sssd-ad-2.9.4-2.el8 >  H   ,0e U]n#4:bֈ͞C3< /_TYj?^sh(4&"VUj!nAu>#I PuO!+{=-J318mA*⩊N:"\׭ 4iEs{/{l1Dt%sW:ǽ2%4 Kj>0.8س\#&,`=p0ֈY5/,o>J9DW{ֺK^h;&Jatt\<ȧ>8 |oPKU>Kp+\M)^OVg)uQ{DF0dp}vk4j>2ڷᶎ,1^䙔|mA5 \MsE!CvIbY:P:K|ACN\%-'V%Q݋Ww,[ j(;71EVIKҡ!vAIF0J5z#\[]b;Ye80370663528578fa34100c96bfb754c8aa00fa3881e3bfd7a84f3b0f4135523cac5daf6a2f2e5e9c9c079c83b6778d6ea9ff9b90302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb5006730650231008565a7643aad464d370b9c669bed4fb6ebf463f1ca499c1318e024b69abe9bdaf6a498026f051a02567d8c2a48cc898102302fe2ebc4283b6a4018ebe25d1ce2b6bd02f9a445b7dc18d5e8abd67dc9ec7e4a65bf9e91906b438bbddc2726cda7b57a0302047c435bb50067306502303e935cd4e4c6b0f840bfe28c91dd2356ece23b2bdbc520263c0e731080ed069334ed0aceb99b1ec906dd5ddcec2dd2e5023100d5cf7b8af14d70163f4431aee875e308b792b0e639b5d6bc5275db494880076d2ee7969e8d6d2b024f86bb8d1bab4a500302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb50067306502305bb0bcf4e2ca031b7d6de3c6a3df1f7b4a200570f412bb05decaa6f4991d4458e1b4e33636ab411af3697fcacc728b3e023100992a9cea98d6aadbc3eefaa0eda385b74eb65dbbf5e24197ad7d2ae9ecce312926d59d4785852b7fa1c1a921c67c63430302047c435bb500683066023100cf34a1e5dc74bee4afc5710065b8e9c7c9e377eee877b8ea3dcad3c33a114b1c16d60d861d4dd37ce8402f4a9ae993e5023100cff719c81b7e052bb5d26eca1b59e28146c97db40b55ea6c80ae6c18fb84fa28fe2d6a8a695581ce0833927d5f79fbd70302047c435bb500673065023100d21eec744b6cad39aba1cea3b52f18d2827314dfdec8d9e3198994f32587aa15c45c2149a242a6be9cabbc67154fc529023028cd581e5b873eb7a917e79ebdb203fb0f9fc5cbd8cc8083ae11780c7883c8be3e50bb414086ed0a8a3a935a630c66190302047c435bb5006730650231009d4e0fe3018ab8bb3e6e63fe12425c2de49dff78da86aeab78bec0856e42f6f7da7022135dc822275c0e14c9846b99e2023015ba22d6b64629f5cda483ff9b80da2e305122816ce51abc756c6cb5431526939f19096f8279577248b74b5a25350a070302047c435bb5006630640230538abebc708d38701d1eccec56a7009da1c3fa48fd52a410054061f9698612dfed412fe6cc865d2d57baae9222d60bb2023077ecadc16a59268de2e396925a1e83bb6648b9706f205ab8076e3fd9de2b875f46fa93eb247cb1ffb6da9cd17717ca1ee U][NjfE=ЛE˃OAqK^ 2'ȋ,f +4t#-GMk -4G$?Җ$bG>PV;$̏zU&OAw .QV+}i?HbGS}h?D>o&m#O >q.$ *eő]`c3?$^XJ;?g+g)3K8fifGƠ®3?&֩ Ҏ1欛]Tp|ڄ! >$H93gLku{l)xHv}BqaVgVxA.ڲ`2 v CjA;H(l<9xO3{D-r@89Еƕ&.d=D~dwd  s}YlOj? 3S6S_nJ2OkY pEW_{xbCJ탶P~͖@GtN'` #Q>`El?\d   2 ,IOX            P    PEdE EDHM(\8d94:hG| H I XY\ ]T ^ b d8e=f@lBt\ u vw( x\ yO XCsssd-ad2.9.42.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.eaarch64-01.stream.rdu2.redhat.comBCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxaarch64'&FHK:N>nQAAAA큤eeeeeeeee+eeeeca3763d5e8ae03aa2d3970ffc91bc93edaf3b4ee64f03f6074acad1b3a4da99fa272cc8d8b8802d38d328ecf7a37953761c4d07f3f38c3f9f0dae9c283a079908ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90313fe4a92ebadab7af11866f7c61ce771c631cdea58fb90fd010a34069423ebc38df69abf102e37440ba5cdf6abce58901eea8a20d61adf01aecfdf02cde52d917f9b1f57008d51c05bb717f3a4ba27aa057ead6b6583ecc0576403ffcc82707e42c287364db50563592cd9ef5032fb6ce6898382020ae25979e68a2eb19bb335../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-2.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-2.el82.9.4-2.el83.0.4-14.6.0-14.0-15.2-14.19.4-3.el82.9.4-2.el82.9.4-2.el82.9.4-2.el8sssd1.10.0-8.beta24.14.3e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-2.el82.9.4-2.el8 .build-id37dea1b9a27c813f6fdbc094e223dfb1aa4a4edfbc3d4adb01c35be46a3cdbb2fa7a78173c769955libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/37//usr/lib/.build-id/bc//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=37dea1b9a27c813f6fdbc094e223dfb1aa4a4edf, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=bc3d4adb01c35be46a3cdbb2fa7a78173c769955, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)88PRRR9R:RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R;RR RR!RR(R,RR+R8R5R R-R4R/RRR?RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR?adclibind-utilssssd-winbind-idmap2.9.4-2.el8utf-87dec26a8ed5f0d0984f0b21386bf2ca3a22e5bb572e41987180177f881ad6072?7zXZ !#,] b2u jӫ`(y/u`TѴwyטj}ʻˈ{u׍:r{U>~1t *>%K'ʻo9qs|3-֎hڎT*> m&)0(p:ԳΛ0naQtp[le)j[/gcqHZ'Ф9{:jYّrc! |\gZ2ճ4X:i}Gsl%f<_/J nN}l=>[jUbYn^>3QPc~&Ŝ88 6̮EקZudm9uZz+ei}W mLK qs }z/dL2.Ĥ[6cY5Pz'C9u)5)ơ޿}wRJjE[kF t/A* 2Q&!=d_zեb7tvQ0@,;ɀ),0;>t 4"xb`3{Fx Z'xXS˳?YQIzum<\L,HrUŋOؑ!FGB@ĀoTZY>vzaB6K $LZ7:S$L#Qqg %;=W 玱!DO"r*3+_2ԣP²n eaى@4wd֫U=i%tBûm!*M5dLm|ZtD*cJVpar}={ SNAMyHzYY9^^q%z7pwϓRpJ/>{׶hthSPKr{䌷k.(Nk%E=/*;PMѡy7d6cEp ~Յ) qo6jM%gbKAQQvIv^aa+ K 8TLfk,2hR*)̆q(8nn16< ]r{mʦMS>V tw ׀M~1 - j,/ƉsK$WJb'"8N ڝG+M݁RZ`Spŷ[mكj>liuɈqߎ,v Q# k6\bUdi]eWOfh<)nR' jL_/"o>aBx:0QEHtoͬ̊dtVmغ.Nf Swn[2(q*5vH9>f wm-V?|H.LOUN ! v/ߑC+᛻Qz*V~⦞`TTm&>g@a.fc(+pq2~QH2-v0{Xp,iY>[g?Ix2L1ٳ5щ;*ƌ0 sGDN[ܤ"̒͸sөRq4?~gx%RT¡ʢrqmG~gXm6&T.Z~Aܲ$WJ$# :FߟYhj}@ݶ'!Vls;wI8WYlTL=%)ڜ*k3Yt??mg/V,mf9'b 30yg쨦b Bm>špUx)obԒ:GNßٯǛ[i?o`Ok:BSфe=G1&f:E薜)G{᜛[MLs2E:Xtjvj;d5,xE;Po.[Wem8pgN b-RX:gEZ" 䛅'ӭ|}>cmP`2DLG5vemtI5QHP­(q</VO?Ơ&8&_^}T0[4a^+)eJ J8FT~jn'BCiܞZTI\ &rM0ljTs}1.`m<ml〯K)Lg^ qG:1b#ӵw |(og}?vKgj,}&w4\e ܅+$Ycu3,7/ꚜG]N y?^aK"mԟPѰ2TaiGEO lgAM.3~["u) uMTRk:__aOv}0L@9ChLj =kF,3|`@6Y}t|2RG~V@30+FmO& A<3=a%쥶00=XG Ԅ?Ǐ!.-eJB#.6iepYb $r‡|%̯}8YJڤq[%^!-CL\Z0EU衇H+mA\It/7s]]ycώ$c4TDVaO:ZeYq#m=x(bRaԃi~a֔ YuP#4SM-e@23C nwZ@3xG P=BW<^) !cp׋́m*)%o%GHP*ve1bW=ꑃ >,P~΋*4~-7R(&ah8T,njrT+`sfo0rݼ(]Ӄ' %[Y~ *q@1zמ@:g"m{~ǹ32#o7dQ4M'Cj 7(\*ONb}%p/7w)b=$vzQarv{LM-*NJޝqN9$DjbljEz̓]І`B{ s.%+ c9o'R7m㮉oD\VjQ܃.E\[SELNͥuavCk:k ]/yXhƴ>tN޲c1w%>T0nՕ!dC7'joJKЉV۶ꮚ# 1lZ!RNH*9e*FǃcZ0_:BbrAZ.hEɕ^#Fe98UmVOQX~"DW" =6JocolȶF d-^vhL˲ ʹ_m72?% %M9#!5Ҿ*{ ʮ=a '(,8EMm~LwďWs <-ZUI;ٟP^^OOV3 Tgr e"O17U(ln'n"9E15IYE?C&zE.oxwGpWwLAo|pn1K7և7d ̄nʞ:scN71dyFJח;zwVv&vwD}6՟hߓw2#8|`#ح,^i8HItoN&I@J)VwTt^9ljyyiu":w~UYu!򋷎+O|Nk@/#_HR{ye}7ie>a?D_rғ=LbF#]<*0jw PCh 4QH=Z?hvpw[' f1W-҅)[]RhmSUxXI)6]+m [߸(4l+Q%SGX31Jm;4Fz7h>۹E -.]gG%ST=unNZ|qK(-Zؔ0dFTy/4y*2I'l3ʲp&W6~?l.MH$ ? a#uw_v{<.4\?JYDmNvRw+5ZV9[..YzX-KLY{@m, :ݐ^[Lf-d0H6dɍ  -{cΝJSRDχNʅOʿEOr?_ҏKC2.`O_^&|%^lSwuw|پ-_5[Zi91=Ͽ0w$UJ Nls;>iq$s N8`zi}h͡ӧ@r ?R3(?d_3`_, pU!6x¶:!`Ot|ҝ *c: . GH ՎZ4=8\#zHn _i $OюqMũU -ז"~F퟼UAlFhaTO4zPKWHKV oB3֙󬾊OW%y1-A‘}vi"Hދ~(~ƁF@gY X*u`9QL͜\kyCMWd T#PV95:V_9د)8 :{||(Tà8ACzʡC4~ [63yl/% Lkk6S{bfLW˺'Ž&cnvT9 =p)[f %hEDf7*Wv>bC5Şuf-(LCje#&B ̉8z k?Q GUC!& . h4QPAUK%Bjt&̥I: ="ƆW-t:X^7{>*&k6P'g5;\@1 HJNG;lC2Nye0z<'[~@bX7;y6nx1&08#MT߿Slq '\qōY}\ Ӟ rkj&*{RSp? \BQV얎Eu.Cͻs QnUVG)k;=V؆7kT6G+m[ob{n2&3kbzCeAm4.^D386;WƁrD02H8ڠ"FHz,?H:fI2w[ex3mv︒31%ifpfi1ݍ0Ib:1jt4V unQ1%pN\i-^ǯ;Ap{g]k㰭кr!D: 럝5<iJ/gq/i%3&K-J|jUye˦=%0K`]wD5u[grBv`}_dcUFw/e){7M^+._amsXC {G=£($q_/tpl:ajE_lD,S4Z)<2̀q 5O Bޖcvv\TgJK>հ zu(9 3y94=L~V]8Vf0MbL46bC}n dY?Kj]EvoC^=(QeR?% L&zN6eK>IҹAKb7sA;X`z=[$ҁJ8%scGMZ,fUѫݺ_ϩo!t\ !nt z4Ih̙XA*Eˁ&r8T+OD kOʗ}t|Q_4*ƦTDkO1 ֚Cbrhhհ.Jd?̍כꯀbj`#Q6Oo咭Zfڥ"m5Ome΃JJBF;o@ob^,Hc&LN ڜ/ߩQfE PJZ;RUlJx߆^@Cl?wjRs^$9i2 wȫUa2}u%m9J`ف&E /,Gk,:ˇo\DFAʰT:6xx{kjZ4Xx9 UЋ?/\IBVfܦ)^PKdn{HjcdY*-N_CY8 !Pk0e PnyqP""W5Q}B`5v=^lxcgYVt(ޝD$@qJ}#L%X~og]|;bMa>x=$Fzl|cc g \ )]+1/͍~0;&FҖ2n =1E8VJ bfK DgefubM+ⴗbI+TpRb+6vr һ=V.9շ~LTn%.gd }@sp%rݹl=DiL":dM^֡^I'Jrd8ut#X=@ -=~a.&4ly=uStm$w!hihEjƗx?@jZc#&da1F;%wyLGHf7Nc_p)7vAuvN\7V &]G/t}Yd@:I\^uÞ:So;6XZם3bR)zXLIMև`| &: C~AV; T2" d(q3nDļ*}=pqū-Hnˏz7;&GI?Krǖyu5BxpUЛj3 ]Q &'Fl@T-:6e蠡 lu{o-Y埂2U*sb|w̛S43;5 Pa6pu w\ZM=/sR㎞-UN& p$ܕwbaTV>0nELξ]>~+" ӵ4 4!qq4|>Z7\q .}ۼR1ddH:A_xtNp--KXU]aO2SP,~t!m*fkn8#ć7R4[YfP`f7= Jɗ G7ʱ]]0ܣ%\FΔ6H.g |Yx$ i֘.'@LJMBxzzU:F+zšȨ0~Cgί~aMᙣg^HC{]_h f^U<K.mHpl fΪ;Uy|be\)6ͽ%*7с g9V9~ƕJy*|eFωfiBd ϾrZ6qGgw7[]'w7Ȇ{2M_$]!H_S 6[e7m7M%BΠ(s%caRd#ӶG δR*')i+L%%_c1ܨ[MJa < VҘb6Bɋ.ܣ{tjS=($S?#O`78T-L}GS7 ;jck\X`)ak2Kj;(_E qPŖD5ݶu\I/łظc M"suY|qz3 2aBkЉ/eD?}>b2ES+'%i 3Lk[ |.G^Fئݷ 8hhuANQ64{@!'d16$KM _g'!K`dF9a?s.%k0/eHUMBb?w.1NϚLEK}<#bůzTXD (pi\aЛAJkՈ2OzNkfUR #  ~0b'&МB4J%}N?&\ePմBh؁=P#J?F@mT.)KRIc:3l,Iw!5rri?dE%x&_0[~JrV)y퇓 nD#.i⢶ђt`M0jAF d7ẂO4ΐ`_RǕQ`dN~6*n ӢCYN?WS#!'7j˙ xP:gwiu(Li²hme $hOrd֙t8Na7ZE>́AZx:`e&'f_O^I~0vԎto`)n@_r zz}) =B'pyZ(/[M U]nnw,;X kN% 1M#<(Ug$ZJ؉299f=2/" ^aճN[7T y "%IW2a,]˅x-5F#42Z۔C\^3MwPSis*Ku\V<|_%W[v9ٹ:҄>=^X'/o-ok\`+ exed} 590r7h 4iE@r-k/]*Vڗ D~ݥ[U"\zZdsfZ^g*+*,(g҃Bmܐ@"]wV HXlDP<D`Co%9E}S$XHG<ӫDљ .c ˽Q3{%j3Sr:M9'I)}zҙg ‘#{ㄼp=b߯6Q$_-!fc^{aC_%{x.ԶT2AY lm 1ML`yЊ3=qt=-O)vHnBwD3 DQt'qxXx{S1ks/1'+M }fq!jn`&uT5ɳN.8"|R' X/IJR~碉cWVhKhf*V@(n$Ōes._,76j=}+X࿣o136`dݗ?P5Ow~'%*58"hb$ݤZkV&xcfA.1UṰ`v ʔGy`+OG4ޞ`!#IM_a{9xFўlDfٺU4Ueg=솊vkUKUcU\y~h_Zž"O%.A HqNrm}JIUP8LB[R(@~|ͱ&ܻ<,9kSy.07P V%7=%yt4ΓiPۦ닦Ew0| 2fPL DX#]4vJ3]!UJOO%":Yi8GB*~?;\; ih <Pkwj'ޫ/Jh|F _'E' .yد9q wdgn-»Oz5-﹠U@vm훊 jwƬԏL] D#hw.Z}e\A6RUk/c}nkkYo~ !WߋTi7QF 5s|ɘe^˜~Z8l#sTT(>dK"b#֖'ruVβB`OBkuw^6քF1!lD+ߨ S̃Hr7aޕt~>fg 28wyRy$]wPiUߠTю\>!HBU`RW^}BѤ[Uqj&-$9G3v18d%LzU5 =Y]pw(:>ٽ}qMժ&8/ܡʉSxƪ0w5HmpU. WT+a5sTbĹe'j6fq]|.28پ7[ =1VTי '6w|`x|4dǻ\L xu6q+JYcC1&^Oͼpzekر\s'RYSLo]J= K" h`ljt hJ?-L෩Mg{k^2mzkH־ Uy!ƺ{,&]@c8Z'hT{YȲmjܣ:Q eu(~%S5/Pbwr=׽ k4\1w۽ M)۸ 2:-Ҍm_aQ 1m8ϋolS|AmR} v*(Fm6pO(8\BeDkC;uO.Wmr0aչs-X&+qX%щE_.Oyrgu&nYmk-`tUf2%xE*"^)p@փ' fk_/b.sŘԹPNWKNfp솣E-oZB \ZLZ c.~&֞5x19HЎfOEA)n ;zZw Ō-殚;YN}a-+P~mJK_鱪v6v=cOoPC۽d 4M> Snh_#wZWjBX*`dduP4\oȗGw1ذ8>'ڇG]JMnq_ҴH(@;^";E*/aR)ڎ^ʼn/:X]zVsm۔>sw}1KX%%9T %ykgIYʼW/{b͂e]& Ǟ~ʼnQ|_x}$+=@_W}sTw4)+3;ç*-__nʲ/ 650්JϹ.\TFYTM8UEcJ5OɎD#ž;eG"b#j0O? DWڍ\ę,gT <0nl.EvMc8Y޷}y(' f,Xɥolƫ$pՊL[ Q7ܥ#% ~nO=BvU/(F-AXl5{@_u }SI# 8Ѽ}c |潥E ]o! Jf?3㛲(8:4,69s<c^~FޔCp(x#;֫qKsm_e}~/G5HtB:‹$+|%a#_1&bZ6!}к[' SW#]g-`=~ǒ.ֿgݰJO=B@OtFm-V@iEmkJ"ӟ[ Ӎ!679aFrjz T=HA "f!$_煮e0CÒߤNN|%np B.&$Q”)ƊpPBH 8+[;ôDF Cs%bb$Ws5UiKc=facfH@A4"i0@\M&/PZz vIҫ<`"gI򔣋n6b%xv׸\3Q:~]4h&۰iXی.)s%&4e)7:1'z2Ф7Ʊy< NjΔ#>셅Y w6w%Ʒ?zoA%!{.W&s!K[W郏ΗsW:LGI"m:ቬx1e$k׷5mIBtX6-K7U/: }܁}d-+}MYx$5 ;%#Fڷ[CZ)/@?g7+XO۶pzU2O#"e(̠c)f2ñVӭu5n6t/p/" qg8<,PQLw1&s@"svؐ^Z܄2[rH6$o V'b_-r >8/s $p4Np'*0yp m'z]}( m1^$Mz1nqA\xgz54(jXt_TMwO3-by6`DGG?yY\6.;U9DCS(jzRR1:It.4 DΞMN쵮wAc Mzfpu k*N2|gw\H bZu_bUc*Ob<>MV!VȊ76n/ފt;&Q [ ~o xVPh(w`\y"X:(DɫEOZU;`E Cd|s1oi46v) F\oGͣy"s xnG;hEҫ$,/}YAG&!lCmCؙ7/*y ?aA}"7Qp9-317ǘFq/d!5PG0񾈩,Ivp҄7.Ys&Xx.Qҁߞ4= Wؐ3T@fW~NГFx7(7E2m0ec*&a7';`ytrgpJfos nI9qGm,もvS.o#^\ϯBzmq QX?pϋЪRi'"zn0H%[lIo_> qY'^>MVYP*e `~nPY}zxIsW?ݺ]ꁡ'cr E@Kܤޒ7HJUD4  \8R%~E8s1q#ļѹd6 2 ]pUM؈9c!?a1!>i Fp6J\2[uGj}pͺ_X"쾖Rx.V?u|V{KnuWH:K 90VpX2dZS|ƽ{7Hz#w/Փh eQ8D|&y| @~wLwDғP=8FjM8S'B1ÚS7^%POC+qG:O֠G@]/2<d@c!RSc$!D%hE.)& N:˷ٕ I`<7 L=Ł}z@xPbX\Bw. Ye\ISy9Ra?D"Б&x YPk`W "+J>"1<>@r@KvF;<=0~BEw_N .+:Zz[xݳt$W3AuU;gYDmyTᚭ؊m~'4[)}&<'))* Qid5Lb^Ϊ%VR@ߪ (۸Xz;fV./-2M3~=z!O, uHhBs|oIqzf{>^q5}坏V?m@3ȵ>M,Tqt9ZVQq(hU"1csoo-@#",eQJw 3ى;ޫd zu{|pv}GuBRiE 3=SV< ͍+ѫϮoAU!ș8n}l*ʼn)\PAtUG9'ح^>$Hq[(MwHijzKlgv-2!)h#/gRblBN+γX6{rshjMޓ*dB E/(DYzk˯y$ǟ4'z=eQ緖e*XMpohedױ:k؛=ޮR pɿ '#l[a:Y4 -{}֝E*7Hù_9IC\R`R`wGE}!94GkVJEc&aaGUcyP]W/8bPxMjfռt<(L,0;GUdR )am] 5̊"Uљsg-jf:E̜Lq=y(Ga$+˲Kyg5wgƪ8p"02 ;ORVjex%v%`Fq$(p2^&jwdn7ܷ˘ee!KˮG =i.J>Z#99o/t\W+RKCpND ;/SgEY U!t=)2kFufetmhlF0~7Blq:Bxعf-@6h?s}!0=>`UGk&{V+XߖuX/ےM 0w8Ow zS.nZ"tEq7ހ`wniE2RW/?KNFJk㤷'"By3@ʗ+j'jK <)ُ-9ޭ%[;LYCb}՛i2lPI|Й\N`Ծs$r:P:T^)|FndA sbkt@8pR#5mTy/ ᪏..P&_2+˯gPq %< 2TiqG:d%l/i̓b up SW)TV_6ɄCL+?4:qWߨ!OF)ѓT?UB$(BU}5d% iD+>w }e($w!VLw}U\7we<:JfRa:d__ߢs8FOBӗx1)-|l S| ıC]hoˁ=|Yx8 ?zH/bzk^9*(#p8{ޯx@*`?]s_ZOj6gv]c#eb %Yg#"QTnO@:Ʃ<[ [.}g;0Rh/4X3|Gj ځm?̕FRE&A`v-5[#S1ؔ苞|Qר{ a(ܘčFCnakoSorCF aĸ<e<-lvh D# DxfM MKK1vS]Bp[tN$yۛj}ɻlf'3HCӱzw)X;n%DJ E./s,reΉ(*n%m_<OfLX>G-V Cne #>1?zM.HfRA0^Yt}%C<6YoWu"j A8 }9iQ-n7FfJqTEi!򹪬1k& CY⯝2y.Ԝɩ$H}?x>F M\fgu'FTpƸ1FD תݑx&->ΰ'LjS㹡3U0Gϴ D6|cD⎉Ɓ:>[or_:qn0DhDFXj<8C}MI[j}F/'v%vrrC0mM &fBW;,{^֌K}#yB)`x@wLeuՄėX| `Jﳏ\wrv/N9(ғ% G'9Ws6 sc:R Kx X[i&U@ھtT;D\;jb~, Zh;ydrvfH"aNvÞG :qԫ(}j*48؃wa~p$L\`VjuS ~2ͥLEP%,eo` P7Ԕ?sxl55I2d$ ܂-L \A.iU6y{xtI"Ml_$Lؚ z rA=S̷eEëЂn\u 3YX&U '+ܾsV %IP1k%*gm]8kę,J\[ᄨT{G}RY&?^WePO|D\Wr $`A3) ѱG$º>O|Zxfw7 ~A{-{Mӂ\A*͂ ^ !{lD~Jw~ڬ_&tR෋.)SokMo^z$Lj40 Τ`p+z*DZDskmkm36ڋG^2āIhGR{I  YJ*i ?Jv|^cQVX-r(:m8̡ɍALXOYk7˵ؒ ,h /=ITZ'"wNo}ωbbġI˕kf 2j/m(ts&`y"WiJ< D`)6t'Pֺ6>.-L4@/7K#SyCkJFAL<|3p7|t;┡1i:D:RkCEӂ*)3 Y3h6RSk_DKcq0sd@+VNUy-4}+Oa~pTu+6KpHjQtR=ܫSi c/~p!ʝ?WO|&Bқ]媵Ca8YO;qbכgBWb"P9a9IQ5Mɧ3$Θvko$;ݧ t~iZNL# <֭pPns4+@CD#Uxن bIW|y^t*ٵ)W-REx ]υ+K3' 'IʺFh(<8y^ZpXeתV̯dM*nm<.y`s5e6uJI8{2w+_Oɺt:NTN.~~#_W@ďB*Iz9ЍIcr4#2GweȞj1,?heFXS%?T%}hOȅ &Woa{yѠƅ!6uD _bq@5aGcF r頼B}8H;?}[A!^o/z6?'S> {>2m8IsJ-ў:E .X/nV..ըmOG8EYOFGIQt B {DZmo/Ka]׺Yr9%9*`g4v]^`n&c"Xr*U,ʪ$zȐPp\fqC.x\`\Ѡ'-W !| $.a2(MC# XhE]k6֓\z lw 匍R:exIUu#8},-8*T"͑,+cJx*dE5dP@fi6lbY =}b.E2\b:TLi7ЅϛI;#W.2Kw@͉ >x %\7uZb 9WoAg#k' }:Nsj;(&vӡv=[0XdՂXbcX3Bޠ$ÂrIj #Bdխ4KrN8S~PS,pfC$^O{r=[ڶ=18Xa#vxod>ɴE*S{I R8V)۱ld;|k@ZdTxy95Z#}$MD9\&H4$R = "hyz_E(y/쥄|}q,l޷+D%x=^fɉ\wnm^qp;- ߞGZVc*W )t{lr50;Oc"eAhs[qKLT{J$@ ]/2K[s9(*N2W9F;_Nlq: ` 0k*lT~p£KE I=dHWWE%W\v9Z.si(!D%]Kg4*Z֦f^|xEX~J6^E4rM.L~^Wpjkȩ˥uh5+kBܻk /=b` K//R"j(ھWxʥl݊I~f$#Z2bؚu# o\7FKXv?1Sjwhzb׉ :D˼,fN3VC>_lȅ|&($(x +KGm !zL:HhII%qNAWP\81-IƵܪ=%l濓%Ef;Fc$SﺝN's)ե+m~Urho) fACzwN3(m'cq$-s{2f*9L<+5FZ2w\{E%'&gT;݈ ЙQi}Դ,lwsOViLˏZֈ)o۩({]-nłIHpG7̠vbЋ#$l ۵ : ~SĤwt=<爎:. Nov5Ys!<ڶ(&#n]|ty<L0QN9\uh~^F CHJjWp*(hrtd![Nz7)! 14p3PgNt1@,2-.IayzCP"]& qoh=~Scv+Hd mYYv+j_;G5\ɵ]FslbɣxYUpZm&¬e#;Z|@ЁKf^JK_n!ޫaqYxܒsj*OBQ[ C򻄖]F#~^{N$;´sO6~ohރ'hv-I1(gI Aٺgth  Z9d$BgIbPnuF {q.FER #V?b5$ρ.75Uظ녶]u #2s@t &OË9#kqLɫw˧R Y`$.'C+Wx>e 79㱚Bd%⥝PeX&z>唿Zs8/4ӯ 9E$+ dE=*쑔=JsYY즚_`w87 n>=d؀o)/"rAncA̶E߰$\)dG [xxr ^Ҧˇ Œhte[r2f-vPaS#+k_ZиP!MY=@;3L@<|y8D= &|#KU²:;$rMZX4N-^0XR=8/*?.Pǜƽ(w[ ݜy$r)B߫ޮncGΜHM:dQeC%54)&ZyTe՗lk,/QcuFS <2,g7ēKL Vц&$稼F(ˬ`]ٳ2ٛ Ú Ig9EI?,@r:fvq>h<%=)i'v)[1y/K7զl8XUjso Kxc {7hN8s#)ߛ[]+)BVU㮃t -%6ͼBB۴f YF|!.?8fVQ7Uk/31S#H0n =c;My:Oʟ= @ q3p{!jRqJif "MPp,ǹw:TzZen UyN v Y3Zn9vẔBz^(nn8Mӯ.c<|urbS_mOx D%#D+b'm6OWOpt?]PsC ~(9T5_#t 7C=f2Ǔ v+mAr5S(rbwϧUY9nXFwDH~o ?+7) #og,ĉSi:*ASշaNHqOB JB t3=<5ީ3A2'#~ZhLX3fd,o,jǂCx[/<~[%T6a`ST*=U(^udKYp.݈є$7\5QF9'B ]K0O χҤ֯a|G)}Dgu&N%i+n*'j&T S*(Du8ʶp? 40Ͽ<1Mi|OX)^}$~wCn3׸8\%B09I^k.| %Cou ߠgjȎ qyGf4!WgZi;%FR9nޭvH&Rute{fwǬjz# V\|Kps雠 Fk0ܺALOo#WZ_a 'e ̺.ր=MCIlڭrb6PN J9)Cw<#ְɤM┇KUE&=hU )oPC4^Ƈ{?x7|kf~A5p+3. ڧYiɖAc?nY|K ̞ B?ΖH}?cqq4|` ]0ISܪUB5 X~'d=2Zv18[ [l_{e:r)#{SBȜM_J3f&P>b@ Fv^ ݚIQQ鿝ž$7Vw{yAD?LZ[:]?h!}pTBv+=8^.{I=-)`x}baWB M^knqwi"޳iYOP|,:8\ 6VbۓVX*o9ŗ[4 ZAe=G5z9S<6Bر[WRvF%0l3Q4f\0q;;ܽ!r_JE责}\΀DfAHr/moq"l7"*Mbm ]֧x`F/j#ʔS@*%Y@Pe#~B* ^r0}@~㤧KvAE96ՙaeRopDfj_Q&Xxx$Fn t@Ԯ7;F~|hBT:;zÊka d?|_yeǑrffӵ1Ɋ+K. ?cvk5i,5LG;_kolcF"O]!HB yco448d ao3_>'9W]_ [U^{q yM@;*P\jZL21vG~w m jˁV!r"V"9K1N1<`H2n'a汙*2 {R;L} B98[Q# 4Y} O)UQQRս]DiqX%AQŲ r25d͠YU W?]HԪx F:@c|G>XJ#MRϲM5{xZvE 1OI^藒p+-Iu杸<@uge[&bLo[k uyԩ{Ty2gmpO2kNm"fX%ڨ xe@3 l۰cnSvw*nS!o?CU`khZYA!D2m'̨8&?֚w`-}$A +g4A2Z[揖J-'5Ǭ "{ȇtpIUd.4۩=[|ch#jtıCʃ|kݶҹZ@bY8vRm8=Pbř9E3&]x ѢN)uC2fb /r#fe;Kx>)Ǯ*%@doCFIqϼR%i塪if6%8-k=^S;X U EꭿC a[0[x/ ~#̍~47,C\\ų 9Z4)71Pþhs'9VJrMe߽Pe(cL<ǩp#bU?YYs4MRLVVEs:$Qm vX $Ӹ#c<;5 H](;Ӟ \:NAa7Qewl&}@% В9X='vٮbnj 5`HaNOǂ!z- ᔋO/~FL\3Ѥ.m5ySQUyjh`6zfEzGfj/WSn>m܆@1wO;OdLOX\#xȟdN$|IcF5߿+5åAG'[B9Ꞔhv9ۑUK\1Wz[r r -BLtAIF)J%=9 HU 80A^j^K ~< {毙ջ)Csr?y- L{5&3mgгzuK*;nBI6®J a9q. LtG]$vcۚ6SZgR IR]0l`wbk Om僎CM{DL$6[swۀ|g݄ _Ræb+_l?nl#"yT䷵0"/d W:c= fMӝgGJb6Cy,hֲ5sa{#Ծ dGZ^Ԗ) \qg7_Kjj@?G`{r):M@7#4cܝ*@Nf%B{nk r]9j49RLM@!.dU_=r)d Zm;4dedW @$;fv^HT1N;qVXq0duڵFiUs~r[?ZNa 4[bY 84`ѓ|d"eĻۓ:ZjdQDžC`N?S5Co _8<7Tkt3"e`H|HBJӿ /t0Sa]_w,/tcS&r Me|u [ݶtT(0Õ\EX{'}E{!WNϣպ9XXggI~?(4Ċ Rvblµ&qz)/:@j<_`iV/Jdh R9BA$;е&I1}iѺJ~g"H;KxF!B ~PwD!Ҳi + $ M#5=-UzbԌ/Hܯ)s̐ҔРcJ OOSid7C$Q#,qpj{lilZn, 6U3T(X-G󓘺m6Kk sqe x cŏa z ?n^dW]ccx"6!J%WFl1*8dJ?ǾXF-_āqݲxdǙK6us(7!-ߧ2ܻNF$(szUD\%+X*?9SjMacԌc1%sȻF 㜭":3M-xWϮ. ܔ LmF}*~mbM00bI 1TQ#;#;&~Al-ٷzٙ>ӻndzSe>a*HX>3wb^S^h })O?='{@ox"`32i 4Nf aEj&Ž NWلkZhk[4]9+1 nxla@HeQZ䊩𰟝dU7薡n `.q#Y}΀z$Iעϳ*q2^Dbz om{,8Av1\ۙre) RxOFlY-@F-!F7j ZA]'1 qIZAd~21ʟ6SuQB͆[2f{MXV_( &z]έKuJd\깬? ΄ĉ+M֡?)֍Zi Ѽrf`;zyl./Tm6:-HgȗI,|+ԉۃ7+P)X=BSf+vBNQ0Nn;*X'c59908tl=$ N xw/jIlNDaJ'!w|Q`vxWoU@\JCArNX7Q ,۳Cu~_E}$,QI"6sRm2ԫfm|Z>$Φoq5)C6?}.pkTO'2(v!IY؆"7WS+k(Mwc$BTlNouɉWM^6dkŨVN +͙^&WI&{[!AcwX~ɘshPyߵ+r`(;6E/E}\~F,ev&z|[M="߃dCy[U cQY}0 mS  C끆EC{|e[{V=Fٞǫ'O5 CxlĘ8K%h9_1.̡pCh8E UT*m`>4[/82÷ 2 z-LʆK->#-7R>3?>,hԺd#t|ʿGRuDa 3+pTKCj m\U41J-qMq~W5 زdͲyUv~Eyj2 )'% {[:bqc Yx?DbطXO؇$aEOLv1ީIȡ++ؖ ɏjg=6Cmnf^Fڝsx_.aS^tr[x\] 4q }29o'|bt6~]gzluy-#h 4ots3q~(A Iuz@  6 _YJٝ?$]T*wfUH367Y1D6TH][UV{M}J PrqH/ڲڛ$0lxU |ZC]sm죽+x=\/YuU08b&ˡ, ԏFh %| 6<i[]wS|#+]&3~eg+Fe JO3حǶ(Jd wpg+t m'D7V%Ts%ju!b+qr' ?B;HA/L"dh\Bv&\af5g9#,TQ/j*F@5Z~rcK|j q> _57#)IQP̍tK VڈD#?.ۡ&{RP^5-v& pmQtW{{MES䆦.@WX>>o=^6?(nq SHNO1[Ǫ,r̛G\~TJ-=40).٥l>wQ{D^C!:h֗BuAEVNvi#Ъ_pA [.(4)8AݳelixX uW#]6:Lch01:5NaJ!' T {tvؙ!V ɰ }myۤ[£^XrBJ$ QiPY^o)^9Є|x+jO>ӳ쪟lhBdT* *%[~AHTͽ&/+AϿW˂n(/7Pର̉:U'ćBiӶ4i֟jv#uj>s)ezpTPrRze@|JX?^j f@AJz~^߰U^$H&h:N iLG78hTX y}:p,R /|}[=PldP/BȧG.0[j]( i} 1,f$L*̝ oYDuo+TҿHf )@~]y(j}/l[⾕W[[W9MpՖrn$acboa*Qu_5\ ) 쮻{t: y[3=0JB76 [wzO(wndTuUӈH+/*"P =.~1:< ΋l05OzXBbc8Sadc=sIqO3dc8 ' bdwNI*euTp%fj&\:0A+H*PYAz~AI]G@:NH{Z XPVP{v9A7gcyU91fl[,>86 "f"O+$w9? m_J/. }K:ð۵_joj6#w.5o3?!i"ښˁpW=t N4&9W^DnPo蘭^%lHϘ"܃޻nmUeSVh. Rw$ F,.1B[#lp%MSd,M P'p APܤһhwBWR +y eyM йjnuvɈq>dι s#&¯q h2kI.4eM!{x3MavLġddTC㐟c.vVҫ }$l(PI!d 1sۆ>QcX'_oYC ݷxOt 8^ieQ*e谸E<;FyBMܘ>x >DZ4 (ݱnŽ8ri~V][fP BW JcJ#މ${!6ZJKDZD.=W9 sϊh%ptfhwtBdi-St/F%7+Bmx{ ~5 7)XKV듲 iWO`KE ,^3l_3rrl@O#_5b: 6uoW8qT`T7!Y []x${Z]qNS7 ^`e$|(of)9 jfTn;, CR:9YGE smQ$ M  niM4 [JKf$"¸/4zJ8nw'KϮ"芢C*3Ԅ.jW:ke*K7y )Y$Ӽmݰ]|ɡ+:&8AdE.M@^ o٤nz`āeJ R2m̕4mOSZ(6XלʘTI϶ƪ8k?#8@݆}1#tl[^[[#qo"cwa¹/--nq&eܹ3ё"Z/[j?jw<,DRVJ]偼 $'w6B(P]b=P1wrlTGp0$j2 x*/Cvc'J07ot*M 2J&ӏqwQvj|.mIgOĕ;N|mH(~=SU+Z&OTRM;qwSK݈UN-m:3+'u~V&C[࢒ф\w+8Thv_Ʋ@wls3G53h֨ mZZɉ/zײ'W}g{R,x)o`V_Q |ѥY ='OngoIJaW._ L1Ib@eƳq^ C[@h-y + :598d- pm]:7j^ 濨 Ggm}HnKKXKX@|(,93)SiQJc_4^G`weaEb ngsY{~Q؂c/s[zWS{ .}7@6׭0'0#H:ud'ո a³X=$ ړ"*Y6X0gʯFg>:J3DMQ Vp+F/մ㫉"˕A]SeF?}YgRt20?V`IS =wJ,,w2Mg)rP8KTxn_La&?ǔobFaPe?_fXd>{P"VU,dbf1Zy9o0C@-q2SF4';2EȠ]'egNU 6N9lfP J+FHSﺠ# w~ ,+? kMKU~ Еf}gi-DG/+ g_7hDUbȿr<xF^Ty-y4ۇ%WLqtkeyV%oKA؀{({J)$iF Dukt8wIꟘ)ZpGEU |+m th55z xW\08d9CwsfHXYQ x'vhu3@Ǟё&xqƛ>Քt?ﶰD6oフʷZ9-$eg}¡Y.j!fK:CT\_|с~:m-nx?x%.gm!Bnևg+&#0j,Doc|fiV7f )Z(<ϧƋ{׭l?x#-yylE9}yiY %L}x&hI;rSz5K楫UM{&P=6yLuQ[^{zȄXC4CiY][O'ßc}hڪ5ҵVHG՜v ^U2B\__{3 >l0Z'PlqOHZRklwS7Ǻ~NK.1.ʻиWvOT߶ìiQ=AgӃ~x2tDI`6>Gg2\x{YcnhjAfѷ) '!Kqb M/ MB=CcN/+H }GZtPHZQ37wi4CB;br/,sв\*zbHhYZ,WD{+2bfJ>cn:ETxnNjO)> =[`JaK>$DNk,q~*bỵw9;jԭwL:1!W\pVaÀSx5TC6B8\艹I gKmni_6v\[H2]h` 㪍Դ/0_l3ߕs{TAm M~b""9y  '@ bm su4`t[ܦY` 4.m+N *'8|w@adBxYk6(eKWIP!/bG۾ R*{C7z{J[@\"$0\2*exjª=# SggoNDP)ϠQT@7z#IeeM'KA{N _OXk$11e$U SZ=`P|Lݽo tSNk᎘7F-Hc"m(RS1fƏD턳Zr?4]y΅0a ilT?ƿ͂\Ft9H4_x<{\}>hxcݪKt2ߩiȠ؀7~=,IlBzx B-iplZPhە3_Q hO-7`d=gľhL@~3ƦdUVf,fPM5i8,A+ `'q">L=L57Qm$ hz<58WUf24NaK(ka:R;0;cq!s< &p#pI+Yyioص36jڒV( O0~+qcX[UK7lVdW3oؠ  *=Nd;!n-aw"ctEZ3W>#jg? ` ϒh5FF\{2i#;_}{svBxrӨ犆[eވF%Sm/㋟hwzfN{vws{dOX# Vf^us4a̠ 12$ ĽĪ^#QY5:d!2|ΞGqjt;C( 1::K'h?D K]q@Ή^%B#^pN 8dMBɠWEbf nVV3,?AAfHqaJW*YڧDzE27瑥Cc~Bz ͮ=OH!޹Tr fbM06n?"逘EM곮A*5 DkHٴrFٰ +5z_ .G'MрZs!:Šfzs@<#oyTk],JbQto/x&K!X!\TLU1>P!pnlJSUhy.zZ!5j46P% t; !stv/ٴ ~z-/wP JJ_#s.HKpQ9l5ߡֆrز:2* B1'^${ޏNplɻ(|j1;zmu5엤t>l{  G>nF;Fzs嶷hӢ\p(XHag.si\5'Xt1}U:IjTWXLf._ZL @jkuvn!&&׹}$K<|cA0Ձ#qFyqh0)2E՚fd&su70A jEİ'ߵjvDhJGQD܊{P! u%f{e>zҢ/KIg[&G8Vt.DYLQ6.h0y7SXn5UUYk{t]qr#8aO),s=9{I2tNZ8(~ؾP{Yay,e 2P&0 ad-R2y[˪Z2{ܰ8;4}gS5JHުI~)^>y[<EfMS<'eq}G˜PxkxK2xScb^俶L_@4C*FUW;yƕ_lռDeSf9ha'rnV.f¥q̡;)M7pBo%!]/Ƕ~lKi(A?g䗛)F[ئZ'j~EW[e9ﳋȿU%jn46^ÑЯ>E~8]pjXbEёl3KLßA]M)TK\W*څHYOΤŖ&1a2<+LjYNzQ+%0)9RDażD#]9" T~+?~q{ErHХlo]Zm8kOc&Z!#1OѶPNJL` Qtz{m=w&[2.L|yХQA~Š0>kˠMȽ^x/62+Ԣg>C?V9h} gOŢ?^.L$D1K[+Ҽyl"f BmfKG$8zݫS8kwh"QSkV)͕XkCG@[Tߌ7uU*蝅QcnvMAǜ8x q</1:h1+ "8O6E35˚R/6 ܔK tyj5;!{AEG*C+AdL Cy5G=t8&WHSo-Ӟ F!psj$)u O Jý.$RbCpNY*ї+)kSyOTMS(!/o|.7:Sys筡x`.j`Ӭ?|90 _zԁASjMPJ{ DCffR==Ӟj}kk y\m5I>3~5tirӶd)/9WLSB\ġg1 cO%iϼٔ~ލn(:RR))>/.&6-ok.ܟz#9: MH8y\b^"3bs[Qq +K^qZӥBK;;Uލ]ҋ`9umФEy i颫Fhg٘XaVW%LB$Sd">0:" ^ .%x!IAX_){ `!Z0d#n "o^ƶ: c 5'[7]sdٕWh+/-2~]*RH * tJuX"̳/E5KrKәkI]P%=:#@ioN4I N>Kzܬwb6it.zb"w4 j"V`2l9ҍlV)v#-5Z3S݀1C]ftl*q+X!Ǧ1'q2#*$ qV5N(zx%H"(!zr^Y{PNlSļPO5~bUYb4+,oĈaRم&}` zAACC4|Zэ[)HcD,[[wRεj)V(=:w*H^9 #gi~m7ή螺7qvl9g e\LiE u)R+|y)Dh=0Yu[tSOD9-HcέG=_^TUf`XLJNGFX8^UqK*]s"̑t9/9dPR M:]vm5goC!`Ejqow{R{IU)/1]ʲ.>q;zV:A»D RCsn$U4,/b~QT.u9HdeYB(}!*.< ds@=:wQ3fd*&3)I{?tk^:A+bX2Sк\q[)rzWc 1oþMJ׈<6)oUJ%\3"<x&1=S[ ~&V?Ap9.@ hȋ N5id_iY쒾@챒k-3J3',*%x|c_"Ė8 _LT!BL{>{l1piC1zHlYD o"tL&)a(Ygz[9FBKʔA ⷙ_*B󻈙y\LEAׯ%{W`ّkJ Q NԀ)/݂1]^VmW+1\U儡M6$|$Y^e~ܹ =ME'+wY&q`}aĉ(H4 i!JRjNKVEu2_#vt(A61d0n켕`4Xih G>tخ?>]W(ۗ|cHvnaCSBC h:q9vɨh gިV/"$ z4J-J siN]^ZZ:5Gf+! nt<a85zT'CKҾسm- &xqbqAmE9I֟$J_ʚ5: Xww'_ oGu| ÿZ8X|IEvno>bB 8_) ɮDn߈_ƙyt۴/_]ѻҢ ΋fx ktN^ƺNj"h r#/:Pc.BP[]%\Ez//WQQc! s1Uf].~%.8˚F{!7ܩ-=q8IQSB9#$)'G!7t鷧+s)xZXh_[Lˆ 拇b,`\;ǽL_J\?xZj7Y74!TJN<1# ~LmaGG!&9qԼ $LIZTQ2 85Iu3$2UN[Hxc2O*՛*Lxp,F!2[1+f4ٸEcI~Nͺ$P>Nq(ȺC.y ?%w())xĠM| lAWȠ ͮՊ9@ӿjePL%kPj}dXtd!t- ITn~SyNL;I=nٟMsXQqz䆵ZH']ϜSVK&^ B<%9WW&hzK/3e?,)Qd(䉕O im~ƈ \#Wn+bNcZKV/9"t<i9ɗcZQ/.3 x.]xsLjL+'TF+LIJC)-McqVmt^2ZD-#sdD-R1sg+`#*IӨ[")i^$,G+ʴ}RDi D}"Uɐ4y]z+WK_LG˙<0 !)n|[ ;2K_N. jbs"QxLddh'$ƥ0#j1CSgPt1vFCqטw]4`=ղHqd<4 q6;stN@9 i ĭK5()?6*P#ޤ=mu-3-Q3j6I{Hy}<,%c~ gu.LH $0Ptڄd@]]_'ULɷ372G O%RXw`Xdw6@c$SF)߯Z -DcHOǸjq(;lMU-},ĭxEꑅEo%y$r~X13JmqA'] 9hdDX9H<ABoxlQS Dt%j"meELCWΕn=:wPqkSIKv{HFɷZ C$H- r^B)ttB1QiU*Q5:+_2NPRa<۫M!\F,uxbo߮0=I L=ueg =K"Gk9@1u1e~?uXK.دͽ[v(v@Zg$fHI{UзH_ܲ3@i|q"x6[&?>hV,;7 ?FF&|-W&{8 5rrkc:9hni"8Y^r1 yA̾O!5~I"4DeM WBe6Gf=9N(M*2FA[3\hlR]b]:TԐE..2+F isx.ʮu'5mGgZZð1_My\`Tud7Al"ְjAhjZHuk#o6!i5bZ&9UkBb.OFGdkPBki"{P!.ZρWSoeBU0-p 2dAڐoYv~"&;I:K‘wbjMBqn?'y'aVEɨ$&ab'Zܜ0  = kt=:!*[;cJLyhĩ"ؠtJMM| w ~_Gy>GMiwxI򻟌o 14YovbJY[39^fv=էS0q{$JBv(1_࢜=ĺ`6NvM R1H}ϡ/Dtdny >^:Hb9tĆs5ӬFV{l5T czz}@c%I*T|֓f~1DYCo/`b{{dLS J#j_~WE$ݒ/OA-]ߓ*/N֑=wF_ihƹS\F68X%YL}+LJWAEiawJ aɁ^g ˖0MOT*w /_>{>t:?{ԝz˪[*C3k-SE @X=UQ8hs7fUb匰tr *_^B'Էz;?c Tէ–f#ےii{?vH;FMb;#$v*Q=gAY`|4I0Q$si:&q|f8"Vbq'PfwY"VV)ʸ4o,iDhiB< ϘEu'&@ )%Oz^=Y L9j3IO|SaP5,Z^q{XX쬕D(M_30,\"өBJ' cO {#Xb:x9A| M\"F* =תǛ5< QfDjQwҺѥNq8&[WJ`@7w ϗMf]0RXw&ЅO[Tl&v`i0S@QE%IJ,!Ҏ2A-Juo|6@k'X5eN67y*t>:u_3 / ?$L"U pGP tׄ:]bݽtq;!Լ2RB6c_˶+Ňw4N- ɔaBkM }btT;j =+AcLwvѨ:3\w%|u|[ݯhDA3iy}gL BP^X2%͋DJLA6t\W{VZWrVXq%^ Rr ęp͸R^,\#m}##^0ĸkDn<ճO~ºK&g4c'ɭ Sb?]թ%{bq@7TZ?բ?BTE({?PC&[0FUl%%L-Kf+z@*)EGCRVw1S4:mbO_fCw( Æt~U*Ju])?!h9dOC3xޮK}XuX KN@?,H׫(]%+5DқNPטIfsjtγNUF[,x [WH$Bte(i&tf^]åM 9ӣ\y,`\ :ŁX6YJ/y|{6Uս`]|6qψiy?Z9o_PYE:W2> 2VJ 3{i`Z.ob8P_l[=ycb>)m{z,As1m!tmLloaU|Ek޺G2 c}\1EHYo:68 {wH+Sד/ eÉ=G0ӊыu!9˦X)bukrFD$9wnYuHr)*Rbw? U HM(1;N|J 6`Gá+U4`gr{t͚QE+JntMuGĥ1ϗuLrߍrfOS}AEN:`[3Ϊ8e[7y}5VP/,1_wT1BII@A}1mT n ~*q]lŮ+$b_|Y8Secu?Kp(j`Mm <);G.=yC4ǃVpeώǑ淋zۙ)9bU??D_d#!]3S0o$n/RJ3ohFk`T=ia[TX1"!_22-{,`5t1%)ą.o0ʻcg(ǙZϫ~k٦&󽽅['(N]8v- r+oۧx\IH6fB47΢[Gბ4ZX<&gaօ{2חeatt#͑yD[VwXӷƫ{4_g+Ƒ Uj>Z`N)ذ%6lxkmxvMB;&puq%kM ճךz15sw;TYbs&ORj/IfH.ȥyYXX &Q_\J*fLն͕1⏊>\Aip2J8x)BH[&-IO§gҘHOOSWcH'BCԝ`\?}` SsA$5$ UR6GveT6U!/ZL0mr48ᮠ"0Q mV",'6hߒ[ki\R5zY3T'C`-Ӑ#\#.n/2aAzs;Tu)qE50)2 +:1f(a‹R~] 6}ƛr'! B` 6f5(c.gHv>O~\~/eԥՖKaoFH HjC t,'ڍczgХ!Ū5c /?eOATLG|& a F?LpS17bo%ET !j\{8_]af eKߘ:70j0:jr qRQz*cpYta-%P#X&HPqJZ!9gPLo+iLlcZmR5I%k䲂 ]pֈ)q߱O]>+״}xm7k7E[OdH95بj3;$(/VG}3' ;Xeb|*fx^RR9$If\ERQb2G0P0@˰?Yҵ|Se>sD|qxˆڳ)ddza'eΚDy0մ)G +5Y:Dpj6`Ǎ.Uc8i zW#`pV'4碈\,vdEηJ i_n0)E:Z ,{)&-~"NQ龜ͨTtJAz-~hFKR0exLw(̀̽G–2w!6(I gc lL yd@˔ :TZcg;/PWGv8?;>p$q4V@bE#uD[g\u Roh.T|1)Z_q`"V\A!  +QX-d^;N"BYt?Ϯ=:}@T/,g$;6ηz-?Ԛ#Ȟ<=91z Kto3L`EyZe3?gFHszO/d/k~pc"O`Y%9!p-HKYhQiOZ6ΦB(n>H|h~4mԥ-󁀱z`=c.8^jj 4M)CUܡ\DJӧȆPNk_,C <ᷞ Bߧ6˥I;rkXyGqa/t?+K͕W"o8sz4{f| ZI/Ejy I4R/U+ő<ۨ2<9 F)!]rwV)Yě4x!I@4L>)>A!ݪdgLv{)"/l+fo$z91XFjCt{1D݂`۝#2dQhh vԋby7 `VԖ=L,2X;.2S@k߆:RgUQFZ?agOy6~ޕRG1W8B6D^[me ݛ>@4e'lP+WFk-;a_Cv 7»EETuԡe)?u0U)U߀ ,ϘaBqM !sYـ(eUyFU~бkV#WF?bO]coa"lpU =+R ȗD"q̼P;̙IJċa}uAj@-Is0*9kJfmċ{wל l_&Χɦ(PM؝zf1uO ִ0@UYXo)tN=7+ XS} /r^O^';^.4Op3 2}f˴%g2,ocMN]gg#5EHM#F>^+HR3YDtX5ފ1>eFͤ`2tߙK@l3{D6fehW1jG=ⅺ<J:1 E^ bڐN!}zf $Z#W\=h(^.bC ׭xiްdpSKkWE4*#,,_Psn#|1ᓐ U0=7c&qWF(+}3ۆ.dmQkl~n7_WGd9nRWv`)(UsJͻrlV\e2ԥC,=T|!XQB+\:1QgX3/eP~ w#$o<ʲ-KǶ ~~]^_jw1F%-}<>hO*u'!)X" n[$rqhd6Uiˏz{# _S'wE?'/Q}A9ֆ˪8`h-6FZ 6"ĩ~6Lzx_ROD ^Idž/';p_8#嫃Lj\%wd&q\^w Z, Q☡bSăy5}wY Reo0kT?-p'GQcquh4T;LYj}.MLN:k O`Bo\Ѻl5&b8<[o= }K3߅s)x P؏^fJLΐnz:@zkߣ#,z'}(Y ҁNbHcm7QigdE"T#* {bdWן KFr zo|8EO!Tb@㻚Pl/t;zO0F+[\b1;w vELVB^3XN%1g+S,uYdot|&bpj>UсHvzMDr(`TphhM<կ52D~[ֳLFs.w&,E @%/` eR ŻtI#dd7WY1EASNB\h Tjt-'? ;>U,)Dy`?y@חݔVQPwGa'p-{^FF>?Tf0N%"ވ3cE=BZq*o@xwbחsbolxJ!^Iknn>VVz;^ɇ&[،r׬y䐯tOp{~Zʧ+]I |oXՠgGm4BڼCM<1鿝ˎ)҆aP'?h=ҕ HSGݠP!oN*W}/jJT=\CLfnk\%ZJů$ T߉;0}DySoR\ ð4t<)@$;lU$ו8G(x?jJyV _8nUj587JP@)gG1B*o˖o]э:ڹЎ|ATXVy*{.:+)]֟bCZkyFe 0G 1=@KKee~; #'МC嚔YYL\.,$B[LiNjqػ_];=p&;(Ƨޫ+ ejV1d>ziwhPۅ? ʫ~8gư#'X4a~PRxQġXwo`ycw=;M)/N(,尴oo^ 9>gu %T"NB6Jl%Idc~&vTɷykDžu˷͐mmiCyg9U_c㋩|h1Miݫ#c,V s# _ݴҫoq[_(m?E Qsf'k v/ٍ6k^}c>&03Yk6UwZHzX1V: ǪG3 _G|.Uq|u lR&?f%+ -~JO&|c_$(ҫ;P:8ՕF Rp+mwwcI93^z0"8_D6Ěs7[Tu;NG T &Q\#S ^hIx@a^#3!X!HpNLmy2œOJl, {'c=w jLJxnVPAzs ?`yX7Ty߻5bS[im_V[P33;4NT&=^ϑDb:@J`;5lL8_$ꇴLkG*R4;=bU&8c^f+Nya)(ˣZmTJa"̆YNwbs .OSzEUĖ.k~TR?A)Ʌ ۉh}lgv⤕"[x=zޙ˜g K9fkT9J K2Xd՞[xDPDGl+q2ӶA]yy(۝:V 3HUz0fv$nVnx%s?]=mbKϾS-B> l'vֽsԯi{u'03#L0FQP$mαҁu[]c/׌o)5b) y &f&|yZA [[/IHGDvSpӥKw";T9zyo'ЪH*0[56soP|@ e^`@|q\hЈMs8iK5HGth`j?BYPI.Mg7卷P0;j{wAf0[pĥ-fh&?8mtR  5V$kT8)yKyl!mz.F2~@׼tY$!-FiT}/{GzZQЩBőg4 ߨie!0g6FV)Qe`,_YK\v|q3X=~q%=5Z "> r|`Wd(uߝT !6gbCF2/C@&\ʕn3Ty\ +ߊPQt/0Qd8 x}kes s^ZȜ'"5hW:Co|L^?-l~ ްN:lsمy"ƈ:'`>&lX8rlyՋu7l 1ꃎ~C5:oFjjp[pj,%DA72$TaÌ \R1Qϫ"|'҅kHZeAlk'!7LX3+w+-MZKG] _F1RP2ɚ ^<>:d*aΙkk_;vq$/]AF2kN'_RnJVfFMÝpF1%چml #XOWr{kWhuZ5q(aO l(#|.Z]͂V袃H} ABlᣅdPyw1ɰ/}޷f{pT,b}{ ecdΌtT^9Z&qxr]7<MNih\)kpC撚n kv3Ho>ӛ_H+^Eǜy&~pFOo;ul((RN`D{hy3?WSR,UTGߒek]&ASLG'=J;" V Žaz5{UY5a@!y]gpՓlC׬; ~֔#;֗r/ʌS|?-%>D,Fvzmapqtonz*i O7qՐ& ?b>l2 J7%BS~*\؟Knc*G6 -{šxmF{'4>C <3S. y[9iy!W\"S`)Q 7 ۉiCFE^Þ͇>K=f?G 1Ϟq$+6|Jnv_^ol3 -*lJuYclL 3Z®}vc'z $sG3kv*Ç]]l(JeMxkADkK-GYظ{; xsu$98m~.묢6WpDҗ,>9Mq5i#_N}t[;(D3WҠ cGނ^(4A z>sEC.k"kV<_|J$]kUZJaENYtM_aT/{?3*ѽGxwH3s r# 9m/<-ntOr,-KUʔi{%w1 P0e87|/:U׭C{J٠nl'8/ h3BĖbPX`o\ol,7/ "a_r tZ@vaA0lWjQss$tıԂpAD">mKM@o:' K03KtL(-$pl2ΌkqSƮՁ dqIPY eAnF77⍫F54m9ǒaT/( [L4U܋ekl +I3#aM[p"^jIqT 7_:S -PD_ K<g2Mocj4X5%o 櫞SO[v϶LbEYkڼ:Γnǝ &4{NS-?~⌽+Alɬ΍e_ܪdTm},hYU[<.+Re1jݫeyaI@n3V utQ_ P]#"L~myKANp er]p?OlsE6"dl+oZa f7D%V:`C6iHBLӠʬ,SpS A4Y ּF >W6t1m{T[a+ޖuHmSOu,'ݽ/U@fk R|§"x%Eao: a8bx2 G3R_[H=RNiqb~‡Qʿ34kw={^yB~q_8,rρF]7c`dS_@[a4@y\y-G..w`fB@i.&.6X,`}0!MhŖ'n;/^>6Eiu`I |x +;xN3Z|1^.s{3#񴘺ůd/a}g/}1 z2r^>ZyxЁ%e)Er{`\=!3ERHCh97&P" uxv/0KH1B$]X)Xd^'IEEjn216 "ibNZ/B THʟȭ?MNAeS z>켝dAh)Gސ]ɵ6U /B̌+#-8wd=[xWS<|i =dHUPdL-T ?,U"%b= \iC'f[1AZS;$#KĆD `}ˆK+IŎ3q &*ѱM 6ZI䙉{.2ݟ %M9kKu!#]VY Fw՜nܱb^26F|5s-i+qfv#t5DgEz'o3R@e tE {2BL(Q.kZ0}nk)4I , `K8 }CJg^SWhM>JX5]U) ]#NoKӹxm`o9-)L FQ . FAԾ` JcW,(#32^q!4;u0bb/Lfm^/2z3@lXRr#6pfcer3PtIb}sj$Ih0 $cÇRI!KC ލĆDjJV%q kn[|2$?u]6ۗ&/B߲hU4N I2CSaba bIR԰$鯭j1.Nw׃#+4haxs  ,BxA ـLHfQ* sM1;)*&F m45PGg'k?Gc]{ ͣ,0a..J,*eogT:Z%aƾF=Sby5~6?2֜͟ Td)40,3#‚gu#,~[ӟzuBȑH#:=AsAI ?dMHSLtnW?H!ٟwmiqۖm5vwfn:hs챉%E}JX]S2V`R8f𗖍#S|F7:l;8K}QdY_`z,RM7u2@)0 6+̫:HbT"kqd\͋\i܆uL0Ry$Φmov^U [ ޜ[Ɖ@0t,m5eu#vI7LBE&y7yҞKS AAOAԄ$}}m#\Ybل1$un\wΐᐅ@xu)Uf}tڢ_ kLT^Į evʮ;fKV@E 昑Pi7T {+Eu+< 7Pim}`gUgŵ@!],iؖIve@=ő!% wfӻ8[,IBulvչXORH"Ux(<*69,}nޡ,S5+yϮy0zr\AӇ.] էև#s؈G/FM깪[l8n=]uU.6ړݣ̶7]G~fjA++'cMN@.v;!*MĤ)jߔ֖F'HȕZ4|p<h8ԡ,ut=gݥZ~H Hl =ܵÑBPH+Ee79*{ߑLot< 66jeZӬbQeg4ǟVw9z d3Š@2t_ӔdAd(xF=|x1Cw9*=}'Ot6Miaռ.'#[E, Ȫ}0a.ăHTRZQMhTк "]ȣ>4D<ʆ]}Tb$j8MĪ1gBzb\g_A߻}]HQݾKIV 5FZ̨R۷gKlR6SVŹ8P(cĒԬiE;@CQkX;~Xj_[Eʶ-qmTo;W _24<]|'LsǻEꝘBө7sds`ԫ/6'z5q0"5U5[X~!!%+}=k7GKq mJ {,`>q}޵ŜA|jؖmĮN I#őuoG4]ZjTFY(Szb$IKXُRQ];FImJs^3b=&ˉ&SLo-NL*2R&SiFhdA0/x~y.To({+# UYucA%xC&A~wcw(C#łPɹR\vǶvB~D=l[ʝ/32lp3Lyķ$#=o1*Ydjn6%\.U`5[Tmq1ܝ Roܪ3ZP?~έǚ U[AK,\C`h0ZT=DЈ,DEۤ3/;ҫԚv$ j ̨335ҙ\uvQR r[f,()4)[NWu0zI]$eJΫBC84ScXM( m!ᅮ I]ŻM/;NuS9˸ _̻D+7ӈ՝^G:' ڥTQ5^;"t<]F3t[7Xp 2U)S}dM^7|.IeO 6Yw|I|hE H4%eTy\ 3+}P 3j ʘׁ֧ZR͈Th[<3.y(͸ڮ={j0 ٳRW@ l9^1KDk^fJQ v=)1N?.gku*zB4;ۅ+yQ)p4tSvڨ\TƜ69}dw,4{u85߲7 hJE*_yn^^WS]TXc~S\_, 'rz!Pc-vtNC: +H.~dF)|hxKF،GLF&Ae6|5h.ˠFOL:m8xC{to'w%-P A\͕C4W>?5bqķ7IFNWHX_ֈ v1̧H}o< N.G Q9f8wsHc>i_$M-64!wyۜD;ABs$]MiGmB*!n xI#'96$DR+V=ӝ'b=uuv5\/p?+aҮq;em}9agcV{)k듒eCk:yl&NHncXwi/ saru,F+CP.c{kwD58ه3`-|w|PL:w'ʩ%B,05&X'@SlY,h,_vp?Ҹ?zGK@>G.ǂ0n%\&c`+aFiPـ0cDxC[Nc)о{-<'S @i|1o[11ij4Gq毰j VR6jz}s@[XD$R?/{M*$ j2I6j}yl#q%*$G[,2rA|Τ$&.J۫ך79~TuhټoK LoSf1 nq\8.b(Aҗb}[u:`of;c!7$xB3o|pȏ_a뭎t=S=  hGCD8 (@ iOߟ lG2P`w˜JӳIA>pn"#.*.'(މOzQb€Wl.<rdsaKE GncӅRDnMkn\˂pRDz49 cں1$M6a]lKΕRMr8Iײ4RJblCKϡ*p(;pZ4tH'uUu׷"Zi@H蚚Y:YhW͈#B1!CD4pB?p=x\,z2kxAqTX2[}Rݝ]$q͆&d#ՑK%"X ο贓7foOɾb]IA O[vaO$f$>Z>w|)G?LJ-[e˙WY9l_?v!z|phޅGVvSKJ{6ƺ75rXm3pA WX;֗R&n8݄WLC5!Mހ.hFSz.uVo-*>_Ke%'T<zNCdYXnYozd7 /PK vs1)af~BtX2ukc]9PHOns oI4)y d3g9BgB-_L@WJv5i%l^k&z}!iM&_zU~/:*8ց UZ]xr!J_+$M '_}YLܶ['J⓭T%k,bk[9x=}"Y_!IoUw-z 8hZmխ< )>XEI6;a)7*aRL!*2:#oLp`C ŝ0uZJ(yP oeSh`Ј<̶;(8 ^yy6̀ nh&3PeZzіٙ/,ІLdcyqoI=~فLR#F'b.V1lP臗F=|%}k z)u&p#msc2;XVΪ\Js>;@$y<(M1]6K{/3ߖ62Q3iM21D[,֍DG[Y-s,o0pj6 fkjJ~Y'B߽vMI!wGr)g2٣i5،RPO O :p:sr"_;ExNe-C*4  8W`ڌWm#|Q,lts> xv>4P>֠}7}=z:3 >b6:IkӫǸ0{~Yk}~}G?|M+Ѫr5--|I{U^ܣ5e! ƵI!িPIB& D,Iɯ:c( EBMU`:~k9.Ƿ_PF($`ZQ*Tx(eM ܸJ wCO/9~ma!g柒KlQ"(blJ" w`o/d,&~r%6~nʻpՑ[ c6gd{^:מ3;7 GAYņ_`a7+ɜd㮘WQP\@=pr8aCJY4 |A!Q)4%b7PQ-!p_R\75uuv%VWi[?/t wC7[cj)ZE:@2> Av%\<2TQ5#П3DlEOuV,X h]Ra=6<ǃD{i8eاOR;VAFF/7' N`r;P8jw]_Rƙ ¨KB7A!i}X) \0;sn6)a3>zԫ4 kԬ}\qF]AsJѪD}o{O}h$b6{(*=;^NLog4qu)5aih2y16aiۧ$vj{Ƃjrtk~.uM\r7B@U@it͖d֎ČPM81W+R?}@Et ]f}r%&Hg°=\/ĹPȅk'|v1KBHlP䦺^wEC>5kuh_-˪/2u$Bn^ƚf*H8vzlW?H ,@?#a9󰾺CUw@[K"P*9BޑUqc>W.ʵ`]M69Acΐs*5h)-6!0㋗V˰ǒαʎe_ 9BX9_ߎmr\,y[6H> 9%m!3V6 zlbN-Q"bɧZ>,OuN[hHϬzb 1ʙ,2r\7zTi.-wZBʴ+"1klLW C3qUkڮiAk`lpV:]3TFyKXAlN]E@Pd_Fnߒa5zhdA$cSWFk 1W2g>?厣N=%秋84>KP蝋}N&̃=efNb:%r nsɗTY:lx$L4W=WSM4O'UBFp:FT48[ c,]F)2,u2;#'B#d>Mhp+Wy^1]@h|7ӳui*%%VJZCYV͑iD_L!kr$]sF}\xWz1jYČ elYݱ]7RL /-!XC婢Ac^zCARBϖo Jk./ Pm(deV:Rn:]59TV k'_'-z0gπD,|4d>J3$0j@wA"0^ř<0T=7eUkQx+ s '߲_YFE[P1`խo@~RqG>N#=h;LO|cJ{,u^ef'%Cתwc|nD|0~ȯ-܌.PěFo\\A7n3cD]=?tL.ԫJ:kO~ ^)+aK{Ƚ oZÉ[&=p/S9 klHWi!>CZwn$Sٽ.([NI NUKQ,w)RYX6ϔz^0ukth *jL_nB!6L~JMaVԴ^J=u!B@TAIPxw?3Q7LUvS4ES 0j*U*+M wb'?'kRk=KqfnmP;W6iHť]$Er=,<]ǿF-;NwԐF. f>H k_{NV*J.!A8[J|> ;LިBfT|~}v| *>Hde].S.g+SHԫ/ț}GEʈͣғE-ܫ6j!# ښw:f+OM苲X\Ow̾JֶӍ_Z~ "(f9Cnbr"Z,4Wzx`A6{4c<^c-W0H^ KFA;"gғDBp Tfc.Πߢ˟}hN'{rTqiG 51eYѷO⣭~փNwm5{6"29rv39z#B9 2d*hǫ +v7U'QJMwqOyg_51B`5RT֠|38v 9#D`>+tB,9Ƙ QdrAƸ:U\*&i8E b'"y|-WU+S-f"r2b̥kTֆ6}[>H):zWEcw/Ih}]GJ_Hs}}K1 _X/rmv)uu7&_ce0zT -MkFPX,&~ Z')|ܰD|DVIx^'&R7F'|Zf %4=ůe-\QHH3"!yG>xO&jLbHetۗ*{+ 8FTe7q81Gm#j$S Jsdb@-\3g> kXd ` x-N:B7kWa^& [㢝fڂɝ.0˂u1BjWOnagurn7Wp S'j{̊wVfcc*I= ~Yt7fڤL&.m=7FGCyn?ۥz ^N Bm^@M t+mT&p졬$~C =e4Ys ?}uȸ^(cV˔}('tn !P+PNb:P|_ȃ!縌GA_sυ0ÄwIs!oVb]>Ff1ٳBSZdkb.|< r k/0&T~+ n9XY*SCNjK}r\RHMpuF0 =I؋ƚ9ʹx+3 k`oq:eEk}^bޡpE#Ñ& QF?I(lȑLM=dvwVՖKύR|JYP w1.ȯy% 0qAKVsZJ iubtC@h/"gi'pC5/>,ݦ0 lж]ۤ<8(^3Pw!]!re&0`>0 m }8 ;hHA͂tNbr>5_+l`LZ7*<܁!f$J"E8#d1i;G蚳{߇!tb6֪W!MYt=q,`y2r9Z8w~&V +V=O~mM' CBeϕ\AH3^k%/<|7_Օ^!tܴBL^'$G$ͦ,pd:qoH}`"8}}B$-'N-IMV¬Њχ9{ZE ʭΨI 7I:@br @UЈHc*v,#3ܐu7ˁTC%0>hX١8B"%85t jWaE TVS|Ru_+st%t8{0xM&%E[gz! wRwt-R*"OQ{A@R p [3(H bJ#MPԣM LȈe Lo+ܿgYzɝFKn6az ]8NüEXuhS}:3$Xi=bTtqKsnbn?jYqY+oꢤaYPkrVrIG=*J"EG0cmm]YoiEHa+n۩;VjYn=ZaEX\ yCDT *xf#R}Os8\`3]#eUykePPO,֤ #C4a&⼳u  oa7-B ~=oy?as];ZZhPŚh0Tpc) qRy_U"uYPC[ %#0K)[*,kP[a(bHҳ^BЄvOO|HÃEAn@&NMY ԟ:(p3a:0s-·&3JY~lP֩^P^2-=5A!'<hT,bQНќ_xy a'HbڮO꾉i: y)W7F8Vӭ\tΎTh<v,QK.DGqx7bcbg*R84CL1qO+ֱ!ׯon[]%+9ѵEm sim)T/xTr4XdHj[ 9΂ܔq?j\-,'{%PL@ &o\)f+cmi[1f4K{[xiнѧ C ]}[ wQ_eq(et"#jl6 o5NвݧsEj4 .:SHYq̧֧X7t#G(`=]* $EuQ7Ft Jg:?oWAJ|$1$ĪWM+9 egE[U2%1~k(vc6Ux?;.zXgb4Cg>9w#`;ʼnTkcN5~!,:uWvWڀ~L);w+U&ѩ &K9{/'ɈꯝDZ{pc\|dT1Ĥ& {cͬK8XaL ̿68D113Ñ] *M;\SO0O(Q+v %ޤEàHH1[H#r`)2.,B'~_- 6VF!/;ɷA^197O'knHi.<1C}<=ȡAh&٤-$eGWWlpwsL2p$u]Pw!1HǸc|m__&gg~k͈Զ+L`g-!8l g D;öm pDnACcHB=N_ǵ?N=Kהjw9j@']`Ҿ)>}VXCzMWĪBf>n%RՅ^v #kM:ktDS=cV<t~k}Uڳ d'V>$SOζ#aɆqNjnq̠{Hsl 276{.Wlo8s#r!_H\JYI8='o.kzmjXkX%~8TD,?9PT p68Ywܚ8^{ESâX-/{ AD-#^~ȼptf, @ b#[TW.C;Sޏo?o Ďb[hDV1^/YYo3u0r-HlE,=0W],!@k(=%{~Qȯz^߼{es, W ʵtOWdeQMUw AtBwFgÆU) )(OxQ3@HOOicA$9Ao/3z>e<[m\fTsyI_X//%ѫ5_B6w\7LXA[q%.< ȽخwS`PJo||1ᆞY poʾR4a.>=d^~R*E_"E¥`$NFr`=Gwnd3HOtԛm@ܣ@ 79/Nƈײ:'_tZt y&j+=_DJ!'~%W4L̄^{n7E&s8no̽/ҳy]y7F]Eu 5SȤىPV)HAO+O̤o0<~fI&D^G!KR 6?%ojI<ܧ)#* .Cb9[f^bwROd0jsKImfߺ'E$|X;&pF,oJ3*~L.gd_t:Vb<ln u׀.矒{0\R o5kk:rAi1 g l^\՟^4yݝ\3ɏo3`.K:GZC9Qkw=Z=R+>MIK1 !z0$Lr-*\mYnlb4xF~>c8M+:u8@-FQX <\ r[v|e AEXg1 Sk vc^@ 9XvճԃIXx30c[yaAx41RmGs,-. SCه֢Z`-Os@.侷%PUGy(6}w/X!0{_1BMe!}WE\+z[R*̈Gȉ榈ha@M0JdgE0Tymn7EokBY}_ͯ'R8 DOS~OJ2?gQ{GE1Z >%y| Ѕ2Q'A|,Dc h9:ISoǔʥV8 nmz1p-!#T(T]}w4"&7Itq0j$#Hbi?\RuՈ<] >max0X,*3۹Stؤ@A8껙¡&[>Na'X]{(L\P3V*ʌufO>dRp`k K+W'y A^3TN5Bk.̙Hbd7ӀqᢔiH|+-DT0lrNӥѲάE WP3$ F3nuz'>!Th [9ɡ, <7T/!W ۜ-Y k6$Se :cۧ5o}^ WCCgvqٕaE} خ'kg]7B0 /%uGHFZNtb=3S0$WxEfaAf))ɞa A_YK:8MAzv5PK!/7>_teGթ>eTh ,u#G޾tm TZ3'h]j6yja]>Ud󄊏XZ, 7;F9U%Em ]ywA7F~! ԛYk/TkjoyВ6b/];A#;UT PW7pMQґi!0|OR %<`SХIOWZmGS m'~:rv8d@:/*g(s D n!')rjRͻE<סyv/uK?#Xփu">(]su䘛UvS Zhjs"X=2krJsxoN6X )\F_nM(DH꾨x]`z[sUg,{iq(7hIzH%. ~?蠽E.Rb^(GZF`Rq½W-e3ڑzu4aح GMXr1f>"~%詼7'As'Q|?,J[(D v/o*=b&luY lzW.:qwQQYeNuJd )eWǨ3 U fIKtG%jJfs(,Itr80QLcL47ԅCqE.TPtD!Y!ҋ g |ۢ?AHedž-RK.mKyK3 i(䝯 ָ'ՊiUwC`ȇ6eK,Ha.L*k_\ʰʷSd%lxYLiV[v>A}YBxC8c^.6inok읬ͤh_U|l򈔖_-!ٕ'#m\1vYC18$ I, AKC/]Wu0\3 ({FVJݠxR*j<Ӳ@=Wt{n)sz"ҚIx ֋e4Wj67htg |ߩֈGI+OX–]&ƍ G:`nU>}وVa}B/I ? r5S/baXP(L:A79h·xq 8w5lֺ }xqetVWϬyMkXtج?X.~clSA._Ğ0DA}9lr}rcGbJN-#=U ft=5E6X'Nw~{y+Ow] *Z ecކ*=h,3A?-dN}&)_;L8z8?,$v\$!YK{&Y˩RRt3l}6xJg1rfryAZѱEXfKbf'=]WqBboPӈmg/u,!fh)Tӟ|D}۞5NSl4ޮ@55>vC\h62gX;P?}]b:DƆ+rSȱM̍^le\i=V"j}o鵝?gFv꟭|yey̎㠦w@4f*|O9)H{2)b ӯ>_SFo1dX l[W땾Z+ +de0dcH/@J,‡ӛI.u6+tX82ϩ@`hT{v~]{O {\Mm^c hJmϏvpn0v)4NŗhCӋTܭyOop*C:JY[C,fKF`:w64 ckaIJF'@66Ǹj"|oSk76WObOq3 EKACA8^^~?h5pMHymFl}_3oMץUE˾Ԡ}_RY&ѱfƪf 4߷aP/-\W YQ~1_Yyw$yT-;xPe$Ñe1-%p$h%n35𣄥ގ,x $;Z(E@NP P!r+K߹nYvtdMh޹e1ZB&qM 5<&֒ʅ Sf2H1>l31yN>e5Ö K6_َ9pZb=][7f_f" Ӵ1O-YXƤTuVj}gfMja9 81*+Y}0TlГQx 0_=D!u#XS(L`W?l=z} D-I+JafM FFOߗ8ыqHR^{Gp Rbధ1c Q&GTB m` XR8c!ca¼ȥ4x(3,-oJ׿+G5vt`&Yjy&4HNiL=/פgn0G.ja14W#wZg~R'|j`Bk*/]DSE<--TY*V8$I\mxѨ5e`?R=h[T]? V@1xkV/^ϯo,4'H) %3NR7\_0WCjj805dgO!j. 2q-UqblKD"SkaaMtRPCdZg;dWB/o|Lf5PF[ O P{ʚ> jWI>Dz$ts,yYo* Q(cYh:>'a}C+C\&E,E+5H⢈gm]\8} S#vсD!:(d扚~v߱c - f!7ґ}D[cte7+d[תaeċacHrmIɮh`W݅$&j؏)(Ҷp].y2@ *=իvd3=!Ƀ6:?-WDi[))TwouƩpSR %*O=N痫4ZT?D*`+Tܝ@e9go@+Bm[rőrFR8҂0rS =sDhI1S(1TQgc nI){B`NSѩ8C>oQh]̈16N\pgax b.#UqX>a ؁,|ctOHieP.,#,q2R~2f0o@ ,eT9Օ #(FJ w#p{2ǡ;]I(ܘz ĝ@>t#r5fJ D Fv.)x%]76ocb;8Jz-h[:K3P#e$44UVqouCc!zO>tڵȰ L3U2.lՠ!'[@LV4ᒕbi;-X*– 0V tFq^Z{lFk@9i-H+B'\FiKΖeԮ{@|6K(@u[K2FWvCUpjT͎6I.O[AG35j$c|vZy5bihO}C%C:uAO3Nid!b6i\PW%IV tSIW*cl_) ;k>/Y\ -r(6֬spTOB'D2n=-93ibXH^%r%s?QG~MhF'푚.}FPߞd:v;5ka{DEC2Y zY .IƩ010\bexxS] 2eM.-]U~mYq6B󴄇C-RM$Hk) yQ~w)Z9m$Y-? RUt#C%ޢSf鬀($.k7o.R"D# ?Q]dCِMeUʋ~6,ݦRӵ,*k6&_^Εu{aHRͨ5C"Kz̪ c(3Uyb\>j:X>cpۨ$zX;3zd$qv:sȓ:O2*垴FBt Yr6wmA8FUWxJ)(MGTZ#na@"q4Rۖ#Q^) 4l3+VmgWuWtw|kqD[\WP Qsģ96T%U)Qqi @<#*Y@y66~ٺCh黑67hFr؞Kz5 SI'ȲUռ'PV?_PEjbR+7r1[c 2'Ew  ;q;ȌbV#}ތH}B*V3m.ce'߀gԿ$"e8FɲxZ[&2?1}*Z9.XQpJsG$ ac$O!v0@M /ӭ8⪣DPl܈їb,"|@^)vI5^J_+ mGjmzި\w& %0rjD͏cYͼ~#8W \7l; "NWHfc\4f!W] rv;E0W`E1Ѭ]&p+RC`ʹ!.Ds־1"7\OjAJ8 6y |ˋ*&b ljo霢("{tdG-}@jFaW EIs Wc%=K9olҾ=1ved0/& }1:$1`RLѠwiK} Mc0t=)%~`!pvBWAP 5Y9Ǹu!"\;)32枂AL!?3UaÛ;ou"L[$L35Sţv/M%>]esP*7(%!;V{8Kv 3]51>o&Md}"6 {vwN6ǟ;5jeՌXPrV#`31hAL LbKa Ҁ$ДVX8/8iW{jF!UߦzV.{A R$}gT^yZ \;wce<rX.VN`/0JCb= ?]Vϕ&q}fWD_ 0hQ 9,M'5Wm;Os]u~L' T(|UUQD0P&Wk7* X"t v2X<1A|MFc}E"rCԢU/Ѱ%eMe w8c% P9,8(J%o\qwfle y^%Z7]Cye"Pc+e L bc@: sa<u)I;^|ǗVeΚR״ᗟY?쏜D9tT0q:"aY^%F B3T(B*^x9ݛ -i'<~}~Ltq))$2kΠA-p!賙-2>V[cwk61 [b ϸ.*ReϾmC ?PG%_ ^з4hLe̥O/s3e$o(ȹj ~b2GUm @J\)ҚDi$!].ű:,mWׇ}=]K; vsz(4/#q#O%6iKᳬKpP?U :D CLi9I;fp.WTE{MwPrm}a{tH =Һ:4,Xv*%] -I~4pZ_nQ0~p}[H'=V*ٙ$x>ZB 54|;"qE7?\0$[NTCl8^It/qNeJiEıUƤpOsCE1ﵹ+ιdDK:wB; $dwobR&we "hlzC6[uV 0Y-h f8ņ(oBK24y5@w̢ϹjC6OUoz%[v!AXK/b. |cAlVbh-vO*$SK}N*G~'2^bD0O#F+ ApnC@sSL%CbfVk`ұ~)lKZǶhQa%0i3symPsolUDV$&Yu>Yt›H}c2 \{EY Lr(b ¥Ӄn[6@ׂP|E$(sLPZ=T:q,=O/3FWsSl;g>ݰ E*)0;oW9ڻiΐTd%jL\GUcdVF IO@$v(PL? VP TV *J:^5Q#4l'/cMZ຿o"!-N?Ce6)OUn_X%pHe|BBL•*eHтDJ5Od΄wCp7 @>7bj^p]0[ngA߳9QU("3l4AħQi e O';o{R՞.Z0n:ݗyUd{!c-Q~b:z kFRȨ*=l]֍ןԪ:( S3S]{%5:qPq(3X` 8fU(rZkgi"%XV sqqQ=]7!&Xݪ fo4uyo0Iu6Djn[E> mF^"5GBy9A fIla>*c'C ٌ)AzYKM7`y SJxibq/؟+L5L3nK<׀zyQ_h^fO(v4޳mHufsQ³ ~3vBk5bcjNwBs_P,)籉jp'^ʓytۣ/ Dzd^뮩ͦoo ߎE z>Ϩn20{!|BǐfYkhIJA8jn˱_juVWFIԿf~D&)+1UlY 3{Pd^ȒK`6@h9d1ƥuP5`\{0A>C.P!*8Q9$aŜUkI> 㶼A̼clPk3K:Y*Rэ[0a q5wVu4f?7g؃vX_Im`_mqPʩ3k\n/dufwcB\Ex)nJEor.vsRsld-^{ܠ:-W)F&#P;̃zN'3Gǔ,4@7 -8G)\ŕ⸚;,Mhur@k#> OC@@: N G;k A$ȡ<;=ݎG N[ޤj=1|rT#0jѲ74I@zύb֥NJ~Os[rzD'; vudJ_*m )F}?ښek#=s6k)t7H@;Pw+SW !L3oQَc]gz Җ)Gbۉb#Li4ݬ-Y_X諈NMzY٪>o"sk. 0yAee<)ۈYtW6~UԔ$G2٣Wml4eve$eϷY*h>N{t`wr-IXZbl]{/ݱɒ]k5Z-[QSP 7Oo(FK jsRGX$8'gFkpR,:&.PR[R&= ] #Ʋ>pD 5qqe=0BL4'2rUBN$e( S+ 鱷;!4 cx~ hh$nP' uuY'S)Yx]ь4'#&oBaAf!Ua>@gbdlZ0%Mof ܡ..aJaS(d&DQ N]Ý!Z`[c.Xy6jEVޣ}۩lJye%w/n 1vhknG+-UQq! "/@>yP3S{t)%:h¢vkGa7Q#h9_d>Z:ih;B]k:6d &<`H ʪ h0BO/ñ۬[6c㊊|D_}e(%-9ݶe!Oa̜;NՋPI˭絺Uyl#;ηۣR5T4;KШb{_)hLN&t+2çN8 DznS;q"P~[5#le]/yXՈ: z X"%jZ cj+g؁N3B/jl9+vr#rjrSG䮔IPל";C&( ϧ 0 X n9ˌV+_:FLD'J5O";_ﰭo'B(e p_ͨ[j^}) aH`WXP?HLL/y$Gy~x/cwIg`p*# (_E!FE>S˭UV(yY.6ul8 JrG|i*-ŚDj̠Ȟ۟| nή OZuAdv(aɆ"}Q[ü{R1뱁NT/)k7v]<£Sy?+fuUb8OܐzIlTpB?3gYBpV[̚W/^>/ {#Z7q!B9D.}j;ŀU ~FVpf`|싡My0_ pPM Q|s9dNj8!"Rwn !||菍}t9 fqV|(KmDntI Gtjt@OT gnq.smI c}9#4љڔ*~X:NL;qcY ?< DI]L[f4ln6vXLOdV^m5_bN[b6f_콣2; \ez晆T0Yݣ& !b2 Fbht{EPP{)N NVI&`355+kLв< ;~YM1/w;U:kr'N@  0ġA10ީ桎 UUm Pdy?.'*G<;+Y$GjڢnmL%Vj+y,ݓX4참-Qkםbh+au8!V<笫A;JtE# )\ov[~,Ϝ0Zؖ`TUñkVq:E$=n/%׏OzY~ N]ImLf29$Q\sxOFYK5ݹrGQ]1Kn} CGssnC0CĹ+r5zE_ZhAkj;2$'Ukw(&8#%H>^WEڝ% P0W>O,JdPJj8ҠjcnmFtrk!hx,z;IhiCH6]3k)\?>l`} Sn &~4"fiqPEXA>+9B!P4t++0RT]Qa ltq<рho(/!&s@=ܑ (Dq$ fF:h->+l\FZGviSzu9-`:&LLI"̩Y&u AiK nͰ>PLd\.17ytg4x4MѨæE 8=Gh\YWq)1w6&xI 26ũ$HF#I| >8k#5ror2HvS`sEl]J69zCc§%>e Ȟ8 ZN]W^Klj8tH@<]}5 F/1P)>J!zNZf mA+iʞXҐ X˻o؝og]"[AɎbl #K@j-2 _u00pa7쁇 ~/y d\#⮸Mm g2BSpyUi'J〗TXѦRm G;'DꀏOnOx$)zm~¸9Hv` q DK@o<\C^ce4hio|"Yg|ީ\_6cC;-\R?Pկ>d~V-0ue£Usu^)teD][dYC%W䁖C/dbBP?єg=M[eKW>7'q?o]f7@Ff=jozĒ5Y5֝jMnkl3n:SDd`5 6JNNħ0bІ!!8GOSO+iW!z 4bm\zS<ƅTտrlkDE!s_S =%sˡ)HhB0dJPQhtl\w=#eH_Qy@ m\Y Bn!Rjq:J@wPG264qt08NqZ=d[.e7x2hѡZ0_O$Z޲ʠKua.[ ]qʌ&.0,LTf-rI li X`~V8CϏxdUA`⺘k|>o9L XGR6EZ(B%G|/]r@8IZcXE0թr(eTY74J[ .\oENd@?ۧ3i6F|M+b%;2ʶڗF&d Z!`DTFB#:N^.#{d 6w- v[z^,6[:SWPկ`²dN0 N8e$Ý )+gt$mީHKq"DJPߝ,|4m7Wx9 44aF @q~>Q%, ;&?$jVڊJS!.+'2O]iY'vr<_-i}0̕%PZzӝB}EƘFC{sn)(Wz&>N=݈EteGBr;(?B3C t}k2rGO"{*K6Q0d~ ƚAh3bm ?&Sr\*x1yMRm݆zg8>"E /0-gƀp?%N׮Ĺ:)Ȭ iT7+;1BFwSlhqM\ 'Ş0-J[yK@WN:M?lϜ|OumD޼9#7{WL$x{)e“SێЪi+vb."'_**0Ha'|^yVBM15bUDEQԘ9L/%SvU-{HxV~ O2<*dK:%d)9 ҏozrdxWU3 f><>EyƳ<CSx`G`MM6%#] Zzx/ΟO$w+ |u?(ZíJ!oWht6n0XvNaf4!1BOVq+0 \ [^d.t(wdڠVPkb݂ ^jc |]J(/wPX EA}\ S xHH:{!d bCoEWN鉾p #{Cz$";Um//ך[$c&dd2bj!@zDnέI+^rf1Vd О\=] wBh~|9N8(~"萕ݏ/X0LūVs'%6~bݢm {7$m ۷FazN2Vg4^U1!NLWs$Œ6g$ތQUTuGrc:`As{]?ED20q"+Ō- ~.Ъ%ƦGC{O&4ypo`9 fi )_ԏ 0IfߙEƅ̓ɗymerYO CȤ"@31$oKC2/3HkrW-Cd ^w|!K5Mhp+Ȧ"}g (BeS Cpqsݱ;WڏW@zNS?.:Fwm^2ןWݖ!^8(Ot[xQ' 5>&%HG\WIZ̡ P*1TMQƕv8 +e8Hq4ГV qd/?Ha=N y3J<h^YY4yiϔR[=%ﮦd|/he.Έ]<5|$ 6MƧ n3 Ҩ"G͝F5oH1_VНZLςEp!%rw+ig"/!ߙY,=%!pyN#c1ۇLĆiМwVHx #aBdZoT]]$Մ^sRWAdS:xI\(~\/~]3棜Fwk#rW ~1HdP %be۞9L+(/h,0msZcY_ !0*}P ;y#K13 z=5`!|. w H\jy8.QH=r1O8YhODzy! mDs5s׃Bd4.I9 =( -p"MD[ixX}REEl(bpx0n gG靶3_;9 /_B|ĒBNs:qs!ڳ͆(~ksI+H{%FH.N:$ @8w@/_ۜ,˹Պ,oCz]{Xtڴ97VuIJDKZ+Z{F2k}oˤnc78%) u~-Jrxk3~Q+L|]{8C"@H3-k?5GB"2$%R,aHLN9Y. u!r=ÐKx?p u{]n!(OvW"O`i&126[Vf)S\wƐLǪ7ھ-XtGM oM E%(%wD+7d:­Tpd=*y6<ze]dVm ZUWX"xϘSc M)g쨁 =l+)Wѿ .eg?E`~.\jd;r~Sq36]k&V-PS !g(?5iE? >&ݹ#TpٜE?]׆1MmV,#`1;gcDgJmOyX:a?Jac0LCyOtXs×4l)pERQڤhAeq\s#W2sP9uxlYZc兑dyp:fZlFLzL0s lɜ!:ܟwMè&WU2#cmW&ݫwZaup.f]=_j^評ALiz:)?2dvFIssOܙ|E g粮|q<9M ӆN*ˢX9m[_vP Nב"r<_->2 P8t\ H@8M9Vz e%0鵁G3H~@e (&ި!_w`pa:ɝD};bˏ! 6^%4C;R V JL#V=#Of'iA&fOX ɤ>H3'kM8xza9-)5`?p0,%[ y4v8l%uEñ|TN 鎲V d]K\u(.DnygH]9YɲX=n3rI/W=>$ORt/Yo:sb~v6\&jbnQb /z@MMEBPkPDc}W5Տ3ٜ!lH3XY/+- ~y17 0!L07~hJaI?]|j%m0.>>$.e*N1ڣhR.4fqJaeq` RRc"iEOyG%:yq$jgo [-y$ ٬tY`5NyHk1uU`.u"e2Bmz9j!mh9W i'#,—!_tbw*5F :I=xb+%$Ώ󛼂h#Ȁk˚^0^}0|Ṏ!}8@*L@P1F'y߄K-بV_<,iw4hb@6}*|(7gwrtno6T Q!>)4e2uֻ1c?8vjƿ`JuT ׊J bMKu `iߕB#J|:.xI|Uz(s C)(c(vۼd6쌌;,jo70=؜EBRw4)"6ANIli2I8.<7qc=ڔ&oM&=y 4{~:p H Ų?q2i\6C-ijˠUd)h_U,=&q 82y5LR(7},BOT! f wD2wX/p\w Srs[`XP*(i!(%$,z:rE%u?`_Mfw񏆭Kr@Jژ;+yTj!] t??l41,(2qMF`͛RhqXH,.@sYfvr;ֆz}?b|H'!ӔVJ" + 'D"@kvA?I͝Dhttj ʻ{mUwQQ՛iD2 dcu>!,!vLJL^l(l?,i3AVWv`\hk`t5n+kE} Ӡ0DR6@~FF)=8*VMNg6{lѦ %^JU*|(oFr.p-U(,=Co8 p'Z:KGЇ%//Iu3㞱ӰHh{6'qYw"$W7ۛSNCstB5C3!%K/f04 @QHp(OApNѷ9ΔJyx".Z>f^~Mݳz\caNb˝ԡdz>+>Ӝn8|~w>pZR&,Of3w]ÇuQ䬽S񨥿+wEW lhhneҢOG(o-;yJf$<MYp[" ȚQJ$ aS\π!{RJhmɱh1c #8yp3:aaa)B1dmPnWK!!';dշ.3R]I'ܔmjWYzP >XijU￙y6kSAa!'2 8]V^*-1)*bC(C8.Tpj&x)3ƮD}2Q:z&`P+ݑvM\~e]=EpIKD?Owo6,ZBIR+81{ҡbQ_h84cH1HƍC9Ej1NMjyV|*Μc s#J8EEF\KpLz8E%gn$C2&&,7uN"wT,鷟G1;Jdi2rSXڬ}7׵%^'"P[+zdO-.*+}R}$4g:FdWR4iTв\h9Q_rAeNji|;FX-Pn2sy_)nvŇ*MRޠugz6O=4BSelIUk0JIK'3U Pi=~6%h^3m &ѽn56 ;EOaO95qY 9'>-mL!KCX'1u~lD90D-YǖŠQJn- o X Rdβ̭ulkO9 R[,QzS@X۷CZS٠46NpA0ibĕ ɝz.CFx2JF'  ;6/ VOL(!91%zh#kS"yKRO;s8 `yuors]cM`4Z_xj>9*"/8rFfoÍ-wZd z7лGs|/^Wi(Ȫn"vV={Sq~Z/.سD0G9Y̌͌mHҳ bc>͡Md&JnAU}ۊN\_T3ٶzq~|ʯ9pώ]rؤm843w{TLu?`Œ^OP`s쮦dwVr|^< bBפT*ynCU0$ }lqMT>%*gП+$l 0`uhið0.|T侜H^Z3(d/S=?le@n" ~e G`!!)POE{BxGmO%&n" jb>֛ݩ.|d?qI 0ϜlKdv!6'{nD^Hcث] GiyaX1I#X}Ζ=-iٱy$\6ZDH Yܨ.$? ]ѽyBchBd0A08#9c"sF#Gc;F49:TVWƩVo QR7Kp'B– */aL11T G.Sfx𦎿H_Dz\(7>mlو\yC gԻ]fM:fg̜򱻃x4lU6\R>< @:"bd3z~ffUsK5Y=@g"T -ځg 18S$Z)i%[oGtv OCE(H"@ 8_aO[h#S%qTӑȲFl~ľJ %җMs̙<}%m gDwfgURHȚ Mȑ||ʓeE/p#)k0M]8cxPhIce ]URS,%VUါ.\-ᥚ(.Q̇Xa1gfWٯནf=9LYA)_?b|=^L[zi6t0pk?xčNL3r &z#'I=t2]sQ!As,_Bܞ~}LhnuUu%5{wj}pd[&i< yl%R+YGUaq.fJK؁+L7`t?ERwq:0ao4^Mױr d(3lQ҈n^9 <Ip,D4k8=[p T!n_b&RvxGRaI-p;t+tds8y0r=?dWM>o><"{Qwd"J32ۤP!=L=ScpPAޫVcI1o?լIfr|4*w<Z^$JYO[>ursГ_We~<\2@}z/,,Vd@ʿ6%P"0U8}8rڴiV' @I/@:J">~,G]E]. UeRj zcT[V>8} nuT| rD~K3s S9J̜Rv գyL`)c8 CUmeqQEڬT4䡕r'.~TxC6̤kv7~;*ہ$81A1Sɪ@ !*Su4tqmFzG"tQ#eS;)y2_R#1R=>W$t6eFlhakMџ@LjK_爚 5x{j}p+KsOy(-E,c kO|RrxYvD e/Rs U ZFeJO$Q$= u{ >z'9=78JZ=|I,%'AhBh$ K]rPaobn"<4aws\b* .k*Dj~$9}nQ}TCJ0͘#z) QVmmT88VV1Da ThQza}07gg@|G&^ +=~Y;eT3 ߼KY M*}7Rރs . r.b^ivAD:UejgT?Hk!t˴(~frlw|;XbԔv2Gm Dͥur#l4H(ny_Q1ZlAOЈڮ;T<GFT hV9y"wh`Nkmsnl6;^U3Z#~Gb!i |Xxux\bےi4mq%؛*&wrL=>I^$@XOwOVggH(RL?1hc'@M)mF&:"dӳAu"JٶCʾaM?o )L}ڡ\mʑn`$pr&PiX] :0a_lvo 3(L,`382qƠۈD"?,5LW0Li4e 5$Z~r]5 z)Խ5Zc?ާ%L 6/N*@o͌U{fŜ!}yMO]_+EnI:*%go!cFڥy’|6c za Σ5bcVMtNHI'ػyC#d?= ,dW6qn{19>r`;+9G72p=)h=v-僀4im>Puq~{=[Nvy+#w1!ƿY3>8,s}.`K;c{JttP+ӗHS| K3tMn0`P60 #Rdօ|)nrvyRLP(Tr@0TR +d K2CYQpՁeT7R,d⵸a/@H8ÛarfkxzIx|@Ži%7WtGaXΞH\y(RiipAy.'p˞tzNr‡v A;<0bTרI"KKl6ww핧 1JܷM'w%H^l8ʦJhDB LI-~\Dpjd}M,*'R|ln ,tX@ӾR4-Ft]/džNrl*y$n֬$,y A(W $#ÛCj!&h!fwm:wRܹv2}kX[` (^ƈ\r ޞZ>kvCD9eWօ~0$E4:p{ኒɥեv)bhE|pO91*[?_`9! †D'bb SLS 40+Q.p)'D㑕٭eqِ>]rى_Q䇛Q)K&5(f.gN#3}>8.)FB6a&.3U}$jqzcZ7i_s0}OB^Sp)E׼@3+CrA/9K8 C!h;` ^Bͥo-%8$,~g1[6lhzi\y7?VgJ,xK֭]f}:9sbB'(( #kCN'vg^@פ#v)2k0f^]oU2~5v|?:"(yxʰ"KiO7ƹPyNCeNs!XQd^ū&*EeX8q*ʹOh7u ~s;BI kif\u+pƻy_Bdx!yL_Tt#XAzȤjE q)F =:0r j^w>3*hO|`EڎA>qKr3s6r|_tE8Qsb*;(YZ^9cJ ӥ0hP0fX]^f+dꛗ< !݂f~~3Q .nEU,TɇKZM@(yk(W|.iy8EQTɝ[Nδ{r^D9:Ѹ@ɹ4+D#^:kXO=D#+ҋThF=υMm9֧)S:f)OejhX6$–AY3 ʁ.avĬ$T H͏0YOE|l҅#%;'p2(#6oΡ` 6X> J!-7PbgnPP[V ^u͌a.&%gM)PcH44`T -7+~^NT[/AzC[6 }-' ?դ~fMgJJ @=F8V݇nO aY ՕPWf9SBOW#p3ML?,n{^o+ecKt[1@\3}?,t}sr|5PbH"~iw|n鳦{;IN] bm>iXT,vYL8E7e]~\]y"SzvթE\8|SX j$昛1"³ySo:vPdKߋ?fuqh4T\F3Mj{xYxrEѯUw z*wnbcN{V4`DhJyC1U)Pc_Y?+3Ą-r(6l$o-n6 mj!NMPVM j->e&AYN˼>tLW! ;2 ~;3< slN(^`uߟ#.*6kqvJO($Z; $*v3mLJ47Ɯm8QH;w`R0zP+cp2t=QtA+K*㗪WM1) ^;xxAASuMj4{b9% Z|cEe(dA9ařr C _ٸ_y9ݼ0\(QZpw}J:W:x7ěG|}ڜY2I!< S6BVԮl>.8 X Y5׮'7ȀN:!Lx.! G2Ye>zax)8OkBm_-׫z Y:~lp~SObe9tKC-DPrcRWv@ `UdPhwӘVb62|I˭l∘UM~4歍=E Eמf=̐4g5;dIqqHqoxm0Ts  &_QYţiկ|#ct@Fv֮[?V] aH𣹩-zdJ=ClH;^87ƥ:?/\zT8 nP,q:oOU̻&=p.{ݧv>;qiȦ+eFPxY@ϭMwYaɈw;̱S+Hf^%#vvڌ =#naT{oPf#l5#m{s \^7ܗ#1v&fK`==|@ѰsI-r5g_ښ sIMހ0Y6ڕ2ߨ#+/đ} @܏r֙]2 'rґ+ sN @Yp-\hM`LM bGYR} s4j(p++H{HMLC44ܸeA:-}Mm}hz M͚CcƳDܾBs lSb7n-oaMMA~|004 G<+VTra# o9LD B+:zw*{v~sڍzI1)A԰7=gB(UOvE gs+<44vo6u5eîKb ?6Ge/LRMyٯt$6 Tq1DV @Xq )+0>-O@F7#h!lbQ:YҔ1'he&On˲J @͛.-<]zN|?P%R2Gs+EW -90'{8hBLe{cɛ=Z5<'LtX( ;kn]nt-ӡڲkAw+RRN[%w-j~ X@U^JZ]Uk#x<wGѢ\|v] ,'6el#*hkw?ϋV:\E8 ϗ4wő 5RX@HNO4"cڈeMT9@"Y0& pL2T(e`-`[-k";@5f;_d٦ok6Ή^fAaCz8b]ⅽ,,ZtbgtԠz PWw eCTOvYR,(z7S)b@i{'LcF>jaή\}Rj^뚷$WgS.ʆ2rx9׍M zUp;xաZ)jQ Cs29j"pvk@ehhRk@%cS|`ba< xm}Pփ8YJ@1az0Ψ-FcQ(>OWnxB-\wS;(D!BKm_cP[ 6!8 ͲR`#~VT=#OitaRިeN܋ }˻AK:L-Ĝ*$,Aޖm\a ejsxCK} _c3Ȥx\xSh$Wي8Ji.a ь}?!"t=b+CpXRFLMiTܿk?GиȚ#S^g!ˈO,f]D#PM(o'm 4.~:0h?}onz_'ޜ!ٶ,z.N#`nن"dN_1kߒW\ SR]lbE㢤CEoq_%߾!w F 3oa QdOZ㬾f™w p3 KKٓ]u&._(׷#|^% ܸog9śilfOGm$wK/Q <1R}@GhomQY0H=rSR k+-60͛iSC#qPX4X Nf,dT#o]tڟ9$_C^`Pª9NOp||]((ԇG!WiK8Do6T1EaAUS%BZ1t4𒯯Ş W"m5v2*C[ǯ>aZv΂{Ѥx?F?{&mV6,:(L$IJI\F phBJاfEh-Hvjw;hʹi%Sg.;ԃ9UGf~nikBmO=*Q'tqw{)xOKD8uoX=MXp0z$=˷J +>{yԱPi:?XXP?2kU];1&F EҨbk fuyl!CvB/;}L6% aDŽVDks}YCQ$TѿܒTGu?I7L;in_?*ޑRB.3CׄH#Qj T!zQ~0t-LM.1WEz9\=dЋ+k!kREkd= ꘸/ @[%<G__3wvA[*Jme V^>ʂX,.q(YX/YM"IW#6;UcG j^l%R x>Bf(tgy[&~b\dMv#6} Զ=S_^5ϩQ >_zz0Qr^ߖlcq\ 9i>`m~fH xdI?^jgG/$c([J.F"2H4+M sfW&O'KEA^z[^#gdo%g\-QEaJl:Ǵ_1\:m?2U6尼ys%4~]򏌃P2+2c  lgsCC|#z(ڗy.oKY K࿑Z.4~h2mȡq+=US?!@>VNalI] 3$E849[%uO M0v{rԅ*]mZ݀-tЛGmsR W|:Aϳ-MΊ/fh$<0 'O^|C1~5@HtJ$SB(d`{'+' ^N˟%*GM(G,PFR"Zi 4Y"4;ٻe:|;Ӆ@Sz ^[N^:ӊw- y7)eܥ&/7} ^ jH # }QCc-I&=XꉫEcś=F1Nk[#`VԈ/6iG8<ƗeJwO2vlo=-HyX^~%d mSY `iO+[1~+'5uol7߫.I*|){Xil \kiYZ*F=@3}^Nd`98">+ `6=+B9zRMX /s 0伳D?rB~I#%g /|$tkK9o)5fw3x5->@yL#ߤ}D2^S/x8j","KGyDl/Go+{x~֮Q@6OX=,`M:gU\2FSsel>w`ϏzKŰ>V;D:H6 < G1bD;EOWb?] feR#bRf>IL̸gOwsF*gQ1-=^mWFw:dpĕa\;N.r uaSyV8I`͡%\*LԐxg3Uuq/$))is5ZYfgu\)qG@oQ0p-$^TJ$V [pc~=wϦ_(yZoV d 9vך^ʵLUUʺ-DrJИVqji'9p=n8Xb r/@~ Rrٸ (R8W5ɬ< ,`BZPs4_aEoa@Um ܶz`fkXۂK"gٽ`?uXO=/ahPvץwt"5`W2WB;Myb@7[p_m2gWB5Kxǖ[8ZŕGjv&hOgx=^&2+j1WtD vUFRϢI`͍/^^_V|?ͅ?;Aװ3v}_Dw!F(|C V͒za0*@~H ڡ'MWu#QF™v6~-_deNocWvej3Ni*.6 `.ujޱ(6Nv[M|O=h R/o(*bROGd +eV~ HF{[TŕZznA2P !p|ڋœE՛k x .9Jn`|pddaXObjj),,@sxiHB іX:LW9@]̋ \^ΗAJ_7Dl_AeĂq#@xOV- Swnw=\B{Xo3o:)vzo۟鯷C @?&_\'ؖo WxBʸX/"hK2ALqX/Ŭ߇KJ$ղ0Nݡ7E9>딈-H)+XG] 'Ls ˠ .k2cHެEFZ=pQz~nl`)_l O m$~~==F]7EH' ̷̰n;ydzq=#GH$%Skf+B"ՂL}#-pV?@y2V?@?,x͌zK@b#>b3~{TQt-ë]ra.fsgj#!R1657R=\1Bżΰ| RFenP)D]PP{~$K&95vN;v߉ /YBZJ;~/1~E͋殿FP7ņ\#R{0rŋDkcֲ *J,c FP :U)cm1 tR0>][hTqg u:+p8{`lܾ fd@n}Yl}CnVN@=j9ND{!]\A @Oq (?.vLߚWuEU6AMD5\lbi0FۏCv37T%هXRbDN{ָ0l*02~YE)EfWXTVgWGfrLU+? sO_x:T ~AFX)eXxq )qZjc[ i5T`Q,M?u NZ -O*wJ7@^k|{ dw!YQ'/Y@ q#m(Le:-[hdžHVv'3DZY`k*bNhA1+0@'\'MdMĶ*2,`tro*·v53ҘNy$QwDSʬQPc.aK瀤o[XU\cC,a(IcwronKpr/qPe9nMiE:f-G2-,Q.YaqR >4,#Д4Fun݆FR9P=LCyㅔu8엀Ӏ9WyI:ҟW+gHYG.;EfS6O&TbwY z+X3EKFu\kq] `ٮFu\dYf GJNTa'A,ezB,{8^L?f=Mw3La7jbJ};WAzo^6bJqo<K {th.&OYF!:~vw:zt CnN='$`'H~Qr|DB8ZZ h#z; J$;20: :Y#ӛc#OהW܄Ġ ʪ9EOw`,/eQբVt.s2IZ^׳3fE˞%uz9cE9 myx{λ FǕݶ 8+#\G߾+P?1PI;:XjA-韶' 1{MӰ ԧUMz΋Dq՟ N?G?t&Rqk[BKtʭ[^ $O!&Sb\٥}P!7A?Z/|THu 4#A6 _O?pZ,$EoXt5kX%=:|pxey< nZtuTVmK(Rx8|Jqs(ThrX4\g,M1;l ZԀn.T*@c\_` =<$!Z侯G{g2 0_0oLo.YDbKn<]@Y`X`I2]IVR uO"eQ6%o]{, ejD<{'U #RD/JLzuYo\jͯk2iφw?D?#x&{P MIZCBƦ9A/L>o&& 2,XH(V!p+ߧmrV.p[co"VyY'AIM!V_Wwt]aAGf#)_E+X]pRxu*+[9Ҹv1CLr/Okܝy+;.h4-[7d(CbL^jii6@#_^_UیRx,~9QL(3|d-z&l'1آ-skՏ@gv٢8Qv0DG(oc=epk"PqKGUtG|*3p4QOuVmto&B$^V86xz x SmڀߚDӜpD]lZ bZ<|Rˏ;^^s}l0}=R*d29og_ vtS ÖM 4hI!r} Δ T c-9ʱdu^\b'9l=ƩXx,KP4` EĄg"hU6IhL9J.L!w:}{Q}ٽJ$Qzk)p)NLVF${h=(͂*C2qΖDx@h!e>҃in HXhPzzܓ'>߼j4a 3ҳtYQGFBb$vf 98'؞Es=`5 aȄ2@ Txqu"sʛ]I092B4+!B2 B͍[/oHc{IOڻ֟FY5wfoΤ[Grz;~D 'G~ Fy7EwyU%`ރr<sG`"Xfyvz%DHkzNu]5ʗKNH:ŻpF'X~͢U#aC1z/Yw? џw u+ 7vG*0,;vgdl 5TBFSd梲fBP3Fpo>@7t/wN0p Ѫ޾Z4rPfoɓ6,2PK"2אb8iuxo ȼO78'5|]9*/x sAKlÄ;*F @ ]/kӞ&KD5~p(L>*[XL^( x2˳cԶ^FP\1^iDeͧ.3L֛: `ɪ~50OJ;v ㉨ԘU<ڲz_77L)&a2iU$o':S`"zuIUb>qQQcc rbpXɣIe´(#z( 5+3cRT~3~{ye(!. gs?Ep kz!Հy?Q]j>f\2}#CĢ(: q~%WrP"E'IuU.(mCTݱJׄp2Ի5O.#5.kpqQ 93YYlKzo'5[^ T"%zqLN{z#ȥTuj;nkvY7T\ 2;̓lD:оV5&aԘ ohN흞g`gx,[1{;p&މ:IRIfҟeXSk+lt#NWc M.(p[An{&`/Ȟk9زˣIkj%$s0DWҡc[ԁyk#^Q׽ZPj %L̋EDل[c!F0%z_,\ȫ ~|fv==3JCFSra KPB?5 u&+%ZFx=__iz68ނ)6|qu?ܙDJɪ15/U, r`ZԳj|+2TyazT.6Hr1"EGo /=V"7hb(ܚJYi G*rWEKOuEۤK<8LSuHF\lĨ;qtEi^Bpy8q@o>{345P *ũ0q4ⵉPŸJB {}j AZQ\fB1Y\sMh|thne^;Z&"wIǞN%/v^mǦ;mjճ>UgA$8鏄 sRO ~ y=Wp}K4b(>rYq>9Eдz1*) Y(+R>w^QXׅn/Ca\cOuۏzhؽyaqśa;+0IZ<4ԙ*~u} &<}?wbyIDX x[dڔ~x̾@s̄T[i*SX4`hJSSooE0D`T{;35x'M&aS' VT7soQ*A͙!{w۬j7#nڐEQ?kd]%Ȓzt}CnA`O$ 1/lW7t]%rox'ݵ1GO+UzKݝ̇tWY~#P DfZ_u7 ̫\LEźpĮQ?  /½(ulc- KZ2DgYk^Ulm# 48D1]#*cO{CPTj@m5 YP'F(9spNT[5TmT4#dxB 4A(1+[GUmzAВqߩo@e3Sq!+QZ~'V>!Dd0-860yztddis>pmZjS|e(PU|\BAa\Vtʂ}-rV S.82ˏ_/@RI j@w#@/Ui=ZJcc~a : X#N$bmGo;y_}8#/agn]BIRbP@48+HDw0Qw XW>!Uw&>R*hTJŁʙ9ψ\F,M:UJN<Fm (s>W Z/\)%كӚ@s4*X7};bܽ.k2/m¾"sfGXdS*2NVRa-a33 5 >p4g6j5#;} eG*Bڴe*Ɂc*mO3)6L$6&{ :M_AUy+jf -#n6a3*y$~LkfyΪ*2o!cH>W)BRJ2zKs`(qV'xuB9A5vV G`sz+ӧIp]O !\Е%$Q:4qN5$=<K.qĔa@/1X|4 ?晓rI*@̼zd oU˫6ovDL5ʻ#Gn"2+^jo\0Vxa4?їS{ϫpq@8SJ<{1 uJς-'_g'''/($$,olz 6^ a=¦}Bo r+#mP/ī쏅uI !Wt`7;XϹ9pK(Yͅn[Jn=WaKt+ +wHEqXʃ3lC#=EK)Niw=ߚ$n(]Rw1'睙JFK0jj OXv󡎣SDžV#P3z,*GpM4~Knp$&~+?ATUOsNݹ!<>,4 |s ᤡEb~&2g⥿w7lPTJ2F._V'6,7E{(V]5'6S .[6[z0@Å#3Q*+.hDgBBiE Q-!^X2^<5śpR{E an( tku.'iyBR(XO9n+wyL_WJKq̕,05v1fUX@ps_*q&s#T(N6eB3{,uyFOmD/ $-Z|OFe,Bb8hWSR`\l]Q¤`sB}1xh.(s8†Cn+ =,[ȘXToWQCx_x^5c L6S3UF$wbVU X⾆#`5Ga7SRk[*-zڡ+d{^Pvu1[dSWxLO5 X|\bN$ؐ`*~cJ߀3Y0VnH7 .f^#ID0xȽRJ¨ץ<3x/3g٤OGGbU˜791aB>K9yLSxE9I@C/ڨKg5J)8 +}UG UtL"~#SZJ 9<ПT 6s7 *JD?sƁ6-z.F^5z,(xw檩YKUص÷d+D](PËQH4S}b&11i$9NzeF$".&m3:ӖCO3&ZG -z%TۖFw)w'uvfX:KȁGBl٢wP;7Zni?2REvbc0{Ig Gd^vlTFΩ,fbKȵ_MD"*f~]d ʦkɱ)`} sA^Sx+ |`5.8Fah(+>x uh)@7;ff-36_a`|p7>? U-z,eCv ߹ DrLI|.\qݦCt2- :P~{]Bv8/y+눤 4?:ܫ=qv [_,rƔȪ5q q>NE'a³Ψ-ZQN;YhO;BK<ܚݹ=yC̫vwIa׉|o+fqH*>+*GpHr﹆$Klqt r( ֿݠ6p494+Bu z6]eZRP6;yHdp[\:5^ '.HGY,mjWJ EsNXugrd_'IHQ:(dWD/@G[,g7LSr ^e&sr#};FDA. fbW,5k7te@^=cL! q,֗-$t25] ǣ.l =@ XS=UPqM7(Qz|wCg'h+[mpgKƶ-T* ?@#?Y$cO^~9bȈSG=%vKy)eT2RAA *1J?-L;g_&7O6=QHeE$;EX7VgdGێw! $wGR|rr5jo^`KОjqrLcƒ2rϹC?"ZU2ɬIYxѲ@޺5l2Aϴ-Ҋqg/묓ϺMa@Wxچ|/|y4rqĎCso.$' cd~YG[s@3y!Y*5cQ,[#0aQ#lYYkMȾ\!~J{0pJmM(V%ǘ#.r>HuH-&f{$Rh9W=@A0&DjIeS-%c-Ht פI$=`f2a,h[( Y#p[P_#5%)Na/x< eqp-8 ADo\r@_IpĿojŃkO i6zJvL@+ZD 5҉i3w5VHUase#W+}#'4fz1'ыҊԻ兰L GFgAF_nx" " 4˙s`P ;@1SSd { YfeH}ȩ:8kX+_ "Ei%$R/\g #h{&12=Z_tT3d6h(zĈOV =LhgXJiMD ܡaՄpsV ,U|Cl9zHEC;-֢UU㘄gw4&>e?Xbq)5BY`M4ˤc%)\tRK.t`QS1bKUO2jL4.;g`hhh:xi;ߏjߴHJ* ɇEWV{U/,-= #+‡amE$EñM@=E4Zes4#MT*XLno)ƴ_t[:w*̦ WZ6ūLuak y/1AesZGiJzsB7IJ#MO *6FK4Sb<ѯ0= zsQ߄'6Sf,d&@Dg %6@1OP=x_BڡmI èt+BDB+$s;qH \_2z׶B_U ,ϊ)z:P78COECX@%px=SBIOW &aA$]=C8k~%Cv y,Z`ȗXϫ@ wy" gb+`8(!TR2Bbs8+YVx->WRI< 6[G^"Dj$éFS" b /|-BJk[=:,:e"e뷅z"tI2`LA]@DW0ڔ9N"p"Ly]̓EU' %{6Mt^ٚNnLb'~M7dE lg/9W>.0cO;L$m?adcRd4_)Z=pi6˛]fd"/⭸lF*_'(@w϶jޟWtBjTɭ  1x@*_3>;R]U'պG6b.Y6H&0Vjا^Sc_`vP~_"0[c0 .pu/ͼn0qHLxtD_9STmchVoUO j*-+ɑ%P 'XUvUq>mޠqFFCЩ]\62<zAvýωp#f/xU'YA20Nϣ3vpd/BLluxJja &);VMx; ;4q+@f n7.<\nb '>GS -6|>3FCn_E.a,I(м5hqM43pUdv1:=r(Dpb p,vUQEuq(n\d+L|kζ"nCLIj[!.{c&Η[GJ)"JJ,!N\B. 2h>T8,{b[xY _Kاipc;+4 Vw.8cSw O;~[[oI A5: WP?HQ0 xrza.cTzɡ,cpWOD,Vﰙ+7:ݚvr9{UUTT(, i7gWHuk4H[y $-l{A/b(\֪$"Eƒ,Lvy:L&zGI }R>,ۋԩ~WKF{b8U{8X)s1<#p5O'd'5^;(b.2 ID ;y\8cb߫Y^0 m<@UJ3. WμWQe+syxXI%x)jTV^ PD.ҌrTq&Klfɞ#\X1vG.o5ϓ]fxRȘdIt 5 ~& ؠ3flevjNɲt&~— EwrRRڒRr;7i M֗'Jm= Hүk7><4Fﮄ6 Bͧ\vf/QY's'^[l\}+ҮbqJZ01LP޳=ݐAH-vm(Vxy|"`ԈlTİx yUŖp={+cH=Q Qb {*XzjO꣬,z+U#r;"w6b9*#!I_JRi&+K$ y uώW.[$1d کN&.)WCETg ^nH!y֤U:5b!_+ΆBJ Xi yNc _dpɁǣDAh٢kd5(jզ|%q'3{]`7MݯĀU|Gv/~S{Ts [Uی 6¯<З>@0G隊7i6{. ,#~Ըr:pGe[$-lQTz! N;n&'z"! ._i\WxC+Zj|AZ 8ڻ֫G٘VLu@9K}LաD{6v|%T&  ;s2=|R%`>j=Z 埫Cu}fg>1ЗzuHd !3%М:uT :N+ҔX#6)rKѷv憏>rݯ ӘnwdĭD!kz"KOuQVke%K~fL^E2FQ|U[~+s?w#Ȣ#>B7ҥC N@=Ml*Y`,t\/#g_5 M8wG1jL-((^s|OB 8phS@U fٛ]̓d8;yp(tgw4ˣ%}h8a}mߐ0E{{oe'INm6## -X!a4QK#" O#d!_c^M>!q.d\ˋ:QH.yvvg BWl; izRL# pd;-y*/ XO]{(aXhnmPfeQjv&&&b8X{h?vn%"9zmS@^|g}?N`wHP(2F "tV# Y a4RC7Yl~0bn:؊q (fɛa=y)(*EyzK$^#򔪥9yB3魩E#Go(bS^wC G| M,Tujִ5er]Yb݀C+t#JܦY'[;|Ϩk,Q1݆jlgwyxq~I.^66\%gݚ}TbQ-Zz s?}ǭogrYU;vpp (2`C,z86vl#K#C(e{@TXfW[PEP\p@"0-+O'MH6Y6udFe7]z8VPiVZ{ߑ4*9#^ΕeFy#~9 lC䑟veNr*_ F F B){[}`]6Tpj[QEATx8WjGca]݋!XvlQ7ˬu K(6$U,Kԅ<["kuCV䅉4ZXiz_̦5t5Hx^p 9 %BXg7`?*f+M 8;-Ԧy8-y5&TYeEDnc,ۍa4I64ju\ehI9Зz$TuH=x**k5%2O^ A] aMSPC)*_ 6+ԋ'Z x'\rsb+#]R|Q)A{(tZj Qw{)qŪ$s헢6I/-/VFD3fgd oQa~,#/q+-1I[ߏ%ZÝ̎cv:4f*CjeT7qkuNmU3]Ś0""00i+T3Sr,b2r?օ2Ea%xFD@@,̌nwW`n$ۂ[K8Û7f@N|m HrԈHtXֿ [i%,kGu9pq&5 xǹW? %1ԞfH3kN2&%s0[`oĜƚ,ЪLTZ@Ƽ];&0M?ZGV W5߻rc]HL/h0 AV?6C{~Fi:-q;S= AВvB=(p-xx؏ si߁P혴ݹSE3.9tQdbb^Һm#EBF?d^M:W;rힳG!1ipR77VOۧwypsg/j 3@VM+O7O͹Z")mXL/2.3CؿN0T |޲a#c&Pfꩍb?h&?KB;Ylt!mVR$ pWjXHF&F iZ/c("6yY4.gUI*d)ɜl! 1U&vJ ;/.b=9G!ajE(=J?0]YPÐuvZlzF>|љOoԩUJ3F (LeG{5ԭ̭I|j~S=k 8mld :q A&K=_R!~4VͭV?\WmJvM 8.a[ 9"cDR#ʪ+=601[UxrpSݸ@"V]MytTtk0P`h8Y!Mj牖6Cjטi e[*A0sfǤXccoԄJ颙`Ս)]n^#Bmn&PA^ꥍ,m2Mդ4cQKǀ.+Mw%Fwdd|Gi\@R~ ƴmX=k8swl4/`:4 p+I\.rߐTG@&XoQUB&GΞ\#V,.!ARd31aYZŸQBFZ0ᵮUyz)U݅ ;(1͝uۅJXMˤ0=^|3Oτ!,\:<ȎJ:.4 l== ϔDnODGE쳎^D!g{] --`qG0oF֤ kn +$(| z/EwjJJWL9_h΀+$id7y"RaAmeGeg֪XkGG:'e"3)G*2:QT̳@~K8mU8loiDq$k~KSbZq\Q {U̐G[;rر/ %{~2xð4e'_g3;fݰ 6@z=f/BP+ȟ\ VkhMH:t͔ b4 ]ҶjXU];j拇|b7VԼP{ 5"bO3NC0.)*XJL,::Ftm""0-8|}\{]֓IN-uW"oY%FRʃ#h㺸F Oy/׶*ϓ"|\6l34Ќ;pJ Y=ԩĒ(ぁQ3G*:ɽJ2/(?Dqa1uN/⬳(1FA_'YX8̹Vf-½}o{t4(WSn:" &I/4ܨ;f bJ [QQaaQX"؆pbP_!o0):Y# =ǮjNѱ=JNwhp$?. ׹^^2 z)vG?;o&UB31>4E%2wuiE"B RdBWB~V2vqs>F(5LzF)DIl_iqr3xAB٣M'^ZN/JIF An%݅LN,{q-}Vc&zBwڂR‚tK@mpҸqs_M*Y9:ab%L^"hJy 0 /اfV:e*.Vmmؚ8CzPj硨^vh/ieOO|)n^@{VqnQ]U2^]GL¹ݙ0Rg(Ԃ9b>z[1Vn*`7aJ.hudU*&GcHHWEƠn18&n6C! |Bby57! C]XZSŵ?( ϒiy $EM0\dټHj}tC#9(jx72EƗ |.HSpz4 د/"f!W}ȑ cܗ˚g Ѡpȝ?O7U eUѠ'+N#H0C_^f̳n-)TB4ƍ"%8;faE3q}WQc)IVWKs6,ļHh-:D1҇?˞vJ3:2gU`9؝N:0q\\.pf)n-x JE9/m5ќ缶̌R/r3~Cвe!W!{ (y=tR: ZJiԊ:Lexo^5yPmޭJ/sz3r1L:/ n aqJ,ṛIr`!eKH.-#t|x h!h!{_\ ɠMO; t`ћ3n )nQ\ʬKDZ6aBX jstU, PƔHh)0P2\6 IjA ֱΏ oYk9\Zuw0#sЁR̂^ 9vz>n;S~9⽶_8)A@% DI-+A7(52Sr7jH^ >~#r xQL'@ % B޸X^h8-5iMlQ׈"thɴũ)rL&Цv,PbE0h("_d*{O :IJpʑ5~y z]sB#jlMwХk-AC`Ii,O"N9Ӟ4šU7Ds- v&;k'R-)lv#]c^I 9zr˿Hēcʲ \7 1 E&fG{4ݻ͟y Q3״Rs`XP%f&PDDY HϨe$[N&c+oA*;DyuYQ?l?D}aSKE:=+ˮ(hek]buM囑@֛\"1V,^h_ΰh"#&K]ac ;s3gSw BA uWQl_.00q'޾p^H<7HlhՔo؛1zjm뒎Ve7-H»2V/W{B̯*M5 ɹ;+lGodHZOL‘yTb;6 yNpB0&=fh܎'Ș)$Kfbo-\;`b|?ewBz? №7#i9-s¿&*/j͉]ڄ$Q4oWYM->A.c;ЗG["Z3|Q1]o婢_ݷPl7pt CTM*"Xn䠄oYa9~($-?-g[5BׅX9jZ˳yB :Aڴ]."_EJ?^)8@NOKp6 q;rz vmW".fZ Oad'BȖи`haNl@CtPT*HӼ4̤KSVDHPsh6`jk{$+gzָ 6`&)z5 =-lQTE tJCH=9Ydpk5 tAG# (p(L+óo=E*fC:y~Ȅ;URZfs־)2oQ4qSF22kq\g-1&4MSyg/N>OFw870Ħ?jPC9{tGD!r$nv9@GR~POh~]Gjol~1H0降[kAPgfX~@ү>gY=HqSF <3iϠ]VjyE2LJ9Eq^(%j͞nVCԳɎSjk~\6Ox6:sFVbH*)|urI8oZH]+{PlT\*}ipåx8()܉=>niAnI=yM>̈́w>ѫȵdLt)KB;<-~>ǐFqrClG>^UrE$a 4~~N n+C2"nuS umacXٴ- ?p0ki{'.Jxa|O9Tڞz ]!4/7OI^CQ"]#G[?z_bipފomeme@\jCV#M|knK Bn6=fhA?nDߦn~Ld?Bw&R8_rյBzHR_&/(=C* +:C*5sݘҠg $*GbdfvOڸcH¸Ì;1( < ^vd_ȅ1l4+lIGtw QeGH*x]ʵ|5.ݤk]k9` ;<0H$#T&AY 0YXmdwow#pIp6ߓ62Q 0tlxS j>/ !VVb\ң[1 cO]{psˬ[W7"7@ˆ6xq}p1".WbywˢH쿟c}ˌxcy-¨1! '|O(a_ޚb9jǣk00v29-A=&3|OtrL=yl"DլRipV܂(M^c0;K^X|)6X>0EwW~gPS,1D+a>KXRr2U:>duc}1Z'fie PhIlU.@?p?r+Bf糙Bp&rPWbpf@|zhEj7 I$WԭBy#ˎnao5>sIJGҝm'/.pwVݷ odRߵ#Ec̛.&Ӻߦ[Qʭn*KXDy?5d6 #Ь=9ϔ ];qqa);(ȦDG zԼKȍ=d[Q.Tɣ8-caol,88Aw&$F`ڎUz32a11~0{_TN>{IJX!1*<;҆v/346w< ;D̸훒 LW .T!;g26+ ֜ckD+wc[Z*[!OQ;j2rPM%׽ˎB3$MAbt %-p`QFjR4,hV-v-y:+_!^Ab~ie"J;©dCKqU5 ջ60 " :#hɕ$-ԛ 9|UoX Ѕ' xǯ*73SFB;)f;1&F) cWݘR>iǍu5>^^LJC ?,oH]1b9*walTp[T *Q;B8*,4edf48;W-eKorum""!6%OEVv3ߗ$h҂ÀlC'1Ꮶ<@;@kytF(Mal̈́!-",}z.'O+Idd?8b}: د[fD=۪䮻8iXOCYtYvB 6>Qyoc& _[2 2WΪz; b9ʐ`clԊ}V\k!@Hda9VC|m( FM]ںI2,+VʏXGUwz}Y*Re6up*.kc{v(0SxdFdMTF;^ W~:v\y]+6xEZFqLùʭƔ:9N)5AP!o79}5Fz[OYܝ$mC$b_KSaqTtIUo*P ?0pS#-2+u' bZw8zo!9FYL07)ADl3A,jHYۼJqɖK/=#ζ ;5;@-!@$&a 6c-BVdUu{O>sBԍi\e7d -2J\lkfI& IhjhU[.po;^? )SC4Gi}GQU<3ym? #s';eᗴn/gvFڍ!4a"ẉ74:APAx7얤:hz)aiۘaeԥ%U5O Rrh\ hvP |+s**ApK-|t>;{w^c*EE!a_;[{fZ=N9>uv24}vs)R 'ݎZh-=ڬI_)E2 *uͻXkEo#1~՗nBȁ/J<̫/C b7adX +@bBra?}_E1}ʝg.M}} F;:K?=+?H(h'Q/}\j} n(b\She" 8INhHw>\޿pL^yKYHeZxDл!5xg@Hș @P@jvBAΐ(mve˔>M3"ܞVY?\|v18oGꨯ\φMS[ipm1@=) `"Gz=/NY(5t57#wVjD"huJ=mma{JAIODQGQ2[ɶ'qw*A궢~ͼ6yy:!D߅P?=g1"i-ڙR|g:P[6Gl*0:axzZk5BssiSEOX>1jT0V,ڸИ-vkVKkafYU%Gf4tVGƌXHq-4<&kQP$e/vC"'\I{,TJA e=ElwdIl!2 E! < VеK8 J051eDmEfVF7zOه53Lg`MED3*U:C#(*f\t<E6}C f*q:?򗗭}viw+#RB_OMc.Lg֤Yd!/L$O~ B0%p(zU:d q0H`ļ{4 @*po!/ߕrL -Wx1iUunWM*"p+ׇ_@'W<-8PB$6MDs }QsΦ , U2GX{'9Nz$Xòqhv,+?eEDž,L?f^;}9 S,.Zns cLK"W۴QvڝjdVgXJΪB)b/KZ^-r²R-T%.2x } k_[. ')/޿썡 68:O,h}ܑ.?niݥ4j:^i7b}_uZO 7 yњ03Rw9>? ñ6Jhh&xNC#ntͪRizfD1c5R@y ux#*k'31^'0omNʉW(!~F"/&9c0^yB?2aA,*DR@ӊ|.,yZ Çܶdq|w:x1>lȚ[p"_UomE\)~+;؈9Ƽ6 |'s .ш;[ ֏/ XX*E\LY¦2//XL+M_8KtUR!tkw)PJIDYk u8 q(.Ql t,Mu!IGulI~KDuǷ\F]V.@sCzn3Ι, 2m!# ERj2h2E6.'"ᅚH"{a FSᡄ赇$n>QnBJl5%E&v#]dJ^hT-KrN~ݽ Z›T; e495L.s?t^ |\~Zw˔Lhf'撚W2lOmK/Nc5_zޡޕM@^HeKu&*ﵱ.sM/|a4F_۟k%;ńֳA4 &[D/^LU+Ȕl"&-ɣ}/#Yah|M1=+l=S~bߣ>@E0A]U95A+G~Զ)HLŁ`}ýUy?몌U@8^e&e1#]1Sh1d&#m gQ)xYZ2kza8;P(ƻ$9/C R$YP^e!xGۆ˕+sjms@ !+Ag?P lJ;M\[^INqB`YV].8-(Idҽrx#Di]w8i~L V ӨRTBSH:Ijte=uWG"ud'm3(IggQH8$һG]cM@a/rZ5@r>\ hUG!q1X> * yA~1dH\[RW>Cbv֤7A؈`QQ( 'p(~z/EA־C/b'(]]"1*Z|BT2;K\?I|jXdVS!jkhήKDj?V }w*>4hl#E1pPp cgh6x+<tŤCB$o5-flYR$'9{_[#&kYw4/.POWJrd- &40 |L۵& 4Qq)_0R !Pla"$빗y@LS5 Mjf1f!1\IT-u^:OugsJ8 RtjDdowelɘHC-3@@tlEv XQ0C]mt10+(pa-E73ƍ%$L0'I]/ʠVKgo UJpJxs=$KYw..!¡CHrmco2V~tźs e=(FkbQr]' ^-Q"ddYͼ@J]:-~SRt+m,>}g:sF\a8y[똆TX7. GkGVAC9^S9 ?E}*ٻsi+$D)z\tnEW>6`]05@1H,Cx f9 *Ԩ9 d2_һsrgu MŖX89(FZQL[zuyDIj5CLT-XH7UD~wC{ `LZ sMSӧc/04g T}fN/z-h0`hdU%sʛIi6eK@޺Gǰ`HzoΦ!b>G2'ȸhٕXbo3\-eE }߻ڑZuS@?pn~u@dr$VLŧ+LcBD~ftf`sTB7٣t]]a-Z F WEϻ|9UI2KO4~cLqH_B񤋗:&atB5>ܪJ3xR?l?!ŦykTvHX4+<#v@-%:Q΄셝5 @΍'{Cybʝg @cy ;\N6^hHRey~i,!W:4gB6?g|$7\帒eT2:$*bUsv{8445?H]Y#PWN_?G>VI^ʼn2g%l"q VX\5c'֎M3#aQ, g0؝ Kx'g/:0M iJE͆Q/6XCM(ї]Uq;bdN' > m8?lytH-$u؎ѐvBٹHN?$)TjdNX%$ƌ5R\Zq{ҍW`3r,—ў/Ɨ:W:hY9ZkF"`{)m=[]y&rmt({/$'I$V|3:X(:TW9 iϵa!2w4|8(EuUcpH z@,_!f64wlCRrɥ@C ? Vv&I搟aVh j6܇lL ~l"FC32fȉ)""bJxcgNCf=;aZ|b#5z!^?}A47f87?\KRN[V+ ӉwL׵S$Ϝp'+M9pSR`OTMdt&nwR gt-T*?|fTg+itZ{q*xT9]2E`dn8>&hh|4Dwrx%_,8w73X22#*V;gJ>_HhqᵖݲWOٓXȷ(d ˜&LV딦,uj{iju aQ#/ ХŜy4A8FĂ5VOg-Bħ平UhkSaI?{zص'FeصE1!Vu8k1̀YhlLZtY>>tI*X4nYQs**B6vP_NFd*&8.(&`"\(C/36-Bp,].*v߲W +Ƭr,h=?{2C3|'T~]9e1oEz82GMrM4u0 I”k}?Щڕ{uVMsF#%z5 5GoiA4֢.7rV~]#Ksb@=~6ؾL(R6'PtըC&}X,X\%tZjuer\o7sIfߥ9xn1y k1Խgm*U i%m&ODH l#k6S B΋sϋj}(8rُæ ۞~ y),mEVකpV#sL4! gլjѤFYbR*}\qGXc .tw?ol^Q@0z9J70 6[35[^\ ^8Yx A*mqSJ,W{is"FV Y:Ct0r"rlg;/]Lf〥VV.ܜKuՈ\Պy5ywKo"sU$?Ef$ T?։ E+W ν˕3c -L}Hb,e0b'rF(Gwͻd3ԙ]!y [<+1}FCUYN,EgshOi|-%M֣SV8,paHɣEhx9x9)s"`sޗF +*v &=+wkr/'(T6YFr.f0c;V(YI懞I>aK~9-@|&?d)AWZҢ SsJWL;.e G]rM|ǺfR QѓcPp |sNE, 6z5QXfPB pa:h#`:#Ӓێ7\ZO{n<6̼/>f_{.W);Vw]<322qrp%+5&\ۦT iGvHWe= Շ-bBNy1`n*~"(\N|;t sUކ7nZba}y{ nKLV ݨ=RS{9n tFW~U~!aP!&:}I!T] vۭ8k?aR`O;<9?/wiD`hV{:lӑy~93#ܮi{R E N:6% dfa_*3v\@־TVjY[`4a`7U2?)餔X}i-f+&dO=W4< 7q0aegkN6_Yp 93?GHWί }x \2w!(^;! m1XuO n&TMbKWc[ovsYWX15qQE|Qi fGÙ~u]Oa lv֛hIB}[$@gM.r9Y 8섁hkXA-5aW49a$ -gE3U>Tya.k n[S1ikmT={ (h`٘1J*X(2a?Kת(vL4w&(KTD^Q0%ڬMLsM"#asr |<0)d2c0\AC\ZK#,C(ץeۙ&_zo [CMX)ci1'*`0% @Jh^uڧ֫H$i"j%zz܊`D}6G_Q!AX8JGČ#qv:3XCWu #08>U'O#B9 M<=~ ^gMs'ljxuMN":ZUؼ%(=>#/BNt92޵ ;] u<>w}Pɝ 'vn0Xhzq6;r8foAy *JOl vQdЭs #oR}Hu~60_P0%?ז;GZ^3c Zv}| n-\䦻BggD5:`r iE|eJ }p @| Om9դВ%:;7z>{W7 m׻Ab7fwNrƟ0.b#E *:U"(}Qp׵ѿzL8lŮoa^5)|W}PX Gqe:0 jQ쎃Hj@C9RX{>heIt:Od!Ɓ'-\:D c6u)/ṉ ųo}ҁG/ 30\3$F0`$qo䰵QջX\tTa|KV^bOH!Al$P\l+Ӆ9 98D͛k3X<ުOU"&d>>CpbH/>ƓU-Ɖah:.d sj֝{x 2zDʢUS@r ߖOJ^׬n:VL+=W/q{qU&MZ KZuNTُKu;{;+Hp5or#LXՖXn6VXå[Z mZ0isNHjze\Gf)pI )RGEANx,ڲ*}i37E 3K37zk4ܑd`z폴˱kEאp7܎=hːX.'aXkq@>n^ @ۑLx[)NxYR찵3#o+ 1+˛R9㵤=Zc,8,vBlW;G-(zO oپ+T~c!Vx2qFJ$9KF7qYܟ)[HӊRsj#S UV_$Vޭ >\t@ ٛZwgc<´o89 vYw?Kc>I:7}zB2]I\9̋!ŝڼ6>= VfG`qS='{31;0`1 L1K!\B7ڒ QT2E))Iwx=Cv 6jz5`1SJP'Gk&Fnr+SxxщR"jfmL,@z|UXm $vpR&M12 ˓J G{gNc~t_xe_ ZJ&$J"OiȲ"3*0JpW~ nx;rޯCDPMS$3*C5gTxABKJ P_!WT̽׺=: ;RSo4K۫'iFWL&3HW@ֈ `֨zݖJֵVNj*DätѵqX6T^,sUthG9 SNPN-&X36t3>z/B~[gv wc$>~(6^cN# `@!&u/3I=@qrWdeGSP ?ks6/m!V*ܶPLRX ~qǺ_y&2nhaq^QQA,!:C- Ώ2\صy[W'=w!ܺVi;JLOLy.#aLoMR]h8( E-D[}-\R%XdABDWXq8Ͱ~I>oO' |M0u2ֆK8`h@R{?6 s <L$0er /ְJ3 ^tYQQA_ NjdTl<טMn@]vHۀ~M#E&j3mPѦs:p!_ Qgޔo, /OG\!.gL|UY'g[;p@Azqp BJ›ԶG`#\>FXXg;Η] #Zd1Ø}lb_";[>Gq;"yڇ ō<Az9A4*<,ppz&'v$}-{/\j+#$qbYkrG/Y $|Qbl\PeGΟ٧dz~$U \jaw7^fW`(*%kChѐʐ{&5*mg8ēfWM^¤( rMN/49 ^™8W~ LT&,.\l=4!Z({;@rGJ$oؙ@\4^3oERdV_+(? GFS ]X~6P,v.bBcwTjZ8zӃeOGKŶ„ AurhXgM[=S:|M[(})<u79w.coY)Q݇@_>R)\a9*hQ5)5se)ؙ񼑒^wNHn$Wk/\v g<>W{xctъ[1G\R4n~}v`Kb\8;W2lZx u4E`˻ƞ7nqSOt&jo~?\WmdtK" MNӋ.jV*eW'aOyΠat>(Ԗ7Ϭl}>='bb ZvF KDeYےLL溻 å׊Aȍt@j8/3@䳿,TN>) 5Z e&)a2.BG] pcϮ;i_譁aČd #M݄5|d\Hs&oHgGKDk\ӃY]҅oŅj\%8x:&{9br&G1 @6Ku,~ݻ5]Eׂ@|,PuCz;nDa/BQOn#<.叀劙5c5x)Lo iS'j0w-mf3'i}ɪS_p.`DQ?H d إ(cc)L ~9u WԐ$tr;cXaqExa0e3b{vMaʇÙ8 c@t@xN*:`؊~x,/J ϓ l)VUb1],k[T*o!SA)(~V-S>{H'RW?,!!Oܫ t1{5>L^+VpAɧn6GikҘvpMI4ڤҤ) <8xfqh&x 0KǨqq^ D^^f$ꓑB. X<;J&0D^R Õ6' tRb=,p=&.r] f^r{K0fb)iriͅl <6K/ 2} O`y <\gLhl5:mLXu9uI f)X̙d&;H )bkuۤ+mB!f}=*ÙƧ'UiwX(Cv쳁1kD="FbvݺnЄ^yP\\5?WS|CNBJb39g\7giZfOۚO{SR+r 5a217aך[{όJ;WYVHmZ:!6OaLt^k F1q6x0ٯnѿGmzڇ X[yUa .Pҫ.*x=e 578Cտ b87jڽ:+X54>Xn:ӥ =?Oq$3WݞwDbV(OZ>$g}rYYнYY/lA#v RA_0)#s71%X])a"Piajwtdp}&#;f z$Ym77W_T֫RVXh";9z ir{UZpeXA$l%پck-*amcLzSMw`\˃od|-\Bm^\]9_nEHk>85׎`96j:?!rk~-V"x;IZioZt@1uEU~zh<΢ICqUYu N@Y$^S0oٚt9Cǚ[^4'm9PD:;h,&Snkr*ګm(*45>4Ce5nOAS[ QFpK66%pӴEĨ#l0Zu0Lf ɿl;fxս/n }OF9{BzUO{JlyXbjstuh-qOE Ր_bag%y_,~#A|ةi/~̮ xd,"x ɼ¸NC'1; %j>E@ ȩݳ98V#Lle;+W|Yk%m>VK6uʏQC*q oD^1 T=`5B [ rZ6M?j ː;/ַn'nxvU7rո;nS>Lf{9s1ǑRu;ldT\˜kAs؅u/iy?1^wLa('E D~kԲJ,I@7u2`RW| h:1ș =+fU;;(aok[NۣkpD'81;jBa/@.fҧn3FnLё&*arV(';"+NuQO. JInx>Xo8<kgw8L?låPZ8ØdW>!c$[fu[QE..s(6a<Ӈ>'b%~ϊɦx+TjfUC?c|c b(&8e ef$wi!l V=f{VF8!AB9_V}  hk +'h~oRzj7 $tka8 ?EeuS4Y!,MiR9U͌ɻO+7\I␷҄Yh}05KȞ=#NbR5ۼʘrOK{njܤT2"E3<1~ę;!Qmw2+L~\U?cn+/ Ll]( m8yʼnk1 Mx?}D)?U+j{(bWLC"sw a>S Ǟ(&ayB$w?rӺ0TXsGEKPQI8~y|u=17npj/s#SµRa(}`&P}M9 @$MeqE8DD=K7ىPM&!L*"="&ĤIJ>ڤb#a)~іY 7(Cnn m\ Q`MX:/MgŸw$ &f"5_BAծ/ z~l81PDʤbGlC"@%\bKex9#z`LQY J(jɞ A ?Ӿ'N(<˝Y1x 2V<3Մ:B 5?E/T97{1ց.!GJb  "񄕧m{*+_8SAGsPpҜ!a՘קg#"1)=Cd3x @$COG,r덝@R\ 5Bx\03;F-?Ty³{K2/>  /k$%cj^BQʄ!)a=YK7-e̷}v\ΎcUgCG&&{ z{7~"IߖWT計%]&"H0 e 1UgʷbR^Z`"eB.+TF4D G_ޠp†,FٷUM698u:o'?$B#FHސM.+1YK1 cՌ ;xʘCȬN6Pw} I_r!Z;_ Tz;"9&Fh3F* T T6cRzJ1"Dq]{: &KԜ۫(ox #Y1Oswz>>B}cNX#,ؿ (c[|)?eQ&叆X-^K?w\ &# 2w'"3"gV茸x϶>z Dw5^Gx`sbgwK3B EZ@ʃ9 w8쇰Xe~#54ф$r|O^]{X?dFQ:wbh9nŢq\9IʘaO_{RK8GT9ͽѼ, ^z<_r.p{ڙQ.X D{&]Ԥnz]+{߀ AnPŢAw [L] 8L>'u"J49Xq/NK+.0dxZм .Z %!h#y4 W.d08z沴fhQWh9彄Oй;`^W.[c >ޖUdD vļ&' ˉS~"ޝ,#=AS܆NQV_=mR6 D'кRD * $lSQlYk;r@%V^*N(=ZߕZ QuϥuxK^T'$vK<_檯2(pRAi&3XD^.oQdCׯֲSr!G}ܚץ3E;3vp2(0C gv (U}Ԥ~]V Q&8ipLL>/Uʹ@qts'igwqF5GLt , Zg!^["OS\pzkAV_< eɯH]ceXtIq+a:D@oު >ژ-6urFYp *)PXEAQ\TGWJ^鴅=Z-S08:n3u"Tuv@y(<:_^ A!SX5v>^EՔrM}gY"Ii@X(bKiZp.Y1c >XLs^PL:,v+vEқuƴl%5T-`jhgt!99v_Ҡ&:D=9p΍B<(C]csC+I/nM(2obr}@4U>PhcOԯBi&ϵ.h9CD͊;y55Mf6wr CNhSYl=%)?vPe'RuXz`:%Us(:Out$v!MgI4ܬBfJ|Q3{9Nj9 b˜^{WR㵱g`L'M^8!47LmÜj#O:'cC'EdV9F#8d` 97+ ==`OCM]5ly+XGW0@7`#]ӝlRFx=E:/#~  220ꝙZҼV6\P! AwbD8A W;9Pj/'Oȝ^*P5^i7ϊ%{=h^gp/8>*7CތgFf2IXt.xEd*ҧrȨ;p`\"鹪_*Tbrޅ4Z]C"̍7綸`le8U)!.u be/D^e=[j{7Q]7֙؇I_%}ŵV <ؤ?Ҟ AY-fS hhQQNMčl루 74J\ES!ևFK8 rP^5neR8Ⱥ,4iv򇴖rE_};@Q}RTQ=;g\"\$Vʍ3Li뙖ԉjlBV2A#l35lXר2,@ZݮIW7s G\"b+b!kr  U!JD,oxt3d bP vEEMFNs4B [4雲M Qsyn?c<%Tpsy# -"-[К1/#Z))y{%蛝T|+[;Gr%BĶζ=7~v[.[͉By%IoXAQXp51r`ݳrB˫t _. `.j^[^*t=r*"]Fv&$rI(# q -fJ92g y캍032 o'UqVWw)ҙ:crq .NwOOMH _3mHY512Qoԧ 枛m i}%X13-\OUIQԛDgd:luʼUKbfX^MCv5@*xoڐzswzjø\X[j$pVJ;qsv:=DZGS;_[7R[ =a)N[ .N5>߯- GNdNbԴv.7k?s,: :lUOyaaib[gzq t >?,ޘv>&7-cmN*dž3 $+ޜcw_`dA~MyOr/3~u@.7xVlDZ'VzDi&e+.veڒ5y r6H'#DѾёbg HDQ2wC¶ < 6w1 VO,uW{=AvH!ťehhaZ>d;d 9YZef[::KFVbڂ1 `7?f/EVlܩ.1lH^~a_}q׌{e7jQcXr'?2Y'/:AnT%T8Q0l ٞ)G0 ͂j[F܂g6 -[" v-Vt\H$7\2}u(%~M:kO=a 6g-/l 1 ?:_./%aglq;Ql{h+ETǎ`nrP"\a9Wu2͜hF宨 %G?Bn9_\VG|'bIچxNl LPF MSsߢ~:=l<#h,[_Z X r!,\ ¸G/‘m~3=|$NȨZIkˊZTǒ2#T/ D?jYKFg^н"j^H1^U82M8.liy.)/g\{8܀1Hk̲Bh^gȭæ<]l-J6-g@IޕwʊD詖nj gX"߸9+[IڰRyDڑ=**(p|9Kcmm|CH$RV 2q W"[MU;]1ty]өԨd(;gs|7fZKHE*W`Ӗ7ovzhJxL,=6 IE7q,iwG,oQ Ő D$M(9嶌h;1B%ϪyS-bSm,'A-P1~V0=,f۹m5]vpo:jh{ثF3/GXB{pO$KNIZ Bs/Pق6$ZW8֗Uذ{_wQ6BٙynhMHFL cOlS7 |]7Y6Bg斪~XǢk9 -/hI+Q/L/e)J%=*sftkqe|Fk6nDoƝbg_9I*X4݉OF}hĉ:gL }l g ;$E]~rg|P 06fuQ㓗FޚzQOɫ/u?}W:mpHi:g.uoX ܴ`uNlftApz3Amzs+ +=*?P7cϔ}CI TnGgrg; I*50gv:^-N#*Lf1/w|WPV H8jM#PS%֥p7ܔ̰:7]:Y%z"##wublu9ظr:mѡ:=ϻNm</!\\R4#".{&^$[ vp-u.ˀV+5D`;e-.iU.eEvOɈ{_U}.uH}?~Mg߿Q޿«D;}W5}E4{wm֟ԗg޸͟ $vq;Q Z9]B(Rҹc,of7*#+ v%rͨ!yh|y|Vؒ]5?ڏc^K>ioXSb&&&['iȢF?L}M@3i1J>-zp,?$٤JNgI_*#":ti4x1&$5rM6ᎃxk^g=GjѶ&i`'D$A_b0cAVi6J O 1丢JfQ#Q)uB}".A0o =G~Ֆ.RZ~ 1jUC&tn) `*@qFr A4So4Q:y\ʆ2h W[WHBafU,?I׮]k֚)Uj_W ȍ&O =Z]jv.y̐oɼGxuz]C_j%4 wy2-7қ6qVg~ȖMԠ-̄H`9=FtzMֺ6QR=ǤO &&JiCLx^aUUE.ouvBA9Fo_r CW |@DxB]mΪ>ЧU%FNu9/Vs 9NQ$F"ng϶ni4M$mځIS,hasjW*(1=ξ2:׶Mޟ`J0#".q?r`@-f?¢v|LDJ2߇RpǶ禦w(Rh]m#j}I?lKXئmޔt"}Zv HWXQx}L:\;IA\a:}k;Q]R0ލ,Z#MlΑ ^9gM&mLTm!PԔS-31RSӒ|JKz btmE;cP2`$ 2 3;s QR6܅dyQ^H5vf:O"&Ƣ:^޵Wj#W&P],PLj LyBB5Q0I_B򝅸Uo+\Xo\Xb k$E qs6ZY)/VDqZA'n IJT@T&3qW<J{?y7Ur|ي3eu@`6n)!$3m)=dR ^)װn97&jj7{m= ]|VoG) `ϭ: Ziocv ZVӵ^lUpM0ܿCEjS`5'> kvNVFdօ]X/E1=&Tb®_B[2\u?%? 9>d.)RYD+#7Y $:mpF9y2V [K&@ZuG"wX2ӳ/zK7b2 5 l彬ȮTa7~R J`+3XSRk4jסVq4J!gеF+!O^1#ˏ6^JWJ x"09پ8<8ljRl]%3 ŤVȐV_G"OH㜊KڅeBIЭFCC c޵=>Ox3WlQ!3 3#N@HkT;e8tO[G<\w/ɇA[Պ(@{G;' a/ ep6լ/FR|~hz8zWjެ֗FtYZп}ѻ(l K `FBd|ߐO]a]i[,^m6ջ8A%df3lQG6O hҼŘ7FS~) 6wȟ:&}r>Ps z4?(ViA c G>N䡣##R[%, >E iq`;HS;J: Ģb YRe1@[x{u "V"YE5f9%K&q':T^I?% _cB׋oYR&dX}%+3e'Ïqn OLJ6_šmAEbv <ƝC}`L(C; qGҲA22%Nbmg<.%lZ@Y F]s*7daDuѯi^h-|׃.to{ 5./3h'qcvYKKs8m,&@d)ɜZF&s9:U ' Z--9' R\NhP2U';7 m\ѵt- ȩ(JyX1U_o" zgg dChjbiNFh7u#a(s%q& Z4w?"R=8*R׎\oUz(CvLpW;( Bn3xNQԿK5.ny2%6i X2W}1v|E=jD#&htM$IJ!b6n)J9}uaQAA9]I!-Wɗ'EdFLDKʘUy|-Ӹո&7r<9.&0^0@7Wsh8K1`atVR]} dT\n&&1Z+E 8CɰKޝb $tvs_&HA;W_ZIٓ E8l0bA(b '3N%ZonAy>u(gO;fP7)lǯEb|%<*tJnM~p.7wi} ^0w_M U|9+aɞ Kv]Ӓ-_ߢZ kW|xÑyvn s 4]Y(^@q9j $>u F"O8[&CSQVxυf *PԎ-@(=F.L(; =hfzxPh_d15ii=y {-p@eZgD62Ȧ[lA]p)Sirkݰ8Jĩ16V?'^`s:32>i_m}zc8=>K,,`yFioVqʑ|.p~S5{!Ն+Ir^kG֗*x$&>[<5X-v3LF%e+j4?nς=!>E{]m]ƀ[tr攅dQ3bu$[o/M$`]3 @A;hDe|8c;^s߈am](Hd=Y:NdYgPPM?2?R0S0M, xXbI, :|FFM0p\Y YD!%'䭫hMYi+'%/&*jd+=lEW)#%xADBf\-a5Ҝ}gXM3W s!QT$m5>Hڜ :ө/&1`B6P1B{Vtr@gA:}QF+ocm ENeӕ%!GGGmRf7խ}4 _ֺr_=> U96OeMڃ*A.](>9_wLgae}޶5u˒J w_ej0:ts*SjAu~Eb4{eJGدHJ=]3T%Sɘ3Ovu,ǫjtg9corf')Ns\/k ~depV=kQkR!7OôT]zoFg^}M>ā&!) U3h΢sOA2oc˖J-_7lmS.^Ba( g3W8`[1 TTrp[5O8wgE3qwN@uE{O+ٽ[.//&mlMo6m;70j'8w1ѩZR-B7C_K2 퇶Lam'B0o 0[. tz-ps.9_93/MJ ',|s&T "0QV V*Djc)wgV9/A-9LyD =۷&AI3|zM. FΕ'mŅCG྇B#:2Q-^#2h*#йV~K˩SH?蹽a1nZ;d+Sθ Yg{| O8>I*ZK,';𙡥.7'tc`G~ĜJ~Iܵ!s&-wy- ]XL!y<Y7+VtLI_⇨9T3fJY1>U2s#o:,O.Mvd8SҌXk /z RuWٰ+xX1_,4H=-B_V>2.6s~TC,:VaƭK& .NoG΀b/f o3PGGde A{fP!y`s.DW9neUF:PC7Ae|Vf{ʎ]ttftf֏IѲ~1 ]cET<nؠϑ)"݀)p)2GJNa7Gtgc}ݙoz 4#*k7ߐ0.vbK[6,320 Vg53]|̥˪N5\ƭ=*!,ڕ(tSzkz._!P=1+5A UF?B[!sE ݵ=i% Ρ6 HյCL#nHOZ1Q `XvÄ͟,0Iqrˍ#m0%fs( ]9Zs~sS tꃭu:Shtz)\2#sqKP KTrY: K2twONc9bWw9xY1zmZ\;e[>dw2QƔ斉:DUJot]xh d,bKԫ )Xo֛5}.4B=ZKz K>Nj">7lōFwZvv\; QڨW_v+ެ8[p[zU}}8 Q\qRθiJ*Y±fӔҙT$JTo\8T٥*6D)j&CQI ]׃ϭҷ\F+ ͷ}ֻ5²ҁ3KwƉaA6V!r2˘tij2]-\W$U7ǵr2^C搳G{JA_]zc/L C]acծ`9 os5N؛'0 /~GTHcV#W]L#9W,WPn]C"ݍ/?077ɫ!zNiU3I1=և!xE]vUY2,M\O'n_0TgШMIrJl8ðFM%z?7RGorѸ[mOfKu6^-G37/J|J>^]SRC&|P6njU#q9害E3΂";׆NDXŒVQ;ٙ}gvIi'gM!\T2Nvv_(|Iƌ9'0 rNyK 5n[xiQ`Õ۪#~/`yk_.hDȖ~rf9m9+2A}~[wQS= $r}݅e,}5SOJE'/4 eRWf"KY{jUF&VYOɮ^ܽ_b:>\oе70"qKw޾2qq꟨ W&.qʛo9qa|Dw/)4ƅ .9>u'iWGKS/[$Uب3-{wI-{<~y~kxkťF [? Bs^ϙ>u61cTJB5/߹z{RA  =J$M KqŁ*D݆uFj4;uЪ Bx&x[40y/`&{6`"G氷M?.Q+\a2U;~*CF/r(*r>Վ>pcX.h3s*K0}Vޠƾ#?CV^ӗ~#!7 YZ\#n̈q&.%zd Ϸœk/IrR{mADz$1ݫ;/08Z/{̥~@d\"Sn@Mθg !xWf=}'^D+PNB3e֜zY>,M$ >Wv*\~U ?+Ra\!P9̼6 "p˝$~={-^/Kqe>#]2)Wo5(6WoλpSj|# ixofSyI ,xCvRcy.`qekKR{?"" 9UkSs E%hj/UEh7ZI;0\H4D U5}LLTB,TSFx:._ORfKS/A&[n>EqKh3p'zV5=X[ikzH^NG>7ka҈F|lv?׆kb܌瓑妒i'n1U10L I$]^AYbZkWӨ϶j̙g_yT.}sML$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!d(Rߛ嚐faUJe(K jh YZ