sssd-kcm-2.5.2-1.el8 >  A `2U]5)aӚH/{/M28+VՐ|ع:}ayʪDmҥ52y'0%~Ɏe=aݤjQG9cJ('%/}'8z/yqN<$Vcto k2 oЈb_8x6M"&/9Cl'ya,)prV3B .a|[_wC[m5UA#=N෹<˯(eҳmT&Ek$ҏp [kwQbύ!= yV,f.}y2BXf. rQ;u#Ƚ-O'^s[P8j02=e[|w?dr|F6@7EO?4ʝZ˩x+F-}.;KfU2Sw*"ɑ* !,d60311c1367766e687de767a394b2635d5740914993e7cc6fcc4c2e4d77b02c3bf1ff168aadf825d2d804d646c7775144def60e4$`2U]-47 c4n1-[fPPE*JcuGha{ֹٓx;03:(,Q {aa"z.}Gb}:=AA(n 95e !\k|bւP&aBӝ,pBp?od   B 'DJRgx     n N0; ;;(8 9:d>f?f@fGfHg,IgdXgxYg\g]g^h bidkek fk lktk(uk`vkwmxn4ynlMooooCsssd-kcm2.5.21.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.`aarch64-05.mbox.centos.org~CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%,p5@zځAA큤A큤`I`v`v`v`v`H`H`L`L`<`;`<`D`Dacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8b4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf961decc9f74d11a90acd55ad46a9453d6aa1534f340d5c95bfd728a8a8c7bca3469f65544bb3008f603ffa3a1008f952be0744205f4c9b83c3faf90927c8dc3ae11f423eaa0a346210975e2f44e4d663e439a92a07b8190d67fca995b6355a044019cfca48df77ea06dc2029af75d78b4e8b134625a465a88e85fa870a0866259023e647f560f509c57b8dbcc1a206f78561cbb45842c124143f34c2ce49d858acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcm../../../../usr/lib64/sssd/libsss_secrets.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-1.el8.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.5.2-1.el83.0.4-14.6.0-14.0-15.2-12.5.2-1.el84.14.3`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.5.2-1.el82.5.2-1.el82.5.2-1.el8 kcm_default_ccache.build-id6a3ee46f8293f6c7df803f4c15524f48052cbabe53d0c251bb4ad50e7fc17eb38c7f4c1dd3ac89sssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/6a//usr/lib/.build-id/83//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8353d0c251bb4ad50e7fc17eb38c7f4c1dd3ac89, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=6a3ee46f8293f6c7df803f4c15524f48052cbabe, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/PRRRR+R'RRRR RR,RRRRRR R R"R R!R.R*RR#R(RRR5R-R)R1RRRRRRR+R RR/RRRR RR0R'R"R#R!R$R%R&RRRR RR,RRRRRR R R R.R*RR(RRR5utf-8be8cb903141012b9c2fef52e69738106359f72dd1ac0b746c7083881d3b26d3a?7zXZ !#,ha] b2u Q{LQ wF|IV\hzlffG'P:LR>ҷsC)c/$ JP(m#PJ܎C=x=]yԪg~ 'g?bkC܃ƔöJYIQS]t{_ۯ7Y zO5ܳP )׎It lKp1/ }9u@9#NAd8N PVI[XxǨ9eqoQ95|LJRɹx3{Ci7;,|М#dft(I4KhQsAkkZBS~X2"G./! wx5ʈ;)yʓyBlD=63C2 Υ:GUQ }8mf'.xG$,k k}`VX~uSq.&Bڅ>[+Cu$Li5Z8 ۘܭnQ4%mD4vm=Zg&QL65$궶ot[T0H+MtW{hȎȫrtXכ{ Sg | r1 e*xZ@{tw?w"0^Slm3Ja*~W7:͊"S5 6`VΞmv8$}j8[tI74(XсP1リiwJ ;`L$dЭbqN`TWgm6^ ru ƴacς|~Q8ÏJ *}sq} _+wa?64G9yFxȡ][1B:i2ĵW5g-Ju1 Ý06UB?}IY7M~ÉEݘ _kdZo21KtuN"2MwwHUD괘B4Ϊ\%bl@3!GٷSu1_uLyd߈6V JeU]`b!ovI?5W&HrhfZU aY?Q-|&-雋 f_=p܈zF#u1j|fC1ulOkkn^0XXRD{ 4wʳ5=А`a,%{{.SL2+џ,B+yME`IG15@Z˺p?&<=gr j:$9Ď)S13>ݜwU\AQWe9`a>-#jT۾^|R"h:ĕf+oqZWI\٬ hYC_Pt;b51 N|<GrUncV{?5P &"m<܌!PjZlx ̈LD]Ǔ78%>٩~Sm"8Cľ㛮Rnx tpY5taX3 tfRN/~LY˚&u+Gw6&FdY7waw=\ҽ.ءëqJNAT@W7[9[<;z=/Dcw@Ɔ3!S5ʞzm;n!&Koqќo|WAn%cf P1==0A2"k2e뫃Tya& ٿˋbVDV \ҞF`ƾk['=9{n6'Xopu%-*6%.xNe1+ԥ:#%3/נG7oR$dHGzQ쌻`}CWDmCY(^ /r[Y\*&O5WU;!bhBF⯺P=d͛Y(tG,sM#>\hĽ"dh>"pǷ@o QnpKFQT IWߥsx?mDͬ]P}Xn#sTfƍlFxy-/JK_\!>ԘJjE4piD%%:oWA 8Sq3KS'r|Pȏ7EiƉl-\;k~$oG;%=n%q$ڝ+1 1ɫS1 >'e(@DTBt[Q MsRܦt쯘DL yltF`~[CQ#>8;4`!i&亝CAB_hmiRÿ.A;IU<C~n"=l!Ӕ / ANR.2IvːgF ?OrLIWml 7kPBE Vb7P^lF/&M=m>o'[?J[+(Kr!aP ˗ iy 8G Vg 4zU)Bǵ%5>@=,NH<&p/ε]hӕ_QgEo/6EX?k)|sg{X5ӌ .ȣ1mME,^X)kQO_TuCn.'c K<Šܳ9dJ˙/~b/|ҧym@2Q;Fc6N1SҲewiZTG!-,}p<!CBp9^!bRnBJLX@6Y$ Ytk/B,V͖&q*#ۛ~)Mru-s}k p{wi|gw.$[e~1$F-0] HKJ6x><5N> Zԝ'O> t3x,{/+<9c gNYloc/_y6.QuP{;^oHOٲt;K 3l\v V̌fWtֶ &;4qf[M]"t=+k?@'ӫB>݆ez P&WNvXXvîz;T1˼h {_fA%L(BZ!du-em\a{"w[ȊxeȯUyvF7[i\ʼ,7%PU5iDy0b KǭHʰ^C 'ˣBzp[$P8rUy@LzTs4ҁ]y5&~)ӝ0V#&\>9Շ@Azkz$gA[ge2;G!^19 6<}U|ACVtyVa"y=9CH-{ZIszp>]AO}xN,0G6e]#q-n'uxʺ>!w4ŰV˔mCtH9*d;d&g}.ȝnߣ4W^!#($=ylFZACC9|9g2RuhD]CLHXWNP dlasnIi^I)5ZARZD^cc޳r|"R: J"{)[#:K_ ~kv`$aǕ]%9ƞ BcrIހVv] X/K)nJe&Ecg^,{H@dRZ>] Ex(֩9:^NWH[Pqi89a-d|Z64h PQJtpXHe&c`yQOu' X#\QmL'e'k^H&79q@:װ9T&$&F "JQwimOt;5 @/6†s@?0XӤYWdrr:"yԛބ͵ ]Fv77(AKj6*U7`&9%դB0^8|eQ0yBmx* Lc_RXNN)i$m~@ \3{L :iDЎ0Pё~9eKWl{Hkp x,6;)%poECZBΛ6gLt12o2U^4G% )I60 )}tO_##_3:-kxbGْ Ao;Knއ6ҿu#UYuC ulrZ]nV]y$:euX'6^o9?r!׮dgaJ{E]F 3c?:jɺ2 j3Lz$:yx9 Tҍxޣ 3"-7K; aqj+/DA$ 6X@I#ƽI[qUVǟuY?f&q_I@,>K@ jYԩf;ɴiO:8/}Hsa&G~wq ®x@խp>3~ vXgeݖL΋v'XGk."4)MUI.?=]=^EMrJ]Qo7˚ 0|0'+l|mg(!/Z>aoXq[",!̠^E=` `ث1 FPixM˄qhDSEBD8̽~T?۵ڿ CO@_GL-]gY:6 .K͉Nk2AIX $\ L1/X"1yJRfz ^eF;5ャ0H8y5b7i嗝$~{W Mpԓ1&ywkj*O<jU17Vh&vUs1?[oPMBQ ĸc _ㅣ,<~Κ4~Ɍ<T7[9}5Ix{PMt<腾 QtP)x]+ Q7akTvS0/2#u⢚!r`z);:pX%tjs@x0vJctCt#&ۉR>A:ܝ`[)`um=,Y] ԃz_n)&7[o؏+JO}aD!<Q^FY Z8f$uM6 Gsȶ q_5umtȩL)g[c3=E}4pChGiMgK#v_kկn@_IoO,&Ui tڍX(qGOfk:)g%>EeNXz+ CQUAbptB((Zte53#BoOtUfL(s':1/^EA* GjK*BT;dNB Ou+)93U#RyME$G F~Fi|_ B.d #:QaK0(T4eGLsG uWHiUӕS#y$sbf[C2?G#O^:92hm ZsySӇo{M?3l@蚦H۝ $EەE: D7N #~窡{,O 6m\S+ #oz8e=1Nv=YOCLм@Xi}1ҷ ՙŰg^ JD=2ȅs??uu.cF90 ·oLkpQݛccBE69,LzRm q¤yU$R&*N#o=G\ }] Qɵ&d(Q"˷m~ c1`PڱF/hш.M*.-6p)Yp CRa*Oq`}=+$1=˓|}ceH,DTn2_AWQ[G^jY`< DhT!*8˩J@ aRe!7z?כ*t$S,&h9K =4nͰ!a03\WIcRh"Y0SY;|{)b\Rm@٫̮Kq4$ # ce\#QH<({Nq9pAّWRux8T{d'PΌ8s z%Ax%2K70&me $zt+ώqrHb< (]2h WTZ:8X Lf6_ 0nS'yNyH +k'~Fv1/@$OP[acj jU]26rXMƓ"?qz<:c &81 уkB Xq+h4(ĥʶ5H(#m|b³lO_ *`Dz @@Mm9)WqV`٩@4en(h iGZ8iiOu4ǘG3CvGʬŨ{FnTHt~qa?fPD{eCpz QŶhH i%'$4p^?xyP; X頻-ow%C.䯐zߓYo. > z$Eu٢-%IIeRTIJ>a֊3r[Uq?91Qk#aPН$Q6*+0g!7M=ʒug3LTHa0 :^iys9=L_УΝKM>n5Z.n,f6#{i䥕+_A]gA\ԉ48]Ǘ!`; ^|բD9wX;JڭL Cld̴^Bk^)ȭ5e*a k X1JeŘEQ0g5HK'Z]sH W럥- a<x¿q\]A0!tgJCVliKzF5ɉ! C?ԻBQ7.ɵpjy>Ygl(NR6qi{@1k^#mNiݜV Si$8BO[ȸL87T^sW2VgM4MjK$J_* v =Yx/ژj?AnT3K+:̱/T[ Wߍ߯8PFnfq*4ޛ9xGە>*wTU/O]2r;Z baO^&BPd4\.e`TBbLft<"I4Sb~pYnsŗNG9"`tu_K\2Vr=$OxhYݳޣpi`<!n X]5b6|ybU$xs>Ze (O݀g$g9yL ]7|$Km]TzY*yԉ)~O%벃u}&-l|?.A5<؏ǻɁxvqߕ/d~n^&C3͢bXha[T(7-CxlaRqV:)H7K@^ׯ'%,qd'&k`KĵOEv Pc"/·+Ou{d땸%yюmt#yF|z= &h麪;b:jڠ`E]҆f9:9A;%i 0і, ۿd v%-2BvDpON8\Y[3׿^!.;ΎozjߏW-q#TVzR~Q_XF]L|jhn<ܻᇳ4ER5!sgʒ ZԺRI9g^?z8Ԝ8aWe,l3&݋xooH|``xv7I!y㾯^p7(0vc;SlxM-:v3T΂[e!wP#  VAo3qB @K@a>fKo:r󵼒eNMM&)6PT o9<reD iPܬj)V>ŁǘCeкx )#H]]:+"KZ7_yIB}oK l+_Ҳelbe*z;Xi g+YYc3 FEŽ)lgykٛw)i ފn~DcڊJ?2OĎ<:-)t>x tk{<hYJ]y{eNEHO;) x#]|*{h7 dxpF rjr\ 5Ī)wX|'gJ0EvY-֌,xtÜ9Vŀ1,[ZG+l%m*,=7V;I3iUڷ҅\|hJA 3w-i.TB?pRW =pw +hr`'+d0ռ btXs]pg>SX6A=G1oba-C6@g h){f8~F1eX#dN޸-b :MU= ݄0"5=!5d6^hhu,[H_rB7-/ D𞞌:U7%Sörq 2k?<'@3>u]EVWyÄ4M&*גn#B{["3RF#t ]jx;ujvkj6̲nVnfN:XXz3`t8QJ4]j`2i@@B%ld91UFK?Hd Ij2s P0!l24+B{u%q\ ;VTF eU 50EA&<9L4E6 *"BShV~&$E{uMOa7 F@."Pg;bȲ$((^,|/Ab?ƝY"Kֺ!WlZ:yMF.aĿL|\}n;1xA.sG:wK"OӋE3x,[>Oюn첾Ú;lX oe`0 xhF%/b ,)T4L!YQh4Î)Fc:L6V:P,[E ARmdǁbrKND1O %Qpn-j8q_ZoJ`j iIjW4-<5ܚ)vu6IBDdJZj?eo.5&T=;`]g {OULsyHJA?L/xH܊Rr*a d[_|2H.6fm%2$u%w%BC95fÇVΙa;vTwl0{tw3|`!#$gg)+r3MyHGO|c-7oT(RLpښD&u/8XиCQ ?\ݰΰ`D L$JLLhE|5XctEΐ%; `u!h{qwYH7-_l)jKD_F^s.͢6om}.j]z~Ě%m+ggEAD p_lUi 1xM]㡈Ǫ@=ԏåq=kCrҌa$ O䳩@c~[H;w@])ڰH1QQw$H(1ze)P'eo,Sc 65:TjmSQ$-X2klrނsp2}f^p}[.ܵlaSa Db;v_Ȏʍ eXێ\SK}Kӣ9$krr:w]҃vSQ A'VDOH6PS-!ؐhVcUT>ʕ {e/NkƳqJjiy~v)+kY+XS\і7Kqe!}c6B1_U@Y?xﲍ lS;^7%a;aٲ!ܪF:=8;' &{6aq`>l+:ǮP#u|>p†OVgy6mWVLWL6Ÿ'Mv)A $ف"'|OXekPdޑi^effP~?P9g$Fկ>j⼼dcm$49](lL~ 5)U|u)X?c.yI{ka1vF w, 8]XGVI2|zohs B@E4L6a)G:f2 B>aGY䍼A\_pFzhF* gRO%4zQNmX5vN\׈|T wioW8PMKh/P柃qm>I?Opco(DZoXuo^L[-7b1VIpUgExA$~3gp COԶV_%<^Û㷃k"Y?vu5mm,":BKPV>k >H@WU( q Ev_6s6ߤW^pAK<=E6$@xߍ5}⒱NMi`m=@`Z/ .U¸o3=p+FF29>j‹M@4[qPAx,gz2|\"*~cDݟ{R95qЦZ:ǝ1re'UxvB1K<&-);R0DSoτԌ},c f_7>"p` W2P 42(UyQ!b#-K\v P3U:Z9cתl@u>&c- 6Q@fu:FQk-vdzA+ILۙI )ifb~c*ϐ9Q'ܕ[^JrhC=s*L;Afj_&߻+b>jkwy68>xx{3HEab7i7 [I%&gl!6䩇bWw܄8Z?~{AQg` JZ ONT@p4;؞@$w 2iaSUM)b/;$ 咚`%Z'JnC$]6=j!Q'=Z>RbF@lRkB5MhC#uPҙ@P\b&=ŎydH"}"QC`6?Or6 {NըbNZ,_ ߣpaFt]쟆/XPXΧ"'wuH@֌t[K["F,Wpr(cg 5%߷z kTmq!A X–PGio[=ZYsz\[Wl3j g&JBek]:D:۱xMn#^*c#^4?#k-n%Z8TbaɈ6BWRnNjk>u4=hSZbxGתQ7ۣpY 3 `%yF-J6dH﷋=2XoڌLEg;Wmѓ5:gdaTuƩҌ+]b굙[]8ˍ@:ĕawEC{yi%w*}7p [%3ϡIs%Ĉ ' V|x N,/F}!'Gh+'F∱`?HS˸˹!FȚQĀ܇ Dwl2Tջ\¤ sY2޾*Y X¸uDgFcu5W5Zw$Kkdcdш֟;ۺR)DkzwәP.$"6X4QvkYqIpTI72biQ+= 7nij1\50ze @<rC;/;W\TߨU韱Hjʦ0CZ"[~ŵ=JCQhl1Mk);if\mPClNɾN@#~4^m$rz>'Gdfzy?g@8>gpC9ԡ\ܴr: X,~=:ܗ>Bگ( `Sd6 %][Kq7U \'^SK\Е`6 XNSR(."GXFod"of)T& ѻaVQ,d>.6M[8CwWLzX,RO^6LLkCST+H+1|<މ$+!K-m3}m vcmHЌ BvCk9:3cGfX`oq2=PK[]'&`@X x=S8W \}ɞwd1&[p°qP8 :|r\عuK[P`"+C:B9R|JJX ps{E[EpNX؇X=ҏ{ Ll[ȧ@Cq+zqC0=7ۀR -*jⳎiw%lr]ֆ97L2KdD8cqm~ svm^\ڹAJʙ 9s6p)N@MJњEziepF0Fp7| 1;lTފkIŸ뮊 M_xfoҫy\1sY$ $ss7ビ$yI盎-N~> פ6p|3,Sj!cE= ȏ׊3Cߎpb҂t D?/SBb޳م-)@׭F?`i< /׾sr tLBNGJίj{#pB{^~ЁE$1E4B>[} oVa%f)␉MVt7 'u_MCv@:t"J]Vy}Nn; xڧh$+G\u=Ls%lucNe4bflڙ\+}+=._FHYE6fR"$4Q#/6t~DJkq\gyEʼa+.-;z.iJZziLtIt^&V۱(jQye`u8i5(SV5mM3ښW[>R8 [?GBǮ#@d%cQ}4L!C|O&K翣ư3YZ%O\~70Ev׀h!٠YxXT@RblTBOk!9_a=.]$'݆S| qrVըLٍ^ќ=) քңF9D vdĻhLL1ÁӴ䅶%Kɨg 7@6x#0}ϠQMG}/]5[=%jxKNNAvy煫v2H(z`nQcrУg6@Ƙfi JMjCtHP<& _EvX4Kb\(wE(벑k</ҹ! 5Bbt4-+..\j[Gݤe:`&$|bxrQnILrEk)DHRʳ6W*?Ymsq;AJPޣoԐ'AtKE4[m>e7msuq!gtƗ"[Z/mo:|Se?7Xr [4Lgd0glT7"YJelӣr-r >h7QI {/yb]$m"V{}}aV~@o{t< ΄!?]OKk^|Qs''P&1Qw [$5IVe)DfٜieV:Rv:2/@~CJAC7BssaYE VSaa*(zkfZUG<lpp ;kIZRPs<:z:л|+}NF@ye9)-dE=S<uQoy/̅mb.#?>LȎ7b?)qRd|N!$c+lZbϢʇ|vcw*&Dn*i?'_.r;5UbcYl`euCzײmA(d7"J#`_pf#O]M\H}xfMGƈ`A5u0d Ts0; {ꮄob-XןlD03}d2z.Gk4{֎ܐ>FjXtSRCCi\3u5%wGm j<15QfxCxȤZZ1Onzj&ݽYx/))teȯE83t'',4|&Rmʇ}PLpHQ`qA,?dW*?YftJ윲?G3[fb(uߠpHo3~*ݴ)2LٻDa=wNzsacik~qStV̷ H WR2cD.aZd;jIYܾ!Mr*ޡLG!uYpbYWM_LdN!=rO,7:"+߆Dq^>SD;aM`W^䍪CMy3W?3[67|l(#qaʠ^14NGGJ9cq!%UjJւ#ҁWxumKu[D;%=L\p~ I1DSͻ ~B ۞%c@)*c[i'?d> u* @x&D6}@9t_i퍫ATnN@\yZz3EYqzF6usb'dD<K6|@qN8'g%aD ù!p [H9䙚cZ1X΅8?:c5>X_&NOf? '`ehUUҾ".ko5=J.*$ sb()O=q#<D ϱˎOk#/ԓE#F{SwT|cTAq ~q!ѤsG.53jUTX)CqӒ e}M:vU(1[C0m= $So Y3Il#G4T^಺ѣR?h2tr X<<^Z%^5ðaNJ-DםL9MKYGc֡RR i#PB%:'-W+^W?4P.GAt8#].D0\tV" L\ۇ-V nUMuU azeol^H 7!.it4:_Bi'L”?p첚<oX 0I&qӽphul+Ύ5sI@Pbd=O,Ǻo -UfVtwʈPݱ|qvWI1/j~Y[|z g#Ɵn'$]UX]lө11.W 0(0L"?ŎZ/~ӈհI3!'ɑ0xxNT-+mBQі9Z[|*R XAۘ݌r}3Uᶒ;+)F eO,g1f:J0R"@(+#"Km'}# `V$$6;Z=M@TQȖ%M,1|[v|IN#X9;V~3L:̄9 \xs>@xÞ ]'&<)m\ {ag-;wki8&Z?vLWm$4!Gx :'pեiװ׫O+.k+E;l]>|kZ U/叱>u=6k>{CtyTެ3t? DArbpΥi-Jih;xۿEdeXk dU)NDSA}[@|WtPEDgӒ%W z8ia Yקth  ͔/X-,{R3 >+G@߻ip 0Ai BtIQkRT{A'EP_͔%f>]HdXQ9l|r}>خѡ+ZvP`1A-}cdNBhcëDFZy9$>-!JJe6>Zܮ?׋y:fq':̅.MA8A#JVD|j/5 k_|xL_UL._=́ƛDyq<[%F}e*ڏipn|p$7#YCs+NaWu]Tq]x?䝝K|5I*HXaՖ)2o4tS0ֈsT @M(n: S@ֶ{z z=v^2-'Vׇ&nEpߩ6S_aDT-(b9Obr. kU9j+ ~#p/0A@H9PS5kL'y'E = 34} ׉C_D?Zs{,tEc'*N8)]gl bSAybOY.Fm5ue\ &rX#*s-@&y-ddc!'".S'$20"z\M:Dt{5-kK1?٤cvp'sn- j4dr<+L֥"[M"tiLv5?h݇wc:wy)|Gs VhW8=d\$1C+BsM` vX(b͝toD*d@_.e'],0]7I_#i|ei*z̺?MM9wK _<+ֆVr4i򈨚C(ԏSڰ@RExL~KI퀶mԩbK<>СVA=1(P$D@ߧ4pA/k[&·0Z/"˚1tQ1nx}uNĽ+-W. ٵ_f4X ucSܝux z>OźXϖ/ W~ R/Kۙ@\1$#xmw^*zTiSkf6jh˦ N@0ǯ̅&~<:ݪI"XWTn](]R쐆ڞ7Mm!Uh-YK,ئi'Mw.l3#Jh3=oq9/,,ƈby[_+L 'tiL)V0e߭žs0b]CSs񟩮@“X3, < ΋ ʎ{q[|i{nWg\<:7_W]d!q"[<. =x{Eܻ뭼4)2(1$!0% $Z >&ɀC] K͈-.I<ۺ)~ BVSi/3bhl#$ooyԍ=rm` d>&-%#k%lTi`OH[$U+kzpx<琠ypVFMc=~HT UrA\(2ͪE,urq ֡H"O4svՉW}Ad3bRqr `SVVQӈ|]RBRK#6 v4%,s0CeїP+# +n&Åޯ4b얡k9y*҆ g%^ri;x=BNTۘz\)k͌տ*:v wk򻇯\0=!<{D!97x`%հ~Nsp_gJ^L@ U$2bkcr%?re)t nC% $ zw5 >",[=Ӡ[Fb[ Q :U} ʣ%vKwulw#lZLm_,踌4Sk L8G ."aKYU{;79`_ۿ,<Ĩnz9LJ>vS]2%WwF&r~bY@f{oUٿ6}Euu %Xyۢ9-h#-P[t 8G3V{l.,óQΙAM>?/ }?|#[V㡋i£I)^vU|w@tɸ^,M1qtyP~dڊ$}m6a? )̠b=1>t?5ƶک,IauCw1:x*4:uxܾ{]_4~ˮ[ s&td$L UcQ;hjc] -Mt!-꥖O4U޴%{7c%zl3D72-ۘNv-W-qޭYtf-[@tF K.z$#jgQ3=ņJ;kNNk}Z#Raax%^A$RJ)ˣqnU0+҆!`) Q./f)6\JNރI{!w佟Ai 3{ o둟āNcZZ.Qq E'K630K& e,(C7ҙamHC4Ekc]aJ[r8 d @愿n8|~p3ՊEi9t6X5!t$DWOULLAbCMUh-[s<״3zXz) T-.?BuP`V:jY@dyjG7S0`Y%75P.ʌа˾E9j!(X_3WPWGB{ <.6j+ۧց.^s#^r՗F5o*3 .;Bs4ɟrudk SJY%37_Y#kϦ='[XY?+DyGUS5Cٟut4ֳ}:3&OdiQ$@,1>%%sEÏղ7N7l,_C@Uɼi7C#W2ÒGOJWytOSoLܪ?)09˄*nӚ25+reӁ]_:JMo=}uCbSb L ^&-Pzމ$E;t+-M#Lo9F_Ad2tSJةg c#0IX_tK_g¥>;lvţ__X0l1f]U9!^K?갧Kl[1Y?Ǔ0mZ!UIj!RK@0բ &zȨ `)a{x $.DAS W?*J7Xw~6u$kl'fxԽ `,]S).b( )%(JQtX#1o {Hͷ;!yںa!NɾM@սuiv/劣 hmʈ)3Z=2Gk|ኺ{ "ɫ޾K\Z&/߭ڂi)k]h+RtF#qm(n3J[[M^YNJlC gj,Azt}'r Eέg[eYMP9q%ٚatvj@>8p ٛBo};3O^#Nu W-z[+s&#ʺ) $z,sa 8 yGYfްɠxYCTMs8Yfn珆Jē9;- fs96U0ށ.|;c"n#kUsus;nantev >05_!AbfCYWPcG8 *|m&n?۬})eG9mq>N8WLO%ɒ͓;o3VE1\sQ,7PL~ܑԋsAQFrd*ab$%Ͷ.f},moZ߉np-NLˇTyώ㝟Tv7H8h |*A<襚>f{"gݯg5Mq +LR!oDS6ͮ!LQɓO<*P3`r,ۈ<(26O)+QY{vK*sa*߁H X#c>tV8n0cS f"g/S3 Pn ~-mt laϭ?!b4R*@|R>~to |;1G\Gn?"J\jiHI~XXT؞0~ 8Q;qbYj=? F[Sw 0m$u*G_/;)FHoFgD&K~gHb&^g%#/nb ٚ0hyTU%vnMC+tݨ:'aŌ]X"$Ag؞x4k.t`6W}@0t]m{J&5蔲L<#&Gn%%HXu_Ql w>OjyYGp}Y]WMA1&$$#0~@idn2XHy3_DqqXj] AL_&UV`1+#yVQu݁`0=-'^+Ǵecx0in r0 k}^npLXPu/<˽ A0;~;k{GI-u5mc,T jA£`Jj׬hPyZ'e9!{O^t jr:w(0ɽ 8fğrxtnz (K/z͵C&zFaWyP!NE:R7´j]dƒ_K{[㬈WSjǘ'i"faK fлZqzJz:[Uw9bmh35 Jas?{򛭧{%"?S3qS2$b^&buK]\pE~SQ ӎ2J&\Np̘ΕKYT:פCЏ>蔣h{alflS~}E*lnQ*6yt r[؆QM1]&&iZl"Pc=NIuC`EP8~Q@%&ˆN@='~4zgRƏs1h(7*3O6an$d/ $5Ue?73ATrsqlyV^ ?AW՝(oVmX0k=ߜi&u/4k<,oıқ7_0k;fY#U^\[qQé C'iu\V/u004_3l+:Bu!xm@yo&.\҃ԥ,K rmE-2rya_%SZ٪$cY5J2SlA2BDjjH\XBoo0`qbK#TFe@ܣXFoO$_r5\ 8VD`6B.JS U&Lr=yhisT.C)X 8x"K|N\jr ї@יO,YnMrx ӇOr]&tbХFkXwNmGi_ƽ9Rۑq^$t)gz^IG 2G@ij^bXXYR@q4ˎSkf"e vfKmΊ{gknQh8B)fFw{᳢;W-$^-} t\һ@h.w˜(EB7~9 S_kSV9q:Np&;O2';ɞ30na|1rf{TE\>^l͉Km`~%W(`!׀'MoPU\%,bڼkfxV lj*J`5r¬"[U ̰v6f;RֹaWDXp0o9b&2%,¿56Y+L:R/9iטᬥ}bh9Qc&c;&ǃts|Ĝ0bUSx֧'Zs/:ɰMZ'>1[\CЛPo`J[+ r(%h&<G0?` yc܎ ^+Mu-JG3k2+$LU&͓`yq)dOKk[]<.z]zB!x7vm~o`ttwQ+yNVvQ=9usg!Ss?@?M8jO ۜ_bOpe?{Uwe>Oa6Wڸʑzij?&XI2mRJ/ڧ,MRkX]: D ϋU `Q?+7無}8!+֢x{bY\R ~y{&p) 1 Iax6F0J ]j ?\ƛ~:O~aL@Jëۥx$V}%6X$L|Jct"y0mZA#Al]c^j@p=%FqdR(T~`n[_k'  Ų9˻Xk33*bڌWzT?fx SV?ZЩ9k`;Ձ"fgH<Ѧv-B WdaB8Qb9.fP͏E^CĹi3?(*뮻):de)$= %iH/Pdw ֑/ qcPyc;59ԁ%OOcu ð*ŝIoH(l\\t#C]N0.4H/< neAV`O9wdQrTdW.Ҷڲ w_ud䇱)9hs4qF y3|5FA{5wC!7O/4E>,}Jl4eelCGL ?̢LE4ȱZN¼go< c^=U CZۍf}gO(buw+M{`0\oe,BP;h|8]'Gǖ0\@IW ) 5.fs`seFrL(K˲T29Zpen|7Ln,CƼkж$F'u!*;Yp'rݲTIu'{19N'Şn{(ABď9l"zEt{ ia73} AZco-E)v͝aڊ\HTmuJ3$5^?TC UT( ,dÃ/^KCo`7}((t%2K9dO4((8 XH)^10Vɝ(W QL(7Mg94Gќ;v 6 paPm#owC~]\%1#)oDkA(PR\ȅY0ixpΚPښ1.Y;jvP])ķ/wSjKo )5:djW/(wJ hGL/0*Wp 9F 'v~O9\PHzcOGcf> c' lńra|^(`v}/0 Ce!Z+|A [{}#R\qG0mYN˥zQo-Ŋ ią5g`Ukd/~lâ  aŒ%'JӍ}sN 1D]dw,kx+9/(uwlTr2m|[oe'c#!O1wiRJ$Tm ILIlar >X ->:`s˷䢵d%ruJ%֝d`}t[3 )W&20FqR941fr(7"9%L&VGXq/6SSTNI_&)p"mqj|3au.+#ځ4g6apBظuIi?@nSkpHPм(uVfbܧHb@y2cêmśK?&7@5D״a n/U11Vv &z⑍b!VCJ#6}CM Tvπ4. ݂x׎` 7) ݼ. h=-n؁g_s~e:H r@+ yI4&st}R}v'­`Pr" )ڕ^qE0LlfPu`cjbJ`{ʬs1|jqw7iYFC唳ZΉ cJOJ~=7r!QjyF#ܤ`>c<#ƌHppԕ\O™ɎY )04qm]l4a~jImjE(|唬hyiTظ2* ;=:guohu.f;ѻ|p'\,:MJ6fk<y^]9m >8Nƒala6 ϳO<[$nQ/9C.|3('H~UpxD jK >G%Rn9+(~J}ḅ7c.ʦT?$qK( I~[ϱ Zw2y ,dя j!aƿ -ռR~󔗠8rto$.>:)P/+{WS蝍,SCUBcn8Pŝ#f!^.ZwkӑvvD>^ՕgMyZ܏PT+c҉rrd|UgO1N;E!հE#Md|c||y5!3a%K#r]-kfoizS4,$ l̞p-dfik)1kŃ]8CퟣUzU҉5'Z<@`W %Ys0(7pa/VF-FRӈQfqmRm>T_/Xkrt}L!TG$`ڝ[c-Q` @<:#6ˑW TnY(p֮Y}=a5}0@)NĪ{ 7Jn?RDŌUpFtz5*P)8cw=z~o']]c'6%3DZ2}8*~~ӆUJ_ {硕=ܐZVW.V{{0Ҳ [$ݚQuHEXK;m+Lt7g<>d6`(β`(kRD@3vJoT}z`}s74EdԈ|UVY-6l ,xj7a`)9m; sĬ1wI_4C΋ڵ1ºS4~!zX})m I=5*Oi]JDkk+pCN(GO0W`[ ƪŁ'2'uYr"K? դKԢ%r{;4(MA8,.J׈zVdՐcΣ~LGE n{X?r<>u.=$TOH VX1mԷι@HcP~:#L'NK!m˺0"vNyoW*YubePnjj-&bSiV{E&LԣQנjD5B[χY9Q =lGIw:/ij.ۧ=J@b:TEҔՇNfw؁[]V QfWZc k"Q03EۏM##=@Gݩ;4ּ$:+D}eٸ\!򙒎:h936J#˂S[BUu\x',H85y xʸ>"Ø ƍUPHcnGZ7TP1%fܴׅ8Hۼ+J܊Z<S/05J'#ѵ8LFܴwTd쯹js(vΖhYz#*Boh,=8q6^z 2“8:G c0ß`SƬiSHl5kNlh<Ӊ| ˨{ݰIߞs cЄ.[84Ipą)A<~Z kuhL"Lg0Ml#p=t2)QcK\ܓz=qȘs~mbZ Z;XN Fwd믔DŸkہ`䃭I x(/ \9^T/.Wyn-:𤓀!$ OCKQVn/LJT ,o5?2﷍07ݑ4}ûQ* ѥKx )*"̆ʨ <0YjME*^U-.22ܞ:o6斥)cƗ#N*fάMRU1qj1 qNV S.0|xz:(u^ˈz+>tzwSDϿ7#%8)nQYS.q,JU]S9j$^Zl{~b1q%g&&"Yr̶.7gA*Wϝ2t0e>]iS]RH ,ZeD:wҢշ0R3.ĩXc-D㼜Sɉ͈jthZިVD ԾjmsuU/z|']h#;~C>ܞv]yC?^a\amVI!Rf"w*oђةG?å$7Թ c(e)>g$:aZX=ɡSM_2uHipB(;:R7@Q:OmoߎY\URA@"u[1]X06-PZ;MsGtRfg2: ۦT%\)⏲XR~z{=S+%Qׄ?m6Gdgl}Vt(qmcȗ-=Gp<{ GZYYR^6R Y;/i 1ܑߎPV;Vl'yC1$RnTZZ:䪡veD{0 #2(;0!}pXD"&7\I "M송٪B]V&> 6H~Y,n%SXau9SNڔ)ΟzɖM;dؑA \~}/'&`)jժg\Qn4e g1`\s0eYTй~`,TA灑7vthV)F18͂l`Q+iHVq2[!`Gx+j+'1*[Ra(hItbwzf&ܰ׺1tpk j(r G߷MZԗ>_{Ո&5)Y9.EuWF hC{Lm(eM@M=Y#!Δ-uWIbsk?@eq:?oȣψ/;E!nrM?B> eE|'6DƤXE%\khv)0 g9sTgNZzU6TL]t$]hj "dnmq^X =MSB.ҍ Ч̵ a>}ƟP6uH0yN*L$,X;\sW. 5hNb>Oq/f  B D+➺9?n%z0th262nu^n3%& %0PZb -ZcJ9UL#ﺙ ]Bu gf?[DFxulV5IPƻR9r隩sma8\;߼LZKTdBie! !jIPqs^Bn{haLÚX7T!DfQ0{ȖAR`2@ tQ;,y$!#f:>_|pluqr#0pR04sz>.?Xa:UJH `rqfPvAs,_}\\ԬR :tܩuʜ+Lz g$iў`W, L{`Dzo.L;m>7ȋle-%d wPA~''dY<™d&IJz!~MH*Ȟ\NwMnSaHrfCࣲ'KP8c-=rzllIЌPbD^*ܪrUz1<"֧lIŀs-.QMT"DL"$߮s]2ss=(Hv/IæZ >a;S揮 + rjfW3gYC@>A3*}HhQ;?ݺ"<,Uen=Ooy{lau+{T 1>D`{"A;^^ Za ,Z5JQKHkLˉηhZ&9AJ~]1ݜٷ˯J>g~mH`JP_^k5TH%ԕOÓ),DLR)V) a ºb'Q јwa[&CD#pQRp؛g^O[+6YƤ>MH:9|@!߃gd m K˻oMijy1=pI _13[OB<{Şm#OK^*ău5p9>Y6ۀ%x܎RnщNlž'BuQ(zڳ:?tLiJo}0iAԈ VW7h2A* W]tj5‹c"$/h/B VJx ]]Z \_nzP>JeRT"ס>y dKyfa^#uG›gNxOo:A201U04>]as],vo$v6#V!U%REqG31L04NxCzN2 ᆵT ,;zunm+j՚sYya{XոE-Zy.&աrsμGq@) \Y0 ޏn:-a,(G%&j-SSEt/!6ҝ-merԘ>BCި+Gp}j-ωeH#jAh$qg&}Q DzR;o]z5`q w0PsWǏ[beqB%ʸ_J%ʅs>-ghn{Bb߽אn{(z{,";/M|}3>}4oaQJÛaRkU~W5H.N.(`h0JN S;V-  ,83`ib~khVlJ['/F, E񶤏n:"ҝq#u+`\Cjovd D_kRL[]~}6 &M0kIv0FC,7Qk ֫{pS?;2|(uD&{ do71\%Ӆ*;U̡ B]1Fԟ>u<p>*s\v?ҶIB'[Zg q8nw܍Sd oGZH `^OT.8D /+mǣ6Ap)Ix4"7Ry3串S#6ȹA4@{pQ纥dU0BD޷Bq6fl4VʞT)o ?b ɞ8*! \y_زi= ~t7H)n Iw<➑~30PtgiJf/pƞH8 's-_\TtN &&RLb8ےTvlB6X%/hl*35sGA [7@;ҹ#i͡*fTd0y Fw[gaJ,t IIi #ɛj(`XRDB@|*ʩg *<c>^N߅2Usm S;jeSevl &n/r&ķoBGh.D[r{ĆB(tX+>N|a0N!j[7k365Uooe\G|t0M6 jf/3vt:O"ĭhɧ>GU:_;6;LOfԧ'ˍm1wm\e/7Ӵ>F X Yiچ.53-(5[1e=MIBЎ2YdآCE^S b'BH#U#fp)_C`2U7A:}rt$zJKXZ $eL0 40s㉱! a.%ӻj ަmZmMJ1ƣ؎!v aOnjtצ7 ֢:/H%8ֆ,M_UB 4]`ĐԦr9ws-*[1J{c-}W4Pp >H& D8!}|ۏ. } /s0v]NQҏTs%1êk;\ij! LQz,xPa%M7E!]*Cp,Zf w}ec^YO"`pw?]Zf<=SI$JBEJ`BߞWXCcpnIph'At#]q#UG^j4m-{᠒) kZp{G ^ (rߥTVdڧ~QU`H+/VR=eX!^+3ECKbMRl1ia][` %/D\Jx.fwyMIva1N6tamv[0>6Wwu-ayʧ>OW*(];,Zūjg}L1`h PAcbr6e}Opjο꼊5X vثmKJWpᄂ@쿂cnk8ViWF+Es$!P9iSz8gRqe17Aʧh΄jUgc&[P~SG ,k|Y}0G*I%d$."Sn^/EC~(k+ayeܵJ?]ͬ%\]: 5Ĺ>2AiƎ]qQ'?QaI@~z} 5+Rj8n(`!(Im/^qsC,rgU5Z XI~ƬnK'õZџ /9.x}k(fur1x$g "dsk6hE N3U⏖SJ:+I˿8 [{k!T92P 1 h Eձ%SVS܎뤈?TF5=1qFUïF36PA~:WgҩG[xI)&e1|WrAH5|Ag.JE>KVg(}G1*7xaqD83kトyeb((Oš$ Jh_e"❌YI nLA 7c.\Wlݡާ)/-CP~u $N6P*;-ηw1Yʶ*06~vܑ21 Xm! jFa˱%#=y%{yҢƃ}b˕X0c&71k?4lM"{oFFg"N1Oq~aNO'TZ023]Pg ,õ 'qqt!w35мf@ePT`![HR̍Ƴ2˹%f5iēDLǼ-D^Kcg(,}rW 8V٘\4Q2JJwn0 ^JEVWhQ $2][lrCr ,R1R ,vn6r3Q8ZC0bR(ا[%͉1ebz8׶x!iEXCzp^2dzɊDV4>}+dؚ 21O:U6m F5[?mMI0mE[ɮP,^ߜCDi➨<$zJ#7dUZ:G=![ y8FtGlbg-wZCZ>S"3 vxljRi"~F [ݘJl 1Ӕ.BWip b- XOkD߲L$/6|bC>2MqBʥDE%'?u~k[X;Ur Jp2~o~}uBݔ:j?j<ڞ`9W|pW)''\^ES95 }šx; lv m2T/DPMY +u s$7 uR%u(5~%RGAIl\tŔߜ ÛYcE"VQ"i+53?Kmߺ@Be&΅(펁[;.SYmqYM LfeeǭAkA6^kz);E')`FMY:cDx/^(Sviqy%2b&٣DYtUVǶPmYSb)T,2ly`N+XFs&+F]mD[. (]/z6'-\wpG ~JIɹ-KoE?SjCs$gWz2RwV0-';vbnҌm'? ZF 'T8\7; =@L+*|yت8YiQQ\I4޹1jLToER`sU4H`S4Uf1rbQ#)8[_FvFS8oXf* <(/)#"o 9{p+RmpPJ |3.2_DW!ec*Z8jmu[Ot#PMiՒE m! `75v$3T @vہ9FN@o3/ew@+_O:h?bЕc ͐Ds`|]l}ӍO)ZCPS(ML}i= @fZqйJ 3D4a\@./sXoKsam~.+3x3)8']@\+K{tpQ?|lg篾7MFCA|PcϚ 2tqtzx+U|[>&$űjDr/;WNc*@M ?+*s97mFg8ыgb" G^xKݷMUnBt0ʰb_0w,3;$3$TL/s}h(A+p0HIjFkDOEEqE^tRh® ũz=8$8gAN|%w< 4ZuC54%9WR1 "!LEYDCȆxk[Kw/'hJw܋woIS`R둈2Y\+H"D7לgX+FҮtin ]u9ô=-0sLLbJBq?L=^#vQ_}vUs+kDd?"<=P9/?QxtM1hL$7?Y#Z0Lw>E;}[&Fx|Žg"eu)[} L*q9l,wpMS1X^|?QflB͎,s7໏Z0mĭC$dX+UVt8߃GZRBR}lƜdJ!mՎeoH%ct.60KBLV}ޫgҒ%h>թKx80OHAUǽ^̨vBcFGfMLu}&ue{nx#$_>m=w,꽰Vn'9Ѽ/ȺzTX$c.eM 6bTU+qA*."*y"Wo TX$#~{h7>% ˔ᇎc kE8-nƒ"\Cwt,DIWL @j̭M]Q8%b< τKzЪG&Q.9N҃?kTZc۱#pQZS<1lEu@ %$[O'ƶ\φ8xOQ"M&N3i~|Aei#>ȃ㋇͐&@5|QR[c_%vlCЖCEچ˳\'<ӨBǭIϥoIuhx<9QV O_e?s3hCW<-t5XK ב~! SӞNT}oEKg8!j^q;粂~ǭ& Zj GNƅV @evkL\a>P3}EAI Z}PiWfءEw˰6wN7^E#CJ>B ''=p-k8)w BbU7MrY˾WLKeK4:}E+Ǫv0xDtx. t@Va籣!a(<-Y"2m֧Hl` 4%W(q,԰qy-9,t=A ~f\0׾N  Xv^WU^:e揄GX~Jߍ|Uvo(J[+,*} %Fd=|zxhߦ)y8K*]@О k2)x}ZFM>U<0-X^XPHPe\B' ֕(Q6(C;֐K_cmu"X8nfHz6M0keуVuS4CBlU:u:͟|D"ænXԗGDgo`~G=]CL+ڧ 8ՅcQ7HMD%DC m*>?K1$F1 ^Q})+zŲ ǠupѮO[GŔ#uNڂ45^SKn?=ƭ-O|vaS0ДWuPDa໻C!a@L[YHGʕ~.(>L/%WYbNUyС$d2W9\ɳ];B~窚 3tZq/NfmOW5F6gw]6tyA)ʠoHTQQ1JCfMOYhڰ Oށ͒9"`JJNTj5G %G"u0jiTؽ#\EN l3Bj:(6:mҺ%hhx@7B^uƳE i9P@W:9l8iҏ :|"_BPr))fZMVQ;&ˍ` Nn߇d]cۿ o;x(3ow6bxN)U4:'BHGVBϠA=֕*0DX|ak [Q_6)czp- $LȧVU*y9ѓJɸ (t(0zNPܩk(y6|Gr Ża} Z 50MBjEk`κfv Ñazn_Ct,TLv[7W|>i6 lÊ>g1 7^)D}+w61)2Ѐ>̡$piqPF9:/EǂPLwGBC`Adq>.fr#[[/!+u7}ZoV$ A|!NR,A@(roDj<$o1vd`AGoJV(KtIcWb"% >pT)/>#VN,(PgB cXoy*eGؿ=]şE{ڽr;bqKB&VH)X]UQi96q>⥔]X7}Яfұ!N<465OT錫1 \0rxnQ(t'a~k*67_mjHN"FuCq qaAp[,H}#PP>,As7]qAh2ΘL)N?.iz T]HgojQ/jE׏ˡ-u<pMcΚp=eeN<5 Sj>K`GҸfEVRB&T !@\U϶>1ӈyw3nUcDAkni9!#ˣUoiXLK5FAc!ԛbwVFr+Xnb/pyCBUZ9S96/!dJ!4@P'V Va d8e@O5jۜUwG>3(wj,d}y=qK!{9S+UC~MMbf%K|ϛq<Ε/vLNPA9h&z2q0wـm$ #.Թz>6rda=-?g~ߑyvIWy!%&Xa@gdϺXNCm #/~NN£6JwP"t-g No)Iyi=lۡ7=3y!,tq6a+!06V09:>#vδkh94p'+l?̷\:!|ZtjHz:U1AܣOp#"oFwbp}ľ{?Rh5:oV [hʂs5#Z/mB0\ILsᰦT;nILk1-pv> 1f]>Q8^Y$_DQ$%Dm%I-R'sBL ?c>(S] _,?T]K4|U-ZwI`/'VP66mRv]a'ׅ{_ũUR7[w>ōto[]E&xFQp.owdڱr\r ^=03vԍ_M[d؇aa ;帀 GmS v͆Ǖm:Ncĺ>ӵ YӑClppOAM\ TzϱjuI.0bMM{b=3k]y\leFpo5 bf=6XuY7`, wuϥkcyQj\аQ(hQ  vf1O7c>D d2DcW!~\uz(Ou}r8*OC5O=kΙ6&=|Ҫ= hkI9|I#4]{ =dbNi'(w c9i@)nGq.6yEa ~7qoboMͥ0xdHZy xi5FM~.\7m촆!ccB:{L%06P1p#ľB, \g^D,{FG;e=E(38{ekɈ,ۖdt"lBl[ }*PWD-S|y_Y#ՅMM܈5hp "`Ѓ'+^8 >PE[q!2gK'!=.H!|B ųlfuԽNy¾ψ46sfr Mq(WpW$qd4`m+9nwiҚ WbδL/,$V$BBT@: (腘,qc[ jLԌj x^ZqIn$5tD5 '8\D<{b}Btv? ThOdNs~J'Uw1E`BqiHDz䬬R/n&/t*\jukf xӃz:ix$tn2urwwK9h0kS_[΋>/]NזL_4+3uzanCvLf5Aн}n);eb*0PK kc:@k'${Uoa}(pw G)@PMPgUo.5g6%]|DHX|I{n i21F/t^UOq7@ǜ c2# &Z5o\PO(/U\s+Ahq4rzXXo{{ƀ 2Pdj"X"?AS;U'.;=:52/u K7bH39$Xo_GG- $˻(rV0}lIN2KՑc@~/y6WPMc mܰc}3%%Mgr^#S2*IhT~dΊU~Nh)Z;W.GBѫRhXbϤjpc)hm8RS(>'vOMPM:ңS M=R Xҧf\,2~oK̘d0%IS~g'_<$h&Ș  7cgqzyxpVJQc W4GapXLq!{NX"U[:y'1cBKIZqjHOn8|ϨᷚX"Qdf޼H,%1[c.y[8~)/2`0WP =#=ⷥřj[ $gWo{McU(]ea.5Vp=LYvu "B+RUFcxQs[wK_r8-/$q mnOe b:@\cG^b AژX8fhSbh ^ͤ4Ivv\b^짽M7ipjuHH,/ap̔F-/g?g*ͲH9Q͞1'Y_幩v"#?t(]EOEV{0WbX4v |D:P,f77Og4vR̾NF: %8{1e x0eYL֓4Qd =d(㖧[<p7 6'LݫޚLtUE=/12pJz'eݸD$20Ѿ<#JP:Tj]]E瑃\{K)ΉfWf\Q{EfCs!?WU+:/\tv WD,\ƌqLwP'R$D4^ɶ;Mg^#KoQmh?[ʕ8Fo^VH6)G!/Q)\{\CJmFhg'Іi{f2]}å4]W &AQW;7 7L+g<(DTEnv9wk26-t:-3)2rlh!'adrSw7L-<%FsS:jy%BNj+"= P|2POao4̈́,g]X_~Tu#JZN̅r`|ڶ"#_ jvKA?rp6 =SsocWudS-.wfE']6* C{Bt*Qf$e M_3Y=2\~$=3x:;&Yv*d/)*tP˜!Ong9|.R W=x]anO3T|ZvחeSs'ATz`㙕X>pc/V6n$6PڈmntPpTb{i$ZZTL:`|H {~TA3t9'Z=E:Q $ /'w"oc(DSߞ)w]%KV/ i϶T9#sn"q3ADƳB_]iœzp3}13kN7 'Ҟ]#DXʷڃ6;[6aDS~ sO:\g:#>#*mRofVЗ,SGR5tөO)֩q4أb(TX35L[3 ;î>yvL+7#0|0 !]S[9ʪm2\d>Ț晢qr@oͽ4b"SCGrXC`G'0Qqo֎[Ek*oM"K&Hֵ6_ΚS @lרaFo qq!rm ^P<?OG})VS4X0i-ep/uYť`:ԁ… Dvx7g]$_Qǰ|J'}jfHWψ=v`}ٻխy@=+gjF BiNj}m,(%pa[.7gq4Rh[kȪZH F0)4H44Klۓ M$QuglDqmtk7d7|1|ūRZrMytnUSq8˱,z4:MhEW =u2+RilG\ZDR`zwKg]j4,Ah{x<2r-R[U`% Njsi3Tv6YEx5\cD rR~├C)ʙfوɛRFH{3CkAG[,ʷj2"`%/C<od8Ag%A+TC[_[3K6s6ORijf&) ֪I|"B[I_N_jDFs{T~~t8w+]@x q !He*FF0 Y# ib[G>TzW',ElʻՀ͚#ѣ57 ) ' _b>oo[N+A"b2r*!7Ɗw. /&{hzdȣDŽts r!0&G b%JWӑz\H! Iw-gjj5hxs E) 鎞sϯX7Rgv% ,PbvLkTx/۾{!S)H@ xaƟʵى>O0kmnDZ,v%u/T=ZejCbV izd7M[;)RrąANg%,B9D?Eyj3x5bfwn7ٴ?ᄂ=?hE?u+pK ĺ(le+LVs.O^{X)xcSxTR#дOVSwiKs Tt"= yDQ|vtE &@]opCx!11h1=/LРLNQld"bj8Sf.:vDtPZB S^ fRF[GoRM:t ݴyFG)ҥnCQ}-ǧʳ¦}Y7<8žcA5 Ni^V7ig^΍q}7JdHzc!KޞE>Xh$gBֹx!'-q~R |ۿShSOaؐ 4dIg)KAzߴR[Yc%(N' \I*\."wϴS`Q=;<5cR!h+i,ՐMؓ^Il_ܼk4* ȍOJT綰kWXi,se=ݷRZ{uCm:n"R9{oH-猉j Àa{ݒ6G(7oKm<>ήWgƭvB:Nr\bu@0muY˒zצ`4[Ԥ槽ЋG<> 6dѭϻ h+R\e&6E@VG2kMX7"ux į K-i>ξJˇcץ|A6_Jഁ9GŘG:o;^u'eѹW;zFH?>]rɸX. ;^@M^Ð!g(Ѽg?>+=%dw"a Cg2)QX2&RD$JGCepև_"MYpc&nz9P_7;DY )qJA=_B[JwJ/lvRDŽâo4l&.hjg| nK˸2#Aje;m1^&=)uXw.I6CW)b4#G:҉ k3RᨵKm"ФSr٣P'݃c} Ѫ DuDT=q$:^P0E—F3~<_Y) D ohd5$iOg_~Q>Fd)Dud)3];B%+LԮ6e!BcxGȯ `SF_ůҒb{#m hȪ:AMxqݏR7쵧_>WtSJyWO>t P i0h&\RX[p5E[/\Fq4SPb {~ZߔJڗ^=n%"5nft\Uѳa 1B̭PIЃׯ d VI(MeaSCLBA%Dsz*JyJǘj7.#Аԗh' ;(WFbH"ņAlz1Dǩ6} O?<ܸ:stO7ļb:TNLYcr66p% <8娨8AثL yC%kGj,5*b&J¸cU`*Ggk$AfzqPOjיe{dӕantghH޸;g{ fm %j/Nwq 4I|i^|=;"tv%QTZ(r?SwWeqPt e sf#ÚCjEk9m3"1Q̭Eo:_xZY.C:M,b:HX/s,yTw(m]inBÍU`ޘwH0{*,*y J >M}&Ǎ\Vxi3__=׷dkM0u! YO(#FkgQZ&sA9Jtջf\gIFH/\P;+i #-+|ݓL^72i6bC7d a #HeԺ^}Lj&Q$,BK_j9l v=>jRE ;&ҟ!חj)`j5a U J!̩E_B,Sժz@>L<Xl4?v/~na}v#]rv7bD}Nŏnf4_t_8V @b{쉉D]d+JtR ngHssN%>-P7X26W9Y;MV͇VO'qT a=ح&7..M2TY2b́7OI|T;7p[sml֜a?(ULvsژg^m@9FcM~5HOLiy!`qzOp,,P61/%}A ?ۥӘ.j[X, Zk:3ˋaś-BI7dkޛHf1b3pv%p~gUR:)bqu#tX' T6ih=.q[%hu>sūL*&Zp]$ U)wk8;P\yA=@7{~;8(pgRROP^WpR}?N- *`L+fh\=m)r~c[{[ n3 MU /|ސuKf,bX}ţ L h-|QCr7¶<.y1,ݥZ"߽Go9_N8jf>9۟yb3 ?NT=O0ϡۧIJ&[&~z][n 8.pݵpΒ\s=8lSpwn"[aO(Y̡+Dg)˷A@: LDb86]93eL?q|Pz-5^1('3aU43i Z:,q1mu?d'WEθx-*q)?sbhN%!?`GCO&GA`ݺdWGx2Y63u"ݱ/7vF9$sv!`ϵtGߔծ!W09aL}DguV}Yt ߕKA٪5J@?V D&l^I3xP^l:&yGLTљ@t3 1zt~Gaj6WG? H 0÷mrb0v_R)l hZHLrݗVEz}&%e*8a/ƿ0W S v$h-r\h~f"Jd(@Hpxkj2-攻Sj#2Nqܺ[Ej, 3ΠA?H bD[`0Zy\8K+գ–us,b3C%뫷h=I#0)ts?gnp%m uG&Y3%> \^yP aʹfdHK Y ':];SPhoxX=Q!GrFwN"oM8̧>P"_;/7!ɝW6"; F5fyfZkh%h#YR$&k$uV61nAP>F vwS`dIH=YM> #9'ҖI|NwX?N5Uݫ5]g6TT{˛I_wFFʂwn- .hs!p|~.{2!~Zo=rrƏ$Yuv^ bg7Y\h?V|%6{+ I Xp)~2;48oCUWijfc@bHnۍx WYЫ`-  SSU* D0(jI4Tt 9XH"C!07'|˘ fBTY)I\nIHΕCC2aEB˺(fV_ ;f/ )@ ` 尖ieHzHS~wU4Mn7 N ZG)P9VU n,7g"C.9TTC2_b8u>߶d8 25 rr'{;-zdeZ3;>۟XaҀWƖ7w5˻ p.FHtc^O38S)l"(g5{ ѭ1kod;oo~OXѣAy֋RR}RWX"%n4',? 6!ΖWGgN2>GK2ѿ$j9yYpUbftg5]D(t([;!6`wτwt Q.YC!X_Nw{|IJ<GO`TAqm_K'9j1j>2 j4AjgܽraM#? %փo<Άsy t.+; 䨤a :Cyˋ-o fi=4=HS>8z+Sx>$M[mu tԛ czTcze[%~kg\ g Z@gfdCQ?ޱ07{thZJ }Pf5Pe.=ZgQ<QK9kN8IXr۸ݡŽ%K#F$!6?M\A<(*q7e+L⥁G}c$jiF8mޑNk n~Yli&Qi+[Bf!x #DSi>?#fY,YFLzXm**|ӗL:5uUDP={j49#;P+yh^ f s؅S:ԉn`wUe`*VZ"p؁S-VV8i_2'L0d/ k|&.aZxxy;fv7{[FzI]S &&=ݞ(D+%]3^_djamCx5c[?UyjY+F|^ir䦙N3 ,P`N-tD8j1I khp!/]܊`Fqy’j%Kҋ%qA~VaA7M|V}|e25T4Jt2@xIݎo# YYx&)ʑ_9ڂAq:(fOգNXݎĔ|M:~^@J9+ùb>W(w^pRqhAH~/y4\X 5ͳB@RCKe)ć{WY!]pd2wjP7 paJ\cz&ݟ{"Z+D˭Ӡ L$EB:s3d-x+ob\`&OH2:ZMֲ,.hIyas&§@{9HH~Ty % cؕ}"BlooA%qdw=Gh#y :dv@#->q% ;CR >>" \$EN,0`Y[^ǎ_68:4vx08 `ùAd)"w瘶ZtSB86Xȥ6NkTuv'V?z?CNP2LQ,"< {r:x*O/>$"XC=+3Q .x1UHQ'K^"!!ۖ!2K*7@q=9ek%"y?2ϸ#[2FYXvSJ?,pY۾MkU-[U|$.%=ٌ+?XU/#łm_7ϛ-/c>Y $۵]5D/UVEu\͉hw(uS=/_4tsMQi)^UL ~s~DeǮrdlثlCZ7`m.cob3%JK.UؗyyT9}񉫧~rԍ9Upd,Llu' TEZh_# ݨѼߏ[ڃ4 P?U0HRT ]mnX)56JMPmj]_j0=.֋+iXW鳕⋁q1=ytdhѦ=HRXT?dJ! >7-߼=0˜ơsG'@z~ anB?zk v91ƽE%iJtoޖ@xURҴeDl44ieP@6IX-;$XPQp#9i~(?lƇuן-Άsб6u,#[&y 0hG\UUVQu+2sɲkje(]{`ci;`-ݧBS SD+@l`ePR+X"W;B_?AP#뗠)f{ۥ9]8G{iQQ2}Q'0[oFtI =Fq3NDkRM/h!Q.sS@u+J^IR$Ju8DC^qνbjj0\ . ^f L^K%H~}V+$5JWSaӬŒO/D媑;Ɗեc߿@TY[n{_*␾t ޅL2^hhIFum``jxy9~5p*fcbt^:QWI)d'$ܫ-#%t0YOy V?Z)C5Sl*|WZ\b%ᔺjKI̢=#Κ%P.=M0z?;sf3ZMOꩰ,jC$VΔ}q7\OrF(ס0dM; D5:q+`^8lm֋30vlw;e&ӾAۆJ_/4Z@ar41Ys*Dl(l`^ wCHnкRHB\+FJV<]J'PkHV뇒~555۰* #ΟJ)pFس HHy+U!?v5Qu`#ATLæ+^q*Y |V EギdRw3ĥ4牙 }2/|S &G 쏛QNt8\7֦Ҿˁg`Ȫ8HUq bcVPTQ"Ch?rHԐU<>ɸiKݢb6[%(^b vHʛ.zL9ׇd^J~LdkjZ +wrSPN"8 I2&RQkBe1Baiށ6VRr'*6yJ,ВvYkVUZhG`1xZ_saOj?p$hs+./ǒ E dhӚd(]y$>8'~TnҸx]>W~2poIr9V_X|ym6:*rby>k9Zb5lt֏ R(?7!_AgRIpcL 0o f?MS͵%Lh4iKk)}u Nomw֏Y*Z % "ݲ^*!"/8e ^i{O ˟;q)RUS~J̨.Hjj] A>>J᮫Cspx؜ :'ߐ奠!&=ٸd̈́}w ?9[rߐt0bi*>&7odJwEh)K`\HT-S1%jA|wq!X!œ[_kGd:QWobZ <3ð'aj~I znw?jDA)2t&<}B} JQR|5sg.F*VvϟhG|`ToW9LLR\- 7FpnK) pa *(}[P,fS 'COB0=E`T)>,>[YQ}OSB1U/!Ͼ\F^ǿQKWh٢\i<6*[HGAbН$-Ylw] q$˶J?UCrN^09{kT!Bt`ŝd8*Bk0VB* ;PK^Zɳ~oمd Ui-4RwA0Kʚ!* mN(HvT\A?A+Ɨ9tOO ?NF4}r]3ެHsI>KL{9>~3TJ]mR쒿7wXk2Dݧ5RbGwL <O/*Q8wfE:)Oei9_; A #~M7dT5d~i f*ܬon? HZCDOeDdYtAԇ^jJ'tdCO 2,WUMQz]Q`;j^-pNUȦP *oY{eǕfl*/FYjl@SŇ8)6|2\˨bM#Ө-XkQmku &yʨ5IxLՇZE`"!E\V\eFbrkqbڧ4LMy~ʼ_kb(#? O|4lIZ! ?F4nN$=,nV7+WMe{0-k0(040r>I?11EvVɫ<5o5;I(Vy*!+jmGn:mGzUe_Ƣm$qn ifb?ߢf!鱏iG% V@1Ax+ g$v..\CPtz7Ia΂a&jKSufOJ~'fƒގ= 1Mڊw̰׬Z詺Z_D' qj0DG>y oPE\ђ.Aes@uNÊQwWlԚy!g H3D_'1s!IzS i[:]Y`6%[N.o-ӡ$0sqY%s"=55^S5w=ym% \RQGio[ 't,및i=l.L$ ;R'mziw;t U*Ap+[N"On#qE|3U&a#C/[# YP_[E^^ljPq=,m:L@3%,k=e`xn;;SLT!E=Wҗ1"t/RC  wJ1&I} WzHE[Lt5_&ik-  x{1ma*.ܝB;y;Ƒ|RZ@oU])O$FZu'mEAmjlě&ZqTDklp+Rz+PQzizVGh46"+W?"崂07Viޣ%kuRDW!&Wzޥ}3lNM+ ul@ŽP ippxB3mJD,3żjPe7` ~x^"YޢjnVG]6Kl w^L{Mnk5aShmuD8Ъ TK4p{"K~lT,Q6ѹpu0f5?*aaP=Rc݄ga)ˈ"*>@~ K 7;ͪgB &XLN {YHSsۆGS_'xyҒ#p%a\odC~JZxs<ŅZ)|y_GZ*ž,T wU]>J8> i115;uKPWVAĵ[-E#;%!pd iOu)п1CMkƸR +bl֐ U2;#~K+w-.5!~imӔ}_ #mMojCYkk+oH~s6Љk$i\K . {J;D^rJp` GGaw E1ϱU 6V۩C7TW67ǶJtlV5p6UW=\֋2[ *8mT>3ZuJSb!1JIbGVv^9r'AP lѵvP}]rI\Ϲs)42S^8 Xm+n5Ye"9k^?huE2+/3Z1?o"aҌ|;B;zG#Z-W,7=e;_'"XPAΫkC_mi Ezi^Q+2U&|,J(es0eLҀp̏:2~7YƩ8O;0wdq?<Yn~ئ&QyWIzUj 4moh>(zKgQ;S"U"xvaiAfh#ϖ۷AeP> $;@挎?g' 5w/gߩS&Xd,S\':k$uc&d/b;l}2oɰ$ bJncHMv!;G|K8C3[ Ijb2Ԯvlշ3LM8^S(j fS iGIbn3nOΤc^q3RRgTM/lی Su<۽Ʊ]|jzѿ5p~_Z]Wx}45e#CV@ʱ_ӄqNTAa&Y:8Uf$%~"*1@#=fό:z܋`4o8/p(+tR8`Fʬ@f h82ى3lpթխ^; kMWgZFc8ܷNuWd9*cBP` Vyۜr]&CwpbLOq;ќ+'%{XR~ZY+ڕ0PD\h'AaA8~_oesIu q鱁/oPƕM S.VWvxr-H6V0ooRZ[zg^uʹNCRLMlF,29 &NsMvMt2Dx >Rq-IvI邘N62=5d(*m|՝I_qk|,t8G_**w-A>'1v޳4}D@Ru(.Yՙʔ{pIf!dRļ4A"Aes`u:|T]b҉W'!3B.VsKeKnI֞)<ŏ!›?CMQ :딝`ۗ!VyCt(+3nr(j>}2F5f*i!3r,K<-ąWHzSUL/0>` olBUftbuc哭.ՕҚ:rH(+6՛9FpXY.\{A H\Y)lPA%KYV;hg\gjB)#$VCp\JEݎc.o3AWHYl=B]j2! f:v nK4}O+ʖ,4'BH]3E$}cЇ.I!Bw)rC2e}x!ҍ=P!`m 8%aqʵVs9 e;T 1@?g0w~q-$[[9vKY^0.<\U%{}-3ԫh NXqҫMe+GQX,exj"6’u '.;0]{(E~Q&Y]VU(>ՖmhԙKP5Ii{&/#`u6TRzJ"4AʆNN U2Ly)Ch{ W=F^>kCRO:JTD+`*TĢ< }"c,=WJzʾHO:&3G"}^V<ĞLGRɀ=8۝m_N'u8F6pvi$E!VN;IE؀aմ$Hړ8- T65JAϝKYD=PsrW1جp~0# &C-݃/;Kf= Xӥ6 uƹҔOCs#v۾&J>4euU‹Ͽ^"WƹQ[QBBkTzp*-^}9 -ӻd$q$9|1K^}e'uh@(c :0.&ܾ؇H#BV6*g|s UO P_bnl9 HGU`C90r/{.scEA8\ih) >;2PIS@ G׶/(} ..n W_'yzްNjD"o w[q,f?d+YB" ř${dt0žy; CV Ѵ0XRh! ो눤 Z宥{qeI;:tNїKTEӒ{~ʳ~`!ʎ`$Ll-P;7R o6zÏ'^Q~H>r8sIhxq$l"M"hkuŝƧM[I2L C-5IY.bjXq 6 fF%9mOJsn1cvȊU)/ӝ4$ӆ9NԃABDǜVs>!@ UrXfTF)y09W'w6lXH$WfI`iL~{ѹnDR«Ǵ",xY] aLBSZDzvl=h3Wt$H7 {5`=i(a 6/X˞fpQ6⼩af(}Nǽ6~'TMޛM$#l6mߺ)z_md  Ώ`0m3B!TT#dGHNzxP9UOj5,re8v[ i[ Au.61:RxFõHVJHBVO:VGVnf ؚ$ E,Dt U6]ֺ]<rp|Ԣ[0Fy Qpw?b\sY$X#wRaO9z!+UD5KO\"^*e+(3 TJ@ZN ȍ0sSI*acC3N+X2J"@HWqDN6\BGU.l> !pꄸ󰱼S6OeΣH؟7S$:Tj|;pNd쓙.ض0م( ?yS#mڛu¸4>{"׼0K)GQr2=1)u*&&3;lmJ{5_ -P 0zKRsJ4$^K21o^ހH xȕOQ%X~Qct/kZyCagWZC 놆 z(V[߻,puL;nb\lzw9j$l"п'1a$3izSF0$$§i.7z&."at%C6*M#Ǐ(N4?W t魪M9zMٍ锁>-@"ymfJ%&LL$Ґ:{MuAWF#o(]yXg--&]n^!Z;O_oRe[M&$~4,,;AWN$9*dMʬ7mM%3|c;v8d~$!kA哠}l[mT͌WkM% ypwW|W[M~eX\M84gBE|ftWyˊl۴'4wTvhOd"A~BzmC;W-T>b]'F-4u$Q>JRYQ)Q$5U<y3YL Ys۫e/rl/#~]Ӓ:OOD&z.޾8d!޸}şl&LVS^Ơe QL/HS>Mӎfwa%?J#)j56}ȾλUao;VY+dS嫦awF/Ξy/Î̻ܖRnVe_]^t4+`d=k=[/`P "RDH=:MNcKF•_~`.D*{RQj+z:5ƀkS`#QOZ` M:+| /`|o{, C3R6H1P=1XSmLݧ4,P 8w cf7/4GD^a }KRO}V8ݯv-!,I^ǟ7aώfɑi }2Qy̎U,| >,!?=H17ڲ6:lVC2`bwC!ԁ\sY1u8b;㏗: h@vmV1R=J[Kȳ5)uG4z! < [ [E{\cSvIeqe3dF #8H7wvDDfw,*{@[drT*T_%G?1\&R&/ )p&9ʾ+wJȐUEz !e1$%ox.ĠӉ|yY˻3&Bň"($K6>X+Vhi\(}O(?iH ]nMP#}ڇKfN&6fDoJB,@=UI1>n%mQFFP>ɚ3|p YZK3C[^mHihٜ{~;S M~hk-݃`Μ:vI~*EhZ;u >m\JϼSۢ"3'5sa(3!cV,b"Ý(gi5%UhJ^c, GL`驴դ!ke$gghInZr>cf`#{ 4ئt jWh2vsQG"P[⾍hV/p=讝Kd%$h8qm>[{'qpDw \یNX01 M7fvhx/($ژhGa%Li1V@0ϏYۀQG7Hro>CYT!7Kkު UeT4lɮxM-G.;n$E`%t9GɚxB]MjSDOF:bgJ͊˼Smw'F" I}7lZqIp`a|Ȓ'ޢ&[?#`<ҷbmBQ陛b*\Xc J\mi;Cx"# `4r` 8= N#xc ysh"<WR|MHPXcJ8.qc4.y`oN7j2̤ʉ^Xr1T'Ã!9ȂJ D~ |°t3~Ȅ}  gh'gtJ9ϐ/RsXRI$mll1'j`ٴ1,[;~ıҭhFs$p 9 ?KaXOT"`$v  gVOXq|@.Л$Yk/Z0!9M'5}3?e7f+\ޘ̌8bf1o a8cVN-NJPTmrpq=u5(17΋/,UfƄ4erL\?f/4ʺ[3LLŽ}DG3b % [m,sBQׂ1bA:!SYzI}OL|%c " bƍU5w+8сJ.ʆֶhf+K4S KGeE.&.$7Zj(Ἓu!Ozg/wݺP{$,ZʻϸffYP` {;{oywo;/PƵR  :E'sbrinK*YUy1W.{Qs:g z30{LλV \}_ϳ;6b{t[' x3_v(*2cֿHybsS%Ij]JD8vDW'bp.@u'-n #H!tl_/8] 6@ hٹaO30\w]E+&[|ҍR|o-jshbUm&ms;wr*~?MѝuS^P42]pGD"oH HmF"@ŒQWER_Ro6XWٌ{aS)>m,mEgk 8!ᄡOVѺ2:.Z{t,< /׮l/6[/X1~&n[5,ӥ1%"~Ò,_;^RnŮJO 0"QWQ!A?_5:/r`,Ue Oer^# y$\jjW3X뿅4S_V$_FzGY1tҹ#Z}5c|pT%`m=kkӬ|rGY77M2f$uh>i`gRMs]U[jAgD Ny4qø J0/ٰO/>M9YJwJVh'1_Ry@rPU.]oH8]B'Lmv6%~`4C̀>Yb "3hW ^i]c Ҿם+-)$HFrm'DU@\(~%yuלp./`7)r0Z׹\`pbt$es.=iP{(1ן壏YJ"iB9 ۫:j3!sJ9s;e7O˂<4rNj:dKW 'e )4$E|&4jh$BO/wOR= LJEd׆wskh\ף]Ng]yY,h:,̆ AHݰk7Z76EkUŽYP\>?(6FWw([4F FY: |{ȟJVis+@u9;(xG#־A`kWȯ4l{yVj#oK9^E/\;QjfF/2E# Tm `w*t餐yCT5gv;ڊL"lM|F.|eZ,/5Iv麐!k;\#'n-x0/^jx/ӍPp\2 /5UMoB(_V Sߓ& : iX׺lmu[qP$zb$j*Zu ֑ G:FvΤ"Ԭ-!@^&K*}/:tJ@Lfir`&b "k}*ʋRp͎6Le 0Q=P>vfy/>B&1vL'/;EDFR?El]v.pK`5ikӾA24l@&p^4A+w-6D^)N̈́ds]l2P2Q)^nȲ{5E2@j?T Fupl6 N?g$y@KیN bEYtZK6o1?^$dUh߭RgGG93f>) Y3LMa@p?fSt ݇rGn6>$H:Q9Q.fk"Vz@M3gNWFd}#"MVV7έ/h SY_\a+#DP=&m%>!g8%DN&DJ7&9>dѮs3yI<3Akc9Պ-t7E:c<) )'鶿p!.r+LmպdXzt9mWIy=}'t4Į -zQC-tz>?Vߢ.^ @MÛƒSˆ7/ ^JB&^{.<3P> W7@ -x(PVXݝz#QE-*( ɤb3ٵ6 ;Ymρ)تDE&a=SGw9ʋ3w< ~,iH\kW"kѨ{=ஐ:i%| u_uˏ'H򮶄X  T@g%-'w b sFVg,Y) 䁓z;"ʉ!m >08o-8N^ m|ejal=MW ҳ CGpK.iŖ) zu09el Js.cA=띌ot*Ƿo:UߋUߥ{MkV?VV%`R3e| 2u ;6ݟ*Ѵe46|2BX1;NS3zK -,69hs |<=7r:~.ֲ>,M AR= F<~ngbe;֮A\5&2T ȃUwHzF_$㻭h>4<O ,QƟWPjlBOJu7sN7HV:ѓfs4NC6;(?hkA&QV;MBE8eW*RgH;$e'pd)akn\*X-ߣ,mVҝSo-0g]i kiu,k}\ 8|%X([7캲p"\X!u{)`dNbSg"B˨dL] FXP~wtì8~W Y~ HCUƗZ VBxRp>/碌X{ 2]M,S!R5H! bv+d,!cF<5'/"D6|cS! ?B,;Ӳ'n ~@3EMՊ9vZFeSnAܱLߚt˧ slM}{0 rlvWzg;eo׬) pu22_t~n)};=Fsn0B%],]f*:#-#iՍѬ66nѪM;0ζ"Agx$wgC!irS=Ytl#_Ԩl񬍼 9J%י{U%dm5ͬg.b"55,S$o6 tk6S^R l1Od*6% Ɠ}ebpOZ2ya7c\ ҎbǛfp" o%>Ynhc$saoy>Ŵ\Fob^n&(wR!) Bbi 8Ӑ edC?EPc 냡@:\ OH3y=MM3-UZzrj^V_IUhlg}ɍFaA>Rv` fIER?[d69k"?&D_NUX³fZtz-_roҹ-mǞl;K?Fv*&DF'vC3mB=ΐ[ު:5ETH*!6tF)S Eg5_eWc$^{WzRqe,.Q.`$k#D; k%6_^#uODр߁IuXU1 90@mIB% {!PDɆ+)yp{ቌ'1*mep˳K✧)Z=wWF{G8L׌q5ҀP*ܢLz Bds0]~_Tr索Wr?cD?>>[kt9 !:#^S5"g,,iT{+E>0\G-.S/m7>J[37`LW9ڷeӰGj}9>TfܑhX/eP֚898EW.uhȴc&~D}WrWou|1v=j5^!JC#:B7 @wF}D&B.\( ܮ)t"p^ݷyTg%=&'X[jz NWRnZ7ۃ(&Q!pHA`oZA_zU_!E%5 ~\?+FÍ԰`iiatט \_n{j1qՌ}mF3l xGt,m{GQX0h$D\bNaHmҭ4@B"4'!g,E )>'' AâPGF<87Io"=붧FŻ9S﹜&:}P੺L*$;V!p7_SB3UsY{Ѷ/3^:uފTjڤCVPWd/#OɇA!]&\0$ +hs iE0ÓҾ7EڶJ$9F/J  ->)GQJLy {l\ݿ=!*&j^N R7fajF g܇)3IuN?}5NqTRFSʭm0v}g=/a''R@Z+ʞSu(?!=cG=BeX.ť+n mC喆SalnPN$u=HĎx9|.(Œq-T4IahOB3->9 li ÈFH`VN1-r+KK -zPje#/VDNi]GEKMVQn5o̓EQZ2PF6cIkI[\| m=|[Bm ևk6H3nVݱ\Mf S|OG}}C#@_b}ݼK ڢf46Yf$WH$ wD;}"q\Hٷ[,l>s7ޅ x!C8A͘ ]ґqx2b:#-DO(u26啫8 mŧK'!W;|,.=_)ὐ̼+ұ 6ϡӛO0,uva9vFm(+Č:zggnq7Ίhbo ;!0 BЦ5 wp-WɎs:5}]Å|T)P'ɞyuO?G6'`%[3\p-z6ƾIFV2 ꃧC+ȕdln-3$@gEV@꬯ .$QrFaWmeMCAĄWੌi,ʜw;p'$!H;vm3vM5rjKp-N\ KZh5R(2f!j\g1b8 =e';Z?/e˸\kg B}z)?N20ow#C{r)IZX Y B%1 `/ݱ2޾RT:u)!S]^mT}Lлj@蘫hxÑJ_ N(֙p`7[g,yRýʒj< V;9l`תCA|&pRſbᠻ|.X؛ CXt03 .[m1 Á[b*)(ԂO dկw L268  pZ=5lOY3"Vv2 (ʇT+8f)BwAF< +O2y$$]2AJFM{\xhlMp{:F'q6)c`0h׵{L }=Y17GOy{AL[yAA̶VcRWpa)DK>~ dCpt6<.v8 .fusT 2dp:R+ 6Y{H&7G~\N uȓ-lr  k$!uX>R;`JS0rbY@JW{Ul}ai s}̅B3}g͝==M5Lu۷W.v,e?܋X(ߪNbfT_]:N0DzdH㒄~6ܡ{"cgu]*>yYK0m-I"wEC5fƱBo1&~uwx 沙RWjΐ 7R4(q(^>'ţ~yтY DkCXekyb 1JͥdL]^ cNHOGNQ뱈OcIFYV)PYl&~I/Nۀv"5\tĢ*2YG)7X z@C#.'[^čl`q@josJ^d]Jo5^ }4c"(cd[=bȷ}< FX;u $y/kER.Y3]V' i~A6m O!kpD) z7#J TbSF)KsoJ]-84H>y2@|Tmd`JgJpH׃yPu#g/*"cq[w)ިFz `2ov)%m$ц}>"O(gP(C7o`!#w-+e9 r}ÝaIdN) ?úò.ymc5HmAP *n udyLWE+Nvq HH9ݸU1ݪ{$Z ހkP./)M8x7(r|E~v3ZRi%=kV;|V맜?t \kR3G%8*և}\ʼnc:R0@H_~̻ rp^">atU3dʒ5u0سaj&䥦j1DoR 0jNTћtM٠A17ycBʀ~x*n >8$s~+ܝ3Te>gx.e,=)(02m)_DK,Ӷe94]h<;F1oBO< 5\4/T]$r{:aA@ࣤN# T#l۪}xY}{3_3$1szB+p)T &jt ත[AmDIʼn">+ 8~yf6חszB'𻥬-jݏ%b)?`չ5w!XT ?(V'9IOԒ\!Q_ޫ^T9aK^pJ°KACVv <ݍ!TF㐨k/PATj+xWf;<4sG kB;;BNGS^$x2؜T*{ޙoAv(Ya_ޏ+-# Zವ",v2V6BfKfaGɌyh֞3OopEZ԰ |u¿O[l#5({ ':A1HaUC*,pލqa1q̎@RW509:q5I6D|/ډDX #$6q&Gm %{ }(: )X0CR]^lֱLY#=G`e'~[sEQ_kZSQGFt9˥u)7<FX0֜Vl bl|'׷c͇IhE\)" {E, R~"b/fC=ޜDzZ*q/pGZ@5.8f&|xtoZ8c綖@h~Zj]nbJOSN$ȩ+l+usk3>WHxHw)XSOCR^uOR*3o#&iBD+dV(?xh2x~]d.|}[!^wL&阱IE3K͟t_gO/s*#UȻRSj6كϳhP@^V7"e?6}0BuVinX|QVK4 A|DѮDZOgIYk+֨djeD+,HqpSa/Ӑ֝+iɜg1/T:ż!#%fعY>ĕP?^&y 3easm|I%aɕ烙Pux.OQGW:6R6 [~h0~ЗWF̜DlJ![Y; 1$0K!!% ]0D8ANrqD:^<w4Llcq'u_'UvąB^Lx+?dp 6[oy x"ig A8 #]ڒDY DJSD#]a! :L`IEX=P2X/-Ryz58iO R6PSu]3 VH8r᲎i Xꑀd+tͥ FuCKLB $rA TU10ί<&̟0Wתn& 6*kNȘE$nM^p,^S*HZԫψAet5=鉶Dr-ZH^̀?L'9Wp.%H^\M`vG5 U5:Y{Ŵ?S#vG>;eqֺ'DCo ̫i\Rc 7Vb< L"01mҚOO3XC̚-޿n\ǀRv*iułMчuf຿Xoϱdּ$ML{;HA2bUp;'jGl,%a=tyX*W/LeMAkwzyѤf\ L<2o;򒄺fuTsR7?oy*\xp޾B 8cO1Ru.MvxigdbB>4.٘h 9SK+^ 'Bն UH&Jkμ7":"8Ky8*5<[%>*`uTrp&O{>i4KPL[YQE0$"F5aܡ1mkDwx[3VŃ-z%}wl5{3g/$Iq^@&)2O1B &\ $gv j##bsI1f*b2Z&Rڪ#8Q3Fo\;|aȊ8OKlj׊Ú6Z7 *Xl1ThIqsBJ_"2 0w49W$1V/w@1x4y_:\:nwU%TM(U8O ;,`]%C?18-TRgd {RŇR/՛~Kr]h#u*W;xS[@ȎC瘒6{ag1{'#`#]HoPDG؛.TNQf) G QiG)Xo{&meCZS1aj\`czYJd߉dٗZ'tGSE0HNs̐LjHl(QiKi|ka@nV KؤP:/ResXD{!Kd3?`DXf"r_)YӞVRANtT~d?LfCݔ:}9( bEaef?$E)Qz\tr@$!S(9n?lkܮl(։eqV}ui_kl 00)v|f^K~ 9'^}0 ڰ :xC, ɋ3uH?zX$2e_\GXd#rơs$4|))7 gbct^; 7fN`V6e\fHX vL s-*tLvPi?"ԢbPRAfe*gЁl>Y6AEݳY(]XcV@u ̀ O\`8iXƯ]eB&.u4-p*oBt1dg##˒^UKB9Dp[n)9RBưl:y,87*kI2 X`KdEwu[Ql1O=.?fqʹ1w1*UOG > ܢRqpY, K5Seմ9G,]#&S*RBpO2=[&MTUsQVbrȢ)g*^?< C+AIEZ"\" t6+_ȗ)_5+[J Gq3Y/+R:]!>]S/_1]]>Rū[<|]gզ?;TE(jו"?ZgV?3#33h8rqTalI5 9Dŕ`Wԗ[{5I-?;#`%/Y%1(4Ig õ߀zR29FiG[ƿ(YKgi/D JQjU}Iݧg%l;4m6śมi$ۀz0=ރLH ,Y?!nNU_P {ϯ2q՛BLrDǗ)[% #+ SFGJUobB=is9Fq瞶v4#Iܳ-{؈})W a=#>zq psDI [:i?X>j ξ?[D08o >XQ. K`i^TM>VJJx?'D _)8usŴ \Q$gxd֗<ߌFƠ6UF1Om}>7Gnw(Ydmihf1aOjKM7(U]nzp=ʇ>*RǀCi%ۥu}۟lC_XF#'QU.zd@?e q;۶Ʒ'wX'E~(A1`*d7 z{P!l.uD{Z{̎Ԥ'k4MHX[s @_E+WߥK/y7tO\- Cj2R B c\YDFyqcԣR=o[6vf3$_TRSCeϲDxG>fgc;+u[nL0+{+^-8oǩ yb)CO-VY3k!c؜xЈΨfWPdኲ,VQCj dރԈ<x*W ;uI6LH'ʝx5o?v+HFZY#q BZ=Haʨ_H1TWoFoa"2 MμX\ϲG[ǎ hr=/?uk]@'{b}Q- c0 k`\Qxܠ"ƃXCfOmRFAL?\9S2#N>1Û)eWƜn[Aج1|mV"/myEs -bKBg@f^%=T2HĨbv-ղl{rd a{'"ni52ObS̕K =ʣz&2OAW DM^58$8O'ߐg< &/2,zp  ΨK+ҰyCASJ@)MC2A_a㨐y^m7qΑ3imwMwy(FzQarimYQߤ1EޤPy&,x"&46mh<{Ío++*wʾg_w On%8 :37K,n/$K:E!#uWg쵹) 8h@;m|hԛE L$R70ߩ윰Lkx$GuU.m<gOo)M?ErCX䅫~A,d 9Ar`vl! :GC 86iWŵ*[}IoQ/3KR 0HƵZз,ҡ 6>d 4 tb_[Ha_RuucڜλէRz 7W<~DusH^wKx67[G~MEpx?]c t>isqLi[ikm*ỜA~csH:cK!wBh3Z ^&"K= '4"$ 7Bٙ nQ#i$(򒈈"їE {\#lVZmqFFOu[lHb'+ַ^=n(.ylΞ#y(o٢濷LzNa :уS`5E SNv]=hyD^DٳoH E b}!GUܥJMR?u Qv}"wD9Na?0挛ɟVĬi7-5aH huO>e;q'_ŏfs ÙCX4ikD0&5.G2pqYf` -˥`<( mZ5A۞$]SscwSCUl/ P\X%8I`a01ԀWCG>88ԿyOP_\<*?95[(2X..@ʭm>WhV!>_ǜ\4WY\Wfdn`#־!طYkBwI%4~΋? .zQl(l)%.Cݻän:A-EG0TJ~͒gmn7.6ڦCL}.q3uk[baF<]U?38Cf[ w.2TS ;ãalgob3-)&߮c\D틸~*j Υ`Qe2 TU>ɇa nv"6<-| !Խ,;HX#//OЕ-6{}D7TM!a`F,Z- FrLUNJd*y ;O8{ Jy1]qr$7< Fh` N @҃F\9gm͎ t 9Ԟ}w :#PڷqΥ4rҁ۳^eĞFt4Y w 2"LT,˪/=]"o;]+16u3( _s BZE EiS=/|dyZr $TY ULCNg]hNz(65WH6KI][ #q!;3кG\Sd-/p,WS}rHQ x˨=\b6:v) 㛔&1Ƿ3Pq̹X5ގy/$HyzCR_MC619ēsyO󏆔\}Ob-JL)ڇWKOuļEfI\=t+& t'̫ֈs-pFeD1Д$1P[270cHHY:z_:5 ?!"Ёn0F,F.(rd ү\\9̦& 1WDQn꯯ w&Q &~mF0]N3/ 8$a@r RˑD?aLޑΨsi9c\\G>jX9`b ;.H:(K 1&KhP-Jnl2:φtky ?-Ȇu$9q#'!LjBЧz=FEQX8lmR=S50{0n3ݹ^+*O*<cQ rd:ۊ߿zK}1(/M c1g<ð{hA#h.x֌xO7 7& tA m~36:mJwXpb͡9C![ U@"uT]v a~W>Fh N@(Io{ '47 !jr/: >Pk HO>wZ)xmsY6E`.ҬR^|cy, -VYrA-$Wkκ\=YpɎ 3y^ݍƾBFmW |"C.O> fLo*wׅnYnrf6ۓ6Lٻ?~-/. Zt&$C'ާxNȝ;!KW1 jg"@6\K'+{+BRصe (N/h8,? YtReGE-eۃՓ1DsOGrcZxbM"6۲wȧeRfZwCH պ [kK*0s$b0jJLhf<䭿A2Ϊ& A=erbk"QS^j _K$,>劖cʘ&Wvt;ǀ|hw]< IU; I2274^fU|`_B26;L@>:s TLhR67p\%i q>% ro"Vш6^S鹠I6|ZuszX);QnXS 61 6CD[`UT)] Fy R<-61D: wa=r(7ʢ}rK6/7A{MPphyvNi(n$0Jvtgc-[!͉2$j‡bxv;k) 3%jCD&BYJkgZcHhըO|I#$2@ĉx7897sC(dtrC~r*ӄLn4;An[:}2BL3,W=YV#& =J'oeHRjB ۑEKrK8²Wwk%b|0n4FN9q_k;sc$pQk Bm 'C2u>oKQT;@{+>~Qi> =h֤7i'O 9u}m?Q'S;*@4E`1q͌+#x%̾yN_:y"55mMqzrFuۜה5+˜eCż Eܽ6O𛚐GA#{aӛqDVޙd*N5PZF l+kj*ua;it  L(HV HNyTq,< J4qsO2x7ȳ`E"W]-mQj- ~{[pJ<$mV, Ă V\*];B+2-AMqU"GD]ѼE"{ PRa /onokqKdm-g!fXg1@&|hvfM{]1"KQ It*iygPҵosiՎ)1Y۶PZu it?aa[y?!jP2 L3;)6 f@񓠤S1uvC ؆mއAq!-#S7ä0`ȎWdoJOXor^:FZxJ9Ec!{$7g7>#srXB[C D+keߨ|рFݻjv+W -aRRU-G!z& yuGX~qt־7͓Qt<˝Ћc\l6+5;]Ǭ=&ȴzűetZd{LBOR5_TkSV7 &{ /G7-WmcNW\+2|Wa1 h{!Ҥs3k!w6z<# pmB[(ngpEf'd_F _1̀sp޷&  ^ OOԁHExuc8cS)#*+ f} }BvlFi8;) qa1C51o`X>>F@SO͜e7H#EW+5AxN4޽Oo.,| |#FfFЫĥ``4ArYmAUNAh昇9?<7(,e0s6balPBk,_ߗ/Vv9+4jw'nܮunW]d,'%puի)lyr*Rpݙ ^,?~ KSh45Fc"#ᶮe7a+iA &NDaCHƧRt?o!f/dUG}*iG$*T~Z,9fʾ#h~"E _@C4ۆ]-ˍ⽭)|96rt,S`Aƚ6#DÔ/5ФRXs˕|؎["_Ur'2a0TŗXQqWg5a]&㾜nR AS!i2{‚3gh񚺴T@@;&7]1"Tˑ_Rqt0_o׸琫ۣRKmUku'}㨀f7k̻ &^= sbB>3ACXA?dQ%cbPˎ"QkGj1 U JX|4܇Fh-!B<'9V וzDhVWfqHWpġ ⵂQ*7*6Z, &ܣ!hZBb []<`2viAM7Y]>ou*0;@ u°Oi/Βtc 0'-tgBɘG*צUo~Kvh.b•ʔX4gĘUŪXt"m5L&sf$4Zh}^K'`n|V-+{e^ri RI> ͱ0f IE G d5Tb:p8^Lo"ǫ 'G[-bF--r'sÂK~Nep>zm-, K)LƧ"ye$Yc$9lqP4_dy\eQAD!? * /"_PTAB5mQK V)]],`*cX*b1߻B"x(Q0{Ö^m&$"H¾_ؽxKﱼ߶Ўj\)m)0gћ/$qyǹWoo0vyg?tr9Uw}&VCn qSUhRmPg{YGa$#kδNukX=xK[ /XpE}C2 t`A/ãl4ѯj(lzQKe%,gܱxޭTHq,N+B:6xl?lgśI\ 7A ZBbxJ>/I@GyU{RDH< `t׀ #eTOvV.$Cz8P /8~AOZ_6ֺ)gf{M?ou/Rw<s' V까OK10 2` 3@rz:]fk{+C^8ٸziU!-q+5z @M)}+ ]3,3DXݙo?Г7wmj}OvLJY$Bk#moa/ENQ_H6[;!/D7Nfze|Β *ӱr:ĭ]8m|fv:8 O@;Sq٩J_hbt`l=} cZC-)<\U*ѣ9L,j׋-V@@ȈnV%NOL'M\1 nۥ/ y?)b~yO|fC<+P蘋 s^DžpaR>OZ$v hhE,hMئe܏C9_ o/ HlQ]|\-lf뿗VŞ{=g-E -@ԲI4ضGNpG^+H32|SLS ˫F7ی*TO[0BJOh=)':8x0G:jefk*$ƀEO٫qc4sl(LN$t,1닌0*+9s4uykGi^ۓrXjpBd (ƁHO[XC:M|Q!0ͮZGTYHmv D9[ELWQnJT;phV6YVI*"qK'NLc{k[K;2MGVSn4}csMShj@͐ggeAS%f%ji"EQӋ;$ '(7M\tGM8g6{\2z7dBle>H]7O.JdFVN_¨[uG[X̧u} h0 TA?ϜPd2vShN  mc޾(W,̢ iH`OnW#WmIz̘rW~6-5Dcx{,?q{w-6Y@ A>^_GʃZ%YHͤf? 7mrQв3)!ov`MkD0שDq2a<GK3&t\#hrISaO$^R^#a'zZL -|ˢmc}T-" poA_ ;|eeW%_voC-Rpы'{WU_(zfnݸ9D ,"q,@!Rk5B0g RD9Lٞ-7|qQ&6ӑH6txw\rqk|:)qpk2gx_} q02uzlT=2"6o}0Mܶ 3I( XA1% |51 ͺ~A\r?䘧C wZR 8;̨,, iӣák-&I xd^y .i;6:i!zϽ 4@'[~Ы]T5಩}^ءjmUT?IKf07/5VJ4͍؁1qC]F 5q)Vōv Ԇ)aݐ>gކ5B=gȬ+"+Ǘ J{8Fh$}L#Pv 6`cWT-}: g˭šN9د`5 Y H~Bަ g&Jt&QX08c"n;)gh+X2&lOëޞ{ў$MEH{# m$ÈJwKWs]Yz[w ?cRM*4qɓ!ymLN4n5R&To5UdŘJ]'+fK҄$FY˓q^u&VjdrvfS2Q2IʽLZ%W:X{eB0 6@rk0ɢ{sd$f3+vtwiOͰh'j^YW>o.Qd$Oޟ=(5yՄ?5}_>\_ҐʀEl -|N;x9y|} ܤW8tVDy@NFjFqfe,Y7X`ZCRa"V*؀ZPajm ]z-?\^v,ŮVs3)m~ l|)^اyuf2a 9xت"Ԣ,b2T`u+- iYĎ¿J!#u௺c?{2G B ?5RƯcv?%#w{dz%BL[SNrgc>=Jݚ*z3s8H<2t:Gw^~IMs51,fZNl9_}`oKu 7 %EVTWKPʻjqm!@rg9K{Jl &;$m3ȼ,Cp{,ǃ]>1#6}vҸ dFa|8a`Ն%=mq KѢ:YF,bNjPOן~)ETlږU{!ٿi~GQk 8AMG@i,zdEVbG$r) ( \@5 W>{DXE.Ru`5H (ƭ/#r$YBycH#1,zu\MuFRPQw[-\HT.@*gGMZ{0d kDpBqhV*!&kW$cT>uӞ$423uS:=,S0R1nɞ=f7H3?Ѣ"#`& eO'9K@5x: L GR`CoC| P R^ &,]%%_zuBթJzRoVJMP^47UtrfSkk)8r*m]8ǮCFkU%U .F^[nᢴhJP'Pþf6vcBgH14Kgm+ѳ2I8rg-DokUzYϸ,u[ ;J#zVQ[۾i2AY%qPG |0d?uҨ'yuweQ>x/}Eq/.[7PY^6ypJJ4Iå޶n[#"~s\YZR1 r}([$V^,DF> ڿ^Xم.*#?IuV7t RĕJoFxї&yPnS?*})!D9^2DxهF_ ap6SYZ\m+ iw<6_B蟫&&^3&uo0_,{N/Cŏx*ܙCcS'e7y̓5$֫69t=cyJ+ nUI{6{MaLl'wci^itK4lEuѩ [KFk^}~brljtEnC:FnEC!HkPw|I1@!HnLHj y xIA7$ęeg˻-=e2"K3-oƹT$2i`G j@TEiq:%|{GCi~JFx%a:4 4CuK,(LNK *'Ka_U&uF;ODAKX Z۟ceo@  s"TRk{#r>IRV(},)9JHi7^-SV<%ӗgİڱ*Usɜt(|9pH/rtK,<'t}j 4NÌ[;M,-D ?jX ѺkAF\ =Qܮh@ȻЇpYe:H}f\Ryߔ< c7׽Uø#*de4룝q랱hVW`miP`ޝԱoVys\p6qf>|u5{Cs?MsW ?[=VIY>q!>zB?B*n ¬~ BO]F H3HJ3I}w_˥?>Tf^;J٦֢%WHueG2WG-!B*ہRmszRڲy3w굔I, o=E3&άЫvpxz}5JC[ēZ+jqCGx7X!5pf ,hmMKB) ƕACen}BqQ;@)wɗ M-n`Zʨbβgwe:?YLu,ʃZ;,pǃuR:&4)Y~\!uOq&U8❘bmٺF4Lgk\>}]z]cPDbbAWʋp}t:`u)d5K}A?2#yadr3]6;1gRJ<$bs3#M, ?o޳Mب._2${A,엮gc_CmAS)Wa^ha39VˮjqO-(n@IS7Tt{xFQvO;.?%j/ⷸ]M#k$\A~Ȇc4*> GGO$2rA&%6X'HTg95jCO(Ӡ6qTێa Oʠq|}uEڙc:~5j!O5K>TTC"M jdy0A CG7}aNp\A׺ͻY@ ͯ T! :8ub28+'laʔYj97I_L J#@-"hrSm8Hm;dPEN;$a3N1W{Ӽj?tu_^G_3-8<~hm:`ֱ 't} {n4%a}\.KR!~޷ }OoPS >瘛1v%)@\DRQey@#Z$GPdɒ)j0*;="`LL":#pqi0& 5ptKMJLN,o0Ua\V4EsQeqarvR[դٵGԩ bLHN8$ޗ]l4Wse9g42,7Ӏ"iGaú~w~S5UYv, 4u @T%Q}6Կ/C{ǣ'wfiC»E TBdOY[jfT` D4+FÛf{2`Z' wNuxq𬅷obK9hMٜ@Ǵ'qͥ˭-pyH\#̛:J"D ;j&OE0NȳM]ec.u'^Pc8B`wպ?,`TH [.Kbp=!؇"lWR5ȉF#]`Dy*nJ4D2Mϰ[o1!AXU|ZTAe?jOr=@Z3y|C6 *5ox9&.;+Ime?z[k.RVaG1Z9FUV)r ^sO)Wb{?X02S-f0\{*w:gdDfyŝ WZ/Pl8V()Z4&2r"ʩ1+F%kU /("^+T]^Tu>*4?KUw?>σ&OZ( W}]k@h#v箮Ƌw,B/)_2yf-l&ո)'͏Xr<]]9^lU.E)X rNdXcլ6ƚ ̰8̺L],8j?u+np$N2`l*6ƲT{Rs)a*L,&9_D.7mʦIJAC;0/D'S:]i`VC-v[ }ayt5i*lENSk\V4VD? RB=׿4-lI&q$X:^T6sa^I1oPvYM )ۊS*آwnLƂ&]_=; c^&Lfr3$^k( OL%fW"(/:TA.%\A5ѭD}aP ְ7BQhO@C]HX7 ,٢ǠbY*K?Wtht`  Xm Gu/E )'׽B]Q,WbyкnJY|͓?[qnT寂i-!}24Igy<JcRp3e0I7-4p Bրo\GEgڐEɅ1j1:/ {!/XkUҲ"/zWM:g\y~fN#yo `79j֮ ѱݓRD) Y0*!CCSq)>A_%~zhZiDbY͗[5'}UʒGo6+6nbF{`[&،ۧ${Fj|Iy^֍w>]4Az;α#pQ'"G ,YA@F>=Kf,!n6mp꾡VmBW9+k~ r=_x 2B6T]mOkFnTi2a0xKJ B=IŸJwZT8g}׼b1+&${w2PCdaDQKt+alϳ+ CSW$n ^{}wcV2` -( n!R`!}Yx;@{Cq H3A,^"6v?!){q1~5{ 5,|l;8"w _Rŭ'0S#Q\9K4X\O:G}<V:=g6#yMb^"ԩA1WPWګ?F.!#Tnv*ASC6Y(],ҬΟzqmWgKpڈt s^ `Sꬹ- oVRciV#(@mJT L6I.n <74 K͛x OM^ %aW4)ԮS$noM[Gic~GiTC#Nr.)WV'Yґ8VL1g<4s'/yQx$zSpq$y{!{W0GVQT(dHeQ玿!y0RlS*{k6>$yF21Y%WPoAR;5AW׈n\4e C}pc*cizk 6Y(fyAeJ(Yy - *-DQvfM73oh2l񬁗\Hh~S]e"vP 0B99j|~:)zm`drl?4*]k%*98z<@4=ϧGW"DrmNznħ)?zDNIz;/^%1 &qPMKh3]?I}OivAJ;=n$z)mN%.` 2$ BjNQ@IϾQob/DrslNbȫA^;ӬfU"Rd)6l)-X?mwJi}#<]"k&/pj .V>\%\LĶ*DZo<GvǬWEdC+6ԦT3=qn܃ߣ!_H#w$7"ξ=B?"HH\vF_T)5H#O6p킲د^vb[sDQQAl/ݸxc{s[9%k;xeO g-Hŷ^92q%q>$JI/-W7 2(vyxM st 7jt s6o| b|w8l~:1.dYRVDI/[ٗ7=#b'tLE0 W IK֪oyz6P(*.“__6uq` }YyzU&+oAuv(,)ё,VJ^vPHҮ%SY kV)OYUouzQRŨ qL G+g=gJ<}@'变ͥϒ:ؿM`7yiD4Yv3{(w+d%sC4;L >0qT9*۔1hS]r,'-jAxezHqb)IH 1"!y<,x㘊jpNPbIFΚM `F`f 1'圁Fp!eOms!Ky lc g{4JD \r z5'p:-kJbh)myݭa&-[ ͤApةsޠ."1b8eρ<@^GI}eD;ARհ&[YwJF* ڡ'ܾaH.#'Jh JIwAx>cijig5I!b?/׀:z7v$$ ]錰V8.L_P~Ts9CT~>Dk\M-Zݬ%r K:{I+xzO+Ğr)~֠hچe  MMIl9?T1u1ttj~/HYԐ8DKC9 j!>hbq4 a3ECLAJGr%`~[sVs_*Yh,z2.dYd{\M6/NwhEb?w`y7*n Rݣ|iA? ,=ZS 32Y?7.Lj]r3PCM+e7+_HDfOla7]E巋5J;쾘 hxܰm݃ *A<#Piu*09Lڱ-#6K~4W%9E`HYx.IXd zMAh "U !'ZȣA1q_73t.f9g8tDQC8簂aS:Rд%!OW^9ed\g_;fJhfLq::ʮjC{B7lQ [_kqX|Ar V" Z%(zqPHY]-=/&{2*ǙFٽV_vbȕ.ˇ#]<9˓QjD<%#D1_u ` a2̓"%?협_Vx*ۥl:i ѓw:FUô#1itMұT6l#6PiFELOm]JxyjH7:]tXAtk`7 :Xؔ?P u~vTJuHkEHN 861r+<jvv|A[}q|s!15 xv{pғan?_FOҊc&DJ񵐯 53qd"Ďk+?'p60(AԼbK5WMVJ[v&*ms*o4h` O3}P6 )~ Dhc]\3/_e'(oCXʋ,#k! {nV"gŗc8{ʀkC $`.uVpU{w[}]5QݤD48vуVIset ӧAL%r7 ?,\O}U\/TV֒u0#Tr[f۳mp_bS:^uYI̩C>0C`$6}&.w1|5q'/ؕOD:L/A{[wAVBhd"<ٞFVkVܟ}Xg}d[*6-R@Mi=T_ܜ߲<|4!$ Md7rw>CK4̩\|SMnq2VkRsBYd?y&}M $բܾ C+xL5xƁJ?8G&p B/u/36^Sͻ'h|dj{2F{8 =M9fŐp#< Cuf`QGAlYO֛s3޴0U}zI@t;2ש;TrrA7P[K<p.ont0[JUVD/27na Z:fɂOGB@;LʯtY^Mi)@]% @G`'~5h52w>f܀RCL%odKqZ 4 ;i )& u^):C9Lit6^"*p*j.@JeqhcȐC2v초 fVұGXs{{&GΞ_s🽽 'k.8YbDsM) d xWÆ_,v'(8$T ^L\636v _%9<9ʙ9~vd88@.iVšiu||;@(ͼDiM W,m8cg"N C#]qA5}w[ϙLRGͥPX]P\1 {1XM:JeSbB#9| FO)KE U Pu/O꺠x.olG=ڮh@j2vFH64RP{XW `Dg_-Ygi[md [["\LUG%\x- !0N:dGb m_\#tv( |wF2OP,ufo|R^4}2w#d&t $z'+ww|w'ٯ!5 Siw.bі~Dkgbq (i 6п8ˍ\tEoY`‚$Cr]H :qūeL@&xXJO'j1}d>eHy#vvJIJH 7aבAN,uj$"R[e_.fC:7&$RcH~|4o ((S&p~UucAC @:].tMV 9&6Y[Fb4C1BW (Z}:ɚ@\Ը{a \pD,ы4myL~`ѫvX,;+Qk;e= Ym䖋C@sK0'3%mrHeH=B հRt'4SH9a"bda ;>0ȷ0;CvP=+z3[s7sM _nz͝z"Ûmvm~%`{=!8tJ/@mRz=u2{%\1^$G.dӊ#z{D!yhn5Z~ ;4HB|뛸b\CB`ƤN D9t<Yc%ބ`z-'gRB=TS U_*R*ha_IPv`v#?838N_XkǭpQjw 54˫2utNۯ}B(5ÎQo391'{vs|J"j::X!eVEv5i|B﷩-Z|OOv&2=/Rˁfs)wgzMd8TD[EJ0Dc4 %o.}y-Xqv % U~*wj-Z>XZR_=)6!yg)6PU2*B5O/ό80"bve?nxeә}EN|CB "mpEy9xtck3+e$@1J6x*>"AZO4o̙১&g&շ9,xTREj9Da=8S 21$`B&:G.(z>^u/x{ Ճ feMVH ‘SZ@ P\{ ˃BH o#OǺcVkmFfbiJ ] 5_@*$ϵڳ{A{c[l՚qlA ׭Ŋ%{F-'lŎ-+}$i +K>t0i`mK ˍ9ȯr9LNF&]Qcasasna%՘ n@ X2,ߟ?քxbYжFw4Yq) g>\zL-[XF+!T;<_6-C#1;c}@M'ZowB={x^d1[߽ODHK2iP=ɤ~Rn<'qN/tYz˅X`:ګ4-!Z%uW}'b4&8P>&#~0Z?1e:.Sq A ؓ`/d{[ib QCt˰0 n/RuJd)yPm FG歬H9So5^OfYⵄUhw3cmm?'5DœHwO7)>.Rٙy#6\dI\xS Z{kOf0NN5$oc'R%Y4n+өoqIbIö`{p>'?ˉU2Dr)ySN E)mDžIOo3&0)S$r{v,:3we;92˔(,iHyNb_m[u*a~c"|P$N/1rLmgtݼU7!\>褩r+Y1Bj  1x^y`s6,椑dVV~ {\ x1@}XpN^0^Ep@0$Һׁ۟?}m ZxC}a%θ(W 컬o M D-uGO:Yju&sCs,Z=|:rvU,^{ _:B4-KIͨ7wLHFTF+JTIۣVyCUF 'P$ DŅQqp#h2ƄC= ID~"93]/@Ӕx;3]@?D鑲NwS㹄 wK6Zit[1m*Zp;aoFc y_3$e{{R{2FqE;&GQ7-`̨ǂshP,]JuuO k?Rg4~n8"zFc*ĞHrXK}8 m,ٟ&VCҸ8^ Yųfj0bҭUn%V.롰d%V1!D+G];U:ricMLlTyݮG6ͱ*տJ ˠ:p8LdKl3C"J<ڭCuC~{ulK/u1n땾n{tǤgF5l~BR; ɽoYx)ꯛMOY`1_-(LADE?Kh~;})zWxbDʠ_:_}gl0}*7KTCe*m֊6k~C`Wv^8kd dt|u~5-`@2ÑJR_f> .g\) S5Mmqƴ==z_O@4N<[4IJ{)_T"蜬HA@hʥh|O %y|E2z!qh"o V.D逎S4ZEA[iRN(9~U'YSW$R\:(Pa"H``Wma)D"v{\3. Hpv*{R$wDh *'sZXx>8&uՊ38iQ6jѽ=t"ݿԵIm΢D3e_ z2j:P@]w˩{TY1</]f40Q!ڧѻRSpe Nx?l5c)CtSjX/؅?bvҲ68Sz9[h;swmUNZXxoyXb?fұ%ׇk&+06VAx nMt{6"Q= PDFq/yR ,|$rDb@p3F?A.vJrVrٿYZd%>SQg" 2>Ύl,KoCVj$'VjkNT 3MT譱: Nz39\z77Aκk .y($Rc#4 H\a<}CLxF ×:GuAUK y!yDGA.v㳚{XƟ<PǽLO9AMlh0)Pڒ-@aυIs`97z̒4G61q?AtZ9}~H{hK/tӖq2n$3/׳1Aa /H-t'破ybՃ#u]?CԻ~g]';T%o)4 !8?؍0 kj̓J 4+"(1ʙIEOҷPFJ&n^JX&ږ`S²@c(ye$`+c?) qV\] 24+B@t5 *\_x9C噧;wnSչZ܅F'lah\HT]uc._B(1|Lj>,hߎdC6,)6Dd)^ &q?]0̫R.D\.ٱJ%9PjM? uMFMŇn&Kͦ}B? Nߕ>9cUluNS9'Sx*'k?Gqtt߼9Z/|J9!Jk|DHt+ `y; 4GDW&2^v70o9L:WFӰ~ Uʰi7kq5sYJeT?^RoI+Rs܇4Zc绉-<SX6*UJ1yj27ѹ!^oN탔89q'v7,xV6 }rڒ0[O):9VƦ a ^b@Ѧcw%=LJNiMW>34%-<\R_{־IGuu`WP36|lR"]K7bgJ|m&jDnh1{ )0Т׆9?l4i,_7Uq#^EOKl;w/^ kB@}`[YLESs90E WX&G^ƒ6?a|dz5*)"{ 20Kb T=AdcGW#F%5'/;;_OOꋡ)AT\(`DcpLP޶#10wEA+hpbg? BW0 *+ @aXM_ J%|pIgSLn:uڞm1wFnS4/:eӈleѨ"-x]WK³L+׉$ W}'>rB0 ߳FX F5d" ^ >Sy.( JŇ<1tXnTb]S^F̭ xIYW˺mIX|%{o6/4؎ρ{bc,m# a6@4 A,,9“|Zy (Eĺ4m"zK Jxd+ x O믡A,oX$~Y"Gf^Ssm螕8ix+R̴ ٹD?1M9Pqk;MHa[tkEV^$MjY)iSabC }~dpdИt"D-P)e"ڇPذbұ=LPJt&F{q{)g [0| #wE D;:qcۊaK%@{WǷK/!@݈)-~q#u{8VqTSThwSXrn"ar1f٫S麿(FUr;뜵(,s2A?{Goꏺm3!)(.fN'j;)QrN*]2i4 ]$7t34wִD#N}iѝP2=oI;x_3ʪCƶ-X'j(7[ʳ;OLN!G)MUJ*Dž_?C4ٱ%}kC[iZkbG Cr0o|6_!Rq~N~"6wƎ@H2ѭAƀpXڷr즆(1䞚Y\hc J#k4!fm7N3W|audS{gާX|p z WX_$ȕ}@%`O?Y"6t2ZY! H WNAߒO+"Sf ՞ȴB%A㫵̷R9 ѓF!q~>p0^z\b*J˶ ֚J~$.Eyw)m*Kr'hE.2;drnn`88aF ɃO6Q.y;ߡO#Oɒꘑ˚8RzHOkl3iv~8RsXVVBWF/=b &al<Dž*D%B]_s}s&/'M4>pVu e\mJQ$_;Q  le/_{hӢ.]℺ 1SH F%211O叅 Ueŕ9d0@.O%"F4HQ]59p_V>#F}'9 !~/.¾;}#Ear5MJ62nߦG;ͅS;y^vhr_WڇtקDk^.ل$w 3̪!<*^ضot?E z[BjDDC3v7IETÂD.P↪z4QhGM!!Gт=De \"`UO"4;5Ը]1U ?K@[EviM]XЏ&"%[E)aH%`I*Ű|7_YBlK>f_2Cc1PAco4UqPsi&(q#s_yDׁ6RRwAaXhĮ :۠I࡞ 7+<[+5 =G'bq3.GuFd WĶW WᐣԎ"#adQ0*w$:8ʺ=lqKM Qaߗ84M،j&Io97mVǓ))\aΗ>;+ f'p˂<4u#??ӾOCCu#Z>u$rU@F_^r4#ꬫS7 ^gnZ?9oFĨ ~m]7bV,c) ^&/K~s^bn"on i[4po'lւ{1lbwLi(Ca֋MI"`FF kJ_QXMb36 T5JaH@F/%v^DoWMJd4(-$<؛](5G%tb _3i';Ǒ`2-cfi/jx#7C}Yv34g!{OB.?"hrĠ][Ҟ8H"QIM-ϗ2{)Ffw1|NŹ{4Lyk>]G_Ȯ K9C*G2a`G)kKjL"8~Z]~sE\Ru*|ڵdB`J68\vѸF΃JvGJ{ vjpf}[+>dr ][pPoG̚=/92yd"bb+uc!4y}Gqza!LD{Bb|V H.KJ вdj#_a5SvG/7Dnf((庆1YvV$f⏄QFhp8@_pT)$Fy?.}JtkIZ'41ʥ7RwdYd?A8b6lAfC4P78ٗX178t#YROY~^81xa/VヤBYa=(8KZލx,~aR'h&p d:>?mc&]kPVZKժx|(HuM3p)DD: җgj9U]Jg &.bɏU"Igpk^+0~p@s90BhAf pqk@߳ Z3 o=. Sia?U̓WLO I։I28Sjv>i"8/Vj}Y3,;}~zk (10?dAV @Sq,|uүA)A (r,+k2ʌ8NJ!uP g7lu]"-\"V;8okeYٖ3)t 4BW@B,HP&%`)D Iu9,}?ĂYr7VړdS^|^;5[[G ")ҡkZ )mPظKMSV|'Aw5'ڿhF3K :HVBo ERv}Z}!B+@.Q[.Z&Iu+$i:p)!Eur!!n2zîeШc2)kw,)?ʈ"$.{( tD>mW7|jHiBBe54rUa>2$Ne`vO6~V3^RC>{@ |n 2RJ"O*%t!'҆~׻ZKs$c%soİKSɃRt-p* /h8a;,%i (Zd` {aFۍc%K ͥbF]jE|J!%VD),Yxm5ԙa*.ɪ%La<4Z__Q _hlȎeF^p^ۂ`LNDCBHRWcq?ӴUs-uNGF^Aʚ(2wi #R֎dLJ9a.ٷ*H~*gU$XhDrOҼ p{kEf]ԓߜI@:.4m? pZ6mgЊ;[C>Cn}% }oeW@ԫwӷ#,=~B(K!֓؄ a<v5M~Vo<2,]5]xN'o dUhv.M˸>+✧k"7IE\7= SH@;^3ğb/ t?헠^oxeE!ɽOw1@1Qۣ3wyO2];}~G锅X2 ,{gh9|L _[-Z]n;bZVGv iΠ~d_Xso)Qcܰ5q6JD:YL5EVI\2ϿDơ}* hqv1zE@-c,o]aH7L፽A