sssd-kcm-2.5.1-2.el8 >  A `{U]*^JKqg:06LҴu}fM,¹&q&wH8v95Ԇ'܁;`@3EEU(ITGaXctW46lu 3'Hdy/*ԤS 1| {Gۙ,' M[}'O.ΌKgtS6=x?cHɗW:`HΜ6r@C4u8}b.˱hw-zjv I;)FwƟ|e`“@A,(Chxs(~ewEX(Z >A 3(=cQӓ#r$lo(5(.BucwR+ڝPy&ǜz-Ԋ=\EîVi}5eY>n5\/CO9pBm@?m0d   B 'DJRgx         a    5 v  <<<(89|:c>dH?dP@dXGd` Hd Id XdYd\e ]eH ^f5 bg"dhNehSfhVlhXtht uh vhwk@ xkt ykNlllm,Csssd-kcm2.5.12.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.` paarch64-02.mbox.centos.orgxCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%p5ځA큤A큤` /` \` ]` ]` .` .` 2` 2` "` !` "` *` *acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf09161942db5689237bab3e24cc38c7eed241d284bbc084ff03b8b939a9f728b6ed6bfdbbf85c67af83e994680b05c0bdc060c1bfd7a965e40af65abc72b872eea036de188ab955e9a19de9d4b88a7847b7f1e55d62aea8cd00d38f33abb38bd3353b5665e3885c8992b660d53347c387ec2c93e46b34b1fb21b55cdc2f4728fa0385c7131ae3ec2df4b609d6e76728881eb18e0fb6da0fce602def11fb16a872acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.1-2.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcares.so.2()(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.1-2.el83.0.4-14.6.0-14.0-15.2-12.5.1-2.el84.14.3`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.1-2.el82.5.1-2.el82.5.1-2.el8 kcm_default_ccache.build-id4cf490f446da7c41f4415d9b909f3b634f88c35ab0d52f74a638aa5bf816d658e9171d2ab22asssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id/6e//usr/lib/.build-id/ad//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6e4cf490f446da7c41f4415d9b909f3b634f88c3, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=ad5ab0d52f74a638aa5bf816d658e9171d2ab22a, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)0PRRRR,R(RRRRR R-RRRRRR R!R#R R"R/R+RR$R)RRR6R.R*R2RRRRRRR,R RR0RRRR RR1R(R#R$R"R%R&R'RRRRR R-RRRRRR R!R R/R+RR)R RRR6utf-8530348d82414115c5a106311a5f5489e3e90e59e5f7140c64d1ca6fba2b260fb?7zXZ !#,h7] b2u Q{LQ >$$ ^/םڟgr2Q0JhiX>^b3s ԧouYp 'EY"/v"ZCOLK%F8fcƵ46 Nc;QO@;*i2R>Vdw8}QiAXYC#fN2?8hl' $pƶ@ @}ƮfvDR?92hVŲRL*.^#-ɸ)G"\-zB^:Dn;ld1P0a9L,_MU[{?*MňbCX_I8(87a Bk*VZ0![^{ʊunw?l/HC+4&U)D݉sF̙@}tc<`_(SŰP ɐ~ `€ctM:1@&,9;N`9,I2pтjO%H1 ͷVY"&>Zc&XR=.Zu"@9qӺ-7SeҍrJu2f$T"ff+T o@{ϱy=zЁS#4^ʟ @xFz2[23x~BkĔ1?Xޛ R2x)@>BZ)q!EO:}k /47 o6 [23pb9< lSt%L`nfĈJ]p$(et?4.jx'cDVغ)2MG! N'E°8hl/Jn'tQ1\|7K #ObՑ+˘)?W"B1@&?)Yn+lz/-u?fyUh3R%*>z0;ݒ_GBh*FHx!}QkPL()Xi7j vY a>Ttk͞Q6/ZgV&$&{|z!;gU&ަ$q8H<1Bj ^ %hAAj{W,n (W!o`K()Dݜ4_AHH=v:in3;N9u|$]3@b!ٟбͅ|r X|6kV#hA}NM%0ŋ cs1ǔMXp_>-YG0EKU`S bf*3l`/3װA5NH+d^!c༬ڕ"<ï.zQhR7C͖If+P;;9eMۢ(ULe`:3rLP;`̜jx*ՔjSdg:%c/ O*#+õ\OwPjzɲ;&JP²^?\V[{P{uK}cHߍ8Ah8(A}p/kɹVA.bL%+ N)$zoË1٬ 7 hU{P8fa؀X9|fS􉁢ē'[r7i v̯n9cz;eۭ؂Vbو B|ޛ2 .q ^ [&[P>-ko^QU|im=0{ZEwTu-/ښI̯p!Z h?Bqޏ>yз)+#T'*ÕT1l+F-M|,=}IַHYU8ם` ܳc t_ 38D^pq>C'kLk *i{nJr 6sԬ*/eo{I@ F ?Qw}H [t7Ns:{/捫B͘`xvp1ImT٪,`4t<'1O9lSL{# /EF^Ka#I]wHy=K "xlく>mt6˘g)!ӏ²TN/e!AjƛX)O UtyE^Sj⮮&b@QĸpM)Q՚6J>9_hl2־ 9m8qѧ2%(׌`0ɓGUucS0^k"JiTǢfb}= .yCP{~1a M9s)g5hof=sHZvcJ$uiaϽ>4}N_jQYY[CL)K zE!Bdv5pwB"g"O!56.n)nkU0si7,P:za~;r 쓙"{,Sf 'jǺϤ6:}}.*cUBY| w}J?DՎ6RenuYykx$~8ŋdHMfO:~L uMQV] QgK#+&JIK-Cq:}pE|τn|׽a#5IRh(duuhנP>T(/tUGuN1jE&PV爔@+ sSbwWօH9[Kİ+*?]Hଡ଼xa F\ 'f{fȩ;`(E' YYU"l߸@T͸}sviBm r']T/@t1 '?G<&ˑN~(Z$tVH}v zc:h1p"z_J7ϯpȹmvۖ+KoEj4u$yx {RVVO zNNmAkDw Iu?6igH^mcЧ+bW'>6.cV F̵O gKՒe*rd{X1pჽSE4\J>XqtN~>Y0`:`225Ux;`ݟ<"MAV]1_09VwTH+T+LDTs{B2nh0V׾:M+gARwZ*Mt\E>.d.:G:ۢl@B# NNTG fW*^[Ru?Ti;#r:fd#"U1@IEy=P2A^k/?E^Hn&pV`6hwmOCBY)qn̰\HI1LH͸x/&U:QMhw)|K-N"ɬBEиxl8*r7|jaD$I?R gb6nGtJk*y]e Oa^Е%8>`Nf0pXqSu-*H@Sj:xt L{SrG?h$U~J֜@'~A".GWirxO쬏fe XA]^GҦ4yd^uƃ':s hr7b@ ̈XUau޶Ja8%88!G#[w^\.ދ LB:V3JGH)Vxc2g? na|L'Iuooi.07+n 5o]|أ =ovJyv0=p P&1u[_z[75όʟQđ ]ũ6>q+/g\v1W*)S-=Eam UlCop5}Ru N01݉K)`.` fN IV]h42f&3F]}tE)PVWr}#]0Pfêgݝ%e&#GccK5>n ~@h(t|,=z93r I |O,~b)Ix/+)KfW5ORcA.+RW"f^`!fpuEşgO@h?羍`2j6Vy:eېn5l{)O1za?`>"ơN,Fk2%na,q7CIs{o!1Z}u_dF 8Wld߰2 ݗK-:Tw0ϛbf:99Q @\wF IY#+{ܬt)G~zנ8( K:V hTWL܃=.@Op[&fUK:{Sn.*d\^{ĻC&L SezߚS)MOeڥ&COuT^y>ZDG2 qyJ*jͿLOsx_ͯPd RM."ܚviKOu_?#@XCFEֆ-{Y@Z}V&l+f{ z9?ɊkUd4A!tq5J1p1<^" x2`DY^JI#*G D ĄfTzLlnWE:Pڅy(cΑغ@49G = +E'ӊ5i)l, xەb)uɰ\̰}QUC$eDTJ?&T66QAnŊMB'óǸѼM5)e/m-ջd*2.63m(-BLK!XXa+xwަniDQ֓SFk,_-9#NFQiu4(?,xJreLa% *kaGa>[] ~Ő"z- (tFȪ [m׺i0-s}]'Z;iPլAϗ::Ԭnk~).b[dh<(f;7N@׵ 5rqꅆGk=o`¶AB?fhRJ] ێWs=S Gڏdfи.=Ad'-aRXbT|8gn# EZáQ%B,C9+^(M$B?D"g$_k)؈Y:ƨk,xgWX@o>PiѳxF0o9H`…j?VH Z3YYnonG!rڃ7a$/IްW8)E*تQ-`+ }Hٯ^8wzEħvmՊa0NH؆ N2U*YpHT;VFX:TKMi$F G.x -d9oL̲O6D}6;rnvF)sYw1fqЗ)#S!BxҼC!W;y+ oYYhnŃu}XEjrprŐNk ͑Cl;'F1&P:RsO%b)%Ẅ`Q8ތhSsy wUR]y kK%nA7֙!n@ݵ-Kd"  W S,LEPOKٮ_??&{:;8eTZ4zg]y:ƕr;R,uu`zR]qTX-Y +):ǿJwփrLn17X!Lɗ"u=!^/~/y4$G٠6}N4gemD݂ J8.dr n!$wk9)8ٿ\c5*[W-U0 &tÌF§ Bv{S?ux .#Ψ* Q~X= ꕂ,yLl\J:WY21.Lp 9)V=$6L8kr Aoq4iHf_^g]{-AҹtJXx^1Ne};/ XH@),s+=ynnr'tI'IZbXʊ N=,&Cל^&4|nSD5(ֱÐ[7Rdm[]%mR`t<:C$ߤ%0|)Ny;5QE{9$L<|ֈx1_#vQ0woWZK㘡ז&u\=@ޱN,'L B%laeQZ׸68E[^e-(e2A=\<]쏡:zRzK3H9{uFMvkÁLJJktg$+GYܼvC3$.V|ĸ'A`)18 Ԣ+{$aA2d~"nYmh$ IZ!bg'vE;#wtRXmLdųo\n!Əo&6-x<7@Ɔ-`)]ֳ}\,'V4.9>+G1{. Ue~eVQ&k6r({M2n[cPKttS?p Rۨ'{03 ~Æ Bv1BV_lJÝzP~Lqy SPwuZw'E-_'4<* !f*X{S?V~@X.`u|9:Tv Y:<.Q` =7:w"]d, om[ڒ?D0c_XAA+s {K#ճp۵n. }41Ľj[xJ 0K̢2v+62ݜĦp+|=y[dUA "1(XgKXI)v܉EVuf92Ev+lv'-ӏBB0=|LxDdz?,t˼YZJJ}D5(oqSCK CY#b7E3'S6P;"q~OP,h^z_>gF3q-җ @Cz* Z##d,>q*COTO#:TIkATΝrc]fXl0qpw<5dFp]؏l#{Nfdg&L0Η.Wwܩ|f|~;l;r?]pqk4/8v+RSʓL24R9NCIh#Di B>g]/$ij3\#}ΪD',΢d^DCVP3Q&z0%bA7lݜPsJ=39gqQ&kH <ۍ@GV>YwC 0t9 Yʠbׯ83Ի~?I`iZA1slPCݦfYL᧫Y` lCFAJ8KoA򱒓S6Ǔ֙?e4*ط0@d+DmdѪ'CwJ'#!!6m$6Wț9j7^\@T09u.Qo+frVW0\`,_5s FiB-v.A?פ0\H#5he?!]} >ۖXQ][(ϼ x'%N'LNdzc} _&Vgqi4MR :bX"EO(B6Q6Y#cr2I+>JLmә]=7 /Gt녷М-zHXO 1mo͂ܩ)Ѽo[t(85hX@vȸ{;7mFsK+O\e2M[y@Y᧏ ŰQ~E*HEXXqp!uwd`>T8b"!7Iټ?i$:JD*UkZY*@ nx4m~C<)nx#/?Gs9%=sM#wYm|xuvN n`uD/ĄȍnvZ=T7|3iyq۰iYv|W4%'P3=JP?/MjI-ɰGQ*@$w5]'s[BV8 E|( nN>]Mz`-@wԉfAoمKnZ̲CO3C^d7OBh,O럩/H8B=| ٚ3la0Rݍ^U=E,·XO?+(4Ej\J5 k "GǢ0A^?G=}yUb|\ER#C8>,jV" [K$4$bd/y1Ru5ABs6Vv)|#xBo%LWQP#hJ5xҘ/B8NiMO`\Xk #µe.)l]؁oK\A<0eˏM+,D41&xir_M6q4EEbݛ㶙mMWל5zωT"z$퇟~PY{BQdԄ}ɜySQYو'K,}? a[ڎp.+B~QY+ikA52#/ >:LhXkp%/B㋩C2?.{qoI"\'r-s-* aY}6cR=~5 Bİ3tSM^f FCeMYDD SӯgU/TIU a5pj_hH.<N/]V?6R4EŧsX[}R ~@&h=tkɇ=Gߕ.Xg2Ⱦ]Eܕ L4XuCٕr' sprż _$$v CT~NIƫUqBaH(*͝L"+QaGtN;NXRw<(#g<9H¶%#>wWGM郦H>*$?.  ?'e'(ō%Z^ P/)=%jI/koXF9!x.cKqdx9-Rͥ`(G6GvuņOAKc?_f2p\#6K  @)CƈA݀PנA˥Hz_h8 #A|5Ql3o\8ޟa!'cqг'O8J.ScD;8D"~P<]0eJZԣJat/z'E)Z\cai L3 |,WH҆N6Znȡ i[3G@%nI̫E,&I!WN l 5]P-JR(KS.DS8@9Ϟ7$Ct%A@fC"`(}MiwGAO˜@  *NE+f'R*#wn~P=n1أ @ T(a F}#hyL`.VV868<'#d }'`"p1"-':eq>~dg8R5=)]q\MOR2 sΫ OOY oqnEi_p((FQ\5Pߌ,7lJ2wF?ym_9kCFMOĥ£@%>MILf~'ӫ\X&nbls7 G.9M94)Exm8Rf< FtBo`\bƒմ~]Nòq;X빾_Vˑd#K`|n}w!)zyvQD$%#sc Ĭʳ}^*TOT1#g`|9:,SM.`N*?Cb)'ɠ(Ez!y6FJ\K\<@Tze3D']Z吹M4:;h,_j}ĿA,7]e_gZiI/zuRCڭ P~7&'mGtF3 G՚ M "l)bOfZd^Vd mWa*c{e Ώ*iJ^ɑ@IN&%fc6 J2L Pc1DkPhG`rZ 7ʞ):/>tϳdΦt[N Mq)Ql6ڃpqwUeJ'1OZG ~] }K l!~W -W!e0Ked|g ^N&DȒݖa3-8w`]!Kf!.na\i%J01c#g%-W}pO H1OSV?Vc+) RK~ZqΔ7fxiNZlxWG4GV63}-!ex,?A0OQ]0*"n4jO:5+Ø;K*^<nb9v'+ѪȲ* hI,T?B`q[^z 2de6]d*.mq(ceO&SePQq~n:FL 7Eׄ" z,l@@ rFUX.yZ'&Sf&}!"Ѽ`*uznA 0fN( c|ǹC8FV΋o %@{IQЙ)Q0:.Y.eOt.WU7\qР214?܄g=U3`IU3nj|O79l]'Z|(=Rdgh @\-??oW[N -\Qs0x뒿e-4g#.3z Z]T {9~^Yk2Lsx.0&snN{x3ݤ.3"ޥf~g]56ب`[BoH(fՠ?\;/@ٹy*_"A~AW{q*V;! bjZeIL-nlaf۝c ~եy, z[Џv/0.hdItCkGi4ORr|3 d LKf$Aqt*RcBwOL*m~s9^[==\8@!ʅ0ennYU^?)F+h`%{]Ly*' ۋڒ֎m3w&1cu , @W&ՏiFL?kPEth^&al~i7X;ɁpPy~ "3+V^&Mf#-QVyS˘4%\@WE* d:t ™!)~,^/Qgb*wD]ПP8w[+;[aBHer LǦXsk:$ /h7̡$>nVBP!rN)*J X)2ngdtTcG [3ߚۻc OwӸf)_עyptS_;ㄱMmYqE=d% q\hJo_u&` l8$qǜI_1g@I 6AkK<9VewsJa6VIq!(eߏ %B ;d HQ/ S8ɝ("&ww_2R'X_l|˃3^l9&P zܒy1o}@dA'Zst8Feо8IȬD4g^>׌L d$[N.,1.0/'+I;}H̫DRVcw~*HזS(gF#j\{iveˤgwTd&YlvX3) U]{Q}(#vzU8̇@-cLOW3ME("zc[{,xV2+mO藪NޢB^.G-3Atvt l^Iy~N(ֳ7MDHK\|!>tDe8'a8GƦ-u5^~NZ\ջ"Lg`O,u\WpJ-,S6kR>Ҧ1 TN_Gn^h|+ w~JnBC lGA넫Ù7$*Z ,VװR#n NFOk~ÑD+ +@L.%x8tn5uY"Db`Tw%>WE-d1R[jzApÏ:_L} DKM2yel{p"XIOyQE>qb:>kLh GϲD/t3&h+cjZ3"Q:C.4OGT%U9ܙ連Xboe4D$UȥЉ*lU12ʚ\f7Nd#x[unjS7gHp&䀺e HUzNKw,l)2)HZB֝K$σH}~lʉJbN=~/i玷y+ʜnk6i][cMjy+8_cUw 1wФ;OؚMmZcbQ0XV @(pݥ(+E할+v֮yshTOfМt4=8+>Ҋ2jg|[J|m\Ùnlܤ⍏n$Bm>,Ѡ ޝGn'aLd(@s󍧃=1‹&B2-S?&sq\` q8xd\vPzU,Lb'U4 D“l1ʯ</5!\̈́( RFq A*mʩ~)ie^Ymj5+yS$DuZ5BBHiys*o>T )nwaQdEne!m:Uh|' +r7Cő\1ڳUҽk~ A!y~δ Cٔb$˓Gr'*݃epijy]Ŝn͖eOZA{;rWǸqTOh^Wv˒0.[8)hy̐X $$qrCJZ|R}suj= ح`fS U9c?[ u8( \9}l_sY=Maԉ';DLN榗]L O6?;֙G" wCReAGs#]OYgsQwu(98Hk,} B:N5Q-jK`+C<|U~.^9Pxl?[8«ǻꮍ/=KKԳ|Fe yBm\o;#5~M1^>Qi\ ytIlr2&#ŎJ:Ntח^͂1UDP;Rľ`xp$҄d28+u`{*h-\ᕂ Bԣaِj2)`9|sE8F0zp@%ipYkFHͤ)ݫ1v+p%}? SOU'6kqQn[=#!ʟp0~ZwS n̿,1 Z zH5%R2)v尔R3-}iN.=*}xiE"EdvVa͜"a6)9.˴6Kdd u-k|0#.Ҷ &_m#v=C <^9iB~0w`^3^%Ib~g.,VWO`*6>v~G]MU"Ptan GoF2H5(M9/, D0jx80{9뇐VFZnmcVA K݄lAUgGF_-TY$7 O&A*;R7MLNH@~֋_W #VqU)vpߪk}H ޕ Rǭ$\3+_y%Mq'BLd1#Hm\l;؞MqJva9_rrۅy^#g0ѳ`qf3?{ڂ\&7;:jz+k/)m4_ 'DŽѡj,n5DArQ/+rجdo0ݷEs1fO Ɛ^R<ݚGW OJ9%R~yxds<6:uŭP_)x] f+q,}xdR`B0}1F5֙K ~:V׎!_K>Ů,6Pv9 _oГɗb>/.-W>;YS|IB-Zdo{1-4_efA81+Lw,zw?*!(זw[X}j٠QP(@#8VV_/p S̑XtH~9ʦ60 #;4R+AG;X?:}сZA0T'XFmC,Qm'}a jýpe--8Bʤ`ٷV؂mܑ%?D9&es0ծ=Y9J~6㛴cL!j+!wu #1C>E譜VL~UY %sȽjkm.qA2bnI^X28rRʂ6ԝ^&aR"ÑN-#JjRO遦e>IXΖvRYJnjӛƛ3j3<0~<g'vhZmcLo&"k~qT`sOН yDfgrKfE|ӧd5,,sWQ4 jD>Dla ` gFR~~l0X %gՌ3/5'vMR)~W<. 0]ϕbA#~#fKxR9g0&]hȆ/]*[>-e<B>/6tk5FEg3Li9T d2 A!. w2 b^^옓 9WHp;[Cn(OmEՁ{.h_q!_}D|ѯGspݖV&7Ne?GסFcJ~fхeLbA 瞕4T̸ߗU b̪ˬ5}CicR$5RuTbSdj'J8&DUQs*+MlSxas2 RA57hפrxj4>("NCCg'wF{΀%ɣ~2U4!#kI g#I\|1,&/o'Oy+xĵ3;fibN-mf"xjҗW{~ w>5ygǾJtaqQ 9!%bY7;Z1^yYm\3!3VWdV[lTgHa c ׎Eg3RpVߡ wZLh}I1A%%tH`Hd1Ok$HIc}=L{aJ!2#Eq~+=u+F_->R{/+J#{4@ XZGAuTh}4kwp?eK(\s|'$V| xjdiOxݣ.qzxgj*Ji؝I彾ІXZ4l ͧW݈y=8|:̗$F T['M3HziK[:  ow=5̘N|R'YEdIBy(]A8xAK"r )80օ|j&E"d̞J-Lb+mg1-h/CPں:Ma&Py;UKM/+V^`Nt(~֩<*0֓-Xh3w|I|4 PBYg/D)҆Ka?T1z!"{?4ͲPPJ7GNEd~S>'v}Dl U#'U>o^(P" [j[N00ԘD3T| N Ec%:"&a#r5B/ (meIJ)euPwWrVp F6t/iiR Ć+yft+6]W*U&ר7^\W=zBshN XF^y1y"G5OB~.)ffvn=1DQçyY W?,'ei~(]WAOR0;'ǵg,4=^MR*;ODwVÌz,) SR;bڭQj맮ybHzrK>JM $PZGiWnv ?,[awpw^.WWnׁ3,r|g}=O o=qJ(8 YN(ۯ\a€4O"{10A&A`3yaC r(||&/JpU@x}§ӝUjoicɈe#ђo fp߀p;rA`l^=yA}id!"3H}%G\82&l%w)Wkpgӝڈp$R֧CH?u2M붓n뎽m45 i̧!2ć "G˃Cژ|TR*Rzm܈ [ Ίi%IL273B哠ۤ$L73_CxDp*S{bݗfLvp2LWz}.\jn;1kCVHYFXIy۽Uݸ;":4Iݦʪj!-!e{\[MS#4]3έKdRk 9iR:Qa9*jFqc{w+d&:q@bL}5U{Aµըg'T%/gKxQ Va7= OW 2W8$ N9r16|Ҿ[09x3S6`RHe &qJO;LǔU E3r#rr2y/v#t5=z߾S#^qg0K]Y*֢&i,/dw sek0(+M~XlYuZł(&5#gT+0n&i*BjBzqS&6mwiEK`yϖ)x4^N6z#UOc>{Bd< Tu"K?(,_(R9F-=Xf,2RGwN9ͷ_Ni">2L:Xx;RڇNB'W.r($&P !8̍6A6oF pݯK<{G̶mivT_))JF*s?&.!ZXml~DkqO_6nO1N={#nHRPZWuN,/ڶEo*n`o&K/V"M@=}C=239A(toYˆ!4w35Ê|>FhPm&:YP -Ch8%(hKI4zBXFyWxp$Ž lӒ_ʷX.)V|t23iK_yBϟ$5Qo}d~۰$V$ iEUXea"*'HK!,\~9vhC̓M~n ~@tE`!-,= #jRj7 ^gc:rUI4/_Nwvgc۬&Nj&(]k-E~bxpJ< u!yzHP:Yr=.H.j0܄y$w/Gap?lW#(fKLDjZRMdX"x^"Fޏ97uŀ. B\$} <\V%F)X(h\>|D$/xrwWc D`M-)?iևnt?xj*   y5b\rMB'x@]kQ38i䀷+'!_w϶Sp wLՓl;H7burGBf "<. 'ik͢j N\Y8P 3% TN^-#;%+]l"Aot'65q"QjsETUh̖@!]N?)bhO)5 gSnY;J(xgvh+2L^PFO1Hi{|Zxh$CU<0ac=?ed 7X4gmPxצ6-1de/7찾FW% @10x\2yh!yuWZ뗯r+ g28` bgGEWLîSk8 D|s܀8n R(!f /쵦/!!ζ:z!0D9bJQol˂A(Ja߉e a=yڷW]6>KX2031qq-OkT,3ۖJ] l`/5b(C#'=H·X5AE+34 LSmw4㟭'?_YhA\K$q=c2D~5Z]bzy!#s}s_ uH:c0r`ʌ%8ЅW8cZ#&A+!brMU}S.'?eA {ڷ#03d{bre?,Q$7M[]fk^ w&5崎,4q!#2#s5&9F> ߟ\xz2V3ne Q/wtl?*ni@޽ք +:x 5Q*xTCѲG }ILIJړHn~MnV#{kmIEtj]&Db5P|!S~AZ%0mXZյʉSMXSC۾_]:ݽnU ~2ra; l,Sl ap8 h*RSDRQFʼ"0?g qj8*1/b:"+iQ6[Y!)]#n679!@#Vk]n.9\R\Cizaͥ*E~M\%wsV2&+΋fkL ˝A[*بmNό,Kd}g> 2,\ u1S1D`5?U|cҰb'&ش0O'52&2x0t')T_Z4Qj@v*[9>tk ħ̔ҥSd#[|*[`P8U}{!J| hVBlq@Z"GþOt7dyJ9y&s`eăݚ}8J<2H;K\&{euWzHЍ}޺ %tr{}(^5\̹CA4TLד>z=`~.BY!4H7B֋CJ^Q,߿8}{mOm@]6.c,{0KILh@o"Q/yOsQQiSGFx$8 1WuZkB*4D J Lne[eO$1} im , NLgj[SNWm/\"{V}ɪX.ԱEUzY\#.؍' ,Idt2EԎ#aɲM+=и\ϾGFϭ)29w;FB[O'w(\QX {+ޭ# yTH ߳T0gw^qB ?-*b97?}WtjU+憎M& ,6f˜Y b%UD+DF!"㿹ZzNGR;Cr$xLF@2!AOt,ǃ9I&'8g#,9ϳuȉoQ wj FRZTZf?Z 4%zF6ffܜ Lڼ<؅[ź);*ǧ5Vf?viŒ>4X?6O7)9 ey'> c #Jm?C׏kC<^Hۜppm+>zd9/c\mHa.yVx]LKуԼ`Eq}SkRV):qV`w v"^fnNIP,80sLRRr{DE~85"s C曟AtA"-:؟Aa'Hsti3a2*+lӝ d4b̎DjƆ#htڝ/#AI1E:=3ZzW'H}LG%G2Z`v\NzŚ[-? B@?${wSV;{&h(%W)ȿgbѸXEMƥH8eK&0$[{ 4͕ŻH XX[Tq3K+媮s~d꼿E}_ݍl 뷬%C :6'V,c1ѩxr=Wdb2bQP0Lf3CS&@S:~&q͙dRLY2Q\tŞȈ3ylGKП\ .HMNH΃Ut^I8*Ի2v8㓃yp=+"{>UrEɩQ`94 Kgv.9:D 3ClY(biVƩӂ06v^Qpf |S$;\;RTo Qem٩a<(Qvʞ@pme UK(0.Q ̣H jm.N[$Oڤ{h^27XiubOHQKwxfD}T,X]ee[sd!"] ÌUݚHPY$>FtU\/&X 1߲N #*f5 I}وQҷXF5I {wUqpOFgN !wi!{2 ۂNqc+:o0_Pإn l:tP N-/ aE_LG Tx[X[t-Pmڝ{IrG;Eؐpb&p7ohWbBP?'! @%5tVt~AC %td+APnbѠC&!=P$υD ?0fsO Z}T2#2IlGd!VD3˜ԤZFr!1ܳG4Swz?sH>mAsxyDpی :î w1Hs1 Drs|B:fa c(C&,D[_=Zi.2POZD!R.2)baa5!Ix6Wwq J?I㓺R1JAh,VLQ,ĞH=e_rX*8\k8ŒR7!4C7 ;LefH ܼ׽-J6BG켉Oe'myrQyq䩨c۰LL}X2PW>%t$rl /;@%|XGl>+]&̢M뚥-~ :LX#!2ZFP9f<6q?t@O6Ti?Y% % w$Ψ}L A^P) 026M%n:AH8Tf(#@*s%4fЃvB3ua‹[#ϛXz?O3#cn/ik}I0 >3I_7*xZpW"3ѣ(|8͢8IpǺrTWI_sEٰN@@g6Q@is8Nŧ5=, (QQJb^8~1kK'#ky i+wެ<,A vO~4aCZԍĬ|`Hʁv ~!y.Η oG#Bj8q5ޫp )LA⻄OQ^#9{vh8P>eW% *ϟ.4>֞Bn5|$bVd,Sdܩ8g~`cflƘ\Vwd{LgQ1^nS.2:T 9Pf!Zo*f415כTDo?Rֈ+Ϧ qk \mhi%+yӄ',._+;O+ߚTb;a?HUtQ I8Oe1noj?(0nhMv1~8 C^&o(>4b<\+t^kDYb2 weãE+65uzL[( hAFO窨~ywA 'ʽ_2NQ2|%6 N<!mx7v臰{X_d|`{{v_{#"-}?/iWoW zlM?BKTx7SFaC5O1Fay3hb\;taXN 6M͕ނG cZki['-^F-_;R̩FWzSZ-Vr#s:>Y ŕSrZk2o{SEr:pdkoc=jaBt!K5/fvX9m#hʐ|NV)N߄G>,K#9}_}5M@$LU|]*}Dqu7"+I/,M7}1xDb&(Vo]]wN^6$XkmXW;h3ftU[&9>FӶ-8cWt:\wDC+W3YB۲?w>z@`RÖK@1;EVvCfx÷wAyI=9_~$LHHj6pfh& m=*Q$3~ ޽>Y2prh3-o ^0k>Ӈ{A ?b p9D&ϵnWM}ҋLW `FfRea @C cPK mDPNz%(ZI7z=PH+*0*U)M T/ ?AɅ*&lȐ"XuG.A,(5Cx` KN& 0c鈎TPe{=-m-_SJ]DNz_HyLLHWf *ݵ3Nƽpkk< )̋,Z`17<67QrF_3BxϮ)Z*H"IchH2+Yg q`Ԙ=u# j$ Q,5H9#sڰpO]_7!OCyq83JͯEi?@,P-> CMqB,$Lo\m c>zxf͝*x$mGQYp~ˀOzh'T_촇E 9t&Ǧ!%rV>"A7Oa]Q7 5 $ε3UsQ{o53>M+6PdVMd3ʸ5z2/;ϝ @ NH(ӢBɦu6WL5,3 o"ǃԿtkuNAx@/UG&=lᶞH+ ! pFon y GãVm'lj'{DD+~+U6 tmr'X:a9aRov _C„gGYQKԔ H$]ºh;XW銳چkCCk2 mީd5o;PpZ 8Է^ 퍒04Bi5eƭ*[H}J`;\E>e ~oY`𹘼s]兀4)uL眆EyJ2qd 94t8aқZt'6H 'J0hk.<҅!v1QIuM l38tB E$ }=ϟ+l<$j[:ЗͭaZB| d|D#eȈ\r֑d9WH{/O%oz<n;p8.+~~nňHxtdKy; i3j`/+!0_lY5PFmLj&VZfG][싓AofITp@WQ#<ΧL{+,U!CͲXlQ[5ˉLj_,Z#+a Q-.$V3κʫn,2o嚱>rryW&פM󺊅4ɸ[PFZ#| RNOi3_sfJBba ΣUө޵Pt&=1TՍ'52mu«UC*#?ׂ'rD2t#h`i4.n:* wS/BPl wZ9g,QߚRaBK)ܭD-zJ42bR)2;˩ڛg1@_>lxTiV }2 "_痃M ,)d 0#B#ܕisR^ G[ 5X&g^ʙ<ڝ[rȝߩ32vLRF]&`8Ŀ/j þSP2 E%Gl٤nZ]r4z tiXTd5EQu + ֓&Hkȑh\6lMȨG-jo.H1ׅA-@=ܴ'ԷdV-:85a ]8{g]l<"ÛQJy3|&gOdL] 4BN`y/ٌN"xIEcɒ(99=7wj+%q=dtOHdI}ӷ2R;e ˅50hl7N!z7PeFkĕJX0jn,e@bK{/u UbE>J1JנoTĚV5^XSMe2|y/=w"H4B6CP؀H|K{w'ChzDnR1WlźZPĦ*M6 #LaZWN& Z[F0bD(#&ΑH13+UH Q*Oޱ%D FxZbA6MͼנB \$ۄ T2'4KM9"p{rի,[TT ƁvV0N_0@x QhĞ %G>Pn0d>y6}ԓ/C> biC v gpuڥ$, LNVj8Qq:SVh'Mݜx<p>} C2V:{%qWu5;ZKzٵ+{y?A͢7b΍1Nrdn궷E+iQR/b-9 ( .XSCצƭ#?4Փ;̃umj6rxFOvׇ,O6NSD~}#9QD]PtFjC/hԜ)A@XJKC;L2KmB˫'L!$^F4հcnIقi/y6V XJjOȾEDBYl̰/w^N6@-?[a E}nN4# _M-wyIXWƋ4=%]ƖhR0G&Zn)rqҐ=p9@LN%Z; {4q&p?:"ⱝOf?F~{ EFfުR_^6v3  ar Nc-H*i:?-;P/l ܖvi #qᣟCRi +xo-jfʺYh i>*ʮkDyEzf#5P Frň)q_ ?FRg䐅QE$u[!ͷ=YorWf ˹3M Bp(SOw?{C`ESOGQp'BsEAwgsJ%r'cקVC*2#ׁU@zA缥8HUj-XѸMf;;B, |JNj5ϯ^) RݳzoR6޸d T]P*i;8 P@?ڱXxZ> h{ K57Rg =HdE1TSX6<_ !¦#4=vu&v{g([=v ;T]h&)SW Ϳ@e`I SX"1 ><,՛9G$ӿDѭ֨oLR ,{nq}e)*;A'O Ɛןh0sʯJgd1)y8^oXYU U( Kb%?Xl&Z{tAb[Jui %:PSg{ϚlyT(؂!}AYq6?SLzhko]}?J +RȰКV_Btrb3n\7k-%eFCcǯWz?L$)Sw'nEV=A0G"sZ|ɹJV>H3u=$OF$yΧFV Uh=\~Y RqƪݲCj< [b.C#tqWs8͓d9Z"KwI*0! j\s ҴܦUhFNȘ(0MM6#?`wJ\(iU/AN{t{uOqQzgc ݰDZ ?7 KzM_[ŗdn<);yG6"V1xCϪ؄)T,7pwR͖BZLmP~ aA zvd^H/Ttnvi(1ZrdE:qL!|Ϣ{{\Gw:g#/r{UlO)'ɳQs gl_$nNie=鷸+YYM@_l,G&4M..*|f(0aAQYGQ&vm7E°=`/r5s&I{2ב|wtUak`ND ө4 k+\¸q%^XմuR%rP͙pߏcn!޿&jrw@T^6⩵mиku 'Վ%Y'FaH?.RM;P -_ZLmzY2RԀMyId YڙHO݉z *$8u6u  Їu6I65*h؇C,2Gf>IZ \6`*fBx>gXxù"5(J/ 3|b1l(.Dr=qv/|Ụ9F_ oRK@N9Bs/ ":7~!UmJ%L1ٕb l>x Oms1NEB. h,"E2A[DDX'M2 p+``DJ%W/-Y&lՔHtJe`D˓t%ߘ 2YFE}g|PзetYoEtvdŐw1]xC(QD-\k츁j͂vji{@ilzjSA/SJk_.Awʾ]9$Y!%g7\V9\('W_c?*o,: ڷf4n4ks +) M7N{Zl0nxݸsW.+'A ;ġs]M~?=4?{wAan6Vss;Bt驇OX_Ա_>:WJ `7ő\8Z~ۆ"]h$"4,>ITP^rxmO4XT2_pd[2l"jN 074`;$ק,Q11+?ZeަFV  Avz-o/r-Xjmϭi<&f^ ՊK~ƵJCelJJnIm h6V;88VFTN4cSZY_˂hVyaAOaqZU _,>V1K@C -\B{H4^jSn,5:"n3}R)F/.YɊUZ#0B]VJ]`7S(|_XP:7IFݦaOրm\t}dw tGh~m>`FkHisyd =&E71L&Az#8k@[ (2Y˱ A!\pJZ?~O] 6z0qQ d9ڷ. 4&)fP=㊧X&|N Y)L͹K '(nM'dT _%P* Vd+#SÁZ8()urS4;3JDӕ w:nY+GxQMA`號7,n+v'RW1XCkcaOP1 8ɱsрio#O/dbpF}x~xB?|lN ,sҺM}j2F~Q*4k2A1ƒ +LkLTZ^9{M|keK;j+l!Qnn?ջSmT ~IOCib 3,/R\{t_2wUTqE~@q8#&bVeK2M$k{T#$3V7a'zܦux սqi UЇߏʵϸˋ4IEyDzqҏ&>ŝܾ\'&;ws#JbE K0Cmw}5y(^>YuqZ3wP:&CNoUWsz!%VR*8W=ӫ_d}0k Pvi^ -o[eEKIe-BO MW寱A @?2˝V}wZo`wu99V윔)dRǪv&n/P W6odx_4nt9JPX͛7S+ˏ׮tbI еUkصis\l%{?kkl.0CCA.,JzD\#Du&nf 0X-`ယPMD&LQP>B*4Acy{sް}<IVV/ WD^5T1q*MJ?{ω;rVpfcGCZtHJf}b  ~(.zzQe@rkBtɱ/2/Z}BЄTČ2N@]s[^UaPŅ^H95P|INya~TiꚐ3vmN $>S笝=S+U`鯬0J7ZFi䳣tb$IM %M?ΉfFd/*VrxbsCx=G?\ir8o0W@Wjiq(9G~f|HW*mwIDh5ndZyZ60QtBQ"'jNJV1ȷi8\o̺[ڪY|r0mfϔ2]&ӝ1_h\8۴ x? F9sY%QB]T$[CTm8PlOJ%si0HW (Lcg"fu܂a25Dҍxk|zӲV|+!+;Yer=aԟ\)t\ rY1K%Wb3ˀ7zE3ԁ=P\j#FD8Q(ޟ)L VVӛ 2 @^!쀿_)ѷd319o.jlƷkP\k>Wp)Ѣ4xYU kX-} ƌ_^M\|6t 'z:Nm$盚_AQ)>@k$O$ٗY)F/U+-܆4l~1FR(񮲶dY.:4g^I-zt{pbNG:~tzc4GhF/Hd7/ر鰏YkyL(M)Y(*2|M3dQ+>l VLO)LFΜEQyaHHExONM ,_DKK'e`2Sn;,f*0̶a9ͯ%רHZ+p 8mOvvdɏ)fkآ軤pdHcˤ-qd3+ amAj4rQǞcW{Cb(SulUxiPGLQªJj:DiC?kai~m'USuv'6|0TwVi1(ax$<]0)66>-1^ǧTu;q4j ;蟧7O(Y8BDZlsG'y#A[mn@:sc r{xELǜ9\|50~-滆YlІ9`"׍C qīIo)@ֳ@ݶOph3a6;K;T>뭸F_1V?_|Q<O n& :(w#e)Ct~D-vƧmNV2PhVw22htjϭ^aʇ_{ٟZjJH4MТ Mt} 1pg(&u581ZaB79j\^FHxU!3SsFIbgs鮃ha{dFo>I(0֙0/_p=5#ٖuճpOy0Hz'7NkZmxG=`}$x[xm!>V YK [J\g$C~Tݣ?0}B.C4!hSBKf3E7^E:TKq~Υ, g[蹇P_/m*=v 2bK2 i+7D΃oEk>@;@3OCr+X}󪺤@C^h|-뎬d5[>-n"ϬhۣDPׇ5K1>᧺ EjN-Z@a54vU-'W[dGsbsLZV[f)|k5 PțwD]û6'g5J̆MhqM=%nw j '{R/5laxoCo/Ycx]`OeǎĹwݹVq%A2V>Phvlt#BPLns*zBtaI6߬e۷Hd*PY~A5;Z#J!S2mΉWRҨk^scGf((uܥ>Hѩ(dg)'3OsL  DK g ):fBdHy-$Cr 6 ^$lgHaJ;e%vk-]TWe?KE&k Bɪ'6KRi*N6vso~N.D{GU"ΕtD1i-]L!,,^+/8nuНX\W.J܌P- {*I H4C8wbk e.; 7wN@.sκ"C°DZ)my(1%DH50zh%N4ZTed֝K .wߦɭB/ÝO@HڼGW&.EmL簘 g/Zؐ PnyO,z6!bP|.}}]延b|>7Pk뚹G7ň!/s}FzR`]Aq5E#aԣz1R| H WU n9 o n)uLή O#16F@xY+Ctw]ٞ3UrOu Y/jz:һxP}1y5OVx tuO䯾^ժD,IX靪<<1zn4^poחtgoW a:9'u] >Au SƅMm/-v fA0m@i| Bc'~μX[YObd}<}t<ؓ* K j0O*]o}G\"v;5r!e*C,њhCWuCjB-XsxuSPT}CX{4:(($(PnTm3P$lƓtVE% [bQgmnc%6>GR,|>,_$TܔBD6.RiQOF]si %g'y\=׎De!{IA|0>ծCylXj&/NᙈRω\ʪbids~ ?ne,]\dVUԲvw7*EHkx^%Z[7#;TX$wrחP57^!j 驙x0 >' 4Uh%lH@hZ_h>bڸOIJK!^en&dZqpv|ݍ^)>2$?prT77R{CAҬ~ÕTuM\jH 3:n|p yuVDg̦X&eIg *0 7 ( +)Ctْe^L8g'iJ^DLH4QA >G=6z ӕw-KĕYFcPpT_}8hQu[7P(q"?1.@fap k $0'?}q&YؤIhsE[|'eq{Cy]d^52U^J0)y>ۈ1yx3Q?3℔!mP^ڂߺf۫W\Jqz309=4M5u#7?PD<+LFoΥ E)}^$Dkv2 V=heB8i9T.>ٙ0T.ns@G#ﰓu$ [ i#pŸW551ޯ_/sB&z{ h%5 h"VAk M8 ߯ 5=nnlاo` \CDcU#a%evG1 O,&-Uڷ6y1:/1M ]9zK87r>͏̞දo6m0 =rMa>OS N06 WŶ # 1.A+ h*|Hv"۬R4ZNw3F@?QoS|ptj06x(p;}B ϛN/;V^>sً:6%dF gIg\>ͭP4#2%w1,)Ӱh)*.tԹZ?τt5N6F6/߄He=~fo'g_i(/cw,]RkT˒Re=sNwR3Z@j-'ro~KZBbP1v'ceWH?hXplj h ZC:]eAxǓ'^jS-3˩Fwȴpbn?Nv\rxWt[z]Jj,s$q\G^b1ePjP52GSn+ p"sʺҽA."Tx>Uo':}p,tZ̦(]\0Q{$V.pp|E9?6 y k4S)Uװ0Dm|@Ekm`e8j iiG DPEUrTX~|X,j IwIkUHQ;2gRqM[hVwְT ń-øse$yk~h}aR!uzyq 4\zn1Ş 7߅P=D |(  =LWӁ6ݱVwVW}"δ9޶sHk-xb:fGe2CRzOW2r%q~p쥪1IO Ѽ l°V]xiwTx.H#au5Dz/5osO)lqH4_s߸<2b 9ŤP86"8B1M wS\唤M,rbsEOHa5k$T&\Ge X8r׵) J4f[NSg'pOqơfm\2Ҋvҵ4\|20eЯ-tͱhv[ܽyu>252s!'380o ZlVZ"wW 0ZT]@@'#~ hT&{07_%YmYChU1PONsVa"# X&*2OO;,c k*]! v*wzV}@zSfzqeǯ/ DT7'gh\1.Cm]|h /Â˷_EYfu |xT'sfv(psҩ1K" @ iPc$"gp'stYVEw7_F)OGڞeK#u+!HJ"vv5M @J1D`mg?c& y)%\8,,_շh$E,f?W*p|\mQ+giI}^ \0Hj]l7>F(MpR ߞÜ9|̒[En(ם|ZjnsejmjyuVCZx(s ߳LNmW;.rl׶d,Wha@I-?1[>NUBfc[66Gg>X.⢊]I{ ٯK?HB jZ2 gRlIN BYIy+E&Pqr2E]8rkfDrduI'l06ߜ1>MobtV=MNɗ0Ga SGhS&Zi֮!?jo]o7r0,\`hdLDȪ2Fy \qV_/U|AWd~gN]F J!g[VcL-n\ȫFd5 Z;)zSF+ wrϺAcc,_eoRU8f2ChHoj)7vzgT^O7;2뙫d̠QҰPoPA3^v ToOxt$G-20m،EPd,-_Yrova{O݂QNꮈ 4e?7 _yj3S5ځ o*/GQ$ InŚY R937~*>:2aJ4=g, [5fOoUvS.T)PN` nhLDtXuYz(7;Mň؊ڄS"/ߺvUH[V@LIwǵ J5FF5"&g_ѢI}\,R{"mcLLԨ'[{] n`C\L^ۗ¸mKs)¡k;Z&ƫ0 R#*+HD_A,"=~H>>p1f0eizs}5Rw<( oD]>esqgX9"w3~3PgGaa)VV;|xO}M2#࿦LpTi9W,eL䳋$H9I< fw :3 HzByf 1LvK3O8+s(,p8+mA>h(/Bw?~]֎e R cRtt͜| nq$3o7'e1J,0ko+a}uHM=%7^e+}}vO=97J0?dh(~wA9F|wy"q+k:峷)#g-2VgM=s'{KXKgcu7k=@GS0C~2|M1:ˈ29~Y IKX-}47۷G$%nwAcV@E1 V8Ơ؝')9\voX9h7| rt+ p)ICfN*f$;l5}$۝o>oqJoV.l$c$B h-|%kGojy ˆ:[I!>1aOz]T%"o#|x, HYTvi/K!\ǺBf2#y(6RvRoMdܷ- +.JCM9 c~^Qj;~n >„zW{t)$^P:kѪa왕OAC|;_79|UIX? |Jh*C̼V T+ج wuD7i}dJYoSW^:l iJI#ٲd{G7cvYZvb[o͹&!P0chlG *'Df$ғ "R>8 \5׏,qpsz; PFDb}rHčB{W@N%eVOTѥ8LV6(*`?9n#F5P\5,@[MTqv'Sc1[X h"cE(0:϶,N# ,T̉܏=ZŲ2QKon[6ơ^ٍ$TOQi&ag~ jmG%)W s&4_!BzBfd9tKiL\M9q|N\H y5K$߀K vXi1< se5s*5ȋ$we/2?v~ FϵDFLBd^; -jgB#_)\PzfQw[PFTrc}nE܉\([ ƞ͞hj8ib)t3p\ A՟ߥO\qWy1jﻠvVil:rHeK_t*IgȽT ţ,л \pOJ?e/wꪕ$ҟ 8yxAEMcѾ(A-?X%{B. aəa%]lxB9!ObW8+;뿀eBj^_gOEBQ耶5'3?2x5z'a\ڣ j-n >ekZލ߼mX~h0|a,e\xHSǻ۞7ƳR]o!6pA{_ܗߡ>2K?I>8Ns+.s8 _k8CЌ,<ץ .&SNC԰nkҀ6VR(/%B&! &@- J&4uDb#P )عK[/VGL X|GW}}1 ߅=+4aDvJ r ^ I2aT1U.qĹ&6t+CSLe!{ 814bNZa$R@.rRL5؊l׮&Ɔ( \!lvȵ/oz9 y:\2" #t}:gM[.>#e#hJ{sj՟B>] :t@H:T>kSS:/imV|3Ő%,uΐ3+ݭR\-SMHɢ*qLEwn1KmzVdi.P|}*}`4}>;-5zXMi(畒'9>1Qм2lIvBW;=`g ۭSN'11i]-'nuRù"'[f"KߕLNMvixK"6G+"`o[ $HcM2 mZfmַWt1x;Ç4IapPԻې&4_ Z%LJmjd(J`zv2*s0dKǨ ,x0p)[ĚX RpjOps74*aJgkέ6& ˙!d@,Cc>hq%Zu;6˻?v9n(PdvD7e5 j,JL!Oèv3˛p1gI(v4^dNw:w61\N}fWYOv:{DUH$]0ncMS 0N!}rɗhUd*kyPYb-gƻPZQ_s'%D?  uUuuyDs̶# psD䝐YIvK6SQ-ֹh"@UnC[7Da}@Q'*P[`lNA&/Dʆ s GRO9x1?%I9䙥SW `CIeN 'e٤2 & *ṝkqt\лROޚXz|Hx&ȳ`0/v?[# YT?抮 Siz!(FrL!@t^2L_"Qr.2 5 MD$.3HB>:1;hb$%`5V3`I_Tǰ><"y4 ik9sPDCH/DRW¥4<.}hٚa pzw SEiO'\-yM`͐M\p\mijƂ \dEˎZúJ}ksQY& 6Z6^*.om&v֮Uk7Wbф{(pN)`eH&'uT4P\f99den8 1Iv{i=, 3ŴBU %9S4XJjx#9hg%nՁn;Dǹlg[p\eq{{{wk%N>P4JpVi~wU9ԚjHIESUEtNӵ] v/Do0OogyBBkd6WxCwծ$*KDVk$Ep)}% ޗJJv0CmFSh~GZUNȕgB)UIzB6\/i&K#-qzAEQ%OMWPEw +-JWoT_8 e >w.>]1Y˾&>(:J`߹ӹ.~iu.赋)L7q6?H[cpS0>fiW<ɔ9YGzMC@*ămJȳE8`ߕUbUGJC1̅j Hvgjj6F}Z 䨁Վ|\σu}'ODȕRhx4_#U9Q@(y;: h!eI( c>lRY@)ʦ#2&z)"Eei.jqbcO2.qQǼĝb粖pE< S"NХʼnciwsWuVpDG Rk}gQaFLZg HnS4Tʻ7gL֔O J|ҕ 4cs5DzGӜZi3Ef cH6_x 4*\kt)x,,dG "b9oAkXB鄥t8E0F$ꚭjr9:/v:H}uIe@! q63 U߰!}wT[v -cZm XwݣSt72|YE#{23|zdAтD!{%ꯄ%\PVmu3oH8=LcCd9Us$8EB9_i`|$H _zw&bޱщK3)wcM:Ơ؅ m>qiǠ1޴y^eQP!SOXG**{hITX>7\*Qݪ{S\tA2]Τ=WQ;F{qY"= |{ w43`}F@4/bztL;U޻oDz 47ɷIf' [Syu1>!G ,VBcX3?]bK/!m)XiO7(OwTa\(\'sbxԹE1~Fz1+'B>nvzKj 0qfиo@plG) )Pܰ W*2!g:UL>mgS ^j8X947!{~RK,~IE߽?T (-PqsӰR7o9|]>=^\N`қ&1I2daGn4>>QzW J`eMEN|E|;BӋUƃv}cxv u~g`|6̓ؓl63Җf7xS"1A(T>U <%1梒&ѱX~1)lne͛Mx:&)I!K8(@1(.9d\ 9 ;ɯ_Pd֘Za4"=݋1!i ~$WF^$b|zgVe!ra2J;66)A2fHuCCUF5~8qP(*|<0VVMVk(7s/~3 #N/|2I3bjfSHu{]y5NtW)(sd'gTFT֣64W5%JAO$Nθ7 yq-:(Bw.ק6ʹ Ov'9 XMH`#ɺa_ؒ Հ $m_,%u~Fof#Bs1u8tаlpynH P8igOz}X3ag\MƝ wOK,R|4("7MJTU|M!G܇?(4J,FVH9ZOHssOOQ9^ cQ hHy 7-鉐K#wgZqmK6vÄ4Morl),L"Tp| j3|p9Oޅ h$jjjpAhm( q/*ew¬4=e%xYsD'㚍;$jC3PEUCTI '$4 Yh9 y4Ϣ~ Z`ָ4HLTR}k7M@XyVQY*/n tV;ʖ˂f'Q]Ug?{S)>{ZɕC:0ĸbl ԩ$3=bAUpdQ0WBȨe '4;6?7~1McEy#Nh܄S >qbl=e 0Hq*jW6q,V!''zԗ0I4z˸) (PFD2v /itk-em{-}+3yDy};a|UÈ}MB?ʤ{rk)VQWG1nBu"I/+$kPމJiq-!C[:&q'<zk+R( SV>8ׄ%_Lp H!k.˿A0*E' FvW5BQK!K濰Bw,"U%!KHIu`J7Vjٍ ,c&h.},'^<;7YHh/6X`L7U]:KŢғK>|G҇AUN \1L"`X?G Cmeot=yU<8L|QdJ0(<1:ӯq3ƞf>Vܗn/=HW#DJ!QEc:_S֍ JﻩQi{Sb(\ǹ{kJ*(zޫT Pp)m f@Y uc-*o;=rmtGN27rC@+,g}^;qԶ:Rr\-.f4 6ެQpPŃ.%k$2/,ڪH`q9rU۹&\dɭn$Fos^z)MPBkgX.^A͛MJ<꺡Bs#pojg04x mP5Ru{v%vWѿfVPM4f.3("MM3Yނl>hR%f4| rG@T\/VBg\'=: HXVa_o䧂9\ [+GԿG+B[.8 Wyg2zˤ蟮sd[R E V QX؉QϜ7U0 1iv B8 .SAL--sQ=Q浪eTEEKH++7PϾb3bsL > W!h>oOL4#PMK@  ),CPCUG$(2 զQ3u4LVq*"q o잊@?Sa"_RsfdW F޼r[M:€-9!R#Nt!}ϫ a¯k&ZChl.@gk ';.,~soON83`ǒܲQe[p 'u+D)`|ӏ~`y:I9mBᣀ{I z( J¸uƒ05qGЖW5l eԓN"uc:!b_+!2brEJ[~Z0iFJ.)w0Yg;\~_'g)y(Q͠Z.fa[sd4As-&s -^g?Ǧ1=WKLy]K dg$z2t0,!|ؐ;%1}cNPN_ϸƩb1Ym>%U?4[AO-oh!$PnT ߚl~fs';"t?nanM;!SEFmxt1DjN.TѳO:9P36xܴ!^ &ɾ(*'K.T>` бiZs f괺Uɍ襅.2RnF*ʅe'D ,8[ڋ7Y8=n,ZVtsO;\Z -J/3${hq%.s2nb1|+"j2ͯPC]8۸z*?Yp.;%Zh .H/w`s$Bv \N.5BL ݶT{!W CQx_8ږ곌S!kyUT?*MbCoBj/UW>q.32$kMb0Upܟ׬^;b 13T tWb٘@-Oz ZQ| sFJj~%ɮjkx 7jCw@`I[^Q[n0QWؐ?w"}5Wwz>GENtM'bԈZq Eo1G|n p~`Acj4 q||MA}KJ]]ᨏm_}7jp3m,(s;zDv*pc9d -P lYdm"Yk/dO2l[@=;i9WO(6K&B|%<:޲?3T}e:U3 3̔eBI5RU|zZ^F27w3{: 0x|b`߸n!`l|iY,o˾j۲qkJ}Nl8/`~mZʸLDQ"ߓCmq]]wT.m+e19Q#}m\5)'a/ TO/#'㞞 t0!x L<7 a$͗0 !{DHOjSrz)4_NhnH,F[Bضb LdkGNV__silk>C+rϛ鴅rny_{t:`kڴ+c2]"hW>+.R4(Ȁ ̆Sz.Cž78@B]K5pRںvÀ%QP^tNƮO9?b 慳1XdRTG uֺ +!.IYL})+SHKBƤ:%<A[ۦYRU80Vޒe@*'PkPFvUa+7J'7 {U0B$9W2v|m~X9NqS C,2yg"q!}>T7Zeēh(E%s0$Ƹʄ;돫I,KƗt  H ;}JRQ#RTOG--~ q0hx#賛㔆=6nG,V0,: rȖQU"9gsXR9*C)'$^jrc> F7'" )!%mzF0GAlWf`c r\[~(͂ [Bdd*2&YȽẾ1yhPq٠l*bn$p,}$vok=Wۆe(7rRsRz3UF῞3OMa gI>t4)Z_.!).밺A'g`;Lٛb;`-d Ė*cY;O+*H ³l@;w tbtpgrAB1ǽBbBTy8O4-Lg_pkp[;_Id˶+v8υV($A_OTO볡r邼wRAo997 @H+4'҄e-6%P՛VGi:ϱ[p${aUWNI*E843rR'?zGӢCtfA\HUiW.yQ$"ȤĔ+s!Aj屜Tl\)c ch>I*wpij g&ە [18<ꎎOrAd*\)T{U#m~68%VYj,.5W6%^Tt2.#MwlVWQ~_=MIJkg>i[y(MILBSL}jIixB Sk't3vev !W ܥ I '%Vn ɟb1~Y@k_]0̤kɛ@8T=Ŷ݈IGAveN ePO ~J{ۿs׼oO&p&Z+3T+H_%*;z8uhܕ4UY^XQ+#&E`^IR,| wnF/Z( n=P/d|>cc';%af Q48b? %I?o0m[ mƎ*E"Z0~W(aI31Ur 7W gT AiL90qboEmAi /v.DO!r##0SoשZ3W;,&x& }y1>Oߠ_nm/?ewB݄;RX\4J[킁FXhqcrGa=R-jERMxN͜ 0s %iA*_r viw _Sx+PȖnH=Wq}x,%tUu`>q.YIPSEK m\{A2?}ӖuKb2Dt!$ߎ R[ tZ=$|ӝ,.'*LL>uM;sf&7򫍙qTaGB}Z?VB ? sVQs2Z j#GuhhYϓ `<(`ܒz5H1V^DWC7{4GAL7a0c̯1զ'u(pwd]}69_*.3ơ ج S[(d}$<]FaC\<mcKN!CGЃe~WI^ %%cUj:MUkZhWwœgmpvʮH̞X69 ƙ_N pfag1Dm: iI!b `LUqv4 C8hs'vpʋ ש$*Jt;)o(]a|Y @ly)C yC-"?~xqF_գR<몶]u esBrIPkX3XP$MP̜҃vkR"fMןjB *NQ*1Fx~8ywg{DaPP%9nQ0hF7+䝫O PwH)2_fG~פ7ShØ0KK"Ag;i] Xo_àxBLr~/joaaz@>|f U1ـ'y: |$R;s|~OݏJ4tjݧA0ۼ+I>*5iwUΊ>Vň~u_(ء>" B@*\N@Ȟ~k n ݩJT(B$R(x>M.1|;(Z|'h0"1[å0˩o%D'g1 Y$$gn.{>Q_8⑥6 h/CKUuVmMݞ;5l ;|jBc3Y#Hbj=#K עr }t]J+K݈ٴf~E[' bQSPF||BsSQT JCc4W+Zq}Z9ס6ᑞn_~t@EG\[+@$Z2t[ota]q6]7Ez׼$oΝ#Je ,nPM]^V~3w7K`ZuS iG׍j1y<RARSXHh\AC=})HϧEw=ꓘn} ɢ0hy'k.qä wJo0+Bg-,|LcLDcx=Z-O\ ?m𨌜筪ԩ"qP  j}Cv%c(5ެl8t7H QԉZ_`1-:z} FN7)w |e"\\a7m| ]L{g+?&+]ro-ԂddI̵P1icBSkԙcWGǹ8NYT)z ̗1|f\S;U .O!5h0J[soF4 D{D`h"p8!= Co\Wj3 As&(m?S\ uۖsRd`U2om+ w_9,mMT3('[Gbr.7'rx2MF]t۔}hu%#κuܶ(2#QOEKԓ s*&b\VdA7$?]Wz U4/5JD=DB? y}=԰7~zR?X5 -n#t T7lEiBn@TNF~.ؗ^8<& D@R#ZFE rև,YQ|-&/9(ZWHz7QӪ5&ʄ;XX&/8TB,x\bpC(}mbԃ΂Gs_KٺĆz7YiXPzxrGz}PH  ҎU5#΍A#.7\檽äzkעgvP>KGߔ>$^# [(yjP%tfk%s!)DYHedC .xpF(~5q`}("brⱤ)IIL4>aRf|Nח]㣺=1V2i#[k꽥ߧ^: Y|T=k*jD;H0 k;|jQ#`Ri%(.5ĨV/lGa*5 \XY(;;p%Usj:ZVgbȺV)uOޏ&OL' 7ZX:T-6J6Ɛ \ oI~4գw-=)Y63I$#k^;^ΘSxgə[KƜ/9s^x1cѷK?v'eO!\#ۆR2P~hTCGgd7zɻElݪ!nۙLJ6{DG.;XvM9bK nRhx*Jn5K/x m:bLxْiU4rlLaqg#Xķqx ZgDBcG<%鵣s dv(?8R$IPcf`?3sNtq)gϨ_wǘR@d!` Vo}S$ uEGO0? :ɗpֶM8A)e 4qG LI:9sG8:Y~? |K[^i,3 O}9"k{+o +"vjY_oom=>I2x`c a&LH[ZU E$].jMe%ဠ2i._8=X͛:[g8J`jn0Vy08Dک_b!ݟ"J${OTԬ3CЂ"4^*|µdv:;FSOڼm̒I1u M(]/EEu$8hT \Phooz~:سҲ,FL~T6&/Ru#jm16St&0!>8ؙ!/7x(K*uu5I|8=O&H%8{bS-MjӔ>o,o* lwm@F*ό"p[5}m{[4EW?'VT΋Ȃ֨b^юW9۸U=e*)2&@w/Ina&xޣ }~۶Sov-Oj ~bǣ> OrMRZ^Y?Y!JN "nLqoɌZWSMsq*B|?P_I0 <|eNo8]O#S:g Wjui; :-#w %= j":/+ŪR0dts{Q ;]:TQOЁXfs %F *戸Ohf5끭l06j9u%^A-Mˬ )ߛ;wVm0۸bUع%3wጡj4))fȭ:ͦ:>tWĞ? %3]Uv`uT7&lXD Cr.|P ;XCoKW0Hmm~'KeX2[{E.@ {zbJqb|GV-Ƥqs^ꗞB6DA1}bo0TLn.j72ӹgzhݞ'DdiF6QU}raH#.[*x@o>+Xz8*#pa|Idk/lNCKDu$2w!%oɺ>,Om6y18jɓd/k#?5J-#_m|AVᆜdqߓ`LZiGKSI"QW%j.*RS1AKd6@%<+َN+$n.+NP Е0w—Ե?Ig/V xN_@Rye:z"Yke c kZ1F&1OonUv h7?zԩi$o"FݘCA>|>޶ذmi:Rt6}9 &YC:ŇGW {1V&pa(¿WoJl`9G!.Sx,j$Y4!ъjjuݒz#_B wϜ،fǒEE3_stf( ͈.1?tS Cw (Mh$9*cOIAK'#pG1iR|tόBQ;>Xk( &q4 Vrt0&H=Nk㨴uʇj¬Ө6|N!ِb7 5?kԏmC*di$d:&!< hIt4!t2o4 HPӵ{A3NY˚:MqNIfܤt`nvQΒϔd9dw:MˎGԟɇ bkă3xjQ %Ym;-s$$ 8g?*TiO7sk7FZ .H$ (RlhYlKdx'C}r珚Nc-ŀVVBGSI q"ɥwdie^r ŋlG4:5eW@|`zJG# +D8Qhh+#i.cj[wL~Oʢb'EZnLV4c90DNr~;ik4'3$uiLpA#*ΈGU4LW (j$(z+$ +9 ?/z=‹BDp KnIfvJ9ia[R-JpZcp6Kh-,pBqL'|y<Z=C'EU׋`ABJ"_-L`^6G*E;6n|(Rᓳm4 h n\3֜nE_8]җX7>׉-6zA9iOǭ魵^C4ȅIJk ^x1,hׅ 9/!΀ɯ'đ6e֔ ,8xBjB03Z+axO +LÛOv3eOodbH̿EZvFDb: **g?h+Ǫc-?ŔM1c ˧cWmT \b]7Ϛwiל0nh:50iW۶F2ֆ!D+m?l(g/jec])1#]<%I28ce$!fc,zjP*;94ۀZreL.AMn锔Hvrv~nѣA1Z੼SߣI&C hGO`<r[W>ZJJߓ΅0Jh}gIɪUM#Ԧoy9@COeHCarx+C]0fjf誃D&= TY/'+\Nֲ)#$TQX9%嵰8-V`<o@D!E?z/'DM%ӥ?YnrW-!3GoLf>iSJMhC)\ulFs7YySq[FU Y$ËgHR /o՚ƘeX_Bج*>+f-UW%8!HfWfUyy4alÐf (_ij!Nu猼.:M,6Â`}%#ܛzG9xU`&^' .mf#9oLf!e$zTse"w4u_`R6ih$MH;NhR ʳHHfF94P\JІh;FƦyV@A rʹK:&=cc_ ks3z#Fpmp +oaKJzj!33-QjO/7Z>tXD%7Dg6Ė(}"@׭hu֖]ЊzF j^Ѡ 8[Wx(Aq5|aRQhlJHj3~ل56:YaDdR"E'6&A8㜄u_*Wo%OrBx$`q}*hLNW/*Vwf^"_6]&J 5t'[7kW)Xdn `OF,uJRE(k9DME( 2kiiO0ނGשg;:?sPPr54Cs-iUjCdvZppc ]Q1KSPkh-@[ :Д`$aK@9s9%u Dή%6Zٻ߬b}o2^Бya?uUR?9hyY>4B°e1aޱ:Tm+o'"܄L< HAyH냜HDC]v#\U#4  rtmF`Ƚ`y5;fjXXL!Rer\`JIoeaKmA8f,d^ nl6eYXnK~Imt?[A'`SQ(/J3-$7gAWjB7d6 ʊ F0bviBZ$drKBʰjnʫ. )/},E„%{̐E vDJ JB|lzh;cVôkɰtz+m%}j "#}t(DGo^6J s*F=d٣cBob2% uY=ӟޔ`VSJ$⭒UaFKl|ep vn#'zrW4,jYQT`1cٛ5#*b=0Ys8^E`s@ّK|³\>s.u44TADpAqna@äDJ"o芀d6%I[Dop+H;{\Ƭ,, Ѯ,W@mUv:!l1<**w\ 6`MC^ESvb p?GZ|OS.^1Vlډ,VamR Б[An|_L.SxGI"V5oxIJ!JAF.[@^ux̎e#Q-ZT^sk@J I;p`43}ɢJ\y%7X?ڴ0 -~ ڈXVʦZ%~'tbFr{dU j9@equ mەFB#\7ƊMhCՒ(>b[ۜ<̊([-m#XŪ4szW;gpv緶LG EJZ[en{V ,}!Ӂ흂l['ߕ5W#[=;YgA Je3x99ŸhcfYJ%LY披OMЋQZeh Nb UBRZ;Lh͠e ;a}cޗG1bSXrg.msڮ(RļjY y|btNžP.0lE/p;-{ҼQ6LN~eRqN<eۮt1b }9&h@X@3Ƿݭߔ0ve@68 X#`5K3)yY&Ytcq{}ZڰBQ@OW7=z34!GOaS5v HF뒤5sӴRC:+7i pd%_aq+ `coPΞss74$(^gAT+^ Rr)^/EM@q=?)C9^@Dό pra)-6M!79b_ƅYG@BC*f{2,4|~P .DCH -0u<_q)#3Cb+T6<1zJa- :2ժoiиzT3#947<1U76*`iVρ$-pk&D (?0P% !D$?Ү8Yl@6w兩(b.K&K/GW8I KB{ A 3q[wVƒ5_˘0hoM3s~.WziN]ʆ,50Pp[ljdC=LcFN.GI=+I 3X%c ȮcIݰ{ڜKJpx)Fn[MǬTjXTj'f(>چmuMDЅ]4`abMGAU)g8qi~Ϛ9ޠJE\p| ťdu[TM,CG' ~Ef'L`Am[6OJ1*ه8*>5`Z'P[vRPVRd]#M/ߒńNF<k=>͐UT _X6C-ZyyGԳ3` ʽ2&T)@] ۺ?Zt47 h97WO-Ίϓ9C@lA޴.pxQ< EtbEGz P|&rpRKu+T-_af;s3iPE85D,ϵQv8n~G2Mn5OF ,N]o$Y F SZ+߰,T`WE*d!B-4!(FT8 $X; uWn\孲>cvʕg1uGkôwHԴӅj퉶un h&&Vd_Ux9Bhޓ_'Kr*5pD>琽Nbiʊ:C+/T*O~k*c4G!p{f[Fo) 3iԼ$g,]{h5& '܈mdwm};*Tl[\gOmU؈u)怸k}X70CˌZwˆ KZ2Ų:b?m1%#8StLH5 . 9-ZBI%fk$FBla/;8po3 '2}׵ yq(: ]NSYo`V.gT筄X'# )" !JY$NactQ@9I]b©5IG ᳭_vW 3*UWΡu o,Td ֐Z?>rJ ;_jՕ,HNBw*vt-qچxeB9 ^z0gS g/:*":Of{;փ`I"$%e%\D.Uf]D:t΋ϝ#l Lڷ˔2sU>c_u'p;*]"fR(̇B ':A''f{pyG,s8 ak^M\t=2~n\ ǭ (W I.Gա[*U&X:z}TшGs=@iAl4 }ek4ydflK+kw~aw tOHZps|,3 3¨/xKWٞJ e O I{׸/6zO+^TR}#{ 3iXD|R+] vcq鶏6Oe꣥!A wEv֣}5J.Al˽_u5vPAP9FMl(c83my./$%`t:LNevLV\- oo A*F2"#>Nh/%)퀲-PV%ǔ;JehHb.[4Ǐ)G#L{v[qsuq͍.Rp^@9'74$BI_x6P2-$ȓsNccCˆ kơAVt뤉9oAYD^n- @0p褻eir^V/9.># EqE;%6|YNQ4Hgx2*c\8Hhޑoex4#1Z~z^&sE8 > o5k߂ U'#.}U gͩye&Q:ͬ` 7g Nu,A|c˕@[dZAӰ#j^j4fG=޹?!r|.9#h0#=1}A[qEhVTLfuTQ&u0vF/!bGi6RN[,Wźk1nT֨d)N'1G=KJE"o!t.X#b c 8J}ЧTe܃=ď';P ڋsp$ %ʴ^A t *Vne5hÎb^ -l9GQ N7*9)x j)␹FAFt_pr4F14AbO7k(֏׋2t>0v3aDk(ʚdu箎8%EL#G6Rz|6E&vZia|+Y'YFMp^{Wr,2Ng0TX _`[=ӌ&1Q^ojv?H' H)]=}b 갲`Ē,drΒ(b @o\Ɍ{c=7$n0hg4 AmGцH;Wb1g!*Ās+0^+0.+ҋM+g4)u/PO<&_\ KK7j5J2zqF%@g#['c6u \me;8jw.:^Ȧ+%/,y ؑJd5׋7߱K"|J2GT;鱗}x+kߺNNC?fdEB1j0P"b=J>"eVZcΧ:!Oǵ?BQpk4[aB XfF$?PqR8qٞ+&g.^((Ff8`xYӒJ)|[.f%qh{/2g !=!3 \ȭh*+ LtE ˮ&SYϦG`e_fVtmcZɠ‡x\ )>= O}M1(k6j`2REs6s]G}%Hz*4o7*;U:vcsf#l ͗(cI㥡㦹%D(Uwձ"_b΍GV @RIay :,OR,UFFT-Yq }eJkD:VLθֽn hdaNG}i8$;rrL2-7^ꟷUn ffGwqcB0"~@lG&e`mYXM[/kobTzv^g.\I:Oxn:(Lk[9K31H?&QN@sQSu}  G4#֪݃<T掷>LE8 "RL$$b{0+u\JmBX P_5#jkg -a, wL҂NXl*5)}r ,of6hN 4E+` x!.}A޶) *%WL;x "o1$$~C[ )hߊ5A s([φ%TKl\Szg`VT5԰kɏQɽqÄ*)db ee[N@`M7ɋլrps Dt ;8;$!?5VRUrkz{jPz 󶔩>?~DZ.eH(8&]=齂WoH Y=)DT?Y?8gְY7GPI{>@VZ4~NYU{#,/m%|0)K 2k]q+/"\=MIlydd-)힟>3oVz/s#eЬkpNH/W88C3<4vrEQ*&(AY&`AL}p"fk0$VOM1w&{s\H.2Iumn%  X3?PHԬ3G{Q]߄~DP1 '[LS5 Y&3LhS8[UƏT{)ˉhS2 .*ԏ2R@PNV?sD6K,?jp'?e'^Q=ޮz퓢&MO7|cp?,1NˍU5u#ZdZě.K/ lY=T2)oO(hڼf:bTSNGO@3(TmJ Q+d9ʶ%H$Z,|J;T__cڟ8st߻'0 @fv3K-i \8lϗ.̀Iu+0vTC)"^0)\ MfIþ4qK #0Gᚿ-'/ p>\jQjL{9V>q<q 1IOU_TFE/'MeJ K pp˞RN|/"uNEٶuEx:ϏB6K>(? Ȧҹ}BG# b;zwPX(d]k'd-Q|^'ivX;@mEׇ`5>mT |T~>iʇMs_YbmC[7}u445 !648ɐl=QA:q))OodaBA緯#˅/!w'q$زɐ?|/}FIܺ;].AY':,?cA羝8<Ë?PSxhC*V=cI}NTQ B!S,۬c[yN֯_R)5˩ !m꡵IN+|m)Е`rؤqKﳣb s1n7i۵Xp./Cĺ.!G!:hSR7D~o(57#;(bk7vZCKSl&.ItۗUT~Z2>W/5.=Mvl } L ӄb.w&U؉ەCC'`/kH~(Ew@. :VQ}Nx1^yVLDa+E]t-(ѠoBEȊx\Y (gTl9[K"$@CB -7BwIz̚T Fՠ(:5b)A sgcGa-52xg gad:ߖ0!,Z9yyk=G{2.mInCxaFTBӓ6Q7U2FÉ:֬ }(\Y ɉ6egf9*$U$B&vnN-}pXڐh6r/V{)$~g:]#3łTpȽA?8?bg^ H:Ju'|]Ńs0[#c" ?À!f,akuwVOv)VE-1w :UY}{a # !DPfr׆V |dR=ytN53v6n1 yNQ% !b= !7w#G(2Ts#525K[F ^tX5eu-Z Lv;kV^ , rAE+=*-;0@ͦ%mT&ZlK~WJ,K V,iu<AP%yZ5: y0,yݳ"6"kg}KU"{?j+! ~ qMcڂ+vIVoϥK<, 4 o5ƚ=_X<<9k÷f\ :>y)E@/MS .I~N`렆dW[s}Y/tra`sDNC_YvScg!|}30UtKU`ZUT;1/[]פq|ӻ%X ,bln]:zBqݯ}PȹB3y.sMGmRgE%SnN@;@lYֺ`^?AXz4ǽϰd3KFuI? 8c0Sr@,7T5Gr |;45-]jk,WT*ຆc Fҿ@+Dꌏ)H߷SC`5fsg#$M kmYhd\= FŚ{lGe酧M "C@w` _]3V8`c57m᪘X)&,thokdyVc6u~5_C]bagvmձNd_l r5Bhk$ނCfMx_|<^j}ʂd'zK eQj Dc>oD՗G6B+({ <n7)A'p!E{Rވoq^0Qnݥnt١{XQG3F%Dofe R\Ղ*Qy y)$-?vqcZ~.h?Զ64ȑ'|_1jFK9n"sx }e mȚd Jm Kr0pO3_!ohkŶջ Gl9g]JaL?ax\?]c Dfp<.YCXM)ݳ•s?!>ӖccF@ cJ_% M0q @ܰ^1pca[]ob_ gzń{,QQf}ꔊ<~:U^ FކdK d-i73фz, ӪD-e1{U7z箤6oض)Uq,dZ PPJAZ|x3{^[LGٔl=?]l_yv}O0]O_u Bʳ3-(0pڣE]cΧtԮAuPȅ|ݪ6ڀ%R5e_v][j\,G'ust!k%hgOE_cFHA!PO h5hRǠGnRl~S= zw/ÀLʣVQ9"o^VIVr_?JviϹN'8pKGhcЭV%T?a΃#I-*ڙ7u񒗨Ҏj'Z+H'$R1Hƍl 6}~sF-Gw%D*l< J"?Fv)D&?vk͇ dzrˁTB@FGH^c!j kGpp8+`!%ӽX`e`Z3Kf=V n٧LG1G~9%u0PH4N,;"^|:"3^R$y}[>9("EBIUJ쉣D5E*vsi^s2b5\!ȟQ˙]48bzV$JMK8U<1雷Eb͞طuDtX~Jdŏ+EĹ:(Y(Ze@m`/I"<9dc)  E \f&͠fv&eZ'oή4,\${믁 j2]Etzm)WME0(Vwtƻ"O|As1xpLc}^cwDJ5S_ki➟kh?d/יe:"\,ŸOVb'c3%D^}8 01LGAjj4 \/So_b "}3;g`!5 "´9vq1$nU&@KQi irٍz!ARY 2 >\"$f+p30 79U Ѭ-#H?7AJDAu t+$_o=z;cJD -z*fZQ\{*:xR $$Hn=JGfb=\& IP "يҕ.N_m-sIJUgF_p/fJ`Y73`t]A&p18axVJڭcQNZ=xA4w$rtV6e@=6Am (!W6VR5#*lP7l[@G~HbݦIx@K~0b=YӮptQmP~(_Ct0!cDp*}dئDW{cɄH85PeZv2sIHTѡ}Rr+>psU-í4G+u1tخl0 O:u@uAXٴXi3bQJ,ޟm,*1} }h:/]9T[F$9 'Ca֨ǟ϶ڲU (S/6Hz?0A2 3iRvA.7 l'֊yqm7gL479%Qq:O-3zR{:S.~UOǥE߂fhH8fA:M?ߕC6ZR,#7$&nv230M38ZN3u,4'3Wv7a["T_os`o ,:,g#*` *h%*9Yx:0Us_|!Y䤘;n*Ae$M[jѠ{Ōt>8~ GvK\ |a9c5( =YuyԀ^cRa!|H/=q˷]jx<9NJU+s J։CxE_< g0M ^ai'MfjG]Yp˦v:MmkvdLR7= ˯ lK쾘 W}n{z<=fR^lqlR*tvg(ylG,aS̀Aw!q@h}̖7<[aլtvXj6^wubXr~n]( 0";2h<GvIP*G'!f.(iH842  1/[ e}k짲n= >:*B$,j6ӗĹqoїGіa%Rt2(oe"X(h=\k桝psLW@3|0VyGIj2̲A*"p/JcR8/CZ`5祷:q"N^XN4 7:6Հ@*KJsHEFwJm+^C A3Ambq2-o;cCRٺzCpxC콛hm+~K]><̝98a_`;9pӿ!܏\"}'v="I|gT~0Lz^Pwd &bk,쬖;?3uK z)k uO8jhWţ:YnIා}y5ӏGP9 zFU 1C4pd͔_鼚\–z;!9 aǚMO0?7I`Zo1J,\ɗTRoD3d=,gAu2z:_0+Kb-ur0KH^y%mPi7|T:d|9Kf5sm9 =Z 7@ϴT`=g.eSǮ=5aW"A~ ͵U&5v*Dz_U ͘ V#^) o{kVvе `$9$>7v$9W)jByW]jl,T)yVoTe4hʍzv"gjnoq172^jXM gWs|4XR5#`0" x<6CUOLC٢Y3zgL Zh؎C3R!Ť5_i &)#4k>D(!b0߫|v2 f$;zofTIXG6~hKk,k`m4js}y>hKuw"'%1>I$fs&E] %7_om B+jkHHHP-  ߳*BK< {R~Z}MI\!3!%HuJknR_!DnR!;ROjsȬvpPYhCqLӊ4Gsҩ֐T1xW9' nLj,K|U[XlX#xˏtA1GwY%YNO2@!s5zShļfԭZ9^n)im I $T#96~}+/+ȣw>EgI36IߧQՑ~v@\eݔ;U0#d/M a,2Nw0ʷmH%^~1n{cG<-Ү!zLo.l†=ntUgsdIT֌ tӋBf$\mѨN 2Toa_~0+$<ԟ`<0o;*>Q8_iQqr2d dfV 6w =AJ(3(W0MTPJoW?7ΧGQf'TV08 @qsfug thP6I8w IvRǽ?<\D"Xm|%MA[i5fo7I?;hh=u)¥Psl]5$b{UbY6Af/6 LuFgZgCs# ЉM%O3P/]F;VbO$(vL6?3LcfUOP-n$D <{jaƖ3z])ZJOU92v*E$HCyL^WzUTV*X*ܱ?%>:a1W%,4Bݴc| 2l0{Q} Y4Zw3[ql8 l$@ _l93bkL m :ou”BvWlސ$K? >%7",֎͂h-ay+b`_Ax5 yaw_0φ`H^V)u"|kOZ/lBh`Qߊ =+H϶b8RgYC-Ă,[ypu6@t׆\zTxXx2eaW4|Ul4` OD\)G۳g*&n%kHix۽)ASgNH\w7@C ܞy.e>$] #*FĠMBpNDLȡXJym;(i ;t_әhNEΗ>w2 ^JB +r&I$U cugJ&yo^p{Ɓ_ ) qR1cQl;v{ӔI}|4o!> ؗ.< w%Ҳ}gY[GS/Yj ^_Ă-[ #W !ne3Fbq3IwS^ ?tZ)]- R3xP1xH,8#4]@W+4b!ߵLyzo̭ƒߐOiJ3"dtv&JJ ONG10 ;E@ank6n4g҃/);6FfOayH:8K0JhxC`{G{.í=x ;y.8E"/O(l%nvFeqŅC]1qiL`){>;b\.ݹYPdQQZ' DGȃ!Ď%,5O%sUV{9^kPrm?A ]c  lHdS+kѪTr;䚆j%(dgJzdpss?Gv9_3Qz䭴*āH}We%*;hl-.Sf^T7roeOtZ83_'ao7Z|sߪ^?joA(m.J!&C5֮~}H` `@~<O% Mߍu 4-lhJD[l{I&/R$/(Oui^/}>6'p+8qIm[=K{wMF9ı.@^47W^84@gd,Rg;,_4+4 X5M"d1'6/Aԯ%T/@yLA2VCPc Cb^3+4x$X?oZo)KvNM?w/M7 ͭ4Ž75y^qXTo\%(Yi|Gz<^lArrlQm uָ'X\,8H6-L>zpu;YZS8^)/Kd|jzj2K`o EpgrY}]T<'%kZ5li]/}U__JK)Ll7&]dipZV.n|A撄+v$*KRn+ W5P>ǰ!tIQ`Zjlr$ qj(âd+7 ;)LV$qcQ*[ؤJ:I/=ǼV&Xҽ>$o(^YQ[9`8 _/֡$^lcPC*-;(#tkJk<ٮTu/+7F!Ш*4 d5#0~e%WzZ5I†B!cLK?ݩ? F+n!JQmfؖ F=Fix𥝹xP+cg-yvPHW$'ٽO7[i-Nc)@H 1'2x_Q]wi& cK3qJ`vQ;:@|y)ۺu?Mm\ksBfyiŁ:o 7s5:^\1W|u5T~.#Cĵc6.cA~pt) Q{bUs?Ud'1ig7_j 6Dž !<]GX+6;(9vR}X^.)JCh fbv]tJ{SGV# UJ@̡È@Lp\. n3nkvX/TݑFMEI7ffW놌(\7gݫBQ\0M1s@.=x2\Ró0<,+њv&f#y8-^a>3ʻ{YT,?[Ұ&Fla7 nPLIO09sБi?ea%}ZYOcV缦M+ixjҭsQ6W~2!GPA\2dddrlnCz W.͵lk %rUmiurtN v߰U!;8Yc.86Zٯ )j=AFN?܇'Fhjquw[a,G o-+j 4+3bUR+L<=:j5Ū/WD$eBef$aϒ$JE8'myhˎ;Ii⮼C7[Q6FXer"n)dBbde ̕hkGp+UPeY˵Z*Si] vu0d賻Ł0rb2KOs;&~[ ~Av& 7ڊsT$2ЀیAv~u9 (hÙPS P)y/fN_FHI E5R]1v:OASLތ"*tG0uW][7vo˵ mf.MLd@.y ZtWDʖ<)[(&7/mxɢAKa$^XcBs){ oD8fAAFPGI0hp\uQ|ՁDh>f q5h\¨ hܱc2͜R>jpvK3x;:=M6 C t`A0L{PpT\;V(sr帞JG}?"BKAеնQ^t+$-L !U$u7Ab`8,;G y}Sn] {h}Y#C ,$jus3RRm%l鮏&H/F@eկIY,Vfoz|YnYP̙ }k>ƠwǮlgmtgJ:wӦ~PY3LSoܱ;4!4`*$6|pNP(.{C2W `lRY WRIlLF[j!)]O5LA՜uf*A?B}3'xλO xs~dE/@f(FTiWj mCyVQ]=CUI*լ)(.fUe U"vU7;_P ()}9rRK7O_)Jq8 ~V cCf+iue Ri]b,JC_MLV#km++G0eʂIkevU| ko&sth;8ʛ,[h&iPҔ,& 6 P ?4q䗢ݝl b:t ^)$7|m=q5yk袋&e \ ҾA B1$a QF v( ~= 7Y2\qp8o6O:gqnu5No㗗]ylٓݦኜٯ8vDvHo-z7]:^(p9(QL'Lƿ s "-{X2xxHJiAx72Ro_&u[a童g҂sB'9*Ɖէ_2"A&RniJĞ& {u֜2>`QkvH8$娆8r\|i+b5UM-\I4gF[Z9rY{"ޣ8 !Zs'=gQVՍjFtB: ̑(41S R~I'†Dopْ0i@딝H}*r( 0H_-6TqGMĿļsOFyݻw/]c)n =(X ;^Ns9~X;5՘mWEMgt[!ZJD"u'G;ˎZ99R4pgX-|satgzqYSKQpz|o$HF(Z$4/nQ8MkywPtb`uQ,,R [H@Y/ϔS.v|{/l( ̞Sf(P[ᧈnCFXj#d['B{%4O ?$I!m+1-mϺZ1QxA=1{׀,׻ CuJ0 JxoO9.WE 5]*|N _ta!o$7ҽQdN0ϼ.K6TɮW璴f^)-̖t}35,f3 m@Yg1#)ٮ:dܷ1*_O* ի_e^3cEZ5Lq?t].~_)Hz{| ! skHv~J^VG%L5f-mHHf hk` F=顙?J~#_VyD=j_3>p%;Ŭ\cuE2"<層> Ơs`4yX ? 'WEor?ňj7nT\2o'g鴞=P68SX'O lݟ]xd)m1RťB <"ѓ뒮؀dZH|N6sOs^ԲQlu=TZP6x< Lp{Kp ςUpFmS;xѭP#K)ϱҔ_X E\$.\S٭1aI35O u7nKѵdG$h*JރM@ѓ2YNAԆhm3fmt,d{b+АwMa%:-I9ʚ*wVEOjWDW$_΂*=q@z$2-Io Yn-?e7AFG?M7h4 Sgօ,ױ伇/u/K*çTY(9zBu;rs b֝iQ?Jwc+"UJ!7 Rx=u*b PVX|n4U3lpDʕP:.CR\*~vgksfY g pBP.Rl Nea!5b.f"JgQCw1;|}(}Fۢ12343yBy-2ϩ2Pwg%~\E0O5_?z,m/wL\jG?^Y>qg4qPu(Ҕi_&=+{U.5E԰mn!z~xz& |'2٘aqsDqĕOե2 5+=:$97]Dq>d U [B`}Y K֖X[&Z*gXZ,Wo͢lwn@'浱"pDPC] [F+v^>aCu6rsw'ۼG$윑 46k_=mT8+>c>"m#ge}v_IPoF6NFYQ lk㹊 ` mprSͲF~mw?2T?.?^q/>fuSQzGc vΈm~OlN01\\yFNt'dHڠE-(~faߙ,:ai6)V'6;cm3FZ-;jϫzv<&F^o)pZ1㿡s7V-`l6^$7uB?U)#o@1A *;U^{ \w05r`9S"EP Yn)I|\E|c9݋qlOowQ8M%1cWԑߒ0֊yau{Vo ѻЩ @I$Q[uQ~Ι(fGtZO[&<&&ϟr/#X~ dO?0!gs})ˊen@S+ɐo\ $ P7fAxCF#;gƳRa8Vr.tP5^@Je-hYJ|µə$2p>zjOOhǽv=кjA.DGΗ"a <?`c՝6)Q=ъ:E IQ7)Θ}l쵶ъV41 ܌ސ]0)U-tmTx{+˃>:|'up 9ۣ;%@, g1G.<t41=}Aa!_UW2LڏۖE zȏD˭(*bg1;ls"d.?F9 t:RVXߊE 2}ZU=cτ[v!+iI\N>aRYzjmIcIG»(%kn~> R lP7?}%l _dQ@Dه ZG7,p=|l<("[^LI j ϹxRK5(fqtPgB>CiShlz$lg{zϊ [6SSIԞI 0̶yS1i#O^?MwzAܫv1VO8JQ8v mƘkФ0#1f[^^$m)A(NQ8c0EyX\?:@P'䟼iCKrSOJ?R& &;ɚ[^5ė`]"9v=R|QNB{ZI\jx ׷ YRh7o%|k%o]ΠMd-硶H :S0.l-n;үU>ѥ1mq` U2+)@aTe,9bx̼;tT73#^eGA%_ Ҵ#*8nVv:Hwoh̶O7 JU}) QlbBU_aD "f7ʘQUY\"EJըLD^ xY}]`W-X UjH[Pj` >= 6]1hr=2l.IT!bmosfhe 0eXJAOTWwH vhEiX_VA ]]Y/H; Pda\teղRam>2Yi!},~.= /On0" V ))OП]/<ժeg1LWuAYôp?NngIhGEow̡1)ҧdܻ)snvRU}Cs¢n \_:vBo\ ˻?yN J"^*wg.Sn>ݲD"QQ/V&-3Kury҈9a9=&ఈoӞ}0_жKš?\ħ`8mԊ?i}#97=pO3I׊~NYux ) Rps$*}#p#='T8gϡP%k]n%s$yX؇F0ݛHyym[A~4rOG)@l_ | "#؀`!߉SGP-2/+è|07#Q#A#RΕ!4=-̸c{lĻjAi_Ry繰Z OH4*e>>`,Se)"eXۘ1̬o&M^ŷ}  _E@є#3%5OQ/yOx!s:p;S5w@j>y{%w!HivQxV#ޒE0]~>Z;S FQIƌt|\*xHZ% 5PSLp S-ߥ"d?Vc֟Br-J/^BACNgCZ{yhdÙ8=3~[FKrhS% krp4ٷt|398Zv2|YRf༟M7ncɠw!o5:*mSF#y_p1D9l5HFhe~!u j';|ZV2* ,Ue3)QgbLQ/|UyTx>&m8 "~ }vL0-*W?3(j_j>f%ά2x(0o*w8s!_* Y%%B |iegz}H#,cWrA!UuρC\Wi[Mx/8vV'q4ss@p8jTq^ʫ}"ZSvAp>a^U/O⧡. &͊JoDjxin[q3/)u6j։=,:!Ě9B$-9-R{x&$p7 2K^.Cyp/q^S8(MZ cpWxRYc 4k%|, GX'Cr އNN kbkĢ+%C ;F,u&$vG.f3 (.u fRa"vrG~dɭ&{Z¿$6 _icH]JE VQb@n c!;؜#8igXT)7b47-0]rDX,>[nĹtjrtx_j ct,pi _><6g~ CCaEX66b@HB1`/&L.hB޼f9:oNY:<#xio/Ob_ȶP74ޛPJ]cS}*9/E5XqzI1B씂(ZkI7`6Opi ?AבCoul_b .a \Sc&724u[1?[FQۜ|%XS+Yib!` č/ =+Tl+w#)ձqs! Qh,A8, 6`PT8Z.P 9d52WUqb$ t3nӎt+T+Y2#'SW1,`Tdj3nhz[\ mPYa*%-2Q,|f=_5=~%r"{O~3\\W\ԋ2-{FG3Vq6* Tޘ$"AJ%ߋ{.Em'z '"1{=a& i]YK~[jr!&ߕﮤ lZxqvF2zL}AG}fFf̜pjQjovjʄ{f>ww.,*C^DޫGv &ƾeË̻wltt)Иdˎ{^[t~tG:k+@kgԡp?xef少 ;ɉ~O`ؒԉ4ytq}?S^L|oGbR^-'8hӂuٖ[ RʘC[u ش= G%QD;<4)F+2pR#e3;b*%׼*Ӯ7? _;:_E Vwvc{g/#*:ri/nѡ<">,[Mg;eF"y:09# A:A0OÀy[)A%\!,rII7֚ BPDlfjwYt4ڲBSv=_␎~!Ŀ::@5f++hEۜUF?6 "E,#4z;Dڂ3V5jyB2Wlu0 At !59Ŋ-X62Eeu`TY 5c'd_L;yڼRo>:؏t>.$A檴h3q.fuٺN%(~?%HCX .9t6jhTn#5c[[AU R+p0/)SQ?ڪ:±ͻm կي(".=ŊlH/GI%KO) l?. nd$]=LoL$# v\CV L{8)omɗc<߷F*~Y̍lƝ]cjcT{*d!O6O7 Βvk1D#%n g(O5C7nڲ:3eR+ s.5"=BzGa}$x)0AKJpyn3m{Z;F7O77e|cx(-J06K'q>xȦfSTQ o'Ox )z964O^TKiC:Gvszda#M{UB[/S)=2Vo@_VG͚!ldEW=F^rVjQ΂VAK@+X/ @.i;7`0U(鰦NXzL:EuU>w$A&lˈSRf,hLb?g.,S!dbLȲ}{@Xjurkv8s0:5m ZOjhU) V~(~\n77y.kGxз y-Sʱ#I{ؠhĨYHppWJ@nErm,"Y&bYR-@  wqWd< MO!"(/S?ZdŀM}r멸,k*]M.(bX^ee )od9#3+~*w!G%WZ7㦎*6s Wp鹰Ur&Ga0ڊv$5b6<~Dsܡ/:M8:cfri%˸ rm<;}GeTKa%x% 6L1ok 1LD8P#*-wtaW O]x6ppn֓ {N ' XDRTp@=-Mlun/ ud8?0jUOg\V-LbΟ Tc> _ӯ{*X+r9zAYnGZ汦}:Oτ h|Rnlȵu:#Jֺн)LAp4eK;Y55 }Bv-6̔4@B䨋y`61N+UX4kŚu +CɃa&7$utG9ʱd Ҋ_R5iQ w^dU&ܐA5)ӝҪ"=lyH CxVEU8P[q܁_4[Q{F?5aylc>X+b]~7?7rڣ +ZAlj=kU$0% ͕~=Qy.\(MjA.rWG#_|pY.z樂̕*fa/ !ulP+QAo|}Mrq"D^/Rp ^ZYX/ W>*38?;\p$ٸNح,@/:uX/=Ҕ meIhy ,C#JsDCLԸqxWV/w86@圀5:\+{;s i*"Z *vyH=,VhƞQC@MJaYQjg\A=_yHs3e ݨv<.U'ŢGhB^F~uju> H_[{Kc"n=CM"qRxFr-]Z0O4Dϵ& {Myuh ַ?f=߻$ ^s = 3Lo,x̱Ef! -؅"EwSѽ^rRs\0d/%uըmFu}x SwWٵ_06gb{9EpVƭAPPwr9듏$TF$NƝ*G(}j0I|5HcDt}T1Y h OS1EY=^+mGkҊ#c_tX '@Ot(sÜ !;pYwe4 ;J@rִ=: lٰcLЀs!$dqkAǕVb@=kr0BPR|:I<>FnX(f封'n|R,|"a7+4Kd|/> (R= aG7-uqJ#ōtTD-ۙ1:"kTM"kSY;/~QǶdW'׸w:Gj kc;3LC\tLn.sTcy#G[6^Q1uMm4=xBn4wեV,N i)CN6eN4S>oK#Kb!A ű.'aFIhFZ"[PyH%[b{YY'bã3H44(nc0YGeZ[Fj-zȇ .a9=vES64)#z~ l=}2h'wӒ_\2l;G17j7%=*t 䠱a+%u9Rc7rGjH^D*D"^uٝ+.j)i}"w ifLL^ԩ˓ٺtztFքЙa?zyBY?&kYˤ8# k6 T$`GGdۋG98>"N.& ~rZ͸B'ӹL4#zut[&JU}<`ç9ݠ`ZڲiRkχ #Nn] gj{krPg#0Ĵ-r$8 'M 0v h.hWf:j'䋹T{„YOyX!:uD|0!UipÆ.H >g#hNN  H*]<(D2nsi& _BupLxHsx9 l$q2WZA`h#JpwDcb@4Qg#/A,kd$1.@yr5[$ƉS:=ܝJZ@eDN3/':*jo$/uJ;u4O @xbBi9V76ԙyf{?%'pPqE,VSS1z U{) ./;d3=ĵ\ Qh[ ˷d6\ &$_S:fo ( ,9, Ǒ) 4NvkPbTk\').qN{!(!aXa):}/^5>v۷V~5PgCճFHJ&*ɫD+"%omSEȯ(~!>Q&;X b{/;+]SB_фWcgH6ج\uyǗN3R6L$'sJZn١ 7~ ΙI<ڀI:8pvziTml7y}HH|b[^$ۘs/Y;^5Cj k._$4&̼.\&Ŷ0#c]=ԒQqUWIs({`eҵdU=F2aD "A4b>|kG@2 LAsd6aK>g>ha~hRe"S\ϑ!-[w<F *n=V;6bo 3LWY~fk:A o,ŝ2%&pXJ8:EE|Ƃ)y88 ֱ8ٌJþF|nh|+"2-A)}C~d nMme'nxB9hXb..š̯5ᗺ12?C>QGBuV/%3pvIz񉦛X`'+}r{y ˢA <΋>NV;D'ٶ'6i~SQ1uSlX[*R;=oD!2JLޗOm5d?a҅@咧+Ta 8PxNv̀냙"Ls 0"X__s(wPm';̥4 c_=xiG , :aLFNd};v"`7?pc$G+EKbPx1ew,(@2Q1њ|wQ!gFUi[W3˪UI\֓dJ" D+୞X<3BXMꅳ& á]r| tq2q0p|xSv_p:O K0hK1TfJ[wnxR΀&3e*|D?*"C/jAz?1^("oTdz Ÿ=!p qL5 uYЇ S~N/l9RWOƯ(W_=_}KӦ"K:3f[[w:@tv8 inʈb)j Ε[m>: ȭ$[>c7ڂ"Џ4@L>+Egb? 'K4gۥ!2m5/1Pm-XZڞ5PQSa6tTѽ"[.d*Ԋ r4Ab_ \bi2l.^r!ŚT>=Gqomor  8>"fz QSbzuTyTi5qOWKNLmZ8R4qGQ8`HWtsU{3*&w0/ɆQHc~nXsJ mqvvO443S!vP Q0ӥkvwm'oH7Gx/]Qʅm4Jg ޥJ f'i{vGmr(h5>$2Pa5P:#~t,aw^ iˢ `U[0׏fkCv:\"wG5Z6#?೓|tlX.Z|iᒵz"?=.%dB+t.}& e̓Ib|E1$yK;;|zcgaFa~,s駮q& %G$;ZQ1ܹAŤNҹsĐTqo2 vL]|CuJ)`}w³+_%k,aӅ*Q|9 (q'nܿZ `\eZ~Xt?=|,E) ]g\*e8K P =eXyJw#$69c腠uj ,S,G3'<=1c}15|*9ޑQ;ʠvS}5e5_gE">׀ pBq0GG}3O2|/M JZl1jפ~mWT3)wtO#WC1q+м}=M{:|OTC:^ƜKSxe"oޯ-ѬׂQ1Exy-5*W \RfKxL1sai ` X";2FwJE.d|sD# lK`C5urv;{s ɸ=I> r"}!Y1" be_ w:4;Y!<(Ă s'^?/ay?j~÷w8˺nprePc#94E܄lk@EQm|"M e,C5mYza\{^?D1f9o +ܾ*aJ'˕)LC{7hZE<exl'X Iz$U200G@gΩxڏ݄1[4tA:|p%.E oc4D-ZJd0b뿨X<9=E[ >%x On!q*.ښ#s]Jmc i8hWlܤ8vh0o ͖BCUk] M>iTgF1b7Y l-4Y-%t954nSXvngpo>V gdAO YՊj##J 8F_P_RH P.sӚXy3CO!Vx̉>ڞjTr?^f GI%^Yo =@Po}HUs kx=ubN闯U^d _Z1s7cфFzBi?=L@` *8DszP JFKJOEAȯj/ɤ׆rT.ޣ2~Ȱgo"ԋpF7;l(.PnZIp&N~32K=O2TFݥzkKnJrXp~c+?≳&N[)~^sqeϓ+Վ;{Jd#Xi4ps-"-״4ZLga".SИW(P8S999Ůz!R~;CS)N0v8přu[ }iĶ4T@aN=樇ȉ<QQik]A)0^FXQ:&NQE!C`#HIz"pkjT}ݣwj.hSk7\ eOPKt!c~m㥗g˞[vP*7'8TRuP.eɟv;6=;(/$'-NnWDE ?IF`F]iP6 ghKG;TJ>Ֆ7-oVXqԜBR8(Yz+GޘAg[sDFQ9Xnz[I{m.߭R t;r7^؟Ț6BguL ]MQCIQ!<\'=[(Sf]M闞7^x\kw:BoK0mޓjpn>xu1kM&F6365Ƶ3v;Jڌ^RGd?AjLe]w~꠹|I!48"Z?S'>?-Zej[bSw/TjW5xKS}9?Tf[뎷FC,3Q{^5ӔRˬ2ֽrV˹Ddr8u[r2D/.'Eb}i t mu{{橞MW(qqf+[֖~5D&qnM>BԯTnߣ%"|ϸK.XBrGȀ*XO;L vxb08"\cг_iP4awa;|Ȇֈ9 }oOjTg@:RNq֯^ :ʐnqxVe1ГcRl}vT<0FI?M|ݪ/zOL!F}moXApב;d8UYCB9R#? *V5d,ʷsPH4*uXtΣ)V2 @_1:PÍf^b jRCR!mWS=L"2ZUj \N= L{c>0# ̙yk0…%Ongupci'LMIY[W\Q3/ _'oZ6teM zZOY­ + V*GS+iJ۫6gb&:<\lf`tMfa6#X;s |LjJ'|K3} ܏п C7eI-JIbMbб}?uyeN _ =_dЕ7џ0S_`DUcuǒk#aN'(Fy8L)*N'ݸQw88&?]͑YM.6>[ ljWGA+K|X+t^`EVWNrAl*YKD̉Cz>U.[j#0r+lCʟXsEy͎C6Or)n%p^Os""2njv 8aVzZSv/I,QdT2"Pڞi 14i2*#RrY2 JyP%ɝ+J6.{S\̣tJ0؍ew wݚy<o WjT]EȜuE-|J1ΐ-da3ABJn.ijJp2Ֆ[_kHH&/+/yy]zpt:1_ gɔi4ϲa'" jiE9T1m(r@:?p+! ɦ"7}4NI]= v`(Ѩ`fOj]86#ՃٻݸVEppkZ-(M~ߺ|$Ɲ;Rlo &Ϊ +f#n1CWoK=TPp(GTr;uC-zh6~9lHPZr=Zn:eC*G2ݠ&՗W mS$+RŕWN9]Ntm"E@f{Ǻuq7ql<8_kBPVx+r127X=%N1~o,ϷNͲ :ЋC#7_(a{F,uDŽ*3AeHԱ"H= D,d>Q(ڐw8@}p#4,G' B%LڭGBE"(+)e-#Z 9\زaQZ62j*dIjjΞ*wᢏg'v饻`t RT*4 4Čֆ `%LJ+K=b^vDH?w+WZ@9K@Ni",AX3=C-cD{($z{΍u]#o9XbˬoCUsncNG6i(2sBqNm F 'D5[\r[bg Ѭ2R pa3/1)@gE*׬<Ԭx]r6%G%VXmu/$~ /OR#WC)̣B Z"%:.=& ȿYQzTpTYž-$DbÉ0Tw!fhPzK|(Oy]x_+ SouG홾`wɧ[PɨçE,f2`XyNn0UR.T0Gu+i& 7jhPt}<R')dWN~'MjMa/=`_y :IkS3f P[ $DX4t#e  $:I_L;M: 8b4:뗄 @۬j|iOT8V߱j^,fĪ.X]9ȶ#yd/c7@W*Ƶ ';f]څmjsZZUzwr hH8X'ky*ƃ+|`o)D'7V0αZ>{ǥjȲhl:Li >fV_w,)/+vZժ6 ;~9жe!!iD,mV%@ ydh(? 8|,e<'iTqpC7BK1.vryzc:@q)S AІv[RdŻF[P!ش a?ucWS] T=y [E!H̽m'FG;H 2<ǥ4"U}KH_$dUk)OƉ\n8^\86_WrwM]! yu%;R ̻yo`xFV{NYM~?*PQp.lr6[%SVЋF3k=1|KȌqȶ&{)1.OcQ1]a17 KP!ku@PiGJHڿmZm⠕gV˿ʴn@Z|5q"4ПNq%-_^Y/Ersi[!-Bkpl9F`lM8 r~FJb:ClVRC>\87mL-\2 *Lږ$Deo]6/AH42`|v'/m/:\NY]E^gQdp!fu JU b8#2C^ WXZl&c`i*: P>֙/&sPCޣs~u:Ee}W߽G޴'_h>1䮸&o#JʴH.tM(l1A~yQk,3~ *=r_Be.oe,(\iTE+St!*֩|)0B1/|z&4(uv.xs&9,{5[).z[ݻ+lDG7Շ8.fP9_8…ڲm4Jfj K~ݤ1mO9*gSqC_B2ɁkHSXPv^ 4hR3aItAĬP;|$ QkR8Ll,REֶ=t8YrbSkrkiMS67{aJL>+;փ}شpCzk~5CK>4nWKP9uv3PIC_Vϣl#9&(#P(sA)PMڲASᛈ漡EHlI~/~c С}j;X1h]դHV,Bu=WcQl Y'|3 q3rVuWn7x(Ն!?8xMΗBy5єAW,}~1%92lgѸ VxUF+jRyM!H%2GuYV!/cEZ:S2LKɦBӣlg+_?8W.j(mFJ7q݆u1hɉJQ&+ce,#a[2]u bʯ U}Wu^ʫн%{`g1BJ̄aWKCvt.Ɲo0 vHܞ~^9wRޙ-*Ζ$(/~ q;H+(Լ^8a <вQjKΨ3g痄iU9MЦc[c䊽t=cFъ#cXޟyH 9Jl׿RH&}vv?/qYAu&,RMj{+Ey/vQr3j3BD BigIbY'2E',אZ9vצ_Y ,LП)޹w* &: y%hy@]m êemQt&TkL @6MdHh-VUXIڝś~8fk|4,On!z+Y<^$2sSΑLDwHtO xQ6қ-w#Ѷu{tn%#4DzeX\bcW,+pӖ(RfgB\)=>g8|"KyyGj=Ո4g#'.{0M!-L֐JHmp.OT,tk-6_>V j{p,ld7}" Rv{Jz;N~¾ΎlmhB?x*HsK"s70b2@N^/Y9{2,Da6Tnvz n!F^N'9Kv'W55)!&:-,pt=,:iT7':Yөjϊp}?r|R2#v*!1OhmYr俳-hlW@ ClJgrѫ&z.)j74ilxIGdN"h`$֔r{pm,0PGs|QVU0ޘ蛶3?G2i9Ga+ -7JMdw{HZ?UAa>tF~BV`%E_fG̨ҫ<䦓oz[d%ƔR`X;m=;x,xycb|wZ* 6dgҦ71dp] N@p%&19UÇiXd֕wTR0ψ\!C fu2.t͗ φn/j3I6tټMvGJl?jvTuR" :~Z;/|y[9+*I`͞լjL}oӅ[S 9q蟩q.ed{:8m mxtvez2D&߆ ☕A ^#eU(tfC0#iOcTX%o_bb 3[lEUچW&{ X`1wwoJczrP<(?՜(Z  aIJ0p!g!0QBNA8c~FDPjОlXu<8d~ƉGC u@&k&m_fu~ \ {q-Ek_K((e8R dB=rI "nZbapI)'KFǪ*k[j>rݯ$ELs$<$_Gu- ɳ׽~~7{Us!<.* uPg#Ԙ{oG̷D_G\=GR1WWŽjZs녆` KKxeM }X5 |#?򖄣@5.0 I$|9ؔي<Ipyaᠷza4;J+:Y(C^T"$+<u3I >V]p`7#ɛ/<^n`.To=)8B*oݙwQ!!o$;>m&kUu7:r\I wAɄ\nj@.;Y{r "apk55Ӌx臾.[¨ N:QQ4}.!zpiA@^ڗ` 3 ctm.a?~""ޑeեBI_^+i"cGiR-x&]H쥌⦝S7.ywO JKY&^ $7eFMLuzJTkngEqz\va>Ҧ\5tșT`4jLqBqbe80<\@>6]8hZWˆ@̫N--JU4 #N w?ᐇJΜ{`ߜn1e]FlȌy;rɪH].!,ýc ^4&m|JDKy/kCGh3""fׯei8dVM Xh\UCDև /{ Ugũ193uy4gAS9{G"JMrKMy<~?~z0'z09V&<{أFӢ5cH_pJioUm-.5ȳUW#_4QeOIVƤz6^~7?΂%<흫* 78{$k]#u=+1f!(n那ҟjHZA/'"˟|,7BrV*'y{8?eDv =S/f47<3ܥuDڹa5Jl]%N?^^(駦FL$P?*"c!u=٤'>h_ܲ>Ppƾ.59Tp5RU4 wfWE.A+I{3Z S`HY] zQлҔ㛤g5 A%n]Y*It_oܩ'A)`8dv}{D.d&s_~eԱgrc%_rOu;|[шcorB >څPU*['M _atr"tk 0^DO{6+yDgr#vII#G|U^_u1nաD\EqfXy6e__:.1)ʈ3ueƾR^{ՙ>OnaGr3s'PGpo 1@ɎNj zzή-q؇Ů=7twjd gB]qж#BF]*덄Wi?yKISAiTɛ+т M=tyTԴn& nYjv_[/V2_dؕĐ(qjyG4NB}(3y6ЯF[WD7];\Qp4^tzmd>#d]Yn|5ELIY+МbvcL]tz?`N7!mby?`gf߳c A?fIm޻-^MT  p'EXt.LA$̾<#gǂK93- +]ۯ8r j9Pg $`|Yn.p|˫Ja%%剓fm\m8Z"8y΅0G():j߮Vc"*p"ad+{Bmu}04KRb |6O@'{5Cޚr SW#i|>=R]C~;ƒ 9}Ѱ, &dNlݒwvQxۋi:)N&|4j5[Ǜ-%g^,OMΑ=lF5.! JM^~Ez.$6 //|ai%ZG?ǫvJk6tT cDpCH"-54#xQANm3%2Aڌ/JkbkVS$(Jߜ`ьhmίrj"HB{i&@s|  ~†M.  ҾsPmn0P;S{"W.9k7gœw I݉%N鴠%/IU̧O&1\αrmfa3i'$Yv Ca#((elExhW22rofTJT OY^WPۋwxs\vשA/}(y[3Ԇ!=k4os\Ѽlbn~\Txll .NP^]R_x{h4Ħv~`;؃7rm*>tﱙ54eUB|&c<:;@MzgJ٣!Wۀe2)8gXNdgĠkӦ?iYqs$Y]M3n_<=ːFpU4C$cE 8'Dcm{ف SlPI#"!w<]!]R, ':FDco^diɉr A߶H>;w0I/ʄb]:}1뀶:<[ByAe<˪gR͗"b{ۗPWʑ!ʧJBgk <_6Ϭhpa>B8YAuԹqF])wtV뷍7^jl%%[+h兣'=3bP}D vE}B2ٺo}b=@0}ڃqwG6Q{c*g* 8L;*1[`g |a'Zlq8BhqгnJ2{L1ˏb)5Voc;4 Ft91M]ڛKX'ͥpTzl hΗȞ5"A h-"˯+pc;ʼz T/HuY93aY}}_q>[z7~S(NYIub{},FgpүSni[f"viA-8bO=M 냕1+ռ-M%#$v</4} >x:}ylz$Jơ~\H {P^O%<Δq԰|IVbʢyx!gѼxi41~̺sqf S8(<7uR/St!r 47+r e@^0kJ҅2X4)IA *?|> I(~aCvBwA5kX!5&89Ylc8! -\ ir>R+=p`L zPaBu:复@1J.4ؾӊ;ޟ9U(v,nXQxj_tN ~0rrvݢŷwHڞnw{OO!5+ⅤOk' q/9Yd[S;991KStxl[ BfqoٳwԮ(q4/]e+㣣*`Xa*GE}{ׅZۑO+ȭsƶ "Nc+.h I@ί*}1}ok9)q3E#U`u:Ivj1lj.JBK(QDJ<{ >2Wk ̜n &k@$$'&W`Ы6a0ΪF'AAc:7ű;"1r #xqy*M9ۂ0Ho|)Yn||QG=b1xv+6K*6fSOYnl#=t}:0r99‹g k-G4F`R)Z.J֒Yt61iQ4s Ad5TF7Hl\OR]&~sXAry=^SmͪKSR3~/##Wj*=X U#Bk-}RQ} ޣb&nkՉoU8'-6H՟TLJ k(JW?81TM ieu 2qMM| &?:mn %e'ވׂйŀ}猉/b?0*'"C%hpqZ3 mV %ՒiH<-ŏޅ%xa뱬|R(3$qc 1mrB"a4)h'5o챨rgz5~,ssi3#?y%M}j7bȫiˆPp< 0ڠ_maB^0/v֢S@] kfJJךOLt:{{ ~$Q=YT$TkZwt"~NNGˆ.?DIh^ ѓ_O8O:r1 (/M **vxzmdl58qoi@z[䵊9䶢%>WT) 7KTɴ|ME xW9u{ui@\xפ4kٴ#(փ#ě굎|3/FOT_pC9|h,}sHYlHN3`zr"c;r `8T, tqmnHlm+&a6UOG>|?A}k*iXۓA2&ZyO&k}X?~˫Xp\MkssQk;8|/'ƨ݈P/V\cN%R4Ct,r'dU>pbmC7YirF]V"x˂  YZ