sssd-kcm-2.5.0-1.el8 >  A `çwU]Ѧ#;9~(u/P9̟}N|f5nx*ͫ@HT_170ma!|C%Y!S uNpEF0vx^8 qc^z:hy!+ehH'9b*ԏ+?۟;8U+E<$0 /hA=F㡆m2R&hDVb\ܲZ|1PKM//_)Xym\u뤠WM#M^|ZGe\Qi\Đi]﹯^8_ Rc7D+WVEϸ,j@^ W-rCܶ,ؿ3d \D`'wgaδ?t8&I~VU5~, X0qTAYJm7X?ϭЎ<0?vDdEGmuFQ5Q vZ$٧o<\3ɷKtG;d~-q&FhFx F&k,#ޟ6#6 `R]|B ;{ e/.GCqGP1M&7D1lJw2hJ~T>pBg?gpd   B 'DJRgx   , { cL; 8;;(48<9:c>^:?^B@^JG^TH^I^X^Y^\_]_T^`G baHdbtebyfb|lb~tbubvcwetxeyeMg g$g*glCsssd-kcm2.5.01.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.`åoaarch64-04.mbox.centos.orguCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%h0 ځAAA큤A큤`å.`å\`å\`å\`å\`å\`å-`å-`å1`å1`å!`å!`å!`å)`å)acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9dafb5c88fb3b6226e6b19b3028bf4d731e3c61dc307202d514db09a21d381af4a760b31b55e5ff80650a9176a161850955320888ea467d76cff85288811c22597a4b8f1921be578ff757290984f571beda4897b0a68d1459e4d63c918a21200ba4f9ee250b68617f10a208d99068b8ffb9e09ca5c8bd6753c22df4ce5b8d5b79890d877416ef4ddd4cc617a108e4857d1cc578b4557f8e95fceef602375c80481f3acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.0-1.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.0-1.el83.0.4-14.6.0-14.0-15.2-12.5.0-1.el84.14.3` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.0-1.el82.5.0-1.el82.5.0-1.el8 kcm_default_ccache.build-id0369e2bb052113f963172c96320151f08b74af1c747ff0c3d992d1dda9ac94071a627f894b9f8abbsssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/03//usr/lib/.build-id/74//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0369e2bb052113f963172c96320151f08b74af1c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=747ff0c3d992d1dda9ac94071a627f894b9f8abb, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/PRRRR+R'RRRR RR,RRRRRR R R"R R!R.R*RR#R(RRR5R-R)R1RRRRRRR+R RR/RRRR RR0R'R"R#R!R$R%R&RRRR RR,RRRRRR R R R.R*RR(RRR5utf-80576ee3faa3a6fbf9e568425468abde3e7be1a99278989658dcf81c6853044a9?7zXZ !#,`(] b2u Q{LQ^/B_GO`O2x _xDh a2C X`EdKUDj*}"S௛dnqld04I!}p`J4w cޜyQ"hpefm$N7WN]#0hg}o k 9Ƚ[Ppm4T|V~4U@o6 6WIhAB% #۠_~l@Q2ϻ/G5u, "+H,tב4"HQ`$`͗#/14\w"1q(nku5EqY\n3-N?BEq:? <on^J~(豐NȢńU ٦Z*SiרNQEv~,L~*xV'UK=jB%=+1a޾+woӆ}4Y[ WgN#{Nуn^fm)|$x<*:+7:;fky]3逤g^XN!!z&RLJNj C798JdϲLa ys\t3^~[ T !M6BN"±CV@>vhc\&Б64]>ELW/_6Q; y4n+R*0MX7, A 5D_͘v6qgr}&Y:1zxA8.oх9  `+a(( {?{=ڥxVb<ycz$ ]]P)"b4J@ _eh"tU)[#I8|4I2}hvȦ끟̀rG9x6R?-p\ZB];# >۟o%CR['^jsc6 uja32.S>B$yj E,64shMc8&H2ruZd[= ݆gVN{ 8?E~@9-@x;Ơ隆?Ax́ itnm.3A#K^r~G4d">6+O=anh~h fOiG2rPV 4ܰw,s _dX0ЈXw ;6b^TdJ1u-/aCJ@nrBjυog"QȅP+[FbfD#:(Uý}OEQd ^0=w=fC5awŎ'c 5Vxډ߆u ;pOPyVU1 $DVI&N zp_x*lo_ 6ɓ#żnGJ$^N>7@cD`z]aNFSG?%zȘ⊁m]ǼVnWB*F4^.ی5{? @.d[Ie%<%sKȎTDqWi'm$vX9}aΟaC257&JY%ً4}*:q<&ƝduYnXa!NGS9z-_LTT 9GB'3"^x2bs8ƻ4Dk􅴙.K52TmYW/}|didi4$+3F7΂h6EVc\ aQpq !F% Xi(S[CfHn VJ"9;gCYlW/hToA]hQb9Pv}~C0yvhKIŮ@1DAq ┞A%V' e>̈́)F oa-Ɯ8;!ۥW = ]vwK.AБkd)IɁ4%l^ݮޒՀ9o m[S6;ik+>-u1XUjk뎔֧s;4zMU:#" q+'*b 0f 9f|3=d= ]gQ*5f_NR22Z1WŨ.T $.qAh-9nXRчBa~k)!qM3._5g#Ֆ+h9.uw/¦fM ?%U!- F7fWцݙSFv {31d(j~.{ӽJL;Ԋ#uwE:}e{:ܦrS)H_~R)!O}E%%t.7O.L۽UUbBM=*83w',EOdmq߸ zkfq`fYF!ې@(C. * ֳ*ֹgJ'E'òNenN(GXp% {(sJV޼2C%8TG%%"|ٕ,/>^n6ُa |B# LN_;n 4`0TFgNĊ:T)(zDfU5xldA}OA%-1 \r'|2' Pv/ JEx2i:5o|} i6X?'$bH^tԋxs8 D JCp@ԍRq+>>z}]j5@3`&IEژl;&4HI5YPS1 \&@aH{DuS;OqA+dX-~!F^P#1= ('y H};KLf@M%m7u7RIPKCg?_Y@PP^ɶnC @UA!И׎ ƽM&Mix#8lڻsWiĽ /9VGX/5%}d4 P@s E݋u`z~ėV7lގj'kL0sl}P:w/5qh2c435~Ġ,%L2Ytie }9=#i)z͉X]Ⱦ$6XR]VĔK %d5u*g~Jپ^QVӤÇ%${ii 1`'%#NuS|TJ0煮c5 jptsvsj,^;f!+ ;. >NLR$.BPpӜC-5$ഽ"&@yxWH9Һ)/vy5/< ."9&ً&BB.*[ĕSzwn"2~}Gr.d^h`QocEW}]:fuw#= :,{z50)C-Jo1mhUf,[ Q$ǾOT?P9gαɔ/^W tUF[V ؿkISnDdr%p4F {]ZWVAj-̨d+NYZ-נ>h>JJ}ǀ4㳺68gn](BlZٳu{W @f˿Vś*$M:kٰz 1Ұ' ,DGaC}&;!Jk`^*Ako6xo5>D$3( }13)tx{M`\Jbª38"/;5تE[&{TjWI{2i"'A#W§fW%/*w1 'ӗ_¶Jg:nR̀$?f4Aɣqa吁XhqLGrR},".!Gf,kUU, }l&ˢܭ҂~uAZiFti;&RPO׹+$^7lȥ`b> $|d mD{t@M9Pq&3xjKX詙=wt㻯|9 }[KtHFD)FPg=^X߉hqe~cP.ãhF^rWI9X2fD[z+sv=YSnn-p9Qlwo1cvei6CBWԊ.1qn q`P#o A>LUj݌!3,RȗX?cƤY@cc$+~>%OSH=0"tYg=u~I]ډ&Xizk_JBxeF)x",)mB!aĕˣ)1DHcZ_ EWo`=ҭCȋn:^c'({/sR_8M0x뻞Lܶ{?#fU}EB[Uq-L?84MV084N?t/ŽĦτm=&/zc^o¿vVxGQ8P6TXXtpJ,%Ķ6/]L߆=K|$V]! Tc͢ʝ!TlSH:!ɪR@L_Ԃ=VI{/Zj AL$[F9ZӔcLQM&.t;XXlfߗ6(t`>Ů",pN0'+)kKǭ‰Q@K} iA&; t+1Yn FiVCŦ]>i5`^@W } Cpe@!o-Q(6͆H5j ?k Dc. 0$d7Y'E:Atcl3i\5m z;(*>zKnɖ L{ǦIڭ(LOrV!W|ɪ0^ m림|['x(&F>ʉ7J{= i~igOέr:m&rdċYSQG_W Qߺ);g4jD460(W[],sr>߈ )/0YDݏv6#IF#*F$b < cHlGP;AOYA ͪ.A"!$)[}> #O/*88C,_5<>wō7Gh׷H~,^nu"[*P_Po⑓3¿kY)d>2 i۵ ʶ_gتo(1^{Rٹc7rg[Xޜ3 2F^-ETɲq cXu* #b35%)F!G1ɔT5gyh}iGʰu8|"i){0+7;[3֒6'23LY/S.WK1Vn ]y9d}~7Ϩ53zn!kk^ 3dXq{ _=1£QC Z`.NX$ZD#KJ<`:xe)'Wá{`z}XnsMUŮ O=ݍuP @M`U̖x0fs[@~ W[ Mؘ֗E+lzYL]#T KWjGifU>#ʗS2$LPׅ=C[!q/0a9®R &/gdA !5n|I+/0C")P~(ئـ3>*_@DMug(gCjÃ{?[;@}x7y,ъw][M #.eF1m>LT|hJQiQwLכbƴ0 zK%8*{n$+ME= Es~O_n3mCٷ$8b-/sT؍~{^BP"%eQXo wܛ\Y7`t9r֋DL= aupw i'膸_`tOE〈AU7WR,%TQZlEL^R#F(H5 P/Һck3$Wʼn^QDn ŞV^7窈/ jcP|[WtؓbBTtFv| x"Z# ƬJ}uYS@nj{=Wii]E)Y?N t/00kM'8z&'9;yk߼Kf9(tZ++=ZۃN82&MANV60w <)D M@EdXZC:N\Zhdk{r4L 6ܯu[|/%[x/@I/0IҦ$LOoAÞwaUrJʣ^M ?Ft 껳-OF>gjv}њHQ,~sqPُr'r L163f커E @92(2LxtotG91-z~CĐ3B)gg矃ae& y!j$-eK!oEucP$($Q%Oun2˹8m>"nv~J YTeAu`pȃky;@^Iֈ[IXE1AjB u ܐP#Lei3l%M\푇UAkx !0=Q3.p!~ۮ"/V}M7j#Yo:(XkoM |P{$#G{3Knd(p_sl_nh360"\dd^U'don1r S{2H>?c"_%}$U2 H /}uf"Aȟ1&M1vSTnBQ2 >92l%%%<+rZ(l^=ocsoˆ[n;7tl˭ch;aa^h(O. ᭞9. J}XٖNV }". _A|2M>)0>c-* e-W`.q.SǨ[ yUtA?;z5(a|Luq8<C}m4B;ʼnGSfh /psIĭ%=S@lL; e@AԦ<@Rܤ#hť{,}:$@ӓ"%%;2 ϐ'و'|+f@u3l斞k,WIݜ-77`\ND9,EGRtE?hr9ߜk;OOXMxMs/|dj>G `8N[c.-y09Z9 wβ!ыϛ{pu2$6OT -8lB Epn uQ?Ώ7Nuz̪8@L8? @J)5@&̪kQ6m_MMK$uLXUF↢w DmDЋg(wcaSw\<'b"..1tېar!𪖛M'!]2S`Tl t0,-DQ:" S2tThjpʸa1xZS0udɜk/F *0Ew> Kcr>,s$&b9>b*6:]P@e!>3w* z 3g_=Xvclߟv|M0j"r+Jq?V Ëߜzd_pí gŮu|ɟ?GydqR}rqIeOMvgG}Zk7+Cy @R V>2Xx0K>j GQA+aA5LkW7yyQQnC>hEeH$BRZo=O2Ȳt\ڸb~Y[:Ge㺩4ž䜸O#n۩&~ttȿaϏ)K3?qRJ9̉>$.BFE> 3v͠^D!{VDLrp5֡CulUVJq&aP+Ipϑ37_P$Z W?w#=8A{b)^9̈Nx4g-B ~Fk&K7n7j#8望Ni2 ZN9P ݿ 63(~g&=Rυll`0H*34]˟[> n Qsk$lX]E-(?O=Wvz۰=ft<3#0k5 n0IKy/mH#;㪴;lOI@`ޓRBMPq7E{FP#S@ =YX#HW;C-6ά"l/|@ }]N~o"dMcz1GHpdEToN|?>eJ”5$#@\MdNeZN|V@I'.c eC=>>^Q65c'8y؏}%Wj:+țY_ݦ z)APma5vI'k5t\Mb(޼ei =3-i:`V>s4%$ C%_m$Qeς}rH2l%.wBF/9h!$oSY}r7-%pջUL#::O/"vKu,WaxI؜[^*|Qͳ}VszGB)x@4T><4Mxn5}c?@}n?Ѵ WFp-:{yS> rCaN: *jGzhf8!?)ȔP8XVǯ5Ѕ29j&D1gn8<=7SMoL;Jd v~R(^1"{yu]Bj4wJ־}*iHK'^>.Muxa86DY]vTճA&@׹HԿ1r=˿7e}ǶɥO8R9Fߤm61Y>UU{S;|`tVǝ4i'Yk8-.2LM, uMvUeG%G E|ԛ3wN Haisآ* ؠ3`xc8t1Wh F y.2)KQ˞1҂_}Lj(hj"" AweVaWviת;e+Lg&q|?佣X2{5iIӳ\rDsVqs 99wlGʕjR3.FSٖNN$Ƶvfesnv"7nxj-^O,Iuf}ueƦ0~ ";7B'}fJ辗e4qT#"Աwqn/1R2LҪ5=(f7>C;qRW.JIp vֱ^?0XK(gs X)0)ΉsKƤ kṱg琹m}閌qh. }QsD6osC 7<+ו; U3!A.yݙ3}*zmw FPnw=/HVTzX*޼zxW/Y?DW(F8[~u]ϡYj2Cʅ7m e!J I*q(@ml6xR&TGd}a4>4Hl*R!X%δp_)tqpG-ڑvy/wW\3Yf`9T彫N^jl x-Rk Va9T{AdxMM;@`K1 xPdֿ ({ȯ?~qJ\4G;+Ot%;߸P! 9L( lbZbw(gfyOzşȐW3NDE_MhE/(u0$QoP*a*dS4Ya&$z*.WjPf ]q7`Io\[@dm 5,IX"Xj<|$!`B73`GKՃt4|Vu}{I< f8Js9 gy4o(b%Xeb"2U>aG፭w. 695~CLR5mlD{ZՒCɶE @Pik|0BB v,IZ]^Z^I}n1N ktXisJMI P''$a9eߪu"W$ ݊ 6Tqq;Bc;ŸE"c27E)6+ kUM?C?-p2il`' ][afW KQZ KEҍQU/TErEʨ_TsX!կ@i ,`@"yofTM#͝JJ)#HR3H9G) H*pAfO[2 ч+: )N-G\) Zy{{tL}>4 Vg\lftxa '_h] QCnBup=.qnX?=*]f$co{1 {N Ɠ&6$ORT~q٪t% r}Jp/ ..0F P}x+=*g>x7tJ@ =cdRyrK-s7s c *FN#`"DMA49M'gY/uH;#QW֓k@nוqd 2utwe7Vyb~yWDk|$6MԶQH{ו;ǘs̤G({Jc&+.P^?zuOɏ\& Iږ@dsCfAf}9dCQ@FEnhtiL}ʉԩ/w;?;oPAݲOϚqL_6CОB4b cR *Uڮv(N>XlP=Ȋop5/\֙bո`  ;/x)uW-f]l74^_3{EQ+7Cxf/5hM}9D{oybtFSUTyuNm6qB (ٮjfRfH6 y1gwue.7Jw7 G &5$ZtW)Y,rč[9qKfʺ.(nq`xegh䞜:F]+3(z^U}YddR6$u%1pmxRJRQ>o I(BӜnc@(+_pΝW$z n~x4YPKM*tB f&YZpY\RY;HIf?HL_=->u]H 6+a|~1[;蠜9S0[38l]NkxO6p8֌ yuB7k*f !7N-B@p;{ug?U:<اJrm I?( Ȅ#RRhB'GD:O}>f6---pOjL򎢖ΖRB+ sycY|O1pCdnju7 7jC6hf牖 NA81XuVNz4O,8_]"-r^fQN_ "a+ r]- 9E)/CttE"e.490[Ic@Y ݒ9:_Hև&hukƭWn]M]k4?r,4:D,o >g=|NZ+?MIʪc)K`ǓhIJ?n5ojoõ&XF:fq4"l>c6¬s_aer1~ٙD硦tt _Xܯ Lf|Mc X5rNvōKVZ8^C U]gsDJd`/{.aQF*)dy|09oB9"2;V܄%5_lzsۭ}}id+P8;y'zRZֲkf+~1YAv#g4foX@8Lsl1qDvmAr1im7^" uI%K#vu dsL@O&`[C@,+?k&0'qӺ <eqYη ip^>9c+;tT}@Vv Rֿp!Yp=k!09б Yx?v/]X,/q׭>1#|' 6J]Sqv8+i[LQ'DLe3@*&I\T'P}鴄q;U2vbǏSdGX2&ψIqJ#Ȇ_^Y5z L(ۈgBMoլU˜rbה1⓸xv["WQBR/_G'gS!bd"sź;]vCVrƌA7<~gfP id7 xgL~ZgS\TfU,}N0Ҿ F*K4S&CVҶL`9 KRf(C7ۍγP+qn>*LInxΧ&YlsʍąKt + *oK6?k6+` ,1BLDӅ"ز*s,:sNB?h!*um & 1i/y[gAmL޷w=': }~VÞa%ķv0@;w$hQh8@*`Q8YTsinY]ٛzy6loNbBҴb&3՗-~OGs٩ wH*oGlLϯI2qUzz\0+I'$_'Y|֓ܐ{xErfD-@/A"`qW|0F?LRsU,fQ|[  3 {N Z|&MS:[t-8j;Hظ%­ o?r B'噻ףgJ,n!N}Tͻi0 Vzќo'ԿpAH(Fф8Z^$m~n)jﳜK`m5YI*#h挅CK|bJy Q筏eUDD-/ɻ~*+}|BD P?k; DC<_9֬C(?)̑\oo-u>[iPBZ|MD54u:0S/5Sӽ8S"O2' (蜹 ]JNʖHkJȕ;σT)>U#m?g!X5%T!sQA95QύT@@ښ}K9*;zohsFY1cL;`?8khtoV0lpL?Tn)qͰ!Gp:ZzçG0HNϘ .ԇ[ߌ/!70$G[v/ӎ{t\,}j<{yv!+IX s´# E.CM  RL˦dust'8ȯ|y[&yezb^S/ëm-r?[$OH}e9n xfj rӁ9PL@"g:}YO;~c&kh:%ic?UQ֩!wC82/4]J=DF~(W87Z9}b39S!8ãBSc 6)Au ClhX@QݐwbŽxyCY935Fow}` k%B4Ӏ ;\졜:AykvJ'{3,^`ow^y,qQwd;MJ5{L;>/y]W}WQЕS[clĚRbx'$> ^f0ŴP]> x @f{Xafַ:m9EDxmxGbhT ߒV> (W:f"C^_!v|=&؛g;or5B,Ufw@F<𡓋]qvfkMG>WF*?j!/;Զ`XJ>#'rM% yϵ)/$#ֳ`Jp]LO+vwvEr(:q,UMj]? pY$ Z8PEգcEW3JAE(P "bGk<:+^L^g0~]CXɩEW?rpX(y l;4bZT're"/e7XKٻ4O[%YrQ,?obVSz54ђe+³蘩HHhPP`92; [q2nh@b~:!U| 'ağ 8:n,x5+q_.{Ъ(A {P-Q̏v46JHDRm:e1F?hn\"+`I2k^Y)nA 4:?URJ1d7cMjqe M>#?HTvxagdV>A~.!L[Uf< b^LB9I7V|(xl&(8 },tB9A p`GfGuH0N}ECz]%}:4~!2 I$.5D 4t]n߲%pI,~եM @b)8] ERlHoQ7):wB)e媺'0 %TmOD<ϰ:+хX[ٟuM$ Ә&|jnB>=9S,9` bvu,uz$ aq[sSfLbln9ec呵L)iK;\kXLƈyŽu@8Q%Md k}Rǩ?On&e ׈O%./~:ն,W & 80nw>X֐.i2p1Gd#m'n?OFLLby:IĈI46T0&] k}p݉b]U JNZkbNwu{ 墦|BhqAsk-<&Dq4; ǐnJ~ cRsR4i1V0HvYl@ 4Df]@~rNH\ƣEqhƊ'Ss?ڒFy3_!WAkR@rAۡIg>k+֭:wEOz~'*lj8)P ~[ڒ)mvtOw%n1l]dl2=F&~Dm.!JC([_IfRWpQB~Rp7j RRh@'hcXwXIC`P5 Rpi" RE|.Y >r}3k *!U(<[#J{ ZK STŎo\v<T yIN=v9%vKU2k9|n oZGcWyK3>#*9.)ɣE3r#,+_8Ò߄uq3-+@A|\ r7Y&>&B3躴3֊U5hOfy$[hmאQ S!xP,)@'6Yc|T[k~o%kzJ0U̖D7n ))xTC:e00q( lYKg PA>z?ZG4& ՘R,Qv[$ِ :YXG^6~sڱROFŸ5Kj-]f"GSJB?za.l~,jٽ#݀#c`\tMz0f#жQ^ WMyq٠>8 { X7lp fȚxP{k$SMzS;,(=5*9~|wQ1! ]Fb/ؘjuQ/aMh<hzeQAIJQ;KM${!c/m44WZ28n`ӝ5G\dE<yf+@öNpNrV$>,d#7~mž^F \_;Wf458%S2jenjtĒ D,Q^vЕMCxy_ 74zŕMesEgkDFh#-F~S)v4M WL.;wQ%px%2y YmFu>m^@=soxnl|Eb - B= sx9O"^O絑"!|e/TV*ꃕ;LĪ/i22ˎ\દ7GLK\]uSY,Е;D1=MT( S(gJHͷXĊrazB!کeS>>K9ժxWKcca7=SujRkTA s*6}O"8 )?fm̹EDQ`*Чl(I &})wAM3RĖ6 B{5"c3/:r!S*3\qNcz*sK1V'3I2 M /{y(OK@o8hMR~1LyP'xD ql|{ٽFb7YzTeJ{`7Ӈ-΀ AH*iV13. z$@ &1^'ޡetV$1|e4(Re4:ŝp[*H]Eui4MntS>HLZvHw|T^݊gf+J5[,Ԫ_ ܵm sF7١܁ޟ PlT  /Ўm9;0kSDK ЗbcHEkX5,IU,N7|O+خH)),j֞gثRKQJ7Yʒ2{4d Q;^x(:^L6͒1WS lru_,m[[n*`^̤^ };028W=1ہ,|wu)}]]Cjb~l|IRҀ0M_TA4? P[}>?.˭WYORuG{N[jMv̽eT`PkW2 B9H瑧#o`2Ō׭8^/vbh.oL5 }ڒ0p٧݅ALlȃ:4:vS̏VM'y QCX3)&h&OS,p)t@Rm;Ij##p;/8*V,g?KKcD+;1T號qn6ehl4:) LYjQaS#q/ڎ_߃z)#)|;>K$-<|ŸPBsѩa`H qG٤E BrGuzj 8YI4"炛Q+Z'86Yd,8ȌKa2(bk#6s# kL?1ųm9t1zs!fۊ(er2S$DO H% #>fǨBzQ5%pz1SΛ}'YDU#la#媎XJ?EȨ.vs/yv~FPZ\ .ۦ|_}ҷuіcBvh ;m3K. pvʱ>%)WP' O(4thg^f>Gc~ՙ<7F>(T V`!j̑iےZm3FpG&o/Jc:WZ//AȽGe<gWa䖚7ubоT]] r _< 5fm…4=h703 A5@_fW/Y 4NqxH? %\Փ}p?qp/x J[kY04FG(7{y?)g+6.0,7wᣓtV14 ; `gz΃-sd[XS[C`6T˜9) 6GueƗK_d.L5lT:w-pjwGn07[(xgq#Xa%ֶϢ:%pԷ'דl9)Eok ˰j/H8 Od?xqK]~t>ZzFt ;`c8~k+ZU`ϝ4Tgՙq, %",hWX6+Y- sSAZՈJ$3ظ r Xܗl5nRL K0Lco=wF7f̧TcJ=눀(:dvhX!m#%f||N.)KWZH60ܬs26b oޏ :iWuv%KDnp`٬nY ٵHr+Z?+ $lx6%"9^yuYQ*M"$)$WHd4yz4ѝyuDPk`C!u.Fh.u?a c]'9~Ũb/BN׶{hetm#X`G9pv6[wĹN%>nCBI#fOiSWHФld!hvW4N:&e_/Z2 zg*!p"ZhĂ Y[,/2g^aNŨ KNl6*^Hj|/w-|G^sƸ4cR ߙ~=wA6mndj!`ʏ'*]NSZGRv5űMP wpd;CJz}%WjV8t0YX+@ڞ6]'G;K˛IrGAR{vINlGĤu-]5˞ŞEۈNayMޔkճ"ֹ=T7t4:?卨ho!+hht'%F}oDva.w7[25!3Չɔ|j $m2(zS ɟ\n@OaA:ƙ*$2 L=~ ' LJ ajrhFŋ)x_r5m/l%Zv< S&&*J o論'{xI?R4yxz[ DL4\qOԑ9QɑI7BMO9b|HS&o2X!okE<2$8 IdޱPINQD] UG}?L,կ<-e }X0 FֻH{V..yXN X0n+Sqꦓ$浟a3$z:A_Jc vt2>iWP!4t]zw3Nd>4f!A&Tͨ4L7ÌgUiҢfxGSCAcJ6·9n~(؁K*yC DlQ5(%uѲ4 S ݄{˧>3spih ӌ>Lk36k>./$-.ٗNϋ3A NN$EBl/fw82~Q=F~׵a'&K :p"tRA5&'ךDžp& h]w/ấ i=rB1vDt,h3[+JA]8C& C6]nGc(RwM]U /~6.9ΡJ&\^:|3 . gdh6ߝ@~K/ Hv[J@$kQi6жݨ1^+>D])8/誏W1Hp,Pi=jpxbH ;Vei=^qd+{5|4k'֍1NM>Oo[u}Bm2y47dflU~JB2vN#݄EK[U@ '?vFY Pxiuwl%7}M^NUE$/yK/d- 4S| g]iM $".!#IT' \lNIv,8ЋM~Bqabr]Nx/[LWԢOK_{WAADcfK\h$kSЁJb;jı,X۶)QTM8/rhI0Vy>iJ<Š/O~Mn848D^]u]~Az伯S$H~>V^C+:%-%q(qXSNoṃI(( Gv_4 L܆ $R;+chf#DeɄ~[ τbF|)Rc5m2{#Z{wTpze1.E W5~J{i1v wS0 _0B Wq ZqFU>-e >|[4lP w;zC\\^T֩WdJ#X2P+;v|cq׉qK>9RYi\\`!o `vh̏?ԇhY%Ӂ"KȐnnJ|" R s_VR2RcZm -O$>" 6E/&>c>YoUMb;FU*Qv ëLr[ązoԌCѤ>WE_(Bv _u иknϮMnhaZv |֯D2h]~mNxvP4Uvsy4) BP43f(ރ )"6A𺨪Z#ZЙ~?b5uUart<:.OgwOʹOv|B`|T!qdafW\o¼{TƎ!T\H\ƆNʠVgTx 7FԪa\QlifCWd4;+FN1Ixc# @z_ډЩ1:[ԡ W)Z}_q{czELxZJG%*CDVʖz)qc_ðɈOMm|&?(-XQA[Vu w*6dSDS_D(?&޳Cf!Pl{H%c T}0P'[@PcK ev6aziVsfLoqqF7 M%!Sډs> ƅ2wv68]X/ԋޫ1H J^ ~cTzmUN.ʽjN<"Чϳix ?aqn.K9@1mKPդC}*%'Zms\5h0J=WyeњKO ܣ\I qW7P^q  !ŕ͡6%_\:dW4PlȲ?2igj:n.yv^>jDn5Ya>ZCQL q{|FbQ<W 嚴k;lPڭn~'!#a 5zghˁO(ykO%i L -}wϽÃWNz\f1j3yʩCB}mdKm6'ND/1T-MU;;2Ώ!wTJ#mm' H8Nn>c`$r N~#ZyUƍBXo')pv%koS@ aSPgW^6#1ajIyg@o9Ӝ*v#6IA]nuUq_ 0h ם:RpOZjP2\Gg}qa?@m2!\[ {3qKbekaEnxk:V{kEyֺڡ#c*SPD}K3뿧^TWl9nr7E̙ri:^B!m&܉F=0N|UA/tz'qGi6(њ"gB' M׆_^"jD`{`m7y=m7TP׀ދ$,wПs;D[^OVղC$(_ >YXKvehkqJj𶓨WL#tRq A  h6=)OQYxV,=I3Nw ΐx+i6p$D[ïtQߑR;{A1Z )e RPz`&r8k;1e6R&8=XWFd/9321J 9,N>31Ȭqr@EWykÅ|wP܎Kk|EJژ1wN2x jjiaQa!퓈ZF)L$Krبh}VR *{ S.5s͵g% TZ]Zϱ. 3q#:n Bʴ\JhO &Aj(V:>IdU% uP'\k?*sڋq *8easտdI5q[3XU$ ɉ.>֪c(y4pO]gyvk@FcCp֤އ;)HL'߿/_F51H1ޮܐmWȔdѕ{Q|4a!²?A!Q6o^N6WΆnAsA M0Moh/Ŷ5L<<_:R>es[AS 44ah-{C.ԧhPWmɜow'Cc&GTZhmKPfLq ؘG1DĢQ)'iG:j?V uM/Kf;%lܔFqQҶy;p6xp_R;_upG7FnHkOaĚi7aB7 b?!ʟ&d'vDT̚9K+,X(2Zq'ڿf,o`\WqmT!YH ɴح'P|_Yza`R=Q6ЮT5<_m{!]H%ZyxVܯs8{=LAM` e:U׹i@W@ 84K?B ҄ 'G=a(,GT Yi"& ^H-5_)_~D1$H7cnڊm:"u{I {;ݯe l1kR)}9l}b/S6~j 49+RW;"q"7c( R,͛|$`BX=F8Յ3Qs"e4tZ 6 (~`Ctm0=8d+mθ#uOFᗆijAxDNA> ju}r2<^1rK5 # )W +[R:f[P025\~,W`z.J- (y~o0үsmA|>~ɠglx`-AII3ęGN!4pbkLҿ,\]uPq;/.mP)iҚltVd{CNT#`[ G߇zk!kq,Kb'HȒmԨq>QÕ*Zwjti/<>-Dpx~HɶFO'Ǿtc> 6Eo cr׀ Ty~&YD9.kji} ]tM#T})76?u/a])0#"{,nk5|I *#(Iy@a_q`(:︻qtcPN~g kd97;w9rz7i~DsÅЛR | J1FXg~涫l;,DlD-h;G)mG=+D=Ou's^⹽kP;5΢$x!tPIk/̄`@@sy6љ?DG-MxP+ 1$ "=Tr~no039Ů?VwR3l*չwtY26]߰gf3<$8@-q0FO$"}6ʑ>^)atJۢDU4zuMGYZO>Pul{oŶg@2>!&N`3s 31.MYO7{4m"vx^UOnuE`>\_"& SˏJG3 l78J$6vDc2^*g9-Wz P>&L?#E,pC]%GSgIk\lD۸g&ez=Z_ ׁw~] l(ua!џ_HU.!\)o!3} Ifϖ͇BSO9JJ`ܱ-9$+GBTw >*I\8,/e67p&sWtP`xHUM1njhb 4UZL/t4 _{EG ^ðԜPVrUa~&J% ud٧ zsH~T2TxY $ԜqOIry;$L,+8#$H@Lnҫ(R^z,KkhO%DmNE,؎@#kxwn)&ϊԹ\T1SWwSgKcl5N11uA 9[c8+]@"!$tWG<Ԍ|;yzm;yk˻PrD_ISMjciŪmCp<̗oj$o$ Xi*kW@04c!0NJ f.P.5q8 ` JYsn4L )%Da{4+JѭY\ 74$c}WtjٔGFʓ6|2pmHYK+O3'^@Q /jGqwj~ݑaG ^,B@]BYRTjO숖|OD/&,#Ʒv<]0c(G`,/IO~$EWET8 tiB@wi'5х(⸵*I}{lCqu\!wO(fG*y[!ݳ }C6fcpfX$a"z|>MxĔ@hdfQlJ>`pʜk$0;Ūa+1f4TkqHlB-|t:P~tLJ%3#>Sx󯝞`jUF1RNlL^4l]`ѣ5R, amqĈG^͡TO';u'EԬ{Wy諾бsZ4׷(@/`9P$EEs$ %U)1K:2`qG̐Ez <?5*doNOĞ_ F9c@NlvmFZɞE%x8`C\Jy3-W^PyøI?Zk~;0[Gztu}>siqP r?37>nnWdRy2(5p|Ϣ.`ג<7(yu* <{Dy+!  jta*ZPHH5]/z!Jsc"KƎGyv4 Ʈ)$[?ƸK"h>9Uk&/N#'ծA:<%J+V0wj-C`bMsxGJw'NJ tVzNVؾ1O@͎f]pg)Iv 7&a"~ j2 yM1 S̷߲$9'S>|FPS) j=?f(( c)+t+#Y#Qb]Pjwe¼gryj4]΅SuO]mS/yUqĽVrlR8PX[KYB ^u6_qC < fs&ª8B]3ٻ]M¿!kHnH.`# ^4:Z*a';_WJf+Bpҵ=yMEl[FLqY mpxCq*%݋lBwO;W߻ܾ3)ྺ^i)淌J*mML-Dڿ` ;mQ3Yݍ_$!6mj\X&lJ/К6@Iq?=YLCG-T=@x`rV9|ҕH:KerIcO)(xN1/!0myѐy_#nIߏ9zWGB4oV%N;ߤ=f4['S)[Yjzqiw ĕU3g&IKqp +L&6c_Z#" Q/EJې /uٴ#ગhj uh gjB)"liz{ls!Ą9a \Çn}rb<&H#>֗rxsg{cVϬJQ5FAn}xh^s$Mp`7LE00R Ii,k62420s<'dL۽7/BwL7CXʙJB]'+ 5Υ0ɹ+"փ^:Uk@Js< I絆Cl'o[@;DŽ. 5+C$%o@ޫ־^5rupȲ$SlpA7gg|?10n$0C6z4M8r7;r$&F{<}[?x8h' 37ѵϛCmtd>;pWcq\Lw*xC,A.<oIܣ#fycacFD"f&l1)|_zqYk 8BM;3_磬e z)'x;P[i't]M7+G3%%Dc519i<SEnr!뻊4d,=yzK1N:9:a)HHn!tqM4k'yͰd, Փ-&.j0;O ISgΌ DAQM?s[G}So\ޏyf?&uVpj G9@ [7OlaD'^OD-@vJFϽZW^NTk%3qj8`Tմgh3!DGޭ@탛S=(Tzs!ح%[wM~;q,@XE~Y]̷r: B\>I߹RWzX0{iz;V0\FUV%0*Wu[q\y}SӪDiNt8ަ;uB4%wyz=@%Uz֌B K/ߔ3D5ɤy6g(d$|D> 6f['Ǵ6nv'+*{Ez#b[ Hm\ 4ku?і3GioKe7 Mhskn;*rKnyXm>u+F9K.b"[Js5HB` p4\x E;aEϩӚ 8R)d ]L,k$xaI|oƛo"oh2!nm|jJNVo Okuqc?儥7ZeGpLʾY0fhĥT$VD7k:#C+Y w LY)_+9[M Z+pȇ8n[k:ÎF]IaEvUIdL&ɑ'Ur"- o9İ<>; "[/,),GBDc-? ]="cd?8LqChR!r_&AȉXۭbC m]H%n#Ө4 YVO[ <^` 4X^iRqlehBQdJC`tI(Rc$-a=:⺣?%]FUr`dqqӘ[J?}[l Ok|40p/?.V0\kCgWځ䀫FUR9KͰOXCVhܙEx#2RJCh߱TDƭ1В\3T$j'du>utiCśuuNPbH &}0fo8)B"ut +~z6aWY ~dH(XT{ɠ$#ʁJeגa|9`; |'/.1 :<$_ y^_;LdF]ɸ%!>`D_2:͜5MƈLd shO)5Xv*3)I yy4 JI۞R<1dtFN~=G^o6٠7nkmn*"հ&j O74aadNn9xŕ-#˻ |J0A,m :3hnW"jDPYuNa,^.Uw\9X $LVY&!-n o%<楢}m:ןԏ@ȗ(^koOrd*&CpzSzui>tİ%H7:GGv4w`4lb~ s"ʮo@4]Y^[2E2S"uG yQrnjz(T.s۳5BqC1C;';3 ~Y~* _fhCk~)D┢`ZZwr5Z'Z*xWT@^@S@|^7t> n#qk"8t8Hx66>VU6?!A H Bor|P.02I ٩1~&!th CIW]am!b FOGZlQ9(hc0 4yOïi 4D5~ Dbtz1Ebteɖ =@ DlcDuZ^pot(IAQ0R.;BP.ztu-c2 KQ"{*ɏ%QRU~84;?j.[C>֘ ?$ CZB&,CAE p.Ƈ\Ȧ%2`z̕уgט^Hh|'ǸK,ŀy"RlJW;v#$S+@zD aәȄt[PoJogzn?`8,ieIa&Xß^C)+Azf) 4Y6%hsETh G=cJ]"^82r\2miz<ٟ)C9Z yF"6e!:쳣RtAMD!+Y㏥T¾yR/'CjS@\8mN6ʠ8Nz- mUN@{oVw{B!柫D\eq|햣2J5n>ˤvy%sq*9S\_J^qjσx.0bL%RJ.ai"=d,Dzfp< Vѥv}vJ}f>)9Q>$W9y xtG'JN\tuss}{#("NC40x3r v5P,lVE 1QSbs>[P-Ǫ_!P}GDCB}dV¿k*r08m d#^S&jO4}W&&cpW9LHU]PDMiABj 8R@nt8Lw>R X;.DQSDe/s-|~[+h U^\h D}inOrUڗyጝqN _S{t=U2HEnIBK"&ޑ>k e2 ^|3Qϒ:Hf..LrN1yK.x0W^0)l]‚lcEB ?~6]:n *#o 2xsƷ_aMmM.a~eX#+u-^]kAu}aۡ^GU|t~^TpgQH,Acv^ff6p؟22+Mopv nů11kۤV@>Y<_0&RiC-kC~߼%SzXIR=R_\ߖBe$}S3;6q2%k#AM(AҤ[y Tqq[[!p-dZ&Rx 7IS*?M,}doI)uoPglסLVPx 52Ff$*vV|㩗x011ﱶp|1 &>-ͯo\OrXUpFX<ͅG#Q9Qp$/A&BBH) 0&dǃCQruJ-8Hjj_M_ ,h_s2IXiuy_L$;<[͹J4eFIccc.Gq%aI\u{xUA("b@CK#cIϬ>=vIe[z`*LR7uO֘̂Tڹr}.9LJuJq߯7h+\@PdqL%E++QQxo6_׭219'n0w0X+ŕ"diȑ2wdӤZQY8Y8F#PRܚbY3z!J)) 'Tc:0WK^|֞V\@KJR$q/T=j˝dep9x7C<7{qj (4M锣[pCDsla>ҬDTmӊO}GLw( 13စ.v LEs9n 2D*dHhV7rPKnZ^=G)C,RG VOJX%V)1Q,QAsQ!i5r٤U縥'j4Be\p~ CollU`K5(0ԕt$4n{.έ߶9$Y<@ tk2Z)*VYhg F(|j2$ Jrempm8|uյ0a<Ь|-ZjVng^;ږTm5&_diH-樰tu@9N)ϜlWN ?>X8?-zXE"`KKn] [!%W`sW#=h\_5 u Og|@,Ԅ Ll9ks>5p V,TӾ\VaEzOU7xVG'$AZ\=Rq3`ZQOn[(Yuv7麙yo tv_kQJ[}CۚXpya*?4l:Mu~$mhwyʳW[YPG*,} ~h{F!5hfG$]j]Xx#%u=WDOojp3^T98*C7q^}'@ԯbQz[JXpVeJ}T2ũx骕}|՚h@h㮉NVY6}*W;/'KYY/ UOf hSw77=]M[=MлS/Yi}:њ[y܃'OdcօEDT|316Xin${qR`/o{rH a<aHOʱ^ڨf})w̏i~{o~ \$jB,7 q9vSmbIN-ʿi <{\g]¥ZTpvWC]$dYLk9J1&ʇn1z->߆#-Y@TB-h# 8IuhgbV^n1oE ņk+Owt:I=zQ(1mK~ VLV9'C#?{>7p Nh$V@@MfH&s[4#'L[ZIČGcsfh*kV#K#8*+t='?-w$qg|ڛ e9'Xx1t,;˗$]fK601 rQɗn姧Y 㳾L;,P;Ҕd\#r'uP>%&9') ]!2AWQGkܙ!4xJۯzՀ6;r -R06ɰsuc $Y8e=,ic_W"|E8ŠF|ˁ]xnP<ֆ_a NpRm vuhc ^ ]),X˝wEO?㪷ѡ&ڣcmG"Fݜ/^1g -k1eI{ Q/h}ݗU8+e+ӓ.>rX,,=59Hko/x0$rKZR@H9ڢM㡫h-7mǐDqz^"-}_1N|w7Vr(~k})*42>[8/l^þ7KQn4p^Ťtp?)0hS;2$YD\0B*OQ Fy[1pD9٭ᚾ Eڴ{2Br84svHUyx @.w<# ?hc8{1r$jSHŹ (;{m-x@߉`S%/5&,-x;6f2jkVqWEUSaYfL3P/ȳv ֖ 9E&s)T8"JVOZ,.Ы~8.ĜȍHK;Hk$ӠUx#*|WFi5X ق"#T`iUg$X W&V 8WH:13|5& NmPL}v#~-b},BorSEw5ٝx!kwz%{6Q#뢳eӞ!2ŷy^{YuK5~Q`>ez{hE̷T,i-Z纰*_)T@/N2BcmH@)cX?bZĹ–Ϟw_țJ[p:䘃&,wb!F2$ae]칊Dnj_(˃w#> u_u`~5qa56 t©CbԬ""K̙֗n^\>t+\4@h:0$Sɣyvn[Ŵ0݁RCP/t1?zo-dב6X i`b[9jn4\|Ntޟ<~ K{>w<7mP BD_[7с9sǓpFt2_گ8(.ro#/ Z6r#f%|͆srX'?fXc0qbSmA$&ℎb 4A6DP,zeohXi˯AMtkr7n LX!d-$[+ ME1 2[$q]*7 y `^U^.%U/#0gg/s:+: C\h'|:W^n9 Xl3FhrsLctܕ|l_tC:e1AkB_,{`@7"0G>"lY `XMo3+{3"`+Q.]1fFmc8?ҡA<7qUj7N_5\. M[cFq.{;BoTH]vF~ԡ=?4y<[~Aʿ֝~u?.`%osMх_VO*nM. Rx_*kuz;=,[[^CO{@C"sBSt5uOf1aw>5,O!b4ɫl08 (~*u7V8Q`txG!D1/z?~gwF؛W~T¬ԜKf=A?gG- wM?P{8kѧz迥Wm fP"c1ZKٜm ӵ܃H=])j>Y4 %\"GxdxHFs1U]#-=} 4:O:%jҎI]@PE{e{-sᖦY,PkULDbQNcRIh h?t$ ؽf@N9(*sO>9iC5z7|ws$ a=ۂjqr_K|Ȕ֊"^)e$Ų$p÷=Vi99v3_+?`l!r I&,U`dx. Q(+x z\=G8٠i=H&+{6&L@&20kjԦpA Gc.Z;c=C:>JI*Mj@c|wFːP)G˔iUcLx!{4Cj Pu a3Xp*^~w1 SP g3?+T'8u 7D컷ÖfCpf]SƓhٝSdAFc:R p՗< uQJR(bM6kz8㌃ } ,`..圥Ql9aV6~FUl>=mpr٬D\&Rw ^IOyw{/wLHiE퇵$ԇ64lH%6x&OO:FR"*F5܇FFSyʼn/!S-y ^ lJ fu X65B I_6LVQS@dr#ʉ"/={}  h4`R|Rm$SYng1FRqttZ`zD}v_T*b%r 7 .ZS.R6[vtQ쉇ªѢuwr(2rq`i?:XퟖUW.C)4hί;̨}dE=%E{PkΝ2cBMZLNiiXLyt_C'jOSm",ׅ(:;n9ٞO=ŽaakBWV6ܨ\=nS~U ҍqS) 2Ýh/tVNcR&vXK`04s|dTp}`P73l(~!L<ʑ1N{( `4lœCph{D* ݗ($ >d=vXɐ$<-J9t @d \)iYg#!#(Cx\{y ݓsKڲt6922& U0씦WcN"1gfAqUoJ^1b/֗.E$Z@xlou-=c::;ʶ٬Vm;K3k ܥC@c##㳩 c_ Y4){%s=3~ 6o}6u 'Clb.Fo4kGDZ~'B&gEJ(?MKE>ƽXvcC;]Zɡ, ~O~ ? ?Ŭ'oV§'2ЂEwM"7K)yg?S[QزvR+-$JfΆNR+aL*}am8FE%k*x˿qH\lXC#2^i=;s]w֖+43={MwL$<:& Q}{ekZ"x?HdޞY.BE*`xuPSݢ诚U=G"֫X0c[oD:dCO9n>#Dh=陃=m5blqy{wVF[1 =U]~ (F9BdFʣC+QΙ̏C()n8&GD$X2܏̻YmMb Āʕq3a0g(YF|_SMyYeys A3*;tIՍ$WčE;-XA(6~4ȎB&YCZXW'_d05iJtfFUs&eV n8z2f3SI^\T{+RH6j%[5(ߟ i}&hy%m#AYIlV#iQ>mz&XVџ3%?SѪ׿| vBc "6$m!aV*ՐjVPl <3vG$Q4mF(21m"$(MAkZM{l+;rmD>A2+-{#!TUڮ{ -k~ǘ( c2e'@"ʐ1\3O{!? 3 I@zU!Qap<(&L:Vϼsݿ7qkpɂ^疫;#9Q I-ВGB$+Mrix"1e>XH@lŇGcIQ+_E7t2* -%UJ*Y@l{Îlrx^QORD]KQwf#4<6pj+/8! \>[bP{8f}7xAb_J/n2~L z*Ǖ4_=#D-h#"!MI*nIRØ;m2R+M$S hh[72pv3 aWpNh= C.X +GbdV3ʔ_xѣ>S!D/!^"Fԭ͛ː'Cn`i:MuO\h$ hlR5't]& Vvy(* k_Bw!R uH ^1j~`J~S/}}Ώ=NyڼnQr(-B07&wtZ ^з0l"]0-K= $,ywLd7ּ6J,ƏXV^. ̮y!EHHs;&xX%K)HBNBK4Yָa|zݑ6nfh߸;:GPoBg'J4(w K?$x| N qӍR@ݧ PS91PR x~Z4JԀ Iu;|]|r[iS| 轀  djr~Vq/Ց9r>ngPo:a9Լ WU.FbaIo$,ѻL +Dd5۟%´t)Sߣ^XNkS\ eT~AVSzB|iSf6wHTN[z$uΨ!McwȪ-+ N'٫aX7aYՑ5,9ɬ>+& DESdZ8&0-Ny͚H<q=ÝyjH/c ŨdJ se~BrNk)!}{%HZ/!Zz[hdce,w f_Ǎ%$0}䯧l eTaRK`5f[goO,Lw%M¦Y`hº4\$y{K kw?G #AuF+fO EŃ0]̍.|TĽ5w6T}C)ܼgFpB~aκLzѠ%JRׇIR;_,E@f>/ nAośU4܇Ai(uNʇ* }CG@b 7l(EjyX+ah9⩶ gR*7ߨ rstsqQ.0[FG;T1R-avUsmycقשBEX"*D0Sa:J&r-2jQ&[ȿ'T t0 igpr_)'ZRϩ?լк4̑jp4(@,Jjܧ(6q]5U0v_e6hڿGEP׻\3- CtDuKN:DAŁM6NqmuP/ uMv+_ IE1߰H݋ŷ'.,w~'1<;, ;B~L0~%Z9MIh2RdKEM Bj d°{ MSpYH[ぽzAAOA;XE܏/An{!d7>M$Ɩ|pAܨBF3I `|4VLU=8P)2._^]VC1>ev]Sz)7GU%lǗ y! T+f) sFz[_;qVti!/~Qb̕]AOHIJU18$¬@Kpda+ƒY>.G88>J0*Zm3cO=Õ 􃀣+1l!N _jg"1C,)|J30e;;ZR~Z)r} > tm5Ѿq n[묹 rxR= ujNsYkD]1MOEn*["^#gtY۟+ޥj}ܙ}κj(Jb-&z^ :u_?7?,t}[aIK/ |ƹ셄.w"Hs/[M,Eky 8W5٠d+ttbK]_ʑ{PjN- as#= t iuKR$o7^ B>KLRQOb6j83. 'Yу󮰳[_R|QsTkI*m `9<&ncqտpW&Ut9kA+)[8ҍVVoKC`)Y8/u_=:'N#PGj ~" WWr| r= B=Wu8YܚDpte 󄘿B*" y?atL%՘PxKxjMex - 1c*uwÐ([e%6g]Z;l 7vs -FGER&̑ݴgb0V'Jf뎑e]Њ=nCx[[M;=I Gt?u ċ'/=-UQ: ~SOb Ld$e/Jt++@)[s?"B* ϺAW4AKàƭ⟼fkY؆K*aT$!D}G|˳Fԫsگq.ZdbY&&0X=E{ F%}&qϺ &T*~@%..U^ڐ2$!і,݆}#V7]QRs9{Wn\@j[XЎ4/6Q@6p4|]'+jxx$ryf_p)8RHdbs 6!u k/w:^QqG$ocia򳝔/CTnݭ ׁWxxbFg4Wj5:Ėi 9䍄5L\qY'|R?U.XfH'Զ2ɼ%DžD]ulZw OP@enC^kxGjL3o2ڧXIJonme|&-ʐJѽ @[?# ] "kY xV-{7٢~cлӺþ|s.x-JJaQp x3}lwc0" P]q(AaKUʱ|VeAˈ )6+㮸-i, ;fC{e;,# ~Mdfo3Z0fɤDCňZ"(>xNK 3M<>:\A{jz9LڮM6%Xii&L3x,TiCEbx#Dv({lͩ%Bv°pON?RQ"JKAJqALG#.RHƱ,4yuH!_7jHu}>EBV{/Mx5l7uENߐElSiJO/kaS_Da oi7UZ[\|]<n]m]S;B4< Ϡ'VA׬Wxq,5 Pm'dŒQYN͖mw-:h{Ӓ8?|&3,$:juL2>K&\1z7f Gmoy_#ʡbhD0Pn1HK& Õ8'fBl5қ( =I,GXy('tanO|3۶^kc0 m  fю3z=mNĩ1Q>S[>1A-roۙ*C/`7i? _xI$E#)8g8B܇ :(kr] J|IRL5͵e?$iǠr"uꍱj?0"lНivǦ+7nNR~2oO#KYQe;؟r>Z'K'ONMg1!lѣ+^޷Xi0U۲&veNwqgKjvkW/޻0ߧ!뇔satųF殜S| abU-a!ZYQ"YBЌX=[I1ZN1PwU]6L W%È;?ҬG%̦0uvT~P xdN1wvIN(mn7c^bZ N3B[7 I^wTE/0 8; jR+*4DvӑZs^RCSWo dI3MpɚW`)JոX@ G̬SH{;-*~ƓkNmD3 Nz26: _̞xCm`Ű^\#>A|zL<Ǘ)h^qɵR w?qH-ӤJ &}@Sumk QC!|׿<- >L)+T}|BgP䘓.|BOVurƭ}Y转&s}!0*5NP_'Sܪ_\Y]Y B]t ..FJhz@4`5{>W 6I' fx,%DZD>nݵ:"91jd#Vv8Jkj퇅anX̀p|Dy\lhx9_(?ӻ:߽¯nP4=@7ܯЉNIAA6X}Q?C!7@o{L.U<C/Y3^q ֿ$O:mu8-<' !g$A> >Wx :=YR2wj!ܑ6=Ha!*b&-Z0?kCY(z'46Z!Bdc-'|8^/ҎhFiVx654Y]~6z:nc7AutcXw-0Q[Y6 p_C&wp5 ÙZ,?zLPvMՉA@hV G*m)I឵Л!c76 M>/XVG0/-9 R bDuu"<trLa6PGۢE_ͯ 5(ɹ?Ft=a}kϮp+k¤Uʲu knjRnh~J]e7ʦ7\Lnhf߃8I r=āMV[*I_R Cri}\z.CXqlR>N.rL c◧TÚ l̅^W[6˪_e|Т>֖r,}_ j4s@-`s!u#c!Kϧ^Ķ8 ~c+Y0A="l]+ +0bĠEVQÍ٥ؼY(/C8]FUp6al&y@!/|VA" oFյK8kcګndɺf;eXLN5\{B{8;Ē6=\&Ql)iӟV[{):%e$/qǚl{PiW]%9\+1 qhSuS0 &'.v%ꢘB$8G:-!ڠ VUn;RM6*D4` Ĺ*Q -aWV\vt3ZHH&ߓ~y!5 2bGc@ k;֗5 Ywkή]ɗrە׈ҪoF[3hUh刜48a\5_\},'~Q#'ֵ 5ZFp@H%t&% ^q|Qe TdyhLtgSI=AL<}cC9U1<`o[F˔ml]z'! 6m-=V{Mzxg3vlFl P*j.j>m(c.> ieFf[k;j?jyn/gl}A|!Kg*mbp@hb=]1^ΊnD>N4W5d녦#9jr=ݣ?:2$k*ȖiK`HccqW`Nf*j{9JXob{Td!/R{n? (HBx\ա(n8C3S#iX!9x;cB\[ֈ䶓eJ ?uW;Eeki~0\RRkNY])_OMOf.?]103N wpcـe{Y,T|E }@;7yV jSiJ;2]5nZ8Ĥxs;?~C X{u29L(wyܶMrT1  4i 3Ba:j hNȇ AY‡ޅmrj/JA\ЇG~)F x$ՔJQ:qUJ.{p@)sCnqp5hM˶9{WtHi TF:VI&ȧԚ ]9;ۑU1#6,\ߌoJgbn4fsB_>;[Ɛj>JvWyvGp}¥:T"rv4"AuNp "wlҗUpHY8G)MW+r O!DX`&VB5ObFZ3v ~ 7}~X=rCy6~wR5( -"ߎ8vc¦^˨/b`&0Cߢ9 [vUy(BI 63/n-ȚuQ0uNՙrg=J?RzUaxEG$ᅜoNQQVI<;wQ释nXv}UkVRGO;C#&+&+%DINѮY#|*ʜ'!M81L*B r-?,69uZqJШbRcݢ@]gzI`o3yq&sQ%oeq|9 (lH 3s:-Tx#)QbPde]~6W7vyEJ}X_͠ +5V쀎v~=tߨMCpv\ՄBe˟ßЩ<7Q3Tw8n7:h0A,-2;oLT=gi0QS_sjJ4m3I ;fTqsߧ><=­.](!L1Q6ȍ'P79Occ7z!#eO}q[_ˎ&>КDl J3U>oN&=]ji#ή4M;C )vqXbhx}W3P N˵gk:7WF)hl'-ý_}oI\zEIKimXH;ٞr6Y1X-"v96Uv!(,HDƞ-sy= Fp62ӌ7`"r3:=Wc^{"[R1^o=y&9,lפzdVul>2MWw.o-Bdoa4Q2 I52? r&?A0joYlǞ-/RcYy=XEIkYm&5Jc{|]a1&mmOWx -1d+򿓁Z{Mщh~65A^?5 ?]Ԃ0Y%@x2% 1$j}Og_5%(cKxV/.z+vμ_n :t1Rbe5Q l#bKU,$&xrK7^Y: Mfl5B1E#y:L޽\( ~6*~g"9مQ%$oG#ĥ깖E'[!T+}gqs6 w.==X`)RT Ecnm'Rl4 GkuǍV&?ٹ<_ǀaaNng=߇7se5p+8.5J[HLR^3ڶCceNRNfw r/trѾ ?/p L%*xqkYwPt1f ݛ_kv{(Glޔk ĆYxjBEk8.~iZmtE#Y*39h;F:;S&$U(eB ]slI}ZB1DfTd.ZmX3*^-# &%XlykF X]V=?{̳Ë{XHP8鹈1`GulH 3b@&`*b>ٌ)38Mg+ZE_k?1ʄGPI&J {48iJ#{̆ApYk'/d牞e&S3Yk`ݾd..ű^cH0MOhaXvqO-g@3KޠTe`ꤞ\^*faÐ{,GOX5BlY'6q|#0Lt-H/%FwU|fǛcL!^ʩR7Cxbf NKXxY6Hن9TX}!ށ9y nӾ&S#ʒg۵M4\hCii̗K#ʺyVhG҈wOdޓ(9S k2WчnI!HG͕Gtțeip;g: Pv#goiV1b|a` E8j?[٤$Pv(:F>Gh;Ȕ oWTASa=`I5Lrw|r)DGrg@zF zT~zd..$t7MZVaI20q~<e?> VR3j雐;.*+qrs?s .NgM#_0m/i޵Wz}PHs>XV .@ҭ2G ǂBM:r}mrm[˯?R(?E=.Ku4Ț2ְ3k<; 켄p#nH-u'R1w* dx~C;iSF ,.FfEۇ! ܽG &$daHKoC=oN&pXE|pZ3xd*nzʟřudaVjV/6iXFNOu#E<)_55/O恏KxtHC xԘ©ruFY[w%&t$zo=a g+F>M1!Mm.*2]R13Fe}8j*k@'D3f3d&R] h-A [(Q nC|~b>-XSJ<`p '` _gMy)5 .=xj[)'_H_^N[9! ;0̈k~ޅSAL S( W364wO| ggVFѐT))^M+2z-l\ *r:K0eݡ";Hv@c QhfI*8F(ڜ8KtgN[kavOۖk!gx-hd'*CE4|Xk?v!>OU;u nZWBu)ӆTNԴ1#@Zog9b5E{[Yt C x12g ackNit%3Isb# LnbjbPVYnsl5%A`u;0B'CZGG"Fn υ1*/=&;lӠ]*TI7O0rdӳ(ՐE+ glN?P^3Hdž*lBfE5ކ}9zFdEga:+D,(ڊ\N Ѳ fUZe\#1]P%ĔmIJsp ]Sɮl;$gGh2I/iLyq^%'SZ/|j<6cwuٕ+-q@j> K1$$LMbi0HbD:#~"$&FByU!VAyg Cv08Bw4Vlխ&:b9IMyq̼"#Gߟ6#IN~&,og GXiMUWC:ifd?QkǟȄh3ȽvGJˌl_893 8ae;ևAsA%Y<%p4P$Q[dFpQ<r;+cPH "4W9Xķh.5& Me,娸Ѱ>WЙRR˔A^vEr`K3a:~7Va1"OYyi nr3/.?]#~V-Tj2d!w|tF΄|MQsφj^!fkrq5,n']bNBP[[6. }' o(f]ጡ<-+׆64'NTiƇ]`D{"5GMo+gIe% " qc[%J8{׫Z*³X;+wm_4Voj"*d"*VԲv*EicπK lHG2o$ңf=|"S+q 9,:4ƛ22Wض.>(D} 쓝pJJ*E(aZ[<+&Ca-h(rne\ekjuy)jzLS:]vd.̣4bg(lᅆ+ck5O!D: Ho_(ٯliZJ2mr142A#pKUGgLF{S_>iߧc G nچy8W YZtI6VxS2nm>חpeob=CNy$5yMi0x:2jNK9lS9AJ+Ù>nl?5.ȵ[,YqC@(=Bu<ftRgZ.k bE^t . R=iD_>:q!ѐ5tjX`_-?6dp>TN r/3l;ي:Y$(WL93i| ./C ڧ?&"]kKϽlpwt'L".+4^Z, )*J~כ܅q!uUK[͏GVc',>5d%%DDTX<9P90o:Q_7Hu5|4Iex S.E\C9γ&b`2 !ZVq"=dcg tG LYm$rR$!KD[թbz5#0^_6k+=BM?sQ-J9䊴=*:s~#ٍrGwl߰sl[xL}{ {hF{M|*^;NjKDYr `'&9yU3Aw[Cc Ra;`?G,(Ccᯌw`5k0#P0,gAHe=ڀQB^?QAW/*LeE #D:cAh ;ANvvzRҷ'ۢ\ !j"_WiF}BjL??.eGlOKl/b vi1Zt; Ֆ-դ_]nڡq*ƊiANL^+V~ij#-55;R% 9#O0.-"$fR-yKK&6CS1YF[o/7(YeF@g㛻p_7dI^SρOr߂FnWo1of:) DzşK й'do rI0=N%WLߚYbt# PaoŹǼ(W!t5་,^U q'Սoy2]Z˙qFcM0t"D+ 5 );҂Q'nQHu3Ue99THkT.᦮TսjAuĿ,[.OG.ѷ%bܘ^FC(${ .(uq`4!v#iGRH(a' 3mN^1bF"(ifLJ 5D,fG8B0>O'SB6I>}"IO ͯ`68@P]STe㑪*HH `wFhq)vi*j+Eā~V.4n/IF{H9Ggh]{ +8}A.6Bp2VbfS[vƒ0v_9SBbX~fvŒJ;EnұiWq?PH$'Ψ^maL^ᷡo]?.QNl|IC7R渑|K4t'̻.*>|?UW`:Xw"AɶՆ̅)&^$2dd9 ^!~dyiְhASY.#SXDvCeI?htcPPq\'FI5W.+j^k]c czr|fmqŦFZ ZI>Fȑ&_͵Yjw' i\|g& 8"8ZoL+bg/!2.PƢ s~Tȏ|KfFuuzx6:XC,u-wD6 7:E)[z5x'JkhաWefq~ )ȎpXkrڼ\^xmHY(J3P;LX Aݞ⚠ hn!%~&Tmty lx=Vu4{bQw_Z*$^l~pehTN& Kh3Шc$./BvWHUȔCVGܺ@-#vYOl9oArގ;ItXƚ ˫];PNDž.Px|74s2=xD=@LSqEV$$ =ԪZjףe9f.ƻMV=: dK.LY42̌A*X)KE?) }>NCuxe=?YF[G^\B3 ϣU :NLr}E9lv C,h 8opItU\bJ°#S/ou ~*aį:& EEqtUz*-bf8rW+,X5%'ecY &Q2rPuPמ8 9mG[X>՚ӳ0{6*.ߺWZ♾JX kq]W6u"%wnYy`_PE:\ %O8 GWb~_BX0َn4Գ;B<܊D[) i©ݥ%3p]8slQ~ZHCX6}aGc7r˴0T Q:jo ]? i`5)mq ؁a8lǐ.v|&J<+#sKket&<]Qߠ;71ZکGF q,HɄzZW (0p$TRmxYhn}%.+@:nB~X'X.H,`h]ĵ%% Fg2tXyܬ2K:T[ )KZQzVFEN^ )iBl‰jP*o ׈Os-;%u7:WKA.l1,2{ \0㔅Eཙ;P|$Ny@vсϻ_C1f _ ǙblY+YZ'׏UxD X#N7QnLn9\G}4xRclӜ'8T'duRpMpr/s{?ѳ!y~B(:zUk5 JphZ꤂>3|za2:ʧs? vJ;P3+u'f.T9(uB %OY60T(D(ώ'ahhl6gArwrs^MADe ܪh+r F L,ۍb`5TDiD-rxy-S-WG*v6' laArP6KBit*M_}4?Y*5yOKF||#~cThӇY?FK~ ].zZaua_9S%:˾BHad-64{yneÖ\~By?7ͱ U8짇ժ J8&wb֯@F7$Pz4T^|E]C+uvW-X`q(Uo KTl٤c> Z~aQM-=QZ c{p1E?\rz<3Pw< 9?d%^#]~K<2 xP yE]&w(;kIuBNO-Vruf*L9|y;cuh gA 2q4;%w%`VG⣻ Eі9q/d50lV;'[Oǧu$ P,^ϫjҳ"pȳaȀCo~͹L r2mVuMtvtHjJR>^b9l]c"HpC+{wrZO65 =x-## vUS꬜V]i..CaY=)r"ZN騙̼>SR<⠙igԇwS_N-T? #Xԓ(0Ne5m)BVpII# 7VUs`35ݙ7دfbb6ϻ6tlTe" ձU=O|Z,d|˲k͇1S4h^QDpzH֮jak-kU%(WdY8}wC& >D.!Csoe:)ԯa ؓ QӢPw*,ax![th$VKBRGz(!TN盁z=7EkWꌻ:3By;~8՚@/Au:V%]eDG攩,-J:S؎\W9_9M GtLbr %)zx5 <͓_XC`m![xQ͉g[ fch>#<&Ke(Б9{j׹X.\JZ8 '捐wcOFMCMPC9 N%g@G [km XuէJ .ĝD e^ szFcN=g?+~pֱ-2D~3V҄ٯ9dқl1De=С>4XZ9Ŀ*挠&`@/[T6uKg2I}[C~Őtb^& W] ѕVAɩ}GWdzG&N2(.}7mcȴn %JzNΪ#Jr|cMؓUʺϹaZ2}(@Uv w9JGc2?drKJ|DToIV3e#û쑡PovNL1@)(ڄ_$MxG(J&'nEg}+V+l(*,DnkU}5 J&F`(*ݾ o7:{lop5z䰜3NjV>>CۯE 7Ϥ Vʤ$܎$+u| U[J-hzSfHb -t,ͮ] jlPmu!W{Z"Q#JܪzvHZ̕V^ɘj`XdBIKr~298YPVG<xnj^#@"zcVŬxn>懳Bνyf&]WAT-S \#>>F"t,i!(vX~[Ȍ+ :ҙF&U ִ*fo߀71P |01|k"ޘóQpr&miߒX6s;q>{yw/%&wP [OLe0OW^ c.Oa&'8_;o`:(5sw "͑dv| ZUqz>bECM=ȯܽV'٢[A97}?|9UjT+Lcw  < ! **GarԴmqL0*q_Ou~B"C9e󜥘lf򱂡<^%T``nc!mc)lZT#3; -u͐hYN5}cz}_۬sٕ=HmR J 0ɉ/43KݚJd sN`l&`;(8V0 lb'(BhGX!q'|쳐rϦv . @*.P=X^qv1~5qz+[%22K mBQWEϑ"<٧I?h_(@d#eQf5MbLuj}%t2,vBK%UǦJ%FԽR f-辍av҄^S}>yպ5TURlϲ%\_ ]Ȑk@IK!_V< 3qSM h8Ը_f XG='}IP,kMǯ{}u260h)vZ:RB~g(໣rɍ$D}@0D:6z7)eIWE 1riW1\d |%cQ0aG ة~45Ogq=%VUQt)BN^}ǮN4/LK2Yim=?Y[8;eW= X[GC_N%/;C rg0,T' sXGJ9fM߯K4w;4~:*׋WtCu*8|ݽ4=4|嚀i+ ]|Lv@dS8 f؉(^f+}pԭBxӻܕ_6'd,$9GiDMP5^]"4i}F_"aj]ߞ. ڵک' q,\b)) wD37SꠣP2in-3CiG~Hn\?}^56\Ze<0j:|_QZ#(E}K>n~@qsSCN胺 ރ2kOrtr8a:g@6ǔ4c `\t,3ZBex}EJ_h˵Aʉ": gY)D]3?OϜ6aRSgB<-B4cbkڼdA<;cfHF%{mM׵p000 #B%&_#Ɵq fͪ$w - ^$KW̃I"p罘z1\?N.+eècډjKm~o,hYaB-Bqq6ޜ XP2">L&i.j:{c'`e孯@r/Ę ZS$%ʾ{ e>Z{&%]&sIgB"wŬ g`JɎǖhw,rVgRr Y'c{kw΃kx[l˪{P hr{Qk+J;4!/ܨ5\Xuã#!%;Ud8++H ofRP,e)P\SПd@$'X{fw%v ʖCU&ٱ`RoX` P, {|P{fH]׹U ^qn戠Fh%°EѨJok9l)%)t8xFJ, fjZj'G!GC #5"tobghqҞ 7Lr iS2ǣ)p:ΓFY_23Gx&`^;jDYe-c!Rxw凇|#S~}E3[ke~YxPMHMs)bjg;ʆEރ;Ti$<wPM9nh0/{I ㌸=ۯ:h\DpRmX n`_47>9{|!b>w)sÙc̯R aWF@#AF12dc#غ!1 @ebR%1uEYcá \[ }m~s{kyI]}vH2a~&'G3n U;߇nFޣc2{/x >Vh8Ԧ =jm}ՊCݴtM *|-/(ÿNق %ټ1)9mZ$S4hh5m#Wr*URÄ~=^zgp6$Eвyh6A>%vs036 FXfOhܪɽ#:N#0ɋĹkp9HbҌ01e)r>!*flB~OG|& ݇&>KW9H^dU|'W]%&g":$%_4iy;jmSU{-g蚥&-ɞEtɪ'ڬA'V@$( Pi7M=pk$IrqR:JbFH1f e8Una`rL0x! 4PGQhV\;%Вg v/ F졃$W+DEzzW(%bӆkJv4rcܫp c&^:e@ˮ5#f[$SCGIm4Xjݪw-_sD.j!aiuх0$fB:l7{Y&\~z$hIS[w~L\/f nnF,of wC-|s+ҦŢ/WDjӶ>e>͙X5WC3Xppڭ71%Z^ϟ8Bw>H㵏 ɊEa *yn"gVIFi>:=_6љ❊ID#N\ ȏQʘ?0׌P MЄW0<t'˻LHUt! aY[ד6T_IG{Vb,P0=!d3Z Ho=dll 1Y)k~žVNh2J\)XGNaI$4Pc@)EtX@Xҷ@yxVǴ"X*޹ߎ,\ڪ=QLk )ֹ~` A7ؼx|l'8Ni LӒ{]HLJ?.ro"7ⴛg`*s#DhtM &2#Mq!yv+e tr*UC7IA"@&ˢ÷m{VJ!RRᥛюՐU4jY3+?+RJnqhěrwLc4Y\GIK:3j.Տx.vFHg/pOq?;.vx*AxZ:rVק#VpYsml7E;|۵3ϗhFTcK7:UlӠ\UOzxo(MF_^w$ax :3#@lۣ<)4|(%'^|YnFKU  n4>X.g{'((z+Uwtzɕ;r$Ck|T.ő2)Ld h4`M$@cKu84-q.#y qۄż({ƅy Tc{mn*c\Mk׹ac!6kǝ<"t)/~H蘒$lS!Wl,kY0 :6۔ң6!́k^f<3e >Lԗ)7%s3w㕠>G[#/[zVuHN/3 o$vsi%P;/y(%;3AYrd lG~ux ˀZSL4Àu!J܎Yw|D!E.WwVGOK@^]c̲iu^ˡȷFLHՁ1hJ8Dml;qRh] Vo6ŦI" ices{(Й=]J94ue~Jl>E TF=R  Drq1c?M^* =+tw9W+9-&RDPRg`r ".T|n!/{{}Y:㶌e'+ux {c^1{>MZ:~SPIFJW<}[P'Xp`iǎrA1dG=Ѳ~^8BF`2F 9GS6 l%V !\f M)d3&J\"3ǥ5}´f-׶TGfEܞM0QAX g#AYvE}zwQ۹<ɤ|ldN<߲V ʣ-8r W~ٳ6N:B ™j pm!;}vrh&-$UM9F87kz7fiyLx +:i+/4dӮMD8X+N yZϰ.p_@Ju>m_-!rCl췒ƍru%0`Ip$Nas ~N.5JqLSa`T1Rq ;7>jW>2( aU:_!nX z#Imz>ЊA%&1$0|lN,5d1m' ![|q9Z?]b8w>~眍(wvjX 錈I<8gH!2o,[>?2`LiyM/v:_=,M 4,]cQ婇s`P$VlI]ǕZXzSi-zI4.Ff3VwO6uJy2&}:V4Eɍ|;lfE2cUk~:鞋"zVq%*gDUV|DxPr\ G'"C{-9Md1Ga\GMC*[I=}P[ԉV>&%=³Z,c\7d:* |ɘ,2\WHdhBxUO җ 0ub+Si6c/cFOӗyh>N2lӚ&W>FXfԭv;U&ep>ߡGru{OfmJ=hA4̓u 3OWV4QܑɅq07Ɗ,$ڶ&Ewʠ=i(WKuȅm@%PT~ eki?ha}!5 ?zG#T/=FpnKCN'wrƩĂ#a9J-jm".(ywU VEdp!/©pM'8HYfeUyDZWΝp^ⷷ9NbʝSCh1KeyP'WڠWqbh]iAu#VI 6JgÓ\s&<#5ߥ3to>WNR1fAuȟkxE#[.n#< 8"5_ s* z!w,{z~_u9UKi[1L&q3^H}P_cNtax?ꢖʣ<#A<7%[}bKl"\ X'O.o !jY.e^[N~Mg'¤VGAVAH's#:3:׿CBѣѩBߏCzـQ[ +NE:nAOJ\a< h,MMǔA<|HR-J܍ %ƀ F]&ɹTK$->gḺ+Y|5Fu4/ٿQ|Fk&taN.Nb!yPRZ#Cmdz=v[a~ Kٞ{}~0= RԥXb0g!eᢖҟNٍ0JW.ϡ\K˭p[,MЀ?I4K--.ױUΖv(_YM%a]mƯ@#s;1<@vi]PX ~n';~u fA(L~ijx}m~KJ~5Tf" 0o>{7W11Սqr?-*|dȮUXPHG^cz>Mx+s-N[:Y9UxM̢%_/)zu[#tZ%D=LBdxpVhw9D0/1{&'4(A_a!!b|PQs8^TqvFkg"|[N#  #96&77z0HbJ ԄBC;ް8qCQ#ڍU^SzlA%oOi_#c_eAw]u8fǺ/G<肎"c*p%.==TT6ls__iڛ!ܻkiz8ڽH9:D7cqυT \N»fC3Pԙ09OޙNB2/гt|Xu#ʬ^]hz=%NK u9+ϒEe%R:!Ϧ^@B!xƐ,%uw^`CwjJ u ;vʤu蠟;[43rrk*W"ADqbAVWXVZz@^8hf/Ǵu@*8V@]QYdn`2FHp6ik#XcPv/QQWe o{0$Bgd:vդso_2c{RiR1I1]_W\IN/ L\O(/ؼ;{ ЪsU䏪h?Ty)V[Sr9K3o6AA?w0G^LϨ]0e'vLyXn"q㰀T\d;.ΣR냑܇W*oTJ͟d@M1yæJ-ef4" 4^wL5݋B|!@ubگ =;'셳2>0ahV~'#8*V4Cҡi;A`گIUHe Y'0F ]-tܝc]Lc$wM, ˶;@6)=]uf0|Ur1Nzmї{?mN1X#29őp8o&2Υ2bN*= }_ԛ""!t""Tg/!a^;Su\ݻ1%#9-Z[E{KRֹL>ؾv`lҌ&DRQ|[P(Q8Ź%Io qY1EO!ĞT¦cŀ%rtyw LHg1 Lj sCht}efшx<0UAh=NlgйVj(meMHyW\/ԆA!PV8IIʤE 2L}c/zT%Jq2Ve%CkdRぇm5~ҙׂp GbOsu*XՂcx|V9?F" OQ]wD\;L)SАTH[:4U>LK"ŃLnǰ/V~8])E9AA7[^CC<dg7  š nlnں:b牘p-(88BYM:شFC&5`*pCܬweH7rCu57CpSZ}럣}1]DWSIˀ62KM0wr+72Zv6{S8>Bج l0MKնpPv/mlg6]V\q)u!`\Cۇ y_4䐯ӣNrӀR7P hP|;uO'( &DsoZtٓj'e&-~X:On׊ᩝH`g"O[gy=p3^5+F4^m24 sp8,ht=q^S*Tźɔsϰ=ҖQ6Z[}/E5aν: l}6VgF^Ix edD$O "&ftP Յb0vT7=1˷htd흴;YC#Rñ4Fֵםv3):KxWBΓ|wcQ#y6oGJDžֺ^3|J9swVY;0la/ʝуo[Cx[Nj'7X&px^&RmfAVYfƼ]^GW k7zpwiryu+p6)FN81̢/RҌq0G7 ,}N4Q<.p!h'M=O(!m995Zsn_%4Îkf :_hQCQ^!TKHǿ8 ֣Gl0cbc2\A %kp'OdۿœN]j9ů v՘րTP->M:?sݙ+ғ j^,]W6ׁfJD_v/_C8E1:HbwZgifŏgWBdK׆Qc *g? %t,ݝ,D݂7CP'NODm<ݾ =jfkC1R)-KR5Dp5JٿԘX,`-*Ƹ][R=M AYFdm!_2Pg0!ۑ*ۏKCh;sԆ+(5eO:yρjq9B" HZw#x,gG|ˠCZ9a@9 NvڭGTFƂwČ38#8[ T߹}WQc"Ȕ vЎkk=@q=/=h_(pXs YdG̯ݥ4 R>gHEgl~M=ƪ Rz'#kף0Eآe.QFDyg!8XH; cpΑboS˺ S9^=M?Q0yهz;RN\HS,EB 41HQABFFeI̤Zj y5QzqĘ@؋Z)˯L PYml$0M@ (g9)uU)֠ xz0= BSe$h?^ % 9fi:]/n՗v \p!VD`KoK"hկj3dn+=Xk.;''7! %<">~N<ݻf^hP ]`@ ]HIZ#j]$]H0ӣSڵ [|"Mt~ dn3 nS슨lhM(Ǟ0r-2UW9۱4RVpt?3I4;3ܵlhz-_7W$Rz W3FbԜ^^yqU׻V"L.JZY\ ӲpdH2hk0=_"XFr5Hc!UT/G6#^:! ^Sgd2.8LB&5k^:di>7MоLJwurՍ=CXQ0T>19fw><& y)$w> i ^ հ5b/D_\Wi7 ?Ibjii'yT_hNNYyv/ǢT8R".w/b"$ GeGcFr7Mu 6P|pM֌ $giqtU'j-cD}#G'+7 _S:A*'Aʂ\R=C8Ol-2Aổ&țPґ$DC'P% v<5k=|vD]]fpː X>r7|#&+%4]Ds+4%(OOlA=-:|AdϞY9;%mtm쿫^@yۣNDl6C[KMq_ޒ(zuE?]+ $v@1 乭!Gck0rτ^\ Of.`GcQֽNxaijaO=xdʖP/6w ,QRoHz`L=Hzth{c3ڜTh)(Ђ:PGޙCٌ%uߓT15e$^\}: Nx %,ql5ant~ƛ|^:gٖ̍lq8Khŀ0IԂ"uP+u<_g$Cγ*mWі6wJ[ahv !B#1R6]U˜m?,AF~|hrfb(RϚȶ he5у صmffyW|Dõm@GL;6a2n[SHUкƕUZ +\Z(1B'Zi5.ظԋOm/' '[FKD"zMi+nC+F3A!'68+ʲ#)#&{`hC~DW(/hɪӲe2-(ofMQZٻ5@ T=ps!T^/#F(Um˂΅Kgnt#q 3=|][@;r ^f/2U|4jId=|1e8iu9@ƚ48Ҡ?ZKk{}#M x '%bL[&Y>u!X1>,ʯTD f=8S%Od/9"V=bx+LKg:T(MK բi3aż86>zPILi--Sxen1H% :BWkBMBq,{b'mRe9Ǟ?Řz Ӎ0[X ӳ(t2qؑ7ib-VRDpskV$g$~7ɓP3m>:5W95:먎kYm=ۂ΄xPL&l>HKe`Rċm0$' YO?1%"dFwtgk@{ Y癀~%^I*d:2 C`aݎqa$.i;TTCMRevQ(K|oc׃p'3;?O.⨚"i;,6iF˶O~N*?Kװ:Z6QAИ#`ĉ8,V žG1'D-+,)EԞG&ƻKCn*3K-jW_"\9˒ 6DȽu!msl+%qy/ay=7ȴEb=u pLS) "jh]!euB*d4XQ̘upXW yFq2$6DG˝x\38mMP#5N_Wx'bBYkȺ>Z6sOP,'Jc[XP_aB ٺ qtr71~اY*gOG)[D!L 'Z.JBM&Tb׺O*ERJc=NWP$~g{x\Q}ş֡t+a؍ۀk\}O:}2ZNd/vw-ja5ܛgO]y&l hcxMWluu80lP][)rKq D'J'- .Me AM/w60弶)+HW&"eVPinG#^FkL\idౌX7C_;\`Dy(ܾȓS柌骉?FURlh{"#g<9u$5#lƌ[ {%DV'K ppΛQ]h|ᵝ5)}/1_1e e*~D=xl*ۈZu|vʠUez /YjڴBp2ʕT܌k%?$ *Nj`{? O p(?# xavNB(Bb!<v5ʝٳn<}HJA/dy!Bv}[yjz :]`@QRy?w!÷flޭĝU)Ia"0mjNqHˠLwpwqX+8A4=VرkQ i'l/G, q٩2_Á1ilh󤴅Tj 1d1Ϛ6ggxăECXq\ '>lIFHG(Oo9٧[1T$@&Sw  fDB5X ~%y`BTm l 8$R`O[F*W3ǽk1qA4o؀Zs^(k9Փ8<׵R<*!^\*n$kdO=\>o@ wq6Y,Xkz=EsmmZ2;i|m$ V2\g_2l%>4)rDƆLSӧn~b&wWxGͤ㏀^ӌ _daQ~;w.}-{jV#r)w% 漳Ʋ8VG#U.ue3Ҕ-9_[n3bޕI,4WBUdfQe!3-h)쵍hGI-]W26U%c4h,V-h8YG&W{jH^K+8~oV`I8-NEZ$)[kTc5MFU))y]oI: qKiT H=,5e!"ѥEoi)#ǨIl 96B~N1EʙF29\8`BOg^ϧej6 E'7 |m$g;tR:8NLsp#~cKYF׎6_+/ʖ#Mpj(cg!3kdig5qQ™w>-phlDS(zO(=l,mfAdp&!J$ց0ܻee2!3LLEKyb[ !߭ZMsu!,B2A wy) 8hoT{4bBG|ۓw seO[/oWkbKG=N _iWdwNyÂFto +/,,A~TFMhFr-R>5CSvY8_PN- W=!# :P`^uP|`A$VȉIX5%X+~1x_D1=J &@{6C>ѐ3Y:.aƀ3+.)XxN5,ie8Soc̻W-9 rT0*pky"BSZ6=s"&s|)gK :%%66,x[ 7I1w~( Lb{,~zRܲX8F\`A? l& ~Ȅ lȨf!v_aGh)A1ՠ6/NJg?Bv z ΅jL X.3?Iռo 0A i2TU4K4E{)r;._I"EGc *&87*Q|G? p Sk{|q}2nptǽ^DNk83yi=וױ}JF^DKb9=rxr$ 3q8-^i`+>9tX@8V 䕮0jQjTr6 CәrrI~IugVN4U7ː4GD% {`I0TNBӰXɘ I]{NՅiDEk%-[qU"I uT\{dw/9ZZ3w Z~K/ Zi'cfaꭡBqɪYR1&r2@Å^ґ'tu HîFQ; vPHpW~AqMsg2ui8^jFU-tzVc@Sw 2nqbޔL@4V UI6`M30In )UNYZ0ݷkd؆WlxU EDձ\]SMԧ|*d4qvZXUT{O482'uhzJ)Y p YW63E@]<Њ>s+GVt?0Rbam-DC%g,Ljv]@z`&8 Gk/Cp4by*l-:+XVpv' ʆVRW^ws2vd)P| @< qڳ`UX.DEZSr(26׬G1YxҬʼXOefFp!쐝6 T?@+|39R((ךc^X%t2OQOD2H6}(K@>PHO>dz4qIbQKM8͹%̋@Yܔ4Ki#eEs͉Yk@~hs˂I饞D„:5g Y'YJ8Fφ;-zP)TƤ(J<37SvaWxN4}DIկGmD]>+1oL@e@ C?S:MHš_ezi_(PCz0vUzks$41e>7=#}B5cD-1^|W" PPGQJPLH%W&Yo< `;obn?`[R%1ǎu?"j55(ťWHI!'J>-}K!n=d !g) @$4>Y`3 ^#)%d|$fywy5VZ]jг\bK~;j':v-B>0-AY3dsl;u.porm1EI"9޵2M2%&E,|h&5 5md# ٵUm?V NMwg@ȾL`E`WEV`4HE?=rA_%BW>=sQ$mّ"y|6B }wkn'HFwBu?#nM@vZVO{_@#ypa0DTLnڽ9˯~OA'6J?ځ!8/m^Bќ- D|kwLϼOg@ڨ~/r/ 3ysxJE6] #-qЊiOkxڽ 56ѩO#ؽ]_5 8NX+ v~ٝW2sbU[^j?6:4%&  4}yFq%^;oV(1}:;8U -oʊ4vȢp0JZ"AV(6l[_M*Q?^y>p%mC&688ZOCxJՇu'5׷K޽[T ,9COvhdxڸ0RBbUՆQ\wHW[w?;iX?}xtE栞i Ʃuk>Z_ȄA8W]ȇDR>aU㦭譅pd0 !؃?;rG ,+g27ո% ,#Wx}(8dmRz,Քj;_ qoa'bf%Ys–Z;YAl7;Coy1OS̭U/ >ZQ?tLa/.b̈́_r` oW'Kki1Lz=5m{n?m_,ŨW>K2]]$S=ɜOP|فLvEz(oDg;OԃF D'0 ̆).~n ٱR+~U,:?jFqy tBYC xm&z E-J4g~!"2A:-67P2]@k𖲈ϲ QtVX o[wvV1AN~Iz/4F\gL67\qR)dX3@B}{>: 3sf \x:\rgMUe]ZA:I{;20G7H oXG߹/dc HM"|Dzt?l-@p!C0}]nV4YA,E\AݍɦUse8ONzIzi'bm.zΝ=B|AD&AAT_ߒhAzU8MŃ4XA*$k986erbf\/sL'=h}"s5]:1WDmK4tw[YQF٢FJ䝠y59bT̎nWN<H ^%2dPtB*dhehG+ZMX#k z/+Fr,Dte8p74B+]`5xDS\NÒEf) }u5WKF5&ZbcSШ;@pQF8{$2@ rՁ(|~ ޛʽCȮ.DЄN$vLx)!Q z8?@}5N x%V=(Gw]Wl}$KwmZ;':}ii 9M$gsl%r*_# kN[Wz`D; =*"ޠF-8i,Y(ko{Dt2U 3)`8Vf$w EO&VL!^cޮMr#l{ag7q. 9hŞ2c߽(Δl,^[8n]UpJu|nQ-#s?>rUeDuƲ9ou)5KXoNzJ`-W!!6f7ԜLa@ 6#rF̞PQ/;9jc #Ǽayhkyx0ѝr ҡOɤSڥˠ'# [ pobymoΉzψ}>rp9xTO/fS˦@E7 1{▬ٚjpc-8!@(֨<=&W' N9Rw0&:e{1$ܡ~@g)~)h"T N+HbJӽL|TiI5צǠiڄ|* O") }E Y7O_n'Ŕ5#DM#Qpxz>ɱX35mN̪-pBh:1eOx@l^eǀ)> ^o@nWl[V;8S 3t5c'tc )z w V| C<>F$h1Jʸ %܏͗U+jr ))yA&Ya$/YXk,;c;ՁW ֝}IJq܊Zv=K}k`bS>gl2w2eG)yצqʉWCBC0sRv3%~/DTh>#~sxjC/"]mKMa5_2ȆwfN;^9[ 7F;5lFI63$FA,IX1Wd"cjFa6{7-3H "Zoi0Ag` *,>Fb6*:ǞK L$xqU/1L1:IYi0>ONb "\/~aAF~t!)$/㴢 X9QgtE,>͘)$'g?B9%=<u1>J]6=sއD8!O7R.Ơm,X,V+|hmdT;)gPK;90* .pSE{OGZCD;ka:l"yVgΣeS PRl#]̕['z&APE) >O!~<@E"ԟ0}l…BˬJn`5/_d9YFg{; VOyR%B:]W,ocLprh*g,!Q$BgQM4ف=8k .f=H LuأĕLbBe)9xϥ }}ae֥nE GO1LʬKJf?sW(/NPjfby!=}Z~v ) G -@>njVQ4KLsv2$CvGbR2b&A29ȧ444NeIBdzsԧ GYF4EfEX]3μPZ&Bi} B+j_Q7R)r Ij xBa‚1,=\4YN,~)NJ O+МpŴgNG7o ՄeT>%ef=ܞsפp}:sv}Tq]w10xH٬wەy(ZRp%/cIt+ kH}+&eȃ3AWVgAhwp N%%s'b==)z[hk8RӛTLQŐjO tΨ~c ǿoR[[@fFt }i5#8w5*; o6Na`Ǣ0^OZR?שÒ[M(Vʔ륲 A9IGO-BPjʡ ;ҽgSy%G8([{;a |ۘ"mpZc(}n5gJGO:]k\Fm̟_DJH>7?YYH }na5Ԃ,l3@*eϡb&ޥlZxIOI屦&va)܎B˰S.C̕VXzY';kzrSH@(XGjHS2ӳgU%Nh .)T&qږ\or+^"1ө_x!7о50`/5}e1C`2pRf3GZR鯚7ku7ӱ@xeu݆ފb9[ +Zj <)Y>u'ef`ū%zU6~/H躭=q9%@ HkX{A-dZ#ֵGBt kF8BYizr=rk*4zDzx>7t7Β/}_9QfuwY"(3ZcX#!!x`tm~Jaob^ N*WY2#7П.bH@Z[HH⒖9"O*r[ʈGn=|טQnE;5,x@gqYナy$&=h %EM6l;>Ѻk&>ZǸQOhJ gR|+ԍ"~=GVzvB6] .H_Mv8)˰"쭔ԤiNa5Gl݄'Htѣ*w1cB1MogM, P:,OcBe_N"mEBPkIwh xX4tY"3V$ w08s+FxZuE߀ Ibлe}AI?^d)}}dg>pct$ki>w.l]З![jD|)H%a| H"2cP 7J{>ܻ栓bhJr&U[[)^?l[mFNv?swi631j,~I|DmkYG\àismd@v]G]Ҡ#˝Y $2=dFYR }͟<:Mq#1S3mb4ULZBꩊ`Z o-& dN"AQ_7JUN8΄a O®_1|.f=Mh&$l:w#O4e5@Aڠ`hfm8_V1<*V E*p yJˣP *g;hUy ִpz1W2 %0;nt3۴۞ u!R{;ۗʼ*JkbC>Hshpf| ),+x-;x;x/R,ji;rVʸQzRpY\DAqxZ"0t-H֒۳@;}(G:xx3m:h 6#@=+ (x~31ѷ>.8TTQ9_{jjWb5{[=u?@Pe s g~^xW>M> 7S&UuƞmZ]I~d%#͆0BX5uX\J.,> _Z! 28͑gTTK Y3: D~&  **3TxLUnDfX4l ? ns gMN%fΨb5a=RYw1bkg{ 4kiy3,ܞm*DlS,GyޖfJ%?ԍ[ u͍pf/q2Bhi($T@YR A Z"BFUzA#㹕j8Č=rzI Kuպܦ $bw qr[2zh.ROMb$_b&o/BFf 94vHԌ|],֫hB*Crxj9G-Nu[&709cUj B-`YldheF^8/ tN$ڷ5/$玹n;O_3JsN(8<4=' Ӻ׳{ J͚94c@PLeᦘZ@ՃQ=K4l'k01"| b }2U b!}j[?Qs:odvs%Љ?PQ{vB_ 6ƐH+h--XrUOB[_Dx@A*]yD& Tb"(74fa$n#/.LFyJŦ$#yw 䔆_HTP1DL<IX$! ['-5| @G-*;^{okt\%|DƂZdqY_c_x:@0G@R=dǝf$vk\[#f$<Z˗w )l)@oCʔ:n\ECL>Vߞ_mTUQRl 7YUeC[Vzz~_d2xphl۫?TÄ_ł+ON$kJ%|it9ydMLp9`]eڔ/#S}6/ _>Vznz5Q!G9K`L -›OF$4z3F."Н"laGIK/l[UHarCrQ"݆ؖ,Ulν,h{U1.CAB T3:nxW&ٝ _uHX.!341F3UZfx#$Ad$H 3}UZ'!EʎtIJZ1_dh02xY\ |a$a |.ȅ7 {VL TYWH Xa!b [Roo/]i8W)#a tp=>R5]B%F`dź.J`xDgKd`ȏVs#5HƉڷXx1e>5mf*à 4( @O ?c w5dض̺ϲFeMfy[᳡P}7We"t\}C KME`[BIt,^1 T^1 cic9 eΡEuJPH+v4^5(3OLz!4"l~Qx}ɄyS7 dH|*vڷ9jGa75к 06EjdXX nXFt,L͢zv?J%QRV# PW + rJA$ ~(Vb!ݭ$ 3J']v'訑`eE~}WیmqĆM\֦<۴MG<L+<}A&ˆhUρד\q3PQ3L 0K_PKj+oQ ,IKbbҋl-3s`xUʫoC+׵]C'DqMw;OUw?iHޤj-܂%DhBNR v}#xV/leW CC۟ݠ9@H"&3ќrݷEX,q-L։JfP: u8&)|C3{ ҭݷ^G?/xPkێդۚԾChVGSf9fd# 6 $iMW 3}KN^F= 6V:>NDȇդj> CL'գW 5ćGy'VD4]w5|+Yawye.4/Žk1#t7aXa3g6:1Onf&UIN 3q)nsXskO!&li/`;DM2L^iGi9<4T|&I&1p;T3^*X8R f"TA1&tp`/5( ||'GIMFj$vKQVp@=x5tK k~e z`^)$hMëjo׼}*d"3+Vvd H@!庼ܮ7LۈZg[G ݌ TZyhx$}(oM#724dgi i?oۯ.U>O(+BB j\3 6@}DwQoҙ]j+a4f'qǍ2gX) G} ϰ]hqd+%FiCub~|)hˉqFٺ V40hS5BXJ/r}̎Eg -Xc,ZrK g01حe*M%9BkgJ}rTPrWTU[ĚJD2 G OY)] 0E;@~!> xE{jԟek 02 h8IU2Y^,@VUG[צ~u luA:hSu#V"`S#(wn2hDB/e@>$qFZb> kl +܍h d=ћ_.Kd2ʆ 47MLU ,^K Y{+=}H-$jh"Xɉ4}̈[x63_oHPd`ǜTŗ]8 # pRycI +fA<aUM"һrXIKvep*(˸8mox! cNaZc2,z+Zds A,[0 I˫5z7ȳfٙX9T<8hlUsZhSJ Tu$(ׇ&࿈ǰC'<-0Y䨓Sȱ_M8Tf-Rӗe?#Yu՝VIŀgymuC"nXMndZ@DN`Jިhr~ dz<: Fzvqn M3~: *s֍NYu4둗;VC& kq]70Q =\1ASגq|uW+΂~믜PB4aJ /Y#dY@yC/u5H]rMm&#q1 P8"OJPvJ}w@X82V̾IުwbH h+ G.*pC.z{oRQQa&B>6/KN19Lʢz$.75{s-//q4p/p F UZ:foCVk XYDڂq-'Gr2볧cqOCD/ ˇl%G";Daͪ}JxQb1T`oGύ\lcxHDrJB%߷DoNiT.⢟"dӅ,ɈP_9DsD# 'POj@9Q_HIRFtlco"K+KR%a|˜WCc% E:$:*=sA'sBu^a[j5qwEݘ qdMYx2_E9s+ٔjI~2Ɗ=$A!Vɝ늕p }Z'g aΕ{Ds h I,nai4, #2I~Ͽ"!$/J,_}sU7,?ElÜ.?OxFZZj`})h`Yngؤ+ipc $$f/pfUZhl}Af,x3izU1c 9[<0$WdzrKATPߓ.NXD6ho8ѬWE7[jp;_{LfjuQo,~(:o(]U&Y")Wgv cnB}@˪֥:]j1e1Nq%'rC1;-r'\!sY̍r 'F&⩒}pF&PCUR9.{WQcf%U?)Hl7|1[uq8Q? : +=_k+2N dXbFa{/*kyfR"`54(~BOPJT_:9: n?m09ܛ|McXbi Bdm{m00`b~O~̟ⵈuo2g!eKՒ[0^Wf7 ٠E>H_}G{ آSبM&کa!Y٠έf=zO2򺔨nЗZKW:dPC7p;Rx$\h;;2t2Uf(Oez5<B&{jVt"9wbMg!M ^$@'Yabp,>զJ]8;`bf`4$UXVpN/5eqEz>2:p?vl|G!e2 16W+)%˴:VxSB!tyf"VU'ݠls ҔCEC$4+E RT,xem`G-B 8|Bq" auijPƍ|‚ofưRRQzRґ$ 첀0+(6>9#zRA 竛5?uÐw#mi~p^ p'7گC8pq8޲V[98 ]1Ts̷Q} 5/F[8WBO*m3W f+lnuĆAa ܲ_c.\wP'JA4!Τt1:L%OllxQDyRQMv%-Bjt6' q_N.n5dԽ{A&&J$ Y[GfB8N Z\Jwnl/ا*Ivq62,2mˬV}bM4̂ҩt ؼQP R8ޫ !ˋe!g 駍SSMgo N/(qϤ 6r!,#~8O Ϳ` A&Vm5{FОl2p'\!">r}v?%gijQ䡜!z2U)^3B1Z&6Jk7[:WƏ{zw&Z,ajPeStUM>nb c Dm;4쒻%żt%@ sW.)fD#(=um7~xm(.ԥ$} rMJǞ) 6`K. /y,W!x+a^-(`ÍVJ Nz>yb5 ,+0$,HD92ԝrVP#y4p  끀Sי PʚFlGsCwFP x&!ȊoD/} +$b 1ľJ!B( A+JbbnC[:.5oI%1>;jLrD<7sz%[\$pqFuNq"WV*+kP-pw=m,$̯fݐ35?3rţ&ojb[9JDmY ܪX{eIw .E;ڕ.}>zdL>[~OG ڲ>++%%D.(-iz],v0tt?)UgS.d>\EPMwbS0Qf,\2"#X۽ép9b6j`C# DUu̎ݥ ۥC$<ʲՈm9ZWp$#5(m\@ٙX1' ׎:&!?#Վ5 ga"vLbݪ.#8ϩ,xB)˃.B7>)IHI&@%K m*4nUKܬ)7eO{id҄{=/5Hv.mf(Z~|+1:Cf{x:KtStymSVĞGp<-qEcV_v}-6]1KJ,PC݋@<*ˢ3~XtLerSAnM(L#/%^?l m,ZASU'~S*e/ez^ @v4o|j udXיh+A>fzґs?CI~O`*`eq78'f,ްQƱ<j%Wc+B߱Ⱶb Q{a1Z⭏GI{dWxֺ`,"`1Q"ؗ9ko%$5OT_0s` ;'}8Fs%\W0b7ٌi Ƭѷ؍oqO`^m:ˤfEdj }^"B=c-{9q--}z>SCTeW5Qj1C jv2I(wz¥=l5\:)#GrWRhȱjY[#ASC*Q(naGMmS& {(GlOELJd xh1m% >ĭͣo}{A_{fvPZ#x_k\UX]+_.sǃm{N,лx&:?I al1Cyp0tiaN_hMw`L"^M[^%:ݓYVtNIV6Ԟ~*¤ψml @tx=bMɥ}ئ0.BBpדM"JE% ^Gi`}夎5-mz_kv\&qX6dҿg{FC _]PܣC-t@n.Euy;= AiPFǼIԔq;3)R+0<\z샇:֢CXTM)y*)Wa5p;#hQ?;C[2b]Xȳuڲ\ g.јO53X҆fvh}S"mfVφڅ_l z;!sa_ Е;E* I)E8諃2)G5= MlThޯfcREBM@b ;fDI?bqu=WtA0WW̻Gen9}[s>Xn]G hm _x{r.)-⵵af?Ejp vQP 6}CLm=yUT~ V~m<cq-cje4i #\m&-4}CBtǔD&k@i "hLTtwMҥy3J1` >enX˷na7E?΄V]R )Fڗ P2 {&U̦40O#[l g8ʒU\xp|H)?Mv{3ⱇH1[|%7/`Eb $Bgy^FƮ/286{1 /-* !^}ĿZduvC]EZm+ިdlMCm vQE{3AOX^ Nue(/.nE}P-g3:nAC&KhՇ@AD24%<4KD8!랗BafVMndz/}dM'?/"%R9Z?WVeulV[ nd?<VPlNռ1[H*"SW 䏏I!L*srL$2嫉8PL1NΊRt3ZF`z c^y@{pj8,KyݭY+e-ܘ K~lo1zr =DUGTm#YL59[c;j?iŘS6;;ՇopiWfwAJw95s0iSga4[`w[CʄR<(fGej 3*rEзm4UnH$˿p4o w@.Q<4ţ],(\ߛh8tψ^qyI&"\4P\d% ڹ,;+iC%ɃjdS҃UhYa5=G"~3+ 1Zi`aL{Gb%CA,>Nk\9rz?hel3 !IHDʫOqr)U%c36ߝpO6b(&Aܛ0SEmU!E֐"ՀU:\}a+(~J嗍 $Q6 j^w]^"3jZB3 SPIp#ls+=m1 "WA^ףm'. ]W5sIra+rFJ eɄ:ǁ}eg/k 9(p+\c i`HZRW;44U0tCW}vizt?XVp>܁Ǖu%h,8Z6v,ǁi+w3 a ]mhnY@u^!w*{ aR7k=*iL?kȝ$106[ <0g =*d4`!2*@$sqA8Q/BݺMS?Tvqi_YslqzÅ9WVJୟV#ԙؘ&<'\G;Ej*2@$MN8{# ؠ_V,Xa3YĿgi#'.БmT ėQЃELSfm@= &S'FTr*ھ4{elc #1*j3erFGO W!$PaaJ5LlTV},S mܰqG3`e$2M̨:͒UNgWz?K{5m%h5MSM.삨(aAj ƳDINk5T0mQA J剂+"/S5DC[AmMg;eƵk1@0' nʃdksp^W/`WZKb<3f7_5NVkbZJYLM)L6dٟ/NnTeaV2. ֒0mɻHMlu/N \KO!'nuTs'70S ŃχzD Osx%E ƳLFǶ"《uؑ**c Dž |DT@#NQ<2`r .SE" (hsrsJMlqQ#FD\FpzUdjDj_L&Ghg^GR :YkK" &~kpsۡ0V/R&Q c@Im _(WhaN5lNt_7GKCh?݇gsgn .Nb1\w/U뇨u] weC3fĘ |6;c zrܳsYllz(}8cl$0€DP';di$Gs7_XЍk* ?ĐHQ3s䃁PiM;5Ka"._fi0Kӈ,I&M uȅ{8a,CMݍ9ZiӳfUݽx)zUL凗^E^I$nzݵ[~ӭ[F_q MOQ.*83PC :*L;)&agCnŢbiyD-eatJ׵˅.;bw?ę/5uh~" 6¼8Qc \ $Hx{0XJ^dnu7wB :G;[/y@f-*?}*'xUUPlP#-GvdP.1`P5_yc#^7&xSQ,^)L۲-ʄWW<J*E@cu1p"l\0@,Ks) 9todоV6 k+aϳ\ i )&݉~>EVY-?HqNV;ސTֿS O^YeطҔҟ8Lj$ Sag_;iu&_ni!UC@7@ H90߸F}y @!^=lNM"Ǎ2 -F$}OYЍCҼ%?b$į}TɿB!ڏh/٨9.cu3 %ѯY~E6!ت Ulf +O -f '$Mf%R%^yeyChQ%,Ki'bgz׉28#zŗ|Qf9# G ۗx jEaO-~/Ajn 6% f S{s{lBB:Mt!h6o4Sr/|'Ogĭ>C{wްuН';쒱pdB$LÓ)C<.Y$fbk"8BnQ9-p&h̞<: OPZJ.HʨXJ!| /,".P ch#*ÔpH@@ͪb.J'mBiMТ k^_-7I7mg+V>\MGB)-Ƃpg=k1NvF[o\bKKk./due#UgróCVv]FJԦ){ߑF@cPI/+ Dhr9|pdGYw.4]rlsB8:eՕ6Va1 tqM;!pO/;"(lwG\Ia@A=S !yǢäkXA:گ 7\$-Wíx_Eޮ_( 5i~rbeNTWJcT'9TIRXDd<-')ɾ7-خVI\S9Jx>HA7]ZUKA:4lLRw8QݗF!ZiTBDnisBںt($cMwͅC`_#Ƀ#w,>'fsXNgg&_y-3ۮ3YcƀvbZRzBg)VsBv^F%N ̭Y^v6{X$M{CH1^?q;E ){zkP) QM~FXiZ[5n=s6I.$<[SsH&LnȽSM!_,)72jn3En) <'B!m"[u ! <$]hA ,4txD7W@ԆdDZ|j:Ku% za;pK_#n O2dRkLv)M=8tO Jpk,JA|:S44z Yg t&Sr+yM~JJ[h4@P g-b+[ ? 9%2_Y*&H3ȯڬ{\iF>SAO'HW'?w9q..{ڧY!̹b7}Nљϐ|f& DQo[U6IV}EX0჎~٦8!Ywi ʛ1j*"gpקZaBhkw 9N1O|<7T3AINwI@}Prśyh0MCbV>L" bP_]p(ڣjzJE/[+j] RI f[]׶hDZ;[MWjg0VS]4dVBVSLja~P>̂OT9Du6V0tB9LBf~zũ~ay.oy04< XfQA rB|@ْQZɇ06-ibjd'ӂJ1dz'EH.nD[_JcL JX@㑹2TX]WI72| }`C#_&#_#; q?Eۦ^6%8lw[OEo`Մ3b @ddދL l&:^k +O8>^֟Aѷ8S8 \>P`gmNCR8 ͱ'HXxa'T037ݐ9ybܾgfhrU10jfL/K,3qn(ly]|ք'uqcIa":!Уy ӮAK.QKPsld2tChsiI8ܯDiq,f`A·QLt:؇2fz[9iA YWt-'ӝj 4%L)N UumHNGjI8o- 24U@FE$W!@C]B>3SLz'ӍUI $_лmkOFk{os*N0t(]>06Η(IN PSj\p.2H"HƑJz+9@ iV0'}8J *?=|1x(EuǖRm!:B!Xa#N@ݓu{Qtc!ᗇgCt1kﮍn%sI$1liZγ=7оLr302Warc 7;j&3TI:{ 3HxYu`@ I\9V7P}o<=9pkkeTlI=P'&Eɤ}x)D[(Fft @>MP-_CzůJcYV`\$nm_C?㟛U8MuM!j ,rS,E,4Q5c ],5sw9je% fڈ.s?ʻXpє6XTF͵Հr=; U[PSdVe; #EE4Oy=Mt #;(.`LѸ*gI&/ |yYoHX!<oZ zx]k C#qFލW.z׹08"׹\P L` 2oO se)ƸOu*f%WX;+@9Z:@jT9wGS8o>"b)R0|o+ť7{G`F1=4!D7a{$)ss>*B7K9idp+T^"(|U}s+fH F=~)//#2tNZD-t`@$v>D{uvȍW] !uA]mZtK]5Vت0uD$4>r>#-w{`JVc/P5wCIGfΤ@ FW8U|,D({Gu+\P#S1zщ2uaSqY.ʂ5bIn!ӥJQJk X[SqħS7㆕ߎkKP=RImq"}LAP;I!Q 3]D(96{NJ%aG5u#'IAp82R{N \|ss8ǡw/MJATbB' Eq#Qhu)b_50)hx?LgϿŮ;q XאȋL tlwx)n:zPK>DLC=EYl52q?l |qpVB_jL6>%vH,s-5_>W\P{г ;jA_ς2<͎%U (AaF/~뮠|TԧDU'v[b2S!T- cHvoboC^o1"M^jE;nm/ UYZH$sn|}YUb:U_Bδ9CAYa>0:bP`w#)r6CXL}J)ۨneON_a> TܗT6rG_!śɰk ^p+H?T(sӘl~# !`2snb t24#@hFp3ߒcRܲ?d|M|eOLPQfy'ኽ~?W<Yp16N2}zh\) BR,ToNmW6x^\9]1Fj_>.-5wwGGU,!f[[O:^Ki/T}WWxAZ-u.[)%.K0XqXFڐjn,?FSH}+'Q^֗$_#T@vyꮻ-[m;ªŦ188 f~XkZ-ĜDm-KXRh pU׭#/?ʢŸh̪cW6aEWyO=~WsFHgC*aP)  Oq^bȲpJ'6:?)C$Ojr&#is_ݝ]k[1?09,1zLfFzKgǑ#5FQ_93l5‘cчOq 񴨣)a݌$KנzzJ)o&_ qG')#uIxeV3q-յ5~N~@ H񻭄Wžq趜Y?75S9 z|*:0em<*kkP Kif7\;Ѡ{>6q86!~¢N6ll$fLdE׻26#U_y/H^?{=Wsfӂ$"1 o 85z t1-L)}rӽ*4iB&+{ em:b2RlX۶vAPt{Abűq_ƀY~_:E`0Xm^.9JbюXqǏHJЙ7{ 9wgFqv%i Fu+!bqov$ú>u?yoUٰ5 KT] ^ټZkS۹>)By scfR+w޿KqogpV ɭR $V1_TI=úl^7D1Cܰ턞-邋yb)gvP(e̸ORQ7lj65D>wf"1'J9ٲ$W?2Xړ nh_[_C:l(Kʻ.tdT%1&I[#-b63`Su+3rYQys2S ׶D3bPQ;T!>w7m0q_gR&6\J~M~7gbgL p,>B-L&pjD)!xF^ 5͂8 F 7U\$HϞ-ȘuO!0̢w?N2l-U27B (ǭ۲65Kp=ͤ<ڸb3eMU&i*P )LGe9{ 0T7穳 0oT倨Ǚ!wJCS YKpoݲ/S(gq,=*>0^K5tZݍ >〫1z%TO(?AoUs34tg(oۿ*_!=PUl [Ia{?#Ej?rƢz&<[;px2^Wߌ*CQԤcFE*(hNeF/),{Q2 p7CM{#JqpM V ;4is5}I0&Cr{*  i\.' ȭ=W΁n!Q lc'M$7|ىޢ/ yuZro(+|8* zPF5-q ȃ 9>xJg D{ܳMjVdX*{9Q<ݢZ]dY |x4jʱ]ߩ\F/Qր;-Upef{&Aʾ6IJ>ZP: 1W海*6΀NoB^ KAླ?^$t%4CLNrݴxcmk^_&s{fS72݁`;+|ySg6'd`E+i݂>F x&mu1}$ z?`1rԹb9`]pyU?4b6t]j{I}c>OS(n*^ya| IoK[":%]yX PܥB``Ʋ{B3C %Fxd2k/8XbV?9]({m=1\NF |Xe;RKedg۴x {tasv?KQߗs%%QB;'Bd4VX*_6sk PjuǦ[&|<${XL,l~+cmD'F=~e魽el4BoB_nn}wtMaۍXR%pl]j98jxq F5($i7eypRX̱QY>lgCn]Adz'@&ť!!lBd+j)Ⲏ  υBxs'e}׌&3Ҽz7`グ\sUHz`կL'@(zCj:O Gˆ F4wvͅQu5ֈw1s+}H3{ fYaY?gd+.f *EoBB0瀌.:,FuOD(v 0#I0Gh89抱=B~Vxh-rygr!Ǩ IzI[M.j]Fa^V1!e`h*WDZFrD%UF+`2k$sS+p^XՑaр Dx,NHt 'C&Qt}/wqX]D8|XM*RnS"텆emCS" -vT|gm yuږ4oهtQr՛ 0%]C.bsnC fOMEѹčNq1v7J0<< `gNAA.:r <ϓ@7 -~ k)Cg^ZL0.>B}$a.(on6$XcI/Q|nCR."<$G| Z1HXr9]Nhr&>De&PUDXϜc~`M.=Ыs1)΁5?2II8ucPNNJA# g:?AC#wZeIǕs9ks=^kvwIK)#ٻj=RTijA*ɿQ'7*YdUi2xox<C>q1kl<[h᯶o[̺pq&ߏP؍_6? ߱~U^.Gܣ1v߉!'[*=`[` .m# պ^#7}svno94 Fy4\yu،6W*:eդ6BF:T3;.g샜OJh9tXjt)"nCY