>_-#{* o']ΆeU6a1?y`J7s^qؐG%'8B!χwbhc~ . PpwoQ`zV/䦥rèU*qG6Kx%>86L%0|,hݱdʨNow:Ck\ƌmɀ(t{5, eZ09lN `E!pTM409G>GqfZ<` A<[r9D83(e1EѲ\G`jLoAwPٻ\ 矺E4w}%&{=|,ɣAO:pӨ^JÍkn_ ^ub_]W\AoO'dc_GڲN|8h$! `j/~oPh}K% F pBJvkpt0ޏĜ%r˻);tXX"vg}HrV# {p`b?~}栝K`eڰ?SRzAL9xl1uϛQG83aϊXxGqC'oލq_~ŽK:zg#=4KUXOl4cb]`s,pmt,@#4)(DxuD2W4 ȐrtqK؋wq2yx@6ڦ=&¶G%Y~ili E0MUi)R VBGϭw{qt;@1A]W*n4NݳZΟM!;tx2WY_g&J8"Z]2}RDLZs<m8,qVhꉏьօ8d3E[ ]lb߀kMb़2[>*LwПJY78HϨqoQ ߯RncR" J\uBSY%/X٤:<^>𶾭 uJ, V6t!R"64f5}˜%4Rq9Oَ`,%d?x݀w7i)~3pmL+~$ͣW ȍ0cOj:Q_͙w!M!*+g+*Qdv cMe0Wȷ? }zhna(v)+x^.|`O=ƹ%pC5@؆/iѻ:sg7v/̒R}@P'7yS5Q*:s dtagkP"/>cݦKTӹ;*$neɘGQ#@qۡ~TTin(HeLr 4A,q{~}Ez ѓ3:>P/2 So ֱ8e@}:#,xnhcF4\r$ pc-f 'Lt&!+vګ?;|dkBʆ%{G*OSyyODv/ XY`rn[6\ {1M2*[O\LfC7K~#{eY@iX =&d?P,i6bXW5r,X(C1_TMQ I;ΖE`!F{q?nNӾuy L͒&v&rE055~kMҸspƆ wk:[ u)5:"-LXBZyaLr`7W=B  4=?w$e+H:ӮڬC(P=C*D)Y-G8RHhL?'goD"૕EޤՉuG23 T&?zb%AscL#Ӫ~+ywi%,lYhWWc-1awU 7#/'Tٽ(8\O3* !cϯ!N9 Hq.n*"eXFDRe>r‘œ*7h\vwtS-*BUUi$<*y$+ΣQ i`ƨn3NFv\SC6b 녚H5ϏC]ttlMF^/4CHڻGj+݊L\jЄQo*D) ^õ}Kbמa, I$ðTb#Sigj<;>m˨Li. .|٠78֜KHH*? {<\w_#I-5߫Cx&jrZQUy]FG98؞+ ~F&t\08-$D\&vvP]}ٷ؁tr Zͤ,m&2ܣ"ԪE6HɋZQU{èi(x3c* ʭJ!0H( ݡMux+cN^5] jq%rfwx:D@) +@>m9#޺n <ݲ4@ٞ(Q01

NQ&j֕eZmX$)^6,o+;xbwT-UY@93e|n䙌;"vD3`Dc[/* 3M$4Ld$$ԝ?Ta# N{"*և𐿝UJZXYF諀Ea{(f2/8XS3hKpY牀Bҗb̖8z!hnK ={!{C)C_BKb+a_R$S2T2r2 Mg3aMMV5|km%`cox)_i wZV.I']޽fOeM`J p—&CCޭ2.v#\ p=}q;ѬO4^ʻ ?b&[>6NڇүeZDI~HLռ?_Я",i^C Qڃ+Nic3Pm` @fQaKi\G%PQp>]<į+L)ۧNM40"j7{3P AsؽlY4 ht+ x]F+]ޜ1Į-s[{ #M Bު 8N5$j~ɚox3h1)=!)>C/A:JlIKCjagWW zL|FZ@A)2! Ye$e qh~jEI)/NdٍP)PɂP:}=>Yq#`@HߏG?ER/\[2^s+4=7s),>q(EV-O,$2hn5_[ )K6+; wa9_~_>OfO*vShfhy~Nu3mptn> բUO;׸:WhFC\%:i'l03#coC-|fǂSx I3\UnڶFHݗ%)!٤'Ex Odц'I8n]DsC FYA[JN7 ept":"ŹI_g*A{VwHշig܌ZZp^Iaײ+PYA^b2=C|l'e Hɫ~?+DžG3ݛ)(Y5+M)eņSGq+Q{l~ D^ pKQ7ۇ@YCԏ-P e,p1T5>pmUSֳ+ S7b}:ƑJZaSb K2-񅥪/]qRo:'\WkKA|l,Eā7;]Fv3iw熣^fR3Hɀ{uN4&B[=7̶X_j9#.K%CR%/-É/}UEoKl2Pȭ.i4쀖)u>u&rΫk/X *CB M C!)g>0ޘ/J{ͪUo8|*O}֋HÆ CF(-ﮪGg$5_ 2.aBdm|vƆ} BE4R"S-<ɀdכ FVǂG)6A1CYGxK°i0p5V;SS6ȸݑeÊӲF2QZg?X-s+R[0!X9+/?t گ XgЇ|w'|W]k΁J,'GXtWrdb O&:jr0|:S`鋡o=jà )jW_fmԑc@9mۆ+a<}@}B8s2s~7ʚٗK:H iⳫߚmrP!Y]P40 4Ⱥ$>?PLԞen9 ÉCP-_Ό}T0v}58[U@|9_TLT J ܚ'S$nfy{ұPȸ22V@J6Pah_G,l%.>WCVIIBD9kqg)`-xUIp`e=_8Si2OUz)@dWlsr!VQVp2T}// :<hjxafip! Х+b 0#W ycX[Qc}b!0y$ҫjG08tx:nkc`3wo<`?o܉^myҾ3{zHU'_*pSr!,ҼVKN>c4a-ZՄMIMo:j|F, h{!mY# Rht^8?xl}%Ȇ}|F[MapvqzT$?E⼯NOP  EM$/t I`* ,Q|j;ycFSB:zR'M:[vog@1!O WvƐX㈔~  egXջ DIXndx1*؝/=0HIzŔIFվдs<֏54pS3@=X:U]G0'>>V 䀋좾 19a1We7==ۚaDwϤ K)eS5 b#KMV2b5۶9Glڌ7ڦXPJ!7UsBH'; Aםȸh]D?f7Mq6(4!%bpmSa:itzH,)nB.qj/nghV S!8LG>|!}=aD.d.g< FQC8S_}U^SrM*۷ގ>Ni(52l:FT>R`iS-x ̘/VFob2ˌ/}k C XKE+&۔,AT i"Y`1gߌ.[T;t;\c_e}@4cx>U!$B/=*?+ eeCF o]$7K*"$E(pIҍa u05&1Y̬NWH D[FJªG՝yFoyNogַgeAeZЭ %]7hAhA/G YOv\8հIچ0_\&ȅpf=3@eF9ljzQ17l"NAAWB [jDY<J-g$=QY~b_A-6w;QB5B2H"ei8*8RRǘO_<qPNK]͞(qhjb"ĜQFݬb*GS 5qw#S spG^BݵR||=#M?]by/aڍ7~^\Uy:.ܲX}XކI֗(LiT~ilÔzH)| R9QdF۞1+(zCoPW;OPC`0GIF. cw>🙇8E~|ʡe LyI j,(8#!?UzQ8x "h?Ub85$"״h2ŠZF]6<D̪6޳Eڊ˴ؒ>r9D5t w#RR܇uao[/9]jtq`ܭK+稟)\?Qثܒls@ˉBm՛\C2\R0x,1av?K(3+?LpҪNǮ٘{ C?a@^svR^7Mne=p|uX;"Ƀ,}zAA826upL *Um0y6v iFڂ ( h&x# +EqOXF l${c` D|TQex[)C><m3a1h N3!?&twdڄ;)ᜑ82*QMIO}z0cI۶jkܠnX3TDEFtFúX[uT\Lwz+VJ1> x(nܹ(@oXR_~NOMy7kfbKM.Jignn֎V\G8Hp}c;aˋӃs|Xj(9',w1 \,6Zqvy=r,w61jVi]>aHӍxފYazw'Ӷ3 -Dm 5=j3;Y1{߱m=Ln7n TۜT ' -' tAȡI2W9^o-(.:2BɂۭR4IE3> BGAl3瀵z`;<)Ko/UZY&J-n)[gvK.Ж$lcA24!o<T;צ>E=>}'];[,X=Ahh$-{&+Xs!u,´|dvJrtBӪ3nu̵~FVbڂg1 `7>fS\-fYViᙍamW`C3}fH]aq9fq><.纮 PPF#2:x3nڏ!At4 p 06n<[.|M2JHn2dPr&M: kO=a 6'-l ` D4-~g ߋ b`9!̍ B,SU'̉}mz)XȠYw[r*ֻJ~#(ZL[[!K26s^'kx%*6Qm=̼AAcٺ,̟OʼPi y%mʹ`T d\xqj #mzJkzq$1>Q+0f+^,Ody?V%ezGəg߉vWղLz{dEԼVN[c+py|1q]t7d9Eq]$aS^ϸpc‘֘ev\Oϐ[Ku;MCy( ~#ٻɪӛlb>t+{8cÕp_S-=dO0En}qwXkG̵aN9pmP#se1T;TPX9rE ds?x~tĺ WǒyLG -<t8r 6I%ٻX|^T*BMv5rܼ3]U=ʱEeb^Pw4}He.d/Dwv c,S)Qp-7v2 q-~X/j-bUDFyӛETcbeNqOe`mxOj.. msnIm>b!|J( Ful "iB /e@ݎhΦ)Q}V͛zmjCg< jCx19wM-麴{X{+V+xE#$+ߕxGFF_<3z>µZ߅| &)l^rJ¶E%ڝzĶx$ ڽ.dž ~j65R9: `sEvCmBF3ً+mG]e3jwvig(U"dmOrK'Z-Ox>ַշ84ɰ(lsh1~4Srh 7ZkjK-KpW=wLCݬfKCCJ(H 5P8qA.nr{x~3٪g;qEKC:3֠ixG65:_CU/|+O!J ǭۍ3j_J\r7V53L55u^fs7EΞm3i]%i wZ;Iӵz#}ʧ ܅Y!.#( 8ծ+dUPQb$y{~ad$m?ؕaBx8.P|z/|@\UZL~ 1Er:jeY7m)MMUsۯQѺzX)Q{~zQ;7 5)9 7F\ |;l}hc^I nWf:Im5_f#t7u\XJa|8n28ogJ8Bm a7lV׏AS:]8gNgkk0.'@&aT)ܙhX/.$3VB́3jxw11N1V45߄b):FLHd"xI2OzϴJKG^\Z'-1dԫDD&zθ $mh3|͞> If8S5^1ܚ!No ׭ ^.\ѝum95imY7c&#[YVo6P;as%Q*R.ȁc^s-l0[:\bM/|Gy a8VW"q5ndROFΫ{ EuA-߂0&:/CcM7?`JNDrms wSU'5Q_G$w:r=V XgU' IgOqxiI"rbzhP\OfG<7n/uU9G#:QHRw(s2ZTyB4=rtQ*KjtMPOwY1$HufnT#Dȱ ԅFXu꺉Z|vnFLX9 bٞmԑ>9MWq*^[hkcs&`u >iJkD ?D/GbO*8П?:yt!8< 1~@x*e`QEPQ+fsF"APmT%`׺Q,)ԱƸM[:uXAZjNNcfϏŒ%E#gd*/or$Zc!!E$e\b)s2Rvy87\5qhpPaX1Fq'&Phu>N1lP'4Өm9mn ־1`f`/Q>1 @@ 6~DqZVh-[|׃t.t{<H\-$ Εg);IdDc- $XN: MC?'Ԉ %QCZ=H'88 ;W@ 'Qu]`C9ڳpxMPs#B47/_go}I{O1;*H&pkŪ˲),He9swRV OBB>!D.Jp"/iӟ+垁?bXf&P)l xEll,+%xrRg2:_Mrf#7zXwe88R~\2&|!v4# D6K bQͪx e jl/3TT{шc}|f@ =4b]Df1=)Xm#ێ[4Rc$x*ec\y"'.q'J,4WΘ >{(;.U2X`\=.NB\S"!DqGx!31ڔTTˎӄ']97DI̴B\bv M1[c4\k_7[W nٱo` Xڗwta?oNGr:å G,OKo'݀eǤed$|jg棩ċ@.un+j@ W&x#vD0E7Ġ w% WOS!\3MU~8Kf彈t C!oSZG2G:Hֽb(ƶRNKFI>W2&Aj MTCAcoG!?7)U<)+5>pVl ӖY-xmA-Hl2Pm}b𦮇< yԷ$q:E9Mݏȃp0Ω;yd:#[՞/ʐm] [ +X{YĪqq{(D)S`^ܢrꋱ+zRn& 0MMFsH5=Eh"HRIp'pqKQ} !e ,)AJ7omRL>#X|=)¬$#h6b%XUGkIƭ /{7Oq5!?Ju!zx%I@I{׎b7=7w$X\n&&!Z˔r}ݤxbd͘%N1Dh;)/qh +DDI"~)s1 8'TR77$:' D3 "1UT攉::#[Gp/\7kPz&% x0cXr%T;9iWȖׯS}gO+>< }; ,NʂF?/8J5j#IX-i5u(c3B3`hS`(j ~i#Y& uE4l=́@<(/L44=w$Pox|U23"ud-pc .4u rG%q͘ch+/0A3_gE(.%rRL$p#\H^ƴ7BWOt+pF{K|Tw: QQVHnRIqH^ 2V<߃fW4B'>gOh4Ljl !8%=*BrOX$N7X1!khM4jtK]fT:eQ$ a8zRRsdPAvX-檉lp^Hj%pz&cBU/d' ¸eNu,u&¨dUg-oIѻ:g9ڂsho_*zKfkV`  tۜR,ʾ6{Fdk?vkf9h2~(b#glk1k r%>|'Klj##2ѩβW<ua-ikH';ϕuheϪNtRrB޺\6SRh,HoF_Y"?qá';@$nu_:x(ͩӣeU9ph .c %}EeD;qAgZŸni# &hA(Wm%yIoe^neN0Q`9؆ _6<]xrddf /nnrSz3NC5Ln+u3c9X4ɉ88cӅ9 +󶥫h\5DUWs,SV ֌TT)$.SHƜ6Jkc9^U<kx+$;I1pZo-z XV#+3Ćro[S]fiReܙ LQ7x99#K6ҧګנ)3u ]?[VիOlZL;x]Ih92 ?w~BƿtF[JTR.̂BaN4a2W-Asu-Očwf~GMGf>awwC飫V|oq(u_~V郤'[S=nN=HAsHYBc+r7&m{6.bgή^#}%\D[N©oP"fR~ Ը2SyLKI;T1ixg{`d6˭ퟡa&U:lrOiGG! [$#i>_ a0jhd;z< NnzIC+G,qAOVF^t\DWd!LXT,AeC@<6Z͊/ki+.KlAmf':^e\ZL%W}O(8:JSedƩ{!S ھZ &/ 4uK8"Nt -ūű|5:Knr(Om'Eʩ d?>6)_`w,[np2'+/]0!2z.QF/{OHgp M'R2!2c>@"7Skp"Oh+!(0D1JKMg&eS#Y{׮/gz6^ZB=xnCk!p{毁n! y?گ!؂75 wEʁir:L=rbfso8Kv"O|%WCB|nb[ ‚DXP¨lTM+ +| 5|3tűݔ[Nųd{ӂZŦY<ڄQ~l>n=x&܉ X_fʓy߶s #UpC=MnzGQ춪K> 4T^C 唊SH?蹽j1n=d+Sθ Ym]| O8ާI*ZK,';pRGMXkm,XzCސDJ+zqi3Ics嶀;NZ#"MǶvk}4wp 7Cq`:+cym7SKhUuPkQ=4N'yYJIIroէ&ύ'УKVKmD?)$10ibW,NLBV[ )sގ4QH5nX8m\3a)(T!#<7#$MN;'k(Zi(9d@@ٞQE1Q=}ݴ\8avIF!6*Toꛗ%$DI@f?UKrj Eo7( bl9ӡ{zM}KVähC7r*D3+(AePiKkҫ r E<}=r]{6 V<ϗ>Kl:#%1 Ruw׃ϹKmd͜м9΁$=esqI&"KO3 Yw9 `69TC2H]7`Cx =1W(z< +vT2N*#=^:+=ceGĮJ:: 3+wf֋5+%$b6@>NJx ܰA'/#?S<@E;STc5R"ҋeݑb4o {~ MwEFCu{q[3']a;iFTtn!?a\7,Ŗ}]um YnKge*7`~jfv#&K@Ujx#[5yr/ݹ~~ϟ>KӃy~O?>}rEBjYc+cWQ8 x8B{]j(C b Q{bW$9kv5:  ^^f#ϣم~kJJCm@2?c? Gݐpyǻ'4kYQ.cX;#;Nl s?1DI`b9b9+-FPa KiM(8P0:wsP;A[U#u^!e H\dF▒t$iIdBMEzX#&Iݹ ;p|/ԡU0 7 O^:1ّtMBϞw)墽,t7L+9F6m 'SziLq!BǚVqj,'KꚠזS8YkrdpV7/PJW{,*A<YLKJ>x7ϝ:w3W?t?&ƟhCnE ٖgKez[W\\x@N LCN-j۔Zwl%9IA;fK#.o =f\$UZzKϾW),5TqTMR1b_̅D݆uHRZeҐ Bx"xC4r4ظ BDN]%"s[ Z HH.3hJ*F/r >ҎPgX.h.)W(6Wͻp cl{W7sfЌcf`3z j{R\fv| t 4H]2XT\T_axR ]Լvs.7[bK& i("]I0@;G龉Jt[hKvJ}c<ũ$e&NpM}S)oޘ| KXRLe䱉,6˵jFqyT:u^*69ju07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!Z-NPq2%Ol ʘ @! YZ